CHRISTIE ÔÚ RANSOMHUB ¹¥»÷ºóÅû¶Êý¾Ýй¶ÊÂÎñ

°ä²¼¹¦·ò 2024-05-30
1. CHRISTIE ÔÚ RANSOMHUB ¹¥»÷ºóÅû¶Êý¾Ýй¶ÊÂÎñ


5ÔÂ28ÈÕ  £¬ÀÕË÷Èí¼þ×éÖ¯ RansomHub Íþвй¶±»µÁÊý¾Ýºó  £¬ÅÄÂôÐмÑÊ¿µÃÅû¶ÁËÊý¾Ýй¶ÊÂÎñ ¡£Õâ´Î°²È«·ì϶²úÉúÓÚ±¾Ô³õ ¡£¹¥»÷²úÉúºó  £¬¸ÃÅÄÂôÐеÄÍøÕ¾ÎÞ·¨½Ó¼û ¡£¾Ý BBC ±¨Â·  £¬¼ÑÊ¿µÃÒòÍøÂç¹¥»÷ÎÞ·¨ÏúÊÛ¼ÛÖµÔ¼ 8.4 ÒÚÃÀÔªµÄÒÕÊõÆ·ºÍÆäËû¸ß¼ÛÖµÎïÆ· ¡£´º¼¾ÅÄÂô»áÉÏÔ̺¬Ò»·ù¼ÛÖµ 3500 ÍòÃÀÔªµÄèó¸ß»­×÷ºÍÕäÏ¡ÆÏÌѾƵÈÅÄÆ· ¡£ÓÉÓÚÍøÂç¹¥»÷  £¬Ò»Ð©ÏúÊÛ±»ÍƳÙ ¡£RansomHub Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü  £¬²¢½«¸Ã¹«Ë¾Ôö³¤µ½Æä Tor Ð¹Â©ÍøÕ¾ ¡£¸ÃÀÕË÷×éÖ¯³Æ  £¬ËûÃÇÇÔÈ¡ÁË 2GB µÄÃô¸ÐÐÅÏ¢  £¬ÆäÖÐÔ̺¬ÖÁÉÙ 50 ÍòÃû¼ÑÊ¿µÃ¿Í»§µÄÓ×ÎÒÐÅÏ¢ ¡£¸Ã×éÖ¯°µÊ¾£ºÍ¨¹ý½Ó¼û¼ÑÊ¿µÃµÄÍøÂç  £¬ÎÒÃÇ¿ÉÄÜ»ñÈ¡Æä¿Í»§µÄÃô¸ÐÓ×ÎÒÐÅÏ¢  £¬Ô̺¬ [µ®ÉúµØ¡¢MRZ¡¢ÆëÈ«ÎļþºÅ¡¢µ®ÉúÈÕÆÚ¡¢µ½ÆÚÈÕÆÚ¡¢Ãû×Ö¡¢ÐÕÊÏ¡¢¿¯ÐÐÈÕÆÚ¡¢¿¯Ðлú¹¹¡¢ÐÔ±ð¡¢ÎļþÀà±ð¡¢ÎļþÀàÐÍ¡¢¹ú¼®Ãû³Æ]  £¬ÒÔ¼°À´×ÔÊÀ½ç¸÷µØµÄÖÁÉÙ 50 ÍòÃû¸öÈ˿ͻ§µÄµØÖ·¡¢Éí¸ß¡¢ÖÖ×åµÈ¸ü¶àÃô¸ÐÐÅÏ¢ ¡£


