Cl0pÀÕË÷Èí¼þÍÅ»ïÔÙÏÖ £¬Éù³Æ¹¥»÷47¼Ò¹«Ë¾

Ðû²¼Ê±¼ä 2025-02-19

1. Cl0pÀÕË÷Èí¼þÍÅ»ïÔÙÏÖ £¬Éù³Æ¹¥»÷47¼Ò¹«Ë¾


2ÔÂ13ÈÕ £¬Óë¶íÂÞ˹ÓйصÄÀÕË÷Èí¼þÍÅ»ïCl0p½üÆÚÔٴλîÔ¾ £¬Éù³Æ¶Ô°üÂÞDXC TechnologyºÍÖ¥¼Ó¸ç¹«Á¢Ñ§Ð£ÔÚÄÚµÄ47¼Ò¹«Ë¾·¢¶¯Á˹¥»÷¡£ÕâЩ¹«Ë¾±é²¼ÃÀ¹ú¡¢¼ÓÄôó¡¢Ä«Î÷¸ç¡¢Ó¢¹úºÍ°®¶ûÀ¼¡£ÆäÖÐ £¬DXC TechnologyÊÇÒ»¼ÒÓµÓÐ130,000ÃûÔ±¹¤µÄ¿ç¹úIT·þÎñºÍ×Éѯ¹«Ë¾ £¬¶øÖ¥¼Ó¸ç¹«Á¢Ñ§Ð£ÔòÊÇÃÀ¹úµÚÈý´óÑ§Çø £¬·þÎñ330,000¶àÃûѧÉú¡£Cl0pÍÅ»ï½ÓÄÉÆæÌصÄÏàͬ·½Ê½ £¬²»ÔÚ°µÍøÉÏÖ±½ÓÁªÏµÊܺ¦Õß £¬¶øÊÇÐû²¼ÏûÏ¢´ÙʹÊܺ¦ÕßÖ÷¶¯ÁªÏµ¡£¸ÃÍÅ»ï½ÓÄÉÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Ä£Ê½ºÍ¡°Ë«ÖØÀÕË÷¡±¼ÆÄ± £¬¼È¼ÓÃÜÊý¾ÝÓÖÇÔÈ¡Êý¾Ý £¬²¢ÔÚÊܺ¦Õß²»Ö§¸¶Êê½ðʱÐû²¼ÇÔÈ¡µÄÊý¾Ý¡£¾ÝÍþвÇ鱨ƽ̨FalconFeeds·ÖÏí £¬Êܺ¦ÕßÃûµ¥Öл¹°üÂÞ¿¨¶ûÉ­·ÖÏú¹«Ë¾¡¢É­±¤»ã¼¯Íŵȶà¼ÒÆóÒµºÍ×éÖ¯¡£Cl0pÍÅ»ïÀúÊ·ÉÏÔø³ïı¹ý°üÂÞMOVEitºÍFortra GoAnywhereÎļþ¹ÜÀíÈí¼þºÚ¿Í¹¥»÷ÔÚÄڵĶàÆð´ó¹æÄ£ºÚ¿Íʼþ £¬²¢´ÓÖлñÀû·áÊ¢¡£¾¡¹Ü2021ÄêÎÚ¿ËÀ¼Ö´·¨²¿ÃÅÔø´Ý»ÙÆäIT»ù´¡ÉèÊ©²¢´þ²¶¶àÃûÏÓÒÉÈË £¬µ«¸ÃÍÅ»ïÈÔÔÚ»ý¼«Ñ°ÕÒеÄÊܺ¦Õß¡£


