ÒÔÉ«ÁÐÀí¹¤Ñ§ÔºTechnion±»DarkBitÀÕË÷170ÍòÃÀÔª

Ðû²¼Ê±¼ä 2023-02-14
1¡¢ÒÔÉ«ÁÐÀí¹¤Ñ§ÔºTechnion±»DarkBitÀÕË÷170ÍòÃÀÔª

      

¾ÝýÌå2ÔÂ12ÈÕ±¨µÀ £¬ÒÔÉ«Áж¥¼âµÄÑо¿ÐÍ´óѧÒÔÉ«ÁÐÀí¹¤Ñ§Ôº£¨Technion£©Ôâµ½ÁËÐÂÀÕË÷ÍÅ»ïDarkBitµÄ¹¥»÷ ¡£¹¥»÷·¢ÉúÓÚ2ÔÂ12ÈÕ»ò֮ǰ £¬DarkBitÍÅ»ïÒªÇó80±ÈÌØ±Ò£¨Ô¼ºÏ1745200ÃÀÔª£©ÓÃÓÚ½âÃÜ ¡£DarkbitÍþвÈç¹ûTechnion²»ÔÚ48СʱÄÚ¸¶Êê½ð £¬ËûÃÇÒª½«½ð¶îÌá¸ß30% ¡£µ«Ñо¿ÈËÔ±Ö¸³ö £¬¸ÃÍŶÓËÆºõÊdzöÓÚÕþÖζ¯»ú £¬¼´Ê¹Âú×ãÒªÇó £¬ËûÃÇÒ²²»Ì«¿ÉÄܸø³ö½âÃÜÃÜÔ¿ ¡£´ËÍâ £¬VX-underground×¢Òâµ½ £¬ÀÕË÷ÐÅÊÇʹÓÃÓ¢Óï·­ÒëÆ÷дµÄ ¡£


https://securityaffairs.com/142160/hacking/israeli-technion-suffered-ransomware-attack.html


2¡¢°ÙÊ¿ÉÀÖ×°Æ¿·çÏÕͶ×ʹ«Ë¾µÄ¸öÈ˺ͲÆÕþÐÅϢй¶

      

¾Ý2ÔÂ13ÈÕ±¨µÀ £¬ÃÀ¹ú×î´óµÄ°ÙÊ¿ÉÀÖÒûÁÏ×°Æ¿ÉÌPepsi Bottling Ventures LLC·¢ÉúÐÅϢй¶ ¡£¸Ã¹«Ë¾ÔÚ֪ͨÖнâÊÍ˵ £¬Î¥¹æÊ¼þ·¢ÉúÔÚ2022Äê12ÔÂ23ÈÕ £¬µ«Ö±µ½18Ììºó £¬Ò²¾ÍÊÇ2023Äê1ÔÂ10Èղű»·¢ÏÖ £¬ÒÑÖªµÄ×îºóÒ»´Î·ÃÎÊʱ¼äΪ1ÔÂ19ÈÕ ¡£¾ÝÊÓ²ì £¬¹¥»÷ÕßÈëÇÖÆäÄÚ²¿ITϵͳ°²×°ÁËÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ £¬²¢ÏÂÔØÁËϵͳÖеIJ¿ÃÅÐÅÏ¢ £¬Éæ¼°ÐÕÃû¡¢Éí·ÝÖ¤ºÅ¡¢Éç»áÄþ¾²ÂëºÍ½ðÈÚÕË»§ÐÅÏ¢µÈ ¡£¸Ã¹«Ë¾ÒÑÖØÖÃËùÓÐÃÜÂë £¬²¢Í¨ÖªÖ´·¨²¿ÃÅ £¬»¹½«ÎªÊÜÓ°ÏìµÄ¸öÈËÌṩһÄêµÄÃâ·ÑÉí·Ý¼à¿Ø·þÎñ ¡£


https://www.theregister.com/2023/02/14/pepsi_bottling_malware/


3¡¢B&G FoodsÔâµ½DaixinµÄ¹¥»÷Ô¼1000̨Ö÷»ú±»¼ÓÃÜ

      

ýÌå2ÔÂ12ÈÕ³Æ £¬Daixin½üÆÚµÄÒ»´ÎÍøÂç¹¥»÷µ¼ÖÂB&G FoodsÔ¼1000̨Ö÷»ú±»¼ÓÃÜ ¡£DaixinµÄ·¢ÑÔÈËÌåÏÖ £¬B&GÓÚ2ÔÂ4ÈÕ±»¼ÓÃÜ £¬µ«ËûÃDz»È·¶¨ÊÇ·ñÒѶÔËùÓб¸·Ý½øÐмÓÃÜ £¬²¢ÌåÏָù«Ë¾¿ÉÄÜÒѾ­»Ö¸´ ¡£´ËÍâ £¬ËûÃÇÔÚµ±µØÉÏÁôÏÂÁËÊê½ð¼Ç¼²¢·¢ËÍÁ˼¸´ÎͨѶ £¬µ«B&GһֱûÓлØÓ¦ ¡£Ñо¿ÈËÔ±³Æ £¬Ð¹Â¶Êý¾ÝÖÐȷʵ°üÂÞ¹«Ë¾ÄÚ²¿Îļþ £¬È»¶ø £¬Õû¸öת´¢ËƺõûÓиüÑÏÖØ»ò»úÃܵĹ«Ë¾Îļþ¡¢ÈËÊÂÎļþ»ò³Ð°üÉÌÎļþ ¡£


https://www.databreaches.net/b-files-leaked/


4¡¢¼ÓÄôó×î´óµÄÊéµêIndigoÔâµ½¹¥»÷µ¼ÖÂÍøÕ¾ÎÞ·¨·ÃÎÊ

      

