ClopÀÕË÷Èí¼þ×éÖ¯¹¥»÷¹þ·ð´óѧ²¢Íþвй¶Êý¾Ý
°ä²¼¹¦·ò 2025-10-141. ClopÀÕË÷Èí¼þ×éÖ¯¹¥»÷¹þ·ð´óѧ²¢Íþвй¶Êý¾Ý
10ÔÂ12ÈÕ£¬ClopÀÕË÷Èí¼þ×éÖ¯ÔÚÆäTorÊý¾ÝÐ¹Â¶ÍøÕ¾Îª¹þ·ð´óѧ´´½¨×¨ÊôÒ³Ãæ£¬Ðû³Æ½«Ð¹Â¶ÇÔÈ¡µÄÊý¾Ý£¬²¢Ðû³Æ¡°Êý¾Ý´æµµ½øÐÐÖУ¬ÖÖ×ÓÁ´½Ó¼´½«ÍƳö¡±£¬Í¬Ê±Ôð¹Ö¹þ·ðºöÊÓ¿Í»§°²È«¡£¸Ã×éÖ¯×÷Ϊ¶íÓïÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©µÄ´ú±í£¬×Ô2019Äê2Ô³õ´Î³öÏÖÒÔÀ´£¬Æ¾½èÆäÔ´×ÔTA505·¸×OÍÅ£¨»îÔ¾×Ô2014Ä꣩µÄ²¼¾°£¬×¨Ò»ÓÚ¡°´óÐÍÁÔÎ¹¥»÷ÓëË«³ÁÀÕË÷Õ½Êõ£¬³ÉΪȫÇòÍøÂ簲ȫ³Á´óÍþв¡£ClopµÄÔË×÷ģʽ¼«¾ßϵͳÐÔ£ºÏÈͨ¹ýÁãÈÕ·ì϶»òÒ×Êܹ¥»÷µÄµÚÈý·½Èí¼þ£¨ÈçMOVEit¡¢GoAnywhere¡¢Oracle EBS£©ÇÖÈëÖ¸±êÍøÂ磬ÇÔÈ¡Ãô¸ÐÊý¾Ý²¢¼ÓÃÜϵͳ£»Ëæºó½«Êý¾Ý°ä²¼ÖÁ°µÍøÐ¹Â¶ÍøÕ¾£¬Ç¿±ÆÊܺ¦ÕßÖ§¸¶Êê½ð¡£Æä¼¼Êõ¼¿Á©Ô̺¬ÀûÓóõʼ½Ó¼û´úÀí¡¢×Ô¶¯»¯¹¤¾ß¼°¸´ÔÓºáÏòÒÆ¶¯¼¼ÊõÀ©´ó¹¥»÷ÁìÓò£¬Í¬Ê±¶ã±Ü¶íÓïϵͳÒÔÔ¤·À±¾ÍÁ·¨Âɽø¹¥¡£ÖµÍ×ÌùÐĵÄÊÇ£¬¸Ã×éÖ¯³Ö¾Ã±Ü¿ªÇ°ËÕÁª¹ú¶ÈÖ¸±ê£¬ÇÒÆä¶ñÒâÈí¼þÔÚ¶íÓïÍÆËã»úÉÏÎÞ·¨¼¤»î¡£
https://securityaffairs.com/183282/cyber-crime/clop-ransomware-group-claims-the-hack-of-harvard-university.html
2. ´ó¹æÄ£¿ç¹ú½©Ê¬ÍøÂç¶Ô×¼ÃÀ¹úRDP·þÎñ
