RECORDSTEALER¶ñÒâÈí¼þÁ¬ÐøÇÔÈ¡Ãô¸ÐÐÅÏ¢
Ðû²¼Ê±¼ä 2024-09-249ÔÂ22ÈÕ£¬GoogleÄþ¾²Ñо¿ÍŶӽüÆÚ¾Û½¹ÓÚÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þµÄÁ¬ÐøÍþв£¬ÓÈÆäÊÇRECORDSTEALER£¨ÓÖ³ÆRecordBreakerºÍRaccoon Stealer V2£©£¬Ò»ÖÖ½ÓÄÉCÓïÑÔ±àдµÄ¸ß¼¶Êý¾Ý͵ÇÔ¹¤¾ß¡£¸Ã¶ñÒâÈí¼þרÃÅÕë¶ÔÐÅÓÿ¨ÐÅÏ¢¡¢ÃÜÂë¡¢cookies¼°¼ÓÃÜ»õ±ÒÇ®°üµÈÃô¸ÐÊý¾Ý½øÐÐ͵ȡ¡£ËüÀûÓöñÒâ¹ã¸æ¼°Î±×°³ÉºÏ·¨Ó¦ÓõÄÆƽâÈí¼þ×÷ΪÁ÷´«ÇþµÀ£¬ÓÕÆÓû§ÊäÈëÃÜÂëÒÔ¼¤»îÊܱ£»¤µÄ´æµµÎļþ£¬½ø¶øÖ´ÐжñÒâ²Ù×÷¡£Ò»µ©¼¤»î£¬RECORDSTEALERͨ¹ý¼ÓÃÜRC4ÐÒ齫Êý¾Ý´«ËÍÖÁC2·þÎñÆ÷£¬Í¬Ê±ÊÕ¼¯É豸ID¡¢Óû§ÃûµÈÒªº¦ÐÅÏ¢¡£¾¡¹ÜRECORDSTEALERÒ»¶ÈÒòµÞÔìÕß±»²¶¼°»ù´¡ÉèÊ©±»´Ý»Ù¶ø¼Å¾²£¬µ«ÆäÁ÷´«¼ÆıÒѱ»ÏÖ´úÐÅÏ¢ÇÔÈ¡Õ߹㷺½ÓÄÉ£¬¼ÌÐøͨ¹ýαװÆƽâÈí¼þÍþвÓû§Äþ¾²¡£¸Ã¶ñÒâÈí¼þ²»½öÂÓ¶áä¯ÀÀÆ÷ÖеĸöÈËÐÅÏ¢£¬»¹ÉîÈë¼ÓÃÜ»õ±ÒÇ®°ü¡¢½ØÈ¡ÆÁÄ»½Øͼ£¬²¢ÊÕ¼¯¼´Ê±Í¨Ñ¶Ó¦ÓõÄÃô¸ÐÎļþ¡£RECORDSTEALERµÄ¼¼ÊõÊÖ·¨ÓëVIDAR¡¢STEALCµÈÆäËûÐÅÏ¢ÇÔÈ¡·¨Ê½´æÔÚ¹²ÐÔ£¬Í¹ÏÔÁ˶ñÒâÈí¼þ¼¼ÊõµÄ¸ß¶È¸´ÓÃÐԺͼì²âÄѶȡ£
https://securityonline.info/recordstealer-a-case-study-in-the-persistent-threat-of-info-stealing-malware/
2. Twilioͨ»°¼Ç¼й¶£º12,000ÌõÒôƵÊý¾Ý̻¶Òþ˽·çÏÕ
