ÐÂÀÕË÷ÍÅ»ïRed CryptoApp½ÓÄɼ¤½øÕ½ÂÔÐßÈèÊܺ¦Õß

Ðû²¼Ê±¼ä 2024-04-07
1. ÐÂÀÕË÷ÍÅ»ïRed CryptoApp½ÓÄɼ¤½øÕ½ÂÔÐßÈèÊܺ¦Õß


4ÔÂ4ÈÕ£¬ £¬£¬£¬£¬Netenrich µÄÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÃûΪ Red Ransomware Group (Red CryptoApp) µÄÐÂÀÕË÷×éÖ¯¡£¡£¡£¸Ã×éÖ¯µÄÔË×÷·½·¨Óëµä·¶µÄÀÕË÷Èí¼þ×éÖ¯²î±ð£¬ £¬£¬£¬£¬ËûÃǵÄÀÕË÷Õ½ÂÔÓÐËù²î±ð¡£¡£¡£Óë´ó´ó¶¼Òþ²ØÆä²Ù×÷µÄÀÕË÷Èí¼þ×éÖ¯²î±ð£¬ £¬£¬£¬£¬Red CryptoApp ËÆºõ½ÓÄÉÁ˼¤½øµÄÒªÁì¡£¡£¡£¾Ý Netenrich ³Æ£¬ £¬£¬£¬£¬¸Ã×éÖ¯½¨ÉèÁË¡°ÐßÈèǽ¡±£¬ £¬£¬£¬£¬²¢Ðû²¼ÁËËûÃÇÀÖ³ÉÃé×¼µÄ¹«Ë¾Ãû³Æ¡£¡£¡£ÕâÖÖÕ½ÂÔÖ¼ÔÚÐßÈèÊܺ¦Õß²¢ÆÈʹËûÃÇÖ§¸¶Êê½ðÒÔɾ³ýËûÃǵÄÃû×Ö¡£¡£¡£Ñо¿Ö°Ô±×¢Öص½¸Ã×é֯׫дµÄÒ»·ÝÀÕË÷Èí¼þÌõ¼ÇÓë 2020 Äê Maze ÀÕË÷Èí¼þÍÅ»ïÓÐһЩÏàËÆÖ®´¦¡£¡£¡£Õâ¿ÉÄÜÊÇÇɺÏ£¬ £¬£¬£¬£¬Ò²¿ÉÄÜÊÇÇɺÏ¡£¡£¡£Òò´Ë£¬ £¬£¬£¬£¬Éв»ÇåÎú Red Ransomware Group ÊÇ·ñÊÇ Maze ÍÅ»ïµÄÑÜÉúÆ·£¬ £¬£¬£¬£¬Maze ÍÅ»ïÓÚ 2020 Äê 11 Ô¹رÕÁËÆäÓªÒµ¡£¡£¡£Red CryptoApp ÀÕË÷Èí¼þÍÅ»ïµÄÐßÈèǽ£¬ £¬£¬£¬£¬ÃÀ¹úÊÇÖ÷ҪĿµÄ£¬ £¬£¬£¬£¬Æä´ÎÊǵ¤Âó¡¢Ó¡¶È¡¢Î÷°àÑÀ¡¢Òâ´óÀû¡¢ÐÂ¼ÓÆÂºÍ¼ÓÄôóµÈÆäËû¹ú¼Ò¡£¡£¡£¾ÍÄ¿µÄÐÐÒµ¶øÑÔ£¬ £¬£¬£¬£¬Èí¼þºÍÖÆÔìÒµ³ÉΪ×î³£¼ûµÄÄ¿µÄÐÐÒµ£¬ £¬£¬£¬£¬½ÌÓý¡¢ÐÞ½¨¡¢ÂÃ¹ÝºÍ IT ÐÐÒµÒ²Êܵ½¹Ø×¢¡£¡£¡£


https://www.hackread.com/red-ransomware-group-red-cryptoapp-wall-of-shame/?web_view=true


