Ó¢¹úij¹«Ë¾µÄITÇå¾²ÆÊÎöʦð³äºÚ¿ÍÍÅ»ïÀÕË÷¹ÍÖ÷±»²¶
Ðû²¼Ê±¼ä 2023-05-251¡¢Ó¢¹úij¹«Ë¾µÄITÇå¾²ÆÊÎöʦð³äºÚ¿ÍÍÅ»ïÀÕË÷¹ÍÖ÷±»²¶
¾ÝýÌå5ÔÂ23ÈÕ±¨µÀ£¬£¬£¬£¬£¬28ËêµÄÓ¢¹úÄÐ×ÓAshley LilesÒòδ¾ÊÚȨ»á¼ûÅÌËã»ú²¢ÀÕË÷Æä¹ÍÖ÷±»ÖÎ×ï¡£¡£¡£¡£2018Äê2Ô£¬£¬£¬£¬£¬¸ÃÄÐ×ÓÔÚÒ»¼ÒÔâµ½ÁËÀÕË÷¹¥»÷µÄÅ£½ò¹«Ë¾µ£µ±ITÇå¾²ÆÊÎöʦ¡£¡£¡£¡£ÓëÆäËü¹¥»÷Ò»Ñù£¬£¬£¬£¬£¬ºÚ¿ÍÁªÏµÁ˹«Ë¾µÄ¸ß¹Ü£¬£¬£¬£¬£¬ÒªÇó½»Êê½ð¡£¡£¡£¡£LilesÔÚ¾¯Ô±¡¢Í¬Êº͹ÍÖ÷²»ÖªµÀµÄÇéÐÎÏ£¬£¬£¬£¬£¬¶Ô¹«Ë¾¾ÙÐÐÁ˵¥¶ÀµÄ¶þ´Î¹¥»÷¡£¡£¡£¡£Ëû»á¼ûÁËÒ»Ãû¶Ê»á³ÉÔ±µÄ˽ÈËÓʼþÁè¼Ý300´Î£¬£¬£¬£¬£¬¸ü¸ÄÁËÔʼÀÕË÷Óʼþ£¬£¬£¬£¬£¬±¾ÒâÊǽ«Êê½ð×ªÒÆµ½×Ô¼ºµÄ¼ÓÃÜÇ®±ÒÇ®°ü¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬¹«Ë¾²¢Î´½»Êê½ð£¬£¬£¬£¬£¬ÆäʱÈÔÔÚ¾ÙÐеÄÄÚ²¿ÊӲ죬£¬£¬£¬£¬·¢Ã÷Lilesδ¾ÊÚȨ»á¼û˽ÈËÓʼþ£¬£¬£¬£¬£¬²¢Ö¸ÏòËû¼ÒµÄIPµØµã¡£¡£¡£¡£¸ÃÔ±¹¤½«ÓÚ2023Äê7ÔÂ11ÈÕ·µ»Ø·¨Í¥ÌýȡѶ¶Ï¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/it-employee-impersonates-ransomware-gang-to-extort-employer/
2¡¢Ó¡¶È°ü¹ÜÐÅÏ¢¾Ö½ü30¸öϵͳ±»¼ÓÃܲ¢±»ÀÕË÷25ÍòÃÀÔª
ýÌå5ÔÂ23Èճƣ¬£¬£¬£¬£¬Ó¡¶È°ü¹ÜÐÅÏ¢¾Ö(IIB) Ôâµ½ÁËÀÕË÷¹¥»÷£¬£¬£¬£¬£¬½ü30¸öЧÀÍÆ÷ϵͳ±»¼ÓÃÜ£¬£¬£¬£¬£¬µ¼Ö¸ûú¹¹µÄÊý¾ÝÎÞ·¨»á¼û¡£¡£¡£¡£¹¥»÷±¬·¢ÓÚ4ÔÂ2ÈÕ£¬£¬£¬£¬£¬IIBÔÚ×î³õÑ¡Ôñ¶Ô¹¥»÷¾ÙÐб£ÃÜ¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬Ëæ×ÅÇéÐÎÔ½À´Ô½ÑÏÖØ£¬£¬£¬£¬£¬ËûÃÇ×îÖÕ±¨¸æ¸øÁËCyberabad¾¯·½¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬ºÚ¿ÍÒªÇó½»250000ÃÀÔªµÄ±ÈÌØ±ÒÀ´½âËøÊý¾Ý¡£¡£¡£¡£IIB¾öÒé²»Ìý´ÓºÚ¿ÍµÄÒªÇ󣬣¬£¬£¬£¬Ïà·´£¬£¬£¬£¬£¬ËûÃÇÒÀÀµÃô¸ÐÊý¾ÝµÄ±¸·ÝÀ´Î¬³ÖÒ»Ñùƽ³£ÔËÓª¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬¶Ô´Ë´Î¹¥»÷µÄÊÓ²ìÈÔÔÚ¾ÙÐÐÖС£¡£¡£¡£
https://www.the420.in/indian-insurance-information-bureau-hit-by-ransomware-attack-russian-hackers-demand-250000-as-ransom/
3¡¢ESETÔÚGoogle Play¼ì²âµ½±»AhRatľÂí»¯µÄiRecorder
5ÔÂ23ÈÕ£¬£¬£¬£¬£¬ESET³ÆÆäÔÚGoogle PlayÊÐËÁÖмì²âµ½Ò»ÖÖеÄRAT£¬£¬£¬£¬£¬ËüÒþ²ØÔÚÒ»¿îAndroidÆÁÄ»Â¼ÖÆÓ¦Óá°iRecorder - Screen Recorder¡±ÖС£¡£¡£¡£¸ÃÓ¦ÓÃÓÚ2021Äê9ÔÂÊ×´ÎÉÏ´«µ½ÊÐËÁ£¬£¬£¬£¬£¬µ«¿ÉÄÜÔÚ¿ìÒªÒ»ÄêºóµÄ2022Äê8ÔÂÐû²¼µÄ¸üÐÂÖб»Ä¾Âí»¯¡£¡£¡£¡£ÔÚ±»É¾³ý֮ǰ£¬£¬£¬£¬£¬Æä×°ÖÃÁ¿ÒÑÁè¼Ý50000´Î¡£¡£¡£¡£ÕâÊÇÒ»¸öеĻùÓÚAhMythµÄAndroid RAT£¬£¬£¬£¬£¬±»ÃüÃûΪAhRat£¬£¬£¬£¬£¬¿É¸ú×ÙλÖá¢ÇÔȡͨ»°¼Í¼¡¢ÇÔÈ¡ÁªÏµÈ˺ͶÌÐÅ¡¢·¢ËͶÌÐÅ¡¢ÕÕÏàºÍÂ¼ÖÆÅä¾°ÒôƵ¡£¡£¡£¡£
https://www.welivesecurity.com/2023/05/23/android-app-breaking-bad-legitimate-screen-recording-file-exfiltration/
4¡¢KasperskyÅû¶GoldenJackalÕë¶ÔÕþ¸®ºÍÍâ½»»ú¹¹µÄ¹¥»÷
KasperskyÔÚ5ÔÂ23ÈÕÅû¶ÁËGoldenJackal×Ô2019ÄêÒÔÀ´Ò»Ö±Õë¶ÔÖж«ºÍÄÏÑǵÄÕþ¸®ºÍÍâ½»»ú¹¹µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¸ÃÍÅ»ïʹÓÃÁËÒ»×é×Ô½ç˵µÄ.NET¶ñÒâÈí¼þ¹¤¾ß£¬£¬£¬£¬£¬ÕâЩ¹¤¾ßÌṩÁËÖÖÖÖ¹¦Ð§¡£¡£¡£¡£Ê×ÏÈѬȾϵͳµÄÖ÷ÒªpayloadÊÇJackalControl£¬£¬£¬£¬£¬¿ÉÔ¶³Ì¿ØÖÆÄ¿µÄÅÌËã»ú¡£¡£¡£¡£µÚ¶þ¸ö¹¤¾ßÊÇJackalSteal£¬£¬£¬£¬£¬¿É´ÓÄ¿µÄµÄËùÓÐÂß¼Çý¶¯Æ÷ÖÐÇÔÈ¡Êý¾Ý¡£¡£¡£¡£µÚÈý¸öJackalWorm£¬£¬£¬£¬£¬Ëü»áѬȾUSBÇý¶¯Æ÷²¢ÔÚÆäËüÅÌËã»úÉÏÈö²¥¡£¡£¡£¡£µÚËĸöÊÇJacklPerInfo£¬£¬£¬£¬£¬Ò»¸ö»ù±¾µÄϵͳÐÅÏ¢ÍøÂç³ÌÐò¡£¡£¡£¡£×îºóÒ»¸öÊÇJackalScreenWatcher£¬£¬£¬£¬£¬ÓÃÓÚÔÚÄ¿µÄ×°±¸ÉϽØÈ¡ÆÁÄ»½ØÍ¼¡£¡£¡£¡£
