RECORDSTEALER¶ñÒâÈí¼þ³ÖÐøÇÔÈ¡Ãô¸ÐÐÅÏ¢
°ä²¼¹¦·ò 2024-09-249ÔÂ22ÈÕ£¬Google°²È«×êÑÐÍŶӽüÆÚ¾Û½¹ÓÚÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þµÄ³ÖÐøÍþв£¬ÓÈÆäÊÇRECORDSTEALER£¨ÓÖ³ÆRecordBreakerºÍRaccoon Stealer V2£©£¬Ò»ÖÖѡȡC˵»°±àдµÄ¸ß¼¶Êý¾Ý͵ÇÔ¹¤¾ß¡£¸Ã¶ñÒâÈí¼þרÃÅÕë¶ÔÐÅÓþ¿¨ÐÅÏ¢¡¢ÃÜÂë¡¢cookies¼°¼ÓÃÜÇ®±ÒÇ®°üµÈÃô¸ÐÊý¾Ý½øÐеÁÈ¡¡£ËüÀûÓöñÒâ¸æ°×¼°¼Ù×°³ÉºÏ·¨ÀûÓÃµÄÆÆ½âÈí¼þ×÷Ϊ´«²¼Çþ·£¬ÓÕÆÓû§ÊäÈëÃÜÂëÒÔ¼¤»îÊܱ£»¤µÄ´æµµÎļþ£¬½ø¶øÖ´ÐжñÒâ²Ù×÷¡£Ò»µ©¼¤»î£¬RECORDSTEALERͨ¹ý¼ÓÃÜRC4ºÍ̸½«Êý¾Ý´«ËÍÖÁC2·þÎñÆ÷£¬Í¬Ê±ÍøÂçÉ豸ID¡¢Óû§ÃûµÈ¹Ø¼üÐÅÏ¢¡£Ö»¹ÜRECORDSTEALERÒ»¶ÈÒò´´ÔìÕß±»²¶¼°»ù´¡ÉèÊ©±»·ÛËé¶øÆ§¾²£¬µ«Æä´«²¼Õ½ÊõÒѱ»ÏÖ´úÐÅÏ¢ÇÔÈ¡Õß¿í·ºÑ¡È¡£¬³ÖÐøÍ¨¹ý¼Ù×°ÆÆ½âÈí¼þÍþвÓû§°²È«¡£¸Ã¶ñÒâÈí¼þ²»½ö´ò½Ùä¯ÀÀÆ÷ÖеÄÓ×ÎÒÐÅÏ¢£¬»¹Éî¿Ì¼ÓÃÜÇ®±ÒÇ®°ü¡¢½ØÈ¡ÆÁÄ»½ØÍ¼£¬²¢ÍøÂ缴ʱͨѶÀûÓõÄÃô¸ÐÎļþ¡£RECORDSTEALERµÄ¼¼ÊõÊÖ·¨ÓëVIDAR¡¢STEALCµÈÆäËûÐÅÏ¢ÇÔÈ¡·¨Ê½´æÔÚ¹²ÐÔ£¬Í¹ÏÔÁ˶ñÒâÈí¼þ¼¼ÊõµÄ¸ß¶È¸´ÓÃÐԺͼì²âÄѶȡ£
https://securityonline.info/recordstealer-a-case-study-in-the-persistent-threat-of-info-stealing-malware/
2. Twilioͨ»°¼Í¼й¶£º12,000ÌõÒôƵÊý¾Ý¶³öÒþÖÔ·çÏÕ
