ÐÂÀÕË÷ÍÅ»ïRed CryptoApp½ÓÄɼ¤½øÕ½ÂÔÐßÈèÊܺ¦Õß
Ðû²¼Ê±¼ä 2024-04-074ÔÂ4ÈÕ£¬£¬£¬£¬£¬Netenrich µÄÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÃûΪ Red Ransomware Group (Red CryptoApp) µÄÐÂÀÕË÷×éÖ¯¡£¡£¡£¡£¸Ã×éÖ¯µÄÔË×÷·½·¨Óëµä·¶µÄÀÕË÷Èí¼þ×éÖ¯²î±ð£¬£¬£¬£¬£¬ËûÃǵÄÀÕË÷Õ½ÂÔÓÐËù²î±ð¡£¡£¡£¡£Óë´ó´ó¶¼Òþ²ØÆä²Ù×÷µÄÀÕË÷Èí¼þ×éÖ¯²î±ð£¬£¬£¬£¬£¬Red CryptoApp ËÆºõ½ÓÄÉÁ˼¤½øµÄÒªÁì¡£¡£¡£¡£¾Ý Netenrich ³Æ£¬£¬£¬£¬£¬¸Ã×éÖ¯½¨ÉèÁË¡°ÐßÈèǽ¡±£¬£¬£¬£¬£¬²¢Ðû²¼ÁËËûÃÇÀÖ³ÉÃé×¼µÄ¹«Ë¾Ãû³Æ¡£¡£¡£¡£ÕâÖÖÕ½ÂÔÖ¼ÔÚÐßÈèÊܺ¦Õß²¢ÆÈʹËûÃÇÖ§¸¶Êê½ðÒÔɾ³ýËûÃǵÄÃû×Ö¡£¡£¡£¡£Ñо¿Ö°Ô±×¢Öص½¸Ã×é֯׫дµÄÒ»·ÝÀÕË÷Èí¼þÌõ¼ÇÓë 2020 Äê Maze ÀÕË÷Èí¼þÍÅ»ïÓÐһЩÏàËÆÖ®´¦¡£¡£¡£¡£Õâ¿ÉÄÜÊÇÇɺϣ¬£¬£¬£¬£¬Ò²¿ÉÄÜÊÇÇɺϡ£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬Éв»ÇåÎú Red Ransomware Group ÊÇ·ñÊÇ Maze ÍÅ»ïµÄÑÜÉúÆ·£¬£¬£¬£¬£¬Maze ÍÅ»ïÓÚ 2020 Äê 11 Ô¹رÕÁËÆäÓªÒµ¡£¡£¡£¡£Red CryptoApp ÀÕË÷Èí¼þÍÅ»ïµÄÐßÈèǽ£¬£¬£¬£¬£¬ÃÀ¹úÊÇÖ÷ҪĿµÄ£¬£¬£¬£¬£¬Æä´ÎÊǵ¤Âó¡¢Ó¡¶È¡¢Î÷°àÑÀ¡¢Òâ´óÀû¡¢ÐÂ¼ÓÆÂºÍ¼ÓÄôóµÈÆäËû¹ú¼Ò¡£¡£¡£¡£¾ÍÄ¿µÄÐÐÒµ¶øÑÔ£¬£¬£¬£¬£¬Èí¼þºÍÖÆÔìÒµ³ÉΪ×î³£¼ûµÄÄ¿µÄÐÐÒµ£¬£¬£¬£¬£¬½ÌÓý¡¢ÐÞ½¨¡¢ÂÃ¹ÝºÍ IT ÐÐÒµÒ²Êܵ½¹Ø×¢¡£¡£¡£¡£
https://www.hackread.com/red-ransomware-group-red-cryptoapp-wall-of-shame/?web_view=true
2. CoralRaiderºÚ¿ÍÍÅ»ïÃé×¼Õû¸öÑÇÖ޵ĽðÈÚÐÐÒµ
