µÂ¹úµ·»ÙÈ«Çò×î´ó°µÍøHydra²¢²é»ñ2500ÍòÃÀÔªµÄBTC

°ä²¼¹¦·ò 2022-04-07

µÂ¹úµ·»ÙÈ«Çò×î´ó°µÍøHydra²¢²é»ñ2500ÍòÃÀÔªµÄBTC


4ÔÂ5ÈÕÐÇÆÚ¶þ£¬µÂ¹úÁª¹úÐÌʾ¯Ô±¾Ö(Bundeskriminalamt)°ä·¢³É¹¦µ·»ÙÁ˰µÍøHydra ¡£¸ÃÊг¡Ô¼ÓÐ19000¸ö×¢²áµÄÂô¼Ò£¬ÎªÈ«ÇòÖÁÉÙ1700Íò¿Í»§Ìṩ·þÎñ£¬¾Ý¹À¼ÆÆäÔÚ2020ÄêµÄ½»Ò×¶îΪ13.5ÒÚÃÀÔª£¬ÊÇÈ«Çò×î´óµÄ°µÍøÊг¡ ¡£µ÷²éÈËԱй©£¬ËûÃDz»½ö¹Ø¹ØÁËHydraÔڵ¹ú·þÎñÆ÷£¬»¹²é»ñÁ˼ÛÖµ543.3¸ö±ÈÌØ±Ò£¨¼ÛÖµ2500ÍòÃÀÔª£© ¡£Ä¿Ç°£¬HydraµÄÖ÷ÓòÃûºÍ±¸·ÝÓòÃû´¦ÓÚÍÑ»ú״̬£¬ÏÔʾÃýÎóÐÂÎÅ¡°502 Bad Gateway¡± ¡£


https://www.hackread.com/germany-russia-dark-web-market-hydra-seize-btc/


ÃÀ¹úÔËͨµÄÔÚÏßϵͳ³öÏÖ¹ÊÕϵ¼ÖÂÆäÈ«Çò·þÎñÖжÏ


¾ÝýÌå4ÔÂ2ÈÕ±¨Â·£¬ÃÀ¹úÔËͨµÄÈ«Çò·þÎñÖжÏÊýÓ×ʱ ¡£ÖжϲúÉúÔÚ4ÔÂ1ÈÕ£¬Óû§»ã±¨ÎÞ·¨µÇ¼ÆäÃÀ¹úÔËͨÕË»§¡¢ÎÞ·¨¸¶¿î»òµç»°ÁªÏµÃÀ¹úÔËͨµÄ¿Í·þ ¡£¸Ã¹«Ë¾ÔÚÆä¹ÙÍø°ä²¼¹«¸æ£¬³ÆÆä¡°Òâʶµ½¼¼ÊõÎÊÌ⡹ØýÔÚÓ°Ïìµç»°Ïß·¡¢ÔÚÏßÕË»§·þÎñºÍÃÀ¹úÔËÍ¨ÒÆ¶¯ÀûÓà ¡£×êÑÐÈËÔ±¾­¹ýÂŴβâÊÔºó´§¶È£¬¸ÃÎÊÌâ¿ÉÄÜÓëÃÀ¹úÔËͨ×î½üÍÆ³öµÄ¡°ËùÓÐÕÊ»§Ò»´ÎµÇ¼¡±Ö°ÄÜÓйØ£¬µ«ÕâÎÞ·¨Ú¹Ê͵绰·þÎñΪºÎÖжÏ ¡£Ä¿Ç°£¬ÖжÏÔ­ÒòÉв»Ã÷È·£¬ÄÚ²¿ÈËÊ¿³Æ²¢·ÇÔ´×ÔÍøÂç¹¥»÷ ¡£


https://www.bleepingcomputer.com/news/security/american-express-down-in-outage-users-report-login-and-payment-issues/


