Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!

ÿÖܸ߼¶ÍþвÇ鱨½â¶Á(2021.12.30~2022.01.06)

ʱ¼ä£º2022-01-07 ×÷ÕߣºÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐÄ

·ÖÏíµ½£º

    2021.12.30~2022.01.06

    ¹¥»÷ÍÅ»ïÇ鱨

    KimsukyÕë¶Ôº«¹úÐÂÎÅÐÐÒµµÄ´¹ÂÚÔ˶¯ÆÊÎö

    LazarusÕë¶Ôº½¿ÕÒµ¼°Çå¾²Ñо¿Ö°Ô±Ìᳫ¹¥»÷

    Ë«Î²Ð«Ê¹ÓöñÒâAndroid³ÌÐò¹¥»÷Öж«µØÇø

    APT33ÐÂÐͶñÒâÔ¶¿ØÈí¼þ“LittleLooter”ÆÊÎö

    EvilnumʹÓÃÒþдÊõͶµÝÐÂÐÍľÂíAgentVX

    “KONNI”ʹÓÃÐÂÄêÎʺòÃé×¼¶íÂÞ˹Íâ½»¹Ù

    ¹¥»÷Ðж¯»òÊÂÎñÇ鱨

    ¹¥»÷Õßð³äÃÀ¹úСÆóÒµÖÎÀí¾ÖÒÔйÚÔ®ÖúΪÓÕ¶ü¾ÙÐд¹ÂÚÔ˶¯

    Lapsus$ÀÕË÷Èí¼þÍÅ»ïÕë¶ÔÆÏÌÑÑÀ×î´óµÄýÌ幫˾

    WebSkimmerÔ˶¯Í¨¹ý¹¥»÷ÔÆÊÓÆµÆ½Ì¨Ãé×¼·¿µØ²úÍøÕ¾

    ¶ñÒâ´úÂëÇ鱨

    AgentTesla¸üÐÂSMTPÊý¾Ýй¶ÊÖÒÕ

    2021ÄêÊ¢ÐÐÀÕË÷Èí¼þÅÌ»õ

    Telegram×°Öðü±»ÓÃÓÚÈö²¥PurpleFoxºóÃųÌÐò

    Îó²îÇ鱨

    ApacheAPISIXDashboardÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲Σº¦Í¨¸æµÚ¶þ´Î¸üÐÂ

    Ñо¿Ö°Ô±·¢Ã÷Uberµç×ÓÓʼþϵͳ±£´æÎó²î


    ¹¥»÷ÍÅ»ïÇ鱨

    01

    KimsukyÕë¶Ôº«¹úÐÂÎÅÐÐÒµµÄ´¹ÂÚÔ˶¯ÆÊÎö

    Åû¶ʱ¼ä£º2021Äê12ÔÂ30ÈÕ

    Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/O_3PFAB4RGxJXHnx_o9f3Q

    Ïà¹ØÐÅÏ¢£º

    Ñо¿Ö°Ô±·¢Ã÷Ò»Àýαװ³Éº«¹ú»¥ÁªÍøÇå¾²¾Ö£¨KISA£©Ñо¿Ô±Õë¶Ôº«¹úÐÂÎÅÐÐÒµÖ÷ÒªÈËÎï¾ÙÐÐÓã²æ´¹ÂÚµÄÍøÂç¹¥»÷Ô˶¯£¬£¬£¬£¬ £¬£¬£¬£¬¾­ÑÐÅÐÆÊÎö£¬£¬£¬£¬ £¬£¬£¬£¬´Ë´ÎÔ˶¯À´×ÔKimsuky×éÖ¯¡£¡£¡£¡£¡£¡£

    ¾­Ì«¹ýÎö»¹Ô­£¬£¬£¬£¬ £¬£¬£¬£¬ÍƲ⹥»÷Á÷³ÌÈçÏ£º¹¥»÷ÕßÊ×ÏÈͨ¹ýBBSÎó²îÈëÇÖÁËÍøÕ¾£¬£¬£¬£¬ £¬£¬£¬£¬È»ºóÉÏ´«Webshell¼°ÆäËû¹¥»÷Ô˶¯ÖÐËùÐèÒªµÄ×é¼þµ½webЧÀÍÆ÷£¬£¬£¬£¬ £¬£¬£¬£¬webЧÀÍÆ÷×÷ÎªÌø°å»ú£¬£¬£¬£¬ £¬£¬£¬£¬ÊµÏÖ·¢ËÍÓʼþ¡¢ÎüÊÕÊܺ¦ÕßÐÅÏ¢¡¢Ìṩ¶ñÒâÔØºÉÏÂÔØµÈ¹¦Ð§¡£¡£¡£¡£¡£¡£×îºó¹¥»÷Õ߽ṹ´¹ÂÚÓʼþͶµÝµ½Ä¿µÄ»úÓÕµ¼Óû§Ö´ÐУ¬£¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýWebshell»ñÈ¡ÍøÂçµ½µÄÊܺ¦ÕßÐÅÏ¢¡£¡£¡£¡£¡£¡£

ÿÖܸ߼¶ÍþвÇ鱨½â¶Á(2021.12.30~2022.01.06)

