MOVEit TransferÐÞ¸´ÆäwebÓ¦ÓÃÖеĶà¸öSQL×¢Èë©¶´

Ðû²¼Ê±¼ä 2023-06-12

1¡¢MOVEit TransferÐÞ¸´ÆäwebÓ¦ÓÃÖеĶà¸öSQL×¢Èë©¶´


¾Ý6ÔÂ10ÈÕ±¨µÀ £¬Progress SoftwareÔÚÆäMOVEit TransferÍйÜÎļþ´«Êä(MFT)½â¾ö·½°¸ÖÐз¢ÏÖÁ˶à¸öÑÏÖØµÄSQL×¢Èë©¶´¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòMOVEit TransferÓ¦Ó÷¨Ê½Ìá½»ÌØÖÆµÄpayload £¬À´Ð޸ĺÍй¶MOVEitÊý¾Ý¿âµÄÄÚÈÝ¡£ÕâЩ©¶´ÊÇͨ¹ý´úÂëÄþ¾²É󼯷¢ÏÖµÄ £¬Ó°ÏìÁËËùÓÐMOVEit Transfer°æ±¾ £¬Ä¿Ç°ÉÐδ·¢ÏÖ±»ÀûÓõļ£Ï󡣸ù«Ë¾ÓÚ6ÔÂ9ÈÕÐû²¼ÁËÄþ¾²²¹¶¡ £¬²¢ÌåÏÖËùÓÐMOVEit Transfer¿Í»§¶¼±ØÐëÓ¦Óô˲¹¶¡¡£


https://thehackernews.com/2023/06/new-critical-moveit-transfer-sql.html


2¡¢¶íÂÞË¹ÒøÐÐÏà¹ØµÄµçÐŹ«Ë¾Infotel JSCÔâµ½´ó¹æÄ£¹¥»÷


¾ÝýÌå6ÔÂ9ÈÕ±¨µÀ £¬ÎÚ¿ËÀ¼ºÚ¿ÍÍÅ»ïCyber.Anarchy.SquadÉù³Æ¹¥»÷Á˶íÂÞ˹µçÐÅÌṩÉÌInfotel JSC²¢µ¼ÖÂÆäå´»ú¡£InfotelÖ÷ÒªÂôÁ¦¶íÂÞ˹ÑëÐÐÓëÆäËü¶íÂÞË¹ÒøÐС¢ÍøÉÏÉ̵êºÍÐÅ´û»ú¹¹Ö®¼äµÄÁ¬½Ó·þÎñ¡£Infotel JSC͸¶´Ë´Î´ó¹æÄ£ºÚ¿Í¹¥»÷Ó°ÏìÁËÆä²¿ÃÅÍøÂçÉ豸 £¬Ä¿Ç°ÕýÔÚŬÁ¦»Ö¸´ÊÜÓ°ÏìµÄϵͳ £¬Íê³ÉÈÕÆÚ½«ÁíÐÐ֪ͨ¡£IODA³Æ·þÎñÓÚUTC 6ÔÂ8ÈÕÉÏÎç11:00×óÓÒÖжÏ¡£ºÚ¿Í»¹Ðû²¼ÁËInfotelϵͳµÄ½ØÍ¼×÷Ϊ¹¥»÷Ö¤¾Ý £¬°üÂÞÍøÂç»ù´¡ÉèʩͼºÍ±»ÈëÇÖµç×ÓÓʼþÕÊ»§¡£


https://www.bleepingcomputer.com/news/security/ukrainian-hackers-take-down-service-provider-for-russian-banks/


3¡¢Ó¢¹úÂü³¹Ë¹ÌØ´óѧÔâµ½¹¥»÷Ô±¹¤ºÍѧÉúÊý¾Ý¿ÉÄÜй¶


ýÌå6ÔÂ9ÈÕ±¨µÀ £¬Ó¢¹úÂü³¹Ë¹ÌØ´óѧÔâµ½¹¥»÷ £¬Ô±¹¤ºÍѧÉúµÄÊý¾Ý¿ÉÄÜÒѾ­Ð¹Â¶¡£¸ÃУ³ÆËüÔÚ6ÔÂ6ÈÕ·¢ÏÖÁËÕâÒ»ÎÊÌâ £¬²¢Á¢¼´Õ¹¿ªÊӲ졣¾­È·Èϲ¿ÃÅϵͳÒѱ»Î´¾­ÊÚȨµÄµÚÈý·½·ÃÎÊ £¬Êý¾Ý¿ÉÄÜÒѱ»¸´ÖÆ¡£´ËÍâ £¬Âü³¹Ë¹ÌØ´óѧÌåÏÖ´Ë´ÎÄþ¾²Ê¼þÓë×î½üµÄMOVEit TransferÊý¾Ýй¶¹¥»÷ºÍZellisÏà¹Ø¹¥»÷Î޹ء£¸Ã´óѧûÓÐÌṩ¹ØÓÚ¹¥»÷µÄ½øÒ»²½ÐÅÏ¢ £¬µ«Ñо¿ÈËÔ±´ÓÏûÏ¢À´Ô´»ñϤÕâÊÇÒ»ÆðÀÕË÷¹¥»÷¡£


https://securityaffairs.com/147290/data-breach/university-of-manchester-cyber-attack.html


