Mandiant·¢ÏÖUNC2891ÀûÓÃеÄCAKETAP¹¥»÷ATMÍøÂç

Ðû²¼Ê±¼ä 2022-03-22

Mandiant·¢ÏÖUNC2891ÀûÓÃеÄCAKETAP¹¥»÷ATMÍøÂç


3ÔÂ16ÈÕ£¬MandiantÐû²¼Á˹ØÓÚUNC2891ÍŻ﹥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£Ôڴ˴λÖУ¬¹¥»÷ÕßʹÓÃÁËÃûΪCAKETAPµÄÐÂUnix rootkit£¬Ö÷ÒªÕë¶ÔÔËÐÐOracle Solaris²Ù×÷ϵͳµÄ·þÎñÆ÷¡£Caketap¿ÉÒÔÒþ²ØÍøÂçÁ¬½Ó¡¢½ø³ÌºÍÎļþ£¬Æä×îÖÕÄ¿±êÊÇ´ÓÄ¿±êATMÖнػñÒøÐп¨ºÍPINÑéÖ¤Êý¾Ý£¬È»ºóʹÓÃÕâЩµÁÊý¾Ý½øÐÐÆÛÕ©½»Òס£´ËÍ⣬¹¥»÷»î¶¯»¹Ê¹ÓÃÁË2¸öÃûΪSLAPSTICKºÍTINYSHELLµÄºóÃÅ£¬ËüÃǶ¼ÓëUNC1945ÓйØ¡£


https://www.mandiant.com/resources/unc2891-overview


ʯÓ͹ܵÀ¹«Ë¾TransneftÑз¢²¿ÃÅOmega 79GBÊý¾Ýй¶


¾ÝýÌå3ÔÂ19ÈÕ±¨µÀ£¬AnonymousÉù³ÆÒÑÈëÇÖÁËTransneftµÄÄÚ²¿Ñз¢²¿ÃÅOmega¡£TransneftÊÇÊÀ½çÉÏ×î´óµÄʯÓ͹ܵÀ¹«Ë¾£¬×ܲ¿Î»ÓÚĪ˹¿Æ¡£3ÔÂ17ÈÕ£¬DDoSecrets³ÆÆäÊÕµ½ÁËOmega¸ß´ï79GBµÄµç×ÓÓʼþ¡£´Ë´Îй¶µÄÊý¾Ý²»½ö°üÂÞµç×ÓÓʼþÐÅÏ¢£¬»¹°üÂÞ·¢Æ±ºÍ²úÎïÔËÊäÏêϸÐÅÏ¢£¬ÒÔ¼°ÏÔʾ·þÎñÆ÷»ú¼ÜºÍÆäËüÉ豸ÅäÖõÄͼÏñÎļþ¡£²»¾Ãǰ£¬Anonymous»¹ÈëÇÖÁ˶íÂÞ˹µÄýÌåÉó²é»ú¹¹Roskomnadzor¡£


https://www.hackread.com/anonymous-leak-79gb-russia-oil-pipeline-email-data/


N4ughtysecTUÉù³ÆÒÑÇÔÈ¡TransUnion·ÇÖÞ·Ö²¿4TBµÄÊý¾Ý


 Ã½Ìå3ÔÂ18ÈÕ±¨µÀ£¬TransUnionÐû²¼ÉùÃ÷³ÆÎ»ÓÚÄϷǵķþÎñÆ÷Ôâµ½ÁËδ¾­ÊÚȨµÄ·ÃÎÊ¡£°ÍÎ÷ºÚ¿ÍÍÅ»ïN4ughtysecTUÉù³Æ¶ÔÕâ´Î¹¥»÷ÂôÁ¦£¬²¢ÒÑÔÚ¹¥»÷ÆÚ¼äÏÂÔØÁË4TBµÄÊý¾Ý¡£¹¥»÷ÕßÌåÏÖËûÃÇͨ¹ý±©Á¦¹¥»÷ÈëÇÖÁËÒ»¸öÄþ¾²ÐԽϲîµÄTransUnion SFTP·þÎñÆ÷£¬²¢ÇÔÈ¡ÁËԼĪ5400Íò¿Í»§µÄÊý¾Ý¡£¾ÝϤ£¬¹¥»÷Õß×îÖÕÆÆ½âµÄÃÜÂëÊÇ¡°Password¡±£¬ÕâÒѱ»ÁÐΪ2021ÄêµÚÎå´ó×î³£ÓõÄÃÜÂë¡£´Ë´Î¹¥»÷µÄÀÕË÷½ð¶îΪ15000000ÃÀÔª£¬µ«TransUnionÒÑÖ¸³öËü²»»áÏòºÚ¿Í¸¶¿î¡£


