DragonForceÀÕË÷Èí¼þ½èSimpleHelp·ì϶¹¥ÆÆMSP

°ä²¼¹¦·ò 2025-05-28

1. DragonForceÀÕË÷Èí¼þ½èSimpleHelp·ì϶¹¥ÆÆMSP


5ÔÂ27ÈÕ £¬DragonForceÀÕË÷Èí¼þÍÅ»ï³É¹¦¹¥ÆÆÒ»¼ÒÍйܷþÎñÌṩÉÌ £¬²¢ÀûÓÃÆäSimpleHelpÔ¶³Ì¼à¿ØºÍÖÎÀí£¨RMM£©Æ½Ì¨Ö´ÐÐÁËһϵÁжñÒâ»î¶¯ ¡£Sophos¹«Ë¾ÊÜÃüµ÷²éÕâ´Î¹¥»÷ £¬·¢ÏÖÍþвÐÐΪÕßÀûÓÃÁËSimpleHelpµÄ½Ï¾É·ì϶ £¬Ô̺¬CVE-2024-57727¡¢CVE-2024-57728ºÍCVE-2024-57726 £¬À´·ÛËéϵͳ ¡£SimpleHelp×÷ΪһÖÖóÒ×Ô¶³ÌÖ§³ÖºÍ½Ó¼û¹¤¾ß £¬³£±»MSPÓÃÓÚÖÎÀíϵͳºÍ²¿ÊðÈí¼þ £¬Õâ´ÎÈ´³ÉΪ¹¥»÷ÕßµÄÀûÓöÔÏó ¡£¹¥»÷ÕßÊ×ÏÈÀûÓÃSimpleHelp¶Ô¿Í»§ÏµÍ³½øÐпúËÅ £¬ÍøÂçÉ豸Ãû³Æ¡¢ÅäÖá¢Óû§ºÍÍøÂçÏνӵÈÐÅÏ¢ ¡£Ëæºó £¬ËûÃÇÊÔͼÇÔÈ¡Êý¾Ý²¢ÔÚ¿Í»§ÍøÂçÉϲ¿Êð¼ÓÃÜÆ÷ £¬²¿ÃÅÍøÂçÒòʹÓÃSophos¶Ëµã±£»¤¶øÀ¹½ØÏàʼûÜÆ÷ £¬µ«ÆäËû¿Í»§Ôò²»ÐÒÖÐÕÐ £¬É豸±»¼ÓÃÜ £¬Êý¾Ý±»ÇÔÈ¡ £¬²¢ÓÃÓÚË«³ÁÀÕË÷¹¥»÷ ¡£SophosÒÑ·ÖÏíÓëÕâ´Î¹¥»÷ÓйصÄIOC £¬ÒÔÔ®ÊÖ×éÖ¯¼ÓÇ¿ÍøÂç·À»¤ ¡£³Ö¾ÃÒÔÀ´ £¬ÍйܷþÎñÌṩÉÌÒ»ÏòÊÇÀÕË÷Èí¼þÍÅ»ïµÄ³Áµã¹¥»÷Ö¸±ê £¬ÒòÒ»´ÎÈëÇÖ¿ÉÄܵ¼Ö¶à¼Ò¹«Ë¾ÊÜË𠡣һЩÀÕË÷Èí¼þͬÃËרÃÅ×êÑÐMSP³£Óù¤¾ß £¬ÈçSimpleHelp £¬Õâµ¼ÖÂÁËÈçREvil¶ÔKaseyaµÄ´ó¹æÄ£ÀÕË÷Èí¼þ¹¥»÷µÈ¸²ÃðÐÔÊÂÎñ ¡£


https://www.bleepingcomputer.com/news/security/dragonforce-ransomware-abuses-simplehelp-in-msp-supply-chain-attack/


