¶íÂÞ˹ColdriverºÚ¿Í×éÖ¯°²ÅÅÐÂÐÍNoRobot¶ñÒâÈí¼þ
Ðû²¼Ê±¼ä 2025-10-231. ¶íÂÞ˹ColdriverºÚ¿Í×éÖ¯°²ÅÅÐÂÐÍNoRobot¶ñÒâÈí¼þ
10ÔÂ21ÈÕ£¬¹È¸èÍþвÇ鱨ÍŶӣ¨GTIG£©Ðû²¼±¨¸æ£¬½ÒÆÆÓë¶íÂÞ˹Áª°îÇå¾²¾Ö£¨FSB£©¹ØÁªµÄºÚ¿Í×éÖ¯Coldriver£¨ÓÖÃûStar Blizzard¡¢CallistoµÈ£©°²ÅÅÁËÒ»Ì×ÐÂÐͶñÒâÈí¼þ£¬È¡´úÆä2025Äê5Ô±»Åû¶µÄÖ÷Á¦¹¤¾ßLostKeys¡£¸Ã×éÖ¯×Ô2017ÄêÆð»îÔ¾£¬ÒÔÕë¶Ô·ÇÕþ¸®×éÖ¯¡¢Ç°Ç鱨¾üÊÂÖ°Ô±¼°±±Ô¼Õþ¸®µÄ¡°Æ¾Ö¤´¹ÂÚ¡±Ìع¤Ô˶¯ÖøÃû£¬Ôø±»Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄÖ¸¿Ø¸ÉÔ¤Ó¢¹úÕþÖΡ£ÐÂÐͶñÒâÈí¼þÓÉNoRobot¡¢YesRobotºÍMaybeRobotÈý¸ö¼Ò×å×é³É£¬¹¥»÷Á´ÒÔ¡°ClickFixÆø¸Å¡±´¹ÂÚÓÕ¶üÆô¶¯£¬Î±ÔìÑéÖ¤ÂëÒ³ÃæÓÕµ¼Óû§Í¨¹ýWindowsÕýµ±¹¤¾ßrundll32.exeÏÂÔØNoRobot DLL£¬Æäµ¼³öº¯ÊýαװΪ¡°humanCheck¡±ÒÔ¹æ±Ü»ùÓھ籾µÄÇå¾²¼à¿Ø¡£NoRobotÔçÆÚ°æ±¾½ÓÄÉ¡°·ÖÔ¿¼ÓÃÜ¡±»úÖÆ£¬²¿·ÖÃÜÔ¿Òþ²ØÔÚ×¢²á±í·¾¶ÖУ¬ÔöÌí½âÃÜÄѶȣ»Ëæºó´Ó¶ñÒâÓòÃû»ñÈ¡Python¾ç±¾£¬½âÃܲ¢Æô¶¯µÚÒ»½×¶ÎºóÃÅYesRobot£¬µ«ÒòÆäÐè×°ÖÃPythonÇéÐÎÁôϺۼ££¬½öʹÓÃÁ½Öܼ´±»ÆúÓá£2025Äê6ÔÂÆð£¬ColdriverתÏò¸üÒþ²ØµÄMaybeRobot£¬»ùÓÚPowerShellµÄºóÃųÌÐò£¬ÇÒÎÞÐèÒÀÀµPython¾ç±¾¡£Í¬ÆÚ£¬¸Ã×éÖ¯ÔÚ¡°¼ò»¯°æ¡±Óë¡°ÖØ´ó°æ¡±Ñ¬È¾Á´¼äƵÈÔÇл»¡£
https://www.infosecurity-magazine.com/news/russian-coldriver-hackers-new/
2. ÐÂ¼ÓÆÂ¹ÙÔ±Éí·ÝÔâ·Âð£¬ÖØ´óͶ×Êթư¸ÆØ¹â
