APT36ÀûÓÃCrimsonRATбäÌå¹¥»÷Ó¡¶ÈµÄÏà¹Ø»ú¹¹

Ðû²¼Ê±¼ä 2022-04-01

APT36ÀûÓÃCrimsonRATбäÌå¹¥»÷Ó¡¶ÈµÄÏà¹Ø»ú¹¹


Cisco TalosÔÚ3ÔÂ29ÈÕ¹ûÈ»ÁËAPT36Õë¶ÔÓ¡¶ÈÕþ¸®ºÍ¾üÊ»ú¹¹µÄл¡£APT36ÓÖ³ÆTransparent Tribe£¬×Ô2016ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬ÒÉËÆÓë°Í»ù˹̹ÓйØ¡£´Ë´Î»î¶¯¿ªÊ¼ÓÚ2021Äê6Ô£¬ÀûÓÃαÔìµÄKavachÉí·ÝÈÏÖ¤Ó¦Ó÷ַ¢¶ñÒâÈí¼þ£¬Ó¡¶ÈÐèÒª·ÃÎÊÓʼþ·þÎñ»òÊý¾Ý¿âµÈIT×ÊÔ´µÄ¹Ù·½×éÖ¯µÄÔ±¹¤¹ã·ºÊ¹ÓøÃÓ¦ÓᣴËÍ⣬¹¥»÷ÕßÈÔÔÚʹÓÃCrimsonRAT£¬Æä2022°æ±¾ÐÂÔöÁ˶à¸ö¹¦Ð§£¬Èç¼üÅ̼Ǽ¡¢ÔÚÄ¿±êϵͳÉÏÖ´ÐÐÈÎÒâÃüÁîÒÔ¼°¶ÁÈ¡ºÍɾ³ýÎļþµÈ¡£


https://blog.talosintelligence.com/2022/03/transparent-tribe-new-campaign.html


LAPSUS$»Ø¹é²¢Ð¹Â¶Èí¼þ¹«Ë¾Globant 70GBµÄÊý¾Ý


¾ÝýÌå3ÔÂ30ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïLAPSUS$ÔÚΪÆÚÒ»ÖܵĶÌÔÝͣЪºóÐû²¼»Ø¹é¡£¸ÃÍÅ»ïÔÚÆäTelegramƵµÀÉÏдµÀ¡°ÎÒÃÇÕýʽ´Ó¼ÙÆÚ»ØÀ´ÁË¡±£¬²¢Ðû²¼ÁËÒ»¸öÎļþ¼ÐÁбíµÄ½ØÍ¼£¬ÁгöÁËArcserve¡¢Banco Galicia¡¢BNP Paribas Cardif¡¢Citibanamex¡¢DHL¡¢FacebookºÍStifelµÈ¹«Ë¾¡£Ëü»¹Ðû²¼ÁËÒ»¸ötorrentÎļþ£¬¾Ý³ÆÊÇGlobantÔ¼70GBµÄÊý¾Ý£¬°üÂÞÔ´´úÂëºÍ¸Ã¹«Ë¾AtlassianÌ×¼þÏà¹ØµÄ¹ÜÀíÔ±ÃÜÂë¡£


https://thehackernews.com/2022/03/lapsus-claims-to-have-breached-it-firm.html 


Morphisec·¢ÏÖÕë¶Ô¼ÓÄôó·Ö·¢Mars StealerµÄ»î¶¯


3ÔÂ29ÈÕ£¬Morphisec¹ûÈ»ÁËÕë¶ÔMars StealerµÄ×îÐÂÑо¿½á¹û¡£Mars»ùÓھɵÄOski Stealer£¬ÓÚ2021Äê6ÔÂÊ״η¢ÏÖ£¬ÔÚRaccoon StealerͻȻ¹Ø±Õºó£¬³ÉΪÆäÌæ´ú·½°¸¡£´Ë´ÎлαÔ쿪Դ°ì¹«Ì×¼þOpenOfficeµÄ¹Ù·½ÍøÕ¾£¬Ê¹ÓÃGoogle Ads¹ã¸æÓÕʹĿ±ê·ÃÎʸöñÒâÍøÕ¾²¢ÏÂÔØMars Stealer¡£ÓÉÓÚ±»µÁÐÅÏ¢µÄĿ¼ÒòÅäÖò»Í×¶ø±£³Ö¹ûÈ»µÄ״̬£¬Ñо¿ÈËÔ±·¢ÏÖ·¢ÏÖ¾ø´ó¶àÊýÄ¿±êÀ´×Ô¼ÓÄôó¡£


