Young ConsultingÊý¾ÝÔâBlackSuitÀÕË÷Èí¼þÇÔȡӰÏì½ü°ÙÍòÓû§
Young Consulting£¨ÏÖConnexure£©ÓÚ2024Äê4ÔÂ10ÈÕÔâÓöBlackSuitÀÕË÷Èí¼þ¹¥»÷£¬½üÈÕÈ·ÈϽü°ÙÍòÃûÓû§Êý¾Ý±»ÇÔÈ¡¡£ÊÜÓ°ÏìµÄÊý¾Ý°üÀ¨È«Ãû¡¢Éç»á»Æ½ð³Ç¹ÙÍøºÅÂ루SSN£©¡¢³öÉúÈÕÆÚºÍ±£ÏÕË÷ÅâÐÅÏ¢¡£¹«Ë¾·¢ÏÖÕâÒ»Êý¾Ýй¶ºó£¬ÓÚ4ÔÂ13ÈÕÆô¶¯µ÷²é£¬²¢ÓÚ6ÔÂ28ÈÕÍê³É¡£BlackSuitÒѽ«Ð¹Â¶µÄÊý¾ÝÉÏ´«ÖÁÆä°µÍøÀÕË÷ÃÅ»§£¬ÍþвÕßÉù³ÆÐ¹Â¶Á˱ȹ«Ë¾Åû¶µÄ¸ü¶àÊý¾Ý¡£Young ConsultingΪÊÜÓ°ÏìÓû§ÌṩÁË12¸öÔÂÃâ·ÑµÄÐÅÓÃ¼à¿Ø·þÎñ£¬Óû§Ó¦¼°Ê±ÀûÓô˷þÎñ²¢¾¯ÌèÕ©ÆÐÅÏ¢¡£¸ù¾ÝCISAºÍFBI±¨¸æ£¬BlackSuitÊÇRoyalÀÕË÷Èí¼þµÄÖØÆ·ÅÆ£¬½üÄêÀ´ÒÑͨ¹ýÀÕË÷»î¶¯»ñµÃ³¬¹ý5ÒÚÃÀÔª¡£
https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/9cb5e8fe-3d04-48e5-a403-d478cdaf5c7f.html
Ñо¿ÈËÔ±¶ÔMalloxÀÕË÷Èí¼þµÄ¶ñÒâ¹¥»÷½øÐзÖÎö
Ñо¿ÈËÔ±ÊÜÑûµ÷²éÒ»ÆðÕë¶ÔÆóÒµÔÆ»·¾³µÄ¶ñÒâ¹¥»÷ʼþ£¬·¢ÏÖÁËMalloxÀÕË÷Èí¼þµÄ×Ù¼£¡£ÓÉÓÚϵͳÅäÖôíÎ󣬹¥»÷Õßͨ¹ý±©Á¦ÆÆ½â¹«¿ªµÄMicrosoft SQL·þÎñÆ÷£¬³É¹¦ÇÖÈë²¢Ö²ÈëMalloxÀÕË÷Èí¼þ¡£Mallox×î³õÓÚ2021Äê³öÏÖ£¬Ö÷ÒªÕë¶ÔWindowsϵͳ£¬Èç½ñÒÑÀ©Õ¹ÖÁLinuxºÍVMware ESXiµÈƽ̨£¬²¢×ª±äΪÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Ä£Ê½£¬Í¨¹ýÕÐÊô³ÉÔ±À©´ó¹¥»÷·¶Î§¡£MalloxÀûÓÃË«ÖØÀÕË÷²ßÂÔ£¬²»½ö¼ÓÃÜÊý¾Ý£¬»¹Íþв¹«¿ª±»µÁÐÅÏ¢£¬½øÒ»²½Ê©Ñ¹Êܺ¦×éÖ¯Ö§¸¶Êê½ð¡£´ËÍ⣬¹¥»÷Õßͨ¹ý°µÍøÐ¹Â¶Õ¾µã¹«¿ª²»Ö§¸¶Êê½ðÕßµÄÊý¾Ý£¬Ôö¼ÓÊܺ¦ÕßµÄÐÄÀíѹÁ¦¡£´Ë´Î¹¥»÷չʾÁËMalloxÍÅ»ïµÄ¸´ÔÓÊֶΣ¬°üÀ¨ÀûÓýű¾ÐÞ¸ÄÎļþȨÏÞ¡¢Çå³ýÈÕÖ¾ÎļþÒÔ¼°¹æ±Ü»Æ½ð³Ç¹ÙÍø·ÀÓù£¬ÒÔÈ·±£ÆäÀÕË÷Èí¼þµÄÓÐЧ²¿ÊðÓëÒþ²Ø¡£
²Î¿¼Á´½Ó£º
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/exposed-and-encrypted-inside-a-mallox-ransomware-attack/
Patelco֪ͨ72.6ÍòÃû¿Í»§¹ØÓÚÀÕË÷Èí¼þÊý¾Ýй¶Ê¼þ
Patelco Credit £õ£î£é£ï£î½üÈÕ¾¯¸æÆä72.6ÍòÃû¿Í»§£¬Æä¸öÈËÊý¾ÝÔÚ½ñÄêÔçЩʱºòµÄRansomHubÀÕË÷Èí¼þ¹¥»÷Öб»µÁÈ¡¡£¾¡¹Üδ¹«¿ª¹¥»÷ÕßÉí·Ý£¬µ«RansomHubºÚ¿Í×éÖ¯ÓÚ2024Äê8ÔÂ15ÈÕÔÚÆäÀÕË÷ÃÅ»§ÉÏ·¢²¼ÁËËùÓб»µÁÊý¾Ý¡£´Ë´Î¹¥»÷·¢ÉúÓÚ2024Äê6ÔÂ29ÈÕ£¬µ¼ÖÂPatelcoÔÝÍ£¿Í»§ÒøÐÐϵͳÒÔ¶ôÖÆË𺦣¬²¢ÔÚÁ½Öܺó»Ö¸´´ó²¿·ÖITϵͳ¹¦ÄÜ¡£µ÷²éÏÔʾ£¬¹¥»÷ÕßÓÚ5ÔÂ23ÈÕ·Ç·¨·ÃÎÊÍøÂ磬²¢ÔÚ6ÔÂ29ÈÕ½øÈëÊý¾Ý¿â£¬ÇÔÈ¡Á˰üÀ¨È«Ãû¡¢Éç»á»Æ½ð³Ç¹ÙÍøºÅÂë¡¢¼ÝÕÕºÅÂë¡¢³öÉúÈÕÆÚºÍµç×ÓÓʼþµØÖ·ÔÚÄÚµÄÃô¸ÐÐÅÏ¢¡£ÊÜÓ°ÏìµÄ¿Í»§½«»ñµÃΪÆÚÁ½ÄêµÄExperianÉí·Ý±£»¤ºÍÐÅÓÃ¼à¿Ø·þÎñ£¬µ«ÐèÔÚ2024Äê11ÔÂ19ÈÕǰע²á¡£´ËÍ⣬PatelcoÌáÐѿͻ§¾¯ÌèµöÓãºÍÆÛÕ©ÐÐΪ£¬±ÜÃâй¶¸öÈËÐÅÏ¢¡£
²Î¿¼Á´½Ó£º
https://www.patelco.org/notification
QilinÀÕË÷Èí¼þÀûÓÃVPNƾ֤ÇÔÈ¡ChromeÊý¾Ý
