ê©ÄÉÒ½ÔºÒòÔâµ½ÍøÂç¹¥»÷¶ø¹Ø¹ØÆäÒ½ÁÆÏµÍ³

°ä²¼¹¦·ò 2024-04-23
1. ê©ÄÉÒ½ÔºÒòÔâµ½ÍøÂç¹¥»÷¶ø¹Ø¹ØÆäÒ½ÁÆÏµÍ³


4ÔÂ22ÈÕ£¬£¬£¬£¬ £¬£¬£¬¸ÃÒ½ÁÆ»ú¹¹Ò²±»³ÆÎª²¼Â³ÈüÒ½Ôº£¬£¬£¬£¬ £¬£¬£¬¾ö¶¨ÆëÈ«¶Â½ØÍÆËã»ú½Ó¼ûÒÔ¶ôÔì¹¥»÷£¬£¬£¬£¬ £¬£¬£¬ÕâÆÈʹԱ¹¤×ªÏò±ÊºÍÖ½³ÖÐøÎª»¼ÕßÌṩ·þÎñ¡£ ¡£¡£¡£¡£¡£CHC-SV °µÊ¾£¬£¬£¬£¬ £¬£¬£¬ÔÚ¾¡ËùÓÐÖÂÁ¦È·±£¿ÉÄÜÔÚÆä»î¶¯ÁìÓòÌṩȫ·½Î»µÄ»¤Àí£¬£¬£¬£¬ £¬£¬£¬²¢²¹³ä˵£¬£¬£¬£¬ £¬£¬£¬ËüÒ»ÏòÔÚÓëµØÓòÒ½ÁÆ»ú¹¹ºÏ×÷£¬£¬£¬£¬ £¬£¬£¬Æ¾¾Ý»¼ÕßµÄÐèÒªµ÷Õû»¼Õߵķ½Ïò¡£ ¡£¡£¡£¡£¡£¹ÌÈ» CHC-SV µÄ´¹Î£»î¶¯ÈÔÔÚ³ÖÐø£¬£¬£¬£¬ £¬£¬£¬µ«ÉÏÖÜÈ¡µÞÁË·Ç´¹Î£ÊÖÊõ·¨Ê½£¬£¬£¬£¬ £¬£¬£¬µ«½øÐÐÁ˲»ÒÀÀµÍÆËã»úϵͳµÄÊÖÊõÒÔ¼°Õë¶ÔÒÑÖªÂýÐÔ²¡»¼ÕßµÄÊÖÊõ¡£ ¡£¡£¡£¡£¡£¸ÃÒ½Ôº°µÊ¾ÒÑ֪ͨÓйص±¾Ö£¬£¬£¬£¬ £¬£¬£¬µ±¾ÖºÍÍøÂ簲ȫר¼ÒÔÚ·ÖÎö¸ÃÊÂÎñ¡£ ¡£¡£¡£¡£¡£CHC-SV °µÊ¾£¬£¬£¬£¬ £¬£¬£¬Æù½ñΪֹ£¬£¬£¬£¬ £¬£¬£¬ÉÐδÌá³öÊê½ðÒªÇ󣬣¬£¬£¬ £¬£¬£¬Ò²Ã»Óз¢ÏÖÊý¾Ý±»µÁµÄÖ¤¾Ý¡£ ¡£¡£¡£¡£¡£¾ÝÒ½Ôº³Æ£¬£¬£¬£¬ £¬£¬£¬¿µ¸´²Ù×÷½«³Áµã¹Ø×¢Ó뻼Õß»¤ÀíÖ±½ÓÓйصÄϵͳ¡£ ¡£¡£¡£¡£¡£²»Í⣬£¬£¬£¬ £¬£¬£¬CHC-SV ¹À¼Æ±ØÒªºÜ³¤¹¦·òÄÜÁ¦¸´Ô­Õý³£ÔËÓª¡£ ¡£¡£¡£¡£¡£CHC-SV ÊÇ·¨¹úê©ÄɵÄÒ»¼ÒÕ¼ÓÐ 840 ¸ö´²Î»µÄÒ½Ôº£¬£¬£¬£¬ £¬£¬£¬Õ¼ÓÐ 2,000 ¶àÃûÔ±¹¤£¬£¬£¬£¬ £¬£¬£¬Ìṩ¼¹Øï¡¢±í¿Æ¡¢²ú¿Æ¡¢¶ù¿Æ¡¢ÐÄÁ鲡ѧºÍÆäËûÒ½ÁƱ£½¡·þÎñ¡£ ¡£¡£¡£¡£¡£


https://www.securityweek.com/cannes-hospital-cancels-medical-procedures-following-cyberattack/


