Positive Technologies°ä²¼RootkitÑݱäÇ÷Ïò»ã±¨

°ä²¼¹¦·ò 2021-11-10

Robinhoodƽ̨³ÆÒòÔâµ½¹¥»÷700Íò¿Í»§ÐÅϢй¶


Robinhoodƽ̨³ÆÒòÔâµ½¹¥»÷700Íò¿Í»§ÐÅϢй¶.png


¹ÉƱÂòÂôƽ̨RobinhoodÔÚ11ÔÂ8ÈÕ°ä²¼²¼¸æ £¬Ðû³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷¡£¹¥»÷²úÉúÔÚ11ÔÂ3ÈÕ £¬¹¥»÷Õßͨ¹ýÉç»á¹¤³Ì¹¥»÷»ñµÃÁ˿ͻ§Ö§³ÖϵͳµÄ½Ó¼ûȨÏÞ £¬¿ÉÄÜÒѾ­½Ó¼ûÁËÔ¼700Íò¿Í»§µÄÊý¾Ý £¬Éæ¼°ÐÕÃû¡¢ÓʼþµØÖ·¡¢µ®ÉúÈÕÆÚºÍÓÊÕþ±àÂëµÈÐÅÏ¢¡£´Ë±í £¬RobinHood°µÊ¾ËûÃÇ»¹Ôâµ½ÁËÀÕË÷ £¬µ«²¢Î´ÌṩÓйØÀÕË÷ÒªÇóµÄϸ½ÚÐÅÏ¢¡£Ä¿Ç° £¬¸Ã¹«Ë¾ÔÚ°²È«¹«Ë¾MandiantµÄЭÖú϶ԴËÊ·¢Õ¹µ÷²é¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/robinhood-discloses-data-breach-impacting-7-million-customers/


¶à¹ú·¨Âɲ¿ÃÅ·¢Õ¹µÄCycloneÐж¯³É¹¦½ø¹¥ClopÍÅ»ï


¶à¹ú·¨Âɲ¿ÃÅ·¢Õ¹µÄCycloneÐж¯³É¹¦½ø¹¥ClopÍÅ»ï.png


ÉÏÖÜÎå £¬Óйز¿ÃŹ«¿ªÁ˹ØÓÚCycloneÐж¯µÄ×îÐÂÐÂÎÅ¡£ÕâÊÇΪÆÚ30¸öÔµĹú¼Ê·¨ÂÉÐж¯ £¬Óɹú¼ÊÐ̾¯×é֯Эµ÷ £¬²¢½áºÏÁËÎÚ¿ËÀ¼ºÍÃÀ¹ú·¨Âɲ¿ÃÅ¡£Ðж¯µÄÖØÒªÖ¸±êÊÇClop £¬ËüÔøÂŴι¥»÷Á˺«¹úµÄ¹«Ë¾ºÍÃÀ¹úµÄѧÊõ»ú¹¹¡£CycloneÐж¯»ñµÃÁËCDI¡¢Kaspersky¡¢FortinetºÍGroup-IBµÈ¹«Ë¾µÄÔ®ÊÖ £¬ÔÚÎÚ¿ËÀ¼¿ÛÁôÁË6ÃûÏÓÒÉÈË £¬²¢³ä¹«ÁË185000ÃÀÔªµÄÏÖ½ð¡£ÈôÊÇ×ïÃû³ÉÁ¢ £¬Õâ6¸öÏÓÒÉÈ˽«Ãæ¶Ô×î¸ß°ËÄêµÄ½ûïÀ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/operation-cyclone-deals-blow-to-clop-ransomware-operation/


unit42Åû¶ÀûÓ÷ì϶CVE-2021-40539µÄ¹¥»÷ϸ½Ú


unit42Åû¶ÀûÓ÷ì϶CVE-2021-40539µÄ¹¥»÷ϸ½Ú.png


unit42ÔÚ11ÔÂ7ÈÕÅû¶ÁËÀûÓÃManageEngine ADSelfService PlusÖзì϶CVE-2021-40539µÄ¹¥»÷ϸ½Ú¡£9ÔÂ16ÈÕ £¬CISAÔø°ä²¼¾¯±¨³ÆAPT×éÖ¯ÔÚÀûÓø÷ì϶¹¥»÷Êý°Ù¸öÒ×Êܹ¥»÷µÄ×éÖ¯¡£¹¥»÷ÆðÍ·ÓÚ9ÔÂ22ÈÕ £¬Õë¶ÔÈ«ÇòÁìÓòÄڵĹú·À¡¢Ò½ÁƱ£½¡¡¢ÄÜÔ´ºÍ½ÌÓýÐÐÒµµÈÖÁÉÙÓоŸöÐÐÒµ¡£ÔÚ·ì϶ÀûÓóɹ¦Ö®ºó £¬¹¥»÷Õß»á×°ÖÃGodzilla webshell¡£Ä¿Ç° £¬Éв»Ã÷ÏԻ±³ºóµÄ¹¥»÷ÍÅ»ï £¬µ«»òÐíÓëAPT27£¨Emissary Panda£©ÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/manageengine-godzilla-nglite-kdcsponge/


