LockBitÍÅ»ïÉù³Æ½«Ðû²¼º«¹ú¹ú¼ÒË°Îñ¾ÖµÄÊý¾Ý
Ðû²¼Ê±¼ä 2023-04-031¡¢LockBitÍÅ»ïÉù³Æ½«Ðû²¼º«¹ú¹ú¼ÒË°Îñ¾ÖµÄÊý¾Ý
¾ÝýÌå4ÔÂ1ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïLockBit³ÆÆäÈëÇÖÁ˺«¹ú¹ú¼ÒË°Îñ¾Ö¡£3ÔÂ29ÈÕ£¬LockBitÍŻォ¸Ã»ú¹¹Ìí¼Óµ½ÆäÍøÕ¾£¬²¢Ðû²¼½«ÓÚ4ÔÂ1ÈÕ֮ǰÐû²¼±»µÁÊý¾Ý¡£¹ú¼ÒË°Îñ¾Ö£¨NTS£©×÷Ϊ²ÆÕþ²¿µÄÒ»¸öÍⲿ×éÖ¯ÓÚ1966Äê3ÔÂ3ÈÕ½¨Á¢£¬Ö÷ÒªÂôÁ¦ÄÚ²¿Ë°ÊÕÆÀ¹ÀºÍÕ÷ÊÕ¡£½ØÖÁ4ÔÂ1ÈÕ£¬¸ÃÍÅ»ïÉÐδÐû²¼±»µÁÊý¾Ý¡£µ«Èç¹û¹¥»÷ÊÇÕæʵµÄ£¬Õ⽫¶Ôº«¹ú¹«ÃñµÄÒþ˽ºÍÄþ¾²×é³ÉÑÏÖØÍþв¡£
https://securityaffairs.com/144342/cyber-crime/lockbit-south-korean-national-tax-service.html
2¡¢TMX Finance¼°Æä×Ó¹«Ë¾Ô¼480Íò¸ö¿Í»§µÄÊý¾Ýй¶
ýÌå3ÔÂ31Èճƣ¬TMX Finance¼°Æä×Ó¹«Ë¾TitleMax¡¢TitleBucksºÍInstaLoanÅû¶ÁËÒ»ÆðÊý¾Ýй¶Ê¼þ£¬Éæ¼°4822580¸ö¿Í»§µÄÊý¾Ý¡£Õâ¼Ò¼ÓÄôó½ðÈÚ¹«Ë¾ÌåÏÖ£¬ºÚ¿ÍÔÚ2022Äê12ÔÂÉÏÑ®ÈëÇÖÁËÆäϵͳ£¬µ«ËûÃÇÖ±µ½2023Äê2ÔÂ13Èղŷ¢ÏÖÁ˹¥»÷»î¶¯¡£3ÔÂ1ÈÕÍê³ÉÄÚ²¿ÊÓ²ìºó£¬TMX·¢ÏÖ¹¥»÷ÕßÔÚ2023Äê2ÔÂ3ÈÕÖÁ14ÈÕÇÔÈ¡ÁË¿Í»§µÄÐÅÏ¢£¬°üÂÞÐÕÃû¡¢»¤Õպš¢¼ÝÕÕºÅÂ롢˰ºÅ¡¢Éç»áÄþ¾²ºÅÂëºÍ½ðÈÚÕË»§ÐÅÏ¢µÈ¡£ÏÖÔÚ£¬¸Ã¹«Ë¾ÊµÊ©Á˶˵㱣»¤ºÍ¼à¿Ø£¬ÖØÖÃÁËËùÓÐÔ±¹¤ÕÊ»§ÃÜÂ룬²¢½«ÎªÓû§ÌṩExperianΪÆÚ12¸öÔµÄÉí·Ý±£»¤·þÎñ¡£
https://www.bleepingcomputer.com/news/security/consumer-lender-tmx-discloses-data-breach-impacting-48-million-people/
3¡¢Ä£¿é»¯¹¤¾ß¼¯AlienFoxÇÔÈ¡¶à¸öÔÆ·þÎñÌṩÉÌƾ¾Ý
3ÔÂ30ÈÕ£¬SentinelLabs³ÆÆä·¢ÏÖÁËÒ»¸öÃûΪAlienFoxµÄй¤¾ß°ü£¬¿É±»ÓÃÓÚÈëÇÖµç×ÓÓʼþºÍÍøÂçÍйܷþÎñ¡£AlienFoxÊÇÄ£¿é»¯µÄ£¬´ó¶àÊý¹¤¾ß¶¼ÊÇ¿ªÔ´µÄ¡£¹¥»÷Õß¿ÉʹÓÃÆä´ÓLeakIXºÍSecurityTrailsµÈÄþ¾²É¨Ãèƽ̨ÊÕ¼¯ÅäÖôíÎóµÄÖ÷»úÁÐ±í¡£È»ºó£¬AlienFoxʹÓÃÊý¾ÝÌáÈ¡½Å±¾ÔÚÅäÖôíÎóµÄ·þÎñÆ÷ÖÐËÑË÷ÓÃÓÚ´æ´¢»úÃܵÄÅäÖÃÎļþ£¬ÀýÈçAPIÃÜÔ¿¡¢ÕÊ»§Æ¾¾ÝºÍÉí·ÝÑéÖ¤ÁîÅÆ¡£¸Ã¶ñÒâÈí¼þÄܹ»Õë¶Ô1and1¡¢AWS¡¢Bluemail¡¢ExotelºÍGoogle WorkspaceµÈÊ®¼¸¸öÔÆƽ̨¡£
https://www.sentinelone.com/labs/dissecting-alienfox-the-cloud-spammers-swiss-army-knife/
