TrickBotͨ¹ý¼ì²éÆÁÄ»Çø·ÖÂÊÌӱܲ¡¶¾ÆÊÎö£»£»£»£»£»ÐÂÀÕË÷Èí¼þEvilQuestÕë¶ÔMacϵͳ£¬£¬£¬Í¨¹ýµÁ°æÈí¼þÈö²¥
Ðû²¼Ê±¼ä 2020-07-021.¶ñÒâÈí¼þTrickBotͨ¹ý¼ì²éÆÁÄ»Çø·ÖÂÊÒÔÌӱܲ¡¶¾ÆÊÎö
ÍøÂçÇå¾²¹«Ë¾MalwareLab·¢Ã÷¶ñÒâÈí¼þTrickBotÒѾ×îÏÈͨ¹ý¼ì²éÊܺ¦ÕߵįÁÄ»Çø·ÖÂÊ£¬£¬£¬À´¼ì²âÆäÊÇ·ñÔÚÐéÄâ»úÖÐÔËÐУ¬£¬£¬ÒÔÌÓ±ÜÑо¿Ö°Ô±»ò×Ô¶¯É³Ïäϵͳ¶ÔÆä¾ÙÐÐÆÊÎö¡£¡£¡£¡£¡£¡£¡£ÐµÄTrickBotÑù±¾ÕýÔÚ¼ì²éÅÌËã»úµÄÆÁÄ»Çø·ÖÂÊÊDz»ÊÇ800x600»ò1024x768£¬£¬£¬ÈôÊÇÊÇ£¬£¬£¬TrickBotÔò»áÁ¬Ã¦ÖÕÖ¹¡£¡£¡£¡£¡£¡£¡£TrickBot¼ì²éÕâÐ©ÌØÊâµÄÇø·ÖÂÊ£¬£¬£¬ÊÇÓÉÓÚÑо¿Ö°Ô±Í¨³£ÊÇÕâÑùÉèÖÃËûÃǵÄÐéÄâ»ú¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/trickbot-malware-now-checks-screen-resolution-to-evade-analysis/
2.Ó¡¶È¹ú¼Ò¹«Â·¾Ö(NHAI)ϵͳÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ÏÖÒѻָ´
Ó¡¶È¹ú¼Ò¹«Â·ÖÎÀí¾Ö£¨NHAI£©ÓÚÉÏÖÜÈÕÍíÉÏÔâµ½ÁËÀÕË÷Èí¼þµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¾Ý¸Ã²¿·ÖÔ±¹¤Ëµ£¬£¬£¬¸Ã¶ñÒâÈí¼þ¹¥»÷ÁËÕþ¸®µÄµç×ÓÓʼþϵͳ£¬£¬£¬¿ÉÄÜÒ²Ó°ÏìÁËÒÑÍùÊ®ÄêÀ´¸ßËÙ¹«Â·ÉϵĴó×ÚÊý¾ÝºÍÉñÃØÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£µ«ØÊºó£¬£¬£¬NHAI½²»°ÈËÌåÏÖ£¬£¬£¬´Ë´Î¹¥»÷ûÓÐÀֳɣ¬£¬£¬ÏÖÔÚϵͳÏÖÒѻָ´£¬£¬£¬Ã»Óб¬·¢Êý¾Ýɥʧ£¬£¬£¬NHAIÊý¾ÝºÍÆäËûϵͳÈÔûÓÐÊܵ½´Ë´Î¹¥»÷µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¾ÝSophos³Æ£¬£¬£¬Ó¡¶ÈÔÚÍøÂç·ÀÓù·½ÃæÎª±¡Èõ»·½Ú£¬£¬£¬½öÈ¥Äê¾ÍÓÐ82£¥µÄÓ¡¶È×éÖ¯Ôâµ½ÀÕË÷Èí¼þµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hindustantimes.com/india-news/nhai-server-attacked-by-malware-govt-says-no-data-loss/story-wGDAcPUo4MWzPLOcqu2WZJ.html
