CoralRaider¶ñÒâÈí¼þ»î¶¯ÀûÓÃCDN»º´æÁ÷´«ÐÅÏ¢ÇÔÈ¡·¨Ê½

Ðû²¼Ê±¼ä 2024-04-25
1. CoralRaider¶ñÒâÈí¼þ»î¶¯ÀûÓÃCDN»º´æÁ÷´«ÐÅÏ¢ÇÔÈ¡·¨Ê½


4ÔÂ24ÈÕ£¬Ñо¿ÈËÔ±·¢ÏÖÒ»ÖÖеÄÁ¬Ðø¶ñÒâÈí¼þ»î¶¯ÕýÔÚ·Ö·¢ÈýÖÖ²îÒìµÄÇÔÈ¡·¨Ê½£¬ÀýÈçÍйÜÔÚÄÚÈݽ»¸¶ÍøÂç (CDN) »º´æÓòÉϵÄCryptBot¡¢LummaC2ºÍRhadamanthys ¡£Ë¼¿Æ Talos ½«´Ë´Î»î¶¯¹éÒòÓÚ±»×·×ÙΪCoralRaiderµÄÍþвÐÐΪÕߣ¬¸Ã×éÖ¯ÒÉËÆÔ´×ÔÔ½ÄÏ£¬ÓÚ½üÆÚÆعâ¡£¸Ã»î¶¯µÄÄ¿±êº­¸Ç¸÷¸öµØÓòµÄ¸÷¸öÉÌÒµ´¹Ö±ÁìÓò£¬°üÂÞÃÀ¹ú¡¢ÄáÈÕÀûÑÇ¡¢°Í»ù˹̹¡¢¶ò¹Ï¶à¶û¡¢µÂ¹ú¡¢°£¼°¡¢Ó¢¹ú¡¢²¨À¼¡¢·ÆÂɱö¡¢Å²Íþ¡¢ÈÕ±¾¡¢ÐðÀûÑǺÍÍÁ¶úÆä¡£¹¥»÷Á´Éæ¼°Óû§Í¨¹ýÍøÂçä¯ÀÀÆ÷ÏÂÔØαװ³ÉÓ°Ï·ÎļþµÄÎļþ£¬´Ó¶øÔö¼ÓÁË´ó¹æÄ£¹¥»÷µÄ¿ÉÄÜÐÔ¡£¸Ã»î¶¯ÖµµÃ×¢ÒâµÄÊÇ£¬ËüÀûÓÃÁË CryptBot µÄ¸üа汾£¬ÆäÖаüÂÞеķ´·ÖÎö¼¼Êõ£¬¶øÇÒ»¹²¶×½ÃÜÂë¹ÜÀíÆ÷Ó¦Ó÷¨Ê½Êý¾Ý¿âºÍÉí·ÝÑéÖ¤Æ÷Ó¦Ó÷¨Ê½ÐÅÏ¢¡£


