LanceflyÀûÓúóÃÅMerdoor¹¥»÷ÄÏÑǺͶ«ÄÏÑǵÄ×éÖ¯

Ðû²¼Ê±¼ä 2023-05-17

1¡¢LanceflyÀûÓúóÃÅMerdoor¹¥»÷ÄÏÑǺͶ«ÄÏÑǵÄ×éÖ¯


SymantecÔÚ5ÔÂ15ÈÕÅû¶ÁËAPT×éÖ¯LanceflyÕë¶ÔÄÏÑǺͶ«ÄÏÑǵÄÕþ¸®¡¢º½¿ÕºÍµçÐÅ×éÖ¯µÄ¹¥»÷»î¶¯¡£×Ô2018ÄêÒÔÀ´ £¬LanceflyÒ»Ö±ÔÚÕë¶ÔÐԵĹ¥»÷»î¶¯Öзַ¢Òþ±ÎµÄ×Ô½ç˵ºóÃÅMerdoor £¬ÒÔÔÚÄ¿±êÍøÂçÉϽ¨Á¢³Ö¾ÃÐÔ¡¢Ö´ÐÐÃüÁîºÍ¼Ç¼¼üÅÌ¡£Ò»µ©½øÈëÄ¿±êϵͳ £¬¹¥»÷Õ߾ͻáͨ¹ýDLL²àÔØ½«MerdoorºóÃÅ×¢ÈëºÏ·¨½ø³Ìperfhost.exe»òsvchost.exe £¬Ö¼ÔÚÈÆ¹ý¼ì²â¡£´ËÍâ £¬¹¥»÷»î¶¯»¹Ê¹ÓÃÁ˸üа汾µÄZXShell rootkit¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/lancefly-merdoor-zxshell-custom-backdoor


2¡¢Check Point·¢ÏÖCamaro Dragon¹¥»÷Å·ÖÞÍâ½»×éÖ¯µÄ»î¶¯


5ÔÂ16ÈÕ £¬Check Point³ÆÆä·¢ÏÖÁËCamaro Dragonͨ¹ýѬȾסլTP-Link·ÓÉÆ÷ £¬À´¹¥»÷Å·ÖÞÍâ½»ÊÂÎñ×éÖ¯µÄ»î¶¯¡£ÉÐδȷ¶¨¹¥»÷ÕßÈçºÎʹÓöñÒâ¹Ì¼þ¾µÏñѬȾTP-Link·ÓÉÆ÷ £¬µ«¿ÉÄÜÊÇͨ¹ý©¶´ÀûÓûò±©Á¦ÆÆ½â¹ÜÀíԱƾ¾Ý¡£ÊӲ췢ÏÖÁËÁ½¸öľÂí»¯¹Ì¼þ¾µÏñÑù±¾ £¬ÓëºÏ·¨°æ±¾½øÐбÈÁ¦ £¬·¢ÏÖÄں˺ÍuBoot²¿ÃÅÊÇÏàͬµÄ¡£µ«ÊÇ £¬¶ñÒâ¹Ì¼þʹÓÃÁËÒ»¸ö×Ô½ç˵µÄSquashFSÎļþϵͳ £¬¸Ãϵͳ°üÂÞÌØ±ðµÄ¶ñÒâÎļþ×é¼þ £¬×÷ΪHorse ShellºóÃŵÄÒ»²¿ÃÅ¡£


https://research.checkpoint.com/2023/the-dragon-who-sold-his-camaro-analyzing-custom-router-implant/


3¡¢º½¿Õ¹«Ë¾airBaltic½«²¿ÃÅ´î¿ÍµÄÔ¤¶©ÐÅÏ¢·¢Ë͸øÆäËûÈË


¾ÝýÌå5ÔÂ15ÈÕ±¨µÀ £¬À­ÍÑάÑÇµÄÆì½¢º½¿Õ¹«Ë¾airBalticÒò¼¼Êõ´íÎó £¬½«²¿ÃÅ´î¿ÍµÄÔ¤¶©ÐÅÏ¢·¢Ë͸øÆäËû´î¿Í¡£5ÔÂ14ÈÕ £¬¶àÃûairBaltic´î¿Í³ÆÆäÊÕµ½ÁË·¢¸øÆäËûÈ˵ĵç×ÓÓʼþ¡£Ð¹Â¶ÐÅÏ¢°üÂÞÐÕÃû¡¢³öÉúÈÕÆÚºÍÓʼþµØÖ·µÈ¡£airBaltic͸¶¸Ãʼþ²¢·ÇÓÉÍøÂç¹¥»÷ÒýÆð £¬5ÔÂ12ÈÕ £¬ÔÚairBalticµÄÓʼþ·Ö·¢ÏµÍ³Öмì²âµ½ÄÚ²¿¼¼ÊõÎÊÌâ £¬Òò´ËÉÙÊý´î¿Í£¨Ô¼Õ¼0.009%µÄÔ¤¶©£©ÊÕµ½ÁË´íÎóµÄÓʼþ¡£


https://www.bleepingcomputer.com/news/security/airline-exposes-passenger-info-to-others-due-to-a-technical-error/


