¶íÂÞ˹ColdriverºÚ¿Í×éÖ¯²¿ÊðÐÂÐÍNoRobot¶ñÒâÈí¼þ

°ä²¼¹¦·ò 2025-10-23

1. ¶íÂÞ˹ColdriverºÚ¿Í×éÖ¯²¿ÊðÐÂÐÍNoRobot¶ñÒâÈí¼þ


10ÔÂ21ÈÕ £¬¹È¸èÍþвµý±¨ÍŶӣ¨GTIG£©°ä²¼»ã±¨ £¬¸æ·¢Óë¶íÂÞ˹Áª°î°²È«¾Ö£¨FSB£©¹ØÁªµÄºÚ¿Í×éÖ¯Coldriver£¨±ðºÅStar Blizzard¡¢¡¢CallistoµÈ£©²¿ÊðÁËÒ»Ì×ÐÂÐͶñÒâÈí¼þ £¬È¡´úÆä2025Äê5Ô±»Åû¶µÄÖ÷Á¦¹¤¾ßLostKeys¡£¡£¡£¸Ã×éÖ¯×Ô2017ÄêÆð»îÔ¾ £¬ÒÔÕë¶Ô·Çµ±¾Ö×éÖ¯¡¢¡¢Ç°µý±¨¾üÊÂÈËÔ±¼°±±Ô¼µ±¾ÖµÄ¡°Æ¾Ö¤´¹µö¡±¼äµý»î¶¯ÎÅÃû £¬Ôø±»Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄÖ¸¿Ø¹ýÎÊÓ¢¹úÕþÖΡ£¡£¡£ÐÂÐͶñÒâÈí¼þÓÉNoRobot¡¢¡¢YesRobotºÍMaybeRobotÈý¸ö¼Ò×å×é³É £¬¹¥»÷Á´ÒÔ¡°ClickFix·ç¸ñ¡±´¹µöµö¶üÆô¶¯ £¬Î±ÔìÑéÖ¤ÂëÒ³ÃæÓÕµ¼Óû§Í¨¹ýWindowsºÏ·¨¹¤¾ßrundll32.exeÏÂÔØNoRobot DLL £¬Æäµ¼³öº¯Êý¼ÙװΪ¡°humanCheck¡±ÒÔ¶ã±Ü»ùÓھ籾µÄ°²È«¼à¿Ø¡£¡£¡£NoRobotÔçÆÚ°æ±¾Ñ¡È¡¡°·ÖÔ¿¼ÓÃÜ¡±»úÖÆ £¬²¿ÃÅÃÜÔ¿°µ²ØÔÚ×¢²á±íõè¾¶ÖÐ £¬Ôö³¤½âÃÜÄѶÈ£»Ëæºó´Ó¶ñÒâÓòÃû»ñÈ¡Python¾ç±¾ £¬½âÃܲ¢Æô¶¯µÚÒ»½×¶ÎºóÃÅYesRobot £¬µ«ÒòÆäÐè×°ÖÃPython»·¾³ÁôϺۼ£ £¬½öʹÓÃÁ½Öܼ´±»ÆúÓᣡ£¡£2025Äê6ÔÂÆð £¬ColdriverתÏò¸üÒñ±ÎµÄMaybeRobot £¬»ùÓÚPowerShellµÄºóÃÅ·¨Ê½ £¬ÇÒÎÞÐèÒÀÀµPython¾ç±¾¡£¡£¡£Í¬ÆÚ £¬¸Ã×éÖ¯ÔÚ¡°¼ò»¯°æ¡±Óë¡°¸´ÔӰ桱ϰȾÁ´¼äƵÈÔÇл»¡£¡£¡£