×î½ü·¢ÏÖµÄQilinÀÕË÷Èí¼þ¹¥»÷ͨ¹ýµÁÈ¡Google Chromeä¯ÀÀÆ÷ÖÐµÄÆ¾Ö¤À´ÔöÇ¿ÆäÍþв¡£¸ù¾ÝÑо¿ÈËÔ±µÄ±¨¸æ£¬¹¥»÷ÕßÓÚ2024Äê7ÔÂͨ¹ýÒ»¸öδÆôÓöàÒòËØÈÏÖ¤£¨MFA£©µÄVPNÃÅ»§½øÈëÄ¿±êÍøÂ磬²¢ÔÚ³õ´Î·ÃÎʺó18ÌìÄÚÖ´ÐÐÁ˹¥»÷¡£¹¥»÷Õß±à¼ÁËÓò¿ØÖÆÆ÷µÄĬÈÏÓò²ßÂÔ£¬´´½¨ÁËÒ»¸ö°üº¬Á½¸ö½Å±¾µÄ×é²ßÂÔ¶ÔÏó£¨GPO£©£ºÒ»¸öPowerShell½Å±¾£¨¡°IPScanner.ps1¡±£©ÓÃÓÚÇÔÈ¡Chromeä¯ÀÀÆ÷ÖÐµÄÆ¾Ö¤Êý¾Ý£¬ÁíÒ»¸öÅú´¦Àí½Å±¾£¨¡°logon.bat¡±£©ÔòÓÃÓÚÖ´ÐÐǰÕß¡£¹¥»÷ÕßÔÚÍøÂçÉÏά³ÖÁËÕâÏîGPO³¬¹ýÈýÌ죬ÆÚ¼äÓû§Ã¿´ÎµÇ¼ʱ¶¼»á´¥·¢Æ¾Ö¤ÇÔÈ¡¡£Ëæºó£¬¹¥»÷Õß½«ÇÔÈ¡µÄƾ֤Íâй²¢Çå³ýºÛ¼££¬È»ºó¼ÓÃÜÎļþ²¢ÔÚϵͳµÄÿ¸öĿ¼ÖзÅÖÃÊê½ð֪ͨ¡£
²Î¿¼Á´½Ó£º
https://news.sophos.com/en-us/2024/08/22/qilin-ransomware-caught-stealing-credentials-stored-in-google-chrome/
PG_MEM¶ñÒâÈí¼þͨ¹ý±©Á¦ÆÆ½â¹¥»÷PostgreSQLÊý¾Ý¿â½øÐмÓÃÜ»õ±ÒÍÚ¿ó
Ñо¿ÈËÔ±·¢ÏÖÁËÒ»ÖÖÃûΪPG_MEMµÄÐÂÐͶñÒâÈí¼þ£¬Ëüͨ¹ý±©Á¦ÆÆ½âPostgreSQLÊý¾Ý¿âʵÀýÀ´ÍÚ¾ò¼ÓÃÜ»õ±Ò¡£¹¥»÷Õßͨ¹ý·´¸´²Â²âÊý¾Ý¿âƾ¾Ý£¬ÀûÓÃÈõÃÜÂë»ñÈ¡·ÃÎÊȨÏÞ£¬ËæºóʹÓÃPostgreSQLµÄSQLÃüÁîÔÚÖ÷»úÉÏÖ´ÐÐÈÎÒâShellÃüÁ´ÓÊÂÊý¾ÝµÁÇÔ»ò²¿Êð¶ñÒâÈí¼þµÈ¶ñÒâ»î¶¯¡£³É¹¦ÈëÇֺ󣬹¥»÷Õß´´½¨¹ÜÀíÔ±½ÇÉ«£¬°þ¶á¡°postgres¡±Óû§µÄ³¬¼¶Óû§È¨ÏÞ£¬ÒÔ·ÀÖ¹ÆäËûÍþвÕßÀûÓÃͬÑùµÄ·½·¨·ÃÎÊÊý¾Ý¿â¡£PG_MEMͨ¹ýÔ¶³Ì·þÎñÆ÷ÏÂÔØ¶ñÒâ¸ºÔØ£¬ÖÕÖ¹¾ºÕù½ø³Ì²¢ÉèÖó־û¯£¬×îÖÕ²¿ÊðMonero¼ÓÃÜ»õ±Ò¿ó¹¤£¬ÀûÓÃÊܺ¦ÕߵķþÎñÆ÷×ÊÔ´½øÐÐÍÚ¿ó¡£
²Î¿¼Á´½Ó£º
https://www.aquasec.com/blog/pg_mem-a-malware-hidden-in-the-postgres-processes/