Ìá½»ÐèÇó
*
*

*
*
*
Á¢¼´Ìá½»
µã»÷¡±Á¢¼´Ìá½»¡±£¬±íÃ÷ÎÒÀí½â²¢Í¬Òâ ¡¶»Æ½ð³Ç¿Æ¼¼Òþ˽Ìõ¿î¡·

logo

    ²úÆ·Óë·þÎñ
    ½â¾ö·½°¸
    ¼¼ÊõÖ§³Ö
    ºÏ×÷·¢Õ¹
    ¹ØÓڻƽð³Ç

    ÉêÇëÊÔÓÃ
      ÿÖܻƽð³Ç¹ÙÍøËÙµÝ???£üRansomHub×éÖ¯ÀûÓÃTDSSKiller»Æ½ð³Ç¹ÙÍø¹¤¾ß½øÐй¥»÷
      ·¢²¼Ê±¼ä£º2024-09-14 ÔĶÁ´ÎÊý£º 2426 ´Î

      ±¾ÖÜÈȵãʼþÍþвÇ鱨


      1

      RansomHub×éÖ¯ÀûÓÃTDSSKiller»Æ½ð³Ç¹ÙÍø¹¤¾ß½øÐй¥»÷

      ¿¨°Í˹»ù´´½¨ÁËÒ»ÖÖÃûΪTDSSKillerµÄ¹¤¾ß£¬¸Ã¹¤¾ß¿ÉÒÔɨÃèϵͳÖÐÊÇ·ñ´æÔÚrootkitºÍbootkit¡£Ñо¿ÈËÔ±×î½ü·¢ÏÖRansomHubÀÕË÷×éÖ¯ÀÄÓÃTDSSKiller¹¤¾ß£¬Í¨¹ýÃüÁîÐнű¾»òÅú´¦ÀíÎļþÓëÄں˼¶·þÎñ½øÐн»»¥£¬´Ó¶ø½ûÓÃÔËÐÐÔÚ»úÆ÷ÉϵÄMalwarebytes·´¶ñÒâÈí¼þ·þÎñ£¨MBAMService£©¡£È»ºó£¬RansomHub×éÖ¯²¿ÊðLaZagneƾ֤ÊÕ¼¯¹¤¾ß£¬´Ó¸÷ÖÖÓ¦ÓóÌÐòÊý¾Ý¿âÖÐÌáÈ¡µÇ¼ÐÅÏ¢£¬ÓÃÓÚÔÚÍøÂçÖнøÐкáÏòÒÆ¶¯¡£


      ²Î¿¼Á´½Ó£º
      https://www.threatdown.com/blog/new-ransomhub-attack-uses-tdskiller-and-lazagne-disables-edr/



      2

      AkiraÀÕË÷×éÖ¯ÀûÓÃSonicWallÉ豸ÖеÄ©¶´½øÐй¥»÷»î¶¯

      ½üÆÚ£¬SonicWallÅû¶ÁËSonicOSÖеÄÒ»¸ö»Æ½ð³Ç¹ÙÍøÂ©¶´CVE-2024-40766£¬¸Ã©¶´Ó°ÏìÁËһЩSonicWall·À»ðǽÉ豸£¬²¢»áÓ°Ïì·À»ðǽµÄSSLVPN¹¦ÄÜ¡£Ñо¿ÈËÔ±·¢ÏÖ£¬AkiraÀÕË÷×é֯ͨ¹ýÈëÇÖSonicWallÉ豸ÉϵÄSSLVPNÓû§Õ˺ŽøÐÐÀÕË÷Èí¼þ¹¥»÷¡£ÔÚ·¢ÏÖµÄÿÆð°¸ÀýÖУ¬±»µÁÓõÄÕ˺Ŷ¼ÊÇÉ豸±¾ÉíµÄ±¾µØÕ˺Å£¬²¢ÇÒÕâЩÕ˺žù먦Æô¶àÒòËØÈÏÖ¤£¨MFA£©¡£Ç¿ÁÒ½¨ÒéÔËÐÐÊÜÓ°ÏìSonicWall²úÆ·µÄ×éÖ¯¾¡¿ìÉý¼¶µ½×îÐÂÖ§³ÖµÄSonicOS¹Ì¼þ°æ±¾¡£´ËÍ⣬°´ÕÕSonicWallµÄ½¨Ò飬ӦΪËùÓб¾µØ¹ÜÀíµÄSSLVPNÕËºÅÆôÓöàÒòËØÈÏÖ¤£¨MFA£©¡£


      ²Î¿¼Á´½Ó£º

      https://arcticwolf.com/resources/blog/arctic-wolf-observes-akira-ransomware-campaign-targeting-sonicwall-sslvpn-accounts/


