Kaspersky·¢ÏÖAPT41ÀûÓÃMoonBounceµÄ¹¥»÷»î¶¯

°ä²¼¹¦·ò 2022-01-24

Kaspersky·¢ÏÖAPT41ÀûÓÃMoonBounceµÄ¹¥»÷»î¶¯


1ÔÂ20ÈÕ£¬Kaspersky°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þMoonBounceµÄ·ÖÎö»ã±¨¡£×êÑÐÈËÔ±³Æ£¬MoonBounceÊÇÆù½ñΪֹÔÚÒ°±í·¢ÏÖµÄ×îÏȽøµÄUEFI¹Ì¼þ¶ñÒâÈí¼þ£¬ÓëºÚ¿Í×éÖ¯APT41£¨Ò²³ÆÎªWinnti£©ÓйØ¡£MoonBounceÖ²ÈëÔÚÖ÷°åµÄSPIÉÁ´æÉÏ£¬Òò¶ø¼´±ã¸ü»»Ó²ÅÌÒ²ÎÞ·¨½«Æä¸ù³ý¡£ÕâÊǽüÆÚ·¢ÏֵĵÚÈý¸öUEFI¶ñÒâÈí¼þ£¬Ö®Ç°Á½¸öΪFinFisherºÍESPecter¡£Kaspersky°µÊ¾Õâ´Î¹¥»÷ÓµÓи߶ÈÕë¶ÔÐÔ£¬Ä³¸ö½ÚÔì׿¸¼ÒÔËÊä¼¼ÊõÓÐ¹ØÆóÒµµÄ×éÖ¯ÒѳÉΪ¹¥»÷Ö¸±ê¡£


https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/


ContiÍÅ»ïÐû³Æ¶ÔÓ¡¶ÈÄáÎ÷ÑÇÑëÐеÄÀÕË÷¹¥»÷ÕÆ¹Ü


¾ÝýÌå1ÔÂ20ÈÕ±¨Â·£¬Ó¡¶ÈÄáÎ÷ÑÇÒøÐУ¨BI£©ÈÏ¿ÉÆäÔâµ½ÀÕË÷¹¥»÷¡£¸ÃÐн²»°È˰µÊ¾£¬¹¥»÷²úÉúÔÚÉϸöÔ£¬¹¥»÷ÕßÇÔÈ¡Á˲¿ÃÅÔ±¹¤µÄÐÅÏ¢£¬²¢ÔÚÊ®¼¸¸öϵͳÉÏ×°ÖÃÁËÀÕË÷Èí¼þ£¬µ«ÆäÔËÓª²¢Î´Êܵ½Ó°Ïì¡£ContiÍÅ»ïÐû³Æ¶Ô´ËÊÂÕÆ¹Ü£¬ÈôÊÇÓ¡ÄáÒøÐв»Ö§¸¶Êê½ð£¬ËûÃǽ«¹«¿ª¸ÃÒøÐÐ13.88 GBµÄÎļþ¡£Ç°²»¾Ã£¬Conti»¹¹¥»÷Á˰®¶ûÀ¼DoH¡¢HSE£¬ºÍÓªÏú¹«Ë¾RR Donnelly¡£


https://www.bleepingcomputer.com/news/security/indonesias-central-bank-confirms-ransomware-attack-conti-leaks-data/


×êÑÐÈËÔ±³ÆÊýÊ®¸öWordPressÖ÷ÌâºÍ²å¼þÒѱ»Ö²ÈëºóÃÅ


JetPackÔÚ1ÔÂ18ÈÕ°ä²¼»ã±¨£¬³ÆÒÑÔÚÊýÊ®¸öWordPressÖ÷ÌâºÍ²å¼þÖз¢ÏÖºóÃÅ¡£×êÑÐÈËÔ±³Æ£¬¹¥»÷ÕßÒÑÔÚAccessPress ThemesµÄ40¸öÖ÷ÌâºÍ53¸ö²å¼þÖÐÖ²ÈëºóÃÅ¡£¾­¹ýµ÷²éµÃÖª£¬AccessPress ThemesÓÚ2021Äê9ÔÂÉϰëÔÂÔâµ½¹¥»÷£¬ÆäÊ±ÍøÕ¾ÉϵÄÀ©´ó·¨Ê½±»×¢ÈëÁ˺óÃÅ¡£ÊÜϰȾµÄÀ©´ó·¨Ê½Ô̺¬Ò»¸öwebshell dropper£¬Ê¹¹¥»÷ÕßÄܹ»ÆëÈ«½Ó¼ûÖ¸±êÍøÕ¾£¬¸Ã·ì϶׷×ÙΪCVE-2021-24867¡£


https://thehackernews.com/2022/01/hackers-planted-secret-backdoor-in.html



ÀûÓÃCWPµÄÎļþÔ̺¬ºÍËÁÒâдÈë·ì϶¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ


ýÌå1ÔÂ22ÈÕ±¨Â·£¬Control Web PanelÖдæÔÚ2¸öÑϳÁµÄ·ì϶¡£Control Web Panel£¨ÒÔǰµÄCentOS Web Panel£©ÊÇÒ»¸ö¿ªÔ´µÄLinux½ÚÔìÃæ°åÈí¼þ£¬ÓÃÓÚ²¿ÊðWebÍйܻ·¾³¡£µÚÒ»¸öÊÇÎļþÔ̺¬·ì϶£¨CVE-2021-45467£©£¬¹¥»÷ÕßÖ»ÐèÅú¸ÄincludeÓï¾ä¾ÍÄܹ»Ô¶³Ì×¢Èë¶ñÒâ´úÂë»òʵÏÖ´úÂëÖ´ÐС£µÚ¶þ¸öΪËÁÒâÎļþдÈë·ì϶£¨CVE-2021-45466£©£¬½áºÏÀûÓÃÕâÁ½¸ö·ì϶Äܹ»ÔÚÒ×Êܹ¥»÷µÄLinux·þÎñÆ÷ÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐС£


https://securityaffairs.co/wordpress/127058/hacking/control-web-panel-flaws.html


MoleratsÍÅ»ïÀûÓöà¸öÔÆ·þÎñ¶ÔÖж«µØÓò½øÐмäµý¹¥»÷


¾ÝýÌå1ÔÂ22ÈÕ±¨Â·£¬°²È«¹«Ë¾Zscaler·¢ÏÖMoleratsÍÅ»ïÕë¶ÔÖж«µØÓòµÄ¼äµý»î¶¯¡£¾ÝϤ£¬¹¥»÷´Ó2021Äê7Ô¾ÍÒÑÆðÍ·£¬¹¥»÷ÕßÀûÓúϷ¨µÄÔÆ·þÎñ£¨ÈçGoogle DriveºÍDropbox£©ÍйܶñÒâÈí¼þpayload£¬´ÓÖж«µØÓòµÄÖ¸±êÖÐÇÔÈ¡Êý¾Ý¡£Õâ´Î»î¶¯ÀûÓÃÓëÒÔÉ«ÁкͰÍÀÕ˹̹ì¶ÜÓйصĵö¶ü£¬ÔÚÖ¸±êϵͳÉÏ×°ÖÃ.NETºóÃÅ£¬ÖØÒªÖ¸±êÔ̺¬°ÍÀÕË¹Ì¹ÒøÐÐÒµÔ±¹¤¡¢°ÍÀÕ˹̹Õþµ³³ÉÔ±£¬ÒÔ¼°ÍÁ¶úÆä¼ÇÕߵȡ£


https://thehackernews.com/2022/01/molerats-hackers-hiding-new-espionage.html


×ÖÄ»ÍøÕ¾OpenSubtitles½ü700ÍòÓû§µÄÐÅϢй¶


¾Ý1ÔÂ23ÈÕ±¨Â·£¬×ÖÄ»ÍøÕ¾OpenSubtitlesÔâµ½¹¥»÷£¬6783158¸öÓû§µÄÐÅÏ¢ÒѾ­Ð¹Â¶¡£2021Äê8Ô£¬ÍøÕ¾ÖÎÀíÔ±ÊÕµ½Êê½ð֪ͨºó²ÅÒâʶµ½ÆäÒÑÔâµ½¹¥»÷¡£¹¥»÷Õß»¹°µÊ¾»áÌṩ֧³ÖÒÔ½¨¸´ÍøÕ¾Öеķì϶£¬µ«ÔÚÖ§¸¶Êê½ðºó¹¥»÷Õß´ÓδԮÊÖËûÃǼӹÌÍøÕ¾£¬²¢ÔÚ1ÔÂ11ÈÕ¹«¿ªÁ˱»µÁÊý¾Ý¡£¾ÝϤ£¬ºÚ¿Íͨ¹ýSQL×¢Èë¹¥»÷½Ó¼ûÁËÍøÕ¾µÄÊý¾Ý¿â£¬ÇÔÈ¡ÁËÓû§Óʼþ¡¢IPµØÖ·¡¢Óû§Ãû¡¢µØµã¹ú¶ÈºÍÃÜÂëµÈÐÅÏ¢¡£


https://securityaffairs.co/wordpress/127092/data-breach/opensubtitles-data-breach.html



°²È«¹¤¾ß


Narthex


ÊÇÒ»¸öÄ£¿é»¯ºÍ×îÓ×µÄ×ÖµäÌìÉúÆ÷£¬ÓÃÓÚÓà C ºÍ Shell ±àдµÄ Unix ºÍÀà Unix ²Ù×÷ϵͳ¡£


https://github.com/MichaelDim02/Narthex


Iptable_Evil 


IptablesµÄºóÃÅ£¬Ê¹¶ñÒâÊý¾Ý°üͨ¹ýiptables£¬ÎÞÂÛ·À»ðǽ¹æ¶¨ÈôºÎ¡£


https://github.com/FlamingSpork/iptable_evil



iMonitor


ÊÇÒ»¿î»ùÓÚiMonitorSDKµÄ¶ËµãÐÐΪ¼à¿Ø·ÖÎöÈí¼þ¡£


https://github.com/wecooperate/iMonitor/releases



°²È«·ÖÎö


΢Èí½¨¸´ÁË Windows 10 µÄ Outlook ËÑË÷ÎÊÌâ


΢Èí½¨¸´ÁË×°ÖÃ2021 Äê 11 Ô°䲼µÄ Windows 10 °²È«¸üкóµ¼Ö Outlook Óû§³öÏÖËÑË÷ÎÊÌâµÄÎÊÌâ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-outlook-search-issues-for-windows-10-users/


WordPress²å¼þ´æÔÚ·ì϶


WP HTML MailÖдæÔÚÒ»¸öÑϳÁµÄ¿çÕ¾µã¾ç±¾(XSS)·ì϶£¬Ó°Ï쳬¹ý20,000¸öWordPressÍøÕ¾¡£


https://threatpost.com/wordpress-insecure-plugin-rest-api/177866/