·¨¹úµçÐŹ«Ë¾La Poste MobileÔâµ½LockbitµÄÀÕË÷¹¥»÷

°ä²¼¹¦·ò 2022-07-12

1¡¢·¨¹úµçÐŹ«Ë¾La Poste MobileÔâµ½LockbitµÄÀÕË÷¹¥»÷


ýÌå7ÔÂ10ÈÕ±¨Â·³Æ £¬·¨¹úµçÐÅÔËÓªÉÌLa Poste MobileÔâµ½ÁËLockbitÍÅ»ïµÄÀÕË÷¹¥»÷¡£¸Ã¹«Ë¾ÔÚÆäÍøÕ¾Éϰ䲼µÄÒ»·ÝÉêÃ÷ÖÐд· £¬¹¥»÷ʼÓÚ7ÔÂ4ÈÕ £¬Ó°ÏìÁËÆäÐÐÕþºÍÖÎÀí·þÎñ¡£ËûÃÇÔÚ»ñϤ´Ë¹ýºóÁ¢¼´²ÉÈ¡±ØÒªµÄ´ëÊ© £¬¹Ø¹ØÁËÓйØÍÆËã»úϵͳ £¬Ô̺¬ÍøÕ¾ºÍ¿Í»§Çø¡£´Ë±í £¬Ô±¹¤ÍÆËã»úÖеIJ¿ÃÅÎļþй¶ £¬¿ÉÄÜÉæ¼°Ó×ÎÒÊý¾Ý¡£ÉÏÖÜÎå £¬LockBitÍÅ»ïÒѽ«La Poste MobileÔö³¤µ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¡£


https://securityaffairs.co/wordpress/133080/cyber-crime/la-poste-mobile-ransomware.html


2¡¢ALPHVÍÅ»ïÐû³ÆÒÑÈëÇÖÈÕ±¾µÄÓÎÏ·¿¯ÐÐÉÌÍò´úÄÏÃι¬


¾ÝVGCÔÚ7ÔÂ11Èյı¨Â· £¬ALPHVÍÅ»ïÐû³ÆÒѾ­ÀÕË÷¹¥»÷ÁËÍò´úÄÏÃ鬣¨Bandai Namco£©¡£Íò´úÄÏÃι¬ÊÇÈÕ±¾³ÛÃûµÄÓÎÏ·¿¯ÐÐÉÌ £¬ÒÔ¡¶³Ô¶¹ÈË¡·¡¢¡¶ÌúÈ­¡·ºÍ¡¶ÒõÓôÖ®»ê¡·µÅ×ÎÏ·¶øÎÅÃû¡£¸ÃÐÂÎÅÓÉvx-undergroundÓÚ±¾ÖÜÒ»°ä²¼ÔÚTwitterÉÏ £¬Ä¿Ç° £¬VGCÒÑÁªÏµÍò´úÄÏÃι¬¶Ô´Ëʰ䷢ÆÀÂÛ¡£ÓÎÏ·¹¤×÷ÊÒCD Projekt RedÔÚÈ¥ÄêÒ²Ôâµ½ÁËÀÕË÷¹¥»÷ £¬µ¼ÖÂÈü²©Åó¿Ë2077ºÍÎ×ʦ3µÄÔ´´úÂë £¬ÒÔ¼°Ô±¹¤µÄ¾ßÌåÐÅϢй¶¡£


https://www.videogameschronicle.com/news/elden-ring-publisher-bandai-namco-reportedly-targeted-in-a-ransomware-attack/


3¡¢Emsisoft°ä²¼AstraLockerºÍYashmaµÄÃâ·Ñ½âÃÜÆ÷


¾ÝýÌå7ÔÂ8ÈÕ±¨Â· £¬ÐÂÎ÷À¼°²È«¹«Ë¾Emsisoft°ä²¼ÁËÀÕË÷Èí¼þAstraLockerºÍYashmaµÄÃâ·Ñ½âÃܹ¤¾ß¡£Emsisoft³Æ £¬AstraLocker½âÃÜÆ÷ºÏÓÃÓÚʹÓÃ.Astra»ò.babykÀ©´óÃû²¢»ùÓÚBabukµÄ½âÃÜÆ÷ £¬ËûÃÇ×ܹ²°ä²¼ÁË8¸öÃÜÔ¿£»Yashma½âÃÜÆ÷ºÏÓÃÓÚʹÓÃ.AstraLocker»òËæ»ú.[a-z0-9]{4}À©´óÃû²¢»ùÓÚChaosµÄ½âÃÜÆ÷ £¬ËûÃÇ×ܹ²°ä²¼ÁË3¸öÃÜÔ¿¡£Emsisoft»¹½¨Òéͨ¹ýWindowsÔ¶³Ì×ÀÃæ±»ÈëÇÖµÄϵͳ¸ü¸ÄËùÓÐÓµÓÐȨԶ³ÌµÇ¼ȨÏÞµÄÓû§µÄÍ´´¦ £¬²¢ÕÒ³ö¹¥»÷Õß¿ÉÄÜÔö³¤µÄÆäËû±¾µØÕÊ»§¡£


https://www.bleepingcomputer.com/news/security/free-decryptor-released-for-astralocker-yashma-ransomware-victims/


