ÈÕ±¾ÓîÖæº½¿ÕÑо¿¿ª·¢»ú¹¹JAXAµÄAD·þÎñÆ÷Ôâµ½¹¥»÷
Ðû²¼Ê±¼ä 2023-12-01¾ÝýÌå11ÔÂ29ÈÕ±¨µÀ£¬ÈÕ±¾ÓîÖæº½¿ÕÑо¿¿ª·¢»ú¹¹(JAXA)Ôâµ½ÁËÍøÂç¹¥»÷¡£JAXAûÓÐ͸¶¹¥»÷·¢ÉúµÄ¾ßÌåʱ¼ä£¬ÓÐÏûÏ¢ÈËʿ͸¶·¢ÉúÓÚÏᄀ£µ«Ö±µ½Çï¼¾µ±Ö´·¨²¿ÃÅÁªÏµËûÃÇʱ£¬ËûÃDzÅÒâʶµ½´Ë´Î¹¥»÷¡£¾ÝϤ£¬¹¥»÷Õß»ñµÃÁ˶Ըûú¹¹Active Directory (AD)·þÎñÆ÷µÄ·ÃÎÊȨÏÞ£¬¸Ã·þÎñÆ÷ÊǼලJAXAÍøÂçÔËÓªµÄÖØÒª×é¼þ£¬¹ÜÀíÔ±¹¤IDºÍÃÜÂëÒÔ¼°¼ì²ìȨÏÞµÈÐÅÏ¢¡£¾¡¹ÜÉÐδ֤ʵ´æÔÚÊý¾Ýй¶£¬µ«JAXAÊÂÇéÈËÔ±ÌåÏÖ£¬Ö»ÒªAD·þÎñÆ÷±»¹¥»÷£¬¾ÍºÜÓпÉÄÜ¿´µ½´ó²¿ÃÅÐÅÏ¢£¬ÕâÖÖÇé¿ö·Ç³£ÑÏÖØ¡£
https://therecord.media/japan-space-agency-cyberattack
2¡¢AppleÐû²¼½ô¼±Äþ¾²¸üÐÂÐÞ¸´Á½¸öÒѱ»ÀûÓõÄ©¶´
AppleÔÚ11ÔÂ30ÈÕÐû²¼Á˽ô¼±Äþ¾²¸üУ¬ÐÞ¸´iPhone¡¢iPadºÍMacÖÐÁ½¸öÒѱ»ÀûÓõÄ©¶´¡£ÕâÁ½¸ö©¶´¶¼ÊÇÔÚWebKitä¯ÀÀÆ÷ÒýÇæÖз¢Ïֵģ¬Apple»ñϤ©¶´¿ÉÄÜÒÑÔÚiOS 16.7.1֮ǰµÄiOS°æ±¾Öб»ÀûÓᣵÚÒ»¸öÊÇÔ½½ç¶Áȡ©¶´£¨CVE-2023-42916£©£¬¿ÉÓÃÀ´·ÃÎÊÃô¸ÐÐÅÏ¢¡£µÚ¶þ¸öÊÇÄÚ´æËð»µÂ©¶´£¨CVE-2023-42917£©£¬¿ÉÄܵ¼ÖÂÈÎÒâ´úÂëµÄÖ´ÐС£¸Ã¹«Ë¾ÉÐδÐû²¼ÓйØÔÚÒ°ÀûÓù¥»÷µÄÐÅÏ¢¡£×Ô½ñÄêÄê³õÒÔÀ´£¬AppleÒѾÐÞ¸´ÁË20¸öÁãÈÕ©¶´¡£
https://securityaffairs.com/155026/security/apple-emergency-security-updates-2-zero-day.html
3¡¢Â׶ذ®µÂ»ªÆßÊÀ¹úÍõÒ½ÔºÔâµ½RhysidaµÄÀÕË÷¹¥»÷
¾Ý11ÔÂ30ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïRhysidaÉù³ÆÈëÇÖÁËÂ׶ذ®µÂ»ªÆßÊÀ¹úÍõÒ½Ôº¡£¸ÃÍÅ»ïÐû²¼Á˱»µÁÎļþµÄͼƬ×÷Ϊ֤¾Ý£¬°üÂÞÒ½ÁƳÂËß¡¢¹ÒºÅ±í¡¢X¹âƬ¡¢Ò½ÁÆ´¦·½ºÍÒ½ÁƳÂËߵȣ¬»¹³ÆÇÔÈ¡Á˰üÂÞÓ¢¹ú»ÊÊÒÔÚÄڵĴóÁ¿»¼ÕߺÍÔ±¹¤µÄÐÅÏ¢¡£¹¥»÷ÕßÒÔ10 BTCµÄ¼Û¸ñÅÄÂôÇÔÈ¡µÄ´óÁ¿¡°Ãô¸ÐÊý¾Ý¡±¡£ÓëÍù³£Ò»Ñù£¬Ëü¼Æ»®½«Êý¾Ý³öÊÛ¸øÎ¨Ò»µÄÂò¼Ò£¬²¢½«ÔÚͨ¸æÐû²¼ºóµÄÆßÌìÄÚ¹ûÈ»Ðû²¼ÕâЩÊý¾Ý¡£
https://securityaffairs.com/154999/cyber-crime/rhysida-ransomware-king-edward-viis-hospital.html
