AI安全专题周报(20260904)

报告编号:TIC-202609-AI01

报告周期:2026年8月29日—9月4日

一、报告概述

基于360威胁情报中心对本期公开网络安全素材的整理与分析,本周AI安全风险主要集中在AI辅助自动化攻击、AI编程与Agent工具链漏洞、模型服务和API密钥滥用、AI辅助恶意软件开发以及AI信任链钓鱼等方向。相关事件显示,AI能力正在加速攻击侦察、攻击规划和漏洞利用适配,同时AI基础设施、代码仓库与云模型资源也成为高价值攻击目标。

报告重点内容涵盖:

· AI辅助攻击与恶意工具开发:攻击者使用AI和智能体框架在不到10小时内完成多阶段勒索攻击,Aurora团伙使用Cursor AI辅助规划,NodeStealer新增AI辅助编写的间谍功能,Claude还被用于跨设备移植工控漏洞利用。

· AI应用与Agent工具链风险:Hermes Agent可因恶意Git配置触发代码执行,LiteLLM漏洞遭在野利用并导致模型配置和API密钥暴露,云端模型资源还面临LLMjacking滥用。

· AI信任链与开发环境风险:银狐通过伪造DeepSeek官网并借助用户对AI输出的信任投递木马,AI搜索与推荐结果、第三方代码库和云凭据需要实施更严格的来源验证。

───────────────────────────────────

二、本周重点安全事件

(一)银狐伪造DeepSeek官网利用AI信任链投递木马

事件名称:银狐借AI信任链钓鱼 搜索结果暗藏下载陷阱

发布日期:2026-09-01

发布机构:火绒安全

威胁概述:

火绒安全披露,银狐团伙伪造DeepSeek官方网站,并利用用户对AI智能体输出结果的信任诱导下载和运行恶意程序。载荷执行后会检测环境、下载后续文件,利用驱动漏洞关闭安全软件并修改注册表关闭UAC,同时通过计划任务和注册表实现持久化,窃取浏览器数据并针对企业微信环境开展定向攻击。

IOC指标:

· Domain:lgtnfx.net, lwuoys.net, eeszuu.com

· IP:8.218.106.149, 8.218.220.211

· IP:Port:92.48.71.103:9000, 92.48.71.103:20032

· URL:https://26usdm.oss-cn-beijing.aliyuncs.com/tad, https://2bbaz2.oss-cn-beijing.aliyuncs.com/tad, https://mm2027.oss-cn-hangzhou.aliyuncs.com/f.dat, https://nm25.cn-hangzhou.aliyuncs.com/qd.dat

STIX详情:

{
  "type": "bundle",
  "id": "bundle--e6aa5455-5e70-4736-a280-1c7def89167a",
  "spec_version": "2.1",
  "objects": [
    {
      "type": "intrusion-set",
      "spec_version": "2.1",
      "id": "intrusion-set--c9887e08-390e-483e-b2eb-42a77c15d5b8",
      "name": "银狐",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "伪造DeepSeek官方网站进行钓鱼攻击的威胁团伙,主要针对企业微信环境发起定向攻击",
      "x_evidence": "原文确认该攻击为银狐团伙伪造DeepSeek官方网站实施的钓鱼活动",
      "x_confidence": 0.97
    },
    {
      "type": "campaign",
      "spec_version": "2.1",
      "id": "campaign--cc14fab9-0d49-4299-b0ad-7c7db9eb841c",
      "name": "伪造的DeepSeek官方网站钓鱼活动",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "银狐团伙开展的伪装DeepSeek官网投递钓鱼诱饵的攻击活动",
      "x_evidence": "原文确认该攻击为银狐团伙伪造DeepSeek官方网站面向用户实施的钓鱼活动",
      "x_confidence": 0.95
    },
    {
      "type": "url",
      "spec_version": "2.1",
      "id": "url--b6350337-ae9e-47d5-89e4-6027cff783a1",
      "name": "https://26usdm.oss-cn-beijing.aliyuncs.com/tad",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "银狐启动载荷下载总览文件的恶意链接",
      "x_evidence": "总览文件下载链接:https://26usdm.oss-cn-beijing.aliyuncs.com/tad",
      "x_confidence": 0.97
    },
    {
      "type": "url",
      "spec_version": "2.1",
      "id": "url--fbf673bd-2831-4ddd-99e7-ae65b3a9ef43",
      "name": "https://2bbaz2.oss-cn-beijing.aliyuncs.com/tad",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "银狐启动载荷下载总览文件的备用恶意链接",
      "x_evidence": "总览文件下载链接:https://2bbaz2.oss-cn-beijing.aliyuncs.com/tad",
      "x_confidence": 0.97
    },
    {
      "type": "url",
      "spec_version": "2.1",
      "id": "url--f97936c8-5f66-4b34-8df6-3d93302958f3",
      "name": "https://mm2027.oss-cn-hangzhou.aliyuncs.com/f.dat",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "解密后的HTTP下载载荷地址,用于获取后续恶意文件",
      "x_evidence": "解密的HTTP下载载荷为:https://mm2027.oss-cn-hangzhou.aliyuncs.com/f.dat",
      "x_confidence": 0.95
    },
    {
      "type": "domain-name",
      "spec_version": "2.1",
      "id": "domain-name--091d75eb-2e80-4ec0-8adc-e425666da185",
      "name": "lgtnfx.net",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "企业微信环境下解密得到的C2备用域名",
      "x_evidence": "企业微信环境:lgtnfx.net lwuoys.net 92.48.71.103:9000 92.48.71.103:20032",
      "x_confidence": 0.96
    },
    {
      "type": "domain-name",
      "spec_version": "2.1",
      "id": "domain-name--a6cbe76c-9f98-4cb9-9f72-7a13b730a1e5",
      "name": "lwuoys.net",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "企业微信环境下解密得到的C2备用域名",
      "x_evidence": "企业微信环境:lgtnfx.net lwuoys.net 92.48.71.103:9000 92.48.71.103:20032",
      "x_confidence": 0.96
    },
    {
      "type": "ipv4-addr",
      "spec_version": "2.1",
      "id": "ipv4-addr--f1a008dc-38cf-443c-b914-a48820bf196b",
      "name": "92.48.71.103:9000",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "针对企业微信环境的独立C2端口",
      "x_evidence": "新增针对企业微信下独立的ip端口以及备用域名:92.48.71.103:9000",
      "x_confidence": 0.95
    },
    {
      "type": "ipv4-addr",
      "spec_version": "2.1",
      "id": "ipv4-addr--8a5b9393-9b7e-46ae-a27e-63cb40d25938",
      "name": "92.48.71.103:20032",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "针对企业微信环境的独立C2端口",
      "x_evidence": "新增针对企业微信下独立的ip端口以及备用域名:92.48.71.103:20032",
      "x_confidence": 0.95
    },
    {
      "type": "url",
      "spec_version": "2.1",
      "id": "url--b9b36d81-006f-40e6-8e88-61a2d0af753a",
      "name": "https://nm25.cn-hangzhou.aliyuncs.com/qd.dat",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "下载被恶意利用的TrueSight驱动文件的链接",
      "x_evidence": "解密字符串得到https://nm25.cn-hangzhou.aliyuncs.com/qd.dat下载替换ranchserv.jpg",
      "x_confidence": 0.94
    },
    {
      "type": "ipv4-addr",
      "spec_version": "2.1",
      "id": "ipv4-addr--4d3595ae-9ab3-4dcf-a8f7-1a9b8e3c707e",
      "name": "8.218.106.149",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "最终载荷回连的默认主C2地址,本次运行因中间载荷覆盖不发生",
      "x_evidence": "回连至c2集合,包括一个主ip 8.218.106.149和一个备用域名eeszuu.com;由于中间载荷覆盖了新的C2,这个ip与备用域名在本次运行不发生",
      "x_confidence": 0.96
    },
    {
      "type": "domain-name",
      "spec_version": "2.1",
      "id": "domain-name--78984c3b-9fbb-435e-9592-04e657f21841",
      "name": "eeszuu.com",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "最终载荷的默认备用C2域名,本次运行因中间载荷覆盖不发生",
      "x_evidence": "回连至c2集合,包括一个主ip 8.218.106.149和一个备用域名eeszuu.com;由于中间载荷覆盖了新的C2,这个ip与备用域名在本次运行不发生",
      "x_confidence": 0.96
    },
    {
      "type": "ipv4-addr",
      "spec_version": "2.1",
      "id": "ipv4-addr--5487f827-6c56-4dc9-a02e-aedac70c4b84",
      "name": "8.218.220.211",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "木马功能指令中上报使用的C2地址",
      "x_evidence": "指令功能3:上报 C2 IP 8.218.220.211",
      "x_confidence": 0.94
    },
    {
      "type": "observed-data",
      "spec_version": "2.1",
      "id": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "first_observed": "2026-09-01T09:53:53Z",
      "last_observed": "2026-09-01T09:53:53Z",
      "number_observed": 1,
      "objects": {
        "0": {
          "type": "file",
          "name": "s.jpg",
          "description": "攻击流程中的中间载荷,实际为一段PE反射加载的shellcode",
          "aliases": [],
          "evidence": "下载中间载荷s.jpg并内存执行;这里s.jpg实际上是一段PE反射加载的shellcode",
          "confidence": 0.97
        },
        "1": {
          "type": "file",
          "name": "kWZH50.exe",
          "description": "用于侧加载XPSPLOG.dll的恶意程序",
          "aliases": [],
          "evidence": "最终载荷的流程:kWZH50.exe侧加载XPSPLOG.dll",
          "confidence": 0.95
        },
        "2": {
          "type": "file",
          "name": "XPSPLOG.dll",
          "description": "被侧加载后解密image.png的恶意文件",
          "aliases": [],
          "evidence": "kWZH50.exe侧加载XPSPLOG.dll;XPSPLOG.dll解密image.png",
          "confidence": 0.94
        },
        "3": {
          "type": "file",
          "name": "image.png",
          "description": "在攻击流程中用于解密Thumbs.db的文件",
          "aliases": [],
          "evidence": "XPSPLOG.dll解密image.png;Image.png解密Thumbs.db",
          "confidence": 0.94
        },
        "4": {
          "type": "file",
          "name": "Thumbs.db",
          "description": "在攻击链中承担最终的功能载荷与回连的文件",
          "aliases": [],
          "evidence": "Thumbs.db实际上为最终的功能载荷与回连",
          "confidence": 0.97
        },
        "5": {
          "type": "file",
          "name": "ranchserv.jpg",
          "description": "被恶意利用的TrueSight驱动文件,用于通过驱动漏洞关闭杀软进程",
          "aliases": [],
          "evidence": "如果本地没有该文件解密字符串得到https://nm25.cn-hangzhou.aliyuncs.com/qd.dat下载替换ranchserv.jpg文件,该文件就是往期银狐利用的TrueSight驱动",
          "confidence": 0.94
        },
        "6": {
          "type": "file",
          "name": "TrueSight",
          "description": "带有漏洞的合法驱动,被银狐用作白加黑的利用驱动",
          "aliases": [],
          "evidence": "该文件就是往期银狐利用的TrueSight驱动",
          "confidence": 0.92
        },
        "7": {
          "type": "file",
          "name": "Sauron Windows 服务",
          "description": "样本默认启动的持久化服务名称",
          "aliases": [],
          "evidence": "样本默认启动的功能还包括,创建Sauron Windows服务持久化",
          "confidence": 0.91
        },
        "8": {
          "type": "file",
          "name": "HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Tencent SecurityHealth",
          "description": "恶意样本创建的注册表自启动项之一",
          "aliases": [],
          "evidence": "创建注册表自启动:HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Tencent SecurityHealth",
          "confidence": 0.95
        },
        "9": {
          "type": "file",
          "name": "HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Alibaba SecurityHealtha",
          "description": "恶意样本创建的注册表自启动项之一",
          "aliases": [],
          "evidence": "创建注册表自启动:HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Alibaba SecurityHealtha",
          "confidence": 0.95
        },
        "10": {
          "type": "file",
          "name": "HKEY_LOCAL_MACHINE\\SOFTWARE\\JDBCC",
          "description": "恶意样本用来解密IP和备用域名的注册表键",
          "aliases": [],
          "evidence": "这些由注册表HKEY_LOCAL_MACHINE\\SOFTWARE\\JDBCC解密得到",
          "confidence": 0.95
        }
      }
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--73b1b5a5-3103-41a7-b5f7-b0d43cd24016",
      "relationship_type": "attributed-to",
      "source_ref": "campaign--cc14fab9-0d49-4299-b0ad-7c7db9eb841c",
      "target_ref": "intrusion-set--c9887e08-390e-483e-b2eb-42a77c15d5b8",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "该钓鱼活动由银狐团伙实施",
      "x_evidence": "确认该攻击为银狐团伙伪造DeepSeek官方网站面向广大用户实施的钓鱼活动",
      "x_confidence": 0.97
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--76352777-116b-4750-8dc4-3a75d50a25b3",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--c9887e08-390e-483e-b2eb-42a77c15d5b8",
      "target_ref": "url--b6350337-ae9e-47d5-89e4-6027cff783a1",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "银狐启动载荷使用该链接下载总览文件",
      "x_evidence": "总览文件下载链接:https://26usdm.oss-cn-beijing.aliyuncs.com/tad",
      "x_confidence": 0.96
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--7dcef0a3-9e52-41eb-b67f-feb6317407ac",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--c9887e08-390e-483e-b2eb-42a77c15d5b8",
      "target_ref": "url--fbf673bd-2831-4ddd-99e7-ae65b3a9ef43",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "银狐启动载荷使用该备用链接下载总览文件",
      "x_evidence": "总览文件下载链接:https://2bbaz2.oss-cn-beijing.aliyuncs.com/tad",
      "x_confidence": 0.96
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d6dae32f-51da-47e1-b721-e09c33b3a3e5",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--c9887e08-390e-483e-b2eb-42a77c15d5b8",
      "target_ref": "url--f97936c8-5f66-4b34-8df6-3d93302958f3",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "银狐攻击链使用该HTTP地址下载后续恶意载荷",
      "x_evidence": "解密的HTTP下载载荷为:https://mm2027.oss-cn-hangzhou.aliyuncs.com/f.dat",
      "x_confidence": 0.94
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--45b3233a-8c27-48e6-8042-83f5bbc31b4b",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--c9887e08-390e-483e-b2eb-42a77c15d5b8",
      "target_ref": "url--b9b36d81-006f-40e6-8e88-61a2d0af753a",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "银狐使用该链接获取被恶意利用的TrueSight驱动文件",
      "x_evidence": "解密字符串得到https://nm25.cn-hangzhou.aliyuncs.com/qd.dat下载替换ranchserv.jpg文件",
      "x_confidence": 0.93
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--64810495-5982-4fe6-8d83-67721b9a7dbd",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--c9887e08-390e-483e-b2eb-42a77c15d5b8",
      "target_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "银狐利用TrueSight驱动进行防御规避",
      "x_evidence": "该文件就是往期银狐利用的TrueSight驱动",
      "x_confidence": 0.92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--28496517-a00a-45f3-a86a-00b9f2223681",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--c9887e08-390e-483e-b2eb-42a77c15d5b8",
      "target_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "银狐攻击链中使用该注册表键解密C2信息",
      "x_evidence": "注册表写入加密C2信息;这些由注册表HKEY_LOCAL_MACHINE\\SOFTWARE\\JDBCC解密得到",
      "x_confidence": 0.93
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--866c7749-832f-466f-9a9f-e77b20a0a4fc",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--c9887e08-390e-483e-b2eb-42a77c15d5b8",
      "target_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "银狐使用中间载荷s.jpg进行持久化与C2配置覆盖",
      "x_evidence": "下载中间载荷s.jpg并内存执行;这里s.jpg实际上是一段PE反射加载的shellcode",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--50ce655f-8034-4077-bf59-c6602a9947f9",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--c9887e08-390e-483e-b2eb-42a77c15d5b8",
      "target_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "银狐使用最终功能载荷Thumbs.db实施持续控制和数据窃取",
      "x_evidence": "Thumbs.db实际上为最终的功能载荷与回连",
      "x_confidence": 0.96
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--5611bd9c-ce05-4212-97ae-a072e0e17c89",
      "relationship_type": "uses",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "url--f97936c8-5f66-4b34-8df6-3d93302958f3",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "中间载荷通过该HTTP地址下载后续恶意载荷",
      "x_evidence": "shellcode3:HTTP下载后续载荷4个;解密的HTTP下载载荷为 https://mm2027.oss-cn-hangzhou.aliyuncs.com/f.dat",
      "x_confidence": 0.94
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--352bf5c7-ac34-4932-b20f-6f2fbdd725f7",
      "relationship_type": "downloads",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "中间载荷下载后续载荷kWZH50.exe",
      "x_evidence": "HTTP下载后续载荷4个;最终载荷流程由kWZH50.exe侧加载XPSPLOG.dll开始",
      "x_confidence": 0.91
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--9be312fd-e8b8-4481-b584-fa9891f34d34",
      "relationship_type": "downloads",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "中间载荷下载后续载荷XPSPLOG.dll",
      "x_evidence": "HTTP下载后续载荷4个;最终载荷流程由kWZH50.exe侧加载XPSPLOG.dll开始",
      "x_confidence": 0.91
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--df2cb004-e77b-4290-892c-44b214871dad",
      "relationship_type": "downloads",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "中间载荷下载后续载荷image.png",
      "x_evidence": "HTTP下载后续载荷4个;XPSPLOG.dll解密image.png",
      "x_confidence": 0.91
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--085b6861-2a78-4cdd-b77a-0429927812af",
      "relationship_type": "downloads",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "中间载荷下载的4号载荷最终对应Thumbs.db",
      "x_evidence": "在解密之后会将ip与备用域名写入下载的4号载荷中(对应最终载荷中的thumbs.db)",
      "x_confidence": 0.92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--eb83c7f1-ba3b-486b-8cb8-1d7251a679ed",
      "relationship_type": "uses",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "中间载荷从注册表HKEY_LOCAL_MACHINE\\SOFTWARE\\JDBCC解密C2配置",
      "x_evidence": "shellcode3:注册表解密获取C2配置;这些由注册表HKEY_LOCAL_MACHINE\\SOFTWARE\\JDBCC解密得到",
      "x_confidence": 0.94
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--9f9170d9-2fdb-42bf-9358-fcedb0671f33",
      "relationship_type": "uses",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "中间载荷创建注册表自启动项Tencent SecurityHealth",
      "x_evidence": "创建注册表自启动:HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Tencent SecurityHealth",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--3b371fa9-df61-4741-a4f1-23266fc8766a",
      "relationship_type": "uses",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "中间载荷创建注册表自启动项Alibaba SecurityHealtha",
      "x_evidence": "创建注册表自启动:HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Alibaba SecurityHealtha",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--11d6a1c8-b31b-402e-ba64-e03217bbdd30",
      "relationship_type": "uses",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "kWZH50.exe侧加载XPSPLOG.dll",
      "x_evidence": "kWZH50.exe侧加载XPSPLOG.dll",
      "x_confidence": 0.96
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--60e80fc6-59e8-464f-9ad7-ce962c2614ab",
      "relationship_type": "uses",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "XPSPLOG.dll解密image.png",
      "x_evidence": "XPSPLOG.dll解密image.png",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--a4fd7a9f-6c42-4233-8f81-0e5cf35c4b2b",
      "relationship_type": "uses",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "image.png解密并加载最终载荷Thumbs.db",
      "x_evidence": "Image.png解密Thumbs.db;Thumbs.db实际上为最终的功能载荷与回连",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--07683359-9915-4929-9e50-11522459fcce",
      "relationship_type": "communicates-with",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "ipv4-addr--f1a008dc-38cf-443c-b914-a48820bf196b",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "最终载荷回连企业微信环境独立C2端口9000",
      "x_evidence": "企业微信环境:92.48.71.103:9000;在解密之后会将ip与备用域名写入下载的4号载荷中",
      "x_confidence": 0.94
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--ec21c3b2-760a-4cff-9658-a082efb9f700",
      "relationship_type": "communicates-with",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "ipv4-addr--8a5b9393-9b7e-46ae-a27e-63cb40d25938",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "最终载荷回连企业微信环境独立C2端口20032",
      "x_evidence": "企业微信环境:92.48.71.103:20032;在解密之后会将ip与备用域名写入下载的4号载荷中",
      "x_confidence": 0.94
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--2e3c18fb-a882-46a5-a537-c647484f7ec8",
      "relationship_type": "communicates-with",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "domain-name--091d75eb-2e80-4ec0-8adc-e425666da185",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "最终载荷使用企业微信环境C2备用域名lgtnfx.net",
      "x_evidence": "企业微信环境:lgtnfx.net;在解密之后会将ip与备用域名写入下载的4号载荷中",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--6e06bcda-36d6-4126-9a53-9b2e3995a5e6",
      "relationship_type": "communicates-with",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "domain-name--a6cbe76c-9f98-4cb9-9f72-7a13b730a1e5",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "最终载荷使用企业微信环境C2备用域名lwuoys.net",
      "x_evidence": "企业微信环境:lwuoys.net;在解密之后会将ip与备用域名写入下载的4号载荷中",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--2b292bae-6e75-4551-89bf-9e4994165024",
      "relationship_type": "communicates-with",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "ipv4-addr--4d3595ae-9ab3-4dcf-a8f7-1a9b8e3c707e",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "最终载荷默认主C2地址,本次运行因中间载荷覆盖不发生",
      "x_evidence": "回连至c2集合,包括一个主ip 8.218.106.149;由于中间载荷覆盖了新的C2,该ip在本次运行不发生",
      "x_confidence": 0.96
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--43fb5222-5187-4eb4-a28c-b3ab8a9b838c",
      "relationship_type": "communicates-with",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "domain-name--78984c3b-9fbb-435e-9592-04e657f21841",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "最终载荷默认备用C2域名,本次运行因中间载荷覆盖不发生",
      "x_evidence": "回连至c2集合,包括一个备用域名eeszuu.com;由于中间载荷覆盖了新的C2,该域名在本次运行不发生",
      "x_confidence": 0.96
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--9b4d75cb-04ae-424b-b93f-ce894b87c15f",
      "relationship_type": "communicates-with",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "ipv4-addr--5487f827-6c56-4dc9-a02e-aedac70c4b84",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "最终载荷按功能指令上报使用该C2地址",
      "x_evidence": "指令功能3:上报 C2 IP 8.218.220.211",
      "x_confidence": 0.93
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1523651c-4195-4bcb-9f34-ae3633918a9f",
      "relationship_type": "uses",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "最终载荷创建Sauron Windows服务实现持久化",
      "x_evidence": "样本默认启动的功能还包括,创建Sauron Windows服务持久化",
      "x_confidence": 0.94
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--3b8786a3-b116-44e2-bfc5-e1738ac671e3",
      "relationship_type": "uses",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "url--b9b36d81-006f-40e6-8e88-61a2d0af753a",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "最终载荷使用该链接下载ranchserv.jpg",
      "x_evidence": "如果本地没有该文件解密字符串得到https://nm25.cn-hangzhou.aliyuncs.com/qd.dat下载替换ranchserv.jpg文件",
      "x_confidence": 0.93
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--f76a2bb8-7d7f-4feb-b866-d1d77d8b9dfe",
      "relationship_type": "downloads",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "最终载荷下载并替换被恶意利用的TrueSight驱动文件ranchserv.jpg",
      "x_evidence": "如果本地没有该文件解密字符串得到https://nm25.cn-hangzhou.aliyuncs.com/qd.dat下载替换ranchserv.jpg文件",
      "x_confidence": 0.93
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--9873c065-ae9c-4871-931d-9535c0589051",
      "relationship_type": "uses",
      "source_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "target_ref": "observed-data--06fa07be-f64a-4c2b-88e3-6dcf76b452f2",
      "created": "2026-09-01T09:53:53Z",
      "modified": "2026-09-01T09:53:53Z",
      "description": "ranchserv.jpg是被恶意利用的TrueSight驱动文件",
      "x_evidence": "该文件就是往期银狐利用的TrueSight驱动",
      "x_confidence": 0.92
    }
  ]
}

