Back Vietnam.Vn Hanoi police warn of a particularly dangerous strain of malware.
This is a particularly dangerous new generation of spyware/trojan malware, directly targeting mobile devices using the Android operating system. The malware primarily spreads through fake SMS messages, OTT messaging applications (Zalo, Telegram, etc.), or websites impersonating the National Public Service Portal, the Hanoi City Public Service Portal, the eTax Mobile tax application, the VNeID electronic identification application, and major commercial banks. The technical methods used by RedHook are as follows:
Abuse of Accessibility Services: As soon as the user downloads and installs the malicious .APK file, the malware uses interface phishing tricks to request "Accessibility Services" permission. Once granted, RedHook gains complete control of the user interface without rooting the device.
Automatic system permission granting: The malware automatically performs stealthy touch operations to grant all sorts of dangerous permissions (read/send SMS, contacts, call logs, storage, recording, screen overlay drawing).
Data theft and real-time monitoring: Silently recording the screen, capturing keyboard activity (keylogging), secretly reading messages containing OTP verification codes, bank account passwords, and sensitive personal information.
Automated money transfer: Automatically activates the victim's own banking app on their phone, initiates a money transfer order, automatically fills in the OTP code, and approves the transaction without the victim's knowledge.
Concealment and self-recovery mechanism: Registers for the system restart event (BOOT_COMPLETED), automatically reactivating all malicious processes even if the user restarts the phone.
StormEncryptor ransomware ( detected August 11 , 2026 ):
Deployed by the professional hacking group Storm-1175, targeting entire server (Windows Server) and workstation (Windows Client) systems within the internal networks of agencies, organizations, and businesses. The infection and damage caused by StormEncryptor:
Supply chain attack via RMM tool: Hackers exploited the critically serious security vulnerability CVE-2026-18577 on the N-able N-central remote monitoring and management platform to gain supreme administrative control of the centralized management center.
Automated mass malware infection: From a compromised N-central server, hackers used the system's automatic software deployment feature to push the StormEncryptor ransomware to numerous workstations and servers within the internal network in a short period of time.
Double encryption and extortion: The hackers disable security/backup services, delete backup copies (Shadow Copies), encrypt all data files using a strong encryption algorithm, and leave a ransom message. Simultaneously, they extract and steal sensitive data before encryption, threatening to release it.
Regarding the immediate review and remediation of malware strains, the Hanoi City Police Department provides the following information:
Regarding the RedHook malware: If you detect signs of infection on your mobile device (strange apps appearing, screens jumping around, unwarranted money loss, unusual overheating when not in use, screens performing actions on their own, or displaying a "Wireless Debugging" message), strictly follow the emergency network isolation procedure, do not enter any additional passwords/OTPs, and use a clean device to call the bank's hotline to immediately block your account.
Emergency response upon detection of RedHook and StormEncryptor malware incidents:
System Isolation: Immediately turn off Wi-Fi, 3G/4G/5G (for mobile devices) or disconnect network/VLAN cables (for computers/servers). Absolutely do not restart the server without backing up RAM. System Isolation: Use a clean device to change passwords, change PINs, immediately the bank to freeze accounts, and urgently block cards. Sample Collection and Reporting: Extract logs, .APK files, or encrypted files exchanged with CATP.
Secure recovery: Reinstall a clean operating system/firmware, patch all security vulnerabilities, and restore data from a secure offline backup (3-2-1 rule).
Given the above situation, in order to strengthen cybersecurity and information security in Hanoi, and to promptly prevent, deter, and respond to cybersecurity threats, the Hanoi City Police Department requests all officials, civil servants, employees, and workers in Hanoi to strictly comply with the legal regulations on cybersecurity, data security, and the protection of personal data and state secrets.
Absolutely do not click on strange links sent via email/SMS/Zalo and OTT applications; do not download or install applications from unknown sources (especially .APK files on Android phones); do not open or extract strange attachments. Only install applications from official app stores (Google Play Store, Apple App Store) and carefully check application permissions before approving them.
Source:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
