Facebook advertisers in Vietnam have been targeted by an information stealer called VietCredCare since August 2022.

“The malware stands out for its ability to automatically detect stolen Facebook cookies and credentials from compromised devices, while checking whether these accounts manage company profiles and maintain a positive credit balance for Meta,” Singapore-based firm Group-IB says, according to a new report published on The Hacker News.
Read more: Ukrainian administrator of Raccoon Infostealer Malware arrested
The ultimate goal of the – large-scale – malware distribution system is to facilitate the acquisition of corporate Facebook accounts, targeting Vietnamese profile administrators of leading companies and organizations on the internet.
Successfully seized Facebook accounts are used by hackers behind businesses to post political content or to spread phishing and scams for financial gain.
VietCredCare is offered to aspiring cybercriminals using the service and is advertised on Facebook, YouTube, and Telegram. It is allegedly run by Vietnamese-speaking individuals.
Customers have the option to purchase access to a botnet run by the malware’s creators, or to obtain access to the source code for resale or personal use. Additionally, a customized Telegram to manage the extraction and delivery of credentials from an infected device.
The .NET-based malware is spread via links to fake websites via social media posts and instant messaging platforms. It presents itself as legitimate software, such as Microsoft Office or Acrobat Reader, to trick visitors into installing it.
One of its main selling points is its ability to extract credentials, cookies, and session IDs from browsers like Google Chrome, Microsoft Edge, and Cốc Cốc. This indicates its focus on the Vietnamese market.
Read more: Kimsuky: New Troll Stealer threat targets South Korea
Additionally, it can detect the IP , check if the Facebook profile is professional, and assess whether the account is currently running ads. It also takes steps to avoid detection by disabling the Windows Anti-Malware Scanning Interface (AMSI) and adding it to the Windows Defender Antivirus exclusion list.
VietCredCare's core function of filtering Facebook credentials puts organizations, both in the public and private sectors, at risk of reputational and financial damage if their sensitive accounts are compromised, said Vesta Matveeva, head of the high- tech for APAC.
Certificates belonging to public bodies, universities, e-commerce platforms, banks, and Vietnamese companies have been compromised through malware.

VietCredCare is the latest addition to a long list of dangerous theft programs, such as Ducktail and NodeStealer, that originate from the Vietnamese cybercrime ecosystem, aiming to attack Facebook accounts.
See also: North Korean hackers target defense sector
The “stealer-as-a-service” business practice allows hackers with little or no technical skills to invade cyberspace ,resulting in more innocent people being affected, Group-IB said.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews.com
