µÂ¿ËÈøË¹ÖÝÂÉʦлáÔâINCÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÊý¾Ýй¶
°ä²¼¹¦·ò 2025-04-081. µÂ¿ËÈøË¹ÖÝÂÉʦлáÔâINCÀÕË÷Èí¼þ¹¥»÷µ¼ÖÂÊý¾Ýй¶
4ÔÂ3ÈÕ£¬ÃÀ¹úµÚ¶þ´óÂÉʦлᡪ¡ªµÂ¿ËÈøË¹ÖÝÂÉʦлáÔâ·ê³Á´óÊý¾Ýй¶ÊÂÎñ£¬²¨¼°³¬10ÍòÃûÖ´ÒµÂÉʦ¡£¸Ãлá³Ðµ£Ö´ÒµÐí¿É¼à¹Ü¡¢³ÖÐø½ÌÓýÖÎÀí¡¢Ö°ÒµÂ·µÂ¼à¶½µÈÖ÷ÌâÖ°ÄÜ£¬ÆäÍøÂçϵͳÓÚ2025Äê1ÔÂ28ÈÕÖÁ2ÔÂ9ÈÕ¼äÔâδ¾ÊÚȨ½Ó¼û£¬µ«Ö±ÖÁ2ÔÂ12ÈÕ·½±»¾õ²ì¡£Æ¾¾ÝлáÏòÊÜÓ°Ïì³ÉÔ±°ä²¼µÄ֪ͨ£¬¹¥»÷ÕßÇÔÈ¡ÁËÔ̺¬È«ÃûµÄÃô¸ÐÐÅÏ¢£¬¾ßÌåй¶ÁìÓòÉÐδÃ÷È·¡£ÖµÍ×ÌùÐĵÄÊÇ£¬INCÀÕË÷Èí¼þÍŻ﹫¿ªÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬²¢ÓÚ3ÔÂ9ÈÕ½«¸ÃлáÁÐÈë°µÍøÀÕË÷Ãûµ¥£¬Í¬Ê±Åû¶Á˲¿ÃžݳÆÎªË¾·¨°¸¼þÎļþµÄ±»µÁÊý¾ÝÑù±¾¡£Ð»áÒѲÉȡӦ¶Ô´ëÊ©£¬ÎªÊÜÓ°Ïì³ÉÔ±ÌṩÓÐЧÆÚÖÁ7ÔÂ31ÈÕµÄÃâ·ÑÐÅÓþ¼°Éí·Ý͵ÇÔ¼à¿Ø·þÎñ£¨ÓÉExperianÌṩ֧³Ö£©£¬²¢½¨Òé³ÉԱͨ¹ý¼¤»îÂë×¢²á¸Ã·þÎñ¡£´Ë±í£¬Ð»áÇ¿ÁÒ½¨Òé³ÉԱ˼¿¼Æô¶¯ÐÅÓþ¶³½á»òÔÚÐÅÓþµµ°¸ÖÐÉèÖÃڲƾ¯±¨£¬ÒÔ×î´óÏ޶ȽµµÍDZÔÚ·çÏÕ¡£
https://www.bleepingcomputer.com/news/security/texas-state-bar-warns-of-data-breach-after-inc-ransomware-claims-attack/
2. EverestÀÕË÷Èí¼þÍÅ»ï°µÍøÐ¹ÃÜÍøÕ¾Ôâδ֪¹¥»÷ÏÂÏß
4ÔÂ7ÈÕ£¬½üÈÕ£¬Everest ÀÕË÷Èí¼þÍÅ»ïµÄ°µÍøÐ¹ÃÜÍøÕ¾Ôâ·êδ֪¹¥»÷ÕßÏ®»÷£¬Ä¿Ç°ÒÑÏÂÏß¡£¹¥»÷Õß½«ÍøÕ¾ÄÚÈÝ´úÌæÎª³°·íÐÅÏ¢£º¡°²»Òª·¸×·¸×ïÊÇ»µÊ£¬À´×Ô²¼À¸ñ¡£¡±Ä¿Ç°£¬¸ÃÍøÕ¾ÏÔʾ¡°Î´ÕÒµ½Ñó´ÐÍøÕ¾¡±ÃýÎó£¬ÎÞ·¨¼ÓÔØ¡£Ö»¹Ü¹¥»÷ÕßÈôºÎ½øÈëÍøÕ¾»òÍøÕ¾ÊÇ·ñ±»ºÚ¿Í¹¥»÷Éв»Ã÷È·£¬µ«°²È«×¨¼ÒÖ¸³ö£¬Everest ʹÓÃµÄ WordPress Ä£°å¿ÉÄÜ´æÔÚDZÔÚ·ì϶£¬¸Ã·ì϶»ò±»ÀûÓÃÀ´ÆÆ»Â·ÕË÷Èí¼þ²Ù×÷µÄÐ¹Â©ÍøÕ¾¡£×Ô 2020 Äê³öÏÖÒÔÀ´£¬Everest