¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.04.05-2021.04.11£©
2021-04-12
Ò»¡¢ ÈÈÃÅ×ÊѶ
1. ¹¤ÐŲ¿×ª´ïϼÜ60¿îËðº¦Óû§È¨ÒæAPP
¡¾¸ÅÊö¡¿
2021Äê3ÔÂ11ÈÕ£¬¹¤ÐŲ¿ÏòÉç»áת´ïÁË136¼Ò±£´æËðº¦Óû§È¨ÒæÐÐΪAPPÆóÒµµÄÃûµ¥¡£×èÖ¹ÏÖÔÚ£¬¾µÚÈý·½¼ì²â»ú¹¹ºË²é¸´¼ì£¬ÉÐÓÐ53¿îAPPδƾ֤ҪÇóÍê³ÉÕû¸Ä¡£ÒÀ¾Ý¡¶ÍøÂçÇå¾²·¨¡·ºÍ¡¶Òƶ¯ÖÇÄÜÖÕ¶ËÓ¦ÓÃÈí¼þÔ¤Öúͷַ¢ÖÎÀíÔÝÐл®¶¨¡·£¨¹¤ÐŲ¿ÐŹܡ²2016¡³407ºÅ£©µÈÖ´·¨ºÍ¹æ·¶ÐÔÎļþÒªÇ󣬹¤ÐŲ¿×éÖ¯¶Ô60¿îAPP¾ÙÐÐϼܡ£
¡¾²Î¿¼Á´½Ó¡¿
https://mp.weixin.qq.com/s/iL_KTArq_TcSMBKODHSypA
2. Cycldek×éÖ¯Õë¶ÔÔ½ÄÏÕþ¸®ºÍ¾ü¶ÓµÄ¹¥»÷Ô˶¯
¡¾¸ÅÊö¡¿
Cycldek£¨ÓÖÃû Lucky Mouse¡¢APT27¡¢Goblin PandaºÍConimes£©ÊÇÒ»¸ö×Ô2013ÄêÒÔÀ´Ò»Ö±ºÜ»îÔ¾¡¢²¢ÓëÖйúÓйصÄÍþв×éÖ¯¡£Cycldek×éÖ¯ÕýÔÚʹÓÃFoundCore ¶ñÒâÈí¼þ¼àÊÓÔ½ÄÏÕþ¸®ºÍ¾ü¶Ó£¬FoundCoreʹ¹¥»÷ÕßÄܹ»Ö´ÐÐÎļþϵͳʹÓᢲ¶»ñÆÁÄ»½ØÍ¼¡¢´¦Öóͷ£Ê¹ÓÃÒÔ¼°Ö´ÐÐí§ÒâÏÂÁî¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securelist.com/the-leap-of-a-cycldek-related-threat-actor/101243/
3. WatchDogʵÑé¼ÓÃÜÐ®ÖÆÔ˶¯ÒÑÓÐÁ½Äê
¡¾¸ÅÊö¡¿
WatchDogÍÚ¿óÐ®ÖÆ×Ô2019Äê1ÔÂ27ÈÕÒÔÀ´Ò»Ö±ÔÚÔËÐУ¬ÏÖÔÚÒÑÍøÂçÖÁÉÙ209¸öÃÅÂÞ±Ò£¨ÃÅÂÞ±Ò£©£¬¼ÛÖµÔ¼32056ÃÀÔª£¬ÒÑÖª±£´æµÄ×î´ó¡¢Ò»Á¬Ê±¼ä×µÄÃÅÂÞ±Ò¼ÓÃÜÐ®ÖÆÔ˶¯¡£Í¬Ê±£¬ÖÁÉÙÓÐ476¸öÖ÷ÒªÓÉWindowsºÍNIXÔÆÊµÀý×é³ÉµÄ±»ÆÆËðµÄϵͳÔÚÈκÎʱ¼ä¶¼ÔÚ¾ÙÐÐÍÚ¾ò²Ù×÷£¬Ê±¼äÁè¼ÝÁËÁ½Äê¡£
¡¾²Î¿¼Á´½Ó¡¿
https://unit42.paloaltonetworks.com/watchdog-cryptojacking/
4. Õë¶Ô°ÍÎ÷µÄÒøÐÐľÂíJaneleiro
¡¾¸ÅÊö¡¿
