TrickBotͨ¹ý²é³­ÆÁÄ»·Ö±æÂÊÌӱܲ¡¶¾·ÖÎö£»ÐÂÀÕË÷Èí¼þEvilQuestÕë¶ÔMacϵͳ  £¬Í¨¹ýµÁ°æÈí¼þ´«²¼

°ä²¼¹¦·ò 2020-07-02

1.¶ñÒâÈí¼þTrickBotͨ¹ý²é³­ÆÁÄ»·Ö±æÂÊÒÔÌӱܲ¡¶¾·ÖÎö


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÍøÂ簲ȫ¹«Ë¾MalwareLab·¢ÏÖ¶ñÒâÈí¼þTrickBotÒѾ­Æðͷͨ¹ý²é³­Êܺ¦ÕߵįÁÄ»·Ö±æÂÊ  £¬À´¼ì²âÆäÊÇ·ñÔÚÐé¹¹»úÖÐÔËÐÐ  £¬ÒÔ¶ã±Ü×êÑÐÈËÔ±»ò×Ô¶¯É³Ïäϵͳ¶ÔÆä½øÐзÖÎö¡£ÐµÄTrickBotÑù±¾ÔÚ²é³­ÍÆËã»úµÄÆÁÄ»·Ö±æÂÊÊDz»ÊÇ800x600»ò1024x768  £¬ÈôÊÇÊÇ  £¬TrickBotÔò»áÁ¢¼´ÖÕÖ¹¡£TrickBot²é³­ÕâÐ©ÌØÊâµÄ·Ö±æÂÊ  £¬ÊÇÓÉÓÚ×êÑÐÈËԱͨ³£ÊÇÕâÑùÅäÖÃËûÃǵÄÐé¹¹»ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/trickbot-malware-now-checks-screen-resolution-to-evade-analysis/


2.Ó¡¶È¹ú¶È¹«Â·¾Ö(NHAI)ϵͳÔâÀÕË÷Èí¼þ¹¥»÷  £¬ÏÖÒѸ´Ô­


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ó¡¶È¹ú¶È¹«Â·ÖÎÀí¾Ö£¨NHAI£©ÓÚÉÏÖÜÈÕÍíÉÏÔâµ½ÁËÀÕË÷Èí¼þµÄ¹¥»÷¡£¾Ý¸Ã²¿ÃÅÔ±¹¤Ëµ  £¬¸Ã¶ñÒâÈí¼þ¹¥»÷Á˵±¾ÖµÄµç×ÓÓʼþϵͳ  £¬¿ÉÄÜÒ²Ó°ÏìÁË´ÓǰʮÄêÀ´¸ßËÙ¹«Â·ÉϵĴóÁ¿Êý¾ÝºÍ»úÃÜÐÅÏ¢¡£µ«ºóÀ´  £¬NHAI½²»°È˰µÊ¾  £¬Õâ´Î¹¥»÷ûÓгɹ¦  £¬´Ë¿ÌϵͳÏÖÒѸ´Ô­  £¬Ã»ÓвúÉúÊý¾ÝÃÔʧ  £¬NHAIÊý¾ÝºÍÆäËûϵͳÈÔûÓÐÊܵ½Õâ´Î¹¥»÷µÄÓ°Ïì¡£¾ÝSophos³Æ  £¬Ó¡¶ÈÔÚÍøÂç·ÀÓù·½ÃæÎªÓÄ΢»·½Ú  £¬½öÈ¥Äê¾ÍÓÐ82£¥µÄÓ¡¶È×éÖ¯Ôâµ½ÀÕË÷Èí¼þµÄ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.hindustantimes.com/india-news/nhai-server-attacked-by-malware-govt-says-no-data-loss/story-wGDAcPUo4MWzPLOcqu2WZJ.html


3.Ê©ÀÖ¹«Ë¾Ôâµ½MazeÀÕË÷Èí¼þ¹¥»÷²¢Ð¹Â¶³¬¹ý100GBÎļþ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ºÚ¿Í×éÖ¯MazeÓÚ6ÔÂ25ÈÕ¶ÔÊ©ÀÖ¹«Ë¾ÌáÒéÁËÀÕË÷Èí¼þ¹¥»÷  £¬¸Ã¹«Ë¾ÖÁÉÙÒ»¸öXeroxÓòÖеÄÍÆËã»ú±»¼ÓÃÜ¡£¾Ý¹¥»÷Õß³Æ  £¬ËûÃÇÒѾ­´ÓÊ©ÀÖ¹«Ë¾ÇÔÈ¡Á˳¬¹ý100GBµÄÎļþ¡£¹¥»÷Õß·ÖÏíµÄÆÁÄ»½ØÍ¼ÏÔʾ  £¬ÓÉXerox CorporationÖÎÀíµÄ¡° eu.xerox.net¡±ÉϵÄÖ÷»úÊܵ½Á˹¥»÷  £¬¸ÃÖ÷»úÃûºÍÓòÃû°µÊ¾Õâ¿ÉÄÜÊÇXeroxÔÚÂ׶صķֹ«Ë¾¡£MazeÀÕË÷Èí¼þ½üÆÚÒ»ÏòÔÚ¹¥»÷´ó¹«Ë¾  £¬¸Ã×éÖ¯Ðû³Æ×î½ü¹¥»÷µÄ¹«Ë¾Ô̺¬LGµç×Ó¡¢Ð¾Æ¬Ôì×÷ÉÌMaxLinear¡¢IT¾ÞÍ·CognizantºÍóÒ×·þÎñ¹«Ë¾Conduent¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/business-giant-xerox-allegedly-suffers-maze-ransomware-attack/


