BlackCat¹¥»÷ÖÐÅ·µÄÄÜÔ´¹«Ë¾Creos Luxembourg SA
°ä²¼¹¦·ò 2022-08-02
¾ÝýÌå8ÔÂ1ÈÕ±¨Â·£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïBlackCatÐû³Æ¶ÔÉÏÖÜÖÐÅ·¹ú¶ÈÌìÈ»Æø¹Ü·ºÍµçÁ¦ÍøÂçÔËÓªÉÌCreos Luxembourg SAµÄ¹¥»÷ÕÆ¹Ü¡£¡£¡£¡£¡£CreosÊÇ5¸öÅ·Ã˹ú¶ÈµÄÄÜÔ´¹©¸øÉÌ£¬£¬£¬£¬£¬Æäĸ¹«Ë¾EncevoÓÚ7ÔÂ25ÈÕй©£¬£¬£¬£¬£¬ËûÃÇÔÚ7ÔÂ22ÈÕÖÁ23ÈÕÔâµ½¹¥»÷¡£¡£¡£¡£¡£¹¥»÷µ¼ÖÂEncevoºÍCreosµÄ¿Í»§ÃÅ»§ÎÞ·¨½Ó¼û£¬£¬£¬£¬£¬µ«·þÎñ²¢Î´Öжϡ£¡£¡£¡£¡£BlackCatÓÚÉÏÖÜÁù½«CreosÔö³¤µ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾£¬£¬£¬£¬£¬²¢ÍþвҪ¹«¿ª180000¸öµÁÈ¡µÄÎļþ£¬£¬£¬£¬£¬×Ü´óÓ×Ϊ150GB£¬£¬£¬£¬£¬Éæ¼°ºÏͬ¡¢ºÍ̸¡¢»¤ÕÕ¡¢Õ˵¥ºÍµç×ÓÓʼþµÈÄÚÈÝ¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/blackcat-ransomware-claims-attack-on-european-gas-pipeline/
2¡¢Group-IB·¢ÏÖÓÉÉÏÍò¸öÓò×é³ÉÕë¶ÔÅ·ÖÞµÄÐéαͶ×ÊȦÌ×
Group-IBÔÚ7ÔÂ29ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öÓÉ11000¶à¸öÓò×é³ÉµÄ¾Þ´óÍøÂ磬£¬£¬£¬£¬ÓÃÓÚÏòÅ·ÖÞµÄÓû§½øÐÐÐéαͶ×Êڿƻ¡£¡£¡£¡£¡£ÕâЩƽ̨ÀûÓÃαÔìµÄÖ¸»Ö¤¾ÝºÍÃûÈË´úÑÔ£¬£¬£¬£¬£¬ÓªÔì³öºÏ·¨µÄÐÎÏó²¢ÒýÓÕ¸ü¶àÖ¸±ê¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯ÒÔ»ñµÃ¸ß»Ø±¨Í¶×ʵĻúÓöΪµö¶ü£¬£¬£¬£¬£¬Ëµ·þÖ¸±ê´æÈëÖÁÉÙ250Å·ÔªÀ´×¢²á·þÎñ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬³¬¹ý5000¸ö¶ñÒâÓòÒÀÈ»´¦Óڻ״̬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÓ¢¹ú¡¢±ÈÀûʱ¡¢µÂ¹ú¡¢ºÉÀ¼¡¢ÆÏÌÑÑÀ¡¢²¨À¼¡¢Å²Íþ¡¢ÈðµäºÍ½Ý¿Ë¹²ºÍ¹ú¡£¡£¡£¡£¡£
https://blog.group-ib.com/investment-scams-europe
3¡¢LockBit¿ÉÀûÓÃWindows DefenderÀ´¼ÓÔØCobalt Strike
Sentinel LabsÔÚ7ÔÂ28ÈÕй©£¬£¬£¬£¬£¬LockBitÀûÓÃMicrosoft DefenderµÄMpCmdRun.exeÀ´½âÃܲ¢×°ÖÃCobalt Strike¡£¡£¡£¡£¡£MpCmdRun.exeÊÇWindows DefenderµÄºÅÁîÐй¤¾ß£¬£¬£¬£¬£¬Ö´ÐÐʱ£¬£¬£¬£¬£¬Ëü½«¼ÓÔØÃûΪmpclient.dllµÄºÏ·¨DLL¡£¡£¡£¡£¡£¹¥»÷Õß¿ª·¢Á˱øÆ÷»¯µÄmpclient.dll£¬£¬£¬£¬£¬²¢½«Æä·ÅÔÚÓÅÏȼÓÔØ¶ñÒâDLLÎļþµÄµØÎ»£¬£¬£¬£¬£¬Ö´ÐеĴúÂë´Óc0000015.logÎļþ½âÃܲ¢¼ÓÔØCobalt Strike payload¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬Éв»Ã÷ÏÔLockBitΪºÎ´ÓʹÓÃVMwareÇл»µ½Ê¹ÓÃWindows DefenderºÅÁîÐй¤¾ßÀ´¼ÓÔØCobalt Strike¡£¡£¡£¡£¡£
https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/
