ʱ¼ä£º2022-02-04
2022.01.27~02.03
¹¥»÷ÍÅ»ïÇ鱨
Packer£¿£¿£¿£¿£¿£¿£¿£¿¶Ô¿¹£¿£¿£¿£¿£¿£¿£¿£¿“͸Ã÷²¿Âä”ÕýÔÚ×·ÇóCrimsonRATµÄгö·
APT29¹¥»÷Ô˶¯ÖÐʹÓõÄÐÂÓ±Õ½ÂÔºÍÊÖÒÕÆÊÎöMuddyWaterͨ¹ý¶ñÒâPDF¡¢¿ÉÖ´ÐÐÎļþÕë¶ÔÍÁ¶úÆäÓû§
LazarusÔÚ×îÐÂÔ˶¯ÖÐʹÓÃWindowsUpdate¿Í»§¶ËºÍGitHub
¹¥»÷Ðж¯»òÊÂÎñÇ鱨
¹ØÓÚDridexÒøÐÐľÂíµÄ´¹ÂÚÔ˶¯µÄÆÊÎö
¹¥»÷ÕßʹÓÃ×°±¸×¢²á¼¼ÇÉͨ¹ýºáÏòÍøÂç´¹ÂÚ¹¥»÷ÆóÒµ
ÕýÔÚʹÓÃÁ÷Ã¥OAuthÓ¦ÓóÌÐò½ÓÊÜCEOÕÊ»§
¶ñÒâ´úÂëÇ鱨
Vultur¶ñÒâÈí¼þαװ³É2FAÓ¦ÓÃÇÔÈ¡Óû§ÒøÐÐÐÅÏ¢AsyncRATľÂíʹÓÃз½·¨¾ÙÐÐÈö²¥
ChaesBankingľÂíͨ¹ý¶ñÒâÀ©Õ¹Ð®ÖÆChromeä¯ÀÀÆ÷
Îó²îÇ鱨
PolkitÎó²îʹ·ÇÌØÈ¨LinuxÓû§Äܹ»»ñµÃrootȨÏÞ
Æ»¹ûÐû²¼iOSºÍmacOS¸üÐÂÐÞ¸´ÁËÁ½¸öÁãÈÕÎó²î
¹¥»÷ÍÅ»ïÇ鱨
01
Packer£¿£¿£¿£¿£¿£¿£¿£¿¶Ô¿¹£¿£¿£¿£¿£¿£¿£¿£¿“͸Ã÷²¿Âä”ÕýÔÚ×·ÇóCrimsonRATµÄгö·
Åû¶ʱ¼ä£º2022Äê1ÔÂ29ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/epRGn7Tnzx6rXihYXIpIIg
Ïà¹ØÐÅÏ¢£º
TransparentTribe£¨Í¸Ã÷²¿Â䣩£¬£¬£¬£¬£¬£¬£¬ÊÇ2016Äê2Ô±»ProofpointÅû¶²¢ÃüÃûµÄAPT×éÖ¯£¬£¬£¬£¬£¬£¬£¬Ò²±»³ÆÎªProjectM¡¢C-Major¡£¡£¡£¡£¡£¡£¡£¡£¸ÃAPT×éÖ¯±»ÆÕ±éÒÔΪÀ´×ÔÄÏÑǵØÇøÄ³¹ú£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÓëÁíÒ»¸öÓÉPaloaltoUnit42ÍŶÓÅû¶µÄGogronGroup±£´æÒ»¶¨µÄ¹ØÏµ¡£¡£¡£¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐĺìÓêµÎÍŶÓÔÚÒ»Ñùƽ³£µÄÍþвá÷ÁÔÖв¶»ñÁ˸Ã×éÖ¯¶à¸öCrimsonRAT¹¥»÷Ñù±¾¡£¡£¡£¡£¡£¡£¡£¡£Ôڴ˹¥»÷Ô˶¯ÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃͼƬÎļþͼ±êÓÃ×÷¶ñÒâÈí¼þͼ±ê£¬£¬£¬£¬£¬£¬£¬ÓÕʹĿµÄ·¿ª"ͼƬ"Éó²é£¬£¬£¬£¬£¬£¬£¬ÊµÔòÔËÐжñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£µ±Êܺ¦Õßµã»÷Ö´ÐÐÓÕ¶üÎļþÖ®ºó£¬£¬£¬£¬£¬£¬£¬½«»áÔÚÍâµØÊÍ·ÅÒ»¸öѹËõ°ü£¬£¬£¬£¬£¬£¬£¬²¢Ö´ÐÐѹËõ°üÄÚ°üÀ¨µÄTransparentTribe×éÖ¯µÄ×ÔÓÐÔ¶¿ØÈí¼þCrimsonRAT¡£¡£¡£¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇTransparentTribe×é֯ΪÁ˽µµÍ¹¥»÷Ñù±¾µÄ²éɱÂÊ£¬£¬£¬£¬£¬£¬£¬¶ÔÏà¹Ø¹¥»÷Ñù±¾¾ÙÐÐÁ˼ӿǴ¦Öóͷ£¡£¡£¡£¡£¡£¡£¡£¡£
