{"id":10415,"date":"2025-07-29T12:30:31","date_gmt":"2025-07-29T05:30:31","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=10415"},"modified":"2026-02-05T12:30:38","modified_gmt":"2026-02-05T05:30:38","slug":"raven-stealer-moi-de-doa-moi-tu-telegram-va-github-nham-vao-nguoi-dung-windows","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/2025\/07\/29\/raven-stealer-moi-de-doa-moi-tu-telegram-va-github-nham-vao-nguoi-dung-windows\/","title":{"rendered":"Raven Stealer: M\u1ed1i \u0111e d\u1ecda m\u1edbi t\u1eeb Telegram v\u00e0 GitHub nh\u1eafm v\u00e0o ng\u01b0\u1eddi d\u00f9ng Windows"},"content":{"rendered":"<p><b>Th\u00e1ng 7\/2025, c\u00e1c chuy\u00ean gia an ninh m\u1ea1ng \u0111\u00e3 c\u1ea3nh b\u00e1o v\u1ec1 Raven Stealer &#8211; m\u1ed9t lo\u1ea1i ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i (malware) m\u1edbi chuy\u00ean \u0111\u00e1nh c\u1eafp th\u00f4ng tin c\u00e1 nh\u00e2n. Kh\u00e1c v\u1edbi nh\u1eefng chi\u1ebfn d\u1ecbch ph\u1ee9c t\u1ea1p tr\u01b0\u1edbc \u0111\u00e2y, Raven Stealer \u0111\u01a1n gi\u1ea3n nh\u01b0ng nguy hi\u1ec3m, \u0111\u01b0\u1ee3c ph\u00e1t t\u00e1n c\u00f4ng khai tr\u00ean GitHub v\u00e0 \u0111i\u1ec1u khi\u1ec3n qua Telegram. V\u1edbi giao di\u1ec7n d\u1ec5 d\u00f9ng v\u00e0 t\u00ednh n\u0103ng t\u1ef1 \u0111\u1ed9ng cao, ph\u1ea7n m\u1ec1m n\u00e0y \u0111ang l\u00e0m d\u1ea5y l\u00ean lo ng\u1ea1i v\u1ec1 l\u00e0n s\u00f3ng m\u00e3 \u0111\u1ed9c-as-a-service (MaaS) d\u00e0nh cho c\u1ea3 hacker &#8220;tay m\u01a1&#8221;.<\/b><\/p>\n<div style=\"text-align: center\">\n<div class=\"bbImageWrapper  js-lbImage\" title=\"1753783039653.png\" data-src=\"https:\/\/whitehat.vn\/attachments\/1753783039653-png.17382\/\" data-lb-sidebar-href=\"\" data-lb-caption-extra-html=\"\" data-single-image=\"1\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage\" title=\"1753783039653.png\" src=\"https:\/\/whitehat.vn\/attachments\/1753783039653-png.17382\/\" alt=\"1753783039653.png\" width=\"617\" height=\"416\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<\/div>\n<p>Raven Stealer \u0111\u01b0\u1ee3c ph\u00e1t tri\u1ec3n b\u1edfi nh\u00f3m hacker ZeroTrace Team, v\u1ed1n n\u1ed5i ti\u1ebfng trong c\u1ed9ng \u0111\u1ed3ng ng\u1ea7m v\u1edbi nhi\u1ec1u c\u00f4ng c\u1ee5 \u0111\u00e1nh c\u1eafp d\u1eef li\u1ec7u nh\u01b0 Octalyn Stealer. Nh\u00f3m n\u00e0y v\u1eadn h\u00e0nh m\u1ed9t k\u00eanh Telegram ri\u00eang, n\u01a1i cung c\u1ea5p, h\u01b0\u1edbng d\u1eabn v\u00e0 qu\u1ea3ng b\u00e1 m\u00e3 \u0111\u1ed9c c\u00f4ng khai.