APT36ÀûÓÃCrimsonRATбäÌå¹¥»÷Ó¡¶ÈµÄÓйػú¹¹

°ä²¼¹¦·ò 2022-04-01

APT36ÀûÓÃCrimsonRATбäÌå¹¥»÷Ó¡¶ÈµÄÓйػú¹¹


Cisco TalosÔÚ3ÔÂ29ÈÕ¹«¿ªÁËAPT36Õë¶ÔÓ¡¶Èµ±¾ÖºÍ¾üÊ»ú¹¹µÄл¡£¡£¡£¡£¡£¡£APT36ÓÖ³ÆTransparent Tribe£¬£¬ £¬£¬£¬£¬£¬×Ô2016ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬ £¬£¬£¬£¬£¬ÒÉËÆÓë°Í»ù˹̹ÓйØ¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÆðÍ·ÓÚ2021Äê6Ô£¬£¬ £¬£¬£¬£¬£¬ÀûÓÃαÔìµÄKavachÉí·ÝÈÏÖ¤ÀûÓ÷ַ¢¶ñÒâÈí¼þ£¬£¬ £¬£¬£¬£¬£¬Ó¡¶È±ØÒª½Ó¼ûÓʼþ·þÎñ»òÊý¾Ý¿âµÈIT×ÊÔ´µÄ¹Ù·½×éÖ¯µÄÔ±¹¤¿í·ºÊ¹ÓøÃÀûÓᣡ£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÈÔÔÚʹÓÃCrimsonRAT£¬£¬ £¬£¬£¬£¬£¬Æä2022°æ±¾ÐÂÔöÁ˶à¸öÖ°ÄÜ£¬£¬ £¬£¬£¬£¬£¬Èç¼üÅ̼ͼ¡¢ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâºÅÁîÒÔ¼°¶ÁÈ¡ºÍɾ³ýÎļþµÈ¡£¡£¡£¡£¡£¡£


https://blog.talosintelligence.com/2022/03/transparent-tribe-new-campaign.html


LAPSUS$»Ø¹é²¢Ð¹Â¶Èí¼þ¹«Ë¾Globant 70GBµÄÊý¾Ý


¾ÝýÌå3ÔÂ30ÈÕ±¨Â·£¬£¬ £¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïLAPSUS$ÔÚΪÆÚÒ»ÖܵĶÌÔÝͣϢºó°ä·¢»Ø¹é¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÔÚÆäTelegramƵ·ÉÏд·¡°ÎÒÃÇÕýʽ´Ó¼ÙÆÚ»ØÀ´ÁË¡±£¬£¬ £¬£¬£¬£¬£¬²¢°ä²¼ÁËÒ»¸öÎļþ¼ÐÁбíµÄ½ØÍ¼£¬£¬ £¬£¬£¬£¬£¬ÁгöÁËArcserve¡¢Banco Galicia¡¢BNP Paribas Cardif¡¢Citibanamex¡¢DHL¡¢FacebookºÍStifelµÈ¹«Ë¾¡£¡£¡£¡£¡£¡£Ëü»¹°ä²¼ÁËÒ»¸ötorrentÎļþ£¬£¬ £¬£¬£¬£¬£¬¾Ý³ÆÊÇGlobantÔ¼70GBµÄÊý¾Ý£¬£¬ £¬£¬£¬£¬£¬Ô̺¬Ô´´úÂëºÍ¸Ã¹«Ë¾AtlassianÌ×¼þÓйصÄÖÎÀíÔ±ÃÜÂë¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/03/lapsus-claims-to-have-breached-it-firm.html 


