AI Security AI安全 1d ago Updated 3h ago 更新于 3小时前 41

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories 威胁日报:200个Android漏洞、浏览器钓鱼、11.9万诈骗店铺及23则更多故事

Malicious Chrome/Firefox extensions (J7Tracker, VREO, Orbit Tracker) steal session tokens and wallet data from Axiom Trade and Padre users via byte-identical collection modules deployed on threat-controlled Vercel infrastructure A Chinese-speaking threat actor uses AI coding assistants (Claude Code, Qwen, DeepSeek) orchestrated through SecFlow framework to automate reconnaissance, exploitation, and persistence across government and financial targets in multiple countries The U.K.'s NCSC warns th 恶意Chrome/Firefox扩展程序窃取加密货币用户会话令牌和钱包数据,使用字节相同的收集模块发送至攻击者控制的Vercel部署 中国籍攻击者利用Claude Code、Qwen、DeepSeek等AI工具配合SecFlow框架自动化入侵政府及金融机构 攻击者利用Shellshock、Log4Shell、Ghostcat等已知漏洞,通过GLUTTON能力生成web shell并部署SecBox后门 英国NCSC警告影子AI使用导致企业敏感数据暴露,AI代理漏洞可能被攻击者利用获取同等访问权限 虚假并购交易成为新型电汇欺诈手段,攻击者伪装高管诱导目标转移至WhatsApp和个人邮箱沟通

58
Hot 热度
65
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • Malicious Chrome/Firefox extensions (J7Tracker, VREO, Orbit Tracker) steal session tokens and wallet data from Axiom Trade and Padre users via byte-identical collection modules deployed on threat-controlled Vercel infrastructure
  • A Chinese-speaking threat actor uses AI coding assistants (Claude Code, Qwen, DeepSeek) orchestrated through SecFlow framework to automate reconnaissance, exploitation, and persistence across government and financial targets in multiple countries
  • The U.K.'s NCSC warns that shadow AI adoption by employees creates undetectable data exposure risks, as consumer AI agents may harbor vulnerabilities attackers can exploit to access privileged data
  • Fake M&A phishing campaigns use forged acquisition documents with reused legal language to manipulate senior professionals into moving communications to WhatsApp/personal email for wire fraud execution

Why It Matters

This bulletin highlights the accelerating convergence of AI capabilities with traditional cybercrime tactics, demonstrating how off-the-shelf AI tools are being weaponized to automate complex intrusion campaigns at scale. For AI practitioners and security teams, it underscores that AI adoption without governance creates both direct attack surfaces (shadow AI) and empowers adversaries with automation previously requiring significant human expertise.

Technical Details

  • AI-Orchestrated Intrusion Framework: The SecFlow framework splits campaign objectives among specialized AI agents handling reconnaissance, exploitation, collection, and reporting. It leverages Claude Code, Alibaba Qwen, and DeepSeek to automate vulnerability exploitation (Shellshock, Spring4Shell, Ghostcat, Log4Shell, Nacos auth bypass) and deploy GLUTTON-generated web shells and SecBox (Go-based) backdoors for remote access and network pivoting
  • Malicious Extension Architecture: Four browser extensions share identical collection modules that harvest authenticated user info, wallet bundle data, Firebase tokens, and application state, exfiltrating to attacker-controlled Vercel deployments. The same publisher previously operated GhostApe and GhostApe Color impersonating legitimate MockApe trading tools
  • Shadow AI Risk Model: NCSC identifies that consumer AI agents introduce compound vulnerabilities—employees transferring proprietary data to unvetted services reduce organizational visibility, while agent-side exploits grant attackers the same data access and privileges as legitimate users
  • Social Engineering Document Pattern: Fake M&A documents follow a consistent template structure with reused legal language, enforced confidentiality clauses, and deliberate communication channel migration (corporate to WhatsApp/personal email) within tight NDA-to-announcement windows

Industry Insight

  • Organizations must treat AI tool governance as a security-critical function: implement approved AI tool allowlists, data loss prevention policies for AI services, and continuous monitoring for shadow AI usage, treating unvetted AI agents as potential attack surface equivalents to unauthorized software
  • Security teams should reassess threat detection strategies to account for AI-automated intrusion campaigns—traditional signature-based detection will miss AI-generated web shells and dynamically crafted exploitation chains; invest in behavioral analytics and agent activity monitoring
  • The reuse of identical malicious code modules across extensions and the templated nature of AI-driven phishing documents suggests threat actors are optimizing for scalability over sophistication; prioritize endpoint detection for known collection module hashes and implement document provenance verification for financial transaction workflows

TL;DR

  • 恶意Chrome/Firefox扩展程序窃取加密货币用户会话令牌和钱包数据,使用字节相同的收集模块发送至攻击者控制的Vercel部署
  • 中国籍攻击者利用Claude Code、Qwen、DeepSeek等AI工具配合SecFlow框架自动化入侵政府及金融机构
  • 攻击者利用Shellshock、Log4Shell、Ghostcat等已知漏洞,通过GLUTTON能力生成web shell并部署SecBox后门
  • 英国NCSC警告影子AI使用导致企业敏感数据暴露,AI代理漏洞可能被攻击者利用获取同等访问权限
  • 虚假并购交易成为新型电汇欺诈手段,攻击者伪装高管诱导目标转移至WhatsApp和个人邮箱沟通

为什么值得看

本文揭示了AI技术被恶意利用的新型攻击模式,展示了大语言模型如何被整合到自动化攻击框架中,对企业和安全从业者具有重要警示意义。同时反映了影子AI治理、浏览器扩展安全、AI代理安全等新兴风险领域。

技术解析

  • SecFlow AI编排框架:攻击者使用该框架将活动目标转化为专业AI代理任务,分配侦察、利用、收集和报告等分工,结合Claude Code、Qwen、DeepSeek等模型实现自动化入侵
  • 已知漏洞利用链:攻击者利用Shellshock、Spring4Shell、Ghostcat、Shiro反序列化、Log4Shell、Grafana/Nexus路径遍历、Nacos认证绕过等漏洞,配合GLUTTON能力生成web shell
  • 恶意扩展技术特征:四个恶意扩展(J7Tracker、VREO、Orbit Tracker等)使用字节相同的Axiom/Padre收集模块,自动获取认证用户信息、钱包数据、Firebase令牌和应用状态
  • SecBox后门框架:Go语言编写的远程访问和网络穿透框架,用于维持持久化访问和后续攻击行动
  • 影子AI风险模型:员工将敏感数据传入消费级AI服务,降低组织可见性和控制力,AI代理的复杂性和漏洞可能被利用获取同等数据访问权限

行业启示

  • AI代理安全成为新战场:攻击者开始将大语言模型整合到自动化攻击框架中,企业需建立AI工具使用监控和限制机制,防范AI代理被恶意利用
  • 影子AI治理亟待加强:NCSC的警告表明未授权AI工具使用已成为企业数据泄露的重要风险源,需要制定明确的AI工具使用政策和数据分类保护机制
  • 浏览器扩展安全需重视:恶意扩展通过伪装成合法工具窃取敏感数据,企业应建立扩展程序白名单机制,定期审查已安装扩展的权限和行为

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究