為了讓變種威脅更能掩人耳目,伊朗駭客Charming Kitten改用C++重寫既有的惡意程式
支付動態 · 2024-12-27

資安業者卡巴斯基揭露伊朗駭客組織Charming Kitten最新一波的攻擊行動,並指出駭客同時使用今年4月出沒的惡意程式BellaCiao做為掩護,打算藉由另一支以C++改寫的變種BellaCPP於受害電腦活動

針對匿稱為APT35、TA453、Mint Sandstorm的伊朗駭客Charming Kitten攻擊行動,今年4月資安業者Bitdefender揭露駭客使用的惡意程式BellaCiao,並指出用途是傳遞其他惡意酬載,如今有研究人員發現,這些駭客透過其他程式語言重新改寫這支惡意程式。

資安業者卡巴斯基指出,他們在調查BellaCiao的行蹤時,從亞洲一臺遭到感染的電腦裡,發現名為BellaCPP的變種程式,兩者最大的差異,在於開發的程式語言,BellaCiao以.NET打造,而BellaCPP則是由C++改寫而成。

而在功能的部分,BellaCPP移除了BellaCiao嵌入的Web Shell模組,然而兩者之間使用的網域相同,甚至攻擊者產生連線網域的方法也一致。研究人員認為,這種變種惡意軟體的發現,突顯徹底調查網路環境與設備的重要性,因為攻擊者很有可能打造未知的惡意程式,從而在資安系統移除已知威脅的同時,藉由未知惡意程式於受害電腦持續活動。

Popular articles
Irish lawmakers at odds over change in gambling bill allowing ‘inducements’
Sports Betting
Online gambling, crypto pose ongoing money laundering risks in Philippines, analyst says
Southeast Asia
DraftKings drops another $5M into Missouri sports betting race
Sports Betting
Meet HUIDU at Booth Z64 of iGB Live 2025 in London
HUIDU Focus
Denise Coates’ charity may have saved Bet365 more in tax than it has given to good causes
Sports Betting
Soft2Bet Expands European Footprint with Launch of ElaBet.gr in Greece
Online Casino
Vietnam's tightening online gaming policy creates new market opportunities
Southeast Asia
GeoComply report: Betting while at NFL games soaring so far this season
Sports Betting
People have a lot to say about Ontario’s Premier wanting to Las Vegas-ify Niagara Falls
Regulation
FDJ completes Kindred deal to transform into ‘Europe’s champion’
Sports Betting
Wynn Resorts obtains United Arab Emirates gaming license
Regulation
BEGE and EEGS 2025 Dates Announced!
Online Casino
Hotel-casino court rulings reveal flaws in AI price-fixing allegations
Regulation
French Gambling Giant FDJ Completes €2.5bn Kindred Group Purchase
Regulation
Bally’s job training program is a big deal at Community College of Rhode Island
Regulation
Home
Game
Cooperation
Find
My