    02

    LazarusÕë¶Ôº½¿ÕÒµ¼°Çå¾²Ñо¿Ö°Ô±Ìᳫ¹¥»÷

    Åû¶ʱ¼ä£º2021Äê12ÔÂ30ÈÕ

    Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/fVrGwrJxo_GW6FtfghzCzA

    Ïà¹ØÐÅÏ¢£º

    Lazarus×éÖ¯ÊÇÒÉËÆ¾ßÓйú¼ÒÅä¾°µÄ¾³Íâ´óÐÍAPT¼¯ÍÅ×éÖ¯£¬£¬£¬£¬ £¬£¬£¬£¬¸Ã×é֝ɯÓÚʹÓÃÉç»á¹¤³Ìѧ¼Æ»®Õë¶ÔÕþ¸®¡¢¿ÆÑС¢½ðÈÚ¡¢º½¿Õ¡¢¼ÓÃÜÇ®±ÒµÈ»ú¹¹¾ÙÐж¨Ïò¹¥»÷Ô˶¯£¬£¬£¬£¬ £¬£¬£¬£¬ÇÔÈ¡Ö÷ÒªÇ鱨ÐÅÏ¢¼°»ñÈ¡¾­¼ÃÀûÒæÊÇÆäÖ÷ҪĿµÄ¡£¡£¡£¡£¡£¡£

    Çå¾²³§É̼à²âµ½Lazarus×éÖ¯Õë¶Ôº½¿ÕÒµ¼°Çå¾²Ñо¿Ö°Ô±µÄ¶¨Ïò¹¥»÷Ô˶¯£¬£¬£¬£¬ £¬£¬£¬£¬ÆÊÎöÓÐÈçÏ·¢Ã÷£º

    ¹¥»÷ÕßαװÃÀ¹ú“Âå¿ËÏ£µÂÂí¶¡”º½¿Õ¹«Ë¾ÕÐÆ¸Îĵµ£¬£¬£¬£¬ £¬£¬£¬£¬ÏòÄ¿µÄͶµÝÓÕ¶üÎĵµ¾ÙÐй¥»÷£»£»£»£»£» £»£»

    ËùͶµÝÎĵµ×îÖÕ¼ÓÔØÖ´ÐжñÒâºóÃÅÄ £¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬ £¬£¬£¬£¬ÊµÏÖ¶ÔÄ¿µÄÖ÷»úµÄÔ¶³Ì¿ØÖÆ£»£»£»£»£» £»£»

    Í¬Ê±»¹Ê¹ÓÃÏàͬµÄÎĵµÄ£°åÖÆ×÷Google¹«Ë¾µÄÕÐÆ¸ÓÕ¶üÎĵµ¾ÙÐй¥»÷Ô˶¯£»£»£»£»£» £»£»

    ¹¥»÷ÕßÐ޸ĿªÔ´ÏîÄ¿NppShell¿ª·¢Ä¾Âí£¬£¬£¬£¬ £¬£¬£¬£¬¿ÉÒÔÌӱܲ¿·ÖÇå¾²Èí¼þ¼ì²â£»£»£»£»£» £»£»

    Lazarus¸´ÓÃÒÔÍù¹¥»÷ÊÖ·¨£¬£¬£¬£¬ £¬£¬£¬£¬Ð޸ĿªÔ´SumatraPDFÔĶÁÆ÷¾ÙÐй¥»÷£»£»£»£»£» £»£»

    ±ðµÄ£¬£¬£¬£¬ £¬£¬£¬£¬¸Ã×éÖ¯½«¶ñÒâ×é¼þÀ¦°óµ½IDAPro×°Öðü³ÌÐòÕë¶ÔÇå¾²Ñо¿Ö°Ô±¾ÙÐй¥»÷¡£¡£¡£¡£¡£¡£

    03

    Ë«Î²Ð«Ê¹ÓöñÒâAndroid³ÌÐò¹¥»÷Öж«µØÇø

    Åû¶ʱ¼ä£º2021Äê12ÔÂ28ÈÕ

    Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/RRH9vgnNJyc1idTLS6okcw

    Ïà¹ØÐÅÏ¢£º

    ½üÆÚ£¬£¬£¬£¬ £¬£¬£¬£¬Ñо¿Ö°Ô±²¶»ñÁËÒ»¿îAPT-C-23Ñù±¾¡£¡£¡£¡£¡£¡£APT-C-23ÓÖ±»³ÆÎª“˫βЫ”£¬£¬£¬£¬ £¬£¬£¬£¬ÔÚ2017ÄêÊ״α»·¢Ã÷£¬£¬£¬£¬ £¬£¬£¬£¬Õâ¸ö×éÖ¯Õë¶Ô°ÍÀÕ˹̹µÈ¹ú¼ÒºÍµØÇø¡£¡£¡£¡£¡£¡£Ôڴ˴β¶»ñµÄÑù±¾ÖУ¬£¬£¬£¬ £¬£¬£¬£¬ÎÒÃÇ·¢Ã÷´Ë¶ñÒâÈí¼þÃûΪ“GooglePlayInstaller”¶ñÒâ³ÌÐò£¬£¬£¬£¬ £¬£¬£¬£¬×°Öúóαװ³ÉTelegramÓ¦ÓóÌÐòÀàËÆµÄͼ±êºÍ½çÃæ¡£¡£¡£¡£¡£¡£

