微軟圖學資料分析服務Graph的API遭駭客用於惡意通訊,攻擊烏克蘭組織
· 2024-05-07

研究人員針對駭客濫用微軟Graph的API提出警告,並舉出針對烏克蘭企業組織的惡意程式BirdyClient為例,他們目前還找不到對方使用的其他作案工具,難以捉摸作案動機及攻擊者身分

資安業者賽門鐵克提出警告,他們看到有越來越多駭客,在攻擊行動當中,濫用微軟圖學資料分析服務Graph的API,並指出駭客這麼做的目的,通常是也利用微軟雲端服務架設C2基礎設施的情況下,能夠促進相關通訊的進行。

研究人員看到利用上述手法針對烏克蘭組織的攻擊行動,對方使用名為BirdyClient(或OneDriveBirdyClient)的惡意程式,並將其偽製成筆記型電腦觸控板驅動程式ALPS Pointing Device Driver(Apoint.exe)相關的DLL程式庫元件vxdiff.dll。

此惡意程式的主要功能,就是連接微軟Graph的API,並利用雲端檔案共享服務OneDrive充當C2伺服器,然後讓攻擊者能上傳或下載檔案。不過,攻擊者的動機為何?研究人員指出,由於尚未找到其他作案工具,目前無從得知意圖,也不確定攻擊者的身分。

但這並非駭客首度濫用Graph的API,最初是2021年資安業者Volexity發現,北韓駭客組織InkySquid在發動惡意軟體BlueLight攻擊行動的過程裡,就濫用這種API建立C2連線。曾經將該API用於攻擊行動的駭客組織,還包含了APT28、APT29、REF2924、Red Stinger、Flea、OilRig。

熱門文章
Brazil Proposes Raising Gambling Tax Rate to 24%, With Revenue Allocated to Social Security and Healthcare
Regulation
Vietnam’s Controlled Gaming Shift Gains Ground, But Domestic Demand Still Lags
Southeast Asia
PropellerAds Shared a New iGaming Case Study: 97,674 Installs and 12,701 Deposits in 3 Months
Marketing
Vietnam's tightening online gaming policy creates new market opportunities
Southeast Asia
Are you ready to maximize your earnings? Try ProPush.me Constructor!
Marketing
Gaming & Technology Expo Makes a Powerful Entrance in CDMX
Marketing
Super PAC Raises $48 Million: Sports Betting Forces Ramp Up Political Push
Regulation
Full House at GAT Expo Cartagena 2026 Academic Agenda
Online Game
SBC Summit Canada to Make Player Safety a Key Pillar of 2026 Agenda
Marketing
Online gambling, crypto pose ongoing money laundering risks in Philippines, analyst says
Southeast Asia
JILI Partners with Cricket Legend AB de Villiers (ABD) to Launch Exclusive Branded Game Series 100% 11
Sports Game
GGC Awards 2026 Shines in Colombo: Honoring Leaders and Innovators in the iGaming Industry
HUIDU Focus
Indiana online casino bill stalls in House committee
Regulation
Kazakhstan plans to penalise online casino promotions
Regulation
B2B Tech Infrastructure Gains Momentum in Philippine Gaming Sector
Southeast Asia
首頁
遊戲
合作
發現
我的