{"id":10521,"date":"2025-10-17T13:26:37","date_gmt":"2025-10-17T06:26:37","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=10521"},"modified":"2026-02-05T13:26:45","modified_gmt":"2026-02-05T06:26:45","slug":"hacker-giau-ma-doc-trong-blockchain-tan-cong-nguoi-dung-qua-website-wordpress","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/2025\/10\/17\/hacker-giau-ma-doc-trong-blockchain-tan-cong-nguoi-dung-qua-website-wordpress\/","title":{"rendered":"Hacker gi\u1ea5u m\u00e3 \u0111\u1ed9c trong blockchain, t\u1ea5n c\u00f4ng ng\u01b0\u1eddi d\u00f9ng qua website WordPress"},"content":{"rendered":"<p><b>Blockchain v\u1ed1n \u0111\u01b0\u1ee3c ca ng\u1ee3i l\u00e0 c\u00f4ng ngh\u1ec7 minh b\u1ea1ch, phi t\u1eadp trung nh\u01b0ng trong tay tin t\u1eb7c n\u00f3 l\u1ea1i tr\u1edf th\u00e0nh c\u00f4ng c\u1ee5 ho\u00e0n h\u1ea3o \u0111\u1ec3 \u1ea9n gi\u1ea5u m\u00e3 \u0111\u1ed9c. M\u1edbi \u0111\u00e2y, nh\u00f3m tin t\u1eb7c UNC5142 \u0111\u00e3 b\u1ecb ph\u00e1t hi\u1ec7n l\u1ee3i d\u1ee5ng h\u1ee3p \u0111\u1ed3ng th\u00f4ng minh tr\u00ean chu\u1ed7i BNB Smart Chain \u0111\u1ec3 ph\u00e1t t\u00e1n c\u00e1c m\u00e3 \u0111\u1ed9c \u0111\u00e1nh c\u1eafp th\u00f4ng tin ng\u01b0\u1eddi d\u00f9ng, bao g\u1ed3m: Atomic Stealer, Lumma, Rhadamanthys v\u00e0 Vidar.<\/b><\/p>\n<div style=\"text-align: center\">\n<div class=\"bbImageWrapper  js-lbImage\" title=\"1760676101072.png\" data-src=\"https:\/\/whitehat.vn\/attachments\/1760676101072-png.17756\/\" data-lb-sidebar-href=\"\" data-lb-caption-extra-html=\"\" data-single-image=\"1\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage\" title=\"1760676101072.png\" src=\"https:\/\/whitehat.vn\/attachments\/1760676101072-png.17756\/\" alt=\"1760676101072.png\" width=\"790\" height=\"413\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<\/div>\n<p>\u0110i\u1ec1u \u0111\u00e1ng n\u00f3i, chi\u1ebfn d\u1ecbch n\u00e0y t\u1ea5n c\u00f4ng c\u1ea3 ng\u01b0\u1eddi d\u00f9ng Windows v\u00e0 macOS, d\u00f9ng ch\u00ednh c\u00e1c website WordPress b\u1ecb x\u00e2m nh\u1eadp l\u00e0m b\u00e0n \u0111\u1ea1p l\u00e2y lan.<\/p>\n<p>Theo b\u00e1o c\u00e1o c\u1ee7a Google, ch\u1ec9 t\u00ednh \u0111\u1ebfn th\u00e1ng 6\/2025, c\u00f3 h\u01a1n 14.000 trang web WordPress b\u1ecb ch\u00e8n m\u00e3 JavaScript \u0111\u1ed9c h\u1ea1i li\u00ean quan \u0111\u1ebfn nh\u00f3m UNC5142. D\u00f9 nh\u00f3m n\u00e0y t\u1ea1m th\u1eddi \u201cim \u1eafng\u201d t\u1eeb th\u00e1ng 7\/2025 nh\u01b0ng chi\u1ebfn thu\u1eadt c\u1ee7a ch\u00fang \u0111ang khi\u1ebfn gi\u1edbi chuy\u00ean gia b\u1ea3o m\u1eadt \u0111\u1eb7c bi\u1ec7t lo ng\u1ea1i.