TrickBotͨ¹ý¼ì²éÆÁÄ»Çø·ÖÂÊÌӱܲ¡¶¾ÆÊÎö£»£»ÐÂÀÕË÷Èí¼þEvilQuestÕë¶ÔMacϵͳ£¬£¬£¬£¬£¬Í¨¹ýµÁ°æÈí¼þÈö²¥

Ðû²¼Ê±¼ä 2020-07-02

1.¶ñÒâÈí¼þTrickBotͨ¹ý¼ì²éÆÁÄ»Çø·ÖÂÊÒÔÌӱܲ¡¶¾ÆÊÎö


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÍøÂçÇå¾²¹«Ë¾MalwareLab·¢Ã÷¶ñÒâÈí¼þTrickBotÒѾ­×îÏÈͨ¹ý¼ì²éÊܺ¦ÕߵįÁÄ»Çø·ÖÂÊ£¬£¬£¬£¬£¬À´¼ì²âÆäÊÇ·ñÔÚÐéÄâ»úÖÐÔËÐУ¬£¬£¬£¬£¬ÒÔÌÓ±ÜÑо¿Ö°Ô±»ò×Ô¶¯É³Ïäϵͳ¶ÔÆä¾ÙÐÐÆÊÎö¡£¡£¡£¡£ ¡£ÐµÄTrickBotÑù±¾ÕýÔÚ¼ì²éÅÌËã»úµÄÆÁÄ»Çø·ÖÂÊÊDz»ÊÇ800x600»ò1024x768£¬£¬£¬£¬£¬ÈôÊÇÊÇ£¬£¬£¬£¬£¬TrickBotÔò»áÁ¬Ã¦ÖÕÖ¹¡£¡£¡£¡£ ¡£TrickBot¼ì²éÕâÐ©ÌØÊâµÄÇø·ÖÂÊ£¬£¬£¬£¬£¬ÊÇÓÉÓÚÑо¿Ö°Ô±Í¨³£ÊÇÕâÑùÉèÖÃËûÃǵÄÐéÄâ»ú¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/trickbot-malware-now-checks-screen-resolution-to-evade-analysis/


2.Ó¡¶È¹ú¼Ò¹«Â·¾Ö(NHAI)ϵͳÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ÏÖÒѻָ´


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Ó¡¶È¹ú¼Ò¹«Â·ÖÎÀí¾Ö£¨NHAI£©ÓÚÉÏÖÜÈÕÍíÉÏÔâµ½ÁËÀÕË÷Èí¼þµÄ¹¥»÷¡£¡£¡£¡£ ¡£¾Ý¸Ã²¿·ÖÔ±¹¤Ëµ£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ¹¥»÷ÁËÕþ¸®µÄµç×ÓÓʼþϵͳ£¬£¬£¬£¬£¬¿ÉÄÜÒ²Ó°ÏìÁËÒÑÍùÊ®ÄêÀ´¸ßËÙ¹«Â·ÉϵĴó×ÚÊý¾ÝºÍÉñÃØÐÅÏ¢¡£¡£¡£¡£ ¡£µ«ØÊºó£¬£¬£¬£¬£¬NHAI½²»°ÈËÌåÏÖ£¬£¬£¬£¬£¬´Ë´Î¹¥»÷ûÓÐÀֳɣ¬£¬£¬£¬£¬ÏÖÔÚϵͳÏÖÒѻָ´£¬£¬£¬£¬£¬Ã»Óб¬·¢Êý¾Ýɥʧ£¬£¬£¬£¬£¬NHAIÊý¾ÝºÍÆäËûϵͳÈÔûÓÐÊܵ½´Ë´Î¹¥»÷µÄÓ°Ïì¡£¡£¡£¡£ ¡£¾ÝSophos³Æ£¬£¬£¬£¬£¬Ó¡¶ÈÔÚÍøÂç·ÀÓù·½ÃæÎª±¡Èõ»·½Ú£¬£¬£¬£¬£¬½öÈ¥Äê¾ÍÓÐ82£¥µÄÓ¡¶È×éÖ¯Ôâµ½ÀÕË÷Èí¼þµÄ¹¥»÷¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hindustantimes.com/india-news/nhai-server-attacked-by-malware-govt-says-no-data-loss/story-wGDAcPUo4MWzPLOcqu2WZJ.html


