{"id":47837,"date":"2026-05-08T15:44:43","date_gmt":"2026-05-08T08:44:43","guid":{"rendered":"https:\/\/antoanthongtinhaiphong.gov.vn\/?p=47837"},"modified":"2026-05-13T15:49:06","modified_gmt":"2026-05-13T08:49:06","slug":"ma-doc-moi-loi-dung-microsoft-phone-link-chiem-otp-va-tai-khoan-nguoi-dung","status":"publish","type":"post","link":"https:\/\/antoanthongtinhaiphong.gov.vn\/ma-doc-moi-loi-dung-microsoft-phone-link-chiem-otp-va-tai-khoan-nguoi-dung\/","title":{"rendered":"M\u00e3 \u0111\u1ed9c m\u1edbi l\u1ee3i d\u1ee5ng Microsoft Phone Link chi\u1ebfm OTP v\u00e0 t\u00e0i kho\u1ea3n ng\u01b0\u1eddi d\u00f9ng"},"content":{"rendered":"<div><b>C\u00e1c chuy\u00ean gia an ninh m\u1ea1ng v\u1eeba c\u00f4ng b\u1ed1 chi ti\u1ebft v\u1ec1 m\u1ed9t chi\u1ebfn d\u1ecbch t\u1ea5n c\u00f4ng m\u1ea1ng tinh vi s\u1eed d\u1ee5ng m\u00e3 \u0111\u1ed9c \u0111i\u1ec1u khi\u1ec3n t\u1eeb xa CloudZ RAT k\u1ebft h\u1ee3p v\u1edbi plugin ch\u01b0a t\u1eebng \u0111\u01b0\u1ee3c ghi nh\u1eadn tr\u01b0\u1edbc \u0111\u00e2y c\u00f3 t\u00ean Pheno nh\u1eb1m \u0111\u00e1nh c\u1eafp th\u00f4ng tin \u0111\u0103ng nh\u1eadp v\u00e0 m\u00e3 x\u00e1c th\u1ef1c m\u1ed9t l\u1ea7n (OTP) c\u1ee7a n\u1ea1n nh\u00e2n.<\/b><br \/>\n\u200b<\/div>\n<div>\n<div class=\"bbImageWrapper  js-lbImage\" title=\"1778146173426.png\" data-src=\"https:\/\/whitehat.vn\/attachments\/1778146173426-png.18973\/\" data-lb-sidebar-href=\"\" data-lb-caption-extra-html=\"\" data-single-image=\"1\"><img loading=\"lazy\" decoding=\"async\" class=\"bbImage\" title=\"1778146173426.png\" src=\"https:\/\/whitehat.vn\/attachments\/1778146173426-png.18973\/\" alt=\"1778146173426.png\" width=\"900\" height=\"470\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<\/div>\n<div>\n\u0110i\u1ec3m \u0111\u00e1ng ch\u00fa \u00fd c\u1ee7a chi\u1ebfn d\u1ecbch n\u00e0y n\u1eb1m \u1edf ch\u1ed7 tin t\u1eb7c kh\u00f4ng c\u1ea7n c\u00e0i m\u00e3 \u0111\u1ed9c tr\u1ef1c ti\u1ebfp l\u00ean \u0111i\u1ec7n tho\u1ea1i nh\u01b0ng v\u1eabn c\u00f3 th\u1ec3 truy c\u1eadp d\u1eef li\u1ec7u \u0111\u1ed3ng b\u1ed9 gi\u1eefa \u0111i\u1ec7n tho\u1ea1i v\u00e0 m\u00e1y t\u00ednh th\u00f4ng qua \u1ee9ng d\u1ee5ng Microsoft Phone Link. \u0110i\u1ec1u n\u00e0y cho th\u1ea5y c\u00e1c t\u00ednh n\u0103ng k\u1ebft n\u1ed1i \u0111a thi\u1ebft b\u1ecb v\u1ed1n ph\u1ee5c v\u1ee5 s\u1ef1 ti\u1ec7n l\u1ee3i cho ng\u01b0\u1eddi d\u00f9ng \u0111ang d\u1ea7n tr\u1edf th\u00e0nh m\u1ee5c ti\u00eau b\u1ecb l\u1ee3i d\u1ee5ng trong c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng m\u1ea1ng hi\u1ec7n \u0111\u1ea1i.