ÐÂÀÕË÷ÍÅ»ïRed CryptoAppѡȡ¼¤½øÕ½ÊõÐßÈèÊܺ¦Õß
°ä²¼¹¦·ò 2024-04-074ÔÂ4ÈÕ£¬Netenrich µÄÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÃûΪ Red Ransomware Group (Red CryptoApp) µÄÐÂÀÕË÷×éÖ¯¡£¸Ã×éÖ¯µÄÔË×÷·½Ê½ÓëµäÐ͵ÄÀÕË÷Èí¼þ×éÖ¯·ÖÆç£¬ËûÃǵÄÀÕË÷Õ½ÊõÓÐËù·ÖÆç¡£Óë´óÎÞÊý°µ²ØÆä²Ù×÷µÄÀÕË÷Èí¼þ×éÖ¯·ÖÆç£¬Red CryptoApp ËÆºõ²ÉÈ¡Á˼¤½øµÄ²½Öè¡£¾Ý Netenrich ³Æ£¬¸Ã×éÖ¯³ÉÁ¢ÁË¡°Ðß³Üǽ¡±£¬²¢°ä²¼ÁËËûÃdzɹ¦¶Ô×¼µÄ¹«Ë¾Ãû³Æ¡£ÕâÖÖÕ½ÊõÖ¼ÔÚÐßÈèÊܺ¦Õß²¢ÆÈʹËûÃÇÖ§¸¶Êê½ðÒÔɾ³ýËûÃǵÄÃû×Ö¡£×êÑÐÈËÔ±°ÑÎȵ½¸Ã×é֯׫дµÄÒ»·ÝÀÕË÷Èí¼þ±Ê¼ÇÓë 2020 Äê Maze ÀÕË÷Èí¼þÍÅ»ïÓÐһЩÀàËÆÖ®´¦¡£Õâ¿ÉÄÜÊÇżºÏ£¬Ò²¿ÉÄÜÊÇżºÏ¡£Òò¶ø£¬Éв»Ã÷ÏÔ Red Ransomware Group ÊÇ·ñÊÇ Maze ÍÅ»ïµÄÑÜÉúÆ·£¬Maze ÍÅ»ïÓÚ 2020 Äê 11 Ô¹عØÁËÆäÒµÎñ¡£Red CryptoApp ÀÕË÷Èí¼þÍÅ»ïµÄÐß³Üǽ£¬ÃÀ¹úÊÇÖØÒªÖ¸±ê£¬Æä´ÎÊǵ¤Âó¡¢Ó¡¶È¡¢Î÷°àÑÀ¡¢Òâ´óÀû¡¢ÐÂ¼ÓÆÂºÍ¼ÓÄôóµÈÆäËû¹ú¶È¡£¾ÍÖ¸±êÐÐÒµ¶øÑÔ£¬Èí¼þºÍÔì×÷Òµ³ÉΪ×î³£¼ûµÄÖ¸±êÐÐÒµ£¬½ÌÓý¡¢¹¹Öþ¡¢¾ÆµêºÍ IT ÐÐÒµÒ²Êܵ½¹Ø×¢¡£
https://www.hackread.com/red-ransomware-group-red-cryptoapp-wall-of-shame/?web_view=true
2. CoralRaiderºÚ¿ÍÍÅ»ï¶Ô×¼Õû¸öÑÇÖ޵ĽðÈÚÐÐÒµ
4ÔÂ5ÈÕ£¬Ë¼¿Æ Talos µÄ×êÑÐÈËÔ±·¢ÏÖÁËһϵÁÐÃûΪ CoralRaider µÄºÚ¿Í»î¶¯£¬ÀûÓÃÉøÈë¶ñÒâÈí¼þ¹¥»÷Ó¡¶È¡¢Öйú¡¢º«¹ú¡¢ÃϼÓÀ¹ú¡¢°Í»ù˹̹¡¢Ó¡¶ÈÄáÎ÷ÑǺ͹úÄÚÖ¸±ê¡£Talos ¼«¶ÈÓÐÐÅÄîµØ½«¸Ã×éÖ¯µÄ·¢Ô´¹éÒòÓÚÔ½ÄÏ£¬²¢Ö¸³öºÚ¿ÍÔÚÆä Telegram ºÅÁîºÍ½ÚÔìͨ·ÖÐʹÓÃÔ½ÄÏÓ²¢½«Ô½ÄÏÓïµ¥´ÊÓ²±àÂëµ½ÓÐЧ¸ºÔضþ½øÔìÎļþÖС£ÆäIPµØÖ·¿É×·Òäµ½ºÓÄÚ¡£ºÚ¿ÍʹÓà RotBot£¨Ò»ÖÖ¶¨ÔìµÄÔ¶³Ì½Ó¼û¹¤¾ß£¨ Quasar RATµÄ±äÌ壩£©ÏÂÔØÐÅÏ¢ÇÔÈ¡·¨Ê½£¬¸Ã·¨Ê½»á²éÕÒÔ̺¬Ö§¸¶¿¨µÈÊý¾ÝµÄóÒ×É罻ýÌåÕÊ»§¡£µ±Óû§´ò¿ª¶ñÒâ Windows ¿ì½Ý·½Ê½Îļþʱ£¬CoralRaider ¹¥»÷¾Í»áÆðÍ·£¬´Ó¶ø´¥·¢Ï°È¾Á´¡£ËþÂå˹°µÊ¾£¬Ä¿Ç°Éв»Ã÷ÏÔÍþвÕßÈôºÎ½«Îļþ´«µÝ¸øÊܺ¦Õß¡£¼¤»îµÄLNKÎļþ»áÏÂÔØÒ»¸öHTMLÀûÓ÷¨Ê½Îļþ£¬¸ÃÎļþÖ´ÐÐVirtual Basic¾ç±¾£¬¸Ã¾ç±¾ÓÖÔÚÄÚ´æÖÐÖ´ÐÐPowerShell¾ç±¾¡°½âÃܲ¢°¤´ÎÖ´ÐÐÆäËûÈý¸öPowerShell¾ç±¾£¬ÕâЩ¾ç±¾Ö´Ðз´Ðé¹¹»úºÍ·´·ÖÎö²é³£¬ÈƹýÓû§½Ó¼û½ÚÔì¡¢½ûÓÃÊܺ¦Õß»úеÉ쵀 Windows ºÍÀûÓ÷¨Ê½Í¨Öª£¬×îºóÏÂÔØ²¢ÔËÐÐ RotBot¡£
https://www.govinfosecurity.com/vietnamese-threat-actor-targeting-financial-data-across-asia-a-24796?&web_view=true
3. Ð嵀 Latrodectus ¶ñÒâÈí¼þÈ¡´úÁËÍøÂç·ì϶ÖÐµÄ IcedID
4ÔÂ4ÈÕ£¬Ò»ÖÖÃûΪ Latrodectus µÄÏà¶Ô½ÏеĶñÒâÈí¼þ±»ÒÔΪÊÇ IcedID ¼ÓÔØ·¨Ê½µÄÑݱ䣬¸Ã¼ÓÔØ·¨Ê½×Ô 2023 Äê 11 ÔÂÒÔÀ´Ò»ÏòÔÚ¶ñÒâµç×ÓÓʼþ»î¶¯ÖгöÏÖ¡£ProofpointºÍ Team CymruµÄ×êÑÐÈËÔ±·¢ÏÖÁ˸öñÒâÈí¼þ £¬ËûÃǹ²Í¬¼Í¼ÁËÆäÖ°ÄÜ£¬µ«ÕâЩְÄÜÒÀÈ»²»²»±äÇÒ´¦ÓÚ³¢ÊԽ׶Ρ£IcedID ÊÇÒ»¸öÓÚ 2017 Äê³õ´Î·¢ÏֵĶñÒâÈí¼þ¼Ò×壬×î³õ±»¹éÀàΪģ¿é»¯ÒøÐÐľÂí£¬Ö¼ÔÚ´ÓÊÜϰȾµÄÍÆËã»úÖÐÇÔÈ¡²ÆÕþÐÅÏ¢¡£Ëæ×ʦ·òµÄÍÆÒÆ£¬Ëü±äµÃÔ½·¢¸´ÔÓ£¬Ôö³¤ÁËÌӱܺͺÅÁîÖ´ÐÐÖ°ÄÜ¡£½üÄêÀ´£¬Ëü³äÈÎÁ˼ÓÔØ·¨Ê½µÄ½ÇÉ«£¬Äܹ»½«ÆäËûÀàÐ͵ĶñÒâÈí¼þ£¨Ô̺¬ÀÕË÷Èí¼þ£©´«Ë͵½ÊÜϰȾµÄϵͳÉÏ¡£´Ó 2022 ÄêÆðÍ·£¬¶à¸ö IcedID »î¶¯Õ¹Ê¾ÁË ¶àÑù»¯µÄ´«µÝÕ½Êõ£¬µ«ÖØÒªµÄ·Ö·¢·½Ê½ÒÀÈ»ÊǶñÒâµç×ÓÓʼþ¡£2022 Ëêĺ£¬ ¸Ã¶ñÒâÈí¼þµÄбäÖÖ ±»ÓÃÓÚ¹¥»÷£¬²¢³¢ÊÔÁ˸÷Àà¶ã±Ü¼¼ÇɺÍÐµĹ¥»÷¼¯¡£
