Horabot¶ñÒâÈí¼þÕë¶ÔÀ­ÃÀ¶à¹úWindowsÓû§ÌáÒéд¹µö¹¥»÷

°ä²¼¹¦·ò 2025-05-15

1. Horabot¶ñÒâÈí¼þÕë¶ÔÀ­ÃÀ¶à¹úWindowsÓû§ÌáÒéд¹µö¹¥»÷


5ÔÂ14ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖÁËÒ»³¡Õë¶ÔÀ­¶¡ÃÀÖÞ¹ú¶ÈWindowsÓû§µÄд¹µö¹¥»÷»î¶¯¡£Õâ´Î»î¶¯ÖØÒªÕë¶ÔÄ«Î÷¸ç¡¢Î£µØÂíÀ­¡¢¸çÂ×±ÈÑÇ¡¢ÃØÂ³¡¢ÖÇÀûºÍ°¢¸ùÍ¢µÈ¹ú£¬ÀûÓÃÃûΪHorabotµÄ¶ñÒâÈí¼þ·¢Õ¹¹¥»÷¡£¸Ã»î¶¯ÓÚ2025Äê4Ô±»¹Û²âµ½£¬ÖØÒªÕë¶ÔÎ÷°àÑÀÓïÓû§¡£ÒÔ·¢Æ±Îªµö¶ü£¬Í¨¹ý´¹µöÓʼþÓÕʹÓû§´ò¿ªÔ̺¬PDFÎĵµµÄZIPѹËõ°ü£¬ÊµÔòÄÚº¬¶ñÒâHTMLÎļþ£¬ÓÃÓÚÏνÓÔ¶³Ì·þÎñÆ÷ÏÂÔØµÚ¶þ½×¶Î¶ñÒâÔØºÉ¡£µÚ¶þ½×¶ÎÔØºÉΪÔ̺¬HTMLÀûÓ÷¨Ê½£¨HTA£©ÎļþµÄZIPѹËõ°ü£¬¸ÃÎļþ¼ÓÔØÔ¶³Ì·þÎñÆ÷Íйܵľ籾£¬¾ç±¾×¢Èë±í²¿VBScript´úÂëÖ´ÐÐһϵÁмì²â£¬ÈôϵͳװÖÃAvastɱ¶¾Èí¼þ»ò´¦ÓÚÐé¹¹»·¾³ÔòÖÕÖ¹¹¥»÷¡£Ö®ºó£¬VBScript»áÍøÂç»ù´¡ÏµÍ³ÐÅÏ¢²¢±í´«ÖÁÔ¶³Ì·þÎñÆ÷£¬Í¬Ê±»ñÈ¡¶î±íÔØºÉ£¬Ô̺¬¿ªÊÍÒøÐÐľÂíµÄAutoIt¾ç±¾ºÍ´«²¼´¹µöÓʼþµÄPowerShell¾ç±¾¡£´Ë±í£¬Horabot»¹ÄÜ´Ó¶àÖÖä¯ÀÀÆ÷ÇÔÈ¡ÓйØÊý¾Ý£¬³ýÊý¾ÝÇÔÈ¡±í£¬»¹¼à¿ØÊܺ¦ÕßÐÐΪ£¬×¢ÈëαÔ쵯´°ÒÔÇÔÈ¡Ãô¸ÐµÇ¼ƾ֤¡£


