FIN8ÀûÓÃSardonicºóÃÅбäÌå·Ö·¢ÀÕË÷Èí¼þNoberus
°ä²¼¹¦·ò 2023-07-201¡¢FIN8ÀûÓÃSardonicºóÃÅбäÌå·Ö·¢ÀÕË÷Èí¼þNoberus
SymantecÔÚ7ÔÂ18Èճƣ¬£¬£¬£¬£¬Æä·¢ÏÖÁËFIN8£¨ÓÖ³ÆSyssphinx£©ÀûÓøĽøµÄSardonic·Ö·¢ÀÕË÷Èí¼þNoberusµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£FIN8×Ô2016Äê1ÔÂÆðÍ·»îÔ¾£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÁãÊÛ¡¢²ÍÒû¡¢¾Æµê¡¢Ò½ÁƱ£½¡ºÍÓéÀÖµÈÐÐÒµ¡£¡£¡£¡£¡£¡£×î½üµÄ¹¥»÷Óë֮ǰµÄÇø±ðÔÚÓÚ£¬£¬£¬£¬£¬×îÖÕpayloadÊÇNoberusÒÔ¼°Ê¹ÓÃÁ˳ÁÐÂÉè¼ÆµÄºóÃÅ¡£¡£¡£¡£¡£¡£¸Ä½øµÄSardonicÓë2021Äê·ÖÎöµÄ°æ±¾ÓкܶàÒ»ÑùµÄÖ°ÄÜ£¬£¬£¬£¬£¬µ«²»ÔÙʹÓÃC++³ß¶È¿â£¬£¬£¬£¬£¬¶øÊÇ´úÌæÎª´¿CʵÏÖ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬SyssphinxתÏòÀÕË÷¹¥»÷Åú×¢£¬£¬£¬£¬£¬ËûÃÇ¿ÉÄܽøÕ¹´ÓÖ¸±ê×éÖ¯ÖлñÈ¡×î´óÀûÈ󡣡£¡£¡£¡£¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/syssphinx-fin8-backdoor
2¡¢ÑÅÊ«À¼÷칫˾Ôâµ½À´×ÔALPHVºÍClopµÄÁ½´ÎÀÕË÷¹¥»÷
¾ÝýÌå7ÔÂ19ÈÕ±¨Â·£¬£¬£¬£¬£¬Á½¸öÀÕË÷ÍÅ»ïALPHVºÍClopÔÚÆäÍøÕ¾ÁгöÁËÃÀ×±¹«Ë¾ÑÅÊ«À¼÷ì¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÈÏ¿ÉÁËÆäÖеÄһ·£¬£¬£¬£¬£¬³Æ¹¥»÷Õß»ñµÃÁ˲¿ÃÅϵͳµÄ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬²¢¿ÉÄÜÇÔÈ¡ÁËÊý¾Ý£¬£¬£¬£¬£¬ËûÃÇÒѲÉÈ¡Ðж¯²¢¹Ø¹ØÁËһЩϵͳ¡£¡£¡£¡£¡£¡£ClopËÆºõÀûÓÃÁËMOVEit Transferƽ̨Öеķì϶»ñµÃ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬²¢Ðû³ÆÇÔÈ¡Á˳¬¹ý131GBµÄÊý¾Ý¡£¡£¡£¡£¡£¡£±¾Öܶþ£¬£¬£¬£¬£¬ALPHVÒ²ÁгöÁËÑÅÊ«À¼÷죬£¬£¬£¬£¬²¢°µÊ¾ÈÔδÊÕµ½¸Ã¹«Ë¾µÄ»Ø¸´¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹³Æ£¬£¬£¬£¬£¬Ã»ÓмÓÃܹ«Ë¾µÄÈκÎϵͳ£¬£¬£¬£¬£¬µ«ÈôÊǸù«Ë¾²»½»É棬£¬£¬£¬£¬ËûÃǽ«Ð¹Â©¸ü¶àÓйر»µÁÊý¾ÝµÄϸ½Ú£¬£¬£¬£¬£¬¿ÉÄÜ»áÓ°Ïì¿Í»§¡¢¹«Ë¾Ô±¹¤ºÍ¹©¸øÉÌ¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/est-e-lauder-beauty-giant-breached-by-two-ransomware-gangs/
