ÀÕË÷Èí¼þ¿ª·¢Õß¹ûÈ»Egregor¡¢MazeºÍSekhmetµÄÖ÷ÃÜÔ¿

Ðû²¼Ê±¼ä 2022-02-14

ÀÕË÷Èí¼þ¿ª·¢Õß¹ûÈ»Egregor¡¢MazeºÍSekhmetµÄÖ÷ÃÜÔ¿


¾ÝýÌå2ÔÂ8ÈÕ±¨µÀ£¬ÀÕË÷Èí¼þMaze¡¢EgregorºÍSekhmetµÄÖ÷½âÃÜÃÜÔ¿Òѱ»¹ûÈ» ¡£ÃûΪ¡°Topleak¡±µÄÓû§ÔÚBleepingComputerÂÛ̳ÉÏÐû²¼ÁËÒ»¸ö7zipÎļþµÄÏÂÔØÁ´½Ó£¬ÆäÖаüÂÞ Maze¡¢EgregorºÍSekhmet½âÃÜÃÜÔ¿£¬ÒÔ¼°ÀÕË÷ÍÅ»ïʹÓõĶñÒâÈí¼þ¡°M0yv¡±µÄÔ´´úÂë ¡£ËûÉù³Æ×Ô¼ºÊÇÕâ3¸ö¶ñÒâÈí¼þµÄ¿ª·¢Õߣ¬²¢ÌåÏÖÕâÊÇÒ»´ÎÓмƻ®µÄ¹ûÈ»£¬Óë½üÆÚµÄÖ´·¨Ðж¯ÎÞ¹Ø ¡£


https://www.bleepingcomputer.com/news/security/ransomware-dev-releases-egregor-maze-master-decryption-keys/


HP·¢ÏÖ¹¥»÷Õß½«RedLineαװ³ÉWindows 11µÄÉý¼¶·¨Ê½


HPÑо¿ÍŶÓÔÚ2ÔÂ8ÈÕÅû¶ÁË·Ö·¢RedLineµÄ»î¶¯µÄϸ½Ú ¡£1ÔÂ27ÈÕ£¬Ñо¿ÈËÔ±×¢Òâµ½¹¥»÷Õß×¢²áÁËÓòwindows-upgraded[.]com ¡£¸ÃÍøÕ¾Ä£·ÂÁËÕæÕýµÄWindows 11¹ÙÍø£¬Óû§µã»÷¡°Á¢¼´ÏÂÔØ¡±°´Å¥£¬¾Í»áÏÂÔØÍйÜÔÚDiscord CDNÉϾÞϸΪ1.5MBµÄZIPÎļþ¡°Windows11InstallationAssistant.zip¡± ¡£½âѹ²¢Ö´Ðк󣬻á´ÓÔ¶³ÌWeb·þÎñÆ÷ÏÂÔØÃûΪwin11.jpgµÄÎļþ£¬ÆäÖаüÂÞRedLineµÄpayload ¡£


https://threatresearch.ext.hp.com/redline-stealer-disguised-as-a-windows-11-upgrade/


ÒÁÀʺڿÍÔÚ¼äµý»î¶¯Out to SeaÖÐʹÓÃкóÃÅMarlin


¾Ý2ÔÂ9ÈÕ±¨µÀ£¬Äþ¾²¹«Ë¾ESET·¢ÏÖÁËÒÁÀʺڿÍÔÚ½üÆÚ¹¥»÷ÖÐʹÓÃеÄMarlinºóÃÅ ¡£ESETÌåÏÖ£¬´Ë´Î¼äµý»î¶¯Out to Sea×Ô2018Äê4Ô¾ÍÒÑ¿ªÊ¼£¬ÀûÓÃеÄMarlinÖ÷ÒªÕë¶ÔÒÔÉ«ÁС¢Í»Äá˹ºÍ°¢À­²®ÁªºÏÇõ³¤¹úµÄÍâ½»×éÖ¯¡¢¿Æ¼¼¹«Ë¾ºÍÒ½ÁÆ×éÖ¯µÈ ¡£´ËÍ⣬»¹½«´Ë´ÎµÄ¹¥»÷»î¶¯¹éÒòÓÚOilRig£¨ÓÖÃûAPT34£©£¬×îÖÕ»¹½«Æä»î¶¯ÓëÁíÒ»¸öÒÁÀÊ×éÖ¯LyceumÁªÏµÆðÀ´ ¡£


