TA544ÀûÓÃWikiLoaderÕë¶ÔÒâ´óÀûµÄÆóÒµ·Ö·¢Ursnif

°ä²¼¹¦·ò 2023-08-02

1¡¢TA544ÀûÓÃWikiLoaderÕë¶ÔÒâ´óÀûµÄÆóÒµ·Ö·¢Ursnif


ProofpointÔÚ7ÔÂ31ÈÕÅû¶ÁËÀûÓÃжñÒâÈí¼þWikiLoaderÕë¶ÔÒâ´óÀûÆóÒµµÄ¹¥»÷»î¶¯¡£WikiLoaderÊÇÒ»¸ö¸´ÔÓµÄÏÂÔØ·¨Ê½ £¬ÓÉÓÚËü»áÏòWikipedia·¢³öÒªÇ󲢲鳭ÏìÓ¦ÄÚÈÝÖÐÊÇ·ñÔ̺¬×Ö·û´®¡°The Free¡±¶øµÃÃû¡£ProofpointÓÚ2022Äê12ÔÂ27ÈÕ³õ´ÎÔÚÒ°±í¼ì²âµ½¸Ã¶ñÒâÈí¼þ £¬ÓÉTA544´«²¼¡£×êÑÐÈËÔ±³Æ £¬ÖÁÉÙÓÐ8¸ö»î¶¯ÔÚ·Ö·¢WikiLoader £¬À´×ÔTA544ºÍTA551 £¬¾ùÕë¶ÔÒâ´óÀûµÄ×éÖ¯¡£´Ë±í £¬¹ÌÈ»´óÎÞÊý¹¥»÷ÕßÒѲ»ÔÙʹÓÃÆôÓúêµÄÎĵ·´´«²¼¶ñÒâÈí¼þ £¬µ«TA544ÈÔÔÚ¹¥»÷Á´ÖÐʹÓÃËüÃÇ £¬Ô̺¬´«²¼WikiLoader¡£


https://www.proofpoint.com/us/blog/threat-insight/out-sandbox-wikiloader-digs-sophisticated-evasion


2¡¢ÃÀ¹úÒÂÊι«Ë¾Hot TopicÔ⵽ײ¿â¹¥»÷й¶¿Í»§µÄÐÅÏ¢


¾ÝýÌå8ÔÂ1ÈÕ±¨Â· £¬ÃÀ¹úÒÂÊμ°ÊÚȨÒôÀÖÁãÊÛÁ¬ËøµêHot Topicй©ÆäÔâµ½Á˶àÆð¹¥»÷ÊÂÎñ £¬µ¼Ö¿ͻ§µÄÃô¸ÐÐÅϢй¶¡£¸Ã¹«Ë¾ÔÚÃÀ¹úÕ¼ÓÐ675¼ÒÉ̵ê £¬ÒÔ¼°Ã¿Ô½ü1000Íò½Ó¼ûÁ¿µÄÔÚÏßÉ̵ê¡£¸Ã¹«Ë¾Ú¹ÊÍ˵ £¬ºÚ¿ÍʹÓÃÇÔÈ¡µÄÕÊ»§Í´´¦ÂŴνӼûÁËRewardsƽ̨ £¬¿ÉÄÜ»ñµÃÁ˿ͻ§µÄÊý¾Ý¡£¾­µ÷²é £¬¹¥»÷ÕßÓÚ2023Äê2ÔÂ7ÈÕ¡¢3ÔÂ11ÈÕ¡¢5ÔÂ19ÈÕÖÁ21ÈÕ¡¢5ÔÂ27ÈÕÖÁ28ÈÕºÍ6ÔÂ18ÈÕÖÁ21ÈÕ £¬Ê¹ÓÃÓÐЧÕÊ»§Í´´¦¶ÔÍøÕ¾ºÍÒÆ¶¯ÀûÓÃÖ´ÐÐÁË×Ô¶¯¹¥»÷¡£¸Ã¹«Ë¾°µÊ¾ £¬Hot Topic²»ÊÇй¶ƾ֤µÄÆðÔ´ £¬µ«Ò²ÎÞ·¨ÕÒµ½ÆðÔ´¡£


https://www.bleepingcomputer.com/news/security/retail-chain-hot-topic-discloses-wave-of-credential-stuffing-attacks/


3¡¢Henry Ford HealthÔâ´¹µö¹¥»÷½ü17Íò»¼ÕßÐÅϢй¶


¾Ý7ÔÂ27ÈÕ±¨Â· £¬ÃÀ¹úµÄѧÊõÒ½ÁÆ»úHenry Ford Health³ÆÆä3ÃûÔ±¹¤Ôâµ½´¹µö¹¥»÷ £¬Ó°ÏìÁË168215¸ö»¼ÕßµÄÐÅÏ¢¡£¸Ã»ú¹¹ÔÚÉêÃ÷ÖаµÊ¾ £¬¹¥»÷ÊÂÎñ²úÉúÓÚ3ÔÂ30ÈÕ £¬¸Ã×éÖ¯Òѽ«±»Ó°ÏìµÄµç×ÓÓʼþÕÊ»§±£»¤ÆðÀ´²¢·¢Õ¹µ÷²é¡£5ÔÂ16 £¬È·¶¨»¼ÕߵĽ¡È«ÐÅÏ¢Ô̺¬ÔÚµç×ÓÓÊÏäÖÐ £¬²¢ÇÒ¿ÉÄÜÒѱ»¹¥»÷ÕßÇÔÈ¡ £¬Éæ¼°ÐÕÃû¡¢³¢ÊÔÊÒÁ˾֡¢ÊÖÊõÀàÐÍ¡¢Õï¶Ï¡¢µç»°ºÅÂë¡¢²¡ÀúºÅºÍÄÚ²¿¸ú×ٺŵÈÐÅÏ¢¡£¸Ã¹«Ë¾°µÊ¾ £¬ËûÃÇÔÚÖ´Ðжî±íµÄ°²È«´ëÊ© £¬²¢½«ÎªÔ±¹¤Ìṩ°²È«Åàѵ¡£


https://www.bankinfosecurity.com/phishing-scam-affects-nearly-170k-henry-ford-health-patients-a-22672 