https://cybernews.com/cybercrime/chicago-schools-dxc-technology-cl0p-ransomware/


2. ÐÂÈÕÌú¹«Ë¾ÔâBianLianÀÕË÷Èí¼þ¹¥»÷ £¬Ãô¸ÐÊý¾ÝÔâÇÔÈ¡


2ÔÂ14ÈÕ £¬È«ÇòµÚËÄ´ó´Ö¸ÖÉú²úÉÌÐÂÈÕÌú¹«Ë¾£¨Nippon Steel£©¾Ý³ÆÔâµ½ÁËBianLianÀÕË÷Èí¼þ¼¯ÍŵĹ¥»÷¡£¸Ã×éÖ¯ÔÚÆä°µÍøÍøÕ¾ÉÏÐû²¼ÐÅÏ¢ £¬Éù³ÆÖØÐÂÈÕÌúÃÀ¹ú·Ö²¿ÍøÂçÇÔÈ¡ÁË500GBµÄÊý¾Ý £¬°üÂÞ»á¼ÆÊý¾Ý¡¢¿Í»§²ÆÕþºÍ¸öÈËÐÅÏ¢¡¢Éú²úÊý¾ÝµÈÃô¸Ð×ÊÁÏ £¬²¢Ïò¹«Ë¾¸ß¹ÜÐû²¼Á˸öÈËÁªÏµÐÅÏ¢¡£´Ë´ÎÏ®»÷¶ÔÐÂÈÕÌúÀ´ËµÊ±»úÔã¸â £¬ÒòΪ×ÔÃÀ¹ú×Üͳ°ÝµÇ×èÖ¹ÆäÓëÃÀ¹ú¸ÖÌú¹«Ë¾µÄºÏ²¢¼Æ»®ÒÔÀ´ £¬¸Ã¹«Ë¾Ò»Ö±±¸ÊܹØ×¢¡£BianLian»¹ÔÚÆä°µÍøÉÏÐû²¼ÁËÒ»¸öÊý¾ÝÑù±¾ £¬ËƺõÃèÊöÁËÐÂÈÕÌúÓëÃÀ¹ú¸ÖÌú¹«Ë¾ºÏ²¢Ç°ºóµÄϸ½Ú¡£È»¶ø £¬µ±Cybernews·ÃÎÊBianLianµÄÑó´ÐÍøÕ¾Ê± £¬È´·¢ÏÖNippon²¢Î´·ºÆðÔÚÊܺ¦ÕßÃûµ¥ÉÏ £¬BianLian³ÆÐÂÈÕÌúµÄÊý¾Ý¡°ºÜ¿ì¾Í»áÐû²¼¡± £¬ÍƲâÈÕ±¾¹«Ë¾¿ÉÄÜÕýÔÚ̸ÅÐÖ§¸¶Êê½ð¡£BianLianÀÕË÷Èí¼þ×éÖ¯×Ô2022Äê6Ô·ºÆðÒÔÀ´ £¬ÒÑÕë¶ÔÒªº¦»ù´¡ÉèÊ©²¿ÃÅ¡¢ÖÐСÐÍÆóÒµÒÔ¼°Ò½ÁÆ¡¢×¨ÒµºÍ·¿µØ²úÐÐÒµ·¢¶¯Á˶à´Î¹¥»÷¡£¾ÝCISAºÍFBIµÄÁªºÏͨ¸æ £¬¸ÃÍÅ»ï¾Ý³ÆÀ´×Ô¶íÂÞ˹ £¬½ÓÄÉË«ÖØÀÕË÷ģʽ £¬Ê×ÏÈÇÔÈ¡Êý¾Ý £¬È»ºó¼ÓÃÜÊܺ¦Õßϵͳ £¬ÒÔʵÏÖ³Ö¾ÃÐÔÃüÁîºÍ¿ØÖÆ¡£