https://www.bleepingcomputer.com/news/security/new-latrodectus-malware-replaces-icedid-in-network-breaches/?&web_view=true
4. Visa ÖÒ¸æÕë¶Ô½ðÈÚ»ú¹¹µÄРJSOutProx ¶ñÒâÈí¼þ±äÌå
4ÔÂ4ÈÕ£¬Visa ÖÒ¸æ³Æ£¬Õë¶Ô½ðÈÚ»ú¹¹¼°Æä¿Í»§µÄа汾 JsOutProx ¶ñÒâÈí¼þ¼ì²âÊýÁ¿¼¤Ôö¡£¸Ã»î¶¯Õë¶ÔÄÏÑǺͶ«ÄÏÑÇ¡¢Öж«ºÍ·ÇÖ޵ĽðÈÚ»ú¹¹¡£JsOutProx ÓÚ 2019 Äê 12 Ô³õ´ÎÓöµ½£¬ÊÇÒ»ÖÖÔ¶³Ì½Ó¼ûľÂí (RAT) ºÍ¸ß¶È»ìºÏµÄ JavaScript ºóÃÅ£¬ÔÊÐíÆä²Ù×÷ÕßÔËÐÐ shell ºÅÁî¡¢ÏÂÔØ¶î±íµÄ¸ºÔØ¡¢Ö´ÐÐÎļþ¡¢²¶»ñÆÁÄ»½ØÍ¼¡¢ÔÚÊÜϰȾµÄÉ豸ÉϳÉÁ¢ÓƾÃÐÔ²¢½ÚÔì¼üÅ̺ÍÊó±ê¡£Visa ¾¯±¨ÖÐд·£º¡°¹ÌÈ» PFD ÎÞ·¨È·ÈÏ×î½ü·¢ÏֵĶñÒâÈí¼þ»î¶¯µÄ×îÖÕÖ¸±ê£¬µ«¸ÃÍøÂç·¸×ï×é֮֯ǰ¿ÉÄÜÔøÕë¶Ô½ðÈÚ»ú¹¹½øÐÐڲƻ¡£¡±¸Ã¾¯±¨ÌṩÁËÓë×îлÓйصÄÍ×ÐÖ¸±ê (IoC)£¬²¢½¨Òé²ÉÈ¡¶àÏ½â´ëÊ©£¬Ô̺¬Ìá¸ß¶ÔÍøÂç´¹µö·çÏÕµÄÒâʶ¡¢ÆôÓà EMV ºÍ°²È«½ÓÊܼ¼Êõ¡¢±£»¤Ô¶³Ì½Ó¼ûÒÔ¼°¼à¿Ø¿ÉÒÉÂòÂô¡£
https://www.bleepingcomputer.com/news/security/visa-warns-of-new-jsoutprox-malware-variant-targeting-financial-orgs/?&web_view=true
5. ÎÂÄá²®´óѧÊýǧÃû½ÌÈËÔ±¹¤ºÍѧÉúµÄÃô¸ÐÊý¾Ý±»µÁ
4ÔÂ5ÈÕ£¬¼ÓÄôóÎÂÄá²®´óѧ֤ʵ£¬ºÚ¿ÍÔÚÉϸöÔÂÄ©²úÉúµÄһ·ÊÂÎñÖÐÇÔÈ¡Á˸ûú¹¹µÄÃô¸ÐÐÅÏ¢£¬Ó°ÏìÁËÒÔǰºÍ´Ë¿ÌµÄѧÉúºÍ½ÌÈËÔ±¹¤¡£ÕâËùÕ¼ÓÐ 18,000 ¶àÃûѧÉúºÍ 800 Ãû½ÌÈËÔ±¹¤µÄ´óѧÔÚÖÜËĵÄÒ»·ÝÉêÃ÷ÖаµÊ¾£¬¡°±»µÁµÄÐÅÏ¢¿ÉÄÜÔ̺¬µ±Ç°ºÍÒÔǰµÄѧÉúºÍÔ±¹¤µÄÓ×ÎÒÐÅÏ¢¡£¡¹ØâÆðÍøÂçÊÂÎñÓÚ 3 Ô 25 ÈÕ³õ´Î°ä·¢£¬Æäʱ¸Ã»ú¹¹ÏÂÏßÁËһϵÁзþÎñ¡£¼¸Ììºó£¬¸Ã´óѧÌó¤Íе¡¤Ãɶà¶û²©Ê¿°µÊ¾£¬ÎÂÄá²®Ôâ·êÁË¡°Õë¶Ô´óÑ§ÍøÂçµÄÓÐÕë¶ÔÐÔµÄÍøÂç¹¥»÷¡±¡£¸Ã´óѧ°µÊ¾£¬µ÷²éÔÚ½øÐÐÖУ¬¡°¿ÉÄܱØÒª¹¦·ò£¬¿ÉÄÜÊǼ¸¸öÔ¡±£¬Ä¿Ç°¸Ã´óѧÒÔΪ¹¥»÷Õß¿ÉÄܽӼûÎļþ·þÎñÆ÷¡£¸ÃÍøÂçÊÂÎñµÄÐÔÖÊÉÐδµÃµ½Ö¤Êµ£¬µ«¸Ã´óѧ°µÊ¾¡°ÍµÇÔÊÂÎñºÜ¿ÉÄܲúÉúÔÚ 