ÃÀ¹úÕþ¸®Ðû²¼Òѵ·»ÙÀÕË÷ÍÅ»ïALPHV²¢Ðû²¼½âÃܹ¤¾ß

Ðû²¼Ê±¼ä 2023-12-21

1.ÃÀ¹úÕþ¸®Ðû²¼Òѵ·»ÙÀÕË÷ÍÅ»ïALPHV²¢Ðû²¼½âÃܹ¤¾ß


¾ÝýÌå20ÈÕ±¨µÀ £¬Áª°îÊÓ²ì¾ÖÐû²¼µ·»ÙÀÕË÷Èí¼þÍÅ»ï ALPHV £¬Õþ¸®Óë°Ä´óÀûÑÇ¡¢°ÂµØÀû¡¢µ¤Âó¡¢Î÷°àÑÀ¡¢ÈðÊ¿ºÍÓ¢¹úµÄÖ´·¨»ú¹¹ºÏ×÷ £¬ALPHV ¾­³£Ñ°Çó¼ÓÃÜ»õ±Ò×éÖ¯ÍøÂçÖÐ×îÃô¸ÐµÄÊý¾Ý ¡£ËûÃÇÍþв˵ £¬Èç¹û²»Ö§¸¶Êê½ð £¬ËûÃǽ«ÎÞ·¨·ÃÎÊÕâЩÐÅÏ¢ £¬²¢Ðû²¼Î´¼ÓÃܵĿɶÁ°æ±¾ ¡£Èç¹û²»¸¶¿î £¬ºÚ¿Í¾Í»áÔÚ°µÍøÍøÕ¾ÉÏÐû²¼ÇÔÈ¡µÄÊý¾Ý ¡£¸Ã»ú¹¹»¹Ðû²¼ÁËÒ»¸ö¹¤¾ß £¬×éÖ¯¿ÉÒÔʹÓøù¤¾ß½âÃÜ ALPHV ÀÕË÷Èí¼þ ¡£Æù½ñΪֹ £¬FBI ¼°ÆäÖ´·¨ºÏ×÷»ï°éÒÑÏò 500 ¶àÃûÊܺ¦ÕßÌṩÁËÕâЩ¹¤¾ß £¬×ÊÖúËûÃÇÖÆÖ¹ÁËÔ¤¼Æ 6800 ÍòÃÀÔªµÄÊê½ð ¡£


https://www.securityweek.com/us-gov-disrupts-blackcat-ransomware-operation-fbi-releases-decryption-tool/


2. SymantecÅû¶SeedwormÕë¶Ô·ÇÖÞµçÐÅÐÐÒµµÄ¹¥»÷


19ÈÕ £¬SymantecµÄÍþвÇ鱨ÍŶÓÐû²¼ÁËһƪÓйØÒÁÀÊAPT×éÖ¯SeedwormµÄ³ÂËß £¬Seedworm£¨ÓÖÃû Muddywater£©Ò»Ö±½«°£¼°¡¢ËÕµ¤ºÍ̹ɣÄáÑǵçÐÅÐÐÒµµÄ×éÖ¯×÷ΪĿ±ê ¡£Ö¸³ö¸Ã×éÖ¯ÕýÔÚÒÔÀûÒæÏà¹ØÎªÃûÔÚ·ÇÖÞµØÓòµÄµçÐŹ«Ë¾ºÍÕþ¸®»ú¹¹½øÐй¥»÷ ¡£SeedwormÀûÓÃÁ÷ÐеÄOffTheShelf¹¦Ð§Ç¿´óµÄ¶ñÒâÈí¼þMimikatzºÍPoweliksÀ´Âú×ãÆä¼äµý»î¶¯µÄÐèÇó ¡£ËûÃǶÔÌØ¶¨¹¤¾ß½øÐмàÊÓºÍÇÔÈ¡²Ù×÷ϵͳ¡¢Ó¦Ó÷¨Ê½ºÍÍøÂçÆ¾Ö¤ £¬Í¬Ê±Ò²»á×Ô¶¯»¯Êý¾ÝÊÕ¼¯ºÍÇ鱨ÊÕ¼¯ÊÂÇé ¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/iran-apt-seedworm-africa-telecoms


