°²È«»ú¹¹³ÆÊ¯Ó͹«Ë¾BapcoϰȾ¶ñÒâÈí¼þDustamn:¹È¸è´ÓPlayÉ̵êÖÐÒÆ³ýÁ˳¬¹ý1700¸öϰȾJokerµÄAPP

°ä²¼¹¦·ò 2020-01-10


1.°²È«»ú¹¹³ÆÊ¯Ó͹«Ë¾BapcoϰȾ¶ñÒâÈí¼þDustamn


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¾Ý±íýZDNet±¨Â·£¬£¬£¬£¬£¬£¬ £¬£¬°ÍÁÖ¹ú¶ÈʯÓ͹«Ë¾BapcoÔâµ½ÒÉËÆÒÁÀʺڿÍ×éÖ¯µÄÊý¾Ý²Á³ý¶ñÒâÈí¼þDustman¹¥»÷¡£¡£¡£¡£¡£¸ÃÊÂÎñ²úÉúÔÚ12ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬ £¬£¬Ö»ÓÐÒ»²¿ÃÅBapcoÍÆËã»úÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬ £¬£¬¸Ã¹«Ë¾µÄÒµÎñÔËÓª²¢Î´Öжϡ£¡£¡£¡£¡£É³Ìذ¢À­²®¹ú¶ÈÍøÂ簲ȫ¾Ö£¨CNA£©ÔÚÉÏÖܵÄÒ»·Ý°²È«¾¯±¨ÖоßÌåÃèÊöÁ˸öñÒâÈí¼þ¡£¡£¡£¡£¡£Dustman±»ÒÔΪÊÇZeroCleare²Á³ýÆ÷µÄ±äÖÖ£¬£¬£¬£¬£¬£¬ £¬£¬²¢ÇÒ¶þÕßÓëShamoon²Á³ýÆ÷ÓµÓÐÒ»ÑùµÄµÚÈý·½Çý¶¯·¨Ê½¡°Eldos RawDisk¡±¡£¡£¡£¡£¡£¹ÌÈ»DustmanÓëZeroCleareµÄ´óÎÞÊý´úÂë¶¼ÊÇÒ»ÑùµÄ£¬£¬£¬£¬£¬£¬ £¬£¬µ«É³ÌØCNA°µÊ¾¶þÕß´æÔÚÁ½¸ö³Á񻂿±ð£ºDustmanµÄ·ÛËéÖ°Äܼ°ËùÓÐÇý¶¯·¨Ê½ºÍ×°ÔØ·¨Ê½¶¼ÔÚÒ»¸ö¿ÉÖ´ÐÐÎļþÖУ¬£¬£¬£¬£¬£¬ £¬£¬¶øZeroCleareÊÇÁ½¸ö£»£»£»£»£»DustmanÖ±½Ó¸²¸Ç¾í£¬£¬£¬£¬£¬£¬ £¬£¬¶øZeroCleareͨ¹ýÓÃÀ¬»øÊý¾Ý£¨0x55£©¸²¸Ç¾íÀ´½øÐвÁ³ý¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-iranian-data-wiper-malware-hits-bapco-bahrains-national-oil-company/


2.À­Ë¹Î¬¼Ó˹ÊÐÍÆËã»úϵͳÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬ £¬£¬²¿ÃÅ·þÎñÈÔδ¸´Ô­


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


À­Ë¹Î¬¼Ó˹ÊаµÊ¾³É¹¦×èÖ¹ÁËÕë¶Ô¸ÃÊеÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£¸ÃÊÂÎñ²úÉúÔÚ1ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬ £¬£¬µ«¸ÃÊаµÊ¾ITÈËÔ±Á¢¼´¼ì²âµ½ÁËÈëÇÖ²¢²ÉÈ¡´ëÊ©±£»£»£»£»£»¤ÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£×÷ΪӦ¼±ÏìÓ¦£¬£¬£¬£¬£¬£¬ £¬£¬¸ÃÊжԲ¿ÃÅ·þÎñ½øÐÐÁËÀëÏß - Ô̺¬¸ÃÊеĹ«¹²ÍøÕ¾£¬£¬£¬£¬£¬£¬ £¬£¬µ±Ç°¸ÃÍøÕ¾ÈÔ´¦ÓڹعØ×´Ì¬¡£¡£¡£¡£¡£ÖÜÈý¸ÃÊÐÔÚTwitterÉϰ䲼ÉêÃ÷֤ʵÆä¡°¸´Ô­ÁËËùº±¼û¾ÝϵͳµÄÕý³£ÔËÓª¡±£¬£¬£¬£¬£¬£¬ £¬£¬Êе±¾Ö¹ÙÔ±ÉÐδй©ÓйØÊÂÎñÐÔÖʵÄÈκÎϸ½Ú£¬£¬£¬£¬£¬£¬ £¬£¬µ«±¾µØÃ½Ì屨·³Æ¹¥»÷ý½é¿ÉÄÜÓëµç×ÓÓʼþÓйء£¡£¡£¡£¡£¸ÃÊл¹°µÊ¾¡°ÎÒÃDz»ÒÔΪÓÐÈκÎÊý¾Ý´ÓϵͳÖÐÃÔʧ£¬£¬£¬£¬£¬£¬ £¬£¬Ò²²»ÒÔΪÓÐÈκÎÓ×ÎÒÊý¾Ý±»µÁ¡£¡£¡£¡£¡£¡±


