Ðéα°æÈ¨ÉùÃ÷´ßÉúÐÂÐÍNoodlophileÇÔÈ¡³ÌÐò±äÖÖ
Ðû²¼Ê±¼ä 2025-08-201. Ðéα°æÈ¨ÉùÃ÷´ßÉúÐÂÐÍNoodlophileÇÔÈ¡³ÌÐò±äÖÖ
8ÔÂ18ÈÕ£¬ÍøÂçÇå¾²¹«Ë¾Morphisec¿ËÈÕÅû¶һÖÖÐÂÐÍNoodlophile Stealer±äÖÖ£¬¸Ã¶ñÒâÈí¼þͨ¹ýÈ«ÐÄÉè¼ÆµÄÐéα°æÈ¨ÇÖȨ´¹ÂÚÓʼþÈö²¥£¬ÍŽáDropboxÁ´½ÓÓëDLL²àÔØÊÖÒÕ£¬¶ÔÃÀ¹ú¡¢Å·ÖÞ¡¢²¨Â޵ĺ£¹ú¼Ò¼°ÑÇÌ«µØÇøÆóÒµÌᳫ¶¨Ïò¹¥»÷¡£Ñо¿ÏÔʾ£¬¸Ã±äÖÖÒÑ´ÓÔçÆÚʹÓÃÐéαAIƽ̨µÄ¹¥»÷ÊÖ¶ÎÉý¼¶Îª¸üÖØ´óµÄÕ½Êõ×éºÏ¡£¹¥»÷Á÷³ÌʼÓڸ߶ȸöÐÔ»¯µÄÍøÂç´¹ÂÚÓʼþ£¬¹¥»÷Õßαװ³É¹Ù·½°æÈ¨ÇÖȨ֪ͨ£¬½ÓÄɶàÓïÑÔ±àд²¢°üÀ¨Ä¿µÄÆóÒµFacebookÒ³ÃæµÄΨһIDµÈÏêϸÐÅÏ¢£¬ÓªÔì½ôÆÈ¸ÐÆÈʹÊÕ¼þÈ˵ã»÷"Éó²éÖ¤¾Ý"Á´½Ó¡£²î±ðÓڹŰ崹ÂÚ¹¥»÷£¬¸Ã¶ñÒâÈí¼þͨ¹ýDropboxÁ´½ÓÌṩѹËõ°üÎļþ£¬ÄÚº¬±»¸Ä¶¯µÄÕýµ±Ó¦ÓóÌÐò£¬Ê¹ÓÃDLL²àÔØÊÖÒÕÓÕÆÊÜÐÅÍÐÈí¼þÔÚÓû§²»ÖªÇéʱ¼ÓÔØÒþ²Ø¶ñÒâÎļþ¡£ÕâÖÖÊÖÒÕͨ¹ýÕýµ±³ÌÐòÓë¶ñÒâDLLµÄ¹ØÁªÖ´ÐУ¬ÓÐÓÃÈÆ¹ýÇå¾²¹¤¾ß¼ì²â£¬×îÖÕ¼ÓÔØµÄ¶ñÒâ´úÂ뻹½èÖúTelegramͨѶ½øÒ»²½¹æ±Ü¼à¿Ø¡£Ò»µ©Ñ¬È¾Àֳɣ¬¸ÃÇÔÈ¡³ÌÐò½«Öص㹥»÷ÍøÂçä¯ÀÀÆ÷£¬ÇÔÈ¡µÇ¼ƾ֤¡¢ÐÅÓÿ¨ºÅ¡¢×Ô¶¯Ìî³äÐÅÏ¢¼°ÅÌËã»úϵͳÏêÇé¡£
https://hackread.com/phishing-scam-fake-copyright-notice-noodlophile-stealer/
2. USB¶ñÒâÈí¼þÔ˶¯ÔÚÈ«Çò¹æÄ£ÄÚÈö²¥¼ÓÃÜÇ®±ÒÍÚ¿ó³ÌÐò
