KasperskyÔÚGoogle play·¢ÏÖ¶à¸öľÂí»¯Telegram
Ðû²¼Ê±¼ä 2023-09-121¡¢KasperskyÔÚGoogle play·¢ÏÖ¶à¸öľÂí»¯Telegram
KasperskyÔÚ9ÔÂ8ÈÕ³ÆÆäÔÚGoogle PlayÉÏ·¢ÏÖÁ˶à¸ö¶ñÒâ°æ±¾TelegramÓ¦Ó᣸û±»×·×ÙΪEvil Telegram£¬¶ñÒâÑù±¾µÄ°²×°Á¿Áè¼Ý60000´Î¡£ÕâЩTelegramÓ¦Óñ»Ðû´«ÎªÍ¨ÀýÓ¦Ó÷¨Ê½µÄ¡°¸ü¿ì¡±Ìæ´úÆ·£¬ËüÃÇÍâòÉÏÓëÔ°æTelegramÏàͬ£¬µ«´úÂëÖаüÂÞÇÔÈ¡Êý¾ÝµÄ¸½¼Ó¹¦Ð§£¬ÇÔÈ¡ID¡¢ÐÕÃûºÍµç»°µÈÐÅÏ¢¡£´ËÍ⣬µ±Óû§Í¨¹ýľÂíÓ¦Ó÷¨Ê½ÊÕÏûϢʱ£¬¶ñÒâÈí¼þ»áÖ±½Ó½«¸±±¾·¢Ë͵½¹¥»÷ÕßµÄC2£¬°üÂÞÏûÏ¢ÄÚÈÝ¡¢ÁÄÌì±êÌâºÍID£¬ÒÔ¼°·¢ËÍÕßÐÕÃûºÍIDµÈ£¬Ð¹Â¶µÄÊý¾ÝÔÚ´«Êäǰ»¹»á±»¼ÓÃÜ¡£Ä¿Ç°£¬GoogleÒѽ«ËùÓжñÒâÓ¦ÓôÓPlayÉ̵êÖÐɾ³ý¡£
https://securelist.com/trojanized-telegram-mod-attacking-chinese-users/110482/
2¡¢Google½ô¼±¸üÐÂÐÞ¸´ChromeÖб»ÀûÓé¶´CVE-2023-4863
¾ÝýÌå9ÔÂ11ÈÕ±¨µÀ£¬GoogleÐû²¼Á˽ô¼±Äþ¾²¸üУ¬ÐÞ¸´½ñÄêÄê³õÒÔÀ´µÚ4¸öÒѱ»ÀûÓõÄChrome©¶´£¨CVE-2023-4863£©¡£ÕâÊÇWebPÖеÄÒ»¸ö¶Ñ»º³åÇøÒç³ö©¶´£¬ÆäÓ°Ï췶Χ´ÓÍ߽⵽ÈÎÒâ´úÂëÖ´ÐС£ËäÈ»GoogleÌåÏָé¶´ÒÑÔÚÒ°ÀûÓ㬵«ÔÚ´ó¶àÊýÓû§¸üÐÂ֮ǰ£¬¸Ã¹«Ë¾²»»á¹ûÈ»¹¥»÷µÄ¸ü¶àϸ½Ú¡£Citizen Lab±íÃ÷£¬¸Ã©¶´¿ÉÄܱ»ÓÃÀ´¹¥»÷ýÌå´ÓÒµÕßµÈÖªÃûÈËÊ¿¡£Ð°汾ĿǰÕýÔÚÏòÎȶ¨°æºÍÀ©Õ¹Îȶ¨°æµÄÓû§ÍƳö£¬Ô¤¼Æ½«ÔÚδÀ´¼¸Ìì»ò¼¸ÖÜÄÚÁýÕÖÕû¸öÓû§Èº¡£
https://www.bleepingcomputer.com/news/google/google-fixes-another-chrome-zero-day-bug-exploited-in-attacks/
3¡¢TheSnakeÔÚ°µÍø¹ûÈ»Coca-Cola FEMSAµÄ²¿ÃÅÊý¾Ý
¾Ý9ÔÂ8ÈÕ±¨µÀ£¬TheSnakeÔÚºÚ¿ÍÂÛ̳ÉϹûÈ»ÁËCoca-Cola FEMSAµÄ²¿ÃÅÊý¾Ý¡£Coca-Cola FEMSAÊǿɿڿÉÀÖÔÚÀ¶¡ÃÀÖÞ´ó²¿ÃŵØÓòµÄ×°Æ¿ÉÌ£¬¹ûÈ»µÄÊý¾Ý¹²8.16GB¡£TheSnake³Æ·ÃÎÊÁ˸ù«Ë¾Á½´Î£¬·Ö±ðÔÚ2022Äê4ÔºÍ2023Äê6Ô£¬¿ÉÒÔ·ÃÎÊÁè¼Ý200GBµÄ¹«Ë¾Êý¾Ý¡£»¹Í¸Â¶ËûÃÇÒªÇó1200ÍòÃÀÔªÀ´É¾³ý±»µÁÎļþ£¬µ«¸Ã¹«Ë¾½»ÁË150ÍòÃÀÔª·ÀÖ¹ÌØ¶¨Îļþй¶¡£ÆäÓàÎļþÒÔ6.5ÍòÃÀÔªµÄ¼Û¸ñ³öÊÛ¡£AlphVÔøÌåÏÖ¹¥»÷Á˸ù«Ë¾²¢ÓÚ6ÔÂ10ÈÕй¶Êý¾Ý£¬Ä¿Ç°ÎÞ·¨È·¶¨Á½Õßй¶µÄÊý¾ÝÊÇ·ñÏàͬ¡£µ±±»Îʼ°´ËÊÂʱ£¬TheSnake·ñÈÏ´ÓAlphV»ñµÃÁËÈκÎÊý¾Ý£¬²¢ÌåÏÖÆäºÏ×÷»ï°éÊÇStormous¡£
