PIXM·¢ÏÖÀûÓÃFacebookºÍMessengerµÄµöÓã»î¶¯

Ðû²¼Ê±¼ä 2022-06-10
1¡¢PIXM·¢ÏÖÀûÓÃFacebookºÍMessengerµÄ´ó¹æÄ£µöÓã»î¶¯


¾Ý6ÔÂ8ÈÕ±¨µÀ £¬Äþ¾²¹«Ë¾PIXM·¢ÏÖÁËÒ»Æð´ó¹æÄ£µÄµöÓã»î¶¯¡£¸Ã»î¶¯ÖÁÉÙ×Ô2021Äê9Ô¿ªÊ¼ £¬ÔÚ2022Äê4ÔÂÖÁ5Ôµ½´ïáÛ·å¡£¹¥»÷ÕßÀûÓÃÁËFacebookºÍMessenger £¬ÓÕʹÊý°ÙÍòÓû§·ÃÎʵöÓãÒ³Ãæ £¬ÊäÈëÕÊ»§Æ¾¾Ý²¢Ô¢Ä¿¹ã¸æ¡£ÕâЩÒѱ»¹¥»÷µÄÕÊ»§»¹»áÏòËûÃǵÄÅóÓÑ·¢Ë͸ü¶àµÄµöÓãÐÅÏ¢ £¬¹¥»÷Õßͨ¹ý¹ã¸æÓ¶½ð»ñµÃ¿É¹ÛµÄÊÕÈë¡£µöÓãÓʼþʹÓÃÁ˺Ϸ¨µÄURLÉú³É·þÎñ £¬¾Ýͳ¼Æ £¬ÔÚ2021Äê £¬ÓÐ270ÍòÓû§·ÃÎÊÁËÆäÖÐÒ»¸öµöÓãÍøÕ¾ £¬µ½2022Äê¸ÃÊý×ÖÔö¼Óµ½850Íò £¬Õâ·´Ó³Á˴˴λ´ó¹æÄ£Ôö³¤µÄÇ÷ÊÆ¡£


https://www.bleepingcomputer.com/news/security/massive-facebook-messenger-phishing-operation-generates-millions/


2¡¢ÀÕË÷Èí¼þCuba»Ø¹é²¢ÀûÓÃÓÅ»¯µÄбäÌå¹¥»÷¶à¸öÄ¿±ê


6ÔÂ8ÈÕ £¬Trend MicroÅû¶Á˹ØÓÚÀÕË÷Èí¼þCubaбäÌåµÄϸ½Ú¡£Cuba×Ô2020Äê2ÔÂÊ״α»¼ì²âµ½ £¬ÔÚ2021Äêµ½´ïáÛ·å¡£½ñÄ꿪ʼ¸ÃÍŻXºõûÓÐÐÂÐж¯ £¬Ö±µ½3Ô·ݾíÍÁÖØÀ´ £¬ÆäÔÚÍøÕ¾ÉÏÁгöÁ˶à¸ö±»¹¥»÷µÄÄ¿±ê£¨4Ô·Ý3¸ö £¬5Ô·Ý1¸ö£©¡£Ñо¿ÈËÔ±³Æ £¬ÔÚ3ÔºÍ4Ô¼ì²âµ½µÄÑù±¾Ê¹ÓÃÁËеÄ×Ô½ç˵ÏÂÔØ·¨Ê½BUGHATCH £¬²¢»áÔÚ¼ÓÃÜǰÖÕÖ¹¸ü¶à½ø³Ì £¬°üÂÞOutlook¡¢MS ExchangeºÍMySQL¡£Õâ±íÃ÷¹¥»÷ÕßÈÔÔÚ»ý¼«¿ª·¢Æä¼ÓÃÜÆ÷ £¬Ö¼ÔÚÓÅ»¯Æä¹¥»÷¹ý³Ì¡£


https://www.trendmicro.com/en_us/research/22/f/cuba-ransomware-group-s-new-variant-found-using-optimized-infect.html


3¡¢Avast·¢ÏÖ·Ö·¢ÇÔÈ¡ÐÅÏ¢µÄ¶ñÒâÈí¼þµÄлFakeCrack


AvastÔÚ6ÔÂ8ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öеĶñÒâÈí¼þ»î¶¯FakeCrack¡£¸Ã»î¶¯Ã°³äÁËÆÆ½â°æµÄÓÅ»¯·¨Ê½CCleaner Pro Windows £¬À´·Ö·¢¿ÉÇÔÈ¡ÃÜÂë¡¢ÐÅÓÿ¨ÐÅÏ¢ºÍ¼ÓÃÜÇ®°üµÄ¶ñÒâÈí¼þ¡£´ËÍâ £¬¹¥»÷»î¶¯»¹ÀûÓÃÁËBlack SEO¼¼Êõ £¬Ê¹¶ñÒâÍøÕ¾ÔڹȸèËÑË÷½á¹ûÖеÄÅÅÃûÔ½·¢¿¿Ç°¡£Öж¾µÄËÑË÷½á¹û»á½«Ä¿±ê´øµ½¶à¸öÍøÕ¾ £¬×îÖÕ¶¼ÊÐÖ¸ÏòÒ»¸öÏÂÔØZIPÎļþµÄµÇÂ¼Ò³Ãæ¡£¸ÃZIP»áÓÃÀàËÆÓÚ"1234"Ö®ÀàµÄÈõÃÜÂë±£»¤ £¬ÒÔÃâ¶ñÒâpayload±»É±¶¾Èí¼þ¼ì²âµ½¡£AvastÌåÏÖ £¬Æ½¾ùÿÌì¼ì²âµ½Ô¼10000´ÎѬȾʵÑé £¬Ö÷ÒªÕë¶Ô·¨¹ú¡¢°ÍÎ÷¡¢Ó¡¶ÈÄáÎ÷ÑǺÍÓ¡¶È¡£


