΢ÈíÓ¡¶ÈXÕË»§±» Roaring Kitty ¼ÓÃÜÇ®±ÒȦÌ×Ð®ÖÆ

Ðû²¼Ê±¼ä 2024-06-05
1. ΢ÈíÓ¡¶ÈXÕË»§±» Roaring Kitty ¼ÓÃÜÇ®±ÒȦÌ×Ð®ÖÆ


6ÔÂ3ÈÕ £¬ÓµÓÐÁè¼Ý 211,000 Ãû¹Ø×¢ÕßµÄ΢ÈíÓ¡¶È¹Ù·½ Twitter Õ˺ű»¼ÓÃÜÇ®±ÒÆ­×ÓÐ®ÖÆ £¬²¢Ã°³äÎÛÃûÕÑÖøµÄÄ£Òò¹ÉƱÉúÒâÔ± Keith Gill ʹÓõÄÓû§Ãû Roaring Kitty¡£Î¢ÈíÓ¡¶ÈµÄ X ÕË»§×÷Ϊ¸Ãƽ̨ÉϹٷ½ÈÏÖ¤µÄ×éÖ¯ £¬ÓµÓлƽð֧Ʊ £¬ÕâʹµÃÐ®ÖÆÕßµÄÌû×Ó¸ü¾ßÕýµ±ÐÔ¡£ÍþвÐÐΪÕßʹÓà Gill ×î½üµÄ¸´³öÀ´ÒýÓÕDZÔÚÊܺ¦Õß £¬²¢ÓüÓÃÜÇ®±ÒÇ®°üºÄ¾¡¶ñÒâÈí¼þѬȾËûÃÇ¡£ËûÃÇÏÖÔÚʹÓñ»Ð®ÖƵÄ΢ÈíÓ¡¶ÈÕË»§»Ø¸´ÍÆÎÄ £¬ÓÕÆ­¸Ã¹«Ë¾µÄ¹Ø×¢ÕßºÍ X ÉÏµÄÆäËûÈ˽øÈëÒ»¸ö¶ñÒâÍøÕ¾ (presaIe-roaringkitty[.]com) £¬¾Ý³Æ¸ÃÍøÕ¾ÔÊÐíËûÃǹºÖà GameStop (GME) ¼ÓÃÜÇ®±Ò×÷ΪËùνԤÊÛµÄÒ»²¿·Ö¡£È»¶ø £¬ÍþвÐÐΪÕß»áÇÔÈ¡Èκν«¼ÓÃÜÇ®±ÒÇ®°üÅþÁ¬µ½¸ÃÍøÕ¾²¢ÊÚȨºÄ¾¡·þÎñ¾ÙÐÐÉúÒâµÄÈ˵Ä×ʲú¡£Ðí¶à»úеÈËÕË»§ÏÖÔÚÒ²ÔÚת·¢±»Ð®ÖÆÕË»§µÄÍÆÎÄ £¬ÕâÖÖÕ½ÂÔÖ¼ÔÚÈËΪµØÔöÌí¶ñÒâÌû×ÓµÄÁýÕÖÃæ²¢ÓÕ²¶¸ü¶àÊܺ¦Õß¡£


https://www.bleepingcomputer.com/news/security/microsoft-indias-x-account-hijacked-in-roaring-kitty-crypto-scam-to-push-wallet-drainers/