<\/p>\n<p>Raven l\u00e0 m\u1ed9t infostealer &#8211; ph\u1ea7n m\u1ec1m \u0111\u00e1nh c\u1eafp th\u00f4ng tin. N\u00f3 ch\u1ee7 y\u1ebfu nh\u1eafm v\u00e0o ng\u01b0\u1eddi d\u00f9ng Windows, thu th\u1eadp d\u1eef li\u1ec7u t\u1eeb tr\u00ecnh duy\u1ec7t Chrome, Edge, Brave, v\u00ed ti\u1ec1n \u0111i\u1ec7n t\u1eed, m\u1eadt kh\u1ea9u \u0111\u00e3 l\u01b0u, cookie, th\u00f4ng tin thanh to\u00e1n v\u00e0 c\u1ea3 \u1ea3nh ch\u1ee5p m\u00e0n h\u00ecnh.<\/p>\n<div style=\"text-align: center\">\n<div class=\"bbImageWrapper  js-lbImage\" title=\"1753783096847.png\" data-src=\"https:\/\/whitehat.vn\/attachments\/1753783096847-png.17383\/\" data-lb-sidebar-href=\"\" data-lb-caption-extra-html=\"\" data-single-image=\"1\"><img decoding=\"async\" class=\"bbImage\" title=\"1753783096847.png\" src=\"https:\/\/whitehat.vn\/attachments\/1753783096847-png.17383\/\" alt=\"1753783096847.png\" width=\"704\" height=\"352\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<p>\u200b<\/p><\/div>\n<p>\u0110i\u1ec1u \u0111\u1eb7c bi\u1ec7t l\u00e0 Raven kh\u00f4ng c\u1ea7n server \u0111i\u1ec1u khi\u1ec3n ri\u00eang (C2). To\u00e0n b\u1ed9 d\u1eef li\u1ec7u b\u1ecb \u0111\u00e1nh c\u1eafp s\u1ebd \u0111\u01b0\u1ee3c n\u00e9n l\u1ea1i r\u1ed3i g\u1eedi tr\u1ef1c ti\u1ebfp l\u00ean Telegram b\u1eb1ng t\u00e0i kho\u1ea3n bot c\u1ee7a k\u1ebb t\u1ea5n c\u00f4ng.<\/p>\n<p>Ng\u01b0\u1eddi d\u00f9ng c\u00f3 th\u1ec3 b\u1ecb nhi\u1ec5m khi t\u1ea3i v\u1ec1 c\u00f4ng c\u1ee5 ho\u1eb7c ph\u1ea7n m\u1ec1m mi\u1ec5n ph\u00ed t\u1eeb GitHub ho\u1eb7c c\u00e1c trang chia s\u1ebb kh\u00f4ng ch\u00ednh th\u1ed1ng. C\u00e1c b\u1ea3n build c\u1ee7a Raven c\u00f2n c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c tu\u1ef3 ch\u1ec9nh d\u1ec5 d\u00e0ng qua giao di\u1ec7n \u0111\u1ed3 ho\u1ea1, khi\u1ebfn vi\u1ec7c ph\u00e1t t\u00e1n c\u00e0ng tr\u1edf n\u00ean \u0111\u01a1n gi\u1ea3n.<\/p>\n<p>Raven ho\u1ea1t \u0111\u1ed9ng nh\u01b0 th\u1ebf n\u00e0o?<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">\u1ea8n m\u00ecnh ho\u00e0n to\u00e0n: Khi ch\u1ea1y, Raven kh\u00f4ng hi\u1ec3n th\u1ecb giao di\u1ec7n, kh\u00f4ng hi\u1ec7n trong thanh t\u00e1c v\u1ee5 v\u00e0 kh\u00f3 b\u1ecb ph\u00e1t hi\u1ec7n qua thao t\u00e1c th\u00f4ng th\u01b0\u1eddng.<\/li>\n<li data-xf-list-type=\"ul\">Ti\u00eam m\u00e3 \u0111\u1ed9c v\u00e0o tr\u00ecnh duy\u1ec7t: Raven m\u1edf m\u1ed9t phi\u00ean b\u1ea3n tr\u00ecnh duy\u1ec7t \u1ea9n (headless Chrome), sau \u0111\u00f3 ti\u00eam m\u00e3 \u0111\u1ed9c tr\u1ef1c ti\u1ebfp v\u00e0o b\u1ed9 nh\u1edb b\u1eb1ng k\u1ef9 thu\u1eadt &#8220;process hollowing&#8221;.