½üÈÕ£¬FortiGuard Labs·¢²¼ÁË¡¶2025 ÄêÈ«ÇòÍþвÐÎÊÆ±¨¸æ¡·£¬±¨¸æ½ÒʾÁËÍøÂç¹¥»÷ÔÚ¹æÄ£ºÍ¸´ÔÓÐÔÉϼ±¾çÉý¼¶£¬¹¥»÷ÕßÕýÔÚÀûÓÃ×Ô¶¯»¯¡¢ÉÌÒµ»¯¹¤¾ßºÍÈ˹¤ÖÇÄÜϵͳµØÇÖÊ´·ÀÓùÕߵĴ«Í³ÓÅÊÆ£¬ÐÐÒµÕýÔÚÃæÁÙ²»ÈÝÀֹ۵ķ¢Õ¹¾³Óö£¬ÏÖ½«²¿·Ö¹Ûµãժ¼ÈçÏ£¬ÒÔ¹©²Î¿¼¡£
¹¥»÷ÕßÃÇÕýÔÚ´óÁ¦Í¶×Ê×Ô¶¯»¯¡¢Õì²ìºÍ¿ÉÀ©Õ¹²Ù×÷£¬ËûÃÇ×·ÇóËÙ¶È¡¢Òþ±ÎÐԺͿÉÉìËõÐÔ£¬ÒÔ¼«¿ìµÄËٶȽøÐÐѰÕÒϵͳÖпÉÒÔ¹¥»÷µ½µÄ©¶´¡£2024Äê£¬ÍøÂç¿Õ¼äÖеÄÖ÷¶¯É¨ÃèÁ¿È«ÇòÔö³¤ÁË16.7%£¬FortiGuard LabsÿÔ¹۲쵽ÊýÊ®ÒڴΠɨÃè³¢ÊÔ£¬Ï൱ÓÚÿÃë36,000´ÎɨÃ裬ÕâЩɨÃèÖ¼ÔÚ·¢ÏÖÃ÷ÏԵĩ¶´£¬²¢Ì½Ë÷¹Ø¼ü»ù´¡ÉèÊ©£¬ÒÔÈ·¶¨ÄÄЩ×ʲú¿ÉÒÔÒÔ×îСµÄŬÁ¦±»ÀûÓá£ÕâÒ²±íÃ÷¹¥»÷Õß¶Ô±©Â¶µÄÊý×Ö»ù´¡ÉèÊ©½øÐÐÁ˸´ÔÓ¶ø´ó¹æÄ£µÄÐÅÏ¢ÊÕ¼¯£¬Éæ¼°µçÐÅ¡¢¹¤Òµ¡¢OT/ICSºÍ½ðÈÚ·þÎñµÈ¹Ø¼üÁìÓò£¬ÆäÖÐSIP(VoIP)ÔÚ¼ì²âµ½µÄɨÃèÖÐÕ¼49%ÒÔÉÏ¡£
ËäÈ»2024ÄêÐÂÅû¶µÄ©¶´µÄƽ¾ùÀûÓÃʱ¼äÏà¶ÔÎȶ¨£¬µ«ÀûÓó¢ÊÔ¹æÄ£¼¤Ôö£¬FortiGuard Labs¼Ç¼Á˳¬¹ý970ÒÚ´ÎÀûÓó¢ÊÔ£¬·´Ó³³ö×Ô¶¯»¯³Ì¶ÈÌá¸ßºÍ¿çÐÐÒµµÄ¹ã·º¹¥»÷¡£ÕâÒ²±íÃ÷ÍøÂç·¸×ï·Ö×ÓÕýÔÚ³ÖÐøÌ½²â±©Â¶µÄϵͳ£¬ÄÇô½ÓÏÂÀ´µÄÎÊÌâ²»ÔÙÊÇ×éÖ¯ÊÇ·ñ»á³ÉΪ¹¥»÷Ä¿±ê£¬¶øÊǺÎʱÒÔ¼°ÒÔ¶à¿ìµÄËٶȳÉΪĿ±ê¡£Ivanti²úÆ·ÖеÄÃüÁî×¢Èë©¶´£¬ÔÚÅû¶ºó½öÁùÌì¾Í±»ÀûÓá£
¹¥»÷Õß²»ÔÙÐèÒªÊÖ¶¯Ê¶±ð©¶´£¬¶øÊÇÀûÓÃ×Ô¶¯É¨Ãè¡¢»úÆ÷ѧϰºÍ¾«ÐÄ´ò°üµÄ©¶´ÀûÓù¤¾ß°ü½«ÐÂÅû¶µÄ»Æ½ð³Ç¹ÙÍøÂ©¶´ÎäÆ÷»¯¡£
Windows SMBÐÅϢй¶©¶´(CVE-2017-0147)ÈÔÈ»Êǹ¥»÷Õßͨ¹ý·þÎñÆ÷ÏûÏ¢¿é(SMB)ÐÒéÉøÍ¸ÆóÒµÍøÂçʱ×îÇàíùµÄÄ¿±êÖ®Ò»£¬ÔÚ2024ÄêµÄ¹¥»÷³¢ÊÔÖÐÕ¼±È26.7%¡£¶øNetcore NetisÓ²±àÂëÃÜÂë(CVE-2019 -18935) Õâ¸öÎïÁªÍøÂ©¶´Õ¼ËùÓй¥»÷³¢ÊÔµÄ8%¡£
