ÈÕ±¾ÓîÖæº½¿Õ×êÑпª·¢»ú¹¹JAXAµÄAD·þÎñÆ÷Ôâµ½¹¥»÷
°ä²¼¹¦·ò 2023-12-01¾ÝýÌå11ÔÂ29ÈÕ±¨Â·£¬ÈÕ±¾ÓîÖæº½¿Õ×êÑпª·¢»ú¹¹(JAXA)Ôâµ½ÁËÍøÂç¹¥»÷¡£JAXAûÓÐй©¹¥»÷²úÉúµÄ¾ßÌ幦·ò£¬ÓÐÐÂÎÅÈËʿй©²úÉúÓÚÏᄀ£µ«Ö±µ½Çï¼¾µ±·¨Âɲ¿ÃÅÁªÏµËûÃÇʱ£¬ËûÃDzÅÒâʶµ½Õâ´Î¹¥»÷¡£¾ÝϤ£¬¹¥»÷Õß»ñµÃÁ˶Ըûú¹¹Active Directory (AD)·þÎñÆ÷µÄ½Ó¼ûȨÏÞ£¬¸Ã·þÎñÆ÷ÊǼලJAXAÍøÂçÔËÓªµÄ³ÁÒª×é¼þ£¬ÖÎÀíÔ±¹¤IDºÍÃÜÂëÒÔ¼°²é¿´È¨ÏÞµÈÐÅÏ¢¡£Ö»¹ÜÉÐδ֤ʵ´æÔÚÊý¾Ýй¶£¬µ«JAXA¹¤×÷ÈËÔ±°µÊ¾£¬Ö»ÓÐAD·þÎñÆ÷±»¹¥»÷£¬¾ÍºÜÓпÉÄÜ¿´µ½´ó²¿ÃÅÐÅÏ¢£¬ÕâÖÖÇé¿ö¼«¶ÈÑϳÁ¡£
https://therecord.media/japan-space-agency-cyberattack
2¡¢Apple°ä²¼´¹Î£°²È«¸üн¨¸´Á½¸öÒѱ»ÀûÓõķì϶
AppleÔÚ11ÔÂ30ÈÕ°ä²¼ÁË´¹Î£°²È«¸üУ¬½¨¸´iPhone¡¢iPadºÍMacÖÐÁ½¸öÒѱ»ÀûÓõķì϶¡£ÕâÁ½¸ö·ì϶¶¼ÊÇÔÚWebKitä¯ÀÀÆ÷ÒýÇæÖз¢Ïֵģ¬Apple»ñϤ·ì϶¿ÉÄÜÒÑÔÚiOS 16.7.1֮ǰµÄiOS°æ±¾Öб»ÀûÓᣵÚÒ»¸öÊÇÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2023-42916£©£¬¿ÉÓÃÀ´½Ó¼ûÃô¸ÐÐÅÏ¢¡£µÚ¶þ¸öÊÇÄÚ´æ°Ü»µ·ì϶£¨CVE-2023-42917£©£¬¿ÉÄܵ¼ÖÂËÁÒâ´úÂëµÄÖ´ÐС£¸Ã¹«Ë¾ÉÐδ°ä²¼ÓйØÔÚÒ°ÀûÓù¥»÷µÄÐÅÏ¢¡£×Ô½ñÄêËêÊ×ÒÔÀ´£¬AppleÒѾ½¨¸´ÁË20¸öÁãÈÕ·ì϶¡£
https://securityaffairs.com/155026/security/apple-emergency-security-updates-2-zero-day.html
3¡¢Â׶ذ®µÂ»ªÆßÊÀ¹úÍõÒ½ÔºÔâµ½RhysidaµÄÀÕË÷¹¥»÷
¾Ý11ÔÂ30ÈÕ±¨Â·£¬ÀÕË÷ÍÅ»ïRhysidaÐû³ÆÈëÇÖÁËÂ׶ذ®µÂ»ªÆßÊÀ¹úÍõÒ½Ôº¡£¸ÃÍÅ»ï°ä²¼Á˱»µÁÎļþµÄͼƬ×÷Ϊ֤¾Ý£¬Ô̺¬Ò½Áƻ㱨¡¢µÇ¼Ç±í¡¢X¹âƬ¡¢Ò½ÁÆ´¦·½ºÍÒ½Áƻ㱨µÈ£¬»¹³ÆÇÔÈ¡ÁËÔ̺¬Ó¢¹ú»ÊÊÒÔÚÄڵĴóÁ¿»¼ÕߺÍÔ±¹¤µÄÐÅÏ¢¡£¹¥»÷ÕßÒÔ10 BTCµÄ¼ÛÖµÅÄÂôÇÔÈ¡µÄ´óÁ¿¡°Ãô¸ÐÊý¾Ý¡±¡£ÓëÆ½·²Ò»Ñù£¬Ëü´òË㽫Êý¾ÝÏúÊÛ¸øÎ¨Ò»µÄÂò¼Ò£¬²¢½«ÔÚ²¼¸æ°ä²¼ºóµÄÆßÌìÄÚ¹«¿ª°ä²¼ÕâЩÊý¾Ý¡£
https://securityaffairs.com/154999/cyber-crime/rhysida-ransomware-king-edward-viis-hospital.html
4¡¢Black Basta×Ô³õ´Î±»·¢ÏÖÒÔÀ´ÒÑÀÕË÷³¬¹ý1ÒÚÃÀÔª
