Ô½ÄÏÍøÂç·¸×ïÍÅ»ï CoralRaiderÒâ±íй¶Æä²ÆÕþÊý¾Ý

°ä²¼¹¦·ò 2024-04-10
1. Ô½ÄÏÍøÂç·¸×ïÍÅ»ï CoralRaiderÒâ±íй¶Æä²ÆÕþÊý¾Ý


4ÔÂ9ÈÕ£¬Ò»¸öÓëÔ½ÄÏÓйصÄÐÂÍøÂç·¸×ï×éÖ¯ÒÔÑÇÖÞµÄÓ×ÎÒºÍ×é֯Ϊָ±ê£¬ÊÔͼÇÔÈ¡É罻ýÌåÕÊ»§ÐÅÏ¢ºÍÓû§Êý¾Ý¡£CoralRaider ÓÚ 2023 Äêµ×³õ´Î³öÏÖ£¬Ë¼¿Æ Talos Íþвµý±¨Ó××éµÄÍþв×êÑÐÈËÔ±ÔÚ CoralRaider µÄ×îзÖÎöÖÐÖ¸³ö£¬¸Ã×éÖ¯Ò²·¸ÁËһЩÐÂÊÖÃýÎó£¬ÀýÈçÎÞÒâÖÐϰȾÁË×Ô¼ºµÄϵͳ£¬´Ó¶øÂ¶³öÁËËûÃǵĻ¡£CoralRaider »î¶¯Í¨³£´Ó Windows ¿ì½Ý·½Ê½ (.LNK) ÎļþÆðÍ·£¬Í¨³£Ê¹Óà .PDF À©´óÃû£¬ÊÔͼºýŪÊܺ¦Õß´ò¿ªÎļþ¡£CoralRaider ×é֯ʹÓà Telegram ·þÎñÉϵÄ×Ô¶¯»¯»úеÈË×÷ΪºÅÁîºÍ½ÚÔìͨ·£¬²¢´ÓÊܺ¦ÕßµÄϵͳÖÐÇÔÈ¡Êý¾Ý¡£È»¶ø£¬ÍøÂç·¸×ï×éÖ¯ËÆºõÒѾ­Ï°È¾ÁËËûÃÇ×Ô¼ºµÄһ̨»úе£¬ÓÉÓÚ˼¿Æ×êÑÐÈËÔ±·¢ÏÖÁ˰䲼µ½¸ÃƵ·µÄÐÅÏ¢µÄÆÁÄ»½ØÍ¼¡£


https://www.darkreading.com/vulnerabilities-threats/vietnamese-cybercrime-group-coralraider-nets-financial-data


2. ¿¨°Í˹»ù2023Äê»ã±¨Êý¾ÝÇÔÈ¡¶ñÒâÈí¼þÊÂÎñ¼¤Ôö


4ÔÂ8ÈÕ£¬¿¨°Í˹»ù»ã±¨ÏÔʾ£¬2023 Ä꣬Êý¾ÝÇÔÈ¡¶ñÒâÈí¼þÊÂÎñ¼¤Ôö£¬Õë¶Ô½ü 1000 Íǫ̀É豸£¬ÍøÂç·¸×ï·Ö×Ó¾ùÔÈÔÚÿ̨ÊÜϰȾÉ豸ÉÏÌáÈ¡ 50.9 ¸öµÇ¼ʹ´¦¡£ÕâЩƾ֤±»ÓÃÓÚ¶ñÒâÖ÷ÕÅ£¬ÀýÈç²ß¶¯ÍøÂç¹¥»÷»òÔÚ°µÍøÂÛ̳ºÍ Telegram Ƶ·ÉÏÏúÊÛËüÃÇ¡£±»µÁƾ֤º­¸ÇÁìÓò¿í·º£¬´ÓÉ罻ýÌåµÇ¼µ½ÍøÉÏÒøÐзþÎñ¡¢¼ÓÃÜÇ®°üºÍÆóÒµÔÚÏ߯½Ì¨µÇ¼¡£¸Ã»ã±¨Ç¿µ÷ .com ÓòÃûÊDZ»µÁÕÊ»§µÄ³Áµã£¬½ôËæÆäºóµÄÊÇÓë°ÍÎ÷ (.br)¡¢Ó¡¶È (.in)¡¢¸çÂ×±ÈÑÇ (.co) ºÍÔ½ÄÏ (.vn) ÓйصÄÓòÃûÇøÓò¡£À´×Ô¿¨°Í˹»ùÊý×Ö×ã¼£µý±¨µÄÊý¾ÝÏÔʾ£¬´ÓǰÈýÄêÖжñÒâÈí¼þÊýÁ¿¼¤Ôö 643%¡£ÕâÍ»ÏÔÁ˶ñÒâÈí¼þ¶ÔÈ«ÇòÓ×ÎÒÏû·ÑÕßºÍÆóÒµ×é³ÉµÄÈÕÒæÑϳÁµÄÍþв¡£Æ¾¾Ý¸Ã»ã±¨£¬´ÓǰÎåÄêÀ´£¬È«ÇòÓÐ 443000 ¸öÍøÕ¾Ãæ¶ÔÍ´´¦Ð¹Â¶ÎÊÌâ¡£


