Lazarus ºÚ¿ÍÀûÓà Windows 0-Day »ñÈ¡ÄÚºËȨÏÞ
°ä²¼¹¦·ò 2024-03-012ÔÂ29ÈÕ£¬³ÛÃûµÄÍøÂç·¸×ï×éÖ¯ Lazarus Group ×î½üÀûÓà Windows ÖеÄÁãÈÕ·ì϶»ñÈ¡ÄÚºËȨÏÞ£¬ÕâÊÇϵͳ½Ó¼ûµÄ¹Ø¼ü¼¶±ð¡£¸Ã·ì϶±»¼ø±ðΪ CVE-2024-21338£¬ÊÇÔÚ appid.Sys AppLocker Çý¶¯·¨Ê½Öз¢Ïֵģ¬Î¢ÈíÆ¾¾Ý Avast Threat Labs µÄ»ã±¨ÔÚÖÙ´º²¹¶¡ÐÇÆÚ¶þ¸üÐÂÖн¨¸´Á˸÷ì϶¡£¸Ã·ì϶ÔÊÐí Lazarus Group ³ÉÁ¢Äں˶Á/дÔÓÕâÊǰѳֲÙ×÷ϵͳÄÚºËÄÚ´æµÄ¸ù»ùÖ°ÄÜ¡£´ËÖ°ÄÜÓÃÓÚ¸üÐÂËûÃÇµÄ FudModule rootkit£¬¼ÓÇ¿ÆäÖ°ÄܺÍÒñ±ÎÐÔ¡£Rootkit ´Ë¿ÌÔ̺¬ÓÃÓÚ²Ù×÷¾ä±ú±íÌõ¿î±êм¼Êõ£¬ÕâЩ¼¼Êõ¿ÉÄÜ»á×ÌÈÅÊÜ Microsoft Protected Process Light (PPL) ±£»¤µÄ¹ý³Ì£¬ÀýÈçÊôÓÚ Microsoft Defender¡¢CrowdStrike Falcon ºÍ HitmanPro µÄ¹ý³Ì¡£CVE-2024-21338ÊÇ Windows Çý¶¯·¨Ê½Öз¢Ïֵķì϶µÄÃû³Æ¡£¶ÔÓÚºÚ¿ÍÀ´Ëµ£¬ËüÊÇÒ»¸öºÜºÃµÄÖ¸±ê£¬ÓÉÓÚËüºÜÈÝÒ×ÓÃÓÚ¹¥»÷£¬²¢ÇÒËüÊÇϵͳµÄÒ»²¿ÃÅ£¬Òò¶øËûÃDz»±ØÒªÔö³¤ÈκÎÄܹ»¼ì²âµ½µÄÐÂÄÚÈÝ¡£
https://gbhackers.com/lazarus-hackers-exploited-windows-0-day/
2. ÔìÒ©¾ÞÍ· Cencora »ã±¨³ÆÆäÔâµ½ÍøÂç¹¥»÷
2ÔÂ28ÈÕ£¬Cencora, Inc.£¨ÒÔϼò³Æ¡°¹«Ë¾¡±£©»ñϤÆäÐÅϢϵͳÖеÄÊý¾ÝÒѱ»Ð¹Â¶£¬ÆäÖв¿ÃÅÊý¾Ý¿ÉÄÜÔ̺¬Ó×ÎÒÐÅÏ¢¡£ÔÚ³õ²½·¢ÏÖδ¾ÊÚȨµÄ¹¥»÷»î¶¯ºó£¬¹«Ë¾µ±¼´²ÉÈ¡¶ôÔì´ëÊ©£¬²¢ÔÚ·¨Âɲ¿ÃÅ¡¢ÍøÂ簲ȫר¼ÒºÍ±í²¿ÕÕ·÷µÄÐÖúÏÂÆðÍ·µ÷²é¡£½ØÖÁ±¾²¼¸æ°ä²¼Ö®ÈÕ£¬¸ÃÊÂÎñÉÐδ¶Ô¹«Ë¾ÔËÓª²úÉú³Á´óÓ°Ï죬ÆäÐÅϢϵͳÈÔÔÚÔËÐС£¹«Ë¾ÉÐδȷ¶¨¸ÃÊÂÎñÊÇ·ñºÏÀí¿ÉÄܶԹ«Ë¾µÄ²ÆÕþÇé¿ö»ò¾½»Ò×¼¨²úÉú³Á´óÓ°Ïì¡£¾ÝThe