ResolverRAT¶ñÒâÈí¼þ¹¥»÷È«ÇòÖÆÒ©ºÍÒ½ÁƱ£½¡»ú¹¹
Ðû²¼Ê±¼ä 2025-04-161. ResolverRAT¶ñÒâÈí¼þ¹¥»÷È«ÇòÖÆÒ©ºÍÒ½ÁƱ£½¡»ú¹¹
4ÔÂ14ÈÕ£¬£¬£¬¿ËÈÕ£¬£¬£¬Ò»ÖÖÃûΪ¡°ResolverRAT¡±µÄÐÂÐÍÔ¶³Ì»á¼ûľÂí£¨RAT£©ÔÚÈ«Çò¹æÄ£ÄÚËÁŰ£¬£¬£¬³ÉΪ×éÖ¯ÐÅÏ¢Çå¾²µÄÒ»´óÍþв£¬£¬£¬ÓÈÆä¶ÔÒ½ÁƱ£½¡ºÍÖÆÒ©ÐÐÒµ×é³ÉÁËÑÏÖØÌôÕ½¡£¡£¡£ResolverRATͨ¹ýÈ«ÐÄÉè¼ÆµÄÍøÂç´¹ÂÚµç×ÓÓʼþ¾ÙÐÐÈö²¥£¬£¬£¬ÕâЩÓʼþαװ³ÉÕë¶ÔÄ¿µÄ¹ú¼Ò/µØÇøÓïÑÔµÄÕýµ±ÄÚÈÝ»òÉæ¼°°æÈ¨ÇÖÕ¼µÄÖÒÑÔ£¬£¬£¬ÓÕʹÓû§µã»÷Á´½ÓÏÂÔØ¿´ËÆÕýµ±µÄ¿ÉÖ´ÐÐÎļþ¡°hpreader.exe¡±¡£¡£¡£ÏÖʵÉÏ£¬£¬£¬¸ÃÎļþʹÓ÷´ÉäDLL¼ÓÔØÊÖÒÕ£¬£¬£¬½«ResolverRATÇÄÈ»×¢ÈëÄڴ棬£¬£¬ÎªºóÐøµÄ¶ñÒâ»î¶¯ÆÌƽõè¾¶¡£¡£¡£Morphisec¹«Ë¾ÂÊÏÈ·¢Ã÷ÁËÕâһδ±»¼Í¼µÄ¶ñÒâÈí¼þ£¬£¬£¬²¢Ö¸³öCheck PointºÍCisco TalosµÄ½üÆÚ±¨¸æÖÐÒ²Ìá¼°ÁËÏàͬµÄÍøÂç´¹ÂÚ»ù´¡ÉèÊ©£¬£¬£¬µ«Î´Äܲ¶»ñµ½ResolverRATÕâÒ»ÆæÒìÓÐÓÃÔØºÉ¡£¡£¡£ResolverRATÒÔÆä¸ß¶ÈÒþ²ØÐÔºÍǿʢµÄ¹æ±ÜÄÜÁ¦Öø³Æ£¬£¬£¬ÍêÈ«ÔÚÄÚ´æÖÐÔËÐУ¬£¬£¬ÀÄÓÃ.NET¡°ResourceResolve¡±ÊÂÎñ¼ÓÔØ¶ñÒâ³ÌÐò¼¯£¬£¬£¬ÓÐÓùæ±ÜÁ˹ŰåÇå¾²¼à¿Ø¡£¡£¡£¸ÃľÂí½ÓÄÉÖØ´óµÄ״̬»úÊÖÒÕ»ìÏý¿ØÖÆÁ÷£¬£¬£¬Ê¹µÃ¾²Ì¬ÆÊÎö±äµÃÒì³£ÄÑÌ⣬£¬£¬²¢Í¨¹ýÖ¸ÎÆ×ÊÔ´ÇëÇó¼ì²âɳºÐºÍÆÊÎö¹¤¾ß£¬£¬£¬½øÒ»²½ÔöÇ¿ÁËÆäÒþ²ØÐÔ¡£¡£¡£±ðµÄ£¬£¬£¬ResolverRAT»¹¾ß±¸Ç¿Ê¢µÄÊý¾Ýй¶¹¦Ð§£¬£¬£¬Í¨Ì«¹ý¿é»úÖÆ´«Êä´óÊý¾Ý£¬£¬£¬½«´óÓÚ1MBµÄÎļþÖ§½â³É16KBµÄ¿é£¬£¬£¬ÒÔÌӱܼì²â¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-resolverrat-malware-targets-pharma-and-healthcare-orgs-worldwide/