<\/li>\n<li data-xf-list-type=\"ul\">Thu th\u1eadp v\u00e0 n\u00e9n d\u1eef li\u1ec7u: D\u1eef li\u1ec7u \u0111\u01b0\u1ee3c t\u1eadp h\u1ee3p trong th\u01b0 m\u1ee5c \u1ea9n trong AppData, sau \u0111\u00f3 n\u00e9n ZIP v\u00e0 g\u1eedi qua Telegram.<\/li>\n<li data-xf-list-type=\"ul\">Tr\u00e1nh b\u1ecb ph\u00e1t hi\u1ec7n: C\u00e1c t\u1ec7p \u0111\u1ec1u \u0111\u01b0\u1ee3c m\u00e3 h\u00f3a b\u1eb1ng ChaCha20, k\u00fd s\u1ed1 b\u1eb1ng ch\u1ee9ng ch\u1ec9 gi\u1ea3 v\u00e0 n\u00e9n b\u1eb1ng UPX nh\u1eb1m qua m\u1eb7t ph\u1ea7n m\u1ec1m ch\u1ed1ng virus c\u01a1 b\u1ea3n.<\/li>\n<\/ul>\n<p>Raven l\u00e0 minh ch\u1ee9ng cho xu h\u01b0\u1edbng \u201cm\u00e3 \u0111\u1ed9c d\u00e0nh cho t\u1ea5t c\u1ea3 m\u1ecdi ng\u01b0\u1eddi\u201d. Ch\u1ec9 v\u1edbi m\u1ed9t t\u00e0i kho\u1ea3n Telegram v\u00e0 v\u00e0i c\u00fa click chu\u1ed9t, b\u1ea5t k\u1ef3 ai c\u0169ng c\u00f3 th\u1ec3 v\u1eadn h\u00e0nh chi\u1ebfn d\u1ecbch \u0111\u00e1nh c\u1eafp d\u1eef li\u1ec7u quy m\u00f4 l\u1edbn m\u00e0 kh\u00f4ng c\u1ea7n ki\u1ebfn th\u1ee9c k\u1ef9 thu\u1eadt chuy\u00ean s\u00e2u.<\/p>\n<p>Nguy hi\u1ec3m h\u01a1n, Raven ho\u1ea1t \u0111\u1ed9ng ho\u00e0n to\u00e0n trong b\u1ed9 nh\u1edb RAM, khi\u1ebfn nhi\u1ec1u ph\u1ea7n m\u1ec1m b\u1ea3o m\u1eadt truy\u1ec1n th\u1ed1ng kh\u00f3 ph\u00e1t hi\u1ec7n. V\u1edbi kh\u1ea3 n\u0103ng l\u1ea5y c\u1eafp v\u00ed ti\u1ec1n s\u1ed1, m\u1eadt kh\u1ea9u ng\u00e2n h\u00e0ng v\u00e0 th\u00f4ng tin \u0111\u0103ng nh\u1eadp, Raven l\u00e0 m\u1ed1i \u0111e d\u1ecda tr\u1ef1c ti\u1ebfp v\u1edbi c\u00e1 nh\u00e2n, doanh nghi\u1ec7p nh\u1ecf v\u00e0 c\u1ea3 t\u1ed5 ch\u1ee9c l\u1edbn.<\/p>\n<p>Raven Stealer l\u00e0 l\u1eddi nh\u1eafc nh\u1edf r\u00f5 r\u00e0ng v\u1ec1 r\u1ee7i ro khi t\u1ea3i ph\u1ea7n m\u1ec1m t\u1eeb ngu\u1ed3n kh\u00f4ng \u0111\u00e1ng tin c\u1eady. \u0110\u1ec3 t\u1ef1 b\u1ea3o v\u1ec7 m\u00ecnh:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">Ch\u1ec9 t\u1ea3i ph\u1ea7n m\u1ec1m t\u1eeb trang ch\u00ednh th\u1ee9c ho\u1eb7c kho \u1ee9ng d\u1ee5ng \u0111\u00e1ng tin.<\/li>\n<li data-xf-list-type=\"ul\">Kh\u00f4ng nh\u1ea5p v\u00e0o link t\u1eeb GitHub\/Telegram n\u1ebfu kh\u00f4ng x\u00e1c minh \u0111\u01b0\u1ee3c ngu\u1ed3n.<\/li>\n<li data-xf-list-type=\"ul\">Lu\u00f4n d\u00f9ng ph\u1ea7n m\u1ec1m ch\u1ed1ng virus \u0111\u00e3 c\u1eadp nh\u1eadt, c\u00f3 t\u00ednh n\u0103ng ph\u00e1t hi\u1ec7n d\u1ef1a tr\u00ean h\u00e0nh vi.