8000 ¶à¸öÖµµÃÐÅÈÎµÄÆ·ÅÆÓòÃû±»Ð®ÖƲ¢´ó¹æÄ£·¢ËÍÀ¬»øÓʼþ
Ðû²¼Ê±¼ä 2024-02-282ÔÂ26ÈÕ£¬£¬Guardio Labs ÕýÔÚ¸ú×Ùе÷µÄ¶ñÒâ»î¶¯£¬£¬¸Ã»î¶¯ÖÁÉÙ×Ô 2022 Äê 9 ÔÂÒÔÀ´Ò»Ö±ÔÚÒ»Á¬£¬£¬ÃûΪ SubdoMailing¡£¡£ÊôÓÚÕýµ±Æ·Åƺͻú¹¹µÄ 8,000 ¶à¸öÓòÃûºÍ 13,000 ¸ö×ÓÓòÃûÒѱ»Ð®ÖÆ£¬£¬×÷ΪÀ¬»øÓʼþÀ©É¢ºÍµã»÷Ç®±Ò»¯µÄÖØ´ó·Ö·¢¼Ü¹¹µÄÒ»²¿·Ö¡£¡£Õâ¼ÒÒÔÉ«ÁÐÇå¾²¹«Ë¾½«´Ë´Î»î¶¯¹éÒòÓÚÒ»¸öÃûΪResurrecAdsµÄÍþвÐÐΪÕߣ¬£¬ÖÚËùÖÜÖª£¬£¬¸ÃÐÐΪÕ߻ḴÉú´óÆ·ÅÆ»òÁ¥ÊôÓÚ´óÆ·ÅÆµÄËÀÓòÃû£¬£¬×îÖÕÄ¿µÄÊÇʹÓÃÊý×Ö¹ã¸æÉú̬ϵͳÒÔ»ñÈ¡²»·¨ÊÕÒæ¡£¡£ÕâЩ×ÓÓòÃûÊôÓÚ»òÁ¥ÊôÓÚ ACLU¡¢eBay¡¢Lacoste¡¢Marvel¡¢McAfee¡¢MSN¡¢Pearson¡¢PwC¡¢Swatch¡¢Symantec¡¢The Economist¡¢UNICEF ºÍ VMware µÈ´óÆ·ÅÆºÍ×éÖ¯¡£¡£
https://thehackernews.com/2024/02/8000-subdomains-of-trusted-brands.html
2. Booking.com ð³ä»î¶¯£ºAgent Tesla ¶ñÒâÈí¼þÆÊÎö
2ÔÂ26ÈÕ£¬£¬¸Ã»î¶¯Ê¹Óà Booking.com µÄÆ·ÅÆÉùÓþÀ´Èö²¥ Agent Tesla£¬£¬ÕâÊÇÒ»Öֶ๦ЧԶ³Ì»á¼ûľÂí ( RAT )¡£¡£¹¥»÷ÕßʹÓÃÓë Booking.com Ïà¹ØµÄÐÅÈΣ¬£¬ÖÆ×÷¿´ËÆÕýµ±ÍË¿î֪ͨµÄÍøÂç´¹ÂÚµç×ÓÓʼþ¡£¡£°üÀ¨ PDF ¸½¼þ»áÒªÇóÊÕ¼þÈ˼ì²éËù¸½ PDF ÖеĿ¨¶ÔÕ˵¥¡£¡£ÕâһȫÐÄÉè¼ÆµÄÍýÏëµÄ×îÖÕЧ¹ûÊǰ²ÅÅÁËAgent Tesla¶ñÒâÈí¼þ¡£¡£¸ÃµÐÊÖ×îÏȽÓÄɶñÒâÐж¯ÇÔȡƾ֤ºÍСÎÒ˽¼ÒÊý¾Ý£¬£¬½«Æä²»ÒåÖ®²Æ´«Ê䵽˽ÈË Telegram ̸ÌìÊÒ¡£¡£Ëü²¢²»Ö¹ÓÚ´Ë£»£»£»£»£»¸Ã¶ñÒâÈí¼þͨ¹ýÌØÁíÍâ PowerShell ¾ç±¾È·±£Æä³¤ÆÚÐÔ£¬£¬²¢Ò»Ö±Ë¢ÐÂÆäÕ½ÂÔÒÔÔÚÊÜѬȾµÄϵͳÖмá³Öפ×ãµã¡£¡£
