ÒÔÉ«ÁÐ×î´óÁ¶Óͳ§BAZANµÄÍøÕ¾Ôâµ½DDoS¹¥»÷ÔÝʱÖжÏ
Ðû²¼Ê±¼ä 2023-07-311¡¢ÒÔÉ«ÁÐ×î´óÁ¶Óͳ§BAZANµÄÍøÕ¾Ôâµ½DDoS¹¥»÷ÔÝʱÖжÏ
¾ÝýÌå7ÔÂ30ÈÕ±¨µÀ£¬ÒÔÉ«ÁÐ×î´óµÄÁ¶Óͳ§ÔËÓªÉÌBAZAN GroupµÄÍøÕ¾Ôâµ½DDoS¹¥»÷£¬ÔÚÈ«Çò´ó²¿ÃŵØÓò¶¼ÎÞ·¨·ÃÎÊ¡£¸Ã¹«Ë¾ÄêÊÕÈëÁè¼Ý135ÒÚÃÀÔª£¬Äê×ÜÁ¶ÓÍÄÜÁ¦Ô¼980Íò¶ÖÔÓÍ¡£±¾ÖÜÄ©£¬BAZAN GroupÍøÕ¾bazan.co.ilºÍeng.bazan.co.ilҪô·ºÆðHTTP 502´íÎó£¬ÒªÃ´±»¹«Ë¾·þÎñÆ÷¾Ü¾ø¡£²âÊÔ·¢ÏÖÒÔÉ«Áо³ÄÚ¿ÉÒÔ·ÃÎÊ£¬Õâ¿ÉÄÜÊÇBAZANʵʩµÄµØÀí·âËø¡£CyberAv3ngersÉù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬»¹¹ûÈ»ÁËBAZAN SCADA ϵͳµÄÆÁÄ»½ØÍ¼£¬²¢Í¸Â¶ÀûÓÃÁËCheck Point·À»ðǽµÄ©¶´ÈëÇָù«Ë¾¡£BAZANÌåÏÖй¶µÄÐÅÏ¢¡°ÍêÈ«ÊÇÄóÔìµÄ¡±£¬¶øCheck Point³ÆÊӲ췢ÏÖûÓЩ¶´µ¼Ö´ËÀ๥»÷¡£
https://www.bleepingcomputer.com/news/security/israels-largest-oil-refinery-website-offline-after-ddos-attack/
2¡¢ºÚ¿ÍÂÛ̳BreachForumsÔ¼21ÍòÌõÓû§¼Ç¼ÔÚ°µÍø±»³öÊÛ
¾Ý7ÔÂ29ÈÕ±¨µÀ£¬ÃûΪ¡°breached_db_person¡±µÄºÚ¿Í³öÊÛÁ˺ڿÍÂÛ̳BreachForumsµÄ±»µÁÊý¾Ý¿â¡£Ä¿Ç°£¬Have I Been PwnedÒÑÈ·Èϱ»µÁBreachForumsÊý¾ÝµÄºÏ·¨ÐÔ¡£¾Ý³Æ£¬±»µÁÊý¾Ý¿â°üÂÞ212000Ìõ¼Ç¼£¬Éæ¼°Óû§Ãû¡¢IPºÍÓʼþµØÖ·¡¢³ÉÔ±µÄ˽ÈËÏûÏ¢ÒÔ¼°argon2¹þÏ£ÃÜÂëµÈÐÅÏ¢¡£ºÚ¿Í¹ûÈ»µÄ2 GBÎļþÖаüÂÞ³ÉÔ±Êý¾Ý¿â¡¢Ë½ÈËÏûÏ¢ºÍÖ§¸¶½»Ò×µÄÏêϸÐÅÏ¢¡£ËäÈ»±»µÁµÄBreachForumsÊý¾ÝÒѾÁ÷ͨ£¬µ«¼Û¸ñ²»·Æ£¬2022Äê11ÔÂ29ÈÕµÄÊý¾Ý¿â¿ìÕյı¨¼Û´Ó10Íòµ½15ÍòÃÀÔª²»µÈ¡£
https://www.hackread.com/breachforums-breached-pii-data-sold-online/
3¡¢BlueBravoÀûÓúóÃÅGraphicalProton¹¥»÷¶«Å·µÄÍâ½»»ú¹¹
Recorded FutureÔÚ7ÔÂ27ÈÕÅû¶Á˶íÂÞ˹Ïà¹ØºÚ¿ÍÍÅ»ïBlueBravoÕë¶Ô¶«Å·µÄÍâ½»»ú¹¹µÄ¹¥»÷»î¶¯¡£3ÔÂÖÁ5ÔÂÆÚ¼ä£¬¹¥»÷ÕßÀûÓÃÁËÓã²æÊ½µöÓã»î¶¯£¬Ö¼ÔÚ·Ö·¢ÐºóÃÅGraphicalProton¡£GraphicalProtonʹÓÃÁËMicrosoft OneDrive»òDropbox½øÐÐͨÐÅ¡£´ËÍ⣬¸ÃÍÅ»ïÀÄÓúϷ¨»¥ÁªÍø·þÎñ(LIS) ×÷ΪÁ¬ÐøÐÔÕ½ÂÔ£¬ÀûÓÃÁËTrello¡¢FirebaseºÍDropboxµÈÔÚÏß·þÎñÈÆ¹ý¼ì²â¡£Ñо¿ÈËÔ±Ô¤²â£¬Î´À´BlueBravo½«¼ÌÐøÕë¶ÔÕþ¸®ºÍÍâ½»»ú¹¹¡£
