{"id":278602,"date":"2022-07-26T08:30:34","date_gmt":"2022-07-26T10:30:34","guid":{"rendered":"https:\/\/teknomers.com\/fr\/smokeloader-infecte-des-systemes-cibles-avec-le-logiciel-malveillant-voleur-dinformations-damadey\/"},"modified":"2022-07-26T08:30:35","modified_gmt":"2022-07-26T10:30:35","slug":"smokeloader-infecte-des-systemes-cibles-avec-le-logiciel-malveillant-voleur-dinformations-damadey","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/smokeloader-infecte-des-systemes-cibles-avec-le-logiciel-malveillant-voleur-dinformations-damadey\/","title":{"rendered":"SmokeLoader infecte des syst\u00e8mes cibl\u00e9s avec le logiciel malveillant voleur d&#8217;informations d&#8217;Amadey"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Un logiciel malveillant voleur d&#8217;informations appel\u00e9 Amadey est distribu\u00e9 au moyen d&#8217;une autre porte d\u00e9rob\u00e9e appel\u00e9e SmokeLoader.<\/p>\n<p>Les attaques consistent \u00e0 inciter les utilisateurs \u00e0 t\u00e9l\u00e9charger SmokeLoader qui se fait passer pour des fissures logicielles, ouvrant la voie au d\u00e9ploiement d&#8217;Amadey, des chercheurs du AhnLab Security Emergency Response Center (ASEC) <a rel=\"nofollow noopener\" href=\"https:\/\/asec.ahnlab.com\/en\/36634\/\" target=\"_blank\">a dit<\/a> dans un rapport publi\u00e9 la semaine derni\u00e8re.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/strike-d\" target=\"_blank\" title=\"DevOps backupy\"><img decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" loading=\"lazy\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/07\/Une-nouvelle-etude-revele-que-la-plupart-des-fournisseurs-dentreprise.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p><a rel=\"nofollow noopener\" href=\"https:\/\/malpedia.caad.fkie.fraunhofer.de\/details\/win.amadey\" target=\"_blank\">Amadey<\/a>un botnet qui <a rel=\"nofollow noopener\" href=\"https:\/\/krabsonsecurity.com\/2019\/02\/13\/analyzing-amadey-a-simple-native-malware\/\" target=\"_blank\">premi\u00e8re apparition<\/a> vers octobre 2018 sur les forums clandestins russes pour 600 $, est \u00e9quip\u00e9 pour siphonner les informations d&#8217;identification, capturer des captures d&#8217;\u00e9cran, des m\u00e9tadonn\u00e9es syst\u00e8me et m\u00eame des informations sur les moteurs antivirus et les logiciels malveillants suppl\u00e9mentaires install\u00e9s sur une machine infect\u00e9e.<\/p>\n<div class=\"separator\" style=\"clear: both\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"319\" data-original-width=\"728\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/07\/1658831434_738_SmokeLoader-infecte-des-systemes-cibles-avec-le-logiciel-malveillant-voleur.jpg\" \/><\/div>\n<p>Alors qu&#8217;une mise \u00e0 jour a \u00e9t\u00e9 rep\u00e9r\u00e9e en juillet dernier par Walmart Global Tech <a rel=\"nofollow noopener\" href=\"https:\/\/medium.com\/walmartglobaltech\/amadey-stealer-plugin-adds-mikrotik-and-outlook-harvesting-518efe724ce4\" target=\"_blank\">incorpor\u00e9<\/a> fonctionnalit\u00e9 de collecte de donn\u00e9es \u00e0 partir des routeurs Mikrotik et de Microsoft Outlook, l&#8217;ensemble d&#8217;outils a depuis \u00e9t\u00e9 mis \u00e0 niveau pour capturer les informations de FileZilla, Pidgin, Total Commander FTP Client, RealVNC, TightVNC, TigerVNC et WinSCP.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/crowdsec-tour-d\" target=\"_blank\" title=\"CyberSecurity\"><img decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" loading=\"lazy\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/07\/1656663365_395_Amazon-corrige-discretement-la-vulnerabilite-de-gravite-elevee-dans-lapplication.jpg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>Son objectif principal, cependant, est de d\u00e9ployer des plugins suppl\u00e9mentaires et des chevaux de Troie d&#8217;acc\u00e8s \u00e0 distance tels que <a rel=\"nofollow noopener\" href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/latest-version-amadey-introduces-screen-capturing-and-pushes-remcos-rat\" target=\"_blank\">Remcos RAT<\/a> et RedLine Stealer, permettant en outre \u00e0 l&#8217;auteur de la menace de mener une s\u00e9rie d&#8217;activit\u00e9s post-exploitation.<\/p>\n<p>Il est recommand\u00e9 aux utilisateurs de mettre \u00e0 niveau leurs appareils vers les derni\u00e8res versions du syst\u00e8me d&#8217;exploitation et du navigateur Web afin de minimiser les voies d&#8217;infection potentielles et d&#8217;\u00e9viter les logiciels pirat\u00e9s.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/07\/smokeloader-infecting-targeted-systems.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Un logiciel malveillant voleur d&#8217;informations appel\u00e9 Amadey est distribu\u00e9 au moyen d&#8217;une autre porte d\u00e9rob\u00e9e appel\u00e9e SmokeLoader. Les attaques consistent \u00e0 inciter les utilisateurs \u00e0 t\u00e9l\u00e9charger SmokeLoader qui se fait passer pour des fissures logicielles, ouvrant la voie au d\u00e9ploiement d&#8217;Amadey, des chercheurs du AhnLab Security Emergency Response Center (ASEC) a dit dans un rapport [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":278603,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[84,9589,4168,4158,4165,4161,93736,133,22908,16220,4157,4159,4171,4170,6816,4167,7733,4160,4163,4162,4172,4169,93735,5046,4166,8808,4164],"class_list":["post-278602","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-avec","tag-cibles","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-damadey","tag-des","tag-dinformations","tag-infecte","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel","tag-logiciel-malveillant-de-ransomware","tag-malveillant","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-securite-informatique","tag-securite-internet","tag-smokeloader","tag-systemes","tag-violation-de-donnees","tag-voleur","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/278602","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=278602"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/278602\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/278603"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=278602"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=278602"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=278602"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}