4ÔÂ5ÈÕ£¬£¬£¬£¬£¬Ë¼¿Æ Talos µÄÑо¿Ö°Ô±·¢Ã÷ÁËһϵÁÐÃûΪ CoralRaider µÄºÚ¿Í»î¶¯£¬£¬£¬£¬£¬Ê¹ÓÃÉøÍ¸¶ñÒâÈí¼þ¹¥»÷Ó¡¶È¡¢Öйú¡¢º«¹ú¡¢ÃϼÓÀ¹ú¡¢°Í»ù˹̹¡¢Ó¡¶ÈÄáÎ÷ÑǺͺ£ÄÚÄ¿µÄ¡£¡£¡£¡£Talos ºÜÊÇÓÐÐÅÐĵؽ«¸Ã×éÖ¯µÄÆðÔ´¹éÒòÓÚÔ½ÄÏ£¬£¬£¬£¬£¬²¢Ö¸³öºÚ¿ÍÔÚÆä Telegram ÏÂÁîºÍ¿ØÖÆÍ¨µÀÖÐʹÓÃÔ½ÄÏÓ£¬£¬£¬£¬²¢½«Ô½ÄÏÓïµ¥´ÊÓ²±àÂëµ½ÓÐÓøºÔضþ½øÖÆÎļþÖС£¡£¡£¡£ÆäIPµØµã¿É×·Ëݵ½ºÓÄÚ¡£¡£¡£¡£ºÚ¿ÍʹÓà RotBot£¨Ò»ÖÖ¶¨ÖƵÄÔ¶³Ì»á¼û¹¤¾ß£¨ Quasar RATµÄ±äÌ壩£©ÏÂÔØÐÅÏ¢ÇÔÈ¡³ÌÐò£¬£¬£¬£¬£¬¸Ã³ÌÐò»á²éÕÒ°üÀ¨Ö§¸¶¿¨µÈÊý¾ÝµÄÉÌÒµÉ罻ýÌåÕÊ»§¡£¡£¡£¡£µ±Óû§·¿ª¶ñÒâ Windows ¿ì½Ý·½·¨Îļþʱ£¬£¬£¬£¬£¬CoralRaider ¹¥»÷¾Í»á×îÏÈ£¬£¬£¬£¬£¬´Ó¶ø´¥·¢Ñ¬È¾Á´¡£¡£¡£¡£ËþÂå˹ÌåÏÖ£¬£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎúÍþвÕßÔõÑù½«Îļþת´ï¸øÊܺ¦Õß¡£¡£¡£¡£¼¤»îµÄLNKÎļþ»áÏÂÔØÒ»¸öHTMLÓ¦ÓóÌÐòÎļþ£¬£¬£¬£¬£¬¸ÃÎļþÖ´ÐÐVirtual Basic¾ç±¾£¬£¬£¬£¬£¬¸Ã¾ç±¾ÓÖÔÚÄÚ´æÖÐÖ´ÐÐPowerShell¾ç±¾¡°½âÃܲ¢Ë³ÐòÖ´ÐÐÆäËûÈý¸öPowerShell¾ç±¾£¬£¬£¬£¬£¬ÕâЩ¾ç±¾Ö´Ðз´ÐéÄâ»úºÍ·´ÆÊÎö¼ì²é£¬£¬£¬£¬£¬ÈƹýÓû§»á¼û¿ØÖÆ¡¢½ûÓÃÊܺ¦Õß»úеÉ쵀 Windows ºÍÓ¦ÓóÌÐò֪ͨ£¬£¬£¬£¬£¬×îºóÏÂÔØ²¢ÔËÐÐ RotBot¡£¡£¡£¡£
https://www.govinfosecurity.com/vietnamese-threat-actor-targeting-financial-data-across-asia-a-24796?&web_view=true
3. Ð嵀 Latrodectus ¶ñÒâÈí¼þÈ¡´úÁËÍøÂçÎó²îÖÐµÄ IcedID
4ÔÂ4ÈÕ£¬£¬£¬£¬£¬Ò»ÖÖÃûΪ Latrodectus µÄÏà¶Ô½ÏеĶñÒâÈí¼þ±»ÒÔΪÊÇ IcedID ¼ÓÔØ³ÌÐòµÄÑݱ䣬£¬£¬£¬£¬¸Ã¼ÓÔØ³ÌÐò×Ô 2023 Äê 11 ÔÂÒÔÀ´Ò»Ö±ÔÚ¶ñÒâµç×ÓÓʼþ»î¶¯ÖзºÆð¡£¡£¡£¡£ProofpointºÍ Team CymruµÄÑо¿Ö°Ô±·¢Ã÷Á˸öñÒâÈí¼þ £¬£¬£¬£¬£¬ËûÃÇÅäºÏ¼Í¼ÁËÆä¹¦Ð§£¬£¬£¬£¬£¬µ«ÕâЩ¹¦Ð§ÈÔÈ»²»ÎȹÌÇÒ´¦ÓÚʵÑé½×¶Î¡£¡£¡£¡£IcedID ÊÇÒ»¸öÓÚ 2017 ÄêÊ״η¢Ã÷µÄ¶ñÒâÈí¼þ¼Ò×壬£¬£¬£¬£¬×î³õ±»¹éÀàΪģ¿£¿£¿£¿£¿é»¯ÒøÐÐľÂí£¬£¬£¬£¬£¬Ö¼ÔÚ´ÓÊÜѬȾµÄÅÌËã»úÖÐÇÔÈ¡²ÆÎñÐÅÏ¢¡£¡£¡£¡£Ëæ×Åʱ¼äµÄÍÆÒÆ£¬£¬£¬£¬£¬Ëü±äµÃÔ½·¢Öش󣬣¬£¬£¬£¬ÔöÌíÁËÌӱܺÍÏÂÁîÖ´Ðй¦Ð§¡£¡£¡£¡£½üÄêÀ´£¬£¬£¬£¬£¬Ëü³äµ±Á˼ÓÔØ³ÌÐòµÄ½ÇÉ«£¬£¬£¬£¬£¬¿ÉÒÔ½«ÆäËûÀàÐ͵ĶñÒâÈí¼þ£¨°üÀ¨ÀÕË÷Èí¼þ£©´«Ë͵½ÊÜѬȾµÄϵͳÉÏ¡£¡£¡£¡£´Ó 2022 Äê×îÏÈ£¬£¬£¬£¬£¬¶à¸ö IcedID »î¶¯Õ¹Ê¾ÁË ¶àÑù»¯µÄת´ïÕ½ÂÔ£¬£¬£¬£¬£¬µ«Ö÷ÒªµÄ·Ö·¢·½·¨ÈÔÈ»ÊǶñÒâµç×ÓÓʼþ¡£¡£¡£¡£2022 Äê⣬£¬£¬£¬£¬ ¸Ã¶ñÒâÈí¼þµÄбäÖÖ ±»ÓÃÓÚ¹¥»÷£¬£¬£¬£¬£¬²¢ÊµÑéÁËÖÖÖÖ¹æ±Ü¼¼ÇɺÍÐµĹ¥»÷¼¯¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-latrodectus-malware-replaces-icedid-in-network-breaches/?&web_view=true
4. Visa ÖÒÑÔÕë¶Ô½ðÈÚ»ú¹¹µÄРJSOutProx ¶ñÒâÈí¼þ±äÌå
4ÔÂ4ÈÕ£¬£¬£¬£¬£¬Visa ÖÒÑԳƣ¬£¬£¬£¬£¬Õë¶Ô½ðÈÚ»ú¹¹¼°Æä¿Í»§µÄа汾 JsOutProx ¶ñÒâÈí¼þ¼ì²âÊýÄ¿¼¤Ôö¡£¡£¡£¡£¸Ã»î¶¯Õë¶ÔÄÏÑǺͶ«ÄÏÑÇ¡¢Öж«ºÍ·ÇÖ޵ĽðÈÚ»ú¹¹¡£¡£¡£¡£JsOutProx ÓÚ 2019 Äê 12 ÔÂÊ×´ÎÓöµ½£¬£¬£¬£¬£¬ÊÇÒ»ÖÖÔ¶³Ì»á¼ûľÂí (RAT) ºÍ¸ß¶È»ìÏýµÄ JavaScript ºóÃÅ£¬£¬£¬£¬£¬ÔÊÐíÆä²Ù×÷ÕßÔËÐÐ shell ÏÂÁî¡¢ÏÂÔØÌØÁíÍâ¸ºÔØ¡¢Ö´ÐÐÎļþ¡¢²¶»ñÆÁÄ»½ØÍ¼¡¢ÔÚÊÜѬȾµÄ×°±¸ÉϽ¨É賤ÆÚÐÔ²¢¿ØÖƼüÅ̺ÍÊó±ê¡£¡£¡£¡£Visa ¾¯±¨ÖÐдµÀ£º¡°ËäÈ» PFD ÎÞ·¨È·ÈÏ×î½ü·¢Ã÷µÄ¶ñÒâÈí¼þ»î¶¯µÄ×îÖÕÄ¿µÄ£¬£¬£¬£¬£¬µ«¸ÃÍøÂç·¸·¨×é֮֯ǰ¿ÉÄÜÔøÕë¶Ô½ðÈÚ»ú¹¹¾ÙÐÐڲƻ¡£¡£¡£¡£¡±¸Ã¾¯±¨ÌṩÁËÓë×îлÏà¹ØµÄÍ×ÐÖ¸±ê (IoC)£¬£¬£¬£¬£¬²¢½¨Òé½ÓÄɶàÏ½â²½·¥£¬£¬£¬£¬£¬°üÀ¨Ìá¸ß¶ÔÍøÂç´¹ÂÚΣº¦µÄÊìϤ¡¢ÆôÓà