FIN8ʹÓÃSardonicºóÃÅбäÌå·Ö·¢ÀÕË÷Èí¼þNoberus

Ðû²¼Ê±¼ä 2023-07-20

1¡¢FIN8ʹÓÃSardonicºóÃÅбäÌå·Ö·¢ÀÕË÷Èí¼þNoberus 


SymantecÔÚ7ÔÂ18ÈÕ³Æ £¬Æä·¢Ã÷ÁËFIN8£¨ÓÖ³ÆSyssphinx£©Ê¹ÓÃˢеÄSardonic·Ö·¢ÀÕË÷Èí¼þNoberusµÄ¹¥»÷Ô˶¯  ¡£FIN8×Ô2016Äê1ÔÂ×îÏÈ»îÔ¾ £¬Ö÷ÒªÕë¶ÔÁãÊÛ¡¢²ÍÒû¡¢Âùݡ¢Ò½ÁƱ£½¡ºÍÓéÀÖµÈÐÐÒµ  ¡£×î½üµÄ¹¥»÷Óë֮ǰµÄÇø±ðÔÚÓÚ £¬×îÖÕpayloadÊÇNoberusÒÔ¼°Ê¹ÓÃÁËÖØÐÂÉè¼ÆµÄºóÃÅ  ¡£Ë¢ÐµÄSardonicÓë2021ÄêÆÊÎöµÄ°æ±¾ÓÐÐí¶àÏàͬµÄ¹¦Ð§ £¬µ«²»ÔÙʹÓÃC++±ê×¼¿â £¬¶øÊÇÌæ»»Îª´¿CʵÏÖ  ¡£±ðµÄ £¬SyssphinxתÏòÀÕË÷¹¥»÷Åú×¢ £¬ËûÃÇ¿ÉÄÜÆÚÍû´ÓÄ¿µÄ×éÖ¯ÖлñÈ¡×î´óÀûÈó  ¡£ 


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/syssphinx-fin8-backdoor


2¡¢ÑÅÊ«À¼÷칫˾Ôâµ½À´×ÔALPHVºÍClopµÄÁ½´ÎÀÕË÷¹¥»÷


¾ÝýÌå7ÔÂ19ÈÕ±¨µÀ £¬Á½¸öÀÕË÷ÍÅ»ïALPHVºÍClopÔÚÆäÍøÕ¾ÁгöÁËÃÀ×±¹«Ë¾ÑÅÊ«À¼÷ì  ¡£¸Ã¹«Ë¾ÈÏ¿ÉÁËÆäÖеÄÒ»Æð £¬³Æ¹¥»÷Õß»ñµÃÁ˲¿·ÖϵͳµÄ»á¼ûȨÏÞ £¬²¢¿ÉÄÜÇÔÈ¡ÁËÊý¾Ý £¬ËûÃÇÒѽÓÄÉÐж¯²¢¹Ø±ÕÁËһЩϵͳ  ¡£ClopËÆºõʹÓÃÁËMOVEit Transferƽ̨ÖеÄÎó²î»ñµÃ»á¼ûȨÏÞ £¬²¢Éù³ÆÇÔÈ¡ÁËÁè¼Ý131GBµÄÊý¾Ý  ¡£±¾Öܶþ £¬ALPHVÒ²ÁгöÁËÑÅÊ«À¼÷ì £¬²¢ÌåÏÖÈÔδÊÕµ½¸Ã¹«Ë¾µÄ»Ø¸´  ¡£¹¥»÷Õß»¹³Æ £¬Ã»ÓмÓÃܹ«Ë¾µÄÈκÎϵͳ £¬µ«ÈôÊǸù«Ë¾²»Ì¸ÅÐ £¬ËûÃǽ«Í¸Â¶¸ü¶àÓйر»µÁÊý¾ÝµÄϸ½Ú £¬¿ÉÄÜ»áÓ°Ïì¿Í»§¡¢¹«Ë¾Ô±¹¤ºÍ¹©Ó¦ÉÌ  ¡£


https://www.bleepingcomputer.com/news/security/est-e-lauder-beauty-giant-breached-by-two-ransomware-gangs/ 


3¡¢VirusTotalй¶´ó×ÚÓû§ÐÅÏ¢Éæ¼°FBIºÍNSAµÈ»ú¹¹


ýÌå7ÔÂ18ÈÕ³Æ £¬¶ñÒâÈí¼þɨÃè·þÎñVirusTotalй¶Á˲¿·Ö×¢²á¿Í»§µÄÐÅÏ¢  ¡£¸ÃÊÂÎñ×îÏÈÓɰµØÀû¡¶±ê×¼±¨¡·ºÍµÂ¹ú¡¶Ã÷¾µÖÜ¿¯¡·±¨µÀ £¬Ð¹Â¶Îļþ¾Þϸ½öΪ313 KB £¬°üÀ¨5600¸ö×¢²áÓû§µÄÐÅÏ¢ £¬ÀýÈçÐÕÃû¡¢ÓʼþµØÖ·ºÍ×éÖ¯µÈ  ¡£ÊÜÓ°ÏìÓû§Éæ¼°ÃÀ¹úÍøÂç˾Á¡¢ÃÀ¹ú˾·¨²¿¡¢Áª°îÊÓ²ì¾ÖºÍÃÀ¹ú¹ú¼ÒÇå¾²¾Ö £¬ÉÐÓкÉÀ¼¡¢Ì¨ÍåºÍÓ¢¹úµÄ¹Ù·½»ú¹¹  ¡£Google Cloud½²»°ÈËÌåÏÖ £¬ÆäÔ±¹¤ÔÚVirusTotalƽ̨ÉÏÎÞÒâ¼ä¹ûÕæÁËһС²¿·Ö¿Í»§×é¹ÜÀíÔ±µÄÓʼþºÍ×éÖ¯Ãû³Æ  ¡£µ±ËûÃÇÒâʶµ½Êý¾Ýй¶ºó £¬Á¬Ã¦É¾³ýÁËÕâЩÊý¾Ý  ¡£


