ResolverRAT¶ñÒâÈí¼þ¹¥»÷È«ÇòÔìÒ©ºÍÒ½ÁƱ£½¡»ú¹¹

°ä²¼¹¦·ò 2025-04-16

1. ResolverRAT¶ñÒâÈí¼þ¹¥»÷È«ÇòÔìÒ©ºÍÒ½ÁƱ£½¡»ú¹¹


4ÔÂ14ÈÕ £¬½üÈÕ £¬Ò»ÖÖÃûΪ¡°ResolverRAT¡±µÄÐÂÐÍÔ¶³Ì½Ó¼ûľÂí£¨RAT£©ÔÚÈ«ÇòÁìÓòÄÚËÁŰ £¬³ÉΪ×éÖ¯ÐÅÏ¢°²È«µÄÒ»´óÍþв £¬ÓÈÆä¶ÔÒ½ÁƱ£½¡ºÍÔìÒ©ÐÐÒµ×é³ÉÁËÑϳÁÌôÕ½¡£ResolverRATͨ¹ý¾«ÐÄÉè¼ÆµÄÍøÂç´¹µöµç×ÓÓʼþ½øÐд«²¼ £¬ÕâЩÓʼþ¼Ù×°³ÉÕë¶ÔÖ¸±ê¹ú¶È/µØÓò˵»°µÄºÏ·¨ÄÚÈÝ»òÉæ¼°°æÈ¨¼Óº¦µÄÖÒ¸æ £¬ÓÕʹÓû§µã»÷Á´½ÓÏÂÔØ¿´ËƺϷ¨µÄ¿ÉÖ´ÐÐÎļþ¡°hpreader.exe¡±¡£ÏÖʵÉÏ £¬¸ÃÎļþÀûÓ÷´ÉäDLL¼ÓÔØ¼¼Êõ £¬½«ResolverRATÇÄÈ»×¢ÈëÄÚ´æ £¬ÎªºóÐøµÄ¶ñÒâ»î¶¯Ì¯Æ½Â·Â·¡£Morphisec¹«Ë¾ÂÊÏÈ·¢ÏÖÁËÕâһδ±»¼Í¼µÄ¶ñÒâÈí¼þ £¬²¢Ö¸³öCheck PointºÍCisco TalosµÄ½üÆÚ»ã±¨ÖÐÒ²Ìá¼°ÁËÒ»ÑùµÄÍøÂç´¹µö»ù´¡ÉèÊ© £¬µ«Î´ÄÜ×½Äõ½ResolverRATÕâÒ»¹ÖÒìÓÐÐ§ÔØºÉ¡£ResolverRATÒÔÆä¸ß¶ÈÒñ±ÎÐÔºÍ׳´óµÄ¶ã±ÜÄÜÁ¦Öø³Æ £¬ÆëÈ«ÔÚÄÚ´æÖÐÔËÐÐ £¬ÀÄÓÃ.NET¡°ResourceResolve¡±ÊÂÎñ¼ÓÔØ¶ñÒⷨʽ¼¯ £¬ÓÐЧ¶ã±ÜÁË´«Í³°²È«¼à¿Ø¡£¸ÃľÂíѡȡ¸´ÔÓµÄ״̬»ú¼¼Êõ»ìºÏ½ÚÔìÁ÷ £¬Ê¹µÃ¾²Ì¬·ÖÎö±äµÃÒì³£ÄÑÌâ £¬²¢Í¨¹ýÖ¸ÎÆ×ÊÔ´ÒªÇó¼ì²âɳºÐºÍ·ÖÎö¹¤¾ß £¬½øÒ»²½¼ÓÇ¿ÁËÆäÒñ±ÎÐÔ¡£´Ë±í £¬ResolverRAT»¹¾ß±¸×³´óµÄÊý¾Ýй¶ְÄÜ £¬Í¨¹ý¶È¿é»úÔì´«Êä´óÊý¾Ý £¬½«´óÓÚ1MBµÄÎļþÔ׸î³É16KBµÄ¿é £¬ÒÔÌӱܼì²â¡£


https://www.bleepingcomputer.com/news/security/new-resolverrat-malware-targets-pharma-and-healthcare-orgs-worldwide/


