LockBitÍÅ»ïÐû³Æ½«°ä²¼º«¹ú¹ú¶È˰Îñ¾ÖµÄÊý¾Ý
°ä²¼¹¦·ò 2023-04-031¡¢LockBitÍÅ»ïÐû³Æ½«°ä²¼º«¹ú¹ú¶È˰Îñ¾ÖµÄÊý¾Ý
¾ÝýÌå4ÔÂ1ÈÕ±¨Â·£¬ÀÕË÷ÍÅ»ïLockBit³ÆÆäÈëÇÖÁ˺«¹ú¹ú¶È˰Îñ¾Ö¡£3ÔÂ29ÈÕ£¬LockBitÍŻォ¸Ã»ú¹¹Ôö³¤µ½ÆäÍøÕ¾£¬²¢°ä·¢½«ÓÚ4ÔÂ1ÈÕ֮ǰ°ä²¼±»µÁÊý¾Ý¡£¹ú¶È˰Îñ¾Ö£¨NTS£©×÷Ϊ²ÆÕþ²¿µÄÒ»¸ö±í²¿×éÖ¯ÓÚ1966Äê3ÔÂ3ÈÕ³ÉÁ¢£¬ÖØÒªÕƹÜÄÚ²¿Ë°ÊÕÆÀ¹ÀºÍÕ÷ÊÕ¡£½ØÖÁ4ÔÂ1ÈÕ£¬¸ÃÍÅ»ïÉÐδ°ä²¼±»µÁÊý¾Ý¡£µ«ÈôÊǹ¥»÷ÊÇÕæÊµµÄ£¬Õ⽫¶Ôº«¹ú¹«ÃñµÄÒþÖԺͰ²È«×é³ÉÑϳÁÍþв¡£
https://securityaffairs.com/144342/cyber-crime/lockbit-south-korean-national-tax-service.html
2¡¢TMX Finance¼°Æä×Ó¹«Ë¾Ô¼480Íò¸ö¿Í»§µÄÊý¾Ýй¶
ýÌå3ÔÂ31Èճƣ¬TMX Finance¼°Æä×Ó¹«Ë¾TitleMax¡¢TitleBucksºÍInstaLoanÅû¶ÁËһ·Êý¾Ýй¶ÊÂÎñ£¬Éæ¼°4822580¸ö¿Í»§µÄÊý¾Ý¡£Õâ¼Ò¼ÓÄôó½ðÈÚ¹«Ë¾°µÊ¾£¬ºÚ¿ÍÔÚ2022Äê12ÔÂÉÏÑ®ÈëÇÖÁËÆäϵͳ£¬µ«ËûÃÇÖ±µ½2023Äê2ÔÂ13Èղŷ¢ÏÖÁ˹¥»÷»î¶¯¡£3ÔÂ1ÈÕʵÏÖÄÚ²¿µ÷²éºó£¬TMX·¢ÏÖ¹¥»÷ÕßÔÚ2023Äê2ÔÂ3ÈÕÖÁ14ÈÕÇÔÈ¡Á˿ͻ§µÄÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢»¤Õպš¢¼ÝÕÕºÅÂ롢˰ºÅ¡¢Éç»á°²È«ºÅÂëºÍ½ðÈÚÕË»§ÐÅÏ¢µÈ¡£´Ë¿Ì£¬¸Ã¹«Ë¾Ö´ÐÐÁ˶˵㱣»¤ºÍ¼à¿Ø£¬³ÁÖÃÁËËùÓÐÔ±¹¤ÕÊ»§ÃÜÂ룬²¢½«ÎªÓû§ÌṩExperianΪÆÚ12¸öÔµÄÉí·Ý±£»¤·þÎñ¡£
https://www.bleepingcomputer.com/news/security/consumer-lender-tmx-discloses-data-breach-impacting-48-million-people/
3¡¢Ä£¿é»¯¹¤¾ß¼¯AlienFoxÇÔÈ¡¶à¸öÔÆ·þÎñÌṩÉÌÍ´´¦
3ÔÂ30ÈÕ£¬SentinelLabs³ÆÆä·¢ÏÖÁËÒ»¸öÃûΪAlienFoxµÄй¤¾ß°ü£¬¿É±»ÓÃÓÚÈëÇÖµç×ÓÓʼþºÍÍøÂçÍйܷþÎñ¡£AlienFoxÊÇÄ£¿é»¯µÄ£¬´óÎÞÊý¹¤¾ß¶¼ÊÇ¿ªÔ´µÄ¡£¹¥»÷Õß¿ÉʹÓÃÆä´ÓLeakIXºÍSecurityTrailsµÈ°²È«É¨ÃèÆ½Ì¨ÍøÂçÅäÖÃÃýÎóµÄÖ÷»úÁÐ±í¡£¶øºó£¬AlienFoxʹÓÃÊý¾ÝÌáÈ¡¾ç±¾ÔÚÅäÖÃÃýÎóµÄ·þÎñÆ÷ÖÐËÑË÷ÓÃÓÚ´æ´¢»úÃܵÄÅäÖÃÎļþ£¬ÀýÈçAPIÃÜÔ¿¡¢ÕÊ»§Í´´¦ºÍÉí·ÝÑéÖ¤ÁîÅÆ¡£¸Ã¶ñÒâÈí¼þ¿ÉÄÜÕë¶Ô1and1¡¢AWS¡¢Bluemail¡¢ExotelºÍGoogle WorkspaceµÈÊ®¼¸¸öÔÆÆ½Ì¨¡£
https://www.sentinelone.com/labs/dissecting-alienfox-the-cloud-spammers-swiss-army-knife/
