Cl0pÀÕË÷Èí¼þÍÅ»ïÔÙÏÖ£¬Ðû³Æ¹¥»÷47¼Ò¹«Ë¾
°ä²¼¹¦·ò 2025-02-191. Cl0pÀÕË÷Èí¼þÍÅ»ïÔÙÏÖ£¬Ðû³Æ¹¥»÷47¼Ò¹«Ë¾
2ÔÂ13ÈÕ£¬Óë¶íÂÞ˹ÓйصÄÀÕË÷Èí¼þÍÅ»ïCl0p½üÆÚÔٴλîÔ¾£¬Ðû³Æ¶ÔÔ̺¬DXC TechnologyºÍÖ¥¼Ó¸ç¹«Á¢Ñ§ÌÃÔÚÄÚµÄ47¼Ò¹«Ë¾·¢ÆðÁ˹¥»÷¡£ÕâЩ¹«Ë¾±é²¼ÃÀ¹ú¡¢¼ÓÄôó¡¢Ä«Î÷¸ç¡¢Ó¢¹úºÍ°®¶ûÀ¼¡£ÆäÖУ¬DXC TechnologyÊÇÒ»¼ÒÕ¼ÓÐ130,000ÃûÔ±¹¤µÄ¿ç¹úIT·þÎñºÍÕ÷ѯ¹«Ë¾£¬¶øÖ¥¼Ó¸ç¹«Á¢Ñ§ÌÃÔòÊÇÃÀ¹úµÚÈý´óÑ§Çø£¬·þÎñ330,000¶àÃûѧÉú¡£Cl0pÍÅ»ïѡȡ¹ÖÒìµÄ¹µÍ¨·½Ê½£¬²»ÔÚ°µÍøÉÏÖ±½ÓÁªÏµÊܺ¦Õߣ¬¶øÊǰ䲼ÐÂÎÅ´ÙʹÊܺ¦Õß×Ô¶¯ÁªÏµ¡£¸ÃÍÅ»ïѡȡÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Ä£Ê½ºÍ¡°Ë«³ÁÀÕË÷¡±Õ½Êõ£¬¼È¼ÓÃÜÊý¾ÝÓÖÇÔÈ¡Êý¾Ý£¬²¢ÔÚÊܺ¦Õß²»Ö§¸¶Êê½ðʱ°ä²¼ÇÔÈ¡µÄÊý¾Ý¡£¾ÝÍþвµý±¨Æ½Ì¨FalconFeeds·ÖÏí£¬Êܺ¦ÕßÃûµ¥Öл¹Ô̺¬¿¨¶ûÉ·ÖÏú¹«Ë¾¡¢É±¤»ã¼¯Íŵȶà¼ÒÆóÒµºÍ×éÖ¯¡£Cl0pÍŻﺹÇàÉÏÔø²ß¶¯¹ýÔ̺¬MOVEitºÍFortra GoAnywhereÎļþÖÎÀíÈí¼þºÚ¿Í¹¥»÷ÔÚÄڵĶàÆð´ó¹æÄ£ºÚ¿ÍÊÂÎñ£¬²¢´ÓÖлñÀû·á¸»¡£Ö»¹Ü2021ÄêÎÚ¿ËÀ¼·¨Âɲ¿ÃÅÔø·ÛËéÆäIT»ù´¡ÉèÊ©²¢¿ÛÁô¶àÃûÏÓÒÉÈË£¬µ«¸ÃÍÅ»ïÈÔÔÚ»ý¼«Ñ°ÕÒеÄÊܺ¦Õß¡£
https://cybernews.com/cybercrime/chicago-schools-dxc-technology-cl0p-ransomware/
2. ÐÂÈÕÌú¹«Ë¾ÔâBianLianÀÕË÷Èí¼þ¹¥»÷£¬Ãô¸ÐÊý¾ÝÔâÇÔÈ¡
