NitroRansomwareÒªÇóʹÓÃDiscord NitroÀñÎïÖ§¸¶Êê½ð£»ÃÀ¹úÖÆ²Ã28¸öÓë¶íÂÞ˹¹¥»÷»î¶¯ÓйصļÓÃÜ»õ±ÒµØÖ·

Ðû²¼Ê±¼ä 2021-04-20

1.NitroRansomwareÒªÇóʹÓÃDiscord NitroÀñÎïÖ§¸¶Êê½ð


1.jpg


ÃûΪNitroRansomwareµÄÐÂÀÕË÷Èí¼þÒªÇóÊܺ¦ÕßʹÓÃDiscord NitroÀñÎï´úÂë×÷ΪÊê½ð ¡£¸ÃÀÕË÷Èí¼þαװ³É¿ÉÒÔÉú³ÉÃâ·ÑNitroÀñÎï´úÂëµÄÓ¦Óà £¬»á¼ÓÃÜÊܺ¦ÕßÎļþ²¢Ìí¼Ó.givemenitroÀ©Õ¹Ãû £¬È»ºó½«Æä×ÀÃæ¸ÄΪÉúÆøµÄDiscord±êÖ¾ ¡£Ö®ºó £¬ÆäÒªÇóÊܺ¦ÕßÔÚÈý¸öСʱÄÚÌṩÃâ·ÑµÄNitroÀñÎï´úÂë £¬·ñÔò½«É¾³ýÊܺ¦ÕߵļÓÃÜÎļþ ¡£DiscordµÄ¸½¼Ó·¨Ê½NitroÐèÿÔ»¨·Ñ9.9ÃÀÔª¶©ÔÄ £¬¹ºÖÃʱ¿ÉÒÔ×ÔÓÃÒ²¿ÉÒÔ×÷ΪÀñÎïÔùËÍËûÈË ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/discord-nitro-gift-codes-now-demanded-as-ransomware-payments/


2.ÃÀ¹úÖÆ²Ã28¸öÓë¶íÂÞ˹¹¥»÷»î¶¯ÓйصļÓÃÜ»õ±ÒµØÖ·


2.jpg


ÃÀ¹úÕþ¸®ÔÚ±¾ÖÜÖÆ²ÃÁË28¸ö¼ÓÃÜ»õ±ÒµØÖ· £¬¾Ý³ÆÕâЩµØÖ·ÓëÉæ¼°¶íÂÞË¹ÍøÂç¹¥»÷»ò×ÌÈÅÑ¡¾Ù»î¶¯µÄ×éÖ¯ºÍ¸öÈËÓйØ ¡£ÃÀ¹úÕþ¸®»¹ÌåÏÖ £¬ÕâЩ»î¶¯ÊÇÓɶíÂÞ˹Áª°îÄþ¾²¾Ö£¨FSB£©ºÍ¶íÂÞ˹Ö÷ÒªÇ鱨¾Ö£¨GRU£©¿ªÕ¹µÄ £¬¶øÇÒÒѾ­µÃµ½ÁËÁù¼ÒÓë¶íÂÞ˹ÓкÏ×÷µÄ¹«Ë¾µÄ×ÊÖú ¡£´ËÍâ £¬ÃûΪSESµÄ°Í»ù˹̹¹«Ë¾Ïò»¥ÁªÍøÑо¿»ú¹¹(IRA)ÌṩÐé¼ÙÉí·ÝÀ´ÌÓ±ÜÃÀ¹úµÄÖÆ²Ã £¬Æä¼ÓÃÜ»õ±ÒµØÖ·ÒÑͨ¹ý26900±Ê½»Ò×ÊÕµ½Á˼ÛÖµÁè¼Ý250ÍòÃÀÔªµÄÊý×Ö»õ±Ò ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-sanctions-cryptocurrency-addresses-linked-to-russian-cyberactivities/


3.FireEyeµÄÍŶÓÑÝʾÈçºÎÆÆ½âÓ¦Óò¢½Ù³ÖÖÇÄܵç±í


3.png


FireEyeµÄMandiantÍŶÓÑÝʾÁËÈçºÎÉøÍ¸µ½±±ÃÀµÄ¹«ÓÃÊÂÒµÍøÂç²¢ÈëÇÖÆä¹¤Òµ¿ØÖÆÏµÍ³ £¬À´½Ù³ÖÆäÖÇÄܵç±í ¡£ÔÚ¹¥»÷µÄµÚÒ»½×¶Î £¬MandiantÍŶӽÓÄÉÁËTEMP.VelesÔÚTRITON¹¥»÷ÆÚ¼äʹÓõļ¼ÊõÀ´ÆÆ»µOTÍøÂç ¡£ÊµÏÖÁ˶ÔÊÂÇéÕ¾µÄ¿ØÖƺóʹÓÿªÔ´¹¥»÷ÐÔÄþ¾²¹¤¾ß£¨OST£©À´»ñµÃÓò¹ÜÀíԱȨÏÞ £¬×îºó·¢³ö¶Ï¿ªÖÇÄܵç±íµÄÃüÁî ¡£¶àÄêÀ´ £¬È«Çò¹¤Òµ×é֯ʹÓõÄICS/SCADAϵͳÊܵ½µÄ¹¥»÷ÊýÁ¿Ñ¸ËÙÔö¼Ó £¬ÆäÖÐ×îÑÏÖØµÄÊÇ2015ÄêÊǶÔÎÚ¿ËÀ¼µçÍøµÄ¹¥»÷ºÍ2017ÄêTriton¶ÔÉ³ÌØÊ¯»¯³§µÄ¹¥»÷ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/117001/ics-scada/ot-network-hack-smart-meters.html


