Win 11×îв¹¶¡µ¼ÖÂMalwarebytesÓëChrome²»¼æÈÝ

Ðû²¼Ê±¼ä 2023-06-16
1¡¢Win 11×îв¹¶¡µ¼ÖÂMalwarebytesÓëChrome²»¼æÈÝ


¾ÝýÌå6ÔÂ14ÈÕ±¨µÀ£¬±¾ÖܶþÐû²¼µÄWindows 11 22H2 KB5027231ÀÛ»ý¸üÐÂÓ°ÏìÁËMalwarebytes¿Í»§ÏµÍ³ÉϵÄGoogle Chrome¡£Ò»Î»¹ÜÀíԱ˵£¬°²×°¸üкóChromeä¯ÀÀÆ÷·ºÆðÎÊÌ⣬ÊÔͼͨ¹ýWSUS»Ø¹ö£¬Ê¼þ¼ì²ìÆ÷ÖÐÏÔʾ¡°catastrophic error¡±£¬¶øÇÒWSUSÏÔʾ²»Äܻعö¡£Chrome½ø³Ìʵ¼ÊÉÏÕýÔÚÔËÐУ¬µ«ÓÉÓÚ³åÍ»¶øÎÞ·¨ÍêÈ«Æô¶¯Ó¦Ó÷¨Ê½ºÍ¼ÓÔØÓû§½çÃæ¡£MalwarebytesÌåÏÖ£¬Win 11¸üе¼ÖÂChromeÓë©¶´ÀûÓñ£»¤·¢Éú³åÍ»£¬½ø¶øµ¼ÖÂä¯ÀÀÆ÷Í߽⡣Óöµ½´ËÎÊÌâµÄÓû§¿ÉÒÔ´ÓÆäMalwarebytesÊܱ£»¤Ó¦Ó÷¨Ê½ÁбíÖйرÕÍøÂçä¯ÀÀÆ÷¡£


https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5027231-update-breaks-google-chrome-for-malwarebytes-users/


2¡¢ÃÀ¹ú¶à¸öÕþ¸®»ú¹¹Ôâµ½ÀÕË÷ÍÅ»ïClopµÄ¹¥»÷


¾Ý6ÔÂ16ÈÕ±¨µÀ£¬ÃÀ¹ú¶à¸öÕþ¸®»ú¹¹Ôâµ½ÁËÀÕË÷ÍÅ»ïClopµÄ¹¥»÷¡£¹¥»÷ÕßÀûÓÃÁËMOVEitÎļþ´«Ê乤¾ßÖеÄ©¶´£¬CISA³ÆÆäÕýÔÚºÍFBIŬÁ¦ÎªÊ¹ÓÃMOVEitµÄÁª°î»ú¹¹Ìṩ×ÊÖú£¬È·ÈϹ¥»÷µÄÓ°Ïì²¢¼°Ê±µ÷Í£¡£¹Ù·½¾Ü¾øÍ¸Â¶ÊÜÓ°ÏìµÄ»ú¹¹µÄÃû³ÆºÍÊýÁ¿£¬µ«Ò»Î»ÄÜÔ´²¿·¢ÑÔÈË͸¶£¬¸Ã²¿ÃÅÊÇÔâµ½ÈëÇֵĶà¸öÁª°î»ú¹¹Ö®Ò»¡£´ËÍ⣬Ӣ¹úʯÓͺÍÌìÈ»Æø¹«Ë¾¿ÇÅÆÔÚ±¾ÖÜËÄ͸¶ÆäÒ²Ôâµ½ÁËClopÀÕË÷¹¥»÷£¬¸Ã¹«Ë¾È¥ÄêµÄÊÕÈëÁè¼Ý3810ÒÚÃÀÔª¡£


https://therecord.media/several-us-federal-agencies-affected-by-moveit-breach


3¡¢HP¹ûȻͨ¹ý¶ñÒâÍøÕ¾·Ö·¢ChromeÀ©Õ¹ShampooµÄ»î¶¯


6ÔÂ14ÈÕ±¨µÀ£¬HP¹ûÈ»ÁËÒ»¸öÕýÔÚ½øÐÐÖеÄÐÂChromeLoader»î¶¯¡£¸Ã»î¶¯Ê¼ÓÚ3Ô£¬Í¨¹ýÉù³Æ¿ÉÃâ·ÑÏÂÔØµÁ°æÒôÀÖ¡¢Ó°Ï·»òÓÎÏ·µÄ¶ñÒâÍøÕ¾·Ö·¢ChromeLoader¡£ÓÕʹĿ±êÏÂÔØÖ´ÐÐPowerShell½Å±¾µÄVBScript£¬¸Ã½Å±¾ÉèÖÃÒÔ¡°chrome_¡±ÎªÇ°×ºµÄ¼Æ»®ÈÎÎñ¡£´ËÈÎÎñ»á´¥·¢Ò»ÏµÁнű¾£¬½«ÐµÄPowerShell½Å±¾ÏÂÔØ²¢Éú´æµ½×¢²á±íÖУ¬Í¬Ê±»á»ñÈ¡¶ñÒâChromeÀ©Õ¹Shampoo¡£ShampooÊÇChromeLoaderµÄ±äÌ壬Äܹ»ÔÚÄ¿±ê·ÃÎʵÄÍøÕ¾ÉÏ×¢Èë¹ã¸æ²¢Ö´ÐÐËÑË÷²éÑ¯ÖØ¶¨Ïò¡£


https://www.bleepingcomputer.com/news/security/new-shampoo-chromeloader-malware-pushed-via-fake-warez-sites/


