8000 ¶à¸öÖµµÃÐÅÈÎµÄÆ·ÅÆÓòÃû±»½Ù³Ö²¢´ó¹æÄ£·¢ËÍÀ¬»øÓʼþ

°ä²¼¹¦·ò 2024-02-28
1. 8000 ¶à¸öÖµµÃÐÅÈÎµÄÆ·ÅÆÓòÃû±»½Ù³Ö²¢´ó¹æÄ£·¢ËÍÀ¬»øÓʼþ


2ÔÂ26ÈÕ£¬Guardio Labs ÔÚ¸ú×ÙЭµ÷µÄ¶ñÒâ»î¶¯£¬¸Ã»î¶¯ÖÁÉÙ×Ô 2022 Äê 9 ÔÂÒÔÀ´Ò»ÏòÔÚ³ÖÐø£¬ÃûΪ SubdoMailing  ¡£ÊôÓںϷ¨Æ·Åƺͻú¹¹µÄ 8,000 ¶à¸öÓòÃûºÍ 13,000 ¸ö×ÓÓòÃûÒѱ»½Ù³Ö£¬×÷ΪÀ¬»øÓʼþÀ©É¢ºÍµã»÷Ç®±Ò»¯µÄ¸´ÔÓ·Ö·¢¼Ü¹¹µÄÒ»²¿ÃÅ  ¡£Õâ¼ÒÒÔÉ«Áа²È«¹«Ë¾½«Õâ´Î»î¶¯¹éÒòÓÚÒ»¸öÃûΪResurrecAdsµÄÍþвÐÐΪÕߣ¬¶àËùÖÜÖª£¬¸ÃÐÐΪÕß»áÐÂÉú´óÆ·ÅÆ»ò´ÓÊôÓÚ´óÆ·ÅÆµÄËÀÓòÃû£¬×îÖÕÖ¸±êÊǰѳÖÊý×Ö¸æ°×Éú̬ϵͳÒÔ»ñÈ¡·¸·¨ÊÕÒæ  ¡£ÕâЩ×ÓÓòÃûÊôÓÚ»ò´ÓÊôÓÚ ACLU¡¢eBay¡¢Lacoste¡¢Marvel¡¢McAfee¡¢MSN¡¢Pearson¡¢PwC¡¢Swatch¡¢Symantec¡¢The Economist¡¢UNICEF ºÍ VMware µÈ´óÆ·ÅÆºÍ×éÖ¯  ¡£


https://thehackernews.com/2024/02/8000-subdomains-of-trusted-brands.html


2. Booking.com ¼ÙÒâ»î¶¯£ºAgent Tesla ¶ñÒâÈí¼þ·ÖÎö


2ÔÂ26ÈÕ£¬¸Ã»î¶¯ÀûÓà Booking.com µÄÆ·ÅÆÃûÓþÀ´´«²¼ Agent Tesla£¬ÕâÊÇÒ»ÖÖ¶àÖ°ÄÜÔ¶³Ì½Ó¼ûľÂí ( RAT )  ¡£¹¥»÷ÕßÀûÓÃÓë Booking.com ÓйصÄÐÅÀµ£¬Ôì×÷¿´ËƺϷ¨ÍË¿î֪ͨµÄÍøÂç´¹µöµç×ÓÓʼþ  ¡£Ô̺¬ PDF ¸½¼þ»áÒªÇóÊÕ¼þÈ˲鳭Ëù¸½ PDF ÖеĿ¨¶ÔÕ˵¥  ¡£ÕâÒ»¾«ÐÄÉè¼ÆµÄ´òËãµÄ×îÖÕÁ˾ÖÊDz¿ÊðÁËAgent Tesla¶ñÒâÈí¼þ  ¡£¸Ã¶ÔÊÔìðÍ·²ÉÈ¡¶ñÒâÐж¯ÇÔȡƾ֤ºÍÓ×ÎÒÊý¾Ý£¬½«Æä²»ÒåÖ®²Æ´«Êäµ½¸öÈË Telegram ̸ÌìÊÒ  ¡£Ëü²¢²»Ö¹ÓÚ´Ë £»¸Ã¶ñÒâÈí¼þͨ¹ý¶î±íµÄ PowerShell ¾ç±¾È·±£ÆäÓÆ¾ÃÐÔ£¬²¢²»ÐݸĽøÆäÕ½ÊõÒÔÔÚÊÜϰȾµÄϵͳÖÐά³Ö°²Éíµã  ¡£


https://securityonline.info/booking-com-impersonation-campaign-agent-tesla-malware-analysis/


