ÀÕË÷Èí¼þÍÅ»ïÆðÍ·¹«¿ª²¿ÃÅ Change Healthcare µÄÊý¾Ý
°ä²¼¹¦·ò 2024-04-174ÔÂ15ÈÕ£¬£¬£¬£¬£¬RansomHub ÀÕË÷ÍÅ»ïÒÑÆðÍ·¹«¿ªËûÃÇÐû³Æ´Ó United Health ×Ó¹«Ë¾ Change Healthcare ÇÔÈ¡µÄ¹«Ë¾ºÍ»¼ÕßÊý¾Ý£¬£¬£¬£¬£¬Õâ¶Ô¸Ã¹«Ë¾À´ËµÊÇÒ»¸öÂþ³¤¶ø¸´ÔÓµÄÀÕË÷¹ý³Ì¡£¡£¡£¡£¡£¡£¡£½ñÄê 2 Ô£¬£¬£¬£¬£¬ Change Healthcare Ôâ·êÁËÍøÂç¹¥»÷ £¬£¬£¬£¬£¬¶ÔÃÀ¹úÒ½ÁƱ£½¡ÏµÍ³Ôì³ÉÁËÑϳÁ·ÛË飬£¬£¬£¬£¬µ¼ÖÂÒ©·¿ºÍÒ½ÉúÎÞ·¨Ïò±£ÏÕ¹«Ë¾¿ª¾ßÕ˵¥»òÌá³öË÷Åâ¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷×îÖÕ Óë BlackCat/ALPHV ÀÕË÷Èí¼þ²Ù×÷Óйأ¬£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þºóÀ´ËµËûÃÇ ÔÚ¹¥»÷ÆÚ¼äÇÔÈ¡ÁË 6 TB Êý¾Ý¡£¡£¡£¡£¡£¡£¡£ÍþвÐÐΪÕ߯ðÍ·¹«¿ªËûÃÇÐû³ÆÔÚ 2 Ô·ÝÀÕË÷Èí¼þ¹¥»÷ÆÚ¼ä´Ó Change Healthcare ÇÔÈ¡µÄÎļþµÄÆÁÄ»½ØÍ¼¡£¡£¡£¡£¡£¡£¡£ÆÁÄ»½ØÍ¼Ô̺¬ Change Healthcare Óë±£ÏÕÌṩÉÌ£¨Ô̺¬ CVS Caremark¡¢Health Net ºÍ Loomis£©Ö®¼äµÄÊý¾Ý¹²ÏíºÍ̸¡£¡£¡£¡£¡£¡£¡£ÆäËûÎļþÔ̺¬¹ÜÕÊÊý¾Ý£¬£¬£¬£¬£¬Ô̺¬ÕËÁä»ã±¨¡¢±£ÏÕ¸¶¿î»ã±¨ºÍÆäËû²ÆÕþÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/ransomware-gang-starts-leaking-alleged-stolen-change-healthcare-data/
2. CISCO DUO ÖÒ¸æµç»°¹©¸øÉÌÊý¾Ýй¶µ¼Ö MFA ¶ÌÐÅÈÕ־¶³ö
4ÔÂ15ÈÕ£¬£¬£¬£¬£¬Cisco Duo ÖÒ¸æÆäÒ»¼Òµç»°¹©¸øÉ̲úÉúÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬µ¼ÖÂͨ¹ý SMS ºÍ VOIP ·¢Ë͸ø¿Í»§µÄ¶à³É·ÖÉí·ÝÑéÖ¤ (MFA) ÐÂÎÅÊܵ½ÇÖº¦¡£¡£¡£¡£¡£¡£¡£¸Ã°²È«·ì϶²úÉúÓÚ 2024 Äê 4 Ô 1 ÈÕ£¬£¬£¬£¬£¬ÍþвÐÐΪÕßʹÓÃÁËͨ¹ýÍøÂç´¹µö¹¥»÷·¸·¨»ñµÃµÄÌṩÉÌÔ±¹¤µÄÍ´´¦¡£¡£¡£¡£¡£¡£¡£¶øºó£¬£¬£¬£¬£¬ËûÃÇʹÓøýӼûȨÏÞÏÂÔØÁËÒ»×éÊôÓÚ¿Í»§ Duo ÕÊ»§µÄ MFA ¶ÌÐÅÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£¸ü¾ßÌåµØËµ£¬£¬£¬£¬£¬ÍþвÐÐΪÕßÏÂÔØÁË 2024 Äê 3 