2. CoralRaiderºÚ¿ÍÍÅ»ïÃé×¼Õû¸öÑÇÖ޵ĽðÈÚÐÐÒµ


4ÔÂ5ÈÕ£¬ £¬£¬£¬£¬Ë¼¿Æ Talos µÄÑо¿Ö°Ô±·¢Ã÷ÁËһϵÁÐÃûΪ CoralRaider µÄºÚ¿Í»î¶¯£¬ £¬£¬£¬£¬Ê¹ÓÃÉøÍ¸¶ñÒâÈí¼þ¹¥»÷Ó¡¶È¡¢Öйú¡¢º«¹ú¡¢ÃϼÓÀ­¹ú¡¢°Í»ù˹̹¡¢Ó¡¶ÈÄáÎ÷ÑǺͺ£ÄÚÄ¿µÄ¡£¡£¡£Talos ºÜÊÇÓÐÐÅÐĵؽ«¸Ã×éÖ¯µÄÆðÔ´¹éÒòÓÚÔ½ÄÏ£¬ £¬£¬£¬£¬²¢Ö¸³öºÚ¿ÍÔÚÆä Telegram ÏÂÁîºÍ¿ØÖÆÍ¨µÀÖÐʹÓÃÔ½ÄÏÓ £¬£¬£¬£¬²¢½«Ô½ÄÏÓïµ¥´ÊÓ²±àÂëµ½ÓÐÓøºÔضþ½øÖÆÎļþÖС£¡£¡£ÆäIPµØµã¿É×·Ëݵ½ºÓÄÚ¡£¡£¡£ºÚ¿ÍʹÓà RotBot£¨Ò»ÖÖ¶¨ÖƵÄÔ¶³Ì»á¼û¹¤¾ß£¨ Quasar RATµÄ±äÌ壩£©ÏÂÔØÐÅÏ¢ÇÔÈ¡³ÌÐò£¬ £¬£¬£¬£¬¸Ã³ÌÐò»á²éÕÒ°üÀ¨Ö§¸¶¿¨µÈÊý¾ÝµÄÉÌÒµÉ罻ýÌåÕÊ»§¡£¡£¡£µ±Óû§·­¿ª¶ñÒâ Windows ¿ì½Ý·½·¨Îļþʱ£¬ £¬£¬£¬£¬CoralRaider ¹¥»÷¾Í»á×îÏÈ£¬ £¬£¬£¬£¬´Ó¶ø´¥·¢Ñ¬È¾Á´¡£¡£¡£ËþÂå˹ÌåÏÖ£¬ £¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎúÍþвÕßÔõÑù½«Îļþת´ï¸øÊܺ¦Õß¡£¡£¡£¼¤»îµÄLNKÎļþ»áÏÂÔØÒ»¸öHTMLÓ¦ÓóÌÐòÎļþ£¬ £¬£¬£¬£¬¸ÃÎļþÖ´ÐÐVirtual Basic¾ç±¾£¬ £¬£¬£¬£¬¸Ã¾ç±¾ÓÖÔÚÄÚ´æÖÐÖ´ÐÐPowerShell¾ç±¾¡°½âÃܲ¢Ë³ÐòÖ´ÐÐÆäËûÈý¸öPowerShell¾ç±¾£¬ £¬£¬£¬£¬ÕâЩ¾ç±¾Ö´Ðз´ÐéÄâ»úºÍ·´ÆÊÎö¼ì²é£¬ £¬£¬£¬£¬ÈƹýÓû§»á¼û¿ØÖÆ¡¢½ûÓÃÊܺ¦Õß»úеÉ쵀 Windows ºÍÓ¦ÓóÌÐò֪ͨ£¬ £¬£¬£¬£¬×îºóÏÂÔØ²¢ÔËÐÐ RotBot¡£¡£¡£


https://www.govinfosecurity.com/vietnamese-threat-actor-targeting-financial-data-across-asia-a-24796?&web_view=true


