Malware and how it spreads on Zalo

Quang Tri provincial police recently discovered a campaign spreading dangerous malware by impersonating state agency documents on the Zalo social network.

  • Target and harm: these files contain dangerous malware capable of stealing users’ personal information and bank accounts. When a user downloads and opens the files, the computer is infected with the Valley RAT malware.
  • Valley RAT is a targeted attack malware that lets attackers control the victim’s system remotely. The command-and-control (C2) address is identified as 27.124.9.13:5689.
  • Scam file names: the malware files usually have a .exe extension and use familiar, misleading names to trick users into opening them.
    • High-risk examples include: “DRAFT CONGRESS RESOLUTION.exe”, “OFFICIAL LETTER ON PARTY ACTIVITY EVALUATION.exe”.
    • Other files identified as high-risk: “FINANCIAL REPORT 2.exe”, “URGENT GOVERNMENT OFFICIAL LETTER.exe”, “TAX DECLARATION SUPPORT.exe”, “POWER OF ATTORNEY TEMPLATE.exe”, “Q3 REPORT MINUTES.exe”, and “BUSINESS INSURANCE PAYMENT.exe”.

Advice and preventive measures

Quang Tri provincial police advise agencies, organisations and users to be more vigilant to avoid infection.

For users and agencies/organisations:

  1. Be more vigilant and absolutely do not open unknown files.
  2. Scan the entire information system using up-to-date security software.
  3. Immediately disconnect from the internet if the system shows signs of malware infection.

For IT administrators:

  1. Proactively scan the system with security software.
  2. Monitor and block access to IP address 27.124.9.13.

Quang Tri provincial police have tasked the Cybersecurity and High-Tech Crime Prevention Division with compiling the results and reporting to the provincial police leadership, and have asked agencies and organisations to cooperate closely to prevent the malware from spreading widely.

Contact Me on Zalo
0945886818