8000 ¶à¸öÖµµÃÐÅÈÎµÄÆ·ÅÆÓòÃû±»½Ù³Ö²¢´ó¹æÄ£·¢ËÍÀ¬»øÓʼþ
°ä²¼¹¦·ò 2024-02-282ÔÂ26ÈÕ£¬Guardio Labs ÔÚ¸ú×Ùе÷µÄ¶ñÒâ»î¶¯£¬¸Ã»î¶¯ÖÁÉÙ×Ô 2022 Äê 9 ÔÂÒÔÀ´Ò»ÏòÔÚ³ÖÐø£¬ÃûΪ SubdoMailing¡£ÊôÓںϷ¨Æ·Åƺͻú¹¹µÄ 8,000 ¶à¸öÓòÃûºÍ 13,000 ¸ö×ÓÓòÃûÒѱ»½Ù³Ö£¬×÷ΪÀ¬»øÓʼþÀ©É¢ºÍµã»÷Ç®±Ò»¯µÄ¸´ÔÓ·Ö·¢¼Ü¹¹µÄÒ»²¿ÃÅ¡£Õâ¼ÒÒÔÉ«Áа²È«¹«Ë¾½«Õâ´Î»î¶¯¹éÒòÓÚÒ»¸öÃûΪResurrecAdsµÄÍþвÐÐΪÕߣ¬¶àËùÖÜÖª£¬¸ÃÐÐΪÕß»áÐÂÉú´óÆ·ÅÆ»ò´ÓÊôÓÚ´óÆ·ÅÆµÄËÀÓòÃû£¬×îÖÕÖ¸±êÊǰѳÖÊý×Ö¸æ°×Éú̬ϵͳÒÔ»ñÈ¡·¸·¨ÊÕÒæ¡£ÕâЩ×ÓÓòÃûÊôÓÚ»ò´ÓÊôÓÚ ACLU¡¢eBay¡¢Lacoste¡¢Marvel¡¢McAfee¡¢MSN¡¢Pearson¡¢PwC¡¢Swatch¡¢Symantec¡¢The Economist¡¢UNICEF ºÍ VMware µÈ´óÆ·ÅÆºÍ×éÖ¯¡£
https://thehackernews.com/2024/02/8000-subdomains-of-trusted-brands.html
2. Booking.com ¼ÙÒâ»î¶¯£ºAgent Tesla ¶ñÒâÈí¼þ·ÖÎö
2ÔÂ26ÈÕ£¬¸Ã»î¶¯ÀûÓà Booking.com µÄÆ·ÅÆÃûÓþÀ´´«²¼ Agent Tesla£¬ÕâÊÇÒ»ÖÖ¶àÖ°ÄÜÔ¶³Ì½Ó¼ûľÂí ( RAT )¡£¹¥»÷ÕßÀûÓÃÓë Booking.com ÓйصÄÐÅÀµ£¬Ôì×÷¿´ËƺϷ¨ÍË¿î֪ͨµÄÍøÂç´¹µöµç×ÓÓʼþ¡£Ô̺¬ PDF ¸½¼þ»áÒªÇóÊÕ¼þÈ˲é³Ëù¸½ PDF ÖеĿ¨¶ÔÕ˵¥¡£ÕâÒ»¾«ÐÄÉè¼ÆµÄ´òËãµÄ×îÖÕÁ˾ÖÊDz¿ÊðÁËAgent Tesla¶ñÒâÈí¼þ¡£¸Ã¶ÔÊÔìðÍ·²ÉÈ¡¶ñÒâÐж¯ÇÔȡƾ֤ºÍÓ×ÎÒÊý¾Ý£¬½«Æä²»ÒåÖ®²Æ´«Êäµ½¸öÈË Telegram ̸ÌìÊÒ¡£Ëü²¢²»Ö¹ÓÚ´Ë£»¸Ã¶ñÒâÈí¼þͨ¹ý¶î±íµÄ PowerShell ¾ç±¾È·±£ÆäÓÆ¾ÃÐÔ£¬²¢²»ÐݸĽøÆäÕ½ÊõÒÔÔÚÊÜϰȾµÄϵͳÖÐά³Ö°²Éíµã¡£
https://securityonline.info/booking-com-impersonation-campaign-agent-tesla-malware-analysis/
3. ALPHV/BlackCat ¶Ô Change Healthcare ÍøÂç¹¥»÷ÕÆ¹Ü