<\/p>\n<p>Thay v\u00ec l\u01b0u m\u00e3 \u0111\u1ed9c tr\u00ean server \u1ea9n danh ho\u1eb7c file-sharing nh\u01b0 tr\u01b0\u1edbc, UNC5142 gi\u1ea5u m\u00e3 \u0111\u1ed9c ngay trong h\u1ee3p \u0111\u1ed3ng th\u00f4ng minh blockchain, khi\u1ebfn vi\u1ec7c g\u1ee1 b\u1ecf g\u1ea7n nh\u01b0 b\u1ea5t kh\u1ea3 thi. M\u1ed9t khi m\u00e3 \u0111\u1ed9c \u0111\u00e3 \u0111\u01b0\u1ee3c ghi v\u00e0o blockchain, n\u00f3 t\u1ed3n t\u1ea1i v\u0129nh vi\u1ec5n v\u00ec d\u1eef li\u1ec7u tr\u00ean chu\u1ed7i kh\u00f4ng th\u1ec3 x\u00f3a hay ch\u1ec9nh s\u1eeda.<\/p>\n<p>Chi\u1ebfn d\u1ecbch n\u00e0y s\u1eed d\u1ee5ng m\u1ed9t tr\u00ecnh t\u1ea3i \u0111a t\u1ea7ng c\u00f3 t\u00ean CLEARSHORT (\u0111\u00e2y l\u00e0 bi\u1ebfn th\u1ec3 c\u1ee7a ClearFake t\u1eebng \u0111\u01b0\u1ee3c ph\u00e1t hi\u1ec7n t\u1eeb n\u0103m 2023). Giai \u0111o\u1ea1n \u0111\u1ea7u, m\u00e3 JavaScript \u0111\u01b0\u1ee3c c\u1ea5y v\u00e0o plugin ho\u1eb7c theme c\u1ee7a website WordPress. M\u00e3 n\u00e0y s\u1ebd g\u1ecdi \u0111\u1ebfn h\u1ee3p \u0111\u1ed3ng th\u00f4ng minh tr\u00ean BNB Smart Chain &#8211; n\u01a1i ch\u1ee9a \u0111\u1ecba ch\u1ec9 m\u00e1y ch\u1ee7 \u0111i\u1ec1u khi\u1ec3n v\u00e0 d\u1eef li\u1ec7u gi\u1ea3i m\u00e3.<\/p>\n<p>T\u1eeb \u0111\u00f3, n\u1ea1n nh\u00e2n s\u1ebd b\u1ecb chuy\u1ec3n h\u01b0\u1edbng \u0111\u1ebfn trang web gi\u1ea3 m\u1ea1o c\u1eadp nh\u1eadt tr\u00ecnh duy\u1ec7t (fake update), th\u01b0\u1eddng \u0111\u01b0\u1ee3c l\u01b0u tr\u1eef tr\u00ean c\u00e1c t\u00ean mi\u1ec1n h\u1ee3p ph\u00e1p nh\u01b0 Cloudflare .dev khi\u1ebfn ng\u01b0\u1eddi d\u00f9ng kh\u00f3 nh\u1eadn ra. Khi truy c\u1eadp, n\u1ea1n nh\u00e2n b\u1ecb d\u1ee5 ch\u1ea1y m\u1ed9t l\u1ec7nh \u0111\u1ed9c h\u1ea1i qua c\u1eeda s\u1ed5 Run tr\u00ean Windows ho\u1eb7c Terminal tr\u00ean macOS \u0111\u1ec3 t\u1ea3i v\u00e0 ch\u1ea1y m\u00e3 \u0111\u1ed9c \u0111\u00e1nh c\u1eafp d\u1eef li\u1ec7u.<\/p>\n<p>Tr\u00ean Windows, m\u00e3 \u0111\u1ed9c t\u1ea3i xu\u1ed1ng file HTA t\u1eeb MediaFire, ch\u1ea1y PowerShell \u0111\u1ec3 t\u1ea3i m\u00e3 \u0111\u1ed9c th\u1ef1c thi tr\u1ef1c ti\u1ebfp trong b\u1ed9 nh\u1edb (fileless malware) gi\u00fap tr\u00e1nh b\u1ecb ph\u1ea7n m\u1ec1m di\u1ec7t virus ph\u00e1t hi\u1ec7n.