TelegramÈÔÈ»Êǹ²Ïí©¶´ÀûÓúͻù´¡ÉèÊ©µÄÖ÷Ҫе÷ÖÐÐÄ£¬ÎªÔ±¾·ÖÉ¢µÄÍþвÍÅÌåÌṩÁËÒ»²ã²Ù×÷ÉϵÄͳһÐÔ¡£
³¬¹ý20%µÄ¼Ç¼ÔÚ°¸µÄ¹¥»÷ÆóͼÕë¶ÔÎïÁªÍøÉ豸£¬ÕâÍ»ÏÔ³öÐí¶à×é֯δÄÜÏñ¶Ô´ý´«Í³IT×ʲúÄÇÑùÑϸñ¶Ô´ýÎïÁªÍø»Æ½ð³Ç¹ÙÍø¡£ ¹¥»÷ÕßÀûÓÃĬÈÏÆ¾Ö¤¡¢¹ýʱµÄ¹Ì¼þºÍ±©Â¶µÄ¹ÜÀí½Ó¿ÚÀ´»ñµÃ³Ö¾ÃÐÔ£¬²¢½«ÕâЩÉ豸×÷ÎªÌø°å£¬ÊµÊ©¸ü´ó¹æÄ£µÄ¹¥»÷£¬ÕâЩÎïÁªÍøÉ豸Ҳ¾³£×÷Ϊ½©Ê¬ÍøÂçµÄ»Æ½ð³Ç¹ÙÍø¸Û¡£
×îÒ×Êܹ¥»÷µÄÎïÁªÍøÉ豸ÊÇ·ÓÉÆ÷¡¢ÉãÏñÍ·ºÍÍøÂçÓ²¼þ£¬ÆäÖзÓÉÆ÷Õ¼±È×î¸ß£¬Æä´ÎÊÇ¼à¿ØÉãÏñÍ·¡£
ÔÆÎªÆóÒµÌṩÁ˱ØÒªµÄÃô½ÝÐԺͿÉÀ©Õ¹ÐÔ£¬µ«Í¬Ê±Ò²ÊÇÆóÒµ±©Â¶ÓÚ²»¶ÏÑݱäµÄ¹¥»÷;¾¶£¬ÒÔ ÔÆÎªÖÐÐĵĹ¥»÷Õý±äµÃ¸ü¼Ó¸´ÔÓ£¬ÔÆ»·¾³Èç½ñÒѳÉΪ¹¥»÷ÕßÀûÓÃÅäÖôíÎó¡¢Éí·Ýй¶ºÍ²»»Æ½ð³Ç¹ÙÍøAPIµÄÕ½³¡£¬¹¥»÷ÕßÀûÓÃ×Ô¶¯»¯É¨ÃèÓë¶à½×¶ÎÉøÍ¸¼¼Êõ£¬½«ÅäÖôíÎó¡¢±©Â¶Æ¾Ö¤¼°´àÈõAPIת»¯ÎªÍ»ÆÆ¿Ú¡£FortiCNAPP¼à²âÊý¾ÝÏÔʾ£¬Ôƹ¥»÷µÄËðʧÔÚÎȲ½ÉÏÉý¡£
ÔÆÅäÖôíÎóÈÔÈ»Êǰ¢¿¦Áð˹֮õà¡£¿ª·Å´æ´¢Í°ºÍ¹ý¶ÈÊÚȨÉí·ÝÈÔÈ»ÊÇÖ÷ÒªµÄ¹¥»÷ÏòÁ¿¡£ÀûÓÃÃæÏò¹«ÖÚµÄÓ¦ÓóÌÐòÈÔÈ»ÊÇÆÕ±é´æÔڵĩ¶´ÀûÓòßÂÔ¡£
API»Æ½ð³Ç¹ÙÍøÏÖÔÚÊÇÊ×ÒªÈÎÎñ¡£¹¥»÷ÕßÔ½À´Ô½¶àµØÀÄÓÃÔÆAPIÒÔºáÏòÒÆ¶¯¡¢ÌáÉýȨÏÞºÍÌáÈ¡Ãô¸Ð Êý¾Ý¡£
¶à½×¶ÎÔÆ¹¥»÷ÊÇеij£Ì¬¡£¹¥»÷ÕßÏÖÔÚ½«Æ¾Ö¤ÇÔÈ¡¡¢Éí·Ýʶ±ðºÍAPIÀÄÓýáºÏÆðÀ´£¬ÒÔ×î´ó Ï޶ȵØÌá¸ß¹¥»÷Ó°Ï죬¶ø²»ÊÇʹÓõ¥Ïò¹¥»÷¡£
ÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Éú̬ϵͳ³ÖÐøÀ©ÕÅ
