RedLineÃé×¼¶íÂÞ˹µÁ°æÆóÒµÈí¼þÓû§½øÐÐÐÅÏ¢ÇÔÈ¡
Ðû²¼Ê±¼ä 2024-12-101. RedLineÃé×¼¶íÂÞ˹µÁ°æÆóÒµÈí¼þÓû§½øÐÐÐÅÏ¢ÇÔÈ¡
12ÔÂ8ÈÕ£¬×Ô2024Äê1ÔÂÆð£¬RedLineÐÅÏ¢ÇÔÈ¡»î¶¯¿ªÊ¼Õë¶ÔʹÓõÁ°æÆóÒµÈí¼þµÄ¶íÂÞ˹ÆóÒµ¡£ÕâЩµÁ°æÈí¼þͨ¹ý¶íÂÞ˹ÔÚÏßÂÛ̳·Ö·¢£¬¹¥»÷ÕßÇÉÃîµØ½«¶ñÒâÈí¼þαװ³É¿ÉÈƹýÒµÎñ×Ô¶¯»¯Èí¼þÐí¿ÉµÄ¹¤¾ß£¬ÌرðÊÇͨ¹ý·Ö·¢¶ñÒâ°æ±¾µÄHPDxLIB¼¤»îÆ÷¡£ÓëºÏ·¨°æ±¾²îÒ죬¶ñÒâ°æ±¾ÔÚ.NETÖй¹½¨£¬²¢Ê¹ÓÃ×ÔÇ©ÃûÖ¤Êé¡£¿¨°Í˹»ù³ÂËßÖ¸³ö£¬ÕâЩδ¾ÊÚȨµÄÆóÒµÒµÎñÁ÷³Ì×Ô¶¯»¯Èí¼þÓû§³ÉΪ¹¥»÷Ä¿±ê£¬¹¥»÷ÕßÔÚ»á¼ÆÂÛ̳ÉÏ·Ö·¢º¬ÓÐRedLineÇÔÈ¡·¨Ê½µÄ¶ñÒ⼤»î·¨Ê½¡£¸Ã·¨Ê½Ê¹ÓÃ.NET Reactor½øÐлìÏý£¬¶ñÒâ´úÂë¾¹ý¶à²ãѹËõºÍ¼ÓÃÜ£¬Òþ²Ø·½Ê½·Ç³£²»Ñ°³£¡£¹¥»÷ÕßÔÚÏà¹ØÂÛ̳ÉÏÐû²¼¶ñÒ⼤»îÆ÷Á´½Ó£¬²¢Ìṩ½ûÓÃÄþ¾²Èí¼þÒÔÔËÐ줻îÆ÷µÄÏêϸ˵Ã÷£¬ÒÔÌӱܼì²â¡£Óû§±»ÓÕÆÓü¤»îÆ÷ÖеĶñÒâ¿âÌæ»»ºÏ·¨µÄtechsys.dll¿â£¬´Ó¶øÔÚÖ´ÐÐÈí¼þʱͨ¹ýºÏ·¨½ø³Ì¼ÓÔضñÒâ¿â£¬ÔËÐÐÇÔÈ¡·¨Ê½¡£RedLineÇÔÈ¡·¨Ê½×Ô2020Äê³õ±ã»îÔ¾£¬ÄÜ´ÓϵͳÖÐÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬°üÂÞƾ¾Ý¡¢cookie¡¢ä¯ÀÀÆ÷ÀúÊ·¼Ç¼¡¢ÐÅÓÿ¨Êý¾ÝºÍ¼ÓÃÜÇ®°üµÈ¡£
https://securityaffairs.com/171771/cyber-crime/redline-info-stealer-campaign-targets-russian-businesses.html
2. °²ÄÈÑÅ¿ËÒ½ÔºÔâÀÕË÷Èí¼þ¹¥»÷£¬31ÍòÓ໼ÕßÊý¾Ýй¶
