ESTsecurityÅû¶ThalliumÕë¶Ô½ðÈÚÐÐÒµµÄ¹©¸øÁ´¹¥»÷£»NISSAN±±ÃÀ·Ö¹«Ë¾ÒòGit·þÎñÆ÷ÅäÖÃÃýÎóµ¼ÖÂÔ´´úÂëй¶

°ä²¼¹¦·ò 2021-01-07

1.ESTsecurityÅû¶ThalliumÕë¶Ô½ðÈÚÐÐÒµµÄ¹©¸øÁ´¹¥»÷


1.jpg


ESTsecurityÅû¶APT×éÖ¯Thallium£¨±ðÃûAPT37£©Õë¶Ô½ðÈÚÐÐÒµµÄ¹©¸øÁ´¹¥»÷¡£ÔÚÕâ´Î¹¥»÷»î¶¯ÖУ¬ºÚ¿Í´Û¸ÄÁËÒ»¿î¸öÈË¹ÉÆ±Í¶×ÊÐÅÏ¢´«µÝµÄÀûÓã¬ÒÔ·Ö·¢¶ñÒâ´úÂë¡£ThalliumÊ×ÏÈʹÓÃNullsoft¾ç±¾×°ÖÃϵͳ£¨NSIS£©ÌìÉúWindows¿ÉÖ´ÐÐÎļþ£¬¸ÃÎļþÔ̺¬ÁËÀ´×ԺϷ¨¹ÉƱͶ×ÊÀûÓ÷¨Ê½µÄºÏ·¨ÎļþºÍ¶ñÒâ´úÂë¡£µ±Óû§ÔÚ×°ÖÃÕæÕýµÄ¹ÉƱͶ×ÊÀûÓ÷¨Ê½Ê±£¬ºó¶ÜͬʱÔËÐжñÒâ¾ç±¾¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/north-korean-software-supply-chain-attack-targets-stock-investors/


2.Intezer·¢ÏÖElectroRAT²ØÓÚαÔìµÄ¼ÓÃÜÇ®±ÒÀûÓÃ


2.jpg


Intezer Labs·¢ÏÖElectroRAT²ØÓÚαÔìµÄ¼ÓÃÜÇ®±ÒÀûÓ᣸ûÔçÔÚ2020Äê1ÔÂ8ÈÕ¾ÍÆðÍ·»îÔ¾£¬µ«ÊÇÔÚ2020Äê12Ô²ű»·¢ÏÖ¡£ºÚ¿ÍÖØÒªÒÀÀµÓÚÈý¸öÓë¼ÓÃÜÇ®±ÒÓйصÄÀûÓÃJamm¡¢eTrade/KintumºÍDaoPokerÀ´·Ö·¢¶ñÒâÈí¼þElectroRAT¡£ElectroRATÓµÓм«Ç¿µÄÇÖÈëÐÔ£¬ÓµÓмüÅ̼ͼ¡¢½ØÍ¼¡¢ÉÏ´«Îļþ¡¢ÏÂÔØÎļþÒÔ¼°ÔÚÖ¸±ê½ÚÔį̀ÉÏÖ´ÐкÅÁîµÈÖ°ÄÜ£¬Ä¿Ç°¿ÉÄÜÒѾ­Ï°È¾ÁËԼĪ6500¸öÓû§¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hackers-target-cryptocurrency-users-with-new-electrorat-malware/


3.°Äµ±¾ÖÖҸ淸×ïÍÅ»ï¼ÙÒâÆäÍøÂ簲ȫÖÐÐÄ·Ö·¢¶ñÒâÈí¼þ


3.png


°Ä´óÀûÑǵ±¾ÖÖÒ¸æ³Æ£¬·¸×ïÍÅ»ï¼ÙÒâ°Ä´óÀûÑÇÍøÂ簲ȫÖÐÐÄ£¨ACSC£©·Ö·¢¶ñÒâÈí¼þ¡£¸ÃÍÅ»ïÓÕʹÊܺ¦Õß×°ÖÃÔ¶³ÌÖÎÀíºÍ×ÀÃæ¹²ÏíÈí¼þ£¬Ö¼ÔÚÇÔȡָ±êÓû§µÄÒøÐÐÐÅÏ¢¡£ÆäÊ×ÏÈÀûÓüÙ×°³ÉACSC¹Ù·½ÐÂÎŵĵç×ÓÓʼþ£¬·î¸æÊܺ¦ÕßµçÄÔÒѾ­±»ÈëÇÖ£¬±ØÒªÍ¨¹ý¶ñÒâÁ´½ÓÏÂÔØ¼ÙµÄɱ¶¾Èí¼þ¡£Ò»µ©Óû§ÏÂÔØ²¢Æô¶¯ºó£¬¸Ã¶ñÒâÈí¼þ¾Í¿ÉÄÜÊÕÊÜÆäÍÆËã»ú²¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£³ý´ËÖ®±í£¬¸ÃÍŻﻹ»áÀûÓÃαÔìµÄµç»°ºÅÂë¸øÊܺ¦Õß´òµç»°£¬ÒªÇóËûÃÇÏÂÔØTeamViewer»òAnyDeskÀûÓã¬ÒÔ·Ö·¢¶ñÒâÈí¼þ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/australian-cybersecurity-agency-used-as-cover-in-malware-campaign/


4.Check Point°ä²¼Õë¶ÔÈ«ÇòÒ½ÁÆ»ú¹¹µÄ¹¥»÷µÄ·ÖÎö»ã±¨


4.png


Check Point°ä²¼ÁËÕë¶ÔÈ«ÇòÒ½ÁÆ»ú¹¹µÄ¹¥»÷µÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬×Ô2020Äê11ÔÂ1ÈÕÒÔÀ´È«ÇòÕë¶ÔÒ½ÁÆÐÐÒµµÄ¹¥»÷ÊýÁ¿Ôö³¤Á˳¬¹ý45£¥£¬¶øÕë¶ÔÆäËûÐÐÒµµÄ¹¥»÷¾ùÔÈÔö³¤ÁË22£¥£»ÔÚ11ÔÂÿ¸ö×éÖ¯¾ùÔÈÿÖÜÔâµ½626´Î¹¥»÷£»Éæ¼°µ½ÀÕË÷Èí¼þ¡¢½©Ê¬ÍøÂç¡¢Ô¶³Ì´úÂëÖ´ÐкÍDDoSµÄ¹¥»÷ÔÚ11Ô·ݶ¼ÓÐËùÔö³¤£¬¶øÀÕË÷Èí¼þ¹¥»÷µÄÔö³¤×îΪÏÔÖø£»¹¥»÷ÖÐʹÓõÄÖØÒªÀÕË÷Èí¼þÊÇRyuk£¬Æä´ÎÊÇSodinokibi¡£


Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2021/01/05/attacks-targeting-healthcare-organizations-spike-globally-as-covid-19-cases-rise-again/


5.ºÚ¿Í¹«¿ª1ÍòÕÅExpressÐÅÓþ¿¨Êý¾Ý²¢³ÆÓûÏúÊÛ¸ü¶à


5.png


ºÚ¿Í¹«¿ª1ÍòÕÅExpressÐÅÓþ¿¨Êý¾Ý£¬²¢³ÆÓûÏúÊÛ¸ü¶àExpress¡¢SantanderºÍBanamexÒøÐпͻ§µÄÐÅÓþ¿¨ÐÅÏ¢¡£Õâ´Îй¶µÄ10000±Ê¼Í¼Ô̺¬ÆëÈ«µÄÃÀ¹úExpressÐÅÓþ¿¨ºÅºÍ¿Í»§µÄÓ×ÎÒÉí·ÝÐÅÏ¢£¨PII£©£¬ÈçÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚºÍÐԱ𣬵«ÊDz¢Ã»ÓÐÐÅÓþ¿¨µÄµ½ÆÚÈÕÆÚ¡¢ÃÜÂë»òÃô¸ÐµÄ²ÆÕþÊý¾Ý¡£Âô·½°µÊ¾²¢²»ÏúÊÛÃÜÂëºÍÉí·ÝÖ¤ºÅµÈ¸öÈËÊý¾Ý£¬ÕâЩÊý¾Ý½ö»á±»ÓÃÓÚÀ¬»øÓʼþ»òÓªÏú¸æ°×¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-posts-data-of-10-000-american-express-accounts-for-free/


6.NISSAN±±ÃÀ·Ö¹«Ë¾ÒòGit·þÎñÆ÷ÅäÖÃÃýÎóµ¼ÖÂÔ´´úÂëй¶


6.png


NISSAN±±ÃÀ·Ö¹«Ë¾ÒòÔÚBitbucket Git·þÎñÆ÷ÖÐʹÓÃÁËĬÈÏÍ´´¦admin/admin£¬µ¼ÖÂÆäÒÆ¶¯ÀûÓ÷¨Ê½ºÍÄÚ²¿¹¤¾ßµÄÔ´´úÂëй¶¡£Õâ´Îй¶µÄÔ´´úÂëÔ̺¬ÈÕ²úNA MobileÀûÓá¢ÈÕ²úASISTÕï¶Ï¹¤¾ßµÄijЩ²¿ÃÅ¡¢¾­ÏúóÒ×Îñϵͳ/¾­ÏúÉÌÃÅ»§¡¢ÈÕ²úÄÚ²¿Ö÷Ìâmobile library¡¢ÈÕ²ú/Ó¢·ÆÄáµÏNCAR/ICAR·þÎñ¡¢¿Í»§»ñÈ¡ºÍ±£Áô¹¤¾ß¡¢ÏúÊÛ/Êг¡×êÑй¤¾ß+Êý¾Ý¡¢¸÷ÀàÓªÏú¹¤¾ß¡¢³µÁ¾ÎïÁ÷ÃÅ»§¡¢³µÁ¾ÁªÍø·þÎñ/ÈÕ²úÁªÍø¡¢ÒÔ¼°ÆäËü¸÷Ààºó¶ËºÍÄÚ²¿¹¤¾ßµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/nissan-source-code-leaked-online-after-git-repo-misconfiguration/