΢ÈíÓ¡¶ÈXÕË»§±» Roaring Kitty ¼ÓÃÜÇ®±ÒȦÌ×ЮÖÆ

Ðû²¼Ê±¼ä 2024-06-05
1. ΢ÈíÓ¡¶ÈXÕË»§±» Roaring Kitty ¼ÓÃÜÇ®±ÒȦÌ×ЮÖÆ


6ÔÂ3ÈÕ£¬ÓµÓÐÁè¼Ý 211,000 Ãû¹Ø×¢ÕßµÄ΢ÈíÓ¡¶È¹Ù·½ Twitter Õ˺ű»¼ÓÃÜÇ®±ÒÆ­×ÓЮÖÆ£¬²¢Ã°³äÎÛÃûÕÑÖøµÄÄ£Òò¹ÉƱÉúÒâÔ± Keith Gill ʹÓõÄÓû§Ãû Roaring Kitty¡£Î¢ÈíÓ¡¶ÈµÄ X ÕË»§×÷Ϊ¸Ãƽ̨ÉϹٷ½ÈÏÖ¤µÄ×éÖ¯£¬ÓµÓлƽð֧Ʊ£¬ÕâʹµÃЮÖÆÕßµÄÌû×Ó¸ü¾ßÕýµ±ÐÔ¡£ÍþвÐÐΪÕßʹÓà Gill ×î½üµÄ¸´³öÀ´ÒýÓÕDZÔÚÊܺ¦Õߣ¬²¢ÓüÓÃÜÇ®±ÒÇ®°üºÄ¾¡¶ñÒâÈí¼þѬȾËûÃÇ¡£ËûÃÇÏÖÔÚʹÓñ»Ð®ÖƵÄ΢ÈíÓ¡¶ÈÕË»§»Ø¸´ÍÆÎÄ£¬ÓÕÆ­¸Ã¹«Ë¾µÄ¹Ø×¢ÕßºÍ X ÉϵÄÆäËûÈ˽øÈëÒ»¸ö¶ñÒâÍøÕ¾ (presaIe-roaringkitty[.]com)£¬¾Ý³Æ¸ÃÍøÕ¾ÔÊÐíËûÃǹºÖà GameStop (GME) ¼ÓÃÜÇ®±Ò×÷ΪËùνԤÊÛµÄÒ»²¿·Ö¡£È»¶ø£¬ÍþвÐÐΪÕß»áÇÔÈ¡Èκν«¼ÓÃÜÇ®±ÒÇ®°üÅþÁ¬µ½¸ÃÍøÕ¾²¢ÊÚȨºÄ¾¡·þÎñ¾ÙÐÐÉúÒâµÄÈ˵Ä×ʲú¡£Ðí¶à»úеÈËÕË»§ÏÖÔÚÒ²ÔÚת·¢±»Ð®ÖÆÕË»§µÄÍÆÎÄ£¬ÕâÖÖÕ½ÂÔÖ¼ÔÚÈËΪµØÔöÌí¶ñÒâÌû×ÓµÄÁýÕÖÃæ²¢ÓÕ²¶¸ü¶àÊܺ¦Õß¡£


https://www.bleepingcomputer.com/news/security/microsoft-indias-x-account-hijacked-in-roaring-kitty-crypto-scam-to-push-wallet-drainers/