2. Windows Defender ¿ÉÄܻᱻºýŪɾ³ýÊý¾Ý¿â


4ÔÂ22ÈÕ£¬£¬£¬£¬ £¬£¬£¬ÐÅÏ¢°²È«»ú¹¹ SafeBreach µÄ×êÑÐÈËÔ±ÉÏÖÜÎå»áÉÌÁË΢ÈíºÍ¿¨°Í˹»ù°²È«²úÆ·ÖпÉÄÜÔÊÐíÔ¶³Ìɾ³ýÎļþµÄȱµã¡£ ¡£¡£¡£¡£¡£²¢ÇÒ£¬£¬£¬£¬ £¬£¬£¬ËûÃÇÐû³Æ£¬£¬£¬£¬ £¬£¬£¬¼´±ãÁ½¼Ò¹©¸øÉ̶¼Ðû³ÆÒѾ­½¨¸´Á˸ÃÎÊÌ⣬£¬£¬£¬ £¬£¬£¬¸Ã·ì϶ÒÀÈ»Äܹ»±»ÀûÓᣠ¡£¡£¡£¡£¡£SafeBreach °²È«×êÑи±×ܲà Tomer Bar ºÍ°²È«×êÑÐÔ± Shmuel Cohen ÔÚÐÂ¼ÓÆÂ½øÐÐµÄ Black Hat Asia »áÒéÉϰ䷢½²»°Ê±Ú¹ÊÍ˵£¬£¬£¬£¬ £¬£¬£¬Microsoft Defender ºÍ¿¨°Í˹»ùµÄ¶Ëµã¼ì²âºÍÏìÓ¦ (EDR) Äܹ»¼ì²â¶ñÒâÎļþµÄÎó±¨Ö¸±ê£¬£¬£¬£¬ £¬£¬£¬¶øºóɾ³ýËüÃÇ¡£ ¡£¡£¡£¡£¡£¸Ã¹¥»÷ÒÀÀµÓÚ΢ÈíºÍ¿¨°Í˹»ùʹÓÃ×Ö½ÚÊðÃû£¨ÎļþÍ·ÖйÖÒìµÄ×Ö½ÚÐòÁУ©À´¼ì²â¶ñÒâÈí¼þµÄÊÂʵ¡£ ¡£¡£¡£¡£¡£Bar ºÍ Cohen Ê×ÏÈÔÚ VirusTotal ƽ̨ÉÏÕÒµ½ÁËÓë¶ñÒâÈí¼þÓйصÄ×Ö½ÚÊðÃû£¬£¬£¬£¬ £¬£¬£¬¶øºó½«Æä²åÈëÊý¾Ý¿âÖУ¬£¬£¬£¬ £¬£¬£¬²½ÖèÊÇ´´½¨Ò»¸öÃû³ÆÔ̺¬¸ÃÊðÃûµÄÐÂÓû§µÈ¡£ ¡£¡£¡£¡£¡£EDR ·¨Ê½ËæºóÒÔΪ´æ´¢ÊðÃûµÄÊý¾Ý¿âÒѱ»¶ñÒâÈí¼þϰȾ¡£ ¡£¡£¡£¡£¡£ÈôÊÇ EDR ÉèÖÃΪɾ³ýÊÜϰȾµÄÎļþ£¬£¬£¬£¬ £¬£¬£¬Ëü½«Ö´Ðд˲Ù×÷¡£ ¡£¡£¡£¡£¡£Á½ÈËÒÔΪ£¬£¬£¬£¬ £¬£¬£¬Êý¾Ý¿â»òÐé¹¹»úÒò¶øÄܹ»±»Ô¶³Ìɾ³ý¡£ ¡£¡£¡£¡£¡£


