ÐÂÀÕË÷ÍÅ»ïRed CryptoApp½ÓÄɼ¤½øÕ½ÂÔÐßÈèÊܺ¦Õß
Ðû²¼Ê±¼ä 2024-04-074ÔÂ4ÈÕ£¬Netenrich µÄÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÃûΪ Red Ransomware Group (Red CryptoApp) µÄÐÂÀÕË÷×éÖ¯¡£¸Ã×éÖ¯µÄÔË×÷·½·¨Óëµä·¶µÄÀÕË÷Èí¼þ×éÖ¯²î±ð£¬ËûÃǵÄÀÕË÷Õ½ÂÔÓÐËù²î±ð¡£Óë´ó´ó¶¼Òþ²ØÆä²Ù×÷µÄÀÕË÷Èí¼þ×éÖ¯²î±ð£¬Red CryptoApp Ëƺõ½ÓÄÉÁ˼¤½øµÄÒªÁì¡£¾Ý Netenrich ³Æ£¬¸Ã×éÖ¯½¨ÉèÁË¡°ÐßÈèǽ¡±£¬²¢Ðû²¼ÁËËûÃÇÀÖ³ÉÃé×¼µÄ¹«Ë¾Ãû³Æ¡£ÕâÖÖÕ½ÂÔÖ¼ÔÚÐßÈèÊܺ¦Õß²¢ÆÈʹËûÃÇÖ§¸¶Êê½ðÒÔɾ³ýËûÃǵÄÃû×Ö¡£Ñо¿Ö°Ô±×¢Öص½¸Ã×é֯׫дµÄÒ»·ÝÀÕË÷Èí¼þÌõ¼ÇÓë 2020 Äê Maze ÀÕË÷Èí¼þÍÅ»ïÓÐһЩÏàËÆÖ®´¦¡£Õâ¿ÉÄÜÊÇÇɺϣ¬Ò²¿ÉÄÜÊÇÇɺϡ£Òò´Ë£¬Éв»ÇåÎú Red Ransomware Group ÊÇ·ñÊÇ Maze ÍÅ»ïµÄÑÜÉúÆ·£¬Maze ÍÅ»ïÓÚ 2020 Äê 11 Ô¹رÕÁËÆäÓªÒµ¡£Red CryptoApp ÀÕË÷Èí¼þÍÅ»ïµÄÐßÈèǽ£¬ÃÀ¹úÊÇÖ÷ҪĿµÄ£¬Æä´ÎÊǵ¤Âó¡¢Ó¡¶È¡¢Î÷°àÑÀ¡¢Òâ´óÀû¡¢Ð¼ÓƺͼÓÄôóµÈÆäËû¹ú¼Ò¡£¾ÍÄ¿µÄÐÐÒµ¶øÑÔ£¬Èí¼þºÍÖÆÔìÒµ³ÉΪ×î³£¼ûµÄÄ¿µÄÐÐÒµ£¬½ÌÓý¡¢ÐÞ½¨¡¢ÂÃ¹ÝºÍ IT ÐÐÒµÒ²Êܵ½¹Ø×¢¡£
https://www.hackread.com/red-ransomware-group-red-cryptoapp-wall-of-shame/?web_view=true
2. CoralRaiderºÚ¿ÍÍÅ»ïÃé×¼Õû¸öÑÇÖ޵ĽðÈÚÐÐÒµ
4ÔÂ5ÈÕ£¬Ë¼¿Æ Talos µÄÑо¿Ö°Ô±·¢Ã÷ÁËһϵÁÐÃûΪ CoralRaider µÄºÚ¿ÍÔ˶¯£¬Ê¹ÓÃÉø͸¶ñÒâÈí¼þ¹¥»÷Ó¡¶È¡¢Öйú¡¢º«¹ú¡¢ÃϼÓÀ¹ú¡¢°Í»ù˹̹¡¢Ó¡¶ÈÄáÎ÷ÑǺͺ£ÄÚÄ¿µÄ¡£Talos ºÜÊÇÓÐÐÅÐĵؽ«¸Ã×éÖ¯µÄÆðÔ´¹éÒòÓÚÔ½ÄÏ£¬²¢Ö¸³öºÚ¿ÍÔÚÆä Telegram ÏÂÁîºÍ¿ØÖÆͨµÀÖÐʹÓÃÔ½ÄÏÓ²¢½«Ô½ÄÏÓïµ¥´ÊÓ²±àÂëµ½ÓÐÓøºÔضþ½øÖÆÎļþÖС£ÆäIPµØµã¿É×·Ëݵ½ºÓÄÚ¡£ºÚ¿ÍʹÓà RotBot£¨Ò»ÖÖ¶¨ÖƵÄÔ¶³Ì»á¼û¹¤¾ß£¨ Quasar