<\/p>\n<p>Trong khi \u0111\u00f3, tr\u00ean macOS, ng\u01b0\u1eddi d\u00f9ng b\u1ecb l\u1eeba ch\u1ea1y l\u1ec7nh bash ho\u1eb7c curl \u0111\u1ec3 t\u1ea3i Atomic Stealer (m\u00e3 \u0111\u1ed9c chuy\u00ean \u0111\u00e1nh c\u1eafp d\u1eef li\u1ec7u v\u00ed ti\u1ec1n \u0111i\u1ec7n t\u1eed, m\u1eadt kh\u1ea9u v\u00e0 cookie).<\/p>\n<p>Google cho bi\u1ebft UNC5142 \u0111\u00e3 tinh vi h\u01a1n qua t\u1eebng giai \u0111o\u1ea1n. Ban \u0111\u1ea7u ch\u1ec9 d\u00f9ng m\u1ed9t h\u1ee3p \u0111\u1ed3ng th\u00f4ng minh, \u0111\u1ebfn cu\u1ed1i n\u0103m 2024, ch\u00fang ph\u00e1t tri\u1ec3n th\u00e0nh ki\u1ebfn tr\u00fac ba h\u1ee3p \u0111\u1ed3ng (Router &#8211; Logic &#8211; Storage) m\u00f4 ph\u1ecfng theo m\u00f4 h\u00ecnh proxy trong l\u1eadp tr\u00ecnh h\u1ee3p ph\u00e1p. C\u00e1ch n\u00e0y cho ph\u00e9p hacker thay \u0111\u1ed5i \u0111\u01b0\u1eddng d\u1eabn t\u1ea3i m\u00e3 \u0111\u1ed9c, kh\u00f3a gi\u1ea3i m\u00e3 ho\u1eb7c m\u00e1y ch\u1ee7 \u0111i\u1ec1u khi\u1ec3n ch\u1ec9 v\u1edbi v\u00e0i thao t\u00e1c c\u1eadp nh\u1eadt d\u1eef li\u1ec7u h\u1ee3p \u0111\u1ed3ng, ti\u00eau t\u1ed1n ch\u01b0a t\u1edbi 2 USD ph\u00ed m\u1ea1ng.<\/p>\n<p>Nh\u1edd \u0111\u00f3, d\u00f9 c\u00e1c chuy\u00ean gia an ninh ch\u1eb7n ho\u1eb7c g\u1ee1 m\u00e3 JavaScript tr\u00ean web b\u1ecb nhi\u1ec5m, hacker v\u1eabn c\u00f3 th\u1ec3 nhanh ch\u00f3ng \u201cc\u1eadp nh\u1eadt\u201d chi\u1ebfn d\u1ecbch m\u00e0 kh\u00f4ng ph\u1ea3i ch\u1ec9nh l\u1ea1i to\u00e0n b\u1ed9 m\u00e3, c\u1ef1c k\u1ef3 linh ho\u1ea1t v\u00e0 kh\u00f3 b\u1ecb tri\u1ec7t h\u1ea1.<\/p>\n<p>Google c\u00f2n ph\u00e1t hi\u1ec7n hai h\u1ea1 t\u1ea7ng ri\u00eang bi\u1ec7t:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">H\u1ea1 t\u1ea7ng ch\u00ednh (Main infrastructure) ho\u1ea1t \u0111\u1ed9ng t\u1eeb th\u00e1ng 11\/2024, \u0111\u01b0\u1ee3c c\u1eadp nh\u1eadt \u0111\u1ec1u \u0111\u1eb7n.<\/li>\n<li data-xf-list-type=\"ul\">H\u1ea1 t\u1ea7ng ph\u1ee5 (Secondary infrastructure) xu\u1ea5t hi\u1ec7n th\u00e1ng 2\/2025, c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c d\u00f9ng \u0111\u1ec3 th\u1eed nghi\u1ec7m ho\u1eb7c t\u0103ng quy m\u00f4 t\u1ea5n c\u00f4ng.<\/li>\n<\/ul>\n<p>Nh\u1eefng d\u1ea5u hi\u1ec7u n\u00e0y cho th\u1ea5y UNC5142 \u0111\u00e3 \u0111\u1ea1t \u0111\u01b0\u1ee3c th\u00e0nh c\u00f4ng nh\u1ea5t \u0111\u1ecbnh, khi quy m\u00f4, t\u1ea7n su\u1ea5t c\u1eadp nh\u1eadt v\u00e0 l\u01b0\u1ee3ng website b\u1ecb x\u00e2m nh\u1eadp \u0111\u1ec1u t\u0103ng \u1ed5n \u0111\u1ecbnh su\u1ed1t h\u01a1n m\u1ed9t n\u0103m qua.