Skip to main content
Official Seqrite Distributor in Thailand
Threat researchOriginally published 28 November 2025 · Seqrite Labs

Fake CVs that steal passwords: a campaign aimed at HR and IT teams in Vietnam

Operation Hanoi Thief sends a ZIP that looks like a job application — open it and you see a real CV while browser passwords leave in the background.

Seqrite Labs' APT team tracked a campaign against IT departments and recruiters in Vietnam, first seen on 3 November 2025. The ZIP holds a shortcut named CV.pdf.lnk and a file that opens as a genuine-looking PDF résumé but hides a script.

Infection chain, from email to exfiltration (image: Seqrite Labs)
Infection chain, from email to exfiltration (image: Seqrite Labs)

Opening the shortcut shows the CV as expected, while Windows' own ftp.exe runs the hidden script and loads an implant Seqrite calls LOTUSHARVEST. It evades virtual machines, reads recent URLs and saved Chrome and Edge logins, and ships them to throwaway attacker endpoints.

It happened in Vietnam, but it works on any company that recruits by email — HR opens attachments from strangers every day as part of the job.

What a business should do

  • Never open applications that arrive as ZIPs with shortcut files inside.
  • Have applicants upload PDFs through a form rather than email.
  • Show file extensions on every PC so CV.pdf.lnk is visibly not a PDF.
  • Use a password manager and MFA instead of browser-saved passwords.

More news

Evaluate it in your own organisation

30 days, no cost, no commitment. We'll send a trial licence and install steps to the email you give us.

Or call 090-295-5556 · LINE @528gkanm