Ô 1 ÈÕÖÁ 2024 Äê 3 Ô 31 ÈÕÆÚ¼ä·¢Ë͸øÄú Duo ÕÊ»§ÏµÄijЩÓû§µÄ SMS ÐÂÎŵÄÐÂÎÅÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£ÐÂÎÅÈÕÖ¾²»Ô̺¬ÈκÎÐÂÎÅÄÚÈÝ£¬£¬£¬£¬£¬µ«Ô̺¬µç»°ºÅÂ룬£¬£¬£¬£¬Ã¿ÌõÐÂÎÅ·¢Ë͵½µÄµç»°ÔËÓªÉÌ¡¢¹ú¶ÈºÍÖÝ£¬£¬£¬£¬£¬ÒÔ¼°ÆäËûÔªÊý¾Ý£¨ÀýÈçÐÂÎŵÄÈÕÆÚºÍ¹¦·ò¡¢ÐÂÎÅÀàÐ͵ȣ©¡£¡£¡£¡£¡£¡£¡£ÔĶÁ·¢Ë͸øÊÜÓ°ÏìÓ×ÎÒµÄÊý¾Ýй¶֪ͨ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»½Ó¼ûÿÌõÐÂÎÅ·¢Ë͵½µÄµç»°ºÅÂë¡¢µç»°ÔËÓªÉÌ¡¢¹ú¶ÈºÍÖÝ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹»ñµÃÁËÆäËûÔªÊý¾Ý£¬£¬£¬£¬£¬Ô̺¬ÐÂÎŵÄÈÕÆÚºÍ¹¦·ò¡¢ÐÂÎÅÀàÐ͵ȡ£¡£¡£¡£¡£¡£¡£·¢Ïִ˹ýºó£¬£¬£¬£¬£¬¹©¸øÉÌÁ¢¼´·¢Õ¹µ÷²é²¢²ÉÈ¡»º½â´ëÊ©¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/161880/cyber-crime/cisco-duo-data-breach.html
3. SteganoAmor ¹¥»÷ʹÓÃÒþдÊõ¹¥»÷È«Çò 320 ¸ö×éÖ¯
4ÔÂ16ÈÕ£¬£¬£¬£¬£¬TA558 ºÚ¿Í×éÖ¯·¢Õ¹µÄÒ»ÏîлÔÚʹÓÃÒþдÊõ½«¶ñÒâ´úÂë°µ²ØÔÚͼÏñÄÚ£¬£¬£¬£¬£¬´Ó¶ø½«¸÷Àà¶ñÒâÈí¼þ¹¤¾ß´«µÝµ½Ö¸±êϵͳÉÏ¡£¡£¡£¡£¡£¡£¡£ÒþдÊõÊÇÒ»ÖÖ½«Êý¾Ý°µ²ØÔÚ¿´ËÆÎÞº¦µÄÎļþÖеļ¼Êõ£¬£¬£¬£¬£¬Ê¹Óû§ºÍ°²È«²úÆ·ÎÞ·¨¼ì²âµ½ËüÃÇ¡£¡£¡£¡£¡£¡£¡£TA558 ÊÇÒ»¸ö×Ô 2018 ÄêÒÔÀ´Ò»Ïò»îÔ¾µÄÍþв×éÖ¯£¬£¬£¬£¬£¬ÒÔ Õë¶ÔÈ«Çò¾ÆµêºÍÓÎÀÀ×éÖ¯£¨ÓÈÆäÊÇÀ¶¡ÃÀÖÞ£©¶øÎÅÃû¡£¡£¡£¡£¡£¡£¡£Positive Technologies ·¢ÏÖÁ˸Ã×éÖ¯µÄ×îл£¬£¬£¬£¬£¬ÓÉÓÚ¿í·ºÊ¹ÓÃÒþдÊõ£¬£¬£¬£¬£¬±»³ÆÎª¡°SteganoAmor¡±¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚÕâ´Î»î¶¯Öз¢ÏÖÁË 320 ÂŴι¥»÷£¬£¬£¬£¬£¬Ó°ÏìÁ˸÷¸ö²¿Ãź͹ú¶È¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷´ÓÔ̺¬¿´ËÆÎÞº¦µÄÎĵµ¸½¼þ£¨Excel ºÍ Word Îļþ£©µÄ¶ñÒâµç×ÓÓʼþÆðÍ·£¬£¬£¬£¬£¬ÕâЩ¸½¼þÀûÓÃÁË CVE-2017-11882 £¬£¬£¬£¬£¬ÕâÊÇ 2017 Ä꽨¸´µÄÒ»¸ö³£¼ûÖ¸±ê Microsoft Office ¹«Ê½±à×ëÆ÷·ì϶¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-steganoamor-attacks-use-steganography-to-target-320-orgs-globally/
