Ô½ÄÏÍøÂç·¸×ïÍÅ»ï CoralRaiderÒâ±íй¶Æä²ÆÕþÊý¾Ý
°ä²¼¹¦·ò 2024-04-104ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Ò»¸öÓëÔ½ÄÏÓйصÄÐÂÍøÂç·¸×ï×éÖ¯ÒÔÑÇÖÞµÄÓ×ÎÒºÍ×é֯Ϊָ±ê£¬£¬£¬£¬£¬£¬£¬£¬ÊÔͼÇÔÈ¡É罻ýÌåÕÊ»§ÐÅÏ¢ºÍÓû§Êý¾Ý¡£¡£¡£¡£¡£¡£¡£CoralRaider ÓÚ 2023 Äêµ×³õ´Î³öÏÖ£¬£¬£¬£¬£¬£¬£¬£¬Ë¼¿Æ Talos Íþвµý±¨Ó××éµÄÍþв×êÑÐÈËÔ±ÔÚ CoralRaider µÄ×îзÖÎöÖÐÖ¸³ö£¬£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯Ò²·¸ÁËһЩÐÂÊÖÃýÎ󣬣¬£¬£¬£¬£¬£¬£¬ÀýÈçÎÞÒâÖÐϰȾÁË×Ô¼ºµÄϵͳ£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÂ¶³öÁËËûÃǵĻ¡£¡£¡£¡£¡£¡£¡£CoralRaider »î¶¯Í¨³£´Ó Windows ¿ì½Ý·½Ê½ (.LNK) ÎļþÆðÍ·£¬£¬£¬£¬£¬£¬£¬£¬Í¨³£Ê¹Óà .PDF À©´óÃû£¬£¬£¬£¬£¬£¬£¬£¬ÊÔͼºýŪÊܺ¦Õß´ò¿ªÎļþ¡£¡£¡£¡£¡£¡£¡£CoralRaider ×é֯ʹÓà Telegram ·þÎñÉϵÄ×Ô¶¯»¯»úеÈË×÷ΪºÅÁîºÍ½ÚÔìͨ·£¬£¬£¬£¬£¬£¬£¬£¬²¢´ÓÊܺ¦ÕßµÄϵͳÖÐÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬£¬£¬ÍøÂç·¸×ï×éÖ¯ËÆºõÒѾϰȾÁËËûÃÇ×Ô¼ºµÄһ̨»úе£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ˼¿Æ×êÑÐÈËÔ±·¢ÏÖÁ˰䲼µ½¸ÃƵ·µÄÐÅÏ¢µÄÆÁÄ»½ØÍ¼¡£¡£¡£¡£¡£¡£¡£
https://www.darkreading.com/vulnerabilities-threats/vietnamese-cybercrime-group-coralraider-nets-financial-data
2. ¿¨°Í˹»ù2023Äê»ã±¨Êý¾ÝÇÔÈ¡¶ñÒâÈí¼þÊÂÎñ¼¤Ôö
4ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¿¨°Í˹»ù»ã±¨ÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬2023 Ä꣬£¬£¬£¬£¬£¬£¬£¬Êý¾ÝÇÔÈ¡¶ñÒâÈí¼þÊÂÎñ¼¤Ôö£¬£¬£¬£¬£¬£¬£¬£¬Õë¶Ô½ü 1000 Íǫ̀É豸£¬£¬£¬£¬£¬£¬£¬£¬ÍøÂç·¸×ï·Ö×Ó¾ùÔÈÔÚÿ̨ÊÜϰȾÉ豸ÉÏÌáÈ¡ 50.9 ¸öµÇ¼ʹ´¦¡£¡£¡£¡£¡£¡£¡£ÕâЩƾ֤±»ÓÃÓÚ¶ñÒâÖ÷ÕÅ£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈç²ß¶¯ÍøÂç¹¥»÷»òÔÚ°µÍøÂÛ̳ºÍ Telegram Ƶ·ÉÏÏúÊÛËüÃÇ¡£¡£¡£¡£¡£¡£¡£±»µÁƾ֤º¸ÇÁìÓò¿í·º£¬£¬£¬£¬£¬£¬£¬£¬´ÓÉ罻ýÌåµÇ¼µ½ÍøÉÏÒøÐзþÎñ¡¢¼ÓÃÜÇ®°üºÍÆóÒµÔÚÏ߯½Ì¨µÇ¼¡£¡£¡£¡£¡£¡£¡£¸Ã»ã±¨Ç¿µ÷ .com ÓòÃûÊDZ»µÁÕÊ»§µÄ³Áµã£¬£¬£¬£¬£¬£¬£¬£¬½ôËæÆäºóµÄÊÇÓë°ÍÎ÷ (.br)¡¢Ó¡¶È (.in)¡¢¸çÂ×±ÈÑÇ (.co) ºÍÔ½ÄÏ (.vn) ÓйصÄÓòÃûÇøÓò¡£¡£¡£¡£¡£¡£¡£À´×Ô¿¨°Í˹»ùÊý×Ö×ã¼£µý±¨µÄÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬´ÓǰÈýÄêÖжñÒâÈí¼þÊýÁ¿¼¤Ôö 