Skip to content
Warning: Some malware strains are particularly dangerous.

Warning: Some malware strains are particularly dangerous.

Vietnam.Vn August 27, 2026

In fulfilling its function and nhiệm vụ of managing state affairs regarding cybersecurity in the city, the Hanoi City Police have recently discovered the emergence of several particularly dangerous malware strains being exploited by hacker groups to directly attack the information systems of agencies and units, as well as the mobile devices of officials, civil servants, and employees in the area, posing a potential risk to cybersecurity and information security of agencies and units.

1. Information particularly dangerous malware strains

1.1. RedHook spyware strain (Discovered in early August 2026):

This is a particularly dangerous new generation of spyware/trojan malware that directly targets mobile devices using the Android operating system.

Malware is primarily spread through fake SMS messages, OTT messaging applications (Zalo, Telegram, etc.), or websites impersonating the National Public Service Portal, the Hanoi City Public Service Portal, the eTax Mobile tax application, the VNeID electronic identification application, and major commercial banks. The technical methods used by RedHook are as follows:

Abuse of Accessibility Services: As soon as a user downloads and installs a malicious .APK file, the malware uses interface phishing tricks to request "Accessibility Services" permission.

Once granted permission, RedHook gains ultimate control over the user interface without needing to root the device.

Automatic system permission granting: The malware automatically performs stealthy touch operations to grant all sorts of dangerous permissions (read/send SMS, contacts, call logs, storage, recording, screen overlay drawing).

Data Theft & Real-Time Monitoring: Silently recording the screen, capturing keystrokes (Keylogging), secretly reading messages containing OTP verification codes, bank account passwords, and sensitive personal information.

Automated money transfer: Automatically activates the victim's own banking app on their phone, initiates a money transfer order, automatically fills in the OTP code, and approves the transaction without the victim's knowledge.

Concealment and self-recovery mechanism: Registers for the system restart event (BOOT_COMPLETED), automatically reactivating all malicious processes even if the user restarts the phone.

1.2. StormEncryptor ransomware (Discovered August 11, 2026):

Deployed by the professional hacking group Storm-1175, targeting entire server (Windows Server) and workstation (Windows Client) systems within the internal networks of agencies, organizations, and businesses. The infection and damage caused by StormEncryptor:

Supply chain attack via RMM tool: Hackers exploited the critically serious security vulnerability CVE-2026-18577 on the N-able N-central remote monitoring and management platform to gain supreme administrative control of the centralized management center.

Automated mass malware infection: From a compromised N-central server, hackers used the system's automatic software deployment feature to push the StormEncryptor ransomware to numerous workstations and servers within the internal network in a short period of time.

Double encryption and extortion: Disabling security/backup services, deleting backup copies (Shadow Copies), encrypting all data files using a strong encryption algorithm, and leaving a ransom message.

At the same time, hackers extract and steal sensitive data before encrypting it, threatening to release it.

2. Immediately review and fix the following malware strains:

2.1. Regarding the RedHook malware:

If you detect signs of infection on your mobile device (unusual apps appearing, screens jumping around, unwarranted money loss, unusual overheating when not in use, screens performing actions on their own, or displaying a "Wireless Debugging" message), strictly follow the emergency network isolation procedure, do not enter any additional passwords/OTPs, and use a clean device to call the bank's hotline to immediately block your account.

2.2. Emergency response upon detection of RedHook and StormEncryptor malware incidents:

System isolation: Immediately turn off Wi-Fi, 3G/4G/5G (for mobile devices) or disconnect network/VLAN cables (for computers/servers). Absolutely do not restart the server without backing up the RAM.

System isolation: Use a clean device to change your password and PIN, immediately your bank to freeze your account and block your card urgently.

Sample collection and reporting: Extract logs, .APK files, or encrypted CATP exchange files.

Secure recovery : Reinstall a clean operating system/firmware, patch all security vulnerabilities, and restore data from a secure offline backup (3-2-1 rule).

Hanoi City Police issue warnings on responding to malware.

3. Based on the above situation, in order to strengthen cybersecurity and information security in Hanoi, and to promptly prevent, deter, and respond to cybersecurity threats, the Hanoi City Police Department requests that all officials, civil servants, employees, and workers in Hanoi implement the following:

3.1. Strictly comply with legal regulations on cybersecurity, data security, and the protection of personal data and state secrets.

3.2. Absolutely do not click on strange links sent via Email/SMS/Zalo and OTT applications; do not download or install applications from unknown sources (especially .APK files on Android phones); do not open or extract strange attachments.

3.3. Only install apps from official app stores (Google Play Store, Apple App Store) and carefully check app permissions before approving them.

Source: