ÿÖܻƽð³Ç¹ÙÍøËÙµÝ???£üRansomHub×éÖ¯ÀûÓÃTDSSKiller»Æ½ð³Ç¹ÙÍø¹¤¾ß½øÐй¥»÷
·¢²¼Ê±¼ä£º2024-09-14
ÔĶÁ´ÎÊý£º 2403 ´Î
±¾ÖÜÈȵãʼþÍþвÇ鱨
RansomHub×éÖ¯ÀûÓÃTDSSKiller»Æ½ð³Ç¹ÙÍø¹¤¾ß½øÐй¥»÷
¿¨°Í˹»ù´´½¨ÁËÒ»ÖÖÃûΪTDSSKillerµÄ¹¤¾ß£¬¸Ã¹¤¾ß¿ÉÒÔɨÃèϵͳÖÐÊÇ·ñ´æÔÚrootkitºÍbootkit¡£Ñо¿ÈËÔ±×î½ü·¢ÏÖRansomHubÀÕË÷×éÖ¯ÀÄÓÃTDSSKiller¹¤¾ß£¬Í¨¹ýÃüÁîÐнű¾»òÅú´¦ÀíÎļþÓëÄں˼¶·þÎñ½øÐн»»¥£¬´Ó¶ø½ûÓÃÔËÐÐÔÚ»úÆ÷ÉϵÄMalwarebytes·´¶ñÒâÈí¼þ·þÎñ£¨MBAMService£©¡£È»ºó£¬RansomHub×éÖ¯²¿ÊðLaZagneƾ֤ÊÕ¼¯¹¤¾ß£¬´Ó¸÷ÖÖÓ¦ÓóÌÐòÊý¾Ý¿âÖÐÌáÈ¡µÇ¼ÐÅÏ¢£¬ÓÃÓÚÔÚÍøÂçÖнøÐкáÏòÒÆ¶¯¡£
https://www.threatdown.com/blog/new-ransomhub-attack-uses-tdskiller-and-lazagne-disables-edr/
AkiraÀÕË÷×éÖ¯ÀûÓÃSonicWallÉ豸ÖеÄ©¶´½øÐй¥»÷»î¶¯
½üÆÚ£¬SonicWallÅû¶ÁËSonicOSÖеÄÒ»¸ö»Æ½ð³Ç¹ÙÍøÂ©¶´CVE-2024-40766£¬¸Ã©¶´Ó°ÏìÁËһЩSonicWall·À»ðǽÉ豸£¬²¢»áÓ°Ïì·À»ðǽµÄSSLVPN¹¦ÄÜ¡£Ñо¿ÈËÔ±·¢ÏÖ£¬AkiraÀÕË÷×é֯ͨ¹ýÈëÇÖSonicWallÉ豸ÉϵÄSSLVPNÓû§Õ˺ŽøÐÐÀÕË÷Èí¼þ¹¥»÷¡£ÔÚ·¢ÏÖµÄÿÆð°¸ÀýÖУ¬±»µÁÓõÄÕ˺Ŷ¼ÊÇÉ豸±¾ÉíµÄ±¾µØÕ˺ţ¬²¢ÇÒÕâЩÕ˺žù먦Æô¶àÒòËØÈÏÖ¤£¨MFA£©¡£Ç¿ÁÒ½¨ÒéÔËÐÐÊÜÓ°ÏìSonicWall²úÆ·µÄ×éÖ¯¾¡¿ìÉý¼¶µ½×îÐÂÖ§³ÖµÄSonicOS¹Ì¼þ°æ±¾¡£´ËÍ⣬°´ÕÕSonicWallµÄ½¨Ò飬ӦΪËùÓб¾µØ¹ÜÀíµÄSSLVPNÕËºÅÆôÓöàÒòËØÈÏÖ¤£¨MFA£©¡£https://arcticwolf.com/resources/blog/arctic-wolf-observes-akira-ransomware-campaign-targeting-sonicwall-sslvpn-accounts/
Ñо¿ÈËÔ±Åû¶MalloxÀÕË÷Èí¼þ
