Fortinet¼ì²âµ½Deep Panda·Ö·¢Fire ChiliµÄ»î¶¯
°ä²¼¹¦·ò 2022-04-06Fortinet¼ì²âµ½Deep Panda·Ö·¢Fire ChiliµÄ»î¶¯
3ÔÂ30ÈÕ£¬Fortinet°ä²¼»ã±¨³ÆÆä¼ì²âµ½APT×éÖ¯Deep PandaµÄ¹¥»÷»î¶¯¡£¸ÃÍÅ»ïÀûÓÃLog4Shell·ì϶¹¥»÷VMware Horizon·þÎñÆ÷£¬×îÖÕÖ¼ÔÚ×°ÖÃÒ»¸öÃûΪFire ChiliµÄÐÂÐÍrootkit¡£¸ÃrootkitʹÓÃFrostburn Studios£¨ÓÎÏ·¿ª·¢ÉÌ£©ºÍComodo£¨°²È«Èí¼þ£©µÄÖ¤Êé½øÐÐÊý×ÖÊðÃû£¬Èƹý°²È«¼ì²â¡£µ÷²éDeep Panda»î¶¯Ê±£¬Fortinet·¢ÏÔìäÓëWinntiÓгÁµþ¡£Õâ´Î»î¶¯ÖØÒªÕë¶Ô½ðÈÚ¡¢Ñ§Êõ¡¢»¯×±Æ·ºÍÓÎÀÀÐÐÒµ¡£
https://www.fortinet.com/blog/threat-research/deep-panda-log4shell-fire-chili-rootkits
Kaspersky³ÆLazarusÀûÓÃľÂí»¯DeFi Wallet·Ö·¢ºóÃÅ
KasperskyÔÚ3ÔÂ31ÈÕ°ä²¼»ã±¨³Æ£¬³¯ÏʺڿÍÍÅ»ïLazarusÔÚÀûÓÃľÂí»¯DeFiÀûÓ÷ַ¢ºóÃÅ¡£×êÑÐÈËÔ±½üÆÚ·¢ÏÖÒ»¸öľÂí»¯DeFi Wallet£¬±àÒëÈÕÆÚΪ2021Äê11Ô£¬Äܹ»ÔÚÖ¸±êϵͳÉÏ×°ÖÃÒ»¸öÖ°ÄÜÆëÈ«µÄºóÃÅ£¬¸ÃºóÃżÙ×°³ÉÁËGoogle Chromeä¯ÀÀÆ÷¡£Ä¿Ç°Éв»Ã÷ÏÔ¸ÃÀûÓõķַ¢²½Ö裬´§Ä¦¿ÉÄÜÊÇ´¹µöÓʼþ»òͨ¹ýÉ罻ýÌå¡£´Ë±í£¬¹¥»÷ÕßʹÓÃÁËλÓÚº«¹úµÄ·þÎñÆ÷ÓëºóÃŽøÐÐͨѶ¡£
https://securelist.com/lazarus-trojanized-defi-app/106195/
INKYÔÚ½üÆÚ·¢ÏÖÐÂÒ»ÂÖÀûÓÃCalendlyµÄ´¹µö¹¥»÷»î¶¯
¾ÝýÌå3ÔÂ31ÈÕ±¨Â·£¬INKY×êÑÐÍŶӷ¢ÏÖÀûÓÃCalendlyµÄ´¹µö»î¶¯¡£CalendlyÊÇÒ»¿îÊ¢ÐеÄÃâ·ÑÈÕÀúÀûÓ㬼¯³ÉÁËZoom£¬¿ÉÓÃÓÚÆÌÅÅ»áÒéºÍÔ¼»á¡£Õâ´Î»î¶¯Ê¼ÓÚ2Ôµף¬¹¥»÷Õßͨ¹ýCalendlyƽ̨ÌìÉú´¹µöÓʼþ¡£Ê×ÏÈÀûÓÃCalendlyÔö³¤×Ô½ç˵Á´½ÓµÄÖ°ÄܲåÈë¶ñÒâÁ´½Ó£¬¸ÃÁ´½ÓǶÈëÔڲ鿴Îĵµ°´¼üÖУ¬Óû§µã»÷ºó»á±»³Á¶¨Ïòµ½´¹µöÒ³Ãæ£¬×îÖÕÇÔȡָ±êµÄMicrosoftµÇ¼ʹ´¦¡£
https://www.bleepingcomputer.com/news/security/calendly-actively-abused-in-microsoft-credentials-phishing/
