RECORDSTEALER¶ñÒâÈí¼þÁ¬ÐøÇÔÈ¡Ãô¸ÐÐÅÏ¢

Ðû²¼Ê±¼ä 2024-09-24
1. RECORDSTEALER¶ñÒâÈí¼þÁ¬ÐøÇÔÈ¡Ãô¸ÐÐÅÏ¢


9ÔÂ22ÈÕ £¬GoogleÄþ¾²Ñо¿ÍŶӽüÆÚ¾Û½¹ÓÚÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þµÄÁ¬ÐøÍþв £¬ÓÈÆäÊÇRECORDSTEALER£¨ÓÖ³ÆRecordBreakerºÍRaccoon Stealer V2£© £¬Ò»ÖÖ½ÓÄÉCÓïÑÔ±àдµÄ¸ß¼¶Êý¾Ý͵ÇÔ¹¤¾ß¡£¸Ã¶ñÒâÈí¼þרÃÅÕë¶ÔÐÅÓÿ¨ÐÅÏ¢¡¢ÃÜÂë¡¢cookies¼°¼ÓÃÜ»õ±ÒÇ®°üµÈÃô¸ÐÊý¾Ý½øÐÐ͵ȡ¡£ËüÀûÓöñÒâ¹ã¸æ¼°Î±×°³ÉºÏ·¨Ó¦ÓõÄÆƽâÈí¼þ×÷ΪÁ÷´«ÇþµÀ £¬ÓÕÆ­Óû§ÊäÈëÃÜÂëÒÔ¼¤»îÊܱ£»¤µÄ´æµµÎļþ £¬½ø¶øÖ´ÐжñÒâ²Ù×÷¡£Ò»µ©¼¤»î £¬RECORDSTEALERͨ¹ý¼ÓÃÜRC4ЭÒ齫Êý¾Ý´«ËÍÖÁC2·þÎñÆ÷ £¬Í¬Ê±ÊÕ¼¯É豸ID¡¢Óû§ÃûµÈÒªº¦ÐÅÏ¢¡£¾¡¹ÜRECORDSTEALERÒ»¶ÈÒòµÞÔìÕß±»²¶¼°»ù´¡ÉèÊ©±»´Ý»Ù¶ø¼Å¾² £¬µ«ÆäÁ÷´«¼ÆıÒѱ»ÏÖ´úÐÅÏ¢ÇÔÈ¡Õ߹㷺½ÓÄÉ £¬¼ÌÐøͨ¹ýαװÆƽâÈí¼þÍþвÓû§Äþ¾²¡£¸Ã¶ñÒâÈí¼þ²»½öÂÓ¶áä¯ÀÀÆ÷ÖеĸöÈËÐÅÏ¢ £¬»¹ÉîÈë¼ÓÃÜ»õ±ÒÇ®°ü¡¢½ØÈ¡ÆÁÄ»½Øͼ £¬²¢ÊÕ¼¯¼´Ê±Í¨Ñ¶Ó¦ÓõÄÃô¸ÐÎļþ¡£RECORDSTEALERµÄ¼¼ÊõÊÖ·¨ÓëVIDAR¡¢STEALCµÈÆäËûÐÅÏ¢ÇÔÈ¡·¨Ê½´æÔÚ¹²ÐÔ £¬Í¹ÏÔÁ˶ñÒâÈí¼þ¼¼ÊõµÄ¸ß¶È¸´ÓÃÐԺͼì²âÄѶÈ¡£


https://securityonline.info/recordstealer-a-case-study-in-the-persistent-threat-of-info-stealing-malware/