2ÔÂ26ÈÕ£¬¾Ý±¨Â·£¬ALPHV/BlackCat ÀÕË÷Èí¼þÍÅ»ï¶Ô Change Healthcare ´ó¹æÄ£ÍøÂç¹¥»÷ÕÆ¹Ü£¬¸Ã¹¥»÷×ÔÉÏÖÜÒÔÀ´ÒѾÇÖÈÅÁËÃÀ¹ú¸÷µØµÄÒ©µê¡£¾Ý·͸ÉçÔ®Òý¡°Á½ÃûÖªÁµÈËÊ¿¡±µÄ»°³Æ£¬³ôÃûÔ¶ÑïµÄÀÕË÷Èí¼þ¼´·þÎñ²Ù×÷ÊǽáºÏ½¡È«ÆìÏÂÆóÒµÌáÒé¹¥»÷µÄÄ»ºóºÚÊÖ¡£RegisterÉÐδ¶ÀÁ¢È·ÈÏ ALPHV ²Î¼ÓÁËÕâ´ÎÈëÇÖ¡£Change Healthcare ΪҽÁÆ»ú¹¹Ìṩ¿í·ºµÄ IT ·þÎñ£¬Ô̺¬ÈÃÒ©·¿²é³»¼ÕßÓÃÒ©×ʸñ²¢È·¶¨±£ÏÕÁìÓòµÄÈí¼þ¡£Æä¿Í»§Ô̺¬ÃÀ¹úÁ½¼Ò×î´óµÄÒ©µê¡ª¡ªCVS ºÍÎÖ¶û¸ñÁÖ¡ª¡ªÕâÁ½¼ÒÒ©µê¶¼¸Ð´¥µ½ÁËÍ£µçµÄ²»Á¼Ó°Ïì¡£Õâ¼Ò½¡È«¿Æ¼¼¹«Ë¾ÓÚ 2 Ô 21 ÈÕ³õ´ÎÅû¶ÁËÕâÒ»·ì϶£¬²¢Òò¶ø¹Ø¹ØÁ˲¿ÃÅ IT ϵͳ¡£ÖÜÎ壬ÃÀ¹úÒ©¼Áʦлᰵʾ£¬ÓÉÓÚÍøÂç¹¥»÷£¬È«¹ú¸÷µØµÄÒ©·¿ÎÞ·¨´«Ëͱ£ÏÕË÷Åâ¡£
https://www.theregister.com/2024/02/26/alphv_healthcare_unitedhealth/
4. UAC-0184 ʹÓà Remcos RAT Õë¶Ô·ÒÀ¼¾³ÄÚµÄÎÚ¿ËÀ¼ÊµÌå
2ÔÂ27ÈÕ£¬±»×·×ÙΪ UAC-0184 µÄÍþвÐÐΪÕßÒ»ÏòÔÚʹÓÃÒþдÊõ¼¼Êõ£¬Í¨¹ýÃûΪ IDAT Loader µÄÏà¶Ô½ÏеĶñÒâÈí¼þÏòλÓÚ·ÒÀ¼µÄÎÚ¿ËÀ¼Ö¸±ê´«ËÍ Remcos Ô¶³Ì½Ó¼ûľÂí (RAT)¡£Ö»¹ÜµÐÊÖ×î³õÕë¶ÔµÄÊÇÎÚ¿ËÀ¼¾³ÄÚµÄʵÌ壬µ«·ÀÓù´ëÊ©¹ÊÕÏÁËÓÐÐ§ÔØºÉµÄ½»¸¶¡£Æ¾¾Ý Morphisec Íþв³¢ÊÔÊÒ½ñÌìµÄ·ÖÎö£¬Õâµ¼ÖÂÁËËæºó¶Ô´úÌæÖ¸±êµÄËÑË÷¡£¹ÌÈ» Morphisec Òò¿Í»§»úÃܶøÃ»ÓÐй©»î¶¯Ï¸½Ú£¬µ«×êÑÐÈËÔ±Ö¸³ö Dark Reading¾Ý³ÆÓë UAC-0148 ½øÐеIJ¢ÐлÓйأ¬¸Ã»î¶¯Ê¹Óõç×ÓÓʼþºÍÓã²æÊ½ÍøÂç´¹µö×÷Ϊ³õʼ½Ó¼ûý½é£¬²¢ÒÔÎÚ¿ËÀ¼¾üÊÂÈËԱΪָ±ê£¬ÒÔÌṩÕ÷ѯΪµö¶ü¡£ÒÔÉ«Áйú·À¾ü (IDF) µÄ½ÇÉ«¡£ÆäÖ¸±êÊÇÍøÂç¼äµý»î¶¯£ºÍøÂç·¸×ï·Ö×ÓʹÓà Remcos£¨¡°Ô¶³Ì½ÚÔìºÍ¼à¶½¡±µÄËõд£©RAT À´Î´¾ÊÚȨ½Ó¼ûÊܺ¦ÕßµÄÍÆËã»ú¡¢Ô¶³Ì½ÚÔìÊÜϰȾµÄϵͳ¡¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡¢Ö´ÐкÅÁîµÈ¡£
https://www.darkreading.com/cyberattacks-data-breaches/uac-0184-targets-ukrainian-entity-finland-remcos-rat
5. ¶íÂÞ˹ºÚ¿ÍÍÅ»ïͨ¹ýÐÝÃßÕÊ»§¶Ô×¼ÔÆ»ù´¡ÉèÊ©
