ÃÀ¹úDish NetworkÒÉËÆÔâµ½¹¥»÷ÍøÕ¾ºÍÀûÓÃÎÞ·¨½Ó¼û
°ä²¼¹¦·ò 2023-02-271¡¢ÃÀ¹úDish NetworkÒÉËÆÔâµ½¹¥»÷ÍøÕ¾ºÍÀûÓÃÎÞ·¨½Ó¼û
¾ÝýÌå2ÔÂ25ÈÕ±¨Â·£¬ÃÀ¹úµçÊÓºÍÎÀÐǹ㲥ÌṩÉÌDish Network·þÎñÖжϡ£Õâ´ÎÖжÏÓ°ÏìÁËDish NetworkÍøÕ¾ºÍÀûÓ÷¨Ê½£¬Ô̺¬Dish.com¡¢DishWireless.comºÍDish AnywhereµÈ£¬¿Í»§Ò²ÎÞ·¨½Ó¼ûËûÃǵÄÕË»§»òÔÚÏß²¥·ÅµçÊÓ¡£´Ë±í£¬Dish NetworkµÄÔ¶³ÌÔ±¹¤°µÊ¾ÎÞ·¨½Ó¼û¹¤×÷ϵͳ¡£¾ÝDish NetworkµÄÒ»ÃûÔ±¹¤Ð¹Â©£¬¸Ã¹«Ë¾µÄÈ·Ôâµ½ÁËÍøÂç¹¥»÷£¬µ«²¢²»È·¶¨¹¥»÷ÕßÊÇÈôºÎ»ñµÃ½Ó¼ûȨÏ޵ġ£
https://www.bleepingcomputer.com/news/security/dish-network-goes-offline-after-likely-cyberattack-employees-cut-off/
2¡¢Symantec·¢ÏÖÐÂÍÅ»ïClasiopaÕë¶ÔÑÇÖÞij×éÖ¯µÄ¹¥»÷
SymantecÔÚ2ÔÂ23ÈÕ³ÆÆä·¢ÏÖкڿÍÍÅ»ïClasiopaÕë¶ÔÑÇÖÞij×éÖ¯µÄ¹¥»÷»î¶¯¡£Clasiopa»òÐíÓëÓ¡¶Å×йأ¬ÆäÌØµãÊÇÓµÓйÖÒìµÄ¹¤¾ß¼¯£¬Ô̺¬Ò»¸ö×Ô½ç˵¶ñÒâÈí¼þ(Backdoor.Atharvan)¡£¸ÃÍÅ»ïʹÓõÄϰȾý½éÈÎȻδ֪£¬µ«Ò»Ð©Ö¤¾ÝÅú×¢¹¥»÷Õßͨ¹ý¶ÔÃæÏò¹«¼ÒµÄ·þÎñÆ÷½øÐб©Á¦¹¥»÷À´»ñµÃ½Ó¼ûȨÏÞ¡£ÈëÇÖʱËü»á¶Ï¸ùϵͳ¼à¶½Æ÷(Sysmon)ºÍÊÂÎñÈÕÖ¾£¬²¢×°Ööà¸öºóÃÅ£¬ÈçAtharvanºÍ¿ªÔ´Lilith RATµÄÅú¸Ä°æ±¾£¬À´ÍøÂçºÍй¼ûô¸ÐÐÅÏ¢¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/clasiopa-materials-research
3¡¢¼ÓÄôóµçÐŹ«Ë¾Telusµ÷²éÔ´´úÂëºÍÔ±¹¤Êý¾Ýй¶ÊÂÎñ
ýÌå2ÔÂ23Èճƣ¬¼ÓÄôóµÚ¶þ´óµçÐŹ«Ë¾TelusÔÚµ÷²éÆäÔ´´úÂëºÍÔ±¹¤Êý¾Ýй¶ÊÂÎñ¡£2ÔÂ17ÈÕ£¬ºÚ¿ÍÔÚÂÛ̳ÉÏÏúÊ۾ݳÆÊÇTelusÔ±¹¤Ãûµ¥µÄÊý¾Ý£¬Ñù±¾Ô̺¬TelusÔ±¹¤£¨ÓÈÆäÊÇÈí¼þ¿ª·¢ÈËÔ±ºÍ¼¼ÊõÈËÔ±£©µÄÐÕÃûºÍÓʼþµØÖ·¡£2ÔÂ21ÈÕ£¬Í³Ò»ºÚ¿Í´´½¨ÁËÁíÒ»¸öÂÛ̳Ìû×Ó£¬ÒªÏúÊÛTelusµÄ¸öÈËGitHub´æ´¢¿â¡¢Ô´´úÂëÒÔ¼°¹«Ë¾µÄ¹¤×ʵ¥¼Í¼¡£Telus½²»°È˳ƣ¬ËûÃÇÔÚµ÷²é´Îй¶ÊÂÎñ£¬²¢È·Èϵ½Ä¿Ç°ÎªÖ¹£¬ÉÐδ·¢ÏÖÈκι«Ë¾»òÁãÊÛ¿Í»§µÄÊý¾Ýй¶¡£
https://www.bleepingcomputer.com/news/security/telus-investigating-leak-of-stolen-source-code-employee-data/
4¡¢ÎÚ¿ËÀ¼CERTй©UAC-0056ÈëÇÔìä¶à¸öµ±¾ÖÓйØÍøÕ¾
ÎÚ¿ËÀ¼CERTÔÚ2ÔÂ23ÈÕй©£¬UAC-0056ÍÅ»ïÔÚÉÏÖÜÈëÇÖÁËÆä¶à¸öµ±¾ÖÓйØÍøÕ¾¡£×êÑÐÈËÔ±ÔÚÎÚ¿ËÀ¼ÖÐÑëºÍ´¦Ëùµ±¾ÖµÄ¶à¸öÍøÕ¾Éϼì²âµ½¹¥»÷£¬µ¼ÖÂÆä²¿ÃÅÍøÒ³µÄÄÚÈݱ»´Û¸Ä¡£¹¥»÷ÕßʹÓÃSSHºóÃÅCredPump£¨PAMÄ£¿é£©ÊµÏÖÔ¶³ÌSSH½Ó¼û£¨Ê¹Óþ²Ì¬ÃÜÂëÖµ£©£¬²¢ÔÚSSHÏÎ½ÓÆÚ¼ä¼Í¼µÇ¼ºÍÃÜÂë¡£»¹Ê¹ÓÃÁËHoaxPenºÍHoaxApeºóÃÅ£¬¶ñÒâ´úÂëÒÔApacheWeb·þÎñÆ÷Ä£¿éµÄ´ó¾Ö³öÏÖ£¬²¢ÓÚ2022Äê2ÔÂ×°Öá£ÖµÍ×ÌùÐĵÄÊÇ£¬webshellµÄ´´½¨¹¦·ò²»ÍíÓÚ2021Äê12ÔÂ23ÈÕ¡£
https://securityaffairs.com/142678/cyber-warfare-2/cert-of-ukraine-russia-backdoors.html
5¡¢Ë¹Ì¹¸£´óѧÅäÖÃÃýÎóµ¼Ö²¿ÃŲ©Ê¿ÉêÇëÕßµÄÐÅϢй¶
¾Ý2ÔÂ24ÈÕ±¨Â·£¬ÃÀ¹ú˹̹¸£´óѧ¾¼Ãѧ²©Ê¿ÉêÇëÕßµÄÐÅϢй¶¡£¸ÃУ°µÊ¾£¬1ÔÂ24ÈÕÆäÊÕµ½Í¨Öª£¬ÓÉÓÚÎļþ¼ÐÉèÖÃÅäÖÃÃýÎ󣬹«¼ÒÄܹ»Í¨¹ýÍøÕ¾½Ó¼ûÔ̺¬2022-23Äê˹̹¸£´óѧ¾¼Ãϵ²©Ê¿ÏîÄ¿ÈëѧÉêÇëÎļþµÄÎļþ¼Ð¡£ÔÚ¶Ô´ËʽøÐе÷²éºó£¬·¢ÏÖÎÞÏ޶ȵĽӼûÊÇ´Ó2022Äê12ÔÂ5ÈÕÆðÍ·µÄ£¬²¢ÇÒÔÚ2022Äê12ÔÂ5ÈÕÖÁ2023Äê1ÔÂ24ÈÕÖ®¼äÓйýÁ½´ÎÏÂÔØ¡£Ë¹Ì¹¸£´óѧÔÚ·¢ÏÖй¶ÊÂÎñºóµ±¼´²ÉÈ¡´ëÊ©×èÖ¹Á˶ÔÕâЩÎļþµÄ½Ó¼û¡£
https://www.bleepingcomputer.com/news/security/stanford-university-discloses-data-breach-affecting-phd-applicants/
6¡¢×êÑÐÈËÔ±Åû¶ÀûÓÃPureCrypter¹¥»÷µ±¾Ö»ú¹¹µÄ»î¶¯
2ÔÂ23ÈÕ£¬Menlo LabsÅû¶ÁËÀûÓöñÒâÈí¼þÏÂÔØ·¨Ê½PureCrypter¹¥»÷µ±¾Ö»ú¹¹µÄ»î¶¯¡£¹¥»÷ÕßʹÓÃDiscordÀ´Íйܳõʼpayload£¬²¢ÈëÇÖÁËÒ»¸ö·ÇͶ»ú×éÖ¯À´´æ´¢»î¶¯ÖÐʹÓÃµÄÆäËüÖ÷»ú¡£¸Ã»î¶¯´«²¼Á˶àÖÖÀàÐ͵ĶñÒâÈí¼þ£¬Ô̺¬Redline Stealer¡¢AgentTesla¡¢Eternity¡¢BlackmoonºÍPhiladelphia Ransomware¡£×êÑÐÈËÔ±³Æ£¬¹Û²ìµ½µÄPureCrypter»î¶¯ÖØÒªÕë¶ÔÑÇÌ«µØÓòºÍ±±ÃÀµØÓòµÄ¶à¸öµ±¾Ö»ú¹¹¡£
https://www.menlosecurity.com/blog/purecrypter-targets-government-entities-through-discord/


¾©¹«Íø°²±¸11010802024551ºÅ