MOVEit·ì϶ÖÂÊý¾Ýй¶£¬£¬£¬£¬£¬ £¬£¬£¬Nam3L3ss×éÖ¯ÆØ¹âÊý°ÙÍòÔ±¹¤¼Í¼

°ä²¼¹¦·ò 2024-12-05

1. MOVEit·ì϶ÖÂÊý¾Ýй¶£¬£¬£¬£¬£¬ £¬£¬£¬Nam3L3ss×éÖ¯ÆØ¹âÊý°ÙÍòÔ±¹¤¼Í¼


12ÔÂ3ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬Ò»Â·Éæ¼°MOVEitÎļþ´«Ê乤¾ßµÄ°²È«·ì϶ÊÂÎñÒý·¢ÁË¿í·º¹Ø×¢¡£¡£¡£ ¡£¡£¡£¡£¸Ã·ì϶±»Cl0pÀÕË÷²¡¶¾ÍÅ»ïÀûÓ㬣¬£¬£¬£¬ £¬£¬£¬µ¼ÖÂÊýǧ¼Ò¹«Ë¾µÄÃô¸ÐÊý¾Ý±»µÁ£¬£¬£¬£¬£¬ £¬£¬£¬ÆäÖÐÔ̺¬À´×Ô27¼Ò´ó¹«Ë¾µÄ³¬¹ý760,000·ÝÔ±¹¤¼Í¼£¬£¬£¬£¬£¬ £¬£¬£¬ÒÔ¼°ÖÙÁ¿ÁªÐй«Ë¾(JLL.com)µÄ1200ÍòÐÐÊý¾Ý£¬£¬£¬£¬£¬ £¬£¬£¬×ÜÊý´ïµ½1312ÍòÌõ¡£¡£¡£ ¡£¡£¡£¡£ÕâЩÊý¾ÝÔ̺¬ÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢µØÖ·ºÍ¹«Ë¾µØÎ»×ø±êµÈÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬£¬±»Ð¹Â¶ºó¿ÉÄܻᱻÓÃÓÚÉç»á¹¤³Ì¹¥»÷¡¢Éí·Ý͵ÇÔ»òÍøÂç´¹µöÚ¿Æ­µÈ¶ñÒâÐÐΪ¡£¡£¡£ ¡£¡£¡£¡£Ð¹Â¶Êý¾ÝµÄ×éÖ¯Nam3L3ss×Գơ°Êý¾ÝÒåÓ¾ü¡±£¬£¬£¬£¬£¬ £¬£¬£¬ÔÚºÚ¿ÍÂÛ̳BreachForumsÉϰ䲼ÁËÕâЩÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬£¬²¢Ðû³ÆÊÇ´ÓMOVEit·ì϶ÖлñµÃµÄÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£Õâ´ÎйÃÜÊÂÎñÉæ¼°µÄ¹«Ë¾Ô̺¬ÃÀ¹úÒøÐÓעŵ»ùÑÇ¡¢Ä¦¸ùÊ¿µ¤ÀûµÈÐÐÒµ¾ÞÍ·£¬£¬£¬£¬£¬ £¬£¬£¬×ÜÊý´ïµ½½ü1ÒÚÓ×ÎÒ¡£¡£¡£ ¡£¡£¡£¡£¹ÌÈ»Nam3L3ssµÄ¶¯»úÉв»Ã÷È·£¬£¬£¬£¬£¬ £¬£¬£¬µ«ËûÃǵÄÐÐΪÎÞÒɶ³öÁËMOVEit·ì϶µÄ³Á´óÓ°ÏìÒÔ¼°±»µÁÔ±¹¤Êý¾Ý´øÀ´µÄ·çÏÕ¡£¡£¡£ ¡£¡£¡£¡£ÊÜÓ°Ï칫˾µÄÔ±¹¤Ó¦Î¬³Ö¾¯Ì裬£¬£¬£¬£¬ £¬£¬£¬ÒÔ·ÀÍøÂç´¹µöµÈ¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£


