Sophos·¢ÏÖÕë¶ÔExchangeµÄÐÂÀÕË÷Èí¼þEpsilon Red £»Bellingcat³ÆÃÀ¹úÊ¿±øµÄѧϰӦÓÿÉй¶ºËÎäÆ÷ÐÅÏ¢

Ðû²¼Ê±¼ä 2021-05-31

1.Sophos·¢ÏÖÕë¶ÔExchangeµÄÐÂÀÕË÷Èí¼þEpsilon Red


1.jpg


Äþ¾²¹«Ë¾Sophos·¢ÏÖÐÂÀÕË÷Èí¼þEpsilon Red£¬Ö÷ÒªÕë¶ÔMicrosoft Exchange·þÎñÆ÷¡£Ñо¿ÈËÔ±ÔÚÊÓ²ìÕë¶ÔÃÀ¹úij¾ÆµêµÄ¹¥»÷»î¶¯Ê±·¢ÏֵĸöñÒâÈí¼þ¡£Epsilon RedÓÃGolang£¨Go£©±àд£¬ÓÐÒ»×éÆæÌصÄPowerShell½Å±¾£¬ÆäÖÐÿ¸ö½Å±¾¶¼ÓÐÌض¨×÷Óã¬ÈçÖÕÖ¹Äþ¾²¹¤¾ß¡¢É¾³ý¸±±¾¡¢ÇÔÈ¡Äþ¾²ÕÊ»§¹ÜÀíÆ÷£¨SAM£©ÎļþµÈ¡£Ñо¿ÈËÔ±ÌåÏÖ£¬¸ÃÍÅ»ïʹÓÃÁËREvilÊê½ð¼Ç¼µÄÄ£°å£¨¾ÀÕýÁËÆäÖеÄÓï·¨ºÍƴд´íÎ󣩣¬¶øÇÒEpsilon RedÊÇÂþÍþÖжíÂÞ˹³¬¼¶Ê¿±øµÄ½ÇÉ«Ãû£¬Òò´ËÍƶϸÃÍÅ»ïÓë¶íÂÞ˹ÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-epsilon-red-ransomware-hunts-unpatched-microsoft-exchange-servers/


2.Ñо¿ÍŶӷ¢ÏÖÒÔÎÖ¶ûÂê°ü¹üÒ쳣ΪÖ÷ÌâµÄµöÓã»î¶¯


2.jpg


Ñо¿ÍŶӷ¢ÏÖеĵöÓã»î¶¯Ã°³äÎÖ¶ûÂ곬ÊС£¸Ã»î¶¯µÄµöÓãÓʼþÒÔ¡°ÄúµÄ°ü¹üµÝËÍÒ쳣֪ͨID££¡±ÎªÖ÷Ì⣬ָ³öÓÉÓÚµØÖ·²»ÕýÈ·ÎÞ·¨Í¶µÝ°ü¹ü£¬Óû§Ðè»Ø¸´ÕýÈ·µÄµØÖ·¡£µ±Óû§µã»÷¡°¸üеØÖ·¡±Ê±£¬½«»á×Ô¶¯´´½¨Ò»¸öÖ÷ÌâΪ¡°¸üÐÂÎҵĵØÖ·£¡¡±µÄÓʼþ£¬²¢·¢Ë͵½¹¥»÷ÕßµÄÓʼþµØÖ·¡£´Ë´Î»î¶¯ÖÐÊÕ¼¯µ½µÄÐÅÏ¢¿ÉÓÃÓÚ½øÐÐÉí·ÝµÁÓù¥»÷¡¢·ÃÎÊÓû§µÄÆäËûÕÊ»§»ò½øÐÐÓÐÕë¶ÔÐÔµÄÓã²æʽÍøÂçµöÓã¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/beware-walmart-phishing-attack-says-your-package-was-not-delivered/


3.Bellingcat³ÆÃÀ¹úÊ¿±øµÄѧϰӦÓÿÉй¶ºËÎäÆ÷ÐÅÏ¢


3.jpg


Bellingcat³ÆÃÀ¹úÊ¿±øʹÓõÄÔÚÏßѧϰӦÓÿÉй¶ºËÎäÆ÷ÐÅÏ¢¡£ÂôÁ¦ÔÚÅ·ÖÞ±£¹ÜºËÎäÆ÷µÄÃÀ¹úÊ¿±øÐèÒª¼ÇÒäÅÓ´óµÄÄþ¾²Ï¸½ÚºÍЭÒ飬²¿ÃÅÏÖÒÛÈËԱʹÓÃÁ˹ûÈ»¿É¼ûµÄ³éÈÏ¿¨Ñ§Ï°Ó¦Óá£ÕâЩӦÓÃй¶ÁË»ùְλÖᢿÉÄÜ×°ÓкËÎäÆ÷¼òÖ±ÇÐλÖá¢ÉãÏñ»úµÄλÖá¢Ñ²ÂßµÄƵÂÊÉõÖÁ½ûÇøËùÐèÒªµÄΨһ±êʶ·ûµÈ¡£Bellingcat³ÆÔÚGoogleÉÏËÑË÷¡°PAS¡±ºÍ¡°WS3¡±µÈ¾üÊÂÊõÓÔÙ¼ÓÉÏÅ·ÖÞ¿Õ¾ü»ùµØµÄÃû³Æ£¬±ã¿ÉÒÔ·¢ÏÖÃâ·ÑµÄ³éÈÏ¿¨Æ½Ì¨£¬ÀýÈçChegg¡¢QuizletºÍCram¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.bellingcat.com/news/2021/05/28/us-soldiers-expose-nuclear-weapons-secrets-via-flashcard-apps/


