Lapsus$Éù³ÆÒÑÈëÇÖ΢ÈíAzure DevOpsÔ´´úÂë´æ´¢¿â
Ðû²¼Ê±¼ä 2022-03-23Lapsus$Éù³ÆÒÑÈëÇÖ΢ÈíAzure DevOpsÔ´´úÂë´æ´¢¿â
¾ÝýÌå3ÔÂ21ÈÕ±¨µÀ£¬£¬£¬£¬£¬Î¢ÈíÕýÔÚÊÓ²ìÓйØLapsus$ÈëÇÖÆäAzure DevOpsÔ´´úÂë´æ´¢¿â²¢ÇÔÈ¡Êý¾ÝµÄÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¡£ÉÏÖÜÈÕÇåÔ磬£¬£¬£¬£¬Lapsus$ÔÚTelegramÉÏÐû²¼ÁËÆäÈëÇÖµÄÔ´´úÂë´æ´¢¿âµÄÆÁÄ»½ØÍ¼£¬£¬£¬£¬£¬ÆäÖаüÀ¨CortanaºÍÖÖÖÖBingÏîÄ¿µÄÔ´´úÂ룬£¬£¬£¬£¬ÃûΪ¡°Bing_STC-SV¡±¡¢¡°Bing_Test_Agile¡±ºÍ¡°Bing_UX¡±£¬£¬£¬£¬£¬ÒÔ¼°ÆäËüÔ´´úÂë¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬½ØÍ¼ÖÐÏÔʾÁ˵ÇÈÎÃü»§µÄÊ××Öĸ¡°IS¡±£¬£¬£¬£¬£¬Õâ¿É±»ÓÃÀ´È·Èϱ»µÁÕÊ»§¡£¡£¡£¡£¡£¡£¡£¡£½ØÍ¼Ðû²¼ºó²»¾Ã£¬£¬£¬£¬£¬Lapsus$³·»ØÁËÕâ¸öÌû×Ó£¬£¬£¬£¬£¬²¢³Æ¡°ÔÝʱɾ³ý£¬£¬£¬£¬£¬ÉÔºóÔÙÐû²¼¡±¡£¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/129312/cyber-crime/lapsus-gang-claims-microsoft-hack.html
ASEC·¢Ã÷αװ³ÉWindows 10µÄÃÜÔ¿¼¤»î¹¤¾ß·Ö·¢BitRAT
ASECÆÊÎöÍŶÓÔÚ3ÔÂ21ÈÕÅû¶ÁËαװ³ÉWindows 10µÄÃÜÔ¿¼¤»î¹¤¾ß·Ö·¢BitRATµÄ»î¶¯µÄϸ½ÚÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚº«¹ú×î³£ÓõÄÎļþ¹²ÏíÆ½Ì¨webhardÉÏÐû²¼ÓÕ¶üÁ´½Ó£¬£¬£¬£¬£¬Ä¿µÄµã»÷ºó»áÏÂÔØÃûΪ¡°Program.zip¡±µÄѹËõÎļþ£¬£¬£¬£¬£¬Ê¹ÓÃÃÜÂë¡°1234¡±¾ÙÐÐѹËõºó£¬£¬£¬£¬£¬»á»ñµÃÃûΪ¡°W10DigitalActivation.exe¡±µÄWindows 10µÄÃÜÔ¿¼¤»î¹¤¾ß¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÄ¿µÄÔËÐиù¤¾ßºó£¬£¬£¬£¬£¬»á×°ÖÃÕæÊµµÄÑéÖ¤¹¤¾ßºÍ¶ñÒâÈí¼þW10DigitalActivation_Temp.msi£¬£¬£¬£¬£¬×îÖÕÏÂÔØ²¢×°ÖÃÔ¶³Ì»á¼ûľÂíBitRAT¡£¡£¡£¡£¡£¡£¡£¡£
https://asec.ahnlab.com/en/32781/
EmsisoftÐû²¼TrickBotµÄÀÕË÷Èí¼þDiavolµÄ½âÃÜÆ÷
¾ÝýÌå3ÔÂ18ÈÕ±¨µÀ£¬£¬£¬£¬£¬Çå¾²¹«Ë¾EmsisoftÐû²¼ÁËÒ»¿î½âÃܹ¤¾ß£¬£¬£¬£¬£¬×ÊÖúÔâµ½DiavolÀÕË÷Èí¼þ¹¥»÷µÄÄ¿µÄÃâ·Ñ»Ö¸´Îļþ¡£¡£¡£¡£¡£¡£¡£¡£Óû§¿ÉÒÔ´ÓEmsisoftµÄЧÀÍÆ÷ÏÂÔØ¸Ã¹¤¾ß£¬£¬£¬£¬£¬²¢Æ¾Ö¤Ö¸ÄÏÖÐÌṩµÄÏêϸ˵Ã÷½âÃÜÆäÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£EmsisoftÚ¹ÊÍ˵£¬£¬£¬£¬£¬¸Ã½âÃÜÆ÷ÐèÒª»á¼ûÓÉÒ»¸ö¼ÓÃÜÎļþºÍ¸Ã¼ÓÃÜÎļþµÄδ¼ÓÃܰ汾×é³ÉµÄÎļþ¶Ô£¬£¬£¬£¬£¬ÒÔÖØÐÞ½âÃÜËùÐèÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£¡£FortiGuard LabsÔÚ2021Äê6ÔÂÉÏÑ®Ê״ν«¸ÃÀÕË÷Èí¼þÓëTrickBotÍÅ»ïÁªÏµÆðÀ´¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/free-decryptor-released-for-trickbot-gangs-diavol-ransomware/
Ñо¿ÍŶÓÅû¶ð³äInstagramÊÖÒÕÖ§³ÖµÄ´¹ÂڻµÄϸ½Ú
ArmorbloxÔÚ3ÔÂ16ÈÕÏêÊöÁËð³äInstagramÊÖÒÕÖ§³ÖµÄ´¹Âڻ¡£¡£¡£¡£¡£¡£¡£¡£´Ë´Î»î¶¯Ö÷ÒªÕë¶Ô×ܲ¿Î»ÓÚŦԼµÄÒ»¼ÒÖøÃûµÄÈËÊÙ°ü¹Ü¹«Ë¾£¬£¬£¬£¬£¬´¹ÂÚÓʼþÒÔ¡°Instagram Support¡± ΪÖ÷Ì⣬£¬£¬£¬£¬À´×Եصãmembershipform@outlook.com.tr¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÓʼþÖÒÑÔÊÕ¼þÈËÆäInstagramÕÊ»§Òѱ»¾Ù±¨Èö²¥ÐéαÐÅÏ¢²¢ÑÏÖØÎ¥·´ÁËInstagramµÄЧÀÍÌõ¿î¡£¡£¡£¡£¡£¡£¡£¡£ÊÕ¼þÈ˱»ÒªÇóÔÚ24СʱÄÚÑéÖ¤ÕÊ»§²»È»ÕÊ»§»á±»É¾³ý£¬£¬£¬£¬£¬Æäµã»÷ÑéÖ¤Á´½Óºó¼´»á±»Öض¨Ïòµ½´¹ÂÚÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¡£
https://www.armorblox.com/blog/the-email-bait-and-phish-instagram-phishing-attack/
AvastÐû²¼½©Ê¬ÍøÂçDirtyMoeбäÌåµÄÊÖÒÕÆÊÎö±¨¸æ
3ÔÂ16ÈÕ£¬£¬£¬£¬£¬AvastÐû²¼Á˽©Ê¬ÍøÂçDirtyMoeбäÌåµÄÊÖÒÕÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£DirtyMoe½ÓÄÉÄ£¿£¿£¿£¿£¿£¿£¿£¿é»¯Éè¼Æ£¬£¬£¬£¬£¬Ö÷ҪʹÓöà¸ö¹¤¾ß°ü£¨ÈçPurpleFox£©¾ÙÐзַ¢¡£¡£¡£¡£¡£¡£¡£¡£×îÐÂÑо¿·¢Ã÷£¬£¬£¬£¬£¬DirtyMoeÐÂÔöÁËÀàËÆÈ䳿µÄÈö²¥¹¦Ð§£¬£¬£¬£¬£¬Ê¹ÆäÄܹ»ÔÚ²»ÐèÒªÓëÓû§½»»¥µÄÇéÐÎÏÂÀ©´óÓ°Ïì¹æÄ£¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÈ䳿ģ¿£¿£¿£¿£¿£¿£¿£¿éÕë¶ÔµÄÊǽÏÔçµÄ³£¼ûÎó²î£¬£¬£¬£¬£¬ÀýÈçEternalBlueºÍHot Potato WindowsȨÏÞÉý¼¶Îó²î£¬£¬£¬£¬£¬Ê¹ÓÃЧÀÍ¿ØÖÆÖÎÀíÆ÷Ô¶³ÌÐÒé(SCMR)¡¢WMIºÍMS SQLЧÀ͵Ä×ֵ乥»÷£¬£¬£¬£¬£¬ÌìÌì¿ÉÒÔÌìÉúºÍ¹¥»÷ÊýÊ®Íò¸öIPµØµã¡£¡£¡£¡£¡£¡£¡£¡£
https://decoded.avast.io/martinchlumecky/dirtymoe-5/
Trend MicroÐû²¼2021ÄêÍøÂçÇå¾²Ì¬ÊÆµÄ»ØÊ×±¨¸æ