\u200b<\/div>\n<div>CloudZ RAT v\u00e0 plugin Pheno l\u00e0 g\u00ec?\u200b<\/div>\n<div>Theo ph\u00e2n t\u00edch, m\u00e3 \u0111\u1ed9c ch\u00ednh \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng trong chi\u1ebfn d\u1ecbch l\u00e0 CloudZ RAT, l\u00e0 m\u1ed9t lo\u1ea1i trojan \u0111i\u1ec1u khi\u1ec3n t\u1eeb xa cho ph\u00e9p k\u1ebb t\u1ea5n c\u00f4ng ki\u1ec3m so\u00e1t m\u00e1y t\u00ednh b\u1ecb nhi\u1ec5m, th\u1ef1c thi l\u1ec7nh, \u0111\u00e1nh c\u1eafp d\u1eef li\u1ec7u v\u00e0 tri\u1ec3n khai th\u00eam c\u00e1c plugin \u0111\u1ed9c h\u1ea1i kh\u00e1c. \u0110i c\u00f9ng v\u1edbi CloudZ l\u00e0 m\u1ed9t plugin m\u1edbi c\u00f3 t\u00ean Pheno. Plugin n\u00e0y \u0111\u01b0\u1ee3c thi\u1ebft k\u1ebf chuy\u00ean bi\u1ec7t \u0111\u1ec3 theo d\u00f5i ho\u1ea1t \u0111\u1ed9ng c\u1ee7a \u1ee9ng d\u1ee5ng Microsoft Phone Link tr\u00ean m\u00e1y t\u00ednh Windows.<\/p>\n<p>Phone Link l\u00e0 \u1ee9ng d\u1ee5ng \u0111\u01b0\u1ee3c t\u00edch h\u1ee3p s\u1eb5n tr\u00ean Windows 10 v\u00e0 Windows 11, cho ph\u00e9p ng\u01b0\u1eddi d\u00f9ng k\u1ebft n\u1ed1i \u0111i\u1ec7n tho\u1ea1i Android ho\u1eb7c iPhone v\u1edbi m\u00e1y t\u00ednh th\u00f4ng qua Wi-Fi v\u00e0 Bluetooth. Sau khi k\u1ebft n\u1ed1i, ng\u01b0\u1eddi d\u00f9ng c\u00f3 th\u1ec3 xem tin nh\u1eafn SMS, nh\u1eadn cu\u1ed9c g\u1ecdi, \u0111\u1ed3ng b\u1ed9 th\u00f4ng b\u00e1o ho\u1eb7c truy c\u1eadp m\u1ed9t s\u1ed1 d\u1eef li\u1ec7u \u0111i\u1ec7n tho\u1ea1i tr\u1ef1c ti\u1ebfp t\u1eeb m\u00e1y t\u00ednh. Ch\u00ednh c\u01a1 ch\u1ebf \u0111\u1ed3ng b\u1ed9 n\u00e0y \u0111\u00e3 b\u1ecb tin t\u1eb7c l\u1ee3i d\u1ee5ng nh\u01b0 m\u1ed9t \u201cc\u1ea7u n\u1ed1i\u201d \u0111\u1ec3 ti\u1ebfp c\u1eadn d\u1eef li\u1ec7u nh\u1ea1y c\u1ea3m tr\u00ean \u0111i\u1ec7n tho\u1ea1i m\u00e0 kh\u00f4ng c\u1ea7n t\u1ea5n c\u00f4ng tr\u1ef1c ti\u1ebfp v\u00e0o thi\u1ebft b\u1ecb di \u0111\u1ed9ng.\u200b<\/p><\/div>\n<div>Cu\u1ed9c t\u1ea5n c\u00f4ng di\u1ec5n ra nh\u01b0 th\u1ebf n\u00e0o?\u200b<\/div>\n<div>Theo Cisco Talos, ho\u1ea1t \u0111\u1ed9ng n\u00e0y \u0111\u00e3 di\u1ec5n ra \u00edt nh\u1ea5t t\u1eeb th\u00e1ng 01\/2026, tuy nhi\u00ean hi\u1ec7n ch\u01b0a x\u00e1c \u0111\u1ecbnh \u0111\u01b0\u1ee3c nh\u00f3m tin t\u1eb7c \u0111\u1ee9ng sau chi\u1ebfn d\u1ecbch. Qu\u00e1 tr\u00ecnh t\u1ea5n c\u00f4ng b\u1eaft \u0111\u1ea7u b\u1eb1ng vi\u1ec7c tin t\u1eb7c t\u00ecm c\u00e1ch x\u00e2m nh\u1eadp v\u00e0o m\u00e1y t\u00ednh n\u1ea1n nh\u00e2n th\u00f4ng qua m\u1ed9t ph\u01b0\u01a1ng th\u1ee9c ch\u01b0a \u0111\u01b0\u1ee3c x\u00e1c \u0111\u1ecbnh r\u00f5. Sau khi c\u00f3 ch\u1ed7 \u0111\u1ee9ng trong h\u1ec7 th\u1ed1ng, ch\u00fang tri\u1ec3n khai m\u1ed9t t\u1ec7p gi\u1ea3 m\u1ea1o mang danh ngh\u0129a ph\u1ea7n m\u1ec1m ConnectWise ScreenConnect.<\/p>\n<p>T\u1ec7p gi\u1ea3 n\u00e0y th\u1ef1c ch\u1ea5t l\u00e0 dropper th\u00e0nh ph\u1ea7n ch\u1ecbu tr\u00e1ch nhi\u1ec7m t\u1ea3i xu\u1ed1ng v\u00e0 k\u00edch ho\u1ea1t m\u00e3 \u0111\u1ed9c &#8220;.NET loader&#8221;. \u0110\u1ed3ng th\u1eddi, malware c\u0169ng s\u1eed d\u1ee5ng PowerShell \u0111\u1ec3 t\u1ea1o Scheduled Task nh\u1eb1m duy tr\u00ec kh\u1ea3 n\u0103ng t\u1ed3n t\u1ea1i tr\u00ean h\u1ec7 th\u1ed1ng ngay c\u1ea3 khi m\u00e1y t\u00ednh kh\u1edfi \u0111\u1ed9ng l\u1ea1i. Sau \u0111\u00f3, loader trung gian s\u1ebd ki\u1ec3m tra m\u00f4i tr\u01b0\u1eddng m\u00e1y t\u00ednh nh\u1eb1m n\u00e9 tr\u00e1nh h\u1ec7 th\u1ed1ng ph\u00e1t hi\u1ec7n m\u00e3 \u0111\u1ed9c tr\u01b0\u1edbc khi c\u00e0i \u0111\u1eb7t CloudZ RAT ho\u00e0n ch\u1ec9nh.<\/p>\n<p>Khi \u0111\u01b0\u1ee3c k\u00edch ho\u1ea1t, CloudZ RAT s\u1ebd gi\u1ea3i m\u00e3 c\u1ea5u h\u00ecnh nh\u00fang b\u00ean trong, thi\u1ebft l\u1eadp k\u1ebft n\u1ed1i m\u00e3 h\u00f3a t\u1edbi m\u00e1y ch\u1ee7 \u0111i\u1ec1u khi\u1ec3n C2 v\u00e0 ch\u1edd nh\u1eadn l\u1ec7nh t\u1eeb tin t\u1eb7c. Malware c\u00f3 th\u1ec3 th\u1ef1c hi\u1ec7n nhi\u1ec1u ch\u1ee9c n\u0103ng nh\u01b0:\u200b<\/p><\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div>\u0110\u00e1nh c\u1eafp d\u1eef li\u1ec7u tr\u00ecnh duy\u1ec7t\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>Thu th\u1eadp th\u00f4ng tin h\u1ec7 th\u1ed1ng\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>Qu\u1ea3n l\u00fd t\u1ec7p tin\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>T\u1ea3i th\u00eam plugin \u0111\u1ed9c h\u1ea1i\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>Quay m\u00e0n h\u00ecnh\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>Th\u1ef1c thi l\u1ec7nh t\u1eeb xa\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>Thu th\u1eadp d\u1eef li\u1ec7u t\u1eeb Microsoft Phone Link\u200b<\/div>\n<\/li>\n<\/ul>\n<div>\u0110i\u1ec3m nguy hi\u1ec3m nh\u1ea5t n\u1eb1m \u1edf plugin Pheno. Plugin n\u00e0y li\u00ean t\u1ee5c ki\u1ec3m tra xem \u1ee9ng d\u1ee5ng Phone Link c\u00f3 \u0111ang ho\u1ea1t \u0111\u1ed9ng tr\u00ean m\u00e1y n\u1ea1n nh\u00e2n hay kh\u00f4ng. N\u1ebfu ph\u00e1t hi\u1ec7n c\u00f3 k\u1ebft n\u1ed1i gi\u1eefa m\u00e1y t\u00ednh v\u00e0 \u0111i\u1ec7n tho\u1ea1i, n\u00f3 s\u1ebd truy c\u1eadp c\u01a1 s\u1edf d\u1eef li\u1ec7u SQLite m\u00e0 Phone Link s\u1eed d\u1ee5ng \u0111\u1ec3 l\u01b0u d\u1eef li\u1ec7u \u0111\u1ed3ng b\u1ed9.<\/p>\n<p>Th\u00f4ng qua \u0111\u00f3, tin t\u1eb7c c\u00f3 th\u1ec3 thu th\u1eadp:\u200b<\/p><\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div>Tin nh\u1eafn SMS\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>M\u00e3 OTP x\u00e1c th\u1ef1c hai l\u1edbp\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>Th\u00f4ng b\u00e1o t\u1eeb \u0111i\u1ec7n tho\u1ea1i\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>M\u1ed9t s\u1ed1 d\u1eef li\u1ec7u li\u00ean quan \u0111\u1ebfn t\u00e0i kho\u1ea3n ng\u01b0\u1eddi d\u00f9ng\u200b<\/div>\n<\/li>\n<\/ul>\n<div>To\u00e0n b\u1ed9 d\u1eef li\u1ec7u sau \u0111\u00f3 \u0111\u01b0\u1ee3c chuy\u1ec3n ng\u01b0\u1ee3c v\u1ec1 m\u00e1y ch\u1ee7 \u0111i\u1ec1u khi\u1ec3n c\u1ee7a hacker.\u200b<\/div>\n<div>V\u00ec sao cu\u1ed9c t\u1ea5n c\u00f4ng n\u00e0y \u0111\u1eb7c bi\u1ec7t nguy hi\u1ec3m?\u200b<\/div>\n<div>Kh\u00e1c v\u1edbi nhi\u1ec1u chi\u1ebfn d\u1ecbch \u0111\u00e1nh c\u1eafp OTP truy\u1ec1n th\u1ed1ng ph\u1ea3i c\u00e0i m\u00e3 \u0111\u1ed9c tr\u1ef1c ti\u1ebfp l\u00ean \u0111i\u1ec7n tho\u1ea1i Android ho\u1eb7c s\u1eed d\u1ee5ng k\u1ef9 thu\u1eadt gi\u1ea3 m\u1ea1o SMS, chi\u1ebfn d\u1ecbch l\u1ea7n n\u00e0y t\u1eadn d\u1ee5ng ch\u00ednh t\u00ednh n\u0103ng h\u1ee3p ph\u00e1p c\u1ee7a Windows. \u0110i\u1ec1u n\u00e0y khi\u1ebfn vi\u1ec7c ph\u00e1t hi\u1ec7n tr\u1edf n\u00ean kh\u00f3 kh\u0103n h\u01a1n r\u1ea5t nhi\u1ec1u v\u00ec Phone Link v\u1ed1n l\u00e0 \u1ee9ng d\u1ee5ng \u0111\u00e1ng tin c\u1eady do Microsoft ph\u00e1t tri\u1ec3n.<\/p>\n<p>Quan tr\u1ecdng h\u01a1n, c\u01a1 ch\u1ebf n\u00e0y c\u00f3 th\u1ec3 gi\u00fap tin t\u1eb7c v\u01b0\u1ee3t qua x\u00e1c th\u1ef1c hai l\u1edbp (2FA). Trong nhi\u1ec1u tr\u01b0\u1eddng h\u1ee3p, d\u00f9 hacker \u0111\u00e3 \u0111\u00e1nh c\u1eafp \u0111\u01b0\u1ee3c m\u1eadt kh\u1ea9u, ch\u00fang v\u1eabn c\u1ea7n OTP \u0111\u1ec3 ho\u00e0n t\u1ea5t \u0111\u0103ng nh\u1eadp. N\u1ebfu OTP b\u1ecb thu th\u1eadp qua Phone Link, l\u1edbp b\u1ea3o v\u1ec7 2FA g\u1ea7n nh\u01b0 m\u1ea5t t\u00e1c d\u1ee5ng.<\/p>\n<p>Theo Cisco Talos, chi\u1ebfn d\u1ecbch n\u00e0y ph\u1ea3n \u00e1nh xu h\u01b0\u1edbng m\u1edbi trong t\u1ea5n c\u00f4ng m\u1ea1ng: thay v\u00ec x\u00e2m nh\u1eadp tr\u1ef1c ti\u1ebfp v\u00e0o \u0111i\u1ec7n tho\u1ea1i hacker chuy\u1ec3n sang khai th\u00e1c c\u00e1c \u201cc\u1ea7u n\u1ed1i\u201d gi\u1eefa \u0111i\u1ec7n tho\u1ea1i v\u00e0 m\u00e1y t\u00ednh.\u200b<\/p><\/div>\n<div>Ng\u01b0\u1eddi d\u00f9ng v\u00e0 doanh nghi\u1ec7p b\u1ecb \u1ea3nh h\u01b0\u1edfng ra sao?