FRONTIER COMMUNICATIONSÔâµ½ºÚ¿ÍÍÅ»ïRANSOMHUBµÄ¹¥»÷

°ä²¼¹¦·ò 2024-06-06

1. FRONTIER COMMUNICATIONSÔâµ½ºÚ¿ÍÍÅ»ïRANSOMHUBµÄ¹¥»÷


6ÔÂ4ÈÕ £¬RansomHub ÀÕË÷Èí¼þ×éÖ¯Ðû³ÆÇÔÈ¡ÁËÃÀ¹úµçÐŹ«Ë¾ Frontier Communications ³¬¹ý 200 Íò¿Í»§µÄÐÅÏ¢ ¡£RansomHub ×éÖ¯Ðû³ÆÇÔÈ¡ÁËÕâ¼ÒµçОÞÍ·µÄ 5GB Êý¾Ý ¡£±»µÁÊý¾ÝÔ̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢Éç»á±£Ïպš¢ÐÅÓþ¡¢·ÖÊý¡¢µ®ÉúÈÕÆÚºÍµç»°ºÅÂë ¡£½ñÄê 4 Ô £¬Frontier Communications֪ͨÃÀ¹ú֤ȯÂòÂôίԱ»á (SEC) £¬¸Ã¹«Ë¾ÔÚÔâ·êÍøÂç¹¥»÷ºó±ØÐë¹Ø¹ØÄ³Ð©ÏµÍ³ ¡£¸ÃÊÂÎñÓÚ 4 Ô 14 ÈÕ±»·¢ÏÖ £¬Ô­ÒòÊÇÒ»Ãûδ¾­ÊÚȨµÄÍþвÐÐΪÕßδ¾­ÊÚȨ½Ó¼ûÁ˸ù«Ë¾µÄ²¿ÃÅ IT »·¾³ ¡£¸Ã¹«Ë¾¶Ô¸Ã°²È«·ì϶·¢Õ¹Á˵÷²é £¬²¢²ÉÈ¡Ðж¯½ÚÔìÊÂÎñ ¡£¸Ã¹«Ë¾Ã»ÓÐÌṩÓйØÕâ´Î¹¥»÷µÄ¾ßÌåÐÅÏ¢ £¬Ò²ÉÐδй©ÊÜÓ°ÏìÈËÊý ¡£RansomHub °ä²¼Á˱»µÁ¼Í¼µÄͼƬ×÷ΪÊý¾Ýй¶µÄÖ¤¾Ý £¬²¢Íþв˵ £¬ÈôÊÇÊܺ¦ÕßÔÚ¾ÅÌìÄÚ²»Ö§¸¶Êê½ð £¬ËûÃǽ«°ä²¼±»µÁÊý¾Ý ¡£


https://securityaffairs.com/164126/data-breach/ransomhub-gang-hacked-frontier-communications.html


