D-Linkй©ÆäÔ±¹¤Ôâµ½´¹µö¹¥»÷µ¼Ö²¿ÃÅÐÅϢй¶
°ä²¼¹¦·ò 2023-10-191¡¢D-Linkй©ÆäÔ±¹¤Ôâµ½´¹µö¹¥»÷µ¼Ö²¿ÃÅÐÅϢй¶
¾ÝýÌå10ÔÂ17ÈÕ±¨Â·£¬Öйų́ÍåÍøÂçÉ豸Ôì×÷ÉÌD-Linkй©´¹µö¹¥»÷µ¼ÖµÄÊý¾Ýй¶ÊÂÎñ¡£±¾Ô³õ£¬ºÚ¿ÍÔÚBreachForumsÒÔ500ÃÀÔªµÄ¼ÛÖµÏúÊÛD-LinkµÄD-ViewÍøÂçÖÎÀíÈí¼þµÄÔ´´úÂ룬ÒÔ¼°Êý°ÙÍòÌõ¿Í»§ºÍÔ±¹¤µÄ¼Í¼£¬ÆäÖÐÔ̺¬¸Ã¹«Ë¾Ê×ϯִÐйٵľßÌåÐÅÏ¢¡£»¹ÌṩÁË45±Ê¼Í¼×÷ΪÑù±¾£¬¹¦·ò´ÁÔÚ2012ÄêÖÁ2013ÄêÖ®¼ä¡£D-Link°µÊ¾£¬¸ÃÊÂÎñÔ´ÓÚÒ»ÃûÔ±¹¤Ôâµ½´¹µö¹¥»÷£¬¹¥»÷Õß½Ó¼ûÁËÆäËùνµÄ¡°²âÊÔ³¢ÊÔÊÒ»·¾³¡±ÄڵIJúÆ·×¢²áϵͳ£¬¸ÃϵͳÊÇÔÚ2015Ä걨·ÏµÄD-View 6ϵͳÉÏÔËÐеġ£ÇÒ¸ÃϵͳֻÔ̺¬Ô¼Äª700±Ê¼Í¼£¬ÕâЩ¼Í¼ÒÑÏÐÖÃÁËÆßÄê¡£
https://www.bleepingcomputer.com/news/security/d-link-confirms-data-breach-after-employee-phishing-attack/
2¡¢ÖÇÀûº£¹Ø×ÜÊð²¿ÃÅ»ù´¡ÉèʩϰȾÀÕË÷Èí¼þBlack Basta
10ÔÂ18ÈÕ±¨Â·³Æ£¬ÖÇÀûº£¹Ø×ÜÊðµÄ²¿ÃÅ»ù´¡ÉèʩϰȾÁËÀÕË÷Èí¼þBlack Basta¡£ÖÇÀû¹ú¶È·þÎñ¾Ö°µÊ¾£¬ÔÚ¼ì²âµ½°²È«ÊÂÎñºóµ±¼´²ÉÈ¡ÁËÏìÓ¦´ëÊ©¡£¸Ã¹úÍÆËã»ú°²È«ÊÂÎñÏìÓ¦Ó××é(CSIRT)µ÷²éÈ·ÈÏ£¬ÕâÊÇÒ»´ÎÀÕË÷¹¥»÷£¬²¢Ö¸³ö¸ÃÊÂÎñÉæ¼°Black BastaÍŻCSIRTÌáÐÑÖÇÀûËùÓÐÈ·µ±¾Ö»ú¹¹£¬ÀÕË÷Èí¼þÊÇÔÚ¹ú¶Èº£¹Ø×ÜÊðµÄ²¿ÃÅ»ù´¡ÉèÊ©Öз¢Ïֵ쬲¢¶½´ÙËûÃDzé³×Ô¼ºµÄϵͳÒÔÕмܽøÒ»²½µÄ¹¥»÷¡£
https://therecord.media/chile-black-basta-ransomware-attack-customs-department
3¡¢ÃÀ¹úÂÞ¿ËÏØÔâµ½CubaµÄÀÕË÷¹¥»÷»Ø¾ø½»190ÍòÃÀÔªÊê½ð
¾Ý10ÔÂ18ÈÕ±¨Â·£¬ÃÀ¹úÍþ˹¿µÐÇÖÝÂÞ¿ËÏØÔÚ9Ô·ÝÔâµ½ÁËÀÕË÷ÍÅ»ïCubaµÄ¹¥»÷¡£¸ÃÏØ¹ÙÔ±³Æ£¬Ã»ÓÐÈËÔ¸Ò⼤Àø·¸×ï״Ϊ£¬Òò¶øËûÃǻؾøÁ˺ڿÍÖ§¸¶190ÍòÃÀÔªÒÔ½âËø±»¼ÓÃÜÎļþµÄÒªÇó¡£Ä¿Ç°£¬¸ÃÏØËùÓйؼüϵͳ¶¼ÒѸ´ÔÔËÐУ¬¶øÒ»Ð©²»Ì«³ÁÒªµÄϵͳÈÔÔÚ½¨¸´ÖС£³ýÁ˼ÓÃÜÊý¾ÝÖ®±í£¬¹¥»÷Õß»¹´Ó²¿ÃÅϵͳÖÐɾ³ýÁËÎļþ¡£µ«ÊÇÐÒÔ˵ÄÊÇ£¬Ïص±¾ÖÔ±¹¤µÄÃô¸ÐÓ×ÎÒÐÅÏ¢²¢Ã»Óб»Ð¹Â¶¡£
https://www.databreaches.net/cuba-ransomware-gang-demands-1-9-million-for-decryption-key-rock-county-refuses/
4¡¢SpyNote¼ÙÒâÒâ´óÀû¹Ù·½¾¯±¨·þÎñIT-alertÀ´´«²¼
