<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>卡巴斯基實驗室 &#8211; 科技島-掌握科技新聞、科技職場最新資訊</title>
	<atom:link href="https://www.technice.com.tw/tag/%e5%8d%a1%e5%b7%b4%e6%96%af%e5%9f%ba%e5%af%a6%e9%a9%97%e5%ae%a4/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.technice.com.tw</link>
	<description>專注於科技新聞、科技職場、科技知識相關資訊，包含生成式AI、人工智慧、Web 3.0、區塊鏈、科技職缺百科、生物科技、軟體發展、雲端技術等豐富內容，適合熱衷科技及從事科技專業人事第一手資訊的平台。</description>
	<lastBuildDate>Thu, 23 Jun 2022 09:01:18 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.4.2</generator>

<image>
	<url>https://www.technice.com.tw/wp-content/uploads/2022/12/cropped-wordpress_512x512-150x150.png</url>
	<title>卡巴斯基實驗室 &#8211; 科技島-掌握科技新聞、科技職場最新資訊</title>
	<link>https://www.technice.com.tw</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>台灣、越南同遭「駭客軍隊」襲擊 政府、軍事組織全被植入木馬程式</title>
		<link>https://www.technice.com.tw/techmanage/2935/</link>
					<comments>https://www.technice.com.tw/techmanage/2935/#respond</comments>
		
		<dc:creator><![CDATA[科技新知]]></dc:creator>
		<pubDate>Thu, 23 Jun 2022 09:01:16 +0000</pubDate>
				<category><![CDATA[生活]]></category>
		<category><![CDATA[產業應用]]></category>
		<category><![CDATA[資安]]></category>
		<category><![CDATA[GReAT]]></category>
		<category><![CDATA[ToddyCat]]></category>
		<category><![CDATA[卡巴斯基實驗室]]></category>
		<category><![CDATA[後門程式]]></category>
		<category><![CDATA[駭客]]></category>
		<guid isPermaLink="false">https://www.technice.com.tw/?p=2935</guid>

					<description><![CDATA[<p><img width="1280" height="853" src="https://www.technice.com.tw/wp-content/uploads/2022/06/pexels-negative-space-97077.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="pexels negative space 97077" decoding="async" srcset="https://www.technice.com.tw/wp-content/uploads/2022/06/pexels-negative-space-97077.jpg 1280w, https://www.technice.com.tw/wp-content/uploads/2022/06/pexels-negative-space-97077-300x200.jpg 300w, https://www.technice.com.tw/wp-content/uploads/2022/06/pexels-negative-space-97077-1024x682.jpg 1024w, https://www.technice.com.tw/wp-content/uploads/2022/06/pexels-negative-space-97077-768x512.jpg 768w" sizes="(max-width: 1280px) 100vw, 1280px" title="台灣、越南同遭「駭客軍隊」襲擊 政府、軍事組織全被植入木馬程式 4"></p>
<p>總部位於俄羅斯莫斯科的電腦安全公司「卡巴斯基實驗室」（Kaspersky Lab）發現自2020年底開始，新興 &#8230;<content><!-- wp:paragraph {"style":{"typography":{"fontSize":"16px"}}} --></p>
<p style="font-size:16px">總部位於俄羅斯莫斯科的電腦安全公司「卡巴斯基實驗室」（Kaspersky Lab）發現自2020年底開始，新興國家駭客組織名為ToddyCat的組織，猶如軍隊一般，開始攻擊歐洲及亞洲地區Exchange Server用戶，其中包括臺灣、越南政府機關、軍隊組織的用戶。</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph {"style":{"typography":{"fontSize":"16px"}}} --></p>
<p style="font-size:16px">今年3月以後，卡巴斯基旗下的「GReAT」（Global Research &amp; Analysis Team）透過Exchange Server 被攻擊的歷史得知，發現自2020年底起，全新駭客組織「ToddyCat」專門鎖定歐洲以及亞洲的政府、軍事單位和軍方、外包商發送惡意軟體超過一年。</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":2936,"sizeSlug":"large","linkDestination":"none"} --></p>
<figure class="wp-block-image size-large"><img src="https://www.technice.com.tw/wp-content/uploads/2022/06/pexels-negative-space-97077-1024x682.jpg" alt="" class="wp-image-2936" /></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph {"fontSize":"small"} --></p>
<p class="has-small-font-size">圖/取自Pexels</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph {"style":{"typography":{"fontSize":"16px"}}} --></p>
<p style="font-size:16px">在卡巴斯基與駭客軍隊幾次的對壘、攻防下，卡巴斯基對於這隻駭客軍隊ToddyCat所掌握的身分資訊仍舊不多，目前僅知ToddyCat專門使用被稱為「FunnyDream」的後門程式，先是駭入了Exchange Server於受害者機器上，並部署China Chopper webshell程式，進行多階段感染鏈。</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph {"style":{"typography":{"fontSize":"16px"}}} --></p>
<p style="font-size:16px">最後，在受害者網路上植入之前沒被發現的後門程式Samurai及木馬程式Ninja Trojan。而Samurai是一種被動式後門程式，經由port 80和443運作，可遠端執行任意C#程式，配合多種模組讓攻擊者執行遠端程式並在目標網路上橫向移動。</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph {"style":{"typography":{"fontSize":"16px"}}} --></p>
<p style="font-size:16px">卡巴斯基現階段先透過攻擊手段，研究出ToddyCat是進階滲透威脅（APT）的國家駭客。這些駭客瞄準台灣以及越南的政府及軍事組織，利用後門程式達到一些政治目的以及利益，而目前還無法判斷是一個還是多個不同組織的行為。（記者／劉閔）</p>
<p><!-- /wp:paragraph --></content></p>
<p>這篇文章 <a rel="nofollow" href="https://www.technice.com.tw/techmanage/2935/">台灣、越南同遭「駭客軍隊」襲擊 政府、軍事組織全被植入木馬程式</a> 最早出現於 <a rel="nofollow" href="https://www.technice.com.tw">科技島-掌握科技新聞、科技職場最新資訊</a>。</p>
]]></description>
		
					<wfw:commentRss>https://www.technice.com.tw/techmanage/2935/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