 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/city-of-las-vegas-said-it-successfully-avoided-devastating-cyber-attack/


3.¹ú¼ÊÐ̾¯µÄ½ðÓã°¢¶û·¨Ðж¯µ¼Ö¶«ÄÏÑÇÍÚ¿ó¹¥»÷½µÂä78£¥


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÔÚ¹ú¼ÊÐ̾¯×é֯ΪÆÚ5¸öÔµĽðÓã°¢¶û·¨Ðж¯Ö®ºó£¬£¬£¬£¬£¬£¬ £¬£¬ÔÚ¶«ÃË£¨¶«ÄÏÑǹú¶ÈÁªÃË£©µØÓòµÄ¹ú¶ÈÖб»¶ñÒâ¿ó¹¤Ï°È¾µÄ·ÓÉÆ÷ÊýÁ¿½µÂäÁË78%¡£¡£¡£¡£¡£½ðÓã°¢¶û·¨Ðж¯ÓÚ2019Äê6ÔÂÆô¶¯£¬£¬£¬£¬£¬£¬ £¬£¬¸ÃÐж¯Ô®ÊÖ10¸ö¶«Ã˹ú¶È£¨ÎÄÀ³¡¢¼íÆÒÕ¯¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢ÀÏÎΡ¢ÂíÀ´Î÷ÑÇ¡¢Ãåµé¡¢·ÆÂɱö¡¢ÐÂ¼ÓÆÂ¡¢Ì©¹úºÍÔ½ÄÏ£©µÄÍøÂç·¸×ïµ÷²éÈËÔ±ºÍר¼Ò¿ÉÄܼì²âµ½ÊÜϰȾµÄ·ÓÉÆ÷£¬£¬£¬£¬£¬£¬ £¬£¬²¢ÖÒ¸æÊܺ¦Õß½¨¸´ÊÜϰȾµÄÉ豸ºÍ×èÖ¹ÍøÂç×ï·¸µÄ½Ó¼û¡£¡£¡£¡£¡£ÔÚÐж¯Ö®Ç°£¬£¬£¬£¬£¬£¬ £¬£¬¸ÃµØÓò´æÔÚ³¬¹ý2Íò¸ö±»ºÚ¿ÍÈëÇֵķÓÉÆ÷£¬£¬£¬£¬£¬£¬ £¬£¬Õ¼È«Çò¼ÓÃܽٳÖϰȾµÄ18%¡£¡£¡£¡£¡£µ±Ðж¯ÔÚ11ÔÂÏÂѮʵÏÖʱ£¬£¬£¬£¬£¬£¬ £¬£¬±»Ï°È¾µÄÉ豸ÊýÁ¿Ï÷¼õÁË78£¥¡£¡£¡£¡£¡£



 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cryptojacking-drops-by-78-percent-in-southeast-asia-after-interpol-action/


4.ÒøÐÐľÂíTrickBotÔٴθüУ¬£¬£¬£¬£¬£¬ £¬£¬Ôö³¤ºóÃÅÄ£¿£¿£¿£¿£¿éPowerTrick


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾ÝSentinelLabsÖÜËİ䲼µÄ×êÑл㱨£¬£¬£¬£¬£¬£¬ £¬£¬ÒøÐÐľÂíTrickBot±³ºóµÄ¹¥»÷ÕßÒѾ­¿ª·¢³öÁËÒ»¸öеĺóÃÅPowerTrick£¬£¬£¬£¬£¬£¬ £¬£¬Ö¼ÔÚÔ®ÊÖTrickBotÌӱܼì²â¡£¡£¡£¡£¡£ÔÚTrickBot½øÐгõʼµÄϰȾ֮ºó£¬£¬£¬£¬£¬£¬ £¬£¬Ëü½«²¿ÊðPowerTrickÄ£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬ £¬£¬PowerTrickÆÚ´ýºÍÖ´Ðй¥»÷ÕßµÄÏÂÒ»¸öºÅÁî²¢ÒÔBase64Ìåʽ·µ»ØÁ˾֡£¡£¡£¡£¡£SentinelLabs¹Û²ìµ½PowerTrickÏÂÔØÁËletmein£¨Ò»¸ö»ùÓÚPowerShellµÄ¾ç±¾£¬£¬£¬£¬£¬£¬ £¬£¬ÓÃÓÚÏνӵ½¿ªÔ´¿ª·¢¿ò¼ÜMetasploit£©£¬£¬£¬£¬£¬£¬ £¬£¬ÒÔÖ´ÐпúËŹ¤×÷ºÍ·¢ÏÔìäËüÖ¸±ê¡£¡£¡£¡£¡£³ý´ËÖ®±í£¬£¬£¬£¬£¬£¬ £¬£¬PowerTrick»¹Äܹ»·Ö·¢ÆäËüºóÃÅ£¬£¬£¬£¬£¬£¬ £¬£¬Ô̺¬TrickBot×Ô½ç˵¿ª·¢µÄAnchor Project DNS±äÌåÒÔ¼°JScriptºóÃŶñÒâÈí¼þMore_eggsµÈ¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://threatpost.com/trickbot-custom-stealthy-backdoor/151663/