ýÌå10ÔÂ17Èճƣ¬D3Lab·¢ÏÖÁ˼ÙÒâIT-alertµÄÍøÕ¾£¬Ö¼ÔÚ´«²¼¼äµýÈí¼þSpyNote¡£IT-alertÊÇÒâ´óÀûµ±¾ÖÔËÓªµÄÒ»Ï¹²·þÎñ£¬ÓÃÓÚÔÚ¼´½«²úÉú»òÔÚ²úÉúµÄ¿àÄÑÆÚ¼äÏòÃñ¶àÌṩ´¹Î£¾¯±¨ºÍÁìµ¼¡£ÈôÊÇÔÚiOSÉ豸µã»÷ÏÂÔØ£¬Óû§»á±»³Á¶¨Ïòµ½ÕæÕýµÄIT-alertÍøÕ¾£¬µ«AndroidÓû§µã»÷ÏÂÔØ»á»ñµÃIT-Alert.apk¡£¸ÃAPKÎļþ»á×°ÖÃSpyNote£¬¸Ã¶ñÒâÈí¼þ»áÔÚÓû§´ò¿ªÒøÐÓ×¢¼ÓÃÜÇ®±ÒÇ®°üºÍÉ罻ýÌåÀûÓÃʱÇÔȡʹ´¦£¬Ò²ÓµÓÐÉãÏñͷ¼Ôì¡¢GPSºÍÍøÂçµØÎ»¸ú×Ù¡¢¼üÅ̼ͼ¡¢ÆÁÄ»½ØÍ¼ºÍµç»°¹àÒôµÈÖ°ÄÜ¡£
https://www.d3lab.net/malware-veicolato-tramite-falso-sito-di-it-alert/
5¡¢×êÑÐÈËÔ±¼ì²âµ½ÒÔNotepad++Ϊµö¶üµÄ¶ñÒâGoogle¸æ°×
MalwarebytesÔÚ10ÔÂ16ÈÕÅû¶ÁËÐÂÒ»ÂÖGoogle¶ñÒâ¸æ°×»î¶¯£¬Õë¶ÔÏëÒªÏÂÔØNotepad++µÄÓû§¡£¸Ã»î¶¯ÒѾ½øÐÐÁ˼¸¸öÔ£¬µ«ÓÉÓÚѡȡÁ˸´Ôӵļ¼ÊõÀ´Èƹý¼ì²âºÍ·ÖÎö£¬Ò»Ïòû±»·¢ÏÖ¡£¸Ã»î¶¯Ðû´«µÄURLÓëÈí¼þÎ޹أ¬µ«È´ÔÚGoogleËÑË÷Á˾ָæ°×ÖÐʹÓÃÁËÎóµ¼ÐÔ±êÌâÓÕÆÖ¸±ê¡£Ö¸±êµã»÷¸æ°×ºó»á±»²é³IP£¬¶øºó³Á¶¨Ïòµ½¼ÙÒâNotepad++µÄÍøÕ¾¡£Ö¸±êµã»÷¶ñÒâÍøÕ¾µÄÁ´½Óʱ£¬»á½øÐеڶþ´Î²é³²¢ÏÂÔØÒ»¸öHTA¾ç±¾¡£Õâ´Î²¶»ñµÄ.htaÎļþ²¢Î´ÆëÈ«±øÆ÷»¯£¬µ«·ÖÎöÈËÔ±ÔÚ7Ô·ÝÉÏ´«µÄVirusTotalÖз¢ÏÖÁËÒ»ÑùµÄÎļþ¡£
https://www.malwarebytes.com/blog/threat-intelligence/2023/10/the-forgotten-malvertising-campaign
6¡¢Kaspersky°ä²¼2023ÄêµÚÈý¼¾¶ÈAPTÌ¬ÊÆµÄ·ÖÎö»ã±¨
10ÔÂ17ÈÕ£¬Kaspersky°ä²¼ÁË2023ÄêµÚÈý¼¾¶ÈAPTÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£±¾¼¾¶ÈµÄÁÁµãÔ̺¬Í¨¹ýÈëÇÖÌØ¶¨ÀàÐ͵ݲȫUSBÇý¶¯Æ÷¶ÔÑÇÌ«µØÓòµÐÔÖʵÌåµÄ¹¥»÷£¬ÒÔ¼°BlindEagleÔÚÀ¶¡ÃÀÖ޵Ļ£¬ºóÕßÇ¿µ÷Á˲¢·ÇËùÓгɹ¦µÄAPT¹¥»÷¶¼±ØÒª¸´Ôӵļ¼Êõ¡£³ÉÊìµÄ¹¥»÷Õ߻᲻ÐݼÓÇ¿Æä¹¤¾ß¼¯£¬±¾¼¾¶È³öÏÖÁËScarCruftµÄ¶à¼¶Ï°È¾Á´¡¢BlindEagleµÄÂ½ÐøRATÒÔ¼°MuddyWater¶ÔVPNÀûÓ÷¨Ê½µÄ¼ÙÒâ¡£±¾¼¾¶È»¹Ð·¢ÏÖÁËBadRoryµÄ»î¶¯¡£
https://securelist.com/apt-trends-report-q3-2023/110752/


¾©¹«Íø°²±¸11010802024551ºÅ