MetaÒòFacebookÊý¾Ý鶱»°®¶ûÀ¼DPC·£¿î2.65ÒÚÅ·Ôª
Ðû²¼Ê±¼ä 2022-11-29¾ÝýÌå11ÔÂ28ÈÕ±¨µÀ£¬Meta±»°®¶ûÀ¼Êý¾Ý±£»¤Î¯Ô±»á(DPC)·£¿î2.65ÒÚÅ·Ôª£¨2.755 ÒÚÃÀÔª£©¡£ÔÒòÊÇ2021ÄêFacebook´ó¹æÄ£Êý¾Ýй¶Ê¼þ£¬Éæ¼°È«ÇòÊýÒÚÓû§µÄÐÅÏ¢¡£ÔÚºÚ¿ÍÐû²¼5.33ÒÚFacebookÓû§µÄÊý¾Ýºó£¬DPCÓÚ2021Äê4ÔÂ14ÈÕÆô¶¯Á˶ÔMetaÎ¥·´GDPRµÄÊӲ졣DPCµÄÊÓ²ìµÃ³ö½áÂÛ£¬MetaÎ¥·´ÁËGDPRµÄµÚ25(1)ºÍ25(2)Ìõ¡£
https://www.bleepingcomputer.com/news/security/meta-fined-265m-for-not-protecting-facebook-users-data-from-scrapers/
2¡¢ÒÁÀÊ·¨¶û˹ͨѶÉçµÄÍøÕ¾Ôâµ½¹¥»÷250 TBÊý¾Ý±»É¾³ý
¾Ý11ÔÂ27ÈÕ±¨µÀ£¬ÒÁÀÊ·¨¶û˹ͨѶÉçµÄÍøÕ¾Ôâµ½ºÚ¿Í¹¥»÷¡£ÃûΪBlack RewardµÄºÚ¿ÍÍÅ»ïÉù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬²¢ÌåÏÖÒÑ´Ó¸ÃÍøÕ¾µÄ·þÎñÆ÷ºÍ¼ÆËã»úÖÐɾ³ýÁ˽ü250 TBµÄÊý¾Ý£¬»¹³ÆÇÔÈ¡Á˸ÃͨѶÉç·¢Ë͸ø¹þ÷ÄÚÒÁ°ì¹«ÊҵĻúÃÜͨ¸æºÍָʾ¡£È»¶ø£¬·¨¶û˹ͨѶÉç·ñÈÏÁ˺ڿÍËùÃèÊöµÄ¹¥»÷ˮƽ£¬³ÆºÚ¿ÍÖ»ÄÜÓ°ÏìÖÜÎåµÄÐÅÏ¢ºÍÐÂÎÅ£¬²¢ÖØÉêÐÂÎÅ»ú¹¹µÄÆäËûÐÅÏ¢ºÍÊý¾Ý¿âûÓб»ÆÆ»µ¡£
https://www.hackread.com/fars-news-agency-website-iran-hacked/
3¡¢Ragnar Locker¹ûÈ»±ÈÀûʱZwijndrecht¾¯²ì¾ÖµÄÊý¾Ý
ýÌå11ÔÂ26Èճƣ¬Ragnar Locker¹ûÈ»ÁËËûÃÇÈÏΪÊÇ´ÓZwijndrechtÊÐÕþÕþ¸®ÇÔÈ¡µÄÊý¾Ý£¬µ«½á¹ûÖ¤Ã÷ÕâЩÊý¾ÝÊÇ´ÓZwijndrecht¾¯²ì¾ÖÇÔÈ¡µÄ¡£¾ÝϤ£¬Ð¹Â¶Êý¾Ý°üÂÞ´óÁ¿³µÅÆ¡¢·£¿î¡¢·¸×ï³ÂËßÎļþ¡¢ÈËÔ±ÏêϸÐÅÏ¢ºÍÊÓ²ì³ÂËߵȡ£´ËÀàÊý¾Ý¿ÉÄÜ»á̻¶¾Ù±¨·¸×ïÐÐΪµÄÈË£¬²¢Î£¼°ÕýÔÚ½øÐеÄÖ´·¨Ðж¯ºÍÊӲ졣±ÈÀûʱýÌå³ÆÕâ´ÎÊý¾Ýй¶ÊÇ´ËÀàʼþÖÐÓ°Ïì¸Ã¹ú¹«¹²·þÎñµÄ×îÑÏÖØʼþÖ®Ò»£¬Ð¹Â¶ÁËZwijndrecht¾¯·½´Ó2006Äêµ½2022Äê9ÔÂÉú´æµÄËùÓÐÊý¾Ý¡£
https://www.bleepingcomputer.com/news/security/ransomware-gang-targets-belgian-municipality-hits-police-instead/