报告链接:

http://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536988&idx=1&sn=ec7f000e629139b96b1f3caa956f5958

───────────────────────────────────

(二)Aurora勒索团伙使用Cursor AI辅助攻击规划

事件名称:黑客服务器裸奔泄露内幕:Aurora勒索团伙用Cursor AI做攻击规划

发布日期:2026-09-01

发布机构:奇安信威胁情报中心

威胁概述:

奇安信威胁情报中心披露,Aurora勒索软件攻击者因服务器开放目录配置错误,暴露了攻击工具、AI聊天记录和加密器。素材显示,攻击者使用Cursor AI辅助攻击规划,并结合有效SSL-VPN凭据、内网枚举、ADCS滥用、NTLM中继和数据打包外传等手段,针对多个国家的组织实施勒索活动。

IOC指标:

· CVE:MS17-010

· Domain:ijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid.onion, pub-c057b7d0b24944a29e381ce9ea22a2f1.r2.dev, exposedrecords.io

· IP:172.86.113.245, 172.86.90.75, 144.172.116.150, 104.194.134.167, 89.106.83.49

· IP:Port:167.88.167.37:50167, 45.61.148.166:21056

· SHA256:eb0aab1e892d7e09e2c7bcf1d21fd83c1743ed9196b3efac6c78482fb0d99207, a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfe

STIX详情:

