ESTsecurityÅû¶ThalliumÕë¶Ô½ðÈÚÐÐÒµµÄ¹©¸øÁ´¹¥»÷£»£»£»£»£»£»£»NISSAN±±ÃÀ·Ö¹«Ë¾ÒòGit·þÎñÆ÷ÅäÖÃÃýÎóµ¼ÖÂÔ´´úÂëй¶
°ä²¼¹¦·ò 2021-01-071.ESTsecurityÅû¶ThalliumÕë¶Ô½ðÈÚÐÐÒµµÄ¹©¸øÁ´¹¥»÷

ESTsecurityÅû¶APT×éÖ¯Thallium£¨±ðÃûAPT37£©Õë¶Ô½ðÈÚÐÐÒµµÄ¹©¸øÁ´¹¥»÷¡£¡£¡£¡£¡£ÔÚÕâ´Î¹¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬ºÚ¿Í´Û¸ÄÁËÒ»¿î¸öÈË¹ÉÆ±Í¶×ÊÐÅÏ¢´«µÝµÄÀûÓ㬣¬£¬£¬£¬ÒÔ·Ö·¢¶ñÒâ´úÂë¡£¡£¡£¡£¡£ThalliumÊ×ÏÈʹÓÃNullsoft¾ç±¾×°ÖÃϵͳ£¨NSIS£©ÌìÉúWindows¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬¸ÃÎļþÔ̺¬ÁËÀ´×ԺϷ¨¹ÉƱͶ×ÊÀûÓ÷¨Ê½µÄºÏ·¨ÎļþºÍ¶ñÒâ´úÂë¡£¡£¡£¡£¡£µ±Óû§ÔÚ×°ÖÃÕæÕýµÄ¹ÉƱͶ×ÊÀûÓ÷¨Ê½Ê±£¬£¬£¬£¬£¬ºó¶ÜͬʱÔËÐжñÒâ¾ç±¾¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/north-korean-software-supply-chain-attack-targets-stock-investors/
2.Intezer·¢ÏÖElectroRAT²ØÓÚαÔìµÄ¼ÓÃÜÇ®±ÒÀûÓÃ

Intezer Labs·¢ÏÖElectroRAT²ØÓÚαÔìµÄ¼ÓÃÜÇ®±ÒÀûÓᣡ£¡£¡£¡£¸Ã»î¶¯ÔçÔÚ2020Äê1ÔÂ8ÈÕ¾ÍÆðÍ·»îÔ¾£¬£¬£¬£¬£¬µ«ÊÇÔÚ2020Äê12Ô²ű»·¢ÏÖ¡£¡£¡£¡£¡£ºÚ¿ÍÖØÒªÒÀÀµÓÚÈý¸öÓë¼ÓÃÜÇ®±ÒÓйصÄÀûÓÃJamm¡¢eTrade/KintumºÍDaoPokerÀ´·Ö·¢¶ñÒâÈí¼þElectroRAT¡£¡£¡£¡£¡£ElectroRATÓµÓм«Ç¿µÄÇÖÈëÐÔ£¬£¬£¬£¬£¬ÓµÓмüÅ̼ͼ¡¢½ØÍ¼¡¢ÉÏ´«Îļþ¡¢ÏÂÔØÎļþÒÔ¼°ÔÚÖ¸±ê½ÚÔį̀ÉÏÖ´ÐкÅÁîµÈÖ°ÄÜ£¬£¬£¬£¬£¬Ä¿Ç°¿ÉÄÜÒѾϰȾÁËԼĪ6500¸öÓû§¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-target-cryptocurrency-users-with-new-electrorat-malware/
3.°Äµ±¾ÖÖҸ淸×ïÍÅ»ï¼ÙÒâÆäÍøÂ簲ȫÖÐÐÄ·Ö·¢¶ñÒâÈí¼þ

°Ä´óÀûÑǵ±¾ÖÖÒ¸æ³Æ£¬£¬£¬£¬£¬·¸×ïÍÅ»ï¼ÙÒâ°Ä´óÀûÑÇÍøÂ簲ȫÖÐÐÄ£¨ACSC£©·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¸ÃÍÅ»ïÓÕʹÊܺ¦Õß×°ÖÃÔ¶³ÌÖÎÀíºÍ×ÀÃæ¹²ÏíÈí¼þ£¬£¬£¬£¬£¬Ö¼ÔÚÇÔȡָ±êÓû§µÄÒøÐÐÐÅÏ¢¡£¡£¡£¡£¡£ÆäÊ×ÏÈÀûÓüÙ×°³ÉACSC¹Ù·½ÐÂÎŵĵç×ÓÓʼþ£¬£¬£¬£¬£¬·î¸æÊܺ¦ÕßµçÄÔÒѾ±»ÈëÇÖ£¬£¬£¬£¬£¬±ØÒªÍ¨¹ý¶ñÒâÁ´½ÓÏÂÔØ¼ÙµÄɱ¶¾Èí¼þ¡£¡£¡£¡£¡£Ò»µ©Óû§ÏÂÔØ²¢Æô¶¯ºó£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ¾Í¿ÉÄÜÊÕÊÜÆäÍÆËã»ú²¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£³ý´ËÖ®±í£¬£¬£¬£¬£¬¸ÃÍŻﻹ»áÀûÓÃαÔìµÄµç»°ºÅÂë¸øÊܺ¦Õß´òµç»°£¬£¬£¬£¬£¬ÒªÇóËûÃÇÏÂÔØTeamViewer»òAnyDeskÀûÓ㬣¬£¬£¬£¬ÒÔ·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/australian-cybersecurity-agency-used-as-cover-in-malware-campaign/
4.Check Point°ä²¼Õë¶ÔÈ«ÇòÒ½ÁÆ»ú¹¹µÄ¹¥»÷µÄ·ÖÎö»ã±¨