4¡¢Trellix³ÆÐÂÇÔÈ¡·¨Ê½SkuldÕë¶ÔÅ·ÃÀºÍ¶«ÄÏÑǵȵØ


TrellixÔÚ6ÔÂ13ÈÕ³ÆÆä·¢ÏÖÁËÐÂÐÍGolangÇÔÈ¡·¨Ê½Skuld£¬ÒÑÈëÇÖÅ·ÖÞ¡¢¶«ÄÏÑǺÍÃÀ¹úµÄWindowsϵͳ¡£¸Ã¶ñÒâÈí¼þ×Ô4ÔÂÏÂÑ®¿ªÊ¼·¢×÷£¬»áËÑË÷´æ´¢ÔÚDiscordºÍä¯ÀÀÆ÷µÈÓ¦ÓÃÖеÄÊý¾Ý£¬ÒÔ¼°ÏµÍ³µÄÐÅÏ¢ºÍÎļþ¼ÐÖеÄÎļþ¡£²¿ÃÅÑù±¾ÉõÖÁ°üÂÞÇÔÈ¡¼ÓÃÜ»õ±ÒµÄÄ £¿é£¬µ«Ñо¿ÈËÔ±ÈÏΪ¸ÃÄ £¿éÈÔÔÚ¿ª·¢ÖС£Ñо¿ÈËÔ±³Æ£¬¿ª·¢ÈËÔ±Deathined´Ó¶à¸ö¿ªÔ´ÏîÄ¿ºÍ¶ñÒâÈí¼þÑù±¾Öм³È¡Áé¸Ð£¬½«¹¦Ð§ÒÆÖ²µ½GolangÀ´¹¹½¨Skuld¡£


https://www.trellix.com/en-us/about/newsroom/stories/research/skuld-the-infostealer-that-speaks-golang.html


5¡¢Î¢ÈíÐû²¼¹ØÓÚºÚ¿ÍÍÅ»ïCadet BlizzardµÄ·ÖÎö³ÂËß


6ÔÂ14ÈÕ£¬Î¢ÈíÐû²¼Á˹ØÓÚºÚ¿ÍÍÅ»ïCadet BlizzardµÄ·ÖÎö³ÂËß¡£¾ÝÐÅ£¬¸Ã×éÖ¯ÓÚ2020Ä꿪ʼÔËÓª£¬Óë¶íÂÞ˹GRUÓйØ£¬Ö÷ÒªÕë¶ÔÎÚ¿ËÀ¼µÄÕþ¸®·þÎñ¡¢Ö´·¨»ú¹¹¡¢·ÇÓªÀû/·ÇÕþ¸®×éÖ¯¡¢IT·þÎñÌṩÉÌ/×Éѯ¹«Ë¾ºÍ½ô¼±·þÎñ¡£²¢½«ÆäÓë2022Äê1ÔÂ13ÈÕÕë¶ÔÎÚ¿ËÀ¼µÄWhisperGate¹¥»÷ÁªÆðÀ´¡£¸ÃÍÅ»ïÔÚ2022Äê6ÔÂÖ®ºóÖð½¥µ­³öÈËÃǵÄÊÓÏߣ¬µ«ÔÚ2023Äê³õÖØÐ¸¡³öË®Ãæ¡£Î¢ÈíÌåÏÖ£¬ÓëAPT28ºÍSandwormµÈÆäËüGRUÏà¹ØºÚ¿ÍÍÅ»ïÏà±È£¬Cadet Blizzard¹¥»÷µÄÀÖ³ÉÂÊÏà¶Ô½ÏµÍ¡£


https://www.microsoft.com/en-us/security/blog/2023/06/14/cadet-blizzard-emerges-as-a-novel-and-distinct-russian-threat-actor/


6¡¢StairwellÅû¶ChamelGangÖ²È뷨ʽChamelDoHµÄϸ½Ú


6ÔÂ13ÈÕ£¬StairwellÅû¶ºÚ¿ÍÍÅ»ïChamelGangµÄÐÂÖ²È뷨ʽChamelDoHµÄϸ½Ú¡£ÕâÊÇÒ»ÖÖÓÃC++¿ª·¢µÄLinuxÖ²È뷨ʽ£¬ÓÃÓÚÔ¶³Ì·ÃÎÊÄ¿±êϵͳ£¬²¢Í¨¹ýDNS-over-HTTPS (DoH)ËíµÀÓëÅäÖõÄC2»ù´¡ÉèʩͨÐÅ¡£ËùÓжñÒâÈí¼þµÄͨÐŶ¼Ê¹ÓÃAES128ºÍÐ޸ĺóµÄbase64±àÂë¼ÓÃÜ£¬ÆäÖаüÂÞ·Ç×ÖĸÊý×Ö×Ö·ûµÄÌæ»»¡£¸ÃÖ²È뷨ʽÊÕ¼¯ÏµÍ³µÄÐÅÏ¢À´·ÖÎö±»Ñ¬È¾µÄÄ¿±ê£¬²¢Äܹ»½øÐлù±¾µÄÔ¶³Ì·ÃÎÊ¿ØÖÆ£¬ÀýÈçÎļþÉÏ´«¡¢ÏÂÔØ¡¢É¾³ýºÍÖ´ÐС£


https://stairwell.com/news/chamelgang-and-chameldoh-a-dns-over-https-implant/