Lapsus$Ðû³ÆÒÑÈëÇÖ΢ÈíAzure DevOpsÔ´´úÂë´æ´¢¿â

°ä²¼¹¦·ò 2022-03-23

Lapsus$Ðû³ÆÒÑÈëÇÖ΢ÈíAzure DevOpsÔ´´úÂë´æ´¢¿â


¾ÝýÌå3ÔÂ21ÈÕ±¨Â· £¬Î¢ÈíÔÚµ÷²éÓйØLapsus$ÈëÇÔìäAzure DevOpsÔ´´úÂë´æ´¢¿â²¢ÇÔÈ¡Êý¾ÝµÄÊÂÎñ ¡£ÉÏÖÜÈÕÔ糿 £¬Lapsus$ÔÚTelegramÉϰ䲼ÁËÆäÈëÇÖµÄÔ´´úÂë´æ´¢¿âµÄÆÁÄ»½ØÍ¼ £¬ÆäÖÐÔ̺¬CortanaºÍ¸÷ÀàBingÏîÖ÷ÕÅÔ´´úÂë £¬ÃûΪ¡°Bing_STC-SV¡±¡¢¡°Bing_Test_Agile¡±ºÍ¡°Bing_UX¡± £¬ÒÔ¼°ÆäËüÔ´´úÂë ¡£´Ë±í £¬½ØÍ¼ÖÐÏÔʾÁ˵ǼÓû§µÄÊ××Öĸ¡°IS¡± £¬Õâ¿É±»ÓÃÀ´È·Èϱ»µÁÕÊ»§ ¡£½ØÍ¼°ä²¼ºó²»¾Ã £¬Lapsus$³·»ØÁËÕâ¸öÌû×Ó £¬²¢³Æ¡°ÁÙʱɾ³ý £¬ÉÔºóÔÙ°ä²¼¡± ¡£


https://securityaffairs.co/wordpress/129312/cyber-crime/lapsus-gang-claims-microsoft-hack.html


ASEC·¢ÏÖ¼Ù×°³ÉWindows 10µÄÃÜÔ¿¼¤»î¹¤¾ß·Ö·¢BitRAT


ASEC·ÖÎöÍŶÓÔÚ3ÔÂ21ÈÕÅû¶Á˼Ù×°³ÉWindows 10µÄÃÜÔ¿¼¤»î¹¤¾ß·Ö·¢BitRATµÄ»î¶¯µÄϸ½ÚÐÅÏ¢ ¡£¹¥»÷ÕßÔÚº«¹ú×î³£ÓõÄÎļþ¹²ÏíÆ½Ì¨webhardÉϰ䲼µö¶üÁ´½Ó £¬Ö¸±êµã»÷ºó»áÏÂÔØÃûΪ¡°Program.zip¡±µÄѹËõÎļþ £¬Ê¹ÓÃÃÜÂë¡°1234¡±½øÐÐѹËõºó £¬»á»ñµÃÃûΪ¡°W10DigitalActivation.exe¡±µÄWindows 10µÄÃÜÔ¿¼¤»î¹¤¾ß ¡£ÔÚÖ¸±êÔËÐиù¤¾ßºó £¬»á×°ÖÃÕæÊµµÄÑéÖ¤¹¤¾ßºÍ¶ñÒâÈí¼þW10DigitalActivation_Temp.msi £¬×îÖÕÏÂÔØ²¢×°ÖÃÔ¶³Ì½Ó¼ûľÂíBitRAT ¡£


