ÃÀ¹úµ±¾Ö°ä²¼½áºÏÖҸ棺BlackMatterÀÕË÷Èí¼þÕý¶ÔÃÀ¹ú»ù´¡ÉèÊ©ÌáÒé¹¥»÷

°ä²¼¹¦·ò 2021-10-21

Symantec·¢ÏÖHarvesterÕë¶ÔÄÏÑǵçÐÅÐÐÒµµÄ¹¥»÷»î¶¯


Symantec·¢ÏÖHarvesterÕë¶ÔÄÏÑǵçÐÅÐÐÒµµÄ¹¥»÷»î¶¯.png


SymantecÔÚ10ÔÂ18ÈÕÅû¶ÁËÒ»¸öеÄÓɹú¶ÈÖ§³ÖµÄºÚ¿ÍÍÅ»ïHarvesterµÄ¹¥»÷»î¶¯¡£Õâ´Î¹¥»÷»î¶¯¶Ô×¼ÁËÄÏÑǵÄ×éÖ¯£¬³ö¸ñÊǰ¢¸»º¹£¬Õë¶ÔµçÐźÍITÐÐÒµµÄ¹«Ë¾ÒÔ¼°¹Ù·½×éÖ¯£¬ÆðÍ·ÓÚ2021Äê6Ô£¬×î½üÒ»´Î»î¶¯²úÉúÔÚ2021Äê10Ô¡£ÔÚ¼¼Êõ·½Ã棬¹¥»÷ÕßÔÚÖ¸±êÖÐ×°ÖÃÁËÒ»¸öÃûΪBackdoor.GraphonµÄ×Ô½ç˵ºóÃÅ£¬ÒÔ¼°ÆäËû×Ô½ç˵ÏÂÔØÆ÷ºÍ½ØÍ¼¹¤¾ß¡£Ä¿Ç°Éв»Ã÷ÏÔ³õʼϰȾý½éÊÇʲô£¬µ«×êÑÐÈËÔ±ÔÚ±»ºÚÉ豸ÉÏ·¢ÏֵĵÚÒ»¸ö¹ØÓÚÕâ´Î»î¶¯µÄÖ¤¾ÝÊǶñÒâURL¡£


Ô­ÎÄÁ´½Ó£º

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/harvester-new-apt-attacks-asia


DesordenÐû³ÆÒÑÈëÇÖºê»ùAcerÔÚÖйų́ÍåµÄ·þÎñÆ÷


DesordenÐû³ÆÒÑÈëÇÖºê»ùAcerÔÚÖйų́ÍåµÄ·þÎñÆ÷.png


ÉÏÖÜ£¬DesordenÈëÇÖÁ˺ê»ù£¨Acer£©Ó¡¶ÈµÄ·þÎñÆ÷²¢ÇÔÈ¡ÁËÆäÖеÄÊý¾Ý¡£²»µ½Ò»Öܺ󣬸ÃÍÅ»ïÓÖ³ÆËûÃÇÔÚ10ÔÂ15ÈÕÈëÇÖÁ˺ê»ų̀ÍåµÄ·þÎñÆ÷£¬²¢¹«¿ªÁ˸ù«Ë¾ÄÚ²¿ÍøÕ¾µÄͼƬºÍÔ±¹¤µÇ¼ʹ´¦µÄCSVÎļþ¡£Desorden°µÊ¾ËûÃÇÕâ´ÎµÄ¹¥»÷ÊÇΪÁËÖ¤Ã÷ºê»ùÒÀÈ»´æÔÚ·ì϶£¬²¢Ö¸³ö¸Ã¹«Ë¾ÔÚÂíÀ´Î÷ÑǺÍÓ¡¶ÈÄáÎ÷ÑǵÄϵͳҲÈÝÒ×Êܵ½¹¥»÷¡£Ä¿Ç°£¬ºê³žÌ¨ÍåÒѾ­¹Ø¹ØÁ˱»ºÚµÄϵͳ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/acer-hacked-twice-in-a-week-by-the-same-threat-actor/


ºÚ¿ÍÍÅ»ïTeamTNTÀûÓöñÒâDocke¾µÏñ·Ö·¢ÍÚ¿óÈí¼þ


ºÚ¿ÍÍÅ»ïTeamTNTÀûÓöñÒâDocke¾µÏñ·Ö·¢ÍÚ¿óÈí¼þ.png

Uptycs×êÑÐÍŶÓÔÚ10ÔÂ18ÈÕ¹«¿ªÁËTeamTNTÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£ÔÚÕâ´Î»î¶¯ÖУ¬TeamTNTÀûÓÃÁ˶ñÒâDocke¾µÏñ£¬²¢Ê¹ÓÃǶÈëʽ¾ç±¾ÏÂÔØÉ¨ÃèÆ÷ZgrabºÍÉøÈë²âÊÔ¹¤¾ßmasscannerÀ´ÌáÈ¡bannerºÍ¶Ë¿ÚɨÃ裬ּÔÚ·Ö·¢¶ñÒâcoinminerÀ´½Ù³ÖÖ¸±êµÄÍÆËã×ÊÔ´Íڿ󡣸þµÏñÍйÜÔÚÃûΪDocker HubÉÏ£¬ÃûΪalpineos£¬¸ÃÓû§ÓÚ2021Äê5ÔÂ26ÈÕ²ÎÓëDocker Hub£¬½ØÖÁ´Ë¿Ì£¬alpineosÅäÖÃÎļþÍйÜÁË25¸öDockerÓ³Ïñ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/123535/cyber-crime/teamtnt-docker-attack.html


