FBI°ä²¼2018Ä껥ÁªÍø·¸×ï»ã±¨£»¹©¸øÁ´¹¥»÷ShadowHammer£»CarbanakÔ´Âëй¶
°ä²¼¹¦·ò 2019-04-24
ƾ¾ÝFBI IC3°ä²¼µÄÄê¶È»¥ÁªÍø·¸×ï»ã±¨£¬2018ÄêBECÚ²ÆÔì³ÉµÄËðʧÏà±È2017Äê·ÁËÒ»±¶£¬´ï13ÒÚÃÀÔª¡£ÀÕË÷Èí¼þͶËßµÄÊýÁ¿ÒѾ½µÂäÖÁ2014ÄêµÄˮƽ£¬µ«ÀÕË÷Èí¼þ¹¥»÷Ôì³ÉµÄ¾¼ÃËðʧ±ÈÒÔÍùÈκÎʱ³½¶¼Òª¸ß£¬ÕâÅú×¢¹¥»÷ÕßÔÚ×ÐϸåàÑ¡Êܺ¦Õߣ¬ÒÔÔì³É×î´óµÄÇÖº¦ºÍ»ñµÃ×î¸ßµÄÅ⸶¡£´Ë±í£¬¼¼ÊõÖ§³¶à¿ÆÔÙ´ÎÉÏÉý£¬ÆäÔÚ2018ÄêÔì³ÉµÄËðʧÔö³¤ÁË161%¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/fbi-us-companies-lost-1-3-billion-in-2018-due-to-bec-scams/2.Õë¶Ô»ªË¶µÄ¹©¸øÁ´¹¥»÷ShadowHammer»¹¶Ô×¼Áí±íÁù¼ÒÑÇÖÞ¹«Ë¾
¿¨°Í˹»ù·¢´Ë¿Ì֮ǰÕë¶Ô»ªË¶µÄ¹©¸øÁ´¹¥»÷ShadowHammerÖУ¬ÖÁÉÙ»¹ÓÐÁù¼ÒÑÇÖÞ¹«Ë¾³ÉΪָ±ê£¬Ô̺¬Èý¼ÒÓÎÏ·¹«Ë¾£¨Electronics Extreme¡¢Innovative ExtremistºÍZepetto£©ÒÔ¼°Î´Ìá¼°Ãû³ÆµÄÒ»¼ÒÊÓÆµÓÎÏ·¹«Ë¾¡¢Ò»¼Ò×ۺϿعɹ«Ë¾ºÍÒ»¼ÒÔìÒ©¹«Ë¾¡£Ôڳɹ¦ÈëÇÖÊܺ¦Õßϵͳºó£¬¹¥»÷Õß¿ªÊ͵ĶñÒâÈí¼þ½«¿ÉÄÜÍøÂçϵͳÐÅÏ¢²¢´ÓC&CÏÂÔØÆäËüpayload¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/shadowhammer-targets-multiple-companies-asus-just-one-of-them/3.¹¥»÷ÕßÀûÓöñÒâTeamViewer¶Ô׼ŷÖÞµ±¾Ö»ú¹¹ºÍ´óʹ¹Ý
Check Point×êÑÐÈËÔ±·¢ÏÖÒ»¸öÕë¶ÔÅ·ÖÞµ±¾ÖµÄ²ÆÕþ²¿Ãźʹóʹ¹ÝµÄ´¹µö¹¥»÷»î¶¯£¬¹¥»÷ÕßÏòÖ¸±ê·¢ËÍÖ÷ÌâΪ¡°¾üÊÂÈÚ×Ê´òË㡱µÄ¡°¾øÃÜ¡±´¹µöÓʼþ£¬Óʼþ¸½´øµÄXLSMÎļþ´øÓÐÃÀ¹ú¹úÎñÔºµÄlogo£¬Ò»µ©Êܺ¦Õß´ò¿ªXLSMÎĵµ£¬¶ñÒâºê¾Í»áÏÂÔØ²¢×°ÖöñÒâ°æ±¾µÄTeamViewer£¬ÒÔÇÔȡϵͳÐÅÏ¢ºÍµÇ¼ʹ´¦¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/trojanized-teamviewer-used-in-government-political-attacks-across-europe/4.×êÑÐÈËÔ±·¢ÏÖ¶ñÒâÈí¼þCarbanakµÄÔ´´úÂëÔÚVirusTotalÉÏй¶
