¶íÂÞ˹UNC5812Íþв×éÖ¯¶Ô×¼ÎÚ¾üбø
°ä²¼¹¦·ò 2024-10-301. ¶íÂÞ˹UNC5812Íþв×éÖ¯¶Ô×¼ÎÚ¾üбø
10ÔÂ28ÈÕ£¬¶íÂÞ˹Íþв×éÖ¯¡°UNC5812¡±±»¸æ·¢·¢Õ¹»ìºÏ¼äµý/Ó°Ïì»î¶¯£¬Õë¶ÔÎÚ¿ËÀ¼¾ü¶ÓбøÊ¹ÓÃWindowsºÍAndroid¶ñÒâÈí¼þ¡£¸Ã×é֯ͨ¹ý¼Ùð¡°Ãñ·À¡±½ÇÉ«ÉèÁ¢ÍøÕ¾ºÍTelegramƵ·£¬´«²¼ÃûΪ¡°Sunspinner¡±µÄÐéαÕÐļ¶ã±ÜÀûÓ÷¨Ê½£¬ÒÔÊý¾ÝÇÔÈ¡ºÍʵʱ¼à¶½ÎªÖ÷ÕÅ¡£¹È¸èÒÑÖ´Ðб£»¤´ëÊ©£¬µ«Õâ´ÎÐж¯ÏÔʾÁ˶íÂÞ˹ÔÚÍøÂçÕ½ÁìÓòµÄ³ÖÐøÊ¹ÓÃºÍ¿í·ºÄÜÁ¦¡£UNC5812²»¼ÙÒâµ±¾Ö»ú¹¹£¬²¢°ä·¢·ñ¾öÎÚ¿ËÀ¼ÕÐļºÍ´øÍ·Ðж¯µÄÓßÂÛ£¬Ö¼ÔÚ¼¤·¢Ãñ¶àµÄ²»ÐÅÀµºÍµÖ¿¹¸ÐÇé¡£¸ÃÐéαÀûÓ÷¨Ê½ÌṩWindowsºÍAndroidÏÂÔØ£¬±ðÀë×°ÖöñÒâÈí¼þ¼ÓÔØÆ÷Pronsis LoaderºÍÐÅÏ¢ÇÔÈ¡·¨Ê½PureStealer£¬ÒÔ¼°Ã³Ò׺óÃÅCraxsRAT¡£ÎªÁËÖ´ÐжñÒâ»î¶¯£¬¸ÃÀûÓ÷¨Ê½ÓÕÆÓû§½ûÓÃAndroid·´¶ñÒâÈí¼þ¹¤¾ß²¢ÊÚÓèΣÏÕȨÏÞ¡£GoogleÒѸüÐÂGoogle Play±£»¤Ö°ÄܺÍChromeµÄ¡°°²È«ä¯ÀÀ¡±Ö°ÄÜ£¬ÒÔ¼ì²âºÍ×èÖ¹ÓйضñÒâÈí¼þ¡£https://www.bleepingcomputer.com/news/security/russia-targets-ukrainian-conscripts-with-windows-android-malware/
2. ¶íÂÞ˹Midnight BlizzardºÚ¿Í×éÖ¯ÌáÒéÐÂÐÍÐÅÏ¢ÇÔÈ¡»î¶¯
