ÎÚ¿ËÀ¼ÖÁÉÙ11¼ÒµçÐŹ«Ë¾Ôâµ½¹¥»÷µ¼Ö·þÎñÔÝʱÖжÏ

Ðû²¼Ê±¼ä 2023-10-18

1¡¢ÎÚ¿ËÀ¼ÖÁÉÙ11¼ÒµçÐŹ«Ë¾Ôâµ½¹¥»÷µ¼Ö·þÎñÔÝʱÖжÏ


¾ÝýÌå10ÔÂ17ÈÕ±¨µÀ£¬ÎÚ¿ËÀ¼´óÁ¿µçÐŹ«Ë¾Ôâµ½¹¥»÷¡£ÎÚ¿ËÀ¼¼ÆËã»úÓ¦¼±ÏìӦС×é(CERT-UA)͸¶£¬5ÔÂ11ÈÕÖÁ9ÔÂ27ÈÕ£¬¹¥»÷ÍŻ׷×ÙΪUAC-0165£©ÈëÇÖÁËÖÁÉÙ11¼ÒµçÐÅ·þÎñÌṩÉ̵ÄÐÅÏ¢ºÍͨÐÅϵͳ£¨ICS£©£¬µ¼Ö¿ͻ§·þÎñÖжÏ¡£¹¥»÷Ê×ÏÈÀûÓù¤¾ßmasscan¶ÔÄ¿±êÍøÂç½øÐÐÕì²ìѰÕÒδ± £»¤µÄRDP»òSSH½Ó¿Ú£¬È»ºóʹÓÃffuf¡¢dirbuster¡¢gowitnessºÍnmapµÈ¹¤¾ßÀ´¼ìË÷Web·þÎñÖеÄ©¶´¡£Ñо¿ÈËÔ±ÔÚ±»ÈëÇÖµÄISPϵͳÖл¹·¢ÏÖÁËÁ½¸öºóÃÅ£¬¼´PoemgateºÍPoseidon¡£


https://thehackernews.com/2023/10/cert-ua-reports-11-ukrainian-telecom.html


2¡¢ÃÀ¹ú¿°ÈøË¹Öݸ÷µØ·¨ÔºÔâµ½ÀÕË÷¹¥»÷ÔËÓªÊܵ½Ó°Ïì


ýÌå10ÔÂ16Èճƣ¬ÔÚÔâµ½ÀÕË÷¹¥»÷ºó£¬ÃÀ¹ú¿°ÈøË¹Öݸ÷µØµÄ·¨ÔºÃæÁÙ×ÅÖÖÖÖÎÊÌâ¡ £¿°ÈøË¹ÖÝ×î¸ß·¨ÔºÔÚÉÏÖÜËÄÐû²¼ÁËÒ»ÏîÐÐÕþÃüÁ³Æ½ØÖÁ10ÔÂ15ÈÕ£¬·¨ÔºÊé¼Ç¹Ù°ì¹«ÊÒ½«ÎÞ·¨½øÐеç×ӹ鵵¡£±¾ÖÜÒ»£¬·¨ÔºÈÔʹÓÃÖ½ÖʼǼ£¬ÇÒÓʼþϵͳ´¦ÓڹرÕ״״̬¡ £¿°ÈøË¹ÖÝÈûÆæÍþ¿ËÏØ·¨¹Ù͸¶£¬´Ë´ÎÖжÏÊÇÀÕË÷¹¥»÷µ¼ÖµÄ£¬µ«Ã»ÓÐ͸¶¹¥»÷ÍÅ»ïºÍÊê½ðµÄÏà¹ØÐÅÏ¢¡£Ä¿Ç°£¬¶Ô´ËʼþµÄÊÓ²ìÕýÔÚ½øÐÐÖУ¬Éв»È·¶¨ÏµÍ³ºÎʱ»á»Ö¸´¡£


https://www.bleepingcomputer.com/news/security/kansas-courts-it-systems-offline-after-security-incident/


3¡¢µçÊÓ¹ã¸æ¹«Ë¾AmpersandÔâµ½Black BastaÀÕË÷¹¥»÷


¾Ý10ÔÂ17ÈÕ±¨µÀ£¬ÃÀ¹úµçÊÓ¹ã¸æÏúÊۺͼ¼Êõ¹«Ë¾AmpersandÔâµ½ÀÕË÷¹¥»÷¡£¸Ã¹«Ë¾ÓÉÃÀ¹úÈý´óÓÐÏßµçÊÓÔËÓªÉÌÅäºÏÓµÓУ¬×Ô1981ÄêÒÔÀ´Ò»Ö±Îª¹ã¸æÉÌÌṩԼ8500Íò»§¼ÒÍ¥µÄÊÕÊÓÊý¾Ý¡£Ampersand³Æ×î½üÔâµ½ÀÕË÷¹¥»÷£¬µ¼ÖÂÔËÓªÔÝʱÖжÏ£¬Ä¿Ç°ÒѾ­»Ö¸´ÁË´ó²¿ÃÅÒµÎñµÄÔËÓª¡£Black BastaÔÚÉÏÖÜÄ©ÌåÏֶԴ˴ι¥»÷ÂôÁ¦£¬µ«Ã»ÓÐ͸¶ÇÔÈ¡Á˼¸¶àÊý¾Ý£¬Ò²Ã»ÓÐÐû²¼±»µÁÊý¾ÝÑù±¾¡£


https://therecord.media/ampersand-television-advertising-sales-company-ransomware


