Skip to content
ThreatCluster

Operation GriefLure: Modular RAT Targets Southeast Asian Executives

First seen 8 May 2026, 19:35 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 9, 2026 at 19:11 UTC

A sophisticated spear-phishing campaign, named Operation GriefLure, has been identified, targeting senior executives in Vietnam and the Philippines. The campaign employs a modular remote access trojan (RAT) capable of stealing credentials and capturing screenshots. High-value organizations such as Viettel Group and St. Luke’s Medical Center are among the affected entities. The attackers are executing simultaneous operations against Vietnam’s military-linked telecom sector and the Philippine healthcare industry. This campaign highlights a calculated approach to cyber-espionage in the region. The specific tools and techniques used in the attacks have not been disclosed. Current status indicates ongoing activity with significant implications for targeted organizations. Security professionals are advised to remain vigilant and implement robust security measures.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 134d ago How this analysis works

Timeline

2026-05-08
Operation GriefLure identified
A sophisticated spear-phishing campaign targeting executives in Southeast Asia was reported, using a modular RAT.
Gbhackers
2026-05-08
Simultaneous campaigns launched
The attackers are running two concurrent operations against Vietnam’s telecom sector and the Philippine healthcare industry.
Cybersecuritynews

More articles in this cluster (2)

Following this threat?

Track St. Luke’s Medical Center in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed