TeamPCP组织去年12月首次发现,利用新蠕虫攻击云平台并瞄准伊朗机器数据

AI导读

TeamPCP是一个新出现的黑客组织,持续在互联网上发动攻击。他们首次被发现于去年12月,在云托管平台上释放蠕虫,旨在建立代理和扫描基础设施以窃取数据、部署勒索软件、进行敲诈勒索及挖矿。最近,该组织通过供应链攻击入侵了Trivy漏洞扫描器的GitHub账户,影响几乎所有版本。TeamPCP以其大规模自动化和整合知名攻击技术而著称,并使用不断演变的恶意软件控制更多系统。

AI Prism 智棱 - AI应用 分类封面图
A new hacking group has been rampaging the Internet in a persistent campaign that spreads a self-propagating and never-before-seen backdoor—and curiously a data wiper that targets Iranian machines. The group, tracked under the name TeamPCP, first gained visibility in December, when researchers from security firm Flare observed it unleashing a worm that targeted cloud-hosted platforms that weren’t properly secured. The objective was to build a distributed proxy and scanning infrastructure and then use it to compromise servers for exfiltrating data, deploying ransomware, conducting extortion, and mining cryptocurrency. The group is notable for its skill in large-scale automation and integration of well-known attack techniques. Relentless and constantly evolving More recently, TeamPCP has waged a relentless campaign that uses continuously evolving malware to bring ever more systems under its control. Late last week, it compromised virtually all versions of the widely used Trivy vulnerability scanner in a supply-chain attack after gaining privileged access to the GitHub account of Aqua Security, the Trivy creator.Read full article Comments

内容声明

本文内容基于公开市场信息与媒体报道进行整理,部分观点来自社区讨论。如涉及事实性问题,欢迎通过 xurj005@163.com 与我们指正,我们将及时核实并更新。