2. ¶íÂÞË¹ÍøÂç¼äµý×éÖ¯¡°Ï´ÒÂÐÜ¡±ÉæÏÓÈëÇÖºÉÀ¼¾¯·½


5ÔÂ27ÈÕ £¬Ò»¸ö´Ëǰ²»ÎªÈËÖªµÄ¶íÂÞ˹֧³ÖµÄÍøÂç¼äµý×éÖ¯¡°Ï´ÒÂÐÜ¡±£¨Laundry Bear£©±»×·×Ùµ½Óë2024Äê9ÔºÉÀ¼¾¯·½°²È«·ì϶ÊÂÎñÓйØ ¡£ºÉÀ¼¹ú¶È¾¯Ô±¾ÖÈ¥Äêй© £¬¹¥»÷ÕßÇÔÈ¡Á˶àÃû¾¯¹ÙµÄ¹¤×÷ÁªÏµÐÅÏ¢ £¬ºÉÀ¼µý±¨ºÍ°²È«×ܾ֣¨AIVD£©ÓëºÉÀ¼¹ú·Àµý±¨ºÍ°²È«¾Ö£¨MIVD£©ÔÚÖܶþµÄ½áºÏÖÒ¸æÖÐ £¬½«¡°Ï´ÒÂÐÜ¡±ÓëÕâ´ÎÈëÇÖÊÂÎñÁªÏµÆðÀ´ £¬²¢ÖÒ¸æ³Æ¸Ã×éÖ¯ºÜ¿ÉÄÜÒ²ÈëÇÖÁËÆäËûºÉÀ¼×éÖ¯ ¡£µ÷²éÏÔʾ £¬¡°Ï´ÒÂÐÜ¡±ÓÚ2024Äê9Ô½ӼûÁËÒ»ÃûºÉÀ¼¾¯Ô±¹ÍÔ±µÄÕË»§ £¬²¢Í¨¹ýÈ«ÇòµØÖ·ÁбíÇÔÈ¡ÁËÓ빤×÷ÓйصÄÁªÏµÐÅÏ¢ £¬¹¥»÷Õß¿ÉÄÜʹÓÃÁË¡°´«µÝ Cookie¡±¹¥»÷ £¬ÀûÓÃÇÔÈ¡µÄCookie¼ÙÒâËùÓÐÕß £¬ÎÞÐèÓû§Ãû»òÃÜÂë¼´¿É½Ó¼ûÐÅÏ¢ ¡£MIVDÖ÷¹Ü±ËµÃ¡¤Àï˹¿Ë°µÊ¾ £¬¸ÃºÚ¿Í×éÖ¯³É¹¦»ñÈ¡ÁËÈ«Çò´óÁ¿×éÖ¯ºÍ¹«Ë¾µÄÃô¸ÐÐÅÏ¢ £¬¶ÔÅ·Ã˺ͱ±Ô¼¹ú¶È³ö¸ñ¸ÐÐËÖ ¡£¡°Ï´ÒÂÐÜ¡±Ò²±»Î¢Èí³ÆÎªVoid Blizzard £¬ÖÁÉÙ×Ô2024Äê4ÔÂÒÔÀ´Ò»Ïò»îÔ¾ £¬×¨Ò»ÓÚÕë¶ÔÎÚ¿ËÀ¼ºÍ±±Ô¼³ÉÔ±¹ú·¢ÆðÓë¶íÂÞ˹սÊõÖ¸±êÒ»ÖµĹ¥»÷ £¬ÆäÕ½ÊõÔ̺¬Ê¹ÓÃÇÔÈ¡µÄƾ֤ºÍÓã²æÊ½ÍøÂç´¹µöµç×ÓÓʼþÀ´Í»ÆÆÖ¸±ê·ÀÓù £¬²¢´ÓÊܺ¦ÕßµÄÊÜϰȾϵͳÖÐÍøÂçºÍÇÔÈ¡ÎļþºÍµç×ÓÓʼþ ¡£


https://www.bleepingcomputer.com/news/security/russian-void-blizzard-cyberspies-linked-to-dutch-police-breach/


