жñÒâÈí¼þSilver SparrowÒÑϰȾ½ü3Íǫ̀MacÉ豸£»£»£»£»£»Bitglass°ä²¼2020ÄêÒ½ÁƱ£½¡ÐÅϢй¶µÄ»ØÊ׻㱨
°ä²¼¹¦·ò 2021-02-231.жñÒâÈí¼þSilver SparrowÒÑϰȾ½ü3Íǫ̀MacÉ豸

Red Canary×êÑÐÈËÔ±·¢ÏÖÕë¶ÔMacÉ豸µÄжñÒâÈí¼þSilver Sparrow¡£¡£¡£¡£¡£¡£¡£½ØÖÁ2ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬Silver SparrowÒÑÔÚ153¸ö¹ú¶ÈºÍµØÓòϰȾÁË29139¸ömacOSÖÕ¶Ë£¬£¬£¬£¬£¬£¬²¢ÔÚÃÀ¹ú¡¢Ó¢¹ú¡¢¼ÓÄô󡢷¨¹úºÍµÂ¹ú´óÁ¿´«²¼¡£¡£¡£¡£¡£¡£¡£Óë´óÎÞÊýʹÓÃ'preinstall'ºÍ'postinstall'¾ç±¾µÄ¶ñÒâÈí¼þ·ÖÆç£¬£¬£¬£¬£¬£¬Silver SparrowÀûÓÃJavaScriptÖ´ÐкÅÁ£¬£¬£¬£¬£¬´Ó¶øºÜÄÑÆ¾¾ÝºÅÁîÐвÎÊý¼ì²â¶ñÒâ»î¶¯¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þµÄÕæÕýÖ÷ÕÅ´Ë¿ÌÒÀÈ»ÊǸöÃÕ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/30000-macs-infected-with-new-silver-sparrow-malware/
2.Bitglass°ä²¼2020ÄêÒ½ÁƱ£½¡ÐÅϢй¶µÄ»ØÊ׻㱨

Bitglass°ä²¼ÁË2020ÄêÒ½ÁƱ£½¡ÐÅϢй¶µÄ»ØÊ׻㱨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬µ½2020Ä꣬£¬£¬£¬£¬£¬ÃÀ¹ú¹²ÓÐ599ÆðÒ½±£Êý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬±ÈÉÏÒ»ÄêÔö³¤ÁË55.1£¥£¬£¬£¬£¬£¬£¬Ó°ÏìÁË2640ÍòÈË¡£¡£¡£¡£¡£¡£¡£¾ø´óÎÞÊý£¨67£¥£©Ð¹Â¶ÊÂÎñ¹éÒòÓÚÀ´×Ô±í²¿¹¥»÷Õߵġ°ºÚ¿ÍºÍITÊÂÎñ¡±£¬£¬£¬£¬£¬£¬Æäй¶µÄÊý¾ÝÕ¼±È´ï91£¥ÒÔÉÏ¡£¡£¡£¡£¡£¡£¡£Æä´ÎÊǶ˵ãÉ豸µÄÃÔʧ»òʧÇÔ£¬£¬£¬£¬£¬£¬Ó°ÏìÁË584000¶àÈË£¬£¬£¬£¬£¬£¬ÒÔ¼°ÏµÍ³Î´¾ÊÚȨµØÐ¹Â¶Êý¾Ý£¬£¬£¬£¬£¬£¬Ó°Ïì763000ÈË¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÊܺ¦ÈËÊý±È2019ÄêµÄ2750ÍòÈËÂÔÓнµÂ䣬£¬£¬£¬£¬£¬µ«Ã¿Ìõй¶Êý¾ÝµÄ¾ùÔȳɱ¾´Ó429ÃÀÔªÔö³¤µ½499ÃÀÔª£¬£¬£¬£¬£¬£¬×ܹ²Ôì³É132ÒÚÃÀÔªËðʧ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bitglass.com/blog/hacking-and-it-incidents-on-the-rise
3.Malwarebytes°ä²¼2020Äê¶ñÒâÈí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨

Malwarebytes°ä²¼ÁË2020Äê¶ñÒâÈí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬WindowsÉ϶ñÒâÈí¼þµÄ¼ìÕÉÁ¿½µÂäÁË24£¥£¬£¬£¬£¬£¬£¬ºÚ¿Í¹¤¾ßºÍ¼äµýÈí¼þµÄ¼ìÕÉÁ¿¼±¾çÔö³¤£¬£¬£¬£¬£¬£¬Ôö³¤ÁË147£¥ºÍ24£¥¡£¡£¡£¡£¡£¡£¡£EmotetºÍTrickbot±ðÀë½µÂäÁË89£¥ºÍ68£¥¡£¡£¡£¡£¡£¡£¡£Õë¶ÔũҵÐÐÒµµÄ¶ñÒâÈí¼þ¼ìÕÉÁ¿Ôö³¤ÁË607£¥£¬£¬£¬£¬£¬£¬Ê³Æ·ºÍÒûÁÏÐÐÒµµÄ¼ìÕÉÁ¿Ôö³¤ÁË67£¥£¬£¬£¬£¬£¬£¬Ôì×÷Òµ¡¢Ò½ÁƱ£½¡ºÍÒ½ÁÆÒÔ¼°Æû³µµÈ¸ü´«Í³µÄÐÐÒµÖжñÒâÈí¼þµÄ¼ìÕÉÁ¿¾ùÓÐËù½µÂ䣬£¬£¬£¬£¬£¬±ðÀëΪ17£¥¡¢22£¥ºÍ18£¥¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/reports/2021/02/state-of-malware-2021-report/
4.Ó¡¶ÈµÄ·ÀÓùϵͳÔâµ½ÈëÇÖ£¬£¬£¬£¬£¬£¬Ä¿Ç°µ±¾ÖÉÐδ²ÉÈ¡²¹¾È´ëÊ©