https://www.bleepingcomputer.com/news/security/hackers-claim-to-breach-transunion-south-africa-with-password-password/


FBIÐû²¼AvosLocker¹¥ÃÀ¹ú¶à¸öÒªº¦»ù´¡ÉèÊ©µÄͨ¸æ


3ÔÂ17ÈÕ£¬ÃÀ¹úFBIÐû²¼¹ØÓÚÀÕË÷ÍÅ»ïAvosLockerµÄÍøÂçÄþ¾²×Éѯ¡£FBI³Æ£¬AvosLockerÊÇÒ»¸ö»ùÓÚRaaSµÄÍŻÕë¶ÔÃÀ¹ú¶à¸öÒªº¦»ù´¡ÉèÊ©µÄ×éÖ¯£¬°üÂÞµ«²»ÏÞÓÚ½ðÈÚ·þÎñÐÐÒµ¡¢ÖÆÔìÐÐÒµºÍÕþ¸®²¿ÃŵÈ¡£¸Ãͨ¸æ¹ûÈ»ÁËÓйشËRaaSÍÅ»ïµÄ¼¼Êõϸ½Ú£¬»¹Îª×éÖ¯ÌṩÁË¿ÉÓÃÓÚ¼ì²âºÍ×èÖ¹´ËÀ๥»÷µÄÈëÇÖÖ¸±ê(IOC)¡£ID-RansomwareÊý¾ÝÏÔʾ£¬AvosLockerÔÚ2021Äê11ÔÂÖÁ2021Äê12ÔÂÆÚ¼äµÄ»î¶¯¼¤Ôö£¬ÇÒĿǰÈÔÔÚ¼ÌÐø¡£


https://www.bleepingcomputer.com/news/security/fbi-avoslocker-ransomware-targets-us-critical-infrastructure/


GoogleÐû²¼¹ØÓÚConti³õʼ·ÃÎÊÊðÀí¼ÆÄ±µÄ·ÖÎö³ÂËß


3ÔÂ17ÈÕ£¬GoogleÍþв·ÖÎöС×é(TAG)Ðû²¼Á˹ØÓÚConti³õʼ·ÃÎÊÊðÀí¼ÆÄ±µÄ·ÖÎö³ÂËß¡£TAG·¢ÏÖеÄEXOTIC LILYÓëContiºÍDiavolµÈÀÕË÷ÍÅ»ïÓйØ£¬ÆäÀûÓÃMicrosoft Windows MSHTMLƽ̨ÖЩ¶´CVE-2021-40444½øÐеöÓã¹¥»÷£¬ÔÚá¯ÁëÆÚÿÌìÏòÈ«Çò¶à´ï650¸öÄ¿±ê×éÖ¯·¢ËÍÁè¼Ý5000·âÓʼþ¡£ËäÈ»EXOTIC LILYµÄ»î¶¯ÓëContiµÄÒµÎñÖØµþ£¬µ«GoogleÈÏΪ£¬ËüÊÇÒ»¸öÍêȫרעÓÚ½¨Á¢³õÊ¼ÍøÂç·ÃÎʵĶÀÁ¢¹¥»÷ÍŻ


https://blog.google/threat-analysis-group/exposing-initial-access-broker-ties-conti/


