ÍøÂç·¸·¨·Ö×ÓÃé×¼AWSÇéÐΣ¬£¬£¬Ê¹ÓÃÉèÖùýÊ§ÍÆËÍ´¹Âڻ
Ðû²¼Ê±¼ä 2025-03-041. ÍøÂç·¸·¨·Ö×ÓÃé×¼AWSÇéÐΣ¬£¬£¬Ê¹ÓÃÉèÖùýÊ§ÍÆËÍ´¹Âڻ
3ÔÂ3ÈÕ£¬£¬£¬¾ÝPalo Alto Networks Unit 42µÄÊӲ죬£¬£¬ÍøÂç·¸·¨·Ö×ÓÕýÕë¶ÔÑÇÂíÑ·ÍøÂçЧÀÍ£¨AWS£©ÇéÐΣ¬£¬£¬ÏòÄ¿µÄÍÆËÍÍøÂç´¹Âڻ¡£¡£¡£¡£Ò»¸öÃûΪTGR-UNK-0011µÄ»î¶¯¼¯Èº£¨ÓëJavaGhost×éÖ¯ÓÐÖØµþ£©×Ô2019ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬ÀúÊ·ÉÏרעÓÚÍøÕ¾¸Ä¶¯£¬£¬£¬µ«×Ô2022ÄêÆðתÏò·¢ËÍÍøÂç´¹ÂÚÓʼþÒÔıȡ¾¼ÃÀûÒæ¡£¡£¡£¡£ÕâЩ¹¥»÷²¢Î´Ê¹ÓÃAWSÎó²î£¬£¬£¬¶øÊÇʹÓÃÊܺ¦ÕßÇéÐÎÖÐAWS»á¼ûÃÜÔ¿µÄÉèÖùýʧ£¬£¬£¬Í¨¹ýÀÄÓÃSESºÍWorkMailЧÀÍ·¢ËÍ´¹ÂÚÐÂÎÅ£¬£¬£¬´Ó¶øÈƹýµç×ÓÓʼþ±£»£»£»£»£»¤¡£¡£¡£¡£¹¥»÷ÕßÒ»µ©»ñµÃ¶ÔAWSÕË»§µÄ»á¼ûȨÏÞ£¬£¬£¬¾Í»áÌìÉúÔÝʱƾ֤ºÍµÇ¼URL£¬£¬£¬Òþ²ØÉí·Ý²¢Éó²éÕË»§×ÊÔ´¡£¡£¡£¡£ËûÃÇ»¹Ê¹ÓÃSESºÍWorkMail½¨Éè´¹ÂÚ»ù´¡ÉèÊ©£¬£¬£¬½¨ÉèÐÂÓû§²¢ÉèÖÃSMTPƾ֤·¢ËÍÓʼþ¡£¡£¡£¡£JavaGhost½¨ÉèÁ˶àÖÖIAMÓû§£¬£¬£¬ÆäÖÐδʹÓõÄÓû§Ëƺõ×÷Ϊºã¾Ã³¤ÆÚÐÔ»úÖÆ¡£¡£¡£¡£±ðµÄ£¬£¬£¬ËûÃÇ»¹½¨ÉèÁËÒ»¸öÐÂIAM½ÇÉ«£¬£¬£¬ÔÊÐí´ÓÁíÒ»¸ö¿ØÖƵÄAWSÕË»§»á¼ûÄ¿µÄÕË»§¡£¡£¡£¡£Unit 42Ö¸³ö£¬£¬£¬¸Ã×éÖ¯ÔÚ¹¥»÷Àú³ÌÖÐÁôÏÂÏàͬ±ê¼Ç£¬£¬£¬Í¨¹ý½¨ÉèÃûΪJava_GhostµÄEC2Çå¾²×飬£¬£¬×éÐÎòΪ¡°ÎÒÃDZ£´æµ«²»¿É¼û¡±£¬£¬£¬ÕâЩÇå¾²×é²»°üÀ¨ÈκÎÇå¾²¹æÔò¡£¡£¡£¡£
https://thehackernews.com/2025/03/hackers-exploit-aws-misconfigurations.html
2. ÅÁÀÍÎÀÉú²¿Ôâ÷è÷ëÀÕË÷Èí¼þ¹¥»÷ºóѸËÙ»Ö¸´