10ÔÂ30ÈÕ£¬¶íÂÞ˹ºÚ¿Í×éÖ¯¡°ÎçÒ¹±©Ñ©¡±£¨Midnight Blizzard£©½üÆÚÕë¶Ôµ±¾Ö¹¤×÷ÈËÔ±ÌáÒéÐÂÐÍÐÅÏ¢ÇÔÈ¡»î¶¯£¬ÀûÓÃÓã²æÊ½ÍøÂç´¹µöµç×ÓÓʼþ·¢ËÍÔ¶³Ì×ÀÃæºÍ̸£¨RDP£©ÅäÖÃÎļþ£¬Ê¹Êܺ¦ÕßÉ豸Ôâ·êÆëÈ«½Ó¼ûȨÏ޵Ĺ¥»÷¡£Î¢ÈíÍþвµý±¨ÍŶÓ×·×Ùµ½¸Ã»î¶¯×Ô10ÔÂ22ÈÕÆð£¬ÒÑÏòÈ«ÇòÔ̺¬Ó¢¹ú¡¢Å·ÖÞ¡¢°Ä´óÀûÑǺÍÈÕ±¾µÈÊýÊ®¸ö¹ú¶È/µØÓòÈ·µ±¾Ö¡¢Ñ§Êõ½ç¡¢¹ú·À¡¢·Çµ±¾Ö×éÖ¯µÈ²¿ÃÅ·¢ËÍÊýǧ·â´ËÀàÓʼþ¡£ÕâЩÓʼþÖÐÔ̺¬Ãô¸ÐÉèÖ㬿ɵ¼Ö´óÁ¿ÐÅϢй¶£¬ÉõÖÁ°²È«ÃÜÔ¿ºÍÏúÊÛµãÉ豸Ҳ¿ÉÄÜÊܵ½Ó°Ïì¡£ºÚ¿Í»¹Í¨¹ý¼ÙÒâ΢ÈíÔ±¹¤µÈ·½Ê½ÓÕÆÊܺ¦Õß´ò¿ªÓʼþ¡£Õâ´Î»î¶¯ÓÈΪÒýÈËÖõÄ¿£¬ÓÉÓÚʹÓÃRDPÅäÖÃÎļþÊÇMidnight BlizzardÕ½ÊõµÄнøÈ¡¡£ÑÇÂíÑ·ºÍÎÚ¿ËÀ¼µ±¾ÖÍÆËã»úÓ¦¼±ÏìÓ¦Ó××éÒ²·¢ÏÖÁËÀàËÆ»î¶¯£¬ÆäÖÐÑÇÂíÑ·Ö¸³ö¶íÂÞ˹±í¹úµý±¨¾Ö£¨SVR£©ÕýÕë¶Ôµ±¾Ö»ú¹¹¡¢¹«Ë¾ºÍ¾ü¶ÓÌáÒéÍøÂç´¹µö»î¶¯£¬Ö¼ÔÚÇÔÈ¡¶íÂÞ˹µÐÊֵį¾Ö¤¡£
https://therecord.media/russia-midnight-blizzard-hackers-target-government-sector
3. ´ó¹æÄ£PSAUXÀÕË÷Èí¼þ¹¥»÷¶Ô×¼22,000¸öCyberPanelÊ·ý
10ÔÂ29ÈÕ£¬³¬¹ý22,000¸öCyberPanelÊ·ýÒò´æÔÚÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶¶øÂ¶³öÓÚ·çÏÕÖ®ÖУ¬ÕâЩÊ·ýÔÚPSAUXÀÕË÷Èí¼þ¹¥»÷ÖÐÏÕЩȫÊýÂÙÏÝ¡£°²È«×êÑÐÔ±DreyAnd·¢ÏÖCyberPanel 2.3.6£¨¼°¿ÉÄÜÊÜÓ°ÏìµÄ2.3.7°æ±¾£©´æÔÚÉí·ÝÑé֤ȱµã¡¢ºÅÁî×¢Èë¼°°²È«¹ýÂËÆ÷ÈÆ¹ýµÈ°²È«ÎÊÌ⣬¿Éµ¼ÖÂδ¾ÊÚȨµÄÔ¶³Ì¸ù½Ó¼û¡£ËûÒÑÓÚ2024Äê10ÔÂ23ÈÕÏòCyberPanel¿ª·¢ÈËÔ±Åû¶·ì϶²¢ÔÚGitHub