ÀÕË÷Èí¼þÐж¯Õ½ÊõÒѲúÉú±ä¶¯£¬´Ó½öÇÔÈ¡Êý¾Ý¡¢ÀÕË÷Æóҵת±äΪÔÚ¹¥»÷ÖвÎÓëÀÕË÷Èí¼þ£¬¼ÓÃÜÊܺ¦Õßϵͳ¡£´Ë±í£¬Everest ÔËÓªÉÌ»¹Òò³äÈÎÆäËûÍøÂç·¸×ïÍÅ»ïºÍÍþвÐÐΪÕߵijõʼ½Ó¼ûȨÏÞ¾¼ÍÈ˶øÎÅÃû£¬ÏúÊÛ±»¹¥ÆÆµÄ¹«Ë¾ÍøÂç½Ó¼ûȨÏÞ¡£ÔÚ´Óǰ 5 ÄêÖУ¬Everest µÄ°µÍøÐ¹ÃÜÍøÕ¾Ôö³¤ÁË 230 ¶àÃûÊܺ¦Õߣ¬³ÉΪ˫³ÁÀÕË÷¹¥»÷µÄÒ»²¿ÃÅ£¬ÀÕË÷Èí¼þÍÅ»ïÊÔͼÒÔ°ä²¼Ãô¸ÐÐÅϢΪÍþв£¬ÆÈʹÊܺ¦ÕßÖ§¸¶Êê½ð¡£
https://www.bleepingcomputer.com/news/security/everest-ransomwares-dark-web-leak-site-defaced-now-offline/
3. VSCode¶ñÒâÀ©´óʾÉí΢ÈíÊг¡£¬½èXMRigÍÚ¿óIJÀû
4ÔÂ7ÈÕ£¬½üÈÕ£¬ExtensionTotal×êÑÐÔ±Yuval Ronen·¢ÏÖ£¬2025Äê4ÔÂ4ÈÕ£¬Î¢ÈíÃÅ»§ÉÏÇÄÈ»°ä²¼Á˾Ÿö¼Ù×°³ÉºÏ·¨¿ª·¢¹¤¾ßµÄVSCodeÀ©´ó¡£ÕâЩÀ©´óÒÔ¡°Discord Rich Presence for VS Code¡±¡°Rojo ¨C Roblox Studio Sync¡±µÈÃû³ÆÊ¾ÈË£¬×°ÖÃÁ¿³¬30Íò´Î£¬µ«Êý×Ö¿ÉÄܱ»±¨´ð¿ä´ó£¬Ö¼ÔÚÓªÔìºÏ·¨¼ÙÏó¡£Ò»µ©×°Öü¤»î£¬ÕâЩ¶ñÒâÀ©´ó±ã´Ó±í²¿Ô´»ñÈ¡²¢Ö´ÐÐPowerShell¾ç±¾£¬Í¬Ê±×°ÖÃÆä·ÂÕյĺϷ¨À©´óÒÔÑÚÈ˶úÄ¿¡£¶ñÒâÈí¼þ»á´´½¨¼Ù×°³É¡°OnedriveStartup¡±µÄ´òË㹤×÷£¬²¢ÔÚWindows×¢²á±íÖÐ×¢Èë¾ç±¾£¬È·±£ÏµÍ³Æô¶¯Ê±×Ô¶¯ÔËÐС£Ëü»¹»á¹Ø¹Ø¹Ø¼üWindows·þÎñ£¬ÈçWindows Update£¬²¢½«×ÔÉíÔö³¤µ½Windows DefenderµÄÅųýÁбíÖУ¬ÒÔÌӱܼì²â¡£ÈôδÒÔÖÎÀíԱȨÏÞÖ´ÐУ¬¶ñÒâÈí¼þ»á·ÂÕÕϵͳ¶þ½øÔìÎļþ£¬Ê¹ÓöñÒâMLANG.dllÖ´ÐÐDLL½Ù³Ö£¬ÌáÉýȨÏÞ²¢Ö´ÐÐÓÐЧ¸ºÔØ¡£¸Ã¿ÉÖ´ÐÐÎļþѡȡbase64±àÂëÌåʽ£¬ÓÉPowerShell¾ç±¾½âÂëºóÏνӵ½¸¨Öú·þÎñÆ÷£¬ÏÂÔØ²¢ÔËÐÐXMRig¼ÓÃÜÇ®±Ò¿ó¹¤¡£Ä¿Ç°£¬Ö»¹ÜExtensionTotalÒÑÏò΢Èí»ã±¨ÕâЩ¶ñÒâÀ©´ó£¬µ«ËüÃÇÈÔ¿ÉÓá£
https://www.bleepingcomputer.com/news/security/malicious-vscode-extensions-infect-windows-with-cryptominers/
