¶íÂÞ˹ÂÉËùRKPLawÔ¼1TBµÄÊý¾Ý±»¹ûÈ»ÔÚDDoSecrets

Ðû²¼Ê±¼ä 2022-06-07

1¡¢¶íÂÞ˹ÂÉËùRKPLawÔ¼1TBµÄÊý¾Ý±»¹ûÈ»ÔÚDDoSecrets


¾Ý6ÔÂ4ÈÕ±¨µÀ£¬¶íÂÞ˹ÂÉʦÊÂÎñËùRustam Kurmaev and Partners(RKP Law) Ô¼1TBµÄÊý¾ÝÒѾ­Ð¹Â¶¡£¾ÝϤ£¬RKP LawÔâµ½ÁËAnonymousµÄÁ¥Êô×éÖ¯B00daºÍPorteurÈëÇÖ¡£PorteurÔÚTwitterÉÏÌåÏÖÇÔÈ¡Á˵ç×ÓÓʼþ¡¢·¨Í¥Îļþ¡¢¿Í»§ÎļþºÍ±¸·ÝµÈÎļþ£¬ÒÔ¼°Ò»¸ö·Ç³£´óµÄ£¨220¸ö¿Í»§£©¿Í»§Áбí¡£´ËÍ⣬±»µÁÊý¾ÝÒ²±»·ÅÔÚÁËDDoSecretsÉÏ¡£¸Ã¹«Ë¾´ú±íÔ¼500¼Ò¿Í»§£¬°üÂÞ¶íÂÞ˹¹«¹²Æû³µ¼¯ÍÅ¡¢Ò˼ҡ¢·áÌïºÍÖÙÁ¿ÁªÐеÈ£¬´Ë´Îй¶Ê¼þ¿ÉÄܶԸù«Ë¾Ôì³É»ÙÃðÐԵĹ¥»÷¡£


https://www.hackread.com/anonymous-hacktivists-leak-1tb-russia-law-firm-data/


2¡¢ÐºڿÍÍÅ»ïCyber SpetsnazÖ÷ÒªÕë¶Ô±±Ô¼µÄ»ù´¡ÉèÊ©


¾ÝýÌå6ÔÂ6ÈÕ±¨µÀ£¬Resecurity·¢ÏÖ½üÆÚÓÉкڿÍÍÅ»ïCyber SpetsnazÌᳫµÄ¹¥»÷»î¶¯ÓÐËùÔö¼Ó¡£¸ÃÍÅ»ïÖ÷ÒªÕë¶Ô±±Ô¼»ù´¡ÉèÊ©½øÐмäµý»î¶¯£¬ÒÔÇÔÈ¡Ãô¸ÐÊý¾Ý¡£Ô¼ÄªÔÚ4Ô£¬¸ÃÍŻィÁ¢Á˵ÚÒ»¸ö²¿ÃÅZarya£¬²¢¶Ô±±Ô¼µÄ×éÖ¯½øÐÐÁËÊ×´ÎЭͬ¹¥»÷¡£6ÔÂ2ÈÕ£¬Ð²¿ÃÅSparta½¨Á¢£¬Ö÷ÒªÂôÁ¦ÖжÏÍøÂç×ÊÔ´ÖжϺÍÇÔÈ¡Ç鱨µÈ£¬ÊÇKillnet CollectiveÍÅ»ïµÄÕýʽ×é³É²¿ÃÅ¡£´ËÍ⣬¸Ã×éÖ¯»¹¹¥»÷ÁËÒâ´óÀûµÄ5¸öÎïÁ÷ÖÕ¶Ë£¨Sech¡¢Trieste¡¢TDT¡¢Yilprort¡¢VTP£©ºÍ¼¸¼ÒÖ÷ÒªµÄ½ðÈÚ»ú¹¹¡£


https://securityaffairs.co/wordpress/131967/hacking/exclusive-pro-russia-cyber-spetsnaz-is-attacking-government-agencies.html


3¡¢ÃÀ¹úFTCÌåÏÖÈ¥Äê¼ÓÃÜ»õ±Ò¹¥»÷Ôì³ÉÁè¼Ý10ÒÚÃÀÔªËðʧ


ÃÀ¹úÁª°îóÒ×ίԱ»á(FTC)ÔÚ6ÔÂ3ÈÕÌåÏÖ£¬2021Äê1ÔÂÖÁ2022Äê3Ô£¬ÓÐÁè¼Ý46000¸öÃÀ¹ú¹«Ãñ³ÂËß³ÆÔâµ½Á˼ÓÃÜ»õ±ÒÕ©Æ­¹¥»÷£¬×ܼÛÖµÁè¼Ý10ÒÚÃÀÔª¡£ÕâÓëFTCÈ¥ÄêµÄ³ÂËßÏà±ÈÔö³¤ÏÔÖø£¬Æäʱ¸Ã»ú¹¹³ÆÔ¼7000ÈË³ÆÆäÔâµ½¹¥»÷£¬ËðʧԼΪ8000ÍòÃÀÔª¡£FBIÌåÏÖ£¬2021ÄêIC3ÊÕµ½ÁË34202ÆðÉæ¼°Ê¹ÓüÓÃÜ»õ±ÒµÄͶËߣ¬±»¹¥»÷ÈËÊý±È2020Ä꣨35229ÈË£©ÓÐËù¼õÉÙ£¬µ«Ëðʧ½ð¶îÔö¼ÓÁ˽üÆß±¶£¬´ÓÔ¼2.4ÒÚÃÀÔªÔö¼Óµ½16ÒÚÃÀÔª¡£


https://www.bleepingcomputer.com/news/security/americans-report-losing-over-1-billion-to-cryptocurrency-scams/