    ¸Ã¶ñÒâÈí¼þÔÚ¶à¸öά¶È»ñÈ¡Óû§µÄÖÖÖÖÒþ˽ÐÅÏ¢£¬£¬£¬£¬ £¬£¬£¬£¬ÔÚ»ñÈ¡Óû§Òþ˽ÐÅÏ¢Öк¬ÓлñÈ¡Óû§µÄÁªÏµÈËÐÅÏ¢¡¢¶ÌÐÅ¡¢Í¨»°¼Í¼¡¢Í¼Æ¬¡¢Îĵµ¡¢ÒÔ¼°ÒôƵÎļþ¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»ñÈ¡ÔÆÔÆÖ®¶àµÄÓû§ÐÅÏ¢¿ÉνÊÇÈ«ÁýÕÖ¡£¡£¡£¡£¡£¡£

ÿÖܸ߼¶ÍþвÇ鱨½â¶Á(2021.12.30~2022.01.06)

    04

    APT33ÐÂÐͶñÒâÔ¶¿ØÈí¼þ“LittleLooter”ÆÊÎö

    Åû¶ʱ¼ä£º2021Äê12ÔÂ31ÈÕ

    Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/Zj44UM--9UyonjhxEHvRBA

    Ïà¹ØÐÅÏ¢£º

    ½üÆÚ£¬£¬£¬£¬ £¬£¬£¬£¬Ñо¿Ö°Ô±¼à²âµ½Ò»¿îÃûΪ“WhatsApp.apk”µÄÐéαÉç½»Èí¼þ£¬£¬£¬£¬ £¬£¬£¬£¬×ÅʵÊÇÒ»¿î¶ñÒâÇÔÃÜÈí¼þ£¬£¬£¬£¬ £¬£¬£¬£¬ÒÉ»óÓû§ÏÂÔØ£¬£¬£¬£¬ £¬£¬£¬£¬Ô¶³Ì¿ØÖÆÓû§ÊÖ»ú,²¢ÇÔÈ¡Óû§µÄÒþ˽Êý¾Ý¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÆÊÎö·¢Ã÷ÊÇAPT33×éÖ¯µÄÐÂÐÍÔ¶¿ØÈí¼þ£¬£¬£¬£¬ £¬£¬£¬£¬Æ¾Ö¤Æä¶ñÒâÐÐΪ½«ÆäÃüÃûΪ“LittleLooter”¡£¡£¡£¡£¡£¡£

    “WhatsApp”ÊÇÈ«Çò×ÅÃûµÄͨѶÉç½»Èí¼þ£¬£¬£¬£¬ £¬£¬£¬£¬µ«´ËÓ¦ÓÃÖ÷ÒªÊÇÍâÑóµÄÓû§ÈºÌ壬£¬£¬£¬ £¬£¬£¬£¬²¢Î´ÔÚº£ÄÚÓ¦ÓÃÊг¡ÉϼÜ£¬£¬£¬£¬ £¬£¬£¬£¬Óû§ÔÚÀÖ³É×°ÖÃÐéαµÄ“WhatsApp”ºó£¬£¬£¬£¬ £¬£¬£¬£¬Ò²ÎÞ·¨·­¿ª£¬£¬£¬£¬ £¬£¬£¬£¬¶ñÒâÈí¼þ»áɾ³ý×ÔÉíµÄ½çÃæµÄͼ±ê£¬£¬£¬£¬ £¬£¬£¬£¬²¢ÇÒÌáÐѓδװÖøÃÓ¦ÓÔ£¬£¬£¬£¬ £¬£¬£¬£¬µ«´Ë¶ñÒâÈí¼þ²¢Ã»ÓÐɾ³ý£¬£¬£¬£¬ £¬£¬£¬£¬ÔÚºǫ́ÒÀÈ»±£´æ£¬£¬£¬£¬ £¬£¬£¬£¬²¢¼ÌÐø¼àÌý£¬£¬£¬£¬ £¬£¬£¬£¬ÍøÂçÊÖ»úÓû§µÄÒþ˽ÐÅÏ¢£¬£¬£¬£¬ £¬£¬£¬£¬°üÀ¨Óû§µÄͨѶ¼¡¢¶ÌÐÅÄÚÈÝ¡¢Í¨Ñ¶¼Í¼¡¢ÊÖ»ú´æ´¢µÄÎļþ¡¢Óû§¶¨Î»¡¢ÍøÂçÐÅÏ¢¡¢×°±¸ÐÅÏ¢¡¢ä¯ÀÀÆ÷ÀúÊ·¡¢ÕÕÆ¬Â¼Òô¼ÏñºÍ×°ÖõÄÓ¦ÓÃÁбí£¬£¬£¬£¬ £¬£¬£¬£¬Í¬Ê±Ô¶³Ì²Ù¿ØÓû§ÊÖ»ú·¢ËͶÌÐÅ¡¢²¦´òµç»°¡¢Â¼ÒôºÍÉÏ´«ÎļþµÈ¶ñÒâ²Ù×÷¡£¡£¡£¡£¡£¡£

ÿÖܸ߼¶ÍþвÇ鱨½â¶Á(2021.12.30~2022.01.06)

    05

    EvilnumʹÓÃÒþдÊõͶµÝÐÂÐÍľÂíAgentVX

    Åû¶ʱ¼ä£º2022Äê1ÔÂ4ÈÕ

    Ç鱨ȪԴ£ºhttp://blog.nsfocus.net/agentvxapt-evilnum/

    Ïà¹ØÐÅÏ¢£º

    EvilnumÊÇÒ»¸öÔÚ2018Äê±»·¢Ã÷µÄAPT×éÖ¯£¬£¬£¬£¬ £¬£¬£¬£¬»îÔ¾ÓÚÓ¢¹úºÍÅ·ÓѰî¼Ò£¬£¬£¬£¬ £¬£¬£¬£¬Ö÷Òª¹¥»÷Ä¿µÄΪ½ðÈڿƼ¼¹«Ë¾¡£¡£¡£¡£¡£¡£×éÖ¯Ãû³ÆEvilnumÀ´×ÔͬÃûµÄľÂí³ÌÐò£¬£¬£¬£¬ £¬£¬£¬£¬Òà±»¿¨°Í˹»ù³ÆÎªDeathStalker¡£¡£¡£¡£¡£¡£

