DragonForceÀÕË÷Èí¼þ½èSimpleHelp·ì϶¹¥ÆÆMSP
°ä²¼¹¦·ò 2025-05-281. DragonForceÀÕË÷Èí¼þ½èSimpleHelp·ì϶¹¥ÆÆMSP
5ÔÂ27ÈÕ£¬DragonForceÀÕË÷Èí¼þÍÅ»ï³É¹¦¹¥ÆÆÒ»¼ÒÍйܷþÎñÌṩÉÌ£¬²¢ÀûÓÃÆäSimpleHelpÔ¶³Ì¼à¿ØºÍÖÎÀí£¨RMM£©Æ½Ì¨Ö´ÐÐÁËһϵÁжñÒâ»î¶¯¡£Sophos¹«Ë¾ÊÜÃüµ÷²éÕâ´Î¹¥»÷£¬·¢ÏÖÍþвÐÐΪÕßÀûÓÃÁËSimpleHelpµÄ½Ï¾É·ì϶£¬Ô̺¬CVE-2024-57727¡¢CVE-2024-57728ºÍCVE-2024-57726£¬À´·ÛËéϵͳ¡£SimpleHelp×÷ΪһÖÖóÒ×Ô¶³ÌÖ§³ÖºÍ½Ó¼û¹¤¾ß£¬³£±»MSPÓÃÓÚÖÎÀíϵͳºÍ²¿ÊðÈí¼þ£¬Õâ´ÎÈ´³ÉΪ¹¥»÷ÕßµÄÀûÓöÔÏó¡£¹¥»÷ÕßÊ×ÏÈÀûÓÃSimpleHelp¶Ô¿Í»§ÏµÍ³½øÐпúËÅ£¬ÍøÂçÉ豸Ãû³Æ¡¢ÅäÖá¢Óû§ºÍÍøÂçÏνӵÈÐÅÏ¢¡£Ëæºó£¬ËûÃÇÊÔͼÇÔÈ¡Êý¾Ý²¢ÔÚ¿Í»§ÍøÂçÉϲ¿Êð¼ÓÃÜÆ÷£¬²¿ÃÅÍøÂçÒòʹÓÃSophos¶Ëµã±£»¤¶øÀ¹½ØÏàʼûÜÆ÷£¬µ«ÆäËû¿Í»§Ôò²»ÐÒÖÐÕУ¬É豸±»¼ÓÃÜ£¬Êý¾Ý±»ÇÔÈ¡£¬²¢ÓÃÓÚË«³ÁÀÕË÷¹¥»÷¡£SophosÒÑ·ÖÏíÓëÕâ´Î¹¥»÷ÓйصÄIOC£¬ÒÔÔ®ÊÖ×éÖ¯¼ÓÇ¿ÍøÂç·À»¤¡£³Ö¾ÃÒÔÀ´£¬ÍйܷþÎñÌṩÉÌÒ»ÏòÊÇÀÕË÷Èí¼þÍÅ»ïµÄ³Áµã¹¥»÷Ö¸±ê£¬ÒòÒ»´ÎÈëÇÖ¿ÉÄܵ¼Ö¶à¼Ò¹«Ë¾ÊÜËð¡£Ò»Ð©ÀÕË÷Èí¼þͬÃËרÃÅ×êÑÐMSP³£Óù¤¾ß£¬ÈçSimpleHelp£¬Õâµ¼ÖÂÁËÈçREvil¶ÔKaseyaµÄ´ó¹æÄ£ÀÕË÷Èí¼þ¹¥»÷µÈ¸²ÃðÐÔÊÂÎñ¡£
https://www.bleepingcomputer.com/news/security/dragonforce-ransomware-abuses-simplehelp-in-msp-supply-chain-attack/
2. ¶íÂÞË¹ÍøÂç¼äµý×éÖ¯¡°Ï´ÒÂÐÜ¡±ÉæÏÓÈëÇÖºÉÀ¼¾¯·½
