ÐÂÀÕË÷Èí¼þGoodWillÒªÇóÄ¿±êÍê³ÉÈýÏîÉç»á¾ÈÖú»î¶¯

Ðû²¼Ê±¼ä 2022-05-31

1¡¢ÐÂÀÕË÷Èí¼þGoodWillÒªÇóÄ¿±êÍê³ÉÈýÏîÉç»á¾ÈÖú»î¶¯


¾Ý5ÔÂ29ÈÕ±¨µÀ£¬CloudSEKÅû¶ÁËÒ»ÖÖÃûΪGoodWillµÄÐÂÀÕË÷Èí¼þ ¡£¸ÃÀÕË÷Èí¼þÓÚ2022Äê3ÔÂÊ״α»·¢ÏÖ£¬ÓÉ.NET±àд£¬Ê¹ÓÃAESËã·¨½øÐмÓÃÜ£¬²¢Í¨¹ýÐÝÃß722.45ÃëÀ´×ÌÈŶ¯Ì¬·ÖÎö ¡£Ëü²»ÊdzöÓÚ¾­¼Ã¶¯»úµÄÀÕË÷»î¶¯£¬ÆäÊê½ð¼Ç¼˵Ã÷£¬ÒªÇóÄ¿±ê½øÐÐÈýÏîÉç»á¾ÈÖú»î¶¯²ÅÆø»ñµÃ½âÃܹ¤¾ß£¬°üÂÞÏòÎ޼ҿɹéÕß¾èÔùÐÂÒ·þºÍ̺×Ó£¬ÒÔ¼°´øÎå¸öƶÀ§¶ùͯȥÓ÷¹µÈ ¡£Ö®ºó»¹ÒªÇóÄ¿±êÒÔÆÁÄ»½ØÍ¼ºÍ×ÔÅĵÄÐÎʽ¼Ç¼»î¶¯£¬²¢Ðû²¼ÔÚËûÃǵÄÉ罻ýÌåÉÏ ¡£¹¥»÷ÕßÉí·ÝÉв»Ã÷È·£¬µ«Í¨¹ý·ÖÎö·¢ÏÖÔËÓªÈËÔ±À´×ÔÓ¡¶È ¡£


https://thehackernews.com/2022/05/new-goodwill-ransomware-forces-victims.html


2¡¢EnemyBotµÄ±äÌåÐÂÔöVMwareºÍF5 BIG-IPµÈ©¶´


AT&T Alien LabsÔÚ5ÔÂ26ÈÕÐû²¼µÄÒ»·Ý³ÂËßÖ¸³ö£¬EnemyBotµÄ×îбäÌå°üÂÞ24¸ö©¶´ ¡£ÆäÖдó¶àÊý¶¼ÊÇÑÏÖØµÄ©¶´£¬Óм¸¸öÉõÖÁûÓÐCVE±àºÅ£¬ÕâʹµÃ·ÀÓù±äµÃÔ½·¢À§ÄÑ ¡£¸Ã±äÌå°üÂÞVMwareÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2022-22954£©¡¢SpringÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2022-22947£©ºÍF5 BIG-IPµÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2022-1388£© ¡£EnemyBot±³ºóµÄÍÅ»ïKeksecÈÔÔÚ»ý¼«¿ª·¢¸Ã¶ñÒâÈí¼þ£¬¸ÃÍŻﻹӵÓÐTsunami¡¢Gafgyt¡¢DarkHTTP¡¢DarkIRCºÍNecro ¡£´ËÍ⣬AT&T³ÆEnemyBotµÄÔ´´úÂëÒѾ­¹ûÈ»£¬ÈκÎÈ˶¼¿ÉÒÔÀûÓÃËü ¡£


https://cybersecurity.att.com/blogs/labs-research/rapidly-evolving-iot-malware-enemybot-now-targeting-content-management-system-servers


3¡¢Ñо¿ÈËÔ±ÑÝʾÈçºÎÀûÓõç´ÅÐźÅÔ¶³Ì¿ØÖÆ´¥ÃþÆÁ


¾ÝýÌå5ÔÂ27ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±·¢ÏÖÒ»ÖÖÐµĹ¥»÷·½Ê½GhostTouch£¬¿ÉÀûÓõç´ÅÐźÅÔ¶³Ì¿ØÖÆ´¥ÃþÆÁ ¡£ÆäºËÐÄ˼ÏëÊÇÀûÓõç´ÅÐźÅÀ´Ö´Ðлù±¾µÄ´¥Ãþ²Ù×÷£¬ÀýÈçÇáÇúͻ¬¶¯µ½´¥ÃþÆÁ£¬Ö¼ÔÚ½Ó¹ÜÔ¶³Ì¿ØÖƺͲٿصײãÉ豸 ¡£ÕâÖÖ¹¥»÷¿ÉÔÚ40ºÁÃ׵ľàÀëÄÚ·¢»Ó×÷Óã¬ÆäÒªº¦ÔÚÓÚµçÈÝʽ´¥ÃþÆÁ¶Ôµç´Å×ÌÈÅ£¨EMI£©µÄÃô¸ÐÐÔ£¬ÀûÓÃËü½«µç´ÅÐźÅ×¢ÈëÄÚÖÃÓÚ´¥ÃþÆÁÖеÄ͸Ã÷µç¼« ¡£Ñо¿ÈËÔ±ÌåÏÖ£¬ÈËÃÇ¿ÉÄܻὫÖÇÄÜÊÖ»úÃæ³¯Ï·ÅÔÚ×À×ÓÉÏ£¬¹¥»÷Õ߾ͿÉÒÔ½«¹¥»÷É豸ǶÈë×ÀÃæÏ£¬ÌᳫԶ³Ì¹¥»÷ ¡£


