ÃÀ¹úµ±¾Ö°ä²¼½áºÏÖҸ棺BlackMatterÀÕË÷Èí¼þÕý¶ÔÃÀ¹ú»ù´¡ÉèÊ©ÌáÒé¹¥»÷

°ä²¼¹¦·ò 2021-10-21

Symantec·¢ÏÖHarvesterÕë¶ÔÄÏÑǵçÐÅÐÐÒµµÄ¹¥»÷»î¶¯


Symantec·¢ÏÖHarvesterÕë¶ÔÄÏÑǵçÐÅÐÐÒµµÄ¹¥»÷»î¶¯.png


SymantecÔÚ10ÔÂ18ÈÕÅû¶ÁËÒ»¸öеÄÓɹú¶ÈÖ§³ÖµÄºÚ¿ÍÍÅ»ïHarvesterµÄ¹¥»÷»î¶¯ ¡£¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯¶Ô×¼ÁËÄÏÑǵÄ×éÖ¯£¬£¬£¬£¬£¬³ö¸ñÊǰ¢¸»º¹£¬£¬£¬£¬£¬Õë¶ÔµçÐźÍITÐÐÒµµÄ¹«Ë¾ÒÔ¼°¹Ù·½×éÖ¯£¬£¬£¬£¬£¬ÆðÍ·ÓÚ2021Äê6Ô£¬£¬£¬£¬£¬×î½üÒ»´Î»î¶¯²úÉúÔÚ2021Äê10Ô ¡£¡£¡£¡£¡£ÔÚ¼¼Êõ·½Ã棬£¬£¬£¬£¬¹¥»÷ÕßÔÚÖ¸±êÖÐ×°ÖÃÁËÒ»¸öÃûΪBackdoor.GraphonµÄ×Ô½ç˵ºóÃÅ£¬£¬£¬£¬£¬ÒÔ¼°ÆäËû×Ô½ç˵ÏÂÔØÆ÷ºÍ½ØÍ¼¹¤¾ß ¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔ³õʼϰȾý½éÊÇʲô£¬£¬£¬£¬£¬µ«×êÑÐÈËÔ±ÔÚ±»ºÚÉ豸ÉÏ·¢ÏֵĵÚÒ»¸ö¹ØÓÚÕâ´Î»î¶¯µÄÖ¤¾ÝÊǶñÒâURL ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/harvester-new-apt-attacks-asia


DesordenÐû³ÆÒÑÈëÇÖºê»ùAcerÔÚÖйų́ÍåµÄ·þÎñÆ÷


DesordenÐû³ÆÒÑÈëÇÖºê»ùAcerÔÚÖйų́ÍåµÄ·þÎñÆ÷.png


ÉÏÖÜ£¬£¬£¬£¬£¬DesordenÈëÇÖÁ˺ê»ù£¨Acer£©Ó¡¶ÈµÄ·þÎñÆ÷²¢ÇÔÈ¡ÁËÆäÖеÄÊý¾Ý ¡£¡£¡£¡£¡£²»µ½Ò»Öܺ󣬣¬£¬£¬£¬¸ÃÍÅ»ïÓÖ³ÆËûÃÇÔÚ10ÔÂ15ÈÕÈëÇÖÁ˺ê»ų̀ÍåµÄ·þÎñÆ÷£¬£¬£¬£¬£¬²¢¹«¿ªÁ˸ù«Ë¾ÄÚ²¿ÍøÕ¾µÄͼƬºÍÔ±¹¤µÇ¼ʹ´¦µÄCSVÎļþ ¡£¡£¡£¡£¡£Desorden°µÊ¾ËûÃÇÕâ´ÎµÄ¹¥»÷ÊÇΪÁËÖ¤Ã÷ºê»ùÒÀÈ»´æÔÚ·ì϶£¬£¬£¬£¬£¬²¢Ö¸³ö¸Ã¹«Ë¾ÔÚÂíÀ´Î÷ÑǺÍÓ¡¶ÈÄáÎ÷ÑǵÄϵͳҲÈÝÒ×Êܵ½¹¥»÷ ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ºê³žÌ¨ÍåÒѾ­¹Ø¹ØÁ˱»ºÚµÄϵͳ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/acer-hacked-twice-in-a-week-by-the-same-threat-actor/


ºÚ¿ÍÍÅ»ïTeamTNTÀûÓöñÒâDocke¾µÏñ·Ö·¢ÍÚ¿óÈí¼þ


ºÚ¿ÍÍÅ»ïTeamTNTÀûÓöñÒâDocke¾µÏñ·Ö·¢ÍÚ¿óÈí¼þ.png

Uptycs×êÑÐÍŶÓÔÚ10ÔÂ18ÈÕ¹«¿ªÁËTeamTNTÐÂÒ»ÂֵĹ¥»÷»î¶¯ ¡£¡£¡£¡£¡£ÔÚÕâ´Î»î¶¯ÖУ¬£¬£¬£¬£¬TeamTNTÀûÓÃÁ˶ñÒâDocke¾µÏñ£¬£¬£¬£¬£¬²¢Ê¹ÓÃǶÈëʽ¾ç±¾ÏÂÔØÉ¨ÃèÆ÷ZgrabºÍÉøÈë²âÊÔ¹¤¾ßmasscannerÀ´ÌáÈ¡bannerºÍ¶Ë¿ÚɨÃ裬£¬£¬£¬£¬Ö¼ÔÚ·Ö·¢¶ñÒâcoinminerÀ´½Ù³ÖÖ¸±êµÄÍÆËã×ÊÔ´ÍÚ¿ó ¡£¡£¡£¡£¡£¸Ã¾µÏñÍйÜÔÚÃûΪDocker HubÉÏ£¬£¬£¬£¬£¬ÃûΪalpineos£¬£¬£¬£¬£¬¸ÃÓû§ÓÚ2021Äê5ÔÂ26ÈÕ²ÎÓëDocker Hub£¬£¬£¬£¬£¬½ØÖÁ´Ë¿Ì£¬£¬£¬£¬£¬alpineosÅäÖÃÎļþÍйÜÁË25¸öDockerÓ³Ïñ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/123535/cyber-crime/teamtnt-docker-attack.html


