Ô¼µ©AbdaliÒ½ÔºÔâµ½RhysidaµÄ¹¥»÷±»ÀÕË÷10 BTC
Ðû²¼Ê±¼ä 2023-12-27¾Ý12ÔÂ26ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïRhysida½«Ô¼µ©µÄÒ»¼ÒÒ½ÔºAbdali HospitalÌí¼Óµ½ÆäTorÍøÕ¾ÖС£¹¥»÷ÕßÐû²¼Á˱»µÁÎļþµÄͼƬ×÷Ϊ¹¥»÷Ö¤¾Ý£¬°üÂÞÉí·ÝÖ¤ºÍºÏͬµÈ¡£Í¬Ê±£¬Ëü»¹Éù³ÆÇÔÈ¡ÁË´óÁ¿Ãô¸ÐÊý¾Ý£¬²¢ÒÔ10 BTCµÄ¼Û¸ñ½øÐÐÅÄÂô¡£ÓëÒÔÍùÒ»Ñù£¬Rhysida¼Æ»®½«±»µÁÊý¾Ý³öÊÛ¸øΨһµÄÂò¼Ò£¬²¢½«ÔÚͨ¸æÐû²¼ºóµÄÆßÌìÄÚ¹ûÈ»ÕâЩÊý¾Ý¡£Rhysida×Ô½ñÄê5ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬Æ¾¾ÝÆäTorÍøÕ¾Òѹ¥»÷ÁËÖÁÉÙ62¼Ò¹«Ë¾¡£
https://securityaffairs.com/156430/cyber-crime/rhysida-ransomware-abdali-hospital-jordan.html
2¡¢FACCTÅû¶Cloud AtlasÕë¶Ô¶íÂÞ˹ÆóÒµµÄµöÓã¹¥»÷
ýÌå12ÔÂ25Èճƣ¬Group-IBµÄ¶ÀÁ¢ÍøÂçÄþ¾²¹«Ë¾FACCTÅû¶ÁËCloud AtlasÕë¶Ô¶íÂÞ˹ÆóÒµµÄµöÓã¹¥»÷¡£Cloud AtlasÊÇÒ»¸öÀ´Ô´²»Ã÷µÄ¼äµýÍŻÖÁÉÙ´Ó2014Ä꿪ʼ»îÔ¾¡£Æä×îеÄɱÉËÁ´Í¨¹ýRTFÄ£°å×¢ÈëÀÖ³ÉÀûÓÃÁËCVE-2017-11882£¬ÎªÂôÁ¦ÏÂÔغÍÔËÐлìÏýHTAÎļþµÄshellcodeÆÌƽÁËÃÅ·¡£¶ñÒâHTMLÓ¦ÓÃËæºóÆô¶¯Visual Basic½Å±¾(VBS)Îļþ£¬ÕâЩÎļþ×îÖÕÂôÁ¦´ÓÔ¶³Ì·þÎñÆ÷¼ìË÷²¢Ö´ÐÐδ֪µÄVBS´úÂë¡£
https://thehackernews.com/2023/12/cloud-atlas-spear-phishing-attacks.html
3¡¢Group-IB³Æ½üÆÚð³ä¿ìµÝ¹«Ë¾µÄµöÓã»î¶¯¼¤Ôö34%
Group-IBÔÚ12ÔÂ21Èճƣ¬ÔÚÊ¥µ®½ÚÇ°¼¸ÖÜ·¢ÏÖð³ä¿ìµÝµÄµöÓãÍøÕ¾ÊýÁ¿¼±¾çÔö¼Ó¡£Group-IBµÄ¼ÆËã»úÓ¦¼±ÏìӦС×é(CERT-GIB)ÔÚ12ÔµÄÇ°10Ìì·¢ÏÖÁË587¸ö¿´ËƺϷ¨ÓÊÕþÔËÓªÉ̺ͿìµÝ¹«Ë¾µÄÍøÕ¾£¬±È11ÔµÄ×îºó10ÌìÔö¼ÓÁË34%¡£×ÜÌå¶øÑÔ£¬×Ô11Ô³õÒÔÀ´£¬CERT-GIB¼ì²âµ½1539¸ö´ËÀàÍøÕ¾£¬ÆäÖдó¶àÊý¶¼Õë¶ÔµÂ¹ú£¨18%£©¡¢Î÷°àÑÀ£¨13%£©¡¢²¨À¼£¨14%£©ºÍÓ¢¹ú£¨4%£©µÈ¹ú¡£
https://www.group-ib.com/media-center/press-releases/christmas-fake-deliveries-scam/