10ÔÂ21ÈÕ£¬ÍøÂçÇå¾²¹«Ë¾Group-IB¿ËÈÕÐû²¼±¨¸æ£¬½ÒÆÆÒ»ÆðÕë¶ÔÐÂ¼ÓÆÂסÃñµÄ´ó¹æÄ£Õ©Æ°¸¼þ¡£Õ©ÆÍÅ»ïͨ¹ý·ÂðÐÂ¼ÓÆÂ×ÜÀí»ÆÑ²Æ¡¢¹ú¼ÒÇ徲ͳ³ï²¿³¤ÉÐĸùµÈ¸ß¼¶¹ÙÔ±Éí·Ý£¬Ê¹ÓþÓÉÑéÖ¤µÄ¹È¸è¹ã¸æ¡¢ÐéαÐÂÎÅÍøÕ¾¼°Éî¶ÈαÔìÊÓÆµ£¬ÓÕµ¼Êܺ¦Õß½øÈëÔÚëÀïÇó˹ע²áµÄÍâ»ãͶ×ÊÆ½Ì¨ÊµÑéÕ©Æ¡£¸ÃÕ©ÆÔ˶¯½ÓÄÉ¡°ÍâµØ»¯¶¨ÏòͶ·Å¡±Õ½ÂÔ£¬½ö¶ÔÐÂ¼ÓÆÂIPµØµãչʾ¹È¸è¹ã¸æ£¬µã»÷ºóÓû§»á±»Ö¸µ¼ÖÁ52ÆäÖÐÐÄÓòÃû£¬×îÖÕÌø×ªÖÁ·ÂðÖ÷Á÷ýÌåµÄÐéÎ±Ò³Ãæ¡£ÕâÐ©Ò³ÃæÐû²¼Éî¶ÈαÔìÊÓÆµ£¬Èç¡°»ÆÑ²Æ×ÜÀí¡±Îª¡°¼´Ê±Ê±´ú¡±ÏîĿվ̨£¬»ò¡°ÉÐĸù²¿³¤¡±ÎªÍ¶×ÊÆ½Ì¨±³Ê飬ÒÔÔöÇ¿¿ÉÐŶȡ£Group-IBÊӲ췢Ã÷£¬Õ©Æ±³ºóÉæ¼°28¸ö¾¹È¸èÑéÖ¤µÄ¹ã¸æÕË»§£¬×¢²áÕß¶àÀ´×Ô±£¼ÓÀûÑÇ¡¢ÂÞÂíÄáÑǵȹú£¬¹²¹ØÁª119¸ö¶ñÒâÓòÃû¡£Îª¹æ±Üî¿Ïµ£¬Õ©Æ·Ö×Ó½ÓÄÉIP¹ýÂË¡¢¿ª·¢Õß¹¤¾ß¼ì²â¼°URL²ÎÊý×èµ²µÈÊÖÒÕ£¬È·±£½öÕæÊµÐÂ¼ÓÆÂÓû§¿É¼ûÕ©ÆÄÚÈÝ¡£Êܺ¦ÕßÌṩÁªÏµ·½·¨ºó£¬»á±»Ê©Ñ¹Í¶×Ê£»ÌáÏÖʱÔòÒÔ¡°ÐÐÕþÁ÷³Ì¡±ÎªÓÉÍÏÑÓ»ò¾Ü¾ø¡£¾Ýͳ¼Æ£¬ÉÏÔ¹²ÓÐ3808ÃûÐÂ¼ÓÆÂÈ˵ã»÷¶ñÒâ¹ã¸æ£¬ÆäÖÐ685È˱»Ö¸µ¼ÖÁÕ©ÆÍøÕ¾¡£
https://www.infosecurity-magazine.com/news/singapore-officials-investment-scam/
3. ΧÀ¸ºÍ³èÎ﹫˾Jewett-CameronÔâÀÕË÷Èí¼þ¹¥»÷
10ÔÂ22ÈÕ£¬×ܲ¿Î»ÓÚ¶íÀÕ¸ÔÖݵÄΧÀ¸¼°³èÎï½â¾ö¼Æ»®ÌṩÉÌJewett-Cameron