¶àÂ׶දÎïÔ°ÔâÍøÂç¹¥»÷£¬Óοͼ°Ô±¹¤ÐÅÏ¢´óй¶
°ä²¼¹¦·ò 2025-03-061. ¶àÂ׶දÎïÔ°ÔâÍøÂç¹¥»÷£¬Óοͼ°Ô±¹¤ÐÅÏ¢´óй¶
3ÔÂ6ÈÕ£¬¶àÂ׶දÎïÔ°±¾Öܰ䲼Á˹ØÓÚ2024Äê1ÔÂÔâ·êÍøÂç¹¥»÷µÄ֪ͨ¡£¸Ã¶¯Îï԰ÿÄê»¶Ó³¬¹ý120ÍòÃûÓοͣ¬Õ¼Óг¬¹ý5000ÖÖ¶¯Îï¡£Õâ´Î¹¥»÷µ¼ÖÂ2000ÄêÖÁ2023Äê4ÔÂÆÚ¼äÿλÓο͵ÄÐÅÏ¢±»Ð¹Â¶£¬ºÚ¿Í¸´ÔìÁËÔ̺¬ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØÖ·ÔÚÄÚµÄÂòÂôÊý¾Ý¡£¶ÔÓÚÔÚ2022Äê1ÔÂÖÁ2023Äê4ÔÂÆÚ¼äʹÓÃÐÅÓþ¿¨ÂòÂôµÄ¿ÍÈ˺ͻáÔ±£¬ºÚ¿Í»¹ÇÔÈ¡ÁË¿¨ºÅµÄºóËÄλÊý×ÖºÍÓÐЧÆÚ¡£¾Ý³Æ£¬AkiraÀÕË÷Èí¼þ×éÖ¯¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬²¢Ðû³ÆÇÔÈ¡ÁË133GBµÄÊý¾Ý£¬Ô̺¬»úÃܺÍ̸ºÍÓ×ÎÒÎļþµÈ¡£³ýÁËÓοÍÐÅÏ¢£¬¶¯ÎïÔ°»¹Ê§È¥ÁËÊýÊ®ÄêµÄÒ°»îÆÃÎï±£»¤×êÑгɾͣ¬Ãæ¶Ô¼«´óÌôÕ½¡£´Ë±í£¬¶¯ÎïÔ°»¹Í¨ÖªÁËÊÜÓ°ÏìµÄÏÖÈκÍǰÈÎÔ±¹¤¡¢×ÔÔ¸Õߺ;èÔùÕߣ¬²¢ÌṩÐÅÓþ¼à¿Ø·þÎñ¡£¶¯ÎïÔ°ÖÒ¸æÇ±ÔÚÊܺ¦ÕßÒª¾¯ÌèÍøÂç´¹µöºÍÍøÂçÚ¿Æ£¬²¢¶¨ÆÚ²é³²ÆÕþÕË»§±¨±í¡£¶àÂ׶දÎïÔ°ÒÑÏò°²´ÖÂÔÊ¡ÐÅÏ¢ºÍÒþÖÔרԱ°ì¹«Êһ㱨ÁËÕâÒ»ÊÂÎñ£¬¸Ã°ì¹«ÊÒÒÑ·¢Õ¹µ÷²é¡£
https://therecord.media/toronto-zoo-warns-decades-cyberattack
2. BadBoxÔâ³Á»÷£¬¹È¸èÒÆ³ý24¿î¶ñÒâÀûÓò¢×è¶Ï50ÍòÉ豸ͨѶ
3ÔÂ5ÈÕ£¬BadBox Android ¶ñÒâÈí¼þ½©Ê¬ÍøÂç½üÆÚÔÙ´ÎÊܵ½½ø¹¥£¬Google Play ÒÑɾ³ý24¸öÓйضñÒâÀûÓ㬲¢×è¶ÏÁË50Íǫ̀ÊÜϰȾÉ豸µÄͨѶ¡£¸Ã½©Ê¬ÍøÂçÖØÒªÕë¶ÔµÍ³É±¾AndroidÉ豸£¬ÈçÁ÷ýÌåºÓעƽ°åµçÄÔ¡¢ÖÇÄܵçÊÓºÍÖÇÄÜÊÖ»ú£¬Í¨¹ýԤװ¶ñÒâÈí¼þ»òÏÂÔØ¶ñÒâÀûÓÃϰȾÉ豸¡£Ï°È¾ºóµÄÉ豸»á±»Ôì³Éסլ´úÀí£¬ÓÃÓÚÌìÉúÐéα¸æ°×Ó¡Ïó¡¢³Á¶¨ÏòÓû§µ½µÍÖÊÁ¿ÍøÕ¾¡¢´´½¨ÐéαÕË»§²¢Ö´ÐÐÆ¾Ö¤Ìî³ä¹¥»÷¡£Ö»¹ÜÈ¥ÄêµÂ¹úµ±¾ÖÒÑÀ¹½Ø¸Ã¶ñÒâÈí¼þ£¬µ«ÆäϰȾÊýÁ¿ÈÔѸ¿ìÔö³¤£¬ÒÑÓ°Ï쳬¹ý100Íǫ̀É豸£¬±é²¼222¸ö¹ú¶È£¬ÖØÒª¼¯ÖÐÔÚ°ÍÎ÷¡¢ÃÀ¹ú¡¢Ä«Î÷¸çºÍ°¢¸ùÍ¢¡£HUMANµÄSatoriÍþвµý±¨ÍŶӽáºÏ¶à¼ÒºÏ×÷ͬ°é·¢Õ¹ÁË×îеķÛËéÐж¯£¬³ÆÎª¡°BadBox 2.0¡±¡£ËûÃÇÈëÇÖÁËBADBOX 2.0µÄÓòÃû£¬×èÖ¹ÁË50¶àÍǫ̀É豸ÓëÍþвÐÐΪÕߵĺÅÁîºÍ½ÚÔì·þÎñÆ÷ͨѶ£¬Ê¹¶ñÒâÈí¼þ½øÈëÐÝÃß״̬¡£´Ë±í£¬¹È¸è´ÓGoogle PlayÖÐÒÆ³ýÁË24¿î×°ÖÃBadBox¶ñÒâÈí¼þµÄÀûÓ㬲¢ÖÕÖ¹ÁËÓйظæ°×ڲƵİ䲼ÉÌÕË»§¡£È»¶ø£¬ÓÉÓÚÈ«ÇòÏúÊÛµÄδ¾Play ProtectÈÏÖ¤µÄAndroidÉ豸ÎÞ·¨±»¹È¸èÏû¶¾£¬BadBox 2.0²¢Î´±»ÆëÈ«ÆËÃð¡£Ïû·ÑÕßÓ¦ÉóÉ÷²É°ì»ùÓÚAOSPµÄAndroidÉ豸£¬Ô¤·ÀʹÓÃԤװ¶ñÒâÈí¼þµÄÓ²¼þ¡£
https://www.bleepingcomputer.com/news/security/badbox-malware-disrupted-on-500k-infected-android-devices/
3. »ÝÌØÂüÒ½ÔºÔâÍøÂç¹¥»÷£¬µç×Óϵͳ̱»¾
