Ô¼µ©AbdaliÒ½ÔºÔâµ½RhysidaµÄ¹¥»÷±»ÀÕË÷10 BTC

Ðû²¼Ê±¼ä 2023-12-27
1¡¢Ô¼µ©AbdaliÒ½ÔºÔâµ½RhysidaµÄ¹¥»÷±»ÀÕË÷10 BTC


¾Ý12ÔÂ26ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬ÀÕË÷ÍÅ»ïRhysida½«Ô¼µ©µÄÒ»¼ÒÒ½ÔºAbdali HospitalÌí¼Óµ½ÆäTorÍøÕ¾ÖС£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÐû²¼Á˱»µÁÎļþµÄͼƬ×÷Ϊ¹¥»÷Ö¤¾Ý£¬£¬£¬ £¬£¬£¬°üÀ¨Éí·ÝÖ¤ºÍÌõÔ¼µÈ¡£¡£¡£¡£¡£ ¡£¡£Í¬Ê±£¬£¬£¬ £¬£¬£¬Ëü»¹Éù³ÆÇÔÈ¡ÁË´ó×ÚÃô¸ÐÊý¾Ý£¬£¬£¬ £¬£¬£¬²¢ÒÔ10 BTCµÄ¼ÛÇ®¾ÙÐÐÅÄÂô¡£¡£¡£¡£¡£ ¡£¡£ÓëÒÔÍùÒ»Ñù£¬£¬£¬ £¬£¬£¬RhysidaÍýÏ뽫±»µÁÊý¾Ý³öÊÛ¸øÎ¨Ò»µÄÂò¼Ò£¬£¬£¬ £¬£¬£¬²¢½«ÔÚͨ¸æÐû²¼ºóµÄÆßÌìÄÚ¹ûÕæÕâЩÊý¾Ý¡£¡£¡£¡£¡£ ¡£¡£Rhysida×Ô½ñÄê5ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬ £¬£¬£¬Æ¾Ö¤ÆäTorÍøÕ¾Òѹ¥»÷ÁËÖÁÉÙ62¼Ò¹«Ë¾¡£¡£¡£¡£¡£ ¡£¡£


https://securityaffairs.com/156430/cyber-crime/rhysida-ransomware-abdali-hospital-jordan.html


2¡¢FACCTÅû¶Cloud AtlasÕë¶Ô¶íÂÞ˹ÆóÒµµÄ´¹ÂÚ¹¥»÷


ýÌå12ÔÂ25Èճƣ¬£¬£¬ £¬£¬£¬Group-IBµÄ×ÔÁ¦ÍøÂçÇå¾²¹«Ë¾FACCTÅû¶ÁËCloud AtlasÕë¶Ô¶íÂÞ˹ÆóÒµµÄ´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£Cloud AtlasÊÇÒ»¸öȪԴ²»Ã÷µÄÌØ¹¤ÍŻ£¬£¬ £¬£¬£¬ÖÁÉÙ´Ó2014Äê×îÏÈ»îÔ¾¡£¡£¡£¡£¡£ ¡£¡£Æä×îеÄɱÉËÁ´Í¨¹ýRTFÄ£°å×¢ÈëÀÖ³ÉʹÓÃÁËCVE-2017-11882£¬£¬£¬ £¬£¬£¬ÎªÈÏÕæÏÂÔØºÍÔËÐлìÏýHTAÎļþµÄshellcodeÆÌƽÁËõè¾¶¡£¡£¡£¡£¡£ ¡£¡£¶ñÒâHTMLÓ¦ÓÃËæºóÆô¶¯Visual Basic¾ç±¾(VBS)Îļþ£¬£¬£¬ £¬£¬£¬ÕâЩÎļþ×îÖÕÈÏÕæ´ÓÔ¶³ÌЧÀÍÆ÷¼ìË÷²¢Ö´ÐÐδ֪µÄVBS´úÂë¡£¡£¡£¡£¡£ ¡£¡£


