ÃÀ¹ú×î´ó²úȨ±£ÏÕ¹«Ë¾FNF±»AlphV¹¥»÷ϵͳÔÝʱ¹Ø±Õ

Ðû²¼Ê±¼ä 2023-11-27

1¡¢ÃÀ¹ú×î´ó²úȨ±£ÏÕ¹«Ë¾FNF±»AlphV¹¥»÷ϵͳÔÝʱ¹Ø±Õ


¾ÝýÌå11ÔÂ24ÈÕ±¨µÀ£¬ÃÀ¹ú×î´óµÄ²úȨ±£ÏÕ¹«Ë¾Fidelity National Financial(FNF)Ôâµ½AlphV(BlackCat) µÄ¹¥»÷¡£ÉÏÖÜÈý£¬AlphVÐû²¼ËûÃǹ¥»÷ÁËFNF£¬»¹½«FNFûÓн»Êê½ðµÄÔ­Òò¹é¾ÌÓÚMandiant¡£Ä¿Ç°£¬AlphVûÓÐÐû²¼ÈκιØÓÚ¹¥»÷µÄÖ¤Ã÷¡£FNFÍøÕ¾ÉÏҲûÓÐÈκμ£Ïó±íÃ÷´æÔÚÊý¾Ýй¶ÎÊÌ⣬µ«ÊÇËü¹Ø±ÕÁËÐí¶àÔÚÏß·þÎñ£¬²¢ÌåÏÖËûÃÇÖªµÀijЩϵͳÒѱ»·ÃÎÊ¡£


https://www.databreaches.net/fidelity-national-financial-ransomware-incident-impacts-real-estate-closings/


2¡¢Í¨ÓÃµçÆøµÄ·ÃÎÊȨÏ޺ʹóÁ¿Êý¾ÝÔÚºÚ¿ÍÂÛ̳±»³öÊÛ


¾Ý11ÔÂ25ÈÕ±¨µÀ£¬ÃÀ¹ú¿ç¹ú¹«Ë¾Í¨ÓÃµçÆø(GE)ÕýÔÚÊÓ²ìÆäÊý¾Ý±»µÁµÄÎÊÌâ¡£±¾ÔÂÔçЩʱºò£¬ºÚ¿ÍIntelBrokerÔÚ°µÍøÒÔ500ÃÀÔªµÄ¼Û¸ñ³öÊÛGEµÄ·ÃÎÊȨÏÞ¡£È»ºó£¬¹¥»÷ÕßÔٴη¢Ìû³Æ£¬ËûÃÇÏÖÔÚͬʱ³öÊÛÍøÂç·ÃÎÊȨÏÞ£¨SSHºÍSVNµÈ£©ºÍ±»µÁÊý¾Ý£¬ÆäÖб»µÁÊý¾Ý°üÂÞ´óÁ¿ÓëDARPAÏà¹ØµÄ¾üÊÂÐÅÏ¢¡¢Îļþ¡¢SQLÎļþºÍÎĵµµÈ¡£×÷Ϊй¶֤¾Ý£¬¹¥»÷Õß¹ûÈ»ÁËÊý¾Ý½ØÍ¼£¬°üÂÞGE AviationsµÄÒ»¸öÊý¾Ý¿â£¬Éæ¼°¾üÊÂÏîÄ¿µÄÐÅÏ¢¡£GEÌåÏÖÒÑ»ñϤ´Ëʼþ£¬²¢ÕýÔÚ½øÐÐÊӲ졣


https://www.bleepingcomputer.com/news/security/general-electric-investigates-claims-of-cyber-attack-data-theft/


3¡¢ITÌṩÉÌCTSÔâµ½ÀÕË÷¹¥»÷Ó¢¹úÊý°Ù¼ÒÂÉËùµÄÒµÎñÊÜÓ°Ïì


11ÔÂ24ÈÕ±¨µÀ³Æ£¬ÎªÓ¢¹úÂÉʦÊÂÎñËùÌṩÍйܷþÎñµÄÌṩÉÌ(MSP)CTSÔâµ½ÍøÂç¹¥»÷¡£Õâ¼ÒIT·þÎñÌṩÉÌÔÚÉÏÖÜÎåÐû²¼ÉùÃ÷³Æ£¬ËûÃÇÕýÔÚ¾­ÀúÒ»´Î·þÎñÖжÏ£¬Ó°ÏìÁËÏò²¿Ãſͻ§ÌṩµÄ·þÎñ¡£ËäÈ»CTSÉÐδ͸¶ÊÜÓ°Ïì¿Í»§µÄÊýÁ¿ºÍ¹¥»÷ÐÔÖÊ£¬µ«Ä¿Ç°µÄÐÅÏ¢±íÃ÷ÕâÊÇÒ»´ÎÀÕË÷¹¥»÷¡£µ±µØÃ½Ì屨µÀ£¬Ô¼80ÖÁ200¼ÒÂÉʦÊÂÎñËù¿ÉÄÜÊܵ½Ó°Ïì¡£ÔÚÕâÒ»ÖÜÀÓÉÓÚ·þÎñÖжÏ£¬ÈËÃÇÎÞ·¨¹ºÖûò³öÊÛ·¿²ú¡£¸Ã¹«Ë¾ÌåÏÖ£¬ÓÐÐÅÐÄÄܹ»»Ö¸´·þÎñ£¬µ«ÎÞ·¨È·¶¨¡°È«Ãæ»Ö¸´¡±µÄʱ¼ä¡£


