To The Moon
Home
News
TigerAI
Log In
Sign Up
追涨杀跌的小韭菜
追涨杀跌,跟随大趋势操作有错吗?
+Follow
Posts · 24
Posts · 24
Following · 0
Following · 0
Followers · 0
Followers · 0
追涨杀跌的小韭菜
追涨杀跌的小韭菜
·
2021-07-06
?
Even more bizarre than a movie! Russian hackers "shocked the United States," making Biden anxious.
令人闻风丧胆的某黑客组织,又有了新的动作。
Even more bizarre than a movie! Russian hackers "shocked the United States," making Biden anxious.
看
4.46K
回复
Comment
点赞
Like
编组 21备份 2
Share
Report
Load more
Most Discussed
{"i18n":{"language":"en_US"},"isCurrentUser":false,"userPageInfo":{"id":"3573655083318340","uuid":"3573655083318340","gmtCreate":1610561060753,"gmtModify":1623325502713,"name":"追涨杀跌的小韭菜","pinyin":"zzsddxjczhuizhangshadiedexiaojiucai","introduction":"","introductionEn":null,"signature":"追涨杀跌,跟随大趋势操作有错吗?","avatar":"https://static.tigerbbs.com/ede67f31d330580bd8b47481e8c99253","hat":null,"hatId":null,"hatName":null,"vip":1,"status":2,"fanSize":8,"headSize":24,"tweetSize":24,"questionSize":0,"limitLevel":999,"accountStatus":2,"level":{"id":3,"name":"书生虎","nameTw":"書生虎","represent":"努力向上","factor":"发布10条非转发主帖,其中5条获得他人回复或点赞","iconColor":"3C9E83","bgColor":"A2F1D9"},"themeCounts":0,"badgeCounts":0,"badges":[],"moderator":false,"superModerator":false,"manageSymbols":null,"badgeLevel":null,"boolIsFan":false,"boolIsHead":false,"favoriteSize":5,"symbols":null,"coverImage":null,"realNameVerified":"success","userBadges":[{"badgeId":"1026c425416b44e0aac28c11a0848493-4","templateUuid":"1026c425416b44e0aac28c11a0848493","name":"Tiger Star","description":"Join the tiger community for 2000 days","bigImgUrl":"https://static.tigerbbs.com/dddf24b906c7011de2617d4fb3f76987","smallImgUrl":"https://static.tigerbbs.com/53d58ad32c97254c6f74db8b97e6ec49","grayImgUrl":"https://static.tigerbbs.com/6304700d92ad91c7a33e2e92ec32ecc1","redirectLinkEnabled":0,"redirectLinkType":null,"redirectLink":null,"redirectLinkValidityFrom":null,"redirectLinkValidityTo":null,"hasAllocated":1,"isWearing":0,"stamp":null,"stampPosition":0,"hasStamp":0,"allocationCount":1,"allocatedDate":"2026.07.07","exceedPercentage":null,"individualDisplayEnabled":0,"backgroundColor":null,"fontColor":null,"individualDisplaySort":0,"categoryType":1001,"isScarce":0,"effectConfig":null,"effectEnabled":0,"plateImgUrl":null,"plateColors":null,"validityTo":null,"validityToTimestamp":null,"wearingSort":0}],"userBadgeCount":1,"currentWearingBadge":null,"individualDisplayBadges":null,"crmLevel":1,"crmLevelSwitch":0,"location":null,"starInvestorFollowerNum":0,"starInvestorFlag":false,"starInvestorOrderShareNum":0,"subscribeStarInvestorNum":0,"ror":null,"winRationPercentage":null,"showRor":false,"investmentPhilosophy":null,"starInvestorSubscribeFlag":false},"page":1,"watchlist":null,"tweetList":[{"id":157286597,"gmtCreate":1625583585419,"gmtModify":1703744431636,"author":{"id":"3573655083318340","authorId":"3573655083318340","name":"追涨杀跌的小韭菜","avatar":"https://static.tigerbbs.com/ede67f31d330580bd8b47481e8c99253","crmLevel":1,"crmLevelSwitch":0,"followedFlag":false,"idStr":"3573655083318340","authorIdStr":"3573655083318340"},"themes":[],"title":"","htmlText":"?","listText":"?","text":"?","images":[],"top":1,"highlighted":1,"essential":1,"paper":1,"likeSize":0,"commentSize":0,"repostSize":0,"link":"https://ttm.financial/post/157286597","repostId":"2149535517","repostType":4,"repost":{"id":"2149535517","kind":"highlight","pubTimestamp":1625552058,"share":"https://ttm.financial/m/news/2149535517?lang=en_US&edition=fundamental","pubTime":"2021-07-06 14:14","market":"us","language":"zh","title":"Even more bizarre than a movie! Russian hackers \"shocked the United States,\" making Biden anxious.","url":"https://stock-news.laohu8.com/highlight/detail?id=2149535517","media":"新智元","summary":"令人闻风丧胆的某黑客组织,又有了新的动作。","content":"<p>[Introduction] A fearsome hacker group has made new moves. Recently, they launched a massive cyberattack, infecting 1 million systems and paralyzing hundreds of American companies, with the hackers offering $70 million. Biden said he has ordered an FBI investigation. Yesterday, news broke that the United States has ordered an investigation into a ransomware campaign in which hackers have extorted more than $100 million, paralyzing hundreds of businesses in just a few months.</p><p>Their name is: REvil.</p><p>The companies they attacked included<a href=\"https://laohu8.com/S/AAPL\">Apple</a>And Acer, as well as JBS, the world's largest meat processing company. JBS obediently complied and paid it $11 million in Bitcoin.</p><p>Their characteristic is that no matter who the hackers are, they will post the stolen files on a website called Happy Blog.</p><p>On Sunday, REvil made another big ask, posting a universal decryption software key on its website that could decrypt all affected machines and demanding $70 million in exchange for the decryption.</p><p><img src=\"https://static.tigerbbs.com/2d2eed2a36488a230837f33fad82eb4c\" tg-width=\"548\" tg-height=\"287\" referrerpolicy=\"no-referrer\"></p><p>Last Friday (02.07.2021), we launched an attack against MSP vendors. More than 1 million systems were infected. If anyone wants to negotiate a universal decryptor – our price is $70 million (BTC) – we will publicly release the decryptor and decrypt all the victims' files, so everyone will be able to recover from the attack in less than an hour. If you are interested in such a transaction, please contact us according to the instructions in the victim's \"readme\" file.</p><p>This attack appears to be the largest ever launched by REvil. This attack has infected up to 40,000 computers worldwide.</p><p>How did this happen?</p><p><h2>The \"ransom\" reached $70 million, and the 0-day vulnerability became a target of global hacker attacks.</h2>Last week's attacks focused primarily on Kaseya VSA software. Kaseya's VSA is used to monitor and manage the infrastructure, provided by Kaseya as a managed cloud service or through an on-premises VSA server.</p><p><img src=\"https://static.tigerbbs.com/bcd641d2adea115d20fb832537ab54c4\" tg-width=\"1080\" tg-height=\"565\" referrerpolicy=\"no-referrer\"></p><p>The REvil ransomware gang is demanding a $70 million ransom and will release a general-purpose decoder once they receive the money.</p><p><img src=\"https://static.tigerbbs.com/cd2c061bb0ba4a2683657a86078ef4cd\" tg-width=\"548\" tg-height=\"269\" referrerpolicy=\"no-referrer\"></p><p>Kesaya's VSA software allows hosting providers to remotely monitor their customers' IT networks</p><p>Some customers have reported that their VSA software contains numerous 0-day vulnerabilities, which are used as channels for deploying ransomware.</p><p><img src=\"https://static.tigerbbs.com/af531d8b622709312543e8769f266089\" tg-width=\"660\" tg-height=\"347\" referrerpolicy=\"no-referrer\"></p><p>They then use ransomware to lock the data and allow attackers to connect to the host via HTTP access and manually inject malware.</p><p><img src=\"https://static.tigerbbs.com/e751fafa9cf4a07426dea97cc7c44a82\" tg-width=\"1080\" tg-height=\"608\" referrerpolicy=\"no-referrer\"></p><p>\"More than 70 management service providers were affected, resulting in more than 350 organizations being further impacted.