·¨¹úµçÐŹ«Ë¾La Poste MobileÔâµ½LockbitµÄÀÕË÷¹¥»÷

Ðû²¼Ê±¼ä 2022-07-12

1¡¢·¨¹úµçÐŹ«Ë¾La Poste MobileÔâµ½LockbitµÄÀÕË÷¹¥»÷


ýÌå7ÔÂ10ÈÕ±¨µÀ³Æ £¬·¨¹úµçÐÅÔËÓªÉÌLa Poste MobileÔâµ½ÁËLockbitÍÅ»ïµÄÀÕË÷¹¥»÷¡£¸Ã¹«Ë¾ÔÚÆäÍøÕ¾ÉÏÐû²¼µÄÒ»·ÝÉùÃ÷ÖÐдµÀ £¬¹¥»÷ʼÓÚ7ÔÂ4ÈÕ £¬Ó°ÏìÁËÆäÐÐÕþºÍ¹ÜÀí·þÎñ¡£ËûÃÇÔÚ»ñϤ´ËʺóÁ¢¼´½ÓÄÉÐëÒªµÄ´ëÊ© £¬¹Ø±ÕÁËÏà¹Ø¼ÆËã»úϵͳ £¬°üÂÞÍøÕ¾ºÍ¿Í»§Çø¡£´ËÍâ £¬Ô±¹¤¼ÆËã»úÖеIJ¿ÃÅÎļþй¶ £¬¿ÉÄÜÉæ¼°¸öÈËÊý¾Ý¡£ÉÏÖÜÎå £¬LockBitÍÅ»ïÒѽ«La Poste MobileÌí¼Óµ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¡£


https://securityaffairs.co/wordpress/133080/cyber-crime/la-poste-mobile-ransomware.html


2¡¢ALPHVÍÅ»ïÉù³ÆÒÑÈëÇÖÈÕ±¾µÄÓÎÏ·¿¯ÐÐÉÌÍò´úÄÏÃι¬


¾ÝVGCÔÚ7ÔÂ11Èյı¨µÀ £¬ALPHVÍÅ»ïÉù³ÆÒѾ­ÀÕË÷¹¥»÷ÁËÍò´úÄÏÃ鬣¨Bandai Namco£©¡£Íò´úÄÏÃι¬ÊÇÈÕ±¾ÖøÃûµÄÓÎÏ·¿¯ÐÐÉÌ £¬ÒÔ¡¶³Ô¶¹ÈË¡·¡¢¡¶ÌúÈ­¡·ºÍ¡¶ºÚ°µÖ®»ê¡·µÈÓÎÏ·¶øÎÅÃû¡£¸ÃÏûÏ¢ÓÉvx-undergroundÓÚ±¾ÖÜÒ»Ðû²¼ÔÚTwitterÉÏ £¬Ä¿Ç° £¬VGCÒÑÁªÏµÍò´úÄÏÃι¬¶Ô´ËÊ·¢±íÆÀÂÛ¡£ÓÎÏ·ÊÂÇéÊÒCD Projekt RedÔÚÈ¥ÄêÒ²Ôâµ½ÁËÀÕË÷¹¥»÷ £¬µ¼ÖÂÈü²©Åó¿Ë2077ºÍÎ×ʦ3µÄÔ´´úÂë £¬ÒÔ¼°Ô±¹¤µÄÏêϸÐÅϢй¶¡£


https://www.videogameschronicle.com/news/elden-ring-publisher-bandai-namco-reportedly-targeted-in-a-ransomware-attack/


3¡¢EmsisoftÐû²¼AstraLockerºÍYashmaµÄÃâ·Ñ½âÃÜÆ÷


¾ÝýÌå7ÔÂ8ÈÕ±¨µÀ £¬ÐÂÎ÷À¼Äþ¾²¹«Ë¾EmsisoftÐû²¼ÁËÀÕË÷Èí¼þAstraLockerºÍYashmaµÄÃâ·Ñ½âÃܹ¤¾ß¡£Emsisoft³Æ £¬AstraLocker½âÃÜÆ÷ÊÊÓÃÓÚʹÓÃ.Astra»ò.babykÀ©Õ¹Ãû²¢»ùÓÚBabukµÄ½âÃÜÆ÷ £¬ËûÃÇ×ܹ²Ðû²¼ÁË8¸öÃÜÔ¿£»Yashma½âÃÜÆ÷ÊÊÓÃÓÚʹÓÃ.AstraLocker»òËæ»ú.[a-z0-9]{4}À©Õ¹Ãû²¢»ùÓÚChaosµÄ½âÃÜÆ÷ £¬ËûÃÇ×ܹ²Ðû²¼ÁË3¸öÃÜÔ¿¡£Emsisoft»¹½¨Òéͨ¹ýWindowsÔ¶³Ì×ÀÃæ±»ÈëÇÖµÄϵͳ¸ü¸ÄËùÓоßÓÐȨԶ³ÌµÇ¼ȨÏÞµÄÓû§µÄƾ¾Ý £¬²¢ÕÒ³ö¹¥»÷Õß¿ÉÄÜÌí¼ÓµÄÆäËûµ±µØÕÊ»§¡£


https://www.bleepingcomputer.com/news/security/free-decryptor-released-for-astralocker-yashma-ransomware-victims/