{
  "type": "bundle",
  "id": "bundle--05145f46-0845-4b7f-8ae3-44408af48dd1",
  "spec_version": "2.1",
  "objects": [
    {
      "type": "intrusion-set",
      "spec_version": "2.1",
      "id": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "name": "Aurora 勒索软件联盟成员",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "执行从准备、初始访问、枚举、提权、横向移动、数据外泄到加密和赎金谈判的俄语操作者联盟成员",
      "x_evidence": "一名 Aurora 勒索软件的俄语操作者...Aurora 勒索软件联盟成员(affiliate)",
      "x_confidence": 0.95
    },
    {
      "type": "malware",
      "spec_version": "2.1",
      "id": "malware--47ea60cc-96c9-4387-a2d3-db5a0cfa8533",
      "name": "Aurora",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "Aurora 勒索软件家族,包含 Windows 版 sap.exe 与 Linux/ESXi 版 encrypt.out 两个变体",
      "x_evidence": "Aurora 加密器本体——勒索信和谈判用的 Tor 洋葱地址就硬编码在二进制文件里",
      "x_confidence": 0.95
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--ae8f34a8-6355-4012-b909-43ce863c7ef1",
      "name": "Cursor",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "AI 编程助手,被操作者用于起草和推演攻击序列、制定 ADCS 利用方案",
      "x_evidence": "操作者开始密集使用 Cursor...起草和推演攻击序列,包括一份完全用俄语写成的 ADCS 利用方案",
      "x_confidence": 0.95
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--c2c974f1-37a5-4a8c-b01d-12b6450299e7",
      "name": "NetExec",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "用于进行 LDAP 与 SMB 探测、抓取密码策略等的工具",
      "x_evidence": "通过 NetExec 进行 LDAP 与 SMB 探测、抓取密码策略、执行 ASREPRoasting 和 Kerberoasting",
      "x_confidence": 0.95
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--42a5597e-324f-4d80-87a0-a696d3e47464",
      "name": "PetitPotam",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "用于强制域控机器账户回连认证的提权手法工具",
      "x_evidence": "通过 PetitPotam、PrinterBug、DFSCoerce 三种手法强制域控机器账户回连认证",
      "x_confidence": 0.9
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--d9f6f4e0-d0f2-44e3-8c9a-24e1ee5c4fe7",
      "name": "PrinterBug",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "强制认证回连的工具",
      "x_evidence": "通过 PetitPotam、PrinterBug、DFSCoerce 三种手法强制域控机器账户回连认证",
      "x_confidence": 0.9
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--f4750c98-fcf7-42b2-b0b4-6cc92130bf83",
      "name": "DFSCoerce",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "强制认证回连的工具",
      "x_evidence": "通过 PetitPotam、PrinterBug、DFSCoerce 三种手法强制域控机器账户回连认证",
      "x_confidence": 0.9
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--f459ffdd-e80a-4a42-a934-da406cf8624e",
      "name": "PowerShell",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "用于驱动 7-Zip 把外泄数据打包的工具",
      "x_evidence": "用 PowerShell 驱动 7-Zip 把数据打成 50GB 一个的分卷包",
      "x_confidence": 0.95
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--93147358-8c13-4413-8a61-28208233c884",
      "name": "7-Zip",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "用于数据分卷打包的工具",
      "x_evidence": "用 PowerShell 驱动 7-Zip 把数据打成 50GB 一个的分卷包",
      "x_confidence": 0.95
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--7c1d9a0b-39c8-479c-b93a-d01b23a882d5",
      "name": "evil-winrm",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "用于横向移动的工具",
      "x_evidence": "evil-winrm、chisel、proxychains 负责横向移动和隧道",
      "x_confidence": 0.9
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--76776baf-566e-41f4-9694-5d0c0d02a8ee",
      "name": "chisel",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "用于建立隧道的工具",
      "x_evidence": "evil-winrm、chisel、proxychains 负责横向移动和隧道",
      "x_confidence": 0.9
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--507aaff7-65b1-444e-828c-41d3bcd82bf7",
      "name": "proxychains",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "用于提供网络代理隧道",
      "x_evidence": "通过 proxychains 提供网络代理隧道",
      "x_confidence": 0.9
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--4cbe2ced-e130-4284-b88a-5f016dd850da",
      "name": "BloodHound",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "用于域内路径分析的工具",
      "x_evidence": "BloodHound 负责域内路径分析",
      "x_confidence": 0.9
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--ebf8b16e-e911-4d39-9a9f-98fae0fa0748",
      "name": "Metasploit",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "用作 C2 及漏洞利用(如 MS17-010)的框架",
      "x_evidence": "Metasploit 承担 C2(包括 MS17-010 模块)...永恒之蓝仍被直接用来创建账户",
      "x_confidence": 0.95
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--19eeed1b-3f38-4c9a-9d11-9805af91ea8c",
      "name": "MS17-010",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "永恒之蓝漏洞,用于攻击遗留主机并创建账户",
      "aliases": [
        "永恒之蓝"
      ],
      "x_evidence": "MS17-010(永恒之蓝)攻击遗留主机",
      "x_confidence": 0.95
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--97e132df-1aac-4a55-a936-809ac63ede0e",
      "name": "Zig",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "用于编写 Aurora 勒索软件的编程语言",
      "x_evidence": "Aurora 选择了 Zig——一门尚未发布 1.0 版本的年轻系统级语言",
      "x_confidence": 0.95
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--e4b2537c-b8e4-4ffb-8f36-71df75654531",
      "name": "Nmap",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "受 Cursor Agent 控制进行扫描的工具",
      "x_evidence": "用 Nmap/NetExec 扫描",
      "x_confidence": 0.9
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--57997b49-b33d-4988-9493-3228c43c1a05",
      "name": "Certipy",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "被操作者用于证书攻击的工具",
      "x_evidence": "用 Certipy 做证书攻击",
      "x_confidence": 0.9
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--0736b305-c27c-4644-bac4-b391c60d3964",
      "name": "krbtgt",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "被用于提取哈希的账户",
      "x_evidence": "提取 krbtgt 哈希(食品/农业受害者案例)",
      "x_confidence": 0.9
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--4fd5bd43-e9da-4084-8f53-8b91ab3b3891",
      "name": "Kerbrute",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "用于口令猜测/喷射",
      "x_evidence": "Kerbrute 等口令猜测/喷射",
      "x_confidence": 0.9
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--f91c994f-bebf-425c-871c-9e3a09417af8",
      "name": "scp",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "用于推送加密器至暂存主机的工具",
      "x_evidence": "scp 推送加密器至暂存主机",
      "x_confidence": 0.9
    },
    {
      "type": "ipv4-addr",
      "spec_version": "2.1",
      "id": "ipv4-addr--4b8f7c78-e417-4c29-9e35-4c9febe65228",
      "name": "172.86.113.245",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者 VPS,用于攻击基础设施",
      "x_evidence": "IPv4 172.86.113.245 操作者 VPS",
      "x_confidence": 0.95
    },
    {
      "type": "ipv4-addr",
      "spec_version": "2.1",
      "id": "ipv4-addr--831328d5-f1de-4a1a-a0b3-f540c585785c",
      "name": "172.86.90.75",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者 VPS,用于攻击基础设施",
      "x_evidence": "IPv4 172.86.90.75 操作者 VPS",
      "x_confidence": 0.95
    },
    {
      "type": "ipv4-addr",
      "spec_version": "2.1",
      "id": "ipv4-addr--f49ab7ed-9eaf-44c4-8d59-a8e344b168fe",
      "name": "144.172.116.150",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者 VPS,用于攻击基础设施",
      "x_evidence": "IPv4 144.172.116.150 操作者 VPS",
      "x_confidence": 0.95
    },
    {
      "type": "ipv4-addr",
      "spec_version": "2.1",
      "id": "ipv4-addr--7c8c0521-10fb-46c3-ac3b-9b60ed24166f",
      "name": "104.194.134.167",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者 VPS(SOCKS 中继)地址",
      "x_evidence": "IPv4 104.194.134.167 操作者 VPS(SOCKS 中继)",
      "x_confidence": 0.95
    },
    {
      "type": "ipv4-addr",
      "spec_version": "2.1",
      "id": "ipv4-addr--41a2bcd4-357c-4923-8c52-9ca6b71919d6",
      "name": "89.106.83.49",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "租用的 SOCKS 跳板 IP",
      "x_evidence": "IPv4 89.106.83.49 租用的 SOCKS 跳板",
      "x_confidence": 0.95
    },
    {
      "type": "ipv4-addr",
      "spec_version": "2.1",
      "id": "ipv4-addr--9f2160f8-9013-44c6-b950-b00c29ee0910",
      "name": "23.234.108.48",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "租用的 SOCKS 跳板 IP",
      "x_evidence": "IPv4 23.234.108.48 租用的 SOCKS 跳板",
      "x_confidence": 0.95
    },
    {
      "type": "ipv4-addr",
      "spec_version": "2.1",
      "id": "ipv4-addr--9abd4339-6282-4b1a-9943-83e18e4a4831",
      "name": "167.88.167.37:50167",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "C2 出口检查地址,IP 167.88.167.37,端口 50167",
      "x_evidence": "IPv4:端口 167.88.167.37:50167 C2 出口检查",
      "x_confidence": 0.95
    },
    {
      "type": "ipv4-addr",
      "spec_version": "2.1",
      "id": "ipv4-addr--ef300339-d039-4e12-89c6-3a88a1734808",
      "name": "45.61.148.166:21056",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "租用的 SOCKS 跳板地址,IP 45.61.148.166,端口 21056",
      "x_evidence": "IPv4:端口 45.61.148.166:21056 租用的 SOCKS 跳板",
      "x_confidence": 0.95
    },
    {
      "type": "domain-name",
      "spec_version": "2.1",
      "id": "domain-name--85cd221b-9550-47c4-9dae-4103257010cf",
      "name": "ijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid.onion",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "内嵌于加密器的 Aurora 受害者谈判站点洋葱地址",
      "x_evidence": "洋葱地址 ijexszhscln27nl263lmcd7tx3jttkhm4wjhd4e3y6r4csdbfyeprvid.onion Aurora 受害者谈判站点",
      "x_confidence": 0.95
    },
    {
      "type": "domain-name",
      "spec_version": "2.1",
      "id": "domain-name--dc0a1349-01d8-4926-ab2a-abc28ed4e2d8",
      "name": "pub-c057b7d0b24944a29e381ce9ea22a2f1.r2.dev",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "加密器下载地址所在公开 Cloudflare R2 存储桶,用于投递加密器",
      "x_evidence": "加密器下载地址位于公开 Cloudflare R2 存储桶(pub-c057b7d0b24944a29e381ce9ea22a2f1.r2.dev)",
      "x_confidence": 0.95
    },
    {
      "type": "domain-name",
      "spec_version": "2.1",
      "id": "domain-name--b59d849a-69a7-4d82-93b6-b8d3ce9bdf12",
      "name": "exposedrecords.io",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "Aurora 明网泄露站点域名,用于公布受害者信息施压",
      "x_evidence": "Aurora 明网泄露站点域名 exposedrecords.io",
      "x_confidence": 0.95
    },
    {
      "type": "infrastructure",
      "spec_version": "2.1",
      "id": "infrastructure--acd6080b-65bf-4a90-8aed-17a80343864f",
      "name": "操作者自有 VPS",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者自有 VPS,包括 172.86.113.245、172.86.90.75、144.172.116.150、104.194.134.167",
      "x_evidence": "操作者自己的基础设施...操作者 VPS(SOCKS 中继)",
      "x_confidence": 0.9
    },
    {
      "type": "infrastructure",
      "spec_version": "2.1",
      "id": "infrastructure--d47ae180-de44-44b0-b70f-af7f0f3d04ab",
      "name": "SOCKS 代理跳板",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "租用的 SOCKS 代理跳板,包括 89.106.83.49、23.234.108.48、45.61.148.166:21056",
      "x_evidence": "所有面向受害者的动作都经由租用的 SOCKS 代理跳板转发",
      "x_confidence": 0.9
    },
    {
      "type": "infrastructure",
      "spec_version": "2.1",
      "id": "infrastructure--aed41bf6-64e6-43a8-9d67-5f6027a052cb",
      "name": "C2 出口检查基础设施",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "C2 出口检查基础设施,地址 167.88.167.37:50167",
      "x_evidence": "C2 出口检查地址 167.88.167.37:50167",
      "x_confidence": 0.9
    },
    {
      "type": "infrastructure",
      "spec_version": "2.1",
      "id": "infrastructure--d46924ed-18e5-4136-9f96-db2937ad720a",
      "name": "赎金谈判与泄露基础设施",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "赎金谈判与泄露基础设施,包括洋葱谈判站点和明网泄露站点",
      "x_evidence": "受害者通过内嵌于加密器的洋葱地址进行赎金谈判...明网泄露站点 exposedrecords.io 公布受害者信息施压",
      "x_confidence": 0.9
    },
    {
      "type": "infrastructure",
      "spec_version": "2.1",
      "id": "infrastructure--53347fd8-36e9-4400-be91-03002a6c757a",
      "name": "加密器下载基础设施",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "加密器下载基础设施,公开 Cloudflare R2 存储桶",
      "x_evidence": "加密器下载地址位于公开 Cloudflare R2 存储桶",
      "x_confidence": 0.9
    },
    {
      "type": "observed-data",
      "spec_version": "2.1",
      "id": "observed-data--b060d16a-f146-4df2-810c-20fea8b013af",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "first_observed": "2026-09-01T07:03:32Z",
      "last_observed": "2026-09-01T07:03:32Z",
      "number_observed": 1,
      "objects": {
        "0": {
          "type": "file",
          "name": "sap.exe",
          "description": "Aurora 勒索软件的 Windows 版加密器变体,SHA-256: eb0aab1e892d7e09e2c7bcf1d21fd83c1743ed9196b3efac6c78482fb0d99207",
          "aliases": [],
          "evidence": "Windows 版 sap.exe...原文明确标注为 Windows 加密器 sap.exe 的 SHA-256 哈希",
          "confidence": 0.95
        },
        "1": {
          "type": "file",
          "name": "encrypt.out",
          "description": "Aurora 勒索软件的 Linux/ESXi 版加密器变体,SHA-256: a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfe",
          "aliases": [],
          "evidence": "Linux/ESXi 版 encrypt.out...原文明确标注为 Linux/ESXi 加密器 encrypt.out 的 SHA-256 哈希",
          "confidence": 0.95
        },
        "2": {
          "type": "process",
          "name": "esxcli vm process list",
          "description": "Linux/ESXi 加密器中用于收集正在运行的虚拟机 World ID 的命令",
          "aliases": [],
          "evidence": "具体调用 esxcli vm process list 收集 World ID",
          "confidence": 0.9
        },
        "3": {
          "type": "process",
          "name": "esxcli vm process kill --type=force",
          "description": "Linux/ESXi 加密器中用于强制终止虚拟机的命令",
          "aliases": [],
          "evidence": "再以 esxcli vm process kill --type=force 终结虚拟机",
          "confidence": 0.9
        },
        "4": {
          "type": "file",
          "name": "sshd-banner",
          "description": "ESXi 勒索信写入的目标文件及 SSH 登录横幅",
          "aliases": [],
          "evidence": "勒索信不落盘成文件,而是写进 ESXi 宿主机的 SSH 登录横幅...文件名为 sshd-banner",
          "confidence": 0.9
        },
        "5": {
          "type": "file",
          "name": "!!!README!!!DO_NOT_DELETE.txt",
          "description": "勒索信文件名",
          "aliases": [],
          "evidence": "勒索信文件名 !!!README!!!DO_NOT_DELETE.txt",
          "confidence": 0.9
        }
      }
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--ef95e720-dc82-43fc-b750-b401f7d2f0ad",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "malware--47ea60cc-96c9-4387-a2d3-db5a0cfa8533",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "Aurora 勒索软件联盟成员使用 Aurora 勒索软件实施加密",
      "x_evidence": "加密器就放在操作者自己的目录里待命;操作者使用 Windows 版和 Linux/ESXi 版加密器",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--e61926fa-51dd-4507-ae3e-a2ee653a4955",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "tool--ae8f34a8-6355-4012-b909-43ce863c7ef1",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 Cursor 起草和推演攻击序列、制定 ADCS 利用方案",
      "x_evidence": "操作者开始密集使用 Cursor...起草和推演攻击序列,包括一份完全用俄语写成的 ADCS 利用方案",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--5ab463f0-7edb-4620-9002-14d7148b2510",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "tool--c2c974f1-37a5-4a8c-b01d-12b6450299e7",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 NetExec 进行 LDAP 与 SMB 探测、抓取密码策略",
      "x_evidence": "通过 NetExec 进行 LDAP 与 SMB 探测、抓取密码策略、执行 ASREPRoasting 和 Kerberoasting",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--da2ba7a0-0135-46f0-a838-db40495d05a7",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "tool--4fd5bd43-e9da-4084-8f53-8b91ab3b3891",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 Kerbrute 进行口令猜测/喷射",
      "x_evidence": "Kerbrute 等口令猜测/喷射",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--fdaf3f49-92e0-4b88-9f75-59cb5168e856",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "tool--e4b2537c-b8e4-4ffb-8f36-71df75654531",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 Nmap 进行扫描",
      "x_evidence": "用 Nmap/NetExec 扫描",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--684903b5-5df3-4632-8e9c-f94c08bfeb2f",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "tool--4cbe2ced-e130-4284-b88a-5f016dd850da",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 BloodHound 进行域内路径分析",
      "x_evidence": "BloodHound 负责域内路径分析",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--6fabb270-4d7f-4ab9-b335-54a7bec4d012",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "tool--57997b49-b33d-4988-9493-3228c43c1a05",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 Certipy 进行 ADCS 证书攻击并铸造域管证书",
      "x_evidence": "用 Certipy 做证书攻击...ADCS ESC1/ESC6/ESC8 滥用,铸造域管证书",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--a823d0fb-8772-4038-9864-dd2099271dbf",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "tool--42a5597e-324f-4d80-87a0-a696d3e47464",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 PetitPotam 强制域控机器账户回连认证",
      "x_evidence": "通过 PetitPotam、PrinterBug、DFSCoerce 强制认证回连",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--37a61089-1a01-4810-ab4c-82f62d278c36",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "tool--d9f6f4e0-d0f2-44e3-8c9a-24e1ee5c4fe7",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 PrinterBug 强制认证回连",
      "x_evidence": "通过 PetitPotam、PrinterBug、DFSCoerce 强制认证回连",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--7d8b015f-689a-4233-a035-b21de23917c9",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "tool--f4750c98-fcf7-42b2-b0b4-6cc92130bf83",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 DFSCoerce 强制认证回连",
      "x_evidence": "通过 PetitPotam、PrinterBug、DFSCoerce 强制认证回连",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--fcc5c939-6ba4-4194-8c83-95b3b1887632",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "tool--7c1d9a0b-39c8-479c-b93a-d01b23a882d5",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 evil-winrm 进行横向移动",
      "x_evidence": "evil-winrm 负责横向移动",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--109ecc25-7e4f-4edc-84ed-0764f9dfbb97",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "tool--ebf8b16e-e911-4d39-9a9f-98fae0fa0748",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 Metasploit 作为 C2 并进行漏洞利用",
      "x_evidence": "Metasploit 承担 C2(包括 MS17-010 模块)",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--5bc5e6c5-1667-4596-83ec-7f73e2702ff2",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "tool--f91c994f-bebf-425c-871c-9e3a09417af8",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 scp 将加密器推送至暂存主机",
      "x_evidence": "scp 推送加密器至暂存主机",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--739ceed2-6ba7-42c2-8b54-2002dbd020b7",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "tool--f459ffdd-e80a-4a42-a934-da406cf8624e",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 PowerShell 驱动数据分卷打包",
      "x_evidence": "用 PowerShell 驱动 7-Zip 把数据打成 50GB 一个的分卷包",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--13ef0400-4acc-4eaa-90a2-6350816558b0",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "tool--93147358-8c13-4413-8a61-28208233c884",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 7-Zip 对数据进行 50GB 分卷打包",
      "x_evidence": "用 PowerShell 驱动 7-Zip 把数据打成 50GB 一个的分卷包",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d68580bf-ca32-4ac4-8fff-65cecbf632b2",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "tool--76776baf-566e-41f4-9694-5d0c0d02a8ee",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 chisel 建立隧道",
      "x_evidence": "chisel 负责隧道",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--994338bf-0382-490f-9916-d16d2cbac5a2",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "tool--507aaff7-65b1-444e-828c-41d3bcd82bf7",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 proxychains 提供网络代理隧道",
      "x_evidence": "proxychains 提供网络代理隧道",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--4e5ec86e-f57b-4d12-81c6-85cef17e49be",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "observed-data--b060d16a-f146-4df2-810c-20fea8b013af",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 Windows 版 Aurora 加密器 sap.exe",
      "x_evidence": "Windows 版 sap.exe...SHA-256 eb0aab1e892d7e09e2c7bcf1d21fd83c1743ed9196b3efac6c78482fb0d99207",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--11a7b266-b771-44d2-8835-313bcfab583e",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "observed-data--b060d16a-f146-4df2-810c-20fea8b013af",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 Linux/ESXi 版 Aurora 加密器 encrypt.out",
      "x_evidence": "Linux/ESXi 版 encrypt.out...SHA-256 a4af136d159a8eb96b54924fa80355ca52874913301300f55af7d67ae97edcfe",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--8863ba7a-5302-4805-9af9-a2169fe624b1",
      "relationship_type": "uses",
      "source_ref": "tool--ae8f34a8-6355-4012-b909-43ce863c7ef1",
      "target_ref": "tool--e4b2537c-b8e4-4ffb-8f36-71df75654531",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "Cursor Agent 控制 Nmap 进行扫描",
      "x_evidence": "用 Nmap/NetExec 扫描...Agent 首次尝试大多失败,随后自行修正命令和脚本",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--6088a5b9-2f20-48cc-a3b3-01fe6114c71c",
      "relationship_type": "uses",
      "source_ref": "tool--f459ffdd-e80a-4a42-a934-da406cf8624e",
      "target_ref": "tool--93147358-8c13-4413-8a61-28208233c884",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "PowerShell 驱动 7-Zip 打包外泄数据",
      "x_evidence": "用 PowerShell 驱动 7-Zip 把数据打成 50GB 一个的分卷包",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--b97dcf5b-39c3-4170-822a-85439b362be6",
      "relationship_type": "exploits",
      "source_ref": "tool--ebf8b16e-e911-4d39-9a9f-98fae0fa0748",
      "target_ref": "vulnerability--19eeed1b-3f38-4c9a-9d11-9805af91ea8c",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "Metasploit 利用 MS17-010(永恒之蓝)漏洞攻击遗留主机",
      "x_evidence": "Metasploit 承担 C2(包括 MS17-010 模块)——在一台遗留主机上,永恒之蓝仍被直接用来创建账户",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1ffe0ab6-47bb-44b7-a5f7-2d12abf124f5",
      "relationship_type": "uses",
      "source_ref": "observed-data--b060d16a-f146-4df2-810c-20fea8b013af",
      "target_ref": "observed-data--b060d16a-f146-4df2-810c-20fea8b013af",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "encrypt.out 执行命令收集正在运行的虚拟机 World ID",
      "x_evidence": "具体调用 esxcli vm process list 收集 World ID",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--89542a6a-df42-4233-98fe-b5786d7a4ef9",
      "relationship_type": "uses",
      "source_ref": "observed-data--b060d16a-f146-4df2-810c-20fea8b013af",
      "target_ref": "observed-data--b060d16a-f146-4df2-810c-20fea8b013af",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "encrypt.out 执行命令强制终止虚拟机",
      "x_evidence": "再以 esxcli vm process kill --type=force 终结虚拟机",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--ccd9deb3-581a-424d-873e-9a5da162bd38",
      "relationship_type": "communicates-with",
      "source_ref": "malware--47ea60cc-96c9-4387-a2d3-db5a0cfa8533",
      "target_ref": "domain-name--85cd221b-9550-47c4-9dae-4103257010cf",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "Aurora 加密器内嵌洋葱谈判站点用于赎金谈判",
      "x_evidence": "赎金谈判用的 Tor 洋葱地址就硬编码在二进制文件里",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--cd2f2358-cd43-495c-8f6c-374942b27e59",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "infrastructure--acd6080b-65bf-4a90-8aed-17a80343864f",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用自有 VPS 作为攻击基础设施",
      "x_evidence": "操作者自己的基础设施从未直接触碰过任何受害者网络",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d861924f-e713-4c80-8fb9-82dcc0ebec50",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "infrastructure--d47ae180-de44-44b0-b70f-af7f0f3d04ab",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用租用的 SOCKS 代理跳板转发面向受害者的动作",
      "x_evidence": "所有面向受害者的动作都经由租用的 SOCKS 代理跳板转发",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--c30a7971-965b-4619-b3c7-d941f32d90b1",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "infrastructure--aed41bf6-64e6-43a8-9d67-5f6027a052cb",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用 C2 出口检查基础设施",
      "x_evidence": "C2 出口检查地址 167.88.167.37:50167",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--872c2bba-4f1b-4614-b71f-3377653c422a",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "infrastructure--d46924ed-18e5-4136-9f96-db2937ad720a",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用赎金谈判与泄露基础设施对受害者施压",
      "x_evidence": "受害者通过洋葱地址赎金谈判...明网泄露站点公布受害者信息施压",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--6cd8048a-3569-46e8-8b00-57d80bd77eba",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "infrastructure--53347fd8-36e9-4400-be91-03002a6c757a",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者使用加密器下载基础设施投递加密器",
      "x_evidence": "加密器下载地址位于公开 Cloudflare R2 存储桶...用于投递加密器",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--3c9ce1ad-9a8d-4017-8ece-d1d58f49ba4c",
      "relationship_type": "consists-of",
      "source_ref": "infrastructure--acd6080b-65bf-4a90-8aed-17a80343864f",
      "target_ref": "ipv4-addr--4b8f7c78-e417-4c29-9e35-4c9febe65228",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者自有 VPS 包含 172.86.113.245",
      "x_evidence": "IPv4 172.86.113.245 操作者 VPS",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--e5993b9c-f482-49a6-b007-0bdbac76c92e",
      "relationship_type": "consists-of",
      "source_ref": "infrastructure--acd6080b-65bf-4a90-8aed-17a80343864f",
      "target_ref": "ipv4-addr--831328d5-f1de-4a1a-a0b3-f540c585785c",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者自有 VPS 包含 172.86.90.75",
      "x_evidence": "IPv4 172.86.90.75 操作者 VPS",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--658d5675-2a05-4d53-96f1-8fc3206cf4fe",
      "relationship_type": "consists-of",
      "source_ref": "infrastructure--acd6080b-65bf-4a90-8aed-17a80343864f",
      "target_ref": "ipv4-addr--f49ab7ed-9eaf-44c4-8d59-a8e344b168fe",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者自有 VPS 包含 144.172.116.150",
      "x_evidence": "IPv4 144.172.116.150 操作者 VPS",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--52d0904b-5696-4b15-911c-f7a9dd83e6bf",
      "relationship_type": "consists-of",
      "source_ref": "infrastructure--acd6080b-65bf-4a90-8aed-17a80343864f",
      "target_ref": "ipv4-addr--7c8c0521-10fb-46c3-ac3b-9b60ed24166f",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者自有 VPS 包含 SOCKS 中继 104.194.134.167",
      "x_evidence": "IPv4 104.194.134.167 操作者 VPS(SOCKS 中继)",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--2d556519-7fe0-4fc4-9eca-158e39ee2a0c",
      "relationship_type": "consists-of",
      "source_ref": "infrastructure--d47ae180-de44-44b0-b70f-af7f0f3d04ab",
      "target_ref": "ipv4-addr--41a2bcd4-357c-4923-8c52-9ca6b71919d6",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "SOCKS 代理跳板包含 89.106.83.49",
      "x_evidence": "IPv4 89.106.83.49 租用的 SOCKS 跳板",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--c4603915-65d7-4463-9cdd-119030b0988c",
      "relationship_type": "consists-of",
      "source_ref": "infrastructure--d47ae180-de44-44b0-b70f-af7f0f3d04ab",
      "target_ref": "ipv4-addr--9f2160f8-9013-44c6-b950-b00c29ee0910",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "SOCKS 代理跳板包含 23.234.108.48",
      "x_evidence": "IPv4 23.234.108.48 租用的 SOCKS 跳板",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--dcd63e50-de29-4054-a0a3-60b961bd53b9",
      "relationship_type": "consists-of",
      "source_ref": "infrastructure--d47ae180-de44-44b0-b70f-af7f0f3d04ab",
      "target_ref": "ipv4-addr--ef300339-d039-4e12-89c6-3a88a1734808",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "SOCKS 代理跳板包含 45.61.148.166:21056",
      "x_evidence": "IPv4:端口 45.61.148.166:21056 租用的 SOCKS 跳板",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--498ba10e-e3a3-49f3-8df1-0e05832d0f1f",
      "relationship_type": "consists-of",
      "source_ref": "infrastructure--aed41bf6-64e6-43a8-9d67-5f6027a052cb",
      "target_ref": "ipv4-addr--9abd4339-6282-4b1a-9943-83e18e4a4831",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "C2 出口检查基础设施包含 167.88.167.37:50167",
      "x_evidence": "IPv4:端口 167.88.167.37:50167 C2 出口检查",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--da4f2c92-73e2-4641-9360-ea6a9777d4bf",
      "relationship_type": "consists-of",
      "source_ref": "infrastructure--d46924ed-18e5-4136-9f96-db2937ad720a",
      "target_ref": "domain-name--85cd221b-9550-47c4-9dae-4103257010cf",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "赎金谈判与泄露基础设施包含洋葱谈判站点",
      "x_evidence": "洋葱地址 ijex...onion Aurora 受害者谈判站点",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--cb2d57e1-4d91-4c8c-9d39-0614f60c8140",
      "relationship_type": "consists-of",
      "source_ref": "infrastructure--d46924ed-18e5-4136-9f96-db2937ad720a",
      "target_ref": "domain-name--b59d849a-69a7-4d82-93b6-b8d3ce9bdf12",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "赎金谈判与泄露基础设施包含明网泄露站点域名",
      "x_evidence": "Aurora 明网泄露站点域名 exposedrecords.io",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--3e7a6628-7dce-4275-98d7-c8d9dd1c6d97",
      "relationship_type": "consists-of",
      "source_ref": "infrastructure--53347fd8-36e9-4400-be91-03002a6c757a",
      "target_ref": "domain-name--dc0a1349-01d8-4926-ab2a-abc28ed4e2d8",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "加密器下载基础设施包含 Cloudflare R2 存储桶域名",
      "x_evidence": "加密器下载地址位于公开 Cloudflare R2 存储桶 pub-c057b7d0b24944a29e381ce9ea22a2f1.r2.dev",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--a61de519-9a0e-4bcc-a03d-d5204709c480",
      "relationship_type": "uses",
      "source_ref": "malware--47ea60cc-96c9-4387-a2d3-db5a0cfa8533",
      "target_ref": "tool--97e132df-1aac-4a55-a936-809ac63ede0e",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "Aurora 勒索软件使用 Zig 编写,两个变体出自同一套 Zig 代码库",
      "x_evidence": "Aurora 选择了 Zig...两个加密器变体...出自同一套 Zig 代码库",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--86e22425-c0fe-4ee1-a3f4-dafc75694972",
      "relationship_type": "uses",
      "source_ref": "observed-data--b060d16a-f146-4df2-810c-20fea8b013af",
      "target_ref": "observed-data--b060d16a-f146-4df2-810c-20fea8b013af",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "encrypt.out 将勒索信写入 sshd-banner 并重启 SSH 服务",
      "x_evidence": "勒索信不落盘成文件,而是写进 ESXi 宿主机的 SSH 登录横幅",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--23824e52-5473-47e1-9939-dbba5b4f4d22",
      "relationship_type": "drops",
      "source_ref": "malware--47ea60cc-96c9-4387-a2d3-db5a0cfa8533",
      "target_ref": "observed-data--b060d16a-f146-4df2-810c-20fea8b013af",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "Aurora 勒索软件投放勒索信文件 !!!README!!!DO_NOT_DELETE.txt",
      "x_evidence": "勒索信文件名 !!!README!!!DO_NOT_DELETE.txt",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--7b4e7c0d-75bb-40b6-9453-bbecdb2b586e",
      "relationship_type": "targets",
      "source_ref": "intrusion-set--74649695-d496-451e-8d95-b95c0837380f",
      "target_ref": "identity--0736b305-c27c-4644-bac4-b391c60d3964",
      "created": "2026-09-01T07:03:32Z",
      "modified": "2026-09-01T07:03:32Z",
      "description": "操作者以 krbtgt 账户为凭据访问目标,提取其哈希",
      "x_evidence": "提取 krbtgt 哈希(食品/农业受害者案例)",
      "x_confidence": 0.9
    }
  ]
}

