2023年5月勒索软件流行态势分析
2023-06-08 16:29

报告编号:CERT-R-2023-208

报告来源:360CERT

报告作者:360CERT

更新日期:2023-06-09

0x01   简述

勒索软件传播至今,360反勒索服务已累计接收到上万勒索软件感染求助。随着新型勒索软件的快速蔓延,企业数据泄露风险不断上升, 勒索金额在数百万到近亿美元的勒索案件不断出现。勒索软件给企业和个人带来的影响范围越来越广,危害性也越来越大。360全网安全 大脑针对勒索软件进行了全方位的监测与防御,为需要帮助的用户提供360反勒索服务。

2023年5月,全球新增的活跃勒索软件家族有: BlackSuit、Zhong、AlphaWare、EXISC等家族。其中BlackSuit会修改被勒索设备的桌面壁纸;EXISC是本月新增的一款以企业为目标的勒索软件。

以下是本月值得关注的部分热点:

1. Linux版RTM Locker勒索软件将VMware ESXi服务器作为攻击目标

2. 跨国科技公司ABB遭到Black Basta勒索软件攻击

3. 以Zimbra服务器为目标的新型勒索软件MalasLocker,要求受害者进行“慈善捐款”

基于对360反勒索服务数据的分析研判,360数字安全集团高级威胁研究分析中心(CCTGA勒索软件防范应对工作组成员)发布本报告。

0x02   感染数据分析

针对本月勒索软件受害者所中病毒家族进行统计:Phobos家族占比25.42%居首位,占比15.25%的BeiJingCrypt家族和占 比14.41%的TellYouThePass家族分居二三位。

对本月受害者所使用的操作系统进行统计,位居前三的是:Windows Server 2012、Windows 10以及Windows Server 2008。

2023年5月被感染的系统中桌面系统和服务器系统占比显示,受攻击的服务器设备再次超过桌面终端。经分析推测——这与近期针对部署 了Java环境的服务器进行定向投毒的Tellyouthepass勒索软件的活跃有很大关系。

0x03   勒索软件疫情分析

Linux版RTM Locker勒索软件将VMware ESXi服务器作为攻击目标

RTM Locker团伙自2015年以来一直活跃于金融欺诈领域,一度以传播用于金融诈骗的木马而著称。在今年4月底,安全研究人员发现RTM Locker勒索软件推出了一项新的勒索软件即服务(Raas)活动,并开始招募附属机构————这其中也包括了来自前Conti集团的附属机构。

据称,RTM目前已将其目标扩展到了Linux系统和VMware ESXi服务器。在过去几年中,很多企业已越来越多的将服务系统转向虚拟机。因 此,各类组织的服务器通常分布在专用设备和运行多个虚拟服务器的VMware ESXi服务器上。而勒索软件也顺应了这一趋势————创建 了专门针对ESXi服务器的Linux版勒索软件,以成功加密企业的所有重要数据。

研究人员分析发现,RTM Locker的Linux版本是基于现已解散的Babuk勒索软件的泄露源代码改写的。而且其似乎是专门为攻击VMware ESXi系统而编写的————因为它包含了大量用于管理虚拟机的命令。此外,目前已知该版本的RTM使用ECDH算法进行非对称加密,同时使用ChaCha20进行对称加密。

跨国科技公司ABB遭到Black Basta勒索软件攻击

瑞士跨国电气化和自动化技术供应商ABB,遭到了Black Basta勒索软件攻击,据报道此次攻击已经影响了其业务运营。该公司与众多客户和地方政府合作,包括沃尔沃、日立、DS Smith、纳什维尔市政府和萨拉戈萨市政府等重要客户。

5月7日,该公司遭到Black Basta勒索软件团伙发动的网络攻击。据悉本次勒索软件攻击主要针对该公司的Windows Active Directory, 影响了数百台设备。而作为对此次攻击的安全响应,ABB终止了与客户的VPN连接以防止勒索软件传播到其他网络。

目前,ABB发表声明称其“最近检测到了一个直接影响某些位置和系统的IT安全事件。为了解决这种情况,ABB已经并将继续采取措施来控制这一事件,而这种控制措施对其运营造成了一些干扰”……但同时也表示其“绝大多数系统和工厂现在都在运行,ABB将继续以安全的 方式为其客户服务。”

以Zimbra服务器为目标的新型勒索软件MalasLocker,要求受害者进行“慈善捐款”

据报道,一款针对Zimbra服务器进行入侵之后窃取电子邮件,并加密文件的新型勒索软件MalasLocker出现。与以往勒索软件不同的是— —该勒索软件攻击者并没有要求受害者,直接向他们支付赎金,而是要求向慈善机构捐款以提供解密工具并防止数据泄露。

该勒索软件于2023年3月底开始针对Zimbra服务器发起攻击并进行加密,受害者均表示发现上传到一下两个路径中存在可疑的JSP文件。

- /opt/zimbra/jetty_base/webapps/zimbra/

- /opt/zimbra/jetty/webapps/zimbra/public/

而相关的jsp文件名可能有如下几个:

- info.jsp

- noops.jsp

- heartbeat.jsp

与常规的勒索软件最大的区别,该家族的赎金诉求:其会要求受害者向他们“批准”的非营利慈善机构捐款。并称“只是不喜欢公司和经济不平等”“这是双赢的,如果您愿意,您可能可以从捐款中获得减税和良好的公关形象”

0x04   黑客信息披露

以下是本月收集到的黑客邮箱信息:

antilock@cock.lidraculakink99@outlook.comxmaster22@tutanota.com
antilock@keemail.mewillbeok1234@tutanota.comxmagic22@tutanota.com
anylock@cock.lieverythingwillbeok@mailfence.comhelprecoverdata@aol.com
anylock@keemail.mesirsilent1@onionmail.orgrrdata@aol.com
Backup@cyberfear.comloki_supp@outlook.comrecovertwilightdata@gmail.com
bestway4u@mailfence.comtrust003@protonmail.compayfordecryption@gmail.com
bestway4u@onionmail.comtrust03@tutanota.comrecovertwilightdata@ gmail.com
carabas1337@proton.medata2022@aol.comMonaharDecryption@airmail.cc
contact03@ tutanota.comlokiguide@yahooweb.cotorresproxytg@proton.me
criptoman@mailfence.comrdpmanager@onionmail.orgbaseus0906@goat.si
crypter@firemail.desirsilent2@onionmail.orgcarlosrestore2020@aol.com
D4nte@onionmail.orgdata2022@onionmail.orgsavetime@cyberfear.com
decgodloki@onionmail.comvpsran1fat@cyberfear.comsyntaxerror@firemail.cc
decgodloki@tutanota.comvpsran1fat@tutanota.commallox.resurrection@onionmail.org
decrliv@aol.comrecoverdata@mail2tor.commalloxdata@mailfence.com
decryption.helper@aol.comdr.dcrypter@mailfence.commalloxdata@tutanota.com
decryptyourfileenvi@onionmail.orgd4rkw4ve@tutanota.commallox@onionmail.org
emeraldcrypt@onionmail.orgirishman@onionmail.comJohnatannielson@protonmail.com
emeraldcrypt@tutanota.comirishman@tutanota.decharlefletcher@onionmail.org
endevecsupp@tutanota.comadvanceloki@mailfence.comlockdata@mailfence.com
everythingwillbeok@onionmail.orgadvanceloki@tutanota.comsmbppt@tutanota.com
falcondal@horsefucker.orgroxlock@keemail.mexhermes@rambler.ru
falcondal@tuta.iominioncrypt@tutanota.comsupport2022@cock.li
filesupport@airmail.ccminioncrypt@bingzone.netbuybackdate@nuke.africa
filesupport@airmail.ccrdecrypt@ yandex.comxhermes@rambler.ru
ghostenc@mailfence.comexploit1@mailfence.comdschen010203@gmail.com
ghostenc@tutanota.comexploit2@cock.liquickstep@tuta.io
ghosttm@zohomail.comdark4wave@yandex.com@Stop_24
gizmo12@tutanota.comrdpmanager@airmail.ccbackjohn131@gmail.com
go.ahead@tutanota.comfilemanager@mailfence.combackjohn@tutanota.com
help_havaneza@cryptolab.netunlockpls.dr01@protonmail.compbs@ciptext.com
helper@firemail.deunlockpls.dr01@yahoo.compbs24@tutanota.com
jackie.ma@tuta.ioultimatehelp@techmail.infounlockhelppk@xmpp.jp
jerd@420blaze.itmiracle11@keemail.meicanrestore@onionmilorg
lokihelp@mail2tor.comultimatehelp@keemail.meinter_hunter@tuta.io
lokihelp@onionmail.orgdecnow@tutamail.comsleepdb@my.com
lokiloki@mailfence.comdecnow@protonmail.comSleepdb@tutanota.com
lokisupp0rt@yandex.comleo.decrypter@protonmail.comRavenRestore@yandex.com
lokisupport@onionmail.orgleo.rinse@mailfence.comfastwindglobe@cock.li
lollooki@protonmail.comdecnow@msgsafe。 io@decryptfastwind
lollooki@yandex.comdecnow@tutanota.comfastwindGlobe@mail.ee
main642@ tutanota.comdexterxanax@criptext.combuydecoder@nerdmail.co
mallox@onionmail.orgtran9ino00@protonmail.com@data_decrypt
mrbroock@msgsafe.ioanoniran@protonmail.comlockdata@tutanota.com
mrlokilocker@telegram.memiiracle11@yandex.comlockdata@cyberfear.com
ransom101@tutanota.comfalcon9@cyberfear.comlockbitdecrypt@msgsafe.io
ransomware919@mailfence.comlockirswsuppurt@mailfence。 comlockbitdecrypt@onionmail.org
ransomware919@zohomail.eurain_man13@keemail.me@decryptfastwind
recoverdata@onionmail.orgloki.help@mailfence.comfastwindglobe@cock.li
recoverlokidata@gmail.compayfordecrypting@gmail。comback2up@swismail.com
reopen@tutanota.compayfordecrypting@outlook.comHelpyoudc1966@gmail.com
sirboz@onionmail.orgloki.help@bingzone.nettsai.shen@mailfence.com
sirhirad@cock.liroxlock@mailfence.comTsaiShen@mail2tor.com
supploki@ onionmail.orgrain.man13@mailfence.comhudsonL@cock.li
supploki@mailfence.comdecoder@firemail.ccdr.files@onionmail.org
supporting@firemail.cchelpingdecode@tutanota.comdr.file2022@gmail.com
trust03@onionmail.orglockteam@keemail.metomas@techmail.info
umbrage@cyberfear.comrdecrypt@ mailfence.comJohnTorrington1843@gmx.com
umbrage@onionmail.orglockteam@cock.liThomasWyaty1977@onionmail.org
unlockerhelp@onionmail.orgsapphire01@keemail.meHonestEcoZ@dnmx.org
unlockloki@mailfence.comsapphire02@mailfence.comenc2@usa.com
unlockloki@onionmail.orgdarksoul@safeswiss.comenc2@dr.com
vulcanteam@mail2tor.comprodecryptor@yandex.comdecryptyourfile@gmail.com
vulcanteam@onionmail.orgmary2005@onionmail.orgmagicback@onionmail.org
warthunder089@mailfence.commary2005@mailfence.comjustin@cyberfear.com
warthunder089@tutanota.depayfordecryption@gmail.comsentafe@rape.lol
winston01@msgsafe.iopayfordecryption@outlook.comiuumua@keemail.me
winston01@onionmail.orgsooua@tuta.io

