LabHost ¿Éµ¼ÖÂÈκÎÈ˶ԼÓÄôóÒøÐÐÓû§½øÐÐÍøÂç´¹µö

°ä²¼¹¦·ò 2024-02-29

1. LabHost ¿Éµ¼ÖÂÈκÎÈ˶ԼÓÄôóÒøÐÐÓû§½øÐÐÍøÂç´¹µö


2ÔÂ27ÈÕ£¬ÍøÂç´¹µö (PhaaS) ƽ̨¡°LabHost¡±Ò»ÏòÔÚÔ®ÊÖÍøÂç·¸×ï·Ö×Ó¶Ô×¼±±ÃÀÒøÐУ¬³ö¸ñÊǼÓÄôóµÄ½ðÈÚ»ú¹¹£¬µ¼Ö»ÏÔ×ÅÔö³¤¡£PhaaS Æ½Ì¨ÎªÍøÂç·¸×ï·Ö×ÓÌṩ½»Ô¿³×ÍøÂç´¹µöÌ×¼þ¡¢ÍйÜÒ³ÃæµÄ»ù´¡ÉèÊ©¡¢µç×ÓÓʼþÄÚÈÝÌìÉúºÍ»î¶¯¸ÅÊö·þÎñ£¬ÒÔ»»È¡Ã¿Ô¶©ÔÄ¡£LabHost ²¢²»ÊÇÒ»¼ÒÐÂÌṩÉÌ£¬µ«ÔÚ 2023 ÄêÉϰëÄêΪ¼ÓÄôóÒøÐÐÍÆ³ö¶¨ÔìÍøÂç´¹µö¹¤¾ß°üºó£¬ÆäÊÜÓ­½Óˮƽì­Éý¡£ÍøÂç´¹µö¼´·þÎñƽ̨ʹ²»´¿ÊìµÄºÚ¿Í¸üÈÝÒ×Ö´ÐÐÍøÂç·¸×´Ó¶øÏÔ×ÅÀ©´óÁËÍþвÐÐΪÕßµÄÁìÓò£¬²¢ÔÚ¸ü¿í·ºµÄÁìÓòÄÚÓ°ÏìÍøÂ簲ȫ¡£×êÑÐÈËÔ±×î½üÖÒ¸æµÄÆäËû³ÛÃû PhaaS ƽ̨Ô̺¬¡° Greatness ¡±ºÍ¡° Robin Banks ¡±£¬ËüÃǾùÓÚ 2022 ÄêÖÐÆÚÍÆ³ö£¬ÓµÓÐ MFA ÈÆ¹ý¡¢×Ô½çËµÍøÂç´¹µö¹¤¾ß°üºÍÖÎÀíÃæ°å¡£


https://www.bleepingcomputer.com/news/security/labhost-cybercrime-service-lets-anyone-phish-canadian-bank-users/


