ê©ÄÉÒ½ÔºÒòÔâµ½ÍøÂç¹¥»÷¶ø¹Ø±ÕÆäÒ½ÁÆϵͳ
Ðû²¼Ê±¼ä 2024-04-234ÔÂ22ÈÕ£¬¸ÃÒ½ÁÆ»ú¹¹Ò²±»³ÆΪ²¼Â³ÈüÒ½Ôº£¬¾ö¶¨ÍêÈ«ÇжϼÆËã»ú·ÃÎÊÒÔÍ£Ö¹¹¥»÷£¬ÕâÆÈʹԱ¹¤×ªÏò±ÊºÍÖ½¼ÌÐøΪ»¼ÕßÌṩ·þÎñ¡£CHC-SV ÌåÏÖ£¬ÕýÔÚ¾¡Ò»ÇÐŬÁ¦È·±£Äܹ»ÔÚÆä»î¶¯ÁìÓòÌṩȫ·½Î»µÄ»¤Àí£¬²¢Ôö²¹Ëµ£¬ËüÒ»Ö±ÔÚÓëµØÓòÒ½ÁÆ»ú¹¹ºÏ×÷£¬Æ¾¾Ý»¼ÕßµÄÐèÇóµ÷Õû»¼ÕßµÄÆ«Ïò¡£ËäÈ» CHC-SV µÄ½ô¼±»î¶¯ÈÔÔÚ¼ÌÐø£¬µ«ÉÏÖÜÈ¡ÏûÁ˷ǽô¼±ÊÖÊõ·¨Ê½£¬µ«½øÐÐÁ˲»ÒÀÀµ¼ÆËã»úϵͳµÄÊÖÊõÒÔ¼°Õë¶ÔÒÑÖªÂýÐÔ²¡»¼ÕßµÄÊÖÊõ¡£¸ÃÒ½ÔºÌåÏÖÒÑ֪ͨÓйØÕþ¸®£¬Õþ¸®ºÍÍøÂçÄþ¾²×¨¼ÒÕýÔÚ·ÖÎö¸Ãʼþ¡£CHC-SV ÌåÏÖ£¬Æù½ñΪֹ£¬ÉÐδÌá³öÊê½ðÒªÇó£¬Ò²Ã»Óз¢ÏÖÊý¾Ý±»µÁµÄÖ¤¾Ý¡£¾ÝÒ½Ôº³Æ£¬¿µ¸´²Ù×÷½«Öصã¹Ø×¢Ó뻼Õß»¤ÀíÖ±½ÓÏà¹ØµÄϵͳ¡£²»Í⣬CHC-SV Ô¤¼ÆÐèÒªºÜ³¤Ê±¼ä²ÅÆø»Ö¸´Õý³£ÔËÓª¡£CHC-SV ÊÇ·¨¹úê©ÄɵÄÒ»¼ÒÓµÓÐ 840 ¸ö´²Î»µÄÒ½Ôº£¬ÓµÓÐ 2,000 ¶àÃûÔ±¹¤£¬Ìṩ¼±Õï¡¢Íâ¿Æ¡¢²ú¿Æ¡¢¶ù¿Æ¡¢¾«Éñ²¡Ñ§ºÍÆäËûÒ½ÁƱ£½¡·þÎñ¡£
https://www.securityweek.com/cannes-hospital-cancels-medical-procedures-following-cyberattack/
2. Windows Defender ¿ÉÄܻᱻÆÛÆɾ³ýÊý¾Ý¿â
4ÔÂ22ÈÕ£¬ÐÅÏ¢Äþ¾²»ú¹¹ SafeBreach µÄÑо¿ÈËÔ±ÉÏÖÜÎåÌÖÂÛÁË΢ÈíºÍ¿¨°Í˹»ùÄþ¾²²úÎïÖпÉÄÜÔÊÐíÔ¶³Ìɾ³ýÎļþµÄȱÏÝ¡£¶øÇÒ£¬ËûÃÇÉù³Æ£¬¼´Ê¹Á½¼Ò¹©Ó¦É̶¼Éù³ÆÒѾÐÞ¸´Á˸ÃÎÊÌ⣬¸Ã©¶´ÈÔÈ»¿ÉÒÔ±»ÀûÓá£SafeBreach Äþ¾²Ñо¿¸±×ܲà Tomer Bar ºÍÄþ¾²Ñо¿Ô± Shmuel Cohen ÔÚмÓƾÙÐÐµÄ Black Hat Asia »áÒéÉÏ·¢±í½²»°Ê±½âÊÍ˵£¬Microsoft