https://thehackernews.com/2024/04/coralraider-malware-campaign-exploits.html


2. Change Healthcare×îÖÕÖ§¸¶Êê½ð½«ÃæÁÙÊý¾Ýй¶µÄ·çÏÕ


4ÔÂ24ÈÕ£¬ÔÚÀÕË÷Èí¼þ±ÀÀ£¿ªÊ¼Á½¸ö¶àÔºó£¬ÀÕË÷Èí¼þµÄÓ°Ïì¿°³ÆÍøÂçÄþ¾²Ê·ÉÏ×îÑÏÖصÄÒ»´Î£¬Ò½Áƹ«Ë¾ Change Healthcare ÖÕÓÚ֤ʵÁËÍøÂç·¸×ï·Ö×Ó¡¢Äþ¾²Ñо¿ÈËÔ±ºÍ±ÈÌرÒÇø¿éÁ´ÒѾ­ËµµÃºÜÇå³þµÄÊÂÇ飺Ëüȷʵ×öµ½ÁËÏò¶þÔ·ÝÏ®»÷¸Ã¹«Ë¾µÄºÚ¿ÍÖ§¸¶Êê½ð¡£È»¶ø£¬ËüÈÔÈ»ÃæÁÙ×ŶªÊ§´óÁ¿¿Í»§Ãô¸ÐÒ½ÁÆÊý¾ÝµÄ·çÏÕ¡£Change Healthcare ËƺõÒÑÓÚ 3 Ô 1 ÈÕÖ§¸¶ÁËÊê½ð£¬²¢Ö¸³öÒ»±Ê 350 ±ÈÌرң¨Ô¼ºÏ 2200 ÍòÃÀÔª£©µÄ½»Ò×±»·¢Ë͵½Óë AlphV ºÚ¿ÍÏà¹ØµÄ¼ÓÃÜÇ®°üÖС£Õâ±Ê½»Ò×Ê×ÏÈÔÚÃûΪ RAMP µÄ¶íÂÞ˹ÍøÂç·¸×ïÂÛ̳ÉϵÄÒ»ÌõÏûÏ¢Öеõ½Ç¿µ÷£¬ÆäÖÐһλ¾Ý³Æ±» AlphV Å×ÆúµÄºÏ×÷»ï°éËß¿à˵£¬ËûÃÇûÓÐÊÕµ½ Change Healthcare ¸¶¿îÖеķֳÉ¡£


https://news.hitb.org/content/change-healthcare-finally-admits-it-paid-ransomware-hackers-and-still-faces-patient-data


3. Î÷°àÑÀÖØÐÂÆô¶¯¶Ô Pegasus ¼äµýÈí¼þ°¸¼þµÄÊÓ²ì


4ÔÂ23ÈÕ£¬Î÷°àÑÀ¹ú¼Ò·¨Ôº·¨¹ÙÌåÏÖ£¬ÓÐÀíÓÉÏàÐÅ·¨¹úÌṩµÄÐÂÐÅÏ¢¿ÉÒÔ¡°ÈÃÊÓ²ìÈ¡µÃ½øÕ¹¡±¡£ÕâÁ½ÏîÊÓ²ì¾ùÉæ¼°ÉæÏÓʹÓÃÒÔÉ«ÁÐ NSO ¼¯ÍÅ¿ª·¢µÄ Pegasus ¼äµýÈí¼þ¡£¼äµýÈí¼þ»áÇÄÇĵØÉø͸µÃÊÖ»ú»òÆäËûÉ豸ÖÐÒÔÊÕ¼¯Êý¾Ý²¢¿ÉÄܼàÊÓÆäËùÓÐÕß¡£NSO Éù³Æ£¬Ëü½öÌṩӦÕþ¸®ÓÃÓÚ¹¥»÷¿Ö²ÀÖ÷ÒåºÍÆäËûÄþ¾²Íþв¡£Æ¾¾ÝÄþ¾²Ñо¿ÈËÔ±ºÍ 2021 ÄêÈ«ÇòýÌåÊӲ죬Pegasus Òѱ»ÓÃÀ´¹¥»÷ 50 ¸ö¹ú¼ÒµÄ 1,000 ¶àÈË£¬ÆäÖаüÂÞ»î¸ÐÈËÊ¿ºÍ¼ÇÕß¡£Î÷°àÑÀÓÚ 2022 Äê 5 ÔÂÐû²¼£¬Ê×ÏàÅåµÂÂÞ¡¤É£ÇÐ˹¼°ÆäÈýÃû²¿³¤£¬°üÂÞ¹ú·À²¿³¤ºÍÄÚÕþ²¿³¤£¬ÒѳÉΪPegasus ¼äµýÈí¼þµÄÄ¿±ê¡£ÓÉ´Ë·¢ÉúµÄ˾·¨ÊÓ²ìÒòδÄÜÈ¡µÃ½á¹û¶øÔÝʱÆú¾è¡£


https://www.securityweek.com/spain-reopens-a-probe-into-a-pegasus-spyware-case-after-a-french-request-to-work-together/