报告链接:

http://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247520161&idx=1&sn=61ee15f915debc760d7d4ddbd6fb19ad

───────────────────────────────────

(三)Hermes Agent恶意Git配置可触发远程代码执行

事件名称:CVE-2026-71963:Nous Research的Hermes Agent中的远程代码执行漏洞

发布日期:2026-09-03

发布机构:SecurityVulnerability.io

威胁概述:

Hermes Agent 0.18.2至0.21.0版本存在远程代码执行漏洞。攻击者可在伪造的.git/config文件中设置core.fsmonitor命令;当用户与受感染代码库交互并触发Agent刷新Git状态时,恶意命令会在用户进程上下文中执行,可能进一步泄露API密钥等敏感信息。

IOC指标:

· CVE:CVE-2026-71963

报告链接:

https://securityvulnerability.io/vulnerability/CVE-2026-71963

───────────────────────────────────

(四)LiteLLM漏洞遭在野利用并窃取大模型API密钥

事件名称:CISA连夜拉黑7个在野漏洞:黑客正顺着LiteLLM偷你的大模型密钥

发布日期:2026-09-04

发布机构:安全客

威胁概述:

素材显示,攻击者正在利用LiteLLM等组件的漏洞实施攻击,并通过LiteLLM漏洞链绕过认证、实现远程代码执行,进而获取数据库中的模型配置和API密钥材料。后续活动还包括建立反向Shell和部署XMRig挖矿程序。相关漏洞已被纳入CISA已知被利用漏洞目录。

IOC指标:

· CVE:CVE-2026-83548, CVE-2026-83549, CVE-2026-82329, CVE-2026-9586, CVE-2026-49869

STIX详情:

{
  "type": "bundle",
  "id": "bundle--f7dd998e-1fb5-4c8a-8504-ac3e121594d1",
  "spec_version": "2.1",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--f901d515-9ed9-45d6-ad8f-7464761fde48",
      "name": "CISA",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "发布KEV目录更新的安全机构",
      "x_evidence": "CISA又更新了KEV目录,一口气加了7个漏洞,全部确认在野利用。",
      "x_confidence": 0.97
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--a46fc5b9-887c-493b-8d01-f996d3d0fc32",
      "name": "LiteLLM",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "被黑客攻击以窃取大模型API密钥的AI基建网关",
      "x_evidence": "LiteLLM、MCP服务这些AI基础设施第一次被成批点名;攻击者攻破LiteLLM网关后翻PostgreSQL数据库。",
      "x_confidence": 0.97
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--4f17b5ea-998e-4a8a-9f4f-420b2e342477",
      "name": "Kestra",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "被黑客攻击的AI基础设施之一,工作流引擎",
      "x_evidence": "Kestra工作流引擎的命令注入漏洞。",
      "x_confidence": 0.95
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--1c8c879f-fe4e-4743-b343-2314deba4266",
      "name": "SonicWall SMA 1000",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "受SSRF和命令注入漏洞影响的设备系列",
      "x_evidence": "SonicWall SMA 1000系列设备的SSRF漏洞;同系列命令注入漏洞。",
      "x_confidence": 0.96
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f715f8f4-7205-4fff-9203-1e43a06e36e2",
      "name": "CVE-2026-83548",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "SonicWall SMA 1000系列设备的SSRF漏洞",
      "x_evidence": "SonicWall SMA 1000系列设备的SSRF漏洞,CVE-2026-83548,CVSS 10.0。",
      "x_confidence": 0.98
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--aed30b55-7441-4209-86e7-4b4903977fa3",
      "name": "CVE-2026-83549",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "SonicWall SMA 1000系列设备的命令注入漏洞",
      "x_evidence": "同系列的命令注入漏洞,CVE-2026-83549。",
      "x_confidence": 0.98
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--9ae3f384-75a4-4f35-8a40-29ae1a812397",
      "name": "JFrog Artifactory",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "受认证缺陷影响的制品库软件",
      "x_evidence": "JFrog Artifactory的认证缺陷。",
      "x_confidence": 0.95
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--994a88c9-9a83-4e95-8470-ff59f66ed3f2",
      "name": "CVE-2026-82329",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "JFrog Artifactory的认证缺陷",
      "x_evidence": "JFrog Artifactory的认证缺陷,CVE-2026-82329,CVSS 9.8。",
      "x_confidence": 0.98
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--248f2d3a-1841-4d5f-9e13-d01449d8d587",
      "name": "Sangoma Switchvox",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "受SQL注入影响的软件",
      "x_evidence": "Sangoma Switchvox的SQL注入。",
      "x_confidence": 0.95
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--db0a8dff-77d5-44d6-909f-e0b64d8bbb64",
      "name": "CVE-2026-9586",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "Sangoma Switchvox的SQL注入漏洞",
      "x_evidence": "Sangoma Switchvox的SQL注入,CVE-2026-9586,9.3分。",
      "x_confidence": 0.98
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--303a3e77-db4c-4c88-9019-143685d8382d",
      "name": "CVE-2026-49869",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "Kestra工作流引擎的命令注入漏洞",
      "x_evidence": "Kestra工作流引擎的命令注入,CVE-2026-49869,10.0分。",
      "x_confidence": 0.98
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--e0340642-5aff-4999-bc3d-13b704f59482",
      "name": "Starlette",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "受HTTP请求走私漏洞影响的软件",
      "x_evidence": "Starlette的HTTP请求走私。",
      "x_confidence": 0.95
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c3b05d1b-0cf8-4923-b74a-fdebd3440249",
      "name": "CVE-2026-48710",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "Starlette的HTTP请求走私漏洞",
      "x_evidence": "Starlette的HTTP请求走私,CVE-2026-48710。",
      "x_confidence": 0.98
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--2d4b0d6a-63c8-4ae8-bc3d-28518ebc9ee8",
      "name": "CVE-2026-59822",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "LiteLLM的MCP接口认证缺陷",
      "x_evidence": "LiteLLM的MCP接口认证缺陷,CVE-2026-59822,8.8分。",
      "x_confidence": 0.98
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--b3b2cb59-93cb-449f-8b55-0ae2b6f40a57",
      "name": "微软",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "发布关于系统性攻击AI基础设施报告的厂商",
      "x_evidence": "微软和Wiz的报告把话说得很直白。",
      "x_confidence": 0.97
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--5198c372-a68b-4d40-9dbf-c86704fb1dc4",
      "name": "Wiz",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "发布关于系统性攻击AI基础设施报告的厂商",
      "x_evidence": "微软和Wiz的报告把话说得很直白。",
      "x_confidence": 0.97
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--12857e40-4a81-48e2-b482-1b295e128816",
      "name": "Flowise",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "被黑客系统性攻击的AI基础设施之一",
      "x_evidence": "黑客正在系统性地攻击AI基础设施:LiteLLM网关、Flowise、LangChain、Ollama、ChromaDB、MCP服务器。",
      "x_confidence": 0.86
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--c9ffc508-7fbe-4d6c-a58e-7035b8e00f58",
      "name": "LangChain",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "被黑客系统性攻击的AI基础设施之一",
      "x_evidence": "黑客正在系统性地攻击AI基础设施:Flowise、LangChain等。",
      "x_confidence": 0.86
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--9eee5f4e-5386-4d29-a3ac-c56066a656fc",
      "name": "Ollama",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "被黑客系统性攻击的AI基础设施之一",
      "x_evidence": "黑客正在系统性地攻击AI基础设施:Ollama。",
      "x_confidence": 0.86
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--6e179c9c-0113-4522-b588-6ccab8b12dc4",
      "name": "ChromaDB",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "被黑客系统性攻击的AI基础设施之一",
      "x_evidence": "黑客正在系统性地攻击AI基础设施:ChromaDB。",
      "x_confidence": 0.86
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--b4f87732-61b1-427b-a39a-dd160dbd5d0d",
      "name": "MCP服务器",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "被黑客系统性攻击的AI基础设施之一",
      "x_evidence": "黑客正在系统性地攻击AI基础设施:MCP服务器。",
      "x_confidence": 0.86
    },
    {
      "type": "intrusion-set",
      "spec_version": "2.1",
      "id": "intrusion-set--2800d20a-6aa7-4c29-a1da-03c95149736b",
      "name": "Qilin",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "利用LiteLLM漏洞链绕过认证实现远程代码执行的勒索组织",
      "x_evidence": "Qilin勒索组织已经下场,利用LiteLLM漏洞链绕过认证实现远程代码执行。",
      "x_confidence": 0.95
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--2a8ea02e-6759-440a-a289-328258f42c4f",
      "name": "LiteLLM_ProxyModelTable",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "PostgreSQL数据库中包含模型配置的表",
      "x_evidence": "攻击者直接翻PostgreSQL数据库里的LiteLLM_ProxyModelTable表。",
      "x_confidence": 0.9
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--68e9a2cf-5835-4d57-b068-e3974ca01160",
      "name": "LiteLLM_VerificationToken",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "PostgreSQL数据库中包含密钥材料的表",
      "x_evidence": "攻击者直接翻PostgreSQL数据库里的LiteLLM_VerificationToken表。",
      "x_confidence": 0.9
    },
    {
      "type": "malware",
      "spec_version": "2.1",
      "id": "malware--1b2eef26-0251-40e5-bb90-9c04202dd9a2",
      "name": "XMRig",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "被植入用于挖矿的程序",
      "x_evidence": "顺手再种一个XMRig挖矿程序。",
      "x_confidence": 0.96
    },
    {
      "type": "observed-data",
      "spec_version": "2.1",
      "id": "observed-data--7315861a-c1cf-4e85-86b5-604eb3447adc",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "first_observed": "2026-09-04T01:42:36Z",
      "last_observed": "2026-09-04T01:42:36Z",
      "number_observed": 1,
      "objects": {
        "0": {
          "type": "file",
          "name": "authorized_keys",
          "description": "可能被改动的文件,用于留下后门",
          "aliases": [],
          "evidence": "重点关注宿主机上的陌生挖矿进程、authorized_keys文件被改动。",
          "confidence": 0.65
        }
      }
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--fd70a925-87e7-43cc-a804-4e3b20868d58",
      "relationship_type": "indicates",
      "source_ref": "identity--f901d515-9ed9-45d6-ad8f-7464761fde48",
      "target_ref": "vulnerability--f715f8f4-7205-4fff-9203-1e43a06e36e2",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "CISA将该漏洞列入KEV目录",
      "x_evidence": "CISA将7个已被在野利用的漏洞列入KEV目录。",
      "x_confidence": 0.98
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--274c45fc-40d0-408f-9c59-5d426764e162",
      "relationship_type": "indicates",
      "source_ref": "identity--f901d515-9ed9-45d6-ad8f-7464761fde48",
      "target_ref": "vulnerability--aed30b55-7441-4209-86e7-4b4903977fa3",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "CISA将该漏洞列入KEV目录",
      "x_evidence": "CISA将7个已被在野利用的漏洞列入KEV目录。",
      "x_confidence": 0.98
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--72a5b52f-44f7-4df9-b43b-39143cad5142",
      "relationship_type": "indicates",
      "source_ref": "identity--f901d515-9ed9-45d6-ad8f-7464761fde48",
      "target_ref": "vulnerability--994a88c9-9a83-4e95-8470-ff59f66ed3f2",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "CISA将该漏洞列入KEV目录",
      "x_evidence": "CISA将7个已被在野利用的漏洞列入KEV目录。",
      "x_confidence": 0.98
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d2fc61e6-61f3-43da-a337-036dddaefc56",
      "relationship_type": "indicates",
      "source_ref": "identity--f901d515-9ed9-45d6-ad8f-7464761fde48",
      "target_ref": "vulnerability--db0a8dff-77d5-44d6-909f-e0b64d8bbb64",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "CISA将该漏洞列入KEV目录",
      "x_evidence": "CISA将7个已被在野利用的漏洞列入KEV目录。",
      "x_confidence": 0.98
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--609e3276-ce1c-4f3b-b4cc-ce4b8892abc3",
      "relationship_type": "indicates",
      "source_ref": "identity--f901d515-9ed9-45d6-ad8f-7464761fde48",
      "target_ref": "vulnerability--303a3e77-db4c-4c88-9019-143685d8382d",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "CISA将该漏洞列入KEV目录",
      "x_evidence": "CISA将7个已被在野利用的漏洞列入KEV目录。",
      "x_confidence": 0.98
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--dc6b4a91-5a1e-49e4-9861-076378a9ca56",
      "relationship_type": "indicates",
      "source_ref": "identity--f901d515-9ed9-45d6-ad8f-7464761fde48",
      "target_ref": "vulnerability--c3b05d1b-0cf8-4923-b74a-fdebd3440249",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "CISA将该漏洞列入KEV目录",
      "x_evidence": "CISA将7个已被在野利用的漏洞列入KEV目录。",
      "x_confidence": 0.98
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--94f25534-0397-45ae-86a1-1eb917cf32fa",
      "relationship_type": "indicates",
      "source_ref": "identity--f901d515-9ed9-45d6-ad8f-7464761fde48",
      "target_ref": "vulnerability--2d4b0d6a-63c8-4ae8-bc3d-28518ebc9ee8",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "CISA将该漏洞列入KEV目录",
      "x_evidence": "CISA将7个已被在野利用的漏洞列入KEV目录。",
      "x_confidence": 0.98
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--4c6c8776-90e1-4b79-b465-2a1585ebb9ed",
      "relationship_type": "exploits",
      "source_ref": "intrusion-set--2800d20a-6aa7-4c29-a1da-03c95149736b",
      "target_ref": "vulnerability--2d4b0d6a-63c8-4ae8-bc3d-28518ebc9ee8",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "Qilin利用CVE-2026-59822绕过认证实现远程代码执行",
      "x_evidence": "Qilin勒索组织利用LiteLLM漏洞链绕过认证实现远程代码执行。",
      "x_confidence": 0.92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--f4e8d5cc-fd21-43ae-aaa7-97ef12b1be64",
      "relationship_type": "targets",
      "source_ref": "vulnerability--2d4b0d6a-63c8-4ae8-bc3d-28518ebc9ee8",
      "target_ref": "identity--a46fc5b9-887c-493b-8d01-f996d3d0fc32",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "CVE-2026-59822影响LiteLLM的MCP接口",
      "x_evidence": "LiteLLM的MCP接口认证缺陷,CVE-2026-59822。",
      "x_confidence": 0.96
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--222db847-2a82-42cd-bf32-0802f6b2df62",
      "relationship_type": "targets",
      "source_ref": "intrusion-set--2800d20a-6aa7-4c29-a1da-03c95149736b",
      "target_ref": "identity--a46fc5b9-887c-493b-8d01-f996d3d0fc32",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "Qilin攻破LiteLLM网关",
      "x_evidence": "Qilin绕过认证实现远程代码执行,攻击者攻破LiteLLM网关。",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--ebd2a279-1a70-48d4-b4b0-b3e47890d889",
      "relationship_type": "targets",
      "source_ref": "intrusion-set--2800d20a-6aa7-4c29-a1da-03c95149736b",
      "target_ref": "identity--2a8ea02e-6759-440a-a289-328258f42c4f",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "Qilin访问并抽取LiteLLM_ProxyModelTable模型配置表",
      "x_evidence": "攻击者攻破LiteLLM网关后,直接翻PostgreSQL数据库里的LiteLLM_ProxyModelTable。",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d68302b7-62de-45d0-b49b-0f728b91f758",
      "relationship_type": "targets",
      "source_ref": "intrusion-set--2800d20a-6aa7-4c29-a1da-03c95149736b",
      "target_ref": "identity--68e9a2cf-5835-4d57-b068-e3974ca01160",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "Qilin访问并抽取LiteLLM_VerificationToken密钥材料表",
      "x_evidence": "攻击者翻PostgreSQL数据库里的LiteLLM_VerificationToken表,把密钥材料整包拖走。",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1bb84327-6f4e-47e4-807f-9a377af228cb",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--2800d20a-6aa7-4c29-a1da-03c95149736b",
      "target_ref": "malware--1b2eef26-0251-40e5-bb90-9c04202dd9a2",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "Qilin植入XMRig挖矿程序",
      "x_evidence": "顺手再种一个XMRig挖矿程序。",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--9c28cbf9-3f99-4278-a2e3-2c045eafd2cd",
      "relationship_type": "targets",
      "source_ref": "intrusion-set--2800d20a-6aa7-4c29-a1da-03c95149736b",
      "target_ref": "observed-data--7315861a-c1cf-4e85-86b5-604eb3447adc",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "authorized_keys文件可能被改动作为持久化迹象",
      "x_evidence": "重点关注宿主机上的陌生挖矿进程、authorized_keys文件被改动。",
      "x_confidence": 0.55
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--e3ff6722-9885-4455-9b32-b82459057a5b",
      "relationship_type": "targets",
      "source_ref": "vulnerability--f715f8f4-7205-4fff-9203-1e43a06e36e2",
      "target_ref": "identity--1c8c879f-fe4e-4743-b343-2314deba4266",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "CVE-2026-83548影响SonicWall SMA 1000系列设备",
      "x_evidence": "SonicWall SMA 1000系列设备的SSRF漏洞,CVE-2026-83548。",
      "x_confidence": 0.97
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--5a6c50fe-bfa6-4aad-9b23-e7972d89c2f3",
      "relationship_type": "targets",
      "source_ref": "vulnerability--aed30b55-7441-4209-86e7-4b4903977fa3",
      "target_ref": "identity--1c8c879f-fe4e-4743-b343-2314deba4266",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "CVE-2026-83549影响SonicWall SMA 1000系列设备",
      "x_evidence": "同系列的命令注入漏洞,CVE-2026-83549。",
      "x_confidence": 0.97
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--c42d87c7-eb9e-4af2-b106-7cbef9c85ad8",
      "relationship_type": "exploits",
      "source_ref": "vulnerability--f715f8f4-7205-4fff-9203-1e43a06e36e2",
      "target_ref": "vulnerability--aed30b55-7441-4209-86e7-4b4903977fa3",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "CVE-2026-83548与CVE-2026-83549可组成完整攻击链",
      "x_evidence": "两个漏洞正好组成一条完整攻击链。",
      "x_confidence": 0.85
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--8371005a-67ba-44e5-ae09-fe31c7f6fafe",
      "relationship_type": "targets",
      "source_ref": "vulnerability--303a3e77-db4c-4c88-9019-143685d8382d",
      "target_ref": "identity--4f17b5ea-998e-4a8a-9f4f-420b2e342477",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "CVE-2026-49869影响Kestra工作流引擎",
      "x_evidence": "Kestra工作流引擎的命令注入,CVE-2026-49869。",
      "x_confidence": 0.96
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--48767c34-39b1-48f4-94f6-21fbfbdf1e25",
      "relationship_type": "targets",
      "source_ref": "vulnerability--994a88c9-9a83-4e95-8470-ff59f66ed3f2",
      "target_ref": "identity--9ae3f384-75a4-4f35-8a40-29ae1a812397",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "CVE-2026-82329影响JFrog Artifactory制品库",
      "x_evidence": "JFrog Artifactory的认证缺陷,CVE-2026-82329。",
      "x_confidence": 0.96
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--6f9cf4bf-a14a-4286-9687-539c201436e9",
      "relationship_type": "targets",
      "source_ref": "vulnerability--db0a8dff-77d5-44d6-909f-e0b64d8bbb64",
      "target_ref": "identity--248f2d3a-1841-4d5f-9e13-d01449d8d587",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "CVE-2026-9586影响Sangoma Switchvox",
      "x_evidence": "Sangoma Switchvox的SQL注入,CVE-2026-9586。",
      "x_confidence": 0.96
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--53f2bed3-1a10-4f3b-bc70-874a87ccb306",
      "relationship_type": "targets",
      "source_ref": "vulnerability--c3b05d1b-0cf8-4923-b74a-fdebd3440249",
      "target_ref": "identity--e0340642-5aff-4999-bc3d-13b704f59482",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "CVE-2026-48710影响Starlette",
      "x_evidence": "Starlette的HTTP请求走私,CVE-2026-48710。",
      "x_confidence": 0.96
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--aec37684-1013-4cff-8162-7eb9b4279a45",
      "relationship_type": "indicates",
      "source_ref": "identity--b3b2cb59-93cb-449f-8b55-0ae2b6f40a57",
      "target_ref": "identity--a46fc5b9-887c-493b-8d01-f996d3d0fc32",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "微软报告指出LiteLLM被系统性攻击",
      "x_evidence": "微软和Wiz的报告指出黑客正在系统性地攻击AI基础设施。",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--8458574c-c83e-42ff-ba9a-ecec768e92c0",
      "relationship_type": "indicates",
      "source_ref": "identity--b3b2cb59-93cb-449f-8b55-0ae2b6f40a57",
      "target_ref": "identity--12857e40-4a81-48e2-b482-1b295e128816",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "微软报告指出Flowise被系统性攻击",
      "x_evidence": "微软和Wiz的报告指出黑客正在系统性地攻击AI基础设施。",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--e5e6e97e-b59c-4ae1-8dc0-39a1d2610054",
      "relationship_type": "indicates",
      "source_ref": "identity--b3b2cb59-93cb-449f-8b55-0ae2b6f40a57",
      "target_ref": "identity--c9ffc508-7fbe-4d6c-a58e-7035b8e00f58",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "微软报告指出LangChain被系统性攻击",
      "x_evidence": "微软和Wiz的报告指出黑客正在系统性地攻击AI基础设施。",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--39fe1345-26fd-4aa2-9998-f580a0646f93",
      "relationship_type": "indicates",
      "source_ref": "identity--b3b2cb59-93cb-449f-8b55-0ae2b6f40a57",
      "target_ref": "identity--9eee5f4e-5386-4d29-a3ac-c56066a656fc",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "微软报告指出Ollama被系统性攻击",
      "x_evidence": "微软和Wiz的报告指出黑客正在系统性地攻击AI基础设施。",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--0d0c5e50-0bf8-4ede-abb9-5bb5cf543562",
      "relationship_type": "indicates",
      "source_ref": "identity--b3b2cb59-93cb-449f-8b55-0ae2b6f40a57",
      "target_ref": "identity--6e179c9c-0113-4522-b588-6ccab8b12dc4",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "微软报告指出ChromaDB被系统性攻击",
      "x_evidence": "微软和Wiz的报告指出黑客正在系统性地攻击AI基础设施。",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--422b5ad9-1b40-42ba-ade0-96b02909f37f",
      "relationship_type": "indicates",
      "source_ref": "identity--b3b2cb59-93cb-449f-8b55-0ae2b6f40a57",
      "target_ref": "identity--b4f87732-61b1-427b-a39a-dd160dbd5d0d",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "微软报告指出MCP服务器被系统性攻击",
      "x_evidence": "微软和Wiz的报告指出黑客正在系统性地攻击AI基础设施。",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--09049ef7-f417-4c45-9a14-b647cf4fddcc",
      "relationship_type": "indicates",
      "source_ref": "identity--5198c372-a68b-4d40-9dbf-c86704fb1dc4",
      "target_ref": "identity--a46fc5b9-887c-493b-8d01-f996d3d0fc32",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "Wiz报告指出LiteLLM被系统性攻击",
      "x_evidence": "微软和Wiz的报告指出黑客正在系统性地攻击AI基础设施。",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--44d59173-149b-44b4-923f-05564b80bac6",
      "relationship_type": "indicates",
      "source_ref": "identity--5198c372-a68b-4d40-9dbf-c86704fb1dc4",
      "target_ref": "identity--12857e40-4a81-48e2-b482-1b295e128816",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "Wiz报告指出Flowise被系统性攻击",
      "x_evidence": "微软和Wiz的报告指出黑客正在系统性地攻击AI基础设施。",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--93e2bf56-009f-46bc-855c-f4fd1bea3623",
      "relationship_type": "indicates",
      "source_ref": "identity--5198c372-a68b-4d40-9dbf-c86704fb1dc4",
      "target_ref": "identity--c9ffc508-7fbe-4d6c-a58e-7035b8e00f58",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "Wiz报告指出LangChain被系统性攻击",
      "x_evidence": "微软和Wiz的报告指出黑客正在系统性地攻击AI基础设施。",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d86f2a39-5be7-48be-bdf8-3b3e8f8371c4",
      "relationship_type": "indicates",
      "source_ref": "identity--5198c372-a68b-4d40-9dbf-c86704fb1dc4",
      "target_ref": "identity--9eee5f4e-5386-4d29-a3ac-c56066a656fc",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "Wiz报告指出Ollama被系统性攻击",
      "x_evidence": "微软和Wiz的报告指出黑客正在系统性地攻击AI基础设施。",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--8baad6d3-7ac7-463c-b2cf-5994c17750f0",
      "relationship_type": "indicates",
      "source_ref": "identity--5198c372-a68b-4d40-9dbf-c86704fb1dc4",
      "target_ref": "identity--6e179c9c-0113-4522-b588-6ccab8b12dc4",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "Wiz报告指出ChromaDB被系统性攻击",
      "x_evidence": "微软和Wiz的报告指出黑客正在系统性地攻击AI基础设施。",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--e13a5e61-52f4-460f-9b0d-52cc916bdb76",
      "relationship_type": "indicates",
      "source_ref": "identity--5198c372-a68b-4d40-9dbf-c86704fb1dc4",
      "target_ref": "identity--b4f87732-61b1-427b-a39a-dd160dbd5d0d",
      "created": "2026-09-04T01:42:36Z",
      "modified": "2026-09-04T01:42:36Z",
      "description": "Wiz报告指出MCP服务器被系统性攻击",
      "x_evidence": "微软和Wiz的报告指出黑客正在系统性地攻击AI基础设施。",
      "x_confidence": 0.9
    }
  ]
}

