¼ÓÄô󺽿յÄϵͳ±»ÈëÇÖ²¿ÃÅÔ±¹¤µÄÓ×ÎÒÐÅϢй¶

°ä²¼¹¦·ò 2023-09-25

1¡¢¼ÓÄô󺽿յÄϵͳ±»ÈëÇÖ²¿ÃÅÔ±¹¤µÄÓ×ÎÒÐÅϢй¶


¾ÝýÌå9ÔÂ21ÈÕ±¨Â·£¬¼ÓÄô󺽿ÕÅû¶ÁËһ·°²È«ÊÂÎñ£¬ÆäÖкڿ͡°¶ÌÔݵء±»ñµÃÁËÆäÄÚ²¿ÏµÍ³µÄ½Ó¼ûȨÏÞ¡£¾ÝϤ£¬Õâ´ÎÊÂÎñµ¼ÖÂÔ±¹¤µÄÓ×ÎÒÐÅÏ¢ºÍ²¿ÃżÍ¼й¶¡£µ«ÊǺ½°àÔËӪϵͳºÍÃæÏò¿Í»§µÄϵͳûÓÐÊܵ½Ó°Ï죬¿Í»§ÐÅϢҲûÓб»½Ó¼û¡£Ä¿Ç°£¬ËùÓÐϵͳ¾ùÒÑÈ«ÃæÔËÐС£²»¾Ãǰ£¬ÒòÔâµ½DDoS¹¥»÷£¬¼ÓÄôóÈ«¹ú¸÷µØµÄ±ßÚï²é³­Õ¾Öµ»úͤµÄÍÆËã»ú³öÏÖ¹ÊÕÏ£¬µ¼ÖÂÈë¾³´î¿Í½â¾öÊÖÐøµÄ¿ìÂÊÂýÁËÒ»¸ö¶àÓ×ʱ¡£


https://therecord.media/air-canada-limited-employee-info-accessed 


2¡¢ALPHV³Æ¶Ô³µÔØÒôÏìÔì×÷ÉÌClarionÔâµ½µÄ¹¥»÷ÕÆ¹Ü


¾Ý9ÔÂ24ÈÕ±¨Â·£¬AlphvÐû³ÆÈëÇÖÁËÒôƵºÍ¶àýÌåÉ豸µÄÈ«ÇòÔì×÷ÉÌClarion¡£¸Ã¹«Ë¾¿ª·¢¡¢Ôì×÷ºÍÏúÊÛ¸÷Àà²úÆ·£¬Ô̺¬Æû³µµ¼º½ÏµÍ³¡¢ÒôƵϵͳ¡¢ÊÓÆµÏµÍ³ºÍºóÊÓÉãÏñÍ·¡£AlphvÔÚ9ÔÂ23ÈÕ½«ClarionÔö³¤µ½ÆäTorÍøÕ¾ÖУ¬³ÆÓйØÒµÎñºÍºÏ×÷ͬ°éµÄ»úÃÜÒѾ­Êý¾Ýй¶¡£¸ÃÍŻﻹ°µÊ¾Æä»ñµÃÁ˿ͻ§Êý¾Ý£¬²¢ÍþвÔÚ9ÔÂ25ÈÕ֮ǰ½«ÕâЩÊý¾ÝÏúÊÛ¸øµÚÈý·½¡£ºÚ¿Í°ä²¼ÁËһЩ±»µÁÎļþµÄ½ØÍ¼×÷Ϊ¹¥»÷µÄÖ¤¾Ý¡£


https://securityaffairs.com/151299/data-breach/alphv-ransomware-hacked-clarion.html


3¡¢SandmanÍÅ»ïÀûÓÃкóÃÅLuaDreamÖØÒªÕë¶ÔµçÐÅÌṩÉÌ


9ÔÂ21ÈÕ£¬SentinelLabs³ÆSandmanÀûÓÃÄ£¿é»¯ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þLuaDream¹¥»÷µçÕÛ·þÎñÌṩÉÌ¡£¸Ã»î¶¯ÓÚ8Ô·ݱ»·¢ÏÖ£¬ÖØÒªÕë¶ÔÖж«¡¢Î÷Å·ºÍÄÏÑÇ¡£SandmanÀûÓÃLuaJITƽ̨²¿ÊðÁËÐÂÐͺóÃÅLuaDream£¬¸ÃºóÃÅÓÉ34¸ö×é¼þ×é³É£¬Ô̺¬13¸öÖ÷Ìâ×é¼þºÍ21¸öÖ§³Ö×é¼þ£¬ËüÃÇͨ¹ýffi¿âʹÓÃLuaJIT×Ö½ÚÂëºÍWindows API¡£¸Ã¶ñÒâÈí¼þµÄ¿ª·¢ËƺõºÜ»îÔ¾£¬°æ±¾ºÅΪ"12.0.2.5.23.29"£¬×îÔç¿É×·Òäµ½2022Äê6Ô¡£