2. Twilioͨ»°¼Ç¼й¶£º12,000ÌõÒôƵÊý¾Ý̻¶Òþ˽·çÏÕ


9ÔÂ23ÈÕ £¬Ò»ÃûºÚ¿ÍÒÔ¡°grep¡±Îª±ðÃû £¬½üÆÚй¶ÁËÉù³ÆΪTwilioÔÆͨÐÅƽ̨¿Í»§µÄÁè¼Ý12,000Ìõͨ»°¼Ç¼ £¬°üÂ޵绰ºÅÂ롢ͨ»°Â¼Òô¼°Ïêϸ»á»°ÐÅÏ¢ £¬Ê±¼ä¿ç¶È´Ó2019ÄêÖÁ2024Äê¡£´ËʼþÑÏÖØÇÖ·¸Á˸öÈ˼°ÆóÒµÓû§µÄÒþ˽ £¬ÒòΪ鶵Äͨ»°¼Ç¼²»½ö°üÂÞÔªÊý¾ÝÈçµç»°ºÅÂ롢ͨ»°Ê±¼äºÍʱ³¤ £¬»¹É漰ʵ¼ÊµÄ¶Ô»°ÄÚÈÝ¡£TwilioÊÇÒ»¼Ò·þÎñÓÚ350,000¶à¸ö¿Í»§ÕË»§µÄ¼ÓÖÝÔÆͨÐŹ«Ë¾ £¬´Ë´Îй¶ԼռÆä×Ü¿Í»§ÊýµÄ3.37%¡£¾¡¹ÜºÚ¿ÍδÃ÷ȷ˵Ã÷ÈëÇÖ·½Ê½ £¬µ«Ð¹Â¶µÄͨ»°¼Ç¼Ïêϸ¼Ç¼ÁËͨ»°Ë«·½ºÅÂ롢״̬¡¢Ê±³¤¼°ÔÚ¿ÚÒë·þÎñÖеÄÌض¨ÐÅÏ¢ £¬ÈçÓïÑÔ¡¢·ÑÂʺͻỰÏêϸÐÅÏ¢¡£´Ë´Îй¶Ê¼þ²»½ö½ÒʾÁËͨ»°µÄÃô¸ÐÄÚÈÝ £¬»¹Ôö¼ÓÁËÊܺ¦ÕßÔâÊÜÀÕË÷¡¢ÆÛÕ©ºÍÉí·Ýð³äµÄ·çÏÕ¡£ÆóÒµ¿ÉÄÜÒò´ËÃæÁÙGDPR»òCCPAµÈÒþ˽±£»¤¹æÔòµÄ´¦·£¡£Í¬Ê± £¬Ð¹Â¶µÄµç»°ºÅÂëÒ²³ÉΪ¶ÌÐźÍÓïÒôÍøÂçµöÓã¹¥»÷µÄÐÂÄ¿±ê¡£ÎªÁËÓ¦¶ÔÕâһΣ»ú £¬ÊÜÓ°Ïì·½ÐèѸËÙÐж¯ £¬Í¨ÖªÓû§¡¢±£»¤Â¼ÒôÊý¾Ý²¢×Éѯִ·¨½¨Òé¡£´ËÍâ £¬¼ÓÇ¿·ÃÎÊ¿ØÖÆ¡¢Êý¾Ý¼ÓÃܺÍÓ¦¼±ÏìÓ¦»úÖÆÒ²ÊÇ·À·¶Î´À´ÀàËÆʼþµÄÒªº¦´ëÊ©¡£


