Threat reportAPTTL-2026-0476
Operation GriefLure — China-Nexus APT Spear-Phishing Targeting Viettel (Vietnam Military Telecom) and St. Luke's Medical Center (Philippines) with ftp.exe LotL Loader and Time-Based Polymorphic Payload Assembly
Operation GriefLure (TL-2026-0476), also tracked as Operation GriefLure, is a high-severity advanced persistent threat campaign, first published 2026-05-07 and last reviewed 2026-08-17. It is attributed to GriefLure Cluster (China) with medium confidence, affects Microsoft Windows, maps to 40 MITRE ATT&CK techniques (T1005, T1020, T1027), and is covered by 9 detection rules and 25 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 40MITRE ATT&CK
- Actors
- 1GriefLure Cluster
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 25Indicators of compromise
Key facts for TL-2026-0476
- Threat ID
- TL-2026-0476
- Also known as
- Operation GriefLure, GriefLure
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- GriefLure Cluster
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- telecommunications, government, defense, healthcare, law-enforcement, consumer-electronics
- Target regions
- Vietnam, Philippines, Southeast Asia
- Detection rules
- 9
- Indicators of compromise
- 25
- Updates
- 2026-08-17
Malware and tooling in Operation GriefLure
Malware and tooling: GriefLure custom HTTPS C2 (WinHTTP, XOR-0xBB), TightVNC tvnserver.exe (-controlapp -connect)
How Operation GriefLure works
Operation GriefLure is an active China-nexus APT spear-phishing campaign uncovered by Seqrite Labs in May 2026 that targets senior executives of Viettel Group (Vietnam's largest telecom under the Ministry of National Defence), Thanh Hoa Provincial Cyber Crime Police investigators, and St. Luke's Medical Center (SLMC) Quezon and Global City branches in the Philippines. The campaign delivers a Windows LNK file inside a nested double-compressed RAR/ZIP, abuses the native Windows ftp.exe binary as a Living-off-the-Land loader, and uses a time-based polymorphic payload assembly mechanism that builds sfsvc.exe (a custom regsvr32 reimplementation) and the 360.dll multi-stage shellcode loader from chunked .doc files at runtime — completing full compromise in under 10 seconds while the victim reads an authentic decoy PDF. C2 traffic terminates at whatsappcenter[.]com / 38.54.122.188 hosted on KAOPU-HK bulletproof infrastructure (AS138915).
Operation GriefLure is a targeted, low-volume spear-phishing operation attributed with moderate-to-high confidence to a China-nexus threat cluster. Seqrite Labs disclosed the campaign in May 2026 after observing two distinct intrusion sets: Campaign 1 against Viettel Group senior executives and Thanh Hoa Provincial Cyber Crime Police investigators in Vietnam, and Campaign 2 against St. Luke's Medical Center (SLMC) Quezon and Global City senior leadership in the Philippines. A third lure variant masqueraded as an iPad Pro confidential display specification — likely intended for a supply-chain-of-trust target in the consumer electronics vertical. In all three lure families the attacker leveraged authentic, presumably stolen, legal and identification documents (Vietnamese police evidence files, a Philippine National ID for a real individual, an SLMC whistleblower report) as decoy PDFs to maximise victim engagement.
Campaign 1 arrives as 'Ho so.rar' — a nested double-compressed RAR archive whose outer payload contains an inner RAR labelled in Vietnamese (HO SO BANG CHUNG ... TAP DOAN VIETTEL.rar). The terminal payload is a Windows LNK shortcut whose icon, name and Unicode characters mimic a PDF document. Campaign 2 uses the same nested-archive technique but switches the outer container to a ZIP ('download.zip') and the LNK targets — 'Whistleblowing_Report_SLMC_Fraud_and_Misconduct_2026.pdf.lnk' and 'Valid_Government_Identification_Card_of_Dela_Cruz_Juan_-_Philippine_National_ID_Front_Side.png.lnk'. When the victim double-clicks the LNK, the embedded command line invokes the native Windows file-transfer client ftp.exe with the -s switch, instructing it to execute a script hidden in the same directory. This abuse of ftp.exe as a script interpreter is a Living-off-the-Land Binary (LOLBin) technique that bypasses application-control policies which trust signed Microsoft binaries, and produces a process tree that is benign-looking on most EDRs (explorer.exe -> ftp.exe -> cmd.exe).
