SpyLoan¶ñÒâÈí¼þÔÙÏ®£º15¿îÐÂÓ¦ÓÃGoogle PlayÏÂÔØ³¬800Íò´Î

Ðû²¼Ê±¼ä 2024-12-02

1. SpyLoan¶ñÒâÈí¼þÔÙÏ®£º15¿îÐÂÓ¦ÓÃGoogle PlayÏÂÔØ³¬800Íò´Î


11ÔÂ30ÈÕ£¬£¬£¬ £¬£¬£¬Google Play ÉÏ·¢Ã÷ÁËÒ»×éеÄ15¸öSpyLoan Android¶ñÒâÈí¼þÓ¦ÓóÌÐò£¬£¬£¬ £¬£¬£¬ÕâЩӦÓÃÖ÷ÒªÕë¶ÔÄÏÃÀ¡¢¶«ÄÏÑǺͷÇÖÞµÄÓû§£¬£¬£¬ £¬£¬£¬×°ÖÃÁ¿ÒÑÁè¼Ý800Íò´Î¡£¡£¡£¡£¡£¡£ÕâЩӦÓóÌÐòÓÉ¡°Ó¦ÓóÌÐò·ÀÓùͬÃË¡±³ÉÔ±Âõ¿Ë·Æ·¢Ã÷²¢±¨¸æ£¬£¬£¬ £¬£¬£¬ËæºóÒѱ»´ÓAndroid¹Ù·½Ó¦ÓÃÊÐËÁÖÐɾ³ý¡£¡£¡£¡£¡£¡£SpyLoanÓ¦ÓóÌÐòÒÔ½ðÈÚ¹¤¾ßΪ»Ï×Ó£¬£¬£¬ £¬£¬£¬Í¨¹ý¿ìËÙÉóÅúÁ÷³ÌÏòÓû§ÌṩÓÕÆ­ÐÔÇÒͨ³£ÐéαµÄ´û¿îÌõ¿î¡£¡£¡£¡£¡£¡£Ò»µ©Êܺ¦Õß×°ÖÃÁËÕâЩӦÓ㬣¬£¬ £¬£¬£¬ËûÃǾͻᱻҪÇóÌá½»Ãô¸ÐµÄÉí·Ý֤ʵÎļþ¡¢Ô±¹¤ÐÅÏ¢ºÍÒøÐÐÕË»§Êý¾Ý£¬£¬£¬ £¬£¬£¬²¢Í¨¹ýÒ»´ÎÐÔÃÜÂë¾ÙÐÐÑéÖ¤¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬ÕâЩӦÓû¹»áÀÄÓÃ×°±¸È¨ÏÞÍøÂç´ó×ÚÃô¸ÐÊý¾Ý£¬£¬£¬ £¬£¬£¬°üÀ¨ÁªÏµÈËÁÐ±í¡¢¶ÌÐÅ¡¢Ïà»ú¡¢Í¨»°¼Í¼ºÍλÖõÈ£¬£¬£¬ £¬£¬£¬ÓÃÓÚºóÐøµÄÀÕË÷Àú³Ì¡£¡£¡£¡£¡£¡£Ö»¹ÜGoogleµÄÓ¦ÓÃÉóºË»úÖÆ¿ÉÒÔÆÁÕÏÎ¥·´Play StoreÌõ¿îµÄÈí¼þ£¬£¬£¬ £¬£¬£¬µ«SpyLoanÓ¦ÓÃÈÔÈ»Äܹ»Â©Íø¡£¡£¡£¡£¡£¡£ÎªÁËÌá·ÀÕâÖÖΣº¦£¬£¬£¬ £¬£¬£¬Óû§Ó¦×ÐϸÔĶÁÓû§Ì¸ÂÛ¡¢¼ì²é¿ª·¢ÕßµÄÉùÓþ¡¢ÏÞ֯װÖÃʱÊÚÓèÓ¦ÓóÌÐòµÄȨÏÞ£¬£¬£¬ £¬£¬£¬²¢È·±£Éè±¹ØÁ¬ÄGoogle Play Protect´¦Óڻ״̬¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/spyloan-android-malware-on-google-play-installed-8-million-times/