https://securityaffairs.com/163808/cyber-crime/christie-data-breach.html


2. Google Play³¬90¸ö¶ñÒâÀûÓà  £¬×°ÖÃÁ¿´ï550Íò´Î


5ÔÂ28ÈÕ  £¬Óг¬¹ý 90 ¸ö¶ñÒâ Android ÀûÓ÷¨Ê½Í¨¹ý Google Play ±»×°Öó¬¹ý 550 Íò´Î  £¬ÓÃÓÚ´«²¼¶ñÒâÈí¼þºÍ¸æ°×Èí¼þ  £¬¶ø Anatsa ÒøÐÐľÂí×î½üµÄ»î¶¯Á¿¼¤Ôö ¡£Anatsa£¨±ðÃû¡°Teabot¡±£©ÊÇÒ»ÖÖÒøÐÐľÂí  £¬Õë¶ÔÅ·ÖÞ¡¢ÃÀ¹ú¡¢Ó¢¹úºÍÑÇÖÞµÄ 650 ¶à¸ö½ðÈÚ»ú¹¹µÄÀûÓ÷¨Ê½ ¡£ËüÊÔͼÇÔÈ¡ÈËÃǵĵç×ÓÒøÐÐÆ¾Ö¤ÒÔ½øÐÐڲƭÂòÂô ¡£2024 Äê 2 Ô  £¬Threat Fabric »ã±¨³Æ  £¬×ÔÈ¥ÄêÄêµ×ÒÔÀ´  £¬Anatsa ʹÓóö²úÁ¦Èí¼þÀà±ðÖеĸ÷Ààµö¶üÀûÓ÷¨Ê½Í¨¹ý Google Play ʵÏÖÁËÖÁÉÙ 150,000 ´ÎϰȾ ¡£Zscaler »ã±¨³Æ  £¬ÔÚ´Óǰ¼¸¸öÔÂÖÐ  £¬Ëü»¹ÔÚ Google Play ÉÏ·¢ÏÖÁ˳¬¹ý 90 ¸ö¶ñÒâÀûÓ÷¨Ê½  £¬ÕâЩÀûÓ÷¨Ê½×ܹ²±»×°ÖÃÁË 550 Íò´Î ¡£´óÎÞÊý¶ñÒâÀûÓ÷¨Ê½·ÂÕÕ¹¤¾ß¡¢¸öÐÔ»¯ÀûÓ÷¨Ê½¡¢ÉãӰʵÓ÷¨Ê½¡¢³ö²úÁ¦ÒÔ¼°½¡È«ºÍ½¡ÉíÀûÓ÷¨Ê½ ¡£Õ¼¾ÝÖ÷µ¼Ö°Î»µÄÎå¸ö¶ñÒâÈí¼þ¼Ò×åÊÇ Joker¡¢Facestealer¡¢Anatsa¡¢Coper ºÍ¸÷Àà¸æ°×Èí¼þ ¡£


https://www.bleepingcomputer.com/news/security/over-90-malicious-android-apps-with-55m-installs-found-on-google-play/


3. ½©Ê¬ÍøÂçCatDDOS ´ó·ùÔö³¤ DDoS ¹¥»÷»î¶¯


5ÔÂ28ÈÕ  £¬×êÑÐÈËÔ±·¢ÏÖ  £¬Mirai É¢²¼Ê½»Ø¾ø·þÎñ (DDoS) ½©Ê¬ÍøÂç±äÖÖ CatDDoS µÄ»î¶¯½üÆÚ¼¤Ôö ¡£Õâ´Î¹¥»÷Õë¶ÔµÄÊǶà¸öÐÐÒµµÄ×éÖ¯  £¬Ô̺¬ÃÀ¹ú¡¢·¨¹ú¡¢µÂ¹ú¡¢°ÍÎ÷ºÍÖйúµÄÔÆ¹©¸øÉÌ¡¢Í¨Ñ¶ÌṩÉÌ¡¢¹¹Öþ¹«Ë¾¡¢¿ÆÑÐʵÌåºÍ½ÌÓý»ú¹¹ ¡£¸Ã¶ñÒâÈí¼þÓÚÈ¥Äê 8 Ô³õ´Î³öÏÖ  £¬²¢ÔÚ 2023 Äê 9 Ô³ÉΪһÖÖÏà¶ÔÆÕ±éµÄÍþв ¡£CatDDoS ÔÚ 12 Ô¸ù»ùÒþû  £¬´ÙʹÖйúÆæ°²ÐÅ XLab ¸ú×ÙÍþвµÄ×êÑÐÈËÔ±ÒÔΪ  £¬¸Ã¶ñÒâÈí¼þµÄÔËÓªÕß¿ÉÄÜÒѾ­ÖÕ³¡Á˹¥»÷ ¡£CatDDoS ± £»¤Ï±»ÀûÓõķì϶ӰÏìÁËÊýÊ®ÖÖ²úÆ·ºÍ¼¼Êõ  £¬Ô̺¬Apache ActiveMQ ·þÎñÆ÷¡¢Apache Log4j¡¢Cisco Linksys¡¢Jenkins·þÎñÆ÷ºÍ NetGear ·ÓÉÆ÷ ¡£


https://www.darkreading.com/cyberattacks-data-breaches/catddos-threat-groups-sharply-ramp-up-ddos-attacks