È«ÇòÍøÂç·¸×ïÕý²½ÈëÐ×÷»¯¡¢Ä£¿é»¯µÄн׶Σ¬ÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Éú̬ϵͳ³ÖÐøÀ©ÕÅ£¬ÐµÄ×éÖ¯²»¶ÏÓ¿ÏÖ²¢½¨Á¢Ë«ÖغÍÈýÖØÀÕË÷ģʽ£¬2024Ä꣬RansomHub(13%)£¬LockBit 3.0(12%)¡¢Play(8%) ºÍ Medusa(4%)ÊÇ×î»îÔ¾µÄÀÕË÷Èí¼þ×éÖ¯¡£
´ÓÄ¿±êÐÐÒµÀ´¿´£¬ÖÆÔìÒµÕ¼17%¡¢ÉÌÒµ·þÎñÕ¼11%¡¢½¨ÖþºÍÁãÊÛÕ¼9%¡£¶øÃÀ¹ú(61%)¡¢Ó¢¹ú(6%)ºÍ¼ÓÄôó(5%) ÔòÊÇÊÜÓ°Ïì×î´óµÄÈý¸ö¹ú¼Ò¡£
2024ÄêÓÐ13¸öÐÂ×éÖ¯áÈÆð£¬ÖÁÉÙÓÐ6¸öÖ÷ÒªµÄRaaS·þÎñÔÚµØÏÂÂÛ̳Éϱ»Ðû´«£¬°üÀ¨PlayBoy¡¢Rape¡¢Medusa¡¢Wing¡¢BE-ASTºÍCicada ¡£
AIÕýÔÚÎªÍøÂç·¸×﹩ӦÁ´Ìṩ³¬¼¶¶¯Á¦
È˹¤ÖÇÄܵķ¢Õ¹½µµÍÁËÍøÂç·¸×ïµÄÃż÷£¬¹¥»÷ÕßÀûÓÃAIÉú³ÉµöÓãÓʼþÎı¾¡¢ÆÛÕ©ÐԵķ¨ÂÉÎļþ¡¢ÍøÂçµöÓãÒ³ÃæºÍ¶ñÒâ´úÂ룬°ïÖú¹¥»÷Õ߸ĽøÆ¾Ö²¢½øÐдó¹æÄ£Éç»á¹¤³Ì»î¶¯£»ÀûÓÃAIÓïÒôºÏ³É¹¤¾ß¿Ë¡ÉùÒô£¬Éî¶ÈαÔìթƵ绰£»ÀûÓÃÁÄÌì»úÆ÷ÈËÄ£·Â¿Í»§Ö§³Ö´ú±í£¬Ê¹ÓÃAIÉú³ÉµÄ¶Ô»°À´ÆÛÆÊܺ¦Õß·ÖÏíÈçÐÅÓÿ¨ÐÅÏ¢¡¢ MFA´úÂëºÍÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£
°µÍøÒѾ³ÉΪ×ÌÉú×ï¶ñµÄ¡°Î´²¡±
°µÍøÒѾ´Óµ¥´¿µÄÍøÂç·¸×ï·Ö×ӵıÜÄÑËùÑݱäÎªÍøÂç¹¥»÷µÄ¹©Ó¦Á´£¬³ÉΪʵʩ¾«×¼»¯¡¢¹æÄ£»¯¹¥»÷µÄºËÐÄÊàŦ¡£FortiGuard Labs¼à²âÏÔʾ£¬°µÍøÒÑÐÎ³É´ÓÆ¾Ö¤ÇÔÈ¡¡¢Â©¶´ÎäÆ÷»¯µ½AI×Ô¶¯»¯¹¥»÷µÄÍêÕû²úÒµÁ´¡£¹¥»÷ÕßÔÚ·¢¶¯ÈëÇÖǰÍùÍùÒÑÍê³ÉÊýÔ²߻®£¬Í¨¹ý°µÍøÊг¡»ñÈ¡ÏÖ³É×ÊÔ´°ü¡ª¡ª°üÀ¨ÆóÒµVPNƾ֤£¨Õ¼IAB½»Ò×Á¿20%£©¡¢RDP½ÓÈëȨÏÞ£¨Õ¼IAB½»Ò×Á¿19%£©¡¢WebshellsµÈ£¬Õ⽫ÆÈʹ·ÀÓùÌåϵ±ØÐ뽨Á¢»ùÓÚ°µÍøÇ鱨µÄǰհÐÔÏìÓ¦»úÖÆ¡£
±¨¸æÏÂÔØµØÖ·£º
https://www.fortinet.com/resources/reports/threat-landscape-report