表格1. 黑客邮箱

当前,通过双重勒索或多重勒索模式获利的勒索软件家族越来越多,勒索软件所带来的数据泄露的风险也越来越大。以下是本月通过数据泄露获利的勒索软件家族占比情况统计,该数据仅为未在第一时间缴纳赎金或拒缴纳赎金部分(已经支付赎金的企业或个人,可能不会出现在这个清单中)。

以下是本月被双重勒索软件家族攻击的企业或个人。若未发现被数据存在泄露风险的企业或个人也请第一时间自查,做好数据已被泄露准备,采取补救措施。

本月总共有560个组织/企业遭遇勒索攻击,其中有5个中国组织/企业在本月遭遇了双重勒索/多重勒索。有6个组织/企业未被标明,因此 不再以下表格中。

buckprop.comvdbassocies.frГород Кафе
Sur La Tablesoftland.clЖБИ2-Инвест
Pacific Union Collegerapidmoldsolutions.comBaggio
credicoop.coop.pysiren-japan.comnanoCAD
nycollege.eduComoli FerrariPetromiralles
fixscr.comCanadian Nurses AssociationКрасный Восток Агро
SK Life ScienceFRESCAAngle Metal Mfg.
The National Association of Home BuildersMSSNYThe Sound Organisation
columbuscitizens.orgLiveActionUtair
Lewis Young Robertson & BurninghamAsia Vital ComponentsЛарина
McCarthy Fingardiasporacs.orgBanco Azzoaglio
casepoint.comFajarPaperantea.es
Sysco Corporationabe-brands.deAutlan Metallorum
Eastern Media International CorporationReach Cooling Groupenovationcontrols.com
Sorocebdlab.comshoreregional.org
AdsbollRheinmetall AGmetalnet.nl
Burch & Cracchiolo, P.A.Kannangara ThomsonE4NET
aquidneckclub.comMaier Sanitär-Technik GmbHNASHUA SCHOOL DISTRICT
C**Al Tamimi Law FirmLolaico Impianti
Earlens CorporationAdvantage Resourcinga*
Neutronic Stampingcsagh.orgENSA - Seguros de Angola
Brokers Trust Insurance GroupRolserZ*s
Computer Information Concepts IncCity of DallasTaslyUS
Fersten WorldwideHECTOR MARTINEZ SOSA Y CIA SAAVIAREPS
retailmerchantservices.co.ukIt Works GlobalAneka Tambang
BilgeAdam SoftwareHarita GroupMagic-Aire
grantierra.comFort Rolins Collection Agencyplastictecnic.com
voyageursdumonde.frCompañía Agricola San FelipePM Medical Billing
Australian Universal Crane LeakAnstelElectrostim Medical Services
FiduagrariaBeeVoipBAMSI
**MDAViSTOAccudo Investments LTD
**G Inc.IPG Automotive GmbHFeit Electric
aI***еКредитance.org.mx
HeVi** ProjectISG Software Groupwings.travel
Servizi OmniaMetaContratasSOWITEC
fiduagraria.gov.coPropac S.r.l.ORION
arnoldoilco.comDalim Software GmbHairtac.com
watersaversinc.comChernoff Thompson Architectschinadailyhk.com
floodlaw.comLivitekIXPERTA
aimtron.comКм ПрофильPCS Wireless
Good Oil CompanyPreference PortugalParker Drilling
AFG HoldingsAMETnorcorp.com
VoltMangum ConstructionGroup DIS (Direct Info Services)
Groupe Sovitrat Interim and RecrutementOrcutt WinslowQUORUMIS
BM PrecisionМебельснабYork County School of Technology
DirectViz SolutionsSpectris Business Systemseuskaltel.com
The Best ConnectionWpatmundo-r.com
MitutoyoradiosvetBluefield University
Grange Packing SolutionsChiltern NetworksRIC Electronics
Marshall Construction LtdHotel SmeraldoTrueLogic
Colrichreg22tool-temp.net
Haworth TompkinsStudio Papapikenursery.com
ProcurriEtanovatroteclaser.com
wiannoclub.comГудвин-НеваAcademy Mortgage Corporation
kyocera-avx.comBusiness Travel SolutionsTTCCPA
fams.netWishmasterHostAfrica
City of AugustaNext Generation SrlAKRON Mquinas Agrcolas
Norton HealthcareRusExport LtdWallick Communities
sfponline.orgFinRe ConsultingAspen Dental Management Inc.
pneusbelislecarrieres.comJvG Consultingbankbsi.co.id