3.Ê©ÀÖ¹«Ë¾Ôâµ½MazeÀÕË÷Èí¼þ¹¥»÷²¢Ð¹Â¶Áè¼Ý100GBÎļþ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ºÚ¿Í×éÖ¯MazeÓÚ6ÔÂ25ÈÕ¶ÔÊ©ÀÖ¹«Ë¾ÌᳫÁËÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÖÁÉÙÒ»¸öXeroxÓòÖеÄÅÌËã»ú±»¼ÓÃÜ¡£¡£¡£¡£ ¡£¾Ý¹¥»÷Õ߳ƣ¬£¬£¬£¬£¬ËûÃÇÒѾ­´ÓÊ©ÀÖ¹«Ë¾ÇÔÈ¡ÁËÁè¼Ý100GBµÄÎļþ¡£¡£¡£¡£ ¡£¹¥»÷Õß·ÖÏíµÄÆÁÄ»½ØÍ¼ÏÔʾ£¬£¬£¬£¬£¬ÓÉXerox CorporationÖÎÀíµÄ¡° eu.xerox.net¡±ÉϵÄÖ÷»úÊܵ½Á˹¥»÷£¬£¬£¬£¬£¬¸ÃÖ÷»úÃûºÍÓòÃûÌåÏÖÕâ¿ÉÄÜÊÇXeroxÔÚÂ׶صķֹ«Ë¾¡£¡£¡£¡£ ¡£MazeÀÕË÷Èí¼þ½üÆÚÒ»Ö±ÔÚ¹¥»÷ÖÁ¹«Ë¾£¬£¬£¬£¬£¬¸Ã×éÖ¯Éù³Æ×î½ü¹¥»÷µÄ¹«Ë¾°üÀ¨LGµç×Ó¡¢Ð¾Æ¬ÖÆÔìÉÌMaxLinear¡¢IT¾ÞÍ·CognizantºÍÉÌҵЧÀ͹«Ë¾Conduent¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/business-giant-xerox-allegedly-suffers-maze-ransomware-attack/


4.ÐÂÀÕË÷Èí¼þEvilQuestÕë¶ÔMacϵͳ£¬£¬£¬£¬£¬Í¨¹ýµÁ°æÈí¼þ°üÈö²¥


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Çå¾²Ñо¿Ô±Dinesh Devadoss·¢Ã÷ÁËÒ»ÖÖÓÐÊýµÄÕë¶ÔmacOSµÄÐÂÐÍÀÕË÷Èí¼þEvilQuest£¬£¬£¬£¬£¬Í¨¹ýµÁ°æÈí¼þ°üÈö²¥¡£¡£¡£¡£ ¡£EvilQuestÓâÔ½ÁËÀÕË÷Èí¼þµÄͨÀý¼ÓÃܹ¦Ð§£¬£¬£¬£¬£¬Ëü»¹Äܹ»°²ÅżüÅ̼ͼ³ÌÐò£¬£¬£¬£¬£¬ÒÔ¼°Äܹ»ÇÔÈ¡¼ÓÃÜÇ®±ÒÇ®°üÎļþ¡£¡£¡£¡£ ¡£¸Ã¶ñÒâÈí¼þÒþ²ØÔÚµÁ°æÈí¼þÖУ¬£¬£¬£¬£¬Ò»µ©Êܺ¦ÕßÏÂÔØÁËÕâЩ¶ñÒâ³ÌÐò£¬£¬£¬£¬£¬Æä½«»á×°ÖÃÒ»¸öÃûΪ¡°²¹¶¡¡±µÄ¿ÉÖ´ÐÐÎļþµ½¡°/Users/Shared/¡±Ä¿Â¼ÖУ¬£¬£¬£¬£¬È»ºó£¬£¬£¬£¬£¬Å²Óá°eip_encrypt¡±º¯Êý¼ÓÃÜÊܺ¦ÕßµÄÎļþ¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/evilquest-mac-ransomware-keylogger-crypto-wallet-stealing/157034/


