ʱ¼ä£º2022-01-07
2021.12.30~2022.01.06
¹¥»÷ÍÅ»ïÇ鱨
KimsukyÕë¶Ôº«¹úÐÂÎÅÐÐÒµµÄ´¹ÂÚÔ˶¯ÆÊÎö
LazarusÕë¶Ôº½¿ÕÒµ¼°Çå¾²Ñо¿Ö°Ô±Ìᳫ¹¥»÷
˫βЫʹÓöñÒâAndroid³ÌÐò¹¥»÷Öж«µØÇø
APT33ÐÂÐͶñÒâÔ¶¿ØÈí¼þ“LittleLooter”ÆÊÎö
EvilnumʹÓÃÒþдÊõͶµÝÐÂÐÍľÂíAgentVX
“KONNI”ʹÓÃÐÂÄêÎʺòÃé×¼¶íÂÞ˹Íâ½»¹Ù
¹¥»÷Ðж¯»òÊÂÎñÇ鱨
¹¥»÷Õßð³äÃÀ¹úСÆóÒµÖÎÀí¾ÖÒÔйÚÔ®ÖúΪÓÕ¶ü¾ÙÐд¹ÂÚÔ˶¯
Lapsus$ÀÕË÷Èí¼þÍÅ»ïÕë¶ÔÆÏÌÑÑÀ×î´óµÄýÌ幫˾
WebSkimmerÔ˶¯Í¨¹ý¹¥»÷ÔÆÊÓÆµÆ½Ì¨Ãé×¼·¿µØ²úÍøÕ¾
¶ñÒâ´úÂëÇ鱨
AgentTesla¸üÐÂSMTPÊý¾Ýй¶ÊÖÒÕ
2021ÄêÊ¢ÐÐÀÕË÷Èí¼þÅÌ»õ
Telegram×°Öðü±»ÓÃÓÚÈö²¥PurpleFoxºóÃųÌÐò
Îó²îÇ鱨
ApacheAPISIXDashboardÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲Σº¦Í¨¸æµÚ¶þ´Î¸üÐÂ
Ñо¿Ö°Ô±·¢Ã÷Uberµç×ÓÓʼþϵͳ±£´æÎó²î
¹¥»÷ÍÅ»ïÇ鱨
01
KimsukyÕë¶Ôº«¹úÐÂÎÅÐÐÒµµÄ´¹ÂÚÔ˶¯ÆÊÎö
Åû¶ʱ¼ä£º2021Äê12ÔÂ30ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/O_3PFAB4RGxJXHnx_o9f3Q
Ïà¹ØÐÅÏ¢£º
Ñо¿Ö°Ô±·¢Ã÷Ò»Àýαװ³Éº«¹ú»¥ÁªÍøÇå¾²¾Ö£¨KISA£©Ñо¿Ô±Õë¶Ôº«¹úÐÂÎÅÐÐÒµÖ÷ÒªÈËÎï¾ÙÐÐÓã²æ´¹ÂÚµÄÍøÂç¹¥»÷Ô˶¯£¬£¬£¬£¬£¬£¬£¬£¬¾ÑÐÅÐÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬´Ë´ÎÔ˶¯À´×ÔKimsuky×éÖ¯¡£¡£¡£¡£¡£¡£
¾Ì«¹ýÎö»¹Ô£¬£¬£¬£¬£¬£¬£¬£¬ÍƲ⹥»÷Á÷³ÌÈçÏ£º¹¥»÷ÕßÊ×ÏÈͨ¹ýBBSÎó²îÈëÇÖÁËÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬È»ºóÉÏ´«Webshell¼°ÆäËû¹¥»÷Ô˶¯ÖÐËùÐèÒªµÄ×é¼þµ½webЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬£¬webЧÀÍÆ÷×÷ÎªÌø°å»ú£¬£¬£¬£¬£¬£¬£¬£¬ÊµÏÖ·¢ËÍÓʼþ¡¢ÎüÊÕÊܺ¦ÕßÐÅÏ¢¡¢Ìṩ¶ñÒâÔØºÉÏÂÔØµÈ¹¦Ð§¡£¡£¡£¡£¡£¡£×îºó¹¥»÷Õ߽ṹ´¹ÂÚÓʼþͶµÝµ½Ä¿µÄ»úÓÕµ¼Óû§Ö´ÐУ¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýWebshell»ñÈ¡ÍøÂçµ½µÄÊܺ¦ÕßÐÅÏ¢¡£¡£¡£¡£¡£¡£

02
LazarusÕë¶Ôº½¿ÕÒµ¼°Çå¾²Ñо¿Ö°Ô±Ìᳫ¹¥»÷
Åû¶ʱ¼ä£º2021Äê12ÔÂ30ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/fVrGwrJxo_GW6FtfghzCzA
Ïà¹ØÐÅÏ¢£º
Lazarus×éÖ¯ÊÇÒÉËÆ¾ßÓйú¼ÒÅä¾°µÄ¾³Íâ´óÐÍAPT¼¯ÍÅ×éÖ¯£¬£¬£¬£¬£¬£¬£¬£¬¸Ã×é֝ɯÓÚʹÓÃÉç»á¹¤³Ìѧ¼Æ»®Õë¶ÔÕþ¸®¡¢¿ÆÑС¢½ðÈÚ¡¢º½¿Õ¡¢¼ÓÃÜÇ®±ÒµÈ»ú¹¹¾ÙÐж¨Ïò¹¥»÷Ô˶¯£¬£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡Ö÷ÒªÇ鱨ÐÅÏ¢¼°»ñÈ¡¾¼ÃÀûÒæÊÇÆäÖ÷ҪĿµÄ¡£¡£¡£¡£¡£¡£
