µ¤ÂóÖÐÑëÒøÐÐºÍÆäËü7¼Ò¸öÈËÒøÐеÄÍøÕ¾Ôâµ½DDoS¹¥»÷

°ä²¼¹¦·ò 2023-01-12
1¡¢µ¤ÂóÖÐÑëÒøÐÐºÍÆäËü7¼Ò¸öÈËÒøÐеÄÍøÕ¾Ôâµ½DDoS¹¥»÷

      

·͸Éç1ÔÂ11ÈÕ±¨Â·£¬£¬£¬£¬£¬µ¤ÂóÖÐÑëÒøÐкÍΪ½ðÈÚÐÐÒµ¿ª·¢IT½â¾ö¹æ»®µÄ¹«Ë¾BankdataµÄÍøÕ¾Ôâµ½DDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÑëÐн²»°È˰µÊ¾£¬£¬£¬£¬£¬ÆäÍøÕ¾ÔÚÖܶþÏÂÎçÕý³£ÔËÐУ¬£¬£¬£¬£¬Õâ´Î¹¥»÷²¢Î´Ó°Ïì¸ÃÒøÐÐµÄÆäËüϵͳ»òÈÕ³£ÔËÓª¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ÔÚBankdataÔâµ½DDoS¹¥»÷ºó£¬£¬£¬£¬£¬ÆäËü7¼Ò¸öÈËÒøÐÐÍøÕ¾µÄ½Ó¼ûÔÚÖܶþÒ²Êܵ½ÁËÏÞ¶È£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬µ¤Âó×î´óµÄÁ½¼ÒÒøÐÐJyske Bank(JYSK.CO)ºÍSydbank(SYDB.CO)¡£¡£¡£¡£¡£¡£¡£


https://www.reuters.com/technology/denmarks-central-bank-website-hit-by-cyberattack-2023-01-10/


2¡¢ESET·¢ÏÖStrongPityÍÅ»ï·Ö·¢Ä¾Âí»¯TelegramµÄ»î¶¯

      

1ÔÂ10ÈÕ£¬£¬£¬£¬£¬ESET³ÆÆä·¢ÏÖÁËAPT×éÖ¯StrongPityµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯×Ô2021Äê11ÔÂÆðÍ·»îÔ¾£¬£¬£¬£¬£¬Í¨¹ýÒ»¸ö¼ÙÒâShagleµÄÍøÕ¾·Ö·¢¶ñÒâÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£¡£ShagleÊÇÒ»¸öºÏ·¨µÄËæ»úÊÓÆµÌ¸ÌìÆ½Ì¨£¬£¬£¬£¬£¬µ«Ëü²¢Ã»ÓÐÒÆ¶¯ÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£¡£¶ñÒâÀûÓÃÊÇÒ»¸öÃûΪvideo.apkµÄAPKÎļþ£¬£¬£¬£¬£¬ÕâÊǺϷ¨TelegramÀûÓõÄľÂí»¯°æ±¾£¬£¬£¬£¬£¬Ê¹ÓÃÁËStrongPityºóÃÅ´úÂë³Áдò°üÀ´¼ÙÒâShagleÒÆ¶¯ÀûÓᣡ£¡£¡£¡£¡£¡£×°Öú󣬣¬£¬£¬£¬´ËÀûÓÿɽøÐжàÖÖ¼äµý»î¶¯£¬£¬£¬£¬£¬Ô̺¬¼à¿Øµç»°¡¢ÍøÂç¶ÌÐźͻñÈ¡ÁªÏµÈËÁбí¡£¡£¡£¡£¡£¡£¡£


https://www.welivesecurity.com/2023/01/10/strongpity-espionage-campaign-targeting-android-users/


3¡¢ÐµÄDark PinkÍÅ»ïÀûÓÃ×Ô½ç˵¶ñÒâÈí¼þ¹¥»÷¾üÕþ×éÖ¯

      

Group-IBÓÚ1ÔÂ11ÈÕÅû¶ÁËеÄAPT×éÖ¯Dark PinkÕë¶ÔÑÇÌ«ºÍÅ·ÖÞµØÓòÈ·µ±¾ÖºÍ¾üÊÂ×éÖ¯µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Ê¼ÓÚÓã²æÊ½´¹µöÓʼþ£¬£¬£¬£¬£¬ÆäʹÓõÄ×Ô½ç˵¹¤¾ß°ü¿ÉÓÃÓÚÇÔÊØÐÅÏ¢²¢Í¨¹ýUSBÇý¶¯Æ÷´«²¼¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹Í¨¹ýDLL²à¼ÓÔØºÍÊÂÎñ´¥·¢µÄ²½Ö裬£¬£¬£¬£¬ÔÚ±»Ï°È¾µÄϵͳÉÏÔËÐÐÆäpayload¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷µÄÖ÷ÌâÊǼäµý»î¶¯£¬£¬£¬£¬£¬Ö¼ÔÚ´ÓÖ¸±êµÄÉ豸ºÍÍøÂçÖÐÇÔÈ¡Îļþ¡¢Âó¿Ë·çÒôƵºÍmessengerÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Group-IB³Æ¸ÃÍÅ»ïÔÚ2022Äê6ÔÂ12ÔÂÒÑÌáÒéÖÁÉÙ7´Î³É¹¦µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£


https://www.group-ib.com/media-center/press-releases/dark-pink-apt/


4¡¢³¬¹ý1300¸öÓò¼ÙÒâAnyDeskÍøÕ¾·Ö·¢Vidar Stealer

      

