CoralRaider¶ñÒâÈí¼þ»î¶¯ÀûÓÃCDN»º´æ´«²¼ÐÅÏ¢ÇÔÈ¡·¨Ê½

°ä²¼¹¦·ò 2024-04-25
1. CoralRaider¶ñÒâÈí¼þ»î¶¯ÀûÓÃCDN»º´æ´«²¼ÐÅÏ¢ÇÔÈ¡·¨Ê½


4ÔÂ24ÈÕ£¬×êÑÐÈËÔ±·¢ÏÖÒ»ÖÖеijÖÐø¶ñÒâÈí¼þ»î¶¯ÔÚ·Ö·¢ÈýÖÖ·ÖÆçµÄÇÔÈ¡·¨Ê½£¬ÀýÈçÍйÜÔÚÄÚÈݽ»¸¶ÍøÂç (CDN) »º´æÓòÉϵÄCryptBot¡¢LummaC2ºÍRhadamanthys  ¡£Ë¼¿Æ Talos ½«Õâ´Î»î¶¯¹éÒòÓÚ±»×·×ÙΪCoralRaiderµÄÍþвÐÐΪÕߣ¬¸Ã×éÖ¯ÒÉËÆÔ´×ÔÔ½ÄÏ£¬ÓÚ½üÆÚÆØ¹â ¡£¸Ã»î¶¯µÄÖ¸±êº­¸Ç¸÷¸öµØÓòµÄ¸÷¸öóÒ×´¹Ö±ÁìÓò£¬Ô̺¬ÃÀ¹ú¡¢ÄáÈÕÀûÑÇ¡¢°Í»ù˹̹¡¢¶ò¹Ï¶à¶û¡¢µÂ¹ú¡¢°£¼°¡¢Ó¢¹ú¡¢²¨À¼¡¢·ÆÂɱö¡¢Å²Íþ¡¢ÈÕ±¾¡¢ÐðÀûÑǺÍÍÁ¶úÆä ¡£¹¥»÷Á´Éæ¼°Óû§Í¨¹ýÍøÂçä¯ÀÀÆ÷ÏÂÔØ¼Ù×°³ÉµçÓ°ÎļþµÄÎļþ£¬´Ó¶øÔö³¤ÁË´ó¹æÄ£¹¥»÷µÄ¿ÉÄÜÐÔ ¡£¸Ã»î¶¯ÖµÍ×ÌùÐĵÄÊÇ£¬ËüÀûÓÃÁË CryptBot µÄ¸üа汾£¬ÆäÖÐÔ̺¬Ðµķ´·ÖÎö¼¼Êõ£¬²¢ÇÒ»¹²¶»ñÃÜÂëÖÎÀíÆ÷ÀûÓ÷¨Ê½Êý¾Ý¿âºÍÉí·ÝÑéÖ¤Æ÷ÀûÓ÷¨Ê½ÐÅÏ¢ ¡£


https://thehackernews.com/2024/04/coralraider-malware-campaign-exploits.html


2. Change Healthcare×îÖÕÖ§¸¶Êê½ð½«Ãæ¶ÔÊý¾Ýй¶µÄ·çÏÕ


4ÔÂ24ÈÕ£¬ÔÚÀÕË÷Èí¼þ±ÀÀ£ÆðÍ·Á½¸ö¶àÔºó£¬ÀÕË÷Èí¼þµÄÓ°Ïì¿°³ÆÍøÂ簲ȫʷÉÏ×îÑϳÁµÄÒ»´Î£¬Ò½Áƹ«Ë¾ Change Healthcare ÖÕÓÚ֤ʵÁËÍøÂç·¸×ï·Ö×Ó¡¢°²È«×êÑÐÈËÔ±ºÍ±ÈÌØ±ÒÇø¿éÁ´ÒѾ­ËµµÃºÜÃ÷ÏÔµÄʼþ£ºËüµÄÈ·×öµ½ÁËÏòÖÙ´º·ÝÏ®»÷¸Ã¹«Ë¾µÄºÚ¿ÍÖ§¸¶Êê½ð ¡£È»¶ø£¬ËüÒÀÈ»Ãæ¶Ô³ÁÃÔʧ´óÁ¿¿Í»§Ãô¸ÐÒ½ÁÆÊý¾ÝµÄ·çÏÕ ¡£Change Healthcare ËÆºõÒÑÓÚ 3 Ô 1 ÈÕÖ§¸¶ÁËÊê½ð£¬²¢Ö¸³öÒ»±Ê 350 ±ÈÌØ±Ò£¨Ô¼ºÏ 2200 ÍòÃÀÔª£©µÄÂòÂô±»·¢Ë͵½Óë AlphV ºÚ¿ÍÓйصļÓÃÜÇ®°üÖÐ ¡£Õâ±ÊÂòÂôÊ×ÏÈÔÚÃûΪ RAMP µÄ¶íÂÞË¹ÍøÂç·¸×ïÂÛ̳ÉϵÄÒ»ÌõÐÂÎÅÖеõ½Ç¿µ÷£¬ÆäÖÐһλ¾Ý³Æ±» AlphV ÅׯúµÄºÏ×÷ͬ°é±§Ô¹Ëµ£¬ËûÃÇûÓÐÊÕµ½ Change Healthcare ¸¶¿îÖеķֳÉ ¡£


https://news.hitb.org/content/change-healthcare-finally-admits-it-paid-ransomware-hackers-and-still-faces-patient-data


3. Î÷°àÑÀ³ÁÐÂÆô¶¯¶Ô Pegasus ¼äµýÈí¼þ°¸¼þµÄµ÷²é


4ÔÂ23ÈÕ£¬Î÷°àÑÀ¹ú¶È·¨Ôº·¨¹Ù°µÊ¾£¬ÓÐÀíÓÉÏàÐÅ·¨¹úÌṩµÄÐÂÐÅÏ¢Äܹ»¡°Èõ÷²é»ñµÃ½øÕ¹¡± ¡£ÕâÁ½Ïîµ÷²é¾ùÉæ¼°ÉæÏÓʹÓÃÒÔÉ«ÁÐ NSO ¼¯ÍÅ¿ª·¢µÄ Pegasus ¼äµýÈí¼þ ¡£¼äµýÈí¼þ»á͵͵µØÉøÈëµÃÊÖ»ú»òÆäËûÉ豸ÖÐÒÔÍøÂçÊý¾Ý²¢¿ÉÄܼලÆäËùÓÐÕß ¡£NSO Ðû³Æ£¬Ëü½öÌṩ¸øµ±¾ÖÓÃÓÚ½ø¹¥¿Ö²ÀÖ÷ÒåºÍÆäËû°²È«Íþв ¡£Æ¾¾Ý°²È«×êÑÐÈËÔ±ºÍ 2021 ÄêÈ«ÇòýÌåµ÷²é£¬Pegasus Òѱ»ÓÃÀ´¹¥»÷ 50 ¸ö¹ú¶ÈµÄ 1,000 ¶àÈË£¬ÆäÖÐÔ̺¬»î¶¯ÈËÊ¿ºÍ¼ÇÕß ¡£Î÷°àÑÀÓÚ 2022 Äê 5 Ô°䷢£¬Ê×ÏàÅåµÂÂÞ¡¤É£ÇÐ˹¼°ÆäÈýÃû²¿³¤£¬Ô̺¬¹ú·À²¿³¤ºÍÄÚÕþ²¿³¤£¬ÒѳÉΪPegasus ¼äµýÈí¼þµÄÖ¸±ê ¡£Óɴ˲úÉúµÄ˾·¨µ÷²éÒòδÄÜ»ñµÃÁ˾ֶøÁÙʱ¸éÖà ¡£


https://www.securityweek.com/spain-reopens-a-probe-into-a-pegasus-spyware-case-after-a-french-request-to-work-together/


4. ºÚ¿Í½Ù³Ö·À²¡¶¾¸üÐÂÒÔ·Ö·¢ºóÃźÍÍÚ¿óGuptiMiner


4ÔÂ23ÈÕ£¬³¯ÏʺڿÍÒ»ÏòÔÚÀûÓà eScan ·À²¡¶¾Èí¼þµÄ¸üлúÔìÔÚ´óÐÍÆóÒµÍøÂçÉÏÖ²ÈëºóÃÅ£¬²¢Í¨¹ý GuptiMiner ¶ñÒâÈí¼þ´«²¼¼ÓÃÜÇ®±Ò¿ó¹¤ ¡£×êÑÐÈËÔ±½« GuptiMiner ÃèÊöΪ¸ß¶È¸´ÔÓµÄÍþв£¬ËüÄܹ»Ïò¹¥»÷ÕßµÄ DNS ·þÎñÆ÷Ö´ÐÐ DNS ÒªÇ󣬴ÓͼÏñÖÐÌáÈ¡ÓÐЧ¸ºÔØ£¬¶ÔÆäÓÐЧ¸ºÔؽøÐÐÊðÃû£¬²¢Ö´ÐÐ DLL ²àÃæ¼ÓÔØ ¡£GuptiMiner ±³ºóµÄÍþвÐÐΪÕßÓµÓÐÖÐÑëµÐÊÖ (AitM) µÄְ룬Äܹ»½Ù³ÖÕý³£µÄ²¡¶¾½ç˵¸üаü£¬²¢½«Æä´úÌæÎªÃûΪ¡°updll62.dlz¡±µÄ¶ñÒâ°ü ¡£¸Ã¶ñÒâÎļþÔ̺¬±ØÒªµÄ·À²¡¶¾¸üÐÂÒÔ¼°ÃûΪ¡°version.dll¡±µÄ DLL Îļþ´ó¾ÖµÄ GuptiMiner ¶ñÒâÈí¼þ ¡£eScan ¸üз¨Ê½Õý³£´¦Öøðü£¬½âѹ²¢Ö´ÐÐËü ¡£Ôڴ˽׶Σ¬DLL ÓÉ eScan µÄºÏ·¨¶þ½øÔìÎļþÅÔ¼ÓÔØ£¬´Ó¶ø¸³Óè¶ñÒâÈí¼þϵͳ¼¶È¨ÏÞ ¡£


https://www.bleepingcomputer.com/news/security/hackers-hijack-antivirus-updates-to-drop-guptiminer-malware/


5. Ó볯ÏÊÓйØÁªµÄ APT ×éÖ¯¶Ô×¼º«¹ú¹ú·À³Ð°üÉÌ


4ÔÂ23ÈÕ£¬º«¹ú¹ú¶È¾¯Ô±ÌüÖÒ¸æ³Æ£¬Ó볯ÏÊÓйصÄÍþвÐÐΪÕßÕýÒÔ¹ú·À¹¤ÒµÊµÌåΪָ±ê£¬ÇÔÈ¡¹ú·À¼¼ÊõÐÅÏ¢ ¡£¾Ýº«¹ú¹ú¶È¾¯Ô±Ìü±¨Â·£¬Ó볯ÏÊÓйØÁªµÄ APT ×éÖ¯Lazarus¡¢AndarielºÍKimsuky¹¥»÷Á˺«¹ú¶à¼Ò¹ú·ÀÓйصĹ«Ë¾ ¡£¾¯Ô±ÌüºÍ¹ú·À²É¹º´òËãÖÎÀí¾Ö£¨DAPA£©¶ÔÖ¸±ê×éÖ¯µÄ»·¾³½øÐÐÁËһϵÁгö¸ñ²é³­ ¡£½áºÏ²é³­ÓÚ1ÔÂ15ÈÕÖÁ2ÔÂ16ÈÕ½øÐУ¬ÊÜÓ°Ïì×éÖ¯Ö´ÐÐÁË·À»¤´ëÊ© ¡£¾¯·½°µÊ¾£¬ÕâЩϮ»÷ÊÇÒÔÈ«ÃæÕ½ÕùµÄ´ó¾Ö½øÐеÄ£¬¶à¸ö APT ×éÖ¯²Î¼ÓÆäÖÐ ¡£µ±¾Öר¼ÒÖÒ¸æËµ£¬¹¥»÷ÕßѡȡÁ˸´Ôӵĺڿͼ¼Êõ ¡£º«¹ú¹ú¶È¾¯Ô±ÌüÌṩÁË·ÖÆç APT ×éÖ¯Ö´ÐеÄÂŴι¥»÷µÄ¾ßÌåÐÅÏ¢ ¡£


https://securityaffairs.com/162193/apt/north-korea-south-korean-defense-contractors.html


6. ÃÀ¹ú²ÆÕþ²¿ºÍ¹úÎñÔºÒÔ¼°¶à¼Ò»ú¹¹µÄϵͳÔâµ½ºÚ¿Í¹¥»÷


4ÔÂ23ÈÕ£¬ËÄÃûÒÁÀʺڿÍÔÚÂü¹þ¶ÙÁªÍõ·¨Ôº±»¸æ×´£¬±»Ö¸¿ØÕë¶ÔÃÀ¹úµ±²¿ÃÅÃÅ¡¢¹ú·À³Ð°üÉ̺Í˽Ӫ¹«Ë¾·¢Õ¹¸´ÔÓµÄÍøÂç¼äµý»î¶¯ ¡£Ä¿Ç°ÈÔÔÚÌӵı»¸æ±»Ö¸¿ØÕë¶ÔÃÀ¹ú²ÆÕþ²¿ºÍ¹úÎñÔºÒÔ¼°Ê®¼¸¼Ò¿ÉÄÜ»ñÈ¡¹ú·ÀÓйØÐÅÏ¢µÄÃÀ¹ú˽Ӫ¹«Ë¾µÄ¹Ø¼üϵͳ½øÐй¥»÷ ¡£Ë¾·¨²¿Ôð¹ÖºÚ¿ÍʹÓöî±íµÄÉç»á¹¤³Ì¼¼Êõ£¬Ô̺¬¼ÙÒâÅ®ÐÔÀ´»ñÈ¡Êܺ¦ÕßµÄÐÅÀµ ¡£Æ¾¾ÝδÃÜ·âµÄ¸æ×´Ê飬¸ÃºÚ¿Í×éÖ¯µÄ¹¥»÷µÄÊܺ¦ÕßÖØÒªÊǾ­¹ýÐí¿ÉµÄ¹ú·À³Ð°üÉÌ£¬ÕâЩ¹«Ë¾ÒÑ»ñµÃÃÀ¹ú¹ú·À²¿µÄ°²È«Ðí¿É£¬Äܹ»½Ó¼û¡¢½Ó¹ÜºÍ´æ´¢»úÃÜÐÅÏ¢ ¡£¸Ã×éÖ¯»¹±»Ö¸¿ØÕë¶ÔÒ»¼Ò×ܲ¿Î»ÓÚŦԼµÄ¹ÜÕÊʦÊÂÎñËùºÍÒ»¼Ò×ܲ¿Î»ÓÚŦԼµÄ¾Æµê¹«Ë¾ ¡£ÔÚ¸æ×´ÊéÆô·âµÄͬʱ£¬ÃÀ¹ú¹úÎñÔº»¹°ä·¢ÐüÉÍ 1000 ÍòÃÀÔª£¬¼Î½±ÌṩÏßË÷×¥»ñËûÃÇ£¬²ÆÕþ²¿»¹¶ÔÉæ°¸Ó×ÎÒÖ´ÐÐÁËÔì²Ã ¡£


https://www.securityweek.com/10-million-bounty-on-iranian-hackers-for-cyber-attacks-on-us-gov-defense-contractors/