https://securelist.com/goldenjackal-apt-group/109677/
5¡¢Apria Healthcare¹ûÕæÓ°ÏìÔ¼20Íò»¼ÕßµÄÊý¾Ýй¶ÊÂÎñ
¾Ý5ÔÂ24ÈÕ±¨µÀ£¬£¬£¬£¬£¬Apria Healthcare¹ûÕæÁË2019ÄêºÍ2021ÄêµÄÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬Ó°ÏìÁËÔ¼180ÍòÓû§¡£¡£¡£¡£Î¥¹æÐÐΪ¿çÔ½Á½¸öʱÆÚ£¬£¬£¬£¬£¬2019Äê4ÔÂ5ÈÕÖÁ5ÔÂ7ÈÕ£¬£¬£¬£¬£¬ÒÔ¼°2021Äê8ÔÂ27ÈÕÖÁ10ÔÂ10ÈÕ£¬£¬£¬£¬£¬Éæ¼°Õʺš¢ÒøÐп¨ºÅ¡¢ÕÊ»§Çå¾²´úÂë¡¢»á¼û´úÂë¡¢ÃÜÂëºÍPINµÈÐÅÏ¢¡£¡£¡£¡£ApriaÌåÏÖ£¬£¬£¬£¬£¬¹¥»÷µÄÄ¿µÄÊÇÒÔÚ²ÆÊֶδÓApria»ñÈ¡×ʽ𣬣¬£¬£¬£¬¶ø²»ÊÇ»á¼ûÆä»¼Õß»òÔ±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¸Ã¹«Ë¾³Æ£¬£¬£¬£¬£¬Ã»ÓÐÖ¤¾ÝÅú×¢×ʽðÒѱ»×ªÒÆ£¬£¬£¬£¬£¬Ò²Ã»ÓÐÓë´ËÊÂÎñÏà¹ØµÄСÎÒ˽¼ÒÐÅÏ¢±»ÀÄÓᣡ£¡£¡£
https://www.hackread.com/apria-healthcare-major-data-breach/
6¡¢SentinelLabsÐû²¼¹ØÓÚKimsuky¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ
5ÔÂ23ÈÕ£¬£¬£¬£¬£¬SentinelLabsÐû²¼Á˹ØÓÚ³¯ÏÊAPT×éÖ¯KimsukyÕýÔÚ¾ÙÐеÄÒ»Ïî»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¸Ã»î¶¯µÄÖØµãÊÇʹÓöñÒâÈí¼þRandomQueryµÄ±äÌå¾ÙÐÐÎļþÕì̽ºÍÐÅϢй¶£¬£¬£¬£¬£¬´Ó¶øÊµÏÖºóÐøµÄ¾«×¼¹¥»÷¡£¡£¡£¡£KimsukyʹÓÃÁËMicrosoft±àÒëµÄHTML×ÊÖú(CHM)Îļþ·Ö·¢RandomQuery£¬£¬£¬£¬£¬ÕâÊÇËûÃÇ·Ö·¢¶ñÒâÈí¼þ¼¯µÄºã¾ÃÕ½Êõ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Kimsuky»¹½ÓÄÉÁËÐµĶ¥¼¶ÓòÃûºÍÓòÃû×÷Ϊ¶ñÒâ»ù´¡ÉèÊ©£¬£¬£¬£¬£¬Ä£Äâ±ê×¼µÄ.com¶¥¼¶ÓòÃûÀ´ÓÕÆÄ¿µÄ¡£¡£¡£¡£
https://www.sentinelone.com/labs/kimsuky-ongoing-campaign-using-tailored-reconnaissance-toolkit/


¾©¹«Íø°²±¸11010802024551ºÅ