https://hackread.com/data-vigilante-leaks-772k-employee-record-database/


2. KimsukyÀûÓô¹µöÓʼþ½øÐÐÆ¾Ö¤ÇÔÈ¡£¬£¬£¬£¬£¬ £¬£¬£¬ÀÄÓöíÂÞ˹·¢¼þÈ˵ØÖ·


12ÔÂ3ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬Ó볯ÏʽáÃ˵ÄÍþвÐÐΪÕßKimsuky£¬£¬£¬£¬£¬ £¬£¬£¬±»Ö¸ÓëһϵÁÐÍøÂç´¹µö¹¥»÷ÓйØÁª¡£¡£¡£ ¡£¡£¡£¡£ÕâЩ¹¥»÷ÖØÒªÍ¨¹ý·¢ËÍÔ´×Ô¶íÂÞ˹·¢¼þÈ˵ØÖ·µÄµç×ÓÓʼþ½øÐУ¬£¬£¬£¬£¬ £¬£¬£¬Ö¼ÔÚÇÔȡƾ֤¡£¡£¡£ ¡£¡£¡£¡£¾Ýº«¹úÍøÂ簲ȫ¹«Ë¾Genians¹Û²ì£¬£¬£¬£¬£¬ £¬£¬£¬´¹µöÓʼþ×î³õÖØÒªÍ¨¹ýÈÕ±¾ºÍº«¹úµÄµç×ÓÓʼþ·þÎñ·¢ËÍ£¬£¬£¬£¬£¬ £¬£¬£¬µ«´Ó9ÔÂÖÐÑ®ÆðÍ·£¬£¬£¬£¬£¬ £¬£¬£¬¼Ù×°³ÉÀ´×Ô¶íÂÞ˹µÄ´¹µöÓʼþÖð²½Ôö¶à£¬£¬£¬£¬£¬ £¬£¬£¬ÀÄÓÃVKµÄMail.ruµç×ÓÓʼþ·þÎñ£¬£¬£¬£¬£¬ £¬£¬£¬¸Ã·þÎñÖ§³ÖÎå¸ö±ðºÅÓò¡£¡£¡£ ¡£¡£¡£¡£Kimsuky¹¥»÷ÕßÀûÓÃÕâЩ·¢¼þÈËÓò¼Ù×°³É½ðÈÚ»ú¹¹ºÍ»¥ÁªÍøÃÅ»§ÍøÕ¾£¬£¬£¬£¬£¬ £¬£¬£¬ÈçNaver£¬£¬£¬£¬£¬ £¬£¬£¬½øÐÐÍøÂç´¹µö»î¶¯¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬£¬£¬»¹·¢ËÍ·ÂÕÕNaver MYBOXÔÆ´æ´¢·þÎñµÄÐÂÎÅ£¬£¬£¬£¬£¬ £¬£¬£¬ÓÕµ¼Óû§µã»÷Á´½Ó£¬£¬£¬£¬£¬ £¬£¬£¬Ðû³ÆÔÚÆäÕÊ»§Öмì²âµ½¶ñÒâÎļþ²¢±ØÒªÉ¾³ý£¬£¬£¬£¬£¬ £¬£¬£¬ÒÔ´ËÓÕÆ­Óû§¡£¡£¡£ ¡£¡£¡£¡£ÕâЩÐÂÎŹÌÈ»±í±íÉÏÊÇ´ÓÌØ¶¨ÓòÃû·¢Ë͵Ä£¬£¬£¬£¬£¬ £¬£¬£¬µ«ÏÖʵÉÏÊÇÀûÓÃÊÜϰȾµÄµç×ÓÓʼþ·þÎñÆ÷·¢Ë͵Ä¡£¡£¡£ ¡£¡£¡£¡£Kimsuky»¹ÉÆÓÚʹÓúϷ¨µç×ÓÓʼþ¹¤¾ßÈçPHPMailerºÍStar£¬£¬£¬£¬£¬ £¬£¬£¬ÒÔÌӱܰ²È«²é³­¡£¡£¡£ ¡£¡£¡£¡£ÕâЩ¹¥»÷µÄ×îÖÕÖ¸±êÊÇÆ¾Ö¤ÍµÇÔ£¬£¬£¬£¬£¬ £¬£¬£¬½ø¶ø½Ù³ÖÊܺ¦ÕßÕË»§£¬£¬£¬£¬£¬ £¬£¬£¬²¢ÀûÓÃËüÃÇ¶ÔÆäËûÔ±¹¤»òÊìÈËÌáÒéºóÐø¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£


