Ô½ÄÏÍøÂç·¸×ïÍÅ»ï CoralRaiderÒâ±íй¶Æä²ÆÕþÊý¾Ý

°ä²¼¹¦·ò 2024-04-10
1. Ô½ÄÏÍøÂç·¸×ïÍÅ»ï CoralRaiderÒâ±íй¶Æä²ÆÕþÊý¾Ý


4ÔÂ9ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬Ò»¸öÓëÔ½ÄÏÓйصÄÐÂÍøÂç·¸×ï×éÖ¯ÒÔÑÇÖÞµÄÓ×ÎÒºÍ×é֯Ϊָ±ê £¬£¬£¬£¬£¬£¬£¬£¬ÊÔͼÇÔÈ¡É罻ýÌåÕÊ»§ÐÅÏ¢ºÍÓû§Êý¾Ý¡£¡£¡£¡£ ¡£¡£¡£CoralRaider ÓÚ 2023 Äêµ×³õ´Î³öÏÖ £¬£¬£¬£¬£¬£¬£¬£¬Ë¼¿Æ Talos Íþвµý±¨Ó××éµÄÍþв×êÑÐÈËÔ±ÔÚ CoralRaider µÄ×îзÖÎöÖÐÖ¸³ö £¬£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯Ò²·¸ÁËһЩÐÂÊÖÃýÎó £¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçÎÞÒâÖÐϰȾÁË×Ô¼ºµÄϵͳ £¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÂ¶³öÁËËûÃǵĻ¡£¡£¡£¡£ ¡£¡£¡£CoralRaider »î¶¯Í¨³£´Ó Windows ¿ì½Ý·½Ê½ (.LNK) ÎļþÆðÍ· £¬£¬£¬£¬£¬£¬£¬£¬Í¨³£Ê¹Óà .PDF À©´óÃû £¬£¬£¬£¬£¬£¬£¬£¬ÊÔͼºýŪÊܺ¦Õß´ò¿ªÎļþ¡£¡£¡£¡£ ¡£¡£¡£CoralRaider ×é֯ʹÓà Telegram ·þÎñÉϵÄ×Ô¶¯»¯»úеÈË×÷ΪºÅÁîºÍ½ÚÔìͨ· £¬£¬£¬£¬£¬£¬£¬£¬²¢´ÓÊܺ¦ÕßµÄϵͳÖÐÇÔÈ¡Êý¾Ý¡£¡£¡£¡£ ¡£¡£¡£È»¶ø £¬£¬£¬£¬£¬£¬£¬£¬ÍøÂç·¸×ï×éÖ¯ËÆºõÒѾ­Ï°È¾ÁËËûÃÇ×Ô¼ºµÄһ̨»úе £¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ˼¿Æ×êÑÐÈËÔ±·¢ÏÖÁ˰䲼µ½¸ÃƵ·µÄÐÅÏ¢µÄÆÁÄ»½ØÍ¼¡£¡£¡£¡£ ¡£¡£¡£


https://www.darkreading.com/vulnerabilities-threats/vietnamese-cybercrime-group-coralraider-nets-financial-data