https://thehackernews.com/2022/02/iranian-hackers-using-new-marlin.html


Qualys·¢ÏÖLazarusð³äLockheed MartinµÄµöÓã»î¶¯


2ÔÂ8ÈÕ£¬QualysÅû¶Á˳¯ÏÊÍÅ»ïLazarus½üÆÚ¿ªÕ¹µÄµöÓã»î¶¯LolZarusµÄϸ½Ú ¡£´Ë´Î»î¶¯Ö÷ÒªÕë¶Ô¹ú·ÀÐÐÒµµÄÇóÖ°Õߣ¬¹¥»÷Õßð³äÁËLockheed Martin¹«Ë¾ÏòÄ¿±ê·¢Ë͵öÓãÎļþ£¬¼Ù×°Ìṩ¾ÍÒµ»ú»á ¡£ÕâÊÇÃÀ¹úµÄÒ»¼Ò¹ú·À¿Æ¼¼¹«Ë¾£¬ÔÚ2020ÄêµÄÏúÊÛ¶îΪ654ÒÚÃÀÔª ¡£´ËÍ⣬¸Ã»î¶¯»¹Ê¹ÓÃÁ˲îÒìµÄlolbin ¡£Õâ²»ÊÇLazarusµÚÒ»´ÎʹÓôËÀàÓÕ¶ü£¬ËüÔøÎ±×°³ÉNorthrop GrummanºÍBAE Systems¼Ù×°Ìṩ¾ÍÒµ»ú»á ¡£


https://www.zdnet.com/article/lazarus-hackers-target-defense-industry-with-fake-lockheed-martin-job-offers/


KasperskyÐû²¼2021ÄêÀ¬»øÓʼþºÍµöÓã»î¶¯µÄ³ÂËß


2ÔÂ9ÈÕ£¬KasperskyÐû²¼ÁË2021ÄêÀ¬»øÓʼþºÍµöÓã»î¶¯µÄ³ÂËß ¡£³ÂËßÖ¸³ö£¬ÔÚ2021Ä꣬56%µÄµç×ÓÓʼþÊÇÀ¬»øÓʼþ£»×î¶àµÄÀ¬»øÓʼþÀ´×Ô¶íÂÞ˹£¨24.77%£©£¬Æä´ÎÊǵ¹ú£¨14.12%£©£»Î÷°àÑÀÔâµ½µÄ¶ñÒâÓʼþ¹¥»÷×î¶à£¬Îª9.32%£¬Æä´ÎÊǶíÂÞ˹£¨6.33%£©£»Ôâµ½µöÓã¹¥»÷×î¶àµÄ¹ú¼ÒÊǰÍÎ÷£¨12.39%£©£¬Æä´ÎÊÇ·¨¹ú£¨12.21%£©£»¸½¼þÖÐ×î³£¼ûµÄ¶ñÒâÈí¼þ¼Ò×åÊÇAgenslaľÂí ¡£


https://securelist.com/spam-and-phishing-in-2021/105713/


AppleÐÞ¸´Òѱ»ÀûÓõÄÊͷźóʹÓé¶´CVE-2022-22620


AppleÔÚ2ÔÂ10ÈÕÐû²¼¸üУ¬ÐÞ¸´ÁËÒ»¸öWebKitµÄÊͷźóʹÓé¶´CVE-2022-22620 ¡£¸Ã©¶´¿ÉÄܻᵼÖ²Ù×÷ϵͳÍß½âºÍÔÚÄ¿±êÉ豸ÉÏÖ´ÐдúÂ룬¹¥»÷ÕßÒÑÔÚÒ°ÍâÀûÓÃËüÈëÇÖiPhone¡¢iPadºÍMac ¡£Appleͨ¹ý¸ïÐÂiOS 15.3.1¡¢iPadOS 15.3.1ºÍmacOS Monterey 12.2.1ÖеÄÄÚ´æ¹ÜÀíÐÞ¸´´Ë©¶´ ¡£ÕâÊÇAppleÔÚ½ñÄêÐÞ¸´µÄµÚÈý¸ö0 day£¬Ç°Á½¸öΪCVE-2022-22587ºÍCVE-2022-22594 ¡£


https://www.bleepingcomputer.com/news/security/apple-patches-new-zero-day-exploited-to-hack-iphones-ipads-macs/