5.×êÑÐÈËÔ±·¢ÏÖÕë¶Ô¹«Ë¾Õû¸öÍøÂçµÄÐÂÀÕË÷Èí¼þSNAKE


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«×êÑÐÈËÔ±¹Û²ìµ½Õë¶ÔÕû¸ö¹«Ë¾ÍøÂçµÄÐÂÀÕË÷Èí¼þSNAKE¡£¡£¡£¡£¡£Æ¾¾ÝMalwareHunterTeamºÍVitali KremezµÄ·ÖÎö£¬£¬£¬£¬£¬£¬ £¬£¬¸ÃÀÕË÷Èí¼þÊÇÓÉGolang±àдµÄ£¬£¬£¬£¬£¬£¬ £¬£¬²¢ÇÒÔ̺¬¸ß¶ÈµÄ»ìºÏ¡£¡£¡£¡£¡£Ôڳɹ¦Ï°È¾ºó£¬£¬£¬£¬£¬£¬ £¬£¬SNAKE»áɾ³ýÍÆËã»úµÄ¾íÓ°¸±±¾£¬£¬£¬£¬£¬£¬ £¬£¬¶øºóɱËÀÓëSCADAϵͳ¡¢ÍøÂçÖÎÀí½â¾ö¹æ»®¡¢Ðé¹¹»úµÈÓйصĸ÷Àà¹ý³Ì¡£¡£¡£¡£¡£ÔÚ¼ÓÃÜÎļþµÄ¹ý³ÌÖУ¬£¬£¬£¬£¬£¬ £¬£¬SNAKE»áÌø¹ý³ÁÒªµÄWindowsÎļþ¼ÐºÍϵͳÎļþ£¬£¬£¬£¬£¬£¬ £¬£¬²¢ÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó¡°EKANS¡±À©´óÃû£¬£¬£¬£¬£¬£¬ £¬£¬ÆäÀÕË÷ÐÅÏ¢ÒªÇóÊܺ¦ÕßÁªÏµ¡°bapcocrypt@ctemplar.com¡±²É°ì½âÃܹ¤¾ß¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.tripwire.com/state-of-security/security-data-protection/snake-ransomware-targeting-entire-corporate-networks/


6.¹È¸è´ÓPlayÉ̵êÖÐÒÆ³ýÁ˳¬¹ý1700¸öϰȾJokerµÄAPP


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×Ô2017ËêÊ×ÒÔÀ´£¬£¬£¬£¬£¬£¬ £¬£¬Ô¼ÓÐ1700¸öϰȾAndroid¶ñÒâÈí¼þJoker£¨Ò²±»³ÆÎªBread£©µÄ¶ñÒâÀûÓôÓPlayÉ̵êÖб»ÒƳý¡£¡£¡£¡£¡£CSIS°²È«ÍŶÓÔÚ2019Äê9Ô¾ͷ¢ÏÖÁË24¸ö´ËÀàÀûÓ㬣¬£¬£¬£¬£¬ £¬£¬ÏÂÔØ×Ü´ÎÊý³¬¹ý47.2Íò´Î¡£¡£¡£¡£¡£Joker×î³õ±»ÓÃÓÚÌáÒéSMS¶ÌÐÅڲƭ£¬£¬£¬£¬£¬£¬ £¬£¬µ«½Ïа汾µÄ±äÌåÒÑ×ªÒÆµ½¸¶·Ñ¶©ÔÄ»ò²É°ì¸÷ÀàÄÚÈݵÄÒÆ¶¯¼Æ·Ñڲƭ¡£¡£¡£¡£¡£Ëæ×Źȸ費Ðݳǫ̈ÐÂÕþ²ßºÍGoogle Play ProtectÀ©´ó·ÀÓù´ëÊ©£¬£¬£¬£¬£¬£¬ £¬£¬JokerÒ²²»ÐÝŤתսÊõѰÕÒPlayÉ̵ê·ÀÓù´ëÊ©Öеķì϶¡£¡£¡£¡£¡£¹È¸èÔÚÆëÈ«µÄ»ã±¨ÖÐÌṩÁËÓйØJokerµÄ¸ü¶à¾ßÌåÐÅÏ¢ºÍIoCÖ¸±ê¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-removed-over-17k-joker-malware-infected-apps-from-play-store/