TrickBotбäÖÖ¿ÉÇÔÈ¡OpenSSHºÍOpenVPNÃÜÔ¿£»Raccoon Stealerй¥»÷»î¶¯ÖØÒªÕë¶Ô½ðÈÚ»ú¹¹
°ä²¼¹¦·ò 2019-11-25
Catch Hospitality Group¶à¼Ò²ÍÌüµÄPoSϵͳÔâ¶ñÒâÈí¼þ¹¥»÷£¬¿Í»§µÄÐÅÓþ¿¨ÐÅÏ¢±»ÇÔ¡£Æ¾¾Ý¸Ã¹«Ë¾°ä²¼µÄÊÂÎñ֪ͨ£¬Catch NYCºÍCatch RooftopµÄPoSϵͳÔÚ2019Äê3ÔÂ19ÈÕÖÁ10ÔÂ17ÈÕÖ®¼äϰȾÁ˶ñÒâÈí¼þ£¬¶øCatch SteakµÄϰȾ¹¦·òÔòΪ9ÔÂ17ÈÕÖÁ10ÔÂ17ÈÕ¡£¸Ã¶ñÒâÈí¼þ¿ÉÇÔÈ¡¿Í»§µÄÐÅÓþ¿¨ÐÅÏ¢£¬Ô̺¬¿¨ºÅ¡¢ÓÐЧÆÚºÍÄÚ²¿ÑéÖ¤Â룬´Ë±í£¬ÔÚijЩÇé¿öÏ¿ÉÄÜ»¹Ô̺¬¿Í»§µÄÐÕÃû¡£¸Ã¹«Ë¾³Æ²¢·ÇËùÓеÄPoSÉ豸¶¼±»Ï°È¾£¬ÆäËùʹÓõÄÁ½ÖÖPoSÉ豸ÖÐÖ»ÓаĘ́ʹÓõÄÉ豸Êܵ½Ó°Ïì¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/catch-restaurants-disclose-credit-card-stealing-malware-incident/2¡¢Waterloo BrewingÒòºÚ¿Í¹¥»÷Ëðʧ210ÍòÃÀÔª
Waterloo BrewingÔâºÚ¿Í¹¥»÷Ëðʧ210ÍòÃÀÔª¡£¸Ã¹«Ë¾Ð¹Â©³Æ´ËÊÂÎñÊÇһ·²úÉúÔÚ±¾Ô³õµÄÉç½»¹¤³ÌÍøÂç¹¥»÷£¬¹¥»÷Õß¼Ù×°³ÉծȨÈ˵ÄÔ±¹¤ÒªÇó½øÐÐÒøÐÐתÕË£¬¸Ã¹«Ë¾Ö±µ½±¾ÖܲÅÒâʶµ½Ô⵽ڲơ£¸Ã¹«Ë¾ÔÚÒ»·ÝÉêÃ÷ÖаµÊ¾¿ÉÄÜÎÞ·¨ÊÕ»ØÈ«Êý»ò²¿ÃÅ×ʽð¡£ÔÚµÃ֪ڲƺ󣬸ù«Ë¾¶ÔÒøÐÐÕË»§ÖеÄÂòÂô¼°ÄÚ²¿ÏµÍ³ºÍÍÆËã»úÍøÂç½øÐÐÁËÉó²é£¬Ä¿Ç°¸Ã¹«Ë¾²»ÒÔΪÆäϵͳÔâµ½·ÛË飬Ҳ²»ÒÔΪÆä¿Í»§µÄÈκÎÓ×ÎÒÐÅÏ¢´æÔÚ·çÏÕ¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/waterloo-brewing-admits-to-having-lost-21-million-in-a-social-engineering-attack-73c15cf53¡¢ÃÀ¹úÁ¬Ëø·¹µêChurch's Chicken¶à¼Ò²ÍÌüÔâºÚ¿Í¹¥»÷
ÃÀ¹úÁ¬Ëø·¹µêChurch's ChickenÔâºÚ¿Í¹¥»÷£¬¸Ã¹«Ë¾°µÊ¾ÓÃÓÚ´¦Öø¶¿îµÄÍÆËã»úϵͳ´æÔÚδÊÚȨµÄ¿ÉÒɻ£¬¿Í»§Êý¾Ý¿ÉÄÜй¶¡£¸ÃÊÂÎñ²úÉúÔÚ10Ôµף¬¿ÉÄÜÓ°ÏìµÄÊý¾ÝÔ̺¬¿Í»§µÄÐÅÓþ¿¨ºÅÂë¡¢ÐÕÃûºÍÓÐЧÆÚ¡£Church's ChickenÔÚÈ«ÊÀ½ç¾Óª×Ŷà¼Ò²Í¹Ý£¬µ«¸Ã¹«Ë¾°µÊ¾Ö»ÓÐÃÀ¹úµÄ²¿ÃŲ͹ÝÊܵ½Ó°Ï졣Ŀǰµ÷²éÔÚ½øÐÐÖУ¬¸Ã¹«Ë¾ÈÔÔÚ³¢ÊÔÈ·¶¨ÊÜÓ°ÏìµÄ¾ßÌå²Í¹Ý¼°ÊÜÓ°Ï칦·ò¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/churchs-chicken-warns-of-possible/4¡¢ÐÂÔóÎ÷ÖÝÀûÎÄ˹¶ÙÑ§ÇøÔâÀÕË÷Èí¼þ¹¥»÷
ÐÂÔóÎ÷ÖÝÀûÎÄ˹¶Ù¹«Á¢Ñ§ÇøÓÚ11ÔÂ21ÈÕÊܵ½ÀÕË÷Èí¼þ¹¥»÷£¬¸ÃÑ§ÇøÒÑ֪ͨ·¨Âɲ¿ÃÅ£¬²¢ÔÚÓ밲ȫ¹«Ë¾ºÏ×÷µ÷²éºÍ¶ÔÆäϵͳ½øÐзÖÎö¡£¸ÃÑ§ÇøÖ¸³ö´óÎÞÊýѧÌ÷þÎñ¶¼ÒѸ´ÔÕý³£ÔËÐУ¬µ«ËüÃǵÄͨÀýµç»°ÏµÍ³ºÍ¼Ò³¤½Ó¼ûÃÅ»§ÍøÕ¾ÈÔ²»³ÉÓá£Ä¿Ç°ÉÐδÅû¶¹¥»÷ÕßÊÇÈôºÎ½øÈë¸ÃÑ§ÇøµÄÍøÂçµÄ£¬Ò²²»Ã÷ÏÔϰȾµÄÀÕË÷Èí¼þÀàÐÍ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/livingston-school-district-in-new-jersey-hit-with-ransomware/
5¡¢TrickBotбäÖÖ¿ÉÇÔÈ¡OpenSSHºÍOpenVPNÃÜÔ¿
Palo Alto NetworksµÄUnit 42×êÑÐÍŶӷ¢ÏÖTrickBotµÄбäÖÖ¸üÐÂÁËÃÜÂëÇÔȡģ¿é£¬¿ÉÓÃÓÚÇÔÈ¡OpenSSH˽ԿÒÔ¼°OpenVPNÃÜÂëºÍÅäÖÃÎļþ¡£¸ÃÄ£¿é²¢²»ÊÇÐÂÔö³¤µÄ£¬ÔçÔÚ2018Äê11ÔÂ×êÑÐÈËÔ±¾Í·¢ÏÖÁ˿ɴӶà¸öä¯ÀÀÆ÷ºÍÀûÓ÷¨Ê½ÖÐÇÔÈ¡ÃÜÂëµÄÄ£¿é¡£¸ÃÄ£¿éÔÚ2Ô·ݽøÐÐÁËÉý¼¶£¬Äܹ»ÇÔÈ¡VNC¡¢PuTTY¼°RDP·þÎñÖеÄÉí·ÝÑé֤ʹ´¦¡£´Ë¿Ì11Ô·Ý×êÑÐÈËÔ±·¢ÏÖ¸ÃÄ£¿éÔÚͨ¹ýHTTP POSTÒªÇó½«OpenSSH˽ԿÒÔ¼°OpenVPNÃÜÂëºÍÅäÖÃÎļþ·¢Ë͵½C2·þÎñÆ÷¡£ÕâÅú×¢×Ô2016Äê10Ô±»·¢ÏÖÒÔÀ´£¬TrickBotÒ»ÏòÔÚ¸üÐÂÆäÖ°ÄܺÍÄ£¿é¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/trickbot-trojan-getting-ready-to-steal-openssh-and-openvpn-keys/
6¡¢Raccoon Stealerй¥»÷»î¶¯ÖØÒªÕë¶Ô½ðÈÚ»ú¹¹
ƾ¾ÝCofense°ä²¼µÄ»ã±¨£¬¶ñÒâÈí¼þRaccoon Stealer±³ºóµÄ·¸×ï·Ö×ÓѡȡÁËÒ»ÖÖµ¥Ò»ÓÐЧµÄ¼¼ÊõÀ´Èƹý΢ÈíºÍÈüÃÅÌú¿ËµÄ·´À¬»øÓʼþÍø¹Ø£¬²¢ÔÚ×î½üµÄBEC¹¥»÷»î¶¯ÖÐÖØÒªÕë¶Ô½ðÈÚ»ú¹¹¡£¸Ã¶ñÒâÈí¼þͨ¹ýÓɺڿͽÚÔìµÄDropboxÕÊ»§ÖÐÍйܵÄ.IMGÎļþ·Ö·¢¡£Æ¾¾ÝCybereasonÔÚ10Ô°䲼µÄ×êÑл㱨£¬×Ô4ÔÂÒÔÀ´£¬¸Ã¶ñÒâÈí¼þÒÑϰȾÁËÉÏÍò¸öWindowsϵͳ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/raccoon-stealer-malware-scurries-past-microsoft-messaging-gateways/150545/


¾©¹«Íø°²±¸11010802024551ºÅ