    EvilnumµÄ´ú±íÐÔ¹¥»÷ÊÖ¶ÎÊǽ«¶ñÒâ³ÌÐòαװ³É¿Í»§µÄÉí·Ý֤ʵÎļþ£¬£¬£¬£¬ £¬£¬£¬£¬ÓÕÆ­½ðÈÚ¹«Ë¾µÄÊÂÇéÖ°Ô±ÔËÐÐÕâЩ³ÌÐò£¬£¬£¬£¬ £¬£¬£¬£¬½ø¶øÍ¨¹ýÖ²ÈëÌØ¹¤Ä¾Âí»ñµÃÊܺ¦ÕßÖ÷»úÉϵĸ߼ÛÖµÐÅÏ¢¡£¡£¡£¡£¡£¡£

    ½üÆÚ£¬£¬£¬£¬ £¬£¬£¬£¬Ñо¿Ö°Ô±²¶»ñµ½¶à¸öÒÔ»¤ÕÕɨÃèÎļþ×÷ΪÓÕ¶üµÄÍøÂç´¹ÂÚÔ˶¯¡£¡£¡£¡£¡£¡£¾­Ì«¹ýÎö£¬£¬£¬£¬ £¬£¬£¬£¬È·ÈϸÃÔ˶¯À´×ÔAPT×éÖ¯Evilnum£¬£¬£¬£¬ £¬£¬£¬£¬ÊÇÆäºã¾ÃÒÔÀ´Õë¶Ô½ðÈÚÄ¿µÄ·¸·¨Ô˶¯µÄÑÓÐø¡£¡£¡£¡£¡£¡£Evilnum¹¥»÷ÕßÔÚ±¾´Î´¹ÂÚÔ˶¯Öй¹½¨ÁËÐÂÐ͹¥»÷Á÷³Ì£¬£¬£¬£¬ £¬£¬£¬£¬²¢Í¨¹ýNSIS°ü×°¡¢ÊðÃû¡¢ÒþдÊõµÈ²Ù×÷ʵÏÖÃâɱ£¬£¬£¬£¬ £¬£¬£¬£¬×îÖÕͶµÝÒ»ÖÖÐÂÐÍľÂí³ÌÐòAgentVX¡£¡£¡£¡£¡£¡£

    06

    “KONNI”ʹÓÃÐÂÄêÎʺòÃé×¼¶íÂÞ˹Íâ½»¹Ù

    Åû¶ʱ¼ä£º2022Äê1ÔÂ3ÈÕ

    Ç鱨ȪԴ£ºhttps://cluster25.io/wp-content/uploads/2022/01/Konni_targeting_Russian_diplomatic_sector.pdf

    Ïà¹ØÐÅÏ¢£º

    ½üÆÚ£¬£¬£¬£¬ £¬£¬£¬£¬Ñо¿Ö°Ô±¼à²âµ½Ò»ÆðÓ볯ÏÊ×éÖ¯“Konni”ÓйصĹ¥»÷Ô˶¯£¬£¬£¬£¬ £¬£¬£¬£¬¸Ã×éÖ¯ÒÔ¶íÂÞ˹Íâ½»²¿·ÖΪĿµÄ£¬£¬£¬£¬ £¬£¬£¬£¬ÔÚ´¹ÂÚÓʼþÖÐʹÓÃÐÂÄê×£ºØ×÷ΪÓÕ¶üÖ÷Ìâ¡£¡£¡£¡£¡£¡£Ò»µ©¶ñÒâµç×ÓÓʼþ¸½¼þ±»·­¿ª²¢Ö´ÐУ¬£¬£¬£¬ £¬£¬£¬£¬¾Í»á´¥·¢Óɶà¸ö½×¶Î×é³ÉµÄ¹¥»÷Á´£¬£¬£¬£¬ £¬£¬£¬£¬×îÖÕÔÚÄ¿µÄÊܺ¦ÕßϵͳÖа²ÅÅKonniRAT¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£

    ÔÚ±¾´Î¹¥»÷Ô˶¯ÖУ¬£¬£¬£¬ £¬£¬£¬£¬Konni×é֯ûÓÐʹÓöñÒâÎļþ×÷Ϊ¸½¼þ£¬£¬£¬£¬ £¬£¬£¬£¬¶øÊǸ½¼ÓÁËÒ»¸öÃûΪ“§á§à§Ù§Õ§â§Ñ§Ó§Ý§Ö§ß§Ú§Ö”µÄ.zipÀàÐÍÎļþ£¬£¬£¬£¬ £¬£¬£¬£¬ÔÚ¶íÓïÖÐÒâΪ“×£ºØ”¡£¡£¡£¡£¡£¡£¸ÃÎļþÒ»µ©½âѹËõ£¬£¬£¬£¬ £¬£¬£¬£¬¾Í»áÊÍ·ÅÒ»¸ö¶ñÒâÏÂÔØ³ÌÐò£¬£¬£¬£¬ £¬£¬£¬£¬¸ÃÏÂÔØ³ÌÐòÄܹ»¼¤»îÒ»¸öÖØ´óµÄ²Ù×÷Á´£¬£¬£¬£¬ £¬£¬£¬£¬×îÖÕ°²ÅÅKonniRAT¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£

