Someone targeted security researchers using a fake crypto conference as a lure
Someone targeted security researchers using a fake crypto conference as a lure
有人利用虚假加密货币会议诱骗安全研究人员
If you are a malicious hacker, cybersecurity professionals may very well be the worst people in the world to try to hack, as there is a very good chance they are going to catch you. 如果你是一名恶意黑客,网络安全专家很可能是你在这个世界上最不该尝试攻击的对象,因为他们极有可能识破你的伎俩。
A person pretending to work for a leading crypto news site targeted several cybersecurity professionals around the time of the Black Hat and Def Con hacking conferences earlier this month. The hacker approached attendees on the social media site X, both via public replies and DMs, and then leveraged Google Docs in an attempt to trick the targets into installing malware, according to researchers. 本月初,在 Black Hat 和 Def Con 黑客大会期间,一名冒充知名加密货币新闻网站员工的人员针对多位网络安全专家发起了攻击。据研究人员称,该黑客通过社交媒体平台 X(原 Twitter)联系参会者,既有公开回复也有私信,随后利用 Google Docs 试图诱骗目标安装恶意软件。
On Wednesday, security firm Huntress published a blog post detailing the hacking campaign, which targeted one of its researchers, who pretended to go along with it to learn what the hacker was trying to do. In broken English, the hacker asked the researcher if they had plans to attend a conference next, and then mentioned a conference allegedly organized by the crypto news website, according to a screenshot of the conversation. 周三,安全公司 Huntress 发布了一篇博客文章,详细介绍了这一黑客行动。该行动针对了 Huntress 的一名研究人员,而这名研究人员假装配合,以便探明黑客的意图。根据对话截图显示,黑客用蹩脚的英语询问研究人员是否有计划参加接下来的会议,随后提到了一个据称由该加密货币新闻网站组织的会议。
After that, the hacker shared a legitimate Google Doc that looked like it was a planning document for the fake conference. The document displayed a sidebar designed to make the target think it was encrypted. The goal was to first trick the target into entering a fake decryption key provided by the hacker. That was the first step in a process that would lead to the installation of malware for macOS and Windows, depending on the operating system used by the target, according to Huntress. 此后,黑客分享了一个合法的 Google 文档,看起来像是该虚假会议的规划文件。文档中显示了一个侧边栏,旨在让目标误以为文档已加密。其目的是先诱骗目标输入黑客提供的虚假解密密钥。据 Huntress 称,这是整个攻击流程的第一步,随后会根据目标所使用的操作系统,安装 macOS 或 Windows 恶意软件。
To make the sidebar appear real, the hacker used Google App Script, a platform that allows developers to customize the user interface of Google Docs with menus and sidebars, for example. 为了让侧边栏看起来真实,黑客使用了 Google App Script,这是一个允许开发者通过菜单和侧边栏等元素自定义 Google Docs 用户界面的平台。
The hacker tried to trick Huntress’ researcher into installing an infostealer for Apple computers; a remote desktop viewing tool repurposed as malware for Windows; and a fake installer for the cryptocurrency wallet Ledger. The person behind the account identified by Huntress researchers as the hacker did not respond when TechCrunch sent them a private message on X. 黑客试图诱骗 Huntress 的研究人员安装针对苹果电脑的信息窃取程序、一个被改装为 Windows 恶意软件的远程桌面查看工具,以及一个虚假的加密货币钱包 Ledger 安装程序。当 TechCrunch 在 X 上向该账号发送私信时,被 Huntress 研究人员认定为黑客的账号持有者并未回应。
Hackers of all kinds — whether they are unknown government hackers using advanced spyware or North Korean government hackers using fake Twitter profiles — have targeted cybersecurity professionals before. What made this campaign a bit more believable was the use of a legitimate Google Doc and Google feature. Google did not immediately respond when TechCrunch reached out asking if the company had seen this or similar hacking campaigns. 各类黑客——无论是使用高级间谍软件的未知政府黑客,还是使用虚假 Twitter 个人资料的朝鲜政府黑客——此前都曾将网络安全专家作为攻击目标。这次行动之所以更具迷惑性,是因为它利用了合法的 Google 文档和 Google 的功能。当 TechCrunch 联系 Google 询问该公司是否发现此类或类似的黑客行动时,Google 未能立即做出回应。