ÖÇÀûµÄµçÐŹ«Ë¾GTDÔâµ½ÀÕË÷ÍÅ»ïRorschachµÄ¹¥»÷

°ä²¼¹¦·ò 2023-10-27

1¡¢ÖÇÀûµÄµçÐŹ«Ë¾GTDÔâµ½ÀÕË÷ÍÅ»ïRorschachµÄ¹¥»÷


¾ÝýÌå10ÔÂ25ÈÕ±¨Â·£¬ÖÇÀûµçÐŹ«Ë¾Grupo GTDÔâµ½¹¥»÷£¬Ó°ÏìÁËÆä»ù´¡ÉèÊ©¼´·þÎñ(IaaS)ƽ̨£¬µ¼ÖÂÔÚÏß·þÎñÁÙʱÖжÏ¡£¹¥»÷²úÉúÓÚ10ÔÂ23ÈÕÉÏÎ磬GTDµÄÊý¾ÝÖÐÐÄ¡¢»¥ÁªÍø½ÓÈëºÍIPÓïÒô(VoIP)µÈ·þÎñÊܵ½Ó°Ïì¡£ÖÇÀûCSIRT³ÆÕâÊÇһ·ÀÕË÷¹¥»÷£¬¹ÌȻûÓÐй©¹¥»÷ÕßÉí·Ý£¬µ«×êÑÐÈËÔ±»ñÏ¤Éæ¼°µ½ÀÕË÷Èí¼þRorschach£¨±ðÃûBabLock£©µÄ±äÖÖ¡£¹ØÓÚGTD¹¥»÷ÊÂÎñµÄ»ã±¨°µÊ¾£¬¹¥»÷ÕßÀûÓÃÁ˺Ϸ¨µÄTrend Micro¡¢BitDefenderºÍCortex XDR¿ÉÖ´ÐÐÎļþÖеÄDLL²à¼ÓÔØ·ì϶À´¼ÓÔØ¶ñÒâDLL¡£


https://www.bleepingcomputer.com/news/security/chilean-telecom-giant-gtd-hit-by-the-rorschach-ransomware-gang/


2¡¢Winter VivernÀûÓÃRoundcube·ì϶¹¥»÷Å·Ö޵Ļú¹¹


ESETÔÚ10ÔÂ25ÈÕÅû¶ÁËWinter VivernÍÅ»ïÕë¶ÔÅ·Ö޵Ĺ¥»÷»î¶¯¡£ÖÁÉÙ×Ô10ÔÂ11ÈÕÆð£¬¸ÃÍÅ»ï¾ÍÒ»ÏòÀûÓÃRoundcube Webmail·þÎñÆ÷ÖеÄXSS·ì϶(CVE-2023-5631)¹¥»÷Å·ÖÞµ±¾Ö»ú¹¹ºÍÖǿ⡣¹¥»÷Õß¼ÙÒâOutlookÍŶÓ£¬Í¨¹ýÔ̺¬ÌØÔìµÄSVGÎĵµµÄHTMLÓʼþÀ´Ô¶³Ì×¢ÈëËÁÒâJavaScript´úÂ룬×îÖÕpayload¿É´Ó±»Ï°È¾µÄÍøÂçÓʼþ·þÎñÆ÷ÇÔÈ¡µç×ÓÓʼþ¡£¸ÃXSS·ì϶ÒÑÓÚ10ÔÂ14ÈÕ±»½¨¸´¡£


https://www.welivesecurity.com/en/eset-research/winter-vivern-exploits-zero-day-vulnerability-roundcube-webmail-servers/


3¡¢MandiantÌáÐÑVolt TyphoonÕë¶ÔÃÀ¹úµÄ¹Ø¼ü»ù´¡ÉèÊ©


¾Ý10ÔÂ25ÈÕ±¨Â·£¬MandiantÌáÐÑÖÎÀíÈËÔ±°ÑÎÈVolt TyphoonÕë¶ÔÃÀ¹úµÄ¹Ø¼ü»ù´¡ÉèÊ©µÄ¹¥»÷¡£×Ô2021ÄêÖÐÆÚÒÔÀ´£¬¸ÃÍÅ»ïÒѹ¥»÷ÁËͨѶ¡¢Ôì×÷¡¢¹«¹²ÊÂÒµ¡¢ÔËÊä¡¢¹¹Öþ¡¢º£Ê¡¢µ±¾Ö¡¢ÐÅÏ¢¼¼ÊõºÍ½ÌÓýµÈÁìÓòµÄ¸÷ÀàʵÌå¡£×êÑÐÈËÔ±³Æ£¬ËûÃÇ¿ÉÄÜÏëÔÚսʱÔì×÷·ÛËéÐÔÊÂÎñ£¬¹ÌȻûÓеý±¨Ö¤ÊµÕâÒ»µã£¬µ«ÖØÒªÕë¶Ô¹Ø¼ü»ù´¡ÉèÊ©µÄ»î¶¯Ê¹Æä²»µÃ²»ÓÅÏÈ˼¿¼¡£×êÑÐÈËÔ±¶½´ÙÖÎÀíÕßÓÅÏÈÎªÃæÏò»¥ÁªÍøµÄ±ßÔµÉ豸ºÍÍøÂç·ÓÉÆ÷´ò²¹¶¡ºÍ²ÉÈ¡»º½â´ëÊ©¡£ 


https://www.securityweek.com/mandiant-intelligence-chief-raises-alarm-over-chinas-volt-typhoon-hackers-in-us-critical-infrastructure/