https://www.infosecurity-magazine.com/news/russian-coldriver-hackers-new/


2. ÐÂ¼ÓÆÂ¹ÙÔ±Éí·ÝÔâ·Â𠣬¸´ÔÓͶ×ÊÚ¿Æ­°¸ÆØ¹â


10ÔÂ21ÈÕ £¬ÍøÂ簲ȫ¹«Ë¾Group-IB½üÈÕ°ä²¼»ã±¨ £¬¸æ·¢Ò»Â·Õë¶ÔÐÂ¼ÓÆÂ¾ÓÃñµÄ´ó¹æÄ£Ú¿Æ­°¸¼þ¡£¡£¡£Ú¿Æ­ÍÅ»ïͨ¹ý·ÂðÐÂ¼ÓÆÂ×ÜÀí»ÆÑ­²Æ¡¢¡¢¹ú¶È°²È«Á½È«¾Ö³¤ÉÐĸùµÈ¸ß¼¶¹ÙÔ±Éí·Ý £¬ÀûÓþ­¹ýÑéÖ¤µÄ¹È¸è¸æ°×¡¢¡¢ÐéαÐÂÎÅÍøÕ¾¼°Éî¶ÈαÔìÊÓÆµ £¬ÓÕµ¼Êܺ¦Õß½øÈëÔÚëÀïÇó˹ע²áµÄÍâ»ãͶ×ÊÆ½Ì¨Ö´ÐÐÚ¿Æ­¡£¡£¡£¸ÃÚ¿Æ­»î¶¯Ñ¡È¡¡°±¾µØ»¯¶¨ÏòͶ·Å¡±Õ½Êõ £¬½ö¶ÔÐÂ¼ÓÆÂIPµØÖ·Õ¹Ê¾¹È¸è¸æ°× £¬µã»÷ºóÓû§»á±»Êèµ¼ÖÁ52¸öÖÐÑëÓòÃû £¬×îÖÕÌø×ªÖÁ·ÂðÖ÷Á÷ýÌåµÄÐéÎ±Ò³Ãæ¡£¡£¡£ÕâÐ©Ò³Ãæ°ä²¼Éî¶ÈαÔìÊÓÆµ £¬Èç¡°»ÆÑ­²Æ×ÜÀí¡±Îª¡°¼´²»¶Ï´ú¡±ÏîĿվ̨ £¬»ò¡°ÉÐĸù²¿³¤¡±ÎªÍ¶×ÊÆ½Ì¨±³Êé £¬ÒÔ¼ÓÇ¿¿ÉÐŶÈ¡£¡£¡£Group-IBµ÷²é·¢ÏÖ £¬Ú¿Æ­±³ºóÉæ¼°28¸ö¾­¹È¸èÑéÖ¤µÄ¸æ°×ÕË»§ £¬×¢²áÕß¶àÀ´×Ô±£¼ÓÀûÑÇ¡¢¡¢ÂÞÂíÄáÑǵȹú £¬¹²¹ØÁª119¸ö¶ñÒâÓòÃû¡£¡£¡£Îª¶ã±Ü¼à¹Ü £¬Ú¿Æ­·Ö×ÓѡȡIP¹ýÂË¡¢¡¢¿ª·¢Õß¹¤¾ß¼ì²â¼°URL²ÎÊýÀ¹½ØµÈ¼¼Êõ £¬È·±£½öÕæÊµÐÂ¼ÓÆÂÓû§¿É¼ûÚ¿Æ­ÄÚÈÝ¡£¡£¡£Êܺ¦ÕßÌṩÁªÏµ·½Ê½ºó £¬»á±»Ê©Ñ¹Í¶×Ê£»ÌáÏÖʱÔòÒÔ¡°ÐÐÕþÁ÷³Ì¡±ÎªÓɳÙÑÓ»ò»Ø¾ø¡£¡£¡£¾Ýͳ¼Æ £¬ÉÏÔ¹²ÓÐ3808ÃûÐÂ¼ÓÆÂÈ˵ã»÷¶ñÒâ¸æ°× £¬ÆäÖÐ685È˱»Êèµ¼ÖÁÚ¿Æ­ÍøÕ¾¡£¡£¡£


