NitroRansomwareÒªÇóʹÓÃDiscord NitroÀñÎïÖ§¸¶Êê½ð£»ÃÀ¹úÖÆ²Ã28¸öÓë¶íÂÞ˹¹¥»÷»î¶¯ÓйصļÓÃÜ»õ±ÒµØÖ·
Ðû²¼Ê±¼ä 2021-04-201.NitroRansomwareÒªÇóʹÓÃDiscord NitroÀñÎïÖ§¸¶Êê½ð
ÃûΪNitroRansomwareµÄÐÂÀÕË÷Èí¼þÒªÇóÊܺ¦ÕßʹÓÃDiscord NitroÀñÎï´úÂë×÷ΪÊê½ð¡£¸ÃÀÕË÷Èí¼þαװ³É¿ÉÒÔÉú³ÉÃâ·ÑNitroÀñÎï´úÂëµÄÓ¦Ó㬻á¼ÓÃÜÊܺ¦ÕßÎļþ²¢Ìí¼Ó.givemenitroÀ©Õ¹Ãû£¬È»ºó½«Æä×ÀÃæ¸ÄΪÉúÆøµÄDiscord±êÖ¾¡£Ö®ºó£¬ÆäÒªÇóÊܺ¦ÕßÔÚÈý¸öСʱÄÚÌṩÃâ·ÑµÄNitroÀñÎï´úÂ룬·ñÔò½«É¾³ýÊܺ¦ÕߵļÓÃÜÎļþ¡£DiscordµÄ¸½¼Ó·¨Ê½NitroÐèÿÔ»¨·Ñ9.9ÃÀÔª¶©ÔÄ£¬¹ºÖÃʱ¿ÉÒÔ×ÔÓÃÒ²¿ÉÒÔ×÷ΪÀñÎïÔùËÍËûÈË¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/discord-nitro-gift-codes-now-demanded-as-ransomware-payments/
2.ÃÀ¹úÖÆ²Ã28¸öÓë¶íÂÞ˹¹¥»÷»î¶¯ÓйصļÓÃÜ»õ±ÒµØÖ·
ÃÀ¹úÕþ¸®ÔÚ±¾ÖÜÖÆ²ÃÁË28¸ö¼ÓÃÜ»õ±ÒµØÖ·£¬¾Ý³ÆÕâЩµØÖ·ÓëÉæ¼°¶íÂÞË¹ÍøÂç¹¥»÷»ò×ÌÈÅÑ¡¾Ù»î¶¯µÄ×éÖ¯ºÍ¸öÈËÓйء£ÃÀ¹úÕþ¸®»¹ÌåÏÖ£¬ÕâЩ»î¶¯ÊÇÓɶíÂÞ˹Áª°îÄþ¾²¾Ö£¨FSB£©ºÍ¶íÂÞ˹Ö÷ÒªÇ鱨¾Ö£¨GRU£©¿ªÕ¹µÄ£¬¶øÇÒÒѾµÃµ½ÁËÁù¼ÒÓë¶íÂÞ˹ÓкÏ×÷µÄ¹«Ë¾µÄ×ÊÖú¡£´ËÍ⣬ÃûΪSESµÄ°Í»ù˹̹¹«Ë¾Ïò»¥ÁªÍøÑо¿»ú¹¹(IRA)ÌṩÐé¼ÙÉí·ÝÀ´ÌÓ±ÜÃÀ¹úµÄÖÆ²Ã£¬Æä¼ÓÃÜ»õ±ÒµØÖ·ÒÑͨ¹ý26900±Ê½»Ò×ÊÕµ½Á˼ÛÖµÁè¼Ý250ÍòÃÀÔªµÄÊý×Ö»õ±Ò¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-sanctions-cryptocurrency-addresses-linked-to-russian-cyberactivities/
3.FireEyeµÄÍŶÓÑÝʾÈçºÎÆÆ½âÓ¦Óò¢½Ù³ÖÖÇÄܵç±í
FireEyeµÄMandiantÍŶÓÑÝʾÁËÈçºÎÉøÍ¸µ½±±ÃÀµÄ¹«ÓÃÊÂÒµÍøÂç²¢ÈëÇÖÆä¹¤Òµ¿ØÖÆÏµÍ³£¬À´½Ù³ÖÆäÖÇÄܵç±í¡£ÔÚ¹¥»÷µÄµÚÒ»½×¶Î£¬MandiantÍŶӽÓÄÉÁËTEMP.VelesÔÚTRITON¹¥»÷ÆÚ¼äʹÓõļ¼ÊõÀ´ÆÆ»µOTÍøÂ硣ʵÏÖÁ˶ÔÊÂÇéÕ¾µÄ¿ØÖƺóʹÓÿªÔ´¹¥»÷ÐÔÄþ¾²¹¤¾ß£¨OST£©À´»ñµÃÓò¹ÜÀíԱȨÏÞ£¬×îºó·¢³ö¶Ï¿ªÖÇÄܵç±íµÄÃüÁî¡£¶àÄêÀ´£¬È«Çò¹¤Òµ×é֯ʹÓõÄICS/SCADAϵͳÊܵ½µÄ¹¥»÷ÊýÁ¿Ñ¸ËÙÔö¼Ó£¬ÆäÖÐ×îÑÏÖØµÄÊÇ2015ÄêÊǶÔÎÚ¿ËÀ¼µçÍøµÄ¹¥»÷ºÍ2017ÄêTriton¶ÔÉ³ÌØÊ¯»¯³§µÄ¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/117001/ics-scada/ot-network-hack-smart-meters.html