EllipticºÍCorvus InsuranceÔÚ11ÔÂ29ÈÕ°ä²¼µÄ½áºÏ×êÑÐÏÔʾ£¬Black BastaÒÑÀÕË÷³¬¹ý1ÒÚÃÀÔª¡£Black BastaϰȾÁ˳¬¹ý329¸öÖ¸±ê£¬ÆäÖÐÔ̺¬Capita¡¢ABBºÍDish Network¡£·ÖÎöÅú×¢£¬×Ô2022ËêÊ×ÒÔÀ´£¬Black BastaÒÑÊÕµ½ÖÁÉÙ1.07ÒÚÃÀÔªÊê½ð£¬Éæ¼°90¸ö±»¹¥»÷Õß¡£ÆäÖÐ×î´óÒ»±ÊÊê½ðµÄ½ð¶îΪ900ÍòÃÀÔª£¬ÖÁÉÙ18±ÊÊê½ð³¬¹ý100ÍòÃÀÔª£¬¾ùÔÈÊê½ð½ð¶îΪ120ÍòÃÀÔª¡£½ØÖÁ2023ÄêQ3 Black BastaÍøÕ¾ÉÏÁгöµÄ±»¹¥»÷Ö¸±êÊýÁ¿£¬ÖÁÉÙÓÐ35%½»ÁËÊê½ð¡£
https://www.corvusinsurance.com/blog/black-basta-ransomware-has-extracted-over-100-million-from-its-victims
5¡¢AhnLabÅû¶KimsukyÕë¶Ôº«¹ú×êÑлú¹¹µÄ¹¥»÷»î¶¯
11ÔÂ30ÈÕ£¬AhnLabÅû¶Á˽üÆÚKimsukyÕë¶Ôº«¹ú×êÑлú¹¹µÄ¹¥»÷»î¶¯¡£¹¥»÷Õßͨ¹ý¼Ù×°³É½ø¿Ú±¨¹Øµ¥À´·Ö·¢¶ñÒâJSEÎļþ£¬¸ÃÎļþÔ̺¬Ò»¸ö»ìºÏµÄPowerShell¾ç±¾¡¢Ò»¸öBase64±àÂëµÄºóÃÅÎļþºÍÒ»¸öºÏ·¨µÄPDFÎļþ¡£PDFÎļþÃûΪ¡°µ¼ÈëÉêÃ÷.PDF¡±£¬ÓÉPowerShell¾ç±¾×Ô¶¯Ö´ÐУ¬Ö¼ÔÚÔ¤·ÀÓû§·¢ÏÖ¹ý³ÌÖÐÔÚÖ´ÐеĶñÒâºóÃÅÎļþ¡£ÎªÁËÇÔȡϵͳÐÅÏ¢£¬ºóÃÅʹÓÃwmicºÅÁî²é³Ö¸±êµÄɱ¶¾Èí¼þ״̬£¬²¢Í¨¹ýipconfigºÅÁîÍøÂçÍøÂçÐÅÏ¢¡£
https://asec.ahnlab.com/en/59387/
6¡¢Symantec°ä²¼¼äµýÈí¼þÀûÓø÷À༼ÊõÈÆ¹ý¶ÈÎöµÄ»ã±¨
11ÔÂ29ÈÕ£¬Symantec°ä²¼Á˼äµýÈí¼þÀûÓø÷Àà»ìºÏ¼¼ÊõÀ´Èƹý¾²Ì¬·ÖÎöµÄ»ã±¨¡£×î½ü£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸ö¼äµýÈí¼þ¼¯Èº£¬Ñ¡È¡ÁËһϵÁм¼ÊõÀ´Ôö³¤¾²Ì¬·ÖÎöµÄÄѶȡ£ÆäÖÐÔ̺¬×ÊÔ´¼Ù×°£¬ÔÚAPKÖд´½¨Óë³ÁÒª×ÊÔ´Ãû³ÆºÍȨÏÞÒ»ÑùµÄĿ¼£»Ñ¹ËõºýŪ£¬Í¨¹ý²»ÊÜÖ§³ÖµÄѹËõ²½ÖèÀ´°µ²ØAPKÖеĹؼü×ÊÔ´£»Í¨¹ý'ÎÞѹËõ'Êý¾Ý¶ã±ÜÊðÃû¹æ»®£»×ÊÔ´»ìºÏ£¬¾¹ý"»ìºÏ"µÄAndroidManifest.xmlºÍresources.arscÎļþ»á·ÛËéÄæÏò¹¤³Ì¹¤¾ß£»ÒÔ¼°¼Ù×°³ÉÓÎÏ·¡¢ÀûÓ÷¨Ê½ºÍϵͳÀûÓõȡ£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/spyware-obfuscation-static-analysis


¾©¹«Íø°²±¸11010802024551ºÅ