4. BLACKJACKʹÓÃICS¶ñÒâÈí¼þFUXNET¹¥»÷¶íÂÞ˹µÄÖ¸±ê
4ÔÂ15ÈÕ£¬£¬£¬£¬£¬¹¤ÒµºÍÆóÒµÎïÁªÍøÍøÂ簲ȫ¹«Ë¾ Claroty »ã±¨³Æ£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼ Blackjack ºÚ¿Í×éÖ¯Ðû³ÆÊ¹ÓÃÃûΪ Fuxnet µÄ·ÛËéÐÔ ICS ¶ñÒâÈí¼þ·ÛËéÁËĪ˹¿Æ¼°¶íÂÞ˹Ê×¶¼ÒÔ±íµØÓòµÄ´¹Î£¼ì²âºÍÏìÓ¦ÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£¾ÝÐÅ£¬£¬£¬£¬£¬ Blackjack ×éÖ¯ÓëÎÚ¿ËÀ¼µý±¨»ú¹¹ÓйØÁª£¬£¬£¬£¬£¬¸Ã»ú¹¹¶Ô¶íÂÞ˹ָ±ê½øÐÐÁËÆäËû¹¥»÷£¬£¬£¬£¬£¬Ô̺¬ »¥ÁªÍøÌṩÉÌ ºÍ ¾üÊ»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯Ðû³ÆÏ®»÷ÁË×ܲ¿Î»ÓÚĪ˹¿ÆµÄ Moscollector ¹«Ë¾£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÕƹܵØÏÂË®¡¢ÎÛË®ºÍͨѶ»ù´¡ÉèÊ©µÄ½¨ÉèºÍ¼à²â¡£¡£¡£¡£¡£¡£¡£ruexfil.comÍøÕ¾ÌṩÁËÓÐ¹Ø Moscollector ¹¥»÷µÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬ºÚ¿Í»¹°ä²¼ÁËËûÃÇÐû³ÆÊܵ½ÇÖº¦µÄ¼à¿ØÏµÍ³¡¢·þÎñÆ÷ºÍÊý¾Ý¿âµÄÆÁÄ»½ØÍ¼¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/161865/hacking/blackjack-ics-malware-fuxnet.html
5. ºÚ¿Í¶¨Ôì LockBit 3.0 ÀÕË÷Èí¼þÀ´¹¥»÷È«Çò×éÖ¯
4ÔÂ16ÈÕ£¬£¬£¬£¬£¬¿¨°Í˹»ù³¢ÊÔÊÒµÄÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖÁËÖ¤¾Ý£¬£¬£¬£¬£¬Åú×¢ÍøÂç·¸×ïÍÅ»ïÔÚ¶¨Ôì¶ñÒâµÄ LockBit 3.0 ÀÕË÷Èí¼þ£¬£¬£¬£¬£¬ÒÔÕë¶ÔÈ«Çò×éÖ¯½øÐÐÓÐÕë¶ÔÐԵĹ¥»÷¡£¡£¡£¡£¡£¡£¡£ÕâʹµÃÍþвÐÐΪÕß¿ÉÄܶ¨Ôì¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ÒÔÕë¶ÔÌØ¶¨Ö¸±ê²úÉú×î´óµÄÓ°ÏìºÍÓÐЧÐÔ¡£¡£¡£¡£¡£¡£¡£ÕâЩ·¢ÏÖÀ´×Ô×êÑÐÈËÔ±¶Ôй¶µÄLockBit 3.0¹¹½¨Æ÷µÄ·ÖÎö£¬£¬£¬£¬£¬¸Ã¹¹½¨Æ÷ÓÚ 2022 