2. ×êÑÐÍŶӷ¢ÏÖͨ¹ý¶ñÒâExcel¹¥»÷ÎÚ¿ËÀ¼µÄWindowsÓû§


6ÔÂ5ÈÕ £¬Ò»ÃûÍþвÐÐΪÕßÕýÊÔͼÔÚÎÚ¿ËÀ¼Óû§µÄ Windows ϵͳÉϲ¿Êð Cobalt Strike ºó·ì϶ÀûÓù¤¾ß°ü ¡£Fortinet µÄ×êÑÐÈËÔ±ÔÚ±¾ÖܵÄһƪ²©¿ÍÎÄÕÂÖаµÊ¾ £¬¸Ã»î¶¯µÄ³ÁµãËÆºõÊÇÆëȫԶ³Ì½ÚÔìÖ¸±êϵͳ £¬ÒԱ㽫À´²¿ÊðÓÐÐ§ÔØºÉ²¢¿ÉÄÜÓÃÓÚÆäËû¶ñÒâÖ÷ÕÅ ¡£°²È«¹©¸øÉÌ³Æ £¬ÍþвÕßʹÓôøÓÐǶÈëʽ Visual Basic ÀûÓ÷¨Ê½ (VBA) ºêµÄÎÚ¿ËÀ¼Ö÷Ìâ Excel Îļþ×÷Ϊ³õʼµö¶ü ¡£ÈôÊDz»ÉóÉ÷µÄÓû§ÆôÓøúê £¬Ëü»áÔÚÊܺ¦ÕßϵͳÉϲ¿Êð¶¯Ì¬Á´½Ó¿â (DLL) ÏÂÔØ·¨Ê½£¨Í¨¹ý ConfuserEX ¿ªÔ´¹¤¾ß½øÐлìºÏ£© ¡£DLL ÏÂÔØ·¨Ê½Ê×ÏÈÒª×öµÄÒ»¼þʾÍÊDzéÕÒÊÜϰȾϵͳÉÏÊÇ·ñ´æÔÚ·À²¡¶¾ºÍÆäËû¶ñÒâÈí¼þ¼ì²â¹¤¾ß ¡£ÈôÊÇÏÂÔØ·¨Ê½¼ì²âµ½´æÔÚ £¬Ëü»áÁ¢¼´ÖÕÖ¹½øÒ»²½µÄ»î¶¯ ¡£²»È» £¬Ëü»áʹÓà Web ÒªÇó´ÓÔ¶³ÌµØÎ»ÌáÈ¡ÏÂÒ»½×¶ÎµÄÓÐЧ¸ºÔØ ¡£DLL ÏÂÔØ·¨Ê½µÄÉè¼ÆÊ¹ÆäÖ»ÄÜÔÚλÓÚÎÚ¿ËÀ¼µÄÉ豸¸ßµÍÔØµÚ¶þ½×¶ÎµÄÓÐЧ¸ºÔØ ¡£¶øºó £¬ÏÂÔØ·¨Ê½»áÖ´ÐÐһϵÁв½Öè £¬µ¼Ö Cobalt Strike ²¿Êðµ½Êܺ¦ÕßÉ豸ÉÏ ¡£


https://news.hitb.org/content/ukrainian-systems-hit-cobalt-strike-malicious-excel-file


3. SYNNOVIS ÔâÀÕË÷Èí¼þ¹¥»÷ £¬Ó°ÏìÂ׶صĶà¼ÒÒ½Ôº


6ÔÂ5ÈÕ £¬Synnovis ÊǸÇÒÁºÍÊ¥ÍÐÂí˹ NHS »ù½ð»áÐÅÍÓ×¢Â׶عúÍõѧԺҽԺ NHS ÐÅÈÎÒÔ¼°Å·ÖÞ×î´óµÄÒ½ÁƼì²âºÍÕï¶ÏÌṩÉÌ SYNLAB Ö®¼äµÄ²¡ÀíѧºÏ×÷ͬ°é¹ØÏµ ¡£Synnovis ÔÚÆäÍøÕ¾Éϰ䲼µÄһƪÎÄÕÂÖÐÅû¶ £¬ÆäÊÇÀÕË÷Èí¼þ¹¥»÷µÄÊܺ¦Õß ¡£Õâ¼Ò²¡ÀíѧºÍÕï¶Ï·þÎñÌṩÉÌÔÚ NHS ר¼ÒµÄÔ®ÊÖ϶԰²È«·ì϶·¢Õ¹Á˵÷²é ¡£×¨¼ÒÃÇÔÚÖÂÁ¦È«ÃæÆÀ¹À¹¥»÷µÄÓ°Ïì £¬²¢²ÉÈ¡Êʵ±´ëÊ©¶ôÔìÊÂÎñ ¡£¸Ã¹«Ë¾»¹°ä·¢ £¬ËûÃÇÔÚÓë NHS Trust ºÏ×÷ͬ°éÇ×êǺÏ×÷ £¬ÒÔ¾¡Á¿Ï÷¼õ¶Ô»¼ÕßºÍÆäËû·þÎñÓû§µÄÓ°Ïì ¡£Ä¿Ç° £¬¸Ã¹«Ë¾ÉÐδÌṩÓйØÕâ´Î¹¥»÷µÄ¾ßÌåÐÅÏ¢ £¬ÀýÈçϰȾÆäϵͳµÄ¶ñÒâÈí¼þ¼Ò×åÒÔ¼°ÊÇ·ñÔâ·êÊý¾Ýй¶ ¡£4Ô £¬SYNLAB¼¯ÍÅÒâ´óÀû·Ö¹«Ë¾Synlab ItaliaÒòÔâ·êBlackbastaÍøÂç¹¥»÷¶øÏÝÈë¸édz ¡£¸Ã¹«Ë¾ÔÝÍ£ÁËÒâ´óÀû²ÉÑùµã¡¢Ò½ÁÆÖÐÐĺͳ¢ÊÔÊÒµÄËùÓл ¡£


https://securityaffairs.com/164142/cyber-crime/ransomware-attack-synnovis-london-hospitals.html