12ÔÂ7ÈÕ£¬°²ÄÈÑÅ¿ËÒ½ÔºÊÇÒ»¼ÒλÓÚÂíÈøÖîÈûÖݵķÇÓªÀûÐÔÉçÇøÒ½Ôº£¬ÓµÓÐ83ÕÅ´²Î»¡¢200ÃûҽʦºÍ1200ÃûÊÂÇéÈËÔ±£¬Îªµ±µØ¾ÓÃñÌṩ»ù±¾Ò½ÁÆ·þÎñ¡£2023Äê12ÔÂ25ÈÕ£¬¸ÃÒ½ÔºÔâÊÜÁËÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÁè¼Ý310,000Ãû»¼ÕßµÄÃô¸Ð½¡¿µÊý¾Ý±»Ð¹Â¶¡£Ò½ÔºÁ¢¼´½ÓÄÉÐж¯£¬ÏÂÏßϵͳ²¢ÏòÖ´·¨²¿ÃÅ·¢³ö¾¯±¨¡£2024Äê1ÔÂ19ÈÕ£¬¡°Money Message¡±ÀÕË÷Èí¼þÍŻ↑ʼ¹ûÈ»ÀÕË÷¸ÃÒ½Ôº£¬²¢ÔÚÆä°µÍøÀÕË÷ÍøÕ¾ÉÏй¶Á˾ݳƴÓÒ½ÔºÇÔÈ¡µÄÊý¾ÝÑù±¾¡£Ò½Ôº¹ÜÀíÈËÔ±²¢Î´ÓëÍþвÐÐΪÕß½»É棬×îÖÕÓÚ1ÔÂ26ÈÕÐû²¼ÁËËùÓÐÊý¾Ý¡£¾¹ý³¹µ×µÄÈ¡Ö¤ÊӲ죬ҽԺÓÚ2024Äê11ÔÂ5ÈÕÍê³ÉÁ˶Ôй¶Êý¾ÝµÄÉó²é£¬²¢Í¨ÖªÁËÊÜÓ°ÏìµÄ¸öÈË¡£Ð¹Â¶µÄÐÅÏ¢°üÂÞÈË¿Úͳ¼ÆÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢¡¢½¡¿µ±£ÏÕÐÅÏ¢¡¢Éç»áÄþ¾²ºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢²ÆÕþÐÅÏ¢µÈ¡£¾¡¹ÜҽԺûÓм£Ïó±íÃ÷ÕâÆðʼþµ¼ÖÂÁËÈκÎÆÛÕ©ÐÐΪ£¬µ«»¹ÊÇÌáÐÑÔ±¹¤ºÍ»¼ÕßÒª±£³Ö¾¯Ì裬²¢ÌṩÁËΪÆÚ24¸öÔµÄÉí·Ý±£»¤ºÍÐÅÓüà¿Ø·þÎñ¡£
https://www.bleepingcomputer.com/news/security/anna-jaques-hospital-ransomware-breach-exposed-data-of-300k-patients/
3. ÂÞÂíÄáÑÇÄÜÔ´¹©Ó¦ÉÌElectrica GroupÔâÊÜÀÕË÷Èí¼þ¹¥»÷
