# Operation GriefLure — China-Nexus APT Spear-Phishing Targeting Viettel (Vietnam Military Telecom) and St. Luke's Medical Center (Philippines) with ftp.exe LotL Loader and Time-Based Polymorphic Payload Assembly

> Operation GriefLure is an active China-nexus APT spear-phishing campaign uncovered by Seqrite Labs in May 2026 that targets senior executives of Viettel Group (Vietnam's largest telecom under the Ministry of National Defence), Thanh Hoa Provincial Cyber Crime Police investigators, and St. Luke's Medical Center (SLMC) Quezon and Global City branches in the Philippines. The campaign delivers a Windows LNK file inside a nested double-compressed RAR/ZIP, abuses the native Windows ftp.exe binary as a Living-off-the-Land loader, and uses a time-based polymorphic payload assembly mechanism that builds sfsvc.exe (a custom regsvr32 reimplementation) and the 360.dll multi-stage shellcode loader from chunked .doc files at runtime — completing full compromise in under 10 seconds while the victim reads an authentic decoy PDF. C2 traffic terminates at whatsappcenter[.]com / 38.54.122.188 hosted on KAOPU-HK bulletproof infrastructure (AS138915).

- **Published:** 2026-05-07T12:00:00Z
- **Last reviewed:** 2026-08-17T11:32:28Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0476
- **ID:** TL-2026-0476
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** GriefLure Cluster (China)
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Operation GriefLure is a targeted, low-volume spear-phishing operation attributed with moderate-to-high confidence to a China-nexus threat cluster. Seqrite Labs disclosed the campaign in May 2026 after observing two distinct intrusion sets: Campaign 1 against Viettel Group senior executives and Thanh Hoa Provincial Cyber Crime Police investigators in Vietnam, and Campaign 2 against St. Luke's Medical Center (SLMC) Quezon and Global City senior leadership in the Philippines. A third lure variant masqueraded as an iPad Pro confidential display specification — likely intended for a supply-chain-of-trust target in the consumer electronics vertical. In all three lure families the attacker leveraged authentic, presumably stolen, legal and identification documents (Vietnamese police evidence files, a Philippine National ID for a real individual, an SLMC whistleblower report) as decoy PDFs to maximise victim engagement.

Campaign 1 arrives as 'Ho so.rar' — a nested double-compressed RAR archive whose outer payload contains an inner RAR labelled in Vietnamese (HO SO BANG CHUNG ... TAP DOAN VIETTEL.rar). The terminal payload is a Windows LNK shortcut whose icon, name and Unicode characters mimic a PDF document. Campaign 2 uses the same nested-archive technique but switches the outer container to a ZIP ('download.zip') and the LNK targets — 'Whistleblowing_Report_SLMC_Fraud_and_Misconduct_2026.pdf.lnk' and 'Valid_Government_Identification_Card_of_Dela_Cruz_Juan_-_Philippine_National_ID_Front_Side.png.lnk'. When the victim double-clicks the LNK, the embedded command line invokes the native Windows file-transfer client ftp.exe with the -s switch, instructing it to execute a script hidden in the same directory. This abuse of ftp.exe as a script interpreter is a Living-off-the-Land Binary (LOLBin) technique that bypasses application-control policies which trust signed Microsoft binaries, and produces a process tree that is benign-looking on most EDRs (explorer.exe -> ftp.exe -> cmd.exe).

The ftp.exe script triggers a batch file that performs the campaign's signature innovation: time-based polymorphic payload assembly. The dropper splits two payloads — sfsvc.exe (a 162 KB custom regsvr32 reimplementation) and 360.dll (a multi-stage shellcode loader / RAT) — into ten chunked .doc files (header.doc, WindowsSecurity.doc, 0.doc through 9.doc). At runtime the batch script reads %TIME:~4,1% to select a single character from the current system time as an index, then assembles the binaries with 'copy /b header.doc + WindowsSecurity.doc + N.doc sfsvc.exe' and a parallel sequence for 360.dll. To further frustrate signature matching, %RANDOM% bytes are appended to the body of 360.dll on each execution, producing a unique SHA256 every time the loader is built. The fully assembled sfsvc.exe is then invoked as 'sfsvc.exe /calldll 360.dll DllRegisterServer', mirroring how regsvr32.exe loads COM servers but executed via an attacker-controlled binary that is not subject to native Microsoft signature verification.

Inside 360.dll, DllRegisterServer allocates RWX memory via VirtualAlloc, walks the import table dynamically with LoadLibraryW + GetProcAddress, and decrypts the embedded shellcode with a static XOR key 0xBB. A secondary XOR key 0x88 protects an Alternate Data Stream dropper component. The shellcode injects into a freshly spawned explorer.exe child process using a classic CreateRemoteThread / WriteProcessMemory / VirtualAllocEx primitive, and a parallel APC injection branch uses QueueUserAPC against suspended threads to defeat behavioural detection that watches only CreateRemoteThread. After injection, the implant duplicates the explorer token, restarts the parent at low integrity (SID S-1-16-4096) to evade UAC-anchored EDR sensors, and writes a persistence component to the NTFS Alternate Data Stream 'C:\Users\Public\Update:2.dll' so the file is invisible to standard directory listings.

