TA544ÀûÓÃWikiLoaderÕë¶ÔÒâ´óÀûµÄÆóÒµ·Ö·¢Ursnif
°ä²¼¹¦·ò 2023-08-021¡¢TA544ÀûÓÃWikiLoaderÕë¶ÔÒâ´óÀûµÄÆóÒµ·Ö·¢Ursnif
ProofpointÔÚ7ÔÂ31ÈÕÅû¶ÁËÀûÓÃжñÒâÈí¼þWikiLoaderÕë¶ÔÒâ´óÀûÆóÒµµÄ¹¥»÷»î¶¯¡£WikiLoaderÊÇÒ»¸ö¸´ÔÓµÄÏÂÔØ·¨Ê½£¬ÓÉÓÚËü»áÏòWikipedia·¢³öÒªÇó²¢²é³ÏìÓ¦ÄÚÈÝÖÐÊÇ·ñÔ̺¬×Ö·û´®¡°The Free¡±¶øµÃÃû¡£ProofpointÓÚ2022Äê12ÔÂ27ÈÕ³õ´ÎÔÚÒ°±í¼ì²âµ½¸Ã¶ñÒâÈí¼þ£¬ÓÉTA544´«²¼¡£×êÑÐÈËÔ±³Æ£¬ÖÁÉÙÓÐ8¸ö»î¶¯ÔÚ·Ö·¢WikiLoader£¬À´×ÔTA544ºÍTA551£¬¾ùÕë¶ÔÒâ´óÀûµÄ×éÖ¯¡£´Ë±í£¬¹ÌÈ»´óÎÞÊý¹¥»÷ÕßÒѲ»ÔÙʹÓÃÆôÓúêµÄÎĵ·´´«²¼¶ñÒâÈí¼þ£¬µ«TA544ÈÔÔÚ¹¥»÷Á´ÖÐʹÓÃËüÃÇ£¬Ô̺¬´«²¼WikiLoader¡£
https://www.proofpoint.com/us/blog/threat-insight/out-sandbox-wikiloader-digs-sophisticated-evasion
2¡¢ÃÀ¹úÒÂÊι«Ë¾Hot TopicÔ⵽ײ¿â¹¥»÷й¶¿Í»§µÄÐÅÏ¢
¾ÝýÌå8ÔÂ1ÈÕ±¨Â·£¬ÃÀ¹úÒÂÊμ°ÊÚȨÒôÀÖÁãÊÛÁ¬ËøµêHot Topicй©ÆäÔâµ½Á˶àÆð¹¥»÷ÊÂÎñ£¬µ¼Ö¿ͻ§µÄÃô¸ÐÐÅϢй¶¡£¸Ã¹«Ë¾ÔÚÃÀ¹úÕ¼ÓÐ675¼ÒÉ̵꣬ÒÔ¼°Ã¿Ô½ü1000Íò½Ó¼ûÁ¿µÄÔÚÏßÉ̵ꡣ¸Ã¹«Ë¾Ú¹ÊÍ˵£¬ºÚ¿ÍʹÓÃÇÔÈ¡µÄÕÊ»§Í´´¦ÂŴνӼûÁËRewardsƽ̨£¬¿ÉÄÜ»ñµÃÁ˿ͻ§µÄÊý¾Ý¡£¾µ÷²é£¬¹¥»÷ÕßÓÚ2023Äê2ÔÂ7ÈÕ¡¢3ÔÂ11ÈÕ¡¢5ÔÂ19ÈÕÖÁ21ÈÕ¡¢5ÔÂ27ÈÕÖÁ28ÈÕºÍ6ÔÂ18ÈÕÖÁ21ÈÕ£¬Ê¹ÓÃÓÐЧÕÊ»§Í´´¦¶ÔÍøÕ¾ºÍÒÆ¶¯ÀûÓÃÖ´ÐÐÁË×Ô¶¯¹¥»÷¡£¸Ã¹«Ë¾°µÊ¾£¬Hot Topic²»ÊÇй¶ƾ֤µÄÆðÔ´£¬µ«Ò²ÎÞ·¨ÕÒµ½ÆðÔ´¡£
https://www.bleepingcomputer.com/news/security/retail-chain-hot-topic-discloses-wave-of-credential-stuffing-attacks/
3¡¢Henry Ford HealthÔâ´¹µö¹¥»÷½ü17Íò»¼ÕßÐÅϢй¶
¾Ý7ÔÂ27ÈÕ±¨Â·£¬ÃÀ¹úµÄѧÊõÒ½ÁÆ»úHenry Ford Health³ÆÆä3ÃûÔ±¹¤Ôâµ½´¹µö¹¥»÷£¬Ó°ÏìÁË168215¸ö»¼ÕßµÄÐÅÏ¢¡£¸Ã»ú¹¹ÔÚÉêÃ÷ÖаµÊ¾£¬¹¥»÷ÊÂÎñ²úÉúÓÚ3ÔÂ30ÈÕ£¬¸Ã×éÖ¯Òѽ«±»Ó°ÏìµÄµç×ÓÓʼþÕÊ»§±£»¤ÆðÀ´²¢·¢Õ¹µ÷²é¡£5ÔÂ16£¬È·¶¨»¼ÕߵĽ¡È«ÐÅÏ¢Ô̺¬ÔÚµç×ÓÓÊÏäÖУ¬²¢ÇÒ¿ÉÄÜÒѱ»¹¥»÷ÕßÇÔÈ¡£¬Éæ¼°ÐÕÃû¡¢³¢ÊÔÊÒÁ˾֡¢ÊÖÊõÀàÐÍ¡¢Õï¶Ï¡¢µç»°ºÅÂë¡¢²¡ÀúºÅºÍÄÚ²¿¸ú×ٺŵÈÐÅÏ¢¡£¸Ã¹«Ë¾°µÊ¾£¬ËûÃÇÔÚÖ´Ðжî±íµÄ°²È«´ëÊ©£¬²¢½«ÎªÔ±¹¤Ìṩ°²È«Åàѵ¡£