ÉÏÌá½»ÁËÕë¶ÔÉí·ÝÑéÖ¤ÎÊÌâµÄ½¨¸´·¨Ê½¡£Óë´Ëͬʱ£¬Íþвµý±¨ËÑË÷ÒýÇæLeakIX»ã±¨³Æ£¬´óÁ¿´æÔÚ·ì϶µÄCyberPanelÊ·ý±»PSAUXÀÕË÷Èí¼þ¹¥»÷£¬µ¼Ö½üÒ»°ëλÓÚÃÀ¹úµÄÊ·ý£¨Ô¼10,170¸ö£©¼°ÖÎÀíµÄ³¬¹ý152,000¸öÓòºÍÊý¾Ý¿âÊܵ½Íþв¡£Ò»Ò¹Ö®¼ä£¬ÊÜÓ°ÏìµÄÊ·ýÊýÁ¿´ó·ù½µÂ䣬½öÊ£Ô¼400¸ö¿É½Ó¼û¡£PSAUXÀÕË÷Èí¼þͨ¹ý·ì϶ºÍÃýÎóÅäÖù¥»÷¶³öµÄWeb·þÎñÆ÷£¬¼ÓÃÜ·þÎñÆ÷Îļþ²¢ÁôÏÂÀÕË÷ÐÅ¡£Ä¿Ç°£¬LeakIXÒѰ䲼½âÃÜÆ÷ÓÃÓÚ½âÃÜÔÚÕâ´Î¹¥»÷ÖмÓÃܵÄÎļþ£¬µ«Ê¹ÓÃǰÐ豸·ÝÊý¾Ý²¢²âÊÔÆäÓÐЧÐÔ£¬ÒÔ·ÀÒòÃýÎóÃÜÔ¿µ¼ÖÂÊý¾Ý°Ü»µ¡£
https://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/
4. ¼ÓÄôó˰Îñ¾ÖÊý¾Ýй¶Òý·¢ÐÅÀµÎ£»ú£¬ÒþÖÔÎ¥¹æÐÐΪ¼¤Ôö
10ÔÂ29ÈÕ£¬ÔÚ½ñÄêµÄÄÉ˰¼¾½Ú¶¥·åÆÚ£¬¼ÓÄôó²úÉúÁËһ·ÑϳÁµÄ˰ÎñÊý¾Ýй¶ÊÂÎñ¡£ºÚ¿ÍÇÔÈ¡ÁËH&R Block CanadaµÄ»úÃÜÊý¾Ý£¬²¢ÀûÓÃÕâЩÐÅϢδ¾ÊÚȨ½Ó¼ûÁËÊý°ÙÃû¼ÓÄôóÈ˵ÄÓ×ÎÒ¼ÓÄôó˰Îñ¾Ö£¨CRA£©ÕË»§¡£ºÚ¿Í¸ü¸ÄÁËÖ±½Ó´æ¿îÐÅÏ¢£¬Ìá½»ÁËÐéαÉ걨±í£¬²¢´Ó¹«¿îÖÐÆÈ¡Á˳¬¹ý600ÍòÃÀÔªµÄÐéαÍ˿Õâ´ÎÊÂÎñ´Ùʹ¼ÓÄôó˰Îñ¾Ö¼ÓÇ¿ÁËýÌåÇþ·³ï±¸£¬ÒÔÓ¦¶Ô¹«¼Ò¶ÔÕâ´ÎÊý¾Ýй¶¼°¸Ã»ú¹¹ÎªºÎÏòÚ¿ÆÕßÖ§¸¶Êý°ÙÍòÃÀÔªµÄÎÊÌ⡣Ȼ¶ø£¬¹«¼Ò²¢Î´»ñϤ´Ë´òË㣬˰Îñ²¿³¤ºÍ¼ÓÄôó˰Îñ¾ÖÒ²¾ùδ»ØÓ¦ÓйØÎÊÌâ¡£H&R Block¹«Ë¾°µÊ¾£¬Ã»ÓÐÖ¤¾ÝÅú×¢Õâ´ÎÈëÇÖÊÂÎñÔ´×Ըù«Ë¾£¬ÆäÊý¾Ý¡¢ÏµÍ³¡¢Èí¼þºÍ°²È«¾ùδÊܵ½ÇÖº¦¡£¼ÓÄôó˰Îñ¾ÖδÄÜÈ·¶¨ºÚ¿ÍµÄÉí·Ý£¬µ«ÅųýÁË×ÔÉíϵͳ±»ÈëÇÖ»òÄÚ²¿ÈËÔ±²Î¼ÓµÄ¿ÉÄÜÐÔ¡£´Ë±í£¬¼ÓÄôó˰Îñ¾Ö»¹Ãæ¶ÔÆäËûÑϳÁÎÊÌ⣬Ô̺¬ÒþÖÔй¶ÊÂÎñÊýÁ¿¼¤Ôö£¬ÒÔ¼°¹«¼Ò¶Ô±£»¤ÄÉ˰È˽ðÇ®ºÍÓ×ÎÒÐÅÏ¢µÄ»ú¹¹Ê§È¥ÐÅÀµµÄ·çÏÕ¡£
