Mandiant·¢ÏÖUNC2891ÀûÓÃеÄCAKETAP¹¥»÷ATMÍøÂç

°ä²¼¹¦·ò 2022-03-22

Mandiant·¢ÏÖUNC2891ÀûÓÃеÄCAKETAP¹¥»÷ATMÍøÂç


3ÔÂ16ÈÕ£¬£¬£¬ £¬£¬£¬£¬£¬Mandiant°ä²¼Á˹ØÓÚUNC2891ÍŻ﹥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£ÔÚÕâ´Î»î¶¯ÖУ¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËÃûΪCAKETAPµÄÐÂUnix rootkit£¬£¬£¬ £¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÔËÐÐOracle Solaris²Ù×÷ϵͳµÄ·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£CaketapÄܹ»°µ²ØÍøÂçÏνӡ¢¹ý³ÌºÍÎļþ£¬£¬£¬ £¬£¬£¬£¬£¬Æä×îÖÕÖ¸±êÊÇ´ÓÖ¸±êATMÖнػñÒøÐп¨ºÍPINÑéÖ¤Êý¾Ý£¬£¬£¬ £¬£¬£¬£¬£¬¶øºóʹÓÃÕâЩµÁÊý¾Ý½øÐÐڲƭÂòÂô¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷»î¶¯»¹Ê¹ÓÃÁË2¸öÃûΪSLAPSTICKºÍTINYSHELLµÄºóÃÅ£¬£¬£¬ £¬£¬£¬£¬£¬ËüÃǶ¼ÓëUNC1945ÓйØ¡£¡£¡£¡£¡£¡£¡£


https://www.mandiant.com/resources/unc2891-overview


ʯÓ͹Ü·¹«Ë¾TransneftÑз¢²¿ÃÅOmega 79GBÊý¾Ýй¶


¾ÝýÌå3ÔÂ19ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬£¬£¬AnonymousÐû³ÆÒÑÈëÇÖÁËTransneftµÄÄÚ²¿Ñз¢²¿ÃÅOmega¡£¡£¡£¡£¡£¡£¡£TransneftÊÇÊÀ½çÉÏ×î´óµÄʯÓ͹Ü·¹«Ë¾£¬£¬£¬ £¬£¬£¬£¬£¬×ܲ¿Î»ÓÚĪ˹¿Æ¡£¡£¡£¡£¡£¡£¡£3ÔÂ17ÈÕ£¬£¬£¬ £¬£¬£¬£¬£¬DDoSecrets³ÆÆäÊÕµ½ÁËOmega¸ß´ï79GBµÄµç×ÓÓʼþ¡£¡£¡£¡£¡£¡£¡£Õâ´Îй¶µÄÊý¾Ý²»½öÔ̺¬µç×ÓÓʼþÐÅÏ¢£¬£¬£¬ £¬£¬£¬£¬£¬»¹Ô̺¬·¢Æ±ºÍ²úÆ·ÔËÊä¾ßÌåÐÅÏ¢£¬£¬£¬ £¬£¬£¬£¬£¬ÒÔ¼°ÏÔʾ·þÎñÆ÷»ú¼ÜºÍÆäËüÉ豸ÅäÖõÄͼÏñÎļþ¡£¡£¡£¡£¡£¡£¡£²»¾Ãǰ£¬£¬£¬ £¬£¬£¬£¬£¬Anonymous»¹ÈëÇÖÁ˶íÂÞ˹µÄýÌåÉó²é»ú¹¹Roskomnadzor¡£¡£¡£¡£¡£¡£¡£


https://www.hackread.com/anonymous-leak-79gb-russia-oil-pipeline-email-data/


N4ughtysecTUÐû³ÆÒÑÇÔÈ¡TransUnion·ÇÖÞ·Ö²¿4TBµÄÊý¾Ý


 Ã½Ìå3ÔÂ18ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬£¬£¬TransUnion°ä²¼ÉêÃ÷³ÆÎ»ÓÚÄϷǵķþÎñÆ÷Ôâµ½ÁËδ¾­ÊÚȨµÄ½Ó¼û¡£¡£¡£¡£¡£¡£¡£°ÍÎ÷ºÚ¿ÍÍÅ»ïN4ughtysecTUÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÒÑÔÚ¹¥»÷ÆÚ¼äÏÂÔØÁË4TBµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß°µÊ¾ËûÃÇͨ¹ý±©Á¦¹¥»÷ÈëÇÖÁËÒ»¸ö°²È«ÐԽϲîµÄTransUnion SFTP·þÎñÆ÷£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁËԼĪ5400Íò¿Í»§µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß×îÖÕÆÆ½âµÄÃÜÂëÊÇ¡°Password¡±£¬£¬£¬ £¬£¬£¬£¬£¬ÕâÒѱ»ÁÐΪ2021ÄêµÚÎå´ó×î³£ÓõÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷µÄÀÕË÷½ð¶îΪ15000000ÃÀÔª£¬£¬£¬ £¬£¬£¬£¬£¬µ«TransUnionÒÑÖ¸³öËü²»»áÏòºÚ¿Í¸¶¿î¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-claim-to-breach-transunion-south-africa-with-password-password/