9ÔÂ23ÈÕ£¬Ò»ÃûºÚ¿ÍÒÔ¡°grep¡±Îª±ðÃû£¬½üÆÚй¶ÁËÉù³ÆΪTwilioÔÆͨÐÅƽ̨¿Í»§µÄÁè¼Ý12,000Ìõͨ»°¼Ç¼£¬°üÂ޵绰ºÅÂ롢ͨ»°Â¼Òô¼°Ïêϸ»á»°ÐÅÏ¢£¬Ê±¼ä¿ç¶È´Ó2019ÄêÖÁ2024Äê¡£´ËʼþÑÏÖØÇÖ·¸Á˸öÈ˼°ÆóÒµÓû§µÄÒþ˽£¬ÒòΪ鶵Äͨ»°¼Ç¼²»½ö°üÂÞÔªÊý¾ÝÈçµç»°ºÅÂ롢ͨ»°Ê±¼äºÍʱ³¤£¬»¹É漰ʵ¼ÊµÄ¶Ô»°ÄÚÈÝ¡£TwilioÊÇÒ»¼Ò·þÎñÓÚ350,000¶à¸ö¿Í»§ÕË»§µÄ¼ÓÖÝÔÆͨÐŹ«Ë¾£¬´Ë´Îй¶ԼռÆä×Ü¿Í»§ÊýµÄ3.37%¡£¾¡¹ÜºÚ¿ÍδÃ÷ȷ˵Ã÷ÈëÇÖ·½Ê½£¬µ«Ð¹Â¶µÄͨ»°¼Ç¼Ïêϸ¼Ç¼ÁËͨ»°Ë«·½ºÅÂ롢״̬¡¢Ê±³¤¼°ÔÚ¿ÚÒë·þÎñÖеÄÌض¨ÐÅÏ¢£¬ÈçÓïÑÔ¡¢·ÑÂʺͻỰÏêϸÐÅÏ¢¡£´Ë´Îй¶Ê¼þ²»½ö½ÒʾÁËͨ»°µÄÃô¸ÐÄÚÈÝ£¬»¹Ôö¼ÓÁËÊܺ¦ÕßÔâÊÜÀÕË÷¡¢ÆÛÕ©ºÍÉí·Ýð³äµÄ·çÏÕ¡£ÆóÒµ¿ÉÄÜÒò´ËÃæÁÙGDPR»òCCPAµÈÒþ˽±£»¤¹æÔòµÄ´¦·£¡£Í¬Ê±£¬Ð¹Â¶µÄµç»°ºÅÂëÒ²³ÉΪ¶ÌÐźÍÓïÒôÍøÂçµöÓã¹¥»÷µÄÐÂÄ¿±ê¡£ÎªÁËÓ¦¶ÔÕâһΣ»ú£¬ÊÜÓ°Ïì·½ÐèѸËÙÐж¯£¬Í¨ÖªÓû§¡¢±£»¤Â¼ÒôÊý¾Ý²¢×Éѯִ·¨½¨Òé¡£´ËÍ⣬¼ÓÇ¿·ÃÎÊ¿ØÖÆ¡¢Êý¾Ý¼ÓÃܺÍÓ¦¼±ÏìÓ¦»úÖÆÒ²ÊÇ·À·¶Î´À´ÀàËÆʼþµÄÒªº¦´ëÊ©¡£
https://hackread.com/hacker-leaks-twilio-call-records-audio-recordings/
3. Android¶ñÒâÈí¼þNecroͨ¹ýGoogle PlayѬȾ1100Íǫ̀É豸
9ÔÂ23ÈÕ£¬Android Óû§ÃæÁÙÑÏÖصĶñÒâÈí¼þÍþв£¬ÃûΪNecroµÄаæľÂí¼ÓÔØÆ÷ͨ¹ýGoogle PlayÉϵĺϷ¨Ó¦Óü°·Ç¹Ù·½ÇþµÀÁ÷´«µÄÐ޸İæÈí¼þ£¬ÒÑDZÈëÁè¼Ý1100Íǫ̀É豸¡£NecroÀûÓöñÒâ¹ã¸æÈí¼þ¿ª·¢¹¤¾ß°ü£¨SDK£©Ç±·üÓÚÕÕƬ±à¼Ó¦Óá°ÎÞËûÏà»ú¡±¼°ÍøÂçä¯ÀÀÆ÷¡°Max