4¡¢Õë¶ÔÎÚ¿ËÀ¼µÄÐÂÀÕË÷Èí¼þRansomBoggsÓëSandwormÓйØ
11ÔÂ25ÈÕ±¨µÀ³Æ£¬Õë¶ÔÎÚ¿ËÀ¼×éÖ¯µÄÐÂÐÍÀÕË÷Èí¼þRansomBoggsÓëºÚ¿ÍÍÅ»ïSandwormÓйء£RansomBoggsÓÚ½ñÄê11ÔÂ21ÈÕÊ״α»ESET¼ì²âµ½£¬¸Ã¹«Ë¾Ö¸³ö£¬ËäÈ»ÓÃ.NET±àдµÄ¶ñÒâÈí¼þÊÇеģ¬µ«ËüµÄ·Ö·¢ÀàËÆÓÚ֮ǰ¹éÒòÓÚSandwormµÄ¹¥»÷»î¶¯¡£ÆäÓÃÓÚ´ÓÓò¿ØÖÆÆ÷·Ö·¢.NETÀÕË÷Èí¼þµÄPowerShell½Å±¾¼¸ºõÓëÈ¥Äê4ÔÂÔÚIndustroyer2¹¥»÷ÄÜÔ´×éÖ¯ÆÚ¼äµÄ½Åµ×ϸͬ¡£Ò»µ©½øÈëÄ¿±êÍøÂ磬RansomBoggs»áÉú³ÉÒ»¸öËæ»úÃÜÔ¿£¬ÔÚCBCģʽÏÂʹÓÃAES-256¼ÓÃÜÎļþ£¬²¢¸½¼Ó.chschÀ©Õ¹Ãû¡£
https://thehackernews.com/2022/11/russia-based-ransomboggs-ransomware.html
5¡¢Ñо¿ÍŶӷ¢ÏÖCrysisµÄ±äÖÖWikiÔÚº«¹ú·Ö·¢µÄ»î¶¯
AhnLabÓÚ11ÔÂ25ÈÕÅû¶ÁËÀÕË÷Èí¼þWikiÔÚº«¹ú·Ö·¢µÄ»î¶¯¡£¸ÃÀÕË÷Èí¼þÒѱ»È·¶¨ÎªCrysisµÄ±äÖÖ£¬Î±×°³ÉÕý³£·¨Ê½¡£ÔÚÖ´ÐÐʵ¼Ê¼ÓÃÜ֮ǰ£¬Wiki½«×Ô¼º¸´ÖƵ½%AppData%»ò%windir%\system32·¾¶£¬²¢Ìí¼Óµ½×¢²á±íÖÐ×¢²áΪÆô¶¯·¨Ê½Ö®Ò»¡£´ËÍ⣬Ëü»¹»á½âÂëÒªÔÚÄÚ´æÖÐÖÕÖ¹µÄÓëÊý¾Ý¿âÏà¹ØµÄ·þÎñºÍ½ø³ÌÃû³Æ£¬²¢²éÕÒµ±Ç°ÕýÔÚÔËÐеķþÎñºÍ½ø³Ì²¢ÖÕÖ¹ËüÃÇ¡£ÓÉÓÚCrysisÀàÐ͵ÄÀÕË÷Èí¼þͨ³£Í¨¹ýRDP·Ö·¢£¬Ñо¿ÈËÔ±½¨Òé×¢ÒâRDPÁ¬½Ó»·¾³¡£
https://asec.ahnlab.com/en/42507/
6¡¢FortiGuardÐû²¼¹ØÓÚÀÕË÷Èí¼þCryptonitµÄ·ÖÎö³ÂËß
11ÔÂ23ÈÕ£¬FortiGuardÐû²¼Á˹ØÓÚÀÕË÷Èí¼þCryptonitµÄ·ÖÎö³ÂËß¡£CryptoniteÊÇÒ»¸öÒÔFOSSÐÎʽ´æÔÚµÄÀÕË÷Èí¼þ¹¤¾ß°ü£¬ÓÉPython¿ª·¢£¬Ê¹ÓÃPyInstaller½øÐдò°ü¡£CryptoniteÓÃÓÚ¼ÓÃÜÎļþµÄÒªÁìÊÇͨ¹ýPython¼ÓÃÜÄ£¿é£¬ËüʹÓÃFernetµÄʵÏÖÀ´ÌṩÕë¶ÔÕû¸öÄ¿±êÎļþµÄ128λAES£¬¼ÓÃÜÎļþµÄÀ©Õ¹ÃûĬÈϸü¸ÄΪ.cryptn8¡£Ò»µ©ËùÓÐÎļþ¶¼±»¼ÓÃÜ£¬Cryptonite¾Í»áʵÑéʹÓÃipinfo.io´ÓÄ¿±êµÄIPµØַʶ±ðÆäλÖ㬲¢ËûµÄ¸ø¼ÒÀï´òµç»°¡£
https://www.fortinet.com/blog/threat-research/Ransomware-Roundup-Cryptonite-Ransomware