жñÒâÈí¼þSilver SparrowÒÑѬȾ½ü3Íǫ̀MacÉ豸£»BitglassÐû²¼2020ÄêÒ½ÁƱ£½¡ÐÅϢй¶µÄ»Ø¹Ë³ÂËß
Ðû²¼Ê±¼ä 2021-02-231.жñÒâÈí¼þSilver SparrowÒÑѬȾ½ü3Íǫ̀MacÉ豸
Red CanaryÑо¿ÈËÔ±·¢ÏÖÕë¶ÔMacÉ豸µÄжñÒâÈí¼þSilver Sparrow¡£½ØÖÁ2ÔÂ17ÈÕ£¬Silver SparrowÒÑÔÚ153¸ö¹ú¼ÒºÍµØÓòѬȾÁË29139¸ömacOSÖÕ¶Ë£¬²¢ÔÚÃÀ¹ú¡¢Ó¢¹ú¡¢¼ÓÄô󡢷¨¹úºÍµÂ¹ú´óÁ¿Á÷´«¡£Óë´ó¶àÊýʹÓÃ'preinstall'ºÍ'postinstall'½Å±¾µÄ¶ñÒâÈí¼þ²îÒ죬Silver SparrowÀûÓÃJavaScriptÖ´ÐÐÃüÁ´Ó¶øºÜÄÑÆ¾¾ÝÃüÁîÐвÎÊý¼ì²â¶ñÒâ»î¶¯¡£´ËÍ⣬¸Ã¶ñÒâÈí¼þµÄÕæÕýÄ¿µÄÏÖÔÚÈÔÈ»ÊǸöÃÕ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/30000-macs-infected-with-new-silver-sparrow-malware/
2.BitglassÐû²¼2020ÄêÒ½ÁƱ£½¡ÐÅϢй¶µÄ»Ø¹Ë³ÂËß
BitglassÐû²¼ÁË2020ÄêÒ½ÁƱ£½¡ÐÅϢй¶µÄ»Ø¹Ë³ÂËß¡£³ÂËßÖ¸³ö£¬µ½2020Ä꣬ÃÀ¹ú¹²ÓÐ599ÆðÒ½±£Êý¾Ýй¶Ê¼þ£¬±ÈÉÏÒ»ÄêÔö³¤ÁË55.1£¥£¬Ó°ÏìÁË2640ÍòÈË¡£¾ø´ó¶àÊý£¨67£¥£©Ð¹Â¶Ê¼þ¹éÒòÓÚÀ´×ÔÍⲿ¹¥»÷Õߵġ°ºÚ¿ÍºÍITʼþ¡±£¬Æäй¶µÄÊý¾ÝÕ¼±È´ï91£¥ÒÔÉÏ¡£Æä´ÎÊǶ˵ãÉ豸µÄ¶ªÊ§»òʧÇÔ£¬Ó°ÏìÁË584000¶àÈË£¬ÒÔ¼°ÏµÍ³Î´¾ÊÚȨµØÐ¹Â¶Êý¾Ý£¬Ó°Ïì763000ÈË¡£¾¡¹ÜÊܺ¦ÈËÊý±È2019ÄêµÄ2750ÍòÈËÂÔÓÐϽµ£¬µ«Ã¿Ìõй¶Êý¾ÝµÄƽ¾ù³É±¾´Ó429ÃÀÔªÔö¼Óµ½499ÃÀÔª£¬×ܹ²Ôì³É132ÒÚÃÀÔªËðʧ¡£
ÔÎÄÁ´½Ó£º
https://www.bitglass.com/blog/hacking-and-it-incidents-on-the-rise
3.MalwarebytesÐû²¼2020Äê¶ñÒâÈí¼þÌ¬ÊÆµÄ·ÖÎö³ÂËß
MalwarebytesÐû²¼ÁË2020Äê¶ñÒâÈí¼þÌ¬ÊÆµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬WindowsÉ϶ñÒâÈí¼þµÄ¼ìÕÉÁ¿Ï½µÁË24£¥£¬ºÚ¿Í¹¤¾ßºÍ¼äµýÈí¼þµÄ¼ìÕÉÁ¿¼±¾çÔö¼Ó£¬Ôö³¤ÁË147£¥ºÍ24£¥¡£EmotetºÍTrickbot·Ö±ðϽµÁË89£¥ºÍ68£¥¡£Õë¶ÔũҵÐÐÒµµÄ¶ñÒâÈí¼þ¼ìÕÉÁ¿Ôö¼ÓÁË607£¥£¬Ê³Æ·ºÍÒûÁÏÐÐÒµµÄ¼ìÕÉÁ¿Ôö¼ÓÁË67£¥£¬ÖÆÔìÒµ¡¢Ò½ÁƱ£½¡ºÍÒ½ÁÆÒÔ¼°Æû³µµÈ¸ü´«Í³µÄÐÐÒµÖжñÒâÈí¼þµÄ¼ìÕÉÁ¿¾ùÓÐËùϽµ£¬·Ö±ðΪ17£¥¡¢22£¥ºÍ18£¥¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/reports/2021/02/state-of-malware-2021-report/