3¡¢VirusTotalй¶´óÁ¿Óû§ÐÅÏ¢Éæ¼°FBIºÍNSAµÈ»ú¹¹
ýÌå7ÔÂ18Èճƣ¬£¬£¬£¬£¬¶ñÒâÈí¼þɨÃè·þÎñVirusTotalй¶Á˲¿ÃÅ×¢²á¿Í»§µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñ×îÏÅ×ɰµØÀû¡¶³ß¶È±¨¡·ºÍµÂ¹ú¡¼û÷¾µÖÜ¿¯¡·±¨Â·£¬£¬£¬£¬£¬Ð¹Â¶Îļþ´óÓ×½öΪ313 KB£¬£¬£¬£¬£¬Ô̺¬5600¸ö×¢²áÓû§µÄÐÅÏ¢£¬£¬£¬£¬£¬ÀýÈçÐÕÃû¡¢ÓʼþµØÖ·ºÍ×éÖ¯µÈ¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìÓû§Éæ¼°ÃÀ¹úÍøÂç˾Á¡¢ÃÀ¹ú˾·¨²¿¡¢Áª¹úµ÷²é¾ÖºÍÃÀ¹ú¹ú¶È°²È«¾Ö£¬£¬£¬£¬£¬»¹ÓкÉÀ¼¡¢Ì¨ÍåºÍÓ¢¹úµÄ¹Ù·½»ú¹¹¡£¡£¡£¡£¡£¡£Google Cloud½²»°È˰µÊ¾£¬£¬£¬£¬£¬ÆäÔ±¹¤ÔÚVirusTotalƽ̨ÉÏÎÞÒâ¼ä¹«¿ªÁËÒ»Óײ¿Ãſͻ§×éÖÎÀíÔ±µÄÓʼþºÍ×éÖ¯Ãû³Æ¡£¡£¡£¡£¡£¡£µ±ËûÃÇÒâʶµ½Êý¾Ýй¶ºó£¬£¬£¬£¬£¬Á¢¼´É¾³ýÁËÕâЩÊý¾Ý¡£¡£¡£¡£¡£¡£
https://www.hackread.com/virustotal-data-leak-user-intel-agencies-data/
4¡¢×êÑÐÈËÔ±·¢ÏÖ¼ÙÒâSophosµÄÀÕË÷Èí¼þSophosEncrypt
¾Ý7ÔÂ18ÈÕ±¨Â·£¬£¬£¬£¬£¬ÍøÂ簲ȫ¹©¸øÉÌSophos±»ÃûΪSophosEncryptµÄÐÂÀÕË÷Èí¼þ¼ÙÒâ¡£¡£¡£¡£¡£¡£MalwareHunterTeam·¢ÏÖÁ˸ÃÀÕË÷Èí¼þ£¬£¬£¬£¬£¬Æð³õÒÔΪËüÊÇSophosºì¶ÓÑÝϰµÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬Sophos X-OpsÍŶӰµÊ¾£¬£¬£¬£¬£¬ËûÃÇûÓд´½¨¸Ã¼ÓÃÜ·¨Ê½£¬£¬£¬£¬£¬²¢ÔÚµ÷²é¸ÃÊÂÎñ¡£¡£¡£¡£¡£¡£¼ÓÃÜ·¨Ê½ÊÇÓÃRust¿ª·¢µÄ£¬£¬£¬£¬£¬±»¶¨ÃûΪsophos_encrypt£¬£¬£¬£¬£¬¼ÓÃÜÎļþʱʹÓÃAES256-CBC¼ÓÃܺÍPKCS#7Ìî³ä¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Ëü»¹Äܸü¸ÄWindows×ÀÃæ±ÚÖ½£¬£¬£¬£¬£¬¶·µ¨µØÏÔʾÁËËüËù¼ÙÒâµÄSophos¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/cybersecurity-firm-sophos-impersonated-by-new-sophosencrypt-ransomware/
5¡¢Henry Ford HealthÔâµ½´¹µö¹¥»÷½ü17Íò»¼ÕßÐÅϢй¶