https://thehackernews.com/2024/12/north-korean-kimsuky-hackers-use.html


3. Å·¾¯µ·»Ù¼ÓÃÜ·¸×ïÆ½Ì¨MATRIX£¬£¬£¬£¬£¬ £¬£¬£¬½É»ñ´óÁ¿·¸·¨×ʲú


12ÔÂ4ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬Å·ÖÞÐ̾¯×éÖ¯°ä·¢£¬£¬£¬£¬£¬ £¬£¬£¬·¨¹úºÍºÉÀ¼·¨Âɲ¿ÃÅÒѵ·»ÙÓë¹ú¼Ê··¶¾¡¢±øÆ÷··Ô˺ÍÏ´Ç®µÈÑϳÁ·¸×ïÓйصÄÃûΪMATRIXµÄ¼ÓÃÜÐÅÏ¢·þÎñ¡£¡£¡£ ¡£¡£¡£¡£¸Ãƽ̨×î³õÓɺÉÀ¼µ±¾ÖÔÚÒ»Ãû×ï·¸ÊÖ»úÖз¢ÏÖ£¬£¬£¬£¬£¬ £¬£¬£¬Õ¼Óнü8000ÃûÓû§£¬£¬£¬£¬£¬ £¬£¬£¬·þÎñÆ÷±é²¼¶à¸ö¹ú¶È£¬£¬£¬£¬£¬ £¬£¬£¬ÖØÒªÔڵ¹úºÍ·¨¹ú¡£¡£¡£ ¡£¡£¡£¡£¾¯·½ÔÚÈý¸öÔµĵ÷²éÖнػñ²¢ÆÆÒëÁË230¶àÍòÌõÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬£¬²¢ÔÚ¹ú¼ÊÐж¯ÖзÛËéÁË·þÎñÆ÷£¬£¬£¬£¬£¬ £¬£¬£¬¿ÛÁôÁËÈýÃûÏÓÒÉÈË£¬£¬£¬£¬£¬ £¬£¬£¬Ô̺¬Æ½Ì¨µÄÏÓÒÉËùÓÐÕߺÍÔËÓªÉÌ¡£¡£¡£ ¡£¡£¡£¡£MATRIXÕ¼Óи´ÔӵĻù´¡ÉèÊ©£¬£¬£¬£¬£¬ £¬£¬£¬Ìṩ¼ÓÃÜÐÂÎÅ´«µÝ¡¢°²È«Í¨»°¡¢ÊÓÆµºÍÓïÒô¹²ÏíÒÔ¼°ÄäÃûÍøÒ³ä¯ÀÀµÈ·þÎñ£¬£¬£¬£¬£¬ £¬£¬£¬ÉõÖÁÍÆ³öÁË´ò¶ÄÀûÓ÷¨Ê½ºÍÇ®±Ò¡£¡£¡£ ¡£¡£¡£¡£Å·ÖÞÐ̾¯×éÖ¯°µÊ¾£¬£¬£¬£¬£¬ £¬£¬£¬MATRIX±È֮ǰ±»È¡µÞµÄSky ECCºÍEncroChatµÈƽ̨¸üΪ¸´ÔÓ£¬£¬£¬£¬£¬ £¬£¬£¬Óû§Ö»ÄÜͨ¹ýÔ¼Çë²ÎÓë¡£¡£¡£ ¡£¡£¡£¡£¾¯·½½«³ÖÐøµ÷²éÓë¸Ãƽ̨Óйصķ¸×ï»î¶¯¡£¡£¡£ ¡£¡£¡£¡£