https://hackread.com/hacker-leaks-twilio-call-records-audio-recordings/


3. Android¶ñÒâÈí¼þNecroͨ¹ýGoogle PlayѬȾ1100Íǫ̀É豸


9ÔÂ23ÈÕ £¬Android Óû§ÃæÁÙÑÏÖصĶñÒâÈí¼þÍþв £¬ÃûΪNecroµÄаæľÂí¼ÓÔØÆ÷ͨ¹ýGoogle PlayÉϵĺϷ¨Ó¦Óü°·Ç¹Ù·½ÇþµÀÁ÷´«µÄÐ޸İæÈí¼þ £¬ÒÑDZÈëÁè¼Ý1100Íǫ̀É豸¡£NecroÀûÓöñÒâ¹ã¸æÈí¼þ¿ª·¢¹¤¾ß°ü£¨SDK£©Ç±·üÓÚÕÕƬ±à¼­Ó¦Óá°ÎÞËûÏà»ú¡±¼°ÍøÂçä¯ÀÀÆ÷¡°Max Browser¡±µÈÁ÷ÐÐÈí¼þÖÐ £¬ÕâЩSDKαװ³ÉÕý³£¹¦Ð§ £¬ÊµÔò°²×°¹ã¸æÈí¼þ¡¢Ö´ÐÐJavaScriptºÍDEXÎļþ¡¢´Ù½ø¶©ÔÄÆÛÕ© £¬²¢×÷Ϊ¶ñÒâÁ÷Á¿ÊðÀí¡£¾¡¹Ü²¿ÃÅÓ¦ÓÃÒѸüÐÂÒÔÒƳýNecro £¬µ«¾É°æ±¾ÒÅÁôµÄ¶ñÒ⸺ÔØÈÔ¿ÉÄܶÔÉ豸×é³ÉÍþв¡£´ËÍâ £¬Necro»¹Í¨¹ý·Ç¹Ù·½ÇþµÀÁ÷´«µÄWhatsApp¡¢Spotify¼°MinecraftµÈÈÈÃÅÈí¼þµÄÐ޸İæ¹ã·ºÀ©É¢ £¬ÊµÊ©ÆÛÕ©ÐÔ¹ã¸æչʾ¡¢Î´¾­ÊÚȨµÄÓ¦Ó÷¨Ê½°²×°¼°Ó븶·Ñ·þÎñ½»»¥µÈ¶ñÒâÐÐΪ¡£ÓÉÓڷǹٷ½ÇþµÀÄÑÒÔ×·×Ù¾ßÌåѬȾÊýÁ¿ £¬µ«ÒÑÖªGoogle Playƽ̨µÄѬȾ¹æÄ£ÒÑÏ൱ÅӴ󡣹ȸèÒѶԴËÀà¾Ù±¨Õ¹¿ªÊÓ²ì £¬¶øÄþ¾²×¨¼Ò½¨ÒéÓû§±£³Ö¾¯Ìè £¬¼°Ê±Ð¶ÔØÊÜѬȾӦÓò¢×ªÏòÄþ¾²À´Ô´¡£


https://www.bleepingcomputer.com/news/security/android-malware-necro-infects-11-million-devices-via-google-play/


4. MC2 DataÊý¾Ýй¶£º2.2TB¸öÈËÐÅϢ̻¶ £¬Ó°Ï쳬1ÒÚÃÀ¹úÈË


9ÔÂ23ÈÕ £¬¾ÝCybernewsµÄÑо¿ £¬Åä¾°ÊӲ칫˾MC2 DataµÄÒ»¸ö´óÐÍÔÚÏßÊý¾Ý¿â £¬ÄÚº¬2.2TBµÄÃÀ¹úÈ˸öÈËÐÅÏ¢ £¬ÒòδÉèÃÜÂë±£»¤¶ø̻¶ÔÚ»¥ÁªÍøÉÏ £¬ÈκÎÈ˾ù¿ÉÇáËÉ·ÃÎÊ¡£¸ÃÊý¾Ý¿â¹ã·ºÊÕ¼¯ÁË°üÂÞ·¸×ï¼Ç¼¡¢¾ÍÒµÀúÊ·¡¢¼ÒÍ¥Êý¾ÝºÍÁªÏµ·½Ê½µÈÃô¸ÐÐÅÏ¢ £¬Ó°Ï췶Χ¹ã·º £¬¾ÝÔ¤¼ÆÖÁÉÙÓÐ1ÒÚÃÀ¹úÈË£¨Ô¼Õ¼È«¹úÈË¿ÚµÄÈý·ÖÖ®Ò»£©µÄÊý¾ÝÔâй¶¡£¸üÁîÈ˵£ÓǵÄÊÇ £¬»¹ÓÐÁè¼Ý230ÍòµÄMC2 Data·þÎñ¶©ÔÄÕßµÄÊý¾ÝҲδÄÜÐÒÃâ¡£´ËʼþÔÙ´Î͹ÏÔÁËijЩÆóÒµÔÚÊý¾ÝÄþ¾²·½ÃæµÄÑÏÖØÊèºö £¬¾¡¹ÜÕâЩÆóÒµÀíÓ¦×ñÊØÏà¹Ø¹æÔò £¬µ«ÆäÄþ¾²´ëÊ©È´Ã÷ÏÔ²»×㡣ר¼Ò¾¯¸æ³Æ £¬´ËÀàÊý¾Ý鶶ÔÍøÂç·¸×ï·Ö×Ó¶øÑÔÈçͬ½ð¿ó £¬ÎªÆäʵʩթƭ¡¢Éí·Ý͵ÇԵȷ¸×ï»î¶¯ÌṩÁ˼«´ó±ãÀû¡£Ãæ¶ÔDZÔÚµÄÊý¾Ýй¶·çÏÕ £¬¸öÈËÓ¦Ìá¸ß¾¯Ìè £¬½ÓÄÉÐëÒª´ëÊ©±£»¤×ÔÉíÐÅÏ¢Äþ¾²¡£