2. Æ­×ÓÍþвй¶´ÓÅä¾°ÊӲ칫˾ÇÔÈ¡µÄÊýÒÚÌõ¼Í¼


6ÔÂ3ÈÕ£¬¾Ý³Æ£¬·ðÂÞÀï´ïÖÝÒ»¼ÒÈÏÕæÅä¾°ÊÓ²ìºÍÆäËûСÎÒ˽¼ÒÐÅÏ¢ÇëÇóµÄ¹«Ë¾»ñÈ¡ÁËÊýÊ®ÒڷݼͼÈËÃÇСÎÒ˽¼ÒÐÅÏ¢µÄ¼Í¼£¬ÕâЩ¼Í¼¿ÉÄܺܿì¾Í»á±»Ð¹Â¶µ½ÍøÉÏ¡£Ò»¸ö×Ô³Æ USDoD µÄ·¸·¨ÍÅ»ïÓÚ 4 ÔÂÔÚµØÏÂÂÛ̳ÉÏÒÔ350 ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛ¸ÃÊý¾Ý¿â£¬²¢ÁîÈËÄÑÒÔÖÃÐŵÄÊÇÉù³Æ¸ÃÊý¾Ý¿â°üÀ¨ 29 ÒÚÌõÃÀ¹ú¡¢¼ÓÄôóºÍÓ¢¹ú¹«ÃñµÄ¼Í¼¡£¾ÝÐÅ£¬Ò»Ãû»ò¶àÃû×Ô³Æ SXUL µÄ·¸·¨ÍÅ»ï¶Ô´Ë´ÎËùνµÄÊý¾Ýй¶ÊÂÎñ¸ºÓÐÔðÈΣ¬ËûÃǽ«Êý¾Ýй¶ÊÂÎñ½»¸øÁ˳䵱ÖÐÐÄÈ赀 USDoD¡£¾Ý³Æ£¬±»µÁÐÅÏ¢°üÀ¨Ð¡ÎÒ˽¼ÒÈ«Ãû¡¢µØµãºÍÖÁÉÙ 30 ÄêÇ°µÄµØµãÀúÊ·¡¢Éç»áÇå¾²ºÅÂëÒÔ¼°ÈËÃǵÄâïÊÑ¡¢ÐֵܽãÃúÍÇ×ÆÝ£¬ÆäÖÐһЩÈËÒѾ­È¥ÊÀ½ü 20 Äê¡£¾ÝÃÀ¹ú¹ú·À²¿³Æ£¬ÕâЩÐÅÏ¢²¢·Ç´Ó¹«¹²ÈªÔ´×¥È¡µÄ£¬Ö»¹ÜÊý¾Ý¿âÖпÉÄܱ£´æÖظ´µÄÌõÄ¿¡£


https://www.theregister.com/2024/06/03/usdod_data_dump/


3. Telegram ÉÏй¶µÄ 3.61 ÒÚ¸ö±»µÁÕË»§±»Ìí¼Óµ½ HIBP


6ÔÂ3ÈÕ£¬´ó×Ú 3.61 ÒÚ¸öµç×ÓÓʼþµØµã±»Ìí¼Óµ½ Have I Been Pwned Êý¾Ýй¶֪ͨ·þÎñÖУ¬ÕâЩµØµãÀ´×Ôͨ¹ýÃÜÂëÇÔÈ¡¶ñÒâÈí¼þ¡¢Æ¾Ö¤Ìî³ä¹¥»÷ºÍÊý¾Ýй¶ÇÔÈ¡µÄƾ֤£¬ÈκÎÈ˶¼¿ÉÒÔ¼ì²éËûÃǵÄÕÊ»§ÊÇ·ñÒѱ»Ð¹Â¶¡£ÍøÂçÇå¾²Ñо¿Ö°Ô±´ÓÖÚ¶à Telegram ÍøÂç·¸·¨ÆµµÀÍøÂçÁËÕâЩƾ֤£¬ÕâЩ±»µÁÊý¾Ýͨ³£±»Ð¹Â¶¸øƵµÀµÄÓû§ÒÔ½¨ÉèÉùÓþºÍ¶©ÔÄÕß¡£±»µÁÊý¾Ýͨ³£ÒÔÓû§ÃûºÍÃÜÂë×éºÏ£¨Í¨³£Í¨¹ýƾ֤Ìî³ä¹¥»÷»òÊý¾Ýй¶ÇÔÈ¡£©¡¢Óû§ÃûºÍÃÜÂëÒÔ¼°ÓëÖ®Ïà¹ØµÄ URL£¨Í¨¹ýÇÔÈ¡ÃÜÂëµÄ¶ñÒâÈí¼þÇÔÈ¡£©ºÍԭʼ cookie£¨Í¨¹ýÇÔÈ¡ÃÜÂëµÄ¶ñÒâÈí¼þÇÔÈ¡£©µÄÐÎʽй¶¡£¸ÃÑо¿Ö°Ô±ÒªÇó BleepingComputer ¼á³ÖÄäÃû£¬ËûÃÇÓë Have I Been Pwned µÄËùÓÐÕß Troy Hunt ·ÖÏíÁË´Ó¶à¸ö Telegram ƵµÀÍøÂçµÄ 122 GB ƾ֤¡£ÕâЩÊý¾ÝºÜÊÇÖش󣬰üÀ¨ 3.61 ÒÚ¸öΨһµÄµç×ÓÓʼþµØµã£¬ÆäÖÐ 1.51 ÒÚ¸öµØµãÒÔÇ°´Óδ±»Êý¾Ýй¶֪ͨ·þÎñ¼û¹ý¡£


