Ô½ÄÏÍøÂç·¸×ïÍÅ»ï CoralRaiderÒâÍâй¶Æä²ÆÕþÊý¾Ý
Ðû²¼Ê±¼ä 2024-04-104ÔÂ9ÈÕ£¬Ò»¸öÓëÔ½ÄÏÓйصÄÐÂÍøÂç·¸×ï×éÖ¯ÒÔÑÇÖ޵ĸöÈ˺Í×é֯ΪĿ±ê£¬ÊÔͼÇÔÈ¡É罻ýÌåÕÊ»§ÐÅÏ¢ºÍÓû§Êý¾Ý¡£CoralRaider ÓÚ 2023 Äêµ×Ê״ηºÆð£¬Ë¼¿Æ Talos ÍþвÇ鱨С×éµÄÍþвÑо¿ÈËÔ±ÔÚ CoralRaider µÄ×îзÖÎöÖÐÖ¸³ö£¬¸Ã×éÖ¯Ò²·¸ÁËһЩÐÂÊÖ´íÎó£¬ÀýÈçÎÞÒâÖÐѬȾÁË×Ô¼ºµÄϵͳ£¬´Ó¶ø̻¶ÁËËûÃǵĻ¡£CoralRaider »î¶¯Í¨³£´Ó Windows ¿ì½Ý·½Ê½ (.LNK) Îļþ¿ªÊ¼£¬Í¨³£Ê¹Óà .PDF À©Õ¹Ãû£¬ÊÔͼÆÛÆÊܺ¦Õß´ò¿ªÎļþ¡£CoralRaider ×é֯ʹÓà Telegram ·þÎñÉϵÄ×Ô¶¯»¯»úÆ÷ÈË×÷ΪÃüÁîºÍ¿ØÖÆͨµÀ£¬²¢´ÓÊܺ¦ÕßµÄϵͳÖÐÇÔÈ¡Êý¾Ý¡£È»¶ø£¬ÍøÂç·¸×ï×éÖ¯ËƺõÒѾѬȾÁËËûÃÇ×Ô¼ºµÄһ̨»úÆ÷£¬ÒòΪ˼¿ÆÑо¿ÈËÔ±·¢ÏÖÁËÐû²¼µ½¸ÃƵµÀµÄÐÅÏ¢µÄÆÁÄ»½Øͼ¡£
https://www.darkreading.com/vulnerabilities-threats/vietnamese-cybercrime-group-coralraider-nets-financial-data
2. ¿¨°Í˹»ù2023Äê³ÂËßÊý¾ÝÇÔÈ¡¶ñÒâÈí¼þʼþ¼¤Ôö
4ÔÂ8ÈÕ£¬¿¨°Í˹»ù³ÂËßÏÔʾ£¬2023 Ä꣬Êý¾ÝÇÔÈ¡¶ñÒâÈí¼þʼþ¼¤Ôö£¬Õë¶Ô½ü 1000 Íǫ̀É豸£¬ÍøÂç·¸×ï·Ö×Óƽ¾ùÔÚÿ̨ÊÜѬȾÉ豸ÉÏÌáÈ¡ 50.9 ¸öµÇ¼ƾ¾Ý¡£ÕâЩƾ֤±»ÓÃÓÚ¶ñÒâÄ¿µÄ£¬ÀýÈç³ïıÍøÂç¹¥»÷»òÔÚ°µÍøÂÛ̳ºÍ Telegram ƵµÀÉϳöÊÛËüÃÇ¡£±»µÁƾ֤º¸Ç·¶Î§¹ã·º£¬´ÓÉ罻ýÌåµÇ¼µ½ÍøÉÏÒøÐзþÎñ¡¢¼ÓÃÜÇ®°üºÍÆóÒµÔÚÏßƽ̨µÇ¼¡£¸Ã³ÂËßÇ¿µ÷ .com ÓòÃûÊDZ»µÁÕÊ»§µÄÖص㣬½ôËæÆäºóµÄÊÇÓë°ÍÎ÷ (.br)¡¢Ó¡¶È (.in)¡¢¸çÂ×±ÈÑÇ (.co) ºÍÔ½ÄÏ (.vn) Ïà¹ØµÄÓòÃûÇøÓò¡£À´×Ô¿¨°Í˹»ùÊý×Ö×ã¼£Ç鱨µÄÊý¾ÝÏÔʾ£¬¹ýÈ¥ÈýÄêÖжñÒâÈí¼þÊýÁ¿¼¤Ôö 643%¡£ÕâÍ»ÏÔÁ˶ñÒâÈí¼þ¶ÔÈ«Çò¸öÈËÏû·ÑÕߺÍÆóÒµ×é³ÉµÄÈÕÒæÑÏÖصÄÍþв¡£Æ¾¾Ý¸Ã³ÂËߣ¬¹ýÈ¥ÎåÄêÀ´£¬È«ÇòÓÐ 443000 ¸öÍøÕ¾ÃæÁÙƾ¾Ýй¶ÎÊÌâ¡£
https://securityboulevard.com/2024/04/10-million-devices-were-infected-by-data-stealing-malware-in-2023/
3. ÃÀ¹ú»·±£¾ÖÊÓ²ìºÚ¿Íй¶ÆäÊý¾ÝµÄÄþ¾²Ê¼þ
4ÔÂ9ÈÕ£¬ÃÀ¹ú»·¾³±£»¤ÊðÕýÔÚÊÓ²ìºÚ¿Íй¶Á˸ûú¹¹Òªº¦»ù´¡ÉèÊ©³Ð°üÉÌÊý¾Ý¿âÖеĴóÁ¿ÁªÏµÐÅÏ¢µÄÖ¸¿Ø¡£±»³ÆΪ USDoD µÄÍþвÐÐΪÕßÔÚÒ»¸ö¿É¹ûÈ»·ÃÎʵĺڿÍÂÛ̳ÉÏÐû²¼ÁËËûËù˵µÄ 500 MB µÄÁªÏµÐÅÏ¢ºÍ EPA Êý¾Ý¿âÖеÄÆäËûÊý¾Ý¡£ÐÅÏ¢Äþ¾²Ã½Ì弯ÍÅ֤ʵ£¬½ØÖÁÖÜÒ»ÏÂÎ磬¸ÃÌû×ÓÈÔÔÚÂÛ̳ÉÏÐû²¼£¬ÆäÖаüÂÞÉù³Æ°üÂÞ´ÓÈ«Ãû¡¢µç×ÓÓʼþµØÖ·µ½ÊðÀí³Ð°üÉÌʵ¼ÊµØÖ·ÐÅÏ¢µÈËùÓÐÐÅÏ¢µÄѹËõÎļþ¡£Ìû×ÓÖÐдµÀ£º¡°¸÷È˺ã¬Breachforums£¬ÕâÊÇÄãÃÇ×îϲ»¶µÄ TA£¬½ñÌìÎÒºÜ×ÔºÀµØ˵£¬ÎÒÕýÔÚÐû²¼ epa.gov ÁªÏµÈËÁбíÊý¾Ý¿â¡£ÕâÊÇËûÃÇ [Òªº¦»ù´¡ÉèÊ©] µÄÈ«²¿ÁªÏµÈË£¬²»½öÕë¶Ô¸Ã»ú¹¹·¢ÑÔÈËÌåÏÖ£¬¸Ã»ú¹¹¶Ô¾Ý³Æ鶵ÄÊý¾Ý½øÐÐÁË¡°¿ª¶Ë·ÖÎö¡±£¬·¢ÏÖÕâЩ¼Ç¼Ëƺõ°üÂÞÒÑÏò¹«ÖÚ¹ûÈ»µÄÉÌÒµÁªÏµÐÅÏ¢£¬¡°ÒÔÌṩ»·¾³Ó°ÏìµÄÈ«ÃæÇé¿ö¡± ¡±¡£
https://news.hitb.org/content/us-epa-investigates-alleged-data-breach-government-hacker
4. unit42¶ñÒâÈí¼þÌᳫµÄ©¶´É¨Ãè³ÊÉÏÉýÇ÷ÊÆ
