Malware Spread Through Recruitment Documents Compromised More Than 12,000 Computers
A group in Vietnam distributed malware through recruitment materials, advertising content, and Word and PDF files beginning in late 2022. Investigators found that more than 12,480 computers across over 90 countries were infected or compromised, including 125 devices using Vietnamese IP addresses. The incident was not associated with a specific CVE.
A recruitment email, candidate résumé, or advertising document may look like routine business content. That familiarity can make such files effective social engineering tools when attackers want to place malware on corporate devices without necessarily exploiting a specific software vulnerability.
A criminal case heard in Ho Chi Minh City on September 16, 2026 illustrates how this approach was used at scale. According to case records cited by multiple Vietnamese news outlets, the group involved not only collected Facebook advertising account credentials but also developed capabilities to remotely control victims' computers.
How did the group distribute the malware?
Around late 2022, prosecutors said Lê Ngọc Sơn asked Lê Đức Tài to develop malware designed to steal Facebook advertising account information. The tool was later embedded into familiar file formats such as Word and PDF documents and distributed through recruitment and advertising content on LinkedIn, Facebook, and other platforms.

When victims downloaded and opened the files, the malware could infect their computers and collect login credentials. The stolen data was then transmitted back to infrastructure operated by the group for further exploitation of advertising accounts.
From late 2022 to around May 2023, antivirus products repeatedly detected the malware. According to the case records, the source code was subsequently modified in an effort to reduce detection. When the original tool became less effective, the group purchased remote-access malware source code through Telegram for USD 40,000 and continued developing it.
How large was the campaign?
Server data seized during the investigation showed that the campaign extended well beyond Vietnam. VnExpress reported that more than 12,480 computers were affected, including 125 systems using Vietnamese IP addresses and 12,360 computers located across more than 90 countries. Báo Công an TP.HCM reported a specific total of 12,485 devices.
Data Point | Reported Information |
Campaign start | Around late 2022 |
Devices affected | More than 12,480; some reports specify 12,485 |
Devices with Vietnamese IP addresses | 125 |
Geographic reach | More than 90 countries |
Malware source code purchase | USD 40,000 |
Initial target | Facebook advertising accounts |
Defendants tried | 15 people |
Alleged illicit proceeds | Approximately VND 12 billion |
The reporting also differs regarding the prison sentences imposed on the two main defendants. Báo Công an Nhân dân and VietnamNet reported eight-year sentences for both Lê Ngọc Sơn and Lê Đức Tài, while VnExpress reported seven years and six months. Because an official published judgment was not used as a source, this difference should be acknowledged rather than silently reconciled.
Why can recruitment documents and Word or PDF files become attack vectors?
The important feature of this case is the attacker's use of trust. If a victim can be persuaded to voluntarily download and open what appears to be a legitimate business document, the attacker may not need a zero-day vulnerability to obtain an initial foothold.
The attack flow can be summarized in four stages:
Create convincing recruitment or advertising content.
Direct the victim to a Word, PDF, or other document containing malicious components.
Once the file is opened, malware executes and collects account information.
Later versions add remote-access and control capabilities.
According to the case records, the group also used a “bot builder” to embed malware into files and generate links for distribution. Compromised computers could then be accessed remotely to view information, observe the screen, or perform actions on the device.
For businesses, this resembles many modern malware campaigns: security software may block part of the malicious payload, but employees remain a primary point of contact with the lure. Antivirus alone should therefore not be treated as a complete security control.
👉 IPSIP Vietnam has also examined cases in which fake websites were used to distribute malware through applications that appeared legitimate. A common pattern is the exploitation of user trust before the actual infection stage begins.
Which business functions should be particularly cautious?
Employees who regularly receive external documents face greater exposure to this type of attack. HR and recruitment teams, marketing staff, sales personnel, agencies, accounting teams, and employees managing advertising accounts are common examples.
Advertising accounts are attractive targets because they may be linked to payment methods, spending limits, or corporate budgets. According to the case records, compromised accounts were used to run advertisements, transferred to others, or otherwise exploited for financial gain.
The risk does not stop at Facebook accounts. If an attacker gains remote control over a corporate endpoint, the potential impact depends on the user's privileges, the information stored on the device, and which internal systems can be reached from it.
Businesses should therefore apply Least Privilege, separate high-value accounts, and strengthen access controls for systems involving payments, email, social media, and administrative privileges.
What should businesses do immediately?
The first priority is to reduce the likelihood that employees open malicious content while also ensuring that the organization can detect a compromise quickly if an endpoint is infected.
Action Checklist:
AFor organizations seeking to improve employee awareness of phishing and social engineering, training should focus on realistic attack scenarios rather than relying only on policy-based instruction. through Cybersecurity Training for Enterprise Security Awareness
What does the IPSIP Vietnam's cybersecurity perspective show?
If a corporate endpoint is compromised, potential consequences include account takeover, unauthorized advertising costs, data exposure, access to internal applications, and incident-response expenses. The actual impact depends on the user's privileges and the attacker's ability to move further into the environment.
Familiar file names and formats are not reliable indicators of trust. Effective defense requires a combination of user awareness, access control, endpoint visibility, and an established incident-response process.
This case shows that a large-scale malware campaign does not necessarily need to begin with a zero-day vulnerability. A convincing recruitment message, a familiar business document, and one user action can create the initial foothold for credential theft or remote endpoint control.
For Vietnamese businesses, the priority should extend beyond simply blocking malicious files. Strong access control, multi-factor authentication, endpoint monitoring, and a tested incident-response process should operate together to limit the impact if an attacker bypasses the first layer of defense.
References










Comments