TrickBotͨ¹ý¼ì²éÆÁÄ»Çø·ÖÂÊÌӱܲ¡¶¾ÆÊÎö£»£»£»£»£»£»ÐÂÀÕË÷Èí¼þEvilQuestÕë¶ÔMacϵͳ£¬£¬£¬£¬Í¨¹ýµÁ°æÈí¼þÈö²¥
Ðû²¼Ê±¼ä 2020-07-021.¶ñÒâÈí¼þTrickBotͨ¹ý¼ì²éÆÁÄ»Çø·ÖÂÊÒÔÌӱܲ¡¶¾ÆÊÎö
ÍøÂçÇå¾²¹«Ë¾MalwareLab·¢Ã÷¶ñÒâÈí¼þTrickBotÒѾ×îÏÈͨ¹ý¼ì²éÊܺ¦ÕߵįÁÄ»Çø·ÖÂÊ£¬£¬£¬£¬À´¼ì²âÆäÊÇ·ñÔÚÐéÄâ»úÖÐÔËÐУ¬£¬£¬£¬ÒÔÌÓ±ÜÑо¿Ö°Ô±»ò×Ô¶¯É³Ïäϵͳ¶ÔÆä¾ÙÐÐÆÊÎö¡£¡£¡£¡£¡£¡£¡£ÐµÄTrickBotÑù±¾ÕýÔÚ¼ì²éÅÌËã»úµÄÆÁÄ»Çø·ÖÂÊÊDz»ÊÇ800x600»ò1024x768£¬£¬£¬£¬ÈôÊÇÊÇ£¬£¬£¬£¬TrickBotÔò»áÁ¬Ã¦ÖÕÖ¹¡£¡£¡£¡£¡£¡£¡£TrickBot¼ì²éÕâÐ©ÌØÊâµÄÇø·ÖÂÊ£¬£¬£¬£¬ÊÇÓÉÓÚÑо¿Ö°Ô±Í¨³£ÊÇÕâÑùÉèÖÃËûÃǵÄÐéÄâ»ú¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/trickbot-malware-now-checks-screen-resolution-to-evade-analysis/
2.Ó¡¶È¹ú¼Ò¹«Â·¾Ö(NHAI)ϵͳÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬ÏÖÒѻָ´
Ó¡¶È¹ú¼Ò¹«Â·ÖÎÀí¾Ö£¨NHAI£©ÓÚÉÏÖÜÈÕÍíÉÏÔâµ½ÁËÀÕË÷Èí¼þµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¾Ý¸Ã²¿·ÖÔ±¹¤Ëµ£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ¹¥»÷ÁËÕþ¸®µÄµç×ÓÓʼþϵͳ£¬£¬£¬£¬¿ÉÄÜÒ²Ó°ÏìÁËÒÑÍùÊ®ÄêÀ´¸ßËÙ¹«Â·ÉϵĴó×ÚÊý¾ÝºÍÉñÃØÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£µ«ØÊºó£¬£¬£¬£¬NHAI½²»°ÈËÌåÏÖ£¬£¬£¬£¬´Ë´Î¹¥»÷ûÓÐÀֳɣ¬£¬£¬£¬ÏÖÔÚϵͳÏÖÒѻָ´£¬£¬£¬£¬Ã»Óб¬·¢Êý¾Ýɥʧ£¬£¬£¬£¬NHAIÊý¾ÝºÍÆäËûϵͳÈÔûÓÐÊܵ½´Ë´Î¹¥»÷µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¾ÝSophos³Æ£¬£¬£¬£¬Ó¡¶ÈÔÚÍøÂç·ÀÓù·½ÃæÎª±¡Èõ»·½Ú£¬£¬£¬£¬½öÈ¥Äê¾ÍÓÐ82£¥µÄÓ¡¶È×éÖ¯Ôâµ½ÀÕË÷Èí¼þµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hindustantimes.com/india-news/nhai-server-attacked-by-malware-govt-says-no-data-loss/story-wGDAcPUo4MWzPLOcqu2WZJ.html