2. ÀÕË÷Èí¼þÈÅÂÒÁËÉö͸Îö¹«Ë¾DaVitaµÄ²¿·ÖÔËÓª
4ÔÂ14ÈÕ£¬£¬£¬Éö͸Îö¾ÞÍ·DaVitaÔâÓöÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬²¿·ÖÔËÓªÊÜÓ°Ïì¡£¡£¡£¸Ã¹«Ë¾ÓÚÖÜÁùÔâÊܹ¥»÷£¬£¬£¬²¿·ÖÍøÂç±»¼ÓÃÜ£¬£¬£¬ÖÜÒ»Ö±ÃÀ¹ú֤ȯÉúÒâίԱ»áת´ï´ËÊ¡£¡£¡£DaVitaÁ¬Ã¦Æô¶¯ÏìÓ¦³ÌÐò£¬£¬£¬ÊµÑé×èÖ¹²½·¥£¬£¬£¬°üÀ¨¸ôÀëÊÜÓ°Ïìϵͳ£¬£¬£¬²¢ÒÑʵÑéÔÝʱ²½·¥ÒÔ»Ö¸´Ä³Ð©¹¦Ð§£¬£¬£¬µ«ÎÞ·¨Ô¤¼ÆÖÐÖ¹µÄÒ»Á¬Ê±¼ä»òˮƽ¡£¡£¡£ÏÖÔÚÅжϴ˴ÎÏ®»÷¶Ô¹«Ë¾Ôì³ÉµÄ×ÜÌåÓ°Ï컹Ϊʱ¹ýÔç¡£¡£¡£DaVita×÷ΪȫÇò×î´óµÄÉöÔàÕչ˻¤Ê¿ÌṩÉÌÖ®Ò»£¬£¬£¬ÔÚÈ«ÇòÓµÓÐ3166¼ÒÃÅÕï͸ÎöÖÐÐÄ£¬£¬£¬Ô¼ÓÐ28.11ÍòÃû»¼Õߣ¬£¬£¬´Ë´Î¹¥»÷¶ÔÆäÔËÓªÔì³ÉÁËÒ»¶¨Ó°Ïì¡£¡£¡£×èÖ¹ÖÜÒ»ÉÏÎ磬£¬£¬ÉÐÎÞÀÕË÷Èí¼þÍÅ»ïÈÏ¿ÉÈÏÕæ¡£¡£¡£ÍøÂçÇ徲ר¼Ò×·×Ùµ½2025ÄêÕë¶ÔÒ½ÁƱ£½¡×éÖ¯µÄ100¶àÆðÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬Ò½ÁƱ£½¡»ú¹¹ÃæÁÙÑÏËàÌôÕ½¡£¡£¡£Î¢ÈíÉϸöÔÂÒ²ÖÒÑԳƣ¬£¬£¬ÀÕË÷Èí¼þ¹¥»÷ÊÇÅ©´åÒ½ÔºÃæÁÙµÄÖ÷ÒªÎÊÌ⣬£¬£¬¿ÉÄÜ´øÀ´Î£¼°ÉúÃüµÄЧ¹û¡£¡£¡£DaVitaÉÐδ»ØÓ¦¹ØÓÚ¹¥»÷×éÖ¯¼°ÊÇ·ñ»áÖ§¸¶Êê½ðµÄÖÃÆÀÇëÇ󡣡£¡£
https://therecord.media/davita-kidney-dialysis-company-ransomware-attack
3. Study HotelsÔâÓöPlayÀÕË÷Èí¼þÍÅ»ïË«ÖØÀÕË÷Íþв
4ÔÂ14ÈÕ£¬£¬£¬Ò»¼ÒÖ÷ҪЧÀÍÓÚ³£´ºÌÙÃËУµÄ¾«Æ·×¡ËÞÆ·ÅÆStudy HotelsÔâÓöÁËÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¸ÃÁ¬ËøÂùÝÔÚҮ³´óѧ¡¢±öϦ·¨ÄáÑÇ´óѧ¡¢Ô¼º²¡¤»ôÆÕ½ð˹´óѧºÍÖ¥¼Ó¸ç´óѧµÈÐ£ÇøÄ±»®ºÀ»ª×¡ËÞ£¬£¬£¬Æä¿Í»§Èº°üÀ¨¿Í×ù½ÌÊÚ¡¢¸ß¾»Öµ¼Ò³¤ºÍ¾Û»á¼ÓÈëÕß¡£¡£¡£´Ë´Î¹¥»÷µÄÄ»ºóºÚÊÖPlayÀÕË÷Èí¼þÍŻ£¬£¬Íþв³ÆÈô²»Ö§¸¶Êê½ð£¬£¬£¬½«Ð¹Â¶Ô±¹¤ÈËΪµ¥¡¢Éí·ÝÖ¤¼þºÍÉñÃØÎļþµÈ¸ß¶ÈÃô¸ÐÊý¾Ý¡£¡£¡£Ð¹ÃÜ֪ͨÓÚ2025Äê4ÔÂ11ÈÕÐû²¼£¬£¬£¬¾àÀëÍþвÕßÉ趨µÄ×îºóÏÞÆÚ½öÊ£Ò»Ìì¡£¡£¡£¸ÃÍÅ»ïÒÑй¶²¿·ÖÊý¾Ý£¬£¬£¬²¢¼ÌÐøÍþв½«ËùÓÐÊý¾Ý¹ûÕæ¡£¡£¡£ÀÕË÷Èí¼þÍÅ»ïͨ³£½«Êܺ¦ÕßÃûµ¥ÁÐÔÚÆä°µÍøÐ¹ÃÜÍøÕ¾ÉÏ£¬£¬£¬ÒÔ´ËÆÈʹ×éÖ¯Ö§¸¶Êê½ð¡£¡£¡£ËûÃǽÓÄÉË«ÖØÀÕË÷ģʽ£¬£¬£¬ÔÚÇÔÈ¡Êý¾Ýºó¼ÓÃÜϵͳ£¬£¬£¬²¢ÒÑÓ°Ïìµ½ÆÕ±éµÄÆóÒµºÍÒªº¦»ù´¡ÉèÊ©¡£¡£¡£ÏÖÔÚÉв»ÇåÎúStudy HotelsÊÇ·ñÒѶԴ˴ÎÍþв×ö³ö»ØÓ¦¡£¡£¡£
https://cybernews.com/security/yale-university-hotel-chain-ransomware-attack/
4. APT29ʹÓÃGrapeLoaderÓëWineLoader±äÖÖ¹¥»÷Å·ÖÞÍâ½»ÍøÂç
4ÔÂ15ÈÕ£¬£¬£¬¶íÂÞ˹Õþ¸®Ö§³ÖµÄÌØ¹¤×éÖ¯ÎçÒ¹±©Ñ©£¨Midnight Blizzard£¬£¬£¬ÓÖÃû¡°Cozy Bear¡±»ò¡°APT29¡±£©ÌᳫÁËÒ»ÏîÕë¶ÔÅ·ÖÞÍ⽻ʵÌ壨°üÀ¨´óʹ¹Ý£©µÄÐÂÓã²æÊ½ÍøÂç´¹Âڻ¡£¡£¡£´Ë´Î»î¶¯ÓÚ2025Äê1ÔÂÆô¶¯£¬£¬£¬Í¨¹ýαװ³ÉÍâ½»²¿µÄµç×ÓÓʼþ£¬£¬£¬ÓÕµ¼ÊÕ¼þÈ˵ã»÷¶ñÒâÁ´½Ó£¬£¬£¬ÏÂÔØ°üÀ¨GrapeLoader¶ñÒâÈí¼þ¼ÓÔØÆ÷ºÍWineLoaderºóÃÅбäÖÖµÄZIPѹËõ°ü¡£¡£¡£GrapeLoaderͨ¹ýDLL²à¼ÓÔØÖ´ÐУ¬£¬£¬ÍøÂçÖ÷»úÐÅÏ¢£¬£¬£¬½¨É賤ÆÚÐÔ£¬£¬£¬²¢ÁªÏµÏÂÁîÓë¿ØÖÆ£¨C2£©Ð§ÀÍÆ÷ÎüÊÕshellcode¡£¡£¡£¸Ã¼ÓÔØÆ÷Ö¼ÔÚÈ¡´ú֮ǰʹÓõĵÚÒ»½×¶ÎHTA×°ÔØ»ú¡°RootSaw¡±£¬£¬£¬ÒòÆäÔ½·¢Òþ²ØºÍÖØ´ó¡£¡£¡£GrapeLoaderʹÓá°PAGE_NOACCESS¡±ÄÚ´æ±£»£»£»£»¤ºÍ10ÃëÑÓ³ÙÊÖÒÕ£¬£¬£¬Í¨¹ý¡°ResumeThread¡±ÔËÐÐshellcode£¬£¬£¬ÒÔ¹æ±Ü·À²¡¶¾ºÍEDRɨÃè¡£¡£¡£WineLoader×÷Ϊģ¿£¿£¿é»¯ºóÃÅ£¬£¬£¬ÈÏÕæÍøÂçÏêϸµÄÖ÷»úÐÅÏ¢£¬£¬£¬°üÀ¨IPµØµã¡¢ÔËÐÐÀú³ÌÃû³Æ¡¢WindowsÓû§ÃûµÈ£¬£¬£¬ÒÔÔö½øÌع¤»î¶¯¡£¡£¡£Ð±äÌå½ÓÄÉRVA¸´ÖÆ¡¢µ¼³ö±í²»Æ¥ÅäºÍÀ¬»øÖ¸Áî¾ÙÐÐÑÏÖØ»ìÏý£¬£¬£¬Ìá¸ßÁËÄæÏò¹¤³ÌÄѶȡ£¡£¡£
https://www.bleepingcomputer.com/news/security/midnight-blizzard-deploys-new-grapeloader-malware-in-embassy-phishing/
5. 4chanÂÛ̳ÒÉÔâSoyjak.partyºÚ¿Í¹¥»÷¶ø±»¹Ø±Õ
4ÔÂ15ÈÕ£¬£¬£¬×ÅÃûÔÚÏßÂÛ̳4chanÒÉËÆÔâÊÜÑÏÖØºÚ¿Í¹¥»÷¶øÏÂÏߣ¬£¬£¬ÒÔºó¼ÓÔØ¶Ï¶ÏÐøÐø¡£¡£¡£Ëæºó£¬£¬£¬Soyjak.partyͼƬÂÛ̳³ÉÔ±Éù³ÆÊǴ˴ι¥»÷µÄÄ»ºóºÚÊÖ£¬£¬£¬²¢Ð¹Â¶ÁËÖÎÀíÃæ°å½ØÍ¼¼°Ò»·Ý¾Ý³ÆÊôÓÚ4chanÖÎÀíÔ±¡¢°æÖ÷µÄµç×ÓÓʼþÁÐ±í¡£¡£¡£Ò»ÃûºÚ¿Í£¨Óû§ÃûΪChud£©ÔÚ4chan¹Ø±Õºó·¢Ìû³Æ£¬£¬£¬ºÚ¿ÍÒÑDZÈë4chanϵͳһÄê¶à£¬£¬£¬Ö´ÐÐÁ˹¥»÷Ðж¯£¬£¬£¬Ð¹Â¶ÁËÔ±¹¤Ð¡ÎÒ˽¼ÒÐÅÏ¢ºÍÍøÕ¾´úÂë¡£¡£¡£Îª¿ØÖÆËðʧ£¬£¬£¬4chanÖÎÀíÔ±Òѽ«ËùÓÐЧÀÍÆ÷ÏÂÏߣ¬£¬£¬µ«Óб¨¸æ³ÆÐ§ÀÍÆ÷Òѱ»ÍêÈ«¹¥ÆÆ£¬£¬£¬¿ÉÄÜÎÞ·¨Ñ¸ËÙ»Ö¸´¡£¡£¡£Chud·ÖÏíµÄ½ØÍ¼ÏÔʾ£¬£¬£¬ºÚ¿Í¿É»á¼û4chanµÄÔ±¹¤ÖÎÀíÃæ°åºÍά»¤¹¤¾ß£¬£¬£¬ÕâЩ¹¤¾ß¹¦Ð§Ç¿Ê¢£¬£¬£¬¿É»á¼ûÓû§Î»ÖúÍIPµØµã¡¢ÖØÐÞ»òÖØÐÂÆô¶¯°å¿é¡¢Éó²éÈÕÖ¾ºÍÕ¾µãͳ¼ÆÐÅÏ¢ÒÔ¼°ÖÎÀíÊý¾Ý¿â¡£¡£¡£ËäÈ»¹¥»÷Õßδ͸¶ÈëÇÖ·½·¨£¬£¬£¬µ«ÓÐÈËÒÔΪ£¬£¬£¬Õâ¿ÉÄÜÊÇÓÉÓÚ4chanʹÓÃÁËÑÏÖØ¹ýʱµÄPHP°æ±¾£¬£¬£¬Î´ÐÞ²¹Ðí¶àÇå¾²Îó²î¡£¡£¡£µ±ÌìÍíЩʱ¼ä£¬£¬£¬4chanµÄPHPÔ´´úÂëÔÚÄäÃûÂÛ̳Kiwi FarmsÉϱ»Ð¹Â¶¡£¡£¡£4chan×Ô2003Ä꽨ÉèÒÔÀ´£¬£¬£¬ÒÑÉÏÏß¶þÊ®¶àÄ꣬£¬£¬¶àÄêÀ´Ò»Ö±±»ÓÃÀ´Ð¹Â¶¾Ý³Æ´Ó¶à¼Ò×ÅÃû¹«Ë¾ÇÔÈ¡µÄÎļþ¡£¡£¡£
https://www.bleepingcomputer.com/news/security/infamous-message-board-4chan-taken-down-following-major-hack/
6. Lemonade°ü¹Ü¹«Ë¾×ª´ï19ÍòÓû§¼ÝÕÕºÅй¶ÊÂÎñ
4ÔÂ15ÈÕ£¬£¬£¬Lemonade½¨ÉèÓÚ2015Ä꣬£¬£¬×Գơ°È«Õ»°ü¹Ü¹«Ë¾¡±£¬£¬£¬ÔÚÃÀ¹úºÍÅ·ÖÞÌṩ×â·¿¡¢·¿¶«¡¢Æû³µ¡¢³èÎï¼°ÈËÊÙ°ü¹Ü²úÆ·¡£¡£¡£¸Ã¹«Ë¾ÒÔʹÓÃÈ˹¤ÖÇÄÜÊÖÒÕ¼¤»î±£µ¥¼°´¦Öóͷ£Ë÷Åâ¶øÖøÃû¡£¡£¡£¸Ã¹«Ë¾¿ËÈÕ֪ͨԼ19ÍòÃû¿Í»§£¬£¬£¬Æä¼ÝÕÕºÅÂë¿ÉÄÜÒòÊÖÒÕ¹ÊÕÏÔâй¶¡£¡£¡£¸ÃÊÂÎñÉæ¼°Ò»¿îÔÚÏ߯û³µ°ü¹ÜÓ¦Ó㬣¬£¬¸ÃÓ¦ÓÃÔÊÐíÓû§»ñÈ¡°ü¹Ü±¨¼Û¼°¹ºÖñ£µ¥¡£¡£¡£¾Ý¹«Ë¾Åû¶£¬£¬£¬Æû³µ°ü¹Ü±¨¼ÛÁ÷³ÌÖб£´æÇå¾²Îó²î£¬£¬£¬µ¼Ö²¿·ÖÓû§µÄ¼ÝÕÕºÅÂë̻¶¡£¡£¡£LemonadeÌåÏÖÒÑÐÞ¸´´ËÎó²î¡£¡£¡£ÔÚ2023Äê4ÔÂÖÁ2024Äê9ÔÂʱ´ú£¬£¬£¬¸ÃÆ½Ì¨ÔøÒÔδ¼ÓÃÜ·½·¨´«ÊäÐÅÏ¢£¬£¬£¬ÖÂʹ¼ÝʻִÕÕºÅÂëÃæÁÙδ¾ÊÚȨµÄ»á¼ûΣº¦¡£¡£¡£¹«Ë¾Ë䳯ÎÞÖ¤¾ÝÅú×¢¼ÝÕÕºÅÂë±»µÁÓ㬣¬£¬µ«ÎªÔ¤·ÀDZÔÚΣº¦£¬£¬£¬ÒÑÏòÊÜÓ°Ïì¸öÌå·¢³ö֪ͨ£¬£¬£¬²¢Ìṩ12¸öÔÂÃâ·ÑÐÅÓÃ¼à¿Ø¼°Éí·Ý±£»£»£»£»¤Ð§ÀÍ¡£¡£¡£LemonadeÒÑÏòÃÀ¹ú֤ȯÉúÒâίԱ»á±¨¸æ£¬£¬£¬´Ë´ÎʹÊÓ°ÏìÔ¼19ÍòÈË¡£¡£¡£¹«Ë¾Ç¿µ÷£¬£¬£¬Æ¾Ö¤Ä¿½ñÕÆÎÕµÄÊÂʵÓëÇéÐΣ¬£¬£¬´Ë´ÎÊÂÎñδӰÏìÆäÔËÓª£¬£¬£¬¿Í»§Êý¾ÝÒàδÔâ¹¥»÷£¬£¬£¬ÇÒ¹«Ë¾ÅжϸÃÊÂÎñ²»×é³ÉÖØ´óΣº¦¡£¡£¡£
https://www.securityweek.com/insurance-firm-lemonade-says-api-glitch-exposed-some-drivers-license-numbers/