MOVEit©¶´ÖÂÊý¾Ýй¶£¬Nam3L3ss×éÖ¯ÆعâÊý°ÙÍòÔ±¹¤¼Ç¼

Ðû²¼Ê±¼ä 2024-12-05

1. MOVEit©¶´ÖÂÊý¾Ýй¶£¬Nam3L3ss×éÖ¯ÆعâÊý°ÙÍòÔ±¹¤¼Ç¼


12ÔÂ3ÈÕ£¬Ò»ÆðÉæ¼°MOVEitÎļþ´«Ê乤¾ßµÄÄþ¾²Â©¶´Ê¼þÒý·¢Á˹㷺¹Ø×¢¡£¸Ã©¶´±»Cl0pÀÕË÷²¡¶¾ÍÅ»ïÀûÓ㬵¼ÖÂÊýǧ¼Ò¹«Ë¾µÄÃô¸ÐÊý¾Ý±»µÁ£¬ÆäÖаüÂÞÀ´×Ô27¼Ò´ó¹«Ë¾µÄÁè¼Ý760,000·ÝÔ±¹¤¼Ç¼£¬ÒÔ¼°ÖÙÁ¿ÁªÐй«Ë¾(JLL.com)µÄ1200ÍòÐÐÊý¾Ý£¬×ÜÊýµ½´ï1312ÍòÌõ¡£ÕâЩÊý¾Ý°üÂÞÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢µØÖ·ºÍ¹«Ë¾Î»ÖÃ×ø±êµÈÃô¸ÐÐÅÏ¢£¬±»Ð¹Â¶ºó¿ÉÄܻᱻÓÃÓÚÉç»á¹¤³Ì¹¥»÷¡¢Éí·Ý͵ÇÔ»òÍøÂçµöÓãÕ©Æ­µÈ¶ñÒâÐÐΪ¡£Ð¹Â¶Êý¾ÝµÄ×éÖ¯Nam3L3ss×Գơ°Êý¾ÝÒåÓ¾ü¡±£¬ÔÚºÚ¿ÍÂÛ̳BreachForumsÉÏÐû²¼ÁËÕâЩÐÅÏ¢£¬²¢Éù³ÆÊÇ´ÓMOVEit©¶´ÖлñµÃµÄÊý¾Ý¡£´Ë´ÎйÃÜʼþÉæ¼°µÄ¹«Ë¾°üÂÞÃÀ¹úÒøÐС¢Åµ»ùÑÇ¡¢Ä¦¸ùÊ¿µ¤ÀûµÈÐÐÒµ¾ÞÍ·£¬×ÜÊýµ½´ï½ü1ÒÚ¸öÈË¡£ËäÈ»Nam3L3ssµÄ¶¯»úÉв»Ã÷È·£¬µ«ËûÃǵÄÐÐΪÎÞÒÉ̻¶ÁËMOVEit©¶´µÄÖØ´óÓ°ÏìÒÔ¼°±»µÁÔ±¹¤Êý¾Ý´øÀ´µÄ·çÏÕ¡£ÊÜÓ°Ï칫˾µÄÔ±¹¤Ó¦±£³Ö¾¯Ì裬ÒÔ·ÀÍøÂçµöÓãµÈ¹¥»÷¡£