\"</p><p>This includes Coop, a supermarket chain in Sweden. The company has temporarily closed about 800 of its stores across the country because the attack affected its cash registers.</p><p><img src=\"https://static.tigerbbs.com/a24a337b7c6d99692cfb2d1c6627d9ca\" tg-width=\"548\" tg-height=\"254\" referrerpolicy=\"no-referrer\"></p><p>Swedish supermarket chain Coop had to temporarily close 800 of its stores due to the attacks.</p><p>Exploiting Kaseya's vulnerabilities to create potential vulnerabilities, the REvil gang certainly didn't forget to boast about successful attacks on MSP vendors and shared news that over a million systems had been infected.</p><p><h2>\"Attracting\" Biden's attention, ordering an FBI investigation, and advising clients not to pay.</h2>Such a large-scale attack has \"received\" attention. Biden has stated that he will investigate the incident, and the FBI hopes that everyone who was hacked will report it to the authorities.</p><p><img src=\"https://static.tigerbbs.com/3d4b3d376621128cd7dc66db53a61a17\" tg-width=\"450\" tg-height=\"300\" referrerpolicy=\"no-referrer\"></p><p>However, in such cases, the FBI has discouraged victims from paying.</p><p><img src=\"https://static.tigerbbs.com/de0b508f1dc225dc83d957aed6dcc987\" tg-width=\"697\" tg-height=\"211\" referrerpolicy=\"no-referrer\"></p><p>Because, according to a report this year, 92% of paid organizations cannot recover all their data; Most victims who take out cash can only partially recover the contents of their encrypted files.</p><p><h2>He once threatened to leak MacBook schematic diagrams and demanded $50 million!</h2>Due to its \"track record,\" REvil is one of the top ten most dangerous cybercrime organizations in the world.</p><p>Prior to this, REvil's famous extortion incident was the theft of Apple product manufacturing secrets in April of this year.</p><p>At the time, the hacking group REvil issued a statement saying that they had hacked Quanta, a Taiwanese manufacturer of products such as MacBooks, and demanded a ransom of $50 million, otherwise it would release sensitive internal documents.</p><p><img src=\"https://static.tigerbbs.com/94ed071c5af49e5abc3f496364341260\" tg-width=\"1012\" tg-height=\"887\" referrerpolicy=\"no-referrer\"></p><p>After Quanta Computer refused to pay the ransom, the hacking group began releasing stolen images during Apple's spring launch event on April 20th (US time) and extorted money from Apple.</p><p>Apple is one of the world's largest companies, and REvil's ability to break in indirectly proves the strength of this criminal gang.</p><p>A cybersecurity firm that specializes in negotiating with criminal hackers says that in the past 90 days alone, his firm has handled 32 cases involving the REvil organization.</p><p><img src=\"https://static.tigerbbs.com/15d07dcd48b9983946ef6e04bb2b79b5\" tg-width=\"548\" tg-height=\"411\" referrerpolicy=\"no-referrer\"></p><p>Hackers invaded Apple suppliers and demanded a ransom of $50 million</p><p>However, in the past, REvil primarily targeted the professional services sector, rather than the technology sector. Therefore, this attack on Apple and its demand for $50 million is very different from its previous approach.</p><p>Negotiation experts say the average ransom paid in the past was also much lower, at nearly $728,000, and after price negotiations, the actual average ransom paid was even lower.</p><p>The cybersecurity company said that, according to rough estimates, the gang has raised a total of $100 million to date. However, this group is also relatively \"easy to negotiate\".</p><p><h2>Russian hackers focus on harming the US.</h2>In addition to extorting money, Russian hackers are \"keen\" to target the United States.