Millions of computers in Vietnam at risk of being attacked by new virus

June 15, 2023 13:53

According to Bkav's statistics on the new attack campaign on businesses and users in Vietnam, 1 out of 10 Windows computers has an SMB vulnerability and is at risk of being infected with the new Spectralviper virus.

According to Bkav's statistics on the new attack campaign on businesses and users in Vietnam, 1 out of 10 Windows computers has an SMB vulnerability and is at risk of being infected with the new Spectralviper virus.

Bkav has just announced that a new virus attack campaign named Spectralviper has just been discovered. The campaign targets computers of a series of large enterprises and users in Vietnam through the SMB vulnerability.

Analysts say that through a vulnerability in the SMB protocol on Microsoft Windows, hackers infiltrated the system and deployed Spectralviper as a backdoor to maintain a connection to the infected device. On the victim's computer, hackers continued malicious actions such as executing malicious code, accessing and stealing data, etc.

Mr. Nguyen Tien Dat, General Director of Bkav's Malware Research Center, said that the SMB vulnerability was once exploited by the WannaCry virus to infect more than 300,000 computers worldwide in a few hours. In 2018, up to 735,000 computers in Vietnam were attacked by the W32.CoinMiner cryptocurrency mining malware by exploiting SMB. "Despite being warned many times, up to now, up to 10% of computers in Vietnam still have SMB vulnerabilities," Mr. Nguyen Tien Dat commented.

After successfully infecting the victim's computer by exploiting the SMB vulnerability, hackers continue to perform malicious actions such as executing malware, accessing and stealing data... (Illustration photo)

Bkav experts recommend that users update the patch as soon as possible by going to “Windows Update” and selecting “Check for updates” to check for the latest patches. Back up important data promptly. Computers with Bkav Pro antivirus software installed will automatically block similar exploit scenarios.

Organizations and businesses are also recommended to deploy additional network security monitoring solutions such as firewalls and Network Security Monitoring Centers - SOC to support early detection of abnormalities for timely response and handling.

In addition, businesses and organizations also need to contact specialized cybersecurity units to get support in reviewing the entire system including servers, workstations and Cloud systems, to thoroughly remove malware.

According to Vietnamnet

(0) Comments
Latest News
Millions of computers in Vietnam at risk of being attacked by new virus