ÿÖܸ߼¶ÍþвÇ鱨½â¶Á(2021.12.30~2022.01.06)

    ¹¥»÷Ðж¯»òÊÂÎñÇ鱨

    01

    ¹¥»÷Õßð³äÃÀ¹úСÆóÒµÖÎÀí¾ÖÒÔйÚÔ®ÖúΪÓÕ¶ü¾ÙÐд¹ÂÚÔ˶¯

    Åû¶ʱ¼ä£º2021Äê12ÔÂ29ÈÕ

    Ç鱨ȪԴ£ºhttps://cofense.com/threat-actors-continue-to-leverage-pandemic-relief-plans/

    Ïà¹ØÐÅÏ¢£º

    ÓÉÓÚйڲ¡¶¾µÄÓ°ÏìÈÔÔÚÈÅÂÒÈËÃǵÄÉúÑÄºÍÆóÒµ£¬£¬£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßÊÔͼʹÓÃÄÇЩ½¹ÂÇÆÚ´ýÕþ¸®Ô®ÖúµÄÈ˵Ľ¹ÂÇ£¬£¬£¬£¬ £¬£¬£¬£¬Ã°³äÃÀ¹úСÆóÒµÖÎÀí¾Ö(SBA)µÄ´ú±íÏòÄ¿µÄ·¢ËÍ´¹ÂÚÓʼþ£¬£¬£¬£¬ £¬£¬£¬£¬Í¨¹ýGoogleDocsÌṩµÄ²»·¨±í¸ñÌṩÐéαµÄ×ÊÖúÉêÇ룬£¬£¬£¬ £¬£¬£¬£¬ÇÔÈ¡Êܺ¦ÕßµÄ˽ÈËÐÅÏ¢¡£¡£¡£¡£¡£¡£

    ¹¥»÷ÕßÔÚ´¹ÂÚÓʼþÖÐʹÓÃSBA»Õ±êºÍSBA¿Í»§Ð§À͵ÄÕýµ±ºÅÂëÒÔÔöÇ¿ºÍÓÕÆ­ÐÔ£¬£¬£¬£¬ £¬£¬£¬£¬Öð²½ÓÕµ¼Êܺ¦Õß·­¿ª²¢ÌîдGoogleÎĵµ±íµ¥£¬£¬£¬£¬ £¬£¬£¬£¬»ñÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬ £¬£¬£¬£¬ÀýÈçÉç»áÇå¾²ºÅÂ룬£¬£¬£¬ £¬£¬£¬£¬²¢×îÖÕ»ñÈ¡ÒøÐÐÕʺźͼÝʻִÕÕÐÅÏ¢¡£¡£¡£¡£¡£¡£

    02

    Lapsus$ÀÕË÷Èí¼þÍÅ»ïÕë¶ÔÆÏÌÑÑÀ×î´óµÄýÌ幫˾

    Åû¶ʱ¼ä£º2022Äê1ÔÂ2ÈÕ

    Ç鱨ȪԴ£ºhttps://therecord.media/lapsus-ransomware-gang-hits-sic-portugals-largest-tv-channel/

    Ïà¹ØÐÅÏ¢£º

    Lapsus$ÀÕË÷Èí¼þÍÅ»ïÈëÇÖÁËÆÏÌÑÑÀ×î´óµÄýÌ弯ÍÅImpresa£¬£¬£¬£¬ £¬£¬£¬£¬²¢¶ÔÆä¾ÙÐÐÀÕË÷Ô˶¯¡£¡£¡£¡£¡£¡£Impresa¹«Ë¾»®·ÖÊÇÆÏÌÑÑÀ×î´óµÄµçÊÓÆµµÀºÍÖܱ¨SICºÍExpressoµÄËùÓÐÕß¡£¡£¡£¡£¡£¡£

    ¹¥»÷±¬·¢ÔÚÐÂÄê¼ÙÆÚʱ´ú£¬£¬£¬£¬ £¬£¬£¬£¬³ýÀÕË÷Ô˶¯Í⣬£¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß»¹¹¥»÷Á˸ù«Ë¾µÄÔÚÏßITЧÀÍÆ÷»ù´¡ÉèÊ©£¬£¬£¬£¬ £¬£¬£¬£¬µ¼ÖÂImpressa¼¯ÍÅ¡¢ExpressoºÍËùÓÐSICµçÊÓÆµµÀµÄÍøÕ¾´¦ÓÚÀëÏß״̬¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹Éù³ÆÒÑ»ñµÃ¶ÔImpresaÑÇÂíÑ·ÍøÂçЧÀÍÕÊ»§µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£