Çå¾²³§É̼à²âµ½Lazarus×éÖ¯Õë¶Ôº½¿ÕÒµ¼°Çå¾²Ñо¿Ö°Ô±µÄ¶¨Ïò¹¥»÷Ô˶¯£¬£¬£¬£¬£¬£¬£¬£¬ÆÊÎöÓÐÈçÏ·¢Ã÷£º
¹¥»÷ÕßαװÃÀ¹ú“Âå¿ËÏ£µÂÂí¶¡”º½¿Õ¹«Ë¾ÕÐÆ¸Îĵµ£¬£¬£¬£¬£¬£¬£¬£¬ÏòÄ¿µÄͶµÝÓÕ¶üÎĵµ¾ÙÐй¥»÷£»£»£»£»£»£»£»
ËùͶµÝÎĵµ×îÖÕ¼ÓÔØÖ´ÐжñÒâºóÃÅÄ£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬£¬ÊµÏÖ¶ÔÄ¿µÄÖ÷»úµÄÔ¶³Ì¿ØÖÆ£»£»£»£»£»£»£»
ͬʱ»¹Ê¹ÓÃÏàͬµÄÎĵµÄ£°åÖÆ×÷Google¹«Ë¾µÄÕÐÆ¸ÓÕ¶üÎĵµ¾ÙÐй¥»÷Ô˶¯£»£»£»£»£»£»£»
¹¥»÷ÕßÐ޸ĿªÔ´ÏîÄ¿NppShell¿ª·¢Ä¾Âí£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÌӱܲ¿·ÖÇå¾²Èí¼þ¼ì²â£»£»£»£»£»£»£»
Lazarus¸´ÓÃÒÔÍù¹¥»÷ÊÖ·¨£¬£¬£¬£¬£¬£¬£¬£¬Ð޸ĿªÔ´SumatraPDFÔĶÁÆ÷¾ÙÐй¥»÷£»£»£»£»£»£»£»
±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯½«¶ñÒâ×é¼þÀ¦°óµ½IDAPro×°Öðü³ÌÐòÕë¶ÔÇå¾²Ñо¿Ö°Ô±¾ÙÐй¥»÷¡£¡£¡£¡£¡£¡£
03
˫βЫʹÓöñÒâAndroid³ÌÐò¹¥»÷Öж«µØÇø
Åû¶ʱ¼ä£º2021Äê12ÔÂ28ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/RRH9vgnNJyc1idTLS6okcw
Ïà¹ØÐÅÏ¢£º
½üÆÚ£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±²¶»ñÁËÒ»¿îAPT-C-23Ñù±¾¡£¡£¡£¡£¡£¡£APT-C-23ÓÖ±»³ÆÎª“˫βЫ”£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ2017ÄêÊ״α»·¢Ã÷£¬£¬£¬£¬£¬£¬£¬£¬Õâ¸ö×éÖ¯Õë¶Ô°ÍÀÕ˹̹µÈ¹ú¼ÒºÍµØÇø¡£¡£¡£¡£¡£¡£Ôڴ˴β¶»ñµÄÑù±¾ÖУ¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷´Ë¶ñÒâÈí¼þÃûΪ“GooglePlayInstaller”¶ñÒâ³ÌÐò£¬£¬£¬£¬£¬£¬£¬£¬×°Öúóαװ³ÉTelegramÓ¦ÓóÌÐòÀàËÆµÄͼ±êºÍ½çÃæ¡£¡£¡£¡£¡£¡£
¸Ã¶ñÒâÈí¼þÔÚ¶à¸öά¶È»ñÈ¡Óû§µÄÖÖÖÖÒþ˽ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ»ñÈ¡Óû§Òþ˽ÐÅÏ¢Öк¬ÓлñÈ¡Óû§µÄÁªÏµÈËÐÅÏ¢¡¢¶ÌÐÅ¡¢Í¨»°¼Í¼¡¢Í¼Æ¬¡¢Îĵµ¡¢ÒÔ¼°ÒôƵÎļþ¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»ñÈ¡ÔÆÔÆÖ®¶àµÄÓû§ÐÅÏ¢¿ÉνÊÇÈ«ÁýÕÖ¡£¡£¡£¡£¡£¡£

04
APT33ÐÂÐͶñÒâÔ¶¿ØÈí¼þ“LittleLooter”ÆÊÎö
Åû¶ʱ¼ä£º2021Äê12ÔÂ31ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/Zj44UM--9UyonjhxEHvRBA
