BahamutÍÅ»ïÀûÓüÙðµÄVPNÓ¦ÓÃÇÔÈ¡AndroidÓû§ÐÅÏ¢
Ðû²¼Ê±¼ä 2022-11-2511ÔÂ23ÈÕ£¬ESETÅû¶ÁËÓÉAPT×éÖ¯BahamutÌᳫÕë¶ÔAndroidÓû§µÄ¹¥»÷»î¶¯¡£¸Ã»î¶¯×Ô2022Äê1ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬BahamutÖØÐ´ò°üÁËÊÊÓÃÓÚAndroidµÄSoftVPNºÍOpenVPNÓ¦Óã¬Ìí¼ÓÁ˾ßÓмäµý¹¦Ð§µÄ¶ñÒâ´úÂë¡£Òò´Ë£¬¸ÃÓ¦ÓÃÈÔ»áÌṩVPN¹¦Ð§£¬Í¬Ê±»¹¿ÉÒÔ´ÓÒÆ¶¯É豸ÖÐÇÔÈ¡ÐÅÏ¢¡£ÎªÁËÑÚÊι¥»÷»î¶¯²¢Ìá¸ß¿ÉÐŶȣ¬BahamutʹÓÃÁËSecureVPN£¨Ò»¸öºÏ·¨µÄVPN·þÎñ£©µÄÃû×Ö£¬²¢´´½¨ÁËÒ»¸ö¼ÙÍøÕ¾[thesecurevpn]À´·Ö·¢¶ñÒâÓ¦Óá£
https://www.welivesecurity.com/2022/11/23/bahamut-cybermercenary-group-targets-android-users-fake-vpn-apps/
2¡¢Áè¼Ý50¸öαÔìµÄMSI Afterburner¹ÙÍø·Ö·¢ÍÚ¿óÈí¼þ
¾Ý11ÔÂ23ÈÕ±¨µÀ£¬CybleµÄÑо¿ÈËÔ±·¢ÏÖÁ˼¸¸öÕë¶ÔMSI AfterburnerÈí¼þµÄµöÓã»î¶¯£¬Ö¼ÔÚ·Ö·¢ÍÚ¿ó¶ñÒâÈí¼þ¡£ÔÚ¹ýÈ¥Èý¸öÔÂÖУ¬ÓÐÁè¼Ý50¸öð³äMSI Afterburner¹ÙÍøµÄµöÓãÍøÕ¾£¬»á·Ö·¢XMR(Monero)¿ó¹¤ÓëÇÔÈ¡ÐÅÏ¢µÄ¶ñÒâÈí¼þ¡£¾ßÌåÀ´Ëµ£¬µ±Ä¿±êÖ´ÐÐαÔìµÄMSI Afterburner°²×°Îļþ(MSIAfterburnerSetup.msi)ʱ£¬³ýÁ˻ᰲװºÏ·¨µÄAfterburner·¨Ê½£¬»¹»áÇÄÇĵذ²×°²¢ÔËÐжñÒâÈí¼þRedLineºÍXMRÍÚ¿ó·¨Ê½¡£²»ÐÒµÄÊÇ£¬¸Ã»î¶¯¼¸ºõËùÓеÄ×é¼þ¶¼Ã»Óб»É±¶¾Èí¼þ¼ì²âµ½¡£
https://blog.cyble.com/2022/11/23/fake-msi-afterburner-sites-delivering-coin-miner/
3¡¢IBM·¢ÏÖÀÕË÷Èí¼þRansomExxµÄбäÌåÒÑÓÃRustÖØÐ´
IBMÔÚ11ÔÂ22ÈÕ³ÆÆä·¢ÏÖÁËRansomExxÀÕË÷Èí¼þµÄÒ»¸öбäÌ壬¸Ã±äÌåÒÑÓÃRustÓïÑÔÖØÐ´¡£ÓÃRust¿ª·¢µÄ¶ñÒâÈí¼þͨ³£»áÓнϵ͵ÄAV¼ì²âÂÊ£¬Õâ¿ÉÄÜÊÇËüʹÓøÃÓïÑÔµÄÖ÷ÒªÔÒò¡£Ð±äÌåµÄ¹¦Ð§ÓëÆäC++µÄ°æ±¾ÀàËÆ£¬½«Òª¼ÓÃܵÄÄ¿±êĿ¼Áбí×÷ΪÃüÁîÐвÎÊýͨ±¨£¬È»ºóʹÓÃAES-256¼ÓÃÜÎļþ£¬²¢Ê¹ÓÃRSAÀ´±£»¤¼ÓÃÜÃÜÔ¿£¬ËùÓдóÓÚ»ò¼´ÊÇ40×Ö½ÚµÄÎļþ¶¼±»¼ÓÃÜ¡£Ä¿Ç°£¬ÔÚ60¶à¼ÒAVÌṩÉÌÖÐÖ»ÓÐ14¼Ò¼ì²âµ½ÁËÐÂÑù±¾¡£
