ÒÁÀÊ×î´óµÄ¸ÖÌúÉú²úÉÌKSC³ÆÆä±»¹¥»÷µ¼ÖÂÔËÓª»î¶¯ÖжÏ

Ðû²¼Ê±¼ä 2022-06-28

1¡¢ÒÁÀÊ×î´óµÄ¸ÖÌúÉú²úÉÌKSC³ÆÆä±»¹¥»÷µ¼ÖÂÔËÓª»î¶¯ÖжÏ


¾Ý6ÔÂ28ÈÕ±¨µÀ  £¬ÒÁÀÊ×î´óµÄ¸ÖÌúÉú²úÉÌKhouzestan Steel Company(KSC)È·ÈÏÆäÔâµ½ÁËÍøÂç¹¥»÷¡£¹¥»÷·¢ÉúÔÚ±¾ÖÜÒ»  £¬ÆäʱÆäÍøÕ¾ÎÞ·¨·ÃÎÊ  £¬¸Ã¹«Ë¾Á¢¿ÌÖжÏÁËÔËÓª¡£ÆäÊ×ϯִÐйÙÉù³ÆËûÃÇÒÑÀֳɵÖÓù´Ë´Î¹¥»÷  £¬ÊÜÓ°ÏìµÄÍøÕ¾½«ºÜ¿ì»Ö¸´²¢ÖØÐÂÉÏÏß¡£È»¶ø  £¬ÒÁÀʵ±µØÃ½ÌåJamaranÌåÏÖ  £¬Õâ´Î¹¥»÷ûÓÐÀÖ³É  £¬ÊÇÒòΪµ±Ëü·¢Éúʱ  £¬¹¤³§ÓÉÓÚÍ£µç¶øÎÞ·¨ÔË×÷¡£


https://www.hackread.com/iran-largest-steel-producer-hit-by-cyberattack/


2¡¢ÎÚ¿ËÀ¼µÄµçÐÅÔËÓªÉ̺͹©Ó¦ÉÌÔâµ½DarkCrystal RATµÄ¹¥»÷


ÎÚ¿ËÀ¼Õþ¸®¼ÆËã»úÓ¦¼±ÏìӦС×é(CERT-UA)ÔÚ6ÔÂ24ÈÕÐû²¼Í¨¸æ  £¬½ÒʾÁËDarkCrystal RATÕë¶ÔÎÚ¿ËÀ¼µçÐÅÔËÓªÉ̵ĶñÒâÈí¼þ»î¶¯¡£´Ë´Î»î¶¯ÀûÓÃÁËÒÔ¡°Ãâ·ÑµÍ¼¶Ö´·¨Ô®Öú¡±ÎªÖ÷ÌâµÄÀ¬»øÓʼþ  £¬¼°¸½¼þ¡°Ê§×Ù¾üÈ˼ÒÍ¥³ÉÔ±µÄÐж¯Ëã·¨LegalAid.rar¡±¡£RARÎĵµ°üÂÞAlgorithm_LegalAid.xlsm  £¬µ±´ò¿ªÎĵµ²¢¼¤»îºêʱ  £¬½«Ö´ÐÐPowerShellÃüÁî  £¬È»ºóÏÂÔØ²¢ÔËÐÐ.NETÒýµ¼¼ÓÔØ·¨Ê½MSCommonll.exe  £¬ËüÓÖ»áÏÂÔØ²¢ÔËÐжñÒâÈí¼þDarkCrystal RAT¡£Æ¾¾ÝÊÕ¼þÈ˵ĵØÖ·ºÍÓò¹ÜÀíDarkCrystal RAT  £¬Ñо¿ÈËÔ±ÍÆ¶Ï¹¥»÷Ä¿±êÊÇÎÚ¿ËÀ¼µÄµçÐÅÔËÓªÉ̺͹©Ó¦ÉÌ¡£


https://securityaffairs.co/wordpress/132651/malware/cert-ua-darkcrystal-rat-attacks.html


3¡¢°ÍÎ÷ÁãÊÛÉÌFast ShopÔâµ½¹¥»÷ºóÏßÉÏÉ̳ÇÔÝʱ¹Ø±Õ


¾ÝýÌå6ÔÂ24ÈÕ±¨µÀ  £¬°ÍÎ÷×î´óµÄÁãÊÛÉÌÖ®Ò»Fast ShopÔâµ½¹¥»÷  £¬µ¼ÖÂÍøÂçÖжϲ¢ÔÝʱ¹Ø±ÕÔÚÏßÉ̵ê¡£¹¥»÷·¢ÉúÔÚÉÏÖÜÈý  £¬Ó°ÏìÁ˸ù«Ë¾µÄ¹Ù·½ÍøÕ¾¡¢Òƶ¯Ó¦Ó÷¨Ê½ºÍÔÚÏß¶©¹ºÏµÍ³  £¬²¢Î´Ó°ÏìʵÌåµê¡£´ËÍâ  £¬¹¥»÷Õß»¹ÈëÇÖÁ˸ù«Ë¾µÄTwitterÕË»§  £¬·¢ÎijÆËûÃÇ·ÃÎÊÁËFast ShopÔÚAWS¡¢Azure¡¢GitLabºÍIBMÔÆÉϵÄÊý¾Ý¿â  £¬²¢ÇÔÈ¡ÁËÍøÕ¾ºÍÓ¦Ó÷¨Ê½µÄÔ´´úÂë  £¬ÒÔ¼°Óû§ºÍÆóÒµÊý¾Ý¡£Fast Shop»ØÓ¦ÁËÕâһ˵·¨  £¬ÌåÏÖËûÃǵÄÊý¾Ý²¢Î´±»Ð¹Â¶¡£


https://therecord.media/brazilian-retail-giant-confirms-cyberattack-after-extortion-group-takes-over-twitter-account/