2ÔÂ26ÈÕ£¬ÃÀ¹ú¡¢¼ÓÄôó¡¢Ó¢¹ú¡¢°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄÍøÂ簲ȫºÍ·¨ÂÉ»ú¹¹°ä²¼½áºÏ¾¯±¨£¬ºôÓõ´¹Î£¹Ø×¢Óë APT29/Cozy Bear/Midnight Blizzard£¨Ò»¸ö³ôÃûÔ¶ÑïµÄºÚ¿Í×éÖ¯£©ÓйصÄ×îÐÂÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½ (TTP)¡£¶íÂÞ˹µý±¨²¿ÃÅ£¨SVR£©¡£¾Ý¹Û²ì£¬SVR ²Î¼ÓÕß²¢Ã»ÓÐÀûÓÃÈí¼þ·ì϶À´¹¥»÷±¾µØ»ù´¡ÉèÊ©£¬¶øÊÇÌáÒ鱩Á¦ÆÆ½âºÍÃÜÂëÅçÉä¹¥»÷À´·ÛËé·þÎñÕÊ»§£¬ÒÔ¼°Õë¶ÔǰԱ¹¤µÄÐÝÃßÕÊ»§À´½Ó¼ûÖ¸±ê×éÖ¯µÄ»·¾³¡£´Ë±í£¬»¹·¢ÏÖ³ôÃûÔ¶ÑïµÄ APT ×é֯ʹÓÃÁîÅÆ½Ó¼ûÊܺ¦ÕßÕÊ»§£¬²¢Ê¹ÓÃÒ»ÖÖ³ÆÎª¡°MFA ºäÕ¨¡±»ò¡°MFA ί¶Ù¡±µÄ¼¼ÊõÈÆ¹ý¶à³ÁÉí·ÝÑéÖ¤ (MFA)¡£³õ´Î½Ó¼ûºó£¬¹¥»÷Õßͨ³£»á½«×Ô¼ºµÄÉ豸ע²áµ½Êܺ¦ÕßµÄÍøÂ磬²¢²¿Êð¸´ÔӵĹ¥»÷ºó¹¤¾ß¡£´Ë±í£¬ºÚ¿Í»¹ÒÀ¸½×¡Õ¬´úÀíÀ´°µ²ØÆä¶ñÒâ»î¶¯£¬Ê¹Á÷Á¿¿´ÆðÀ´ÏñÊÇÀ´×Ôסլ¿í´ø¿Í»§µÄ IP µØÖ·¡£
https://www.securityweek.com/russian-cyberspies-targeting-cloud-infrastructure-via-dormant-accounts/
6. Anonymous ËÕµ¤ÍƹãÐ嵀 DDoS ½©Ê¬ÍøÂçSkynet-GodzillaBotnet
2ÔÂ26ÈÕ£¬¾ÝÏàʶ£¬Ò»¸öÃûΪ¡°ÄäÃûËÕµ¤¡±µÄ×éÖ¯ÔÚ»ý¼«ÍƹãÒ»ÖÖÃûΪ¡°Skynet-GodzillaBotnet¡±µÄÐÂÐÍÉ¢²¼Ê½»Ø¾ø·þÎñ (DDoS) ½©Ê¬ÍøÂç·þÎñ¡£ÍøÉÏÁ÷´«µÄÒ»Ôò¸æ°×չʾÁË´øÓÓ×°SKYNET¡±×ÖÑùµÄºìÁú±êÖ¾¡£¸Ã·þÎñ±»Ðû´«ÎªÖ´ÐÐDDoS ¹¥»÷µÄ׳´ó¹¤¾ß£¬¸Ã×éÖ¯Ðû³ÆÍ¨¹ý½«ÆäÈ¨ÊÆÓëÁíÒ»¸öʵÌå¹é²¢À´¼ÓÇ¿ÆäÖ°ÄÜ¡£¡¶ÖðÈÕ°µÍø¡·Öз¢Ïֵĸæ°×Ã÷È·Ö¸³ö£¬ËüÌṩ½©Ê¬ÍøÂçµÄ½Ó¼ûȨÏÞ£¬¼ÛֵΪһÌì 100 ÃÀÔª¡¢Ò»ÖÜ 600 ÃÀÔª¡¢Ò»¸öÔ 1700 ÃÀÔª¡£Anonymous ËÕµ¤ÒÔÆä¼¤½øµÄ Web DDoS ¹¥»÷¶øÎÅÃû£¬ÆäÖÐÔ̺¬½»ÌæµÄ UDP ºÍ SYN ºéË®¹¥»÷¡£ÕâЩ¹¥»÷´ÓÊýÒÔÍò¼ÆµÄΨһԴ IP µØÖ·ÌáÒ飬UDP Á÷Á¿¸ß´ï 600Gbps£¬HTTPS ÒªÇóºéË®·åÖµ¿É´ïÿÃëÊý°ÙÍò¸öÒªÇó¡£
https://gbhackers.com/anonymous-sudan-new-ddos-botnet-warning/


¾©¹«Íø°²±¸11010802024551ºÅ