DevolutionsÐû²¼2021ÄêÖÐСÐÍÆóÒµÇå¾²Ì¬ÊÆµÄ±¨¸æ
Ðû²¼Ê±¼ä 2021-11-24RedCurlÍÅ»ï»Ø¹é£¬£¬£¬£¬£¬ÐµĹ¥»÷Ä¿µÄÉæ¼°¸÷Ðи÷Òµ
Group-IBÔÚ11ÔÂ18ÈÕÅû¶Á˺ڿÍÍÅ»ïRedCurlµÄл¡£¡£¡£¡£¡£¡£ÍøÂçÌØ¹¤ºÚ¿Í×éÖ¯RedCurlÔÚ2018ÄêÖÁ2020Äêʱ´ú£¬£¬£¬£¬£¬ÌᳫÁËÖÁÉÙ26´Î¹¥»÷£¬£¬£¬£¬£¬Éæ¼°Ó¢¹ú¡¢µÂ¹ú¡¢¼ÓÄôó¡¢Å²Íþ¡¢¶íÂÞ˹ºÍÎÚ¿ËÀ¼µÈµØÇøµÄÐÞ½¨¡¢½ðÈÚ¡¢×Éѯ¡¢ÁãÊÛ¡¢°ü¹ÜºÍÖ´·¨ÐÐÒµµÄ¹«Ë¾¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÔÚÖÐÖ¹7¸öÔºó¾íÍÁÖØÀ´£¬£¬£¬£¬£¬×Ô2021ÄêÍ·ÒÔÀ´Õë¶Ô4¼Ò¹«Ë¾ÌᳫÁËÐµĹ¥»÷£¬£¬£¬£¬£¬ÆäÖаüÀ¨¶íÂÞ˹×î´óµÄÅú·¢ÊÐËÁ¡£¡£¡£¡£¡£¡£Group-IB³Æ£¬£¬£¬£¬£¬RedCurlÔÚÿ´Î¹¥»÷Öж¼»áʹÓÃÆä×Ô½ç˵¶ñÒâÈí¼þÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.group-ib.com/media/red-curl-threat-report/
Ñо¿Ö°Ô±ÑÝʾеÄSAD DNS»º´æÖж¾¹¥»÷ģʽ
¼ÓÖÝ´óѧÑо¿Ö°Ô±ÔÚ11ÔÂ18ÈÕÑÝʾÁËÒ»ÖÖеÄSAD DNS»º´æÖж¾¹¥»÷ģʽ¡£¡£¡£¡£¡£¡£SAD DNS£¨Side channel AttackeD DNS£©ÓÚ2020Äê11ÔÂÊ×´ÎÅû¶£¬£¬£¬£¬£¬ËüÒÀÀµICMPµÄ¡°port unreachable¡±ÐÂÎÅÀ´ÍƶÏʹÓÃÄĸöÔÝʱ¶Ë¿Ú¡£¡£¡£¡£¡£¡£Ê¹Óô˹¥»÷ģʽ¿É½«¶ñÒâµÄDNS¼Í¼עÈëDNS»º´æ£¬£¬£¬£¬£¬È»ºó½«Ä¿µÄÁ÷Á¿Öض¨Ïòµ½¹¥»÷ÕßµÄЧÀÍÆ÷ÖУ¬£¬£¬£¬£¬¾ÙÐÐÖÐÐÄÈË(MITM)¹¥»÷¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬´ËÖÖ¹¥»÷±£´æÓÚLinuxÉÏÔËÐеÄBIND¡¢UnboundºÍdnsmasqµÈDNSÈí¼þÖУ¬£¬£¬£¬£¬Ó°ÏìÔ¼38%µÄÓòÃûÆÊÎöÆ÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/11/new-side-channel-attacks-re-enable.html
ÃÀ¹ú֤ȯÉúÒâίԱ»á·¢Ã÷ð³äÆäÔ±¹¤µÄ´¹Âڻ
ÃÀ¹ú֤ȯÉúÒâίԱ»á(SEC)Ͷ×ÊÕß½ÌÓýºÍÐû´«°ì¹«ÊÒ(OIEA)ÓÚ11ÔÂ19ÈÕÐû²¼¾¯±¨£¬£¬£¬£¬£¬³Æ·¢Ã÷ð³äSECÔ±¹¤µÄ»î¶¯¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýµç»°¡¢ÓïÒôÓʼþ¡¢µç×ÓÓʼþºÍÐżþ£¬£¬£¬£¬£¬ÖÒÑÔÊÕ¼þÈËÆä»îÆÚ´æ¿î»ò¼ÓÃÜÇ®±ÒµÄÕË»§Öб£´æÎ´¾ÊÚȨµÄÉúÒâ»òÆäËû¿ÉÒɻ£¬£¬£¬£¬£¬²¢Ë÷ÒªÆä¹ÉȨ¡¢Õʺš¢PINÂë¡¢ÃÜÂëµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£OIEA½¨ÒéÓû§ÔÚ·¢ËÍСÎÒ˽¼ÒÐÅϢ֮ǰ£¬£¬£¬£¬£¬Ó¦ÏÈͨ¹ýÓʼþ»òÖµçSECÈ·¶¨·¢¼þÈ˵ÄÉí·Ý¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-sec-warns-investors-of-ongoing-govt-impersonation-attacks/
ÓÌËûÖÝÒ½ÁÆÖÐÐÄUIA½ü60Íò»¼ÕßµÄСÎÒ˽¼ÒÐÅϢй¶
