ÃÀ¹úÊý°Ù¸öÐÂÎÅÍøÕ¾Ôâµ½¹©¸øÁ´¹¥»÷²¢×°ÖÃSocGholish

°ä²¼¹¦·ò 2022-11-04
1¡¢ÃÀ¹úÊý°Ù¸öÐÂÎÅÍøÕ¾Ôâµ½¹©¸øÁ´¹¥»÷²¢×°ÖÃSocGholish

      

ýÌå11ÔÂ2ÈÕ³Æ £¬TA569ÍÅ»ïÀûÓÃijýÌ幫˾±»ÈëÇֵĻù´¡ÉèÊ© £¬ÔÚÃÀ¹ú250¶à¼ÒÐÂÎÅýÌåµÄÍøÕ¾ÉÏ×°ÖÃSocGholish JavaScript¶ñÒâÈí¼þ¿ò¼Ü£¨Ò²³ÆÎªFakeUpdates£©¡£¹¥»÷ÕßÊ×ÏȽ«¶ñÒâ´úÂë×¢Èëµ½ÍøÕ¾¼ÓÔØµÄJavaScriptÎļþÖÐ £¬¸ÃÎļþ±»ÓÃÀ´×°ÖÃSocGholish £¬Ëü½«Í¨¹ýαÔìµÄ¸üÐÂÌáÐÑ £¬°Ñ¶ñÒâÈí¼þpayload¼Ù×°³ÉÐéαµÄä¯ÀÀÆ÷¸üÐÂÎļþ£¨ÈçChrom§Ö.U§âdat§Ö.zip¡¢ºÍFirefo§ç.U§âdat§Ö.zipµÈ£©Ï°È¾½Ó¼ûÍøÕ¾µÄÓû§¡£


https://www.bleepingcomputer.com/news/security/hundreds-of-us-news-sites-push-malware-in-supply-chain-attack/


2¡¢×êÑÐÍŶӷ¢ÏÖÊýÊ®¸öÊÔͼ·Ö·¢¶ñÒâÈí¼þW4SPµÄPyPI°ü

      

Phylum 11ÔÂ1ÈÕ³ÆÆäÔÚPyPI×¢²á±íÖз¢ÏÖÁË29¸öPython°ü £¬ËüÃÇ·ÂÕÕÊ¢ÐеĿâ £¬²¢ÔÚϰȾָ±êºó·Ö·¢ÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þW4SP¡£Phylum×êÑÐÈËԱй© £¬Æ¾¾ÝPepy.techµÄͳ¼ÆÊý¾Ý £¬ÕâЩÈí¼þ°üÒѱ»ÏÂÔØÁ˳¬¹ý5700´Î¡£´Ë±í £¬×êÑÐÈËÔ±Hauke L¨¹bbers·¢ÏÖÁËPyPI°üpystileºÍthreadingsÔ̺¬×Ô³ÆÎªGyruzPIPµÄ¶ñÒâÈí¼þ £¬¸Ã¶ñÒâÈí¼þ»ùÓÚÒ»¸ö¿ªÔ´ÏîÄ¿evil-pip¡£L¨¹bbersÒѽ«ÕâЩ°ü»ã±¨¸øPyPIÖÎÀíÔ±¡£


https://blog.phylum.io/phylum-discovers-dozens-more-pypi-packages-attempting-to-deliver-w4sp-stealer-in-ongoing-supply-chain-attack


3¡¢ÎÖ´ï·áÒâ´óÀû¹«Ë¾Åû¶Æä¾­ÏúÉ̱»ºÚµ¼ÖµÄÊý¾Ýй¶ÊÂÎñ

      

¾Ý11ÔÂ2ÈÕ±¨Â· £¬ÎÖ´ï·áÒâ´óÀû¹«Ë¾£¨Vodafone Italia£©Í¨ÖªÆä¿Í»§¹ØÓÚ¾­ÏúÉÌFourB SpA±»ºÚµ¼ÖµÄÊý¾Ýй¶ÊÂÎñ¡£¹¥»÷²úÉúÔÚ9ÔµĵÚÒ»ÖÜ £¬Ð¹Â¶ÁËÓû§µÄ¾ßÌåÐÅÏ¢ £¬Èç¶©ÔÄÐÅÏ¢¡¢Éí·ÝÖ¤¼þºÍÁªÏµ·½Ê½µÈ¡£Ä¿Ç° £¬FourBÒѾ­¹Ø¹ØÁ˶Ա»ÈëÇÖ·þÎñÆ÷µÄ½Ó¼û £¬²¢Ö´ÐÐÁ˸ü¸ß¼¶´ËÍⰲȫսÊõ¡£2022Äê9ÔÂ3ÈÕ £¬×Ô³ÆKelvinSecurityÍÅ»ïÔøÐû³Æ¹¥»÷ÁËVodafone Italia²¢ÇÔÈ¡ÁË295000¸öÎļþ £¬×ܼÆ310 GBµÄÊý¾Ý¡£Æäʱ £¬ÎÖ´ï·á»ØÓ¦³ÆÆä¹«Ë¾ÄÚ²¿ITϵͳ²¢Î´Ô⵽δ¾­ÊÚȨµÄ½Ó¼û £¬µ«½«³ÖÐøµ÷²é¡£Éв»Ã÷ÏÔ¸ÃÊÂÎñÊÇ·ñÓëÕâ´ÎÅû¶µÄй¶ÊÂÎñÓйØ¡£


https://www.bleepingcomputer.com/news/security/vodafone-italy-discloses-data-breach-after-reseller-hacked/


