ʹÓÃGoogle Play·Ö·¢µÄÐÂľÂíXenomorphÕë¶ÔÅ·ÖÞµØÇø

Ðû²¼Ê±¼ä 2022-02-24

ʹÓÃGoogle Play·Ö·¢µÄÐÂľÂíXenomorphÕë¶ÔÅ·ÖÞµØÇø


¾ÝýÌå2ÔÂ21ÈÕ±¨µÀ £¬Çå¾²¹«Ë¾ThreatFabric·¢Ã÷ÁËеÄAndroidÒøÐÐľÂíXenomorph¡£¸ÃľÂíαװ³ÉÐÔÄÜÌáÉýÓ¦ÓóÌÐò£¨ÀýÈçFast Cleaner£©Í¨¹ýGoogle PlayÊÐËÁ·Ö·¢ £¬Òѱ»×°ÖÃÁè¼Ý50000´Î¡£ËüÏÖÔÚÈÔ´¦ÓÚÔçÆÚ¿ª·¢½×¶Î £¬Ä¿µÄÊÇÎ÷°àÑÀ¡¢ÆÏÌÑÑÀ¡¢Òâ´óÀûºÍ±ÈÀûʱµÈÅ·ÖÞ¹ú¼ÒµÄ56¼Ò½ðÈÚ»ú¹¹¡£Ñо¿Ö°Ô±»¹·¢Ã÷¸ÃľÂíµÄ´úÂëÓëAlienÓÐËùÖØµþ £¬ÕâÅú×¢¶þÕß±£´æÄ³ÖÖÁªÏµ£ºÒªÃ´XenomorphÊÇAlienµÄ¼ÌÈÎÕß £¬ÒªÃ´XenomorphµÄ¿ª·¢Ö°Ô±Ò»Ö±ÔÚÑо¿Alien¡£


https://thehackernews.com/2022/02/xenomorph-android-banking.html


ÃÀ¹úMeyerÔâµ½ContiÀÕË÷¹¥»÷µ¼Ö´ó×ÚÔ±¹¤ÐÅϢй¶


¾Ý2ÔÂ21ÈÕ±¨µÀ £¬ÃÀ¹ú×î´óµÄ´¶¾ß¹«Ë¾MeyerÔâµ½ContiÀÕË÷¹¥»÷¡£¹¥»÷±¬·¢ÔÚ2021Äê10ÔÂ25ÈÕ £¬¼ì²âµ½¹¥»÷ºó¸Ã¹«Ë¾Á¬Ã¦Õö¿ªÊÓ²ì £¬²¢ÓÚ12ÔÂ1ÈÕÈ·¶¨MeyerÔ±¹¤µÄÐÅÏ¢¿ÉÄÜÒÑÔ⵽δ¾­ÊÚȨµÄ»á¼û¡£Ñо¿Ö°Ô±ÔÚContiµÄÐÅÏ¢Ð¹Â¶ÍøÕ¾·¢Ã÷Ò»¸ö¿É×·Ëݵ½11ÔÂ7ÈÕµÄÁбí £¬¾Ý³Æ°üÀ¨ÁËÔÚMeyerÇÔÈ¡µÄ2%µÄÊý¾Ý £¬µ«ÖÁ½ñÈÔδÐû²¼Ê£ÓàµÄ98%¡£MeyerÌåÏÖ½«ÎªÊÜÓ°ÏìµÄÔ±¹¤¼°Æä¾ìÊôÌṩÁ½ÄêµÄÉí·Ý±£»¤·þÎñ¡£


https://www.bleepingcomputer.com/news/security/cookware-giant-meyer-discloses-cyberattack-that-impacted-employees/


