The Operation SignSight VGCA Supply Chain Attack

Updated 5 Oct 2026 · Incident date 23 Jul 2020 · vendor binary

PackageVGCA client installers gca01-client-v2-x32-8.3.msi and gca01-client-v2-x64-8.3.msi, served 23 July to 16 August 2020
FileeToken.exe added to the MSI installer

From 23 July to 16 August 2020, the website of the Vietnam Government Certification Authority (VGCA) served two modified installers: gca01-client-v2-x32-8.3.msi and gca01-client-v2-x64-8.3.msi. They installed the PhantomNet backdoor. ESET named the operation SignSight and published the findings on 17 December 2020.

The software is a digital signature toolkit for USB token signing. Visitors to a certification authority site have a high level of trust in it.

What happened

Attackers compromised the VGCA website, ca.gov.vn, and replaced two installers with versions that held a backdoor. ESET states that a man-in-the-middle attack is unlikely, because the downloads used HTTPS. The sources do not say how the attackers entered the site.

The modified installer ran the real installer and also dropped a malicious file. ESET describes the backdoor as PhantomNet, also called SManager. It posed as eToken.exe. The dropper wrote it to C:\Program Files\VGCA\Authentication\SAC\x32\eToken.exe. When run with administrator rights, a component went to C:\Windows\apppatch\netapi32.dll. For a normal user, it went to %TEMP%\Wmedia\<number>.tmp.

PhantomNet talks to its servers over HTTPS with certificate pinning. It supports commands for system reconnaissance, plugin management, proxy detection and lateral movement with an embedded Mimikatz. A plugin named SnowballS suggests a focus on Active Directory. ESET reports that most victims were in Vietnam, with a few in the Philippines. ESET notes that the clean VGCA installers are also signed incorrectly, so a signature check alone is not enough. The Vietnamese authority told ESET that it knew about the attack and notified users.

Vigilance compares the version you trust with the new one. A vendor installer that now drops a second program is the kind of change it reports. See the scan block below.

Affected versions

The sources name no other installers or versions.

Indicators of compromise

How to check

Hash the installer you kept, and search for the dropped files. Run this in PowerShell.

Get-FileHash -Algorithm SHA1 .\gca01-client-v2-x64-8.3.msi; Test-Path C:\Windows\apppatch\netapi32.dll; Get-ChildItem $env:TEMP\Wmedia -ErrorAction SilentlyContinue

Replace the file name if you kept the x32 installer. Compare the hash with the list above. Also search DNS and proxy logs for the two command domains.

What to do now

  1. Find out who downloaded the two installers between 23 July and 16 August 2020.
  2. If a machine ran one, isolate it and reinstall it. PhantomNet includes Mimikatz, so treat the credentials on that host as stolen.
  3. Reset domain and local passwords that were used on the machine. Review Active Directory for unusual activity.
  4. Block the two command domains.
  5. Get the VGCA client only from the authority and ask the authority for the current hash.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old VGCA-prev --new VGCA-current
files scanned: 31 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   eToken.exe
           It downloads from the internet.

Frequently asked questions

Which VGCA installers were compromised in Operation SignSight?

Two installers were compromised: gca01-client-v2-x32-8.3.msi and gca01-client-v2-x64-8.3.msi. They were served from ca.gov.vn from 23 July to 16 August 2020.

What is PhantomNet?

PhantomNet, also called SManager, is a backdoor. It collects system information, loads plugins and talks to its servers over HTTPS. ESET found it in the trojanized VGCA installers.

Sources

  1. welivesecurity.com/2020/12/17/operation-signsight-supply-chain-attack-southeast-asia/
  2. thehackernews.com/2020/12/software-supply-chain-attack-hits.html

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free