Õë¶Ô·¨ÓïÇøµÄÍþвÍÅ»ïCryptosLabsÒÑ»ñÀûÔ¼4.8ÒÚÅ·Ôª

°ä²¼¹¦·ò 2023-06-30

1¡¢Õë¶Ô·¨ÓïÇøµÄÍþвÍÅ»ïCryptosLabsÒÑ»ñÀûÔ¼4.8ÒÚÅ·Ôª


¾Ý6ÔÂ28ÈÕ±¨Â· £¬Group-IBÅû¶Á˹ØÓÚÍþвÍÅ»ïCryptosLabsÔË×÷·½Ê½µÄ¾ßÌåÐÅÏ¢¡£Ëü×Ô2018Äê4ÔÂÒÔÀ´ £¬ÖØÒªÕë¶Ô·¨¹ú¡¢±ÈÀûʱºÍ¬ɭ±¤µÄ·¨ÓïÇøÓû§ £¬¹À¼ÆÒÑ»ñµÃ4.8ÒÚÅ·ÔªµÄ·¸·¨ÀûÈ󡣸ÃÍÅ»ïµÄ´ó¹æÄ£Ú²Æ­»î¶¯Éæ¼°¼ÙÒâ40¼Ò³ÛÃûÒøÐÓ×¢½ðÈڿƼ¼¹«Ë¾¡¢×ʲúÖÎÀí¹«Ë¾ºÍ¼ÓÃÜÇ®±Òƽ̨ £¬³ÉÁ¢Á˺á¿ç350¶à¸öÓòÃûµÄ»ù´¡ÉèÊ© £¬ÍйÜÔÚ80¶ą̀·þÎñÆ÷ÉÏ¡£Æä»î¶¯µÄÒ»¸öÁÁµãÊÇʹÓÃ×Ô½ç˵ڿƭ¹¤¾ß°ü £¬¿ÉÔËÐÓ×¢ÖÎÀíºÍ¹æÄ£»¯Í¶×ÊÚ¿Æ­»î¶¯¡£


https://thehackernews.com/2023/06/cryptoslabs-scam-ring-targets-french.html


2¡¢×êÑÐÈËÔ±ÑÝʾÈôºÎͨ¹ýµç´Å¹ÊÕÏ×¢Èë¹¥»÷À´ÊÕÊÜÎÞÈË»ú


ýÌå6ÔÂ28ÈÕ³Æ £¬IOActive·¢ÏÖÁËͨ¹ýµç´Å¹ÊÕÏ×¢Èë(EMFI)¹¥»÷À´ÊÕÊÜÎÞÈË»úµÄ²½Öè¡£Ëæ×ÅÎÞÈË»úµÄʹÓò»ÐÝÔö³¤ £¬×êÑÐÈËԱרһÓÚʹÓ÷ÇÇÖÈëÐÔ¼¼ÊõÔÚÎÞÈË»úÉÏʵÏÖ´úÂëÖ´ÐС£¸Ã¹«Ë¾·¢ÏÖ £¬Í¨¹ýÔڹ̼þ¸üÐÂÆÚ¼äµÄÊÊÆä¹¦·ò×¢ÈëÌØ¶¨µÄµç´Å¹ÊÕÏÀ´ÈëÇÖÖ¸±êÉ豸ÊÇ¿ÉÐеÄ¡£¹¥»÷ÕßÄܹ»Í¨¹ý´ËÀ๥»÷ÔÚÖ÷´¦ÖÃÆ÷ÉÏÖ´ÐдúÂë £¬²¢»ñµÃ¶ÔʵÏÖÎÞÈË»úÖ÷ÌâÖ°ÄܵÄAndroid²Ù×÷ϵͳµÄ½Ó¼û¡£ÖÁÓÚ»º½â´ëÊ© £¬×êÑÐÈËÔ±½¨ÒéÎÞÈË»ú¿ª·¢ÈËÔ±½áºÏ»ùÓÚÓ²¼þºÍÈí¼þµÄEMFI¶Ô²ß¡£


https://thehackernews.com/2023/06/alert-new-electromagnetic-attacks-on.html


3¡¢Ó¢¹úNHS³¬¹ý100ÍòÃû»¼ÕߵľßÌåÐÅÏ¢ÒòÍøÂç¹¥»÷й¶


¾Ý6ÔÂ29ÈÕ±¨Â· £¬Ó¢¹úNHS³¬¹ý100Íò»¼ÕߵľßÌåÐÅÏ¢ÒÑÔÚÍøÂç¹¥»÷ÖÐй¶¡£¾ÝϤ £¬Âü³¹Ë¹ÌØ´óѧ½üÆÚÔâµ½ÀÕË÷¹¥»÷ £¬Ó°ÏìÁËNHS»¼ÕßÊý¾Ý¿â £¬Éæ¼°200¼ÒÒ½Ôº110ÍòÃû»¼ÕßµÄÐÅÏ¢ £¬ÕâЩÐÅÏ¢ÊÇÓɸôóѧ³öÓÚ×êÑÐÖ÷ÕŶøÍøÂçµÄ¡£Æ¾¾Ý¸Ã´óѧ½øÐеÄÒ»Ïîµ÷²é £¬·ÖÎöÅúעԼĪ250 GBµÄÊý¾Ý±»½Ó¼û¡£Âü³¹Ë¹ÌØ´óѧ½²»°È˻ؾø¾ÍNHSÊý¾Ý°ä·¢ÆÀÂÛ £¬µ«Ã»Óзñ¶¨ÕâÒ»Êý¾Ýй¶ÊÂÎñ¡£