Ó¡¶ÈµÄ·ÀÓùϵͳÔâµ½ÃûΪSakura SamuraiµÄºÚ¿ÍµÄÈëÇÖ£¬£¬£¬£¬£¬£¬Ä¿Ç°µ±¾ÖÉÐδ²ÉÈ¡²¹¾È´ëÊ©¡£¡£¡£¡£¡£¡£¡£Í¨¹ý¶ÈÎö·¢ÏÖ£¬£¬£¬£¬£¬£¬Ôâµ½¹¥»÷µÄ·þÎñÆ÷Éæ¼°µ½´óÁ¿²ÆÕþ¼Í¼±¸·Ý¡¢ÊýÊ®·ÝÔ̺¬Êܺ¦ÕßÊý¾ÝµÄ¾¯·½»ã±¨¡¢¼«ÆäÃô¸ÐÈ·µ±¾ÖϵͳºÍÆäËûÐÅÏ¢Êý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÄܹ»»ñµÃ³¬¹ý13000¶à¸öµ±¾Ö¹ÍÔ±ºÍ¹«ÃñµÄÓ×ÎÒÉí·ÝÐÅÏ¢£¨PII£©£¬£¬£¬£¬£¬£¬ÒÔ¼°Äܹ»²é¿´¸Ã¹ú¾¯Ô±¾ÖµÄ·¨Ò½»ã±¨¡¢¹¤¾ßºÍÆäËûÃô¸ÐµÄ¾¯¾Ö¼Í¼µÄÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬¸Ã¹úµ±¾ÖÈÔδ²ÉÈ¡²¹¾È´ëÊ©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.thehindu.com/sci-tech/technology/indias-cyber-defenses-breached-and-reported-govt-yet-to-fix-it/article33888110.ece
5.Tokyo Shoko³Æ2020ÄêÈÕ±¾ÓÐ2515ÍòÈËÔâÐÅϢй¶

¶«¾©ÉÌÊÂ×êÑÐÓÐÏÞ¹«Ë¾£¨Tokyo Shoko Research Ltd£©³Æ2020ÄêÈÕ±¾ÓÐ2515ÍòÈËÔâÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¾Ý¸Ã¹«Ë¾½øÐеÄÒ»Ïîµ÷²éÏÔʾ£¬£¬£¬£¬£¬£¬µ½2020Ä꣬£¬£¬£¬£¬£¬ÈÕ±¾¹²ÓÐ88¼ÒÉÏÊй«Ë¾¼°Æä×Ó¹«Ë¾µÄÓ×ÎÒÐÅϢй¶»òÃÔʧ£¬£¬£¬£¬£¬£¬Éæ¼°µ½2515ÍòÈË£¬£¬£¬£¬£¬£¬ÕâÊÇ×Ô2012ÄêÒÔÀ´µÄ·åÖµ¡£¡£¡£¡£¡£¡£¡£ÍÆËã»ú²¡¶¾ºÍδ¾ÊÚȨµÄ½Ó¼ûµ¼ÖµÄй¶ÊÂÎñÔ¼Õ¼×ÜÊýµÄÒ»°ë£¬£¬£¬£¬£¬£¬Îó·¢Ë͵ç×ÓÓʼþÖ®ÀàµÄÃýÎóÔ¼Õ¼30£¥¡£¡£¡£¡£¡£¡£¡£ÐÅϢй¶°¸¼þ¼¤ÔöµÄ±³ºó£¬£¬£¬£¬£¬£¬ÊǺܶ๫˾¶¼ÔÚÕùÏàÍÆ¶¯Êý×Ö»¯ºÍÔ¶³Ì¹¤×÷£¬£¬£¬£¬£¬£¬µ«¿ÉÄÜÎÞ·¨²ÉÈ¡×ã¹»µÄ°²È«´ëÊ©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.japantimes.co.jp/news/2021/02/21/national/crime-legal/computer-viruses-big-data-cybersecurity/
6.Check Point·¢ÏÖOffice¶ñÒâÈí¼þÌìÉúÆ÷APOMacroSploit

Check PointµÄ×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÃûΪAPOMacroSploitµÄÐÂOffice¶ñÒâÈí¼þÌìÉúÆ÷¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¿É´´½¨ÍøÂç´¹µö¹¥»÷ËùʹÓõıøÆ÷»¯ExcelÎĵµ£¬£¬£¬£¬£¬£¬Òѱ»ÓÃÓÚÕë¶ÔÈ«Çò80¶à¸ö¿Í»§µÄ¹¥»÷ÖС£¡£¡£¡£¡£¡£¡£Ê¹ÓÃAPOMacroSploit builder´´½¨µÄExcelÎĵµ¿ÉÄÜÈÆ¹ýɱ¶¾Èí¼þ¡¢Windows·´¶ñÒâÈí¼þɨÃè½çÃæ(AMSI)¡¢GmailºÍÆäËûµç×ÓÓʼþµÄ´¹µö¼ì²â¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±´§Ä¦£¬£¬£¬£¬£¬£¬ÆäÊÇÓÉ·¨¹úºÚ¿ÍApocaliptiqueºÍNitrix¿ª·¢µÄµÄ£¬£¬£¬£¬£¬£¬²¢ÔÚHackForums.netÉϽøÐÐÏúÊÛ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/114880/cyber-crime/apomacrosploit-macro-builder.html


¾©¹«Íø°²±¸11010802024551ºÅ