4. ºÚ¿Í¼ÙÒâÎÚ»ú¹¹·¢Æð¹¥»÷£¬ÇÔÃܶñÒâÈí¼þÍþв¼Ó¾ç
4ÔÂ8ÈÕ£¬Æ¾¾Ýµ±¾Ö×îÐÂ×êÑУ¬ºÚ¿ÍÕýÀûÓÃÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þ¶ÔÎÚ¿ËÀ¼¹Ø¼ü²¿ÃÅ·¢Æð¹¥»÷¡£×Ô2ÔÂÒÔÀ´£¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±ÏìÓ¦Ó××飨CERT-UA£©Ò»ÏòÔÚ×·×ÙÕâÒ»»î¶¯£¬ÆäÄ»ºóÍþвÕß±»×·×ÙΪUAC-0226£¬µ«ÉÐδ¹é×ïÓÚÈκÎÒÑÖªºÚ¿Í×éÖ¯¡£ºÚ¿Í´Ó±»ÈëÇÖµÄÕË»§·¢ËÍ´øÓжñÒâÎĵµ¸½¼þµÄµç×ÓÓʼþ£¬ÎļþÃû»òÖ÷ÌâÐÐÉæ¼°µØÀ׶ϸù¡¢ÐÐÕþ·£¿î¡¢ÎÞÈË»ú³ö²ú»ò²Æ¸»ËðʧÅâ³¥µÈ»°Ì⣬ÒÔϰȾÎÚ¿ËÀ¼Îä×°¶ÓÁÓ×¢·¨ÂÉ»ú¹¹ºÍ´¦Ëùµ±¾Ö»ú¹¹µÈÖ¸±ê¡£½ØÖÁ4Ô£¬ºÚ¿ÍÒѲ¿ÊðÁ½ÖÖ¶ñÒâÈí¼þ£¬Ò»ÖÖ»ùÓÚGitHub¹«¿ª´úÂ룬ÁíÒ»ÖÖÃûΪGiftedCrook£¬¿ÉÇÔÈ¡ä¯ÀÀÆ÷Êý¾Ý²¢·¢Ë͵½Telegramй¶¡£´Ë±í£¬3Ô·ݻ¹·¢ÏÖÁËÖÁÉÙÈýÆðÀûÓÃÐÂÐͼäµý¶ñÒâÈí¼þWrecksteelµÄÍøÂç¹¥»÷£¬ºÚ¿Íͨ¹ý±»µÁÕË»§·¢ËÍÔ̺¬¹«¹²Îļþ¹²Ïí·þÎñÁ´½ÓµÄÐÂÎÅ£¬Ö´ÐÐPowerShell¾ç±¾ºó£¬¿ÉÌáÈ¡¶àÖÖÎļþ²¢½ØÈ¡ÆÁÄ»½ØÍ¼¡£CERT-UAÌṩÁËÍøÂç´¹µöµç×ÓÓʼþʾÀý£¬ÒÔ¾¯Ê¾¹«¼Ò°ÑÎÈ´ËÀ๥»÷¡£
https://therecord.media/hackers-impersonate-drone-companies-state-agencies-spy-ukraine
5. WK Kellogg CoÔâClopÀûÓÃCleo·ì϶ִÐÐÊý¾Ý͵ÇÔ¹¥»÷
4ÔÂ7ÈÕ£¬ÃÀ¹úʳƷ¾ÞÍ·WK Kellogg Co½üÈÕÖÒ¸æÔ±¹¤ºÍ¹©¸øÉÌ£¬¹«Ë¾Êý¾ÝÔÚ2024ÄêCleoÊý¾Ý͵ÇÔ¹¥»÷ÖÐÔâÇÔÈ¡¡£CleoÈí¼þÊÇÒ»¿îÍйÜÎļþ´«ÊäʵÓ÷¨Ê½£¬È¥ÄêÄêµ×£¬ClopÀÕË÷Èí¼þÍÅ»ïÀûÓÃÁ½¸öÁãÈÕ·ì϶CVE-2024-50623ºÍCVE-2024-55956£¬¼¯Ìå¹¥»÷Á˸ÃÈí¼þ£¬Ê¹ÍþвÐÐΪÕß¿ÉÄÜÈëÇÖ·þÎñÆ÷²¢ÇÔÈ¡Êý¾Ý¡£WK KelloggÓÚ2025Äê2ÔÂ27ÈÕ»ñϤ´ËÊ£¬²¢µ±¼´·¢Õ¹µ÷²é¡£¾ÁªÏµCleoºóµÃÖª£¬Ò»Ãûδ¾ÊÚȨµÄÈËÓÚ2024Äê12ÔÂ7ÈÕ½Ó¼ûÁËCleoΪWK KelloggÍйܵķþÎñÆ÷¡£Ö»¹ÜWK