Pendragon¾Ü¾øLockBitÍÅ»ï6000ÍòÃÀÔªµÄÊê½ðÒªÇó
Ðû²¼Ê±¼ä 2022-10-26
ýÌå10ÔÂ24Èճƣ¬Ó¢¹úÆû³µ¾ÏúÉÌPendragon GroupÔâµ½LockBitµÄÀÕË÷¹¥»÷¡£¸Ã¹«Ë¾ÌåÏÖ£¬¹¥»÷·¢ÉúÔÚԼĪһ¸öÔÂǰ£¬Î´Ó°ÏìÆäÕý³£ÔËÓª£¬ËûÃÇÒ»Ö±ÔÚÓëºÚ¿ÍÁªÏµ£¬²¢ÊÕµ½Á˱»µÁÎļþ×÷Ϊ¹¥»÷µÄÖ¤¾Ý£¬µ«Ã»ÓнøÐÐ̸ÅС£¾ÝÓ¢¹úýÌ峯£¬LockBitÒªÇó6000ÍòÃÀÔªÊê½ð£¬¶øPendragon·¢ÑÔÈËÌåÏÖËûÃǼá³Ö²»ÏòºÚ¿Í¸¶¿îµÄ¾ö¶¨¡£Pendragon»¹³ÎÇåµÀ£¬ÆäITÍŶÓÔÚÔâµ½¹¥»÷ºóÁ¢¼´×ö³öÁË·´Ó³£¬ÊÓ²ìÏÔʾºÚ¿Í½öÇÔÈ¡ÁË5%µÄÊý¾Ý¿â¡£
https://www.bleepingcomputer.com/news/security/pendragon-car-dealer-refuses-60-million-lockbit-ransomware-demand/
2¡¢CiscoÌáÐÑAnyConnectÖеÄÁ½¸ö©¶´Õý±»¹ã·ºÀûÓÃ
CiscoÔÚ10ÔÂ25ÈÕÌáÐѿͻ§£¬ÊÊÓÃÓÚWindowsµÄCisco AnyConnectÄþ¾²Òƶ¯¿Í»§¶ËÖеÄÁ½¸ö©¶´Õý±»¹ã·ºÀûÓá£ÕâЩ©¶´£¨CVE-2020-3433ºÍCVE-2020-3153£©¿É±»µ±µØ¹¥»÷ÕßÓÃÀ´Ö´ÐÐDLL½Ù³Ö¹¥»÷²¢½«Îļþ¸´ÖƵ½¾ßÓÐϵͳ¼¶È¨ÏÞµÄϵͳĿ¼¡£ÀÖ³ÉÀûÓú󣬹¥»÷Õß¿ÉÒÔÔÚ¾ßÓÐϵͳȨÏÞµÄÄ¿±êÉ豸ÉÏÖ´ÐÐÈÎÒâ´úÂë¡£¸Ã¹«Ë¾³Æ£¬ÔÚ2022Äê10Ô£¬Æä·¢ÏÖÓÐÈËÊÔͼÀûÓôË©¶´£¬²¢Ç¿ÁÒ½¨Òé¿Í»§Éý¼¶¡£
https://www.bleepingcomputer.com/news/security/cisco-warns-admins-to-patch-anyconnect-flaw-exploited-in-attacks/
3¡¢ÎÚ¿ËÀ¼¾ÍCubaÍÅ»ïÕë¶ÔÆäÒªº¦»ù´¡ÉèÊ©µÄ¹¥»÷·¢³ö¾¯±¨
¾Ý10ÔÂ24ÈÕ±¨µÀ£¬ÎÚ¿ËÀ¼¼ÆËã»úÓ¦¼±ÏìӦС×é(CERT-UA)ÒѾÍÀÕË÷ÍÅ»ïCuba¶ÔÆäÒªº¦¼ü»ù´¡ÉèÊ©µÄ¹¥»÷·¢³ö¾¯±¨¡£´Ó10ÔÂ21ÈÕ¿ªÊ¼£¬CERT-UA¾Í¼ì²âµ½ÐÂÒ»²¨µöÓãÓʼþ£¬Ã°³äÁËÎÚ¿ËÀ¼Îä×°¶ÓÎé×ÜÕÕÁϲ¿ÐÂÎÅ·þÎñ²¿£¬ÓÕʹÊÕ¼þÈ˵ã»÷ÆäÖеÄǶÈëʽÁ´½Ó£¬×îÖջᰲװROMCOM RAT¡£¸Ã»ú¹¹ÌåÏÖ£¬¿¼Âǵ½RomComºóÃŵÄʹÓÃÒÔ¼°Ïà¹ØÎļþµÄÆäËûÌØÕ÷£¬ÍƲâ´Ë´Î»î¶¯ÓëTropical Scorpius(UNC2596)Óйأ¬¸ÃÍÅ»ïÂôÁ¦·Ö·¢CubaÀÕË÷Èí¼þ¡£
https://securityaffairs.co/wordpress/137567/cyber-warfare-2/cuba-ransomware-cert-ua.html
4¡¢ÐÂµÄ¹ã¸æ»î¶¯Dormant Colors·Ö·¢¶ñÒâChromeÀ©Õ¹
