Vietnam Newsroom & Threat Intelligence
Clear sources · Careful assessments
NOTEDo not attribute a ransomware family from a file extension or a single ransom note.Vietnam time · UTC+7

Sources

Documents used in the initial library; each article cites relevant sources within its content.

Information published by the unit receiving the case; not independently verified.

03/10/2026 · Archived reference source; see its scope in the related article

Guidance on prevention, response and recovery.

See the update date at the source · Archived reference source; see its scope in the related article

Reference documentation on Akira, IOCs and TTPs. See the update date at the source.

Initially published 18/04/2024 · Archived reference source; see its scope in the related article

Analysis of ESXi exploitation observed by Microsoft.

29/07/2024 · Archived reference source; see its scope in the related article

Vendor advisory; check affected versions and mitigations.

2024 · Archived reference source; see its scope in the related article

Observed activity and defensive recommendations.

14/06/2023 · Archived reference source; see its scope in the related article

Sourced behavioral profile. Does not attribute an individual case to Qilin.

See the update date at the source · Archived reference source; see its scope in the related article

Sample research and intrusion chain analysis by Unit 42.

2023 · Archived reference source; see its scope in the related article

The vendor's backup design guidance.

See the update date at the source · Archived reference source; see its scope in the related article

Foundational guidance on collecting, examining, analyzing and reporting digital evidence.

2006 · Archived reference source; see its scope in the related article

A behavioral reference framework; attacks do not necessarily follow one sequence.

See the update date at the source · Archived reference source; see its scope in the related article

Reference for encryption of data to cause disruption.

See the update date at the source · Archived reference source; see its scope in the related article

Publication by the case-receiving unit, preserved from No.Ransomware.VN source code. Eight tickets are internal observations, not independently verified.

26/09/2026 · Source reviewed: 10/09/2026

Reviewed primary source. It does not confirm the .PIZ, AnyDesk or Safe Mode chain attributed to it in the old No.Ransomware.VN article.

08/09/2026 · Source reviewed: 10/09/2026

Statistics within Cyble's collection scope. Victim claims are not equivalent to incidents independently verified by Ransomware.VN.

August 2026 · Source reviewed: 10/09/2026

Source cited in the original article; read figures within the researcher's period and methodology.

Q2/2026 · Archived reference source; see its scope in the related article

Official report page; surveys and leak-site claims are different datasets.

See the update date at the source · Archived reference source; see its scope in the related article

The original date is retained in source code. The consolidated article preserves immutability, retention, administrator permissions and recovery tests.

12/09/2026 · Source reviewed: 10/09/2026

Content from the source homepage and categories. Guidance passages have no separate publication dates; no invented historical dates are assigned.

See the update date at the source · Source reviewed: 10/09/2026

A reference link retained on No.Ransomware.VN. The date and title come from the source record; they were not independently reviewed during consolidation. Do not treat this as a verified incident report.

26/08/2026 · Archived reference source; see its scope in the related article

A reference link retained on No.Ransomware.VN. The date and title come from the source record; they were not independently reviewed during consolidation. Do not treat this as a verified incident report.

06/08/2026 · Archived reference source; see its scope in the related article

A reference link retained on No.Ransomware.VN. The date and title come from the source record; they were not independently reviewed during consolidation. Do not treat this as a verified incident report.

28/05/2026 · Archived reference source; see its scope in the related article

A reference link retained on No.Ransomware.VN. The date and title come from the source record; they were not independently reviewed during consolidation. Do not treat this as a verified incident report.

10/09/2026 · Archived reference source; see its scope in the related article

A reference link retained on No.Ransomware.VN. The date and title come from the source record; they were not independently reviewed during consolidation. Do not treat this as a verified incident report.

10/09/2026 · Archived reference source; see its scope in the related article

A reference link retained on No.Ransomware.VN. The date and title come from the source record; they were not independently reviewed during consolidation. Do not treat this as a verified incident report.

09/09/2026 · Archived reference source; see its scope in the related article

Archived documentation has its own canonical URL on t.tungtek.com; the reference link is retained without duplicating the full article into a competing version.

30/09/2026 · Archived reference source; see its scope in the related article

The operator confirms ransomware as the cause and dates the disruption.

07/10/2026 · Source reviewed: 10/10/2026

Four affected zones and the operator's recovery assessment at publication.

08/10/2026 · Source reviewed: 10/10/2026

Response coordination update; it does not announce complete restoration.

09/10/2026 · Source reviewed: 10/10/2026

Public warning mentions StormEncryptor and RMM abuse; no victim case is established here.

29/08/2026 · Source reviewed: 10/10/2026

Vendor notice on CVE-2026-18577 and the August HF2 release; not a claim that it is today's latest release.

06/08/2026 · Source reviewed: 10/10/2026

Research-team observations and attribution; not confirmation of a new incident in Vietnam.

01/10/2026 · Source reviewed: 10/10/2026

Citing a reference does not endorse every statement on the website. Read conclusions within the document's scope and timeframe.