Seqrite Labs describes two targeted phishing waves in the region: one at executives of a major Vietnamese telecom operator, the other at a private hospital in the Philippines. Both deliver a shortcut file inside a double-compressed RAR.

The worrying part is the bait. The Vietnamese wave reused eight genuine documents from a publicised data-breach dispute; the Philippine one used a fabricated fraud complaint. While the victim reads a convincing PDF, the implant is assembled and installed in under ten seconds.
The result is a remote-access trojan that runs in memory, takes screenshots, lists files and processes, and checks which security product is installed. Seqrite attributes it, with moderate-to-high confidence, to a China-nexus cluster.
What a business should do
- A lure can be entirely real — don't trust an attachment because its content checks out.
- *.pdf.lnk files inside archives are a red flag.
- Confirm legal, complaint or urgent emails with the sender through another channel.
- Keep endpoint protection running — this malware specifically checks for it.