</p><p>Two months ago, another hacking group called DarkSide hacked into Colonial Pipeline, the largest fuel Pipeline operator in the United States.</p><p><img src=\"https://static.tigerbbs.com/7848ac8acc903d061227edb37b76ae08\" tg-width=\"950\" tg-height=\"534\" referrerpolicy=\"no-referrer\"></p><p>At the time, nearly 100GB of data was hijacked, and the data could only be retrieved by paying a ransom.</p><p>This directly forced the shutdown of key fuel networks supplying fuel to states along the East Coast of the United States. Moreover, fuel prices in the United States also soared to a new high.</p><p>Ironically, after extorting money, these people actually donated it to a charitable organization.</p>","source":"lsy1569730104218","collect":0,"html":"<!DOCTYPE html>\n<html>\n<head>\n<meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\" />\n<meta name=\"viewport\" content=\"width=device-width,initial-scale=1.0,minimum-scale=1.0,maximum-scale=1.0,user-scalable=no\"/>\n<meta name=\"format-detection\" content=\"telephone=no,email=no,address=no\" />\n<title>Even more bizarre than a movie! Russian hackers \"shocked the United States,\" making Biden anxious.</title>\n<style type=\"text/css\">\na,abbr,acronym,address,applet,article,aside,audio,b,big,blockquote,body,canvas,caption,center,cite,code,dd,del,details,dfn,div,dl,dt,\nem,embed,fieldset,figcaption,figure,footer,form,h1,h2,h3,h4,h5,h6,header,hgroup,html,i,iframe,img,ins,kbd,label,legend,li,mark,menu,nav,\nobject,ol,output,p,pre,q,ruby,s,samp,section,small,span,strike,strong,sub,summary,sup,table,tbody,td,tfoot,th,thead,time,tr,tt,u,ul,var,video{ font:inherit;margin:0;padding:0;vertical-align:baseline;border:0 }\nbody{ font-size:16px; line-height:1.5; color:#999; background:transparent; }\n.wrapper{ overflow:hidden;word-break:break-all;padding:10px; }\nh1,h2{ font-weight:normal; line-height:1.35; margin-bottom:.6em; }\nh3,h4,h5,h6{ line-height:1.35; margin-bottom:1em; }\nh1{ font-size:24px; }\nh2{ font-size:20px; }\nh3{ font-size:18px; }\nh4{ font-size:16px; }\nh5{ font-size:14px; }\nh6{ font-size:12px; }\np,ul,ol,blockquote,dl,table{ margin:1.2em 0; }\nul,ol{ margin-left:2em; }\nul{ list-style:disc; }\nol{ list-style:decimal; }\nli,li p{ margin:10px 0;}\nimg{ max-width:100%;display:block;margin:0 auto 1em; }\nblockquote{ color:#B5B2B1; border-left:3px solid #aaa; padding:1em; }\nstrong,b{font-weight:bold;}\nem,i{font-style:italic;}\ntable{ width:100%;border-collapse:collapse;border-spacing:1px;margin:1em 0;font-size:.9em; }\nth,td{ padding:5px;text-align:left;border:1px solid #aaa; }\nth{ font-weight:bold;background:#5d5d5d; }\n.symbol-link{font-weight:bold;}\n/* header{ border-bottom:1px solid #494756; } */\n.title{ margin:0 0 8px;line-height:1.3;color:#ddd; }\n.meta {color:#5e5c6d;font-size:13px;margin:0 0 .5em; }\na{text-decoration:none; color:#2a4b87;}\n.meta .head { display: inline-block; overflow: hidden}\n.head .h-thumb { width: 30px; height: 30px; margin: 0; padding: 0; border-radius: 50%; float: left;}\n.head .h-content { margin: 0; padding: 0 0 0 9px; float: left;}\n.head .h-name {font-size: 13px; color: #eee; margin: 0;}\n.head .h-time {font-size: 12.5px; color: #7E829C; margin: 0;}\n.small {font-size: 12.5px; display: inline-block; transform: scale(0.9); -webkit-transform: scale(0.9); transform-origin: left; -webkit-transform-origin: left;}\n.smaller {font-size: 12.5px; display: inline-block; transform: scale(0.8); -webkit-transform: scale(0.8); transform-origin: left; -webkit-transform-origin: left;}\n.bt-text {font-size: 12px;margin: 1.5em 0 0 0}\n.bt-text p {margin: 0}\n</style>\n</head>\n<body>\n<div class=\"wrapper\">\n<header>\n<h2 class=\"title\">\nEven more bizarre than a movie! Russian hackers \"shocked the United States,\" making Biden anxious.