中國駭客UNC3886利用Fortinet、VMware設備零時差漏洞持續在受害組織網路環境活動
支付動態 · 2024-06-20

研究人員發現,中國駭客組織UNC3886在攻擊行動裡,利用多項Fortinet防火牆作業系統、VMware虛擬化環境的零時差漏洞,而能暗中從事網路間諜行動不被發現

除此之外,他們也發現這些駭客也有利用FortiOS的SSL VPN漏洞CVE-2022-42475的情況,而這項漏洞能讓攻擊者藉由發送偽造的請求執行任意程式碼。

在成功利用上述漏洞控制vCenter伺服器及ESXi伺服器後,對方於虛擬機器部署名為Reptile、Medusa兩款rootkit,以便在不被察覺異狀的情況下,持續存取受害的網路環境。

而為了遠端進行控制,這些駭客也使用名為Mopsled、Riflespine的惡意程式,它們濫用GitHub及Google Drive做為存取C2的通道。

热门文章
PropellerAds Shared a New iGaming Case Study: 97,674 Installs and 12,701 Deposits in 3 Months
Marketing
GAT Expo CDMX 2026 Kicks Off Today in Mexico with a Sold-Out Opening Reception at Big Bola Casino Santa Fe
Marketing
Kazakhstan plans to penalise online casino promotions
Regulation
That’s a Wrap: AffPapa Conference Madrid 2026 Highlights
Online Game
B2B Tech Infrastructure Gains Momentum in Philippine Gaming Sector
Southeast Asia
Indiana online casino bill stalls in House committee
Regulation
Vietnam's tightening online gaming policy creates new market opportunities
Southeast Asia
British gambling levy rates confirmed for each vertical
Regulation
1spin4win grows its Latin American presence by partnering with Fortuna Juegos
Online Game
PropellerAds Positions Itself as a Go-To Traffic Source for iGaming Advertisers Ahead of a High-Demand Season
Marketing
Super PAC Raises $48 Million: Sports Betting Forces Ramp Up Political Push
Regulation
Online gambling, crypto pose ongoing money laundering risks in Philippines, analyst says
Southeast Asia
1spin4win releases unique slot Don Catleone Hold and Win featuring gangster cats
Online Game
Are you ready to maximize your earnings? Try ProPush.me Constructor!
Marketing
UK MPs reopen 2025 gambling inquiry as reform stalls
Regulation
首页
游戏
合作
发现
我的