https://www.bankinfosecurity.com/phishing-scam-affects-nearly-170k-henry-ford-health-patients-a-22672
4¡¢Cado·¢ÏÖ¿ÉÕë¶ÔRedis·þÎñÆ÷µÄP2PInfectÈ䳿бäÌå
7ÔÂ31ÈÕ£¬Cado·¢ÏÖÁËÒ»ÖÖÕë¶ÔRedisµÄÐÂÐͶñÒâÈí¼þ»î¶¯¡£¸Ã¶ñÒâÈí¼þ±»¿ª·¢Õß¶¨ÃûΪP2Pinfect£¬ÓÃRust¿ª·¢£¬³äÈν©Ê¬ÍøÂç´úÀí¡£×êÑÐÈËÔ±·ÖÎöµÄÑù±¾Ô̺¬Ò»¸öǶÈëʽPEÎļþÒÔ¼°Ò»¸öELF¶þ½øÔìÎļþ£¬Õâ½²ÁËÈ»WindowsºÍLinuxÖ®¼äÓµÓÐ¿çÆ½Ì¨¼æÈÝÐÔ¡£Ëü»¹ÀûÓø´ÔìÖ°ÄÜÀ´¹¥»÷RedisÊý¾Ý´æ´¢µÄÊ·ý¡£´Ë±í£¬P2PinfectÊÔͼͨ¹ýCronδ¾Éí·ÝÑéÖ¤µÄRCE»úÔì¹¥»÷RedisÖ÷»ú¡£¸Ã»î¶¯±³ºóµÄ¹¥»÷ÕßÉí·ÝÉв»Ã÷ÏÔ£¬P2PInfectµÄÖ÷ÕÅÒ²²»Ã÷ÏÔ¡£
https://www.cadosecurity.com/redis-p2pinfect/
5¡¢Minecraft mod·ì϶BleedingPipeÒѱ»´ó¹æÄ£ÀûÓÃ
ýÌå7ÔÂ31ÈÕ±¨Â·³Æ£¬ºÚ¿ÍÔÚÀûÓÃMinecraft modÖеÄRCE·ì϶BleedingPipeÔÚ·þÎñÆ÷ºÍ¿Í»§¶ËÖ´ÐжñÒâºÅÁ´Ó¶ø½ÚÔìÉ豸¡£BleedingPipe·ì϶×î³õÓÚ2022Äê3Ô±»ÀûÓ㬵«ºÜ¿ì¾Í±»mod¿ª·¢Õß½¨¸´ÁË¡£È»¶øÔÚ7ÔÂÔçЩʱ³½£¬ForgeÂÛ̳µÄһƪÌû×ӳƣ¬ÓÐÈËÀûÓÃδ֪RCEÀ´´ó¹æÄ£ÇÔÈ¡Íæ¼ÒµÄDiscordºÍSteam»á»°cookie¡£½øÒ»²½×êÑз¢ÏÖ£¬¶à¸öMinecraft modÖÐÒ²´æÔÚBleedingPipe·ì϶¡£¹¥»÷ÕßÔÚɨÃèÊܸ÷ì϶ӰÏìµÄMinecraft·þÎñÆ÷²¢Ö´Ðй¥»÷£¬Òò¶ø½¨¸´·þÎñÆ÷ÉÏÒ×±»¹¥»÷µÄmodÖÁ¹Ø³ÁÒª¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-bleedingpipe-rce-to-target-minecraft-servers-players/
6¡¢Bahamutͨ¹ý¼ÙðµÄAndroidÀûÓÃSafeChatÇÔÊØÐÅÏ¢
7ÔÂ28ÈÕ£¬CYFIRMA³ÆÆä·¢ÏÖÁËÒ»¸ö¿ÉÒɵÄAndroid¶ñÒâÈí¼þ£¬¼Ù×°³ÉÐéαµÄ̸ÌìÀûÓÃSafeChat£¬ÇÔÈ¡ÊÖ»úµÄͨ»°¼Í¼¡¢¶ÌÐźÍGPSµØÎ»µÈÊý¾Ý¡£¸Ã¶ñÒâÈí¼þ±»ÒÉ»óÊÇCoverlmµÄ±äÖÖ£¬»áÇÔÈ¡Telegram¡¢Signal¡¢WhatsApp¡¢ViberºÍFacebook MessengerµÈͨѶÀûÓõÄÊý¾Ý¡£¸Ã»î¶¯ÓëÓ¡¶ÈºÚ¿ÍÍÅ»ïBahamutÓйأ¬ÖØÒªÍ¨¹ýWhatsAppÉϵÄÓã²æÊ½´¹µöÐÂÎŽøÐУ¬ÖØÒªÕë¶ÔÄÏÑǵØÓò¡£´Ë±í£¬¸Ã»î¶¯ÓëÓ¡¶ÈµÄÁíÒ»¸öºÚ¿ÍÍÅ»ïDoNotµÄ»î¶¯ÓÐÀàËÆÖ®´¦¡£
https://www.cyfirma.com/outofband/apt-bahamut-targets-individuals-with-android-malware-using-spear-messaging/


¾©¹«Íø°²±¸11010802024551ºÅ