TA453 ÀûÓÃÐÂÐÍ AnvilEcho ¶ñÒâÈí¼þ¹¥»÷ÓÌÌ«³ÛÃûÈËÎï

°ä²¼¹¦·ò 2024-08-22
1. TA453 ÀûÓÃÐÂÐÍ AnvilEcho ¶ñÒâÈí¼þ¹¥»÷ÓÌÌ«³ÛÃûÈËÎï


8ÔÂ20ÈÕ£¬ÒÁÀʹú¶ÈÖ§³ÖµÄÍþв×éÖ¯TA453Õë¶ÔÓÌÌ«³ÛÃûÈËÎïÌáÒéÁËһϵÁо«ÐIJ߶¯µÄÓã²æÊ½ÍøÂç´¹µö»î¶¯¡£´Ë»î¶¯Ö¼ÔÚ´«²¼ÃûΪAnvilEchoµÄÐÂÐ͵ý±¨ÍøÂ繤¾ß£¬¸Ã¹¤¾ßͨ¹ýBlackSmith¶ñÒâÈí¼þ¹¤¾ß°ü´«²¼£¬²¢¼Ù×°³ÉºÏ·¨Ô¼ÇëÒÔ³ÉÁ¢ÐÅÀµ¡£AnvilEcho×÷Ϊһ¿î׳´óµÄPowerShellľÂí£¬¾ß±¸ÏµÍ³¿úËÅ¡¢½ØÆÁ¡¢ÏÂÔØÔ¶³ÌÎļþ¼°Ãô¸ÐÊý¾ÝÉÏ´«µÈÖ°ÄÜ£¬ÏÔÖø¾Û½¹ÓÚµý±¨ÍøÂçºÍй¶¡£´Ë±í£¬¸Ã»î¶¯ÀûÓÃÉç»á¹¤³Ìѧ¼¿Á©£¬Èç¼ÙÒâ×êÑлú¹¹·¢ËÍÐéαԼÇëºÍÊÜÃÜÂë±£»¤µÄÎĵµÁ´½Ó£¬ÓÕµ¼Êܺ¦Õßµã»÷¶ñÒâÁ´½ÓºÍÏÂÔØ²¡¶¾¡£Óë´Ëͬʱ£¬ÁíÒ»Ïî·¢ÏÖ½ÒʾÁËÒ»ÖÖеĻùÓÚGo˵»°µÄ¶ñÒâÈí¼þCyclops£¬¿ÉÄÜ×÷ΪCharming KittenºóÃÅBellaCiaoµÄºóÐø²úÆ·£¬½øÒ»²½Åú×¢¹¥»÷ÕßÕý»ý¼«¸üÐÂÆä±øÆ÷¿â¡£CyclopsÖ¼ÔÚͨ¹ýREST API·´ÏòËí·´«ÊäÖÁC2·þÎñÆ÷£¬½ÚÔìÖ¸±ê»úе£¬²¢Òѱ»ÓÃÓÚ¹¥»÷Àè°ÍÄۺͰ¢¸»º¹µÄÌØ¶¨×éÖ¯¡£´Ë¶ñÒâÈí¼þµÄÑ¡Ôñ·´Ó³ÁËGo˵»°ÔÚ¶ñÒâÈí¼þ¿ª·¢ÕßÖеÄÊ¢ÐУ¬ÇÒÆäµÍ¼ì²âÂʶ԰²È«½â¾ö¹æ»®×é³ÉÌôÕ½¡£


