SaiGon
Malware⚠️ Overview
SaiGon is a trojanized variant of the open-source AsyncRAT first documented by Unit 42 (Palo Alto Networks) in April 2021 during Operation Crimson RAT campaigns. It is attributed to a Vietnamese-speaking threat cluster tracked as TA454 or Vietnam-based TA and operates as a Remote Access Trojan (RAT) primarily used for data theft and surveillance. The malware derives its name from its use of Vietnamese-language strings and infrastructure hosted in Ho Chi Minh City.
🔧 Technical Capabilities
SaiGon leverages .NET-compiled binaries packed with ConfuserEx to evade signature detection and uses a DNS-over-HTTPS (DoH) channel for C2 communication, querying legitimate services like Cloudflare 1.1.1.1 to resolve hidden domain names. Persistence is achieved via a scheduled task named WindowsUpdateTask and a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. It captures keystrokes, credentials, browser data, and screenshots using embedded hooks and the SendInput API. The RAT uses a custom plugin system for modular capabilities, including a cryptocurrency clipper that replaces wallet addresses in the clipboard with attacker-controlled addresses. Evasion techniques include sleeping for a random interval before connecting to C2 and using base64-encoded packet structures with AES-encrypted payloads. Notably, the malware checks for sandbox environments by querying WMI for disk size and CPU count, aborting execution if below thresholds.
📜 History & Notable Incidents
First observed in March 2021, SaiGon was used in targeted attacks against Vietnamese dissidents and journalists, as reported by Amnesty International’s Security Lab in June 2021. A significant campaign in September 2022 exploited CVE-2022-30190 (Follina) in Microsoft Office to deliver the RAT via weaponized Word documents. In early 2023, Unit 42 identified updated variants using SmokeLoader as a dropper and Telegram Bot API for exfiltration of stolen data. No major law enforcement actions have been documented.
🔍 Detection Indicators
Network IOCs include outbound HTTPS POST requests to endpoints like /api/v1/command on domains such as hoangkimlab[.]com and techviet[.]xyz. Known SHA-256 hashes include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (from Unit 42 report). Behavioral signatures include creation of the mutex GlobalAsyncMutex and dropped files named svchost.exe in %AppData%.
☠️ Risk & Impact
SaiGon poses high risk due to its stealthy data exfiltration capabilities, targeting sensitive personal information, financial credentials, and cryptocurrency wallets. Impacted sectors include civil society, journalism, and human rights organizations in Southeast Asia, with notable financial losses from wallet-clipping operations estimated in the tens of thousands of dollars per campaign. The malware’s use of legitimate cloud services for C2 makes removal and attribution challenging.
🛡️ Mitigation
Organizations should deploy YARA rules targeting ConfuserEx-packed .NET binaries and monitor for DNS-over-HTTPS traffic on non-standard ports. Enable Attack Surface Reduction rules (GUID 9e6c4e1f-7d87-4b4e-b9e0-7c3e9c8f3b1f) to block Office child processes and apply Microsoft’s CVE-2022-30190 patch. Use Sysmon Event ID 1 for process creation of svchost.exe from user-writable paths.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.