4¡¢×êÑÐÈËÔ±·¢ÏÖÐÂÀÕË÷Èí¼þ0megaÕë¶ÔÈ«ÇòÁìÓòÄÚµÄ×éÖ¯


ýÌå7ÔÂ8ÈÕ³Æ £¬ÃûΪ0megaµÄÐÂÀÕË÷ÍÅ»ïÕë¶ÔÈ«ÇòÁìÓòÄÚµÄ×éÖ¯½øÐÐË«³ÁÀÕË÷¹¥»÷ £¬²¢ÀÕË÷Êý°ÙÍòÃÀÔªµÄÊê½ð¡£0mega×Ô2022Äê5ÔÂÆðÍ·»îÔ¾ £¬×êÑÐÈËÔ±ÉÐδÕÒµ½ÆäÀÕË÷Èí¼þÑù±¾ £¬Òò¶øÃ»ÓÐÌ«¶à¹ØÓÚÎļþÈôºÎ±»¼ÓÃܵľßÌåÐÅÏ¢¡£¸ÃÍÅ»ïÔËÓª×ÅÒ»¸öÊý¾ÝÐ¹Â¶ÍøÕ¾ £¬Ä¿Ç°ÍйÜ×Å152 GBÊý¾Ý £¬¾Ý³ÆÊÇ5ÔµĹ¥»÷»î¶¯ÖдÓÒ»¼Òµç×Óά½¨¹«Ë¾ÇÔÈ¡µÄ¡£´Ë±í £¬ÉÏÖÜÓÐÒ»¸ö±»¹¥»÷Ö¸±êÒѱ»´ÓÖÐÒÆ³ý £¬ÕâÅú×¢¸Ã¹«Ë¾¿ÉÄÜÒѾ­Ö§¸¶ÁËÊê½ð¡£


https://www.bleepingcomputer.com/news/security/new-0mega-ransomware-targets-businesses-in-double-extortion-attacks/


5¡¢Fortinet°ä²¼°²È«¸üР£¬½¨¸´¶à¸ö²úÆ·Öеķì϶


ýÌå7ÔÂ9ÈÕ±¨Â·³Æ £¬Fortinet½¨¸´ÁËÆä¶à¿î²úÆ·Öеķì϶¡£ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬FortiADC¡¢FortiAnalyzer¡¢FortiManager¡¢FortiOSºÍFortiProxyµÈ¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄÊÇFortiNACÖпÕÃÜÂëȱµã£¨CVE-2022-26117£© £¬¿ÉÓÃÀ´Í¨¹ýCLI½Ó¼ûMySQLÊý¾Ý¿â£»»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¨CVE-2021-43072£© £¬¿Éͨ¹ýÌØÔìµÄCLIÖ´ÐкÅÁõè¾¶±éÀú·ì϶£¨CVE-2022-30302£© £¬¿Éͨ¹ýÌØÔìµÄWebÒªÇó´Óµ×²ãÎļþϵͳÖмìË÷ºÍɾ³ýËÁÒâÎļþ£»ÒÔ¼°Ä¿Â¼±éÀú·ì϶£¨CVE-2021-41031£© £¬¿É½«È¨ÏÞÌáÉýµ½SYSTEM¡£


https://securityaffairs.co/wordpress/133059/security/fortinet-multiple-issues-several-products.html


6¡¢CheckmarxÅû¶CuteBoiÀûÓÃNPM°üµÄ´ó¹æÄ£ÍÚ¿ó»î¶¯


7ÔÂ6ÈÕ £¬CheckmarxÅû¶ÁËÕë¶ÔNPM JavaScript°ü´æ´¢¿âµÄÐÂÒ»ÂֵĴó¹æÄ£ÍÚ¿ó»î¶¯¡£¸Ã»î¶¯¹éÒòÓÚ¹¥»÷ÍÅ»ïCuteBoi £¬Éæ¼°1283¸önpm°ü £¬ÕâЩ°üÄܹ»×Ô¶¯´Ó1000¶à¸ö·ÖÆçµÄÓû§ÕÊ»§Öа䲼¡£ËùÓÐÕâЩ°ü¶¼ÓµÓÐÏÕЩһÑùµÄeazyminer°üµÄ´úÂ븱±¾ £¬eazyminerÊÇXMRigµÄJS  wrapper £¬Ö¼ÔÚÀûÓÃÍÆËã»úÉÏδʹÓõÄ×ÊÔ´ £¬Èçci/cdºÍweb·þÎñÆ÷¡£×êÑÐÈËÔ±³Æ £¬CuteBoiÊǽñÄêµÚ¶þ¸ö×Ô¶¯»¯¶ÔNPMÌáÒé´ó¹æÄ£¹¥»÷µÄÍÅ»ï £¬²¢Ô¤¼Æ½«À´½«¿´µ½¸ü¶à´ËÀ๥»÷¡£


https://checkmarx.com/blog/cuteboi-detected-preparing-a-large-scale-crypto-mining-campaign-on-npm-users/