https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/


4¡¢³¬¹ý200ÍòÃû°Í»ù˹̹¹«ÃñµÄÓ×ÎÒÐÅÏ¢±»ºÚ¿ÍÏúÊÛ


9ÔÂ21ÈÕ±¨Â·³Æ£¬ºÚ¿ÍÈëÇÖÁ˰ͻù˹̹Êý°Ù¼Ò²ÍÌüʹÓõĸöÈ˹«Ë¾Ôì×÷µÄÊý¾Ý¿â£¬µ¼Ö³¬¹ý200Íò¹«ÃñÃæ¶Ô×ÅÓ×ÎÒÐÅϢй¶µÄ·çÏÕ¡£¸ÃÊÂÎñÓ°ÏìÁ˲ÍÌüµÄ¿Í»§£¬Ð¹Â¶ÁËÐÅÓþ¿¨¡¢µØÖ·ºÍÒøÐоßÌåÐÅÏ¢µÈÊý¾Ý¡£ºÚ¿ÍÔÚÒÔ2±ÈÌØ±ÒµÄ¼ÛÖµÏúÊÛ±»µÁÊý¾Ý¡£ºÚ¿ÍÔÚµãÃûij¶¥¼¶²ÍÌüʱй©£¬ËûÃÇÒÑÈëÇÖÁË250¶à¼Ò²ÍÌüµÄÊý¾Ý¿â¡£ÁíÒ»·½Ã棬Áª¹úµ÷²éÈËÔ±°µÊ¾£¬ËûÃÇûÓÐÊÕµ½Õâ·½ÃæµÄͶËß¡£


https://en.dailypakistan.com.pk/21-Sep-2023/hackers-put-over-2-million-pakistanis-private-data-for-sale-after-restaurant-software-breach


5¡¢Unit 42Åû¶GelsemiumÕë¶Ô¶«ÄÏÑÇ»ú¹¹µÄ¹¥»÷»î¶¯


Unit 42ÔÚ9ÔÂ22ÈÕÅû¶ÁËGelsemiumÕë¶Ô¶«ÄÏÑǵ±¾Ö»ú¹¹µÄ¹¥»÷»î¶¯¡£¹¥»÷ÕßÔÚ±»Ï°È¾µÄWeb·þÎñÆ÷ÉÏ×°ÖÃÁ˶à¸öWeb shellÀ´»ñµÃϵͳ½Ó¼ûȨÏÞ£¬Ô̺¬¹«¿ª¿ÉÓõÄreGeorg¡¢China ChopperºÍAspxSpy¡£¹¥»÷ÕßÓÃÓÚºáÏòÒÆ¶¯¡¢Êý¾ÝÍøÂçºÍÌáȨµÄ¹¤¾ßÔ̺¬OwlProxy¡¢SessionManager¡¢Cobalt Strike¡¢SpoolFoolºÍEarthWorm¡£×êÑÐÈËԱͨ¹ýOwlProxyºÍSessionManager´§¶ÈÕâ´Î¹¥»÷»î¶¯ÓëGelsemiumÓйØ¡£


https://unit42.paloaltonetworks.com/rare-possible-gelsemium-attack-targets-se-asia/


6¡¢ESET³ÆStealth FalconÀûÓÃDeadglyph¹¥»÷Öж«µÄʵÌå


9ÔÂ22ÈÕ£¬ESET°ä²¼»ã±¨³ÆStealth FalconÀûÓÃDeadglyph¹¥»÷Öж«µÄʵÌå¡£DeadglyphµÄ¼Ü¹¹Óɶà¸öºÏ×÷×é¼þ×é³É£¬Ô̺¬±¾µØx64¶þ½øÔì×é¼þºÍ.NET·¨Ê½¼¯¡£Óë½öʹÓÃÒ»ÖÖ±à³Ì˵»°¿ª·¢µÄ³£¼û¶ñÒâÈí¼þ·ÖÆç£¬DeadglyphʹÓÃÁË·ÖÆçµÄ˵»°¡£¸Ã¶ñÒâÈí¼þÒÔ¸½¼ÓÄ£¿éµÄ´ó¾Ö´ÓC2¶¯Ì¬½Ó¹ÜºÅÁ»¹Ö§³Ö¶àÖÖÈÆ¹ýÖ°ÄÜ¡£¸Ã»ã±¨·ÖÎöµÄÊÇÕë¶ÔÖж«Ä³µÐÔÖʵÌåµÄ¹¥»÷£¬ÉÐδȷ¶¨ºóÃŵľßÌå´«²¼·½Ê½¡£


https://www.welivesecurity.com/en/eset-research/stealth-falcon-preying-middle-eastern-skies-deadglyph/