µÂ¹úµ·»ÙÈ«Çò×î´ó°µÍøHydra²¢²é»ñ2500ÍòÃÀÔªµÄBTC
Ðû²¼Ê±¼ä 2022-04-07µÂ¹úµ·»ÙÈ«Çò×î´ó°µÍøHydra²¢²é»ñ2500ÍòÃÀÔªµÄBTC
4ÔÂ5ÈÕÐÇÆÚ¶þ£¬µÂ¹úÁª°îÐÌʾ¯²ì¾Ö(Bundeskriminalamt)Ðû²¼Àֳɵ·»ÙÁË°µÍøHydra¡£¸ÃÊг¡Ô¼ÓÐ19000¸ö×¢²áµÄÂô¼Ò£¬ÎªÈ«ÇòÖÁÉÙ1700Íò¿Í»§Ìṩ·þÎñ£¬¾ÝÔ¤¼ÆÆäÔÚ2020ÄêµÄÓªÒµ¶îΪ13.5ÒÚÃÀÔª£¬ÊÇÈ«Çò×î´óµÄ°µÍøÊг¡¡£ÊÓ²ìÈËԱ͸¶£¬ËûÃDz»½ö¹Ø±ÕÁËHydraÔڵ¹ú·þÎñÆ÷£¬»¹²é»ñÁ˼ÛÖµ543.3¸ö±ÈÌرң¨¼ÛÖµ2500ÍòÃÀÔª£©¡£Ä¿Ç°£¬HydraµÄÖ÷ÓòÃûºÍ±¸·ÝÓòÃû´¦ÓÚÍÑ»ú״̬£¬ÏÔʾ´íÎóÏûÏ¢¡°502 Bad Gateway¡±¡£
https://www.hackread.com/germany-russia-dark-web-market-hydra-seize-btc/
ÃÀ¹úÔËͨµÄÔÚÏßϵͳ·ºÆð¹ÊÕϵ¼ÖÂÆäÈ«Çò·þÎñÖжÏ
¾ÝýÌå4ÔÂ2ÈÕ±¨µÀ£¬ÃÀ¹úÔËͨµÄÈ«Çò·þÎñÖжÏÊýСʱ¡£ÖжϷ¢ÉúÔÚ4ÔÂ1ÈÕ£¬Óû§³ÂËßÎÞ·¨µÇ¼ÆäÃÀ¹úÔËͨÕË»§¡¢ÎÞ·¨¸¶¿î»òµç»°ÁªÏµÃÀ¹úÔËͨµÄ¿Í·þ¡£¸Ã¹«Ë¾ÔÚÆä¹ÙÍøÐû²¼Í¨¸æ£¬³ÆÆä¡°Òâʶµ½¼¼ÊõÎÊÌ⡱ÕýÔÚÓ°Ïìµç»°Ïß·¡¢ÔÚÏßÕË»§·þÎñºÍÃÀ¹úÔËͨÒƶ¯Ó¦Óá£Ñо¿ÈËÔ±¾¹ý¶à´Î²âÊÔºóÍƶϣ¬¸ÃÎÊÌâ¿ÉÄÜÓëÃÀ¹úÔËͨ×î½üÍƳöµÄ¡°ËùÓÐÕÊ»§Ò»´ÎµÇ¼¡±¹¦Ð§Óйأ¬µ«ÕâÎÞ·¨½âÊ͵绰·þÎñΪºÎÖжϡ£Ä¿Ç°£¬ÖжÏÔÒòÉв»Ã÷È·£¬ÄÚ²¿ÈËÊ¿³Æ²¢·ÇÔ´×ÔÍøÂç¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/american-express-down-in-outage-users-report-login-and-payment-issues/
Î÷°àÑÀIberdrolaÔâµ½¹¥»÷й¶130Íò¿Í»§µÄÊý¾Ý
ýÌå4ÔÂ2Èճƣ¬Î÷°àÑÀÄÜÔ´¹«Ë¾Iberdrolaй¶ÁË130Íò¿Í»§µÄ¸öÈËÐÅÏ¢¡£¸Ã¹«Ë¾ÒÑ֤ʵ£¬ËûÃÇÔÚ3ÔÂ15ÈÕÔâµ½ÍøÂç¹¥»÷£¬ºÚ¿Í·Ç·¨·ÃÎÊÁË¿Í»§µÄÉí·ÝÖ¤ºÅÂë¡¢µØÖ·¡¢µç»°ºÅÂëºÍÓʼþµØÖ·µÈÐÅÏ¢¡£IberdrolaÌåÏÖ£¬¸ÃÎÊÌâÒÑÔÚµ±Ìì±»ÐÞ¸´£¬ÆäÀÖ³É×èÖ¹Á˽øÒ»²½µÄ¹¥»÷£¬µ«»¹ÊÇÌáÐÑ¿Í»§×¢ÒâÀûÓÃÕâЩÐÅÏ¢µÄµöÓã»î¶¯¡£¾Ý³Æ£¬ÔÚͬһÌìÖУ¬ÂíµÂÀïµÄͨÇÚÌú·ÍøÂçCercan¨ªas¡¢Î÷°àÑÀÒé»áºÍ¼¸¸öµØÓòµÄ»ú¹¹Ò²Ôâµ½Á˹¥»÷¡£
