µ¤ÂóÖÐÑëÒøÐÐºÍÆäËü7¼Ò¸öÈËÒøÐеÄÍøÕ¾Ôâµ½DDoS¹¥»÷
°ä²¼¹¦·ò 2023-01-12
·͸Éç1ÔÂ11ÈÕ±¨Â·£¬µ¤ÂóÖÐÑëÒøÐкÍΪ½ðÈÚÐÐÒµ¿ª·¢IT½â¾ö¹æ»®µÄ¹«Ë¾BankdataµÄÍøÕ¾Ôâµ½DDoS¹¥»÷¡£ÑëÐн²»°È˰µÊ¾£¬ÆäÍøÕ¾ÔÚÖܶþÏÂÎçÕý³£ÔËÐУ¬Õâ´Î¹¥»÷²¢Î´Ó°Ïì¸ÃÒøÐÐµÄÆäËüϵͳ»òÈÕ³£ÔËÓª¡£´Ë±í£¬ÔÚBankdataÔâµ½DDoS¹¥»÷ºó£¬ÆäËü7¼Ò¸öÈËÒøÐÐÍøÕ¾µÄ½Ó¼ûÔÚÖܶþÒ²Êܵ½ÁËÏÞ¶È£¬ÆäÖÐÔ̺¬µ¤Âó×î´óµÄÁ½¼ÒÒøÐÐJyske Bank(JYSK.CO)ºÍSydbank(SYDB.CO)¡£
https://www.reuters.com/technology/denmarks-central-bank-website-hit-by-cyberattack-2023-01-10/
2¡¢ESET·¢ÏÖStrongPityÍÅ»ï·Ö·¢Ä¾Âí»¯TelegramµÄ»î¶¯
1ÔÂ10ÈÕ£¬ESET³ÆÆä·¢ÏÖÁËAPT×éÖ¯StrongPityµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯¡£¸Ã»î¶¯×Ô2021Äê11ÔÂÆðÍ·»îÔ¾£¬Í¨¹ýÒ»¸ö¼ÙÒâShagleµÄÍøÕ¾·Ö·¢¶ñÒâÀûÓ÷¨Ê½¡£ShagleÊÇÒ»¸öºÏ·¨µÄËæ»úÊÓÆµÌ¸ÌìÆ½Ì¨£¬µ«Ëü²¢Ã»ÓÐÒÆ¶¯ÀûÓ÷¨Ê½¡£¶ñÒâÀûÓÃÊÇÒ»¸öÃûΪvideo.apkµÄAPKÎļþ£¬ÕâÊǺϷ¨TelegramÀûÓõÄľÂí»¯°æ±¾£¬Ê¹ÓÃÁËStrongPityºóÃÅ´úÂë³Áдò°üÀ´¼ÙÒâShagleÒÆ¶¯ÀûÓá£×°Öú󣬴ËÀûÓÿɽøÐжàÖÖ¼äµý»î¶¯£¬Ô̺¬¼à¿Øµç»°¡¢ÍøÂç¶ÌÐźͻñÈ¡ÁªÏµÈËÁÐ±í¡£
https://www.welivesecurity.com/2023/01/10/strongpity-espionage-campaign-targeting-android-users/
3¡¢ÐµÄDark PinkÍÅ»ïÀûÓÃ×Ô½ç˵¶ñÒâÈí¼þ¹¥»÷¾üÕþ×éÖ¯
Group-IBÓÚ1ÔÂ11ÈÕÅû¶ÁËеÄAPT×éÖ¯Dark PinkÕë¶ÔÑÇÌ«ºÍÅ·ÖÞµØÓòÈ·µ±¾ÖºÍ¾üÊÂ×éÖ¯µÄ¹¥»÷»î¶¯¡£¸Ã»î¶¯Ê¼ÓÚÓã²æÊ½´¹µöÓʼþ£¬ÆäʹÓõÄ×Ô½ç˵¹¤¾ß°ü¿ÉÓÃÓÚÇÔÊØÐÅÏ¢²¢Í¨¹ýUSBÇý¶¯Æ÷´«²¼¶ñÒâÈí¼þ¡£¹¥»÷Õß»¹Í¨¹ýDLL²à¼ÓÔØºÍÊÂÎñ´¥·¢µÄ²½Ö裬ÔÚ±»Ï°È¾µÄϵͳÉÏÔËÐÐÆäpayload¡£Õâ´Î¹¥»÷µÄÖ÷ÌâÊǼäµý»î¶¯£¬Ö¼ÔÚ´ÓÖ¸±êµÄÉ豸ºÍÍøÂçÖÐÇÔÈ¡Îļþ¡¢Âó¿Ë·çÒôƵºÍmessengerÊý¾Ý¡£Group-IB³Æ¸ÃÍÅ»ïÔÚ2022Äê6ÔÂ12ÔÂÒÑÌáÒéÖÁÉÙ7´Î³É¹¦µÄ¹¥»÷¡£
https://www.group-ib.com/media-center/press-releases/dark-pink-apt/
4¡¢³¬¹ý1300¸öÓò¼ÙÒâAnyDeskÍøÕ¾·Ö·¢Vidar Stealer
