FIN8ʹÓÃSardonicºóÃÅбäÌå·Ö·¢ÀÕË÷Èí¼þNoberus
Ðû²¼Ê±¼ä 2023-07-201¡¢FIN8ʹÓÃSardonicºóÃÅбäÌå·Ö·¢ÀÕË÷Èí¼þNoberus
SymantecÔÚ7ÔÂ18Èճƣ¬£¬£¬£¬£¬Æä·¢Ã÷ÁËFIN8£¨ÓÖ³ÆSyssphinx£©Ê¹ÓÃˢеÄSardonic·Ö·¢ÀÕË÷Èí¼þNoberusµÄ¹¥»÷»î¶¯¡£¡£¡£¡£FIN8×Ô2016Äê1ÔÂ×îÏÈ»îÔ¾£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÁãÊÛ¡¢²ÍÒû¡¢Âùݡ¢Ò½ÁƱ£½¡ºÍÓéÀÖµÈÐÐÒµ¡£¡£¡£¡£×î½üµÄ¹¥»÷Óë֮ǰµÄÇø±ðÔÚÓÚ£¬£¬£¬£¬£¬×îÖÕpayloadÊÇNoberusÒÔ¼°Ê¹ÓÃÁËÖØÐÂÉè¼ÆµÄºóÃÅ¡£¡£¡£¡£Ë¢ÐµÄSardonicÓë2021ÄêÆÊÎöµÄ°æ±¾ÓÐÐí¶àÏàͬµÄ¹¦Ð§£¬£¬£¬£¬£¬µ«²»ÔÙʹÓÃC++±ê×¼¿â£¬£¬£¬£¬£¬¶øÊÇÌæ»»Îª´¿CʵÏÖ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬SyssphinxתÏòÀÕË÷¹¥»÷Åú×¢£¬£¬£¬£¬£¬ËûÃÇ¿ÉÄÜÆÚÍû´ÓÄ¿µÄ×éÖ¯ÖлñÈ¡×î´óÀûÈ󡣡£¡£¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/syssphinx-fin8-backdoor
2¡¢ÑÅÊ«À¼÷칫˾Ôâµ½À´×ÔALPHVºÍClopµÄÁ½´ÎÀÕË÷¹¥»÷
¾ÝýÌå7ÔÂ19ÈÕ±¨µÀ£¬£¬£¬£¬£¬Á½¸öÀÕË÷ÍÅ»ïALPHVºÍClopÔÚÆäÍøÕ¾ÁгöÁËÃÀ×±¹«Ë¾ÑÅÊ«À¼÷ì¡£¡£¡£¡£¸Ã¹«Ë¾ÈÏ¿ÉÁËÆäÖеÄÒ»Æð£¬£¬£¬£¬£¬³Æ¹¥»÷Õß»ñµÃÁ˲¿·ÖϵͳµÄ»á¼ûȨÏÞ£¬£¬£¬£¬£¬²¢¿ÉÄÜÇÔÈ¡ÁËÊý¾Ý£¬£¬£¬£¬£¬ËûÃÇÒѽÓÄÉÐж¯²¢¹Ø±ÕÁËһЩϵͳ¡£¡£¡£¡£ClopËÆºõʹÓÃÁËMOVEit Transferƽ̨ÖеÄÎó²î»ñµÃ»á¼ûȨÏÞ£¬£¬£¬£¬£¬²¢Éù³ÆÇÔÈ¡ÁËÁè¼Ý131GBµÄÊý¾Ý¡£¡£¡£¡£±¾Öܶþ£¬£¬£¬£¬£¬ALPHVÒ²ÁгöÁËÑÅÊ«À¼÷죬£¬£¬£¬£¬²¢ÌåÏÖÈÔδÊÕµ½¸Ã¹«Ë¾µÄ»Ø¸´¡£¡£¡£¡£¹¥»÷Õß»¹³Æ£¬£¬£¬£¬£¬Ã»ÓмÓÃܹ«Ë¾µÄÈκÎϵͳ£¬£¬£¬£¬£¬µ«ÈôÊǸù«Ë¾²»Ì¸ÅУ¬£¬£¬£¬£¬ËûÃǽ«Í¸Â¶¸ü¶àÓйر»µÁÊý¾ÝµÄϸ½Ú£¬£¬£¬£¬£¬¿ÉÄÜ»áÓ°Ïì¿Í»§¡¢¹«Ë¾Ô±¹¤ºÍ¹©Ó¦ÉÌ¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/est-e-lauder-beauty-giant-breached-by-two-ransomware-gangs/