02
APT29¹¥»÷Ô˶¯ÖÐʹÓõÄÐÂÓ±Õ½ÂÔºÍÊÖÒÕ·Ö
Åû¶ʱ¼ä£º2022Äê1ÔÂ27ÈÕ
Ç鱨ȪԴ£ºhttps://www.crowdstrike.com/blog/observations-from-the-stellarparticle-campaign/
Ïà¹ØÐÅÏ¢£º
¹©Ó¦Á´ÈëÇÖÊÇÓ°ÏìһϵÁв¿·ÖµÄÈÕÒæÑÏÖØµÄÍþв£¬£¬£¬£¬£¬£¬£¬Íþв¼ÓÈëÕßʹÓûá¼ûȨÏÞÀ´Ö§³Ö¶àÖÖÄîÍ·£¬£¬£¬£¬£¬£¬£¬°üÀ¨¾¼ÃÀûÒæ£¨ÀýÈçKaseyaÀÕË÷Èí¼þ¹¥»÷£©ºÍÌØ¹¤Ô˶¯¡£¡£¡£¡£¡£¡£¡£¡£Õû¸ö2020Ä꣬£¬£¬£¬£¬£¬£¬ÃÀ¹úÕþ¸®¶Ô¶íÂÞ˹Áª°îÍâ¹úÇ鱨¾Ö(SVR)¾ÙÐÐÁËÒ»ÏîÐж¯£¬£¬£¬£¬£¬£¬£¬ÒÔ»ñÈ¡SolarWindsITÖÎÀíÈí¼þµÄ¸üлúÖÆ£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃËüÀ´À©´óÆäÇé±¨ÍøÂçÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÔ˶¯±»CrowdStrikeÑо¿Ö°Ô±¸ú×ÙΪStellarParticleÔ˶¯£¬£¬£¬£¬£¬£¬£¬²¢ÓëAPT29COZYBEAR×éÖ¯Ïà¹ØÁª¡£¡£¡£¡£¡£¡£¡£¡£
Ñо¿Ö°Ô±¹ØÓÚStellarParticleÔ˶¯Ê¹ÓõÄÐÂÓ±Õ½ÂÔºÍÊÖÒÕ¾ÙÐÐÁËÆÊÎö¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÊÖÒÕ°üÀ¨£º
1.ÓÃÓÚÑÚÊκáÏòÒÆ¶¯µÄÆ¾Ö¤ÌøÔ¾
2.Office365(O365)ЧÀÍÖ÷ÌåºÍÓ¦ÓóÌÐòÐ®ÖÆ¡¢Ä£ÄâºÍʹÓÃ
3.ÇÔÈ¡ä¯ÀÀÆ÷cookieÒÔÈÆ¹ý¶àÒòËØÉí·ÝÑéÖ¤
4.ʹÓÃTrailBlazerÖ²Èë³ÌÐòºÍGoldMax¶ñÒâÈí¼þµÄLinux±äÖÖ
5.ʹÓÃGet-ADReplAccountÇÔȡƾ֤
ÏÂÍ¼ÎªÆ¾Ö¤ÌøÔ¾ÊÖÒÕʾÀý£º

03
MuddyWaterͨ¹ý¶ñÒâPDF¡¢¿ÉÖ´ÐÐÎļþÕë¶ÔÍÁ¶úÆäÓû§
Åû¶ʱ¼ä£º2022Äê1ÔÂ31ÈÕ
Ç鱨ȪԴ£ºhttps://blog.talosintelligence.com/2022/01/iranian-apt-muddywater-targets-turkey.html
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬CiscoTalosÑо¿Ö°Ô±ÊӲ쵽һÏîÕë¶ÔÍÁ¶úÆä˽ÈË×éÖ¯ºÍÕþ¸®»ú¹¹µÄÐÂÔ˶¯£¬£¬£¬£¬£¬£¬£¬²¢½«Æä¹éÒòÓÚMuddyWater——ÃÀ¹úÍøÂç˾Á×î½ü½«Æä¹éÓÚÒÁÀÊÇ鱨ÓëÇå¾²²¿(MOIS)µÄAPT×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡£
¸ÃÔ˶¯Ê¹ÓöñÒâPDF¡¢XLSÎļþºÍWindows¿ÉÖ´ÐÐÎļþ½«»ùÓÚPowerShellµÄ¶ñÒâÏÂÔØÆ÷°²ÅÅΪĿµÄÆóÒµµÄ³õʼפ×ãµã¡£¡£¡£¡£¡£¡£¡£¡£MuddyWaterʹÓûùÓھ籾µÄ×é¼þ£¨ÀýÈç»ùÓÚPowerShellµÄ»ìÏýÏÂÔØÆ÷£©Ò²ÊÇÃÀ¹úÍøÂç˾Á2021Äê1ÔµÄͨ¸æÖÐÐÎòµÄÒ»ÖÖÕ½ÂÔ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÚ±¾´Î¹¥»÷Ô˶¯ÖУ¬£¬£¬£¬£¬£¬£¬MuddyWater»¹Ê¹Óýð˿ȸÁîÅÆÀ´¸ú×ÙÄ¿µÄµÄÀÖ³ÉѬȾ£¬£¬£¬£¬£¬£¬£¬ÕâÊǸÃ×éÖ¯ÐÂʹÓõÄTTP¡£¡£¡£¡£¡£¡£¡£¡£ÕâÖÖÔÚ´ËÔ˶¯ÖÐʹÓýð˿ȸÁîÅÆµÄÌØ¶¨ÒªÁìÒ²¿ÉÄÜÊǹæ±Ü»ùÓÚɳºÐµÄ¼ì²âϵͳµÄÒ»ÖÖ²½·¥¡£¡£¡£¡£¡£¡£¡£¡£

04
LazarusÔÚ×îÐÂÔ˶¯ÖÐʹÓÃWindowsUpdate¿Í»§¶ËºÍGitHub
Åû¶ʱ¼ä£º2022Äê1ÔÂ27ÈÕ
Ç鱨ȪԴ£ºhttps://blog.malwarebytes.com/threat-intelligence/2022/01/north-koreas-lazarus-apt-leverages-windows-update-client-github-in-latest-campaign/
Ïà¹ØÐÅÏ¢£º
LazarusGroupÊÇ×Ô2009ÄêÒÔÀ´Ò»Ö±»îÔ¾µÄ×îÖØ´óµÄ³¯ÏÊAPTÖ®Ò»¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÒÑÍùÔø¶ÔÐí¶à¸ßµ÷µÄ¹¥»÷ÈÏÕæ£¬£¬£¬£¬£¬£¬£¬²¢»ñµÃÁËÈ«ÌìÏµĹØ×¢¡£¡£¡£¡£¡£¡£¡£¡£MalwarebytesÍþвÇ鱨ÍŶÓÕýÔÚÆð¾¢¼à¿ØÆäÔ˶¯£¬£¬£¬£¬£¬£¬£¬²¢Äܹ»ÔÚ2022Äê1ÔÂ18ÈÕ·¢Ã÷еÄÔ˶¯¡£¡£¡£¡£¡£¡£¡£¡£
ÔÚÕâ´ÎÔ˶¯ÖУ¬£¬£¬£¬£¬£¬£¬Lazarus¾ÙÐÐÁËÓã²æÊ½ÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÕâЩ¹¥»÷ʹÓÃÁËʹÓÃÆäÒÑÖªÊÂÇéʱ»úÖ÷ÌâµÄ¶ñÒâÎĵµ×÷ΪÎäÆ÷£¬£¬£¬£¬£¬£¬£¬°üÀ¨Á½·Ýαװ³ÉÃÀ¹úÈ«ÇòÇå¾²ºÍº½¿Õº½Ìì¾ÞÍ·Âå¿ËÏ£µÂÂí¶¡¹«Ë¾µÄÓÕ¶üÎļþ¡£¡£¡£¡£¡£¡£¡£¡£
Ñо¿Ö°Ô±·ÖÏíÁ˶ÔÕâÒ»×îй¥»÷µÄÊÖÒÕÆÊÎö£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÇÉÃîµØÊ¹ÓÃWindowsUpdateÀ´Ö´ÐжñÒâ¸ºÔØ£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°½«GitHub×÷ΪÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£¡£ÎÒÃDZ¨¸æÁ˶ñÒâGitHubÕÊ»§µÄÓк¦ÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£¡£

¹¥»÷Ðж¯»òÊÂÎñÇ鱨
01
¹ØÓÚDridexÒøÐÐľÂíµÄ´¹ÂÚÔ˶¯µÄÆÊÎö
