ResolverRAT¶ñÒâÈí¼þ¹¥»÷È«ÇòÔìÒ©ºÍÒ½ÁƱ£½¡»ú¹¹

°ä²¼¹¦·ò 2025-04-16

1. ResolverRAT¶ñÒâÈí¼þ¹¥»÷È«ÇòÔìÒ©ºÍÒ½ÁƱ£½¡»ú¹¹


4ÔÂ14ÈÕ£¬½üÈÕ£¬Ò»ÖÖÃûΪ¡°ResolverRAT¡±µÄÐÂÐÍÔ¶³Ì½Ó¼ûľÂí£¨RAT£©ÔÚÈ«ÇòÁìÓòÄÚËÁŰ£¬³ÉΪ×éÖ¯ÐÅÏ¢°²È«µÄÒ»´óÍþв£¬ÓÈÆä¶ÔÒ½ÁƱ£½¡ºÍÔìÒ©ÐÐÒµ×é³ÉÁËÑϳÁÌôÕ½¡£ResolverRATͨ¹ý¾«ÐÄÉè¼ÆµÄÍøÂç´¹µöµç×ÓÓʼþ½øÐд«²¼£¬ÕâЩÓʼþ¼Ù×°³ÉÕë¶ÔÖ¸±ê¹ú¶È/µØÓò˵»°µÄºÏ·¨ÄÚÈÝ»òÉæ¼°°æÈ¨¼Óº¦µÄÖҸ棬ÓÕʹÓû§µã»÷Á´½ÓÏÂÔØ¿´ËƺϷ¨µÄ¿ÉÖ´ÐÐÎļþ¡°hpreader.exe¡±¡£ÏÖʵÉÏ£¬¸ÃÎļþÀûÓ÷´ÉäDLL¼ÓÔØ¼¼Êõ£¬½«ResolverRATÇÄÈ»×¢ÈëÄڴ棬ΪºóÐøµÄ¶ñÒâ»î¶¯Ì¯Æ½Â·Â·¡£Morphisec¹«Ë¾ÂÊÏÈ·¢ÏÖÁËÕâһδ±»¼Í¼µÄ¶ñÒâÈí¼þ£¬²¢Ö¸³öCheck PointºÍCisco TalosµÄ½üÆÚ»ã±¨ÖÐÒ²Ìá¼°ÁËÒ»ÑùµÄÍøÂç´¹µö»ù´¡ÉèÊ©£¬µ«Î´ÄÜ×½Äõ½ResolverRATÕâÒ»¹ÖÒìÓÐÐ§ÔØºÉ¡£ResolverRATÒÔÆä¸ß¶ÈÒñ±ÎÐÔºÍ׳´óµÄ¶ã±ÜÄÜÁ¦Öø³Æ£¬ÆëÈ«ÔÚÄÚ´æÖÐÔËÐУ¬ÀÄÓÃ.NET¡°ResourceResolve¡±ÊÂÎñ¼ÓÔØ¶ñÒⷨʽ¼¯£¬ÓÐЧ¶ã±ÜÁË´«Í³°²È«¼à¿Ø¡£¸ÃľÂíѡȡ¸´ÔÓµÄ״̬»ú¼¼Êõ»ìºÏ½ÚÔìÁ÷£¬Ê¹µÃ¾²Ì¬·ÖÎö±äµÃÒì³£ÄÑÌ⣬²¢Í¨¹ýÖ¸ÎÆ×ÊÔ´ÒªÇó¼ì²âɳºÐºÍ·ÖÎö¹¤¾ß£¬½øÒ»²½¼ÓÇ¿ÁËÆäÒñ±ÎÐÔ¡£´Ë±í£¬ResolverRAT»¹¾ß±¸×³´óµÄÊý¾Ýй¶ְÄÜ£¬Í¨¹ý¶È¿é»úÔì´«Êä´óÊý¾Ý£¬½«´óÓÚ1MBµÄÎļþÔ׸î³É16KBµÄ¿é£¬ÒÔÌӱܼì²â¡£


https://www.bleepingcomputer.com/news/security/new-resolverrat-malware-targets-pharma-and-healthcare-orgs-worldwide/