2. ²©ÂåÄáÑÇ×ãÇò¾ãÀÖ²¿ÔâRansomHubÀÕË÷Èí¼þ¹¥»÷


11ÔÂ30ÈÕ£¬£¬£¬ £¬£¬£¬Òâ´óÀûÖ°Òµ×ãÇò¾ãÀÖ²¿²©ÂåÄáÑÇ×î½ü³ÉΪÁËRansomHubÍøÂç·¸·¨ÍÅ»ïµÄÀÕË÷Èí¼þ¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£¡£¾Ý¸ÃÍÅ»ïÔÚ°µÍøÉϵÄÌû×Ó£¬£¬£¬ £¬£¬£¬ËûÃÇÉù³ÆÒѾ­ÇÔÈ¡²¢Ðû²¼Á˲©ÂåÄáÑǵĴó×ÚÊý¾Ý£¬£¬£¬ £¬£¬£¬°üÀ¨Ö÷½ÌÁ·ÎÄÉ­×ô¡¤Òâ´óÀûŵµÄ¹ÍÓ¶ÌõÔ¼£¬£¬£¬ £¬£¬£¬ÆäÖÐÏêϸÁгöÁËËûµÄн³êºÍ½±½ðÐÅÏ¢¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬»¹Éù³ÆÇÔÈ¡ÁËǰÖúÀí½ÌÁ·µÄ»¤ÕÕɨÃè¼þ¡¢Ò»Ïß¶ÓÇòÔ±µÄ»¤ÕÕ¡¢ÌõÔ¼ºÍСÎÒ˽¼ÒÊý¾Ý£¬£¬£¬ £¬£¬£¬ÒÔ¼°¾ãÀÖ²¿µÄ²ÆÎñ״̬Ã÷ϸºÍÒ½ÁÆÊý¾ÝµÈ¡£¡£¡£¡£¡£¡£RansomHubÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏÌåÏÖ£¬£¬£¬ £¬£¬£¬²©ÂåÄáÑÇÒòÍøÂçÇå¾²ÐÔȱ·¦¶øÔâµ½¹¥»÷£¬£¬£¬ £¬£¬£¬ËùÓÐÊý¾Ý¾ù±»µÁ¡£¡£¡£¡£¡£¡£¾ãÀÖ²¿Ëæºó½ÒÏþÉùÃ÷֤ʵÁËÀÕË÷Èí¼þ¹¥»÷µÄ±£´æ£¬£¬£¬ £¬£¬£¬²¢ÌåÏÖÊý¾Ý¿ÉÄܻᱻ¹ûÕæ¡£¡£¡£¡£¡£¡£RansomHub¸øÁ˲©ÂåÄáÑÇÈýÌìʱ¼äÀ´Öª×ãδ¹ûÕæµÄÒªÇ󣬣¬£¬ £¬£¬£¬²»È»ËùÓÐÊý¾Ý½«ÓÚ11ÔÂ29ÈÕÖÐÎç°²ÅÅÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏ¡£¡£¡£¡£¡£¡£Ö»¹Ü²©ÂåÄáÑǵȾãÀÖ²¿´ËÇ°Ò²ÔøÔâÊܹýÍøÂç¹¥»÷£¬£¬£¬ £¬£¬£¬µ«´Ë´ÎÊÂÎñÔÙ´ÎÌáÐÑÁËÖ°Òµ×ãÇò¾ãÀÖ²¿ÔöÇ¿ÍøÂçÇå¾²·À»¤µÄÖ÷ÒªÐÔ¡£¡£¡£¡£¡£¡£