https://thehackernews.com/2025/05/horabot-malware-targets-6-latin.html


2. ¹È¸èÖҸ桰·ÖÉ¢Ö©Ö롱ºÚ¿Íת¹¥ÃÀ¹úÁãÊÛÉÌ


5ÔÂ14ÈÕ£¬¹È¸è½ñÈÕÖҸ棬ʹÓá°·ÖÉ¢Ö©Ö롱£¨Scattered Spider£¬Ò²³ÆUNC3944µÈ£©Õ½Êõ¹¥»÷Ó¢¹úÁãÊÛÁ¬ËøµêµÄºÚ¿Í£¬Òѽ«Ö¸±êתÏòÃÀ¹úÁãÊÛÉÌ¡£¹È¸èÍþвµý±¨¼¯ÍÅÊ×ϯ·ÖÎöʦԼº²¡¤ºÕ¶û¿üË¹ÌØ°µÊ¾£¬ÃÀ¹úÁãÊÛÒµÕý³ÉΪÀÕË÷Èí¼þºÍڲƭÀÕË÷Ðж¯µÄÖ¸±ê£¬ÒÉ»óÓë¡°·ÖÉ¢Ö©Ö롱ÓйØ¡£¸Ã×éÖ¯³Ö¾ÃƧ¾²ºóתÏòÓ¢¹úÁãÊÛÒµ£¬Ô¤¼Æ¶ÌÆÚÄÚÈÔ»áÒÔ´ËΪָ±ê¡£Ó¢¹úÁãÊÛ¾ÞÍ·Âêɯ°Ù»õÔøÔâÀÕË÷Èí¼þ¹¥»÷£¬¹¥»÷ÕßʹÓÃDragonForce¼ÓÃÜÆ÷¼ÓÃÜVMware ESXiÖ÷»úÉϵÄÐé¹¹»ú£¬Õâ´Î¹¥»÷±»¹é×ïÓÚ¡°·ÖÉ¢Ö©Ö롱¡£´Ë±í£¬ºÏ×÷ÉçºÍ¹þÂ޵°ٻõ¹«Ë¾Ò²±ðÀëÔâ·êÍøÂç¹¥»÷£¬Ç°ÕßÊý¾Ý±»ÇÔ£¬ºóÕß±»ÆÈÏÞ¶ÈÍøÕ¾»¥ÁªÍø½Ó¼û¡£DragonForceÀÕË÷Èí¼þ×éÖ¯°ä·¢¶ÔÕâÈýÆð¹¥»÷ÕÆ¹Ü£¬²ß¶¯ÕßʹÓÃÁËÓë¡°·ÖÉ¢Ö©Ö롱һÑùµÄÉç»á¹¤³ÌѧսÊõ¡£¡°·ÖÉ¢Ö©Ö롱ÊÇһȺÁ÷¶¯µÄÍþвÐÐΪÕߣ¬ÒÔ¸´ÔÓµÄÉç»á¹¤³Ì¹¥»÷ÈëÇÖÈ«Çò³ÛÃû×éÖ¯¶øÎÅÃû£¬¹¥»÷·½Ê½Éæ¼°ÍøÂç´¹µö¡¢SIM¿¨»¥»»¡¢MFAºäÕ¨µÈ¡£²¿ÃÅ¡°·ÖÉ¢Ö©Ö롱ÍþвÐÐΪÕß±»ÒÔΪÊÇ¡°Com¡±µÄÒ»²¿ÃÅ£¬ÕâÊÇÒ»¸öÊèËÉÁªÏµµÄÉçÇø£¬²Î¼ÓÍøÂç¹¥»÷µÈÐÐΪ¡£ÕâÐ©ÍøÂç·¸×ï·Ö×Ó¶àΪӢÓïʹÓÃÕߣ¬³£ÔÚTelegramƵ·¡¢Discord·þÎñÆ÷ºÍºÚ¿ÍÂÛ̳²ß¶¯Ö´Ðй¥»÷¡£


https://www.bleepingcomputer.com/news/security/google-scattered-spider-switches-targets-to-us-retail-chains/