报告链接:

http://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790451&idx=1&sn=8dfae39e2b70514d7beb78ba0e053345

───────────────────────────────────

(五)泄露AWS凭据被用于LLMjacking盗用模型资源

事件名称:其他人正在使用您的AI

发布日期:2026-09-03

发布机构:FortiGuard Labs

威胁概述:

FortiGuard Labs披露,攻击者利用泄露且具有AdministratorAccess权限的长期AWS IAM访问密钥进入云账户,创建新的IAM身份,并通过AWS Marketplace订阅基础AI模型。攻击者随后调用模型产生高额推理费用,或转售模型访问权,形成LLMjacking风险。

IOC指标:

· 暂无公开IOC

STIX详情:

{
  "type": "bundle",
  "id": "bundle--2d9e784a-5205-477d-8f18-470a14e890a9",
  "spec_version": "2.1",
  "objects": [
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--19136d59-674b-45c5-a766-2e1b54f11b3a",
      "name": "Cloud credential theft",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "窃取云服务访问凭证的攻击行为",
      "x_evidence": "原文 Threat Type 列为 Cloud credential theft",
      "x_confidence": 0.9
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--51fa40fd-54c7-40af-8cea-6b76e3a545fa",
      "name": "AI/LLM service hijacking",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "劫持人工智能或大型语言模型服务访问权限的攻击行为,在攻击链中亦称为 LLMjacking",
      "aliases": [
        "LLMjacking"
      ],
      "x_evidence": "原文 Threat Type 列为 AI/LLM service hijacking (\"LLMjacking\")",
      "x_confidence": 0.95
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--bd3021a6-7c91-4b43-b3e8-fe99b820b50e",
      "name": "CreateAgreementRequest",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "用于在 AWS Marketplace 订阅基础模型的 API 请求/命令",
      "x_evidence": "原文称 Subscribed ... (CreateAgreementRequest/AcceptAgreementRequest on agreement-marketplace.amazonaws.com)",
      "x_confidence": 0.85
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--d9e774ff-504b-47d0-a1f5-e964b4a5a1a4",
      "name": "AcceptAgreementRequest",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "用于在 AWS Marketplace 接受订阅基础模型协议的 API 请求/命令",
      "x_evidence": "原文称 CreateAgreementRequest/AcceptAgreementRequest on agreement-marketplace.amazonaws.com",
      "x_confidence": 0.85
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--c2b5c215-41ed-4d9b-9bc6-86e769b2b8fa",
      "name": "InvokeModel",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "调用 Amazon Bedrock 模型 API 的命令/调用操作",
      "x_evidence": "原文称 Invoked the subscribed foundation model(s), generating inference charges against the victim account",
      "x_confidence": 0.85
    },
    {
      "type": "domain-name",
      "spec_version": "2.1",
      "id": "domain-name--66a5f1d8-4ec8-48fc-b517-46a8462a2655",
      "name": "agreement-marketplace.amazonaws.com",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "AWS Marketplace 协议订阅相关域名",
      "x_evidence": "原文称 CreateAgreementRequest/AcceptAgreementRequest on agreement-marketplace.amazonaws.com",
      "x_confidence": 0.95
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--85999d88-a260-4a67-beab-0c9e798fa570",
      "name": "Leaked long-term AWS IAM access key",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "泄露的长期 AWS IAM 访问密钥,具有 AdministratorAccess 权限",
      "aliases": [
        "AdministratorAccess key"
      ],
      "x_evidence": "原文称 leaked long-lived AWS IAM access key with AdministratorAccess permissions was used",
      "x_confidence": 0.9
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--39d700b9-7798-452b-8667-4eafebac5c09",
      "name": "New IAM user",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "使用泄露凭据创建的新的 IAM 用户",
      "x_evidence": "原文称 Created a new IAM user",
      "x_confidence": 0.9
    },
    {
      "type": "infrastructure",
      "spec_version": "2.1",
      "id": "infrastructure--1c6d8bc3-7991-4e37-949b-63f13382bb56",
      "name": "Victim AWS account",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "被滥用的受害者 AWS 账户",
      "x_evidence": "原文称 An AWS account was compromised",
      "x_confidence": 0.9
    },
    {
      "type": "infrastructure",
      "spec_version": "2.1",
      "id": "infrastructure--50328992-d303-4567-bc9a-32adbc85fbd3",
      "name": "AWS Marketplace",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "用于订阅基础模型的 AWS Marketplace 服务",
      "x_evidence": "原文称 through AWS Marketplace",
      "x_confidence": 0.9
    },
    {
      "type": "infrastructure",
      "spec_version": "2.1",
      "id": "infrastructure--5397aa09-37e9-42df-9810-b16eb5c31afc",
      "name": "Amazon Bedrock",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "托管模型推理服务,InvokeModel 调用目标",
      "aliases": [
        "Bedrock"
      ],
      "x_evidence": "原文涉及 Amazon Bedrock 未授权访问",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--40d56349-63c7-4edc-9581-644a3dfbd7eb",
      "relationship_type": "uses",
      "source_ref": "attack-pattern--51fa40fd-54c7-40af-8cea-6b76e3a545fa",
      "target_ref": "attack-pattern--19136d59-674b-45c5-a766-2e1b54f11b3a",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "AI/LLM 服务劫持利用云凭据窃取获得的访问权限",
      "x_evidence": "原文将 Cloud credential theft 与 AI/LLM service hijacking 列为威胁类型,并称 leaked key 被用于 Bedrock 滥用",
      "x_confidence": 0.8
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--5b440e66-dcc1-476c-8438-7de9ce88679e",
      "relationship_type": "uses",
      "source_ref": "attack-pattern--51fa40fd-54c7-40af-8cea-6b76e3a545fa",
      "target_ref": "attack-pattern--bd3021a6-7c91-4b43-b3e8-fe99b820b50e",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "AI/LLM 服务劫持使用 CreateAgreementRequest 订阅基础模型",
      "x_evidence": "原文称 CreateAgreementRequest/AcceptAgreementRequest on agreement-marketplace.amazonaws.com 是订阅步骤",
      "x_confidence": 0.85
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--0e3c2c6d-1227-42bd-b2c3-5f0b9d63517f",
      "relationship_type": "uses",
      "source_ref": "attack-pattern--51fa40fd-54c7-40af-8cea-6b76e3a545fa",
      "target_ref": "attack-pattern--d9e774ff-504b-47d0-a1f5-e964b4a5a1a4",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "AI/LLM 服务劫持使用 AcceptAgreementRequest 接受订阅协议",
      "x_evidence": "原文称 CreateAgreementRequest/AcceptAgreementRequest on agreement-marketplace.amazonaws.com 是订阅步骤",
      "x_confidence": 0.85
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--720f2382-c99c-4e15-a486-00227cc32830",
      "relationship_type": "uses",
      "source_ref": "attack-pattern--51fa40fd-54c7-40af-8cea-6b76e3a545fa",
      "target_ref": "attack-pattern--c2b5c215-41ed-4d9b-9bc6-86e769b2b8fa",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "AI/LLM 服务劫持使用 InvokeModel 调用模型",
      "x_evidence": "原文称 Invoked the subscribed foundation model(s)",
      "x_confidence": 0.85
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1b4c6255-1250-4a31-a9ad-bc78a0b59776",
      "relationship_type": "targets",
      "source_ref": "attack-pattern--bd3021a6-7c91-4b43-b3e8-fe99b820b50e",
      "target_ref": "domain-name--66a5f1d8-4ec8-48fc-b517-46a8462a2655",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "CreateAgreementRequest 针对 agreement-marketplace.amazonaws.com 发起",
      "x_evidence": "原文称 CreateAgreementRequest on agreement-marketplace.amazonaws.com",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--3132ba17-cafe-4d02-86ae-fe7cb7e98257",
      "relationship_type": "targets",
      "source_ref": "attack-pattern--d9e774ff-504b-47d0-a1f5-e964b4a5a1a4",
      "target_ref": "domain-name--66a5f1d8-4ec8-48fc-b517-46a8462a2655",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "AcceptAgreementRequest 针对 agreement-marketplace.amazonaws.com 发起",
      "x_evidence": "原文称 AcceptAgreementRequest on agreement-marketplace.amazonaws.com",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--30e5f573-eedd-442a-9e8a-71350ad72263",
      "relationship_type": "targets",
      "source_ref": "attack-pattern--c2b5c215-41ed-4d9b-9bc6-86e769b2b8fa",
      "target_ref": "infrastructure--5397aa09-37e9-42df-9810-b16eb5c31afc",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "InvokeModel 针对 Amazon Bedrock 发起推理调用",
      "x_evidence": "原文称 Invoked the subscribed foundation model(s),并提及 Amazon Bedrock",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--696793a1-3588-4ccd-b08f-b7e1ff301b58",
      "relationship_type": "uses",
      "source_ref": "attack-pattern--51fa40fd-54c7-40af-8cea-6b76e3a545fa",
      "target_ref": "identity--85999d88-a260-4a67-beab-0c9e798fa570",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "AI/LLM 服务劫持使用泄露的长期 AWS IAM 访问密钥",
      "x_evidence": "原文称 long-lived AWS IAM access key with administrator privileges was used",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--8cfab17f-6923-421b-ba07-ba1de02a1398",
      "relationship_type": "targets",
      "source_ref": "attack-pattern--51fa40fd-54c7-40af-8cea-6b76e3a545fa",
      "target_ref": "infrastructure--1c6d8bc3-7991-4e37-949b-63f13382bb56",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "AI/LLM 服务劫持滥用受害者 AWS 账户",
      "x_evidence": "原文称 An AWS account was compromised,并产生 inference charges against the victim account",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--e350700e-5084-41d0-b37c-087ae27d9347",
      "relationship_type": "uses",
      "source_ref": "identity--85999d88-a260-4a67-beab-0c9e798fa570",
      "target_ref": "identity--39d700b9-7798-452b-8667-4eafebac5c09",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "新 IAM 用户是使用泄露的长期 AWS IAM 访问密钥创建的",
      "x_evidence": "原文称 Using that access, the operator: Created a new IAM user",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--e7199535-81b4-41e5-b2c4-0b358ca1781f",
      "relationship_type": "uses",
      "source_ref": "attack-pattern--51fa40fd-54c7-40af-8cea-6b76e3a545fa",
      "target_ref": "identity--39d700b9-7798-452b-8667-4eafebac5c09",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "AI/LLM 服务劫持使用新创建的 IAM 用户完成后续访问",
      "x_evidence": "原文观察到攻击者使用泄露密钥创建新 IAM 用户后订阅并调用模型",
      "x_confidence": 0.85
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--ebe5a325-feaa-4d49-bcfa-ad843fa52abf",
      "relationship_type": "uses",
      "source_ref": "identity--39d700b9-7798-452b-8667-4eafebac5c09",
      "target_ref": "infrastructure--50328992-d303-4567-bc9a-32adbc85fbd3",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "新 IAM 用户通过 AWS Marketplace 订阅基础模型",
      "x_evidence": "原文称 Created a new IAM user. Subscribed ... through AWS Marketplace",
      "x_confidence": 0.85
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--9a752436-a3d8-46ab-9914-399c67194af0",
      "relationship_type": "uses",
      "source_ref": "identity--39d700b9-7798-452b-8667-4eafebac5c09",
      "target_ref": "infrastructure--5397aa09-37e9-42df-9810-b16eb5c31afc",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "新 IAM 用户被用于调用 Amazon Bedrock 已订阅模型",
      "x_evidence": "原文称 Created a new IAM user ... and begin invoking them",
      "x_confidence": 0.85
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--253ba4e8-5fe8-4f94-82ea-0a30cbf48d27",
      "relationship_type": "uses",
      "source_ref": "infrastructure--1c6d8bc3-7991-4e37-949b-63f13382bb56",
      "target_ref": "identity--39d700b9-7798-452b-8667-4eafebac5c09",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "新 IAM 用户在受害者 AWS 账户中被创建",
      "x_evidence": "原文称 An AWS account was compromised ... Created a new IAM user",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1aeb0a97-c4b0-43f2-83c9-5237144de479",
      "relationship_type": "consists-of",
      "source_ref": "infrastructure--50328992-d303-4567-bc9a-32adbc85fbd3",
      "target_ref": "domain-name--66a5f1d8-4ec8-48fc-b517-46a8462a2655",
      "created": "2026-09-03T16:46:39Z",
      "modified": "2026-09-03T16:46:39Z",
      "description": "AWS Marketplace 基础设施包含 agreement-marketplace.amazonaws.com 域名",
      "x_evidence": "原文称 CreateAgreementRequest/AcceptAgreementRequest on agreement-marketplace.amazonaws.com",
      "x_confidence": 0.9
    }
  ]
}

