Ìá½»ÐèÇó
*
*

*
*
*
Á¢¼´Ìá½»
µã»÷¡±Á¢¼´Ìá½»¡±£¬±íÃ÷ÎÒÀí½â²¢Í¬Òâ ¡¶»Æ½ð³Ç¿Æ¼¼Òþ˽Ìõ¿î¡·

logo

    ²úÆ·Óë·þÎñ
    ½â¾ö·½°¸
    ¼¼ÊõÖ§³Ö
    ºÏ×÷·¢Õ¹
    ¹ØÓڻƽð³Ç

    ÉêÇëÊÔÓÃ
      ÿÖܻƽð³Ç¹ÙÍøËÙµÝ???|STAC6451¹¥»÷Ó¡¶È¶à¼Ò×éÖ¯²¢²¿ÊðMimicÀÕË÷Èí¼þ
      ·¢²¼Ê±¼ä£º2024-08-09 ÔĶÁ´ÎÊý£º 2718 ´Î
      ±¾ÖÜÈȵãʼþÍþвÇ鱨


       
      1

      STAC6451¹¥»÷Ó¡¶È¶à¼Ò×éÖ¯²¢²¿ÊðMimicÀÕË÷Èí¼þ
      Ñо¿ÈËÔ±ÔÚÖ§³ÖÒ»Æð»îԾʼþʱ£¬·¢ÏÖÁËÒ»¸öеÄÍþв»î¶¯¼¯ÈºSTAC6451£¬¸Ã¼¯ÈºÍ¨¹ý¹«¿ª±©Â¶ÔÚ»¥ÁªÍøµÄMicrosoft SQL ServerÊý¾Ý¿â·þÎñÆ÷£¨Ä¬ÈÏTCP/IP¶Ë¿Ú1433£©¶ÔÓ¡¶ÈµÄ¶à¼Ò×éÖ¯½øÐй¥»÷£¬ÊÔͼ²¿ÊðÀÕË÷Èí¼þ¡£STAC6451¼¯ÈºµÄÖ÷ÒªÌØÕ÷ÊÇÀÄÓÃSQL Server½øÐÐδ¾­ÊÚȨµÄ·ÃÎÊ£¬²¢Í¨¹ýxp_cmdshellÔ¶³ÌÖ´ÐдúÂ룬ʹÓÃBCP£¨´óÅúÁ¿¸´ÖƳÌÐò£©¹¤¾ßÔÚ±»¹¥»÷µÄMSSQLÊý¾Ý¿âÖа²ÖöñÒâ¸ºÔØºÍ¹¤¾ß£¬°üÀ¨È¨ÏÞÌáÉý¹¤¾ß¡¢Cobalt Strike BeaconsºÍMimicÀÕË÷Èí¼þ¶þ½øÖÆÎļþ¡£´ËÍ⣬¹¥»÷Õß»¹ÀûÓÃPython Impacket¿â´´½¨¸÷ÖÖºóÃÅÕË»§ÓÃÓÚºáÏòÒÆ¶¯ºÍ³Ö¾Ã»¯¡£Ñо¿ÈËÔ±Ê×´ÎÔÚ2024Äê3ÔÂÄ©·¢Ïָû£¬µ±Ê±Ö§³Öij×éÖ¯µÄSQL ServerÔâµ½¹¥»÷²¢³¢ÊÔºáÏòÒÆ¶¯¡£ÉîÈë·ÖÎöºó£¬·¢ÏÖÁ˶à¸ö¾ßÓÐÏàËÆÕ½Êõ¡¢¼¼ÊõºÍ³ÌÐò£¨TTPs£©µÄʼþ£¬×îÖÕÐγÉÁËSTAC6451¼¯Èº¡£¸Ã¼¯ÈºÖ÷Ҫͨ¹ý±©Â¶ÔÚ»¥ÁªÍøµÄMSSQL·þÎñÆ÷»ñÈ¡³õʼ·ÃÎÊȨÏÞ£¬²¢Ê¹Óüòµ¥ÕË»§Æ¾Ö¤½øÐб©Á¦ÆÆ½â¹¥»÷¡£¹¥»÷ÕßÔÚ»ñÈ¡·ÃÎÊȨÏÞºó£¬ÆôÓÃxp_cmdshellÒÔͨ¹ýSQL·þÎñÖ´ÐÐÃüÁî¡£
      __

      ___²Î¿¼Á´½Ó£º__

      __
      __

      ___https://www.board-cybersecurity.com/incidents/tracker/20240621-sonic-automotive-inc-cybersecurity-incident/#8-ka-filed-on-2024-08-05