https://thehackernews.com/2024/08/iranian-cyber-group-ta453-targets.html


2. Xeon SenderÔÆ¹¥»÷¹¤¾ß£¬ÀûÓúϷ¨·þÎñ´ó¾Ù½øÐжÌÐÅ´¹µö


8ÔÂ19ÈÕ£¬¶ñÒâÐÐΪÕßÕýÀûÓÃÃûΪXeon SenderµÄÔÆ¹¥»÷¹¤¾ß£¬Í¨¹ýÀÄÓúϷ¨ÔÆ·þÎñ½øÐдó¹æÄ£µÄ¶ÌÐÅ´¹µöºÍÀ¬»øÓʼþ»î¶¯¡£Õâ¿î¹¤¾ßÀûÓöà¸öÈí¼þ¼´·þÎñ£¨SaaS£©ÌṩÉ̵ÄÓÐЧƾ֤£¬Í¨¹ýºÏ·¨API½Ó¿Ú·¢ËÍÀ¬»øÐÅÏ¢£¬¶ø²»ÒÀÀµÈκιÌÓÐÈõµã¡£SentinelOne°²È«×êÑÐÔ±Ö¸³ö£¬Xeon Sender¼°Æä±äÌåÈçXeonV5ºÍSVG Sender£¬ÀûÓÃÔ̺¬ÑÇÂíѷ֪ͨ·þÎñ£¨SNS£©ÔÚÄڵĶà¸ö¶ÌÐÅ·Ö·¢Æ½Ì¨£¬Í¨¹ýTelegramºÍºÚ¿ÍÂÛ̳´«²¼¡£×îа汾µÄXeon SenderÔÚÃûΪOrion ToolxhubµÄTelegramƵ·Éϰ䲼£¬¸ÃƵ·»¹ÌṩÆäËûºÚ¿Í¹¤¾ß¡£Xeon Sender²»½öÏÞÓÚ¶ÌÐÅ·¢ËÍ£¬»¹¾ß±¸ÑéÖ¤ÕË»§Æ¾Ö¤¡¢ÌìÉúµç»°ºÅÂë¼°²é³­ºÅÂëÓÐЧÐÔµÈÖ°ÄÜ¡£Æä»ùÓÚPythonµÄºÅÁîÐнçÃæÔÊÐíÓû§ÇáËÉÓëAPIͨѶ£¬Ð­µ÷¹¥»÷¡£¸Ã¹¤¾ß¹ÌȻԴ´úÂë»ìÂÒ£¬µ«ÓÐЧ½µµÍÁ˼¼ÊõÃż÷£¬Ê¹µÃµÍ¼¼Êõ¹¥»÷ÕßÒ²ÄÜÀûÓá£ÓÉÓÚXeon SenderʹÓÃÌØ¶¨¹©¸øÉÌ¿â½øÐÐAPIÒªÇ󣬼ì²âÄѶÈÔö³¤£¬ÆóÒµÐèѡȡ×ۺϼ¿Á©£¬Ô̺¬APIÈÕÖ¾·ÖÎöºÍÐÐΪ¼à¿Ø£¬ÒÔ¼ø±ð²¢·ÀÓù´ËÀ๥»÷¡£