9ÔÂ23ÈÕ£¬Ò»ÃûºÚ¿ÍÒÔ¡°grep¡±Îª±ðºÅ£¬½üÆÚй¶ÁËÐû³ÆÎªTwilioÔÆÍ¨Ñ¶Æ½Ì¨¿Í»§µÄ³¬¹ý12,000Ìõͨ»°¼Í¼£¬Ô̺¬µç»°ºÅÂ롢ͨ»°¹àÒô¼°¾ßÌåζ»°ÐÅÏ¢£¬¹¦·ò¿ç¶È´Ó2019ÄêÖÁ2024Äê¡£´ËÊÂÎñÑϳÁ¼Óº¦ÁËÓ×ÎÒ¼°ÆóÒµÓû§µÄÒþÖÔ£¬ÓÉÓÚй¶µÄͨ»°¼Í¼²»½öÔ̺¬ÔªÊý¾ÝÈçµç»°ºÅÂ롢ͨ»°¹¦·òºÍʱ³¤£¬»¹Éæ¼°ÏÖʵµÄ¶Ô»°ÄÚÈÝ¡£TwilioÊÇÒ»¼Ò·þÎñÓÚ350,000¶à¸ö¿Í»§ÕË»§µÄ¼ÓÖÝÔÆÍ¨Ñ¶¹«Ë¾£¬Õâ´Îй¶ԼռÆä×ܿͻ§ÊýµÄ3.37%¡£Ö»¹ÜºÚ¿ÍδÃ÷È·×¢Ã÷ÈëÇÖ·½Ê½£¬µ«Ð¹Â¶µÄͨ»°¼Í¼¾ßÌå¼Í¼ÁËͨ»°Ë«·½ºÅÂ롢״̬¡¢Ê±³¤¼°ÔÚ¿ÚÒë·þÎñÖеÄÌØ¶¨ÐÅÏ¢£¬Èç˵»°¡¢·ÑÂʺͻỰ¾ßÌåÐÅÏ¢¡£Õâ´Îй¶ÊÂÎñ²»½ö½ÒʾÁËͨ»°µÄÃô¸ÐÄÚÈÝ£¬»¹Ôö³¤ÁËÊܺ¦ÕßÔâ·êÀÕË÷¡¢Ú²ÆºÍÉí·Ý¼ÙÒâµÄ·çÏÕ¡£ÆóÒµ¿ÉÄÜÒò¶øÃæ¶ÔGDPR»òCCPAµÈÒþÖÔ±£»¤ÂÉÀýµÄ´¦·£¡£Í¬Ê±£¬Ð¹Â¶µÄµç»°ºÅÂëÒ²³ÉΪ¶ÌÐźÍÓïÒôÍøÂç´¹µö¹¥»÷µÄÐÂÖ¸±ê¡£ÎªÁËÓ¦¶ÔÕâһΣ»ú£¬ÊÜÓ°Ïì·½ÐèѸ¿ìÐж¯£¬Í¨ÖªÓû§¡¢±£»¤¹àÒôÊý¾Ý²¢Õ÷ѯ˾·¨½¨Òé¡£´Ë±í£¬¼ÓÇ¿½Ó¼û½ÚÔì¡¢Êý¾Ý¼ÓÃܺÍÓ¦¼±ÏìÓ¦»úÔìÒ²ÊÇ·À±¸½«À´ÀàËÆÊÂÎñµÄ¹Ø¼ü´ëÊ©¡£
https://hackread.com/hacker-leaks-twilio-call-records-audio-recordings/
3. Android¶ñÒâÈí¼þNecroͨ¹ýGoogle PlayϰȾ1100Íǫ̀É豸
