ÃÀ¹úµ±¾Ö°ä²¼½áºÏÖҸ棺BlackMatterÀÕË÷Èí¼þÕý¶ÔÃÀ¹ú»ù´¡ÉèÊ©ÌáÒé¹¥»÷
°ä²¼¹¦·ò 2021-10-21Symantec·¢ÏÖHarvesterÕë¶ÔÄÏÑǵçÐÅÐÐÒµµÄ¹¥»÷»î¶¯

SymantecÔÚ10ÔÂ18ÈÕÅû¶ÁËÒ»¸öеÄÓɹú¶ÈÖ§³ÖµÄºÚ¿ÍÍÅ»ïHarvesterµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯¶Ô×¼ÁËÄÏÑǵÄ×éÖ¯£¬£¬£¬£¬£¬³ö¸ñÊǰ¢¸»º¹£¬£¬£¬£¬£¬Õë¶ÔµçÐźÍITÐÐÒµµÄ¹«Ë¾ÒÔ¼°¹Ù·½×éÖ¯£¬£¬£¬£¬£¬ÆðÍ·ÓÚ2021Äê6Ô£¬£¬£¬£¬£¬×î½üÒ»´Î»î¶¯²úÉúÔÚ2021Äê10Ô¡£¡£¡£¡£¡£ÔÚ¼¼Êõ·½Ã棬£¬£¬£¬£¬¹¥»÷ÕßÔÚÖ¸±êÖÐ×°ÖÃÁËÒ»¸öÃûΪBackdoor.GraphonµÄ×Ô½ç˵ºóÃÅ£¬£¬£¬£¬£¬ÒÔ¼°ÆäËû×Ô½ç˵ÏÂÔØÆ÷ºÍ½ØÍ¼¹¤¾ß¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔ³õʼϰȾý½éÊÇʲô£¬£¬£¬£¬£¬µ«×êÑÐÈËÔ±ÔÚ±»ºÚÉ豸ÉÏ·¢ÏֵĵÚÒ»¸ö¹ØÓÚÕâ´Î»î¶¯µÄÖ¤¾ÝÊǶñÒâURL¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/harvester-new-apt-attacks-asia
DesordenÐû³ÆÒÑÈëÇÖºê»ùAcerÔÚÖйų́ÍåµÄ·þÎñÆ÷

ÉÏÖÜ£¬£¬£¬£¬£¬DesordenÈëÇÖÁ˺ê»ù£¨Acer£©Ó¡¶ÈµÄ·þÎñÆ÷²¢ÇÔÈ¡ÁËÆäÖеÄÊý¾Ý¡£¡£¡£¡£¡£²»µ½Ò»Öܺ󣬣¬£¬£¬£¬¸ÃÍÅ»ïÓÖ³ÆËûÃÇÔÚ10ÔÂ15ÈÕÈëÇÖÁ˺ê»ų̀ÍåµÄ·þÎñÆ÷£¬£¬£¬£¬£¬²¢¹«¿ªÁ˸ù«Ë¾ÄÚ²¿ÍøÕ¾µÄͼƬºÍÔ±¹¤µÇ¼ʹ´¦µÄCSVÎļþ¡£¡£¡£¡£¡£Desorden°µÊ¾ËûÃÇÕâ´ÎµÄ¹¥»÷ÊÇΪÁËÖ¤Ã÷ºê»ùÒÀÈ»´æÔÚ·ì϶£¬£¬£¬£¬£¬²¢Ö¸³ö¸Ã¹«Ë¾ÔÚÂíÀ´Î÷ÑǺÍÓ¡¶ÈÄáÎ÷ÑǵÄϵͳҲÈÝÒ×Êܵ½¹¥»÷¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ºê³žÌ¨ÍåÒѾ¹Ø¹ØÁ˱»ºÚµÄϵͳ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/acer-hacked-twice-in-a-week-by-the-same-threat-actor/
ºÚ¿ÍÍÅ»ïTeamTNTÀûÓöñÒâDocke¾µÏñ·Ö·¢ÍÚ¿óÈí¼þ

Uptycs×êÑÐÍŶÓÔÚ10ÔÂ18ÈÕ¹«¿ªÁËTeamTNTÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£¡£¡£¡£¡£ÔÚÕâ´Î»î¶¯ÖУ¬£¬£¬£¬£¬TeamTNTÀûÓÃÁ˶ñÒâDocke¾µÏñ£¬£¬£¬£¬£¬²¢Ê¹ÓÃǶÈëʽ¾ç±¾ÏÂÔØÉ¨ÃèÆ÷ZgrabºÍÉøÈë²âÊÔ¹¤¾ßmasscannerÀ´ÌáÈ¡bannerºÍ¶Ë¿ÚɨÃ裬£¬£¬£¬£¬Ö¼ÔÚ·Ö·¢¶ñÒâcoinminerÀ´½Ù³ÖÖ¸±êµÄÍÆËã×ÊÔ´Íڿ󡣡£¡£¡£¡£¸Ã¾µÏñÍйÜÔÚÃûΪDocker HubÉÏ£¬£¬£¬£¬£¬ÃûΪalpineos£¬£¬£¬£¬£¬¸ÃÓû§ÓÚ2021Äê5ÔÂ26ÈÕ²ÎÓëDocker Hub£¬£¬£¬£¬£¬½ØÖÁ´Ë¿Ì£¬£¬£¬£¬£¬alpineosÅäÖÃÎļþÍйÜÁË25¸öDockerÓ³Ïñ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/123535/cyber-crime/teamtnt-docker-attack.html
×êÑÐÈËÔ±·¢ÏÖLyceumÍÅ»ïÕë¶ÔÍ»Äá˹µÄ¹¥»÷»î¶¯