FBI°ä²¼AvosLocker¹¥ÃÀ¹ú¶à¸ö¹Ø¼ü»ù´¡ÉèÊ©µÄ¹«¸æ


3ÔÂ17ÈÕ£¬£¬£¬ £¬£¬£¬£¬£¬ÃÀ¹úFBI°ä²¼¹ØÓÚÀÕË÷ÍÅ»ïAvosLockerµÄÍøÂ簲ȫÕ÷ѯ¡£¡£¡£¡£¡£¡£¡£FBI³Æ£¬£¬£¬ £¬£¬£¬£¬£¬AvosLockerÊÇÒ»¸ö»ùÓÚRaaSµÄÍŻ£¬£¬ £¬£¬£¬£¬£¬Õë¶ÔÃÀ¹ú¶à¸ö¹Ø¼ü»ù´¡ÉèÊ©µÄ×éÖ¯£¬£¬£¬ £¬£¬£¬£¬£¬Ô̺¬µ«²»ÏÞÓÚ½ðÈÚ·þÎñÐÐÒµ¡¢Ôì×÷ÐÐÒµºÍµ±²¿ÃÅÃŵÈ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«¸æ¹«¿ªÁËÓйشËRaaSÍÅ»ïµÄ¼¼Êõϸ½Ú£¬£¬£¬ £¬£¬£¬£¬£¬»¹Îª×éÖ¯ÌṩÁË¿ÉÓÃÓÚ¼ì²âºÍ×èÖ¹´ËÀ๥»÷µÄÈëÇÖÖ¸±ê(IOC)¡£¡£¡£¡£¡£¡£¡£ID-RansomwareÊý¾ÝÏÔʾ£¬£¬£¬ £¬£¬£¬£¬£¬AvosLockerÔÚ2021Äê11ÔÂÖÁ2021Äê12ÔÂÆÚ¼äµÄ»î¶¯¼¤Ôö£¬£¬£¬ £¬£¬£¬£¬£¬ÇÒĿǰÈÔÔÚ³ÖÐø¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fbi-avoslocker-ransomware-targets-us-critical-infrastructure/


Google°ä²¼¹ØÓÚConti³õʼ½Ó¼û´úÀíÕ½ÊõµÄ·ÖÎö»ã±¨


3ÔÂ17ÈÕ£¬£¬£¬ £¬£¬£¬£¬£¬GoogleÍþв·ÖÎöÓ××é(TAG)°ä²¼Á˹ØÓÚConti³õʼ½Ó¼û´úÀíÕ½ÊõµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£TAG·¢ÏÖеÄEXOTIC LILYÓëContiºÍDiavolµÈÀÕË÷ÍÅ»ïÓйأ¬£¬£¬ £¬£¬£¬£¬£¬ÆäÀûÓÃMicrosoft Windows MSHTMLƽ̨Öзì϶CVE-2021-40444½øÐд¹µö¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬ÔÚ¶¥·åÆÚÿÌìÏòÈ«Çò¶à´ï650¸öÖ¸±ê×éÖ¯·¢Ëͳ¬¹ý5000·âÓʼþ¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»EXOTIC LILYµÄ»î¶¯ÓëContiµÄÒµÎñ³Áµþ£¬£¬£¬ £¬£¬£¬£¬£¬µ«GoogleÒÔΪ£¬£¬£¬ £¬£¬£¬£¬£¬ËüÊÇÒ»¸öÆëȫרһÓÚ³ÉÁ¢³õÊ¼ÍøÂç½Ó¼ûµÄ¶ÀÁ¢¹¥»÷ÍŻ¡£¡£¡£¡£¡£¡£


https://blog.google/threat-analysis-group/exposing-initial-access-broker-ties-conti/