3. ºÚ¿ÍαÔìɱ¶¾ÍøÕ¾ÒÔ´«²¼Venom RAT²¢ÇÔÈ¡¼ÓÃÜÇ®°ü


5ÔÂ27ÈÕ £¬ÍøÂ簲ȫ×êÑÐÈËÔ±½üÈÕÅû¶ÁËÁ½ÆðÐÂÐͶñÒâ»î¶¯ ¡£ÆäÒ» £¬¹¥»÷Õß·ÂðBitdefenderɱ¶¾Èí¼þÏÂÔØÍøÕ¾¡°bitdefender-download[.]com¡± £¬ÓÕµ¼Óû§ÏÂÔØº¬VenomRATÔ¶³Ì½Ó¼ûľÂíµÄ¶ñÒⷨʽ ¡£Óû§µã»÷¸Ã·ÂÃ°ÍøÕ¾¡°Download for Windows¡±°´Å¥ºó £¬»á´¥·¢ÎļþÏÂÔØÁ÷³Ì £¬µ«Ä¿Ç°ÓйØBitbucketÕË»§Òѱ»·â½û ¡£ÏÂÔØµÄZIPѹËõ°üÖÐÔ̺¬ÕûºÏÁËVenomRATľÂíÅäÖᢿªÔ´ºóÆÚÀûÓÿò¼ÜSilentTrinity¼°StormKittyÐÅÏ¢ÇÔÈ¡Æ÷µÄ¿ÉÖ´ÐÐÎļþ ¡£VenomRAT×÷ΪQuasar RAT±äÖÖ £¬¾ßº±¼û¾ÝÍøÂçÓëÓÆ¾Ã»¯Ô¶³Ì½ÚÔìÄÜÁ¦ ¡£DomainToolsµý±¨ÍŶÓÖ¸³ö £¬¸Ã´¹µöÍøÕ¾»ù´¡ÉèÊ©Óë¶à¸ö·Âð¼ÓÄôó»Ê¼ÒÒøÐÓע΢Èí·þÎñµÄ¶ñÒâÓòÃûÓйØÁª £¬ÕâЩÓòÃû´ËǰÒѱ»ÓÃÓÚÇÔÈ¡µÇ¼ƾ֤µÄ´¹µö»î¶¯ ¡£¹¥»÷¼¼ÊõÁ´ÏÔʾ £¬VenomRAT¡¢StormKittyÓëSilentTrinity¸÷˾ÆäÖ° £¬¹²Í¬ÊµÏÖ¹¥»÷ ¡£×êÑÐÈËԱǿµ÷ £¬Õâ´Î»î¶¯Ñ¡È¡Ä£¿é»¯¿ªÔ´×é¼þ¹¹½¨¶ñÒâÈí¼þϵͳ £¬ÌáÉýÁ˹¥»÷ЧÄÜÓëÒñ±ÎÐÔ ¡£Í¬ÆÚ £¬Áíһ·ClickFixʽ¹¥»÷»î¶¯Ò²±»ÆØ¹â ¡£¹¥»÷ÕßαÔì¹È¸èMeetÒ³Ãæ £¬ÀûÓÃÐéαÃýÎóÌáÐÑÓÕµ¼Óû§Ö´ÐÐÌØ¶¨PowerShellºÅÁî £¬²¿Êð»ìºÏÅú´¦Öþ籾ʵÏÖÔ¶³Ì½ÚÔì ¡£´Ë±í £¬Õë¶ÔMetaµÄ´ó¹æÄ£´¹µö»î¶¯½èÖú¹È¸èAppSheetÎÞ´úÂ뿪·¢Æ½Ì¨ £¬ÈƹýÓʼþ°²È«ºÍ̸ £¬Í¨¹ý¶¯Ì¬ÌìÉúΨһ°¸ÀýID¶ã±Ü´«Í³¼ì²âϵͳ £¬¼Ù×°³ÉFacebookÖ§³ÖÍŶÓÓÕÆ­Óû§µã»÷Á´½Ó £¬ÇÔȡ˫³É·ÖÈÏÖ¤´úÂë ¡£