Record±¨Â·£¬Cencora ÒÔǰ³ÆÎª AmerisourceBergen¡£AmerisourceBergen ¹«Ë¾Ëƺõ¾ÀúÁË Lorenz ÀÕË÷Èí¼þ×éÖ¯ÓÚ 2023 Äê 1 ÔÂÐû³ÆµÄÀÕË÷Èí¼þ¹¥»÷£¬²¢ÇÒËÆºõÓ°ÏìÁË MWI Animal Health¡£DataBreaches Éв»Ã÷ÏÔ 2022 ÄêÁäÎñÓë×î½üµÄ»ã±¨Ö®¼äÊÇ·ñÓÐÈκÎÁªÏµ¡£
https://www.databreaches.net/pharmaceutical-giant-cencora-reports-cyberattack/
3. Rhysida ÀÕË÷ÍŻ﹥»÷Lurie²¢ÀÕË÷ 360 ÍòÃÀÔª
2ÔÂ28ÈÕ£¬Rhysida ÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶Ô±¾Ô³õÕë¶ÔÖ¥¼Ó¸ç¬Àï¶ùͯҽԺµÄÍøÂç¹¥»÷ÕÆ¹Ü¡£Lurie ÊÇÃÀ¹úµ±ÏȵĶù¿Æ¼±Ö¢»¤Àí»ú¹¹£¬Ã¿ÄêΪ³¬¹ý 200,000 Ãû¶ùͯÌṩ»¤Àí¡£ÍøÂç¹¥»÷ÆÈʹҽÁƱ£½¡ÌṩÉÌ¹Ø¹ØÆä IT ϵͳ£¬²¢ÔÚijЩÇé¿öÏÂÍÆ³ÙÒ½ÁÆ»¤Àí¡£µç×ÓÓʼþ¡¢µç»°¡¢MyChart ½Ó¼ûºÍ±¾µØ»¥ÁªÍø¾ùÊܵ½Ó°Ïì¡£³¬Éù²¨ºÍ CT ɨÃèÁ˾ÖÎÞ·¨»ñµÃ£¬»¼Õß·þÎñÓÅÏÈϵͳ±»È¡µÞ£¬Ò½Éú±»ÆÈ¸ÄÓñʺÍÖ½¿ª´¦·½¡£Rhysida ÀÕË÷Èí¼þÍÅ»ïÒѽ« Lurie Children¡¯s Ò½ÔºÁÐÈëÆä°µÍøÉϵÄÀÕË÷ÃÅ»§ÍøÕ¾£¬Ðû³Æ´Ó¸ÃÒ½ÔºÇÔÈ¡ÁË 600 GB µÄÊý¾Ý¡£Æ¾¾ÝLurie Children's ÓÚ 2024 Äê 2 Ô 22 ÈÕ°ä²¼µÄ×îÐÂ״̬¸üУ¬¸´Ô IT ϵͳµÄ¹¤×÷ÔÚ½øÐÐÖУ¬·þÎñÖжÏÒÀȻӰÏìһЩÔËÓª²¿ÃÅ¡£
https://www.bleepingcomputer.com/news/security/rhysida-ransomware-wants-36-million-for-childrens-stolen-data/
