¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181210
Ðû²¼Ê±¼ä 2018-12-10
Anomali LabsÑо¿Ö°Ô±·¢Ã÷Ò»¸öеĶñÒâÈí¼þLinux Rabbit£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÔÚ2018Äê8ÔÂÖÁ10ÔµĶñÒâ»î¶¯ÖÐÖ÷ҪѬȾLinuxЧÀÍÆ÷ºÍIoT×°±¸¡£¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄµØÇøÎª¶íÂÞ˹¡¢º«¹ú¡¢Ó¢¹úºÍÃÀ¹ú¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâ»î¶¯ÖÐʹÓÃÁËÁ½ÖÖ¶ñÒâÈí¼þ£ºLinux RabbitºÍRabbot¡£¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö¶ñÒâÈí¼þÊÇ»ùÓÚÏàͬµÄ´úÂë¿â¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâ»î¶¯ÓÃÓÚÔÚÄ¿µÄ×°±¸ÉÏ×°ÖöñÒâ¿ó¹¤£¬£¬£¬£¬²¢ÇÒÆ¾Ö¤Ä¿µÄ¼Ü¹¹µÄ²î±ð×°Öòî±ðµÄÃÅÂޱҿ󹤡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.anomali.com/blog/pulling-linux-rabbit-rabbot-malware-out-of-a-hat2¡¢ÐÂMac¶ñÒâÈí¼þOSX.DarthMiner£¬£¬£¬£¬Á¬ÏµEmPyreºóÃż°XMRig¿ó¹¤
Malwarebytes LabsÑо¿ÍŶӷ¢Ã÷Ò»ÖÖеÄMac¶ñÒâÈí¼þOSX.DarthMiner£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÁ¬ÏµÁËEmPyreºóÃźÍXMRig¿ó¹¤µÄ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£¡£DarthMinerαװ³ÉÓ¦ÓóÌÐòAdobe Zii¾ÙÐÐÈö²¥£¬£¬£¬£¬µ«Ê¹ÓÃÁ˳£¼ûµÄAutomatorС³ÌÐòͼ±ê£¬£¬£¬£¬²¢ÇÒʵÖÊÉÏÖ»ÊÇÒ»¸öshell¾ç±¾¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¾ç±¾ÓÃÓÚÏÂÔØºÍ×°ÖöñÒâÈí¼þµÄÆäËü×é¼þ£¬£¬£¬£¬°üÀ¨EmPyreºóÃźÍXMRig¿ó¹¤¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/threat-analysis/2018/12/mac-malware-combines-empyre-backdoor-and-xmrig-miner/3¡¢ÐÂsextortionթƻÏòÓû§·Ö·¢AZORultºÍGandCrab
ProofpointÑо¿Ö°Ô±·¢Ã÷Sextortionڲƻ·ºÆðÁËÒ»ÖÖеÄÇ÷ÊÆ¡£¡£¡£¡£¡£¡£¡£¡£sextortionͨ³£Éæ¼°·¸·¨·Ö×Óð³äÓµÓÐÄ¿µÄÓû§»á¼û³ÉÈËÍøÕ¾µÄÖ¤¾Ý»òÊÓÆµÀ´¾ÙÐÐÚ²ÆÀÕË÷£¬£¬£¬£¬µ«ProofpointÔÚ12ÔÂ5ÈÕ·¢Ã÷µÄÐÂsextortionթƻ×îÏÈÏòÄ¿µÄÓû§·Ö·¢ÐÅϢ͵ÇÔľÂíAzorultºÍÀÕË÷Èí¼þGandCrab¡£¡£¡£¡£¡£¡£¡£¡£ÕâÖÖеÄÕ½ÂÔÔ½·¢µÄΣÏÕ£¬£¬£¬£¬ÓÉÓÚÊܺ¦ÈË¿ÉÄÜ»áÏëҪȷÈÏÊÓÆµÖ¤¾ÝÊÇ·ñ±£´æ£¬£¬£¬£¬´Ó¶øµã»÷¶ñÒâÁ´½Ó²¢ÏÂÔØÄ¾Âí¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.proofpoint.com/us/threat-insight/post/sextortion-side-ransomware4¡¢ÀñÎ│թƼ°BECڲƻÔÚãåÈÕ¼¾½Ú¼¤Ôö