EMV ºÍÇå¾²½ÓÊÜÊÖÒÕ¡¢±£»£»£»£»£»¤Ô¶³Ì»á¼ûÒÔ¼°¼à¿Ø¿ÉÒÉÉúÒâ¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/visa-warns-of-new-jsoutprox-malware-variant-targeting-financial-orgs/?&web_view=true
5. ÎÂÄá²®´óѧÊýǧÃû½ÌÖ°Ô±¹¤ºÍѧÉúµÄÃô¸ÐÊý¾Ý±»µÁ
4ÔÂ5ÈÕ£¬£¬£¬£¬£¬¼ÓÄôóÎÂÄá²®´óѧ֤ʵ£¬£¬£¬£¬£¬ºÚ¿ÍÔÚÉϸöÔÂÄ©±¬·¢µÄÒ»ÆðÊÂÎñÖÐÇÔÈ¡Á˸ûú¹¹µÄÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬Ó°ÏìÁËÒÔǰºÍÏÖÔÚµÄѧÉúºÍ½ÌÖ°Ô±¹¤¡£¡£¡£¡£ÕâËùÓµÓÐ 18,000 ¶àÃûѧÉúºÍ 800 Ãû½ÌÖ°Ô±¹¤µÄ´óѧÔÚÖÜËĵÄÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬£¬£¬£¬£¬¡°±»µÁµÄÐÅÏ¢¿ÉÄܰüÀ¨Ä¿½ñºÍÒÔǰµÄѧÉúºÍÔ±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡±ÕâÆðÍøÂçÊÂÎñÓÚ 3 Ô 25 ÈÕÊ×´ÎÐû²¼£¬£¬£¬£¬£¬Æäʱ¸Ã»ú¹¹ÏÂÏßÁËһϵÁÐЧÀÍ¡£¡£¡£¡£¼¸Ììºó£¬£¬£¬£¬£¬¸Ã´óѧУ³¤Íе¡¤Ãɶà¶û²©Ê¿ÌåÏÖ£¬£¬£¬£¬£¬ÎÂÄá²®ÔâÊÜÁË¡°Õë¶Ô´óÑ§ÍøÂçµÄÓÐÕë¶ÔÐÔµÄÍøÂç¹¥»÷¡±¡£¡£¡£¡£¸Ã´óѧÌåÏÖ£¬£¬£¬£¬£¬ÊÓ²ìÕýÔÚ¾ÙÐÐÖУ¬£¬£¬£¬£¬¡°¿ÉÄÜÐèҪʱ¼ä£¬£¬£¬£¬£¬¿ÉÄÜÊǼ¸¸öÔ¡±£¬£¬£¬£¬£¬ÏÖÔڸôóѧÒÔΪ¹¥»÷ÕßÄܹ»»á¼ûÎļþЧÀÍÆ÷¡£¡£¡£¡£¸ÃÍøÂçÊÂÎñµÄÐÔ×ÓÉÐδ»ñµÃ֤ʵ£¬£¬£¬£¬£¬µ«¸Ã´óѧÌåÏÖ¡°ÍµÇÔÊÂÎñºÜ¿ÉÄܱ¬·¢ÔÚ 3 Ô 24 ÈÕ֮ǰµÄÒ»ÖÜ¡£¡£¡£¡£¡±¸Ã´óѧÌåÏÖ£¬£¬£¬£¬£¬½«ÎªÊÜÓ°ÏìµÄСÎÒ˽¼ÒÌṩΪÆÚÁ½ÄêµÄÐÅÓÃ¼à¿ØÐ§ÀÍ£¬£¬£¬£¬£¬²¢ÃãÀøËùÓÐÊÜÓ°ÏìµÄÈË×¢²á£¬£¬£¬£¬£¬²¢Ö¸³öËü»¹ÎªËæºó³ÉΪڲÆÕßÄ¿µÄµÄÈκÎÈËÌṩ°ü¹ÜÌõ¿î¡£¡£¡£¡£
https://therecord.media/university-of-winnipeg-cyberattack