PaloAlto Networks¶Ô¿Í»§ÌṩµÄ¼¼ÊõÖ§³ÖÐÅÏ¢Òâ±íй¶
ýÌå3ÔÂ31ÈÕ±¨Â·£¬PaloAlto Networks(PAN) Ö§³ÖϵͳÖÐÅäÖÃÃýÎóµ¼Ö¿ͻ§µÄÃô¸ÐÐÅϢй¶¡£¸ÃÎÊÌâÓÉPANµÄÒ»¸ö¿Í»§ÔÚ±¾Ô·¢ÏÖ£¬Ëû³ÆÄܹ»¿´µ½Ô¼Äª1989¸ö²»ÊôÓÚËûÃǵÄ×éÖ¯µÄ¼¼ÊõÖ§³ÖÊÂÎñ¼Í¼£¬ÆäÖÐÔ̺¬ÓÃÓÚÅųýÃýÎóµÄ·À»ðǽÈÕÖ¾¡¢ÅäÖÃת´¢ºÍÍøÂ簲ȫ×é(NSG)²¼¾ÖµÈ¡£PAN°µÊ¾Ã»ÓÐÈκÎÊý¾Ý±»ÏÂÔØ£¬²¢°µÊ¾Õâ´Îй¶ÊÂÎñµÄÁìÓò½öÏÞÓÚһλ¿Í»§¡£¾ÝϤ£¬¸ÃÎÊÌâµÄ½¨¸´Ô¼Äª±ØÒª8Ì칦·ò¡£
https://www.bleepingcomputer.com/news/security/palo-alto-networks-error-exposed-customer-support-cases-attachments/
Aqua°ä²¼Õë¶ÔJupyter NotebookµÄÀÕË÷Èí¼þµÄ·ÖÎö»ã±¨
Aqua SecurityÓÚ3ÔÂ29ÈÕ°ä²¼ÁËÕë¶ÔJupyterµÄ»ùÓÚPythonµÄÀÕË÷Èí¼þµÄ·ÖÎö»ã±¨¡£Jupyter NotebookÊÇÊý¾ÝרҵÈËÔ±ÓÃÀ´´¦ÖÃÊý¾Ý¡¢±àдºÍÖ´ÐдúÂëÒÔ¼°¿ÉÊÓ»¯Á˾ֵĿªÔ´WebÀûÓ᣹¥»÷ÕßÊ×ÏÈͨ¹ýÅäÖÃÃýÎóµÄÀûÓýӼû·þÎñÆ÷£¬ÏÂÔØÓÃÓÚ¹¥»÷µÄ¿âºÍ¹¤¾ß£¨ÀýÈç¼ÓÃÜ·¨Ê½£©£¬¶øºóͨ¹ýÕ³ÌùPython´úÂë²¢Ö´Ðо籾ÊÖ¶¯´´½¨ÀÕË÷Èí¼þ¡£¹¥»÷ÕßµÄÉí·ÝÉв»Ã÷È·£¬×êÑÐÈËÔ±ÒÔΪ¿ÉÄÜÓë¶íÂÞ˹µÄºÚ¿ÍÍÅ»ïÓйء£
https://blog.aquasec.com/python-ransomware-jupyter-notebook
Lab52°ä²¼ÓëTurlaÓйصÄAndroid¼äµýÈí¼þµÄ¼¼Êõ»ã±¨
4ÔÂ1ÈÕ£¬Lab52°ä²¼ÓëTurlaÓйصÄAndroid¼äµýÈí¼þµÄ¼¼Êõ»ã±¨¡£½üÆÚ£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÃûΪProcess ManagerµÄ¶ñÒâAPK¡£Ò»µ©×°Öã¬Ëü»áʹÓóÝÂÖÐÎͼ±ê°µ²ØÔÚAndroidÉ豸ÉÏ£¬¼Ù×°³Éϵͳ×é¼þ£¬²¢ÒªÇó»ñÈ¡É豸µÄµØÎ»¡¢·¢ËͺÍÔĶÁÎı¾¡¢½Ó¼û´æ´¢¡¢Ê¹ÓÃÏà»úÅÄÕÕÒÔ¼°Â¼ÔìÒôƵµÈ18ÏîȨÏÞ¡£Ëü»¹»áÏÂÔØÆäËüµÄpayload£¬ÀýÈçRoz Dhan£¬¸Ã¼äµýÈí¼þ¿ÉÄÜ»áͨ¹ý´ËÖÖ·½Ê½£¬×¬È¡ÍƼöÀûÓõÄÓ¶½ð¡£