The ftp.exe script triggers a batch file that performs the campaign's signature innovation: time-based polymorphic payload assembly. The dropper splits two payloads — sfsvc.exe (a 162 KB custom regsvr32 reimplementation) and 360.dll (a multi-stage shellcode loader / RAT) — into ten chunked .doc files (header.doc, WindowsSecurity.doc, 0.doc through 9.doc). At runtime the batch script reads %TIME:~4,1% to select a single character from the current system time as an index, then assembles the binaries with 'copy /b header.doc + WindowsSecurity.doc + N.doc sfsvc.exe' and a parallel sequence for 360.dll. To further frustrate signature matching, %RANDOM% bytes are appended to the body of 360.dll on each execution, producing a unique SHA256 every time the loader is built. The fully assembled sfsvc.exe is then invoked as 'sfsvc.exe /calldll 360.dll DllRegisterServer', mirroring how regsvr32.exe loads COM servers but executed via an attacker-controlled binary that is not subject to native Microsoft signature verification.
Inside 360.dll, DllRegisterServer allocates RWX memory via VirtualAlloc, walks the import table dynamically with LoadLibraryW + GetProcAddress, and decrypts the embedded shellcode with a static XOR key 0xBB. A secondary XOR key 0x88 protects an Alternate Data Stream dropper component. The shellcode injects into a freshly spawned explorer.exe child process using a classic CreateRemoteThread / WriteProcessMemory / VirtualAllocEx primitive, and a parallel APC injection branch uses QueueUserAPC against suspended threads to defeat behavioural detection that watches only CreateRemoteThread. After injection, the implant duplicates the explorer token, restarts the parent at low integrity (SID S-1-16-4096) to evade UAC-anchored EDR sensors, and writes a persistence component to the NTFS Alternate Data Stream 'C:\Users\Public\Update:2.dll' so the file is invisible to standard directory listings.
The implant exposes a full-featured RAT capability set: process enumeration and system profiling, screen capture via BitBlt/StretchBlt to BMP, recursive directory listings with file metadata exfiltration, chunked file upload, remote command execution, and an embedded TightVNC deployment routine that drops tvnserver.exe and invokes -controlapp -connect to give the operator GUI access. Credential theft modules target Chrome (Login Data, Cookies, History, Local State for v80+ DPAPI key extraction), FileZilla, PL/SQL Developer, the Sunlogin and ToDesk remote-access clients, Xshell .xsh session files, and WeChat document directories. Before any payload activity the implant enumerates running security software against a hard-coded list weighted toward the Chinese AV market — 360Safe, Qianxin, Sangfor — alongside Western EDRs (Defender, Kaspersky, ESET, Bitdefender, Avast, Avira, Sophos, McAfee, SentinelOne, CrowdStrike), an indicator that combined with WeChat targeting and KAOPU-HK bulletproof hosting strongly supports the China-nexus attribution.
Command-and-control traffic is HTTPS via WinHTTP to whatsappcenter[.]com (38.54.122.188), an autoshell-tagged bulletproof asset on AS138915 (KAOPU-HK Kaopu Cloud HK Limited), which has been previously associated with Chinese APT and gambling-affiliate infrastructure. Defenders should treat any DNS resolution to whatsappcenter[.]com or beacon to 38.54.122.188 as confirmed compromise. Mitigations centre on three controls: (1) block ftp.exe outbound and / or alert on ftp.exe -s invocations from non-IT user contexts via Sysmon Event ID 1; (2) restrict execution of sfsvc.exe (which is not a legitimate Microsoft binary outside of Symantec / NextLabs deployments, where the path is well known); (3) hunt for the LNK-spawning-cmd-with-copy-/b-source-of-doc-files behavioural pattern in EDR telemetry. Users who interact with foreign legal correspondence or international whistleblowing reports should be moved to enhanced phishing simulation cadence.
