中國駭客UNC3886利用Fortinet、VMware設備零時差漏洞持續在受害組織網路環境活動
支付動態 · 2024-06-20

研究人員發現,中國駭客組織UNC3886在攻擊行動裡,利用多項Fortinet防火牆作業系統、VMware虛擬化環境的零時差漏洞,而能暗中從事網路間諜行動不被發現

除此之外,他們也發現這些駭客也有利用FortiOS的SSL VPN漏洞CVE-2022-42475的情況,而這項漏洞能讓攻擊者藉由發送偽造的請求執行任意程式碼。

在成功利用上述漏洞控制vCenter伺服器及ESXi伺服器後,對方於虛擬機器部署名為Reptile、Medusa兩款rootkit,以便在不被察覺異狀的情況下,持續存取受害的網路環境。

而為了遠端進行控制,這些駭客也使用名為Mopsled、Riflespine的惡意程式,它們濫用GitHub及Google Drive做為存取C2的通道。

Popular articles
UK MPs reopen 2025 gambling inquiry as reform stalls
Regulation
Zenith partners with HUIDU for 2026 World Cup Carnival Official Tour
Online Game
Full House at GAT Expo Cartagena 2026 Academic Agenda
Online Game
Gaming & Technology Expo Makes a Powerful Entrance in CDMX
Marketing
1spin4win releases unique slot Don Catleone Hold and Win featuring gangster cats
Online Game
SBC Summit Canada to Make Player Safety a Key Pillar of 2026 Agenda
Marketing
PropellerAds Shared a New iGaming Case Study: 97,674 Installs and 12,701 Deposits in 3 Months
Marketing
Are you ready to maximize your earnings? Try ProPush.me Constructor!
Marketing
Manila delivers: Highlights from SiGMA Asia 2026 
Southeast Asia
GAT Expo Puerto Rico Will Pulse with the New Era of Gaming in the Caribbean
Marketing
What’s on the SBC Summit Conference Agenda in 2026?
Marketing
Kazakhstan plans to penalise online casino promotions
Regulation
Vietnam's tightening online gaming policy creates new market opportunities
Southeast Asia
Vietnam’s Controlled Gaming Shift Gains Ground, But Domestic Demand Still Lags
Southeast Asia
Brazil Proposes Raising Gambling Tax Rate to 24%, With Revenue Allocated to Social Security and Healthcare
Regulation
Home
Game
Cooperation
Find
My