12ÔÂ10ÈÕ£¬ÂÞÂíÄáÑÇÄÜÔ´¹©Ó¦ÉÌElectrica GroupÕýÃæÁÙÒ»ÆðÁ¬ÐøµÄÀÕË÷Èí¼þ¹¥»÷£¬µ«¸Ã¹«Ë¾ÒÑÏòͶ×ÊÕß±£Ö¤£¬ÆäÒªº¦ÏµÍ³²¢Î´Êܵ½Ó°Ï졣ΪÁ˱£ÕÏÔËÓªºÍ¸öÈËÊý¾ÝµÄÄþ¾²£¬ElectricaÒÑÆô¶¯ÄÚ²¿ÍøÂçÄþ¾²ÐÒ飬²¢Óë¹ú¼ÒÍøÂçÄþ¾²»ú¹¹ºÏ×÷£¬Ö¼ÔÚʶ±ð¹¥»÷Ô´²¢¿ØÖÆÆäÓ°Ïì¡£ElectricaÊÇÂÞÂíÄáÑǵçÁ¦ÅäËͺ͹©Ó¦Êг¡µÄÖ÷Òª¼ÓÈëÕߣ¬ÎªÁè¼Ý380Íò¿Í»§Ìṩ·þÎñ£¬²¢ÔÚ²¼¼ÓÀÕ˹ÌغÍÂ׶Ø֤ȯ½»Ò×ËùÉÏÊС£±¾ÖÜÔçЩʱºò£¬¸Ã¹«Ë¾Ðû²¼Í¨Öª£¬¼û¸æͶ×ÊÕßÕýÔÚ·¢ÉúµÄÍøÂç¹¥»÷£¬²¢Ç¿µ÷ËùÓÐÌض¨µÄÏìÓ¦ÐÒéÒÑƾ¾ÝÄÚ²¿·¨Ê½ºÍÏÖÐйæÔòÆô¶¯¡£ÂÞÂíÄáÑÇÄÜÔ´²¿Ö¤Êµ¸Ã¹«Ë¾È·ÊµÔâÊÜÁËÀÕË÷Èí¼þ¹¥»÷£¬µ«¹¥»÷²¢Î´Ó°Ïì¸Ã¹«Ë¾µÄSCADAϵͳ¡£Ç鱨·ÖÎöÈËÊ¿ÈÏΪ£¬´Ë´ÎÏ®»÷¿ÉÄÜÊÇÇ׶íÍÅÌå·¢¶¯µÄ£¬Ö¼ÔÚÅê»÷ÂÞÂíÄáÑÇÒò¶íÂÞ˹ÉæÏÓ¸ÉÔ¤¶øÈ¡Ïû×Üͳѡ¾Ù¡£ÂÞÂíÄáÑÇÇ鱨¾Ö͸¶£¬Áè¼Ý85,000´ÎÍøÂç¹¥»÷Õë¶Ô¸Ã¹úÑ¡¾Ùϵͳ£¬µ«ÄªË¹¿Æ·ñÈ϶Դ˽øÐÐÈκι¥»÷¡£Electrica Group½¨Òé¿Í»§¶ÔDZÔÚµÄÍøÂçµöÓãʵÑéºÍ¿ÉÒÉͨÐű£³Ö¾¯Ìè¡£
https://securityaffairs.com/171832/hacking/electrica-group-ransomware-attack.html
4. ÐÄÔàÍâ¿ÆÒ½ÁÆÉ豸ÖÆÔìÉÌArtivionÔâÀÕË÷Èí¼þ¹¥»÷
12ÔÂ9ÈÕ£¬ÐÄÔàÍâ¿ÆÒ½ÁÆÉ豸ÖÆÔìÉÌArtivionÔÚ11ÔÂ21ÈÕÔâÊÜÁËÀÕË÷Èí¼þ¹¥»÷£¬¸Ã¹¥»÷ÈÅÂÒÁËÆäÔËÓª²¢µ¼Ö²¿ÃÅϵͳ¹Ø±Õ¡£Artivion×ܲ¿Î»ÓÚÑÇÌØÀ¼´ó£¬È«ÇòÔ±¹¤Áè¼Ý1,250Ãû£¬ÔÚ100¶à¸ö¹ú¼ÒÉèÓÐÏúÊÛ´ú±í£¬²¢ÔÚÑÇÌØÀ¼´ó¡¢°Â˹͡ºÍºÚÐÀ¸ùÉèÓÐÖÆÔ칤³§¡£¾ÝArtivionÏòÃÀ¹ú֤ȯ½»Ò×ίԱ»áÌá½»µÄ³ÂËߣ¬¹¥»÷Õß¼ÓÃÜÁËÆ䲿ÃÅϵͳ²¢ÇÔÈ¡ÁËÊý¾Ý£¬µ«¹«Ë¾ÔËÓª¡¢¶©µ¥´¦ÖúÍÔËÊäÖжÏÎÊÌâÒÑ»ù±¾µÃµ½½â¾ö¡£ËäÈ»ÉÐδÓÐÀÕË÷Èí¼þ×éÖ¯Éù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬µ«ArtivionÈÏΪ¿ÉÄܻᷢÉú±£ÏÕδº¸ÇµÄÌرðÓöȡ£½üÆÚ£¬ÃÀ¹úÒ½ÁƱ£½¡ÐÐÒµÒ²ÔâÓöÁ˶àÆðÀÕË÷Èí¼þ¹¥»÷£¬°üÂÞBoston Children's Health PhysiciansºÍUMCÒ½ÁÆϵͳ£¬ÒÔ¼°È¥ÄêÊ¥µ®½ÚÔâÊܹ¥»÷µÄ°²ÄÈÑÅ¿ËÒ½Ôº£¬ÕâЩ¹¥»÷¶¼µ¼ÖÂÁËÃô¸ÐÊý¾ÝµÄй¶ºÍÔËÓªµÄÖжϡ£
https://www.bleepingcomputer.com/news/security/ransomware-attack-hits-leading-heart-surgery-device-maker/
5. ΢Èí½â³ý¶ÔUbisoftÓÎÏ·Windows 24H2¸üÐÂÏÞÖÆ
12ÔÂ9ÈÕ£¬Î¢ÈíÒѲ¿ÃŽâ³ýÁ˶ÔWindows 24H2¸üÐÂÓëijЩUbisoftÓÎϷϵͳ¼æÈÝÐÔµÄÏÞÖÆ¡£´ËÇ°£¬ÓÉÓÚ¡¶´Ì¿ÍÐÅÌõ¡·¡¢¡¶ÐÇÇò´óÕ½£º·¨Íâ¿ñͽ¡·ºÍ¡¶°¢·²´ï£ºÅ˶àÀ±ß½®¡·µÈÓÎÏ·ÔÚWindows 11 24H2Ô¤ÀÀ°æÖзºÆðÍ߽⡢ËÀ»úºÍÒôƵÎÊÌ⣬΢Èí×èÖ¹ÁË×°ÓÐÕâЩÓÎÏ·µÄPC½øÐÐWindows 24H2Éý¼¶¡£Óû§·´À¡ÏÔʾ£¬ÓÎÏ·´æÔÚ²»Îȶ¨Çé¿ö£¬ÈçÆô¶¯ºóÁ¢¼´±ÀÀ£»ò¼ÓÔØÉú´æÓÎÏ·ºó¼¸·ÖÖÓÄÚÍ߽⡢¶³½á»òºÚÆÁ¡£Îª·ÀÖ¹ÎÊÌâÀ©É¢£¬Î¢Èí½ÓÄÉÁ˱£»¤´ëÊ©¡£ÏÖÔÚ£¬ÔÚUbisoftÐû²¼ÁÙʱÐÞ²¹·¨Ê½»º½âÍß½âÎÊÌâºó£¬Î¢Èí½â³ýÁ˶ԡ¶ÐÇÇò´óÕ½£º·¨Íâ¿ñͽ¡·ºÍ¡¶°¢·²´ï£ºÅ˶àÀ±ß½®¡·µÄÉý¼¶ÏÞÖÆ£¬µ«½¨ÒéÍæ¼ÒÔÚÎÊÌâ½â¾öÇ°²»ÒªÊ¹ÓÃWindows 11°²×°ÖúÊÖ»òýÌå´´½¨¹¤¾ßÉý¼¶ÊÜÓ°ÏìPC¡£Í¬Ê±£¬Î¢Èí»¹Ðû²¼×èÖ¹°²×°Á˹ýʱGoogle Workspace SyncµÄϵͳºÍ¾ßÓв»¼æÈÝÓ¢ÌضûÖÇÄÜÉùÒô¼¼ÊõÒôƵÇý¶¯·¨Ê½µÄÉ豸½øÐÐWindows 11 24H2¸üУ¬ÒòΪÕâЩ»áµ¼ÖÂOutlookÆô¶¯ÎÊÌâºÍÀ¶ÆÁËÀ»úÎÊÌâ¡£