https://therecord.media/matrix-criminal-encrypted-chat-platform-takedown-police


4. CISA½«Èý¸ö·ì϶Ôö³¤µ½ÒÑÖª±»ÀûÓ÷ì϶Ŀ¼


12ÔÂ4ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ¸üÐÂÁËÆäÒÑÖª±»ÀûÓ÷ì϶£¨KEV£©Ä¿Â¼£¬£¬£¬£¬£¬ £¬£¬£¬ÐÂÔöÁËÈý¸ö·ì϶£¬£¬£¬£¬£¬ £¬£¬£¬±ðÀëÊÇProjectSendµÄÉí·ÝÑéÖ¤²»µ±·ì϶£¨CVE-2024-11680£©¡¢North Grid ProselfµÄXML±í²¿ÊµÌ壨XEE£©ÒýÓ÷ì϶£¨CVE-2023-45727£©ÒÔ¼°Zyxel¶à·À»ðǽµÄõè¾¶±éÀú·ì϶£¨CVE-2024-11667£©¡£¡£¡£ ¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬ £¬£¬£¬ProselfµÄ·ì϶ÔÊÐíδ¾­ÊÚȨµÄ¹¥»÷Õß¶ÁÈ¡·þÎñÆ÷Îļþ£¬£¬£¬£¬£¬ £¬£¬£¬Ô̺¬ÕË»§Êý¾Ý£»£»£» £»£»£»£»ProjectSendµÄ·ì϶ÔòÓ°Ïìr1720֮ǰµÄ°æ±¾£¬£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õ߿ɽè´Ëδ¾­ÊÚȨÅú¸ÄÀûÓÃÅäÖ㬣¬£¬£¬£¬ £¬£¬£¬´´½¨ÕË»§£¬£¬£¬£¬£¬ £¬£¬£¬ÉÏ´«¶ñÒâÈí¼þ£»£»£» £»£»£»£»¶øZyxelµÄ·ì϶Ôò¿ÉÄÜÈù¥»÷Õßͨ¹ý¾«ÐÄÉè¼ÆµÄURLÏÂÔØ»òÉÏ´«Îļþ¡£¡£¡£ ¡£¡£¡£¡£¾ÝVulnCheck×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬ £¬£¬£¬ProjectSendµÄ·ìÏ¶ËÆºõÒѱ»Ò°±í¹¥»÷ÕßÀûÓ㬣¬£¬£¬£¬ £¬£¬£¬ÇÒ¹¥»÷ÕßÒѲÉȡһϵÁÐÐж¯£¬£¬£¬£¬£¬ £¬£¬£¬Èç¸ü¸ÄµÇÂ¼Ò³Ãæ±êÌ⣬£¬£¬£¬£¬ £¬£¬£¬ÆôÓÃÓû§×¢²áÒÔ»ñÈ¡Éí·ÝÑéÖ¤ºóµÄ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬ £¬£¬£¬²¢ÉÏ´«Webshell¡£¡£¡£ ¡£¡£¡£¡£CISAÒÑÒªÇóÁª¹ú»ú¹¹ÔÚ2024Äê12ÔÂ24ÈÕ֮ǰ½¨¸´ÕâЩ·ì϶£¬£¬£¬£¬£¬ £¬£¬£¬²¢½¨Òé¸öÈË×éÖ¯Éó²é¸ÃĿ¼²¢½â¾öÆä»ù´¡ÉèÊ©Öеķì϶£¬£¬£¬£¬£¬ £¬£¬£¬ÒÔ±£»£»£» £»£»£»£»¤ÍøÂçÃâÊܹ¥»÷¡£¡£¡£ ¡£¡£¡£¡£


https://securityaffairs.com/171638/security/u-s-cisa-adds-projectsend-north-grid-proself-and-zyxel-firewalls-bugs-to-its-known-exploited-vulnerabilities-catalog.html