Ïà¹ØÐÅÏ¢£º
½üÆÚ£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±¼à²âµ½Ò»¿îÃûΪ“WhatsApp.apk”µÄÐéαÉç½»Èí¼þ£¬£¬£¬£¬£¬£¬£¬£¬×ÅʵÊÇÒ»¿î¶ñÒâÇÔÃÜÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÒÉ»óÓû§ÏÂÔØ£¬£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¿ØÖÆÓû§ÊÖ»ú,²¢ÇÔÈ¡Óû§µÄÒþ˽Êý¾Ý¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÆÊÎö·¢Ã÷ÊÇAPT33×éÖ¯µÄÐÂÐÍÔ¶¿ØÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬Æ¾Ö¤Æä¶ñÒâÐÐΪ½«ÆäÃüÃûΪ“LittleLooter”¡£¡£¡£¡£¡£¡£
“WhatsApp”ÊÇÈ«Çò×ÅÃûµÄͨѶÉç½»Èí¼þ£¬£¬£¬£¬£¬£¬£¬£¬µ«´ËÓ¦ÓÃÖ÷ÒªÊÇÍâÑóµÄÓû§ÈºÌ壬£¬£¬£¬£¬£¬£¬£¬²¢Î´ÔÚº£ÄÚÓ¦ÓÃÊг¡Éϼܣ¬£¬£¬£¬£¬£¬£¬£¬Óû§ÔÚÀÖ³É×°ÖÃÐéαµÄ“WhatsApp”ºó£¬£¬£¬£¬£¬£¬£¬£¬Ò²ÎÞ·¨·¿ª£¬£¬£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ»áɾ³ý×ÔÉíµÄ½çÃæµÄͼ±ê£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÌáÐѓδװÖøÃÓ¦ÓÔ£¬£¬£¬£¬£¬£¬£¬£¬µ«´Ë¶ñÒâÈí¼þ²¢Ã»ÓÐɾ³ý£¬£¬£¬£¬£¬£¬£¬£¬ÔÚºǫ́ÒÀÈ»±£´æ£¬£¬£¬£¬£¬£¬£¬£¬²¢¼ÌÐø¼àÌý£¬£¬£¬£¬£¬£¬£¬£¬ÍøÂçÊÖ»úÓû§µÄÒþ˽ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨Óû§µÄͨѶ¼¡¢¶ÌÐÅÄÚÈÝ¡¢Í¨Ñ¶¼Í¼¡¢ÊÖ»ú´æ´¢µÄÎļþ¡¢Óû§¶¨Î»¡¢ÍøÂçÐÅÏ¢¡¢×°±¸ÐÅÏ¢¡¢ä¯ÀÀÆ÷ÀúÊ·¡¢ÕÕÆ¬Â¼Òô¼ÏñºÍ×°ÖõÄÓ¦ÓÃÁÐ±í£¬£¬£¬£¬£¬£¬£¬£¬Í¬Ê±Ô¶³Ì²Ù¿ØÓû§ÊÖ»ú·¢ËͶÌÐÅ¡¢²¦´òµç»°¡¢Â¼ÒôºÍÉÏ´«ÎļþµÈ¶ñÒâ²Ù×÷¡£¡£¡£¡£¡£¡£

05
EvilnumʹÓÃÒþдÊõͶµÝÐÂÐÍľÂíAgentVX
Åû¶ʱ¼ä£º2022Äê1ÔÂ4ÈÕ
Ç鱨ȪԴ£ºhttp://blog.nsfocus.net/agentvxapt-evilnum/
Ïà¹ØÐÅÏ¢£º
EvilnumÊÇÒ»¸öÔÚ2018Äê±»·¢Ã÷µÄAPT×éÖ¯£¬£¬£¬£¬£¬£¬£¬£¬»îÔ¾ÓÚÓ¢¹úºÍÅ·ÓѰî¼Ò£¬£¬£¬£¬£¬£¬£¬£¬Ö÷Òª¹¥»÷Ä¿µÄΪ½ðÈڿƼ¼¹«Ë¾¡£¡£¡£¡£¡£¡£×éÖ¯Ãû³ÆEvilnumÀ´×ÔͬÃûµÄľÂí³ÌÐò£¬£¬£¬£¬£¬£¬£¬£¬Òà±»¿¨°Í˹»ù³ÆÎªDeathStalker¡£¡£¡£¡£¡£¡£
EvilnumµÄ´ú±íÐÔ¹¥»÷ÊÖ¶ÎÊǽ«¶ñÒâ³ÌÐòαװ³É¿Í»§µÄÉí·Ý֤ʵÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÓÕÆ½ðÈÚ¹«Ë¾µÄÊÂÇéÖ°Ô±ÔËÐÐÕâЩ³ÌÐò£¬£¬£¬£¬£¬£¬£¬£¬½ø¶øÍ¨¹ýÖ²ÈëÌØ¹¤Ä¾Âí»ñµÃÊܺ¦ÕßÖ÷»úÉϵĸ߼ÛÖµÐÅÏ¢¡£¡£¡£¡£¡£¡£