4¡¢Ñо¿ÈËÔ±·¢ÏÖÐÂÀÕË÷Èí¼þ0megaÕë¶ÔÈ«Çò·¶Î§ÄÚµÄ×éÖ¯


ýÌå7ÔÂ8ÈÕ³Æ £¬ÃûΪ0megaµÄÐÂÀÕË÷ÍÅ»ïÕë¶ÔÈ«Çò·¶Î§ÄÚµÄ×éÖ¯½øÐÐË«ÖØÀÕË÷¹¥»÷ £¬²¢ÀÕË÷Êý°ÙÍòÃÀÔªµÄÊê½ð¡£0mega×Ô2022Äê5Ô¿ªÊ¼»îÔ¾ £¬Ñо¿ÈËÔ±ÉÐδÕÒµ½ÆäÀÕË÷Èí¼þÑù±¾ £¬Òò´ËûÓÐÌ«¶à¹ØÓÚÎļþÈçºÎ±»¼ÓÃܵÄÏêϸÐÅÏ¢¡£¸ÃÍÅ»ïÔËÓª×ÅÒ»¸öÊý¾ÝÐ¹Â¶ÍøÕ¾ £¬Ä¿Ç°ÍйÜ×Å152 GBÊý¾Ý £¬¾Ý³ÆÊÇ5ÔµĹ¥»÷»î¶¯ÖдÓÒ»¼Òµç×ÓάÐÞ¹«Ë¾ÇÔÈ¡µÄ¡£´ËÍâ £¬ÉÏÖÜÓÐÒ»¸ö±»¹¥»÷Ä¿±êÒѱ»´ÓÖÐÒÆ³ý £¬Õâ±íÃ÷¸Ã¹«Ë¾¿ÉÄÜÒѾ­Ö§¸¶ÁËÊê½ð¡£


https://www.bleepingcomputer.com/news/security/new-0mega-ransomware-targets-businesses-in-double-extortion-attacks/


5¡¢FortinetÐû²¼Äþ¾²¸üР£¬ÐÞ¸´¶à¸ö²úÎïÖеÄ©¶´


ýÌå7ÔÂ9ÈÕ±¨µÀ³Æ £¬FortinetÐÞ¸´ÁËÆä¶à¿î²úÎïÖеÄ©¶´¡£ÊÜÓ°ÏìµÄ²úÎï°üÂÞFortiADC¡¢FortiAnalyzer¡¢FortiManager¡¢FortiOSºÍFortiProxyµÈ¡£´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖØµÄÊÇFortiNACÖпÕÃÜÂëȱÏÝ£¨CVE-2022-26117£© £¬¿ÉÓÃÀ´Í¨¹ýCLI·ÃÎÊMySQLÊý¾Ý¿â£»»ùÓÚ¶ÑÕ»µÄ»º³åÇøÒç³ö©¶´£¨CVE-2021-43072£© £¬¿Éͨ¹ýÌØÖÆµÄCLIÖ´ÐÐÃüÁ·¾¶±éÀú©¶´£¨CVE-2022-30302£© £¬¿Éͨ¹ýÌØÖÆµÄWebÇëÇó´Óµ×²ãÎļþϵͳÖмìË÷ºÍɾ³ýÈÎÒâÎļþ£»ÒÔ¼°Ä¿Â¼±éÀú©¶´£¨CVE-2021-41031£© £¬¿É½«È¨ÏÞÌáÉýµ½SYSTEM¡£


https://securityaffairs.co/wordpress/133059/security/fortinet-multiple-issues-several-products.html


6¡¢CheckmarxÅû¶CuteBoiÀûÓÃNPM°üµÄ´ó¹æÄ£ÍÚ¿ó»î¶¯


7ÔÂ6ÈÕ £¬CheckmarxÅû¶ÁËÕë¶ÔNPM JavaScript°ü´æ´¢¿âµÄÐÂÒ»ÂֵĴó¹æÄ£ÍÚ¿ó»î¶¯¡£¸Ã»î¶¯¹éÒòÓÚ¹¥»÷ÍÅ»ïCuteBoi £¬Éæ¼°1283¸önpm°ü £¬ÕâЩ°ü¿ÉÒÔ×Ô¶¯´Ó1000¶à¸ö²îÒìµÄÓû§ÕÊ»§ÖÐÐû²¼¡£ËùÓÐÕâЩ°ü¶¼¾ßÓм¸ºõÏàͬµÄeazyminer°üµÄ´úÂ븱±¾ £¬eazyminerÊÇXMRigµÄJS  wrapper £¬Ö¼ÔÚÀûÓüÆËã»úÉÏδʹÓõÄ×ÊÔ´ £¬Èçci/cdºÍweb·þÎñÆ÷¡£Ñо¿ÈËÔ±³Æ £¬CuteBoiÊǽñÄêµÚ¶þ¸ö×Ô¶¯»¯¶ÔNPMÌᳫ´ó¹æÄ£¹¥»÷µÄÍÅ»ï £¬²¢Ô¤¼ÆÎ´À´½«¿´µ½¸ü¶à´ËÀ๥»÷¡£


https://checkmarx.com/blog/cuteboi-detected-preparing-a-large-scale-crypto-mining-campaign-on-npm-users/