4. BianLian й¶Êý¾Ýºó £¬°Ä´óÀûÑÇ¿óÒµ¹«Ë¾Åû¶Υ¹æÐÐΪ


6ÔÂ5ÈÕ £¬±±·½¿óÒµ¹«Ë¾ÔçЩʱ³½°ä²¼²¼¸æÖÒ¸æ³Æ £¬¸Ã¹«Ë¾Ôâ·êÍøÂç¹¥»÷ÊÂÎñ £¬µ¼Ö²¿Ãű»µÁÊý¾Ý±»°ä²¼ÔÚ°µÍøÉÏ ¡£Northern Minerals ÊÇÒ»¼Ò°Ä´óÀûÑǹ«Ë¾ £¬×¨Ò»ÓÚ¿±Ì½ºÍ¿ª·¢³ÁÏ¡ÍÁÔªËØ (HRE) £¬³ö¸ñÊÇïáºÍï« £¬ÓÃÓÚµç×Ó¡¢µç³ØºÍ·É»ú ¡£¸Ã¹«Ë¾¶Ô°Ä´óÀûÑǵ±¾ÖÀ´ËµÓµÓÐÖÁ¹Ø³ÁÒªµÄÕ½ÊõÒâ˼ £¬×î½ü°Ä´óÀûÑǵ±¾ÖºôÓõÖйú¹É¶«ÏúÊÛÆäÔÚ¸ÃÏ¡ÍÁ¿ó¹«Ë¾µÄ¹É·Ý¾ÍÖ¤ÁËÈ»ÕâÒ»µã ¡£¸Ã¹«Ë¾ÔÚ°Ä´óÀûÑÇ֤ȯÂòÂôËù (ASX) ¹«¿ªÂòÂô £¬¹ÉƱ´úÂëΪ¡°NTU¡± £¬Òò¶øÓÐ˾·¨ÒåÇóʵʱÅû¶ÈκÎÊý¾Ýй¶ÊÂÎñ ¡£¸Ã¹«Ë¾½ñÌìÅû¶ £¬ÆäϵͳÖеÄÊý¾ÝÓÚ 2024 Äê 3 ÔÂÏÂÑ®±»ÇÔÈ¡ £¬Ëæºó°ä²¼ÔÚ°µÍøÉÏ £¬µ«Ã»ÓÐÐ¹Â©ÕØÊÂÕßµÄÃû×Ö ¡£¸Ã¹«Ë¾°µÊ¾ £¬Òѽ«´ËÊÂ·î¸æ°Ä´óÀûÑÇÍøÂ簲ȫÖÐÐĺͰĴóÀûÑÇÐÅϢרԱ°ì¹«ÊÒ £¬Í¬Ê±»¹½«Í¨¹ý¸öÐÔ»¯Í¨Öª·î¸æÊÜÓ°ÏìµÄÓ×ÎÒ ¡£


https://www.bleepingcomputer.com/news/security/australian-mining-company-discloses-breach-after-bianlian-leaks-data/