Ahn Lab·¢Ã÷CryptBotбäÌåʹÓõÁ°æÈí¼þÍøÕ¾Èö²¥


Ahn LabÔÚ2ÔÂ21ÈÕÐû²¼µÄÑо¿ÏÔʾ £¬CryptBotбäÌåÕýÔÚͨ¹ýµÁ°æÈí¼þÍøÕ¾¾ÙÐÐÈö²¥¡£CryptBotÊÇÒ»ÖÖWindowsÐÅÏ¢ÇÔÈ¡³ÌÐò £¬¿É´ÓÄ¿µÄÇÔÈ¡ä¯ÀÀÆ÷ƾ֤¡¢cookie¡¢¼ÓÃÜÇ®±ÒÇ®°üºÍÐÅÓÿ¨µÈÐÅÏ¢¡£¹¥»÷ÕßʹÓÃÆÆ½âÈí¼þºÍÃÜÔ¿ÌìÉúÆ÷µÈÍøÕ¾·Ö·¢¶ñÒâÈí¼þ £¬²¢Í¨¹ýËÑË÷ÒýÇæÓÅ»¯½«ÕâÐ©ÍøÕ¾ÔڹȸèµÄËÑË÷Ч¹ûÖÐÖö¥¡£±ðµÄ £¬¸Ã°æ±¾±ÈÒÔÍùÓнϴóµÄ¸Ä¶¯ £¬É¾³ýÁË·´É³ºÐ¹¦Ð§ºÍ±¸ÓÃC2µÈÈßÓàµÄ¹¦Ð§ £¬²¢ÒÑ¿ÉÊÊÓÃÓÚËùÓÐChrome°æ±¾¡£


https://asec.ahnlab.com/en/31802/


KasperskyÐû²¼2021ÄêÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄÆÊÎö±¨¸æ


2ÔÂ21ÈÕ £¬KasperskyÐû²¼ÁË2021ÄêÒÆ¶¯¶ñÒâÈí¼þÌ¬ÊÆµÄÆÊÎö±¨¸æ¡£±¨¸æÖ¸³ö £¬KasperskyÔÚ2021Äê×ܼƼì²âµ½3464756¸ö¶ñÒâ×°Öðü¡¢97661¸öеÄÒÆ¶¯ÒøÐÐľÂíºÍ17372¸öеÄÒÆ¶¯ÀÕË÷Èí¼þ¡£ÊÜÒÆ¶¯¶ñÒâÈí¼þ¹¥»÷×î¶àµÄ¹ú¼ÒÊÇÒÁÀÊ £¬Æä´ÎÊÇÖйú¡¢É³Ìذ¢À­²®ºÍ°¢¶û¼°ÀûÑÇ¡£¼ì²âµ½µÄ¶ñÒâÈí¼þÖÐ¹ã¸æÈí¼þ£¨42.42%£©µÄÕ¼±È×î´ó £¬Æä´ÎΪRiskToolÓ¦ÓóÌÐò£¨35.27%£©ºÍľÂí£¨8.86%£©¡£


https://securelist.com/mobile-malware-evolution-2021/105876/


Trend MicroÅû¶ÐµÄMac¶ñÒâÍÚ¿óÈí¼þµÄÊÖÒÕϸ½Ú


Trend MicroÔÚ2ÔÂ21ÈÕÅû¶ÁËÐÂMac¶ñÒâÍÚ¿óÈí¼þµÄÊÖÒÕϸ½Ú¡£¶ñÒâÈí¼þÑù±¾±»¼ì²âΪCoinminer.MacOS.MALXMR.H £¬ÓÚ2022Äê1Ô³õÊ״α»·¢Ã÷ £¬ÊÇÒ»¸öMach-OÎļþ¡£Ö´ÐÐʱ £¬ËüʹÓÃAuthorizationExecuteWithPrivileges APIͨ¹ýÌáÐÑÓû§ÊäÈëÆ¾Ö¤À´ÌáÉýȨÏÞ¡£³ý´ËÖ®Íâ £¬¸ÃÑù±¾»¹Ê¹ÓÃÁËi2pd£¨ÓÖÃûI2PÊØ»¤³ÌÐò£©À´Òþ²ØÆäÍøÂçÁ÷Á¿ £¬¶øÆäËüMac¶ñÒâÈí¼þͨ³£Ê¹ÓÃTor¡£


https://www.trendmicro.com/en_us/research/22/b/latest-mac-coinminer-utilizes-open-source-binaries-and-the-i2p-network.html