https://www.infosecurity-magazine.com/news/singapore-officials-investment-scam/


3. ΧÀ¸ºÍ³èÎ﹫˾Jewett-CameronÔâÀÕË÷Èí¼þ¹¥»÷


10ÔÂ22ÈÕ £¬×ܲ¿Î»ÓÚ¶íÀÕ¸ÔÖݵÄΧÀ¸¼°³èÎï½â¾ö¹æ»®ÌṩÉÌJewett-Cameron Company½üÈÕÔâ·êÍøÂç¹¥»÷ £¬µ¼ÖÂÒµÎñÖжÏÓëÃô¸ÐÐÅÏ¢±»µÁ¡£¡£¡£¸Ã¹«Ë¾Ö÷Óª¹·ÎÑ¡¢¡¢¹·Áý¡¢¡¢Î§À¸¡¢¡¢ÌØÖÖľ²Ä¼°Ô°ÒÕ²úÆ· £¬ÓÚ10ÔÂ15ÈÕ¼ì²âµ½IT»·¾³ÈëÇÖ £¬ºÚ¿ÍÔÚÆäϵͳÖв¿ÊðÁ˼ÓÃÜºÍ¼à¿ØÈí¼þ £¬Ôì³É²¿ÃÅÒµÎñÀûÓÃÎÞ·¨½Ó¼û £¬ÔËÓªÅö±Ú¡£¡£¡£µ÷²éÏÔʾ £¬¹¥»÷ÊÂÎñÉæ¼°Ë«ÖØÀÕË÷Èí¼þÕ½Êõ £¬¼È¼ÓÃÜÎļþÓÖÇÔÈ¡Êý¾Ý¡£¡£¡£ºÚ¿Í»ñÈ¡ÁËÔ̺¬ITÐÅÏ¢¡¢¡¢²ÆÕþÊý¾Ý¼°ÊÓÆµ»áÒé¡¢¡¢µçÄÔÆÁĻͼÏñµÄÃô¸ÐÄÚÈÝ £¬µ«Ä¿Ç°ÎÞÖ¤¾ÝÅú×¢Ô±¹¤¡¢¡¢¿Í»§»ò¹©¸øÉ̵ÄСÎÒÐÅÏ¢Ôâй¶¡£¡£¡£¹«Ë¾Ç¿µ÷ÈëÇÖÒѵõ½½ÚÖÆ £¬ÕýÈ«Á¦¸´Ô­ÊÜÓ°Ïìϵͳ £¬²¢Ô¤¼Æ11ÔÂÖÐÑ®°ä²¼½ØÖÁ½ñÄê8ÔÂ31ÈÕµÄÄê¶È»ã±¨ £¬ÓйØÊý¾ÝÍøÂçÓë·ÖÎö¹¤×÷ÒѳÖÐøÊýÖÜ¡£¡£¡£Jewett-Cameron°µÊ¾ £¬ÊÂÎñÏìÓ¦³É±¾½«ÓÉÍøÂ簲ȫ±£ÏÕ¸²¸Ç £¬µ«ÈÏ¿ÉÖжϿÉÄܶÔÔËÓª²úÉúÖØ´óÓ°Ïì¡£¡£¡£


https://www.securityweek.com/fencing-and-pet-company-jewett-cameron-hit-by-ransomware/


4. PhantomCaptcha ClickFix¹¥»÷ÎÚ¿ËÀ¼Õ½Õù½Ó¼Ã×éÖ¯


10ÔÂ22ÈÕ £¬½üÈÕ £¬Ò»³¡Õë¶ÔÎÚ¿ËÀ¼´¦Ëùµ±¾ÐİսÕù½Ó¼Ã¹Ø¼ü×éÖ¯£¨ÈçºìÊ®×Ö¹ú¼ÊίԱ»á¡¢¡¢½áºÏ¹ú¶ùͯ»ù½ð»á£©µÄÓã²æÊ½ÍøÂç´¹µö¹¥»÷"PhantomCaptcha"·¢×÷¡£¡£¡£¸ÃÐж¯³ÖÐø½öÒ»Ìì £¬È´Õ¹Ê¾Á˸߶Ⱦ«Ãܵļ¼ÊõÁ´Ìõ£º¹¥»÷Õß¼ÙÒâÎÚ¿ËÀ¼×Üͳ°ì¹«ÊÒ·¢Ëͺ¬¶ñÒâPDFµÄÓʼþ £¬ÓÕµ¼µã»÷¼Ù×°³ÉZoomƽ̨µÄ´¹µöÁ´½Ó £¬×îÖÕͨ¹ýαÔìµÄ"ÎÒ²»ÊÇ»úеÈË"CAPTCHAÑéÖ¤Ö´ÐÐClickFix¹¥»÷¡£¡£¡£¹¥»÷Á÷³Ì·ÖΪÈý½×¶Î£ºÊ×ÏÈ £¬Êܺ¦Õßµã»÷ÐéαZoom»áÒéÁ´½Óºó £¬ä¯ÀÀÆ÷»áÌìÉú¿Í»§¶Ë±êʶ·û²¢Í¨¹ýWebSocketÏνÓÖÁ¹¥»÷Õß·þÎñÆ÷¡£¡£¡£Èô±êʶ·ûÆ¥Åä £¬Óû§½«±»Öض¨ÏòÖÁºÏ·¨Zoom»áÒé½øÐÐʵʱÉç»á¹¤³Ì¹¥»÷£»Èô²»Æ¥Åä £¬ÔòÐèʵÏÖÎÚ¿ËÀ¼ÓïµÄαÔìCAPTCHAÑéÖ¤ £¬Í¨¹ý¸´ÖÆÕ³Ìù"ÁîÅÆ"Ö´ÐÐPowerShellºÅÁî £¬ÏÂÔØ²¢ÔËÐжñÒâ¾ç±¾"cptch"¡£¡£¡£¸Ã¾ç±¾»áÍøÂçϵͳÐÅÏ¢²¢»Ø´«ÖÁC2·þÎñÆ÷ £¬×îÖÕ²¿ÊðÇáÁ¿¼¶WebSocketÔ¶³Ì½Ó¼ûľÂí£¨RAT£© £¬ÊµÏÖÔ¶³ÌºÅÁîÖ´ÐÐÓëÊý¾Ýй¶¡£¡£¡£¼¼ÊõËÝÔ´Ö¸Ïò¶íϵÍþв×éÖ¯£ºWebSocket RATÍйÜÓÚ¶íÂÞ˹»ù´¡ÉèÊ© £¬³ÉÈËÖ÷Ìâ¹¥»÷¹¤¾ßÓë¶í/°×¶íÂÞ˹¿ª·¢´æÔÚ¹ØÁª¡£¡£¡£