affinityhealthservices.netTBIT ServicesPeachtree Orthopedics
LeidosConfindustria EnergiaMare Hotel
StantAltarixSterling Solutions
globalinfovision.comNTA srlprolinerrescue.com
The Middleton GroupInternational Cargo Equipmentweberweber.at
Trabzonspor Football ClubNEXT OSLibyana
MBoarding ConceptRockbridge Capital
roha.comLegatoSchottenstein Property Group Inc
Voxx ElectronicsLoeje Trust SASettlement Music School
interstateplastics.comhappy-snack.ruPak-Rite, Ltd.
Coos BayOmniglobe Business SolutionsAlliance Sports Group
Amaszonas S.A.Evology ManufacturingThompson Builders
Leland Campbell LLP law firmINFINREAL Immobilien GmbHBridgeValley Community & Technical College
H*Accurate Section BendersThe McGregor
Rusan PharmaVilla Grazioli4LEAF, Inc.
surfsidefoods.comQball TechnologiesNovatech Engineering Consultants
spectre.dkTitanPowerColumbia Distributing
Dotcom DistributionRivas Boquete SLGregory Poole Equipment Company
Chattanooga Heart InstituteSA.FIIpleiria Student Brnch
The Travel Network GroupWinner ItaliaSun Windows
Jacklyn Dawson SolicitorsSBG GlobalMercer University
Southwest Healthcare ServicesВК ЛогистикThe Perry Law Firm
JANUS Research GroupBMW АлдисThe Lab Consulting
Garden Hotel NARITAFroese & PartnerNew World Travel, Inc.
Montgomery General HospitalKomGarantThe Mitchell Partnership
Nabtesco Motion ControlCommerciale FerramentaGarcia Hamilton & Associates
UnitedLex.comГис НефтесервисFee, Smith & Sharp
P1 Technical ServicesOnubo s.r.l.Family Day Care Services
GIOTTO - COMÉRCIO DE VESTUÁRIO, UNIPESSOAL, LDAAnswerproDATALAN
ESSPEEATE ElettronicaResultsCX
MTS OfficeNTD SAAo
Concept FastenersНевский АльянсDA Alexander Company INC
Meklas GroupIris Key Solutionsviseg.com
AS NetzAsanger Modellbauvuteq.mx
THE HARCOURTS FOUNDATION (AUSTRALIA) PTY LTDBenarITCSD Network Services Ltd
Butler and Gatz CPAs, LLCАзимут НТtec-mex.com.mx
LebensWohnArtТерра-Минораwuppermann.com
Irmler RechtsanwälteISONA GmbHmetronottevigilanza.it
Innormax LLCOPIT SolutionsAxiom Professional Solutions
Moore GlobalAxonSauerbruch Hutton
ShipmatePMP MeccanicaJP Maguire & Associates
SOVACTCGGermany Trade & Invest (GTAI)
Intermountain CentersУниверсалресурсHouser LLP
Grupo 2MGAАстраVdi
BrandaoСК БлагоДатьgocontec.com
DBT DruckluftTotality SolutionsCooperativa de Ahorro y Crédito Ahorrocoop Ltda
Constantino Contabilidade E ComunicacaoSpecialinsertmbwswim.com
FrameOneТрансКом-Авиаinterfides.de
Watex SolutionsAVM Software & TechnologyCADOpt Technologies
Lerch BatesVeglioluxDepartment of Education of the Canton of Basel-Stadt
Clear Start AccountantsFresh-Heads ITHumana
CST Medicina do TrabalhoTycoon GroupFresh Insurance IT Services
SembaGrassi srlhk-finance.pl
Direct Cleaning ServicesFEA srlcbelaw.com
Bronzino EngineeringMobalpa BiarritzKLC Network Services
Grupo RimetICT-LabSASL 1 - Avezzano Sulmona L'Aquila
Taylor Made HoseCosmos Hotel GroupLUX Automation
Formax Credit UKПсковпассажиравтотрансstmarys.net
NORTCONEvropolyastate.edu
Redwood Lab ServicesGallagher & Co Consultantslssny.org
ER of Dallas3Punto6unity.edu
SMYRNAPEDIATRICSStudio ConsulenzaFirst Community Credit Union
