ÐÂÀÕË÷Èí¼þAXLocker²»½ö¼ÓÃÜÎļþ»¹ÇÔÈ¡DiscordÕÊ»§

°ä²¼¹¦·ò 2022-11-22
1¡¢ÐÂÀÕË÷Èí¼þAXLocker²»½ö¼ÓÃÜÎļþ»¹ÇÔÈ¡DiscordÕÊ»§

CybleÔÚ11ÔÂ18ÈÕ³ÆÆä·¢ÏÖÒ»¸öÐÂÀÕË÷Èí¼þAXLocker£¬£¬£¬£¬£¬£¬£¬ £¬²»½ö»áͨ¹ý¼ÓÃÜÖ¸±êµÄÎļþÀÕË÷Êê½ð£¬£¬£¬£¬£¬£¬£¬ £¬»¹»áÇÔȡָ±êÓû§µÄDiscordÕÊ»§¡£¡£¡£ ¡£¡£¡£¡£µ±Óû§Ê¹ÓÃÍ´´¦µÇ¼Discordʱ£¬£¬£¬£¬£¬£¬£¬ £¬Æ½Ì¨»á·¢»¹±£ÁôÔÚÍÆËã»úÉϵÄÓû§Éí·ÝÑéÖ¤ÁîÅÆ£¬£¬£¬£¬£¬£¬£¬ £¬¶øºóʹÓôËÁîÅÆÒÔÓû§Éí·ÝµÇ¼»ò·¢³öAPIÒªÇóÒÔ¼ìË÷¹ØÓÚ¹ØÁªÕÊ»§µÄÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£×÷ΪÀÕË÷Èí¼þËüûÓÐÊ²Ã´ÌØÊâµÄ´¦Ëù£¬£¬£¬£¬£¬£¬£¬ £¬Ê¹ÓÃAESËã·¨¼ÓÃÜÎļþ£¬£¬£¬£¬£¬£¬£¬ £¬ÇÒ²»»áÔÚ¼ÓÃÜÎļþÉϸԶ×ãļþÀ©´óÃû¡£¡£¡£ ¡£¡£¡£¡£

https://blog.cyble.com/2022/11/18/axlocker-octocrypt-and-alice-leading-a-new-wave-of-ransomware-campaigns/

2¡¢DraftKingsµÄ¿Í»§Ô⵽ײ¿â¹¥»÷Ëðʧ½ü300000ÃÀÔª

¾Ý11ÔÂ21ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬ £¬ÌåÓý²©²Ê¹«Ë¾DraftKingsй©Æä¿Í»§Êܵ½×²¿â¹¥»÷µÄÓ°Ï죬£¬£¬£¬£¬£¬£¬ £¬Ôì³É300000ÃÀÔªËðʧ¡£¡£¡£ ¡£¡£¡£¡£ËùÓб»½Ù³ÖµÄÕË»§µÄ¹²Í¬µãËÆºõÊÇ×î³õµÄ5ÃÀÔª´æ¿î£¬£¬£¬£¬£¬£¬£¬ £¬¶øºó¹¥»÷Õß»á´Û¸ÄÃÜÂ룬£¬£¬£¬£¬£¬£¬ £¬ÔÚ·ÖÆçµÄµç»°ºÅÂëÉÏÆôÓÃ2FA£¬£¬£¬£¬£¬£¬£¬ £¬¶øºó´ÓÖ¸±ê¹ØÁªÒøÐÐÕË»§Öо¡¿ÉÄÜ¶àµØÌá¿î¡£¡£¡£ ¡£¡£¡£¡£DraftKingsÒÔΪ£¬£¬£¬£¬£¬£¬£¬ £¬ÕâЩ¿Í»§µÄµÇ¼ÐÅÏ¢ÊÇÔÚÆäËüÍøÕ¾ÉÏй¶µÄ£¬£¬£¬£¬£¬£¬£¬ £¬DraftKingsµÄϵͳ²¢Î´Ôâµ½ÈëÇÖ¡£¡£¡£ ¡£¡£¡£¡£Ä¿Ç°ÒÑÈ·¶¨Ëðʧ²»µ½300000ÃÀÔª£¬£¬£¬£¬£¬£¬£¬ £¬¸Ã¹«Ë¾³ïËãÅâ³¥ÊÜÓ°Ïì¿Í»§¡£¡£¡£ ¡£¡£¡£¡£

https://www.bleepingcomputer.com/news/security/hackers-steal-300-000-in-draftkings-credential-stuffing-attack/