4¡¢Cado·¢ÏÖ¿ÉÕë¶ÔRedis·þÎñÆ÷µÄP2PInfectÈ䳿бäÌå


7ÔÂ31ÈÕ £¬Cado·¢ÏÖÁËÒ»ÖÖÕë¶ÔRedisµÄÐÂÐͶñÒâÈí¼þ»î¶¯¡£¸Ã¶ñÒâÈí¼þ±»¿ª·¢Õß¶¨ÃûΪP2Pinfect £¬ÓÃRust¿ª·¢ £¬³äÈν©Ê¬ÍøÂç´úÀí¡£×êÑÐÈËÔ±·ÖÎöµÄÑù±¾Ô̺¬Ò»¸öǶÈëʽPEÎļþÒÔ¼°Ò»¸öELF¶þ½øÔìÎļþ £¬Õâ½²ÁËÈ»WindowsºÍLinuxÖ®¼äÓµÓÐ¿çÆ½Ì¨¼æÈÝÐÔ¡£Ëü»¹ÀûÓø´ÔìÖ°ÄÜÀ´¹¥»÷RedisÊý¾Ý´æ´¢µÄÊ·ý¡£´Ë±í £¬P2PinfectÊÔͼͨ¹ýCronδ¾­Éí·ÝÑéÖ¤µÄRCE»úÔì¹¥»÷RedisÖ÷»ú¡£¸Ã»î¶¯±³ºóµÄ¹¥»÷ÕßÉí·ÝÉв»Ã÷ÏÔ £¬P2PInfectµÄÖ÷ÕÅÒ²²»Ã÷ÏÔ¡£


https://www.cadosecurity.com/redis-p2pinfect/


5¡¢Minecraft mod·ì϶BleedingPipeÒѱ»´ó¹æÄ£ÀûÓÃ


ýÌå7ÔÂ31ÈÕ±¨Â·³Æ £¬ºÚ¿ÍÔÚÀûÓÃMinecraft modÖеÄRCE·ì϶BleedingPipeÔÚ·þÎñÆ÷ºÍ¿Í»§¶ËÖ´ÐжñÒâºÅÁî £¬´Ó¶ø½ÚÔìÉ豸¡£BleedingPipe·ì϶×î³õÓÚ2022Äê3Ô±»ÀûÓà £¬µ«ºÜ¿ì¾Í±»mod¿ª·¢Õß½¨¸´ÁË¡£È»¶øÔÚ7ÔÂÔçЩʱ³½ £¬ForgeÂÛ̳µÄһƪÌû×Ó³Æ £¬ÓÐÈËÀûÓÃδ֪RCEÀ´´ó¹æÄ£ÇÔÈ¡Íæ¼ÒµÄDiscordºÍSteam»á»°cookie¡£½øÒ»²½×êÑз¢ÏÖ £¬¶à¸öMinecraft modÖÐÒ²´æÔÚBleedingPipe·ì϶¡£¹¥»÷ÕßÔÚɨÃèÊܸ÷ì϶ӰÏìµÄMinecraft·þÎñÆ÷²¢Ö´Ðй¥»÷ £¬Òò¶ø½¨¸´·þÎñÆ÷ÉÏÒ×±»¹¥»÷µÄmodÖÁ¹Ø³ÁÒª¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-bleedingpipe-rce-to-target-minecraft-servers-players/


6¡¢Bahamutͨ¹ý¼ÙðµÄAndroidÀûÓÃSafeChatÇÔÊØÐÅÏ¢


7ÔÂ28ÈÕ £¬CYFIRMA³ÆÆä·¢ÏÖÁËÒ»¸ö¿ÉÒɵÄAndroid¶ñÒâÈí¼þ £¬¼Ù×°³ÉÐéαµÄ̸ÌìÀûÓÃSafeChat £¬ÇÔÈ¡ÊÖ»úµÄͨ»°¼Í¼¡¢¶ÌÐźÍGPSµØÎ»µÈÊý¾Ý¡£¸Ã¶ñÒâÈí¼þ±»ÒÉ»óÊÇCoverlmµÄ±äÖÖ £¬»áÇÔÈ¡Telegram¡¢Signal¡¢WhatsApp¡¢ViberºÍFacebook MessengerµÈͨѶÀûÓõÄÊý¾Ý¡£¸Ã»î¶¯ÓëÓ¡¶ÈºÚ¿ÍÍÅ»ïBahamutÓйØ £¬ÖØÒªÍ¨¹ýWhatsAppÉϵÄÓã²æÊ½´¹µöÐÂÎŽøÐÐ £¬ÖØÒªÕë¶ÔÄÏÑǵØÓò¡£´Ë±í £¬¸Ã»î¶¯ÓëÓ¡¶ÈµÄÁíÒ»¸öºÚ¿ÍÍÅ»ïDoNotµÄ»î¶¯ÓÐÀàËÆÖ®´¦¡£


https://www.cyfirma.com/outofband/apt-bahamut-targets-individuals-with-android-malware-using-spear-messaging/