2. ¿¨°Í˹»ù2023Äê»ã±¨Êý¾ÝÇÔÈ¡¶ñÒâÈí¼þÊÂÎñ¼¤Ôö


4ÔÂ8ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬¿¨°Í˹»ù»ã±¨ÏÔʾ £¬£¬£¬£¬£¬£¬£¬£¬2023 Äê £¬£¬£¬£¬£¬£¬£¬£¬Êý¾ÝÇÔÈ¡¶ñÒâÈí¼þÊÂÎñ¼¤Ôö £¬£¬£¬£¬£¬£¬£¬£¬Õë¶Ô½ü 1000 Íǫ̀É豸 £¬£¬£¬£¬£¬£¬£¬£¬ÍøÂç·¸×ï·Ö×Ó¾ùÔÈÔÚÿ̨ÊÜϰȾÉ豸ÉÏÌáÈ¡ 50.9 ¸öµÇ¼ʹ´¦¡£¡£¡£¡£ ¡£¡£¡£ÕâЩƾ֤±»ÓÃÓÚ¶ñÒâÖ÷ÕÅ £¬£¬£¬£¬£¬£¬£¬£¬ÀýÈç²ß¶¯ÍøÂç¹¥»÷»òÔÚ°µÍøÂÛ̳ºÍ Telegram Ƶ·ÉÏÏúÊÛËüÃÇ¡£¡£¡£¡£ ¡£¡£¡£±»µÁƾ֤º­¸ÇÁìÓò¿í·º £¬£¬£¬£¬£¬£¬£¬£¬´ÓÉ罻ýÌåµÇ¼µ½ÍøÉÏÒøÐзþÎñ¡¢¼ÓÃÜÇ®°üºÍÆóÒµÔÚÏ߯½Ì¨µÇ¼¡£¡£¡£¡£ ¡£¡£¡£¸Ã»ã±¨Ç¿µ÷ .com ÓòÃûÊDZ»µÁÕÊ»§µÄ³Áµã £¬£¬£¬£¬£¬£¬£¬£¬½ôËæÆäºóµÄÊÇÓë°ÍÎ÷ (.br)¡¢Ó¡¶È (.in)¡¢¸çÂ×±ÈÑÇ (.co) ºÍÔ½ÄÏ (.vn) ÓйصÄÓòÃûÇøÓò¡£¡£¡£¡£ ¡£¡£¡£À´×Ô¿¨°Í˹»ùÊý×Ö×ã¼£µý±¨µÄÊý¾ÝÏÔʾ £¬£¬£¬£¬£¬£¬£¬£¬´ÓǰÈýÄêÖжñÒâÈí¼þÊýÁ¿¼¤Ôö 643%¡£¡£¡£¡£ ¡£¡£¡£ÕâÍ»ÏÔÁ˶ñÒâÈí¼þ¶ÔÈ«ÇòÓ×ÎÒÏû·ÑÕßºÍÆóÒµ×é³ÉµÄÈÕÒæÑϳÁµÄÍþв¡£¡£¡£¡£ ¡£¡£¡£Æ¾¾Ý¸Ã»ã±¨ £¬£¬£¬£¬£¬£¬£¬£¬´ÓǰÎåÄêÀ´ £¬£¬£¬£¬£¬£¬£¬£¬È«ÇòÓÐ 443000 ¸öÍøÕ¾Ãæ¶ÔÍ´´¦Ð¹Â¶ÎÊÌâ¡£¡£¡£¡£ ¡£¡£¡£


https://securityboulevard.com/2024/04/10-million-devices-were-infected-by-data-stealing-malware-in-2023/