https://www.malwarebytes.com/blog/news/2024/09/100-million-us-citizens-have-records-leaked-by-background-check-service


5. ¿°Èø˹Öݸ»À¼¿ËÁÖÏؽü3Íò¾ÓÃñÊý¾ÝÔâÀÕË÷Èí¼þ¹¥»÷й¶


9ÔÂ24ÈÕ £¬¿°Èø˹Öݵĸ»À¼¿ËÁÖÏØ×î½üÔâÓöÁËÑÏÖصÄÀÕË÷Èí¼þ¹¥»÷ʼþ £¬µ¼Ö½ü30,000Ãû¾ÓÃñµÄÃô¸ÐÐÅÏ¢±»Ð¹Â¶¡£¸Ã¹¥»÷·¢ÉúÔÚ½ñÄê5ÔÂ19ÈÕ £¬ºÚ¿ÍÀÖ³ÉÇÖÈëÁËÏØÊé¼Ç¹Ù°ì¹«ÊÒµÄϵͳ £¬ÍµÈ¡ÁË°üÂÞÐÕÃû¡¢Éç»áÄþ¾²ºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢½ðÈÚÕË»§ºÅÂë¼°Ò½ÁÆÐÅÏ¢µÈÔÚÄڵĸöÈËÊý¾Ý¡£ÕâЩÊý¾Ý»¹º­¸ÇÁËÒ½ÁƼǼ¡¢ÒßÃç½ÓÖÖ¡¢COVID-19Ïà¹ØÐÅÏ¢ÒÔ¼°±£ÏÕʶ±ðºÅµÈÃô¸Ð·þÎñÐÅÏ¢¡£Ê¼þÆعâºó £¬¸»À¼¿ËÁÖÏØѸËÙÁªÏµÍøÂçÄþ¾²×¨¼ÒºÍÁª°îÖ´·¨²¿ÃÅ £¬²¢ÓÚ7ÔÂ19ÈÕÏò¹«ÖÚͨ±¨ÁËÊÓ²ì½øÕ¹¡£¾¡¹ÜĿǰûÓÐÀÕË÷Èí¼þÍÅ»ïÈÏ¿ÉÔðÈÎ £¬ÇÒÏØ·½ÔÚ°µÍøËÑË÷ÖÐδ·¢ÏÖÊý¾Ý±»Ðû²¼»ò³öÊ۵ļ£Ïó £¬µ«¸ÃʼþÈÔÒýÆðÁ˹㷺¹Ø×¢¡£¿°Èø˹ÖÝÖÝÎñÇä°ì¹«Êҵȼà¹Ü»ú¹¹ÒÑ»ñÖª´ËÊ £¬²¢ÒªÇó¸ÃÏؼÓÇ¿Äþ¾²´ëÊ© £¬ÒÔ·À·¶Î´À´ÀàËÆʼþµÄ·¢Éú¡£Îª´Ë £¬¸»À¼¿ËÁÖÏØÒѽÓÄÉһϵÁдëÊ© £¬°üÂÞ½ûÓò»»îÔ¾µÄÓû§ÕÊ»§ £¬ÒÔÌá¸ßÊý¾Ý±£»¤Ë®Æ½¡£


https://therecord.media/kansas-ransomware-attack-thousands-residents


6. µÂ¹úÖ´·¨²¿ÃÅÀֳɽӹÜVanirÀÕË÷Èí¼þйÃÜÍøÕ¾


9ÔÂ19ÈÕ £¬µÂ¹úÖ´·¨²¿ÃÅÔÚ½üÆÚÐж¯ÖÐÀֳɴݻÙÁËÒ»¸öÃûΪVanirµÄÀÕË÷Èí¼þ×éÖ¯µÄ²¿ÃÅ»ù´¡ÉèÊ© £¬²¢½Ó¹ÜÁËÆäÓÃÓÚй¶Êܺ¦ÕßÊý¾ÝµÄÍøÕ¾¡£¸ÃÍøÕ¾ÓÚ7ÔÂÉÏÏß £¬Æð³õÅû¶ÁËÈýÃûÊܺ¦ÕßµÄÐÅÏ¢ £¬°üÂÞÒ»¼ÒµÂ¹ú¹«Ë¾¡£¿¨¶û˹³¶òÊм°°ÍµÇ-·ûÌÚ±¤Öݵľ¯·½Óë¼ì²ì¹Ù°ì¹«ÊÒ×ÔÁùÔÂÆð±ãÕë¶Ô´Ë×éÖ¯Õ¹¿ªÊÓ²ì £¬²¢ÔÚ8ÔÂÀֳɶ¨Î»²¢·âËøÁËÆäÔÚTORÍøÂçÉϵĻҳÃæ £¬×èÖ¹Á˸ü¶àÊý¾Ýй¶¡£¾¡¹ÜÈ¡µÃ´Ë´ÎʤÀû £¬µ«¹ØÓÚÏÓÒÉÈËÊÇ·ñ±»²¶¼°ËùÁе¹ú¹«Ë¾¾ßÌåÊÜËðÇé¿ö £¬¹Ù·½Î´Óè͸¶ £¬½öÌåÏÖÏà¹ØÊÓ²ìÈÔÔÚ½øÐÐÖС£·ÖÎöÈËÊ¿Ö¸³ö £¬Vanir×éÖ¯ÓëÏÈÇ°ÒÑÖªµÄAkiraÀÕË÷Èí¼þÐж¯ÔÚйÃÜÍøÕ¾Éè¼ÆÉÏ´æÔÚÏàËÆÐÔ £¬»ò´æÔÚ¹ØÁª¡£¸Ã×éÖ¯¾ÝÐÅÓɶ«Å·³ÉÔ±×é³É £¬²¢¿ÉÄÜÓëKarakurt¡¢LockBitµÈ¾ÉÓÐÀÕË÷Èí¼þÍÅ»ïµÄÇ°³ÉÔ±Ïà¹Ø¡£´ËʼþÔÙ´Î̻¶ÁËÈ«ÇòÖ´·¨»ú¹¹ÔÚ¹¥»÷ÀÕË÷Èí¼þ·¸×ïʱËùÃæÁٵġ°´òµØÊó¡±À§¾³ £¬ÓÉÓÚ·¸×ï·Ö×Ó¶à²ØÄäÓÚÄÑÒÔ´¥¼°µÄ¹ú¼Ò £¬ÆäѸËÙÖØ×éºÍ±äÖÖµÄÄÜÁ¦¸øÖ´·¨´øÀ´Á˾޴óÌôÕ½¡£


https://therecord.media/germany-seizes-vanir-ransomware-leak?&web_view=true