Automatically translated.View original post

Cyber crime has skyrocketed by more than 400%.

Bitdefender reveals cyber crimes soared more than 400% from Iranian wartime opportunism

The war has always brought turmoil and opportunism, and this time with the Iranian war, it can be called opportunism - politics, prices, cyber security.

According to a report by the B2B website, Cyber Security has discussed the situation of the famous antivirus software developer Bitdefender in the Gulf Counties, a Muslim group that has had a strong relationship with Iran, with an average of 130% more attacks than before the war, and during the peak of the war, it showed a 400% spike in attacks. But Bitdefender said that the attack, when verified, predicted that it might not have come directly from the Iranian authorities, but rather from the opportunistic hackers. Hackers) during the war, because the attacks are primarily focused on the business part, such as the use of phishing scams through e-mail, claiming to be loan contracts, and financial agreements to trick victims into getting caught up in malware.

In addition, on the part of malware, Bitdefender found that hackers are headed to use every weapon available - RAT or Remote Access Trojan malware, Fileless with Multi-Stage embedded malware via PowerShell. These malware are embedded in fake files claimed to come from partners or financial institutions as mentioned above. There is also a scam to download fake applications disguised as harmless applications to be used as intermediaries for malware release by certain malware when Log in to the victim's machine, it will create a task schedule that will be re-run every 30 minutes to guarantee that the malware will be persistent on the victim's machine at all times (even with a reboot, allowing it to be embedded on the system for a long time).

# Trending # Lemon 8 Howtoo # lemon 8 diary # Cyber # freedomhack

4/29 Edited to

... Read moreในฐานะผู้ที่ติดตามและทำงานด้านเทคโนโลยีความปลอดภัยไซเบอร์มาเป็นเวลานาน ผมเห็นว่าช่วงเวลาความขัดแย้งทางการเมืองหรือสงคราม มักจะเป็นช่วงเวลาที่แฮกเกอร์จะใช้ประโยชน์จากความโกลาหลและความไม่แน่นอนในการโจมตีอย่างหนักหน่วง ความน่ากลัวของการโจมตีในช่วงสงครามอิหร่านที่ Bitdefender รายงานนั้น มันไม่ใช่แค่การเพิ่มจำนวนของการโจมตี แต่ยังแฝงด้วยเทคนิคที่ซับซ้อนขึ้น เช่น การใช้มัลแวร์แบบไฟล์เลส (Fileless malware) ที่ซ่อนตัวได้ดีมากและหลบเลี่ยงการตรวจจับจากโปรแกรมแอนตี้ไวรัสทั่วไป ผมได้เคยเจอการโจมตีลักษณะนี้ในองค์กรขนาดกลางที่ผมรับผิดชอบ ระบบถูกรบกวนจากโปรแกรมประเภท RAT ที่เปิดโอกาสให้แฮกเกอร์เข้าควบคุมเครื่องได้ จนทำให้องค์กรต้องยกระดับมาตรการความปลอดภัยเพิ่มมากขึ้น เช่น การทำระบบ Multi-factor authentication (MFA) การฝึกอบรมพนักงานให้รู้จักวิธีสังเกตอีเมลฟิชชิง และการตรวจสอบการทำงานของ Task Scheduler อย่างสม่ำเสมอ เทคนิคที่ใช้กันคือการส่งอีเมลปลอมที่ดูน่าเชื่อถือ เช่น สัญญากู้ยืมเงินหรือข้อตกลงทางธุรกิจ ในช่วงที่ทุกคนกำลังตึงเครียดและมีความกังวลทางเศรษฐกิจ เป็นช่วงเวลาที่คนทำงานอาจจะเลือกที่จะคลิกลิงก์หรือดาวน์โหลดไฟล์โดยไม่ทันระวัง ส่งผลให้ติดมัลแวร์และถูกเข้าควบคุมเครื่องโดยไม่ได้ตั้งใจ สิ่งที่ผมอยากแนะนำสำหรับผู้ใช้งานในช่วงเวลาปัจจุบันคือ ให้เพิ่มความระมัดระวังอย่างมาก โดยเฉพาะเมลที่เกี่ยวข้องกับการเงินและธุรกิจ ควรตรวจสอบให้แน่ใจว่ามาจากแหล่งที่เชื่อถือได้ก่อนเปิดไฟล์หรือคลิกลิงก์ อีกทั้งองค์กรควรลงทุนในซอฟต์แวร์ความปลอดภัยที่สามารถตรวจจับมัลแวร์แบบหลายขั้นตอนและไฟล์เลส รวมถึงมีระบบการแจ้งเตือนเมื่อพบการสร้าง Task Schedule ที่ผิดปกติด้วย เพื่อป้องกันการโจมตีที่ฝังตัวถาวรบนเครื่องผู้ใช้ ท้ายสุดนี้ สงครามหรือความวุ่นวายทางภูมิรัฐศาสตร์อาจจุดชนวนให้เกิดภัยคุกคามไซเบอร์รุนแรงขึ้น ดังนั้นการตื่นตัวและยกระดับความปลอดภัยไซเบอร์ทั้งในระดับบุคคลและองค์กร จึงเป็นสิ่งจำเป็นอย่างยิ่งในยุคนี้