°Í¶ûµÄĦÊаÙÍòÃÀÔªBECÚ¿Æ­°¸Â¶³öϵͳÐÔ°²È«·ì϶

°ä²¼¹¦·ò 2025-09-02

1. °Í¶ûµÄĦÊаÙÍòÃÀÔªBECÚ¿Æ­°¸Â¶³öϵͳÐÔ°²È«·ì϶


9ÔÂ1ÈÕ £¬°Í¶ûµÄĦÊнüÆÚÅû¶һ·³Á´óóÒ×µç×ÓÓʼþй¶£¨BEC£©¹¥»÷ÊÂÎñ £¬Ú¿Æ­Õßͨ¹ýαÔìÉí·Ý¡¢´Û¸Ä¹©¸øÉÌÒøÐÐÐÅÏ¢µÈ¼¿Á© £¬´ÓÊÐÕþ²¿ÃÅÇÔÈ¡³¬150ÍòÃÀÔª £¬Í¹ÏÔ¹«¹²»ú¹¹ÔÚÍøÂ簲ȫÓë²ÆÕþÄÚ¿ØÖеÄÑϳÁ·ì϶¡£Æ¾¾Ý¼à²ì³¤°ì¹«ÊÒµ÷²é £¬2025Äê2ÔÂÖÁ3ÔÂÆÚ¼ä £¬¸ÃÊÐÓ¦³êÕ˿ÃÅ£¨AP£©·ÖÁ½´ÎÏòÚ¿Æ­Õß½ÚÔìµÄÒøÐÐÕË»§×ªÕ˹²¼Æ1,524,621.04ÃÀÔª¡£Ú¿Æ­ÕßÓÚ2024Äê12ÔÂͨ¹ýÐéαÓÊÏä¼ÙÒ⹩¸øÉÌÔ±¹¤ £¬ÇÖÈëÆäWorkdayϵͳ²¢´Û¸ÄÒøÐÐÕË»§ÐÅÏ¢¡£Ö»¹ÜÚ¿Æ­ÕßÌá½»µÄ±í¸ñ´æÔÚÐÅÏ¢ÃýÎó £¬ÇÒÂŴγ¢ÊÔµ÷»»ÒøÐÐϸ½Ú £¬µ«AP²¿ÃÅÈýÃûÔ±¹¤¾ùδִÐиù»ùºËʵ·¨Ê½ £¬×îÖÕºË×¼ÁËڲƭÐÔÒªÇó¡£ÊÂÎñ¶³ö³ö¶à³ÁÎÊÌ⣺Ê×ÏÈ £¬AP²¿ÃŲ»×㹩¸øÉÌÐÅÏ¢ºËÑé»úÔì £¬¼´±ãÔÚ2019Äê¡¢2022ÄêÏȺóÒòÐéÎ±ÒøÐÐÐÅÏ¢µ÷»»Ëðʧ6.2Íò¼°37.6ÍòÃÀÔªºó £¬ÈÔδ³ÉÁ¢ÓÐЧ±£ÏÕ´ëÊ© £»Æä´Î £¬ÄÚ²¿½ÚÔìÐÎͬÐéÉè £¬Ô±¹¤ÂÅ´ÎδºËʵÎļþÕæÊµÐÔ¼´Í¨¹ý¹Ø¼ü²Ù×÷ £»´Ë±í £¬ÊÐÕþϵͳ¶Ô¹©¸øÉÌÕË»§µÄ½Ó¼ûȨÏÞÖÎÀí´æÔÚÊè© £¬µ¼ÖÂÚ¿Æ­ÕßÄܳ־ÃÉøÈë²¢Åú¸ÄÖ÷ÌâÊý¾Ý¡£


https://securityaffairs.com/181772/cyber-crime/fraudster-stole-over-1-5-million-from-city-of-baltimore.html