4. Anycubic 3D´òÓ¡»úÔÚÈ«ÇòÁìÓòÄÚÔâµ½ºÚ¿Í¹¥»÷
2ÔÂ28ÈÕ£¬Æ¾¾Ý Anycubic ¿Í»§µÄÒ»²¨ÔÚÏ߻㱨£¬ÓÐÈËÈëÇÖÁËËûÃÇµÄ 3D ´òÓ¡»ú£¬²¢ÖÒ¸æÕâЩÉè±¸Ãæ¶Ô¹¥»÷¡£´ËÊÂÎñ±³ºóµÄÈËÔÚÆäÉ豸ÖÐÔö³¤ÁË hacked_machine_readme.gcode Îļþ£¨¸ÃÎļþͨ³£Ô̺¬ 3D ´òÓ¡Ö¸Á£¬ÌáÐÑÊÜÓ°ÏìµÄÓû§ËûÃǵĴòÓ¡»úÊܵ½ÑϳÁ°²È«ÃýÎóµÄÓ°Ïì¡£¾Ý³Æ£¬´Ë·ì϶ʹDZÔÚ¹¥»÷Õß¿ÉÄÜʹÓøù«Ë¾µÄ MQTT ·þÎñ API ½ÚÔìÈκÎÊÜ´Ë·ì϶ӰÏìµÄ Anycubic 3D ´òÓ¡»ú¡£ÊÜÓ°ÏìÉ豸ÊÕµ½µÄÎļþ»¹ÒªÇó Anycubic ¿ªÔ´Æä 3D ´òÓ¡»ú£¬ÔÚÓû§»ã±¨ 3D ´òÓ¡»úÏÔʾ¡°±»ºÚ¡±ÐÂÎÅÆðÍ·³öÏÖºó£¬ AnycubicÀûÓ÷¨Ê½Ò²ÖÕ³¡Á˹¤×÷¡£ÕýÈçTechCrunch³õ´Î±¨Â·µÄÄÇÑù£¬³¢ÊԵǼµÄÓû§»á¿´µ½¡°ÍøÂç²»³ÉÓá±ÃýÎóÐÂÎÅ¡£
https://www.bleepingcomputer.com/news/security/anycubic-3d-printers-hacked-worldwide-to-expose-security-flaw/
5. ÓëÒÁÀÊÓÐ¹ØµÄ UNC1549 ºÚ¿Í¶Ô×¼Öж«º½¿Õº½ÌìºÍ¹ú·À²¿ÃÅ
2ÔÂ28ÈÕ£¬¹È¸èÆìÏ嵀 Mandiant ÔÚÒ»·ÝзÖÎöÖаµÊ¾£¬ÍøÂç¼äµý»î¶¯µÄÆäËûÖ¸±ê¿ÉÄÜÔ̺¬ÍÁ¶úÆä¡¢Ó¡¶ÈºÍ°¢¶û°ÍÄáÑÇ¡£ÕâЩ¹¥»÷±ØÒªÊ¹Óà Microsoft Azure ÔÆ»ù´¡ÉèÊ©½øÐкÅÁîÓë½ÚÔì (C2) ºÍÉæ¼°Ó빤×÷ÓйصÄÒýÓÕµÄÉç»á¹¤³Ì£¬ÒÔÌṩÁ½¸öÃûΪ MINIBIKE ºÍ MINIBUS µÄºóÃÅ¡£Óã²æÊ½ÍøÂç´¹µöµç×ÓÓʼþÖ¼ÔÚ´«²¼Ô̺¬ÒÔÉ«ÁйþÂí˹ÓйØÄÚÈÝ»òÐéα¹¤×÷»úÓöµÄÐéÎ±ÍøÕ¾Á´½Ó£¬´Ó¶øµ¼Ö²¿Êð¶ñÒâ¸ºÔØ¡£»¹¹Û²ìµ½·ÂÕÕ´ó¹«Ë¾µÄÐéαµÇÂ¼Ò³ÃæÒÔ»ñȡʹ´¦¡£×Ô½ç˵ºóÃÅÔÚ³ÉÁ¢ C2 ½Ó¼ûºó£¬³äÈεý±¨ÍøÂçºÍ½øÒ»²½½Ó¼ûÖ¸±êÍøÂçµÄÇþ·¡£´Ë½×¶Î²¿ÊðµÄÁíÒ»¸ö¹¤¾ßÊÇÃûΪ LIGHTRAIL µÄËí·Èí¼þ£¬ËüʹÓà Azure ÔÆ½øÐÐͨѶ¡£Õâ´Î¹¥»÷»î¶¯Öв¿ÊðµÄ¶ã±Ü²½Ö裬¼´Á¿Éí¶¨ÔìµÄÒÔ¹¤×÷ΪÖ÷ÌâµÄµö¶üÓë C2 ÔÆ»ù´¡ÉèÊ©µÄʹÓÃÏà½áºÏ£¬¿ÉÄÜ»áÈÃÍøÂç·ÀÓùÕßÄÑÒÔÔ¤·À¡¢¼ì²âºÍ¼õÇáÕâÖֻ¡£
https://thehackernews.com/2024/02/iran-linked-unc1549-hackers-target.html
6. ÀÕË÷Èí¼þÍÅ»ïÐû³ÆÇÔÈ¡½ü 200GB µÄ Epic Games ÄÚ²¿Êý¾Ý
2ÔÂ28ÈÕ£¬¾Ý±¨Â·£¬¸ÃÍÅ»ïÃûΪ Mogilevich£¬ÔÚÆä°µÍøÐ¹ÃÜÍøÕ¾Éϰ䲼ÁËÒ»ÌõÐÂÎÅ£¬ÌṩÁËÓÐ¹ØÆäÐû³ÆµÄ¡¶µï±¤Ö®Ò¹¡·ºÍEpic Games Store¹«Ë¾Ð¹ÃÜÊÂÎñµÄ¸ü¶àÐÅÏ¢¡£»¹Ðû³ÆÒѾй¶ÁË¡°µç×ÓÓʼþ¡¢ÃÜÂ롢ȫÃû¡¢¸¶¿îÐÅÏ¢¡¢Ô´´úÂëºÍºÜ¶àÆäËûÊý¾Ý¡±£¬×Ü´óÓ×´ïµ½ 189GB¡£»¹Ëµ£º¡°Êý¾ÝÒ²Äܹ»ÏúÊÛ¡±£¬²¢Îª¡°¹«Ë¾Ô±¹¤»òÏëÒª²É°ìÊý¾ÝµÄÈË¡±Ôö³¤ÁËÁ´½Ó¡£¸ÃÍŻﻮ¶¨ÁË 3 Ô 4 ÈÕΪ²É°ìÊý¾ÝµÄ×îºóÆÚÏÞ£¬µ«Ã»Óиø³ö¾ßÌåÊý×Ö£¬Ò²Ã»ÓÐÅú×¢ÈôÊǽØÖ¹ÈÕÆÚ¹ýºó½«ÈôºÎ´¦ÖÃÕâЩÊý¾Ý¡£Mogilevich ÊÇÒ»¸öÏà¶Ô½ÏеÄÀÕË÷Èí¼þ×éÖ¯£¬Epic Games ÊÇÆäµÚËĸöÖ¸±ê¡£µÚÒ»¸öÊÇÈÕ²ú×Ó¹«Ë¾Ó¢·ÆÄáµÏÃÀ¹ú¹«Ë¾£¬¸Ã¹«Ë¾ÉÏÖÜÔâµ½ºÚ¿Í¹¥»÷¡£
https://www.videogameschronicle.com/news/a-ransomware-gang-claims-to-have-hacked-nearly-200gb-of-epic-games-internal-data/


¾©¹«Íø°²±¸11010802024551ºÅ