TTG Logmeta-spbnamibmills.com
Colares LinharesRiboli srlmarshallconstruction.co.uk
Ayers Mechanical GroupStudio Rossetti e PartnersInsurance Providers Group
FORMA ESPACOS IMOBILIARIOS LTDAAxon Certified AuditorsWealth Enhancement Group
Conklin BenhamStudio Eco PeruccaBisco Industries
China Export & Credit Insurance CorporationNu-Pro GroupEyeGene
Print Globepaulmitchell.ruEagle Eye Produce
Neighborhood Progress FundHerold DruckGrupo Cativa
La CanasteríaPasquetti Sarti & PartnersAxure Software Solutions
Richard W. Fuller CPAФормексKKDI.CO.ID
MRO SUPPORT, INCТрансбалтB&R Eckel's Transport
IMASAZite MediaC*
Immobilienmakler in OldenburgHorseman SimM
COREALBE.iT SAN
Veal and PrasadJohnston Technical ServicesCoteccons
HELPHONEKourosR**
Thayer AcademyDSSLMeade Tractor
Midway FordСКППКeyeDOCS Ottawa
Lake CableSteelgroupConstellation Software Inc
ZenexBalbi SrlEssen Medical Associates
M Metzler & AssociatesSkyFORSjoysonsafety.com
General de Alimentos Nisa C.A. (GENICA)InfinCEPRESS-SERVICE Monitoring Mediów
Ellard-Willson Engineering LtdGrupo FatecsaWillamette Falls
CONTASSBaur Hausverwaltunglayherna.com
Artconta - Contabilidade e. Assistência FiscalЯмалтелекомFR
Csc Baixo Sul Assessoria e Consultoria Empresarial e Contabil LTDAHardman'sGihealthcare
Just us lawyersKriaaNet IncBluefield College
Asbestos-Inspections-Solution-ManagementBleu BlancThe Crown Princess Mary Cancer Centre
SiComputercashbackAPPMidwest Truck
Malkasian AccountancyMappy ItaliaIDTECHPRODUCTS.COM
APIQROOspw.ruGropper & Nejat, PLLC
InquirerTransitus GroupSIVSA
Black Cat NetworksBicomNova Group
Paragon Software LankaBEI SrlCoremain
Mayberry InvestmentsSallemi CarburantiCity of Lowell
Grupo Corporacion ControlRepcoLiteDGC
Studioline PhotographyD&G impianti elettriciLibra Virtua
Optimus SteelFraport SkylinersCommune de Saxon
Chattanooga State Community CollegeExsetNegma Business Solutions
XplainSita SoftwareVocalcom
Aria OnlineHostingPerTeWoonkracht10
Royal CentreHoteles GlobalesCarrington
PolyStudio Negri e Associatitriaflex.at
CafpiAmersportSouthern West Virginia Community and Technical College
Oppida Estates LimitedСервистаAeco
SMDEAConnectToZBW News
T*Azzurra Groupcydsa.com
Alconex Specialty ProductsOasis Ads MediaLawrence Family Development Charter School
H**LunarWebMYSIMPLYGREEN.COM
Zoni Language CentersГласс Фурнитураhasenauer-anlagenbau.at
WestsideArCloudAvidXchange
Harmony GoldКопчёновbaycrestpartners.com
rmc-canada.comCustom Manufacturing & Engineering, Inccloud51.com
TA SupplyФГУП "ЦНИИХМ"American Foam & Packaging
Agostini Insurance BrokersKondorCSTony Clark Consulting
Trinity Exploration and ProductionAster CucineEirMed Devices, part of TRELLEBORG
Morris HospitalЕвроэкспоambit.co
Atlas CommoditiesAltiafinvest.ambit.co
Technology and Telecommunications Consultants IncИмедиLincoln Wood Products
Loreto NormanhurstPerglerCoca-Cola FEMSA Mexico
SIGMAMHWEBAlto Calore Servizi S.p.A.
Utah-Yamas Controls.A.&,**.Polat Yol Yap
wenntownsendDiete-SiepmannBrighton Hill Community School
Mazars GroupMontana State UniversityGreat Falls College of Technology
hadefpartners.com

