SpyLoan¶ñÒâÈí¼þÔÙÏ®£º15¿îÐÂÓ¦ÓÃGoogle PlayÏÂÔØ³¬800Íò´Î

Ðû²¼Ê±¼ä 2024-12-02

1. SpyLoan¶ñÒâÈí¼þÔÙÏ®£º15¿îÐÂÓ¦ÓÃGoogle PlayÏÂÔØ³¬800Íò´Î


11ÔÂ30ÈÕ £¬Google Play ÉÏ·¢ÏÖÁËÒ»×éеÄ15¸öSpyLoan Android¶ñÒâÈí¼þÓ¦Ó÷¨Ê½ £¬ÕâЩӦÓÃÖ÷ÒªÕë¶ÔÄÏÃÀ¡¢¶«ÄÏÑǺͷÇÖÞµÄÓû§ £¬°²×°Á¿ÒÑÁè¼Ý800Íò´Î¡£ÕâЩӦÓ÷¨Ê½ÓÉ¡°Ó¦Ó÷¨Ê½·ÀÓùÁªÃË¡±³ÉÔ±Âõ¿Ë·Æ·¢ÏÖ²¢³ÂËß £¬ËæºóÒѱ»´ÓAndroid¹Ù·½Ó¦ÓÃÉ̵êÖÐɾ³ý¡£SpyLoanÓ¦Ó÷¨Ê½ÒÔ½ðÈÚ¹¤¾ßΪ»Ï×Ó £¬Í¨¹ý¿ìËÙÉóÅúÁ÷³ÌÏòÓû§ÌṩÆÛÆ­ÐÔÇÒͨ³£Ðé¼ÙµÄ´û¿îÌõ¿î¡£Ò»µ©Êܺ¦Õß°²×°ÁËÕâЩӦÓà £¬ËûÃǾͻᱻҪÇóÌá½»Ãô¸ÐµÄÉí·ÝÖ¤Ã÷Îļþ¡¢Ô±¹¤ÐÅÏ¢ºÍÒøÐÐÕË»§Êý¾Ý £¬²¢Í¨¹ýÒ»´ÎÐÔÃÜÂë½øÐÐÑéÖ¤¡£´ËÍâ £¬ÕâЩӦÓû¹»áÀÄÓÃÉ豸ȨÏÞÊÕ¼¯´óÁ¿Ãô¸ÐÊý¾Ý £¬°üÂÞÁªÏµÈËÁÐ±í¡¢¶ÌÐÅ¡¢Ïà»ú¡¢Í¨»°¼Ç¼ºÍλÖõÈ £¬ÓÃÓÚºóÐøµÄÀÕË÷¹ý³Ì¡£¾¡¹ÜGoogleµÄÓ¦ÓÃÉóºË»úÖÆ¿ÉÒÔÆÁ±ÎÎ¥·´Play StoreÌõ¿îµÄÈí¼þ £¬µ«SpyLoanÓ¦ÓÃÈÔÈ»Äܹ»Â©Íø¡£ÎªÁË·À·¶ÕâÖÖ·çÏÕ £¬Óû§Ó¦×ÐϸÔĶÁÓû§ÆÀÂÛ¡¢¼ì²é¿ª·¢ÕßµÄÉùÓþ¡¢ÏÞÖÆ°²×°Ê±ÊÚÓèÓ¦Ó÷¨Ê½µÄȨÏÞ £¬²¢È·±£Éè±¹ØÁ¬ÄGoogle Play Protect´¦Óڻ״̬¡£


https://www.bleepingcomputer.com/news/security/spyloan-android-malware-on-google-play-installed-8-million-times/


