Commune · Littérature
DoublePulsar
Backdoor implant tool
DoublePulsar is a backdoor implant tool developed by the U.S. National Security Agency's (NSA) Equation Group that was leaked by The Shadow Brokers in early 2017. The tool infected more than 200,000 Microsoft Windows computers in only a few weeks, and was used alongside EternalBlue in the May 2017 WannaCry ransomware attack.
Sur Wikipédia
Texte en anglais Pas encore d'article dans ta langue : extrait en anglais.
DoublePulsar is a backdoor implant tool developed by the U.S. National Security Agency's (NSA) Equation Group that was leaked by The Shadow Brokers in early 2017. The tool infected more than 200,000 Microsoft Windows computers in only a few weeks, and was used alongside EternalBlue in the May 2017 WannaCry ransomware attack. A variant of DoublePulsar was first seen in the wild in March 2016, as discovered by Symantec. Sean Dillon, senior analyst of security company RiskSense Inc., first dissected and inspected DoublePulsar. He said that the NSA exploits are "10 times worse" than the Heartbleed security bug, and use DoublePulsar as the primary payload. DoublePulsar runs in kernel mode, which grants cybercriminals a high level of control over the computer system. Once installed, it uses three commands: ping, kill, and exec, the latter of which can be used to load malware onto the system.
Texte : Wikipédia en anglais, CC BY-SA 4.0. · Image : NSA (Public domain) ·
Cartes voisines
-
c★★★
cyberattaque Wannacry
Cyberattaque informatique mondiale survenue du 12 au 14 mai 2017
-
★★★
WannaCry
Rançongiciel
-
E★★
EternalBlue
-
★★
The Shadow Brokers
Groupe de hackers
-
M★
Malicious Software Removal Tool
Programme Microsoft pour analyser et supprimer des logiciels malveillants spécifiques
-
★
Bullrun
Programme de déchiffrement de la NSA