https://www.surinenglish.com/spain/cyberattack-iberdrola-accessed-20220401183800-nt.html
µÂ¹úNordex¶à¸ö·Ö¹«Ë¾µÄϵͳÒòÔâµ½ÈëÇÖ¶ø¹Ø±Õ
ýÌå4ÔÂ4ÈÕ±¨µÀ³Æ£¬µÂ¹ú·çÁ¦ÎÐÂÖ»úÖÆÔìÉÌNordexÔâµ½¹¥»÷ºó£¬¹Ø±ÕÁ˶à¸ö·Ö¹«Ë¾ºÍÒµÎñ²¿ÃŵÄϵͳ¡£NordexÖ÷ÒªÉè¼Æ¡¢ÖÆÔìºÍÏúÊÛ·çÁ¦ÎÐÂÖ»ú£¬2021ÄêµÄÏúÊÛ¶î½Ó½ü60ÒÚÃÀÔª£¬Ôڵ¹ú¡¢Öйú¡¢Ä«Î÷¸ç¡¢ÃÀ¹ú¡¢°ÍÎ÷¡¢Î÷°àÑÀºÍÓ¡¶ÈÉèÓй¤³§¡£¹¥»÷·¢ÉúÔÚ3ÔÂ31ÈÕ£¬Æä¼ì²âµ½¹¥»÷ºóÁ¢¿Ì½øÐÐÁËÏìÓ¦£¬¿Í»§¡¢Ô±¹¤µÈÀûÒæÏà¹ØÕß¿ÉÄÜ»áÊܵ½¶à¸öITϵͳ¹Ø±ÕµÄÓ°Ïì¡£NordexÔÚ±¾ÖÜһûÓлØÓ¦¹ØÓÚÆäÔËӪ״¿öµÄÆÀÂÛÇëÇó¡£
https://therecord.media/german-wind-turbine-maker-shut-down-after-cyberattack/
MandiantÅû¶ºÚ¿ÍÍÅ»ïFIN7Ñݱä¹ý³ÌµÄÏêϸÐÅÏ¢
4ÔÂ4ÈÕ£¬MandiantÐû²¼Á˹ØÓÚ2021Äêµ×ÖÁ2022Äê³õFIN7ÔËÓª»î¶¯µÄÏêϸ¼¼Êõ³ÂËß¡£FIN7ÔÚÈëÇÖ¹ý³ÌÖмÌÐøÀûÓÃPowerShell£¬°üÂÞÔÚÒ»¸öкóÃÅPOWERPLANT£¬ÒÔ¼°ÕýÔÚ¿ª·¢µÄBIRDWATCHÏÂÔØÆ÷µÄа汾CROWVIEWºÍFOWLGAZE¡£FIN7µÄ³õʼ·ÃÎʼ¼ÊõÒѾ¶àÑù»¯£¬³ýÁË´«Í³µÄµöÓã¹¥»÷Í⣬»¹Í¨¹ýÈí¼þ¹©Ó¦Á´ÈëÇÖºÍʹÓñ»µÁƾ֤¡£¶à¸öÀÕË÷»î¶¯ÓëFIN7ÓÐÖصþ£¬Éæ¼°ÀÕË÷Èí¼þREVIL¡¢DARKSIDE¡¢BLACKMATTERºÍALPHV¡£
https://www.mandiant.com/resources/evolution-of-fin7
CybleÐû²¼Ð¶ñÒâÈí¼þBorat RATµÄÉî¶È·ÖÎö³ÂËß
CybleÔÚ3ÔÂ31ÈÕÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þBorat RATµÄÉî¶È·ÖÎö³ÂËß¡£¿ª·¢ÕßÒÔÒ»²¿ºÚɫϲ¾çα¼Í¼Ƭ¡°Borat¡±µÄÃû×ÖÃüÃû¸ÃRAT£¬ÓëÆäËüRAT²îÒìµÄÊÇ£¬³ýÁ˳£¼ûµÄRAT¹¦Ð§Ö®Í⣬Borat»¹Ïò¹¥»÷ÕßÌṩÀÕË÷Èí¼þºÍDDOS·þÎñ£¬½øÒ»²½À©Õ¹Á˶ñÒâÈí¼þµÄ¹¦Ð§¡£Borat RAT×÷Ϊһ¸ö°üÌṩ£¬ÆäÖаüÂÞ¹¹½¨Æ÷µÄ¶þ½øÖÆÎļþ¡¢Ö§³ÖÄ£¿é¡¢·þÎñÆ÷Ö¤ÊéµÈ£¬ÊǼ¯Ô¶³Ì·ÃÎÊľÂí¡¢¼äµýÈí¼þºÍÀÕË÷Èí¼þµÄÓÚÒ»ÌåµÄÇ¿´ó×éºÏ£¬¶ÔÄ¿±ê¾ßÓÐÈýÖØÍþв¡£
