LockBitÍÅ»ïÐû³Æ½«°ä²¼º«¹ú¹ú¶È˰Îñ¾ÖµÄÊý¾Ý

°ä²¼¹¦·ò 2023-04-03

1¡¢LockBitÍÅ»ïÐû³Æ½«°ä²¼º«¹ú¹ú¶È˰Îñ¾ÖµÄÊý¾Ý


¾ÝýÌå4ÔÂ1ÈÕ±¨Â·£¬ÀÕË÷ÍÅ»ïLockBit³ÆÆäÈëÇÖÁ˺«¹ú¹ú¶È˰Îñ¾Ö ¡£3ÔÂ29ÈÕ£¬LockBitÍŻォ¸Ã»ú¹¹Ôö³¤µ½ÆäÍøÕ¾£¬²¢°ä·¢½«ÓÚ4ÔÂ1ÈÕ֮ǰ°ä²¼±»µÁÊý¾Ý ¡£¹ú¶È˰Îñ¾Ö£¨NTS£©×÷Ϊ²ÆÕþ²¿µÄÒ»¸ö±í²¿×éÖ¯ÓÚ1966Äê3ÔÂ3ÈÕ³ÉÁ¢£¬ÖØÒªÕƹÜÄÚ²¿Ë°ÊÕÆÀ¹ÀºÍÕ÷ÊÕ ¡£½ØÖÁ4ÔÂ1ÈÕ£¬¸ÃÍÅ»ïÉÐδ°ä²¼±»µÁÊý¾Ý ¡£µ«ÈôÊǹ¥»÷ÊÇÕæÊµµÄ£¬Õ⽫¶Ôº«¹ú¹«ÃñµÄÒþÖԺͰ²È«×é³ÉÑϳÁÍþв ¡£


https://securityaffairs.com/144342/cyber-crime/lockbit-south-korean-national-tax-service.html


2¡¢TMX Finance¼°Æä×Ó¹«Ë¾Ô¼480Íò¸ö¿Í»§µÄÊý¾Ýй¶


ýÌå3ÔÂ31Èճƣ¬TMX Finance¼°Æä×Ó¹«Ë¾TitleMax¡¢TitleBucksºÍInstaLoanÅû¶ÁËһ·Êý¾Ýй¶ÊÂÎñ£¬Éæ¼°4822580¸ö¿Í»§µÄÊý¾Ý ¡£Õâ¼Ò¼ÓÄôó½ðÈÚ¹«Ë¾°µÊ¾£¬ºÚ¿ÍÔÚ2022Äê12ÔÂÉÏÑ®ÈëÇÖÁËÆäϵͳ£¬µ«ËûÃÇÖ±µ½2023Äê2ÔÂ13Èղŷ¢ÏÖÁ˹¥»÷»î¶¯ ¡£3ÔÂ1ÈÕʵÏÖÄÚ²¿µ÷²éºó£¬TMX·¢ÏÖ¹¥»÷ÕßÔÚ2023Äê2ÔÂ3ÈÕÖÁ14ÈÕÇÔÈ¡Á˿ͻ§µÄÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢»¤Õպš¢¼ÝÕÕºÅÂ롢˰ºÅ¡¢Éç»á°²È«ºÅÂëºÍ½ðÈÚÕË»§ÐÅÏ¢µÈ ¡£´Ë¿Ì£¬¸Ã¹«Ë¾Ö´ÐÐÁ˶˵ã±£»¤ºÍ¼à¿Ø£¬³ÁÖÃÁËËùÓÐÔ±¹¤ÕÊ»§ÃÜÂ룬²¢½«ÎªÓû§ÌṩExperianΪÆÚ12¸öÔµÄÉí·Ý±£»¤·þÎñ ¡£


https://www.bleepingcomputer.com/news/security/consumer-lender-tmx-discloses-data-breach-impacting-48-million-people/


3¡¢Ä£¿é»¯¹¤¾ß¼¯AlienFoxÇÔÈ¡¶à¸öÔÆ·þÎñÌṩÉÌÍ´´¦


3ÔÂ30ÈÕ£¬SentinelLabs³ÆÆä·¢ÏÖÁËÒ»¸öÃûΪAlienFoxµÄй¤¾ß°ü£¬¿É±»ÓÃÓÚÈëÇÖµç×ÓÓʼþºÍÍøÂçÍйܷþÎñ ¡£AlienFoxÊÇÄ£¿é»¯µÄ£¬´óÎÞÊý¹¤¾ß¶¼ÊÇ¿ªÔ´µÄ ¡£¹¥»÷Õß¿ÉʹÓÃÆä´ÓLeakIXºÍSecurityTrailsµÈ°²È«É¨ÃèÆ½Ì¨ÍøÂçÅäÖÃÃýÎóµÄÖ÷»úÁбí ¡£¶øºó£¬AlienFoxʹÓÃÊý¾ÝÌáÈ¡¾ç±¾ÔÚÅäÖÃÃýÎóµÄ·þÎñÆ÷ÖÐËÑË÷ÓÃÓÚ´æ´¢»úÃܵÄÅäÖÃÎļþ£¬ÀýÈçAPIÃÜÔ¿¡¢ÕÊ»§Í´´¦ºÍÉí·ÝÑéÖ¤ÁîÅÆ ¡£¸Ã¶ñÒâÈí¼þ¿ÉÄÜÕë¶Ô1and1¡¢AWS¡¢Bluemail¡¢ExotelºÍGoogle WorkspaceµÈÊ®¼¸¸öÔÆÆ½Ì¨ ¡£


https://www.sentinelone.com/labs/dissecting-alienfox-the-cloud-spammers-swiss-army-knife/


