ÎÚ¿ËÀ¼ÖÁÉÙ11¼ÒµçÐŹ«Ë¾Ôâµ½¹¥»÷µ¼ÖÂЧÀÍÔÝʱÖÐÖ¹

Ðû²¼Ê±¼ä 2023-10-18

1¡¢ÎÚ¿ËÀ¼ÖÁÉÙ11¼ÒµçÐŹ«Ë¾Ôâµ½¹¥»÷µ¼ÖÂЧÀÍÔÝʱÖÐÖ¹


¾ÝýÌå10ÔÂ17ÈÕ±¨µÀ£¬£¬ £¬ £¬ÎÚ¿ËÀ¼´ó×ÚµçÐŹ«Ë¾Ôâµ½¹¥»÷¡£¡£¡£ ¡£¡£ÎÚ¿ËÀ¼ÅÌËã»úÓ¦¼±ÏìӦС×é(CERT-UA)͸¶£¬£¬ £¬ £¬5ÔÂ11ÈÕÖÁ9ÔÂ27ÈÕ£¬£¬ £¬ £¬¹¥»÷ÍŻ׷×ÙΪUAC-0165£©ÈëÇÖÁËÖÁÉÙ11¼ÒµçÐÅЧÀÍÌṩÉ̵ÄÐÅÏ¢ºÍͨѶϵͳ£¨ICS£©£¬£¬ £¬ £¬µ¼Ö¿ͻ§Ð§ÀÍÖÐÖ¹¡£¡£¡£ ¡£¡£¹¥»÷Ê×ÏÈʹÓù¤¾ßmasscan¶ÔÄ¿µÄÍøÂç¾ÙÐÐÕì̽ѰÕÒδ±£»£»£»£» £»£»¤µÄRDP»òSSH½Ó¿Ú£¬£¬ £¬ £¬È»ºóʹÓÃffuf¡¢dirbuster¡¢gowitnessºÍnmapµÈ¹¤¾ßÀ´¼ìË÷WebЧÀÍÖеÄÎó²î¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±ÔÚ±»ÈëÇÖµÄISPϵͳÖл¹·¢Ã÷ÁËÁ½¸öºóÃÅ£¬£¬ £¬ £¬¼´PoemgateºÍPoseidon¡£¡£¡£ ¡£¡£


https://thehackernews.com/2023/10/cert-ua-reports-11-ukrainian-telecom.html


2¡¢ÃÀ¹ú¿°ÈøË¹Öݸ÷µØ·¨ÔºÔâµ½ÀÕË÷¹¥»÷ÔËÓªÊܵ½Ó°Ïì


ýÌå10ÔÂ16Èճƣ¬£¬ £¬ £¬ÔÚÔâµ½ÀÕË÷¹¥»÷ºó£¬£¬ £¬ £¬ÃÀ¹ú¿°ÈøË¹Öݸ÷µØµÄ·¨ÔºÃæÁÙ×ÅÖÖÖÖÎÊÌâ¡£¡£¡£ ¡£¡£¿£¿°ÈøË¹ÖÝ×î¸ß·¨ÔºÔÚÉÏÖÜËÄÐû²¼ÁËÒ»ÏîÐÐÕþÏÂÁ£¬ £¬ £¬³Æ×èÖ¹10ÔÂ15ÈÕ£¬£¬ £¬ £¬·¨ÔºÊé¼Ç¹Ù°ì¹«ÊÒ½«ÎÞ·¨¾ÙÐеç×ӹ鵵¡£¡£¡£ ¡£¡£±¾ÖÜÒ»£¬£¬ £¬ £¬·¨ÔºÈÔʹÓÃÖ½Öʼͼ£¬£¬ £¬ £¬ÇÒÓʼþϵͳ´¦ÓڹرÕ״״̬¡£¡£¡£ ¡£¡£¿£¿°ÈøË¹ÖÝÈûÆæÍþ¿ËÏØ·¨¹Ù͸¶£¬£¬ £¬ £¬´Ë´ÎÖÐÖ¹ÊÇÀÕË÷¹¥»÷µ¼ÖµÄ£¬£¬ £¬ £¬µ«Ã»ÓÐ͸¶¹¥»÷ÍÅ»ïºÍÊê½ðµÄÏà¹ØÐÅÏ¢¡£¡£¡£ ¡£¡£ÏÖÔÚ£¬£¬ £¬ £¬¶Ô´ËÊÂÎñµÄÊÓ²ìÕýÔÚ¾ÙÐÐÖУ¬£¬ £¬ £¬Éв»È·¶¨ÏµÍ³ºÎʱ»á»Ö¸´¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/kansas-courts-it-systems-offline-after-security-incident/