Morphisec·¢ÏÖÕë¶Ô¼ÓÄôó·Ö·¢Mars StealerµÄ»î¶¯


3ÔÂ29ÈÕ£¬£¬ £¬£¬£¬£¬£¬Morphisec¹«¿ªÁËÕë¶ÔMars StealerµÄ×îÐÂ×êÑÐÁ˾Ö¡£¡£¡£¡£¡£¡£Mars»ùÓھɵÄOski Stealer£¬£¬ £¬£¬£¬£¬£¬ÓÚ2021Äê6Ô³õ´Î·¢ÏÖ£¬£¬ £¬£¬£¬£¬£¬ÔÚRaccoon StealerºöÈ»¹Ø¹Øºó£¬£¬ £¬£¬£¬£¬£¬³ÉΪÆä´úÌæ¹æ»®¡£¡£¡£¡£¡£¡£Õâ´ÎлαÔ쿪Դ°ì¹«Ì×¼þOpenOfficeµÄ¹Ù·½ÍøÕ¾£¬£¬ £¬£¬£¬£¬£¬Ê¹ÓÃGoogle Ads¸æ°×ÓÕʹָ±ê½Ó¼û¸Ã¶ñÒâÍøÕ¾²¢ÏÂÔØMars Stealer¡£¡£¡£¡£¡£¡£ÓÉÓÚ±»µÁÐÅÏ¢µÄĿ¼ÒòÅäÖò»µ±¶øÎ¬³Ö¹«¿ªµÄ״̬£¬£¬ £¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖ·¢ÏÖ¾ø´óÎÞÊýÖ¸±êÀ´×Ô¼ÓÄô󡣡£¡£¡£¡£¡£


https://blog.morphisec.com/threat-research-mars-stealer


Wyze CamÉãÏñÍ·´æÔÚ¿ÉÓÃÀ´Ô¶³Ì½Ó¼ûSD¿¨ÄÚÈݵķì϶


ýÌå3ÔÂ29ÈÕ±¨Â·£¬£¬ £¬£¬£¬£¬£¬Wyze CamÍøÂçÉãÏñÍ·ÖдæÔÚ·ì϶¡£¡£¡£¡£¡£¡£¸Ã·ì϶δ·ÖÅäCVE ID£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³ÌÓû§Í¨¹ýÕìÌý¶Ë¿Ú80½Ó¼ûÏà»úÖÐSD¿¨µÄÄÚÈÝ£¬£¬ £¬£¬£¬£¬£¬ÇÒÎÞÐèÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£SD¿¨Í¨³£ÓÃÀ´´æ´¢ÊÓÆµ¡¢Í¼ÏñºÍÒôƵ¼Í¼¡£¡£¡£¡£¡£¡£ÔÚWyze Cam IoTÉϲåÈëSD¿¨ºó£¬£¬ £¬£¬£¬£¬£¬»áÔÚwwwĿ¼ÖÐ×Ô¶¯´´½¨Ö¸ÏòËüµÄ·ûºÅÁ´½Ó£¬£¬ £¬£¬£¬£¬£¬¸ÃĿ¼ÓÉweb·þÎñÆ÷Ìṩ·þÎñÇÒûÓÐÈκνӼûÏÞ¶È¡£¡£¡£¡£¡£¡£·ì϶ÓÉBitdefenderÓÚ2019Äê3Ô·¢ÏÖ²¢Éϱ¨£¬£¬ £¬£¬£¬£¬£¬Ö±µ½2022Äê1ÔÂ29Èղލ¸´¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/wyze-cam-flaw-lets-hackers-remotely-access-your-saved-videos/


ѹËõ·¨Ê½Zlib°ä²¼¸üУ¬£¬ £¬£¬£¬£¬£¬½¨¸´ÒÑ´æÔÚ17ÄêµÄ°²È«·ì϶


¾Ý3ÔÂ29ÈÕ±¨Â·£¬£¬ £¬£¬£¬£¬£¬Ñ¹Ëõ·¨Ê½Zlib½¨¸´ÁËÒÑ´æÔÚ17ÄêµÄ°²È«·ì϶¡£¡£¡£¡£¡£¡£GoogleµÄ×êÑÐÈËÔ±Tavis Ormandy·¢ÏÖZlibÖдæÔÚÒ»¸ö·ì϶£¬£¬ £¬£¬£¬£¬£¬ÔÚÉϱ¨Ê±·¢Ïָ÷ì϶ÔçÔÚ2018Äê¾Í±»»ã±¨²¢½¨¸´¹ý£¬£¬ £¬£¬£¬£¬£¬Æäʱ³ÆÆäÒÑ´æÔÚ13Äê¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬ £¬£¬£¬£¬£¬²»ÖªÎªºÎ2018Äê4ÔÂ20ÈÕÌá½»µÄ²¹¶¡²¢Ã»ÓгÉΪZlibµÄ¸üС£¡£¡£¡£¡£¡£Ö±µ½2022Äê03ÔÂ27ÈÕ£¬£¬ £¬£¬£¬£¬£¬¸Ã¿âµÄÉÏÒ»¸ö°æ±¾²ÅÔÚ2017Äê01ÔÂ15ÈÕ°ä²¼¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÔÚ±¾Öܲű»·ÖÅä±àºÅCVE-2018-25032£¬£¬ £¬£¬£¬£¬£¬µ±Ñ¹ËõijЩÊäÈëʱ»á³öÏÖÎÊÌ⣬£¬ £¬£¬£¬£¬£¬²¢´æÔÚDZÔڵĻº³åÇøÒç³öÎÊÌâ¡£¡£¡£¡£¡£¡£