https://securityboulevard.com/2024/04/10-million-devices-were-infected-by-data-stealing-malware-in-2023/


3. ÃÀ¹ú»·±£¾Öµ÷²éºÚ¿Íй¶ÆäÊý¾ÝµÄ°²È«ÊÂÎñ


4ÔÂ9ÈÕ£¬ÃÀ¹ú»·¾³±£»¤ÊðÔÚµ÷²éºÚ¿Íй¶Á˸ûú¹¹¹Ø¼ü»ù´¡ÉèÊ©³Ð°üÉÌÊý¾Ý¿âÖеĴóÁ¿ÁªÏµÐÅÏ¢µÄÖ¸¿Ø¡£±»³ÆÎª USDoD µÄÍþвÐÐΪÕßÔÚÒ»¸ö¿É¹«¿ª½Ó¼ûµÄºÚ¿ÍÂÛ̳Éϰ䲼ÁËËûËù˵µÄ 500 MB µÄÁªÏµÐÅÏ¢ºÍ EPA Êý¾Ý¿âÖÐµÄÆäËûÊý¾Ý¡£ÐÅÏ¢°²È«Ã½Ì弯ÍÅ֤ʵ£¬½ØÖÁÖÜÒ»ÏÂÎ磬¸ÃÌû×ÓÈÔÔÚÂÛ̳Éϰ䲼£¬ÆäÖÐÔ̺¬Ðû³ÆÔ̺¬´ÓÈ«Ãû¡¢µç×ÓÓʼþµØÖ·µ½´úÀí³Ð°üÉÌÏÖʵµØÖ·ÐÅÏ¢µÈËùÓÐÐÅÏ¢µÄѹËõÎļþ¡£Ìû×ÓÖÐд·£º¡°¸÷È˺ã¬Breachforums£¬ÕâÊÇÄãÃÇ×îϲ»¶µÄ TA£¬½ñÌìÎҺܸßÂýµØËµ£¬ÎÒÔÚ°ä²¼ epa.gov ÁªÏµÈËÁбíÊý¾Ý¿â¡£ÕâÊÇËûÃÇ [¹Ø¼ü»ù´¡ÉèÊ©] µÄÈ«ÊýÁªÏµÈË£¬²»½öÕë¶Ô¸Ã»ú¹¹½²»°È˰µÊ¾£¬¸Ã»ú¹¹¶Ô¾Ý³ÆÐ¹Â¶µÄÊý¾Ý½øÐÐÁË¡°³õ²½·ÖÎö¡±£¬·¢ÏÖÕâЩ¼ÍÂ¼ËÆºõÔ̺¬ÒÑÏò¹«¼Ò¹«¿ªµÄóÒ×ÁªÏµÐÅÏ¢£¬¡°ÒÔÌṩ»·¾³Ó°ÏìµÄÈ«ÃæÇé¿ö¡± ¡±¡£


https://news.hitb.org/content/us-epa-investigates-alleged-data-breach-government-hacker


