À³Ë÷ÍÐÖÐÑëÒøÐÐ͸¶ÆäϵͳÔâµ½¹¥»÷²¿·Ö¸¶¿î¿ÉÄÜÑÓ³Ù

Ðû²¼Ê±¼ä 2023-12-19
1¡¢À³Ë÷ÍÐÖÐÑëÒøÐÐ͸¶ÆäϵͳÔâµ½¹¥»÷²¿·Ö¸¶¿î¿ÉÄÜÑÓ³Ù


¾Ý12ÔÂ15ÈÕ±¨µÀ£¬£¬£¬£¬ÄϷǹú¼ÒÀ³Ë÷ÍеÄÖÐÑëÒøÐÐÔâµ½¹¥»÷¡£¡£¡£¸ÃÒøÐÐת´ï³Æ£¬£¬£¬£¬Æäϵͳ11ÈÕÔâµ½¹¥»÷£¬£¬£¬£¬ÏÖÔÚÕýÔÚÊÓ²ì´ËÊ£¬£¬£¬£¬²¢È«ÌìºòÊÂÇéÒÔ»Ö¸´ÏµÍ³¡£¡£¡£¸Ã»ú¹¹»¹°ü¹Ü£¬£¬£¬£¬ËüûÓÐÔâµ½ÈκβÆÎñ»òÆäËüËðʧ¡£¡£¡£²»¹ý£¬£¬£¬£¬ËüÒÑÔÝÍ£²¿·ÖϵͳÒÔ±ÜÃâ½øÒ»²½µÄ¹¥»÷¡£¡£¡£Òò´Ë£¬£¬£¬£¬ÔÚÒøÐÐÆð¾¢»Ö¸´ÏµÍ³µÄµÄͬʱ£¬£¬£¬£¬Ò»Ð©¸¶¿î¿ÉÄÜ»áÑÓ³Ù¡£¡£¡£ÍâµØÃ½Ì屨µÀ£¬£¬£¬£¬ÓÉÓڸùúÇ®±ÒÂåµÙÓëÄÏ·ÇÀ¼Ìعҹ³£¬£¬£¬£¬ÓÐÈ˵£ÐĸÃÊÂÎñ¿ÉÄÜ»áÓ°Ïì»ãÂÊ¡£¡£¡£


https://therecord.media/central-bank-lesotho-cyberattack-causes-outages


2¡¢ÒÁÀÊÔ¼70%µÄ¼ÓÓÍÕ¾ÒòÔâµ½ÍøÂç¹¥»÷ЧÀÍÔÝʱÖÐÖ¹


¾ÝýÌå12ÔÂ18ÈÕ±¨µÀ£¬£¬£¬£¬À´×ÔºÚ¿ÍÍÅ»ïGonjeshke DarandeµÄ¹¥»÷×ÌÈÅÁËÒÁÀʸ÷µØ¼ÓÓÍÕ¾µÄÔËÓª¡£¡£¡£¹¥»÷±¬·¢ÓÚ±¾ÖÜÒ»£¬£¬£¬£¬Õâ¶ÔÊ×¶¼µÂºÚÀ¼Ôì³ÉÁËÑÏÖØµÄÓ°Ï죬£¬£¬£¬Ðí¶à¼ÓÓÍÕ¾±»ÆÈÊÖ¶¯ÔËÐС£¡£¡£Ê¯ÓͲ¿³¤Javad Owji͸¶£¬£¬£¬£¬´Ë´Î¹¥»÷µ¼ÖÂÒÁÀÊÔ¼70%µÄ¼ÓÓÍվЧÀÍÖÐÖ¹¡£¡£¡£Gonjeshke DarandeÉù³Æ¶Ô´ËÊÂÎñÈÏÕæ£¬£¬£¬£¬²¢ÌåÏÖËüÈëÇÖÁ˼ÓÓÍÕ¾µÄÖÐÑëЧÀÍÆ÷£¬£¬£¬£¬»ñÈ¡ÁËÌØ¶¨¼ÓÓÍÕ¾ÐÅÏ¢¡¢Ö§¸¶ÏµÍ³ÏêϸÐÅÏ¢ºÍÖÎÀíϵͳ¡£¡£¡£


https://securityaffairs.com/156065/hacktivism/pro-israel-predatory-sparrow-iran-fuel-stations.html


3¡¢¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨GokuMarketÉϰÙÍòÓû§µÄÐÅϢй¶


ýÌå12ÔÂ15Èճƣ¬£¬£¬£¬ByteXÆìϵļ¯ÖÐʽ¼ÓÃÜÇ®±ÒÉúÒâËùGokuMarketй¶ÁËÏÕЩËùÓÐÓû§µÄÏêϸÐÅÏ¢¡£¡£¡£Cybernews·¢Ã÷ÁËÒ»¸öδÊܱ£»£»£»£»¤µÄMongoDBʵÀý£¬£¬£¬£¬´æ´¢ÁËGokuMarketÁè¼ÝÒ»°ÙÍò¿Í»§ºÍÖÎÀíÓû§µÄÏêϸÐÅÏ¢¡£¡£¡£Õâ¸ö̻¶µÄÊý¾Ý¿â°üÀ¨Óû§IP¡¢¹ú¼Ò¡¢ÓʼþµØµã¡¢¼ÓÃÜÃÜÂëºÍÓû§¼ÓÃÜÇ®°üµØµãµÈÐÅÏ¢£¬£¬£¬£¬ÒÔ¼°35¸ö¾ßÓÐÍêÈ«ÖÎÆÊÎö¼ûȨÏÞµÄÕÊ»§¡£¡£¡£ËüÓÚ10Ô±»·¢Ã÷£¬£¬£¬£¬²¢ÔÚ±¨¸æºóµÄµÚ¶þÌì¾Í±»±£»£»£»£»¤ÆðÀ´¡£¡£¡£


https://securityaffairs.com/155885/security/crypto-exchange-gokumarket-exposed.html


4¡¢Resecurity³ÆBianLian¡¢White RabbitºÍMario±£´æÁªÏµ


ResecurityÔÚ12ÔÂ15ÈÕÅû¶Á˺ڿÍÍÅ»ïBianLian¡¢White RabbitºÍMarioÖ®¼äµÄÁªÏµ¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÁËÕâ3¸ö¹¥»÷ÍÅ»ïÏàÖúÁªºÏ¿ªÕ¹Õë¶ÔÉÏÊнðÈÚЧÀ͹«Ë¾µÄÀÕË÷¹¥»÷¡£¡£¡£ÕâÖÖÁªºÏµÄÀÕË÷¹¥»÷²¢Î´¼¸¼û£¬£¬£¬£¬µ«ÓÉÓÚIABÓë°µÍøÉ϶à¸ö¹¥»÷ÍÅ»ïµÄÏàÖú£¬£¬£¬£¬ÕâÖֻ¿ÉÄÜ»á±äµÃÔ½À´Ô½³£¼û¡£¡£¡£Resecurity¹ûÕæÁËÓë3¸öÍÅ»ïͬʱִÐÐ"ÃÜÂëÅçÉä"¹¥»÷Ïà¹ØµÄIPµØµãÁбí£¬£¬£¬£¬Ê¹ÓÃÁËÑÇÌ«µØÇøµÄ¶à¸öסլIPÊðÀí¡£¡£¡£¹¥»÷Õß»¹Ê¹ÓÃBEC×÷ÎªÔØÌ壬£¬£¬£¬Ê¹ÓÃÆäËü×éÖ¯µÄ±»¹¥»÷ÓʼþÕÊ»§ÄäÃû·¢ËÍÊê½ðÒªÇ󣬣¬£¬£¬½øÒ»²½ÔöÌíÁËÊÓ²ìµÄÄѶÈ¡£¡£¡£


https://www.resecurity.com/blog/article/Exposing-Cyber-Extortion-Trinity-BianLian-White-Rabbit-Mario-Ransomware-Gangs-Spotted-Joint-Campaign 


5¡¢ESETÅû¶OilRig¶à¸öÒÀÀµÓÚÔÆÐ§À;ÙÐÐC&CµÄÏÂÔØ³ÌÐò


12ÔÂ14ÈÕ£¬£¬£¬£¬ESETÆÊÎöÁËһϵÁÐеÄOilRigÏÂÔØ³ÌÐò£¬£¬£¬£¬ËüÃǶ¼ÒÀÀµÕýµ±µÄÔÆÐ§ÀÍÌṩÉÌ¡£¡£¡£OilRig£¬£¬£¬£¬Ò²³ÆAPT34£¬£¬£¬£¬×Ô2014ÄêÒÔÀ´Ò»Ö±»îÔ¾¡£¡£¡£¸ÃÍÅ»ïÔÚ2022ÄêµÄÒ»ÔٻÖж¼Ê¹ÓÃÁ˶à¸öÏÂÔØ³ÌÐò£¬£¬£¬£¬°üÀ¨SampleCheck5000(SC5k v1-v3)¡¢OilCheck¡¢ODAgentºÍOilBooster¡£¡£¡£ÕâЩÏÂÔØ³ÌÐòµÄÏÔÖøÌØµãÊÇʹÓÃÁ˶à¸öÕýµ±ÔÆÐ§ÀÍAPI¾ÙÐÐC&CͨѶºÍÊý¾Ýй¶£¬£¬£¬£¬ÀýÈçMicrosoft Graph OneDrive API¡¢Microsoft Graph Outlook APIºÍMicrosoft Office EWS API¡£¡£¡£


https://www.welivesecurity.com/en/eset-research/oilrig-persistent-attacks-cloud-service-powered-downloaders/  


6¡¢Check PointÐû²¼Rhadamanthysа汾µÄÆÊÎö±¨¸æ


12ÔÂ14ÈÕ£¬£¬£¬£¬Check PointÐû²¼Á˹ØÓÚRhadamanthys 0.5.0°æ±¾µÄÆÊÎö±¨¸æ¡£¡£¡£ÕâÊÇÒ»ÖÖC++ÐÅÏ¢ÇÔÈ¡³ÌÐò£¬£¬£¬£¬ÓÚ2022Äê8ÔÂÊ״α»·¢Ã÷£¬£¬£¬£¬Ä¿µÄÊǵç×ÓÓʼþ¡¢FTPºÍÔÚÏßÒøÐÐЧÀÍÕÊ»§Æ¾Ö¤¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬¸Ã°æ±¾ÒýÈëÁËÒ»¸öеIJå¼þϵͳ£¬£¬£¬£¬¿É¶ÔÌØ¶¨·Ö·¢ÐèÇó¾ÙÐиü¸ß¼¶±ðµÄ¶¨ÖÆ¡£¡£¡£0.5.0°æ»¹Ë¢ÐÂÁË´æ¸ù¹¹½¨ºÍ¿Í»§¶ËÖ´ÐÐÀú³Ì£¬£¬£¬£¬ÐÞ¸´ÁËÕë¶Ô¼ÓÃÜÇ®±ÒÇ®°üµÄϵͳ£¬£¬£¬£¬²¢ÐÞ¸´ÁËDiscordÁîÅÆ»ñÈ¡ÎÊÌâ¡£¡£¡£


https://research.checkpoint.com/2023/rhadamanthys-v0-5-0-a-deep-dive-into-the-stealers-components/