½üÆÚ£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±²¶»ñµ½¶à¸öÒÔ»¤ÕÕɨÃèÎļþ×÷ΪÓÕ¶üµÄÍøÂç´¹ÂÚÔ˶¯¡£¡£¡£¡£¡£¡£¾Ì«¹ýÎö£¬£¬£¬£¬£¬£¬£¬£¬È·ÈϸÃÔ˶¯À´×ÔAPT×éÖ¯Evilnum£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÆäºã¾ÃÒÔÀ´Õë¶Ô½ðÈÚÄ¿µÄ·¸·¨Ô˶¯µÄÑÓÐø¡£¡£¡£¡£¡£¡£Evilnum¹¥»÷ÕßÔÚ±¾´Î´¹ÂÚÔ˶¯Öй¹½¨ÁËÐÂÐ͹¥»÷Á÷³Ì£¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýNSIS°ü×°¡¢ÊðÃû¡¢ÒþдÊõµÈ²Ù×÷ʵÏÖÃâɱ£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕͶµÝÒ»ÖÖÐÂÐÍľÂí³ÌÐòAgentVX¡£¡£¡£¡£¡£¡£
06
“KONNI”ʹÓÃÐÂÄêÎʺòÃé×¼¶íÂÞ˹Íâ½»¹Ù
Åû¶ʱ¼ä£º2022Äê1ÔÂ3ÈÕ
Ç鱨ȪԴ£ºhttps://cluster25.io/wp-content/uploads/2022/01/Konni_targeting_Russian_diplomatic_sector.pdf
Ïà¹ØÐÅÏ¢£º
½üÆÚ£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±¼à²âµ½Ò»ÆðÓ볯ÏÊ×éÖ¯“Konni”ÓйصĹ¥»÷Ô˶¯£¬£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ÒÔ¶íÂÞ˹Íâ½»²¿·ÖΪĿµÄ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ´¹ÂÚÓʼþÖÐʹÓÃÐÂÄê×£ºØ×÷ΪÓÕ¶üÖ÷Ìâ¡£¡£¡£¡£¡£¡£Ò»µ©¶ñÒâµç×ÓÓʼþ¸½¼þ±»·¿ª²¢Ö´ÐУ¬£¬£¬£¬£¬£¬£¬£¬¾Í»á´¥·¢Óɶà¸ö½×¶Î×é³ÉµÄ¹¥»÷Á´£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕÔÚÄ¿µÄÊܺ¦ÕßϵͳÖа²ÅÅKonniRAT¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£
ÔÚ±¾´Î¹¥»÷Ô˶¯ÖУ¬£¬£¬£¬£¬£¬£¬£¬Konni×é֯ûÓÐʹÓöñÒâÎļþ×÷Ϊ¸½¼þ£¬£¬£¬£¬£¬£¬£¬£¬¶øÊǸ½¼ÓÁËÒ»¸öÃûΪ“§á§à§Ù§Õ§â§Ñ§Ó§Ý§Ö§ß§Ú§Ö”µÄ.zipÀàÐÍÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ¶íÓïÖÐÒâΪ“×£ºØ”¡£¡£¡£¡£¡£¡£¸ÃÎļþÒ»µ©½âѹËõ£¬£¬£¬£¬£¬£¬£¬£¬¾Í»áÊÍ·ÅÒ»¸ö¶ñÒâÏÂÔØ³ÌÐò£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÏÂÔØ³ÌÐòÄܹ»¼¤»îÒ»¸öÖØ´óµÄ²Ù×÷Á´£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕ°²ÅÅKonniRAT¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£

¹¥»÷Ðж¯»òÊÂÎñÇ鱨
01
¹¥»÷Õßð³äÃÀ¹úСÆóÒµÖÎÀí¾ÖÒÔйÚÔ®ÖúΪÓÕ¶ü¾ÙÐд¹ÂÚÔ˶¯
Åû¶ʱ¼ä£º2021Äê12ÔÂ29ÈÕ
Ç鱨ȪԴ£ºhttps://cofense.com/threat-actors-continue-to-leverage-pandemic-relief-plans/
