Ragnar LockerÍŻ﹫¿ªADATA£¨Íþ¸Õ£©700GBÊý¾Ý £»×êÑÐÍŶÓÔÚPyPI´æ´¢¿â·¢ÏÖ¶à¸öÓÃÓÚÍÚ¿óµÄ¶ñÒâÈí¼þ°ü

°ä²¼¹¦·ò 2021-06-23

1.Ragnar LockerÍŻ﹫¿ªADATA£¨Íþ¸Õ£©700GBÊý¾Ý


1.jpg


ÀÕË÷ÍÅ»ïRagnar LockerÍÅ»ïÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¹«¿ªÖйų́ÍåÄÚ´æºÍ´æ´¢Ð¾Æ¬Ôì×÷ÉÌADATA£¨Íþ¸Õ£©³¬¹ý700GBµÄÊý¾Ý¡£²»¾Ãǰ£¬¸ÃÍÅ»ïÐû³Æ´ÓADATAÇÔÈ¡ÁËÔ̺¬²ÆÕþÎļþ¡¢ºÏͬ¡¢±£ÃܺÍ̸µÈÆäËûÎļþÔÚÄÚµÄ1.5TBÃô¸ÐÊý¾Ý¡£Õâ´Î×ܹ²ÀûÓÃMEGA´æ´¢·þÎñ¹«¿ªÁË13¸öÎļþ¼Ð£¬ÆäÖÐ×î´óµÄÎļþ¿¿½ü300GB£¬µ«ÊÇÆ¾¾ÝÆäÃû³ÆÎÞ·¨È·¶¨Ëü¿ÉÄÜÔ̺¬µÄÄÚÈÝ¡£ÕâÊÇRagnar Locker¹«¿ªµÄµÚ¶þÅúÓйØADATAµÄÊý¾Ý£¬ÔÚ±¾Ô³õ¸ÃÍŻﻹ¹«¿ªÁË4¸ö7-zip´æµµ£¬×ܹ²²»µ½250MB¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119196/cyber-crime/ragnar-locker-ransomware-adata.html


2.×êÑÐÍŶÓÔÚPyPI´æ´¢¿â·¢ÏÖ¶à¸öÓÃÓÚÍÚ¿óµÄ¶ñÒâÈí¼þ°ü


2.jpg


×êÑÐÍŶÓÔÚPythonÏîÖ÷ÕÅPyPI¿âÖз¢ÏÖÁË6¸ö¶ñÒâÈí¼þ°ü£¬Äܹ»½«¿ª·¢ÈËÔ±µÄÍÆËã»úÔì³É¿ó»ú¡£ËùÓжñÒâÈí¼þ°ü¾ùÓÉͳһÓû§¡°nedog123¡±°ä²¼£¬±ðÀëΪmaratlib¡¢maratlib1¡¢matplatlib-plus¡¢mllearnlib¡¢mplatlibºÍlearninglib£¬ÆäÖдó²¿ÃŵÄÃû³Æ¶¼ÊǺϷ¨»­Í¼Èí¼þmatplotlibµÄƴдÃýÎó°æ±¾£¬ºÚ¿Íͨ¹ýÕâÖÖ·½Ê½À´ºýŪ¿ª·¢ÈËÔ±ÏÂÔØ¡£×êÑÐÈËÔ±³Æ¶ñÒâ´úÂë¶¼ÔÚsetup.pyÎļþÖУ¬Ëü»áÔÚGitHub´æ´¢¿âÏÂÔØBash¾ç±¾(aza2.sh)£¬¸Ã¾ç±¾µÄ×÷ÓÃÊÇÔÚÖ¸±ê»úеÉÏÔËÐеļÓÃÜ¿ó¹¤Ubqminer¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/malicious-pypi-packages-hijack-dev-devices-to-mine-cryptocurrency/


3.×êÑÐÈËÔ±·¢ÏÖеĴ¹µö»î¶¯·Ö·¢Agent TeslaбäÌå


3.jpg


BitdefenderµÄ×êÑÐÈËÔ±·¢ÏÖÐÂÒ»ÂֵĴ¹µö»î¶¯·Ö·¢Agent TeslaбäÌå¡£Agent Tesla RATÒѾ­´æÔÚÖÁÉÙÆßÄ꣬ʱʱ±»ÓÃÓÚÇÔÈ¡Óû§Í´´¦¡¢ÃÜÂëºÍÃô¸ÐÐÅÏ¢µÄÍøÂç´¹µö»î¶¯¡£Õâ´Î»î¶¯ÒÔCOVID-19ÒßÃç½ÓÖÖ´òËã×÷Ϊµö¶ü£¬¶ñÒ⸽¼þÊÇÒ»¸ö.rtfÎĵµ£¬¸ÃÎĵ·ûÓÃÁËÒÑÖªµÄMicrosoft Office·ì϶(CVE-2017-11882)£¬»áÏÂÔØ²¢Ö´ÐÐAgent TeslaбäÌå¡£´Ë±í£¬´óÎÞÊý¹¥»÷ËÆºõÔ´×ÔÔ½ÄϵÄIPµØÖ·£¬²¢ÇÒ50%µÄ¶ñÒâÓʼþ±»·¢Ë͵½º«¹úµÄIPµØÖ·¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/agent-tesla-covid-vax-phish/167082/    