4.Ó¡¶ÈµÄ·ÀÓùϵͳÔâµ½ÈëÇÖ£¬Ä¿Ç°Õþ¸®ÉÐδ½ÓÄɵ÷Í£´ëÊ©
Ó¡¶ÈµÄ·ÀÓùϵͳÔâµ½ÃûΪSakura SamuraiµÄºÚ¿ÍµÄÈëÇÖ£¬Ä¿Ç°Õþ¸®ÉÐδ½ÓÄɵ÷Í£´ëÊ©¡£Í¨¹ý·ÖÎö·¢ÏÖ£¬Ôâµ½¹¥»÷µÄ·þÎñÆ÷Éæ¼°µ½´óÁ¿²ÆÕþ¼Ç¼±¸·Ý¡¢ÊýÊ®·Ý°üÂÞÊܺ¦ÕßÊý¾ÝµÄ¾¯·½³ÂËß¡¢¼«ÆäÃô¸ÐµÄÕþ¸®ÏµÍ³ºÍÆäËûÐÅÏ¢Êý¾Ý¿â¡£ºÚ¿Í¿ÉÒÔ»ñµÃÁè¼Ý13000¶à¸öÕþ¸®¹ÍÔ±ºÍ¹«ÃñµÄ¸öÈËÉí·ÝÐÅÏ¢£¨PII£©£¬ÒÔ¼°¿ÉÒÔ¼ì²ì¸Ã¹ú¾¯²ì¾ÖµÄ·¨Ò½³ÂËß¡¢¹¤¾ßºÍÆäËûÃô¸ÐµÄ¾¯¾Ö¼Ç¼µÄÓ¦Ó÷¨Ê½¡£Ä¿Ç°£¬¸Ã¹úÕþ¸®ÈÔδ½ÓÄɵ÷Í£´ëÊ©¡£
ÔÎÄÁ´½Ó£º
https://www.thehindu.com/sci-tech/technology/indias-cyber-defenses-breached-and-reported-govt-yet-to-fix-it/article33888110.ece
5.Tokyo Shoko³Æ2020ÄêÈÕ±¾ÓÐ2515ÍòÈËÔâÐÅϢй¶
¶«¾©ÉÌÊÂÑо¿ÓÐÏÞ¹«Ë¾£¨Tokyo Shoko Research Ltd£©³Æ2020ÄêÈÕ±¾ÓÐ2515ÍòÈËÔâÐÅϢй¶¡£¾Ý¸Ã¹«Ë¾½øÐеÄÒ»ÏîÊÓ²ìÏÔʾ£¬µ½2020Ä꣬ÈÕ±¾¹²ÓÐ88¼ÒÉÏÊй«Ë¾¼°Æä×Ó¹«Ë¾µÄ¸öÈËÐÅϢй¶»ò¶ªÊ§£¬Éæ¼°µ½2515ÍòÈË£¬ÕâÊÇ×Ô2012ÄêÒÔÀ´µÄ·åÖµ¡£¼ÆËã»ú²¡¶¾ºÍδ¾ÊÚȨµÄ·ÃÎʵ¼ÖµÄй¶Ê¼þÔ¼Õ¼×ÜÊýµÄÒ»°ë£¬Îó·¢Ë͵ç×ÓÓʼþÖ®ÀàµÄ´íÎóÔ¼Õ¼30£¥¡£ÐÅϢй¶°¸¼þ¼¤ÔöµÄ±³ºó£¬ÊÇÐí¶à¹«Ë¾¶¼ÔÚÕùÏàÍÆ¶¯Êý×Ö»¯ºÍÔ¶³ÌÊÂÇ飬µ«¿ÉÄÜÎÞ·¨½ÓÄÉ×ã¹»µÄÄþ¾²´ëÊ©¡£
ÔÎÄÁ´½Ó£º
https://www.japantimes.co.jp/news/2021/02/21/national/crime-legal/computer-viruses-big-data-cybersecurity/
6.Check Point·¢ÏÖOffice¶ñÒâÈí¼þÉú³ÉÆ÷APOMacroSploit
Check PointµÄÑо¿ÈËÔ±·¢ÏÖÁËÒ»¸öÃûΪAPOMacroSploitµÄÐÂOffice¶ñÒâÈí¼þÉú³ÉÆ÷¡£¸Ã¶ñÒâÈí¼þ¿É´´½¨ÍøÂçµöÓã¹¥»÷ËùʹÓõÄÎäÆ÷»¯ExcelÎĵµ£¬Òѱ»ÓÃÓÚÕë¶ÔÈ«Çò80¶à¸ö¿Í»§µÄ¹¥»÷ÖС£Ê¹ÓÃAPOMacroSploit builder´´½¨µÄExcelÎĵµÄܹ»Èƹýɱ¶¾Èí¼þ¡¢Windows·´¶ñÒâÈí¼þɨÃè½çÃæ(AMSI)¡¢GmailºÍÆäËûµç×ÓÓʼþµÄµöÓã¼ì²â¡£Ñо¿ÈËÔ±ÍÆ²â£¬ÆäÊÇÓÉ·¨¹úºÚ¿ÍApocaliptiqueºÍNitrix¿ª·¢µÄµÄ£¬²¢ÔÚHackForums.netÉϽøÐгöÊÛ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/114880/cyber-crime/apomacrosploit-macro-builder.html