4.°ÍÎ÷¹ú¼ÒͼÊé¹ÝÁ¬ÔâÁ½´ÎÀÕË÷Èí¼þ¹¥»÷ £¬Êý¾Ýй¶


4.jpg


°ÍÎ÷¹ú¼ÒͼÊé¹ÝÁ¬ÔâÁ½´ÎÀÕË÷Èí¼þ¹¥»÷ £¬²¿ÃÅÊý¾Ýй¶ ¡£µÚÒ»´Î¹¥»÷·¢ÉúÔÚÖÜÈÕ£¨4ÔÂ11ÈÕ£© £¬°ÍÎ÷¹ú¼ÒͼÊé¹ÝÔÚ·¢ÏÖ¹¥»÷ºóÁ¢¼´¹Ø±ÕÁË·þÎñÆ÷ £¬ÒÔ·ÀÖ¹¶ñÒâÈí¼þµÄÁ÷´«ºÍÐµĹ¥»÷ ¡£µ«ÊÇ £¬ÉÏÖܶþ£¨4ÔÂ13ÈÕ£©¸ÃÍøÕ¾Ôٴα»¼¤»î²¢Ôâµ½Á˵ڶþ´Î¹¥»÷ £¬²¢±»¼û¸æ²¿ÃÅÊý¾ÝÒѱ»ÇÔÈ¡ ¡£Ä¿Ç° £¬¸ÃͼÊé¹ÝÒѽ«´ËÊÂ֪ͨÕþ¸®×éÖ¯ £¬²¢ÁªºÏÄþ¾²°ì¹«ÊÒ¶Ô´ËÊÂÕ¹¿ªÁËÊÓ²ì ¡£


Ô­ÎÄÁ´½Ó£º

https://olhardigital.com.br/en/2021/04/16/safety/national-library-website-victim-ransomware-attack/


5.McAfeeÐû²¼2020ϰëÄêÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß


5.jpg


McAfeeÐû²¼ÁË2020ϰëÄêÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß ¡£³ÂËß³Æ £¬2020ÄêQ4ƽ¾ùÿ·ÖÖӿɼì²âµ½648¸öÍþв £¬±ÈQ3Ôö¼ÓÁË10£¥ £¬±ÈQ2Ôö³¤ÁË40£¥ £¬Ê¼ÖÕ³ÊÁ¬ÐøÉÏÉýÇ÷ÊÆ ¡£³ÂËß»¹Ö¸³ö2020ÄêϰëÄêÔÚÒ°Íâ·¢ÏֵĹ¥»÷ÊýÁ¿¼¤ÔöµÄÖ÷ÒªÔ­ÒòÊÇÒÔCOVIDΪÖ÷ÌâµÄ¹¥»÷ºÍPowerShellľÂíµÄ¼¤Ôö £¬ÒÔ¼°SolarWinds©¶´ºÍSunburst¶ñÒâÈí¼þµÄÁ¬ÐøÂûÑÓ ¡£Ïà±ÈÓÚQ3 £¬Q4µÄPowerShellÊýÁ¿Ôö¼ÓÁË208% £¬Õë¶ÔofficeµÄ¶ñÒâÈí¼þÊýÁ¿Ôö¼ÓÁË199% ¡£


Ô­ÎÄÁ´½Ó£º

https://www.mcafee.com/enterprise/en-us/lp/threats-reports/apr-2021.html


6.Check PointÐû²¼2020ÄêÒÆ¶¯Äþ¾²µÄ·ÖÎö³ÂËß


6.jpg


Check Point ResearchÐû²¼ÁË2020ÄêÒÆ¶¯Äþ¾²µÄ·ÖÎö³ÂËß ¡£¸Ã³ÂËßÊ״νÒ¶ÁËÕë¶ÔÆóÒµÒÆ¶¯É豸µÄ×îÐÂÍþв £¬´Ó¶ñÒâÓ¦Óõ½ÀÕË÷Èí¼þ¹¥»÷ £¬ÒÔ¼°ÀûÓÃÆóÒµÒÆ¶¯É豸¹ÜÀíµÄ¹¥»÷ ¡£³ÂËßÖ¸³ö £¬2020Äê £¬97%µÄ×éÖ¯ÃæÁÙÀûÓÃÁ˶àÖÖ¹¥»÷ý½éµÄÒÆ¶¯Äþ¾²Íþв£»46%µÄ×éÖ¯ÖÐÓÐÖÁÉÙÒ»ÃûÔ±¹¤ÏÂÔØÁ˶ñÒâµÄÒÆ¶¯Ó¦Ó÷¨Ê½£»È«ÇòÖÁÉÙÓÐ40%µÄÒÆ¶¯É豸×Ô¼º¾ÍÈÝÒ×Êܵ½ÍøÂç¹¥»÷ ¡£


Ô­ÎÄÁ´½Ó£º

https://pages.checkpoint.com/mobile-security-report-2021.html