10ÔÂ13ÈÕ£¬½üÈÕ£¬Ò»¸öÓɳ¬¹ý10ÍòIPµØÖ·×é³ÉµÄ¿ç¶à¹ú½©Ê¬ÍøÂçÕý¶ÔÃÀ¹úÔ¶³Ì×ÀÃæºÍ̸£¨RDP£©·þÎñÌáÒé´ó¹æÄ£¹¥»÷¡£¸Ã»î¶¯×Ô10ÔÂ8ÈÕÆô¶¯£¬×êÑÐÈËԱͨ¹ýIPÆðÔ´·ÖÎöÈ·ÈϹ¥»÷Ô´×Ô¶à¹ú½©Ê¬ÍøÂ缯Ⱥ¡£RDP×÷ΪWindowsϵͳԶ³ÌÏνӵÄÖ÷ÌâºÍ̸£¬³£±»ÖÎÀíÔ±¡¢·þÎñ̨¼°Ô¶³Ì¹¤×÷ÕßʹÓ㬵«Ê¢ÅüÍ·¿ÚÒ׳ÉΪ¹¥»÷Ö¸±ê¡£¹¥»÷Õßͨ³£Í¨¹ýɨÃèÊ¢ÅüÍ·¿Ú¡¢Ç¿ÔìµÇ¼¡¢ÀûÓ÷ì϶»òÖ´Ðа´Ê±¹¥»÷Ö´ÐÐÈëÇÖ¡£±¾´Î¹¥»÷ÖУ¬Íþв¼à¿ØÆ½Ì¨GreyNoise·¢ÏÖ½©Ê¬ÍøÂçÖØÒªÑ¡È¡Á½ÖÖRDPÓйع¥»÷¼¿Á©£ºÆäһΪ¡°RD Web½Ó¼û¼ÆÊ±¹¥»÷¡±£¬Í¨¹ý̽²âRD Web¶Ëµã²¢ÕÉÁ¿ÄäÃûÈÏÖ¤Á÷³ÌµÄÏìÓ¦¹¦·ò²î¾à£¬´§¶ÈÓÐЧÓû§Ãû£»Æä¶þΪ¡°RDP Web¿Í»§¶ËµÇ¼ö¾Ù¡±£¬Í¨¹ý¹Û²ì·þÎñÆ÷ÐÐΪ¼°ÏìÓ¦²î¾àö¾ÙÓû§ÕË»§¡£»î¶¯×î³õÔÚ°ÍÎ÷³öÏÖÒì³£Á÷Á¿¼¤Ôö£¬ËæºóѸ¿ìÀ©É¢ÖÁ°¢¸ùÍ¢¡¢ÒÁÀÊ¡¢Öйú¡¢Ä«Î÷¸ç¡¢¶íÂÞ˹¡¢ÄÏ·Ç¡¢¶ò¹Ï¶à¶ûµÈÈ«Çò¶à¹ú£¬Éæ¼°É豸ÊÜËð¹ú¶ÈÒѳ¬100¸ö¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ÏÕЩËùÓй¥»÷IPµØÖ·¾ù¹²ÏíͨÓÃTCPÖ¸ÎÆ£¬Ö»¹Ü×î´ó¶Î´óС£¨MSS£©´æÔÚ²î¾à£¬µ«×êÑÐÈËÔ±ÒÔΪÕâÔ´ÓÚ½©Ê¬ÍøÂ缯ȺµÄ×é³É¸öÐÔ¡£
https://www.bleepingcomputer.com/news/security/massive-multi-country-botnet-targets-rdp-services-in-the-us/
3. ÃÀ¹úҽѧ³ÉÏñ¾ÞÍ·SimonMedÔâMedusaÀÕË÷Èí¼þ¹¥»÷
10ÔÂ13ÈÕ£¬ÃÀ¹úҽѧ³ÉÏñÌṩÉÌSimonMed Imaging½üÈÕÏò³¬120ÍòÃûÓ×ÎÒ·¢³öÊý¾Ýй¶֪ͨ£¬½ÒʾÆäÔâ·êµÄÑϳÁÍøÂ簲ȫÊÂÎñ¡£¸Ã¹«Ë¾×÷ΪÃÀ¹ú11¸öÖÝÔ¼170¼ÒÒ½ÁÆÖÐÐĵÄÔËÓª·½£¬ÄêÊÕÈ볬5ÒÚÃÀÔª£¬ÌṩMRI¡¢CT¡¢XÉäÏßµÈȫϵÁÐҽѧӰÏñ·þÎñ¡£ÊÂÎñʼÓÚ2025Äê1ÔÂ21ÈÕÖÁ2ÔÂ5ÈÕÆÚ¼ä£¬ºÚ¿ÍÈëÇÖSimonMedϵͳ²¢½Ó¼û¹«Ë¾ÍøÂç¡£1ÔÂ27ÈÕ£¬Æä¹©¸øÉÌÊ×ÏȻ㱨°²È«ÊÂÎñ£