ÿÖܻƽð³Ç¹ÙÍøËÙµÝ???£üÐÂÐÍÔ¶³Ì¿ØÖÆÄ¾ÂíNonEuclid¸ÐȾWindowsϵͳ
·¢²¼Ê±¼ä£º2025-01-17
ÔĶÁ´ÎÊý£º 1675 ´Î
±¾ÖÜÈȵãʼþÍþвÇ鱨
ÐÂÐÍÔ¶³Ì¿ØÖÆÄ¾ÂíNonEuclid¸ÐȾWindowsϵͳÑо¿ÈËÔ±½üÈÕ½ÒʾÁËÒ»ÖÖÃûΪNonEuclidµÄÔ¶³Ì·ÃÎÊľÂí£¨RAT£©£¬ÆäÒԸ߼¶Òþ±ÎÓë·´¼ì²â¼¼ÊõÖø³Æ¡£¸Ã¶ñÒâÈí¼þÓÉC#¿ª·¢£¬¾ß±¸Èƹýɱ¶¾Èí¼þ¡¢·À»¤ÌÓÒÝ¡¢ÌØÈ¨Éý¼¶ÒÔ¼°Õë¶Ô¹Ø¼üÎļþµÄÀÕË÷¼ÓÃܹ¦ÄÜ¡£NonEuclid×Ô2024Äê11ÔÂÆðÔÚµØÏÂÂÛ̳¹ã·ºÍƹ㣬ÉõÖÁÔÚDiscordºÍYouTubeÉϳöÏÖÏà¹Ø½Ì³Ì¡£¸ÃľÂíͨ¹ýWindows APIµ÷ÓÃ¼à¿Ø·ÖÎö¹¤¾ß£¬ÀûÓÃÐéÄâ»·¾³¼ì²âºÍWindows AMSIÈÆ¹ýµÈ¼¼Êõ£¬±ÜÃâ±»¼ì²â¡£´ËÍ⣬Ëü»¹Í¨¹ýÐÞ¸Ä×¢²á±í¡¢´´½¨¼Æ»®ÈÎÎñµÈ·½Ê½ÊµÏֳ־û¯£¬²¢ÄÜͨ¹ýÈÆ¹ýÓû§ÕË»§¿ØÖÆ£¨UAC£©ÌáÉýȨÏÞ¡£ÌرðÖµµÃ¹Ø×¢µÄÊÇ£¬¸Ã¶ñÒâÈí¼þÄܹ»¼ÓÃÜÖ¸¶¨ÀàÐÍÎļþ²¢Ìí¼Ó¡°.NonEuclid¡±ºó׺£¬Ê¹Æä¾ß±¸ÀÕË÷Èí¼þÌØÐÔ¡£
https://www.cyfirma.com/research/noneuclid-rat/ÀÕË÷Èí¼þFunkSecʹÓÃË«ÖØÀÕË÷²ßÂÔ¹¥»÷85ÃûÊܺ¦Õß2024Äêµ×£¬ÐÂÐËÀÕË÷Èí¼þ×éÖ¯FunkSec¸¡³öË®Ãæ£¬¸ÃÍÅ»ï½èÖúÈ˹¤ÖÇÄÜ£¨AI£©¹¤¾ß£¬Ê¹ÓÃË«ÖØÀÕË÷²ßÂÔ¼ÓÃܲ¢ÇÔÈ¡Êý¾Ý£¬ÒÔµÍÖÁ1ÍòÃÀÔªµÄÊê½ðÍþвÊܺ¦Õߣ¬²¢ÒÔÕÛ¿Û¼Û³öÊÛÇÔÈ¡Êý¾Ý¡£FunkSecÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏÕûºÏÀÕË÷ÒµÎñ£¬»¹ÒýÈëDDoS¹¥»÷¹¤¾ßºÍÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Ä£Ê½£¬½øÒ»²½À©Õ¹ÆäÓ°ÏìÁ¦¡£Êܺ¦Õß·Ö²¼ÓÚÃÀ¹ú¡¢Ó¡¶È¡¢Òâ´óÀûµÈÆß¹ú£¬²¿·Ö³ÉÔ±ÒÉÓëºÚ¿Í»î¶¯Ïà¹ØÁª£¬ÕÃÏÔºÚ¿ÍÖ÷ÒåÓëÍøÂç·¸×ïµÄ½çÏÞÓú¼ÓÄ£ºý¡£FunkSec¹¤¾ß¿ª·¢ÒÉΪAI¸¨Öú£¬¾¡¹Ü¼¼ÊõÄÜÁ¦ÓÐÏÞ£¬µ«¿ìËÙµü´úʹÆä¾ß±¸Íþв¡£Æä×îÐÂÀÕË÷Èí¼þ°æ±¾Ê¹ÓÃRust±àд£¬¾ß±¸½ûÓûƽð³Ç¹ÙÍø¿ØÖÆ¡¢É¾³ý±¸·ÝµÈ¹¦ÄÜ¡£
²Î¿¼Á´½Ó£º
