RedLine¶Ô×¼¶íÂÞ˹µÁ°æÆóÒµÈí¼þÓû§½øÐÐÐÅÏ¢ÇÔÈ¡
°ä²¼¹¦·ò 2024-12-101. RedLine¶Ô×¼¶íÂÞ˹µÁ°æÆóÒµÈí¼þÓû§½øÐÐÐÅÏ¢ÇÔÈ¡
12ÔÂ8ÈÕ£¬×Ô2024Äê1ÔÂÆð£¬RedLineÐÅÏ¢ÇÔÈ¡»î¶¯ÆðÍ·Õë¶ÔʹÓõÁ°æÆóÒµÈí¼þµÄ¶íÂÞ˹ÆóÒµ¡£ÕâЩµÁ°æÈí¼þͨ¹ý¶íÂÞ˹ÔÚÏßÂÛ̳·Ö·¢£¬¹¥»÷Õ߯æÃîµØ½«¶ñÒâÈí¼þ¼Ù×°³É¿ÉÈÆ¹ýÒµÎñ×Ô¶¯»¯Èí¼þÐí¿ÉµÄ¹¤¾ß£¬³ö¸ñÊÇͨ¹ý¶È·¢¶ñÒâ°æ±¾µÄHPDxLIB¼¤»îÆ÷¡£ÓëºÏ·¨°æ±¾·ÖÆç£¬¶ñÒâ°æ±¾ÔÚ.NETÖй¹½¨£¬²¢Ê¹ÓÃ×ÔÊðÃûÖ¤Êé¡£¿¨°Í˹»ù»ã±¨Ö¸³ö£¬ÕâЩδ¾ÊÚȨµÄÆóÒµÒµÎñÁ÷³Ì×Ô¶¯»¯Èí¼þÓû§³ÉΪ¹¥»÷Ö¸±ê£¬¹¥»÷ÕßÔÚ¹ÜÕÊÂÛ̳ÉÏ·Ö·¢º¬ÓÐRedLineÇÔÈ¡·¨Ê½µÄ¶ñÒ⼤»î·¨Ê½¡£¸Ã·¨Ê½Ê¹ÓÃ.NET Reactor½øÐлìºÏ£¬¶ñÒâ´úÂë¾¹ý¶à²ãѹËõºÍ¼ÓÃÜ£¬°µ²Ø·½Ê½¼«¶È²»Ñ°³£¡£¹¥»÷ÕßÔÚÓйØÂÛ̳Éϰ䲼¶ñÒ⼤»îÆ÷Á´½Ó£¬²¢Ìṩ½ûÓð²È«Èí¼þÒÔÔËÐ줻îÆ÷µÄ¾ßÌå×¢Ã÷£¬ÒÔÌӱܼì²â¡£Óû§±»ÓÕÆÓü¤»îÆ÷ÖеĶñÒâ¿â´úÌæºÏ·¨µÄtechsys.dll¿â£¬´Ó¶øÔÚÖ´ÐÐÈí¼þʱͨ¹ýºÏ·¨¹ý³Ì¼ÓÔØ¶ñÒâ¿â£¬ÔËÐÐÇÔÈ¡·¨Ê½¡£RedLineÇÔÈ¡·¨Ê½×Ô2020ËêÊ×±ã»îÔ¾£¬ÄÜ´ÓϵͳÖÐÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬Ô̺¬Í´´¦¡¢cookie¡¢ä¯ÀÀÆ÷º¹Çà¼Í¼¡¢ÐÅÓþ¿¨Êý¾ÝºÍ¼ÓÃÜÇ®°üµÈ¡£
https://securityaffairs.com/171771/cyber-crime/redline-info-stealer-campaign-targets-russian-businesses.html
2. °²ÄÈÑÅ¿ËÒ½ÔºÔâÀÕË÷Èí¼þ¹¥»÷£¬31ÍòÓ໼ÕßÊý¾Ýй¶
