×êÑÐÈËÔ±Åû¶ÀûÓÃBiBi-Linux¹¥»÷ÒÔÉ«ÁÐµÄÆóÒµµÄ»î¶¯
°ä²¼¹¦·ò 2023-11-011¡¢×êÑÐÈËÔ±Åû¶ÀûÓÃBiBi-Linux¹¥»÷ÒÔÉ«ÁÐµÄÆóÒµµÄ»î¶¯
¾ÝýÌå10ÔÂ30ÈÕ±¨Â·£¬Ò»ÖÖÃûΪBiBi-LinuxµÄÐÂÐÍWiper¶ñÒâÈí¼þÔÚ±»ÓÃÓÚÕë¶ÔÒÔÉ«ÁеĹ«Ë¾µÄ¹¥»÷»î¶¯¡£¸Ã¶ñÒâÈí¼þÊÇx64 ELF¿ÉÖ´ÐÐÎļþ£¬Ã»ÓлìºÏµÈ±£»¤´ëÊ©£¬Õâʹ×êÑÐÈËÔ±µÄ·ÖÎö¹ý³Ì±äµÃÔ½·¢ÈÝÒס£Ëü¿ÉÖ¸¶¨Ö¸±êÎļþ¼Ð£¬ÈôÊÇÒÔrootȨÏÞÔËÐÐÔò¿ÉÄÜ»áÏú»ÙÕû¸öϵͳ¡£BiBi-Linux»¹Ê¹ÓöàÏ̺߳ͶÓÁÐϵͳÀ´Ìá¸ß¿ìÂʺÍЧÄÜ¡£VirusTotal³Æ£¬Ä¿Ç°£¬Ö»ÓÐÁ½¼Íâ²È«¹©¸øÉ̵ĶñÒâÈí¼þɨÃèÒýÇæ½«BiBi-Linux¼ì²âΪ¶ñÒâÈí¼þ¡£
https://www.bleepingcomputer.com/news/security/new-bibi-linux-wiper-malware-targets-israeli-orgs-in-destructive-attacks/
2¡¢Unit 42·¢ÏÖÀûÓÃIAMƾ֤µÄ¼ÓÃܽٳֹ¥»÷EleKtra-Leak
Unit 42ÔÚ10ÔÂ30ÈÕ³ÆÆä·¢ÏÖÁËÐµĹ¥»÷»î¶¯EleKtra-Leak£¬¿É×Ô¶¯¶¨Î»¹«¿ªGitHub´æ´¢¿âÖж³öµÄÉí·ÝºÍ½Ó¼ûÖÎÀí(IAM)ƾ֤£¬Ö¼ÔÚ½øÐмÓÃÜÇ®±Ò½Ù³Ö»î¶¯¡£¸Ã»î¶¯ÖÁÉÙ×Ô2020Äê12Ô¾ÍÒ»Ïò»îÔ¾£¬²¢ÓÚ½ñÄê8ÔÂ30ÈÕÖÁ10ÔÂ6ÈÕ´Ó¶à´ï474¸öAmazon EC2Ê·ýÖÐÍÚ¾òÃÅÂÞ±Ò¡£´Ë±í£¬¹¥»÷Õß¿ÉÄÜÔÚIAMƾ֤³õ´Î¶³öµÄÎå·ÖÖÓÄھͼì²â²¢ÀûÓÃËü£¬»¹»á°Ñ¹«¿ªIAMƾ֤µÄAWSÕË»§ÁÐÈëºÚÃûµ¥¡£
https://unit42.paloaltonetworks.com/malicious-operations-of-exposed-iam-keys-cryptojacking/
3¡¢eSentireÑÝʾ½«Ö¸±ê³Á¶¨Ïòµ½¶ñÒâÍøÕ¾µÄWiki-Slack¹¥»÷
¾Ý10ÔÂ30ÈÕ±¨Â·£¬eSentire×êÑÐÈËÔ±Éè¼ÆÁËÒ»ÖÖеÄWiki-Slack¹¥»÷£¬¿É½«×¨ÒµÈËÊ¿³Á¶¨Ïòµ½¶ñÒâÍøÕ¾¡£¹¥»÷ÕßÊ×ÏÈÑ¡ÔñÒ»¸öWikipediaÖ÷Ì⣬¶øºó½øÈëÌõ¿î±êÊ×Ò³²¢±à×ëÒ³Ãæ£¬Ôö³¤Ò»¸öºÏ·¨µÄ²Î¿¼½Å×¢¡£ÔÚSlackÉÏ·ÖÏíÎÄÕÂʱ£¬Ò»µ©Âú×ãijЩ¸½¼ÓǰÌᣬSlack½«³Ê´Ë¿ÌÔʼWikipediaÖв»Ë½¼ûµÄÁ´½Ó¡£Òò¶ø£¬×¨ÒµÈËÊ¿½«WikipediaÌõ¿î¸´Ôìµ½Slackʱ¾Í»á³öÏÖ¶ñÒâÁ´½Ó£¬ÈôÊÇÁ´½ÓµÄÓï·¨Éè¼ÆµÃ×ã¹»ºÃ£¬SlackÓû§¾Í»á±»ÎüÒý²¢µã»÷Ëü£¬´Ó¶ø±»³Á¶¨Ïòµ½¶ñÒâÍøÕ¾£¬ÆäÖпÉÄÜÓлùÓÚä¯ÀÀÆ÷µÄ¶ñÒâÈí¼þ¡£