3.Ê©ÀÖ¹«Ë¾Ôâµ½MazeÀÕË÷Èí¼þ¹¥»÷²¢Ð¹Â¶Áè¼Ý100GBÎļþ
ºÚ¿Í×éÖ¯MazeÓÚ6ÔÂ25ÈÕ¶ÔÊ©ÀÖ¹«Ë¾ÌᳫÁËÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬¸Ã¹«Ë¾ÖÁÉÙÒ»¸öXeroxÓòÖеÄÅÌËã»ú±»¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£¾Ý¹¥»÷Õ߳ƣ¬£¬£¬£¬ËûÃÇÒѾ´ÓÊ©ÀÖ¹«Ë¾ÇÔÈ¡ÁËÁè¼Ý100GBµÄÎļþ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß·ÖÏíµÄÆÁÄ»½ØÍ¼ÏÔʾ£¬£¬£¬£¬ÓÉXerox CorporationÖÎÀíµÄ¡° eu.xerox.net¡±ÉϵÄÖ÷»úÊܵ½Á˹¥»÷£¬£¬£¬£¬¸ÃÖ÷»úÃûºÍÓòÃûÌåÏÖÕâ¿ÉÄÜÊÇXeroxÔÚÂ׶صķֹ«Ë¾¡£¡£¡£¡£¡£¡£¡£MazeÀÕË÷Èí¼þ½üÆÚÒ»Ö±ÔÚ¹¥»÷ÖÁ¹«Ë¾£¬£¬£¬£¬¸Ã×éÖ¯Éù³Æ×î½ü¹¥»÷µÄ¹«Ë¾°üÀ¨LGµç×Ó¡¢Ð¾Æ¬ÖÆÔìÉÌMaxLinear¡¢IT¾ÞÍ·CognizantºÍÉÌҵЧÀ͹«Ë¾Conduent¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/business-giant-xerox-allegedly-suffers-maze-ransomware-attack/
4.ÐÂÀÕË÷Èí¼þEvilQuestÕë¶ÔMacϵͳ£¬£¬£¬£¬Í¨¹ýµÁ°æÈí¼þ°üÈö²¥
Çå¾²Ñо¿Ô±Dinesh Devadoss·¢Ã÷ÁËÒ»ÖÖÓÐÊýµÄÕë¶ÔmacOSµÄÐÂÐÍÀÕË÷Èí¼þEvilQuest£¬£¬£¬£¬Í¨¹ýµÁ°æÈí¼þ°üÈö²¥¡£¡£¡£¡£¡£¡£¡£EvilQuestÓâÔ½ÁËÀÕË÷Èí¼þµÄͨÀý¼ÓÃܹ¦Ð§£¬£¬£¬£¬Ëü»¹Äܹ»°²ÅżüÅ̼ͼ³ÌÐò£¬£¬£¬£¬ÒÔ¼°Äܹ»ÇÔÈ¡¼ÓÃÜÇ®±ÒÇ®°üÎļþ¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÒþ²ØÔÚµÁ°æÈí¼þÖУ¬£¬£¬£¬Ò»µ©Êܺ¦ÕßÏÂÔØÁËÕâЩ¶ñÒâ³ÌÐò£¬£¬£¬£¬Æä½«»á×°ÖÃÒ»¸öÃûΪ¡°²¹¶¡¡±µÄ¿ÉÖ´ÐÐÎļþµ½¡°/Users/Shared/¡±Ä¿Â¼ÖУ¬£¬£¬£¬È»ºó£¬£¬£¬£¬Å²Óá°eip_encrypt¡±º¯Êý¼ÓÃÜÊܺ¦ÕßµÄÎļþ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/evilquest-mac-ransomware-keylogger-crypto-wallet-stealing/157034/
