ÔËÓªÉÌDP WorldÔâµ½¹¥»÷µ¼Ö°ĴóÀûÑǶà¸ö¿Ú°¶¹Ø±Õ
Ðû²¼Ê±¼ä 2023-11-141¡¢ÔËÓªÉÌDP WorldÔâµ½¹¥»÷µ¼Ö°ĴóÀûÑǶà¸ö¿Ú°¶¹Ø±Õ
¾ÝýÌå11ÔÂ13ÈÕ±¨µÀ£¬ÎïÁ÷¹«Ë¾DP World AustraliaÔâµ½¹¥»÷£¬µ¼Ö°ĴóÀûÑǵÄ4¸öÖ÷Òª¿Ú°¶¹Ø±Õ¡£DP World´¦Öóͷ£°Ä´óÀûÑÇ40%µÄ¼¯×°ÏäÉÌÒµ£¬ÉùÃ÷³Æ£¬11ÔÂ10ÈÕµÄÍøÂç¹¥»÷Ó°ÏìÁËÆä¿Ú°¶µÄ½·»õÔËÓªÒµ¡£×ÔÉÏÖÜÎåÒÔÀ´£¬Ô¼30000¸ö¼¯×°ÏäһֱûÓб»Òƶ¯£¬²¢ÇÒÕ¼ÂúÁË¿ÉÓõĴ洢¿Õ¼ä£¬Ô¤¼ÆËðʧ´ïÊý°ÙÍòÃÀÔª¡£ÏÖÔÚ£¬ÔËÓªÕýÔÚÖð²½»Ö¸´£¬ÉÐÎÞ¹¥»÷ÍÅ»ïÉù³Æ¶Ô´ËÊÂÈÏÕæ¡£
https://www.bleepingcomputer.com/news/security/dp-world-cyberattack-blocks-thousands-of-containers-in-ports/
2¡¢¹¥»÷ÕßÔÚDollyÖ§¸¶²¿·ÖÊê½ðºóÈÔÑ¡Ôñ¹ûÕæ͵ȡµÄÊý¾Ý
ýÌå11ÔÂ10Èճƣ¬ÔÚDolly.comÖ§¸¶²¿·ÖÊê½ðºó£¬¹¥»÷ÕßÈÔȻѡÔñ¹ûÕæ͵ȡµÄÊý¾Ý¡£Dolly.comÔÚ8ÔÂÄ©»ò9Ô³õµÄij¸öʱ¼äÔâµ½ÈëÇÖ£¬ÐÅÓÿ¨ÏêϸÐÅÏ¢ºÍDolly.comÄÚ²¿ÏµÍ³µÄÖÎÀíԱƾ֤µÈÃô¸ÐÊý¾Ýй¶¡£¹¥»÷Õߺ͸ù«Ë¾Ö®¼äµÄÒ»·âÈÕÆÚΪ9ÔÂ7ÈÕµÄÓʼþÏÔʾ£¬DollyÔÞ³ÉÖ§¸¶Êê½ð¡£Æ¾Ö¤¹¥»÷ÕßµÄ˵·¨£¬¸Ã¹«Ë¾È·ÊµÖ§¸¶ÁËÊê½ð£¬µ«²¢È±·¦ÒÔÖª×ãËûÃǵÄÒªÇ󡣸ÃÍÅ»ïûÓÐÍË»ØÊê½ð£¬²¢ÇÒ¹ûÕæÁËй¶Êý¾Ý¡£Î¨Ò»ÖµµÃÇìÐÒµÄÊÇ£¬¿ÉÏÂÔصÄÎļþÔÚÐû²¼Ò»Öܺó±»É¾³ý¡£
https://securityaffairs.com/153975/cyber-crime/dolly-com-pays-ransom.html
3¡¢¼ÓÃÜÉúÒâƽ̨PoloniexÔâµ½¹¥»÷ËðʧÁè¼Ý1ÒÚÃÀÔª
¾Ý11ÔÂ13ÈÕ±¨µÀ£¬ºÚ¿Í´Ó¼ÓÃÜÇ®±ÒÉúÒâƽ̨PoloniexÇÔÈ¡ÁËÁè¼Ý1ÒÚÃÀÔª¡£¸Ãƽ̨ÔÚÉ罻ýÌåÉÏ֤ʵ£¬ÕýÔÚÊÓ²ìÕâÆðÊÂÎñ£¬²¢ÍýÏëÈ«¶îÅâ³¥ÊÜÓ°ÏìµÄ¿Í»§¡£PoloniexÌåÏÖ½«ÏòºÚ¿ÍÖ§¸¶±»µÁ×ʽðµÄ5%×÷ΪÉͽð£¬Ï£ÍûÆäËÍ»¹×ʽð¡£Poloniex³ÆËûÃǵÄÍŶÓÒÑÀÖ³Éʶ±ð²¢¶³½áÁËÓëºÚ¿ÍµØµãÏà¹ØµÄ²¿·Ö×ʲú¡£ÏÖÔÚ£¬ËðʧÔڿɿعæÄ£ÄÚ£¬PoloniexµÄÓªÒµÊÕÈë¿ÉÒÔÌî²¹ÕâЩËðʧ¡£Çå¾²¹«Ë¾Slow MistÌåÏÖËðʧԼΪ1.3ÒÚÃÀÔª£¬Beosin¹«Ë¾Ô¤¼ÆËðʧΪ1.14ÒÚÃÀÔª¡£
https://therecord.media/poloniex-cryptocurrency-platform-millions-stolen
4¡¢Medusa³ÆÒÑÈëÇÖ¼ÓÄôó½ðÈڿƼ¼¹«Ë¾Moneris²¢ÀÕË÷600ÍòÃÀÔª