FireEye×êÑÐÈËÔ±·¢ÏÖ¶ñÒâÈí¼þCarbanakµÄÔ´´úÂëÔÚVirusTotalÉÏй¶£¬²¢ÇÒÒѾ±£ÁôÁËÁ½ÄêµÄ¹¦·ò¡£CarbanakÊÇÒ»¸öºóÃÅľÂí£¬ËüÊÇAPT×éÖ¯FIN7µÄµÚ¶þ´ú¶ñÒâÈí¼þ·¨Ê½£¬±»ÓÃ×÷ÈëÇÖÒøÐÐÍøÂçµÄÖØÒª¹¤¾ß¡£Æ¾¾Ý×êÑÐÈËÔ±µÄ˵·¨£¬VirusTotalÉÏ´æÔÚÁ½¸öÔ̺¬CarbanakÔ´´úÂëµÄѹËõÎļþ£¬ÎļþÖÐÔ̺¬Carbanak¼°ÒÔǰδ֪µÄ²å¼þµÄÆëȫԴ´úÂ룬´úÂëÐÐÊý³¬¹ý10ÍòÐС£ÕâЩԴ´úÂëÄܹ»Ô®ÊÖFireEye¸üºÃµØ·ÖÎö¸Ã¶ñÒâÈí¼þ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/source-code-of-carbanak-trojan-found-on-virustotal/5.Evisort¹«Ë¾ElasticsearchÊý¾Ý¿âÒòÅäÖÃÃýÎóй¶¿Í»§Êý¾Ý
EvisortÊÇÒ»¼ÒÎļþºÍºÏͬÖÎÀí¹«Ë¾£¬¸Ã¹«Ë¾µÄÒ»¸öElasticsearchÎļþÊý¾Ý¿âδÉèÃÜÂ룬µ¼Ö²¿Ãſͻ§µÄÊý¾Ýй¶¡£Æ¾¾ÝTechCrunchµÄ»ã±¨£¬¹ÌÈ»Êý¾Ý¿âÖеÄһЩÎļþ±»ÏóÕ÷Ϊ¡°Ðé¹¹¡±ºÍ¡°²âÊÔ¡±£¬µ«Ò²ÓкܶàÎĵµÔ̺¬¿Í»§Êý¾Ý£¬ÀýÈçÔ±¹¤ºÏͬ¡¢´û¿îºÍ̸¡¢¼òÀú¼°ÓëÈýÐÇÇ©¶¨µÄ±£ÃܺÍ̸µÈ¡£ÔÚ½Óµ½»ã±¨ºó£¬EvisortÔÚÒ»Ó×ʱÄÚÒÆ³ýÁ˸ÃÊý¾Ý¿â¡£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2019/04/22/evisort-data-exposed/6.WannaCryÓ¢ÐÛMarcus HutchinsÈÏ×ï£¬Ãæ¶Ô×î¸ßÊ®Äê½ûïÀ
Ôø±»ÊÓΪսʤWannaCryµÄÓ¢ÐÛµÄÓ¢¹ú°²È«×êÑÐÈËÔ±Marcus HutchinsÓÚ½üÈÕÔÚÃÀÍõ·¨ÔºÈÏ×ÈÏ¿ÉÔø´´½¨ºÍ·Ö·¢¶ñÒâÈí¼þ¡£HutchinsÔÚ2017Äê8ÔÂ2ÈÕ²ÎÓëÍêBlack HatºÍDEFCON´ó»áºó±»²¶£¬ÃÀ¹ú¼ì²ìÔº¶ÔÆäÌá³öÁËÊ®ÏîÖ¸¿Ø£¬Æ¾¾ÝHutchinsÇ©ÊðµÄÈÏ×ïºÍ̸£¬ËûÈÏ¿ÉÁËÁ½Ïî×ïÃû£¬¼ì·½½«³·ÏúÆäËü×ïÃû¡£ÕâÁ½Ïî×ïÃûÊDzμӴ´½¨ºÍ·Ö·¢¶ñÒâÈí¼þÒÔ¼°Ö§Ê¹ºÍÐÖú·Ö·¢¶ñÒâÈí¼þ¡£Á½Ïî×ïÃûÏà¼Ó£¬Hutchins½«Ãæ¶Ô×î¸ßÊ®ÄêµÄ½ûïÀ¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/security-researcher-malwaretech-pleads-guilty-faces-10-years-in-prison-479f3ac1


¾©¹«Íø°²±¸11010802024551ºÅ