Ò½ÁÆÈí¼þ¹«Ë¾ESOÔâµ½ÀÕË÷¹¥»÷ £¬270ÍòÈËÊܵ½Ó°Ïì

Ðû²¼Ê±¼ä 2023-12-26
1¡¢Ò½ÁÆÈí¼þ¹«Ë¾ESOÔâµ½ÀÕË÷¹¥»÷ £¬270ÍòÈËÊܵ½Ó°Ïì


¾Ý12ÔÂ21ÈÕ±¨µÀ £¬Ò½ÁÆ»ú¹¹µÄÊý¾ÝºÍÈí¼þÌṩÉÌESO SolutionsÒÑ¿ªÊ¼Ïò270ÍòÈË·¢ËÍÊý¾Ýй¶֪ͨ¡£¸Ãʼþ·¢ÉúÓÚ9ÔÂ28ÈÕ £¬ESOÔâµ½ÁËÀÕË÷¹¥»÷ £¬ÆÈʹÆäÔÝʱ¹Ø±Õϵͳ¡£¾¡¹Ü¹¥»÷Õß·ÃÎʲ¢¼ÓÃÜÁËÄÚ²¿ÏµÍ³ £¬µ«¸Ã¹«Ë¾ÌåÏÖÒÑʹÓñ¸·Ý»Ö¸´ÁËÕâЩϵͳ¡£ËäÈ»ÀÕË÷¹¥»÷ÍÅ»ïµÄÉí·ÝÈÔδȷ¶¨ £¬µ«ESOµÄÉùÃ÷±íÃ÷¸Ã¹«Ë¾¿ÉÄÜÒѽ»Êê½ðÀ´È·±£É¾³ý±»µÁÊý¾Ý¡£


https://www.infosecurity-magazine.com/news/eso-hit-ransomware-27m-impacted/


2¡¢¡¶ÏÀµÁÁÔ³µÊÖ5¡·£¨GTA 5£©µÄÔ´´úÂë±»¹ûÈ»ÔÚ¶à¸öÇþµÀ


¾ÝýÌå12ÔÂ25ÈÕ±¨µÀ £¬¡¶ÏÀµÁÁÔ³µÊÖ5¡·£¨GTA 5£©µÄÔ´´úÂëÔÚÊ¥µ®Ò¹±»Ð¹Â¶ £¬Õâ¾àÀëLapsus$ÈëÇÖRockstar Games²¢ÇÔÈ¡¹«Ë¾Êý¾ÝÒѾ­¹ýÈ¥ÁËÒ»Äê¶à¡£ÏÂÔØÔ´´úÂëµÄÁ´½Ó±»·ÖÏíµ½¶à¸öÇþµÀ £¬°üÂÞDiscordÒÔ¼°Telegram¡£ÔÚTelegramÉÏ £¬ÃûΪPhilµÄÓû§Ðû²¼Á˱»µÁÔ´´úÂëµÄÁ´½Ó £¬²¢·ÖÏíÁËÆäÖÐÒ»¸öÎļþ¼ÐµÄ½ØÍ¼¡£DiscordÉϵÄй¶ÕßÌåÏÖ £¬ËûÃÇÔÚ8Ô·ݾÍÊÕµ½ÁËÔ´´úÂë¡£ËûÃǵ͝»úÊǹ¥»÷¡¶GTA 5¡·¸Ä×°³¡¾°ÖеÄÕ©Æ­ÐÐΪ £¬Ðí¶àÈ˱»Éù³ÆÓµÓÐÔ´´úÂëµÄÈËÆÛÆ­¡£


https://www.bleepingcomputer.com/news/security/gta-5-source-code-reportedly-leaked-online-a-year-after-rockstar-hack/


3¡¢Å·ÃËÖ´·¨»ú¹¹³Æ443¸öµçÉÌÆ½Ì¨Ôâµ½¶ñÒâ½Å±¾µÄ¹¥»÷


ýÌå12ÔÂ24ÈÕ³Æ £¬Å·ÖÞÐ̾¯×éÖ¯ºÍENISAºÏ×÷¿ªÕ¹ÁËÒ»ÏîÁªºÏÖ´·¨Ðж¯ £¬·¢ÏÖ443¸öµçÉÌÆ½Ì¨Ñ¬È¾ÁËskimmer¡£SkimmerÊÇÌí¼Óµ½½áÕËÒ³Ãæ»ò´ÓÔ¶³Ì×ÊÔ´¼ÓÔØµÄһС¶ÎJavaScript´úÂë £¬Ö¼ÔÚÀ¹½ØºÍÇÔȡ֧¸¶¿¨ºÅ¡¢ÓÐЧÆÚ¡¢ÑéÖ¤Âë¡¢ÐÕÃûºÍËÍ»õµØÖ· £¬¹¥»÷ÕßÀûÓõçÉÌÆ½Ì¨ºÍÄÚÈݹÜÀíϵͳÖеÄ©¶´À´×¢Èë¶ñÒâ½Å±¾¡£Group-IBÐû²¼µÄÆäËüÐÅÏ¢ÏÔʾ £¬Õâ´ÎÐж¯·¢ÏÖÁË23¸ö²îÒìµÄJavaScriptÐá̽¹¤¾ß £¬°üÂÞATMZOW¡¢health_check¡¢FirstKiss¡¢FakeGA¡¢AngryBeaver¡¢InterºÍR3ninµÈ¡£


https://securityaffairs.com/156340/security/europol-and-enisa-spotted-443-e-stores-compromised-with-digital-skimming.html


