ÎÚ¿ËÀ¼ÖÁÉÙ11¼ÒµçÐŹ«Ë¾Ôâµ½¹¥»÷µ¼Ö·þÎñÔÝʱÖÐÖ¹
Ðû²¼Ê±¼ä 2023-10-181¡¢ÎÚ¿ËÀ¼ÖÁÉÙ11¼ÒµçÐŹ«Ë¾Ôâµ½¹¥»÷µ¼Ö·þÎñÔÝʱÖÐÖ¹
¾ÝýÌå10ÔÂ17ÈÕ±¨µÀ£¬ÎÚ¿ËÀ¼´ó×ÚµçÐŹ«Ë¾Ôâµ½¹¥»÷¡£ÎÚ¿ËÀ¼ÅÌËã»úÓ¦¼±ÏìӦС×é(CERT-UA)͸¶£¬5ÔÂ11ÈÕÖÁ9ÔÂ27ÈÕ£¬¹¥»÷ÍŻ׷×ÙΪUAC-0165£©ÈëÇÖÁËÖÁÉÙ11¼ÒµçÐÅ·þÎñÌṩÉ̵ÄÐÅÏ¢ºÍͨѶϵͳ£¨ICS£©£¬µ¼Ö¿ͻ§·þÎñÖÐÖ¹¡£¹¥»÷Ê×ÏÈʹÓù¤¾ßmasscan¶ÔÄ¿µÄÍøÂç¾ÙÐÐÕì̽ѰÕÒδ±£»¤µÄRDP»òSSH½Ó¿Ú£¬È»ºóʹÓÃffuf¡¢dirbuster¡¢gowitnessºÍnmapµÈ¹¤¾ßÀ´¼ìË÷Web·þÎñÖеÄÎó²î¡£Ñо¿Ö°Ô±ÔÚ±»ÈëÇÖµÄISPϵͳÖл¹·¢Ã÷ÁËÁ½¸öºóÃÅ£¬¼´PoemgateºÍPoseidon¡£
https://thehackernews.com/2023/10/cert-ua-reports-11-ukrainian-telecom.html
2¡¢ÃÀ¹ú¿°Èø˹Öݸ÷µØ·¨ÔºÔâµ½ÀÕË÷¹¥»÷ÔËÓªÊܵ½Ó°Ïì
ýÌå10ÔÂ16Èճƣ¬ÔÚÔâµ½ÀÕË÷¹¥»÷ºó£¬ÃÀ¹ú¿°Èø˹Öݸ÷µØµÄ·¨ÔºÃæÁÙ×ÅÖÖÖÖÎÊÌâ¡£¿°Èø˹ÖÝ×î¸ß·¨ÔºÔÚÉÏÖÜËÄÐû²¼ÁËÒ»ÏîÐÐÕþÏÂÁ³Æ×èÖ¹10ÔÂ15ÈÕ£¬·¨ÔºÊé¼Ç¹Ù°ì¹«ÊÒ½«ÎÞ·¨¾ÙÐеç×ӹ鵵¡£±¾ÖÜÒ»£¬·¨ÔºÈÔʹÓÃÖ½Öʼͼ£¬ÇÒÓʼþϵͳ´¦ÓڹرÕ״״̬¡£¿°Èø˹ÖÝÈûÆæÍþ¿ËÏØ·¨¹Ù͸¶£¬´Ë´ÎÖÐÖ¹ÊÇÀÕË÷¹¥»÷µ¼Öµģ¬µ«Ã»ÓÐ͸¶¹¥»÷ÍÅ»ïºÍÊê½ðµÄÏà¹ØÐÅÏ¢¡£ÏÖÔÚ£¬¶Ô´ËÊÂÎñµÄÊÓ²ìÕýÔÚ¾ÙÐÐÖУ¬Éв»È·¶¨ÏµÍ³ºÎʱ»á»Ö¸´¡£
https://www.bleepingcomputer.com/news/security/kansas-courts-it-systems-offline-after-security-incident/
3¡¢µçÊÓ¹ã¸æ¹«Ë¾AmpersandÔâµ½Black BastaÀÕË÷¹¥»÷
¾Ý10ÔÂ17ÈÕ±¨µÀ£¬ÃÀ¹úµçÊÓ¹ã¸æÏúÊÛºÍÊÖÒÕ¹«Ë¾AmpersandÔâµ½ÀÕË÷¹¥»÷¡£¸Ã¹«Ë¾ÓÉÃÀ¹úÈý´óÓÐÏßµçÊÓÔËÓªÉÌÅäºÏÓµÓУ¬×Ô1981ÄêÒÔÀ´Ò»Ö±Îª¹ã¸æÉÌÌṩԼ8500Íò»§¼ÒÍ¥µÄÊÕÊÓÊý¾Ý¡£Ampersand³Æ×î½üÔâµ½ÀÕË÷¹¥»÷£¬µ¼ÖÂÔËÓªÔÝʱÖÐÖ¹£¬ÏÖÔÚÒѾ»Ö¸´Á˴󲿷ÖÓªÒµµÄÔËÓª¡£Black BastaÔÚÉÏÖÜÄ©ÌåÏֶԴ˴ι¥»÷ÈÏÕ棬µ«Ã»ÓÐ͸¶ÇÔÈ¡Á˼¸´ó¶¼¾Ý£¬Ò²Ã»ÓÐÐû²¼±»µÁÊý¾ÝÑù±¾¡£
https://therecord.media/ampersand-television-advertising-sales-company-ransomware
4¡¢Cloudflare·¢Ã÷αװ³É¾¯±¨Ó¦ÓÃRedAlertµÄÌع¤Èí¼þ
CloudflareÔÚ10ÔÂ14ÈÕ³ÆÆä·¢Ã÷¶ñÒâ°æ±¾µÄRedAlert ¨C Rocket AlertsÓ¦ÓóÌÐò£¬Ö÷ÒªÕë¶ÔÒÔÉ«ÁеÄAndroidÓû§¡£¸Ã¶ñÒâ°æ±¾Í¨¹ýÍøÕ¾redalerts[.]meÈö²¥£¬¸ÃÍøÕ¾½¨ÉèÓÚ10ÔÂ12ÈÕ£¬¿ÉÓÃÓÚÏÂÔØiOSºÍAndroid°æ±¾Ó¦Óá£ÆäÖÐiOSµÄÏÂÔØ»áÁ´½Óµ½Õýµ±µÄApp StoreÒ³Ã棬AndroidÏÂÔØÖ±½ÓÌṩ¶ñÒâ°æ±¾µÄAPK¡£¸ÃAPKʹÓÃÁËÕæÕýµÄRedAlertµÄ´úÂ룬µ«»áÇëÇóÌØÊâȨÏÞ¡£³ÌÐòÆô¶¯ºó£¬ºǫ́·þÎñ»áÀÄÓÃÕâЩȨÏÞÍøÂçÊý¾Ý£¬²¢ÔÚCBCģʽÏÂÓÃAES¼ÓÃÜ£¬ÉÏ´«µ½Ò»¸öÓ²±àÂëIPµØµã¡£ÏÖÔÚ£¬¸ÃÍøÕ¾ÒѾ¹Ø±Õ¡£
https://blog.cloudflare.com/malicious-redalert-rocket-alerts-application-targets-israeli-phone-calls-sms-and-user-information/
5¡¢Ñо¿Ö°Ô±Åû¶ͨ¹ýDiscord·Ö·¢Lumma StealerµÄÔ˶¯
10ÔÂ16ÈÕ£¬Trend MicroÏêÊöÁ˹¥»÷ÕßÔõÑùʹÓÃDiscordµÄÄÚÈݽ»¸¶ÍøÂç(CDN)À´ÍйܺÍÈö²¥Lumma Stealer£¬²¢ÌÖÂÛÁ˸ÃÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þµÄÐÂÔö¹¦Ð§¡£¹¥»÷Õßͨ³£Ê¹ÓÃËæ»úDiscordÕÊ»§ÏòÄ¿µÄ·¢ËÍÐÂÎÅ£¬Í¨¹ýΪÏîĿ׷Çó×ÊÖú²¢Ìṩ10ÃÀÔª»òDiscord Nitro boostÀ´ÓÕ»óÄ¿µÄ¡£Ä¿µÄÔ޳ɺó»á±»ÒªÇóÏÂÔØÒ»¸öÎļþ£¬ÆäÖаüÀ¨Lumma Stealer¡£¾Ý³Æ£¬Lumma Stealer»¹»á¼ÓÔØÆäËü¶ñÒâÈí¼þ£¬²¢Äܹ»Ê¹ÓÃÈ˹¤ÖÇÄܺÍÉî¶ÈѧϰÀ´¼ì²â»úеÈË¡£
https://www.trendmicro.com/en_us/research/23/j/beware-lumma-stealer-distributed-via-discord-cdn-.html
6¡¢Unit42Ðû²¼¹ØÓÚXorDDoS¹¥»÷Ô˶¯µÄÉîÈëÆÊÎö±¨¸æ
10ÔÂ16ÈÕ£¬Unit42Ðû²¼Á˹ØÓÚXorDDoS¹¥»÷Ô˶¯µÄÉîÈëÆÊÎö±¨¸æ¡£´Ë´ÎÆÊÎöµÄÔ˶¯ÓÚ7ÔÂ28ÈÕ×îÏÈ£¬²¢ÓÚ8ÔÂ12ÈÕ¼¤Ôö£¬ÀÖ³ÉÈëÇÖÁËλÓÚ21¸ö¹ú¼Ò/µØÇøµÄϵͳ£¬ÆäÖд󲿷ֹ¥»÷Á÷Á¿¼¯ÖÐÔÚ·ÇÖÞ¡¢ÄÏÑǺͶ«ÄÏÑÇ¡£¸ÃľÂíѬȾLinux×°±¸²¢½«Æä¼ÓÈëΪ½©Ê¬ÍøÂçÒÔÖ´ÐÐDDoS¹¥»÷£¬¹¥»÷ÕßʹÓÃÁËÒÔÇ°ÀÄÓùýµÄC2Óòе÷½©Ê¬ÍøÂ硣Ȼ¶ø£¬ËûÃÇ×î½ü½«ÆäC2·þÎñÆ÷´Ó¹«¹²ÍйܷþÎñǨáãµ½ÁËеÄIPµØµã¡£
https://unit42.paloaltonetworks.com/new-linux-xorddos-trojan-campaign-delivers-malware/