https://hackread.com/data-vigilante-leaks-772k-employee-record-database/


2. KimsukyÀûÓõöÓãÓʼþ½øÐÐƾ֤ÇÔÈ¡£¬ÀÄÓöíÂÞ˹·¢¼þÈ˵ØÖ·


12ÔÂ3ÈÕ£¬Ó볯ÏʽáÃ˵ÄÍþвÐÐΪÕßKimsuky£¬±»Ö¸ÓëһϵÁÐÍøÂçµöÓã¹¥»÷ÓйØÁª¡£ÕâЩ¹¥»÷Ö÷Ҫͨ¹ý·¢ËÍÔ´×Ô¶íÂÞ˹·¢¼þÈ˵ØÖ·µÄµç×ÓÓʼþ½øÐУ¬Ö¼ÔÚÇÔȡƾ֤¡£¾Ýº«¹úÍøÂçÄþ¾²¹«Ë¾GeniansÊӲ죬µöÓãÓʼþ×î³õÖ÷Ҫͨ¹ýÈÕ±¾ºÍº«¹úµÄµç×ÓÓʼþ·þÎñ·¢ËÍ£¬µ«´Ó9ÔÂÖÐÑ®¿ªÊ¼£¬Î±×°³ÉÀ´×Ô¶íÂÞ˹µÄµöÓãÓʼþÖð½¥Ôö¶à£¬ÀÄÓÃVKµÄMail.ruµç×ÓÓʼþ·þÎñ£¬¸Ã·þÎñÖ§³ÖÎå¸öÌåÃûÓò¡£Kimsuky¹¥»÷ÕßÀûÓÃÕâЩ·¢¼þÈËÓòαװ³É½ðÈÚ»ú¹¹ºÍ»¥ÁªÍøÃÅ»§ÍøÕ¾£¬ÈçNaver£¬½øÐÐÍøÂçµöÓã»î¶¯¡£´ËÍ⣬»¹·¢ËÍÄ£·ÂNaver MYBOXÔÆ´æ´¢·þÎñµÄÏûÏ¢£¬ÓÕµ¼Óû§µã»÷Á´½Ó£¬Éù³ÆÔÚÆäÕÊ»§Öмì²âµ½¶ñÒâÎļþ²¢ÐèҪɾ³ý£¬ÒÔ´ËÓÕÆ­Óû§¡£ÕâЩÏûÏ¢ËäÈ»ÍâòÉÏÊÇ´ÓÌض¨ÓòÃû·¢Ë͵Ä£¬µ«Êµ¼ÊÉÏÊÇÀûÓÃÊÜѬȾµÄµç×ÓÓʼþ·þÎñÆ÷·¢Ë͵Ä¡£Kimsuky»¹Éó¤Ê¹ÓúϷ¨µç×ÓÓʼþ¹¤¾ßÈçPHPMailerºÍStar£¬ÒÔÌÓ±ÜÄþ¾²¼ì²é¡£ÕâЩ¹¥»÷µÄ×îÖÕÄ¿±êÊÇƾ֤͵ÇÔ£¬½ø¶ø½Ù³ÖÊܺ¦ÕßÕË»§£¬²¢ÀûÓÃËüÃǶÔÆäËûÔ±¹¤»òÊìÈËÌᳫºóÐø¹¥»÷¡£


https://thehackernews.com/2024/12/north-korean-kimsuky-hackers-use.html


3. Å·¾¯µ·»Ù¼ÓÃÜ·¸×ïƽ̨MATRIX£¬½É»ñ´óÁ¿·Ç·¨×ʲú


12ÔÂ4ÈÕ£¬Å·ÖÞÐ̾¯×éÖ¯Ðû²¼£¬·¨¹úºÍºÉÀ¼Ö´·¨²¿ÃÅÒѵ·»ÙÓë¹ú¼Ê··¶¾¡¢ÎäÆ÷··Ô˺ÍÏ´Ç®µÈÑÏÖØ·¸×ïÓйصÄÃûΪMATRIXµÄ¼ÓÃÜÐÅÏ¢·þÎñ¡£¸Ãƽ̨×î³õÓɺÉÀ¼Õþ¸®ÔÚÒ»Ãû×ï·¸ÊÖ»úÖз¢ÏÖ£¬ÓµÓнü8000ÃûÓû§£¬·þÎñÆ÷±é²¼¶à¸ö¹ú¼Ò£¬Ö÷ÒªÔڵ¹úºÍ·¨¹ú¡£¾¯·½ÔÚÈý¸öÔµÄÊÓ²ìÖнػñ²¢ÆÆÒëÁË230¶àÍòÌõÐÅÏ¢£¬²¢ÔÚ¹ú¼ÊÐж¯ÖдݻÙÁË·þÎñÆ÷£¬´þ²¶ÁËÈýÃûÏÓÒÉÈË£¬°üÂÞƽ̨µÄÏÓÒÉËùÓÐÕߺÍÔËÓªÉÌ¡£MATRIXÓµÓÐÅÓ´óµÄ»ù´¡ÉèÊ©£¬Ìṩ¼ÓÃÜÏûϢͨ±¨¡¢Äþ¾²Í¨»°¡¢ÊÓƵºÍÓïÒô¹²ÏíÒÔ¼°ÄäÃûÍøÒ³ä¯ÀÀµÈ·þÎñ£¬ÉõÖÁÍƳöÁ˶ÄǮӦÓ÷¨Ê½ºÍ»õ±Ò¡£Å·ÖÞÐ̾¯×éÖ¯ÌåÏÖ£¬MATRIX±È֮ǰ±»È¡µÞµÄSky ECCºÍEncroChatµÈƽ̨¸üΪÅÓ´ó£¬Óû§Ö»ÄÜͨ¹ýÑûÇë¼ÓÈë¡£¾¯·½½«¼ÌÐøÊÓ²ìÓë¸Ãƽ̨Ïà¹ØµÄ·¸×ï»î¶¯¡£