https://blog.morphisec.com/threat-research-mars-stealer


Wyze CamÉãÏñÍ·´æÔÚ¿ÉÓÃÀ´Ô¶³Ì·ÃÎÊSD¿¨ÄÚÈݵÄ©¶´


ýÌå3ÔÂ29ÈÕ±¨µÀ£¬Wyze CamÍøÂçÉãÏñÍ·ÖдæÔÚ©¶´¡£¸Ã©¶´Î´·ÖÅäCVE ID£¬ÔÊÐíÔ¶³ÌÓû§Í¨¹ýÕìÌý¶Ë¿Ú80·ÃÎÊÏà»úÖÐSD¿¨µÄÄÚÈÝ£¬ÇÒÎÞÐèÉí·ÝÑéÖ¤¡£SD¿¨Í¨³£ÓÃÀ´´æ´¢ÊÓÆµ¡¢Í¼ÏñºÍÒôƵ¼Ç¼¡£ÔÚWyze Cam IoTÉϲåÈëSD¿¨ºó£¬»áÔÚwwwĿ¼ÖÐ×Ô¶¯´´½¨Ö¸ÏòËüµÄ·ûºÅÁ´½Ó£¬¸ÃĿ¼ÓÉweb·þÎñÆ÷Ìṩ·þÎñÇÒûÓÐÈκηÃÎÊÏÞÖÆ¡£Â©¶´ÓÉBitdefenderÓÚ2019Äê3Ô·¢ÏÖ²¢Éϱ¨£¬Ö±µ½2022Äê1ÔÂ29ÈÕ²ÅÐÞ¸´¡£


https://www.bleepingcomputer.com/news/security/wyze-cam-flaw-lets-hackers-remotely-access-your-saved-videos/


ѹËõ·¨Ê½ZlibÐû²¼¸üУ¬ÐÞ¸´ÒÑ´æÔÚ17ÄêµÄÄþ¾²Â©¶´


¾Ý3ÔÂ29ÈÕ±¨µÀ£¬Ñ¹Ëõ·¨Ê½ZlibÐÞ¸´ÁËÒÑ´æÔÚ17ÄêµÄÄþ¾²Â©¶´¡£GoogleµÄÑо¿ÈËÔ±Tavis Ormandy·¢ÏÖZlibÖдæÔÚÒ»¸ö©¶´£¬ÔÚÉϱ¨Ê±·¢Ïָé¶´ÔçÔÚ2018Äê¾Í±»³ÂËß²¢ÐÞ¸´¹ý£¬Æäʱ³ÆÆäÒÑ´æÔÚ13ÄꡣȻ¶ø£¬²»ÖªÎªºÎ2018Äê4ÔÂ20ÈÕÌá½»µÄ²¹¶¡²¢Ã»ÓгÉΪZlibµÄ¸üС£Ö±µ½2022Äê03ÔÂ27ÈÕ£¬¸Ã¿âµÄÉÏÒ»¸ö°æ±¾²ÅÔÚ2017Äê01ÔÂ15ÈÕÐû²¼¡£¸Ã©¶´ÔÚ±¾Öܲű»·ÖÅä±àºÅCVE-2018-25032£¬µ±Ñ¹ËõijЩÊäÈëʱ»á·ºÆðÎÊÌ⣬²¢´æÔÚDZÔڵĻº³åÇøÒç³öÎÊÌâ¡£


https://nakedsecurity.sophos.com/2022/03/29/zlib-data-compressor-fixes-17-year-old-security-bug-patch-errr-now/