5ÔÂ27ÈÕ£¬Ò»¸ö´Ëǰ²»ÎªÈËÖªµÄ¶íÂÞ˹֧³ÖµÄÍøÂç¼äµý×éÖ¯¡°Ï´ÒÂÐÜ¡±£¨Laundry Bear£©±»×·×Ùµ½Óë2024Äê9ÔºÉÀ¼¾¯·½°²È«·ì϶ÊÂÎñÓйء£ºÉÀ¼¹ú¶È¾¯Ô±¾ÖÈ¥Äêй©£¬¹¥»÷ÕßÇÔÈ¡Á˶àÃû¾¯¹ÙµÄ¹¤×÷ÁªÏµÐÅÏ¢£¬ºÉÀ¼µý±¨ºÍ°²È«×ܾ֣¨AIVD£©ÓëºÉÀ¼¹ú·Àµý±¨ºÍ°²È«¾Ö£¨MIVD£©ÔÚÖܶþµÄ½áºÏÖÒ¸æÖУ¬½«¡°Ï´ÒÂÐÜ¡±ÓëÕâ´ÎÈëÇÖÊÂÎñÁªÏµÆðÀ´£¬²¢ÖÒ¸æ³Æ¸Ã×éÖ¯ºÜ¿ÉÄÜÒ²ÈëÇÖÁËÆäËûºÉÀ¼×éÖ¯¡£µ÷²éÏÔʾ£¬¡°Ï´ÒÂÐÜ¡±ÓÚ2024Äê9Ô½ӼûÁËÒ»ÃûºÉÀ¼¾¯Ô±¹ÍÔ±µÄÕË»§£¬²¢Í¨¹ýÈ«ÇòµØÖ·ÁбíÇÔÈ¡ÁËÓ빤×÷ÓйصÄÁªÏµÐÅÏ¢£¬¹¥»÷Õß¿ÉÄÜʹÓÃÁË¡°´«µÝ Cookie¡±¹¥»÷£¬ÀûÓÃÇÔÈ¡µÄCookie¼ÙÒâËùÓÐÕߣ¬ÎÞÐèÓû§Ãû»òÃÜÂë¼´¿É½Ó¼ûÐÅÏ¢¡£MIVDÖ÷¹Ü±ËµÃ¡¤Àï˹¿Ë°µÊ¾£¬¸ÃºÚ¿Í×éÖ¯³É¹¦»ñÈ¡ÁËÈ«Çò´óÁ¿×éÖ¯ºÍ¹«Ë¾µÄÃô¸ÐÐÅÏ¢£¬¶ÔÅ·Ã˺ͱ±Ô¼¹ú¶È³ö¸ñ¸ÐÐËÖ¡£¡°Ï´ÒÂÐÜ¡±Ò²±»Î¢Èí³ÆÎªVoid Blizzard£¬ÖÁÉÙ×Ô2024Äê4ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬×¨Ò»ÓÚÕë¶ÔÎÚ¿ËÀ¼ºÍ±±Ô¼³ÉÔ±¹ú·¢ÆðÓë¶íÂÞ˹սÊõÖ¸±êÒ»ÖµĹ¥»÷£¬ÆäÕ½ÊõÔ̺¬Ê¹ÓÃÇÔÈ¡µÄƾ֤ºÍÓã²æÊ½ÍøÂç´¹µöµç×ÓÓʼþÀ´Í»ÆÆÖ¸±ê·ÀÓù£¬²¢´ÓÊܺ¦ÕßµÄÊÜϰȾϵͳÖÐÍøÂçºÍÇÔÈ¡ÎļþºÍµç×ÓÓʼþ¡£
https://www.bleepingcomputer.com/news/security/russian-void-blizzard-cyberspies-linked-to-dutch-police-breach/
3. ºÚ¿ÍαÔìɱ¶¾ÍøÕ¾ÒÔ´«²¼Venom RAT²¢ÇÔÈ¡¼ÓÃÜÇ®°ü
5ÔÂ27ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±½üÈÕÅû¶ÁËÁ½ÆðÐÂÐͶñÒâ»î¶¯¡£ÆäÒ»£¬¹¥»÷Õß·ÂðBitdefenderɱ¶¾Èí¼þÏÂÔØÍøÕ¾¡°bitdefender-download[.]com¡±£¬ÓÕµ¼Óû§ÏÂÔØº¬VenomRATÔ¶³Ì½Ó¼ûľÂíµÄ¶ñÒⷨʽ¡£Óû§µã»÷¸Ã·ÂÃ°ÍøÕ¾¡°Download