https://thehackernews.com/2024/08/xeon-sender-tool-exploits-cloud-apis.html


3. CERT-UAÖҸ棺ÐÂÐÍÍøÂç´¹µö¹¥»÷ÀûÓÃVermin¼¯Èº´«²¼¶ñÒâÈí¼þ


8ÔÂ21ÈÕ£¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±·´Ó³Ó××飨CERT-UA£©½üÈÕ·¢³öÖҸ棬ָ³öÒ»ÖÖеÄÍøÂç´¹µö¹¥»÷ÔÚ»îÔ¾£¬¸Ã¹¥»÷ÀûÓöñÒâÈí¼þ̰ͼϰȾÓû§É豸£¬Æä±³ºóÍþв¼¯Èº±»ÏóÕ÷ΪUAC-0020£¬ÓÖ³ÆVermin¡£Ö»¹Ü¹¥»÷µÄ¾ßÌ广ģºÍÁìÓòÉв»Ë¬ÀÊ£¬µ«ÒÑÖªÆäͨ¹ý¼Ù×°³É¿â¶û˹¿ËµØÓòÕ½·ýÕÕÆ¬µÄÍøÂç´¹µöÓʼþÌáÒ飬ÓÕµ¼Óû§µã»÷Á´½ÓÏÂÔØZIPÎļþ¡£ÕâЩZIPÎļþÄÚº¬Ç¶ÓÐJavaScript´úÂëµÄMicrosoft CHMÎļþ£¬¸Ã´úÂë½øÒ»²½´¥·¢»ìºÏµÄPowerShell¾ç±¾Ö´ÐС£Ò»µ©Óû§´ò¿ªÕâЩÎļþ£¬²»½ö»á×°ÖÃÒÑÖª¼äµýÈí¼þSPECTRµÄ×é¼þ£¬»¹»áÒýÈëÃûΪFIRMACHAGENTµÄжñÒâÈí¼þ¡£FIRMACHAGENTµÄÖØÒª¹¤×÷ÊÇÍøÂçSPECTRÇÔÈ¡µÄÊý¾Ý£¬²¢½«Æä»Ø´«ÖÁÔ¶³Ì·þÎñÆ÷¡£SPECTR×÷Ϊһ¿îÖ°ÄÜ׳´óµÄ¶ñÒâÈí¼þ£¬×Ô2019ÄêÆð±ãÓëVermin×éÖ¯ÓйØÁª£¬ÇÒ¾ÝÐÅÓ문Ê˹¿ËÈËÃñ¹²ºÍ¹ú£¨LPR£©µÄ°²È«»ú¹¹ÓÐÁªÏµ¡£SPECTR¿ÉÄÜ¿í·ºÍøÂçÓû§ÐÅÏ¢£¬Ô̺¬µ«²»ÏÞÓÚ¼´Ê±Í¨Ñ¶ÀûÓã¨Element¡¢Signal¡¢Skype¡¢TelegramµÈ£©ÖеÄÎļþ¡¢ÆÁÄ»½ØÍ¼¡¢µÇ¼ƾ֤¼°Ãô¸ÐÊý¾Ý¡£


https://thehackernews.com/2024/08/cert-ua-warns-of-new-vermin-linked.html


4. CannonDesignÔâÀÕË÷Èí¼þAvos Locker¹¥»÷£¬1.3 Íò¿Í»§Êý¾Ýй¶


8ÔÂ20ÈÕ£¬³ÛÃûÃÀ¹ú¹¹ÖþÉè¼Æ¹«Ë¾CannonDesign½üÆÚÏòÆäÖØ´óµÄ13,000ÓàÃû¿Í»§Èº·¢ËÍÁËÊý¾Ýй¶֪ͨ£¬½ÒʾÁË2023ËêÊ×Ôâ·êµÄ³Á´óÍøÂ簲ȫÊÂÎñ¡£¸ÃÊÂÎñ²úÉúÔÚ1ÔÂ19ÈÕÖÁ25ÈÕÖ®¼ä£¬ºÚ¿Í·¸·¨ÇÖÈëÁ˹«Ë¾ÏµÍ³²¢ÇÔÈ¡ÁËÊý¾Ý£¬Ö»¹Ü¹«Ë¾Ñ¸¿ìÓÚ1ÔÂ25ÈÕ·¢ÏÖ²¢È¾Ö¸£¬µ«È«ÃæµÄµ÷²é¹¤×÷Ö±ÖÁ2024Äê5ÔÂ3ÈղŸæÒ»¶ÎÂä¡£¾Ý´«µÝ£¬Ð¹Â¶µÄÐÅÏ¢¿ÉÄÜÔ̺¬¿Í»§µÄÃô¸ÐÓ×ÎÒ×ÊÁÏ£¬ÈçÐÕÃû¡¢µØÖ·¡¢Éç»á°²È«ºÅÂë¼°¼ÝÊ»ÅÆÕպţ¬¶Ô´Ë£¬CannonDesign¾ö¶¨ÎªÊܺ¦ÕßÌṩΪÆÚ24¸öÔµÄÐÅÓþ¼à¿Ø·þÎñ¡£Õâ´ÎÊý¾Ýй¶ÓëAvos LockerÀÕË÷Èí¼þ¹¥»÷çÇÃÜÓйØ£¬¸ÃÍÅ»ïÓÚ2023Äê2Ô¹«¿ªÐû³Æ¹¥»÷ÁËCannonDesign²¢°ÑÎÕ5.7 TB µÄ±»µÁÊý¾Ý£¬Ô̺¬¹«Ë¾ºÍ¿Í»§Îļþ¡£ÔÚÀÕË÷δ¹ûºó£¬Êý¾Ý±»×ª½»¸øÁËDark Angels ÀÕË÷Èí¼þ×éÖ¯µÄÊý¾ÝÐ¹Â¶ÍøÕ¾ Dunghill Leaks£¬¸Ã×éÖ¯°ä²¼ÁËÉæ¼°¿Í»§ÏêÇé¡¢ÏîÄ¿×ÊÁϼ°¹«Ë¾ÄÚ²¿ÐÅÏ¢µÈ2TB Êý¾Ý¡£2024 Äê 2 Ô£¬Í³Ò»Êý¾Ý¼¯ÔÚ°µÍøÖеĺڿÍÂÛ̳Éϰ䲼£¬Ô̺¬ ClubHydra£¬¶øÊý¾Ý¼¯µÄÒ»²¿ÃÅÔÚ 2024 Äê 7 ÔÂͨ¹ý torrent ÔÚ Breached Forums ÉÏ·ÖÏí¡£