¬´ÎÈÕSimonMedÈ·ÈÏÍøÂç´æÔÚ¿ÉÒɻ¡£¹«Ë¾Ëæ¼´Æô¶¯Ó¦¼±ÏìÓ¦£¬Ô̺¬³ÁÖÃÃÜÂë¡¢²¿Êð¶à³É·ÖÈÏÖ¤£¨MFA£©¡¢Ôö³¤¶Ëµã¼ì²âÓëÏìÓ¦£¨EDR£©¼à¿Ø¡¢Ï޶ȵÚÈý·½½Ó¼ûȨÏÞ£¬²¢ÏÞ¶ÈÍøÂçÁ÷Á¿ÖÁ¿ÉÐÅÏνӡ£Í¬Ê±£¬¹«Ë¾Ïò·¨Âɲ¿Ãż°Êý¾Ý°²È«×¨×æ´«µÝÇé¿ö¡£¾ÝMedusaÀÕË÷Èí¼þÉêÃ÷£¬ÆäÇÔÈ¡ÁË212GBÊý¾Ý£¬Ô̺¬Éí·Ý֤ɨÃè¼þ¡¢»¼Õß¾ßÌåÐÅÏ¢¡¢¸¶¿î¼Í¼¡¢ÕË»§Óà¶î¡¢Ò½Áƻ㱨¼°ÔʼɨÃè¼þµÈÃô¸ÐÄÚÈÝ¡£¸ÃÍÅ»ïÒªÇóÖ§¸¶100ÍòÃÀÔªÊê½ð¼°ÖðÈÕ1ÍòÃÀÔªÑÓÆÚ·Ñ£¬²»È»½«¹«¿ªÈ«ÊýÊý¾Ý¡£
https://www.bleepingcomputer.com/news/security/simonmed-says-12-million-patients-impacted-in-january-data-breach/
4. Unity Technologies SpeedTreeÍøÕ¾Ôâ¶ñÒâ´úÂë¹¥»÷
10ÔÂ13ÈÕ£¬ÊÓÆµÓÎÏ·Èí¼þ¿ª·¢¹«Ë¾Unity TechnologiesÅû¶ÆäSpeedTreeÍøÕ¾½áÕËÒ³Ãæ´æÔÚ¶ñÒâ´úÂ룬µ¼ÖÂÊý°ÙÃû¿Í»§Ãô¸ÐÐÅϢй¶¡£¾µ÷²é£¬¸Ã¶ñÒâ´úÂë×Ô2025Äê3ÔÂ13ÈÕÆð±ã±»Ö²ÈëÍøÕ¾£¬Ö±ÖÁ8ÔÂ26ÈÕ±»·¢ÏÖºóµ±¼´É¾³ý£¬ÆÚ¼ä³ÖÐøÇÔÈ¡Óû§Ôڲɰì¹ý³ÌÖÐÊäÈëµÄÃô¸ÐÊý¾Ý¡£Õâ´ÎÊÂÎñÓ°ÏìÁìÓòÃ÷È·£¬Éæ¼°2025Äê3ÔÂ13ÈÕÖÁ8ÔÂ26ÈÕÆÚ¼äͨ¹ýSpeedTreeÍøÕ¾¹ºÎïµÄ428Ãû¿Í»§¡£Ð¹Â¶ÐÅÏ¢Ô̺¬¿Í»§ÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþ¡¢ÐÅÓþ¿¨ºÅ¼°½Ó¼û´úÂëµÈ¸ß¶ÈÃô¸ÐÊý¾Ý¡£Æ¾¾ÝUnity TechnologiesÏòÃåÒòÖÝ×ܼì²ì³¤Ìá½»µÄÊý¾Ýй¶֪ͨ£¬¸Ã¶ñÒâ´úÂëδ¾ÊÚȨ£¬¿ÉÄÜÔÊÐí¹¥»÷Õß»ñÈ¡Óû§ÔÚ½áÕËÒ³ÃæÊäÈëµÄÉÏÊöÐÅÏ¢¡£ÎªÓ¦¶ÔÕâ´Î°²È«ÊÂÎñ£¬Unity