8ÔÂ18ÈÕ£¬CyberProofÍйܼì²âÓëÏìÓ¦£¨MDR£©ÍŶӽüÆÚ½ÒÆÆÒ»ÆðʹÓÃÊÜѬȾUSB×°±¸Èö²¥µÄ¶à½×¶Î¶ñÒâÈí¼þ¹¥»÷ÊÂÎñ£¬ÆäÊÖÒÕÊÖ·¨Óë2024Äê°¢Èû°Ý½®CERTÅû¶µÄ¡°Í¨ÓÃÍÚ¿ó¡±ÍýÏë¸ß¶È¹ØÁª£¬Í¹ÏÔ¼ÓÃÜÇ®±ÒÍÚ¿óÍþвÔÚ2025ÄêµÄÒ»Á¬Ñݱ䡣¸Ã¹¥»÷ͨ¹ýÒþ²ØÓÚUSBÇý¶¯Æ÷µÄVisual Basic¾ç±¾Æô¶¯£¬Ö´ÐкóŲÓÃxcopy.exeµÈÀú³Ì½«¶ñÒâÎļþ×ªÒÆÖÁWindows System32Ŀ¼£¬²¢Ê¹ÓÃDLLËÑË÷˳ÐòÐ®ÖÆÊÖÒÕ²àÔØ¼ÓÃܿ󹤳ÌÐò¡£Ö»¹Ü×îÖÕ±»EDR¹¤¾ß×èÖ¹£¬µ«ÆäÈÆ¹ýÇå¾²¿ØÖƵÄÕ½ÂÔ£¨ÈçÍŽáPowerShell¾ç±¾£©ÈÔ̻¶³ö¹Å°å·ÀÓùϵͳµÄDZÔÚÎó²î¡£Ñо¿ÏÔʾ£¬´Ë´Î¹¥»÷ÓëÔçÆÚ»ùÓÚXMRigµÄZephyrÔ˶¯±£´æÊÖÒÕ¹ØÁª£¬¹¥»÷Õßͨ¹ý»ìÏý¾ç±¾ºÍ·Ö½×¶ÎÔØºÉ°²ÅÅ£¬ÊÔͼÔÚÖÕ¶Ë×°±¸ÉϽ¨É賤ÆÚ»¯ÍÚ¿óÄÜÁ¦¡£CyberProofͨ¹ý¶àÔ´Ç鱨׷×Ù·¢Ã÷£¬¸Ã¶ñÒâÈí¼þÒÑÀ©É¢ÖÁÃÀ¹ú¡¢Å·ÖÞ¡¢¶«ÄÏÑǼ°·ÇÖÞ¶à¹ú£¬µØÀíÁýÕÖ¹æÄ£Ö®¹ãÓ¡Ö¤ÁË¿ÉÒÆ¶¯½éÖÊÔÚÅÓëÉú³¤ÖеØÇø¾ù×÷ΪÍç¹ÌÈö²¥ÔØÌåµÄÏÖ×´¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬¹¥»÷Á÷³ÌÖвàÔØµÄ¶ñÒâDLLÎļþרÃÅÕë¶ÔÒªº¦ÏµÍ³Àú³Ì£¨Èçlsass.exe£©£¬Ëäδֱ½ÓÇÔȡƾ֤£¬µ«ÎªºóÐøÉý¼¶Îª¸ü¾ßÆÆËðÐÔµÄÎó²îʹÓÃÔ¤ÁôÁ˽ӿڡ£
https://www.infosecurity-magazine.com/news/usb-malware-spreads-cryptominer/
3. APT43ʹÓÃXenoRAT¶ñÒâÈí¼þ¹¥»÷¶à¸öפº«´óʹ¹Ý
8ÔÂ18ÈÕ£¬TrellixÑо¿Ö°Ô±¿ËÈÕÅû¶һÆðÓɹú¼ÒÖ§³ÖµÄÌØ¹¤Ô˶¯£¬¸ÃÐж¯×Ô2025Äê3ÔÂÆðÒ»Á¬Õë¶Ôפº«ÍâÑó½»Ê¹¹ÝÌᳫÖÁÉÙ19´ÎÓã²æÊ½´¹ÂÚ¹¥»÷£¬Æä»ù´¡ÉèÊ©Óë¹¥»÷ÊÖ·¨Ó볯ÏʺڿÍ×éÖ¯Kimsuky£¨APT43£©¸ß¶ÈÎǺϡ£´Ë´Î¹¥»÷ͨ¹ý¶ñÒâGitHub¿ÍÕ»·Ö·¢¹¦Ð§Ç¿Ê¢µÄXenoRATľÂí£¬Õ¹ÏÖ³ö¸ß¶ÈÕë¶ÔÐÔµÄÕ½ÊõÑݱ䡣¹¥»÷·ÖΪÈý¸ö