4¡¢×êÑÐÍŶӷ¢ÏÖͳ³ÆÎªDawDropperµÄ¶à¸ö¶ñÒâÈí¼þ·Ö·¢Ä¾Âí
Trend MicroÔÚ7ÔÂ29ÈÕ°ä²¼»ã±¨£¬£¬£¬£¬£¬³ÆÆä·¢ÏÖÁËһ·¶ñÒâ»î¶¯£¬£¬£¬£¬£¬ÀûÓÃGoogle PlayÉ̵êÖеÄ17¸ö¿´ËÆÎÞº¦µÄAndroid dropper£¨Í³³ÆÎªDawDropper£©À´·Ö·¢ÒøÐÐľÂí¡£¡£¡£¡£¡£ÕâЩÀûÓüÙ×°³ÉÀýÈçÎĵµÉ¨Ã蹤¾ß¡¢VPN·þÎñ¡¢¶þάÂëɨÃ蹤¾ßºÍͨ»°¼Í¼¹¤¾ßµÈ¡£¡£¡£¡£¡£DawDropperʹÓõÚÈý·½ÔÆ·þÎñFirebaseʵʱÊý¾Ý¿âÀ´Èƹý¼ì²â²¢¶¯Ì¬»ñµÃpayloadµÄÏÂÔØµØÖ·£¬£¬£¬£¬£¬Ëü»¹ÔÚGitHubÉÏÍйܶñÒâpayload¡£¡£¡£¡£¡£Æ¾¾Ý¹Û²ì£¬£¬£¬£¬£¬DawDropperµÄ±äÌåÄܹ»·Ö·¢4ÖÖÀàÐ͵ÄÒøÐÐľÂí£¬£¬£¬£¬£¬Ô̺¬Octo¡¢Hydra¡¢ErmacºÍTeaBot¡£¡£¡£¡£¡£
https://www.trendmicro.com/en_us/research/22/g/examining-new-dawdropper-banking-dropper-and-daas-on-the-dark-we.html
5¡¢ÃÀ¹úFCCÌáÐÑÖ¼ÔÚÇÔÊØÐÅÏ¢»ò½ðÈÚڿƵÄÍøÂç¹¥»÷Ôö³¤
¾Ý8ÔÂ1ÈÕ±¨Â·£¬£¬£¬£¬£¬ÃÀ¹úÁª¹úͨѶίԱ»á(FCC)ÌáÐÑ£¬£¬£¬£¬£¬Ô½À´Ô½¶àµÄSMS´¹µö»î¶¯ÊÔͼÇÔȡָ±êµÄÓ×ÎÒÐÅÏ¢ºÍ½ðÇ®¡£¡£¡£¡£¡£´ËÀ๥»÷Ò²³ÆÎªsmishing»òrobotsexts£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓø÷À෽ʽÓÕʹָ±ê½»³ö»úÃÜÐÅÏ¢¡£¡£¡£¡£¡£FCC³Æ½üÄêÀ´¶ÔÀ¬»ø¶ÌÐŵÄͶËßÊýÁ¿ÎȲ½ÉÏÉý£¬£¬£¬£¬£¬´Ó2019ÄêµÄÔ¼5700Æð¡¢2020ÄêµÄ14000Æð¡¢2021ÄêµÄ15300Æðµ½2022Äê6ÔÂ30ÈÕµÄ8500Æð¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬¾ÝһЩ¶ÀÁ¢»ã±¨¹À¼Æ£¬£¬£¬£¬£¬Ã¿Ôº±¼ûÊ®ÒÚÌõrobotext£¬£¬£¬£¬£¬ÈçRoboKiller¹À¼ÆÓû§ÔÚ6Ô·ÝÊÕµ½Á˳¬¹ý120ÒÚÌõrobotext¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/133865/cyber-crime/fcc-warns-smishing-attacks.html
6¡¢Kaspersky°ä²¼2022ÄêµÚ¶þ¼¾¶ÈAPT¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨
7ÔÂ28ÈÕ£¬£¬£¬£¬£¬Kaspersky°ä²¼Á˹ØÓÚ2022ÄêµÚ¶þ¼¾¶ÈAPT¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬µØÔµÕþÖÎÒÀÈ»ÊÇAPT·¢Õ¹µÄÇý¶¯Á¦Ö®Ò»£¬£¬£¬£¬£¬¶ø¾¼ÃÀûÒæÊÇAPT¹¥»÷±³ºóµÄ³ÖÐø¶¯»úÖ®Ò»¡£¡£¡£¡£¡£2021Äê·¢ÏÖÁËÁ½¸öUEFIÖ²È뷨ʽ£¬£¬£¬£¬£¬±¾¼¾¶È·¢ÏÖÁËÁíÒ»¸ö¶ñÒâUEFI×é¼þCosmicStrand¡£¡£¡£¡£¡£»ã±¨»¹½éÉÜÁËÕâÒ»¼¾¶ÈµÄAPT¹¥»÷»î¶¯£¬£¬£¬£¬£¬Ô̺¬¶íÂÞ˹UNC1151Õë¶ÔÅ·ÖÞµ±¾Ö»ú¹¹·Ö·¢Ä¾ÂíSunseed£»£»£»£»£»£»Storm CloudÍÅ»ïÀûÓÃGimmick¹¥»÷macOSÓû§£»£»£»£»£»£»TransparentTribe¶ÔÓ¡¶Èµ±¾Ö¹¤×÷ÈËÔ±½øÐÐÐÂÒ»Âֵļäµý¹¥»÷µÈ¡£¡£¡£¡£¡£
https://securelist.com/apt-trends-report-q2-2022/106995/


¾©¹«Íø°²±¸11010802024551ºÅ