ÐÂÀÕË÷ÍÅ»ïRed CryptoApp½ÓÄɼ¤½øÕ½ÂÔÐßÈèÊܺ¦Õß
Ðû²¼Ê±¼ä 2024-04-074ÔÂ4ÈÕ£¬£¬£¬£¬Netenrich µÄÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÃûΪ Red Ransomware Group (Red CryptoApp) µÄÐÂÀÕË÷×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯µÄÔË×÷·½·¨Óëµä·¶µÄÀÕË÷Èí¼þ×éÖ¯²î±ð£¬£¬£¬£¬ËûÃǵÄÀÕË÷Õ½ÂÔÓÐËù²î±ð¡£¡£¡£¡£¡£¡£¡£¡£Óë´ó´ó¶¼Òþ²ØÆä²Ù×÷µÄÀÕË÷Èí¼þ×éÖ¯²î±ð£¬£¬£¬£¬Red CryptoApp ËÆºõ½ÓÄÉÁ˼¤½øµÄÒªÁì¡£¡£¡£¡£¡£¡£¡£¡£¾Ý Netenrich ³Æ£¬£¬£¬£¬¸Ã×éÖ¯½¨ÉèÁË¡°ÐßÈèǽ¡±£¬£¬£¬£¬²¢Ðû²¼ÁËËûÃÇÀÖ³ÉÃé×¼µÄ¹«Ë¾Ãû³Æ¡£¡£¡£¡£¡£¡£¡£¡£ÕâÖÖÕ½ÂÔÖ¼ÔÚÐßÈèÊܺ¦Õß²¢ÆÈʹËûÃÇÖ§¸¶Êê½ðÒÔɾ³ýËûÃǵÄÃû×Ö¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±×¢Öص½¸Ã×é֯׫дµÄÒ»·ÝÀÕË÷Èí¼þÌõ¼ÇÓë 2020 Äê Maze ÀÕË÷Èí¼þÍÅ»ïÓÐһЩÏàËÆÖ®´¦¡£¡£¡£¡£¡£¡£¡£¡£Õâ¿ÉÄÜÊÇÇɺϣ¬£¬£¬£¬Ò²¿ÉÄÜÊÇÇɺϡ£¡£¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬Éв»ÇåÎú Red Ransomware Group ÊÇ·ñÊÇ Maze ÍÅ»ïµÄÑÜÉúÆ·£¬£¬£¬£¬Maze ÍÅ»ïÓÚ 2020 Äê 11 Ô¹رÕÁËÆäÓªÒµ¡£¡£¡£¡£¡£¡£¡£¡£Red CryptoApp ÀÕË÷Èí¼þÍÅ»ïµÄÐßÈèǽ£¬£¬£¬£¬ÃÀ¹úÊÇÖ÷ҪĿµÄ£¬£¬£¬£¬Æä´ÎÊǵ¤Âó¡¢Ó¡¶È¡¢Î÷°àÑÀ¡¢Òâ´óÀû¡¢ÐÂ¼ÓÆÂºÍ¼ÓÄôóµÈÆäËû¹ú¼Ò¡£¡£¡£¡£¡£¡£¡£¡£¾ÍÄ¿µÄÐÐÒµ¶øÑÔ£¬£¬£¬£¬Èí¼þºÍÖÆÔìÒµ³ÉΪ×î³£¼ûµÄÄ¿µÄÐÐÒµ£¬£¬£¬£¬½ÌÓý¡¢ÐÞ½¨¡¢ÂÃ¹ÝºÍ IT ÐÐÒµÒ²Êܵ½¹Ø×¢¡£¡£¡£¡£¡£¡£¡£¡£
https://www.hackread.com/red-ransomware-group-red-cryptoapp-wall-of-shame/?web_view=true
2. CoralRaiderºÚ¿ÍÍÅ»ïÃé×¼Õû¸öÑÇÖ޵ĽðÈÚÐÐÒµ
