SpyLoan¶ñÒâÈí¼þÔÙÏ®£º15¿îÐÂÓ¦ÓÃGoogle PlayÏÂÔس¬800Íò´Î

Ðû²¼Ê±¼ä 2024-12-02

1. SpyLoan¶ñÒâÈí¼þÔÙÏ®£º15¿îÐÂÓ¦ÓÃGoogle PlayÏÂÔس¬800Íò´Î


11ÔÂ30ÈÕ£¬Google Play ÉÏ·¢ÏÖÁËÒ»×éеÄ15¸öSpyLoan Android¶ñÒâÈí¼þÓ¦Ó÷¨Ê½£¬ÕâЩӦÓÃÖ÷ÒªÕë¶ÔÄÏÃÀ¡¢¶«ÄÏÑǺͷÇÖÞµÄÓû§£¬°²×°Á¿ÒÑÁè¼Ý800Íò´Î¡£ÕâЩӦÓ÷¨Ê½ÓÉ¡°Ó¦Ó÷¨Ê½·ÀÓùÁªÃË¡±³ÉÔ±Âõ¿Ë·Æ·¢ÏÖ²¢³ÂËߣ¬ËæºóÒѱ»´ÓAndroid¹Ù·½Ó¦ÓÃÉ̵êÖÐɾ³ý¡£SpyLoanÓ¦Ó÷¨Ê½ÒÔ½ðÈÚ¹¤¾ßΪ»Ï×Ó£¬Í¨¹ý¿ìËÙÉóÅúÁ÷³ÌÏòÓû§ÌṩÆÛÆ­ÐÔÇÒͨ³£Ðé¼ÙµÄ´û¿îÌõ¿î¡£Ò»µ©Êܺ¦Õß°²×°ÁËÕâЩӦÓã¬ËûÃǾͻᱻҪÇóÌá½»Ãô¸ÐµÄÉí·ÝÖ¤Ã÷Îļþ¡¢Ô±¹¤ÐÅÏ¢ºÍÒøÐÐÕË»§Êý¾Ý£¬²¢Í¨¹ýÒ»´ÎÐÔÃÜÂë½øÐÐÑéÖ¤¡£´ËÍ⣬ÕâЩӦÓû¹»áÀÄÓÃÉ豸ȨÏÞÊÕ¼¯´óÁ¿Ãô¸ÐÊý¾Ý£¬°üÂÞÁªÏµÈËÁÐ±í¡¢¶ÌÐÅ¡¢Ïà»ú¡¢Í¨»°¼Ç¼ºÍλÖõÈ£¬ÓÃÓÚºóÐøµÄÀÕË÷¹ý³Ì¡£¾¡¹ÜGoogleµÄÓ¦ÓÃÉóºË»úÖÆ¿ÉÒÔÆÁ±ÎÎ¥·´Play StoreÌõ¿îµÄÈí¼þ£¬µ«SpyLoanÓ¦ÓÃÈÔÈ»Äܹ»Â©Íø¡£ÎªÁË·À·¶ÕâÖÖ·çÏÕ£¬Óû§Ó¦×ÐϸÔĶÁÓû§ÆÀÂÛ¡¢¼ì²é¿ª·¢ÕßµÄÉùÓþ¡¢ÏÞÖÆ°²×°Ê±ÊÚÓèÓ¦Ó÷¨Ê½µÄȨÏÞ£¬²¢È·±£Éè±¹ØÁ¬ÄGoogle Play Protect´¦Óڻ״̬¡£


https://www.bleepingcomputer.com/news/security/spyloan-android-malware-on-google-play-installed-8-million-times/