MITRE ATT&CK techniques used in TL-2026-0476
Collection
T1005 Data from Local System; T1113 Screen Capture; T1560 Archive Collected Data
Exfiltration
T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel
Defense Evasion
T1027 Obfuscated Files or Information; T1027.014 Obfuscated Files or Information: Polymorphic Code; T1036 Masquerading; T1055.001 Process Injection: Dynamic-link Library Injection; T1055.004 Process Injection: Asynchronous Procedure Call; T1070.006 Indicator Removal: Timestomp; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1564.004 NTFS File Attributes; T1574.001 DLL
Discovery
T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518.001 Software Discovery: Security Software Discovery
Privilege Escalation
T1055 Process Injection; T1134.002 Access Token Manipulation: Create Process with Token
Execution
T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1106 Native API; T1129 Shared Modules; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1573 Encrypted Channel; T1573.001 Encrypted Channel: Symmetric Cryptography
Credential Access
T1539 Steal Web Session Cookie; T1552.001 Unsecured Credentials: Credentials In Files; T1555.003 Credentials from Password Stores: Credentials from Web Browsers
Persistence
T1547 Boot or Logon Autostart Execution
Initial Access
T1566 Phishing; T1566.001 Phishing: Spearphishing Attachment
stealth
T1574.007 Hijack Execution Flow: Path Interception by PATH Environment Variable
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.004 Acquire Infrastructure: Server
Affected products and versions in Operation GriefLure
- Microsoft — Windows
Vulnerable versions: Windows 10; Windows 11; Windows Server 2016; Windows Server 2019; Windows Server 2022
Fixed in: Configuration mitigations only — no patch - Microsoft — ftp.exe (Windows native FTP client)
Vulnerable versions: All shipped versions
Fixed in: Mitigation: AppLocker / WDAC denial of ftp.exe execution - Google — Chrome (credential store)
Vulnerable versions: v80+ DPAPI-protected Login Data and Local State
Fixed in: No patch — implant steals via process token of authenticated user
Remediation for Operation GriefLure
Patches
- No vendor patch — campaign abuses native Windows binaries (ftp.exe) and user execution; defence is configuration- and detection-based
Immediate actions
- Block DNS resolution and HTTPS egress to whatsappcenter[.]com at perimeter and DNS resolver
- Block outbound traffic to 38.54.122.188 (AS138915 KAOPU-HK) at firewall and proxy
- Block all egress to the AS138915 KAOPU-HK address space pending threat-hunt completion
- Hunt EDR telemetry for ftp.exe -s parent-of-cmd.exe events and any explorer.exe -> ftp.exe child relationship
- Sweep endpoints for sfsvc.exe, 360.dll, header.doc, WindowsSecurity.doc and numeric .doc chunks (0.doc - 9.doc)
- Enumerate NTFS Alternate Data Streams under C:\Users\Public\ — specifically Update:2.dll
- Quarantine any host that matches the SHA256 IOCs and force credential rotation for Chrome, FileZilla, Xshell, PL/SQL Developer, Sunlogin, ToDesk, and WeChat-stored secrets
- Run an out-of-band credential rotation for any user who opened the lure (Chrome DPAPI keys cannot be assumed safe)
Workarounds
- Disable ftp.exe via AppLocker / WDAC on all non-IT-admin endpoints
- Disable Windows shell handling of LNK files for files originating from external sources via Mark-of-the-Web enforcement
- Force opening of inbound RAR / ZIP archives in a sandbox / detonation gateway before delivery to mailbox
Longer-term hardening
- Deploy AppLocker / WDAC rules that deny ftp.exe execution for all standard-user contexts
- Implement Sysmon ruleset that alerts on ftp.exe with -s argument, on copy /b operations chaining .doc files into .exe targets, and on LNK files spawning cmd.exe
- Enable Attack Surface Reduction (ASR) rule 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' and 'Block Win32 API calls from Office macros'
- Deploy EDR with behavioural detection for token duplication, low-integrity-level process re-launch, and CreateRemoteThread into explorer.exe
- Block double-archive attachments (RAR-in-RAR, ZIP-in-ZIP, RAR-in-ZIP) at email gateway
- Strip or rewrite LNK files in inbound mail attachments at the SEG
- Implement DNS sinkhole / RPZ feed that captures KAOPU-HK and known bulletproof hosting ASNs
- Educate executives and HR on supply-chain-of-trust phishing using authentic-looking legal documents
Weaknesses (CWE) in Operation GriefLure
Timeline of Operation GriefLure
- First passive-DNS observation of whatsappcenter[.]com resolving to 38.54.122.188 on AS138915 (KAOPU-HK Kaopu Cloud HK Limited), consistent with infrastructure staging for the campaign.