Äþ¾²¹¤¾ß


Merry-Maker


ΪÁËÍ£Ö¹ÈÕÒæÔö¶àµÄÕë¶Ôµç×ÓÉ̵êµÄÍøÂçä¯ÀÀ¹¥»÷ʼþ£¬Target¿ªÔ´ÁËÒѾ­¹ý²âÊÔµÄɨÃ蹤¾ß ¡£


https://latesthackingnews.com/2022/02/09/merry-maker-card-skimmer-scanner-tool-released-as-open-source/


Second Order 


ͨ¹ýץȡӦÓ÷¨Ê½²¢ÊÕ¼¯ÇкÏÌØ¶¨¹æÔò»òÒÔÌØ¶¨·½Ê½ÏìÓ¦µÄ URL£¨ºÍÆäËûÊý¾Ý£©À´É¨Ãè Web Ó¦Ó÷¨Ê½ÒÔ½øÐжþ¼¶×ÓÓò½Ó¹Ü ¡£


https://github.com/mhmdiaa/second-order


whatfiles


Linux ʵÓ÷¨Ê½£¬Ëü¼Ç¼ÁíÒ»¸ö·¨Ê½ÔÚϵͳÉ϶ÁÈ¡/дÈë/´´½¨/ɾ³ýµÄÎļþ£¬»¹¸ú×ÙÄ¿±ê½ø³Ì´´½¨µÄÈκÎнø³ÌºÍÏß³Ì ¡£


https://github.com/spieglt/whatfiles


logdata anomaly miner


¸Ã¹¤¾ß½âÎöÈÕÖ¾Êý¾Ý²¢ÔÊÐíΪÒì³£¼ì²â½ç˵·ÖÎö¹ÜµÀ£¬Ö¼ÔÚÒÔÓÐÏÞµÄ×ÊÔ´ºÍ¾¡¿ÉÄܵ͵ÄȨÏÞÔËÐзÖÎö ¡£


https://github.com/ait-aecid/logdata-anomaly-miner


extrude


·ÖÎö¶þ½øÖÆÎļþÊÇ·ñȱÉÙÄþ¾²¹¦Ð§¡¢ÐÅϢй¶µÈ ¡£


https://github.com/liamg/extrude/


Äþ¾²·ÖÎö


FederalÐû²¼Éí·ÝÆÛÕ©µÖÓù¹¤¾ß°üÒÔ×ÊÖúÆóÒµ¹¥»÷ÆÛÕ©


https://www.helpnetsecurity.com/2022/02/10/federal-reserve-synthetic-identity-fraud-mitigation-toolkit/


PHP Everywhere RCE ©¶´Íþв×Å´óÁ¿µÄ WordPress ÍøÕ¾


https://thehackernews.com/2022/02/critical-rce-flaws-in-php-everywhere.html


Apple ÒâÍâ±£Áô²¿ÃÅ iPhone É쵀 Siri ¼Òô


https://blog.malwarebytes.com/opinion/2022/02/apple-accidentally-kept-some-siri-recordings-from-iphones-even-for-opted-out-users/


Meta ºÍ Chime ÆðËß2¸öÄáÈÕÀûÑÇÈËÀûÓà Facebook¡¢Instagram µöÓã


https://www.bleepingcomputer.com/news/security/meta-and-chime-sue-nigerians-behind-facebook-instagram-phishing/


FBI ¾¯¸æÉý¼¶µÄ SIM ¿¨½»»»¹¥»÷ÇÔÈ¡Êý°ÙÍòÃÀÔª


https://www.bleepingcomputer.com/news/security/fbi-warns-of-criminals-escalating-sim-swap-attacks-to-steal-millions/