https://www.theregister.com/2024/04/22/edr_attack_remote_data_deletion/


3. AKIRA´Ó250¶àÃûÊܺ¦ÕßÄÇÀïÊÕµ½4200ÍòÊê½ð


4ÔÂ21ÈÕ£¬£¬£¬£¬ £¬£¬£¬CISA¡¢FBI¡¢Å·ÖÞÐ̾¯×éÖ¯ºÍºÉÀ¼¹ú¶ÈÍøÂ簲ȫÖÐÐÄ (NCSC-NL) °ä²¼µÄ½áºÏ²¼¸æÏÔʾ£¬£¬£¬£¬ £¬£¬£¬×Ô 2023 ËêÊ×ÒÔÀ´£¬£¬£¬£¬ £¬£¬£¬Akira ÀÕË÷Èí¼þÔËÓªÉÌ´ÓÈ«Çò 250 ¶àÃûÊܺ¦ÕßÄÇÀïÊÕµ½ÁË 4200 ÍòÃÀÔªµÄÊê½ð¡£ ¡£¡£¡£¡£¡£Akira ÀÕË÷Èí¼þ×Ô  2023 Äê 3 ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬ £¬£¬£¬¸Ã¶ñÒâÈí¼þ±³ºóµÄÍþвÐÐΪÕßÐû³ÆÒѾ­ÈëÇÖÁ˶à¸öÐÐÒµµÄ¶à¸ö×éÖ¯£¬£¬£¬£¬ £¬£¬£¬Ô̺¬½ÌÓý¡¢½ðÈںͷ¿µØ²ú¡£ ¡£¡£¡£¡£¡£ÓëÆäËûÀÕË÷Èí¼þÍÅ»ïÒ»Ñù£¬£¬£¬£¬ £¬£¬£¬¸Ã×éÖ¯¿ª·¢ÁËÒ»¿îÕë¶Ô VMware ESXi ·þÎñÆ÷µÄ Linux ¼ÓÃÜÆ÷¡£ ¡£¡£¡£¡£¡£Akira ÀÕË÷Èí¼þÔËÓªÉÌͨ¹ýÔÚ¼ÓÃÜ֮ǰÇÔÈ¡Êܺ¦ÕßµÄÊý¾ÝÀ´Ö´ÐÐË«³ÁÀÕË÷Ä£ÐÍ¡£ ¡£¡£¡£¡£¡£¸ÃÀÕË÷Èí¼þµÄÔçÆÚ°æ±¾ÊÇÓà C++ ±àдµÄ£¬£¬£¬£¬ £¬£¬£¬²¢ÇҸöñÒâÈí¼þÔÚ¼ÓÃÜÎļþÖÐÔö³¤ÁË .akira À©´óÃû¡£ ¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬ £¬£¬£¬´Ó 2023 Äê 8 ÔÂÆð£¬£¬£¬£¬ £¬£¬£¬Ä³Ð© Akira ¹¥»÷ÆðÍ·ÀûÓà Megazord£¬£¬£¬£¬ £¬£¬£¬Ëüѡȡ»ùÓÚ Rust µÄ´úÂ벢ʹÓà .powerranges À©´óÃû¼ÓÃÜÎļþ¡£ ¡£¡£¡£¡£¡£Akira ÍþвÐÐΪÕß¶ÔÖŽ»ÌæÊ¹Óà Megazord ºÍ Akira£¬£¬£¬£¬ £¬£¬£¬Ô̺¬¶ÀÁ¢µ÷²éÈ·¶¨µÄ Akira_v2¡£ ¡£¡£¡£¡£¡£