11ÔÂ14ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïMedusaÔÚÖÜÒ»Éù³ÆËûÃǹ¥»÷ÁËMoneris£¬²¢¸ø¸Ã¹«Ë¾9ÌìµÄʱ¼äÖ§¸¶600ÍòÃÀÔªµÄÊê½ð¡£MonerisÊǼÓÄôóÁ½¼Ò×î´óµÄÒøÐн¨ÉèµÄÒ»¼Ò¿Æ¼¼¹«Ë¾£¬ËüÌåÏÖÒÑÀֳɵÖÓùÁË×î½üµÄÀÕË÷¹¥»÷¡£Òªº¦Êý¾ÝûÓб»»á¼û£¬Ò²Ã»ÓÐÊê½ðÒªÇó¡£Moneris½²»°ÈË˵£¬È·ÊµÓÐÍⲿְԱÊÔͼÈëÇÖMonerisµÄϵͳ£¬µ«ËûÃǵÄÍŶӶÔÕâÒ»ÊÂÎñ¾ÙÐÐÁËÖÜÈ«µÄÉó¼ÆºÍÆÊÎö£¬µÃ³öµÄ½áÂÛÊÇûÓд¥·¢ÆäÊý×Öɥʧ·À»¤Õþ²ß¡£MonerisÔøÔÚ9Ô·ݱ¬·¢ÏµÍ³ÖÐÖ¹£¬Ó°ÏìÁ˼ÓÄôó¸÷µØµÄÊýÊ®¼ÒÆóÒµ¡£
https://therecord.media/moneris-canada-ransomware-attack-prevented
5¡¢Ñо¿Ö°Ô±·¢Ã÷ʹÓÃGoogle Ads·Ö·¢Ä¾Âí»¯CPU-ZµÄÔ˶¯
MalwarebytesÔÚ11ÔÂ8ÈÕÅû¶Á˹¥»÷ÕßÀÄÓÃGoogle Ads·Ö·¢Ä¾Âí»¯CPU-ZµÄÔ˶¯¡£Ä¾Âí»¯CPU-ZµÄ¶ñÒâ¹È¸è¹ã¸æÍйÜÔÚÕýµ±WindowsÐÂÎÅÍøÕ¾WindowsReportµÄ¿Ë¡¸±±¾ÉÏ£¬»á¼ûÕßµã»÷¹ã¸æºó»á±»Öض¨Ïòµ½¶ñÒâÍøÕ¾¡£¶ñÒâÍøÕ¾ÉÏÍйܾÓÉÊý×ÖÊðÃûµÄCPU-Z×°ÖóÌÐò£¨MSIÎļþ£©£¬ÆäÖаüÀ¨¶ñÒâÈí¼þ¼ÓÔسÌÐòFakeBatµÄPowerShell¾ç±¾¡£¼ÓÔسÌÐò´ÓÔ¶³ÌURL»ñÈ¡Redline Stealer payload£¬²¢ÔÚÄ¿µÄÅÌËã»úÉÏÆô¶¯Ëü¡£
https://www.malwarebytes.com/blog/threat-intelligence/2023/11/malvertiser-copies-pc-news-site-to-deliver-infostealer
6¡¢BlackberryÐû²¼¹ØÓÚBiBi-Linux WiperµÄÆÊÎö±¨¸æ
11ÔÂ10ÈÕ£¬BlackberryÐû²¼Á˹ØÓÚBiBi-Linux WiperµÄÆÊÎö±¨¸æ¡£Ñо¿Ö°Ô±Ö®Ç°ÔøÔÚÕë¶ÔÒÔÉ«Áй«Ë¾µÄ¹¥»÷Öз¢Ã÷ÁËÐÂÐͲÁ³ý¶ñÒâÈí¼þBiBi-Linux Wiper£¬Ö®ºóBlackBerry·¢Ã÷ÁËÒ»¸öÕë¶ÔWindowsϵͳµÄ±äÌ壬²¢³ÆΪBiBi-Windows Wiper¡£¸Ã±äÌå¾Ý³Æ±àÒëÓÚ10ÔÂ21ÈÕ£¬ÓëLinux±äÌåµÄÏàËÆÖ®´¦ÊǶàÏ̹߳¦Ð§£¬ËüÔËÐÐ12¸öÏ̺߳Í8¸ö´¦Öóͷ£Æ÷Äںˡ£Õâ¸öWindows±äÌå֤ʵÁË¿ª·¢²Á³ý³ÌÐòµÄ¹¥»÷ÕßÈÔÔÚ¼ÌÐø¹¹½¨¶ñÒâÈí¼þ£¬²¢Åú×¢¹¥»÷¹æÄ£À©´óµ½ÁËÖÕ¶ËÓû§ÅÌËã»úºÍÓ¦Ó÷þÎñÆ÷¡£
https://blogs.blackberry.com/en/2023/11/bibi-wiper-used-in-the-israel-hamas-war-now-runs-on-windows