4¡¢AhnLab·¢ÏÖÀûÓðæÈ¨ÇÖȨ¾¯¸æÓʼþ·Ö·¢LockBitµÄ»î¶¯


AhnLabÔÚ6ÔÂ24ÈÕÐû²¼³ÂËß  £¬ÏêÊöÁËÀûÓðæÈ¨ÇÖȨ¾¯¸æÓʼþ·Ö·¢LockBitµÄ»î¶¯¡£ÓʼþÖ¸³öÊÕ¼þÈËÔÚδ¾­´´×÷ÕßÐí¿ÉµÄÇé¿öÏÂʹÓÃÁËýÌåÎļþ  £¬ÐèÒªÏÂÔØ²¢´ò¿ª¸½¼þÒÔ¼ì²ìÇÖȨÄÚÈÝ¡£¸½¼þÖаüÂÞÒ»¸öʹÓÃPDFÎļþͼ±êαװµÄ¿ÉÖ´ÐÐÎļþ  £¬µ«Êµ¼ÊÉÏÊÇNSIS°²×°·¨Ê½¡£¼ì²ìnsi½Å±¾ÏêϸÐÅÏ¢  £¬Ëü»á½âÂëÊý¾ÝÎļþ¡°162809383¡±²¢Í¨¹ýµÝ¹éºÍ×¢ÈëÖ´ÐжñÒâ»î¶¯¡£µ±Ä¿±ê´ò¿ªËùνµÄPDFÎļþºó  £¬ÆäÉ豸»á±»ÀÕË÷Èí¼þLockBit 2.0¼ÓÃÜ¡£


https://asec.ahnlab.com/en/35822/


5¡¢CafePressÒòÑÚ¸Ç2300Íò¿Í»§Êý¾Ýй¶Ê¼þ±»·£¿î50ÍòÃÀÔª


ýÌå6ÔÂ24ÈÕ³Æ  £¬ÃÀ¹úÁª°îóÒ×ίԱ»á(FTC)ÒÑÔðÁîCafePressµÄǰËùÓÐÕßResidual Pumpkin EntityÖ§¸¶500000ÃÀÔªµÄ·£¿î¡£Ô­ÒòÊÇËüÑÚ¸ÇÁËÓ°ÏìÁè¼Ý2300Íò¿Í»§µÄÊý¾Ýй¶Ê¼þ  £¬¶øÇÒδÄܱ £»¤ËûÃǵÄÊý¾Ý¡£¸Ã»ú¹¹³Æ  £¬Residual Pumpkin EntityÒÔ´¿Îı¾ÐÎʽ´æ´¢Á˿ͻ§µÄÉç»áÄþ¾²ºÅÂëºÍÃÜÂëÖØÖôð°¸  £¬¶øÇÒ³¬³öÁËÐëÒªµÄʱ¼ä¡£´ËÍâ  £¬¸Ã¹«Ë¾Ò²Î´ÄܽÓÄÉÓÐЧµÄ± £»¤´ëÊ©²¢¶ÔÄþ¾²Ê¹Ê×÷³ö·´Ó³  £¬ÔÚÆä·þÎñÆ÷±»¶à´ÎÈëÇÖºó  £¬ÊÔͼÑÚ¸ÇÒò²»Í×µÄÄþ¾²¼ÆÄ±¶øµ¼ÖµÄÖØ´óÊý¾Ýй¶Ê¼þ¡£


https://www.bleepingcomputer.com/news/security/cafepress-fined-500-000-for-breach-affecting-23-million-users/


6¡¢CybleÅû¶´´½¨¶ñÒâLNKµÄй¤¾ßQuantumµÄ¼¼Êõϸ½Ú


6ÔÂ22ÈÕ  £¬CybleÅû¶ÁË´´½¨¶ñÒâLNKµÄй¤¾ßQuantumµÄ¼¼Êõϸ½Ú¡£¸Ã¶ñÒâÈí¼þ¾ßÓÐUACÈÆ¹ý¡¢Windows SmartscreenÈÆ¹ý¡¢ÔÚµ¥¸öLNKÎļþÉϼÓÔØ¶à¸öpayload¡¢Ö´ÐкóÒþ²Ø¡¢Æô¶¯ºÍÑÓ³ÙÖ´Ðеȹ¦Ð§¡£´ËÍâ  £¬¿ª·¢ÕßÉù³ÆÊ¹ÓÃQuantumÉú³ÉµÄÎļþÊÇ100% FUD¡£ÔÚÒ°ÀûÓøöñÒâÈí¼þµÄ×îÔçÑù±¾¿ÉÒÔ×·Ëݵ½5ÔÂ24ÈÕ  £¬Æäαװ³ÉÎÞº¦µÄÎı¾Îļþtest.txt.lnk¡£¾ÝϤ  £¬QuantumÓ볯ÏʵÄLazarusÓйØÁª  £¬±ÈÁ¦Á½ÕßʹÓõĽű¾ºó  £¬·¢ÏÖÈ¥»ìÏýÑ­»·ºÍ±äÁ¿³õʼ»¯ÊÇÏàͬµÄ¡£


https://blog.cyble.com/2022/06/22/quantum-software-lnk-file-based-builders-growing-in-popularity/