12ÔÂ7ÈÕ£¬°²ÄÈÑÅ¿ËÒ½ÔºÊÇÒ»¼ÒλÓÚÂíÈøÖîÈûÖݵķÇͶ»úÐÔÉçÇøÒ½Ôº£¬Õ¼ÓÐ83ÕÅ´²Î»¡¢200ÃûҽʦºÍ1200Ãû¹¤×÷ÈËÔ±£¬Îª±¾µØ¾ÓÃñÌṩ¸ù»ùÒ½ÁÆ·þÎñ¡£2023Äê12ÔÂ25ÈÕ£¬¸ÃÒ½ÔºÔâ·êÁËÀÕË÷Èí¼þ¹¥»÷£¬µ¼Ö³¬¹ý310,000Ãû»¼ÕßµÄÃô¸Ð½¡È«Êý¾Ý±»Ð¹Â¶¡£Ò½Ôºµ±¼´²ÉÈ¡Ðж¯£¬ÏÂÏßϵͳ²¢Ïò·¨Âɲ¿ÃÅ·¢³ö¾¯±¨¡£2024Äê1ÔÂ19ÈÕ£¬¡°Money Message¡±ÀÕË÷Èí¼þÍÅ»ïÆðÍ·¹«¿ªÀÕË÷¸ÃÒ½Ôº£¬²¢ÔÚÆä°µÍøÀÕË÷ÍøÕ¾ÉÏй¶Á˾ݳƴÓÒ½ÔºÇÔÈ¡µÄÊý¾ÝÑù±¾¡£Ò½ÔºÖÎÀíÈËÔ±²¢Î´ÓëÍþвÐÐΪÕß½»É棬×îÖÕÓÚ1ÔÂ26ÈÕ°ä²¼ÁËËùº±¼û¾Ý¡£¾¹ý³¹µ×µÄȡ֤µ÷²é£¬Ò½ÔºÓÚ2024Äê11ÔÂ5ÈÕʵÏÖÁ˶Ôй¶Êý¾ÝµÄÉó²é£¬²¢Í¨ÖªÁËÊÜÓ°ÏìµÄÓ×ÎÒ¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬È˶¡Í³¼ÆÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢¡¢½¡È«±£ÏÕÐÅÏ¢¡¢Éç»á°²È«ºÅÂë¡¢¼ÝÊ»ÅÆÕÕºÅÂë¡¢²ÆÕþÐÅÏ¢µÈ¡£Ö»¹ÜҽԺûÓм£ÏóÅú×¢ÕâÆðÊÂÎñµ¼ÖÂÁËÈκÎÚ²ÆÐÐΪ£¬µ«»¹ÊÇÌáÐÑÔ±¹¤ºÍ»¼ÕßҪά³Ö¾¯Ì裬²¢ÌṩÁËΪÆÚ24¸öÔµÄÉí·Ý±£»¤ºÍÐÅÓþ¼à¿Ø·þÎñ¡£
https://www.bleepingcomputer.com/news/security/anna-jaques-hospital-ransomware-breach-exposed-data-of-300k-patients/
3. ÂÞÂíÄáÑÇÄÜÔ´¹©¸øÉÌElectrica GroupÔâ·êÀÕË÷Èí¼þ¹¥»÷
