ÿÖܻƽð³Ç¹ÙÍøËÙµÝ??? | ¶íÂÞ˹·¨ÔºÊͷŶàÃûREvilÀÕË÷Èí¼þÍÅ»ï³ÉÔ±Òý·¢ÕùÒé
·¢²¼Ê±¼ä£º2025-06-27
ÔĶÁ´ÎÊý£º 3438 ´Î
¶íÂÞ˹·¨ÔºÊͷŶàÃûREvilÀÕË÷Èí¼þÍÅ»ï³ÉÔ±Òý·¢ÕùÒé
½üÈÕ£¬¶íÂÞ˹·¨ÔºÅж¨ËÄÃûREvilÀÕË÷Èí¼þÍÅ»ï³ÉÔ±ÓÐ×µ«ÒòÆäÔÚ¿´ÊØËùÒÑ·þÐÌÁ½Äê¶à£¬±»ÒÔ¡°ÐÌÆÚÕÛµÖ¡±ÎªÓɵ±Í¥ÊÍ·Å¡£±»ÊÍ·ÅÕß°üÀ¨Andrey Bessonov¡¢Mikhail Golovachuk¡¢Roman MuromskyºÍDmitry Korotayev£¬ËûÃǾù³ÐÈϲÎÓë½ðÈÚÆÛÕ©Óë¼ÆËã»ú·¸×Ö÷ҪĿ±êΪÃÀ¹ú»ú¹¹ºÍÆóÒµ¡£¾¡¹Ü·¨ÔºÃüÁîûÊÕÆäÃûϺÀ³µºÍÊýÊ®ÍòÃÀÔªÏֽ𣬸ÃÅоöÈÔÒý·¢ÖÊÒÉ£¬ÓÈÆäÊÇÔÚREvilÔø²ß¶¯°üÀ¨2021ÄêKaseya¹©Ó¦Á´¹¥»÷ÔÚÄڵĶàÆðÖØ´óÀÕË÷ʼþÖ®ºó¡£ÔçǰÔÚ2024Äê10Ô£¬ÁíÍâËÄÃûREvil³ÉÔ±Òѱ»Åд¦ËÄÄê°ëÖÁÁùÄê²»µÈµÄÐÌÆÚ¡£´Ë´ÎÅоö±³¾°ÊǶíÃÀÔÚ2022Äê³õ¾ÍREvil½øÐеĶÌÔÝÖ´·¨ºÏ×÷£¬µ±Ê±¶íÂÞ˹ӦÃÀ·½Ç鱨ҪÇó¾Ð²¶ÁË14ÃûÏÓÒÉÈË¡£¸Ã°¸Ôø±»ÊÓΪ´ò»÷¿ç¹úÍøÂç·¸×ïµÄµä·¶£¬µ«Ëæ×ŶíÎÚÕ½Õù±¬·¢£¬Ë«±ßºÏ×÷ѸËÙÖÐÖ¹£¬¶íÂÞ˹·½Ãæ½ö¾Í·Ç·¨ÒøÐп¨Êý¾ÝʹÓýøÐÐÆðËߣ¬¶øÎ´ÉæÍøÂç¹¥»÷±¾Éí¡£
https://cyberscoop.com/revil-ransomware-sentence-russia-time-served/
McLarenÒ½ÁƼ¯ÍÅÔâÀÕË÷Èí¼þ¹¥»÷
µ¼Ö³¬74ÍòÈËÐÅϢй¶
ÃÀ¹úÃÜЪ¸ùÖݵÄMcLarenÒ½ÁƼ¯ÍŽüÈÕÅû¶£¬¸Ã»ú¹¹ÓÚ2024ÄêÏÄÌìÔâÓö¹ú¼ÊÀÕË÷Èí¼þ×éÖ¯¡°Inc. Ransom¡±¹¥»÷£¬µ¼ÖÂ743000ÓàÈ˸öÈËÐÅÏ¢±»ÇÔÈ¡£¬ÕâÊÇMcLarenÁ½ÄêÄÚµÚ¶þ´ÎÔâÓöÖØ´óÀÕË÷¹¥»÷¡£¹¥»÷·¢ÉúÓÚ2024Äê7ÔÂ17ÈÕÖÁ8ÔÂ3ÈÕÖ®¼ä£¬ÊÜÓ°ÏìµÄ²»½ö°üÀ¨McLarenµÄҽԺϵͳ£¬Ò²Éæ¼°ÆäÆìϵÄKarmanos°©Ö¢ÖÐÐÄ¡£¹¥»÷Õß²»½öÈëÇÖ²¢¼ÓÃÜÁËITϵͳ£¬»¹Ðû³Æ³É¹¦ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£´Ë´Îʼþµ¼ÖÂMcLaren±»ÆÈÍ£Óõç×Ó½¡¿µ¼Ç¼ϵͳÈýÖÜ£¬ÆÚ¼äתΪֽÖʼǼºÍÊÖ¶¯²Ù×÷£¬»¹ÁÙʱ½«²¿·Ö¾È»¤³µ×ªÒÆÖÁÆäËûÒ½Ôº¡£µ÷²é·¢ÏÖ£¬Ð¹Â¶Êý¾Ý¿ÉÄܰüº¬ÐÕÃû¡¢Éç»á»Æ½ð³Ç¹ÙÍøºÅ¡¢¼ÝÕÕºÅÂë¡¢½¡¿µÐÅÏ¢¼°±£ÏÕ×ÊÁÏ¡£ÖµµÃ×¢ÒâµÄÊÇ£¬McLarenÔÚ2023Äê10Ô¸Õͨ±¨ÁíÒ»ÆðÓÉAlphV£¨ÓÖÃûBlackCat£©ºÚ¿ÍÍÅ»ïʵʩµÄ¹¥»÷ʼþ£¬Ó°Ïì210ÍòÈË¡£AlphVµ±Ê±Éù³ÆÈÔÔÚMcLarenÍøÂçÖб£ÁôºóÃÅ£¬±¾´ÎÔÙ¶ÈÔâ¹¥»÷£¬Òý·¢Íâ½ç¶ÔÆäÄÚ²¿ÍøÂç»Æ½ð³Ç¹ÙÍø·À»¤ÊÇ·ñµ½Î»µÄÖÊÒÉ¡£
https://www.govinfosecurity.com/mclaren-health-says-743000-affected-by-2024-ransomware-hack-a-28785
AnubisÀÕË÷Èí¼þ½«°ÍÀèµÏÊ¿ÄáÀÖÔ°ÁÐΪÐÂÊܺ¦Õß
ÀÕË÷Èí¼þÍÅ»ïAnubis½üÈÕÔÚÆä°µÍøÐ¹Â¶ÍøÕ¾ÉÏÐû³Æ£¬³É¹¦ÈëÇÖ°ÍÀèµÏÊ¿Äáϵͳ£¬ÇÔÈ¡ÁËÔ¼64GBµÄÃô¸ÐÊý¾Ý¡£´Ë´Îʼþ±»¸Ã×éÖ¯³ÆÎª¡°µÏÊ¿ÄáÀÖÔ°Ê·ÉÏ×î´ó¹æÄ£µÄÊý¾Ýй¶¡±£¬Ä¿Ç°ÉÐδ»ñµÃ¹Ù·½Ö¤Êµ¡£Ð¹Â¶ÄÚÈݾݳưüÀ¨Éæ¼°¶à¸öÓÎÀÖÉèÊ©½¨ÉèÓë·ÐÂÏîÄ¿µÄ39000¸ö¹¤³ÌÎļþ£¬Éæ¼°ÏîÄ¿°üÀ¨±ùÑ©ÆæÔµ¡¢¼ÓÀձȺ£µÁ¡¢À×öªÉ½¡¢°Í˹¹âÄê¡¢»ÃÏëÊÀ½çµÈ¡£¾ÝAnubis±íʾ£¬´Ë´ÎÊý¾Ý²¢·ÇÖ±½ÓÀ´×ÔµÏÊ¿Äᣬ¶øÊÇͨ¹ý¹¥»÷ÆäºÏ×÷·½ÏµÍ³¶ø»ñÈ¡¡£¸ÃÍŻﻹÒÑÔÚ°µÍøÉϹ«²¼Á˲¿·ÖÎļþ¡¢Í¼Ö½ºÍÊÓÆµ×ÊÁÏ£¬ÒÔÖ¤Ã÷ÆäÕÆÎÕÁËÏà¹ØÊý¾Ý¡£Anubis×Ô2024Äêµ×¿ªÊ¼»îÔ¾£¬ÊÇ´ÓÔçÆÚ²âÊÔ°æ±¾¡°Sphinx¡±ÑÝ»¯¶øÀ´µÄÀÕË÷¼´·þÎñ£¨RaaS£©Æ½Ì¨¡£ÆäÓ¯Àûģʽ°üÀ¨¼ÓÃÜÊê½ð·Ö³É¡¢Êý¾Ýй¶·Ö³ÉºÍ·ÃÎÊȨÏÞµ¹ÂôµÈ£¬¾ß±¸ÄÚÖÃÊý¾ÝÏú»Ù£¨Wiper£©¹¦ÄÜ¡£Ä¿Ç°Éв»Çå³þ´Ë´ÎʼþÊÇ·ñÉæ¼°Óοͻò¿Í»§¸öÈËÐÅÏ¢£¬ÒàδÓÐÀÕË÷ÒªÇ󹫿ª¡£