    Æ¾Ö¤ÆÏÌÑÑÀ2021Äê9ÔµĵçÊÓÊÕÊÓÂÊ£¬£¬£¬£¬ £¬£¬£¬£¬SIC¼°ÆäËùÓжþ¼¶ÆµµÀÖ÷µ¼×ŵçÊÓÊг¡£¬£¬£¬£¬ £¬£¬£¬£¬¶øExpressoµÄÖÜ¿¯¿¯ÐÐÁ¿×î´ó¡£¡£¡£¡£¡£¡£Ö»¹ÜÔÆÔÆ£¬£¬£¬£¬ £¬£¬£¬£¬Impressa»¹ÓµÓÐÐí¶àÆäËûýÌ幫˾ºÍÔÓÖ¾£¬£¬£¬£¬ £¬£¬£¬£¬ËùÓÐÕâЩ¹«Ë¾ºÍÔÓÖ¾ÏÖÔÚÒ²×îÓпÉÄÜÊܵ½¹¥»÷µÄÓ°Ïì¡£¡£¡£¡£¡£¡£

    03

    WebSkimmerÔ˶¯Í¨¹ý¹¥»÷ÔÆÊÓÆµÆ½Ì¨Ãé×¼·¿µØ²úÍøÕ¾

    Åû¶ʱ¼ä£º2022Äê1ÔÂ3ÈÕ

    Ç鱨ȪԴ£ºhttps://unit42.paloaltonetworks.com/web-skimmer-video-distribution/

    Ïà¹ØÐÅÏ¢£º

    ¹©Ó¦Á´ÍøÂçÊÇÍøÂç·¸·¨µÄ³£¼ûÄ¿µÄ£¬£¬£¬£¬ £¬£¬£¬£¬ÓÉÓÚ¿ØÖƹ©Ó¦Á´Öеı¡Èõ»·½Ú¿ÉÒÔÈù¥»÷Õß½Ó´¥µ½¸ü¶àµÄÊܺ¦Õß——ÓÈÆäÊǵ±±¡Èõ»·½ÚÊǹ©Ó¦Á´µÄȪԴʱ¡£¡£¡£¡£¡£¡£

    ×î½ü£¬£¬£¬£¬ £¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷¹¥»÷ÕßʹÓÃÔÆÊÓÆµÆ½Ì¨Ïò·¿µØ²úÕ¾µã·Ö·¢Skimmer£¨ÓÖÃû±íµ¥Ð®ÖÆ£©µÄ¹©Ó¦Á´¹¥»÷Ô˶¯¡£¡£¡£¡£¡£¡£ÔÚSkimmer¹¥»÷ÖУ¬£¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß×¢Èë¶ñÒâJavaScript´úÂëÀ´ÈëÇÖÍøÕ¾²¢½ÓÊÜÍøÕ¾HTML±íµ¥Ò³ÃæµÄ¹¦Ð§ÒÔÍøÂçÃô¸ÐµÄÓû§ÐÅÏ¢¡£¡£¡£¡£¡£¡£

    ÔÚ´Ë´¦ÐÎòµÄ¹¥»÷°¸ÀýÖУ¬£¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß½«SkimmerJavaScript´úÂë×¢ÈëÊÓÆµÖУ¬£¬£¬£¬ £¬£¬£¬£¬Òò´Ëÿµ±ÆäËûÈ˵¼ÈëÊÓÆµÊ±£¬£¬£¬£¬ £¬£¬£¬£¬ËûÃǵÄÍøÕ¾Ò²»áǶÈëSkimmer´úÂë¡£¡£¡£¡£¡£¡£

    ¶ñÒâ´úÂëÇ鱨

    01

    AgentTesla¸üÐÂSMTPÊý¾Ýй¶ÊÖÒÕ

    Åû¶ʱ¼ä£º2021Äê12ÔÂ30ÈÕ

    Ç鱨ȪԴ£ºhttps://isc.sans.edu/diary/rss/28190

    Ïà¹ØÐÅÏ¢£º

    AgentTeslaÊÇÒ»ÖÖ»ùÓÚWindowsµÄ¼üÅ̼ͼÆ÷ºÍRAT£¬£¬£¬£¬ £¬£¬£¬£¬Í¨³£Ê¹ÓÃSMTP»òFTPÀ´ÇÔÈ¡±»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ×Ô2014ÄêÒÔÀ´Ò»Ö±±£´æ£¬£¬£¬£¬ £¬£¬£¬£¬SMTPÊÇÆä×î³£ÓõÄÊý¾Ýй¶ҪÁì¡£¡£¡£¡£¡£¡£

    µ½2021Äê11Ô£¬£¬£¬£¬ £¬£¬£¬£¬AgentTeslaÑù±¾Í¨¹ýÍйÜÌṩÉ̽¨ÉèµÄÓʼþЧÀÍÆ÷¸ø±»Ñ¬È¾»ò¿ÉÄÜÊÜÆ­µÄÕË»§·¢ËÍËûÃǵĵç×ÓÓʼþ¡£¡£¡£¡£¡£¡£×Ô2021Äê12ÔÂÒÔÀ´£¬£¬£¬£¬ £¬£¬£¬£¬AgentTeslaʹÓÃÕâЩ±»µÁÓõĵç×ÓÓʼþÕÊ»§½«ÇÔÈ¡µÄÊý¾Ý·¢Ë͵½GmailµØµã¡£¡£¡£¡£¡£¡£

    Æ¾Ö¤ÕâЩGmailµØµãÃû³Æ£¬£¬£¬£¬ £¬£¬£¬£¬ÍƲâËüÃÇÊÇڲƭÐÔµÄGmailÕÊ»§£¬£¬£¬£¬ £¬£¬£¬£¬»òÕßÊÇרÃÅΪÎüÊÕÀ´×ÔAgentTeslaµÄÊý¾Ý¶ø½¨ÉèµÄ¡£¡£¡£¡£¡£¡£

