Agent Tesla³¢ÊÔ´Û¸Ä΢ÈíAMSIÀ´Èƹýɱ¶¾Èí¼þ¼ì²â£»£»£»£»£»£»£»Google°ä²¼Android°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬×ܼƽ¨¸´40¶à¸ö·ì϶

°ä²¼¹¦·ò 2021-02-04

1.Agent Tesla³¢ÊÔ´Û¸Ä΢ÈíAMSIÀ´Èƹýɱ¶¾Èí¼þ¼ì²â


1.jpg


Sophos×êÑÐÈËÔ±·¢ÏÖ¼äµýÈí¼þAgent Tesla³¢ÊÔ´Û¸Ä΢Èí·À¶ñÒâÈí¼þÈí¼þ½Ó¿Ú£¨AMSI£©£¬£¬£¬£¬£¬£¬£¬£¬À´Èƹýɱ¶¾Èí¼þµÄɨÃèºÍ·ÖÎö ¡£¡£¡£¡£¡£¡£¡£¡£Agent TeslaÓÚ2014Äê³õ´Î±»·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÒ»ÖÖÓÃ.NET±àдµÄóÒ×RAT ¡£¡£¡£¡£¡£¡£¡£¡£Sophos°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÔÚ²»ÐÝ¿ª·¢ÖУ¬£¬£¬£¬£¬£¬£¬£¬Æä.NETÏÂÔØ·¨Ê½¿ÉŲÓò¢ÏÂÔØÍйÜÔںϷ¨ÍøÕ¾ÉϵĶñÒâ´úÂë ¡£¡£¡£¡£¡£¡£¡£¡£Ôڳɹ¦´Û¸ÄAMSIºó¸Ã¶ñÒâÈí¼þ¿ÉÔÚûÓÐÈκÎ×ÌÈŵÄÇé¿öÏÂÆëÈ«ÊýÊ𣬣¬£¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡Êý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔOpera¡¢Chromium¡¢Chrome¡¢Firefox¡¢OpenVPNºÍOutlookµÅצÓà ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/agent-tesla-ramps-up-its-game-in-bypassing-security-walls-attacks-endpoint-protection/


2.Google°ä²¼Android°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬×ܼƽ¨¸´40¶à¸ö·ì϶


2.png


Google°ä²¼ÁË2Ô·ÝAndroid°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬×ܼƽ¨¸´40¶à¸ö·ì϶ ¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶ÖнÏΪ³ÁÒªµÄ·ì϶ÊÇMedia Framework×é¼þÖеĴúÂëÖ´Ðзì϶£¨CVE-2021-0325)¡¢ÌáȨ·ì϶£¨CVE-2021-0332£©ºÍÐÅϢй¶·ì϶£¨CVE-2021-0335£© ¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬¸üл¹½¨¸´ÁËÄÚºËÖеĴúÂëÖ´Ðзì϶£¨CVE-2017-18509£©ÒÔ¼°Qualcomm×é¼þÖеĶà¸ö·ì϶£¨CVE-2020-11272¡¢CVE-2020-11163ºÍCVE-2020-11170µÈ£© ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/google-patches-16-high-severity-privilege-escalation-vulnerabilities-android


3.ºÚ¿ÍÏúÊÛAirtelIndiaµÄ250ÍòÓû§ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬±»¸Ã¹«Ë¾·ñ¶¨


3.png


ºÚ¿Í×éÖ¯Red RabbitÔÚ°µÍøÒÔ3500ÃÀÔªµÄ¼ÛÖµÏúÊÛAirtelIndiaµÄ250ÍòÓû§ÐÅÏ¢ ¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬ÊÓ×¢ÐÔ±ð¡¢ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢·þÎñ״̬¡¢µç»°ºÅÂë¡¢ÃÅÉ̱êÂë¡¢AadhaarºÅÂë¡¢»¤ÕÕºÅÂ롢ѡÃñ±àºÅ¡¢¸¸Ç×»òÕÉ·òµÄÃû×ÖºÍIMSI£¨¹ú¼ÊÒÆ¶¯Óû§Éí·Ý£©ºÅÂë ¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í»¹°ä²¼ÁËÆäÔÚAirtelµÄһ̨·þÎñÆ÷ÉÏ´«ShellµÄÆÁÄ»½ØÍ¼ ¡£¡£¡£¡£¡£¡£¡£¡£µ«Airtel·ñ¶¨Æä²úÉúÁËÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬²¢Ö¸³ö´óÎÞÊýµÄÊý¾Ý²»ÊôÓÚAirtelµÄ¿Í»§ ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬Red RabbitÔËÓªµÄÍøÕ¾Ò²ÒÑ¹Ø¹Ø ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/hackers-leak-airtel-india-user-data-aadhaar-numbers/