4.ÐÂÀÕË÷Èí¼þEvilQuestÕë¶ÔMacϵͳ  £¬Í¨¹ýµÁ°æÈí¼þ°ü´«²¼


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


°²È«×êÑÐÔ±Dinesh Devadoss·¢ÏÖÁËÒ»ÖÖº±¼ûµÄÕë¶ÔmacOSµÄÐÂÐÍÀÕË÷Èí¼þEvilQuest  £¬Í¨¹ýµÁ°æÈí¼þ°ü´«²¼¡£EvilQuest³¬¹ýÁËÀÕË÷Èí¼þµÄͨÀý¼ÓÃÜÖ°ÄÜ  £¬Ëü»¹¿ÉÄܲ¿Êð¼üÅ̼ͼ·¨Ê½  £¬ÒÔ¼°¿ÉÄÜÇÔÈ¡¼ÓÃÜÇ®±ÒÇ®°üÎļþ¡£¸Ã¶ñÒâÈí¼þ°µ²ØÔÚµÁ°æÈí¼þÖÐ  £¬Ò»µ©Êܺ¦ÕßÏÂÔØÁËÕâЩ¶ñÒⷨʽ  £¬Æä½«»á×°ÖÃÒ»¸öÃûΪ¡°²¹¶¡¡±µÄ¿ÉÖ´ÐÐÎļþµ½¡°/Users/Shared/¡±Ä¿Â¼ÖÐ  £¬¶øºó  £¬Å²Óá°eip_encrypt¡±º¯Êý¼ÓÃÜÊܺ¦ÕßµÄÎļþ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/evilquest-mac-ransomware-keylogger-crypto-wallet-stealing/157034/


5.Googleɾ³ý25¸ö¶ñÒâAndroidÀûÓà  £¬¿ÉÇÔÈ¡FacebookÍ´´¦


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¹È¸è±¾ÔÂ´ÓÆäÉ̵êÖÐɾ³ýÁË25¸öÓÃÀ´ÇÔÈ¡FacebookÍ´´¦µÄAndroidÀûÓà  £¬Ä¿Ç°ËüÃǵÄÏÂÔØÁ¿×ܼƳ¬¹ý234Íò´Î¡£Æ¾¾Ý·¨¹ú°²È«¹«Ë¾EvinaµÄ»ã±¨  £¬ÕâЩÀûÓÃÔ̺¬¼Æ²½Æ÷¡¢Í¼Ïñ±à×ëÆ÷¡¢ÊÓÆµ±à×ëÆ÷¡¢Ç½Ö½ÀûÓá¢ÊÖµçͲÀûÓá¢ÎļþÖÎÀíÆ÷ºÍÊÖ»úÓÎÏ·¡£ËûÃǾùÊÇÊÇÓÉͳһºÚ¿Í×éÖ¯¿ª·¢µÄ  £¬Ö»¹ÜÖ°ÄÜ·ÖÆç  £¬µ«¹¤×÷µÀÀí¶¼ÊÇÒ»ÑùµÄ¡£ËüÏȼì²âÓû§×î½ü´ò¿ªÁËʲôÀûÓà  £¬ÈôÊÇÊÇFacebook  £¬¸Ã¶ñÒâÀûÓý«ÔÚ¹Ù·½FacebookÀûÓõĶ¥²¿¸²¸ÇÒ»¸öWebä¯ÀÀÆ÷´°¿Ú  £¬²¢¼ÓÔØ¼ÙµÄFacebookµÇÂ¼Ò³Ãæ  £¬ÓÃÀ´ÇÔÈ¡Óû§µÇ¼ƾ֤¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-removes-25-android-apps-caught-stealing-facebook-credentials/    


6.FakeSpy¼ÙÒâÓÊÕþ·þÎñÕë¶ÔÃÀ¹ú¡¢ÖйúºÍÅ·ÖÞÓû§ÇÔÈ¡²ÆÕþÐÅÏ¢


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


°²È«¹«Ë¾Cybereason·¢ÏÖ  £¬ÔÚ´ÓǰµÄ¼¸ÖÜÄÚ  £¬FakeSpyÕý¼Ùð¸÷ÀàÓÊÕþ·þÎñÀ´¹¥»÷ÃÀ¹ú¡¢ÖйúºÍÅ·ÖÞµÄÓû§  £¬ÒÔÇÔÈ¡Æä²ÆÕþÐÅÏ¢¡£ºÚ¿Íͨ¹ý·¢ËÍαÔìµÄ¶ÌÐŽøÐй¥»÷  £¬µ±Êܺ¦Õßµã»÷ÕâЩ¶ÌÐÅʱ  £¬°µ²ØµÄ´úÂë¾Í»áÇÔÈ¡²ÆÕþÊý¾Ý¡£ÓÉÓÚÊÇͨ¹ý·¢ËͶÌÐŽøÐй¥»÷  £¬ËûÃDz»±ØÒªÈëÇֹȸèÓÎÏ·É̵êÀ´Ö²ÈëÆä¶ñÒâ´úÂë¡£´Ë±í  £¬ºÚ¿Í»¹Í¨¹ý±àдÊÖ»ú¶ñÒâÈí¼þ¹¤¾ß°ü  £¬µ÷Õû´úÂëÒÔÕë¶ÔÊÀ½çÉÏ·ÖÆçµØÓò  £¬ÒÔ×·Çó×îÓÐÀû¿ÉͼµÄ¹¥»÷·½Ê½¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyberscoop.com/fakespy-android-cybereason-postal-service/