https://www.bleepingcomputer.com/news/security/phantomcaptcha-clickfix-attack-targets-ukraine-war-relief-orgs/


5. Adobe Commerce SessionReaper·ì϶Ôâ´ó¹æÄ£¹¥»÷


10ÔÂ22ÈÕ £¬AdobeÓÚ9ÔÂ8ÈÕÕë¶ÔÆìÏÂCommerceƽ̨£¨Ô­Magento£©°ä²¼´¹Î£°²È«ÖÒ¸æ £¬Ö¸³ö´æÔÚÒ»¸ö±»¶¨ÃûΪSessionReaper£¨CVE-2025-54236£©µÄÑÏÖØ²»µ±ÊäÈëÑéÖ¤·ì϶¡£¡£¡£¸Ã·ì϶ӰÏì2.4.9-alpha2¡¢¡¢2.4.8-p2µÈ¶à¸ö°æ±¾¼°¸üÔç°æ±¾ £¬¹¥»÷ÕßÎÞÐèÓû§½»»¥¼´¿Éͨ¹ýCommerce REST APIÊÕÊܿͻ§ÕË»§ £¬ÊµÏÖÆëÈ«½ÚÖÆ»á»°È¨ÏÞ¡£¡£¡£µç×ÓÉÌÎñ°²È«¹«Ë¾SansecËæºó֤ʵ £¬¸Ã·ì϶Òѱ»ÊÓΪAdobe Commerceº¹ÇàÉÏ×îÑÏÖØµÄ°²È«·ì϶֮һ £¬²¢ÔÚ´¹Î£²¹¶¡°ä²¼Ô¼ÁùÖܺó½øÈë»îÔ¾ÀûÓý׶Ρ£¡£¡£Sansec¼à²âÊý¾ÝÏÔʾ £¬×Ô²¹¶¡°ä²¼ÒÔÀ´ £¬ÒѼͼÊý°Ù´ÎÕë¶ÔδÐÞ¸´É̵êµÄ¹¥»÷³¢ÊÔ¡£¡£¡£½öÔÚ×î½üÒ»´Î¹Û²âÖÐ £¬Sansec Shieldϵͳ¾ÍÀ¹½ØÁËÀ´×ÔÎå¸öIPµØÖ·µÄ250Óà´Î¹¥»÷ £¬¹¥»÷¼¿Á©Ô̺¬Ö²ÈëPHP webshell»òÖ´ÐÐphpinfo̽²âÒÔÍøÂçϵͳÅäÏàÐÅÏ¢¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ £¬62%µÄMagentoÔÚÏßÉ̵êÉÐδװÖÃAdobeµÄ°²È«¸üР£¬Îå·ÖÖ®ÈýµÄÉ̵êÈÔ¶³öÔÚ·çÏÕÖС£¡£¡£Sansec×êÑÐÈËÔ±Ö¸³ö £¬·ì϶ÀûÓõĻîÔ¾¶ÈÓëSearchlight Cyber°ä²¼µÄ¼¼Êõ·ÖÎö»ã±¨´æÔÚ¹ØÁª £¬¸Ã»ã±¨¿ÉÄܽøÒ»²½´Ì¼¤Á˹¥»÷³¢ÊÔµÄÔö³¤¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-exploiting-critical-sessionreaper-flaw-in-adobe-magento/