Åû¶ʱ¼ä£º2022Äê1ÔÂ28ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/fXggBsgYzWJVXV_2eSr_tg
Ïà¹ØÐÅÏ¢£º
´Ë´Î´¹ÂÚÔ˶¯£¬£¬£¬£¬£¬£¬£¬TA575×é֯ʹÓþßÓÐExcel4.0ºêµÄÎĵµ×÷Ϊ¸½¼þ£¬£¬£¬£¬£¬£¬£¬ÊͷŲ¢ÔËÐÐHTAÎļþ£¬£¬£¬£¬£¬£¬£¬¶ÔÆä´æ·ÅÓÚDiscord¡¢DropboxºÍOneDriveµÈÉç½»ºÍÎļþÔÆ´æ´¢Æ½Ì¨ÖеĶñÒâÑù±¾ÊµÏÖÏÂÔØ¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚHTAÎļþ´úÂëÖб£´æÒ»¸öÓò¿ØÇéÐεÄÅжϣ¬£¬£¬£¬£¬£¬£¬Òò´Ë±¾´Î´¹ÂÚÔ˶¯Ö»Õë¶Ô´¦ÓÚÓò¿ØÇéÐÎϵÄÖÕ¶Ëϵͳ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÕû¸ö¹¥»÷Àú³ÌÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁË»ìÏý¡¢ºê´úÂëÒþ²Ø¡¢¼ÓÃܺÍÒì³£´¦Öóͷ£µÈÐÎʽÀ´¶Ô¿¹ÆÊÎöºÍ¼ì²â¡£¡£¡£¡£¡£¡£¡£¡£ÆÊÎö·¢Ã÷£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÖÁÄ¿µÄÇéÐÎÖеĶñÒâÑù±¾ÊµÖÊÊÇDridexÒøÐÐľÂíµÄ×°ÔØÆ÷£¬£¬£¬£¬£¬£¬£¬¹¦Ð§Îª»ñȡĿµÄϵͳ»ù±¾ÐÅÏ¢¡¢ÅþÁ¬C2²¢»Ø´«¡¢»ñÈ¡P2P½ÚµãÁÐ±í¡¢¼ÓÈë¹¹½¨½©Ê¬ÍøÂç¡¢»ñÈ¡ºóÐøÄ£¿£¿£¿£¿£¿£¿£¿£¿éºÍʵÏÖÇÔÃÜ»òÀÕË÷µÈ¡£¡£¡£¡£¡£¡£¡£¡£ÓÉ´Ë¿ÉÒÔ¿´³ö£¬£¬£¬£¬£¬£¬£¬Ò»µ©Óû§±»Ö²Èë¸ÃÒøÐÐľÂí£¬£¬£¬£¬£¬£¬£¬½«ÃæÁÙÃô¸ÐÐÅÏ¢ÍâйºÍÀÕË÷µ¼ÖÂϵͳ¹ÊÕϵÄÇå¾²Íþв¡£¡£¡£¡£¡£¡£¡£¡£
02
¹¥»÷ÕßʹÓÃ×°±¸×¢²á¼¼ÇÉͨ¹ýºáÏòÍøÂç´¹ÂÚ¹¥»÷ÆóÒµ
Åû¶ʱ¼ä£º2022Äê1ÔÂ26ÈÕ
Ç鱨ȪԴ£ºhttps://www.microsoft.com/security/blog/2022/01/26/evolved-phishing-device-registration-trick-adds-to-phishers-toolbox-for-victims-without-mfa/
Ïà¹ØÐÅÏ¢£º
Ñо¿Ö°Ô±×î½ü·¢Ã÷ÁËÒ»¸ö´ó¹æÄ£¡¢¶à½×¶ÎµÄÔ˶¯£¬£¬£¬£¬£¬£¬£¬¸ÃÔ˶¯Í¨¹ý½«¹¥»÷Õß²Ù×÷µÄ×°±¸¼ÓÈë×éÖ¯µÄÍøÂçÒÔ½øÒ»²½Èö²¥Ô˶¯£¬£¬£¬£¬£¬£¬£¬Îª¹Å°åµÄÍøÂç´¹ÂÚÕ½ÂÔÔöÌíÁËÒ»ÖÖÐÂÊÖÒÕ¡£¡£¡£¡£¡£¡£¡£¡£
µÚÒ»¸öÔ˶¯½×¶ÎÉæ¼°ÇÔÈ¡Ö÷ҪλÓÚ°Ä´óÀûÑÇ¡¢ÐÂ¼ÓÆÂ¡¢Ó¡¶ÈÄáÎ÷ÑǺÍÌ©¹úµÄÄ¿µÄ×éÖ¯µÄƾ֤¡£¡£¡£¡£¡£¡£¡£¡£È»ºóÔÚµÚ¶þ½×¶ÎʹÓñ»µÁƾ֤£¬£¬£¬£¬£¬£¬£¬ÆäÖй¥»÷ÕßʹÓÃÊÜѬȾµÄÕÊ»§Í¨¹ýºáÏòÍøÂç´¹ÂÚÒÔ¼°Í¨¹ý³öÕ¾À¬»øÓʼþÔÚÍøÂçÖ®ÍâÀ©Õ¹ÆäÔÚ×éÖ¯ÄÚµÄפ×ãµã¡£¡£¡£¡£¡£¡£¡£¡£