4¡¢OPERA1ERÍÅ»ïÒÑ´ÓÒøÐк͵çÐŹ«Ë¾ÇÔÈ¡³¬¹ý1100ÍòÃÀÔª

      

¾ÝGroup-IB 11ÔÂ3ÈÕ³Æ £¬ºÚ¿ÍÍÅ»ïOPERA1ERÀûÓÃÏֳɵĺڿ͹¤¾ß £¬ÒÑ´ÓÒøÐк͵çÕÛ·þÎñÌṩÉÌÇÔÈ¡ÁËÖÁÉÙ1100ÍòÃÀÔª¡£³ýÁËÖØÒªÕë¶Ô·ÇÖ޵Ĺ«Ë¾±í £¬¸ÃÍŻﻹ¹¥»÷Á˰¢¸ùÍ¢¡¢°ÍÀ­¹çºÍÃϼÓÀ­¹úµÄ×éÖ¯¡£´Ó2018Äêµ½2022Äê £¬ºÚ¿Í×ܹ²ÌáÒéÁ˳¬¹ý35´Î³É¹¦µÄ¹¥»÷ £¬ÆäÖÐÔ¼Èý·ÖÖ®Ò»ÊÇÔÚ2020Äê½øÐеÄ¡£OPERA1ERÀûÓÃÓã²æÊ½´¹µö¹¥»÷»ñµÃ³õʼ½Ó¼ûȨÏÞ £¬ÖØÒªÒÀ¸½¿ªÔ´¹¤¾ß¡¢ÉÌÆ·¶ñÒâÈí¼þÒÔ¼°MetasploitºÍCobalt StrikeµÈ¿ò¼ÜÀ´ÈëÇÖ¹«Ë¾µÄ·þÎñÆ÷¡£


https://blog.group-ib.com/opera1er-apt


5¡¢Lookout°ä²¼2022ÄêÃÀ¹úµ±¾Ö»ú¹¹ÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨

      

11ÔÂ2ÈÕ £¬Lookout°ä²¼Á˹ØÓÚ2022ÄêÃÀ¹úµ±¾Ö»ú¹¹ÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨»ùÓÚ¶Ô2021ÄêÖÁ2022ÄêϰëÄêµÄ2ÒŲ́É豸ºÍ1.75ÒÚ¸öÀûÓ÷¨Ê½½øÐзÖÎö £¬·¢ÏÖÃÀ¹úµ±¾ÖÔ±¹¤Ê¹ÓõÄAndroidÊÖ»úÖÐ £¬½üÒ»°ëÔËÐеÄÊǹýÆÚµÄ²Ù×÷ϵͳ°æ±¾¡£Õë¶ÔÒÆ¶¯Óû§×î³£¼ûµÄ¹¥»÷ÊǶñÒâÈí¼þµÄ´«²¼ £¬Ô¼Õ¼75% £¬¶øÆ¾Ö¤ÇÔÈ¡ÔòÕ¼Ôü×Ò±ÈÀýµÄ´ó²¿ÃÅ¡£2022Äê £¬Lookout¼à¿ØµÄ11Ãûµ±¾ÖÔ±¹¤ÖÐÓÐ1ÈËÔâµ½´¹µö¹¥»÷¡£ÄÇЩµã»÷¶ñÒâÁ´½Ó²¢±»ÖÒ¸æµÄÈËÖÐ £¬57%ûÓÐÔÙ³Á¸´ËûÃǵÄÃýÎó £¬19%µÄÈ˵ã»÷ÁËÁ½´Î £¬24%µÄÈ˵ã»÷ÁËÈý´ÎÒÔÉÏ¡£


https://www.lookout.com/form/threats-government-threat-report-lp


6¡¢Deep Instinct°ä²¼2022ÄêÖÐÆÚÍøÂçÍþÐ²Ì¬ÊÆµÄ»ã±¨

      

¾ÝýÌå11ÔÂ1ÈÕ³Æ £¬Deep Instinct°ä²¼ÁË2022ÄêÖÐÆÚÍøÂçÍþÐ²Ì¬ÊÆµÄ»ã±¨¡£»ã±¨Ö¸³ö £¬RaaSÍÅ»ïLockBitÕ¼2022ÄêËùÓÐÀÕË÷¹¥»÷µÄ44% £¬Æä´ÎÊÇConti(23%)¡¢Hive(21%)¡¢Black Cat(7%)ºÍConti Splinters(5%)¡£Ëæ×Å΢ÈíÔÚOfficeÎļþÖÐĬÈϽûÓúê £¬Ê¹ÓÃÎĵµµÄ¶ñÒâÈí¼þ×÷ÎªÔØÌåµÄÇé¿öÏ÷¼õÁË £¬È¡¶ø´úÖ®µÄÊÇLNK¡¢HTMLºÍ´æµµµç×ÓÓʼþ¸½¼þ¡£´Ë±í £¬»ã±¨»¹Ìáµ½ÁËÏñSpoolFool¡¢FollinaºÍDirtyPipeÕâÑùµÄ·ì϶͹ÆðÁËWindowsºÍLinuxϵͳµÄ¿ÉÀûÓÃÐÔ £¬ÅúעÿÈýµ½ËĸöÔ±»ÀûÓõķì϶ÊýÁ¿¾Í»á¼¤Ôö¡£


https://www.infosecurity-magazine.com/news/lockbit-dominates-ransomware/