½×¶Î£º3Ô³õµÄ³õʼ̽²â½×¶ÎÒÔijÖÐÅ·¹ú¼Òʹ¹ÝΪĿµÄ£»5ÔÂתÈëÖØ´óÍâ½»Ö÷Ì⣬Èçð³äÅ·Ã˸߼¶¹ÙÔ±·¢ËÍ¡°5ÔÂ14ÈÕÅ·ÃË´ú±íÍÅÕþÖÎ×Éѯ¾Û»á¡±µÄÐéαԼÇ룻6ÖÁ7ÔÂÔò¾Û½¹ÃÀº«¾üÊÂͬÃËÒéÌ⣬ÓÕ¶üÄÚÈÝÓëÕæÊµÊÂÎñʱ¼äµã¸ß¶ÈÆõºÏ¡£Ä¿µÄ¼¯ÖÐÓÚפÊ×¶ûµÄÅ·ÖÞʹ¹Ý£¬´¹ÂÚÓʼþαװ³É¾Û»áÔ¼Çë¡¢¹Ù·½ÐꝵÈÔ˶¯Í¨Öª£¬½ÓÄɶàÓïÖÖ²¢Ã°ÓÃÍâ½»¹ÙÃûÒå·¢ËÍ£¬³¡¾°»¯Éè¼ÆÏÔÖøÔöÇ¿¿ÉÐŶȡ£ËùÓй¥»÷¾ù½ÓÄÉͳһͶµÝ·½·¨£ºÍ¨¹ýDropbox¡¢Google Drive»òº«¹ú±¾ÍÁÔÆ´æ´¢·þÎñ·¢ËÍÃÜÂë±£»¤µÄZIPѹËõÎļþ£¬ÄÚº¬Î±×°³ÉPDFµÄLNKÎļþ¡£Óû§´¥·¢ºó£¬Îļþ»áÖ´ÐлìÏý´¦Öóͷ£µÄPowerShell´úÂ룬´ÓGitHub»òDropbox»ñÈ¡XenoRATÓÐÓÃÔØºÉ£¬²¢Í¨¹ýÍýÏëʹÃüʵÏÖϵͳ³¤ÆÚ»¯×¤Áô¡£
https://www.bleepingcomputer.com/news/security/xenorat-malware-campaign-hits-multiple-embassies-in-south-korea/
4. ÃÀ¹úÖÆÒ©ÆóÒµInotivÔâQilinÀÕË÷Èí¼þ¹¥»÷
8ÔÂ19ÈÕ£¬ÃÀ¹úÓ¡µÚ°²ÄÉÖÝÌõÔ¼Ñо¿×éÖ¯InotivÓÚ2025Äê8ÔÂ8ÈÕÅû¶һÆðÖØ´óÍøÂçÇå¾²ÊÂÎñ£¬Æä²¿·ÖϵͳÓëÊý¾ÝÔâ"÷è÷ë"£¨Qilin£©ÀÕË÷Èí¼þÍÅ»ï¼ÓÃÜ£¬µ¼ÖÂÓªÒµÔËÓªÖÐÖ¹¡£¸Ã¹«Ë¾×¨×¢ÓÚÒ©Î↑·¢¡¢»îÌ嶯ÎïÑо¿½¨Ä£¼°Çå¾²ÆÀ¹À£¬ÓµÓÐÔ¼2000ÃûÔ±¹¤£¬ÄêÊÕÈ볬5ÒÚÃÀÔª¡£Æ¾Ö¤InotivÏòÃÀ¹ú֤ȯÉúÒâίԱ»á£¨SEC£©Ìá½»µÄÎļþ£¬¹¥»÷±¬·¢ºó£¬¹«Ë¾Á¬Ã¦Æô¶¯Ó¦¼±ÏìÓ¦£¬ÍŽáÍⲿÇ徲ר¼ÒÊӲ첢ת´ïÖ´·¨²¿·Ö¡£³õ³ÌÐò²éÏÔʾ£¬ÍþвÐÐΪÕßδ¾ÊÚȨ»á¼ûϵͳºóʵÑé¼ÓÃÜ£¬µ¼ÖÂÊý¾Ý¿â¡¢ÄÚ²¿Ó¦ÓóÌÐòµÈÒªº¦ÉèÊ©ÎÞ·¨Õý³£Ê¹Óá£Îª»º½âÓ°Ï죬ITÍŶÓÒѽ«²¿·ÖÊÜÓ°Ïì²Ù×÷ǨáãÖÁÀëÏßÌæ»»¼Æ»®£¬µ«×èÖ¹Åû¶ʱ£¬ÏµÍ³»Ö¸´Ê±¼äÈÔÎÞ·¨Ô¤¼Æ£¬ÓªÒµÖÐÖ¹Ô¤¼ÆÒ»Á¬Ò»¶Îʱ¼ä¡£ÖµµÃ¹Ø×¢µÄÊÇ£¬QilinÍÅ»ïÉù³ÆÇÔȡԼ16.2Íò¸öÎļþ£¨×ÜÁ¿´ï176GB£©£¬²¢ÔÚÆäйÃÜÍøÕ¾Ðû²¼Êý¾ÝÑù±¾£¬µ«InotivÉÐδȷÈÏÊý¾ÝÕæÊµÐÔ¡£
https://www.bleepingcomputer.com/news/security/pharma-firm-inotiv-says-ransomware-attack-impacted-operations/
5. ¼ÓÄôó½ðÈÚî¿Ïµ»ú¹¹CIROÅû¶Êý¾Ýй¶ÊÂÎñ
8ÔÂ19ÈÕ£¬¼ÓÄôóͶ×Êî¿Ïµ×éÖ¯£¨CIRO£©ÓÚ2025Äê8ÔÂ11ÈÕÅû¶һÆðÖØ´óÍøÂçÇå¾²ÊÂÎñ£¬Æä²¿·Ö»áÔ±¹«Ë¾¼°×¢²áÔ±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢Ôâδ¾ÊÚȨ»á¼û¡£×÷Ϊ2023Ä꽨ÉèµÄÌìÏÂÐÔ×ÔÂÉ×éÖ¯£¬CIROÈÏÕæî¿Ïµ¼ÓÄôóͶ×ÊÉúÒâÉÌ¡¢ÅäºÏ»ù½ðÉúÒâÉ̼°Õ®Îñ/¹ÉƱÊг¡Ô˶¯£¬²¢ÓµÓжԲ»¶Ô¹æÊµÌå´¦ÒÔ·£¿îµÈ´¦·ÖµÄȨÁ¦¡£´Ë´ÎÊÂÎñÒý·¢¶Ô½ðÈÚî¿Ïµ»ú¹¹Êý¾ÝÇå¾²ÄÜÁ¦µÄ¹Ø×¢¡£ÊÂÎñ±¬·¢ºó£¬CIROѸËٹرÕÊÜÓ°ÏìϵͳÒÔÈ·±£Çå¾²£¬²¢ÍŽáÍâ²¿ÍøÂçÇ徲ר¼Ò¼°Ö´·¨²¿·ÖÕö¿ªÊӲ졣³õ³ÌÐò²éÈ·ÈÏ£¬ÍþвÐÐΪÕß»ñÈ¡Á˲¿·Ö»áÔ±¹«Ë¾¼°ÆäÔ±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢£¬µ«Ïêϸй¶Êý¾ÝµÄÐÔ×ÓÈçÐÕÃû¡¢ÁªÏµ·½·¨¡¢²ÆÎñÐÅÏ¢µÈÉÐδ¹ûÕæ¡£CIROÔÚ8ÔÂ18ÈÕµÄÐÂΟåÖÐÇ¿µ÷£¬Ö»¹ÜÊÂÎñÒý·¢µ£ÐÄ£¬µ«Æä½¹µãÖ°ÄÜÈçʵʱ¹ÉƱÊг¡î¿ÏµÎ´ÊÜÓ°Ï죬Ͷ×ÊÕßͶ×ÊÔ˶¯ÎÞΣº¦¡£ÎªÓ¦¶ÔDZÔÚÓ°Ï죬CIROÔÊÐí½«Ö±½Ó֪ͨÊÜÓ°ÏìСÎÒ˽¼Ò£¬²¢ÌṩΣº¦»º½â·þÎñ¡£Í¬Ê±£¬¸Ã»ú¹¹ÖÒÑÔÆä³ÉԱСÐÄÒÔî¿Ïµ»ú¹¹ÃûÒåË÷ȡСÎÒ˽¼Ò»ò²ÆÎñÐÅÏ¢µÄ´¹Âڵ绰¼°Óʼþ£¬±ÜÃâ¶þ´Î¹¥»÷¡£