5.Googleɾ³ý25¸ö¶ñÒâAndroidÓ¦Ó㬣¬£¬£¬£¬¿ÉÇÔÈ¡Facebookƾ֤


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


¹È¸è±¾ÔÂ´ÓÆäÊÐËÁÖÐɾ³ýÁË25¸öÓÃÀ´ÇÔÈ¡Facebookƾ֤µÄAndroidÓ¦Ó㬣¬£¬£¬£¬ÏÖÔÚËüÃǵÄÏÂÔØÁ¿×ܼÆÁè¼Ý234Íò´Î¡£¡£¡£¡£ ¡£Æ¾Ö¤·¨¹úÇå¾²¹«Ë¾EvinaµÄ±¨¸æ£¬£¬£¬£¬£¬ÕâЩӦÓðüÀ¨¼Æ²½Æ÷¡¢Í¼Ïñ±à¼­Æ÷¡¢ÊÓÆµ±à¼­Æ÷¡¢Ç½Ö½Ó¦Óá¢ÊÖµçͲӦÓá¢ÎļþÖÎÀíÆ÷ºÍÊÖ»úÓÎÏ·¡£¡£¡£¡£ ¡£ËûÃǾùÊÇÊÇÓÉͳһºÚ¿Í×éÖ¯¿ª·¢µÄ£¬£¬£¬£¬£¬Ö»¹Ü¹¦Ð§²î±ð£¬£¬£¬£¬£¬µ«ÊÂÇéÔ­Àí¶¼ÊÇÏàͬµÄ¡£¡£¡£¡£ ¡£ËüÏȼì²âÓû§×î½ü·­¿ªÁËʲôӦÓ㬣¬£¬£¬£¬ÈôÊÇÊÇFacebook£¬£¬£¬£¬£¬¸Ã¶ñÒâÓ¦Óý«ÔÚ¹Ù·½FacebookÓ¦ÓõĶ¥²¿ÁýÕÖÒ»¸öWebä¯ÀÀÆ÷´°¿Ú£¬£¬£¬£¬£¬²¢¼ÓÔØ¼ÙµÄFacebookµÇÂ¼Ò³Ãæ£¬£¬£¬£¬£¬ÓÃÀ´ÇÔÈ¡Óû§µÇ¼ƾ֤¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-removes-25-android-apps-caught-stealing-facebook-credentials/    


6.FakeSpyð³äÓÊÕþЧÀÍÕë¶ÔÃÀ¹ú¡¢ÖйúºÍÅ·ÖÞÓû§ÇÔÈ¡²ÆÎñÐÅÏ¢


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Çå¾²¹«Ë¾Cybereason·¢Ã÷£¬£¬£¬£¬£¬ÔÚÒÑÍùµÄ¼¸ÖÜÄÚ£¬£¬£¬£¬£¬FakeSpyÕýð³äÖÖÖÖÓÊÕþЧÀÍÀ´¹¥»÷ÃÀ¹ú¡¢ÖйúºÍÅ·ÖÞµÄÓû§£¬£¬£¬£¬£¬ÒÔÇÔÈ¡Æä²ÆÎñÐÅÏ¢¡£¡£¡£¡£ ¡£ºÚ¿Íͨ¹ý·¢ËÍαÔìµÄ¶ÌОÙÐй¥»÷£¬£¬£¬£¬£¬µ±Êܺ¦Õßµã»÷ÕâЩ¶ÌÐÅʱ£¬£¬£¬£¬£¬Òþ²ØµÄ´úÂë¾Í»áÇÔÈ¡²ÆÎñÊý¾Ý¡£¡£¡£¡£ ¡£ÓÉÓÚÊÇͨ¹ý·¢ËͶÌОÙÐй¥»÷£¬£¬£¬£¬£¬ËûÃDz»ÐèÒªÈëÇֹȸèÓÎÏ·ÊÐËÁÀ´Ö²ÈëÆä¶ñÒâ´úÂë¡£¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬£¬ºÚ¿Í»¹Í¨¹ý±àдÊÖ»ú¶ñÒâÈí¼þ¹¤¾ß°ü£¬£¬£¬£¬£¬µ÷½â´úÂëÒÔÕë¶ÔÌìÏÂÉϲî±ðµØÇø£¬£¬£¬£¬£¬ÒÔ×·Çó×îÓÐÀû¿ÉͼµÄ¹¥»÷·½·¨¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyberscoop.com/fakespy-android-cybereason-postal-service/