4¡¢²àÐÅ·¹¥»÷iLeakage¿ÉÀûÓÃSafariÇÔÈ¡AppleÉ豸Êý¾Ý


ýÌå10ÔÂ26Èճƣ¬×êÑÐÈËÔ±Éè¼ÆÁËÒ»ÖÖеĴ§Ä¦²àÐÅ·¹¥»÷·½Ê½iLeakage£¬¿ÉÀûÓÃSafariÇÔÈ¡Mac¡¢iPhoneºÍiPadµÄÊý¾Ý¡£iLeakageÊÇÕë¶ÔApple Silicon CPUºÍSafariä¯ÀÀÆ÷µÄ´§Ä¦Ö´Ðй¥»÷£¬Ëü¿ÉÓÃÓÚÒÔ¡°½üºõÃÀÂúµÄÕýÈ·ÐÔ¡±´ÓSafariÒÔ¼°iOSÉϵÄFirefox¡¢TorºÍEdge¼ìË÷Êý¾Ý¡£´ÓÐÔÖÊÉϽ²£¬ËüÊÇÒ»ÖÖÎÞ¼ÆÊ±Æ÷µÄSpectre¹¥»÷£¬Äܹ»ÈƹýËùÓÐä¯ÀÀÆ÷¹©¸øÉÌÖ´Ðеij߶Ȳàͨ·¹¥»÷µÄ±£»¤¡£


https://www.bleepingcomputer.com/news/security/new-ileakage-attack-steals-emails-passwords-from-apple-safari/


5¡¢CiscoÅû¶YoroTrooperÕë¶ÔCIS¹ú¶ÈµÄ¹¥»÷»î¶¯


10ÔÂ25ÈÕ£¬Cisco³ÆYoroTrooperÔÚ½üÆÚÖØÒªÕë¶Ô¶ÀÁ¢¹ú¶È½áºÏÌå(CIS)¹ú¶È¡£¸ÃÍÅ»ïÓÚ2022Äê6Ô³õ´Î»îÔ¾£¬¿ÉÄÜÓëÈø¿Ë˹̹ÓйØ£¬»¹Í¨¹ýVPNµÈ·½Ê½¼Ù×°À´×Ô°¢Èû°Ý½®¡£½ñÄê5ÔÂÖÁ8Ô£¬¹¥»÷ÕßÈëÇÖÁ˶à¸ö¹úÓÐÍøÕ¾ºÍµ±¾Ö¹¤×÷ÈËÔ±µÄÕË»§¡£´óÎÞÊý¹¥»÷ʼÓÚ´¹µöÓʼþ£¬²¢·Ö·¢¶¨ÔìµÄ¶ñÒâÈí¼þ£¬Ö¼ÔÚÇÔÈ¡Êý¾ÝºÍÍ´´¦¡£×ÔÉϴα»¹«¿ªÅû¶ºó£¬YoroTrooper¾Í¸Ä½ø²¢À©´óÁËËûÃǵÄTTP£¬½«ËûÃÇ»ùÓÚPythonµÄÖ²Èë·¨Ê½ÒÆÖ²µ½PowerShell£¬²¢Ô½À´Ô½¶àµØÑ¡È¡×Ô½ç˵ֲÈ뷨ʽ£¬ÉÕ»ÙÁËÒÔǰʹÓõÄÉÌÆ·»¯¶ñÒâÈí¼þ¡£


https://blog.talosintelligence.com/attributing-yorotrooper/


6¡¢Kaspersky°ä²¼¸´ÔӵĶñÒâÈí¼þStripedFlyµÄ·ÖÎö


10ÔÂ26ÈÕ£¬Kaspersky°ä²¼Á˹ØÓÚ¸´ÔӵĶñÒâÈí¼þ¿ò¼ÜStripedFlyµÄ·ÖÎö»ã±¨¡£¸Ã¶ñÒâÈí¼þÒÑÒñ±ÎÔËÐÐÁË5Ä꣬¾Ý¹À¼ÆÒÑϰȾÁ˳¬¹ý100Íò¸öWindowsºÍLinuxϵͳ¡£StripedFly֮ǰ±»ÃýÎ󵨹éÀàΪMonero¼ÓÃܿ󹤣¬KasperskyÔÚÈ¥Äê·¢ÏÖÁËËüµÄÕæÊµÐÔÖÊ£¬²¢·¢Ïָÿò¼Ü×Ô2017Äê¾ÍÆðÍ·»î¶¯¡£¸Ã¶ñÒâÈí¼þpayloadÔ̺¬¶à¸öÄ£¿é£¬Ê¹¹¥»÷Õß¿ÉÄÜ¿ÉÄÜÒÔAPT¡¢¼ÓÃÜ¿ó¹¤ÉõÖÁÀÕË÷ÍÅ»ïµÄÉí·ÝÐÐÊ¡£ÍÚ¿óÄ£¿é¿ÉÄÜÊdzöÆæÔìʤµÄÕ½Êõ£¬Ò²ÊǸöñÒâÈí¼þ¿ÉÄܳ־ÃÈÆ¹ý¼ì²âµÄÖØÒª³É·Ö£¬¹¥»÷ÕßÖØÒªÍ¨¹ýÆäËüÄ£¿éÇÔÈ¡Êý¾ÝºÍÈëÇÖϵͳ¡£


https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/