ÃÀ¹úÕþ¸®Ðû²¼ÍŽáÖÒÑÔ£ºBlackMatterÀÕË÷Èí¼þÕý¶ÔÃÀ¹ú»ù´¡ÉèÊ©Ìᳫ¹¥»÷

Ðû²¼Ê±¼ä 2021-10-21

Symantec·¢Ã÷HarvesterÕë¶ÔÄÏÑǵçÐÅÐÐÒµµÄ¹¥»÷Ô˶¯


Symantec·¢Ã÷HarvesterÕë¶ÔÄÏÑǵçÐÅÐÐÒµµÄ¹¥»÷Ô˶¯.png


SymantecÔÚ10ÔÂ18ÈÕÅû¶ÁËÒ»¸öеÄÓɹú¼ÒÖ§³ÖµÄºÚ¿ÍÍÅ»ïHarvesterµÄ¹¥»÷Ô˶¯¡£´Ë´Î¹¥»÷Ô˶¯Ãé×¼ÁËÄÏÑǵÄ×éÖ¯ £¬ÌØÊâÊǰ¢¸»º¹ £¬Õë¶ÔµçÐźÍITÐÐÒµµÄ¹«Ë¾ÒÔ¼°¹Ù·½×éÖ¯ £¬×îÏÈÓÚ2021Äê6Ô £¬×î½üÒ»´ÎÔ˶¯±¬·¢ÔÚ2021Äê10Ô¡£ÔÚÊÖÒÕ·½Ãæ £¬¹¥»÷ÕßÔÚÄ¿µÄÖÐ×°ÖÃÁËÒ»¸öÃûΪBackdoor.GraphonµÄ×Ô½ç˵ºóÃÅ £¬ÒÔ¼°ÆäËû×Ô½ç˵ÏÂÔØÆ÷ºÍ½ØÍ¼¹¤¾ß¡£ÏÖÔÚÉв»ÇåÎú³õʼѬȾǰÑÔÊÇʲô £¬µ«Ñо¿Ö°Ô±ÔÚ±»ºÚ×°±¸ÉÏ·¢Ã÷µÄµÚÒ»¸ö¹ØÓÚ´Ë´ÎÔ˶¯µÄÖ¤¾ÝÊǶñÒâURL¡£


Ô­ÎÄÁ´½Ó£º

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/harvester-new-apt-attacks-asia


DesordenÉù³ÆÒÑÈëÇÖºê»ùAcerÔÚÖйų́ÍåµÄ·þÎñÆ÷


DesordenÉù³ÆÒÑÈëÇÖºê»ùAcerÔÚÖйų́ÍåµÄ·þÎñÆ÷.png


ÉÏÖÜ £¬DesordenÈëÇÖÁ˺ê»ù£¨Acer£©Ó¡¶ÈµÄ·þÎñÆ÷²¢ÇÔÈ¡ÁËÆäÖеÄÊý¾Ý¡£²»µ½Ò»Öܺó £¬¸ÃÍÅ»ïÓÖ³ÆËûÃÇÔÚ10ÔÂ15ÈÕÈëÇÖÁ˺ê»ų̀ÍåµÄ·þÎñÆ÷ £¬²¢¹ûÕæÁ˸ù«Ë¾ÄÚ²¿ÍøÕ¾µÄͼƬºÍÔ±¹¤µÇ¼ƾ֤µÄCSVÎļþ¡£DesordenÌåÏÖËûÃǴ˴εĹ¥»÷ÊÇΪÁË֤ʵºê»ùÈÔÈ»±£´æÎó²î £¬²¢Ö¸³ö¸Ã¹«Ë¾ÔÚÂíÀ´Î÷ÑǺÍÓ¡¶ÈÄáÎ÷ÑǵÄϵͳҲÈÝÒ×Êܵ½¹¥»÷¡£ÏÖÔÚ £¬ºê³žÌ¨ÍåÒѾ­¹Ø±ÕÁ˱»ºÚµÄϵͳ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/acer-hacked-twice-in-a-week-by-the-same-threat-actor/


ºÚ¿ÍÍÅ»ïTeamTNTʹÓöñÒâDocke¾µÏñ·Ö·¢ÍÚ¿óÈí¼þ


ºÚ¿ÍÍÅ»ïTeamTNTʹÓöñÒâDocke¾µÏñ·Ö·¢ÍÚ¿óÈí¼þ.png

UptycsÑо¿ÍŶÓÔÚ10ÔÂ18ÈÕ¹ûÕæÁËTeamTNTÐÂÒ»ÂֵĹ¥»÷Ô˶¯¡£ÔÚ´Ë´ÎÔ˶¯ÖÐ £¬TeamTNTʹÓÃÁ˶ñÒâDocke¾µÏñ £¬²¢Ê¹ÓÃǶÈëʽ¾ç±¾ÏÂÔØÉ¨ÃèÆ÷ZgrabºÍÉøÍ¸²âÊÔ¹¤¾ßmasscannerÀ´ÌáÈ¡bannerºÍ¶Ë¿ÚɨÃè £¬Ö¼ÔÚ·Ö·¢¶ñÒâcoinminerÀ´Ð®ÖÆÄ¿µÄµÄÅÌËã×ÊÔ´Íڿ󡣸þµÏñÍйÜÔÚÃûΪDocker HubÉÏ £¬ÃûΪalpineos £¬¸ÃÓû§ÓÚ2021Äê5ÔÂ26ÈÕ¼ÓÈëDocker Hub £¬×èÖ¹ÏÖÔÚ £¬alpineosÉèÖÃÎļþÍйÜÁË25¸öDockerÓ³Ïñ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/123535/cyber-crime/teamtnt-docker-attack.html


