216.73.216.233

Rebex-based Telegram RAT Targeting Vietnam

· Published 29/04/2026 09:42 · Modified 29/04/2026 10:14

Export JSON

Essential information

Published
29/04/2026 09:42
Modified
29/04/2026 10:14
Tags
2026-04-29 chm infection multi-stage payload python loader rebex library shell hijacking telegram rat vietnam targeting xor encryption
Related entities
5 observables, 18 techniques (mitre)

Description

A sophisticated CHM-based malware campaign has been identified targeting Vietnamese victims through a trojanized CV document. The infection chain utilizes a compiled HTML file that deploys a delivery mechanism involving Python interpreters, C++ DLLs, and layered . The malware establishes persistence through and scheduled tasks, ultimately delivering a weaponized version of Rebex.Common.dll functioning as a Telegram-based remote access trojan. The RAT communicates via Telegram bot API, supporting commands for file download, token swapping, and arbitrary command execution. The infection demonstrates characteristics typical of targeted state-sponsored activity rather than opportunistic cybercrime, employing techniques historically associated with advanced threat actors operating in the Southeast Asian region.

External references