Lazarus ºÚ¿ÍÀûÓà Windows 0-Day »ñÈ¡ÄÚºËȨÏÞ

°ä²¼¹¦·ò 2024-03-01
1. Lazarus ºÚ¿ÍÀûÓà Windows 0-Day »ñÈ¡ÄÚºËȨÏÞ


2ÔÂ29ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬³ÛÃûµÄÍøÂç·¸×ï×éÖ¯ Lazarus Group ×î½üÀûÓà Windows ÖеÄÁãÈÕ·ì϶»ñÈ¡ÄÚºËȨÏÞ£¬£¬£¬£¬£¬ £¬£¬£¬ÕâÊÇϵͳ½Ó¼ûµÄ¹Ø¼ü¼¶±ð¡£¡£¡£¡£¡£¸Ã·ì϶±»¼ø±ðΪ CVE-2024-21338£¬£¬£¬£¬£¬ £¬£¬£¬ÊÇÔÚ appid.Sys AppLocker Çý¶¯·¨Ê½Öз¢Ïֵ쬣¬£¬£¬£¬ £¬£¬£¬Î¢ÈíÆ¾¾Ý Avast Threat Labs µÄ»ã±¨ÔÚÖÙ´º²¹¶¡ÐÇÆÚ¶þ¸üÐÂÖн¨¸´Á˸÷ì϶¡£¡£¡£¡£¡£¸Ã·ì϶ÔÊÐí Lazarus Group ³ÉÁ¢Äں˶Á/дԭÓ£¬£¬£¬£¬ £¬£¬£¬ÕâÊǰѳֲÙ×÷ϵͳÄÚºËÄÚ´æµÄ¸ù»ùÖ°ÄÜ¡£¡£¡£¡£¡£´ËÖ°ÄÜÓÃÓÚ¸üÐÂËûÃÇµÄ FudModule rootkit£¬£¬£¬£¬£¬ £¬£¬£¬¼ÓÇ¿ÆäÖ°ÄܺÍÒñ±ÎÐÔ¡£¡£¡£¡£¡£Rootkit ´Ë¿ÌÔ̺¬ÓÃÓÚ²Ù×÷¾ä±ú±íÌõ¿î±êм¼Êõ£¬£¬£¬£¬£¬ £¬£¬£¬ÕâЩ¼¼Êõ¿ÉÄÜ»á×ÌÈÅÊÜ Microsoft Protected Process Light (PPL) ±£»£»£»£»£»¤µÄ¹ý³Ì£¬£¬£¬£¬£¬ £¬£¬£¬ÀýÈçÊôÓÚ Microsoft Defender¡¢CrowdStrike Falcon ºÍ HitmanPro µÄ¹ý³Ì¡£¡£¡£¡£¡£CVE-2024-21338ÊÇ Windows Çý¶¯·¨Ê½Öз¢Ïֵķì϶µÄÃû³Æ¡£¡£¡£¡£¡£¶ÔÓÚºÚ¿ÍÀ´Ëµ£¬£¬£¬£¬£¬ £¬£¬£¬ËüÊÇÒ»¸öºÜºÃµÄÖ¸±ê£¬£¬£¬£¬£¬ £¬£¬£¬ÓÉÓÚËüºÜÈÝÒ×ÓÃÓÚ¹¥»÷£¬£¬£¬£¬£¬ £¬£¬£¬²¢ÇÒËüÊÇϵͳµÄÒ»²¿ÃÅ£¬£¬£¬£¬£¬ £¬£¬£¬Òò¶øËûÃDz»±ØÒªÔö³¤ÈκÎÄܹ»¼ì²âµ½µÄÐÂÄÚÈÝ¡£¡£¡£¡£¡£


https://gbhackers.com/lazarus-hackers-exploited-windows-0-day/


2. ÔìÒ©¾ÞÍ· Cencora »ã±¨³ÆÆäÔâµ½ÍøÂç¹¥»÷


2ÔÂ28ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬Cencora, Inc.£¨ÒÔϼò³Æ¡°¹«Ë¾¡±£©»ñϤÆäÐÅϢϵͳÖеÄÊý¾ÝÒѱ»Ð¹Â¶£¬£¬£¬£¬£¬ £¬£¬£¬ÆäÖв¿ÃÅÊý¾Ý¿ÉÄÜÔ̺¬Ó×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£ÔÚ³õ²½·¢ÏÖδ¾­ÊÚȨµÄ¹¥»÷»î¶¯ºó£¬£¬£¬£¬£¬ £¬£¬£¬¹«Ë¾Á¢¼´²ÉÈ¡¶ôÔì´ëÊ©£¬£¬£¬£¬£¬ £¬£¬£¬²¢ÔÚ·¨Âɲ¿ÃÅ¡¢ÍøÂ簲ȫר¼ÒºÍ±í²¿ÕÕ·÷µÄЭÖúÏÂÆðÍ·µ÷²é¡£¡£¡£¡£¡£½ØÖÁ±¾²¼¸æ°ä²¼Ö®ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬¸ÃÊÂÎñÉÐδ¶Ô¹«Ë¾ÔËÓª²úÉú³Á´óÓ°Ï죬£¬£¬£¬£¬ £¬£¬£¬ÆäÐÅϢϵͳÈÔÔÚÔËÐС£¡£¡£¡£¡£¹«Ë¾ÉÐδȷ¶¨¸ÃÊÂÎñÊÇ·ñºÏÀí¿ÉÄܶԹ«Ë¾µÄ²ÆÕþÇé¿ö»ò¾­½»Ò×¼¨²úÉú³Á´óÓ°Ïì¡£¡£¡£¡£¡£¾ÝThe Record±¨Â·£¬£¬£¬£¬£¬ £¬£¬£¬Cencora ÒÔǰ³ÆÎª AmerisourceBergen¡£¡£¡£¡£¡£AmerisourceBergen ¹«Ë¾Ëƺõ¾­ÀúÁË Lorenz ÀÕË÷Èí¼þ×éÖ¯ÓÚ 2023 Äê 1 ÔÂÐû³ÆµÄÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ £¬£¬£¬²¢ÇÒËÆºõÓ°ÏìÁË MWI Animal Health¡£¡£¡£¡£¡£DataBreaches Éв»Ã÷ÏÔ 2022 ÄêÁäÎñÓë×î½üµÄ»ã±¨Ö®¼äÊÇ·ñÓÐÈκÎÁªÏµ¡£¡£¡£¡£¡£


https://www.databreaches.net/pharmaceutical-giant-cencora-reports-cyberattack/


3. Rhysida ÀÕË÷ÍŻ﹥»÷Lurie²¢ÀÕË÷ 360 ÍòÃÀÔª


2ÔÂ28ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬Rhysida ÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶Ô±¾Ô³õÕë¶ÔÖ¥¼Ó¸ç¬Àï¶ùͯҽԺµÄÍøÂç¹¥»÷ÕÆ¹Ü¡£¡£¡£¡£¡£Lurie ÊÇÃÀ¹úµ±ÏȵĶù¿Æ¼±Ö¢»¤Àí»ú¹¹£¬£¬£¬£¬£¬ £¬£¬£¬Ã¿ÄêΪ³¬¹ý 200,000 Ãû¶ùͯÌṩ»¤Àí¡£¡£¡£¡£¡£ÍøÂç¹¥»÷ÆÈʹҽÁƱ£½¡ÌṩÉÌ¹Ø¹ØÆä IT ϵͳ£¬£¬£¬£¬£¬ £¬£¬£¬²¢ÔÚijЩÇé¿öÏÂÍÆ³ÙÒ½ÁÆ»¤Àí¡£¡£¡£¡£¡£µç×ÓÓʼþ¡¢µç»°¡¢MyChart ½Ó¼ûºÍ±¾µØ»¥ÁªÍø¾ùÊܵ½Ó°Ïì¡£¡£¡£¡£¡£³¬Éù²¨ºÍ CT ɨÃèÁ˾ÖÎÞ·¨»ñµÃ£¬£¬£¬£¬£¬ £¬£¬£¬»¼Õß·þÎñÓÅÏÈϵͳ±»È¡µÞ£¬£¬£¬£¬£¬ £¬£¬£¬Ò½Éú±»ÆÈ¸ÄÓñʺÍÖ½¿ª´¦·½¡£¡£¡£¡£¡£Rhysida ÀÕË÷Èí¼þÍÅ»ïÒѽ« Lurie Children¡¯s Ò½ÔºÁÐÈëÆä°µÍøÉϵÄÀÕË÷ÃÅ»§ÍøÕ¾£¬£¬£¬£¬£¬ £¬£¬£¬Ðû³Æ´Ó¸ÃÒ½ÔºÇÔÈ¡ÁË 600 GB µÄÊý¾Ý¡£¡£¡£¡£¡£Æ¾¾ÝLurie Children's ÓÚ 2024 Äê 2 Ô 22 ÈÕ°ä²¼µÄ×îÐÂ״̬¸üУ¬£¬£¬£¬£¬ £¬£¬£¬¸´Ô­ IT ϵͳµÄ¹¤×÷ÔÚ½øÐÐÖУ¬£¬£¬£¬£¬ £¬£¬£¬·þÎñÖжÏÒÀȻӰÏìһЩÔËÓª²¿ÃÅ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/rhysida-ransomware-wants-36-million-for-childrens-stolen-data/


4. Anycubic 3D´òÓ¡»úÔÚÈ«ÇòÁìÓòÄÚÔâµ½ºÚ¿Í¹¥»÷


2ÔÂ28ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬Æ¾¾Ý Anycubic ¿Í»§µÄÒ»²¨ÔÚÏ߻㱨£¬£¬£¬£¬£¬ £¬£¬£¬ÓÐÈËÈëÇÖÁËËûÃÇµÄ 3D ´òÓ¡»ú£¬£¬£¬£¬£¬ £¬£¬£¬²¢ÖÒ¸æÕâЩÉè±¸Ãæ¶Ô¹¥»÷¡£¡£¡£¡£¡£´ËÊÂÎñ±³ºóµÄÈËÔÚÆäÉ豸ÖÐÔö³¤ÁË hacked_machine_readme.gcode Îļþ£¨¸ÃÎļþͨ³£Ô̺¬ 3D ´òÓ¡Ö¸Á£¬£¬£¬£¬£¬ £¬£¬£¬ÌáÐÑÊÜÓ°ÏìµÄÓû§ËûÃǵĴòÓ¡»úÊܵ½ÑϳÁ°²È«ÃýÎóµÄÓ°Ïì¡£¡£¡£¡£¡£¾Ý³Æ£¬£¬£¬£¬£¬ £¬£¬£¬´Ë·ì϶ʹDZÔÚ¹¥»÷Õß¿ÉÄÜʹÓøù«Ë¾µÄ MQTT ·þÎñ API ½ÚÔìÈκÎÊÜ´Ë·ì϶ӰÏìµÄ Anycubic 3D ´òÓ¡»ú¡£¡£¡£¡£¡£ÊÜÓ°ÏìÉ豸ÊÕµ½µÄÎļþ»¹ÒªÇó Anycubic ¿ªÔ´Æä 3D ´òÓ¡»ú£¬£¬£¬£¬£¬ £¬£¬£¬ÔÚÓû§»ã±¨ 3D ´òÓ¡»úÏÔʾ¡°±»ºÚ¡±ÐÂÎÅÆðÍ·³öÏֺ󣬣¬£¬£¬£¬ £¬£¬£¬ AnycubicÀûÓ÷¨Ê½Ò²ÖÕ³¡Á˹¤×÷¡£¡£¡£¡£¡£ÕýÈçTechCrunch³õ´Î±¨Â·µÄÄÇÑù£¬£¬£¬£¬£¬ £¬£¬£¬³¢ÊԵǼµÄÓû§»á¿´µ½¡°ÍøÂç²»³ÉÓá±ÃýÎóÐÂÎÅ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/anycubic-3d-printers-hacked-worldwide-to-expose-security-flaw/


5. ÓëÒÁÀÊÓÐ¹ØµÄ UNC1549 ºÚ¿Í¶Ô×¼Öж«º½¿Õº½ÌìºÍ¹ú·À²¿ÃÅ


2ÔÂ28ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬¹È¸èÆìÏ嵀 Mandiant ÔÚÒ»·ÝзÖÎöÖаµÊ¾£¬£¬£¬£¬£¬ £¬£¬£¬ÍøÂç¼äµý»î¶¯µÄÆäËûÖ¸±ê¿ÉÄÜÔ̺¬ÍÁ¶úÆä¡¢Ó¡¶ÈºÍ°¢¶û°ÍÄáÑÇ¡£¡£¡£¡£¡£ÕâЩ¹¥»÷±ØÒªÊ¹Óà Microsoft Azure ÔÆ»ù´¡ÉèÊ©½øÐкÅÁîÓë½ÚÔì (C2) ºÍÉæ¼°Ó빤×÷ÓйصÄÒýÓÕµÄÉç»á¹¤³Ì£¬£¬£¬£¬£¬ £¬£¬£¬ÒÔÌṩÁ½¸öÃûΪ MINIBIKE ºÍ MINIBUS µÄºóÃÅ¡£¡£¡£¡£¡£Óã²æÊ½ÍøÂç´¹µöµç×ÓÓʼþÖ¼ÔÚ´«²¼Ô̺¬ÒÔÉ«ÁйþÂí˹ÓйØÄÚÈÝ»òÐéα¹¤×÷»úÓöµÄÐéÎ±ÍøÕ¾Á´½Ó£¬£¬£¬£¬£¬ £¬£¬£¬´Ó¶øµ¼Ö²¿Êð¶ñÒâ¸ºÔØ¡£¡£¡£¡£¡£»£»£»£»£»¹¹Û²ìµ½·ÂÕÕ´ó¹«Ë¾µÄÐéαµÇÂ¼Ò³ÃæÒÔ»ñȡʹ´¦¡£¡£¡£¡£¡£×Ô½ç˵ºóÃÅÔÚ³ÉÁ¢ C2 ½Ó¼ûºó£¬£¬£¬£¬£¬ £¬£¬£¬³äÈεý±¨ÍøÂçºÍ½øÒ»²½½Ó¼ûÖ¸±êÍøÂçµÄÇþ·¡£¡£¡£¡£¡£´Ë½×¶Î²¿ÊðµÄÁíÒ»¸ö¹¤¾ßÊÇÃûΪ LIGHTRAIL µÄËí·Èí¼þ£¬£¬£¬£¬£¬ £¬£¬£¬ËüʹÓà Azure ÔÆ½øÐÐͨѶ¡£¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯Öв¿ÊðµÄ¶ã±Ü²½Ö裬£¬£¬£¬£¬ £¬£¬£¬¼´Á¿Éí¶¨ÔìµÄÒÔ¹¤×÷ΪÖ÷ÌâµÄµö¶üÓë C2 ÔÆ»ù´¡ÉèÊ©µÄʹÓÃÏà½áºÏ£¬£¬£¬£¬£¬ £¬£¬£¬¿ÉÄÜ»áÈÃÍøÂç·ÀÓùÕßÄÑÒÔÔ¤·À¡¢¼ì²âºÍ¼õÇáÕâÖֻ¡£¡£¡£¡£¡£


