¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181126
Ðû²¼Ê±¼ä 2018-11-26

2018ÄêµÄÐþÉ«ÐÇÆÚÎå´Ó11ÔÂ23ÈÕ×îÏÈ£¬£¬£¬£¬¹ºÎï¼¾½Ú½«Ò»Ö±ÑÓÐøµ½Ê¥µ®½Úʱ´ú¡£¡£¡£Group-IBÑо¿Ö°Ô±·¢Ã÷ÁË400¶à¸öÄ£ÄâÔÚÏßÉúÒâÆ½Ì¨µÄAliExpressÍøÕ¾£¬£¬£¬£¬ÒÔ¼°200¶à¸öÄ£Äâ×ÅÃûÆ·ÅÆµÄÍøÕ¾£¬£¬£¬£¬ÕâЩڲÆÐÔµÄÍøÕ¾¿ÉÄÜÊÇΪÁËÏúÊÛð³äÉÌÆ·£¬£¬£¬£¬Ò²¿ÉÄÜÊÇΪÁË͵ÇÔÓû§µÄÒøÐп¨Êý¾Ý¼°¿î×Ó¡£¡£¡£¹¥»÷Õ߸´ÖÆÁËÕæÊµÍøÕ¾µÄÆ·ÅÆ¡¢logoÒÔ¼°ÑÕÉ«£¬£¬£¬£¬²¢×¢²áÏàËÆµÄÓòÃûÀ´Îóµ¼ÏûºÄÕß¡£¡£¡£ÕâÖÖÍøÕ¾µÄ»á¼ûÁ¿¿É´ïÿ¸öÔÂ20ÍòÈ˴Ρ£¡£¡£Æ¾Ö¤Group-IBµÄͳ¼Æ£¬£¬£¬£¬Æ½¾ùÿ¸ö¶íÂÞ˹ÈËÔÚð³äÉÌÆ·ÉÏÆÆ·ÑÁË5300¬²¼¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.group-ib.ru/blog/blackfridaysale2¡¢Çå¾²³§ÉÌ·¢Ã÷ºÚÎåʱ´úEmotetµÄ´ó¹æÄ£À¬»øÓʼþ»î¶¯

ESET·¢Ã÷ÓëºÚÎ幺Îï¼¾ÓйصÄEmotet´ó¹æÄ£À¬»øÓʼþ»î¶¯¡£¡£¡£Óë֮ǰµÄ¹¥»÷Ïà±È£¬£¬£¬£¬EmotetÉÔ΢¸Ä±äÁËËûÃǵÄ×÷°¸ÊÖ·¨¡£¡£¡£ËäÈ»ÓÐÓúÉÔØÈÔÈ»ÊÇͨ¹ýÀ¬»øÓʼþÖеĸ½¼þºÍ¶ñÒâÁ´½ÓÀ´½»¸¶£¬£¬£¬£¬µ«ÔÚºÚÎåʱ´ú£¬£¬£¬£¬ÕâЩ¶ñÒâÎļþÊÇÀ©Õ¹ÃûΪ.docµÄXMLÎļþ£¬£¬£¬£¬¶ø²»ÊÇ֮ǰµÄdocºÍpdfÎļþ¡£¡£¡£¸Ã¶ñÒâ»î¶¯µÄÓÐÓúÉÔØÊÇÖÖÖÖÒøÐÐľÂí£¬£¬£¬£¬°üÀ¨Ursnif¡¢TrickBotºÍIcedId¡£¡£¡£À¶¡ÃÀÖÞÊÇÊÜÓ°Ïì×î´óµÄ¹ú¼Ò£¬£¬£¬£¬Æä´ÎÊÇÄ«Î÷¸ç¡¢¶ò¹Ï¶à¶û¡¢°¢¸ùÍ¢ºÍÃÀ¹ú¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.welivesecurity.com/2018/11/23/black-friday-special-emotet-filling-inboxes-infected-xml-macros/3¡¢Ñо¿Ö°Ô±·¢Ã÷Õë¶ÔÒôÀÖЧÀÍÆ½Ì¨SpotifyµÄÍøÂç´¹ÂÚ¹¥»÷

AppRiverµÄÑо¿Ö°Ô±·¢Ã÷Ò»¸öÕë¶ÔÔÚÏßÒôÀÖЧÀÍSpotifyÓû§µÄÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£ÕâЩÀ¬»øÓʼþÊÔͼͨ¹ýÓÕÆÓû§µã»÷ÓʼþÖеĴ¹ÂÚÁ´½Ó£¬£¬£¬£¬½«Óû§Öض¨ÏòÖÁ´¹ÂÚÍøÕ¾£¬£¬£¬£¬²¢ÒýÓÕÓû§ÊäÈëÓû§ÃûºÍÃÜÂë¡£¡£¡£ÈôÊÇÓû§ÔÚÆäËüÍøÕ¾ÉÏ£¨ÀýÈçÍøÉÏÒøÐУ©Ê¹ÓÃÁËÏàͬµÄƾ֤£¬£¬£¬£¬ÄÇôÓû§¿ÉÄÜÔÚײ¿â¹¥»÷ÖÐÊܵ½¸ü´óµÄË𺦡£¡£¡£ËäÈ»´¹ÂÚÍøÕ¾µÄµÇÂ¼Ò³ÃæÓë¹ÙÍøspotify.comÏàËÆ£¬£¬£¬£¬µ«Óû§ÈÔÈ»¿ÉÒÔ´ÓÓʼþµÄ·¢¼þÈË¡¢ÍøÕ¾µÄURLÖÐÇø·Ö³ö´¹ÂÚÍøÕ¾£¬£¬£¬£¬×èÖ¹Êܵ½Ëðʧ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/spotify-phishers-hijack-music-fans-accounts/139329/4¡¢21ËêºÚ¿ÍÈëÇÖ¹è¹È¶àÃû¸ß¹ÙµÄÊÖ»ú£¬£¬£¬£¬ÇÔÈ¡¼ÛÖµ100ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò

ƾ֤ÃÀ¹ú¼ì·½±¾ÔÂÏò¼ÓÖÝ·¨ÔºÌá½»µÄÒ»·ÝÎļþ£¬£¬£¬£¬21ËêµÄNicholas TrugliaʹÓÃÒ»ÖÖ±»³ÆÎªSIM¿¨½»Á÷µÄÕ½ÂÔÈëÇÖÁ˶àÃû¹è¹È¸ß¹ÜµÄÊÖ»ú£¬£¬£¬£¬²¢´ÓRobert RossµÄCoinbaseºÍGeminiÕË»§Öл®·ÖÇÔÈ¡ÁË50ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£¡£¡£¸ÃÎļþÏÔʾTrugliaÒѱ»Ö¸¿Ø21Ïî×ïÃû£¬£¬£¬£¬°üÀ¨Éí·Ý͵ÇÔ¡¢Ú²Æ¡¢Å²Óù«¿î¡¢ÖØ´ó͵ÇÔδËìµÈ¡£¡£¡£SIM¿¨½»Á÷ÊÇÖ¸·¸·¨·Ö×Óαװ³ÉÊܺ¦Õߣ¬£¬£¬£¬ÓÕÆÔËÓªÉ̽«Êܺ¦ÕßµÄÊÖ»úºÅÂëÖØÐ·ÖÅɸø¹¥»÷ÕßÓµÓеÄSIM¿¨µÄÕ½ÂÔ¡£¡£¡£¸ÃÀú³ÌÖз¸·¨·Ö×ÓÐèÒª»Ø¸²Ò»Ð©ÓÃÓÚÑéÖ¤Éí·ÝµÄÇå¾²ÎÊÌâ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.welivesecurity.com/2018/11/23/new-yorker-accused-stealing-1m-sim-swap/5¡¢ÎÚ¿ËÀ¼¾¯·½¾Ð²¶ÉæÏÓÈö²¥DarkComet RATµÄÏÓÒÉ·¸

ÎÚ¿ËÀ¼¾¯·½¾Ð²¶ÁËÒ»ÃûÉæÏÓÈö²¥DarkComet RATµÄ42ËêÄÐ×Ó£¬£¬£¬£¬¸ÃÄÐ×Ó±»Ö¸¿ØÊ¹ÓÃDarkCometѬȾÁË50¶à¸ö¹ú¼ÒµÄÁè¼Ý2000ÃûÊܺ¦Õß¡£¡£¡£¸ÃÄÐ×ÓÔÚÎÚ¿ËÀ¼Î÷²¿ÀûÎÖ·òÊеļÒÖб»²¶¡£¡£¡£ÎÚ¿ËÀ¼¾¯·½ÌåÏÖËûÃÇÔÚÏÓÒÉÈ˵ÄÅÌËã»úÉÏ·¢Ã÷ÁËDarkCommet RATµÄÖÎÀíÃæ°å£¬£¬£¬£¬²¢ÕÒµ½ÁËDarkCommetµÄ×°ÖÃÎļþÒÔ¼°Êܺ¦ÕßÅÌËã»úµÄÆÁÄ»½ØÍ¼¡£¡£¡£¸ÃÏÓ·¸ÏÖʵÉÏ·¸ÁËÒ»¸öOpSec¹ýʧ£¬£¬£¬£¬Ëû½«DarkCometÖÎÀíÃæ°åÖ±½Ó·ÅÔÚ¼ÒÀïµÄÅÌËã»úÉÏ£¬£¬£¬£¬Ê¹µÃ¾¯·½ºÜÈÝÒ×¶¨Î»µ½ÆäÉí·Ý¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/ukrainian-police-arrest-hacker-who-infected-over-2000-users-with-darkcomet-rat/6¡¢Ñо¿Ö°Ô±·¢Ã÷Ö¼ÔÚѬȾWindowsϵͳµÄжñÒâÈí¼þL0rdix

EnSiloÑо¿Ö°Ô±Ben Hunter·¢Ã÷ÔÚ°µÍøÂÛ̳ÉÏ·ºÆðÁËÒ»¸öеĶñÒâÈí¼þL0rdix£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÖ÷ÒªÕë¶ÔWindowsϵͳ£¬£¬£¬£¬Á¬ÏµÁËÊý¾ÝÇÔÈ¡ºÍ¶ñÒâÍÚ¿ó¹¦Ð§£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔÌӱܶñÒâÈí¼þÆÊÎö¹¤¾ß¡£¡£¡£L0rdixËäÈ»ÒÑÔÚ°µÍøÂÛ̳ÉϳöÊÛ£¬£¬£¬£¬µ«ÈÔÓÐһЩ֤¾ÝÅú×¢¸Ã¶ñÒâÈí¼þ»¹ÔÚ¿ª·¢Àú³ÌÖС£¡£¡£L0rdixʹÓÃ.NET±àд£¬£¬£¬£¬Ê¹ÓÃConfuserExºÍ.NETGuard¾ÙÐлìÏý£¬£¬£¬£¬²¢Í¨¹ýWMIÅÌÎʺÍ×¢²á±íÏîÀ´¼ì²âÊÇ·ñɳÏäÇéÐΡ£¡£¡£EnSiloÔ¤¼Æ½«»á¿´µ½¸Ã¶ñÒâÈí¼þµÄ¸ü¶àÖØ´ó°æ±¾¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.ensilo.com/l0rdix-attack-toolÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí