CSIDB logo
Incident

Government of Vietnam

Incident posture

Attack window
Jun 2020
Location
Viet Nam
Status
Historical
CIA posture
Available to members
Updated
2025-10-30 00:00

Linked entities

Victim
Government of Vietnam
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jun 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A China-linked cyber-espionage group known as Cycldek conducted a sophisticated campaign targeting Vietnamese government and military entities, along with organizations in health, diplomacy, education, and political sectors. The attackers employed DLL side-loading techniques to deploy malicious payloads, including the FoundCore remote access Trojan, which enabled full system control, file manipulation, command execution, and screenshot capture. Additional malware like DropPhone and CoreLoader were used in the attacks, which established persistence, hid malicious processes, and connected to command-and-control infrastructure. Dozens of organizations were compromised, predominantly within Vietnam, with occasional targets in Central Asia and Thailand. The operation demonstrated increased technical evolution compared to the group's earlier activities.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

China-linked cyber-espionage group Cycldek, also known as Goblin Panda and Conimes, conducted a campaign targeting Vietnamese government and military entities between June 2020 and January 2021. The group, active since at least 2013, had historically focused on Southeast Asian governments but demonstrated increasing technical sophistication in this operation. Attackers employed an infection chain leveraging DLL side-loading to deliver malicious payloads, ultimately deploying the FoundCore remote access Trojan (RAT) on compromised systems. During an attack against a high-profile Vietnamese organization, threat actors abused a legitimate Microsoft Outlook component to load a malicious DLL. This DLL executed shellcode acting as a loader for FoundCore, which established persistence through multiple coordinated processes: one creating a service for persistence, another hiding that service, a third blocking access to malicious files, and a fourth connecting to command-and-control infrastructure.

The FoundCore RAT provided attackers with comprehensive control over infected machines, enabling file system manipulation, process execution, arbitrary command execution, and screenshot capture capabilities. Additional malware families including DropPhone and CoreLoader were deployed alongside FoundCore during the campaign. Kaspersky telemetry indicated dozens of affected organizations, with approximately 80% located in Vietnam across government, military, health, diplomatic, educational, and political sectors. Secondary targets included entities in Central Asia and Thailand. The incident represented a continuation of Cycldek's focus on Vietnamese targets following earlier campaigns, including a 2019 operation where the group deployed custom malware to breach air-gapped systems. No specific remediation actions or victim responses were detailed in available reporting.

Sources

Sources available to members: 1 source.

CSIDB