Browser¡±µÈÁ÷ÐÐÈí¼þÖУ¬ÕâЩSDKαװ³ÉÕý³£¹¦Ð§£¬ÊµÔò°²×°¹ã¸æÈí¼þ¡¢Ö´ÐÐJavaScriptºÍDEXÎļþ¡¢´Ù½ø¶©ÔÄÆÛÕ©£¬²¢×÷Ϊ¶ñÒâÁ÷Á¿ÊðÀí¡£¾¡¹Ü²¿ÃÅÓ¦ÓÃÒѸüÐÂÒÔÒƳýNecro£¬µ«¾É°æ±¾ÒÅÁôµÄ¶ñÒ⸺ÔØÈÔ¿ÉÄܶÔÉ豸×é³ÉÍþв¡£´ËÍ⣬Necro»¹Í¨¹ý·Ç¹Ù·½ÇþµÀÁ÷´«µÄWhatsApp¡¢Spotify¼°MinecraftµÈÈÈÃÅÈí¼þµÄÐ޸İæ¹ã·ºÀ©É¢£¬ÊµÊ©ÆÛÕ©ÐÔ¹ã¸æչʾ¡¢Î´¾ÊÚȨµÄÓ¦Ó÷¨Ê½°²×°¼°Ó븶·Ñ·þÎñ½»»¥µÈ¶ñÒâÐÐΪ¡£ÓÉÓڷǹٷ½ÇþµÀÄÑÒÔ×·×Ù¾ßÌåѬȾÊýÁ¿£¬µ«ÒÑÖªGoogle Playƽ̨µÄѬȾ¹æÄ£ÒÑÏ൱ÅӴ󡣹ȸèÒѶԴËÀà¾Ù±¨Õ¹¿ªÊӲ죬¶øÄþ¾²×¨¼Ò½¨ÒéÓû§±£³Ö¾¯Ì裬¼°Ê±Ð¶ÔØÊÜѬȾӦÓò¢×ªÏòÄþ¾²À´Ô´¡£
https://www.bleepingcomputer.com/news/security/android-malware-necro-infects-11-million-devices-via-google-play/
4. MC2 DataÊý¾Ýй¶£º2.2TB¸öÈËÐÅϢ̻¶£¬Ó°Ï쳬1ÒÚÃÀ¹úÈË
9ÔÂ23ÈÕ£¬¾ÝCybernewsµÄÑо¿£¬Åä¾°ÊӲ칫˾MC2 DataµÄÒ»¸ö´óÐÍÔÚÏßÊý¾Ý¿â£¬ÄÚº¬2.2TBµÄÃÀ¹úÈ˸öÈËÐÅÏ¢£¬ÒòδÉèÃÜÂë±£»¤¶ø̻¶ÔÚ»¥ÁªÍøÉÏ£¬ÈκÎÈ˾ù¿ÉÇáËÉ·ÃÎÊ¡£¸ÃÊý¾Ý¿â¹ã·ºÊÕ¼¯ÁË°üÂÞ·¸×ï¼Ç¼¡¢¾ÍÒµÀúÊ·¡¢¼ÒÍ¥Êý¾ÝºÍÁªÏµ·½Ê½µÈÃô¸ÐÐÅÏ¢£¬Ó°Ï췶Χ¹ã·º£¬¾ÝÔ¤¼ÆÖÁÉÙÓÐ1ÒÚÃÀ¹úÈË£¨Ô¼Õ¼È«¹úÈË¿ÚµÄÈý·ÖÖ®Ò»£©µÄÊý¾ÝÔâй¶¡£¸üÁîÈ˵£ÓǵÄÊÇ£¬»¹ÓÐÁè¼Ý230ÍòµÄMC2 