{"id":20242,"date":"2024-08-27T16:36:09","date_gmt":"2024-08-27T09:36:09","guid":{"rendered":"https:\/\/thegioifirewall.com\/?p=20242"},"modified":"2025-03-24T07:27:22","modified_gmt":"2025-03-24T07:27:22","slug":"nhung-ke-tan-cong-ransomware-gioi-thieu-sat-thu-edr-moi-vao-kho-vu-khi-cua-chung","status":"publish","type":"post","link":"https:\/\/vacif.com\/en\/nhung-ke-tan-cong-ransomware-gioi-thieu-sat-thu-edr-moi-vao-kho-vu-khi-cua-chung\/","title":{"rendered":"NH\u1eeeNG K\u1eba T\u1ea4N C\u00d4NG RANSOMWARE GI\u1edaI THI\u1ec6U S\u00c1T TH\u1ee6 EDR M\u1edaI V\u00c0O KHO V\u0168 KH\u00cd C\u1ee6A CH\u00daNG"},"content":{"rendered":"\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1009\" height=\"564\" src=\"http:\/\/aws.vacif.com\/wp-content\/uploads\/sites\/3\/2024\/08\/nhung-ke-tan-cong-ransomware-gioi-thieu-sat-thu-edr-moi-vao-kho-vu-khi-cua-chung.png\" alt=\"\" class=\"wp-image-20252\" srcset=\"https:\/\/vacif.com\/en\/wp-content\/uploads\/sites\/3\/2024\/08\/nhung-ke-tan-cong-ransomware-gioi-thieu-sat-thu-edr-moi-vao-kho-vu-khi-cua-chung.png 1009w, https:\/\/vacif.com\/en\/wp-content\/uploads\/sites\/3\/2024\/08\/nhung-ke-tan-cong-ransomware-gioi-thieu-sat-thu-edr-moi-vao-kho-vu-khi-cua-chung-600x335.png 600w, https:\/\/vacif.com\/en\/wp-content\/uploads\/sites\/3\/2024\/08\/nhung-ke-tan-cong-ransomware-gioi-thieu-sat-thu-edr-moi-vao-kho-vu-khi-cua-chung-300x168.png 300w, https:\/\/vacif.com\/en\/wp-content\/uploads\/sites\/3\/2024\/08\/nhung-ke-tan-cong-ransomware-gioi-thieu-sat-thu-edr-moi-vao-kho-vu-khi-cua-chung-768x429.png 768w\" sizes=\"auto, (max-width: 1009px) 100vw, 1009px\" \/><\/figure>\n\n\n\n<p>Sophos ph\u00e1t hi\u1ec7n ra c\u00e1c t\u00e1c nh\u00e2n \u0111e d\u1ecda \u0111\u1eb1ng sau ransomware RansomHub s\u1eed d\u1ee5ng EDRKillShifter trong c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng<\/p>\n\n\n\n<p>Vi\u1ebft b\u1edfi Andreas Klopsch<\/p>\n\n\n\n<p><a href=\"https:\/\/news.sophos.com\/en-us\/2024\/08\/14\/edr-kill-shifter\/\"><strong>August 14, 2024<\/strong><\/a><\/p>\n\n\n\n<p>C\u00e1c nh\u00e0 ph\u00e2n t\u00edch c\u1ee7a Sophos g\u1ea7n \u0111\u00e2y \u0111\u00e3 ph\u00e1t hi\u1ec7n ra m\u1ed9t ti\u1ec7n \u00edch di\u1ec7t EDR m\u1edbi \u0111ang \u0111\u01b0\u1ee3c m\u1ed9t nh\u00f3m t\u1ed9i ph\u1ea1m tri\u1ec3n khai, nh\u1eefng k\u1ebb \u0111ang c\u1ed1 g\u1eafng t\u1ea5n c\u00f4ng m\u1ed9t t\u1ed5 ch\u1ee9c b\u1eb1ng ph\u1ea7n m\u1ec1m t\u1ed1ng ti\u1ec1n c\u00f3 t\u00ean l\u00e0 RansomHub. M\u1eb7c d\u00f9 cu\u1ed9c t\u1ea5n c\u00f4ng b\u1eb1ng ph\u1ea7n m\u1ec1m t\u1ed1ng ti\u1ec1n cu\u1ed1i c\u00f9ng \u0111\u00e3 kh\u00f4ng th\u00e0nh c\u00f4ng, nh\u01b0ng qu\u00e1 tr\u00ecnh ph\u00e2n t\u00edch h\u1eadu qu\u1ea3 c\u1ee7a cu\u1ed9c t\u1ea5n c\u00f4ng \u0111\u00e3 ti\u1ebft l\u1ed9 s\u1ef1 t\u1ed3n t\u1ea1i c\u1ee7a m\u1ed9t c\u00f4ng c\u1ee5 m\u1edbi \u0111\u01b0\u1ee3c thi\u1ebft k\u1ebf \u0111\u1ec3 ch\u1ea5m d\u1ee9t ph\u1ea7n m\u1ec1m b\u1ea3o v\u1ec7 \u0111i\u1ec3m cu\u1ed1i. Ch\u00fang t\u00f4i g\u1ecdi c\u00f4ng c\u1ee5 n\u00e0y l\u00e0 EDRKillShifter.&nbsp;<\/p>\n\n\n\n<p>T\u1eeb n\u0103m 2022, ch\u00fang t\u00f4i \u0111\u00e3 ch\u1ee9ng ki\u1ebfn \u200b\u200bs\u1ef1 gia t\u0103ng v\u1ec1 m\u1ee9c \u0111\u1ed9 tinh vi c\u1ee7a ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i \u0111\u01b0\u1ee3c thi\u1ebft k\u1ebf \u0111\u1ec3 v\u00f4 hi\u1ec7u h\u00f3a c\u00e1c h\u1ec7 th\u1ed1ng EDR tr\u00ean h\u1ec7 th\u1ed1ng b\u1ecb nhi\u1ec5m, v\u00ec kh\u00e1ch h\u00e0ng ng\u00e0y c\u00e0ng s\u1eed d\u1ee5ng c\u00f4ng c\u1ee5 EDR \u0111\u1ec3 b\u1ea3o v\u1ec7 c\u00e1c \u0111i\u1ec3m cu\u1ed1i. Sophos tr\u01b0\u1edbc \u0111\u00e2y \u0111\u00e3 c\u00f4ng b\u1ed1&nbsp;<a href=\"https:\/\/news.sophos.com\/en-us\/2023\/04\/19\/aukill-edr-killer-malware-abuses-process-explorer-driver\/\">nghi\u00ean c\u1ee9u v\u1ec1 AuKill<\/a>&nbsp;, m\u1ed9t c\u00f4ng c\u1ee5 ti\u00eau di\u1ec7t EDR m\u00e0 Sophos X-Ops ph\u00e1t hi\u1ec7n ra v\u00e0o n\u0103m ngo\u00e1i \u0111ang \u0111\u01b0\u1ee3c b\u00e1n th\u01b0\u01a1ng m\u1ea1i trong c\u00e1c th\u1ecb tr\u01b0\u1eddng t\u1ed9i ph\u1ea1m.