4.Èí¼þ¹«Ë¾Wind River³ÆÆäÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ô±¹¤ÐÅϢй¶


4.png


¼ÓÀû¸£ÄáÑǵÄÈí¼þ¹«Ë¾Wind River³ÆÆäÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ±¹¤µÄÓ×ÎÒÐÅϢй¶ ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³ÆÊÂÎñ²úÉúÔÚ2020Äê9ÔÂ29ÈÕ×óÓÒ£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í¿ÉÄÜÒѾ­ÇÔÈ¡ÁËÒ»¸ö»ò¶à¸öÎļþ ¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬µ®ÉúÈÕÆÚ¡¢¼ÝÕÕºÅÂë¡¢¹«ÃñÉí·ÝÖ¤ºÅÂë¡¢Éç»á±£ÏÕºÅÂë¡¢»¤ÕÕ»òǩ֤ºÅÂë¡¢½¡È«¾ßÌåÐÅÏ¢ºÍ²ÆÕþÕÊ»§ÐÅÏ¢µÈ ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬Wind RiverÉÐδÌṩÓйØÊÜÓ°ÏìÔ±¹¤µÄÊýÁ¿»ò¹¥»÷ÕßÈôºÎ·ÛËéÆäϵͳµÄ¾ßÌåÐÅÏ¢ ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/114151/data-breach/wind-river-data-breach.html


5.»õÔ˹«Ë¾Forward AirϰȾHades£¬£¬£¬£¬£¬£¬£¬£¬Ëðʧ´ï750ÍòÃÀÔª


5.png


»õÔ˹«Ë¾Forward AirÔâµ½ÁËHadesÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ôì³ÉµÄËðʧ´ï750ÍòÃÀÔª ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ÊÂÎñ²úÉúÔÚÈ¥Äê12ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÒòϰȾHadesµ¼Ö¸ù«Ë¾½«ËùÓÐITϵͳÍÑ»úÒÔÓ¦¶ÔÈëÇÖ ¡£¡£¡£¡£¡£¡£¡£¡£µ¼Ö¼ÝʻԱºÍÔ±¹¤ÎÞ·¨»ñÈ¡±ØÒªµÄÎļþÒÔͨ¹ýº£¹ØÇ幨ÔËÊ䣬£¬£¬£¬£¬£¬£¬£¬ÆäÔËÓªÊܵ½ÑϳÁ·ÛËé ¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜForward Air°µÊ¾ÆäÒѳɹ¦µØ´Ó¹¥»÷Öи´Ô­£¬£¬£¬£¬£¬£¬£¬£¬µ«»¹ÊÇÖ§³öÁ˳Á³Á¼ÛÖµ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÔÚµÚËÄʱ¶ÈµÄ²ÆÕþÒµ¼¨ÖеÄËðʧ¸ß´ï750ÍòÃÀÔª ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/trucking-company-forward-air-said-its-ransomware-incident-cost-it-7-5-million/


6.Chainalysis°ä²¼2020ÄêÀÕË÷Èí¼þ¹¥»÷µÄ»ØÊ׻㱨


6.png


Chainalysis°ä²¼ÁË2020ÄêÀÕË÷Èí¼þ¹¥»÷µÄ»ØÊ׻㱨 ¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þµÄÊܺ¦ÕßÔÚ2020ÄêÖÁÉÙ×ܹ²Ö§¸¶ÁË3.5ÒÚÃÀÔªÊê½ð£¬£¬£¬£¬£¬£¬£¬£¬±È2019Äêͬ±ÈÔö³¤ÁË311£¥ ¡£¡£¡£¡£¡£¡£¡£¡£È¥ÄêÓ¯Àû×î¶àµÄÍÅ»ïΪRyuk¡¢Maze¡¢Doppelpaymer¡¢Netwalker¡¢ContiºÍREvil£¬£¬£¬£¬£¬£¬£¬£¬Æä´ÎΪSnatch¡¢Defray777£¨RansomExx£©ºÍDharmaµÈ ¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þ¹¥»÷½öÕ¼ËùÓлùÓÚ¼ÓÃÜÇ®±ÒµÄ·¸×ï»î¶¯µÄ7£¥£¬£¬£¬£¬£¬£¬£¬£¬Ö»¹ÜÕâ¸öÊý×ֺܵÍ£¬£¬£¬£¬£¬£¬£¬£¬µ«´ËÀ๥»÷ÊýÁ¿ÆäʵÔÚÔö³¤ ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.chainalysis.com/reports/ransomware-ecosystem-crypto-crime-2021