Data·þÎñ¶©ÔÄÕßµÄÊý¾ÝҲδÄÜÐÒÃâ¡£´ËʼþÔÙ´Î͹ÏÔÁËijЩÆóÒµÔÚÊý¾ÝÄþ¾²·½ÃæµÄÑÏÖØÊèºö£¬¾¡¹ÜÕâЩÆóÒµÀíÓ¦×ñÊØÏà¹Ø¹æÔò£¬µ«ÆäÄþ¾²´ëÊ©È´Ã÷ÏÔ²»×㡣ר¼Ò¾¯¸æ³Æ£¬´ËÀàÊý¾Ý鶶ÔÍøÂç·¸×ï·Ö×Ó¶øÑÔÈçͬ½ð¿ó£¬ÎªÆäʵʩթơ¢Éí·Ý͵ÇԵȷ¸×ï»î¶¯ÌṩÁ˼«´ó±ãÀû¡£Ãæ¶ÔDZÔÚµÄÊý¾Ýй¶·çÏÕ£¬¸öÈËÓ¦Ìá¸ß¾¯Ì裬½ÓÄÉÐëÒª´ëÊ©±£»¤×ÔÉíÐÅÏ¢Äþ¾²¡£
https://www.malwarebytes.com/blog/news/2024/09/100-million-us-citizens-have-records-leaked-by-background-check-service
5. ¿°Èø˹Öݸ»À¼¿ËÁÖÏؽü3Íò¾ÓÃñÊý¾ÝÔâÀÕË÷Èí¼þ¹¥»÷й¶
9ÔÂ24ÈÕ£¬¿°Èø˹Öݵĸ»À¼¿ËÁÖÏØ×î½üÔâÓöÁËÑÏÖصÄÀÕË÷Èí¼þ¹¥»÷ʼþ£¬µ¼Ö½ü30,000Ãû¾ÓÃñµÄÃô¸ÐÐÅÏ¢±»Ð¹Â¶¡£¸Ã¹¥»÷·¢ÉúÔÚ½ñÄê5ÔÂ19ÈÕ£¬ºÚ¿ÍÀÖ³ÉÇÖÈëÁËÏØÊé¼Ç¹Ù°ì¹«ÊÒµÄϵͳ£¬ÍµÈ¡ÁË°üÂÞÐÕÃû¡¢Éç»áÄþ¾²ºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢½ðÈÚÕË»§ºÅÂë¼°Ò½ÁÆÐÅÏ¢µÈÔÚÄڵĸöÈËÊý¾Ý¡£ÕâЩÊý¾Ý»¹º¸ÇÁËÒ½ÁƼǼ¡¢ÒßÃç½ÓÖÖ¡¢COVID-19Ïà¹ØÐÅÏ¢ÒÔ¼°±£ÏÕʶ±ðºÅµÈÃô¸Ð·þÎñÐÅÏ¢¡£Ê¼þÆعâºó£¬¸»À¼¿ËÁÖÏØѸËÙÁªÏµÍøÂçÄþ¾²×¨¼ÒºÍÁª°îÖ´·¨²¿ÃÅ£¬²¢ÓÚ7ÔÂ19ÈÕÏò¹«ÖÚͨ±¨ÁËÊÓ²ì½øÕ¹¡£¾¡¹ÜĿǰûÓÐÀÕË÷Èí¼þÍÅ»ïÈÏ¿ÉÔðÈΣ¬ÇÒÏØ·½ÔÚ°µÍøËÑË÷ÖÐδ·¢ÏÖÊý¾Ý±»Ðû²¼»ò³öÊ۵ļ£Ï󣬵«¸ÃʼþÈÔÒýÆðÁ˹㷺¹Ø×¢¡£¿°Èø˹ÖÝÖÝÎñÇä°ì¹«Êҵȼà¹Ü»ú¹¹ÒÑ»ñÖª´ËÊ£¬²¢ÒªÇó¸ÃÏؼÓÇ¿Äþ¾²´ëÊ©£¬ÒÔ·À·¶Î´À´ÀàËÆʼþµÄ·¢Éú¡£Îª´Ë£¬¸»À¼¿ËÁÖÏØÒѽÓÄÉһϵÁдëÊ©£¬°üÂÞ½ûÓò»»îÔ¾µÄÓû§ÕÊ»§£¬ÒÔÌá¸ßÊý¾Ý±£»¤Ë®Æ½¡£