https://www.theregister.com/2024/11/30/bologna_fc_ransomhub/


3. Rockstar 2FA£ºÐÂÐÍÍøÂç´¹ÂÚÆ½Ì¨ÇÔÈ¡Microsoft 365ƾ֤


11ÔÂ29ÈÕ£¬£¬£¬ £¬£¬£¬ÃûΪ¡°Rockstar 2FA¡±µÄÐÂÐÍÍøÂç´¹ÂÚ¼´Ð§ÀÍ£¨PhaaS£©Æ½Ì¨ÒѾ­·ºÆð£¬£¬£¬ £¬£¬£¬×¨ÎªÊµÑé´ó¹æÄ£ÖÐÐÄÈË£¨AiTM£©¹¥»÷¶øÉè¼Æ£¬£¬£¬ £¬£¬£¬Ö¼ÔÚÇÔÈ¡Microsoft 365ƾ֤¡£¡£¡£¡£¡£¡£¸Ãƽ̨ͨ¹ý×èµ²ÓÐÓõĻỰcookie£¬£¬£¬ £¬£¬£¬ÔÊÐí¹¥»÷ÕßÈÆ¹ýÄ¿µÄÕÊ»§µÄ¶àÖØÉí·ÝÑéÖ¤£¨MFA£©±£»£»£»¤¡£¡£¡£¡£¡£¡£Êܺ¦Õß±»ÓÕµ¼µ½·ÂðµÄMicrosoft 365µÇÂ¼Ò³Ãæ£¬£¬£¬ £¬£¬£¬ÊäÈëÆ¾Ö¤ºó£¬£¬£¬ £¬£¬£¬AiTMЧÀÍÆ÷½«Æäת·¢ÖÁMicrosoftµÄÕýµ±Ð§ÀÍÍê³ÉÑéÖ¤£¬£¬£¬ £¬£¬£¬²¢ÔÚ·µ»ØÊ±²¶»ñcookie¡£¡£¡£¡£¡£¡£Rockstar 2FAÏÖʵÉÏÊÇDadSecºÍPhoenix¹¤¾ß°üµÄ¸üаæ£¬£¬£¬ £¬£¬£¬×Ô2024Äê8ÔÂÒÔÀ´ÔÚÍøÂç·¸·¨ÉçÇøÖдóÊܽӴý£¬£¬£¬ £¬£¬£¬Á½ÖÜÊÛ¼Û200ÃÀÔª£¬£¬£¬ £¬£¬£¬API»á¼ûÐø¶©180ÃÀÔª¡£¡£¡£¡£¡£¡£¸ÃЧÀÍÔÚTelegramµÈÆ½Ì¨ÍÆ¹ã£¬£¬£¬ £¬£¬£¬¾ß±¸¶àÏЧ£¬£¬£¬ £¬£¬£¬ÈçÖ§³Ö¶à¸öƽ̨¡¢Ìӱܼì²â¡¢Êܺ¦Õßɸ²é¡¢×Ô¶¯FUD¸½¼þºÍÁ´½Ó¡¢Óû§ÓѺõÄÖÎÀíÃæ°åµÈ¡£¡£¡£¡£¡£¡£×Ô2024Äê5ÔÂÒÔÀ´£¬£¬£¬ £¬£¬£¬Òѽ¨Éè5000¶à¸öÍøÂç´¹ÂÚÓò£¬£¬£¬ £¬£¬£¬ÀÄÓÃÕýµ±µç×ÓÓʼþÓªÏúƽ̨»òÈëÇÖÕË»§Èö²¥¶ñÒâÐÅÏ¢£¬£¬£¬ £¬£¬£¬Ê¹ÓöþάÂë¡¢Õýµ±Ëõ¶ÌЧÀÍÁ´½ÓºÍPDF¸½¼þµÈÌÓ±Ü×èÖ¹ÒªÁì¡£¡£¡£¡£¡£¡£Ö»¹ÜÖ´·¨²¿·ÖÒѽÓÄÉÐж¯¹¥»÷PhaaSƽ̨£¬£¬£¬ £¬£¬£¬µ«Rockstar 2FAµÄ·ºÆðºÍÆÕ¼°Åú×¢£¬£¬£¬ £¬£¬£¬Ö»ÒªÍøÂç·¸·¨·Ö×ÓÄÜÒԵͱ¾Ç®»ñÈ¡ÕâЩ¹¤¾ß£¬£¬£¬ £¬£¬£¬´ó¹æÄ£ÓÐÓÃÍøÂç´¹ÂÚÐж¯µÄΣº¦ÈÔ½«Ò»Á¬±£´æ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-rockstar-2fa-phishing-service-targets-microsoft-365-accounts/