      3

      Ñо¿ÈËÔ±Åû¶MalloxÀÕË÷Èí¼þ


      MalloxÀÕË÷Èí¼þ±³ºóµÄ¹¥»÷×éÖ¯ÓÚ2021ÄêÉϰëÄ꿪ʼÔË×÷£¬Ê׸öÒÑÖªµÄ¼ÓÃÜÑù±¾±»·¢ÏÖÓÚ2021Äê5Ô¡£¸ÃÀÕË÷Èí¼þÊǸù¾ÝÌØ¶¨Êܺ¦Õß¶¨ÖƵÄ£¬Ä¿±ê¹«Ë¾µÄÃû³Æ±»Ó²±àÂëÔÚÀÕË÷ÐÅÖв¢×÷Ϊ¼ÓÃÜÎļþµÄÀ©Õ¹Ãû¡£2023Ä꣬ÓëMalloxÀÕË÷Èí¼þÏà¹ØµÄ¹¥»÷»î¶¯ÓÐËùÔö¼Ó£¬·¢ÏÖµÄÑù±¾×ÜÊý³¬¹ý700¸ö¡£2024ÄêÉϰëÄ꣬¸Ã¶ñÒâÈí¼þÈÔÔÚ»ý¼«¿ª·¢ÖУ¬Ã¿Ô·¢²¼¶à¸öа汾£¬Í¬Ê±£¬Æä±³ºóµÄ¹¥»÷×éÖ¯Ò²ÔÚ°µÍøÂÛ̳ÖÐÕÐļÐµĹ¥»÷Õß¡£


      ²Î¿¼Á´½Ó£º

      https://securelist.com/mallox-ransomware/113529/


      4

      ¹¥»÷ÕßʹÓÃFogÀÕË÷Èí¼þÕë¶Ô½ðÈÚÐÐÒµ½øÐй¥»÷

      FogÀÕË÷Èí¼þÊÇSTOP/DJVUÀÕË÷Èí¼þ¼Ò×åµÄÒ»¸ö±äÖÖ£¬Ê״η¢ÏÖÓÚ2021Ä꣬Æä±³ºóµÄ¹¥»÷ÕßÖ÷ÒªÒÔ½ÌÓýºÍÓéÀÖÐÐÒµ½øÐй¥»÷£¬ÏÖÔÚ¿ªÊ¼Õë¶Ô½ðÈÚÐÐÒµ½øÐй¥»÷¡£Ñо¿ÈËÔ±ÔÚ2024Äê8Ô·¢ÏÖÒ»ÆðÕë¶Ô½ðÈÚÐÐÒµ¿Í»§µÄÀÕË÷Èí¼þ¹¥»÷»î¶¯£¬¹¥»÷ÕßÔÚWindows¼°Linux²Ù×÷ϵͳÉϲ¿ÊðÁËÒ»ÖÖÃûΪ¡°Fog¡±£¨ÓÖÃû¡°Lost in the Fog¡±£©µÄÀÕË÷Èí¼þ±äÖÖ¡£±»FogÀÕË÷Èí¼þ¼ÓÃܵÄÎļþͨ³£º¬ÓС°.FOG¡±»ò¡°.FLOCKED¡±µÄÀ©Õ¹Ãû£¬²¢¸½ÓÐÃûΪ¡°readme.txt¡±µÄÀÕË÷ÐÅ¡£ 


      ²Î¿¼Á´½Ó£º

      https://adlumin.com/post/fog-ransomware-now-targeting-the-financial-sector


      5

      Ñо¿ÈËÔ±Åû¶CyberVolkÀÕË÷Èí¼þ

      CyberVolkÀÕË÷Èí¼þÓÚ2024Äê7ÔÂÊ״α»·¢ÏÖ¡£CyberVolkÀÕË÷Èí¼þ×î³õʹÓÃAES¼ÓÃÜËã·¨¶ÔÊܺ¦ÕßµÄÎļþ½øÐмÓÃÜ¡£ºóÀ´£¬¹¥»÷Õß·¢²¼Á˸ÃÀÕË÷Èí¼þµÄбäÖÖ£¬¸Ã±äÖÖ½áºÏÁ˸üÇ¿µÄ¼ÓÃÜËã·¨£¬°üÀ¨ChaCha20-Poly1305¡¢AES¼ÓÃÜËã·¨£¬ÉõÖÁÊÇ¿¹Á¿×Ó¼¼Êõ¡£Ñо¿ÈËÔ±±íʾ£¬¸Ã¹¥»÷×éÖ¯ÒÑͨ¹ýÀÕË÷Èí¼þ¹¥»÷׬ȡÁ˳¬¹ý20000ÃÀÔª¡£


      ²Î¿¼Á´½Ó£º

      https://securityonline.info/cybervolk-ransomware-a-new-and-evolving-threat-to-global-cybersecurity

      Ãâ·ÑÊÔÓÃ
      ·þÎñÈÈÏß

      ÂíÉÏ×Éѯ

      400-811-3777

      »Øµ½¶¥²¿
      ¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