2ÔÂ9ÈÕ±¨µÀ³Æ £¬¼ÓÄôó×î´óµÄÁ¬ËøÊéµêIndigo Books & MusicÔâµ½¹¥»÷ ¡£ÉÏÖÜÈý £¬IndigoÐû²¼Òò¼¼ÊõÎÊÌâµ¼ÖÂÎÞ·¨·ÃÎʸÃÍøÕ¾ £¬ÊµÌåµêµÄÖ÷¹ËÖ»ÄÜÓÃÏÖ½ðÖ§¸¶ ¡£´ËÍâ £¬ÎÞ·¨½øÐÐÀñÆ·¿¨½»Ò× £¬ÔÚÏß¶©µ¥Ò²¿ÉÄ᷺ܻÆðÑÓ³Ù ¡£¼¸¸öСʱºó £¬¸Ã¹«Ë¾³ÆÆäϵͳÔâµ½ÁËÍøÂç¹¥»÷ £¬¶øÇÒÕýÔÚÊÓ²ì´Ëʼþ ¡£¸Ã¹«Ë¾Ã»ÓÐ͸¶ĿǰÄþ¾²Ê¼þµÄÀàÐÍ £¬µ«ÌåÏÖÕýÔÚŬÁ¦È·¶¨¹¥»÷ÕßÊÇ·ñÉè·¨·ÃÎÊ»òÇÔÈ¡Á˿ͻ§Êý¾Ý ¡£


https://www.bleepingcomputer.com/news/security/largest-canadian-bookstore-indigo-shuts-down-site-after-cyberattack/


5¡¢ProofpointÅû¶TA866Õë¶ÔÃÀ¹úºÍµÂ¹úµÄ¹¥»÷»î¶¯

      

ProofpointÔÚ2ÔÂ8ÈÕÅû¶ÁËÐÂÍþвÍÅ»ïTA866Õë¶ÔÃÀ¹úºÍµÂ¹úµÄ¹¥»÷»î¶¯ ¡£¸Ã»î¶¯ËƺõÊdzöÓÚ¾­¼Ã¶¯»ú £¬ÓÚ2022Äê10ÔÂÊ״α»·¢ÏÖ £¬²¢Ò»Ö±Á¬Ðøµ½2023Äê ¡£¹¥»÷ÖÐʹÓõĵöÓãÓʼþ°üÂÞ´øÓжñÒâºêµÄMicrosoft Publisher(.pub)¸½¼þ¡¢Á´½Óµ½´øÓкêµÄ.pubÎļþµÄURL £¬»ò°üÂÞÏÂÔØÎ£ÏÕJavaScriptÎļþµÄURLµÄPDF ¡£Ä¿±êµã»÷URLºó»á´¥·¢¶à²½Öè¹¥»÷Á´ £¬È»ºóÏÂÔØ²¢Ö´ÐÐTA886µÄ×Ô½ç˵¶ñÒâÈí¼þScreenshotter ¡£


https://www.proofpoint.com/us/blog/threat-insight/screentime-sometimes-it-feels-like-somebodys-watching-me


6¡¢AvastÐû²¼2022ÄêµÚËļ¾¶ÈÍøÂçÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß

      

2ÔÂ9ÈÕ £¬AvastÐû²¼Á˹ØÓÚ2022ÄêµÚËļ¾¶ÈÍøÂçÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß ¡£³ÂËßÖ¸³ö £¬¹ã¸æÈí¼þ»î¶¯ÔÚ2022ÄêµÚÈý¼¾¶ÈÄ©¿ìËÙÉÏÉý £¬²¢Á¬Ðøµ½2022ÄêµÚËļ¾¶È³õ ¡£¼ÓÃܿ󹤻ÕûÌåÂÔÓÐϽµ(4%) £¬×î³£¼ûµÄΪWeb miners¡¢XMRig¡¢CoinBitMinerºÍVMinerµÈ ¡£×î³£¼ûµÄÐÅÏ¢ÇÔÈ¡·¨Ê½Îª £¬FormBook¡¢AgentTesla¡¢RedLineºÍLokibot £¬ÊÜ´ËÀà¶ñÒâÈí¼þÓ°Ïì×î´óµÄ¹ú¼ÒÊÇÒ²ÃÅ¡¢°¢¸»º¹ºÍÂíÀï ¡£ÀÕË÷Èí¼þµÄ×ÜÊýϽµÁË17% £¬Õ¼±ÈÁ¦´óµÄÊÇSTOP(21%)¡¢WannaCry(20%)ºÍThanatos(2%) ¡£


https://decoded.avast.io/threatresearch/avast-q4-2022-threat-report/