2. ²©ÂåÄáÑÇ×ãÇò¾ãÀÖ²¿ÔâRansomHubÀÕË÷Èí¼þ¹¥»÷


11ÔÂ30ÈÕ £¬Òâ´óÀûÖ°Òµ×ãÇò¾ãÀÖ²¿²©ÂåÄáÑÇ×î½ü³ÉΪÁËRansomHubÍøÂç·¸×ïÍÅ»ïµÄÀÕË÷Èí¼þ¹¥»÷Ä¿±ê¡£¾Ý¸ÃÍÅ»ïÔÚ°µÍøÉϵÄÌû×Ó £¬ËûÃÇÉù³ÆÒѾ­ÇÔÈ¡²¢Ðû²¼Á˲©ÂåÄáÑǵĴóÁ¿Êý¾Ý £¬°üÂÞÖ÷½ÌÁ·ÎÄÉ­×ô¡¤Òâ´óÀûŵµÄ¹ÍÓ¶ºÏͬ £¬ÆäÖÐÏêϸÁгöÁËËûµÄн³êºÍ½±½ðÐÅÏ¢¡£´ËÍâ £¬»¹Éù³ÆÇÔÈ¡ÁËǰÖúÀí½ÌÁ·µÄ»¤ÕÕɨÃè¼þ¡¢Ò»Ïß¶ÓÇòÔ±µÄ»¤ÕÕ¡¢ºÏͬºÍ¸öÈËÊý¾Ý £¬ÒÔ¼°¾ãÀÖ²¿µÄ²ÆÕþ×´¿öÃ÷ϸºÍÒ½ÁÆÊý¾ÝµÈ¡£RansomHubÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏÌåÏÖ £¬²©ÂåÄáÑÇÒòÍøÂçÄþ¾²ÐÔ²»×ã¶øÔâµ½¹¥»÷ £¬ËùÓÐÊý¾Ý¾ù±»µÁ¡£¾ãÀÖ²¿Ëæºó·¢±íÉùÃ÷֤ʵÁËÀÕË÷Èí¼þ¹¥»÷µÄ´æÔÚ £¬²¢ÌåÏÖÊý¾Ý¿ÉÄܻᱻ¹ûÈ»¡£RansomHub¸øÁ˲©ÂåÄáÑÇÈýÌìʱ¼äÀ´Âú×ãδ¹ûÈ»µÄÒªÇó £¬·ñÔòËùÓÐÊý¾Ý½«ÓÚ11ÔÂ29ÈÕÖÐÎç·ÅÖÃÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏ¡£¾¡¹Ü²©ÂåÄáÑǵȾãÀÖ²¿´ËÇ°Ò²ÔøÔâÊܹýÍøÂç¹¥»÷ £¬µ«´Ë´ÎʼþÔÙ´ÎÌáÐÑÁËÖ°Òµ×ãÇò¾ãÀÖ²¿¼ÓÇ¿ÍøÂçÄþ¾²·À»¤µÄÖØÒªÐÔ¡£