      3

      McLarenҽԺϵͳÒòINC RansomÀÕË÷Èí¼þ¹¥»÷ÖжÏ
      McLaren Health CareÒ½ÔºµÄITºÍµç»°ÏµÍ³ÔÚÒ»´ÎÓëINC RansomÀÕË÷Èí¼þÓйصĹ¥»÷ºóÖжÏ¡£McLarenÊÇÒ»¼ÒÄêÊÕÈ볬¹ý65ÒÚÃÀÔªµÄ·ÇÓªÀûÐÔÒ½ÁÆÏµÍ³£¬ÔÚÃÜЪ¸ùÖÝÔËÓª13¼ÒÒ½Ôº£¬ÓµÓÐ640ÃûÒ½ÉúºÍ³¬¹ý28000ÃûÔ±¹¤£¬²¢ÓëÓ¡µÚ°²ÄÉÖÝºÍ¶íº¥¶íÖݵÄ113000¸öÍøÂçÌṩÉ̺Ï×÷¡£McLarenÔÚÆäÍøÕ¾ÉÏ·¢²¼ÉùÃ÷³Æ£¬ÕýÔÚµ÷²éÆäÐÅÏ¢¼¼ÊõϵͳµÄÖжÏ£¬½¨Ò黼ÕßÔÚԤԼʱЯ´øÏêϸµÄÒ©ÎïÐÅÏ¢¡¢Ò½Éú¶©µ¥ºÍ×î½üµÄʵÑéÊÒ²âÊÔ½á¹û¡£²¿·ÖÔ¤Ô¼ºÍ·Ç½ô¼±»òÑ¡ÔñÐÔ³ÌÐò¿ÉÄÜ»á±»ÖØÐ°²ÅÅ¡£¾¡¹ÜMcLarenÉÐδÅû¶Ê¼þµÄ¾ßÌåÐÔÖÊ£¬µ«McLaren Bay Region HospitalµÄÔ±¹¤·ÖÏíÁËÒ»·ÝÀÕË÷ÐÅ£¬¾¯¸æ³ÆÒ½ÔºÏµÍ³Òѱ»¼ÓÃÜ£¬Èç¹û²»Ö§¸¶Êê½ð£¬Êý¾Ý½«±»Ð¹Â¶µ½INC RansomÀÕË÷Èí¼þÍÅ»ïµÄÍøÕ¾ÉÏ¡£


      ²Î¿¼Á´½Ó£º

      https://www.mclaren.org/main/notification

      4

      ÀÕË÷Èí¼þÍÅ»ïÀûÓÃÐÂÐÍSharpRhino¶ñÒâÈí¼þ¹¥»÷IT¹¤×÷Õß

      Ñо¿ÈËÔ±·¢ÏÖ£¬Hunters InternationalÀÕË÷Èí¼þÍÅ»ïÕýÔÚʹÓÃÒ»ÖÖÃûΪSharpRhinoµÄÈ«ÐÂC#Ô¶³Ì·ÃÎÊľÂí£¨RAT£©£¬×¨ÃÅÕë¶ÔITÈËÔ±ÈëÇÖÆóÒµÍøÂç¡£´Ë¶ñÒâÈí¼þ°ïÖúHunters InternationalʵÏÖ³õʼ¸ÐȾ¡¢ÌáÉýÔÚÊܸÐȾϵͳÉϵÄȨÏÞ¡¢Ö´ÐÐPowerShellÃüÁ²¢×îÖÕ²¿ÊðÀÕË÷Èí¼þ¡£¸ù¾ÝÑо¿ÈËÔ±µÄ±¨¸æ£¬SharpRhinoͨ¹ýÒ»¸ö¼ÙðºÏ·¨ÍøÂ繤¾ßAngry IP ScannerÍøÕ¾µÄtyposquattingÕ¾µã´«²¥¡£Hunters International²¿Êðαװ³ÉºÏ·¨¿ªÔ´ÍøÂçɨÃ蹤¾ßµÄÍøÕ¾£¬±íÃ÷ÆäÄ¿±êÊÇITÈËÔ±£¬Ï£Íûͨ¹ýËûÃÇÈëÇÖ¾ßÓÐÌáÉýȨÏÞµÄÕË»§¡£

