
Defense
EGGCOP cluster: Vietnamese commercial infostealer ring identified through operator self-infection
A 2.9 GB Telegram exfiltration archive places 845 credential-theft packages and the operators themselves in Ho Chi Minh City. The cluster operates a corporate front, eggcop.com, with eight identified staff mailboxes and one strongly attributed individual operator.
