Thứ Hai, Tháng Hai 6, 2023
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
No Result
View All Result
Home Tech

Chinese hackers target online casinos with GamePlayerFramework Malware

19 Tháng Mười, 2022
in Tech
0
Chinese hackers target online casinos with GamePlayerFramework Malware
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter

Các bài viết liên quan:

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022

DiceyF Chinese hacker

An Advanced Persistent Threat (APT) group that has source from China codenamed DiceyF is involved in a series of attacks targeting online casinos in Southeast Asia over the years.

Company network security Russia’s Kaspersky said the activity was consistent with a series of other intrusions carried out by Earth Berberoka (aka GamblingPuppet) and DRBControl, citing similarities in tactics and targeting as well as overuse of the malware. Secure messaging app.

“Maybe we have a combination of spies and [intellectual property] Researchers Kurt Baumgartner and Georgy Kucherin said in a technical paper published this week.

The starting point of the investigation was in November 2021 when Kaspersky said it detected various PlugX loaders and other payloads deployed through the security package deployment and employee monitoring service.

Malware GamePlayerFramework

The original infection method – distributing the framework through security solution packages – allowed the threat actor to “perform cyber espionage activities with some degree of stealth”, the company claims.

Later, the same security package implementation service was said to have been used to provide the so-called GamePlayerFramework, a C# variant of malware based on C++ called PuppetLoader.

This ‘framework’ includes a downloader, launcher, and a set of plugins that provide remote access and steal keystrokes and clipboard data, the researchers explain.

Malware GamePlayerFramework

Signs suggest that the DiceyF operation is a follow-up to Earth Berberoka’s campaign with a retooled malware toolkit, even if the framework is maintained through two separate forks named Tifa and Yuna, comes with different modules with different levels of complexity.

While the Tifa branch contains the downloader and core components, Yuna is more functionally complex, consisting of a downloader, a set of plugins, and at least 12 PuppetLoader modules. That said, both branches are said to be under active and incremental updates.

Regardless of the variant used, the GamePlayerFramework, once launched, connects to command and control (C2) and transmits information about the compromised server and clipboard contents, then C2 responds with one of 15 commands that allows malware to take control of the machine.

This also includes launching a plugin on the victim system that can be downloaded from the C2 server when the framework is initialized or retrieved with the “InstallPlugin” command sent by the server.

In turn, these plugins can steal cookies from Google Chrome and Mozilla Firefox browsers, log keystrokes and clipboard data, establish virtual desktop sessions, and even remotely connect to machines via SSH. .

Kaspersky also pointed out the use of a malicious application that mimics another software called Mango Employee Account Data Synchronizer, a messaging application used for targeted audiences, to remove GamePlayerFramework in the network.

“There are many interesting features of the DiceyF and TTP campaigns,” the researchers said. “The team modifies their codebase over time and develops functionality in the code throughout their forays.”

“To ensure that victims do not become suspicious of camouflage implantation, the attackers obtained information about the targeted organizations (such as the tier where the organization’s IT department is located) and it goes inside the graphical window displayed to the victim.”

Related Posts

Previous Post

The most delicious and delicious Can Tho Tet cake addresses

Next Post

How to open the Downloads folder, find the downloaded file

Megusta

Megusta

Related Posts

5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
Instruction how to use OBS streaming software

Features, settings and how to use OBS streaming software through 9 simple steps

25 Tháng Mười Hai, 2022
What is Trans woman?  What is Transgender Women?

What is Trans woman? What is Transgender Women?

23 Tháng Mười Hai, 2022
Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

22 Tháng Mười Hai, 2022
How to get 50 free coins of SkyJoy App to redeem

How to get 50 free coins of SkyJoy App to redeem

21 Tháng Mười Hai, 2022
Load More
Next Post
How to open the Downloads folder, find the downloaded file

How to open the Downloads folder, find the downloaded file

Trả lời Hủy

Email của bạn sẽ không được hiển thị công khai. Các trường bắt buộc được đánh dấu *

Bài viết mới

How to get travel insurance
Đời sống

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly
Phần mềm

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games
Software

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power
Software

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 
Tech

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software
Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022
W3Schools

Ads

Contact: [email protected]

DMCA.com Protection Status

Categories

  • Android
  • Cạm bẫy tâm lí
  • Chưa được phân loại
  • Đồ họa
  • Đời sống
  • Gen Z
  • Health
  • iOS
  • Kĩ năng mềm
  • News
  • Nhà mạng
  • Phần mềm
  • Phần mềm đồ họa
  • Review sách
  • Software
  • Tech
  • Thiết kế ảnh
  • Thiết kế video
  • Thủ thuật
  • Travel
  • Văn hóa Nam Bộ
  • Văn học
  • Window

Browse by Tag

ai là triệu phú android Apple browser Bullet Journal bản thân chai pin Chỉnh ảnh data domain download fshare game game show giả lập màu hosting IKEA ios khuyến mãi kinh doanh kiến thức kiểm tra pin messenger miễn phí mua sắm Máy ảnh mạng network nghệ thuật ngôn ngữ nhà Trần pin laptop quảng cáo tiếng anh trạng thái Trần Thủ Độ tên miền tắt hoạt động từ vựng video viettel window 10 word zalo Đơn giản

Recent News

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023

Trang tin nóng hổi - vừa thổi vừa xem

No Result
View All Result
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z

Trang tin nóng hổi - vừa thổi vừa xem