FIN8ÀûÓÃSardonicºóÃÅбäÌå·Ö·¢ÀÕË÷Èí¼þNoberus
°ä²¼¹¦·ò 2023-07-201¡¢FIN8ÀûÓÃSardonicºóÃÅбäÌå·Ö·¢ÀÕË÷Èí¼þNoberus
SymantecÔÚ7ÔÂ18Èճƣ¬Æä·¢ÏÖÁËFIN8£¨ÓÖ³ÆSyssphinx£©ÀûÓøĽøµÄSardonic·Ö·¢ÀÕË÷Èí¼þNoberusµÄ¹¥»÷»î¶¯¡£FIN8×Ô2016Äê1ÔÂÆðÍ·»îÔ¾£¬ÖØÒªÕë¶ÔÁãÊÛ¡¢²ÍÒû¡¢¾Æµê¡¢Ò½ÁƱ£½¡ºÍÓéÀÖµÈÐÐÒµ¡£×î½üµÄ¹¥»÷Óë֮ǰµÄÇø±ðÔÚÓÚ£¬×îÖÕpayloadÊÇNoberusÒÔ¼°Ê¹ÓÃÁ˳ÁÐÂÉè¼ÆµÄºóÃÅ¡£¸Ä½øµÄSardonicÓë2021Äê·ÖÎöµÄ°æ±¾ÓкܶàÒ»ÑùµÄÖ°ÄÜ£¬µ«²»ÔÙʹÓÃC++³ß¶È¿â£¬¶øÊÇ´úÌæÎª´¿CʵÏÖ¡£´Ë±í£¬SyssphinxתÏòÀÕË÷¹¥»÷Åú×¢£¬ËûÃÇ¿ÉÄܽøÕ¹´ÓÖ¸±ê×éÖ¯ÖлñÈ¡×î´óÀûÈó¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/syssphinx-fin8-backdoor
2¡¢ÑÅÊ«À¼÷칫˾Ôâµ½À´×ÔALPHVºÍClopµÄÁ½´ÎÀÕË÷¹¥»÷
¾ÝýÌå7ÔÂ19ÈÕ±¨Â·£¬Á½¸öÀÕË÷ÍÅ»ïALPHVºÍClopÔÚÆäÍøÕ¾ÁгöÁËÃÀ×±¹«Ë¾ÑÅÊ«À¼÷ì¡£¸Ã¹«Ë¾ÈÏ¿ÉÁËÆäÖеÄһ·£¬³Æ¹¥»÷Õß»ñµÃÁ˲¿ÃÅϵͳµÄ½Ó¼ûȨÏÞ£¬²¢¿ÉÄÜÇÔÈ¡ÁËÊý¾Ý£¬ËûÃÇÒѲÉÈ¡Ðж¯²¢¹Ø¹ØÁËһЩϵͳ¡£ClopËÆºõÀûÓÃÁËMOVEit Transferƽ̨Öеķì϶»ñµÃ½Ó¼ûȨÏÞ£¬²¢Ðû³ÆÇÔÈ¡Á˳¬¹ý131GBµÄÊý¾Ý¡£±¾Öܶþ£¬ALPHVÒ²ÁгöÁËÑÅÊ«À¼÷죬²¢°µÊ¾ÈÔδÊÕµ½¸Ã¹«Ë¾µÄ»Ø¸´¡£¹¥»÷Õß»¹³Æ£¬Ã»ÓмÓÃܹ«Ë¾µÄÈκÎϵͳ£¬µ«ÈôÊǸù«Ë¾²»½»É棬ËûÃǽ«Ð¹Â©¸ü¶àÓйر»µÁÊý¾ÝµÄϸ½Ú£¬¿ÉÄÜ»áÓ°Ïì¿Í»§¡¢¹«Ë¾Ô±¹¤ºÍ¹©¸øÉÌ¡£
https://www.bleepingcomputer.com/news/security/est-e-lauder-beauty-giant-breached-by-two-ransomware-gangs/
3¡¢VirusTotalй¶´óÁ¿Óû§ÐÅÏ¢Éæ¼°FBIºÍNSAµÈ»ú¹¹
ýÌå7ÔÂ18Èճƣ¬¶ñÒâÈí¼þɨÃè·þÎñVirusTotalй¶Á˲¿ÃÅ×¢²á¿Í»§µÄÐÅÏ¢¡£¸ÃÊÂÎñ×îÏÅ×ɰµØÀû¡¶³ß¶È±¨¡·ºÍµÂ¹ú¡¼û÷¾µÖÜ¿¯¡·±¨Â·£¬Ð¹Â¶Îļþ´óÓ×½öΪ313 KB£¬Ô̺¬5600¸ö×¢²áÓû§µÄÐÅÏ¢£¬ÀýÈçÐÕÃû¡¢ÓʼþµØÖ·ºÍ×éÖ¯µÈ¡£ÊÜÓ°ÏìÓû§Éæ¼°ÃÀ¹úÍøÂç˾Á¡¢ÃÀ¹ú˾·¨²¿¡¢Áª¹úµ÷²é¾ÖºÍÃÀ¹ú¹ú¶È°²È«¾Ö£¬»¹ÓкÉÀ¼¡¢Ì¨ÍåºÍÓ¢¹úµÄ¹Ù·½»ú¹¹¡£Google Cloud½²»°È˰µÊ¾£¬ÆäÔ±¹¤ÔÚVirusTotalƽ̨ÉÏÎÞÒâ¼ä¹«¿ªÁËÒ»Óײ¿Ãſͻ§×éÖÎÀíÔ±µÄÓʼþºÍ×éÖ¯Ãû³Æ¡£µ±ËûÃÇÒâʶµ½Êý¾Ýй¶ºó£¬µ±¼´É¾³ýÁËÕâЩÊý¾Ý¡£