9ÔÂ23ÈÕ£¬Android Óû§Ãæ¶ÔÑϳÁµÄ¶ñÒâÈí¼þÍþв£¬ÃûΪNecroµÄаæÄ¾Âí¼ÓÔØÆ÷ͨ¹ýGoogle PlayÉϵĺϷ¨ÀûÓü°·Ç¹Ù·½Çþ·´«²¼µÄÅú¸Ä°æÈí¼þ£¬ÒÑDZÈ볬¹ý1100Íǫ̀É豸¡£NecroÀûÓöñÒâ¸æ°×Èí¼þ¿ª·¢¹¤¾ß°ü£¨SDK£©Âñ·üÓÚÕÕÆ¬±à×ëÀûÓá°ÎÞËûÏà»ú¡±¼°ÍøÂçä¯ÀÀÆ÷¡°Max Browser¡±µÈÊ¢ÐÐÈí¼þÖУ¬ÕâЩSDK¼Ù×°³ÉÕý³£Ö°ÄÜ£¬ÊµÔò×°Öøæ°×Èí¼þ¡¢Ö´ÐÐJavaScriptºÍDEXÎļþ¡¢Íƽø¶©ÔÄڲƣ¬²¢×÷Ϊ¶ñÒâÁ÷Á¿´úÀí¡£Ö»¹Ü²¿ÃÅÀûÓÃÒѸüÐÂÒÔÒÆ³ýNecro£¬µ«¾É°æ±¾ÒÅÁôµÄ¶ñÒâ¸ºÔØÈÔ¿ÉÄܶÔÉ豸×é³ÉÍþв¡£´Ë±í£¬Necro»¹Í¨¹ý·Ç¹Ù·½Çþ·´«²¼µÄWhatsApp¡¢Spotify¼°MinecraftµÈÈȵãÈí¼þµÄÅú¸Ä°æ¿í·ºÀ©É¢£¬Ö´ÐÐÚ²ÆÐÔ¸æ°×չʾ¡¢Î´¾ÊÚȨµÄÀûÓ÷¨Ê½×°Öü°Ó븶·Ñ·þÎñ½»»¥µÈ¶ñÒâÐÐΪ¡£ÓÉÓڷǹٷ½Çþ·ÄÑÒÔ×·×Ù¾ßÌåϰȾÊýÁ¿£¬µ«ÒÑÖªGoogle Playƽ̨µÄϰȾ¹æÄ£ÒÑÏàµ±ÖØ´ó¡£¹È¸èÒѶԴËÀà¾Ù±¨·¢Õ¹µ÷²é£¬¶ø°²È«×¨¼Ò½¨ÒéÓû§Î¬³Ö¾¯Ìè£¬ÊµÊ±Ð¶ÔØÊÜϰȾÀûÓò¢×ªÏò°²È«ÆðÔ´¡£
https://www.bleepingcomputer.com/news/security/android-malware-necro-infects-11-million-devices-via-google-play/
4. MC2 DataÊý¾Ýй¶£º2.2TBÓ×ÎÒÐÅϢ¶³ö£¬Ó°Ï쳬1ÒÚÃÀ¹úÈË
9ÔÂ23ÈÕ£¬¾ÝCybernewsµÄ×êÑУ¬²¼¾°µ÷²é¹«Ë¾MC2 DataµÄÒ»¸ö´óÐÍÔÚÏßÊý¾Ý¿â£¬ÄÚº¬2.2TBµÄÃÀ¹úÈËÓ×ÎÒÐÅÏ¢£¬ÒòδÉèÃÜÂë±£»¤¶øÂ¶³öÔÚ»¥ÁªÍøÉÏ£¬ÈκÎÈ˾ù¿ÉÇáËɽӼû¡£¸ÃÊý¾Ý¿â¿í·ºÍøÂçÁËÔ̺¬·¸×ï¼Í¼¡¢¾ÍÒ·úÊ·¡¢¼ÒÍ¥Êý¾ÝºÍÁªÏµ·½Ê½µÈÃô¸ÐÐÅÏ¢£¬Ó°ÏìÁìÓò¿í·º£¬¾Ý¹À¼ÆÖÁÉÙÓÐ1ÒÚÃÀ¹úÈË£¨Ô¼Õ¼È«¹úÈ˶¡µÄÈý·ÖÖ®Ò»£©µÄÊý¾ÝÔâй¶¡£¸üÁîÈËÓÇÓôµÄÊÇ£¬»¹Óг¬¹ý230ÍòµÄMC2 