4. ÐéᲩ²ÊÓ¦ÓÃʹÓÃAIÉùÒôÇÔÈ¡Ãô¸ÐÊý¾Ý


11ÔÂ29ÈÕ£¬£¬£¬ £¬£¬£¬ÍøÂç·¸·¨·Ö×ÓÕýʹÓôøÓÐAIÌìÉúÉùÒôµÄÐéᲩ²ÊÓ¦ÓóÌÐòºÍ¹ã¸æ£¬£¬£¬ £¬£¬£¬Í¨¹ýÉ罻ýÌåÆ½Ì¨ÒýÓÕÓû§ÏÂÔØÚ²Æ­ÐÔÓ¦Ó㬣¬£¬ £¬£¬£¬´Ó¶øÇÔȡСÎÒ˽¼ÒÐÅÏ¢ºÍ¿î×Ó¡£¡£¡£¡£¡£¡£¾ÝÍøÂçÇå¾²¹«Ë¾Group-IB·¢Ã÷£¬£¬£¬ £¬£¬£¬ÒÑÓÐÁè¼Ý500ÌõÐéα¹ã¸æºÍ1377¸ö¶ñÒâÍøÕ¾±»Ê¶±ð£¬£¬£¬ £¬£¬£¬Ö÷ÒªÕë¶Ô°£¼°¡¢Öж«¡¢Å·ÖÞºÍÑÇÖÞÓû§¡£¡£¡£¡£¡£¡£ÕâЩթƭÕßʹÓÃAIÌìÉú¶àÓïÑÔÉùÒô£¬£¬£¬ £¬£¬£¬ÔöÌíȦÌ׵ĿÉÐŶÈ£¬£¬£¬ £¬£¬£¬µ¼ÖÂÊܺ¦ÕßÔâÊÜÖØ´ó¾­¼ÃËðʧ£¬£¬£¬ £¬£¬£¬²¿·ÖËðʧÁè¼Ý10,000ÃÀÔª¡£¡£¡£¡£¡£¡£Óû§Ó¦×èÖ¹´Ó·Ç¹Ù·½ÈªÔ´ÏÂÔØÓ¦Ó㬣¬£¬ £¬£¬£¬Ð¡ÐIJ»¿ÉÐŵÄÓŻݣ¬£¬£¬ £¬£¬£¬²¢½ÓÄÉÇ¿ÓÐÁ¦µÄÇå¾²²½·¥£¬£¬£¬ £¬£¬£¬ÈçʹÓÃÃÜÂëºÍË«ÒòËØÉí·ÝÑéÖ¤£¬£¬£¬ £¬£¬£¬ÒÔÌá·À´ËÀàÍøÂçÕ©Æ­¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬Ðéα̸ÂÛºÍÍÆ¼öÒ²ÊÇÕâЩȦÌ×µÄÒªº¦´Ù³ÉÒòËØ£¬£¬£¬ £¬£¬£¬Óû§Ó¦¼á³ÖСÐÄ£¬£¬£¬ £¬£¬£¬Ïàʶ×îеÄÔÚÏßÕ©Æ­ºÍÍøÂç´¹ÂÚÊÖÒÕ£¬£¬£¬ £¬£¬£¬È·±£Ð¡ÎÒ˽¼ÒÐÅÏ¢Çå¾²¡£¡£¡£¡£¡£¡£