4¡¢WordPress²å¼þElementor ProÖеÄ©¶´Òѱ»ÀûÓÃ
¾Ý3ÔÂ31ÈÕ±¨µÀ£¬WordPress²å¼þElementor ProÖеÄ©¶´Òѱ»»ý¼«ÀûÓá£Elementor ProÊÇÒ»¸öWordPressÒ³Ãæ¹¹½¨Æ÷²å¼þ£¬±»Áè¼Ý1100Íò¸öÍøվʹÓ᣸鶴ӰÏìÁËv3.11.6¼°¸üµÍ°æ±¾£¬¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÀûÓÃÆä¸ü¸ÄÍøÕ¾ÉèÖã¬ÉõÖÁÍêÈ«½Ó¹ÜÍøÕ¾¡£Äþ¾²¹«Ë¾PatchStack³ÂË߳ƣ¬ºÚ¿ÍÕýÔÚ»ý¼«ÀûÓô˲å¼þ©¶´½«·ÃÎÊÕßÖض¨Ïòµ½¶ñÒâÓò£¨¡°away[.]trackersline[.]com¡±£©»ò½«ºóÃÅÉÏ´«µ½±»ÈëÇÖµÄÍøÕ¾¡£ÕâЩ¹¥»÷ÖÐÉÏ´«µÄºóÃÅÃûΪwp-resortpark.zip¡¢wp-rate.php»òlll.zip¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-bug-in-elementor-pro-wordpress-plugin-with-11m-installs/
5¡¢ÎÚ¿ËÀ¼Ö´·¨²¿ÃÅ´þ²¶ÒÑÇÔÈ¡430ÍòÃÀÔªµÄµöÓãÍÅ»ï
ýÌå3ÔÂ31ÈÕ±¨µÀ³Æ£¬ÎÚ¿ËÀ¼ºÍ½Ý¿ËµÄÖ´·¨ÈËÔ±Ðͬ´þ²¶ÁËijµöÓãÍÅ»ïµÄ¼¸Ãû³ÉÔ±¡£¸ÃÍÅ»ïÕë¶Ô·¨¹ú¡¢Î÷°àÑÀ¡¢²¨À¼¡¢½Ý¿Ë¡¢ÆÏÌÑÑÀµÈÅ·ÖÞ¹ú¼Ò½¨Á¢ÁË100¶à¸öµöÓãÍøÕ¾£¬ÒÔµÍÓÚÊг¡¼ÛµÄÖÖÖÖÉÌƷΪÓÕ¶ü£¬ÓÕʹĿ±êÊäÈëÐÅÓÿ¨ÏêϸÐÅÏ¢À´Ö§¸¶Ðé¼Ù¶©µ¥£¬²¢ÀûÓÃÕâЩÐÅÏ¢´ÓÄ¿±êÕË»§ÖÐŲÓÃ×ʽð¡£ËûÃÇÒÑ´ÓÅ·ÖÞ1000¶à¸ö±»¹¥»÷Ä¿±êÄÇÀïÇÔÈ¡ÁËÁè¼Ý430ÍòÃÀÔª¡£Ä¿Ç°£¬ÒѾ¶ÔÏÓÒÉÈËÌáÆðÐÌÊÂËßËÏ£¬ËûÃÇ¿ÉÄÜÃæÁÙ×î¸ß12ÄêµÄ¼à½û¡£
https://securityaffairs.com/144279/cyber-crime/cyber-police-of-ukraine-cybercrime-gang.html
6¡¢Ñо¿ÍŶÓÅû¶RedGolfÀûÓúóÃÅKEYPLUGµÄ¹¥»÷»î¶¯
Recorded FutureÔÚ3ÔÂ30ÈÕÅû¶ÁËRedGolfÀûÓúóÃÅKEYPLUGµÄ¹¥»÷»î¶¯¡£RedGolfÖ÷ÒªÕë¶Ôº½¿Õ¡¢Æû³µ¡¢½ÌÓý¡¢Õþ¸®¡¢Ã½Ìå¡¢ÐÅÏ¢¼¼ÊõºÍ×Ú½ÌÏà¹ØµÄ×éÖ¯¡£Ñо¿ÈËÔ±³ýÁ˼ì²âµ½¸ÃÍÅ»ïÔÚ2021ÄêÖÁ2023ÄêʹÓõÄKEYPLUGÑù±¾ºÍ»ù´¡ÉèÊ©£¨´úºÅΪGhostWolf£©Í⣬»¹Ö¸³öÆäʹÓÃÁËCobaltStrikeºÍPlugXµÈÆäËü¹¤¾ß¡£¸ÃÄþ¾²¹«Ë¾»¹ÌåÏÖ£¬RedGolf½«¼ÌÐø¸ßÔËÓª½Ú×࣬²¢Ñ¸ËÙ½«ÃæÏòÍⲿµÄ¹«Ë¾É豸£¨VPN¡¢·À»ðǽºÍÓʼþ·þÎñÆ÷µÈ£©ÖеÄ©¶´ÎäÆ÷»¯£¬ÒÔ»ñµÃÄ¿±êÍøÂçµÄ³õʼ·ÃÎÊȨÏÞ¡£
https://www.recordedfuture.com/with-keyplug-chinas-redgolf-spies-on-steals-from-wide-field-targets