Agent Tesla³¢ÊÔ´Û¸Ä΢ÈíAMSIÀ´Èƹýɱ¶¾Èí¼þ¼ì²â£»Google°ä²¼Android°²È«¸üУ¬×ܼƽ¨¸´40¶à¸ö·ì϶

°ä²¼¹¦·ò 2021-02-04

1.Agent Tesla³¢ÊÔ´Û¸Ä΢ÈíAMSIÀ´Èƹýɱ¶¾Èí¼þ¼ì²â


1.jpg


Sophos×êÑÐÈËÔ±·¢ÏÖ¼äµýÈí¼þAgent Tesla³¢ÊÔ´Û¸Ä΢Èí·À¶ñÒâÈí¼þÈí¼þ½Ó¿Ú£¨AMSI£©£¬À´Èƹýɱ¶¾Èí¼þµÄɨÃèºÍ·ÖÎö¡£Agent TeslaÓÚ2014Äê³õ´Î±»·¢ÏÖ£¬ÊÇÒ»ÖÖÓÃ.NET±àдµÄóÒ×RAT¡£Sophos°µÊ¾£¬¸Ã¶ñÒâÈí¼þÔÚ²»ÐÝ¿ª·¢ÖУ¬Æä.NETÏÂÔØ·¨Ê½¿ÉŲÓò¢ÏÂÔØÍйÜÔںϷ¨ÍøÕ¾ÉϵĶñÒâ´úÂë¡£Ôڳɹ¦´Û¸ÄAMSIºó¸Ã¶ñÒâÈí¼þ¿ÉÔÚûÓÐÈκÎ×ÌÈŵÄÇé¿öÏÂÆëÈ«ÊýÊð£¬ÒÔÇÔÈ¡Êý¾Ý£¬ÖØÒªÕë¶ÔOpera¡¢Chromium¡¢Chrome¡¢Firefox¡¢OpenVPNºÍOutlookµÅצÓá£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/agent-tesla-ramps-up-its-game-in-bypassing-security-walls-attacks-endpoint-protection/


2.Google°ä²¼Android°²È«¸üУ¬×ܼƽ¨¸´40¶à¸ö·ì϶


2.png


Google°ä²¼ÁË2Ô·ÝAndroid°²È«¸üУ¬×ܼƽ¨¸´40¶à¸ö·ì϶¡£ÕâЩ·ì϶ÖнÏΪ³ÁÒªµÄ·ì϶ÊÇMedia Framework×é¼þÖеĴúÂëÖ´Ðзì϶£¨CVE-2021-0325)¡¢ÌáȨ·ì϶£¨CVE-2021-0332£©ºÍÐÅϢй¶·ì϶£¨CVE-2021-0335£©¡£´Ë±í£¬¸üл¹½¨¸´ÁËÄÚºËÖеĴúÂëÖ´Ðзì϶£¨CVE-2017-18509£©ÒÔ¼°Qualcomm×é¼þÖеĶà¸ö·ì϶£¨CVE-2020-11272¡¢CVE-2020-11163ºÍCVE-2020-11170µÈ£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/google-patches-16-high-severity-privilege-escalation-vulnerabilities-android


3.ºÚ¿ÍÏúÊÛAirtelIndiaµÄ250ÍòÓû§ÐÅÏ¢£¬±»¸Ã¹«Ë¾·ñ¶¨


3.png


ºÚ¿Í×éÖ¯Red RabbitÔÚ°µÍøÒÔ3500ÃÀÔªµÄ¼ÛÖµÏúÊÛAirtelIndiaµÄ250ÍòÓû§ÐÅÏ¢¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬ÊÓ×¢ÐÔ±ð¡¢ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢·þÎñ״̬¡¢µç»°ºÅÂë¡¢ÃÅÉ̱êÂë¡¢AadhaarºÅÂë¡¢»¤ÕÕºÅÂ롢ѡÃñ±àºÅ¡¢¸¸Ç×»òÕÉ·òµÄÃû×ÖºÍIMSI£¨¹ú¼ÊÒÆ¶¯Óû§Éí·Ý£©ºÅÂë¡£´Ë±í£¬ºÚ¿Í»¹°ä²¼ÁËÆäÔÚAirtelµÄһ̨·þÎñÆ÷ÉÏ´«ShellµÄÆÁÄ»½ØÍ¼¡£µ«Airtel·ñ¶¨Æä²úÉúÁËÊý¾Ýй¶£¬²¢Ö¸³ö´óÎÞÊýµÄÊý¾Ý²»ÊôÓÚAirtelµÄ¿Í»§¡£Ä¿Ç°£¬Red RabbitÔËÓªµÄÍøÕ¾Ò²ÒѹعØ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/hackers-leak-airtel-india-user-data-aadhaar-numbers/