3. ÃÀ¹ú»·±£¾Öµ÷²éºÚ¿Íй¶ÆäÊý¾ÝµÄ°²È«ÊÂÎñ


4ÔÂ9ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹ú»·¾³±£»£»£»£»£»£»¤ÊðÔÚµ÷²éºÚ¿Íй¶Á˸ûú¹¹¹Ø¼ü»ù´¡ÉèÊ©³Ð°üÉÌÊý¾Ý¿âÖеĴóÁ¿ÁªÏµÐÅÏ¢µÄÖ¸¿Ø¡£¡£¡£¡£ ¡£¡£¡£±»³ÆÎª USDoD µÄÍþвÐÐΪÕßÔÚÒ»¸ö¿É¹«¿ª½Ó¼ûµÄºÚ¿ÍÂÛ̳Éϰ䲼ÁËËûËù˵µÄ 500 MB µÄÁªÏµÐÅÏ¢ºÍ EPA Êý¾Ý¿âÖÐµÄÆäËûÊý¾Ý¡£¡£¡£¡£ ¡£¡£¡£ÐÅÏ¢°²È«Ã½Ì弯ÍÅ֤ʵ £¬£¬£¬£¬£¬£¬£¬£¬½ØÖÁÖÜÒ»ÏÂÎç £¬£¬£¬£¬£¬£¬£¬£¬¸ÃÌû×ÓÈÔÔÚÂÛ̳Éϰ䲼 £¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Ðû³ÆÔ̺¬´ÓÈ«Ãû¡¢µç×ÓÓʼþµØÖ·µ½´úÀí³Ð°üÉÌÏÖʵµØÖ·ÐÅÏ¢µÈËùÓÐÐÅÏ¢µÄѹËõÎļþ¡£¡£¡£¡£ ¡£¡£¡£Ìû×ÓÖÐд·£º¡°¸÷È˺à £¬£¬£¬£¬£¬£¬£¬£¬Breachforums £¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÄãÃÇ×îϲ»¶µÄ TA £¬£¬£¬£¬£¬£¬£¬£¬½ñÌìÎҺܸßÂýµØËµ £¬£¬£¬£¬£¬£¬£¬£¬ÎÒÔÚ°ä²¼ epa.gov ÁªÏµÈËÁбíÊý¾Ý¿â¡£¡£¡£¡£ ¡£¡£¡£ÕâÊÇËûÃÇ [¹Ø¼ü»ù´¡ÉèÊ©] µÄÈ«ÊýÁªÏµÈË £¬£¬£¬£¬£¬£¬£¬£¬²»½öÕë¶Ô¸Ã»ú¹¹½²»°È˰µÊ¾ £¬£¬£¬£¬£¬£¬£¬£¬¸Ã»ú¹¹¶Ô¾Ý³ÆÐ¹Â¶µÄÊý¾Ý½øÐÐÁË¡°³õ²½·ÖÎö¡± £¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÖÕâЩ¼ÍÂ¼ËÆºõÔ̺¬ÒÑÏò¹«¼Ò¹«¿ªµÄóÒ×ÁªÏµÐÅÏ¢ £¬£¬£¬£¬£¬£¬£¬£¬¡°ÒÔÌṩ»·¾³Ó°ÏìµÄÈ«ÃæÇé¿ö¡± ¡±¡£¡£¡£¡£ ¡£¡£¡£


https://news.hitb.org/content/us-epa-investigates-alleged-data-breach-government-hacker