4. »¥ÁªÍøµµ°¸¹ÝºÍ Wayback Machine Ôâ·ê DDoS ÍøÂç¹¥»÷


5ÔÂ28ÈÕ  £¬»¥ÁªÍøµµ°¸¹ÝÊÇÒ»¼Ò·ÇͶ»úÐÔ×êÑÐͼÊé¹Ý  £¬¹Ý²Øº±¼û°ÙÍò·Ýº¹ÇàÎļþ¡¢±£ÁôµÄÍøÕ¾ºÍýÌåÄÚÈÝ  £¬Ä¿Ç°Õý´¦ÓÚÕмܼäЪÐÔ DDoS£¨É¢²¼Ê½»Ø¾ø·þÎñ£©ÍøÂç¹¥»÷µÄµÚÈýÌì ¡£¾ÝͼÊé¹Ý¹¤×÷ÈËÔ±³Æ  £¬²ØÆ·Êǰ²È«µÄ  £¬Ö»¹Ü·þÎñÒÀÈ»²»²»±ä ¡ £»¥ÁªÍøµµ°¸¹Ý Wayback Machine£¨±£ÁôÁ˳¬¹ý 8660 ÒÚ¸öÍøÒ³µÄº¹Çà¼Í¼£©µÄ½Ó¼ûÒ²Êܵ½ÁËÓ°Ïì ¡£×ÔÖÜÈÕ¹¥»÷ÆðÍ·ÒÔÀ´  £¬DDoS ÈëÇÖÿÃëÌáÒéÊýÍò¸öÐéαÐÅÏ¢ÒªÇó ¡£¹¥»÷ÆðÔ´Éв»Ã÷ÏÔ ¡£³ýÁË×î½üÔâ·êµÄÒ»²¨ÍøÂç¹¥»÷Ö®±í  £¬»¥ÁªÍøµµ°¸¹Ý»¹Ôâµ½ÃÀ¹úͼÊé³ö°æÒµºÍÃÀ¹ú³ªÆ¬ÒµÐ­»áµÄ¸æ×´  £¬ËûÃÇÐû³Æ»¥ÁªÍøµµ°¸¹Ý¼Óº¦ÁËÆä°æÈ¨  £¬²¢ÒªÇóÅâ³¥ÊýÒÚÃÀÔª²¢Ï÷¼õËùÓÐͼÊé¹ÝµÄ·þÎñ ¡£ 


https://blog.archive.org/2024/05/28/internet-archive-and-the-wayback-machine-under-ddos-cyber-attack/


5. Î÷ÑÅͼ¹«¹²Í¼Êé¹ÝÔâ·êÀÕË÷Èí¼þ¹¥»÷  £¬µ¼ÖÂÔÚÏßϵͳ̱»¾


5ÔÂ29ÈÕ  £¬Î÷ÑÅͼ¹«¹²Í¼Êé¹ÝÔâ·êÀÕË÷Èí¼þ¹¥»÷  £¬µ¼ÖÂÆä·þÎñÏÝÈë̱»¾¡ª¡ªÎÞÏßÍøÂç¡¢Ô±¹¤ºÍ¹Ë¿ÍʹÓõÄÍÆËã»úÒÔ¼°Õû¸öÔÚÏßĿ¼¶¼Ì±»¾ÁË ¡£¸Ã×éÖ¯ÔÚÖÜÒ»ÏÂÎçµÄÒ»·ÝÉêÃ÷ÖаµÊ¾  £¬ÊÂÎñ²úÉúÔÚÖÜÁù ¡£¸ÃͼÊé¹ÝÓÐ 27 ¸ö·ÖÆçµÄ·Ö¹Ý  £¬Îª½ü 80 Íò¾ÓÃñÌṩ·þÎñ ¡£¸ÃͼÊé¹ÝÕý±¾´òËãÔÚÕóÍö½«Ê¿ÁôÏëÈÕÖÜÄ©ÆÚ¼äÈÃϵͳÏÂÏßÒÔ¶Ô·þÎñÆ÷½øÐÐÊØ»¤  £¬µ«µ±ÌìÔçÉÏÈ´·¢ÏÖÁËÀÕË÷Èí¼þ¹¥»÷ ¡£ÔÚµ÷²éÊÂÎñµÄͬʱ  £¬¸Ã¹«Ë¾ÒѹعØËùÓÐϵͳ²¢ÁªÏµÁË·¨Âɲ¿ÃÅ ¡£Ä¿Ç°Éв»Ã÷ÏÔ¸´Ô­¹¦·ò ¡£Í¼Êé¹ÝÈÔ½«Ê¢¿ª  £¬²¢½«ÊÖ¶¯½è³ö°æ¼®ºÍ CD ¡£Î÷ÑÅͼ¹«¹²Í¼Êé¹ÝÓëÈ«Çò¶à¸ö³ÇÊкÍÏØÍ¼Êé¹ÝϵͳһÑù  £¬³ÉΪÀÕË÷Èí¼þÍÅ»ïµÄÖ¸±ê¡ª¡ªÕâЩÍÅ»ïÀûÓöԵç×ÓÊéºÍ¹Ø¼ü·þÎñµÄÐèÒª×÷Ϊ½è¿Ú  £¬ÈÃÖ¸±êÖ§¸¶Êê½ð ¡£