https://securityonline.info/booking-com-impersonation-campaign-agent-tesla-malware-analysis/
3. ALPHV/BlackCat ¶Ô Change Healthcare ÍøÂç¹¥»÷ÈÏÕæ
2ÔÂ26ÈÕ£¬£¬¾Ý±¨µÀ£¬£¬ALPHV/BlackCat ÀÕË÷Èí¼þÍÅ»ï¶Ô Change Healthcare ´ó¹æÄ£ÍøÂç¹¥»÷ÈÏÕæ£¬£¬¸Ã¹¥»÷×ÔÉÏÖÜÒÔÀ´ÒѾÈÅÂÒÁËÃÀ¹ú¸÷µØµÄÒ©µê¡£¡£¾Ý·͸ÉçÔ®Òý¡°Á½ÃûÖªÇéÈËÊ¿¡±µÄ»°³Æ£¬£¬ÎÛÃûÕÑÖøµÄÀÕË÷Èí¼þ¼´Ð§ÀͲÙ×÷ÊÇÁªºÏ¿µ½¡ÆìÏÂÆóÒµÌᳫ¹¥»÷µÄÄ»ºóºÚÊÖ¡£¡£RegisterÉÐδ×ÔÁ¦È·ÈÏ ALPHV ¼ÓÈëÁË´Ë´ÎÈëÇÖ¡£¡£Change Healthcare ΪҽÁÆ»ú¹¹ÌṩÆÕ±éµÄ IT ЧÀÍ£¬£¬°üÀ¨ÈÃÒ©·¿¼ì²é»¼ÕßÓÃÒ©×ʸñ²¢È·¶¨°ü¹Ü¹æÄ£µÄÈí¼þ¡£¡£Æä¿Í»§°üÀ¨ÃÀ¹úÁ½¼Ò×î´óµÄÒ©µê¡ª¡ªCVS ºÍÎÖ¶û¸ñÁÖ¡ª¡ªÕâÁ½¼ÒÒ©µê¶¼¸ÐÊܵ½ÁËÍ£µçµÄ²»Á¼Ó°Ïì¡£¡£Õâ¼Ò¿µ½¡¿Æ¼¼¹«Ë¾ÓÚ 2 Ô 21 ÈÕÊ×´ÎÅû¶ÁËÕâÒ»Îó²î£¬£¬²¢Òò´Ë¹Ø±ÕÁ˲¿·Ö IT ϵͳ¡£¡£ÖÜÎ壬£¬ÃÀ¹úÒ©¼ÁʦлáÌåÏÖ£¬£¬ÓÉÓÚÍøÂç¹¥»÷£¬£¬Ììϸ÷µØµÄÒ©·¿ÎÞ·¨´«ËͰü¹ÜË÷Åâ¡£¡£
https://www.theregister.com/2024/02/26/alphv_healthcare_unitedhealth/
4. UAC-0184 ʹÓà Remcos RAT Õë¶Ô·ÒÀ¼¾³ÄÚµÄÎÚ¿ËÀ¼ÊµÌå
2ÔÂ27ÈÕ£¬£¬±»×·×ÙΪ UAC-0184 µÄÍþвÐÐΪÕßÒ»Ö±ÔÚʹÓÃÒþдÊõÊÖÒÕ£¬£¬Í¨¹ýÃûΪ IDAT Loader µÄÏà¶Ô½ÏеĶñÒâÈí¼þÏòλÓÚ·ÒÀ¼µÄÎÚ¿ËÀ¼Ä¿µÄ´«ËÍ Remcos Ô¶³Ì»á¼ûľÂí (RAT)¡£¡£Ö»¹ÜµÐÊÖ×î³õÕë¶ÔµÄÊÇÎÚ¿ËÀ¼¾³ÄÚµÄʵÌ壬£¬µ«·ÀÓù²½·¥×è°ÁËÓÐÓÃÔØºÉµÄ½»¸¶¡£¡£Æ¾Ö¤ Morphisec ÍþвʵÑéÊÒ½ñÌìµÄÆÊÎö£¬£¬Õâµ¼ÖÂÁËËæºó¶ÔÌæ»»Ä¿µÄµÄËÑË÷¡£¡£ËäÈ» Morphisec Òò¿Í»§ÉñÃØ¶øÃ»ÓÐ͸¶»î¶¯Ï¸½Ú£¬£¬µ«Ñо¿Ö°Ô±Ö¸³ö Dark Reading¾Ý³ÆÓë UAC-0148 ¾ÙÐеIJ¢ÐлÓйأ¬£¬¸Ã»î¶¯Ê¹Óõç×ÓÓʼþºÍÓã²æÊ½ÍøÂç´¹ÂÚ×÷Ϊ³õʼ»á¼ûǰÑÔ£¬£¬²¢ÒÔÎÚ¿ËÀ¼¾üÊÂְԱΪĿµÄ£¬£¬ÒÔÌṩ×ÉѯΪÓÕ¶ü¡£¡£ÒÔÉ«Áйú·À¾ü (IDF) µÄ½ÇÉ«¡£¡£ÆäÄ¿µÄÊÇÍøÂçÌØ¹¤»î¶¯£ºÍøÂç·¸·¨·Ö×ÓʹÓà Remcos£¨¡°Ô¶³Ì¿ØÖƺͼàÊÓ¡±µÄËõд£©RAT À´Î´¾ÊÚȨ»á¼ûÊܺ¦ÕßµÄÅÌËã»ú¡¢Ô¶³Ì¿ØÖÆÊÜѬȾµÄϵͳ¡¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡¢Ö´ÐÐÏÂÁîµÈ¡£¡£
https://www.darkreading.com/cyberattacks-data-breaches/uac-0184-targets-ukrainian-entity-finland-remcos-rat
5. ¶íÂÞ˹ºÚ¿ÍÍÅ»ïͨ¹ýÐÝÃßÕÊ»§Ãé×¼ÔÆ»ù´¡ÉèÊ©
2ÔÂ26ÈÕ£¬£¬ÃÀ¹ú¡¢¼ÓÄôó¡¢Ó¢¹ú¡¢°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄÍøÂçÇå¾²ºÍÖ´·¨»ú¹¹Ðû²¼ÁªºÏ¾¯±¨£¬£¬ºôÓõ½ôÆÈ¹Ø×¢Óë APT29/Cozy Bear/Midnight Blizzard£¨Ò»¸öÎÛÃûÕÑÖøµÄºÚ¿Í×éÖ¯£©Ïà¹ØµÄ×îÐÂÕ½ÂÔ¡¢ÊÖÒպͳÌÐò (TTP)¡£¡£¶íÂÞ˹Ç鱨²¿·Ö£¨SVR£©¡£¡£¾ÝÊӲ죬£¬SVR ¼ÓÈëÕß²¢Ã»ÓÐʹÓÃÈí¼þÎó²îÀ´¹¥»÷ÍâµØ»ù´¡ÉèÊ©£¬£¬¶øÊÇÌᳫ±©Á¦ÆÆ½âºÍÃÜÂëÅçÉä¹¥»÷À´ÆÆËðЧÀÍÕÊ»§£¬£¬ÒÔ¼°Õë¶ÔǰԱ¹¤µÄÐÝÃßÕÊ»§À´»á¼ûÄ¿µÄ×éÖ¯µÄÇéÐΡ£¡£±ðµÄ£¬£¬»¹·¢Ã÷ÎÛÃûÕÑÖøµÄ APT ×é֯ʹÓÃÁîÅÆ»á¼ûÊܺ¦ÕßÕÊ»§£¬£¬²¢Ê¹ÓÃÒ»ÖÖ³ÆÎª¡°MFA ºäÕ¨¡±»ò¡°MFA Æ£ÀÍ¡±µÄÊÖÒÕÈÆ¹ý¶àÖØÉí·ÝÑéÖ¤ (MFA)¡£¡£Ê״λá¼ûºó£¬£¬¹¥»÷Õßͨ³£»£»£»£»£»á½«×Ô¼ºµÄ×°±¸×¢²áµ½Êܺ¦ÕßµÄÍøÂ磬£¬²¢°²ÅÅÖØ´óµÄ¹¥»÷ºó¹¤¾ß¡£¡£±ðµÄ£¬£¬ºÚ¿Í»¹ÒÀÀµ×¡Õ¬ÊðÀíÀ´Òþ²ØÆä¶ñÒâ»î¶¯£¬£¬Ê¹Á÷Á¿¿´ÆðÀ´ÏñÊÇÀ´×Ôסլ¿í´ø¿Í»§µÄ IP µØµã¡£¡£
https://www.securityweek.com/russian-cyberspies-targeting-cloud-infrastructure-via-dormant-accounts/
6. Anonymous ËÕµ¤ÍƹãÐ嵀 DDoS ½©Ê¬ÍøÂçSkynet-GodzillaBotnet
2ÔÂ26ÈÕ£¬£¬¾ÝÏàʶ£¬£¬Ò»¸öÃûΪ¡°ÄäÃûËÕµ¤¡±µÄ×éÖ¯ÕýÔÚÆð¾¢ÍƹãÒ»ÖÖÃûΪ¡°Skynet-GodzillaBotnet¡±µÄÐÂÐÍÂþÑÜʽ¾Ü¾øÐ§ÀÍ (DDoS) ½©Ê¬ÍøÂçЧÀÍ¡£¡£ÍøÉÏÈö²¥µÄÒ»Ôò¹ã¸æÕ¹Ê¾ÁË´øÓС°SKYNET¡±×ÖÑùµÄºìÁú±ê¼Ç¡£¡£¸ÃЧÀͱ»Ðû´«ÎªÖ´ÐÐDDoS ¹¥»÷µÄǿʢ¹¤¾ß£¬£¬¸Ã×éÖ¯Éù³ÆÍ¨¹ý½«ÆäȨÁ¦ÓëÁíÒ»¸öʵÌåºÏ²¢À´ÔöÇ¿Æä¹¦Ð§¡£¡£¡¶ÖðÈÕ°µÍø¡·Öз¢Ã÷µÄ¹ã¸æÃ÷È·Ö¸³ö£¬£¬ËüÌṩ½©Ê¬ÍøÂçµÄ»á¼ûȨÏÞ£¬£¬¼ÛǮΪһÌì 100 ÃÀÔª¡¢Ò»ÖÜ 600 ÃÀÔª¡¢Ò»¸öÔ 1700 ÃÀÔª¡£¡£Anonymous ËÕµ¤ÒÔÆä¼¤½øµÄ Web DDoS ¹¥»÷¶øÖøÃû£¬£¬ÆäÖаüÀ¨½»ÌæµÄ UDP ºÍ SYN ºéË®¹¥»÷¡£¡£ÕâЩ¹¥»÷´ÓÊýÒÔÍò¼ÆµÄΨһԴ IP µØµãÌᳫ£¬£¬UDP Á÷Á¿¸ß´ï 600Gbps£¬£¬HTTPS ÇëÇóºéË®·åÖµ¿É´ïÿÃëÊý°ÙÍò¸öÇëÇ󡣡£
https://gbhackers.com/anonymous-sudan-new-ddos-botnet-warning/


¾©¹«Íø°²±¸11010802024551ºÅ