KasperskyÔÚGoogle play·¢ÏÖ¶à¸öľÂí»¯Telegram

Ðû²¼Ê±¼ä 2023-09-12

1¡¢KasperskyÔÚGoogle play·¢ÏÖ¶à¸öľÂí»¯Telegram


KasperskyÔÚ9ÔÂ8ÈÕ³ÆÆäÔÚGoogle PlayÉÏ·¢ÏÖÁ˶à¸ö¶ñÒâ°æ±¾TelegramÓ¦Ó᣸û±»×·×ÙΪEvil Telegram £¬¶ñÒâÑù±¾µÄ°²×°Á¿Áè¼Ý60000´Î¡£ÕâЩTelegramÓ¦Óñ»Ðû´«ÎªÍ¨ÀýÓ¦Ó÷¨Ê½µÄ¡°¸ü¿ì¡±Ìæ´úÆ· £¬ËüÃÇÍâòÉÏÓëÔ­°æTelegramÏàͬ £¬µ«´úÂëÖаüÂÞÇÔÈ¡Êý¾ÝµÄ¸½¼Ó¹¦Ð§ £¬ÇÔÈ¡ID¡¢ÐÕÃûºÍµç»°µÈÐÅÏ¢¡£´ËÍâ £¬µ±Óû§Í¨¹ýľÂíÓ¦Ó÷¨Ê½ÊÕÏûϢʱ £¬¶ñÒâÈí¼þ»áÖ±½Ó½«¸±±¾·¢Ë͵½¹¥»÷ÕßµÄC2 £¬°üÂÞÏûÏ¢ÄÚÈÝ¡¢ÁÄÌì±êÌâºÍID £¬ÒÔ¼°·¢ËÍÕßÐÕÃûºÍIDµÈ £¬Ð¹Â¶µÄÊý¾ÝÔÚ´«Êäǰ»¹»á±»¼ÓÃÜ¡£Ä¿Ç° £¬GoogleÒѽ«ËùÓжñÒâÓ¦ÓôÓPlayÉ̵êÖÐɾ³ý¡£


https://securelist.com/trojanized-telegram-mod-attacking-chinese-users/110482/


2¡¢Google½ô¼±¸üÐÂÐÞ¸´ChromeÖб»ÀûÓé¶´CVE-2023-4863


¾ÝýÌå9ÔÂ11ÈÕ±¨µÀ £¬GoogleÐû²¼Á˽ô¼±Äþ¾²¸üР£¬ÐÞ¸´½ñÄêÄê³õÒÔÀ´µÚ4¸öÒѱ»ÀûÓõÄChrome©¶´£¨CVE-2023-4863£©¡£ÕâÊÇWebPÖеÄÒ»¸ö¶Ñ»º³åÇøÒç³ö©¶´ £¬ÆäÓ°Ï췶Χ´ÓÍ߽⵽ÈÎÒâ´úÂëÖ´ÐС£ËäÈ»GoogleÌåÏָé¶´ÒÑÔÚÒ°ÀûÓà £¬µ«ÔÚ´ó¶àÊýÓû§¸üÐÂ֮ǰ £¬¸Ã¹«Ë¾²»»á¹ûÈ»¹¥»÷µÄ¸ü¶àϸ½Ú¡£Citizen Lab±íÃ÷ £¬¸Ã©¶´¿ÉÄܱ»ÓÃÀ´¹¥»÷ýÌå´ÓÒµÕßµÈÖªÃûÈËÊ¿¡£Ð°汾ĿǰÕýÔÚÏòÎȶ¨°æºÍÀ©Õ¹Îȶ¨°æµÄÓû§ÍƳö £¬Ô¤¼Æ½«ÔÚδÀ´¼¸Ìì»ò¼¸ÖÜÄÚÁýÕÖÕû¸öÓû§Èº¡£


https://www.bleepingcomputer.com/news/google/google-fixes-another-chrome-zero-day-bug-exploited-in-attacks/


3¡¢TheSnakeÔÚ°µÍø¹ûÈ»Coca-Cola FEMSAµÄ²¿ÃÅÊý¾Ý


¾Ý9ÔÂ8ÈÕ±¨µÀ £¬TheSnakeÔÚºÚ¿ÍÂÛ̳ÉϹûÈ»ÁËCoca-Cola FEMSAµÄ²¿ÃÅÊý¾Ý¡£Coca-Cola FEMSAÊǿɿڿÉÀÖÔÚÀ­¶¡ÃÀÖÞ´ó²¿ÃŵØÓòµÄ×°Æ¿ÉÌ £¬¹ûÈ»µÄÊý¾Ý¹²8.16GB¡£TheSnake³Æ·ÃÎÊÁ˸ù«Ë¾Á½´Î £¬·Ö±ðÔÚ2022Äê4ÔºÍ2023Äê6Ô £¬¿ÉÒÔ·ÃÎÊÁè¼Ý200GBµÄ¹«Ë¾Êý¾Ý¡ £»¹Í¸Â¶ËûÃÇÒªÇó1200ÍòÃÀÔªÀ´É¾³ý±»µÁÎļþ £¬µ«¸Ã¹«Ë¾½»ÁË150ÍòÃÀÔª·ÀÖ¹ÌØ¶¨Îļþй¶¡£ÆäÓàÎļþÒÔ6.5ÍòÃÀÔªµÄ¼Û¸ñ³öÊÛ¡£AlphVÔøÌåÏÖ¹¥»÷Á˸ù«Ë¾²¢ÓÚ6ÔÂ10ÈÕй¶Êý¾Ý £¬Ä¿Ç°ÎÞ·¨È·¶¨Á½Õßй¶µÄÊý¾ÝÊÇ·ñÏàͬ¡£µ±±»Îʼ°´ËÊÂʱ £¬TheSnake·ñÈÏ´ÓAlphV»ñµÃÁËÈκÎÊý¾Ý £¬²¢ÌåÏÖÆäºÏ×÷»ï°éÊÇStormous¡£


https://www.databreaches.net/coca-cola-femsa-victim-of-ransomware-attack-and-data-leak/


