ÖÇÀûµÄµçÐŹ«Ë¾GTDÔâµ½ÀÕË÷ÍÅ»ïRorschachµÄ¹¥»÷

Ðû²¼Ê±¼ä 2023-10-27

1¡¢ÖÇÀûµÄµçÐŹ«Ë¾GTDÔâµ½ÀÕË÷ÍÅ»ïRorschachµÄ¹¥»÷


¾ÝýÌå10ÔÂ25ÈÕ±¨µÀ£¬ÖÇÀûµçÐŹ«Ë¾Grupo GTDÔâµ½¹¥»÷£¬Ó°ÏìÁËÆä»ù´¡ÉèÊ©¼´·þÎñ(IaaS)ƽ̨£¬µ¼ÖÂÔÚÏß·þÎñÔÝʱÖжÏ¡£¹¥»÷·¢ÉúÓÚ10ÔÂ23ÈÕÉÏÎ磬GTDµÄÊý¾ÝÖÐÐÄ¡¢»¥ÁªÍø½ÓÈëºÍIPÓïÒô(VoIP)µÈ·þÎñÊܵ½Ó°Ïì¡£ÖÇÀûCSIRT³ÆÕâÊÇÒ»ÆðÀÕË÷¹¥»÷£¬ËäȻûÓÐ͸¶¹¥»÷ÕßÉí·Ý£¬µ«Ñо¿ÈËÔ±»ñÏ¤Éæ¼°µ½ÀÕË÷Èí¼þRorschach£¨ÓÖÃûBabLock£©µÄ±äÖÖ¡£¹ØÓÚGTD¹¥»÷ʼþµÄ³ÂËßÌåÏÖ£¬¹¥»÷ÕßÀûÓÃÁ˺Ϸ¨µÄTrend Micro¡¢BitDefenderºÍCortex XDR¿ÉÖ´ÐÐÎļþÖеÄDLL²à¼ÓÔØÂ©¶´À´¼ÓÔØ¶ñÒâDLL¡£


https://www.bleepingcomputer.com/news/security/chilean-telecom-giant-gtd-hit-by-the-rorschach-ransomware-gang/


2¡¢Winter VivernÀûÓÃRoundcube©¶´¹¥»÷Å·Ö޵Ļú¹¹


ESETÔÚ10ÔÂ25ÈÕÅû¶ÁËWinter VivernÍÅ»ïÕë¶ÔÅ·Ö޵Ĺ¥»÷»î¶¯¡£ÖÁÉÙ×Ô10ÔÂ11ÈÕÆð£¬¸ÃÍÅ»ï¾ÍÒ»Ö±ÀûÓÃRoundcube Webmail·þÎñÆ÷ÖеÄXSS©¶´(CVE-2023-5631)¹¥»÷Å·ÖÞÕþ¸®»ú¹¹ºÍÖǿ⡣¹¥»÷Õßð³äOutlookÍŶÓ£¬Í¨¹ý°üÂÞÌØÖÆµÄSVGÎĵµµÄHTMLÓʼþÀ´Ô¶³Ì×¢ÈëÈÎÒâJavaScript´úÂ룬×îÖÕpayload¿É´Ó±»Ñ¬È¾µÄÍøÂçÓʼþ·þÎñÆ÷ÇÔÈ¡µç×ÓÓʼþ¡£¸ÃXSS©¶´ÒÑÓÚ10ÔÂ14ÈÕ±»ÐÞ¸´¡£


https://www.welivesecurity.com/en/eset-research/winter-vivern-exploits-zero-day-vulnerability-roundcube-webmail-servers/


3¡¢MandiantÌáÐÑVolt TyphoonÕë¶ÔÃÀ¹úµÄÒªº¦»ù´¡ÉèÊ©


¾Ý10ÔÂ25ÈÕ±¨µÀ£¬MandiantÌáÐѹÜÀíÈËÔ±×¢ÒâVolt TyphoonÕë¶ÔÃÀ¹úµÄÒªº¦»ù´¡ÉèÊ©µÄ¹¥»÷¡£×Ô2021ÄêÖÐÆÚÒÔÀ´£¬¸ÃÍÅ»ïÒѹ¥»÷ÁËͨÐÅ¡¢ÖÆÔì¡¢¹«¹²ÊÂÒµ¡¢ÔËÊä¡¢½¨Öþ¡¢º£Ê¡¢Õþ¸®¡¢ÐÅÏ¢¼¼ÊõºÍ½ÌÓýµÈÁìÓòµÄÖÖÖÖʵÌå¡£Ñо¿ÈËÔ±³Æ£¬ËûÃÇ¿ÉÄÜÏëÔÚÕ½Ê±ÖÆÔìÆÆ»µÐÔʼþ£¬ËäȻûÓÐÇ鱨֤ʵÕâÒ»µã£¬µ«Ö÷ÒªÕë¶ÔÒªº¦»ù´¡ÉèÊ©µÄ»î¶¯Ê¹Æä²»µÃ²»ÓÅÏÈ¿¼ÂÇ¡£Ñо¿ÈËÔ±¶Ø´Ù¹ÜÀíÕßÓÅÏÈÎªÃæÏò»¥ÁªÍøµÄ±ßÔµÉ豸ºÍÍøÂç·ÓÉÆ÷´ò²¹¶¡ºÍ½ÓÄÉ»º½â´ëÊ©¡£ 


https://www.securityweek.com/mandiant-intelligence-chief-raises-alarm-over-chinas-volt-typhoon-hackers-in-us-critical-infrastructure/


