為了讓變種威脅更能掩人耳目,伊朗駭客Charming Kitten改用C++重寫既有的惡意程式
支付動態 · 2024-12-27

資安業者卡巴斯基揭露伊朗駭客組織Charming Kitten最新一波的攻擊行動,並指出駭客同時使用今年4月出沒的惡意程式BellaCiao做為掩護,打算藉由另一支以C++改寫的變種BellaCPP於受害電腦活動

針對匿稱為APT35、TA453、Mint Sandstorm的伊朗駭客Charming Kitten攻擊行動,今年4月資安業者Bitdefender揭露駭客使用的惡意程式BellaCiao,並指出用途是傳遞其他惡意酬載,如今有研究人員發現,這些駭客透過其他程式語言重新改寫這支惡意程式。

資安業者卡巴斯基指出,他們在調查BellaCiao的行蹤時,從亞洲一臺遭到感染的電腦裡,發現名為BellaCPP的變種程式,兩者最大的差異,在於開發的程式語言,BellaCiao以.NET打造,而BellaCPP則是由C++改寫而成。

而在功能的部分,BellaCPP移除了BellaCiao嵌入的Web Shell模組,然而兩者之間使用的網域相同,甚至攻擊者產生連線網域的方法也一致。研究人員認為,這種變種惡意軟體的發現,突顯徹底調查網路環境與設備的重要性,因為攻擊者很有可能打造未知的惡意程式,從而在資安系統移除已知威脅的同時,藉由未知惡意程式於受害電腦持續活動。

Popular articles
Bally’s job training program is a big deal at Community College of Rhode Island
Regulation
GamingTECH CEE Awards 2025: The Online Voting Battle Begins February 12!
Online Casino
Spanish regulator warns of identity theft via online gambling platforms
Regulation
Meet HUIDU at Booth Z64 of iGB Live 2025 in London
HUIDU Focus
Industry sources: Time to pump the brakes a little on an Alberta online market rollout
Sports Betting
German gambling regulator wins case against lottery operator
Regulation
Swedish lawmaker proposes lowered gambling tax to fight black market
Sports Betting
Elevate Your Casino’s Success with Opexa Game Aggregators
HUIDU Focus
Major UK banks join new Gambling Harms Action Lab
Regulation
FDJ says it doesn’t foresee French gambling tax hike, as stock price hit
Sports Betting
HUIDU is Ready at Booth 2249 to Meet You at SiGMA Asia 2025
HUIDU Focus
FDJ completes Kindred deal to transform into ‘Europe’s champion’
Sports Betting
Vietnam's tightening online gaming policy creates new market opportunities
Southeast Asia
Dutch gambling regulator wanrs lottery over advertorial
Regulation
GeoComply report: Betting while at NFL games soaring so far this season
Sports Betting
Home
Game
Cooperation
Find
My