ÃÀ¹úÕþ¸®Ðû²¼ÁªºÏÖÒÑÔ£ºBlackMatterÀÕË÷Èí¼þÕý¶ÔÃÀ¹ú»ù´¡ÉèÊ©Ìᳫ¹¥»÷
Ðû²¼Ê±¼ä 2021-10-21Symantec·¢Ã÷HarvesterÕë¶ÔÄÏÑǵçÐÅÐÐÒµµÄ¹¥»÷»î¶¯

SymantecÔÚ10ÔÂ18ÈÕÅû¶ÁËÒ»¸öеÄÓɹú¼ÒÖ§³ÖµÄºÚ¿ÍÍÅ»ïHarvesterµÄ¹¥»÷»î¶¯¡£¡£¡£´Ë´Î¹¥»÷»î¶¯Ãé×¼ÁËÄÏÑǵÄ×éÖ¯£¬£¬£¬£¬£¬£¬£¬ÌØÊâÊǰ¢¸»º¹£¬£¬£¬£¬£¬£¬£¬Õë¶ÔµçÐźÍITÐÐÒµµÄ¹«Ë¾ÒÔ¼°¹Ù·½×éÖ¯£¬£¬£¬£¬£¬£¬£¬×îÏÈÓÚ2021Äê6Ô£¬£¬£¬£¬£¬£¬£¬×î½üÒ»´Î»î¶¯±¬·¢ÔÚ2021Äê10Ô¡£¡£¡£ÔÚÊÖÒÕ·½Ã棬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÄ¿µÄÖÐ×°ÖÃÁËÒ»¸öÃûΪBackdoor.GraphonµÄ×Ô½ç˵ºóÃÅ£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÆäËû×Ô½ç˵ÏÂÔØÆ÷ºÍ½ØÍ¼¹¤¾ß¡£¡£¡£ÏÖÔÚÉв»ÇåÎú³õʼѬȾǰÑÔÊÇʲô£¬£¬£¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±ÔÚ±»ºÚ×°±¸ÉÏ·¢Ã÷µÄµÚÒ»¸ö¹ØÓڴ˴λµÄÖ¤¾ÝÊǶñÒâURL¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/harvester-new-apt-attacks-asia
DesordenÉù³ÆÒÑÈëÇÖºê»ùAcerÔÚÖйų́ÍåµÄЧÀÍÆ÷

ÉÏÖÜ£¬£¬£¬£¬£¬£¬£¬DesordenÈëÇÖÁ˺ê»ù£¨Acer£©Ó¡¶ÈµÄЧÀÍÆ÷²¢ÇÔÈ¡ÁËÆäÖеÄÊý¾Ý¡£¡£¡£²»µ½Ò»Öܺ󣬣¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïÓÖ³ÆËûÃÇÔÚ10ÔÂ15ÈÕÈëÇÖÁ˺ê»ų̀ÍåµÄЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬²¢¹ûÕæÁ˸ù«Ë¾ÄÚ²¿ÍøÕ¾µÄͼƬºÍÔ±¹¤µÇ¼ƾ֤µÄCSVÎļþ¡£¡£¡£DesordenÌåÏÖËûÃǴ˴εĹ¥»÷ÊÇΪÁË֤ʵºê»ùÈÔÈ»±£´æÎó²î£¬£¬£¬£¬£¬£¬£¬²¢Ö¸³ö¸Ã¹«Ë¾ÔÚÂíÀ´Î÷ÑǺÍÓ¡¶ÈÄáÎ÷ÑǵÄϵͳҲÈÝÒ×Êܵ½¹¥»÷¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬ºê³žÌ¨ÍåÒѾ¹Ø±ÕÁ˱»ºÚµÄϵͳ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/acer-hacked-twice-in-a-week-by-the-same-threat-actor/
ºÚ¿ÍÍÅ»ïTeamTNTʹÓöñÒâDocke¾µÏñ·Ö·¢ÍÚ¿óÈí¼þ

UptycsÑо¿ÍŶÓÔÚ10ÔÂ18ÈÕ¹ûÕæÁËTeamTNTÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£¡£¡£Ôڴ˴λÖУ¬£¬£¬£¬£¬£¬£¬TeamTNTʹÓÃÁ˶ñÒâDocke¾µÏñ£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃǶÈëʽ¾ç±¾ÏÂÔØÉ¨ÃèÆ÷ZgrabºÍÉøÍ¸²âÊÔ¹¤¾ßmasscannerÀ´ÌáÈ¡bannerºÍ¶Ë¿ÚɨÃ裬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ·Ö·¢¶ñÒâcoinminerÀ´Ð®ÖÆÄ¿µÄµÄÅÌËã×ÊÔ´Íڿ󡣡£¡£¸Ã¾µÏñÍйÜÔÚÃûΪDocker HubÉÏ£¬£¬£¬£¬£¬£¬£¬ÃûΪalpineos£¬£¬£¬£¬£¬£¬£¬¸ÃÓû§ÓÚ2021Äê5ÔÂ26ÈÕ¼ÓÈëDocker Hub£¬£¬£¬£¬£¬£¬£¬×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬alpineosÉèÖÃÎļþÍйÜÁË25¸öDockerÓ³Ïñ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/123535/cyber-crime/teamtnt-docker-attack.html
Ñо¿Ö°Ô±·¢Ã÷LyceumÍÅ»ïÕë¶ÔÍ»Äá˹µÄ¹¥»÷»î¶¯

