ESTsecurityÅû¶ThalliumÕë¶Ô½ðÈÚÐÐÒµµÄ¹©¸øÁ´¹¥»÷£»£»£»£»£»£»£»NISSAN±±ÃÀ·Ö¹«Ë¾ÒòGit·þÎñÆ÷ÅäÖÃÃýÎóµ¼ÖÂÔ´´úÂëй¶

°ä²¼¹¦·ò 2021-01-07

1.ESTsecurityÅû¶ThalliumÕë¶Ô½ðÈÚÐÐÒµµÄ¹©¸øÁ´¹¥»÷


1.jpg


ESTsecurityÅû¶APT×éÖ¯Thallium£¨±ðÃûAPT37£©Õë¶Ô½ðÈÚÐÐÒµµÄ¹©¸øÁ´¹¥»÷¡£¡£ ¡£¡£¡£ÔÚÕâ´Î¹¥»÷»î¶¯ÖУ¬£¬£¬£¬ £¬ºÚ¿Í´Û¸ÄÁËÒ»¿î¸öÈË¹ÉÆ±Í¶×ÊÐÅÏ¢´«µÝµÄÀûÓ㬣¬£¬£¬ £¬ÒÔ·Ö·¢¶ñÒâ´úÂë¡£¡£ ¡£¡£¡£ThalliumÊ×ÏÈʹÓÃNullsoft¾ç±¾×°ÖÃϵͳ£¨NSIS£©ÌìÉúWindows¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬ £¬¸ÃÎļþÔ̺¬ÁËÀ´×ԺϷ¨¹ÉƱͶ×ÊÀûÓ÷¨Ê½µÄºÏ·¨ÎļþºÍ¶ñÒâ´úÂë¡£¡£ ¡£¡£¡£µ±Óû§ÔÚ×°ÖÃÕæÕýµÄ¹ÉƱͶ×ÊÀûÓ÷¨Ê½Ê±£¬£¬£¬£¬ £¬ºó¶ÜͬʱÔËÐжñÒâ¾ç±¾¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/north-korean-software-supply-chain-attack-targets-stock-investors/


2.Intezer·¢ÏÖElectroRAT²ØÓÚαÔìµÄ¼ÓÃÜÇ®±ÒÀûÓÃ


2.jpg


Intezer Labs·¢ÏÖElectroRAT²ØÓÚαÔìµÄ¼ÓÃÜÇ®±ÒÀûÓᣡ£ ¡£¡£¡£¸Ã»î¶¯ÔçÔÚ2020Äê1ÔÂ8ÈÕ¾ÍÆðÍ·»îÔ¾£¬£¬£¬£¬ £¬µ«ÊÇÔÚ2020Äê12Ô²ű»·¢ÏÖ¡£¡£ ¡£¡£¡£ºÚ¿ÍÖØÒªÒÀÀµÓÚÈý¸öÓë¼ÓÃÜÇ®±ÒÓйصÄÀûÓÃJamm¡¢eTrade/KintumºÍDaoPokerÀ´·Ö·¢¶ñÒâÈí¼þElectroRAT¡£¡£ ¡£¡£¡£ElectroRATÓµÓм«Ç¿µÄÇÖÈëÐÔ£¬£¬£¬£¬ £¬ÓµÓмüÅ̼ͼ¡¢½ØÍ¼¡¢ÉÏ´«Îļþ¡¢ÏÂÔØÎļþÒÔ¼°ÔÚÖ¸±ê½ÚÔį̀ÉÏÖ´ÐкÅÁîµÈÖ°ÄÜ£¬£¬£¬£¬ £¬Ä¿Ç°¿ÉÄÜÒѾ­Ï°È¾ÁËԼĪ6500¸öÓû§¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hackers-target-cryptocurrency-users-with-new-electrorat-malware/


3.°Äµ±¾ÖÖҸ淸×ïÍÅ»ï¼ÙÒâÆäÍøÂ簲ȫÖÐÐÄ·Ö·¢¶ñÒâÈí¼þ


3.png


°Ä´óÀûÑǵ±¾ÖÖÒ¸æ³Æ£¬£¬£¬£¬ £¬·¸×ïÍÅ»ï¼ÙÒâ°Ä´óÀûÑÇÍøÂ簲ȫÖÐÐÄ£¨ACSC£©·Ö·¢¶ñÒâÈí¼þ¡£¡£ ¡£¡£¡£¸ÃÍÅ»ïÓÕʹÊܺ¦Õß×°ÖÃÔ¶³ÌÖÎÀíºÍ×ÀÃæ¹²ÏíÈí¼þ£¬£¬£¬£¬ £¬Ö¼ÔÚÇÔȡָ±êÓû§µÄÒøÐÐÐÅÏ¢¡£¡£ ¡£¡£¡£ÆäÊ×ÏÈÀûÓüÙ×°³ÉACSC¹Ù·½ÐÂÎŵĵç×ÓÓʼþ£¬£¬£¬£¬ £¬·î¸æÊܺ¦ÕßµçÄÔÒѾ­±»ÈëÇÖ£¬£¬£¬£¬ £¬±ØÒªÍ¨¹ý¶ñÒâÁ´½ÓÏÂÔØ¼ÙµÄɱ¶¾Èí¼þ¡£¡£ ¡£¡£¡£Ò»µ©Óû§ÏÂÔØ²¢Æô¶¯ºó£¬£¬£¬£¬ £¬¸Ã¶ñÒâÈí¼þ¾Í¿ÉÄÜÊÕÊÜÆäÍÆËã»ú²¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£ ¡£¡£¡£³ý´ËÖ®±í£¬£¬£¬£¬ £¬¸ÃÍŻﻹ»áÀûÓÃαÔìµÄµç»°ºÅÂë¸øÊܺ¦Õß´òµç»°£¬£¬£¬£¬ £¬ÒªÇóËûÃÇÏÂÔØTeamViewer»òAnyDeskÀûÓ㬣¬£¬£¬ £¬ÒÔ·Ö·¢¶ñÒâÈí¼þ¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/australian-cybersecurity-agency-used-as-cover-in-malware-campaign/