3¡¢µçÊÓ¹ã¸æ¹«Ë¾AmpersandÔâµ½Black BastaÀÕË÷¹¥»÷


¾Ý10ÔÂ17ÈÕ±¨µÀ£¬£¬ £¬ £¬ÃÀ¹úµçÊÓ¹ã¸æÏúÊÛºÍÊÖÒÕ¹«Ë¾AmpersandÔâµ½ÀÕË÷¹¥»÷¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾ÓÉÃÀ¹úÈý´óÓÐÏßµçÊÓÔËÓªÉÌÅäºÏÓµÓУ¬£¬ £¬ £¬×Ô1981ÄêÒÔÀ´Ò»Ö±Îª¹ã¸æÉÌÌṩԼ8500Íò»§¼ÒÍ¥µÄÊÕÊÓÊý¾Ý¡£¡£¡£ ¡£¡£Ampersand³Æ×î½üÔâµ½ÀÕË÷¹¥»÷£¬£¬ £¬ £¬µ¼ÖÂÔËÓªÔÝʱÖÐÖ¹£¬£¬ £¬ £¬ÏÖÔÚÒѾ­»Ö¸´Á˴󲿷ÖÓªÒµµÄÔËÓª¡£¡£¡£ ¡£¡£Black BastaÔÚÉÏÖÜÄ©ÌåÏֶԴ˴ι¥»÷ÈÏÕæ£¬£¬ £¬ £¬µ«Ã»ÓÐ͸¶ÇÔÈ¡Á˼¸´ó¶¼¾Ý£¬£¬ £¬ £¬Ò²Ã»ÓÐÐû²¼±»µÁÊý¾ÝÑù±¾¡£¡£¡£ ¡£¡£


https://therecord.media/ampersand-television-advertising-sales-company-ransomware


4¡¢Cloudflare·¢Ã÷αװ³É¾¯±¨Ó¦ÓÃRedAlertµÄÌØ¹¤Èí¼þ


CloudflareÔÚ10ÔÂ14ÈÕ³ÆÆä·¢Ã÷¶ñÒâ°æ±¾µÄRedAlert ¨C Rocket AlertsÓ¦ÓóÌÐò£¬£¬ £¬ £¬Ö÷ÒªÕë¶ÔÒÔÉ«ÁеÄAndroidÓû§¡£¡£¡£ ¡£¡£¸Ã¶ñÒâ°æ±¾Í¨¹ýÍøÕ¾redalerts[.]meÈö²¥£¬£¬ £¬ £¬¸ÃÍøÕ¾½¨ÉèÓÚ10ÔÂ12ÈÕ£¬£¬ £¬ £¬¿ÉÓÃÓÚÏÂÔØiOSºÍAndroid°æ±¾Ó¦Óᣡ£¡£ ¡£¡£ÆäÖÐiOSµÄÏÂÔØ»áÁ´½Óµ½Õýµ±µÄApp StoreÒ³Ãæ£¬£¬ £¬ £¬AndroidÏÂÔØÖ±½ÓÌṩ¶ñÒâ°æ±¾µÄAPK¡£¡£¡£ ¡£¡£¸ÃAPKʹÓÃÁËÕæÕýµÄRedAlertµÄ´úÂ룬£¬ £¬ £¬µ«»áÇëÇóÌØÊâȨÏÞ¡£¡£¡£ ¡£¡£³ÌÐòÆô¶¯ºó£¬£¬ £¬ £¬ºǫ́ЧÀÍ»áÀÄÓÃÕâЩȨÏÞÍøÂçÊý¾Ý£¬£¬ £¬ £¬²¢ÔÚCBCģʽÏÂÓÃAES¼ÓÃÜ£¬£¬ £¬ £¬ÉÏ´«µ½Ò»¸öÓ²±àÂëIPµØµã¡£¡£¡£ ¡£¡£ÏÖÔÚ£¬£¬ £¬ £¬¸ÃÍøÕ¾ÒѾ­¹Ø±Õ¡£¡£¡£ ¡£¡£


https://blog.cloudflare.com/malicious-redalert-rocket-alerts-application-targets-israeli-phone-calls-sms-and-user-information/