ÿÖܸ߼¶ÍþвÇ鱨½â¶Á(2021.12.30~2022.01.06)

    02

    2021ÄêÊ¢ÐÐÀÕË÷Èí¼þÅÌ»õ

    Åû¶ʱ¼ä£º2022Äê1ÔÂ3ÈÕ

    Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/OX0jsdIXpdKWXiWOrgd_Hw

    Ïà¹ØÐÅÏ¢£º

    ÀÕË÷Èí¼þÒѾ­³ÉΪȫÇòÆóÒµºÍ×éÖ¯ÃæÁÙµÄÖ÷ÒªÍøÂçÍþв£¬£¬£¬£¬ £¬£¬£¬£¬Ñ¬È¾ÀÕË÷Èí¼þºóÑÏÖØÓ°ÏìÆóÒµºÍ×éÖ¯µÄÔËÓª£¬£¬£¬£¬ £¬£¬£¬£¬°üÀ¨ÓªÒµÖÐÖ¹¡¢Êý¾ÝºÍÐÅÏ¢±»ÇÔÈ¡¹ûÕæÊÛÂô¡£¡£¡£¡£¡£¡£2021ÄêÈ«ÇòÖÆÔìÒµ¡¢Ð§ÀÍÒµ¡¢ÐÞ½¨¡¢½ðÈÚ¡¢ÄÜÔ´¡¢Ò½ÁÆ¡¢¹¤¿ØºÍÕþ¸®×éÖ¯»ú¹¹µÈƵÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬ £¬£¬£¬£¬¸øÈ«Çò¹¤Òµ²úÖµÔì³ÉÑÏÖØËðʧ¡£¡£¡£¡£¡£¡£

    Çå¾²Ö°Ô±´Ó¼Ò×åÃû¡¢Êܺ¦Õß¡¢¹¥»÷ʱ¼ä¡¢Ó°ÏìµÈ·½ÃæÄÚÈÝÈëÊÖ£¬£¬£¬£¬ £¬£¬£¬£¬¶Ô2021ÄêÊ¢ÐеÄÀÕË÷Èí¼þ¾ÙÐÐÁËÊáÀí£¬£¬£¬£¬ £¬£¬£¬£¬ÐÎÁ¢ÊÒ×å¸ÅÀÀ²¢¶ÔÆä¾ÙÐÐÁËÏêϸÏÈÈÝ¡£¡£¡£¡£¡£¡£ÆäÖÐ2021ÄêµÄÀÕË÷Èí¼þÐÐΪÖ÷ÒªÓÐÒÔÏÂËÄÀࣺӰÏìÓû§ÏµÍ³¡¢ÆÆËðÊý¾Ý¡¢¼ÓÃÜÎļþ¡¢ÇÔÈ¡Îļþ¡£¡£¡£¡£¡£¡£

    03

    Telegram×°Öðü±»ÓÃÓÚÈö²¥PurpleFoxºóÃųÌÐò

    Åû¶ʱ¼ä£º2022Äê1ÔÂ4ÈÕ

    Ç鱨ȪԴ£ºhttps://blog.minerva-labs.com/malicious-telegram-installer-drops-purple-fox-rootkit

    Ïà¹ØÐÅÏ¢£º

    PurpleFoxÊÇÒ»ÖÖ»ùÓÚWindowsµÄºóÃÅ£¬£¬£¬£¬ £¬£¬£¬£¬ÓÚ2018ÄêÊ×´Î×÷ΪÎÞÎļþÏÂÔØÆ÷ľÂí·ºÆð£¬£¬£¬£¬ £¬£¬£¬£¬¸ÃľÂíͨ¹ýÎó²îʹÓù¤¾ß°ü·Ö·¢£¬£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÆÆËðÁË30,000¶ą̀ÅÌËã»ú¡£¡£¡£¡£¡£¡£

    ¿ËÈÕ£¬£¬£¬£¬ £¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷»ùÓÚÔÆµÄ¼´Ê±ÐÂÎÅÓ¦ÓóÌÐòTelegramµÄ×°ÖóÌÐòÒѱ»ÆÆË𣬣¬£¬£¬ £¬£¬£¬£¬ÓÃÒÔ·Ö·¢PurpleFox¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£±¾´Î¹¥»÷Ô˶¯Í¨¹ý½«¹¥»÷ÔØºÉ·Ö³É¼¸¸öСÎļþ£¬£¬£¬£¬ £¬£¬£¬£¬×îºó½×¶Îµ¼ÖÂPurpleFoxrootkitѬȾ¡£¡£¡£¡£¡£¡£

    ¹¥»÷Á´ÒÔTelegram×°ÖóÌÐòÎļþ×îÏÈ£¬£¬£¬£¬ £¬£¬£¬£¬ÒÔÃûΪ“TextInputh.exe”µÄ¶ñÒâÏÂÔØ³ÌÐò¿¢Ê¡£¡£¡£¡£¡£¡£¶ñÒâÏÂÔØÆ÷ʹÓÃÃûΪ“TelegramDesktop.exe”µÄAutoIt¾ç±¾´ÓC2ЧÀÍÆ÷×°ÖÃÆäËû¶ñÒâÈí¼þ£º1.rar–°üÀ¨ÏÂÒ»½×¶ÎµÄÎļþ£»£»£»£»£» £»£»7zz.exe–Õýµ±µÄ7z¹éµµ³ÌÐò¡£¡£¡£¡£¡£¡£7zz.exeÓÃÓÚ½âѹ1.rar£¬£¬£¬£¬ £¬£¬£¬£¬ÆäÖаüÀ¨rundll3222.exe¡¢svchost.txt¡¢360.tct¡¢ojbk.exe¡£¡£¡£¡£¡£¡£