3. Ð嵀 Latrodectus ¶ñÒâÈí¼þÈ¡´úÁËÍøÂçÎó²îÖÐµÄ IcedID


4ÔÂ4ÈÕ£¬ £¬£¬£¬£¬Ò»ÖÖÃûΪ Latrodectus µÄÏà¶Ô½ÏеĶñÒâÈí¼þ±»ÒÔΪÊÇ IcedID ¼ÓÔØ³ÌÐòµÄÑݱ䣬 £¬£¬£¬£¬¸Ã¼ÓÔØ³ÌÐò×Ô 2023 Äê 11 ÔÂÒÔÀ´Ò»Ö±ÔÚ¶ñÒâµç×ÓÓʼþ»î¶¯ÖзºÆð¡£¡£¡£ProofpointºÍ Team CymruµÄÑо¿Ö°Ô±·¢Ã÷Á˸öñÒâÈí¼þ  £¬ £¬£¬£¬£¬ËûÃÇÅäºÏ¼Í¼ÁËÆä¹¦Ð§£¬ £¬£¬£¬£¬µ«ÕâЩ¹¦Ð§ÈÔÈ»²»ÎȹÌÇÒ´¦ÓÚʵÑé½×¶Î¡£¡£¡£IcedID ÊÇÒ»¸öÓÚ 2017 ÄêÊ״η¢Ã÷µÄ¶ñÒâÈí¼þ¼Ò×壬 £¬£¬£¬£¬×î³õ±»¹éÀàΪģ¿£¿£¿é»¯ÒøÐÐľÂí£¬ £¬£¬£¬£¬Ö¼ÔÚ´ÓÊÜѬȾµÄÅÌËã»úÖÐÇÔÈ¡²ÆÎñÐÅÏ¢¡£¡£¡£Ëæ×Åʱ¼äµÄÍÆÒÆ£¬ £¬£¬£¬£¬Ëü±äµÃÔ½·¢ÖØ´ó£¬ £¬£¬£¬£¬ÔöÌíÁËÌӱܺÍÏÂÁîÖ´Ðй¦Ð§¡£¡£¡£½üÄêÀ´£¬ £¬£¬£¬£¬Ëü³äµ±Á˼ÓÔØ³ÌÐòµÄ½ÇÉ«£¬ £¬£¬£¬£¬¿ÉÒÔ½«ÆäËûÀàÐ͵ĶñÒâÈí¼þ£¨°üÀ¨ÀÕË÷Èí¼þ£©´«Ë͵½ÊÜѬȾµÄϵͳÉÏ¡£¡£¡£´Ó 2022 Äê×îÏÈ£¬ £¬£¬£¬£¬¶à¸ö IcedID »î¶¯Õ¹Ê¾ÁË ¶àÑù»¯µÄת´ïÕ½ÂÔ£¬ £¬£¬£¬£¬µ«Ö÷ÒªµÄ·Ö·¢·½·¨ÈÔÈ»ÊǶñÒâµç×ÓÓʼþ¡£¡£¡£2022 Äê⣬ £¬£¬£¬£¬ ¸Ã¶ñÒâÈí¼þµÄбäÖÖ ±»ÓÃÓÚ¹¥»÷£¬ £¬£¬£¬£¬²¢ÊµÑéÁËÖÖÖÖ¹æ±Ü¼¼ÇɺÍÐµĹ¥»÷¼¯¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-latrodectus-malware-replaces-icedid-in-network-breaches/?&web_view=true


4. Visa ÖÒÑÔÕë¶Ô½ðÈÚ»ú¹¹µÄРJSOutProx ¶ñÒâÈí¼þ±äÌå


4ÔÂ4ÈÕ£¬ £¬£¬£¬£¬Visa ÖÒÑԳƣ¬ £¬£¬£¬£¬Õë¶Ô½ðÈÚ»ú¹¹¼°Æä¿Í»§µÄа汾 JsOutProx ¶ñÒâÈí¼þ¼ì²âÊýÄ¿¼¤Ôö¡£¡£¡£¸Ã»î¶¯Õë¶ÔÄÏÑǺͶ«ÄÏÑÇ¡¢Öж«ºÍ·ÇÖ޵ĽðÈÚ»ú¹¹¡£¡£¡£JsOutProx ÓÚ 2019 Äê 12 ÔÂÊ×´ÎÓöµ½£¬ £¬£¬£¬£¬ÊÇÒ»ÖÖÔ¶³Ì»á¼ûľÂí (RAT) ºÍ¸ß¶È»ìÏýµÄ JavaScript ºóÃÅ£¬ £¬£¬£¬£¬ÔÊÐíÆä²Ù×÷ÕßÔËÐÐ shell ÏÂÁî¡¢ÏÂÔØÌØÁíÍâ¸ºÔØ¡¢Ö´ÐÐÎļþ¡¢²¶»ñÆÁÄ»½ØÍ¼¡¢ÔÚÊÜѬȾµÄ×°±¸ÉϽ¨É賤ÆÚÐÔ²¢¿ØÖƼüÅ̺ÍÊó±ê¡£¡£¡£Visa ¾¯±¨ÖÐдµÀ£º¡°ËäÈ» PFD ÎÞ·¨È·ÈÏ×î½ü·¢Ã÷µÄ¶ñÒâÈí¼þ»î¶¯µÄ×îÖÕÄ¿µÄ£¬ £¬£¬£¬£¬µ«¸ÃÍøÂç·¸·¨×é֮֯ǰ¿ÉÄÜÔøÕë¶Ô½ðÈÚ»ú¹¹¾ÙÐÐڲƭ»î¶¯¡£¡£¡£¡±¸Ã¾¯±¨ÌṩÁËÓë×îлÏà¹ØµÄÍ×Эָ±ê (IoC)£¬ £¬£¬£¬£¬²¢½¨Òé½ÓÄɶàÏ½â²½·¥£¬ £¬£¬£¬£¬°üÀ¨Ìá¸ß¶ÔÍøÂç´¹ÂÚΣº¦µÄÊìϤ¡¢ÆôÓà EMV ºÍÇå¾²½ÓÊÜÊÖÒÕ¡¢±£»£»£»£» £»¤Ô¶³Ì»á¼ûÒÔ¼°¼à¿Ø¿ÉÒÉÉúÒâ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/visa-warns-of-new-jsoutprox-malware-variant-targeting-financial-orgs/?&web_view=true