https://www.independent.co.uk/news/health/nhs-patient-data-attack-b2364202.html


4¡¢ÃÀ¹ú¹ú¶ÈѧÉúÐÅÏ¢»¥»»ËùÔâµ½ClopµÄ¹¥»÷»òÒѽ»Êê½ð


¾ÝýÌå6ÔÂ28ÈÕ±¨Â· £¬ÃÀ¹ú¹ú¶ÈѧÉúÐÅÏ¢»¥»»ËùÔâµ½ÁËClopÀûÓÃMOVEit·ì϶µÄ¹¥»÷¡£¸Ã»ú¹¹Æù½ñΪֹµÄÉêÃ÷²¢Î´Åú×¢ËûÃÇÊÇ·ñÂú×ãÁËÊê½ðÒªÇó £¬µ«¾ÝÏàʶ £¬ËûÃǵÄÃû×ÖÒÑ´ÓClopµÄÍøÕ¾ÉÑþ³Øý £¬Õâͨ³£Åú×¢×éÖ¯ÒѾ­½»ÁËÊê½ð¡£»¥»»Ëù°µÊ¾ £¬µ÷²éÈÔÔÚ½øÐÐÖÐ £¬¹¥»÷Õß¿ÉÄÜ»ñÈ¡ÁËͨ¹ýMOVEit Transfer¹¤¾ß´«ÊäµÄ²¿ÃÅÎļþ £¬ÆäÖÐÔ̺¬Ó×ÎÒÊý¾ÝµÄÎļþ £¬µ«ÊDz¢Î´Ó°Ïì¸Ã×é֯ϵͳµÄÊý¾Ý¡£


https://www.databreaches.net/national-student-clearinghouse-notifies-schools-of-moveit-breach/


5¡¢Cyble°ä²¼¹ØÓÚLinux°æ±¾AkiraÀÕË÷Èí¼þµÄ·ÖÎö»ã±¨


6ÔÂ28ÈÕ £¬Cyble°ä²¼Á˹ØÓÚLinux°æ±¾AkiraÀÕË÷Èí¼þµÄ·ÖÎö»ã±¨¡£Akira³õ´Î³öÏÖÓÚ2023Äê3Ô £¬Õë¶Ô¸÷¸öÁìÓòµÄWindowsϵͳ¡£½üÆÚ £¬×êÑÐÈËÔ±·¢ÏÖÁËAkiraµÄLinux±äÌå £¬ÖØÒªÕë¶ÔVMware ESXiÐé¹¹»ú¡£Linux¼ÓÃÜ·¨Ê½Ô̺¬¹«¹²RSA¼ÓÃÜÃÜÔ¿ £¬²¢ÀûÓöàÖÖ¶Ô³ÆÃÜÔ¿Ëã·¨½øÐÐÎļþ¼ÓÃÜ £¬ÀýÈçAES¡¢CAMELLIA¡¢IDEA-CBºÍDES¡£ÓëÆäËüVMware ESXi¼ÓÃÜ·¨Ê½·ÖÆç £¬AkiraµÄ¼ÓÃÜ·¨Ê½²»Ô̺¬ºÜ¶à¸ß¼¶Ö°ÄÜ £¬ÀýÈçÔÚʹÓÃesxcliºÅÁî¼ÓÃÜÎļþ֮ǰ×Ô¶¯¹Ø¹ØÐé¹¹»ú¡£


https://blog.cyble.com/2023/06/28/akira-ransomware-extends-reach-to-linux-platform/


6¡¢Kaspersky°ä²¼AndarielÍŻPÆäÐÂEarlyRatµÄ»ã±¨


KasperskyÔÚ6ÔÂ28ÈÕ°ä²¼Á˹ØÓÚAndarielÍŻPÆäжñÒâÈí¼þEarlyRatµÄ»ã±¨¡£AndarielÊdz¯ÏÊLazarusµÄ×Ó×éÖ¯ £¬ÖØÒªÊ¹ÓÃDTrackÄ£¿é»¯ºóÃÅ´Ó±»Ï°È¾µÄÏµÍ³ÍøÂçÐÅÏ¢¡£EarlyRATÆô¶¯ºó»áÍøÂçϵͳÐÅÏ¢²¢Í¨¹ýPOSTÒªÇ󽫯䷢Ë͵½C2 £¬ÆäµÚ¶þ¸öÖØÒªÖ°ÄÜÊÇÔÚÖ¸±êϵͳÉÏÖ´ÐкÅÁî¡£×êÑÐÈËÔ±°µÊ¾ £¬¼øÓÚÃýÎóºÍ´í±ð×ÖµÄÊýÁ¿ £¬Ëù¼ì²âµ½µÄEarlyRAT»î¶¯ËƺõÊÇÓɲ»×ã¾­ÑéµÄÔËÓªÈËÔ±ÊÖ¶¯Ö´ÐеÄ¡£


https://securelist.com/lazarus-andariel-mistakes-and-easyrat/110119/