4¡¢Blink MobilityÊý¾Ý¿âÅäÖôíÎóй¶2Íò¶àÓû§ÐÅÏ¢
¾ÝýÌå12ÔÂ21ÈÕ±¨µÀ£¬×ܲ¿Î»ÓÚÂåÉ¼í¶µÄµç¶¯Æû³µ¹²ÏíÌṩÉÌBlink MobilityµÄÒ»¸öMongoDBÊý¾Ý¿âÅäÖôíÎó¡£Ëæºó£¬ÆäÔªÊý¾Ý±»ËÑË÷ÒýÇæ±àÈëË÷Òý£¬²¢ÓÚ10ÔÂ17ÈÕ±»CybernewsÑо¿ÈËÔ±·¢ÏÖ¡£ÊÓ²ìÏÔʾ£¬¸ÃÊý¾Ý¿â°üÂÞÁè¼Ý22000ÃûÓû§ºÍ181000Ìõ¼Ç¼£¬ÆäÖдó²¿ÃÅÓëÆû³µ×âÁÞÓйأ¬ÀýÈçµç»°ºÅÂë¡¢ÓʼþµØÖ·¡¢¼ÓÃÜÃÜÂë¡¢×¢²áÈÕÆÚ¡¢É豸ÐÅÏ¢ºÍÉ豸ÁîÅÆÒÔ¼°¶©ÔĺÍ×âÁÞ³µÁ¾µÄÏêϸÐÅÏ¢¡£Ä¿Ç°£¬¹ûÈ»µÄÊý¾Ý¿âÒѱ»±£»¤ÆðÀ´¡£
https://securityaffairs.com/156241/security/blink-mobility-data-leak.html
5¡¢CorvusÐû²¼11Ô·ÝÀÕË÷¹¥»÷µÄ̬ÊƵķÖÎö³ÂËß
12ÔÂ25ÈÕ±¨µÀ³Æ£¬Corvus InsuranceÐû²¼³ÂËߣ¬11Ô·ÝÀÕË÷ÍÅ»ïÁгöµÄ±»¹¥»÷Ä¿±êÊýÁ¿µ½´ïÁËÓÐÊ·ÒÔÀ´µÄ×î¸ß¼Ç¼¡£³ÂËßÖ¸³ö£¬11ÔÂÓÐ484¸öеı»¹¥»÷Ä¿±êÐû²¼µ½Ð¹Â©ÍøÕ¾£¬Õâ½Ï10Ô·ÝÔö³¤39.08%£¬½Ï2022Äê11ÔÂͬ±ÈÔö³¤110.43%¡£Æ¾¾ÝCorvusµÄÊý¾Ý£¬11Ô·ݵķåÖµ²¿ÃŹéÒòÓÚLockBit»î¶¯µÄËÕÐÑ£¬Æä¹¥»÷ÁË121¸öÄ¿±ê£¬Æä´ÎÊÇPLAY¡¢AlphVM¡¢BlackBastaºÍ8Base¡£CorvusÔ¤²â£¬Æ¾¾ÝÀúÊ·¼¾½ÚÐÔÊý¾Ý£¬12Ô½«±£³Öͬ±ÈÔö³¤£¬µ«ºÜ¿ÉÄÜÎÞ·¨ÓöÉÏ11Ô·ݵÄÊý×Ö¡£
https://www.infosecurity-magazine.com/news/ransomware-victims-record-november/
6¡¢FortiGuardÐû²¼¹ØÓÚBandookбäÌåµÄ·ÖÎö³ÂËß
12ÔÂ21ÈÕ£¬FortiGuardÐû²¼¹ØÓÚBandookбäÌåµÄ·ÖÎö³ÂËß¡£BandookÊÇÒ»ÖÖÔ¶³Ì·ÃÎÊľÂí£¬×Ô2007ÄêÊ״α»¼ì²âµ½ÒÔÀ´Ò»Ö±ÔÚ²»Í£Éú³¤¡£FortiGuardÔÚ10Ô·¢ÏÖÁËÒ»ÖÖͨ¹ýPDFÎļþÁ÷´«µÄÐÂBandook±äÌå¡£´ËPDFÎļþ°üÂÞÒ»¸öËõ¶ÌµÄURL£¬¿ÉÏÂÔØÊÜÃÜÂë±£»¤µÄ.7zÎļþ¡£Ä¿±êʹÓÃPDFÎļþÖеÄÃÜÂëÌáÈ¡¶ñÒâÈí¼þºó£¬¶ñÒâÈí¼þ»á½«Æäpayload×¢Èëµ½msinfo32.exeÖС£¸Ã³ÂËß¼òÒª½éÉÜÁËBandookµÄÐÐΪ£¬ÌṩÓйظñäÌåµÄÐÞ¸ÄÔªËصÄÏêϸÐÅÏ¢£¬²¢·ÖÏíÁËÆäC2ͨÐÅ»úÖƵÄһЩʾÀý¡£
https://www.fortinet.com/blog/threat-research/bandook-persistent-threat-that-keeps-evolving