Company¿ËÈÕÔâÓöÍøÂç¹¥»÷£¬µ¼ÖÂÓªÒµÖÐÖ¹ÓëÃô¸ÐÐÅÏ¢±»µÁ¡£¸Ã¹«Ë¾Ö÷Óª¹·ÎÑ¡¢¹·Áý¡¢Î§À¸¡¢ÌØÖÖľÁϼ°Ô°ÒÕ²úÆ·£¬ÓÚ10ÔÂ15ÈÕ¼ì²âµ½ITÇéÐÎÈëÇÖ£¬ºÚ¿ÍÔÚÆäϵͳÖа²ÅÅÁ˼ÓÃÜºÍ¼à¿ØÈí¼þ£¬Ôì³É²¿·ÖÓªÒµÓ¦ÓÃÎÞ·¨»á¼û£¬ÔËÓªÊÜ×è¡£ÊÓ²ìÏÔʾ£¬¹¥»÷ÊÂÎñÉæ¼°Ë«ÖØÀÕË÷Èí¼þÕ½ÂÔ£¬¼È¼ÓÃÜÎļþÓÖÇÔÈ¡Êý¾Ý¡£ºÚ¿Í»ñÈ¡Á˰üÀ¨ITÐÅÏ¢¡¢²ÆÎñÊý¾Ý¼°ÊÓÆµ¾Û»á¡¢µçÄÔÆÁĻͼÏñµÄÃô¸ÐÄÚÈÝ£¬µ«ÏÖÔÚÎÞÖ¤¾ÝÅú×¢Ô±¹¤¡¢¿Í»§»ò¹©Ó¦É̵ÄСÎÒ˽¼ÒÐÅÏ¢Ôâй¶¡£¹«Ë¾Ç¿µ÷ÈëÇÖÒÑ»ñµÃ¿ØÖÆ£¬ÕýÈ«Á¦»Ö¸´ÊÜÓ°Ïìϵͳ£¬²¢Ô¤¼Æ11ÔÂÖÐÑ®Ðû²¼×èÖ¹½ñÄê8ÔÂ31ÈÕµÄÄê¶È±¨¸æ£¬Ïà¹ØÊý¾ÝÍøÂçÓëÆÊÎöÊÂÇéÒÑÒ»Á¬ÊýÖÜ¡£Jewett-CameronÌåÏÖ£¬ÊÂÎñÏìÓ¦±¾Ç®½«ÓÉÍøÂçÇå¾²°ü¹ÜÁýÕÖ£¬µ«ÈÏ¿ÉÖÐÖ¹¿ÉÄܶÔÔËÓª±¬·¢ÖØ´óÓ°Ïì¡£
https://www.securityweek.com/fencing-and-pet-company-jewett-cameron-hit-by-ransomware/
4. PhantomCaptcha ClickFix¹¥»÷ÎÚ¿ËÀ¼Õ½Õù¾ÈÔ®×éÖ¯
10ÔÂ22ÈÕ£¬¿ËÈÕ£¬Ò»³¡Õë¶ÔÎÚ¿ËÀ¼µØ·½Õþ¸®¼°Õ½Õù¾ÈÔ®Òªº¦×éÖ¯£¨ÈçºìÊ®×Ö¹ú¼ÊίԱ»á¡¢ÍŽá¹ú¶ùͯ»ù½ð»á£©µÄÓã²æÊ½ÍøÂç´¹ÂÚ¹¥»÷"PhantomCaptcha"±¬·¢¡£¸ÃÐж¯Ò»Á¬½öÒ»Ì죬ȴչÏÖÁ˸߶ÈϸÃܵÄÊÖÒÕÁ´Ìõ£º¹¥»÷Õßð³äÎÚ¿ËÀ¼×Üͳ°ì¹«ÊÒ·¢Ëͺ¬¶ñÒâPDFµÄÓʼþ£¬ÓÕµ¼µã»÷αװ³ÉZoomƽ̨µÄ´¹ÂÚÁ´½Ó£¬×îÖÕͨ¹ýαÔìµÄ"ÎÒ²»ÊÇ»úеÈË"CAPTCHAÑé֤ʵÑéClickFix¹¥»÷¡£¹¥»÷Á÷³Ì·ÖΪÈý½×¶Î£ºÊ×ÏÈ£¬Êܺ¦Õßµã»÷ÐéαZoom¾Û»áÁ´½Óºó£¬ä¯ÀÀÆ÷»áÌìÉú¿Í»§¶Ë±êʶ·û²¢Í¨¹ýWebSocketÅþÁ¬ÖÁ¹¥»÷Õß·þÎñÆ÷¡£Èô±êʶ·ûÆ¥Å䣬Óû§½«±»Öض¨ÏòÖÁÕýµ±Zoom¾Û»á¾ÙÐÐʵʱÉç»á¹¤³Ì¹¥»÷£»Èô²»Æ¥Å䣬ÔòÐèÍê³ÉÎÚ¿ËÀ¼ÓïµÄαÔìCAPTCHAÑéÖ¤£¬Í¨¹ý¸´ÖÆÕ³Ìù"ÁîÅÆ"Ö´ÐÐPowerShellÏÂÁÏÂÔØ²¢ÔËÐжñÒâ¾ç±¾"cptch"¡£¸Ã¾ç±¾»áÍøÂçϵͳÐÅÏ¢²¢»Ø´«ÖÁC2·þÎñÆ÷£¬×îÖÕ°²ÅÅÇáÁ¿¼¶WebSocketÔ¶³Ì»á¼ûľÂí£¨RAT£©£¬ÊµÏÖÔ¶³ÌÏÂÁîÖ´ÐÐÓëÊý¾Ýй¶¡£ÊÖÒÕËÝÔ´Ö¸Ïò¶íϵÍþв×éÖ¯£ºWebSocket