&nbsp;<\/p>\n\n\n\n<p>Trong s\u1ef1 c\u1ed1 v\u00e0o th\u00e1ng 5, nh\u1eefng k\u1ebb t\u1ea5n c\u00f4ng &#8211; ch\u00fang t\u00f4i \u01b0\u1edbc t\u00ednh v\u1edbi m\u1ee9c \u0111\u1ed9 tin c\u1eady v\u1eeba ph\u1ea3i r\u1eb1ng c\u00f4ng c\u1ee5 n\u00e0y \u0111ang \u0111\u01b0\u1ee3c nhi\u1ec1u k\u1ebb t\u1ea5n c\u00f4ng s\u1eed d\u1ee5ng &#8211; \u0111\u00e3 c\u1ed1 g\u1eafng s\u1eed d\u1ee5ng EDRKillShifter \u0111\u1ec3 ch\u1ea5m d\u1ee9t b\u1ea3o v\u1ec7 c\u1ee7a Sophos tr\u00ean m\u00e1y t\u00ednh m\u1ee5c ti\u00eau, nh\u01b0ng c\u00f4ng c\u1ee5 \u0111\u00e3 th\u1ea5t b\u1ea1i. Sau \u0111\u00f3, ch\u00fang c\u1ed1 g\u1eafng ch\u1ea1y t\u1ec7p th\u1ef1c thi ransomware tr\u00ean m\u00e1y m\u00e0 ch\u00fang ki\u1ec3m so\u00e1t, nh\u01b0ng c\u0169ng th\u1ea5t b\u1ea1i khi t\u00ednh n\u0103ng CryptoGuard c\u1ee7a t\u00e1c nh\u00e2n \u0111i\u1ec3m cu\u1ed1i \u0111\u01b0\u1ee3c k\u00edch ho\u1ea1t.&nbsp;<\/p>\n\n\n\n<p><strong>EDRKillShifter ho\u1ea1t \u0111\u1ed9ng nh\u01b0 th\u1ebf n\u00e0o&nbsp;<\/strong><\/p>\n\n\n\n<p>C\u00f4ng c\u1ee5 EDRKillShifter l\u00e0 m\u1ed9t ch\u01b0\u01a1ng tr\u00ecnh th\u1ef1c thi \u201cloader\u201d \u2013 m\u1ed9t c\u01a1 ch\u1ebf ph\u00e2n ph\u1ed1i cho tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n h\u1ee3p l\u1ec7 d\u1ec5 b\u1ecb l\u1ea1m d\u1ee5ng (c\u00f2n \u0111\u01b0\u1ee3c g\u1ecdi l\u00e0 c\u00f4ng c\u1ee5 \u201cmang tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n d\u1ec5 b\u1ecb t\u1ea5n c\u00f4ng c\u1ee7a ri\u00eang b\u1ea1n\u201d ho\u1eb7c BYOVD). T\u00f9y thu\u1ed9c v\u00e0o y\u00eau c\u1ea7u c\u1ee7a t\u00e1c nh\u00e2n \u0111e d\u1ecda, n\u00f3 c\u00f3 th\u1ec3 ph\u00e2n ph\u1ed1i nhi\u1ec1u lo\u1ea1i t\u1ea3i tr\u1ecdng tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n kh\u00e1c nhau.&nbsp;<\/p>\n\n\n\n<p>C\u00f3 ba b\u01b0\u1edbc trong qu\u00e1 tr\u00ecnh th\u1ef1c thi c\u1ee7a tr\u00ecnh t\u1ea3i n\u00e0y. K\u1ebb t\u1ea5n c\u00f4ng ph\u1ea3i th\u1ef1c thi EDRKillShifter b\u1eb1ng d\u00f2ng l\u1ec7nh bao g\u1ed3m chu\u1ed7i m\u1eadt kh\u1ea9u. Khi ch\u1ea1y v\u1edbi m\u1eadt kh\u1ea9u \u0111\u00fang, t\u1ec7p th\u1ef1c thi s\u1ebd gi\u1ea3i m\u00e3 m\u1ed9t t\u00e0i nguy\u00ean nh\u00fang c\u00f3 t\u00ean l\u00e0 BIN v\u00e0 th\u1ef1c thi n\u00f3 trong b\u1ed9 nh\u1edb.&nbsp;<\/p>\n\n\n\n<p>M\u00e3 BIN gi\u1ea3i n\u00e9n v\u00e0 th\u1ef1c thi payload cu\u1ed1i c\u00f9ng. Payload cu\u1ed1i c\u00f9ng n\u00e0y, \u0111\u01b0\u1ee3c vi\u1ebft b\u1eb1ng ng\u00f4n ng\u1eef l\u1eadp tr\u00ecnh Go, s\u1ebd lo\u1ea1i b\u1ecf v\u00e0 khai th\u00e1c m\u1ed9t trong nhi\u1ec1u tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n h\u1ee3p ph\u00e1p, d\u1ec5 b\u1ecb t\u1ea5n c\u00f4ng kh\u00e1c nhau \u0111\u1ec3 gi\u00e0nh \u0111\u01b0\u1ee3c c\u00e1c \u0111\u1eb7c quy\u1ec1n \u0111\u1ee7 \u0111\u1ec3 g\u1ee1 b\u1ecf b\u1ea3o v\u1ec7 c\u1ee7a c\u00f4ng c\u1ee5 EDR.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"http:\/\/aws.vacif.com\/wp-content\/uploads\/sites\/3\/2024\/08\/nhung-ke-tan-cong-ransomware-gioi-thieu-sat-thu-edr-moi-vao-kho-vu-khi-cua-chung-1.png\" alt=\"\" class=\"wp-image-20244\"\/><\/figure>\n\n\n\n<p><strong>T\u1ed5ng quan c\u1ea5p cao v\u1ec1 quy tr\u00ecnh th\u1ef1c hi\u1ec7n b\u1ed9 t\u1ea3i<\/strong><\/p>\n\n\n\n<p><strong>L\u1ed9t b\u1ecf l\u1edbp \u0111\u1ea7u ti\u00ean&nbsp;<\/strong><\/p>\n\n\n\n<p>Ph\u00e2n t\u00edch h\u1eddi h\u1ee3t cho th\u1ea5y t\u1ea5t c\u1ea3 c\u00e1c m\u1eabu \u0111\u1ec1u chia s\u1ebb c\u00f9ng m\u1ed9t d\u1eef li\u1ec7u phi\u00ean b\u1ea3n. T\u00ean t\u1ec7p g\u1ed1c l\u00e0 Loader.exe v\u00e0 t\u00ean s\u1ea3n ph\u1ea9m c\u1ee7a n\u00f3 l\u00e0 ARK-Game. (M\u1ed9t s\u1ed1 th\u00e0nh vi\u00ean c\u1ee7a nh\u00f3m nghi\u00ean c\u1ee9u suy \u0111o\u00e1n r\u1eb1ng t\u00e1c nh\u00e2n \u0111e d\u1ecda c\u1ed1 g\u1eafng ng\u1ee5y trang t\u1ea3i tr\u1ecdng cu\u1ed1i c\u00f9ng th\u00e0nh m\u1ed9t tr\u00f2 ch\u01a1i m\u00e1y t\u00ednh ph\u1ed5 bi\u1ebfn c\u00f3 t\u00ean l\u00e0 ARK: Survival Evolved.)&nbsp;&nbsp;<\/p>\n\n\n\n<p>Thu\u1ed9c t\u00ednh ng\u00f4n ng\u1eef c\u1ee7a t\u1ec7p nh\u1ecb ph\u00e2n l\u00e0 ti\u1ebfng Nga, cho bi\u1ebft t\u00e1c gi\u1ea3 ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i \u0111\u00e3 bi\u00ean d\u1ecbch t\u1ec7p th\u1ef1c thi tr\u00ean m\u00e1y t\u00ednh c\u00f3 c\u00e0i \u0111\u1eb7t b\u1ea3n \u0111\u1ecba h\u00f3a ti\u1ebfng Nga.