ÃÀ¹úÕþ¸®Ðû²¼ÁªºÏ¾¯¸æ£ºBlackMatterÀÕË÷Èí¼þÕý¶ÔÃÀ¹ú»ù´¡ÉèÊ©Ìᳫ¹¥»÷

Ðû²¼Ê±¼ä 2021-10-21

Symantec·¢ÏÖHarvesterÕë¶ÔÄÏÑǵçÐÅÐÐÒµµÄ¹¥»÷»î¶¯


Symantec·¢ÏÖHarvesterÕë¶ÔÄÏÑǵçÐÅÐÐÒµµÄ¹¥»÷»î¶¯.png


SymantecÔÚ10ÔÂ18ÈÕÅû¶ÁËÒ»¸öеÄÓɹú¼ÒÖ§³ÖµÄºÚ¿ÍÍÅ»ïHarvesterµÄ¹¥»÷»î¶¯¡£´Ë´Î¹¥»÷»î¶¯Ãé×¼ÁËÄÏÑǵÄ×éÖ¯£¬ÌرðÊǰ¢¸»º¹£¬Õë¶ÔµçÐźÍITÐÐÒµµÄ¹«Ë¾ÒÔ¼°¹Ù·½×éÖ¯£¬¿ªÊ¼ÓÚ2021Äê6Ô£¬×î½üÒ»´Î»î¶¯·¢ÉúÔÚ2021Äê10Ô¡£ÔÚ¼¼Êõ·½Ã棬¹¥»÷ÕßÔÚÄ¿±êÖа²×°ÁËÒ»¸öÃûΪBackdoor.GraphonµÄ×Ô½ç˵ºóÃÅ£¬ÒÔ¼°ÆäËû×Ô½ç˵ÏÂÔØÆ÷ºÍ½ØÍ¼¹¤¾ß¡£Ä¿Ç°Éв»Çå³þ³õʼѬȾý½éÊÇʲô£¬µ«Ñо¿ÈËÔ±ÔÚ±»ºÚÉ豸ÉÏ·¢ÏֵĵÚÒ»¸ö¹ØÓڴ˴λµÄÖ¤¾ÝÊǶñÒâURL¡£


Ô­ÎÄÁ´½Ó£º

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/harvester-new-apt-attacks-asia


DesordenÉù³ÆÒÑÈëÇÖºê»ùAcerÔÚÖйų́ÍåµÄ·þÎñÆ÷


DesordenÉù³ÆÒÑÈëÇÖºê»ùAcerÔÚÖйų́ÍåµÄ·þÎñÆ÷.png


ÉÏÖÜ£¬DesordenÈëÇÖÁ˺ê»ù£¨Acer£©Ó¡¶ÈµÄ·þÎñÆ÷²¢ÇÔÈ¡ÁËÆäÖеÄÊý¾Ý¡£²»µ½Ò»Öܺ󣬸ÃÍÅ»ïÓÖ³ÆËûÃÇÔÚ10ÔÂ15ÈÕÈëÇÖÁ˺ê»ų̀ÍåµÄ·þÎñÆ÷£¬²¢¹ûÈ»Á˸ù«Ë¾ÄÚ²¿ÍøÕ¾µÄͼƬºÍÔ±¹¤µÇ¼ƾ¾ÝµÄCSVÎļþ¡£DesordenÌåÏÖËûÃǴ˴εĹ¥»÷ÊÇΪÁËÖ¤Ã÷ºê»ùÈÔÈ»´æÔÚ©¶´£¬²¢Ö¸³ö¸Ã¹«Ë¾ÔÚÂíÀ´Î÷ÑǺÍÓ¡¶ÈÄáÎ÷ÑǵÄϵͳҲÈÝÒ×Êܵ½¹¥»÷¡£Ä¿Ç°£¬ºê³žÌ¨ÍåÒѾ­¹Ø±ÕÁ˱»ºÚµÄϵͳ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/acer-hacked-twice-in-a-week-by-the-same-threat-actor/


ºÚ¿ÍÍÅ»ïTeamTNTÀûÓöñÒâDocke¾µÏñ·Ö·¢ÍÚ¿óÈí¼þ


ºÚ¿ÍÍÅ»ïTeamTNTÀûÓöñÒâDocke¾µÏñ·Ö·¢ÍÚ¿óÈí¼þ.png

UptycsÑо¿ÍŶÓÔÚ10ÔÂ18ÈÕ¹ûÈ»ÁËTeamTNTÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£Ôڴ˴λÖУ¬TeamTNTÀûÓÃÁ˶ñÒâDocke¾µÏñ£¬²¢Ê¹ÓÃǶÈëʽ½Å±¾ÏÂÔØÉ¨ÃèÆ÷ZgrabºÍÉøÍ¸²âÊÔ¹¤¾ßmasscannerÀ´ÌáÈ¡bannerºÍ¶Ë¿ÚɨÃ裬ּÔÚ·Ö·¢¶ñÒâcoinminerÀ´½Ù³ÖÄ¿±êµÄ¼ÆËã×ÊÔ´Íڿ󡣸þµÏñÍйÜÔÚÃûΪDocker HubÉÏ£¬ÃûΪalpineos£¬¸ÃÓû§ÓÚ2021Äê5ÔÂ26ÈÕ¼ÓÈëDocker Hub£¬½ØÖÁÏÖÔÚ£¬alpineosÅäÖÃÎļþÍйÜÁË25¸öDockerÓ³Ïñ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/123535/cyber-crime/teamtnt-docker-attack.html