https://www.theregister.com/2024/11/30/bologna_fc_ransomhub/


3. Rockstar 2FA£ºÐÂÐÍÍøÂçµöÓãÆ½Ì¨ÇÔÈ¡Microsoft 365ƾ¾Ý


11ÔÂ29ÈÕ £¬ÃûΪ¡°Rockstar 2FA¡±µÄÐÂÐÍÍøÂçµöÓã¼´·þÎñ£¨PhaaS£©Æ½Ì¨ÒѾ­·ºÆð £¬×¨ÎªÊµÊ©´ó¹æÄ£ÖмäÈË£¨AiTM£©¹¥»÷¶øÉè¼Æ £¬Ö¼ÔÚÇÔÈ¡Microsoft 365ƾ¾Ý¡£¸Ãƽ̨ͨ¹ýÀ¹½ØÓÐЧµÄ»á»°cookie £¬ÔÊÐí¹¥»÷ÕßÈÆ¹ýÄ¿±êÕÊ»§µÄ¶àÖØÉí·ÝÑéÖ¤£¨MFA£©±£»¤¡£Êܺ¦Õß±»ÓÕµ¼µ½·ÂðµÄMicrosoft 365µÇÂ¼Ò³Ãæ £¬ÊäÈëÆ¾¾Ýºó £¬AiTM·þÎñÆ÷½«Æäת·¢ÖÁMicrosoftµÄºÏ·¨·þÎñÍê³ÉÑéÖ¤ £¬²¢ÔÚ·µ»ØÊ±²¶×½cookie¡£Rockstar 2FAʵ¼ÊÉÏÊÇDadSecºÍPhoenix¹¤¾ß°üµÄ¸üаæ £¬×Ô2024Äê8ÔÂÒÔÀ´ÔÚÍøÂç·¸×ïÉçÇøÖдóÊÜ»¶Ó­ £¬Á½ÖÜÊÛ¼Û200ÃÀÔª £¬API·ÃÎÊÐø¶©180ÃÀÔª¡£¸Ã·þÎñÔÚTelegramµÈÆ½Ì¨ÍÆ¹ã £¬¾ß±¸¶àÏЧ £¬ÈçÖ§³Ö¶à¸öƽ̨¡¢Ìӱܼì²â¡¢Êܺ¦Õßɸ²é¡¢×Ô¶¯FUD¸½¼þºÍÁ´½Ó¡¢Óû§ÓѺõĹÜÀíÃæ°åµÈ¡£×Ô2024Äê5ÔÂÒÔÀ´ £¬Òѽ¨Á¢5000¶à¸öÍøÂçµöÓãÓò £¬ÀÄÓúϷ¨µç×ÓÓʼþÓªÏúƽ̨»òÈëÇÖÕË»§Á÷´«¶ñÒâÐÅÏ¢ £¬Ê¹ÓöþάÂë¡¢ºÏ·¨Ëõ¶Ì·þÎñÁ´½ÓºÍPDF¸½¼þµÈÌÓ±Ü×èÖ¹ÒªÁì¡£¾¡¹ÜÖ´·¨²¿ÃÅÒѽÓÄÉÐж¯¹¥»÷PhaaSƽ̨ £¬µ«Rockstar 2FAµÄ·ºÆðºÍÆÕ¼°±íÃ÷ £¬Ö»ÒªÍøÂç·¸×ï·Ö×ÓÄÜÒԵͳɱ¾»ñÈ¡ÕâЩ¹¤¾ß £¬´ó¹æÄ£ÓÐÐ§ÍøÂçµöÓãÐж¯µÄ·çÏÕÈÔ½«Á¬Ðø´æÔÚ¡£


https://www.bleepingcomputer.com/news/security/new-rockstar-2fa-phishing-service-targets-microsoft-365-accounts/


4. Ðé¼Ù²©²ÊÓ¦ÓÃÀûÓÃAIÉùÒôÇÔÈ¡Ãô¸ÐÊý¾Ý


11ÔÂ29ÈÕ £¬ÍøÂç·¸×ï·Ö×ÓÕýÀûÓôøÓÐAIÉú³ÉÉùÒôµÄÐé¼Ù²©²ÊÓ¦Ó÷¨Ê½ºÍ¹ã¸æ £¬Í¨¹ýÉ罻ýÌåÆ½Ì¨ÒýÓÕÓû§ÏÂÔØÆÛÕ©ÐÔÓ¦Óà £¬´Ó¶øÇÔÈ¡¸öÈËÐÅÏ¢ºÍ½ðÇ®¡£¾ÝÍøÂçÄþ¾²¹«Ë¾Group-IB·¢ÏÖ £¬ÒÑÓÐÁè¼Ý500ÌõÐé¼Ù¹ã¸æºÍ1377¸ö¶ñÒâÍøÕ¾±»Ê¶±ð £¬Ö÷ÒªÕë¶Ô°£¼°¡¢Öж«¡¢Å·ÖÞºÍÑÇÖÞÓû§¡£ÕâЩթƭÕßʹÓÃAIÉú³É¶àÓïÑÔÉùÒô £¬Ôö¼ÓÆ­¾ÖµÄ¿ÉÐŶÈ £¬µ¼ÖÂÊܺ¦ÕßÔâÊÜÖØ´ó¾­¼ÃËðʧ £¬²¿ÃÅËðʧÁè¼Ý10,000ÃÀÔª¡£Óû§Ó¦ÖÆÖ¹´Ó·Ç¹Ù·½À´Ô´ÏÂÔØÓ¦Óà £¬¾¯Ìè²»ÐÐÐŵÄÓÅ»Ý £¬²¢½ÓÄÉÇ¿ÓÐÁ¦µÄÄþ¾²´ëÊ© £¬ÈçʹÓÃÃÜÂëºÍË«ÒòËØÉí·ÝÑéÖ¤ £¬ÒÔ·À·¶´ËÀàÍøÂçÕ©Æ­¡£´ËÍâ £¬Ðé¼ÙÆÀÂÛºÍÍÆ¼öÒ²ÊÇÕâЩƭ¾ÖµÄÒªº¦´Ù³ÉÒòËØ £¬Óû§Ó¦±£³Ö¾¯Ìè £¬Á˽â×îеÄÔÚÏßÕ©Æ­ºÍÍøÂçµöÓã¼¼Êõ £¬È·±£¸öÈËÐÅÏ¢Äþ¾²¡£


