ÃÀ¹úDish NetworkÒÉËÆÔâµ½¹¥»÷ÍøÕ¾ºÍÀûÓÃÎÞ·¨½Ó¼û
°ä²¼¹¦·ò 2023-02-271¡¢ÃÀ¹úDish NetworkÒÉËÆÔâµ½¹¥»÷ÍøÕ¾ºÍÀûÓÃÎÞ·¨½Ó¼û
¾ÝýÌå2ÔÂ25ÈÕ±¨Â·£¬£¬£¬£¬£¬ÃÀ¹úµçÊÓºÍÎÀÐǹ㲥ÌṩÉÌDish Network·þÎñÖжϡ£¡£¡£¡£¡£Õâ´ÎÖжÏÓ°ÏìÁËDish NetworkÍøÕ¾ºÍÀûÓ÷¨Ê½£¬£¬£¬£¬£¬Ô̺¬Dish.com¡¢DishWireless.comºÍDish AnywhereµÈ£¬£¬£¬£¬£¬¿Í»§Ò²ÎÞ·¨½Ó¼ûËûÃǵÄÕË»§»òÔÚÏß²¥·ÅµçÊÓ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Dish NetworkµÄÔ¶³ÌÔ±¹¤°µÊ¾ÎÞ·¨½Ó¼û¹¤×÷ϵͳ¡£¡£¡£¡£¡£¾ÝDish NetworkµÄÒ»ÃûÔ±¹¤Ð¹Â©£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄÈ·Ôâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬£¬µ«²¢²»È·¶¨¹¥»÷ÕßÊÇÈôºÎ»ñµÃ½Ó¼ûȨÏ޵ġ£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/dish-network-goes-offline-after-likely-cyberattack-employees-cut-off/
2¡¢Symantec·¢ÏÖÐÂÍÅ»ïClasiopaÕë¶ÔÑÇÖÞij×éÖ¯µÄ¹¥»÷
SymantecÔÚ2ÔÂ23ÈÕ³ÆÆä·¢ÏÖкڿÍÍÅ»ïClasiopaÕë¶ÔÑÇÖÞij×éÖ¯µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£Clasiopa»òÐíÓëÓ¡¶Å×йأ¬£¬£¬£¬£¬ÆäÌØµãÊÇÓµÓйÖÒìµÄ¹¤¾ß¼¯£¬£¬£¬£¬£¬Ô̺¬Ò»¸ö×Ô½ç˵¶ñÒâÈí¼þ(Backdoor.Atharvan)¡£¡£¡£¡£¡£¸ÃÍÅ»ïʹÓõÄϰȾý½éÈÎȻδ֪£¬£¬£¬£¬£¬µ«Ò»Ð©Ö¤¾ÝÅú×¢¹¥»÷Õßͨ¹ý¶ÔÃæÏò¹«¼ÒµÄ·þÎñÆ÷½øÐб©Á¦¹¥»÷À´»ñµÃ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£ÈëÇÖʱËü»á¶Ï¸ùϵͳ¼à¶½Æ÷(Sysmon)ºÍÊÂÎñÈÕÖ¾£¬£¬£¬£¬£¬²¢×°Ööà¸öºóÃÅ£¬£¬£¬£¬£¬ÈçAtharvanºÍ¿ªÔ´Lilith RATµÄÅú¸Ä°æ±¾£¬£¬£¬£¬£¬À´ÍøÂçºÍй¼ûô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/clasiopa-materials-research
3¡¢¼ÓÄôóµçÐŹ«Ë¾Telusµ÷²éÔ´´úÂëºÍÔ±¹¤Êý¾Ýй¶ÊÂÎñ
ýÌå2ÔÂ23Èճƣ¬£¬£¬£¬£¬¼ÓÄôóµÚ¶þ´óµçÐŹ«Ë¾TelusÔÚµ÷²éÆäÔ´´úÂëºÍÔ±¹¤Êý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£2ÔÂ17ÈÕ£¬£¬£¬£¬£¬ºÚ¿ÍÔÚÂÛ̳ÉÏÏúÊ۾ݳÆÊÇTelusÔ±¹¤Ãûµ¥µÄÊý¾Ý£¬£¬£¬£¬£¬Ñù±¾Ô̺¬TelusÔ±¹¤£¨ÓÈÆäÊÇÈí¼þ¿ª·¢ÈËÔ±ºÍ¼¼ÊõÈËÔ±£©µÄÐÕÃûºÍÓʼþµØÖ·¡£¡£¡£¡£¡£2ÔÂ21ÈÕ£¬£¬£¬£¬£¬Í³Ò»ºÚ¿Í´´½¨ÁËÁíÒ»¸öÂÛ̳Ìû×Ó£¬£¬£¬£¬£¬ÒªÏúÊÛTelusµÄ¸öÈËGitHub´æ´¢¿â¡¢Ô´´úÂëÒÔ¼°¹«Ë¾µÄ¹¤×ʵ¥¼Í¼¡£¡£¡£¡£¡£Telus½²»°È˳ƣ¬£¬£¬£¬£¬ËûÃÇÔÚµ÷²é´Îй¶ÊÂÎñ£¬£¬£¬£¬£¬²¢È·Èϵ½Ä¿Ç°ÎªÖ¹£¬£¬£¬£¬£¬ÉÐδ·¢ÏÖÈκι«Ë¾»òÁãÊÛ¿Í»§µÄÊý¾Ýй¶¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/telus-investigating-leak-of-stolen-source-code-employee-data/