Ïà¹ØÐÅÏ¢£º
ÓÉÓÚйڲ¡¶¾µÄÓ°ÏìÈÔÔÚÈÅÂÒÈËÃǵÄÉúÑÄºÍÆóÒµ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÊÔͼʹÓÃÄÇЩ½¹ÂÇÆÚ´ýÕþ¸®Ô®ÖúµÄÈ˵Ľ¹ÂÇ£¬£¬£¬£¬£¬£¬£¬£¬Ã°³äÃÀ¹úСÆóÒµÖÎÀí¾Ö(SBA)µÄ´ú±íÏòÄ¿µÄ·¢ËÍ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýGoogleDocsÌṩµÄ²»·¨±í¸ñÌṩÐéαµÄ×ÊÖúÉêÇ룬£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡Êܺ¦ÕßµÄ˽ÈËÐÅÏ¢¡£¡£¡£¡£¡£¡£
¹¥»÷ÕßÔÚ´¹ÂÚÓʼþÖÐʹÓÃSBA»Õ±êºÍSBA¿Í»§Ð§À͵ÄÕýµ±ºÅÂëÒÔÔöÇ¿ºÍÓÕÆÐÔ£¬£¬£¬£¬£¬£¬£¬£¬Öð²½ÓÕµ¼Êܺ¦Õß·¿ª²¢ÌîдGoogleÎĵµ±íµ¥£¬£¬£¬£¬£¬£¬£¬£¬»ñÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçÉç»áÇå¾²ºÅÂ룬£¬£¬£¬£¬£¬£¬£¬²¢×îÖÕ»ñÈ¡ÒøÐÐÕʺźͼÝʻִÕÕÐÅÏ¢¡£¡£¡£¡£¡£¡£
02
Lapsus$ÀÕË÷Èí¼þÍÅ»ïÕë¶ÔÆÏÌÑÑÀ×î´óµÄýÌ幫˾
Åû¶ʱ¼ä£º2022Äê1ÔÂ2ÈÕ
Ç鱨ȪԴ£ºhttps://therecord.media/lapsus-ransomware-gang-hits-sic-portugals-largest-tv-channel/
Ïà¹ØÐÅÏ¢£º
Lapsus$ÀÕË÷Èí¼þÍÅ»ïÈëÇÖÁËÆÏÌÑÑÀ×î´óµÄýÌ弯ÍÅImpresa£¬£¬£¬£¬£¬£¬£¬£¬²¢¶ÔÆä¾ÙÐÐÀÕË÷Ô˶¯¡£¡£¡£¡£¡£¡£Impresa¹«Ë¾»®·ÖÊÇÆÏÌÑÑÀ×î´óµÄµçÊÓÆµµÀºÍÖܱ¨SICºÍExpressoµÄËùÓÐÕß¡£¡£¡£¡£¡£¡£
¹¥»÷±¬·¢ÔÚÐÂÄê¼ÙÆÚʱ´ú£¬£¬£¬£¬£¬£¬£¬£¬³ýÀÕË÷Ô˶¯Í⣬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹¹¥»÷Á˸ù«Ë¾µÄÔÚÏßITЧÀÍÆ÷»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂImpressa¼¯ÍÅ¡¢ExpressoºÍËùÓÐSICµçÊÓÆµµÀµÄÍøÕ¾´¦ÓÚÀëÏß״̬¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹Éù³ÆÒÑ»ñµÃ¶ÔImpresaÑÇÂíÑ·ÍøÂçЧÀÍÕÊ»§µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£
ƾ֤ÆÏÌÑÑÀ2021Äê9ÔµĵçÊÓÊÕÊÓÂÊ£¬£¬£¬£¬£¬£¬£¬£¬SIC¼°ÆäËùÓжþ¼¶ÆµµÀÖ÷µ¼×ŵçÊÓÊг¡£¬£¬£¬£¬£¬£¬£¬£¬¶øExpressoµÄÖÜ¿¯¿¯ÐÐÁ¿×î´ó¡£¡£¡£¡£¡£¡£Ö»¹ÜÔÆÔÆ£¬£¬£¬£¬£¬£¬£¬£¬Impressa»¹ÓµÓÐÐí¶àÆäËûýÌ幫˾ºÍÔÓÖ¾£¬£¬£¬£¬£¬£¬£¬£¬ËùÓÐÕâЩ¹«Ë¾ºÍÔÓÖ¾ÏÖÔÚÒ²×îÓпÉÄÜÊܵ½¹¥»÷µÄÓ°Ïì¡£¡£¡£¡£¡£¡£
03
WebSkimmerÔ˶¯Í¨¹ý¹¥»÷ÔÆÊÓÆµÆ½Ì¨Ãé×¼·¿µØ²úÍøÕ¾
Åû¶ʱ¼ä£º2022Äê1ÔÂ3ÈÕ
Ç鱨ȪԴ£ºhttps://unit42.paloaltonetworks.com/web-skimmer-video-distribution/
