ÃÀ¹úºÍ±£¼ÓÀûÑǽáºÏµ·»ÙNetWalker£¬ÖÁÉÙÓ¯Àû2760ÍòÃÀÔª  £»×êÑÐÈËÔ±Åû¶VS Code´æÔÚ´úÂë×¢È룬¿ÉÈëÇÔìäGitHub¿â

°ä²¼¹¦·ò 2021-01-29

1.ÃÀ¹úºÍ±£¼ÓÀûÑǽáºÏµ·»ÙNetWalker£¬ÖÁÉÙÓ¯Àû2760ÍòÃÀÔª


1.png


ÔÚÅ·ÖÞÐ̾¯×éÖ¯ÆÆ»ñEmotet½©Ê¬ÍøÂçµÄͳһÌ죬ÃÀ¹úºÍ±£¼ÓÀûÑǵ±¾Ö½áºÏµ·»ÙÁË2020Äê×î»îÔ¾µÄÀÕË÷Èí¼þÍÅ»ïÖ®Ò»NetWalkerµÄ»ù´¡ÉèÊ© ¡£Õâ´ÎÐж¯¿ÛÁôÁËÒ»Ãû¼ÓÄôóÏÓÒÉÈËVachon Desjardins£¬»¹½É»ñÁËÍйÜ×ÅÊý¾ÝÐ¹Â¶ÍøÕ¾µÄ·þÎñÆ÷ ¡£¾ÝÃÀ¹úµ±¾Ö³Æ£¬NetWalkerÒѹ¥»÷ÁËÀ´×Ô27¸ö·ÖÆç¹ú¶ÈµÄÖÁÉÙ305ÃûÊܺ¦Õß ¡£McAfee³ÆNetWalkerÒÑÓ¯Àû³¬¹ý2500ÍòÃÀÔª£¬¶øÇø¿éÁ´·ÖÎö¹«Ë¾Chainalysis°µÊ¾NetWalker 2020ÄêÓ¯Àû¿ÉÄܳ¬¹ý4600ÍòÃÀÔª£¬½ö´ÎÓÚRyuk¡¢Maze¡¢DoppelpaymerºÍSodinokibi ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/113944/cyber-crime/netwalker-ransowmare-dismantled.html


2.TeamTNTʹÓÿªÔ´Èí¼þlibprocesshiderÈÆ¹ý¼ì²â


2.png


AT£¦TµÄ×êÑÐÈËÔ±·¢ÏÖTeamTNTʹÓÿªÔ´Èí¼þlibprocesshiderÈÆ¹ý¼ì²â ¡£TeamTNTÒÔ»ùÓÚÔÆµÄ¹¥»÷¶øÎÅÃû£¬ÀýÈçÀûÓÃÑÇÂíÑ·ÍøÂç·þÎñ£¨AWS£©Æ¾Ö¤À´ÇÖÈëÔÆ£¬²¢ÓÃÆäÀ´ÍÚ¾òMonero¼ÓÃÜÇ®±Ò ¡£¿ªÔ´¹¤¾ßlibprocesshiderÊÇ2014Äê±»·ÅÔÚGithubÉϵÄ£¬¿ÉʹÓÃldÔ¤¼ÓÔØÆ÷ÔÚLinuxϰµ²Ø¹ý³Ì ¡£ºÚ¿Íѡȡbase64±àÂëµÄ¾ç±¾£¬½«¸Ã¹¤¾ß°µ²ØÔÚTeamTNT cryptominerµÄ¶þ½øÔìÎļþÖУ¬Ö¼ÔÚ´Ó¹ý³ÌÐÅÏ¢·¨Ê½£¨ÀýÈçpsºÍlsof£©Öаµ²Ø¶ñÒâ¹ý³ÌÒÔÈÆ¹ý¼ì²â ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/teamtnt-cloaks-malware-open-source-tool/163414/


3.×êÑÐÈËÔ±Åû¶VS Code´æÔÚ´úÂë×¢È룬¿ÉÈëÇÔìäGitHub¿â


3.png


×êÑÐÈËÔ±RyotaKÅû¶VS Code´æÔÚ´úÂë×¢Èë·ì϶£¬¿ÉÈëÇÔìäGitHub¿â ¡£¸Ã·ì϶λÓÚVS CodeµÄ³ÖÐø¼¯³É£¨CI£©¾ç±¾µÄvscode-github-triage-actions´æ´¢¿âÖУ¬ÓÉÓÚÔÚclosedWithºÅÁîÖжÌȱÉí·ÝÑéÖ¤²é³­£¬²¢ÇÒÓÃÓÚÑéÖ¤¹Ø¹Ø×¢½âµÄÕýÔò±í°×ʽ´æÔÚȱµã£¬µ¼ÖÂÈκÎÈ˶¼Äܹ»ÔÚclosewithÖµÖÐ×¢Èë´úÂë ¡£RyotaK·¢ÏÖ¿ÉÀûÓø÷ì϶»ñµÃVS Code GitHub´æ´¢¿âµÄÊÚȨÁîÅÆ£¬²¢ÄÜ¶ÔÆä½øÐжÁд ¡£RyotaKÒÑÏòMicrosoft»ã±¨Á˸÷ì϶£¬²¢°ä²¼ÁË·ì϶µÄPoC ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/heres-how-a-researcher-broke-into-microsoft-vs-codes-github/


