ÃÀ¹úÊý°Ù¸öÐÂÎÅÍøÕ¾Ôâµ½¹©Ó¦Á´¹¥»÷²¢°²×°SocGholish
Ðû²¼Ê±¼ä 2022-11-04
ýÌå11ÔÂ2Èճƣ¬TA569ÍÅ»ïÀûÓÃijýÌ幫˾±»ÈëÇֵĻù´¡ÉèÊ©£¬ÔÚÃÀ¹ú250¶à¼ÒÐÂÎÅýÌåµÄÍøÕ¾Éϰ²×°SocGholish JavaScript¶ñÒâÈí¼þ¿ò¼Ü£¨Ò²³ÆÎªFakeUpdates£©¡£¹¥»÷ÕßÊ×ÏȽ«¶ñÒâ´úÂë×¢Èëµ½ÍøÕ¾¼ÓÔØµÄJavaScriptÎļþÖУ¬¸ÃÎļþ±»ÓÃÀ´°²×°SocGholish£¬Ëü½«Í¨¹ýαÔìµÄ¸üÐÂÌáÐÑ£¬°Ñ¶ñÒâÈí¼þpayloadαװ³ÉÐé¼ÙµÄä¯ÀÀÆ÷¸üÐÂÎļþ£¨ÈçChrom§Ö.U§âdat§Ö.zip¡¢ºÍFirefo§ç.U§âdat§Ö.zipµÈ£©Ñ¬È¾·ÃÎÊÍøÕ¾µÄÓû§¡£
https://www.bleepingcomputer.com/news/security/hundreds-of-us-news-sites-push-malware-in-supply-chain-attack/
2¡¢Ñо¿ÍŶӷ¢ÏÖÊýÊ®¸öÊÔͼ·Ö·¢¶ñÒâÈí¼þW4SPµÄPyPI°ü
Phylum 11ÔÂ1ÈÕ³ÆÆäÔÚPyPI×¢²á±íÖз¢ÏÖÁË29¸öPython°ü£¬ËüÃÇÄ£·ÂÁ÷ÐеĿ⣬²¢ÔÚѬȾĿ±êºó·Ö·¢ÇÔÈ¡ÐÅÏ¢µÄ¶ñÒâÈí¼þW4SP¡£PhylumÑо¿ÈËԱ͸¶£¬Æ¾¾ÝPepy.techµÄͳ¼ÆÊý¾Ý£¬ÕâЩÈí¼þ°üÒѱ»ÏÂÔØÁËÁè¼Ý5700´Î¡£´ËÍ⣬Ñо¿ÈËÔ±Hauke L¨¹bbers·¢ÏÖÁËPyPI°üpystileºÍthreadings°üÂÞ×Ô³ÆÎªGyruzPIPµÄ¶ñÒâÈí¼þ£¬¸Ã¶ñÒâÈí¼þ»ùÓÚÒ»¸ö¿ªÔ´ÏîÄ¿evil-pip¡£L¨¹bbersÒѽ«ÕâЩ°ü³ÂË߸øPyPI¹ÜÀíÔ±¡£
https://blog.phylum.io/phylum-discovers-dozens-more-pypi-packages-attempting-to-deliver-w4sp-stealer-in-ongoing-supply-chain-attack
3¡¢ÎÖ´ï·áÒâ´óÀû¹«Ë¾Åû¶Æä¾ÏúÉ̱»ºÚµ¼ÖµÄÊý¾Ýй¶Ê¼þ
¾Ý11ÔÂ2ÈÕ±¨µÀ£¬ÎÖ´ï·áÒâ´óÀû¹«Ë¾£¨Vodafone Italia£©Í¨ÖªÆä¿Í»§¹ØÓÚ¾ÏúÉÌFourB SpA±»ºÚµ¼ÖµÄÊý¾Ýй¶Ê¼þ¡£¹¥»÷·¢ÉúÔÚ9ÔµĵÚÒ»ÖÜ£¬Ð¹Â¶ÁËÓû§µÄÏêϸÐÅÏ¢£¬Èç¶©ÔÄÐÅÏ¢¡¢Éí·ÝÖ¤¼þºÍÁªÏµ·½Ê½µÈ¡£Ä¿Ç°£¬FourBÒѾ¹Ø±ÕÁ˶Ա»ÈëÇÖ·þÎñÆ÷µÄ·ÃÎÊ£¬²¢ÊµÊ©Á˸ü¸ß¼¶´ËÍâÄþ¾²¼ÆÄ±¡£2022Äê9ÔÂ3ÈÕ£¬×Ô³ÆKelvinSecurityÍÅ»ïÔøÉù³Æ¹¥»÷ÁËVodafone Italia²¢ÇÔÈ¡ÁË295000¸öÎļþ£¬×ܼÆ310 GBµÄÊý¾Ý¡£Æäʱ£¬ÎÖ´ï·á»ØÓ¦³ÆÆä¹«Ë¾ÄÚ²¿ITϵͳ²¢Î´Ô⵽δ¾ÊÚȨµÄ·ÃÎÊ£¬µ«½«¼ÌÐøÊӲ졣Éв»Çå³þ¸ÃʼþÊÇ·ñÓë´Ë´ÎÅû¶µÄй¶Ê¼þÓйء£
https://www.bleepingcomputer.com/news/security/vodafone-italy-discloses-data-breach-after-reseller-hacked/