6. ÒÁÀÊMuddyWater²¿ÊðPhoenix v4ºóÃÅÇÔÈ¡µÐÔÖÊý¾Ý


10ÔÂ22ÈÕ £¬ÒÁÀʵ±¾ÖÖ§³ÖµÄMuddyWaterºÚ¿Í×éÖ¯£¨±ðºÅStatic Kitten¡¢¡¢Mercury¡¢¡¢Seedworm£©½üÆÚÕë¶ÔÖж«¼°±±·ÇµØÓò100Óà¸öµÐÔÖʵÌåÌáÒé¹¥»÷ £¬Ö¸±êÔ̺¬´óʹ¹Ý¡¢¡¢Í⽻ʹÍÅ¡¢¡¢ÁìʹݵÈÖ÷Ìâ˼¹¹¡£¡£¡£Õâ´Î¹¥»÷×Ô2025Äê8ÔÂ19ÈÕÆð £¬Í¨¹ýNordVPN½Ó¼ûÊÜϰȾÕË»§Ö´ÐÐÍøÂç´¹µö £¬ÏòÖ¸±ê·¢Ëͺ¬¶ñÒâWordÎĵµµÄÓʼþ £¬ÓÕÆ­Óû§ÆôÓúê´úÂëÒÔ½âÂ벢дÈëFakeUpdate¶ñÒâÈí¼þ¼ÓÔØ·¨Ê½ÖÁ´ÅÅÌ¡£¡£¡£Group-IB»ã±¨Ö¸³ö £¬8ÔÂ24ÈÕ¹¥»÷Õ߹رշþÎñÆ÷¼°C2×é¼þ £¬¿ÉÄܽøÈëн׶Π£¬ÒÀÀµÆäËû¹¤¾ßÍøÂçÐÅÏ¢¡£¡£¡£Õâ´Î²¿ÊðµÄPhoenixºó¼ÒÊÀ4°æ£¨v4£©Ñ¡È¡AES¼ÓÃÜ £¬Í¨¹ýÅú¸ÄWindows×¢²á±í³ÉÁ¢ÓƾÃÐÔ £¬²¢ÐÂÔö»ùÓÚCOMµÄÓÆ¾Ã»úÖÆ¡£¡£¡£¸ÃºóÃÅÖ§³Ö65-85ºÅºÅÁ £¬º­¸Ç˯Ãß¡¢¡¢ÎļþÉÏ´«/ÏÂÔØ¡¢¡¢Æô¶¯shell¼°µ÷ÕûÂÖѯ¾àÀëµÈÖ°ÄÜ £¬¿ÉÍøÂçϵͳÐÅÏ¢²¢Í¨¹ýWinHTTPÏνÓC2·þÎñÆ÷¡£¡£¡£´ËÍâ £¬¹¥»÷ÖÐʹÓÃÁË×Ô½ç˵ÐÅÏ¢ÇÔÈ¡·¨Ê½ £¬Õë¶Ôä¯ÀÀÆ÷Êý¾Ý¿âÌáȡʹ´¦¼°Ö÷ÃÜÔ¿¡£¡£¡£Group-IB»¹·¢ÏÖMuddyWaterÔÚC2»ù´¡ÉèÊ©Öв¿ÊðÁËPDQÈí¼þ²¿Ê𹤾߼°Action1 RMMÔ¶³ÌÖÎÀí¹¤¾ß £¬ÕâЩ¹¤¾ß´ËÇ°ÔøÔÚÒÁÀʺڿ͹¥»÷Öб»Ê¹Óᣡ£¡£


https://www.bleepingcomputer.com/news/security/iranian-hackers-targeted-over-100-govt-orgs-with-phoenix-backdoor/