5¡¢Ñо¿Ö°Ô±Åû¶ͨ¹ýDiscord·Ö·¢Lumma StealerµÄ»î¶¯


10ÔÂ16ÈÕ£¬£¬ £¬ £¬Trend MicroÏêÊöÁ˹¥»÷ÕßÔõÑùʹÓÃDiscordµÄÄÚÈݽ»¸¶ÍøÂç(CDN)À´ÍйܺÍÈö²¥Lumma Stealer£¬£¬ £¬ £¬²¢ÌÖÂÛÁ˸ÃÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þµÄÐÂÔö¹¦Ð§¡£¡£¡£ ¡£¡£¹¥»÷Õßͨ³£Ê¹ÓÃËæ»úDiscordÕÊ»§ÏòÄ¿µÄ·¢ËÍÐÂÎÅ£¬£¬ £¬ £¬Í¨¹ýΪÏîĿ׷Çó×ÊÖú²¢Ìṩ10ÃÀÔª»òDiscord Nitro boostÀ´ÓÕ»óÄ¿µÄ¡£¡£¡£ ¡£¡£Ä¿µÄÔ޳ɺó»á±»ÒªÇóÏÂÔØÒ»¸öÎļþ£¬£¬ £¬ £¬ÆäÖаüÀ¨Lumma Stealer¡£¡£¡£ ¡£¡£¾Ý³Æ£¬£¬ £¬ £¬Lumma Stealer»¹»á¼ÓÔØÆäËü¶ñÒâÈí¼þ£¬£¬ £¬ £¬²¢Äܹ»Ê¹ÓÃÈ˹¤ÖÇÄܺÍÉî¶ÈѧϰÀ´¼ì²â»úеÈË¡£¡£¡£ ¡£¡£


https://www.trendmicro.com/en_us/research/23/j/beware-lumma-stealer-distributed-via-discord-cdn-.html


6¡¢Unit42Ðû²¼¹ØÓÚXorDDoS¹¥»÷»î¶¯µÄÉîÈëÆÊÎö±¨¸æ


10ÔÂ16ÈÕ£¬£¬ £¬ £¬Unit42Ðû²¼Á˹ØÓÚXorDDoS¹¥»÷»î¶¯µÄÉîÈëÆÊÎö±¨¸æ¡£¡£¡£ ¡£¡£´Ë´ÎÆÊÎöµÄ»î¶¯ÓÚ7ÔÂ28ÈÕ×îÏÈ£¬£¬ £¬ £¬²¢ÓÚ8ÔÂ12ÈÕ¼¤Ôö£¬£¬ £¬ £¬ÀÖ³ÉÈëÇÖÁËλÓÚ21¸ö¹ú¼Ò/µØÇøµÄϵͳ£¬£¬ £¬ £¬ÆäÖд󲿷ֹ¥»÷Á÷Á¿¼¯ÖÐÔÚ·ÇÖÞ¡¢ÄÏÑǺͶ«ÄÏÑÇ¡£¡£¡£ ¡£¡£¸ÃľÂíѬȾLinux×°±¸²¢½«Æä¼ÓÈëΪ½©Ê¬ÍøÂçÒÔÖ´ÐÐDDoS¹¥»÷£¬£¬ £¬ £¬¹¥»÷ÕßʹÓÃÁËÒÔǰÀÄÓùýµÄC2ÓòЭµ÷½©Ê¬ÍøÂç¡£¡£¡£ ¡£¡£È»¶ø£¬£¬ £¬ £¬ËûÃÇ×î½ü½«ÆäC2ЧÀÍÆ÷´Ó¹«¹²ÍйÜЧÀÍǨáãµ½ÁËеÄIPµØµã¡£¡£¡£ ¡£¡£


https://unit42.paloaltonetworks.com/new-linux-xorddos-trojan-campaign-delivers-malware/