RATÍйÜÓÚ¶íÂÞ˹»ù´¡ÉèÊ©£¬³ÉÈËÖ÷Ìâ¹¥»÷¹¤¾ßÓë¶í/°×¶íÂÞ˹¿ª·¢±£´æ¹ØÁª¡£
https://www.bleepingcomputer.com/news/security/phantomcaptcha-clickfix-attack-targets-ukraine-war-relief-orgs/
5. Adobe Commerce SessionReaperÎó²îÔâ´ó¹æÄ£¹¥»÷
10ÔÂ22ÈÕ£¬AdobeÓÚ9ÔÂ8ÈÕÕë¶ÔÆìÏÂCommerceƽ̨£¨ÔMagento£©Ðû²¼½ôÆÈÇå¾²ÖÒÑÔ£¬Ö¸³ö±£´æÒ»¸ö±»ÃüÃûΪSessionReaper£¨CVE-2025-54236£©µÄÑÏÖØ²»µ±ÊäÈëÑéÖ¤Îó²î¡£¸ÃÎó²îÓ°Ïì2.4.9-alpha2¡¢2.4.8-p2µÈ¶à¸ö°æ±¾¼°¸üÔç°æ±¾£¬¹¥»÷ÕßÎÞÐèÓû§½»»¥¼´¿Éͨ¹ýCommerce REST API½ÓÊܿͻ§ÕË»§£¬ÊµÏÖÍêÈ«¿ØÖƻỰȨÏÞ¡£µç×ÓÉÌÎñÇå¾²¹«Ë¾SansecËæºó֤ʵ£¬¸ÃÎó²îÒѱ»ÊÓΪAdobe CommerceÀúÊ·ÉÏ×îÑÏÖØµÄÇå¾²Îó²îÖ®Ò»£¬²¢ÔÚ½ôÆÈ²¹¶¡Ðû²¼Ô¼ÁùÖܺó½øÈë»îԾʹÓý׶Ρ£Sansec¼à²âÊý¾ÝÏÔʾ£¬×Ô²¹¶¡Ðû²¼ÒÔÀ´£¬ÒѼͼÊý°Ù´ÎÕë¶ÔδÐÞ¸´ÊÐËÁµÄ¹¥»÷ʵÑé¡£½öÔÚ×î½üÒ»´ÎÊÓ²ìÖУ¬Sansec Shieldϵͳ¾Í×èµ²ÁËÀ´×ÔÎå¸öIPµØµãµÄ250Óà´Î¹¥»÷£¬¹¥»÷ÊֶΰüÀ¨Ö²ÈëPHP webshell»òÖ´ÐÐphpinfo̽²âÒÔÍøÂçϵͳÉèÖÃÐÅÏ¢¡£ÖµµÃ×¢ÖØµÄÊÇ£¬62%µÄMagentoÔÚÏßÊÐËÁÉÐδװÖÃAdobeµÄÇå¾²¸üУ¬Îå·ÖÖ®ÈýµÄÊÐËÁÈÔ̻¶ÔÚΣº¦ÖС£SansecÑо¿Ö°Ô±Ö¸³ö£¬Îó²îʹÓõĻîÔ¾¶ÈÓëSearchlight CyberÐû²¼µÄÊÖÒÕÆÊÎö±¨¸æ±£´æ¹ØÁª£¬¸Ã±¨¸æ¿ÉÄܽøÒ»²½´Ì¼¤Á˹¥»÷ʵÑéµÄÔöÌí¡£