4¡¢Black Basta×ÔÊ״α»·¢ÏÖÒÔÀ´ÒÑÀÕË÷Áè¼Ý1ÒÚÃÀÔª
EllipticºÍCorvus InsuranceÔÚ11ÔÂ29ÈÕÐû²¼µÄÁªºÏÑо¿ÏÔʾ£¬Black BastaÒÑÀÕË÷Áè¼Ý1ÒÚÃÀÔª¡£Black BastaѬȾÁËÁè¼Ý329¸öÄ¿±ê£¬ÆäÖаüÂÞCapita¡¢ABBºÍDish Network¡£·ÖÎö±íÃ÷£¬×Ô2022Äê³õÒÔÀ´£¬Black BastaÒÑÊÕµ½ÖÁÉÙ1.07ÒÚÃÀÔªÊê½ð£¬Éæ¼°90¸ö±»¹¥»÷Õß¡£ÆäÖÐ×î´óÒ»±ÊÊê½ðµÄ½ð¶îΪ900ÍòÃÀÔª£¬ÖÁÉÙ18±ÊÊê½ðÁè¼Ý100ÍòÃÀÔª£¬Æ½¾ùÊê½ð½ð¶îΪ120ÍòÃÀÔª¡£½ØÖÁ2023ÄêQ3 Black BastaÍøÕ¾ÉÏÁгöµÄ±»¹¥»÷Ä¿±êÊýÁ¿£¬ÖÁÉÙÓÐ35%½»ÁËÊê½ð¡£
https://www.corvusinsurance.com/blog/black-basta-ransomware-has-extracted-over-100-million-from-its-victims
5¡¢AhnLabÅû¶KimsukyÕë¶Ôº«¹úÑо¿»ú¹¹µÄ¹¥»÷»î¶¯
11ÔÂ30ÈÕ£¬AhnLabÅû¶Á˽üÆÚKimsukyÕë¶Ôº«¹úÑо¿»ú¹¹µÄ¹¥»÷»î¶¯¡£¹¥»÷Õßͨ¹ýαװ³É½ø¿Ú±¨¹Øµ¥À´·Ö·¢¶ñÒâJSEÎļþ£¬¸ÃÎļþ°üÂÞÒ»¸ö»ìÏýµÄPowerShell½Å±¾¡¢Ò»¸öBase64±àÂëµÄºóÃÅÎļþºÍÒ»¸öºÏ·¨µÄPDFÎļþ¡£PDFÎļþÃûΪ¡°µ¼ÈëÉùÃ÷.PDF¡±£¬ÓÉPowerShell½Å±¾×Ô¶¯Ö´ÐУ¬Ö¼ÔÚ·ÀÖ¹Óû§·¢ÏÖ½ø³ÌÖÐÕýÔÚÖ´ÐеĶñÒâºóÃÅÎļþ¡£ÎªÁËÇÔȡϵͳÐÅÏ¢£¬ºóÃÅʹÓÃwmicÃüÁî¼ì²éÄ¿±êµÄɱ¶¾Èí¼þ״̬£¬²¢Í¨¹ýipconfigÃüÁîÊÕ¼¯ÍøÂçÐÅÏ¢¡£
https://asec.ahnlab.com/en/59387/
6¡¢SymantecÐû²¼¼äµýÈí¼þÀûÓÃÖÖÖÖ¼¼ÊõÈÆ¹ý·ÖÎöµÄ³ÂËß
11ÔÂ29ÈÕ£¬SymantecÐû²¼Á˼äµýÈí¼þÀûÓÃÖÖÖÖ»ìÏý¼¼ÊõÀ´Èƹý¾²Ì¬·ÖÎöµÄ³ÂËß¡£×î½ü£¬Ñо¿ÈËÔ±·¢ÏÖÁËÒ»¸ö¼äµýÈí¼þ¼¯Èº£¬½ÓÄÉÁËһϵÁм¼ÊõÀ´Ôö¼Ó¾²Ì¬·ÖÎöµÄÄѶȡ£ÆäÖаüÂÞ×ÊԴαװ£¬ÔÚAPKÖд´½¨ÓëÖØÒª×ÊÔ´Ãû³ÆºÍȨÏÞÏàͬµÄĿ¼£»Ñ¹ËõÆÛÆ£¬Í¨¹ý²»ÊÜÖ§³ÖµÄѹËõÒªÁìÀ´Òþ²ØAPKÖеÄÒªº¦×ÊÔ´£»Í¨¹ý'ÎÞѹËõ'Êý¾Ý¹æ±ÜÇ©Ãû·½°¸£»×ÊÔ´»ìÏý£¬¾¹ý"»ìÏý"µÄAndroidManifest.xmlºÍresources.arscÎļþ»áÆÆ»µÄæÏò¹¤³Ì¹¤¾ß£»ÒÔ¼°Î±×°³ÉÓÎÏ·¡¢Ó¦Ó÷¨Ê½ºÍϵͳӦÓõȡ£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/spyware-obfuscation-static-analysis