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"http:\/\/aws.vacif.com\/wp-content\/uploads\/sites\/3\/2024\/08\/nhung-ke-tan-cong-ransomware-gioi-thieu-sat-thu-edr-moi-vao-kho-vu-khi-cua-chung-2.png\" alt=\"\" class=\"wp-image-20245\"\/><\/figure>\n\n\n\n<p><strong>Th\u00f4ng tin phi\u00ean b\u1ea3n c\u1ee7a EDRKillShifter nh\u01b0 \u0111\u01b0\u1ee3c hi\u1ec3n th\u1ecb trong CFF Explorer<\/strong><\/p>\n\n\n\n<p>T\u1ea5t c\u1ea3 c\u00e1c m\u1eabu \u0111\u1ec1u y\u00eau c\u1ea7u m\u1eadt kh\u1ea9u 64 k\u00fd t\u1ef1 duy nh\u1ea5t \u0111\u01b0\u1ee3c truy\u1ec1n \u0111\u1ebfn d\u00f2ng l\u1ec7nh. N\u1ebfu m\u1eadt kh\u1ea9u sai (ho\u1eb7c kh\u00f4ng \u0111\u01b0\u1ee3c cung c\u1ea5p), l\u1ec7nh s\u1ebd kh\u00f4ng th\u1ef1c thi.&nbsp;<\/p>\n\n\n\n<p>Vi\u1ec7c th\u1ef1c thi s\u1ebd kh\u00f4ng th\u00e0nh c\u00f4ng n\u1ebfu ng\u01b0\u1eddi d\u00f9ng kh\u00f4ng cung c\u1ea5p \u0111\u00fang m\u1eadt kh\u1ea9u v\u00e0o b\u1ea3ng \u0111i\u1ec1u khi\u1ec3n khi ch\u01b0\u01a1ng tr\u00ecnh th\u1ef1c thi<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" src=\"http:\/\/aws.vacif.com\/wp-content\/uploads\/sites\/3\/2024\/08\/nhung-ke-tan-cong-ransomware-gioi-thieu-sat-thu-edr-moi-vao-kho-vu-khi-cua-chung-3.png\" alt=\"\" class=\"wp-image-20246\"\/><\/figure>\n<\/div>\n\n\n<p>Khi \u0111\u01b0\u1ee3c th\u1ef1c thi, EDRKillShifter t\u1ea3i m\u1ed9t t\u00e0i nguy\u00ean \u0111\u01b0\u1ee3c m\u00e3 h\u00f3a c\u00f3 t\u00ean BIN, \u0111\u01b0\u1ee3c nh\u00fang b\u00ean trong ch\u00ednh n\u00f3, v\u00e0o b\u1ed9 nh\u1edb. N\u00f3 c\u0169ng sao ch\u00e9p d\u1eef li\u1ec7u \u0111\u00f3 v\u00e0o m\u1ed9t t\u1ec7p m\u1edbi c\u00f3 t\u00ean Config.ini v\u00e0 ghi t\u1ec7p \u0111\u00f3 v\u00e0o c\u00f9ng m\u1ed9t v\u1ecb tr\u00ed h\u1ec7 th\u1ed1ng t\u1ec7p n\u01a1i t\u1ec7p nh\u1ecb ph\u00e2n \u0111\u01b0\u1ee3c th\u1ef1c thi.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Sau \u0111\u00f3, m\u00e3 t\u1ea3i s\u1ebd ph\u00e2n b\u1ed5 m\u1ed9t trang b\u1ed9 nh\u1edb m\u1edbi b\u1eb1ng VirtualAlloc v\u00e0 ghi n\u1ed9i dung \u0111\u01b0\u1ee3c m\u00e3 h\u00f3a v\u00e0o trang m\u1edbi \u0111\u01b0\u1ee3c ph\u00e2n b\u1ed5. Sau \u0111\u00f3, ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i x\u00f3a t\u1ec7p config.ini v\u00e0 ti\u1ebfn h\u00e0nh gi\u1ea3i m\u00e3 t\u1eadp h\u1ee3p c\u00e1c t\u1ea3i tr\u1ecdng ti\u1ebfp theo \u2013 tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n c\u00f3 th\u1ec3 l\u1ea1m d\u1ee5ng v\u00e0 t\u1ec7p nh\u1ecb ph\u00e2n Go. Tr\u00ecnh t\u1ea3i s\u1eed d\u1ee5ng h\u00e0m b\u0103m SHA256 c\u1ee7a m\u1eadt kh\u1ea9u \u0111\u1ea7u v\u00e0o l\u00e0m kh\u00f3a gi\u1ea3i m\u00e3 c\u1ee7a c\u00e1c t\u1ea3i tr\u1ecdng l\u1edbp th\u1ee9 hai.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"http:\/\/aws.vacif.com\/wp-content\/uploads\/sites\/3\/2024\/08\/nhung-ke-tan-cong-ransomware-gioi-thieu-sat-thu-edr-moi-vao-kho-vu-khi-cua-chung-4.png\" alt=\"\" class=\"wp-image-20247\"\/><\/figure>\n\n\n\n<p><strong>M\u00e3 gi\u1ea3 c\u1ee7a ch\u01b0\u01a1ng tr\u00ecnh gi\u1ea3i m\u00e3 l\u1edbp th\u1ee9 hai c\u1ee7a ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i EDRKillShifter<\/strong><\/p>\n\n\n\n<p>N\u1ebfu ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i gi\u1ea3i m\u00e3 th\u00e0nh c\u00f4ng d\u1eef li\u1ec7u l\u1edbp th\u1ee9 hai, n\u00f3 s\u1ebd t\u1ea1o m\u1ed9t lu\u1ed3ng m\u1edbi v\u00e0 b\u1eaft \u0111\u1ea7u th\u1ef1c thi trong lu\u1ed3ng \u0111\u00f3.&nbsp;<\/p>\n\n\n\n<p><strong>T\u1ea3i EDR killer cu\u1ed1i c\u00f9ng v\u00e0o b\u1ed9 nh\u1edb&nbsp;<\/strong><\/p>\n\n\n\n<p>Giai \u0111o\u1ea1n th\u1ee9 hai \u0111\u01b0\u1ee3c che gi\u1ea5u th\u00f4ng qua vi\u1ec7c s\u1eed d\u1ee5ng k\u1ef9 thu\u1eadt m\u00e3 t\u1ef1 s\u1eeda \u0111\u1ed5i. Trong th\u1eddi gian ch\u1ea1y, l\u1edbp th\u1ee9 hai thay \u0111\u1ed5i c\u00e1c l\u1ec7nh c\u1ee7a ch\u00ednh n\u00f3. V\u00ec c\u00e1c l\u1ec7nh th\u1ef1c thi th\u1ef1c t\u1ebf ch\u1ec9 \u0111\u01b0\u1ee3c ti\u1ebft l\u1ed9 trong qu\u00e1 tr\u00ecnh th\u1ef1c thi, n\u00ean c\u1ea7n c\u00f3 th\u00eam c\u00f4ng c\u1ee5 ho\u1eb7c m\u00f4 ph\u1ecfng \u0111\u1ec3 ph\u00e2n t\u00edch.