Vietnam.vn - Nền tảng quảng bá Việt Nam

Vietnamese Facebook users are being targeted by malicious 'Snake' campaign

Báo Thanh niênBáo Thanh niên08/03/2024


According to TechRadar , a new study has warned that bad guys are exploiting Facebook messages to deploy a sophisticated Python-based infostealer tool called Snake.

Accordingly, researchers at security solutions company Cybereason shared details of this dangerous attack campaign, saying that Snake's main goal is to steal sensitive data and login credentials from naive users. This appears to be a relatively new campaign, first detected in August 2023 and showing signs of targeting Vietnamese users.

In terms of attack methods, the attackers will send messages with content that piques the victim’s curiosity, often mentioning the victim’s sensitive video exposure, along with links to download compressed RAR or ZIP files. Although seemingly harmless, when opened, they will trigger an infection chain involving two malware downloaders, including a batch script and a cmd script. The cmd script is responsible for executing the Snake information-stealing tool from an attacker-controlled GitLab repository.

Người dùng Facebook Việt Nam đang là mục tiêu của chiến dịch độc hại 'Snake'- Ảnh 1.

Messages containing malicious links are spread via Facebook messages.

Cybereason has identified three variants of Snake, with the third being an executable created by PyInstaller and targeting users of the Cốc Cốc browser, which is popular in Vietnam.

Once collected, the logins and cookies were shared across multiple platforms, including Discord, GitHub, and Telegram. The malware also targeted Facebook accounts by extracting cookie information, which could indicate that the account takeover was intended to be used for malware-spreading purposes.

The campaign appears to be linked to hackers from Vietnam, as the naming convention of the attacker-controlled repositories is said to include Vietnamese references in the source code, such as 'hoang.exe' or 'hoangtuan.exe', or the GitLab path that appears to reference the name 'Khoi Nguyen'.

Cybereason also noted that the malware also targets other browsers such as Brave, Chromium, Google Chrome, Microsoft Edge, Mozilla Firefox, and Opera.

The discovery comes amid increased scrutiny of Facebook for its perceived lack of support for victims of account hijacking. To protect themselves, users are advised to take security precautions, especially using complex passwords and two-factor authentication (2FA).



Source link

Comment (0)

No data
No data
Overview of the Opening Ceremony of National Tourism Year 2025: Hue - Ancient Capital, New Opportunities
Helicopter squadron carrying the national flag flies over the Independence Palace
Concert Brother Overcomes a Thousand Difficulties: 'Breaking Through the Roof, Flying to the Ceiling, and Breaking Through the Heavens and Earth'
Artists are busy practicing for the concert "The Brother Overcame a Thousand Thorns"

Heritage

Figure

Business

No videos available

News

Political System

Local

Product