LockBitÍÅ»ïÉù³Æ½«Ðû²¼º«¹ú¹ú¼Ò˰Îñ¾ÖµÄÊý¾Ý

Ðû²¼Ê±¼ä 2023-04-03

1¡¢LockBitÍÅ»ïÉù³Æ½«Ðû²¼º«¹ú¹ú¼Ò˰Îñ¾ÖµÄÊý¾Ý


¾ÝýÌå4ÔÂ1ÈÕ±¨µÀ £¬ÀÕË÷ÍÅ»ïLockBit³ÆÆäÈëÇÖÁ˺«¹ú¹ú¼Ò˰Îñ¾Ö¡£3ÔÂ29ÈÕ £¬LockBitÍŻォ¸Ã»ú¹¹Ìí¼Óµ½ÆäÍøÕ¾ £¬²¢Ðû²¼½«ÓÚ4ÔÂ1ÈÕ֮ǰÐû²¼±»µÁÊý¾Ý¡£¹ú¼Ò˰Îñ¾Ö£¨NTS£©×÷Ϊ²ÆÎñ²¿µÄÒ»¸öÍⲿ×éÖ¯ÓÚ1966Äê3ÔÂ3ÈÕ½¨Éè £¬Ö÷ÒªÈÏÕæÄÚ²¿Ë°ÊÕÆÀ¹ÀºÍÕ÷ÊÕ¡£×èÖ¹4ÔÂ1ÈÕ £¬¸ÃÍÅ»ïÉÐδÐû²¼±»µÁÊý¾Ý¡£µ«ÈôÊǹ¥»÷ÊÇÕæÊµµÄ £¬Õ⽫¶Ôº«¹ú¹«ÃñµÄÒþ˽ºÍÇå¾²×é³ÉÑÏÖØÍþв¡£


https://securityaffairs.com/144342/cyber-crime/lockbit-south-korean-national-tax-service.html


2¡¢TMX Finance¼°Æä×Ó¹«Ë¾Ô¼480Íò¸ö¿Í»§µÄÊý¾Ýй¶


ýÌå3ÔÂ31ÈÕ³Æ £¬TMX Finance¼°Æä×Ó¹«Ë¾TitleMax¡¢TitleBucksºÍInstaLoanÅû¶ÁËÒ»ÆðÊý¾Ýй¶ÊÂÎñ £¬Éæ¼°4822580¸ö¿Í»§µÄÊý¾Ý¡£Õâ¼Ò¼ÓÄôó½ðÈÚ¹«Ë¾ÌåÏÖ £¬ºÚ¿ÍÔÚ2022Äê12ÔÂÉÏÑ®ÈëÇÖÁËÆäϵͳ £¬µ«ËûÃÇÖ±µ½2023Äê2ÔÂ13Èղŷ¢Ã÷Á˹¥»÷»î¶¯¡£3ÔÂ1ÈÕÍê³ÉÄÚ²¿ÊÓ²ìºó £¬TMX·¢Ã÷¹¥»÷ÕßÔÚ2023Äê2ÔÂ3ÈÕÖÁ14ÈÕÇÔÈ¡Á˿ͻ§µÄÐÅÏ¢ £¬°üÀ¨ÐÕÃû¡¢»¤Õպš¢¼ÝÕÕºÅÂ롢˰ºÅ¡¢Éç»áÇå¾²ºÅÂëºÍ½ðÈÚÕË»§ÐÅÏ¢µÈ¡£ÏÖÔÚ £¬¸Ã¹«Ë¾ÊµÑéÁ˶˵ã±£»¤ºÍ¼à¿Ø £¬ÖØÖÃÁËËùÓÐÔ±¹¤ÕÊ»§ÃÜÂë £¬²¢½«ÎªÓû§ÌṩExperianΪÆÚ12¸öÔµÄÉí·Ý±£»¤·þÎñ¡£


https://www.bleepingcomputer.com/news/security/consumer-lender-tmx-discloses-data-breach-impacting-48-million-people/


3¡¢Ä£¿é»¯¹¤¾ß¼¯AlienFoxÇÔÈ¡¶à¸öÔÆ·þÎñÌṩÉÌÆ¾Ö¤


3ÔÂ30ÈÕ £¬SentinelLabs³ÆÆä·¢Ã÷ÁËÒ»¸öÃûΪAlienFoxµÄй¤¾ß°ü £¬¿É±»ÓÃÓÚÈëÇÖµç×ÓÓʼþºÍÍøÂçÍйܷþÎñ¡£AlienFoxÊÇÄ£¿é»¯µÄ £¬´ó´ó¶¼¹¤¾ß¶¼ÊÇ¿ªÔ´µÄ¡£¹¥»÷Õß¿ÉʹÓÃÆä´ÓLeakIXºÍSecurityTrailsµÈÇ徲ɨÃèÆ½Ì¨ÍøÂçÉèÖùýʧµÄÖ÷»úÁбí¡£È»ºó £¬AlienFoxʹÓÃÊý¾ÝÌáÈ¡¾ç±¾ÔÚÉèÖùýʧµÄ·þÎñÆ÷ÖÐËÑË÷ÓÃÓÚ´æ´¢ÉñÃØµÄÉèÖÃÎļþ £¬ÀýÈçAPIÃÜÔ¿¡¢ÕÊ»§Æ¾Ö¤ºÍÉí·ÝÑéÖ¤ÁîÅÆ¡£¸Ã¶ñÒâÈí¼þÄܹ»Õë¶Ô1and1¡¢AWS¡¢Bluemail¡¢ExotelºÍGoogle WorkspaceµÈÊ®¼¸¸öÔÆÆ½Ì¨¡£


https://www.sentinelone.com/labs/dissecting-alienfox-the-cloud-spammers-swiss-army-knife/