4.°ÍÎ÷¹ú¼ÒͼÊé¹ÝÁ¬ÔâÁ½´ÎÀÕË÷Èí¼þ¹¥»÷£¬Êý¾Ýй¶
°ÍÎ÷¹ú¼ÒͼÊé¹ÝÁ¬ÔâÁ½´ÎÀÕË÷Èí¼þ¹¥»÷£¬²¿ÃÅÊý¾Ýй¶¡£µÚÒ»´Î¹¥»÷·¢ÉúÔÚÖÜÈÕ£¨4ÔÂ11ÈÕ£©£¬°ÍÎ÷¹ú¼ÒͼÊé¹ÝÔÚ·¢ÏÖ¹¥»÷ºóÁ¢¼´¹Ø±ÕÁË·þÎñÆ÷£¬ÒÔ·ÀÖ¹¶ñÒâÈí¼þµÄÁ÷´«ºÍÐµĹ¥»÷¡£µ«ÊÇ£¬ÉÏÖܶþ£¨4ÔÂ13ÈÕ£©¸ÃÍøÕ¾Ôٴα»¼¤»î²¢Ôâµ½Á˵ڶþ´Î¹¥»÷£¬²¢±»¼û¸æ²¿ÃÅÊý¾ÝÒѱ»ÇÔÈ¡¡£Ä¿Ç°£¬¸ÃͼÊé¹ÝÒѽ«´ËÊÂ֪ͨÕþ¸®×éÖ¯£¬²¢ÁªºÏÄþ¾²°ì¹«ÊÒ¶Ô´ËÊÂÕ¹¿ªÁËÊӲ졣
ÔÎÄÁ´½Ó£º
https://olhardigital.com.br/en/2021/04/16/safety/national-library-website-victim-ransomware-attack/
5.McAfeeÐû²¼2020ϰëÄêÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß
McAfeeÐû²¼ÁË2020ϰëÄêÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£³ÂË߳ƣ¬2020ÄêQ4ƽ¾ùÿ·ÖÖӿɼì²âµ½648¸öÍþв£¬±ÈQ3Ôö¼ÓÁË10£¥£¬±ÈQ2Ôö³¤ÁË40£¥£¬Ê¼ÖÕ³ÊÁ¬ÐøÉÏÉýÇ÷ÊÆ¡£³ÂËß»¹Ö¸³ö2020ÄêϰëÄêÔÚÒ°Íâ·¢ÏֵĹ¥»÷ÊýÁ¿¼¤ÔöµÄÖ÷ÒªÔÒòÊÇÒÔCOVIDΪÖ÷ÌâµÄ¹¥»÷ºÍPowerShellľÂíµÄ¼¤Ôö£¬ÒÔ¼°SolarWinds©¶´ºÍSunburst¶ñÒâÈí¼þµÄÁ¬ÐøÂûÑÓ¡£Ïà±ÈÓÚQ3 £¬Q4µÄPowerShellÊýÁ¿Ôö¼ÓÁË208%£¬Õë¶ÔofficeµÄ¶ñÒâÈí¼þÊýÁ¿Ôö¼ÓÁË199%¡£
ÔÎÄÁ´½Ó£º
https://www.mcafee.com/enterprise/en-us/lp/threats-reports/apr-2021.html
6.Check PointÐû²¼2020ÄêÒÆ¶¯Äþ¾²µÄ·ÖÎö³ÂËß
Check Point ResearchÐû²¼ÁË2020ÄêÒÆ¶¯Äþ¾²µÄ·ÖÎö³ÂËß¡£¸Ã³ÂËßÊ״νÒ¶ÁËÕë¶ÔÆóÒµÒÆ¶¯É豸µÄ×îÐÂÍþв£¬´Ó¶ñÒâÓ¦Óõ½ÀÕË÷Èí¼þ¹¥»÷£¬ÒÔ¼°ÀûÓÃÆóÒµÒÆ¶¯É豸¹ÜÀíµÄ¹¥»÷¡£³ÂËßÖ¸³ö£¬2020Ä꣬97%µÄ×éÖ¯ÃæÁÙÀûÓÃÁ˶àÖÖ¹¥»÷ý½éµÄÒÆ¶¯Äþ¾²Íþв£»46%µÄ×éÖ¯ÖÐÓÐÖÁÉÙÒ»ÃûÔ±¹¤ÏÂÔØÁ˶ñÒâµÄÒÆ¶¯Ó¦Ó÷¨Ê½£»È«ÇòÖÁÉÙÓÐ40%µÄÒÆ¶¯É豸×Ô¼º¾ÍÈÝÒ×Êܵ½ÍøÂç¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://pages.checkpoint.com/mobile-security-report-2021.html