ÐÂÀÕË÷ÍÅ»ïRed CryptoApp½ÓÄɼ¤½øÕ½ÂÔÐßÈèÊܺ¦Õß

Ðû²¼Ê±¼ä 2024-04-07
1. ÐÂÀÕË÷ÍÅ»ïRed CryptoApp½ÓÄɼ¤½øÕ½ÂÔÐßÈèÊܺ¦Õß


4ÔÂ4ÈÕ£¬ £¬£¬ £¬£¬Netenrich µÄÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÃûΪ Red Ransomware Group (Red CryptoApp) µÄÐÂÀÕË÷×éÖ¯¡£¡£¡£¡£¸Ã×éÖ¯µÄÔË×÷·½·¨Óëµä·¶µÄÀÕË÷Èí¼þ×éÖ¯²î±ð£¬ £¬£¬ £¬£¬ËûÃǵÄÀÕË÷Õ½ÂÔÓÐËù²î±ð¡£¡£¡£¡£Óë´ó´ó¶¼Òþ²ØÆä²Ù×÷µÄÀÕË÷Èí¼þ×éÖ¯²î±ð£¬ £¬£¬ £¬£¬Red CryptoApp ËÆºõ½ÓÄÉÁ˼¤½øµÄÒªÁì¡£¡£¡£¡£¾Ý Netenrich ³Æ£¬ £¬£¬ £¬£¬¸Ã×éÖ¯½¨ÉèÁË¡°ÐßÈèǽ¡±£¬ £¬£¬ £¬£¬²¢Ðû²¼ÁËËûÃÇÀÖ³ÉÃé×¼µÄ¹«Ë¾Ãû³Æ¡£¡£¡£¡£ÕâÖÖÕ½ÂÔÖ¼ÔÚÐßÈèÊܺ¦Õß²¢ÆÈʹËûÃÇÖ§¸¶Êê½ðÒÔɾ³ýËûÃǵÄÃû×Ö¡£¡£¡£¡£Ñо¿Ö°Ô±×¢Öص½¸Ã×é֯׫дµÄÒ»·ÝÀÕË÷Èí¼þÌõ¼ÇÓë 2020 Äê Maze ÀÕË÷Èí¼þÍÅ»ïÓÐһЩÏàËÆÖ®´¦¡£¡£¡£¡£Õâ¿ÉÄÜÊÇÇɺÏ£¬ £¬£¬ £¬£¬Ò²¿ÉÄÜÊÇÇɺÏ¡£¡£¡£¡£Òò´Ë£¬ £¬£¬ £¬£¬Éв»ÇåÎú Red Ransomware Group ÊÇ·ñÊÇ Maze ÍÅ»ïµÄÑÜÉúÆ·£¬ £¬£¬ £¬£¬Maze ÍÅ»ïÓÚ 2020 Äê 11 Ô¹رÕÁËÆäÓªÒµ¡£¡£¡£¡£Red CryptoApp ÀÕË÷Èí¼þÍÅ»ïµÄÐßÈèǽ£¬ £¬£¬ £¬£¬ÃÀ¹úÊÇÖ÷ҪĿµÄ£¬ £¬£¬ £¬£¬Æä´ÎÊǵ¤Âó¡¢Ó¡¶È¡¢Î÷°àÑÀ¡¢Òâ´óÀû¡¢ÐÂ¼ÓÆÂºÍ¼ÓÄôóµÈÆäËû¹ú¼Ò¡£¡£¡£¡£¾ÍÄ¿µÄÐÐÒµ¶øÑÔ£¬ £¬£¬ £¬£¬Èí¼þºÍÖÆÔìÒµ³ÉΪ×î³£¼ûµÄÄ¿µÄÐÐÒµ£¬ £¬£¬ £¬£¬½ÌÓý¡¢ÐÞ½¨¡¢ÂÃ¹ÝºÍ IT ÐÐÒµÒ²Êܵ½¹Ø×¢¡£¡£¡£¡£


https://www.hackread.com/red-ransomware-group-red-cryptoapp-wall-of-shame/?web_view=true