4¡¢²àÐŵÀ¹¥»÷iLeakage¿ÉÀûÓÃSafariÇÔÈ¡AppleÉ豸Êý¾Ý


ýÌå10ÔÂ26Èճƣ¬Ñо¿ÈËÔ±Éè¼ÆÁËÒ»ÖÖеÄÍÆ²â²àÐŵÀ¹¥»÷·½Ê½iLeakage£¬¿ÉÀûÓÃSafariÇÔÈ¡Mac¡¢iPhoneºÍiPadµÄÊý¾Ý¡£iLeakageÊÇÕë¶ÔApple Silicon CPUºÍSafariä¯ÀÀÆ÷µÄÍÆ²âÖ´Ðй¥»÷£¬Ëü¿ÉÓÃÓÚÒÔ¡°½üºõÍêÃÀµÄ׼ȷÐÔ¡±´ÓSafariÒÔ¼°iOSÉϵÄFirefox¡¢TorºÍEdge¼ìË÷Êý¾Ý¡£´Ó±¾ÖÊÉϽ²£¬ËüÊÇÒ»ÖÖÎÞ¼ÆÊ±Æ÷µÄSpectre¹¥»÷£¬¿ÉÒÔÈÆ¹ýËùÓÐä¯ÀÀÆ÷¹©Ó¦ÉÌʵʩµÄ³ß¶È²àͨµÀ¹¥»÷µÄ± £»¤¡£


https://www.bleepingcomputer.com/news/security/new-ileakage-attack-steals-emails-passwords-from-apple-safari/


5¡¢CiscoÅû¶YoroTrooperÕë¶ÔCIS¹ú¼ÒµÄ¹¥»÷»î¶¯


10ÔÂ25ÈÕ£¬Cisco³ÆYoroTrooperÔÚ½üÆÚÖ÷ÒªÕë¶Ô¶ÀÁ¢¹ú¼ÒÁªºÏÌå(CIS)¹ú¼Ò¡£¸ÃÍÅ»ïÓÚ2022Äê6ÔÂÊ״λîÔ¾£¬¿ÉÄÜÓëÈø¿Ë˹̹ÓйØ£¬»¹Í¨¹ýVPNµÈ·½Ê½Î±×°À´×Ô°¢Èû°Ý½®¡£½ñÄê5ÔÂÖÁ8Ô£¬¹¥»÷ÕßÈëÇÖÁ˶à¸ö¹úÓÐÍøÕ¾ºÍÕþ¸®ÊÂÇéÈËÔ±µÄÕË»§¡£´ó¶àÊý¹¥»÷ʼÓÚµöÓãÓʼþ£¬²¢·Ö·¢¶¨ÖƵĶñÒâÈí¼þ£¬Ö¼ÔÚÇÔÈ¡Êý¾ÝºÍƾ¾Ý¡£×ÔÉϴα»¹ûÈ»Åû¶ºó£¬YoroTrooper¾Í¸ïв¢À©Õ¹ÁËËûÃǵÄTTP£¬½«ËûÃÇ»ùÓÚPythonµÄÖ²Èë·¨Ê½ÒÆÖ²µ½PowerShell£¬²¢Ô½À´Ô½¶àµØ½ÓÄÉ×Ô½ç˵ֲÈ뷨ʽ£¬·ÅÆúÁËÒÔǰʹÓõÄÉÌÆ·»¯¶ñÒâÈí¼þ¡£


https://blog.talosintelligence.com/attributing-yorotrooper/


6¡¢KasperskyÐû²¼ÅÓ´óµÄ¶ñÒâÈí¼þStripedFlyµÄ·ÖÎö


10ÔÂ26ÈÕ£¬KasperskyÐû²¼Á˹ØÓÚÅÓ´óµÄ¶ñÒâÈí¼þ¿ò¼ÜStripedFlyµÄ·ÖÎö³ÂËß¡£¸Ã¶ñÒâÈí¼þÒÑÒþ±ÎÔËÐÐÁË5Ä꣬¾ÝÔ¤¼ÆÒÑѬȾÁËÁè¼Ý100Íò¸öWindowsºÍLinuxϵͳ¡£StripedFly֮ǰ±»´íÎ󵨹éÀàΪMonero¼ÓÃܿ󹤣¬KasperskyÔÚÈ¥Äê·¢ÏÖÁËËüµÄÕæÊÕþ¸®Ê£¬²¢·¢Ïָÿò¼Ü×Ô2017Äê¾Í¿ªÊ¼»î¶¯¡£¸Ã¶ñÒâÈí¼þpayload°üÂÞ¶à¸öÄ£¿é£¬Ê¹¹¥»÷ÕßÄܹ»Äܹ»ÒÔAPT¡¢¼ÓÃÜ¿ó¹¤ÉõÖÁÀÕË÷ÍÅ»ïµÄÉí·ÝÐÐÊ¡£ÍÚ¿óÄ£¿é¿ÉÄÜÊÇÉù¶«»÷Î÷µÄ¼ÆÄ±£¬Ò²ÊǸöñÒâÈí¼þÄܹ»ºã¾ÃÈÆ¹ý¼ì²âµÄÖ÷ÒªÒòËØ£¬¹¥»÷ÕßÖ÷Ҫͨ¹ýÆäËüÄ£¿éÇÔÈ¡Êý¾ÝºÍÈëÇÖϵͳ¡£


https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/