2. ÀÕË÷Èí¼þÇÖÈÅÁËÉö͸Îö¹«Ë¾DaVitaµÄ²¿ÃÅÔËÓª


4ÔÂ14ÈÕ£¬Éö͸Îö¾ÞÍ·DaVitaÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬²¿ÃÅÔËÓªÊÜÓ°Ïì¡£¸Ã¹«Ë¾ÓÚÖÜÁùÔâ·ê¹¥»÷£¬²¿ÃÅÍøÂç±»¼ÓÃÜ£¬ÖÜÒ»¹áÃÀ¹ú֤ȯÂòÂôίԱ»á´«µÝ´ËÊ¡£DaVitaµ±¼´Æô¶¯ÏìÓ¦·¨Ê½£¬Ö´ÐжôÔì´ëÊ©£¬Ô̺¬¸ôÀëÊÜÓ°Ïìϵͳ£¬²¢ÒÑÖ´ÐÐһʱ´ëÊ©ÒÔ¸´Ô­Ä³Ð©Ö°ÄÜ£¬µ«ÎÞ·¨¹À¼ÆÖжϵijÖÐø¹¦·ò»òˮƽ¡£Ä¿Ç°ÅжÏÕâ´ÎÏ®»÷¶Ô¹«Ë¾Ôì³ÉµÄ×ÜÌåÓ°Ï컹Ϊʱ¹ýÔç¡£DaVita×÷ΪȫÇò×î´óµÄÉöÔ໤ÀíÌṩÉÌÖ®Ò»£¬ÔÚÈ«ÇòÕ¼ÓÐ3166¼ÒÃÅÕï͸ÎöÖÐÐÄ£¬Ô¼ÓÐ28.11ÍòÃû»¼Õߣ¬Õâ´Î¹¥»÷¶ÔÆäÔËÓªÔì³ÉÁ˿϶¨Ó°Ïì¡£½ØÖÁÖÜÒ»ÉÏÎ磬ÉÐÎÞÀÕË÷Èí¼þÍÅ»ïÈÏ¿ÉÕÆ¹Ü¡£ÍøÂ簲ȫר¼Ò×·×Ùµ½2025ÄêÕë¶ÔÒ½ÁƱ£½¡×éÖ¯µÄ100¶àÆðÀÕË÷Èí¼þ¹¥»÷£¬Ò½ÁƱ£½¡»ú¹¹Ãæ¶ÔÑϸñÌôÕ½¡£Î¢ÈíÉϸöÔÂÒ²ÖÒ¸æ³Æ£¬ÀÕË÷Èí¼þ¹¥»÷ÊÇ´åÂäÒ½ÔºÃæ¶ÔµÄÖØÒªÎÊÌ⣬¿ÉÄÜ´øÀ´Î£¼°ÐÔÃüµÄºó¹û¡£DaVitaÉÐδ»ØÓ¦¹ØÓÚ¹¥»÷×éÖ¯¼°ÊÇ·ñ»áÖ§¸¶Êê½ðµÄÖÃÆÀÒªÇó¡£