±»¹¥»÷Õß¿ØÖƵÄ×°±¸ÅþÁ¬µ½ÍøÂ罫ÔÊÐí¹¥»÷ÕßÉñÃØÈö²¥¹¥»÷²¢ÔÚÕû¸öÄ¿µÄÍøÂçÖкáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£¡£¡£ËäÈ»ÔÚÕâÖÖÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬×°±¸×¢²á±»ÓÃÓÚ½øÒ»²½µÄÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ«Ëæ×ÅÆäËûÓÃÀýµÄ·ºÆð£¬£¬£¬£¬£¬£¬£¬×°±¸×¢²áµÄʹÓÃÕýÔÚÔöÌí¡£¡£¡£¡£¡£¡£¡£¡£

03
¹¥»÷ÕßÕýÔÚʹÓÃÁ÷Ã¥OAuthÓ¦ÓóÌÐò½ÓÊÜCEOÕÊ»§
Åû¶ʱ¼ä£º2022Äê01ÔÂ27ÈÕ
Ç鱨ȪԴ£ºhttps://www.proofpoint.com/us/blog/cloud-security/oivavoii-active-malicious-hybrid-cloud-threats-campaign
Ïà¹ØÐÅÏ¢£º
ÍþвÆÊÎöʦÊӲ쵽һ¸öÃûΪ“OiVaVoii”µÄÐÂÔ˶¯£¬£¬£¬£¬£¬£¬£¬Õë¶Ô¹«Ë¾¸ß¹ÜºÍ×Ü˾ÀíʹÓöñÒâOAuthÓ¦ÓóÌÐòºÍ´Ó±»Ð®ÖƵÄOffice365ÕÊ»§·¢Ë͵Ä×Ô½çËµÍøÂç´¹ÂÚÓÕ¶ü¡£¡£¡£¡£¡£¡£¡£¡£
OiVaVoiiÔ˶¯±³ºóµÄ¼ÓÈëÕßÖÁÉÙʹÓÃÁËÎå¸ö¶ñÒâOAuthÓ¦ÓóÌÐò£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÈý¸öÊÇÓÉÁ½¸ö²î±ðµÄ“¾ÓÉÑéÖ¤µÄÐû²¼Õß”½¨ÉèµÄ£¬£¬£¬£¬£¬£¬£¬ÕâÒâζןÃÓ¦ÓóÌÐòµÄËùÓÐÕߺܿÉÄÜÊÇÕýµ±Office×â»§Öб»µÁÓõÄÖÎÀíÔ±Óû§ÕÊ»§¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÆäÓàÁ½¸öÓ¦ÓóÌÐòÖУ¬£¬£¬£¬£¬£¬£¬ÖÁÉÙÒ»¸öÊÇÓÉδÂÄÀúÖ¤µÄ×éÖ¯½¨ÉèµÄ£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÒâζ×ÅʹÓ㨵ÚÈý¸ö£©±»Ð®ÖƵÄÔÆÇéÐλòʹÓÃרÃŵĶñÒâOffice×â»§¡£¡£¡£¡£¡£¡£¡£¡£
¹¥»÷ÕßʹÓÃÕâЩӦÓóÌÐòÏòÄ¿µÄ×éÖ¯µÄ¸ß¼¶ÖÎÀíÖ°Ô±·¢ËÍÊÚȨÇëÇ󡣡£¡£¡£¡£¡£¡£¡£ÔÚÐí¶àÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ÊÕ¼þÈ˽ÓÊÜÁËÇëÇ󣬣¬£¬£¬£¬£¬£¬Ã»Óз¢Ã÷ÈκοÉÒÉÖ®´¦¡£¡£¡£¡£¡£¡£¡£¡£µ±Êܺ¦Õßµã»÷½ÓÊܰ´Å¥Ê±£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁîÅÆ´ÓËûÃǵÄÕÊ»§Ïòͳһ×éÖ¯Ä򵀮äËûÔ±¹¤·¢Ë͵ç×ÓÓʼþ
¶ñÒâ´úÂëÇ鱨
01
Vultur¶ñÒâÈí¼þαװ³É2FAÓ¦ÓÃÇÔÈ¡Óû§ÒøÐÐÐÅÏ¢
Åû¶ʱ¼ä£º2022Äê01ÔÂ27ÈÕ