<\/li>\n<li data-xf-list-type=\"ul\">\u0110\u1ed5i m\u1eadt kh\u1ea9u \u0111\u1ecbnh k\u1ef3 v\u00e0 b\u1eadt x\u00e1c th\u1ef1c 2 y\u1ebfu t\u1ed1 v\u1edbi t\u00e0i kho\u1ea3n quan tr\u1ecdng.<\/li>\n<li data-xf-list-type=\"ul\">Theo d\u00f5i ho\u1ea1t \u0111\u1ed9ng m\u1ea1ng b\u1ea5t th\u01b0\u1eddng, nh\u01b0 k\u1ebft n\u1ed1i \u0111\u1ebfn Telegram ho\u1eb7c h\u00e0nh vi n\u00e9n\/chuy\u1ec3n file t\u1ef1 \u0111\u1ed9ng.<\/li>\n<\/ul>\n<p>S\u1ef1 xu\u1ea5t hi\u1ec7n c\u1ee7a Raven cho th\u1ea5y m\u00e3 \u0111\u1ed9c ng\u00e0y c\u00e0ng d\u1ec5 ti\u1ebfp c\u1eadn v\u00e0 nguy hi\u1ec3m h\u01a1n, \u0111\u1eb7c bi\u1ec7t khi ch\u00fang d\u1ef1a v\u00e0o n\u1ec1n t\u1ea3ng ph\u1ed5 bi\u1ebfn nh\u01b0 Telegram hay GitHub. Ng\u01b0\u1eddi d\u00f9ng c\u1ea7n t\u1ec9nh t\u00e1o v\u00e0 c\u1ea9n tr\u1ecdng trong t\u1eebng c\u00fa click \u0111\u1ec3 kh\u00f4ng tr\u1edf th\u00e0nh n\u1ea1n nh\u00e2n ti\u1ebfp theo.<\/p>\n<div style=\"text-align: right\"><b><i>Theo Cyber Press<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/raven-stealer-moi-de-doa-moi-tu-telegram-va-github-nham-vao-nguoi-dung-windows.18611\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/raven-stealer-moi-de-doa-moi-tu-telegram-va-github-nham-vao-nguoi-dung-windows.18611\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Th\u00e1ng 7\/2025, c\u00e1c chuy\u00ean gia an ninh m\u1ea1ng \u0111\u00e3 c\u1ea3nh b\u00e1o v\u1ec1 Raven Stealer &#8211; m\u1ed9t lo\u1ea1i ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i (malware) m\u1edbi chuy\u00ean \u0111\u00e1nh c\u1eafp th\u00f4ng tin c\u00e1 nh\u00e2n. Kh\u00e1c v\u1edbi nh\u1eefng chi\u1ebfn d\u1ecbch ph\u1ee9c t\u1ea1p tr\u01b0\u1edbc \u0111\u00e2y, Raven Stealer \u0111\u01a1n gi\u1ea3n nh\u01b0ng nguy hi\u1ec3m, \u0111\u01b0\u1ee3c ph\u00e1t t\u00e1n c\u00f4ng khai tr\u00ean GitHub v\u00e0 \u0111i\u1ec1u [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33],"tags":[],"class_list":["post-10415","post","type-post","status-publish","format-standard","hentry","category-tin-tuc-cua-vien"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10415","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=10415"}],"version-history":[{"count":0,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10415\/revisions"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=10415"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=10415"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=10415"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}