3 Ô 24 ÈÕ֮ǰµÄÒ»ÖÜ¡£¡±¸Ã´óѧ°µÊ¾£¬½«ÎªÊÜÓ°ÏìµÄÓ×ÎÒÌṩΪÆÚÁ½ÄêµÄÐÅÓþ¼à¿Ø·þÎñ£¬²¢¼¤ÀøËùÓÐÊÜÓ°ÏìµÄÈË×¢²á£¬²¢Ö¸³öËü»¹ÎªËæºó³ÉΪڲÆÕßÖ¸±êµÄÈκÎÈËÌṩ±£ÏÕÌõ¿î¡£
https://therecord.media/university-of-winnipeg-cyberattack
6. ºÚ¿ÍÀûÓà Facebook ¸æ°×ºÍ½Ù³ÖÒ³ÃæÍÆ¹ãÐéαÈËΪÖÇÄÜ·þÎñ
4ÔÂ5ÈÕ£¬ÕâЩ¶ñÒâ¸æ°×»î¶¯ÊÇͨ¹ý½Ù³Ö Facebook Ó×ÎÒ×ÊÁÏ´´½¨µÄ£¬ÕâЩÓ×ÎÒ×ÊÁϼÙÒâÊ¢ÐеÄÈËΪÖÇÄÜ·þÎñ£¬¼Ù×°ÌṩÐÂÖ°ÄܵÄÔ¤ÀÀ¡£±»¸æ°×ºýŪµÄÓû§³ÉΪڲÆÐÔ Facebook ÉçÇøµÄ³ÉÔ±£¬ÍþвÐÐΪÕßÔÚÆäÖа䲼ÐÂÎÅ¡¢ÈËΪÖÇÄÜÌìÉúµÄͼÏñºÍÆäËûÓйØÐÅÏ¢£¬ÒÔÊ¹Ò³Ãæ¿´ÆðÀ´ºÏ·¨¡£È»¶ø£¬ÉçÇøÌû×ÓʱʱÌᳫÏÞʱ½Ó¼û¼´½«ÍƳöÇÒ±¸ÊܵȴýµÄ AI ·þÎñ£¬ÓÕÆÓû§ÏÂÔØ¶ñÒâ¿ÉÖ´ÐÐÎļþ£¬ÕâЩ¿ÉÖ´ÐÐÎļþ»áÀûÓà Rilide¡¢Vidar¡¢IceRAT ºÍ Nova µÈÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þϰȾ Windows ÍÆËã»ú¡£ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þרһÓÚ´ÓÊܺ¦ÕßµÄä¯ÀÀÆ÷ÇÔÈ¡Êý¾Ý£¬Ô̺¬´æ´¢µÄÍ´´¦¡¢cookie¡¢¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡¢×Ô¶¯ÊµÏÖÊý¾ÝºÍÐÅÓþ¿¨ÐÅÏ¢¡£¶øºó£¬ÕâЩÊý¾Ý»áÔÚ°µÍøÊг¡ÉÏÏúÊÛ£¬»ò±»¹¥»÷ÕßÓÃÀ´·ÛËéÖ¸±êµÄÔÚÏßÕÊ»§£¬ÒÔÍÆ½ø½øÒ»²½µÄÚ¿Æ»ò½øÐÐڲơ£Facebook µÈÉ罻ýÌåÍøÂç¹æÄ£ÖØ´ó£¬¼ÓÉϼà¹Ü²»¼°£¬Ê¹µÃÕâЩ»î¶¯¿ÉÄܳ־óÖÐø£¬´Ó¶øÍƽø¶ñÒâÈí¼þ²»ÊܽÚÔìµÄ´«²¼£¬´Ó¶øµ¼Ö¶ñÒâÈí¼þϰȾÔì³É¿í·ºÇÖº¦¡£
https://www.bleepingcomputer.com/news/security/fake-facebook-midjourney-ai-page-promoted-malware-to-12-million-people/


¾©¹«Íø°²±¸11010802024551ºÅ