{"id":283991,"date":"2023-03-28T17:48:00","date_gmt":"2023-03-28T14:48:00","guid":{"rendered":"https:\/\/vpn.inform.click\/?p=283991"},"modified":"2023-06-20T03:32:33","modified_gmt":"2023-06-20T00:32:33","slug":"varjatud-pahavaraoht-oma-paroolide-vaikne-varastamine","status":"publish","type":"post","link":"https:\/\/vpn.inform.click\/et\/varjatud-pahavaraoht-oma-paroolide-vaikne-varastamine\/","title":{"rendered":"Varjatud pahavaraoht: oma paroolide vaikne varastamine"},"content":{"rendered":"<p>Paljud k\u00fcberjulgeolekuteadlased on j\u00f5udnud t\u00e4helepanu sellele, et paljud k\u00fcberkurjategijad kasutavad n\u00fc\u00fcd JavaScripti allalaadijate abi, et levitada kaheksat erinevat t\u00fc\u00fcpi kaugjuurdep\u00e4\u00e4su Trooja (RAT) pahavara, et saada kontroll teie Windowsi s\u00fcsteemide \u00fcle ja varastada erinevaid tundlikke andmeid.<\/p>\n<p><a href=\"https:\/\/threatresearch.ext.hp.com\/javascript-malware-dispensing-rats-into-the-wild\/\" rel=\"noopener nofollow\" class=\"external external_icon\" target=\"_blank\">HP Wolf Security k\u00fcberjulgeolekuteadlased<\/a> on nimetanud seda troojalast &quot;RATDispenseriks&quot; .<\/p>\n<p>H\u00e4kkerid kasutavad p\u00e4\u00e4supunktina <a href=\"https:\/\/vpn.inform.click\/et\/andmepuuk-kuidas-seda-ara-tunda-ja-selle-eest-kaitsta\/\" title=\"andmep\u00fc\u00fcgimeili, mis sisaldab tootetellimuse tekstifaile.\">andmep\u00fc\u00fcgimeili, mis sisaldab tootetellimuse tekstifaile.<\/a> Kui kasutaja seda faili kontrollib, k\u00e4ivitab see automaatse protsessi, mis installib RATDispenseri pahavara. H\u00e4kkerid on lisanud esialgsele JavaScriptile pika komplekti koode, et varjata seda tuvastamise eest.<\/p>\n<p>P\u00e4rast installimist levitab RATDispenser mitut erinevat t\u00fc\u00fcpi troojalasi, pahavara, klahvilogijaid ja muud pahatahtlikku sisu, et p\u00fc\u00fcda teie tundlikku teavet varastada.<\/p>\n<p>STRRAT ja WSHRAT on avastatud neljas proovis viiest, muutes need k\u00f5ige levinumaks pahavaraks. Muud t\u00fc\u00fcpi RATDispenseri kaudu levivad pahavarad on Ratty, GuLoader, Panda Stealer, Formbook ja Adwind.<\/p>\n<p>Kui Panda Stealer avastati sel aastal, siis WSHRAT on tegutsenud juba aastaid. Samuti tuvastati selle uuringu l\u00e4biviimisel ja avaldamisel RATDispenser \u00fches k\u00fcmnest viiruset\u00f5rjetarkvarast.<\/p>\n<p>Patrick Schlapfer, kes t\u00f6\u00f6tab HP Wolf Security pahavaraanal\u00fc\u00fctikuna, pidi avastatud trooja kohta \u00fctlema j\u00e4rgmist:<\/p>\n<blockquote>\n<p>Eriti murettekitav on see, et RATDispenseri tuvastab ainult umbes 11% viiruset\u00f5rjes\u00fcsteemidest, mille tulemusel juurdub see varjatud pahavara enamikul juhtudel edukalt ohvrite l\u00f5pp-punktidesse. RAT-id ja klahvilogijad kujutavad endast vaikset ohtu, aidates r\u00fcndajatel saada tagaukse kaudu ligi nakatunud arvutitele ja varastada mandaate ettev\u00f5ttekontodelt v\u00f5i isegi kr\u00fcptovaluuta rahakottidelt. Siit saavad k\u00fcberkurjategijad delikaatseid andmeid v\u00e4lja t\u00f5mmata, oma juurdep\u00e4\u00e4su eskaleerida ja m\u00f5nel juhul seda juurdep\u00e4\u00e4su lunavaragruppidele edasi m\u00fc\u00fca.<\/p>\n<\/blockquote>\n<p>Ettevaatusabin\u00f5una RATDispenseri r\u00fcnnakute vastu on teadlased soovitanud v\u00f5rguadministraatoritel vaadata \u00fcle, millist t\u00fc\u00fcpi meilimanust nende meiliv\u00e4rav lubab, mis on t\u00e4iesti ebavajalik.<\/p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>HP Wolf Security k\u00fcberturvalisuse teadlased avastasid uue trooja nimega<\/p>\n","protected":false},"author":1,"featured_media":400657,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wp_rev_ctl_limit":""},"categories":[8518,8558,8599,8588,8548,8476,8476],"tags":[],"class_list":["post-283991","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-andmekaitse","category-kindral","category-lekked","category-mitmesugust","category-uudised","category-vpn-ja-privaatsus"],"_links":{"self":[{"href":"https:\/\/vpn.inform.click\/et\/wp-json\/wp\/v2\/posts\/283991","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vpn.inform.click\/et\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vpn.inform.click\/et\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vpn.inform.click\/et\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vpn.inform.click\/et\/wp-json\/wp\/v2\/comments?post=283991"}],"version-history":[{"count":0,"href":"https:\/\/vpn.inform.click\/et\/wp-json\/wp\/v2\/posts\/283991\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vpn.inform.click\/et\/wp-json\/wp\/v2\/media\/400657"}],"wp:attachment":[{"href":"https:\/\/vpn.inform.click\/et\/wp-json\/wp\/v2\/media?parent=283991"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vpn.inform.click\/et\/wp-json\/wp\/v2\/categories?post=283991"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vpn.inform.click\/et\/wp-json\/wp\/v2\/tags?post=283991"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}