- Earliest known build timestamp embedded in the Vietnamese-language Viettel evidence LNK (35af2cf5494181920b8624c7b719d39590e2a5ff5eaa1a2fa1ba86b2b5aa9b43), suggesting the Vietnam-targeted intrusion set was tooled up first.
- Spear-phishing distribution to Viettel Group senior executives and Thanh Hoa Provincial Cyber Crime Police investigators commences via Ho so.rar nested archive.
- Campaign 2 begins distribution to St. Luke's Medical Center (SLMC) Quezon and Global City senior leadership via download.zip nested archive carrying SLMC whistleblower and Philippine National ID lures.
- Third lure variant — iPad_Pro_Display_Spec_Final_CONFIDENTIAL.docx.lnk (f34f550147c2792c1ff2a003d15be89e5573f0896c5aa6126068baa4621ef416) — surfaces in Seqrite telemetry, suggesting a consumer-electronics supply-chain target.
- Seqrite Labs first detects the campaign via signatures Lnk.Trojan.50682.GC, Script.Trojan.50683.GC and Trojan.Win32CiR; analysts begin reverse-engineering the time-based polymorphic loader.
- Seqrite Labs publishes 'Operation GriefLure: Dissecting an APT Campaign Targeting Vietnam's Military Telecom & Philippine Healthcare' on the Seqrite blog with full IOCs, MITRE mapping and reverse-engineering.
- Threadlinqs Intelligence opens TL-2026-0476 — full threat record, detection coverage and attack-emulation simulations published for defender consumption.
- As of 2026-05-29, Operation GriefLure remains ACTIVE: Seqrite disclosed this China-nexus ftp.exe-LotL spear-phishing campaign against Viettel and St. Luke's only on May 1, 2026, with no reported takedown, sinkhole, or arrest, and the whatsappcenter[.]com/KAOPU-HK C2 still live. It has no CVE/patch (abuses native Windows binaries), so the LOLBin and polymorphic-loader tradecraft stays viable.
Update history for TL-2026-0476
- 2026-08-17 — tweetfeed.live community intel: New TL_OSINT_Scan community intel: 4 newly-corroborated indicator(s).
Sources cited for Operation GriefLure
- Operation GriefLure: Dissecting an APT Campaign Targeting Vietnam's Military Telecom & Philippine Healthcare
- MITRE ATT&CK T1218 — System Binary Proxy Execution
- MITRE ATT&CK T1027.014 — Polymorphic Code
- LOLBAS Project — ftp.exe
- MITRE ATT&CK T1564.004 — Hide Artifacts: NTFS File Attributes (ADS)
- MITRE ATT&CK T1574.002 — Hijack Execution Flow: DLL Side-Loading
- MITRE ATT&CK T1566.001 — Spearphishing Attachment
- Seqrite Detection Names — Lnk.Trojan.50682.GC, Script.Trojan.50683.GC, Trojan.Win32CiR
Detection coverage for TL-2026-0476
As of 2026-08-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0476 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.