https://securityaffairs.com/162098/cyber-crime/akira-ransomware-report-fbi.html


4. 2024ÄêµÚÒ»¼¾¶ÈÀÕË÷Èí¼þÖ§¸¶¶î½µÖÁ28%µÄº¹ÇàеÍ


4ÔÂ21ÈÕ£¬£¬£¬£¬ £¬£¬£¬ÀÕË÷Èí¼þ¹¥»÷Õß½ñÄêµÄ¿ª¾Ö²¢²»Ë³Àû£¬£¬£¬£¬ £¬£¬£¬ÍøÂ簲ȫ¹«Ë¾ Coveware µÄͳ¼ÆÊý¾ÝÏÔʾ£¬£¬£¬£¬ £¬£¬£¬Ô½À´Ô½¶àµÄ¹«Ë¾»Ø¾øÖ§¸¶ÀÕË÷ÒªÇ󣬣¬£¬£¬ £¬£¬£¬µ¼Ö 2024 ÄêµÚÒ»¼¾¶ÈÖ§¸¶Êê½ðµÄ¹«Ë¾´ïµ½º¹ÇàÐÂµÍ 28%¡£ ¡£¡£¡£¡£¡£2023 ÄêµÚËÄʱ¶ÈÕâÒ»Êý×Ö Îª 29%£¬£¬£¬£¬ £¬£¬£¬Coveware µÄͳ¼ÆÊý¾ÝÏÔʾ£¬£¬£¬£¬ £¬£¬£¬×Ô 2019 ËêÊ×ÒÔÀ´£¬£¬£¬£¬ £¬£¬£¬Ö§¸¶½ð¶îµÄÏ÷¼õÒ»Ïòά³Ö²»±ä¡£ ¡£¡£¡£¡£¡£ÕâÖÖ½µÂäÊÇÓÉÓÚ×éÖ¯Ö´ÐÐÁ˸üÏȽøµÄ±£» £»£»£»£» £»£»¤´ëÊ©£¬£¬£¬£¬ £¬£¬£¬²»ÐݼӴóµÄ˾·¨Ñ¹Á¦À´Âú×ãÆ­×ӵIJÆÕþÒªÇ󣬣¬£¬£¬ £¬£¬£¬ÒÔ¼°ÍøÂç·¸×ï·Ö×ÓÒ»ÔÙÎ¥·´ÔÚÖ§¸¶Êê½ðµÄÇé¿öϲ»»á°ä²¼»òתÊÛ±»µÁÊý¾ÝµÄ³Ðŵ¡£ ¡£¡£¡£¡£¡£´ÓÒÑÈ·¶¨µÄ·ì϶À´¿´£¬£¬£¬£¬ £¬£¬£¬Ô¶³Ì½Ó¼ûºÍ·ì϶ÀûÓòûÑïÁË×î´óµÄ×÷Ó㬣¬£¬£¬ £¬£¬£¬ÆäÖÐ CVE-2023-20269¡¢CVE-2023-4966 ºÍ CVE-2024-1708-9 ȱµãÔÚµÚÒ»¼¾¶È±»ÀÕË÷Èí¼þÔËÓªÉÌÀûÓõÃ×îΪ¿í·º¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ransomware-payments-drop-to-record-low-of-28-percent-in-q1-2024/


5. Veriti Research·¢ÏÖAndroxgh0stµÄ¹¥»÷»î¶¯¼¤Ôö


4ÔÂ21ÈÕ£¬£¬£¬£¬ £¬£¬£¬Veriti Research ·¢ÏÖ Androxgh0st ¶ñÒâÈí¼þ¼Ò×åÌáÒéµÄ¹¥»÷»î¶¯¼¤Ôö£¬£¬£¬£¬ £¬£¬£¬·¢ÏÖ 600 ¶ą̀·þÎñÆ÷Êܵ½Íþв£¬£¬£¬£¬ £¬£¬£¬ÖØÒªÉ¢²¼ÔÚÃÀ¹úºÍÓ¡¶È¡£ ¡£¡£¡£¡£¡£Æ¾¾Ý Veriti µÄ²©¿ÍÎÄÕ£¬£¬£¬£¬ £¬£¬£¬Androxgh0st ±³ºóµÄµÐÊÖµÄ C2 ·þÎñÆ÷±»Â¶³ö£¬£¬£¬£¬ £¬£¬£¬ÕâÄܹ»Í¨¹ý¶³öÊÜÓ°ÏìµÄÖ¸±êÀ´½øÐлػ÷¡£ ¡£¡£¡£¡£¡£×êÑÐÈËÔ±Ëæºó³ÖÐøÏòÊܺ¦Õß·¢³ö¾¯±¨¡£ ¡£¡£¡£¡£¡£½øÒ»²½×êÑÐÏÔʾ£¬£¬£¬£¬ £¬£¬£¬Androxgh0st ÔËÓªÕßÔÚÀûÓöà¸ö CVE£¨Ô̺¬CVE-2021-3129ºÍCVE-2024-1709£© ÔÚÒ×Êܹ¥»÷µÄ·þÎñÆ÷Éϲ¿Êð Web shell£¬£¬£¬£¬ £¬£¬£¬´Ó¶øÊÚÓèÔ¶³Ì½ÚÔìÖ°ÄÜ¡£ ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬£¬ÓÐÖ¤¾ÝÅú×¢»îÔ¾µÄ Web shell ÓëCVE-2019-2725ÓйØ¡£ ¡£¡£¡£¡£¡£×Ô 2022 Äê 12 Ô³õ´Î±»·¢ÏÖÒÔÀ´£¬£¬£¬£¬ £¬£¬£¬Hackread.com Ò»ÏòÔÚ¸ú×Ù Androxgh0st µÄ²Ù×÷¡£ ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÔËÓªÕßÒÔ²¿ÊðAdhublika ÀÕË÷Èí¼þ¶øÎÅÃû£¬£¬£¬£¬ £¬£¬£¬Ö®Ç°Ôø¹Û²ìµ½ÓëÓë Adhublika ×éÖ¯ÓÐ¹ØµÄ IP µØÖ·½øÐÐͨѶ¡£ ¡£¡£¡£¡£¡£