https://www.bleepingcomputer.com/news/security/cannondesign-confirms-avos-locker-ransomware-data-breach/


5. Chrome´¹Î£½¨²¹ÒÑÔâºÚ¿Í»ý¼«ÀûÓõÄÁãÈÕ·ì϶CVE-2024-7971


8ÔÂ21ÈÕ£¬Google½üÆÚ´¹Î£°ä²¼ÁËChromeä¯ÀÀÆ÷µÄ×îа汾£¨128.0.6613.84/85£©£¬ÖØÒªÊÇΪÁËÓ¦¶ÔÒ»¸öÒѱ»ºÚ¿Í»ý¼«ÀûÓõÄÁãÈÕ·ì϶CVE-2024-7971¡£ÕâÒ»¸ßΣ·ì϶´æÔÚÓÚV8 JavaScriptÒýÇæÖУ¬¾ßÌå²û·¢ÎªÀàÐÍ»ìºÏÎÊÌ⣬ËüÔÊÐí¹¥»÷ÕßÔÚ·¸·¨½Ó¼ûÓû§É豸ʱִÐжñÒâ´úÂ룬ÑϳÁÍþвÓû§Êý¾Ý°²È«£¬¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢·¸·¨½Ó¼û»ò¶ñÒâÈí¼þÖ²Èë¡£¼øÓڸ÷ì϶ÒÑÔÚÏÖʵÖÐÔâµ½ÀûÓã¬Õâ´Î¸üÐÂÏÔµÃÓÈΪ»ð¼±¡£³ýÁËÕë¶ÔCVE-2024-7971µÄ½¨¸´±í£¬Chrome 128°æ±¾»¹Ò»²¢½â¾öÁËÔ̺¬CVE-2024-7964ºÍCVE-2024-7965ÔÚÄڵĶà¸ö¸ßÑϳÁÐÔ°²È«·ì϶¡£ËùÓÐChromeÓû§±»Ç¿ÁÒ½¨Òéµ±¼´ÊÖ¶¯²é³­²¢¸üÐÂÖÁ128.0.6613.84»ò¸ü¸ß°æ±¾¡£´Ë±í£¬¶ÔÓÚÒÀÀµChrome´¦ÖÃÃô¸ÐÊý¾ÝµÄ×éÖ¯¶øÑÔ£¬Ñ¸¿ìÀûÓô˸üв¢Ë¼¿¼Ö´Ðжî±íµÄ°²È«·À»¤´ëÊ©£¨ÈçÀûÓÃɳºÐ¸ôÀ롢ǿ»¯ÍøÂç·Ö¶ÎµÈ£©±äµÃÓÈΪ¹Ø¼ü£¬ÒÔ½øÒ»²½½µµÍCVE-2024-7971¼°ÆäËûDZÔÚ·ì϶´øÀ´µÄ°²È«·çÏÕ¡£


https://securityonline.info/urgent-chrome-update-active-zero-day-exploit-detected-cve-2024-7971/


