⤷ Title: Operation Hanoi Thief: Hackers Use ‘Pseudo-Polyglot’ LNK/Image to Deploy LOTUSHARVEST Stealer via DLL Sideloading
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:42:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DLL Sideloading #information stealer #LNK Exploit #LOTUSHARVEST #Operation Hanoi Thief #Pseudo_Polyglot #Recruitment Scam #Vietnam
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:42:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DLL Sideloading #information stealer #LNK Exploit #LOTUSHARVEST #Operation Hanoi Thief #Pseudo_Polyglot #Recruitment Scam #Vietnam
Daily CyberSecurity
Operation Hanoi Thief: Hackers Use 'Pseudo-Polyglot' LNK/Image to Deploy LOTUSHARVEST Stealer via DLL Sideloading
Operation Hanoi Thief targets Vietnam with a pseudo-polyglot LNK/image file that executes malicious code via ftp.exe. The attack deploys LOTUSHARVEST stealer via DLL sideloading to steal Chrome/Edge credentials.