ÃÀ¹úÊý°Ù¸öÐÂÎÅÍøÕ¾Ôâµ½¹©¸øÁ´¹¥»÷²¢×°ÖÃSocGholish
°ä²¼¹¦·ò 2022-11-04
ýÌå11ÔÂ2Èճƣ¬TA569ÍÅ»ïÀûÓÃijýÌ幫˾±»ÈëÇֵĻù´¡ÉèÊ©£¬ÔÚÃÀ¹ú250¶à¼ÒÐÂÎÅýÌåµÄÍøÕ¾ÉÏ×°ÖÃSocGholish JavaScript¶ñÒâÈí¼þ¿ò¼Ü£¨Ò²³ÆÎªFakeUpdates£©¡£¹¥»÷ÕßÊ×ÏȽ«¶ñÒâ´úÂë×¢Èëµ½ÍøÕ¾¼ÓÔØµÄJavaScriptÎļþÖУ¬¸ÃÎļþ±»ÓÃÀ´×°ÖÃSocGholish£¬Ëü½«Í¨¹ýαÔìµÄ¸üÐÂÌáÐÑ£¬°Ñ¶ñÒâÈí¼þpayload¼Ù×°³ÉÐéαµÄä¯ÀÀÆ÷¸üÐÂÎļþ£¨ÈçChrom§Ö.U§âdat§Ö.zip¡¢ºÍFirefo§ç.U§âdat§Ö.zipµÈ£©Ï°È¾½Ó¼ûÍøÕ¾µÄÓû§¡£
https://www.bleepingcomputer.com/news/security/hundreds-of-us-news-sites-push-malware-in-supply-chain-attack/
2¡¢×êÑÐÍŶӷ¢ÏÖÊýÊ®¸öÊÔͼ·Ö·¢¶ñÒâÈí¼þW4SPµÄPyPI°ü
Phylum 11ÔÂ1ÈÕ³ÆÆäÔÚPyPI×¢²á±íÖз¢ÏÖÁË29¸öPython°ü£¬ËüÃÇ·ÂÕÕÊ¢ÐеĿ⣬²¢ÔÚϰȾָ±êºó·Ö·¢ÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þW4SP¡£Phylum×êÑÐÈËԱй©£¬Æ¾¾ÝPepy.techµÄͳ¼ÆÊý¾Ý£¬ÕâЩÈí¼þ°üÒѱ»ÏÂÔØÁ˳¬¹ý5700´Î¡£´Ë±í£¬×êÑÐÈËÔ±Hauke L¨¹bbers·¢ÏÖÁËPyPI°üpystileºÍthreadingsÔ̺¬×Ô³ÆÎªGyruzPIPµÄ¶ñÒâÈí¼þ£¬¸Ã¶ñÒâÈí¼þ»ùÓÚÒ»¸ö¿ªÔ´ÏîÄ¿evil-pip¡£L¨¹bbersÒѽ«ÕâЩ°ü»ã±¨¸øPyPIÖÎÀíÔ±¡£
https://blog.phylum.io/phylum-discovers-dozens-more-pypi-packages-attempting-to-deliver-w4sp-stealer-in-ongoing-supply-chain-attack
3¡¢ÎÖ´ï·áÒâ´óÀû¹«Ë¾Åû¶Æä¾ÏúÉ̱»ºÚµ¼ÖµÄÊý¾Ýй¶ÊÂÎñ
¾Ý11ÔÂ2ÈÕ±¨Â·£¬ÎÖ´ï·áÒâ´óÀû¹«Ë¾£¨Vodafone Italia£©Í¨ÖªÆä¿Í»§¹ØÓÚ¾ÏúÉÌFourB SpA±»ºÚµ¼ÖµÄÊý¾Ýй¶ÊÂÎñ¡£¹¥»÷²úÉúÔÚ9ÔµĵÚÒ»ÖÜ£¬Ð¹Â¶ÁËÓû§µÄ¾ßÌåÐÅÏ¢£¬Èç¶©ÔÄÐÅÏ¢¡¢Éí·ÝÖ¤¼þºÍÁªÏµ·½Ê½µÈ¡£Ä¿Ç°£¬FourBÒѾ¹Ø¹ØÁ˶Ա»ÈëÇÖ·þÎñÆ÷µÄ½Ó¼û£¬²¢Ö´ÐÐÁ˸ü¸ß¼¶´ËÍⰲȫսÊõ¡£2022Äê9ÔÂ3ÈÕ£¬×Ô³ÆKelvinSecurityÍÅ»ïÔøÐû³Æ¹¥»÷ÁËVodafone Italia²¢ÇÔÈ¡ÁË295000¸öÎļþ£¬×ܼÆ310 GBµÄÊý¾Ý¡£Æäʱ£¬ÎÖ´ï·á»ØÓ¦³ÆÆä¹«Ë¾ÄÚ²¿ITϵͳ²¢Î´Ô⵽δ¾ÊÚȨµÄ½Ó¼û£¬µ«½«³ÖÐøµ÷²é¡£Éв»Ã÷ÏÔ¸ÃÊÂÎñÊÇ·ñÓëÕâ´ÎÅû¶µÄй¶ÊÂÎñÓйء£
https://www.bleepingcomputer.com/news/security/vodafone-italy-discloses-data-breach-after-reseller-hacked/
