Sophos·¢ÏÖÕë¶ÔExchangeµÄÐÂÀÕË÷Èí¼þEpsilon Red£»Bellingcat³ÆÃÀ¹úÊ¿±øµÄ½ø½¨ÀûÓÿÉй¶ºË±øÆ÷ÐÅÏ¢
°ä²¼¹¦·ò 2021-05-311.Sophos·¢ÏÖÕë¶ÔExchangeµÄÐÂÀÕË÷Èí¼þEpsilon Red

°²È«¹«Ë¾Sophos·¢ÏÖÐÂÀÕË÷Èí¼þEpsilon Red£¬ÖØÒªÕë¶ÔMicrosoft Exchange·þÎñÆ÷¡£×êÑÐÈËÔ±ÔÚµ÷²éÕë¶ÔÃÀ¹úij¾ÆµêµÄ¹¥»÷»î¶¯Ê±·¢ÏֵĸöñÒâÈí¼þ¡£Epsilon RedÓÃGolang£¨Go£©±àд£¬ÓÐÒ»×é¹ÖÒìµÄPowerShell¾ç±¾£¬ÆäÖÐÿ¸ö¾ç±¾¶¼ÓÐÌØ¶¨×÷Óã¬ÈçÖÕÖ¹°²È«¹¤¾ß¡¢É¾³ý¸±±¾¡¢ÇÔÈ¡°²È«ÕÊ»§ÖÎÀíÆ÷£¨SAM£©ÎļþµÈ¡£×êÑÐÈËÔ±°µÊ¾£¬¸ÃÍÅ»ïʹÓÃÁËREvilÊê½ð¼Í¼µÄÄ£°å£¨¸üÕýÁËÆäÖеÄÓï·¨ºÍƴдÃýÎ󣩣¬²¢ÇÒEpsilon RedÊÇÂþÍþÖжíÂÞ˹³¬µÈÊ¿±øµÄ½ÇÉ«Ãû£¬Òò¶ø´§¶È¸ÃÍÅ»ïÓë¶íÂÞ˹Óйء£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-epsilon-red-ransomware-hunts-unpatched-microsoft-exchange-servers/
2.×êÑÐÍŶӷ¢ÏÖÒÔÎÖ¶ûÂê°ü¹üÒ쳣ΪÖ÷ÌâµÄ´¹µö»î¶¯

×êÑÐÍŶӷ¢ÏÖеĴ¹µö»î¶¯¼ÙÒâÎÖ¶ûÂ곬ÊС£¸Ã»î¶¯µÄ´¹µöÓʼþÒÔ¡°ÄúµÄ°ü¹üµÝËÍÒ쳣֪ͨID££¡±ÎªÖ÷Ì⣬ָ³öÓÉÓÚµØÖ·²»ÕýÈ·ÎÞ·¨Í¶µÝ°ü¹ü£¬Óû§Ðè»Ø¸´ÕýÈ·µÄµØÖ·¡£µ±Óû§µã»÷¡°¸üеØÖ·¡±Ê±£¬½«»á×Ô¶¯´´½¨Ò»¸öÖ÷ÌâΪ¡°¸üÐÂÎҵĵØÖ·£¡¡±µÄÓʼþ£¬²¢·¢Ë͵½¹¥»÷ÕßµÄÓʼþµØÖ·¡£Õâ´Î»î¶¯ÖÐÍøÂçµ½µÄÐÅÏ¢¿ÉÓÃÓÚ½øÐÐÉí·ÝµÁÓù¥»÷¡¢½Ó¼ûÓû§µÄÆäËûÕÊ»§»ò½øÐÐÓÐÕë¶ÔÐÔµÄÓã²æÊ½ÍøÂç´¹µö¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/beware-walmart-phishing-attack-says-your-package-was-not-delivered/
3.Bellingcat³ÆÃÀ¹úÊ¿±øµÄ½ø½¨ÀûÓÿÉй¶ºË±øÆ÷ÐÅÏ¢

Bellingcat³ÆÃÀ¹úÊ¿±øÊ¹ÓõÄÔÚÏß½ø½¨ÀûÓÿÉй¶ºË±øÆ÷ÐÅÏ¢¡£ÕƹÜÔÚÅ·ÖÞÉú»îºË±øÆ÷µÄÃÀ¹úÊ¿±ø±ØÒªÓ°Ïó¸´Ôӵݲȫϸ½ÚºÍºÍ̸£¬²¿ÃÅÏÖÒÛÈËԱʹÓÃÁ˹«¿ª¿É¼ûµÄ³éÈÏ¿¨½ø½¨ÀûÓá£ÕâЩÀûÓÃй¶ÁË»ùÖ°µØÎ»¡¢¿ÉÄÜ×°Óк˱øÆ÷¼òÖ±ÇеØÎ»¡¢ÉãÏñ»úµÄµØÎ»¡¢Ñ²ÂߵįµÂÊÉõÖÁ½ûÇøËù±ØÒªµÄΨһ±êʶ·ûµÈ¡£Bellingcat³ÆÔÚGoogleÉÏËÑË÷¡°PAS¡±ºÍ¡°WS3¡±µÈ¾üÊÂÊõÓÔÙ¼ÓÉÏÅ·ÖÞ¿Õ¾ü»ùµØµÄÃû³Æ£¬±ãÄܹ»·¢ÏÖÃâ·ÑµÄ³éÈÏ¿¨Æ½Ì¨£¬ÀýÈçChegg¡¢QuizletºÍCram¡£
ÔÎÄÁ´½Ó£º
https://www.bellingcat.com/news/2021/05/28/us-soldiers-expose-nuclear-weapons-secrets-via-flashcard-apps/
4.×êÑÐÈËÔ±ÑÝʾ¿É´Û¸ÄÒÑÈÏÖ¤µÄPDFÎĵµµÄй¥»÷·½Ê½