3ÔÂ17ÈÕ£¬£¬£¬£¬£¬Trend MicroÐû²¼ÁË2021ÄêÍøÂçÇå¾²Ì¬ÊÆµÄ»ØÊ×±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬ÕûÌåÀÕË÷Èí¼þÊýĿͬ±ÈϽµ21%£¬£¬£¬£¬£¬Õþ¸®¡¢ÒøÐкÍÒ½ÁƱ£½¡ÐÐÒµÈÔÊÇ2021ÄêÔâµ½´ËÀ๥»÷×î¶àµÄÐÐÒµ£¬£¬£¬£¬£¬ÀÕË÷¹¥»÷Õß×î³£ÓõĶñÒ⹤¾ß°üÀ¨Cobalt Strike beacon¡¢TrickbotºÍBazarLoaderµÈ¡£¡£¡£¡£¡£¡£¡£¡£Ç÷ÊÆ¿Æ¼¼ÔÚ2021Äê¼ì²âµ½Áè¼Ý2500Íò·â¶ñÒâÓʼþÍþв£¬£¬£¬£¬£¬ÆäÖд¹ÂÚÓʼþµÄÊýÄ¿ÏÕЩÊÇ2020ÄêµÄÁ½±¶£¬£¬£¬£¬£¬½ðÈÚ¡¢Ò½ÁƱ£½¡ºÍ½ÌÓýÐÐÒµÔâµ½´ËÀ๥»÷×î¶à¡£¡£¡£¡£¡£¡£¡£¡£2021 Ä꣬£¬£¬£¬£¬Ç÷ÊÆ¿Æ¼¼ZDIÐû²¼Á˹ØÓÚ1604¸öÎó²îµÄͨ¸æ£¬£¬£¬£¬£¬±ÈÉÏÒ»ÄêÔöÌíÁË10%¡£¡£¡£¡£¡£¡£¡£¡£
https://www.trendmicro.com/vinfo/us/security/research-and-analysis/threat-reports/roundup/navigating-new-frontiers-trend-micro-2021-annual-cybersecurity-report
Çå¾²¹¤¾ß
Mip22
Ò»Öָ߼¶ÍøÂç´¹ÂÚ¹¤¾ß£¬£¬£¬£¬£¬½öÓÃÓÚ½ÌÓýÄ¿µÄÒÔÏàÊ¶ÍøÂç´¹ÂÚÒªÁìµÄÊÂÇéÔÀí¡£¡£¡£¡£¡£¡£¡£¡£
https://github.com/makdosx/mip22
routeros-scanner
΢ÈíÐû²¼ÁËÒ»¿î¿ÉÒÔ¼ì²â±» TrickBot ÍÅ»ïÈëÇÖµÄ MikroTik ·ÓÉÆ÷µÄȡ֤¹¤¾ß¡£¡£¡£¡£¡£¡£¡£¡£
https://github.com/microsoft/routeros-scanner
ThreatMapper 1.3.0
ÔÚ×îеĸüÐÂÖУ¬£¬£¬£¬£¬Deepfence ½«Ê¢ÐÐµÄ SecretScanner ¹¤¾ßÌí¼Óµ½ ThreatMapper ÖС£¡£¡£¡£¡£¡£¡£¡£
https://deepfence.io/new-release-threatmapper-1-3-0/
agartha
ÉøÍ¸²âÊÔ¹¤¾ß£¬£¬£¬£¬£¬Ëü½¨É趯̬payloadÁбíºÍÓû§»á¼û¾ØÕ󣬣¬£¬£¬£¬ÒÔÕ¹ÏÖ×¢ÈëÎó²îºÍÉí·ÝÑéÖ¤/ÊÚȨÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£
https://github.com/volkandindar/agartha
Çå¾²ÆÊÎö
¹È¸èÔÊÐí°²×¿Óû§É¾³ý×î½ü 15 ·ÖÖÓµÄËÑË÷ÀúÊ·
https://news.softpedia.com/news/google-allowing-android-users-to-delete-the-last-15-mins-of-search-history-535073.shtml
ÓÐÈËÔÚ Windows 1.0 Öз¢Ã÷Ò»¸ö¸´Éú½Ú²Êµ°
https://news.softpedia.com/news/someone-has-just-discovered-an-easter-egg-in-windows-1-0-535072.shtml
ÎÚ¿ËÀ¼¼ÓÃÜÇ®±Ò³ï¿îÖб£´æÚ²Æ»î¶¯
https://blog.checkpoint.com/2022/03/17/crypto-fundraising-for-ukraine-found-on-the-darknet-used-by-cyber-criminals-for-fraud/
CiscoÐû²¼BlackMatterºÍBlackCatµÄÆÊÎö±¨¸æ
https://blog.talosintelligence.com/2022/03/from-blackmatter-to-blackcat-analyzing.html
IsaacWiper ºÍ CaddyWiper ÆÊÎö±¨¸æ
https://blog.malwarebytes.com/threat-intelligence/2022/03/double-header-isaacwiper-and-caddywiper/


¾©¹«Íø°²±¸11010802024551ºÅ