4¡¢OPERA1ERÍÅ»ïÒÑ´ÓÒøÐк͵çÐŹ«Ë¾ÇÔÈ¡Áè¼Ý1100ÍòÃÀÔª
¾ÝGroup-IB 11ÔÂ3Èճƣ¬ºÚ¿ÍÍÅ»ïOPERA1ERÀûÓÃÏֳɵĺڿ͹¤¾ß£¬ÒÑ´ÓÒøÐк͵çÐÅ·þÎñÌṩÉÌÇÔÈ¡ÁËÖÁÉÙ1100ÍòÃÀÔª¡£³ýÁËÖ÷ÒªÕë¶Ô·ÇÖ޵Ĺ«Ë¾Í⣬¸ÃÍŻﻹ¹¥»÷Á˰¢¸ùÍ¢¡¢°ÍÀ¹çºÍÃϼÓÀ¹úµÄ×éÖ¯¡£´Ó2018Äêµ½2022Ä꣬ºÚ¿Í×ܹ²ÌᳫÁËÁè¼Ý35´ÎÀֳɵĹ¥»÷£¬ÆäÖÐÔ¼Èý·ÖÖ®Ò»ÊÇÔÚ2020Äê½øÐеġ£OPERA1ERÀûÓÃÓã²æÊ½µöÓã¹¥»÷»ñµÃ³õʼ·ÃÎÊȨÏÞ£¬Ö÷ÒªÒÀ¿¿¿ªÔ´¹¤¾ß¡¢ÉÌÆ·¶ñÒâÈí¼þÒÔ¼°MetasploitºÍCobalt StrikeµÈ¿ò¼ÜÀ´ÈëÇÖ¹«Ë¾µÄ·þÎñÆ÷¡£
https://blog.group-ib.com/opera1er-apt
5¡¢LookoutÐû²¼2022ÄêÃÀ¹úÕþ¸®»ú¹¹ÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß
11ÔÂ2ÈÕ£¬LookoutÐû²¼Á˹ØÓÚ2022ÄêÃÀ¹úÕþ¸®»ú¹¹ÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£¸Ã³ÂËß»ùÓÚ¶Ô2021ÄêÖÁ2022ÄêϰëÄêµÄ2ÒŲ́É豸ºÍ1.75ÒÚ¸öÓ¦Ó÷¨Ê½½øÐзÖÎö£¬·¢ÏÖÃÀ¹úÕþ¸®Ô±¹¤Ê¹ÓõÄAndroidÊÖ»úÖУ¬½üÒ»°ëÔËÐеÄÊǹýʱµÄ²Ù×÷ϵͳ°æ±¾¡£Õë¶ÔÒÆ¶¯Óû§×î³£¼ûµÄ¹¥»÷ÊǶñÒâÈí¼þµÄÁ÷´«£¬Ô¼Õ¼75%£¬¶øÆ¾Ö¤ÇÔÈ¡ÔòռʣÓà±ÈÀýµÄ´ó²¿ÃÅ¡£2022Ä꣬Lookout¼à¿ØµÄ11ÃûÕþ¸®Ô±¹¤ÖÐÓÐ1ÈËÔâµ½µöÓã¹¥»÷¡£ÄÇЩµã»÷¶ñÒâÁ´½Ó²¢±»¾¯¸æµÄÈËÖУ¬57%ûÓÐÔÙÖØ¸´ËûÃǵĴíÎó£¬19%µÄÈ˵ã»÷ÁËÁ½´Î£¬24%µÄÈ˵ã»÷ÁËÈý´ÎÒÔÉÏ¡£
https://www.lookout.com/form/threats-government-threat-report-lp
6¡¢Deep InstinctÐû²¼2022ÄêÖÐÆÚÍøÂçÍþÐ²Ì¬ÊÆµÄ³ÂËß
¾ÝýÌå11ÔÂ1Èճƣ¬Deep InstinctÐû²¼ÁË2022ÄêÖÐÆÚÍøÂçÍþÐ²Ì¬ÊÆµÄ³ÂËß¡£³ÂËßÖ¸³ö£¬RaaSÍÅ»ïLockBitÕ¼2022ÄêËùÓÐÀÕË÷¹¥»÷µÄ44%£¬Æä´ÎÊÇConti(23%)¡¢Hive(21%)¡¢Black Cat(7%)ºÍConti Splinters(5%)¡£Ëæ×Å΢ÈíÔÚOfficeÎļþÖÐĬÈϽûÓú꣬ʹÓÃÎĵµµÄ¶ñÒâÈí¼þ×÷ÎªÔØÌåµÄÇé¿ö¼õÉÙÁË£¬È¡¶ø´úÖ®µÄÊÇLNK¡¢HTMLºÍ´æµµµç×ÓÓʼþ¸½¼þ¡£´ËÍ⣬³ÂËß»¹Ìáµ½ÁËÏñSpoolFool¡¢FollinaºÍDirtyPipeÕâÑùµÄ©¶´Í»³öÁËWindowsºÍLinuxϵͳµÄ¿ÉÀûÓÃÐÔ£¬±íÃ÷ÿÈýµ½ËĸöÔ±»ÀûÓõÄ©¶´ÊýÁ¿¾Í»á¼¤Ôö¡£
https://www.infosecurity-magazine.com/news/lockbit-dominates-ransomware/