https://therecord.media/davita-kidney-dialysis-company-ransomware-attack


3. Study HotelsÔâ·êPlayÀÕË÷Èí¼þÍÅ»ïË«³ÁÀÕË÷Íþв


4ÔÂ14ÈÕ£¬Ò»¼ÒÖØÒª·þÎñÓÚ³£´ºÌÙÃËУµÄ¾«Æ·×¡ËÞÆ·ÅÆStudy HotelsÔâ·êÁËÀÕË÷Èí¼þ¹¥»÷¡£¸ÃÁ¬Ëø¾ÆµêÔÚҮ³´óѧ¡¢±öϦ·¨ÄáÑÇ´óѧ¡¢Ô¼º²¡¤»ôÆÕ½ð˹´óѧºÍÖ¥¼Ó¸ç´óѧµÈÐ£Çø¾­ÓªÉÝ»ª×¡ËÞ£¬Æä¿Í»§ÈºÔ̺¬¿Í×ù½ÌÊÚ¡¢¸ß¾»Öµ¼Ò³¤ºÍ»áÒé²Î¼ÓÕß¡£Õâ´Î¹¥»÷µÄÄ»ºóºÚÊÖPlayÀÕË÷Èí¼þÍŻÍþв³ÆÈô²»Ö§¸¶Êê½ð£¬½«Ð¹Â¶Ô±¹¤¹¤×ʵ¥¡¢Éí·ÝÖ¤¼þºÍ»úÃÜÎļþµÈ¸ß¶ÈÃô¸ÐÊý¾Ý¡£Ð¹ÃÜ֪ͨÓÚ2025Äê4ÔÂ11ÈÕ°ä²¼£¬¾àÀëÍþвÕßÉ趨µÄ×îºóÆÚÏÞ½öÊ£Ò»Ìì¡£¸ÃÍÅ»ïÒÑй¶²¿ÃÅÊý¾Ý£¬²¢³ÖÐøÍþв½«È«ÊýÊý¾Ý¹«¿ª¡£ÀÕË÷Èí¼þÍÅ»ïͨ³£½«Êܺ¦ÕßÃûµ¥ÁÐÔÚÆä°µÍøÐ¹ÃÜÍøÕ¾ÉÏ£¬ÒÔ´ËÆÈʹ×éÖ¯Ö§¸¶Êê½ð¡£ËûÃÇѡȡ˫³ÁÀÕË÷ģʽ£¬ÔÚÇÔÈ¡Êý¾Ýºó¼ÓÃÜϵͳ£¬²¢ÒÑÓ°Ïìµ½¿í·ºµÄÆóÒµºÍ¹Ø¼ü»ù´¡ÉèÊ©¡£Ä¿Ç°Éв»Ã÷ÏÔStudy HotelsÊÇ·ñÒѶÔÕâ´ÎÍþв×ö³ö»ØÓ¦¡£


https://cybernews.com/security/yale-university-hotel-chain-ransomware-attack/


4. APT29ÀûÓÃGrapeLoaderÓëWineLoader±äÖÖ¹¥»÷Å·ÖÞ±í½»ÍøÂç


4ÔÂ15ÈÕ£¬¶íÂÞ˹µ±¾ÖÖ§³ÖµÄ¼äµý×éÖ¯ÎçÒ¹±©Ñ©£¨Midnight Blizzard£¬±ðÃû¡°Cozy Bear¡±»ò¡°APT29¡±£©ÌáÒéÁËÒ»ÏîÕë¶ÔÅ·ÖÞ±í½»ÊµÌ壨Ô̺¬´óʹ¹Ý£©µÄÐÂÓã²æÊ½ÍøÂç´¹µö»î¶¯¡£Õâ´Î»î¶¯ÓÚ2025Äê1ÔÂÆô¶¯£¬Í¨¹ý¼Ù×°³É±í½»²¿µÄµç×ÓÓʼþ£¬ÓÕµ¼ÊÕ¼þÈ˵ã»÷¶ñÒâÁ´½Ó£¬ÏÂÔØÔ̺¬GrapeLoader¶ñÒâÈí¼þ¼ÓÔØÆ÷ºÍWineLoaderºóÃÅбäÖÖµÄZIPѹËõ°ü¡£GrapeLoaderͨ¹ýDLL²à¼ÓÔØÖ´ÐУ¬ÍøÂçÖ÷»úÐÅÏ¢£¬³ÉÁ¢ÓƾÃÐÔ£¬²¢ÁªÏµºÅÁîÓë½ÚÔ죨C2£©·þÎñÆ÷½Ó¹Üshellcode¡£¸Ã¼ÓÔØÆ÷Ö¼ÔÚÈ¡´ú֮ǰʹÓõĵÚÒ»½×¶ÎHTA×°ÔØ»ú¡°RootSaw¡±£¬ÒòÆäÔ½·¢Òñ±ÎºÍ¸´ÔÓ¡£GrapeLoaderÀûÓá°PAGE_NOACCESS¡±ÄÚ´æ±£»¤ºÍ10ÃëÑÓ³¤¼¼Êõ£¬Í¨¹ý¡°ResumeThread¡±ÔËÐÐshellcode£¬ÒÔ¶ã±Ü·À²¡¶¾ºÍEDRɨÃè¡£WineLoader×÷ΪÄ£¿é»¯ºóÃÅ£¬ÕƹÜÍøÂç¾ßÌåµÄÖ÷»úÐÅÏ¢£¬Ô̺¬IPµØÖ·¡¢ÔËǰ¹ý³ÌÃû³Æ¡¢WindowsÓû§ÃûµÈ£¬ÒÔÍÆ½ø¼äµý»î¶¯¡£Ð±äÌåѡȡRVA¸´Ôì¡¢µ¼³ö±í²»Æ¥ÅäºÍÀ¬»øÖ¸Áî½øÐÐÑϳÁ»ìºÏ£¬Ìá¸ßÁËÄæÏò¹¤³ÌÄѶÈ¡£