https://thehackernews.com/2024/02/iran-linked-unc1549-hackers-target.html


6. ÀÕË÷Èí¼þÍÅ»ïÐû³ÆÇÔÈ¡½ü 200GB µÄ Epic Games ÄÚ²¿Êý¾Ý


2ÔÂ28ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬¾Ý±¨Â·£¬£¬£¬£¬£¬ £¬£¬£¬¸ÃÍÅ»ïÃûΪ Mogilevich£¬£¬£¬£¬£¬ £¬£¬£¬ÔÚÆä°µÍøÐ¹ÃÜÍøÕ¾Éϰ䲼ÁËÒ»ÌõÐÂÎÅ£¬£¬£¬£¬£¬ £¬£¬£¬ÌṩÁËÓÐ¹ØÆäÐû³ÆµÄ¡¶µï±¤Ö®Ò¹¡·ºÍEpic Games Store¹«Ë¾Ð¹ÃÜÊÂÎñµÄ¸ü¶àÐÅÏ¢¡£¡£¡£¡£¡£»£»£»£»£»¹Ðû³ÆÒѾ­Ð¹Â¶ÁË¡°µç×ÓÓʼþ¡¢ÃÜÂ롢ȫÃû¡¢¸¶¿îÐÅÏ¢¡¢Ô´´úÂëºÍºÜ¶àÆäËûÊý¾Ý¡±£¬£¬£¬£¬£¬ £¬£¬£¬×Ü´óÓ×´ïµ½ 189GB¡£¡£¡£¡£¡£»£»£»£»£»¹Ëµ£º¡°Êý¾ÝÒ²Äܹ»ÏúÊÛ¡±£¬£¬£¬£¬£¬ £¬£¬£¬²¢Îª¡°¹«Ë¾Ô±¹¤»òÏëÒª²É°ìÊý¾ÝµÄÈË¡±Ôö³¤ÁËÁ´½Ó¡£¡£¡£¡£¡£¸ÃÍŻﻮ¶¨ÁË 3 Ô 4 ÈÕΪ²É°ìÊý¾ÝµÄ×îºóÆÚÏÞ£¬£¬£¬£¬£¬ £¬£¬£¬µ«Ã»Óиø³ö¾ßÌåÊý×Ö£¬£¬£¬£¬£¬ £¬£¬£¬Ò²Ã»ÓÐÅú×¢ÈôÊǽØÖ¹ÈÕÆÚ¹ýºó½«ÈôºÎ´¦ÖÃÕâЩÊý¾Ý¡£¡£¡£¡£¡£Mogilevich ÊÇÒ»¸öÏà¶Ô½ÏеÄÀÕË÷Èí¼þ×éÖ¯£¬£¬£¬£¬£¬ £¬£¬£¬Epic Games ÊÇÆäµÚËĸöÖ¸±ê¡£¡£¡£¡£¡£µÚÒ»¸öÊÇÈÕ²ú×Ó¹«Ë¾Ó¢·ÆÄáµÏÃÀ¹ú¹«Ë¾£¬£¬£¬£¬£¬ £¬£¬£¬¸Ã¹«Ë¾ÉÏÖÜÔâµ½ºÚ¿Í¹¥»÷¡£¡£¡£¡£¡£


https://www.videogameschronicle.com/news/a-ransomware-gang-claims-to-have-hacked-nearly-200gb-of-epic-games-internal-data/