https://cybernews.com/news/nippon-steel-claimed-by-bianlian-ransomware-group/


3. StaryDobry¶ñÒâÈí¼þ»î¶¯£ºÀûÓÃÆÆ½âÓÎÏ·Á÷´«XMRigÍڿ󲡶¾


2ÔÂ18ÈÕ £¬StaryDobryÊÇÒ»¸öÕë¶ÔÈ«ÇòÓÎÏ·Íæ¼ÒµÄ´ó¹æÄ£¶ñÒâÈí¼þ»î¶¯ £¬ËüÀûÓÃÆÆ½âµÄÓÎÏ·°æ±¾ £¬ÈçGarry's Mod¡¢BeamNG.driveºÍDyson Sphere ProgramµÈSteamÉÏ¸ßÆÀ·ÖµÄÓÎÏ· £¬×÷ΪÁ÷´«¶ñÒâÈí¼þµÄÔØÌå¡£¾Ý±¨µÀ £¬¸Ã»î¶¯ÔÚ2024Äê12ÔÂÏÂÑ®ÖÁ2025Äê1ÔÂ27ÈÕÆÚ¼ä»îÔ¾ £¬Ö÷ÒªÓ°ÏìµÂ¹ú¡¢¶íÂÞ˹¡¢°ÍÎ÷¡¢°×¶íÂÞ˹ºÍ¹þÈø¿Ë˹̹µÄÓû§¡£ÍþвÐÐΪÕßÌáǰÊýÔÂÉÏ´«ÊÜѬȾµÄÓÎÏ·°²×°·¨Ê½µ½ÖÖ×ÓÍøÕ¾ £¬ÔÚ¼ÙÆÚÆÚ¼ä´¥·¢ÓÐÐ§ÔØºÉÒÔ½µµÍ±»·¢ÏֵķçÏÕ¡£StaryDobry½ÓÄɶà½×¶ÎѬȾÁ´ £¬×îÖÕÄ¿µÄÊÇÔÚÓû§ÏµÍ³Öа²×°XMRig¼ÓÃܿ󹤡£Óû§ÏÂÔØ¿´ËÆÕý³£µÄÓÎÏ·°²×°·¨Ê½ºó £¬¶ñÒâÈí¼þÖ²È뷨ʽ»áÔÚºǫ́½âѹ²¢Æô¶¯ £¬ÊÕ¼¯ÏµÍ³ÐÅÏ¢ºó·¢Ë͵½C2·þÎñÆ÷¡£Ëæºó £¬¶ñÒâÈí¼þ¼ÓÔØ·¨Ê½»áαװ³ÉWindowsϵͳÎļþ £¬´´½¨¼Æ»®ÈÎÎñÒÔÁ¬Ðø´æÔÚ £¬²¢ÔÚÂú×ãÌõ¼þʱÏÂÔØ²¢ÔËÐÐXMRigÍÚ¿ó·¨Ê½¡£XMRig¿ó¹¤ÊÇMonero¿ó¹¤µÄÐ޸İ汾 £¬ËüÁ¬½Óµ½Ë½ÈËÍÚ¿ó·þÎñÆ÷ £¬Ê¹µÃÊÕÒæ¸üÄÑ×·×Ù¡ £¿¨°Í˹»ùÖ¸³ö £¬ÕâЩ¹¥»÷¿ÉÄÜÀ´×ÔÒ»Ãû½²¶íÓïµÄ¹¥»÷Õß £¬ÇÒStaryDobryÇãÏòÓÚÒ»´ÎÐԻ £¬Ö¼ÔÚͨ¹ýÃé׼ǿ´óµÄÓÎÏ·»úÀ´×î´ó»¯ÍÚ¿óÊÕÒæ¡£


https://www.bleepingcomputer.com/news/security/cracked-garrys-mod-beamngdrive-games-infect-gamers-with-miners/