3ÔÂ5ÈÕ£¬Î»ÓÚ»ªÊ¢¶ÙÖݿƶû·¨¿Ë˹µÄ»ÝÌØÂüÒ½ÔººÍÒ½ÁÆÕïËù£¨WHMC£©½üÆÚÔâ·êÁËÍøÂç¹¥»÷£¬µ¼ÖÂÆäÄÚ²¿µç×ÓϵͳÏÝÈë̱»¾×´Ì¬¡£Ò½ÔºÔÚ2025Äê2ÔÂ28ÈÕ³õ´Îͨ¹ýFacebookÒ³Ãæ°ä²¼Á˹ØÓÚ´ËÊÂÎñµÄ¾¯±¨£¬Ö¸³öÆäµç×ÓϵͳÔâµ½ÁËδ֪·¸×ïÕßµÄÈëÇÖ£¬²¢Ð¹Â©Ò»¼ÒÍøÂ簲ȫ¹«Ë¾ÔÚ»ý¼«Ó¦¶ÔÕâÒ»ÎÊÌâ¡£Ö»¹ÜÃæ¶ÔÀ§¾³£¬Ò½ÔºÒÀȻά³ÖÊ¢¿ª£¬²¢³Ðŵ³ÖÐø¹Ø×¢ÊÂ̬·¢Õ¹£¬Í¬Ê±ÔÚÉ罻ýÌåºÍ¹Ù·½ÍøÕ¾Éϰ䲼×îÐÂÐÂÎÅ¡£ÔÚ3ÔÂ4ÈյĸüÐÂÖУ¬Ò½ÔºÖ¸³öÄÚ²¿µç×ÓϵͳÈÔδ¸´Ô£¬Òò¶ø£¬ÔÚ3ÔÂ5ÈÕÔ¤Ô¼¾ÍÕïµÄ»¼Õß¿ÉÄÜ»áÔâ·êÑÓÎó¡£Ö»¹ÜÃæ¶ÔÌôÕ½£¬Ò½ÔºÈÔÇ¿µ÷Æä½«³ÖÐøÎª»¼ÕßÌṩ·þÎñ¡£Ä¿Ç°£¬Ò½ÔºÉÐδй©¸ü¶à¹ØÓÚÕâ´ÎÍøÂç¹¥»÷µÄϸ½Ú£¬µ«°µÊ¾ÔÚ»ñµÃ½â¾öÕâÒ»ÎÊÌâµÄ½øÕ¹¡£
https://databreaches.net/2025/03/05/whitman-hospital-medical-clinics-in-colfax-suffers-cyber-attack/
4. LinkedInÍøÂç´¹µöÚ¿ÆÐ±äÖÖ´«²¼ConnectWise RAT
3ÔÂ5ÈÕ£¬Cofense µÄÍøÂ簲ȫ×êÑÐÈËÔ±½üÆÚ·¢ÏÖÁËÒ»¸öÀûÓÃαÔì LinkedIn µç×ÓÓʼþ·Ö·¢¶ñÒâÈí¼þµÄÐÂÍøÂç´¹µöڿƻ¡£Óë³£¼ûµÄ LinkedIn Ö÷ÌâÍøÂç´¹µö¹¥»÷·ÖÆç£¬´Ë»î¶¯Ö¼ÔÚ´«²¼Ò»ÖÖÃûΪ ConnectWise RAT µÄÔ¶³Ì½Ó¼ûľÂí¡£¸ÃÚ²ÆÐÔµç×ÓÓʼþ·ÂÕÕ LinkedIn InMail ÐÂÎŵÄ֪ͨ£¬ÀûÓÃÁË LinkedIn µÄÆ·ÅÆ£¬µ«Ê¹ÓÃÁ˹ýÆÚµÄÄ£°å¡£ÓʼþÐû³ÆÀ´×ÔÐé¹¹µÄÏúÊÛ×ܼ࣬ҪÇó¶Ô·½Ìṩ±¨¼Û£¬ÒÔÓªÔì½ôÆÈ¸Ð¡£ÓʼþÖеÄÓ×ÎÒ×ÊÁÏͼƬÊôÓÚÕæÊµÓ×ÎÒ£¬µ«¹«Ë¾Ãû³ÆÊÇÐé¹¹µÄ¡£µã»÷ÓʼþÖеİ´Å¥»á´¥·¢ ConnectWise RAT ×°Ö÷¨Ê½µÄÏÂÔØ£¬ÇÒÔ¤·ÀÁËÖ±½ÓÌáÐÑÓû§ÏÂÔØ»òÔËÐÐÎļþµÄ³£¼ûÕ½Êõ¡£Ö»¹ÜÓʼþδͨ¹ýÉí·ÝÑéÖ¤²é³£¬µ«ÈÔÈÆ¹ýÁËÏÖÓа²È«´ëÊ©¡£¸Ã¹¥»÷»î¶¯×Ô 2024 Äê 5 ÔÂÆð¾ÍÒÑÆðÍ·£¬ÓʼþÄ£°åά³ÖÒ»Ö£¬µ«ÎÞ·¨È·ÈÏÔçÆÚ°æ±¾ÊÇ·ñÒ²´«²¼ÁË ConnectWise RAT¡£Õâ´Î»î¶¯Í¹ÏÔÁËÍøÂç·¸×ï·Ö×Ó²»ÐÝÑݱäµÄÕ½ÊõÒÔ¼°Éæ¼° LinkedIn µÄ¸´ÔÓÍøÂç´¹µö¹¥»÷µÄÍþв£¬±ØÒª½ÌÓýÔ±¹¤×ÐϸÉó²éµç×ÓÓʼþ·¢¼þÈË£¬Êʵ±ÅäÖõç×ÓÓʼþÉí·ÝÑéÖ¤ºÍ̸£¬²¢È·±£ÅäÖð²È«µç×ÓÓʼþÍø¹ØÒÔÓÐЧ¹ýÂ˺Í×èÖ¹¿ÉÒɵç×ÓÓʼþ¡£
https://hackread.com/scammers-fake-linkedin-inmail-deliver-connectwise-trojan/
5. ¼ÙÒâBianLianÍÅ»ïµÄÐéαÀÕË÷ÐÅÚ¿ÆÃÀ¹ú¹«Ë¾¸ß¹Ü
3ÔÂ4ÈÕ£¬½üÆÚ£¬Ú¿ÆÕß¼ÙÒâ BianLian ÀÕË÷Èí¼þÍŻͨ¹ýÃÀ¹úÓÊÕþÏòÃÀ¹ú¹«Ë¾Ê×ϯִÐйÙÓʼÄÐéαÀÕË÷ÐÅ¡£ÕâЩº¯¼þÐû³ÆÀ´×ÔλÓÚ²¨Ê¿¶ÙµÄ¡°BIANLIAN GROUP¡±£¬²¢º¬ÓÐÕë¶Ô¹«Ë¾ÐÐÒµµÄÁ¿Éí¶¨ÔìµÄÉæÏÓ±»µÁÊý¾Ý¡£ÐÅÖÐÐû³ÆÒÑ»ñȡϵͳ½Ó¼ûȨÏÞ£¬²¢µ¼³ö´óÁ¿Ãô¸ÐÊý¾ÝÎļþ£¬ÒªÇóÖ§¸¶25ÍòÖÁ50ÍòÃÀÔªµÄ±ÈÌØ±ÒÊê½ðÒÔ·ÀÊý¾Ýй¶£¬²»È»½«ÔÚ10ÌìÄÚ¹«¿ª¡£È»¶ø£¬¾ Guidepoint Security¡¢BleepingComputer ¼° Arctic Wolf µÈ»ú¹¹·ÖÎö£¬ÕâЩÀÕË÷ÐÅʵΪȦÌ×£¬Ö¼ÔÚÏÅ»£¸ß¹ÜÖ§¸¶Êê½ð£¬ÎÞÏÖʵΥ¹æÖ¤¾Ý¡£ÐÅÖÐËäÔ̺¬ÕæÊµµÄTorÊý¾ÝÐ¹Â¶ÍøÕ¾¼°ºÏ·¨µÄй¼ûÜÂëÒÔÔö³¤¿ÉÐŶȣ¬µ«¾È·Èϲ¢·ÇÀ´×Ô BianLian ÀÕË÷Èí¼þ×éÖ¯¡£Ö»¹ÜÈç´Ë£¬ÓÉÓÚÓʼþ¿í·º´«²¼£¬ITºÍ°²È«ÖÎÀíÔ±ÈÔÐè֪ͨ¸ß¹ÜÓйØÈ¦Ì×£¬Ô¤·ÀÀË·Ñ×ÊÔ´¡£´ËȦÌ×Ϊµç×ÓÓʼþÀÕË÷ȦÌ×µÄÑݱ䣬ָ±êÓÉÓ×ÎÒתÏò¹«Ë¾¸ß¹Ü¡£Ä¿Ç°£¬BianLian ÀÕË÷Èí¼þÐж¯ÉÐδ»ØÓ¦ÊÇ·ñ²Î¼Ó´ËÊ¡£