4ÔÂ5ÈÕ£¬£¬£¬£¬Ë¼¿Æ Talos µÄÑо¿Ö°Ô±·¢Ã÷ÁËһϵÁÐÃûΪ CoralRaider µÄºÚ¿Í»î¶¯£¬£¬£¬£¬Ê¹ÓÃÉøÍ¸¶ñÒâÈí¼þ¹¥»÷Ó¡¶È¡¢Öйú¡¢º«¹ú¡¢ÃϼÓÀ¹ú¡¢°Í»ù˹̹¡¢Ó¡¶ÈÄáÎ÷ÑǺͺ£ÄÚÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£¡£Talos ºÜÊÇÓÐÐÅÐĵؽ«¸Ã×éÖ¯µÄÆðÔ´¹éÒòÓÚÔ½ÄÏ£¬£¬£¬£¬²¢Ö¸³öºÚ¿ÍÔÚÆä Telegram ÏÂÁîºÍ¿ØÖÆÍ¨µÀÖÐʹÓÃÔ½ÄÏÓ£¬£¬£¬²¢½«Ô½ÄÏÓïµ¥´ÊÓ²±àÂëµ½ÓÐÓøºÔضþ½øÖÆÎļþÖС£¡£¡£¡£¡£¡£¡£¡£ÆäIPµØµã¿É×·Ëݵ½ºÓÄÚ¡£¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍʹÓà RotBot£¨Ò»ÖÖ¶¨ÖƵÄÔ¶³Ì»á¼û¹¤¾ß£¨ Quasar RATµÄ±äÌ壩£©ÏÂÔØÐÅÏ¢ÇÔÈ¡³ÌÐò£¬£¬£¬£¬¸Ã³ÌÐò»á²éÕÒ°üÀ¨Ö§¸¶¿¨µÈÊý¾ÝµÄÉÌÒµÉ罻ýÌåÕÊ»§¡£¡£¡£¡£¡£¡£¡£¡£µ±Óû§·¿ª¶ñÒâ Windows ¿ì½Ý·½·¨Îļþʱ£¬£¬£¬£¬CoralRaider ¹¥»÷¾Í»á×îÏÈ£¬£¬£¬£¬´Ó¶ø´¥·¢Ñ¬È¾Á´¡£¡£¡£¡£¡£¡£¡£¡£ËþÂå˹ÌåÏÖ£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎúÍþвÕßÔõÑù½«Îļþת´ï¸øÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£¡£¼¤»îµÄLNKÎļþ»áÏÂÔØÒ»¸öHTMLÓ¦ÓóÌÐòÎļþ£¬£¬£¬£¬¸ÃÎļþÖ´ÐÐVirtual Basic¾ç±¾£¬£¬£¬£¬¸Ã¾ç±¾ÓÖÔÚÄÚ´æÖÐÖ´ÐÐPowerShell¾ç±¾¡°½âÃܲ¢Ë³ÐòÖ´ÐÐÆäËûÈý¸öPowerShell¾ç±¾£¬£¬£¬£¬ÕâЩ¾ç±¾Ö´Ðз´ÐéÄâ»úºÍ·´ÆÊÎö¼ì²é£¬£¬£¬£¬ÈƹýÓû§»á¼û¿ØÖÆ¡¢½ûÓÃÊܺ¦Õß»úеÉ쵀 Windows ºÍÓ¦ÓóÌÐò֪ͨ£¬£¬£¬£¬×îºóÏÂÔØ²¢ÔËÐÐ RotBot¡£¡£¡£¡£¡£¡£¡£¡£
https://www.govinfosecurity.com/vietnamese-threat-actor-targeting-financial-data-across-asia-a-24796?&web_view=true
3. Ð嵀 Latrodectus ¶ñÒâÈí¼þÈ¡´úÁËÍøÂçÎó²îÖÐµÄ IcedID
4ÔÂ4ÈÕ£¬£¬£¬£¬Ò»ÖÖÃûΪ Latrodectus µÄÏà¶Ô½ÏеĶñÒâÈí¼þ±»ÒÔΪÊÇ IcedID ¼ÓÔØ³ÌÐòµÄÑݱ䣬£¬£¬£¬¸Ã¼ÓÔØ³ÌÐò×Ô 2023 Äê 11 ÔÂÒÔÀ´Ò»Ö±ÔÚ¶ñÒâµç×ÓÓʼþ»î¶¯ÖзºÆð¡£¡£¡£¡£¡£¡£¡£¡£ProofpointºÍ Team CymruµÄÑо¿Ö°Ô±·¢Ã÷Á˸öñÒâÈí¼þ £¬£¬£¬£¬ËûÃÇÅäºÏ¼Í¼ÁËÆä¹¦Ð§£¬£¬£¬£¬µ«ÕâЩ¹¦Ð§ÈÔÈ»²»ÎȹÌÇÒ´¦ÓÚʵÑé½×¶Î¡£¡£¡£¡£¡£¡£¡£¡£IcedID ÊÇÒ»¸öÓÚ 2017 ÄêÊ״η¢Ã÷µÄ¶ñÒâÈí¼þ¼Ò×壬£¬£¬£¬×î³õ±»¹éÀàΪģ¿£¿£¿é»¯ÒøÐÐľÂí£¬£¬£¬£¬Ö¼ÔÚ´ÓÊÜѬȾµÄÅÌËã»úÖÐÇÔÈ¡²ÆÎñÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Ëæ×Åʱ¼äµÄÍÆÒÆ£¬£¬£¬£¬Ëü±äµÃÔ½·¢Öش󣬣¬£¬£¬ÔöÌíÁËÌӱܺÍÏÂÁîÖ´Ðй¦Ð§¡£¡£¡£¡£¡£¡£¡£¡£½üÄêÀ´£¬£¬£¬£¬Ëü³äµ±Á˼ÓÔØ³ÌÐòµÄ½ÇÉ«£¬£¬£¬£¬¿ÉÒÔ½«ÆäËûÀàÐ͵ĶñÒâÈí¼þ£¨°üÀ¨ÀÕË÷Èí¼þ£©´«Ë͵½ÊÜѬȾµÄϵͳÉÏ¡£¡£¡£¡£¡£¡£¡£¡£´Ó 2022 Äê×îÏÈ£¬£¬£¬£¬¶à¸ö IcedID »î¶¯Õ¹Ê¾ÁË ¶àÑù»¯µÄת´ïÕ½ÂÔ£¬£¬£¬£¬µ«Ö÷ÒªµÄ·Ö·¢·½·¨ÈÔÈ»ÊǶñÒâµç×ÓÓʼþ¡£¡£¡£¡£¡£¡£¡£¡£2022 Äê⣬£¬£¬£¬ ¸Ã¶ñÒâÈí¼þµÄбäÖÖ ±»ÓÃÓÚ¹¥»÷£¬£¬£¬£¬²¢ÊµÑéÁËÖÖÖÖ¹æ±Ü¼¼ÇɺÍÐµĹ¥»÷¼¯¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-latrodectus-malware-replaces-icedid-in-network-breaches/?&web_view=true
4. Visa ÖÒÑÔÕë¶Ô½ðÈÚ»ú¹¹µÄРJSOutProx ¶ñÒâÈí¼þ±äÌå
4ÔÂ4ÈÕ£¬£¬£¬£¬Visa ÖÒÑԳƣ¬£¬£¬£¬Õë¶Ô½ðÈÚ»ú¹¹¼°Æä¿Í»§µÄа汾 JsOutProx ¶ñÒâÈí¼þ¼ì²âÊýÄ¿¼¤Ôö¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Õë¶ÔÄÏÑǺͶ«ÄÏÑÇ¡¢Öж«ºÍ·ÇÖ޵ĽðÈÚ»ú¹¹¡£¡£¡£¡£¡£¡£¡£¡£JsOutProx ÓÚ 2019 Äê 12 ÔÂÊ×´ÎÓöµ½£¬£¬£¬£¬ÊÇÒ»ÖÖÔ¶³Ì»á¼ûľÂí (RAT) ºÍ¸ß¶È»ìÏýµÄ JavaScript ºóÃÅ£¬£¬£¬£¬ÔÊÐíÆä²Ù×÷ÕßÔËÐÐ shell ÏÂÁî¡¢ÏÂÔØÌØÁíÍâ¸ºÔØ¡¢Ö´ÐÐÎļþ¡¢²¶»ñÆÁÄ»½ØÍ¼¡¢ÔÚÊÜѬȾµÄ×°±¸ÉϽ¨É賤ÆÚÐÔ²¢¿ØÖƼüÅ̺ÍÊó±ê¡£¡£¡£¡£¡£¡£¡£¡£Visa ¾¯±¨ÖÐдµÀ£º¡°ËäÈ» PFD ÎÞ·¨È·ÈÏ×î½ü·¢Ã÷µÄ¶ñÒâÈí¼þ»î¶¯µÄ×îÖÕÄ¿µÄ£¬£¬£¬£¬µ«¸ÃÍøÂç·¸·¨×é֮֯ǰ¿ÉÄÜÔøÕë¶Ô½ðÈÚ»ú¹¹¾ÙÐÐڲƻ¡£¡£¡£¡£¡£¡£¡£¡£¡±¸Ã¾¯±¨ÌṩÁËÓë×îлÏà¹ØµÄÍ×ÐÖ¸±ê (IoC)£¬£¬£¬£¬²¢½¨Òé½ÓÄɶàÏ½â²½·¥£¬£¬£¬£¬°üÀ¨Ìá¸ß¶ÔÍøÂç´¹ÂÚΣº¦µÄÊìϤ¡¢ÆôÓà EMV ºÍÇå¾²½ÓÊÜÊÖÒÕ¡¢±£»£»£»£»£»£»£»£»¤Ô¶³Ì»á¼ûÒÔ¼°¼à¿Ø¿ÉÒÉÉúÒâ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/visa-warns-of-new-jsoutprox-malware-variant-targeting-financial-orgs/?&web_view=true
5. ÎÂÄá²®´óѧÊýǧÃû½ÌÖ°Ô±¹¤ºÍѧÉúµÄÃô¸ÐÊý¾Ý±»µÁ
4ÔÂ5ÈÕ£¬£¬£¬£¬¼ÓÄôóÎÂÄá²®´óѧ֤ʵ£¬£¬£¬£¬ºÚ¿ÍÔÚÉϸöÔÂÄ©±¬·¢µÄÒ»ÆðÊÂÎñÖÐÇÔÈ¡Á˸ûú¹¹µÄÃô¸ÐÐÅÏ¢£¬£¬£¬£¬Ó°ÏìÁËÒÔǰºÍÏÖÔÚµÄѧÉúºÍ½ÌÖ°Ô±¹¤¡£¡£¡£¡£¡£¡£¡£¡£ÕâËùÓµÓÐ 18,000 ¶àÃûѧÉúºÍ 800 Ãû½ÌÖ°Ô±¹¤µÄ´óѧÔÚÖÜËĵÄÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬£¬£¬£¬¡°±»µÁµÄÐÅÏ¢¿ÉÄܰüÀ¨Ä¿½ñºÍÒÔǰµÄѧÉúºÍÔ±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£¡±ÕâÆðÍøÂçÊÂÎñÓÚ 3 Ô 25 ÈÕÊ×´ÎÐû²¼£¬£¬£¬£¬Æäʱ¸Ã»ú¹¹ÏÂÏßÁËһϵÁÐЧÀÍ¡£¡£¡£¡£¡£¡£¡£¡£¼¸Ììºó£¬£¬£¬£¬¸Ã´óѧУ³¤Íе¡¤Ãɶà¶û²©Ê¿ÌåÏÖ£¬£¬£¬£¬ÎÂÄá²®ÔâÊÜÁË¡°Õë¶Ô´óÑ§ÍøÂçµÄÓÐÕë¶ÔÐÔµÄÍøÂç¹¥»÷¡±¡£¡£¡£¡£¡£¡£¡£¡£¸Ã´óѧÌåÏÖ£¬£¬£¬£¬ÊÓ²ìÕýÔÚ¾ÙÐÐÖУ¬£¬£¬£¬¡°¿ÉÄÜÐèҪʱ¼ä£¬£¬£¬£¬¿ÉÄÜÊǼ¸¸öÔ¡±£¬£¬£¬£¬ÏÖÔڸôóѧÒÔΪ¹¥»÷ÕßÄܹ»»á¼ûÎļþЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍøÂçÊÂÎñµÄÐÔ×ÓÉÐδ»ñµÃ֤ʵ£¬£¬£¬£¬µ«¸Ã´óѧÌåÏÖ¡°ÍµÇÔÊÂÎñºÜ¿ÉÄܱ¬·¢ÔÚ 3 Ô 24 ÈÕ֮ǰµÄÒ»ÖÜ¡£¡£¡£¡£¡£¡£¡£¡£¡±¸Ã´óѧÌåÏÖ£¬£¬£¬£¬½«ÎªÊÜÓ°ÏìµÄСÎÒ˽¼ÒÌṩΪÆÚÁ½ÄêµÄÐÅÓÃ¼à¿ØÐ§ÀÍ£¬£¬£¬£¬²¢ÃãÀøËùÓÐÊÜÓ°ÏìµÄÈË×¢²á£¬£¬£¬£¬²¢Ö¸³öËü»¹ÎªËæºó³ÉΪڲÆÕßÄ¿µÄµÄÈκÎÈËÌṩ°ü¹ÜÌõ¿î¡£¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/university-of-winnipeg-cyberattack