表格2. 受害组织/企业

0x05   系统安全防护数据分析

360终端安全产品,目前已加入黑客入侵防护功能。在本月被攻击的系统版本中,排行前三的依次为Windows Server 2008、Windows 7以 及Windows Server 2016。

对2023年5月被攻击系统所属地域统计发现,与之前几个月采集到的数据进行对比,地区排名和占比变化均不大。数字经济发达地区仍是 攻击的主要对象。

通过观察2023年5月弱口令攻击态势发现,RDP弱口令攻击、MYSQL弱口令攻击和MSSQL弱口令攻击整体无较大波动。

0x06   勒索软件关键词

以下是本月上榜活跃勒索软件关键词统计,数据来自360勒索软件搜索引擎。

- devos:该后缀有三种情况,均因被加密文件后缀会被修改为devos而成为关键词。但本月活跃的是phobos勒索软件家族,该家族的主要传播方式为:通过暴力破解远程桌面口令成功后手动投毒。

- 360:属于BeijngCrypt勒索软件家族,由于被加密文件后缀会被修改为360而成为关键词。该家族主要的传播方式为:通过暴力破解远 程桌面口令成功后手动投毒,本月新增通过数据库弱口令攻击进行传播。

- malox:属于TargetCompany(Mallox)勒索软件家族,由于被加密文件后缀会被修改为mallox而成为关键词。主要通过暴力破解远程桌面口令成功后手动投毒和SQLGlobeImposter渠道进行传播。此外360安全大脑监控到该家族本曾通过匿影僵尸网络进行传播。

- locked1:属于TellYouThePass勒索软件家族,由于被加密文件后缀会被修改为locked1而成为关键词。该家族主要通过各种软件漏洞、系统漏洞进行传播。

- mkp:属于Makop勒索软件家族,由于被加密文件后缀会被修改为mkp而成为关键词。该家族主要的传播方式为:通过暴力破解远程桌面 口令成功后手动投毒。

- halo:同360。

- eking:同devos。

- faust:同devos。

- buddha:属于DeepInWeb勒索软件家族,由于被加密文件后缀会被修改为buddha而成为关键词。该家族的主要传播方式为:通过暴力破 解远程桌面口令成功后手动投毒。

- elbie:同eking。

0x07   时间线

2023年06月08日 360高级威胁研究分析中心发布通告