2. Æ­×ÓÍþвй¶´ÓÅä¾°ÊӲ칫˾ÇÔÈ¡µÄÊýÒÚÌõ¼Í¼


6ÔÂ3ÈÕ £¬¾Ý³Æ £¬·ðÂÞÀï´ïÖÝÒ»¼ÒÈÏÕæÅä¾°ÊÓ²ìºÍÆäËûСÎÒ˽¼ÒÐÅÏ¢ÇëÇóµÄ¹«Ë¾»ñÈ¡ÁËÊýÊ®ÒڷݼͼÈËÃÇСÎÒ˽¼ÒÐÅÏ¢µÄ¼Í¼ £¬ÕâЩ¼Í¼¿ÉÄܺܿì¾Í»á±»Ð¹Â¶µ½ÍøÉÏ¡£Ò»¸ö×Ô³Æ USDoD µÄ·¸·¨ÍÅ»ïÓÚ 4 ÔÂÔÚµØÏÂÂÛ̳ÉÏÒÔ350 ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛ¸ÃÊý¾Ý¿â £¬²¢ÁîÈËÄÑÒÔÖÃÐŵÄÊÇÉù³Æ¸ÃÊý¾Ý¿â°üÀ¨ 29 ÒÚÌõÃÀ¹ú¡¢¼ÓÄôóºÍÓ¢¹ú¹«ÃñµÄ¼Í¼¡£¾ÝÐÅ £¬Ò»Ãû»ò¶àÃû×Ô³Æ SXUL µÄ·¸·¨ÍÅ»ï¶Ô´Ë´ÎËùνµÄÊý¾Ýй¶ÊÂÎñ¸ºÓÐÔðÈÎ £¬ËûÃǽ«Êý¾Ýй¶ÊÂÎñ½»¸øÁ˳䵱ÖÐÐÄÈ赀 USDoD¡£¾Ý³Æ £¬±»µÁÐÅÏ¢°üÀ¨Ð¡ÎÒ˽¼ÒÈ«Ãû¡¢µØµãºÍÖÁÉÙ 30 ÄêǰµÄµØµãÀúÊ·¡¢Éç»áÇå¾²ºÅÂëÒÔ¼°ÈËÃǵÄâïÊÑ¡¢ÐֵܽãÃúÍÇׯÝ £¬ÆäÖÐһЩÈËÒѾ­È¥ÊÀ½ü 20 Äê¡£¾ÝÃÀ¹ú¹ú·À²¿³Æ £¬ÕâЩÐÅÏ¢²¢·Ç´Ó¹«¹²ÈªÔ´×¥È¡µÄ £¬Ö»¹ÜÊý¾Ý¿âÖпÉÄܱ£´æÖظ´µÄÌõÄ¿¡£


https://www.theregister.com/2024/06/03/usdod_data_dump/


3. Telegram ÉÏй¶µÄ 3.61 ÒÚ¸ö±»µÁÕË»§±»Ìí¼Óµ½ HIBP


6ÔÂ3ÈÕ £¬´ó×Ú 3.61 ÒÚ¸öµç×ÓÓʼþµØµã±»Ìí¼Óµ½ Have I Been Pwned Êý¾Ýй¶֪ͨ·þÎñÖÐ £¬ÕâЩµØµãÀ´×Ôͨ¹ýÃÜÂëÇÔÈ¡¶ñÒâÈí¼þ¡¢Æ¾Ö¤Ìî³ä¹¥»÷ºÍÊý¾Ýй¶ÇÔÈ¡µÄƾ֤ £¬ÈκÎÈ˶¼¿ÉÒÔ¼ì²éËûÃǵÄÕÊ»§ÊÇ·ñÒѱ»Ð¹Â¶¡£ÍøÂçÇå¾²Ñо¿Ö°Ô±´ÓÖÚ¶à Telegram ÍøÂç·¸·¨ÆµµÀÍøÂçÁËÕâЩƾ֤ £¬ÕâЩ±»µÁÊý¾Ýͨ³£±»Ð¹Â¶¸øÆµµÀµÄÓû§ÒÔ½¨ÉèÉùÓþºÍ¶©ÔÄÕß¡£±»µÁÊý¾Ýͨ³£ÒÔÓû§ÃûºÍÃÜÂë×éºÏ£¨Í¨³£Í¨¹ýƾ֤Ìî³ä¹¥»÷»òÊý¾Ýй¶ÇÔÈ¡£©¡¢Óû§ÃûºÍÃÜÂëÒÔ¼°ÓëÖ®Ïà¹ØµÄ URL£¨Í¨¹ýÇÔÈ¡ÃÜÂëµÄ¶ñÒâÈí¼þÇÔÈ¡£©ºÍԭʼ cookie£¨Í¨¹ýÇÔÈ¡ÃÜÂëµÄ¶ñÒâÈí¼þÇÔÈ¡£©µÄÐÎʽй¶¡£¸ÃÑо¿Ö°Ô±ÒªÇó BleepingComputer ¼á³ÖÄäÃû £¬ËûÃÇÓë Have I Been Pwned µÄËùÓÐÕß Troy Hunt ·ÖÏíÁË´Ó¶à¸ö Telegram ƵµÀÍøÂçµÄ 122 GB ƾ֤¡£ÕâЩÊý¾ÝºÜÊÇÖØ´ó £¬°üÀ¨ 3.61 ÒÚ¸öΨһµÄµç×ÓÓʼþµØµã £¬ÆäÖÐ 1.51 ÒÚ¸öµØµãÒÔǰ´Óδ±»Êý¾Ýй¶֪ͨ·þÎñ¼û¹ý¡£