4¡¢WordPress²å¼þElementor ProÖеķì϶Òѱ»ÀûÓÃ


¾Ý3ÔÂ31ÈÕ±¨Â·£¬WordPress²å¼þElementor ProÖеķì϶Òѱ»»ý¼«ÀûÓà ¡£Elementor ProÊÇÒ»¸öWordPressÒ³Ãæ¹¹½¨Æ÷²å¼þ£¬±»³¬¹ý1100Íò¸öÍøÕ¾Ê¹Óà ¡£¸Ã·ì϶ӰÏìÁËv3.11.6¼°¸üµÍ°æ±¾£¬¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÀûÓÃÆä¸ü¸ÄÍøÕ¾ÉèÖã¬ÉõÖÁÆëÈ«ÊÕÊÜÍøÕ¾ ¡£°²È«¹«Ë¾PatchStack»ã±¨³Æ£¬ºÚ¿ÍÔÚ»ý¼«ÀûÓô˲å¼þ·ì϶½«½Ó¼ûÕß³Á¶¨Ïòµ½¶ñÒâÓò£¨¡°away[.]trackersline[.]com¡±£©»ò½«ºóÃÅÉÏ´«µ½±»ÈëÇÖµÄÍøÕ¾ ¡£ÕâЩ¹¥»÷ÖÐÉÏ´«µÄºóÃÅÃûΪwp-resortpark.zip¡¢wp-rate.php»òlll.zip ¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-bug-in-elementor-pro-wordpress-plugin-with-11m-installs/


5¡¢ÎÚ¿ËÀ¼·¨Âɲ¿ÃÅ¿ÛÁôÒÑÇÔÈ¡430ÍòÃÀÔªµÄ´¹µöÍÅ»ï


ýÌå3ÔÂ31ÈÕ±¨Â·³Æ£¬ÎÚ¿ËÀ¼ºÍ½Ý¿ËµÄ·¨ÂÉÈËԱЭͬ¿ÛÁôÁËij´¹µöÍÅ»ïµÄ¼¸Ãû³ÉÔ± ¡£¸ÃÍÅ»ïÕë¶Ô·¨¹ú¡¢Î÷°àÑÀ¡¢²¨À¼¡¢½Ý¿Ë¡¢ÆÏÌÑÑÀµÈÅ·ÖÞ¹ú¶È³ÉÁ¢ÁË100¶à¸ö´¹µöÍøÕ¾£¬ÒÔµÍÓÚÊг¡¼ÛµÄ¸÷ÀàÉÌÆ·Îªµö¶ü£¬ÓÕʹָ±êÊäÈëÐÅÓþ¿¨¾ßÌåÐÅÏ¢À´Ö§¸¶Ðéα¶©µ¥£¬²¢ÀûÓÃÕâЩÐÅÏ¢´ÓÖ¸±êÕË»§ÖÐŲÓÃ×ʽð ¡£ËûÃÇÒÑ´ÓÅ·ÖÞ1000¶à¸ö±»¹¥»÷Ö¸±êÄÇÀïÇÔÈ¡Á˳¬¹ý430ÍòÃÀÔª ¡£Ä¿Ç°£¬ÒѾ­¶ÔÏÓÒÉÈËÌáÆðÐÌÊÂËßËÏ£¬ËûÃÇ¿ÉÄÜÃæ¶Ô×î¸ß12ÄêµÄ½ûïÀ ¡£


https://securityaffairs.com/144279/cyber-crime/cyber-police-of-ukraine-cybercrime-gang.html


6¡¢×êÑÐÍŶÓÅû¶RedGolfÀûÓúóÃÅKEYPLUGµÄ¹¥»÷»î¶¯


Recorded FutureÔÚ3ÔÂ30ÈÕÅû¶ÁËRedGolfÀûÓúóÃÅKEYPLUGµÄ¹¥»÷»î¶¯ ¡£RedGolfÖØÒªÕë¶Ôº½¿Õ¡¢Æû³µ¡¢½ÌÓý¡¢µ±¾Ö¡¢Ã½Ìå¡¢ÐÅÏ¢¼¼ÊõºÍ×Ú½ÌÓйصÄ×éÖ¯ ¡£×êÑÐÈËÔ±³ýÁ˼ì²âµ½¸ÃÍÅ»ïÔÚ2021ÄêÖÁ2023ÄêʹÓõÄKEYPLUGÑù±¾ºÍ»ù´¡ÉèÊ©£¨´úºÅΪGhostWolf£©±í£¬»¹Ö¸³öÆäʹÓÃÁËCobaltStrikeºÍPlugXµÈÆäËü¹¤¾ß ¡£¸Ã°²È«¹«Ë¾»¹°µÊ¾£¬RedGolf½«³ÖÐø¸ßÔËÓª½ÚÅÄ£¬²¢Ñ¸¿ì½«ÃæÏò±í²¿µÄ¹«Ë¾É豸£¨VPN¡¢·À»ðǽºÍÓʼþ·þÎñÆ÷µÈ£©Öеķì϶±øÆ÷»¯£¬ÒÔ»ñµÃÖ¸±êÍøÂçµÄ³õʼ½Ó¼ûȨÏÞ ¡£


https://www.recordedfuture.com/with-keyplug-chinas-redgolf-spies-on-steals-from-wide-field-targets