Win 11×îв¹¶¡µ¼ÖÂMalwarebytesÓëChrome²»¼æÈÝ

°ä²¼¹¦·ò 2023-06-16
1¡¢Win 11×îв¹¶¡µ¼ÖÂMalwarebytesÓëChrome²»¼æÈÝ


¾ÝýÌå6ÔÂ14ÈÕ±¨Â·£¬±¾Öܶþ°ä²¼µÄWindows 11 22H2 KB5027231ÀÛ»ý¸üÐÂÓ°ÏìÁËMalwarebytes¿Í»§ÏµÍ³ÉϵÄGoogle Chrome¡£Ò»Î»ÖÎÀíԱ˵£¬×°ÖøüкóChromeä¯ÀÀÆ÷³öÏÖÎÊÌ⣬ÊÔͼͨ¹ýWSUS»Ø¹ö£¬ÊÂÎñ²é¿´Æ÷ÖÐÏÔʾ¡°catastrophic error¡±£¬²¢ÇÒWSUSÏÔʾ²»Äܻعö¡£Chrome¹ý³ÌÏÖʵÉÏÔÚÔËÐУ¬µ«ÓÉÓÚì¶Ü¶øÎÞ·¨ÆëÈ«Æô¶¯ÀûÓ÷¨Ê½ºÍ¼ÓÔØÓû§½çÃæ¡£Malwarebytes°µÊ¾£¬Win 11¸üе¼ÖÂChromeÓë·ì϶ÀûÓñ£»¤²úÉúì¶Ü£¬½ø¶øµ¼ÖÂä¯ÀÀÆ÷±ÀÀ£¡£Óöµ½´ËÎÊÌâµÄÓû§Äܹ»´ÓÆäMalwarebytesÊܱ£»¤ÀûÓ÷¨Ê½ÁбíÖйعØÍøÂçä¯ÀÀÆ÷¡£


https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5027231-update-breaks-google-chrome-for-malwarebytes-users/


2¡¢ÃÀ¹ú¶à¸öµ±¾Ö»ú¹¹Ôâµ½ÀÕË÷ÍÅ»ïClopµÄ¹¥»÷


¾Ý6ÔÂ16ÈÕ±¨Â·£¬ÃÀ¹ú¶à¸öµ±¾Ö»ú¹¹Ôâµ½ÁËÀÕË÷ÍÅ»ïClopµÄ¹¥»÷¡£¹¥»÷ÕßÀûÓÃÁËMOVEitÎļþ´«Ê乤¾ßÖеķì϶£¬CISA³ÆÆäÔÚºÍFBIÖÂÁ¦ÎªÊ¹ÓÃMOVEitµÄÁª¹ú»ú¹¹ÌṩԮÊÖ£¬È·ÈϹ¥»÷µÄÓ°Ï첢ʵʱ²¹¾È¡£¹Ù·½»Ø¾øÐ¹Â©ÊÜÓ°ÏìµÄ»ú¹¹µÄÃû³ÆºÍÊýÁ¿£¬µ«Ò»Î»ÄÜÔ´²¿½²»°ÈËй©£¬¸Ã²¿ÃÅÊÇÔâµ½ÈëÇֵĶà¸öÁª¹ú»ú¹¹Ö®Ò»¡£´Ë±í£¬Ó¢¹úʯÓͺÍÌìÈ»Æø¹«Ë¾¿ÇÅÆÔÚ±¾ÖÜËÄй©ÆäÒ²Ôâµ½ÁËClopÀÕË÷¹¥»÷£¬¸Ã¹«Ë¾È¥ÄêµÄÊÕÈ볬¹ý3810ÒÚÃÀÔª¡£


https://therecord.media/several-us-federal-agencies-affected-by-moveit-breach


3¡¢HP¹«¿ªÃ÷¹ý¶ñÒâÍøÕ¾·Ö·¢ChromeÀ©´óShampooµÄ»î¶¯


6ÔÂ14ÈÕ±¨Â·£¬HP¹«¿ªÁËÒ»¸öÔÚ½øÐÐÖеÄÐÂChromeLoader»î¶¯¡£¸Ã»î¶¯Ê¼ÓÚ3Ô£¬Í¨¹ýÐû³Æ¿ÉÃâ·ÑÏÂÔØµÁ°æÒôÀÖ¡¢µçÓ°»òÓÎÏ·µÄ¶ñÒâÍøÕ¾·Ö·¢ChromeLoader¡£ÓÕʹָ±êÏÂÔØÖ´ÐÐPowerShell¾ç±¾µÄVBScript£¬¸Ã¾ç±¾ÉèÖÃÒÔ¡°chrome_¡±ÎªÇ°×ºµÄ´òË㹤×÷¡£´Ë¹¤×÷»á´¥·¢Ò»ÏµÁо籾£¬½«ÐµÄPowerShell¾ç±¾ÏÂÔØ²¢±£Áôµ½×¢²á±íÖУ¬Í¬Ê±»á»ñÈ¡¶ñÒâChromeÀ©´óShampoo¡£ShampooÊÇChromeLoaderµÄ±äÌ壬¿ÉÄÜÔÚÖ¸±ê½Ó¼ûµÄÍøÕ¾ÉÏ×¢Èë¸æ°×²¢Ö´ÐÐËÑË÷²éÎʳÁ¶¨Ïò¡£


https://www.bleepingcomputer.com/news/security/new-shampoo-chromeloader-malware-pushed-via-fake-warez-sites/


