慢雾:朝鲜Lazarus正使用名为OtterCookie的新型窃密木马,针对加密从业者发起定向攻击

Blockbeats
06 Jun

BlockBeats 消息,6 月 6 日,慢雾安全团队最新情报显示,朝鲜 Lazarus 黑客组织正在使用名为 OtterCookie 的新型窃密木马,针对加密货币及金融从业者发起定向攻击。

共计手法包括伪造高薪职位面试/投资人洽谈、使用深度伪造 (Deepfake) 视频冒充招聘方、将恶意软件伪装成“编程测试题”或“系统更新包”。

窃取目标包括浏览器保存的登录凭证、macOS 钥匙串中的密码与数字证书,以及加密钱包信息及私钥。

慢雾建议,对主动提供的职位/投资邀约保持警惕,远程面试需多重验证,切勿运行来历不明的可执行文件,尤其是所谓“技术测试题”或“更新补丁”,强化终端防护 (EDR),部署杀毒软件并定期排查异常进程。

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10