https://www.cbc.ca/news/canada/canada-revenue-agency-taxpayer-accounts-hacked-1.7363440
5. й¤¾ß¿ÉÈÆ¹ýGoogle ChromeµÄÐÂCookie¼ÓÃÜϵͳ
10ÔÂ28ÈÕ£¬ÍøÂ簲ȫ×êÑÐÔ±ÑÇÀúɽ´ó-¹þ¸ùÄɰ䲼ÁËÒ»¿îÃûΪ¡°Chrome-App-Bound-Encryption-Decryption¡±µÄ¹¤¾ß£¬¸Ã¹¤¾ßÄÜÈÆ¹ý¹È¸èÐÂÍÆ³öµÄÀûÓ÷¨Ê½°ó¶¨¼ÓÃܼ¼Êõ£¬´ÓChromeä¯ÀÀÆ÷ÖÐÌáÈ¡Òѱ£ÁôµÄÍ´´¦£¬Ôö³¤ÁËChromeÓû§µÄ·çÏÕ¡£¹È¸èÔÚ7ÔÂÍÆ³öµÄÕâÒ»¼ÓÃܼ¼Êõ£¬Ö¼ÔÚͨ¹ýWindows·þÎñÒÔϵͳȨÏÞ¶Ôcookies½øÐмÓÃÜ£¬±£»¤Ãô¸ÐÐÅÏ¢ÃâÊܶñÒâÈí¼þ¹¥»÷¡£È»¶ø£¬9ÔÂʱÒÑÓжà¸öÐÅÏ¢ÇÔÈ¡ÕßÕÒµ½Èƹý²½Öè¡£×òÌ죬¹þ¸ùÄÉÔÚGitHubÉϹ«¿ªÁËÕâ¿îÅÔ·¹¤¾ß¼°ÆäÔ´´úÂë¡£¸Ã¹¤¾ßÀûÓÃChromeä¯ÀÀÆ÷ÄÚ²¿µÄIElevator·þÎñ£¬½âÃÜ´æ´¢ÔÚ±¾µØ×´Ì¬ÎļþÖеÄApp-Bound¼ÓÃÜÃÜÔ¿¡£¹ÌȻʹÓøù¤¾ß±ØÒªÖÎÀíԱȨÏÞ£¬µ«ºÜ¶àWindowsÓû§¶¼Ê¹Æ÷ÓµÓÐÖÎÀíȨÏÞµÄÕË»§£¬Òò¶øÕâͨ³£ÈÝÒ×ʵÏÖ¡£¾Ý¶ñÒâÈí¼þ·ÖÎöʦ³Æ£¬¹þ¸ùÄɵIJ½ÖèÓëÔçÆÚÐÅÏ¢ÇÔÈ¡Õß²ÉÈ¡µÄÈÆ¹ý²½ÖèÀàËÆ£¬¹ÌÈ»¹È¸èÒ»ÏòÔÚÖÂÁ¦¸Ä½ø·ÀÓù´ëÊ©£¬µ«Ê¹ÓÃй¤¾ßÈÔÄܵÈÏÐÇÔÈ¡Chromeä¯ÀÀÆ÷ÖеÄÓû§°ÂÃØ¡£¹È¸è°µÊ¾£¬¹ÌÈ»Õâ¶Î´úÂë±ØÒªÖÎÀíԱȨÏÞ£¬µ«¶ñÒâÈí¼þµÄÊýÁ¿ÈÔÔÚÔö³¤£¬ËüÃÇͨ¹ý·ÖÆç·½Ê½Ëø¶¨Óû§¡£
https://www.bleepingcomputer.com/news/security/new-tool-bypasses-google-chromes-new-cookie-encryption-system/