2. ÀÕË÷Èí¼þÇÖÈÅÁËÉö͸Îö¹«Ë¾DaVitaµÄ²¿ÃÅÔËÓª


4ÔÂ14ÈÕ £¬Éö͸Îö¾ÞÍ·DaVitaÔâ·êÀÕË÷Èí¼þ¹¥»÷ £¬²¿ÃÅÔËÓªÊÜÓ°Ïì¡£¸Ã¹«Ë¾ÓÚÖÜÁùÔâ·ê¹¥»÷ £¬²¿ÃÅÍøÂç±»¼ÓÃÜ £¬ÖÜÒ»¹áÃÀ¹ú֤ȯÂòÂôίԱ»á´«µÝ´ËÊ¡£DaVitaÁ¢¼´Æô¶¯ÏìÓ¦·¨Ê½ £¬Ö´ÐжôÔì´ëÊ© £¬Ô̺¬¸ôÀëÊÜÓ°Ïìϵͳ £¬²¢ÒÑÖ´ÐÐһʱ´ëÊ©ÒÔ¸´Ô­Ä³Ð©Ö°ÄÜ £¬µ«ÎÞ·¨¹À¼ÆÖжϵijÖÐø¹¦·ò»òˮƽ¡£Ä¿Ç°ÅжÏÕâ´ÎÏ®»÷¶Ô¹«Ë¾Ôì³ÉµÄ×ÜÌåÓ°Ï컹Ϊʱ¹ýÔç¡£DaVita×÷ΪȫÇò×î´óµÄÉöÔ໤ÀíÌṩÉÌÖ®Ò» £¬ÔÚÈ«ÇòÕ¼ÓÐ3166¼ÒÃÅÕï͸ÎöÖÐÐÄ £¬Ô¼ÓÐ28.11ÍòÃû»¼Õß £¬Õâ´Î¹¥»÷¶ÔÆäÔËÓªÔì³ÉÁ˿϶¨Ó°Ïì¡£½ØÖÁÖÜÒ»ÉÏÎç £¬ÉÐÎÞÀÕË÷Èí¼þÍÅ»ïÈÏ¿ÉÕÆ¹Ü¡£ÍøÂ簲ȫר¼Ò×·×Ùµ½2025ÄêÕë¶ÔÒ½ÁƱ£½¡×éÖ¯µÄ100¶àÆðÀÕË÷Èí¼þ¹¥»÷ £¬Ò½ÁƱ£½¡»ú¹¹Ãæ¶ÔÑϸñÌôÕ½¡£Î¢ÈíÉϸöÔÂÒ²ÖÒ¸æ³Æ £¬ÀÕË÷Èí¼þ¹¥»÷ÊÇ´åÂäÒ½ÔºÃæ¶ÔµÄÖØÒªÎÊÌâ £¬¿ÉÄÜ´øÀ´Î£¼°ÐÔÃüµÄºó¹û¡£DaVitaÉÐδ»ØÓ¦¹ØÓÚ¹¥»÷×éÖ¯¼°ÊÇ·ñ»áÖ§¸¶Êê½ðµÄÖÃÆÀÒªÇó¡£