4. ·çÏÕͶ×ʾÞÍ· Insight Partners ÔâÓöÍøÂç¹¥»÷


2ÔÂ18ÈÕ £¬×ܲ¿Î»ÓÚŦԼµÄ·çÏÕͶ×ʺÍ˽ļ¹ÉȨ¹«Ë¾Insight Partners £¬ÔÚÆä30ÄêµÄÒµÎñÔËÓªÆÚ¼äÒÑͶ×ÊÁËÈ«Çò800¶à¼ÒÈí¼þºÍ¼¼Êõ³õ´´ÆóÒµ £¬¹ÜÀí×ÅÁè¼Ý900ÒÚÃÀÔªµÄ¼à¹Ü×ʲú¡£È»¶ø £¬¸Ã¹«Ë¾ÔÚ1Ô·ÝÔâÊÜÁËÒ»´ÎÅÓ´óµÄÉç»á¹¤³Ì¹¥»÷¡£¾Ý¸Ã¹«Ë¾ÖܶþÐû²¼µÄÉùÃ÷ £¬Æä²¿ÃÅÐÅϢϵͳÓÚ1ÔÂ16ÈÕÔâµ½¹¥»÷¡£·¢ÏÖÎ¥¹æÐÐΪºó £¬Insight PartnersѸËÙ½ÓÄÉÐж¯ £¬ÔÚ¼¸Ð¡Ê±ÄÚ¿ØÖÆÁ˾ÖÃæ²¢¿ªÊ¼ÊÓ²ì £¬Í¬Ê±Í¨ÖªÁËÏà¹ØÖ´·¨²¿ÃźÍÀûÒæÏà¹ØÕß £¬²¢Æ¸ÇëÁ˵ÚÈý·½ÍøÂçÄþ¾²×¨¼ÒÀ´ÆÀ¹ÀÓ°Ïì¡£ËäÈ»¸Ã¹«Ë¾ÉÐδ·ÖÏíÓйع¥»÷ÐÔÖʵĸü¶àÐÅÏ¢ £¬ÒÔ¼°Êý¾ÝÊÇ·ñÔÚ¹¥»÷Öб»·ÃÎÊ»òÇÔÈ¡ £¬µ«ÌåÏÖûÓÐÖ¤¾Ý±íÃ÷¹¥»÷ÕßÔÚ±»·¢ÏÖºóÈÔÄÜ·ÃÎÊÆäÍøÂç £¬ÇÒ´Ë´Îʼþ²¢Î´¶Ô¹«Ë¾µÄÔËÓªÔì³É½øÒ»²½µÄ×ÌÈÅ¡£Insight PartnersÕýÔÚÓëµÚÈý·½ÍøÂçÄþ¾²×¨¼Ò¡¢È¡Ö¤×¨¼ÒÒÔ¼°Íⲿִ·¨ÕÕÁϺÏ×÷ £¬Å¬Á¦È·¶¨Ê¼þµÄ·¶Î§ £¬²¢ÓëÀûÒæÏà¹ØÕß·ÖÏíÐÅÏ¢ £¬Ô¤¼ÆÕâÒ»¹ý³Ì½«ÐèÒªÊýÖÜʱ¼ä¡£Ä¿Ç° £¬¸Ã¹«Ë¾ÈÏΪ´Ë´Î¹¥»÷²»»á¶ÔͶ×Ê×éºÏ¹«Ë¾¡¢Insight»ù½ð»òÆäËûÀûÒæÏà¹ØÕß·¢ÉúÖØ´óÓ°Ïì £¬²¢ÔÊÐíÔÚÊÓ²ì¹ý³ÌÖлñµÃÏà¹ØÐÅÏ¢ºó £¬½«ÏòÊÜÓ°ÏìµÄ¸öÈËͨ±¨×îÐÂÇé¿ö¡£


https://www.bleepingcomputer.com/news/security/venture-capital-giant-insight-partners-hit-by-cyberattack/