12ÔÂ10ÈÕ£¬ÂÞÂíÄáÑÇÄÜÔ´¹©¸øÉÌElectrica GroupÕýÃæ¶Ôһ·³ÖÐøµÄÀÕË÷Èí¼þ¹¥»÷£¬µ«¸Ã¹«Ë¾ÒÑÏòͶ×ÊÕß±£ÕÏ£¬Æä¹Ø¼üϵͳ²¢Î´Êܵ½Ó°Ï졣ΪÁ˱£ÏÕÔËÓªºÍÓ×ÎÒÊý¾ÝµÄ°²È«£¬ElectricaÒÑÆô¶¯ÄÚ²¿ÍøÂ簲ȫºÍ̸£¬²¢Óë¹ú¶ÈÍøÂ簲ȫ»ú¹¹ºÏ×÷£¬Ö¼ÔÚ¼ø±ð¹¥»÷Ô´²¢½ÚÔìÆäÓ°Ïì¡£ElectricaÊÇÂÞÂíÄáÑǵçÁ¦ÅäËͺ͹©¸øÊг¡µÄÖØÒª²Î¼ÓÕߣ¬Îª³¬¹ý380Íò¿Í»§Ìṩ·þÎñ£¬²¢ÔÚ²¼¼ÓÀÕË¹ÌØºÍÂ×¶ØÖ¤È¯ÂòÂôËùÉÏÊС£±¾ÖÜÔçЩʱ³½£¬¸Ã¹«Ë¾°ä²¼Í¨Öª£¬·î¸æÍ¶×ÊÕßÔÚ²úÉúµÄÍøÂç¹¥»÷£¬²¢Ç¿µ÷ËùÓÐÌØ¶¨µÄÏìÓ¦ºÍ̸ÒÑÆ¾¾ÝÄÚ²¿·¨Ê½ºÍÏÖÐÐÂÉÀýÆô¶¯¡£ÂÞÂíÄáÑÇÄÜÔ´²¿Ö¤Êµ¸Ã¹«Ë¾µÄÈ·Ôâ·êÁËÀÕË÷Èí¼þ¹¥»÷£¬µ«¹¥»÷²¢Î´Ó°Ïì¸Ã¹«Ë¾µÄSCADAϵͳ¡£µý±¨·ÖÎöÈËÊ¿ÒÔΪ£¬Õâ´ÎÏ®»÷¿ÉÄÜÊÇÇ×¶í¼¯Ìå·¢ÆðµÄ£¬Ö¼ÔÚ±¨³ðÂÞÂíÄáÑÇÒò¶íÂÞË¹ÉæÏÓ¹ýÎʶøÈ¡µÞ×Üͳѡ¾Ù¡£ÂÞÂíÄáÑǵý±¨¾Öй©£¬³¬¹ý85,000´ÎÍøÂç¹¥»÷Õë¶Ô¸Ã¹úÑ¡¾Ùϵͳ£¬µ«ÄªË¹¿Æ·ñ¶¨¶Ô´Ë½øÐÐÈκι¥»÷¡£Electrica Group½¨Òé¿Í»§¶ÔDZÔÚµÄÍøÂç´¹µö³¢ÊԺͿÉÒÉͨѶά³Ö¾¯Ìè¡£
https://securityaffairs.com/171832/hacking/electrica-group-ransomware-attack.html
4. ÐÄÔà±í¿ÆÒ½ÁÆÉ豸Ôì×÷ÉÌArtivionÔâÀÕË÷Èí¼þ¹¥»÷
12ÔÂ9ÈÕ£¬ÐÄÔà±í¿ÆÒ½ÁÆÉ豸Ôì×÷ÉÌArtivionÔÚ11ÔÂ21ÈÕÔâ·êÁËÀÕË÷Èí¼þ¹¥»÷£¬¸Ã¹¥»÷ÇÖÈÅÁËÆäÔËÓª²¢µ¼Ö²¿ÃÅϵͳ¹Ø¹Ø¡£Artivion×ܲ¿Î»ÓÚÑÇÌØÀ¼´ó£¬È«ÇòÔ±¹¤³¬¹ý1,250Ãû£¬ÔÚ100¶à¸ö¹ú¶ÈÉèÓÐÏúÊÛ´ú±í£¬²¢ÔÚÑÇÌØÀ¼´ó¡¢°Â˹͡ºÍºÚÐÀ¸ùÉèÓÐÔì×÷¹¤³§¡£¾ÝArtivionÏòÃÀ¹ú֤ȯÂòÂôίԱ»áÌá½»µÄ»ã±¨£¬¹¥»÷Õß¼ÓÃÜÁËÆä²¿ÃÅϵͳ²¢ÇÔÈ¡ÁËÊý¾Ý£¬µ«¹«Ë¾ÔËÓª¡¢¶©µ¥´¦ÖúÍÔËÊäÖжÏÎÊÌâÒѸù»ùµÃµ½½â¾ö¡£¹ÌÈ»ÉÐδÓÐÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬µ«ArtivionÒÔΪ¿ÉÄÜ»á²úÉú±£ÏÕδº¸ÇµÄ¶î±íÓöȡ£½üÆÚ£¬ÃÀ¹úÒ½ÁƱ£½¡ÐÐÒµÒ²Ôâ·êÁ˶àÆðÀÕË÷Èí¼þ¹¥»÷£¬Ô̺¬Boston