4.ClearskyÅû¶Àè°ÍÄÛCedar APTÕë¶ÔÈ«ÇòISPµÄ¼äµý»î¶¯


4.png


ClearskyÅû¶Àè°ÍÄÛCedar APT×éÖ¯Õë¶ÔÈ«ÇòµçÐÅÔËÓªÉ̺ÍISPµÄ¼äµý»î¶¯ ¡£¹¥»÷ʼÓÚ2020ËêÊ×£¬ºÚ¿Í¹¥»÷ÁËÃÀ¹ú¡¢Ó¢¹ú¡¢°£¼°¡¢ÒÔÉ«ÁÓ×¢Àè°ÍÄÛ¡¢Ô¼µ©¡¢°ÍÀÕ˹̹¡¢É³Ìذ¢À­²®ºÍ°¢ÁªÇõµÄ»¥ÁªÍø·þÎñÔËÓªÉÌ£¬Ö¼ÔÚÍøÂçµý±¨ºÍÇÔÈ¡¹«Ë¾µÄÃô¸ÐÊý¾Ý ¡£¹¥»÷ÕßʹÓÿªÔ´¹¤¾ßɨÃèInternetÉÏδ´ò²¹¶¡µÄAtlassianºÍOracle·þÎñÆ÷£¬¶øºóÀûÓ÷ì϶À´½Ó¼û·þÎñÆ÷²¢²¿ÊðWeb Shell£¬ÖØÒªÀûÓÃÁË3¸ö1ÈÕ·ì϶CVE-2019-3396¡¢CVE-2019-11581ºÍCVE-2012-3152 ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/113975/apt/lebanese-cedar-apt-attacks.html


5.Netscout°ä²¼ÓйØDDoS¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨


5.png


Netscout°ä²¼ÁËÓйØDDoS¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨ ¡£»ã±¨Ö¸³ö£¬·þÎñÌṩÉÌÍøÂç³ÉΪɢ²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷µÄ³Áµã£¬µçÐÅÌṩÉÌÔÚ2020ÉϰëÄêÔâµ½492807´Î¹¥»÷£¬±È2019ÄêͬÆÚÔö³¤ÁË25£¥ ¡£´Ë±í£¬DDoS¹¥»÷ý½éµÄ¸´ÔÓÐÔÒ²ÔÚÔö³¤£¬×Ô2017ÄêÒÔÀ´£¬Ê¹ÓÃ15¸öÒÔÉÏý½éµÄ¹¥»÷ÊýÁ¿Ôö³¤ÁË2851£¥ ¡£¶ø2020ÄêÉϰëÄê¹¥»÷µÄÍÌÍÂÁ¿£¨pps£©±È2019ÄêÔö³¤ÁË31£¥£¬¹¥»÷³ÖÐø¹¦·òÏ÷¼õÁË51£¥ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.netscout.com/blog/service-provider-ddos-attacks-are-rise


6.¹ú¼ÊÐ̾¯×éÖ¯°ä²¼COVID-19ÍøÂç¹¥»÷µÄ·ÖÎö»ã±¨


6.png


¹ú¼ÊÐ̾¯×éÖ¯°ä²¼ÁËCOVID-19ÒÔÀ´ÍøÂç¹¥»÷µÄ·ÖÎö»ã±¨ ¡£×êÑз¢ÏÖ£¬ÔÚ2020Äê1ÔÂÖÁ4ÔÂÖÐ×ܹ²¼ì²âµ½ÁËԼĪ907000ÌõÀ¬»øÓʼþ£¬737ÆðÓë¶ñÒâÈí¼þÓйصÄÊÂÎñºÍ48000¸öÓëCOVID-19ÓйصÄURL ¡£2020Äê2ÔÂÖÁ3Ô£¬¶ñÒâÓòÃû×¢²áÊýÁ¿Ôö³¤ÁË569£¥£¬¶øÒÉËÆ¶ñÒâÓòÃûµÄ×¢²áÊýÁ¿ÔòÔö³¤ÁË788£¥ ¡£»ã±¨»¹Ö¸³öÍøÂç·¸×ï·Ö×ÓÀûÓÃÁËÓÉCOVID-19Ôì³ÉµÄÉç»á²»²»±äÐԺ;­¼Ã¾ÖÊÆÔì³ÉµÄÕ𾪺Ͳ»È·¶¨ÐÔ£¬ÔÚÒÔ¾ªÈ˵ĿìÂÊ·¢Õ¹¹¥»÷ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.interpol.int/en/News-and-Events/News/2020/INTERPOL-report-shows-alarming-rate-of-cyberattacks-during-COVID-19