5. ±¨Òµ¾ÞÍ·Lee EnterprisesÔâÀÕË÷Èí¼þ¹¥»÷ÖÂÔËÓªÖжÏ


2ÔÂ18ÈÕ £¬±¨Òµ³öÊé¾ÞÍ·Lee EnterprisesÈ·ÈÏ £¬ÆäÔâÓöµÄÀÕË÷Èí¼þ¹¥»÷Êǵ¼Ö¼¯ÍÅÔËÓªÁ¬ÐøÖжÏÁè¼ÝÁ½ÖܵĻù´¡Ô­Òò¡£¸Ã¼¯ÍÅÔÚ26¸öÖݳöÊé77·ÝÈÕ±¨¡¢350·ÝÖÜ¿¯¼°×¨Òµ¿¯Îï £¬ÓµÓÐÁè¼Ý120ÍòµÄÈÕ±¨¿¯ÐÐÁ¿ºÍ4400ÍòµÄÊý×Ö°æ¶ÀÁ¢·Ã¿Í¡£´Ë´Î¹¥»÷µ¼ÖÂ2ÔÂ3ÈÕϵͳÖжÏ £¬Ó°ÏìÁ˲úÎï·ÖÏú¡¢Õ˵¥¡¢ÊÕ¿îºÍ¹©Ó¦É̸¶¿îµÈÔËÓª £¬Ó¡Ë¢³öÊéÎï·ÖÏúÑÓ³Ù £¬ÔÚÏßÔËÓªÊÜÏÞ¡£½ØÖÁ2ÔÂ12ÈÕ £¬ËùÓкËÐIJúÎïÒѻָ´Õý³£·Ö·¢ £¬µ«ÖܶȺ͸¨Öú²úÎïÉÐδ»Ö¸´ £¬Õ¼¹«Ë¾×ÜÓªÒµÊÕÈëµÄ5%¡£LeeÕýÔÚÊÓ²ìÃô¸ÐÊý¾ÝÊÇ·ñй¶ £¬Í¬Ê±ÊµÊ©ÁÙʱ´ëʩά³ÖÒªº¦ÒµÎñ¹¦Ð§¡£´Ë´Î¹¥»÷µ¼Ö±¨Òµ¼¯ÍÅÏÝÈë»ìÂÒ £¬¼ÇÕߺͱ༭ÎÞ·¨·ÃÎÊÎļþ¡£´Ëǰ £¬¸Ã¼¯ÍÅÔøÔÚ2020ÄêÃÀ¹ú×Üͳ´óѡǰÔâÊÜÒÁÀʺڿ͵ÄÍøÂç¹¥»÷¡£


https://www.bleepingcomputer.com/news/security/lee-enterprises-newspaper-disruptions-caused-by-ransomware-attack/


6. Snake KeyloggerбäÖÖ£ºÒþÉí¹¥»÷WindowsÓû§²¢ÇÔȡƾ¾Ý


2ÔÂ18ÈÕ £¬New Snake Keylogger±äÖÖ £¬Ò²±»³ÆÎª404 Keylogger £¬ÊÇÒ»ÖÖÕë¶ÔWindowsÓû§µÄ¶ñÒâÈí¼þ £¬Ö÷Ҫͨ¹ýÍøÂçµöÓãµç×ÓÓʼþÁ÷´«¡£ËüʹÓÃAutoIt½Å±¾ÓïÑÔ½øÐÐÒþÉí¹¥»÷ £¬Äܹ»Èƹý³ß¶È·À²¡¶¾½â¾ö·½°¸ £¬Ôö¼Ó¼ì²âÄѶÈ¡£¸Ã¶ñÒâÈí¼þ¼Ç¼»÷¼ü¡¢²¶×½Æ¾¾Ý¡¢¼àÊÓ¼ôÌù°å £¬²¢½«±»µÁÊý¾Ýͨ¹ýµç×ÓÓʼþºÍTelegram»úÆ÷ÈËй¶µ½ÃüÁîºÍ¿ØÖÆ·þÎñÆ÷¡£ÔÚ¹¥»÷¹ý³ÌÖÐ £¬Ëü½«×ÔÉí¸±±¾Òþ²ØÔÚϵͳÆô¶¯Îļþ¼ÐÖÐ £¬²¢Ê¹Óýø³ÌÍÚ¿Õ¼¼Êõ½«¶ñÒâ¸ºÔØ×¢ÈëºÏ·¨µÄ.NET½ø³Ì £¬´Ó¶øÌӱܼì²â¡£´ËÍâ £¬Ëü»¹ÄܼìË÷Êܺ¦ÕßµØÀíλÖà £¬¼ì²â¶Ô°üÂÞÃô¸ÐÊý¾ÝµÄÎļþ¼ÐµÄ·ÃÎÊ £¬²¢´Óä¯ÀÀÆ÷×Ô¶¯Ìî³äϵͳÖÐÇÔÈ¡Êý¾Ý¡£ÕâÊÇÒ»ÖÖÅÓ´óÇÒ¹¦Ð§¸»ºñµÄ¶ñÒâÈí¼þ±äÌå £¬¶ÔÈ«ÇòWindowsÓû§×é³ÉÑÏÖØÍþв £¬ÐèÒª×éÖ¯ºÍ¸öÈ˽ÓÄɸ߼¶Íþв·À»¤ºÍÖ÷¶¯Äþ¾²´ëÊ©À´·ÀÓù¡£


https://hackread.com/snake-keylogger-variant-windows-data-telegram-bots/