https://asec.ahnlab.com/en/32781/


Emsisoft°ä²¼TrickBotµÄÀÕË÷Èí¼þDiavolµÄ½âÃÜÆ÷


¾ÝýÌå3ÔÂ18ÈÕ±¨Â· £¬°²È«¹«Ë¾Emsisoft°ä²¼ÁËÒ»¿î½âÃܹ¤¾ß £¬Ô®ÊÖÔâµ½DiavolÀÕË÷Èí¼þ¹¥»÷µÄÖ¸±êÃâ·Ñ¸´Ô­Îļþ ¡£Óû§Äܹ»´ÓEmsisoftµÄ·þÎñÆ÷ÏÂÔØ¸Ã¹¤¾ß £¬²¢Æ¾¾ÝÖ¸ÄÏÖÐÌṩµÄ¾ßÌå×¢Ã÷½âÃÜÆäÊý¾Ý ¡£EmsisoftÚ¹ÊÍ˵ £¬¸Ã½âÃÜÆ÷±ØÒª½Ó¼ûÓÉÒ»¸ö¼ÓÃÜÎļþºÍ¸Ã¼ÓÃÜÎļþµÄδ¼ÓÃܰ汾×é³ÉµÄÎļþ¶Ô £¬ÒÔ³Á½¨½âÃÜËùÐèÃÜÔ¿ ¡£FortiGuard LabsÔÚ2021Äê6ÔÂÉÏÑ®³õ´Î½«¸ÃÀÕË÷Èí¼þÓëTrickBotÍÅ»ïÁªÏµÆðÀ´ ¡£


https://www.bleepingcomputer.com/news/security/free-decryptor-released-for-trickbot-gangs-diavol-ransomware/


×êÑÐÍŶÓÅû¶¼ÙÒâInstagram¼¼ÊõÖ§³ÖµÄ´¹µö»î¶¯µÄϸ½Ú


ArmorbloxÔÚ3ÔÂ16ÈÕÏêÊöÁ˼ÙÒâInstagram¼¼ÊõÖ§³ÖµÄ´¹µö»î¶¯ ¡£Õâ´Î»î¶¯ÖØÒªÕë¶Ô×ܲ¿Î»ÓÚŦԼµÄÒ»¼Ò³ÛÃûµÄÈËÊÙ±£ÏÕ¹«Ë¾ £¬´¹µöÓʼþÒÔ¡°Instagram Support¡± ΪÖ÷Ìâ £¬À´×ÔµØÖ·membershipform@outlook.com.tr ¡£¸ÃÓʼþÖÒ¸æÊÕ¼þÈËÆäInstagramÕÊ»§Òѱ»¾Ù±¨´«²¼ÐéαÐÅÏ¢²¢ÑϳÁÎ¥·´ÁËInstagramµÄ·þÎñÌõ¿î ¡£ÊÕ¼þÈ˱»ÒªÇóÔÚ24Ó×ʱÄÚÑéÖ¤ÕÊ»§²»È»ÕÊ»§»á±»É¾³ý £¬Æäµã»÷ÑéÖ¤Á´½Óºó¼´»á±»³Á¶¨Ïòµ½´¹µöÍøÕ¾ ¡£


https://www.armorblox.com/blog/the-email-bait-and-phish-instagram-phishing-attack/


Avast°ä²¼½©Ê¬ÍøÂçDirtyMoeбäÌåµÄ¼¼Êõ·ÖÎö»ã±¨


3ÔÂ16ÈÕ £¬Avast°ä²¼Á˽©Ê¬ÍøÂçDirtyMoeбäÌåµÄ¼¼Êõ·ÖÎö»ã±¨ ¡£DirtyMoeѡȡÄ£¿é»¯Éè¼Æ £¬ÖØÒªÊ¹Óöà¸ö¹¤¾ß°ü£¨ÈçPurpleFox£©½øÐзַ¢ ¡£×îÐÂ×êÑз¢ÏÖ £¬DirtyMoeÐÂÔöÁËÀàËÆÈ䳿µÄ´«²¼Ö°ÄÜ £¬Ê¹Æä¿ÉÄÜÔÚ²»±ØÒªÓëÓû§½»»¥µÄÇé¿öÏÂÀ©´óÓ°ÏìÁìÓò ¡£¸ÃÈ䳿Ä£¿éÕë¶ÔµÄÊǽÏÔçµÄ³£¼û·ì϶ £¬ÀýÈçEternalBlueºÍHot Potato WindowsȨÏÞÉý¼¶·ì϶ £¬Ê¹Ó÷þÎñ½ÚÔìÖÎÀíÆ÷Ô¶³ÌºÍ̸(SCMR)¡¢WMIºÍMS SQL·þÎñµÄ×ֵ乥»÷ £¬Ã¿ÌìÄܹ»ÌìÉúºÍ¹¥»÷ÊýÊ®Íò¸öIPµØÖ· ¡£


