ÃÀ¹úDish NetworkÒÉËÆÔâµ½¹¥»÷ÍøÕ¾ºÍÓ¦ÓÃÎÞ·¨·ÃÎÊ
Ðû²¼Ê±¼ä 2023-02-271¡¢ÃÀ¹úDish NetworkÒÉËÆÔâµ½¹¥»÷ÍøÕ¾ºÍÓ¦ÓÃÎÞ·¨·ÃÎÊ
¾ÝýÌå2ÔÂ25ÈÕ±¨µÀ£¬ÃÀ¹úµçÊÓºÍÎÀÐǹ㲥ÌṩÉÌDish Network·þÎñÖжϡ£´Ë´ÎÖжÏÓ°ÏìÁËDish NetworkÍøÕ¾ºÍÓ¦Ó÷¨Ê½£¬°üÂÞDish.com¡¢DishWireless.comºÍDish AnywhereµÈ£¬¿Í»§Ò²ÎÞ·¨·ÃÎÊËûÃǵÄÕË»§»òÔÚÏß²¥·ÅµçÊÓ¡£´ËÍ⣬Dish NetworkµÄÔ¶³ÌÔ±¹¤ÌåÏÖÎÞ·¨·ÃÎÊÊÂÇéϵͳ¡£¾ÝDish NetworkµÄÒ»ÃûÔ±¹¤Í¸Â¶£¬¸Ã¹«Ë¾È·ÊµÔâµ½ÁËÍøÂç¹¥»÷£¬µ«²¢²»È·¶¨¹¥»÷ÕßÊÇÈçºÎ»ñµÃ·ÃÎÊȨÏ޵ġ£
https://www.bleepingcomputer.com/news/security/dish-network-goes-offline-after-likely-cyberattack-employees-cut-off/
2¡¢Symantec·¢ÏÖÐÂÍÅ»ïClasiopaÕë¶ÔÑÇÖÞij×éÖ¯µÄ¹¥»÷
SymantecÔÚ2ÔÂ23ÈÕ³ÆÆä·¢ÏÖкڿÍÍÅ»ïClasiopaÕë¶ÔÑÇÖÞij×éÖ¯µÄ¹¥»÷»î¶¯¡£Clasiopa»òÐíÓëÓ¡¶ÈÓйأ¬ÆäÌØµãÊǾßÓÐÆæÌصŤ¾ß¼¯£¬°üÂÞÒ»¸ö×Ô½ç˵¶ñÒâÈí¼þ(Backdoor.Atharvan)¡£¸ÃÍÅ»ïʹÓõÄѬȾý½éÈÎȻδ֪£¬µ«Ò»Ð©Ö¤¾Ý±íÃ÷¹¥»÷Õßͨ¹ýÅüÃæÏò¹«ÖڵķþÎñÆ÷½øÐб©Á¦¹¥»÷À´»ñµÃ·ÃÎÊȨÏÞ¡£ÈëÇÖʱËü»áÇå³ýϵͳ¼àÊÓÆ÷(Sysmon)ºÍʼþÈÕÖ¾£¬²¢°²×°¶à¸öºóÃÅ£¬ÈçAtharvanºÍ¿ªÔ´Lilith RATµÄÐ޸İ汾£¬À´ÊÕ¼¯ºÍй¶Ãô¸ÐÐÅÏ¢¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/clasiopa-materials-research
3¡¢¼ÓÄôóµçÐŹ«Ë¾TelusÊÓ²ìÔ´´úÂëºÍÔ±¹¤Êý¾Ýй¶Ê¼þ
ýÌå2ÔÂ23Èճƣ¬¼ÓÄôóµÚ¶þ´óµçÐŹ«Ë¾TelusÕýÔÚÊÓ²ìÆäÔ´´úÂëºÍÔ±¹¤Êý¾Ýй¶Ê¼þ¡£2ÔÂ17ÈÕ£¬ºÚ¿ÍÔÚÂÛ̳ÉϳöÊ۾ݳÆÊÇTelusÔ±¹¤Ãûµ¥µÄÊý¾Ý£¬Ñù±¾°üÂÞTelusÔ±¹¤£¨ÓÈÆäÊÇÈí¼þ¿ª·¢ÈËÔ±ºÍ¼¼ÊõÈËÔ±£©µÄÐÕÃûºÍÓʼþµØÖ·¡£2ÔÂ21ÈÕ£¬Í¬Ò»ºÚ¿Í´´½¨ÁËÁíÒ»¸öÂÛ̳Ìû×Ó£¬Òª³öÊÛTelusµÄ˽ÈËGitHub´æ´¢¿â¡¢Ô´´úÂëÒÔ¼°¹«Ë¾µÄÈËΪµ¥¼Ç¼¡£Telus·¢ÑÔÈ˳ƣ¬ËûÃÇÕýÔÚÊÓ²ì´Îй¶Ê¼þ£¬²¢È·Èϵ½Ä¿Ç°ÎªÖ¹£¬ÉÐδ·¢ÏÖÈκι«Ë¾»òÁãÊÛ¿Í»§µÄÊý¾Ýй¶¡£
https://www.bleepingcomputer.com/news/security/telus-investigating-leak-of-stolen-source-code-employee-data/