3. IBM·¢ÏÖÀûÓÃWeb×¢ÈëÕë¶ÔÅ·ÃÀµÈµØ40¶à¼ÒÒøÐеĻ


19ÈÕýÌ屨µÀ £¬IBM Security Trusteer µÄÄþ¾²Ñо¿ÈËÔ±·¢ÏÖÒ»¿îÃûΪ Danabot µÄ¶ñÒâÈí¼þ½üÆÚÔÚ°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄÒøÐÐÖзºÆð ¡£¸Ã¶ñÒâÈí¼þ¿ÉÒÔͨ¹ýÍøÂç×¢Èë¹¥»÷ÇÔÈ¡Óû§µÄÒøÐÐÆ¾Ö¤ºÍÆäËû¸öÈËÐÅÏ¢ ¡£½üÄêÀ´ÕâÀ๥»÷·½Ê½ÓÐËù¼õÉÙ £¬µ«×î½ü Web ×¢Èë¹¥»÷ÓÖÖØÐ·ºÆð ¡£×¨¼ÒÃÇÈÏΪÕâÖÖ¹¥»÷»áÁ¬ÐøÔö¼Ó £¬ÒòΪ¹¥»÷ÕßÄܹ»ÇáËɵػñÈ¡´óÁ¿¸öÈËÊý¾Ý £¬²¢´ÓÖлñÀû ¡£½¨ÒéÓû§ÔÚʹÓÃÒøÐÐÓ¦Ó÷¨Ê½Ê±Ó¦±£³Ö¾¯Ìè ¡£Õâ°üÂÞÕË»§ÉÏDZÔڵĿÉÒɻ¡¢²»´Óδ֪À´Ô´ÏÂÔØÈí¼þÒÔ¼°×ñÑ­ÅÓ´óÃÜÂëµÄÔ­ÔòºÍµç×ÓÓʼþÄþ¾²µÈ ¡£

https://securityintelligence.com/posts/web-injections-back-on-rise-banks-affected-danabot-malware/


4. Ñо¿ÈËÔ±ÑÝʾ½µµÍOpenSSHÁ¬½ÓÄþ¾²ÐÔµÄTerrapin¹¥»÷


19ÈÕ±¨µÀ £¬Äþ¾²Ñо¿ÈËÔ±·¢ÏÖÁËÒ»ÖÖÐÂÐ͹¥»÷·½Ê½ £¬ÃûΪTerrapin £¬¿ÉÒÔͨ¹ý¸Ä¶¯×èÁ¦ÒÔ¼°½µ¼¶Äþ¾²Ð­ÒéµÄ·½Ê½ £¬½µµÍOpenSSHÁ¬½ÓµÄÄþ¾²ÐÔ ¡£Terrapin¹¥»÷ÀûÓÃSSHЭÒéµÄȱÏÝ £¬½èÖú¼ÆËã»úÍøÂç´ø¿í¹ÜÀíÈí¼þtcµÄ"¡°ÑÓ³ÙºÍÑÓ³Ù·¢¶¶(Delay and Jitter)"¹¦Ð§¶ÔÍøÂçÁ¬½Ó½øÐе÷Õû £¬´Ó¶ø½µµÍSSHÁ¬½ÓµÄÄþ¾²³ß¶È ¡£Ä¿Ç° £¬¸Ã¹¥»÷×î´óµÄÒòËØÊÇ MiTM £¬ÕâʹµÃ Terrapin µÄÍþв²»ÄÇôÑÏÖØ ¡£


https://www.bleepingcomputer.com/news/security/terrapin-attacks-can-downgrade-security-of-openssh-connections/