\u200b<\/div>\n<div>C\u00e1c c\u00e1 nh\u00e2n s\u1eed d\u1ee5ng Phone Link \u0111\u1ec3 \u0111\u1ed3ng b\u1ed9 \u0111i\u1ec7n tho\u1ea1i v\u1edbi m\u00e1y t\u00ednh c\u00f3 nguy c\u01a1 b\u1ecb \u0111\u00e1nh c\u1eafp:\u200b<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div>T\u00e0i kho\u1ea3n email\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>T\u00e0i kho\u1ea3n m\u1ea1ng x\u00e3 h\u1ed9i\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>T\u00e0i kho\u1ea3n ng\u00e2n h\u00e0ng ho\u1eb7c v\u00ed \u0111i\u1ec7n t\u1eed\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>OTP x\u00e1c th\u1ef1c\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>D\u1eef li\u1ec7u nh\u1ea1y c\u1ea3m trong tin nh\u1eafn\u200b<\/div>\n<\/li>\n<\/ul>\n<div>\u0110\u1ed1i v\u1edbi doanh nghi\u1ec7p, nguy c\u01a1 c\u00f2n l\u1edbn h\u01a1n n\u1ebfu nh\u00e2n vi\u00ean s\u1eed d\u1ee5ng Phone Link tr\u00ean m\u00e1y t\u00ednh c\u00f4ng vi\u1ec7c. Khi hacker chi\u1ebfm \u0111\u01b0\u1ee3c t\u00e0i kho\u1ea3n n\u1ed9i b\u1ed9 ho\u1eb7c OTP x\u00e1c th\u1ef1c h\u1ec7 th\u1ed1ng doanh nghi\u1ec7p, ch\u00fang c\u00f3 th\u1ec3 m\u1edf r\u1ed9ng x\u00e2m nh\u1eadp sang nhi\u1ec1u h\u1ec7 th\u1ed1ng quan tr\u1ecdng kh\u00e1c. Ngo\u00e0i ra, vi\u1ec7c malware ho\u1ea1t \u0111\u1ed9ng ho\u00e0n to\u00e0n tr\u00ean m\u00e1y t\u00ednh c\u0169ng khi\u1ebfn nhi\u1ec1u ng\u01b0\u1eddi d\u00f9ng ch\u1ee7 quan v\u00ec \u0111i\u1ec7n tho\u1ea1i kh\u00f4ng xu\u1ea5t hi\u1ec7n d\u1ea5u hi\u1ec7u nhi\u1ec5m m\u00e3 \u0111\u1ed9c r\u00f5 r\u00e0ng.\u200b<\/div>\n<div>C\u00f3 m\u00e3 CVE hay b\u1ea3n v\u00e1 b\u1ea3o m\u1eadt kh\u00f4ng?\u200b<\/div>\n<div>Hi\u1ec7n t\u1ea1i, \u0111\u00e2y ch\u01b0a \u0111\u01b0\u1ee3c c\u00f4ng b\u1ed1 l\u00e0 m\u1ed9t l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt c\u1ee5 th\u1ec3 c\u00f3 m\u00e3 CVE hay \u0111i\u1ec3m CVSS ri\u00eang bi\u1ec7t. Thay v\u00e0o \u0111\u00f3, \u0111\u00e2y l\u00e0 m\u1ed9t k\u1ef9 thu\u1eadt t\u1ea5n c\u00f4ng l\u1ee3i d\u1ee5ng h\u00e0nh vi h\u1ee3p ph\u00e1p c\u1ee7a \u1ee9ng d\u1ee5ng Phone Link k\u1ebft h\u1ee3p v\u1edbi malware tr\u00ean Windows.<\/p>\n<p>Do \u0111\u00f3, v\u1ea5n \u0111\u1ec1 kh\u00f4ng n\u1eb1m \u1edf m\u1ed9t l\u1ed7i ph\u1ea7n m\u1ec1m \u0111\u01a1n l\u1ebb m\u00e0 \u1edf c\u00e1ch malware t\u1eadn d\u1ee5ng c\u01a1 ch\u1ebf \u0111\u1ed3ng b\u1ed9 d\u1eef li\u1ec7u gi\u1eefa c\u00e1c thi\u1ebft b\u1ecb.\u200b<\/p><\/div>\n<div>C\u00e1c chuy\u00ean gia an ninh m\u1ea1ng khuy\u1ebfn ngh\u1ecb g\u00ec?