Automatically translated.View original post

A new malware outbreak through Whatsapp in several countries

A new malware outbreak has been found through Whatsapp in several countries with a fake business document.

According to a report by the website Windows Report, a research team from Kaspersky, a well-known antivirus software developer, found a malware distribution campaign through the Whatsapp application, a phishing scam. Hackers are business or Trusted Contracts. After the victim responds, hackers claim to have financial documents such as financial reports, statements, and other business documents as attachments for the victim to open, but the file is actually a VBScript script file for opening the Windows operating system.

In the malware operation, after the victim runs the file, the script contacts the control server (C2 or Command and Control) to download the component element of the malware on the machine. After that, the second script modifies the Windows Registry to weaken the User Account Control (UAC) protection system. This leads to the next step: the script downloads a zip compressed file that contains a remote management tool called ManageEngine Endpoint Central. As usual, it's often a tool used by IT departments to take over to manage the maintenance of employees' machines in companies, but hackers have misused it to control the victim's machine instead in this case.

The research team conducted an in-depth investigation and found that the impersonation file was made in a variety of languages, making it expected that the campaign was not limited to a certain area, but was targeted as a global attack. The confirmed outbreak countries included Brazil, India, Mexico, Singapore, Taiwan, Spain, Australia, Russia, Vietnam, Malaysia, and the United Kingdom, which is called a huge variety. In addition, the research team also investigated the related infrastructure, found that it was mainly used in Chinese, and that it was used in combination with remote control type malware ( RAT or Remote Access Trojan), but it still can't confirm the real male behind it at the moment.

# Trending # lemon 8 diary # whatsapp # freedomhack # it

1 week agoEdited to

... Read moreจากประสบการณ์ส่วนตัวที่เคยได้รับข้อความลักษณะคล้ายไฟล์แนบจาก Whatsapp ที่อ้างว่าเป็นเอกสารธุรกิจ ผมขอแนะนำให้ระมัดระวังเป็นพิเศษ เพราะมัลแวร์ตัวนี้ใช้วิธีหลอกลวงแบบ Phishing โดยส่งไฟล์สคริปท์ VBScript ที่ดูเหมือนรายงานการเงินหรือเอกสารสำคัญอื่น ๆ ซึ่งถ้าเผลอเปิดไฟล์ อาจทำให้คอมพิวเตอร์ของเราถูกควบคุมจากระยะไกลและข้อมูลส่วนตัวรั่วไหลได้ คำแนะนำในการป้องกันตัวเองคือ หลีกเลี่ยงการคลิกลิงก์หรือเปิดไฟล์แนบที่ส่งมาทาง Whatsapp โดยเฉพาะหากมาจากบุคคลที่เราไม่รู้จักหรือไม่น่าเชื่อถือ นอกจากนี้ควรใช้โปรแกรมแอนตี้ไวรัสที่มีการอัปเดตล่าสุด และตั้งค่าความปลอดภัยของระบบให้เหมาะสม เช่น เปิดใช้งาน User Account Control (UAC) อย่างเข้มงวด ปัญหานี้เรียกได้ว่าเป็นตัวอย่างหนึ่งของภัยไซเบอร์ที่มาพร้อมเทคนิคการหลอกลวงที่แยบยล รวมถึงใช้เครื่องมือไอทีที่องค์กรใช้บ่อย ๆ อย่าง ManageEngine Endpoint Central มาประยุกต์ใช้ในทางที่ผิด จึงเป็นเรื่องสำคัญที่ผู้ใช้ทุกคนต้องเพิ่มความรู้ความเข้าใจเกี่ยวกับภัยคุกคามทางไซเบอร์ และติดตามข่าวสารด้านความปลอดภัยอยู่เสมอเพื่อเตรียมพร้อมรับมืออย่างถูกวิธี สุดท้าย การสังเกตบริบทของข้อความ เช่น การสะกดคำผิดหรือการขอให้เปิดไฟล์ทันที รวมถึงการตรวจสอบยืนยันกับผู้ส่ง คนใกล้ตัวหรือองค์กรที่เกี่ยวข้องจะช่วยลดความเสี่ยงได้มาก และถ้าได้รับข้อความหรือไฟล์ที่น่าสงสัย ควรแจ้งให้ฝ่ายไอทีหรือผู้เชี่ยวชาญด้านความปลอดภัยช่วยตรวจสอบโดยด่วน เพื่อปกป้องระบบและข้อมูลจากการถูกโจมตีอย่างมีประสิทธิภาพ