2. CoralRaiderºÚ¿ÍÍÅ»ïÃé×¼Õû¸öÑÇÖ޵ĽðÈÚÐÐÒµ


4ÔÂ5ÈÕ£¬ £¬£¬ £¬£¬Ë¼¿Æ Talos µÄÑо¿Ö°Ô±·¢Ã÷ÁËһϵÁÐÃûΪ CoralRaider µÄºÚ¿Í»î¶¯£¬ £¬£¬ £¬£¬Ê¹ÓÃÉøÍ¸¶ñÒâÈí¼þ¹¥»÷Ó¡¶È¡¢Öйú¡¢º«¹ú¡¢ÃϼÓÀ­¹ú¡¢°Í»ù˹̹¡¢Ó¡¶ÈÄáÎ÷ÑǺͺ£ÄÚÄ¿µÄ¡£¡£¡£¡£Talos ºÜÊÇÓÐÐÅÐĵؽ«¸Ã×éÖ¯µÄÆðÔ´¹éÒòÓÚÔ½ÄÏ£¬ £¬£¬ £¬£¬²¢Ö¸³öºÚ¿ÍÔÚÆä Telegram ÏÂÁîºÍ¿ØÖÆÍ¨µÀÖÐʹÓÃÔ½ÄÏÓ £¬£¬ £¬£¬²¢½«Ô½ÄÏÓïµ¥´ÊÓ²±àÂëµ½ÓÐÓøºÔضþ½øÖÆÎļþÖС£¡£¡£¡£ÆäIPµØµã¿É×·Ëݵ½ºÓÄÚ¡£¡£¡£¡£ºÚ¿ÍʹÓà RotBot£¨Ò»ÖÖ¶¨ÖƵÄÔ¶³Ì»á¼û¹¤¾ß£¨ Quasar RATµÄ±äÌ壩£©ÏÂÔØÐÅÏ¢ÇÔÈ¡³ÌÐò£¬ £¬£¬ £¬£¬¸Ã³ÌÐò»á²éÕÒ°üÀ¨Ö§¸¶¿¨µÈÊý¾ÝµÄÉÌÒµÉ罻ýÌåÕÊ»§¡£¡£¡£¡£µ±Óû§·­¿ª¶ñÒâ Windows ¿ì½Ý·½·¨Îļþʱ£¬ £¬£¬ £¬£¬CoralRaider ¹¥»÷¾Í»á×îÏÈ£¬ £¬£¬ £¬£¬´Ó¶ø´¥·¢Ñ¬È¾Á´¡£¡£¡£¡£ËþÂå˹ÌåÏÖ£¬ £¬£¬ £¬£¬ÏÖÔÚÉв»ÇåÎúÍþвÕßÔõÑù½«Îļþת´ï¸øÊܺ¦Õß¡£¡£¡£¡£¼¤»îµÄLNKÎļþ»áÏÂÔØÒ»¸öHTMLÓ¦ÓóÌÐòÎļþ£¬ £¬£¬ £¬£¬¸ÃÎļþÖ´ÐÐVirtual Basic¾ç±¾£¬ £¬£¬ £¬£¬¸Ã¾ç±¾ÓÖÔÚÄÚ´æÖÐÖ´ÐÐPowerShell¾ç±¾¡°½âÃܲ¢Ë³ÐòÖ´ÐÐÆäËûÈý¸öPowerShell¾ç±¾£¬ £¬£¬ £¬£¬ÕâЩ¾ç±¾Ö´Ðз´ÐéÄâ»úºÍ·´ÆÊÎö¼ì²é£¬ £¬£¬ £¬£¬ÈƹýÓû§»á¼û¿ØÖÆ¡¢½ûÓÃÊܺ¦Õß»úеÉ쵀 Windows ºÍÓ¦ÓóÌÐò֪ͨ£¬ £¬£¬ £¬£¬×îºóÏÂÔØ²¢ÔËÐÐ RotBot¡£¡£¡£¡£


https://www.govinfosecurity.com/vietnamese-threat-actor-targeting-financial-data-across-asia-a-24796?&web_view=true


3. Ð嵀 Latrodectus ¶ñÒâÈí¼þÈ¡´úÁËÍøÂçÎó²îÖÐµÄ IcedID


4ÔÂ4ÈÕ£¬ £¬£¬ £¬£¬Ò»ÖÖÃûΪ Latrodectus µÄÏà¶Ô½ÏеĶñÒâÈí¼þ±»ÒÔΪÊÇ IcedID ¼ÓÔØ³ÌÐòµÄÑݱ䣬 £¬£¬ £¬£¬¸Ã¼ÓÔØ³ÌÐò×Ô 2023 Äê 11 ÔÂÒÔÀ´Ò»Ö±ÔÚ¶ñÒâµç×ÓÓʼþ»î¶¯ÖзºÆð¡£¡£¡£¡£ProofpointºÍ Team CymruµÄÑо¿Ö°Ô±·¢Ã÷Á˸öñÒâÈí¼þ  £¬ £¬£¬ £¬£¬ËûÃÇÅäºÏ¼Í¼ÁËÆä¹¦Ð§£¬ £¬£¬ £¬£¬µ«ÕâЩ¹¦Ð§ÈÔÈ»²»ÎȹÌÇÒ´¦ÓÚʵÑé½×¶Î¡£¡£¡£¡£IcedID ÊÇÒ»¸öÓÚ 2017 ÄêÊ״η¢Ã÷µÄ¶ñÒâÈí¼þ¼Ò×壬 £¬£¬ £¬£¬×î³õ±»¹éÀàΪÄ£¿£¿£¿£¿£¿é»¯ÒøÐÐľÂí£¬ £¬£¬ £¬£¬Ö¼ÔÚ´ÓÊÜѬȾµÄÅÌËã»úÖÐÇÔÈ¡²ÆÎñÐÅÏ¢¡£¡£¡£¡£Ëæ×Åʱ¼äµÄÍÆÒÆ£¬ £¬£¬ £¬£¬Ëü±äµÃÔ½·¢ÖØ´ó£¬ £¬£¬ £¬£¬ÔöÌíÁËÌӱܺÍÏÂÁîÖ´Ðй¦Ð§¡£¡£¡£¡£½üÄêÀ´£¬ £¬£¬ £¬£¬Ëü³äµ±Á˼ÓÔØ³ÌÐòµÄ½ÇÉ«£¬ £¬£¬ £¬£¬¿ÉÒÔ½«ÆäËûÀàÐ͵ĶñÒâÈí¼þ£¨°üÀ¨ÀÕË÷Èí¼þ£©´«Ë͵½ÊÜѬȾµÄϵͳÉÏ¡£¡£¡£¡£´Ó 2022 Äê×îÏÈ£¬ £¬£¬ £¬£¬¶à¸ö IcedID »î¶¯Õ¹Ê¾ÁË ¶àÑù»¯µÄת´ïÕ½ÂÔ£¬ £¬£¬ £¬£¬µ«Ö÷ÒªµÄ·Ö·¢·½·¨ÈÔÈ»ÊǶñÒâµç×ÓÓʼþ¡£¡£¡£¡£2022 Äê⣬ £¬£¬ £¬£¬ ¸Ã¶ñÒâÈí¼þµÄбäÖÖ ±»ÓÃÓÚ¹¥»÷£¬ £¬£¬ £¬£¬²¢ÊµÑéÁËÖÖÖÖ¹æ±Ü¼¼ÇɺÍÐµĹ¥»÷¼¯¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-latrodectus-malware-replaces-icedid-in-network-breaches/?&web_view=true


4. Visa ÖÒÑÔÕë¶Ô½ðÈÚ»ú¹¹µÄРJSOutProx ¶ñÒâÈí¼þ±äÌå


4ÔÂ4ÈÕ£¬ £¬£¬ £¬£¬Visa ÖÒÑԳƣ¬ £¬£¬ £¬£¬Õë¶Ô½ðÈÚ»ú¹¹¼°Æä¿Í»§µÄа汾 JsOutProx ¶ñÒâÈí¼þ¼ì²âÊýÄ¿¼¤Ôö¡£¡£¡£¡£¸Ã»î¶¯Õë¶ÔÄÏÑǺͶ«ÄÏÑÇ¡¢Öж«ºÍ·ÇÖ޵ĽðÈÚ»ú¹¹¡£¡£¡£¡£JsOutProx ÓÚ 2019 Äê 12 ÔÂÊ×´ÎÓöµ½£¬ £¬£¬ £¬£¬ÊÇÒ»ÖÖÔ¶³Ì»á¼ûľÂí (RAT) ºÍ¸ß¶È»ìÏýµÄ JavaScript ºóÃÅ£¬ £¬£¬ £¬£¬ÔÊÐíÆä²Ù×÷ÕßÔËÐÐ shell ÏÂÁî¡¢ÏÂÔØÌØÁíÍâ¸ºÔØ¡¢Ö´ÐÐÎļþ¡¢²¶»ñÆÁÄ»½ØÍ¼¡¢ÔÚÊÜѬȾµÄ×°±¸ÉϽ¨É賤ÆÚÐÔ²¢¿ØÖƼüÅ̺ÍÊó±ê¡£¡£¡£¡£Visa ¾¯±¨ÖÐдµÀ£º¡°ËäÈ» PFD ÎÞ·¨È·ÈÏ×î½ü·¢Ã÷µÄ¶ñÒâÈí¼þ»î¶¯µÄ×îÖÕÄ¿µÄ£¬ £¬£¬ £¬£¬µ«¸ÃÍøÂç·¸·¨×é֮֯ǰ¿ÉÄÜÔøÕë¶Ô½ðÈÚ»ú¹¹¾ÙÐÐڲƭ»î¶¯¡£¡£¡£¡£¡±¸Ã¾¯±¨ÌṩÁËÓë×îлÏà¹ØµÄÍ×Эָ±ê (IoC)£¬ £¬£¬ £¬£¬²¢½¨Òé½ÓÄɶàÏ½â²½·¥£¬ £¬£¬ £¬£¬°üÀ¨Ìá¸ß¶ÔÍøÂç´¹ÂÚΣº¦µÄÊìϤ¡¢ÆôÓà EMV ºÍÇå¾²½ÓÊÜÊÖÒÕ¡¢±£»£»£»£»£»¤Ô¶³Ì»á¼ûÒÔ¼°¼à¿Ø¿ÉÒÉÉúÒâ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/visa-warns-of-new-jsoutprox-malware-variant-targeting-financial-orgs/?&web_view=true