Ç鱨ȪԴ£ºhttps://blog.pradeo.com/vultur-malware-dropper-google-play
Ïà¹ØÐÅÏ¢£º
PradeoµÄÑо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÃûΪ2FAAuthenticatorµÄ¶ñÒâÒÆ¶¯Ó¦ÓóÌÐò£¬£¬£¬£¬£¬£¬£¬¸ÃÓ¦ÓóÌÐòÂþÑÜÔÚGooglePlayÉϲ¢ÓÐ10K+Óû§×°Öᣡ£¡£¡£¡£¡£¡£¡£ÍøÂç·¸·¨·Ö×ÓʹÓÃËüÔÚÓû§µÄÒÆ¶¯×°±¸ÉÏÉñÃØ×°ÖöñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬ÊÇÒ»¸öÓÃÓÚÔÚÆäÓû§×°±¸ÉÏÈö²¥¶ñÒâÈí¼þµÄdropper¡£¡£¡£¡£¡£¡£¡£¡£ÆÊÎöÏÔʾ£¬£¬£¬£¬£¬£¬£¬dropper»á×Ô¶¯×°ÖÃÒ»¸öÃûΪVulturµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÕë¶Ô½ðÈÚЧÀÍÇÔÈ¡Óû§µÄÒøÐÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£
02
AsyncRATľÂíʹÓÃз½·¨¾ÙÐÐÈö²¥
Åû¶ʱ¼ä£º2022Äê01ÔÂ25ÈÕ
Ç鱨ȪԴ£ºhttps://blog.morphisec.com/asyncrat-new-delivery-technique-new-threat-campaign
Ïà¹ØÐÅÏ¢£º
½üÆÚ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁË·¢Ã÷ÁËÒ»ÖÖеġ¢ÖØ´óµÄÔ˶¯½»¸¶·½·¨£¬£¬£¬£¬£¬£¬£¬ËüÒÑÀֳɵرܿªÁËÐí¶àÇå¾²¹©Ó¦É̵ÄÀ×´ï¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý´øÓÐhtml¸½¼þµÄ¼òÆÓµç×ÓÓʼþÍøÂç´¹ÂÚÕ½ÂÔ£¬£¬£¬£¬£¬£¬£¬ÌṩAsyncRAT£¨Ò»ÖÖÔ¶³Ì»á¼ûľÂí£©£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚͨ¹ýÇå¾²¡¢¼ÓÃܵÄÅþÁ¬Ô¶³Ì¼à¿ØºÍ¿ØÖÆÊÜѬȾµÄÅÌËã»ú¡£¡£¡£¡£¡£¡£¡£¡£
¹¥»÷´Ó°üÀ¨Î±×°³É¶©µ¥È·ÈÏÊÕÌõ£¨ÀýÈ磬£¬£¬£¬£¬£¬£¬Receipt-.html£©µÄHTML¸½¼þµÄµç×ÓÓʼþÐÂÎÅ×îÏÈ¡£¡£¡£¡£¡£¡£¡£¡£·¿ªÓÕ¶üÎļþ»á½«ÐÂÎÅÎüÊÕÕßÖØ¶¨Ïòµ½ÌáÐÑÓû§ÉúÑÄISOÎļþµÄÍøÒ³¡£¡£¡£¡£¡£¡£¡£¡£
×îеÄRATÔ˶¯ÇÉÃîµØÊ¹ÓÃJavaScript´ÓBase64±àÂëµÄ×Ö·û´®ÍâµØ½¨ÉèISOÎļþ²¢Ä£ÄâÏÂÔØÀú³Ì¡£¡£¡£¡£¡£¡£¡£¡£µ±Êܺ¦Õß·¿ªISOÎļþʱ£¬£¬£¬£¬£¬£¬£¬Ëü»á×Ô¶¯¹ÒÔØÎªWindowsÖ÷»úÉϵÄDVDÇý¶¯Æ÷£¬£¬£¬£¬£¬£¬£¬²¢°üÀ¨Ò»¸ö.BAT»òÒ»¸ö.VBSÎļþ£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþ»á¼ÌÐøÑ¬È¾Á´ÒÔͨ¹ýÖ´ÐÐPowerShellÏÂÁî¼ìË÷ÏÂÒ»½×¶ÎµÄ×é¼þ¡£¡£¡£¡£¡£¡£¡£¡£