https://www.bleepingcomputer.com/news/security/hackers-exploiting-critical-sessionreaper-flaw-in-adobe-magento/
6. ÒÁÀÊMuddyWater°²ÅÅPhoenix v4ºóÃÅÇÔÈ¡Õþ¸®Êý¾Ý
10ÔÂ22ÈÕ£¬ÒÁÀÊÕþ¸®Ö§³ÖµÄMuddyWaterºÚ¿Í×éÖ¯£¨ÓÖÃûStatic Kitten¡¢Mercury¡¢Seedworm£©½üÆÚÕë¶ÔÖж«¼°±±·ÇµØÇø100Óà¸öÕþ¸®ÊµÌåÌᳫ¹¥»÷£¬Ä¿µÄ°üÀ¨´óʹ¹Ý¡¢Í⽻ʹÍÅ¡¢ÁìʹݵȽ¹µã»ú¹¹¡£´Ë´Î¹¥»÷×Ô2025Äê8ÔÂ19ÈÕÆð£¬Í¨¹ýNordVPN»á¼ûÊÜѬȾÕË»§ÊµÑéÍøÂç´¹ÂÚ£¬ÏòÄ¿µÄ·¢Ëͺ¬¶ñÒâWordÎĵµµÄÓʼþ£¬ÓÕÆÓû§ÆôÓúê´úÂëÒÔ½âÂ벢дÈëFakeUpdate¶ñÒâÈí¼þ¼ÓÔØ³ÌÐòÖÁ´ÅÅÌ¡£Group-IB±¨¸æÖ¸³ö£¬8ÔÂ24ÈÕ¹¥»÷Õ߹رշþÎñÆ÷¼°C2×é¼þ£¬¿ÉÄܽøÈëн׶Σ¬ÒÀÀµÆäËû¹¤¾ßÍøÂçÐÅÏ¢¡£´Ë´Î°²ÅŵÄPhoenixºóÃŵÚ4°æ£¨v4£©½ÓÄÉAES¼ÓÃÜ£¬Í¨¹ýÐÞ¸ÄWindows×¢²á±í½¨É賤ÆÚÐÔ£¬²¢ÐÂÔö»ùÓÚCOMµÄ³¤ÆÚ»úÖÆ¡£¸ÃºóÃÅÖ§³Ö65-85ºÅÏÂÁ£¬º¸Ç˯Ãß¡¢ÎļþÉÏ´«/ÏÂÔØ¡¢Æô¶¯shell¼°µ÷½âÂÖѯ¾àÀëµÈ¹¦Ð§£¬¿ÉÍøÂçϵͳÐÅÏ¢²¢Í¨¹ýWinHTTPÅþÁ¬C2·þÎñÆ÷¡£±ðµÄ£¬¹¥»÷ÖÐʹÓÃÁË×Ô½ç˵ÐÅÏ¢ÇÔÈ¡³ÌÐò£¬Õë¶Ôä¯ÀÀÆ÷Êý¾Ý¿âÌáȡƾ֤¼°Ö÷ÃÜÔ¿¡£Group-IB»¹·¢Ã÷MuddyWaterÔÚC2»ù´¡ÉèÊ©Öа²ÅÅÁËPDQÈí¼þ°²Åʤ¾ß¼°Action1 RMMÔ¶³ÌÖÎÀí¹¤¾ß£¬ÕâЩ¹¤¾ß´ËÇ°ÔøÔÚÒÁÀʺڿ͹¥»÷Öб»Ê¹Óá£
https://www.bleepingcomputer.com/news/security/iranian-hackers-targeted-over-100-govt-orgs-with-phoenix-backdoor/


¾©¹«Íø°²±¸11010802024551ºÅ