MalloxÀÕË÷Èí¼þ±³ºóµÄ¹¥»÷×éÖ¯ÓÚ2021ÄêÉϰëÄ꿪ʼÔË×÷£¬Ê׸öÒÑÖªµÄ¼ÓÃÜÑù±¾±»·¢ÏÖÓÚ2021Äê5Ô¡£¸ÃÀÕË÷Èí¼þÊǸù¾ÝÌØ¶¨Êܺ¦Õß¶¨ÖƵģ¬Ä¿±ê¹«Ë¾µÄÃû³Æ±»Ó²±àÂëÔÚÀÕË÷ÐÅÖв¢×÷Ϊ¼ÓÃÜÎļþµÄÀ©Õ¹Ãû¡£2023Ä꣬ÓëMalloxÀÕË÷Èí¼þÏà¹ØµÄ¹¥»÷»î¶¯ÓÐËùÔö¼Ó£¬·¢ÏÖµÄÑù±¾×ÜÊý³¬¹ý700¸ö¡£2024ÄêÉϰëÄ꣬¸Ã¶ñÒâÈí¼þÈÔÔÚ»ý¼«¿ª·¢ÖУ¬Ã¿Ô·¢²¼¶à¸öа汾£¬Í¬Ê±£¬Æä±³ºóµÄ¹¥»÷×éÖ¯Ò²ÔÚ°µÍøÂÛ̳ÖÐÕÐļÐµĹ¥»÷Õß¡£
https://securelist.com/mallox-ransomware/113529/
¹¥»÷ÕßʹÓÃFogÀÕË÷Èí¼þÕë¶Ô½ðÈÚÐÐÒµ½øÐй¥»÷
FogÀÕË÷Èí¼þÊÇSTOP/DJVUÀÕË÷Èí¼þ¼Ò×åµÄÒ»¸ö±äÖÖ£¬Ê״η¢ÏÖÓÚ2021Ä꣬Æä±³ºóµÄ¹¥»÷ÕßÖ÷ÒªÒÔ½ÌÓýºÍÓéÀÖÐÐÒµ½øÐй¥»÷£¬ÏÖÔÚ¿ªÊ¼Õë¶Ô½ðÈÚÐÐÒµ½øÐй¥»÷¡£Ñо¿ÈËÔ±ÔÚ2024Äê8Ô·¢ÏÖÒ»ÆðÕë¶Ô½ðÈÚÐÐÒµ¿Í»§µÄÀÕË÷Èí¼þ¹¥»÷»î¶¯£¬¹¥»÷ÕßÔÚWindows¼°Linux²Ù×÷ϵͳÉϲ¿ÊðÁËÒ»ÖÖÃûΪ¡°Fog¡±£¨ÓÖÃû¡°Lost in the Fog¡±£©µÄÀÕË÷Èí¼þ±äÖÖ¡£±»FogÀÕË÷Èí¼þ¼ÓÃܵÄÎļþͨ³£º¬ÓС°.FOG¡±»ò¡°.FLOCKED¡±µÄÀ©Õ¹Ãû£¬²¢¸½ÓÐÃûΪ¡°readme.txt¡±µÄÀÕË÷ÐÅ¡£
https://adlumin.com/post/fog-ransomware-now-targeting-the-financial-sector
Ñо¿ÈËÔ±Åû¶CyberVolkÀÕË÷Èí¼þ
CyberVolkÀÕË÷Èí¼þÓÚ2024Äê7ÔÂÊ״α»·¢ÏÖ¡£CyberVolkÀÕË÷Èí¼þ×î³õʹÓÃAES¼ÓÃÜËã·¨¶ÔÊܺ¦ÕßµÄÎļþ½øÐмÓÃÜ¡£ºóÀ´£¬¹¥»÷Õß·¢²¼Á˸ÃÀÕË÷Èí¼þµÄбäÖÖ£¬¸Ã±äÖÖ½áºÏÁ˸üÇ¿µÄ¼ÓÃÜËã·¨£¬°üÀ¨ChaCha20-Poly1305¡¢AES¼ÓÃÜËã·¨£¬ÉõÖÁÊÇ¿¹Á¿×Ó¼¼Êõ¡£Ñо¿ÈËÔ±±íʾ£¬¸Ã¹¥»÷×éÖ¯ÒÑͨ¹ýÀÕË÷Èí¼þ¹¥»÷׬ȡÁ˳¬¹ý20000ÃÀÔª¡£
https://securityonline.info/cybervolk-ransomware-a-new-and-evolving-threat-to-global-cybersecurity