Ñо¿ÍŶӷ¢Ã÷Õë¶ÔMicrosoft SQLÊý¾Ý¿âµÄ¹¥»÷Ô˶¯


ýÌå2ÔÂ21ÈÕ³Æ £¬Ñо¿ÍŶӷ¢Ã÷ÁËÕë¶ÔMicrosoft SQLÊý¾Ý¿âµÄ¹¥»÷Ô˶¯¡£¹¥»÷ÕßÊ×ÏÈɨÃèTCP¶Ë¿Ú1433¿ª·ÅµÄ·þÎñ £¬È»ºóͨ¹ý±©Á¦ÆÆ½âºÍ×ֵ乥»÷À´ÆÆ½âÃÜÂë¡£Ò»µ©»ñµÃ¹ÜÀíÔ±ÕÊ»§µÄ»á¼ûȨÏÞ £¬¹¥»÷Õ߾ͻáÁ¬Ã¦×°ÖÃLemon Duck¡¢KingMinerºÍVollgarµÈ¶ñÒâ¿ó¹¤Èí¼þ¡£×îºó £¬ËûÃÇ»¹»áʹÓÃCobalt StrikeÔÚÊý¾Ý¿âÖн¨ÉèºóÃÅ £¬ÒÔ¼á³Ö³¤ÆÚÐÔ²¢¾ÙÐкáÏòÒÆ¶¯¡£


https://www.bleepingcomputer.com/news/security/vulnerable-microsoft-sql-servers-targeted-with-cobalt-strike/



Çå¾²¹¤¾ß


coraza


golang ÆóÒµ¼¶ Web Ó¦Ó÷À»ðǽ¿ò¼Ü £¬Ö§³Ö Modsecurity µÄ seclang ÓïÑÔ £¬Óë OWASP Core Ruleset 100% ¼æÈÝ¡£


https://github.com/corazawaf/coraza


m3


ÒÆ¶¯¶ñÒâÈí¼þÄ£Äâ¿ò¼Ü£¨¼ò³Æm3£©ÊÇÒ»¸ö¼òÆÓÇÒ¿ÉÀ©Õ¹µÄ Android »úеÈËÄ£Äâ¿ò¼Ü¡£


https://github.com/ThisIsLibra/m3/


SecureBank


°üÀ¨ËùÓÐ OWASP TOP 10 Çå¾²Îó²îµÄ½ðÈڿƼ¼Ó¦ÓóÌÐò¡£


https://ssrd.gitbook.io/securebank/


Talisman 


¿É½«hook×°Öõ½´æ´¢¿â £¬ÒÔÈ·±£Ç±ÔÚµÄÃô¸ÐÐÅÏ¢²»»áÍÑÀ뿪·¢Ö°Ô±µÄÊÂÇéÕ¾¡£


https://github.com/thoughtworks/talisman#what-is-talisman


SharpCookieMonster


cookie-crimesÄ£¿éµÄÒ»¸ö Sharp ¶Ë¿Ú £¬Õâ¸ö C# ÏîÄ¿½«ÎªËùÓÐÕ¾µãת´¢ cookie¡£


https://github.com/m0rv4i/SharpCookieMonster



Çå¾²ÆÊÎö


ÕûÊýÒç³ö£ºËüÊÇÔõÑù±¬·¢µÄÒÔ¼°ÔõÑùÔ¤·À


https://www.welivesecurity.com/2022/02/21/integer-overflow-how-it-occur-can-be-prevented/


¹¥»÷ÕßʹÓÃSMS PVA ·þÎñ¾ÙÐжñÒâÔ˶¯


https://securityaffairs.co/wordpress/128242/cyber-crime/sms-pva-services.html


ÆÏÌÑÑÀÍþв±¨¸æ£º2021 ÄêµÚËÄÐò¶È


https://seguranca-informatica.pt/threat-report-portugal-q3-2021/


΢Èí¸üÐÂÁË Your Phone Ó¦ÓóÌÐòµÄÒ»Ïîй¦Ð§


https://news.softpedia.com/news/microsoft-announces-a-new-feature-for-the-your-phone-app-534911.shtml


CVE-2022-0290£ºChrome RenderFrameHostImplÊͷźóʹÓÃÎó²î


https://packetstormsecurity.com/files/166080/GS20220221155706.tgz