https://therecord.media/kansas-ransomware-attack-thousands-residents
6. µÂ¹úÖ´·¨²¿ÃÅÀֳɽӹÜVanirÀÕË÷Èí¼þйÃÜÍøÕ¾
9ÔÂ19ÈÕ£¬µÂ¹úÖ´·¨²¿ÃÅÔÚ½üÆÚÐж¯ÖÐÀֳɴݻÙÁËÒ»¸öÃûΪVanirµÄÀÕË÷Èí¼þ×éÖ¯µÄ²¿ÃÅ»ù´¡ÉèÊ©£¬²¢½Ó¹ÜÁËÆäÓÃÓÚй¶Êܺ¦ÕßÊý¾ÝµÄÍøÕ¾¡£¸ÃÍøÕ¾ÓÚ7ÔÂÉÏÏߣ¬Æð³õÅû¶ÁËÈýÃûÊܺ¦ÕßµÄÐÅÏ¢£¬°üÂÞÒ»¼ÒµÂ¹ú¹«Ë¾¡£¿¨¶û˹³¶òÊм°°ÍµÇ-·ûÌÚ±¤Öݵľ¯·½Óë¼ì²ì¹Ù°ì¹«ÊÒ×ÔÁùÔÂÆð±ãÕë¶Ô´Ë×éÖ¯Õ¹¿ªÊӲ죬²¢ÔÚ8ÔÂÀֳɶ¨Î»²¢·âËøÁËÆäÔÚTORÍøÂçÉϵĻҳÃ棬×èÖ¹Á˸ü¶àÊý¾Ýй¶¡£¾¡¹ÜÈ¡µÃ´Ë´ÎʤÀû£¬µ«¹ØÓÚÏÓÒÉÈËÊÇ·ñ±»²¶¼°ËùÁе¹ú¹«Ë¾¾ßÌåÊÜËðÇé¿ö£¬¹Ù·½Î´Óè͸¶£¬½öÌåÏÖÏà¹ØÊÓ²ìÈÔÔÚ½øÐÐÖС£·ÖÎöÈËÊ¿Ö¸³ö£¬Vanir×éÖ¯ÓëÏÈÇ°ÒÑÖªµÄAkiraÀÕË÷Èí¼þÐж¯ÔÚйÃÜÍøÕ¾Éè¼ÆÉÏ´æÔÚÏàËÆÐÔ£¬»ò´æÔÚ¹ØÁª¡£¸Ã×éÖ¯¾ÝÐÅÓɶ«Å·³ÉÔ±×é³É£¬²¢¿ÉÄÜÓëKarakurt¡¢LockBitµÈ¾ÉÓÐÀÕË÷Èí¼þÍÅ»ïµÄÇ°³ÉÔ±Ïà¹Ø¡£´ËʼþÔÙ´Î̻¶ÁËÈ«ÇòÖ´·¨»ú¹¹ÔÚ¹¥»÷ÀÕË÷Èí¼þ·¸×ïʱËùÃæÁٵġ°´òµØÊó¡±À§¾³£¬ÓÉÓÚ·¸×ï·Ö×Ó¶à²ØÄäÓÚÄÑÒÔ´¥¼°µÄ¹ú¼Ò£¬ÆäѸËÙÖØ×éºÍ±äÖÖµÄÄÜÁ¦¸øÖ´·¨´øÀ´Á˾޴óÌôÕ½¡£
https://therecord.media/germany-seizes-vanir-ransomware-leak?&web_view=true