https://www.hackread.com/virustotal-data-leak-user-intel-agencies-data/
4¡¢×êÑÐÈËÔ±·¢ÏÖ¼ÙÒâSophosµÄÀÕË÷Èí¼þSophosEncrypt
¾Ý7ÔÂ18ÈÕ±¨Â·£¬ÍøÂ簲ȫ¹©¸øÉÌSophos±»ÃûΪSophosEncryptµÄÐÂÀÕË÷Èí¼þ¼ÙÒâ¡£MalwareHunterTeam·¢ÏÖÁ˸ÃÀÕË÷Èí¼þ£¬Æð³õÒÔΪËüÊÇSophosºì¶ÓÑÝϰµÄÒ»²¿ÃÅ¡£È»¶ø£¬Sophos X-OpsÍŶӰµÊ¾£¬ËûÃÇûÓд´½¨¸Ã¼ÓÃÜ·¨Ê½£¬²¢ÔÚµ÷²é¸ÃÊÂÎñ¡£¼ÓÃÜ·¨Ê½ÊÇÓÃRust¿ª·¢µÄ£¬±»¶¨ÃûΪsophos_encrypt£¬¼ÓÃÜÎļþʱʹÓÃAES256-CBC¼ÓÃܺÍPKCS#7Ìî³ä¡£´Ë±í£¬Ëü»¹Äܸü¸ÄWindows×ÀÃæ±ÚÖ½£¬¶·µ¨µØÏÔʾÁËËüËù¼ÙÒâµÄSophos¡£
https://www.bleepingcomputer.com/news/security/cybersecurity-firm-sophos-impersonated-by-new-sophosencrypt-ransomware/
5¡¢Henry Ford HealthÔâµ½´¹µö¹¥»÷½ü17Íò»¼ÕßÐÅϢй¶
7ÔÂ17ÈÕ±¨Â·³Æ£¬Henry Ford Healthй©ÆäÔâµ½´¹µö¹¥»÷£¬µ¼ÖÂ168000Ãû»¼ÕßµÄÐÅϢй¶¡£ÊÜÓ°Ï컼ÕßÔÚ±¾ÖÜÒ»±»·î¸æ£¬¹¥»÷ÕßÓÚ3ÔÂ30ÈÕ»ñµÃÁËÆóÒµµç×ÓÓʼþÕÊ»§µÄ½Ó¼ûȨÏÞ¡£µ«¸Ã»ú¹¹ºÜ¿ì·¢ÏÖÁËÕâÖÖ½Ó¼û¡£ÊÜÓ°ÏìµÄÓʼþÖÐÔ̺¬²¿ÃÅ»¼ÕßÐÅÏ¢£¬ÕâÊÇÔÚ5ÔÂ16ÈÕ·¢Ïֵġ£Ð¹Â¶µÄÐÅÏ¢¿ÉÄÜÔ̺¬ÐÕÃû¡¢ÐԱ𡢴ºÇï¡¢»¯ÑéÁ˾֡¢ÊÖÊõÀàÐÍ¡¢Õï¶Ï¡¢Ò½ÁƼͼ±àºÅºÍÄÚ²¿¸ú×Ù±àºÅµÈ¡£¸Ã»ú¹¹³ÆÆäÔÚ¼ÓÇ¿°²È«´ëÊ©²¢ÎªÔ±¹¤Ìṩ½øÒ»²½Åàѵ¡£
https://www.clickondetroit.com/news/local/2023/07/17/henry-ford-health-confirms-data-breach-affecting-168000-patients/
6¡¢Check Point°ä²¼2023ÄêQ2Æ·ÅÆÍøÂç´¹µö»î¶¯µÄ»ã±¨
7ÔÂ18ÈÕ£¬Check Point°ä²¼ÁË2023ÄêQ2Æ·ÅÆÍøÂç´¹µö»î¶¯µÄ·ÖÎö»ã±¨¡£2023ÄêQ2£¬¿Æ¼¼¹«Ë¾Î¢ÈíµÄÅÅÃûÉÏÉý£¬´ÓQ1µÄµÚÈýλԾÉýÖÁQ2µÄ°ñÊ×£¬Õ¼ËùÓÐÆ·ÅÆ´¹µö¹¥»÷µÄ29%¡£Æä´ÎÊÇGoogle£¨19.5%£©ºÍApple£¨5.2%£©¡£¾ÍÐÐÒµ¶øÑÔ£¬¿Æ¼¼ÐÐÒµ±»¼ÙÒâ×î¶à£¬Æä´ÎÊÇÒøÐкÍÉ罻ýÌåÍøÂ磬ÀýÈçÅÅÃûµÚËĵĸ»¹úÒøÐÐ(4.2%)£¬ÒÔ¼°½ôËæÆäºóµÄÑÇÂíÑ·(4%)ºÍÎÖ¶ûÂê(3.9%)¡£×îºó£¬Check Point»¹ÁгöÁ˲¿ÃÅ´¹µö¹¥»÷µÄʾÀý¡£
https://blog.checkpoint.com/security/microsoft-dominates-as-the-most-impersonated-brand-for-phishing-scams-in-q2-2023/


¾©¹«Íø°²±¸11010802024551ºÅ