3ÔÂ4ÈÕ£¬£¬£¬Ì«Æ½Ñ󵺹úÅÁÀ͵ÄÎÀÉú²¿½üÆÚÔâÊÜÁËÒ»´ÎÓÉ×ÅÃû·¸·¨ÍÅ»ïQilinÌᳫµÄÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£´Ë´Î¹¥»÷µ¼ÖÂÅÁÀÍÎÀÉúÓ빫ÖÚЧÀͲ¿£¨MHHS£©µÄITϵͳ±»ÈëÇÖ£¬£¬£¬²¿·ÖÎļþ±»ÇÔÈ¡¡£¡£¡£¡£ÅÁÀ͹ú¼ÒÒ½Ôº×÷Ϊ¸Ã¹úÒªº¦Ò½ÁÆ»ú¹¹£¬£¬£¬ÆäÔËÓªÒò´ËÊܵ½Íþв¡£¡£¡£¡£È»¶ø£¬£¬£¬ÔÚÅÁÀÍ¡¢°Ä´óÀûÑÇÍøÂçÇ徲ר¼ÒºÍ²ÆÎñ²¿¹ÙÔ±µÄÐÖúÏ£¬£¬£¬Õþ¸®Ñ¸ËÙ²éÃ÷ÊÂÎñÕæÏ࣬£¬£¬²¢ÔÚ48СʱÄÚ»Ö¸´ÁËÒ½ÔºµÄÕý³£ÔËÓª¡£¡£¡£¡£Í¬Ê±£¬£¬£¬ÃÀ¹úÍøÂç˾Á¡°Ç°ÑØ·ÀÓù¡±Ð¡×éÒ²ÔÚÏÖ³¡¾ÙÐÐÈ¡Ö¤ÍøÂçºÍÆÊÎö¡£¡£¡£¡£÷è÷ëºÚ¿ÍÍþвҪÐû²¼ÇÔÈ¡µÄÊý¾Ý£¬£¬£¬µ«ÅÁÀ͹ÙÔ±²¢Î´ÊÔͼÐÉÌÊê½ð¡£¡£¡£¡£Ö»¹Ü²¿·Ö±»µÁÐÅÏ¢Òѱ»Ðû²¼£¬£¬£¬°üÀ¨»¼ÕßÕ˵¥ÕªÒªµÈСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬µ«MHHSÒÔΪÕâЩÐÅϢй¶²»»á¶ÔÅÁÀÍСÎÒ˽¼ÒµÄÇå¾²Ôì³ÉÖØ´óÓ°Ï죬£¬£¬µ«ÈÔ½¨ÒéÃñÖÚ¼á³ÖСÐÄ£¬£¬£¬Ìá·ÀDZÔÚµÄڲƺÍÍøÂç´¹ÂÚÓʼþ¡£¡£¡£¡£±ðµÄ£¬£¬£¬÷è÷ëÀÕË÷Èí¼þÍÅ»ï½üÆÚ»¹Õë¶ÔÆäËûÒ½ÁÆ»ú¹¹¡¢µØ·½Õþ¸®ºÍ´óÐ͹«Ë¾Õö¿ªÁ˹¥»÷£¬£¬£¬ÒýÆðÁËÆÕ±é¹Ø×¢¡£¡£¡£¡£
https://therecord.media/palau-health-ministry-ransomware-recover
3. ¼ÙÊÖÒÕÖ§³ÖʹÓõ绰ºÍMicrosoft TeamsÓÕÆÓû§×°ÖÃÀÕË÷Èí¼þ
3ÔÂ3ÈÕ£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢³öÖÒÑÔ£¬£¬£¬Ò»ÖÖеÄȦÌ×ÕýÔÚËÁŰ£¬£¬£¬ÍøÂç·¸·¨·Ö×Ó¼Ù°ç³ÉÊÖÒÕÖ§³ÖÖ°Ô±£¬£¬£¬Í¨¹ý·¢ËÍ´ó×Úµç×ÓÓʼþ²¢Ê¹Óà Microsoft Teams »òµç»°ÓÕÆÊܺ¦ÕߵǼ£¬£¬£¬½ø¶ø»ñȡԶ³Ì»á¼ûȨÏÞ¡£¡£¡£¡£ËûÃÇʹÓÃÕýµ±µÄWindows³ÌÐòQuick