https://www.bleepingcomputer.com/news/security/361-million-stolen-accounts-leaked-on-telegram-added-to-hibp/


4. ÍþвÕßÉù³Æ³öÊÛ°üÀ¨1700ÍòÓû§¼Í¼µÄPandabuyÊý¾Ý¿â


6ÔÂ3ÈÕ £¬¾Ý±¨µÀ £¬±»µÁÊý¾Ý¿â°üÀ¨¶à´ï 1700 ÍòÐÐÓû§¼Í¼ £¬º­¸ÇÃû×Ö¡¢ÐÕÊÏ¡¢Óû§ ID¡¢µç×ÓÓʼþ¡¢¶©µ¥Êý¾Ý¡¢IP µØµã¡¢¹ú¼Ò¡¢ÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£ÍþвÕß Sanggiero ÒÑ¾ÍÆäÒâͼ½ÒÏþÉùÃ÷¡£ËûÃÇÉù³Æ £¬ÓÃÓÚÆÆËð Pandabuy ·ÀÓùϵͳµÄÎó²î£¨¾Ý³Æ¸Ã¹«Ë¾ÉÐδ½â¾ö£©½«ºÜ¿ìÔÚÆä²©¿ÍÍøÕ¾ÉÏÐû²¼¡£±ðµÄ £¬ËûÃÇ»¹Ðû²¼ÍýÏëÅû¶ Pandabuy Ô±¹¤µÄÐÕÃûºÍÃÜÂë £¬Ö»¹ÜÊÇÒÔʹÓà base-64 ¼ÓÃܵıàÂëÐÎʽ¡£ÍþвÕßÖÒÑÔ Pandabuy ÈÔÓпÉÄܾÙÐÐ̸ÅÐ £¬µ«Ê±¼äδ¼¸ÁË¡£ËûÃÇΪ±»µÁÊý¾Ý¿â¿ª³öÁË 40,000 ÃÀÔªµÄ¸ß¼Û £¬Åú×¢ËûÃÇ×¼±¸½«ÇÔÈ¡µÄÊý¾ÝÂô¸ø³ö¼Û×î¸ßµÄÈË¡£


https://dailydarkweb.net/threat-actor-claims-to-sell-pandabuy-database-with-17-million-user-records/


5. Discord¶ñÒâÈí¼þ¹¥»÷¼¤Ôö £¬·¢Ã÷50000¸ö¶ñÒâÁ´½Ó


6ÔÂ3ÈÕ £¬ÔÚ×î½üÁù¸öÔÂµÄÆÊÎöÖÐ £¬ÍøÂçÇå¾²¹«Ë¾ Bitdefender ·¢Ã÷ÁËÒ»¸öÁîÈ˵£ÐĵÄÇ÷ÊÆ£ºÍøÂç·¸·¨·Ö×ÓÕýÔÚʹÓÃÊ¢ÐеÄͨѶƽ̨ Discord À´Èö²¥¶ñÒâÈí¼þ²¢Ö´ÐÐÍøÂç´¹ÂÚÔ˶¯¡£Bitdefender ÔÚ 2024 Äê 29 ÈÕÐÇÆÚÈýÐû²¼Ö®Ç°Óë Hackread.com ·ÖÏíÁ˸ñ¨¸æ £¬ÆäÖÐÖØµãÏÈÈÝÁË Discord ÉÏ·¢Ã÷µÄ 50,000 ¶à¸ö¶ñÒâÁ´½Ó £¬ÏÔʾ³ö¸Ãƽ̨ԽÀ´Ô½ÈÝÒ×Êܵ½ÍøÂçÍþв¡£¶ñÒâÈí¼þºÍÍøÂç´¹ÂÚÁ´½ÓÕ¼¼ì²âµ½µÄ¶ñÒâÁ´½ÓµÄ 39%¡£ÕâЩ¹¥»÷ͨ³£Éæ¼°ÓÕÆ­ÊÖ¶Î £¬ÓÕÆ­Óû§ÏÂÔØÓк¦Èí¼þ»òÌṩÃô¸ÐÐÅÏ¢¡£ÃÀ¹úÓû§ÓÈÆäÈÝÒ×Êܵ½¹¥»÷ £¬Õ¼ÍþвµÄ 16.2%¡£ÕâʹËûÃdzÉΪ×îÈÝÒ×Êܵ½¹¥»÷µÄȺÌå £¬²¢ÇÒÕ¼±ÈÏÔÖø¡£Í¨¹ý Discord Ìᳫ¶ñÒâ¹¥»÷µÄÆäËû¹ú¼Ò»¹°üÀ¨·¨¹ú¡¢ÂÞÂíÄáÑÇ¡¢Ó¢¹úºÍµÂ¹ú¡£