3. ALPHV/BlackCat ¶Ô Change Healthcare ÍøÂç¹¥»÷ÕÆ¹Ü


2ÔÂ26ÈÕ£¬¾Ý±¨Â·£¬ALPHV/BlackCat ÀÕË÷Èí¼þÍÅ»ï¶Ô Change Healthcare ´ó¹æÄ£ÍøÂç¹¥»÷ÕÆ¹Ü£¬¸Ã¹¥»÷×ÔÉÏÖÜÒÔÀ´ÒѾ­ÇÖÈÅÁËÃÀ¹ú¸÷µØµÄÒ©µê  ¡£¾Ý·͸ÉçÔ®Òý¡°Á½ÃûÖªÁµÈËÊ¿¡±µÄ»°³Æ£¬³ôÃûÔ¶ÑïµÄÀÕË÷Èí¼þ¼´·þÎñ²Ù×÷ÊǽáºÏ½¡È«ÆìÏÂÆóÒµÌáÒé¹¥»÷µÄÄ»ºóºÚÊÖ  ¡£RegisterÉÐδ¶ÀÁ¢È·ÈÏ ALPHV ²Î¼ÓÁËÕâ´ÎÈëÇÖ  ¡£Change Healthcare ΪҽÁÆ»ú¹¹Ìṩ¿í·ºµÄ IT ·þÎñ£¬Ô̺¬ÈÃÒ©·¿²é³­»¼ÕßÓÃÒ©×ʸñ²¢È·¶¨±£ÏÕÁìÓòµÄÈí¼þ  ¡£Æä¿Í»§Ô̺¬ÃÀ¹úÁ½¼Ò×î´óµÄÒ©µê¡ª¡ªCVS ºÍÎÖ¶û¸ñÁÖ¡ª¡ªÕâÁ½¼ÒÒ©µê¶¼¸Ð´¥µ½ÁËÍ£µçµÄ²»Á¼Ó°Ïì  ¡£Õâ¼Ò½¡È«¿Æ¼¼¹«Ë¾ÓÚ 2 Ô 21 ÈÕ³õ´ÎÅû¶ÁËÕâÒ»·ì϶£¬²¢Òò¶ø¹Ø¹ØÁ˲¿ÃÅ IT ϵͳ  ¡£ÖÜÎ壬ÃÀ¹úÒ©¼ÁʦЭ»á°µÊ¾£¬ÓÉÓÚÍøÂç¹¥»÷£¬È«¹ú¸÷µØµÄÒ©·¿ÎÞ·¨´«Ëͱ£ÏÕË÷Åâ  ¡£ 


https://www.theregister.com/2024/02/26/alphv_healthcare_unitedhealth/


4. UAC-0184 ʹÓà Remcos RAT Õë¶Ô·ÒÀ¼¾³ÄÚµÄÎÚ¿ËÀ¼ÊµÌå


2ÔÂ27ÈÕ£¬±»×·×ÙΪ UAC-0184 µÄÍþвÐÐΪÕßÒ»ÏòÔÚʹÓÃÒþдÊõ¼¼Êõ£¬Í¨¹ýÃûΪ IDAT Loader µÄÏà¶Ô½ÏеĶñÒâÈí¼þÏòλÓÚ·ÒÀ¼µÄÎÚ¿ËÀ¼Ö¸±ê´«ËÍ Remcos Ô¶³Ì½Ó¼ûľÂí (RAT)  ¡£Ö»¹ÜµÐÊÖ×î³õÕë¶ÔµÄÊÇÎÚ¿ËÀ¼¾³ÄÚµÄʵÌ壬µ«·ÀÓù´ëÊ©¹ÊÕÏÁËÓÐÐ§ÔØºÉµÄ½»¸¶  ¡£Æ¾¾Ý Morphisec Íþв³¢ÊÔÊÒ½ñÌìµÄ·ÖÎö£¬Õâµ¼ÖÂÁËËæºó¶Ô´úÌæÖ¸±êµÄËÑË÷  ¡£¹ÌÈ» Morphisec Òò¿Í»§»úÃܶøÃ»ÓÐй©»î¶¯Ï¸½Ú£¬µ«×êÑÐÈËÔ±Ö¸³ö Dark Reading¾Ý³ÆÓë UAC-0148 ½øÐеIJ¢ÐлÓйØ£¬¸Ã»î¶¯Ê¹Óõç×ÓÓʼþºÍÓã²æÊ½ÍøÂç´¹µö×÷Ϊ³õʼ½Ó¼ûý½é£¬²¢ÒÔÎÚ¿ËÀ¼¾üÊÂÈËԱΪָ±ê£¬ÒÔÌṩÕ÷ѯΪµö¶ü  ¡£ÒÔÉ«Áйú·À¾ü (IDF) µÄ½ÇÉ«  ¡£ÆäÖ¸±êÊÇÍøÂç¼äµý»î¶¯£ºÍøÂç·¸×ï·Ö×ÓʹÓà Remcos£¨¡°Ô¶³Ì½ÚÔìºÍ¼à¶½¡±µÄËõд£©RAT À´Î´¾­ÊÚȨ½Ó¼ûÊܺ¦ÕßµÄÍÆËã»ú¡¢Ô¶³Ì½ÚÔìÊÜϰȾµÄϵͳ¡¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡¢Ö´ÐкÅÁîµÈ  ¡£


https://www.darkreading.com/cyberattacks-data-breaches/uac-0184-targets-ukrainian-entity-finland-remcos-rat