https://lab52.io/blog/complete-dissection-of-an-apk-with-a-suspicious-c2-server/
°²È«¹¤¾ß
Socid-Extractor
´ÓÓ×ÎÒ×ÊÁÏÍøÒ³/API ÏìÓ¦ÖÐÌáÈ¡ÓйØÓû§µÄÐÅÏ¢£¬²¢½«Æä±£ÁôΪ»úе¿É¶ÁÌåʽ¡£
https://github.com/soxoj/socid-extractor
GitBleed Tools
ÓÃÓÚ´Ó¾µÏñ git ´æ´¢¿âÖÐÌáÈ¡Êý¾Ý¡£
https://github.com/nightwatchcybersecurity/gitbleed_tools
ggshield
ÊÇÒ»¸ö CLI ÀûÓ÷¨Ê½£¬¼ì²âÔ´´úÂëÖеÄÃÜÂë¡£
https://github.com/GitGuardian/ggshield
PackMyPayload
ÓÃÓÚ½«payload´ò°üµ½×÷Ϊ´æµµ/ÈÝÆ÷µÄÊä³öÎļþÖС£
https://securityonline.info/packmypayload-packages-payloads-into-output-containers/
°²È«·ÖÎö
ºÚ¿ÍÂÛ̳ÉÏÏúÊÛµÄРBlackGuard ÃÜÂëÇÔÈ¡¶ñÒâÈí¼þ
https://www.bleepingcomputer.com/news/security/new-blackguard-password-stealing-malware-sold-on-hacker-forums/
FORCEDENTRY£ºÉ³ºÐÌÓÒÝ
https://googleprojectzero.blogspot.com/2022/03/forcedentry-sandbox-escape.html
Microsoft Build ½«ÓÚ 5 Ô 24 ÈÕÆô¶¯
https://news.softpedia.com/news/microsoft-build-will-kick-off-on-may-24-535139.shtml
Atento³ÆÈ¥ÄêµÄLockBitÀÕË÷¹¥»÷Ôì³É4200ÍòÃÀÔªËðʧ
https://www.bleepingcomputer.com/news/security/lockbit-victim-estimates-cost-of-ransomware-attack-to-be-42-million/
Anonymous¹¥»÷¶íÂÞ˹Ͷ×ʹ«Ë¾Thozis Corp
https://securityaffairs.co/wordpress/129651/hacktivism/anonymous-hacked-thozis-corp.html
ÍøÂç´¹µöʹÓà Azure ¾²Ì¬ÍøÒ³¼ÙÒâ΢Èí
https://www.bleepingcomputer.com/news/microsoft/phishing-uses-azure-static-web-pages-to-impersonate-microsoft/


¾©¹«Íø°²±¸11010802024551ºÅ