ÒÁÀÊ×î´óµÄ¸ÖÌúÉú²úÉÌKSC³ÆÆä±»¹¥»÷µ¼ÖÂÔËÓª»î¶¯ÖÐÖ¹

Ðû²¼Ê±¼ä 2022-06-28

1¡¢ÒÁÀÊ×î´óµÄ¸ÖÌúÉú²úÉÌKSC³ÆÆä±»¹¥»÷µ¼ÖÂÔËÓª»î¶¯ÖÐÖ¹


¾Ý6ÔÂ28ÈÕ±¨µÀ£¬£¬£¬ÒÁÀÊ×î´óµÄ¸ÖÌúÉú²úÉÌKhouzestan Steel Company(KSC)È·ÈÏÆäÔâµ½ÁËÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ±¾ÖÜÒ»£¬£¬£¬ÆäʱÆäÍøÕ¾ÎÞ·¨»á¼û£¬£¬£¬¸Ã¹«Ë¾Á¬Ã¦ÖÐÖ¹ÁËÔËÓª¡£¡£¡£¡£¡£¡£ÆäÊ×ϯִÐйÙÉù³ÆËûÃÇÒÑÀֳɵÖÓù´Ë´Î¹¥»÷£¬£¬£¬ÊÜÓ°ÏìµÄÍøÕ¾½«ºÜ¿ì»Ö¸´²¢ÖØÐÂÉÏÏß¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬ÒÁÀÊÍâµØÃ½ÌåJamaranÌåÏÖ£¬£¬£¬Õâ´Î¹¥»÷ûÓÐÀֳɣ¬£¬£¬ÊÇÓÉÓÚµ±Ëü±¬·¢Ê±£¬£¬£¬¹¤³§ÓÉÓÚÍ£µç¶øÎÞ·¨ÔË×÷¡£¡£¡£¡£¡£¡£


https://www.hackread.com/iran-largest-steel-producer-hit-by-cyberattack/


2¡¢ÎÚ¿ËÀ¼µÄµçÐÅÔËÓªÉ̺͹©Ó¦ÉÌÔâµ½DarkCrystal RATµÄ¹¥»÷


ÎÚ¿ËÀ¼Õþ¸®ÅÌËã»úÓ¦¼±ÏìӦС×é(CERT-UA)ÔÚ6ÔÂ24ÈÕÐû²¼Í¨¸æ£¬£¬£¬Õ¹ÏÖÁËDarkCrystal RATÕë¶ÔÎÚ¿ËÀ¼µçÐÅÔËÓªÉ̵ĶñÒâÈí¼þ»î¶¯¡£¡£¡£¡£¡£¡£´Ë´Î»î¶¯Ê¹ÓÃÁËÒÔ¡°Ãâ·Ñ³õ¼¶Ö´·¨Ô®Öú¡±ÎªÖ÷ÌâµÄÀ¬»øÓʼþ£¬£¬£¬¼°¸½¼þ¡°Ê§×ÙÎäÊ¿¼ÒÍ¥³ÉÔ±µÄÐж¯Ëã·¨LegalAid.rar¡±¡£¡£¡£¡£¡£¡£RARÎĵµ°üÀ¨Algorithm_LegalAid.xlsm£¬£¬£¬µ±·­¿ªÎĵµ²¢¼¤»îºêʱ£¬£¬£¬½«Ö´ÐÐPowerShellÏÂÁ£¬£¬È»ºóÏÂÔØ²¢ÔËÐÐ.NETÖ¸µ¼¼ÓÔØ³ÌÐòMSCommonll.exe£¬£¬£¬ËüÓÖ»áÏÂÔØ²¢ÔËÐжñÒâÈí¼þDarkCrystal RAT¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÊÕ¼þÈ˵ĵصãºÍÓòÖÎÀíDarkCrystal RAT£¬£¬£¬Ñо¿Ö°Ô±ÍƶϹ¥»÷Ä¿µÄÊÇÎÚ¿ËÀ¼µÄµçÐÅÔËÓªÉ̺͹©Ó¦ÉÌ¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/132651/malware/cert-ua-darkcrystal-rat-attacks.html


3¡¢°ÍÎ÷ÁãÊÛÉÌFast ShopÔâµ½¹¥»÷ºóÏßÉÏÉ̳ÇÔÝʱ¹Ø±Õ


¾ÝýÌå6ÔÂ24ÈÕ±¨µÀ£¬£¬£¬°ÍÎ÷×î´óµÄÁãÊÛÉÌÖ®Ò»Fast ShopÔâµ½¹¥»÷£¬£¬£¬µ¼ÖÂÍøÂçÖÐÖ¹²¢ÔÝʱ¹Ø±ÕÔÚÏßÊÐËÁ¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚÉÏÖÜÈý£¬£¬£¬Ó°ÏìÁ˸ù«Ë¾µÄ¹Ù·½ÍøÕ¾¡¢Òƶ¯Ó¦ÓóÌÐòºÍÔÚÏß¶©¹ºÏµÍ³£¬£¬£¬²¢Î´Ó°ÏìʵÌåµê¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬¹¥»÷Õß»¹ÈëÇÖÁ˸ù«Ë¾µÄTwitterÕË»§£¬£¬£¬·¢ÎijÆËûÃÇ»á¼ûÁËFast ShopÔÚAWS¡¢Azure¡¢GitLabºÍIBMÔÆÉϵÄÊý¾Ý¿â£¬£¬£¬²¢ÇÔÈ¡ÁËÍøÕ¾ºÍÓ¦ÓóÌÐòµÄÔ´´úÂ룬£¬£¬ÒÔ¼°Óû§ºÍÆóÒµÊý¾Ý¡£¡£¡£¡£¡£¡£Fast Shop»ØÓ¦ÁËÕâһ˵·¨£¬£¬£¬ÌåÏÖËûÃǵÄÊý¾Ý²¢Î´±»Ð¹Â¶¡£¡£¡£¡£¡£¡£


https://therecord.media/brazilian-retail-giant-confirms-cyberattack-after-extortion-group-takes-over-twitter-account/