2. ²©ÂåÄáÑÇ×ãÇò¾ãÀÖ²¿ÔâRansomHubÀÕË÷Èí¼þ¹¥»÷


11ÔÂ30ÈÕ£¬Òâ´óÀûÖ°Òµ×ãÇò¾ãÀÖ²¿²©ÂåÄáÑÇ×î½ü³ÉΪÁËRansomHubÍøÂç·¸×ïÍÅ»ïµÄÀÕË÷Èí¼þ¹¥»÷Ä¿±ê¡£¾Ý¸ÃÍÅ»ïÔÚ°µÍøÉϵÄÌû×Ó£¬ËûÃÇÉù³ÆÒѾ­ÇÔÈ¡²¢Ðû²¼Á˲©ÂåÄáÑǵĴóÁ¿Êý¾Ý£¬°üÂÞÖ÷½ÌÁ·ÎÄÉ­×ô¡¤Òâ´óÀûŵµÄ¹ÍÓ¶ºÏͬ£¬ÆäÖÐÏêϸÁгöÁËËûµÄн³êºÍ½±½ðÐÅÏ¢¡£´ËÍ⣬»¹Éù³ÆÇÔÈ¡ÁËÇ°ÖúÀí½ÌÁ·µÄ»¤ÕÕɨÃè¼þ¡¢Ò»Ï߶ÓÇòÔ±µÄ»¤ÕÕ¡¢ºÏͬºÍ¸öÈËÊý¾Ý£¬ÒÔ¼°¾ãÀÖ²¿µÄ²ÆÕþ×´¿öÃ÷ϸºÍÒ½ÁÆÊý¾ÝµÈ¡£RansomHubÔÚÆäÊý¾Ýй¶ÍøÕ¾ÉÏÌåÏÖ£¬²©ÂåÄáÑÇÒòÍøÂçÄþ¾²ÐÔ²»×ã¶øÔâµ½¹¥»÷£¬ËùÓÐÊý¾Ý¾ù±»µÁ¡£¾ãÀÖ²¿Ëæºó·¢±íÉùÃ÷֤ʵÁËÀÕË÷Èí¼þ¹¥»÷µÄ´æÔÚ£¬²¢ÌåÏÖÊý¾Ý¿ÉÄܻᱻ¹ûÈ»¡£RansomHub¸øÁ˲©ÂåÄáÑÇÈýÌìʱ¼äÀ´Âú×ãδ¹ûÈ»µÄÒªÇ󣬷ñÔòËùÓÐÊý¾Ý½«ÓÚ11ÔÂ29ÈÕÖÐÎç·ÅÖÃÔÚÆäÊý¾Ýй¶ÍøÕ¾ÉÏ¡£¾¡¹Ü²©ÂåÄáÑǵȾãÀÖ²¿´ËÇ°Ò²ÔøÔâÊܹýÍøÂç¹¥»÷£¬µ«´Ë´ÎʼþÔÙ´ÎÌáÐÑÁËÖ°Òµ×ãÇò¾ãÀÖ²¿¼ÓÇ¿ÍøÂçÄþ¾²·À»¤µÄÖØÒªÐÔ¡£