10ÔÂ23ÈÕ£¬Guardio LabsÅû¶ÁËÐÂÒ»ÂֵĶñÒâ¹ã¸æ»î¶¯Dormant Colors¡£µ½2022Äê10ÔÂÖÐÑ®£¬ÔÚChromeºÍEdgeÍøÂçÉ̵êÖж¼ÓÐ30¸öä¯ÀÀÆ÷À©Õ¹µÄ±äÖÖ£¬ÀÛ¼ÆÁè¼Ý100ÍòµÄ°²×°Á¿¡£¸Ã»î¶¯µÄÖ÷ÌâÓëÑÕÉ«Óйأ¬Ê¼ÓÚ¶ñÒâ¹ã¸æ»î¶¯£¬ÒÔÐÂÓ±µÄÒªÁìÔÚûÈË×¢ÒâµÄÇé¿öϲà¼ÓÔØÕæÕýµÄ¶ñÒâ´úÂë¡£×îºó£¬²»½öÇÔȡĿ±êËÑË÷ºÍä¯ÀÀÊý¾Ý£¬²¢Îª10000¸öÍøÕ¾ÒýÁ÷£¬Óû§ÔÚÕâÐ©ÍøÕ¾ÉϽøÐеÄÈκιºÖÃÐÐΪ¶¼ÊÐΪ¹¥»÷Õß´øÀ´Ó¶½ð¡£
https://guardiosecurity.medium.com/dormant-colors-live-campaign-with-over-1m-data-stealing-extensions-installed-9a9a459b5849
5¡¢SideWinderÀûÓÃкóÃÅWarHawk¹¥»÷°Í»ù˹̹µÄ×éÖ¯
¾ÝýÌå10ÔÂ24ÈÕ±¨µÀ£¬ZscalerÅû¶Á˺ڿÍÍÅ»ïSideWinderµÄкóÃÅWarHawk¡£SideWinderÒÉËÆÓëÓ¡¶ÈÓйأ¬×Ô2012ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬Ö÷ÒªÕë¶ÔÑÇÖÞµÝÈ¥£¬ÓÈÆäÊǰͻù˹̹µÄÕþ¸®¡¢¾ü¶ÓºÍÆóÒµ×éÖ¯¡£½ñÄê9Ô£¬Ñо¿ÈËÔ±ÔÚ°Í»ù˹̹¹ú¼ÒµçÁ¦¼à¹Ü¾ÖµÄºÏ·¨ÍøÕ¾nepra[.]org[.]pk·¢ÏÖÒ»¸öÎäÆ÷»¯ISOÎļþ£¬À´¼¤»îÓÃÀ´°²×°WarHawkµÄkillchain¡£WarHawkÔòαװ³ÉASUS Update SetupºÍRealtek HD Audio ManagerµÈºÏ·¨Ó¦Óã¬Ëü·Ö·¢Cobalt Strike×÷Ϊ×îÖÕpayload¡£
https://thehackernews.com/2022/10/sidewinder-apt-using-new-warhawk.html
6¡¢½¨Öþ¹«Ë¾InterserveÒòÔâµ½ÀÕË÷¹¥»÷±»·£¿î440ÍòÓ¢°÷
10ÔÂ24ÈÕ±¨µÀ³Æ£¬Ó¢¹ú½¨Öþ¹«Ë¾InterserveÒòÀÕË÷¹¥»÷й¶113000ÃûÔ±¹¤µÄÊý¾Ý£¬±»Ó¢¹úÊý¾Ý±£»¤¼à¹Ü»ú¹¹·£¿î440ÍòÓ¢°÷¡£ÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©ÌåÏÖ£¬Interserve GroupδÄܽÓÄÉÊʵ±µÄÄþ¾²´ëÊ©À´·À·¶ÍøÂç¹¥»÷¡£ICO½âÊ͵À£¬¹¥»÷ʼÓÚµöÓãÓʼþ£¬Ä³Ô±¹¤´ò¿ªºóÎÞÒâÖÐÏÂÔØÁ˶ñÒâÈí¼þ£¬¸Ã¹«Ë¾µÄAVÈí¼þÒÑ·¢Ë;¯±¨¡£µ«ºóÐøÊӲ첻¹»³¹µ×£¬µ¼Ö¹¥»÷Õß·ÃÎÊÁË283¸öϵͳºÍ16¸öÕË»§£¬²¢Ð¶ÔØÁ˹«Ë¾µÄAVÈí¼þ¡£Interserve ÒѾͷ£¿îÏòICOÌá³öÉÏËߣ¬µ«×îÖÕ·£¿î²¢Î´¼õÉÙ¡£
https://therecord.media/british-company-fined-4-4-million-over-ransomware-attack/