https://thehackernews.com/2023/12/cloud-atlas-spear-phishing-attacks.html


3¡¢Group-IB³Æ½üÆÚð³ä¿ìµÝ¹«Ë¾µÄ´¹Âڻ¼¤Ôö34%


Group-IBÔÚ12ÔÂ21Èճƣ¬£¬£¬ £¬£¬£¬ÔÚÊ¥µ®½Úǰ¼¸ÖÜ·¢Ã÷ð³ä¿ìµÝµÄ´¹ÂÚÍøÕ¾ÊýÄ¿¼±¾çÔöÌí¡£¡£¡£¡£¡£ ¡£¡£Group-IBµÄÅÌËã»úÓ¦¼±ÏìӦС×é(CERT-GIB)ÔÚ12ÔµÄǰ10Ìì·¢Ã÷ÁË587¸ö¿´ËÆÕýµ±ÓÊÕþÔËÓªÉ̺ͿìµÝ¹«Ë¾µÄÍøÕ¾£¬£¬£¬ £¬£¬£¬±È11ÔµÄ×îºó10ÌìÔöÌíÁË34%¡£¡£¡£¡£¡£ ¡£¡£×ÜÌå¶øÑÔ£¬£¬£¬ £¬£¬£¬×Ô11Ô³õÒÔÀ´£¬£¬£¬ £¬£¬£¬CERT-GIB¼ì²âµ½1539¸ö´ËÀàÍøÕ¾£¬£¬£¬ £¬£¬£¬ÆäÖдó´ó¶¼¶¼Õë¶ÔµÂ¹ú£¨18%£©¡¢Î÷°àÑÀ£¨13%£©¡¢²¨À¼£¨14%£©ºÍÓ¢¹ú£¨4%£©µÈ¹ú¡£¡£¡£¡£¡£ ¡£¡£


https://www.group-ib.com/media-center/press-releases/christmas-fake-deliveries-scam/


4¡¢Blink MobilityÊý¾Ý¿âÉèÖùýʧй¶2Íò¶àÓû§ÐÅÏ¢


¾ÝýÌå12ÔÂ21ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬×ܲ¿Î»ÓÚÂåÉ¼í¶µÄµç¶¯Æû³µ¹²ÏíÌṩÉÌBlink MobilityµÄÒ»¸öMongoDBÊý¾Ý¿âÉèÖùýʧ¡£¡£¡£¡£¡£ ¡£¡£Ëæºó£¬£¬£¬ £¬£¬£¬ÆäÔªÊý¾Ý±»ËÑË÷ÒýÇæ±àÈëË÷Òý£¬£¬£¬ £¬£¬£¬²¢ÓÚ10ÔÂ17ÈÕ±»CybernewsÑо¿Ö°Ô±·¢Ã÷¡£¡£¡£¡£¡£ ¡£¡£ÊÓ²ìÏÔʾ£¬£¬£¬ £¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨Áè¼Ý22000ÃûÓû§ºÍ181000Ìõ¼Í¼£¬£¬£¬ £¬£¬£¬ÆäÖд󲿷ÖÓëÆû³µ×âÁÞÓйØ£¬£¬£¬ £¬£¬£¬ÀýÈçµç»°ºÅÂë¡¢ÓʼþµØµã¡¢¼ÓÃÜÃÜÂë¡¢×¢²áÈÕÆÚ¡¢×°±¸ÐÅÏ¢ºÍ×°±¸ÁîÅÆÒÔ¼°¶©ÔĺÍ×âÁÞ³µÁ¾µÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£ÏÖÔÚ£¬£¬£¬ £¬£¬£¬¹ûÕæµÄÊý¾Ý¿âÒѱ»±£»£»£»£»£»£» £»¤ÆðÀ´¡£¡£¡£¡£¡£ ¡£¡£