6. ºÚ¿ÍʹÓà Facebook ¹ã¸æºÍÐ®ÖÆÒ³ÃæÍÆ¹ãÐéαÈ˹¤ÖÇÄÜЧÀÍ
4ÔÂ5ÈÕ£¬£¬£¬£¬£¬ÕâЩ¶ñÒâ¹ã¸æ»î¶¯ÊÇͨ¹ýÐ®ÖÆ Facebook СÎÒ˽¼Ò×ÊÁϽ¨ÉèµÄ£¬£¬£¬£¬£¬ÕâЩСÎÒ˽¼Ò×ÊÁÏð³äÊ¢ÐеÄÈ˹¤ÖÇÄÜЧÀÍ£¬£¬£¬£¬£¬Ã°³äÌṩй¦Ð§µÄÔ¤ÀÀ¡£¡£¡£¡£±»¹ã¸æÓÕÆµÄÓû§³ÉΪڲÆÐÔ Facebook ÉçÇøµÄ³ÉÔ±£¬£¬£¬£¬£¬ÍþвÐÐΪÕßÔÚÆäÖÐÐû²¼ÐÂÎÅ¡¢È˹¤ÖÇÄÜÌìÉúµÄͼÏñºÍÆäËûÏà¹ØÐÅÏ¢£¬£¬£¬£¬£¬ÒÔÊ¹Ò³Ãæ¿´ÆðÀ´Õýµ±¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬ÉçÇøÌû×Ó¾³£ÌᳫÏÞʱ»á¼û¼´½«ÍƳöÇÒ±¸ÊÜÆÚ´ýµÄ AI ЧÀÍ£¬£¬£¬£¬£¬ÓÕÆÓû§ÏÂÔØ¶ñÒâ¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬ÕâЩ¿ÉÖ´ÐÐÎļþ»áʹÓà Rilide¡¢Vidar¡¢IceRAT ºÍ Nova µÈÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þѬȾ Windows ÅÌËã»ú¡£¡£¡£¡£ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þרעÓÚ´ÓÊܺ¦ÕßµÄä¯ÀÀÆ÷ÇÔÈ¡Êý¾Ý£¬£¬£¬£¬£¬°üÀ¨´æ´¢µÄƾ֤¡¢cookie¡¢¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡¢×Ô¶¯Íê³ÉÊý¾ÝºÍÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£È»ºó£¬£¬£¬£¬£¬ÕâЩÊý¾Ý»áÔÚ°µÍøÊг¡ÉϳöÊÛ£¬£¬£¬£¬£¬»ò±»¹¥»÷ÕßÓÃÀ´ÆÆËðÄ¿µÄµÄÔÚÏßÕÊ»§£¬£¬£¬£¬£¬ÒÔÔö½ø½øÒ»²½µÄÕ©Æ»ò¾ÙÐÐڲơ£¡£¡£¡£Facebook µÈÉ罻ýÌåÍøÂç¹æÄ£ÖØ´ó£¬£¬£¬£¬£¬¼ÓÉÏî¿ÏµÈ±·¦£¬£¬£¬£¬£¬Ê¹µÃÕâЩ»î¶¯Äܹ»ºã¾ÃÒ»Á¬£¬£¬£¬£¬£¬´Ó¶øÔö½ø¶ñÒâÈí¼þ²»ÊÜ¿ØÖƵÄÈö²¥£¬£¬£¬£¬£¬´Ó¶øµ¼Ö¶ñÒâÈí¼þѬȾÔì³ÉÆÕ±éË𺦡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/fake-facebook-midjourney-ai-page-promoted-malware-to-12-million-people/