5. ¶íÂÞ˹ºÚ¿ÍÍÅ»ïͨ¹ýÐÝÃßÕÊ»§¶Ô×¼ÔÆ»ù´¡ÉèÊ©


2ÔÂ26ÈÕ£¬ÃÀ¹ú¡¢¼ÓÄôó¡¢Ó¢¹ú¡¢°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄÍøÂ簲ȫºÍ·¨ÂÉ»ú¹¹°ä²¼½áºÏ¾¯±¨£¬ºôÓõ´¹Î£¹Ø×¢Óë APT29/Cozy Bear/Midnight Blizzard£¨Ò»¸ö³ôÃûÔ¶ÑïµÄºÚ¿Í×éÖ¯£©ÓйصÄ×îÐÂÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½ (TTP)  ¡£¶íÂÞ˹µý±¨²¿ÃÅ£¨SVR£©  ¡£¾Ý¹Û²ì£¬SVR ²Î¼ÓÕß²¢Ã»ÓÐÀûÓÃÈí¼þ·ì϶À´¹¥»÷±¾µØ»ù´¡ÉèÊ©£¬¶øÊÇÌáÒ鱩Á¦ÆÆ½âºÍÃÜÂëÅçÉä¹¥»÷À´·ÛËé·þÎñÕÊ»§£¬ÒÔ¼°Õë¶ÔǰԱ¹¤µÄÐÝÃßÕÊ»§À´½Ó¼ûÖ¸±ê×éÖ¯µÄ»·¾³  ¡£´Ë±í£¬»¹·¢ÏÖ³ôÃûÔ¶ÑïµÄ APT ×é֯ʹÓÃÁîÅÆ½Ó¼ûÊܺ¦ÕßÕÊ»§£¬²¢Ê¹ÓÃÒ»ÖÖ³ÆÎª¡°MFA ºäÕ¨¡±»ò¡°MFA ί¶Ù¡±µÄ¼¼ÊõÈÆ¹ý¶à³ÁÉí·ÝÑéÖ¤ (MFA)  ¡£³õ´Î½Ó¼ûºó£¬¹¥»÷Õßͨ³ £»á½«×Ô¼ºµÄÉ豸ע²áµ½Êܺ¦ÕßµÄÍøÂ磬²¢²¿Êð¸´ÔӵĹ¥»÷ºó¹¤¾ß  ¡£´Ë±í£¬ºÚ¿Í»¹ÒÀ¸½×¡Õ¬´úÀíÀ´°µ²ØÆä¶ñÒâ»î¶¯£¬Ê¹Á÷Á¿¿´ÆðÀ´ÏñÊÇÀ´×Ôסլ¿í´ø¿Í»§µÄ IP µØÖ·  ¡£


https://www.securityweek.com/russian-cyberspies-targeting-cloud-infrastructure-via-dormant-accounts/


6. Anonymous ËÕµ¤ÍƹãÐ嵀 DDoS ½©Ê¬ÍøÂçSkynet-GodzillaBotnet


2ÔÂ26ÈÕ£¬¾ÝÏàʶ£¬Ò»¸öÃûΪ¡°ÄäÃûËÕµ¤¡±µÄ×éÖ¯ÔÚ»ý¼«ÍƹãÒ»ÖÖÃûΪ¡°Skynet-GodzillaBotnet¡±µÄÐÂÐÍÉ¢²¼Ê½»Ø¾ø·þÎñ (DDoS) ½©Ê¬ÍøÂç·þÎñ  ¡£ÍøÉÏÁ÷´«µÄÒ»Ôò¸æ°×չʾÁË´øÓÓ×°SKYNET¡±×ÖÑùµÄºìÁú±êÖ¾  ¡£¸Ã·þÎñ±»Ðû´«ÎªÖ´ÐÐDDoS ¹¥»÷µÄ׳´ó¹¤¾ß£¬¸Ã×éÖ¯Ðû³ÆÍ¨¹ý½«ÆäÈ¨ÊÆÓëÁíÒ»¸öʵÌå¹é²¢À´¼ÓÇ¿ÆäÖ°ÄÜ  ¡£¡¶ÖðÈÕ°µÍø¡·Öз¢Ïֵĸæ°×Ã÷È·Ö¸³ö£¬ËüÌṩ½©Ê¬ÍøÂçµÄ½Ó¼ûȨÏÞ£¬¼ÛֵΪһÌì 100 ÃÀÔª¡¢Ò»ÖÜ 600 ÃÀÔª¡¢Ò»¸öÔ 1700 ÃÀÔª  ¡£Anonymous ËÕµ¤ÒÔÆä¼¤½øµÄ Web DDoS ¹¥»÷¶øÎÅÃû£¬ÆäÖÐÔ̺¬½»ÌæµÄ UDP ºÍ SYN ºéË®¹¥»÷  ¡£ÕâЩ¹¥»÷´ÓÊýÒÔÍò¼ÆµÄΨһԴ IP µØÖ·ÌáÒ飬UDP Á÷Á¿¸ß´ï 600Gbps£¬HTTPS ÒªÇóºéË®·åÖµ¿É´ïÿÃëÊý°ÙÍò¸öÒªÇó  ¡£


https://gbhackers.com/anonymous-sudan-new-ddos-botnet-warning/