&nbsp;&nbsp;<\/p>\n\n\n\n<p>H\u00ecnh b\u00ean d\u01b0\u1edbi minh h\u1ecda th\u00eam v\u1ec1 k\u1ef9 thu\u1eadt n\u00e0y. Ph\u1ea7n \u0111\u1ea7u ti\u00ean cho th\u1ea5y s\u1ef1 kh\u1edfi \u0111\u1ea7u c\u1ee7a l\u1edbp m\u00e3 t\u1ef1 s\u1eeda \u0111\u1ed5i. T\u1ea5t c\u1ea3 c\u00e1c l\u1ec7nh sau l\u1ec7nh g\u1ecdi \u0111\u1ea7u ti\u00ean trong qu\u00e1 tr\u00ecnh th\u00e1o r\u1eddi \u0111\u1ec1u v\u00f4 ngh\u0129a t\u1ea1i th\u1eddi \u0111i\u1ec3m n\u00e0y. N\u1ebfu ch\u00fang ta xem l\u1ea1i c\u00f9ng m\u1ed9t kh\u1ed1i l\u1ec7nh sau khi th\u1ef1c hi\u1ec7n l\u1ec7nh g\u1ecdi \u0111\u1ea7u ti\u00ean, ch\u00fang ta s\u1ebd th\u1ea5y m\u1ed9t t\u1eadp l\u1ec7nh kh\u00e1c. L\u1ec7nh g\u1ecdi \u0111\u1ea7u ti\u00ean s\u1eeda \u0111\u1ed5i t\u1eadp l\u1ec7nh ti\u1ebfp theo, sau \u0111\u00f3 s\u1eeda \u0111\u1ed5i t\u1eadp l\u1ec7nh ti\u1ebfp theo, v.v.&nbsp;&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"http:\/\/aws.vacif.com\/wp-content\/uploads\/sites\/3\/2024\/08\/nhung-ke-tan-cong-ransomware-gioi-thieu-sat-thu-edr-moi-vao-kho-vu-khi-cua-chung-5.png\" alt=\"\" class=\"wp-image-20248\"\/><\/figure>\n\n\n\n<p><strong>EDRKillShifter s\u1eed d\u1ee5ng m\u00e3 t\u1ef1 s\u1eeda \u0111\u1ed5i \u0111\u1ec3 thay \u0111\u1ed5i m\u1ecdi l\u1ec7nh ti\u1ebfp theo<\/strong><\/p>\n\n\n\n<p>M\u1ee5c \u0111\u00edch duy nh\u1ea5t c\u1ee7a l\u1edbp gi\u1ea3i m\u00e3 cu\u1ed1i c\u00f9ng l\u00e0 t\u1ea3i d\u1eef li\u1ec7u cu\u1ed1i c\u00f9ng v\u00e0o b\u1ed9 nh\u1edb m\u1ed9t c\u00e1ch \u0111\u1ed9ng v\u00e0 th\u1ef1c thi n\u00f3.&nbsp;<\/p>\n\n\n\n<p><strong>Ph\u00e2n t\u00edch t\u1ea3i tr\u1ecdng cu\u1ed1i c\u00f9ng&nbsp;<\/strong><\/p>\n\n\n\n<p>T\u1ea5t c\u1ea3 c\u00e1c m\u1eabu ch\u00fang t\u00f4i ph\u00e2n t\u00edch \u0111\u1ec1u th\u1ef1c thi m\u1ed9t bi\u1ebfn th\u1ec3 EDR killer kh\u00e1c nhau trong b\u1ed9 nh\u1edb. T\u1ea5t c\u1ea3 ch\u00fang \u0111\u1ec1u \u0111\u01b0\u1ee3c vi\u1ebft b\u1eb1ng Go v\u00e0 \u0111\u01b0\u1ee3c l\u00e0m t\u1ed1i ngh\u0129a (c\u00f3 th\u1ec3 th\u00f4ng qua vi\u1ec7c s\u1eed d\u1ee5ng m\u1ed9t c\u00f4ng c\u1ee5 ngu\u1ed3n m\u1edf c\u00f3 t\u00ean&nbsp;<a href=\"https:\/\/github.com\/unixpickle\/gobfuscate\">gobfuscate<\/a>&nbsp;)&nbsp;. C\u00e1c tr\u00ecnh l\u00e0m t\u1ed1i ngh\u0129a l\u00e0 c\u00e1c c\u00f4ng c\u1ee5 \u0111\u01b0\u1ee3c thi\u1ebft k\u1ebf \u0111\u1ec3 c\u1ea3n tr\u1edf k\u1ef9 thu\u1eadt \u0111\u1ea3o ng\u01b0\u1ee3c. C\u00f3 th\u1ec3 c\u00f3 nh\u1eefng l\u00fd do ch\u00ednh \u0111\u00e1ng \u0111\u1ec3 c\u00e1c k\u1ef9 s\u01b0 ph\u1ea7n m\u1ec1m l\u00e0m t\u1ed1i ngh\u0129a ph\u1ea7n m\u1ec1m, ch\u1eb3ng h\u1ea1n nh\u01b0 \u0111\u1ec3 ng\u0103n ch\u1eb7n \u0111\u1ed1i th\u1ee7 c\u1ea1nh tranh \u0111\u00e1nh c\u1eafp t\u00e0i s\u1ea3n tr\u00ed tu\u1ec7. Tuy nhi\u00ean, t\u00e1c gi\u1ea3 ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i c\u0169ng s\u1eed d\u1ee5ng c\u00e1c tr\u00ecnh l\u00e0m t\u1ed1i ngh\u0129a \u0111\u1ec3 khi\u1ebfn c\u00e1c nh\u00e0 nghi\u00ean c\u1ee9u b\u1ea3o m\u1eadt kh\u00f3 ph\u00e2n t\u00edch ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i h\u01a1n.&nbsp;<\/p>\n\n\n\n<p>H\u1ea7u h\u1ebft c\u00e1c k\u1ef9 s\u01b0 \u0111\u1ea3o ng\u01b0\u1ee3c \u0111\u1ec1u d\u1ef1a v\u00e0o d\u1eef li\u1ec7u \u0111\u01b0\u1ee3c che gi\u1ea5u n\u00e0y khi ph\u00e2n t\u00edch ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i \u0111\u01b0\u1ee3c vi\u1ebft b\u1eb1ng Go, nh\u01b0ng trong tr\u01b0\u1eddng h\u1ee3p n\u00e0y, d\u1eef li\u1ec7u ch\u00ednh n\u00e0y b\u1ecb che gi\u1ea5u trong m\u00e3 \u0111\u00e3 bi\u00ean d\u1ecbch. M\u1ed9t s\u1ed1 th\u00f4ng tin n\u00e0y bao g\u1ed3m:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Chu\u1ed7i \u0111\u01b0\u1ee3c m\u00e3 h\u00f3a. Ch\u00fang s\u1ebd \u0111\u01b0\u1ee3c gi\u1ea3i m\u00e3 trong th\u1eddi gian ch\u1ea1y.\u00a0<\/li>\n\n\n\n<li>Th\u00f4ng tin phi\u00ean b\u1ea3n Go \u0111\u00e3 m\u1ea5t. R\u1ea5t nhi\u1ec1u c\u00f4ng c\u1ee5 k\u1ef9 thu\u1eadt \u0111\u1ea3o ng\u01b0\u1ee3c ngu\u1ed3n m\u1edf d\u1ef1a v\u00e0o th\u00f4ng tin phi\u00ean b\u1ea3n Go n\u00e0y \u0111\u1ec3 x\u00e2y d\u1ef1ng l\u1ea1i c\u00e1c c\u1ea5u tr\u00fac trong qu\u00e1 tr\u00ecnh ph\u00e2n t\u00e1ch.