\n</h2>\n<h4 class=\"meta\">\n<p class=\"head\">\n<strong class=\"h-name small\">新智元</strong><span class=\"h-time small\">2021-07-06 14:14</span>\n</p>\n</h4>\n</header>\n<article>\n<p>[Introduction] A fearsome hacker group has made new moves. Recently, they launched a massive cyberattack, infecting 1 million systems and paralyzing hundreds of American companies, with the hackers offering $70 million. Biden said he has ordered an FBI investigation. Yesterday, news broke that the United States has ordered an investigation into a ransomware campaign in which hackers have extorted more than $100 million, paralyzing hundreds of businesses in just a few months.</p><p>Their name is: REvil.</p><p>The companies they attacked included<a href=\"https://laohu8.com/S/AAPL\">Apple</a>And Acer, as well as JBS, the world's largest meat processing company. JBS obediently complied and paid it $11 million in Bitcoin.</p><p>Their characteristic is that no matter who the hackers are, they will post the stolen files on a website called Happy Blog.</p><p>On Sunday, REvil made another big ask, posting a universal decryption software key on its website that could decrypt all affected machines and demanding $70 million in exchange for the decryption.</p><p><img src=\"https://static.tigerbbs.com/2d2eed2a36488a230837f33fad82eb4c\" tg-width=\"548\" tg-height=\"287\" referrerpolicy=\"no-referrer\"></p><p>Last Friday (02.07.2021), we launched an attack against MSP vendors. More than 1 million systems were infected. If anyone wants to negotiate a universal decryptor – our price is $70 million (BTC) – we will publicly release the decryptor and decrypt all the victims' files, so everyone will be able to recover from the attack in less than an hour. If you are interested in such a transaction, please contact us according to the instructions in the victim's \"readme\" file.</p><p>This attack appears to be the largest ever launched by REvil. This attack has infected up to 40,000 computers worldwide.</p><p>How did this happen?</p><p><h2>The \"ransom\" reached $70 million, and the 0-day vulnerability became a target of global hacker attacks.</h2>Last week's attacks focused primarily on Kaseya VSA software. Kaseya's VSA is used to monitor and manage the infrastructure, provided by Kaseya as a managed cloud service or through an on-premises VSA server.</p><p><img src=\"https://static.tigerbbs.com/bcd641d2adea115d20fb832537ab54c4\" tg-width=\"1080\" tg-height=\"565\" referrerpolicy=\"no-referrer\"></p><p>The REvil ransomware gang is demanding a $70 million ransom and will release a general-purpose decoder once they receive the money.</p><p><img src=\"https://static.tigerbbs.com/cd2c061bb0ba4a2683657a86078ef4cd\" tg-width=\"548\" tg-height=\"269\" referrerpolicy=\"no-referrer\"></p><p>Kesaya's VSA software allows hosting providers to remotely monitor their customers' IT networks</p><p>Some customers have reported that their VSA software contains numerous 0-day vulnerabilities, which are used as channels for deploying ransomware.</p><p><img src=\"https://static.tigerbbs.com/af531d8b622709312543e8769f266089\" tg-width=\"660\" tg-height=\"347\" referrerpolicy=\"no-referrer\"></p><p>They then use ransomware to lock the data and allow attackers to connect to the host via HTTP access and manually inject malware.</p><p><img src=\"https://static.tigerbbs.com/e751fafa9cf4a07426dea97cc7c44a82\" tg-width=\"1080\" tg-height=\"608\" referrerpolicy=\"no-referrer\"></p><p>\"More than 70 management service providers were affected, resulting in more than 350 organizations being further impacted.