Security companies: more than 1 million computers around the world have been infected by Trojans due to the "Eternal Blue" vulnerability.
CTOnews.com, October 30 (Xinhua)-- the EternalBlue vulnerability, which was released by the hacker organization The Shadow Brokers in April 2017, triggered an explosion of WannaCry ransomware.
But Kaspersky points out that researchers estimate that there are still more than 1 million computers around the world that still have vulnerabilities, while nearly 60,000 computers were hacked due to vulnerabilities between April and September this year.
Kaspersky also disclosed a malicious Trojan horse StripedFly that is said to have existed for more than 5 years. Researchers first found that malicious code was injected into the victim's Wininit.exe process in 2022.
This malicious code has appeared in the malicious Trojan Equation before, but was mistaken for a mining program by security companies at the time, but now Kaspersky has found that the malicious code not only excavates the mine, but also deploys the StripedFly malicious Trojan that exploits the eternal blue vulnerability.
▲ source Kaspersky CTOnews.com found in the Kaspersky report that the relevant malicious code will download a series of camouflaged malicious Trojans from Bitbucket, GitHub, and GitLab, exploiting the Eternal Blue (EternalBlue,CVE-2017-0144) vulnerability exposed in 2017, and eventually deploying StripedFly on the victim's computer.
It is reported that StripedFly can execute any code deployed by hackers and spread StripedFly to Windows and Linux computers connected to the same network through SSH, thus causing attacks on more devices.