Ïà¹ØÐÅÏ¢£º
¹©Ó¦Á´ÍøÂçÊÇÍøÂç·¸·¨µÄ³£¼ûÄ¿µÄ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ¿ØÖƹ©Ó¦Á´Öеı¡Èõ»·½Ú¿ÉÒÔÈù¥»÷Õß½Ó´¥µ½¸ü¶àµÄÊܺ¦Õß——ÓÈÆäÊǵ±±¡Èõ»·½ÚÊǹ©Ó¦Á´µÄȪԴʱ¡£¡£¡£¡£¡£¡£
×î½ü£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷¹¥»÷ÕßʹÓÃÔÆÊÓÆµÆ½Ì¨Ïò·¿µØ²úÕ¾µã·Ö·¢Skimmer£¨ÓÖÃû±íµ¥Ð®ÖÆ£©µÄ¹©Ó¦Á´¹¥»÷Ô˶¯¡£¡£¡£¡£¡£¡£ÔÚSkimmer¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß×¢Èë¶ñÒâJavaScript´úÂëÀ´ÈëÇÖÍøÕ¾²¢½ÓÊÜÍøÕ¾HTML±íµ¥Ò³ÃæµÄ¹¦Ð§ÒÔÍøÂçÃô¸ÐµÄÓû§ÐÅÏ¢¡£¡£¡£¡£¡£¡£
ÔÚ´Ë´¦ÐÎòµÄ¹¥»÷°¸ÀýÖУ¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß½«SkimmerJavaScript´úÂë×¢ÈëÊÓÆµÖУ¬£¬£¬£¬£¬£¬£¬£¬Òò´Ëÿµ±ÆäËûÈ˵¼ÈëÊÓÆµÊ±£¬£¬£¬£¬£¬£¬£¬£¬ËûÃǵÄÍøÕ¾Ò²»áǶÈëSkimmer´úÂë¡£¡£¡£¡£¡£¡£
¶ñÒâ´úÂëÇ鱨
01
AgentTesla¸üÐÂSMTPÊý¾Ýй¶ÊÖÒÕ
Åû¶ʱ¼ä£º2021Äê12ÔÂ30ÈÕ
Ç鱨ȪԴ£ºhttps://isc.sans.edu/diary/rss/28190
Ïà¹ØÐÅÏ¢£º
AgentTeslaÊÇÒ»ÖÖ»ùÓÚWindowsµÄ¼üÅ̼ͼÆ÷ºÍRAT£¬£¬£¬£¬£¬£¬£¬£¬Í¨³£Ê¹ÓÃSMTP»òFTPÀ´ÇÔÈ¡±»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ×Ô2014ÄêÒÔÀ´Ò»Ö±±£´æ£¬£¬£¬£¬£¬£¬£¬£¬SMTPÊÇÆä×î³£ÓõÄÊý¾Ýй¶ҪÁì¡£¡£¡£¡£¡£¡£
µ½2021Äê11Ô£¬£¬£¬£¬£¬£¬£¬£¬AgentTeslaÑù±¾Í¨¹ýÍйÜÌṩÉ̽¨ÉèµÄÓʼþЧÀÍÆ÷¸ø±»Ñ¬È¾»ò¿ÉÄÜÊÜÆµÄÕË»§·¢ËÍËûÃǵĵç×ÓÓʼþ¡£¡£¡£¡£¡£¡£×Ô2021Äê12ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬AgentTeslaʹÓÃÕâЩ±»µÁÓõĵç×ÓÓʼþÕÊ»§½«ÇÔÈ¡µÄÊý¾Ý·¢Ë͵½GmailµØµã¡£¡£¡£¡£¡£¡£
ƾ֤ÕâЩGmailµØµãÃû³Æ£¬£¬£¬£¬£¬£¬£¬£¬ÍƲâËüÃÇÊÇÚ²ÆÐÔµÄGmailÕÊ»§£¬£¬£¬£¬£¬£¬£¬£¬»òÕßÊÇרÃÅΪÎüÊÕÀ´×ÔAgentTeslaµÄÊý¾Ý¶ø½¨ÉèµÄ¡£¡£¡£¡£¡£¡£

02
2021ÄêÊ¢ÐÐÀÕË÷Èí¼þÅÌ»õ
Åû¶ʱ¼ä£º2022Äê1ÔÂ3ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/OX0jsdIXpdKWXiWOrgd_Hw
Ïà¹ØÐÅÏ¢£º
ÀÕË÷Èí¼þÒѾ³ÉΪȫÇòÆóÒµºÍ×éÖ¯ÃæÁÙµÄÖ÷ÒªÍøÂçÍþв£¬£¬£¬£¬£¬£¬£¬£¬Ñ¬È¾ÀÕË÷Èí¼þºóÑÏÖØÓ°ÏìÆóÒµºÍ×éÖ¯µÄÔËÓª£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÓªÒµÖÐÖ¹¡¢Êý¾ÝºÍÐÅÏ¢±»ÇÔÈ¡¹ûÕæÊÛÂô¡£¡£¡£¡£¡£¡£2021ÄêÈ«ÇòÖÆÔìÒµ¡¢Ð§ÀÍÒµ¡¢ÐÞ½¨¡¢½ðÈÚ¡¢ÄÜÔ´¡¢Ò½ÁÆ¡¢¹¤¿ØºÍÕþ¸®×éÖ¯»ú¹¹µÈƵÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¸øÈ«Çò¹¤Òµ²úÖµÔì³ÉÑÏÖØËðʧ¡£¡£¡£¡£¡£¡£