ÒøÐÐľÂíJaneleiro½üÆÚ½Ï»îÔ¾£¬JaneleiroľÂí×Ô2019ÄêÒÔÀ´Ò»Ö±Ãé×¼°ÍÎ÷µÄÆóÒµÓû§£¬Éæ¼°¶à¸ö±ÊÖ±ÁìÓò£¬Éæ¼°¹¤³Ì¡¢Ò½ÁƱ£½¡¡¢ÁãÊÛ¡¢ÖÆÔìÒµ¡¢½ðÈÚ¡¢ÔËÊäºÍÕþ¸®µÈÁìÓò¡£JaneleiroľÂíÔÚ¹¥»÷Ô˶¯ÖÐÊÔͼͨ¹ýµ¯³ö´°¿ÚÀ´ÓÕÆÊܺ¦Õߣ¬ÕâЩµ¯³ö´°¿ÚµÄÍâ¹ÛÀàËÆÓÚ°ÍÎ÷һЩ´óÐÍÒøÐеÄÍøÕ¾£¬µ¯³ö´°¿Ú°üÀ¨Î±ÔìµÄ±í¸ñ£¬Ö¼ÔÚÓÕʹ¶ñÒâÈí¼þµÄÊܺ¦ÕßÊäÈëÒøÐÐÆ¾Ö¤ºÍСÎÒ˽¼ÒÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.welivesecurity.com/2021/04/06/janeleiro-time-traveler-new-old-banking-trojan-brazil/
5. ºÚ¿ÍʹÓÃFortinet VPNÖеÄÒªº¦Îó²î
¡¾¸ÅÊö¡¿
¸ß¼¶Ò»Á¬Íþв£¨APT£©×é֯ʹÓÃFortiOSÍøÂçÇå¾²²Ù×÷ϵͳÖеÄÒÑÖªÎó²î£¬²¢½«Ä¿µÄËø¶¨ÎªFortinetµÄSSL VPN²úÆ·£¬Ö¼ÔÚÆÆËð´óÖÐÐÍÆóÒµµÄÇå¾²ÐÔ¡£FortiOS SSL VPNÓÃÓÚ½çÏß·À»ðǽ£¬ÈÏÕæ´ÓÆäËû¹«¹²InternetÅþÁ¬ÖиôÀëÃô¸ÐµÄÄÚ²¿ÍøÂç¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.hackread.com/fbi-cisa-hackers-exploit-fortinet-vpn-vulnerabilitie
6. Õë¶ÔApplus¹«Ë¾µÄ¶ñÒâÈí¼þ¹¥»÷×èÖ¹ÁËÃÀ¹úijЩÖݵijµÁ¾¼ì²é
¡¾¸ÅÊö¡¿
³µÁ¾¼ì²â·þÎñÌṩÉÌApplus Technologies£¬ÊDzâÊÔ¡¢¼ì²éºÍÈÏÖ¤ÁìÓòµÄÈ«ÇòÏòµ¼Õߣ¬¸Ã¹«Ë¾×î½üÊܵ½¶ñÒâÈí¼þÍøÂç¹¥»÷£¬±»ÆÈ´ÓInternet¶Ï¿ªÆäITϵͳµÄÅþÁ¬£¬ÒÔ±ÜÃâ¶ñÒâÈí¼þÈö²¥¡£´Ë´Î¹¥»÷Ô˶¯Ó°ÏìÁËÃÀ¹ú°Ë¸öÖݵijµÁ¾¼ì²é£¬°üÀ¨¿µÄùµÒ¸ñÖÝ¡¢ÇÇÖÎÑÇÖÝ¡¢°®´ïºÉÖÝ¡¢ÒÁÀûŵÒÁÖÝ¡¢ÂíÈøÖîÈûÖÝ¡¢ÓÌËûÖݺÍÍþ˹¿µÐÇÖÝ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/116338/malware/malware-attack-on-applus.html
7. Õë¶ÔÒ½ÁƱ£½¡×éÖ¯µÄÍøÂç´¹ÂÚÊÂÎñʹ¸ü¶àÈËÊÜÓ°Ïì
¡¾¸ÅÊö¡¿
Ëæ×ÅÒ½ÁƱ£½¡×éÖ¯¼ÌÐø³ÉÎªÍøÂç´¹ÂÚÊÂÎñµÄÊܺ¦Õߣ¬Éæ¼°ÊÜËðµç×ÓÓʼþÕÊ»§µÄ¿µ½¡Êý¾Ýй¶ӰÏìµÄСÎÒ˽¼ÒÊýÄ¿¼ÌÐøÔöÌí¡£2021ÄêµÚÒ»¼¾¶ÈÃÀ¹úÎÀÉúºÍ¹«¹²·þÎñ²¿¼Í¼¿µ½¡Êý¾Ýй¶ÊÂÎñ125Æð£¬Éæ¼°Ô¼940ÍòÈË£¬ÆäÖÐ×î´ó¹æÄ£µÄÍøÂç´¹ÂÚÊÂÎñÓ°Ïì½ü130ÍòÈË¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/healthcare-phishing-incidents-lead-to-big-breaches-a-16339