Western Digital½¨¸´ÆäEdgeRoverÖеÄĿ¼±éÀú·ì϶


3ÔÂ18ÈÕ£¬£¬£¬ £¬£¬£¬£¬£¬Western Digital°ä²¼°²È«¸üУ¬£¬£¬ £¬£¬£¬£¬£¬½¨¸´Æä×ÀÃæÀûÓ÷¨Ê½EdgeRoverÖеÄĿ¼±éÀú·ì϶£¨CVE-2022-22998£©¡£¡£¡£¡£¡£¡£¡£EdgeRoverÊǼ¯ÖÐʽÄÚÈÝÖÎÀí½â¾ö¹æ»®£¬£¬£¬ £¬£¬£¬£¬£¬½«¶à¸öÊý×Ö´æ´¢É豸ͳһÔÚÒ»¸öÖÎÀí½çÃæÏ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶CVSSÆÀ·ÖΪ9.1£¬£¬£¬ £¬£¬£¬£¬£¬¿É±»¹¥»÷ÕßÓÃÀ´½øÐб¾µØÈ¨ÏÞÌáÉýºÍɳºÐÌÓÒÝ£¬£¬£¬ £¬£¬£¬£¬£¬¿ÉÄܻᵼÖÂÐÅϢй¶»ò»Ø¾ø·þÎñ(DoS)¹¥»÷¡£¡£¡£¡£¡£¡£¡£Western DigitalµÄ²¼¸æ²¢Î´ÌṩÓйظ÷ì϶µÄ¾ßÌåÐÅÏ¢£¬£¬£¬ £¬£¬£¬£¬£¬Òò¶ø»¹²»Ã÷ÏÔÕâÊÇÒ»¸öÔÊÐí±¾µØÈ¨ÏÞÌáÉýµÄDLL½Ù³Ö·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬»¹ÊÇÒ»¸öÔÊÐí½Ó¼û·ÇÌØÈ¨Êý¾ÝµØÎ»µÄ·ì϶¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/western-digital-app-bug-gives-elevated-privileges-in-windows-macos/



°²È«¹¤¾ß


EvilSelenium


ÊÇÒ»¸ö½« Selenium±øÆ÷»¯ÒÔÀÄÓà Chrome µÄÐÂÏîÄ¿¡£¡£¡£¡£¡£¡£¡£


https://github.com/mrd0x/EvilSelenium/


wholeaked


ÊÇÒ»¸öÎļþ¹²Ïí¹¤¾ß£¬£¬£¬ £¬£¬£¬£¬£¬¿ÉÈÃÄúÔÚ²úÉúй©ʹØÒµ½ÕƹÜÈË¡£¡£¡£¡£¡£¡£¡£


https://github.com/utkusen/wholeaked


WSVuls


ºÅÁîÐй¤¾ß£¬£¬£¬ £¬£¬£¬£¬£¬×¨Îª¿ª·¢/²âÊÔÈËԱͨ¹ýµ¥¸öºÅÁî²âÊÔ·ì϶ºÍ·ÖÎöÍøÕ¾¶øÉè¼Æ¡£¡£¡£¡£¡£¡£¡£


https://github.com/anouarbensaad/wsvuls


AWS CloudSaga


ÓÃÓÚÔÚ Amazon Web Services (AWS) »·¾³ÖвâÊÔ°²È«½ÚÔìºÍ¾¯±¨¡£¡£¡£¡£¡£¡£¡£


https://github.com/awslabs/aws-cloudsaga#running-the-code



°²È«·ÖÎö


Windows 11 Ϊ USB Çý¶¯Æ÷Ôö³¤ÁË BitLocker ÅųýÕ½Êõ


https://www.bleepingcomputer.com/news/microsoft/windows-11-adds-a-bitlocker-exclusion-policy-for-usb-drives/


΢ÈíÌáÐÑ Internet Explorer ÔÚ 6 Ô¼´½«²Ã¼õ


https://www.bleepingcomputer.com/news/microsoft/microsoft-reminds-of-internet-explorers-looming-demise-in-june/


NIST ΪÔì×÷Ḛ́䲼 ICS ÍøÂ簲ȫָÄÏ


https://www.securityweek.com/nist-releases-ics-cybersecurity-guidance-manufacturers


д¹µö¹¤¾ß°ü¿ÉÓÃÀ´´´½¨ÐéαµÄ Chrome ä¯ÀÀÆ÷´°¿Ú


https://www.bleepingcomputer.com/news/security/new-phishing-toolkit-lets-anyone-create-fake-chrome-browser-windows/


CISA¡¢FBI ÖÒ¸æ¶Ô SATCOM ÍøÂ繩¸øÉ̵Ĺ¥»÷


https://www.hackread.com/targeting-satellite-cisa-fbi-warns-satcom-providers/


¶à¼ÒÆû³µÔì×÷ÉÌϰȾ Emotet


https://www.darkreading.com/attacks-breaches/multiple-automakers-infected-with-emotet