https://securityintelligence.com/posts/ransomexx-upgrades-rust/
4¡¢Smith FamilyÔ¼8Íò¾èÔùÕßµÄÏêϸÐÅÏ¢¿ÉÄÜÒÑй¶
¾ÝýÌå11ÔÂ22ÈÕ±¨µÀ£¬°Ä´óÀûÑÇ´ÈÉÆ»ú¹¹Smith Family͸¶ÆäÔâµ½ºÚ¿Í¹¥»÷£¬Ô¼8Íò¾èÔùÕßµÄÏêϸÐÅÏ¢¿ÉÄÜÒѱ»·ÃÎÊ¡£Ð¹Â¶ÐÅÏ¢Éæ¼°ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢ÓʼþµØÖ·ºÍ¾èÔù¼Ç¼£¬ÒÔ¼°²¿ÃÅÖ§¸¶¿¨µÄ¶øÐÅÏ¢¡£¸Ã»ú¹¹µÄÉùÃ÷ÌåÏÖ£¬ºÚ¿ÍÆóͼ͵ȡ×ʽðµ«ÊÇûÓÐÀֳɣ¬ËûÃÇÒÑ֪ͨÊÜÓ°ÏìµÄ¾èÔùÕߣ¬Ä¿Ç°Ã»ÓÐÈκÎÈ˵ÄÐÅÏ¢±»ÀÄÓá£
https://www.abc.net.au/news/2022-11-22/smith-family-charity-cyber-crime-hackers-donor-details/101683860
5¡¢Î±×°³ÉÐÂÎÅÊÓ²ìµÄ¶ñÒâwordÎĵµÇÔȡĿ±êµÄÐÅÏ¢
¾ÝASEC 11ÔÂ25ÈÕ±¨µÀ£¬½üÆÚÒ»¸öÓ볯ÏÊÏà¹ØµÄ¶ñÒâWordÎļþÒ»Ö±ÔÚʹÓÃFTPй¶Óû§Æ¾¾Ý¡£¸ÃWordÎĵµµÄÎļþÃûΪ¡°CNA[Q].doc¡±£¬Î±×°³ÉCNAÐÂ¼ÓÆÂµçÊÓ½ÚÄ¿²É·Ã¡£¸ÃÎļþÊÜÃÜÂë±£»¤£¬ÓëÃÜÂëÒ»Æð×÷ΪÓʼþ¸½¼þ·Ö·¢¡£ÎļþÖаüÂÞ¶ñÒâVBAºê£¬Í¨¹ýDocument_Open()º¯Êýʹ¶ñÒâºê×Ô¶¯Ö´ÐС£Ëü¿ÉÒÔʹÓÃFTPй¶Óû§µÄÐÅÏ¢¡¢´´½¨LNKÎļþ¡¢¸ü¸ÄMS OfficeÄþ¾²ÉèÖúͼǼ¼üÅÌ¡£
https://asec.ahnlab.com/en/42529/
6¡¢Group-IBÐû²¼ÇÔÈ¡ÐÅÏ¢µÄ¶ñÒâÈí¼þ·Ö·¢»î¶¯µÄ·ÖÎö³ÂËß
11ÔÂ23ÈÕ£¬Group-IBÐû²¼³ÂËß³ÆÒÑÈ·¶¨34¸ö¶íÂÞ˹ºÚ¿ÍÍÅ»ïÔÚÒÔÇÔÈ¡¼´·þÎñģʽ(SaaS)·Ö·¢ÇÔÈ¡ÐÅÏ¢µÄ¶ñÒâÈí¼þ¡£¹¥»÷ÕßÖ÷ҪʹÓÃRacoonºÍRedlineÇÔÈ¡·¨Ê½£¬À´ÊÕ¼¯SteamºÍRobloxÓÎÏ·ÕÊ»§µÄÃÜÂ룬ÑÇÂíÑ·ºÍPayPalµÄƾ¾Ý£¬ÒÔ¼°Óû§µÄÖ§¸¶¼Ç¼ºÍ¼ÓÃÜÇ®°üÐÅÏ¢¡£2022ÄêµÄǰ7¸öÔ£¬¹¥»÷Õß¹²Ñ¬È¾Áè¼Ý89Íǫ̀É豸£¬ÇÔÈ¡Áè¼Ý5000Íò¸öÃÜÂ룬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢°ÍÎ÷¡¢Ó¡¶È¡¢µÂ¹úºÍÓ¡¶ÈÄáÎ÷ÑÇ£¬¶ñÒâ»î¶¯Éæ¼°111¸ö¹ú¼Ò/µØÓò¡£
https://www.group-ib.com/media-center/press-releases/professional-stealers/