A highly sophisticated spearphishing campaign dubbed “Operation GriefLure.” The attackers targeted senior executives at Viettel Group, Vietnam’s largest telecommunications provider, and St. Luke’s Medical Center in the Philippines.
What makes this campaign uniquely devastating is its use of perfectly authentic, legally sensitive documents as decoys.
Instead of forging files, the threat actors harvested real legal disputes from social media, weaponizing a genuine data breach victim’s distress to create a lure that easily bypasses basic security awareness training.
For the Philippine target, the attackers crafted a highly convincing whistleblower complaint alleging financial fraud to trigger immediate action from hospital administrators.
Modular RAT Steals Credentials
The attack begins when victims download a double-compressed RAR or ZIP archive containing a malicious Windows shortcut (LNK) file disguised alongside the decoy PDFs.
Once executed, the LNK file uses a Living-off-the-Land (LotL) technique by abusing the native Windows ftp.exe binary.
This stealthy approach allows the malware to bypass conventional endpoint detection by silently assembling a payload from disguised document fragments in the background.

The entire compromise happens invisibly in under ten seconds, all while the victim views the legitimate decoy document.
At the core of this operation is a custom execution framework, sfsvc.exe, which is a heavily modified version of the legitimate Windows registration tool.

This framework loads a polymorphic loader called 360.dll. Through fileless execution and process injection, the malware forcibly terminates and replaces the Windows Explorer process, injecting its malicious shellcode into a trusted system environment.
Once active, the modular Remote Access Trojan (RAT) deploys a wide array of surveillance capabilities.

It systematically captures screenshots of the victim’s desktop, dynamically adjusting image resolution based on network conditions, and exfiltrates them to a remote server.
Furthermore, the malware includes a highly targeted credential-harvesting module.
It scours the infected system for sensitive data stored in web browsers like Chrome, FTP clients like FileZilla, remote access tools like Sunlogin, and communication applications such as WeChat.
According to Seqrite research, security researchers assess with moderate-to-high confidence that Operation GriefLure is the work of a China-nexus threat cluster.
This attribution is supported by several technical artifacts, including the use of Hong Kong-based bulletproof hosting, specifically Kaopu Cloud, which has a documented history of supporting Asia-Pacific threat actors.
Indicators of Compromise
| File Name / Type | Indicator (SHA256 / Domain) |
|---|---|
HỒ SƠ BẰNG CHỨNG GHI NHẬN CHUỖI HÀNH VI VI PHẠM PHÁP LUẬT CÓ HỆ THỐNG VÀ LEO THANG CỦA TẬP ĐOÀN VIETTEL.lnk | 35af2cf5494181920b8624c7b719d39590e2a5ff5eaa1a2fa1ba86b2b5aa9b43 |
Whistleblowing_Report_SLMC_Fraud_and_Misconduct_2026.pdf.lnk | bc090d75f51c293d916c40d4b21094faaec191a42d97448c92d264875bf1f17b |
Valid_Government_Identification_Card_of_Dela_Cruz_Juan_-_Philippine_National_ID_Front_Side.png.lnk | 197f11a7b0003aa7da58a3302cfa2a96a670de91d39ddebc7a51ac1d9404a7e6 |
iPad_Pro_Display_Spec_Final_CONFIDENTIAL.docx.lnk | f34f550147c2792c1ff2a003d15be89e5573f0896c5aa6126068baa4621ef416 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.