4¡¢Elastic·¢ÏÖÖ÷ÒªÕë¶ÔÔ½ÄÏÆóÒµµÄкóÃÅSPECTRALVIPER 


ElasticÔÚ6ÔÂ9ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öÐÂÐͺóÃÅSPECTRALVIPER £¬Ö÷ÒªÓÃÓÚÕë¶ÔÔ½ÄÏÉÏÊй«Ë¾µÄ¹¥»÷»î¶¯¡£PECTRALVIPERÊÇÒ»¸ö»ìÏýµÄx64ºóÃÅ £¬Ëü¾ßÓÐPE¼ÓÔØºÍ×¢Èë¡¢ÎļþÉÏ´«ºÍÏÂÔØ¡¢ÎļþºÍĿ¼¿ØÖÆÒÔ¼°ÁîÅÆÄ£Ä⹦Ч¡£Ñо¿ÈËÔ±½«¸Ã»î¶¯¹éÒòÓÚÔ½ÄϵĹ¥»÷ÍÅ»ïREF2754¡£×îÐÂѬȾÁ´ÖÐ £¬ÀûÓÃÁËSysInternals ProcDumpʵÓ÷¨Ê½¼ÓÔØ°üÂÞDONUTLOADERµÄδǩÃûDLLÎļþ £¬¶ûºóÕßÓÖ±»ÅäÖÃΪ¼ÓÔØSPECTRALVIPERºÍÆäËü¶ñÒâÈí¼þ £¬ÀýÈçP8LOADER»òPOWERSEAL¡£


https://www.elastic.co/cn/security-labs/elastic-charms-spectralviper


5¡¢Sorgu Paneli¿É¹ûÈ»¼ìË÷Ô¼8500ÍòÍÁ¶úÆä¾ÓÃñµÄÐÅÏ¢


6ÔÂ10ÈÕ±¨µÀ £¬8500ÍòÍÁ¶úÆä¾ÓÃñµÄÃô¸ÐÐÅϢй¶¡£ÍÁ¶úÆäµÄƽ̨Free Web TurkeyÆØ¹âÁËÒ»¸öÃûΪSorgu PaneliµÄÍøÕ¾ £¬¿É²»ÊÜÏÞÖÆµØ·ÃÎʸöÈËÐÅÏ¢ £¬ÀýÈçÉí·ÝÖ¤ºÅÂë¡¢ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëÉõÖÁÒøÐÐÕË»§ÏêϸÐÅÏ¢ £¬ÒÔ»»È¡Ãâ·Ñ»áÔ±×ʸñ¡£¸¶·Ñ»áÔ±¿ÉÒÔ»ñµÃ¸ü¶àÐÅÏ¢ £¬ÀýÈçլȯ¡£¸ÃÍøÕ¾ÔÚÓòÃûSorgu.liveÏÂÔËÓª £¬Ä¿Ç°¹²ÓÐ5195ÃûÓû§ £¬²¢ÔÚTelegramºÍDiscordÉÏÌṩÀàËÆµÄ·þÎñ¡£¾ÝÔ¤¼Æ £¬Ô¼ÓÐ8500ÍòÍÁ¶úÆä¹«ÃñµÄÐÅÏ¢Êܵ½Ó°Ïì¡£


https://medyanews.net/website-leak-exposes-sensitive-data-of-85-million-turkish-residents-report/


6¡¢Check Point¹ûÈ»ÀûÓÃStealth Soldier¹¥»÷±±·ÇµÄ»î¶¯


6ÔÂ8ÈÕ £¬Check Point¹ûÈ»ÁËÒ»ÆðÕë¶ÔÐÔºÜÇ¿µÄ¼äµý¹¥»÷ £¬ÀûÓÃÁËÐµĶ¨ÖÆÄ£¿é»¯ºóÃÅStealth Soldier¡£¸Ã¶ñÒâÈí¼þÖ÷ÒªÔËÐмàÊÓ¹¦Ð§ £¬ÀýÈçÎļþй¶¡¢ÆÁÄ»ºÍÂó¿Ë·çÂ¼ÖÆ¡¢¼üÅ̼ǼºÍÇÔÈ¡ä¯ÀÀÆ÷ÐÅÏ¢¡£Stealth SoldierÓëThe Eye on the NileµÄ»ù´¡ÉèÊ©Óв¿ÃÅÖØµþ £¬¹¥»÷ÕßʹÓÃÁËαװ³ÉÀû±ÈÑÇÍâ½»²¿ÍøÕ¾µÄC2Óò¡£Ñо¿ÈËÔ±³Æ £¬Ñ¬È¾Á´´ÓºÜÅÓ´ó £¬Éæ¼°´ÓC&C·þÎñÆ÷ÏÂÔØµÄÁù¸öÎļþ £¬°üÂÞLoader( MSDataV5.16945.exe)¡¢Watchdog(MSCheck.exe)ºÍPayload(MShc.txt)µÈ¡£


https://research.checkpoint.com/2023/stealth-soldier-backdoor-used-in-targeted-espionage-attacks-in-north-africa/