4¡¢ÎÚ¿ËÀ¼CERT͸¶UAC-0056ÈëÇÖÆä¶à¸öÕþ¸®Ïà¹ØÍøÕ¾
ÎÚ¿ËÀ¼CERTÔÚ2ÔÂ23ÈÕ͸¶£¬UAC-0056ÍÅ»ïÔÚÉÏÖÜÈëÇÖÁËÆä¶à¸öÕþ¸®Ïà¹ØÍøÕ¾¡£Ñо¿ÈËÔ±ÔÚÎÚ¿ËÀ¼ÖÐÑëºÍµØ·½Õþ¸®µÄ¶à¸öÍøÕ¾Éϼì²âµ½¹¥»÷£¬µ¼ÖÂÆä²¿ÃÅÍøÒ³µÄÄÚÈݱ»¸Ä¶¯¡£¹¥»÷ÕßʹÓÃSSHºóÃÅCredPump£¨PAMÄ£¿é£©ÊµÏÖÔ¶³ÌSSH·ÃÎÊ£¨Ê¹Óþ²Ì¬ÃÜÂëÖµ£©£¬²¢ÔÚSSHÁ¬½ÓÆÚ¼ä¼Ç¼µÇ¼ºÍÃÜÂë¡£»¹Ê¹ÓÃÁËHoaxPenºÍHoaxApeºóÃÅ£¬¶ñÒâ´úÂëÒÔApacheWeb·þÎñÆ÷Ä£¿éµÄÐÎʽ·ºÆð£¬²¢ÓÚ2022Äê2Ô°²×°¡£ÖµµÃ×¢ÒâµÄÊÇ£¬webshellµÄ´´½¨Ê±¼ä²»ÍíÓÚ2021Äê12ÔÂ23ÈÕ¡£
https://securityaffairs.com/142678/cyber-warfare-2/cert-of-ukraine-russia-backdoors.html
5¡¢Ë¹Ì¹¸£´óѧÅäÖôíÎóµ¼Ö²¿ÃŲ©Ê¿ÉêÇëÕßµÄÐÅϢй¶
¾Ý2ÔÂ24ÈÕ±¨µÀ£¬ÃÀ¹ú˹̹¸£´óѧ¾¼Ãѧ²©Ê¿ÉêÇëÕßµÄÐÅϢй¶¡£¸ÃУÌåÏÖ£¬1ÔÂ24ÈÕÆäÊÕµ½Í¨Öª£¬ÓÉÓÚÎļþ¼ÐÉèÖÃÅäÖôíÎ󣬹«ÖÚ¿ÉÒÔͨ¹ýÍøÕ¾·ÃÎʰüÂÞ2022-23Äê˹̹¸£´óѧ¾¼Ãϵ²©Ê¿ÏîÄ¿ÈëѧÉêÇëÎļþµÄÎļþ¼Ð¡£ÔÚ¶Ô´ËʽøÐÐÊÓ²ìºó£¬·¢ÏÖÎÞÏÞÖÆµÄ·ÃÎÊÊÇ´Ó2022Äê12ÔÂ5ÈÕ¿ªÊ¼µÄ£¬¶øÇÒÔÚ2022Äê12ÔÂ5ÈÕÖÁ2023Äê1ÔÂ24ÈÕÖ®¼äÓйýÁ½´ÎÏÂÔØ¡£Ë¹Ì¹¸£´óѧÔÚ·¢ÏÖй¶Ê¼þºóÁ¢¼´½ÓÄÉ´ëÊ©×èÖ¹Á˶ÔÕâЩÎļþµÄ·ÃÎÊ¡£
https://www.bleepingcomputer.com/news/security/stanford-university-discloses-data-breach-affecting-phd-applicants/
6¡¢Ñо¿ÈËÔ±Åû¶ÀûÓÃPureCrypter¹¥»÷Õþ¸®»ú¹¹µÄ»î¶¯
2ÔÂ23ÈÕ£¬Menlo LabsÅû¶ÁËÀûÓöñÒâÈí¼þÏÂÔØ·¨Ê½PureCrypter¹¥»÷Õþ¸®»ú¹¹µÄ»î¶¯¡£¹¥»÷ÕßʹÓÃDiscordÀ´Íйܳõʼpayload£¬²¢ÈëÇÖÁËÒ»¸ö·ÇÓªÀû×éÖ¯À´´æ´¢»î¶¯ÖÐʹÓÃµÄÆäËüÖ÷»ú¡£¸Ã»î¶¯Á÷´«Á˶àÖÖÀàÐ͵ĶñÒâÈí¼þ£¬°üÂÞRedline Stealer¡¢AgentTesla¡¢Eternity¡¢BlackmoonºÍPhiladelphia Ransomware¡£Ñо¿ÈËÔ±³Æ£¬ÊӲ쵽µÄPureCrypter»î¶¯Ö÷ÒªÕë¶ÔÑÇÌ«µØÓòºÍ±±ÃÀµØÓòµÄ¶à¸öÕþ¸®»ú¹¹¡£
https://www.menlosecurity.com/blog/purecrypter-targets-government-entities-through-discord/