×êÑÐÈËÔ±·¢ÏÖLyceumÍÅ»ïÕë¶ÔÍ»Äá˹µÄ¹¥»÷»î¶¯


×êÑÐÈËÔ±·¢ÏÖLyceumÍÅ»ïÕë¶ÔÍ»Äá˹µÄ¹¥»÷»î¶¯.png


KasperskyµÄ×êÑÐÈËÔ±ÓÚ10ÔÂ18ÈÕ°ä²¼»ã±¨£¬£¬£¬£¬£¬½éÉÜÁËLyceumÍÅ»ïÕë¶ÔÍ»Äá˹µÄ¹¥»÷»î¶¯ ¡£¡£¡£¡£¡£Lyceum£¨±ðÃûHexane£©ÓÚ2019Äê³õ´Î±»SecureworksÆØ¹â£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÖж«µÄÄÜÔ´ºÍµçÐÅÐÐÒµ ¡£¡£¡£¡£¡£Õâ´Î¹¥»÷µÄÖ¸±ê¾ùÊÇÍ»Äá˹µÄ³ÛÃû¹«Ë¾£¬£¬£¬£¬£¬ÈçµçÐÅ»òº½¿Õ¹«Ë¾ ¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁËÁ½¸öÓÃC++±àдµÄжñÒâÈí¼þJamesºÍKevin£¬£¬£¬£¬£¬¹ÌÈ»JamesÔںܴóˮƽÉÏÈÔ»ùÓÚ¶ñÒâÈí¼þDanBot£¬£¬£¬£¬£¬µ«KevinÔڼܹ¹ºÍͨѶºÍ̸·½Ãæ×ö³öÁ˳Á´óŤת ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/lyceum-group-reborn/104586/


°²È«¹«Ë¾Trustwave°ä²¼ÀÕË÷Èí¼þBlackByteµÄ½âÃÜÆ÷


°²È«¹«Ë¾Trustwave°ä²¼ÀÕË÷Èí¼þBlackByteµÄ½âÃÜÆ÷.png


°²È«¹«Ë¾TrustwaveµÄ×êÑÐÍŶÓSpiderLabsÔÚGitHubÉϰ䲼ÁËÀÕË÷Èí¼þBlackByteµÄ½âÃÜÆ÷ ¡£¡£¡£¡£¡£Æ¾¾Ý¶ÔÀÕË÷Èí¼þµÄ·ÖÎöÅú×¢£¬£¬£¬£¬£¬BlackByteʹÓÃÁËÒ»ÑùµÄԭʼÃÜÔ¿À´¼ÓÃÜÎļþ£¬£¬£¬£¬£¬²¢Ê¹ÓöԳÆÃÜÔ¿Ëã·¨AES£¬£¬£¬£¬£¬Òò¶øÈκÎÓµÓÐԭʼÃÜÔ¿µÄÈ˶¼Äܹ»½âÃÜÎļþ ¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÀÕË÷Èí¼þʹÓÃÒ»¸öǶÈëÁ˶à¸öÃÜÔ¿.PNGÎļþ£¬£¬£¬£¬£¬Í¨¹ý¶ÈÎö¸ÃÎļþ¿ª·¢ÁËÃâ·ÑµÄ½âÃÜÆ÷ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/blackbyte-ransomware-decryptor-released/


CISA¡¢FBIºÍNSA°ä²¼BlackMatterµÄÔ¤¾¯²¼¸æ


CISA¡¢FBIºÍNSA°ä²¼BlackMatterµÄÔ¤¾¯²¼¸æ.png


10ÔÂ18ÈÕ£¬£¬£¬£¬£¬CISA¡¢FBIºÍNSA°ä²¼ÁËÀÕË÷Èí¼þBlackMatterµÄ½áºÏÍøÂ簲ȫÕ÷ѯ (CSA) ¡£¡£¡£¡£¡£×Ô½ñÄê7ÔÂÒÔÀ´£¬£¬£¬£¬£¬ÀÕË÷Èí¼þBlackMatterÒѹ¥»÷ÁËÃÀ¹úµÄ¶à¸öÓë¹Ø¼ü»ù´¡ÉèÊ©ÓйصĹ«Ë¾£¬£¬£¬£¬£¬ÀýÈçʳƷºÍũҵÐÐÒµ ¡£¡£¡£¡£¡£¸ÃCSA·ÖÎöÁËBlackMatterµÄÑù±¾²¢½áºÏÁËÀ´×ÔµÚÈý·½µÄÐÅÏ¢£¬£¬£¬£¬£¬ÌṩÁ˹¥»÷ÕßµÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½£¬£¬£¬£¬£¬²¢¸ÅÊö»º½â´ëÊ©£¬£¬£¬£¬£¬ÒÔÔ®ÊÖ×éÖ¯¸Ä½øÕë¶Ô´ËÀ๥»÷µÄ±£»£»£»£»£» £»¤¡¢¼ì²âºÍÏìÓ¦´ëÊ© ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/10/18/cisa-fbi-and-nsa-release-joint-cybersecurity-advisory-blackmatter