4¡¢GoogleÒÑɾ³ý3¸öð³äVPNµÄ¶ñÒâChromeÀ©Õ¹·¨Ê½


ýÌå12ÔÂ22ÈÕ±¨µÀ £¬3¸öð³äVPNµÄ¶ñÒâChromeÀ©Õ¹±»ÒÑÏÂÔØÁË150Íò´Î¡£ËüÃÇ×÷Ϊä¯ÀÀÆ÷½Ù³Ö¹¤¾ß¡¢Ïֽ𷵻¹ºÚ¿Í¹¤¾ßºÍÊý¾ÝÇÔÈ¡¹¤¾ß £¬Òþ²ØÔÚ¡¶ÏÀµÁÁÔ³µÊÖ¡·¡¢¡¶´Ì¿ÍÐÅÌõ¡·ºÍ¡¶Ä£ÄâÈËÉú4¡·µÈÈÈÃÅÓÎÏ·µÄµÁ°æ°²×°·¨Ê½½øÐÐÁ÷´« £¬¶øÕâЩµÁ°æÓÎÏ·¶¼ÊÇ´ÓtorrentÍøÕ¾·Ö·¢µÄ¡£¾ßÌåÀ´Ëµ £¬¶ñÒâÀ©Õ¹ÊÇnetPlus£¨100Íò´Î°²×°£©¡¢netSaveºÍnetWin£¨50Íò´Î£© £¬´ó¶àÊýѬȾ·¢ÉúÔÚ¶íÂÞ˹ÒÔ¼°ÎÚ¿ËÀ¼¡¢¹þÈø¿Ë˹̹ºÍ°×¶íÂÞ˹µÈ¹ú¼Ò¡£Ä¿Ç° £¬GoogleÒÑÔÚChromeÍøÉÏÓ¦ÓõêÖÐɾ³ýÁËÕâЩ¶ñÒâÀ©Õ¹¡£


https://www.bleepingcomputer.com/news/security/fake-vpn-chrome-extensions-force-installed-15-million-times/


5¡¢Ñо¿ÍŶÓÅû¶Õë¶ÔÓ¡¶ÈÕþ¸®»ú¹¹µÄRusticWebÐж¯


SEQRITEÓÚ12ÔÂ21ÈÕÅû¶Á˶ÔÓ¡¶ÈµÄ´úºÅΪ¡°Operation RusticWeb¡±µÄµöÓã¹¥»÷»î¶¯¡£¸Ã»î¶¯ÓÚ10Ô·ÝÊ״α»¼ì²âµ½ £¬Ö÷ÒªÕë¶ÔÓ¡¶ÈÕþ¸®»ú¹¹ºÍ¹ú·À²¿ÃÅ £¬Ö¼ÔÚ·Ö·¢»ùÓÚRustµÄ¶ñÒâÈí¼þ £¬À´½øÐÐÇ鱨ÊÕ¼¯¡£ÐµĻùÓÚRustµÄpayloadºÍ¼ÓÃܵÄPowerShellÃüÁî±»ÓÃÀ´½«»úÃÜÎĵµÐ¹Â¶µ½»ùÓÚWebµÄ·þÎñÒýÇæ £¬¶ø²»ÊÇרÓõÄC2·þÎñÆ÷¡£´ËÍâ £¬¸ÃÍÅ»ïÓëTransparent TribeºÍSideCopyÔÚÕ½ÊõÉÏ´æÔÚÖØµþ¡£

https://thehackernews.com/2023/12/operation-rusticweb-rust-based-malware.html


6¡¢ThreatFabricÐû²¼AndroidľÂíChameleonµÄ³ÂËß


12ÔÂ21ÈÕ £¬ThreatFabricÐû²¼Á˹ØÓÚAndroidľÂíChameleonа汾µÄ·ÖÎö³ÂËß¡£¸Ã¶ñÒâÈí¼þ×Ô2023Äê³õ¿ªÊ¼»îÔ¾ £¬×î³õÖ÷ÒªÕë¶Ô°Ä´óÀûÑǺͲ¨À¼µÄÊÖ»úÒøÐÐÓ¦Óà £¬ÏÖÔÚÆäÓ°Ï췶ΧÀ©´óµ½ÁËÓ¢¹úºÍÒâ´óÀû¡£Ð°汾ChameleonÓÐÁ½ÏîÒýÈËעĿµÄй¦Ð§£ºËü¿ÉÒÔÈÆ¹ýÉúÎïʶ±ðÌáʾ £¬»¹¿ÉÒÔÏÔʾHTMLÒ³Ãæ £¬ÒÔ±ãÔÚʹÓÃAndroid 13µÄ"Restricted Settings"¹¦Ð§µÄÉ豸ÉÏÆôÓÃÎÞÕϰ­·þÎñ¡£


https://www.threatfabric.com/blogs/android-banking-trojan-chameleon-is-back-in-action