¾ÝýÌå1ÔÂ10ÈÕ±¨Â·£¬Ò»³¡Ê¹ÓÃÁË1300¶à¸öÓò¼ÙÒâAnyDesk¹Ù·½ÍøÕ¾µÄ´ó¹æÄ£»î¶¯ÔÚ½øÐÐÖС£ÕâЩÓò¶¼½«Óû§³Á¶¨Ïòµ½Í³Ò»¸öDropboxÁ´½Ó£¬Ö¼±ÉÈËÔØVidar stealer£¬ÇÒËùÓÐÓò¶¼½âÎöΪһÑùµÄIPµØÖ·185.149.120[.]9¡£½ØÖÁĿǰ£¬´óÎÞÊýÓòÒÀÈ»ÔÚÏߣ¬¶øÆäËüÓòÒѱ»×¢²áÉ̻㱨²¢ÏÂÏß»ò±»AV¹¤¾ß×èÖ¹¡£ÓÉÓÚAnyDeskµÄÊ¢ÐÐÐÔ£¬Æäʱʱ±»ÀÄÓÃÀ´·Ö·¢¶ñÒâÈí¼þ£¬CybleÔÚ2022Äê10ÔÂÒ²Ôø·¢ÏÖͨ¹ýAnyDesk´¹µöÍøÕ¾·Ö·¢Mitsu StealerµÄ»î¶¯¡£
https://www.bleepingcomputer.com/news/security/over-1-300-fake-anydesk-sites-push-vidar-info-stealing-malware/
5¡¢UptycsÅû¶Õë¶ÔÒâ´óÀûµÄInfostealer¶ñÒâÈí¼þ»î¶¯
UptycsÔÚ1ÔÂ6ÈÕ°ä²¼ÁËÕë¶ÔÒâ´óÀûµÄInfostealer¶ñÒâÈí¼þ»î¶¯µÄ·ÖÎö»ã±¨¡£¹¥»÷»î¶¯µÄ¶à½×¶ÎϰȾÁ´´ÓÒÔ·¢Æ±ÎªÖ÷ÌâµÄ´¹µöÓʼþÆðÍ·£¬ÆäÖÐÔ̺¬Ò»¸öÁ´½Ó£¬µã»÷Á´½Ó»áÏÂÔØÒ»¸öÊÜÃÜÂë±£»¤µÄZIP´æµµÎļþ£¬ÆäÖÐÔ̺¬Ò»¸ö.LNKÎļþºÍÒ»¸ö.BATÎļþ¡£Åú´¦Öþ籾»á´ÓGitHub´æ´¢¿âÖÐ×°ÖöñÒâÈí¼þpayload¡£×°Öú󣬻ùÓÚC#µÄ¶ñÒâÈí¼þ»áÇÔȡϵͳÐÅÏ¢¡¢¼ÓÃÜÇ®°ü¡¢ä¯ÀÀÆ÷º¹Çà¼Í¼¡¢cookieÒÔ¼°¼ÓÃÜÇ®°üµÄÍ´´¦µÈ¡£
https://www.uptycs.com/blog/infostealer-malware-attacks-targeting-italian-region/
6¡¢CiscoÌáÐѿͻ§°ÑÎÈEoL·ÓÉÆ÷ÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶
1ÔÂ11ÈÕ£¬Cisco°ä²¼°²È«¹«¸æÌáÐѿͻ§°ÑÎÈÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2023-20025£©¡£¸Ã·ì϶»áÓ°Ïì¶à¸öÒѶôÖÆÖ§³Ö(EoL)µÄVPN·ÓÉÆ÷£¬Ô̺¬Cisco Small Business RV016¡¢RV042¡¢RV042GºÍRV082·ÓÉÆ÷¡£³É¹¦ÀûÓø÷ì϶¿É»ñµÃroot½Ó¼ûȨÏÞ£¬½«ÆäÓëÁíÒ»¸ö·ì϶£¨CVE-2023-2002£©½áºÏÀûÓÿÉÔڵײã²Ù×÷ϵͳÉÏÖ´ÐÐËÁÒâºÅÁĿǰÒÑÔÚÒ°±í·¢ÏÖ¿ÉÓõĸÅÏëÑéÖ¤·ì϶ÀûÓôúÂ룬ÖÎÀíÔ±Äܹ»Í¨¹ý½ûÓÃÔ¶³ÌÖÎÀí²¢×èÖ¹¶Ô¶Ë¿Ú443ºÍ60443µÄ½Ó¼ûÀ´»º½â·ì϶¡£
https://www.bleepingcomputer.com/news/security/cisco-warns-of-auth-bypass-bug-with-public-exploit-in-eol-routers/


¾©¹«Íø°²±¸11010802024551ºÅ