ÎÚ¿ËÀ¼CERT-UA¼ì²âµ½Õë¶ÔÕþ¸®»ú¹¹°²×°RemcosµÄµöÓã»î¶¯

Ðû²¼Ê±¼ä 2023-02-10
1¡¢ÎÚ¿ËÀ¼CERT-UA¼ì²âµ½Õë¶ÔÕþ¸®»ú¹¹°²×°RemcosµÄµöÓã»î¶¯

      

¾ÝýÌå2ÔÂ8ÈÕ±¨µÀ£¬ÎÚ¿ËÀ¼¼ÆËã»úÓ¦¼±ÏìӦС×é(CERT-UA)·¢ÏÖÕë¶ÔÕþ¸®»ú¹¹°²×°RemcosµÄÐÂÒ»ÂÖµöÓã»î¶¯¡£ÓʼþÉù³ÆÀ´×ÔÎÚ¿ËÀ¼µçÐŹ«Ë¾Ukrtelecom£¬²¢´øÓÐÓÕ¶üRARÎĵµ¡£°üÂÞÁ½¸öÎļþÖУ¬Ò»¸öÊÇÁè¼Ý600MBµÄÊÜÃÜÂë±£»¤µÄRAR£¬ºÍÒ»¸öÓÃÓÚ´ò¿ªRARÎļþÃÜÂëµÄÎı¾Îļþ¡£RARÎĵµÖаüÂÞÒ»¸ö¿ÉÖ´ÐÐÎļþ¡°court letter, information on debt.pdf.exe¡±£¬Ö´Ðкó»á°²×°Remcos¡£CERT-UA½«¸Ã»î¶¯¹éÒòÓÚUAC-0050¡£


https://securityaffairs.com/141959/cyber-warfare-2/cert-ua-remcos-attacks.html


2¡¢RedditÔâµ½µöÓã¹¥»÷µ¼ÖÂÄÚ²¿ÎļþºÍÔ´´úÂëй¶

      

ýÌå2ÔÂ9Èճƣ¬RedditÔâµ½ÍøÂç¹¥»÷£¬ÒµÎñϵͳ±»ÈëÇÖ£¬ÄÚ²¿ÎļþºÍÔ´´úÂëй¶¡£¹¥»÷·¢ÉúÔÚÉÏÖÜÈÕÍí¼ä£¬¸Ã¹«Ë¾ÌåÏÖ£¬ºÚ¿ÍʹÓÃÁËÕë¶ÔRedditÔ±¹¤µÄÓÕ¶ü£¬ÓÃÒ»¸öµÇ½ҳÃæð³äÆäÄÚÍøÍøÕ¾£¬ÊÔͼÇÔÈ¡Ô±¹¤Æ¾Ö¤ºÍË«ÒòËØÈÏÖ¤ÁîÅÆ¡£ÔÚÀÖ³ÉÇÔÈ¡Ò»ÃûÔ±¹¤µÄƾ֤ºó£¬¹¥»÷Õß»ñµÃÁ˶ÔһЩÄÚ²¿Îĵµ¡¢´úÂëÒÔ¼°Ò»Ð©ÄÚ²¿ÏÔʾÃæ°åºÍÒµÎñϵͳµÄ·ÃÎÊȨÏÞ¡£ËäÈ»RedditûÓйûÈ»¹ØÓÚµöÓã¹¥»÷µÄÈκÎϸ½Ú£¬µ«Ìáµ½Á˵ÄÀàËÆÓÚÕë¶ÔRiot GamesµÄ¹¥»÷¡£


https://www.bleepingcomputer.com/news/security/hackers-breach-reddit-to-steal-source-code-and-internal-data/


3¡¢ºÚ¿ÍIntelBroker¹ûÈ»Weee!Ô¼110Íò¿Í»§µÄ¸öÈËÐÅÏ¢

      

2ÔÂ8ÈÕ±¨µÀ³Æ£¬ÑÇÒáºÍÎ÷°àÑÀÒáËͲͷþÎñWeee!Ô¼110Íò¿Í»§µÄ¸öÈËÐÅϢй¶¡£±¾ÖÜÒ»£¬ÃûΪIntelBrokerµÄºÚ¿ÍÔÚ°µÍøBreachedÉÏ·¢Ìû³Æ£¬2023Äê2Ô£¬SayweeeµÄ1100Íò¿Í»§µÄÊý¾Ý¿â±»µÁ¡£Weee! ÔÚÉùÃ÷ÖÐÌåÏÖ£¬´Ë´ÎʼþÓ°ÏìÁËÔÚ2021Äê7ÔÂ12ÈÕÖÁ2022Äê7ÔÂ12ÈÕÖ®¼ä϶©µ¥µÄ¿Í»§£¬µ«ÊǸ¶¿îÐÅϢûÓÐй¶¡£ËäÈ»¹¥»÷ÕßÌåÏÖÉæ¼°1100Íò¿Í»§£¬µ«Have I Been Pwned³Æй¶Êý¾Ý½ö°üÂÞ110Íò¸öΨһµÄÓʼþµØÖ·£¬ÌرðµÄ¼Ç¼ºÜ¿ÉÄÜÊÇÓÉÓÚͬһ¿Í»§ÏÂÁ˶à¸ö¶©µ¥µ¼ÖµÄ¡£


hackread.com/weee-grocery-service-hacked/


4¡¢AmerisourceBergenµÄ×Ó¹«Ë¾Ôâµ½LorenzÀÕË÷¹¥»÷

      