4.Èí¼þ¹«Ë¾Wind River³ÆÆäÔâµ½¹¥»÷£¬Ô±¹¤ÐÅϢй¶


4.png


¼ÓÀû¸£ÄáÑǵÄÈí¼þ¹«Ë¾Wind River³ÆÆäÔâµ½¹¥»÷£¬µ¼ÖÂÔ±¹¤µÄÓ×ÎÒÐÅϢй¶¡£¸Ã¹«Ë¾³ÆÊÂÎñ²úÉúÔÚ2020Äê9ÔÂ29ÈÕ×óÓÒ£¬ºÚ¿Í¿ÉÄÜÒѾ­ÇÔÈ¡ÁËÒ»¸ö»ò¶à¸öÎļþ¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬µ®ÉúÈÕÆÚ¡¢¼ÝÕÕºÅÂë¡¢¹«ÃñÉí·ÝÖ¤ºÅÂë¡¢Éç»á±£ÏÕºÅÂë¡¢»¤ÕÕ»òǩ֤ºÅÂë¡¢½¡È«¾ßÌåÐÅÏ¢ºÍ²ÆÕþÕÊ»§ÐÅÏ¢µÈ¡£Ä¿Ç°£¬Wind RiverÉÐδÌṩÓйØÊÜÓ°ÏìÔ±¹¤µÄÊýÁ¿»ò¹¥»÷ÕßÈôºÎ·ÛËéÆäϵͳµÄ¾ßÌåÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/114151/data-breach/wind-river-data-breach.html


5.»õÔ˹«Ë¾Forward AirϰȾHades£¬Ëðʧ´ï750ÍòÃÀÔª


5.png


»õÔ˹«Ë¾Forward AirÔâµ½ÁËHadesÀÕË÷Èí¼þ¹¥»÷£¬Ôì³ÉµÄËðʧ´ï750ÍòÃÀÔª¡£¸Ã¹¥»÷ÊÂÎñ²úÉúÔÚÈ¥Äê12ÔÂ15ÈÕ£¬ÒòϰȾHadesµ¼Ö¸ù«Ë¾½«ËùÓÐITϵͳÍÑ»úÒÔÓ¦¶ÔÈëÇÖ¡£µ¼Ö¼ÝʻԱºÍÔ±¹¤ÎÞ·¨»ñÈ¡±ØÒªµÄÎļþÒÔͨ¹ýº£¹ØÇ幨ÔËÊ䣬ÆäÔËÓªÊܵ½ÑϳÁ·ÛËé¡£Ö»¹ÜForward Air°µÊ¾ÆäÒѳɹ¦µØ´Ó¹¥»÷Öи´Ô­£¬µ«»¹ÊÇÖ§³öÁ˳Á³Á¼ÛÖµ£¬ÆäÔÚµÚËÄʱ¶ÈµÄ²ÆÕþÒµ¼¨ÖеÄËðʧ¸ß´ï750ÍòÃÀÔª¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/trucking-company-forward-air-said-its-ransomware-incident-cost-it-7-5-million/


6.Chainalysis°ä²¼2020ÄêÀÕË÷Èí¼þ¹¥»÷µÄ»ØÊ׻㱨


6.png


Chainalysis°ä²¼ÁË2020ÄêÀÕË÷Èí¼þ¹¥»÷µÄ»ØÊ׻㱨¡£»ã±¨ÏÔʾ£¬ÀÕË÷Èí¼þµÄÊܺ¦ÕßÔÚ2020ÄêÖÁÉÙ×ܹ²Ö§¸¶ÁË3.5ÒÚÃÀÔªÊê½ð£¬±È2019Äêͬ±ÈÔö³¤ÁË311£¥¡£È¥ÄêÓ¯Àû×î¶àµÄÍÅ»ïΪRyuk¡¢Maze¡¢Doppelpaymer¡¢Netwalker¡¢ContiºÍREvil£¬Æä´ÎΪSnatch¡¢Defray777£¨RansomExx£©ºÍDharmaµÈ¡£´Ë±í£¬ÀÕË÷Èí¼þ¹¥»÷½öÕ¼ËùÓлùÓÚ¼ÓÃÜÇ®±ÒµÄ·¸×ï»î¶¯µÄ7£¥£¬Ö»¹ÜÕâ¸öÊý×ֺܵÍ£¬µ«´ËÀ๥»÷ÊýÁ¿ÆäʵÔÚÔö³¤¡£


Ô­ÎÄÁ´½Ó£º

https://blog.chainalysis.com/reports/ransomware-ecosystem-crypto-crime-2021