https://www.databreaches.net/coca-cola-femsa-victim-of-ransomware-attack-and-data-leak/
4¡¢See TicketsÔâWeb Skimmer¹¥»÷30ÍòÈËÒøÐп¨Ð¹Â¶
ýÌå9ÔÂ7ÈÕ±¨µÀ£¬Æ±Îñ·þÎñ»ú¹¹See TicketsÒÑ֪ͨÁè¼Ý300000ÈË£¬ËûÃǵÄÖ§¸¶¿¨ÐÅÏ¢ÔÚWeb Skimmer¹¥»÷Öб»µÁ¡£5Ô·ݣ¬See TicketÒâʶµ½ÆäijЩµçÉÌÍøÕ¾ÉÏ´æÔÚÒì³£»î¶¯¡£ÊӲ췢ÏÖ£¬5ÔºÍ6Ô£¬¹¥»÷ÕßÔÚһЩµçÉ̽áÕËÒ³ÃæÖÐ×¢ÈëÁ˶à¸ö¶ñÒâ´úÂëʵÀý¡£´Ó2ÔÂ28ÈÕµ½7ÔÂ2ÈÕ£¬ÕâЩ¶ñÒâ´úÂëÊÕ¼¯²¢ÇÔÈ¡ÁËÓû§ÔÚ½áÕËÒ³ÃæÉÏÌṩµÄÐÅÏ¢£¬°üÂÞÐÕÃû¡¢µØÖ·ºÍÖ§¸¶¿¨ÐÅÏ¢¡£See TicketsÌåÏÖÒÑÊµÊ©ÌØ±ðµÄ´ëÊ©À´±£»¤ÆäÍøÒ³ÉϵÄÖ§¸¶¿¨ÐÅÏ¢¡£
https://www.securityweek.com/see-tickets-alerts-300000-customers-after-another-web-skimmer-attack/
5¡¢Ë¹ÀïÀ¼¿¨¹ú¼Òµç×ÓÓʼþÓòÃûÔâµ½ÀÕË÷¹¥»÷²¿ÃÅÊý¾Ý¶ªÊ§
¾Ý9ÔÂ10ÈÕ±¨µÀ£¬Ë¹ÀïÀ¼¿¨°üÂÞÄÚ¸ó°ì¹«ÊÒÔÚÄÚµÄËùÓÐʹÓá°gov.lk¡±ÓòµÄÓÊÏä¶¼¶ªÊ§ÁË5ÔÂ17ÈÕÖÁ8ÔÂ26ÈÕµÄÊý¾Ý¡£ÀÕË÷¹¥»÷·¢ÉúÓÚ8ÔÂ26ÈÕ£¬µ¼ÖÂÍøÕ¾±»¼ÓÃÜ¡£ËäÈ»ÐÅÏ¢ºÍͨÐż¼Êõ¾Ö(ICTA)ÔÚLGNÔÆÖÐά»¤Á˶à¸ö±¸·Ý£¬µ«±»ÈëÇÖ·þÎñÆ÷µÄ¼ÓÃܹý³ÌÈ´±»¸´ÖƵ½ÁËÔÚÏß±¸·ÝϵͳÖС£ÏµÍ³ÔÚ12СʱÄھͻָ´ÁË£¬±¸·ÝÒ²»Ö¸´ÁË£¬µ«¶ªÊ§Á½¸ö°ëÔµÄÊý¾Ý¡£¸ÃʼþÓ°ÏìÁËÔ¼5000¸öÓÊÏ䣬ICTA³ÆÒѾ½ÓÄÉ´ëÊ©£¬¿ªÊ¼Ã¿ÈÕÀëÏß±¸·Ý£¬²¢½«Ïà¹ØÓ¦ÓÃÉý¼¶µ½×îа汾£¬ÊµÑéÕһضªÊ§µÄÊý¾Ý¡£
https://srilankamirror.com/news/massive-ransomware-attack-on-state-email-domain/
6¡¢Truesec·¢ÏÖͨ¹ýTeamsÏûÏ¢·Ö·¢DarkGateµÄµöÓã¹¥»÷
9ÔÂ6ÈÕ£¬Truesec³ÆÆä·¢ÏÖÁËͨ¹ýMicrosoft TeamsÏûÏ¢·Ö·¢DarkGate LoaderµÄµöÓã¹¥»÷»î¶¯¡£¸Ã»î¶¯¿ªÊ¼ÓÚ8ÔÂÏÂÑ®£¬ÆäʱÁ½¸ö±»ÈëÇÖµÄÍⲿOffice 365ÕË»§·¢ËͰüÂÞZIPÎļþ¡°¼ÙÆÚ²¿Êð±ä»»¡±µÄMicrosoft TeamsµöÓãÓʼþ¡£µã»÷¸½¼þ»á´ÓSharePoint URLÏÂÔØZIPÎļþ£¬°üÂÞÒ»¸öαװ³ÉPDFµÄLNKÎļþ¡£Ñо¿ÈËÔ±·ÖÎö·¢ÏÖÆäÖаüÂÞ¶ñÒâVBScript£¬¿É´¥·¢Ñ¬È¾Á´£¬²¢°²×°DarkGate Loader¡£ÎªÁËÈÆ¹ý¼ì²â£¬ÏÂÔØ¹ý³ÌÀûÓÃWindows cURL»ñÈ¡¶ñÒâÈí¼þµÄ¿ÉÖ´ÐÐÎļþºÍ½Å±¾¡£
https://www.truesec.com/hub/blog/darkgate-loader-delivered-via-teams