4¡¢OPERA1ERÍÅ»ïÒÑ´ÓÒøÐк͵çÐŹ«Ë¾ÇÔÈ¡³¬¹ý1100ÍòÃÀÔª
¾ÝGroup-IB 11ÔÂ3Èճƣ¬ºÚ¿ÍÍÅ»ïOPERA1ERÀûÓÃÏֳɵĺڿ͹¤¾ß£¬ÒÑ´ÓÒøÐк͵çÕÛ·þÎñÌṩÉÌÇÔÈ¡ÁËÖÁÉÙ1100ÍòÃÀÔª¡£³ýÁËÖØÒªÕë¶Ô·ÇÖ޵Ĺ«Ë¾±í£¬¸ÃÍŻﻹ¹¥»÷Á˰¢¸ùÍ¢¡¢°ÍÀ¹çºÍÃϼÓÀ¹úµÄ×éÖ¯¡£´Ó2018Äêµ½2022Ä꣬ºÚ¿Í×ܹ²ÌáÒéÁ˳¬¹ý35´Î³É¹¦µÄ¹¥»÷£¬ÆäÖÐÔ¼Èý·ÖÖ®Ò»ÊÇÔÚ2020Äê½øÐеġ£OPERA1ERÀûÓÃÓã²æÊ½´¹µö¹¥»÷»ñµÃ³õʼ½Ó¼ûȨÏÞ£¬ÖØÒªÒÀ¸½¿ªÔ´¹¤¾ß¡¢ÉÌÆ·¶ñÒâÈí¼þÒÔ¼°MetasploitºÍCobalt StrikeµÈ¿ò¼ÜÀ´ÈëÇÖ¹«Ë¾µÄ·þÎñÆ÷¡£
https://blog.group-ib.com/opera1er-apt
5¡¢Lookout°ä²¼2022ÄêÃÀ¹úµ±¾Ö»ú¹¹ÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨
11ÔÂ2ÈÕ£¬Lookout°ä²¼Á˹ØÓÚ2022ÄêÃÀ¹úµ±¾Ö»ú¹¹ÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨»ùÓÚ¶Ô2021ÄêÖÁ2022ÄêϰëÄêµÄ2ÒŲ́É豸ºÍ1.75ÒÚ¸öÀûÓ÷¨Ê½½øÐзÖÎö£¬·¢ÏÖÃÀ¹úµ±¾ÖÔ±¹¤Ê¹ÓõÄAndroidÊÖ»úÖУ¬½üÒ»°ëÔËÐеÄÊǹýÆÚµÄ²Ù×÷ϵͳ°æ±¾¡£Õë¶ÔÒÆ¶¯Óû§×î³£¼ûµÄ¹¥»÷ÊǶñÒâÈí¼þµÄ´«²¼£¬Ô¼Õ¼75%£¬¶øÆ¾Ö¤ÇÔÈ¡ÔòÕ¼Ôü×Ò±ÈÀýµÄ´ó²¿ÃÅ¡£2022Ä꣬Lookout¼à¿ØµÄ11Ãûµ±¾ÖÔ±¹¤ÖÐÓÐ1ÈËÔâµ½´¹µö¹¥»÷¡£ÄÇЩµã»÷¶ñÒâÁ´½Ó²¢±»ÖÒ¸æµÄÈËÖУ¬57%ûÓÐÔÙ³Á¸´ËûÃǵÄÃýÎó£¬19%µÄÈ˵ã»÷ÁËÁ½´Î£¬24%µÄÈ˵ã»÷ÁËÈý´ÎÒÔÉÏ¡£
https://www.lookout.com/form/threats-government-threat-report-lp
6¡¢Deep Instinct°ä²¼2022ÄêÖÐÆÚÍøÂçÍþÐ²Ì¬ÊÆµÄ»ã±¨
¾ÝýÌå11ÔÂ1Èճƣ¬Deep Instinct°ä²¼ÁË2022ÄêÖÐÆÚÍøÂçÍþÐ²Ì¬ÊÆµÄ»ã±¨¡£»ã±¨Ö¸³ö£¬RaaSÍÅ»ïLockBitÕ¼2022ÄêËùÓÐÀÕË÷¹¥»÷µÄ44%£¬Æä´ÎÊÇConti(23%)¡¢Hive(21%)¡¢Black Cat(7%)ºÍConti Splinters(5%)¡£Ëæ×Å΢ÈíÔÚOfficeÎļþÖÐĬÈϽûÓú꣬ʹÓÃÎĵµµÄ¶ñÒâÈí¼þ×÷ÎªÔØÌåµÄÇé¿öÏ÷¼õÁË£¬È¡¶ø´úÖ®µÄÊÇLNK¡¢HTMLºÍ´æµµµç×ÓÓʼþ¸½¼þ¡£´Ë±í£¬»ã±¨»¹Ìáµ½ÁËÏñSpoolFool¡¢FollinaºÍDirtyPipeÕâÑùµÄ·ì϶͹ÆðÁËWindowsºÍLinuxϵͳµÄ¿ÉÀûÓÃÐÔ£¬ÅúעÿÈýµ½ËĸöÔ±»ÀûÓõķì϶ÊýÁ¿¾Í»á¼¤Ôö¡£
https://www.infosecurity-magazine.com/news/lockbit-dominates-ransomware/


¾©¹«Íø°²±¸11010802024551ºÅ