Turla APTÀÄÓÃMSBuild·Ö·¢TinyTurlaºóÃÅ

°ä²¼¹¦·ò 2024-05-23
1. Turla APTÀÄÓÃMSBuild·Ö·¢TinyTurlaºóÃÅ


5ÔÂ22ÈÕ£¬Ò»¸öÓë¶íÂÞ˹Óйصĸ߼¶³ÖÐøÐÔÍþв (APT) ×éÖ¯Ò»ÏòÔÚÀÄÓà PDF ºÍ MSBuild ÏîÄ¿Îļþ£¬ÀûÓÃÉç½»¹¤³Ìµç×ÓÓʼþ½« TinyTurla ºóÃÅ×÷ΪÎÞÎļþ¸ºÔؽøÐд«²¼¡£×êÑÐÈËÔ±°µÊ¾£¬¸Ã»î¶¯µÄÎÞ·ì´«²¼·¨Ê½ÔÚ¸´ÔÓÐÔ·½Ãæ»ñµÃÁËÏÔÖøµÄ½øÈ¡¡£Cyble ×êÑÐÈËÔ±ºÍµý±¨³¢ÊÔÊÒ (CRIL) µÄ×êÑÐÈËÔ±·¢ÏÖÁËÕâÒ»»î¶¯£¬¸Ã»î¶¯Ê¹Óõç×ÓÓʼþºÍÔ¼ÇëÈËȨ×êÑлá»òÌṩ¹«¹²Õ÷ѯµÄÎļþ×÷Ϊµö¶ü£¬ÒÔϰȾ TinyTurla Óû§¡£ËûÃÇÔÚ×òÌì°ä²¼µÄÓйظûµÄ²©¿ÍÎÄÕÂÖаµÊ¾£¬¹¥»÷Õß»¹¼ÙÒâºÏ·¨µ±¾Ö£¬ÒÔÒýÓÕÊܺ¦ÕßÊÜÆ­¡£×êÑÐÈËÔ±Ö¸³ö£¬TinyTurla ºóÃÅÓë¶íÂÞ˹ÔÞÖúµÄ³Ö¾ÃÍþв×éÖ¯TurlaÓйØ£¬¸Ã×é֯ͨ³£Õë¶Ô·Çµ±¾Ö×éÖ¯£¬¡°³ö¸ñÊÇÄÇЩÓëÖ§³ÖÎÚ¿ËÀ¼ÓÐÁªÏµµÄ×éÖ¯¡±¡£Ìû×ӳƣ¬ËûÃÇÒÔΪ¸Ã×éÖ¯ÊǶñÒâ¹¥»÷»î¶¯µÄÄ»ºóºÚÊÖ¡£


https://www.darkreading.com/cyberattacks-data-breaches/russia-turla-apt-msbuild-tinyturla-backdoor


2. CISA ÖÒ¸æÀûÓÃMirth Connect·ì϶µÄ¹¥»÷»î¶¯


5ÔÂ21ÈÕ£¬Mirth Connect ÊÇÒ»ÖÖ¿í·ºÊ¹ÓÃµÄ¿çÆ½Ì¨½çÃæÒýÇæ£¬Ò½ÁƱ£½¡×éÖ¯½«ÆäÓÃÓÚÐÅÏ¢ÖÎÀí¡£Ó°Ï쿪Դ²úÆ·µÄ·ì϶ CVE-2023-43208 ÊÇÒ»¸öÊý¾Ý·´ÐòÁл¯ÎÊÌ⣬¿Éµ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐС£4.4.1 °æ°ä²¼Ê±ÒÑÍÆ³ö²¹¶¡¡£¸Ã·ì϶ÓÚ 2023 Äê 10 ÔÂÆØ¹â£¬ÆäÊ±ÍøÂ簲ȫ¹«Ë¾ Horizon3.ai ÖÒ¸æ³Æ¸Ã·ì϶¿ÉÄܶÔÒ½ÁƱ£½¡¹«Ë¾Ôì³ÉÓ°Ïì¡£CVE-2023-43208 ÊÇ CVE-2023-37679 µÄÒ»¸ö±äÌ壬Mirth Connect ¿ª·¢ÈËԱ֮ǰÒÑÔÚ 4.4.0 °æ°ä²¼Ê±¶Ô¸Ã·ì϶½øÐÐÁ˽¨²¹¡£Horizon3.ai Æäʱ½«¸Ã·ìϼûèÊöΪÒ×ÓÚÀûÓ㬲¢ÖÒ¸æ³Æ¡°¹¥»÷ÕߺܿÉÄÜÀûÓô˷ì϶½øÐгõʼ½Ó¼û»ò·ÛËéÃô¸ÐµÄÒ½ÁÆÊý¾Ý¡±¡£¸Ã°²È«¹«Ë¾»¹Ö¸³ö£¬·¢ÏÖÁË 1,200 ¶à¸ö¶³öÔÚ»¥ÁªÍøÉ쵀 NextGen Mirth Connect Ê·ý¡£


https://www.securityweek.com/cisa-warns-of-attacks-exploiting-nextgen-healthcare-mirth-connect-flaw/