https://hackread.com/fake-betting-apps-ai-generated-voices-steal-data/


5. NHS¶ùͯҽԺÔâINC RansomÀÕË÷Èí¼þÍŻ﹥»÷


11ÔÂ29ÈÕ£¬£¬£¬ £¬£¬£¬Ó¢¹ú¹ú¼ÒÒ½ÁÆÐ§ÀÍϵͳ£¨NHS£©µÄÀûÎïÆÖ°¢¶ûµÂº£¶ùͯҽԺºÍÀûÎïÆÖÐÄÐØÒ½ÔºNHS»ù½ð»áËÆºõÕýÔâÊÜINC RansomÀÕË÷Èí¼þÍÅ»ïµÄ¹¥»÷£¬£¬£¬ £¬£¬£¬¸ÃÍÅ»ïÍþвҪй¶ÆäËùÇÔÈ¡µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¾Ý³Æ£¬£¬£¬ £¬£¬£¬ÕâЩÊý¾Ý°üÀ¨»¼Õߺ;èÔùÕßµÄÈ«Ãû¡¢µØµã¡¢¾èÔù½ð¶î¡¢Ò½ÁƱ¨¸æºÍ²ÆÎñÎļþµÈ£¬£¬£¬ £¬£¬£¬Ê±¼ä¿ç¶È´Ó2018ÄêÖÁ2024Äê¡£¡£¡£¡£¡£¡£Ò½ÔºÒѽÒÏþÉùÃ÷£¬£¬£¬ £¬£¬£¬ÕýÔÚÓëÏàÖúͬ°éºËʵÊý¾Ý²¢ÏàʶDZÔÚÓ°Ï죬£¬£¬ £¬£¬£¬Í¬Ê±Óë¹ú¼Ò·¸·¨¾ÖÏàÖú±£»£»£»¤ÏµÍ³¡£¡£¡£¡£¡£¡£Óë´Ëͬʱ£¬£¬£¬ £¬£¬£¬µØÀíλÖÃÏàÁÚµÄÍþÀÕ¶ûNHSÐÅÍлú¹¹Ò²ÔâÓöÁËÍøÂç¹¥»÷£¬£¬£¬ £¬£¬£¬µ«Á½´ÎÏ®»÷ËÆºõûÓйØÁª¡£¡£¡£¡£¡£¡£Ö»¹ÜNHS×éÖ¯Êܵ½Ï®»÷µÄÇéÐβ¢²»ÓÐÊý£¬£¬£¬ £¬£¬£¬µ«Á½´ÎÏ®»÷ÔÚͳһÖÜÄÚÏà¸ô²»Ô¶£¬£¬£¬ £¬£¬£¬ÊµÊôÏ£Ææ¡£¡£¡£¡£¡£¡£°¢¶ûµÂ¡¤ºÚÒÁÒ½ÔºÌåÏÖ£¬£¬£¬ £¬£¬£¬ÆäЧÀÍÕý³£ÔËÐУ¬£¬£¬ £¬£¬£¬Ã»ÓÐÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£INC RansomÍÅ»ïÔøÏ®»÷¹ýËÕ¸ñÀ¼NHSϵͳ£¬£¬£¬ £¬£¬£¬²¢ÇÔÈ¡ÁË15ÍòÈ˵ÄÊý¾Ý£¬£¬£¬ £¬£¬£¬´Ë´ÎÏ®»÷ÊÖ·¨ÀàËÆ£¬£¬£¬ £¬£¬£¬¿ÉÄÜÊÇΪÁËÊ©¼ÓѹÁ¦ÒÔÖª×ãÀÕË÷ÒªÇ󡣡£¡£¡£¡£¡£