4. unit42¶ñÒâÈí¼þÌáÒéµÄ·ì϶ɨÃè³ÊÉÏÉýÇ÷Ïò


4ÔÂ8ÈÕ£¬GA»Æ½ð¼×Ò£²âÊý¾ÝÅú×¢£¬Ô½À´Ô½¶àµÄÍþв²Î¼ÓÕßÔÚתÏò¶ñÒâÈí¼þÌáÒéµÄɨÃè¹¥»÷¡£±¾ÎÄ»ØÊ×Á˹¥»÷ÕßÈôºÎʹÓÃÊÜϰȾµÄÖ÷»ú¶ÔÆäÖ¸±ê½øÐлùÓÚ¶ñÒâÈí¼þµÄɨÃ裬¶ø²»ÊÇʹÓøü´«Í³µÄÖ±½ÓɨÃè²½Öè¡£ÍþвÐÐΪÕß³Ö¾ÃÒÔÀ´Ò»ÏòÔÚʹÓÃɨÃè²½ÖèÀ´²éÃ÷ÍøÂç»òϵͳÖеķì϶¡£Ò»Ð©É¨Ãè¹¥»÷Ô´×ÔÁ¼ÐÔÍøÂ磬¿ÉÄÜÊÇÓÉÊÜÏ°È¾ÍÆËã»úÉϵĶñÒâÈí¼þÇý¶¯µÄ¡£µ±¹¥»÷ÕßÌáÒéÍøÂçÒªÇóÒÔÊÔIJÀûÓÃÖ¸±êÖ÷»úµÄDZÔÚ·ì϶ʱ£¬¾Í»á²úÉúɨÃè¡£Ö¸±êÖ÷»úͨ³£ÊÇÁ¼ÐԵ쬲¢ÇÒ¿ÉÄÜÈÝÒ×Êܵ½¹¥»÷ÕßÕë¶ÔµÄ CVE µÄ¹¥»÷¡£Í¨¹ý¸ú×ÙÀ´×Ô¶à¸öÍøÂçµÄÁ÷Á¿ÈÕÖ¾£¬ÎÒÃÇ·¢ÏÖ¶Ô´óÁ¿Ö÷ÕŵصÄÒªÇóÓµÓп´ËÆÁ¼ÐÔµÄõè¾¶¡£ºÜ¶àɨÃè°¸Àý£¬ÆäÖй¥»÷ÕßǶÈëÁËÒÔǰδ¼û¹ýµÄ URL£¬ÓÃÓÚÓÐЧ¸ºÔØ´«Êä»ò C2 ÒÔ¼°·ì϶ÀûÓÃÒªÇó¡£Õâ½µµÍÁ˺óÐøÓÐЧ¸ºÔØ»ò C2 URL ±»°²È«¹©¸øÉÌ×èÖ¹µÄ¿ÉÄÜÐÔ¡£ÓÉÓÚÕâЩÓÐЧ¸ºÔØ´«ËÍ»ò C2 URL ¶ÔÓÚ°²È«¹©¸øÉÌÀ´ËµÊÇеÄ£¬Òò¶ø¼ì²âºÍ×èÖ¹´ËÀà³õʼɨÃèÒªÇóÖÁ¹Ø³ÁÒª£¬ÓÉÓÚ¹©¸øÉ̲»Ì«¿ÉÄÜ×èÖ¹ºóÐøÒªÇó¡£