6. ³¯ÏʺڿÍUAT-5394²¿ÊðÐÂÐͶñÒâÈí¼þMoonPeak


8ÔÂ21ÈÕ£¬Ò»ÖÖÐÂÐÍÔ¶³Ì½Ó¼ûľÂíMoonPeak±»¸æ·¢Îª¹ú¶ÈÖ§³ÖµÄ³¯ÏÊÍþв»î¶¯¼¯ÍŵÄй¤¾ß¡£Ë¼¿ÆTalos½«ÆäÓë±àºÅΪUAT-5394µÄºÚ¿Í×éÖ¯ÁªÏµÆðÀ´£¬¸Ã×éÖ¯ÔÚÕ½ÊõÉÏÓëÒÑÖªµÄKimsuky¹ú¶ÈÐÐΪÕß´æÔÚ½»¼¯¡£MoonPeak×÷ΪXeno RAT¶ñÒâÈí¼þµÄ±äÖÖ£¬±»Éè¼ÆÓÃÓÚ´ÓÔÆ·þÎñÖмìË÷¶ñÒâ¸ºÔØ£¬¾ß±¸¼ÓÔØ²å¼þ¡¢½ÚÔì¹ý³Ì¼°ÓëC2·þÎñÆ÷ͨѶµÈÖ°ÄÜ¡£Talos·ÖÎöÖ¸³ö£¬UAT-5394¿ÉÄÜÊÇKimsukyµÄ·ÖÖ§»ò³¯ÏÊÍøÂç»ú¹¹ÄÚÁíһѡȡÀàËÆÕ½ÊõµÄÍŶÓ¡£Õâ´Î»î¶¯ÏÔÖøÌØµãÊǹ¹½¨ÁËеĻù´¡ÉèÊ©£¬Ô̺¬C2·þÎñÆ÷¡¢¸ºÔØÍйܵãºÍ²âÊÔ»·¾³£¬ÒÔÖ§³ÖMoonPeakµÄ³ÖÐøµü´ú¡£×êÑÐÈËÔ±¹Û²ìµ½£¬ÍþвÐÐΪÕ߯µÈÔ¸üзþÎñÆ÷ÉϵĶñÒâÎļþ£¬²¢ÍøÂçϰȾÈÕÖ¾£¬ÏÔʾ³ö¸ß¶ÈµÄ½Ã½ÝÐÔºÍÒñ±ÎÐÔ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬MoonPeakµÄ½ø»¯Óëлù´¡ÉèÊ©µÄ³ÉÁ¢çÇÃÜÏàÁ¬£¬Ã¿´Î¸üж¼ÒýÈë¸ü¶à»ìºÏ¼¼Êõ£¬ÒÔ¹ÊÕÏ·ÖÎöºÍŤתͨѶ»úÔì¡£ÕâÖÖÉè¼ÆÈ·±£ÁËMoonPeakµÄÌØ¶¨°æ±¾½öÓëÆ¥ÅäµÄC2·þÎñÆ÷Эͬ¹¤×÷£¬Ôö³¤ÁË·ÀÓùÄѶÈ¡£UAT-5394Ѹ¿ì¹¹½¨Ð»ù´¡ÉèÊ©µÄÄÜÁ¦Åú×¢£¬¸Ã×éÖ¯Õý»ý¼«À©´ó»î¶¯ÁìÓò£¬ÔöÉèͶ·ÅµãºÍC2·þÎñÆ÷¡£²»Í⣬ĿǰÉв»Ã÷ÏÔÕâ´Î»î¶¯µÄÖ¸±ê¡£


https://thehackernews.com/2024/08/north-korean-hackers-deploy-new.html