https://securityaffairs.com/153245/hacking/wiki-slack-attack.html
4¡¢WiHDÅäÖÃÃýÎóй¶½ü10ÍòtorrentÓû§µÄ¾ßÌåÐÅÏ¢
ýÌå10ÔÂ31Èճƣ¬World-in-HD(WiHD)ÅäÖÃÃýÎó£¬Ð¹Â¶ÁË97327¸öÓû§µÄ¾ßÌåÐÅÏ¢¡£WiHDÊÇÒ»¿îÊ¢ÐеĸöÈËÖÖ×Ó¸ú×Ù·¨Ê½£¬×¢²áÓû§Äܹ»½Ó¼û·¨ÓïºÍÓ¢ÓïµÄµçÊӾ硢µçÓ°¡¢¶¯»µÈÄÚÈÝ¡£¸Ã¸öÈ˸ú×Ù·¨Ê½Í¨³£½ö½ÓÊÜÔ¼Ç룬һЩÈËÒÔ³¬¹ý100ÃÀÔªµÄ¼ÛÖµÏúÊÛ¸ÃÍøÕ¾µÄÔ¼Çë¡£Cybernews·¢ÏÖÁËWiHDµÄÒ»¸ö¹«¿ªµÄElasticsearch£¬Ã»ÓÐÈκÎÃÜÂë±£»¤£¬Ð¹Â¶ÁËÓû§µç×ÓÓʼþ¡¢IPµØÖ·¡¢·þÎñÐÅÏ¢¡¢Óû§ÃûºÍËùÓÐtorrentÓû§µÄÃÜÂë¡£
https://securityaffairs.com/153296/deep-web/wihd-data-leak.html
5¡¢SlashNext°ä²¼2023ÄêÍøÂç´¹µöÌ¬ÊÆµÄ·ÖÎö»ã±¨
10ÔÂ30ÈÕ±¨Â·³Æ£¬SlashNext°ä²¼ÁË2023ÄêÍøÂç´¹µöÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨¶Ô2022ÄêQ4ÖÁ2023ÄêQ3µÄ12¸öÔÂÄÚͨ¹ýµç×ÓÓʼþ¡¢Òƶ¯É豸ºÍä¯ÀÀÆ÷¹Û²ìµ½µÄ¹¥»÷»î¶¯½øÐÐÁË·ÖÎö¡£È¥ÄêQ4ÒÔÀ´£¬´¹µöµç×ÓÓʼþ¼¤ÔöÁË1265%£¬Æ¾Ö¤ÍøÂç´¹µö¹¥»÷Ôö³¤ÁË967%¡£×ÔChatGPTÍÆ³öÒÔÀ´£¬µç×ÓÓʼþ´¹µö´ó·ùÔö³¤¡£ÆäËü³ÁÒªµÄ·¢ÏÖÔ̺¬£¬¾ùÔÈÿÌì31000´Î´¹µö¹¥»÷£¬ÆäÖÐ68%±»¼ø±ðΪ»ùÓÚÎı¾µÄBEC¡£77%µÄרҵÈËÊ¿Ôø³ÉΪ´¹µö¹¥»÷µÄÖ¸±ê£¬ÆäÖÐ28%µÄ¹¥»÷ÊÇͨ¹ý¶ÌÐŽøÐеġ£
https://slashnext.com/state-of-phishing-2023/
6¡¢Fortinet°ä²¼¹ØÓÚÀÕË÷Èí¼þKnightµÄ×ÛÊö»ã±¨
10ÔÂ30ÈÕ£¬Fortinet°ä²¼Á˹ØÓÚÀÕË÷Èí¼þKnightµÄ×ÛÊö»ã±¨¡£KnightÊÇÒ»¸öÏà¶Ô½ÏеÄÀÕË÷ÍŻÓÚ½ñÄê8Ô³öÏÖ¡£KnightµÄǰÉíCyclopsÕ¼ÓкÏÓÃÓÚWindows¡¢LinuxºÍMac OSµÄ¶àϵͳ¹¤¾ß¡£Òò¶ø£¬¹ÌÈ»×êÑÐÈËÔ±½ö·¢ÏÖÁËKnightµÄWindows°æ±¾£¬µ«ÆäËû°æ±¾¿ÉÄÜÔÚ³öÏÖ¡£KnightÕë¶Ô¶à¸ö´¹Ö±ÐÐÒµ£¬ÆäÖÐÁãÊÛÐÐÒµÊÜÓ°Ïì×î´ó¡£°´µØÓò·ÖÀ࣬ÃÀ¹úÔâµ½µÄKnight¹¥»÷×î¶à¡£
https://www.fortinet.com/blog/threat-research/ransomware-roundup-knight


¾©¹«Íø°²±¸11010802024551ºÅ