SYMBOLCOMMON_NAMEaka. SYNONYMS

CoralRaider  (Back to overview)


CoralRaider is a financially motivated threat actor of Vietnamese origin, targeting victims in Asian and Southeast Asian countries since at least 2023. They use the RotBot loader family and XClient stealer to steal victim information, with hardcoded Vietnamese words in their payloads. CoralRaider operates from Hanoi, Vietnam, and uses a Telegram bot as a C2 channel for their malicious campaigns. Their activities include system reconnaissance, data exfiltration, and targeting victims in multiple countries in the region.


Associated Families
py.pxa_stealer

References
2026-03-24 ⋅ ⋅ Nguoi Lao Dong ⋅ Tuan Minh
A 12th grader in Thanh Hoa used malicious code to steal computer data users worldwide
PXA Stealer
2025-08-31 ⋅ Darkrym ⋅ Darkrym
PXA Stealers Evolution to PureRAT: Part 3 - Weaponised Python Stage (Stage 5)
PXA Stealer
2025-08-04 ⋅ Sentinel LABS ⋅ Alex Delamotte, Bobby Venal, Francisco Donoso, Jim Walter, Sam Mayers, Tell Hause
Ghost in the Zip | New PXA Stealer and Its Telegram-Powered Ecosystem
PXA Stealer
2025-08-04 ⋅ Beazley Security Labs ⋅ Alex Delamotte, Bobby Venal, Francisco Donoso, Jim Walter, Sam Mayers, Tell Hause
Ghost in the Zip | New PXA Stealer and Its Telegram-Powered Ecosystem
PXA Stealer
2025-06-13 ⋅ Twitter (@luc4m) ⋅ Luca Mella
Tweet on PXA Stealer targeting Italy
PXA Stealer
2024-11-14 ⋅ Cisco Talos ⋅ Alex Karkins, Chetan Raghuprasad, Joey Chen
New PXA Stealer targets government and education sectors for sensitive information
PXA Stealer
2024-04-04 ⋅ Cisco Talos ⋅ Chetan Raghuprasad, Joey Chen
CoralRaider targets victims’ data and social media accounts
CoralRaider

Credits: MISP Project