The Operation SignSight VGCA Supply Chain Attack
Updated 5 Oct 2026 · Incident date 23 Jul 2020 · vendor binary
VGCA client installers gca01-client-v2-x32-8.3.msi and gca01-client-v2-x64-8.3.msi, served 23 July to 16 August 2020eToken.exe added to the MSI installerFrom 23 July to 16 August 2020, the website of the Vietnam Government Certification Authority (VGCA) served two modified installers: gca01-client-v2-x32-8.3.msi and gca01-client-v2-x64-8.3.msi. They installed the PhantomNet backdoor. ESET named the operation SignSight and published the findings on 17 December 2020.
The software is a digital signature toolkit for USB token signing. Visitors to a certification authority site have a high level of trust in it.
What happened
Attackers compromised the VGCA website, ca.gov.vn, and replaced two installers with versions that held a backdoor. ESET states that a man-in-the-middle attack is unlikely, because the downloads used HTTPS. The sources do not say how the attackers entered the site.
The modified installer ran the real installer and also dropped a malicious file. ESET describes the backdoor as PhantomNet, also called SManager. It posed as eToken.exe. The dropper wrote it to C:\Program Files\VGCA\Authentication\SAC\x32\eToken.exe. When run with administrator rights, a component went to C:\Windows\apppatch\netapi32.dll. For a normal user, it went to %TEMP%\Wmedia\<number>.tmp.
PhantomNet talks to its servers over HTTPS with certificate pinning. It supports commands for system reconnaissance, plugin management, proxy detection and lateral movement with an embedded Mimikatz. A plugin named SnowballS suggests a focus on Active Directory. ESET reports that most victims were in Vietnam, with a few in the Philippines. ESET notes that the clean VGCA installers are also signed incorrectly, so a signature check alone is not enough. The Vietnamese authority told ESET that it knew about the attack and notified users.
Vigilance compares the version you trust with the new one. A vendor installer that now drops a second program is the kind of change it reports. See the scan block below.
Affected versions
gca01-client-v2-x32-8.3.msiandgca01-client-v2-x64-8.3.msidownloaded fromca.gov.vnfrom 23 July to 16 August 2020.
The sources name no other installers or versions.
Indicators of compromise
- Command servers:
vgca.homeunix[.]organdoffice365.blogdns[.]com. - SHA-1 of the x64 installer:
5C77A18880CF58DF9FBA102DD8267C3F369DF449. - SHA-1 of the x32 installer:
B0E4E9BB6EF8AA7A9FCB9C9E571D8162B1B2443A. - SHA-1 of the dropper:
9522F369AC109B03E6C16511D49D1C5B42E12A44. - SHA-1 of PhantomNet.B:
989334094EC5BA8E0E8F2238CDF34D5C57C283F2. - SHA-1 of the PhantomNet.A plugin:
5DFC07BB6034B4FDA217D96441FB86F5D43B6C62. - Paths:
C:\Windows\apppatch\netapi32.dll,%TEMP%\Wmedia\*.tmpandC:\Program Files\VGCA\Authentication\SAC\x32\eToken.exe.
How to check
Hash the installer you kept, and search for the dropped files. Run this in PowerShell.
Get-FileHash -Algorithm SHA1 .\gca01-client-v2-x64-8.3.msi; Test-Path C:\Windows\apppatch\netapi32.dll; Get-ChildItem $env:TEMP\Wmedia -ErrorAction SilentlyContinue
Replace the file name if you kept the x32 installer. Compare the hash with the list above. Also search DNS and proxy logs for the two command domains.
What to do now
- Find out who downloaded the two installers between 23 July and 16 August 2020.
- If a machine ran one, isolate it and reinstall it. PhantomNet includes Mimikatz, so treat the credentials on that host as stolen.
- Reset domain and local passwords that were used on the machine. Review Active Directory for unusual activity.
- Block the two command domains.
- Get the VGCA client only from the authority and ask the authority for the current hash.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 31 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE eToken.exe It downloads from the internet.
Frequently asked questions
Which VGCA installers were compromised in Operation SignSight?
Two installers were compromised: gca01-client-v2-x32-8.3.msi and gca01-client-v2-x64-8.3.msi. They were served from ca.gov.vn from 23 July to 16 August 2020.
What is PhantomNet?
PhantomNet, also called SManager, is a backdoor. It collects system information, loads plugins and talks to its servers over HTTPS. ESET found it in the trojanized VGCA installers.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.