4.Check Point°ä²¼Õë¶ÔÈ«ÇòÒ½ÁÆ»ú¹¹µÄ¹¥»÷µÄ·ÖÎö»ã±¨


4.png


Check Point°ä²¼ÁËÕë¶ÔÈ«ÇòÒ½ÁÆ»ú¹¹µÄ¹¥»÷µÄ·ÖÎö»ã±¨¡£¡£ ¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬ £¬×Ô2020Äê11ÔÂ1ÈÕÒÔÀ´È«ÇòÕë¶ÔÒ½ÁÆÐÐÒµµÄ¹¥»÷ÊýÁ¿Ôö³¤Á˳¬¹ý45£¥£¬£¬£¬£¬ £¬¶øÕë¶ÔÆäËûÐÐÒµµÄ¹¥»÷¾ùÔÈÔö³¤ÁË22£¥£»£»£»£»£»£»£»ÔÚ11ÔÂÿ¸ö×éÖ¯¾ùÔÈÿÖÜÔâµ½626´Î¹¥»÷£»£»£»£»£»£»£»Éæ¼°µ½ÀÕË÷Èí¼þ¡¢½©Ê¬ÍøÂç¡¢Ô¶³Ì´úÂëÖ´ÐкÍDDoSµÄ¹¥»÷ÔÚ11Ô·ݶ¼ÓÐËùÔö³¤£¬£¬£¬£¬ £¬¶øÀÕË÷Èí¼þ¹¥»÷µÄÔö³¤×îΪÏÔÖø£»£»£»£»£»£»£»¹¥»÷ÖÐʹÓõÄÖØÒªÀÕË÷Èí¼þÊÇRyuk£¬£¬£¬£¬ £¬Æä´ÎÊÇSodinokibi¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2021/01/05/attacks-targeting-healthcare-organizations-spike-globally-as-covid-19-cases-rise-again/


5.ºÚ¿Í¹«¿ª1ÍòÕÅExpressÐÅÓþ¿¨Êý¾Ý²¢³ÆÓûÏúÊÛ¸ü¶à


5.png


ºÚ¿Í¹«¿ª1ÍòÕÅExpressÐÅÓþ¿¨Êý¾Ý£¬£¬£¬£¬ £¬²¢³ÆÓûÏúÊÛ¸ü¶àExpress¡¢SantanderºÍBanamexÒøÐпͻ§µÄÐÅÓþ¿¨ÐÅÏ¢¡£¡£ ¡£¡£¡£Õâ´Îй¶µÄ10000±Ê¼Í¼Ô̺¬ÆëÈ«µÄÃÀ¹úExpressÐÅÓþ¿¨ºÅºÍ¿Í»§µÄÓ×ÎÒÉí·ÝÐÅÏ¢£¨PII£©£¬£¬£¬£¬ £¬ÈçÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚºÍÐԱ𣬣¬£¬£¬ £¬µ«ÊDz¢Ã»ÓÐÐÅÓþ¿¨µÄµ½ÆÚÈÕÆÚ¡¢ÃÜÂë»òÃô¸ÐµÄ²ÆÕþÊý¾Ý¡£¡£ ¡£¡£¡£Âô·½°µÊ¾²¢²»ÏúÊÛÃÜÂëºÍÉí·ÝÖ¤ºÅµÈ¸öÈËÊý¾Ý£¬£¬£¬£¬ £¬ÕâЩÊý¾Ý½ö»á±»ÓÃÓÚÀ¬»øÓʼþ»òÓªÏú¸æ°×¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-posts-data-of-10-000-american-express-accounts-for-free/


6.NISSAN±±ÃÀ·Ö¹«Ë¾ÒòGit·þÎñÆ÷ÅäÖÃÃýÎóµ¼ÖÂÔ´´úÂëй¶


6.png


NISSAN±±ÃÀ·Ö¹«Ë¾ÒòÔÚBitbucket Git·þÎñÆ÷ÖÐʹÓÃÁËĬÈÏÍ´´¦admin/admin£¬£¬£¬£¬ £¬µ¼ÖÂÆäÒÆ¶¯ÀûÓ÷¨Ê½ºÍÄÚ²¿¹¤¾ßµÄÔ´´úÂëй¶¡£¡£ ¡£¡£¡£Õâ´Îй¶µÄÔ´´úÂëÔ̺¬ÈÕ²úNA MobileÀûÓá¢ÈÕ²úASISTÕï¶Ï¹¤¾ßµÄijЩ²¿ÃÅ¡¢¾­ÏúóÒ×Îñϵͳ/¾­ÏúÉÌÃÅ»§¡¢ÈÕ²úÄÚ²¿Ö÷Ìâmobile library¡¢ÈÕ²ú/Ó¢·ÆÄáµÏNCAR/ICAR·þÎñ¡¢¿Í»§»ñÈ¡ºÍ±£Áô¹¤¾ß¡¢ÏúÊÛ/Êг¡×êÑй¤¾ß+Êý¾Ý¡¢¸÷ÀàÓªÏú¹¤¾ß¡¢³µÁ¾ÎïÁ÷ÃÅ»§¡¢³µÁ¾ÁªÍø·þÎñ/ÈÕ²úÁªÍø¡¢ÒÔ¼°ÆäËü¸÷Ààºó¶ËºÍÄÚ²¿¹¤¾ßµÈ¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/nissan-source-code-leaked-online-after-git-repo-misconfiguration/