¾Ý2ÔÂ8ÈÕ±¨µÀ£¬Ò©Æ··ÖÏúÉÌAmerisourceBergen³ÆºÚ¿ÍÈëÇÖÁËÆä×Ó¹«Ë¾µÄITϵͳ¡£¸Ã¹«Ë¾Ðû²¼ÉùÃ÷³ÆÈëÇÖÒѱ»×èÖ¹£¬ËûÃÇÕýÔÚÊÓ²ì¸ÃʼþÊÇ·ñµ¼ÖÂÃô¸ÐÊý¾Ýй¶¡£LorenzÔÚÆäÍøÕ¾Ðû²¼Á˾ݳƴÓAmerisourceBergenºÍMWI Animal Health£¨Ô¤¼ÆÊDZ»ÈëÇÖµÄ×Ó¹«Ë¾£©ÇÔÈ¡µÄËùÓÐÎļþ¡£¹¥»÷Õß½«Ðû²¼ÈÕÆÚÉèÖÃΪ2022Äê11ÔÂ1ÈÕ£¬ËµÃ÷¼´Ê¹ÎļþÊǸոÕÐû²¼µÄ£¬µ«Î¥¹æÐÐΪ¿ÉÄÜ·¢ÉúÔÚ¼¸¸öÔÂÇ°¡£ËäȻ鶵ÄÎļþ¿´ËÆÕæʵ£¬µ«AmerisourceBergenÉÐδȷÈÏÕâЩÎļþÊÇ´ÓÆäϵͳÖÐÇÔÈ¡µÄ¡£


https://www.bleepingcomputer.com/news/security/drug-distributor-amerisourcebergen-confirms-security-breach/


5¡¢Check PointÐû²¼2022ÄêÍøÂç¹¥»÷»î¶¯µÄ»Ø¹Ë³ÂËß

      

2ÔÂ8ÈÕ£¬Check PointÐû²¼Á˹ØÓÚ2022ÄêÍøÂç¹¥»÷»î¶¯µÄ»Ø¹Ë³ÂËß¡£³ÂË߻عËÁ˶¯µ´µÄ2022Ä꣬¸ÃÄêÍøÂç¹¥»÷µ½´ïÀúÊ·×î¸ßˮƽ¡£ÓëÉÏÒ»ÄêÏà±È£¬2022ÄêµÄÍøÂç¹¥»÷Ôö¼ÓÁË38%£¬Ã¿¸ö×é֯ƽ¾ùÿÖÜÔâµ½1168´Î¹¥»÷¡£½ÌÓýºÍÑо¿ÈÔÈ»ÊÇÔâµ½¹¥»÷×î¶àµÄÐÐÒµ£¬µ«Õë¶ÔÒ½ÁƱ£½¡ÐÐÒµµÄ¹¥»÷ͬ±ÈÔö³¤ÁË74%¡£¸Ã³ÂËß»¹Ç¿µ÷Á˹æÄ£¸üС¡¢¸üÁé»îµÄºÚ¿ÍºÍÀÕË÷ÍÅ»ïÔÚÀûÓûìºÏÊÂÇ鳡ËùʹÓõĺϷ¨Ð­×÷¹¤¾ß·½ÃæËù·¢»ÓµÄ×÷Óá£


https://blog.checkpoint.com/2023/02/08/check-point-2023-security-report-cyberattacks-reach-an-all-time-high-in-response-to-geo-political-conflict-and-the-rise-of-disruption-and-destruction-malware/


6¡¢ESETÐû²¼¹ØÓÚ2022ÄêT3Íþв̬ÊƵķÖÎö³ÂËß

      

ESETÔÚ2ÔÂ8ÈÕÐû²¼¹ØÓÚ2022ÄêT3Íþв̬ÊƵķÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬Õë¶Ô̻¶µÄRDP·þÎñµÄ±©Á¦¹¥»÷ÔÚ2022Äê·ºÆðÁËÖè½µ£¬Ï½µÔ­Òò³ýÁËÕ½ÕùÍ⣬»¹¿ÉÄÜÊÇÔ¶³ÌÊÂÇéµÄ¼õÉÙ¡¢¹«Ë¾IT²¿ÃŵÄÉèÖúͶԲߵĸïÐÂÒÔ¼°Windows 11ÖÐÄÚÖõı©Á¦À¹½Ø¹¦Ð§¡£¼´Ê¹RDP¹¥»÷ÓÐËùϽµ£¬ÃÜÂëÍƲâÈÔÈ»ÊÇ2022ÄêT3×îÊÜ»¶Ó­µÄÍøÂç¹¥»÷ÔØÌå¡£ÔÚ¼ÓÃÜ»õ±ÒÇÔÈ¡·¨Ê½ºÍ¼ÓÃܿ󹤵ȴ«Í³¶ñÒâÈí¼þ¼õÉÙµÄͬʱ£¬Óë¼ÓÃÜ»õ±ÒÏà¹ØµÄÕ©Æ­ÕýÔÚÔÙÆð¡£Androidƽ̨ÉϵļäµýÈí¼þÒ²ÔÚÕâÒ»ÄêÖÐÓÐËùÔö¼Ó¡£


https://www.welivesecurity.com/2023/02/08/eset-threat-report-t3-2022/