Ruhr University Bochum×êÑÐÈËÔ±ÑÝʾ¿É´Û¸ÄÒÑÈÏÖ¤µÄPDFÎĵµµÄÁ½ÖÖÐµĹ¥»÷·½Ê½¡£ÕâÁ½ÖÖ¹¥»÷·½Ê½±»³ÆÎªEvil Annotation Attack£¨EAA£©ºÍSneaky Signature Attack£¨SSA£©£¬¹¥»÷ÕßÄܹ»Åú¸ÄÎĵµÄÚÈݶø²»»áʹÆäÊý×ÖÊðÃûÎÞЧ¡£ÆäÖÐEAAÊÇͨ¹ý²åÈëÔ̺¬¶ñÒâ´úÂëµÄ×¢½âÀ´Åú¸ÄÒÑÈÏÖ¤µÄÎĵµ£¬¶øSSAÊÇͨ¹ýÏòÎĵµÖÐÔö³¤¸²¸ÇÊðÃûµÄÔªËØÀ´½ÚÔì±í¹Û£¬ÒÔÌîд±íµ¥×ֶΡ£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/05/researchers-demonstrate-2-new-hacks-to.html
5.¼ÓÖÝAzusa¾¯¾Ö³ÆÆäϰȾÀÕË÷Èí¼þDoppelPaymer

¼ÓÀû¸£ÄáÑÇÖݵÄAzusa¾¯Ô±¾ÖϰȾDoppelPaymer£¬²¿ÃÅÐÅϢй¶¡£4ÔÂ22ÈÕ£¬ºÚ¿Í¹«¿ªÁ˸ò¿ÃŵÄÐÅÏ¢£¬Ô̺¬¾¯Ô±µÄµ÷²é¼Í¼¡¢Ñ²ÂßÈËÔ±»ã±¨ÒÔ¼°²ÆÕþºÍн×ÊÓйصÄÐÅÏ¢£¬µ«¹¥»÷Õß²¢Ã»ÓÐÅú×¢ËûÃÇÇÔÈ¡Á˼¸¶àÊý¾Ý¡£¸Ã²¿ÃÅÔÚ5ÔÂ28ÈÕ°ä²¼ÁËÉêÃ÷£¬Ö¸³ö¹¥»÷²úÉúÔÚ3ÔÂ9ÈÕ£¬¾¯¾ÖµÄ²¿ÃÅϵͳÎÞ·¨½Ó¼û£¬Ö±µ½5ÔÂ20ÈÕÈ·¶¨Ð¹Â¶ÐÅÏ¢Ô̺¬Éç»á°²È«ºÅÂë¡¢¼ÓÖÝÉí·ÝÖ¤ºÅÂë¡¢¾üÊÂÉí·ÝÖ¤ºÅÂë¡¢²ÆÕþÕË»§ÐÅÏ¢ºÍͨ¹ý×Ô¶¯³µÅƼø±ðÏµÍ³ÍøÂçµÄÐÅÏ¢µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/ca-azusa-police-reveal-ransomware-attack-in-march/
6.¿¨°Í˹»ù°ä²¼ÓйØÀÕË÷Èí¼þJSWormµÄÑݱäµÄ·ÖÎö»ã±¨

¿¨°Í˹»ù°ä²¼ÁËÓйØÀÕË÷Èí¼þJSWormµÄÑݱäµÄ·ÖÎö»ã±¨¡£JSWormÀÕË÷Èí¼þÔÚ2019±»·¢ÏÖ£¬´ÓÄÇÒÔÀ´£¬³öÏÖÁËÖîÈçNemty¡¢nefilem¡¢OffwhiteµÈ·ÖÆçµÄ±äÖÖ¡£¸Ã¶ñÒâÈí¼þµÄ¿ª·¢ÈËÔ±Ò»ÏòÔÚ³Áбàд´úÂ룬²¢³¢ÊÔʹÓÃ·ÖÆçµÄ·Ö·¢²½Öè¡£ÔÚ2020ÄêµÄʱ³½£¬¿ª·¢ÈËÔ±ÉõÖÁ½«±à³Ì˵»°´ÓC ++¸ü¸ÄΪGolang£¬²¢ÆëÈ«ÖØÐÂÆðÍ·³Áд´úÂë¡£´Ó2019Äê´´½¨µ½2020ÄêÉϰëÄ꣬JSWormµÄ´«²¼·½Ê½Ô̺¬Trik botnet¡¢RIG¿ª·¢¹¤¾ß¡¢¼ÙµÄ¸¶¿îÍøÕ¾ºÍÀ¬»øÓʼþ»î¶¯µÈ¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/evolution-of-jsworm-ransomware/102428/


¾©¹«Íø°²±¸11010802024551ºÅ