3. ºÚ¿ÍÍÅ»ïÀûÓÃÀÕË÷Èí¼þ¹¥»÷·ÆÂɱöµ±¾Ö


5ÔÂ22ÈÕ£¬ºÚ¿ÍÔÚÀûÓÃй¶µÄÀÕË÷Èí¼þ¹¹½¨Õß¶Ô·ÆÂɱöµÄ¹Ø¼ü»ù´¡ÉèÊ©ÌáÒé¹¥»÷¡ª¡ªÕâÊdzöÓÚÕþÖζ¯»úµÄ¼¯ÌåµÄÇ÷ÏòµÄÒ»²¿ÃÅ£¬ËûÃÇÔ½À´Ô½¶àµØÊÔͼÇÖÈÅÕâ¸ö¶«ÄÏÑǹú¶ÈµÄÉúÑÄ¡£ÍøÂ簲ȫ¹«Ë¾ SentinelOneµÄ×êÑÐÈËÔ±°µÊ¾£¬Ò»¸öÃûΪ¡°Ikaruz Red Team¡±µÄ×éÖ¯ÊÇÉÙÊý¼¸¸öÕë¶Ô·ÆÂɱöµ±¾ÖÖ¸±êµÄºÚ¿Í×éÖ¯Ö®Ò»¡£¸ÃÐж¯ÀûÓÃÁ˶àÖÖÀÕË÷Èí¼þ¹¹½¨Õß¡ª¡ªÔ̺¬ LockBit¡¢Vice Society¡¢Clop ºÍ AlphV¡ª¡ªÌáÒé¡°Ó×¹æÄ£¡±¹¥»÷¡£Ëü»¹ÔÚÍøÉÏÐû´«·ÆÂɱö¶à¸ö×éÖ¯µÄÊý¾Ýй¶Çé¿ö¡£SentinelOne °µÊ¾£¬Êܺ¦ÕߵıãÌõÏÕЩȫÊýØâÇÔ×Ôԭʼ LockBit Ä£°å£¬¶¥²¿µÄÃû×ÖÖ®±í¡£Î´ÌṩÁªÏµÐÅÏ¢¡£


https://therecord.media/philippines-hacktivist-groups-leaked-versions-ransomware


4. GhostEngine ÍÚ¿ó¹¥»÷ÀûÓÃÒ×Êܹ¥»÷µÄÇý¶¯


5ÔÂ22ÈÕ£¬ÒÑ·¢ÏÖ´úºÅΪ¡°REF4578¡±µÄ¶ñÒâ¼ÓÃÜÇ®±ÒÍÚ¾ò»î¶¯²¿ÊðÁËÃûΪ GhostEngine µÄ¶ñÒâ¸ºÔØ£¬¸Ã¸ºÔØÊ¹ÓÃÒ×Êܹ¥»÷µÄÇý¶¯·¨Ê½À´¹Ø¹Ø°²È«²úÆ·²¢²¿Êð XMRig ÍÚ¿ó·¨Ê½¡£Elastic Security Labs ºÍ °²ÌìµÄ×êÑÐÈËÔ±  ÔÚµ¥¶ÀµÄ»ã±¨ºÍ¹²ÏíµÄ¼ì²â¹æ¶¨ÖÐÇ¿µ÷ÁËÕâЩ¼ÓÃÜÇ®±ÒÍÚ¾ò¹¥»÷µÄÒì³£¸´ÔÓÐÔ£¬ÒÔÔ®ÊÖ·ÀÓùÕß¼ø±ðºÍ×èÖ¹ËüÃÇ¡£È»¶ø£¬Á½·Ý»ã±¨¾ù佫¸Ã»î¶¯¹é×ïÓÚÒÑÖªµÄÍþвÐÐΪÕߣ¬Ò²Î´·ÖÏíÓйØÖ¸±ê/Êܺ¦ÕߵľßÌåÐÅÏ¢£¬Òò¶ø¸Ã»î¶¯µÄ·¢Ô´ºÍÁìÓòÒÀȻδ֪¡£¹ÌÈ»Éв»Ã÷ÏÔ·þÎñÆ÷×î³õÊÇÈôºÎ±»·ÛËéµÄ£¬µ«ÍþвÐÐΪÕߵĹ¥»÷´ÓÖ´ÐÐÃûΪ¡°Tiworker.exe¡±µÄÎļþÆðÍ·£¬¸ÃÎļþ¼Ù×°³ÉºÏ·¨µÄ Windows Îļþ¡£¸Ã¿ÉÖ´ÐÐÎļþÊÇ GhostEngine µÄ³õʼµÇ̨ÓÐЧ¸ºÔØ£¬GhostEngine ÊÇÒ»¸ö PowerShell ¾ç±¾£¬¿ÉÏÂÔØ¸÷ÀàÄ£¿éÒÔÔÚÊÜϰȾµÄÉ豸ÉÏÖ´ÐÐ·ÖÆçµÄÐÐΪ¡£


https://www.bleepingcomputer.com/news/security/ghostengine-mining-attacks-kill-edr-security-using-vulnerable-drivers/