The implant exposes a full-featured RAT capability set: process enumeration and system profiling, screen capture via BitBlt/StretchBlt to BMP, recursive directory listings with file metadata exfiltration, chunked file upload, remote command execution, and an embedded TightVNC deployment routine that drops tvnserver.exe and invokes -controlapp -connect to give the operator GUI access. Credential theft modules target Chrome (Login Data, Cookies, History, Local State for v80+ DPAPI key extraction), FileZilla, PL/SQL Developer, the Sunlogin and ToDesk remote-access clients, Xshell .xsh session files, and WeChat document directories. Before any payload activity the implant enumerates running security software against a hard-coded list weighted toward the Chinese AV market — 360Safe, Qianxin, Sangfor — alongside Western EDRs (Defender, Kaspersky, ESET, Bitdefender, Avast, Avira, Sophos, McAfee, SentinelOne, CrowdStrike), an indicator that combined with WeChat targeting and KAOPU-HK bulletproof hosting strongly supports the China-nexus attribution.

Command-and-control traffic is HTTPS via WinHTTP to whatsappcenter[.]com (38.54.122.188), an autoshell-tagged bulletproof asset on AS138915 (KAOPU-HK Kaopu Cloud HK Limited), which has been previously associated with Chinese APT and gambling-affiliate infrastructure. Defenders should treat any DNS resolution to whatsappcenter[.]com or beacon to 38.54.122.188 as confirmed compromise. Mitigations centre on three controls: (1) block ftp.exe outbound and / or alert on ftp.exe -s invocations from non-IT user contexts via Sysmon Event ID 1; (2) restrict execution of sfsvc.exe (which is not a legitimate Microsoft binary outside of Symantec / NextLabs deployments, where the path is well known); (3) hunt for the LNK-spawning-cmd-with-copy-/b-source-of-doc-files behavioural pattern in EDR telemetry. Users who interact with foreign legal correspondence or international whistleblowing reports should be moved to enhanced phishing simulation cadence.

## MITRE ATT&CK

- T1566 Phishing
- T1566.001 Phishing: Spearphishing Attachment
- T1204.002 User Execution: Malicious File
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1106 Native API
- T1129 Shared Modules
- T1574.007 Hijack Execution Flow: Path Interception by PATH Environment Variable
- T1547 Boot or Logon Autostart Execution
- T1134.002 Access Token Manipulation: Create Process with Token
- T1055 Process Injection
- T1218 System Binary Proxy Execution
- T1027 Obfuscated Files or Information
- T1027.014 Obfuscated Files or Information: Polymorphic Code
- T1036 Masquerading
- T1055.001 Process Injection: Dynamic-link Library Injection
- T1055.004 Process Injection: Asynchronous Procedure Call
- T1574.001 DLL
- T1564.004 NTFS File Attributes
- T1070.006 Indicator Removal: Timestomp
- T1140 Deobfuscate/Decode Files or Information
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1552.001 Unsecured Credentials: Credentials In Files
- T1539 Steal Web Session Cookie
- T1057 Process Discovery
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1518.001 Software Discovery: Security Software Discovery
- T1033 System Owner/User Discovery
- T1113 Screen Capture
- T1005 Data from Local System
- T1560 Archive Collected Data
- T1071.001 Application Layer Protocol: Web Protocols
- T1573 Encrypted Channel
- T1573.001 Encrypted Channel: Symmetric Cryptography
- T1105 Ingress Tool Transfer
- T1219 Remote Access Tools
- T1041 Exfiltration Over C2 Channel
- T1020 Automated Exfiltration
- T1583.001 Acquire Infrastructure: Domains
- T1583.004 Acquire Infrastructure: Server

## Sources

- [Operation GriefLure: Dissecting an APT Campaign Targeting Vietnam's Military Telecom & Philippine Healthcare](https://www.seqrite.com/blog/operation-grieflure-dissecting-an-apt-campaign-targeting-vietnams-military-telecom-philippine-healthcare/)
- [MITRE ATT&CK T1218 — System Binary Proxy Execution](https://attack.mitre.org/techniques/T1218/)
- [MITRE ATT&CK T1027.014 — Polymorphic Code](https://attack.mitre.org/techniques/T1027/014/)
- [LOLBAS Project — ftp.exe](https://lolbas-project.github.io/lolbas/Binaries/Ftp/)
- [MITRE ATT&CK T1564.004 — Hide Artifacts: NTFS File Attributes (ADS)](https://attack.mitre.org/techniques/T1564/004/)
- [MITRE ATT&CK T1574.002 — Hijack Execution Flow: DLL Side-Loading](https://attack.mitre.org/techniques/T1574/002/)
- [MITRE ATT&CK T1566.001 — Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001/)
- [Seqrite Detection Names — Lnk.Trojan.50682.GC, Script.Trojan.50683.GC, Trojan.Win32CiR](https://www.seqrite.com/threat-research-and-response/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0476
