BahamutÍÅ»ïʹÓÃð³äµÄVPNÓ¦ÓÃÇÔÈ¡AndroidÓû§ÐÅÏ¢
Ðû²¼Ê±¼ä 2022-11-2511ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ESETÅû¶ÁËÓÉAPT×éÖ¯BahamutÌᳫÕë¶ÔAndroidÓû§µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯×Ô2022Äê1ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬£¬£¬BahamutÖØÐ´ò°üÁËÊÊÓÃÓÚAndroidµÄSoftVPNºÍOpenVPNÓ¦Ó㬣¬£¬£¬£¬£¬£¬£¬Ìí¼ÓÁ˾ßÓÐÌØ¹¤¹¦Ð§µÄ¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÓ¦ÓÃÈÔ»áÌṩVPN¹¦Ð§£¬£¬£¬£¬£¬£¬£¬£¬Í¬Ê±»¹¿ÉÒÔ´ÓÒÆ¶¯×°±¸ÖÐÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÎªÁËÑÚÊι¥»÷»î¶¯²¢Ìá¸ß¿ÉÐŶȣ¬£¬£¬£¬£¬£¬£¬£¬BahamutʹÓÃÁËSecureVPN£¨Ò»¸öÕýµ±µÄVPNЧÀÍ£©µÄÃû×Ö£¬£¬£¬£¬£¬£¬£¬£¬²¢½¨ÉèÁËÒ»¸ö¼ÙÍøÕ¾[thesecurevpn]À´·Ö·¢¶ñÒâÓ¦Óᣡ£¡£¡£¡£¡£¡£¡£
https://www.welivesecurity.com/2022/11/23/bahamut-cybermercenary-group-targets-android-users-fake-vpn-apps/
2¡¢Áè¼Ý50¸öαÔìµÄMSI Afterburner¹ÙÍø·Ö·¢ÍÚ¿óÈí¼þ
¾Ý11ÔÂ23ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬CybleµÄÑо¿Ö°Ô±·¢Ã÷Á˼¸¸öÕë¶ÔMSI AfterburnerÈí¼þµÄ´¹Âڻ£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ·Ö·¢ÍÚ¿ó¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÒÑÍùÈý¸öÔÂÖУ¬£¬£¬£¬£¬£¬£¬£¬ÓÐÁè¼Ý50¸öð³äMSI Afterburner¹ÙÍøµÄ´¹ÂÚÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬»á·Ö·¢XMR(Monero)¿ó¹¤ÓëÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬£¬µ±Ä¿µÄÖ´ÐÐαÔìµÄMSI Afterburner×°ÖÃÎļþ(MSIAfterburnerSetup.msi)ʱ£¬£¬£¬£¬£¬£¬£¬£¬³ýÁË»á×°ÖÃÕýµ±µÄAfterburner³ÌÐò£¬£¬£¬£¬£¬£¬£¬£¬»¹»áÇÄÇĵØ×°Öò¢ÔËÐжñÒâÈí¼þRedLineºÍXMRÍÚ¿ó³ÌÐò¡£¡£¡£¡£¡£¡£¡£¡£²»ÐÒµÄÊÇ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã»î¶¯ÏÕЩËùÓеÄ×é¼þ¶¼Ã»Óб»É±¶¾Èí¼þ¼ì²âµ½¡£¡£¡£¡£¡£¡£¡£¡£
https://blog.cyble.com/2022/11/23/fake-msi-afterburner-sites-delivering-coin-miner/
3¡¢IBM·¢Ã÷ÀÕË÷Èí¼þRansomExxµÄбäÌåÒÑÓÃRustÖØÐ´
IBMÔÚ11ÔÂ22ÈÕ³ÆÆä·¢Ã÷ÁËRansomExxÀÕË÷Èí¼þµÄÒ»¸öбäÌ壬£¬£¬£¬£¬£¬£¬£¬¸Ã±äÌåÒÑÓÃRustÓïÑÔÖØÐ´¡£¡£¡£¡£¡£¡£¡£¡£ÓÃRust¿ª·¢µÄ¶ñÒâÈí¼þͨ³£»£»£»£»áÓнϵ͵ÄAV¼ì²âÂÊ£¬£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÊÇËüʹÓøÃÓïÑÔµÄÖ÷ÒªÔµ¹ÊÔÓÉ¡£¡£¡£¡£¡£¡£¡£¡£Ð±äÌåµÄ¹¦Ð§ÓëÆäC++µÄ°æ±¾ÀàËÆ£¬£¬£¬£¬£¬£¬£¬£¬½«Òª¼ÓÃܵÄÄ¿µÄĿ¼Áбí×÷ΪÏÂÁîÐвÎÊýת´ï£¬£¬£¬£¬£¬£¬£¬£¬È»ºóʹÓÃAES-256¼ÓÃÜÎļþ£¬£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃRSAÀ´±£»£»£»£»¤¼ÓÃÜÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬£¬ËùÓдóÓÚ»ò¼´ÊÇ40×Ö½ÚµÄÎļþ¶¼±»¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ60¶à¼ÒAVÌṩÉÌÖÐÖ»ÓÐ14¼Ò¼ì²âµ½ÁËÐÂÑù±¾¡£¡£¡£¡£¡£¡£¡£¡£
https://securityintelligence.com/posts/ransomexx-upgrades-rust/