4¡¢AhnLab·¢Ã÷ʹÓðæÈ¨ÇÖȨÖÒÑÔÓʼþ·Ö·¢LockBitµÄ»î¶¯


AhnLabÔÚ6ÔÂ24ÈÕÐû²¼±¨¸æ£¬£¬£¬ÏêÊöÁËʹÓðæÈ¨ÇÖȨÖÒÑÔÓʼþ·Ö·¢LockBitµÄ»î¶¯¡£¡£¡£¡£¡£¡£ÓʼþÖ¸³öÊÕ¼þÈËÔÚδ¾­´´×÷ÕßÔÊÐíµÄÇéÐÎÏÂʹÓÃÁËýÌåÎļþ£¬£¬£¬ÐèÒªÏÂÔØ²¢·­¿ª¸½¼þÒÔÉó²éÇÖȨÄÚÈÝ¡£¡£¡£¡£¡£¡£¸½¼þÖаüÀ¨Ò»¸öʹÓÃPDFÎļþͼ±êαװµÄ¿ÉÖ´ÐÐÎļþ£¬£¬£¬µ«ÏÖʵÉÏÊÇNSIS×°ÖóÌÐò¡£¡£¡£¡£¡£¡£Éó²énsi¾ç±¾ÏêϸÐÅÏ¢£¬£¬£¬Ëü»á½âÂëÊý¾ÝÎļþ¡°162809383¡±²¢Í¨¹ýµÝ¹éºÍ×¢ÈëÖ´ÐжñÒâ»î¶¯¡£¡£¡£¡£¡£¡£µ±Ä¿µÄ·­¿ªËùνµÄPDFÎļþºó£¬£¬£¬Æä×°±¸»á±»ÀÕË÷Èí¼þLockBit 2.0¼ÓÃÜ¡£¡£¡£¡£¡£¡£


https://asec.ahnlab.com/en/35822/


5¡¢CafePressÒòÑÚÊÎ2300Íò¿Í»§Êý¾Ýй¶ÊÂÎñ±»·£¿ £¿£¿£¿£¿î50ÍòÃÀÔª


ýÌå6ÔÂ24Èճƣ¬£¬£¬ÃÀ¹úÁª°îÉÌҵίԱ»á(FTC)ÒÑÔðÁîCafePressµÄǰËùÓÐÕßResidual Pumpkin EntityÖ§¸¶500000ÃÀÔªµÄ·£¿ £¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£Ôµ¹ÊÔ­ÓÉÊÇËüÑÚÊÎÁËÓ°ÏìÁè¼Ý2300Íò¿Í»§µÄÊý¾Ýй¶ÊÂÎñ£¬£¬£¬²¢ÇÒδÄܱ£»£»£»£»£» £»¤ËûÃǵÄÊý¾Ý¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹³Æ£¬£¬£¬Residual Pumpkin EntityÒÔ´¿Îı¾ÐÎʽ´æ´¢Á˿ͻ§µÄÉç»áÇå¾²ºÅÂëºÍÃÜÂëÖØÖÃÃÕµ×£¬£¬£¬²¢ÇÒÁè¼ÝÁËÐëÒªµÄʱ¼ä¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬¸Ã¹«Ë¾Ò²Î´ÄܽÓÄÉÓÐÓõı£»£»£»£»£» £»¤²½·¥²¢¶ÔÇ徲ʹÊ×÷³ö·´Ó¦£¬£¬£¬ÔÚÆäЧÀÍÆ÷±»¶à´ÎÈëÇֺ󣬣¬£¬ÊÔͼÑÚÊÎÒò²»µ±µÄÇå¾²Õ½ÂÔ¶øµ¼ÖµÄÖØ´óÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cafepress-fined-500-000-for-breach-affecting-23-million-users/


6¡¢CybleÅû¶½¨Éè¶ñÒâLNKµÄй¤¾ßQuantumµÄÊÖÒÕϸ½Ú


6ÔÂ22ÈÕ£¬£¬£¬CybleÅû¶Á˽¨Éè¶ñÒâLNKµÄй¤¾ßQuantumµÄÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¾ßÓÐUACÈÆ¹ý¡¢Windows SmartscreenÈÆ¹ý¡¢ÔÚµ¥¸öLNKÎļþÉϼÓÔØ¶à¸öpayload¡¢Ö´ÐкóÒþ²Ø¡¢Æô¶¯ºÍÑÓ³ÙÖ´Ðеȹ¦Ð§¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬¿ª·¢ÕßÉù³ÆÊ¹ÓÃQuantumÌìÉúµÄÎļþÊÇ100% FUD¡£¡£¡£¡£¡£¡£ÔÚҰʹÓøöñÒâÈí¼þµÄ×îÔçÑù±¾¿ÉÒÔ×·Ëݵ½5ÔÂ24ÈÕ£¬£¬£¬Æäαװ³ÉÎÞº¦µÄÎı¾Îļþtest.txt.lnk¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬QuantumÓ볯ÏʵÄLazarusÓйØÁª£¬£¬£¬½ÏÁ¿Á½ÕßʹÓõľ籾ºó£¬£¬£¬·¢Ã÷È¥»ìÏýÑ­»·ºÍ±äÁ¿³õʼ»¯ÊÇÏàͬµÄ¡£¡£¡£¡£¡£¡£


https://blog.cyble.com/2022/06/22/quantum-software-lnk-file-based-builders-growing-in-popularity/