ÃÀ¹úºÍ±£¼ÓÀûÑǽáºÏµ·»ÙNetWalker£¬ÖÁÉÙÓ¯Àû2760ÍòÃÀÔª£»×êÑÐÈËÔ±Åû¶VS Code´æÔÚ´úÂë×¢È룬¿ÉÈëÇÔìäGitHub¿â
°ä²¼¹¦·ò 2021-01-291.ÃÀ¹úºÍ±£¼ÓÀûÑǽáºÏµ·»ÙNetWalker£¬ÖÁÉÙÓ¯Àû2760ÍòÃÀÔª

ÔÚÅ·ÖÞÐ̾¯×éÖ¯ÆÆ»ñEmotet½©Ê¬ÍøÂçµÄͳһÌ죬ÃÀ¹úºÍ±£¼ÓÀûÑǵ±¾Ö½áºÏµ·»ÙÁË2020Äê×î»îÔ¾µÄÀÕË÷Èí¼þÍÅ»ïÖ®Ò»NetWalkerµÄ»ù´¡ÉèÊ©¡£Õâ´ÎÐж¯¿ÛÁôÁËÒ»Ãû¼ÓÄôóÏÓÒÉÈËVachon Desjardins£¬»¹½É»ñÁËÍйÜ×ÅÊý¾ÝÐ¹Â¶ÍøÕ¾µÄ·þÎñÆ÷¡£¾ÝÃÀ¹úµ±¾Ö³Æ£¬NetWalkerÒѹ¥»÷ÁËÀ´×Ô27¸ö·ÖÆç¹ú¶ÈµÄÖÁÉÙ305ÃûÊܺ¦Õß¡£McAfee³ÆNetWalkerÒÑÓ¯Àû³¬¹ý2500ÍòÃÀÔª£¬¶øÇø¿éÁ´·ÖÎö¹«Ë¾Chainalysis°µÊ¾NetWalker 2020ÄêÓ¯Àû¿ÉÄܳ¬¹ý4600ÍòÃÀÔª£¬½ö´ÎÓÚRyuk¡¢Maze¡¢DoppelpaymerºÍSodinokibi¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/113944/cyber-crime/netwalker-ransowmare-dismantled.html
2.TeamTNTʹÓÿªÔ´Èí¼þlibprocesshiderÈÆ¹ý¼ì²â

AT£¦TµÄ×êÑÐÈËÔ±·¢ÏÖTeamTNTʹÓÿªÔ´Èí¼þlibprocesshiderÈÆ¹ý¼ì²â¡£TeamTNTÒÔ»ùÓÚÔÆµÄ¹¥»÷¶øÎÅÃû£¬ÀýÈçÀûÓÃÑÇÂíÑ·ÍøÂç·þÎñ£¨AWS£©Æ¾Ö¤À´ÇÖÈëÔÆ£¬²¢ÓÃÆäÀ´ÍÚ¾òMonero¼ÓÃÜÇ®±Ò¡£¿ªÔ´¹¤¾ßlibprocesshiderÊÇ2014Äê±»·ÅÔÚGithubÉϵģ¬¿ÉʹÓÃldÔ¤¼ÓÔØÆ÷ÔÚLinuxϰµ²Ø¹ý³Ì¡£ºÚ¿Íѡȡbase64±àÂëµÄ¾ç±¾£¬½«¸Ã¹¤¾ß°µ²ØÔÚTeamTNT cryptominerµÄ¶þ½øÔìÎļþÖУ¬Ö¼ÔÚ´Ó¹ý³ÌÐÅÏ¢·¨Ê½£¨ÀýÈçpsºÍlsof£©Öаµ²Ø¶ñÒâ¹ý³ÌÒÔÈÆ¹ý¼ì²â¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/teamtnt-cloaks-malware-open-source-tool/163414/
3.×êÑÐÈËÔ±Åû¶VS Code´æÔÚ´úÂë×¢È룬¿ÉÈëÇÔìäGitHub¿â

×êÑÐÈËÔ±RyotaKÅû¶VS Code´æÔÚ´úÂë×¢Èë·ì϶£¬¿ÉÈëÇÔìäGitHub¿â¡£¸Ã·ì϶λÓÚVS CodeµÄ³ÖÐø¼¯³É£¨CI£©¾ç±¾µÄvscode-github-triage-actions´æ´¢¿âÖУ¬ÓÉÓÚÔÚclosedWithºÅÁîÖжÌȱÉí·ÝÑéÖ¤²é³£¬²¢ÇÒÓÃÓÚÑéÖ¤¹Ø¹Ø×¢½âµÄÕýÔò±í°×ʽ´æÔÚȱµã£¬µ¼ÖÂÈκÎÈ˶¼Äܹ»ÔÚclosewithÖµÖÐ×¢Èë´úÂë¡£RyotaK·¢ÏÖ¿ÉÀûÓø÷ì϶»ñµÃVS Code GitHub´æ´¢¿âµÄÊÚȨÁîÅÆ£¬²¢ÄÜ¶ÔÆä½øÐжÁд¡£RyotaKÒÑÏòMicrosoft»ã±¨Á˸÷ì϶£¬²¢°ä²¼ÁË·ì϶µÄPoC¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/heres-how-a-researcher-broke-into-microsoft-vs-codes-github/
4.ClearskyÅû¶Àè°ÍÄÛCedar APTÕë¶ÔÈ«ÇòISPµÄ¼äµý»î¶¯

ClearskyÅû¶Àè°ÍÄÛCedar APT×éÖ¯Õë¶ÔÈ«ÇòµçÐÅÔËÓªÉ̺ÍISPµÄ¼äµý»î¶¯¡£¹¥»÷ʼÓÚ2020ËêÊ×£¬ºÚ¿Í¹¥»÷ÁËÃÀ¹ú¡¢Ó¢¹ú¡¢°£¼°¡¢ÒÔÉ«ÁÓ×¢Àè°ÍÄÛ¡¢Ô¼µ©¡¢°ÍÀÕ˹̹¡¢É³Ìذ¢À²®ºÍ°¢ÁªÇõµÄ»¥ÁªÍø·þÎñÔËÓªÉÌ£¬Ö¼ÔÚÍøÂçµý±¨ºÍÇÔÈ¡¹«Ë¾µÄÃô¸ÐÊý¾Ý¡£¹¥»÷ÕßʹÓÿªÔ´¹¤¾ßɨÃèInternetÉÏδ´ò²¹¶¡µÄAtlassianºÍOracle·þÎñÆ÷£¬¶øºóÀûÓ÷ì϶À´½Ó¼û·þÎñÆ÷²¢²¿ÊðWeb Shell£¬ÖØÒªÀûÓÃÁË3¸ö1ÈÕ·ì϶CVE-2019-3396¡¢CVE-2019-11581ºÍCVE-2012-3152¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/113975/apt/lebanese-cedar-apt-attacks.html
5.Netscout°ä²¼ÓйØDDoS¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨

Netscout°ä²¼ÁËÓйØDDoS¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬·þÎñÌṩÉÌÍøÂç³ÉΪɢ²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷µÄ³Áµã£¬µçÐÅÌṩÉÌÔÚ2020ÉϰëÄêÔâµ½492807´Î¹¥»÷£¬±È2019ÄêͬÆÚÔö³¤ÁË25£¥¡£´Ë±í£¬DDoS¹¥»÷ý½éµÄ¸´ÔÓÐÔÒ²ÔÚÔö³¤£¬×Ô2017ÄêÒÔÀ´£¬Ê¹ÓÃ15¸öÒÔÉÏý½éµÄ¹¥»÷ÊýÁ¿Ôö³¤ÁË2851£¥¡£¶ø2020ÄêÉϰëÄê¹¥»÷µÄÍÌÍÂÁ¿£¨pps£©±È2019ÄêÔö³¤ÁË31£¥£¬¹¥»÷³ÖÐø¹¦·òÏ÷¼õÁË51£¥¡£
ÔÎÄÁ´½Ó£º
https://www.netscout.com/blog/service-provider-ddos-attacks-are-rise
6.¹ú¼ÊÐ̾¯×éÖ¯°ä²¼COVID-19ÍøÂç¹¥»÷µÄ·ÖÎö»ã±¨

¹ú¼ÊÐ̾¯×éÖ¯°ä²¼ÁËCOVID-19ÒÔÀ´ÍøÂç¹¥»÷µÄ·ÖÎö»ã±¨¡£×êÑз¢ÏÖ£¬ÔÚ2020Äê1ÔÂÖÁ4ÔÂÖÐ×ܹ²¼ì²âµ½ÁËԼĪ907000ÌõÀ¬»øÓʼþ£¬737ÆðÓë¶ñÒâÈí¼þÓйصÄÊÂÎñºÍ48000¸öÓëCOVID-19ÓйصÄURL¡£2020Äê2ÔÂÖÁ3Ô£¬¶ñÒâÓòÃû×¢²áÊýÁ¿Ôö³¤ÁË569£¥£¬¶øÒÉËÆ¶ñÒâÓòÃûµÄ×¢²áÊýÁ¿ÔòÔö³¤ÁË788£¥¡£»ã±¨»¹Ö¸³öÍøÂç·¸×ï·Ö×ÓÀûÓÃÁËÓÉCOVID-19Ôì³ÉµÄÉç»á²»²»±äÐԺ;¼Ã¾ÖÊÆÔì³ÉµÄÕ𾪺Ͳ»È·¶¨ÐÔ£¬ÔÚÒÔ¾ªÈ˵ĿìÂÊ·¢Õ¹¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.interpol.int/en/News-and-Events/News/2020/INTERPOL-report-shows-alarming-rate-of-cyberattacks-during-COVID-19


¾©¹«Íø°²±¸11010802024551ºÅ