ÒÔÉ«ÁÐÀí¹¤Ñ§ÔºTechnion±»DarkBitÀÕË÷170ÍòÃÀÔª
Ðû²¼Ê±¼ä 2023-02-14
¾ÝýÌå2ÔÂ12ÈÕ±¨µÀ£¬ÒÔÉ«Áж¥¼âµÄÑо¿ÐÍ´óѧÒÔÉ«ÁÐÀí¹¤Ñ§Ôº£¨Technion£©Ôâµ½ÁËÐÂÀÕË÷ÍÅ»ïDarkBitµÄ¹¥»÷¡£¹¥»÷±¬·¢ÓÚ2ÔÂ12ÈÕ»ò֮ǰ£¬DarkBitÍÅ»ïÒªÇó80±ÈÌØ±Ò£¨Ô¼ºÏ1745200ÃÀÔª£©ÓÃÓÚ½âÃÜ¡£DarkbitÍþвÈôÊÇTechnion²»ÔÚ48СʱÄÚ¸¶Êê½ð£¬ËûÃÇÒª½«½ð¶îÌá¸ß30%¡£µ«Ñо¿Ö°Ô±Ö¸³ö£¬¸ÃÍŶÓËÆºõÊdzöÓÚÕþÖÎÄîÍ·£¬×ÝȻ֪×ãÒªÇó£¬ËûÃÇÒ²²»Ì«¿ÉÄܸø³ö½âÃÜÃÜÔ¿¡£±ðµÄ£¬VX-underground×¢ÖØµ½£¬ÀÕË÷ÐÅÊÇʹÓÃÓ¢Óï·ÒëÆ÷дµÄ¡£
https://securityaffairs.com/142160/hacking/israeli-technion-suffered-ransomware-attack.html
2¡¢°ÙÊ¿ÉÀÖװƿΣº¦Í¶×ʹ«Ë¾µÄСÎÒ˽¼ÒºÍ²ÆÎñÐÅϢй¶
¾Ý2ÔÂ13ÈÕ±¨µÀ£¬ÃÀ¹ú×î´óµÄ°ÙÊ¿ÉÀÖÒûÁÏ×°Æ¿ÉÌPepsi Bottling Ventures LLC±¬·¢ÐÅϢй¶¡£¸Ã¹«Ë¾ÔÚ֪ͨÖÐÚ¹ÊÍ˵£¬Î¥¹æÊÂÎñ±¬·¢ÔÚ2022Äê12ÔÂ23ÈÕ£¬µ«Ö±µ½18Ììºó£¬Ò²¾ÍÊÇ2023Äê1ÔÂ10Èղű»·¢Ã÷£¬ÒÑÖªµÄ×îºóÒ»´Î»á¼ûʱ¼äΪ1ÔÂ19ÈÕ¡£¾ÝÊӲ죬¹¥»÷ÕßÈëÇÖÆäÄÚ²¿ITϵͳװÖÃÁËÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¬²¢ÏÂÔØÁËϵͳÖеIJ¿·ÖÐÅÏ¢£¬Éæ¼°ÐÕÃû¡¢Éí·ÝÖ¤ºÅ¡¢Éç»áÇå¾²ÂëºÍ½ðÈÚÕË»§ÐÅÏ¢µÈ¡£¸Ã¹«Ë¾ÒÑÖØÖÃËùÓÐÃÜÂ룬²¢Í¨ÖªÖ´·¨²¿·Ö£¬»¹½«ÎªÊÜÓ°ÏìµÄСÎÒ˽¼ÒÌṩһÄêµÄÃâ·ÑÉí·Ý¼à¿Ø·þÎñ¡£
https://www.theregister.com/2023/02/14/pepsi_bottling_malware/
3¡¢B&G FoodsÔâµ½DaixinµÄ¹¥»÷Ô¼1000̨Ö÷»ú±»¼ÓÃÜ
ýÌå2ÔÂ12Èճƣ¬Daixin½üÆÚµÄÒ»´ÎÍøÂç¹¥»÷µ¼ÖÂB&G FoodsÔ¼1000̨Ö÷»ú±»¼ÓÃÜ¡£DaixinµÄ½²»°ÈËÌåÏÖ£¬B&GÓÚ2ÔÂ4ÈÕ±»¼ÓÃÜ£¬µ«ËûÃDz»È·¶¨ÊÇ·ñÒѶÔËùÓб¸·Ý¾ÙÐмÓÃÜ£¬²¢ÌåÏָù«Ë¾¿ÉÄÜÒѾ»Ö¸´¡£±ðµÄ£¬ËûÃÇÔÚÍâµØÉÏÁôÏÂÁËÊê½ð¼Í¼²¢·¢ËÍÁËÒ»ÔÙͨѶ£¬µ«B&GһֱûÓлØÓ¦¡£Ñо¿Ö°Ô±³Æ£¬Ð¹Â¶Êý¾ÝÖÐȷʵ°üÀ¨¹«Ë¾ÄÚ²¿Îļþ£¬È»¶ø£¬Õû¸öת´¢ËƺõûÓиüÑÏÖØ»òÉñÃØµÄ¹«Ë¾Îļþ¡¢ÈËÊÂÎļþ»ò³Ð°üÉÌÎļþ¡£
https://www.databreaches.net/b-files-leaked/
4¡¢¼ÓÄôó×î´óµÄÊéµêIndigoÔâµ½¹¥»÷µ¼ÖÂÍøÕ¾ÎÞ·¨»á¼û