https://thehackernews.com/2022/05/attackers-can-use-electromagnetic.html


4¡¢¹ú¼ÊÐ̾¯×éÖ¯ÒÑ´þ²¶ÈýÃûʹÓÃRAT½øÐнðÈÚ·¸×ïµÄÏÓÒÉÈË


ýÌå5ÔÂ30Èճƣ¬¹ú¼ÊÐ̾¯×éÖ¯ÒÑ´þ²¶ÈýÃûÄáÈÕÀûÑǵÄÍøÂç·¸×ïÏÓÒÉÈË ¡£´Ë´ÎÐж¯´úºÅΪKiller Bee£¬Óɹú¼ÊÐ̾¯×é֯ǣͷ£¬¶«ÄÏÑÇ11¹úµÄÖ´·¨»ú¹¹Ð­Öú ¡£¸ÃÍÅ»ïÉæÏÓʹÓÃÔ¶³Ì·ÃÎÊľÂíAgent Tesla¸Ä¶¯½ðÈÚ½»Òײ¢ÇÔÈ¡ÕË»§Æ¾Ö¤£¬Ä¿±ê°üÂÞÖж«¡¢±±·ÇºÍ¶«ÄÏÑǵĴóÐÍÆóÒµ×éÖ¯ºÍÓÍÆø¹«Ë¾ ¡£Ä¿Ç°£¬Ö´·¨»ú¹¹²¢Î´Í¸Â¶Æä´ÓÄ¿±ê×éÖ¯ÄÇÀïÇÔÈ¡Á˼¸¶àÇ® ¡£ÉÏÖÜ£¬¹ú¼ÊÐ̾¯×éÖ¯µÄÁíÒ»¸ö´úºÅΪDelilahµÄÐж¯Öдþ²¶ÁËSilverTerrierÍÅ»ïµÄÍ·Ä¿ ¡£


https://www.bleepingcomputer.com/news/security/three-nigerians-arrested-for-malware-assisted-financial-crimes/


5¡¢FBI³Æ¹¥»÷ÕßÔÚ°µÍøÉϳöÊÛÃÀ¹ú¸ßУµÄÍøÂç·ÃÎÊÆ¾¾Ý


FBIÔÚ5ÔÂ26ÈÕÐû²¼µÄµÄͨ¸æ³Æ£¬ÃÀ¹ú¸ßУµÄÍøÂç·ÃÎÊÆ¾Ö¤ºÍVPN·ÃÎÊȨÏÞÕýÔÚ°µÍøÉϳöÊÛ ¡£¹¥»÷ÕßÀûÓÃÓã²æÊ½µöÓã¹¥»÷ºÍÀÕË÷¹¥»÷µÈ¼ÆÄ±À´ÊÕ¼¯Æ¾Ö¤£¬È»ºó½«»ñµÃµÄƾ֤Ðû²¼ÔÚ¶íÂÞ˹µÄºÚ¿ÍÂÛ̳ÉÏ£¬ÒÔ¼¸ÃÀÔªµ½¼¸Ç§ÃÀÔª²»µÈµÄ¼Û¸ñ³öÊÛ ¡£¸Ã»ú¹¹³Æ£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩµÇ¼ÐÅÏ¢½øÐб©Á¦×²¿â¹¥»÷£¬¿É¿çÔ½²îÒìµÄÕË»§¡¢ÍøÕ¾ºÍ·þÎñÈëÇÖÄ¿±ê£¬²¢½¨Òéͨ¹ýÏÞÖÆÕÊ»§µÄʹÓÃλÖÃºÍÆôÓõ±µØÉ豸ƾ¾Ý±£»¤»úÖÆÀ´¼õÉÙÆ¾¾Ýй¶ ¡£


https://www.bleepingcomputer.com/news/security/fbi-warns-of-hackers-selling-credentials-for-us-college-networks/


6¡¢KasperskyÐû²¼2022ÄêQ1ÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄ·ÖÎö³ÂËß


5ÔÂ27ÈÕ£¬KasperskyÐû²¼ÁË2022ÄêµÚÒ»¼¾¶ÈÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄ·ÖÎö³ÂËß ¡£³ÂËßÖ¸³ö£¬ÔÚµÚÒ»¼¾¶È¹²¼ì²âµ½516617¸ö¶ñÒâ°²×°°ü£¬±ÈÉÏÒ»¼¾¶È¼õÉÙ79448¸ö£¬ÆäÖÐ53947¸öÓëÊÖ»úÒøÐÐľÂíÓйØ£¬1942¸öÊÇÒÆ¶¯ÀÕË÷Èí¼þ ¡£ÔÚ¼ì²âµ½µÄËùÓÐÍþвÖУ¬Õ¼±È×î´óµÄÊÇRiskToolÓ¦Ó÷¨Ê½£¨48.75%£©£¬Æä´ÎÊÇ¹ã¸æÈí¼þÓ¦Óã¨16.92%£© ¡£Ö÷ÒªµÄÒÆ¶¯¶ñÒâÈí¼þ·¨Ê½ÊÇDangerousObject.Multi.Generic (Õ¼±È20.45%)£¬Æä´ÎÊÇTrojan.AndroidOS.Fakemoney.d£¨10.73%£©ºÍTrojan-SMS.AndroidOS.Fakeapp.d£¨7.82 £© ¡£


https://securelist.com/it-threat-evolution-in-q1-2022-mobile-statistics/106589/