Data·þÎñ¶©ÔÄÕßµÄÊý¾ÝҲδÄÜÐÒÃâ¡£´ËÊÂÎñÔÙ´Î͹ÏÔÁËijЩÆóÒµÔÚÊý¾Ý°²È«·½ÃæµÄÑϳÁºöÂÔ£¬Ö»¹ÜÕâЩÆóÒ·íÓ¦×ñÊØÓйØÂÉÀý£¬µ«Æä°²È«´ëʩȴÏÔÖø²»¼°¡£×¨¼ÒÖÒ¸æ³Æ£¬´ËÀàÊý¾Ýй¶¶ÔÍøÂç·¸×ï·Ö×Ó¶øÑÔÈçͬ½ð¿ó£¬ÎªÆäÖ´ÐÐÚ¿Æ¡¢Éí·Ý͵ÇԵȷ¸×ï»î¶¯ÌṩÁ˼«·çÑÅ±ã¡£Ãæ¶ÔDZÔÚµÄÊý¾Ýй¶·çÏÕ£¬Ó×ÎÒÓ¦Ìá¸ß¾¯Ì裬²ÉÈ¡±ØÒª´ëÊ©±£»¤×ÔÉíÐÅÏ¢°²È«¡£
https://www.malwarebytes.com/blog/news/2024/09/100-million-us-citizens-have-records-leaked-by-background-check-service
5. ¿°ÈøË¹Öݸ»À¼¿ËÁÖÏØ½ü3Íò¾ÓÃñÊý¾ÝÔâÀÕË÷Èí¼þ¹¥»÷й¶
9ÔÂ24ÈÕ£¬¿°ÈøË¹Öݵĸ»À¼¿ËÁÖÏØ×î½üÔâ·êÁËÑϳÁµÄÀÕË÷Èí¼þ¹¥»÷ÊÂÎñ£¬µ¼Ö½ü30,000Ãû¾ÓÃñµÄÃô¸ÐÐÅÏ¢±»Ð¹Â¶¡£¸Ã¹¥»÷²úÉúÔÚ½ñÄê5ÔÂ19ÈÕ£¬ºÚ¿Í³É¹¦ÇÖÈëÁËÏØÊé¼Ç¹Ù°ì¹«ÊÒµÄϵͳ£¬µÁÈ¡ÁËÔ̺¬ÐÕÃû¡¢Éç»á°²È«ºÅÂë¡¢¼ÝÊ»ÅÆÕÕºÅÂë¡¢½ðÈÚÕË»§ºÅÂë¼°Ò½ÁÆÐÅÏ¢µÈÔÚÄÚµÄÓ×ÎÒÊý¾Ý¡£ÕâЩÊý¾Ý»¹º¸ÇÁËÒ½ÁƼͼ¡¢ÒßÃç½ÓÖÖ¡¢COVID-19ÓйØÐÅÏ¢ÒÔ¼°±£ÏÕ¼ø±ðºÅµÈÃô¸Ð·þÎñÐÅÏ¢¡£ÊÂÎñÆØ¹âºó£¬¸»À¼¿ËÁÖÏØÑ¸¿ìÁªÏµÍøÂ簲ȫר¼ÒºÍÁª¹ú·¨Âɲ¿ÃÅ£¬²¢ÓÚ7ÔÂ19ÈÕÏò¹«×æ´«µÝÁ˵÷²é½øÕ¹¡£Ö»¹ÜĿǰûÓÐÀÕË÷Èí¼þÍÅ»ïÈÏ¿ÉÔðÈΣ¬ÇÒÏØ·½ÔÚ°µÍøËÑË÷ÖÐδ·¢ÏÖÊý¾Ý±»°ä²¼»òÏúÊ۵ļ£Ï󣬵«¸ÃÊÂÎñÈÔÒýÆðÁË¿í·º¹Ø×¢¡£¿°ÈøË¹ÖÝÖÝÎñÇä°ì¹«Êҵȼà¹Ü»ú¹¹ÒÑ»ñÖª´ËÊ£¬²¢ÒªÇó¸ÃÏØ¼ÓÇ¿°²È«´ëÊ©£¬ÒÔ·À±¸½«À´ÀàËÆÊÂÎñµÄ²úÉú¡£Îª´Ë£¬¸»À¼¿ËÁÖÏØÒѲÉȡһϵÁдëÊ©£¬Ô̺¬½ûÓò»»îÔ¾µÄÓû§ÕÊ»§£¬ÒÔÌá¸ßÊý¾Ý±£»¤Ë®Æ½¡£