https://www.bleepingcomputer.com/news/security/361-million-stolen-accounts-leaked-on-telegram-added-to-hibp/


4. ÍþвÕßÉù³Æ³öÊÛ°üÀ¨1700ÍòÓû§¼Í¼µÄPandabuyÊý¾Ý¿â


6ÔÂ3ÈÕ£¬¾Ý±¨µÀ£¬±»µÁÊý¾Ý¿â°üÀ¨¶à´ï 1700 ÍòÐÐÓû§¼Í¼£¬º­¸ÇÃû×Ö¡¢ÐÕÊÏ¡¢Óû§ ID¡¢µç×ÓÓʼþ¡¢¶©µ¥Êý¾Ý¡¢IP µØµã¡¢¹ú¼Ò¡¢ÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£ÍþвÕß Sanggiero ÒѾÍÆäÒâͼ½ÒÏþÉùÃ÷¡£ËûÃÇÉù³Æ£¬ÓÃÓÚÆÆËð Pandabuy ·ÀÓùϵͳµÄÎó²î£¨¾Ý³Æ¸Ã¹«Ë¾ÉÐδ½â¾ö£©½«ºÜ¿ìÔÚÆ䲩¿ÍÍøÕ¾ÉÏÐû²¼¡£±ðµÄ£¬ËûÃÇ»¹Ðû²¼ÍýÏëÅû¶ Pandabuy Ô±¹¤µÄÐÕÃûºÍÃÜÂ룬ֻ¹ÜÊÇÒÔʹÓà base-64 ¼ÓÃܵıàÂëÐÎʽ¡£ÍþвÕßÖÒÑÔ Pandabuy ÈÔÓпÉÄܾÙÐÐ̸ÅУ¬µ«Ê±¼äδ¼¸ÁË¡£ËûÃÇΪ±»µÁÊý¾Ý¿â¿ª³öÁË 40,000 ÃÀÔªµÄ¸ß¼Û£¬Åú×¢ËûÃÇ×¼±¸½«ÇÔÈ¡µÄÊý¾ÝÂô¸ø³ö¼Û×î¸ßµÄÈË¡£


https://dailydarkweb.net/threat-actor-claims-to-sell-pandabuy-database-with-17-million-user-records/


5. Discord¶ñÒâÈí¼þ¹¥»÷¼¤Ôö£¬·¢Ã÷50000¸ö¶ñÒâÁ´½Ó


6ÔÂ3ÈÕ£¬ÔÚ×î½üÁù¸öÔµÄÆÊÎöÖУ¬ÍøÂçÇå¾²¹«Ë¾ Bitdefender ·¢Ã÷ÁËÒ»¸öÁîÈ˵£ÐĵÄÇ÷ÊÆ£ºÍøÂç·¸·¨·Ö×ÓÕýÔÚʹÓÃÊ¢ÐеÄͨѶƽ̨ Discord À´Èö²¥¶ñÒâÈí¼þ²¢Ö´ÐÐÍøÂç´¹ÂÚÔ˶¯¡£Bitdefender ÔÚ 2024 Äê 29 ÈÕÐÇÆÚÈýÐû²¼Ö®Ç°Óë Hackread.com ·ÖÏíÁ˸ñ¨¸æ£¬ÆäÖÐÖصãÏÈÈÝÁË Discord ÉÏ·¢Ã÷µÄ 50,000 ¶à¸ö¶ñÒâÁ´½Ó£¬ÏÔʾ³ö¸Ãƽ̨ԽÀ´Ô½ÈÝÒ×Êܵ½ÍøÂçÍþв¡£¶ñÒâÈí¼þºÍÍøÂç´¹ÂÚÁ´½ÓÕ¼¼ì²âµ½µÄ¶ñÒâÁ´½ÓµÄ 39%¡£ÕâЩ¹¥»÷ͨ³£Éæ¼°ÓÕÆ­ÊֶΣ¬ÓÕÆ­Óû§ÏÂÔØÓк¦Èí¼þ»òÌṩÃô¸ÐÐÅÏ¢¡£ÃÀ¹úÓû§ÓÈÆäÈÝÒ×Êܵ½¹¥»÷£¬Õ¼ÍþвµÄ 16.2%¡£ÕâʹËûÃdzÉΪ×îÈÝÒ×Êܵ½¹¥»÷µÄȺÌ壬²¢ÇÒÕ¼±ÈÏÔÖø¡£Í¨¹ý Discord Ìᳫ¶ñÒâ¹¥»÷µÄÆäËû¹ú¼Ò»¹°üÀ¨·¨¹ú¡¢ÂÞÂíÄáÑÇ¡¢Ó¢¹úºÍµÂ¹ú¡£