2. U-Haul »ã±¨ 67000 Ãû¿Í»§Êܵ½Êý¾Ýй¶µÄÓ°Ïì


2ÔÂ28ÈÕ£¬U-Haul ÊÇÒ»¼ÒλÓÚÑÇÀûÉ£ÄÇÖݵĿ¨³µ¡¢ÍϳµºÍ×ÔÖ÷²Ö´¢×âÁÞ¹«Ë¾£¬È¥ÄêÄêµ×ÒÑÆðÍ·Ïò 67,000 Ãû¿Í»§´«µÝÊý¾Ýй¶ÊÂÎñ£¬¸ÃÊÂÎñµ¼ÖÂËûÃǵÄÓ×ÎÒÐÅÏ¢Ô⵽й¶¡£¸Ã·ì϶²úÉúÔÚ 12 Ô 5 ÈÕ£¬Æäʱδ¾­ÊÚȨµÄ¹¥»÷ÕßÒÔijÖÖ·½Ê½Ê¹ÓúϷ¨Í´´¦½Ó¼ûU-Haul¾­ÏúÉ̺ÍÍŶӳÉÔ±ÓÃÀ´¸ú×Ù¿Í»§Ô¤Ô¼ºÍ²é¿´¿Í»§¼Í¼µÄϵͳ¡£U-Haul ·¢ÏÖÕâÒ»ÊÂÎñºó£¬µ±¼´Æô¶¯ÁËÏìÓ¦ºÍ̸£¬²¢ÓëÒ»¼ÒÍøÂ簲ȫ¹«Ë¾Ò»Â·¶ÔÕâ´Îй¶ÊÂÎñ·¢Õ¹Á˵÷²é¡£µ÷²éÏÔʾ£¬Ä³Ð©¿Í»§¼Í¼ÔÚÕâ´Îй¶Öб»½Ó¼û£¬Ô̺¬¾ÓסÔÚÃåÒòÖÝµÄ 136 ÃûÓ×ÎÒµÄÐÕÃûºÍ¼ÝÊ»ÅÆÕÕÐÅÏ¢¡£U-HaulÔÚ¸øÊÜÓ°ÏìÓ×ÎÒµÄ֪ͨÐÅÖÐÖ¸³ö£¬Õâ´ÎÎ¥¹æÊÂÎñÉæ¼°µÄ¿Í»§¼Í¼ϵͳδÏνӵ½Ö§¸¶ÏµÍ³£¬Òò¶øÍþвÐÐΪÕßûÓнӼûÈκÎÒøÐп¨Êý¾Ý¡£È»¶ø£¬¶ÔÓÚ×âÁÞ¹«Ë¾À´Ëµ£¬ÕâÖÖÎ¥¹æÐÐΪ²¢²»ÊǵÚÒ»´Î¡£


https://www.darkreading.com/cyberattacks-data-breaches/67k-customers-impacted-by-data-breach-according-to-u-haul


3. Õë¶Ô UnitedHealth Optum µÄ¹¥»÷µ¼ÖÂÒ½ÁƱ£½¡¼Æ·ÑÖжÏ


2ÔÂ27ÈÕ£¬È«ÇòÊÕÈë×î´óµÄÒ½ÁƱ£½¡¹«Ë¾½áºÏ½¡È«¼¯ÍÅ (UnitedHealth Group) ֤ʵ£¬Æä×Ó¹«Ë¾ Optum ×î½üÔÚ Change Healthcare ¼Æ·Ñƽ̨ÉÏÔâ·êÁËÑϳÁµÄÍøÂç¹¥»÷¡£Õâ´Î¹¥»÷µ¼ÖÂÃÀ¹ú¸÷µØÒ½ÁƱ£½¡¼Æ·Ñ·þÎñÑϳÁÖжÏ£¬¸øÈ«¹úÁìÓòÄÚµÄÒ½ÁÆÕïËù¡¢Ò©·¿ºÍ±£ÏÕÌṩÉÌÔì³É»ìÂÒ¡£Æ¾¾Ý UnitedHealth µÄÉêÃ÷£¬Õâ´Î¹¥»÷ÒÉËÆÓɾ­Ñé·á˶µÄÃñ×å¹ú¶ÈºÚ¿ÍËùΪ£¬ËûÃÇ¿ÉÄÜÉøÈë Optum µÄϵͳ²¢ÆÈʹ¸Ã¹«Ë¾¹Ø¹Ø IT »ù´¡ÉèÊ©ÒÔ¶ôÔìÍþв¡£Êܵ½¹¥»÷µÄ Change Healthcare ƽ̨¶ÔÓÚÍÆ½øÒ½ÁƱ£½¡ÌṩÕßÖ®¼äµÄÖ§¸¶»¥»»ÖÁ¹Ø³ÁÒª£¬´Ó¶øÊµÏÖµç×Ó½¡È«¼Í¼¡¢Ë÷Åâ´¦Öᢻ¤ÀíЭºÍгÊý¾Ý·ÖÎöµÈ¹Ø¼üÖ°ÄÜ¡£ÓÉÓÚÎÞ·¨Ê¹Óà Optum µÄ¼Æ·Ñ¹¤¾ß£¬ºÜ¶àÒ©·¿¡¢ÕïËùºÍÒ½ÁƼƷѹ«Ë¾¶¼»ã±¨ÁËÑϳÁµÄÔËÓªÌôÕ½ºÍÔ¤Ô¼ÖжÏ¡£Õâ´ÎÍ£µçÀ´µÃÇÐʵÊÇÌ«Ôã¸âÁË£¬ÓÉÓÚÒ½ÁƱ£½¡ÌṩÕßÔÚÓ¦¶ÔÒ½ÁÆ·þÎñÐèÒªµÄ¼¤Ôö¡£ÔÚ Optum ÆëÈ«¸´Ô­·þÎñ֮ǰ£¬Ó°ÏìÔ¤¼Æ½«³ÖÐøÊýÌìÉõÖÁÊýÖÜ¡£