3.Ê©ÀÖ¹«Ë¾Ôâµ½MazeÀÕË÷Èí¼þ¹¥»÷²¢Ð¹Â¶Áè¼Ý100GBÎļþ
ºÚ¿Í×éÖ¯MazeÓÚ6ÔÂ25ÈÕ¶ÔÊ©ÀÖ¹«Ë¾ÌᳫÁËÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬¸Ã¹«Ë¾ÖÁÉÙÒ»¸öXeroxÓòÖеÄÅÌËã»ú±»¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£¾Ý¹¥»÷Õ߳ƣ¬£¬£¬ËûÃÇÒѾ´ÓÊ©ÀÖ¹«Ë¾ÇÔÈ¡ÁËÁè¼Ý100GBµÄÎļþ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß·ÖÏíµÄÆÁÄ»½ØÍ¼ÏÔʾ£¬£¬£¬ÓÉXerox CorporationÖÎÀíµÄ¡° eu.xerox.net¡±ÉϵÄÖ÷»úÊܵ½Á˹¥»÷£¬£¬£¬¸ÃÖ÷»úÃûºÍÓòÃûÌåÏÖÕâ¿ÉÄÜÊÇXeroxÔÚÂ׶صķֹ«Ë¾¡£¡£¡£¡£¡£¡£¡£MazeÀÕË÷Èí¼þ½üÆÚÒ»Ö±ÔÚ¹¥»÷ÖÁ¹«Ë¾£¬£¬£¬¸Ã×éÖ¯Éù³Æ×î½ü¹¥»÷µÄ¹«Ë¾°üÀ¨LGµç×Ó¡¢Ð¾Æ¬ÖÆÔìÉÌMaxLinear¡¢IT¾ÞÍ·CognizantºÍÉÌҵЧÀ͹«Ë¾Conduent¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/business-giant-xerox-allegedly-suffers-maze-ransomware-attack/
4.ÐÂÀÕË÷Èí¼þEvilQuestÕë¶ÔMacϵͳ£¬£¬£¬Í¨¹ýµÁ°æÈí¼þ°üÈö²¥
Çå¾²Ñо¿Ô±Dinesh Devadoss·¢Ã÷ÁËÒ»ÖÖÓÐÊýµÄÕë¶ÔmacOSµÄÐÂÐÍÀÕË÷Èí¼þEvilQuest£¬£¬£¬Í¨¹ýµÁ°æÈí¼þ°üÈö²¥¡£¡£¡£¡£¡£¡£¡£EvilQuestÓâÔ½ÁËÀÕË÷Èí¼þµÄͨÀý¼ÓÃܹ¦Ð§£¬£¬£¬Ëü»¹Äܹ»°²ÅżüÅ̼ͼ³ÌÐò£¬£¬£¬ÒÔ¼°Äܹ»ÇÔÈ¡¼ÓÃÜÇ®±ÒÇ®°üÎļþ¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÒþ²ØÔÚµÁ°æÈí¼þÖУ¬£¬£¬Ò»µ©Êܺ¦ÕßÏÂÔØÁËÕâЩ¶ñÒâ³ÌÐò£¬£¬£¬Æä½«»á×°ÖÃÒ»¸öÃûΪ¡°²¹¶¡¡±µÄ¿ÉÖ´ÐÐÎļþµ½¡°/Users/Shared/¡±Ä¿Â¼ÖУ¬£¬£¬È»ºó£¬£¬£¬Å²Óá°eip_encrypt¡±º¯Êý¼ÓÃÜÊܺ¦ÕßµÄÎļþ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/evilquest-mac-ransomware-keylogger-crypto-wallet-stealing/157034/