2ÔÂ14ÈÕ£¬È«ÇòµÚËÄ´ó´Ö¸Ö³ö²úÉÌÐÂÈÕÌú¹«Ë¾£¨Nippon Steel£©¾Ý³ÆÔâµ½ÁËBianLianÀÕË÷Èí¼þ¼¯ÍŵĹ¥»÷¡£¸Ã×éÖ¯ÔÚÆä°µÍøÍøÕ¾Éϰ䲼ÐÅÏ¢£¬Ðû³Æ´ÓÐÂÈÕÌúÃÀ¹ú·Ö²¿ÍøÂçÇÔÈ¡ÁË500GBµÄÊý¾Ý£¬Ô̺¬¹ÜÕÊÊý¾Ý¡¢¿Í»§²ÆÕþºÍÓ×ÎÒÐÅÏ¢¡¢³ö²úÊý¾ÝµÈÃô¸Ð×ÊÁÏ£¬²¢Ïò¹«Ë¾¸ß¹Ü°ä²¼ÁËÓ×ÎÒÁªÏµÐÅÏ¢¡£Õâ´ÎÏ®»÷¶ÔÐÂÈÕÌúÀ´Ëµ»úÓöÔã¸â£¬ÓÉÓÚ×ÔÃÀ¹ú×Üͳ°ÝµÇ×èÖ¹ÆäÓëÃÀ¹ú¸ÖÌú¹«Ë¾µÄ¹é²¢´òËãÒÔÀ´£¬¸Ã¹«Ë¾Ò»Ïò±¸ÊܹØ×¢¡£BianLian»¹ÔÚÆä°µÍøÉϰ䲼ÁËÒ»¸öÊý¾ÝÑù±¾£¬ËƺõÃèÊöÁËÐÂÈÕÌúÓëÃÀ¹ú¸ÖÌú¹«Ë¾¹é²¢Ç°ºóµÄϸ½Ú¡£È»¶ø£¬µ±Cybernews½Ó¼ûBianLianµÄÑó´ÐÍøÕ¾Ê±£¬È´·¢ÏÖNippon²¢Î´³Ê´Ë¿ÌÊܺ¦ÕßÃûµ¥ÉÏ£¬BianLian³ÆÐÂÈÕÌúµÄÊý¾Ý¡°ºÜ¿ì¾Í»á°ä²¼¡±£¬²Â²âÈÕ±¾¹«Ë¾¿ÉÄÜÔÚ½»ÉæÖ§¸¶Êê½ð¡£BianLianÀÕË÷Èí¼þ×éÖ¯×Ô2022Äê6Ô³öÏÖÒÔÀ´£¬ÒÑÕë¶Ô¹Ø¼ü»ù´¡ÉèÊ©²¿ÃÅ¡¢ÖÐÓ×ÐÍÆóÒµÒÔ¼°Ò½ÁÆ¡¢×¨ÒµºÍ·¿µØ²úÐÐÒµ·¢ÆðÁËÂŴι¥»÷¡£¾ÝCISAºÍFBIµÄ½áºÏ²¼¸æ£¬¸ÃÍÅ»ï¾Ý³ÆÀ´×Ô¶íÂÞ˹£¬Ñ¡È¡Ë«³ÁÀÕË÷ģʽ£¬Ê×ÏÈÇÔÈ¡Êý¾Ý£¬¶øºó¼ÓÃÜÊܺ¦Õßϵͳ£¬ÒÔʵÏÖÓÆ¾ÃÉúºÅÁîºÍ½ÚÔì¡£
https://cybernews.com/news/nippon-steel-claimed-by-bianlian-ransomware-group/
3. StaryDobry¶ñÒâÈí¼þ»î¶¯£ºÀûÓÃÆÆ½âÓÎÏ·´«²¼XMRigÍڿ󲡶¾
2ÔÂ18ÈÕ£¬StaryDobryÊÇÒ»¸öÕë¶ÔÈ«ÇòÓÎÏ·Íæ¼ÒµÄ´ó¹æÄ£¶ñÒâÈí¼þ»î¶¯£¬ËüÀûÓÃÆÆ½âµÄÓÎÏ·°æ±¾£¬ÈçGarry's Mod¡¢BeamNG.driveºÍDyson Sphere