RATµÄ±äÌ壩£©ÏÂÔØÐÅÏ¢ÇÔÈ¡³ÌÐò£¬¸Ã³ÌÐò»á²éÕÒ°üÀ¨Ö§¸¶¿¨µÈÊý¾ÝµÄÉÌÒµÉ罻ýÌåÕÊ»§¡£µ±Óû§·¿ª¶ñÒâ Windows ¿ì½Ý·½·¨Îļþʱ£¬CoralRaider ¹¥»÷¾Í»á×îÏÈ£¬´Ó¶ø´¥·¢Ñ¬È¾Á´¡£ËþÂå˹ÌåÏÖ£¬ÏÖÔÚÉв»ÇåÎúÍþвÕßÔõÑù½«Îļþת´ï¸øÊܺ¦Õß¡£¼¤»îµÄLNKÎļþ»áÏÂÔØÒ»¸öHTMLÓ¦ÓóÌÐòÎļþ£¬¸ÃÎļþÖ´ÐÐVirtual Basic¾ç±¾£¬¸Ã¾ç±¾ÓÖÔÚÄÚ´æÖÐÖ´ÐÐPowerShell¾ç±¾¡°½âÃܲ¢Ë³ÐòÖ´ÐÐÆäËûÈý¸öPowerShell¾ç±¾£¬ÕâЩ¾ç±¾Ö´Ðз´ÐéÄâ»úºÍ·´ÆÊÎö¼ì²é£¬ÈƹýÓû§»á¼û¿ØÖÆ¡¢½ûÓÃÊܺ¦Õß»úеÉ쵀 Windows ºÍÓ¦ÓóÌÐò֪ͨ£¬×îºóÏÂÔز¢ÔËÐÐ RotBot¡£
https://www.govinfosecurity.com/vietnamese-threat-actor-targeting-financial-data-across-asia-a-24796?&web_view=true
3. Ð嵀 Latrodectus ¶ñÒâÈí¼þÈ¡´úÁËÍøÂçÎó²îÖÐµÄ IcedID
4ÔÂ4ÈÕ£¬Ò»ÖÖÃûΪ Latrodectus µÄÏà¶Ô½ÏеĶñÒâÈí¼þ±»ÒÔΪÊÇ IcedID ¼ÓÔسÌÐòµÄÑݱ䣬¸Ã¼ÓÔسÌÐò×Ô 2023 Äê 11 ÔÂÒÔÀ´Ò»Ö±ÔÚ¶ñÒâµç×ÓÓʼþÔ˶¯ÖзºÆð¡£ProofpointºÍ Team CymruµÄÑо¿Ö°Ô±·¢Ã÷Á˸öñÒâÈí¼þ £¬ËûÃÇÅäºÏ¼Í¼ÁËÆ书Ч£¬µ«ÕâЩ¹¦Ð§ÈÔÈ»²»ÎȹÌÇÒ´¦ÓÚʵÑé½×¶Î¡£IcedID ÊÇÒ»¸öÓÚ 2017 ÄêÊ״η¢Ã÷µÄ¶ñÒâÈí¼þ¼Ò×壬×î³õ±»¹éÀàΪģ¿é»¯ÒøÐÐľÂí£¬Ö¼ÔÚ´ÓÊÜѬȾµÄÅÌËã»úÖÐÇÔÈ¡²ÆÎñÐÅÏ¢¡£Ëæ×Åʱ¼äµÄÍÆÒÆ£¬Ëü±äµÃÔ½·¢ÖØ´ó£¬ÔöÌíÁËÌӱܺÍÏÂÁîÖ´Ðй¦Ð§¡£½üÄêÀ´£¬Ëü³äµ±Á˼ÓÔسÌÐòµÄ½ÇÉ«£¬¿ÉÒÔ½«ÆäËûÀàÐ͵ĶñÒâÈí¼þ£¨°üÀ¨ÀÕË÷Èí¼þ£©´«Ë͵½ÊÜѬȾµÄϵͳÉÏ¡£´Ó 2022 Äê×îÏÈ£¬¶à¸ö IcedID Ô˶¯Õ¹Ê¾ÁË ¶àÑù»¯µÄת´ïÕ½ÂÔ£¬µ«Ö÷ÒªµÄ·Ö·¢·½·¨ÈÔÈ»ÊǶñÒâµç×ÓÓʼþ¡£2022 Äê⣬ ¸Ã¶ñÒâÈí¼þµÄбäÖÖ ±»ÓÃÓÚ¹¥»÷£¬²¢ÊµÑéÁËÖÖÖÖ¹æ±Ü¼¼ÇɺÍÐµĹ¥»÷¼¯¡£
https://www.bleepingcomputer.com/news/security/new-latrodectus-malware-replaces-icedid-in-network-breaches/?&web_view=true