Õâµ¼ÖÂÔÚÄÚ´æÖÐÖ´ÐÐ.NETÄ£¿£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬¸ÃÄ£¿£¿£¿£¿£¿£¿£¿£¿éËæºó³äµ±Èý¸öÎļþµÄÊÍ·ÅÆ÷£¨Ò»¸ö³äµ±ÏÂÒ»¸öÎļþµÄ´¥·¢Æ÷£©£¬£¬£¬£¬£¬£¬£¬×îÖÕ½»¸¶AsyncRAT×÷Ϊ×îÖÕÓÐÓøºÔØ£¬£¬£¬£¬£¬£¬£¬Í¬Ê±»¹¼ì²é·À²¡¶¾Èí¼þ²¢ÉèÖÃWindowsDefenderɨ³ýÏî¡£¡£¡£¡£¡£¡£¡£¡£

03
ChaesBankingľÂíͨ¹ý¶ñÒâÀ©Õ¹Ð®ÖÆChromeä¯ÀÀÆ÷
Åû¶ʱ¼ä£º2022Äê01ÔÂ27ÈÕ
Ç鱨ȪԴ£ºhttps://decoded.avast.io/anhho/chasing-chaes-kill-chain/
Ïà¹ØÐÅÏ¢£º
Ò»³¡³öÓÚ¾¼ÃÄîÍ·µÄ¶ñÒâÈí¼þÔ˶¯ÒѾÈëÇÖÁË800¶à¸öWordPressÍøÕ¾£¬£¬£¬£¬£¬£¬£¬ÒÔÌṩһ¸öÃûΪChaesµÄÒøÐÐľÂí£¬£¬£¬£¬£¬£¬£¬Õë¶ÔBancodoBrasil¡¢LojaIntegrada¡¢MercadoBitcoin¡¢MercadoLivreºÍMercadoPagoµÄ°ÍÎ÷¿Í»§¡£¡£¡£¡£¡£¡£¡£¡£
ChaesµÄÌØµãÊǶà½×¶Î½»¸¶£¬£¬£¬£¬£¬£¬£¬ËüʹÓÃJScript¡¢PythonºÍNodeJSµÈ¾ç±¾¿ò¼Ü¡¢ÓÃDelphi±àдµÄ¶þ½øÖÆÎļþÒÔ¼°¶ñÒâµÄGoogleChromeÀ©Õ¹£¬£¬£¬£¬£¬£¬£¬Æä×îÖÕÄ¿µÄÊÇÇÔÈ¡´æ´¢ÔÚChromeÖÐµÄÆ¾Ö¤²¢×èµ²°ÍÎ÷Ê¢ÐÐÒøÐÐÍøÕ¾µÄµÇ¼¡£¡£¡£¡£¡£¡£¡£¡£
µ±Óû§»á¼ûÆäÖÐÒ»¸öÊÜѬȾµÄÍøÕ¾Ê±»á´¥·¢¹¥»÷ÐòÁУ¬£¬£¬£¬£¬£¬£¬È»ºó»áÏÔʾһ¸öµ¯³ö´°¿Ú£¬£¬£¬£¬£¬£¬£¬±Þ²ßËûÃÇ×°ÖÃÐéαµÄJavaRuntimeÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÓû§Æ¾Ìý˵Ã÷¾ÙÐвÙ×÷£¬£¬£¬£¬£¬£¬£¬¶ñÒâ×°ÖóÌÐò½«Æô¶¯ÖØ´óµÄ¶ñÒâÈí¼þ½»¸¶Àý³Ì£¬£¬£¬£¬£¬£¬£¬×îÖÕ°²ÅŶà¸öÄ£¿£¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£¡£¡£¡£

Îó²îÏà¹Ø
01
PolkitÎó²îʹ·ÇÌØÈ¨LinuxÓû§Äܹ»»ñµÃrootȨÏÞ
Åû¶ʱ¼ä£º2022Äê01ÔÂ25ÈÕ
Ç鱨ȪԴ£ºhttps://thehackernews.com/2022/01/12-year-old-polkit-flaw-lets.html
Ïà¹ØÐÅÏ¢£º