4¡¢Smith FamilyÔ¼8Íò¾èÔùÕßµÄÏêϸÐÅÏ¢¿ÉÄÜÒÑй¶
¾ÝýÌå11ÔÂ22ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬°Ä´óÀûÑÇ´ÈÉÆ»ú¹¹Smith Family͸¶ÆäÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ô¼8Íò¾èÔùÕßµÄÏêϸÐÅÏ¢¿ÉÄÜÒѱ»»á¼û¡£¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶ÐÅÏ¢Éæ¼°ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢ÓʼþµØµãºÍ¾èÔù¼Í¼£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°²¿·ÖÖ§¸¶¿¨µÄ¶øÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹µÄÉùÃ÷ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÍýÏë͵ȡ×ʽð¿ÉÊÇûÓÐÀֳɣ¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇÒÑ֪ͨÊÜÓ°ÏìµÄ¾èÔùÕߣ¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚûÓÐÈκÎÈ˵ÄÐÅÏ¢±»ÀÄÓᣡ£¡£¡£¡£¡£¡£¡£
https://www.abc.net.au/news/2022-11-22/smith-family-charity-cyber-crime-hackers-donor-details/101683860
5¡¢Î±×°³ÉÐÂÎÅÊÓ²ìµÄ¶ñÒâwordÎĵµÇÔȡĿµÄµÄÐÅÏ¢
¾ÝASEC 11ÔÂ25ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬½üÆÚÒ»¸öÓ볯ÏÊÏà¹ØµÄ¶ñÒâWordÎļþÒ»Ö±ÔÚʹÓÃFTPй¶Óû§Æ¾Ö¤¡£¡£¡£¡£¡£¡£¡£¡£¸ÃWordÎĵµµÄÎļþÃûΪ¡°CNA[Q].doc¡±£¬£¬£¬£¬£¬£¬£¬£¬Î±×°³ÉCNAÐÂ¼ÓÆÂµçÊÓ½ÚÄ¿²É·Ã¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎļþÊÜÃÜÂë±£»£»£»£»¤£¬£¬£¬£¬£¬£¬£¬£¬ÓëÃÜÂëÒ»Æð×÷ΪÓʼþ¸½¼þ·Ö·¢¡£¡£¡£¡£¡£¡£¡£¡£ÎļþÖаüÀ¨¶ñÒâVBAºê£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýDocument_Open()º¯Êýʹ¶ñÒâºê×Ô¶¯Ö´ÐС£¡£¡£¡£¡£¡£¡£¡£Ëü¿ÉÒÔʹÓÃFTPй¶Óû§µÄÐÅÏ¢¡¢½¨ÉèLNKÎļþ¡¢¸ü¸ÄMS OfficeÇå¾²ÉèÖúͼͼ¼üÅÌ¡£¡£¡£¡£¡£¡£¡£¡£
https://asec.ahnlab.com/en/42529/
6¡¢Group-IBÐû²¼ÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þ·Ö·¢»î¶¯µÄÆÊÎö±¨¸æ
11ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Group-IBÐû²¼±¨¸æ³ÆÒÑÈ·¶¨34¸ö¶íÂÞ˹ºÚ¿ÍÍÅ»ïÔÚÒÔÇÔÈ¡¼´Ð§ÀÍģʽ(SaaS)·Ö·¢ÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÖ÷ҪʹÓÃRacoonºÍRedlineÇÔÈ¡³ÌÐò£¬£¬£¬£¬£¬£¬£¬£¬À´ÍøÂçSteamºÍRobloxÓÎÏ·ÕÊ»§µÄÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬ÑÇÂíÑ·ºÍPayPalµÄƾ֤£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Óû§µÄÖ§¸¶¼Í¼ºÍ¼ÓÃÜÇ®°üÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£2022ÄêµÄǰ7¸öÔ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¹²Ñ¬È¾Áè¼Ý89Íǫ̀װ±¸£¬£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡Áè¼Ý5000Íò¸öÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢°ÍÎ÷¡¢Ó¡¶È¡¢µÂ¹úºÍÓ¡¶ÈÄáÎ÷ÑÇ£¬£¬£¬£¬£¬£¬£¬£¬¶ñÒâ»î¶¯Éæ¼°111¸ö¹ú¼Ò/µØÇø¡£¡£¡£¡£¡£¡£¡£¡£
https://www.group-ib.com/media-center/press-releases/professional-stealers/


¾©¹«Íø°²±¸11010802024551ºÅ