TA544ʹÓÃWikiLoaderÕë¶ÔÒâ´óÀûµÄÆóÒµ·Ö·¢Ursnif

Ðû²¼Ê±¼ä 2023-08-02

1¡¢TA544ʹÓÃWikiLoaderÕë¶ÔÒâ´óÀûµÄÆóÒµ·Ö·¢Ursnif


ProofpointÔÚ7ÔÂ31ÈÕÅû¶ÁËʹÓÃжñÒâÈí¼þWikiLoaderÕë¶ÔÒâ´óÀûÆóÒµµÄ¹¥»÷Ô˶¯¡£WikiLoaderÊÇÒ»¸öÖØ´óµÄÏÂÔسÌÐò £¬ÓÉÓÚËü»áÏòWikipedia·¢³öÇëÇó²¢¼ì²éÏìÓ¦ÄÚÈÝÖÐÊÇ·ñ°üÀ¨×Ö·û´®¡°The Free¡±¶øµÃÃû¡£ProofpointÓÚ2022Äê12ÔÂ27ÈÕÊ×´ÎÔÚÒ°Íâ¼ì²âµ½¸Ã¶ñÒâÈí¼þ £¬ÓÉTA544Èö²¥¡£Ñо¿Ö°Ô±³Æ £¬ÖÁÉÙÓÐ8¸öÔ˶¯ÔÚ·Ö·¢WikiLoader £¬À´×ÔTA544ºÍTA551 £¬¾ùÕë¶ÔÒâ´óÀûµÄ×éÖ¯¡£±ðµÄ £¬ËäÈ»´ó´ó¶¼¹¥»÷ÕßÒѲ»ÔÙʹÓÃÆôÓúêµÄÎĵµÀ´Èö²¥¶ñÒâÈí¼þ £¬µ«TA544ÈÔÔÚ¹¥»÷Á´ÖÐʹÓÃËüÃÇ £¬°üÀ¨Èö²¥WikiLoader¡£


https://www.proofpoint.com/us/blog/threat-insight/out-sandbox-wikiloader-digs-sophisticated-evasion


2¡¢ÃÀ¹úÒÂÊι«Ë¾Hot TopicÔ⵽ײ¿â¹¥»÷й¶¿Í»§µÄÐÅÏ¢


¾ÝýÌå8ÔÂ1ÈÕ±¨µÀ £¬ÃÀ¹úÒÂÊμ°ÊÚȨÒôÀÖÁãÊÛÁ¬ËøµêHot Topic͸¶ÆäÔâµ½Á˶àÆð¹¥»÷ÊÂÎñ £¬µ¼Ö¿ͻ§µÄÃô¸ÐÐÅϢй¶¡£¸Ã¹«Ë¾ÔÚÃÀ¹úÓµÓÐ675¼ÒÊÐËÁ £¬ÒÔ¼°Ã¿Ô½ü1000Íò»á¼ûÁ¿µÄÔÚÏßÊÐËÁ¡£¸Ã¹«Ë¾Ú¹ÊÍ˵ £¬ºÚ¿ÍʹÓÃÇÔÈ¡µÄÕÊ»§Æ¾Ö¤¶à´Î»á¼ûÁËRewardsƽ̨ £¬¿ÉÄÜ»ñµÃÁË¿Í»§µÄÊý¾Ý¡£¾­ÊÓ²ì £¬¹¥»÷ÕßÓÚ2023Äê2ÔÂ7ÈÕ¡¢3ÔÂ11ÈÕ¡¢5ÔÂ19ÈÕÖÁ21ÈÕ¡¢5ÔÂ27ÈÕÖÁ28ÈÕºÍ6ÔÂ18ÈÕÖÁ21ÈÕ £¬Ê¹ÓÃÓÐÓÃÕÊ»§Æ¾Ö¤¶ÔÍøÕ¾ºÍÒƶ¯Ó¦ÓÃÖ´ÐÐÁË×Ô¶¯¹¥»÷¡£¸Ã¹«Ë¾ÌåÏÖ £¬Hot Topic²»ÊÇй¶ƾ֤µÄȪԴ £¬µ«Ò²ÎÞ·¨ÕÒµ½ÈªÔ´¡£


https://www.bleepingcomputer.com/news/security/retail-chain-hot-topic-discloses-wave-of-credential-stuffing-attacks/


3¡¢Henry Ford HealthÔâ´¹ÂÚ¹¥»÷½ü17Íò»¼ÕßÐÅϢй¶


¾Ý7ÔÂ27ÈÕ±¨µÀ £¬ÃÀ¹úµÄѧÊõÒ½ÁÆ»úHenry Ford Health³ÆÆä3ÃûÔ±¹¤Ôâµ½´¹ÂÚ¹¥»÷ £¬Ó°ÏìÁË168215¸ö»¼ÕßµÄÐÅÏ¢¡£¸Ã»ú¹¹ÔÚÉùÃ÷ÖÐÌåÏÖ £¬¹¥»÷ÊÂÎñ±¬·¢ÓÚ3ÔÂ30ÈÕ £¬¸Ã×éÖ¯Òѽ«±»Ó°ÏìµÄµç×ÓÓʼþÕÊ»§±£»¤ÆðÀ´²¢Õö¿ªÊӲ졣5ÔÂ16 £¬È·¶¨»¼ÕߵĿµ½¡ÐÅÏ¢°üÀ¨ÔÚµç×ÓÓÊÏäÖÐ £¬²¢ÇÒ¿ÉÄÜÒѱ»¹¥»÷ÕßÇÔÈ¡ £¬Éæ¼°ÐÕÃû¡¢ÊµÑéÊÒЧ¹û¡¢ÊÖÊõÀàÐÍ¡¢Õï¶Ï¡¢µç»°ºÅÂë¡¢²¡ÀúºÅºÍÄÚ²¿¸ú×ٺŵÈÐÅÏ¢¡£¸Ã¹«Ë¾ÌåÏÖ £¬ËûÃÇÕýÔÚʵÑéÌØÁíÍâÇå¾²²½·¥ £¬²¢½«ÎªÔ±¹¤ÌṩÇå¾²Åàѵ¡£


https://www.bankinfosecurity.com/phishing-scam-affects-nearly-170k-henry-ford-health-patients-a-22672 