ProgramµÈSteamÉÏ¸ßÆÀ·ÖµÄÓÎÏ·£¬×÷Ϊ´«²¼¶ñÒâÈí¼þµÄÔØÌå¡£¾Ý±¨Â·£¬¸Ã»î¶¯ÔÚ2024Äê12ÔÂÏÂÑ®ÖÁ2025Äê1ÔÂ27ÈÕÆÚ¼ä»îÔ¾£¬ÖØÒªÓ°ÏìµÂ¹ú¡¢¶íÂÞ˹¡¢°ÍÎ÷¡¢°×¶íÂÞ˹ºÍ¹þÈø¿Ë˹̹µÄÓû§¡£ÍþвÐÐΪÕßÌáǰÊýÔÂÉÏ´«ÊÜϰȾµÄÓÎÏ·×°Ö÷¨Ê½µ½ÖÖ×ÓÍøÕ¾£¬ÔÚ¼ÙÆÚÆÚ¼ä´¥·¢ÓÐÐ§ÔØºÉÒÔ½µµÍ±»·¢ÏֵķçÏÕ¡£StaryDobryѡȡ¶à½×¶ÎϰȾÁ´£¬×îÖÕÖ÷ÕÅÊÇÔÚÓû§ÏµÍ³ÖÐ×°ÖÃXMRig¼ÓÃܿ󹤡£Óû§ÏÂÔØ¿´ËÆÕý³£µÄÓÎÏ·×°Ö÷¨Ê½ºó£¬¶ñÒâÈí¼þÖ²È뷨ʽ»áÔÚºó¶Ü½âѹ²¢Æô¶¯£¬ÍøÂçϵͳÐÅÏ¢ºó·¢Ë͵½C2·þÎñÆ÷¡£Ëæºó£¬¶ñÒâÈí¼þ¼ÓÔØ·¨Ê½»á¼Ù×°³ÉWindowsϵͳÎļþ£¬´´½¨´òË㹤×÷ÒÔ³ÖÐø´æÔÚ£¬²¢ÔÚÂú×ãǰÌáʱÏÂÔØ²¢ÔËÐÐXMRigÍÚ¿ó·¨Ê½¡£XMRig¿ó¹¤ÊÇMonero¿ó¹¤µÄÅú¸Ä°æ±¾£¬ËüÏνӵ½¸öÈËÍÚ¿ó·þÎñÆ÷£¬Ê¹µÃÊÕÒæ¸üÄÑ×·×Ù¡£¿¨°Í˹»ùÖ¸³ö£¬ÕâЩ¹¥»÷¿ÉÄÜÀ´×ÔÒ»Ãû½²¶íÓïµÄ¹¥»÷Õߣ¬ÇÒStaryDobryÆ«²îÓÚÒ»´ÎÐԻ£¬Ö¼ÔÚͨ¹ý¶Ô׼׳´óµÄÓÎÏ·»úÀ´×î´ó»¯ÍÚ¿óÊÕÒæ¡£
https://www.bleepingcomputer.com/news/security/cracked-garrys-mod-beamngdrive-games-infect-gamers-with-miners/
4. ·çÏÕͶ×ʾÞÍ· Insight Partners Ôâ·êÍøÂç¹¥»÷
2ÔÂ18ÈÕ£¬×ܲ¿Î»ÓÚŦԼµÄ·çÏÕͶ×ʺÍ˽ļ¹ÉȨ¹«Ë¾Insight Partners£¬ÔÚÆä30ÄêµÄÒµÎñÔËÓªÆÚ¼äÒÑͶ×ÊÁËÈ«Çò800¶à¼ÒÈí¼þºÍ¼¼Êõ²Ý´´ÆóÒµ£¬ÖÎÀí×ų¬¹ý900ÒÚÃÀÔªµÄ¼à¹Ü×ʲú¡£È»¶ø£¬¸Ã¹«Ë¾ÔÚ1Ô·ÝÔâ·êÁËÒ»´Î¸´ÔÓµÄÉç»á¹¤³Ì¹¥»÷¡£¾Ý¸Ã¹«Ë¾Öܶþ°ä²¼µÄÉêÃ÷£¬Æä²¿ÃÅÐÅϢϵͳÓÚ1ÔÂ16ÈÕÔâµ½¹¥»÷¡£·¢ÏÖÎ¥¹æÐÐΪºó£¬Insight