\u200b<\/div>\n<div>C\u00e1c chuy\u00ean gia b\u1ea3o m\u1eadt khuy\u1ebfn ngh\u1ecb ng\u01b0\u1eddi d\u00f9ng v\u00e0 doanh nghi\u1ec7p c\u1ea7n \u0111\u1eb7c bi\u1ec7t c\u1ea9n tr\u1ecdng v\u1edbi c\u00e1c c\u00f4ng c\u1ee5 \u0111\u1ed3ng b\u1ed9 \u0111a thi\u1ebft b\u1ecb, nh\u1ea5t l\u00e0 tr\u00ean m\u00e1y t\u00ednh l\u00e0m vi\u1ec7c ch\u1ee9a d\u1eef li\u1ec7u quan tr\u1ecdng.<\/p>\n<p>M\u1ed9t s\u1ed1 bi\u1ec7n ph\u00e1p gi\u1ea3m thi\u1ec3u r\u1ee7i ro g\u1ed3m:\u200b<\/p><\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div>Kh\u00f4ng m\u1edf ho\u1eb7c ch\u1ea1y c\u00e1c t\u1ec7p th\u1ef1c thi kh\u00f4ng r\u00f5 ngu\u1ed3n g\u1ed1c\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>Gi\u00e1m s\u00e1t c\u00e1c Scheduled Task v\u00e0 ti\u1ebfn tr\u00ecnh PowerShell b\u1ea5t th\u01b0\u1eddng\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>T\u1eaft Phone Link n\u1ebfu kh\u00f4ng th\u1ef1c s\u1ef1 c\u1ea7n thi\u1ebft\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>H\u1ea1n ch\u1ebf \u0111\u1ed3ng b\u1ed9 SMS v\u00e0 th\u00f4ng b\u00e1o OTP l\u00ean m\u00e1y t\u00ednh\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>S\u1eed d\u1ee5ng ph\u1ea7n m\u1ec1m b\u1ea3o m\u1eadt c\u00f3 kh\u1ea3 n\u0103ng ph\u00e1t hi\u1ec7n h\u00e0nh vi b\u1ea5t th\u01b0\u1eddng\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>Ki\u1ec3m tra \u0111\u1ecbnh k\u1ef3 c\u00e1c k\u1ebft n\u1ed1i gi\u1eefa \u0111i\u1ec7n tho\u1ea1i v\u00e0 m\u00e1y t\u00ednh\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>Tri\u1ec3n khai c\u01a1 ch\u1ebf Zero Trust trong m\u00f4i tr\u01b0\u1eddng doanh nghi\u1ec7p\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div>S\u1eed d\u1ee5ng \u1ee9ng d\u1ee5ng x\u00e1c th\u1ef1c ri\u00eang thay v\u00ec OTP qua SMS khi c\u00f3 th\u1ec3\u200b<\/div>\n<\/li>\n<\/ul>\n<div>Ngo\u00e0i ra, c\u00e1c t\u1ed5 ch\u1ee9c c\u0169ng n\u00ean t\u0103ng c\u01b0\u1eddng gi\u00e1m s\u00e1t c\u00e1c k\u1ebft n\u1ed1i outbound b\u1ea5t th\u01b0\u1eddng t\u1eeb m\u00e1y tr\u1ea1m t\u1edbi m\u00e1y ch\u1ee7 C2 nh\u1eb1m ph\u00e1t hi\u1ec7n s\u1edbm d\u1ea5u hi\u1ec7u l\u00e2y nhi\u1ec5m CloudZ RAT. Chi\u1ebfn d\u1ecbch s\u1eed d\u1ee5ng CloudZ RAT v\u00e0 plugin Pheno cho th\u1ea5y tin t\u1eb7c \u0111ang ng\u00e0y c\u00e0ng chuy\u1ec3n h\u01b0\u1edbng sang khai th\u00e1c c\u00e1c t\u00ednh n\u0103ng h\u1ee3p ph\u00e1p thay v\u00ec ch\u1ec9 d\u1ef1a v\u00e0o l\u1ed7 h\u1ed5ng truy\u1ec1n th\u1ed1ng.<\/p>\n<p>Vi\u1ec7c l\u1ee3i d\u1ee5ng Microsoft Phone Link \u0111\u1ec3 \u0111\u00e1nh c\u1eafp OTP v\u00e0 d\u1eef li\u1ec7u \u0111i\u1ec7n tho\u1ea1i l\u00e0 l\u1eddi c\u1ea3nh b\u00e1o r\u00f5 r\u00e0ng r\u1eb1ng c\u00e1c h\u1ec7 sinh th\u00e1i k\u1ebft n\u1ed1i \u0111a thi\u1ebft b\u1ecb c\u00f3 th\u1ec3 v\u00f4 t\u00ecnh m\u1edf r\u1ed9ng b\u1ec1 m\u1eb7t t\u1ea5n c\u00f4ng n\u1ebfu kh\u00f4ng \u0111\u01b0\u1ee3c ki\u1ec3m so\u00e1t \u0111\u00fang c\u00e1ch.