4¡¢Cado·¢Ã÷¿ÉÕë¶ÔRedis·þÎñÆ÷µÄP2PInfectÈä³æбäÌå


7ÔÂ31ÈÕ £¬Cado·¢Ã÷ÁËÒ»ÖÖÕë¶ÔRedisµÄÐÂÐͶñÒâÈí¼þÔ˶¯¡£¸Ã¶ñÒâÈí¼þ±»¿ª·¢ÕßÃüÃûΪP2Pinfect £¬ÓÃRust¿ª·¢ £¬³äµ±½©Ê¬ÍøÂçÊðÀí¡£Ñо¿Ö°Ô±ÆÊÎöµÄÑù±¾°üÀ¨Ò»¸öǶÈëʽPEÎļþÒÔ¼°Ò»¸öELF¶þ½øÖÆÎļþ £¬ÕâÅú×¢ÎúWindowsºÍLinuxÖ®¼ä¾ßÓпçƽ̨¼æÈÝÐÔ¡£Ëü»¹Ê¹Óø´Öƹ¦Ð§À´¹¥»÷RedisÊý¾Ý´æ´¢µÄʵÀý¡£±ðµÄ £¬P2PinfectÊÔͼͨ¹ýCronδ¾­Éí·ÝÑéÖ¤µÄRCE»úÖƹ¥»÷RedisÖ÷»ú¡£¸ÃÔ˶¯±³ºóµÄ¹¥»÷ÕßÉí·ÝÉв»ÇåÎú £¬P2PInfectµÄÄ¿µÄÒ²²»ÇåÎú¡£


https://www.cadosecurity.com/redis-p2pinfect/


5¡¢Minecraft modÎó²îBleedingPipeÒѱ»´ó¹æģʹÓÃ


ýÌå7ÔÂ31ÈÕ±¨µÀ³Æ £¬ºÚ¿ÍÕýÔÚʹÓÃMinecraft modÖеÄRCEÎó²îBleedingPipeÔÚ·þÎñÆ÷ºÍ¿Í»§¶ËÖ´ÐжñÒâÏÂÁî £¬´Ó¶ø¿ØÖÆ×°±¸¡£BleedingPipeÎó²î×î³õÓÚ2022Äê3Ô±»Ê¹Óà £¬µ«ºÜ¿ì¾Í±»mod¿ª·¢ÕßÐÞ¸´ÁË¡£È»¶øÔÚ7ÔÂÔçЩʱ¼ä £¬ForgeÂÛ̳µÄһƪÌû×Ó³Æ £¬ÓÐÈËʹÓÃδ֪RCEÀ´´ó¹æÄ£ÇÔÈ¡Íæ¼ÒµÄDiscordºÍSteam»á»°cookie¡£½øÒ»²½Ñо¿·¢Ã÷ £¬¶à¸öMinecraft modÖÐÒ²±£´æBleedingPipeÎó²î¡£¹¥»÷ÕßÕýÔÚɨÃèÊܸÃÎó²îÓ°ÏìµÄMinecraft·þÎñÆ÷²¢Ö´Ðй¥»÷ £¬Òò´ËÐÞ¸´·þÎñÆ÷ÉÏÒ×±»¹¥»÷µÄmodÖÁ¹ØÖ÷Òª¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-bleedingpipe-rce-to-target-minecraft-servers-players/


6¡¢Bahamutͨ¹ýð³äµÄAndroidÓ¦ÓÃSafeChatÇÔÊØÐÅÏ¢


7ÔÂ28ÈÕ £¬CYFIRMA³ÆÆä·¢Ã÷ÁËÒ»¸ö¿ÉÒɵÄAndroid¶ñÒâÈí¼þ £¬Î±×°³ÉÐéαµÄ̸ÌìÓ¦ÓÃSafeChat £¬ÇÔÈ¡ÊÖ»úµÄͨ»°¼Í¼¡¢¶ÌÐźÍGPSλÖõÈÊý¾Ý¡£¸Ã¶ñÒâÈí¼þ±»ÏÓÒÉÊÇCoverlmµÄ±äÖÖ £¬»áÇÔÈ¡Telegram¡¢Signal¡¢WhatsApp¡¢ViberºÍFacebook MessengerµÈͨѶӦÓõÄÊý¾Ý¡£¸ÃÔ˶¯ÓëÓ¡¶ÈºÚ¿ÍÍÅ»ïBahamutÓÐ¹Ø £¬Ö÷Ҫͨ¹ýWhatsAppÉϵÄÓã²æʽ´¹ÂÚÐÂΞÙÐÐ £¬Ö÷ÒªÕë¶ÔÄÏÑǵØÇø¡£±ðµÄ £¬¸ÃÔ˶¯ÓëÓ¡¶ÈµÄÁíÒ»¸öºÚ¿ÍÍÅ»ïDoNotµÄÔ˶¯ÓÐÏàËÆÖ®´¦¡£


https://www.cyfirma.com/outofband/apt-bahamut-targets-individuals-with-android-malware-using-spear-messaging/