5. ESETÐû²¼¹ØÓÚ2023ÄêϰëÄêµÄÍþÐ²Ì¬ÊÆ·ÖÎö³ÂËß


19ÈÕÔÚESETÐû²¼µÄ2023ÄêϰëÄêÍþв³ÂËßÖÐÖ¸³ö £¬2023ÄêϰëÄêÍøÂç·¸×ï»î¶¯µÄÊýÁ¿ºÍÅÓ´ó¶È½«½øÒ»²½Ôö¼Ó ¡£Cl0p ÊÇÒ»¸öÎÛÃûÕÑÖøµÄÍøÂç·¸×ï×éÖ¯ £¬ÒÔ´ó¹æÄ£ÊµÊ©ÀÕË÷Èí¼þ¹¥»÷¶øÎÅÃû £¬Ëüͨ¹ý¹ã·ºµÄ¡°MOVEit ºÚ¿Í¹¥»÷¡±ÒýÆðÁËÈËÃǵĹØ×¢ £¬µ«ÁîÈ˾ªÑȵÄÊÇ £¬¸ÃºÚ¿Í¹¥»÷²¢Î´Éæ¼°ÀÕË÷Èí¼þ²¿Êð ¡£ÔÚÎïÁªÍøÁìÓò £¬¸ú×Ù¼à¿ØMozi IoT ½©Ê¬ÍøÂç £¬ÒÔ¼° Android ¼äµýÈí¼þ°¸ÀýÏÔÖøÔö¼Ó £¬ÕâÖ÷Òª¹éÒòÓÚ SpinOk ¼äµýÈí¼þµÄ´æÔÚ ¡£³ÂËß»¹¾¯¸æËµ £¬ÐéÄâ»õ±Ò½»Ò×Ëù¿ÉÄÜÃæÁÙ¸üƵ·±µÄ¹¥»÷ £¬²¢¾¯Ê¾Õþ¸®ºÍÆóÒµÓ¦Ô½·¢¹Ø×¢ÍøÂçÄþ¾²ºÍ¼äµý»î¶¯ ¡£


https://www.welivesecurity.com/en/eset-research/eset-threat-report-h2-2023/


6. ¹ú¼ÊÖ´·¨Ðж¯´þ²¶3500ÃûÍøÂç·¸×ïÏÓÒÉÈ˲¢»ñ3ÒÚÃÀÔª


19ÈÕýÌ屨µÀ £¬¹ú¼ÊÐ̾¯×éÖ¯½øÐеÄÒ»Ïî´úºÅΪ¡°HAECHI IV Ðж¯¡±µÄ¹ú¼ÊÖ´·¨Ðж¯Ðж¯´þ²¶ÁË3500ÃûÍøÂç×ï·¸ £¬²¢²é»ñÁ˼ÛÖµ3ÒÚÃÀÔªµÄ×ʲú £¬º«¹úÕþ¸®Ö÷µ¼ÁË HAECHI Ðж¯ £¬²¢ÓëÃÀ¹ú¡¢Ó¢¹ú¡¢ÈÕ±¾¡¢ÖйúÏã¸ÛºÍÓ¡¶ÈµÈ 34 ¸ö¹ú¼ÒµÄÖ´·¨»ú¹¹ºÏ×÷ £¬×îеÄÐж¯·¢ÉúÔÚ 2023 Äê 7 ÔÂÖÁ 12 ÔÂÆÚ¼ä £¬Ä¿±êÊÇ´ÓÊÂÓïÒôÍøÂçµöÓã¡¢Áµ°®Õ©Æ­¡¢ÔÚÏßÐÔÀÕË÷¡¢Í¶×ÊÆÛÕ©¡¢Óë·Ç·¨ÔÚÏß¶ÄÇ®Ïà¹ØµÄÏ´Ç®¡¢ÉÌÒµµç×ÓÓʼþй¶ºÍµç×ÓÉÌÎñÆÛÕ©µÄÍþвÐÐΪÕß ¡£


https://www.bleepingcomputer.com/news/security/interpol-operation-arrests-3-500-cybercriminals-seizes-300-million/