4. unit42¶ñÒâÈí¼þÌáÒéµÄ·ì϶ɨÃè³ÊÉÏÉýÇ÷Ïò


4ÔÂ8ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅÒ£²âÊý¾ÝÅú×¢ £¬£¬£¬£¬£¬£¬£¬£¬Ô½À´Ô½¶àµÄÍþв²Î¼ÓÕßÔÚתÏò¶ñÒâÈí¼þÌáÒéµÄɨÃè¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£±¾ÎÄ»ØÊ×Á˹¥»÷ÕßÈôºÎʹÓÃÊÜϰȾµÄÖ÷»ú¶ÔÆäÖ¸±ê½øÐлùÓÚ¶ñÒâÈí¼þµÄɨÃè £¬£¬£¬£¬£¬£¬£¬£¬¶ø²»ÊÇʹÓøü´«Í³µÄÖ±½ÓɨÃè²½Öè¡£¡£¡£¡£ ¡£¡£¡£ÍþвÐÐΪÕß³Ö¾ÃÒÔÀ´Ò»ÏòÔÚʹÓÃɨÃè²½ÖèÀ´²éÃ÷ÍøÂç»òϵͳÖеķì϶¡£¡£¡£¡£ ¡£¡£¡£Ò»Ð©É¨Ãè¹¥»÷Ô´×ÔÁ¼ÐÔÍøÂç £¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÊÇÓÉÊÜÏ°È¾ÍÆËã»úÉϵĶñÒâÈí¼þÇý¶¯µÄ¡£¡£¡£¡£ ¡£¡£¡£µ±¹¥»÷ÕßÌáÒéÍøÂçÒªÇóÒÔÊÔIJÀûÓÃÖ¸±êÖ÷»úµÄDZÔÚ·ì϶ʱ £¬£¬£¬£¬£¬£¬£¬£¬¾Í»á²úÉúɨÃè¡£¡£¡£¡£ ¡£¡£¡£Ö¸±êÖ÷»úͨ³£ÊÇÁ¼Ð﵀ £¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜÈÝÒ×Êܵ½¹¥»÷ÕßÕë¶ÔµÄ CVE µÄ¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£Í¨¹ý¸ú×ÙÀ´×Ô¶à¸öÍøÂçµÄÁ÷Á¿ÈÕÖ¾ £¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢ÏÖ¶Ô´óÁ¿Ö÷ÕŵصÄÒªÇóÓµÓп´ËÆÁ¼ÐÔµÄõè¾¶¡£¡£¡£¡£ ¡£¡£¡£ºÜ¶àɨÃè°¸Àý £¬£¬£¬£¬£¬£¬£¬£¬ÆäÖй¥»÷ÕßǶÈëÁËÒÔǰδ¼û¹ýµÄ URL £¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÓÐЧ¸ºÔØ´«Êä»ò C2 ÒÔ¼°·ì϶ÀûÓÃÒªÇ󡣡£¡£¡£ ¡£¡£¡£Õâ½µµÍÁ˺óÐøÓÐЧ¸ºÔØ»ò C2 URL ±»°²È«¹©¸øÉÌ×èÖ¹µÄ¿ÉÄÜÐÔ¡£¡£¡£¡£ ¡£¡£¡£ÓÉÓÚÕâЩÓÐЧ¸ºÔØ´«ËÍ»ò C2 URL ¶ÔÓÚ°²È«¹©¸øÉÌÀ´ËµÊÇÐ嵀 £¬£¬£¬£¬£¬£¬£¬£¬Òò¶ø¼ì²âºÍ×èÖ¹´ËÀà³õʼɨÃèÒªÇóÖÁ¹Ø³ÁÒª £¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ¹©¸øÉ̲»Ì«¿ÉÄÜ×èÖ¹ºóÐøÒªÇ󡣡£¡£¡£ ¡£¡£¡£


https://unit42.paloaltonetworks.com/malware-initiated-scanning-attacks/


5. ÀÕË÷ÍÅ»ïRansomHub ´Ó Change Healthcare ÇÔÈ¡4TBÊý¾Ý


4ÔÂ9ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬¾Ý±¨Â· £¬£¬£¬£¬£¬£¬£¬£¬Change Healthcare ÕýÃæ¶ÔÁíÒ»´Î¹¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬Õâ´ÎÊÇÀÕË÷Èí¼þÍÅ»ï RansomHub ÌáÒéµÄ¹¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬¶ø¾ÍÔÚ¼¸ÖÜǰ £¬£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯³ÉΪALPHV/BlackCat ÍøÂç¹¥»÷µÄÊܺ¦Õß¡£¡£¡£¡£ ¡£¡£¡£RansomHub ÒªÇóΪÆä´Ó¸Ã¹«Ë¾ÇÔÈ¡µÄ 4TB Êý¾ÝڲƭÀÕË÷£»£»£»£»£»£»²»È» £¬£¬£¬£¬£¬£¬£¬£¬Ëü»áÍþвÔÚ 12 ÌìÄÚ½«Êý¾ÝÏúÊÛ¸ø³ö¼Û×î¸ßÕß¡£¡£¡£¡£ ¡£¡£¡£±»µÁÐÅÏ¢Ô̺¬ÃÀ¹ú¾üÊÂÈËÔ±ºÍ»¼ÕßµÄÃô¸ÐÊý¾Ý £¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Ò½ÁƼͼºÍ²ÆÕþÐÅÏ¢µÈ¡£¡£¡£¡£ ¡£¡£¡£ÕâʹµÃ½áºÏÒ½ÁƱ£½¡¹«Ë¾µÄ×Ó¹«Ë¾ Change Healthcare ÏÝÈëÁËÒ»¸öÀ§¾³ £¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËü¸Õ¸Õ´ÓÉϴεĹ¥»÷Öи´Ô­¹ýÀ´ £¬£¬£¬£¬£¬£¬£¬£¬±ØÐë¾ö¶¨Ö§¸¶Êê½ðÊÇ·ñÊÇ×îºÃµÄÑ¡Ôñ¡£¡£¡£¡£ ¡£¡£¡£Ö»¹ÜÈËÃÇ¶Ô ALPHV ÊÇ·ñ¸ÄÃûΪ RansomHub £¬£¬£¬£¬£¬£¬£¬£¬»òÕßÊÇ·ñ´æÔÚÖ°ºÎÁªÏµ´æÔÚ³Á´ó²Â²â £¬£¬£¬£¬£¬£¬£¬£¬µ«Îֿ˰µÊ¾ £¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°»¹Ã»Óеõ½Ö¤Êµ £¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ´Ë¿ÌϽáÂÛ»¹ÎªÊ±¹ýÔç¡£¡£¡£¡£ ¡£¡£¡£