SymantecÐû²¼¹ØÓÚжñÒâÈí¼þVerbleconµÄ·ÖÎö³ÂËß


3ÔÂ29ÈÕ£¬SymantecÐû²¼Á˹ØÓÚжñÒâÈí¼þVerbleconµÄ·ÖÎö³ÂËß¡£Ñо¿ÈËÔ±ÓÚ½ñÄê1Ô·¢ÏÖÁËVerblecon£¬ËüÒѱ»ÓÃÓÚ°²×°¼ÓÃܿ󹤵ĻÖС£¸Ã¶ñÒâÈí¼þ»ùÓÚJava£¬ÓÉÓÚÆä´úÂëµÄ¶à̬ÐÔʹµÃÆäÑù±¾µÄ¼ì²âÂʺܵÍ¡£¸Ã¶ñÒâÈí¼þ»á¼ì²éËüÊÇ·ñÔÚÐéÄâ»·¾³ÖÐÔËÐУ¬È»ºó»ñÈ¡ÕýÔÚÔËÐеĽø³ÌÁбíÒÔ¼ì²éÊÇ·ñÓÐÓëÐéÄâ»úϵͳÏà¹ØµÄÎļþ£¬ËùÓмì²é¶¼Í¨¹ýºó»á½«×ÔÉí¸´ÖÆµ½µ±µØÄ¿Â¼£¨%ProgramData%¡¢%LOCALAPPDATA%¡¢Users£©£¬²¢¶¨ÆÚʵÑéÁ¬½ÓÓòÃûhxxps://gaymers[.]ax/ºÍhxxp://[DGA_NAME][.]tk/¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/verblecon-sophisticated-malware-cryptocurrency-mining-discord





Äþ¾²¹¤¾ß


Privid


¼à¿ØÊÓÆµ·ÖÎöϵͳ£¬Äܹ»ÒÔ±£»¤Òþ˽µÄ·½Ê½½øÐÐÊÓÆµ·ÖÎö£¬ÒÔÓ¦¶ÔÇÖÈëÐÔ¸ú×ٵĵ£ÓÇ¡£


https://thehackernews.com/2022/03/privid-privacy-preserving-surveillance.html


Live Forensicator


ÓÃÓÚ×ÊÖúʵʱȡ֤ºÍʼþÏìÓ¦µÄ POWERSHELL ½Å±¾¡£


https://github.com/Johnng007/Live-Forensicator#dependencies


nettrust


ÊÇÒ»¸ö¶¯Ì¬µÄ³öÕ¾·À»ðǽÊÚȨÆ÷¡£


https://github.com/ulfox/nettrust




Äþ¾²·ÖÎö


Google Chrome 100 Ðû²¼£¬°üÂÞй¦Ð§¡¢Í¼±êµÈ


https://www.bleepingcomputer.com/news/google/google-chrome-100-released-with-new-features-icon-and-more/


ÈçºÎ½« Wslink ¶ñÒâÈí¼þ¼ÓÔØ·¨Ê½ÓÃÓÚ»ìÏýµÄÐéÄâ»ú


https://thehackernews.com/2022/03/experts-detail-virtual-machine-used-by.html


Yandex ÕýÔÚÏò¶íÂÞ˹·¢ËÍ iOS Óû§Êý¾Ý


https://www.infosecurity-magazine.com/news/yandex-is-sending-ios-users-data/


´óÁ¿¿ó¹¤ºÍºóÃÅÀûÓà Log4J ¹¥»÷ VMware Horizon ·þÎñÆ÷


https://news.sophos.com/en-us/2022/03/29/horde-of-miner-bots-and-backdoors-leveraged-log4j-to-attack-vmware-horizon-servers/


Proofpoint·¢ÏÖÕë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£µöÓã»î¶¯


https://www.proofpoint.com/us/blog/threat-insight/school-hard-knocks-job-fraud-threats-target-university-students