Î÷°àÑÀIberdrolaÔâµ½¹¥»÷й¶130Íò¿Í»§µÄÊý¾Ý


ýÌå4ÔÂ2Èճƣ¬Î÷°àÑÀÄÜÔ´¹«Ë¾Iberdrolaй¶ÁË130Íò¿Í»§µÄÓ×ÎÒÐÅÏ¢ ¡£¸Ã¹«Ë¾ÒÑ֤ʵ£¬ËûÃÇÔÚ3ÔÂ15ÈÕÔâµ½ÍøÂç¹¥»÷£¬ºÚ¿Í·¸·¨½Ó¼ûÁ˿ͻ§µÄÉí·ÝÖ¤ºÅÂë¡¢µØÖ·¡¢µç»°ºÅÂëºÍÓʼþµØÖ·µÈÐÅÏ¢ ¡£Iberdrola°µÊ¾£¬¸ÃÎÊÌâÒÑÔÚµ±Ìì±»½¨¸´£¬Æä³É¹¦×èÖ¹Á˽øÒ»²½µÄ¹¥»÷£¬µ«»¹ÊÇÌáÐѿͻ§°ÑÎÈÀûÓÃÕâЩÐÅÏ¢µÄ´¹µö»î¶¯ ¡£¾Ý³Æ£¬ÔÚͳһÌìÖУ¬ÂíµÂÀïµÄͨÇÚÌúÂ·ÍøÂçCercan¨ªas¡¢Î÷°àÑÀÒé»áºÍ¼¸¸öµØÓòµÄ»ú¹¹Ò²Ôâµ½Á˹¥»÷ ¡£


https://www.surinenglish.com/spain/cyberattack-iberdrola-accessed-20220401183800-nt.html


µÂ¹úNordex¶à¸ö·Ö¹«Ë¾µÄϵͳÒòÔâµ½ÈëÇÖ¶ø¹Ø¹Ø


ýÌå4ÔÂ4ÈÕ±¨Â·³Æ£¬µÂ¹ú·çÁ¦ÎÐÂÖ»úÔì×÷ÉÌNordexÔâµ½¹¥»÷ºó£¬¹Ø¹ØÁ˶à¸ö·Ö¹«Ë¾ºÍÒµÎñ²¿ÃŵÄϵͳ ¡£NordexÖØÒªÉè¼Æ¡¢Ôì×÷ºÍÏúÊÛ·çÁ¦ÎÐÂÖ»ú£¬2021ÄêµÄÏúÊÛ¶î¿¿½ü60ÒÚÃÀÔª£¬Ôڵ¹ú¡¢Öйú¡¢Ä«Î÷¸ç¡¢ÃÀ¹ú¡¢°ÍÎ÷¡¢Î÷°àÑÀºÍÓ¡¶ÈÉèÓй¤³§ ¡£¹¥»÷²úÉúÔÚ3ÔÂ31ÈÕ£¬Æä¼ì²âµ½¹¥»÷ºóÂíÉϽøÐÐÁËÏìÓ¦£¬¿Í»§¡¢Ô±¹¤µÈÀûÒæÓйØÕß¿ÉÄÜ»áÊܵ½¶à¸öITϵͳ¹Ø¹ØµÄÓ°Ïì ¡£NordexÔÚ±¾ÖÜһûÓлØÓ¦¹ØÓÚÆäÔËÓªÇé¿öµÄÆÀÂÛÒªÇó ¡£ 


https://therecord.media/german-wind-turbine-maker-shut-down-after-cyberattack/


MandiantÅû¶ºÚ¿ÍÍÅ»ïFIN7Ñݱä¹ý³ÌµÄ¾ßÌåÐÅÏ¢


4ÔÂ4ÈÕ£¬Mandiant°ä²¼Á˹ØÓÚ2021Äêµ×ÖÁ2022ËêÊ×FIN7ÔËÓª»î¶¯µÄ¾ßÌå¼¼Êõ»ã±¨ ¡£FIN7ÔÚÈëÇÖ¹ý³ÌÖгÖÐøÀûÓÃPowerShell£¬Ô̺¬ÔÚÒ»¸öкóÃÅPOWERPLANT£¬ÒÔ¼°ÔÚ¿ª·¢µÄBIRDWATCHÏÂÔØÆ÷µÄа汾CROWVIEWºÍFOWLGAZE ¡£FIN7µÄ³õʼ½Ó¼û¼¼ÊõÒѾ­¶àÑù»¯£¬³ýÁË´«Í³µÄ´¹µö¹¥»÷±í£¬»¹Í¨¹ýÈí¼þ¹©¸øÁ´ÈëÇÖºÍʹÓñ»µÁƾ֤ ¡£¶à¸öÀÕË÷»î¶¯ÓëFIN7ÓгÁµþ£¬Éæ¼°ÀÕË÷Èí¼þREVIL¡¢DARKSIDE¡¢BLACKMATTERºÍALPHV ¡£


