ÒÔÉ«ÁÐÀí¹¤Ñ§ÔºTechnion±»DarkBitÀÕË÷170ÍòÃÀÔª

°ä²¼¹¦·ò 2023-02-14
1¡¢ÒÔÉ«ÁÐÀí¹¤Ñ§ÔºTechnion±»DarkBitÀÕË÷170ÍòÃÀÔª

      

¾ÝýÌå2ÔÂ12ÈÕ±¨Â·£¬ÒÔÉ«Áж¥¼âµÄ×êÑÐÐÍ´óѧÒÔÉ«ÁÐÀí¹¤Ñ§Ôº£¨Technion£©Ôâµ½ÁËÐÂÀÕË÷ÍÅ»ïDarkBitµÄ¹¥»÷¡£¹¥»÷²úÉúÓÚ2ÔÂ12ÈÕ»ò֮ǰ£¬DarkBitÍÅ»ïÒªÇó80±ÈÌØ±Ò£¨Ô¼ºÏ1745200ÃÀÔª£©ÓÃÓÚ½âÃÜ¡£DarkbitÍþвÈôÊÇTechnion²»ÔÚ48Ó×ʱÄÚ¸¶Êê½ð£¬ËûÃÇÒª½«½ð¶îÌá¸ß30%¡£µ«×êÑÐÈËÔ±Ö¸³ö£¬¸ÃÍŶÓËÆºõÊdzöÓÚÕþÖζ¯»ú£¬¼´±ãÂú×ãÒªÇó£¬ËûÃÇÒ²²»Ì«¿ÉÄܸø³ö½âÃÜÃÜÔ¿¡£´Ë±í£¬VX-underground°ÑÎȵ½£¬ÀÕË÷ÐÅÊÇʹÓÃÓ¢Óï·­ÒëÆ÷дµÄ¡£


https://securityaffairs.com/142160/hacking/israeli-technion-suffered-ransomware-attack.html


2¡¢°ÙÊ¿ÉÀÖ×°Æ¿·çÏÕͶ×ʹ«Ë¾µÄÓ×ÎҺͲÆÕþÐÅϢй¶

      

¾Ý2ÔÂ13ÈÕ±¨Â·£¬ÃÀ¹ú×î´óµÄ°ÙÊ¿ÉÀÖÒûÁÏ×°Æ¿ÉÌPepsi Bottling Ventures LLC²úÉúÐÅϢй¶¡£¸Ã¹«Ë¾ÔÚ֪ͨÖÐÚ¹ÊÍ˵£¬Î¥¹æÊÂÎñ²úÉúÔÚ2022Äê12ÔÂ23ÈÕ£¬µ«Ö±µ½18Ììºó£¬Ò²¾ÍÊÇ2023Äê1ÔÂ10Èղű»·¢ÏÖ£¬ÒÑÖªµÄ×îºóÒ»´Î½Ó¼û¹¦·òΪ1ÔÂ19ÈÕ¡£¾Ýµ÷²é£¬¹¥»÷ÕßÈëÇÔìäÄÚ²¿ITϵͳװÖÃÁËÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¬²¢ÏÂÔØÁËϵͳÖеIJ¿ÃÅÐÅÏ¢£¬Éæ¼°ÐÕÃû¡¢Éí·ÝÖ¤ºÅ¡¢Éç»á°²È«ÂëºÍ½ðÈÚÕË»§ÐÅÏ¢µÈ¡£¸Ã¹«Ë¾ÒѳÁÖÃËùÓÐÃÜÂ룬²¢Í¨Öª·¨Âɲ¿ÃÅ£¬»¹½«ÎªÊÜÓ°ÏìµÄÓ×ÎÒÌṩһÄêµÄÃâ·ÑÉí·Ý¼à¿Ø·þÎñ¡£


https://www.theregister.com/2023/02/14/pepsi_bottling_malware/


3¡¢B&G FoodsÔâµ½DaixinµÄ¹¥»÷Ô¼1000̨Ö÷»ú±»¼ÓÃÜ

      

ýÌå2ÔÂ12Èճƣ¬Daixin½üÆÚµÄÒ»´ÎÍøÂç¹¥»÷µ¼ÖÂB&G FoodsÔ¼1000̨Ö÷»ú±»¼ÓÃÜ¡£DaixinµÄ½²»°È˰µÊ¾£¬B&GÓÚ2ÔÂ4ÈÕ±»¼ÓÃÜ£¬µ«ËûÃDz»È·¶¨ÊÇ·ñÒѶÔËùÓб¸·Ý½øÐмÓÃÜ£¬²¢°µÊ¾¸Ã¹«Ë¾¿ÉÄÜÒѾ­¸´Ô­¡£´Ë±í£¬ËûÃÇÔÚ±¾µØÉÏÁôÏÂÁËÊê½ð¼Í¼²¢·¢ËÍÁ˼¸´ÎͨѶ£¬µ«B&GÒ»ÏòûÓлØÓ¦¡£×êÑÐÈËÔ±³Æ£¬Ð¹Â¶Êý¾ÝÖеÄÈ·Ô̺¬¹«Ë¾ÄÚ²¿Îļþ£¬È»¶ø£¬Õû¸öת´¢ËƺõûÓиüÑϳÁ»ò»úÃܵĹ«Ë¾Îļþ¡¢ÈËÊÂÎļþ»ò³Ð°üÉÌÎļþ¡£


https://www.databreaches.net/b-files-leaked/


4¡¢¼ÓÄôó×î´óµÄÊéµêIndigoÔâµ½¹¥»÷µ¼ÖÂÍøÕ¾ÎÞ·¨½Ó¼û

      