643%¡£¡£¡£¡£¡£¡£¡£ÕâÍ»ÏÔÁ˶ñÒâÈí¼þ¶ÔÈ«ÇòÓ×ÎÒÏû·ÑÕßºÍÆóÒµ×é³ÉµÄÈÕÒæÑϳÁµÄÍþв¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý¸Ã»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬´ÓǰÎåÄêÀ´£¬£¬£¬£¬£¬£¬£¬£¬È«ÇòÓÐ 443000 ¸öÍøÕ¾Ãæ¶ÔÍ´´¦Ð¹Â¶ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£
https://securityboulevard.com/2024/04/10-million-devices-were-infected-by-data-stealing-malware-in-2023/
3. ÃÀ¹ú»·±£¾Öµ÷²éºÚ¿Íй¶ÆäÊý¾ÝµÄ°²È«ÊÂÎñ
4ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹ú»·¾³±£»£»£»£»£»£»¤ÊðÔÚµ÷²éºÚ¿Íй¶Á˸ûú¹¹¹Ø¼ü»ù´¡ÉèÊ©³Ð°üÉÌÊý¾Ý¿âÖеĴóÁ¿ÁªÏµÐÅÏ¢µÄÖ¸¿Ø¡£¡£¡£¡£¡£¡£¡£±»³ÆÎª USDoD µÄÍþвÐÐΪÕßÔÚÒ»¸ö¿É¹«¿ª½Ó¼ûµÄºÚ¿ÍÂÛ̳Éϰ䲼ÁËËûËù˵µÄ 500 MB µÄÁªÏµÐÅÏ¢ºÍ EPA Êý¾Ý¿âÖÐµÄÆäËûÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÐÅÏ¢°²È«Ã½Ì弯ÍÅ֤ʵ£¬£¬£¬£¬£¬£¬£¬£¬½ØÖÁÖÜÒ»ÏÂÎ磬£¬£¬£¬£¬£¬£¬£¬¸ÃÌû×ÓÈÔÔÚÂÛ̳Éϰ䲼£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Ðû³ÆÔ̺¬´ÓÈ«Ãû¡¢µç×ÓÓʼþµØÖ·µ½´úÀí³Ð°üÉÌÏÖʵµØÖ·ÐÅÏ¢µÈËùÓÐÐÅÏ¢µÄѹËõÎļþ¡£¡£¡£¡£¡£¡£¡£Ìû×ÓÖÐд·£º¡°¸÷È˺㬣¬£¬£¬£¬£¬£¬£¬Breachforums£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÄãÃÇ×îϲ»¶µÄ TA£¬£¬£¬£¬£¬£¬£¬£¬½ñÌìÎҺܸßÂýµØËµ£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÔÚ°ä²¼ epa.gov ÁªÏµÈËÁбíÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£ÕâÊÇËûÃÇ [¹Ø¼ü»ù´¡ÉèÊ©] µÄÈ«ÊýÁªÏµÈË£¬£¬£¬£¬£¬£¬£¬£¬²»½öÕë¶Ô¸Ã»ú¹¹½²»°È˰µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬¸Ã»ú¹¹¶Ô¾Ý³ÆÐ¹Â¶µÄÊý¾Ý½øÐÐÁË¡°³õ²½·ÖÎö¡±£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÖÕâЩ¼ÍÂ¼ËÆºõÔ̺¬ÒÑÏò¹«¼Ò¹«¿ªµÄóÒ×ÁªÏµÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬¡°ÒÔÌṩ»·¾³Ó°ÏìµÄÈ«ÃæÇé¿ö¡± ¡±¡£¡£¡£¡£¡£¡£¡£
https://news.hitb.org/content/us-epa-investigates-alleged-data-breach-government-hacker
4. unit42¶ñÒâÈí¼þÌáÒéµÄ·ì϶ɨÃè³ÊÉÏÉýÇ÷Ïò
4ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅÒ£²âÊý¾ÝÅú×¢£¬£¬£¬£¬£¬£¬£¬£¬Ô½À´Ô½¶àµÄÍþв²Î¼ÓÕßÔÚתÏò¶ñÒâÈí¼þÌáÒéµÄɨÃè¹¥»÷¡£¡£¡£¡£¡£¡£¡£±¾ÎÄ»ØÊ×Á˹¥»÷ÕßÈôºÎʹÓÃÊÜϰȾµÄÖ÷»ú¶ÔÆäÖ¸±ê½øÐлùÓÚ¶ñÒâÈí¼þµÄɨÃ裬£¬£¬£¬£¬£¬£¬£¬¶ø²»ÊÇʹÓøü´«Í³µÄÖ±½ÓɨÃè²½Öè¡£¡£¡£¡£¡£¡£¡£ÍþвÐÐΪÕß³Ö¾ÃÒÔÀ´Ò»ÏòÔÚʹÓÃɨÃè²½ÖèÀ´²éÃ÷ÍøÂç»òϵͳÖеķì϶¡£¡£¡£¡£¡£¡£¡£Ò»Ð©É¨Ãè¹¥»÷Ô´×ÔÁ¼ÐÔÍøÂ磬£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÊÇÓÉÊÜÏ°È¾ÍÆËã»úÉϵĶñÒâÈí¼þÇý¶¯µÄ¡£¡£¡£¡£¡£¡£¡£µ±¹¥»÷ÕßÌáÒéÍøÂçÒªÇóÒÔÊÔIJÀûÓÃÖ¸±êÖ÷»úµÄDZÔÚ·ì϶ʱ£¬£¬£¬£¬£¬£¬£¬£¬¾Í»á²úÉúɨÃè¡£¡£¡£¡£¡£¡£¡£Ö¸±êÖ÷»úͨ³£ÊÇÁ¼ÐԵ쬣¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜÈÝÒ×Êܵ½¹¥»÷ÕßÕë¶ÔµÄ CVE µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£Í¨¹ý¸ú×ÙÀ´×Ô¶à¸öÍøÂçµÄÁ÷Á¿ÈÕÖ¾£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢ÏÖ¶Ô´óÁ¿Ö÷ÕŵصÄÒªÇóÓµÓп´ËÆÁ¼ÐÔµÄõè¾¶¡£¡£¡£¡£¡£¡£¡£ºÜ¶àɨÃè°¸Àý£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖй¥»÷ÕßǶÈëÁËÒÔǰδ¼û¹ýµÄ URL£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÓÐЧ¸ºÔØ´«Êä»ò C2 ÒÔ¼°·ì϶ÀûÓÃÒªÇ󡣡£¡£¡£¡£¡£¡£Õâ½µµÍÁ˺óÐøÓÐЧ¸ºÔØ»ò C2 URL ±»°²È«¹©¸øÉÌ×èÖ¹µÄ¿ÉÄÜÐÔ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÕâЩÓÐЧ¸ºÔØ´«ËÍ»ò C2 URL ¶ÔÓÚ°²È«¹©¸øÉÌÀ´ËµÊÇÐµģ¬£¬£¬£¬£¬£¬£¬£¬Òò¶ø¼ì²âºÍ×èÖ¹´ËÀà³õʼɨÃèÒªÇóÖÁ¹Ø³ÁÒª£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ¹©¸øÉ̲»Ì«¿ÉÄÜ×èÖ¹ºóÐøÒªÇ󡣡£¡£¡£¡£¡£¡£
https://unit42.paloaltonetworks.com/malware-initiated-scanning-attacks/
5. ÀÕË÷ÍÅ»ïRansomHub ´Ó Change Healthcare ÇÔÈ¡4TBÊý¾Ý
4ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¾Ý±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬Change Healthcare ÕýÃæ¶ÔÁíÒ»´Î¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Õâ´ÎÊÇÀÕË÷Èí¼þÍÅ»ï RansomHub ÌáÒéµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¶ø¾ÍÔÚ¼¸ÖÜǰ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯³ÉΪALPHV/BlackCat ÍøÂç¹¥»÷µÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£RansomHub ÒªÇóΪÆä´Ó¸Ã¹«Ë¾ÇÔÈ¡µÄ 4TB Êý¾ÝÚ²ÆÀÕË÷£»£»£»£»£»£»²»È»£¬£¬£¬£¬£¬£¬£¬£¬Ëü»áÍþвÔÚ 12 