<\/p>\n<p>Trong b\u1ed1i c\u1ea3nh ng\u00e0y c\u00e0ng nhi\u1ec1u ng\u01b0\u1eddi d\u00f9ng \u0111\u1ed3ng b\u1ed9 \u0111i\u1ec7n tho\u1ea1i v\u1edbi m\u00e1y t\u00ednh \u0111\u1ec3 ph\u1ee5c v\u1ee5 c\u00f4ng vi\u1ec7c v\u00e0 c\u00e1 nh\u00e2n, vi\u1ec7c gi\u00e1m s\u00e1t c\u00e1c k\u1ebft n\u1ed1i thi\u1ebft b\u1ecb, h\u1ea1n ch\u1ebf quy\u1ec1n truy c\u1eadp kh\u00f4ng c\u1ea7n thi\u1ebft v\u00e0 n\u00e2ng cao nh\u1eadn th\u1ee9c an to\u00e0n th\u00f4ng tin s\u1ebd tr\u1edf th\u00e0nh y\u1ebfu t\u1ed1 quan tr\u1ecdng \u0111\u1ec3 ng\u0103n ch\u1eb7n c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng ki\u1ec3u m\u1edbi n\u00e0y.\u200b<\/p><\/div>\n<div style=\"text-align: right;\"><b><i>Theo The Hacker News<\/i><\/b><\/div>\n","protected":false},"excerpt":{"rendered":"<p>C\u00e1c chuy\u00ean gia an ninh m\u1ea1ng v\u1eeba c\u00f4ng b\u1ed1 chi ti\u1ebft v\u1ec1 m\u1ed9t chi\u1ebfn d\u1ecbch t\u1ea5n c\u00f4ng m\u1ea1ng tinh vi s\u1eed d\u1ee5ng m\u00e3 \u0111\u1ed9c \u0111i\u1ec1u khi\u1ec3n t\u1eeb xa CloudZ RAT k\u1ebft h\u1ee3p v\u1edbi plugin ch\u01b0a t\u1eebng \u0111\u01b0\u1ee3c ghi nh\u1eadn tr\u01b0\u1edbc \u0111\u00e2y c\u00f3 t\u00ean Pheno nh\u1eb1m \u0111\u00e1nh c\u1eafp th\u00f4ng tin \u0111\u0103ng nh\u1eadp v\u00e0 m\u00e3 x\u00e1c th\u1ef1c [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":47838,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"tdm_status":"","tdm_grid_status":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-47837","post","type-post","status-publish","format-standard","has-post-thumbnail","category-khong-phan-loai"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/posts\/47837","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/comments?post=47837"}],"version-history":[{"count":1,"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/posts\/47837\/revisions"}],"predecessor-version":[{"id":47839,"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/posts\/47837\/revisions\/47839"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/media\/47838"}],"wp:attachment":[{"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/media?parent=47837"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/categories?post=47837"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/antoanthongtinhaiphong.gov.vn\/wp-json\/wp\/v2\/tags?post=47837"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}