Ñо¿ÈËÔ±·¢ÏÖLyceumÍÅ»ïÕë¶ÔÍ»Äá˹µÄ¹¥»÷»î¶¯


Ñо¿ÈËÔ±·¢ÏÖLyceumÍÅ»ïÕë¶ÔÍ»Äá˹µÄ¹¥»÷»î¶¯.png


KasperskyµÄÑо¿ÈËÔ±ÓÚ10ÔÂ18ÈÕÐû²¼³ÂËߣ¬½éÉÜÁËLyceumÍÅ»ïÕë¶ÔÍ»Äá˹µÄ¹¥»÷»î¶¯¡£Lyceum£¨ÓÖÃûHexane£©ÓÚ2019ÄêÊ״α»SecureworksÆØ¹â£¬Ö÷ÒªÕë¶ÔÖж«µÄÄÜÔ´ºÍµçÐÅÐÐÒµ¡£´Ë´Î¹¥»÷µÄÄ¿±ê¾ùÊÇÍ»Äá˹µÄÖªÃû¹«Ë¾£¬ÈçµçÐÅ»òº½¿Õ¹«Ë¾¡£¹¥»÷ÕßʹÓÃÁËÁ½¸öÓÃC++±àдµÄжñÒâÈí¼þJamesºÍKevin£¬ËäÈ»JamesÔںܺéÁ÷ƽÉÏÈÔ»ùÓÚ¶ñÒâÈí¼þDanBot£¬µ«KevinÔڼܹ¹ºÍͨÐÅЭÒé·½Ãæ×ö³öÁËÖØ´ó¸Ä±ä¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/lyceum-group-reborn/104586/


Äþ¾²¹«Ë¾TrustwaveÐû²¼ÀÕË÷Èí¼þBlackByteµÄ½âÃÜÆ÷


Äþ¾²¹«Ë¾TrustwaveÐû²¼ÀÕË÷Èí¼þBlackByteµÄ½âÃÜÆ÷.png


Äþ¾²¹«Ë¾TrustwaveµÄÑо¿ÍŶÓSpiderLabsÔÚGitHubÉÏÐû²¼ÁËÀÕË÷Èí¼þBlackByteµÄ½âÃÜÆ÷¡£Æ¾¾Ý¶ÔÀÕË÷Èí¼þµÄ·ÖÎö±íÃ÷£¬BlackByteʹÓÃÁËÏàͬµÄԭʼÃÜÔ¿À´¼ÓÃÜÎļþ£¬²¢Ê¹ÓöԳÆÃÜÔ¿Ëã·¨AES£¬Òò´ËÈκξßÓÐԭʼÃÜÔ¿µÄÈ˶¼¿ÉÒÔ½âÃÜÎļþ¡£Ñо¿ÈËÔ±·¢ÏÖÀÕË÷Èí¼þʹÓÃÒ»¸öǶÈëÁ˶à¸öÃÜÔ¿.PNGÎļþ£¬Í¨¹ý·ÖÎö¸ÃÎļþ¿ª·¢ÁËÃâ·ÑµÄ½âÃÜÆ÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/blackbyte-ransomware-decryptor-released/


CISA¡¢FBIºÍNSAÐû²¼BlackMatterµÄÔ¤¾¯Í¨¸æ


CISA¡¢FBIºÍNSAÐû²¼BlackMatterµÄÔ¤¾¯Í¨¸æ.png


10ÔÂ18ÈÕ£¬CISA¡¢FBIºÍNSAÐû²¼ÁËÀÕË÷Èí¼þBlackMatterµÄÁªºÏÍøÂçÄþ¾²×Éѯ (CSA)¡£×Ô½ñÄê7ÔÂÒÔÀ´£¬ÀÕË÷Èí¼þBlackMatterÒѹ¥»÷ÁËÃÀ¹úµÄ¶à¸öÓëÒªº¦»ù´¡ÉèÊ©Ïà¹ØµÄ¹«Ë¾£¬ÀýÈçʳƷºÍũҵÐÐÒµ¡£¸ÃCSA·ÖÎöÁËBlackMatterµÄÑù±¾²¢½áºÏÁËÀ´×ÔµÚÈý·½µÄÐÅÏ¢£¬ÌṩÁ˹¥»÷ÕߵļÆÄ±¡¢¼¼ÊõºÍ·¨Ê½£¬²¢¸ÅÊö»º½â´ëÊ©£¬ÒÔ×ÊÖú×éÖ¯¸ïÐÂÕë¶Ô´ËÀ๥»÷µÄ±£»¤¡¢¼ì²âºÍÏìÓ¦´ëÊ©¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/10/18/cisa-fbi-and-nsa-release-joint-cybersecurity-advisory-blackmatter