4. ºÚ¿Í½Ù³Ö·À²¡¶¾¸üÐÂÒÔ·Ö·¢ºóÃźÍÍÚ¿óGuptiMiner


4ÔÂ23ÈÕ£¬³¯ÏʺڿÍÒ»Ö±ÔÚÀûÓà eScan ·À²¡¶¾Èí¼þµÄ¸üлúÖÆÔÚ´óÐÍÆóÒµÍøÂçÉÏÖ²ÈëºóÃÅ£¬²¢Í¨¹ý GuptiMiner ¶ñÒâÈí¼þÁ÷´«¼ÓÃÜ»õ±Ò¿ó¹¤¡£Ñо¿ÈËÔ±½« GuptiMiner ÃèÊöΪ¸ß¶ÈÅÓ´óµÄÍþв£¬Ëü¿ÉÒÔÏò¹¥»÷ÕßµÄ DNS ·þÎñÆ÷Ö´ÐÐ DNS ÇëÇ󣬴ÓͼÏñÖÐÌáÈ¡ÓÐЧ¸ºÔØ£¬¶ÔÆäÓÐЧ¸ºÔؽøÐÐÇ©Ãû£¬²¢Ö´ÐÐ DLL ²àÃæ¼ÓÔØ¡£GuptiMiner ±³ºóµÄÍþвÐÐΪÕß¾ßÓÐÖмä¶ÔÊÖ (AitM) µÄְ룬¿ÉÒÔ½Ù³ÖÕý³£µÄ²¡¶¾½ç˵¸üаü£¬²¢½«ÆäÌ滻ΪÃûΪ¡°updll62.dlz¡±µÄ¶ñÒâ°ü¡£¸Ã¶ñÒâÎļþ°üÂÞÐëÒªµÄ·À²¡¶¾¸üÐÂÒÔ¼°ÃûΪ¡°version.dll¡±µÄ DLL ÎļþÐÎʽµÄ GuptiMiner ¶ñÒâÈí¼þ¡£eScan ¸üз¨Ê½Õý³£´¦Öøðü£¬½âѹ²¢Ö´ÐÐËü¡£Ôڴ˽׶Σ¬DLL ÓÉ eScan µÄºÏ·¨¶þ½øÖÆÎļþÅÔ¼ÓÔØ£¬´Ó¶ø¸³Óè¶ñÒâÈí¼þϵͳ¼¶È¨ÏÞ¡£


https://www.bleepingcomputer.com/news/security/hackers-hijack-antivirus-updates-to-drop-guptiminer-malware/


5. Ó볯ÏÊÓйØÁªµÄ APT ×éÖ¯Ãé×¼º«¹ú¹ú·À³Ð°üÉÌ


4ÔÂ23ÈÕ£¬º«¹ú¹ú¼Ò¾¯²ìÌü¾¯¸æ³Æ£¬Ó볯ÏÊÓйصÄÍþвÐÐΪÕßÕýÒÔ¹ú·À¹¤ÒµÊµÌåΪĿ±ê£¬ÇÔÈ¡¹ú·À¼¼ÊõÐÅÏ¢¡£¾Ýº«¹ú¹ú¼Ò¾¯²ìÌü±¨µÀ£¬Ó볯ÏÊÓйØÁªµÄ APT ×éÖ¯Lazarus¡¢AndarielºÍKimsuky¹¥»÷Á˺«¹ú¶à¼Ò¹ú·ÀÏà¹ØµÄ¹«Ë¾¡£¾¯²ìÌüºÍ¹ú·À²É¹º¼Æ»®¹ÜÀí¾Ö£¨DAPA£©¶ÔÄ¿±ê×éÖ¯µÄ»·¾³½øÐÐÁËһϵÁÐÌرð¼ì²é¡£ÁªºÏ¼ì²éÓÚ1ÔÂ15ÈÕÖÁ2ÔÂ16ÈÕ½øÐУ¬ÊÜÓ°Ïì×é֯ʵʩÁË·À»¤´ëÊ©¡£¾¯·½ÌåÏÖ£¬ÕâЩϮ»÷ÊÇÒÔÈ«ÃæÕ½ÕùµÄÐÎʽ½øÐеÄ£¬¶à¸ö APT ×éÖ¯¼ÓÈëÆäÖС£Õþ¸®×¨¼Ò¾¯¸æ˵£¬¹¥»÷Õß½ÓÄÉÁËÅÓ´óµÄºÚ¿Í¼¼Êõ¡£º«¹ú¹ú¼Ò¾¯²ìÌüÌṩÁ˲îÒì APT ×é֯ʵʩµÄ¶à´Î¹¥»÷µÄÏêϸÐÅÏ¢¡£


