為了讓變種威脅更能掩人耳目,伊朗駭客Charming Kitten改用C++重寫既有的惡意程式
支付動態 · 2024-12-27

資安業者卡巴斯基揭露伊朗駭客組織Charming Kitten最新一波的攻擊行動,並指出駭客同時使用今年4月出沒的惡意程式BellaCiao做為掩護,打算藉由另一支以C++改寫的變種BellaCPP於受害電腦活動

針對匿稱為APT35、TA453、Mint Sandstorm的伊朗駭客Charming Kitten攻擊行動,今年4月資安業者Bitdefender揭露駭客使用的惡意程式BellaCiao,並指出用途是傳遞其他惡意酬載,如今有研究人員發現,這些駭客透過其他程式語言重新改寫這支惡意程式。

資安業者卡巴斯基指出,他們在調查BellaCiao的行蹤時,從亞洲一臺遭到感染的電腦裡,發現名為BellaCPP的變種程式,兩者最大的差異,在於開發的程式語言,BellaCiao以.NET打造,而BellaCPP則是由C++改寫而成。

而在功能的部分,BellaCPP移除了BellaCiao嵌入的Web Shell模組,然而兩者之間使用的網域相同,甚至攻擊者產生連線網域的方法也一致。研究人員認為,這種變種惡意軟體的發現,突顯徹底調查網路環境與設備的重要性,因為攻擊者很有可能打造未知的惡意程式,從而在資安系統移除已知威脅的同時,藉由未知惡意程式於受害電腦持續活動。

Popular articles
Pennsylvania: Valley Forge Casino opening new dining hall
Regulation
The ultimate gambler? How Bet365’s Denise Coates became Britain’s richest woman
Sports Betting
Online gambling, crypto pose ongoing money laundering risks in Philippines, analyst says
Southeast Asia
Australia weighing strict measures on gambling ads
Regulation
People have a lot to say about Ontario’s Premier wanting to Las Vegas-ify Niagara Falls
Regulation
Indiana online casino bill stalls in House committee
Regulation
‘A target on their back’: college athletes face wave of abuse amid gambling boom
Sports Betting
In a rare video message, Light & Wonder CEO says slot issue was ‘an isolated incident’
Regulation
GamingTECH CEE Awards 2025: The Online Voting Battle Begins February 12!
Online Casino
French Gambling Giant FDJ Completes €2.5bn Kindred Group Purchase
Regulation
Italian regulator updates technical rules for gambling systems verification
Regulation
BEGE and EEGS 2025 Dates Announced!
Online Casino
Spanish regulator warns of identity theft via online gambling platforms
Regulation
FDJ says it doesn’t foresee French gambling tax hike, as stock price hit
Sports Betting
Wynn Resorts obtains United Arab Emirates gaming license
Regulation
Home
Game
Cooperation
Find
My