5.Googleɾ³ý25¸ö¶ñÒâAndroidÓ¦Ó㬣¬£¬£¬¿ÉÇÔÈ¡Facebookƾ֤
¹È¸è±¾ÔÂ´ÓÆäÊÐËÁÖÐɾ³ýÁË25¸öÓÃÀ´ÇÔÈ¡Facebookƾ֤µÄAndroidÓ¦Ó㬣¬£¬£¬ÏÖÔÚËüÃǵÄÏÂÔØÁ¿×ܼÆÁè¼Ý234Íò´Î¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤·¨¹úÇå¾²¹«Ë¾EvinaµÄ±¨¸æ£¬£¬£¬£¬ÕâЩӦÓðüÀ¨¼Æ²½Æ÷¡¢Í¼Ïñ±à¼Æ÷¡¢ÊÓÆµ±à¼Æ÷¡¢Ç½Ö½Ó¦Óá¢ÊÖµçͲӦÓá¢ÎļþÖÎÀíÆ÷ºÍÊÖ»úÓÎÏ·¡£¡£¡£¡£¡£¡£¡£ËûÃǾùÊÇÊÇÓÉͳһºÚ¿Í×éÖ¯¿ª·¢µÄ£¬£¬£¬£¬Ö»¹Ü¹¦Ð§²î±ð£¬£¬£¬£¬µ«ÊÂÇéÔÀí¶¼ÊÇÏàͬµÄ¡£¡£¡£¡£¡£¡£¡£ËüÏȼì²âÓû§×î½ü·¿ªÁËʲôӦÓ㬣¬£¬£¬ÈôÊÇÊÇFacebook£¬£¬£¬£¬¸Ã¶ñÒâÓ¦Óý«ÔÚ¹Ù·½FacebookÓ¦ÓõĶ¥²¿ÁýÕÖÒ»¸öWebä¯ÀÀÆ÷´°¿Ú£¬£¬£¬£¬²¢¼ÓÔØ¼ÙµÄFacebookµÇÂ¼Ò³Ãæ£¬£¬£¬£¬ÓÃÀ´ÇÔÈ¡Óû§µÇ¼ƾ֤¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/google-removes-25-android-apps-caught-stealing-facebook-credentials/
6.FakeSpyð³äÓÊÕþЧÀÍÕë¶ÔÃÀ¹ú¡¢ÖйúºÍÅ·ÖÞÓû§ÇÔÈ¡²ÆÎñÐÅÏ¢
Çå¾²¹«Ë¾Cybereason·¢Ã÷£¬£¬£¬£¬ÔÚÒÑÍùµÄ¼¸ÖÜÄÚ£¬£¬£¬£¬FakeSpyÕýð³äÖÖÖÖÓÊÕþЧÀÍÀ´¹¥»÷ÃÀ¹ú¡¢ÖйúºÍÅ·ÖÞµÄÓû§£¬£¬£¬£¬ÒÔÇÔÈ¡Æä²ÆÎñÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ºÚ¿Íͨ¹ý·¢ËÍαÔìµÄ¶ÌОÙÐй¥»÷£¬£¬£¬£¬µ±Êܺ¦Õßµã»÷ÕâЩ¶ÌÐÅʱ£¬£¬£¬£¬Òþ²ØµÄ´úÂë¾Í»áÇÔÈ¡²ÆÎñÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÊÇͨ¹ý·¢ËͶÌОÙÐй¥»÷£¬£¬£¬£¬ËûÃDz»ÐèÒªÈëÇֹȸèÓÎÏ·ÊÐËÁÀ´Ö²ÈëÆä¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ºÚ¿Í»¹Í¨¹ý±àдÊÖ»ú¶ñÒâÈí¼þ¹¤¾ß°ü£¬£¬£¬£¬µ÷½â´úÂëÒÔÕë¶ÔÌìÏÂÉϲî±ðµØÇø£¬£¬£¬£¬ÒÔ×·Çó×îÓÐÀû¿ÉͼµÄ¹¥»÷·½·¨¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cyberscoop.com/fakespy-android-cybereason-postal-service/