6. Discord Bots±»¶ñÒâÀûÓãºPySilon RATÍþÐ²ÍøÂ簲ȫ
10ÔÂ29ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾AhnLabÔÚ×î½üµÄÒ»·Ý»ã±¨ÖÐÖ¸³ö£¬Õý±¾ÓÃÓÚÁ¼ÐÔ·þÎñÆ÷ÖÎÀíµÄDiscord Bots´Ë¿Ì±»ÓÃÓÚ²¿ÊðÔ¶³Ì½Ó¼ûľÂí£¨RAT£©£¬ÆäÖÐ×îÐµİ¸ÀýÉæ¼°ÃûΪPySilonµÄ¶ñÒâÈí¼þ±äÖÖ¡£PySilonÊÇÒ»ÖÖÀûÓÃDiscord BotÆ½Ì¨ÉøÈëϵͳ²¢»ñÈ¡Ãô¸ÐÊý¾ÝµÄRAT£¬ËüŤÇúÁËDiscord BotÕý±¾ÌṩµÄ·þÎñÆ÷ÖÎÀí¡¢×Ô¶¯ÐÂÎÅÏìÓ¦µÈÖ°ÄÜ£¬ÔÚDiscord»ù´¡ÉèÊ©ÄÚ¶ñÒâÔËÐС£Õâ¿îʹÓÃPython¿ª·¢µÄRAT¶ñÒâÈí¼þ¿ÉÔÚGitHubÉϽӼû£¬ÍþвÐÐΪÕßÄܹ»ÇáËɹ¹½¨×Ô½ç˵°æ±¾£¬²¢Í¨¹ýµ÷Õû·þÎñÆ÷IDºÍ»úеÈËÁîÅÆµÈ¾ßÌåÐÅÏ¢£¬Ê¹Óù¹½¨Æ÷·¨Ê½´´½¨¸öÐÔ»¯µÄ¶ñÒâÈí¼þ°æ±¾¡£Ö´Ðкó£¬PySilon»áÔÚ¹¥»÷ÕߵķþÎñÆ÷ÄÚ´´½¨Ò»¸öÐÂͨ·£¬½«³õʼϵͳÐÅϢת·¢¸ø²Ù×÷Ô±£¬´Ó¶øÊµÏÖºÚ¿ÍÓëÊÜϰȾÉ豸µÄÓÆ¾ÃͨѶÁ´½Ó¡£PySilonÓµÓÐ¿í·ºµÄºÅÁîÁìÓò£¬¿ÉÓÃÓÚ¼äµý¡¢Êý¾ÝÇÔÈ¡ºÍ·ÛËéµÈ»î¶¯£¬Ô̺¬ÍøÂçÓ×ÎÒºÍϵͳÐÅÏ¢¡¢ÆÁÄ»ºÍÒôƵ¼Í¼¡¢¼üÅ̼ͼÒÔ¼°Îļþ¼Ð¼ÓÃܵȡ£AhnLabÇ¿µ÷£¬¼ì²â´ËÀàÍþвӵÓÐÌôÕ½ÐÔ£¬ÓÉÓÚÊý¾ÝÊÇʹÓÃΪÕý³£»úеÈËÖ°ÄÜÖ´ÐеĹٷ½Discord·þÎñÆ÷´«ÊäµÄ£¬¸²¸ÇÁËÆä¶ñÒâÐÔÖÊ¡£
https://securityonline.info/pysilon-a-discord-bot-turned-malicious-rat-for-data-theft-and-surveillance/


¾©¹«Íø°²±¸11010802024551ºÅ