https://securityaffairs.com/156241/security/blink-mobility-data-leak.html


5¡¢CorvusÐû²¼11Ô·ÝÀÕË÷¹¥»÷µÄÌ¬ÊÆµÄÆÊÎö±¨¸æ


12ÔÂ25ÈÕ±¨µÀ³Æ£¬£¬£¬ £¬£¬£¬Corvus InsuranceÐû²¼±¨¸æ£¬£¬£¬ £¬£¬£¬11Ô·ÝÀÕË÷ÍÅ»ïÁгöµÄ±»¹¥»÷Ä¿µÄÊýÄ¿µÖ´ïÁËÓÐÊ·ÒÔÀ´µÄ×î¸ß¼Í¼¡£¡£¡£¡£¡£ ¡£¡£±¨¸æÖ¸³ö£¬£¬£¬ £¬£¬£¬11ÔÂÓÐ484¸öеı»¹¥»÷Ä¿µÄÐû²¼µ½×ßÂ©ÍøÕ¾£¬£¬£¬ £¬£¬£¬Õâ½Ï10Ô·ÝÔöÌí39.08%£¬£¬£¬ £¬£¬£¬½Ï2022Äê11ÔÂͬ±ÈÔöÌí110.43%¡£¡£¡£¡£¡£ ¡£¡£Æ¾Ö¤CorvusµÄÊý¾Ý£¬£¬£¬ £¬£¬£¬11Ô·ݵķåÖµ²¿·Ö¹éÒòÓÚLockBit»î¶¯µÄËÕÐÑ£¬£¬£¬ £¬£¬£¬Æä¹¥»÷ÁË121¸öÄ¿µÄ£¬£¬£¬ £¬£¬£¬Æä´ÎÊÇPLAY¡¢AlphVM¡¢BlackBastaºÍ8Base¡£¡£¡£¡£¡£ ¡£¡£CorvusÕ¹Íû£¬£¬£¬ £¬£¬£¬Æ¾Ö¤ÀúÊ·¼¾½ÚÐÔÊý¾Ý£¬£¬£¬ £¬£¬£¬12Ô½«¼á³Öͬ±ÈÔöÌí£¬£¬£¬ £¬£¬£¬µ«ºÜ¿ÉÄÜÎÞ·¨ÓöÉÏ11Ô·ݵÄÊý×Ö¡£¡£¡£¡£¡£ ¡£¡£


https://www.infosecurity-magazine.com/news/ransomware-victims-record-november/


6¡¢FortiGuardÐû²¼¹ØÓÚBandookбäÌåµÄÆÊÎö±¨¸æ


12ÔÂ21ÈÕ£¬£¬£¬ £¬£¬£¬FortiGuardÐû²¼¹ØÓÚBandookбäÌåµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£ ¡£¡£BandookÊÇÒ»ÖÖÔ¶³Ì»á¼ûľÂí£¬£¬£¬ £¬£¬£¬×Ô2007ÄêÊ״α»¼ì²âµ½ÒÔÀ´Ò»Ö±ÔÚÒ»Ö±Éú³¤¡£¡£¡£¡£¡£ ¡£¡£FortiGuardÔÚ10Ô·¢Ã÷ÁËÒ»ÖÖͨ¹ýPDFÎļþÈö²¥µÄÐÂBandook±äÌå¡£¡£¡£¡£¡£ ¡£¡£´ËPDFÎļþ°üÀ¨Ò»¸öËõ¶ÌµÄURL£¬£¬£¬ £¬£¬£¬¿ÉÏÂÔØÊÜÃÜÂë±£»£»£»£»£»£» £»¤µÄ.7zÎļþ¡£¡£¡£¡£¡£ ¡£¡£Ä¿µÄʹÓÃPDFÎļþÖеÄÃÜÂëÌáÈ¡¶ñÒâÈí¼þºó£¬£¬£¬ £¬£¬£¬¶ñÒâÈí¼þ»á½«Æäpayload×¢Èëµ½msinfo32.exeÖС£¡£¡£¡£¡£ ¡£¡£¸Ã±¨¸æ¼òÒªÏÈÈÝÁËBandookµÄÐÐΪ£¬£¬£¬ £¬£¬£¬ÌṩÓйظñäÌåµÄÐÞ¸ÄÔªËØµÄÏêϸÐÅÏ¢£¬£¬£¬ £¬£¬£¬²¢·ÖÏíÁËÆäC2ͨѶ»úÖÆµÄһЩʾÀý¡£¡£¡£¡£¡£ ¡£¡£


https://www.fortinet.com/blog/threat-research/bandook-persistent-threat-that-keeps-evolving