6. ºÚ¿ÍʹÓà Facebook ¹ã¸æºÍÐ®ÖÆÒ³ÃæÍÆ¹ãÐéαÈ˹¤ÖÇÄÜЧÀÍ
4ÔÂ5ÈÕ£¬£¬£¬£¬ÕâЩ¶ñÒâ¹ã¸æ»î¶¯ÊÇͨ¹ýÐ®ÖÆ Facebook СÎÒ˽¼Ò×ÊÁϽ¨ÉèµÄ£¬£¬£¬£¬ÕâЩСÎÒ˽¼Ò×ÊÁÏð³äÊ¢ÐеÄÈ˹¤ÖÇÄÜЧÀÍ£¬£¬£¬£¬Ã°³äÌṩй¦Ð§µÄÔ¤ÀÀ¡£¡£¡£¡£¡£¡£¡£¡£±»¹ã¸æÓÕÆµÄÓû§³ÉΪڲÆÐÔ Facebook ÉçÇøµÄ³ÉÔ±£¬£¬£¬£¬ÍþвÐÐΪÕßÔÚÆäÖÐÐû²¼ÐÂÎÅ¡¢È˹¤ÖÇÄÜÌìÉúµÄͼÏñºÍÆäËûÏà¹ØÐÅÏ¢£¬£¬£¬£¬ÒÔÊ¹Ò³Ãæ¿´ÆðÀ´Õýµ±¡£¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬ÉçÇøÌû×Ó¾³£ÌᳫÏÞʱ»á¼û¼´½«ÍƳöÇÒ±¸ÊÜÆÚ´ýµÄ AI ЧÀÍ£¬£¬£¬£¬ÓÕÆÓû§ÏÂÔØ¶ñÒâ¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬ÕâЩ¿ÉÖ´ÐÐÎļþ»áʹÓà Rilide¡¢Vidar¡¢IceRAT ºÍ Nova µÈÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þѬȾ Windows ÅÌËã»ú¡£¡£¡£¡£¡£¡£¡£¡£ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þרעÓÚ´ÓÊܺ¦ÕßµÄä¯ÀÀÆ÷ÇÔÈ¡Êý¾Ý£¬£¬£¬£¬°üÀ¨´æ´¢µÄƾ֤¡¢cookie¡¢¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡¢×Ô¶¯Íê³ÉÊý¾ÝºÍÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£È»ºó£¬£¬£¬£¬ÕâЩÊý¾Ý»áÔÚ°µÍøÊг¡ÉϳöÊÛ£¬£¬£¬£¬»ò±»¹¥»÷ÕßÓÃÀ´ÆÆËðÄ¿µÄµÄÔÚÏßÕÊ»§£¬£¬£¬£¬ÒÔÔö½ø½øÒ»²½µÄÕ©Æ»ò¾ÙÐÐڲơ£¡£¡£¡£¡£¡£¡£¡£Facebook µÈÉ罻ýÌåÍøÂç¹æÄ£ÖØ´ó£¬£¬£¬£¬¼ÓÉÏî¿ÏµÈ±·¦£¬£¬£¬£¬Ê¹µÃÕâЩ»î¶¯Äܹ»ºã¾ÃÒ»Á¬£¬£¬£¬£¬´Ó¶øÔö½ø¶ñÒâÈí¼þ²»ÊÜ¿ØÖƵÄÈö²¥£¬£¬£¬£¬´Ó¶øµ¼Ö¶ñÒâÈí¼þѬȾÔì³ÉÆÕ±éË𺦡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/fake-facebook-midjourney-ai-page-promoted-malware-to-12-million-people/


¾©¹«Íø°²±¸11010802024551ºÅ