แคสเปอร์สกี้พบมัลแวร์ใหม่ OkoBot กำหนดเป้าหมายนักลงทุนคริปโต พร้อมหลอกลวงผ่าน GitHub และ LinkedIn ปลอม

ภัยคุกคามไซเบอร์รูปแบบใหม่สำหรับนักลงทุนคริปโท

แคสเปอร์สกี้ได้เปิดเผยมัลแวร์เฟรมเวิร์กใหม่ที่ถูกออกแบบมาเพื่อโจมตีนักลงทุนสกุลเงินดิจิทัลโดยเฉพาะ ภายใต้ชื่อรหัส “OkoBot” ซึ่งเป็นภัยคุกคามที่พัฒนามาจากแคมเปญ “TookPS” ที่เคยถูกตรวจพบในปีที่ผ่านมา โดยมัลแวร์นี้ใช้กลยุทธ์ทางวิศวกรรมสังคมขั้นสูงเพื่อเจาะระบบอุปกรณ์ของเหยื่อ และสามารถขโมยข้อมูลสำคัญได้อย่างครอบคลุม

การวิเคราะห์เชิงลึกสำหรับนักลงทุน

ในฐานะนักลงทุนคริปโทและผู้ดูแลพอร์ตการลงทุน ภัยคุกคามเหล่านี้ส่งสัญญาณเตือนที่สำคัญเกี่ยวกับความจำเป็นในการยกระดับมาตรการรักษาความปลอดภัยทางไซเบอร์ โดยเฉพาะอย่างยิ่งในโลกของการเงินดิจิทัลที่ภัยคุกคามมีความซับซ้อนมากขึ้นทุกวัน

OkoBot โดดเด่นกว่ามัลแวร์ทั่วไปด้วยความสามารถในการ:

  • เจาะระบบผ่าน GitHub ปลอม: แคมเปญนี้สร้างขึ้นมากกว่า 200 โครงการ GitHub ปลอมที่แอบอ้างว่าเป็นเครื่องมือโอเพนซอร์ส ซึ่งเป็นกลยุทธ์ที่อันตรายมากเพราะนักพัฒนาและนักลงทุนมักไว้วางใจแพลตฟอร์มนี้
  • ใช้เทคนิค ClickFix: หลอกให้เหยื่อรันคำสั่งที่เป็นอันตรายผ่านการแจ้งเตือนอัปเดตปลอม ซึ่งเป็นกลยุทธ์ทางวิศวกรรมสังคมที่แยบยล
  • ขโมยข้อมูลผ่าน SSH Tunnel: เฟรมเวิร์กนี้สามารถจัดส่งเพย์โหลดที่เป็นอันตรายถึง 20 รายการผ่าน SSH Tunnel ช่วยให้ผู้โจมตีสามารถดึงข้อมูลจากเครื่องที่ติดเชื้อไปยังเซิร์ฟเวอร์ของตนได้อย่างแนบเนียน
  • โจมตีบน LinkedIn ปลอม: มีการตรวจพบแคมเปญที่แอบอ้างเป็นผู้สรรหางานในวงการ Web3 เพื่อหลอกให้นักพัฒนาโหลดและรันโปรเจกต์ที่เป็นอันตราย

แผนการโจมตีหลักของ OkoBot

  • การเก็บเกี่ยว Wallet File: OkoBot สามารถเข้าถึงและขโมยไฟล์กระเป๋าเงินคริปโทได้โดยตรง
  • การขโมยข้อมูลเบราว์เซอร์: ข้อมูลการท่องเว็บ คุกกี้ และรหัสผ่านถูกขโมยอย่างเป็นระบบ
  • การจับภาพหน้าต่างแอปพลิเคชัน: มัลแวร์สามารถจับภาพหน้าจอของวอลเล็ตและแอปพลิเคชันการเงินเพื่อขโมยทรัพย์สิน
  • การดักจับคลิปบอร์ด: เปลี่ยนที่อยู่กระเป๋าเงินที่ถูกคัดลอกไปเป็นที่อยู่ของผู้โจมตีในระหว่างการทำธุรกรรม

