ÃÀ¹úÊý°Ù¸öÐÂÎÅÍøÕ¾Ôâµ½¹©¸øÁ´¹¥»÷²¢×°ÖÃSocGholish

°ä²¼¹¦·ò 2022-11-04
1¡¢ÃÀ¹úÊý°Ù¸öÐÂÎÅÍøÕ¾Ôâµ½¹©¸øÁ´¹¥»÷²¢×°ÖÃSocGholish

      

ýÌå11ÔÂ2Èճƣ¬TA569ÍÅ»ïÀûÓÃijýÌ幫˾±»ÈëÇֵĻù´¡ÉèÊ©£¬ÔÚÃÀ¹ú250¶à¼ÒÐÂÎÅýÌåµÄÍøÕ¾ÉÏ×°ÖÃSocGholish JavaScript¶ñÒâÈí¼þ¿ò¼Ü£¨Ò²³ÆÎªFakeUpdates£©¡£¹¥»÷ÕßÊ×ÏȽ«¶ñÒâ´úÂë×¢Èëµ½ÍøÕ¾¼ÓÔØµÄJavaScriptÎļþÖУ¬¸ÃÎļþ±»ÓÃÀ´×°ÖÃSocGholish£¬Ëü½«Í¨¹ýαÔìµÄ¸üÐÂÌáÐÑ£¬°Ñ¶ñÒâÈí¼þpayload¼Ù×°³ÉÐéαµÄä¯ÀÀÆ÷¸üÐÂÎļþ£¨ÈçChrom§Ö.U§âdat§Ö.zip¡¢ºÍFirefo§ç.U§âdat§Ö.zipµÈ£©Ï°È¾½Ó¼ûÍøÕ¾µÄÓû§¡£


https://www.bleepingcomputer.com/news/security/hundreds-of-us-news-sites-push-malware-in-supply-chain-attack/


2¡¢×êÑÐÍŶӷ¢ÏÖÊýÊ®¸öÊÔͼ·Ö·¢¶ñÒâÈí¼þW4SPµÄPyPI°ü

      

Phylum 11ÔÂ1ÈÕ³ÆÆäÔÚPyPI×¢²á±íÖз¢ÏÖÁË29¸öPython°ü£¬ËüÃÇ·ÂÕÕÊ¢ÐеĿ⣬²¢ÔÚϰȾָ±êºó·Ö·¢ÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þW4SP¡£Phylum×êÑÐÈËԱй©£¬Æ¾¾ÝPepy.techµÄͳ¼ÆÊý¾Ý£¬ÕâЩÈí¼þ°üÒѱ»ÏÂÔØÁ˳¬¹ý5700´Î¡£´Ë±í£¬×êÑÐÈËÔ±Hauke L¨¹bbers·¢ÏÖÁËPyPI°üpystileºÍthreadingsÔ̺¬×Ô³ÆÎªGyruzPIPµÄ¶ñÒâÈí¼þ£¬¸Ã¶ñÒâÈí¼þ»ùÓÚÒ»¸ö¿ªÔ´ÏîÄ¿evil-pip¡£L¨¹bbersÒѽ«ÕâЩ°ü»ã±¨¸øPyPIÖÎÀíÔ±¡£


https://blog.phylum.io/phylum-discovers-dozens-more-pypi-packages-attempting-to-deliver-w4sp-stealer-in-ongoing-supply-chain-attack


3¡¢ÎÖ´ï·áÒâ´óÀû¹«Ë¾Åû¶Æä¾­ÏúÉ̱»ºÚµ¼ÖµÄÊý¾Ýй¶ÊÂÎñ

      

¾Ý11ÔÂ2ÈÕ±¨Â·£¬ÎÖ´ï·áÒâ´óÀû¹«Ë¾£¨Vodafone Italia£©Í¨ÖªÆä¿Í»§¹ØÓÚ¾­ÏúÉÌFourB SpA±»ºÚµ¼ÖµÄÊý¾Ýй¶ÊÂÎñ¡£¹¥»÷²úÉúÔÚ9ÔµĵÚÒ»ÖÜ£¬Ð¹Â¶ÁËÓû§µÄ¾ßÌåÐÅÏ¢£¬Èç¶©ÔÄÐÅÏ¢¡¢Éí·ÝÖ¤¼þºÍÁªÏµ·½Ê½µÈ¡£Ä¿Ç°£¬FourBÒѾ­¹Ø¹ØÁ˶Ա»ÈëÇÖ·þÎñÆ÷µÄ½Ó¼û£¬²¢Ö´ÐÐÁ˸ü¸ß¼¶´ËÍⰲȫսÊõ¡£2022Äê9ÔÂ3ÈÕ£¬×Ô³ÆKelvinSecurityÍÅ»ïÔøÐû³Æ¹¥»÷ÁËVodafone Italia²¢ÇÔÈ¡ÁË295000¸öÎļþ£¬×ܼÆ310 GBµÄÊý¾Ý¡£Æäʱ£¬ÎÖ´ï·á»ØÓ¦³ÆÆä¹«Ë¾ÄÚ²¿ITϵͳ²¢Î´Ô⵽δ¾­ÊÚȨµÄ½Ó¼û£¬µ«½«³ÖÐøµ÷²é¡£Éв»Ã÷ÏÔ¸ÃÊÂÎñÊÇ·ñÓëÕâ´ÎÅû¶µÄй¶ÊÂÎñÓйØ¡£


https://www.bleepingcomputer.com/news/security/vodafone-italy-discloses-data-breach-after-reseller-hacked/