4¡¢ÎÚ¿ËÀ¼CERTй©UAC-0056ÈëÇÔìä¶à¸öµ±¾ÖÓйØÍøÕ¾
ÎÚ¿ËÀ¼CERTÔÚ2ÔÂ23ÈÕй©£¬£¬£¬£¬£¬UAC-0056ÍÅ»ïÔÚÉÏÖÜÈëÇÖÁËÆä¶à¸öµ±¾ÖÓйØÍøÕ¾¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚÎÚ¿ËÀ¼ÖÐÑëºÍ´¦Ëùµ±¾ÖµÄ¶à¸öÍøÕ¾Éϼì²âµ½¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂÆä²¿ÃÅÍøÒ³µÄÄÚÈݱ»´Û¸Ä¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃSSHºóÃÅCredPump£¨PAMÄ£¿£¿£¿£¿£¿£¿£¿£¿é£©ÊµÏÖÔ¶³ÌSSH½Ó¼û£¨Ê¹Óþ²Ì¬ÃÜÂëÖµ£©£¬£¬£¬£¬£¬²¢ÔÚSSHÏÎ½ÓÆÚ¼ä¼Í¼µÇ¼ºÍÃÜÂë¡£¡£¡£¡£¡£»£»£»£»£»£»£»£»¹Ê¹ÓÃÁËHoaxPenºÍHoaxApeºóÃÅ£¬£¬£¬£¬£¬¶ñÒâ´úÂëÒÔApacheWeb·þÎñÆ÷Ä£¿£¿£¿£¿£¿£¿£¿£¿éµÄ´ó¾Ö³öÏÖ£¬£¬£¬£¬£¬²¢ÓÚ2022Äê2ÔÂ×°Öᣡ£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬webshellµÄ´´½¨¹¦·ò²»ÍíÓÚ2021Äê12ÔÂ23ÈÕ¡£¡£¡£¡£¡£
https://securityaffairs.com/142678/cyber-warfare-2/cert-of-ukraine-russia-backdoors.html
5¡¢Ë¹Ì¹¸£´óѧÅäÖÃÃýÎóµ¼Ö²¿ÃŲ©Ê¿ÉêÇëÕßµÄÐÅϢй¶
¾Ý2ÔÂ24ÈÕ±¨Â·£¬£¬£¬£¬£¬ÃÀ¹ú˹̹¸£´óѧ¾¼Ãѧ²©Ê¿ÉêÇëÕßµÄÐÅϢй¶¡£¡£¡£¡£¡£¸ÃУ°µÊ¾£¬£¬£¬£¬£¬1ÔÂ24ÈÕÆäÊÕµ½Í¨Öª£¬£¬£¬£¬£¬ÓÉÓÚÎļþ¼ÐÉèÖÃÅäÖÃÃýÎ󣬣¬£¬£¬£¬¹«¼ÒÄܹ»Í¨¹ýÍøÕ¾½Ó¼ûÔ̺¬2022-23Äê˹̹¸£´óѧ¾¼Ãϵ²©Ê¿ÏîÄ¿ÈëѧÉêÇëÎļþµÄÎļþ¼Ó×£¡£¡£¡£¡£ÔÚ¶Ô´ËʽøÐе÷²éºó£¬£¬£¬£¬£¬·¢ÏÖÎÞÏ޶ȵĽӼûÊÇ´Ó2022Äê12ÔÂ5ÈÕÆðÍ·µÄ£¬£¬£¬£¬£¬²¢ÇÒÔÚ2022Äê12ÔÂ5ÈÕÖÁ2023Äê1ÔÂ24ÈÕÖ®¼äÓйýÁ½´ÎÏÂÔØ¡£¡£¡£¡£¡£Ë¹Ì¹¸£´óѧÔÚ·¢ÏÖй¶ÊÂÎñºóÁ¢¼´²ÉÈ¡´ëÊ©×èÖ¹Á˶ÔÕâЩÎļþµÄ½Ó¼û¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/stanford-university-discloses-data-breach-affecting-phd-applicants/
6¡¢×êÑÐÈËÔ±Åû¶ÀûÓÃPureCrypter¹¥»÷µ±¾Ö»ú¹¹µÄ»î¶¯
2ÔÂ23ÈÕ£¬£¬£¬£¬£¬Menlo LabsÅû¶ÁËÀûÓöñÒâÈí¼þÏÂÔØ·¨Ê½PureCrypter¹¥»÷µ±¾Ö»ú¹¹µÄ»î¶¯¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃDiscordÀ´Íйܳõʼpayload£¬£¬£¬£¬£¬²¢ÈëÇÖÁËÒ»¸ö·ÇͶ»ú×éÖ¯À´´æ´¢»î¶¯ÖÐʹÓÃµÄÆäËüÖ÷»ú¡£¡£¡£¡£¡£¸Ã»î¶¯´«²¼Á˶àÖÖÀàÐ͵ĶñÒâÈí¼þ£¬£¬£¬£¬£¬Ô̺¬Redline Stealer¡¢AgentTesla¡¢Eternity¡¢BlackmoonºÍPhiladelphia Ransomware¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬¹Û²ìµ½µÄPureCrypter»î¶¯ÖØÒªÕë¶ÔÑÇÌ«µØÓòºÍ±±ÃÀµØÓòµÄ¶à¸öµ±¾Ö»ú¹¹¡£¡£¡£¡£¡£
https://www.menlosecurity.com/blog/purecrypter-targets-government-entities-through-discord/


¾©¹«Íø°²±¸11010802024551ºÅ