Ragnar LockerÍÅ»ï¹ûÈ»ADATA£¨Íþ¸Õ£©700GBÊý¾Ý£»Ñо¿ÍŶÓÔÚPyPI´æ´¢¿â·¢ÏÖ¶à¸öÓÃÓÚÍÚ¿óµÄ¶ñÒâÈí¼þ°ü
Ðû²¼Ê±¼ä 2021-06-231.Ragnar LockerÍÅ»ï¹ûÈ»ADATA£¨Íþ¸Õ£©700GBÊý¾Ý
ÀÕË÷ÍÅ»ïRagnar LockerÍÅ»ïÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¹ûÈ»Öйų́ÍåÄÚ´æºÍ´æ´¢Ð¾Æ¬ÖÆÔìÉÌADATA£¨Íþ¸Õ£©Áè¼Ý700GBµÄÊý¾Ý¡£²»¾Ãǰ£¬¸ÃÍÅ»ïÉù³Æ´ÓADATAÇÔÈ¡Á˰üÂÞ²ÆÕþÎļþ¡¢ºÏͬ¡¢±£ÃÜÐÒéµÈÆäËûÎļþÔÚÄÚµÄ1.5TBÃô¸ÐÊý¾Ý¡£´Ë´Î×ܹ²ÀûÓÃMEGA´æ´¢·þÎñ¹ûÈ»ÁË13¸öÎļþ¼Ð£¬ÆäÖÐ×î´óµÄÎļþ½Ó½ü300GB£¬µ«ÊÇÆ¾¾ÝÆäÃû³ÆÎÞ·¨È·¶¨Ëü¿ÉÄܰüÂÞµÄÄÚÈÝ¡£ÕâÊÇRagnar Locker¹ûÈ»µÄµÚ¶þÅúÓйØADATAµÄÊý¾Ý£¬ÔÚ±¾Ô³õ¸ÃÍŻﻹ¹ûÈ»ÁË4¸ö7-zip´æµµ£¬×ܹ²²»µ½250MB¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119196/cyber-crime/ragnar-locker-ransomware-adata.html
2.Ñо¿ÍŶÓÔÚPyPI´æ´¢¿â·¢ÏÖ¶à¸öÓÃÓÚÍÚ¿óµÄ¶ñÒâÈí¼þ°ü
Ñо¿ÍŶÓÔÚPythonÏîÄ¿µÄPyPI¿âÖз¢ÏÖÁË6¸ö¶ñÒâÈí¼þ°ü£¬¿ÉÒÔ½«¿ª·¢ÈËÔ±µÄ¼ÆËã»úÄð³É¿ó»ú¡£ËùÓжñÒâÈí¼þ°ü¾ùÓÉͬһÓû§¡°nedog123¡±Ðû²¼£¬·Ö±ðΪmaratlib¡¢maratlib1¡¢matplatlib-plus¡¢mllearnlib¡¢mplatlibºÍlearninglib£¬ÆäÖдó²¿ÃŵÄÃû³Æ¶¼ÊǺϷ¨»æÍ¼Èí¼þmatplotlibµÄƴд´íÎó°æ±¾£¬ºÚ¿Íͨ¹ýÕâÖÖ·½Ê½À´ÆÛÆ¿ª·¢ÈËÔ±ÏÂÔØ¡£Ñо¿ÈËÔ±³Æ¶ñÒâ´úÂë¶¼ÔÚsetup.pyÎļþÖУ¬Ëü»áÔÚGitHub´æ´¢¿âÏÂÔØBash½Å±¾(aza2.sh)£¬¸Ã½Å±¾µÄ×÷ÓÃÊÇÔÚÄ¿±ê»úÆ÷ÉÏÔËÐеļÓÃÜ¿ó¹¤Ubqminer¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/malicious-pypi-packages-hijack-dev-devices-to-mine-cryptocurrency/
3.Ñо¿ÈËÔ±·¢ÏÖеĵöÓã»î¶¯·Ö·¢Agent TeslaбäÌå
BitdefenderµÄÑо¿ÈËÔ±·¢ÏÖÐÂÒ»ÂֵĵöÓã»î¶¯·Ö·¢Agent TeslaбäÌå¡£Agent Tesla RATÒѾ´æÔÚÖÁÉÙÆßÄ꣬¾³£±»ÓÃÓÚÇÔÈ¡Óû§Æ¾¾Ý¡¢ÃÜÂëºÍÃô¸ÐÐÅÏ¢µÄÍøÂçµöÓã»î¶¯¡£´Ë´Î»î¶¯ÒÔCOVID-19ÒßÃç½ÓÖּƻ®×÷ΪÓÕ¶ü£¬¶ñÒ⸽¼þÊÇÒ»¸ö.rtfÎĵµ£¬¸ÃÎĵµÀûÓÃÁËÒÑÖªµÄMicrosoft Office©¶´(CVE-2017-11882)£¬»áÏÂÔØ²¢Ö´ÐÐAgent TeslaбäÌå¡£´ËÍ⣬´ó¶àÊý¹¥»÷ËÆºõÔ´×ÔÔ½ÄϵÄIPµØÖ·£¬¶øÇÒ50%µÄ¶ñÒâÓʼþ±»·¢Ë͵½º«¹úµÄIPµØÖ·¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/agent-tesla-covid-vax-phish/167082/