5. ÎÂÄá²®´óѧÊýǧÃû½ÌÖ°Ô±¹¤ºÍѧÉúµÄÃô¸ÐÊý¾Ý±»µÁ


4ÔÂ5ÈÕ£¬ £¬£¬£¬£¬¼ÓÄôóÎÂÄá²®´óѧ֤ʵ£¬ £¬£¬£¬£¬ºÚ¿ÍÔÚÉϸöÔÂÄ©±¬·¢µÄÒ»ÆðÊÂÎñÖÐÇÔÈ¡Á˸ûú¹¹µÄÃô¸ÐÐÅÏ¢£¬ £¬£¬£¬£¬Ó°ÏìÁËÒÔǰºÍÏÖÔÚµÄѧÉúºÍ½ÌÖ°Ô±¹¤¡£¡£¡£ÕâËùÓµÓÐ 18,000 ¶àÃûѧÉúºÍ 800 Ãû½ÌÖ°Ô±¹¤µÄ´óѧÔÚÖÜËĵÄÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬ £¬£¬£¬£¬¡°±»µÁµÄÐÅÏ¢¿ÉÄܰüÀ¨Ä¿½ñºÍÒÔǰµÄѧÉúºÍÔ±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡±ÕâÆðÍøÂçÊÂÎñÓÚ 3 Ô 25 ÈÕÊ×´ÎÐû²¼£¬ £¬£¬£¬£¬Æäʱ¸Ã»ú¹¹ÏÂÏßÁËһϵÁÐЧÀÍ¡£¡£¡£¼¸Ììºó£¬ £¬£¬£¬£¬¸Ã´óѧУ³¤Íе¡¤Ãɶà¶û²©Ê¿ÌåÏÖ£¬ £¬£¬£¬£¬ÎÂÄá²®ÔâÊÜÁË¡°Õë¶Ô´óÑ§ÍøÂçµÄÓÐÕë¶ÔÐÔµÄÍøÂç¹¥»÷¡±¡£¡£¡£¸Ã´óѧÌåÏÖ£¬ £¬£¬£¬£¬ÊÓ²ìÕýÔÚ¾ÙÐÐÖУ¬ £¬£¬£¬£¬¡°¿ÉÄÜÐèҪʱ¼ä£¬ £¬£¬£¬£¬¿ÉÄÜÊǼ¸¸öÔ¡±£¬ £¬£¬£¬£¬ÏÖÔڸôóѧÒÔΪ¹¥»÷ÕßÄܹ»»á¼ûÎļþЧÀÍÆ÷¡£¡£¡£¸ÃÍøÂçÊÂÎñµÄÐÔ×ÓÉÐδ»ñµÃ֤ʵ£¬ £¬£¬£¬£¬µ«¸Ã´óѧÌåÏÖ¡°ÍµÇÔÊÂÎñºÜ¿ÉÄܱ¬·¢ÔÚ 3 Ô 24 ÈÕ֮ǰµÄÒ»ÖÜ¡£¡£¡£¡±¸Ã´óѧÌåÏÖ£¬ £¬£¬£¬£¬½«ÎªÊÜÓ°ÏìµÄСÎÒ˽¼ÒÌṩΪÆÚÁ½ÄêµÄÐÅÓÃ¼à¿ØÐ§ÀÍ£¬ £¬£¬£¬£¬²¢ÃãÀøËùÓÐÊÜÓ°ÏìµÄÈË×¢²á£¬ £¬£¬£¬£¬²¢Ö¸³öËü»¹ÎªËæºó³ÉΪڲƭÕßÄ¿µÄµÄÈκÎÈËÌṩ°ü¹ÜÌõ¿î¡£¡£¡£