ÌìÄÚ½«Êý¾ÝÏúÊÛ¸ø³ö¼Û×î¸ßÕß¡£¡£¡£¡£¡£¡£¡£±»µÁÐÅÏ¢Ô̺¬ÃÀ¹ú¾üÊÂÈËÔ±ºÍ»¼ÕßµÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Ò½ÁƼͼºÍ²ÆÕþÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£ÕâʹµÃ½áºÏÒ½ÁƱ£½¡¹«Ë¾µÄ×Ó¹«Ë¾ Change Healthcare ÏÝÈëÁËÒ»¸öÀ§¾³£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËü¸Õ¸Õ´ÓÉϴεĹ¥»÷Öи´Ô¹ýÀ´£¬£¬£¬£¬£¬£¬£¬£¬±ØÐë¾ö¶¨Ö§¸¶Êê½ðÊÇ·ñÊÇ×îºÃµÄÑ¡Ôñ¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÈËÃÇ¶Ô ALPHV ÊÇ·ñ¸ÄÃûΪ RansomHub£¬£¬£¬£¬£¬£¬£¬£¬»òÕßÊÇ·ñ´æÔÚÖ°ºÎÁªÏµ´æÔÚ³Á´ó²Â²â£¬£¬£¬£¬£¬£¬£¬£¬µ«Îֿ˰µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°»¹Ã»Óеõ½Ö¤Êµ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ´Ë¿ÌϽáÂÛ»¹ÎªÊ±¹ýÔç¡£¡£¡£¡£¡£¡£¡£
https://www.darkreading.com/cyberattacks-data-breaches/round-2-change-healthcare-targeted-second-ransomware-attack
6. AGENT TESLA ¶ñÒâÈí¼þÇÔÈ¡ Chrome ºÍ Firefox µÄµÇ¼ʹ´¦
4ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±µ÷²éÁË×î½üÕë¶ÔÃÀ¹úºÍ°Ä´óÀûÑÇ×éÖ¯µÄ Agent Tesla ¶ñÒâÈí¼þ»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬¸Ã»î¶¯Ê¹ÓôøÓÐÐéα²É¹º¶©µ¥µÄÍøÂç´¹µöµç×ÓÓʼþÀ´ÓÕÆÊܺ¦Õßµã»÷¶ñÒâÁ´½Ó¡£¡£¡£¡£¡£¡£¡£µ¥»÷ºó£¬£¬£¬£¬£¬£¬£¬£¬ÊÜ Cassandra Protector ±£»£»£»£»£»£»¤µÄ»ìºÏµÄ Agent Tesla Ñù±¾¾Í»á±»ÏÂÔØ²¢Ö´ÐУ¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÇÔÈ¡»÷¼üºÍµÇ¼ʹ´¦¡£¡£¡£¡£¡£¡£¡£µ÷²é·¢ÏÖÁËÁ½ÃûÍøÂç·¸×ï·Ö×Ó Bignosa£¨ÖØÒªÍþв£©ºÍ Gods£¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇʹÓôóÐ͵ç×ÓÓʼþÊý¾Ý¿âºÍ¶à¸ö·þÎñÆ÷½øÐÐ RDP ÏνӺͶñÒâÈí¼þ»î¶¯¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»î¶¯ÔÚ·Ö·¢¶ñÒâÀ¬»øÓʼþÖ®Ç°Éæ¼°¶à¸ö²½ÖèµÄ³ï±¸½×¶Î¡£¡£¡£¡£¡£¡£¡£Bignosa ʹÓà Agent Tesla ½øÐÐÁËÍøÂç´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¶ø Gods Áìµ¼ Bignosa Ò²Ôø½øÐйýÍøÂç´¹µö¹¥»÷¡£¡£¡£¡£¡£¡£¡£ËûÃÇͨ¹ý Jabber ºÍTeamViewer½øÐÐͨѶ£¬£¬£¬£¬£¬£¬£¬£¬¶ø Bignosa ʹÓà RDP Ïνӵ½ VDS ·þÎñÆ÷²¢·Ö·¢ Agent Tesla¡£¡£¡£¡£¡£¡£¡£
https://gbhackers.com/agent-tesla-malware-steals-login-credentials-from-chrome-firefox/


¾©¹«Íø°²±¸11010802024551ºÅ