5. DroidBot£ºÐÂÐÍAndroidÒøÐжñÒâÈí¼þÇÔÈ¡¶à¹ú¼ÓÃÜÇ®±Ò¼°ÒøÐÐÆ¾Ö¤


12ÔÂ4ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬DroidBotÊÇÒ»ÖÖÐÂÐÍAndroidÒøÐжñÒâÈí¼þ£¬£¬£¬£¬£¬ £¬£¬£¬×Ô2024Äê6ÔÂÆð»îÔ¾£¬£¬£¬£¬£¬ £¬£¬£¬ÒÔ¶ñÒâÈí¼þ¼´·þÎñ£¨MaaS£©´ó¾ÖÔËÓª£¬£¬£¬£¬£¬ £¬£¬£¬Ã¿ÔÂÊÛ¼Û3000ÃÀÔª¡£¡£¡£ ¡£¡£¡£¡£ËüÊÔͼÇÔȡӢ¹ú¡¢Òâ´óÀû¡¢·¨¹ú¡¢Î÷°àÑÀ¡¢ÆÏÌÑÑÀµÈ¹úµÄ77¶à¸ö¼ÓÃÜÇ®±ÒÂòÂôËùºÍÒøÐÐÀûÓÃµÄÆ¾Ö¤¡£¡£¡£ ¡£¡£¡£¡£Ö»¹ÜÖ°Äܲ¢²»ÐÂÏʸ´ÔÓ£¬£¬£¬£¬£¬ £¬£¬£¬µ«DroidBotÔÚÓ¢¹ú¡¢Òâ´óÀû¡¢·¨¹ú¡¢ÍÁ¶úÆäºÍµÂ¹úÒÑÔì³É776Æð¹ÖÒìϰȾ£¬£¬£¬£¬£¬ £¬£¬£¬ÏÔʾÆä¸ß¶È»îÔ¾¡£¡£¡£ ¡£¡£¡£¡£´Ë¶ñÒâÈí¼þÕý´óÁ¦¿ª·¢ÖУ¬£¬£¬£¬£¬ £¬£¬£¬²¢ÊÔͼÀ©´óÖÁеØÓò£¬£¬£¬£¬£¬ £¬£¬£¬Ô̺¬À­¶¡ÃÀÖÞ¡£¡£¡£ ¡£¡£¡£¡£DroidBotÓÉÍÁ¶úÆä¿ª·¢Õß´´½¨£¬£¬£¬£¬£¬ £¬£¬£¬ÎªÁªÃ˳ÉÔ±Ìṩ¶ñÒâÈí¼þ¹¹½¨Æ÷¡¢ºÅÁîºÍ½ÚÔ죨C2£©·þÎñÆ÷¼°ÖÐÑëÖÎÀíÃæ°åµÈ¹¤¾ß£¬£¬£¬£¬£¬ £¬£¬£¬Ê¹ÍøÂç·¸×ï·Ö×ÓÒ×ÓÚʹÓᣡ£¡£ ¡£¡£¡£¡£Ëü³£¼Ù×°³ÉGoogle Chrome¡¢Google PlayÉ̵ê»òAndroid°²È«ÖÐÐÄ£¬£¬£¬£¬£¬ £¬£¬£¬ÓÕÆ­Óû§×°Ö㬣¬£¬£¬£¬ £¬£¬£¬³äÈÎľÂí½ÇÉ«ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£ÖØÒªÌصãÔ̺¬¼üÅ̼ͼ¡¢¸²¸ÇºÏ·¨ÒøÐÐÀûÓýçÃæÏÔʾÐéαµÇÂ¼Ò³Ãæ¡¢¶ÌÐÅÀ¹½ØºÍVNCÄ£¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£ ¡£¡£¡£¡£Ëü»¹ÀÄÓÃAndroid¸¨ÖúÖ°ÄÜ·þÎñ¼à¿ØÓû§²Ù×÷¡£¡£¡£ ¡£¡£¡£¡£ÎªÁ˼õÇáÍþв£¬£¬£¬£¬£¬ £¬£¬£¬½¨ÒéAndroidÓû§½ö´ÓGoogle PlayÏÂÔØÀûÓ㬣¬£¬£¬£¬ £¬£¬£¬×Ðϸ²é³­È¨ÏÞÒªÇ󣬣¬£¬£¬£¬ £¬£¬£¬²¢È·±£Play Protect´¦Óڻ״̬¡£¡£¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-droidbot-android-malware-targets-77-banking-crypto-apps/


