LockBitÍÅ»ïÉù³Æ½«Ðû²¼º«¹ú¹ú¼Ò˰Îñ¾ÖµÄÊý¾Ý

Ðû²¼Ê±¼ä 2023-04-03

1¡¢LockBitÍÅ»ïÉù³Æ½«Ðû²¼º«¹ú¹ú¼Ò˰Îñ¾ÖµÄÊý¾Ý


¾ÝýÌå4ÔÂ1ÈÕ±¨µÀ £¬£¬£¬ÀÕË÷ÍÅ»ïLockBit³ÆÆäÈëÇÖÁ˺«¹ú¹ú¼Ò˰Îñ¾Ö¡£¡£¡£¡£¡£¡£3ÔÂ29ÈÕ £¬£¬£¬LockBitÍŻォ¸Ã»ú¹¹Ìí¼Óµ½ÆäÍøÕ¾ £¬£¬£¬²¢Ðû²¼½«ÓÚ4ÔÂ1ÈÕ֮ǰÐû²¼±»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£¹ú¼Ò˰Îñ¾Ö£¨NTS£©×÷Ϊ²ÆÎñ²¿µÄÒ»¸öÍⲿ×éÖ¯ÓÚ1966Äê3ÔÂ3ÈÕ½¨Éè £¬£¬£¬Ö÷ÒªÈÏÕæÄÚ²¿Ë°ÊÕÆÀ¹ÀºÍÕ÷ÊÕ¡£¡£¡£¡£¡£¡£×èÖ¹4ÔÂ1ÈÕ £¬£¬£¬¸ÃÍÅ»ïÉÐδÐû²¼±»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£µ«ÈôÊǹ¥»÷ÊÇÕæÊµµÄ £¬£¬£¬Õ⽫¶Ôº«¹ú¹«ÃñµÄÒþ˽ºÍÇå¾²×é³ÉÑÏÖØÍþв¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/144342/cyber-crime/lockbit-south-korean-national-tax-service.html


2¡¢TMX Finance¼°Æä×Ó¹«Ë¾Ô¼480Íò¸ö¿Í»§µÄÊý¾Ýй¶


ýÌå3ÔÂ31ÈÕ³Æ £¬£¬£¬TMX Finance¼°Æä×Ó¹«Ë¾TitleMax¡¢TitleBucksºÍInstaLoanÅû¶ÁËÒ»ÆðÊý¾Ýй¶ÊÂÎñ £¬£¬£¬Éæ¼°4822580¸ö¿Í»§µÄÊý¾Ý¡£¡£¡£¡£¡£¡£Õâ¼Ò¼ÓÄôó½ðÈÚ¹«Ë¾ÌåÏÖ £¬£¬£¬ºÚ¿ÍÔÚ2022Äê12ÔÂÉÏÑ®ÈëÇÖÁËÆäϵͳ £¬£¬£¬µ«ËûÃÇÖ±µ½2023Äê2ÔÂ13Èղŷ¢Ã÷Á˹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£3ÔÂ1ÈÕÍê³ÉÄÚ²¿ÊÓ²ìºó £¬£¬£¬TMX·¢Ã÷¹¥»÷ÕßÔÚ2023Äê2ÔÂ3ÈÕÖÁ14ÈÕÇÔÈ¡Á˿ͻ§µÄÐÅÏ¢ £¬£¬£¬°üÀ¨ÐÕÃû¡¢»¤Õպš¢¼ÝÕÕºÅÂ롢˰ºÅ¡¢Éç»áÇå¾²ºÅÂëºÍ½ðÈÚÕË»§ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬¸Ã¹«Ë¾ÊµÑéÁ˶˵ã±£»£»£»£» £»£»£»¤ºÍ¼à¿Ø £¬£¬£¬ÖØÖÃÁËËùÓÐÔ±¹¤ÕÊ»§ÃÜÂë £¬£¬£¬²¢½«ÎªÓû§ÌṩExperianΪÆÚ12¸öÔµÄÉí·Ý±£»£»£»£» £»£»£»¤Ð§ÀÍ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/consumer-lender-tmx-discloses-data-breach-impacting-48-million-people/


