Mandiant·¢ÏÖUNC2891ÀûÓÃеÄCAKETAP¹¥»÷ATMÍøÂç

°ä²¼¹¦·ò 2022-03-22

Mandiant·¢ÏÖUNC2891ÀûÓÃеÄCAKETAP¹¥»÷ATMÍøÂç


3ÔÂ16ÈÕ£¬Mandiant°ä²¼Á˹ØÓÚUNC2891ÍŻ﹥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£ÔÚÕâ´Î»î¶¯ÖУ¬¹¥»÷ÕßʹÓÃÁËÃûΪCAKETAPµÄÐÂUnix rootkit£¬ÖØÒªÕë¶ÔÔËÐÐOracle Solaris²Ù×÷ϵͳµÄ·þÎñÆ÷¡£CaketapÄܹ»°µ²ØÍøÂçÏνӡ¢¹ý³ÌºÍÎļþ£¬Æä×îÖÕÖ¸±êÊÇ´ÓÖ¸±êATMÖнػñÒøÐп¨ºÍPINÑéÖ¤Êý¾Ý£¬¶øºóʹÓÃÕâЩµÁÊý¾Ý½øÐÐڲƭÂòÂô¡£´Ë±í£¬¹¥»÷»î¶¯»¹Ê¹ÓÃÁË2¸öÃûΪSLAPSTICKºÍTINYSHELLµÄºóÃÅ£¬ËüÃǶ¼ÓëUNC1945ÓйØ¡£


https://www.mandiant.com/resources/unc2891-overview


ʯÓ͹Ü·¹«Ë¾TransneftÑз¢²¿ÃÅOmega 79GBÊý¾Ýй¶


¾ÝýÌå3ÔÂ19ÈÕ±¨Â·£¬AnonymousÐû³ÆÒÑÈëÇÖÁËTransneftµÄÄÚ²¿Ñз¢²¿ÃÅOmega¡£TransneftÊÇÊÀ½çÉÏ×î´óµÄʯÓ͹Ü·¹«Ë¾£¬×ܲ¿Î»ÓÚĪ˹¿Æ¡£3ÔÂ17ÈÕ£¬DDoSecrets³ÆÆäÊÕµ½ÁËOmega¸ß´ï79GBµÄµç×ÓÓʼþ¡£Õâ´Îй¶µÄÊý¾Ý²»½öÔ̺¬µç×ÓÓʼþÐÅÏ¢£¬»¹Ô̺¬·¢Æ±ºÍ²úÆ·ÔËÊä¾ßÌåÐÅÏ¢£¬ÒÔ¼°ÏÔʾ·þÎñÆ÷»ú¼ÜºÍÆäËüÉ豸ÅäÖõÄͼÏñÎļþ¡£²»¾Ãǰ£¬Anonymous»¹ÈëÇÖÁ˶íÂÞ˹µÄýÌåÉó²é»ú¹¹Roskomnadzor¡£


https://www.hackread.com/anonymous-leak-79gb-russia-oil-pipeline-email-data/


N4ughtysecTUÐû³ÆÒÑÇÔÈ¡TransUnion·ÇÖÞ·Ö²¿4TBµÄÊý¾Ý


 Ã½Ìå3ÔÂ18ÈÕ±¨Â·£¬TransUnion°ä²¼ÉêÃ÷³ÆÎ»ÓÚÄϷǵķþÎñÆ÷Ôâµ½ÁËδ¾­ÊÚȨµÄ½Ó¼û¡£°ÍÎ÷ºÚ¿ÍÍÅ»ïN4ughtysecTUÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬²¢ÒÑÔÚ¹¥»÷ÆÚ¼äÏÂÔØÁË4TBµÄÊý¾Ý¡£¹¥»÷Õß°µÊ¾ËûÃÇͨ¹ý±©Á¦¹¥»÷ÈëÇÖÁËÒ»¸ö°²È«ÐԽϲîµÄTransUnion SFTP·þÎñÆ÷£¬²¢ÇÔÈ¡ÁËԼĪ5400Íò¿Í»§µÄÊý¾Ý¡£¾ÝϤ£¬¹¥»÷Õß×îÖÕÆÆ½âµÄÃÜÂëÊÇ¡°Password¡±£¬ÕâÒѱ»ÁÐΪ2021ÄêµÚÎå´ó×î³£ÓõÄÃÜÂë¡£Õâ´Î¹¥»÷µÄÀÕË÷½ð¶îΪ15000000ÃÀÔª£¬µ«TransUnionÒÑÖ¸³öËü²»»áÏòºÚ¿Í¸¶¿î¡£