4¡¢OPERA1ERÍÅ»ïÒÑ´ÓÒøÐк͵çÐŹ«Ë¾ÇÔÈ¡³¬¹ý1100ÍòÃÀÔª

      

¾ÝGroup-IB 11ÔÂ3Èճƣ¬ºÚ¿ÍÍÅ»ïOPERA1ERÀûÓÃÏֳɵĺڿ͹¤¾ß£¬ÒÑ´ÓÒøÐк͵çÕÛ·þÎñÌṩÉÌÇÔÈ¡ÁËÖÁÉÙ1100ÍòÃÀÔª¡£³ýÁËÖØÒªÕë¶Ô·ÇÖ޵Ĺ«Ë¾±í£¬¸ÃÍŻﻹ¹¥»÷Á˰¢¸ùÍ¢¡¢°ÍÀ­¹çºÍÃϼÓÀ­¹úµÄ×éÖ¯¡£´Ó2018Äêµ½2022Ä꣬ºÚ¿Í×ܹ²ÌáÒéÁ˳¬¹ý35´Î³É¹¦µÄ¹¥»÷£¬ÆäÖÐÔ¼Èý·ÖÖ®Ò»ÊÇÔÚ2020Äê½øÐеÄ¡£OPERA1ERÀûÓÃÓã²æÊ½´¹µö¹¥»÷»ñµÃ³õʼ½Ó¼ûȨÏÞ£¬ÖØÒªÒÀ¸½¿ªÔ´¹¤¾ß¡¢ÉÌÆ·¶ñÒâÈí¼þÒÔ¼°MetasploitºÍCobalt StrikeµÈ¿ò¼ÜÀ´ÈëÇÖ¹«Ë¾µÄ·þÎñÆ÷¡£


https://blog.group-ib.com/opera1er-apt


5¡¢Lookout°ä²¼2022ÄêÃÀ¹úµ±¾Ö»ú¹¹ÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨

      

11ÔÂ2ÈÕ£¬Lookout°ä²¼Á˹ØÓÚ2022ÄêÃÀ¹úµ±¾Ö»ú¹¹ÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨»ùÓÚ¶Ô2021ÄêÖÁ2022ÄêϰëÄêµÄ2ÒŲ́É豸ºÍ1.75ÒÚ¸öÀûÓ÷¨Ê½½øÐзÖÎö£¬·¢ÏÖÃÀ¹úµ±¾ÖÔ±¹¤Ê¹ÓõÄAndroidÊÖ»úÖУ¬½üÒ»°ëÔËÐеÄÊǹýÆÚµÄ²Ù×÷ϵͳ°æ±¾¡£Õë¶ÔÒÆ¶¯Óû§×î³£¼ûµÄ¹¥»÷ÊǶñÒâÈí¼þµÄ´«²¼£¬Ô¼Õ¼75%£¬¶øÆ¾Ö¤ÇÔÈ¡ÔòÕ¼Ôü×Ò±ÈÀýµÄ´ó²¿ÃÅ¡£2022Ä꣬Lookout¼à¿ØµÄ11Ãûµ±¾ÖÔ±¹¤ÖÐÓÐ1ÈËÔâµ½´¹µö¹¥»÷¡£ÄÇЩµã»÷¶ñÒâÁ´½Ó²¢±»ÖÒ¸æµÄÈËÖУ¬57%ûÓÐÔÙ³Á¸´ËûÃǵÄÃýÎó£¬19%µÄÈ˵ã»÷ÁËÁ½´Î£¬24%µÄÈ˵ã»÷ÁËÈý´ÎÒÔÉÏ¡£


https://www.lookout.com/form/threats-government-threat-report-lp


6¡¢Deep Instinct°ä²¼2022ÄêÖÐÆÚÍøÂçÍþÐ²Ì¬ÊÆµÄ»ã±¨

      

¾ÝýÌå11ÔÂ1Èճƣ¬Deep Instinct°ä²¼ÁË2022ÄêÖÐÆÚÍøÂçÍþÐ²Ì¬ÊÆµÄ»ã±¨¡£»ã±¨Ö¸³ö£¬RaaSÍÅ»ïLockBitÕ¼2022ÄêËùÓÐÀÕË÷¹¥»÷µÄ44%£¬Æä´ÎÊÇConti(23%)¡¢Hive(21%)¡¢Black Cat(7%)ºÍConti Splinters(5%)¡£Ëæ×Å΢ÈíÔÚOfficeÎļþÖÐĬÈϽûÓú꣬ʹÓÃÎĵµµÄ¶ñÒâÈí¼þ×÷ÎªÔØÌåµÄÇé¿öÏ÷¼õÁË£¬È¡¶ø´úÖ®µÄÊÇLNK¡¢HTMLºÍ´æµµµç×ÓÓʼþ¸½¼þ¡£´Ë±í£¬»ã±¨»¹Ìáµ½ÁËÏñSpoolFool¡¢FollinaºÍDirtyPipeÕâÑùµÄ·ì϶͹ÆðÁËWindowsºÍLinuxϵͳµÄ¿ÉÀûÓÃÐÔ£¬ÅúעÿÈýµ½ËĸöÔ±»ÀûÓõķì϶ÊýÁ¿¾Í»á¼¤Ôö¡£


https://www.infosecurity-magazine.com/news/lockbit-dominates-ransomware/