×êÑÐÈËÔ±·¢ÏÖLyceumÍÅ»ïÕë¶ÔÍ»Äá˹µÄ¹¥»÷»î¶¯


×êÑÐÈËÔ±·¢ÏÖLyceumÍÅ»ïÕë¶ÔÍ»Äá˹µÄ¹¥»÷»î¶¯.png


KasperskyµÄ×êÑÐÈËÔ±ÓÚ10ÔÂ18ÈÕ°ä²¼»ã±¨£¬½éÉÜÁËLyceumÍÅ»ïÕë¶ÔÍ»Äá˹µÄ¹¥»÷»î¶¯¡£Lyceum£¨±ðÃûHexane£©ÓÚ2019Äê³õ´Î±»SecureworksÆØ¹â£¬ÖØÒªÕë¶ÔÖж«µÄÄÜÔ´ºÍµçÐÅÐÐÒµ¡£Õâ´Î¹¥»÷µÄÖ¸±ê¾ùÊÇÍ»Äá˹µÄ³ÛÃû¹«Ë¾£¬ÈçµçÐÅ»òº½¿Õ¹«Ë¾¡£¹¥»÷ÕßʹÓÃÁËÁ½¸öÓÃC++±àдµÄжñÒâÈí¼þJamesºÍKevin£¬¹ÌÈ»JamesÔںܴóˮƽÉÏÈÔ»ùÓÚ¶ñÒâÈí¼þDanBot£¬µ«KevinÔڼܹ¹ºÍͨѶºÍ̸·½Ãæ×ö³öÁ˳Á´óŤת¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/lyceum-group-reborn/104586/


°²È«¹«Ë¾Trustwave°ä²¼ÀÕË÷Èí¼þBlackByteµÄ½âÃÜÆ÷


°²È«¹«Ë¾Trustwave°ä²¼ÀÕË÷Èí¼þBlackByteµÄ½âÃÜÆ÷.png


°²È«¹«Ë¾TrustwaveµÄ×êÑÐÍŶÓSpiderLabsÔÚGitHubÉϰ䲼ÁËÀÕË÷Èí¼þBlackByteµÄ½âÃÜÆ÷¡£Æ¾¾Ý¶ÔÀÕË÷Èí¼þµÄ·ÖÎöÅú×¢£¬BlackByteʹÓÃÁËÒ»ÑùµÄԭʼÃÜÔ¿À´¼ÓÃÜÎļþ£¬²¢Ê¹ÓöԳÆÃÜÔ¿Ëã·¨AES£¬Òò¶øÈκÎÓµÓÐԭʼÃÜÔ¿µÄÈ˶¼Äܹ»½âÃÜÎļþ¡£×êÑÐÈËÔ±·¢ÏÖÀÕË÷Èí¼þʹÓÃÒ»¸öǶÈëÁ˶à¸öÃÜÔ¿.PNGÎļþ£¬Í¨¹ý¶ÈÎö¸ÃÎļþ¿ª·¢ÁËÃâ·ÑµÄ½âÃÜÆ÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/blackbyte-ransomware-decryptor-released/


CISA¡¢FBIºÍNSA°ä²¼BlackMatterµÄÔ¤¾¯²¼¸æ


CISA¡¢FBIºÍNSA°ä²¼BlackMatterµÄÔ¤¾¯²¼¸æ.png


10ÔÂ18ÈÕ£¬CISA¡¢FBIºÍNSA°ä²¼ÁËÀÕË÷Èí¼þBlackMatterµÄ½áºÏÍøÂ簲ȫÕ÷ѯ (CSA)¡£×Ô½ñÄê7ÔÂÒÔÀ´£¬ÀÕË÷Èí¼þBlackMatterÒѹ¥»÷ÁËÃÀ¹úµÄ¶à¸öÓë¹Ø¼ü»ù´¡ÉèÊ©ÓйصĹ«Ë¾£¬ÀýÈçʳƷºÍũҵÐÐÒµ¡£¸ÃCSA·ÖÎöÁËBlackMatterµÄÑù±¾²¢½áºÏÁËÀ´×ÔµÚÈý·½µÄÐÅÏ¢£¬ÌṩÁ˹¥»÷ÕßµÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½£¬²¢¸ÅÊö»º½â´ëÊ©£¬ÒÔÔ®ÊÖ×éÖ¯¸Ä½øÕë¶Ô´ËÀ๥»÷µÄ± £»¤¡¢¼ì²âºÍÏìÓ¦´ëÊ©¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/10/18/cisa-fbi-and-nsa-release-joint-cybersecurity-advisory-blackmatter