https://www.theregister.com/2024/11/30/bologna_fc_ransomhub/


3. Rockstar 2FA£ºÐÂÐÍÍøÂçµöÓãƽ̨ÇÔÈ¡Microsoft 365ƾ¾Ý


11ÔÂ29ÈÕ£¬ÃûΪ¡°Rockstar 2FA¡±µÄÐÂÐÍÍøÂçµöÓã¼´·þÎñ£¨PhaaS£©Æ½Ì¨ÒѾ­·ºÆð£¬×¨ÎªÊµÊ©´ó¹æÄ£ÖмäÈË£¨AiTM£©¹¥»÷¶øÉè¼Æ£¬Ö¼ÔÚÇÔÈ¡Microsoft 365ƾ¾Ý¡£¸Ãƽ̨ͨ¹ýÀ¹½ØÓÐЧµÄ»á»°cookie£¬ÔÊÐí¹¥»÷ÕßÈƹýÄ¿±êÕÊ»§µÄ¶àÖØÉí·ÝÑéÖ¤£¨MFA£©±£»¤¡£Êܺ¦Õß±»ÓÕµ¼µ½·ÂðµÄMicrosoft 365µÇ¼ҳÃ棬ÊäÈëƾ¾Ýºó£¬AiTM·þÎñÆ÷½«Æäת·¢ÖÁMicrosoftµÄºÏ·¨·þÎñÍê³ÉÑéÖ¤£¬²¢ÔÚ·µ»Øʱ²¶×½cookie¡£Rockstar 2FAʵ¼ÊÉÏÊÇDadSecºÍPhoenix¹¤¾ß°üµÄ¸üа棬×Ô2024Äê8ÔÂÒÔÀ´ÔÚÍøÂç·¸×ïÉçÇøÖдóÊÜ»¶Ó­£¬Á½ÖÜÊÛ¼Û200ÃÀÔª£¬API·ÃÎÊÐø¶©180ÃÀÔª¡£¸Ã·þÎñÔÚTelegramµÈƽ̨Íƹ㣬¾ß±¸¶àÏЧ£¬ÈçÖ§³Ö¶à¸öƽ̨¡¢Ìӱܼì²â¡¢Êܺ¦Õßɸ²é¡¢×Ô¶¯FUD¸½¼þºÍÁ´½Ó¡¢Óû§ÓѺõĹÜÀíÃæ°åµÈ¡£×Ô2024Äê5ÔÂÒÔÀ´£¬Òѽ¨Á¢5000¶à¸öÍøÂçµöÓãÓò£¬ÀÄÓúϷ¨µç×ÓÓʼþÓªÏúƽ̨»òÈëÇÖÕË»§Á÷´«¶ñÒâÐÅÏ¢£¬Ê¹ÓöþάÂë¡¢ºÏ·¨Ëõ¶Ì·þÎñÁ´½ÓºÍPDF¸½¼þµÈÌÓ±Ü×èÖ¹ÒªÁì¡£¾¡¹ÜÖ´·¨²¿ÃÅÒѽÓÄÉÐж¯¹¥»÷PhaaSƽ̨£¬µ«Rockstar 2FAµÄ·ºÆðºÍÆÕ¼°±íÃ÷£¬Ö»ÒªÍøÂç·¸×ï·Ö×ÓÄÜÒԵͳɱ¾»ñÈ¡ÕâЩ¹¤¾ß£¬´ó¹æÄ£ÓÐЧÍøÂçµöÓãÐж¯µÄ·çÏÕÈÔ½«Á¬Ðø´æÔÚ¡£


https://www.bleepingcomputer.com/news/security/new-rockstar-2fa-phishing-service-targets-microsoft-365-accounts/


