ÀûÓÃGoogle Play·Ö·¢µÄÐÂľÂíXenomorphÕë¶ÔÅ·ÖÞµØÓò

°ä²¼¹¦·ò 2022-02-24

ÀûÓÃGoogle Play·Ö·¢µÄÐÂľÂíXenomorphÕë¶ÔÅ·ÖÞµØÓò


¾ÝýÌå2ÔÂ21ÈÕ±¨Â·£¬°²È«¹«Ë¾ThreatFabric·¢ÏÖÁËеÄAndroidÒøÐÐľÂíXenomorph¡£¸ÃľÂí¼Ù×°³É»úÄÜÌáÉýÀûÓ÷¨Ê½£¨ÀýÈçFast Cleaner£©Í¨¹ýGoogle PlayÉ̵ê·Ö·¢£¬Òѱ»×°Öó¬¹ý50000´Î¡£ËüĿǰÈÔ´¦ÓÚÔçÆÚ¿ª·¢½×¶Î£¬Ö¸±êÊÇÎ÷°àÑÀ¡¢ÆÏÌÑÑÀ¡¢Òâ´óÀûºÍ±ÈÀûʱµÈÅ·ÖÞ¹ú¶ÈµÄ56¼Ò½ðÈÚ»ú¹¹¡£×êÑÐÈËÔ±»¹·¢ÏÖ¸ÃľÂíµÄ´úÂëÓëAlienÓÐËù³Áµþ£¬ÕâÅú×¢¶þÕß´æÔÚijÖÖÁªÏµ£ºÒªÃ´XenomorphÊÇAlienµÄ¼ÌÈÎÕߣ¬ÒªÃ´XenomorphµÄ¿ª·¢ÈËÔ±Ò»ÏòÔÚ×êÑÐAlien¡£


https://thehackernews.com/2022/02/xenomorph-android-banking.html


ÃÀ¹úMeyerÔâµ½ContiÀÕË÷¹¥»÷µ¼Ö´óÁ¿Ô±¹¤ÐÅϢй¶


¾Ý2ÔÂ21ÈÕ±¨Â·£¬ÃÀ¹ú×î´óµÄ´¶¾ß¹«Ë¾MeyerÔâµ½ContiÀÕË÷¹¥»÷¡£¹¥»÷²úÉúÔÚ2021Äê10ÔÂ25ÈÕ£¬¼ì²âµ½¹¥»÷ºó¸Ã¹«Ë¾µ±¼´·¢Õ¹µ÷²é£¬²¢ÓÚ12ÔÂ1ÈÕÈ·¶¨MeyerÔ±¹¤µÄÐÅÏ¢¿ÉÄÜÒÑÔ⵽δ¾­ÊÚȨµÄ½Ó¼û¡£×êÑÐÈËÔ±ÔÚContiµÄÐÅÏ¢Ð¹Â¶ÍøÕ¾·¢ÏÖÒ»¸ö¿É×·Òäµ½11ÔÂ7ÈÕµÄÁбí£¬¾Ý³ÆÔ̺¬ÁËÔÚMeyerÇÔÈ¡µÄ2%µÄÊý¾Ý£¬µ«ÖÁ½ñÈÔδ°ä²¼Ôü×ÒµÄ98%¡£Meyer°µÊ¾½«ÎªÊÜÓ°ÏìµÄÔ±¹¤¼°Æä¾ìÊôÌṩÁ½ÄêµÄÉí·Ý± £»¤·þÎñ¡£


https://www.bleepingcomputer.com/news/security/cookware-giant-meyer-discloses-cyberattack-that-impacted-employees/