5. ÎÂÄá²®´óѧÊýǧÃû½ÌÖ°Ô±¹¤ºÍѧÉúµÄÃô¸ÐÊý¾Ý±»µÁ


4ÔÂ5ÈÕ£¬ £¬£¬ £¬£¬¼ÓÄôóÎÂÄá²®´óѧ֤ʵ£¬ £¬£¬ £¬£¬ºÚ¿ÍÔÚÉϸöÔÂÄ©±¬·¢µÄÒ»ÆðÊÂÎñÖÐÇÔÈ¡Á˸ûú¹¹µÄÃô¸ÐÐÅÏ¢£¬ £¬£¬ £¬£¬Ó°ÏìÁËÒÔǰºÍÏÖÔÚµÄѧÉúºÍ½ÌÖ°Ô±¹¤¡£¡£¡£¡£ÕâËùÓµÓÐ 18,000 ¶àÃûѧÉúºÍ 800 Ãû½ÌÖ°Ô±¹¤µÄ´óѧÔÚÖÜËĵÄÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬ £¬£¬ £¬£¬¡°±»µÁµÄÐÅÏ¢¿ÉÄܰüÀ¨Ä¿½ñºÍÒÔǰµÄѧÉúºÍÔ±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡±ÕâÆðÍøÂçÊÂÎñÓÚ 3 Ô 25 ÈÕÊ×´ÎÐû²¼£¬ £¬£¬ £¬£¬Æäʱ¸Ã»ú¹¹ÏÂÏßÁËһϵÁÐЧÀÍ¡£¡£¡£¡£¼¸Ììºó£¬ £¬£¬ £¬£¬¸Ã´óѧУ³¤Íе¡¤Ãɶà¶û²©Ê¿ÌåÏÖ£¬ £¬£¬ £¬£¬ÎÂÄá²®ÔâÊÜÁË¡°Õë¶Ô´óÑ§ÍøÂçµÄÓÐÕë¶ÔÐÔµÄÍøÂç¹¥»÷¡±¡£¡£¡£¡£¸Ã´óѧÌåÏÖ£¬ £¬£¬ £¬£¬ÊÓ²ìÕýÔÚ¾ÙÐÐÖУ¬ £¬£¬ £¬£¬¡°¿ÉÄÜÐèҪʱ¼ä£¬ £¬£¬ £¬£¬¿ÉÄÜÊǼ¸¸öÔ¡±£¬ £¬£¬ £¬£¬ÏÖÔڸôóѧÒÔΪ¹¥»÷ÕßÄܹ»»á¼ûÎļþЧÀÍÆ÷¡£¡£¡£¡£¸ÃÍøÂçÊÂÎñµÄÐÔ×ÓÉÐδ»ñµÃ֤ʵ£¬ £¬£¬ £¬£¬µ«¸Ã´óѧÌåÏÖ¡°ÍµÇÔÊÂÎñºÜ¿ÉÄܱ¬·¢ÔÚ 3 Ô 24 ÈÕ֮ǰµÄÒ»ÖÜ¡£¡£¡£¡£¡±¸Ã´óѧÌåÏÖ£¬ £¬£¬ £¬£¬½«ÎªÊÜÓ°ÏìµÄСÎÒ˽¼ÒÌṩΪÆÚÁ½ÄêµÄÐÅÓÃ¼à¿ØÐ§ÀÍ£¬ £¬£¬ £¬£¬²¢ÃãÀøËùÓÐÊÜÓ°ÏìµÄÈË×¢²á£¬ £¬£¬ £¬£¬²¢Ö¸³öËü»¹ÎªËæºó³ÉΪڲƭÕßÄ¿µÄµÄÈκÎÈËÌṩ°ü¹ÜÌõ¿î¡£¡£¡£¡£