3. BianLianºÍRansomExxÀûÓÃSAP NetWeaver·ì϶


5ÔÂ14ÈÕ£¬½üÈÕ£¬ÍøÂ簲ȫÁìÓòÆØ³ö¶à¸öÍþвÐÐΪÕßÀûÓÃSAP NetWeaver°²È«·ì϶½øÐй¥»÷µÄÊÂÎñ¡£¾ÝÍøÂ簲ȫ¹«Ë¾ReliaQuest×îÐÂÐÂÎÅ£¬ÖÁÉÙÓÐÁ½¸ö·ÖÆçµÄÍøÂç·¸×OÍÅBianLianºÍRansomExx²Î¼ÓÁËÀûÓø÷ì϶µÄ¹¥»÷»î¶¯¡£ReliaQuest·¢ÏÖÁËBianLianÊý¾ÝÀÕË÷ÍŶӺÍRansomExxÀÕË÷Èí¼þ¼Ò×壨΢Èí×·×ÙÃû³ÆÎªStorm-2460£©²Î¼Ó¹¥»÷µÄÖ¤¾Ý¡£ÆäÖУ¬BianLian±»ÆÀ¹ÀΪÖÁÉÙÉæ¼°Ò»Â·ÊÂÎñ£¬ÒòÆä»ù´¡ÉèÊ©Á´½ÓÓëÏÈǰȷ¶¨µÄ¸Ãµç×Ó·¸×OÍŵÄIPµØÖ·ÓйØ¡£ReliaQuest»¹¹Û²ìµ½£¬Ò»ÖÖÃûΪPipeMagicµÄ»ùÓÚ²å¼þµÄľÂí±»²¿ÊðÔÚ¹¥»÷ÖУ¬¸ÃľÂíÓëWindowsͨÓÃÈÕÖ¾Îļþϵͳ£¨CLFS£©ÖеÄȨÏÞÌáÉý·ì϶£¨CVE-2025-29824£©µÄÁãÈÕ·ì϶ÀûÓÃÓйØ£¬²¢ÔÚÕë¶Ô¶à¹úʵÌåµÄÓÐÏÞ¹¥»÷Öб»ÀûÓ᣹¥»÷Õßͨ¹ýÀûÓÃSAP NetWeaver·ì϶Ͷ·ÅWeb ShellÀ´´«ËÍPipeMagic£¬Ö»¹Ü³õ´Î³¢ÊÔʧ°Ü£¬µ«ºóÐø¹¥»÷³É¹¦²¿ÊðÁËBrute Ratel C2¿ò¼Ü¡£SAP°²È«¹«Ë¾OnapsisÔòй©£¬×Ô2025Äê3ÔÂÒÔÀ´£¬ÍþвÐÐΪÕßÒ»ÏòÔÚÀûÓø÷ì϶¼°Í³Ò»×é¼þÖеķ´ÐòÁл¯·ì϶£¨CVE-2025-42999£©½øÐй¥»÷¡£Ö»¹ÜCVE-2025-42999±ØÒª¸ü¸ßȨÏÞ£¬µ«CVE-2025-31324ÄÜÌṩÆëÕûϵͳ½Ó¼ûȨÏÞ£¬Òò¶øÁ½¸ö·ì϶µÄ²¹¾È½¨ÒéÒ»Ñù£¬¼´Ö»ÓÐCVE-2025-31324·ì϶´æÔÚ£¬¾ÍÐèµ±¼´½¨²¹ÒÔ·À±¸Ç±ÔÚ¹¥»÷¡£


https://thehackernews.com/2025/05/bianlian-and-ransomexx-exploit-sap.html


4. °Ä´óÀûÑÇÈËȨίԱ»áÍøÕ¾ÏÖÒâ±íÊý¾Ýй¶


5ÔÂ14ÈÕ£¬°Ä´óÀûÑÇÈËȨίԱ»á£¨AHRC£©Ð¹Â©£¬2025Äê4ÔÂÖÁ5ÔÂÆÚ¼ä£¬ÆäÍøÕ¾²úÉúÁËһ·Òâ±íÊý¾Ýй¶ÊÂÎñ£¬Éæ¼°600¶à·ÝÌá½»ºÍÌáÃûµÄÄÚÈÝ¡£4ÔÂ10ÈÕ£¬AHRC·¢ÏÖ3ÔÂ24ÈÕÖÁ4ÔÂ10ÈÕÆÚ¼äÉÏ´«µ½Í¶ËßÍøÂç±íµ¥µÄ¸½¼þÔÚ4ÔÂ3ÈÕÖÁ4ÔÂ10ÈÕÆÚ¼ä±»¹«¿ª°ä²¼²¢Ôâ½Ó¼û¡£5ÔÂ8ÈÕ£¬¸ÃίԱ»áÓÖ·¢ÏÖ¸ü¶àÎļþ±»ÆØ¹â£¬ÕâЩÎļþÊÇÌá½»¸øÍøÂç±íµ¥µÄ¸½¼þ£¬ÓÃÓÚ·´À¡¡°¾­Ñé̸֮¡±ÏîÄ¿¡¢2023ÄêÈËȨ½±ÌáÃû¼°¹ú¶È·´ÖÖ×åÖ÷Òå¿ò¼Ü¸ÅÏëÎļþµÄ¶¨¼û£¬ÆØ¹â¹¦·òΪ4ÔÂ3ÈÕÖÁ5ÔÂ5ÈÕ¡£AHRCÔÚ5ÔÂ13ÈÕµÄÊý¾Ýй¶֪ͨÖÐÖ¸³ö£¬Ô¼Äª670·ÝÎļþ¿ÉÄÜÒòÃýÎó¶ø±»Ð¹Â¶£¬ÆäÖÐÔ¼100·ÝÎļþÒÑͨ¹ý¹È¸è»ò±ØÓ¦µÈËÑË÷ÒýÇæÔÚÏß½Ó¼û£¬ÇҺܶàÎļþÔ̺¬Ó×ÎÒÐÅÏ¢¡£AHRC°µÊ¾ÒѲÉÈ¡Ðж¯½â¾öй¶ÎÊÌ⣬²¢ÒªÇó½«ÕâЩÎļþ´ÓËÑË÷ÒýÇæÖÐɾ³ý¡£Õâ´ÎÐÅϢй¶²¢·Ç¶ñÒâ»ò·¸×ï¹¥»÷ËùÖ£¬AHRC½«Ëæ×ŵ÷²éÉî¿ÌÌṩ×îÐÂÐÅÏ¢¡£Æ¾¾Ý֪ͨ£¬Ìذ´¹¦·ò¶ÎÄÚʹÓÃÍøÂç±í¸ñÌύͶËß¡¢¶¨¼û»òÌáÃûµÄÈË¿ÉÄÜÊܵ½Ó°Ïì¡£¿ÉÄܱ»Ð¹Â¶µÄÊý¾ÝÔ̺¬È«Ãû¡¢µç×ÓÓʼþµØÖ·¡¢×¡Õ¬µØÖ·¡¢ÊÖ»úºÅÂëµÈÃô¸ÐÐÅÏ¢¡£Ä¿Ç°£¬AHRCÔÚÈ·ÈÏÊÜÓ°ÏìÈËÊý£¬²¢µ÷²éÊÂÎñÔ­Òò£¬Í¬Ê±ÒѽûÓÃËùÓÐÍøÂç±íµ¥¡£¸ÃίԱ»áÒѳÉÁ¢×¨ÃÅÓ××éÓ¦¶ÔÕâ´ÎÊÂÎñ£¬²¢²ÉÈ¡´ëÊ©×èÖ¹½øÒ»²½½Ó¼ûÊÜÓ°ÏìÎļþ¡£