2ÔÂ9ÈÕ±¨µÀ³Æ£¬¼ÓÄôó×î´óµÄÁ¬ËøÊéµêIndigo Books & MusicÔâµ½¹¥»÷¡£ÉÏÖÜÈý£¬IndigoÐû²¼ÒòÊÖÒÕÎÊÌâµ¼ÖÂÎÞ·¨»á¼û¸ÃÍøÕ¾£¬ÊµÌåµêµÄÖ÷¹ËÖ»ÄÜÓÃÏÖ½ðÖ§¸¶¡£±ðµÄ£¬ÎÞ·¨¾ÙÐÐÀñÎ│ÉúÒ⣬ÔÚÏß¶©µ¥Ò²¿ÉÄ᷺ܻÆðÑÓ³Ù¡£¼¸¸öСʱºó£¬¸Ã¹«Ë¾³ÆÆäϵͳÔâµ½ÁËÍøÂç¹¥»÷£¬²¢ÇÒÕýÔÚÊÓ²ì´ËÊÂÎñ¡£¸Ã¹«Ë¾Ã»ÓÐ͸¶ÏÖÔÚÇå¾²ÊÂÎñµÄÀàÐÍ£¬µ«ÌåÏÖÕýÔÚÆð¾¢È·¶¨¹¥»÷ÕßÊÇ·ñÏë·¨»á¼û»òÇÔÈ¡Á˿ͻ§Êý¾Ý¡£
https://www.bleepingcomputer.com/news/security/largest-canadian-bookstore-indigo-shuts-down-site-after-cyberattack/
5¡¢ProofpointÅû¶TA866Õë¶ÔÃÀ¹úºÍµÂ¹úµÄ¹¥»÷Ô˶¯
ProofpointÔÚ2ÔÂ8ÈÕÅû¶ÁËÐÂÍþвÍÅ»ïTA866Õë¶ÔÃÀ¹úºÍµÂ¹úµÄ¹¥»÷Ô˶¯¡£¸ÃÔ˶¯ËƺõÊdzöÓÚ¾¼ÃÄîÍ·£¬ÓÚ2022Äê10ÔÂÊ״α»·¢Ã÷£¬²¢Ò»Ö±Ò»Á¬µ½2023Äê¡£¹¥»÷ÖÐʹÓõĴ¹ÂÚÓʼþ°üÀ¨´øÓжñÒâºêµÄMicrosoft Publisher(.pub)¸½¼þ¡¢Á´½Óµ½´øÓкêµÄ.pubÎļþµÄURL£¬»ò°üÀ¨ÏÂÔØÎ£ÏÕJavaScriptÎļþµÄURLµÄPDF¡£Ä¿µÄµã»÷URLºó»á´¥·¢¶à°ì·¨¹¥»÷Á´£¬È»ºóÏÂÔØ²¢Ö´ÐÐTA886µÄ×Ô½ç˵¶ñÒâÈí¼þScreenshotter¡£
https://www.proofpoint.com/us/blog/threat-insight/screentime-sometimes-it-feels-like-somebodys-watching-me
6¡¢AvastÐû²¼2022ÄêµÚËÄÐò¶ÈÍøÂçÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ
2ÔÂ9ÈÕ£¬AvastÐû²¼Á˹ØÓÚ2022ÄêµÚËÄÐò¶ÈÍøÂçÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£±¨¸æÖ¸³ö£¬¹ã¸æÈí¼þÔ˶¯ÔÚ2022ÄêµÚÈý¼¾¶ÈÄ©¿ìËÙÉÏÉý£¬²¢Ò»Á¬µ½2022ÄêµÚËÄÐò¶È³õ¡£¼ÓÃÜ¿ó¹¤Ô˶¯ÕûÌåÂÔÓÐϽµ(4%)£¬×î³£¼ûµÄΪWeb miners¡¢XMRig¡¢CoinBitMinerºÍVMinerµÈ¡£×î³£¼ûµÄÐÅÏ¢ÇÔÈ¡³ÌÐòΪ£¬FormBook¡¢AgentTesla¡¢RedLineºÍLokibot£¬ÊÜ´ËÀà¶ñÒâÈí¼þÓ°Ïì×î´óµÄ¹ú¼ÒÊÇÒ²ÃÅ¡¢°¢¸»º¹ºÍÂíÀï¡£ÀÕË÷Èí¼þµÄ×ÜÊýϽµÁË17%£¬Õ¼½ÏÁ¿´óµÄÊÇSTOP(21%)¡¢WannaCry(20%)ºÍThanatos(2%)¡£
https://decoded.avast.io/threatresearch/avast-q4-2022-threat-report/


¾©¹«Íø°²±¸11010802024551ºÅ