7ÔÂ17ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬Henry Ford Healthй©ÆäÔâµ½´¹µö¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂ168000Ãû»¼ÕßµÄÐÅϢй¶¡£¡£¡£¡£¡£¡£ÊÜÓ°Ï컼ÕßÔÚ±¾ÖÜÒ»±»·î¸æ£¬£¬£¬£¬£¬¹¥»÷ÕßÓÚ3ÔÂ30ÈÕ»ñµÃÁËÆóÒµµç×ÓÓʼþÕÊ»§µÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£µ«¸Ã»ú¹¹ºÜ¿ì·¢ÏÖÁËÕâÖÖ½Ó¼û¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÓʼþÖÐÔ̺¬²¿ÃÅ»¼ÕßÐÅÏ¢£¬£¬£¬£¬£¬ÕâÊÇÔÚ5ÔÂ16ÈÕ·¢Ïֵġ£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢¿ÉÄÜÔ̺¬ÐÕÃû¡¢ÐԱ𡢴ºÇï¡¢»¯ÑéÁ˾֡¢ÊÖÊõÀàÐÍ¡¢Õï¶Ï¡¢Ò½ÁƼͼ±àºÅºÍÄÚ²¿¸ú×Ù±àºÅµÈ¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹³ÆÆäÔÚ¼ÓÇ¿°²È«´ëÊ©²¢ÎªÔ±¹¤Ìṩ½øÒ»²½Åàѵ¡£¡£¡£¡£¡£¡£
https://www.clickondetroit.com/news/local/2023/07/17/henry-ford-health-confirms-data-breach-affecting-168000-patients/
6¡¢Check Point°ä²¼2023ÄêQ2Æ·ÅÆÍøÂç´¹µö»î¶¯µÄ»ã±¨
7ÔÂ18ÈÕ£¬£¬£¬£¬£¬Check Point°ä²¼ÁË2023ÄêQ2Æ·ÅÆÍøÂç´¹µö»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£2023ÄêQ2£¬£¬£¬£¬£¬¿Æ¼¼¹«Ë¾Î¢ÈíµÄÅÅÃûÉÏÉý£¬£¬£¬£¬£¬´ÓQ1µÄµÚÈýλԾÉýÖÁQ2µÄ°ñÊ×£¬£¬£¬£¬£¬Õ¼ËùÓÐÆ·ÅÆ´¹µö¹¥»÷µÄ29%¡£¡£¡£¡£¡£¡£Æä´ÎÊÇGoogle£¨19.5%£©ºÍApple£¨5.2%£©¡£¡£¡£¡£¡£¡£¾ÍÐÐÒµ¶øÑÔ£¬£¬£¬£¬£¬¿Æ¼¼ÐÐÒµ±»¼ÙÒâ×î¶à£¬£¬£¬£¬£¬Æä´ÎÊÇÒøÐкÍÉ罻ýÌåÍøÂ磬£¬£¬£¬£¬ÀýÈçÅÅÃûµÚËĵĸ»¹úÒøÐÐ(4.2%)£¬£¬£¬£¬£¬ÒÔ¼°½ôËæÆäºóµÄÑÇÂíÑ·(4%)ºÍÎÖ¶ûÂê(3.9%)¡£¡£¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬Check Point»¹ÁгöÁ˲¿ÃÅ´¹µö¹¥»÷µÄʾÀý¡£¡£¡£¡£¡£¡£
https://blog.checkpoint.com/security/microsoft-dominates-as-the-most-impersonated-brand-for-phishing-scams-in-q2-2023/


¾©¹«Íø°²±¸11010802024551ºÅ