https://hackread.com/fake-betting-apps-ai-generated-voices-steal-data/


5. NHS¶ùͯҽԺÔâINC RansomÀÕË÷Èí¼þÍŻ﹥»÷


11ÔÂ29ÈÕ £¬Ó¢¹ú¹ú¼ÒÒ½ÁÆ·þÎñÌåϵ£¨NHS£©µÄÀûÎïÆÖ°¢¶ûµÂº£¶ùͯҽԺºÍÀûÎïÆÖÐÄÐØÒ½ÔºNHS»ù½ð»áËÆºõÕýÔâÊÜINC RansomÀÕË÷Èí¼þÍÅ»ïµÄ¹¥»÷ £¬¸ÃÍÅ»ïÍþвҪй¶ÆäËùÇÔÈ¡µÄÊý¾Ý¡£¾Ý³Æ £¬ÕâЩÊý¾Ý°üÂÞ»¼Õߺ;èÔùÕßµÄÈ«Ãû¡¢µØÖ·¡¢¾èÔù½ð¶î¡¢Ò½ÁƳÂËߺͲÆÕþÎļþµÈ £¬Ê±¼ä¿ç¶È´Ó2018ÄêÖÁ2024Äê¡£Ò½ÔºÒÑ·¢±íÉùÃ÷ £¬ÕýÔÚÓëºÏ×÷»ï°éºËʵÊý¾Ý²¢Á˽âDZÔÚÓ°Ïì £¬Í¬Ê±Óë¹ú¼Ò·¸×ï¾ÖºÏ×÷±£»¤ÏµÍ³¡£Óë´Ëͬʱ £¬µØÀíλÖÃÏàÁÚµÄÍþÀÕ¶ûNHSÐÅÍлú¹¹Ò²ÔâÓöÁËÍøÂç¹¥»÷ £¬µ«Á½´ÎÏ®»÷ËÆºõûÓйØÁª¡£¾¡¹ÜNHS×éÖ¯Êܵ½Ï®»÷µÄÇé¿ö²¢²»º±¼û £¬µ«Á½´ÎÏ®»÷ÔÚͬһÖÜÄÚÏà¸ô²»Ô¶ £¬ÊµÊôÆæ¹Ö¡£°¢¶ûµÂ¡¤ºÚÒÁÒ½ÔºÌåÏÖ £¬Æä·þÎñÕý³£ÔËÐÐ £¬Ã»ÓÐÊܵ½Ó°Ïì¡£INC RansomÍÅ»ïÔøÏ®»÷¹ýËÕ¸ñÀ¼NHSϵͳ £¬²¢ÇÔÈ¡ÁË15ÍòÈ˵ÄÊý¾Ý £¬´Ë´ÎÏ®»÷ÊÖ·¨ÀàËÆ £¬¿ÉÄÜÊÇΪÁËÊ©¼ÓѹÁ¦ÒÔÂú×ãÀÕË÷ÒªÇó¡£


