Back Vietnam.Vn Hanoi police warn of several particularly dangerous malware strains.
Recently, several particularly dangerous malware strains have emerged, being exploited by hacker groups to directly attack the information systems of agencies and organizations, as well as the mobile devices of officials, civil servants, and employees in the area, posing a potential risk to cybersecurity and information security of these agencies and organizations.
The RedHook spyware strain
Accordingly, particularly dangerous malware strains include the RedHook spyware strain (discovered in early August 2026).
This is a particularly dangerous new generation of spyware/trojan malware that directly targets mobile devices using the Android operating system.
Malware is primarily spread through fake SMS messages, OTT messaging applications (Zalo, Telegram, etc.), or websites impersonating the National Public Service Portal, the Hanoi City Public Service Portal, the eTax Mobile tax application, the VNeID electronic identification application, and major commercial banks.
As soon as the user downloads and installs the malicious .APK file, the malware uses interface phishing tricks to request "Accessibility Services" permission. Once granted, RedHook gains complete control over the user interface without needing to root the device.
The malware automatically performs stealthy touch operations to grant all sorts of dangerous permissions (read/send SMS, contacts, call logs, storage, recording, screen overlay drawing).
The malware silently records the screen, captures keyboard input (keylogging), and secretly reads messages containing OTP verification codes, bank account passwords, and sensitive personal information.
The app automatically activates the victim's own banking application on their phone, initiates a money transfer order, automatically fills in the OTP code, and approves the transaction without the victim's knowledge.
The malware has a stealth and self-recovery mechanism. It registers for the system restart event (BOOT_COMPLETED), automatically reactivating all malicious processes even after the user restarts the phone.
The StormEncryptor ransomware (discovered on August 11, 2026), deployed by the professional hacking group Storm-1175, targets entire server (Windows Server) and workstation (Windows Client) systems within the internal networks of agencies, organizations, and businesses.
StormEncryptor's infection and damage tactics include supply chain attacks via RMM tools.
Hackers exploited the critically serious security vulnerability CVE-2026-18577 on the N-able N-central remote monitoring and administration platform to gain supreme administrative control over the centralized management center.
From the compromised N-central server, hackers used the system's automatic software deployment feature to push the StormEncryptor ransomware to numerous workstations and servers within the internal network in a short period of time.
The malware disables security/backup services, deletes backup copies (Shadow Copies), encrypts all data files using a strong encryption algorithm, and leaves a ransom message. Simultaneously, the hackers extract and steal sensitive data before encryption, threatening to release it.
Review and fix malware strains.
The police recommend that malware strains be reviewed and fixed immediately.
Regarding the RedHook malware, if you detect signs of infection on your mobile device (strange apps appearing, screens jumping around, unwarranted money loss, unusual overheating when not in use, screens performing actions on their own, or displaying "Wireless Debugging" notifications), strictly follow the emergency network isolation procedure, do not enter any additional passwords/OTPs, and use a clean device to call the bank's hotline to immediately block your account.
Emergency response upon detecting RedHook and StormEncryptor malware: Immediately turn off Wi-Fi, 3G/4G/5G (for mobile devices), or disconnect network/VLAN cables (for computers/servers). Absolutely do not restart the server without backing up RAM.
Use a clean device to change your password or PIN, and immediately your bank to freeze your account or block your card urgently.
Extract logs, .APK files, or encrypted files exchanged to Coing an TP Hanoi. Reinstall a clean operating system/firmware, patch all security vulnerabilities, and restore data from a secure offline backup (3-2-1 rule).
Given the above situation, in order to strengthen cybersecurity and information security in Hanoi, and to promptly prevent, deter, and respond to cybersecurity threats, the Hanoi City Police Department requests all officials, civil servants, employees, and workers in Hanoi to strictly comply with the legal regulations on cybersecurity, data security, and the protection of personal data and state secrets.
Absolutely do not click on strange links sent via email/SMS/Zalo and OTT applications; do not download or install applications from unknown sources (especially .APK files on Android phones); do not open or extract strange attachments.
Only install apps from official app stores (Google Play Store, Apple App Store) and carefully check app permissions before approving them.
Source:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