      5

      MagniberÀÕË÷Èí¼þ¹¥»÷Ó°ÏìÈ«Çò¼ÒÍ¥Óû§

      2024Äê8ÔÂ4ÈÕ£¬È«Çò¸÷µØµÄ¼ÒÍ¥Óû§ÕýÔâÊÜÒ»²¨´ó¹æÄ£µÄMagniberÀÕË÷Èí¼þ¹¥»÷£¬É豸±»¼ÓÃܺóÐèÖ§¸¶¸ß´ïÊýǧÃÀÔªµÄÊê½ð²ÅÄÜ»ñÈ¡½âÃÜÆ÷¡£×Ô2024Äê7ÔÂ20ÈÕÒÔÀ´£¬BleepingComputerÂÛ̳ÉÏѰÇó°ïÖúµÄMagniberÀÕË÷Èí¼þÊܺ¦Õß¼¤Ôö£¬ÀÕË÷Èí¼þʶ±ðÍøÕ¾ID-RansomwareÒ²ÊÕµ½Á˽ü720·ÝÏà¹ØÌá½»¡£¾¡¹ÜĿǰÉв»Çå³þÊܺ¦ÕßÊÇÈçºÎ¸ÐȾµÄ£¬µ«Ò»Ð©Êܺ¦Õß±íʾ£¬ËûÃǵÄÉ豸ÔÚÔËÐÐÈí¼þÆÆ½â»òÃÜÔ¿Éú³ÉÆ÷ºó±»¼ÓÃÜ£¬ÕâÒ²ÊÇÍþвÕß¹ýÈ¥³£Óõķ½·¨¡£Ò»µ©Æô¶¯£¬ÀÕË÷Èí¼þ»á¼ÓÃÜÉ豸ÉϵÄÎļþ£¬²¢ÔÚ¼ÓÃܵÄÎļþÃûºó¸½¼ÓËæ»úµÄ5-9×Ö·ûÀ©Õ¹Ãû£¬Èç.oaxysw»ò.oymtk¡£ÀÕË÷Èí¼þ»¹»á´´½¨ÃûΪREAD_ME.htmµÄÊê½ð֪ͨ£¬°üº¬ÓйØÎļþ·¢Éú×´¿öµÄÐÅÏ¢ºÍ·ÃÎÊÍþвÕßTorÊê½ðÍøÕ¾µÄΨһURL¡£MagniberµÄÊê½ðÒªÇóͨ³£´Ó1000ÃÀÔªÆð£¬Èç¹ûÔÚÈýÌìÄÚδ֧¸¶±ÈÌØ±Ò£¬Êê½ð½«Ôö¼ÓÖÁ5000ÃÀÔª¡£²»ÐÒµÄÊÇ£¬Ä¿Ç°Ã»ÓÐÃâ·Ñ½âÃܵ±Ç°°æ±¾Magniber¼ÓÃÜÎļþµÄ·½·¨¡£


      ²Î¿¼Á´½Ó£º

      https://www.bleepingcomputer.com/news/security/surge-in-magniber-ransomware-attacks-impact-home-users-worldwide/


      6

      ÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂKeytronicËðʧ³¬¹ý1700ÍòÃÀÔª

      µç×ÓÖÆÔì·þÎñ¹«Ë¾KeytronicÅû¶£¬×î½üµÄÒ»´ÎÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÆä¶îÍ⿪֧ºÍÊÕÈëËðʧ×ܼƳ¬¹ý1700ÍòÃÀÔª¡£¹«Ë¾ÔÚ2024²ÆÄêµÚËļ¾¶ÈµÄ³õ²½²ÆÎñ±¨¸æÖй«²¼ÁËÓë´Ë´ÎʼþÏà¹ØµÄ³É±¾¡£Keytronic±íʾ£º¡°ÓÉÓÚ´Ë´Îʼþ£¬¹«Ë¾ÔÚµÚËļ¾¶È²úÉúÁË´óÔ¼230ÍòÃÀÔªµÄ¶îÍ⿪֧£¬²¢ÇÒÔ¤¼ÆËðʧÁËÔ¼1500ÍòÃÀÔªµÄÊÕÈë¡£¡±´Ë´ÎÍøÂç¹¥»÷·¢ÉúÓÚ5ÔÂ6ÈÕ£¬µ¼ÖÂÃÀ¹úºÍÄ«Î÷¸çµÄ¶à¸öÕ¾µãÔËÓªÖжϡ£ÕâЩվµãµÄÔËÓªÒòʼþÔÝÍ£ÁËÁ½ÖÜ¡£¹«Ë¾ÔÚ6Ô³õ´Î±¨¸æÊ±£¬ÒÑΪÍâ²¿ÍøÂç»Æ½ð³Ç¹ÙÍø×¨¼ÒÖ§¸¶ÁËÔ¼60ÍòÃÀÔªµÄ·ÑÓ᣺ڿÍ×éÖ¯Black BastaÉù³Æ¶ÔÕâ´Î¹¥»÷¸ºÔ𣬲¢³ÆÇÔÈ¡Á˳¬¹ý500GBµÄÊý¾Ý£¬°üÀ¨²ÆÎñÎļþ¡¢¹¤³ÌÎļþ¡¢ÈËÁ¦×ÊÔ´ÐÅÏ¢¼°ÆäËûÀàÐ͵Ĺ«Ë¾Êý¾Ý¡£