<\/p>\n<p>C\u00e1c chi\u1ebfn d\u1ecbch ki\u1ec3u n\u00e0y \u0111\u00e1nh tr\u1ef1c ti\u1ebfp v\u00e0o ng\u01b0\u1eddi d\u00f9ng Internet th\u00f4ng th\u01b0\u1eddng. \u0110\u1ed3ng th\u1eddi, c\u00e1c qu\u1ea3n tr\u1ecb vi\u00ean website WordPress c\u0169ng l\u00e0 m\u1ee5c ti\u00eau trung gian quan tr\u1ecdng: khi website b\u1ecb c\u1ea5y m\u00e3 \u0111\u1ed9c, n\u00f3 v\u00f4 t\u00ecnh tr\u1edf th\u00e0nh c\u00f4ng c\u1ee5 ph\u00e1t t\u00e1n.<\/p>\n<p>Nguy c\u01a1 ch\u00ednh ng\u01b0\u1eddi d\u00f9ng s\u1ebd ph\u1ea3i \u0111\u1ed1i m\u1eb7t:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">Ng\u01b0\u1eddi d\u00f9ng c\u00e1 nh\u00e2n b\u1ecb \u0111\u00e1nh c\u1eafp d\u1eef li\u1ec7u \u0111\u0103ng nh\u1eadp, v\u00ed ti\u1ec1n \u0111i\u1ec7n t\u1eed, cookie tr\u00ecnh duy\u1ec7t.<\/li>\n<li data-xf-list-type=\"ul\">Website doanh nghi\u1ec7p ho\u1eb7c blog b\u1ecb l\u1ee3i d\u1ee5ng ph\u00e1t t\u00e1n m\u00e3 \u0111\u1ed9c, \u1ea3nh h\u01b0\u1edfng uy t\u00edn SEO.<\/li>\n<li data-xf-list-type=\"ul\">Blockchain b\u1ecb \u201c\u00f4 nhi\u1ec5m\u201d b\u1edfi d\u1eef li\u1ec7u \u0111\u1ed9c h\u1ea1i kh\u00f3 x\u00f3a b\u1ecf.<\/li>\n<\/ul>\n<p>Khuy\u1ebfn c\u00e1o t\u1eeb c\u00e1c chuy\u00ean gia an ninh m\u1ea1ng:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">C\u1eadp nh\u1eadt WordPress, plugin, theme l\u00ean phi\u00ean b\u1ea3n m\u1edbi nh\u1ea5t.<\/li>\n<li data-xf-list-type=\"ul\">X\u00f3a m\u00e3 ch\u00e8n l\u1ea1 trong file plugin\/theme ho\u1eb7c c\u01a1 s\u1edf d\u1eef li\u1ec7u.<\/li>\n<li data-xf-list-type=\"ul\">C\u1ea3nh gi\u00e1c v\u1edbi c\u1ea3nh b\u00e1o \u201cc\u1eadp nh\u1eadt tr\u00ecnh duy\u1ec7t\u201d, \u0111\u1eb7c bi\u1ec7t khi xu\u1ea5t hi\u1ec7n tr\u00ean trang kh\u00f4ng ch\u00ednh ch\u1ee7.<\/li>\n<li data-xf-list-type=\"ul\">V\u1edbi qu\u1ea3n tr\u1ecb vi\u00ean web, n\u00ean qu\u00e9t \u0111\u1ecbnh k\u1ef3 b\u1eb1ng c\u00f4ng c\u1ee5 b\u1ea3o m\u1eadt, gi\u00e1m s\u00e1t t\u1ec7p JavaScript v\u00e0 ho\u1ea1t \u0111\u1ed9ng b\u1ea5t th\u01b0\u1eddng.<\/li>\n<li data-xf-list-type=\"ul\">T\u1ed5 ch\u1ee9c doanh nghi\u1ec7p c\u00f3 th\u1ec3 \u00e1p d\u1ee5ng CSP (Content Security Policy) v\u00e0 WAF \u0111\u1ec3 ng\u0103n ch\u00e8n m\u00e3 tr\u00e1i ph\u00e9p.