6. BT¼¯ÍÅÔâBlack BastaÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ £¬£¬£¬²¿ÃÅ·þÎñÆ÷ÒѹعØ


12ÔÂ4ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬¿ç¹úµçОÞÍ·BT¼¯ÍÅ£¨Ç°ÉíΪӢ¹úµçÐÅ£©È·ÈÏÆäBT»áÒéÒµÎñ²¿ÃÅÔÚÔâ·êBlack BastaÀÕË÷Èí¼þ¹¥»÷ºó£¬£¬£¬£¬£¬ £¬£¬£¬Òѹعز¿ÃÅ·þÎñÆ÷¡£¡£¡£ ¡£¡£¡£¡£Ö»¹ÜÕâ´Î°²È«ÊÂÎñδӰÏìBT¼¯ÍŵÄÔËÓª»òBT»áÒé·þÎñ£¬£¬£¬£¬£¬ £¬£¬£¬µ«Black BastaÍÅ»ïÐû³ÆÒÑÈëÇָù«Ë¾·þÎñÆ÷²¢ÇÔÈ¡500GBÊý¾Ý£¬£¬£¬£¬£¬ £¬£¬£¬Ô̺¬²ÆÕþ¡¢×éÖ¯¡¢Óû§Êý¾ÝºÍÓ×ÎÒÎĵµµÈ¡£¡£¡£ ¡£¡£¡£¡£¸ÃÍŻﻹÔÚ°µÍøÐ¹ÃÜÍøÕ¾ÉÏÔö³¤Á˵¹¼ÆÊ±£¬£¬£¬£¬£¬ £¬£¬£¬Ðû³Æ½«ÓÚÏÂÖÜй¶¾Ý³Æ±»µÁµÄÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£BT¼¯ÍŰµÊ¾½«³ÖÐø»ý¼«µ÷²é´ËÊ£¬£¬£¬£¬£¬ £¬£¬£¬²¢ÓëÓйػú¹¹ºÏ×÷Ó¦¶Ô¡£¡£¡£ ¡£¡£¡£¡£Black BastaÀÕË÷Èí¼þÐж¯×Ô2022Äê4ÔÂÒÔÀ´ÒÑÔì³ÉºÜ¶à³ÛÃûÊܺ¦Õߣ¬£¬£¬£¬£¬ £¬£¬£¬Ô̺¬Ò½ÁƱ£½¡¹«Ë¾¡¢µ±¾Ö³Ð°üÉ̵È£¬£¬£¬£¬£¬ £¬£¬£¬Æä·ÖÖ§»ú¹¹ÒÑÈëÇÖ500¶à¸ö×éÖ¯£¬£¬£¬£¬£¬ £¬£¬£¬²¢´Ó90¶àÃûÊܺ¦ÕßÊÖÖÐÊÕÈ¡ÖÁÉÙ1ÒÚÃÀÔªµÄÊê½ð¡£¡£¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/bt-conferencing-division-took-servers-offline-after-black-basta-ransomware-attack/