https://www.hackread.com/virustotal-data-leak-user-intel-agencies-data/


4¡¢Ñо¿Ö°Ô±·¢Ã÷ð³äSophosµÄÀÕË÷Èí¼þSophosEncrypt


¾Ý7ÔÂ18ÈÕ±¨µÀ £¬ÍøÂçÇå¾²¹©Ó¦ÉÌSophos±»ÃûΪSophosEncryptµÄÐÂÀÕË÷Èí¼þð³ä  ¡£MalwareHunterTeam·¢Ã÷Á˸ÃÀÕË÷Èí¼þ £¬ÔçÏÈÒÔΪËüÊÇSophosºì¶ÓÑÝϰµÄÒ»²¿·Ö  ¡£È»¶ø £¬Sophos X-OpsÍŶÓÌåÏÖ £¬ËûÃÇûÓн¨Éè¸Ã¼ÓÃܳÌÐò £¬²¢ÕýÔÚÊÓ²ì¸ÃÊÂÎñ  ¡£¼ÓÃܳÌÐòÊÇÓÃRust¿ª·¢µÄ £¬±»ÃüÃûΪsophos_encrypt £¬¼ÓÃÜÎļþʱʹÓÃAES256-CBC¼ÓÃܺÍPKCS#7Ìî³ä  ¡£±ðµÄ £¬Ëü»¹Äܸü¸ÄWindows×ÀÃæ±ÚÖ½ £¬´óµ¨µØÏÔʾÁËËüËùð³äµÄSophos  ¡£


https://www.bleepingcomputer.com/news/security/cybersecurity-firm-sophos-impersonated-by-new-sophosencrypt-ransomware/


5¡¢Henry Ford HealthÔâµ½´¹ÂÚ¹¥»÷½ü17Íò»¼ÕßÐÅϢй¶


7ÔÂ17ÈÕ±¨µÀ³Æ £¬Henry Ford Health͸¶ÆäÔâµ½´¹ÂÚ¹¥»÷ £¬µ¼ÖÂ168000Ãû»¼ÕßµÄÐÅϢй¶  ¡£ÊÜÓ°Ï컼ÕßÔÚ±¾ÖÜÒ»±»¼û¸æ £¬¹¥»÷ÕßÓÚ3ÔÂ30ÈÕ»ñµÃÁËÆóÒµµç×ÓÓʼþÕÊ»§µÄ»á¼ûȨÏÞ  ¡£µ«¸Ã»ú¹¹ºÜ¿ì·¢Ã÷ÁËÕâÖÖ»á¼û  ¡£ÊÜÓ°ÏìµÄÓʼþÖаüÀ¨²¿·Ö»¼ÕßÐÅÏ¢ £¬ÕâÊÇÔÚ5ÔÂ16ÈÕ·¢Ã÷µÄ  ¡£Ð¹Â¶µÄÐÅÏ¢¿ÉÄܰüÀ¨ÐÕÃû¡¢ÐÔ±ð¡¢ÄêËê¡¢»¯ÑéЧ¹û¡¢ÊÖÊõÀàÐÍ¡¢Õï¶Ï¡¢Ò½ÁƼͼ±àºÅºÍÄÚ²¿¸ú×Ù±àºÅµÈ  ¡£¸Ã»ú¹¹³ÆÆäÕýÔÚÔöÇ¿Çå¾²²½·¥²¢ÎªÔ±¹¤Ìṩ½øÒ»²½Åàѵ  ¡£


https://www.clickondetroit.com/news/local/2023/07/17/henry-ford-health-confirms-data-breach-affecting-168000-patients/


6¡¢Check PointÐû²¼2023ÄêQ2Æ·ÅÆÍøÂç´¹ÂÚÔ˶¯µÄ±¨¸æ


7ÔÂ18ÈÕ £¬Check PointÐû²¼ÁË2023ÄêQ2Æ·ÅÆÍøÂç´¹ÂÚÔ˶¯µÄÆÊÎö±¨¸æ  ¡£2023ÄêQ2 £¬¿Æ¼¼¹«Ë¾Î¢ÈíµÄÅÅÃûÉÏÉý £¬´ÓQ1µÄµÚÈýλԾÉýÖÁQ2µÄ°ñÊ× £¬Õ¼ËùÓÐÆ·ÅÆ´¹ÂÚ¹¥»÷µÄ29%  ¡£Æä´ÎÊÇGoogle£¨19.5%£©ºÍApple£¨5.2%£©  ¡£¾ÍÐÐÒµ¶øÑÔ £¬¿Æ¼¼ÐÐÒµ±»Ã°³ä×î¶à £¬Æä´ÎÊÇÒøÐкÍÉ罻ýÌåÍøÂç £¬ÀýÈçÅÅÃûµÚËĵĸ»¹úÒøÐÐ(4.2%) £¬ÒÔ¼°½ôËæØÊºóµÄÑÇÂíÑ·(4%)ºÍÎÖ¶ûÂê(3.9%)  ¡£×îºó £¬Check Point»¹ÁгöÁ˲¿·Ö´¹ÂÚ¹¥»÷µÄʾÀý  ¡£


https://blog.checkpoint.com/security/microsoft-dominates-as-the-most-impersonated-brand-for-phishing-scams-in-q2-2023/