Ref2754

Threat Actor updated 6 months ago (2024-05-04T20:24:05.742Z)
Download STIX
Preview STIX
REF2754 is a cybersecurity threat actor that has been linked with malicious activities targeting primarily Vietnamese entities. This group shares tactical similarities with another threat group referred to as REF4322, which is known for deploying a post-exploitation implant called PHOREAL (also known as Rizzo). The overlap in tactics suggests that these two groups may be coordinating their attacks or even operating under the same umbrella organization. The attacks orchestrated by REF2754 have also shown connections with APT32, Canvas Cyclone (formerly Bismuth), Cobalt Kitty, and OceanLotus, all of which are recognized Vietnamese threat groups. This further supports the theory of collaboration or shared operations among these entities. The commonalities between these groups extend beyond just their targets, indicating possible shared resources, strategies, or even leadership. Given the overlapping methodologies and target selection, there is a growing suspicion within the cybersecurity community that both REF4322 and REF2754 represent campaigns planned and executed by a Vietnamese state-affiliated entity. If this is true, it could signal a significant escalation in state-sponsored cyber threats originating from Vietnam. Further investigation is required to confirm these connections and understand the full extent of the threat posed by these actors.
Description last updated: 2023-10-11T01:15:53.702Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Ref2754 Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
a year ago