https://research.checkpoint.com/2025/funksec-alleged-top-ransomware-group-powered-by-ai/CodefingerÀÕË÷Èí¼þʹÓÃSSE-C¼ÓÃÜS3´æ´¢Í°Ò»¸öÃûΪCodefingerµÄÀÕË÷ÍÅ»ïͨ¹ýAWSµÄ·þÎñÆ÷¶Ë¼ÓÃÜÑ¡ÏSSE-C£©¼ÓÃÜÄ¿±ê×éÖ¯µÄAWS S3Êý¾Ý£¬ÒªÇóÊܺ¦ÕßÖ§¸¶Êê½ðÒÔ»ñÈ¡¼ÓÃÜÃÜÔ¿¡£¹¥»÷ÕßÀûÓñ»Ð¹Â¶»òµÁÈ¡µÄAWSÃÜÔ¿£¬Ê¹ÓÃAES-256¼ÓÃÜËã·¨£¬Í¨¹ýx-amz-server-side-encryption-customer-algorithm±êÍ·Ö´ÐмÓÃÜ¡£ÓÉÓÚAWS½ö¼Ç¼HMACÖµ¶ø²»´æ´¢ÃÜÔ¿£¬Êܺ¦ÕßÎÞ·¨×ÔÐнâÃÜÊý¾Ý¡£¹¥»÷ÕßδÇÔÈ¡Êý¾Ý£¬µ«»á±ê¼Ç¼ÓÃÜÎļþÔÚÆßÌìÄÚɾ³ý£¬½øÒ»²½Ê©Ñ¹Ä¿±ê×éÖ¯¡£
https://www.halcyon.ai/blog/abusing-aws-native-services-ransomware-encrypting-s3-buckets-with-sse-c2024ÄêÕë¶ÔVMware ESXi·þÎñÆ÷µÄÀÕË÷Èí¼þ¹¥»÷¼¤Ôö2024Ä꣬Õë¶ÔVMware ESXi·þÎñÆ÷µÄÀÕË÷¹¥»÷ÏÔÖøÔö¼Ó£¬Æ½¾ùÊê½ð¸ß´ï500ÍòÃÀÔª¡£¶àÊý¹¥»÷ʹÓøÄÁ¼µÄBabukÀÕË÷Èí¼þ±äÖÖ£¬ÕâЩ±äÖÖרΪ¹æ±Ü»Æ½ð³Ç¹ÙÍø¹¤¾ß¼ì²â¶øÉè¼Æ¡£¹¥»÷Õßͨ¹ý¼ÓÃÜESXi¹Ø¼üÎļþ£¨ÈçVMDK¡¢VMEM¡¢VSWP¡¢VMSNÎļþ£©Ê¹ÐéÄâ»ú²»¿ÉÓã¬Í¬Ê±Í¨¹ý¶Ô³Æ¼ÓÃÜÓë·Ç¶Ô³Æ¼ÓÃܽáºÏµÄ·½·¨¼ÓËÙÊý¾Ý¼ÓÃܲ¢È·±£ÃÜÔ¿»Æ½ð³Ç¹ÙÍø¡£ÀÕË÷Èí¼þÍŻﻹͨ¹ý³öÊÛ³õʼ·ÃÎÊȨÏÞ»ñÀû£¬Ê¹µÃ¹¥»÷Á´¸ü¼Ó¸´ÔÓ¡£ÓÉÓÚESXi¼Ü¹¹ÖеÄvCenter·þÎñÆ÷¼¯ÖйÜÀí¶à¸öESXiÖ÷»ú£¬Æä"vpxuser"ÕË»§³ÉΪ¹¥»÷Ä¿±ê£¬¹¥»÷ÕßÒ»µ©»ñÈ¡ÃÜÔ¿½âÃÜȨÏÞ£¬±ã¿É¶ÔÐéÄâ»·¾³ÊµÊ©È«Ãæ¿ØÖÆ¡£
https://thehackernews.com/2025/01/ransomware-on-esxi-mechanization-of.html
OneBloodÈ·ÈÏ7ÔÂÀÕË÷Èí¼þ¹¥»÷µ¼Ö¸öÈËÊý¾Ýй¶
ÃÀ¹úѪҺ¾èÔù·ÇÓªÀû×éÖ¯OneBloodÈ·ÈÏ£¬È¥Äê7ÔµÄÀÕË÷Èí¼þ¹¥»÷µ¼Ö¾èÔùÕßÐÕÃûºÍÉç»á»Æ½ð³Ç¹ÙÍøºÅÂ루SSN£©±»ÇÔÈ¡¡£¹¥»÷·¢ÉúÓÚ2024Äê7ÔÂ14ÈÕÖÁ29ÈÕ£¬ÍþвÕßÔÚÍøÂçÖÐÍ£Áô15Ì죬ÆÚ¼ä¸´ÖÆÁËÏà¹ØÎļþ¡£´Ë´ÎʼþÓ°ÏìOneBloodΪȫÃÀ250¶à¼ÒÒ½Ôº¹©Ó¦ÑªÒºµÄÄÜÁ¦£¬Ôì³ÉѪҺÊÕ¼¯¡¢¼ì²âºÍ·Ö·¢ÑÓÎ󣬲¢Æô¶¯¡°¹Ø¼üѪҺ¶Ìȱ¡±Ó¦¶Ô´ëÊ©¡£¾¡¹ÜÆäËûÃô¸ÐÐÅϢδ±»Ð¹Â¶£¬µ«±»±©Â¶µÄSSN¿ÉÄܳ¤ÆÚÃæÁÙÉí·ÝµÁÓúͲÆÎñÆÛÕ©·çÏÕ¡£ÊÜÓ°ÏìÕßÒÑ»ñ֪ͨ£¬¿ÉÃâ·Ñ»ñȡһÄêÐÅÓÃ¼à¿Ø·þÎñ£¬²¢½¨Òé²ÉÈ¡ÐÅÓö³½áºÍÆÛÕ©¾¯±¨µÈ´ëÊ©ÒÔ½µµÍDZÔÚ·çÏÕ¡£
https://ago.vermont.gov/sites/ago/files/documents/2025-01-09%20OneBlood%20Data%20Breach%20Notice%20to%20Consumers.pdf