for Windows¡±°´Å¥ºó£¬»á´¥·¢ÎļþÏÂÔØÁ÷³Ì£¬µ«Ä¿Ç°ÓйØBitbucketÕË»§Òѱ»·â½û¡£ÏÂÔØµÄZIPѹËõ°üÖÐÔ̺¬ÕûºÏÁËVenomRATľÂíÅäÖᢿªÔ´ºóÆÚÀûÓÿò¼ÜSilentTrinity¼°StormKittyÐÅÏ¢ÇÔÈ¡Æ÷µÄ¿ÉÖ´ÐÐÎļþ¡£VenomRAT×÷ΪQuasar RAT±äÖÖ£¬¾ßº±¼û¾ÝÍøÂçÓëÓÆ¾Ã»¯Ô¶³Ì½ÚÔìÄÜÁ¦¡£DomainToolsµý±¨ÍŶÓÖ¸³ö£¬¸Ã´¹µöÍøÕ¾»ù´¡ÉèÊ©Óë¶à¸ö·Âð¼ÓÄôó»Ê¼ÒÒøÐÓע΢Èí·þÎñµÄ¶ñÒâÓòÃûÓйØÁª£¬ÕâЩÓòÃû´ËǰÒѱ»ÓÃÓÚÇÔÈ¡µÇ¼ƾ֤µÄ´¹µö»î¶¯¡£¹¥»÷¼¼ÊõÁ´ÏÔʾ£¬VenomRAT¡¢StormKittyÓëSilentTrinity¸÷˾ÆäÖ°£¬¹²Í¬ÊµÏÖ¹¥»÷¡£×êÑÐÈËԱǿµ÷£¬Õâ´Î»î¶¯Ñ¡È¡Ä£¿é»¯¿ªÔ´×é¼þ¹¹½¨¶ñÒâÈí¼þϵͳ£¬ÌáÉýÁ˹¥»÷ЧÄÜÓëÒñ±ÎÐÔ¡£Í¬ÆÚ£¬Áíһ·ClickFixʽ¹¥»÷»î¶¯Ò²±»ÆØ¹â¡£¹¥»÷ÕßαÔì¹È¸èMeetÒ³Ãæ£¬ÀûÓÃÐéαÃýÎóÌáÐÑÓÕµ¼Óû§Ö´ÐÐÌØ¶¨PowerShellºÅÁ²¿Êð»ìºÏÅú´¦Öþ籾ʵÏÖÔ¶³Ì½ÚÔì¡£´Ë±í£¬Õë¶ÔMetaµÄ´ó¹æÄ£´¹µö»î¶¯½èÖú¹È¸èAppSheetÎÞ´úÂ뿪·¢Æ½Ì¨£¬ÈƹýÓʼþ°²È«ºÍ̸£¬Í¨¹ý¶¯Ì¬ÌìÉúΨһ°¸ÀýID¶ã±Ü´«Í³¼ì²âϵͳ£¬¼Ù×°³ÉFacebookÖ§³ÖÍŶÓÓÕÆÓû§µã»÷Á´½Ó£¬ÇÔȡ˫³É·ÖÈÏÖ¤´úÂë¡£
https://thehackernews.com/2025/05/cybercriminals-clone-antivirus-site-to_4.html
4. Everest GroupÀÕË÷Èí¼þÍÅ»ïÈëÇÖMediclinic²¢ÒªÇóÊê½ð
5ÔÂ26ÈÕ£¬ÀÕË÷Èí¼þÍÅ»ïEverest GroupÐû³ÆÈëÇÖÁ˼ÛÖµ50ÒÚÃÀÔªµÄÒ½ÁƵ۹úMediclinic£¬²¢Íþв³ý·Ç»ñµÃÊê½ð£¬²»È»½«Ð¹Â¼ûô¸ÐÊý¾Ý¡£Mediclinic³ÉÁ¢ÓÚ1983Ä꣬ÔÚ¶à¹úÔËÓªÒ½Ôº£¬ÄêÊÕÈë¸ß´ï54ÒÚÃÀÔª¡£¾Ý°µÍø5ÔÂ26ÈÕ¹«¸æ£¬¸ÃÀÕË÷Èí¼þÍÅ»ïÇÔÈ¡ÁË1000Ãû