https://www.bleepingcomputer.com/news/security/midnight-blizzard-deploys-new-grapeloader-malware-in-embassy-phishing/


5. 4chanÂÛ̳ÒÉÔâSoyjak.partyºÚ¿Í¹¥»÷¶ø±»¹Ø¹Ø


4ÔÂ15ÈÕ£¬³ÛÃûÔÚÏßÂÛ̳4chanÒÉËÆÔâ·êÑϳÁºÚ¿Í¹¥»÷¶øÏÂÏߣ¬¶ûºó¼ÓÔØ¶Ï¶ÏÐøÐø¡£Ëæºó£¬Soyjak.partyͼƬÂÛ̳³ÉÔ±Ðû³ÆÊÇÕâ´Î¹¥»÷µÄÄ»ºóºÚÊÖ£¬²¢Ð¹Â¶ÁËÖÎÀíÃæ°å½ØÍ¼¼°Ò»·Ý¾Ý³ÆÊôÓÚ4chanÖÎÀíÔ±¡¢°æÖ÷µÄµç×ÓÓʼþÁбí¡£Ò»ÃûºÚ¿Í£¨Óû§ÃûΪChud£©ÔÚ4chan¹Ø¹Øºó·¢Ìû³Æ£¬ºÚ¿ÍÒÑDZÈë4chanϵͳһÄê¶à£¬Ö´ÐÐÁ˹¥»÷Ðж¯£¬Ð¹Â¶ÁËÔ±¹¤Ó×ÎÒÐÅÏ¢ºÍÍøÕ¾´úÂ롣Ϊ½ÚÔìËðʧ£¬4chanÖÎÀíÔ±Òѽ«ËùÓзþÎñÆ÷ÏÂÏߣ¬µ«Óл㱨³Æ·þÎñÆ÷Òѱ»ÆëÈ«¹¥ÆÆ£¬¿ÉÄÜÎÞ·¨Ñ¸¿ì¸´Ô­¡£Chud·ÖÏíµÄ½ØÍ¼ÏÔʾ£¬ºÚ¿Í¿É½Ó¼û4chanµÄÔ±¹¤ÖÎÀíÃæ°åºÍÊØ»¤¹¤¾ß£¬ÕâЩ¹¤¾ßÖ°ÄÜ׳´ó£¬¿É½Ó¼ûÓû§µØÎ»ºÍIPµØÖ·¡¢³Á½¨»ò³ÁÐÂÆô¶¯°å¿é¡¢²é¿´ÈÕÖ¾ºÍÕ¾µãͳ¼ÆÐÅÏ¢ÒÔ¼°ÖÎÀíÊý¾Ý¿â¡£¹ÌÈ»¹¥»÷Õßδй©ÈëÇÖ·½Ê½£¬µ«ÓÐÈËÒÔΪ£¬Õâ¿ÉÄÜÊÇÓÉÓÚ4chanʹÓÃÁËÑϳÁ¹ýÆÚµÄPHP°æ±¾£¬Î´½¨²¹ºÜ¶à°²È«·ì϶¡£µ±ÌìÍíЩʱ³½£¬4chanµÄPHPÔ´´úÂëÔÚÄäÃûÂÛ̳Kiwi FarmsÉϱ»Ð¹Â¶¡£4chan×Ô2003ÄêµÞÔìÒÔÀ´£¬ÒÑÉÏÏß¶þÊ®¶àÄ꣬¶àÄêÀ´Ò»Ïò±»ÓÃÀ´Ð¹Â¶¾Ý³Æ´Ó¶à¼Ò³ÛÃû¹«Ë¾ÇÔÈ¡µÄÎļþ¡£


https://www.bleepingcomputer.com/news/security/infamous-message-board-4chan-taken-down-following-major-hack/