https://blog.avast.com/fakecrack-campaign


4¡¢Aoqin DragonÕë¶Ô¶«ÄÏÑǵØÓòºÍ°Ä´óÀûÑǵĹ¥»÷³¤´ïÊ®Äê


¾ÝýÌå6ÔÂ9ÈÕ±¨µÀ £¬SentinelOne·¢ÏÖÁËAoqin DragonÕë¶Ô¶«ÄÏÑǵØÓòºÍ°Ä´óÀûÑdz¤´ïÊ®ÄêµÄ¹¥»÷»î¶¯¡£¸ÃÍÅ»ïÖ÷ÒªÕë¶ÔÐÂ¼ÓÆÂ¡¢ÖйúÏã¸Û¡¢Ô½ÄÏ¡¢¼íÆÒÕ¯ºÍ°Ä´óÀûÑǵÄÕþ¸®¡¢½ÌÓýºÍµçÐÅÏà¹Ø×éÖ¯¡£¹¥»÷ÕßÀûÓÃÁËÎĵµÖеÄ©¶´ºÍ¼ÙµÄ¿ÉÒÆ¶¯É豸À´»ñµÃ³õʼ·ÃÎÊȨÏÞ¡£¾ÝÊÓ²ì £¬¹¥»÷ÕßʹÓÃµÄÆäËü¼¼Êõ°üÂÞDLL½Ù³Ö¡¢Themida°ü×°µÄÎļþºÍDNSËíµÀ £¬ÓÃÀ´Èƹý¼ì²â¡£¾­¹ý¶ÔAoqin Dragon»î¶¯µÄÄ¿±ê¡¢»ù´¡ÉèÊ©ºÍ¶ñÒâÈí¼þ½á¹¹µÄ·ÖÎö £¬Ñо¿ÈËÔ±ÍÆ¶Ï¸ÃÍÅ»ï¿ÉÄÜÓëUNC94(Mandiant)ÓйØÁª¡£


https://thehackernews.com/2022/06/a-decade-long-chinese-espionage.html


5¡¢KasperskyÐû²¼2021Äê·ÓÉÆ÷Äþ¾²Ì¬ÊƵķÖÎö³ÂËß


6ÔÂ8ÈÕ £¬KasperskyÐû²¼Á˹ØÓÚ2021Äê·ÓÉÆ÷Äþ¾²Ì¬ÊƵķÖÎö³ÂËß¡£³ÂËßÖ¸³ö £¬ÔÚ¹ýȥʮÄêÖÐ £¬ÔÚÖÖÖÖ·ÓÉÆ÷Öз¢Ïֵĩ¶´ÊýÁ¿²»Í£Ôö¼Ó £¬2020ÄêºÍ2021ÆÚ¼ä £¬·¢ÏÖÁË500¶à¸ö·ÓÉÆ÷©¶´¡£²»ÐÒµÄÊÇ £¬²¢·ÇËùÓй©Ó¦É̶¼ºÜ¿ìÐÞ¸´Â©¶´ £¬½ØÖÁĿǰ £¬ÔÚ2021ÄêÐû²¼µÄ87¸öÑÏÖØµÄ©¶´ÖÐ £¬29.9%ÈÔδ±»ÐÞ¸´¡£Õë¶Ô·ÓÉÆ÷µÄ¶ñÒâÈí¼þÖ÷ҪΪBackdoor.Linux.Mirai.b£¨Õ¼±È48.25%£©¡¢Trojan-Downloader.Linux.NyaDrop.b£¨13.57%£©ºÍBackdoor.Linux.Mirai.ba£¨6.54%£©¡£


https://securelist.com/router-security-2021/106711/


6¡¢MalwarebytesÐû²¼¹ØÓÚMakeMoney¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß


MalwarebytesÔÚ6ÔÂ8ÈÕÐû²¼ÁËMakeMoney¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£Ñо¿ÈËÔ±½üÆÚ·¢ÏÖÁËÒ»¸öеĶñÒâ¹ã¸æ»î¶¯ £¬»á°²×°Î±ÔìµÄFirefox¸üС£Õâ¸öαÔìµÄ¸üаüÂÞ¼¸¸ö½Å±¾ £¬ÓÃÀ´ÏÂÔØ¼ÓÃܵÄpayload¡£³õʼ¿ÉÖ´ÐÐÎļþ°üÂÞÒ»¸ö¼ÓÔØ·¨Ê½ £¬»á¼ìË÷±»¼ì²âΪBrowserAssistantµÄ¹ã¸æÈí¼þ¡£¶ñÒâ¹ã¸æ»ù´¡ÉèÊ©Óë×Ô2019Äêµ×ÒÔÀ´Ðí¶à»î¶¯ÖÐʹÓõĻù´¡ÉèÊ©»ùµ×ϸͬ £¬¿ÉÄܳöÓÚijÖÖÔ­Òò £¬¹¥»÷ÕßÖØ¸´Ê¹ÓÃÁËÏàͬµÄ·þÎñÆ÷ £¬Õ⽫¸Ã»î¶¯ÓëMakeMoneyÁªÏµÆðÀ´¡£


https://blog.malwarebytes.com/threat-intelligence/2022/06/makemoney-malvertising-campaign-adds-fake-update-template/