5. ÐÂÐÍ V3B ÍøÂç´¹µö¹¤¾ß°ü¶Ô×¼ 54 ¼ÒÅ·ÖÞÒøÐеĿͻ§


6ÔÂ4ÈÕ £¬ÍøÂç·¸×ï·Ö×ÓÔÚ Telegram ÉÏÍÆ¹ãÒ»ÖÖÃûΪ¡°V3B¡±µÄÐÂÐÍÍøÂç´¹µö¹¤¾ß°ü £¬Ä¿Ç°¸Ã¹¤¾ß°üµÄÖ¸±êÊǰ®¶ûÀ¼¡¢ºÉÀ¼¡¢·ÒÀ¼¡¢°ÂµØÀû¡¢µÂ¹ú¡¢·¨¹ú¡¢±ÈÀûʱ¡¢Ï£À°¡¢Â¬É­±¤ºÍÒâ´óÀûµÄ 54 ¼ÒÖØÒª½ðÈÚ»ú¹¹µÄ¿Í»§ ¡£¸ÃÍøÂç´¹µö¹¤¾ß°üµÄ¼ÛÖµÔÚÿÔ 130 ÖÁ 450 ÃÀÔªÖ®¼ä £¬¾ßÌåÈ¡¾öÓڲɰìµÄÄÚÈÝ £¬ÓµÓи߼¶»ìºÏ¡¢±¾µØ»¯Ñ¡Ïî¡¢OTP/TAN/2FA Ö§³Ö¡¢ÓëÊܺ¦ÕßµÄʵʱ̸ÌìÒÔ¼°¸÷ÀàÌӱܻúÔì ¡£¾Ý·¢ÏÖ V3B µÄ Resecurity ×êÑÐÈËÔ±³Æ £¬Æä Telegram Ƶ·ÒѾ­Õ¼Óг¬¹ý 1,250 Ãû³ÉÔ± £¬ÕâÅúעеÄÍøÂç´¹µö¼´·þÎñ (PhaaS) ƽ̨ÔÚÍøÂç·¸×ïÁìÓòѸËÙ»ñµÃ¹Ø×¢ ¡£V3B ÔÚ×Ô½ç˵ CMS ÉÏʹÓø߶ȻìºÏµÄ JavaScript ´úÂëÀ´Ìӱܷ´ÍøÂç´¹µöºÍËÑË÷ÒýÇæ»úеÈ˵ļì²â²¢Ô¤·À×êÑÐÈËÔ±µÄ¹¥»÷ ¡£ËüÔ̺¬·ÒÀ¼Óï¡¢·¨Óï¡¢Òâ´óÀûÓï¡¢²¨À¼ÓïºÍµÂÓïµÈ¶àÖÖ˵»°µÄרҵ·­ÒëÒ³Ãæ £¬ÒÔ¼ÓÇ¿ÍøÂç´¹µö¹¥»÷µÄÓÐЧÐÔ £¬Ê¹ÍþвÐÐΪÕß¿ÉÄÜ·¢Õ¹¶à¹ú»î¶¯ ¡£


https://www.bleepingcomputer.com/news/security/new-v3b-phishing-kit-targets-customers-of-54-european-banks/


6. ºÚ¿ÍÍÅ»ïͨ¹ý DM ¹¥»÷ÓâÔ½Ãû¶ÈµÄ TikTok Óû§


6ÔÂ5ÈÕ £¬TikTok °µÊ¾ £¬Ä¿Ç°ÔÚ²ÉÈ¡´ëÊ©·À±¸ÍøÂç¹¥»÷ £¬¸Ã¹¥»÷ͨ¹ýÖ±½ÓÐÂÎÅÕë¶ÔһЩ³ÛÃûÓû§ £¬ÊÔͼ½Ù³ÖËûÃǵÄÕË»§ ¡£TikTok ÒþÖԺͰ²È«ÍŶӽ²»°ÈË Jason Grosse °µÊ¾£º¡°ÎÒÃÇÒѲÉÈ¡´ëÊ©×èÖ¹Õâ´Î¹¥»÷ £¬²¢Ô¤·À½«À´ÔٴβúÉú ¡£ÎÒÃÇÔÚÓëÊÜÓ°ÏìµÄÕË»§ËùÓÐÕßÖ±½ÓºÏ×÷ £¬ÒÔÔÚ±ØÒªÊ±¸´Ô­½Ó¼ûȨÏÞ ¡£¡±Grosse °µÊ¾ £¬TikTok ÈÔÔÚµ÷²éÕâ´Î¹¥»÷ £¬Ä¿Ç°ÎÞ·¨¾ÍÆä¹æÄ£»ò¸´ÔÓˮƽ°ä·¢ÆÀÂÛ £¬³Æ¸ÃÍþв½ö½öÊÇ¡°Ç±Ôڵķì϶¡± ¡£TikTok ÈϿɴËÊÂ֮ǰ £¬ÖܶþÓб¨Â·³Æ £¬CNN µÄÕ˺ÅÉÏÖÜÔø±»ÁÙʱÈëÇÖ ¡£Semafor Ô®Òý¸ÃÐÂÎÅ»ú¹¹Ò»Î»ÄäÃûÐÂÎÅÈËÊ¿µÄ»°³Æ £¬Õâ´ÎÈëÇÖ¡°Ëƺõ²»ÊÇÓÐÈË´Ó CNN ÄÇÀï»ñµÃ½Ó¼ûȨÏÞµÄÁ˾֡± ¡£CNN ûÓÐÁ¢¼´»ØÓ¦¡¶Á¬Ïß¡·ÔÓÖ¾µÄÖÃÆÀÒªÇó ¡£¼øÓÚ½ñÄêÇïÌì¼´½«½øÐеÄ×Üͳ´óÑ¡ £¬ÈËÃǶÔÃÀ¹úÐÂÎÅ»ú¹¹Ôâµ½ºÚ¿Í¹¥»÷µÄÓÇÓôÓÈÆä¸ßÕÇ ¡£


https://news.hitb.org/content/tiktok-hack-targets-high-profile-users-dms