https://www.infosecurity-magazine.com/news/canadian-financial-regulator-hacked/
6. °²ÁªÈËÊÙ´ó¹æÄ£Êý¾Ýй¶ӰÏì110ÍòÈË
8ÔÂ19ÈÕ£¬2025Äê7Ô£¬È«Çò×ÅÃûÀÕË÷×éÖ¯ShinyHuntersͨ¹ýÕë¶ÔSalesforceƽ̨µÄ¶ñÒâOAuthÓ¦Óù¥»÷£¬Òý·¢¶àÆð´ó¹æÄ£Êý¾Ýй¶ÊÂÎñ£¬Ó°Ïì¹æÄ£º¸Ç°ü¹Ü¡¢¿Æ¼¼¡¢ÁãÊÛ¡¢ÉÝ³ÞÆ·µÈÁìÓò¡£´Ë´Î¹¥»÷Á´ÖУ¬ÃÀ¹ú°ü¹Ü¾ÞÍ·°²ÁªÈËÊÙ£¨Allianz Life£©³ÉΪ½¹µã£¬Æä110Íò¿Í»§Ð¡ÎÒ˽¼ÒÐÅÏ¢ÔâÇÔ£¬ÊÂÎñ̻¶³öµÚÈý·½ÔÆ·þÎñÇå¾²Îó²îµÄÑÏÖØÎ£º¦¡£Æ¾Ö¤Åû¶£¬7ÔÂ16ÈÕ£¬¹¥»÷Õßͨ¹ýÓÕÆ°²ÁªÈËÊÙÔ±¹¤½«¶ñÒâOAuthÓ¦ÓÃÁ´½ÓÖÁ¹«Ë¾SalesforceʵÀý£¬Àֳɻá¼ûµÚÈý·½ÔÆCRMϵͳ²¢ÏÂÔØÊý¾Ý¿â¡£Ð¹Â¶Êý¾Ý°üÀ¨¿Í»§µç×ÓÓʼþ¡¢ÐÕÃû¡¢ÐԱ𡢳öÉúÈÕÆÚ¡¢µç»°ºÅÂë¼°ÏÖʵµØµãµÈÃô¸ÐÐÅÏ¢£¬²¿·Ö°²ÁªÔ±¹¤Ò²Êܲ¨¼°¡£Ö»¹Ü°²ÁªÎ´¹ûÕæ±»ÈëÇÖµÄÔÆCRMÌṩÉÌÃû³Æ£¬µ«BleepingComputerÈ·Èϴ˴ι¥»÷ÓëShinyHuntersÖ±½ÓÏà¹Ø£¬¸Ã×éÖ¯ËæºóÔÚйÃÜÍøÕ¾Ðû²¼Ô¼280ÍòÌõÀ´×Ô°²Áª¼°ÆäËûÆóÒµµÄÊý¾Ý¼Í¼£¬°üÀ¨²Æ²úÖÎÀí¹«Ë¾¡¢²ÆÎñÕÕÁϵÈÏàÖúͬ°éÐÅÏ¢¡£Êý¾Ýй¶֪ͨ·þÎñHave I Been PwnedµÄ±¨¸æ½øÒ»²½Ö¤ÊµÁËÊÂÎñµÄÑÏÖØÐÔ£¬110Íò°²Áª¿Í»§ÐÅÏ¢ÒÑÁ÷ÈëºÚÊУ¬²¿·ÖÊܺ¦Õß·´Ïìй¶ÎļþÖеÄ˰ºÅ¡¢µç»°ºÅÂëµÈÊý¾Ý׼ȷÎÞÎó¡£
https://www.bleepingcomputer.com/news/security/massive-allianz-life-data-breach-impacts-11-million-people/


¾©¹«Íø°²±¸11010802024551ºÅ