\u00a0<\/li>\n\n\n\n<li>Th\u00f4ng tin g\u00f3i h\u1eefu \u00edch ho\u1eb7c \u0111\u01b0\u1eddng d\u1eabn g\u00f3i s\u1ebd \u0111\u01b0\u1ee3c m\u00e3 h\u00f3a ho\u1eb7c lo\u1ea1i b\u1ecf kh\u1ecfi ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i cu\u1ed1i c\u00f9ng.\u00a0<\/li>\n<\/ul>\n\n\n\n<p>Tuy nhi\u00ean, ch\u00fang t\u00f4i c\u00f3 th\u1ec3 tr\u00edch xu\u1ea5t th\u00f4ng tin c\u00f3 gi\u00e1 tr\u1ecb&nbsp;<a href=\"https:\/\/github.com\/mandiant\/GoReSym\">b\u1eb1ng c\u00e1ch s\u1eed d\u1ee5ng c\u00f4ng c\u1ee5 GoReSym<\/a>&nbsp;t\u1eeb Mandiant.&nbsp;<\/p>\n\n\n\n<p><strong>\u0110i\u1ec3m t\u01b0\u01a1ng \u0111\u1ed3ng gi\u1eefa c\u00e1c t\u1ea3i tr\u1ecdng cu\u1ed1i c\u00f9ng&nbsp;<\/strong><\/p>\n\n\n\n<p>T\u1ea5t c\u1ea3 c\u00e1c tr\u00ecnh di\u1ec7t EDR ch\u01b0a gi\u1ea3i n\u00e9n \u0111\u1ec1u nh\u00fang tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n d\u1ec5 b\u1ecb t\u1ea5n c\u00f4ng v\u00e0o ph\u1ea7n .data. H\u00e0nh vi c\u1ee7a ch\u00fang r\u1ea5t \u0111\u01a1n gi\u1ea3n, gi\u1ed1ng nh\u01b0 c\u00e1c tr\u00ecnh di\u1ec7t EDR kh\u00e1c m\u00e0 ch\u00fang t\u00f4i \u0111\u00e3 ph\u00e2n t\u00edch[&nbsp;<a href=\"https:\/\/news.sophos.com\/en-us\/2023\/04\/19\/aukill-edr-killer-malware-abuses-process-explorer-driver\/\">1<\/a>&nbsp;][&nbsp;<a href=\"https:\/\/news.sophos.com\/en-us\/2022\/12\/13\/signed-driver-malware-moves-up-the-software-trust-chain\/?cmp=30728\">2<\/a>&nbsp;][&nbsp;<a href=\"https:\/\/news.sophos.com\/en-us\/2024\/03\/04\/itll-be-back-attackers-still-abusing-terminator-tool-and-variants\/\">3<\/a>&nbsp;]. \u0110i\u1ec3m kh\u00e1c bi\u1ec7t l\u1edbn duy nh\u1ea5t gi\u1eefa hai bi\u1ebfn th\u1ec3 m\u00e0 ch\u00fang t\u00f4i \u0111\u00e3 xem x\u00e9t l\u00e0 tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n d\u1ec5 b\u1ecb t\u1ea5n c\u00f4ng \u0111\u01b0\u1ee3c t\u1ea3i v\u00e0 khai th\u00e1c.&nbsp;<\/p>\n\n\n\n<p>Khi th\u1ef1c hi\u1ec7n, c\u1ea3 hai bi\u1ebfn th\u1ec3 \u0111\u1ec1u c\u00f3 \u0111\u01b0\u1ee3c c\u00e1c \u0111\u1eb7c quy\u1ec1n c\u1ea7n thi\u1ebft \u0111\u1ec3 t\u1ea3i tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n v\u00e0 th\u1ea3 t\u1ec7p sys c\u00f3 th\u1ec3 khai th\u00e1c v\u00e0o th\u01b0 m\u1ee5c \\AppData\\Local\\Temp. Ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i t\u1ea1o ra m\u1ed9t t\u00ean t\u1ec7p ng\u1eabu nhi\u00ean cho tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n m\u1ed7i khi ch\u1ea1y.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"http:\/\/aws.vacif.com\/wp-content\/uploads\/sites\/3\/2024\/08\/nhung-ke-tan-cong-ransomware-gioi-thieu-sat-thu-edr-moi-vao-kho-vu-khi-cua-chung-6.png\" alt=\"\" class=\"wp-image-20249\"\/><\/figure>\n\n\n\n<p><strong>Nh\u1eadt k\u00fd Process Monitor cho th\u1ea5y ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i th\u1ea3 tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n c\u00f3 th\u1ec3 l\u1ea1m d\u1ee5ng v\u00e0o th\u01b0 m\u1ee5c TEMP<\/strong><\/p>\n\n\n\n<p>Sau khi ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i t\u1ea1o m\u1ed9t d\u1ecbch v\u1ee5 m\u1edbi cho tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n, kh\u1edfi \u0111\u1ed9ng d\u1ecbch v\u1ee5 v\u00e0 t\u1ea3i tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n, n\u00f3 s\u1ebd \u0111i v\u00e0o m\u1ed9t v\u00f2ng l\u1eb7p v\u00f4 t\u1eadn li\u00ean t\u1ee5c li\u1ec7t k\u00ea c\u00e1c quy tr\u00ecnh \u0111ang ch\u1ea1y, ch\u1ea5m d\u1ee9t c\u00e1c quy tr\u00ecnh n\u1ebfu t\u00ean c\u1ee7a ch\u00fang xu\u1ea5t hi\u1ec7n trong danh s\u00e1ch m\u1ee5c ti\u00eau \u0111\u01b0\u1ee3c m\u00e3 h\u00f3a c\u1ee9ng. H\u00e0nh vi n\u00e0y ph\u00f9 h\u1ee3p v\u1edbi c\u1ea3 hai bi\u1ebfn th\u1ec3.&nbsp;<\/p>\n\n\n\n<p>C\u0169ng \u0111\u00e1ng l\u01b0u \u00fd r\u1eb1ng c\u1ea3 hai bi\u1ebfn th\u1ec3 \u0111\u1ec1u khai th\u00e1c c\u00e1c tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n h\u1ee3p l\u1ec7 (m\u1eb7c d\u00f9 d\u1ec5 b\u1ecb t\u1ea5n c\u00f4ng), s\u1eed d\u1ee5ng c\u00e1c khai th\u00e1c b\u1eb1ng ch\u1ee9ng kh\u00e1i ni\u1ec7m c\u00f3 s\u1eb5n tr\u00ean Github. Ch\u00fang t\u00f4i nghi ng\u1edd r\u1eb1ng c\u00e1c t\u00e1c nh\u00e2n \u0111e d\u1ecda \u0111\u00e3 sao ch\u00e9p m\u1ed9t ph\u1ea7n c\u1ee7a c\u00e1c b\u1eb1ng ch\u1ee9ng kh\u00e1i ni\u1ec7m n\u00e0y, s\u1eeda \u0111\u1ed5i ch\u00fang v\u00e0 chuy\u1ec3n m\u00e3 sang ng\u00f4n ng\u1eef Go. \u0110\u00e2y l\u00e0 xu h\u01b0\u1edbng ph\u1ed5 bi\u1ebfn m\u00e0 ch\u00fang t\u00f4i c\u0169ng \u0111\u00e3 quan s\u00e1t th\u1ea5y \u1edf c\u00e1c tr\u00ecnh di\u1ec7t EDR kh\u00e1c, ch\u1eb3ng h\u1ea1n nh\u01b0&nbsp;<a href=\"https:\/\/news.sophos.com\/en-us\/2024\/03\/04\/itll-be-back-attackers-still-abusing-terminator-tool-and-variants\/\">Terminator<\/a>&nbsp;.