4¡¢Trellix³ÆÐÂÇÔÈ¡·¨Ê½SkuldÕë¶ÔÅ·ÃÀºÍ¶«ÄÏÑǵȵØ


TrellixÔÚ6ÔÂ13ÈÕ³ÆÆä·¢ÏÖÁËÐÂÐÍGolangÇÔÈ¡·¨Ê½Skuld£¬ÒÑÈëÇÖÅ·ÖÞ¡¢¶«ÄÏÑǺÍÃÀ¹úµÄWindowsϵͳ¡£¸Ã¶ñÒâÈí¼þ×Ô4ÔÂÏÂÑ®ÆðÍ··¢×÷£¬»áËÑË÷´æ´¢ÔÚDiscordºÍä¯ÀÀÆ÷µÅצÓÃÖеÄÊý¾Ý£¬ÒÔ¼°ÏµÍ³µÄÐÅÏ¢ºÍÎļþ¼ÐÖеÄÎļþ¡£²¿ÃÅÑù±¾ÉõÖÁÔ̺¬ÇÔÈ¡¼ÓÃÜÇ®±ÒµÄÄ£¿é£¬µ«×êÑÐÈËÔ±ÒÔΪ¸ÃÄ£¿éÈÔÔÚ¿ª·¢ÖС£×êÑÐÈËÔ±³Æ£¬¿ª·¢ÈËÔ±Deathined´Ó¶à¸ö¿ªÔ´ÏîÄ¿ºÍ¶ñÒâÈí¼þÑù±¾ÖÐÂÞÖÂÁé¸Ð£¬½«Ö°ÄÜÒÆÖ²µ½GolangÀ´¹¹½¨Skuld¡£


https://www.trellix.com/en-us/about/newsroom/stories/research/skuld-the-infostealer-that-speaks-golang.html


5¡¢Î¢Èí°ä²¼¹ØÓÚºÚ¿ÍÍÅ»ïCadet BlizzardµÄ·ÖÎö»ã±¨


6ÔÂ14ÈÕ£¬Î¢Èí°ä²¼Á˹ØÓÚºÚ¿ÍÍÅ»ïCadet BlizzardµÄ·ÖÎö»ã±¨¡£¾ÝÐÅ£¬¸Ã×éÖ¯ÓÚ2020ÄêÆðÍ·ÔËÓª£¬Óë¶íÂÞ˹GRUÓйØ£¬ÖØÒªÕë¶ÔÎÚ¿ËÀ¼È·µ±¾Ö·þÎñ¡¢·¨ÂÉ»ú¹¹¡¢·ÇͶ»ú/·Çµ±¾Ö×éÖ¯¡¢IT·þÎñÌṩÉÌ/Õ÷ѯ¹«Ë¾ºÍ´¹Î£·þÎñ¡£²¢½«ÆäÓë2022Äê1ÔÂ13ÈÕÕë¶ÔÎÚ¿ËÀ¼µÄWhisperGate¹¥»÷ÁªÆðÀ´¡£¸ÃÍÅ»ïÔÚ2022Äê6ÔÂÖ®ºóÖð²½µ­³öÈËÃǵÄÊÓÏߣ¬µ«ÔÚ2023ËêÊ׳Áи¡³öË®Ãæ¡£Î¢Èí°µÊ¾£¬ÓëAPT28ºÍSandwormµÈÆäËüGRUÓйغڿÍÍÅ»ïÏà±È£¬Cadet Blizzard¹¥»÷µÄ³É¹¦ÂÊÏà¶Ô½ÏµÍ¡£


https://www.microsoft.com/en-us/security/blog/2023/06/14/cadet-blizzard-emerges-as-a-novel-and-distinct-russian-threat-actor/


6¡¢StairwellÅû¶ChamelGangÖ²È뷨ʽChamelDoHµÄϸ½Ú


6ÔÂ13ÈÕ£¬StairwellÅû¶ºÚ¿ÍÍÅ»ïChamelGangµÄÐÂÖ²È뷨ʽChamelDoHµÄϸ½Ú¡£ÕâÊÇÒ»ÖÖÓÃC++¿ª·¢µÄLinuxÖ²È뷨ʽ£¬ÓÃÓÚÔ¶³Ì½Ó¼ûÖ¸±êϵͳ£¬²¢Í¨¹ýDNS-over-HTTPS (DoH)Ëí·ÓëÅäÖõÄC2»ù´¡ÉèʩͨѶ¡£ËùÓжñÒâÈí¼þµÄͨѶ¶¼Ê¹ÓÃAES128ºÍÅú¸ÄºóµÄbase64±àÂë¼ÓÃÜ£¬ÆäÖÐÔ̺¬·Ç×ÖĸÊý×Ö×Ö·ûµÄ´úÌæ¡£¸ÃÖ²Èë·¨Ê½ÍøÂçϵͳµÄÐÅÏ¢À´·ÖÎö±»Ï°È¾µÄÖ¸±ê£¬²¢¿ÉÄܽøÐиù»ùµÄÔ¶³Ì½Ó¼û½ÚÔ죬ÀýÈçÎļþÉÏ´«¡¢ÏÂÔØ¡¢É¾³ýºÍÖ´ÐС£


https://stairwell.com/news/chamelgang-and-chameldoh-a-dns-over-https-implant/