https://therecord.media/kansas-ransomware-attack-thousands-residents
6. µÂ¹ú·¨Âɲ¿Ãųɹ¦ÊÕÊÜVanirÀÕË÷Èí¼þйÃÜÍøÕ¾
9ÔÂ19ÈÕ£¬µÂ¹ú·¨Âɲ¿ÃÅÔÚ½üÆÚÐж¯Öгɹ¦·ÛËéÁËÒ»¸öÃûΪVanirµÄÀÕË÷Èí¼þ×éÖ¯µÄ²¿ÃÅ»ù´¡ÉèÊ©£¬²¢ÊÕÊÜÁËÆäÓÃÓÚй¶Êܺ¦ÕßÊý¾ÝµÄÍøÕ¾¡£¸ÃÍøÕ¾ÓÚ7ÔÂÉÏÏߣ¬Æð³õÅû¶ÁËÈýÃûÊܺ¦ÕßµÄÐÅÏ¢£¬Ô̺¬Ò»¼ÒµÂ¹ú¹«Ë¾¡£¿¨¶û˹³¶òÊм°°ÍµÇ-·ûÌÚ±¤Öݵľ¯·½Óë¼ì²ì¹Ù°ì¹«ÊÒ×ÔÁùÔÂÆð±ãÕë¶Ô´Ë×éÖ¯·¢Õ¹µ÷²é£¬²¢ÔÚ8Ô³ɹ¦¶¨Î»²¢¹Ø±ÕÁËÆäÔÚTORÍøÂçÉÏµÄ»î¶¯Ò³Ãæ£¬×èÖ¹Á˸üÎÞÊý¾Ýй¶¡£Ö»¹Ü»ñµÃÕâ´Î³É¹¦£¬µ«¹ØÓÚÏÓÒÉÈËÊÇ·ñ±»²¶¼°ËùÁе¹ú¹«Ë¾¾ßÌåÊÜËðÇé¿ö£¬¹Ù·½Î´Óèй©£¬½ö°µÊ¾Óйص÷²éÈÔÔÚ½øÐÐÖС£·ÖÎöÈËʿָ³ö£¬Vanir×éÖ¯ÓëÏÈǰÒÑÖªµÄAkiraÀÕË÷Èí¼þÐж¯ÔÚйÃÜÍøÕ¾Éè¼ÆÉÏ´æÔÚÀàËÆÐÔ£¬»ò´æÔÚ¹ØÁª¡£¸Ã×éÖ¯¾ÝÐÅÓɶ«Å·³ÉÔ±×é³É£¬²¢¿ÉÄÜÓëKarakurt¡¢LockBitµÈ¾ÉÓÐÀÕË÷Èí¼þÍÅ»ïµÄǰ³ÉÔ±Óйء£´ËÊÂÎñÔٴζ³öÁËÈ«Çò·¨ÂÉ»ú¹¹ÔÚ½ø¹¥ÀÕË÷Èí¼þ·¸×ïʱËùÃæ¶ÔµÄ¡°´òµØÊó¡±À§¾³£¬ÓÉÓÚ·¸×ï·Ö×Ó¶àÒþÄäÓÚÄÑÒÔ´¥¼°µÄ¹ú¶È£¬ÆäѸ¿ì³Á×éºÍ±äÖÖµÄÄÜÁ¦¸ø·¨ÂÉ´øÀ´Á˾޴óÌôÕ½¡£
https://therecord.media/germany-seizes-vanir-ransomware-leak?&web_view=true


¾©¹«Íø°²±¸11010802024551ºÅ