https://therecord.media/matrix-criminal-encrypted-chat-platform-takedown-police


4. CISA½«Èý¸ö©¶´Ìí¼Óµ½ÒÑÖª±»ÀûÓ鶴Ŀ¼


12ÔÂ4ÈÕ£¬ÃÀ¹úÍøÂçÄþ¾²ºÍ»ù´¡ÉèÊ©Äþ¾²¾Ö£¨CISA£©½üÈÕ¸üÐÂÁËÆäÒÑÖª±»ÀûÓ鶴£¨KEV£©Ä¿Â¼£¬ÐÂÔöÁËÈý¸ö©¶´£¬·Ö±ðÊÇProjectSendµÄÉí·ÝÑéÖ¤²»Íש¶´£¨CVE-2024-11680£©¡¢North Grid ProselfµÄXMLÍⲿʵÌ壨XEE£©ÒýÓ鶴£¨CVE-2023-45727£©ÒÔ¼°Zyxel¶à·À»ðǽµÄ·¾¶±éÀú©¶´£¨CVE-2024-11667£©¡£ÆäÖУ¬ProselfµÄ©¶´ÔÊÐíδ¾­ÊÚȨµÄ¹¥»÷Õ߶ÁÈ¡·þÎñÆ÷Îļþ£¬°üÂÞÕË»§Êý¾Ý £»ProjectSendµÄ©¶´ÔòÓ°Ïìr1720֮ǰµÄ°æ±¾£¬¹¥»÷Õ߿ɽè´Ëδ¾­ÊÚȨÐÞ¸ÄÓ¦ÓÃÅäÖ㬴´½¨ÕË»§£¬ÉÏ´«¶ñÒâÈí¼þ £»¶øZyxelµÄ©¶´Ôò¿ÉÄÜÈù¥»÷Õßͨ¹ý¾«ÐÄÉè¼ÆµÄURLÏÂÔØ»òÉÏ´«Îļþ¡£¾ÝVulnCheckÑо¿ÈËÔ±³Æ£¬ProjectSendµÄ©¶´ËƺõÒѱ»Ò°Íâ¹¥»÷ÕßÀûÓã¬ÇÒ¹¥»÷ÕßÒѽÓÄÉһϵÁÐÐж¯£¬Èç¸ü¸ÄµÇ¼ҳÃæ±êÌ⣬ÆôÓÃÓû§×¢²áÒÔ»ñÈ¡Éí·ÝÑéÖ¤ºóµÄ·ÃÎÊȨÏÞ£¬²¢ÉÏ´«Webshell¡£CISAÒÑÒªÇóÁª°î»ú¹¹ÔÚ2024Äê12ÔÂ24ÈÕ֮ǰÐÞ¸´ÕâЩ©¶´£¬²¢½¨Òé˽ÈË×éÖ¯Éó²é¸ÃĿ¼²¢½â¾öÆä»ù´¡ÉèÊ©ÖеÄ©¶´£¬ÒÔ± £»¤ÍøÂçÃâÊܹ¥»÷¡£


https://securityaffairs.com/171638/security/u-s-cisa-adds-projectsend-north-grid-proself-and-zyxel-firewalls-bugs-to-its-known-exploited-vulnerabilities-catalog.html


5. DroidBot£ºÐÂÐÍAndroidÒøÐжñÒâÈí¼þÇÔÈ¡¶à¹ú¼ÓÃÜ»õ±Ò¼°ÒøÐÐƾ֤


12ÔÂ4ÈÕ£¬DroidBotÊÇÒ»ÖÖÐÂÐÍAndroidÒøÐжñÒâÈí¼þ£¬×Ô2024Äê6ÔÂÆð»îÔ¾£¬ÒÔ¶ñÒâÈí¼þ¼´·þÎñ£¨MaaS£©ÐÎʽÔËÓª£¬Ã¿ÔÂÊÛ¼Û3000ÃÀÔª¡£ËüÊÔͼÇÔÈ¡Ó¢¹ú¡¢Òâ´óÀû¡¢·¨¹ú¡¢Î÷°àÑÀ¡¢ÆÏÌÑÑÀµÈ¹úµÄ77¶à¸ö¼ÓÃÜ»õ±Ò½»Ò×ËùºÍÒøÐÐÓ¦ÓõÄƾ֤¡£¾¡¹Ü¹¦Ð§²¢²»ÐÂÓ±ÅӴ󣬵«DroidBotÔÚÓ¢¹ú¡¢Òâ´óÀû¡¢·¨¹ú¡¢ÍÁ¶úÆäºÍµÂ¹úÒÑÔì³É776ÆðÆæÌØѬȾ£¬ÏÔʾÆä¸ß¶È»îÔ¾¡£´Ë¶ñÒâÈí¼þÕý¶¦Á¦¿ª·¢ÖУ¬²¢ÊÔͼÀ©Õ¹ÖÁеØÓò£¬°üÂÞÀ­¶¡ÃÀÖÞ¡£DroidBotÓÉÍÁ¶úÆ俪·¢Õß´´½¨£¬ÎªÁªÃ˳ÉÔ±Ìṩ¶ñÒâÈí¼þ¹¹½¨Æ÷¡¢ÃüÁîºÍ¿ØÖÆ£¨C2£©·þÎñÆ÷¼°ÖÐÑë¹ÜÀíÃæ°åµÈ¹¤¾ß£¬Ê¹ÍøÂç·¸×ï·Ö×ÓÒ×ÓÚʹÓá£Ëü³£Î±×°³ÉGoogle Chrome¡¢Google PlayÉ̵ê»òAndroidÄþ¾²ÖÐÐÄ£¬ÓÕÆ­Óû§°²×°£¬³äµ±Ä¾Âí½ÇÉ«ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£Ö÷ÒªÌØÕ÷°üÂÞ¼üÅ̼Ǽ¡¢ÁýÕֺϷ¨ÒøÐÐÓ¦ÓýçÃæÏÔʾÐé¼ÙµÇ¼ҳÃæ¡¢¶ÌÐÅÀ¹½ØºÍVNCÄ£¿é¡£Ëü»¹ÀÄÓÃAndroid¸¨Öú¹¦Ð§·þÎñ¼à¿ØÓû§²Ù×÷¡£ÎªÁ˼õÇáÍþв£¬½¨ÒéAndroidÓû§½ö´ÓGoogle PlayÏÂÔØÓ¦Óã¬×Ðϸ¼ì²éȨÏÞÇëÇ󣬲¢È·±£Play Protect´¦Óڻ״̬¡£


https://www.bleepingcomputer.com/news/security/new-droidbot-android-malware-targets-77-banking-crypto-apps/


6. BT¼¯ÍÅÔâBlack BastaÀÕË÷Èí¼þ¹¥»÷£¬²¿ÃÅ·þÎñÆ÷ÒѹرÕ


12ÔÂ4ÈÕ£¬¿ç¹úµçОÞÍ·BT¼¯ÍÅ£¨Ç°ÉíΪӢ¹úµçÐÅ£©È·ÈÏÆäBT»áÒéÒµÎñ²¿ÃÅÔÚÔâÊÜBlack BastaÀÕË÷Èí¼þ¹¥»÷ºó£¬Òѹرղ¿ÃÅ·þÎñÆ÷¡£¾¡¹Ü´Ë´ÎÄþ¾²Ê¼þδӰÏìBT¼¯ÍŵÄÔËÓª»òBT»áÒé·þÎñ£¬µ«Black BastaÍÅ»ïÉù³ÆÒÑÈëÇָù«Ë¾·þÎñÆ÷²¢ÇÔÈ¡500GBÊý¾Ý£¬°üÂÞ²ÆÕþ¡¢×éÖ¯¡¢Óû§Êý¾ÝºÍ¸öÈËÎĵµµÈ¡£¸ÃÍŻﻹÔÚ°µÍøйÃÜÍøÕ¾ÉÏÌí¼ÓÁ˵¹¼Æʱ£¬Éù³Æ½«ÓÚÏÂÖÜй¶¾Ý³Æ±»µÁµÄÊý¾Ý¡£BT¼¯ÍÅÌåÏÖ½«¼ÌÐø»ý¼«ÊÓ²ì´ËÊ£¬²¢ÓëÏà¹Ø»ú¹¹ºÏ×÷Ó¦¶Ô¡£Black BastaÀÕË÷Èí¼þÐж¯×Ô2022Äê4ÔÂÒÔÀ´ÒÑÔì³ÉÐí¶àÖªÃûÊܺ¦Õߣ¬°üÂÞÒ½ÁƱ£½¡¹«Ë¾¡¢Õþ¸®³Ð°üÉ̵È£¬Æä·ÖÖ§»ú¹¹ÒÑÈëÇÖ500¶à¸ö×éÖ¯£¬²¢´Ó90¶àÃûÊܺ¦ÕßÊÖÖÐÊÕÈ¡ÖÁÉÙ1ÒÚÃÀÔªµÄÊê½ð¡£


https://www.bleepingcomputer.com/news/security/bt-conferencing-division-took-servers-offline-after-black-basta-ransomware-attack/