FBIÐû²¼2018Ä껥ÁªÍø·¸·¨±¨¸æ£»£» £»£»¹©Ó¦Á´¹¥»÷ShadowHammer£»£» £»£»CarbanakÔ´Âëй¶

Ðû²¼Ê±¼ä 2019-04-24
1.FBIÐû²¼2018Ä껥ÁªÍø·¸·¨±¨¸æ£¬ £¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÆóÒµÒòBECڲƭËðʧ13ÒÚÃÀÔª


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ƾ֤FBI IC3Ðû²¼µÄÄê¶È»¥ÁªÍø·¸·¨±¨¸æ£¬ £¬£¬£¬£¬£¬£¬£¬2018ÄêBECڲƭÔì³ÉµÄËðʧÏà±È2017Äê·­ÁËÒ»±¶£¬ £¬£¬£¬£¬£¬£¬£¬´ï13ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£ ¡£ÀÕË÷Èí¼þͶËßµÄÊýÄ¿ÒѾ­Ï½µÖÁ2014ÄêµÄˮƽ£¬ £¬£¬£¬£¬£¬£¬£¬µ«ÀÕË÷Èí¼þ¹¥»÷Ôì³ÉµÄ¾­¼ÃËðʧ±ÈÒÔÍùÈκÎʱ¼ä¶¼Òª¸ß£¬ £¬£¬£¬£¬£¬£¬£¬ÕâÅú×¢¹¥»÷ÕßÕýÔÚ×ÐϸÌôÑ¡Êܺ¦Õߣ¬ £¬£¬£¬£¬£¬£¬£¬ÒÔÔì³É×î´óµÄË𺦺ͻñµÃ×î¸ßµÄÅ⸶¡£¡£¡£¡£¡£¡£¡£ ¡£±ðµÄ£¬ £¬£¬£¬£¬£¬£¬£¬ÊÖÒÕÖ§³ÖÕ©Æ­ÔÙ´ÎÉÏÉý£¬ £¬£¬£¬£¬£¬£¬£¬ÆäÔÚ2018ÄêÔì³ÉµÄËðʧÔöÌíÁË161%¡£¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/fbi-us-companies-lost-1-3-billion-in-2018-due-to-bec-scams/

2.Õë¶Ô»ªË¶µÄ¹©Ó¦Á´¹¥»÷ShadowHammer»¹Ãé×¼ÁíÍâÁù¼ÒÑÇÖÞ¹«Ë¾


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù·¢Ã÷ÔÚ֮ǰÕë¶Ô»ªË¶µÄ¹©Ó¦Á´¹¥»÷ShadowHammerÖУ¬ £¬£¬£¬£¬£¬£¬£¬ÖÁÉÙÉÐÓÐÁù¼ÒÑÇÖÞ¹«Ë¾³ÉΪĿµÄ£¬ £¬£¬£¬£¬£¬£¬£¬°üÀ¨Èý¼ÒÓÎÏ·¹«Ë¾£¨Electronics Extreme¡¢Innovative ExtremistºÍZepetto£©ÒÔ¼°Î´Ìá¼°Ãû³ÆµÄÒ»¼ÒÊÓÆµÓÎÏ·¹«Ë¾¡¢Ò»¼Ò×ۺϿعɹ«Ë¾ºÍÒ»¼ÒÖÆÒ©¹«Ë¾¡£¡£¡£¡£¡£¡£¡£ ¡£ÔÚÀÖ³ÉÈëÇÖÊܺ¦Õßϵͳºó£¬ £¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÊͷŵĶñÒâÈí¼þ½«Äܹ»ÍøÂçϵͳÐÅÏ¢²¢´ÓC&CÏÂÔØÆäËüpayload¡£¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/shadowhammer-targets-multiple-companies-asus-just-one-of-them/

3.¹¥»÷ÕßʹÓöñÒâTeamViewerÃé׼ŷÖÞÕþ¸®»ú¹¹ºÍ´óʹ¹Ý

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

Check PointÑо¿Ö°Ô±·¢Ã÷Ò»¸öÕë¶ÔÅ·ÖÞÕþ¸®µÄ²ÆÎñ²¿·ÖºÍ´óʹ¹ÝµÄ´¹ÂÚ¹¥»÷»î¶¯£¬ £¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÏòÄ¿µÄ·¢ËÍÖ÷ÌâΪ¡°¾üÊÂÈÚ×ÊÍýÏ롱µÄ¡°¾øÃÜ¡±´¹ÂÚÓʼþ£¬ £¬£¬£¬£¬£¬£¬£¬Óʼþ¸½´øµÄXLSMÎļþ´øÓÐÃÀ¹ú¹úÎñÔºµÄlogo£¬ £¬£¬£¬£¬£¬£¬£¬Ò»µ©Êܺ¦Õß·­¿ªXLSMÎĵµ£¬ £¬£¬£¬£¬£¬£¬£¬¶ñÒâºê¾Í»áÏÂÔØ²¢×°ÖöñÒâ°æ±¾µÄTeamViewer£¬ £¬£¬£¬£¬£¬£¬£¬ÒÔÇÔȡϵͳÐÅÏ¢ºÍµÇ¼ƾ֤¡£¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/trojanized-teamviewer-used-in-government-political-attacks-across-europe/