5. Î÷ϤÄá´óѧÔâµ½ºÚ¿Í¹¥»÷²¿ÃÅѧÉúÊý¾Ýй¶


5ÔÂ21ÈÕ£¬ÔÚÍþвÐÐΪÕß·ÛËéÁËÆä Microsoft 365 ºÍ Sharepoint »·¾³ºó£¬Î÷ϤÄá´óѧ (WSU) ÒÑÏòѧÉúºÍѧÊõÈËÔ±´«µÝÁËÊý¾Ýй¶ÊÂÎñ¡£WSU ÊǰĴóÀûÑǵÄÒ»Ëù½ÌÓý»ú¹¹£¬Ìṩ¿çѧ¿ÆµÄ¿í·º±¾¿Æ¡¢×êÑÐÉúºÍ×êÑпγÌ¡£ËüÕ¼ÓÐ 47,000 ÃûѧÉúºÍ 4,500 ¶àÃûÕýʽºÍ¼¾½ÚÐÔÔ±¹¤£¬ÔËÓªÔ¤ËãΪ 6 ÒÚÃÀÔª¡£Î÷ϤÄá´óÑ§ÍøÕ¾½ñÈÕ°ä²¼²¼¸æ£¬ÖÒ¸æ³ÆºÚ¿ÍÒѽӼûÆä Microsoft Office 365 »·¾³£¬Ô̺¬µç×ÓÓʼþÕÊ»§ºÍ SharePoint Îļþ¡£Ëù¶³öµÄÊý¾ÝÒòÈ˶øÒ죬¾ßÌåÈ¡¾öÓÚµç×ÓÓʼþͨѶµÄÄÚÈÝÒÔ¼°´óѧ SharePoint »·¾³Öд洢µÄÎĵµ¡£


https://www.bleepingcomputer.com/news/security/western-sydney-university-data-breach-exposed-student-data/#google_vignette


6. Void Manticore¶Ô×¼ÒÔÉ«ÁкͰ¢¶û°ÍÄáÑÇ


5ÔÂ22ÈÕ£¬¸Ã×éÖ¯ÃûΪ Void Manticore (Storm-0842)£¬ÔÚ·ÖÆç¹ú¶ÈÒÔ¸÷À໯Ãû·¢Õ¹»î¶¯¡£×î³ÛÃûµÄ±ðºÅÔ̺¬Õë¶Ô°¢¶û°ÍÄáÑÇÏ®»÷µÄ¡°ºÓɽÕýÒ塱ºÍÕë¶ÔÒÔÉ«ÁÐÐж¯µÄ¡°Òò¹û±¨Ó¦¡±¡£Õë¶Ô·ÖÆçµÄÇøÓò£¬Õë¶Ôÿ¸öÖ¸±êѡȡ¹ÖÒìµÄ²½Öè¡£¸Ã×éÖ¯µÄ»î¶¯ÓëÁíÒ»¸öÒÁÀÊ×éÖ¯ Scarred Manticore µÄ»î¶¯³Áµþ£¬ÕâÅúעЭºÍгϵͳµÄÊܺ¦ÕßÑ¡ÔñÊÇËûÃÇΪÒÁÀʵý±¨ºÍ°²È«Êý (MOIS) ¹¤×÷µÄÒ»²¿ÃÅ¡£×¨¼ÒÖÒ¸æËµ£¬Ðé¿ÕЫʨ¶ÔÈκηñ¾öÒÁÀÊÀûÒæµÄÈË×é³É³Á´óÍþв¡£¸Ã×éÖ¯ÀûÓø´ÔӵϝÃûÍøÂç¡¢Õ½ÊõºÏ×÷ºÍ¸´ÔӵĹ¥»÷²½Öè¡£¸Ã×éÖ¯ÒÔÆäË«³ÁÍøÂç¹¥»÷·½Ê½¶øÎÅÃû£¬½«ÎïÀíÊý¾Ý·ÛËéÓëÉúÀíѹÁ¦Ïà½áºÏ¡£Void Manticore ʹÓÃÎåÖÖ·ÖÆçµÄ²½Ö裬Ô̺¬Õë¶Ô Windows ºÍ Linux µÄ×Ô½ç˵²Á³ýÆ÷£¬Í¨¹ýɾ³ýÎļþºÍ°Ñ³Ö¹²Ïí´ÅÅÌÀ´·ÛËéϵͳ¡£


https://meterpreter.org/void-manticore-iranian-state-sponsored-hackers-target-israel-albania/