https://www.theregister.com/2024/11/29/inc_ransom_alder_hey_childrens_hospital/


6. ¶íÂÞ˹ִ·¨²¿ÃÅÒÑ´þ²¶²¢ÆðËßÍøÂç·¸×ï·Ö×ÓWazawaka


11ÔÂ29ÈÕ £¬¶íÂÞ˹ִ·¨²¿ÃÅÒÑ´þ²¶²¢ÆðËßÎÛÃûÕÑÖøµÄÀÕË÷Èí¼þ¿ª·¢ÕßÃ×¹þÒÁ¶û¡¤ÅÁ·òÂåÎ¬Ææ¡¤ÂíÌØÎ¬Ò®·ò£¨Mikhail Pavlovich Matveev£© £¬ËûÒ²±»³ÆÎªWazawaka¡¢Uhodiransomwar¡¢m1xºÍBoriselcin¡£Ëû±»Ö¸¿Ø¿ª·¢¶ñÒâÈí¼þ²¢¼ÓÈë¶à¸öºÚ¿Í×éÖ¯¡£¾Ý¶íÂÞ˹ÄÚÎñ²¿ÉùÃ÷ £¬ÊÓ²ìÈËÔ±ÒÑÊÕ¼¯µ½×ã¹»Ö¤¾Ý £¬²¢½«ÆäÒÆËÍÖÁ¼ÓÀïÄþ¸ñÀÕÊÐÖÐÑëµØÒªÁìÔº½øÐÐÉóÀí¡£ÍøÂçÕþ²ßר¼Ò°ÂÁиñ¡¤É³»ùÂå·ò·¢ÏÖ £¬ÂíÌØÎ¬Ò®·ò¼Æ»®Ê¹ÓÃÀÕË÷Èí¼þ¼ÓÃÜÉÌÒµ×éÖ¯µÄÊý¾ÝÒÔÊÕÈ¡½âÃÜÊê½ð¡£È¥Äê5Ô £¬ÃÀ¹ú˾·¨²¿Ò²¶ÔÂíÌØÎ¬Ò®·òÌá³öÖ¸¿Ø £¬Ö¸¿ØËû¼ÓÈëÁËHiveºÍLockBitÀÕË÷Èí¼þÐж¯¡£´ËÍâ £¬Ëû»¹±»ÈÏΪÊÇRampºÚ¿ÍÂÛ̳µÄ´´½¨Õߺ͹ÜÀíÔ± £¬ÒÔ¼°BabukÀÕË÷Èí¼þÐж¯µÄ×î³õ¹ÜÀíÔ±¡£ÃÀ¹ú²ÆÕþ²¿Íâ¹ú×ʲú¿ØÖư칫ÊÒÒ²¶ÔÂíÌØÎ¬Ò®·òʵʩÁËÖÆ²Ã £¬ÃÀ¹ú¹úÎñÔºÐüÉÍ1000ÍòÃÀÔªÕ÷¼¯ÓйØËûµÄÐÅÏ¢¡£ÂíÌØÎ¬Ò®·òÔÚÍøÉϷdz£»îÔ¾ £¬¾­³£ÓëÍøÂçÄþ¾²Ñо¿ÈËÔ±ºÍרҵÈËÊ¿½»Ì¸ £¬²¢¹ûÈ»ÌÖÂÛËûµÄÍøÂç·¸×ï»î¶¯¡£ÔÚÊܵ½ÃÀ¹úÖÆ²Ãºó £¬ËûÉõÖÁÔÚÍÆÌØÉϼ¥Ð¦ÃÀ¹úÖ´·¨²¿ÃÅ £¬²¢Ðû²¼ÁËÒ»ÕÅͨ¼©º£±¨µÄÕÕÆ¬¡£


https://www.bleepingcomputer.com/news/security/russia-arrests-cybercriminal-wazawaka-for-ties-with-ransomware-gangs/