KasperskyÔÚGoogle play·¢Ã÷¶à¸öľÂí»¯Telegram
Ðû²¼Ê±¼ä 2023-09-121¡¢KasperskyÔÚGoogle play·¢Ã÷¶à¸öľÂí»¯Telegram
KasperskyÔÚ9ÔÂ8ÈÕ³ÆÆäÔÚGoogle PlayÉÏ·¢Ã÷Á˶à¸ö¶ñÒâ°æ±¾TelegramÓ¦Ó᣸ÃÔ˶¯±»×·×ÙΪEvil Telegram£¬¶ñÒâÑù±¾µÄ×°ÖÃÁ¿Áè¼Ý60000´Î¡£ÕâЩTelegramÓ¦Óñ»Ðû´«ÎªÍ¨ÀýÓ¦ÓóÌÐòµÄ¡°¸ü¿ì¡±Ì滻Ʒ£¬ËüÃÇÍâòÉÏÓëÔ°æTelegramÏàͬ£¬µ«´úÂëÖаüÀ¨ÇÔÈ¡Êý¾ÝµÄ¸½¼Ó¹¦Ð§£¬ÇÔÈ¡ID¡¢ÐÕÃûºÍµç»°µÈÐÅÏ¢¡£±ðµÄ£¬µ±Óû§Í¨¹ýľÂíÓ¦ÓóÌÐòÊÕÐÂÎÅʱ£¬¶ñÒâÈí¼þ»áÖ±½Ó½«¸±±¾·¢Ë͵½¹¥»÷ÕßµÄC2£¬°üÀ¨ÐÂÎÅÄÚÈÝ¡¢Ì¸ÌìÎÊÌâºÍID£¬ÒÔ¼°·¢ËÍÕßÐÕÃûºÍIDµÈ£¬Ð¹Â¶µÄÊý¾ÝÔÚ´«ÊäÇ°»¹»á±»¼ÓÃÜ¡£ÏÖÔÚ£¬GoogleÒѽ«ËùÓжñÒâÓ¦ÓôÓPlayÊÐËÁÖÐɾ³ý¡£
https://securelist.com/trojanized-telegram-mod-attacking-chinese-users/110482/
2¡¢Google½ôÆȸüÐÂÐÞ¸´ChromeÖб»Ê¹ÓÃÎó²îCVE-2023-4863
¾ÝýÌå9ÔÂ11ÈÕ±¨µÀ£¬GoogleÐû²¼Á˽ôÆÈÇå¾²¸üУ¬ÐÞ¸´½ñÄêÄêÍ·ÒÔÀ´µÚ4¸öÒѱ»Ê¹ÓõÄChromeÎó²î£¨CVE-2023-4863£©¡£ÕâÊÇWebPÖеÄÒ»¸ö¶Ñ»º³åÇøÒç³öÎó²î£¬ÆäÓ°Ïì¹æÄ£´ÓÍ߽⵽í§Òâ´úÂëÖ´ÐС£ËäÈ»GoogleÌåÏÖ¸ÃÎó²îÒÑÔÚҰʹÓ㬵«ÔÚ´ó´ó¶¼Óû§¸üÐÂ֮ǰ£¬¸Ã¹«Ë¾²»»á¹ûÕæ¹¥»÷µÄ¸ü¶àϸ½Ú¡£Citizen LabÅú×¢£¬¸ÃÎó²î¿ÉÄܱ»ÓÃÀ´¹¥»÷ýÌå´ÓÒµÕßµÈ×ÅÃûÈËÊ¿¡£Ð°汾ÏÖÔÚÕýÔÚÏòÎȹ̰æºÍÀ©Õ¹Îȹ̰æµÄÓû§ÍƳö£¬Ô¤¼Æ½«ÔÚδÀ´¼¸Ìì»ò¼¸ÖÜÄÚÁýÕÖÕû¸öÓû§Èº¡£
https://www.bleepingcomputer.com/news/google/google-fixes-another-chrome-zero-day-bug-exploited-in-attacks/
3¡¢TheSnakeÔÚ°µÍø¹ûÕæCoca-Cola FEMSAµÄ²¿·ÖÊý¾Ý
¾Ý9ÔÂ8ÈÕ±¨µÀ£¬TheSnakeÔÚºÚ¿ÍÂÛ̳ÉϹûÕæÁËCoca-Cola FEMSAµÄ²¿·ÖÊý¾Ý¡£Coca-Cola FEMSAÊÇÊÊ¿Ú¿ÉÀÖÔÚÀ¶¡ÃÀÖ޴󲿷ֵØÇøµÄ×°Æ¿ÉÌ£¬¹ûÕæµÄÊý¾Ý¹²8.16GB¡£TheSnake³Æ»á¼ûÁ˸ù«Ë¾Á½´Î£¬»®·ÖÔÚ2022Äê4ÔºÍ2023Äê6Ô£¬¿ÉÒÔ»á¼ûÁè¼Ý200GBµÄ¹«Ë¾Êý¾Ý¡£»¹Í¸Â¶ËûÃÇÒªÇó1200ÍòÃÀÔªÀ´É¾³ý±»µÁÎļþ£¬µ«¸Ã¹«Ë¾½»ÁË150ÍòÃÀÔª±ÜÃâÌض¨Îļþй¶¡£ÆäÓàÎļþÒÔ6.5ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛ¡£AlphVÔøÌåÏÖ¹¥»÷Á˸ù«Ë¾²¢ÓÚ6ÔÂ10ÈÕй¶Êý¾Ý£¬ÏÖÔÚÎÞ·¨È·¶¨Á½Õß鶵ÄÊý¾ÝÊÇ·ñÏàͬ¡£µ±±»Îʼ°´ËÊÂʱ£¬TheSnake·ñ¶¨´ÓAlphV»ñµÃÁËÈκÎÊý¾Ý£¬²¢ÌåÏÖÆäÏàÖúͬ°éÊÇStormous¡£