<\/li>\n<\/ul>\n<p>V\u1ee5 vi\u1ec7c UNC5142 l\u00e0 v\u00ed d\u1ee5 \u0111i\u1ec3n h\u00ecnh cho th\u1ea5y c\u00f4ng ngh\u1ec7 trung l\u1eadp nh\u01b0 blockchain c\u00f3 th\u1ec3 b\u1ecb bi\u1ebfn t\u01b0\u1edbng th\u00e0nh \u201c\u1ed5 ch\u1ee9a\u201d m\u00e3 \u0111\u1ed9c b\u1ea5t c\u1ee9 l\u00fac n\u00e0o. Khi hacker bi\u1ebft t\u1eadn d\u1ee5ng t\u00ednh phi t\u1eadp trung v\u00e0 kh\u00f3 ki\u1ec3m so\u00e1t, vi\u1ec7c g\u1ee1 b\u1ecf m\u00e3 \u0111\u1ed9c g\u1ea7n nh\u01b0 l\u00e0 nhi\u1ec7m v\u1ee5 b\u1ea5t kh\u1ea3 thi. Ng\u01b0\u1eddi d\u00f9ng v\u00e0 qu\u1ea3n tr\u1ecb vi\u00ean web c\u1ea7n hi\u1ec3u r\u1eb1ng m\u1ed9t d\u00f2ng JavaScript nh\u1ecf c\u0169ng \u0111\u1ee7 m\u1edf c\u00e1nh c\u1eeda cho c\u1ea3 h\u1ec7 th\u1ed1ng t\u1ed9i ph\u1ea1m m\u1ea1ng b\u01b0\u1edbc v\u00e0o. Trong th\u1ebf gi\u1edbi m\u1ea1ng, th\u1ee9 nguy hi\u1ec3m nh\u1ea5t kh\u00f4ng ph\u1ea3i l\u00e0 c\u00f4ng ngh\u1ec7 m\u00e0 l\u00e0 b\u00e0n tay con ng\u01b0\u1eddi \u0111i\u1ec1u khi\u1ec3n n\u00f3 sai h\u01b0\u1edbng.<\/p>\n<div style=\"text-align: right\"><b><i>WhiteHat<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/hacker-giau-ma-doc-trong-blockchain-tan-cong-nguoi-dung-qua-website-wordpress.18845\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/hacker-giau-ma-doc-trong-blockchain-tan-cong-nguoi-dung-qua-website-wordpress.18845\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Blockchain v\u1ed1n \u0111\u01b0\u1ee3c ca ng\u1ee3i l\u00e0 c\u00f4ng ngh\u1ec7 minh b\u1ea1ch, phi t\u1eadp trung nh\u01b0ng trong tay tin t\u1eb7c n\u00f3 l\u1ea1i tr\u1edf th\u00e0nh c\u00f4ng c\u1ee5 ho\u00e0n h\u1ea3o \u0111\u1ec3 \u1ea9n gi\u1ea5u m\u00e3 \u0111\u1ed9c. M\u1edbi \u0111\u00e2y, nh\u00f3m tin t\u1eb7c UNC5142 \u0111\u00e3 b\u1ecb ph\u00e1t hi\u1ec7n l\u1ee3i d\u1ee5ng h\u1ee3p \u0111\u1ed3ng th\u00f4ng minh tr\u00ean chu\u1ed7i BNB Smart Chain \u0111\u1ec3 ph\u00e1t t\u00e1n [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33],"tags":[],"class_list":["post-10521","post","type-post","status-publish","format-standard","hentry","category-tin-tuc-cua-vien"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10521","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=10521"}],"version-history":[{"count":0,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10521\/revisions"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=10521"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=10521"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=10521"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}