https://securityboulevard.com/2024/02/major-cyberattack-on-unitedhealths-optum-causes-widespread-healthcare-billing-disruption/


4. LoanDepot³ÆÔ¼ 1700 Íò¿Í»§µÄÐÅÏ¢ÔÚÍøÂç¹¥»÷ÆÚ¼ä±»µÁ


2ÔÂ26ÈÕ£¬LoanDepot ÒÑ֤ʵ£¬½ü 1700 Íò LoanDepot ¿Í»§µÄÃô¸ÐÓ×ÎÒÐÅÏ¢£¨Ô̺¬Éç»á°²È«ºÅÂ룩ÔÚ 1 Ô·ݵÄÀÕË÷Èí¼þ¹¥»÷Öб»µÁ¡£Õâ¼Ò´û¿îºÍµÖѺ´û¿î¾ÞÍ·¹«Ë¾ÔÚÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒÌá½»µÄÊý¾Ýй¶֪ͨÖаµÊ¾£¬±»µÁµÄ LoanDepot ¿Í»§Êý¾ÝÔ̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µç×ÓÓʼþºÍÓÊÕþµØÖ·¡¢²ÆÕþÕʺź͵绰ºÅÂë¡£±»µÁÊý¾Ý»¹Ô̺¬ LoanDepot ´Ó¿Í»§ÄÇÀïÍøÂçµÄÉç»á°²È«ºÅÂë¡£ÊÜÓ°ÏìµÄ LoanDepot ¿Í»§ÊýÁ¿½ÏÉϸöÔÂ×î³õÏòÁª¹ú¼à¹Ü»ú¹¹Åû¶µÄ1660 ÍòÓÐËùÔö³¤£¬Áª¹ú¼à¹Ü»ú¹¹²¢Î´Ð¹Â©¾ßÌåÄÄЩ¿Í»§Êý¾Ý±»µÁ¡£Õâ´ÎÍøÂç¹¥»÷µ¼Ö LoanDepot µÄÊý°ÙÍò¿Í»§ÔÚ½ÓÏÂÀ´µÄ¼¸ÖÜÄÚÎÞ·¨¸¶¿î»ò½Ó¼ûÆäÔÚÏßÕË»§¡£LoanDepot Êǽü¼¸¸öÔÂÀ´Ôâµ½¶ñÒâºÚ¿Í¹¥»÷µÄ¼¸¼Ò´û¿îºÍµÖѺ´û¿î¹«Ë¾Ö®Ò»¡£


https://techcrunch.com/2024/02/26/loandepot-millions-sensitive-personal-data-ransomware/?&web_view=true