https://hackread.com/discord-malware-attacks-as-50000-malicious-links/


6. ÔÆ´æ´¢ Hudson Rock ÆðËßÐÅÏ¢Çå¾²»ú¹¹ Snowflake


6ÔÂ4ÈÕ£¬ÐÅÏ¢Çå¾²»ú¹¹±¨¸æ³Æ£¬·¸·¨·Ö×ÓʹÓÃÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ»ñÈ¡ÁË Snowflake Ô±¹¤µÄÊÂÇéƾ֤£¬²¢Ê¹ÓøÃÌØȨ»á¼ûȨÏÞ´Ó Snowflake µÄ¿Í»§ÔÆÕÊ»§ÖÐÇÔÈ¡ÁË´ó×ÚÊý¾Ý¡£Snowflake ÌåÏÖ£¬ÕâÖÖÇéÐβ¢Ã»Óб¬·¢¡£ÖÁÉÙTicketmasterºÍSantander ÒøÐеÄÐÅϢȷʵ±»µÁÁË£¬Ö»¹Ü¹Ù·½ÉÐδ֪ÏþÏêϸÊÇÔõÑù±»µÁµÄ£¬ÒÔ¼°´ÓÄÇÀï±»µÁµÄ £»ÕâÁ½¼ÒÒøÐж¼ÊÇ Snowflake µÄ¿Í»§¡£¾Ý±¨µÀ£¬Ticketmaster µÄһλýÌå´ú±í¸æËßTechCrunch£¬Æä±»µÁÊý¾ÝÓÉ Snowflake ÍйÜ¡£Snowflake ÌåÏÖ£¬ÈôÊÇÓÐÈκοͻ§Êý¾Ý´ÓÆä·þÎñÆ÷Öб»ÇÔÈ¡£¬ÄÇôÕâЩÊý¾Ý¿ÉÄÜÊDZ»ÇÔÔôͨ¹ýÓÐÕë¶ÔÐÔµÄÍøÂç´¹ÂÚ¡¢ÆäËûйÃÜ»ò¶ñÒâÈí¼þµÈ·½·¨»ñÈ¡ÁËСÎÒ˽¼Ò¿Í»§µÄÕË»§Æ¾Ö¤¶ø»ñµÃµÄ£¬¶ø²»ÊÇͨ¹ý¶Ô Snowflake Çå¾²ÐÔµÄÆÕ±éÆÆËð¶ø»ñµÃµÄ¡£ÊÂʵÉÏ£¬Snowflake ÒÔΪ£¬Æä¡°ÓÐÏÞ¡±ÊýÄ¿ÉÐδ͸¶ÐÕÃûµÄ¿Í»§µÄÊý¾Ý¿ÉÄÜȷʵ±»ÇÔÈ¡µÄÕË»§Æ¾Ö¤»á¼û£¬¶øÕâЩÕË»§²¢Ã»ÓÐÆôÓÃË«ÒòËØÉí·ÝÑéÖ¤¡£


https://www.theregister.com/2024/06/04/snowflake_report_pulled/