Polkit£¨ÒÔǰ³ÆÎªPolicyKit£©ÊÇÒ»¸öÓÃÓÚÔÚÀàUnix²Ù×÷ϵͳÖпØÖÆÏµÍ³¹æÄ£È¨Ï޵Ť¾ß°ü£¬£¬£¬£¬£¬£¬£¬²¢Îª·ÇÌØÈ¨Àú³ÌÓëÌØÈ¨Àú³ÌͨѶÌṩÁËÒ»ÖÖ»úÖÆ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ¸ÃϵͳÊÊÓóÌÐòÖÐÅû¶ÁËÒ»¸ö±£´æ12ÄêÖ®¾ÃµÄÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬´ËÎó²îÔÊÐíÈκηÇÌØÈ¨Óû§Í¨¹ýÔÚÒ×Êܹ¥»÷Ö÷»úµÄĬÈÏÉèÖÃÖÐʹÓôËÎó²îÀ´»ñµÃ¶ÔÒ×Êܹ¥»÷Ö÷»úµÄÍêÈ«rootȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£
¸ÃÎó²î±»ÍøÂçÇå¾²¹«Ë¾Qualys³ÆÎª“PwnKit”£¬£¬£¬£¬£¬£¬£¬ËüÓ°ÏìÁËpolkitÖÐÒ»¸öÃûΪpkexecµÄ×é¼þ£¬£¬£¬£¬£¬£¬£¬¸Ã³ÌÐòĬÈÏ×°ÖÃÔÚÿ¸öÖ÷ÒªµÄLinux¿¯ÐаæÉÏ£¬£¬£¬£¬£¬£¬£¬ÈçUbunti¡¢Debian¡¢FedoraºÍCentOS¡£¡£¡£¡£¡£¡£¡£¡£
02
Æ»¹ûÐû²¼iOSºÍmacOS¸üÐÂÐÞ¸´ÁËÁ½¸öÁãÈÕÎó²î
Åû¶ʱ¼ä£º2022Äê01ÔÂ26ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/faMOI5C3H1Eu_61LYBJLBg
Ïà¹ØÐÅÏ¢£º
Apple½â¾öµÄÁãÈÕÎó²îÖ®Ò»£¨±àºÅΪCVE-2022-22587£©ÊÇÄÚ´æËð»µÎÊÌ⣬£¬£¬£¬£¬£¬£¬Î»ÓÚIOMobileFrameBufferÖв¢Ó°ÏìiOS¡¢iPadOSºÍmacOSMonterey¡£¡£¡£¡£¡£¡£¡£¡£
ʹÓôËÎó²î»áµ¼ÖÂÔÚÊÜѬȾװ±¸ÉÏÒÔÄÚºËȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Í¨¹ýË¢ÐÂÊäÈëÑéÖ¤À´½â¾ö¸ÃȱÏÝ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìiPhone6s¼°¸üлúÐÍ¡¢iPadPro£¨ËùÓÐÐͺţ©¡¢iPadAir2¼°¸üлúÐÍ¡¢iPadµÚ5´ú¼°¸üлúÐÍ¡¢iPadmini4¼°¸üлúÐÍÒÔ¼°iPodtouch£¨µÚ7´ú£©¡£¡£¡£¡£¡£¡£¡£¡£
µÚ¶þ¸öÁãÈÕÎó²î£¬£¬£¬£¬£¬£¬£¬±àºÅΪCVE-2022-22594£¬£¬£¬£¬£¬£¬£¬ÊÇÒ»¸öÓ°ÏìiOSºÍiPadOSµÄSafariWebKitÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÕâ¸öȱÏÝ£¬£¬£¬£¬£¬£¬£¬ÍøÕ¾¿ÉÒÔʵʱ¸ú×ÙÓû§µÄä¯ÀÀÔ˶¯ºÍÉí·Ý¡£¡£¡£¡£¡£¡£¡£¡£
´ËÎó²îÓ°ÏìiPhone6s¼°¸üлúÐÍ¡¢iPadPro£¨ËùÓÐÐͺţ©¡¢iPadAir2¼°¸üлúÐÍ¡¢iPadµÚ5´ú¼°¸üлúÐÍ¡¢iPadmini4¼°¸üлúÐÍÒÔ¼°iPodtouch£¨µÚ7´ú£©¡£¡£¡£¡£¡£¡£¡£¡£
ʱ¼ä£º2026-04-22
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-18
Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ
ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