\"</p><p>This includes Coop, a supermarket chain in Sweden. The company has temporarily closed about 800 of its stores across the country because the attack affected its cash registers.</p><p><img src=\"https://static.tigerbbs.com/a24a337b7c6d99692cfb2d1c6627d9ca\" tg-width=\"548\" tg-height=\"254\" referrerpolicy=\"no-referrer\"></p><p>Swedish supermarket chain Coop had to temporarily close 800 of its stores due to the attacks.</p><p>Exploiting Kaseya's vulnerabilities to create potential vulnerabilities, the REvil gang certainly didn't forget to boast about successful attacks on MSP vendors and shared news that over a million systems had been infected.</p><p><h2>\"Attracting\" Biden's attention, ordering an FBI investigation, and advising clients not to pay.</h2>Such a large-scale attack has \"received\" attention. Biden has stated that he will investigate the incident, and the FBI hopes that everyone who was hacked will report it to the authorities.</p><p><img src=\"https://static.tigerbbs.com/3d4b3d376621128cd7dc66db53a61a17\" tg-width=\"450\" tg-height=\"300\" referrerpolicy=\"no-referrer\"></p><p>However, in such cases, the FBI has discouraged victims from paying.</p><p><img src=\"https://static.tigerbbs.com/de0b508f1dc225dc83d957aed6dcc987\" tg-width=\"697\" tg-height=\"211\" referrerpolicy=\"no-referrer\"></p><p>Because, according to a report this year, 92% of paid organizations cannot recover all their data; Most victims who take out cash can only partially recover the contents of their encrypted files.</p><p><h2>He once threatened to leak MacBook schematic diagrams and demanded $50 million!</h2>Due to its \"track record,\" REvil is one of the top ten most dangerous cybercrime organizations in the world.</p><p>Prior to this, REvil's famous extortion incident was the theft of Apple product manufacturing secrets in April of this year.</p><p>At the time, the hacking group REvil issued a statement saying that they had hacked Quanta, a Taiwanese manufacturer of products such as MacBooks, and demanded a ransom of $50 million, otherwise it would release sensitive internal documents.</p><p><img src=\"https://static.tigerbbs.com/94ed071c5af49e5abc3f496364341260\" tg-width=\"1012\" tg-height=\"887\" referrerpolicy=\"no-referrer\"></p><p>After Quanta Computer refused to pay the ransom, the hacking group began releasing stolen images during Apple's spring launch event on April 20th (US time) and extorted money from Apple.</p><p>Apple is one of the world's largest companies, and REvil's ability to break in indirectly proves the strength of this criminal gang.</p><p>A cybersecurity firm that specializes in negotiating with criminal hackers says that in the past 90 days alone, his firm has handled 32 cases involving the REvil organization.</p><p><img src=\"https://static.tigerbbs.com/15d07dcd48b9983946ef6e04bb2b79b5\" tg-width=\"548\" tg-height=\"411\" referrerpolicy=\"no-referrer\"></p><p>Hackers invaded Apple suppliers and demanded a ransom of $50 million</p><p>However, in the past, REvil primarily targeted the professional services sector, rather than the technology sector. Therefore, this attack on Apple and its demand for $50 million is very different from its previous approach.</p><p>Negotiation experts say the average ransom paid in the past was also much lower, at nearly $728,000, and after price negotiations, the actual average ransom paid was even lower.</p><p>The cybersecurity company said that, according to rough estimates, the gang has raised a total of $100 million to date. However, this group is also relatively \"easy to negotiate\".