Symantec³ÆBillbug¹¥»÷ÑÇÖÞµØÇøµÄÊý×ÖÖ¤Êé½ÒÏþ»ú¹¹

Ðû²¼Ê±¼ä 2022-11-17
1¡¢Symantec³ÆBillbug¹¥»÷ÑÇÖÞµØÇøµÄÊý×ÖÖ¤Êé½ÒÏþ»ú¹¹

SymantecÔÚ11ÔÂ15ÈÕ³ÆÆä·¢Ã÷Billbug¹¥»÷ÁËÑÇÖ޵Ķà¸öÕþ¸®»ú¹¹£¬ÆäÖаüÀ¨Ò»¸öÊý×ÖÖ¤Êé½ÒÏþ»ú¹¹¡£¸ÃÍÅ»ï×Ô2009ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬Symantec 2019ÄêËê¼µÄÔ˶¯ÖÐÏêϸÏÈÈÝÁ˸ÃÍÅ»ïÔõÑùʹÓúóÃÅHannotogºÍSagerunexµÄ£¬ÕâЩ¹¤¾ßÔÚ×î½üµÄÔ˶¯ÖÐÒ²ÓзºÆð¡£´Ë´ÎÔ˶¯ÖÁÉÙ´Ó3Ô¾ÍÒÑ×îÏÈ£¬Óм£ÏóÅú×¢¹¥»÷ÕßÕýÔÚʹÓÃÃæÏò¹«ÖÚµÄÓ¦ÓóÌÐòÀ´»ñµÃ¶ÔÄ¿µÄÍøÂçµÄ³õʼ»á¼ûȨÏÞ¡£Óë֮ǰµÄÔ˶¯Ò»Ñù£¬¹¥»÷ÕßҲʹÓÃÁ˶àÖÖÁ½Óù¤¾ß¼°×Ô½ç˵¶ñÒâÈí¼þ£¬ÈçAdFind¡¢Directory¡¢Winmail¡¢WinRAR¡¢PingºÍTracertµÈ¡£

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments-cert-authority

2¡¢VaronisÅû¶Zendesk ExploreÖÐSQL×¢ÈëµÈÎó²îµÄϸ½Ú

VaronisÔÚ11ÔÂ15ÈÕÅû¶ÁËZendesk ExploreÖÐÁ½¸öÎó²îµÄϸ½Ú¡£ÆäÖÐÒ»¸öÊÇSQL×¢ÈëÎó²î£¬¸ÃÎó²îÉæ¼°ÆäGraphQL APIÖеÄSQL×¢È룬¿É±»ÓÃÀ´Ð¹Â¶×÷ΪÖÎÀíÔ±´æ´¢ÔÚÊý¾Ý¿âÖеÄËùÓÐÐÅÏ¢£¬°üÀ¨ÓʼþµØµã¡¢¹¤µ¥ÒÔ¼°ÓëʵʱÊðÀíµÄ¶Ô»°µÈ¡£ÁíÒ»¸öÎó²îÊÇÉæ¼°ÓëÅÌÎÊÖ´ÐÐAPIÏà¹ØµÄÂß¼­»á¼ûÎÊÌ⣬¸ÃAPI±»ÉèÖÃΪÔËÐÐÅÌÎÊ£¬¶ø²»¼ì²é¾ÙÐÐŲÓõÄÓû§ÊÇ·ñÓÐ×ã¹»µÄȨÏÞÕâÑù×ö¡£ÏÖÔÚ£¬ÕâЩÎó²îÒѱ»ÐÞ¸´¡£

https://securityaffairs.co/wordpress/138579/hacking/zendesk-explore-critical-flaws.html

3¡¢LazarusʹÓúóÃÅDTrack¹¥»÷Å·ÖÞºÍÀ­¶¡ÃÀÖÞµÄ×éÖ¯

¾Ý11ÔÂ15ÈÕ±¨µÀ£¬³¯ÏʺڿÍÍÅ»ïLazarusÕýÔÚʹÓÃа汾µÄDTrackºóÃÅÀ´¹¥»÷Å·ÖÞºÍÀ­¶¡ÃÀÖÞµÄ×éÖ¯¡£Ä¿µÄÐÐÒµ°üÀ¨Ñо¿ÖÐÐÄ¡¢Õþ²ß»ú¹¹¡¢»¯Ñ§Æ·ÖÆÔìÉÌ¡¢IT·þÎñÌṩÉÌ¡¢µçÐÅÌṩÉÌ¡¢¹«ÓÃÊÂÒµ·þÎñÌṩÉ̺ͽÌÓý¡£ÔÚеÄÔ˶¯ÖУ¬DTrackͨ³£Ê¹ÓÃÓëÕýµ±ÎļþÏà¹ØµÄÎļþÃû¾ÙÐзַ¢£¬ÈçÒ»¸öÑù±¾ÒÔ¡°NvContainer.exe¡±ÎªÃû·Ö·¢£¬ËüÓëÕýµ±µÄNVIDIAÎļþͬÃû¡£±ðµÄ£¬DTrackÈÔ¼ÌÐøÍ¨¹ýÇÔÈ¡µÄƾ֤ÈëÇÖÍøÂç»òʹÓÃÍøÉÏ̻¶µÄ·þÎñÆ÷À´¾ÙÐзַ¢¡£