5. °²È«»ú¹¹ÖÒ¸æ Ubiquiti EdgeRouter Óû§°ÑÎÈ APT28 µÄÍþв


2ÔÂ28ÈÕ£¬ÔÚÒ»·ÝеĽáºÏÕ÷ѯÖУ¬ÃÀ¹úºÍÆäËû¹ú¶ÈµÄÍøÂ簲ȫºÍµý±¨»ú¹¹¶½´Ù Ubiquiti EdgeRouter Óû§²ÉÈ¡±£»¤´ëÊ©£¬¼¸ÖÜǰ·¨Âɲ¿ÃÅÔÚ´úºÅΪ¡° Dying Ember¡±µÄÐж¯ÖзÛËéÁËÒ»¸öÓÉÊÜϰȾ·ÓÉÆ÷×é³ÉµÄ½©Ê¬ÍøÂç¡£¾Ý³Æ£¬¸Ã½©Ê¬ÍøÂçÃûΪ MooBot£¬±»Óë¶íÂÞ˹ÓÐ¹ØµÄ APT28 Íþв×éÖ¯ÓÃÀ´¹¥»÷»î¶¯£¬²¢Í¶·Å×Ô½ç˵¶ñÒâÈí¼þÒÔ¹©ºóÐøÀûÓ᣾ÝÏàʶ£¬APT28 ´ÓÊôÓÚ¶íÂÞ˹×ÜÕÕ·÷²¿ (GRU)£¬ÖÁÉÙ×Ô 2007 ÄêÒÔÀ´¾ÍÒ»Ïò»îÔ¾¡£MooBot ¹¥»÷±ØÒªÒÔĬÈÏ»òÈõÍ´´¦µÄ·ÓÉÆ÷Ϊָ±êÀ´²¿Êð OpenSSH ľÂí£¬APT28 »ñÈ¡´Ë½Ó¼ûȨÏÞÒÔÌṩ bash ¾ç±¾ºÍÆäËû ELF ¶þ½øÔìÎļþÀ´ÍøÂçÍ´´¦¡¢´úÀíÍøÂçÁ÷Á¿¡¢Ö÷»úÍøÂç´¹µöÒ³ÃæºÍÆäËû¹¤¾ß¡£ÆäÖÐÔ̺¬ÓÃÓÚÉÏ´«ÊôÓÚÌØ¶¨Ö¸±êÍøÂçÓʼþÓû§µÄÕÊ»§Í´´¦µÄ Python ¾ç±¾£¬ÕâЩʹ´¦ÊÇͨ¹ý¿çÕ¾µã¾ç±¾ºÍä¯ÀÀÆ÷ÖеÄä¯ÀÀÆ÷ ( BitB ) Óã²æÊ½ÍøÂç´¹µö»î¶¯ÍøÂçµÄ¡£


https://thehackernews.com/2024/02/cybersecurity-agencies-warn-ubiquiti.html


6. ¿ªÔ´ Xeno RAT ľÂí³ÉΪ GitHub ÉϵÄDZÔÚÍþв


2ÔÂ27ÈÕ£¬Ò»ÖÖÃûΪXeno RATµÄ¡°¾«ÐÄÉè¼Æ¡±µÄÔ¶³Ì½Ó¼ûľÂí (RAT)ÒÑÔÚ GitHub Éϰ䲼£¬ÆäËû²Î¼ÓÕßÎÞÐè¶î±í¸¶·Ñ¼´¿ÉʹÓøÃľÂí¡£¸Ã¿ªÔ´ RAT ѡȡ C# ±àд£¬Óë Windows 10 ºÍ Windows 11 ²Ù×÷ϵͳ¼æÈÝ£¬½¨ÉèÁË¡°ÓÃÓÚÔ¶³ÌϵͳÖÎÀíµÄÈ«ÃæÖ°ÄÜ¡±£¬Æä¿ª·¢ÈËÔ±£¨ÆäÃû³ÆÎª moom825£©°µÊ¾¡£ËüÔ̺¬ SOCKS5 ·´Ïò´úÀíºÍ¼ÔìʵʱÒôƵµÄÖ°ÄÜ£¬²¢½áºÏDarkVNC µÄ°µ²ØÐé¹¹ÍøÂçÍÆËã (hVNC) Ä £¿é£¬Ê¹¹¥»÷Õß¿ÉÄÜÔ¶³Ì½Ó¼ûÊÜϰȾµÄÍÆËã»ú¡£ÖµÍ×ÌùÐĵÄÊÇ£¬moom825 Ò²ÊÇÁíÒ»ÖÖÃûΪDiscordRAT 2.0µÄ»ùÓÚ C# µÄ RAT µÄ¿ª·¢Õߣ¬¸Ã RAT ÒÑÓÉÍþвÐÐΪÕßÔÚÃûΪ node-hide-console-windows µÄ¶ñÒâ npm °üÖзַ¢£¬ÕýÈçReversingLabs ÓÚ 2023 Äê 10 ÔÂÅû¶µÄÄÇÑù¡£


https://thehackernews.com/2024/02/open-source-xeno-rat-trojan-emerges-as.html?&web_view=true