BahamutÍÅ»ïÀûÓüÙðµÄVPNÀûÓÃÇÔÈ¡AndroidÓû§ÐÅÏ¢

°ä²¼¹¦·ò 2022-11-25
1¡¢BahamutÍÅ»ïÀûÓüÙðµÄVPNÀûÓÃÇÔÈ¡AndroidÓû§ÐÅÏ¢

11ÔÂ23ÈÕ £¬ESETÅû¶ÁËÓÉAPT×éÖ¯BahamutÌáÒéÕë¶ÔAndroidÓû§µÄ¹¥»÷»î¶¯ ¡£¸Ã»î¶¯×Ô2022Äê1ÔÂÒÔÀ´Ò»Ïò»îÔ¾ £¬Bahamut³Áдò°üÁ˺ÏÓÃÓÚAndroidµÄSoftVPNºÍOpenVPNÀûÓà £¬Ôö³¤ÁËÓµÓмäµýÖ°ÄܵĶñÒâ´úÂë ¡£Òò¶ø £¬¸ÃÀûÓÃÈÔ»áÌṩVPNÖ°ÄÜ £¬Í¬Ê±»¹Äܹ»´ÓÒÆ¶¯É豸ÖÐÇÔÊØÐÅÏ¢ ¡£ÎªÁË·ÛÊι¥»÷»î¶¯²¢Ìá¸ß¿ÉÐŶÈ £¬BahamutʹÓÃÁËSecureVPN£¨Ò»¸öºÏ·¨µÄVPN·þÎñ£©µÄÃû×Ö £¬²¢´´½¨ÁËÒ»¸ö¼ÙÍøÕ¾[thesecurevpn]À´·Ö·¢¶ñÒâÀûÓà ¡£

https://www.welivesecurity.com/2022/11/23/bahamut-cybermercenary-group-targets-android-users-fake-vpn-apps/

2¡¢³¬¹ý50¸öαÔìµÄMSI Afterburner¹ÙÍø·Ö·¢ÍÚ¿óÈí¼þ

¾Ý11ÔÂ23ÈÕ±¨Â· £¬CybleµÄ×êÑÐÈËÔ±·¢ÏÖÁ˼¸¸öÕë¶ÔMSI AfterburnerÈí¼þµÄ´¹µö»î¶¯ £¬Ö¼ÔÚ·Ö·¢ÍÚ¿ó¶ñÒâÈí¼þ ¡£ÔÚ´ÓǰÈý¸öÔÂÖÐ £¬Óг¬¹ý50¸ö¼ÙÒâMSI Afterburner¹ÙÍøµÄ´¹µöÍøÕ¾ £¬»á·Ö·¢XMR(Monero)¿ó¹¤ÓëÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þ ¡£¾ßÌåÀ´Ëµ £¬µ±Ö¸±êÖ´ÐÐαÔìµÄMSI Afterburner×°ÖÃÎļþ(MSIAfterburnerSetup.msi)ʱ £¬³ýÁË»á×°ÖúϷ¨µÄAfterburner·¨Ê½ £¬»¹»á͵͵µØ×°Öò¢ÔËÐжñÒâÈí¼þRedLineºÍXMRÍÚ¿ó·¨Ê½ ¡£²»ÐÒµÄÊÇ £¬¸Ã»î¶¯ÏÕЩËùÓеÄ×é¼þ¶¼Ã»Óб»É±¶¾Èí¼þ¼ì²âµ½ ¡£

https://blog.cyble.com/2022/11/23/fake-msi-afterburner-sites-delivering-coin-miner/

3¡¢IBM·¢ÏÖÀÕË÷Èí¼þRansomExxµÄбäÌåÒÑÓÃRust³Áд

IBMÔÚ11ÔÂ22ÈÕ³ÆÆä·¢ÏÖÁËRansomExxÀÕË÷Èí¼þµÄÒ»¸öбäÌå £¬¸Ã±äÌåÒÑÓÃRust˵»°³Áд ¡£ÓÃRust¿ª·¢µÄ¶ñÒâÈí¼þͨ³£»áÓнϵ͵ÄAV¼ì²âÂÊ £¬Õâ¿ÉÄÜÊÇËüʹÓøÃ˵»°µÄÖØÒªÔ­Òò ¡£Ð±äÌåµÄÖ°ÄÜÓëÆäC++µÄ°æ±¾ÀàËÆ £¬½«Òª¼ÓÃܵÄÖ¸±êĿ¼Áбí×÷ΪºÅÁîÐвÎÊý´«µÝ £¬¶øºóʹÓÃAES-256¼ÓÃÜÎļþ £¬²¢Ê¹ÓÃRSAÀ´±£»¤¼ÓÃÜÃÜÔ¿ £¬ËùÓдóÓÚ»òµÅ×Ú40×Ö½ÚµÄÎļþ¶¼±»¼ÓÃÜ ¡£Ä¿Ç° £¬ÔÚ60¶à¼ÒAVÌṩÉÌÖÐÖ»ÓÐ14¼Ò¼ì²âµ½ÁËÐÂÑù±¾ ¡£