https://therecord.media/university-of-winnipeg-cyberattack


6. ºÚ¿ÍʹÓà Facebook ¹ã¸æºÍÐ®ÖÆÒ³ÃæÍÆ¹ãÐéαÈ˹¤ÖÇÄÜЧÀÍ


4ÔÂ5ÈÕ£¬ £¬£¬£¬£¬ÕâЩ¶ñÒâ¹ã¸æ»î¶¯ÊÇͨ¹ýÐ®ÖÆ Facebook СÎÒ˽¼Ò×ÊÁϽ¨ÉèµÄ£¬ £¬£¬£¬£¬ÕâЩСÎÒ˽¼Ò×ÊÁÏð³äÊ¢ÐеÄÈ˹¤ÖÇÄÜЧÀÍ£¬ £¬£¬£¬£¬Ã°³äÌṩй¦Ð§µÄÔ¤ÀÀ¡£¡£¡£±»¹ã¸æÓÕÆ­µÄÓû§³ÉΪڲƭÐÔ Facebook ÉçÇøµÄ³ÉÔ±£¬ £¬£¬£¬£¬ÍþвÐÐΪÕßÔÚÆäÖÐÐû²¼ÐÂÎÅ¡¢È˹¤ÖÇÄÜÌìÉúµÄͼÏñºÍÆäËûÏà¹ØÐÅÏ¢£¬ £¬£¬£¬£¬ÒÔÊ¹Ò³Ãæ¿´ÆðÀ´Õýµ±¡£¡£¡£È»¶ø£¬ £¬£¬£¬£¬ÉçÇøÌû×Ó¾­³£ÌᳫÏÞʱ»á¼û¼´½«ÍƳöÇÒ±¸ÊÜÆÚ´ýµÄ AI ЧÀÍ£¬ £¬£¬£¬£¬ÓÕÆ­Óû§ÏÂÔØ¶ñÒâ¿ÉÖ´ÐÐÎļþ£¬ £¬£¬£¬£¬ÕâЩ¿ÉÖ´ÐÐÎļþ»áʹÓà Rilide¡¢Vidar¡¢IceRAT ºÍ Nova µÈÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þѬȾ Windows ÅÌËã»ú¡£¡£¡£ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þרעÓÚ´ÓÊܺ¦ÕßµÄä¯ÀÀÆ÷ÇÔÈ¡Êý¾Ý£¬ £¬£¬£¬£¬°üÀ¨´æ´¢µÄƾ֤¡¢cookie¡¢¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡¢×Ô¶¯Íê³ÉÊý¾ÝºÍÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£È»ºó£¬ £¬£¬£¬£¬ÕâЩÊý¾Ý»áÔÚ°µÍøÊг¡ÉϳöÊÛ£¬ £¬£¬£¬£¬»ò±»¹¥»÷ÕßÓÃÀ´ÆÆËðÄ¿µÄµÄÔÚÏßÕÊ»§£¬ £¬£¬£¬£¬ÒÔÔö½ø½øÒ»²½µÄÕ©Æ­»ò¾ÙÐÐڲƭ¡£¡£¡£Facebook µÈÉ罻ýÌåÍøÂç¹æÄ£ÖØ´ó£¬ £¬£¬£¬£¬¼ÓÉÏî¿ÏµÈ±·¦£¬ £¬£¬£¬£¬Ê¹µÃÕâЩ»î¶¯Äܹ»ºã¾ÃÒ»Á¬£¬ £¬£¬£¬£¬´Ó¶øÔö½ø¶ñÒâÈí¼þ²»ÊÜ¿ØÖƵÄÈö²¥£¬ £¬£¬£¬£¬´Ó¶øµ¼Ö¶ñÒâÈí¼þѬȾÔì³ÉÆÕ±éË𺦡£¡£¡£


https://www.bleepingcomputer.com/news/security/fake-facebook-midjourney-ai-page-promoted-malware-to-12-million-people/