https://blog.cyble.com/2022/03/31/deep-dive-analysis-borat-rat/
Äþ¾²¹¤¾ß
CVE-2022-22963µÄPoC
Spring Java FrameworkÔ¶³Ì´úÂëÖ´ÐЩ¶´µÄPoC¡£
https://github.com/darryk10/CVE-2022-22963
BackupOperatorToDA
¿ÉÒÔÔÚûÓÐ RDP »òÓò¿ØÖÆÆ÷É쵀 WinRM µÄÇé¿öϳÉΪÓò¹ÜÀíÔ±¡£
https://github.com/mpgn/BackupOperatorToDA
DuplicateDump
ÊÇMirrorDumpµÄÒ»¸ö·ÖÖ§£¬Äܹ»ÔÚ²»¼ì²âµ½µÄÇé¿öÏÂת´¢ LSASS ÄÚ´æ¡£
https://github.com/Hagrid29/DuplicateDump
Slyther
Slyther ÊÇ AWS Äþ¾²¹¤¾ß£¬ÓÃÓÚ¼ì²é S3 ´æ´¢Í°µÄ¶Á/д/ɾ³ý·ÃÎÊȨÏÞ¡£
https://github.com/iamavu/Slyther
Äþ¾²·ÖÎö
CISA ÌáÐÑÖ÷¶¯ÀûÓÃµÄ Spring4Shell ©¶´
https://thehackernews.com/2022/04/cisa-warns-of-active-exploitation-of.html
GitLab Ðû²¼¿ÉÄÜÈù¥»÷Õß½Ù³ÖÕË»§µÄÒªº¦Â©¶´²¹¶¡
https://thehackernews.com/2022/04/gitlab-releases-patch-for-critical.html
Anonymousй¶´Ó¶íÂÞ˹¶«Õý½Ì½ÌÌÃÇÔÈ¡µÄ 15 GB Êý¾Ý
https://securityaffairs.co/wordpress/129760/hacktivism/anonymous-hacked-russian-orthodox-church.html
Å·ÃËÖ´·¨²Ý°¸ÎªËùÓмÓÃܽ»Ò×Ôö¼ÓÁËÄþ¾²¼ì²é
https://www.bleepingcomputer.com/news/legal/eu-draft-law-adds-security-checks-to-all-crypto-transactions/
Æ»¹ûÀñÆ·¿¨Õ©ÆÍÅ»ïÒòÉæÏÓ¼ÓÈë 150 ÍòÃÀÔªÆÛÕ©¶ø±»ÅÐÐÌ
https://www.darkreading.com/attacks-breaches/apple-gift-card-scammers-sentenced-for-role-in-1-5m-fraud
Ñо¿ÈËÔ±·¢ÏÖPEAR PHP´æ´¢¿âÖÐ2¸ö´æÔÚ15ÄêµÄ©¶´
https://securityaffairs.co/wordpress/129797/hacking/pear-php-critical-flaws.html