https://thehackernews.com/2025/05/cybercriminals-clone-antivirus-site-to_4.html


4. Everest GroupÀÕË÷Èí¼þÍÅ»ïÈëÇÖMediclinic²¢ÒªÇóÊê½ð


5ÔÂ26ÈÕ £¬ÀÕË÷Èí¼þÍÅ»ïEverest GroupÐû³ÆÈëÇÖÁ˼ÛÖµ50ÒÚÃÀÔªµÄÒ½ÁƵ۹úMediclinic £¬²¢Íþв³ý·Ç»ñµÃÊê½ð £¬²»È»½«Ð¹Â¼ûô¸ÐÊý¾Ý ¡£Mediclinic³ÉÁ¢ÓÚ1983Äê £¬ÔÚ¶à¹úÔËÓªÒ½Ôº £¬ÄêÊÕÈë¸ß´ï54ÒÚÃÀÔª ¡£¾Ý°µÍø5ÔÂ26ÈÕ¹«¸æ £¬¸ÃÀÕË÷Èí¼þÍÅ»ïÇÔÈ¡ÁË1000Ãû¹«Ë¾Ô±¹¤Ó×ÎÒÊý¾Ý¼°4GBÄÚ²¿»úÃÜÊý¾Ý £¬²¢ÒªÇó¹«Ë¾ÔÚÎåÌìÄÚÓëÆäÁªÏµ²¢´ï³ÉºÍ̸ £¬²»È»½«¿ªÊͱ»µÁÊý¾Ý ¡£Ä¿Ç° £¬ÉæÏÓÊý¾Ýй¶µÄ¾ßÌåÁìÓòÉв»Ã÷ÏÔ £¬µ«¼øÓÚMediclinic´ÓÊÂÒ½ÁÆÒµÎñ £¬ÕâЩÊý¾Ý¿ÉÄܸ߶ÈÃô¸Ð £¬Ò»µ©Ö¤Êµ £¬½«Î£¼°ÊÜÓ°ÏìµÄÓ×ÎÒ¼°¹«Ë¾ÔËÓª ¡£×êÑÐÈËÔ±Ö¸³ö £¬Ð¹Â¶ÄÚ²¿»úÃÜÎļþ¶ÔÔ±¹¤ÓÈΪΣÏÕ £¬¹¥»÷Õß¿ÉÄÜÀûÓÃÇÔÈ¡µÄÊý¾Ý½øÐÐÉí·Ý͵ÇÔ¡¢Ú²Æ­»òÍøÂç´¹µö¹¥»÷ £¬ÉõÖÁ¿ÉÄÜÒý·¢¶Ô»ù´¡ÉèÊ©µÄ½øÒ»²½¹¥»÷»ò˾·¨Ðж¯ ¡£Everest GroupÀÕË÷Èí¼þÍŶӾݳÆÓë¶íÂÞ˹µÄBlackByte¼¯ÍÅÓÐÁªÏµ £¬×Ô2021ÄêÖÐÆÚÒÔÀ´Ò»ÏòÔڻ £¬±¾Ô»¹Ï®»÷ÁË¿ç¹úÈíÒûÁϳö²úÉÌÊʿڿÉÀÖ £¬ÇÔÈ¡ÁËÔ±¹¤Êý¾Ý¼°»úÃÜÎļþ £¬²¢²ß¶¯ÁË2022Äê10ÔÂÕë¶ÔAT&TµÄ¹¥»÷ ¡£


https://cybernews.com/security/mediclinic-everest-ransomware-attack/


5. RhysidaÀÕË÷ÍÅ»ïÐû³ÆÇÔÈ¡°ÍÎ÷Æû³µ¾­ÏúÉÌCarreraµÄÊý¾Ý


5ÔÂ26ÈÕ £¬½üÈÕ £¬Óë¶íÂÞ˹ÓйØÁªµÄRhysidaÀÕË÷Èí¼þÍÅ»ïÐû³ÆÇÔÈ¡Á˰ÍÎ÷³ÛÃûÆû³µ¾­ÏúÉÌCarreraµÄÃô¸ÐÊý¾Ý £¬Ô̺¬»¤ÕÕ¡¢ºÏÒ»Ö £¬²¢Ë÷Òª100ÍòÃÀÔªÊê½ðÒÔ¸²¸ÇÕæÏà ¡£¸ÃÍÅ»ïÔÚ°µÍø°ä²¼ÉêÃ÷ £¬ÒÔµäÐÍ·½Ê½Íþв¸Ã¹«Ë¾ £¬ÒªÇóÔÚ6ÔÂ1ÈÕǰ֧¸¶¾Þ¶îÊê½ð £¬²»È»½«¹«¿ªÊý¾Ý ¡£Carrera¹«Ë¾×ܲ¿Î»ÓÚÊ¥±£ÂÞ £¬¾­Óª¶à¸öÆû³µÆ·ÅÆÏúÊÛ¼°ÓйطþÎñ ¡£Õâ´ÎÀÕË÷¹¥»÷¿ÉÄܸø¹«Ë¾´øÀ´¾Þ¶îËðʧ £¬Ô̺¬×ÊÔ´·ÖÅ䡢˾·¨·î¸æ¡¢¿Í»§Åâ³¥¼°·£¿îµÈ £¬·£¿î½ð¶î¿ÉÄܸߴï½ü300ÍòÃÀÔª ¡£´Ë±í £¬»¤ÕÕ¸´Ó¡¼þй¶¿ÉÄܵ¼ÖÂÉí·Ý͵ÇÔºÍڲƭ £¬ÊÜÓ°Ïì¿Í»§¿ÉÄܸæ×´¹«Ë¾ÒªÇóÅâ³¥ ¡£³ý¾­¼Ã´¦·£±í £¬¹«Ë¾»¹¿ÉÄÜÔâ·êÃûÓþÇÖº¦ £¬Ó°ÏìÒµÎñ¼¨Ð§ ¡£Rhysida×éÖ¯ÒÔË«³ÁÀÕË÷¼¿Á©ÎÅÃû £¬ÒÑÉøÈëµ½½ÌÓý¡¢Ò½ÁƱ£½¡µÈ¶à¸öÁìÓò £¬×Ô2023Äê5Ô³ÉÁ¢ÒÔÀ´ÒÑÔì³É³¬¹ý202ÃûÊܺ¦Õß ¡£²»Íâ £¬2024Ä꺫¹ú»¥ÁªÍø°²È«¾ÖµÄ×êÑÐÓ××éÒÑÆÆ½â¸ÃÍÅ»ïµÄ¼ÓÃÜ´úÂë £¬²¢ÔÚÆäÍøÕ¾ÉÏ·ÖÏíÁËÃâ·ÑµÄRhysida½âÃܹ¤¾ßºÍÊÖ²á ¡£