报告链接:

https://www.fortinet.com/blog/threat-research/someone-else-is-using-your-ai

───────────────────────────────────

(六)AI辅助NodeStealer扩展为全功能间谍软件

事件名称:Python NodeStealer:AI辅助成为全面间谍软件

发布日期:2026-09-02

发布机构:Netskope Threat Labs

威胁概述:

Netskope发现Python版NodeStealer新变种增加了AI辅助编写的按键记录、剪贴板监控和截图功能,并可查询20多个Facebook Graph API端点收集账户信息。恶意程序通过两个Telegram C2机器人通道分别回传操作数据和Facebook专用数据,主要影响金融服务等行业。

IOC指标:

· 暂无公开IOC

STIX详情:

{
  "type": "bundle",
  "id": "bundle--108f5ccd-3dbe-4048-a223-1a4e8dd5ca24",
  "spec_version": "2.1",
  "objects": [
    {
      "type": "intrusion-set",
      "spec_version": "2.1",
      "id": "intrusion-set--83b241ba-2c15-4df5-b95b-3c0b6d0cc0e4",
      "name": "Unknown Threat Actor",
      "created": "2026-09-03T04:36:24Z",
      "modified": "2026-09-03T04:36:24Z",
      "description": "未具名攻击者/威胁行为者,利用 Python NodeStealer 实施攻击,目标受害者主要位于亚洲和北美,金融服务业领先。",
      "x_evidence": "原文未具名,多处以 cyberattackers/threat actor 指代。",
      "x_confidence": 0.85
    },
    {
      "type": "malware",
      "spec_version": "2.1",
      "id": "malware--154bcab0-458c-40b6-9047-6f890029c92a",
      "name": "Python NodeStealer",
      "created": "2026-09-03T04:36:24Z",
      "modified": "2026-09-03T04:36:24Z",
      "description": "基于 Python 的信息窃取恶意软件,窃取浏览器敏感数据、Facebook 用户及 Ads Manager 账户;新变种新增键盘记录、剪贴板监控、截图捕获等间谍软件功能。Netskope 将其检测为 Script-Python.Infostealer、Trojan.Stealer.130、Trojan.Generic.39958647。",
      "aliases": [
        "NodeStealer",
        "Script-Python.Infostealer",
        "Trojan.Stealer.130",
        "Trojan.Generic.39958647"
      ],
      "x_evidence": "原文称 'Python NodeStealer',Netskope Threat Protection 检测为 Script-Python.Infostealer、Trojan.Stealer.130、Trojan.Generic.39958647。",
      "x_confidence": 0.96
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--0e869b07-0d23-4da9-afc5-723d1cdbf4b9",
      "name": "Telegram",
      "created": "2026-09-03T04:36:24Z",
      "modified": "2026-09-03T04:36:24Z",
      "description": "被攻击者用作命令与控制(C2)通信工具;最新变种使用双 Telegram bot 架构。",
      "x_evidence": "原文称 'dual bot Telegram C2 architecture' 和 'Telegram C2 channel'。",
      "x_confidence": 0.95
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--34612730-2c8a-4283-b358-e23e693365de",
      "name": "Victims in Asia and North America",
      "created": "2026-09-03T04:36:24Z",
      "modified": "2026-09-03T04:36:24Z",
      "description": "目标受害者主要位于亚洲和北美,跨多个行业,金融服务业领先。",
      "x_evidence": "原文称 'The campaign’s target victims were mainly in Asia and North America...led by the financial services sector'。",
      "x_confidence": 0.9
    },
    {
      "type": "observed-data",
      "spec_version": "2.1",
      "id": "observed-data--116ea284-33e8-43b7-9dc5-6f6a2012d01f",
      "created": "2026-09-03T04:36:24Z",
      "modified": "2026-09-03T04:36:24Z",
      "first_observed": "2026-09-03T04:36:24Z",
      "last_observed": "2026-09-03T04:36:24Z",
      "number_observed": 1,
      "objects": {
        "0": {
          "type": "file",
          "name": "keylog({ip}).txt",
          "description": "用于记录用户键盘输入的文件,保存在临时文件夹,并每 120 秒发送至主 Telegram C2 通道后清除内容。",
          "aliases": [],
          "evidence": "原文称 'All recorded keystrokes are saved in the temporary folder using keylog({ip}).txt file name'。",
          "confidence": 0.95
        }
      }
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--fb48eccd-39db-4fd6-b5da-4d88535c414b",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--83b241ba-2c15-4df5-b95b-3c0b6d0cc0e4",
      "target_ref": "malware--154bcab0-458c-40b6-9047-6f890029c92a",
      "created": "2026-09-03T04:36:24Z",
      "modified": "2026-09-03T04:36:24Z",
      "description": "未具名攻击者使用 Python NodeStealer 实施信息窃取和间谍活动。",
      "x_evidence": "原文描述 cyberattackers 利用 NodeStealer 的新能力,如监控剪贴板。",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--768ffeaf-9472-48c1-bf49-20369e4068f3",
      "relationship_type": "uses",
      "source_ref": "malware--154bcab0-458c-40b6-9047-6f890029c92a",
      "target_ref": "tool--0e869b07-0d23-4da9-afc5-723d1cdbf4b9",
      "created": "2026-09-03T04:36:24Z",
      "modified": "2026-09-03T04:36:24Z",
      "description": "Python NodeStealer 使用 Telegram 作为 C2 通道,双 bot 分别接收主数据与 Facebook 数据。",
      "x_evidence": "原文称 'dual bot Telegram C2 architecture';主 Telegram bot 接收主 ZIP,第二 bot 接收 Facebook 数据。",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--6f6d4969-bb4d-4428-8771-9d7aaf75e8f8",
      "relationship_type": "uses",
      "source_ref": "malware--154bcab0-458c-40b6-9047-6f890029c92a",
      "target_ref": "observed-data--116ea284-33e8-43b7-9dc5-6f6a2012d01f",
      "created": "2026-09-03T04:36:24Z",
      "modified": "2026-09-03T04:36:24Z",
      "description": "Python NodeStealer 将键盘记录写入 keylog({ip}).txt 文件。",
      "x_evidence": "原文称 'All recorded keystrokes are saved in the temporary folder using keylog({ip}).txt file name'。",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--31eaca2d-569a-428d-8904-f8e1378a009b",
      "relationship_type": "targets",
      "source_ref": "intrusion-set--83b241ba-2c15-4df5-b95b-3c0b6d0cc0e4",
      "target_ref": "identity--34612730-2c8a-4283-b358-e23e693365de",
      "created": "2026-09-03T04:36:24Z",
      "modified": "2026-09-03T04:36:24Z",
      "description": "攻击目标受害者主要位于亚洲和北美,跨多个行业,金融服务业领先。",
      "x_evidence": "原文称 'The campaign’s target victims were mainly in Asia and North America...led by the financial services sector'。",
      "x_confidence": 0.9
    }
  ]
}

报告链接:

https://www.netskope.com/blog/python-nodestealer-ai-assisted-to-full-spyware

───────────────────────────────────

(七)研究人员使用Claude跨设备移植工控漏洞利用

事件名称:安全专家用Claude将工控漏洞利用跨设备移植

发布日期:2026-09-02

发布机构:安全圈

威胁概述:

素材显示,Forescout实验室研究人员使用Claude大模型,在8小时内将CVE-2021-31886漏洞利用跨设备移植至WAGO控制器。Claude辅助修改协议时序并保留攻击载荷,最终实现ARM Shellcode执行。该实验说明,AI可降低工控漏洞利用适配不同设备和协议实现的技术成本。

IOC指标:

· CVE:CVE-2021-31886

报告链接:

http://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078593&idx=3&sn=b27684913ac539add1c5dbc2ff39eb66

───────────────────────────────────

(八)AI与智能体框架辅助企业网络勒索攻击

事件名称:一场AI辅助的网络攻击:深入Unit 42调查

发布日期:2026-09-02

发布机构:Palo Alto Networks Unit 42

威胁概述:

Unit 42调查显示,攻击者利用前沿AI和智能体AI框架对企业网络实施勒索攻击,在不到10小时内完成多阶段行动。攻击者首先破坏公共API端点并部署自动化侦察智能体,随后梳理代码库提取硬编码令牌和密码,利用暴露凭据获取根权限、窃取云访问密钥,并劫持受害者AI基础设施用于后续攻击。

IOC指标:

· 暂无公开IOC

STIX详情:

{
  "type": "bundle",
  "id": "bundle--3a9d50cc-cd3c-4db0-9d71-85b4e9152798",
  "spec_version": "2.1",
  "objects": [
    {
      "type": "intrusion-set",
      "spec_version": "2.1",
      "id": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "name": "未具名威胁行为者",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "未具名人类攻击者/威胁行为者,在勒索软件攻击中使用前沿 AI 模型及攻击专用 agentic AI 框架实施自动化入侵。",
      "x_evidence": "原文:a human attacker used frontier AI to breach an enterprise network autonomously as part of a ransomware attack;threat actor told us they leveraged frontier AI models and attack-specific agentic AI frameworks。",
      "x_confidence": 0.95
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--13ef2275-eaa9-434c-84a5-450c57500075",
      "name": "Exploit Public-Facing Application",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "初始访问与侦察阶段:利用公共 API 端点入侵。对应 MITRE ATT&CK T1190。",
      "x_evidence": "原文:The actor breached a public API endpoint to tunnel into the network;Table 1:T1190: Exploit Public-Facing Application。",
      "x_confidence": 0.95
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--9de80a5f-b1a6-41ce-a6b3-c4568f025bf8",
      "name": "Network Service Discovery",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "初始访问与侦察阶段:使用服务发现工具自动化映射内部微服务。对应 MITRE ATT&CK T1046。",
      "x_evidence": "原文:deploying an automated recon agent to map internal microservices;Table 1:T1046: Network Service Discovery。",
      "x_confidence": 0.94
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--70625df9-9ee4-4a49-b829-6a9a7e1a847e",
      "name": "Initial Access",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "初始访问与侦察阶段在 MITRE ATLAS 中的映射。对应 AML.T0000。",
      "x_evidence": "Table 1:AML.T0000: Initial Access。",
      "x_confidence": 0.92
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--63b42859-8f7c-488c-b3d9-fe070fce9301",
      "name": "AI-Automated Reconnaissance",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "初始访问与侦察阶段在 MITRE ATLAS 中的 AI 自动化侦察映射。对应 AML.T0002。",
      "x_evidence": "Table 1:AML.T0002: AI-Automated Reconnaissance。",
      "x_confidence": 0.92
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--e02b0f15-543b-4124-8c71-ed55156715eb",
      "name": "Credentials In Files",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "凭据访问阶段:搜索企业代码仓库,抓取硬编码 token 和服务密码。对应 MITRE ATT&CK T1552.001。",
      "x_evidence": "原文:Sub-agents combed enterprise code repositories, extracting hard-coded tokens and service passwords;Table 1:T1552.001: Credentials In Files。",
      "x_confidence": 0.95
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--4bc9dcc4-abcb-4d26-9d81-79f85176716f",
      "name": "Credentials Harvesting",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "凭据访问阶段在 MITRE ATLAS 中的映射。对应 AML.T0014。",
      "x_evidence": "Table 1:AML.T0014: Credentials Harvesting。",
      "x_confidence": 0.92
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--49de59cc-95d8-4652-8217-e36b1641f106",
      "name": "Credentials from Password Stores",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "权限提升阶段:入侵秘密管理系统,从密码存储中获取管理员系统凭据。对应 MITRE ATT&CK T1555。",
      "x_evidence": "原文:the actor infiltrated the secrets management system, harvesting master administrative credentials;Table 1:T1555: Credentials from Password Stores。",
      "x_confidence": 0.95
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--b27881c3-9fbf-40b2-bc9f-185bd4283120",
      "name": "Privilege Escalation via Automated Pivot",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "权限提升阶段在 MITRE ATLAS 中的映射。对应 AML.T0016。",
      "x_evidence": "Table 1:AML.T0016: Privilege Escalation via Automated Pivot。",
      "x_confidence": 0.92
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--14ffaf2e-7731-48fa-9b15-f2e042f455ee",
      "name": "Modify Cloud Compute Infrastructure",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "流水线滥用/云基础设施修改阶段:执行 CI/CD 操作并尝试编辑云配置。对应 MITRE ATT&CK T1578。",
      "x_evidence": "原文:The agents also triggered unauthorized CI/CD builds;They attempted to plant backdoors in Terraform configurations;Table 1:T1578: Modify Cloud Compute Infrastructure。",
      "x_confidence": 0.94
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--d47bcb0d-c98d-4238-ac9c-21d2314ff201",
      "name": "ML/DevOps Pipeline Interception",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "流水线滥用/云基础设施修改阶段在 MITRE ATLAS 中的映射。对应 AML.T0010。",
      "x_evidence": "Table 1:AML.T0010: ML/DevOps Pipeline Interception。",
      "x_confidence": 0.93
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--fe62345a-af98-42e0-8bdf-b86bbc8abc97",
      "name": "Valid Accounts",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "AI 基础设施劫持阶段:使用窃取的云密钥调用云 AI 模型。对应 MITRE ATT&CK T1078。",
      "x_evidence": "原文:Using stolen cloud keys, the actor turned the victim’s AI endpoints into post-compromise infrastructure;Table 1:T1078: Valid Accounts。",
      "x_confidence": 0.93
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--7d5cf373-3cf5-4273-8369-dcf7e7be7df9",
      "name": "LLM Invocations via Stolen API Keys",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "AI 基础设施劫持阶段在 MITRE ATLAS 中的映射。对应 AML.T0043。",
      "x_evidence": "Table 1:AML.T0043: LLM Invocations via Stolen API Keys。",
      "x_confidence": 0.93
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--c567cf57-02e6-44be-a4f2-5ea16386f53b",
      "name": "AI 代理与攻击专用 agentic AI 框架",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "攻击者使用的自主 AI 代理和攻击专用 agentic AI 框架,以监控-评估-行动-重规划循环执行入侵。",
      "x_evidence": "原文:Using autonomous AI agents;attack-specific agentic AI frameworks;The agents that monitored, evaluated, acted and re-planned in real time。",
      "x_confidence": 0.95
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--083b4821-da47-432b-b56c-4fa86581f643",
      "name": "自定义脚本与自定义工作流",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "攻击者用于管理动态操作的 AI 生成自定义脚本,以及用于劫持企业代码应用、窃取云访问密钥的自定义工作流。",
      "x_evidence": "原文:Custom scripts (assessed with high confidence to be AI-generated due to UI elements) managing dynamic operations;hijacked an enterprise code application via custom workflows to exfiltrate cloud access keys。",
      "x_confidence": 0.9
    },
    {
      "type": "infrastructure",
      "spec_version": "2.1",
      "id": "infrastructure--8a19d86c-626d-4f31-b9e4-bc157741401a",
      "name": "受害方公共 API 端点",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "被攻击者利用作为初始入口的公共 API 端点;原文未提供具体 URL、域名或 IP。",
      "x_evidence": "原文:The actor breached a public API endpoint to tunnel into the network。",
      "x_confidence": 0.94
    },
    {
      "type": "infrastructure",
      "spec_version": "2.1",
      "id": "infrastructure--a6470dad-3af2-49f1-9a61-1588b3647c5e",
      "name": "受害方内部微服务",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "被自动化侦察代理映射的受害方内部微服务。",
      "x_evidence": "原文:deploying an automated recon agent to map internal microservices。",
      "x_confidence": 0.93
    },
    {
      "type": "infrastructure",
      "spec_version": "2.1",
      "id": "infrastructure--630ff70d-6ad1-4747-bc90-8139624ecf5f",
      "name": "企业代码仓库",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "被 AI 子代理搜索并提取硬编码 token 和服务密码的企业代码仓库。",
      "x_evidence": "原文:Sub-agents combed enterprise code repositories, extracting hard-coded tokens and service passwords。",
      "x_confidence": 0.95
    },
    {
      "type": "infrastructure",
      "spec_version": "2.1",
      "id": "infrastructure--12dabd18-bb80-4c89-8c12-bf42f1e8575a",
      "name": "秘密管理系统",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "被入侵并用于获取管理员系统凭据/主管理员凭据的秘密管理系统。",
      "x_evidence": "原文:the actor infiltrated the secrets management system, harvesting master administrative credentials。",
      "x_confidence": 0.95
    },
    {
      "type": "infrastructure",
      "spec_version": "2.1",
      "id": "infrastructure--1f746272-c050-4348-8c82-b7144b89c6a8",
      "name": "CI/CD 流水线",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "被触发未授权构建并用于建立持久性的 CI/CD 流水线。",
      "x_evidence": "原文:The agents also triggered unauthorized continuous integration/continuous delivery (CI/CD) builds;CI/CD pipelines。",
      "x_confidence": 0.95
    },
    {
      "type": "infrastructure",
      "spec_version": "2.1",
      "id": "infrastructure--33f700ef-e014-4ee9-9890-f1c96f93f5d1",
      "name": "Terraform 配置",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "攻击者尝试植入后门但被硬分支保护控制阻止的 Terraform 配置。",
      "x_evidence": "原文:They attempted to plant backdoors in Terraform configurations, but hard branch-protection controls stopped this。",
      "x_confidence": 0.94
    },
    {
      "type": "infrastructure",
      "spec_version": "2.1",
      "id": "infrastructure--228be810-3753-4c55-83a4-977b3b9d18fc",
      "name": "云 AI 端点",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "被窃取的云密钥调用并劫持为攻击者后渗透基础设施的受害者云 AI 模型/端点。",
      "x_evidence": "原文:Using stolen cloud keys, the actor turned the victim’s AI endpoints into post-compromise infrastructure。",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--ed8fc72b-3048-4fb6-9d97-b0171714be09",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "attack-pattern--13ef2275-eaa9-434c-84a5-450c57500075",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "攻击者在初始访问阶段利用公共 API 端点,使用 T1190 Exploit Public-Facing Application 技术。",
      "x_evidence": "原文:The actor breached a public API endpoint to tunnel into the network;Table 1:T1190: Exploit Public-Facing Application。",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d1d63b51-ac40-458d-bf57-f2ea685a3028",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "attack-pattern--70625df9-9ee4-4a49-b829-6a9a7e1a847e",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "初始访问行为同时对应 MITRE ATLAS 中的 AML.T0000 Initial Access。",
      "x_evidence": "Table 1:AML.T0000: Initial Access。",
      "x_confidence": 0.92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--0b827033-7946-4135-9bd8-9e4bea3a919c",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "attack-pattern--9de80a5f-b1a6-41ce-a6b3-c4568f025bf8",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "攻击者部署自动化侦察代理,使用服务发现工具映射内部微服务,对应 T1046 Network Service Discovery。",
      "x_evidence": "原文:deploying an automated recon agent to map internal microservices;Table 1:T1046: Network Service Discovery。",
      "x_confidence": 0.94
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d1149bcb-c3dd-4072-ac8d-f18b1a8f942c",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "attack-pattern--63b42859-8f7c-488c-b3d9-fe070fce9301",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "自动化侦察行为同时对应 MITRE ATLAS 中的 AML.T0002 AI-Automated Reconnaissance。",
      "x_evidence": "Table 1:AML.T0002: AI-Automated Reconnaissance。",
      "x_confidence": 0.92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--660e3b21-6772-45f2-8d18-c1e16bb945c6",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "attack-pattern--e02b0f15-543b-4124-8c71-ed55156715eb",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "攻击者通过 AI 子代理搜索企业代码仓库,提取硬编码 token 和服务密码,对应 T1552.001 Credentials In Files。",
      "x_evidence": "原文:Sub-agents combed enterprise code repositories, extracting hard-coded tokens and service passwords;Table 1:T1552.001: Credentials In Files。",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--02b3765f-76ce-4835-99cf-93376e3c14e0",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "attack-pattern--4bc9dcc4-abcb-4d26-9d81-79f85176716f",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "凭据刮取行为同时对应 MITRE ATLAS 中的 AML.T0014 Credentials Harvesting。",
      "x_evidence": "Table 1:AML.T0014: Credentials Harvesting。",
      "x_confidence": 0.92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--c8fdfaa8-335f-45f7-a922-9216b1ec5b59",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "attack-pattern--49de59cc-95d8-4652-8217-e36b1641f106",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "攻击者入侵秘密管理系统并从密码存储中获取管理员凭据,对应 T1555 Credentials from Password Stores。",
      "x_evidence": "原文:the actor infiltrated the secrets management system, harvesting master administrative credentials;Table 1:T1555: Credentials from Password Stores。",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1202980b-d811-446a-ab2b-10b124a3be47",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "attack-pattern--b27881c3-9fbf-40b2-bc9f-185bd4283120",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "权限提升行为同时对应 MITRE ATLAS 中的 AML.T0016 Privilege Escalation via Automated Pivot。",
      "x_evidence": "Table 1:AML.T0016: Privilege Escalation via Automated Pivot。",
      "x_confidence": 0.92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--3787c5d9-b656-4de0-9bfc-1882a13b78e8",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "attack-pattern--14ffaf2e-7731-48fa-9b15-f2e042f455ee",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "攻击者触发未授权 CI/CD 构建并尝试编辑云配置,对应 T1578 Modify Cloud Compute Infrastructure。",
      "x_evidence": "原文:The agents also triggered unauthorized CI/CD builds;They attempted to plant backdoors in Terraform configurations;Table 1:T1578: Modify Cloud Compute Infrastructure。",
      "x_confidence": 0.94
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--172d4c53-2048-4fd3-846b-911ca2653796",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "attack-pattern--d47bcb0d-c98d-4238-ac9c-21d2314ff201",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "流水线拦截行为同时对应 MITRE ATLAS 中的 AML.T0010 ML/DevOps Pipeline Interception。",
      "x_evidence": "Table 1:AML.T0010: ML/DevOps Pipeline Interception。",
      "x_confidence": 0.93
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--853917e6-3d20-4141-9141-1b137ad2a78b",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "attack-pattern--fe62345a-af98-42e0-8bdf-b86bbc8abc97",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "攻击者使用窃取的云密钥调用受害者云 AI 模型,对应 T1078 Valid Accounts。",
      "x_evidence": "原文:Using stolen cloud keys, the actor turned the victim’s AI endpoints into post-compromise infrastructure;Table 1:T1078: Valid Accounts。",
      "x_confidence": 0.93
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--f3399169-6092-499f-bd88-8b4236de8f44",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "attack-pattern--7d5cf373-3cf5-4273-8369-dcf7e7be7df9",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "AI 基础设施劫持行为同时对应 MITRE ATLAS 中的 AML.T0043 LLM Invocations via Stolen API Keys。",
      "x_evidence": "Table 1:AML.T0043: LLM Invocations via Stolen API Keys。",
      "x_confidence": 0.93
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--11cc568c-f069-4361-a47d-c87cf572229e",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "tool--c567cf57-02e6-44be-a4f2-5ea16386f53b",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "威胁行为者通过 AI 代理和攻击专用 agentic AI 框架,以自动化循环执行入侵并压缩攻击时间。",
      "x_evidence": "原文:Using autonomous AI agents;attack-specific agentic AI frameworks;the attacker compressed weeks of methodical intrusion tradecraft into less than 10 hours。",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--c18d94fc-b269-422c-a01c-5817c841433d",
      "relationship_type": "uses",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "tool--083b4821-da47-432b-b56c-4fa86581f643",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "攻击者使用 AI 生成自定义脚本管理动态操作,并通过自定义工作流劫持企业代码应用。",
      "x_evidence": "原文:Custom scripts (assessed with high confidence to be AI-generated due to UI elements) managing dynamic operations;custom workflows to exfiltrate cloud access keys。",
      "x_confidence": 0.9
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--7d27cfee-3910-43a0-89f0-2ba22fa48a77",
      "relationship_type": "targets",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "infrastructure--8a19d86c-626d-4f31-b9e4-bc157741401a",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "受害方公共 API 端点是初始入侵的被利用目标。",
      "x_evidence": "原文:The actor breached a public API endpoint to tunnel into the network。",
      "x_confidence": 0.94
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--809a160f-a898-4398-aca8-b2fdc6c81acb",
      "relationship_type": "targets",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "infrastructure--a6470dad-3af2-49f1-9a61-1588b3647c5e",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "受害方内部微服务是自动化侦察代理的映射和侦察目标。",
      "x_evidence": "原文:deploying an automated recon agent to map internal microservices。",
      "x_confidence": 0.93
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--4b8ba6d9-da0f-4f21-8b22-a5ee2443d225",
      "relationship_type": "targets",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "infrastructure--630ff70d-6ad1-4747-bc90-8139624ecf5f",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "企业代码仓库被攻击者通过 AI 子代理搜索和刮取,是凭据访问目标。",
      "x_evidence": "原文:Sub-agents combed enterprise code repositories, extracting hard-coded tokens and service passwords。",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--69903601-194d-46a9-9e16-89922f9a0314",
      "relationship_type": "targets",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "infrastructure--12dabd18-bb80-4c89-8c12-bf42f1e8575a",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "秘密管理系统被入侵以获取管理员凭据,是权限提升目标。",
      "x_evidence": "原文:the actor infiltrated the secrets management system, harvesting master administrative credentials。",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--82e63cd9-d748-4209-aa3a-27142cc28dd8",
      "relationship_type": "targets",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "infrastructure--1f746272-c050-4348-8c82-b7144b89c6a8",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "CI/CD 流水线被触发未授权构建并用于持久性,是流水线滥用目标。",
      "x_evidence": "原文:The agents also triggered unauthorized continuous integration/continuous delivery (CI/CD) builds;CI/CD pipelines。",
      "x_confidence": 0.95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1fba111f-bd69-48f6-a07c-86edfdd1d414",
      "relationship_type": "targets",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "infrastructure--33f700ef-e014-4ee9-9890-f1c96f93f5d1",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "Terraform 配置被尝试植入后门,但被硬分支保护阻止。",
      "x_evidence": "原文:They attempted to plant backdoors in Terraform configurations, but hard branch-protection controls stopped this。",
      "x_confidence": 0.94
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--70738acb-3d6d-43a1-868d-ea13e3200926",
      "relationship_type": "targets",
      "source_ref": "intrusion-set--a25c74ad-6e93-4c37-a5c1-3a073e5b17d6",
      "target_ref": "infrastructure--228be810-3753-4c55-83a4-977b3b9d18fc",
      "created": "2026-09-02T16:36:47Z",
      "modified": "2026-09-02T16:36:47Z",
      "description": "云 AI 端点被攻击者作为劫持目标并转换为后渗透基础设施。",
      "x_evidence": "原文:Using stolen cloud keys, the actor turned the victim’s AI endpoints into post-compromise infrastructure。",
      "x_confidence": 0.95
    }
  ]
}

报告链接:

https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/

───────────────────────────────────

三、本周AI安全风险观察

AI辅助攻击已覆盖完整入侵链:Unit 42案例显示,AI和智能体框架可用于自动化侦察、代码库凭据提取、权限提升和AI基础设施劫持;Aurora事件则表明,Cursor AI已被用于勒索攻击规划,AI能力正嵌入真实攻击流程。

AI编程工具和Agent执行边界成为新的攻击面:Hermes Agent漏洞可借助恶意Git配置触发命令执行,说明Agent自动读取代码仓库状态、调用本地工具和继承用户权限时,可能将不可信项目内容转化为主机风险。

AI基础设施与模型资源面临凭据驱动的直接滥用:LiteLLM在野利用可导致模型配置和API密钥泄露,LLMjacking则利用长期AWS IAM密钥订阅并调用基础模型,攻击影响同时涉及数据、权限和云成本。

AI降低恶意代码开发和社会工程门槛:NodeStealer使用AI辅助扩展间谍功能,Claude可加速工控漏洞利用的跨设备适配,银狐还利用AI输出信任和仿冒DeepSeek网站增强木马投递效果。

───────────────────────────────────

四、安全建议

强化AI Agent和开发工具执行边界:升级Hermes Agent等受影响组件,禁止AI编程工具自动信任未知仓库配置,对Git状态刷新、Shell执行、文件访问和凭据读取实施最小权限,并对高风险工具调用增加人工确认。

加强AI基础设施与云凭据安全:及时修复LiteLLM相关在野漏洞,排查异常日志并轮换可能暴露的API密钥;避免使用长期高权限AWS IAM密钥,启用CloudTrail和Bedrock调用日志,监控异常模型订阅及推理费用。

提升AI辅助攻击和恶意软件检测能力:关注代码库批量读取、凭据管理系统访问、云密钥调用及自动化侦察循环;加强Python字节码分析、Telegram C2通信监测,并针对工控环境关闭非必要FTP服务、实施网络隔离和异常流量检测。

强化AI输出和软件下载来源验证:限制AI工具直接下载或执行外部文件,不依赖搜索结果、智能体推荐或仿冒品牌页面安装软件;对DeepSeek等AI产品仅使用官方渠道,并结合终端安全工具二次核验文件。

───────────────────────────────────

五、报告总结

本周AI安全风险体现出“AI增强攻击能力”与“AI基础设施自身暴露”并行发展的特征。AI和智能体框架已经能够加速侦察、凭据提取、攻击规划和漏洞利用适配,使传统勒索、间谍软件及工控攻击链的执行效率进一步提升。

同时,Hermes Agent、LiteLLM和AWS模型资源相关事件表明,代码仓库配置、Agent工具调用、模型API密钥和云身份凭据正在成为AI应用安全的关键控制点。组织需要将AI平台按照核心基础设施实施资产管理、权限隔离和持续监测。

此外,银狐仿冒DeepSeek官网的活动说明,攻击者正在利用用户对AI输出和品牌的信任实施恶意软件投递。企业在推进AI辅助开发和自动化应用时,应同步强化来源真实性验证、外部内容隔离和高风险操作审批。

───────────────────────────────────

报告说明

本报告由360威胁情报中心基于2026年8月29日至9月4日公开威胁情报整理形成,重点分析AI与智能体框架辅助勒索攻击、Cursor AI攻击规划、AI编程Agent恶意Git配置执行、LiteLLM在野漏洞利用、LLMjacking模型资源滥用、AI辅助间谍软件开发、Claude辅助工控漏洞移植及AI信任链钓鱼风险,为企业AI应用、开发环境、云模型服务、工业控制系统及安全运营防护提供参考。

情报时效性: 2026年8月29日—9月4日  威胁评估等级: 高风险(多源情报验证)