Western DigitalÐÞ¸´ÆäEdgeRoverÖеÄĿ¼±éÀú©¶´


3ÔÂ18ÈÕ£¬Western DigitalÐû²¼Äþ¾²¸üУ¬ÐÞ¸´Æä×ÀÃæÓ¦Ó÷¨Ê½EdgeRoverÖеÄĿ¼±éÀú©¶´£¨CVE-2022-22998£©¡£EdgeRoverÊǼ¯ÖÐʽÄÚÈݹÜÀí½â¾ö·½°¸£¬½«¶à¸öÊý×Ö´æ´¢É豸ͳһÔÚÒ»¸ö¹ÜÀí½çÃæÏ¡£¸Ã©¶´CVSSÆÀ·ÖΪ9.1£¬¿É±»¹¥»÷ÕßÓÃÀ´½øÐе±µØÈ¨ÏÞÌáÉýºÍɳºÐÌÓÒÝ£¬¿ÉÄܻᵼÖÂÐÅϢй¶»ò¾Ü¾ø·þÎñ(DoS)¹¥»÷¡£Western DigitalµÄͨ¸æ²¢Î´ÌṩÓйظé¶´µÄÏêϸÐÅÏ¢£¬Òò´Ë»¹²»Çå³þÕâÊÇÒ»¸öÔÊÐíµ±µØÈ¨ÏÞÌáÉýµÄDLL½Ù³Ö©¶´£¬»¹ÊÇÒ»¸öÔÊÐí·ÃÎÊ·ÇÌØÈ¨Êý¾ÝλÖõÄ©¶´¡£


https://www.bleepingcomputer.com/news/security/western-digital-app-bug-gives-elevated-privileges-in-windows-macos/



Äþ¾²¹¤¾ß


EvilSelenium


ÊÇÒ»¸ö½« SeleniumÎäÆ÷»¯ÒÔÀÄÓà Chrome µÄÐÂÏîÄ¿¡£


https://github.com/mrd0x/EvilSelenium/


wholeaked


ÊÇÒ»¸öÎļþ¹²Ïí¹¤¾ß£¬¿ÉÈÃÄúÔÚ·¢Éúй©ʱÕÒµ½ÂôÁ¦ÈË¡£


https://github.com/utkusen/wholeaked


WSVuls


ÃüÁîÐй¤¾ß£¬×¨Îª¿ª·¢/²âÊÔÈËԱͨ¹ýµ¥¸öÃüÁî²âÊÔ©¶´ºÍ·ÖÎöÍøÕ¾¶øÉè¼Æ¡£


https://github.com/anouarbensaad/wsvuls


AWS CloudSaga


ÓÃÓÚÔÚ Amazon Web Services (AWS) »·¾³ÖвâÊÔÄþ¾²¿ØÖƺ;¯±¨¡£


https://github.com/awslabs/aws-cloudsaga#running-the-code



Äþ¾²·ÖÎö


Windows 11 Ϊ USB Çý¶¯Æ÷Ìí¼ÓÁË BitLocker Åųý¼ÆÄ±


https://www.bleepingcomputer.com/news/microsoft/windows-11-adds-a-bitlocker-exclusion-policy-for-usb-drives/


΢ÈíÌáÐÑ Internet Explorer ÔÚ 6 Ô¼´½«ÌÔÌ­


https://www.bleepingcomputer.com/news/microsoft/microsoft-reminds-of-internet-explorers-looming-demise-in-june/


NIST ÎªÖÆÔìÉÌÐû²¼ ICS ÍøÂçÄþ¾²Ö¸ÄÏ


https://www.securityweek.com/nist-releases-ics-cybersecurity-guidance-manufacturers


еöÓ㹤¾ß°ü¿ÉÓÃÀ´´´½¨Ðé¼ÙµÄ Chrome ä¯ÀÀÆ÷´°¿Ú


https://www.bleepingcomputer.com/news/security/new-phishing-toolkit-lets-anyone-create-fake-chrome-browser-windows/


CISA¡¢FBI ¾¯¸æ¶Ô SATCOM ÍøÂ繩ӦÉ̵Ĺ¥»÷


https://www.hackread.com/targeting-satellite-cisa-fbi-warns-satcom-providers/


¶à¼ÒÆû³µÖÆÔìÉÌѬȾ Emotet


https://www.darkreading.com/attacks-breaches/multiple-automakers-infected-with-emotet