https://www.bleepingcomputer.com/news/security/hackers-claim-to-breach-transunion-south-africa-with-password-password/


FBI°ä²¼AvosLocker¹¥ÃÀ¹ú¶à¸ö¹Ø¼ü»ù´¡ÉèÊ©µÄ¹«¸æ


3ÔÂ17ÈÕ£¬ÃÀ¹úFBI°ä²¼¹ØÓÚÀÕË÷ÍÅ»ïAvosLockerµÄÍøÂ簲ȫÕ÷ѯ¡£FBI³Æ£¬AvosLockerÊÇÒ»¸ö»ùÓÚRaaSµÄÍŻÕë¶ÔÃÀ¹ú¶à¸ö¹Ø¼ü»ù´¡ÉèÊ©µÄ×éÖ¯£¬Ô̺¬µ«²»ÏÞÓÚ½ðÈÚ·þÎñÐÐÒµ¡¢Ôì×÷ÐÐÒµºÍµ±²¿ÃÅÃŵÈ¡£¸Ã¹«¸æ¹«¿ªÁËÓйشËRaaSÍÅ»ïµÄ¼¼Êõϸ½Ú£¬»¹Îª×éÖ¯ÌṩÁË¿ÉÓÃÓÚ¼ì²âºÍ×èÖ¹´ËÀ๥»÷µÄÈëÇÖÖ¸±ê(IOC)¡£ID-RansomwareÊý¾ÝÏÔʾ£¬AvosLockerÔÚ2021Äê11ÔÂÖÁ2021Äê12ÔÂÆÚ¼äµÄ»î¶¯¼¤Ôö£¬ÇÒĿǰÈÔÔÚ³ÖÐø¡£


https://www.bleepingcomputer.com/news/security/fbi-avoslocker-ransomware-targets-us-critical-infrastructure/


Google°ä²¼¹ØÓÚConti³õʼ½Ó¼û´úÀíÕ½ÊõµÄ·ÖÎö»ã±¨


3ÔÂ17ÈÕ£¬GoogleÍþв·ÖÎöÓ××é(TAG)°ä²¼Á˹ØÓÚConti³õʼ½Ó¼û´úÀíÕ½ÊõµÄ·ÖÎö»ã±¨¡£TAG·¢ÏÖеÄEXOTIC LILYÓëContiºÍDiavolµÈÀÕË÷ÍÅ»ïÓйØ£¬ÆäÀûÓÃMicrosoft Windows MSHTMLƽ̨Öзì϶CVE-2021-40444½øÐд¹µö¹¥»÷£¬ÔÚ¶¥·åÆÚÿÌìÏòÈ«Çò¶à´ï650¸öÖ¸±ê×éÖ¯·¢Ëͳ¬¹ý5000·âÓʼþ¡£¹ÌÈ»EXOTIC LILYµÄ»î¶¯ÓëContiµÄÒµÎñ³Áµþ£¬µ«GoogleÒÔΪ£¬ËüÊÇÒ»¸öÆëȫרһÓÚ³ÉÁ¢³õÊ¼ÍøÂç½Ó¼ûµÄ¶ÀÁ¢¹¥»÷ÍŻ


https://blog.google/threat-analysis-group/exposing-initial-access-broker-ties-conti/