3¡¢Ä£¿£¿£¿£¿£¿£¿é»¯¹¤¾ß¼¯AlienFoxÇÔÈ¡¶à¸öÔÆÐ§ÀÍÌṩÉÌÆ¾Ö¤


3ÔÂ30ÈÕ £¬£¬£¬SentinelLabs³ÆÆä·¢Ã÷ÁËÒ»¸öÃûΪAlienFoxµÄй¤¾ß°ü £¬£¬£¬¿É±»ÓÃÓÚÈëÇÖµç×ÓÓʼþºÍÍøÂçÍйÜЧÀÍ¡£¡£¡£¡£¡£¡£AlienFoxÊÇÄ£¿£¿£¿£¿£¿£¿é»¯µÄ £¬£¬£¬´ó´ó¶¼¹¤¾ß¶¼ÊÇ¿ªÔ´µÄ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÆä´ÓLeakIXºÍSecurityTrailsµÈÇ徲ɨÃèÆ½Ì¨ÍøÂçÉèÖùýʧµÄÖ÷»úÁÐ±í¡£¡£¡£¡£¡£¡£È»ºó £¬£¬£¬AlienFoxʹÓÃÊý¾ÝÌáÈ¡¾ç±¾ÔÚÉèÖùýʧµÄЧÀÍÆ÷ÖÐËÑË÷ÓÃÓÚ´æ´¢ÉñÃØµÄÉèÖÃÎļþ £¬£¬£¬ÀýÈçAPIÃÜÔ¿¡¢ÕÊ»§Æ¾Ö¤ºÍÉí·ÝÑéÖ¤ÁîÅÆ¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÄܹ»Õë¶Ô1and1¡¢AWS¡¢Bluemail¡¢ExotelºÍGoogle WorkspaceµÈÊ®¼¸¸öÔÆÆ½Ì¨¡£¡£¡£¡£¡£¡£


https://www.sentinelone.com/labs/dissecting-alienfox-the-cloud-spammers-swiss-army-knife/


4¡¢WordPress²å¼þElementor ProÖеÄÎó²îÒѱ»Ê¹ÓÃ


¾Ý3ÔÂ31ÈÕ±¨µÀ £¬£¬£¬WordPress²å¼þElementor ProÖеÄÎó²îÒѱ»Æð¾¢Ê¹Óᣡ£¡£¡£¡£¡£Elementor ProÊÇÒ»¸öWordPressÒ³Ãæ¹¹½¨Æ÷²å¼þ £¬£¬£¬±»Áè¼Ý1100Íò¸öÍøÕ¾Ê¹Óᣡ£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËv3.11.6¼°¸üµÍ°æ±¾ £¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓÃÆä¸ü¸ÄÍøÕ¾ÉèÖà £¬£¬£¬ÉõÖÁÍêÈ«½ÓÊÜÍøÕ¾¡£¡£¡£¡£¡£¡£Çå¾²¹«Ë¾PatchStack±¨¸æ³Æ £¬£¬£¬ºÚ¿ÍÕýÔÚÆð¾¢Ê¹Óô˲å¼þÎó²î½«»á¼ûÕßÖØ¶¨Ïòµ½¶ñÒâÓò£¨¡°away[.]trackersline[.]com¡±£©»ò½«ºóÃÅÉÏ´«µ½±»ÈëÇÖµÄÍøÕ¾¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷ÖÐÉÏ´«µÄºóÃÅÃûΪwp-resortpark.zip¡¢wp-rate.php»òlll.zip¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-bug-in-elementor-pro-wordpress-plugin-with-11m-installs/