https://unit42.paloaltonetworks.com/malware-initiated-scanning-attacks/


5. ÀÕË÷ÍÅ»ïRansomHub ´Ó Change Healthcare ÇÔÈ¡4TBÊý¾Ý


4ÔÂ9ÈÕ£¬¾Ý±¨Â·£¬Change Healthcare ÕýÃæ¶ÔÁíÒ»´Î¹¥»÷£¬Õâ´ÎÊÇÀÕË÷Èí¼þÍÅ»ï RansomHub ÌáÒéµÄ¹¥»÷£¬¶ø¾ÍÔÚ¼¸ÖÜǰ£¬¸Ã×éÖ¯³ÉΪALPHV/BlackCat ÍøÂç¹¥»÷µÄÊܺ¦Õß¡£RansomHub ÒªÇóΪÆä´Ó¸Ã¹«Ë¾ÇÔÈ¡µÄ 4TB Êý¾ÝڲƭÀÕË÷£»²»È»£¬Ëü»áÍþвÔÚ 12 ÌìÄÚ½«Êý¾ÝÏúÊÛ¸ø³ö¼Û×î¸ßÕß¡£±»µÁÐÅÏ¢Ô̺¬ÃÀ¹ú¾üÊÂÈËÔ±ºÍ»¼ÕßµÄÃô¸ÐÊý¾Ý£¬ÒÔ¼°Ò½ÁƼͼºÍ²ÆÕþÐÅÏ¢µÈ¡£ÕâʹµÃ½áºÏÒ½ÁƱ£½¡¹«Ë¾µÄ×Ó¹«Ë¾ Change Healthcare ÏÝÈëÁËÒ»¸öÀ§¾³£¬ÓÉÓÚËü¸Õ¸Õ´ÓÉϴεĹ¥»÷Öи´Ô­¹ýÀ´£¬±ØÐë¾ö¶¨Ö§¸¶Êê½ðÊÇ·ñÊÇ×îºÃµÄÑ¡Ôñ¡£Ö»¹ÜÈËÃÇ¶Ô ALPHV ÊÇ·ñ¸ÄÃûΪ RansomHub£¬»òÕßÊÇ·ñ´æÔÚÖ°ºÎÁªÏµ´æÔÚ³Á´ó²Â²â£¬µ«Îֿ˰µÊ¾£¬Ä¿Ç°»¹Ã»Óеõ½Ö¤Êµ£¬ÓÉÓÚ´Ë¿ÌϽáÂÛ»¹ÎªÊ±¹ýÔç¡£


https://www.darkreading.com/cyberattacks-data-breaches/round-2-change-healthcare-targeted-second-ransomware-attack


6. AGENT TESLA ¶ñÒâÈí¼þÇÔÈ¡ Chrome ºÍ Firefox µÄµÇ¼ʹ´¦


4ÔÂ8ÈÕ£¬×êÑÐÈËÔ±µ÷²éÁË×î½üÕë¶ÔÃÀ¹úºÍ°Ä´óÀûÑÇ×éÖ¯µÄ Agent Tesla ¶ñÒâÈí¼þ»î¶¯£¬¸Ã»î¶¯Ê¹ÓôøÓÐÐéα²É¹º¶©µ¥µÄÍøÂç´¹µöµç×ÓÓʼþÀ´ÓÕÆ­Êܺ¦Õßµã»÷¶ñÒâÁ´½Ó¡£µ¥»÷ºó£¬ÊÜ Cassandra Protector ±£»¤µÄ»ìºÏµÄ Agent Tesla Ñù±¾¾Í»á±»ÏÂÔØ²¢Ö´ÐУ¬´Ó¶øÇÔÈ¡»÷¼üºÍµÇ¼ʹ´¦¡£µ÷²é·¢ÏÖÁËÁ½ÃûÍøÂç·¸×ï·Ö×Ó Bignosa£¨ÖØÒªÍþв£©ºÍ Gods£¬ËûÃÇʹÓôóÐ͵ç×ÓÓʼþÊý¾Ý¿âºÍ¶à¸ö·þÎñÆ÷½øÐÐ RDP ÏνӺͶñÒâÈí¼þ»î¶¯¡£¸Ã¶ñÒâÈí¼þ»î¶¯ÔÚ·Ö·¢¶ñÒâÀ¬»øÓʼþÖ®Ç°Éæ¼°¶à¸ö²½ÖèµÄ³ï±¸½×¶Î¡£Bignosa ʹÓà Agent Tesla ½øÐÐÁËÍøÂç´¹µö¹¥»÷£¬¶ø Gods Áìµ¼ Bignosa Ò²Ôø½øÐйýÍøÂç´¹µö¹¥»÷¡£ËûÃÇͨ¹ý Jabber ºÍTeamViewer½øÐÐͨѶ£¬¶ø Bignosa ʹÓà RDP Ïνӵ½ VDS ·þÎñÆ÷²¢·Ö·¢ Agent Tesla¡£ 


https://gbhackers.com/agent-tesla-malware-steals-login-credentials-from-chrome-firefox/