https://securityaffairs.com/162193/apt/north-korea-south-korean-defense-contractors.html


6. ÃÀ¹ú²ÆÕþ²¿ºÍ¹úÎñÔºÒÔ¼°¶à¼Ò»ú¹¹µÄϵͳÔâµ½ºÚ¿Í¹¥»÷


4ÔÂ23ÈÕ£¬ËÄÃûÒÁÀʺڿÍÔÚÂü¹þ¶ÙÁª°î·¨Ôº±»ÆðËߣ¬±»Ö¸¿ØÕë¶ÔÃÀ¹úÕþ¸®²¿ÃÅ¡¢¹ú·À³Ð°üÉ̺Í˽Ӫ¹«Ë¾¿ªÕ¹ÅÓ´óµÄÍøÂç¼äµý»î¶¯¡£Ä¿Ç°ÈÔÔÚÌӵı»¸æ±»Ö¸¿ØÕë¶ÔÃÀ¹ú²ÆÕþ²¿ºÍ¹úÎñÔºÒÔ¼°Ê®¼¸¼ÒÄܹ»»ñÈ¡¹ú·ÀÏà¹ØÐÅÏ¢µÄÃÀ¹ú˽Ӫ¹«Ë¾µÄÒªº¦ÏµÍ³½øÐй¥»÷¡£Ë¾·¨²¿Ö¸ÔðºÚ¿ÍʹÓÃÌرðµÄÉç»á¹¤³Ì¼¼Êõ£¬°üÂÞð³äÅ®ÐÔÀ´»ñÈ¡Êܺ¦ÕßµÄÐÅÈΡ£Æ¾¾ÝδÃÜ·âµÄÆðËßÊ飬¸ÃºÚ¿Í×éÖ¯µÄ¹¥»÷µÄÊܺ¦ÕßÖ÷ÒªÊǾ­¹ýÐí¿ÉµÄ¹ú·À³Ð°üÉÌ£¬ÕâЩ¹«Ë¾ÒÑ»ñµÃÃÀ¹ú¹ú·À²¿µÄÄþ¾²Ðí¿É£¬¿ÉÒÔ·ÃÎÊ¡¢½ÓÊպʹ洢»úÃÜÐÅÏ¢¡£¸Ã×éÖ¯»¹±»Ö¸¿ØÕë¶ÔÒ»¼Ò×ܲ¿Î»ÓÚŦԼµÄ»á¼ÆʦÊÂÎñËùºÍÒ»¼Ò×ܲ¿Î»ÓÚŦԼµÄ¾Æµê¹«Ë¾¡£ÔÚÆðËßÊéÆô·âµÄͬʱ£¬ÃÀ¹ú¹úÎñÔº»¹Ðû²¼ÐüÉÍ 1000 ÍòÃÀÔª£¬½±ÀøÌṩÏßË÷×¥»ñËûÃÇ£¬²ÆÕþ²¿»¹¶ÔÉæ°¸¸öÈËʵʩÁËÖƲá£


https://www.securityweek.com/10-million-bounty-on-iranian-hackers-for-cyber-attacks-on-us-gov-defense-contractors/