https://therecord.media/uk-cyberattack-msp-cts-law-firms


4¡¢Äþ¾²»ú¹¹Åû¶LazarusÀûÓÃMagicLine4NX©¶´µÄ¹©Ó¦Á´¹¥»÷


ýÌå11ÔÂ25Èճƣ¬Äþ¾²»ú¹¹NCSCºÍNISÁªºÏÐû²¼Í¨¸æ³ÆLazarusÕýÔÚÀûÓÃMagicLine4NXÖеÄodayÖ´Ðй©Ó¦Á´¹¥»÷¡£MagicLine4NXÊÇÒ»¿îÄþ¾²ÈÏÖ¤Èí¼þ£¬¹¥»÷·¢ÉúÓÚ½ñÄê3Ô·Ý¡£¹¥»÷Á´Ê¼ÓÚË®¿Ó¹¥»÷£¬¹¥»÷ÕßÈëÇÖÁËÒ»¼ÒýÌåÍøÕ¾£¬²¢½«¶ñÒâ½Å±¾Ö²È뵽һƪÎÄÕÂÖУ¬ÕâЩ½Å±¾½öÕë¶ÔÌØ¶¨IP·¶Î§µÄ·ÃÎÊÕß¡£µ±Óû§Ê¹ÓÃMagicLine4NX·ÃÎʱ»Ñ¬È¾ÍøÕ¾Ê±£¬¶ñÒâ´úÂë¾Í»áÖ´ÐдӶøÍêÈ«¿ØÖÆÏµÍ³¡£Ëæºó£¬¹¥»÷ÕßÀûÓÃϵͳ©¶´´ÓÁªÍøµÄPCÉÏ·Ç·¨·ÃÎÊ·þÎñÆ÷£¬²¢ÀÄÓÃÁªÍøÏµÍ³µÄÊý¾Ýͬ²½¹¦Ð§½«¶ñÒâ´úÂëÁ÷´«µ½ÒµÎñ¶Ë·þÎñÆ÷£¬×îÖÕÖ¼ÔÚÇÔÈ¡ÐÅÏ¢¡£


https://securityaffairs.com/154765/apt/lazarus-magicline4nx-supply-chain-attack.html


5¡¢Granger Medical ClinicÔâµ½NoEscape¹¥»÷¾Ü¸¶Êê½ð


ýÌå11ÔÂ26ÈÕ±¨µÀ³Æ£¬ÀÕË÷ÍÅ»ïNoEscapeÓÚ11ÔÂ24ÈÕ½«ÓÌËûÖݵÄGranger Medical ClinicÌí¼Óµ½ÆäÍøÕ¾ÖС£¹¥»÷ÕßÉù³ÆÓµÓÐÁè¼Ý35GBµÄÊý¾Ý£¬°üÂÞ±£ÃÜЭÒéºÍºÏͬ¡¢NDA¡¢SSN¿¨¡¢É󼯡¢³ÂËß¡¢²ÆÕþ¡¢Êý¾Ý¿â¡¢Ô¤ËãºÍÒøÐÐÒµÎñµÈÏà¹ØÎļþ¡£×÷Ϊ֤¾Ý£¬NoEscape»¹ÌṩÁËÎļþÊ÷ºÍÆÁÄ»½ØÍ¼¡£Ì¸ÅÐËÆºõÆÆÁÑÁË£¬Granger¾ö¶¨²»¸¶¿î¡£NoEscapeÍþвÔÚ24СʱÄÚÖ§¸¶70ÍòÃÀÔªÊê½ð£¬·ñÔò½«¹ûÈ»ËùÓÐÊý¾Ý¡£Ñо¿ÈËÔ±ÔÚ25ÈÕ¼ì²é·¢ÏÖ£¬¹¥»÷ÕßÒѾ­Ð¹Â¶ÁËÁè¼Ý31 GBµÄÎļþ¡£


https://www.databreaches.net/ransomware-group-leaks-data-allegedly-from-granger-medical-clinic/


6¡¢Check Point·¢ÏÖʹÓÃSysJokerºóÃŹ¥»÷ÒÔÉ«ÁеĻ


11ÔÂ23ÈÕ£¬Check PointÅû¶ÁËʹÓÃSysJokerºóÃŹ¥»÷ÒÔÉ«ÁеĻ¡£SysJokerÓÚ2021Äê12ÔÂÊ״α»·¢ÏÖ£¬¸ÃºóÃÅÄܹ»Ñ¬È¾Windows¡¢macOSºÍLinuxϵͳ£¬Æäʱ·¢ÏÖµÄÊÇC++°æ±¾¡£Õë¶ÔÒÔÉ«ÁеĹ¥»÷ÖÐʹÓõİ汾ÊÇRust¿ª·¢µÄ£¬Õâ±íÃ÷¸Ã¶ñÒâÈí¼þÊÇÖØÐ¿ªÊ¼ÖØÐ´£¬ÓÚ½ñÄê10ÔÂ12ÈÕÊ×´ÎÌá½»µ½VirusTotal¡£´ËÍ⣬¸Ã¶ñÒâÈí¼þ½ÓÄÉËæ»ú˯Ãß¼ä¸ôºÍÅÓ´óµÄ×Ô½ç˵¼ÓÃÜ´úÂë×Ö·û´®À´Èƹý¼ì²âºÍ·ÖÎö¡£


https://research.checkpoint.com/2023/israel-hamas-war-spotlight-shaking-the-rust-off-sysjoker/