Kelloggδ¾ßÌåÌá¼°Clop»òÊý¾Ý͵ÇÔ¹¥»÷£¬µ«»ã±¨ÊÂÎñµÄÈÕÆÚÓë2024Äê12Ô²úÉúµÄÒ»²¨¹¥»÷ÏàÎǺϡ£´Ë±í£¬ClopÀÕË÷Èí¼þÍÅ»ïÔÚ½«WK KelloggÁÐÈëÆäÊý¾ÝÐÂäįÕË÷ÍøÕ¾ºó²»¾Ã£¬¾Í°ä²¼ÁËÎ¥¹æÍ¨Öª¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬Ó×ÎÒµÄÐÕÃûºÍÉç»á±£Ïպš£WK KelloggÒÑÓëCleoÇ×êǺÏ×÷£¬È·¶¨ÁËΪ½â¾öÎ¥¹æÐÐΪ²¢Ô¤·À½«À´²úÉúÀàËÆÊÂÎñ¶øÖ´Ðеݲȫ´ëÊ©¡£Õâ´ÎÊÂÎñʹWK Kellogg³ÉΪÊܵ½ClopµÄCleoÁãÈÕ¹¥»÷Ó°ÏìµÄ¶à¶à¹«Ë¾ÖеÄ×îÐÂÊܺ¦Õß¡£
https://www.bleepingcomputer.com/news/security/food-giant-wk-kellogg-discloses-data-breach-linked-to-clop-ransomware/
6. ÐÂÐÍNeptune RAT±äÖÖÍþв¼Ó¾ç£¬ÇÔÃÜÓë·ÛËéÄÜÁ¦Éý¼¶
4ÔÂ7ÈÕ£¬½üÈÕ£¬Ò»ÖÖеÄNeptune RAT±äÖÖͨ¹ýYouTubeºÍTelegramµÈÉ罻ƽ̨¿í·º´«²¼£¬¶ÔWindowsÓû§×é³ÉÑϳÁÍþв¡£¸Ã¶ñÒâÈí¼þËäÐû³ÆÓÃÓÚ¡°½ÌÓýºÍ·µÂÖ÷ÕÅ¡±£¬µ«ÏÖʵְÄÜÈ´Ô¶·ÇÈç´Ë¡£Neptune RAT¿ÉÄÜÇÔÈ¡Óû§Æ¾Ö¤¡¢´úÌæ¼ÓÃÜÇ®±ÒÇ®°üµØÖ·£¬ÉõÖÁʹÓÃÀÕË÷Èí¼þÖ°ÄÜËø¶¨Îļþ£¬Ê¹¹¥»÷Õß¿ÉÄÜÈ«Ãæ½ÚÔìÊÜϰȾµÄϵͳ¡£¸Ã¶ñÒâÈí¼þÔÚÉ罻ƽ̨ÉÏÃâ·Ñ·Ö·¢£¬°µ²ØÁË¿ÉÖ´ÐÐÎļþ£¬²¢Ê¹Óð¢À²®×Ö·ûºÍ±íÇé·ûºÅ´úÌæ²¿ÃÅ×Ö·û´®£¬Ôö³¤ÁË·ÖÎöÄѶȡ£ÆäÃâ·Ñ°æ±¾»á×Ô¶¯ÌìÉúPowerShellºÅÁÏÂÔØ²¢ÔËÐÐÆäËû¶ñÒâ×é¼þ¡£Neptune RATÔ̺¬¶àÖÖ¹¥»÷Ä£¿é£¬ÈçÆ¾Ö¤ÍµÇÔ¡¢¼ôÌù°å½Ù³Ö¡¢ÀÕË÷Èí¼þºÍϵͳ°Ü»µµÈ£¬¿ÉÄÜÐͬ¹¥»÷WindowsÍÆËã»ú¡£ÎªÌӱܼì²â£¬¸Ã¶ñÒâÈí¼þ»áÅú¸Ä×¢²á±íÖµ¡¢Ôö³¤µ½Windows¹¤×÷´òË㷨ʽÖУ¬²¢²é³ÊÇ·ñÔÚÐé¹¹»·¾³ÖÐÔËÐС£´Ë±í£¬¸½¼ÓµÄDLLÎļþÔö³¤Á˸ü¶àÖ°ÄÜ£¬Ô̺¬ÈƹýÓû§ÕÊ»§½ÚÔì¡¢ÇÔÈ¡Êý¾ÝºÍʵʱÆÁÄ»¼à¿ØµÈ¡£
https://hackread.com/neptune-rat-variant-youtube-steal-windows-passwords/


¾©¹«Íø°²±¸11010802024551ºÅ