5¡¢ÎÚ¿ËÀ¼Ö´·¨²¿·Ö¾Ð²¶ÒÑÇÔÈ¡430ÍòÃÀÔªµÄ´¹ÂÚÍÅ»ï


ýÌå3ÔÂ31ÈÕ±¨µÀ³Æ £¬£¬£¬ÎÚ¿ËÀ¼ºÍ½Ý¿ËµÄÖ´·¨Ö°Ô±Ð­Í¬¾Ð²¶ÁËij´¹ÂÚÍÅ»ïµÄ¼¸Ãû³ÉÔ±¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÕë¶Ô·¨¹ú¡¢Î÷°àÑÀ¡¢²¨À¼¡¢½Ý¿Ë¡¢ÆÏÌÑÑÀµÈÅ·ÖÞ¹ú¼Ò½¨ÉèÁË100¶à¸ö´¹ÂÚÍøÕ¾ £¬£¬£¬ÒÔµÍÓÚÊг¡¼ÛµÄÖÖÖÖÉÌÆ·ÎªÓÕ¶ü £¬£¬£¬ÓÕʹĿµÄÊäÈëÐÅÓÿ¨ÏêϸÐÅÏ¢À´Ö§¸¶Ðéα¶©µ¥ £¬£¬£¬²¢Ê¹ÓÃÕâЩÐÅÏ¢´ÓÄ¿µÄÕË»§ÖÐŲÓÃ×ʽ𡣡£¡£¡£¡£¡£ËûÃÇÒÑ´ÓÅ·ÖÞ1000¶à¸ö±»¹¥»÷Ä¿µÄÄÇÀïÇÔÈ¡ÁËÁè¼Ý430ÍòÃÀÔª¡£¡£¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬ÒѾ­¶ÔÏÓÒÉÈËÌáÆðÐÌÊÂËßËÏ £¬£¬£¬ËûÃÇ¿ÉÄÜÃæÁÙ×î¸ß12ÄêµÄî¿Ïµ¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/144279/cyber-crime/cyber-police-of-ukraine-cybercrime-gang.html


6¡¢Ñо¿ÍŶÓÅû¶RedGolfʹÓúóÃÅKEYPLUGµÄ¹¥»÷»î¶¯


Recorded FutureÔÚ3ÔÂ30ÈÕÅû¶ÁËRedGolfʹÓúóÃÅKEYPLUGµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£RedGolfÖ÷ÒªÕë¶Ôº½¿Õ¡¢Æû³µ¡¢½ÌÓý¡¢Õþ¸®¡¢Ã½Ìå¡¢ÐÅÏ¢ÊÖÒÕºÍ×Ú½ÌÏà¹ØµÄ×éÖ¯¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³ýÁ˼ì²âµ½¸ÃÍÅ»ïÔÚ2021ÄêÖÁ2023ÄêʹÓõÄKEYPLUGÑù±¾ºÍ»ù´¡ÉèÊ©£¨´úºÅΪGhostWolf£©Íâ £¬£¬£¬»¹Ö¸³öÆäʹÓÃÁËCobaltStrikeºÍPlugXµÈÆäËü¹¤¾ß¡£¡£¡£¡£¡£¡£¸ÃÇå¾²¹«Ë¾»¹ÌåÏÖ £¬£¬£¬RedGolf½«¼ÌÐø¸ßÔËÓª½Ú×à £¬£¬£¬²¢Ñ¸ËÙ½«ÃæÏòÍⲿµÄ¹«Ë¾×°±¸£¨VPN¡¢·À»ðǽºÍÓʼþЧÀÍÆ÷µÈ£©ÖеÄÎó²îÎäÆ÷»¯ £¬£¬£¬ÒÔ»ñµÃÄ¿µÄÍøÂçµÄ³õʼ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£


https://www.recordedfuture.com/with-keyplug-chinas-redgolf-spies-on-steals-from-wide-field-targets