KasperskyµÄÑо¿Ö°Ô±ÓÚ10ÔÂ18ÈÕÐû²¼±¨¸æ£¬£¬£¬£¬£¬£¬£¬ÏÈÈÝÁËLyceumÍÅ»ïÕë¶ÔÍ»Äá˹µÄ¹¥»÷»î¶¯¡£¡£¡£Lyceum£¨ÓÖÃûHexane£©ÓÚ2019ÄêÊ״α»SecureworksÆØ¹â£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÖж«µÄÄÜÔ´ºÍµçÐÅÐÐÒµ¡£¡£¡£´Ë´Î¹¥»÷µÄÄ¿µÄ¾ùÊÇÍ»Äá˹µÄ×ÅÃû¹«Ë¾£¬£¬£¬£¬£¬£¬£¬ÈçµçÐÅ»òº½¿Õ¹«Ë¾¡£¡£¡£¹¥»÷ÕßʹÓÃÁËÁ½¸öÓÃC++±àдµÄжñÒâÈí¼þJamesºÍKevin£¬£¬£¬£¬£¬£¬£¬ËäÈ»JamesÔںܺéÁ÷ƽÉÏÈÔ»ùÓÚ¶ñÒâÈí¼þDanBot£¬£¬£¬£¬£¬£¬£¬µ«KevinÔڼܹ¹ºÍͨѶÐÒé·½Ãæ×ö³öÁËÖØ´ó¸Ä±ä¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/lyceum-group-reborn/104586/
Çå¾²¹«Ë¾TrustwaveÐû²¼ÀÕË÷Èí¼þBlackByteµÄ½âÃÜÆ÷

Çå¾²¹«Ë¾TrustwaveµÄÑо¿ÍŶÓSpiderLabsÔÚGitHubÉÏÐû²¼ÁËÀÕË÷Èí¼þBlackByteµÄ½âÃÜÆ÷¡£¡£¡£Æ¾Ö¤¶ÔÀÕË÷Èí¼þµÄÆÊÎöÅú×¢£¬£¬£¬£¬£¬£¬£¬BlackByteʹÓÃÁËÏàͬµÄÔʼÃÜÔ¿À´¼ÓÃÜÎļþ£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓöԳÆÃÜÔ¿Ëã·¨AES£¬£¬£¬£¬£¬£¬£¬Òò´ËÈκξßÓÐÔʼÃÜÔ¿µÄÈ˶¼¿ÉÒÔ½âÃÜÎļþ¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÀÕË÷Èí¼þʹÓÃÒ»¸öǶÈëÁ˶à¸öÃÜÔ¿.PNGÎļþ£¬£¬£¬£¬£¬£¬£¬Í¨Ì«¹ýÎö¸ÃÎļþ¿ª·¢ÁËÃâ·ÑµÄ½âÃÜÆ÷¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/blackbyte-ransomware-decryptor-released/
CISA¡¢FBIºÍNSAÐû²¼BlackMatterµÄÔ¤¾¯Í¨¸æ

10ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬£¬CISA¡¢FBIºÍNSAÐû²¼ÁËÀÕË÷Èí¼þBlackMatterµÄÁªºÏÍøÂçÇå¾²×Éѯ (CSA)¡£¡£¡£×Ô½ñÄê7ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þBlackMatterÒѹ¥»÷ÁËÃÀ¹úµÄ¶à¸öÓëÒªº¦»ù´¡ÉèÊ©Ïà¹ØµÄ¹«Ë¾£¬£¬£¬£¬£¬£¬£¬ÀýÈçʳÎïºÍũҵÐÐÒµ¡£¡£¡£¸ÃCSAÆÊÎöÁËBlackMatterµÄÑù±¾²¢Á¬ÏµÁËÀ´×ÔµÚÈý·½µÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÌṩÁ˹¥»÷ÕßµÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐò£¬£¬£¬£¬£¬£¬£¬²¢¸ÅÊö»º½â²½·¥£¬£¬£¬£¬£¬£¬£¬ÒÔ×ÊÖú×é֯ˢÐÂÕë¶Ô´ËÀ๥»÷µÄ±£»£»£»£»£»¤¡¢¼ì²âºÍÏìÓ¦²½·¥¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2021/10/18/cisa-fbi-and-nsa-release-joint-cybersecurity-advisory-blackmatter


¾©¹«Íø°²±¸11010802024551ºÅ