4¡¢WordPress²å¼þElementor ProÖеÄÎó²îÒѱ»Ê¹ÓÃ


¾Ý3ÔÂ31ÈÕ±¨µÀ £¬WordPress²å¼þElementor ProÖеÄÎó²îÒѱ»Æð¾¢Ê¹Óá£Elementor ProÊÇÒ»¸öWordPressÒ³Ãæ¹¹½¨Æ÷²å¼þ £¬±»Áè¼Ý1100Íò¸öÍøÕ¾Ê¹Ó᣸ÃÎó²îÓ°ÏìÁËv3.11.6¼°¸üµÍ°æ±¾ £¬¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓÃÆä¸ü¸ÄÍøÕ¾ÉèÖà £¬ÉõÖÁÍêÈ«½ÓÊÜÍøÕ¾¡£Çå¾²¹«Ë¾PatchStack±¨¸æ³Æ £¬ºÚ¿ÍÕýÔÚÆð¾¢Ê¹Óô˲å¼þÎó²î½«»á¼ûÕßÖØ¶¨Ïòµ½¶ñÒâÓò£¨¡°away[.]trackersline[.]com¡±£©»ò½«ºóÃÅÉÏ´«µ½±»ÈëÇÖµÄÍøÕ¾¡£ÕâЩ¹¥»÷ÖÐÉÏ´«µÄºóÃÅÃûΪwp-resortpark.zip¡¢wp-rate.php»òlll.zip¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-bug-in-elementor-pro-wordpress-plugin-with-11m-installs/


5¡¢ÎÚ¿ËÀ¼Ö´·¨²¿·Ö¾Ð²¶ÒÑÇÔÈ¡430ÍòÃÀÔªµÄ´¹ÂÚÍÅ»ï


ýÌå3ÔÂ31ÈÕ±¨µÀ³Æ £¬ÎÚ¿ËÀ¼ºÍ½Ý¿ËµÄÖ´·¨Ö°Ô±Ð­Í¬¾Ð²¶ÁËij´¹ÂÚÍÅ»ïµÄ¼¸Ãû³ÉÔ±¡£¸ÃÍÅ»ïÕë¶Ô·¨¹ú¡¢Î÷°àÑÀ¡¢²¨À¼¡¢½Ý¿Ë¡¢ÆÏÌÑÑÀµÈÅ·ÖÞ¹ú¼Ò½¨ÉèÁË100¶à¸ö´¹ÂÚÍøÕ¾ £¬ÒÔµÍÓÚÊг¡¼ÛµÄÖÖÖÖÉÌÆ·ÎªÓÕ¶ü £¬ÓÕʹĿµÄÊäÈëÐÅÓÿ¨ÏêϸÐÅÏ¢À´Ö§¸¶Ðéα¶©µ¥ £¬²¢Ê¹ÓÃÕâЩÐÅÏ¢´ÓÄ¿µÄÕË»§ÖÐŲÓÃ×ʽð¡£ËûÃÇÒÑ´ÓÅ·ÖÞ1000¶à¸ö±»¹¥»÷Ä¿µÄÄÇÀïÇÔÈ¡ÁËÁè¼Ý430ÍòÃÀÔª¡£ÏÖÔÚ £¬ÒѾ­¶ÔÏÓÒÉÈËÌáÆðÐÌÊÂËßËÏ £¬ËûÃÇ¿ÉÄÜÃæÁÙ×î¸ß12ÄêµÄî¿Ïµ¡£


https://securityaffairs.com/144279/cyber-crime/cyber-police-of-ukraine-cybercrime-gang.html


6¡¢Ñо¿ÍŶÓÅû¶RedGolfʹÓúóÃÅKEYPLUGµÄ¹¥»÷»î¶¯


Recorded FutureÔÚ3ÔÂ30ÈÕÅû¶ÁËRedGolfʹÓúóÃÅKEYPLUGµÄ¹¥»÷»î¶¯¡£RedGolfÖ÷ÒªÕë¶Ôº½¿Õ¡¢Æû³µ¡¢½ÌÓý¡¢Õþ¸®¡¢Ã½Ìå¡¢ÐÅÏ¢ÊÖÒÕºÍ×Ú½ÌÏà¹ØµÄ×éÖ¯¡£Ñо¿Ö°Ô±³ýÁ˼ì²âµ½¸ÃÍÅ»ïÔÚ2021ÄêÖÁ2023ÄêʹÓõÄKEYPLUGÑù±¾ºÍ»ù´¡ÉèÊ©£¨´úºÅΪGhostWolf£©Íâ £¬»¹Ö¸³öÆäʹÓÃÁËCobaltStrikeºÍPlugXµÈÆäËü¹¤¾ß¡£¸ÃÇå¾²¹«Ë¾»¹ÌåÏÖ £¬RedGolf½«¼ÌÐø¸ßÔËÓª½Ú×à £¬²¢Ñ¸ËÙ½«ÃæÏòÍⲿµÄ¹«Ë¾×°±¸£¨VPN¡¢·À»ðǽºÍÓʼþ·þÎñÆ÷µÈ£©ÖеÄÎó²îÎäÆ÷»¯ £¬ÒÔ»ñµÃÄ¿µÄÍøÂçµÄ³õʼ»á¼ûȨÏÞ¡£


https://www.recordedfuture.com/with-keyplug-chinas-redgolf-spies-on-steals-from-wide-field-targets