Çå¾²Ö°Ô±´Ó¼Ò×åÃû¡¢Êܺ¦Õß¡¢¹¥»÷ʱ¼ä¡¢Ó°ÏìµÈ·½ÃæÄÚÈÝÈëÊÖ£¬£¬£¬£¬£¬£¬£¬£¬¶Ô2021ÄêÊ¢ÐеÄÀÕË÷Èí¼þ¾ÙÐÐÁËÊáÀí£¬£¬£¬£¬£¬£¬£¬£¬ÐÎÁ¢ÊÒ×å¸ÅÀÀ²¢¶ÔÆä¾ÙÐÐÁËÏêϸÏÈÈÝ¡£¡£¡£¡£¡£¡£ÆäÖÐ2021ÄêµÄÀÕË÷Èí¼þÐÐΪÖ÷ÒªÓÐÒÔÏÂËÄÀࣺӰÏìÓû§ÏµÍ³¡¢ÆÆËðÊý¾Ý¡¢¼ÓÃÜÎļþ¡¢ÇÔÈ¡Îļþ¡£¡£¡£¡£¡£¡£
03
Telegram×°Öðü±»ÓÃÓÚÈö²¥PurpleFoxºóÃųÌÐò
Åû¶ʱ¼ä£º2022Äê1ÔÂ4ÈÕ
Ç鱨ȪԴ£ºhttps://blog.minerva-labs.com/malicious-telegram-installer-drops-purple-fox-rootkit
Ïà¹ØÐÅÏ¢£º
PurpleFoxÊÇÒ»ÖÖ»ùÓÚWindowsµÄºóÃÅ£¬£¬£¬£¬£¬£¬£¬£¬ÓÚ2018ÄêÊ×´Î×÷ΪÎÞÎļþÏÂÔØÆ÷ľÂí·ºÆð£¬£¬£¬£¬£¬£¬£¬£¬¸ÃľÂíͨ¹ýÎó²îʹÓù¤¾ß°ü·Ö·¢£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÆÆËðÁË30,000¶ą̀ÅÌËã»ú¡£¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷»ùÓÚÔÆµÄ¼´Ê±ÐÂÎÅÓ¦ÓóÌÐòTelegramµÄ×°ÖóÌÐòÒѱ»ÆÆË𣬣¬£¬£¬£¬£¬£¬£¬ÓÃÒÔ·Ö·¢PurpleFox¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£±¾´Î¹¥»÷Ô˶¯Í¨¹ý½«¹¥»÷ÔØºÉ·Ö³É¼¸¸öСÎļþ£¬£¬£¬£¬£¬£¬£¬£¬×îºó½×¶Îµ¼ÖÂPurpleFoxrootkitѬȾ¡£¡£¡£¡£¡£¡£
¹¥»÷Á´ÒÔTelegram×°ÖóÌÐòÎļþ×îÏÈ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÃûΪ“TextInputh.exe”µÄ¶ñÒâÏÂÔØ³ÌÐò¿¢Ê¡£¡£¡£¡£¡£¡£¶ñÒâÏÂÔØÆ÷ʹÓÃÃûΪ“TelegramDesktop.exe”µÄAutoIt¾ç±¾´ÓC2ЧÀÍÆ÷×°ÖÃÆäËû¶ñÒâÈí¼þ£º1.rar–°üÀ¨ÏÂÒ»½×¶ÎµÄÎļþ£»£»£»£»£»£»£»7zz.exe–Õýµ±µÄ7z¹éµµ³ÌÐò¡£¡£¡£¡£¡£¡£7zz.exeÓÃÓÚ½âѹ1.rar£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨rundll3222.exe¡¢svchost.txt¡¢360.tct¡¢ojbk.exe¡£¡£¡£¡£¡£¡£

Îó²îÏà¹Ø
01
ApacheAPISIXDashboardÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲Σº¦Í¨¸æµÚ¶þ´Î¸üÐÂ
Åû¶ʱ¼ä£º2021Äê12ÔÂ30ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/VWS0awKU5K5kPul9G0DnFw
Ïà¹ØÐÅÏ¢£º
