Fraud group specializes in finding security holes in Vietnamese banks

Minh Ánh (Theo CyProtek) |

International hackers coordinate to steal assets from bank users through sophisticated tricks. Users need to be more vigilant.

Continuing the series on the GoldFactory campaign, the CyProtek investigative team of the Anti-Fraud project continues to expose an international hacker network of alarming scale and sophistication.

Cybercrime network exposed

Over 277 days of monitoring, the Anti-Fraud team tracked a large-scale cybercriminal network with operations centers in multiple countries, including Cambodia, Myanmar, and China. The campaign not only targeted banking users in Vietnam but also expanded its operations to neighboring regions.

Mot minh chung dien hinh la tuyen bo tu mot nhom hacker Trung Quoc vao ngay 27.12.2024, lien quan den mot ngan hang lon tai Viet Nam. Chung viet (dich tu tieng Trung): “Ai noi ngan hang da duoc nang cap? Du co nang cap den muc nao, chung toi van phai ha no xuong!”. Anh: Cy
Statement from a Chinese hacker group on December 27, 2024 (translated from Chinese): “Who said the bank has been upgraded? No matter how much it is upgraded, we still have to take it down!” Photo: CyProtek

Starting from victim reports, the CyProtek investigation team discovered units that led to hundreds of fake websites designed to distribute malicious applications. During the investigation, the team tracked down more than 64 servers used to control victim devices and conduct unauthorized transactions.

“We found that these servers are located in many different locations, closely linked to hacker groups abroad. This shows that this is a large-scale and organized criminal network,” said Mr. Ngo Minh Hieu, a representative of the group.

Cac ung dung app gia mao, sau khi chiem quyen kiem soat thanh cong, thuong chay ngam trong nen (background) cua dien thoai xuyen suot qua trinh nan nhan su dung thiet bi. Anh:
Fake applications, after successfully taking control, often run in the background of the phone throughout the victim's use of the device. Photo: CyProtek

One notable point is the coordination between domestic and foreign hacker groups. They not only share victims' personal data but also sell attack tools, such as fake apps and malware, through platforms like Telegram and online black markets.

“Cambodian hackers often focus on using fake apps for fraud, while groups in China specialize in developing fake apps and reverse engineering the source code of banking apps to find security vulnerabilities. This helps them optimize their attacks,” the CyProtek team revealed.

Startling numbers from the GoldFactory campaign

More than 421 fake websites were detected.

64 device control servers were traced.

Thousands of bank accounts were hijacked.

Estimated damage up to hundreds of billions of dong.

“Although it is difficult to determine the exact amount of damage, through the cases we investigated, the value of stolen assets is very large,” Mr. Hieu shared.

Con so thu vi: “64” la so may chu ma hacker dang dung de thuc hien hanh vi dieu khien thiet bi dien thoai nan nhan ma nhom Chong lua dao dang giam sat hang ngay. Anh:
Interesting number: “64” is the server number that the hacker is using to control the victim’s phone device, which the investigation team is monitoring daily. Photo: CyProtek.

Challenges in tackling cybercrime

One of the biggest challenges in tackling these scams, the CyProtek team said, is the complexity of the international network. Servers are located overseas, while transactions are often routed through multiple intermediary accounts to cover their tracks.

“Close coordination between domestic and international authorities is needed to completely destroy this network. This is not a simple task,” Mr. Hieu emphasized.

Warning to the community

The CyProtek team calls on the community to raise awareness of cyber threats. Hackers are increasingly sophisticated and dangerous, but if users are vigilant, these tricks can be neutralized.

“We hope that these findings will help people realize the importance of protecting personal information and always be alert to signs of fraud,” the CyProtek team shared.

Operation GoldFactory is a stark reminder of the sophistication and scale of today’s hacker groups. But with the support of the community and authorities, this threat can be completely repelled.

Minh Ánh (Theo CyProtek)
TIN LIÊN QUAN

Fake Vietnamese bank application to scam customers

|

Hackers use fake applications to take control of devices, steal OTP codes and users' assets at the bank.

Wrong password - sophisticated scam targeting bank customers

|

Hackers impersonate bank employees and use the "account locking" trick to steal assets via OTP code.

Deepfake, online fraud is becoming more dangerous

|

Experts warn of the risk of a new wave of security attacks from 2025, as artificial intelligence (AI) makes scams and deepfakes more dangerous.

Lao Dong Newspaper presented 208 gifts to children in flooded areas of Yen Bai

|

During the Gala night celebrating the 4th anniversary of the Northwest Office, Lao Dong Newspaper launched the program "Warm Tet for Children" and donated 208 million VND to Yen Bai province.

Factory fire in residential area in Binh Duong

|

In Di An city, Binh Duong province, a fire broke out in a fabric factory, the fire burned fiercely.

China plans to acquire iconic German car company

|

China targets struggling German carmakers like Volkswagen.

Update on the closing price of gold on January 18: Lost the 87 million VND mark

|

Updated gold price closing session 17.1: All prices decreased. Domestic gold lost the mark of 87 million VND/tael.

Top 10 localities in the number of national excellent student awards

|

With a total of 200 prize-winning candidates, Hanoi is the locality with the most prizes in the national high school competition for excellent students in the 2024-2025 school year.

Fake Vietnamese bank application to scam customers

Minh Ánh (Theo CyProtek) |

Hackers use fake applications to take control of devices, steal OTP codes and users' assets at the bank.

Wrong password - sophisticated scam targeting bank customers

Minh Ánh (Theo CyProtek) |

Hackers impersonate bank employees and use the "account locking" trick to steal assets via OTP code.

Deepfake, online fraud is becoming more dangerous

NGUYỄN ĐĂNG |

Experts warn of the risk of a new wave of security attacks from 2025, as artificial intelligence (AI) makes scams and deepfakes more dangerous.

Cựu nhân viên ngân hàng lừa đảo chiếm đoạt tài sản

BẢO TRUNG |

Đắk Lắk - Với thủ đoạn đưa ra thông tin gian dối là làm hồ sơ đáo hạn ngân hàng, Phạm Kiều Hưng đã vay tiền của nhiều người rồi lừa đảo chiếm đoạt tài sản.