https://www.cyberdaily.au/security/12090-breaking-personal-information-exposed-by-australian-human-rights-commission-data-breach


5. ÃÀ¹úŦ¿Â¹«Ë¾ÔâÍøÂç¹¥»÷£¬²¿Ãųö²úÔÝÍ£


5ÔÂ14ÈÕ£¬ÃÀ¹ú×î´ó¸ÖÌú³ö²úÉÌŦ¿Â¹«Ë¾½üÈÕÔâ·êÍøÂ簲ȫÊÂÎñ£¬µ¼ÖÂÆä²¿ÃÅÍøÂçÏÂÏß²¢Ö´ÐÐÁ˶ôÔì´ëÊ©¡£Õâ´ÎÊÂÎñÔì³É¸Ã¹«Ë¾¶à¸öµØÖ·³ö²úÔÝÍ££¬µ«È«ÃæÓ°ÏìÉдýÆÀ¹À¡£Å¦¿Â¹«Ë¾²»½öÊÇÃÀ¹úÖØÒªµÄ¸ÖÌú³ö²úÉÌ£¬Ò²ÊDZ±ÃÀ³ÁÒªµÄ·Ï¸Ö»ØÊÕÉÌ£¬Æä¸Ö½î²úÆ·¿í·ºÀûÓÃÓÚÃÀ¹ú¹¹Öþ¡¢ÇÅÁº¡¢Â·Â·ºÍ»ù´¡ÉèÊ©ÁìÓò¡£¹«Ë¾ÔÚÃÀ¹ú¡¢Ä«Î÷¸çºÍ¼ÓÄôóÕ¼Óжà¶à¹¤³§£¬Ô±¹¤×ÜÊý³¬¹ý32,000ÈË£¬½ñÄêµÚÒ»¼¾¶ÈÊÕÈë¸ß´ï78.3ÒÚÃÀÔª¡£¸Ã¹«Ë¾ÔÚÌá½»¸øÃÀ¹ú֤ȯÂòÂôίԱ»á£¨SEC£©µÄ8-KÎļþÖÐÅû¶ÁËÕâÒ»ÊÂÎñ£¬ÎļþÖÐÖ¸³ö£¬Å¦¿Â¹«Ë¾·¢ÏÖÁËÒ»Â·ÍøÂ簲ȫÊÂÎñ£¬É漰δ¾­ÊÚȨµÄµÚÈý·½½Ó¼ûÆäÐÅÏ¢¼¼Êõϵͳ¡£ÊÂÎñ²úÉúºó£¬¹«Ë¾Ñ¸¿ìÆô¶¯ÁËÓ¦¼±ÏìÓ¦´òË㣬×Ô¶¯ÏÂÏß¿ÉÄÜÊÜÓ°ÏìµÄϵͳ£¬²¢²ÉÈ¡ÁËÆäËû¶ôÔì¡¢²¹¾ÈºÍ¸´Ô­´ëÊ©¡£Í¬Ê±£¬Å¦¿Â¹«Ë¾ÒÑ֪ͨ·¨Âɲ¿ÃÅ£¬²¢ÀñƸ±í²¿ÍøÂ簲ȫר¼ÒЭÖúµ÷²é¡£Ö»¹Ü²¿Ãųö²ú×÷ÒµÒÑÔÝÍ££¬µ«¹«Ë¾°µÊ¾ÔÚÖð²½³ÁÆô¡£È»¶ø£¬¹ØÓÚ¹¥»÷µÄ¾ßÌåÈÕÆÚºÍÀàÐÍ£¬¹«Ë¾²¢Î´Ìṩ¾ßÌåÐÅÏ¢£¬Òò¶øÎÞ·¨È·¶¨¸ÃÊÂÎñÊÇ·ñÉæ¼°Êý¾Ý͵ÇÔ»ò¼ÓÃÜ¡£½ØÖÁĿǰ£¬ÉÐÎÞÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£