Defender ºÍ¿¨°Í˹»ùµÄ¶Ëµã¼ì²âºÍÏìÓ¦ (EDR) ¿ÉÒÔ¼ì²â¶ñÒâÎļþµÄÎó±¨Ö¸±ê£¬È»ºóɾ³ýËüÃÇ¡£¸Ã¹¥»÷ÒÀÀµÓÚ΢ÈíºÍ¿¨°Í˹»ùʹÓÃ×Ö½ÚÇ©Ãû£¨ÎļþÍ·ÖÐÆæÌصÄ×Ö½ÚÐòÁУ©À´¼ì²â¶ñÒâÈí¼þµÄÊÂʵ¡£Bar ºÍ Cohen Ê×ÏÈÔÚ VirusTotal ƽ̨ÉÏÕÒµ½ÁËÓë¶ñÒâÈí¼þÏà¹ØµÄ×Ö½ÚÇ©Ãû£¬È»ºó½«Æä²åÈëÊý¾Ý¿âÖУ¬ÒªÁìÊÇ´´½¨Ò»¸öÃû³Æ°üÂÞ¸ÃÇ©ÃûµÄÐÂÓû§µÈ¡£EDR ·¨Ê½ËæºóÈÏΪ´æ´¢Ç©ÃûµÄÊý¾Ý¿âÒѱ»¶ñÒâÈí¼þѬȾ¡£Èç¹û EDR ÉèÖÃΪɾ³ýÊÜѬȾµÄÎļþ£¬Ëü½«Ö´Ðд˲Ù×÷¡£Á½ÈËÈÏΪ£¬Êý¾Ý¿â»òÐéÄâ»úÒò´Ë¿ÉÒÔ±»Ô¶³Ìɾ³ý¡£
https://www.theregister.com/2024/04/22/edr_attack_remote_data_deletion/
3. AKIRA´Ó250¶àÃûÊܺ¦ÕßÄÇÀïÊÕµ½4200ÍòÊê½ð
4ÔÂ21ÈÕ£¬CISA¡¢FBI¡¢Å·ÖÞÐ̾¯×éÖ¯ºÍºÉÀ¼¹ú¼ÒÍøÂçÄþ¾²ÖÐÐÄ (NCSC-NL) Ðû²¼µÄÁªºÏͨ¸æÏÔʾ£¬×Ô 2023 Äê³õÒÔÀ´£¬Akira ÀÕË÷Èí¼þÔËÓªÉÌ´ÓÈ«Çò 250 ¶àÃûÊܺ¦ÕßÄÇÀïÊÕµ½ÁË 4200 ÍòÃÀÔªµÄÊê½ð¡£Akira ÀÕË÷Èí¼þ×Ô 2023 Äê 3 ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬¸Ã¶ñÒâÈí¼þ±³ºóµÄÍþвÐÐΪÕßÉù³ÆÒѾÈëÇÖÁ˶à¸öÐÐÒµµÄ¶à¸ö×éÖ¯£¬°üÂÞ½ÌÓý¡¢½ðÈںͷ¿µØ²ú¡£ÓëÆäËûÀÕË÷Èí¼þÍÅ»ïÒ»Ñù£¬¸Ã×éÖ¯¿ª·¢ÁËÒ»¿îÕë¶Ô VMware ESXi ·þÎñÆ÷µÄ Linux ¼ÓÃÜÆ÷¡£Akira ÀÕË÷Èí¼þÔËÓªÉÌͨ¹ýÔÚ¼ÓÃÜ֮ǰÇÔÈ¡Êܺ¦ÕßµÄÊý¾ÝÀ´ÊµÊ©Ë«ÖØÀÕË÷Ä£ÐÍ¡£¸ÃÀÕË÷Èí¼þµÄÔçÆÚ°æ±¾ÊÇÓà C++ ±àдµÄ£¬¶øÇҸöñÒâÈí¼þÔÚ¼ÓÃÜÎļþÖÐÌí¼ÓÁË .akira À©Õ¹Ãû¡£È»¶ø£¬´Ó 2023 Äê 8 ÔÂÆð£¬Ä³Ð© Akira ¹¥»÷¿ªÊ¼ÀûÓà Megazord£¬Ëü½ÓÄÉ»ùÓÚ Rust µÄ´úÂ벢ʹÓà .powerranges À©Õ¹Ãû¼ÓÃÜÎļþ¡£Akira ÍþвÐÐΪÕß¼á³Ö½»ÌæʹÓà Megazord ºÍ Akira£¬°üÂÞ¶ÀÁ¢ÊÓ²ìÈ·¶¨µÄ Akira_v2¡£
