Skip to main content
Official Seqrite Distributor in Thailand
Threat researchOriginally published 7 May 2026 · Seqrite Labs

Operation GriefLure: a Southeast Asian espionage campaign that uses real documents as bait

Seqrite Labs found a campaign against a Vietnamese telecom and a Philippine hospital that installs its implant in under ten seconds with nothing visible.

Seqrite Labs describes two targeted phishing waves in the region: one at executives of a major Vietnamese telecom operator, the other at a private hospital in the Philippines. Both deliver a shortcut file inside a double-compressed RAR.

The GriefLure attack chain (image: Seqrite Labs)
The GriefLure attack chain (image: Seqrite Labs)

The worrying part is the bait. The Vietnamese wave reused eight genuine documents from a publicised data-breach dispute; the Philippine one used a fabricated fraud complaint. While the victim reads a convincing PDF, the implant is assembled and installed in under ten seconds.

The result is a remote-access trojan that runs in memory, takes screenshots, lists files and processes, and checks which security product is installed. Seqrite attributes it, with moderate-to-high confidence, to a China-nexus cluster.

What a business should do

  • A lure can be entirely real — don't trust an attachment because its content checks out.
  • *.pdf.lnk files inside archives are a red flag.
  • Confirm legal, complaint or urgent emails with the sender through another channel.
  • Keep endpoint protection running — this malware specifically checks for it.

More news

Evaluate it in your own organisation

30 days, no cost, no commitment. We'll send a trial licence and install steps to the email you give us.

Or call 090-295-5556 · LINE @528gkanm