https://www.mandiant.com/resources/evolution-of-fin7


Cyble°ä²¼Ð¶ñÒâÈí¼þBorat RATµÄÉî¶È·ÖÎö»ã±¨


CybleÔÚ3ÔÂ31ÈÕ°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þBorat RATµÄÉî¶È·ÖÎö»ã±¨ ¡£¿ª·¢ÕßÒÔÒ»²¿ÐþɫЦ¾çα¼Í¼Ƭ¡°Borat¡±µÄÃû×Ö¶¨Ãû¸ÃRAT£¬ÓëÆäËüRAT·ÖÆçµÄÊÇ£¬³ýÁ˳£¼ûµÄRATÖ°ÄÜÖ®±í£¬Borat»¹Ïò¹¥»÷ÕßÌṩÀÕË÷Èí¼þºÍDDOS·þÎñ£¬½øÒ»²½À©´óÁ˶ñÒâÈí¼þµÄÖ°ÄÜ ¡£Borat RAT×÷Ϊһ¸ö°üÌṩ£¬ÆäÖÐÔ̺¬¹¹½¨Æ÷µÄ¶þ½øÔìÎļþ¡¢Ö§³ÖÄ£¿é¡¢·þÎñÆ÷Ö¤ÊéµÈ£¬ÊǼ¯Ô¶³Ì½Ó¼ûľÂí¡¢¼äµýÈí¼þºÍÀÕË÷Èí¼þµÄÓÚÒ»ÌåµÄ׳´ó×éºÏ£¬¶ÔÖ¸±êÓµÓÐÈý³ÁÍþв ¡£


https://blog.cyble.com/2022/03/31/deep-dive-analysis-borat-rat/




°²È«¹¤¾ß


CVE-2022-22963µÄPoC


Spring Java FrameworkÔ¶³Ì´úÂëÖ´Ðзì϶µÄPoC ¡£


https://github.com/darryk10/CVE-2022-22963


BackupOperatorToDA


Äܹ»ÔÚûÓÐ RDP »òÓò½ÚÔìÆ÷É쵀 WinRM µÄÇé¿öϳÉΪÓòÖÎÀíÔ± ¡£


https://github.com/mpgn/BackupOperatorToDA


DuplicateDump


ÊÇMirrorDumpµÄÒ»¸ö·ÖÖ§£¬¿ÉÄÜÔÚ²»¼ì²âµ½µÄÇé¿öÏÂת´¢ LSASS ÄÚ´æ ¡£


https://github.com/Hagrid29/DuplicateDump


Slyther


Slyther ÊÇ AWS °²È«¹¤¾ß£¬ÓÃÓڲ鳭 S3 ´æ´¢Í°µÄ¶Á/д/ɾ³ý½Ó¼ûȨÏÞ ¡£


https://github.com/iamavu/Slyther





°²È«·ÖÎö


CISA ÌáÐÑ×Ô¶¯ÀûÓÃµÄ Spring4Shell ·ì϶


https://thehackernews.com/2022/04/cisa-warns-of-active-exploitation-of.html


GitLab °ä²¼¿ÉÄÜÈù¥»÷Õß½Ù³ÖÕË»§µÄ¹Ø¼ü·ì϶²¹¶¡


https://thehackernews.com/2022/04/gitlab-releases-patch-for-critical.html


Anonymousй¶´Ó¶íÂÞ˹¶«Õý½Ì½ÌÌÃÇÔÈ¡µÄ 15 GB Êý¾Ý


https://securityaffairs.co/wordpress/129760/hacktivism/anonymous-hacked-russian-orthodox-church.html


Å·ÃË˾·¨²Ý°¸ÎªËùÓмÓÃÜÂòÂôÔö³¤Á˰²È«²é³­


https://www.bleepingcomputer.com/news/legal/eu-draft-law-adds-security-checks-to-all-crypto-transactions/


Æ»¹ûÀñÎ│ڿƭÍÅ»ïÒòÉæÏÓ²Î¼Ó 150 ÍòÃÀԪڲƭ¶ø±»ÅÐÐÌ


https://www.darkreading.com/attacks-breaches/apple-gift-card-scammers-sentenced-for-role-in-1-5m-fraud


×êÑÐÈËÔ±·¢ÏÖPEAR PHP´æ´¢¿âÖÐ2¸ö´æÔÚ15ÄêµÄ·ì϶


https://securityaffairs.co/wordpress/129797/hacking/pear-php-critical-flaws.html