4. Visa ÖÒÑÔÕë¶Ô½ðÈÚ»ú¹¹µÄРJSOutProx ¶ñÒâÈí¼þ±äÌå
4ÔÂ4ÈÕ£¬Visa ÖÒÑԳƣ¬Õë¶Ô½ðÈÚ»ú¹¹¼°Æä¿Í»§µÄа汾 JsOutProx ¶ñÒâÈí¼þ¼ì²âÊýÄ¿¼¤Ôö¡£¸ÃÔ˶¯Õë¶ÔÄÏÑǺͶ«ÄÏÑÇ¡¢Öж«ºÍ·ÇÖ޵ĽðÈÚ»ú¹¹¡£JsOutProx ÓÚ 2019 Äê 12 ÔÂÊ×´ÎÓöµ½£¬ÊÇÒ»ÖÖÔ¶³Ì»á¼ûľÂí (RAT) ºÍ¸ß¶È»ìÏýµÄ JavaScript ºóÃÅ£¬ÔÊÐíÆä²Ù×÷ÕßÔËÐÐ shell ÏÂÁî¡¢ÏÂÔØÌØÁíÍ⸺ÔØ¡¢Ö´ÐÐÎļþ¡¢²¶»ñÆÁÄ»½Øͼ¡¢ÔÚÊÜѬȾµÄ×°±¸ÉϽ¨É賤ÆÚÐÔ²¢¿ØÖƼüÅ̺ÍÊó±ê¡£Visa ¾¯±¨ÖÐдµÀ£º¡°ËäÈ» PFD ÎÞ·¨È·ÈÏ×î½ü·¢Ã÷µÄ¶ñÒâÈí¼þÔ˶¯µÄ×îÖÕÄ¿µÄ£¬µ«¸ÃÍøÂç·¸·¨×é֮֯ǰ¿ÉÄÜÔøÕë¶Ô½ðÈÚ»ú¹¹¾ÙÐÐÚ²ÆÔ˶¯¡£¡±¸Ã¾¯±¨ÌṩÁËÓë×îÐÂÔ˶¯Ïà¹ØµÄÍ×ÐÖ¸±ê (IoC)£¬²¢½¨Òé½ÓÄɶàÏ½â²½·¥£¬°üÀ¨Ìá¸ß¶ÔÍøÂç´¹ÂÚΣº¦µÄÊìϤ¡¢ÆôÓà EMV ºÍÇå¾²½ÓÊÜÊÖÒÕ¡¢±£»¤Ô¶³Ì»á¼ûÒÔ¼°¼à¿Ø¿ÉÒÉÉúÒâ¡£
https://www.bleepingcomputer.com/news/security/visa-warns-of-new-jsoutprox-malware-variant-targeting-financial-orgs/?&web_view=true
5. ÎÂÄá²®´óѧÊýǧÃû½ÌÖ°Ô±¹¤ºÍѧÉúµÄÃô¸ÐÊý¾Ý±»µÁ
4ÔÂ5ÈÕ£¬¼ÓÄôóÎÂÄá²®´óѧ֤ʵ£¬ºÚ¿ÍÔÚÉϸöÔÂÄ©±¬·¢µÄÒ»ÆðÊÂÎñÖÐÇÔÈ¡Á˸ûú¹¹µÄÃô¸ÐÐÅÏ¢£¬Ó°ÏìÁËÒÔÇ°ºÍÏÖÔÚµÄѧÉúºÍ½ÌÖ°Ô±¹¤¡£ÕâËùÓµÓÐ 18,000 ¶àÃûѧÉúºÍ 800 Ãû½ÌÖ°Ô±¹¤µÄ´óѧÔÚÖÜËĵÄÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬¡°±»µÁµÄÐÅÏ¢¿ÉÄÜ°üÀ¨Ä¿½ñºÍÒÔÇ°µÄѧÉúºÍÔ±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡±ÕâÆðÍøÂçÊÂÎñÓÚ 3 Ô 25 ÈÕÊ×´ÎÐû²¼£¬Æäʱ¸Ã»ú¹¹ÏÂÏßÁËһϵÁзþÎñ¡£¼¸Ììºó£¬¸Ã´óѧУ³¤Íе¡¤Ãɶà¶û²©Ê¿ÌåÏÖ£¬ÎÂÄá²®ÔâÊÜÁË¡°Õë¶Ô´óѧÍøÂçµÄÓÐÕë¶ÔÐÔµÄÍøÂç¹¥»÷¡±¡£¸Ã´óѧÌåÏÖ£¬ÊÓ²ìÕýÔÚ¾ÙÐÐÖУ¬¡°¿ÉÄÜÐèҪʱ¼ä£¬¿ÉÄÜÊǼ¸¸öÔ¡±£¬ÏÖÔڸôóѧÒÔΪ¹¥»÷ÕßÄܹ»»á¼ûÎļþ·þÎñÆ÷¡£¸ÃÍøÂçÊÂÎñµÄÐÔ×ÓÉÐδ»ñµÃ֤ʵ£¬µ«¸Ã´óѧÌåÏÖ¡°ÍµÇÔÊÂÎñºÜ¿ÉÄܱ¬·¢ÔÚ 