AssistÀ´ÌṩԶ³ÌÊÖÒÕÖ§³Ö£¬£¬£¬µ«ÊµÔòÔÚ×°ÖÃÃûΪBackConnectµÄºóÃŶñÒâÈí¼þ£¬£¬£¬Ê¹¹¥»÷ÕßÄܹ»ÍêÈ«¿ØÖÆÊÜѬȾµÄϵͳ¡£¡£¡£¡£ÕâһȦÌ×ÓëÎÛÃûÕÑÖøµÄBlack BastaÀÕË÷Èí¼þ×é֯ϸÃÜÏà¹Ø£¬£¬£¬¸Ã×éÖ¯ÔøÔÚ2024ÄêÒòÀàËÆÊÖ·¨±»±ê¼Ç£¬£¬£¬²¢¾Ý±¨µÀÔÚ2023Äê´ÓÊܺ¦ÕßÄÇÀï׬ȡÁËÁè¼Ý1ÒÚÃÀÔª¡£¡£¡£¡£±ðµÄ£¬£¬£¬Ò»Ð©Black Basta³ÉÔ±ÒѾתÏòCactusÀÕË÷Èí¼þÍŻ£¬£¬×î½üµÄCactus¹¥»÷ÖÐʹÓõÄÒªÁìÓëBlack Basta¾ªÈ˵ØÏàËÆ¡£¡£¡£¡£ÕâЩ¹¥»÷Ö÷ÒªÕë¶Ô±±ÃÀµÄÖÆÔìÒµ¡¢½ðÈÚ¡¢Í¶×Ê×ÉѯºÍ·¿µØ²úÐÐÒµ£¬£¬£¬×Ô2024Äê10ÔÂÒÔÀ´ÓÈΪ»îÔ¾¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÉç½»¹¤³ÌºÍÀÄÓÃÕý°æÈí¼þºÍÔÆÐ§ÀÍÏàÁ¬ÏµµÄ·½·¨£¬£¬£¬Ê¹¶ñÒâÐÐΪ¿´ÆðÀ´ÏñÕý³£µÄÅÌËã»ú»î¶¯¡£¡£¡£¡£ÍøÂçÇå¾²²»µ«ÔÚÓÚÓµÓÐ׼ȷµÄÈí¼þ£¬£¬£¬¸üÔÚÓÚÒâʶµ½·¸·¨·Ö×ÓÔõÑùÊÔͼÓÕÆÈËÃÇ¡£¡£¡£¡£Òò´Ë£¬£¬£¬Microsoft TeamsÓû§Ó¦¼á³ÖСÐÄ£¬£¬£¬×èÖ¹Êܵ½´ËÀàȦÌ×µÄË𺦡£¡£¡£¡£
https://hackread.com/fake-it-support-calls-microsoft-teams-users-install-ransomware/
4. ¶íÂÞ˹µçОÞÍ·BeelineÔÙÔâDDoS¹¥»÷
3ÔÂ3ÈÕ£¬£¬£¬¶íÂÞ˹µçÐŹ«Ë¾BeelineÔâÊÜÁ˶¨ÏòÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©¹¥»÷£¬£¬£¬µ¼Ö²¿·ÖÓû§»¥ÁªÍøÖÐÖ¹£¬£¬£¬ÕâÊǽü¼¸ÖÜÄÚÕë¶Ô¸Ã¹«Ë¾µÄµÚ¶þ´ÎÖØ´ó¹¥»÷¡£¡£¡£¡£´Ë´Î¹¥»÷Ó°ÏìÁËBeelineµÄÒÆ¶¯Ó¦ÓóÌÐò¡¢ÍøÕ¾ºÍ»¥ÁªÍøÐ§ÀÍ£¬£¬£¬Óû§ÔÚ»á¼ûʱÓöµ½ÄÑÌ⣬£¬£¬ÄªË¹¿ÆºÍÖܱߵØÇøµÄÓû§·×·×ͶËßÅþÁ¬ÎÊÌâ¡£¡£¡£¡£BeelineÒѽÓÄɲ½·¥ÎȹÌЧÀÍ£¬£¬£¬µ«Î´Ìṩ¸ü¶àϸ½Ú¡£¡£¡£¡£½ñÄê2Ô£¬£¬£¬BeelineÒ²ÔøÔâÊÜÀàËÆ¹¥»÷£¬£¬£¬µ¼Ö´óÃæ»ýЧÀÍÖÐÖ¹¡£¡£¡£¡£´Ë´Î¹¥»÷Óë1Ô¶íÂÞ˹µçОÞÍ·MegaFonÔâÊܵĹ¥»÷ÏàËÆ£¬£¬£¬¾ùÓÉ´ó¹æÄ£DDoS¹¥»÷Ôì³É£¬£¬£¬±»ÒÔΪÊÇÕë¶ÔµçÐÅÐÐÒµµÄÑÏÖØºÚ¿Í»î¶¯Ö÷ÒåÍøÂç¹¥»÷Ö®Ò»¡£¡£¡£¡£Beeline֮ǰ¹éºÉÀ¼¹«Ë¾VeonËùÓУ¬£¬£¬VeonÔÚÈëÇÖÎÚ¿ËÀ¼ºó×îÏȰþÀëÆä¶íÂÞ˹Ӫҵ¡£¡£¡£¡£´Ë´Î¹¥»÷ÊǶíÂÞ˹µçÐÅÐÐҵһϵÁÐÍøÂçÊÂÎñÖ®Ò»£¬£¬£¬°üÀ¨RostelecomÒÉËÆÔâÊÜÍøÂç¹¥»÷¡¢ÎÚ¿ËÀ¼ÍøÂçͬÃËÉù³Æ¶Ô¶íÂÞ˹»¥ÁªÍøÌṩÉÌNodexµÄ¹¥»÷ÈÏÕæ£¬£¬£¬ÒÔ¼°Rapporto±¨¸æÆä»ù´¡ÉèÊ©ÔâÊÜÍøÂç¹¥»÷µÈ¡£¡£¡£¡£
https://therecord.media/russian-telecom-beeline-outages-cyber
5. еÄClickFix¹¥»÷ͨ¹ýMicrosoft Sharepoint°²ÅÅHavoc¿ò¼Ü
3ÔÂ3ÈÕ£¬£¬£¬Ð·¢Ã÷µÄClickFixÍøÂç´¹ÂڻÓÕÆÊܺ¦ÕßÖ´ÐжñÒâPowerShellÏÂÁ£¬£¬ÒÔ°²ÅÅHavocºóʹÓÿò¼ÜÀ´Ô¶³Ì»á¼ûÊÜѬȾװ±¸¡£¡£¡£¡£ClickFix ÊÇÈ¥Äê·ºÆðµÄÒ»ÖÖÉç»á¹¤³ÌÕ½ÂÔ£¬£¬£¬ÍþвÐÐΪÕßͨ¹ý½¨ÉèÏÔʾÐéα¹ýʧµÄÍøÕ¾»ò¸½¼þ£¬£¬£¬ÌáÐÑÓû§µ¥»÷°´Å¥ÐÞ¸´¹ýʧ¡£¡£¡£¡£µ¥»÷ºó£¬£¬£¬¶ñÒâPowerShellÏÂÁî»á±»¸´ÖƵ½¼ôÌù°å£¬£¬£¬È»ºóÌáÐÑÓû§Õ³Ìùµ½ÏÂÁîÌáÐÑ·ûÖУ¬£¬£¬ÏÖʵÉÏÖ´ÐеÄÊÇÔ¶³ÌÕ¾µãÉϵĶñÒâ¾ç±¾£¬£¬£¬ÏÂÔØ²¢×°ÖöñÒâÈí¼þ¡£¡£¡£¡£ÔÚ×î½üµÄÒ»´ÎClickFix»î¶¯ÖУ¬£¬£¬ÍþвÐÐΪÕßʹÓÃMicrosoftÔÆÐ§ÀÍ£¬£¬£¬·¢ËÍ´¹ÂÚÓʼþÉù³ÆÓС°ÏÞÖÆÍ¨Öª¡±£¬£¬£¬ÓÕʹÓû§·¿ªHTMLÎĵµºóÏÔʾ¼ÙµÄ¹ýʧÌáÐÑ£¬£¬£¬Ö¸µ¼Óû§Ö´ÐÐPowerShellÏÂÁî¡£¡£¡£¡£¸ÃÏÂÁîÆô¶¯ÍйÜÔÚÍþвÐÐΪÕßSharePointЧÀÍÆ÷Éϵľ籾£¬£¬£¬¼ì²é×°±¸ÊÇ·ñÔÚɳºÐÇéÐÎÖУ¬£¬£¬È»ºóÐÞ¸Ä×¢²á±í¡¢×°ÖÃPythonÚ¹ÊÍÆ÷£¬£¬£¬²¢ÏÂÔØ²¢Ö´ÐÐPython¾ç±¾ÒÔ°²ÅÅHavoc¿ò¼Ü¡£¡£¡£¡£Havoc¿ò¼ÜÔÊÐí¹¥»÷ÕßÔ¶³Ì¿ØÖÆ×°±¸£¬£¬£¬Í¨¹ýMicrosoft