Ahn Lab·¢ÏÖCryptBotбäÌåÀûÓõÁ°æÈí¼þÍøÕ¾´«²¼


Ahn LabÔÚ2ÔÂ21ÈÕ°ä²¼µÄ×êÑÐÏÔʾ£¬CryptBotбäÌåÔÚͨ¹ýµÁ°æÈí¼þÍøÕ¾½øÐд«²¼¡£CryptBotÊÇÒ»ÖÖWindowsÐÅÏ¢ÇÔÈ¡·¨Ê½£¬¿É´ÓÖ¸±êÇÔÈ¡ä¯ÀÀÆ÷Í´´¦¡¢cookie¡¢¼ÓÃÜÇ®±ÒÇ®°üºÍÐÅÓþ¿¨µÈÐÅÏ¢¡£¹¥»÷ÕßÀûÓÃÆÆ½âÈí¼þºÍÃÜÔ¿ÌìÉúÆ÷µÈÍøÕ¾·Ö·¢¶ñÒâÈí¼þ£¬²¢Í¨¹ýËÑË÷ÒýÇæÓÅ»¯½«ÕâÐ©ÍøÕ¾ÔڹȸèµÄËÑË÷Á˾ÖÖÐÖö¥¡£´Ë±í£¬¸Ã°æ±¾±ÈÒÔÍùÓнϴóµÄŤת£¬É¾³ýÁË·´É³ºÐÖ°Äܺͱ¸ÓÃC2µÈÈßÓàµÄÖ°ÄÜ£¬²¢ÒѿɺÏÓÃÓÚËùÓÐChrome°æ±¾¡£


https://asec.ahnlab.com/en/31802/


Kaspersky°ä²¼2021ÄêÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨


2ÔÂ21ÈÕ£¬Kaspersky°ä²¼ÁË2021ÄêÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬KasperskyÔÚ2021Äê×ܼƼì²âµ½3464756¸ö¶ñÒâ×°Öðü¡¢97661¸öеÄÒÆ¶¯ÒøÐÐľÂíºÍ17372¸öеÄÒÆ¶¯ÀÕË÷Èí¼þ¡£ÊÜÒÆ¶¯¶ñÒâÈí¼þ¹¥»÷×î¶àµÄ¹ú¶ÈÊÇÒÁÀÊ£¬Æä´ÎÊÇÖйú¡¢É³Ìذ¢À­²®ºÍ°¢¶û¼°ÀûÑÇ¡£¼ì²âµ½µÄ¶ñÒâÈí¼þÖиæ°×Èí¼þ£¨42.42%£©µÄÕ¼±È×î´ó£¬Æä´ÎΪRiskToolÀûÓ÷¨Ê½£¨35.27%£©ºÍľÂí£¨8.86%£©¡£


https://securelist.com/mobile-malware-evolution-2021/105876/


Trend MicroÅû¶ÐµÄMac¶ñÒâÍÚ¿óÈí¼þµÄ¼¼Êõϸ½Ú


Trend MicroÔÚ2ÔÂ21ÈÕÅû¶ÁËÐÂMac¶ñÒâÍÚ¿óÈí¼þµÄ¼¼Êõϸ½Ú¡£¶ñÒâÈí¼þÑù±¾±»¼ì²âΪCoinminer.MacOS.MALXMR.H£¬ÓÚ2022Äê1Ô³õ³õ´Î±»·¢ÏÖ£¬ÊÇÒ»¸öMach-OÎļþ¡£Ö´ÐÐʱ£¬ËüÀûÓÃAuthorizationExecuteWithPrivileges APIͨ¹ýÌáÐÑÓû§ÊäÈëÍ´´¦À´ÌáÉýȨÏÞ¡£³ý´ËÖ®±í£¬¸ÃÑù±¾»¹Ê¹ÓÃÁËi2pd£¨±ðÃûI2PÊØ»¤·¨Ê½£©À´°µ²ØÆäÍøÂçÁ÷Á¿£¬¶øÆäËüMac¶ñÒâÈí¼þͨ³£Ê¹ÓÃTor¡£


https://www.trendmicro.com/en_us/research/22/b/latest-mac-coinminer-utilizes-open-source-binaries-and-the-i2p-network.html