https://www.theregister.com/2024/11/29/inc_ransom_alder_hey_childrens_hospital/


6. ¶íÂÞ˹ִ·¨²¿·ÖÒѾв¶²¢ÆðËßÍøÂç·¸·¨·Ö×ÓWazawaka


11ÔÂ29ÈÕ£¬£¬£¬ £¬£¬£¬¶íÂÞ˹ִ·¨²¿·ÖÒѾв¶²¢ÆðËßÎÛÃûÕÑÖøµÄÀÕË÷Èí¼þ¿ª·¢ÕßÃ×¹þÒÁ¶û¡¤ÅÁ·òÂåÎ¬Ææ¡¤ÂíÌØÎ¬Ò®·ò£¨Mikhail Pavlovich Matveev£©£¬£¬£¬ £¬£¬£¬ËûÒ²±»³ÆÎªWazawaka¡¢Uhodiransomwar¡¢m1xºÍBoriselcin¡£¡£¡£¡£¡£¡£Ëû±»Ö¸¿Ø¿ª·¢¶ñÒâÈí¼þ²¢¼ÓÈë¶à¸öºÚ¿Í×éÖ¯¡£¡£¡£¡£¡£¡£¾Ý¶íÂÞ˹ÄÚÎñ²¿ÉùÃ÷£¬£¬£¬ £¬£¬£¬ÊÓ²ìÖ°Ô±ÒÑÍøÂçµ½×ã¹»Ö¤¾Ý£¬£¬£¬ £¬£¬£¬²¢½«ÆäÒÆËÍÖÁ¼ÓÀïÄþ¸ñÀÕÊÐÖÐÑëµØÒªÁìÔº¾ÙÐÐÉóÀí¡£¡£¡£¡£¡£¡£ÍøÂçÕþ²ßר¼Ò°ÂÁиñ¡¤É³»ùÂå·ò·¢Ã÷£¬£¬£¬ £¬£¬£¬ÂíÌØÎ¬Ò®·òÍýÏëʹÓÃÀÕË÷Èí¼þ¼ÓÃÜÉÌÒµ×éÖ¯µÄÊý¾ÝÒÔÊÕÈ¡½âÃÜÊê½ð¡£¡£¡£¡£¡£¡£È¥Äê5Ô£¬£¬£¬ £¬£¬£¬ÃÀ¹ú˾·¨²¿Ò²¶ÔÂíÌØÎ¬Ò®·òÌá³öÖ¸¿Ø£¬£¬£¬ £¬£¬£¬Ö¸¿ØËû¼ÓÈëÁËHiveºÍLockBitÀÕË÷Èí¼þÐж¯¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬Ëû»¹±»ÒÔΪÊÇRampºÚ¿ÍÂÛ̳µÄ½¨ÉèÕߺÍÖÎÀíÔ±£¬£¬£¬ £¬£¬£¬ÒÔ¼°BabukÀÕË÷Èí¼þÐж¯µÄ×î³õÖÎÀíÔ±¡£¡£¡£¡£¡£¡£ÃÀ¹ú²ÆÎñ²¿Íâ¹ú×ʲú¿ØÖư칫ÊÒÒ²¶ÔÂíÌØÎ¬Ò®·òʵÑéÁËÖÆ²Ã£¬£¬£¬ £¬£¬£¬ÃÀ¹ú¹úÎñÔºÐüÉÍ1000ÍòÃÀÔªÕ÷¼¯ÓйØËûµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£ÂíÌØÎ¬Ò®·òÔÚÍøÉϷdz£»£»£»îÔ¾£¬£¬£¬ £¬£¬£¬¾­³£ÓëÍøÂçÇå¾²Ñо¿Ö°Ô±ºÍרҵÈËÊ¿ÅÊ̸£¬£¬£¬ £¬£¬£¬²¢¹ûÕæÌÖÂÛËûµÄÍøÂç·¸·¨»î¶¯¡£¡£¡£¡£¡£¡£ÔÚÊܵ½ÃÀ¹úÖÆ²Ãºó£¬£¬£¬ £¬£¬£¬ËûÉõÖÁÔÚÍÆÌØÉϼ¥Ð¦ÃÀ¹úÖ´·¨²¿·Ö£¬£¬£¬ £¬£¬£¬²¢Ðû²¼ÁËÒ»ÕÅͨ¼©º£±¨µÄÕÕÆ¬¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/russia-arrests-cybercriminal-wazawaka-for-ties-with-ransomware-gangs/