3¡¢VirusTotalй¶´ó×ÚÓû§ÐÅÏ¢Éæ¼°FBIºÍNSAµÈ»ú¹¹
ýÌå7ÔÂ18Èճƣ¬£¬£¬£¬£¬¶ñÒâÈí¼þɨÃèЧÀÍVirusTotalй¶Á˲¿·Ö×¢²á¿Í»§µÄÐÅÏ¢¡£¡£¡£¡£¸ÃÊÂÎñ×îÏÈÓɰµØÀû¡¶±ê×¼±¨¡·ºÍµÂ¹ú¡¶Ã÷¾µÖÜ¿¯¡·±¨µÀ£¬£¬£¬£¬£¬Ð¹Â¶Îļþ¾Þϸ½öΪ313 KB£¬£¬£¬£¬£¬°üÀ¨5600¸ö×¢²áÓû§µÄÐÅÏ¢£¬£¬£¬£¬£¬ÀýÈçÐÕÃû¡¢ÓʼþµØµãºÍ×éÖ¯µÈ¡£¡£¡£¡£ÊÜÓ°ÏìÓû§Éæ¼°ÃÀ¹úÍøÂç˾Á¡¢ÃÀ¹ú˾·¨²¿¡¢Áª°îÊÓ²ì¾ÖºÍÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¬£¬£¬£¬£¬ÉÐÓкÉÀ¼¡¢Ì¨ÍåºÍÓ¢¹úµÄ¹Ù·½»ú¹¹¡£¡£¡£¡£Google Cloud½²»°ÈËÌåÏÖ£¬£¬£¬£¬£¬ÆäÔ±¹¤ÔÚVirusTotalƽ̨ÉÏÎÞÒâ¼ä¹ûÕæÁËһС²¿·Ö¿Í»§×éÖÎÀíÔ±µÄÓʼþºÍ×éÖ¯Ãû³Æ¡£¡£¡£¡£µ±ËûÃÇÒâʶµ½Êý¾Ýй¶ºó£¬£¬£¬£¬£¬Á¬Ã¦É¾³ýÁËÕâЩÊý¾Ý¡£¡£¡£¡£
https://www.hackread.com/virustotal-data-leak-user-intel-agencies-data/
4¡¢Ñо¿Ö°Ô±·¢Ã÷ð³äSophosµÄÀÕË÷Èí¼þSophosEncrypt
¾Ý7ÔÂ18ÈÕ±¨µÀ£¬£¬£¬£¬£¬ÍøÂçÇå¾²¹©Ó¦ÉÌSophos±»ÃûΪSophosEncryptµÄÐÂÀÕË÷Èí¼þð³ä¡£¡£¡£¡£MalwareHunterTeam·¢Ã÷Á˸ÃÀÕË÷Èí¼þ£¬£¬£¬£¬£¬ÔçÏÈÒÔΪËüÊÇSophosºì¶ÓÑÝϰµÄÒ»²¿·Ö¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬Sophos X-OpsÍŶÓÌåÏÖ£¬£¬£¬£¬£¬ËûÃÇûÓн¨Éè¸Ã¼ÓÃܳÌÐò£¬£¬£¬£¬£¬²¢ÕýÔÚÊÓ²ì¸ÃÊÂÎñ¡£¡£¡£¡£¼ÓÃܳÌÐòÊÇÓÃRust¿ª·¢µÄ£¬£¬£¬£¬£¬±»ÃüÃûΪsophos_encrypt£¬£¬£¬£¬£¬¼ÓÃÜÎļþʱʹÓÃAES256-CBC¼ÓÃܺÍPKCS#7Ìî³ä¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Ëü»¹Äܸü¸ÄWindows×ÀÃæ±ÚÖ½£¬£¬£¬£¬£¬´óµ¨µØÏÔʾÁËËüËùð³äµÄSophos¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/cybersecurity-firm-sophos-impersonated-by-new-sophosencrypt-ransomware/