4.Ñо¿ÈËÔ±ÑÝʾ¿É¸Ä¶¯ÒÑÈÏÖ¤µÄPDFÎĵµµÄй¥»÷·½Ê½


4.jpg


Ruhr University BochumÑо¿ÈËÔ±ÑÝʾ¿É¸Ä¶¯ÒÑÈÏÖ¤µÄPDFÎĵµµÄÁ½ÖÖÐµĹ¥»÷·½Ê½¡£ÕâÁ½ÖÖ¹¥»÷·½Ê½±»³ÆΪEvil Annotation Attack£¨EAA£©ºÍSneaky Signature Attack£¨SSA£©£¬¹¥»÷Õß¿ÉÒÔÐÞ¸ÄÎĵµÄÚÈݶø²»»áʹÆäÊý×ÖÇ©ÃûÎÞЧ¡£ÆäÖÐEAAÊÇͨ¹ý²åÈë°üÂÞ¶ñÒâ´úÂëµÄ×¢ÊÍÀ´ÐÞ¸ÄÒÑÈÏÖ¤µÄÎĵµ£¬¶øSSAÊÇͨ¹ýÏòÎĵµÖÐÌí¼ÓÁýÕÖÇ©ÃûµÄÔªËØÀ´¿ØÖÆÍâ¹Û£¬ÒÔÌîд±íµ¥×ֶΡ£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/05/researchers-demonstrate-2-new-hacks-to.html


5.¼ÓÖÝAzusa¾¯¾Ö³ÆÆäѬȾÀÕË÷Èí¼þDoppelPaymer


5.jpg


¼ÓÀû¸£ÄáÑÇÖݵÄAzusa¾¯²ì¾ÖѬȾDoppelPaymer£¬²¿ÃÅÐÅϢй¶¡£4ÔÂ22ÈÕ£¬ºÚ¿Í¹ûÈ»Á˸ò¿ÃŵÄÐÅÏ¢£¬°üÂÞ¾¯²ìµÄÊÓ²ì¼Ç¼¡¢Ñ²ÂßÈËÔ±³ÂËßÒÔ¼°²ÆÕþºÍн×ÊÏà¹ØµÄÐÅÏ¢£¬µ«¹¥»÷Õß²¢Ã»ÓбíÃ÷ËûÃÇÇÔÈ¡Á˼¸¶àÊý¾Ý¡£¸Ã²¿ÃÅÔÚ5ÔÂ28ÈÕÐû²¼ÁËÉùÃ÷£¬Ö¸³ö¹¥»÷·¢ÉúÔÚ3ÔÂ9ÈÕ£¬¾¯¾ÖµÄ²¿ÃÅϵͳÎÞ·¨·ÃÎÊ£¬Ö±µ½5ÔÂ20ÈÕÈ·¶¨Ð¹Â¶ÐÅÏ¢°üÂÞÉç»áÄþ¾²ºÅÂë¡¢¼ÓÖÝÉí·ÝÖ¤ºÅÂë¡¢¾üÊÂÉí·ÝÖ¤ºÅÂë¡¢²ÆÕþÕË»§ÐÅÏ¢ºÍͨ¹ý×Ô¶¯³µÅÆʶ±ðϵͳÊÕ¼¯µÄÐÅÏ¢µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/ca-azusa-police-reveal-ransomware-attack-in-march/


6.¿¨°Í˹»ùÐû²¼ÓйØÀÕË÷Èí¼þJSWormµÄÑݱäµÄ·ÖÎö³ÂËß


6.jpg


¿¨°Í˹»ùÐû²¼ÁËÓйØÀÕË÷Èí¼þJSWormµÄÑݱäµÄ·ÖÎö³ÂËß¡£JSWormÀÕË÷Èí¼þÔÚ2019±»·¢ÏÖ£¬´ÓÄÇÒԺ󣬷ºÆðÁËÖîÈçNemty¡¢nefilem¡¢OffwhiteµÈ²îÒìµÄ±äÖÖ¡£¸Ã¶ñÒâÈí¼þµÄ¿ª·¢ÈËÔ±Ò»Ö±ÔÚÖØбàд´úÂ룬²¢ÊµÑéʹÓòîÒìµÄ·Ö·¢ÒªÁì¡£ÔÚ2020ÄêµÄʱºò£¬¿ª·¢ÈËÔ±ÉõÖÁ½«±à³ÌÓïÑÔ´ÓC ++¸ü¸ÄΪGolang£¬²¢ÍêÈ«ÖØпªÊ¼ÖØд´úÂë¡£´Ó2019Äê´´½¨µ½2020ÄêÉÏ°ëÄ꣬JSWormµÄÁ÷´«·½Ê½°üÂÞTrik botnet¡¢RIG¿ª·¢¹¤¾ß¡¢¼ÙµÄ¸¶¿îÍøÕ¾ºÍÀ¬»øÓʼþ»î¶¯µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/evolution-of-jsworm-ransomware/102428/