https://securityintelligence.com/posts/ransomexx-upgrades-rust/

4¡¢Smith FamilyÔ¼8Íò¾èÔùÕߵľßÌåÐÅÏ¢¿ÉÄÜÒÑй¶

¾ÝýÌå11ÔÂ22ÈÕ±¨Â· £¬°Ä´óÀûÑǴȱ¯»ú¹¹Smith Familyй©ÆäÔâµ½ºÚ¿Í¹¥»÷ £¬Ô¼8Íò¾èÔùÕߵľßÌåÐÅÏ¢¿ÉÄÜÒѱ»½Ó¼û ¡£Ð¹Â¶ÐÅÏ¢Éæ¼°ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢ÓʼþµØÖ·ºÍ¾èÔù¼Í¼ £¬ÒÔ¼°²¿ÃÅÖ§¸¶¿¨µÄ¶øÐÅÏ¢ ¡£¸Ã»ú¹¹µÄÉêÃ÷°µÊ¾ £¬ºÚ¿Ḭ́ͼµÁÈ¡×ʽðµ«ÊÇûÓгɹ¦ £¬ËûÃÇÒÑ֪ͨÊÜÓ°ÏìµÄ¾èÔùÕß £¬Ä¿Ç°Ã»ÓÐÈκÎÈ˵ÄÐÅÏ¢±»ÀÄÓà ¡£

https://www.abc.net.au/news/2022-11-22/smith-family-charity-cyber-crime-hackers-donor-details/101683860

5¡¢¼Ù×°³ÉÐÂÎŵ÷²éµÄ¶ñÒâwordÎĵµÇÔȡָ±êµÄÐÅÏ¢

¾ÝASEC 11ÔÂ25ÈÕ±¨Â· £¬½üÆÚÒ»¸öÓ볯ÏÊÓйصĶñÒâWordÎļþÒ»ÏòÔÚʹÓÃFTPй¶Óû§Í´´¦ ¡£¸ÃWordÎĵµµÄÎļþÃûΪ¡°CNA[Q].doc¡± £¬¼Ù×°³ÉCNAÐÂ¼ÓÆÂµçÊÓ½ÚÄ¿²É·Ã ¡£¸ÃÎļþÊÜÃÜÂë±£»¤ £¬ÓëÃÜÂëһ·×÷ΪÓʼþ¸½¼þ·Ö·¢ ¡£ÎļþÖÐÔ̺¬¶ñÒâVBAºê £¬Í¨¹ýDocument_Open()º¯Êýʹ¶ñÒâºê×Ô¶¯Ö´ÐÐ ¡£ËüÄܹ»Ê¹ÓÃFTPй¶Óû§µÄÐÅÏ¢¡¢´´½¨LNKÎļþ¡¢¸ü¸ÄMS Office°²È«ÉèÖúͼͼ¼üÅÌ ¡£

https://asec.ahnlab.com/en/42529/

6¡¢Group-IB°ä²¼ÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þ·Ö·¢»î¶¯µÄ·ÖÎö»ã±¨

11ÔÂ23ÈÕ £¬Group-IB°ä²¼»ã±¨³ÆÒÑÈ·¶¨34¸ö¶íÂÞ˹ºÚ¿ÍÍÅ»ïÔÚÒÔÇÔÈ¡¼´·þÎñģʽ(SaaS)·Ö·¢ÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þ ¡£¹¥»÷ÕßÖØÒªÊ¹ÓÃRacoonºÍRedlineÇÔÈ¡·¨Ê½ £¬À´ÍøÂçSteamºÍRobloxÓÎÏ·ÕÊ»§µÄÃÜÂë £¬ÑÇÂíÑ·ºÍPayPalµÄÍ´´¦ £¬ÒÔ¼°Óû§µÄÖ§¸¶¼Í¼ºÍ¼ÓÃÜÇ®°üÐÅÏ¢ ¡£2022ÄêµÄǰ7¸öÔ £¬¹¥»÷Õß¹²Ï°È¾³¬¹ý89Íǫ̀É豸 £¬ÇÔÈ¡³¬¹ý5000Íò¸öÃÜÂë £¬ÖØÒªÕë¶ÔÃÀ¹ú¡¢°ÍÎ÷¡¢Ó¡¶È¡¢µÂ¹úºÍÓ¡¶ÈÄáÎ÷ÑÇ £¬¶ñÒâ»î¶¯Éæ¼°111¸ö¹ú¶È/µØÓò ¡£

https://www.group-ib.com/media-center/press-releases/professional-stealers/