https://therecord.media/university-of-winnipeg-cyberattack


6. ºÚ¿ÍʹÓà Facebook ¹ã¸æºÍÐ®ÖÆÒ³ÃæÍÆ¹ãÐéαÈ˹¤ÖÇÄÜЧÀÍ


4ÔÂ5ÈÕ£¬ £¬£¬ £¬£¬ÕâЩ¶ñÒâ¹ã¸æ»î¶¯ÊÇͨ¹ýÐ®ÖÆ Facebook СÎÒ˽¼Ò×ÊÁϽ¨ÉèµÄ£¬ £¬£¬ £¬£¬ÕâЩСÎÒ˽¼Ò×ÊÁÏð³äÊ¢ÐеÄÈ˹¤ÖÇÄÜЧÀÍ£¬ £¬£¬ £¬£¬Ã°³äÌṩй¦Ð§µÄÔ¤ÀÀ¡£¡£¡£¡£±»¹ã¸æÓÕÆ­µÄÓû§³ÉΪڲƭÐÔ Facebook ÉçÇøµÄ³ÉÔ±£¬ £¬£¬ £¬£¬ÍþвÐÐΪÕßÔÚÆäÖÐÐû²¼ÐÂÎÅ¡¢È˹¤ÖÇÄÜÌìÉúµÄͼÏñºÍÆäËûÏà¹ØÐÅÏ¢£¬ £¬£¬ £¬£¬ÒÔÊ¹Ò³Ãæ¿´ÆðÀ´Õýµ±¡£¡£¡£¡£È»¶ø£¬ £¬£¬ £¬£¬ÉçÇøÌû×Ó¾­³£ÌᳫÏÞʱ»á¼û¼´½«ÍƳöÇÒ±¸ÊÜÆÚ´ýµÄ AI ЧÀÍ£¬ £¬£¬ £¬£¬ÓÕÆ­Óû§ÏÂÔØ¶ñÒâ¿ÉÖ´ÐÐÎļþ£¬ £¬£¬ £¬£¬ÕâЩ¿ÉÖ´ÐÐÎļþ»áʹÓà Rilide¡¢Vidar¡¢IceRAT ºÍ Nova µÈÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þѬȾ Windows ÅÌËã»ú¡£¡£¡£¡£ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þרעÓÚ´ÓÊܺ¦ÕßµÄä¯ÀÀÆ÷ÇÔÈ¡Êý¾Ý£¬ £¬£¬ £¬£¬°üÀ¨´æ´¢µÄƾ֤¡¢cookie¡¢¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡¢×Ô¶¯Íê³ÉÊý¾ÝºÍÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£È»ºó£¬ £¬£¬ £¬£¬ÕâЩÊý¾Ý»áÔÚ°µÍøÊг¡ÉϳöÊÛ£¬ £¬£¬ £¬£¬»ò±»¹¥»÷ÕßÓÃÀ´ÆÆËðÄ¿µÄµÄÔÚÏßÕÊ»§£¬ £¬£¬ £¬£¬ÒÔÔö½ø½øÒ»²½µÄÕ©Æ­»ò¾ÙÐÐڲƭ¡£¡£¡£¡£Facebook µÈÉ罻ýÌåÍøÂç¹æÄ£ÖØ´ó£¬ £¬£¬ £¬£¬¼ÓÉÏî¿ÏµÈ±·¦£¬ £¬£¬ £¬£¬Ê¹µÃÕâЩ»î¶¯Äܹ»ºã¾ÃÒ»Á¬£¬ £¬£¬ £¬£¬´Ó¶øÔö½ø¶ñÒâÈí¼þ²»ÊÜ¿ØÖƵÄÈö²¥£¬ £¬£¬ £¬£¬´Ó¶øµ¼Ö¶ñÒâÈí¼þѬȾÔì³ÉÆÕ±éË𺦡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fake-facebook-midjourney-ai-page-promoted-malware-to-12-million-people/