Binance Square
LIVE
LIVE
Bu_Alee
--35 views
查看原文
威胁行为者正在使用虚假的 #Facebook 招聘广告来欺骗受害者安装 Ov3r_Stealer,这是一种基于 Windows 的新型窃取病毒。 Ov3r_Stealer 旨在从受感染的主机中提取基于 IP 地址的位置、硬件详细信息、密码、cookie、信用卡信息、自动填充、浏览器扩展、加密钱包、Microsoft Office 文档以及防病毒产品列表。 该活动的动机仍不清楚;然而,被盗数据经常被出售给其他威胁行为者。 Ov3r_Stealer 也可能被修改以部署恶意软件和其他有效负载,例如 QakBot。 该攻击以看似托管在 OneDrive 上的恶意 PDF 文件发起,诱使用户单击“访问文档”按钮。 Trustwave 发现了在假亚马逊首席执行官 Andy Jassy Facebook 帐户上发布的 PDF 文件以及宣传数字广告机会的 Facebook 广告。 单击该按钮后,用户将被定向到一个 .URL 文件,该文件伪装成托管在 Discord 的 CDN 上的 DocuSign 文档。控制面板项 (.CPL) 文件通过快捷方式文件传递并由 Windows 控制面板进程二进制文件 (“control.exe”) 执行。 执行 CPL 文件会触发从 GitHub 检索 PowerShell 加载程序(“DATA1.txt”)以执行 Ov3r_Stealer。 #BewareOfScams #TrendingTopic #SafetyTips

威胁行为者正在使用虚假的 #Facebook 招聘广告来欺骗受害者安装 Ov3r_Stealer,这是一种基于 Windows 的新型窃取病毒。

Ov3r_Stealer 旨在从受感染的主机中提取基于 IP 地址的位置、硬件详细信息、密码、cookie、信用卡信息、自动填充、浏览器扩展、加密钱包、Microsoft Office 文档以及防病毒产品列表。

该活动的动机仍不清楚;然而,被盗数据经常被出售给其他威胁行为者。 Ov3r_Stealer 也可能被修改以部署恶意软件和其他有效负载,例如 QakBot。

该攻击以看似托管在 OneDrive 上的恶意 PDF 文件发起,诱使用户单击“访问文档”按钮。

Trustwave 发现了在假亚马逊首席执行官 Andy Jassy Facebook 帐户上发布的 PDF 文件以及宣传数字广告机会的 Facebook 广告。

单击该按钮后,用户将被定向到一个 .URL 文件,该文件伪装成托管在 Discord 的 CDN 上的 DocuSign 文档。控制面板项 (.CPL) 文件通过快捷方式文件传递并由 Windows 控制面板进程二进制文件 (“control.exe”) 执行。

执行 CPL 文件会触发从 GitHub 检索 PowerShell 加载程序(“DATA1.txt”)以执行 Ov3r_Stealer。

#BewareOfScams #TrendingTopic #SafetyTips

免责声明:含第三方内容,不构成财务建议,并且可能包含赞助内容。 详见《条款和条件》。
0
浏览最新的加密货币新闻
⚡️ 参与加密货币领域的最新讨论
💬 与喜爱的创作者互动
👍 查看感兴趣的内容
邮箱/手机号码
相关创作者

创作者的更多内容

--
Here’s How Much Crypto Scammers Drained From Victims in January Alone The top seven victims collectively lost $17 million due to phishing signatures like ERC20 Permit, Create2, increaseAllowance, and Swap. According to Scam Sniffer, scammers stole $55 million worth of cryptocurrency in January alone and set up more than 11,000 phishing websites. Notably, most of these thefts occurred on the Ethereum $ETH mainnet, with Arbitrum$ARB , BNB $BNB , Optimism, and Polygon closely behind. Crypto Phishing Attacks Surged in January In a recent Feb. 9 thread on X, Scam Sniffer highlighted a concerning trend observed in January, noting a surge in phishing attacks coinciding with heightened activity within crypto communities following a series of airdrops in the previous month. These scams, often occurring alongside airdrops and other project activities, have impacted around 40,000 individuals. According to Scam Sniffer, fraudsters created the phishing websites in January, impersonating various projects such as Manta Network, Frame, SatoshiVM, AltLayer, Dymension, zkSync, Pyth, OpenSea, Optimism, Blast, and others. Their efforts proved successful, with the top seven victims losing $17 million in total owing to phishing signatures such as ERC20 Permit, Create2, increaseAllowance, and Swap. Scam Sniffer reported that hackers commonly exploited the ERC-20 Permit function, tricking users into unknowingly transferring funds from their non-custodial wallets under the guise of legitimate operations. Many individuals fell victim to these scams due to cybercriminals actively posting fake comments on various platforms, posing as legitimate projects like Optimism and zkSync. Crypto Cyberattacks Hit $2 Billion in 2023 Throughout 2023, scammers and hackers executed numerous cyberattacks and rug pulls, resulting in the theft of $1.9 billion worth of cryptocurrency, as reported earlier by CryptoPotato. #TrendingTopic #SCAMalerts #SafetyTips
--
Binance Joins Forces with INTERPOL to Boost Cybersecurity Worldwide Binance, a key player in the cryptocurrency exchange realm, has been actively engaged in fortifying global cybersecurity measures. Throughout 2023, the company’s specialized teams orchestrated an array of educational events, hosting over 120 seminars, workshops, and training sessions. These initiatives were designed to provide law enforcement professionals with comprehensive insights into the intricacies of the crypto landscape, equipping them with the necessary skills to combat emerging threats. Looking ahead to 2024, Binance reaffirms its dedication to bolstering cybersecurity efforts, emphasizing a proactive approach to staying ahead of evolving cyber threats and ensuring the security of the digital ecosystem. In a bid to enhance cybersecurity on a global scale, Binance has forged a strategic collaboration with INTERPOL. Recent endeavors include hosting a virtual session aimed at fostering dialogue and knowledge exchange among law enforcement officers. Representatives from INTERPOL emphasized the importance of collaborative partnerships with industry leaders like Binance, highlighting the need for effective strategies to combat cybercrime. Jarek Jakubcek, Head of Law Enforcement Training at Binance, emphasized the company’s commitment to proactive cybersecurity measures, underscoring collaboration as a cornerstone of its approach. By leveraging its expertise and resources, Binance aims to play a pivotal role in shaping a safer digital landscape, combatting cyber threats, and mitigating cryptocurrency-related crimes. #Breaking #BinanceSqaure #CyberSecurityAnalysis #TrendingTopic
--

实时新闻

查看更多

热门文章

查看更多
网站地图
Cookie Preferences
平台条款和条件