жñÒâÈí¼þ¿ÉÀûÓÃImgurÀ´½âÂëCobalt Strike¾ç±¾£»£»£»£» £»ºÚ¿ÍÀûÓÃFacebook¸æ°×ÇÔÈ¡61.5Íò¸öÓû§µÇ¼ʹ´¦

°ä²¼¹¦·ò 2020-12-30
1.жñÒâÈí¼þ¿ÉÀûÓÃImgurÀ´½âÂëCobalt Strike¾ç±¾


1.png


жñÒâÈí¼þ¿ÉÀûÓÃͼÏñÍйܷþÎñImgurÏÂÔØºÏ·¨µÄͼÏñ£¬£¬£¬£¬£¬£¬À´½âÂëCobalt Strike¾ç±¾¡£¡£¡£¡£¡£¡£ÐµĶñÒâÈí¼þʹÓôøÓкêµÄWordÎļþ´ÓGitHubÏÂÔØPowerShell¾ç±¾£¬£¬£¬£¬£¬£¬¸Ã¾ç±¾½«´ÓImgurÏÂÔØÏÖʵPNGÎļþ¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬ÀûÓÃÏñInvoke-PSImageÕâÑùµÄ¹¤¾ßÀ´Ê¹ÓÃPNGÎļþÖеÄÏñËØÖµ±àÂëPowerShell¾ç±¾£¬£¬£¬£¬£¬£¬²¢ÌìÉúÒ»ÐкÅÁîÀ´Ö´ÐÐpayload£¬£¬£¬£¬£¬£¬×îÖÕ»ñµÃCobalt Strike¾ç±¾¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±´§Ä¦´Ë¶ñÒâÈí¼þ¿ÉÄÜÓëÖØÒªÕë¶ÔÖж«ÊµÌåµÄAPT×éÖ¯MuddyWaterÓйØ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/github-hosted-malware-calculates-cobalt-strike-payload-from-imgur-pic/


2.×êÑÐÈËÔ±ÔÚShopifyµÈÍйܵĵçÉÌÆ½Ì¨¼ì²âµ½Magecart¾ç±¾


2.png


SansecµÄ×êÑÐÈËÔ±ÔÚShopify¡¢BigCommerce¡¢ZencartºÍWoocommerceµÈµçÉÌÆ½Ì¨¼ì²âµ½Magecart¾ç±¾¡£¡£¡£¡£¡£¡£ÕâÖÖеÄMagecart¾ç±¾Ò²Äܹ»±»ÓÃÓÚ¹¥»÷²»Ö§³Ö×Ô½ç˵½áÕÊÒ³ÃæµÄÍйܵçÉÌϵͳ£¬£¬£¬£¬£¬£¬Í¨¹ýÔÚ¿Í»§µÇÂ½ÕæÊµµÄ½áÕÊÒ³ÃæÖ®Ç°ÏÔʾһ¸öαÔìµÄÒ³Ãæ£¬£¬£¬£¬£¬£¬²¢Ê¹ÓüüÅ̼ͼÆ÷À´À¹½Ø¸¶¿îºÍÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¸Ã»î¶¯×Ô2020Äê8ÔÂÆðÍ·£¬£¬£¬£¬£¬£¬ÒѾ­½øÐÐÁ˺ܳ¤¹¦·ò¡£¡£¡£¡£¡£¡£Sansec°µÊ¾ÔÚͳһ´Î¹¥»÷»î¶¯Õë¶ÔÕâô¶à·ÖÆçµÄƽ̨ÊǺÜÉÙ¼ûµÄ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/multi-platform-card-skimmer-found-on-shopify-bigcommerce-stores/


3.ºÚ¿ÍÏúÊÛÒâ´óÀûHo MobileµÄ250ÍòÌõÓû§Êý¾Ý


3.png


ºÚ¿ÍÔÚ°µÍøÏúÊÛÒâ´óÀûÒÆ¶¯ÔËÓªÉÌHo MobileµÄ250ÍòÌõÓû§Êý¾Ý¡£¡£¡£¡£¡£¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬Óû§ÐÕÃû¡¢ÐÔ±ð¡¢ÉúÈÕ¡¢ÓʼþµØÖ·¡¢¾ÓסµØÖ·¡¢Óʱࡢ²ÆÕþ´úÂë¡¢¹ú¼®¡¢´ºÇï¡¢µç»°ºÅÂëºÍÓйØÓû§sim¿¨µÄÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£ÕâЩÐÅÏ¢¿É±»ÓÃÀ´½øÐÐSIM»¥»»¹¥»÷¡¢ÍøÂç´¹µö¹¥»÷ºÍÒøÐÐڲƭ¡£¡£¡£¡£¡£¡£¶øHo MobileÒѰ䷢ÉêÃ÷£¬£¬£¬£¬£¬£¬³ÆÃ»ÓÐÖ¤¾ÝÅú×¢´æÔÚ´ó¹æÄ£½Ó¼ûITϵͳµÄ¹¥»÷»î¶¯Î£¼°ÁËÆä¿Í»§µÄÊý¾Ý¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/112740/data-breach/ho-mobile-data-leak.html