Children's Health PhysiciansºÍUMCÒ½ÁÆÏµÍ³£¬ÒÔ¼°È¥ÄêÊ¥µ®½ÚÔâ·ê¹¥»÷µÄ°²ÄÈÑÅ¿ËÒ½Ôº£¬ÕâЩ¹¥»÷¶¼µ¼ÖÂÁËÃô¸ÐÊý¾ÝµÄй¶ºÍÔËÓªµÄÖжϡ£
https://www.bleepingcomputer.com/news/security/ransomware-attack-hits-leading-heart-surgery-device-maker/
5. ΢Èí½â³ý¶ÔUbisoftÓÎÏ·Windows 24H2¸üÐÂÏÞ¶È
12ÔÂ9ÈÕ£¬Î¢ÈíÒѲ¿ÃÅ»¯³ýÁ˶ÔWindows 24H2¸üÐÂÓëijЩUbisoftÓÎϷϵͳ¼æÈÝÐÔµÄÏÞ¶È¡£´Ëǰ£¬ÓÉÓÚ¡¶´Ì¿ÍÐÅÌõ¡·¡¢¡¶ÐÇÇò´óÕ½£º·¨±í¿ñͽ¡·ºÍ¡¶°¢·²´ï£ºÅ˶àÀ±ß½®¡·µÅ×ÎÏ·ÔÚWindows 11 24H2Ô¤ÀÀ°æÖгöÏÖ±ÀÀ£¡¢ËÀ»úºÍÒôƵÎÊÌ⣬΢Èí×èÖ¹ÁË×°ÓÐÕâЩÓÎÏ·µÄPC½øÐÐWindows 24H2Éý¼¶¡£Óû§·´À¡ÏÔʾ£¬ÓÎÏ·´æÔÚ²»²»±äÇé¿ö£¬ÈçÆô¶¯ºóµ±¼´±ÀÀ£»ò¼ÓÔØ±£ÁôÓÎÏ·ºó¼¸·ÖÖÓÄÚ±ÀÀ£¡¢¶³½á»òºÚÆÁ¡£ÎªÔ¤·ÀÎÊÌâÀ©É¢£¬Î¢Èí²ÉÈ¡Á˱£»¤´ëÊ©¡£´Ë¿Ì£¬ÔÚUbisoft°ä²¼Ò»Ê±½¨²¹·¨Ê½»º½â±ÀÀ£ÎÊÌâºó£¬Î¢Èí½â³ýÁ˶ԡ¶ÐÇÇò´óÕ½£º·¨±í¿ñͽ¡·ºÍ¡¶°¢·²´ï£ºÅ˶àÀ±ß½®¡·µÄÉý¼¶ÏÞ¶È£¬µ«½¨ÒéÍæ¼ÒÔÚÎÊÌâ½â¾öǰ²»ÒªÊ¹ÓÃWindows 11×°Öø±ÊÖ»òýÌå´´½¨¹¤¾ßÉý¼¶ÊÜÓ°ÏìPC¡£Í¬Ê±£¬Î¢Èí»¹°ä·¢×èÖ¹×°ÖÃÁ˹ýÆÚGoogle Workspace SyncµÄϵͳºÍÓµÓв»¼æÈÝÓ¢ÌØ¶ûÖÇÄÜÉùÒô¼¼ÊõÒôƵÇý¶¯·¨Ê½µÄÉ豸½øÐÐWindows 11 24H2¸üУ¬ÓÉÓÚÕâЩ»áµ¼ÖÂOutlookÆô¶¯ÎÊÌâºÍÀ¶ÆÁËÀ»úÎÊÌâ¡£
https://www.bleepingcomputer.com/news/microsoft/ubisoft-fixes-windows-11-24h2-conflicts-causing-game-crashes/
6. ³¯ÏʺڿÍCitrine SleetµÁÈ¡Radiant Capital 5000ÍòÃÀÔª¼ÓÃÜÇ®±Ò
12ÔÂ9ÈÕ£¬È¥ÖÐÐÄ»¯½ðÈÚ(DeFi)ƽ̨Radiant CapitalÔÚ10ÔÂ16ÈÕ°ä·¢ÆäϵͳÔâ·êÍøÂç¹¥»÷£¬µ¼ÖÂ5000ÍòÃÀÔª¼ÓÃÜÇ®±Ò±»µÁ¡£ÔÚMandiantÍøÂ簲ȫר¼ÒµÄÐÖúÏ£¬Radiant¶ÔÕâ´Î¹¥»÷½øÐÐÁËÉî¿Ìµ÷²é£¬²¢È·¶¨Ä»ºóºÚÊÖΪ³¯Ïʹú¶È´ÓÊôºÚ¿Í×éÖ¯Citrine Sleet£¨±ðÃû¡°UNC4736¡±ºÍ¡°AppleJeus¡±£©¡£Õâ´Î¹¥»÷ʼÓÚ9ÔÂ11ÈÕ£¬ºÚ¿Íͨ¹ýTelegram·¢ËͼÙÒâǰ³Ð°üÉ̵ĶñÒâÐÂÎÅ£¬ÓÕÆ¿ª·¢ÈËÔ±ÏÂÔØÔ̺¬¡°InletDrift¡±macOS¶ñÒâÈí¼þ¸ºÔصÄZIPÎļþ£¬´Ó¶øÔÚÊÜϰȾµÄÉ豸ÉϳÉÁ¢ºóÃÅ¡£ºÚ¿ÍÀûÓÃͨÀýµÄ¶à³ÁÊðÃûÈ˳̣¬ÒÔÂòÂôÃýÎóµÄÃûÒåÍøÂçÓÐЧÊðÃû£¬²¢´ÓArbitrumºÍ±Ò°²ÖÇÄÜÁ´(BSC)Êг¡ÇÔÈ¡×ʽð¡£Õâ´Î¹¥»÷Éè¼ÆÓÅÔ½£¬ÈƹýÁËÓ²¼þÇ®°ü°²È«ºÍ¶à²ãÑéÖ¤£¬ÂòÂôÔÚÊÖ¶¯ºÍ·ÂÕÕ²é³Öп´ÆðÀ´¶¼ºÜÕý³££¬ÏÔʾ³ö¼«¸ßµÄ¸´ÔÓÐÔ¡£RadiantÔÚÓëÃÀ¹ú·¨Âɲ¿ÃźÍzeroShadowºÏ×÷£¬×·»Ø¾¡¿ÉÄܶàµÄ±»µÁ×ʽ𣬲¢Ç¿µ÷±ØÒª¸ü׳´óµÄÉ豸¼¶½â¾ö¹æ»®À´¼ÓÇ¿ÂòÂô°²È«ÐÔ¡£
https://www.bleepingcomputer.com/news/security/radiant-links-50-million-crypto-heist-to-north-korean-hackers


¾©¹«Íø°²±¸11010802024551ºÅ