&nbsp;&nbsp;<\/p>\n\n\n\n<p><strong>C\u00f9ng m\u1ed9t b\u1ed9 n\u1ea1p, t\u1ea3i tr\u1ecdng cu\u1ed1i c\u00f9ng kh\u00e1c nhau&nbsp;<\/strong><\/p>\n\n\n\n<p>M\u1eabu v\u1edbi SHA256 451f5aa55eb207e73c5ca53d249b95911d3fad6fe32eee78c58947761336cc60 l\u1ea1m d\u1ee5ng tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n d\u1ec5 b\u1ecb t\u1ea5n c\u00f4ng c\u0169ng \u0111\u00e3 \u0111\u01b0\u1ee3c nh\u00ecn th\u1ea5y b\u1ecb l\u1ea1m d\u1ee5ng trong c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng v\u00e0 t\u1ef1 g\u1ecdi m\u00ecnh l\u00e0 RentDrv2. B\u1eb1ng ch\u1ee9ng kh\u00e1i ni\u1ec7m \u0111\u1ec3 khai th\u00e1c tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n n\u00e0y c\u00f3 s\u1eb5n tr\u00ean&nbsp;<a href=\"https:\/\/github.com\/keowu\/BadRentdrv2\">Github<\/a>&nbsp;.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Bi\u1ebfn th\u1ec3 n\u00e0y c\u0169ng c\u00f3 th\u1ec3 nh\u1eadn th\u00eam \u0111\u1ed1i s\u1ed1 d\u00f2ng l\u1ec7nh \u201c\u2013list\u201d, cho ph\u00e9p k\u1ebb t\u1ea5n c\u00f4ng truy\u1ec1n th\u00eam danh s\u00e1ch t\u00ean quy tr\u00ecnh l\u00e0m m\u1ee5c ti\u00eau.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"http:\/\/aws.vacif.com\/wp-content\/uploads\/sites\/3\/2024\/08\/nhung-ke-tan-cong-ransomware-gioi-thieu-sat-thu-edr-moi-vao-kho-vu-khi-cua-chung-7.png\" alt=\"\" class=\"wp-image-20250\"\/><\/figure>\n\n\n\n<p><strong>Bi\u1ebfn th\u1ec3 \u0111\u1ea7u ti\u00ean c\u0169ng c\u00f3 th\u1ec3 ch\u1ea5p nh\u1eadn c\u00e1c \u0111\u1ed1i s\u1ed1 d\u00f2ng l\u1ec7nh b\u1ed5 sung l\u00e0m \u0111\u1ea7u v\u00e0o, bao g\u1ed3m danh s\u00e1ch t\u00f9y ch\u1ec9nh c\u00e1c quy tr\u00ecnh c\u1ea7n nh\u1eafm m\u1ee5c ti\u00eau<\/strong><\/p>\n\n\n\n<p>Ng\u01b0\u1ee3c l\u1ea1i, bi\u1ebfn th\u1ec3 v\u1edbi SHA256 d0f9eae1776a98c77a6c6d66a3fd32cee7ee6148a7276bc899c1a1376865d9b0 l\u1ea1i l\u1ee3i d\u1ee5ng m\u1ed9t tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n d\u1ec5 b\u1ecb t\u1ea5n c\u00f4ng \u0111\u01b0\u1ee3c bi\u1ebft \u0111\u1ebfn c\u00f3 t\u00ean l\u00e0 ThreatFireMonitor, m\u1ed9t th\u00e0nh ph\u1ea7n c\u1ee7a m\u1ed9t g\u00f3i gi\u00e1m s\u00e1t h\u1ec7 th\u1ed1ng \u0111\u00e3 l\u1ed7i th\u1eddi. M\u1ed9t b\u1eb1ng ch\u1ee9ng v\u1ec1 kh\u00e1i ni\u1ec7m cho tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n c\u1ee5 th\u1ec3 n\u00e0y c\u0169ng c\u00f3 s\u1eb5n tr\u00ean Github .<\/p>\n\n\n\n<p><strong>\u00c1nh x\u1ea1 EDRKillShifter v\u00e0o b\u1ed1i c\u1ea3nh m\u1ed1i \u0111e d\u1ecda l\u1edbn h\u01a1n&nbsp;<\/strong><\/p>\n\n\n\n<p>T\u1ea3i tr\u1ecdng cu\u1ed1i c\u00f9ng \u0111\u01b0\u1ee3c nh\u00fang v\u00e0o tr\u00ecnh t\u1ea3i thay \u0111\u1ed5i theo t\u1eebng s\u1ef1 c\u1ed1 (v\u00e0 c\u00f3 l\u1ebd l\u00e0 t\u1eeb ng\u01b0\u1eddi t\u1ea1o ra n\u00f3). N\u1ebfu ch\u00fang ta th\u1eed \u00e1nh x\u1ea1 EDRKillShifter v\u00e0o b\u1ed1i c\u1ea3nh m\u1ed1i \u0111e d\u1ecda l\u1edbn h\u01a1n, th\u00ec c\u0169ng c\u00f3 kh\u1ea3 n\u0103ng tr\u00ecnh t\u1ea3i v\u00e0 t\u1ea3i tr\u1ecdng cu\u1ed1i c\u00f9ng \u0111\u01b0\u1ee3c ph\u00e1t tri\u1ec3n b\u1edfi c\u00e1c t\u00e1c nh\u00e2n \u0111e d\u1ecda ri\u00eang bi\u1ec7t.&nbsp;<\/p>\n\n\n\n<p>B\u00e1n tr\u00ecnh t\u1ea3i ho\u1eb7c tr\u00ecnh che gi\u1ea5u l\u00e0 m\u1ed9t ho\u1ea1t \u0111\u1ed9ng kinh doanh b\u00e9o b\u1edf tr\u00ean dark net. Sophos X-Ops nghi ng\u1edd r\u1eb1ng m\u1ee5c \u0111\u00edch duy nh\u1ea5t c\u1ee7a tr\u00ecnh t\u1ea3i l\u00e0 tri\u1ec3n khai t\u1ea3i tr\u1ecdng BYOVD cu\u1ed1i c\u00f9ng v\u00e0 t\u1ea3i tr\u1ecdng n\u00e0y c\u00f3 th\u1ec3 \u0111\u00e3 \u0111\u01b0\u1ee3c mua tr\u00ean dark net. Sau \u0111\u00f3, c\u00e1c t\u1ea3i tr\u1ecdng EDR killer cu\u1ed1i c\u00f9ng ch\u1ec9 \u0111\u01b0\u1ee3c ph\u00e2n ph\u1ed1i b\u1edfi ch\u00ednh tr\u00ecnh t\u1ea3i, bao g\u1ed3m l\u1edbp 1 v\u00e0 2 m\u00e0 ch\u00fang t\u00f4i \u0111\u00e3 m\u00f4 t\u1ea3 trong ph\u00e2n t\u00edch \u1edf tr\u00ean.