ÀÕË÷Èí¼þÍÅ»ïÆðÍ·¹«¿ª²¿ÃÅ Change Healthcare µÄÊý¾Ý
°ä²¼¹¦·ò 2024-04-174ÔÂ15ÈÕ£¬RansomHub ÀÕË÷ÍÅ»ïÒÑÆðÍ·¹«¿ªËûÃÇÐû³Æ´Ó United Health ×Ó¹«Ë¾ Change Healthcare ÇÔÈ¡µÄ¹«Ë¾ºÍ»¼ÕßÊý¾Ý£¬Õâ¶Ô¸Ã¹«Ë¾À´ËµÊÇÒ»¸öÂþ³¤¶ø¸´ÔÓµÄÀÕË÷¹ý³Ì¡£½ñÄê 2 Ô£¬ Change Healthcare Ôâ·êÁËÍøÂç¹¥»÷ £¬¶ÔÃÀ¹úÒ½ÁƱ£½¡ÏµÍ³Ôì³ÉÁËÑϳÁ·ÛË飬µ¼ÖÂÒ©·¿ºÍÒ½ÉúÎÞ·¨Ïò±£ÏÕ¹«Ë¾¿ª¾ßÕ˵¥»òÌá³öË÷Åâ¡£Õâ´Î¹¥»÷×îÖÕ Óë BlackCat/ALPHV ÀÕË÷Èí¼þ²Ù×÷Óйأ¬¸ÃÀÕË÷Èí¼þºóÀ´ËµËûÃÇ ÔÚ¹¥»÷ÆÚ¼äÇÔÈ¡ÁË 6 TB Êý¾Ý¡£ÍþвÐÐΪÕ߯ðÍ·¹«¿ªËûÃÇÐû³ÆÔÚ 2 Ô·ÝÀÕË÷Èí¼þ¹¥»÷ÆÚ¼ä´Ó Change Healthcare ÇÔÈ¡µÄÎļþµÄÆÁÄ»½ØÍ¼¡£ÆÁÄ»½ØÍ¼Ô̺¬ Change Healthcare Óë±£ÏÕÌṩÉÌ£¨Ô̺¬ CVS Caremark¡¢Health Net ºÍ Loomis£©Ö®¼äµÄÊý¾Ý¹²ÏíºÍ̸¡£ÆäËûÎļþÔ̺¬¹ÜÕÊÊý¾Ý£¬Ô̺¬ÕËÁä»ã±¨¡¢±£ÏÕ¸¶¿î»ã±¨ºÍÆäËû²ÆÕþÐÅÏ¢¡£
https://www.bleepingcomputer.com/news/security/ransomware-gang-starts-leaking-alleged-stolen-change-healthcare-data/
2. CISCO DUO ÖÒ¸æµç»°¹©¸øÉÌÊý¾Ýй¶µ¼Ö MFA ¶ÌÐÅÈÕ־¶³ö
4ÔÂ15ÈÕ£¬Cisco Duo ÖÒ¸æÆäÒ»¼Òµç»°¹©¸øÉ̲úÉúÊý¾Ýй¶ÊÂÎñ£¬µ¼ÖÂͨ¹ý SMS ºÍ VOIP ·¢Ë͸ø¿Í»§µÄ¶à³É·ÖÉí·ÝÑéÖ¤ (MFA) ÐÂÎÅÊܵ½ÇÖº¦¡£¸Ã°²È«·ì϶²úÉúÓÚ 2024 Äê 4 Ô 1 ÈÕ£¬ÍþвÐÐΪÕßʹÓÃÁËͨ¹ýÍøÂç´¹µö¹¥»÷·¸·¨»ñµÃµÄÌṩÉÌÔ±¹¤µÄÍ´´¦¡£¶øºó£¬ËûÃÇʹÓøýӼûȨÏÞÏÂÔØÁËÒ»×éÊôÓÚ¿Í»§ Duo ÕÊ»§µÄ MFA ¶ÌÐÅÈÕÖ¾¡£¸ü¾ßÌåµØËµ£¬ÍþвÐÐΪÕßÏÂÔØÁË 2024 Äê 3 Ô 1 ÈÕÖÁ 2024 Äê 3 Ô 31 ÈÕÆÚ¼ä·¢Ë͸øÄú Duo ÕÊ»§ÏµÄijЩÓû§µÄ SMS ÐÂÎŵÄÐÂÎÅÈÕÖ¾¡£ÐÂÎÅÈÕÖ¾²»Ô̺¬ÈκÎÐÂÎÅÄÚÈÝ£¬µ«Ô̺¬µç»°ºÅÂ룬ÿÌõÐÂÎÅ·¢Ë͵½µÄµç»°ÔËÓªÉÌ¡¢¹ú¶ÈºÍÖÝ£¬ÒÔ¼°ÆäËûÔªÊý¾Ý£¨ÀýÈçÐÂÎŵÄÈÕÆÚºÍ¹¦·ò¡¢ÐÂÎÅÀàÐ͵ȣ©¡£ÔĶÁ·¢Ë͸øÊÜÓ°ÏìÓ×ÎÒµÄÊý¾Ýй¶֪ͨ¡£¹¥»÷ÕßÄܹ»½Ó¼ûÿÌõÐÂÎÅ·¢Ë͵½µÄµç»°ºÅÂë¡¢µç»°ÔËÓªÉÌ¡¢¹ú¶ÈºÍÖÝ¡£¹¥»÷Õß»¹»ñµÃÁËÆäËûÔªÊý¾Ý£¬Ô̺¬ÐÂÎŵÄÈÕÆÚºÍ¹¦·ò¡¢ÐÂÎÅÀàÐ͵ȡ£·¢Ïִ˹ýºó£¬¹©¸øÉ̵±¼´·¢Õ¹µ÷²é²¢²ÉÈ¡»º½â´ëÊ©¡£
https://securityaffairs.com/161880/cyber-crime/cisco-duo-data-breach.html
3. SteganoAmor ¹¥»÷ʹÓÃÒþдÊõ¹¥»÷È«Çò 320 ¸ö×éÖ¯
4ÔÂ16ÈÕ£¬TA558 ºÚ¿Í×éÖ¯·¢Õ¹µÄÒ»ÏîлÔÚʹÓÃÒþдÊõ½«¶ñÒâ´úÂë°µ²ØÔÚͼÏñÄÚ£¬´Ó¶ø½«¸÷Àà¶ñÒâÈí¼þ¹¤¾ß´«µÝµ½Ö¸±êϵͳÉÏ¡£ÒþдÊõÊÇÒ»ÖÖ½«Êý¾Ý°µ²ØÔÚ¿´ËÆÎÞº¦µÄÎļþÖеļ¼Êõ£¬Ê¹Óû§ºÍ°²È«²úÆ·ÎÞ·¨¼ì²âµ½ËüÃÇ¡£TA558 ÊÇÒ»¸ö×Ô 2018 ÄêÒÔÀ´Ò»Ïò»îÔ¾µÄÍþв×éÖ¯£¬ÒÔ Õë¶ÔÈ«Çò¾ÆµêºÍÓÎÀÀ×éÖ¯£¨ÓÈÆäÊÇÀ¶¡ÃÀÖÞ£©¶øÎÅÃû¡£Positive Technologies ·¢ÏÖÁ˸Ã×éÖ¯µÄ×îл£¬ÓÉÓÚ¿í·ºÊ¹ÓÃÒþдÊõ£¬±»³ÆÎª¡°SteganoAmor¡±¡£×êÑÐÈËÔ±ÔÚÕâ´Î»î¶¯Öз¢ÏÖÁË 320 ÂŴι¥»÷£¬Ó°ÏìÁ˸÷¸ö²¿Ãź͹ú¶È¡£ÕâЩ¹¥»÷´ÓÔ̺¬¿´ËÆÎÞº¦µÄÎĵµ¸½¼þ£¨Excel ºÍ Word Îļþ£©µÄ¶ñÒâµç×ÓÓʼþÆðÍ·£¬ÕâЩ¸½¼þÀûÓÃÁË CVE-2017-11882 £¬ÕâÊÇ 2017 Ä꽨¸´µÄÒ»¸ö³£¼ûÖ¸±ê Microsoft Office ¹«Ê½±à×ëÆ÷·ì϶¡£
https://www.bleepingcomputer.com/news/security/new-steganoamor-attacks-use-steganography-to-target-320-orgs-globally/
4. BLACKJACKʹÓÃICS¶ñÒâÈí¼þFUXNET¹¥»÷¶íÂÞ˹µÄÖ¸±ê
4ÔÂ15ÈÕ£¬¹¤ÒµºÍÆóÒµÎïÁªÍøÍøÂ簲ȫ¹«Ë¾ Claroty »ã±¨³Æ£¬ÎÚ¿ËÀ¼ Blackjack ºÚ¿Í×éÖ¯Ðû³ÆÊ¹ÓÃÃûΪ Fuxnet µÄ·ÛËéÐÔ ICS ¶ñÒâÈí¼þ·ÛËéÁËĪ˹¿Æ¼°¶íÂÞ˹Ê×¶¼ÒÔ±íµØÓòµÄ´¹Î£¼ì²âºÍÏìÓ¦ÄÜÁ¦¡£¾ÝÐÅ£¬ Blackjack ×éÖ¯ÓëÎÚ¿ËÀ¼µý±¨»ú¹¹ÓйØÁª£¬¸Ã»ú¹¹¶Ô¶íÂÞ˹ָ±ê½øÐÐÁËÆäËû¹¥»÷£¬Ô̺¬ »¥ÁªÍøÌṩÉÌ ºÍ ¾üÊ»ù´¡ÉèÊ©¡£¸Ã×éÖ¯Ðû³ÆÏ®»÷ÁË×ܲ¿Î»ÓÚĪ˹¿ÆµÄ Moscollector ¹«Ë¾£¬¸Ã¹«Ë¾ÕƹܵØÏÂË®¡¢ÎÛË®ºÍͨѶ»ù´¡ÉèÊ©µÄ½¨ÉèºÍ¼à²â¡£ruexfil.comÍøÕ¾ÌṩÁËÓÐ¹Ø Moscollector ¹¥»÷µÄ¾ßÌåÐÅÏ¢£¬ºÚ¿Í»¹°ä²¼ÁËËûÃÇÐû³ÆÊܵ½ÇÖº¦µÄ¼à¿ØÏµÍ³¡¢·þÎñÆ÷ºÍÊý¾Ý¿âµÄÆÁÄ»½ØÍ¼¡£
https://securityaffairs.com/161865/hacking/blackjack-ics-malware-fuxnet.html
5. ºÚ¿Í¶¨Ôì LockBit 3.0 ÀÕË÷Èí¼þÀ´¹¥»÷È«Çò×éÖ¯
4ÔÂ16ÈÕ£¬¿¨°Í˹»ù³¢ÊÔÊÒµÄÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖÁËÖ¤¾Ý£¬Åú×¢ÍøÂç·¸×ïÍÅ»ïÔÚ¶¨Ôì¶ñÒâµÄ LockBit 3.0 ÀÕË÷Èí¼þ£¬ÒÔÕë¶ÔÈ«Çò×éÖ¯½øÐÐÓÐÕë¶ÔÐԵĹ¥»÷¡£ÕâʹµÃÍþвÐÐΪÕß¿ÉÄܶ¨Ôì¶ñÒâÈí¼þ£¬ÒÔÕë¶ÔÌØ¶¨Ö¸±ê²úÉú×î´óµÄÓ°ÏìºÍÓÐЧÐÔ¡£ÕâЩ·¢ÏÖÀ´×Ô×êÑÐÈËÔ±¶Ôй¶µÄLockBit 3.0¹¹½¨Æ÷µÄ·ÖÎö£¬¸Ã¹¹½¨Æ÷ÓÚ 2022 Äê³õ´Î³Ê´Ë¿ÌµØÏÂÂÛ̳ÉÏ¡£¸Ã¹¹½¨Æ÷ʹ·¸×ï·Ö×Ó¿ÉÄÜͨ¹ýÅäÖÃÍøÂç´«²¼Ö°ÄܺͽûÓ÷ÀÓùµÈÑ¡ÏîÀ´ÌìÉúÀÕË÷Èí¼þµÄ¶¨Ôì°æ±¾¡£µ÷²éÈËÔ±·¢ÏÖ¹¥»÷ÕßÒѳɹ¦ÇÔÈ¡´¿Îı¾ÖÎÀíԱʹ´¦¡£¶øºó£¬ËûÃÇʹÓà LockBit ¹¹½¨Æ÷ÌìÉú¶¨ÔìµÄÀÕË÷Èí¼þ±äÌ壬¿ÉÄÜÀûÓÃÕâЩ±»µÁµÄȨÏÞÔÚÍøÂçÉϼ±¾ç´«²¼¡£¶¨ÔìµÄ¶ñÒâÈí¼þÔÚ¶ÔÊÜϰȾϵͳÖеÄÊý¾Ý½øÐмÓÃÜ֮ǰ£¬»á·ÛËé Windows Defender ±£»¤²¢É¾³ýÊÂÎñÈÕÖ¾ÒÔ¸²¸ÇÆä×ÙÓ°¡£
https://gbhackers.com/hacker-customize-lockbit-3-0-ransomware-to-attack-orgs-worldwide/
6. »ìÂÒµÄ Libra ½«³ÁµãתÏòSaaSºÍÔÆÒÔ½øÐÐÀÕË÷¹¥»÷
4ÔÂ15ÈÕ£¬¾Ý¹Û²ì£¬±»³ÆÎªMuddled LibraµÄ¹¥»÷Õß»ý¼«Õë¶ÔÈí¼þ¼´·þÎñ (SaaS) ÀûÓ÷¨Ê½ºÍÔÆ·þÎñÌṩÉÌ (CSP) »·¾³£¬ÒÔÇÔÈ¡Ãô¸ÐÊý¾Ý¡£ÍþвÐÐΪÕßÒѾÆðÍ·³¢ÊÔÀûÓÃÆäÖÐһЩÊý¾ÝÀ´ÐÖúËûÃǵĹ¥»÷½øÕ¹£¬²¢ÔÚÊÔͼͨ¹ýËûÃǵŤ×÷»ñÀûʱÓÃÓÚÀÕË÷¡£Muddled Libra£¬Ò²³ÆÎª Starfraud¡¢UNC3944¡¢Scatter Swine ºÍ Scattered Spider£¬ÊÇÒ»¸ö³ôÃûÔ¶ÑïµÄÍøÂç·¸×ï×éÖ¯£¬ÀûÓø´ÔÓµÄÉç»á¹¤³Ì¼¼ÊõÀ´»ñµÃ¶ÔÖ¸±êÍøÂçµÄ³õʼ½Ó¼ûȨÏÞ¡£¹¥»÷Õß»¹ÔøÒÔ¶àÖÖ·½Ê½Í¨¹ý½Ó¼ûÊܺ¦ÕßÍøÂçÀ´»ñÀû£¬Ô̺¬Í¨¹ýÀÕË÷Èí¼þºÍÊý¾Ý͵ÇÔ½øÐÐÀÕË÷¡£ÍþвÐÐΪÕßÕ½ÊõÑݱäµÄÒ»¸ö¹Ø¼ü·½ÃæÊÇ£¬ÔÚ¼ÙÒâÔ®ÊǪ̈¹¤×÷ÈËԱͨ¹ýµç»°»ñÈ¡ÃÜÂëʱ£¬Ê¹ÓÿúËż¼ÊõÀ´¼ø±ðÖ¸±êÖÎÀíÓû§¡£¿úËŽ׶λ¹ÑÓ³¤µ½ Muddled Libra ½øÐÐ¿í·ºµÄ×êÑУ¬ÒÔ²éÕÒÓйØÖ¸±ê×é֯ʹÓõÄÀûÓ÷¨Ê½ºÍÔÆ·þÎñÌṩÉ̵ÄÐÅÏ¢¡£
https://thehackernews.com/2024/04/muddled-libra-shifts-focus-to-saas-and.html?&web_view=true


¾©¹«Íø°²±¸11010802024551ºÅ