https://securelist.com/dtrack-targeting-europe-latin-america/107798/

4¡¢Ñо¿ÍŶӷ¢Ã÷¿ÉÓ°Ï캽ÌìÆ÷ºÍ·É»úµÄ¹¥»÷·½·¨PCspooF

ýÌå11ÔÂ15ÈÕ±¨µÀ£¬Ñо¿ÍŶӷ¢Ã÷ÁËÒ»ÖÖÕë¶Ôʱ¼ä´¥·¢ÒÔÌ«Íø(TTE)µÄÐÂÐ͹¥»÷ÒªÁì¡£TTEÊôÓÚ»ìÏýÒªº¦ÐÔÍøÂçµÄÍøÂçÊÖÒÕÖ®Ò»£¬ÆäÖоßÓвî±ðʱÐòºÍÈÝ´íÒªÇóµÄÁ÷Á¿¹²´æÓÚͳһÎïÀíÍøÂçÖС£¸ÃÊÖÒÕÓÃÓÚÇå¾²»ù´¡ÉèÊ©£¬¿Éµ¼ÖÂΪº½ÌìÆ÷ºÍ·É»úÌṩ¶¯Á¦µÄϵͳ·ºÆð¹ÊÕÏ¡£ÕâÊÇʹÓöñÒâ×°±¸Í¨¹ýÒÔÌ«ÍøµçÀ½«µç´Å×ÌÈÅ(EMI)×¢ÈëTTE½»Á÷»úÀ´ÊµÏֵģ¬¿ÉÓÐÓõØÓÕʹ½»Á÷»ú·¢ËÍ¿´ËÆÕæÊµµÄͬ²½ÐÂÎŲ¢ÈÃËüÃDZ»ÆäËûTTE×°±¸½ÓÊÜ¡£×÷Ϊ»º½â²½·¥£¬Ñо¿Ö°Ô±½¨ÒéʹÓùâñîºÏÆ÷»òÀËÓ¿±£»¤Æ÷À´×èÖ¹µç´Å×ÌÈÅ¡£

https://thehackernews.com/2022/11/pcspoof-new-vulnerability-affects.html

5¡¢ÒÁÀÊÏà¹ØºÚ¿ÍʹÓÃLog4ShellÎó²îÈëÇÖÃÀ¹úÕþ¸®»ú¹¹

11ÔÂ16ÈÕ£¬FBIºÍCISAÍŽáÐû²¼ÁËÒ»·Ýͨ¸æ£¬³ÆÓëÒÁÀÊÏà¹ØµÄºÚ¿ÍÈëÇÖÁËÒ»¸öÕþ¸®»ú¹¹²¢×°ÖÃÁËXMRig¿ó¹¤¶ñÒâÈí¼þ¡£Í¨¸æ³Æ£¬´Ó2022Äê6ÔÂÖÐÑ®µ½7Ô£¬CISAÔÚÁª°îÃñÓÃÐÐÕþ²¿·Ö(FCEB)×éÖ¯ÖÐÊӲ쵽ÁË¿ÉÒɵÄAPTÔ˶¯¡£¹¥»÷ÕßʹÓÃδÐÞ¸´µÄVMware Horizon·þÎñÆ÷ÖеÄLog4ShellÎó²î£¬×°ÖÃXMRig¿ó¹¤Èí¼þ£¬ºáÏòÒÆ¶¯µ½Óò¿ØÖÆÆ÷(DC)£¬ÇÔȡƾ֤£¬È»ºóÖ²ÈëNgrok·´ÏòÊðÀíÀ´ÔÚ¶à¸ö×°±¸Éϼá³Ö³¤ÆÚÐÔ¡£CISA ºÍ FBI Ðû²¼´ËCSAÌṩºÚ¿ÍµÄTTPºÍIOC£¬ÒÔ×ÊÖú×éÖ¯¼ì²âºÍ·ÀÓùÏà¹ØµÄ¹¥»÷¡£

https://www.cisa.gov/uscert/ncas/alerts/aa22-320a

6¡¢KasperskyÐû²¼¹ØÓÚ2023ÄêAPT¹¥»÷Ô˶¯µÄÕ¹Íû±¨¸æ

KasperskyÔÚ11ÔÂ14ÈÕÐû²¼Á˹ØÓÚ2023ÄêAPT¹¥»÷Ô˶¯µÄÕ¹Íû±¨¸æ¡£±¨¸æÕ¹ÍûÔÚ2023Ä꣬½«·ºÆð´ó×򵀮ÆËðÐÔÍøÂç¹¥»÷£¬Ó°ÏìÕþ¸®²¿·ÖºÍÒªº¦ÐÐÒµ£»Óʼþ·þÎñÆ÷½«³ÉΪÖ÷ҪĿµÄ£¬ºÜ¿ÉÄÜËùÓÐÖ÷Òªµç×ÓÓʼþÈí¼þ¶¼·ºÆð0-day£»Ò»Ð©¾ßÓÐÓ°ÏìÁ¦µÄ²¡¶¾Ã¿6-7Ä걬·¢Ò»´Î£¬¿ÉÄÜ·ºÆðÏÂÒ»¸öWannaCry£»APT¹¥»÷ÍŻォĿµÄתÏòÎÀÐÇÊÖÒÕ¡¢Éú²úÉ̺ÍÔËÓªÉÌ£»¸ü¶àAPT×éÖ¯½«´ÓCobaltStrike×ªÒÆµ½ÆäËüÌæ»»¼Æ»®µÈ¡£

https://securelist.com/advanced-threat-predictions-for-2023/107939/