2. ÍøÂç·¸×ï·Ö×ÓÀûÓÃMeta¸æ°×ƽ̨´«²¼Brokewell¶ñÒâÈí¼þ


8ÔÂ31ÈÕ £¬ÍøÂç·¸×ï·Ö×ÓÀÄÓÃMetaÆìÏÂÉ罻ƽ̨µÄ¸æ°×ϵͳ £¬Í¨¹ýαÔì³ÛÃû½ðÈÚ·ÖÎö¹¤¾ßTradingViewµÄÐéα¸æ°× £¬ÏòAndroidÓû§¶¨Ïò´«²¼¾ß±¸¶à³ÁÇÔÃÜÖ°ÄܵÄBrokewell¶ñÒâÈí¼þ £¬ÐγÉÕë¶Ô¼ÓÃÜÇ®±Ò×ʲúµÄ¾«×¼¹¥»÷Á´Ìõ¡£¾ÝBitdefender°²È«ÍŶÓÅû¶ £¬¸Ã»î¶¯×Ô7ÔÂ22ÈÕÆðͨ¹ýÔ¼75¸ö±¾µØ»¯¸æ°×·¢Õ¹ £¬¸æ°×ÄÚÈÝÒÔ"Ãâ·Ñ»ñÈ¡TradingView Premium"Ϊµö¶ü £¬½ö¶ÔAndroidÉ豸Óû§Õ¹Ê¾¶ñÒâÄÚÈÝ £¬ÆäËûϵͳ½Ó¼ûÔòÏÔʾÎÞº¦Ò³Ãæ¡£¹¥»÷Á÷³ÌÉè¼Æ¾«ÃÜ£ºÊܺ¦Õßµã»÷¸æ°×ºó»á±»³Á¶¨ÏòÖÁ·ÂðTradingView¹ÙÍøµÄ´¹µöÒ³Ãæ £¬ÓÕµ¼ÏÂÔØ¼Ù×°³ÉÀûÓøüеÄtw-update.apkÎļþ¡£¸Ã¶ñÒâÈí¼þ×°Öúó»áÁ¢¼´ÒªÇó¸¨ÖúÖ°ÄÜȨÏÞ £¬Í¨¹ýµ¯³öÐéαϵͳ¸üÐÂÌáÐѸ²¸Çºó¶Ü²Ù×÷ £¬×Ô¶¯ÊÚÓèÉ豸ÆëÈ«½ÚÔìȨ¡£¸üÖµÍ×ÌùÐĵÄÊÇ £¬Èí¼þ»á·ÂÕÕAndroidϵͳÉý¼¶½çÃæ £¬ÓÕÆ­Óû§ÊäÈëËøÆÁPINÂë £¬ÎªºóÐøÓÆ¾Ã»¯½ÚÔìÆÌ·¡£×÷Ϊ×Ô2024ËêÊ×»îÔ¾µÄ¶ñÒⷨʽ £¬BrokewellÕâ´ÎչʾµÄ"¸ß¼¶°æ±¾"Ö°ÄÜÈ«ÃæÉý¼¶¡£


https://www.bleepingcomputer.com/news/security/brokewell-android-malware-delivered-through-fake-tradingview-ads/