TechnologiesѸ¿ì²ÉÈ¡¶àÏî´ëÊ©£º¹Ø¹ØÊÜϰȾµÄSpeedTreeÍøÕ¾ÒÔ×è¶Ï¹¥»÷õè¾¶£¬È«ÃæÉó²éÊÜÓ°ÏìÎļþÒÔÆÀ¹ÀËðʧÁìÓò£¬²¢×Ô¶¯Í¨ÖªÊÜÓ°Ïì¿Í»§¼°¼à¹Ü²¿ÃÅ¡£Í¬Ê±£¬¹«Ë¾¼ÓÇ¿ÁËÍøÂ簲ȫ·À»¤´ëÊ©£¬ÒÔÔ¤·ÀÀàËÆÊÂÎñÔٴβúÉú¡£×÷Ϊ²¹¾È´ëÊ©£¬Unity Technologiesͨ¹ýEquifaxΪÊÜÓ°ÏìÓ×ÎÒÌṩΪÆÚ12¸öÔµÄÃâ·ÑÐÅÓþ¼à¿ØºÍÉí·Ý±£»¤·þÎñ£¬ÒÔ½µµÍÉí·Ý͵ÇÔºÍڲƷçÏÕ¡£
https://securityaffairs.com/183349/data-breach/customer-payment-data-stolen-in-unity-technologiess-speedtree-website-compromise.html
5. SonicWall SSLVPNÕË»§Ôâ´ó¹æÄ£Æ¾Ö¤ÇÔÈ¡¹¥»÷
10ÔÂ13ÈÕ£¬×êÑÐÈËÔ±½üÈÕÖҸ棬ÍþвÐÐΪÕßͨ¹ýÇÔÈ¡µÄÓÐЧƾ֤ÌáÒé´ó¹æÄ£¹¥»÷£¬ÈëÇÖÁ˳¬¹ý100¸öSonicWall SSLVPNÕË»§¡£Õâ´Î¹¥»÷»î¶¯×Ô10ÔÂ4ÈÕÆðÔÚÍйÜÍøÂ簲ȫƽ̨Huntress¼à²âµÄ16¸ö¿Í»§»·¾³Öм¯Öз¢×÷£¬ÖÁ10ÔÂ10ÈÕÈÔ³ÖÐø½øÐУ¬Éæ¼°100Óà¸öÕË»§µÄÒì³£½Ó¼û¡£¹¥»÷ÕßÀûÓÃÇÔÈ¡µÄƾ֤¼±¾çÑéÖ¤¶à¸öÕË»§Éí·Ý£¬ÔÚ²¿Ã۸ÀýÖÐ»á½øÒ»²½Ö´ÐÐÍøÂçɨÃè²¢³¢ÊÔ½Ó¼û±¾µØWindowsÕË»§£¬Ö´ÐкáÏòÉøÈë¡£Huntress×êÑÐÈËÔ±Ö¸³ö£¬¹¥»÷µÄ¿ì¶Å×ë¹æÄ£Åú×¢¹¥»÷Õß°ÑÎÕµÄÊÇÓÐЧƾ֤¶ø·Çͨ¹ý±©Á¦ÆÆ½â»ñÈ¡¡£Ö»¹Ü¹¥»÷Õß¿ÉÄܽâÂëÁËSonicWallÔÆ±¸·ÝÖмÓÃܵķÀ»ðǽÅäÖÃÎļþ£¬µ«ÏÖʵ»ñÈ¡µÄƾ֤ºÍÃÜÔ¿ÈÔÒÔAES-256¼ÓÃÜ´ó¾Ö´æÔÚ£¬Ö±½ÓÀûÓüÛÖµÊÜÏÞ¡£Õâ´ÎÊÂÎñÓëSonicWall½üÆÚ¶³öµÄÔÆ±¸·Ý·ì϶ÎÞÖ±½Ó¹ØÁª£¬¸Ã·ì϶Ëäµ¼Ö·À»ðǽÅäÖÃÎļþй¶£¬µ«ÆäÖÐÆ¾Ö¤Òѵ¥¶À¼ÓÃÜ¡£È»¶ø£¬¹¥»÷ÈÔ¶³ö³öSSLVPNÕË»§µÄ°²È«Òþ»¼¡£