Äê³õ´Î³Ê´Ë¿ÌµØÏÂÂÛ̳ÉÏ¡£¡£¡£¡£¡£¡£¡£¸Ã¹¹½¨Æ÷ʹ·¸×ï·Ö×Ó¿ÉÄÜͨ¹ýÅäÖÃÍøÂç´«²¼Ö°ÄܺͽûÓ÷ÀÓùµÈÑ¡ÏîÀ´ÌìÉúÀÕË÷Èí¼þµÄ¶¨Ôì°æ±¾¡£¡£¡£¡£¡£¡£¡£µ÷²éÈËÔ±·¢ÏÖ¹¥»÷ÕßÒѳɹ¦ÇÔÈ¡´¿Îı¾ÖÎÀíԱʹ´¦¡£¡£¡£¡£¡£¡£¡£¶øºó£¬£¬£¬£¬£¬ËûÃÇʹÓà LockBit ¹¹½¨Æ÷ÌìÉú¶¨ÔìµÄÀÕË÷Èí¼þ±äÌ壬£¬£¬£¬£¬¿ÉÄÜÀûÓÃÕâЩ±»µÁµÄȨÏÞÔÚÍøÂçÉϼ±¾ç´«²¼¡£¡£¡£¡£¡£¡£¡£¶¨ÔìµÄ¶ñÒâÈí¼þÔÚ¶ÔÊÜϰȾϵͳÖеÄÊý¾Ý½øÐмÓÃÜ֮ǰ£¬£¬£¬£¬£¬»á·ÛËé Windows Defender ±£»£»£»£»£»¤²¢É¾³ýÊÂÎñÈÕÖ¾ÒÔ¸²¸ÇÆä×ÙÓ°¡£¡£¡£¡£¡£¡£¡£
https://gbhackers.com/hacker-customize-lockbit-3-0-ransomware-to-attack-orgs-worldwide/
6. »ìÂÒµÄ Libra ½«³ÁµãתÏòSaaSºÍÔÆÒÔ½øÐÐÀÕË÷¹¥»÷
4ÔÂ15ÈÕ£¬£¬£¬£¬£¬¾Ý¹Û²ì£¬£¬£¬£¬£¬±»³ÆÎªMuddled LibraµÄ¹¥»÷Õß»ý¼«Õë¶ÔÈí¼þ¼´·þÎñ (SaaS) ÀûÓ÷¨Ê½ºÍÔÆ·þÎñÌṩÉÌ (CSP) »·¾³£¬£¬£¬£¬£¬ÒÔÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÍþвÐÐΪÕßÒѾÆðÍ·³¢ÊÔÀûÓÃÆäÖÐһЩÊý¾ÝÀ´ÐÖúËûÃǵĹ¥»÷½øÕ¹£¬£¬£¬£¬£¬²¢ÔÚÊÔͼͨ¹ýËûÃǵŤ×÷»ñÀûʱÓÃÓÚÀÕË÷¡£¡£¡£¡£¡£¡£¡£Muddled Libra£¬£¬£¬£¬£¬Ò²³ÆÎª Starfraud¡¢UNC3944¡¢Scatter Swine ºÍ Scattered Spider£¬£¬£¬£¬£¬ÊÇÒ»¸ö³ôÃûÔ¶ÑïµÄÍøÂç·¸×ï×éÖ¯£¬£¬£¬£¬£¬ÀûÓø´ÔÓµÄÉç»á¹¤³Ì¼¼ÊõÀ´»ñµÃ¶ÔÖ¸±êÍøÂçµÄ³õʼ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹ÔøÒÔ¶àÖÖ·½Ê½Í¨¹ý½Ó¼ûÊܺ¦ÕßÍøÂçÀ´»ñÀû£¬£¬£¬£¬£¬Ô̺¬Í¨¹ýÀÕË÷Èí¼þºÍÊý¾Ý͵ÇÔ½øÐÐÀÕË÷¡£¡£¡£¡£¡£¡£¡£ÍþвÐÐΪÕßÕ½ÊõÑݱäµÄÒ»¸ö¹Ø¼ü·½ÃæÊÇ£¬£¬£¬£¬£¬ÔÚ¼ÙÒâÔ®ÊǪ̈¹¤×÷ÈËԱͨ¹ýµç»°»ñÈ¡ÃÜÂëʱ£¬£¬£¬£¬£¬Ê¹ÓÿúËż¼ÊõÀ´¼ø±ðÖ¸±êÖÎÀíÓû§¡£¡£¡£¡£¡£¡£¡£¿úËŽ׶λ¹ÑÓ³¤µ½ Muddled Libra ½øÐÐ¿í·ºµÄ×êÑУ¬£¬£¬£¬£¬ÒÔ²éÕÒÓйØÖ¸±ê×é֯ʹÓõÄÀûÓ÷¨Ê½ºÍÔÆ·þÎñÌṩÉ̵ÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2024/04/muddled-libra-shifts-focus-to-saas-and.html?&web_view=true


¾©¹«Íø°²±¸11010802024551ºÅ