Vietnam Newsroom & Threat Intelligence
Clear sources · Careful assessments
NOTEDo not attribute a ransomware family from a file extension or a single ransom note.Vietnam time · UTC+7
Threat Intelligence

Threat Intelligence

Connect indicators, behavior and exposure to sources that can be checked.

IOC tracking

Hashes, domains, IPs and technical artifacts. Every indicator needs a source, timestamp and context.

View details

TTP map

Examine the sequence from initial access to data theft, encryption and disruption.

View details

Exposure Watch

CVEs, exposed services and management layers to review in enterprise infrastructure.

View details
Threat intelligence becomes useful when technical data informs defensive decisions. This section examines ransomware families, tactics, techniques and procedures, linking IOCs to suitable hunting and response.

Ransomware families

Behavioral profiles, extensions, ransom notes and variants; do not assign a family from extensions alone.

TTPs and entry paths

Track vulnerability exploitation, credentials, RDP/VPN and lateral movement.

From intelligence to hunting

Use indicators within their context, timeframe and confidence level.

Look up IOCsPreventive measures

Indicators expire

IPs and domains can change ownership. Historical data is not a current blocklist.

Behavior needs evidence

TTPs are a comparison framework. Do not mark a stage as observed without supporting data.

Exposure requires an inventory

A CVE's existence does not establish that every system using the product is affected.