8. ÀÕË÷ÍÅ»ïͨ¹ýµç×ÓÓʼþÏòÊܺ¦Õ߿ͻ§Ë÷Òª³ïÂë
¡¾¸ÅÊö¡¿
һЩÀÕË÷Èí¼þÍÅ»ïÕýÔÚ½ÓÄÉÒ»ÖÖеÄѹÁ¦Õ½ÂÔ£¬ÒÔÆÈʹ¸ü¶àµÄÊܺ¦Õß×éÖ¯Ö§¸¶ÀÕË÷ÒªÇó£ºÖ±½Óͨ¹ýµç×ÓÓʼþÏòÊܺ¦ÕߵĿͻ§ºÍÏàÖúͬ°é·¢Ë͵ç×ÓÓʼþ£¬ÖÒÑÔËûÃǵÄÊý¾Ý½«×ß©µ½°µÍøÖУ¬µÖ´ïÀÕË÷Ä¿µÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://krebsonsecurity.com/2021/04/ransom-gangs-emailing-victim-customers-for-leverage/
9. ¹¥»÷ÕßÕýÔÚÀÄÓÃGitHub»ù´¡ÉèÊ©À´ÍÚ¾ò¼ÓÃÜÇ®±Ò
¡¾¸ÅÊö¡¿
¹¥»÷ÕßÕýÔÚÀÄÓÃGitHub Actions¹¦Ð§£¬¸Ã¹¦Ð§ÊÇΪÁËÔÊÐí×Ô¶¯Ö´ÐÐÈí¼þÊÂÇéÁ÷¶øÊµÑéµÄ£¬¹¥»÷Àú³Ì½«¾ßÓд˹¦Ð§µÄ´æ´¢¿â¶¨Î»ÎªÄ¿µÄ£¬ÒÔÆôÓøù¦Ð§À´Ìí¼Ó¶ñÒâµÄGitHub²Ù×÷²¢Ìî³ä¶ñÒâµÄ“ÀÈ¡ÇëÇó”ÒÔÖ´ÐжñÒâ¹¥»÷ÕߵĴúÂ룬ּÔÚÀÄÓÃÆä»ù´¡ÉèÊ©À´²»·¨¿ª²É¼ÓÃÜÇ®±Ò¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/116294/malware/github-infrastructure-attacks-miner.html
10. ±»ºöÊӵĹ̼þ±£»¤
¡¾¸ÅÊö¡¿
΢ÈíÐû²¼µÄÒ»·Ýб¨¸æÏÔʾ£¬ÒÑÍùÁ½ÄêÖУ¬È«Çò80£¥µÄÆóÒµ¶¼ÊÇÕë¶Ô¹Ì¼þµÄÍøÂç¹¥»÷µÄÊܺ¦Õߣ¬Í¬Ê±Ö¸³ö£¬Ö»ÓÐ29£¥µÄÄ¿µÄ×éÖ¯·ÖÅÉÁËÔ¤ËãÀ´±£»¤¹Ì¼þ¡£¸ÃÑо¿»ùÓÚÀ´×ÔÖйú¡¢µÂ¹ú¡¢ÈÕ±¾¡¢Ó¢¹úºÍÃÀ¹úµÄ1000λÆóÒµÇå¾²¾öÒéÕßТ˳µÄÊý¾Ý£¬ÏÔʾ´ó´ó¶¼Ç徲Ͷ×ʽ«ÓÃÓÚÇå¾²¸üС¢Îó²îɨÃèºÍ¸ß¼¶Íþв·À»¤½â¾ö¼Æ»®¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.microsoft.com/en-us/secured-corepc
11. ContiÀÕË÷Èí¼þÕûÀíÓöÈËÕ¸ñÀ¼»ú¹¹110ÍòÃÀÔª
¡¾¸ÅÊö¡¿
ContiÀÕË÷Èí¼þÍÅ»ïÔÚ2020ÄêÆ½°²Ò¹¹¥»÷ÁËËÕ¸ñÀ¼ÇéÐα£»¤¾Ö£¬µ½ÏÖÔÚΪֹ£¬´Ë´Î¹¥»÷ÊÂÎñÈÃËÕ¸ñÀ¼ÇéÐα£»¤¾ÖÒÑÆÆ·ÑÁË¿ìÒª790,000Ó¢°÷£¨110ÍòÃÀÔª£©£¬Ôڸýð¶îÖУ¬ÓÐ635,000ÃÀÔªÓÃÓÚÎȹ̸ûú¹¹µÄITƽ̨¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.bbc.com/news/uk-scotland-56612867

AG¹«Ë¾ÔÆ