https://decoded.avast.io/martinchlumecky/dirtymoe-5/


Trend Micro°ä²¼2021ÄêÍøÂç°²È«Ì¬ÊÆµÄ»ØÊ׻㱨


3ÔÂ17ÈÕ £¬Trend Micro°ä²¼ÁË2021ÄêÍøÂç°²È«Ì¬ÊÆµÄ»ØÊ׻㱨 ¡£»ã±¨Ö¸³ö £¬ÕûÌåÀÕË÷Èí¼þÊýÁ¿Í¬±È½µÂä21% £¬µ±¾Ö¡¢ÒøÐкÍÒ½ÁƱ£½¡ÐÐÒµÈÔÊÇ2021ÄêÔâµ½´ËÀ๥»÷×î¶àµÄÐÐÒµ £¬ÀÕË÷¹¥»÷Õß×î³£ÓõĶñÒ⹤¾ßÔ̺¬Cobalt Strike beacon¡¢TrickbotºÍBazarLoaderµÈ ¡£Ç÷Ïò¿Æ¼¼ÔÚ2021Äê¼ì²âµ½³¬¹ý2500Íò·â¶ñÒâÓʼþÍþв £¬ÆäÖд¹µöÓʼþµÄÊýÁ¿ÏÕЩÊÇ2020ÄêµÄÁ½±¶ £¬½ðÈÚ¡¢Ò½ÁƱ£½¡ºÍ½ÌÓýÐÐÒµÔâµ½´ËÀ๥»÷×î¶à ¡£2021 Äê £¬Ç÷Ïò¿Æ¼¼ZDI°ä²¼Á˹ØÓÚ1604¸ö·ì϶µÄ²¼¸æ £¬±ÈÉÏÒ»ÄêÔö³¤ÁË10% ¡£


https://www.trendmicro.com/vinfo/us/security/research-and-analysis/threat-reports/roundup/navigating-new-frontiers-trend-micro-2021-annual-cybersecurity-report



°²È«¹¤¾ß


Mip22


Ò»Öָ߼¶ÍøÂç´¹µö¹¤¾ß £¬½öÓÃÓÚ½ÌÓýÖ÷ÕÅÒÔÏàÊ¶ÍøÂç´¹µö²½ÖèµÄ¹¤×÷µÀÀí ¡£


https://github.com/makdosx/mip22


routeros-scanner 


΢Èí°ä²¼ÁËÒ»¿îÄܹ»¼ì²â±» TrickBot ÍÅ»ïÈëÇÖµÄ MikroTik ·ÓÉÆ÷µÄȡ֤¹¤¾ß ¡£


https://github.com/microsoft/routeros-scanner


ThreatMapper 1.3.0


ÔÚ×îеĸüÐÂÖÐ £¬Deepfence ½«Ê¢ÐÐµÄ SecretScanner ¹¤¾ßÔö³¤µ½ ThreatMapper ÖÐ ¡£


https://deepfence.io/new-release-threatmapper-1-3-0/


agartha


ÉøÈë²âÊÔ¹¤¾ß £¬Ëü´´½¨¶¯Ì¬payloadÁбíºÍÓû§½Ó¼û¾ØÕó £¬ÒÔ½ÒʾעÈë·ì϶ºÍÉí·ÝÑéÖ¤/ÊÚȨÎÊÌâ ¡£


https://github.com/volkandindar/agartha



°²È«·ÖÎö


¹È¸èÔÊÐí°²×¿Óû§É¾³ý×î½ü 15 ·ÖÖÓµÄËÑË÷º¹Çà


https://news.softpedia.com/news/google-allowing-android-users-to-delete-the-last-15-mins-of-search-history-535073.shtml


ÓÐÈËÔÚ Windows 1.0 Öз¢ÏÖÒ»¸öÐÂÉú½Ú²Êµ°


https://news.softpedia.com/news/someone-has-just-discovered-an-easter-egg-in-windows-1-0-535072.shtml


ÎÚ¿ËÀ¼¼ÓÃÜÇ®±Ò³ï¿îÖдæÔÚڲƭ»î¶¯


https://blog.checkpoint.com/2022/03/17/crypto-fundraising-for-ukraine-found-on-the-darknet-used-by-cyber-criminals-for-fraud/


Cisco°ä²¼BlackMatterºÍBlackCatµÄ·ÖÎö»ã±¨


https://blog.talosintelligence.com/2022/03/from-blackmatter-to-blackcat-analyzing.html


IsaacWiper ºÍ CaddyWiper ·ÖÎö»ã±¨


https://blog.malwarebytes.com/threat-intelligence/2022/03/double-header-isaacwiper-and-caddywiper/