¾ÝýÌå1ÔÂ10ÈÕ±¨Â·£¬£¬£¬£¬£¬Ò»³¡Ê¹ÓÃÁË1300¶à¸öÓò¼ÙÒâAnyDesk¹Ù·½ÍøÕ¾µÄ´ó¹æÄ£»£»£» £»£»£»î¶¯ÔÚ½øÐÐÖС£¡£¡£¡£¡£¡£¡£ÕâЩÓò¶¼½«Óû§³Á¶¨Ïòµ½Í³Ò»¸öDropboxÁ´½Ó£¬£¬£¬£¬£¬Ö¼±ÉÈËÔØVidar stealer£¬£¬£¬£¬£¬ÇÒËùÓÐÓò¶¼½âÎöΪһÑùµÄIPµØÖ·185.149.120[.]9¡£¡£¡£¡£¡£¡£¡£½ØÖÁĿǰ£¬£¬£¬£¬£¬´óÎÞÊýÓòÒÀÈ»ÔÚÏߣ¬£¬£¬£¬£¬¶øÆäËüÓòÒѱ»×¢²áÉ̻㱨²¢ÏÂÏß»ò±»AV¹¤¾ß×èÖ¹¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚAnyDeskµÄÊ¢ÐÐÐÔ£¬£¬£¬£¬£¬Æäʱʱ±»ÀÄÓÃÀ´·Ö·¢¶ñÒâÈí¼þ£¬£¬£¬£¬£¬CybleÔÚ2022Äê10ÔÂÒ²Ôø·¢ÏÖͨ¹ýAnyDesk´¹µöÍøÕ¾·Ö·¢Mitsu StealerµÄ»î¶¯¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/over-1-300-fake-anydesk-sites-push-vidar-info-stealing-malware/


5¡¢UptycsÅû¶Õë¶ÔÒâ´óÀûµÄInfostealer¶ñÒâÈí¼þ»î¶¯

      

UptycsÔÚ1ÔÂ6ÈÕ°ä²¼ÁËÕë¶ÔÒâ´óÀûµÄInfostealer¶ñÒâÈí¼þ»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¹¥»÷»î¶¯µÄ¶à½×¶ÎϰȾÁ´´ÓÒÔ·¢Æ±ÎªÖ÷ÌâµÄ´¹µöÓʼþÆðÍ·£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Ò»¸öÁ´½Ó£¬£¬£¬£¬£¬µã»÷Á´½Ó»áÏÂÔØÒ»¸öÊÜÃÜÂë±£»£»£» £»£»£»¤µÄZIP´æµµÎļþ£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Ò»¸ö.LNKÎļþºÍÒ»¸ö.BATÎļþ¡£¡£¡£¡£¡£¡£¡£Åú´¦Öþ籾»á´ÓGitHub´æ´¢¿âÖÐ×°ÖöñÒâÈí¼þpayload¡£¡£¡£¡£¡£¡£¡£×°Öú󣬣¬£¬£¬£¬»ùÓÚC#µÄ¶ñÒâÈí¼þ»áÇÔȡϵͳÐÅÏ¢¡¢¼ÓÃÜÇ®°ü¡¢ä¯ÀÀÆ÷º¹Çà¼Í¼¡¢cookieÒÔ¼°¼ÓÃÜÇ®°üµÄÍ´´¦µÈ¡£¡£¡£¡£¡£¡£¡£


https://www.uptycs.com/blog/infostealer-malware-attacks-targeting-italian-region/


6¡¢CiscoÌáÐѿͻ§°ÑÎÈEoL·ÓÉÆ÷ÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶

      

1ÔÂ11ÈÕ£¬£¬£¬£¬£¬Cisco°ä²¼°²È«¹«¸æÌáÐѿͻ§°ÑÎÈÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2023-20025£©¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶»áÓ°Ïì¶à¸öÒѶôÖÆÖ§³Ö(EoL)µÄVPN·ÓÉÆ÷£¬£¬£¬£¬£¬Ô̺¬Cisco Small Business RV016¡¢RV042¡¢RV042GºÍRV082·ÓÉÆ÷¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓø÷ì϶¿É»ñµÃroot½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬½«ÆäÓëÁíÒ»¸ö·ì϶£¨CVE-2023-2002£©½áºÏÀûÓÿÉÔڵײã²Ù×÷ϵͳÉÏÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°ÒÑÔÚÒ°±í·¢ÏÖ¿ÉÓõĸÅÏëÑéÖ¤·ì϶ÀûÓôúÂ룬£¬£¬£¬£¬ÖÎÀíÔ±Äܹ»Í¨¹ý½ûÓÃÔ¶³ÌÖÎÀí²¢×èÖ¹¶Ô¶Ë¿Ú443ºÍ60443µÄ½Ó¼ûÀ´»º½â·ì϶¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cisco-warns-of-auth-bypass-bug-with-public-exploit-in-eol-routers/