https://www.bleepingcomputer.com/news/security/sonicwall-vpn-accounts-breached-using-stolen-creds-in-widespread-attacks/
6. NPM»ù´¡ÉèÊ©ÔâÀÄÓÃÒý·¢´ó¹æÄ£ÍøÂç´¹µö¹¥»÷
10ÔÂ13ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±½üÈո淢£¬ÍþвÐÐΪÕßÕýͨ¹ýÀÄÓúϷ¨µÄNPMÈí¼þ°ü»ù´¡ÉèÊ©ÌáÒéÐÂÐÍÍøÂç´¹µö¹¥»÷£¬¸Ã»î¶¯Í»ÆÆ´«Í³¹©¸øÁ´¹¥»÷ģʽ£¬ÒѲ¨¼°È«Çò135¸öÄÜÔ´¡¢¹¤ÒµÉ豸¼°¼¼ÊõÁìÓò×éÖ¯¡£Õâ´Î¹¥»÷ÒÔ¡°Beamglea¡±»î¶¯ÎªÖ÷Ì⣬¶ñÒâÈí¼þ°üѡȡ¡°redirect-[a-z0-9]{6}¡±Ìåʽ¶¨Ãû£¬Í¨¹ýNPM°ä²¼ºó£¬ÓÉCDN·þÎñunpkg.comÌṩ¶ñÒâHTMLÎļþ·Ö·¢¡£¹¥»÷Á´ÌõÉè¼Æ¾«ÃÜ£ºÍþвÐÐΪÕßÊ×ÏÈÏòÖ¸±êÊܺ¦Õß·¢ËͼÙ×°³É²É¹º¶©µ¥¡¢¼¼ÊõÎĵµµÄHTML¸½¼þ£¬µ±Êܺ¦ÕßÔÚä¯ÀÀÆ÷Öдò¿ªÎļþʱ£¬ÄÚǶµÄ¶ñÒâJavaScript´úÂë»á´Óunpkg.com¼ÓÔØ£¬²¢µ±¼´½«Óû§³Á¶¨ÏòÖÁ´¹µöÒ³Ãæ¡£¸ÃÒ³Ãæ»áÔ¤ÏÈÌîдÊܺ¦ÕßÓÊÏ䵨ַ£¬ÓªÔì¡°ºÏ·¨µÇ¼ÃÅ»§¡±¼ÙÏóÒÔÓÕÆÆ¾Ö¤ÊäÈë¡£°²È«¹«Ë¾Socket¼à²âÏÔʾ£¬´ËÀà¶ñÒâÈí¼þ°üÊýÁ¿Òѳ¬175¸ö£¬ÀÛ¼ÆÏÂÔØÁ¿³¬26,000´Î£¬Ö»¹Ü²¿ÃÅÏÂÔØÀ´×Ô°²È«×êÑÐÈËÔ±»ò×Ô¶¯»¯É¨Ã蹤¾ß¡£Ö¸±ê×éÖ¯Ô̺¬ArcelorMittal¡¢ThyssenKrupp Nucera¡¢D-LinkµÈ¿ç¹úÆóÒµ£¬¹¥»÷ÁìÓò¼¯ÖÐÔÚÎ÷Å·¹ú¶È£¬Í¬Ê±ÑÓ³¤ÖÁ±±Å·ºÍÑÇÌ«µØÓò¡£
https://www.securityweek.com/npm-infrastructure-abused-in-phishing-campaign-aimed-at-industrial-and-electronics-firms/


¾©¹«Íø°²±¸11010802024551ºÅ