11ÔÂ18ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÓÌËûÖÝ·ÅÉäÖÐÐÄUtah Imaging Associates(UIA)È·ÈÏ582170»¼ÕßµÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£¡£¡£¡£Ð¹Â¶ÊÂÎñ±¬·¢ÔÚ8ÔÂ29ÈÕ£¬£¬£¬£¬£¬Êý¾ÝÔÚ̻¶ԼһÖܺ󣬣¬£¬£¬£¬ÓÚ9ÔÂ4ÈÕ±»·¢Ã÷²¢ÓÚͬÈÕÐÞ¸´¡£¡£¡£¡£¡£¡£´Ë´Îй¶ÁË»¼ÕßµÄÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂë¡¢¿µ½¡°ü¹Üµ¥ºÅºÍÒ½ÁÆÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬¹¥»÷ÕßÇãÏòÓÚ¹¥»÷ÏñUIAÕâÑùµÄÒ½ÁÆÖÐÐÄ£¬£¬£¬£¬£¬ÊÇÓÉÓÚËûÃÇÒÔΪ´ËÀàÊý¾ÝÔÚ°µÍøÖеļÛÖµ¸ü¸ß¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/utah-medical-center-hit-by-data-breach-affecting-582k-patients/
ProdaftÐû²¼¹ØÓÚÀÕË÷ÔËÓªÍÅ»ïContiµÄÆÊÎö±¨¸æ
ProdaftÓÚ11ÔÂ18ÈÕÐû²¼Á˹ØÓÚÀÕË÷ÔËÓªÍÅ»ïContiµÄÉî¶ÈÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£ContiÊÇ˽ÓÐRaaS£¬£¬£¬£¬£¬ÓÚ2019Äê12ÔÂβÊ״ηºÆð£¬£¬£¬£¬£¬²¢Í¨¹ýTrickBot¾ÙÐÐÈö²¥¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬×Ô2021Äê7ÔÂÒÔÀ´£¬£¬£¬£¬£¬Conti´ÓÊê½ðÖÐ׬ǮÖÁÉÙ2550ÍòÃÀÔª£¬£¬£¬£¬£¬¶øContiÍÅ»ïÔòÉù³ÆÒÑ׬Ǯ3ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Prodaft»¹¹ûÕæÁËContiµÄÖ§¸¶ÍøÕ¾£¬£¬£¬£¬£¬ÆäЧÀÍÆ÷ÍйÜÔÚ217.12.204.135ÉÏ£¬£¬£¬£¬£¬¸ÃIPµØµãÊôÓÚÎÚ¿ËÀ¼ÍøITL LLC¡£¡£¡£¡£¡£¡£Ôڸñ¨¸æÐû²¼¼¸Ð¡Ê±ºó£¬£¬£¬£¬£¬ContiÍÅ»ï¾Í½«ÆäÖ§¸¶ÍøÕ¾¹Ø±Õ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.prodaft.com/resource/detail/conti-ransomware-group-depth-analysis
DevolutionsÐû²¼2021ÄêÖÐСÐÍÆóÒµÇå¾²Ì¬ÊÆµÄ±¨¸æ
DevolutionsÔÚ11ÔÂ17ÈÕÐû²¼ÁË2021ÄêÖÐСÐÍÆóÒµÇå¾²Ì¬ÊÆµÄÑо¿±¨¸æ¡£¡£¡£¡£¡£¡£¸ÃÑо¿¾ÍÎå¸ö½¹µãÖ÷Ì⣺ÖÐСÆóÒµµÄÍøÂç¹¥»÷ºÍÍþв¡¢ÃÜÂëÖÎÀí¡¢Ê¹ÓõÄÌØÈ¨»á¼ûÖÎÀí¡¢Çå¾²ÅàѵºÍÖÎÀíÒÔ¼°Ç徲Ͷ×ʾÙÐÐÁËÆÊÎö¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬ÓëÈ¥ÄêÏà±È£¬£¬£¬£¬£¬72%µÄÖÐСÆóÒµÏÖÔÚÔ½·¢ÌåÌùÍøÂçÇå¾²£»£»£»£»£»£»ÖÎÀíÕß×îµ£ÐĵÄÍøÂçÍþвÊÇÀÕË÷Èí¼þ¡¢ÍøÂç´¹ÂںͶñÒâÈí¼þ£»£»£»£»£»£»52%µÄÆóÒµÔÚÈ¥ÄêÔâµ½¹ýÍøÂç¹¥»÷£»£»£»£»£»£»Ö»ÓÐ13%µÄÆóÒµÓµÓÐÍêÕûµÄPAM½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.devolutions.net/2021/11/new-now-available-devolutions-state-of-cybersecurity-in-smbs-in-2021-2022-report