8000 ¶à¸öÖµµÃÐÅÈÎµÄÆ·ÅÆÓòÃû±»½Ù³Ö²¢´ó¹æÄ£·¢ËÍÀ¬»øÓʼþ
°ä²¼¹¦·ò 2024-02-282ÔÂ26ÈÕ£¬£¬£¬£¬£¬Guardio Labs ÔÚ¸ú×Ùе÷µÄ¶ñÒâ»î¶¯£¬£¬£¬£¬£¬¸Ã»î¶¯ÖÁÉÙ×Ô 2022 Äê 9 ÔÂÒÔÀ´Ò»ÏòÔÚ³ÖÐø£¬£¬£¬£¬£¬ÃûΪ SubdoMailing¡£¡£¡£¡£¡£ÊôÓںϷ¨Æ·Åƺͻú¹¹µÄ 8,000 ¶à¸öÓòÃûºÍ 13,000 ¸ö×ÓÓòÃûÒѱ»½Ù³Ö£¬£¬£¬£¬£¬×÷ΪÀ¬»øÓʼþÀ©É¢ºÍµã»÷Ç®±Ò»¯µÄ¸´ÔÓ·Ö·¢¼Ü¹¹µÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£Õâ¼ÒÒÔÉ«Áа²È«¹«Ë¾½«Õâ´Î»î¶¯¹éÒòÓÚÒ»¸öÃûΪResurrecAdsµÄÍþвÐÐΪÕߣ¬£¬£¬£¬£¬¶àËùÖÜÖª£¬£¬£¬£¬£¬¸ÃÐÐΪÕß»áÐÂÉú´óÆ·ÅÆ»ò´ÓÊôÓÚ´óÆ·ÅÆµÄËÀÓòÃû£¬£¬£¬£¬£¬×îÖÕÖ¸±êÊǰѳÖÊý×Ö¸æ°×Éú̬ϵͳÒÔ»ñÈ¡·¸·¨ÊÕÒæ¡£¡£¡£¡£¡£ÕâЩ×ÓÓòÃûÊôÓÚ»ò´ÓÊôÓÚ ACLU¡¢eBay¡¢Lacoste¡¢Marvel¡¢McAfee¡¢MSN¡¢Pearson¡¢PwC¡¢Swatch¡¢Symantec¡¢The Economist¡¢UNICEF ºÍ VMware µÈ´óÆ·ÅÆºÍ×éÖ¯¡£¡£¡£¡£¡£
https://thehackernews.com/2024/02/8000-subdomains-of-trusted-brands.html
2. Booking.com ¼ÙÒâ»î¶¯£ºAgent Tesla ¶ñÒâÈí¼þ·ÖÎö
2ÔÂ26ÈÕ£¬£¬£¬£¬£¬¸Ã»î¶¯ÀûÓà Booking.com µÄÆ·ÅÆÃûÓþÀ´´«²¼ Agent Tesla£¬£¬£¬£¬£¬ÕâÊÇÒ»ÖÖ¶àÖ°ÄÜÔ¶³Ì½Ó¼ûľÂí ( RAT )¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃÓë Booking.com ÓйصÄÐÅÀµ£¬£¬£¬£¬£¬Ôì×÷¿´ËƺϷ¨ÍË¿î֪ͨµÄÍøÂç´¹µöµç×ÓÓʼþ¡£¡£¡£¡£¡£Ô̺¬ PDF ¸½¼þ»áÒªÇóÊÕ¼þÈ˲é³Ëù¸½ PDF ÖеĿ¨¶ÔÕ˵¥¡£¡£¡£¡£¡£ÕâÒ»¾«ÐÄÉè¼ÆµÄ´òËãµÄ×îÖÕÁ˾ÖÊDz¿ÊðÁËAgent Tesla¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¸Ã¶ÔÊÔìðÍ·²ÉÈ¡¶ñÒâÐж¯ÇÔȡƾ֤ºÍÓ×ÎÒÊý¾Ý£¬£¬£¬£¬£¬½«Æä²»ÒåÖ®²Æ´«Êäµ½¸öÈË Telegram ̸ÌìÊÒ¡£¡£¡£¡£¡£Ëü²¢²»Ö¹ÓÚ´Ë£»£»£»£»£»£»£»¸Ã¶ñÒâÈí¼þͨ¹ý¶î±íµÄ PowerShell ¾ç±¾È·±£ÆäÓÆ¾ÃÐÔ£¬£¬£¬£¬£¬²¢²»ÐݸĽøÆäÕ½ÊõÒÔÔÚÊÜϰȾµÄϵͳÖÐά³Ö°²Éíµã¡£¡£¡£¡£¡£