4¡¢Cado LabsÅû¶ºÚ¿ÍÍÅ»ïWatchDog½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú


6ÔÂ2ÈÕ£¬Cado LabsÅû¶ÁËÔÚ½üÆÚ¿ªÕ¹µÄÐÂÒ»ÂÖ¼ÓÃܽٳֻµÄϸ½ÚÐÅÏ¢¡£´Ë´Î»î¶¯ÀûÓÃÁËÏȽøµÄ¼¼ÊõÀ´ÈëÇÖ¡¢worm-likeÁ÷´«²¢ÈƹýÄþ¾²Èí¼þ£¬Ö÷ÒªÕë¶Ô̻¶µÄDocker Engine APIÖն˺ÍRedis·þÎñÆ÷£¬¿ÉÒÔ¿ìËٵشÓһ̨±»Ñ¬È¾µÄÉè±¸ÒÆ¶¯µ½Õû¸öÍøÂç¡£¹¥»÷ÕßµÄÄ¿±êÊÇͨ¹ýÀÄÓÃÄþ¾²ÐԽϲîµÄ·þÎñÆ÷µÄ¿ÉÓüÆËã×ÊÔ´ÍÚ¾ò¼ÓÃÜ»õ±ÒÀ´»ñÀû¡£Í¨¹ý¶Ô¹¥»÷»î¶¯µÄ¼ÆÄ±½øÐзÖÎö£¬Ñо¿ÈËÔ±½«´Ë´Î»î¶¯¹éÒòÓÚWatchDog¡£


https://www.cadosecurity.com/tales-from-the-honeypot-watchdog-evolves-with-a-new-multi-stage-cryptojacking-attack/


5¡¢Mandiant³ÆÆä²¢Î´Ôâµ½ÀÕË÷ÍÅ»ïLockBitµÄ¹¥»÷


¾Ý±¨µÀ£¬6ÔÂ6ÈÕÀÕË÷ÍÅ»ïLockBitÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏÐû²¼ÁËÒ»¸öÐÂÒ³Ãæ£¬³Æ½«¹ûÈ»´ÓMandiantÇÔÈ¡µÄ356841¸öÎļþ¡£Æäʱ£¬¸ÃÍÅ»ïµÄ¼ÆÊ±Æ÷ÏÔʾ¾àÀë¼ÆÊ±½áÊø½öÊ£²»µ½Èý¸öСʱµÄʱ¼ä¡£ÓÉÓÚ¸ÃÐ¹Â¶Ò³ÃæÉϵÄÎļþÁбíΪ¿Õ£¬LockBitÒ²ÉÐδ͸¶Ëü´ÓMandiantµÄϵͳÖÐÇÔÈ¡ÁËÄÄЩÎļþ¡£½öÓÐÒ»¸öÃûΪ¡°mandiantyellowpress.com.7z¡±µÄ0×Ö½ÚÎļþ£¬ËƺõÓëmandiantyellowpress[.]comÓò£¨¸Õ¸Õ×¢²á£©ÓйØ¡£MandiantÔòÌåÏÖÆäÕýÔÚÊÓ²ì´Ë´Îʼþ£¬ÉÐδÕÒµ½Î¥¹æµÄÖ¤¾Ý¡£


https://www.bleepingcomputer.com/news/security/mandiant-no-evidence-we-were-hacked-by-lockbit-ransomware/


6¡¢AvastÐû²¼Android¶ñÒâÈí¼þSMSFactoryµÄ·ÖÎö³ÂËß


AvastÔÚ6ÔÂ1ÈÕÐû²¼Á˹ØÓÚAndroid¶ñÒâÈí¼þSMSFactoryµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬Ò»¿îÃûΪSMSFactoryµÄ¶ñÒâÈí¼þ»áͨ¹ýΪĿ±ê¶©Ôĸ߼¶·þÎñÀ´Ôö¼Ó»°·Ñ³É±¾£¬Æä¾ßÓжàÖÖ·Ö·¢ÇþµÀ£¬°üÂÞ¶ñÒâ¹ã¸æ¡¢ÍÆËÍ֪ͨ¡¢ÍøÕ¾ÉϵĴÙÏúµ¯´°ºÍÆÆ½âÓÎÏ·µÄÊÓÆµµÈ¡£¾ÝAvast³Æ£¬¸Ã¶ñÒâÈí¼þÔÚ2021Äê5ÔÂÖÁ2022Äê5ÔÂѬȾÁËÁè¼Ý165000¸öAndroidÉ豸£¬ÆäÖдó²¿ÃÅλÓÚ¶íÂÞ˹¡¢°ÍÎ÷¡¢°¢¸ùÍ¢¡¢ÍÁ¶úÆäºÍÎÚ¿ËÀ¼¡£


http://blog.avast.com/smsfactory-android-trojan