Hackers using password-stealing malware are increasing in Southeast Asia

NGUYỄN ĐĂNG |

Password-stealing malware (password stealer) is being increasingly exploited by bad actors to attack organizations in Southeast Asia.

Worrying trend

Remote measurement data from cybersecurity company Kaspersky recorded that the number of password-theft malware attacks targeting business users in Southeast Asia increased by 18% in 2025, reflecting the alarming current situation: bad actors are secretly collecting and exploiting authenticated information to infiltrate the business environment, overcoming all warning barriers without being detected by security systems.

Password-theft malware is a form of malicious software, designed to steal passwords and other account information. This type of malware extracts password decryption keys stored on the browser, analyzes buffer data and browser data storage files, and finds ways to access encrypted user wallet data.

Cybercriminals can use stolen passwords to illegally access accounts for many malicious purposes, such as property appropriation, impersonation, extortion, or using these compromised accounts as springboards for subsequent attacks.

Mr. Adrian Hia, CEO of Kaspersky Asia-Pacific region revealed a worrying figure, after analyzing 193 million compromised passwords, they found that up to 45% of passwords could be cracked in less than a minute, and only 23% of passwords are strong enough to withstand attacks for more than a year.

These figures show that the habit of creating weak passwords and neglecting the creation of authentication information is becoming a loophole, creating conditions for large-scale attacks and intrusions.

Recommendations

To strengthen password policy, users and businesses can apply the following simple measures:

- Use a password manager. Usually, remembering long and unique passwords for all services used is almost impossible. But with a password manager, you only need to remember the main password.

- Use different passwords for each service. Thus, even if one account is stolen, the remaining accounts are still guaranteed to be safe.

- Combine random, unrelated words for the password phrase to increase security. Even when setting passwords with ordinary words and phrases, arrange them in unusual order and make sure they are not related to each other. You can also use online password checking tools to assess the strength of the password.

- Avoid using predictable passwords taken from personal information such as date of birth, relative's name, pet name or your own name. These are usually the first suggestions that attackers will try.

- Turn on two-factor authentication (2FA). Although not directly related to password strength, 2FA adds an important security layer.

- Use reliable security solutions to enhance protection capabilities, through monitoring the Internet and dark web, warning immediately when your password needs to be changed.

- Deploy advanced security solutions, integrate endpoint, cloud protection capabilities and XDR/EDR endpoint detection and response solutions to detect, investigate and respond to complex threats such as spyware, backdoors and ransomware.

- Frequently update software, especially widely used applications such as Microsoft Office, to minimize the risk of vulnerability exploitation attacks.

- Grasp information about threats to equip yourself with knowledge of the latest attack tactics and build corresponding defense scenarios.

NGUYỄN ĐĂNG
RELATED NEWS

Amazon replaces chatbot Rufus with smarter shopping assistant

|

Amazon is expanding the application of artificial intelligence in retail when replacing the chatbot Rufus with the new AI shopping assistant Alexa for Shopping.

Samsung Galaxy Z Fold 8 may be the first device to be updated with Gemini Intelligence

|

Samsung may become the first company to bring Google's new Gemini Intelligence feature series to foldable phones.

A computer infected with malware, an entire business can be ransomed by hackers

|

Cybersecurity experts warn that many people think that using the crack helps save costs, but in reality, they may have to trade it off with all personal data, bank accounts, e-wallets, work emails, or even business computer systems.

Famous Australian candy found to contain foreign objects, Ministry of Health immediately intervenes

|

After Australia urgently recalled a number of Allen's iNSiDE OUTS candies due to the discovery of plastic foreign objects, the Ministry of Health requested a review and suspension of business of this product.

Stock market liquidity unexpectedly drops sharply

|

The stock market still maintained green color but liquidity was quite low with a trading value of less than 14,000 billion VND in the trading session.

Overview of the 692 billion VND road connecting 2 expressways in Phu Tho

|

Phu Tho - The 2.7km longer route connecting Noi Bai - Lao Cai expressway with Tuyen Quang - Phu Tho expressway is in the process of being completed.

Official exam questions and answers for Literature subject of the 10th grade exam in Ho Chi Minh City

|

On the afternoon of June 5, the Ho Chi Minh City Department of Education and Training (GDĐT) announced the official exam questions and answers for Literature in the 10th grade entrance exam for the 2026-2027 school year.

Ministry of Education appoints many directors and principals of directly affiliated universities and colleges

|

The Ministry of Education and Training has completed nearly 95% of the plan to consolidate heads at affiliated educational institutions, with 51/54 units completing the arrangement of leadership personnel.

Amazon replaces chatbot Rufus with smarter shopping assistant

Cát Tiên |

Amazon is expanding the application of artificial intelligence in retail when replacing the chatbot Rufus with the new AI shopping assistant Alexa for Shopping.

Samsung Galaxy Z Fold 8 may be the first device to be updated with Gemini Intelligence

QUANG MINH |

Samsung may become the first company to bring Google's new Gemini Intelligence feature series to foldable phones.

A computer infected with malware, an entire business can be ransomed by hackers

HOÀI ANH |

Cybersecurity experts warn that many people think that using the crack helps save costs, but in reality, they may have to trade it off with all personal data, bank accounts, e-wallets, work emails, or even business computer systems.