BahamutÍÅ»ïÀûÓüÙðµÄVPNÀûÓÃÇÔÈ¡AndroidÓû§ÐÅÏ¢
°ä²¼¹¦·ò 2022-11-2511ÔÂ23ÈÕ£¬ESETÅû¶ÁËÓÉAPT×éÖ¯BahamutÌáÒéÕë¶ÔAndroidÓû§µÄ¹¥»÷»î¶¯¡£¸Ã»î¶¯×Ô2022Äê1ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬Bahamut³Áдò°üÁ˺ÏÓÃÓÚAndroidµÄSoftVPNºÍOpenVPNÀûÓã¬Ôö³¤ÁËÓµÓмäµýÖ°ÄܵĶñÒâ´úÂë¡£Òò¶ø£¬¸ÃÀûÓÃÈÔ»áÌṩVPNÖ°ÄÜ£¬Í¬Ê±»¹Äܹ»´ÓÒÆ¶¯É豸ÖÐÇÔÊØÐÅÏ¢¡£ÎªÁË·ÛÊι¥»÷»î¶¯²¢Ìá¸ß¿ÉÐŶȣ¬BahamutʹÓÃÁËSecureVPN£¨Ò»¸öºÏ·¨µÄVPN·þÎñ£©µÄÃû×Ö£¬²¢´´½¨ÁËÒ»¸ö¼ÙÍøÕ¾[thesecurevpn]À´·Ö·¢¶ñÒâÀûÓá£
https://www.welivesecurity.com/2022/11/23/bahamut-cybermercenary-group-targets-android-users-fake-vpn-apps/
2¡¢³¬¹ý50¸öαÔìµÄMSI Afterburner¹ÙÍø·Ö·¢ÍÚ¿óÈí¼þ
¾Ý11ÔÂ23ÈÕ±¨Â·£¬CybleµÄ×êÑÐÈËÔ±·¢ÏÖÁ˼¸¸öÕë¶ÔMSI AfterburnerÈí¼þµÄ´¹µö»î¶¯£¬Ö¼ÔÚ·Ö·¢ÍÚ¿ó¶ñÒâÈí¼þ¡£ÔÚ´ÓǰÈý¸öÔÂÖУ¬Óг¬¹ý50¸ö¼ÙÒâMSI Afterburner¹ÙÍøµÄ´¹µöÍøÕ¾£¬»á·Ö·¢XMR(Monero)¿ó¹¤ÓëÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þ¡£¾ßÌåÀ´Ëµ£¬µ±Ö¸±êÖ´ÐÐαÔìµÄMSI Afterburner×°ÖÃÎļþ(MSIAfterburnerSetup.msi)ʱ£¬³ýÁË»á×°ÖúϷ¨µÄAfterburner·¨Ê½£¬»¹»á͵͵µØ×°Öò¢ÔËÐжñÒâÈí¼þRedLineºÍXMRÍÚ¿ó·¨Ê½¡£²»ÐÒµÄÊÇ£¬¸Ã»î¶¯ÏÕЩËùÓеÄ×é¼þ¶¼Ã»Óб»É±¶¾Èí¼þ¼ì²âµ½¡£
https://blog.cyble.com/2022/11/23/fake-msi-afterburner-sites-delivering-coin-miner/
3¡¢IBM·¢ÏÖÀÕË÷Èí¼þRansomExxµÄбäÌåÒÑÓÃRust³Áд
IBMÔÚ11ÔÂ22ÈÕ³ÆÆä·¢ÏÖÁËRansomExxÀÕË÷Èí¼þµÄÒ»¸öбäÌ壬¸Ã±äÌåÒÑÓÃRust˵»°³Áд¡£ÓÃRust¿ª·¢µÄ¶ñÒâÈí¼þͨ³£»áÓнϵ͵ÄAV¼ì²âÂÊ£¬Õâ¿ÉÄÜÊÇËüʹÓøÃ˵»°µÄÖØÒªÔÒò¡£Ð±äÌåµÄÖ°ÄÜÓëÆäC++µÄ°æ±¾ÀàËÆ£¬½«Òª¼ÓÃܵÄÖ¸±êĿ¼Áбí×÷ΪºÅÁîÐвÎÊý´«µÝ£¬¶øºóʹÓÃAES-256¼ÓÃÜÎļþ£¬²¢Ê¹ÓÃRSAÀ´±£»¤¼ÓÃÜÃÜÔ¿£¬ËùÓдóÓÚ»òµÅ×Ú40×Ö½ÚµÄÎļþ¶¼±»¼ÓÃÜ¡£Ä¿Ç°£¬ÔÚ60¶à¼ÒAVÌṩÉÌÖÐÖ»ÓÐ14¼Ò¼ì²âµ½ÁËÐÂÑù±¾¡£