      ²Î¿¼Á´½Ó£º

      https://www.sec.gov/Archives/edgar/data/719733/000071973324000044/q42024preliminaryexhibit991.htm


      7

      ×îÐÂÊý¾Ý±íÃ÷ÀÕË÷Èí¼þ¹¥»÷²»ÔÙ¹Ø×¢´óÆ·ÅÆ

      ¾ÝÑо¿ÈËÔ±±¨¸æ³Æ£¬4ÔÂÖÁ6Ô¼ä¼à¿Øµ½µÄËùÓÐÀÕË÷Èí¼þ¹¥»÷ÖУ¬10%À´×Ô¶ÀÁ¢²Ù×÷Ô±£¬ÕâÊÇÒ»¸ö¾Þ´óµÄ¼¤Ôö¡£ÕâЩºÚ¿ÍºÜ¿ÉÄÜÊÇAlphv£¨ÓÖÃûBlackCat£©»òLockBitµÄǰ¸½ÊôºÚ¿Í£¬»òÒò¡°Óж¾¡±ÀÕË÷Èí¼þÆ·ÅÆµÄÆØ¹â¡¢¸ÉÈźÍÀûÈóËðʧ·çÏÕÔö¼Ó¶ø¾ö¶¨¶ÀÁ¢Ðж¯¡£²¢·ÇËùÓб»½âÉ¢µÄÀÕË÷Èí¼þÍÅ»ïµÄǰ¸½ÊôºÚ¿Í¶¼Ñ¡Ôñ¶ÀÁ¢Ðж¯¡£½ñÄêÔçЩʱºò£¬Ò»ÃûÊܺ¦ÕßÏòDark AngelsÀÕË÷Èí¼þÍÅ»ïÖ§¸¶ÁËÆù½ñΪֹ×î¸ßµÄ¹«¿ªÀÕË÷½ð¶î¡ª¡ª7500ÍòÃÀÔª¡£Dark Angels×Ô2022Äê5ÔÂÆðÔËÓª£¬ÔËÐÐDunghillÊý¾ÝÐ¹Â©ÍøÕ¾£¬µ«¡°ÒýÆðµÄ¹Ø×¢·Ç³£ÉÙ¡±¡£ÀÕË÷Èí¼þ¹¥»÷µÄ²»¶Ï´´ÐÂÍ»ÏÔÁËÆäÓ¯ÀûÇý¶¯£¬Ò½Ôº¡¢Ñª¿â¡¢Ñ§Ð£ºÍ¹Ø¼ü»ù´¡ÉèÊ©µÄ·´¸´¹¥»÷¾ÍÊÇÖ¤Ã÷¡£½üÄêÀ´£¬Ëæ×ÅÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©×éÖ¯µÄÐËÆð£¬´´Ð²»¶Ï¡£ÕâЩ×éÖ¯½«¿ª·¢¼ÓÃÜËø¶¨¶ñÒâÈí¼þ¡¢ÔËÐÐÊý¾Ýй©»ù´¡ÉèÊ©ºÍ´¦Àí̸ÅеIJÙ×÷Ô±ÓëʹÓöñÒâÈí¼þ¹¥»÷Ä¿±êµÄ¸½ÊôºÚ¿ÍÅä¶Ô£¬Í¨³£¸½ÊôºÚ¿Í¿É»ñµÃÿ´ÎÀÕË÷½ð¶îµÄ70%»ò80%¡£

      ²Î¿¼Á´½Ó£º

      https://www.coveware.com/blog/2024/7/29/ransomware-actors-pivot-away-from-major-brands-in-q2-2024


      Ãâ·ÑÊÔÓÃ
      ·þÎñÈÈÏß

      ÂíÉÏ×Éѯ

      400-811-3777

      »Øµ½¶¥²¿
      ¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