https://therecord.media/davita-kidney-dialysis-company-ransomware-attack


3. Study HotelsÔâ·êPlayÀÕË÷Èí¼þÍÅ»ïË«³ÁÀÕË÷Íþв


4ÔÂ14ÈÕ £¬Ò»¼ÒÖØÒª·þÎñÓÚ³£´ºÌÙÃËУµÄ¾«Æ·×¡ËÞÆ·ÅÆStudy HotelsÔâ·êÁËÀÕË÷Èí¼þ¹¥»÷¡£¸ÃÁ¬Ëø¾ÆµêÔÚҮ³´óѧ¡¢±öϦ·¨ÄáÑÇ´óѧ¡¢Ô¼º²¡¤»ôÆÕ½ð˹´óѧºÍÖ¥¼Ó¸ç´óѧµÈÐ£Çø¾­ÓªÉÝ»ª×¡ËÞ £¬Æä¿Í»§ÈºÔ̺¬¿Í×ù½ÌÊÚ¡¢¸ß¾»Öµ¼Ò³¤ºÍ»áÒé²Î¼ÓÕß¡£Õâ´Î¹¥»÷µÄÄ»ºóºÚÊÖPlayÀÕË÷Èí¼þÍÅ»ï £¬Íþв³ÆÈô²»Ö§¸¶Êê½ð £¬½«Ð¹Â¶Ô±¹¤¹¤×ʵ¥¡¢Éí·ÝÖ¤¼þºÍ»úÃÜÎļþµÈ¸ß¶ÈÃô¸ÐÊý¾Ý¡£Ð¹ÃÜ֪ͨÓÚ2025Äê4ÔÂ11ÈÕ°ä²¼ £¬¾àÀëÍþвÕßÉ趨µÄ×îºóÆÚÏÞ½öÊ£Ò»Ìì¡£¸ÃÍÅ»ïÒÑй¶²¿ÃÅÊý¾Ý £¬²¢³ÖÐøÍþв½«È«ÊýÊý¾Ý¹«¿ª¡£ÀÕË÷Èí¼þÍÅ»ïͨ³£½«Êܺ¦ÕßÃûµ¥ÁÐÔÚÆä°µÍøÐ¹ÃÜÍøÕ¾ÉÏ £¬ÒÔ´ËÆÈʹ×éÖ¯Ö§¸¶Êê½ð¡£ËûÃÇѡȡ˫³ÁÀÕË÷ģʽ £¬ÔÚÇÔÈ¡Êý¾Ýºó¼ÓÃÜϵͳ £¬²¢ÒÑÓ°Ïìµ½¿í·ºµÄÆóÒµºÍ¹Ø¼ü»ù´¡ÉèÊ©¡£Ä¿Ç°Éв»Ã÷ÏÔStudy HotelsÊÇ·ñÒѶÔÕâ´ÎÍþв×ö³ö»ØÓ¦¡£


https://cybernews.com/security/yale-university-hotel-chain-ransomware-attack/


4. APT29ÀûÓÃGrapeLoaderÓëWineLoader±äÖÖ¹¥»÷Å·ÖÞ±í½»ÍøÂç


4ÔÂ15ÈÕ £¬¶íÂÞ˹µ±¾ÖÖ§³ÖµÄ¼äµý×éÖ¯ÎçÒ¹±©Ñ©£¨Midnight Blizzard £¬±ðÃû¡°Cozy Bear¡±»ò¡°APT29¡±£©ÌáÒéÁËÒ»ÏîÕë¶ÔÅ·ÖÞ±í½»ÊµÌ壨Ô̺¬´óʹ¹Ý£©µÄÐÂÓã²æÊ½ÍøÂç´¹µö»î¶¯¡£Õâ´Î»î¶¯ÓÚ2025Äê1ÔÂÆô¶¯ £¬Í¨¹ý¼Ù×°³É±í½»²¿µÄµç×ÓÓʼþ £¬ÓÕµ¼ÊÕ¼þÈ˵ã»÷¶ñÒâÁ´½Ó £¬ÏÂÔØÔ̺¬GrapeLoader¶ñÒâÈí¼þ¼ÓÔØÆ÷ºÍWineLoaderºóÃÅбäÖÖµÄZIPѹËõ°ü¡£GrapeLoaderͨ¹ýDLL²à¼ÓÔØÖ´ÐÐ £¬ÍøÂçÖ÷»úÐÅÏ¢ £¬³ÉÁ¢ÓƾÃÐÔ £¬²¢ÁªÏµºÅÁîÓë½ÚÔ죨C2£©·þÎñÆ÷½Ó¹Üshellcode¡£¸Ã¼ÓÔØÆ÷Ö¼ÔÚÈ¡´ú֮ǰʹÓõĵÚÒ»½×¶ÎHTA×°ÔØ»ú¡°RootSaw¡± £¬ÒòÆäÔ½·¢Òñ±ÎºÍ¸´ÔÓ¡£GrapeLoaderÀûÓá°PAGE_NOACCESS¡±ÄÚ´æ±£»¤ºÍ10ÃëÑÓ³¤¼¼Êõ £¬Í¨¹ý¡°ResumeThread¡±ÔËÐÐshellcode £¬ÒÔ¶ã±Ü·À²¡¶¾ºÍEDRɨÃè¡£WineLoader×÷ΪÄ£¿é»¯ºóÃÅ £¬ÕƹÜÍøÂç¾ßÌåµÄÖ÷»úÐÅÏ¢ £¬Ô̺¬IPµØÖ·¡¢ÔËǰ¹ý³ÌÃû³Æ¡¢WindowsÓû§ÃûµÈ £¬ÒÔÍÆ½ø¼äµý»î¶¯¡£Ð±äÌåѡȡRVA¸´Ôì¡¢µ¼³ö±í²»Æ¥ÅäºÍÀ¬»øÖ¸Áî½øÐÐÑϳÁ»ìºÏ £¬Ìá¸ßÁËÄæÏò¹¤³ÌÄѶÈ¡£