https://hackread.com/discord-malware-attacks-as-50000-malicious-links/


6. ÔÆ´æ´¢ Hudson Rock ÆðËßÐÅÏ¢Çå¾²»ú¹¹ Snowflake


6ÔÂ4ÈÕ £¬ÐÅÏ¢Çå¾²»ú¹¹±¨¸æ³Æ £¬·¸·¨·Ö×ÓʹÓÃÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ»ñÈ¡ÁË Snowflake Ô±¹¤µÄÊÂÇ鯾֤ £¬²¢Ê¹ÓøÃÌØÈ¨»á¼ûȨÏÞ´Ó Snowflake µÄ¿Í»§ÔÆÕÊ»§ÖÐÇÔÈ¡ÁË´ó×ÚÊý¾Ý¡£Snowflake ÌåÏÖ £¬ÕâÖÖÇéÐβ¢Ã»Óб¬·¢¡£ÖÁÉÙTicketmasterºÍSantander ÒøÐеÄÐÅϢȷʵ±»µÁÁË £¬Ö»¹Ü¹Ù·½ÉÐδ֪ÏþÏêϸÊÇÔõÑù±»µÁµÄ £¬ÒÔ¼°´ÓÄÇÀï±»µÁµÄ£»ÕâÁ½¼ÒÒøÐж¼ÊÇ Snowflake µÄ¿Í»§¡£¾Ý±¨µÀ £¬Ticketmaster µÄһλýÌå´ú±í¸æËßTechCrunch £¬Æä±»µÁÊý¾ÝÓÉ Snowflake ÍйÜ¡£Snowflake ÌåÏÖ £¬ÈôÊÇÓÐÈκοͻ§Êý¾Ý´ÓÆä·þÎñÆ÷Öб»ÇÔÈ¡ £¬ÄÇôÕâЩÊý¾Ý¿ÉÄÜÊDZ»ÇÔÔôͨ¹ýÓÐÕë¶ÔÐÔµÄÍøÂç´¹ÂÚ¡¢ÆäËûйÃÜ»ò¶ñÒâÈí¼þµÈ·½·¨»ñÈ¡ÁËСÎÒ˽¼Ò¿Í»§µÄÕË»§Æ¾Ö¤¶ø»ñµÃµÄ £¬¶ø²»ÊÇͨ¹ý¶Ô Snowflake Çå¾²ÐÔµÄÆÕ±éÆÆËð¶ø»ñµÃµÄ¡£ÊÂʵÉÏ £¬Snowflake ÒÔΪ £¬Æä¡°ÓÐÏÞ¡±ÊýÄ¿ÉÐδ͸¶ÐÕÃûµÄ¿Í»§µÄÊý¾Ý¿ÉÄÜȷʵ±»ÇÔÈ¡µÄÕË»§Æ¾Ö¤»á¼û £¬¶øÕâЩÕË»§²¢Ã»ÓÐÆôÓÃË«ÒòËØÉí·ÝÑéÖ¤¡£


https://www.theregister.com/2024/06/04/snowflake_report_pulled/