Check Point°ä²¼ÁËÕë¶ÔÈ«ÇòÒ½ÁÆ»ú¹¹µÄ¹¥»÷µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬×Ô2020Äê11ÔÂ1ÈÕÒÔÀ´È«ÇòÕë¶ÔÒ½ÁÆÐÐÒµµÄ¹¥»÷ÊýÁ¿Ôö³¤Á˳¬¹ý45£¥£¬£¬£¬£¬£¬¶øÕë¶ÔÆäËûÐÐÒµµÄ¹¥»÷¾ùÔÈÔö³¤ÁË22£¥£»£»£»£»£»£»£»ÔÚ11ÔÂÿ¸ö×éÖ¯¾ùÔÈÿÖÜÔâµ½626´Î¹¥»÷£»£»£»£»£»£»£»Éæ¼°µ½ÀÕË÷Èí¼þ¡¢½©Ê¬ÍøÂç¡¢Ô¶³Ì´úÂëÖ´ÐкÍDDoSµÄ¹¥»÷ÔÚ11Ô·ݶ¼ÓÐËùÔö³¤£¬£¬£¬£¬£¬¶øÀÕË÷Èí¼þ¹¥»÷µÄÔö³¤×îΪÏÔÖø£»£»£»£»£»£»£»¹¥»÷ÖÐʹÓõÄÖØÒªÀÕË÷Èí¼þÊÇRyuk£¬£¬£¬£¬£¬Æä´ÎÊÇSodinokibi¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.checkpoint.com/2021/01/05/attacks-targeting-healthcare-organizations-spike-globally-as-covid-19-cases-rise-again/
5.ºÚ¿Í¹«¿ª1ÍòÕÅExpressÐÅÓþ¿¨Êý¾Ý²¢³ÆÓûÏúÊÛ¸ü¶à

ºÚ¿Í¹«¿ª1ÍòÕÅExpressÐÅÓþ¿¨Êý¾Ý£¬£¬£¬£¬£¬²¢³ÆÓûÏúÊÛ¸ü¶àExpress¡¢SantanderºÍBanamexÒøÐпͻ§µÄÐÅÓþ¿¨ÐÅÏ¢¡£¡£¡£¡£¡£Õâ´Îй¶µÄ10000±Ê¼Í¼Ô̺¬ÆëÈ«µÄÃÀ¹úExpressÐÅÓþ¿¨ºÅºÍ¿Í»§µÄÓ×ÎÒÉí·ÝÐÅÏ¢£¨PII£©£¬£¬£¬£¬£¬ÈçÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚºÍÐԱ𣬣¬£¬£¬£¬µ«ÊDz¢Ã»ÓÐÐÅÓþ¿¨µÄµ½ÆÚÈÕÆÚ¡¢ÃÜÂë»òÃô¸ÐµÄ²ÆÕþÊý¾Ý¡£¡£¡£¡£¡£Âô·½°µÊ¾²¢²»ÏúÊÛÃÜÂëºÍÉí·ÝÖ¤ºÅµÈ¸öÈËÊý¾Ý£¬£¬£¬£¬£¬ÕâЩÊý¾Ý½ö»á±»ÓÃÓÚÀ¬»øÓʼþ»òÓªÏú¸æ°×¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-posts-data-of-10-000-american-express-accounts-for-free/
6.NISSAN±±ÃÀ·Ö¹«Ë¾ÒòGit·þÎñÆ÷ÅäÖÃÃýÎóµ¼ÖÂÔ´´úÂëй¶

NISSAN±±ÃÀ·Ö¹«Ë¾ÒòÔÚBitbucket Git·þÎñÆ÷ÖÐʹÓÃÁËĬÈÏÍ´´¦admin/admin£¬£¬£¬£¬£¬µ¼ÖÂÆäÒÆ¶¯ÀûÓ÷¨Ê½ºÍÄÚ²¿¹¤¾ßµÄÔ´´úÂëй¶¡£¡£¡£¡£¡£Õâ´Îй¶µÄÔ´´úÂëÔ̺¬ÈÕ²úNA MobileÀûÓá¢ÈÕ²úASISTÕï¶Ï¹¤¾ßµÄijЩ²¿ÃÅ¡¢¾ÏúóÒ×Îñϵͳ/¾ÏúÉÌÃÅ»§¡¢ÈÕ²úÄÚ²¿Ö÷Ìâmobile library¡¢ÈÕ²ú/Ó¢·ÆÄáµÏNCAR/ICAR·þÎñ¡¢¿Í»§»ñÈ¡ºÍ±£Áô¹¤¾ß¡¢ÏúÊÛ/Êг¡×êÑй¤¾ß+Êý¾Ý¡¢¸÷ÀàÓªÏú¹¤¾ß¡¢³µÁ¾ÎïÁ÷ÃÅ»§¡¢³µÁ¾ÁªÍø·þÎñ/ÈÕ²úÁªÍø¡¢ÒÔ¼°ÆäËü¸÷Ààºó¶ËºÍÄÚ²¿¹¤¾ßµÈ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/nissan-source-code-leaked-online-after-git-repo-misconfiguration/


¾©¹«Íø°²±¸11010802024551ºÅ