4. Ðé¼Ù²©²ÊÓ¦ÓÃÀûÓÃAIÉùÒôÇÔÈ¡Ãô¸ÐÊý¾Ý


11ÔÂ29ÈÕ£¬ÍøÂç·¸×ï·Ö×ÓÕýÀûÓôøÓÐAIÉú³ÉÉùÒôµÄÐé¼Ù²©²ÊÓ¦Ó÷¨Ê½ºÍ¹ã¸æ£¬Í¨¹ýÉ罻ýÌåƽ̨ÒýÓÕÓû§ÏÂÔØÆÛÕ©ÐÔÓ¦Ó㬴ӶøÇÔÈ¡¸öÈËÐÅÏ¢ºÍ½ðÇ®¡£¾ÝÍøÂçÄþ¾²¹«Ë¾Group-IB·¢ÏÖ£¬ÒÑÓÐÁè¼Ý500ÌõÐé¼Ù¹ã¸æºÍ1377¸ö¶ñÒâÍøÕ¾±»Ê¶±ð£¬Ö÷ÒªÕë¶Ô°£¼°¡¢Öж«¡¢Å·ÖÞºÍÑÇÖÞÓû§¡£ÕâЩթƭÕßʹÓÃAIÉú³É¶àÓïÑÔÉùÒô£¬Ôö¼ÓÆ­¾ÖµÄ¿ÉÐŶÈ£¬µ¼ÖÂÊܺ¦ÕßÔâÊÜÖØ´ó¾­¼ÃËðʧ£¬²¿ÃÅËðʧÁè¼Ý10,000ÃÀÔª¡£Óû§Ó¦ÖÆÖ¹´Ó·Ç¹Ù·½À´Ô´ÏÂÔØÓ¦Ó㬾¯Ìè²»ÐÐÐŵÄÓŻݣ¬²¢½ÓÄÉÇ¿ÓÐÁ¦µÄÄþ¾²´ëÊ©£¬ÈçʹÓÃÃÜÂëºÍË«ÒòËØÉí·ÝÑéÖ¤£¬ÒÔ·À·¶´ËÀàÍøÂçÕ©Æ­¡£´ËÍ⣬Ðé¼ÙÆÀÂÛºÍÍƼöÒ²ÊÇÕâЩƭ¾ÖµÄÒªº¦´Ù³ÉÒòËØ£¬Óû§Ó¦±£³Ö¾¯Ì裬Á˽â×îеÄÔÚÏßÕ©Æ­ºÍÍøÂçµöÓã¼¼Êõ£¬È·±£¸öÈËÐÅÏ¢Äþ¾²¡£


https://hackread.com/fake-betting-apps-ai-generated-voices-steal-data/


5. NHS¶ùͯҽԺÔâINC RansomÀÕË÷Èí¼þÍŻ﹥»÷


11ÔÂ29ÈÕ£¬Ó¢¹ú¹ú¼ÒÒ½ÁÆ·þÎñÌåϵ£¨NHS£©µÄÀûÎïÆÖ°¢¶ûµÂº£¶ùͯҽԺºÍÀûÎïÆÖÐÄÐØÒ½ÔºNHS»ù½ð»áËƺõÕýÔâÊÜINC RansomÀÕË÷Èí¼þÍÅ»ïµÄ¹¥»÷£¬¸ÃÍÅ»ïÍþвҪй¶ÆäËùÇÔÈ¡µÄÊý¾Ý¡£¾Ý³Æ£¬ÕâЩÊý¾Ý°üÂÞ»¼Õߺ;èÔùÕßµÄÈ«Ãû¡¢µØÖ·¡¢¾èÔù½ð¶î¡¢Ò½ÁƳÂËߺͲÆÕþÎļþµÈ£¬Ê±¼ä¿ç¶È´Ó2018ÄêÖÁ2024Äê¡£Ò½ÔºÒÑ·¢±íÉùÃ÷£¬ÕýÔÚÓëºÏ×÷»ï°éºËʵÊý¾Ý²¢Á˽âDZÔÚÓ°Ï죬ͬʱÓë¹ú¼Ò·¸×ï¾ÖºÏ×÷±£»¤ÏµÍ³¡£Óë´Ëͬʱ£¬µØÀíλÖÃÏàÁÚµÄÍþÀÕ¶ûNHSÐÅÍлú¹¹Ò²ÔâÓöÁËÍøÂç¹¥»÷£¬µ«Á½´ÎÏ®»÷ËƺõûÓйØÁª¡£¾¡¹ÜNHS×éÖ¯Êܵ½Ï®»÷µÄÇé¿ö²¢²»º±¼û£¬µ«Á½´ÎÏ®»÷ÔÚͬһÖÜÄÚÏà¸ô²»Ô¶£¬ÊµÊôÆæ¹Ö¡£°¢¶ûµÂ¡¤ºÚÒÁÒ½ÔºÌåÏÖ£¬Æä·þÎñÕý³£ÔËÐУ¬Ã»ÓÐÊܵ½Ó°Ïì¡£INC RansomÍÅ»ïÔøÏ®»÷¹ýËÕ¸ñÀ¼NHSϵͳ£¬²¢ÇÔÈ¡ÁË15ÍòÈ˵ÄÊý¾Ý£¬´Ë´ÎÏ®»÷ÊÖ·¨ÀàËÆ£¬¿ÉÄÜÊÇΪÁËÊ©¼ÓѹÁ¦ÒÔÂú×ãÀÕË÷ÒªÇó¡£