https://www.bleepingcomputer.com/news/microsoft/ubisoft-fixes-windows-11-24h2-conflicts-causing-game-crashes/
6. ³¯ÏʺڿÍCitrine Sleet͵ȡRadiant Capital 5000ÍòÃÀÔª¼ÓÃÜ»õ±Ò
12ÔÂ9ÈÕ£¬È¥ÖÐÐÄ»¯½ðÈÚ(DeFi)ƽ̨Radiant CapitalÔÚ10ÔÂ16ÈÕÐû²¼ÆäϵͳÔâÊÜÍøÂç¹¥»÷£¬µ¼ÖÂ5000ÍòÃÀÔª¼ÓÃÜ»õ±Ò±»µÁ¡£ÔÚMandiantÍøÂçÄþ¾²×¨¼ÒµÄÐÖúÏ£¬Radiant¶Ô´Ë´Î¹¥»÷½øÐÐÁËÉîÈëÊӲ죬²¢È·¶¨Ä»ºóºÚÊÖΪ³¯Ïʹú¼ÒÁ¥ÊôºÚ¿Í×éÖ¯Citrine Sleet£¨ÓÖÃû¡°UNC4736¡±ºÍ¡°AppleJeus¡±£©¡£´Ë´Î¹¥»÷ʼÓÚ9ÔÂ11ÈÕ£¬ºÚ¿Íͨ¹ýTelegram·¢ËÍð³äÇ°³Ð°üÉ̵ĶñÒâÏûÏ¢£¬ÓÕÆ¿ª·¢ÈËÔ±ÏÂÔØ°üÂÞ¡°InletDrift¡±macOS¶ñÒâÈí¼þ¸ºÔصÄZIPÎļþ£¬´Ó¶øÔÚÊÜѬȾµÄÉ豸ÉϽ¨Á¢ºóÃÅ¡£ºÚ¿ÍÀûÓÃͨÀýµÄ¶àÖØÇ©ÃûÁ÷³Ì£¬ÒÔ½»Ò×´íÎóµÄÃûÒåÊÕ¼¯ÓÐЧǩÃû£¬²¢´ÓArbitrumºÍ±Ò°²ÖÇÄÜÁ´(BSC)Êг¡ÇÔÈ¡×ʽ𡣴˴ι¥»÷Éè¼Æ¾«Á¼£¬ÈƹýÁËÓ²¼þÇ®°üÄþ¾²ºÍ¶à²ãÑéÖ¤£¬½»Ò×ÔÚÊÖ¶¯ºÍÄ£Äâ¼ì²éÖп´ÆðÀ´¶¼ºÜÕý³££¬ÏÔʾ³ö¼«¸ßµÄÅÓ´óÐÔ¡£RadiantÕýÔÚÓëÃÀ¹úÖ´·¨²¿ÃźÍzeroShadowºÏ×÷£¬×·»Ø¾¡¿ÉÄܶàµÄ±»µÁ×ʽ𣬲¢Ç¿µ÷ÐèÒª¸üÇ¿´óµÄÉ豸¼¶½â¾ö·½°¸À´ÔöÇ¿½»Ò×Äþ¾²ÐÔ¡£
https://www.bleepingcomputer.com/news/security/radiant-links-50-million-crypto-heist-to-north-korean-hackers