6. Lemonade±£ÏÕ¹«Ë¾´«µÝ19ÍòÓû§¼ÝÕÕºÅй¶ÊÂÎñ


4ÔÂ15ÈÕ£¬Lemonade³ÉÁ¢ÓÚ2015Ä꣬×Գơ°È«Õ»±£ÏÕ¹«Ë¾¡±£¬ÔÚÃÀ¹úºÍÅ·ÖÞÌṩ×â·¿¡¢·¿¶«¡¢Æû³µ¡¢³èÎï¼°ÈËÊÙ±£ÏÕ²úÆ·¡£¸Ã¹«Ë¾ÒÔÀûÓÃÈËΪÖÇÄܼ¼Êõ¼¤»î±£µ¥¼°´¦ÖÃË÷Åâ¶øÎÅÃû¡£¸Ã¹«Ë¾½üÈÕ֪ͨԼ19ÍòÃû¿Í»§£¬Æä¼ÝÕÕºÅÂë¿ÉÄÜÒò¼¼Êõ¹ÊÕÏÔâй¶¡£¸ÃÊÂÎñÉæ¼°Ò»¿îÔÚÏ߯û³µ±£ÏÕÀûÓ㬸ÃÀûÓÃÔÊÐíÓû§»ñÈ¡±£ÏÕ±¨¼Û¼°²É°ì±£µ¥¡£¾Ý¹«Ë¾Åû¶£¬Æû³µ±£ÏÕ±¨¼ÛÁ÷³ÌÖдæÔÚ°²È«·ì϶£¬µ¼Ö²¿ÃÅÓû§µÄ¼ÝÕÕºÅÂë¶³ö¡£Lemonade°µÊ¾Òѽ¨¸´´Ë·ì϶¡£ÔÚ2023Äê4ÔÂÖÁ2024Äê9ÔÂÆÚ¼ä£¬¸ÃÆ½Ì¨ÔøÒÔδ¼ÓÃÜ·½Ê½´«ÊäÐÅÏ¢£¬ÒÔÖÁ¼ÝÊ»ÅÆÕÕºÅÂëÃæ¶Ôδ¾­ÊÚȨµÄ½Ó¼û·çÏÕ¡£¹«Ë¾Ë䳯ÎÞÖ¤¾ÝÅú×¢¼ÝÕÕºÅÂë±»µÁÓ㬵«ÎªÔ¤·ÀDZÔÚ·çÏÕ£¬ÒÑÏòÊÜÓ°Ïì¸ö±ð·¢³ö֪ͨ£¬²¢Ìṩ12¸öÔÂÃâ·ÑÐÅÓþ¼à¿Ø¼°Éí·Ý±£»¤·þÎñ¡£LemonadeÒÑÏòÃÀ¹ú֤ȯÂòÂôίԱ»á»ã±¨£¬Õâ´Î±äÂÒÓ°ÏìÔ¼19ÍòÈË¡£¹«Ë¾Ç¿µ÷£¬Æ¾¾Ýµ±Ç°°ÑÎÕµÄÊÂʵÓëÇé¿ö£¬Õâ´ÎÊÂÎñδӰÏìÆäÔËÓª£¬¿Í»§Êý¾ÝÒàδÔâ¹¥»÷£¬ÇÒ¹«Ë¾Åж¨¸ÃÊÂÎñ²»×é³É³Á´ó·çÏÕ¡£


https://www.securityweek.com/insurance-firm-lemonade-says-api-glitch-exposed-some-drivers-license-numbers/