3. ºÚ¿ÍÐû³ÆÈëÇÖÁËAT&T £¬ÇÔÈ¡2400ÍòÓû§Êý¾Ý


9ÔÂ1ÈÕ £¬¹¥»÷ÕßÐû³ÆÒѳɹ¦ÈëÇÖÃÀ¹úµçОÞÍ·AT&TµÄÖ÷Ìâ»ù´¡ÉèÊ© £¬²¢ÔÚµØÏÂÂÛ̳Ðû³ÆÍ¨¹ý²¿Êð¶¨Ôì¶ñÒâÈí¼þ»ñµÃʵʱ¶Á/дȨÏÞ £¬¿ÉÄÜÓ°ÏìÊý°ÙÍòÓû§¡£¾ÝºÚ¿ÍÔÚ°µÍø°ä²¼µÄÌû×ÓÃèÊö £¬ÆäÇÖÈëÐÐΪÒѳÖÐøÊýÖÜδ±»¼ì²âµ½ £¬²¢Ðû³Æ°ÑÎÕÁËÒ»¸öÔ̺¬Ô¼2400ÍòAT&TÓû§Êý¾ÝµÄ¶¯Ì¬Êý¾Ý¿â £¬¿ÉʵʱÅú¸ÄÓû§ÐÅÏ¢²¢Ö´ÐÐSIM»¥»»¹¥»÷¡£½ØÖÁĿǰ £¬Cybernews×êÑÐÍŶÓÉÐδÄÜÑéÖ¤ÕâЩ˵·¨µÄÕæÊµÐÔ £¬ÓйØÊý¾ÝÑù±¾ÍøÕ¾Ò²´¦ÓÚÎÞ·¨½Ó¼û״̬¡£Õâ´ÎÊÂÎñµÄÖ÷ÌâÍþвÔÚÓÚ¹¥»÷ÕßÐû³ÆµÄÈý´óÄÜÁ¦£ºÆäÒ» £¬Í¨¹ý´Û¸ÄÓû§µç»°ºÅÂëÓëSIM¿¨µÄ°ó¶¨¹ØÏµ £¬Ö´ÐÐSIM»¥»»¹¥»÷ £»Æä¶þ £¬Èƹý»ùÓÚ¶ÌÐŵÄË«³É·ÖÈÏÖ¤£¨2FA£© £¬Ö±½Ó¶ÁÈ¡ÒøÐÓ×¢É罻ýÌåµÈ·þÎñµÄ¶þ´ÎÑéÖ¤´úÂë £»ÆäÈý £¬½Ó¼ûÔ̺¬Ë°ÎñID¡¢ÐÕÃû¡¢IPµØÖ·µÈÃô¸ÐÐÅÏ¢µÄÓû§Êý¾Ý¿â £¬ÈôÊôʵ½«×é³É³Á´óÊý¾Ýй¶¡£Ä¿Ç° £¬AT&TÉÐδ¶Ô´Ë×÷³ö¹«¿ª»ØÓ¦ £¬CybernewsÍŶÓÕý³ÖÐø×·×Ù°µÍøÊý¾ÝÑù±¾¡£


https://cybernews.com/security/att-data-breach-impacted-millions-hackers-say/


4. ±öϦ·¨ÄáÑÇÖÝ×ܼì²ì³¤°ì¹«ÊÒÔâÀÕË÷Èí¼þ¹¥»÷


9ÔÂ1ÈÕ £¬ÃÀ¹ú±öϦ·¨ÄáÑÇÖÝ×ܼì²ì³¤°ì¹«ÊÒ£¨OAG£©½üÈÕÈ·ÈÏÔâ·êÀÕË÷Èí¼þ¹¥»÷ £¬µ¼ÖÂÆä·þÎñÆ÷ÓÚ8Ô³õ±»ÆÈÏÂÏß £¬ÐÌÊÂÓëÃñʰ¸¼þÉóÀí³öÏÖÑÓÎ󡣸ÃÖÝ×ܼì²ì³¤´÷·ò¡¤É­µÏ£¨Dave Sunday£©ÔÚ8ÔÂ29ÈյĴ«µÝÖÐ֤ʵ £¬Õâ´ÎÖжÏÓÉ±í²¿ÈËԱͨ¹ý¼ÓÃÜÎļþÖ´ÐÐ £¬¹¥»÷ÕßÒªÇóÖ§¸¶Êê½ðÒÔ¸´Ô­ÔËÓª £¬µ«½ØÖÁĿǰOAGÉÐδ֧¸¶ÈκÎÊê½ð¡£Ö»¹ÜδÃ÷È·Êý¾ÝÊÇ·ñ±»µÁ £¬É­µÏ°µÊ¾ÕýÓëÆäËû»ú¹¹·¢Õ¹½áºÏµ÷²é £¬²¢Ç¿µ÷¡°Èôµ÷²éÏÔʾÓбØÒª £¬½«ÏòÓйØÓ×ÎÒ·¢ËÍ֪ͨ¡± £¬µ«Î´½øÒ»²½Ð¹Â©µ÷²éϸ½Ú»òÓ¦¶Ô´ëÊ©¡£×÷Ϊ±öÖÝ×î¸ß·¨ÂÉ»ú¹¹ £¬OAGÕÆ¹ÜÌáÆðÐÌÊÂËßËÏ¡¢Ö´ÐÐÏû·ÑÕß± £»¤·¨µÈÖ÷ÌâÖ°ÄÜ¡£Õâ´ÎÍøÂçÊÂÎñµ¼ÖÂÈ«Öݶà¼Ò·¨Ôº±»ÆÈµ¢¸é°¸¼þÉóÀíÆÚÏÞ¡£ÊÂÎñ³õ´ÎÅû¶ÓÚ8ÔÂ18ÈÕ £¬ÆäʱOAGÍøÕ¾¡¢°ì¹«ÓÊÏä¼°¹Ì¶¨µç»°È«ÃæÌ±»¾ £¬Ö±½ÓÓ°ÏìÆäÓ빫¼Ò¼°ÀûÒæÓйØÕߵŵͨ¡£½ØÖÁ×îд«µÝ £¬OAG´ó²¿Ãʤ×÷ÈËÔ±ÒѸ´Ô­ÓÊÏä½Ó¼ûȨÏÞ £¬Ö÷µç»°Ïߺ͹ٷ½ÍøÕ¾Òà³ÁÐÂÉÏÏß £¬µ«È«ÊýÖ°Äܵĸ´Ô­ÈÔÔÚ½øÐÐÖС£É­µÏÖ¸³ö £¬È«ÖÝ17¸ö°ì¹«µØÖ·µÄÔ¼1200ÃûÔ±¹¤ÈÔÔÚͨ¹ý´úÌæÇþ·ά³ÖÈÕ³£¹¤×÷¡£


https://www.infosecurity-magazine.com/news/ransomware-pennsylvania-ag/


5. Silver FoxÀûÓÃÊðÃûÇý¶¯·¨Ê½²¿ÊðValleyRATºóÃÅ


9ÔÂ1ÈÕ £¬Check Point Research£¨CPR£©½üÈÕÅû¶ £¬Ó볯ÏʹØÁªµÄSilver Fox APT×éÖ¯ÕýÀûÓÃ΢ÈíÊðÃûµÄºÏ·¨Çý¶¯·¨Ê½Ö´ÐÐÐÂÐÍÍøÂç¹¥»÷ £¬Í¨¹ý"×Ô´ø·ì϶Çý¶¯·¨Ê½£¨BYOVD£©"¼¼ÊõÈÆ¹ý°²È«·À»¤ £¬²¿ÊðÄ£¿é»¯ºóÃÅValleyRAT¡£¸Ã×éÖ¯ÀÄÓÃWatchDog AntimalwareÇý¶¯·¨Ê½£¨amsdk.sys£©ºÍZemanaÇý¶¯£¨ZAM.exe£© £¬ÀûÓÃÆäËÁÒâ¹ý³ÌÖÕÖ¹Ö°ÄÜ £¬Ç¿ÐÐÖÕÖ¹·À²¡¶¾¼°EDR¹¤¾ß¹ý³Ì £¬Îª¶ñÒâÈí¼þÆÌ·¡£Ö»¹ÜÉÏÊöÇý¶¯¾ùͨ¹ý΢ÈíÊý×ÖÊðÃûÈÏÖ¤ £¬ÇÒδ±»ÁÐÈëÒÑÖª·ì϶Áбí £¬µ«¹¥»÷Õßͨ¹ýÅú¸Ä¹¦·ò´Á×Ö¶ÎÌìÉúÐÂÎļþ¹þÏ£ £¬ÔÚά³ÖÊðÃûÓÐЧÐÔµÄͬʱ¶ã±Ü¼ì²â¡£Õâ´Î¹¥»÷³öÏÖÏÔÖø¼¼ÊõÑݽøÌص㣺Silver Fox½«·´·ÖÎöÄ£¿é¡¢Óƾû¯»úÔ졢ǶÈëʽÇý¶¯¼°Ö¸±ê¹ý³ÌÁбí·â×°ÖÁµ¥Ò»¼ÓÔØÆ÷ £¬²¢¼±¾çµü´úÇý¶¯°æ±¾ÒÔÔ¤·À²éɱ¡£×êÑÐÏÔʾ £¬Æä¶ñÒâÈí¼þÅäÖÃרÃÅÕë¶Ô¶«ÑǵØÓòÊ¢Ðеݲȫ²úÆ· £¬ÇÒ»ù´¡ÉèʩָÏòÖйú·þÎñÆ÷¡£ValleyRATºóÞ߱¸ÆÁÄ»¼à¿Ø¡¢ºÅÁîÖ´ÐÓ×¢Êý¾Ý±íйµÈÄÜÁ¦ £¬¿Éͨ¹ýTorÍøÂç½Ó¹ÜÔ¶³ÌÖ¸Áî £¬½øÒ»²½Ç¿»¯¹¥»÷Òñ±ÎÐÔ¡£


