Lazarus ºÚ¿ÍÀûÓà Windows 0-Day »ñÈ¡ÄÚºËȨÏÞ
Ðû²¼Ê±¼ä 2024-03-012ÔÂ29ÈÕ£¬ÖøÃûµÄÍøÂç·¸×ï×éÖ¯ Lazarus Group ×î½üÀûÓà Windows ÖеÄÁãÈÕ©¶´»ñÈ¡ÄÚºËȨÏÞ£¬ÕâÊÇϵͳ·ÃÎʵÄÒªº¦¼¶±ð¡£¸Ã©¶´±»Ê¶±ðΪ CVE-2024-21338£¬ÊÇÔÚ appid.Sys AppLocker Çý¶¯·¨Ê½Öз¢Ïֵģ¬Î¢ÈíÆ¾¾Ý Avast Threat Labs µÄ³ÂËßÔÚ¶þÔ²¹¶¡ÐÇÆÚ¶þ¸üÐÂÖÐÐÞ¸´Á˸é¶´¡£¸Ã©¶´ÔÊÐí Lazarus Group ½¨Á¢Äں˶Á/дÔÓÕâÊÇÀûÓòÙ×÷ϵͳÄÚºËÄÚ´æµÄ»ù±¾¹¦Ð§¡£´Ë¹¦Ð§ÓÃÓÚ¸üÐÂËûÃÇµÄ FudModule rootkit£¬ÔöÇ¿Æä¹¦Ð§ºÍÒþ±ÎÐÔ¡£Rootkit ÏÖÔÚ°üÂÞÓÃÓÚ²Ù×÷¾ä±ú±íÌõÄ¿µÄм¼Êõ£¬ÕâЩ¼¼Êõ¿ÉÄÜ»á×ÌÈÅÊÜ Microsoft Protected Process Light (PPL) ±£»¤µÄ½ø³Ì£¬ÀýÈçÊôÓÚ Microsoft Defender¡¢CrowdStrike Falcon ºÍ HitmanPro µÄ½ø³Ì¡£CVE-2024-21338ÊÇ Windows Çý¶¯·¨Ê½Öз¢Ïֵĩ¶´µÄÃû³Æ¡£¶ÔÓÚºÚ¿ÍÀ´Ëµ£¬ËüÊÇÒ»¸öºÜºÃµÄÄ¿±ê£¬ÒòΪËüºÜÈÝÒ×ÓÃÓÚ¹¥»÷£¬¶øÇÒËüÊÇϵͳµÄÒ»²¿ÃÅ£¬Òò´ËËûÃDz»ÐèÒªÌí¼ÓÈκοÉÒÔ¼ì²âµ½µÄÐÂÄÚÈÝ¡£
https://gbhackers.com/lazarus-hackers-exploited-windows-0-day/
2. ÖÆÒ©¾ÞÍ· Cencora ³ÂËß³ÆÆäÔâµ½ÍøÂç¹¥»÷
2ÔÂ28ÈÕ£¬Cencora, Inc.£¨ÒÔϼò³Æ¡°¹«Ë¾¡±£©»ñϤÆäÐÅϢϵͳÖеÄÊý¾ÝÒѱ»Ð¹Â¶£¬ÆäÖв¿ÃÅÊý¾Ý¿ÉÄܰüÂÞ¸öÈËÐÅÏ¢¡£ÔÚ¿ª¶Ë·¢ÏÖδ¾ÊÚȨµÄ¹¥»÷»î¶¯ºó£¬¹«Ë¾Á¢¼´½ÓÄÉÍ£Ö¹´ëÊ©£¬²¢ÔÚÖ´·¨²¿ÃÅ¡¢ÍøÂçÄþ¾²×¨¼ÒºÍÍⲿÕÕÁϵÄÐÖúÏ¿ªÊ¼ÊӲ졣½ØÖÁ±¾Í¨¸æÐû²¼Ö®ÈÕ£¬¸ÃʼþÉÐδ¶Ô¹«Ë¾ÔËÓª·¢ÉúÖØ´óÓ°Ï죬ÆäÐÅϢϵͳÈÔÔÚÔËÐС£¹«Ë¾ÉÐδȷ¶¨¸ÃʼþÊÇ·ñºÏÀí¿ÉÄܶԹ«Ë¾µÄ²ÆÕþ×´¿ö»ò¾ÓªÒµ¼¨·¢ÉúÖØ´óÓ°Ïì¡£¾ÝThe