5¡¢Henry Ford HealthÔâµ½´¹ÂÚ¹¥»÷½ü17Íò»¼ÕßÐÅϢй¶
7ÔÂ17ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬Henry Ford Health͸¶ÆäÔâµ½´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂ168000Ãû»¼ÕßµÄÐÅϢй¶¡£¡£¡£¡£ÊÜÓ°Ï컼ÕßÔÚ±¾ÖÜÒ»±»¼û¸æ£¬£¬£¬£¬£¬¹¥»÷ÕßÓÚ3ÔÂ30ÈÕ»ñµÃÁËÆóÒµµç×ÓÓʼþÕÊ»§µÄ»á¼ûȨÏÞ¡£¡£¡£¡£µ«¸Ã»ú¹¹ºÜ¿ì·¢Ã÷ÁËÕâÖÖ»á¼û¡£¡£¡£¡£ÊÜÓ°ÏìµÄÓʼþÖаüÀ¨²¿·Ö»¼ÕßÐÅÏ¢£¬£¬£¬£¬£¬ÕâÊÇÔÚ5ÔÂ16ÈÕ·¢Ã÷µÄ¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢¿ÉÄܰüÀ¨ÐÕÃû¡¢ÐÔ±ð¡¢ÄêËê¡¢»¯ÑéЧ¹û¡¢ÊÖÊõÀàÐÍ¡¢Õï¶Ï¡¢Ò½ÁƼͼ±àºÅºÍÄÚ²¿¸ú×Ù±àºÅµÈ¡£¡£¡£¡£¸Ã»ú¹¹³ÆÆäÕýÔÚÔöÇ¿Çå¾²²½·¥²¢ÎªÔ±¹¤Ìṩ½øÒ»²½Åàѵ¡£¡£¡£¡£
https://www.clickondetroit.com/news/local/2023/07/17/henry-ford-health-confirms-data-breach-affecting-168000-patients/
6¡¢Check PointÐû²¼2023ÄêQ2Æ·ÅÆÍøÂç´¹ÂڻµÄ±¨¸æ
7ÔÂ18ÈÕ£¬£¬£¬£¬£¬Check PointÐû²¼ÁË2023ÄêQ2Æ·ÅÆÍøÂç´¹ÂڻµÄÆÊÎö±¨¸æ¡£¡£¡£¡£2023ÄêQ2£¬£¬£¬£¬£¬¿Æ¼¼¹«Ë¾Î¢ÈíµÄÅÅÃûÉÏÉý£¬£¬£¬£¬£¬´ÓQ1µÄµÚÈýλԾÉýÖÁQ2µÄ°ñÊ×£¬£¬£¬£¬£¬Õ¼ËùÓÐÆ·ÅÆ´¹ÂÚ¹¥»÷µÄ29%¡£¡£¡£¡£Æä´ÎÊÇGoogle£¨19.5%£©ºÍApple£¨5.2%£©¡£¡£¡£¡£¾ÍÐÐÒµ¶øÑÔ£¬£¬£¬£¬£¬¿Æ¼¼ÐÐÒµ±»Ã°³ä×î¶à£¬£¬£¬£¬£¬Æä´ÎÊÇÒøÐкÍÉ罻ýÌåÍøÂ磬£¬£¬£¬£¬ÀýÈçÅÅÃûµÚËĵĸ»¹úÒøÐÐ(4.2%)£¬£¬£¬£¬£¬ÒÔ¼°½ôËæØÊºóµÄÑÇÂíÑ·(4%)ºÍÎÖ¶ûÂê(3.9%)¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬Check Point»¹ÁгöÁ˲¿·Ö´¹ÂÚ¹¥»÷µÄʾÀý¡£¡£¡£¡£
https://blog.checkpoint.com/security/microsoft-dominates-as-the-most-impersonated-brand-for-phishing-scams-in-q2-2023/