4.Ñо¿Ö°Ô±·¢Ã÷¶ñÒâÈí¼þCarbanakµÄÔ´´úÂëÔÚVirusTotalÉÏй¶


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


FireEyeÑо¿Ö°Ô±·¢Ã÷¶ñÒâÈí¼þCarbanakµÄÔ´´úÂëÔÚVirusTotalÉÏй¶£¬ £¬£¬£¬£¬£¬£¬£¬²¢ÇÒÒѾ­±£´æÁËÁ½ÄêµÄʱ¼ä¡£¡£¡£¡£¡£¡£¡£ ¡£CarbanakÊÇÒ»¸öºóÃÅľÂí£¬ £¬£¬£¬£¬£¬£¬£¬ËüÊÇAPT×éÖ¯FIN7µÄµÚ¶þ´ú¶ñÒâÈí¼þ³ÌÐò£¬ £¬£¬£¬£¬£¬£¬£¬±»ÓÃ×÷ÈëÇÖÒøÐÐÍøÂçµÄÖ÷Òª¹¤¾ß¡£¡£¡£¡£¡£¡£¡£ ¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄ˵·¨£¬ £¬£¬£¬£¬£¬£¬£¬VirusTotalÉϱ£´æÁ½¸ö°üÀ¨CarbanakÔ´´úÂëµÄѹËõÎļþ£¬ £¬£¬£¬£¬£¬£¬£¬ÎļþÖаüÀ¨Carbanak¼°ÒÔǰδ֪µÄ²å¼þµÄÍêÕûÔ´´úÂ룬 £¬£¬£¬£¬£¬£¬£¬´úÂëÐÐÊýÁè¼Ý10ÍòÐС£¡£¡£¡£¡£¡£¡£ ¡£ÕâЩԴ´úÂë¿ÉÒÔ×ÊÖúFireEye¸üºÃµØÆÊÎö¸Ã¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/source-code-of-carbanak-trojan-found-on-virustotal/

5.Evisort¹«Ë¾ElasticsearchÊý¾Ý¿âÒòÉèÖùýʧй¶¿Í»§Êý¾Ý


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


EvisortÊÇÒ»¼ÒÎļþºÍÌõÔ¼ÖÎÀí¹«Ë¾£¬ £¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄÒ»¸öElasticsearchÎļþÊý¾Ý¿âδÉèÃÜÂ룬 £¬£¬£¬£¬£¬£¬£¬µ¼Ö²¿·Ö¿Í»§µÄÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£ ¡£Æ¾Ö¤TechCrunchµÄ±¨¸æ£¬ £¬£¬£¬£¬£¬£¬£¬ËäÈ»Êý¾Ý¿âÖеÄһЩÎļþ±»±ê¼ÇΪ¡°ÐéÄ⡱ºÍ¡°²âÊÔ¡±£¬ £¬£¬£¬£¬£¬£¬£¬µ«Ò²ÓÐÐí¶àÎĵµ°üÀ¨¿Í»§Êý¾Ý£¬ £¬£¬£¬£¬£¬£¬£¬ÀýÈçÔ±¹¤ÌõÔ¼¡¢´û¿îЭÒé¡¢¼òÀú¼°ÓëÈýÐÇÇ©ÊðµÄ±£ÃÜЭÒéµÈ¡£¡£¡£¡£¡£¡£¡£ ¡£ÔÚ½Óµ½±¨¸æºó£¬ £¬£¬£¬£¬£¬£¬£¬EvisortÔÚһСʱÄÚÒÆ³ýÁ˸ÃÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2019/04/22/evisort-data-exposed/

6.WannaCryÓ¢ÐÛMarcus HutchinsÈÏ× £¬£¬£¬£¬£¬£¬£¬ÃæÁÙ×î¸ßÊ®Äêî¿Ïµ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ôø±»ÊÓΪ»÷°ÜWannaCryµÄÓ¢ÐÛµÄÓ¢¹úÇå¾²Ñо¿Ö°Ô±Marcus HutchinsÓÚ¿ËÈÕÔÚÃÀÍõ·¨ÔºÈÏ× £¬£¬£¬£¬£¬£¬£¬ÈÏ¿ÉÔø½¨ÉèºÍ·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£ ¡£HutchinsÔÚ2017Äê8ÔÂ2ÈÕ¼ÓÈëÍêBlack HatºÍDEFCON´ó»áºó±»²¶£¬ £¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÉó²éÔº¶ÔÆäÌá³öÁËÊ®ÏîÖ¸¿Ø£¬ £¬£¬£¬£¬£¬£¬£¬Æ¾Ö¤HutchinsÇ©ÊðµÄÈÏ×ïЭÒ飬 £¬£¬£¬£¬£¬£¬£¬ËûÈÏ¿ÉÁËÁ½Ïî×ïÃû£¬ £¬£¬£¬£¬£¬£¬£¬¼ì·½½«×÷·ÏÆäËü×ïÃû¡£¡£¡£¡£¡£¡£¡£ ¡£ÕâÁ½Ïî×ïÃûÊǼÓÈ뽨ÉèºÍ·Ö·¢¶ñÒâÈí¼þÒÔ¼°Ìô²¦ºÍЭÖú·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£ ¡£Á½Ïî×ïÃûÏà¼Ó£¬ £¬£¬£¬£¬£¬£¬£¬Hutchins½«ÃæÁÙ×î¸ßÊ®ÄêµÄî¿Ïµ¡£¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/security-researcher-malwaretech-pleads-guilty-faces-10-years-in-prison-479f3ac1