ÿÖܸ߼¶ÍþвÇ鱨½â¶Á(2021.12.30~2022.01.06)

    Îó²îÏà¹Ø

    01

    ApacheAPISIXDashboardÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲Σº¦Í¨¸æµÚ¶þ´Î¸üÐÂ

    Åû¶ʱ¼ä£º2021Äê12ÔÂ30ÈÕ

    Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/VWS0awKU5K5kPul9G0DnFw

    Ïà¹ØÐÅÏ¢£º

    APISIXÊÇÒ»¸ö¸ßÐÔÄÜ¡¢¿ÉÀ©Õ¹µÄ΢ЧÀÍAPIÍø¹Ø£¬£¬£¬£¬ £¬£¬£¬£¬»ùÓÚnginx£¨openresty£©ºÍLuaʵÏÖ¹¦Ð§£¬£¬£¬£¬ £¬£¬£¬£¬½è¼øÁËKongµÄ˼Ð÷£¬£¬£¬£¬ £¬£¬£¬£¬½«Kongµ×²ãµÄ¹ØÏµÐÍÊý¾Ý¿â£¨Postgres£©Ìæ»»³ÉÁËNoSQLÐ͵Äetcd¡£¡£¡£¡£¡£¡£

    ¿ËÈÕ£¬£¬£¬£¬ £¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!CERT¼à²âµ½Apache¹Ù·½Ðû²¼ApacheAPISIXDashboardÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-45232£©Ç徲ͨ¸æ¡£¡£¡£¡£¡£¡£

    ÔÚ2.10.1֮ǰµÄApacheAPISIXDashboardÖУ¬£¬£¬£¬ £¬£¬£¬£¬ManagerAPIʹÓÃÁË”gin”ºÍ”droplet”¿ò¼Ü£¬£¬£¬£¬ £¬£¬£¬£¬ÓÉÓÚijЩAPIÖ±½ÓʹÓÃÁË`gin`¿ò¼ÜµÄ½Ó¿Ú²¢Î´×ö¼øÈ¨£¬£¬£¬£¬ £¬£¬£¬£¬´Ó¶øµ¼ÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔ½èÖúδÊÚȨµÄ½Ó¿Ú»ñȡ·ÓÉÉèÖ㬣¬£¬£¬ £¬£¬£¬£¬ÁýÕÖÉèÖÃÐÅÏ¢£¬£¬£¬£¬ £¬£¬£¬£¬»á¼ûÌØ¶¨½Ó¿Ú´Ó¶øÔÚAPISIXServerÖÐÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£

    ÏÖÔÚ£¬£¬£¬£¬ £¬£¬£¬£¬Apache¹Ù·½ÒÑÐû²¼¿É¸üа汾£¬£¬£¬£¬ £¬£¬£¬£¬½¨Òé¿Í»§¾¡¿ì×Բ鲢ÐÞ¸´¡£¡£¡£¡£¡£¡£

    02

    Ñо¿Ö°Ô±·¢Ã÷Uberµç×ÓÓʼþϵͳ±£´æÎó²î

    Åû¶ʱ¼ä£º2022Äê1ÔÂ2ÈÕ

    Ç鱨ȪԴ£ºhttps://www.bleepingcomputer.com/news/security/uber-ignores-vulnerability-that-lets-you-send-any-email-from-ubercom/

    Ïà¹ØÐÅÏ¢£º

    Çå¾²Ñо¿Ô±ºÍÎó²îÉͽðÁÔÈËSeifElsallamy·¢Ã÷ÁËUberϵͳÖеÄÒ»¸öȱÏÝ£¬£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îʹÈκÎÈ˶¼¿ÉÒÔ´ú±íUber·¢Ë͵ç×ÓÓʼþ¡£¡£¡£¡£¡£¡£

    ÕâЩ´ÓUberЧÀÍÆ÷·¢Ë͵ĵç×ÓÓʼþ¶Ôµç×ÓÓʼþÌṩÉÌÀ´ËµËƺõÊÇÕýµ±µÄ£¬£¬£¬£¬ £¬£¬£¬£¬²¢ÇÒ¿ÉÒÔͨ¹ýÈκÎÀ¬»øÓʼþ¹ýÂËÆ÷¡£¡£¡£¡£¡£¡£

    UberÔÚ2016ÄêµÄÊý¾Ýй¶ÊÂÎñÖУ¬£¬£¬£¬ £¬£¬£¬£¬Ì»Â¶ÁË5700ÍòUber¿Í»§ºÍ˾»úµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£Í¨¹ýʹÓÃÕâ¸öδÐÞ²¹µÄÎó²î£¬£¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»áÏòÒÔǰÊܸÃÎó²îÓ°ÏìµÄÊý°ÙÍòUberÓû§·¢ËÍÓÐÕë¶ÔÐÔµÄÍøÂç´¹ÂÚÕ©Æ­¡£¡£¡£¡£¡£¡£

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015ÍøÂçÇ徲ЧÀÍÈÈÏß

95015ÍøÂçÇ徲ЧÀÍÈÈÏß

ɨһɨ¹Ø×¢

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! ÔÚÏ߿ͷþ Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015

Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ

ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