2ÔÂ9ÈÕ±¨Â·³Æ£¬¼ÓÄôó×î´óµÄÁ¬ËøÊéµêIndigo Books & MusicÔâµ½¹¥»÷¡£ÉÏÖÜÈý£¬Indigo°ä·¢Òò¼¼ÊõÎÊÌâµ¼ÖÂÎÞ·¨½Ó¼û¸ÃÍøÕ¾£¬ÊµÌåµêµÄ¹Ë¿ÍÖ»ÄÜÓÃÏÖ½ðÖ§¸¶¡£´Ë±í£¬ÎÞ·¨½øÊ©ÀñÎ│ÂòÂô£¬ÔÚÏß¶©µ¥Ò²¿ÉÄÜ»á³öÏÖÑÓ³¤¡£¼¸¸öÓ×ʱºó£¬¸Ã¹«Ë¾³ÆÆäϵͳÔâµ½ÁËÍøÂç¹¥»÷£¬²¢ÇÒÔÚµ÷²é´ËÊÂÎñ¡£¸Ã¹«Ë¾Ã»ÓÐй©Ŀǰ°²È«ÊÂÎñµÄÀàÐÍ£¬µ«°µÊ¾ÔÚÖÂÁ¦È·¶¨¹¥»÷ÕßÊÇ·ñÉè·¨½Ó¼û»òÇÔÈ¡Á˿ͻ§Êý¾Ý¡£


https://www.bleepingcomputer.com/news/security/largest-canadian-bookstore-indigo-shuts-down-site-after-cyberattack/


5¡¢ProofpointÅû¶TA866Õë¶ÔÃÀ¹úºÍµÂ¹úµÄ¹¥»÷»î¶¯

      

ProofpointÔÚ2ÔÂ8ÈÕÅû¶ÁËÐÂÍþвÍÅ»ïTA866Õë¶ÔÃÀ¹úºÍµÂ¹úµÄ¹¥»÷»î¶¯¡£¸Ã»î¶¯ËƺõÊdzöÓÚ¾­¼Ã¶¯»ú£¬ÓÚ2022Äê10Ô³õ´Î±»·¢ÏÖ£¬²¢Ò»Ïò³ÖÐøµ½2023Äê¡£¹¥»÷ÖÐʹÓõĴ¹µöÓʼþÔ̺¬´øÓжñÒâºêµÄMicrosoft Publisher(.pub)¸½¼þ¡¢Á´½Óµ½´øÓкêµÄ.pubÎļþµÄURL£¬»òÔ̺¬ÏÂÔØÎ£ÏÕJavaScriptÎļþµÄURLµÄPDF¡£Ö¸±êµã»÷URLºó»á´¥·¢¶à²½Öè¹¥»÷Á´£¬¶øºóÏÂÔØ²¢Ö´ÐÐTA886µÄ×Ô½ç˵¶ñÒâÈí¼þScreenshotter¡£


https://www.proofpoint.com/us/blog/threat-insight/screentime-sometimes-it-feels-like-somebodys-watching-me


6¡¢Avast°ä²¼2022ÄêµÚËÄʱ¶ÈÍøÂçÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨

      

2ÔÂ9ÈÕ£¬Avast°ä²¼Á˹ØÓÚ2022ÄêµÚËÄʱ¶ÈÍøÂçÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬¸æ°×Èí¼þ»î¶¯ÔÚ2022ÄêµÚÈý¼¾¶ÈÄ©¼±¾çÉÏÉý£¬²¢³ÖÐøµ½2022ÄêµÚËÄʱ¶È³õ¡£¼ÓÃܿ󹤻ÕûÌåÂÔÓнµÂä(4%)£¬×î³£¼ûµÄΪWeb miners¡¢XMRig¡¢CoinBitMinerºÍVMinerµÈ¡£×î³£¼ûµÄÐÅÏ¢ÇÔÈ¡·¨Ê½Îª£¬FormBook¡¢AgentTesla¡¢RedLineºÍLokibot£¬ÊÜ´ËÀà¶ñÒâÈí¼þÓ°Ïì×î´óµÄ¹ú¶ÈÊÇÒ²ÃÅ¡¢°¢¸»º¹ºÍÂíÀï¡£ÀÕË÷Èí¼þµÄ×ÜÊý½µÂäÁË17%£¬Õ¼±ÈÁ¦´óµÄÊÇSTOP(21%)¡¢WannaCry(20%)ºÍThanatos(2%)¡£


https://decoded.avast.io/threatresearch/avast-q4-2022-threat-report/