APISIXÊÇÒ»¸ö¸ßÐÔÄÜ¡¢¿ÉÀ©Õ¹µÄ΢ЧÀÍAPIÍø¹Ø£¬£¬£¬£¬£¬£¬£¬£¬»ùÓÚnginx£¨openresty£©ºÍLuaʵÏÖ¹¦Ð§£¬£¬£¬£¬£¬£¬£¬£¬½è¼øÁËKongµÄ˼Ð÷£¬£¬£¬£¬£¬£¬£¬£¬½«Kongµ×²ãµÄ¹ØÏµÐÍÊý¾Ý¿â£¨Postgres£©Ìæ»»³ÉÁËNoSQLÐ͵Äetcd¡£¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!CERT¼à²âµ½Apache¹Ù·½Ðû²¼ApacheAPISIXDashboardÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-45232£©Ç徲ͨ¸æ¡£¡£¡£¡£¡£¡£
ÔÚ2.10.1֮ǰµÄApacheAPISIXDashboardÖУ¬£¬£¬£¬£¬£¬£¬£¬ManagerAPIʹÓÃÁË”gin”ºÍ”droplet”¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚijЩAPIÖ±½ÓʹÓÃÁË`gin`¿ò¼ÜµÄ½Ó¿Ú²¢Î´×ö¼øÈ¨£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔ½èÖúδÊÚȨµÄ½Ó¿Ú»ñȡ·ÓÉÉèÖ㬣¬£¬£¬£¬£¬£¬£¬ÁýÕÖÉèÖÃÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬»á¼ûÌØ¶¨½Ó¿Ú´Ó¶øÔÚAPISIXServerÖÐÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£
ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬Apache¹Ù·½ÒÑÐû²¼¿É¸üа汾£¬£¬£¬£¬£¬£¬£¬£¬½¨Òé¿Í»§¾¡¿ì×Բ鲢ÐÞ¸´¡£¡£¡£¡£¡£¡£
02
Ñо¿Ö°Ô±·¢Ã÷Uberµç×ÓÓʼþϵͳ±£´æÎó²î
Åû¶ʱ¼ä£º2022Äê1ÔÂ2ÈÕ
Ç鱨ȪԴ£ºhttps://www.bleepingcomputer.com/news/security/uber-ignores-vulnerability-that-lets-you-send-any-email-from-ubercom/
Ïà¹ØÐÅÏ¢£º
Çå¾²Ñо¿Ô±ºÍÎó²îÉͽðÁÔÈËSeifElsallamy·¢Ã÷ÁËUberϵͳÖеÄÒ»¸öȱÏÝ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îʹÈκÎÈ˶¼¿ÉÒÔ´ú±íUber·¢Ë͵ç×ÓÓʼþ¡£¡£¡£¡£¡£¡£
ÕâЩ´ÓUberЧÀÍÆ÷·¢Ë͵ĵç×ÓÓʼþ¶Ôµç×ÓÓʼþÌṩÉÌÀ´ËµËƺõÊÇÕýµ±µÄ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔͨ¹ýÈκÎÀ¬»øÓʼþ¹ýÂËÆ÷¡£¡£¡£¡£¡£¡£
UberÔÚ2016ÄêµÄÊý¾Ýй¶ÊÂÎñÖУ¬£¬£¬£¬£¬£¬£¬£¬Ì»Â¶ÁË5700ÍòUber¿Í»§ºÍ˾»úµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£Í¨¹ýʹÓÃÕâ¸öδÐÞ²¹µÄÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»áÏòÒÔǰÊܸÃÎó²îÓ°ÏìµÄÊý°ÙÍòUberÓû§·¢ËÍÓÐÕë¶ÔÐÔµÄÍøÂç´¹ÂÚÕ©Æ¡£¡£¡£¡£¡£¡£
ʱ¼ä£º2026-04-22
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-18
Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ
ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