https://cybernews.com/security/carrera-chevloret-brazil-ransomware-attack/


6. ºÚ¿ÍÐû³ÆAT&T³Á´óйÃÜÊÂÎñ¶³öÁË3100Íò±Ê¼Í¼


5ÔÂ26ÈÕ £¬¹¥»÷Õß½üÈÕÐû³ÆÊýǧÍòÌõAT&T¼Í¼±»Ð¹Â¶ÖÁÍøÉÏ £¬µ«×êÑÐÈËÔ±ÒÔΪ²»×ã×ã¹»Ö¤¾ÝÖ§³Ö ¡£¸ÃÊÂÎñÏêÇé°ä²¼ÓÚÒ»³ÛÃûºÚ¿ÍÂÛ̳ £¬¹¥»÷Õß³ÆÊý¾Ý¼¯º¬¶à´ï3100ÍòÌõÃô¸ÐÓû§¼Í¼ £¬Ô̺¬¿Í»§È«Ãû¡¢ÐԱ𡢵®ÉúÈÕÆÚ¡¢Ë°ºÅ¡¢É豸ID¡¢CookieID¡¢IPµØÖ·¡¢ÆëÈ«µØÖ·¡¢µç»°ºÅÂë¼°µç×ÓÓʼþµØÖ·µÈ ¡£×êÑÐÍŶӵ÷²é·¢ÏÖ £¬Ñù±¾½öº¬µ¥¸öÓû§¾ßÌåÐÅÏ¢ £¬ÎÞ·¨ÑéÖ¤ÆëÈ«Êý¾Ý¿âÊÇ·ñÕæÓÐ3100Íò±Ê¼Í¼ ¡£²»Íâ £¬Èç¹ûÿ¸öÓû§Â¶³öÐÅÏ¢Á¿Ò»Ñù £¬Ôò³¬300ÍòAT&TÓû§Ó×ÎÒÐÅÏ¢¿ÉÄÜÒÑй¶ ¡£×êÑÐÈËԱǿµ÷ £¬ÈôÐÅÏ¢ÕæÓÐ3100ÍòÐÐ £¬½«ÊÇÑϳÁÓû§ÒþÖÔй¶ ¡£Ö»¹ÜĿǰÎÞ·¨È·ÈÏй¶ÊÂÎñ £¬µ«¹¥»÷Õß5Ô·dz£»îÔ¾ £¬°ä²¼ÁËÊýÊ®Ìõº¬¸÷ÀàÊý¾ÝµÄÌû×Ó ¡£ÈôAT&TÊý¾Ýй¶±»Ö¤Êµ £¬½«¶ÔÊÜÓ°ÏìÓ×ÎÒ×é³ÉÑϳÁÍøÂ簲ȫºÍÒþÖÔ·çÏÕ £¬ÕâЩÊý¾Ý×ãÒÔÒý·¢½ðÈÚڲƭ¡¢ÕË»§µÁÓúÍÉç»á¹¤³Ì¹¥»÷ ¡£AT&T×÷ΪȫÇò×î´óµçÐŹ«Ë¾Ö®Ò» £¬ÄêÓªÊÕ³¬1220ÒÚÃÀÔª £¬ÆäÖØ´ó¹æÄ£Ê¹Æä³ÉΪºÚ¿Í¹¥»÷Ö¸±ê £¬È¥Äê4Ô¸ù«Ë¾¾ÍÔø°µÊ¾¿Í»§Êý¾Ý±»´ÓµÚÈý·½ÔÆÆ½Ì¨·¸·¨ÏÂÔØ £¬ÏÕЩËùÓпͻ§¶¼ÊÜÓ°Ïì ¡£


https://cybernews.com/security/att-data-breach-millions-records-claimed/