4.TorÐû²¼Äþ¾²¸üУ¬ÐÞ¸´¿É¿çä¯ÀÀÆ÷¸ú×ÙÓû§µÄ©¶´
TorÒÑÐû²¼Äþ¾²¸üУ¬ÐÞ¸´¿É¿çä¯ÀÀÆ÷¸ú×ÙÓû§µÄ©¶´¡£½ñÄê5Ô£¬Ö¸ÎÆÊ¶±ð¹«Ë¾FingerprintJSÅû¶ÁËä¯ÀÀÆ÷×Ô½ç˵ÐÒé´¦Ö÷¨Ê½Öеĺ鷺©¶´£¬¿ÉÒÔ¿çGoogle Chrome¡¢Edge¡¢Tor¡¢FirefoxºÍSafariµÈä¯ÀÀÆ÷¸ú×ÙÓû§¡£TorÏîĿͨ¹ý½«¡°network.protocol-handler.external¡±ÉèÖÃΪfalseÀ´ÐÞ¸´´Ë©¶´£¬ÕâÑùÉèÖÿÉÒÔ×èÖ¹ä¯ÀÀÆ÷½«Ìض¨URLµÄ´¦ÖÃͨ±¨¸øÍⲿӦÓ÷¨Ê½¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/tor-browser-fixes-vulnerability-that-tracks-you-using-installed-apps/
5.ÃÀ¹úLucky Star¶Ä³¡Ñ¬È¾ÀÕË÷Èí¼þ£¬ÓªÒµ³¡Ëù¹Ø±Õ
ÃÀ¹úLucky Star¶Ä³¡Ñ¬È¾ÀÕË÷Èí¼þ£¬È«¶í¿ËÀºÎÂíÖݵÄÓªÒµ³¡Ëù¹Ø±Õ¡£Lucky StarÓÚÉÏÖÜÁùÔÚÆäFacebookÉÏÐû²¼½«¹Ø±ÕÆäÔÚ¶í¿ËÀºÎÂíÖݵÄËùÓÐÓªÒµ³¡Ëù£¬Ö®ºó£¬ÓÖÓÚ±¾ÖÜÒ»ÌåÏÖ£¬ÆäÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷¡£Ä¿Ç°£¬¸Ã¶Ä³¡ÈÔÔڹرÕÖС£¸Ã¹«Ë¾ÌåÏÖËüÒѾÁªÏµÁ˰üÂÞÁª°îÊÓ²ì¾ÖÔÚÄÚµÄÖ´·¨²¿ÃŶԴËÊÂÕ¹¿ªÊӲ죬ÉÐÎÞÓйش˴ι¥»÷µÄÏêϸÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/ok-lucky-star-casino-confirmed-it-suffered-ransomware-attack/
6.Check PonitÐû²¼ÈçºÎ¼ÓǿҽÁÆ»ú¹¹µÄÄþ¾²µÄ³ÂËß
Check PonitÐû²¼ÁËÓйØÈçºÎ¼ÓǿҽÁÆ»ú¹¹µÄÎïÁªÍøÄþ¾²µÄ³ÂËß¡£¸Ã³ÂËß̽ÌÖÁËÎïÁªÍøÕýÔڸıäÒ½ÁÆÐÐÒµµÄһЩ·½Ê½£¬È»ºóÈ·¶¨Ò½ÁÆ»·¾³ÖÐÁ¬½ÓÉ豸´øÀ´µÄһЩDZÔÚÎÊÌâ¡£¾ÝÔ¤¼Æ£¬µ½2025Ä꣬ȫÇòÎïÁªÍøÊг¡½«Ôö³¤µ½5343ÒÚÃÀÔª¡£¹¥»÷Ôì³ÉµÄËðʧÊǾªÈ˵ģºÒ½ÔºÆ½¾ù»¨·Ñ430ÃÀÔªÀ´»ñȡй¶ÐÅÏ¢£¬2019ÄêÕë¶ÔÒ½ÁÆ»ú¹¹µÄÒ»´ÎÎïÁªÍø¹¥»÷µÄƽ¾ùËðʧΪ346205ÃÀÔª¡£Ò½ÁÆÐÐÒµµÄ×éÖ¯Ó¦¸Ã±£³ÖËùÓÐÉ豸µÄ¿É¼û¡¢¼°Ê±ÐÞ¸´Â©¶´ºÍÁãÐÅÈÎÍøÂç·Ö¶Î¡£
ÔÎÄÁ´½Ó£º
https://blog.checkpoint.com/2021/06/21/how-to-tighten-iot-security-for-healthcare-organization/