4¡¢Cloudflare·¢ÏÖαװ³É¾¯±¨Ó¦ÓÃRedAlertµÄ¼äµýÈí¼þ


CloudflareÔÚ10ÔÂ14ÈÕ³ÆÆä·¢ÏÖ¶ñÒâ°æ±¾µÄRedAlert ¨C Rocket AlertsÓ¦Ó÷¨Ê½£¬Ö÷ÒªÕë¶ÔÒÔÉ«ÁеÄAndroidÓû§¡£¸Ã¶ñÒâ°æ±¾Í¨¹ýÍøÕ¾redalerts[.]meÁ÷´«£¬¸ÃÍøÕ¾´´½¨ÓÚ10ÔÂ12ÈÕ£¬¿ÉÓÃÓÚÏÂÔØiOSºÍAndroid°æ±¾Ó¦Óá£ÆäÖÐiOSµÄÏÂÔØ»áÁ´½Óµ½ºÏ·¨µÄApp StoreÒ³Ãæ£¬AndroidÏÂÔØÖ±½ÓÌṩ¶ñÒâ°æ±¾µÄAPK¡£¸ÃAPKʹÓÃÁËÕæÕýµÄRedAlertµÄ´úÂ룬µ«»áÇëÇóÌØ±ðȨÏÞ¡£·¨Ê½Æô¶¯ºó£¬ºǫ́·þÎñ»áÀÄÓÃÕâЩȨÏÞÊÕ¼¯Êý¾Ý£¬²¢ÔÚCBCģʽÏÂÓÃAES¼ÓÃÜ£¬ÉÏ´«µ½Ò»¸öÓ²±àÂëIPµØÖ·¡£Ä¿Ç°£¬¸ÃÍøÕ¾ÒѾ­¹Ø±Õ¡£


https://blog.cloudflare.com/malicious-redalert-rocket-alerts-application-targets-israeli-phone-calls-sms-and-user-information/


5¡¢Ñо¿ÈËÔ±Åû¶ͨ¹ýDiscord·Ö·¢Lumma StealerµÄ»î¶¯


10ÔÂ16ÈÕ£¬Trend MicroÏêÊöÁ˹¥»÷ÕßÈçºÎÀûÓÃDiscordµÄÄÚÈݽ»¸¶ÍøÂç(CDN)À´ÍйܺÍÁ÷´«Lumma Stealer£¬²¢ÌÖÂÛÁ˸ÃÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þµÄÐÂÔö¹¦Ð§¡£¹¥»÷Õßͨ³£Ê¹ÓÃËæ»úDiscordÕÊ»§ÏòÄ¿±ê·¢ËÍÏûÏ¢£¬Í¨¹ýΪÏîĿѰÇó×ÊÖú²¢Ìṩ10ÃÀÔª»òDiscord Nitro boostÀ´ÓÕ»óÄ¿±ê¡£Ä¿±êͬÒâºó»á±»ÒªÇóÏÂÔØÒ»¸öÎļþ£¬ÆäÖаüÂÞLumma Stealer¡£¾Ý³Æ£¬Lumma Stealer»¹»á¼ÓÔØÆäËü¶ñÒâÈí¼þ£¬²¢Äܹ»ÀûÓÃÈ˹¤ÖÇÄܺÍÉî¶ÈѧϰÀ´¼ì²â»úÆ÷ÈË¡£


https://www.trendmicro.com/en_us/research/23/j/beware-lumma-stealer-distributed-via-discord-cdn-.html


6¡¢Unit42Ðû²¼¹ØÓÚXorDDoS¹¥»÷»î¶¯µÄÉîÈë·ÖÎö³ÂËß


10ÔÂ16ÈÕ£¬Unit42Ðû²¼Á˹ØÓÚXorDDoS¹¥»÷»î¶¯µÄÉîÈë·ÖÎö³ÂËß¡£´Ë´Î·ÖÎöµÄ»î¶¯ÓÚ7ÔÂ28ÈÕ¿ªÊ¼£¬²¢ÓÚ8ÔÂ12ÈÕ¼¤Ôö£¬ÀÖ³ÉÈëÇÖÁËλÓÚ21¸ö¹ú¼Ò/µØÓòµÄϵͳ£¬ÆäÖдó²¿ÃŹ¥»÷Á÷Á¿¼¯ÖÐÔÚ·ÇÖÞ¡¢ÄÏÑǺͶ«ÄÏÑÇ¡£¸ÃľÂíѬȾLinuxÉ豸²¢½«Æä¼ÓÈëΪ½©Ê¬ÍøÂçÒÔÖ´ÐÐDDoS¹¥»÷£¬¹¥»÷ÕßÀûÓÃÁËÒÔǰÀÄÓùýµÄC2ÓòЭµ÷½©Ê¬ÍøÂ硣Ȼ¶ø£¬ËûÃÇ×î½ü½«ÆäC2·þÎñÆ÷´Ó¹«¹²ÍйܷþÎñÇ¨ÒÆµ½ÁËеÄIPµØÖ·¡£


https://unit42.paloaltonetworks.com/new-linux-xorddos-trojan-campaign-delivers-malware/