DetectifyÐÂ×êÑз¢ÏÖSSLÖ¤Êé¿ÉÄÜ»áй¼ûô¸ÐÐÅÏ¢


DetectifyÐÂ×êÑз¢ÏÖSSLÖ¤Êé¿ÉÄÜ»áй¼ûô¸ÐÐÅÏ¢.png


Detectify 11ÔÂ4ÈÕµÄ×îÐÂ×êÑз¢ÏÖ £¬SSLÖ¤Êé¿ÉÄÜ»áй¼ûô¸ÐÐÅÏ¢¡£×Ô7Ô·ÝÒÔÀ´ £¬DetectifyÒѾ­ÍøÂçºÍ·ÖÎöÁ˳¬¹ý9ÒÚ¸ö¹«¹²SSL/TLSÖ¤Êé £¬²¢·¢ÏÔìäÖдæÔڵġ°ÏÝÚ塱¿ÉÄÜ»áй¶¹«Ë¾µÄ»úÃÜÐÅÏ¢¡£¾ø´óÎÞÊýÐÂÈÏÖ¤µÄÓò¶¼±»¸³ÓèÁËÃèÊöÐÔÃû³Æ £¬ÈôÊÇÖ¤ÊéÊÇÔÚ¹«¿ªÇ°µÄ¿ª·¢½×¶ÎÐû¸æµÄ £¬¿ÉÄÜÈþºÕùµÐÊÖÓй¦·òÔÚвúÆ·½øÈëÊг¡Ö®Ç°½øÐзÛËé¡£´Ë±í £¬Í¨Åä·ûÖ¤Êé¿ÉÄÜ»áÊܵ½ALPACA¹¥»÷µÄÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://blog.detectify.com/2021/11/04/new-research-are-ssl-certificates-leaking-company-secrets/


Intel 471°ä²¼Õë¶Ô½»Í¨ÔËÊäÐÐÒµµÄ¹¥»÷µÄ·ÖÎö»ã±¨


Intel 471°ä²¼Õë¶Ô½»Í¨ÔËÊäÐÐÒµµÄ¹¥»÷µÄ·ÖÎö»ã±¨.png


Intel 471ÔÚ11ÔÂ2ÈÕ°ä²¼ÁËÕë¶Ô½»Í¨ÔËÊäÐÐÒµµÄ¹¥»÷µÄ·ÖÎö»ã±¨¡£×êÑÐÈËÔ±·¢ÏÖ £¬´óÁ¿ºÚ¿ÍÔÚ°µÍøÏúÊÛÔËÊäºÍÎïÁ÷×éÖ¯µÄ½Ó¼ûȨÏÞ £¬²¢´§¶ÈËûÃÇÊÇÀûÓÃÔ¶³Ì½Ó¼û½â¾ö¹æ»®£¨Ô̺¬Ô¶³Ì×ÀÃæºÍ̸RDP¡¢VPN¡¢CitrixºÍSonicWallµÈ£©Öеķì϶»ñµÃµÄ¡£»ã±¨Ö¸³ö £¬ÎïÊ¢ÐÐÒµÖð²½³ÉΪ¹¥»÷Ö¸±ê £¬¹¥»÷¿ÉÄÜ»á¶ÔÈ«Çò¾­¼ÃÔì³ÉÑϳÁµÄÁ¬Ëø·´Ó³ £¬Ò»´Î³É¹¦µÄ¹¥»÷¿ÉÄÜ»áʹÕû¸öÐÐÒµÖͰ­ £¬Òò¶øÓйØ×éÖ¯Òª×Ô¶¯½¨¸´·ì϶ÒÔÔ¤·À´ËÀ๥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://intel471.com/blog/shipping-companies-ransomware-credentials


Positive Technologies°ä²¼RootkitÑݱäÇ÷Ïò»ã±¨


Positive Technologies°ä²¼RootkitÑݱäÇ÷Ïò»ã±¨.png


Positive TechnologiesÔÚ11ÔÂ3ÈÕ°ä²¼ÁËRootkitµÄÑݱäÇ÷ÏòºÍµ±Ç°ÍþвµÄ·ÖÎö»ã±¨¡£×êÑÐÈËÔ±·ÖÎöÁ˽ü10Äê×î³ÛÃûµÄ16¸örootkit¼Ò×å £¬·¢ÏÔìäÖеÄ44%ÓÃÓÚ¹¥»÷µ±¾Ö»ú¹¹ £¬ 77%±»ÓÃÓÚÍøÂç¼äµý»î¶¯¡£´Ë±í £¬rootkitºÜÄÑ¿ª·¢ £¬±ØÒªÆÆ·ÑºÃ¶à¹¦·òºÍ½ðÇ® £¬Òò¶ø´óÎÞÊý»ùÓÚrootkitµÄ¹¥»÷¶¼ÓëAPT×éÖ¯ÓйØ¡£ËùÓеÄrootkitÖÐ38%ÊôÓÚÄÚºËģʽ £¬31%ÊÇÓû§Ä£Ê½ £¬31%ÊÇ×éºÏÀàÐÍ £¬ÇÒ´ó²¿ÃÅÕë¶ÔWindowsϵͳ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.ptsecurity.com/ww-en/analytics/rootkits-evolution-and-detection-methods/