https://securityaffairs.com/162098/cyber-crime/akira-ransomware-report-fbi.html
4. 2024ÄêµÚÒ»¼¾¶ÈÀÕË÷Èí¼þÖ§¸¶¶î½µÖÁ28%µÄÀúʷеÍ
4ÔÂ21ÈÕ£¬ÀÕË÷Èí¼þ¹¥»÷Õß½ñÄêµÄ¿ª¾Ö²¢²»Ë³Àû£¬ÍøÂçÄþ¾²¹«Ë¾ Coveware µÄͳ¼ÆÊý¾ÝÏÔʾ£¬Ô½À´Ô½¶àµÄ¹«Ë¾¾Ü¾øÖ§¸¶ÀÕË÷ÒªÇ󣬵¼Ö 2024 ÄêµÚÒ»¼¾¶ÈÖ§¸¶Êê½ðµÄ¹«Ë¾µ½´ïÀúÊ·ÐÂµÍ 28%¡£2023 ÄêµÚËļ¾¶ÈÕâÒ»Êý×Ö Îª 29%£¬Coveware µÄͳ¼ÆÊý¾ÝÏÔʾ£¬×Ô 2019 Äê³õÒÔÀ´£¬Ö§¸¶½ð¶îµÄ¼õÉÙÒ»Ö±±£³ÖÎȶ¨¡£ÕâÖÖϽµÊÇÓÉÓÚ×é֯ʵʩÁ˸üÏȽøµÄ±£»¤´ëÊ©£¬²»Í£¼Ó´óµÄÖ´·¨Ñ¹Á¦À´Âú×ãÆ×ӵIJÆÕþÒªÇó£¬ÒÔ¼°ÍøÂç·¸×ï·Ö×ÓÒ»ÔÙÎ¥·´ÔÚÖ§¸¶Êê½ðµÄÇé¿öϲ»»áÐû²¼»òתÊÛ±»µÁÊý¾ÝµÄÔÊÐí¡£´ÓÒÑÈ·¶¨µÄ©¶´À´¿´£¬Ô¶³Ì·ÃÎʺÍ©¶´ÀûÓ÷¢»ÓÁË×î´óµÄ×÷Óã¬ÆäÖÐ CVE-2023-20269¡¢CVE-2023-4966 ºÍ CVE-2024-1708-9 ȱÏÝÔÚµÚÒ»¼¾¶È±»ÀÕË÷Èí¼þÔËÓªÉÌÀûÓõÃ×îΪ¹ã·º¡£
https://www.bleepingcomputer.com/news/security/ransomware-payments-drop-to-record-low-of-28-percent-in-q1-2024/
5. Veriti Research·¢ÏÖAndroxgh0stµÄ¹¥»÷»î¶¯¼¤Ôö
4ÔÂ21ÈÕ£¬Veriti Research ·¢ÏÖ Androxgh0st ¶ñÒâÈí¼þ¼Ò×åÌᳫµÄ¹¥»÷»î¶¯¼¤Ôö£¬·¢ÏÖ 600 ¶ą̀·þÎñÆ÷Êܵ½Íþв£¬Ö÷ÒªÂþÑÜÔÚÃÀ¹úºÍÓ¡¶È¡£Æ¾¾Ý Veriti µÄ²©¿ÍÎÄÕ£¬Androxgh0st ±³ºóµÄ¶ÔÊÖµÄ C2 ·þÎñÆ÷±»Ì»Â¶£¬Õâ¿ÉÒÔͨ¹ý̻¶ÊÜÓ°ÏìµÄÄ¿±êÀ´½øÐл¹»÷¡£Ñо¿ÈËÔ±Ëæºó¼ÌÐøÏòÊܺ¦Õß·¢³ö¾¯±¨¡£½øÒ»²½Ñо¿ÏÔʾ£¬Androxgh0st ÔËÓªÕßÕýÔÚÀûÓöà¸ö CVE£¨°üÂÞCVE-2021-3129ºÍCVE-2024-1709£© ÔÚÒ×Êܹ¥»÷µÄ·þÎñÆ÷Éϲ¿Êð Web shell£¬´Ó¶øÊÚÓèÔ¶³Ì¿ØÖƹ¦Ð§¡£´ËÍ⣬ÓÐÖ¤¾Ý±íÃ÷»îÔ¾µÄ Web shell ÓëCVE-2019-2725Ïà¹Ø¡£×Ô 2022 Äê 12 ÔÂÊ״α»·¢ÏÖÒÔÀ´£¬Hackread.com Ò»Ö±ÔÚ¸ú×Ù Androxgh0st µÄ²Ù×÷¡£¸Ã¶ñÒâÈí¼þÔËÓªÕßÒÔ²¿ÊðAdhublika ÀÕË÷Èí¼þ¶øÎÅÃû£¬Ö®Ç°ÔøÊӲ쵽ÓëÓë Adhublika ×éÖ¯Ïà¹ØµÄ IP µØÖ·½øÐÐͨÐÅ¡£
https://www.hackread.com/androxgh0st-malware-servers-botnets-attacks/
6. Hellokity ÀÕË÷Èí¼þµÄ¹¥»÷ÕßÒÔHelloGookie»Ø¹é
4ÔÂ22ÈÕ£¬ÍøÂç·¸×ï×éÖ¯£¨ÒÔÇ°³ÆΪ Hellokity£©ÒÔбðÃû¡°HelloGookie¡±ÖØзºÆð¡£ÍøÂçÄþ¾²¼à¹Ü»ú¹¹ MonThreat ͨ¹ýÆä Twitter ÕÊ»§³ÂËßÁËÕâÒ»½øÕ¹¡£Hellokity ÒÔÆ䱸ÊÜÖõÄ¿µÄÍøÂç¹¥»÷¶øÎÅÃû£¬Ò»Ö±ÊÇÊý×ÖÀÕË÷µÄÖØÒª¼ÓÈëÕß¡£¸Ã×éÖ¯Òò²¿ÊðÀÕË÷Èí¼þÉø͸ÆóÒµÍøÂç¡¢¼ÓÃÜÊý¾ÝÒÔ¼°Ë÷Òª¾Þ¶îÊê½ð»»È¡½âÃÜÃÜÔ¿¶øÎÛÃûÕÑÖø¡£ËûÃǵÄÔËÓª¶Ô¸÷¸öÐÐÒµÔì³ÉÁË×ÌÈÅ£¬Ó°ÏìÁËÒµÎñÔËÓªºÍÏû·ÑÕßÊý¾ÝÒþ˽¡£Æ¾¾Ý MonThreat ·ÖÏíµÄÏêϸÐÅÏ¢£¬Hellokity ²»½ö¸ü¸ÄÁËÃû³Æ£¬¶øÇÒËƺõ»¹Éý¼¶ÁËÆäÀÕË÷Èí¼þ¹¤¾ßºÍ¼Æı¡£ÕâÖÖÆ·ÅÆÖØËÜ¿ÉÄÜÊÇΪÁËÌÓ±ÜÒÑÊÊÓ¦ÆäÏÈÇ°ÒªÁìµÄÖ´·¨ºÍÍøÂçÄþ¾²·ÀÓù¡£Hellokity ÒÔÐÂÃû³Æ¡°HelloGookie¡±»Ø¹é£¬¸øÍøÂçÄþ¾²×¨ÒµÈËÊ¿´øÀ´ÁËеÄÌôÕ½¡£
https://gbhackers.com/hellokity-ransomware-new-name/