Graph APIÓëÍþвÐÐΪÕßµÄЧÀÍͨѶ£¬£¬£¬»ìÈëͨÀýÍøÂçͨѶÒÔÌӱܼì²â¡£¡£¡£¡£ClickFix¹¥»÷Ô½À´Ô½ÊܽӴý£¬£¬£¬±»ÓÃÓÚ°²ÅÅÖÖÖÖ¶ñÒâÈí¼þ£¬£¬£¬ÍþвÐÐΪÕß»¹Ò»Ö±Ë¢ÐÂÊÖÒÕ£¬£¬£¬Ê¹ÓÃÉ罻ýÌåÆ½Ì¨ÓÕÆÓû§¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-clickfix-attack-deploys-havoc-c2-via-microsoft-sharepoint/
6. ²¨À¼º½Ìì¾ÖÔâÍøÂç¹¥»÷£¬£¬£¬Ì«¿Õ»ú×é³ÉºÚ¿ÍÐÂÄ¿µÄ
3ÔÂ3ÈÕ£¬£¬£¬²¨À¼º½Ìì¾Ö£¨POLSA£©ÖÜÈÕÐû²¼ÆäÔâÊÜÁËÍøÂç¹¥»÷£¬£¬£¬²¢ÒѶϿªÓ뻥ÁªÍøµÄÅþÁ¬¾ÙÐÐÊӲ죬£¬£¬Í¬Ê±ÆäÍøÕ¾×èÖ¹ÖÜÒ»ÈÔÎÞ·¨»á¼û¡£¡£¡£¡£¹ú¼ÒÍøÂçÇ徲ЧÀͲ¿·ÖÒѼì²âµ½¶ÔPOLSA IT»ù´¡ÉèÊ©µÄδ¾ÊÚȨ»á¼û£¬£¬£¬²¢ÕýÔÚ±£»£»£»£»£»¤ÊÜÓ°ÏìµÄϵͳ£¬£¬£¬Í¬Ê±Æð¾¢Ê¶±ð¹¥»÷Õß¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎú´Ë´Î¹¥»÷ÊÇÓÉÀÕË÷Èí¼þ×éÖ¯ÕÕ¾ÉÕþÖÎÄîÍ·µÄºÚ¿ÍÌᳫ£¬£¬£¬Ò²Î´Í¸Â¶ºÚ¿ÍÈëÇÖϵͳµÄÏêϸϸ½Ú¡£¡£¡£¡£POLSAÊDz¨À¼ÈÏÕæÌ«¿Õ»î¶¯µÄÕþ¸®»ú¹¹£¬£¬£¬Ò²ÊÇÅ·ÖÞº½Ìì¾Ö³ÉÔ±£¬£¬£¬Æä¿ÉÄܳÉΪºÚ¿ÍµÄÓÕÈËÄ¿µÄ£¬£¬£¬ÓÉÓÚÓë¾üʺÍÇ鱨»ú¹¹µÄÏàÖú¿ÉÄÜ̻¶Ãô¸ÐµÄ¹ú·ÀÏà¹ØÐÅÏ¢¡¢ÎÀÐÇÔËÓª»òÉñÃØÑо¿£¬£¬£¬Î£¼°¹ú¼ÒÇå¾²¡£¡£¡£¡£²¨À¼ÒѳÉΪÇ×¶íºÚ¿ÍµÄÖ÷ҪĿµÄ£¬£¬£¬½ñÄêÍøÂç¹¥»÷ÊýÄ¿·±¶£¬£¬£¬Îª´Ë²¨À¼ÒÑͶ×Ê7.6ÒÚÃÀÔªÔöÇ¿ÍøÂçÇå¾²¡£¡£¡£¡£
https://therecord.media/poland-space-cyberattack-agency-investigate


¾©¹«Íø°²±¸11010802024551ºÅ