https://www.bleepingcomputer.com/news/security/midnight-blizzard-deploys-new-grapeloader-malware-in-embassy-phishing/


5. 4chanÂÛ̳ÒÉÔâSoyjak.partyºÚ¿Í¹¥»÷¶ø±»¹Ø¹Ø


4ÔÂ15ÈÕ £¬³ÛÃûÔÚÏßÂÛ̳4chanÒÉËÆÔâ·êÑϳÁºÚ¿Í¹¥»÷¶øÏÂÏß £¬¶ûºó¼ÓÔØ¶Ï¶ÏÐøÐø¡£Ëæºó £¬Soyjak.partyͼƬÂÛ̳³ÉÔ±Ðû³ÆÊÇÕâ´Î¹¥»÷µÄÄ»ºóºÚÊÖ £¬²¢Ð¹Â¶ÁËÖÎÀíÃæ°å½ØÍ¼¼°Ò»·Ý¾Ý³ÆÊôÓÚ4chanÖÎÀíÔ±¡¢°æÖ÷µÄµç×ÓÓʼþÁбí¡£Ò»ÃûºÚ¿Í£¨Óû§ÃûΪChud£©ÔÚ4chan¹Ø¹Øºó·¢Ìû³Æ £¬ºÚ¿ÍÒÑDZÈë4chanϵͳһÄê¶à £¬Ö´ÐÐÁ˹¥»÷Ðж¯ £¬Ð¹Â¶ÁËÔ±¹¤Ó×ÎÒÐÅÏ¢ºÍÍøÕ¾´úÂ롣Ϊ½ÚÔìËðʧ £¬4chanÖÎÀíÔ±Òѽ«ËùÓзþÎñÆ÷ÏÂÏß £¬µ«Óл㱨³Æ·þÎñÆ÷Òѱ»ÆëÈ«¹¥ÆÆ £¬¿ÉÄÜÎÞ·¨Ñ¸ËÙ¸´Ô­¡£Chud·ÖÏíµÄ½ØÍ¼ÏÔʾ £¬ºÚ¿Í¿É½Ó¼û4chanµÄÔ±¹¤ÖÎÀíÃæ°åºÍÊØ»¤¹¤¾ß £¬ÕâЩ¹¤¾ßÖ°ÄÜ׳´ó £¬¿É½Ó¼ûÓû§µØÎ»ºÍIPµØÖ·¡¢³Á½¨»ò³ÁÐÂÆô¶¯°å¿é¡¢²é¿´ÈÕÖ¾ºÍÕ¾µãͳ¼ÆÐÅÏ¢ÒÔ¼°ÖÎÀíÊý¾Ý¿â¡£¹ÌÈ»¹¥»÷Õßδй©ÈëÇÖ·½Ê½ £¬µ«ÓÐÈËÒÔΪ £¬Õâ¿ÉÄÜÊÇÓÉÓÚ4chanʹÓÃÁËÑϳÁ¹ýÆÚµÄPHP°æ±¾ £¬Î´½¨²¹ºÜ¶à°²È«·ì϶¡£µ±ÌìÍíЩʱ³½ £¬4chanµÄPHPÔ´´úÂëÔÚÄäÃûÂÛ̳Kiwi FarmsÉϱ»Ð¹Â¶¡£4chan×Ô2003ÄêµÞÔìÒÔÀ´ £¬ÒÑÉÏÏß¶þÊ®¶àÄê £¬¶àÄêÀ´Ò»Ïò±»ÓÃÀ´Ð¹Â¶¾Ý³Æ´Ó¶à¼Ò³ÛÃû¹«Ë¾ÇÔÈ¡µÄÎļþ¡£


https://www.bleepingcomputer.com/news/security/infamous-message-board-4chan-taken-down-following-major-hack/