https://www.hackread.com/androxgh0st-malware-servers-botnets-attacks/


6. Hellokity ÀÕË÷Èí¼þµÄ¹¥»÷ÕßÒÔHelloGookie»Ø¹é


4ÔÂ22ÈÕ£¬£¬£¬£¬ £¬£¬£¬ÍøÂç·¸×ï×éÖ¯£¨ÒÔǰ³ÆÎª Hellokity£©ÒÔбðºÅ¡°HelloGookie¡±³ÁгöÏÖ¡£ ¡£¡£¡£¡£¡£ÍøÂ簲ȫ¼à¹Ü»ú¹¹ MonThreat ͨ¹ýÆä Twitter ÕÊ»§»ã±¨ÁËÕâÒ»½øÕ¹¡£ ¡£¡£¡£¡£¡£Hellokity ÒÔÆä±¸ÊÜÖõÖ÷ÕÅÍøÂç¹¥»÷¶øÎÅÃû£¬£¬£¬£¬ £¬£¬£¬Ò»ÏòÊÇÊý×ÖÀÕË÷µÄ³ÁÒª²Î¼ÓÕß¡£ ¡£¡£¡£¡£¡£¸Ã×éÖ¯Òò²¿ÊðÀÕË÷Èí¼þÉøÈëÆóÒµÍøÂç¡¢¼ÓÃÜÊý¾ÝÒÔ¼°Ë÷Òª¾Þ¶îÊê½ð»»È¡½âÃÜÃÜÔ¿¶ø³ôÃûÔ¶Ñï¡£ ¡£¡£¡£¡£¡£ËûÃǵÄÔËÓª¶Ô¸÷¸öÐÐÒµÔì³ÉÁË×ÌÈÅ£¬£¬£¬£¬ £¬£¬£¬Ó°ÏìÁËÒµÎñÔËÓªºÍÏû·ÑÕßÊý¾ÝÒþÖÔ¡£ ¡£¡£¡£¡£¡£Æ¾¾Ý MonThreat ·ÖÏíµÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬ £¬£¬£¬Hellokity ²»½ö¸ü¸ÄÁËÃû³Æ£¬£¬£¬£¬ £¬£¬£¬²¢ÇÒËÆºõ»¹Éý¼¶ÁËÆäÀÕË÷Èí¼þ¹¤¾ßºÍÕ½Êõ¡£ ¡£¡£¡£¡£¡£ÕâÖÔì·ÅƳÁËÜ¿ÉÄÜÊÇΪÁËÌÓ±ÜÒÑÊÊÓ¦ÆäÏÈǰ²½ÖèµÄ·¨ÂɺÍÍøÂ簲ȫ·ÀÓù¡£ ¡£¡£¡£¡£¡£Hellokity ÒÔÐÂÃû³Æ¡°HelloGookie¡±»Ø¹é£¬£¬£¬£¬ £¬£¬£¬¸øÍøÂ簲ȫרҵÈËÊ¿´øÀ´ÁËеÄÌôÕ½¡£ ¡£¡£¡£¡£¡£


https://gbhackers.com/hellokity-ransomware-new-name/