A suspected Vietnamese threat actor group named CoralRaider has been targeting financial data across Asia since at least May 2023, using malware such as RotBot, a customized variant of Quasar RAT, and XClient stealer. The group focuses on stealing credentials, financial data, and social media accounts, including business and advertisement accounts, with a modus operandi involving Telegram for exfiltrating stolen information. Additionally, Bitdefender disclosed a malvertising campaign on Facebook targeting European users with information stealers, with threat actors mimicking popular AI tools to distribute malware.