4ÔÂ8ÈÕ£¬ÎÒÃǵÄÒ£²âÊý¾Ý±íÃ÷£¬Ô½À´Ô½¶àµÄÍþв¼ÓÈëÕßÕýÔÚתÏò¶ñÒâÈí¼þÌᳫµÄɨÃè¹¥»÷¡£±¾ÎĻعËÁ˹¥»÷ÕßÈçºÎʹÓÃÊÜѬȾµÄÖ÷»ú¶ÔÆäÄ¿±ê½øÐлùÓÚ¶ñÒâÈí¼þµÄɨÃ裬¶ø²»ÊÇʹÓøü´«Í³µÄÖ±½ÓɨÃèÒªÁì¡£ÍþвÐÐΪÕߺã¾ÃÒÔÀ´Ò»Ö±ÔÚʹÓÃɨÃèÒªÁìÀ´²éÃ÷ÍøÂç»òϵͳÖеÄ©¶´¡£Ò»Ð©É¨Ãè¹¥»÷Ô´×ÔÁ¼ÐÔÍøÂ磬¿ÉÄÜÊÇÓÉÊÜѬȾ¼ÆËã»úÉϵĶñÒâÈí¼þÇý¶¯µÄ¡£µ±¹¥»÷ÕßÌᳫÍøÂçÇëÇóÒÔÊÔͼÀûÓÃÄ¿±êÖ÷»úµÄDZÔÚ©¶´Ê±£¬¾Í»á·¢ÉúɨÃ衣Ŀ±êÖ÷»úͨ³£ÊÇÁ¼ÐԵģ¬¶øÇÒ¿ÉÄÜÈÝÒ×Êܵ½¹¥»÷ÕßÕë¶ÔµÄ CVE µÄ¹¥»÷¡£Í¨¹ý¸ú×ÙÀ´×Ô¶à¸öÍøÂçµÄÁ÷Á¿ÈÕÖ¾£¬ÎÒÃÇ·¢ÏÖ¶Ô´óÁ¿Ä¿µÄµØµÄÇëÇó¾ßÓп´ËÆÁ¼ÐԵķ¾¶¡£Ðí¶àɨÃè°¸Àý£¬ÆäÖй¥»÷ÕßǶÈëÁËÒÔǰδ¼û¹ýµÄ URL£¬ÓÃÓÚÓÐЧ¸ºÔØ´«Êä»ò C2 ÒÔ¼°Â©¶´ÀûÓÃÇëÇó¡£Õâ½µµÍÁ˺óÐøÓÐЧ¸ºÔØ»ò C2 URL ±»Äþ¾²¹©Ó¦ÉÌ×èÖ¹µÄ¿ÉÄÜÐÔ¡£ÓÉÓÚÕâЩÓÐЧ¸ºÔØ´«ËÍ»ò C2 URL ¶ÔÓÚÄþ¾²¹©Ó¦ÉÌÀ´ËµÊÇеģ¬Òò´Ë¼ì²âºÍ×èÖ¹´ËÀà³õʼɨÃèÇëÇóÖÁ¹ØÖØÒª£¬ÒòΪ¹©Ó¦É̲»Ì«¿ÉÄÜ×èÖ¹ºóÐøÇëÇó¡£
https://unit42.paloaltonetworks.com/malware-initiated-scanning-attacks/
5. ÀÕË÷ÍÅ»ïRansomHub ´Ó Change Healthcare ÇÔÈ¡4TBÊý¾Ý
4ÔÂ9ÈÕ£¬¾Ý±¨µÀ£¬Change Healthcare ÕýÃæÁÙÁíÒ»´Î¹¥»÷£¬Õâ´ÎÊÇÀÕË÷Èí¼þÍÅ»ï RansomHub ÌᳫµÄ¹¥»÷£¬¶ø¾ÍÔÚ¼¸ÖÜÇ°£¬¸Ã×éÖ¯³ÉΪALPHV/BlackCat ÍøÂç¹¥»÷µÄÊܺ¦Õß¡£RansomHub ÒªÇóΪÆä´Ó¸Ã¹«Ë¾ÇÔÈ¡µÄ 4TB Êý¾ÝÇÃÕ©ÀÕË÷£»·ñÔò£¬Ëü»áÍþвÔÚ 12 ÌìÄÚ½«Êý¾Ý³öÊÛ¸ø³ö¼Û×î¸ßÕß¡£±»µÁÐÅÏ¢°üÂÞÃÀ¹ú¾üÊÂÈËÔ±ºÍ»¼ÕßµÄÃô¸ÐÊý¾Ý£¬ÒÔ¼°Ò½ÁƼǼºÍ²ÆÕþÐÅÏ¢µÈ¡£ÕâʹµÃÁªºÏÒ½ÁƱ£½¡¹«Ë¾µÄ×Ó¹«Ë¾ Change Healthcare ÏÝÈëÁËÒ»¸öÀ§¾³£¬ÒòΪËü¸Õ¸Õ´ÓÉϴεĹ¥»÷Öлָ´¹ýÀ´£¬±ØÐë¾ö¶¨Ö§¸¶Êê½ðÊÇ·ñÊÇ×îºÃµÄÑ¡Ôñ¡£¾¡¹ÜÈËÃÇ¶Ô ALPHV ÊÇ·ñ¸üÃûΪ RansomHub£¬»òÕßÊÇ·ñ´æÔÚÈκÎÁªÏµ´æÔÚÖØ´óÍƲ⣬µ«ÎÖ¿ËÌåÏÖ£¬Ä¿Ç°»¹Ã»Óеõ½Ö¤Êµ£¬ÒòΪÏÖÔÚϽáÂÛ»¹ÎªÊ±¹ýÔç¡£
https://www.darkreading.com/cyberattacks-data-breaches/round-2-change-healthcare-targeted-second-ransomware-attack
6. AGENT TESLA ¶ñÒâÈí¼þÇÔÈ¡ Chrome ºÍ Firefox µÄµÇ¼ƾ¾Ý
4ÔÂ8ÈÕ£¬Ñо¿ÈËÔ±ÊÓ²ìÁË×î½üÕë¶ÔÃÀ¹úºÍ°Ä´óÀûÑÇ×éÖ¯µÄ Agent Tesla ¶ñÒâÈí¼þ»î¶¯£¬¸Ã»î¶¯Ê¹ÓôøÓÐÐé¼Ù²É¹º¶©µ¥µÄÍøÂçµöÓãµç×ÓÓʼþÀ´ÓÕÆÊܺ¦Õßµã»÷¶ñÒâÁ´½Ó¡£µ¥»÷ºó£¬ÊÜ Cassandra Protector ±£»¤µÄ»ìÏýµÄ Agent Tesla Ñù±¾¾Í»á±»ÏÂÔز¢Ö´ÐУ¬´Ó¶øÇÔÈ¡»÷¼üºÍµÇ¼ƾ¾Ý¡£ÊӲ췢ÏÖÁËÁ½ÃûÍøÂç·¸×ï·Ö×Ó Bignosa£¨Ö÷ÒªÍþв£©ºÍ Gods£¬ËûÃÇʹÓôóÐ͵ç×ÓÓʼþÊý¾Ý¿âºÍ¶à¸ö·þÎñÆ÷½øÐÐ RDP Á¬½ÓºÍ¶ñÒâÈí¼þ»î¶¯¡£¸Ã¶ñÒâÈí¼þ»î¶¯ÔÚ·Ö·¢¶ñÒâÀ¬»øÓʼþ֮ǰÉæ¼°¶à¸ö²½ÖèµÄ×¼±¸½×¶Î¡£Bignosa ʹÓà Agent Tesla ½øÐÐÁËÍøÂçµöÓã¹¥»÷£¬¶ø Gods Ö¸µ¼ Bignosa Ò²Ôø½øÐйýÍøÂçµöÓã¹¥»÷¡£ËûÃÇͨ¹ý Jabber ºÍTeamViewer½øÐÐͨÐÅ£¬¶ø Bignosa ʹÓà RDP Á¬½Óµ½ VDS ·þÎñÆ÷²¢·Ö·¢ Agent Tesla¡£
https://gbhackers.com/agent-tesla-malware-steals-login-credentials-from-chrome-firefox/