</p><p><h2>Russian hackers focus on harming the US.</h2>In addition to extorting money, Russian hackers are \"keen\" to target the United States.</p><p>Two months ago, another hacking group called DarkSide hacked into Colonial Pipeline, the largest fuel Pipeline operator in the United States.</p><p><img src=\"https://static.tigerbbs.com/7848ac8acc903d061227edb37b76ae08\" tg-width=\"950\" tg-height=\"534\" referrerpolicy=\"no-referrer\"></p><p>At the time, nearly 100GB of data was hijacked, and the data could only be retrieved by paying a ransom.</p><p>This directly forced the shutdown of key fuel networks supplying fuel to states along the East Coast of the United States. Moreover, fuel prices in the United States also soared to a new high.</p><p>Ironically, after extorting money, these people actually donated it to a charitable organization.</p>\n<div class=\"bt-text\">\n\n\n<p> source:<a href=\"https://36kr.com/p/1298906657966471\">新智元</a></p>\n\n\n</div>\n</article>\n</div>\n</body>\n</html>\n","type":0,"thumbnail":"https://static.tigerbbs.com/af531d8b622709312543e8769f266089","relate_stocks":{"AAPL":"苹果"},"source_url":"https://36kr.com/p/1298906657966471","is_english":false,"share_image_url":"https://static.laohu8.com/e9f99090a1c2ed51c021029395664489","article_id":"2149535517","content_text":"【导读】令人闻风丧胆的某黑客组织,又有了新的动作。近日,他们发起了超大规模网攻,100 万系统被感染,数百家美国企业瘫痪,而黑客那边开价七千万美元。拜登表示,他已下令FBI调查。\n\n昨日消息,美国已下令调查一个勒索软件活动,该活动背后的黑客已经勒索超过1亿美元,短短数月内令数百家企业陷入瘫痪。\n他们的名字叫:REvil。\n被他们攻击过的公司包括苹果和宏碁,以及全球最大的肉类加工公司JBS等。其中,JBS乖乖就范向其支付了 1100 万美元的比特币。\n他们的特点是,无论被入侵者是谁,他们都会将盗来的文件发布在一个名为Happy Blog的网站上。\n周日,REvil再次狮子大开口,在其网站上发布了一个通用解密软件密钥,可以解密所有受影响的机器,并索要 7000 万美元换取解密。\n\n上周五(02.07.2021)我们对 MSP 供应商发起了一次攻击。超过 100 万的系统被感染。如果有人想就通用解密器进行谈判--我们的价格是 70000000 美元(BTC),我们将公开发布解密器,解密所有受害者的文件,所以每个人都将能够在不到一个小时内从攻击中恢复。如果你对这样的交易感兴趣,请按照受害者的 \"readme\"文件说明与我们联系\n此次攻击似乎是 REvil 有史以来发起的规模最大的一次。此次攻击事件已导致全球多达 4 万台电脑被感染。\n这怎么发生的?\n「赎金」高达 7000 万美元,0-day 漏洞成为全球黑客攻击的目标\n上周攻击主要集中在 Kaseya VSA 软件上。Kaseya 的 VSA 用于监控和管理基础架构,它由 Kaseya 作为托管云服务或通过本地 VSA 服务器提供。\n\nREvil 勒索软件团伙索要7000 万美元的赎金,拿到钱就会发布一个通用的的解码器。\n\nKesaya 的 VSA 软件允许托管服务提供商远程监控其客户的 IT 网络\n有客户表示,其 VSA 软件中存在大量 0-day 漏洞,这些漏洞被用作部署勒索软件的渠道。\n\n然后,他们使用勒索软件锁定数据,并允许攻击者通过 HTTP 访问连接到主机,并手动注入恶意软件。\n\n「有70多个管理服务提供商受到影响,导致350多个组织进一步受到影响」。\n其中包括瑞典的一家连锁超市Coop。该公司已经暂时关闭了其在全国各地的约800家商店,因为这次攻击影响了其收银机。\n\n由于袭击事件,瑞典连锁超市 Coop 不得不暂时关闭其 800 家门店\n利用Kaseya的漏洞来造成潜在的漏洞,REvil团伙当然没忘记吹嘘对MSP供应商的成功攻击,并分享了超过一百万个系统被感染的消息。\n「吸引」拜登注意,令FBI调查,劝客户别付款\n如此大规模的攻击「得到了」重视,拜登都表示要调查这一事件,FBI希望每个被入侵的人都能向当局报警。\n\n不过对此类事件,FBI曾劝阻受害者不要付款。\n\n因为根据今年的一份报告,92% 付费的组织无法恢复所有数据;大多数掏出现金的受害者只能部分恢复其加密文件的内容。\n曾威胁泄露MacBook原理图,索要5000万美元!\n由于「业绩累累」,REvil是世界上十大最危险的网络犯罪组织之一。\n在此之前,REvil的著名勒索事件是今年4月份的盗窃苹果产品制造机密。\n当时,黑客组织REvil发布声明称,他们已入侵MacBook等产品的生产商台湾广达电脑(Quanta),要求提供5000万美元的赎金,否则它将发布敏感的内部文件。\n\n广达电脑拒绝支付赎金后,该黑客组织在美国时间4月20日苹果春季发布活动期间就开始曝光被盗的图片,并向继续苹果勒索。\n苹果是世界上最大的公司之一,REvil能够攻进进来从侧面证明了这个犯罪团伙的强大。\n专门与犯罪黑客进行谈判的网络安全公司表示,仅在过去90天内,他的公司已处理了32起REvil组织的案件。\n\n黑客入侵了苹果供应商,并要求交出5000万美元赎金\n不过,过去REvil主要攻击专业服务领域,而非技术领域。所以这次攻击苹果并索要5千万美元与其之前的做法大不相同。\n谈判专家表示,过去的平均赎金也低得多,当时只有近728000美元,而在价格谈判之后,实际支付的平均赎金比这还要低。\n网络安全公司表示,根据粗略估计,该团伙迄今已筹集了总计1亿美元。不过这个团伙也比较「好商量」。\n俄罗斯黑客,专注坑「美」\n除了勒索钱财,俄罗斯黑客「热衷」于搞美国。\n2个月前,另一个名为DarkSide的黑客团伙黑了入侵美国最大的燃料管道运营商科洛尼尔公司(Colonial Pipeline)。\n\n当时,约有近100GB的数据被劫持,只有交付赎金才能重新拿回数据。\n这直接让美国东部沿海各州供油的关键燃油网络被迫关闭。不仅如此,美国燃油价格也随之飙升创了新高。\n戏剧性的是,这帮人勒索钱财之后,居然还捐给了一个慈善组织。","news_type":1,"symbols_score_info":{"AAPL":0.9}},"isVote":1,"tweetType":1,"viewCount":4456,"authorTweetTopStatus":1,"verified":2,"comments":[],"imageCount":0,"langContent":"EN","totalScore":0}],"defaultTab":"posts","isTTM":true}