https://www.infosecurity-magazine.com/news/silver-fox-deploy-valleyrat/


6. ÑÇÂíÑ·×èÖ¹¶íÂÞ˹APT29ºÚ¿Í¹¥»÷Microsoft 365


9ÔÂ1ÈÕ £¬ÑÇÂíÑ·Íþвµý±¨ÍŶӽüÈÕ½áºÏCloudflareÓë΢Èí £¬³É¹¦·ÛËé¶íÂÞ˹µ±¾Ö²¼¾°ºÚ¿Í×éÖ¯Midnight Blizzard£¨APT29£©Õë¶ÔMicrosoft 365ÕË»§µÄ¸´ÔÓ¹¥»÷Ðж¯¡£¸Ã×é֯ͨ¹ýË®¿Ó¹¥»÷¼¼ÊõÈëÇֺϷ¨ÍøÕ¾ £¬ÀûÓÃbase64±àÂë»ìºÏ¶ñÒâ´úÂë £¬½«Ô¼10%µÄ½Ó¼ûÕßËæ»ú³Á¶¨ÏòÖÁ·ÂðCloudflareÑéÖ¤Ò³ÃæµÄÓòÃû £¬ÓÕµ¼Êܺ¦Õß½øÈë¶ñÒâÉ豸´úÂëÈÏÖ¤Á÷³Ì £¬ÊÔͼÊÚȨ¹¥»÷Õß½ÚÔìµÄÉ豸½Ó¼ûÆä΢ÈíÕË»§¡£×÷Ϊ¶íÂÞ˹¶Ô±íµý±¨¾Ö£¨SVR£©¹ØÁªµÄAPT29×éÖ¯ £¬Õâ´ÎÐж¯Ò»Á¬ÁËÆä¹ßÓõÄÍøÂç´¹µöÕ½Êõ £¬µ«¼¼ÊõÊÖ·¨ÏÔÖøÉý¼¶£ºÍ¨¹ý»ùÓÚcookieµÄϵͳԤ·ÀͳһÓû§ÂŴγÁ¶¨Ïò £¬½µµÍ¶³ö·çÏÕ £»²»ÔÙÒÀÀµ¼ÙÒâAWSÓòÃû»òÉç»á¹¤³ÌÈÆ¹ýMFA £¬×ª¶øÀûÓÃ΢ÈíÉ豸´úÂëÑéÖ¤»úÔìµÄ·ì϶¡£×êÑÐÏÔʾ £¬¸Ã×éÖ¯½üÆÚ¹¥»÷Ö¸±êº­¸ÇÅ·ÖÞ´óʹ¹Ý¡¢»ÝÆÕÆóÒµ¼°TeamViewer £¬Í¹ÏÔÆäµý±¨ÍøÂçÒâͼ¡£ÑÇÂíÑ·×êÑÐÈËÔ±ÔÚ·¢ÏÖ¶ñÒâEC2Ê·ýºóѸËÙ¸ôÀë £¬²¢Ð­Í¬ºÏ×÷ͬ°é×è¶ÏÓòÃû½âÎö¡£Ö»¹ÜAPT29ÊÔÍ¼×ªÒÆ»ù´¡ÉèÊ©ÖÁÆäËûÔÆ·þÎñÉ̲¢×¢²áÐÂÓòÃû £¬µ«Ðж¯ÒÑÔâ·ÛËé¡£


https://www.bleepingcomputer.com/news/security/amazon-disrupts-russian-apt29-hackers-targeting-microsoft-365/