KasperskyµÄ×êÑÐÈËÔ±ÓÚ10ÔÂ18ÈÕ°ä²¼»ã±¨£¬£¬£¬£¬£¬½éÉÜÁËLyceumÍÅ»ïÕë¶ÔÍ»Äá˹µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£Lyceum£¨±ðÃûHexane£©ÓÚ2019Äê³õ´Î±»SecureworksÆØ¹â£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÖж«µÄÄÜÔ´ºÍµçÐÅÐÐÒµ¡£¡£¡£¡£¡£Õâ´Î¹¥»÷µÄÖ¸±ê¾ùÊÇÍ»Äá˹µÄ³ÛÃû¹«Ë¾£¬£¬£¬£¬£¬ÈçµçÐÅ»òº½¿Õ¹«Ë¾¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁËÁ½¸öÓÃC++±àдµÄжñÒâÈí¼þJamesºÍKevin£¬£¬£¬£¬£¬¹ÌÈ»JamesÔںܴóˮƽÉÏÈÔ»ùÓÚ¶ñÒâÈí¼þDanBot£¬£¬£¬£¬£¬µ«KevinÔڼܹ¹ºÍͨѶºÍ̸·½Ãæ×ö³öÁ˳Á´óŤת¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/lyceum-group-reborn/104586/
°²È«¹«Ë¾Trustwave°ä²¼ÀÕË÷Èí¼þBlackByteµÄ½âÃÜÆ÷

°²È«¹«Ë¾TrustwaveµÄ×êÑÐÍŶÓSpiderLabsÔÚGitHubÉϰ䲼ÁËÀÕË÷Èí¼þBlackByteµÄ½âÃÜÆ÷¡£¡£¡£¡£¡£Æ¾¾Ý¶ÔÀÕË÷Èí¼þµÄ·ÖÎöÅú×¢£¬£¬£¬£¬£¬BlackByteʹÓÃÁËÒ»ÑùµÄÔʼÃÜÔ¿À´¼ÓÃÜÎļþ£¬£¬£¬£¬£¬²¢Ê¹ÓöԳÆÃÜÔ¿Ëã·¨AES£¬£¬£¬£¬£¬Òò¶øÈκÎÓµÓÐÔʼÃÜÔ¿µÄÈ˶¼Äܹ»½âÃÜÎļþ¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÀÕË÷Èí¼þʹÓÃÒ»¸öǶÈëÁ˶à¸öÃÜÔ¿.PNGÎļþ£¬£¬£¬£¬£¬Í¨¹ý¶ÈÎö¸ÃÎļþ¿ª·¢ÁËÃâ·ÑµÄ½âÃÜÆ÷¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/blackbyte-ransomware-decryptor-released/
CISA¡¢FBIºÍNSA°ä²¼BlackMatterµÄÔ¤¾¯²¼¸æ

10ÔÂ18ÈÕ£¬£¬£¬£¬£¬CISA¡¢FBIºÍNSA°ä²¼ÁËÀÕË÷Èí¼þBlackMatterµÄ½áºÏÍøÂ簲ȫÕ÷ѯ (CSA)¡£¡£¡£¡£¡£×Ô½ñÄê7ÔÂÒÔÀ´£¬£¬£¬£¬£¬ÀÕË÷Èí¼þBlackMatterÒѹ¥»÷ÁËÃÀ¹úµÄ¶à¸öÓë¹Ø¼ü»ù´¡ÉèÊ©ÓйصĹ«Ë¾£¬£¬£¬£¬£¬ÀýÈçʳƷºÍũҵÐÐÒµ¡£¡£¡£¡£¡£¸ÃCSA·ÖÎöÁËBlackMatterµÄÑù±¾²¢½áºÏÁËÀ´×ÔµÚÈý·½µÄÐÅÏ¢£¬£¬£¬£¬£¬ÌṩÁ˹¥»÷ÕßµÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½£¬£¬£¬£¬£¬²¢¸ÅÊö»º½â´ëÊ©£¬£¬£¬£¬£¬ÒÔÔ®ÊÖ×éÖ¯¸Ä½øÕë¶Ô´ËÀ๥»÷µÄ±£»£»£»£»£»£»¤¡¢¼ì²âºÍÏìÓ¦´ëÊ©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2021/10/18/cisa-fbi-and-nsa-release-joint-cybersecurity-advisory-blackmatter


¾©¹«Íø°²±¸11010802024551ºÅ