4¡¢WordPress²å¼þElementor ProÖеķì϶Òѱ»ÀûÓÃ
¾Ý3ÔÂ31ÈÕ±¨Â·£¬WordPress²å¼þElementor ProÖеķì϶Òѱ»»ý¼«ÀûÓá£Elementor ProÊÇÒ»¸öWordPressÒ³Ãæ¹¹½¨Æ÷²å¼þ£¬±»³¬¹ý1100Íò¸öÍøÕ¾Ê¹Ó᣸÷ì϶ӰÏìÁËv3.11.6¼°¸üµÍ°æ±¾£¬¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÀûÓÃÆä¸ü¸ÄÍøÕ¾ÉèÖã¬ÉõÖÁÆëÈ«ÊÕÊÜÍøÕ¾¡£°²È«¹«Ë¾PatchStack»ã±¨³Æ£¬ºÚ¿ÍÔÚ»ý¼«ÀûÓô˲å¼þ·ì϶½«½Ó¼ûÕß³Á¶¨Ïòµ½¶ñÒâÓò£¨¡°away[.]trackersline[.]com¡±£©»ò½«ºóÃÅÉÏ´«µ½±»ÈëÇÖµÄÍøÕ¾¡£ÕâЩ¹¥»÷ÖÐÉÏ´«µÄºóÃÅÃûΪwp-resortpark.zip¡¢wp-rate.php»òlll.zip¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-bug-in-elementor-pro-wordpress-plugin-with-11m-installs/
5¡¢ÎÚ¿ËÀ¼·¨Âɲ¿ÃÅ¿ÛÁôÒÑÇÔÈ¡430ÍòÃÀÔªµÄ´¹µöÍÅ»ï
ýÌå3ÔÂ31ÈÕ±¨Â·³Æ£¬ÎÚ¿ËÀ¼ºÍ½Ý¿ËµÄ·¨ÂÉÈËÔ±Ðͬ¿ÛÁôÁËij´¹µöÍÅ»ïµÄ¼¸Ãû³ÉÔ±¡£¸ÃÍÅ»ïÕë¶Ô·¨¹ú¡¢Î÷°àÑÀ¡¢²¨À¼¡¢½Ý¿Ë¡¢ÆÏÌÑÑÀµÈÅ·ÖÞ¹ú¶È³ÉÁ¢ÁË100¶à¸ö´¹µöÍøÕ¾£¬ÒÔµÍÓÚÊг¡¼ÛµÄ¸÷ÀàÉÌÆ·Îªµö¶ü£¬ÓÕʹָ±êÊäÈëÐÅÓþ¿¨¾ßÌåÐÅÏ¢À´Ö§¸¶Ðéα¶©µ¥£¬²¢ÀûÓÃÕâЩÐÅÏ¢´ÓÖ¸±êÕË»§ÖÐŲÓÃ×ʽð¡£ËûÃÇÒÑ´ÓÅ·ÖÞ1000¶à¸ö±»¹¥»÷Ö¸±êÄÇÀïÇÔÈ¡Á˳¬¹ý430ÍòÃÀÔª¡£Ä¿Ç°£¬ÒѾ¶ÔÏÓÒÉÈËÌáÆðÐÌÊÂËßËÏ£¬ËûÃÇ¿ÉÄÜÃæ¶Ô×î¸ß12ÄêµÄ½ûïÀ¡£
https://securityaffairs.com/144279/cyber-crime/cyber-police-of-ukraine-cybercrime-gang.html
6¡¢×êÑÐÍŶÓÅû¶RedGolfÀûÓúóÃÅKEYPLUGµÄ¹¥»÷»î¶¯
Recorded FutureÔÚ3ÔÂ30ÈÕÅû¶ÁËRedGolfÀûÓúóÃÅKEYPLUGµÄ¹¥»÷»î¶¯¡£RedGolfÖØÒªÕë¶Ôº½¿Õ¡¢Æû³µ¡¢½ÌÓý¡¢µ±¾Ö¡¢Ã½Ìå¡¢ÐÅÏ¢¼¼ÊõºÍ×Ú½ÌÓйصÄ×éÖ¯¡£×êÑÐÈËÔ±³ýÁ˼ì²âµ½¸ÃÍÅ»ïÔÚ2021ÄêÖÁ2023ÄêʹÓõÄKEYPLUGÑù±¾ºÍ»ù´¡ÉèÊ©£¨´úºÅΪGhostWolf£©±í£¬»¹Ö¸³öÆäʹÓÃÁËCobaltStrikeºÍPlugXµÈÆäËü¹¤¾ß¡£¸Ã°²È«¹«Ë¾»¹°µÊ¾£¬RedGolf½«³ÖÐø¸ßÔËÓª½ÚÅÄ£¬²¢Ñ¸¿ì½«ÃæÏò±í²¿µÄ¹«Ë¾É豸£¨VPN¡¢·À»ðǽºÍÓʼþ·þÎñÆ÷µÈ£©Öеķì϶±øÆ÷»¯£¬ÒÔ»ñµÃÖ¸±êÍøÂçµÄ³õʼ½Ó¼ûȨÏÞ¡£
https://www.recordedfuture.com/with-keyplug-chinas-redgolf-spies-on-steals-from-wide-field-targets


¾©¹«Íø°²±¸11010802024551ºÅ