PartnersѸ¿ì²ÉÈ¡Ðж¯£¬ÔÚ¼¸Ó×ʱÄÚ½ÚÔìÖÕ¾ÖÃæ²¢ÆðÍ·µ÷²é£¬Í¬Ê±Í¨ÖªÁËÓйط¨Âɲ¿ÃźÍÀûÒæÓйØÕߣ¬²¢ÀñƸÁ˵ÚÈý·½ÍøÂ簲ȫר¼ÒÀ´ÆÀ¹ÀÓ°Ïì¡£¹ÌÈ»¸Ã¹«Ë¾ÉÐδ·ÖÏíÓйع¥»÷ÐÔÖʵĸü¶àÐÅÏ¢£¬ÒÔ¼°Êý¾ÝÊÇ·ñÔÚ¹¥»÷Öб»½Ó¼û»òÇÔÈ¡£¬µ«°µÊ¾Ã»ÓÐÖ¤¾ÝÅú×¢¹¥»÷ÕßÔÚ±»·¢ÏÖºóÈÔÄܽӼûÆäÍøÂ磬ÇÒÕâ´ÎÊÂÎñ²¢Î´¶Ô¹«Ë¾µÄÔËÓªÔì³É½øÒ»²½µÄ×ÌÈÅ¡£Insight PartnersÔÚÓëµÚÈý·½ÍøÂ簲ȫר¼Ò¡¢È¡Ö¤×¨¼ÒÒÔ¼°±í²¿Ë¾·¨ÕÕ·÷ºÏ×÷£¬ÖÂÁ¦È·¶¨ÊÂÎñµÄÁìÓò£¬²¢ÓëÀûÒæÓйØÕß·ÖÏíÐÅÏ¢£¬Ô¤¼ÆÕâÒ»¹ý³Ì½«±ØÒªÊýÖܹ¦·ò¡£Ä¿Ç°£¬¸Ã¹«Ë¾ÒÔΪÕâ´Î¹¥»÷²»»á¶ÔͶ×Ê×éºÏ¹«Ë¾¡¢Insight»ù½ð»òÆäËûÀûÒæÓйØÕß²úÉú³Á´óÓ°Ï죬²¢³ÐŵÔÚµ÷²é¹ý³ÌÖлñµÃÓйØÐÅÏ¢ºó£¬½«ÏòÊÜÓ°ÏìµÄÓ×ÎÒ´«µÝ×îÐÂÇé¿ö¡£
https://www.bleepingcomputer.com/news/security/venture-capital-giant-insight-partners-hit-by-cyberattack/
5. ±¨Òµ¾ÞÍ·Lee EnterprisesÔâÀÕË÷Èí¼þ¹¥»÷ÖÂÔËÓªÖжÏ
2ÔÂ18ÈÕ£¬±¨Òµ³ö°æ¾ÞÍ·Lee EnterprisesÈ·ÈÏ£¬ÆäÔâ·êµÄÀÕË÷Èí¼þ¹¥»÷Êǵ¼Ö¼¯ÍÅÔËÓª³ÖÐøÖжϳ¬¹ýÁ½Öܵĵ××ÓÔÒò¡£¸Ã¼¯ÍÅÔÚ26¸öÖݳö°æ77·ÝÈÕ±¨¡¢350·ÝÖÜ¿¯¼°×¨Òµ¿¯ÎռÓг¬¹ý120ÍòµÄÈÕ±¨¿¯ÐÐÁ¿ºÍ4400ÍòµÄÊý×Ö°æ¶ÀÁ¢·Ã¿Í¡£Õâ´Î¹¥»÷µ¼ÖÂ2ÔÂ3ÈÕϵͳÖжϣ¬Ó°ÏìÁ˲úÆ··ÖÏú¡¢Õ˵¥¡¢ÊÕ¿îºÍ¹©¸øÉ̸¶¿îµÈÔËÓª£¬Ó¡Ë¢³ö°æÎï·ÖÏúÑÓ³¤£¬ÔÚÏßÔËÓªÊÜÏÞ¡£½ØÖÁ2ÔÂ12ÈÕ£¬ËùÓÐÖ÷Ìâ²úÆ·ÒѸ´ÔÕý³£·Ö·¢£¬µ«ÖܶȺ͸¨Öú²úÆ·ÉÐδ¸´Ô£¬Õ¼¹«Ë¾×ܽ»Ò×ÊÕÈëµÄ5%¡£LeeÔÚµ÷²éÃô¸ÐÊý¾ÝÊÇ·ñй¶£¬Í¬Ê±Ö´ÐÐһʱ´ëʩά³Ö¹Ø¼üÒµÎñÖ°ÄÜ¡£Õâ´Î¹¥»÷µ¼Ö±¨Òµ¼¯ÍÅÏÝÈë»ìÂÒ£¬¼ÇÕߺͱà×ëÎÞ·¨½Ó¼ûÎļþ¡£´Ëǰ£¬¸Ã¼¯ÍÅÔøÔÚ2020ÄêÃÀ¹ú×Üͳ´óѡǰÔâ·êÒÁÀʺڿ͵ÄÍøÂç¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/lee-enterprises-newspaper-disruptions-caused-by-ransomware-attack/
6. Snake KeyloggerбäÖÖ£ºÒþÉí¹¥»÷WindowsÓû§²¢ÇÔȡʹ´¦
2ÔÂ18ÈÕ£¬New Snake Keylogger±äÖÖ£¬Ò²±»³ÆÎª404 Keylogger£¬ÊÇÒ»ÖÖÕë¶ÔWindowsÓû§µÄ¶ñÒâÈí¼þ£¬ÖØÒªÍ¨¹ýÍøÂç´¹µöµç×ÓÓʼþ´«²¼¡£ËüʹÓÃAutoIt¾ç±¾Ëµ»°½øÐÐÒþÉí¹¥»÷£¬¿ÉÄÜÈÆ¹ý³ß¶È·À²¡¶¾½â¾ö¹æ»®£¬Ôö³¤¼ì²âÄѶȡ£¸Ã¶ñÒâÈí¼þ¼Í¼»÷¼ü¡¢²¶»ñÍ´´¦¡¢¼à¶½¼ôÌù°å£¬²¢½«±»µÁÊý¾Ýͨ¹ýµç×ÓÓʼþºÍTelegram»úеÈËй¶µ½ºÅÁîºÍ½ÚÔì·þÎñÆ÷¡£ÔÚ¹¥»÷¹ý³ÌÖУ¬Ëü½«×ÔÉí¸±±¾°µ²ØÔÚϵͳÆô¶¯Îļþ¼ÐÖУ¬²¢Ê¹Óùý³ÌÍÚ¿Õ¼¼Êõ½«¶ñÒâ¸ºÔØ×¢ÈëºÏ·¨µÄ.NET¹ý³Ì£¬´Ó¶øÌӱܼì²â¡£´Ë±í£¬Ëü»¹ÄܼìË÷Êܺ¦ÕßµØÀíµØÎ»£¬¼ì²â¶ÔÔ̺¬Ãô¸ÐÊý¾ÝµÄÎļþ¼ÐµÄ½Ó¼û£¬²¢´Óä¯ÀÀÆ÷×Ô¶¯Ìî³äϵͳÖÐÇÔÈ¡Êý¾Ý¡£ÕâÊÇÒ»ÖÖ¸´ÔÓÇÒÖ°ÄÜ·á˶µÄ¶ñÒâÈí¼þ±äÌ壬¶ÔÈ«ÇòWindowsÓû§×é³ÉÑϳÁÍþв£¬±ØÒª×éÖ¯ºÍÓ×ÎÒ²ÉÈ¡¸ß¼¶Íþв·À»¤ºÍ×Ô¶¯°²È«´ëÊ©À´·ÀÓù¡£
https://hackread.com/snake-keylogger-variant-windows-data-telegram-bots/


¾©¹«Íø°²±¸11010802024551ºÅ