https://www.databreaches.net/coca-cola-femsa-victim-of-ransomware-attack-and-data-leak/
4¡¢See TicketsÔâWeb Skimmer¹¥»÷30ÍòÈËÒøÐп¨Ð¹Â¶
ýÌå9ÔÂ7ÈÕ±¨µÀ£¬Æ±Îñ·þÎñ»ú¹¹See TicketsÒÑ֪ͨÁè¼Ý300000ÈË£¬ËûÃǵÄÖ§¸¶¿¨ÐÅÏ¢ÔÚWeb Skimmer¹¥»÷Öб»µÁ¡£5Ô·ݣ¬See TicketÒâʶµ½ÆäijЩµçÉÌÍøÕ¾Éϱ£´æÒì³£Ô˶¯¡£ÊӲ췢Ã÷£¬5ÔºÍ6Ô£¬¹¥»÷ÕßÔÚһЩµçÉ̽áÕËÒ³ÃæÖÐ×¢ÈëÁ˶à¸ö¶ñÒâ´úÂëʵÀý¡£´Ó2ÔÂ28ÈÕµ½7ÔÂ2ÈÕ£¬ÕâЩ¶ñÒâ´úÂëÍøÂç²¢ÇÔÈ¡ÁËÓû§ÔÚ½áÕËÒ³ÃæÉÏÌṩµÄÐÅÏ¢£¬°üÀ¨ÐÕÃû¡¢µØµãºÍÖ§¸¶¿¨ÐÅÏ¢¡£See TicketsÌåÏÖÒÑʵÑéÌØÁíÍâ²½·¥À´±£»¤ÆäÍøÒ³ÉϵÄÖ§¸¶¿¨ÐÅÏ¢¡£
https://www.securityweek.com/see-tickets-alerts-300000-customers-after-another-web-skimmer-attack/
5¡¢Ë¹ÀïÀ¼¿¨¹ú¼Òµç×ÓÓʼþÓòÃûÔâµ½ÀÕË÷¹¥»÷²¿·ÖÊý¾Ýɥʧ
¾Ý9ÔÂ10ÈÕ±¨µÀ£¬Ë¹ÀïÀ¼¿¨°üÀ¨ÄÚ¸ó°ì¹«ÊÒÔÚÄÚµÄËùÓÐʹÓá°gov.lk¡±ÓòµÄÓÊÏ䶼ɥʧÁË5ÔÂ17ÈÕÖÁ8ÔÂ26ÈÕµÄÊý¾Ý¡£ÀÕË÷¹¥»÷±¬·¢ÓÚ8ÔÂ26ÈÕ£¬µ¼ÖÂÍøÕ¾±»¼ÓÃÜ¡£ËäÈ»ÐÅÏ¢ºÍͨѶÊÖÒÕ¾Ö(ICTA)ÔÚLGNÔÆÖÐά»¤Á˶à¸ö±¸·Ý£¬µ«±»ÈëÇÖ·þÎñÆ÷µÄ¼ÓÃÜÀú³ÌÈ´±»¸´ÖƵ½ÁËÔÚÏß±¸·ÝϵͳÖС£ÏµÍ³ÔÚ12СʱÄھͻָ´ÁË£¬±¸·ÝÒ²»Ö¸´ÁË£¬µ«É¥Ê§Á½¸ö°ëÔµÄÊý¾Ý¡£¸ÃÊÂÎñÓ°ÏìÁËÔ¼5000¸öÓÊÏ䣬ICTA³ÆÒѾ½ÓÄɲ½·¥£¬×îÏÈÖðÈÕÀëÏß±¸·Ý£¬²¢½«Ïà¹ØÓ¦ÓÃÉý¼¶µ½×îа汾£¬ÊµÑéÕÒ»ØɥʧµÄÊý¾Ý¡£
https://srilankamirror.com/news/massive-ransomware-attack-on-state-email-domain/
6¡¢Truesec·¢Ã÷ͨ¹ýTeamsÐÂÎÅ·Ö·¢DarkGateµÄ´¹ÂÚ¹¥»÷
9ÔÂ6ÈÕ£¬Truesec³ÆÆä·¢Ã÷ÁËͨ¹ýMicrosoft TeamsÐÂÎÅ·Ö·¢DarkGate LoaderµÄ´¹ÂÚ¹¥»÷Ô˶¯¡£¸ÃÔ˶¯×îÏÈÓÚ8ÔÂÏÂÑ®£¬ÆäʱÁ½¸ö±»ÈëÇÖµÄÍⲿOffice 365ÕË»§·¢ËÍ°üÀ¨ZIPÎļþ¡°¼ÙÆÚ°²Åű任¡±µÄMicrosoft Teams´¹ÂÚÓʼþ¡£µã»÷¸½¼þ»á´ÓSharePoint URLÏÂÔØZIPÎļþ£¬°üÀ¨Ò»¸öαװ³ÉPDFµÄLNKÎļþ¡£Ñо¿Ö°Ô±ÆÊÎö·¢Ã÷ÆäÖаüÀ¨¶ñÒâVBScript£¬¿É´¥·¢Ñ¬È¾Á´£¬²¢×°ÖÃDarkGate Loader¡£ÎªÁËÈƹý¼ì²â£¬ÏÂÔØÀú³ÌʹÓÃWindows cURL»ñÈ¡¶ñÒâÈí¼þµÄ¿ÉÖ´ÐÐÎļþºÍ¾ç±¾¡£
https://www.truesec.com/hub/blog/darkgate-loader-delivered-via-teams