ThreatCluster
  • Feed
  • Dashboard
  • Saved
THREAT HUNTING
  • Domains
  • IP Addresses
  • File Hashes
  • CVEs
THREAT INTELLIGENCE
  • APT Groups
  • Ransomware Groups
  • Malware Families
  • Attack Types
  • MITRE ATT&CK
  • Security Standards
  • Vulnerability Types
BUSINESS INTELLIGENCE
  • Companies
  • Industry Sectors
  • Security Vendors
  • Government Agencies
  • Countries
  • Platforms
Home / Feed / Article

Cyble Uncovers RedHook Android Trojan Targeting Vietnamese Users

Threat Score:
47
The Cyber Express
7 days ago
Part of cluster #1429

Overview

Cybersecurity researchers at Cyble Research and Intelligence Labs (CRIL) have uncovered a new Android banking trojan called RedHook that is actively targeting Vietnamese mobile users. The malware is distributed via carefully crafted phishing sites impersonating trusted financial and government agencies. Once installed, RedHook delivers a dangerous combination of phishing, keylogging, and remote access capabilities, enabling full control over infected devices, yet it remains low‑profile with limi...

Continue Reading on Original Site

Related Articles

5 articles
1
Stop Reacting; Start Anticipating: The Global State of Threat Intelligence

Stop Reacting; Start Anticipating: The Global State of Threat Intelligence

Brighttalk • 14 hours ago

Presented by Jitin Shabadu, Forrester Analyst | Jayce Nichols, Director, Intelligence Solutions, Google Threat Intelligence Group

Score
83
Read more
2

SonicWall Probes Potential Zero-Day After Ransomware Hits

Data Breach Today UK • 8 hours ago

Akira Ransomware Exploited MFA-Protected SonicWall SSL VPNs, Say Researchers SonicWall said it is probing a surge in attacks against its Gen 7 firewalls, running various firmware versions, which have SSL VPN enabled. Researchers said attackers may have been exploiting a zero-day vulnerability and that multiple victims have been infected with Akira ransomware.

Score
83
Read more
3

Dialysis company DaVita says more than 900,000 people affected by April ransomware attack

Therecord • 12 hours ago

A broad range of personal and health data was exposed in an April ransomware attack on dialysis provider DaVita, the company said in notices filed in several states.

Score
81
Read more
4

More than 1 million patients affected by DaVita ransomware attack; those are preliminary numbers

Databreaches • 10 hours ago

There is an update to the ransomware attack involving DaVita Dialysis first reported in April. According to DaVita’s disclosures this month,  unauthorized access to its servers began on March 24, 2025 and continued until April 12, 2025, when they were able to kick the attacker out and keep them out. The incident was first reported...

Score
78
Read more
5

‘Critical’ firmware-level vulnerabilities found in laptops commonly used by security specialists

Therecord • 12 hours ago

According to the research published Tuesday, it is possible for an attacker to break into the ControlVault chip used in many laptops owned by security professionals and modify the firmware inside.

Score
76
Read more

Save to Folder

Choose a folder to save this article:

Article Intelligence

Key entities and indicators for this article

DOMAINS
api9.iosgaxx423.xyz
mailisa.me
sbvhn.com
skt9.iosgaxx423.xyz
ATTACK TYPES
Credential Theft
Overlay Attack
Phishing
Social Engineering
INDUSTRIES
Banking
Financial Services
COUNTRIES
Portugal
South Korea
Spain
Vietnam
PLATFORMS
AWS
Android
iOS
RANSOMWARE
AnDROid
First
One
Trojan
Unknown
MITRE ATT&CK
Phishing
T1003
T1053
T1059
T1059.001
MALWARE
DoubleTrouble
RedHook
ToxicPanda
SECURITY VENDORS
Kaspersky
VULNERABILITIES
Credential Theft
DOMAINS
mailisa.me
sbvhn.com
api9.iosgaxx423.xyz
skt9.iosgaxx423.xyz
ARTICLE INFORMATION
Article #5320
Published 7 days ago
The Cyber Express

We use cookies

We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.

Cookie Settings

Essential Cookies

Required for the website to function. Cannot be disabled.

  • Session management and authentication
  • Security and fraud prevention
  • Cookie consent preferences

Analytics Cookies

Help us understand how visitors interact with our website.

  • Plausible Analytics - Privacy-focused usage statistics
  • PostHog - Product analytics and feature tracking
  • Page views and user journey analysis

Performance Cookies

Help us monitor and improve website performance.

  • Page load time monitoring
  • Error tracking and debugging
  • Performance optimisation

Marketing Cookies

Used to track visitors across websites for marketing purposes.

  • Conversion tracking
  • Remarketing campaigns
  • Social media integration