https://therecord.media/ransomware-attack-seattle-knocks-out


6. ÃÀ¹úµ±¾Ö¶Ô911 S5½©Ê¬ÍøÂç±³ºóµÄ·¸×ïÍÅ»ïÖ´ÐÐÔì²Ã


5ÔÂ28ÈÕ  £¬¼ÓÄôóÉ᲼³¿Ë´óѧµÄ×êÑÐÈËÔ±ÔÚԼĪÁ½Äêǰ£¨2022 Äê 6 Ô£©Ð¹Â©  £¬ÕâÖÖ·¸·¨×¡Õ¬´úÀí·þÎñͨ¹ýÌṩÃâ·Ñ VPN ·þÎñÀ´ÒýÓÕDZÔÚÊܺ¦Õß×°ÖöñÒâÈí¼þ  £¬Ö¼ÔÚ½«ËûÃÇµÄ IP µØÖ·Ôö³¤µ½ 911 S5 ½©Ê¬ÍøÂçÖÐ ¡£Æäʱ  £¬½©Ê¬ÍøÂç½ÚÔì×ÅÀ´×ÔÊÀ½ç¸÷µØµÄԼĪ 120,000 ¸öסլ´úÀí½Úµã  £¬ËùÓнڵ㶼ÓëλÓÚº£±í»òÍйÜÔÚÔÆ·þÎñÆ÷ÄڵĶà¸öºÅÁîºÍ½ÚÔì·þÎñÆ÷½øÐÐͨѶ ¡£911 S5 Òò°²È«·ì϶¶ø¡°±ÀÀ£¡±  £¬ÆäÒµÎñÔËÓªµÄ¹Ø¼ü×é¼þ±»·ÛËé ¡£Ò»µ©ÍøÂç·¸×ï·Ö×Óͨ¹ý 911 S5 ½©Ê¬ÍøÂ縲¸ÇÁËËûÃǵÄÊý×Ö×ÙÓ°  £¬ËûÃǵÄÍøÂç·¸×ïËÆºõ¾Í»á×·Òäµ½Êܺ¦ÕßµÄÍÆËã»ú¶ø²»ÊÇËûÃÇ×Ô¼ºµÄÍÆËã»ú ¡£OFAC ²¹³ä˵  £¬×¡Õ¬´úÀí½©Ê¬ÍøÂçÈëÇÖÁËԼĪ 1900 Íò¸ö IP µØÖ· ¡£ÕâЩÊÜϰȾµÄÉ豸ÔÊÐíÍøÂç·¸×ï·Ö×ÓÌá½»ÊýÍò·ÝÓë¹Ú×´²¡¶¾ÔöÔ®¡¢¾ÈÖúºÍ¾­¼Ã°²È«·¨°¸ÓйصĴòËãµÄڲƭÐÔÉêÇë  £¬Ôì³ÉÊýÊ®ÒÚÃÀÔªµÄËðʧ ¡£


https://www.bleepingcomputer.com/news/security/us-govt-sanctions-cybercrime-gang-behind-massive-911-s5-proxy-botnet-linked-to-illegitimate-residential-proxy-service/