Vietnam.vn - Nền tảng quảng bá Việt Nam

Độc lập - Tự do - Hạnh phúc

Vietnamese Facebook users are being targeted by malicious 'Snake' campaign

Báo Thanh niênBáo Thanh niên08/03/2024


According to TechRadar , a new study has warned that bad guys are exploiting Facebook messages to deploy a sophisticated Python-based infostealer tool called Snake.

Accordingly, researchers at security solutions company Cybereason shared details of this dangerous attack campaign, saying that Snake's main goal is to steal sensitive data and login credentials from naive users. This appears to be a relatively new campaign, first detected in August 2023 and showing signs of targeting Vietnamese users.

In terms of attack methods, the attackers will send messages with content that piques the victim’s curiosity, often mentioning the victim’s sensitive video exposure, along with links to download compressed RAR or ZIP files. Although seemingly harmless, when opened, they will trigger an infection chain involving two malware downloaders, including a batch script and a cmd script. The cmd script is responsible for executing the Snake information-stealing tool from an attacker-controlled GitLab repository.

Người dùng Facebook Việt Nam đang là mục tiêu của chiến dịch độc hại 'Snake'- Ảnh 1.

Messages containing malicious links are spread via Facebook messages.

Cybereason has identified three variants of Snake, with the third variant being an executable created by PyInstaller and targeting users of the Cốc Cốc browser, which is popular in Vietnam.

Once collected, the logins and cookies were shared across multiple platforms, including Discord, GitHub, and Telegram. The malware also targeted Facebook accounts by extracting cookie information, which could indicate that the account takeover was intended to be used for malware-spreading purposes.

The campaign appears to be linked to hackers from Vietnam, as the naming convention of the attacker-controlled repositories is said to include Vietnamese references in the source code, such as 'hoang.exe' or 'hoangtuan.exe', or the GitLab path that appears to reference the name 'Khoi Nguyen'.

Cybereason also noted that the malware also targets other browsers such as Brave, Chromium, Google Chrome, Microsoft Edge, Mozilla Firefox, and Opera.

The discovery comes amid increased scrutiny of Facebook for its perceived lack of support for victims of account hijacking. To protect themselves, users are advised to take security precautions, especially using complex passwords and two-factor authentication (2FA).



Source link

Comment (0)

No data
No data
Patriotism in the young way
People joyfully welcome the 80th anniversary of National Day
Vietnam women's team beat Thailand to win bronze medal: Hai Yen, Huynh Nhu, Bich Thuy shine
People flock to Hanoi, immersing themselves in the heroic atmosphere before National Day.
Suggested locations to watch the parade on National Day September 2
Visit Nha Xa silk village
See beautiful photos taken by flycam by photographer Hoang Le Giang
When young people tell patriotic stories through fashion
More than 8,800 volunteers in the capital are ready to contribute to the A80 festival.
The moment the SU-30MK2 "cuts the wind", air gathers on the back of the wings like white clouds

Heritage

Figure

Enterprise

No videos available

News

Political System

Destination

Product