The two malware variants mentioned are the RedHook spyware, which directly targets mobile devices using the Android operating system, and the StormEncryptor ransomware, which targets entire server (Windows Server) and client (Windows Client) systems within the internal networks of agencies, organizations, and businesses.
RedHook can silently take control of your phone.
Regarding details these two types of malware, the Hanoi City Police stated that RedHook is a particularly dangerous new generation of spyware/Trojan malware, discovered in early August 2026.
Malware is primarily spread through fake SMS messages, OTT messaging applications (Zalo, Telegram, etc.), or websites impersonating the National Public Service Portal, the Hanoi City Public Service Portal, the eTax Mobile tax application, the VNeID electronic identification application, and major commercial banks.
As soon as the user downloads and installs the malicious .APK file, the malware uses interface phishing tricks to request "Accessibility Services" permission. Once granted, RedHook gains complete control over the user interface without needing to root the device.
Starting with initial access, the malware automatically performs stealthy touch operations to grant all other dangerous permissions such as: reading/sending SMS, contacts, call logs, storage, recording audio, overwriting the screen with drawings, etc.
More dangerously, this malware can silently record the screen, capture keyboard input (keylogging), and secretly read messages containing OTP verification codes, bank account passwords, and sensitive personal information.
In some cases, RedHook automatically activates the victim's own banking app on their phone, initiates money transfers, automatically fills in the OTP code, and approves transactions without the victim's knowledge.
In addition, the malware can automatically reactivate all malicious processes even after the user restarts their phone.
StormEncryptor can gain supreme administrative privileges within an organization's or business's internal network.
Meanwhile, the StormEncryptor ransomware (discovered on August 11, 2026), deployed by the professional hacking group Storm-1175, targeted entire server and workstation systems within the internal networks of agencies, organizations, and businesses.
According to the warning, the hacker group behind this malware could exploit the particularly critical security vulnerability CVE-2026-18577 on the N-able N-central remote monitoring and administration platform to gain supreme administrative control of the centralized management center.
From the compromised N-central server, hackers used the system's automatic software deployment feature to push the StormEncryptor ransomware to numerous workstations and servers within the internal network in a short period of time.
Through this malware, the hacker group can disable security/backup services, delete backup copies (Shadow Copies), encrypt entire data files using a strong encryption algorithm, and leave a ransom message. Simultaneously, they can extract and steal sensitive data before encryption to threaten its release.
Emergency response upon detection of malware incidents.
According to the Hanoi City Police, signs that a mobile device may have been infected with malware include: the appearance of strange applications, screens jumping around, unwarranted loss of money, unusual overheating when not in use, screens performing actions on their own, or the appearance of "Wireless Debugging" notifications.
When encountering these symptoms, users must strictly follow the emergency network isolation procedure, and not enter any additional passwords/OTPs. Simultaneously, they should quickly turn off Wi-Fi, 3G/4G/5G (for mobile devices), or disconnect network cables/VLANs (for computers/servers); absolutely do not restart the server without backing up the RAM.
At the same time, use a clean device to change your password and PIN, and immediately your bank to freeze your account and block your card urgently.
To promptly prevent, deter, and respond to cybersecurity threats, the Hanoi City Police recommend that users absolutely refrain from clicking on suspicious links sent via email, SMS, Zalo, and other OTT applications.
Do not download or install applications from unknown sources (especially .APK files on Android phones); do not open or extract strange attachments.
Users should only install apps from official app stores (Google Play Store, Apple App Store) and carefully check app permissions before approving them.
According to Nhan Dan newspaper
Source:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