¹«Ë¾Ô±¹¤Ó×ÎÒÊý¾Ý¼°4GBÄÚ²¿»úÃÜÊý¾Ý£¬²¢ÒªÇó¹«Ë¾ÔÚÎåÌìÄÚÓëÆäÁªÏµ²¢´ï³ÉºÍ̸£¬²»È»½«¿ªÊͱ»µÁÊý¾Ý¡£Ä¿Ç°£¬ÉæÏÓÊý¾Ýй¶µÄ¾ßÌåÁìÓòÉв»Ã÷ÏÔ£¬µ«¼øÓÚMediclinic´ÓÊÂÒ½ÁÆÒµÎñ£¬ÕâЩÊý¾Ý¿ÉÄܸ߶ÈÃô¸Ð£¬Ò»µ©Ö¤Êµ£¬½«Î£¼°ÊÜÓ°ÏìµÄÓ×ÎÒ¼°¹«Ë¾ÔËÓª¡£×êÑÐÈËÔ±Ö¸³ö£¬Ð¹Â¶ÄÚ²¿»úÃÜÎļþ¶ÔÔ±¹¤ÓÈΪΣÏÕ£¬¹¥»÷Õß¿ÉÄÜÀûÓÃÇÔÈ¡µÄÊý¾Ý½øÐÐÉí·Ý͵ÇÔ¡¢Ú²Æ»òÍøÂç´¹µö¹¥»÷£¬ÉõÖÁ¿ÉÄÜÒý·¢¶Ô»ù´¡ÉèÊ©µÄ½øÒ»²½¹¥»÷»ò˾·¨Ðж¯¡£Everest GroupÀÕË÷Èí¼þÍŶӾݳÆÓë¶íÂÞ˹µÄBlackByte¼¯ÍÅÓÐÁªÏµ£¬×Ô2021ÄêÖÐÆÚÒÔÀ´Ò»ÏòÔڻ£¬±¾Ô»¹Ï®»÷ÁË¿ç¹úÈíÒûÁϳö²úÉÌÊʿڿÉÀÖ£¬ÇÔÈ¡ÁËÔ±¹¤Êý¾Ý¼°»úÃÜÎļþ£¬²¢²ß¶¯ÁË2022Äê10ÔÂÕë¶ÔAT&TµÄ¹¥»÷¡£
https://cybernews.com/security/mediclinic-everest-ransomware-attack/
5. RhysidaÀÕË÷ÍÅ»ïÐû³ÆÇÔÈ¡°ÍÎ÷Æû³µ¾ÏúÉÌCarreraµÄÊý¾Ý
5ÔÂ26ÈÕ£¬½üÈÕ£¬Óë¶íÂÞ˹ÓйØÁªµÄRhysidaÀÕË÷Èí¼þÍÅ»ïÐû³ÆÇÔÈ¡Á˰ÍÎ÷³ÛÃûÆû³µ¾ÏúÉÌCarreraµÄÃô¸ÐÊý¾Ý£¬Ô̺¬»¤ÕÕ¡¢ºÏÒ»Ö£¬²¢Ë÷Òª100ÍòÃÀÔªÊê½ðÒÔ¸²¸ÇÕæÏà¡£¸ÃÍÅ»ïÔÚ°µÍø°ä²¼ÉêÃ÷£¬ÒÔµäÐÍ·½Ê½Íþв¸Ã¹«Ë¾£¬ÒªÇóÔÚ6ÔÂ1ÈÕǰ֧¸¶¾Þ¶îÊê½ð£¬²»È»½«¹«¿ªÊý¾Ý¡£Carrera¹«Ë¾×ܲ¿Î»ÓÚÊ¥±£ÂÞ£¬¾Óª¶à¸öÆû³µÆ·ÅÆÏúÊÛ¼°ÓйطþÎñ¡£Õâ´ÎÀÕË÷¹¥»÷¿ÉÄܸø¹«Ë¾´øÀ´¾Þ¶îËðʧ£¬Ô̺¬×ÊÔ´·ÖÅ䡢˾·¨·î¸æ¡¢¿Í»§Åâ³¥¼°·£¿îµÈ£¬·£¿î½ð¶î¿ÉÄܸߴï½ü300ÍòÃÀÔª¡£´Ë±í£¬»¤ÕÕ¸´Ó¡¼þй¶¿ÉÄܵ¼ÖÂÉí·Ý͵ÇÔºÍڲƣ¬ÊÜÓ°Ïì¿Í»§¿ÉÄܸæ×´¹«Ë¾ÒªÇóÅâ³¥¡£³ý¾¼Ã´¦·£±í£¬¹«Ë¾»¹¿ÉÄÜÔâ·êÃûÓþÇÖº¦£¬Ó°ÏìÒµÎñ¼¨Ð§¡£Rhysida×éÖ¯ÒÔË«³ÁÀÕË÷¼¿Á©ÎÅÃû£¬ÒÑÉøÈëµ½½ÌÓý¡¢Ò½ÁƱ£½¡µÈ¶à¸öÁìÓò£¬×Ô2023Äê5Ô³ÉÁ¢ÒÔÀ´ÒÑÔì³É³¬¹ý202ÃûÊܺ¦Õß¡£²»Í⣬2024Ä꺫¹ú»¥ÁªÍø°²È«¾ÖµÄ×êÑÐÓ××éÒÑÆÆ½â¸ÃÍÅ»ïµÄ¼ÓÃÜ´úÂ룬²¢ÔÚÆäÍøÕ¾ÉÏ·ÖÏíÁËÃâ·ÑµÄRhysida½âÃܹ¤¾ßºÍÊֲᡣ
https://cybernews.com/security/carrera-chevloret-brazil-ransomware-attack/
6. ºÚ¿ÍÐû³ÆAT&T³Á´óйÃÜÊÂÎñ¶³öÁË3100Íò±Ê¼Í¼
5ÔÂ26ÈÕ£¬¹¥»÷Õß½üÈÕÐû³ÆÊýǧÍòÌõAT&T¼Í¼±»Ð¹Â¶ÖÁÍøÉÏ£¬µ«×êÑÐÈËÔ±ÒÔΪ²»×ã×ã¹»Ö¤¾ÝÖ§³Ö¡£¸ÃÊÂÎñÏêÇé°ä²¼ÓÚÒ»³ÛÃûºÚ¿ÍÂÛ̳£¬¹¥»÷Õß³ÆÊý¾Ý¼¯º¬¶à´ï3100ÍòÌõÃô¸ÐÓû§¼Í¼£¬Ô̺¬¿Í»§È«Ãû¡¢ÐԱ𡢵®ÉúÈÕÆÚ¡¢Ë°ºÅ¡¢É豸ID¡¢CookieID¡¢IPµØÖ·¡¢ÆëÈ«µØÖ·¡¢µç»°ºÅÂë¼°µç×ÓÓʼþµØÖ·µÈ¡£×êÑÐÍŶӵ÷²é·¢ÏÖ£¬Ñù±¾½öº¬µ¥¸öÓû§¾ßÌåÐÅÏ¢£¬ÎÞ·¨ÑéÖ¤ÆëÈ«Êý¾Ý¿âÊÇ·ñÕæÓÐ3100Íò±Ê¼Í¼¡£²»Í⣬Èç¹ûÿ¸öÓû§Â¶³öÐÅÏ¢Á¿Ò»Ñù£¬Ôò³¬300ÍòAT&TÓû§Ó×ÎÒÐÅÏ¢¿ÉÄÜÒÑй¶¡£×êÑÐÈËԱǿµ÷£¬ÈôÐÅÏ¢ÕæÓÐ3100ÍòÐУ¬½«ÊÇÑϳÁÓû§ÒþÖÔй¶¡£Ö»¹ÜĿǰÎÞ·¨È·ÈÏй¶ÊÂÎñ£¬µ«¹¥»÷Õß5Ô·dz£»îÔ¾£¬°ä²¼ÁËÊýÊ®Ìõº¬¸÷ÀàÊý¾ÝµÄÌû×Ó¡£ÈôAT&TÊý¾Ýй¶±»Ö¤Êµ£¬½«¶ÔÊÜÓ°ÏìÓ×ÎÒ×é³ÉÑϳÁÍøÂ簲ȫºÍÒþÖÔ·çÏÕ£¬ÕâЩÊý¾Ý×ãÒÔÒý·¢½ðÈÚڲơ¢ÕË»§µÁÓúÍÉç»á¹¤³Ì¹¥»÷¡£AT&T×÷ΪȫÇò×î´óµçÐŹ«Ë¾Ö®Ò»£¬ÄêÓªÊÕ³¬1220ÒÚÃÀÔª£¬ÆäÖØ´ó¹æÄ£Ê¹Æä³ÉΪºÚ¿Í¹¥»÷Ö¸±ê£¬È¥Äê4Ô¸ù«Ë¾¾ÍÔø°µÊ¾¿Í»§Êý¾Ý±»´ÓµÚÈý·½ÔÆÆ½Ì¨·¸·¨ÏÂÔØ£¬ÏÕЩËùÓпͻ§¶¼ÊÜÓ°Ïì¡£
https://cybernews.com/security/att-data-breach-millions-records-claimed/


¾©¹«Íø°²±¸11010802024551ºÅ