8000 ¶à¸öÖµµÃÐÅÀµµÄÆ·ÅÆÓòÃû±»½Ù³Ö²¢´ó¹æÄ£·¢ËÍÀ¬»øÓʼþ
Ðû²¼Ê±¼ä 2024-02-282ÔÂ26ÈÕ£¬Guardio Labs ÕýÔÚ¸ú×Ùе÷µÄ¶ñÒâ»î¶¯£¬¸Ã»î¶¯ÖÁÉÙ×Ô 2022 Äê 9 ÔÂÒÔÀ´Ò»Ö±ÔÚÁ¬Ðø£¬ÃûΪ SubdoMailing¡£ÊôÓںϷ¨Æ·Åƺͻú¹¹µÄ 8,000 ¶à¸öÓòÃûºÍ 13,000 ¸ö×ÓÓòÃûÒѱ»½Ù³Ö£¬×÷ΪÀ¬»øÓʼþÀ©É¢ºÍµã»÷»õ±Ò»¯µÄÅÓ´ó·Ö·¢¼Ü¹¹µÄÒ»²¿ÃÅ¡£Õâ¼ÒÒÔÉ«ÁÐÄþ¾²¹«Ë¾½«´Ë´Î»î¶¯¹éÒòÓÚÒ»¸öÃûΪResurrecAdsµÄÍþвÐÐΪÕߣ¬ÖÚËùÖÜÖª£¬¸ÃÐÐΪÕ߻ḴÉú´óÆ·ÅÆ»òÁ¥ÊôÓÚ´óÆ·ÅƵÄËÀÓòÃû£¬×îÖÕÄ¿±êÊÇÀûÓÃÊý×Ö¹ã¸æÉú̬ϵͳÒÔ»ñÈ¡·Ç·¨ÊÕÒæ¡£ÕâЩ×ÓÓòÃûÊôÓÚ»òÁ¥ÊôÓÚ ACLU¡¢eBay¡¢Lacoste¡¢Marvel¡¢McAfee¡¢MSN¡¢Pearson¡¢PwC¡¢Swatch¡¢Symantec¡¢The Economist¡¢UNICEF ºÍ VMware µÈ´óÆ·ÅƺÍ×éÖ¯¡£
https://thehackernews.com/2024/02/8000-subdomains-of-trusted-brands.html
2. Booking.com ð³ä»î¶¯£ºAgent Tesla ¶ñÒâÈí¼þ·ÖÎö
2ÔÂ26ÈÕ£¬¸Ã»î¶¯ÀûÓà Booking.com µÄÆ·ÅÆÉùÓþÀ´Á÷´« Agent Tesla£¬ÕâÊÇÒ»Öֶ๦ЧԶ³Ì·ÃÎÊľÂí ( RAT )¡£¹¥»÷ÕßÀûÓÃÓë Booking.com Ïà¹ØµÄÐÅÈΣ¬ÖÆ×÷¿´ËƺϷ¨ÍË¿î֪ͨµÄÍøÂçµöÓãµç×ÓÓʼþ¡£°üÂÞ PDF ¸½¼þ»áÒªÇóÊÕ¼þÈ˼ì²éËù¸½ PDF ÖеĿ¨¶ÔÕ˵¥¡£ÕâÒ»¾«ÐÄÉè¼ÆµÄ¼Æ»®µÄ×îÖÕ½á¹ûÊDz¿ÊðÁËAgent Tesla¶ñÒâÈí¼þ¡£¸Ã¶ÔÊÖ¿ªÊ¼½ÓÄɶñÒâÐж¯ÇÔȡƾ֤ºÍ¸öÈËÊý¾Ý£¬½«Æä²»ÒåÖ®²Æ´«Ê䵽˽ÈË Telegram ÁÄÌìÊÒ¡£Ëü²¢²»Ö¹ÓÚ´Ë£»¸Ã¶ñÒâÈí¼þͨ¹ýÌرðµÄ PowerShell ½Å±¾È·±£Æä³Ö¾ÃÐÔ£¬²¢²»Í£¸ïÐÂÆä¼ÆıÒÔÔÚÊÜѬȾµÄϵͳÖб£³ÖÁ¢×ãµã¡£
https://securityonline.info/booking-com-impersonation-campaign-agent-tesla-malware-analysis/
3. ALPHV/BlackCat ¶Ô Change Healthcare ÍøÂç¹¥»÷ÂôÁ¦
2ÔÂ26ÈÕ£¬¾Ý±¨µÀ£¬ALPHV/BlackCat ÀÕË÷Èí¼þÍÅ»ï¶Ô Change Healthcare ´ó¹æÄ£ÍøÂç¹¥»÷ÂôÁ¦£¬¸Ã¹¥»÷×ÔÉÏÖÜÒÔÀ´ÒѾÈÅÂÒÁËÃÀ¹ú¸÷µØµÄÒ©µê¡£¾Ý·͸ÉçÔ®Òý¡°Á½ÃûÖªÇéÈËÊ¿¡±µÄ»°³Æ£¬ÎÛÃûÕÑÖøµÄÀÕË÷Èí¼þ¼´·þÎñ²Ù×÷ÊÇÁªºÏ½¡¿µÆìÏÂÆóÒµÌᳫ¹¥»÷µÄÄ»ºóºÚÊÖ¡£RegisterÉÐδ¶ÀÁ¢È·ÈÏ ALPHV ¼ÓÈëÁË´Ë´ÎÈëÇÖ¡£Change Healthcare ΪҽÁÆ»ú¹¹Ìṩ¹ã·ºµÄ IT ·þÎñ£¬°üÂÞÈÃÒ©·¿¼ì²é»¼ÕßÓÃÒ©×ʸñ²¢È·¶¨±£ÏÕ·¶Î§µÄÈí¼þ¡£Æä¿Í»§°üÂÞÃÀ¹úÁ½¼Ò×î´óµÄÒ©µê¡ª¡ªCVS ºÍÎÖ¶û¸ñÁÖ¡ª¡ªÕâÁ½¼ÒÒ©µê¶¼¸ÐÊܵ½ÁËÍ£µçµÄ²»Á¼Ó°Ïì¡£Õâ¼Ò½¡¿µ¿Æ¼¼¹«Ë¾ÓÚ 2 Ô 21 ÈÕÊ×´ÎÅû¶ÁËÕâһ©¶´£¬²¢Òò´Ë¹Ø±ÕÁ˲¿ÃÅ IT ϵͳ¡£ÖÜÎ壬ÃÀ¹úÒ©¼ÁʦлáÌåÏÖ£¬ÓÉÓÚÍøÂç¹¥»÷£¬È«¹ú¸÷µØµÄÒ©·¿ÎÞ·¨´«Ëͱ£ÏÕË÷Åâ¡£
https://www.theregister.com/2024/02/26/alphv_healthcare_unitedhealth/
4. UAC-0184 ʹÓà Remcos RAT Õë¶Ô·ÒÀ¼¾³ÄÚµÄÎÚ¿ËÀ¼ÊµÌå
2ÔÂ27ÈÕ£¬±»×·×ÙΪ UAC-0184 µÄÍþвÐÐΪÕßÒ»Ö±ÔÚʹÓÃÒþдÊõ¼¼Êõ£¬Í¨¹ýÃûΪ IDAT Loader µÄÏà¶Ô½ÏеĶñÒâÈí¼þÏòλÓÚ·ÒÀ¼µÄÎÚ¿ËÀ¼Ä¿±ê´«ËÍ Remcos Ô¶³Ì·ÃÎÊľÂí (RAT)¡£¾¡¹Ü¶ÔÊÖ×î³õÕë¶ÔµÄÊÇÎÚ¿ËÀ¼¾³ÄÚµÄʵÌ壬µ«·ÀÓù´ëÊ©×è°ÁËÓÐЧÔغɵĽ»¸¶¡£Æ¾¾Ý Morphisec ÍþвʵÑéÊÒ½ñÌìµÄ·ÖÎö£¬Õâµ¼ÖÂÁËËæºó¶ÔÌæ´úÄ¿±êµÄËÑË÷¡£ËäÈ» Morphisec Òò¿Í»§»úÃܶøûÓÐ͸¶»î¶¯Ï¸½Ú£¬µ«Ñо¿ÈËÔ±Ö¸³ö Dark Reading¾Ý³ÆÓë UAC-0148 ½øÐеIJ¢ÐлÓйأ¬¸Ã»î¶¯Ê¹Óõç×ÓÓʼþºÍÓã²æʽÍøÂçµöÓã×÷Ϊ³õʼ·ÃÎÊý½é£¬²¢ÒÔÎÚ¿ËÀ¼¾üÊÂÈËԱΪĿ±ê£¬ÒÔÌṩ×ÉѯΪÓÕ¶ü¡£ÒÔÉ«Áйú·À¾ü (IDF) µÄ½ÇÉ«¡£ÆäÄ¿±êÊÇÍøÂç¼äµý»î¶¯£ºÍøÂç·¸×ï·Ö×ÓʹÓà Remcos£¨¡°Ô¶³Ì¿ØÖƺͼàÊÓ¡±µÄËõд£©RAT À´Î´¾ÊÚȨ·ÃÎÊÊܺ¦ÕߵļÆËã»ú¡¢Ô¶³Ì¿ØÖÆÊÜѬȾµÄϵͳ¡¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡¢Ö´ÐÐÃüÁîµÈ¡£
https://www.darkreading.com/cyberattacks-data-breaches/uac-0184-targets-ukrainian-entity-finland-remcos-rat
5. ¶íÂÞ˹ºÚ¿ÍÍÅ»ïͨ¹ýÐÝÃßÕÊ»§Ãé×¼ÔÆ»ù´¡ÉèÊ©
2ÔÂ26ÈÕ£¬ÃÀ¹ú¡¢¼ÓÄôó¡¢Ó¢¹ú¡¢°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄÍøÂçÄþ¾²ºÍÖ´·¨»ú¹¹Ðû²¼ÁªºÏ¾¯±¨£¬ºôÓõ½ô¼±¹Ø×¢Óë APT29/Cozy Bear/Midnight Blizzard£¨Ò»¸öÎÛÃûÕÑÖøµÄºÚ¿Í×éÖ¯£©Ïà¹ØµÄ×îмÆı¡¢¼¼ÊõºÍ·¨Ê½ (TTP)¡£¶íÂÞ˹Ç鱨²¿ÃÅ£¨SVR£©¡£¾ÝÊӲ죬SVR ¼ÓÈëÕß²¢Ã»ÓÐÀûÓÃÈí¼þ©¶´À´¹¥»÷µ±µØ»ù´¡ÉèÊ©£¬¶øÊÇÌᳫ±©Á¦ÆƽâºÍÃÜÂëÅçÉä¹¥»÷À´ÆÆ»µ·þÎñÕÊ»§£¬ÒÔ¼°Õë¶ÔÇ°Ô±¹¤µÄÐÝÃßÕÊ»§À´·ÃÎÊÄ¿±ê×éÖ¯µÄ»·¾³¡£´ËÍ⣬»¹·¢ÏÖÎÛÃûÕÑÖøµÄ APT ×é֯ʹÓÃÁîÅÆ·ÃÎÊÊܺ¦ÕßÕÊ»§£¬²¢Ê¹ÓÃÒ»ÖÖ³ÆΪ¡°MFA ºäÕ¨¡±»ò¡°MFA Æ£ÀÍ¡±µÄ¼¼ÊõÈƹý¶àÖØÉí·ÝÑéÖ¤ (MFA)¡£³õ´Î·ÃÎʺ󣬹¥»÷Õßͨ³£»á½«×Ô¼ºµÄÉ豸ע²áµ½Êܺ¦ÕßµÄÍøÂ磬²¢²¿ÊðÅÓ´óµÄ¹¥»÷ºó¹¤¾ß¡£´ËÍ⣬ºÚ¿Í»¹ÒÀ¿¿×¡Õ¬ÊðÀíÀ´Òþ²ØÆä¶ñÒâ»î¶¯£¬Ê¹Á÷Á¿¿´ÆðÀ´ÏñÊÇÀ´×Ôסլ¿í´ø¿Í»§µÄ IP µØÖ·¡£
https://www.securityweek.com/russian-cyberspies-targeting-cloud-infrastructure-via-dormant-accounts/
6. Anonymous ËÕµ¤ÍƹãÐ嵀 DDoS ½©Ê¬ÍøÂçSkynet-GodzillaBotnet
2ÔÂ26ÈÕ£¬¾ÝÁ˽⣬һ¸öÃûΪ¡°ÄäÃûËÕµ¤¡±µÄ×éÖ¯ÕýÔÚ»ý¼«ÍƹãÒ»ÖÖÃûΪ¡°Skynet-GodzillaBotnet¡±µÄÐÂÐÍÂþÑÜʽ¾Ü¾ø·þÎñ (DDoS) ½©Ê¬ÍøÂç·þÎñ¡£ÍøÉÏÁ÷´«µÄÒ»Ôò¹ã¸æչʾÁË´øÓС°SKYNET¡±×ÖÑùµÄºìÁú±êÖ¾¡£¸Ã·þÎñ±»Ðû´«ÎªÖ´ÐÐDDoS ¹¥»÷µÄÇ¿´ó¹¤¾ß£¬¸Ã×éÖ¯Éù³Æͨ¹ý½«ÆäȨÁ¦ÓëÁíÒ»¸öʵÌåºÏ²¢À´ÔöÇ¿Æ书Ч¡£¡¶Ã¿ÈÕ°µÍø¡·Öз¢ÏֵĹã¸æÃ÷È·Ö¸³ö£¬ËüÌṩ½©Ê¬ÍøÂçµÄ·ÃÎÊȨÏÞ£¬¼Û¸ñΪһÌì 100 ÃÀÔª¡¢Ò»ÖÜ 600 ÃÀÔª¡¢Ò»¸öÔ 1700 ÃÀÔª¡£Anonymous ËÕµ¤ÒÔÆ伤½øµÄ Web DDoS ¹¥»÷¶øÎÅÃû£¬ÆäÖаüÂÞ½»ÌæµÄ UDP ºÍ SYN ºéË®¹¥»÷¡£ÕâЩ¹¥»÷´ÓÊýÒÔÍò¼ÆµÄΨһԴ IP µØÖ·Ìᳫ£¬UDP Á÷Á¿¸ß´ï 600Gbps£¬HTTPS ÇëÇóºéË®·åÖµ¿É´ïÿÃëÊý°ÙÍò¸öÇëÇó¡£
https://gbhackers.com/anonymous-sudan-new-ddos-botnet-warning/