https://securityintelligence.com/posts/ransomexx-upgrades-rust/
4¡¢Smith FamilyÔ¼8Íò¾èÔùÕߵľßÌåÐÅÏ¢¿ÉÄÜÒÑй¶
¾ÝýÌå11ÔÂ22ÈÕ±¨Â·£¬°Ä´óÀûÑǴȱ¯»ú¹¹Smith Familyй©ÆäÔâµ½ºÚ¿Í¹¥»÷£¬Ô¼8Íò¾èÔùÕߵľßÌåÐÅÏ¢¿ÉÄÜÒѱ»½Ó¼û¡£Ð¹Â¶ÐÅÏ¢Éæ¼°ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢ÓʼþµØÖ·ºÍ¾èÔù¼Í¼£¬ÒÔ¼°²¿ÃÅÖ§¸¶¿¨µÄ¶øÐÅÏ¢¡£¸Ã»ú¹¹µÄÉêÃ÷°µÊ¾£¬ºÚ¿Ḭ́ͼµÁÈ¡×ʽðµ«ÊÇûÓгɹ¦£¬ËûÃÇÒÑ֪ͨÊÜÓ°ÏìµÄ¾èÔùÕߣ¬Ä¿Ç°Ã»ÓÐÈκÎÈ˵ÄÐÅÏ¢±»ÀÄÓá£
https://www.abc.net.au/news/2022-11-22/smith-family-charity-cyber-crime-hackers-donor-details/101683860
5¡¢¼Ù×°³ÉÐÂÎŵ÷²éµÄ¶ñÒâwordÎĵµÇÔȡָ±êµÄÐÅÏ¢
¾ÝASEC 11ÔÂ25ÈÕ±¨Â·£¬½üÆÚÒ»¸öÓ볯ÏÊÓйصĶñÒâWordÎļþÒ»ÏòÔÚʹÓÃFTPй¶Óû§Í´´¦¡£¸ÃWordÎĵµµÄÎļþÃûΪ¡°CNA[Q].doc¡±£¬¼Ù×°³ÉCNAÐÂ¼ÓÆÂµçÊÓ½ÚÄ¿²É·Ã¡£¸ÃÎļþÊÜÃÜÂë±£»¤£¬ÓëÃÜÂëһ·×÷ΪÓʼþ¸½¼þ·Ö·¢¡£ÎļþÖÐÔ̺¬¶ñÒâVBAºê£¬Í¨¹ýDocument_Open()º¯Êýʹ¶ñÒâºê×Ô¶¯Ö´ÐС£ËüÄܹ»Ê¹ÓÃFTPй¶Óû§µÄÐÅÏ¢¡¢´´½¨LNKÎļþ¡¢¸ü¸ÄMS Office°²È«ÉèÖúͼͼ¼üÅÌ¡£
https://asec.ahnlab.com/en/42529/
6¡¢Group-IB°ä²¼ÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þ·Ö·¢»î¶¯µÄ·ÖÎö»ã±¨
11ÔÂ23ÈÕ£¬Group-IB°ä²¼»ã±¨³ÆÒÑÈ·¶¨34¸ö¶íÂÞ˹ºÚ¿ÍÍÅ»ïÔÚÒÔÇÔÈ¡¼´·þÎñģʽ(SaaS)·Ö·¢ÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þ¡£¹¥»÷ÕßÖØÒªÊ¹ÓÃRacoonºÍRedlineÇÔÈ¡·¨Ê½£¬À´ÍøÂçSteamºÍRobloxÓÎÏ·ÕÊ»§µÄÃÜÂ룬ÑÇÂíÑ·ºÍPayPalµÄÍ´´¦£¬ÒÔ¼°Óû§µÄÖ§¸¶¼Í¼ºÍ¼ÓÃÜÇ®°üÐÅÏ¢¡£2022ÄêµÄǰ7¸öÔ£¬¹¥»÷Õß¹²Ï°È¾³¬¹ý89Íǫ̀É豸£¬ÇÔÈ¡³¬¹ý5000Íò¸öÃÜÂë£¬ÖØÒªÕë¶ÔÃÀ¹ú¡¢°ÍÎ÷¡¢Ó¡¶È¡¢µÂ¹úºÍÓ¡¶ÈÄáÎ÷ÑÇ£¬¶ñÒâ»î¶¯Éæ¼°111¸ö¹ú¶È/µØÓò¡£
https://www.group-ib.com/media-center/press-releases/professional-stealers/


¾©¹«Íø°²±¸11010802024551ºÅ