4.ºÚ¿ÍÀûÓÃFacebook¸æ°×ÇÔÈ¡61.5Íò¸öÓû§µÇ¼ʹ´¦


4.png


ThreatNixµÄ×êÑÐÈËÔ±·¢ÏÖºÚ¿ÍÀûÓÃFacebook¸æ°×ÌáÒé´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬ÇÔÈ¡61.5Íò¸öÓû§µÇ¼ʹ´¦¡£¡£¡£¡£¡£¡£Ôڸù¥»÷»î¶¯ÖкڿÍÒÔÄá²´¶ûµçÐŵÄÃûÒå°ä²¼Facebook¸æ°×£¬£¬£¬£¬£¬£¬³ÐŵÔùËÍ3 GBµÄÁ÷Á¿¡£¡£¡£¡£¡£¡£µ±Óû§µã»÷ÏνӺ󣬣¬£¬£¬£¬£¬½«±»³Á¶¨Ïòµ½Ò»¸ö¾²Ì¬GithubÒ³Ãæ£¬£¬£¬£¬£¬£¬ÕâÊÇαÔì³ÉFacebookµÇÂ¼Ò³ÃæµÄ´¹µöÒ³Ãæ¡£¡£¡£¡£¡£¡£±»µÁµÄÍ´´¦½«Í¨¹ýFirestoreÊý¾Ý¿âºÍGoDaddyÉÏÍйܵÄÓò´«»Ø¸ø¹¥»÷Õß¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÖØÒªÕë¶ÔÀ´×Ô°£¼°¡¢·ÆÂɱö¡¢°Í»ù˹̹ºÍÄá²´¶ûµÈ¹ú¶ÈµÄÓû§£¬£¬£¬£¬£¬£¬×ܹ²Ó°Ï쳬¹ý615000Ó×ÎÒ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/hackers-phish-login-credentials-with-facebook-ads/


5.FBI°ä²¼ÓйغڿͽٳÖÖÇÄÜÉ豸µÄ¹¥»÷»î¶¯µÄ¾¯±¨


5.png


FBI°ä²¼ÁËÓйغڿͽٳÖÖÇÄÜÉ豸µÄ¹¥»÷»î¶¯µÄ¾¯±¨¡£¡£¡£¡£¡£¡£FBI³Æ£¬£¬£¬£¬£¬£¬ºÚ¿Í»áÀûÓÃÏÈǰÔÚÆäËû¹«Ë¾²úÉúÊý¾Ýй¶ʱй©µÄÍ´´¦£¬£¬£¬£¬£¬£¬À´½Ù³ÖÊܺ¦ÕßµÄÖÇÄÜÉ豸£¬£¬£¬£¬£¬£¬ÀýÈçÓµÓÐÊÓÆµºÍÒôƵְÄܵļÒÍ¥¼à¿ØÉ豸¡£¡£¡£¡£¡£¡£¶øºó±¨¼Ù¾¯£¬£¬£¬£¬£¬£¬³ÆÊܺ¦ÕßסËù´¦Óз¸×ï»î¶¯¡£¡£¡£¡£¡£¡£ºÚ¿Í»áͨ¹ý½Ù³ÖµÄÉ豸ÅÔ¹ÛÖ±²¥ÊÓÆµ£¬£¬£¬£¬£¬£¬²¢ÀûÓÃÉãÏñÍ·ºÍÑïÉùÆ÷Óë³ö¾¯µÄ¾¯Ô±½øÐн»»¥¡£¡£¡£¡£¡£¡£ÓÐʱ£¬£¬£¬£¬£¬£¬ºÚ¿Í»¹»áÔÚ¹²ÏíÆ½Ì¨ÉϽøÐÐʵʱֱ²¥¡£¡£¡£¡£¡£¡£FBI³Æ£¬£¬£¬£¬£¬£¬ËûÃÇ´Ë¿ÌÔÚÓëÉ豸¹©¸øÉ̺Ï×÷£¬£¬£¬£¬£¬£¬ÒÔÔ®ÊÖÓû§ÎªÉ豸ÉèÖøüºÃµÄÃÜÂë¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/fbi-pranksters-are-hijacking-smart-devices-to-live-stream-swatting-incidents/


6.¼Òµç¹«Ë¾»Ý¶øÆÖϰȾNefilim£¬£¬£¬£¬£¬£¬ÆäÊý¾Ý±»¼ÓÃܲ¢Ð¹Â¶


6.png


¼Òµç¹«Ë¾»Ý¶øÆÖ£¨Whirlpool£©Ï°È¾ÀÕË÷Èí¼þNefilim£¬£¬£¬£¬£¬£¬ÆäÊý¾Ý±»¼ÓÃܲ¢Ð¹Â¶¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷²úÉúÔÚÖÜÄ©£¬£¬£¬£¬£¬£¬ºÚ¿ÍÇÔÈ¡µÄÊý¾ÝÔ̺¬ÓëÔ±¹¤¸£Àû¡¢×¡ËÞÒªÇó¡¢Ò½ÁÆÐÅÏ¢ÒªÇóºÍ²¼¾°µ÷²éµÅ×йصÄÎĵµ£¬£¬£¬£¬£¬£¬Ëæºó¼ÓÃÜÁËÆäÉ豸¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬»Ý¶øÆÖµÄϵͳÒÑÆëÈ«¸´Ô­£¬£¬£¬£¬£¬£¬²¢Ðû³ÆÃ»ÓÐÈκÎÓëÏû·ÑÕßÓйصÄÐÅϢй¶¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/home-appliance-giant-whirlpool-hit-in-nefilim-ransomware-attack/