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"http:\/\/aws.vacif.com\/wp-content\/uploads\/sites\/3\/2024\/08\/nhung-ke-tan-cong-ransomware-gioi-thieu-sat-thu-edr-moi-vao-kho-vu-khi-cua-chung-8-1024x682.png\" alt=\"\" class=\"wp-image-20251\"\/><\/figure>\n\n\n\n<p><strong>V\u00ed d\u1ee5 v\u1ec1 qu\u1ea3ng c\u00e1o c\u00f4ng c\u1ee5 che gi\u1ea5u \u0111\u01b0\u1ee3c b\u00e1n tr\u00ean di\u1ec5n \u0111\u00e0n t\u1ed9i ph\u1ea1m dark net<\/strong><\/p>\n\n\n\n<p>\u0110i\u1ec1u \u0111\u00e1ng l\u01b0u \u00fd l\u00e0 ch\u00fang t\u00f4i kh\u00f4ng th\u1ec3 x\u00e1c nh\u1eadn gi\u1ea3 thuy\u1ebft n\u00e0y v\u00e0o th\u1eddi \u0111i\u1ec3m n\u00e0y.&nbsp;<\/p>\n\n\n\n<p><strong>Bi\u1ec7n ph\u00e1p gi\u1ea3m thi\u1ec3u&nbsp;v\u00e0 t\u01b0 v\u1ea5n<\/strong><\/p>\n\n\n\n<p>Sophos hi\u1ec7n ph\u00e1t hi\u1ec7n EDRKillShifter l\u00e0&nbsp;<strong>Troj\/KillAV-KG<\/strong>&nbsp;. H\u01a1n n\u1eefa, c\u00e1c quy t\u1eafc b\u1ea3o v\u1ec7 h\u00e0nh vi b\u1ea3o v\u1ec7 ch\u1ed1ng l\u1ea1i vi\u1ec7c tr\u1ed1n tr\u00e1nh ph\u00f2ng th\u1ee7 v\u00e0 leo thang \u0111\u1eb7c quy\u1ec1n ch\u1eb7n c\u00e1c cu\u1ed9c g\u1ecdi h\u1ec7 th\u1ed1ng n\u00e0y \u0111i qua. C\u00e1c doanh nghi\u1ec7p v\u00e0 c\u00e1 nh\u00e2n c\u0169ng c\u00f3 th\u1ec3 th\u1ef1c hi\u1ec7n c\u00e1c b\u01b0\u1edbc b\u1ed5 sung \u0111\u1ec3 b\u1ea3o v\u1ec7 m\u00e1y c\u1ee7a h\u1ecd kh\u1ecfi vi\u1ec7c tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n l\u1ea1m d\u1ee5ng:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Sophos X-Ops khuy\u1ebfn c\u00e1o b\u1ea1n n\u00ean ki\u1ec3m tra xem s\u1ea3n ph\u1ea9m b\u1ea3o m\u1eadt \u0111i\u1ec3m cu\u1ed1i c\u1ee7a b\u1ea1n c\u00f3 tri\u1ec3n khai v\u00e0 k\u00edch ho\u1ea1t b\u1ea3o v\u1ec7 ch\u1ed1ng gi\u1ea3 m\u1ea1o hay kh\u00f4ng. T\u00ednh n\u0103ng n\u00e0y cung c\u1ea5p m\u1ed9t l\u1edbp m\u1ea1nh m\u1ebd ch\u1ed1ng l\u1ea1i lo\u1ea1i t\u1ea5n c\u00f4ng nh\u01b0 v\u1eady. N\u1ebfu b\u1ea1n s\u1eed d\u1ee5ng s\u1ea3n ph\u1ea9m Sophos nh\u01b0ng hi\u1ec7n t\u1ea1i kh\u00f4ng b\u1eadt b\u1ea3o v\u1ec7 ch\u1ed1ng gi\u1ea3 m\u1ea1o Sophos, h\u00e3y b\u1eadt ngay h\u00f4m nay.\u00a0<\/li>\n\n\n\n<li>Th\u1ef1c h\u00e0nh v\u1ec7 sinh m\u1ea1nh m\u1ebd cho c\u00e1c vai tr\u00f2 b\u1ea3o m\u1eadt Windows. Cu\u1ed9c t\u1ea5n c\u00f4ng n\u00e0y ch\u1ec9 c\u00f3 th\u1ec3 x\u1ea3y ra n\u1ebfu k\u1ebb t\u1ea5n c\u00f4ng leo thang c\u00e1c \u0111\u1eb7c quy\u1ec1n m\u00e0 ch\u00fang ki\u1ec3m so\u00e1t ho\u1eb7c n\u1ebfu ch\u00fang c\u00f3 th\u1ec3 c\u00f3 \u0111\u01b0\u1ee3c quy\u1ec1n qu\u1ea3n tr\u1ecb vi\u00ean. Vi\u1ec7c t\u00e1ch bi\u1ec7t gi\u1eefa c\u00e1c \u0111\u1eb7c quy\u1ec1n c\u1ee7a ng\u01b0\u1eddi d\u00f9ng v\u00e0 qu\u1ea3n tr\u1ecb vi\u00ean c\u00f3 th\u1ec3 gi\u00fap ng\u0103n ch\u1eb7n k\u1ebb t\u1ea5n c\u00f4ng d\u1ec5 d\u00e0ng t\u1ea3i tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n.\u00a0<\/li>\n\n\n\n<li>Lu\u00f4n c\u1eadp nh\u1eadt h\u1ec7 th\u1ed1ng c\u1ee7a b\u1ea1n. T\u1eeb n\u0103m ngo\u00e1i, Microsoft \u0111\u00e3 b\u1eaft \u0111\u1ea7u \u0111\u01b0a ra c\u00e1c b\u1ea3n c\u1eadp nh\u1eadt h\u1ee7y ch\u1ee9ng nh\u1eadn c\u00e1c tr\u00ecnh \u0111i\u1ec1u khi\u1ec3n \u0111\u00e3 k\u00fd \u0111\u01b0\u1ee3c bi\u1ebft l\u00e0 \u0111\u00e3 b\u1ecb l\u1ea1m d\u1ee5ng trong qu\u00e1 kh\u1ee9.\u00a0\u00a0<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Sophos ph\u00e1t hi\u1ec7n ra c\u00e1c t\u00e1c nh\u00e2n \u0111e d\u1ecda \u0111\u1eb1ng sau ransomware RansomHub s\u1eed d\u1ee5ng EDRKillShifter trong c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng Vi\u1ebft b\u1edfi Andreas Klopsch August 14, 2024 C\u00e1c nh\u00e0 ph\u00e2n t\u00edch c\u1ee7a Sophos g\u1ea7n \u0111\u00e2y \u0111\u00e3 ph\u00e1t hi\u1ec7n ra m\u1ed9t ti\u1ec7n \u00edch di\u1ec7t EDR m\u1edbi \u0111ang \u0111\u01b0\u1ee3c m\u1ed9t nh\u00f3m t\u1ed9i ph\u1ea1m tri\u1ec3n khai, nh\u1eefng [&hellip;]<\/p>\n","protected":false},"author":8,"featured_media":20252,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_eb_attr":"","ocean_post_layout":"","ocean_both_sidebars_style":"","ocean_both_sidebars_content_width":0,"ocean_both_sidebars_sidebars_width":0,"ocean_sidebar":"","ocean_second_sidebar":"","ocean_disable_margins":"enable","ocean_add_body_class":"","ocean_shortcode_before_top_bar":"","ocean_shortcode_after_top_bar":"","ocean_shortcode_before_header":"","ocean_shortcode_after_header":"","ocean_has_shortcode":"","ocean_shortcode_after_title":"","ocean_shortcode_before_footer_widgets":"","ocean_shortcode_after_footer_widgets":"","ocean_shortcode_before_footer_bottom":"","ocean_shortcode_after_footer_bottom":"","ocean_display_top_bar":"default","ocean_display_header":"default","ocean_header_style":"","ocean_center_header_left_menu":"","ocean_custom_header_template":"","ocean_custom_logo":0,"ocean_custom_retina_logo":0,"ocean_custom_logo_max_width":0,"ocean_custom_logo_tablet_max_width":0,"ocean_custom_logo_mobile_max_width":0,"ocean_custom_logo_max_height":0,"ocean_custom_logo_tablet_max_height":0,"ocean_custom_logo_mobile_max_height":0,"ocean_header_custom_menu":"","ocean_menu_typo_font_family":"","ocean_menu_typo_font_subset":"","ocean_menu_typo_font_size":0,"ocean_menu_typo_font_size_tablet":0,"ocean_menu_typo_font_size_mobile":0,"ocean_menu_typo_font_size_unit":"px","ocean_menu_typo_font_weight":"","ocean_menu_typo_font_weight_tablet":"","ocean_menu_typo_font_weight_mobile":"","ocean_menu_typo_transform":"","ocean_menu_typo_transform_tablet":"","ocean_menu_typo_transform_mobile":"","ocean_menu_typo_line_height":0,"ocean_menu_typo_line_height_tablet":0,"ocean_menu_typo_line_height_mobile":0,"ocean_menu_typo_line_height_unit":"","ocean_menu_typo_spacing":0,"ocean_menu_typo_spacing_tablet":0,"ocean_menu_typo_spacing_mobile":0,"ocean_menu_typo_spacing_unit":"","ocean_menu_link_color":"","ocean_menu_link_color_hover":"","ocean_menu_link_color_active":"","ocean_menu_link_background":"","ocean_menu_link_hover_background":"","ocean_menu_link_active_background":"","ocean_menu_social_links_bg":"","ocean_menu_social_hover_links_bg":"","ocean_menu_social_links_color":"","ocean_menu_social_hover_links_color":"","ocean_disable_title":"default","ocean_disable_heading":"default","ocean_post_title":"","ocean_post_subheading":"","ocean_post_title_style":"","ocean_post_title_background_color":"","ocean_post_title_background":0,"ocean_post_title_bg_image_position":"","ocean_post_title_bg_image_attachment":"","ocean_post_title_bg_image_repeat":"","ocean_post_title_bg_image_size":"","ocean_post_title_height":0,"ocean_post_title_bg_overlay":0.5,"ocean_post_title_bg_overlay_color":"","ocean_disable_breadcrumbs":"default","ocean_breadcrumbs_color":"","ocean_breadcrumbs_separator_color":"","ocean_breadcrumbs_links_color":"","ocean_breadcrumbs_links_hover_color":"","ocean_display_footer_widgets":"default","ocean_display_footer_bottom":"default","ocean_custom_footer_template":"","ocean_post_oembed":"","ocean_post_self_hosted_media":"","ocean_post_video_embed":"","ocean_link_format":"","ocean_link_format_target":"self","ocean_quote_format":"","ocean_quote_format_link":"post","ocean_gallery_link_images":"on","ocean_gallery_id":[],"footnotes":""},"categories":[80,10],"tags":[487,92],"class_list":["post-20242","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-huong-dan-tai-lieu","category-tin-tuc","tag-edrkillshifter","tag-ransomware","entry","has-media"],"_links":{"self":[{"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/posts\/20242","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/comments?post=20242"}],"version-history":[{"count":1,"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/posts\/20242\/revisions"}],"predecessor-version":[{"id":20303,"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/posts\/20242\/revisions\/20303"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/media\/20252"}],"wp:attachment":[{"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/media?parent=20242"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/categories?post=20242"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vacif.com\/en\/wp-json\/wp\/v2\/tags?post=20242"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}