กลยุทธ์การป้องกันสำหรับนักลงทุน

เพื่อปกป้องพอร์ตการลงทุนคริปโทของคุณจากภัยคุกคามเหล่านี้ ควรดำเนินการดังนี้:

  • ตรวจสอบแหล่งที่มาของซอฟต์แวร์: ดาวน์โหลดเฉพาะจากเว็บไซต์ทางการและตรวจสอบลายเซ็นดิจิทัลของไฟล์
  • ใช้กระเป๋าเงินฮาร์ดแวร์: เก็บสินทรัพย์คริปโทหลักใน cold wallet หรือ hardware wallet ที่ไม่เชื่อมต่ออินเทอร์เน็ตตลอดเวลา
  • ระมัดระวังข้อเสนองานปลอม: หากมีคนแปลกหน้าติดต่อมาทาง LinkedIn พร้อมลิงก์หรือโปรเจกต์ GitHub ให้น่าสงสัยไว้ก่อน
  • อัปเดตซอฟต์แวร์ป้องกันมัลแวร์: ใช้โปรแกรม Antivirus ที่เชื่อถือได้และอัปเดตเป็นประจำ
  • เปิดใช้งาน 2FA ทุกครั้ง: ใช้ Two-Factor Authentication สำหรับทุกบัญชีที่เกี่ยวข้องกับคริปโท

Full English Translation

New Cyber Threats Targeting Crypto Investors

Kaspersky has uncovered a new malware framework specifically designed to target cryptocurrency investors, codenamed “OkoBot.” This threat has evolved from the “TookPS” campaign previously detected last year. The malware uses advanced social engineering tactics to infiltrate victims’ devices and can comprehensively steal critical data.

Deep Analysis for Investors

As a crypto investor and portfolio manager, these threats send a critical signal about the need to elevate cybersecurity measures, especially in the digital finance world where threats are becoming more sophisticated daily.

OkoBot stands out from common malware with its ability to:
Infiltrate via Fake GitHub: The campaign created over 200 fake GitHub projects posing as open-source tools, a dangerous strategy because developers and investors often trust this platform.
Use ClickFix Technique: Tricking victims into running malicious commands through fake update prompts, a sophisticated social engineering tactic.
Steal Data via SSH Tunnel: This framework can deliver up to 20 malicious payloads through an SSH tunnel, allowing attackers to discreetly extract data from infected machines to their servers.
Attack via Fake LinkedIn: Campaigns have been detected posing as Web3 recruiters to trick developers into downloading and running malicious projects.

OkoBot’s Main Attack Vectors

  • Crypto Wallet File Harvesting: OkoBot can directly access and steal cryptocurrency wallet files.
  • Browser Data Theft: Browsing data, cookies, and passwords are systematically stolen.
  • Application Window Capture: The malware can capture screenshots of wallet and financial applications to steal assets.
  • Clipboard Hijacking: Substituting copied wallet addresses with attacker-controlled addresses during transactions.

Defense Strategies for Investors

To protect your crypto portfolio from these threats, you should:
Verify Software Sources: Download only from official websites and check digital file signatures.
Use Hardware Wallets: Store primary crypto assets in cold wallets or hardware wallets not constantly connected to the internet.
Beware of Fake Job Offers: Be suspicious of strangers contacting you on LinkedIn with GitHub links or projects.
Update Anti-Malware Software: Use reliable antivirus software and update it regularly.
Enable 2FA Everywhere: Use Two-Factor Authentication for all crypto-related accounts.


อ้างอิง / Citation

Source: CryptoBriefing – Kaspersky identifies malware framework targeting crypto investors

Leave a Reply

อีเมลของคุณจะไม่แสดงให้คนอื่นเห็น ช่องข้อมูลจำเป็นถูกทำเครื่องหมาย *