Back Vietnam.Vn High school seniors create malware to launch global attacks, earning tens of billions ...
On March 25th, according to information from the Thanh Hoa Provincial Police, through monitoring the online environment, the Cyber Security and High-Tech Crime Prevention Department of the Ministry of Public Security , in coordination with the Cyber Security and High-Tech Crime Prevention Department (Thanh Hoa Provincial Police), discovered a network distributing malware to steal data from Internet users in many countries around the world.
Based on the initial information gathered, the authorities proceeded to verify and clarify the methods and tactics used by the individuals involved.
According to initial investigation documents from the Cyber Security and High-Tech Crime Prevention Department ( Thanh Hoa Provincial Police), around 2023, NVX (name changed), residing in Hac Thanh ward, Thanh Hoa province (currently a 12th-grade student in the province), began to independently learn programming languages such as Python and C++ to write programs that run on computers.
Initially, programming was solely for the purpose of learning, researching, and experimenting with simple computer programs.
However, during his in-depth study of operating system architecture and how data is stored on computers, NVX conceived the idea of building code that could access data stored in users' web browsers.
The police investigation revealed that to develop the malware, X used programming languages such as Python and C++, creating source code files capable of collecting data stored on users' browsers, such as login cookies, saved passwords, autofill data, and other sensitive information.
The completed code will automatically scan the browser's data storage directories, then package the collected data into files and send them to the server specified by the object.
In July 2024, through the social network Telegram, X became acquainted with Le Thanh Cong (born in 1998), residing in Ha Tinh province.
Through online conversations, Cong asked X to help develop malware for distribution, with the aim of collecting sensitive information stored on users' computer browsers (mainly cookies and account login information, as these accounts could be sold for money).
After reaching an agreement, X programmed the malicious code files, compressed them into ZIP files, and sent them to Cong for distribution. The data stolen from the victims' computers would then be automatically sent to Telegram bot systems set up and managed by the perpetrators.
After a period of collaboration that proved ineffective, Le Thanh Cong introduced NVX to Phan Xuan Anh (born in 2005, residing in Nghe An province, using the Telegram account "Mr Bean") so that the two could continue their cooperation in developing and distributing malware.
After contacting NVX, Phan Xuan Anh proposed programming a new type of malware called "PXA Stealers" with the function of stealing information from computers and gaining administrative control of the victim's computer. The two parties agreed that X would receive 15% of the total profit obtained from exploiting the stolen data.
From August 2024 until his arrest, X repeatedly assisted Phan Xuan Anh in creating different versions of the "PXA Stealers" malware to distribute to users both domestically and internationally; he also regularly updated and modified the malware's source code to bypass operating system protection layers.
To further expand their operations, around November 2024, Phan Xuan Anh introduced Nguyen Thanh Truong (using the Telegram account “Adonis”) to X.
Through an introduction, Truong contacted, exchanged information with, and "ordered" X to build a malware program called "Adonis" (abbreviated as AND) for $500, with the same features as the "PXA Stealers" malware.
The unified school agreed to the profits from the collected data mining with X, giving him 50-100 USDT each time money was earned from data mining. After creating the malware, X transferred it to the school for use in illegal activities.
To spread malware on a large scale, perpetrators use personal computers in combination with mass email sending software to distribute emails containing malicious files. These emails are sent to numerous email addresses of internet users in different countries around the world.
According to investigators, more than 94,000 user computers in various countries around the world have been infected with malware distributed by this group.
Using the stolen data, the perpetrators primarily exploited social media accounts, especially accounts with advertising capabilities.
Initially, investigators determined that the individuals in the network had illegally profited tens of billions of VND from programming and modifying malware.
The Security Investigation Agency of the Thanh Hoa Provincial Police has initiated a criminal case and indicted 12 defendants on charges of "Producing, buying, selling, exchanging, or giving away tools, computers, or software for illegal purposes" as stipulated in Article 285 of the Penal Code and "Illegally accessing the computer network, telecommunications network, or electronic devices of others" as stipulated in Article 289 of the Penal Code.
The case is still under expanded investigation to clarify the role of each individual in the network and to strictly prosecute them according to the law.
Source:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