https://www.darkreading.com/cyberattacks-data-breaches/round-2-change-healthcare-targeted-second-ransomware-attack


6. AGENT TESLA ¶ñÒâÈí¼þÇÔÈ¡ Chrome ºÍ Firefox µÄµÇ¼ʹ´¦


4ÔÂ8ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±µ÷²éÁË×î½üÕë¶ÔÃÀ¹úºÍ°Ä´óÀûÑÇ×éÖ¯µÄ Agent Tesla ¶ñÒâÈí¼þ»î¶¯ £¬£¬£¬£¬£¬£¬£¬£¬¸Ã»î¶¯Ê¹ÓôøÓÐÐéα²É¹º¶©µ¥µÄÍøÂç´¹µöµç×ÓÓʼþÀ´ÓÕÆ­Êܺ¦Õßµã»÷¶ñÒâÁ´½Ó¡£¡£¡£¡£ ¡£¡£¡£µ¥»÷ºó £¬£¬£¬£¬£¬£¬£¬£¬ÊÜ Cassandra Protector ±£»£»£»£»£»£»¤µÄ»ìºÏµÄ Agent Tesla Ñù±¾¾Í»á±»ÏÂÔØ²¢Ö´ÐÐ £¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÇÔÈ¡»÷¼üºÍµÇ¼ʹ´¦¡£¡£¡£¡£ ¡£¡£¡£µ÷²é·¢ÏÖÁËÁ½ÃûÍøÂç·¸×ï·Ö×Ó Bignosa£¨ÖØÒªÍþв£©ºÍ Gods £¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇʹÓôóÐ͵ç×ÓÓʼþÊý¾Ý¿âºÍ¶à¸ö·þÎñÆ÷½øÐÐ RDP ÏνӺͶñÒâÈí¼þ»î¶¯¡£¡£¡£¡£ ¡£¡£¡£¸Ã¶ñÒâÈí¼þ»î¶¯ÔÚ·Ö·¢¶ñÒâÀ¬»øÓʼþÖ®Ç°Éæ¼°¶à¸ö²½ÖèµÄ³ï±¸½×¶Î¡£¡£¡£¡£ ¡£¡£¡£Bignosa ʹÓà Agent Tesla ½øÐÐÁËÍøÂç´¹µö¹¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬¶ø Gods Áìµ¼ Bignosa Ò²Ôø½øÐйýÍøÂç´¹µö¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£ËûÃÇͨ¹ý Jabber ºÍTeamViewer½øÐÐͨѶ £¬£¬£¬£¬£¬£¬£¬£¬¶ø Bignosa ʹÓà RDP Ïνӵ½ VDS ·þÎñÆ÷²¢·Ö·¢ Agent Tesla¡£¡£¡£¡£ ¡£¡£¡£ 


https://gbhackers.com/agent-tesla-malware-steals-login-credentials-from-chrome-firefox/