https://nakedsecurity.sophos.com/2022/03/29/zlib-data-compressor-fixes-17-year-old-security-bug-patch-errr-now/


Symantec°ä²¼¹ØÓÚжñÒâÈí¼þVerbleconµÄ·ÖÎö»ã±¨


3ÔÂ29ÈÕ£¬£¬ £¬£¬£¬£¬£¬Symantec°ä²¼Á˹ØÓÚжñÒâÈí¼þVerbleconµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ½ñÄê1Ô·¢ÏÖÁËVerblecon£¬£¬ £¬£¬£¬£¬£¬ËüÒѱ»ÓÃÓÚ×°ÖüÓÃܿ󹤵ĻÖС£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»ùÓÚJava£¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚÆä´úÂëµÄ¶à̬ÐÔʹµÃÆäÑù±¾µÄ¼ì²âÂʺܵÍ¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»á²é³­ËüÊÇ·ñÔÚÐé¹¹»·¾³ÖÐÔËÐУ¬£¬ £¬£¬£¬£¬£¬¶øºó»ñÈ¡ÔÚÔËÐеĹý³ÌÁбíÒԲ鳭ÊÇ·ñÓÐÓëÐé¹¹»úϵͳÓйصÄÎļþ£¬£¬ £¬£¬£¬£¬£¬ËùÓв鳭¶¼Í¨¹ýºó»á½«×ÔÉí¸´Ôìµ½±¾µØÄ¿Â¼£¨%ProgramData%¡¢%LOCALAPPDATA%¡¢Users£©£¬£¬ £¬£¬£¬£¬£¬²¢¶¨ÆÚ³¢ÊÔÏνÓÓòÃûhxxps://gaymers[.]ax/ºÍhxxp://[DGA_NAME][.]tk/¡£¡£¡£¡£¡£¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/verblecon-sophisticated-malware-cryptocurrency-mining-discord





°²È«¹¤¾ß


Privid


¼à¿ØÊÓÆµ·ÖÎöϵͳ£¬£¬ £¬£¬£¬£¬£¬¿ÉÄÜÒÔ± £»£»£»£»£»£»¤ÒþÖԵķ½Ê½½øÐÐÊÓÆµ·ÖÎö£¬£¬ £¬£¬£¬£¬£¬ÒÔÓ¦¶ÔÇÖÈëÐÔ¸ú×ÙµÄÓÇÓô¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/03/privid-privacy-preserving-surveillance.html


Live Forensicator


ÓÃÓÚÔ®ÊÖʵʱȡ֤ºÍÊÂÎñÏìÓ¦µÄ POWERSHELL ¾ç±¾¡£¡£¡£¡£¡£¡£


https://github.com/Johnng007/Live-Forensicator#dependencies


nettrust


ÊÇÒ»¸ö¶¯Ì¬µÄ³öÕ¾·À»ðǽÊÚȨÆ÷¡£¡£¡£¡£¡£¡£


https://github.com/ulfox/nettrust




°²È«·ÖÎö


Google Chrome 100 °ä²¼£¬£¬ £¬£¬£¬£¬£¬Ô̺¬ÐÂÖ°ÄÜ¡¢Í¼±êµÈ


https://www.bleepingcomputer.com/news/google/google-chrome-100-released-with-new-features-icon-and-more/


ÈôºÎ½« Wslink ¶ñÒâÈí¼þ¼ÓÔØ·¨Ê½ÓÃÓÚ»ìºÏµÄÐé¹¹»ú


https://thehackernews.com/2022/03/experts-detail-virtual-machine-used-by.html


Yandex ÔÚÏò¶íÂÞ˹·¢ËÍ iOS Óû§Êý¾Ý


https://www.infosecurity-magazine.com/news/yandex-is-sending-ios-users-data/


´óÁ¿¿ó¹¤ºÍºóