΢ÈíÓ¡¶ÈXÕË»§±» Roaring Kitty ¼ÓÃÜÇ®±ÒȦÌ×½Ù³Ö

°ä²¼¹¦·ò 2024-06-05
1. ΢ÈíÓ¡¶ÈXÕË»§±» Roaring Kitty ¼ÓÃÜÇ®±ÒȦÌ×½Ù³Ö


6ÔÂ3ÈÕ£¬Õ¼Óг¬¹ý 211,000 Ãû¹Ø×¢ÕßµÄ΢ÈíÓ¡¶È¹Ù·½ Twitter Õ˺ű»¼ÓÃÜÇ®±ÒÆ­×Ó½Ù³Ö£¬²¢¼ÙÒâ³ôÃûÔ¶ÑïµÄÄ£Òò¹ÉƱÂòÂôÔ± Keith Gill ʹÓõÄÓû§Ãû Roaring Kitty¡£Î¢ÈíÓ¡¶ÈµÄ X ÕË»§×÷Ϊ¸Ãƽ̨ÉϹٷ½ÈÏÖ¤µÄ×éÖ¯£¬Õ¼Óлƽð֧Ʊ£¬ÕâʹµÃ½Ù³ÖÕßµÄÌû×Ó¸ü¾ßºÏ·¨ÐÔ¡£ÍþвÐÐΪÕßÀûÓà Gill ×î½üµÄ¸´³öÀ´ÒýÓÕDZÔÚÊܺ¦Õߣ¬²¢ÓüÓÃÜÇ®±ÒÇ®°üºÄ¾¡¶ñÒâÈí¼þϰȾËûÃÇ¡£ËûÃÇ´Ë¿ÌʹÓñ»½Ù³ÖµÄ΢ÈíÓ¡¶ÈÕË»§»Ø¸´ÍÆÎÄ£¬ÓÕÆ­¸Ã¹«Ë¾µÄ¹Ø×¢ÕßºÍ X ÉÏµÄÆäËûÈ˽øÈëÒ»¸ö¶ñÒâÍøÕ¾ (presaIe-roaringkitty[.]com)£¬¾Ý³Æ¸ÃÍøÕ¾ÔÊÐíËûÃDzɰì GameStop (GME) ¼ÓÃÜÇ®±Ò×÷ΪËùνԤÊÛµÄÒ»²¿ÃÅ¡£È»¶ø£¬ÍþвÐÐΪÕß»áÇÔÈ¡Èκν«¼ÓÃÜÇ®±ÒÇ®°üÏνӵ½¸ÃÍøÕ¾²¢ÊÚȨºÄ¾¡·þÎñ½øÐÐÂòÂôµÄÈ˵Ä×ʲú¡£ºÜ¶à»úеÈËÕË»§´Ë¿ÌÒ²ÔÚת·¢±»½Ù³ÖÕË»§µÄÍÆÎÄ£¬ÕâÖÖÕ½ÊõÖ¼ÔÚ±¨´ðµØÔö³¤¶ñÒâÌû×ӵĸ²¸ÇÃæ²¢ÓÕ²¶¸ü¶àÊܺ¦Õß¡£


https://www.bleepingcomputer.com/news/security/microsoft-indias-x-account-hijacked-in-roaring-kitty-crypto-scam-to-push-wallet-drainers/


2. Æ­×ÓÍþвй¶´Ó²¼¾°µ÷²é¹«Ë¾ÇÔÈ¡µÄÊýÒڱʼͼ


6ÔÂ3ÈÕ£¬¾Ý³Æ£¬·ðÂÞÀï´ïÖÝÒ»¼ÒÕÆ¹Ü²¼¾°µ÷²éºÍÆäËûÓ×ÎÒÐÅÏ¢ÒªÇóµÄ¹«Ë¾»ñÈ¡ÁËÊýÊ®ÒڷݼͼÈËÃÇÓ×ÎÒÐÅÏ¢µÄ¼Í¼£¬ÕâЩ¼Í¼¿ÉÄܺܿì¾Í»á±»Ð¹Â¶µ½ÍøÉÏ¡£Ò»¸ö×Ô³Æ USDoD µÄ·¸×ïÍÅ»ïÓÚ 4 ÔÂÔÚµØÏÂÂÛ̳ÉÏÒÔ350 ÍòÃÀÔªµÄ¼ÛÖµÏúÊÛ¸ÃÊý¾Ý¿â£¬²¢ÁîÈËÄÑÒÔÏàÐŵÄÊÇÐû³Æ¸ÃÊý¾Ý¿âÔ̺¬ 29 ÒÚÌõÃÀ¹ú¡¢¼ÓÄôóºÍÓ¢¹ú¹«ÃñµÄ¼Í¼¡£¾ÝÐÅ£¬Ò»Ãû»ò¶àÃû×Ô³Æ SXUL µÄ·¸×ïÍÅ»ï¶ÔÕâ´ÎËùνµÄÊý¾Ýй¶ÊÂÎñ¸ºÓÐÔðÈΣ¬ËûÃǽ«Êý¾Ýй¶ÊÂÎñ½»¸øÁË³ä°ø±ß¼äÈ赀 USDoD¡£¾Ý³Æ£¬±»µÁÐÅÏ¢Ô̺¬Ó×ÎÒÈ«Ãû¡¢µØÖ·ºÍÖÁÉÙ 30 ÄêǰµÄµØÖ·º¹Çà¡¢Éç»á°²È«ºÅÂëÒÔ¼°ÈËÃǵĸ¸Ä¸¡¢ÐֵܽãÃúÍÇׯÝ£¬ÆäÖÐһЩÈËÒѾ­¹éÌì½ü 20 Äê¡£¾ÝÃÀ¹ú¹ú·À²¿³Æ£¬ÕâЩÐÅÏ¢²¢·Ç´Ó¹«¹²ÆðԴץȡµÄ£¬Ö»¹ÜÊý¾Ý¿âÖпÉÄÜ´æÔÚ³Á¸´µÄÌõ¿î¡£


https://www.theregister.com/2024/06/03/usdod_data_dump/


3. Telegram ÉÏй¶µÄ 3.61 ÒÚ¸ö±»µÁÕË»§±»Ôö³¤µ½ HIBP


6ÔÂ3ÈÕ£¬´óÁ¿ 3.61 ÒÚ¸öµç×ÓÓʼþµØÖ·±»Ôö³¤µ½ Have I Been Pwned Êý¾Ýй¶֪ͨ·þÎñÖУ¬ÕâЩµØÖ·À´×Ôͨ¹ýÃÜÂëÇÔÈ¡¶ñÒâÈí¼þ¡¢Æ¾Ö¤Ìî³ä¹¥»÷ºÍÊý¾Ýй¶ÇÔÈ¡µÄƾ֤£¬ÈκÎÈ˶¼Äܹ»²é³­ËûÃǵÄÕÊ»§ÊÇ·ñÒѱ»Ð¹Â¶¡£ÍøÂ簲ȫ×êÑÐÈËÔ±´Ó¶à¶à Telegram ÍøÂç·¸×ïÆµÂ·ÍøÂçÁËÕâЩƾ֤£¬ÕâЩ±»µÁÊý¾Ýͨ³£±»Ð¹Â¶¸øÆµÂ·µÄÓû§ÒÔ³ÉÁ¢ÃûÓþºÍ¶©ÔÄÕß¡£±»µÁÊý¾Ýͨ³£ÒÔÓû§ÃûºÍÃÜÂë×éºÏ£¨Í¨³£Í¨¹ýƾ֤Ìî³ä¹¥»÷»òÊý¾Ýй¶ÇÔÈ¡£©¡¢Óû§ÃûºÍÃÜÂëÒÔ¼°ÓëÖ®ÓÐ¹ØµÄ URL£¨Í¨¹ýÇÔÈ¡ÃÜÂëµÄ¶ñÒâÈí¼þÇÔÈ¡£©ºÍԭʼ cookie£¨Í¨¹ýÇÔÈ¡ÃÜÂëµÄ¶ñÒâÈí¼þÇÔÈ¡£©µÄ´ó¾Öй¶¡£¸Ã×êÑÐÈËÔ±ÒªÇó BleepingComputer ά³ÖÄäÃû£¬ËûÃÇÓë Have I Been Pwned µÄËùÓÐÕß Troy Hunt ·ÖÏíÁË´Ó¶à¸ö Telegram ÆµÂ·ÍøÂçµÄ 122 GB ƾ֤¡£ÕâЩÊý¾Ý¼«¶ÈÖØ´ó£¬Ô̺¬ 3.61 ÒÚ¸öΨһµÄµç×ÓÓʼþµØÖ·£¬ÆäÖÐ 1.51 ÒÚ¸öµØÖ·ÒÔǰ´Óδ±»Êý¾Ýй¶֪ͨ·þÎñ¼û¹ý¡£


https://www.bleepingcomputer.com/news/security/361-million-stolen-accounts-leaked-on-telegram-added-to-hibp/


4. ÍþвÕßÐû³ÆÏúÊÛÔ̺¬1700ÍòÓû§¼Í¼µÄPandabuyÊý¾Ý¿â


6ÔÂ3ÈÕ£¬¾Ý±¨Â·£¬±»µÁÊý¾Ý¿âÔ̺¬¶à´ï 1700 ÍòÐÐÓû§¼Í¼£¬º­¸ÇÃû×Ö¡¢ÐÕÊÏ¡¢Óû§ ID¡¢µç×ÓÓʼþ¡¢¶©µ¥Êý¾Ý¡¢IP µØÖ·¡¢¹ú¶È¡¢ÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£ÍþвÕß Sanggiero ÒÑ¾ÍÆäÒâͼ°ä·¢ÉêÃ÷¡£ËûÃÇÐû³Æ£¬ÓÃÓÚ·ÛËé Pandabuy ·ÀÓùϵͳµÄ·ì϶£¨¾Ý³Æ¸Ã¹«Ë¾ÉÐδ½â¾ö£©½«ºÜ¿ìÔÚÆä²©¿ÍÍøÕ¾Éϰ䲼¡£´Ë±í£¬ËûÃÇ»¹°ä·¢³ïËãÅû¶ Pandabuy Ô±¹¤µÄÐÕÃûºÍÃÜÂ룬ֻ¹ÜÊÇÒÔʹÓà base-64 ¼ÓÃܵıàÂë´ó¾Ö¡£ÍþвÕßÖÒ¸æ Pandabuy ÈÔÓпÉÄܽøÐн»É棬µ«¹¦·ò²»¶àÁË¡£ËûÃÇΪ±»µÁÊý¾Ý¿â¿ª³öÁË 40,000 ÃÀÔªµÄ¸ß¼Û£¬Åú×¢ËûÃdzﱸ½«ÇÔÈ¡µÄÊý¾ÝÂô¸ø³ö¼Û×î¸ßµÄÈË¡£


https://dailydarkweb.net/threat-actor-claims-to-sell-pandabuy-database-with-17-million-user-records/


5. Discord¶ñÒâÈí¼þ¹¥»÷¼¤Ôö£¬·¢ÏÖ50000¸ö¶ñÒâÁ´½Ó


6ÔÂ3ÈÕ£¬ÔÚ×î½üÁù¸öÔµķÖÎöÖУ¬ÍøÂ簲ȫ¹«Ë¾ Bitdefender ·¢ÏÖÁËÒ»¸öÁîÈ˲»°²µÄÇ÷Ïò£ºÍøÂç·¸×ï·Ö×ÓÔÚʹÓÃÊ¢ÐеÄͨѶƽ̨ Discord À´´«²¼¶ñÒâÈí¼þ²¢Ö´ÐÐÍøÂç´¹µö»î¶¯¡£Bitdefender ÔÚ 2024 Äê 29 ÈÕÐÇÆÚÈý°ä²¼Ö®Ç°Óë Hackread.com ·ÖÏíÁ˸û㱨£¬ÆäÖгÁµã½éÉÜÁË Discord ÉÏ·¢ÏÖµÄ 50,000 ¶à¸ö¶ñÒâÁ´½Ó£¬ÏÔʾ³ö¸Ãƽ̨ԽÀ´Ô½ÈÝÒ×Êܵ½ÍøÂçÍþв¡£¶ñÒâÈí¼þºÍÍøÂç´¹µöÁ´½ÓÕ¼¼ì²âµ½µÄ¶ñÒâÁ´½ÓµÄ 39%¡£ÕâЩ¹¥»÷ͨ³£Éæ¼°ºýŪ¼¿Á©£¬ÓÕÆ­Óû§ÏÂÔØÓк¦Èí¼þ»òÌṩÃô¸ÐÐÅÏ¢¡£ÃÀ¹úÓû§ÓÈÆäÈÝÒ×Êܵ½¹¥»÷£¬Õ¼ÍþвµÄ 16.2%¡£ÕâʹËûÃdzÉΪ×îÈÝÒ×Êܵ½¹¥»÷µÄȺÌ壬²¢ÇÒÕ¼±ÈÏÔÖø¡£Í¨¹ý Discord ÌáÒé¶ñÒâ¹¥»÷µÄÆäËû¹ú¶È»¹Ô̺¬·¨¹ú¡¢ÂÞÂíÄáÑÇ¡¢Ó¢¹úºÍµÂ¹ú¡£


https://hackread.com/discord-malware-attacks-as-50000-malicious-links/


6. ÔÆ´æ´¢ Hudson Rock ¸æ×´ÐÅÏ¢°²È«»ú¹¹ Snowflake


6ÔÂ4ÈÕ£¬ÐÅÏ¢°²È«»ú¹¹»ã±¨³Æ£¬·¸×ï·Ö×ÓÀûÓÃÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ»ñÈ¡ÁË Snowflake Ô±¹¤µÄ¹¤×÷ƾ֤£¬²¢ÀûÓøÃÌØÈ¨½Ó¼ûȨÏÞ´Ó Snowflake µÄ¿Í»§ÔÆÕÊ»§ÖÐÇÔÈ¡ÁË´óÁ¿Êý¾Ý¡£Snowflake °µÊ¾£¬ÕâÖÖÇé¿ö²¢Ã»ÓвúÉú¡£ÖÁÉÙTicketmasterºÍSantander ÒøÐеÄÐÅÏ¢µÄÈ·±»µÁÁË£¬Ö»¹Ü¹Ù·½ÉÐδͨ´ï¾ßÌåÊÇÈôºÎ±»µÁµÄ£¬ÒÔ¼°´ÓÄÄÀï±»µÁµÄ£»ÕâÁ½¼ÒÒøÐж¼ÊÇ Snowflake µÄ¿Í»§¡£¾Ý±¨Â·£¬Ticketmaster µÄһλýÌå´ú±í֪ͨTechCrunch£¬Æä±»µÁÊý¾ÝÓÉ Snowflake ÍйÜ¡£Snowflake °µÊ¾£¬ÈôÊÇÓÐÈκοͻ§Êý¾Ý´ÓÆä·þÎñÆ÷Öб»ÇÔÈ¡£¬ÄÇôÕâЩÊý¾Ý¿ÉÄÜÊDZ»ÇÔÔôͨ¹ýÓÐÕë¶ÔÐÔµÄÍøÂç´¹µö¡¢ÆäËûйÃÜ»ò¶ñÒâÈí¼þµÈ·½Ê½»ñÈ¡ÁËÓ×ÎÒ¿Í»§µÄÕË»§Æ¾Ö¤¶ø»ñµÃµÄ£¬¶ø²»ÊÇͨ¹ý¶Ô Snowflake °²È«ÐÔµÄÆÕ±é·ÛËé¶ø»ñµÃµÄ¡£ÊÂʵÉÏ£¬Snowflake ÒÔΪ£¬Æä¡°ÓÐÏÞ¡±ÊýÁ¿ÉÐδй©ÐÕÃûµÄ¿Í»§µÄÊý¾Ý¿ÉÄܵÄÈ·±»ÇÔÈ¡µÄÕË»§Æ¾Ö¤½Ó¼û£¬¶øÕâЩÕË»§²¢Ã»ÓÐÆôÓÃË«³É·ÖÉí·ÝÑéÖ¤¡£


https://www.theregister.com/2024/06/04/snowflake_report_pulled/