
Group-IB, a Singapore-headquartered cybersecurity firm, says it has uncovered a large phishing operation aimed at customers of Vietnamese banks and other financial companies. Its incident response team, CERT-GIB, identified 240 interconnected domains impersonating 27 Vietnamese financial institutions and passed the findings to Vietnam's national computer emergency response team, VNCERT. Group-IB says all 240 domains have since been blocked.
The method is the part worth following. Victims were pulled in through messages on SMS, Telegram and WhatsApp, and through comments on the Facebook pages of legitimate financial companies. The fake pages offered a choice of bank logos, then asked for a username and password, and then for a one-time password. Once the victim handed over the code, the operators used the already-stolen credentials to log in to the real account, so the login the victim saw succeed was the fraudsters'.
The number that is missing
Group-IB says it found web counters on 44 of the 240 sites and counted at least 7,800 visitors since the start of 2021. It says the true number of visitors is unknown but believed to be higher. That is the honest limit of the evidence: a blocked domain list is countable, victims are not. The firm also says it has seen offers to sell data on Vietnamese bank-account holders in underground markets, while noting it cannot confirm the data came from this campaign.
The campaign's first domain was registered in May 2019 and its most recent went live on 1 June 2022, days before the release — which is to say the takedown is a snapshot, not an ending. Group-IB says new domains appear regularly by design, kept live only briefly to frustrate detection. The practical advice offered, that urgency in a bank message is a red flag, is sound and also an admission of how little a domain takedown changes.