4¡¢See TicketsÔâWeb Skimmer¹¥»÷30ÍòÈËÒøÐп¨Ð¹Â¶


ýÌå9ÔÂ7ÈÕ±¨µÀ £¬Æ±Îñ·þÎñ»ú¹¹See TicketsÒÑ֪ͨÁè¼Ý300000ÈË £¬ËûÃǵÄÖ§¸¶¿¨ÐÅÏ¢ÔÚWeb Skimmer¹¥»÷Öб»µÁ¡£5Ô·Ý £¬See TicketÒâʶµ½ÆäijЩµçÉÌÍøÕ¾ÉÏ´æÔÚÒì³ £»î¶¯¡£ÊӲ췢ÏÖ £¬5ÔºÍ6Ô £¬¹¥»÷ÕßÔÚһЩµçÉ̽áÕËÒ³ÃæÖÐ×¢ÈëÁ˶à¸ö¶ñÒâ´úÂëʵÀý¡£´Ó2ÔÂ28ÈÕµ½7ÔÂ2ÈÕ £¬ÕâЩ¶ñÒâ´úÂëÊÕ¼¯²¢ÇÔÈ¡ÁËÓû§ÔÚ½áÕËÒ³ÃæÉÏÌṩµÄÐÅÏ¢ £¬°üÂÞÐÕÃû¡¢µØÖ·ºÍÖ§¸¶¿¨ÐÅÏ¢¡£See TicketsÌåÏÖÒÑÊµÊ©ÌØ±ðµÄ´ëÊ©À´± £»¤ÆäÍøÒ³ÉϵÄÖ§¸¶¿¨ÐÅÏ¢¡£


https://www.securityweek.com/see-tickets-alerts-300000-customers-after-another-web-skimmer-attack/


5¡¢Ë¹ÀïÀ¼¿¨¹ú¼Òµç×ÓÓʼþÓòÃûÔâµ½ÀÕË÷¹¥»÷²¿ÃÅÊý¾Ý¶ªÊ§


¾Ý9ÔÂ10ÈÕ±¨µÀ £¬Ë¹ÀïÀ¼¿¨°üÂÞÄÚ¸ó°ì¹«ÊÒÔÚÄÚµÄËùÓÐʹÓá°gov.lk¡±ÓòµÄÓÊÏä¶¼¶ªÊ§ÁË5ÔÂ17ÈÕÖÁ8ÔÂ26ÈÕµÄÊý¾Ý¡£ÀÕË÷¹¥»÷·¢ÉúÓÚ8ÔÂ26ÈÕ £¬µ¼ÖÂÍøÕ¾±»¼ÓÃÜ¡£ËäÈ»ÐÅÏ¢ºÍͨÐż¼Êõ¾Ö(ICTA)ÔÚLGNÔÆÖÐά»¤Á˶à¸ö±¸·Ý £¬µ«±»ÈëÇÖ·þÎñÆ÷µÄ¼ÓÃܹý³ÌÈ´±»¸´ÖƵ½ÁËÔÚÏß±¸·ÝϵͳÖС£ÏµÍ³ÔÚ12СʱÄھͻָ´ÁË £¬±¸·ÝÒ²»Ö¸´ÁË £¬µ«¶ªÊ§Á½¸ö°ëÔµÄÊý¾Ý¡£¸ÃʼþÓ°ÏìÁËÔ¼5000¸öÓÊÏä £¬ICTA³ÆÒѾ­½ÓÄÉ´ëÊ© £¬¿ªÊ¼Ã¿ÈÕÀëÏß±¸·Ý £¬²¢½«Ïà¹ØÓ¦ÓÃÉý¼¶µ½×îа汾 £¬ÊµÑéÕһضªÊ§µÄÊý¾Ý¡£


https://srilankamirror.com/news/massive-ransomware-attack-on-state-email-domain/


6¡¢Truesec·¢ÏÖͨ¹ýTeamsÏûÏ¢·Ö·¢DarkGateµÄµöÓã¹¥»÷


9ÔÂ6ÈÕ £¬Truesec³ÆÆä·¢ÏÖÁËͨ¹ýMicrosoft TeamsÏûÏ¢·Ö·¢DarkGate LoaderµÄµöÓã¹¥»÷»î¶¯¡£¸Ã»î¶¯¿ªÊ¼ÓÚ8ÔÂÏÂÑ® £¬ÆäʱÁ½¸ö±»ÈëÇÖµÄÍⲿOffice 365ÕË»§·¢ËͰüÂÞZIPÎļþ¡°¼ÙÆÚ²¿Êð±ä»»¡±µÄMicrosoft TeamsµöÓãÓʼþ¡£µã»÷¸½¼þ»á´ÓSharePoint URLÏÂÔØZIPÎļþ £¬°üÂÞÒ»¸öαװ³ÉPDFµÄLNKÎļþ¡£Ñо¿ÈËÔ±·ÖÎö·¢ÏÖÆäÖаüÂÞ¶ñÒâVBScript £¬¿É´¥·¢Ñ¬È¾Á´ £¬²¢°²×°DarkGate Loader¡£ÎªÁËÈÆ¹ý¼ì²â £¬ÏÂÔØ¹ý³ÌÀûÓÃWindows cURL»ñÈ¡¶ñÒâÈí¼þµÄ¿ÉÖ´ÐÐÎļþºÍ½Å±¾¡£  


https://www.truesec.com/hub/blog/darkgate-loader-delivered-via-teams