Record±¨µÀ£¬Cencora ÒÔǰ³ÆÎª AmerisourceBergen¡£AmerisourceBergen ¹«Ë¾Ëƺõ¾ÀúÁË Lorenz ÀÕË÷Èí¼þ×éÖ¯ÓÚ 2023 Äê 1 ÔÂÉù³ÆµÄÀÕË÷Èí¼þ¹¥»÷£¬¶øÇÒËÆºõÓ°ÏìÁË MWI Animal Health¡£DataBreaches Éв»Çå³þ 2022 ÄêʼþÓë×î½üµÄ³ÂËßÖ®¼äÊÇ·ñÓÐÈκÎÁªÏµ¡£
https://www.databreaches.net/pharmaceutical-giant-cencora-reports-cyberattack/
3. Rhysida ÀÕË÷ÍŻ﹥»÷Lurie²¢ÀÕË÷ 360 ÍòÃÀÔª
2ÔÂ28ÈÕ£¬Rhysida ÀÕË÷Èí¼þÍÅ»ïÉù³Æ¶Ô±¾Ô³õÕë¶ÔÖ¥¼Ó¸ç¬Àï¶ùͯҽԺµÄÍøÂç¹¥»÷ÂôÁ¦¡£Lurie ÊÇÃÀ¹úÁìÏȵĶù¿Æ¼±Ö¢»¤Àí»ú¹¹£¬Ã¿ÄêΪÁè¼Ý 200,000 Ãû¶ùͯÌṩ»¤Àí¡£ÍøÂç¹¥»÷ÆÈʹҽÁƱ£½¡ÌṩÉÌ¹Ø±ÕÆä IT ϵͳ£¬²¢ÔÚijЩÇé¿öÏÂÍÆ³ÙÒ½ÁÆ»¤Àí¡£µç×ÓÓʼþ¡¢µç»°¡¢MyChart ·ÃÎʺ͵±µØ»¥ÁªÍø¾ùÊܵ½Ó°Ïì¡£³¬Éù²¨ºÍ CT ɨÃè½á¹ûÎÞ·¨»ñµÃ£¬»¼Õß·þÎñÓÅÏÈϵͳ±»È¡Ïû£¬Ò½Éú±»ÆÈ¸ÄÓñʺÍÖ½¿ª´¦·½¡£Rhysida ÀÕË÷Èí¼þÍÅ»ïÒѽ« Lurie Children¡¯s Ò½ÔºÁÐÈëÆä°µÍøÉϵÄÀÕË÷ÃÅ»§ÍøÕ¾£¬Éù³Æ´Ó¸ÃÒ½ÔºÇÔÈ¡ÁË 600 GB µÄÊý¾Ý¡£Æ¾¾ÝLurie Children's ÓÚ 2024 Äê 2 Ô 22 ÈÕÐû²¼µÄ×îÐÂ״̬¸üУ¬»Ö¸´ IT ϵͳµÄÊÂÇéÕýÔÚ½øÐÐÖУ¬·þÎñÖжÏÈÔȻӰÏìһЩÔËÓª²¿ÃÅ¡£
https://www.bleepingcomputer.com/news/security/rhysida-ransomware-wants-36-million-for-childrens-stolen-data/