4.Tor°ä²¼°²È«¸üУ¬½¨¸´¿É¿çä¯ÀÀÆ÷¸ú×ÙÓû§µÄ·ì϶


4.jpg


TorÒѰ䲼°²È«¸üУ¬½¨¸´¿É¿çä¯ÀÀÆ÷¸ú×ÙÓû§µÄ·ì϶¡£½ñÄê5Ô£¬Ö¸ÎƼø±ð¹«Ë¾FingerprintJSÅû¶ÁËä¯ÀÀÆ÷×Ô½ç˵ºÍ̸´¦Ö÷¨Ê½Öеĺ鷺·ì϶£¬Äܹ»¿çGoogle Chrome¡¢Edge¡¢Tor¡¢FirefoxºÍSafariµÈä¯ÀÀÆ÷¸ú×ÙÓû§¡£TorÏîĿͨ¹ý½«¡°network.protocol-handler.external¡±ÉèÖÃΪfalseÀ´½¨¸´´Ë·ì϶£¬ÕâÑùÉèÖÃÄܹ»×èÖÓίÀÀÆ÷½«Ìض¨URLµÄ´¦Öô«µÝ¸ø±í²¿ÀûÓ÷¨Ê½¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/tor-browser-fixes-vulnerability-that-tracks-you-using-installed-apps/


5.ÃÀ¹úLucky Star¶Ä³¡Ï°È¾ÀÕË÷Èí¼þ£¬½»Ò׳¡Ëù¹Ø¹Ø


5.jpg


ÃÀ¹úLucky Star¶Ä³¡Ï°È¾ÀÕË÷Èí¼þ£¬È«¶í¿ËÀ­ºÎÂíÖݵĽ»Ò׳¡Ëù¹Ø¹Ø¡£Lucky StarÓÚÉÏÖÜÁùÔÚÆäFacebookÉϰ䷢½«¹Ø¹ØÆäÔÚ¶í¿ËÀ­ºÎÂíÖݵÄËùÓн»Ò׳¡Ëù£¬Ö®ºó£¬ÓÖÓÚ±¾ÖÜÒ»°µÊ¾£¬ÆäÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷¡£Ä¿Ç°£¬¸Ã¶Ä³¡ÈÔÔڹعØÖС£¸Ã¹«Ë¾°µÊ¾ËüÒѾ­ÁªÏµÁËÔ̺¬Áª¹úµ÷²é¾ÖÔÚÄڵķ¨Âɲ¿ÃŶԴËÊ·¢Õ¹µ÷²é£¬ÉÐÎÞÓйØÕâ´Î¹¥»÷µÄ¾ßÌåÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/ok-lucky-star-casino-confirmed-it-suffered-ransomware-attack/


6.Check Ponit°ä²¼ÈôºÎ¼ÓǿҽÁÆ»ú¹¹µÄ°²È«µÄ»ã±¨


6.jpg


Check Ponit°ä²¼ÁËÓйØÈôºÎ¼ÓǿҽÁÆ»ú¹¹µÄÎïÁªÍø°²È«µÄ»ã±¨¡£¸Ã»ã±¨Ì½ÇóÁËÎïÁªÍøÔÚŤתҽÁÆÐÐÒµµÄһЩ·½Ê½£¬¶øºóÈ·¶¨Ò½ÁÆ»·¾³ÖÐÏνÓÉ豸´øÀ´µÄһЩDZÔÚÎÊÌâ¡£¾Ý¹À¼Æ£¬µ½2025Ä꣬ȫÇòÎïÁªÍøÊг¡½«Ôö³¤µ½5343ÒÚÃÀÔª¡£¹¥»÷Ôì³ÉµÄËðʧÊǾªÈ˵ģºÒ½Ôº¾ùÔÈÆÆ·Ñ430ÃÀÔªÀ´»ñȡй¶ÐÅÏ¢£¬2019ÄêÕë¶ÔÒ½ÁÆ»ú¹¹µÄÒ»´ÎÎïÁªÍø¹¥»÷µÄ¾ùÔÈËðʧΪ346205ÃÀÔª¡£Ò½ÁÆÐÐÒµµÄ×éÖ¯Ó¦¸Ãά³ÖËùÓÐÉ豸µÄ¿É¼û¡¢ÊµÊ±½¨¸´·ì϶ºÍÁãÐÅÀµÍøÂç·Ö¶Î¡£


Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2021/06/21/how-to-tighten-iot-security-for-healthcare-organization/