3¡¢Unit221b¹«¿ªÁ½Äêǰ¿ª·¢µÄZeppelin½âÃÜÆ÷µÄϸ½Ú

¾ÝýÌå11ÔÂ18ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬ £¬Unit221bÔøÔÚZeppelinµÄ¼ÓÃÜ»úÔìÖз¢ÏÖ·ì϶²¢ÀûÓÃÆä¿ª·¢ÏàʼûÜÆ÷£¬£¬£¬£¬£¬£¬£¬ £¬ÓÚ2020ÄêÆðÍ·Ô®ÊÖ±»¹¥»÷µÄ×éÖ¯¸´Ô­Îļþ¡£¡£¡£ ¡£¡£¡£¡£ZeppelinʹÓÃһʱµÄRSA-512ÃÜÔ¿À´¼ÓÃÜAESÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬ £¬AESÃÜÔ¿´æ´¢ÔÚÿ¸ö¼ÓÃÜÎļþµÄÒ³½ÅÖУ¬£¬£¬£¬£¬£¬£¬ £¬Òò¶øÆÆ½âRSA-512ÃÜÔ¿¼´¿É½âÃÜÎļþ¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾ÒÑÔ­´òËãÓÚ2020Äê2Ô¹«¿ªÆä¼¼ÊõÐŽÚ£¬£¬£¬£¬£¬£¬£¬ £¬µ«ÎªÁËÏò¹¥»÷ÕßÒþÂ÷¸Ã·ì϶¶øÍƳÙÁË´òËã¡£¡£¡£ ¡£¡£¡£¡£ÓÉÓÚ×î½ü¼¸¸öÔÂZeppelinµÄ±»¹¥»÷Ö¸±êµÄÊýÁ¿´ó·ù½µÂ䣬£¬£¬£¬£¬£¬£¬ £¬ËûÃǾö¶¨¹«¿ªËùÓÐϸ½Ú¡£¡£¡£ ¡£¡£¡£¡£

https://www.bleepingcomputer.com/news/security/researchers-secretly-helped-decrypt-zeppelin-ransomware-for-2-years/

4¡¢CheckmarxÅû¶WASPÕë¶ÔPython¿ª·¢ÈËÔ±µÄ¹©¸øÁ´¹¥»÷

11ÔÂ18ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬ £¬Checkmarx·¢ÏÖÁËһ·³ÖÐøµÄ¹©¸øÁ´¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬ £¬À´×ÔÆä×·×ÙΪWASPµÄ¹¥»÷ÍŻ£¬£¬£¬£¬£¬£¬ £¬ÖØÒªÕë¶ÔPython¿ª·¢ÈËÔ±¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷ÕßʹÓÃPython°üÀ´·Ö·¢¶à̬¶ñÒâÈí¼þW4SP Stealer¡£¡£¡£ ¡£¡£¡£¡£¶ñÒâ´úÂë¿ÉÄÜÇÔȡָ±êDiscordÕÊ»§¡¢ÃÜÂë¡¢¼ÓÃÜÇ®°üºÍÐÅÓþ¿¨µÈÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ £¬¶øºóͨ¹ýÓ²±àÂëµÄDiscord webhookµØÖ·½«±»µÁÊý¾Ý·¢Ëͻع¥»÷Õß¡£¡£¡£ ¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßʹÓÃÒþдÊõÀ´ÌáÈ¡°µ²ØÔÚImgurÉϵÄͼÏñÎļþÖеĶñÒâÈí¼þpayload¡£¡£¡£ ¡£¡£¡£¡£Ä¿Ç°ÒѺ±¼û°Ù¸öÓû§Ôâµ½¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£

https://thehackernews.com/2022/11/w4sp-stealer-constantly-targeting.html

5¡¢BlackBerry¼ì²âµ½ARCrypterÕë¶ÔÈ«Çò×éÖ¯µÄ¹¥»÷»î¶¯

11ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬ £¬BlackBerry°ä²¼»ã±¨³ÆARCrypterµÄ¹¥»÷ÁìÓòÒÑ´ÓÀ­¶¡ÃÀÖÞÀ©´óµ½È«Çò¡£¡£¡£ ¡£¡£¡£¡£½ñÄê8Ô£¬£¬£¬£¬£¬£¬£¬ £¬¸ÃÀÕË÷Èí¼þÔø¹¥»÷ÁËÖÇÀûµÄÒ»¸öµ±¾Ö»ú¹¹ £¬£¬£¬£¬£¬£¬£¬ £¬²¢ÔÚ10Ô¹¥»÷Á˸çÂ×±ÈÑǹú¶ÈʳƷºÍÒ©Îï¼à¶½×êÑÐËù¡£¡£¡£ ¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬ £¬¹¥»÷ý½éÒÀȻδ֪£¬£¬£¬£¬£¬£¬£¬ £¬µ«×êÑÐÈËÔ¹ØÒµ½ÁËÁ½¸öAnonFiles URL£¬£¬£¬£¬£¬£¬£¬ £¬ËüÃÇÓÃ×÷¡°win.exe¡±ºÍ¡°win.zip¡±µÄÏÂÔØ¡£¡£¡£ ¡£¡£¡£¡£DropperÔ̺¬Á½¸öÎļþBINºÍHTML£¬£¬£¬£¬£¬£¬£¬ £¬ÆäÖÐHTML´æ´¢Êê½ð¼Í¼£¬£¬£¬£¬£¬£¬£¬ £¬BINÔ̺¬±ØÒªÃÜÂëµÄ¼ÓÃÜÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£×êÑÐÈËÔ±ÈÔÎÞ·¨È·¶¨BINµÄ½âÃÜÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬ £¬µ«´§¶ÈµÚ¶þ¸öpayloadÊÇARCrypterÀÕË÷Èí¼þ¡£¡£¡£ ¡£¡£¡£¡£

https://blogs.blackberry.com/en/2022/11/arcrypter-ransomware-expands-its-operations-from-latin-america-to-the-world

6¡¢Kaspersky°ä²¼2022ÄêµÚÈý¼¾¶ÈITÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨

11ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬£¬ £¬Kaspersky°ä²¼ÁË2022ÄêµÚÈý¼¾¶ÈITÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£ ¡£¡£¡£¡£»ã±¨Ö¸³öÁËQ3ÓÐÕë¶ÔÐԵĹ¥»÷£¬£¬£¬£¬£¬£¬£¬ £¬Ô̺¬¸´ÔÓµÄUEFI rootkit CosmicStrand£»£»£»£»£»£»Andariel·Ö·¢DTrackºÍMauiÀÕË÷Èí¼þ£»£»£»£»£»£»DeathStalker³ÖÐø¹¥»÷±í»ãºÍ¼ÓÃÜÇ®±ÒÂòÂôËù£»£»£»£»£»£»KimsukyµÄGoldDragon¼¯ÈººÍC2²Ù×÷£»£»£»£»£»£»¶Ô¹¤ÒµÆóÒµµÄÕë¶ÔÐÔ¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£»ã±¨»¹¹«¿ªÁËÆäËü¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬ £¬ÈçPrilex¡¢LunaºÍBlack Basta¡¢ÔÚÏß´úÂë´æ´¢¿âÖеĶñÒâ°ü¡¢Õë¶ÔÓÎÏ·Íæ¼ÒµÄÍøÂçÍþв¡¢NullMixerºÍä¯ÀÀÆ÷ÖеÄDZÔÚÍþв¡£¡£¡£ ¡£¡£¡£¡£

https://securelist.com/it-threat-evolution-q3-2022/107957/