6. Lemonade±£ÏÕ¹«Ë¾´«µÝ19ÍòÓû§¼ÝÕÕºÅй¶ÊÂÎñ


4ÔÂ15ÈÕ £¬Lemonade³ÉÁ¢ÓÚ2015Äê £¬×Գơ°È«Õ»±£ÏÕ¹«Ë¾¡± £¬ÔÚÃÀ¹úºÍÅ·ÖÞÌṩ×â·¿¡¢·¿¶«¡¢Æû³µ¡¢³èÎï¼°ÈËÊÙ±£ÏÕ²úÆ·¡£¸Ã¹«Ë¾ÒÔÀûÓÃÈËΪÖÇÄܼ¼Êõ¼¤»î±£µ¥¼°´¦ÖÃË÷Åâ¶øÎÅÃû¡£¸Ã¹«Ë¾½üÈÕ֪ͨԼ19ÍòÃû¿Í»§ £¬Æä¼ÝÕÕºÅÂë¿ÉÄÜÒò¼¼Êõ¹ÊÕÏÔâй¶¡£¸ÃÊÂÎñÉæ¼°Ò»¿îÔÚÏ߯û³µ±£ÏÕÀûÓà £¬¸ÃÀûÓÃÔÊÐíÓû§»ñÈ¡±£ÏÕ±¨¼Û¼°²É°ì±£µ¥¡£¾Ý¹«Ë¾Åû¶ £¬Æû³µ±£ÏÕ±¨¼ÛÁ÷³ÌÖдæÔÚ°²È«·ì϶ £¬µ¼Ö²¿ÃÅÓû§µÄ¼ÝÕÕºÅÂë¶³ö¡£Lemonade°µÊ¾Òѽ¨¸´´Ë·ì϶¡£ÔÚ2023Äê4ÔÂÖÁ2024Äê9ÔÂÆÚ¼ä £¬¸ÃÆ½Ì¨ÔøÒÔδ¼ÓÃÜ·½Ê½´«ÊäÐÅÏ¢ £¬ÒÔÖÁ¼ÝÊ»ÅÆÕÕºÅÂëÃæ¶Ôδ¾­ÊÚȨµÄ½Ó¼û·çÏÕ¡£¹«Ë¾Ë䳯ÎÞÖ¤¾ÝÅú×¢¼ÝÕÕºÅÂë±»µÁÓà £¬µ«ÎªÔ¤·ÀDZÔÚ·çÏÕ £¬ÒÑÏòÊÜÓ°Ïì¸ö±ð·¢³ö֪ͨ £¬²¢Ìṩ12¸öÔÂÃâ·ÑÐÅÓþ¼à¿Ø¼°Éí·Ý±£»¤·þÎñ¡£LemonadeÒÑÏòÃÀ¹ú֤ȯÂòÂôίԱ»á»ã±¨ £¬Õâ´Î±äÂÒÓ°ÏìÔ¼19ÍòÈË¡£¹«Ë¾Ç¿µ÷ £¬Æ¾¾Ýµ±Ç°°ÑÎÕµÄÊÂʵÓëÇé¿ö £¬Õâ´ÎÊÂÎñδӰÏìÆäÔËÓª £¬¿Í»§Êý¾ÝÒàδÔâ¹¥»÷ £¬ÇÒ¹«Ë¾Åж¨¸ÃÊÂÎñ²»×é³É³Á´ó·çÏÕ¡£


https://www.securityweek.com/insurance-firm-lemonade-says-api-glitch-exposed-some-drivers-license-numbers/