4¡¢CiscoÅû¶RA GroupÕë¶ÔÃÀ¹úºÍº«¹ú¹«Ë¾µÄ¹¥»÷»î¶¯


Cisco TalosÓÚ5ÔÂ15ÈÕÅû¶ÁËÐÂÀÕË÷ÍÅ»ïRA GroupµÄ¹¥»÷»î¶¯ £¬ÈëÇÖÁËÈý¸öÃÀ¹úµÄ×éÖ¯ºÍÒ»¸öº«¹úµÄ×éÖ¯¡£¸Ã»î¶¯ÖÁÉÙ´Ó4ÔÂ22ÈÕ¿ªÊ¼»îÔ¾ £¬Éæ¼°¶à¸ö´¹Ö±ÐÐÒµ £¬°üÂÞÖÆÒ©¡¢±£ÏÕ¡¢²Æ¸»¹ÜÀíºÍÖÆÔ칫˾¡£¹¥»÷ÕßʹÓÃÁËй¶µÄÀÕË÷Èí¼þBabukµÄÔ´´úÂë¡£RA GroupµÄ¼ÓÃÜ·¨Ê½½ÓÄɼäЪ¼ÓÃÜ £¬¼ÓÃÜÊý¾Ýʱ £¬»áʹÓÃcurve25519ºÍeSTREAM cipher hc-128Ëã·¨¡£Ñо¿ÈËԱ͸¶¸Ã»î¶¯Õý´¦ÓÚÔçÆÚ½×¶Î¡£


https://blog.talosintelligence.com/ra-group-ransomware/


5¡¢Academy MortgageÔâµ½BlackCatÍÅ»ïµÄÀÕË÷¹¥»÷


ýÌå5ÔÂ15ÈÕ±¨µÀ £¬Academy MortgageÔâµ½ÁËÀÕË÷ÍÅ»ïBlackCatµÄ¹¥»÷¡£ÔÚͬÒâÖ§¸¶3850ÍòÃÀÔªÒÔ½â¾öÁª°îÖ¸¿ØµÄ¼¸¸öÔºó £¬Academy MortgageÓÖÔâµ½ÁËÀÕË÷¹¥»÷¡£5ÔÂ14ÈÕ £¬ÀÕË÷ÍŻォAcademy MortgageÌí¼Óµ½ÆäÍøÕ¾ £¬³ÆÆä»ñµÃÁË»úÃÜÊý¾Ý²¢×¼±¸Ðû²¼ £¬°üÂÞ¿Í»§/ºÏ×÷»ï°éµÄÊý¾Ý¡¢¸öÈËÐÅÏ¢¡¢²ÆÕþºÍ»úÃÜÊý¾ÝµÈ¡£¹¥»÷Õß»¹Ìáµ½Á˸ù«Ë¾Ö®Ç°µÄÂé·³ £¬³Æ¿¼Âǵ½¹ó¹«Ë¾ÔÚ2022Äê12ÔÂÃæÁÙµÄÖ¸¿Ø £¬Êý¾Ýй¶¿ÉÄÜ»á¶Ô¹«Ë¾µÄÉùÓþºÍÐÅÓþÔì³É»ÙÃðÐÔÓ°Ïì¡£BlackCatÌåÏָù«Ë¾¾Ü¾øÖ§¸¶ÈκÎÓöÈ¡£


https://www.databreaches.net/only-months-after-dealing-with-one-problem-academy-mortgage-gets-hit-with-a-ransomware-attack/


6¡¢Group-IBÐû²¼¹ØÓÚÀÕË÷Èí¼þQilinµÄ¼¼Êõ·ÖÎö³ÂËß


5ÔÂ15ÈÕ £¬Group-IBÐû²¼Á˹ØÓÚÀÕË÷Èí¼þQilinµÄRaaS·¨Ê½µÄ·ÖÎö³ÂËß¡£Qilin £¬ÓÖÃûAgenda £¬ÔÚ2022Äê8Ô±»·¢ÏÖ £¬Ò»Ö±Õë¶ÔÒªº¦ÐÐÒµµÄ¹«Ë¾ £¬Ê¹ÓÃRustºÍGoÓïÑÔ£¨Golang£©¿ª·¢µÄÀÕË÷Èí¼þ¡£3Ô £¬Group-IB·¢ÏÖQilinÔÚRaaSģʽÏÂÔË×÷ £¬²¢ÎªÆäÁ¥Êô×éÖ¯Ìṩ¹ÜÀíÃæ°å £¬·ÖΪargets¡¢Blogs¡¢Stuffers¡¢News¡¢PaymentsºÍFAQsµÈ²¿ÃÅ £¬ÒÔ¸üÓÐЧµØ¹ÜÀí¹¥»÷¡£¾ÝϤ £¬ÕâЩÁ¥Êô×éÖ¯¿É´Óÿ±ÊÊê½ðÖÐ׬ȡ80%ÖÁ85%µÄÊÕÒæ¡£


https://www.group-ib.com/blog/qilin-ransomware/