https://www.bleepingcomputer.com/news/security/steel-giant-nucor-corporation-facing-disruptions-after-cyberattack/


6. ·¨¹úµÏ°ÂÅûÂ¶ÍøÂ簲ȫÊÂÎñ£¬¿Í»§ÐÅϢй¶


5ÔÂ14ÈÕ£¬·¨¹úÉݳÞʱÉÐÆ·ÅƵϰÂÅû¶ÁËÒ»Â·ÍøÂ簲ȫÊÂÎñ£¬µ¼ÖÂÆäʱװ¼°ÅäÊοͻ§ÐÅϢй¶¡£¹«Ë¾½²»°È˰µÊ¾£¬·¢ÏÖδ¾­ÊÚȨµÄ±í²¿»ú¹¹½Ó¼ûÁËΪµÏ°ÂʱװºÍÅäÊοͻ§±£ÁôµÄ²¿ÃÅÊý¾Ý¡£µÏ°Âµ±¼´²ÉÈ¡´ëÊ©½ÚÔìÊÂÎñ£¬²¢ÔÚ¶¥¼âÍøÂ簲ȫר¼ÒµÄÖ§³ÖϳÖÐøµ÷²éÓ¦¶Ô¡£¾ÝµÏ°Â³ÎÇ壬Õâ´ÎÊÂÎñ²¢Î´Ð¹Â¶ÕË»§ÃÜÂë»òÖ§¸¶¿¨ÐÅÏ¢£¬ÒòÕâЩÐÅÏ¢´æ´¢ÔÚÁíһδÊÜÓ°ÏìµÄÊý¾Ý¿âÖС£µÏ°Â°µÊ¾ÔÚÖÂÁ¦Æ¾¾ÝºÏÓÃ˾·¨Í¨ÖªÓйؼà¹Ü»ú¹¹ºÍ¿Í»§£¬²¢¶Ô¿ÉÄܸø¿Í»§´øÀ´µÄÓÇÓô»ò²»±ãÉî¸Ð±§À¢¡£Ö»¹ÜµÏ°Âδ¾ßÌå×¢Ã÷ÊÜÓ°ÏìµÄ¿Í»§ÊýÁ¿ºÍµØÓò£¬µ«ÒÑÈ·ÈϺ«¹úÍøÕ¾Êܵ½Ó°Ï죬ÇÒÖйú¿Í»§Ò²ÊÕµ½ÁË×ÊÁÏй¶֪ͨ¡£ÍøÉÏÁ÷´«µÄ֪ͨ½ØÍ¼ÏÔʾ£¬ÊÂÎñÓÚ5ÔÂ7ÈÕ±»·¢ÏÖ£¬É漰δ¾­ÊÚȨ½Ó¼û£¬Â¶³öÁ˿ͻ§ÐÕÃû¡¢ÐԱ𡢵绰ºÅÂë¡¢µç×ÓÓʼþ¡¢ÓÊÕþµØÖ·¼°²É°ìº¹Çà¼Í¼µÈÐÅÏ¢¡£Óë´Ëͬʱ£¬µÏ°ÂÔÚº«¹úÒòδÏòËùÓÐÓйز¿ÃÅ´«µÝÊý¾Ýй¶ÊÂÎñ¶øÃæ¶Ô˾·¨Éó²é¡£µÏ°Â½¨Òé¹Ë¿Í¶ÔÍøÂç´¹µöÐÐΪά³Ö¾¯Ì裬²¢µ±¼´ÁªÏµ¾Ù±¨Æ·ÅƼÙÒâÇé¿ö¡£Ä¿Ç°£¬ÊÜÓ°Ïì¿Í»§ÊýÁ¿ºÍ¹ú¶ÈµÄ¾ßÌåÐÅÏ¢ÉÐδ¹«¿ªÅû¶¡£


https://www.bleepingcomputer.com/news/security/fashion-giant-dior-discloses-cyberattack-warns-of-data-breach/