Western Digital½¨¸´ÆäEdgeRoverÖеÄĿ¼±éÀú·ì϶


3ÔÂ18ÈÕ£¬Western Digital°ä²¼°²È«¸üУ¬½¨¸´Æä×ÀÃæÀûÓ÷¨Ê½EdgeRoverÖеÄĿ¼±éÀú·ì϶£¨CVE-2022-22998£©¡£EdgeRoverÊǼ¯ÖÐʽÄÚÈÝÖÎÀí½â¾ö¹æ»®£¬½«¶à¸öÊý×Ö´æ´¢É豸ͳһÔÚÒ»¸öÖÎÀí½çÃæÏ¡£¸Ã·ì϶CVSSÆÀ·ÖΪ9.1£¬¿É±»¹¥»÷ÕßÓÃÀ´½øÐб¾µØÈ¨ÏÞÌáÉýºÍɳºÐÌÓÒÝ£¬¿ÉÄܻᵼÖÂÐÅϢй¶»ò»Ø¾ø·þÎñ(DoS)¹¥»÷¡£Western DigitalµÄ²¼¸æ²¢Î´ÌṩÓйظ÷ì϶µÄ¾ßÌåÐÅÏ¢£¬Òò¶ø»¹²»Ã÷ÏÔÕâÊÇÒ»¸öÔÊÐí±¾µØÈ¨ÏÞÌáÉýµÄDLL½Ù³Ö·ì϶£¬»¹ÊÇÒ»¸öÔÊÐí½Ó¼û·ÇÌØÈ¨Êý¾ÝµØÎ»µÄ·ì϶¡£


https://www.bleepingcomputer.com/news/security/western-digital-app-bug-gives-elevated-privileges-in-windows-macos/



°²È«¹¤¾ß


EvilSelenium


ÊÇÒ»¸ö½« Selenium±øÆ÷»¯ÒÔÀÄÓà Chrome µÄÐÂÏîÄ¿¡£


https://github.com/mrd0x/EvilSelenium/


wholeaked


ÊÇÒ»¸öÎļþ¹²Ïí¹¤¾ß£¬¿ÉÈÃÄúÔÚ²úÉúй©ʹØÒµ½ÕƹÜÈË¡£


https://github.com/utkusen/wholeaked


WSVuls


ºÅÁîÐй¤¾ß£¬×¨Îª¿ª·¢/²âÊÔÈËԱͨ¹ýµ¥¸öºÅÁî²âÊÔ·ì϶ºÍ·ÖÎöÍøÕ¾¶øÉè¼Æ¡£


https://github.com/anouarbensaad/wsvuls


AWS CloudSaga


ÓÃÓÚÔÚ Amazon Web Services (AWS) »·¾³ÖвâÊÔ°²È«½ÚÔìºÍ¾¯±¨¡£


https://github.com/awslabs/aws-cloudsaga#running-the-code



°²È«·ÖÎö


Windows 11 Ϊ USB Çý¶¯Æ÷Ôö³¤ÁË BitLocker ÅųýÕ½Êõ


https://www.bleepingcomputer.com/news/microsoft/windows-11-adds-a-bitlocker-exclusion-policy-for-usb-drives/


΢ÈíÌáÐÑ Internet Explorer ÔÚ 6 Ô¼´½«²Ã¼õ


https://www.bleepingcomputer.com/news/microsoft/microsoft-reminds-of-internet-explorers-looming-demise-in-june/


NIST ΪÔì×÷Ḛ́䲼 ICS ÍøÂ簲ȫָÄÏ


https://www.securityweek.com/nist-releases-ics-cybersecurity-guidance-manufacturers


д¹µö¹¤¾ß°ü¿ÉÓÃÀ´´´½¨ÐéαµÄ Chrome ä¯ÀÀÆ÷´°¿Ú


https://www.bleepingcomputer.com/news/security/new-phishing-toolkit-lets-anyone-create-fake-chrome-browser-windows/


CISA¡¢FBI ÖÒ¸æ¶Ô SATCOM ÍøÂ繩¸øÉ̵Ĺ¥»÷


https://www.hackread.com/targeting-satellite-cisa-fbi-warns-satcom-providers/


¶à¼ÒÆû³µÔì×÷ÉÌϰȾ Emotet


https://www.darkreading.com/attacks-breaches/multiple-automakers-infected-with-emotet