×êÑÐÍŶӷ¢ÏÖÕë¶ÔMicrosoft SQLÊý¾Ý¿âµÄ¹¥»÷»î¶¯


ýÌå2ÔÂ21Èճƣ¬×êÑÐÍŶӷ¢ÏÖÁËÕë¶ÔMicrosoft SQLÊý¾Ý¿âµÄ¹¥»÷»î¶¯¡£¹¥»÷ÕßÊ×ÏÈɨÃèTCP¶Ë¿Ú1433Ê¢¿ªµÄ·þÎñ£¬¶øºóͨ¹ý±©Á¦ÆÆ½âºÍ×ֵ乥»÷À´ÆÆ½âÃÜÂë¡£Ò»µ©»ñµÃÖÎÀíÔ¹ØÊ»§µÄ½Ó¼ûȨÏÞ£¬¹¥»÷Õ߾ͻᵱ¼´×°ÖÃLemon Duck¡¢KingMinerºÍVollgarµÈ¶ñÒâ¿ó¹¤Èí¼þ¡£×îºó£¬ËûÃÇ»¹»áʹÓÃCobalt StrikeÔÚÊý¾Ý¿âÖгÉÁ¢ºóÃÅ£¬ÒÔά³ÖÓÆ¾ÃÐÔ²¢½øÐкáÏòÒÆ¶¯¡£


https://www.bleepingcomputer.com/news/security/vulnerable-microsoft-sql-servers-targeted-with-cobalt-strike/



°²È«¹¤¾ß


coraza


golang ÆóÒµ¼¶ Web ÀûÓ÷À»ðǽ¿ò¼Ü£¬Ö§³Ö Modsecurity µÄ seclang ˵»°£¬Óë OWASP Core Ruleset 100% ¼æÈÝ¡£


https://github.com/corazawaf/coraza


m3


ÒÆ¶¯¶ñÒâÈí¼þ·ÂÕÕ¿ò¼Ü£¨¼ò³Æm3£©ÊÇÒ»¸öµ¥Ò»ÇÒ¿ÉÀ©´óµÄ Android »úеÈË·ÂÕÕ¿ò¼Ü¡£


https://github.com/ThisIsLibra/m3/


SecureBank


Ô̺¬ËùÓÐ OWASP TOP 10 °²È«·ì϶µÄ½ðÈڿƼ¼ÀûÓ÷¨Ê½¡£


https://ssrd.gitbook.io/securebank/


Talisman 


¿É½«hook×°Öõ½´æ´¢¿â£¬ÒÔÈ·±£Ç±ÔÚµÄÃô¸ÐÐÅÏ¢²»»áÍÑÀ뿪·¢ÈËÔ±µÄ¹¤×÷Õ¾¡£


https://github.com/thoughtworks/talisman#what-is-talisman


SharpCookieMonster


cookie-crimesÄ£¿éµÄÒ»¸ö Sharp ¶Ë¿Ú£¬Õâ¸ö C# ÏîÄ¿½«ÎªËùÓÐÕ¾µãת´¢ cookie¡£


https://github.com/m0rv4i/SharpCookieMonster



°²È«·ÖÎö


ÕûÊýÒç³ö£ºËüÊÇÈôºÎ²úÉúµÄÒÔ¼°ÈôºÎÔ¤·À


https://www.welivesecurity.com/2022/02/21/integer-overflow-how-it-occur-can-be-prevented/


¹¥»÷ÕßÀûÓÃSMS PVA ·þÎñ½øÐжñÒâ»î¶¯


https://securityaffairs.co/wordpress/128242/cyber-crime/sms-pva-services.html


ÆÏÌÑÑÀÍþв»ã±¨£º2021 ÄêµÚËÄʱ¶È


https://seguranca-informatica.pt/threat-report-portugal-q3-2021/


΢Èí¸üÐÂÁË Your Phone ÀûÓ÷¨Ê½µÄÒ»ÏîÐÂÖ°ÄÜ


https://news.softpedia.com/news/microsoft-announces-a-new-feature-for-the-your-phone-app-534911.shtml


CVE-2022-0290£ºChrome RenderFrameHostImpl¿ªÊͺóʹÓ÷ì϶


https://packetstormsecurity.com/files/166080/GS20220221155706.tgz