ProofpointÑо¿Ö°Ô±·¢Ã÷ÀñÎ│թƼ°BECڲƻÔÚãåÈÕ¼¾½Ú¼¤Ôö¡£¡£¡£¡£¡£¡£¡£¡£ÕâÖÖթƻÔÚ2018ÄêµÚÒ»¼¾¶ÈÏÕЩ²»±£´æ£¬£¬£¬£¬µ«ÔÚµÚ¶þ¼¾¶ÈÔöÌíÖÁ1%£¬£¬£¬£¬²¢ÔÚµÚÈý¼¾¶È··¬¡£¡£¡£¡£¡£¡£¡£¡£´Ó¸Ð¶÷½Úµ½Ê¥µ®½Úʱ´ú£¬£¬£¬£¬ÍøÂçڲƻ½øÈë¸ß·¢¼¾½Ú¡£¡£¡£¡£¡£¡£¡£¡£2018ÄêPoS¶ñÒâÈí¼þµÄ»î¶¯Ïà¶ÔÎȹ̣¬£¬£¬£¬×î³£¼ûµÄ¼Ò×åÊÇFindPOS¡£¡£¡£¡£¡£¡£¡£¡£MagikPOSµÄ¶ñÒâ»î¶¯ÔÚ11Ô³õ·ºÆðÁËÒ»¸ö¼¤Ôö¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/threatlist-gift-card-themed-bec-holiday-scams-spike/139716/5¡¢WebKitÎó²îʹÓôúÂë±»Åû¶£¬£¬£¬£¬¿ÉÓ°Ïì×îа汾µÄSafari
Ñо¿Ö°Ô±Linus HenzeÔÚGithubÉÏÐû²¼ÁËWebKitÒ»¸öÎó²îµÄʹÓôúÂ룬£¬£¬£¬¸ÃÎó²îÒÑÔÚWebKitÔ´´úÂëÖÐÐÞ¸´£¬£¬£¬£¬µ«ÐÞ¸´²¹¶¡ÉÐδµÖ´ïSafariä¯ÀÀÆ÷¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓëWebKitÆ¥ÅäÕýÔò±í´ïʽÖеÄÓÅ»¯¹ýʧÓйأ¬£¬£¬£¬×îÖÕ¿ÉÄܵ¼ÖÂÖ´ÐÐí§Òâshell´úÂë¡£¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄϵͳ°üÀ¨iOS 12.0µ½12.1.1ÒÔ¼°macOS 10.14.0µ½10.14.2¡£¡£¡£¡£¡£¡£¡£¡£¸ÃʹÓôúÂë¿ÉÓ¦ÓÃÓÚiOS£¬£¬£¬£¬µ«ÓÉÓÚiOS²»Ö§³Ö¼ÓÔØshell´úÂ룬£¬£¬£¬Òò´Ë»áµ¯³öiOSÉÐδ֧³ÖµÄÖÒÑÔ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/webkit-vulnerability-affects-latest-versions-of-apple-safari/6¡¢Å·ÖÞÐ̾¯×éÖ¯¿ªÕ¹µÚËĴη´Ï´Ç®Ðж¯EMMA 4£¬£¬£¬£¬168Ç®ÂâÂäÍø
2018Äê9ÔÂÖÁ11ÔÂʱ´ú£¬£¬£¬£¬Å·ÖÞÐ̾¯×éÖ¯¿ªÕ¹µÚËĴη´Ï´Ç®Ðж¯EMMA 4£¬£¬£¬£¬¹²¾Ð²¶ÁË168ÃûÇ®Â⣬£¬£¬£¬²¢·¢Ã÷ÁË140ÃûÇ®Ââ×éÖ¯ÕßÒÔ¼°ÁíÍâµÄ1504ÃûÇ®Ââ¡£¡£¡£¡£¡£¡£¡£¡£¹²ÓÐ30¸ö¹ú¼Ò¼ÓÈëÁË´Ë´ÎÐж¯£¬£¬£¬£¬¿ªÕ¹ÁË837ÆðÐÌʰ¸¼þÊӲ졣¡£¡£¡£¡£¡£¡£¡£Áè¼Ý300¼ÒÒøÐС¢20¸öÒøÐÐлáÒÔ¼°ÆäËü½ðÈÚ»ú¹¹±¨¸æÁË26376ÆðÚ²ÆÐÔÇ®ÂâÉúÒ⣬£¬£¬£¬Íì»ØËðʧ3610ÍòÅ·Ôª¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.europol.europa.eu/newsroom/news/over-1500-money-mules-identified-in-worldwide-money-laundering-stingÉùÃ÷£º±¾×ÊѶÓÉ¿·¢k8άËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