4. Anycubic 3D´òÓ¡»úÔÚÈ«Çò·¶Î§ÄÚÔâµ½ºÚ¿Í¹¥»÷
2ÔÂ28ÈÕ£¬Æ¾¾Ý Anycubic ¿Í»§µÄÒ»²¨ÔÚÏß³ÂËߣ¬ÓÐÈËÈëÇÖÁËËûÃÇµÄ 3D ´òÓ¡»ú£¬²¢¾¯¸æÕâЩÉè±¸ÃæÁÙ¹¥»÷¡£´Ëʼþ±³ºóµÄÈËÔÚÆäÉ豸ÖÐÌí¼ÓÁË hacked_machine_readme.gcode Îļþ£¨¸ÃÎļþͨ³£°üÂÞ 3D ´òÓ¡Ö¸Á£¬ÌáÐÑÊÜÓ°ÏìµÄÓû§ËûÃǵĴòÓ¡»úÊܵ½ÑÏÖØÄþ¾²´íÎóµÄÓ°Ïì¡£¾Ý³Æ£¬´Ë©¶´Ê¹Ç±ÔÚ¹¥»÷ÕßÄܹ»Ê¹Óøù«Ë¾µÄ MQTT ·þÎñ API ¿ØÖÆÈκÎÊÜ´Ë©¶´Ó°ÏìµÄ Anycubic 3D ´òÓ¡»ú¡£ÊÜÓ°ÏìÉ豸ÊÕµ½µÄÎļþ»¹ÒªÇó Anycubic ¿ªÔ´Æä 3D ´òÓ¡»ú£¬ÔÚÓû§³ÂËß 3D ´òÓ¡»úÏÔʾ¡°±»ºÚ¡±ÏûÏ¢¿ªÊ¼·ºÆðºó£¬ AnycubicÓ¦Ó÷¨Ê½Ò²Í£Ö¹ÁËÊÂÇé¡£ÕýÈçTechCrunchÊ״ᨵÀµÄÄÇÑù£¬ÊµÑéµÇ¼µÄÓû§»á¿´µ½¡°ÍøÂç²»ÐÐÓá±´íÎóÏûÏ¢¡£
https://www.bleepingcomputer.com/news/security/anycubic-3d-printers-hacked-worldwide-to-expose-security-flaw/
5. ÓëÒÁÀÊÓÐ¹ØµÄ UNC1549 ºÚ¿ÍÃé×¼Öж«º½¿Õº½ÌìºÍ¹ú·À²¿ÃÅ
2ÔÂ28ÈÕ£¬¹È¸èÆìÏ嵀 Mandiant ÔÚÒ»·ÝзÖÎöÖÐÌåÏÖ£¬ÍøÂç¼äµý»î¶¯µÄÆäËûÄ¿±ê¿ÉÄܰüÂÞÍÁ¶úÆä¡¢Ó¡¶ÈºÍ°¢¶û°ÍÄáÑÇ¡£ÕâЩ¹¥»÷ÐèҪʹÓà Microsoft Azure ÔÆ»ù´¡ÉèÊ©½øÐÐÃüÁîÓë¿ØÖÆ (C2) ºÍÉæ¼°ÓëÊÂÇéÏà¹ØµÄÓÕ»óµÄÉç»á¹¤³Ì£¬ÒÔÌṩÁ½¸öÃûΪ MINIBIKE ºÍ MINIBUS µÄºóÃÅ¡£Óã²æÊ½ÍøÂçµöÓãµç×ÓÓʼþÖ¼ÔÚÁ÷´«°üÂÞÒÔÉ«ÁйþÂí˹Ïà¹ØÄÚÈÝ»òÐé¼ÙÊÂÇé»ú»áµÄÐé¼ÙÍøÕ¾Á´½Ó£¬´Ó¶øµ¼Ö²¿Êð¶ñÒâ¸ºÔØ¡£»¹ÊӲ쵽ģ·Â´ó¹«Ë¾µÄÐé¼ÙµÇÂ¼Ò³ÃæÒÔ»ñȡƾ¾Ý¡£×Ô½ç˵ºóÃÅÔÚ½¨Á¢ C2 ·ÃÎʺ󣬳䵱Ç鱨ÊÕ¼¯ºÍ½øÒ»²½·ÃÎÊÄ¿±êÍøÂçµÄÇþµÀ¡£´Ë½×¶Î²¿ÊðµÄÁíÒ»¸ö¹¤¾ßÊÇÃûΪ LIGHTRAIL µÄËíµÀÈí¼þ£¬ËüʹÓà Azure ÔÆ½øÐÐͨÐÅ¡£´Ë´Î¹¥»÷»î¶¯Öв¿ÊðµÄ¹æ±ÜÒªÁ죬¼´Á¿Éí¶¨ÖÆµÄÒÔÊÂÇéΪÖ÷ÌâµÄÓÕ¶üÓë C2 ÔÆ»ù´¡ÉèÊ©µÄʹÓÃÏà½áºÏ£¬¿ÉÄÜ»áÈÃÍøÂç·ÀÓùÕßÄÑÒÔÔ¤·À¡¢¼ì²âºÍ¼õÇáÕâÖֻ¡£
https://thehackernews.com/2024/02/iran-linked-unc1549-hackers-target.html
6. ÀÕË÷Èí¼þÍÅ»ïÉù³ÆÇÔÈ¡½ü 200GB µÄ Epic Games ÄÚ²¿Êý¾Ý
2ÔÂ28ÈÕ£¬¾Ý±¨µÀ£¬¸ÃÍÅ»ïÃûΪ Mogilevich£¬ÔÚÆä°µÍøÐ¹ÃÜÍøÕ¾ÉÏÐû²¼ÁËÒ»ÌõÏûÏ¢£¬ÌṩÁËÓÐ¹ØÆäÉù³ÆµÄ¡¶µï±¤Ö®Ò¹¡·ºÍEpic Games Store¹«Ë¾Ð¹ÃÜʼþµÄ¸ü¶àÐÅÏ¢¡£»¹Éù³ÆÒѾй¶ÁË¡°µç×ÓÓʼþ¡¢ÃÜÂ롢ȫÃû¡¢¸¶¿îÐÅÏ¢¡¢Ô´´úÂëºÍÐí¶àÆäËûÊý¾Ý¡±£¬×ܾÞϸµ½´ï 189GB¡£»¹Ëµ£º¡°Êý¾ÝÒ²¿ÉÒÔ³öÊÛ¡±£¬²¢Îª¡°¹«Ë¾Ô±¹¤»òÏëÒª¹ºÖÃÊý¾ÝµÄÈË¡±Ìí¼ÓÁËÁ´½Ó¡£¸ÃÍÅ»ï¹æ¶¨ÁË 3 Ô 4 ÈÕΪ¹ºÖÃÊý¾ÝµÄ×îºóÆÚÏÞ£¬µ«Ã»Óиø³ö¾ßÌåÊý×Ö£¬Ò²Ã»ÓбíÃ÷Èç¹û½ØÖ¹ÈÕÆÚ¹ýºó½«ÈçºÎ´¦ÖÃÕâЩÊý¾Ý¡£Mogilevich ÊÇÒ»¸öÏà¶Ô½ÏеÄÀÕË÷Èí¼þ×éÖ¯£¬Epic Games ÊÇÆäµÚËĸöÄ¿±ê¡£µÚÒ»¸öÊÇÈÕ²ú×Ó¹«Ë¾Ó¢·ÆÄáµÏÃÀ¹ú¹«Ë¾£¬¸Ã¹«Ë¾ÉÏÖÜÔâµ½ºÚ¿Í¹¥»÷¡£
https://www.videogameschronicle.com/news/a-ransomware-gang-claims-to-have-hacked-nearly-200gb-of-epic-games-internal-data/