https://hackread.com/anubis-ransomware-lists-disneyland-paris-new-victim/
ÎÚ¿ËÀ¼½«ÒÉËÆRyukÀÕË÷Èí¼þÍÅ»ï³ÉÔ±µÄÄÐ×ÓÒý¶ÉÖÁÃÀ¹ú
ÎÚ¿ËÀ¼µ±¾Ö½üÈÕÐû²¼£¬Òѽ«Ò»Ãû33ËêµÄÍâ¹ú¼®ÄÐ×ÓÒý¶ÉÖÁÃÀ¹ú£¬ÉæÏÓ×÷ΪRyukÀÕË÷Èí¼þÍÅ»ïµÄ¡°³õʼÈëÇÖר¼Ò¡±£¬ÐÖúÆäÔÚÈ«Çò·¶Î§ÄÚ·¢¶¯³¬¹ý2400ÆðÀÕË÷¹¥»÷£¬Éæ°¸½ð¶î³¬¹ý1ÒÚÃÀÔª¡£¸ÃÏÓÒÉÈËÓÚ½ñÄê4ÔÂÔÚ»ù¸¨±»²¶£¬µ±Ê±Õý¾ÓסÓÚµ±µØ£¬ÒòFBI½«ÆäÁÐÈë¹ú¼Êͨ¼©Ãûµ¥¶øÂäÍø¡£¾ÝÎÚ¿ËÀ¼¼ì·½³Æ£¬¸ÃÏÓÒÉÈËͨ¹ý·¢ÏÖÆóÒµÍøÂç©¶´²¢»ñÈ¡³õʼ·ÃÎÊȨÏÞ£¬ÎªºóÐøÀÕË÷Èí¼þµÄ²¿ÊðÆÌƽµÀ·¡£¾¡¹Ü¹Ù·½Î´¹«¿ªÆäÉí·Ý£¬µ«Ö¸³öÆä²¢·ÇÎÚ¿ËÀ¼¹ú¼®¡£Ä¿Ç°£¬ÃÀ¹ú˾·¨²¿ÉÐδ¶Ô´Ë»ØÓ¦¡£´Ë´ÎÒý¶ÉÊǽüÄêÀ´Õë¶ÔÎÚ¿ËÀ¼¾³ÄÚÀÕË÷Èí¼þÍÅ»ï³ÖÐø´ò»÷Ðж¯µÄÒ»²¿·Ö¡£2023ÄêÍíЩʱºò£¬ÎÚ¾¯·½ÔøÅäºÏÃÀ¡¢·¨¡¢µÂ¡¢Å²ÍþºÍºÉÀ¼Ö´·¨²¿ÃÅ£¬´þ²¶¸ÃÍÅ»ïµÄ¡°Ê×ÄÔ¡±¼°Æä4Ãû»îÔ¾³ÉÔ±£¬²¢²é»ñ¼ÛÖµ³¬¹ý50ÍòÃÀÔªµÄ¼ÓÃÜ×ʲú¡¢¾ÅÁ¾ºÀ³µºÍ½ü30ӢĶÍÁµØ¡£Å·ÃËÐ̾¯×éÖ¯EuropolÖ¸³ö£¬¸ÃÍÅ»ïʹÓõÄÀÕË÷Èí¼þ²»Ö¹Ryuk£¬»¹°üÀ¨Dharma¡¢Hive¡¢LockerGogaºÍMegaCortexµÈ¶à¸ö±äÖÖ£¬²¢³£½èÖúTrickBot¡¢Cobalt StrikeµÈ¹¤¾ß½øÐкáÏòÉøÍ¸ºÍ³Ö¾Ã¿ØÖÆ¡£
https://www.govinfosecurity.com/ukraine-extradites-suspected-ransomware-group-member-to-us-a-28754