ÃÀ¹ú×î´ó²úȨ±£ÏÕ¹«Ë¾FNF±»AlphV¹¥»÷ϵÍÂäÙʱ¹Ø¹Ø

°ä²¼¹¦·ò 2023-11-27

1¡¢ÃÀ¹ú×î´ó²úȨ±£ÏÕ¹«Ë¾FNF±»AlphV¹¥»÷ϵÍÂäÙʱ¹Ø¹Ø


¾ÝýÌå11ÔÂ24ÈÕ±¨Â· £¬ÃÀ¹ú×î´óµÄ²úȨ±£ÏÕ¹«Ë¾Fidelity National Financial(FNF)Ôâµ½AlphV(BlackCat) µÄ¹¥»÷¡£ÉÏÖÜÈý £¬AlphV°ä·¢ËûÃǹ¥»÷ÁËFNF £¬»¹½«FNFûÓн»Êê½ðµÄÔ­Òò¹é×ïÓÚMandiant¡£Ä¿Ç° £¬AlphVûÓа䲼ÈκθÉÓÚ¹¥»÷µÄÖ¤Ã÷¡£FNFÍøÕ¾ÉÏҲûÓÐÈκμ£ÏóÅú×¢´æÔÚÊý¾Ýй¶ÎÊÌâ £¬µ«ÊÇËü¹Ø¹ØÁ˺ܶàÔÚÏß·þÎñ £¬²¢°µÊ¾ËûÃÇ֪·ijЩϵͳÒѱ»½Ó¼û¡£


https://www.databreaches.net/fidelity-national-financial-ransomware-incident-impacts-real-estate-closings/


2¡¢Í¨ÓÃµçÆøµÄ½Ó¼ûȨÏ޺ʹóÁ¿Êý¾ÝÔÚºÚ¿ÍÂÛ̳±»ÏúÊÛ


¾Ý11ÔÂ25ÈÕ±¨Â· £¬ÃÀ¹ú¿ç¹ú¹«Ë¾Í¨ÓÃµçÆø(GE)ÔÚµ÷²éÆäÊý¾Ý±»µÁµÄÎÊÌâ¡£±¾ÔÂÔçЩʱ³½ £¬ºÚ¿ÍIntelBrokerÔÚ°µÍøÒÔ500ÃÀÔªµÄ¼ÛÖµÏúÊÛGEµÄ½Ó¼ûȨÏÞ¡£¶øºó £¬¹¥»÷ÕßÔٴη¢Ìû³Æ £¬ËûÃÇ´Ë¿ÌͬʱÏúÊÛÍøÂç½Ó¼ûȨÏÞ£¨SSHºÍSVNµÈ£©ºÍ±»µÁÊý¾Ý £¬ÆäÖб»µÁÊý¾ÝÔ̺¬´óÁ¿ÓëDARPAÓйصľüÊÂÐÅÏ¢¡¢Îļþ¡¢SQLÎļþºÍÎĵµµÈ¡£×÷Ϊй¶֤¾Ý £¬¹¥»÷Õß¹«¿ªÁËÊý¾Ý½ØÍ¼ £¬Ô̺¬GE AviationsµÄÒ»¸öÊý¾Ý¿â £¬Éæ¼°¾üÊÂÏîÖ÷ÕÅÐÅÏ¢¡£GE°µÊ¾ÒÑ»ñϤ´ËÊÂÎñ £¬²¢ÔÚ½øÐе÷²é¡£


https://www.bleepingcomputer.com/news/security/general-electric-investigates-claims-of-cyber-attack-data-theft/


3¡¢ITÌṩÉÌCTSÔâµ½ÀÕË÷¹¥»÷Ó¢¹úÊý°Ù¼ÒÂÉËùµÄÒµÎñÊÜÓ°Ïì


11ÔÂ24ÈÕ±¨Â·³Æ £¬ÎªÓ¢¹úÂÉʦÊÂÎñËùÌṩÍйܷþÎñµÄÌṩÉÌ(MSP)CTSÔâµ½ÍøÂç¹¥»÷¡£Õâ¼ÒIT·þÎñÌṩÉÌÔÚÉÏÖÜÎå°ä²¼ÉêÃ÷³Æ £¬ËûÃÇÔÚ¾­ÀúÒ»´Î·þÎñÖжÏ £¬Ó°ÏìÁËÏò²¿Ãſͻ§ÌṩµÄ·þÎñ¡£¹ÌÈ»CTSÉÐδй©ÊÜÓ°Ïì¿Í»§µÄÊýÁ¿ºÍ¹¥»÷ÐÔÖÊ £¬µ«Ä¿Ç°µÄÐÅÏ¢Åú×¢ÕâÊÇÒ»´ÎÀÕË÷¹¥»÷¡£±¾µØÃ½Ì屨· £¬Ô¼80ÖÁ200¼ÒÂÉʦÊÂÎñËù¿ÉÄÜÊܵ½Ó°Ïì¡£ÔÚÕâÒ»ÖÜÀï £¬ÓÉÓÚ·þÎñÖжÏ £¬ÈËÃÇÎÞ·¨²É°ì»òÏúÊÛ·¿²ú¡£¸Ã¹«Ë¾°µÊ¾ £¬ÓÐÐÅÄî¿ÉÄܸ´Ô­·þÎñ £¬µ«ÎÞ·¨È·¶¨¡°È«Ã渴ԭ¡±µÄ¹¦·ò¡£