3 Ô 24 ÈÕ֮ǰµÄÒ»ÖÜ¡£¡±¸Ã´óѧÌåÏÖ£¬½«ÎªÊÜÓ°ÏìµÄСÎÒ˽¼ÒÌṩΪÆÚÁ½ÄêµÄÐÅÓüà¿Ø·þÎñ£¬²¢ÃãÀøËùÓÐÊÜÓ°ÏìµÄÈË×¢²á£¬²¢Ö¸³öËü»¹ÎªËæºó³ÉΪڲÆÕßÄ¿µÄµÄÈκÎÈËÌṩ°ü¹ÜÌõ¿î¡£
https://therecord.media/university-of-winnipeg-cyberattack
6. ºÚ¿ÍʹÓà Facebook ¹ã¸æºÍЮÖÆÒ³ÃæÍƹãÐéαÈ˹¤ÖÇÄÜ·þÎñ
4ÔÂ5ÈÕ£¬ÕâЩ¶ñÒâ¹ã¸æÔ˶¯ÊÇͨ¹ýЮÖÆ Facebook СÎÒ˽¼Ò×ÊÁϽ¨ÉèµÄ£¬ÕâЩСÎÒ˽¼Ò×ÊÁÏð³äÊ¢ÐеÄÈ˹¤ÖÇÄÜ·þÎñ£¬Ã°³äÌṩй¦Ð§µÄÔ¤ÀÀ¡£±»¹ã¸æÓÕƵÄÓû§³ÉΪڲÆÐÔ Facebook ÉçÇøµÄ³ÉÔ±£¬ÍþвÐÐΪÕßÔÚÆäÖÐÐû²¼ÐÂÎÅ¡¢È˹¤ÖÇÄÜÌìÉúµÄͼÏñºÍÆäËûÏà¹ØÐÅÏ¢£¬ÒÔʹҳÃæ¿´ÆðÀ´Õýµ±¡£È»¶ø£¬ÉçÇøÌû×Ó¾³£ÌᳫÏÞʱ»á¼û¼´½«ÍƳöÇÒ±¸ÊÜÆÚ´ýµÄ AI ·þÎñ£¬ÓÕÆÓû§ÏÂÔضñÒâ¿ÉÖ´ÐÐÎļþ£¬ÕâЩ¿ÉÖ´ÐÐÎļþ»áʹÓà Rilide¡¢Vidar¡¢IceRAT ºÍ Nova µÈÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þѬȾ Windows ÅÌËã»ú¡£ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þרעÓÚ´ÓÊܺ¦ÕßµÄä¯ÀÀÆ÷ÇÔÈ¡Êý¾Ý£¬°üÀ¨´æ´¢µÄƾ֤¡¢cookie¡¢¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡¢×Ô¶¯Íê³ÉÊý¾ÝºÍÐÅÓÿ¨ÐÅÏ¢¡£È»ºó£¬ÕâЩÊý¾Ý»áÔÚ°µÍøÊг¡ÉϳöÊÛ£¬»ò±»¹¥»÷ÕßÓÃÀ´ÆÆËðÄ¿µÄµÄÔÚÏßÕÊ»§£¬ÒÔÔö½ø½øÒ»²½µÄÕ©Æ»ò¾ÙÐÐڲơ£Facebook µÈÉ罻ýÌåÍøÂç¹æÄ£Öش󣬼ÓÉÏî¿ÏµÈ±·¦£¬Ê¹µÃÕâЩÔ˶¯Äܹ»ºã¾ÃÒ»Á¬£¬´Ó¶øÔö½ø¶ñÒâÈí¼þ²»ÊÜ¿ØÖƵÄÈö²¥£¬´Ó¶øµ¼Ö¶ñÒâÈí¼þѬȾÔì³ÉÆÕ±éË𺦡£
https://www.bleepingcomputer.com/news/security/fake-facebook-midjourney-ai-page-promoted-malware-to-12-million-people/