https://securityonline.info/booking-com-impersonation-campaign-agent-tesla-malware-analysis/
3. ALPHV/BlackCat ¶Ô Change Healthcare ÍøÂç¹¥»÷ÕÆ¹Ü
2ÔÂ26ÈÕ£¬£¬£¬£¬£¬¾Ý±¨Â·£¬£¬£¬£¬£¬ALPHV/BlackCat ÀÕË÷Èí¼þÍÅ»ï¶Ô Change Healthcare ´ó¹æÄ£ÍøÂç¹¥»÷ÕÆ¹Ü£¬£¬£¬£¬£¬¸Ã¹¥»÷×ÔÉÏÖÜÒÔÀ´ÒѾÇÖÈÅÁËÃÀ¹ú¸÷µØµÄÒ©µê¡£¡£¡£¡£¡£¾Ý·͸ÉçÔ®Òý¡°Á½ÃûÖªÁµÈËÊ¿¡±µÄ»°³Æ£¬£¬£¬£¬£¬³ôÃûÔ¶ÑïµÄÀÕË÷Èí¼þ¼´·þÎñ²Ù×÷ÊǽáºÏ½¡È«ÆìÏÂÆóÒµÌáÒé¹¥»÷µÄÄ»ºóºÚÊÖ¡£¡£¡£¡£¡£RegisterÉÐδ¶ÀÁ¢È·ÈÏ ALPHV ²Î¼ÓÁËÕâ´ÎÈëÇÖ¡£¡£¡£¡£¡£Change Healthcare ΪҽÁÆ»ú¹¹Ìṩ¿í·ºµÄ IT ·þÎñ£¬£¬£¬£¬£¬Ô̺¬ÈÃÒ©·¿²é³»¼ÕßÓÃÒ©×ʸñ²¢È·¶¨±£ÏÕÁìÓòµÄÈí¼þ¡£¡£¡£¡£¡£Æä¿Í»§Ô̺¬ÃÀ¹úÁ½¼Ò×î´óµÄÒ©µê¡ª¡ªCVS ºÍÎÖ¶û¸ñÁÖ¡ª¡ªÕâÁ½¼ÒÒ©µê¶¼¸Ð´¥µ½ÁËÍ£µçµÄ²»Á¼Ó°Ïì¡£¡£¡£¡£¡£Õâ¼Ò½¡È«¿Æ¼¼¹«Ë¾ÓÚ 2 Ô 21 ÈÕ³õ´ÎÅû¶ÁËÕâÒ»·ì϶£¬£¬£¬£¬£¬²¢Òò¶ø¹Ø¹ØÁ˲¿ÃÅ IT ϵͳ¡£¡£¡£¡£¡£ÖÜÎ壬£¬£¬£¬£¬ÃÀ¹úÒ©¼Áʦлᰵʾ£¬£¬£¬£¬£¬ÓÉÓÚÍøÂç¹¥»÷£¬£¬£¬£¬£¬È«¹ú¸÷µØµÄÒ©·¿ÎÞ·¨´«Ëͱ£ÏÕË÷Åâ¡£¡£¡£¡£¡£
https://www.theregister.com/2024/02/26/alphv_healthcare_unitedhealth/
4. UAC-0184 ʹÓà Remcos RAT Õë¶Ô·ÒÀ¼¾³ÄÚµÄÎÚ¿ËÀ¼ÊµÌå
2ÔÂ27ÈÕ£¬£¬£¬£¬£¬±»×·×ÙΪ UAC-0184 µÄÍþвÐÐΪÕßÒ»ÏòÔÚʹÓÃÒþдÊõ¼¼Êõ£¬£¬£¬£¬£¬Í¨¹ýÃûΪ IDAT Loader µÄÏà¶Ô½ÏеĶñÒâÈí¼þÏòλÓÚ·ÒÀ¼µÄÎÚ¿ËÀ¼Ö¸±ê´«ËÍ Remcos Ô¶³Ì½Ó¼ûľÂí (RAT)¡£¡£¡£¡£¡£Ö»¹ÜµÐÊÖ×î³õÕë¶ÔµÄÊÇÎÚ¿ËÀ¼¾³ÄÚµÄʵÌ壬£¬£¬£¬£¬µ«·ÀÓù´ëÊ©¹ÊÕÏÁËÓÐÐ§ÔØºÉµÄ½»¸¶¡£¡£¡£¡£¡£Æ¾¾Ý Morphisec Íþв³¢ÊÔÊÒ½ñÌìµÄ·ÖÎö£¬£¬£¬£¬£¬Õâµ¼ÖÂÁËËæºó¶Ô´úÌæÖ¸±êµÄËÑË÷¡£¡£¡£¡£¡£¹ÌÈ» Morphisec Òò¿Í»§»úÃܶøÃ»ÓÐй©»î¶¯Ï¸½Ú£¬£¬£¬£¬£¬µ«×êÑÐÈËÔ±Ö¸³ö Dark Reading¾Ý³ÆÓë UAC-0148 ½øÐеIJ¢ÐлÓйأ¬£¬£¬£¬£¬¸Ã»î¶¯Ê¹Óõç×ÓÓʼþºÍÓã²æÊ½ÍøÂç´¹µö×÷Ϊ³õʼ½Ó¼ûý½é£¬£¬£¬£¬£¬²¢ÒÔÎÚ¿ËÀ¼¾üÊÂÈËԱΪָ±ê£¬£¬£¬£¬£¬ÒÔÌṩÕ÷ѯΪµö¶ü¡£¡£¡£¡£¡£ÒÔÉ«Áйú·À¾ü (IDF) µÄ½ÇÉ«¡£¡£¡£¡£¡£ÆäÖ¸±êÊÇÍøÂç¼äµý»î¶¯£ºÍøÂç·¸×ï·Ö×ÓʹÓà Remcos£¨¡°Ô¶³Ì½ÚÔìºÍ¼à¶½¡±µÄËõд£©RAT À´Î´¾ÊÚȨ½Ó¼ûÊܺ¦ÕßµÄÍÆËã»ú¡¢Ô¶³Ì½ÚÔìÊÜϰȾµÄϵͳ¡¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡¢Ö´ÐкÅÁîµÈ¡£¡£¡£¡£¡£
https://www.darkreading.com/cyberattacks-data-breaches/uac-0184-targets-ukrainian-entity-finland-remcos-rat
5. ¶íÂÞ˹ºÚ¿ÍÍÅ»ïͨ¹ýÐÝÃßÕÊ»§¶Ô×¼ÔÆ»ù´¡ÉèÊ©
2ÔÂ26ÈÕ£¬£¬£¬£¬£¬ÃÀ¹ú¡¢¼ÓÄôó¡¢Ó¢¹ú¡¢°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄÍøÂ簲ȫºÍ·¨ÂÉ»ú¹¹°ä²¼½áºÏ¾¯±¨£¬£¬£¬£¬£¬ºôÓõ´¹Î£¹Ø×¢Óë APT29/Cozy Bear/Midnight Blizzard£¨Ò»¸ö³ôÃûÔ¶ÑïµÄºÚ¿Í×éÖ¯£©ÓйصÄ×îÐÂÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½ (TTP)¡£¡£¡£¡£¡£¶íÂÞ˹µý±¨²¿ÃÅ£¨SVR£©¡£¡£¡£¡£¡£¾Ý¹Û²ì£¬£¬£¬£¬£¬SVR ²Î¼ÓÕß²¢Ã»ÓÐÀûÓÃÈí¼þ·ì϶À´¹¥»÷±¾µØ»ù´¡ÉèÊ©£¬£¬£¬£¬£¬¶øÊÇÌáÒ鱩Á¦ÆÆ½âºÍÃÜÂëÅçÉä¹¥»÷À´·ÛËé·þÎñÕÊ»§£¬£¬£¬£¬£¬ÒÔ¼°Õë¶ÔǰԱ¹¤µÄÐÝÃßÕÊ»§À´½Ó¼ûÖ¸±ê×éÖ¯µÄ»·¾³¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬»¹·¢ÏÖ³ôÃûÔ¶ÑïµÄ APT ×é֯ʹÓÃÁîÅÆ½Ó¼ûÊܺ¦ÕßÕÊ»§£¬£¬£¬£¬£¬²¢Ê¹ÓÃÒ»ÖÖ³ÆÎª¡°MFA ºäÕ¨¡±»ò¡°MFA ί¶Ù¡±µÄ¼¼ÊõÈÆ¹ý¶à³ÁÉí·ÝÑéÖ¤ (MFA)¡£¡£¡£¡£¡£³õ´Î½Ó¼ûºó£¬£¬£¬£¬£¬¹¥»÷Õßͨ³£»£»£»£»£»£»£»á½«×Ô¼ºµÄÉ豸ע²áµ½Êܺ¦ÕßµÄÍøÂ磬£¬£¬£¬£¬²¢²¿Êð¸´ÔӵĹ¥»÷ºó¹¤¾ß¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ºÚ¿Í»¹ÒÀ¸½×¡Õ¬´úÀíÀ´°µ²ØÆä¶ñÒâ»î¶¯£¬£¬£¬£¬£¬Ê¹Á÷Á¿¿´ÆðÀ´ÏñÊÇÀ´×Ôסլ¿í´ø¿Í»§µÄ IP µØÖ·¡£¡£¡£¡£¡£
https://www.securityweek.com/russian-cyberspies-targeting-cloud-infrastructure-via-dormant-accounts/
6. Anonymous ËÕµ¤ÍƹãÐ嵀 DDoS ½©Ê¬ÍøÂçSkynet-GodzillaBotnet
2ÔÂ26ÈÕ£¬£¬£¬£¬£¬¾ÝÏàʶ£¬£¬£¬£¬£¬Ò»¸öÃûΪ¡°ÄäÃûËÕµ¤¡±µÄ×éÖ¯ÔÚ»ý¼«ÍƹãÒ»ÖÖÃûΪ¡°Skynet-GodzillaBotnet¡±µÄÐÂÐÍÉ¢²¼Ê½»Ø¾ø·þÎñ (DDoS) ½©Ê¬ÍøÂç·þÎñ¡£¡£¡£¡£¡£ÍøÉÏÁ÷´«µÄÒ»Ôò¸æ°×չʾÁË´øÓÓ×°SKYNET¡±×ÖÑùµÄºìÁú±êÖ¾¡£¡£¡£¡£¡£¸Ã·þÎñ±»Ðû´«ÎªÖ´ÐÐDDoS ¹¥»÷µÄ׳´ó¹¤¾ß£¬£¬£¬£¬£¬¸Ã×éÖ¯Ðû³ÆÍ¨¹ý½«ÆäÈ¨ÊÆÓëÁíÒ»¸öʵÌå¹é²¢À´¼ÓÇ¿ÆäÖ°ÄÜ¡£¡£¡£¡£¡£¡¶ÖðÈÕ°µÍø¡·Öз¢Ïֵĸæ°×Ã÷È·Ö¸³ö£¬£¬£¬£¬£¬ËüÌṩ½©Ê¬ÍøÂçµÄ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬¼ÛֵΪһÌì 100 ÃÀÔª¡¢Ò»ÖÜ 600 ÃÀÔª¡¢Ò»¸öÔ 1700 ÃÀÔª¡£¡£¡£¡£¡£Anonymous ËÕµ¤ÒÔÆä¼¤½øµÄ Web DDoS ¹¥»÷¶øÎÅÃû£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬½»ÌæµÄ UDP ºÍ SYN ºéË®¹¥»÷¡£¡£¡£¡£¡£ÕâЩ¹¥»÷´ÓÊýÒÔÍò¼ÆµÄΨһԴ IP µØÖ·ÌáÒ飬£¬£¬£¬£¬UDP Á÷Á¿¸ß´ï 600Gbps£¬£¬£¬£¬£¬HTTPS ÒªÇóºéË®·åÖµ¿É´ïÿÃëÊý°ÙÍò¸öÒªÇ󡣡£¡£¡£¡£
https://gbhackers.com/anonymous-sudan-new-ddos-botnet-warning/


¾©¹«Íø°²±¸11010802024551ºÅ