https://therecord.media/uk-cyberattack-msp-cts-law-firms


4¡¢°²È«»ú¹¹Åû¶LazarusÀûÓÃMagicLine4NX·ì϶µÄ¹©¸øÁ´¹¥»÷


ýÌå11ÔÂ25ÈÕ³Æ £¬°²È«»ú¹¹NCSCºÍNIS½áºÏ°ä²¼¹«¸æ³ÆLazarusÔÚÀûÓÃMagicLine4NXÖеÄodayÖ´Ðй©¸øÁ´¹¥»÷¡£MagicLine4NXÊÇÒ»¿î°²È«ÈÏÖ¤Èí¼þ £¬¹¥»÷²úÉúÓÚ½ñÄê3Ô·Ý¡£¹¥»÷Á´Ê¼ÓÚË®¿Ó¹¥»÷ £¬¹¥»÷ÕßÈëÇÖÁËÒ»¼ÒýÌåÍøÕ¾ £¬²¢½«¶ñÒâ¾ç±¾Ö²È뵽һƪÎÄÕÂÖÐ £¬ÕâЩ¾ç±¾½öÕë¶ÔÌØ¶¨IPÁìÓòµÄ½Ó¼ûÕß¡£µ±Óû§Ê¹ÓÃMagicLine4NX½Ó¼û±»Ï°È¾ÍøÕ¾Ê± £¬¶ñÒâ´úÂë¾Í»áÖ´ÐдӶøÆëÈ«½ÚÔìϵͳ¡£Ëæºó £¬¹¥»÷ÕßÀûÓÃϵͳ·ì϶´ÓÁªÍøµÄPCÉÏ·¸·¨½Ó¼û·þÎñÆ÷ £¬²¢ÀÄÓÃÁªÍøÏµÍ³µÄÊý¾Ýͬ²½Ö°Äܽ«¶ñÒâ´úÂë´«²¼µ½ÒµÎñ¶Ë·þÎñÆ÷ £¬×îÖÕÖ¼ÔÚÇÔÊØÐÅÏ¢¡£


https://securityaffairs.com/154765/apt/lazarus-magicline4nx-supply-chain-attack.html


5¡¢Granger Medical ClinicÔâµ½NoEscape¹¥»÷¾Ü¸¶Êê½ð


ýÌå11ÔÂ26ÈÕ±¨Â·³Æ £¬ÀÕË÷ÍÅ»ïNoEscapeÓÚ11ÔÂ24ÈÕ½«ÓÌËûÖݵÄGranger Medical ClinicÔö³¤µ½ÆäÍøÕ¾ÖС£¹¥»÷ÕßÐû³ÆÕ¼Óг¬¹ý35GBµÄÊý¾Ý £¬Ô̺¬±£ÃܺÍ̸ºÍºÏͬ¡¢NDA¡¢SSN¿¨¡¢É󼯡¢»ã±¨¡¢²ÆÕþ¡¢Êý¾Ý¿â¡¢Ô¤ËãºÍÒøÐÐÒµÎñµÈÓйØÎļþ¡£×÷Ϊ֤¾Ý £¬NoEscape»¹ÌṩÁËÎļþÊ÷ºÍÆÁÄ»½ØÍ¼¡£½»ÉæËƺõ·ÖÁÑÁË £¬Granger¾ö¶¨²»¸¶¿î¡£NoEscapeÍþвÔÚ24Ó×ʱÄÚÖ§¸¶70ÍòÃÀÔªÊê½ð £¬²»È»½«¹«¿ªËùº±¼û¾Ý¡£×êÑÐÈËÔ±ÔÚ25Èղ鳭·¢ÏÖ £¬¹¥»÷ÕßÒѾ­Ð¹Â¶Á˳¬¹ý31 GBµÄÎļþ¡£


https://www.databreaches.net/ransomware-group-leaks-data-allegedly-from-granger-medical-clinic/


6¡¢Check Point·¢ÏÖʹÓÃSysJokerºóÃŹ¥»÷ÒÔÉ«ÁеĻ


11ÔÂ23ÈÕ £¬Check PointÅû¶ÁËʹÓÃSysJokerºóÃŹ¥»÷ÒÔÉ«ÁеĻ¡£SysJokerÓÚ2021Äê12Ô³õ´Î±»·¢ÏÖ £¬¸ÃºóÃÅ¿ÉÄÜϰȾWindows¡¢macOSºÍLinuxϵͳ £¬Æäʱ·¢ÏÖµÄÊÇC++°æ±¾¡£Õë¶ÔÒÔÉ«ÁеĹ¥»÷ÖÐʹÓõİ汾ÊÇRust¿ª·¢µÄ £¬ÕâÅú×¢¸Ã¶ñÒâÈí¼þÊÇÖØÐÂÆðÍ·³Áд £¬ÓÚ½ñÄê10ÔÂ12ÈÕ³õ´ÎÌá½»µ½VirusTotal¡£´Ë±í £¬¸Ã¶ñÒâÈí¼þÑ¡È¡Ëæ»ú˯Ãß¾àÀëºÍ¸´ÔÓµÄ×Ô½ç˵¼ÓÃÜ´úÂë×Ö·û´®À´Èƹý¼ì²âºÍ·ÖÎö¡£


https://research.checkpoint.com/2023/israel-hamas-war-spotlight-shaking-the-rust-off-sysjoker/