https://www.bleepingcomputer.com/news/security/fake-bianlian-ransom-notes-mailed-to-us-ceos-in-postal-mail-scam/
6. YouTubeÖҸ棺ڿÆÕßÀûÓÃAIÌìÉúCEOÊÓÆµ½øÐÐÍøÂç´¹µö¹¥»÷
3ÔÂ5ÈÕ£¬YouTubeÖÒ¸æ³Æ£¬Ú¿ÆÕßÕýÀûÓÃAIÌìÉúµÄÊ×ϯִÐйÙÊÓÆµ½øÐÐÍøÂç´¹µö¹¥»÷£¬ÒÔÇÔÈ¡´´×÷Õ߯¾Ö¤¡£¹¥»÷Õßͨ¹ýµç×ÓÓʼþ·ÖÏíÐû³Æ¹ØÓÚÇ®±Ò»¯Õþ²ß±ä¶¯µÄ¸öÈËÊÓÆµ¡£YouTubeÇ¿µ÷£¬ËûÃǾø²»»áͨ¹ý¸öÈËÊÓÆµÁªÏµÓû§·ÖÏíÐÅÏ¢¡£ÕâЩ´¹µöÓʼþÖеÄÁ´½Ó»áÊèµ¼Óû§µ½Ò»¸öαÔìµÄµÇÂ¼Ò³Ãæ£¬ÒªÇóÊäÈëÕË»§Æ¾Ö¤ÒÔÈ·ÈϸüеÄYouTubeºÏ×÷ͬ°é´òËãÌõ¿î£¬ÊµÔòΪÁËÇÔÈ¡ÕâЩÐÅÏ¢¡£Ú¿ÆÕß»¹Íþв³Æ£¬²»È·ÈÏ×ñÊØÐ¹涨½«µ¼ÖÂÕË»§ÊÜÏÞÆßÌ죬ÒÔ´ËÔì×÷½ôÆÈ¸Ð¡£×Ô2024Äê1Ôµ×ÒÔÀ´£¬YouTubeÓû§²»ÐÝÊÕµ½´ËÀàÓʼþ£¬¶øYouTubeÍŶÓÒÑÓÚ2ÔÂÖÐÑ®ÆðÍ·µ÷²é¡£ºÜ¶à´´×÷ÕßÒѳÉΪÊܺ¦Õߣ¬ÆäƵ·±»½Ù³ÖÓÃÓÚÖ±²¥¼ÓÃÜÇ®±ÒÚ¿Æ¡£YouTubeÌṩÁËÔ¤·ÀºÍ»ã±¨´ËÀàÍøÂç´¹µöÓʼþµÄÌáÐÑ£¬²¢×Ô8ÔÂÆðÍÆ³öÐÂÖ§³Ö¸±ÊÖ£¬Ô®ÊÖÓû§ÔÚ±»ºÚºó¸´Ô²¢±£»¤ÕË»§¡£
https://www.bleepingcomputer.com/news/security/youtube-warns-of-ai-generated-video-of-its-ceo-used-in-phishing-attacks/


¾©¹«Íø°²±¸11010802024551ºÅ