5.Googleɾ³ý25¸ö¶ñÒâAndroidÓ¦Ó㬣¬£¬¿ÉÇÔÈ¡Facebookƾ֤
¹È¸è±¾ÔÂ´ÓÆäÊÐËÁÖÐɾ³ýÁË25¸öÓÃÀ´ÇÔÈ¡Facebookƾ֤µÄAndroidÓ¦Ó㬣¬£¬ÏÖÔÚËüÃǵÄÏÂÔØÁ¿×ܼÆÁè¼Ý234Íò´Î¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤·¨¹úÇå¾²¹«Ë¾EvinaµÄ±¨¸æ£¬£¬£¬ÕâЩӦÓðüÀ¨¼Æ²½Æ÷¡¢Í¼Ïñ±à¼Æ÷¡¢ÊÓÆµ±à¼Æ÷¡¢Ç½Ö½Ó¦Óá¢ÊÖµçͲӦÓá¢ÎļþÖÎÀíÆ÷ºÍÊÖ»úÓÎÏ·¡£¡£¡£¡£¡£¡£¡£ËûÃǾùÊÇÊÇÓÉͳһºÚ¿Í×éÖ¯¿ª·¢µÄ£¬£¬£¬Ö»¹Ü¹¦Ð§²î±ð£¬£¬£¬µ«ÊÂÇéÔÀí¶¼ÊÇÏàͬµÄ¡£¡£¡£¡£¡£¡£¡£ËüÏȼì²âÓû§×î½ü·¿ªÁËʲôӦÓ㬣¬£¬ÈôÊÇÊÇFacebook£¬£¬£¬¸Ã¶ñÒâÓ¦Óý«ÔÚ¹Ù·½FacebookÓ¦ÓõĶ¥²¿ÁýÕÖÒ»¸öWebä¯ÀÀÆ÷´°¿Ú£¬£¬£¬²¢¼ÓÔØ¼ÙµÄFacebookµÇÂ¼Ò³Ãæ£¬£¬£¬ÓÃÀ´ÇÔÈ¡Óû§µÇ¼ƾ֤¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/google-removes-25-android-apps-caught-stealing-facebook-credentials/
6.FakeSpyð³äÓÊÕþЧÀÍÕë¶ÔÃÀ¹ú¡¢ÖйúºÍÅ·ÖÞÓû§ÇÔÈ¡²ÆÎñÐÅÏ¢
Çå¾²¹«Ë¾Cybereason·¢Ã÷£¬£¬£¬ÔÚÒÑÍùµÄ¼¸ÖÜÄÚ£¬£¬£¬FakeSpyÕýð³äÖÖÖÖÓÊÕþЧÀÍÀ´¹¥»÷ÃÀ¹ú¡¢ÖйúºÍÅ·ÖÞµÄÓû§£¬£¬£¬ÒÔÇÔÈ¡Æä²ÆÎñÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ºÚ¿Íͨ¹ý·¢ËÍαÔìµÄ¶ÌОÙÐй¥»÷£¬£¬£¬µ±Êܺ¦Õßµã»÷ÕâЩ¶ÌÐÅʱ£¬£¬£¬Òþ²ØµÄ´úÂë¾Í»áÇÔÈ¡²ÆÎñÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÊÇͨ¹ý·¢ËͶÌОÙÐй¥»÷£¬£¬£¬ËûÃDz»ÐèÒªÈëÇֹȸèÓÎÏ·ÊÐËÁÀ´Ö²ÈëÆä¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ºÚ¿Í»¹Í¨¹ý±àдÊÖ»ú¶ñÒâÈí¼þ¹¤¾ß°ü£¬£¬£¬µ÷½â´úÂëÒÔÕë¶ÔÌìÏÂÉϲî±ðµØÇø£¬£¬£¬ÒÔ×·Çó×îÓÐÀû¿ÉͼµÄ¹¥»÷·½·¨¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cyberscoop.com/fakespy-android-cybereason-postal-service/


¾©¹«Íø°²±¸11010802024551ºÅ