Ñо¿Ö°Ô±·¢Ã÷LyceumÍÅ»ïÕë¶ÔÍ»Äá˹µÄ¹¥»÷Ô˶¯


Ñо¿Ö°Ô±·¢Ã÷LyceumÍÅ»ïÕë¶ÔÍ»Äá˹µÄ¹¥»÷Ô˶¯.png


KasperskyµÄÑо¿Ö°Ô±ÓÚ10ÔÂ18ÈÕÐû²¼±¨¸æ £¬ÏÈÈÝÁËLyceumÍÅ»ïÕë¶ÔÍ»Äá˹µÄ¹¥»÷Ô˶¯¡£Lyceum£¨ÓÖÃûHexane£©ÓÚ2019ÄêÊ״α»SecureworksÆØ¹â £¬Ö÷ÒªÕë¶ÔÖж«µÄÄÜÔ´ºÍµçÐÅÐÐÒµ¡£´Ë´Î¹¥»÷µÄÄ¿µÄ¾ùÊÇÍ»Äá˹µÄ×ÅÃû¹«Ë¾ £¬ÈçµçÐÅ»òº½¿Õ¹«Ë¾¡£¹¥»÷ÕßʹÓÃÁËÁ½¸öÓÃC++±àдµÄжñÒâÈí¼þJamesºÍKevin £¬ËäÈ»JamesÔںܺéÁ÷ƽÉÏÈÔ»ùÓÚ¶ñÒâÈí¼þDanBot £¬µ«KevinÔڼܹ¹ºÍͨѶЭÒé·½Ãæ×ö³öÁËÖØ´ó¸Ä±ä¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/lyceum-group-reborn/104586/


Çå¾²¹«Ë¾TrustwaveÐû²¼ÀÕË÷Èí¼þBlackByteµÄ½âÃÜÆ÷


Çå¾²¹«Ë¾TrustwaveÐû²¼ÀÕË÷Èí¼þBlackByteµÄ½âÃÜÆ÷.png


Çå¾²¹«Ë¾TrustwaveµÄÑо¿ÍŶÓSpiderLabsÔÚGitHubÉÏÐû²¼ÁËÀÕË÷Èí¼þBlackByteµÄ½âÃÜÆ÷¡£Æ¾Ö¤¶ÔÀÕË÷Èí¼þµÄÆÊÎöÅú×¢ £¬BlackByteʹÓÃÁËÏàͬµÄԭʼÃÜÔ¿À´¼ÓÃÜÎļþ £¬²¢Ê¹ÓöԳÆÃÜÔ¿Ëã·¨AES £¬Òò´ËÈκξßÓÐԭʼÃÜÔ¿µÄÈ˶¼¿ÉÒÔ½âÃÜÎļþ¡£Ñо¿Ö°Ô±·¢Ã÷ÀÕË÷Èí¼þʹÓÃÒ»¸öǶÈëÁ˶à¸öÃÜÔ¿.PNGÎļþ £¬Í¨Ì«¹ýÎö¸ÃÎļþ¿ª·¢ÁËÃâ·ÑµÄ½âÃÜÆ÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/blackbyte-ransomware-decryptor-released/


CISA¡¢FBIºÍNSAÐû²¼BlackMatterµÄÔ¤¾¯Í¨¸æ


CISA¡¢FBIºÍNSAÐû²¼BlackMatterµÄÔ¤¾¯Í¨¸æ.png


10ÔÂ18ÈÕ £¬CISA¡¢FBIºÍNSAÐû²¼ÁËÀÕË÷Èí¼þBlackMatterµÄÍŽáÍøÂçÇå¾²×Éѯ (CSA)¡£×Ô½ñÄê7ÔÂÒÔÀ´ £¬ÀÕË÷Èí¼þBlackMatterÒѹ¥»÷ÁËÃÀ¹úµÄ¶à¸öÓëÒªº¦»ù´¡ÉèÊ©Ïà¹ØµÄ¹«Ë¾ £¬ÀýÈçʳÎïºÍũҵÐÐÒµ¡£¸ÃCSAÆÊÎöÁËBlackMatterµÄÑù±¾²¢ÍŽáÁËÀ´×ÔµÚÈý·½µÄÐÅÏ¢ £¬ÌṩÁ˹¥»÷ÕßµÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐò £¬²¢¸ÅÊö»º½â²½·¥ £¬ÒÔ×ÊÖú×é֯ˢÐÂÕë¶Ô´ËÀ๥»÷µÄ± £»¤¡¢¼ì²âºÍÏìÓ¦²½·¥¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/10/18/cisa-fbi-and-nsa-release-joint-cybersecurity-advisory-blackmatter