https://go.recordedfuture.com/hubfs/reports/cta-2023-0727-1.pdf
4¡¢Ñо¿ÈËÔ±·¢ÏÖÀûÓÃBarracuda©¶´°²×°ºóÃÅSUBMARINEµÄ»î¶¯
7ÔÂ29ÈÕ±¨µÀ³Æ£¬Ñо¿ÈËÔ±·¢ÏÖÁËÀûÓÃBarracuda ESGÉ豸ÖЩ¶´£¨CVE-2023-2868£©°²×°SUBMARINEµÄ»î¶¯¡£ÔçÔÚÈ¥Äê10Ô£¬¸Ã©¶´¾Í±»¹¥»÷ÕßÓÃÀ´»ñµÃESGÉ豸µÄ·ÃÎÊȨÏÞ¡£SUBMARINEÊÇÒ»ÖÖÐÂÐͳ־ÃÐÔºóÃÅ£¬ÒÔrootȨÏÞÖ´ÐУ¬´æÔÚÓÚESGÉè±¹ØÁ¬ÄSQLÊý¾Ý¿âÖС£SUBMARINEÓɶà¸ö¹¤¼þ×é³É£¬°üÂÞSQL´¥·¢·¨Ê½¡¢shell½Å±¾ºÍLinuxÊØ»¤·¨Ê½µÄ¼ÓÔØ¿â¡£´ËÍ⣬¹¥»÷Õß¿ÉÒÔÀûÓúóÃŽøÐкáÏòÒÆ¶¯¡£
https://securityaffairs.com/148942/malware/submarine-backdoor-barracuda-esg-attacks.html
5¡¢Trend MicroÅûÂ¶Éæ¼°CherryBlosºÍFakeTradeµÄÁ½Æð»î¶¯
7ÔÂ28ÈÕ£¬Trend MicroÅû¶ÁËÉæ¼°Á½¸öAndroid¶ñÒâÈí¼þCherryBlosºÍFakeTradeµÄ¹¥»÷»î¶¯¡£µÚÒ»¸ö»î¶¯ÀûÓÃÁ÷ÐеÄTelegram¡¢TwitterºÍYouTubeµÈƽ̨Á÷´«£¬ÓÕʹĿ±êÏÂÔØºÍ°²×°¶ñÒâÈí¼þCherryBlos¡£CherryBlos×î³õ·ºÆðÓÚ4Ô·ݣ¬¿Éͨ¹ý¹âѧ×Ö·ûʶ±ð(OCR)´ÓͼƬÖÐÊÕ¼¯Æ¾Ö¤¡£ÁíÒ»Æð»î¶¯Ê¹ÓÃÁ˶à¸öÉù³ÆÊǵç×ÓÉÌÎñƽ̨µÄÆÛÕ©ÐÔÓ¦Óã¬ÔÊÐíͨ¹ýÍÆ¼öºÍ³äֵΪÓû§Ôö¼ÓÊÕÈë£¬Éæ¼°¶ñÒâÈí¼þFakeTrade¡£
https://www.trendmicro.com/en_us/research/23/g/cherryblos-and-faketrade-android-malware-involved-in-scam-campai.html
6¡¢BankCard USAÔâµ½Black Basta¹¥»÷Òѽ»5ÍòÃÀÔªÊê½ð
ýÌå7ÔÂ29Èճƣ¬BankCard USA(BUSA)Ôâµ½ÁËÀÕË÷ÍÅ»ïBlack BastaµÄ¹¥»÷£¬²¢½»ÁË50000ÃÀÔªµÄÊê½ð¡£BankCard USAΪÁè¼Ý100000¼ÒÃÀ¹ú¹«Ë¾Ìṩ¶Ëµ½¶Ëµç×ÓÖ§¸¶²úÎïºÍ·þÎñ¡£ÔÚԼĪһ¸öÔµÄʱ¼äÀBUSAÔÚ̸ÅÐÖÐÒªÇóBlack BastaÌṩһϵÁб£Ö¤£¬²¢Ìá³öÁ˵ÍÓÚÔ¼Û10%µÄÊê½ð£¬ÒªÇó¹¥»÷Õßɾ³ýËûÃÇÇÔÈ¡µÄ200 GBÎļþ¡£Ñо¿ÈËÔ±³Æ£¬¹¥»÷Õß¡°²»»áÐû²¼ÈκÎÐÅÏ¢¡±µÄ±£Ö¤ÏÔÈ»²»ÊÇÕæµÄ£¬ÃÀ¹úÒøÐп¨¹«Ë¾µÄÃû³ÆÒÔ¼°²¿ÃŲÆÕþÎļþºÍ»¤ÕÕÒѾ¹ûÈ»ÁËÒ»¸ö¶àÔ¡£
https://www.databreaches.net/attacked-by-black-basta-bankcard-usa-paid-ransom/