https://www.theregister.com/2024/11/29/inc_ransom_alder_hey_childrens_hospital/


6. ¶íÂÞ˹ִ·¨²¿ÃÅÒÑ´þ²¶²¢ÆðËßÍøÂç·¸×ï·Ö×ÓWazawaka


11ÔÂ29ÈÕ£¬¶íÂÞ˹ִ·¨²¿ÃÅÒÑ´þ²¶²¢ÆðËßÎÛÃûÕÑÖøµÄÀÕË÷Èí¼þ¿ª·¢ÕßÃ×¹þÒÁ¶û¡¤ÅÁ·òÂåάÆ桤ÂíÌØάҮ·ò£¨Mikhail Pavlovich Matveev£©£¬ËûÒ²±»³ÆΪWazawaka¡¢Uhodiransomwar¡¢m1xºÍBoriselcin¡£Ëû±»Ö¸¿Ø¿ª·¢¶ñÒâÈí¼þ²¢¼ÓÈë¶à¸öºÚ¿Í×éÖ¯¡£¾Ý¶íÂÞ˹ÄÚÎñ²¿ÉùÃ÷£¬ÊÓ²ìÈËÔ±ÒÑÊÕ¼¯µ½×ã¹»Ö¤¾Ý£¬²¢½«ÆäÒÆËÍÖÁ¼ÓÀïÄþ¸ñÀÕÊÐÖÐÑëµØÒªÁìÔº½øÐÐÉóÀí¡£ÍøÂçÕþ²ßר¼Ò°ÂÁиñ¡¤É³»ùÂå·ò·¢ÏÖ£¬ÂíÌØάҮ·ò¼Æ»®Ê¹ÓÃÀÕË÷Èí¼þ¼ÓÃÜÉÌÒµ×éÖ¯µÄÊý¾ÝÒÔÊÕÈ¡½âÃÜÊê½ð¡£È¥Äê5Ô£¬ÃÀ¹ú˾·¨²¿Ò²¶ÔÂíÌØάҮ·òÌá³öÖ¸¿Ø£¬Ö¸¿ØËû¼ÓÈëÁËHiveºÍLockBitÀÕË÷Èí¼þÐж¯¡£´ËÍ⣬Ëû»¹±»ÈÏΪÊÇRampºÚ¿ÍÂÛ̳µÄ´´½¨Õߺ͹ÜÀíÔ±£¬ÒÔ¼°BabukÀÕË÷Èí¼þÐж¯µÄ×î³õ¹ÜÀíÔ±¡£ÃÀ¹ú²ÆÕþ²¿Íâ¹ú×ʲú¿ØÖư칫ÊÒÒ²¶ÔÂíÌØάҮ·òʵʩÁËÖƲã¬ÃÀ¹ú¹úÎñÔºÐüÉÍ1000ÍòÃÀÔªÕ÷¼¯ÓйØËûµÄÐÅÏ¢¡£ÂíÌØάҮ·òÔÚÍøÉϷdz£»îÔ¾£¬¾­³£ÓëÍøÂçÄþ¾²Ñо¿ÈËÔ±ºÍרҵÈËÊ¿½»Ì¸£¬²¢¹ûÈ»ÌÖÂÛËûµÄÍøÂç·¸×ï»î¶¯¡£ÔÚÊܵ½ÃÀ¹úÖƲúó£¬ËûÉõÖÁÔÚÍÆÌØÉϼ¥Ð¦ÃÀ¹úÖ´·¨²¿ÃÅ£¬²¢Ðû²¼ÁËÒ»ÕÅͨ¼©º£±¨µÄÕÕƬ¡£


https://www.bleepingcomputer.com/news/security/russia-arrests-cybercriminal-wazawaka-for-ties-with-ransomware-gangs/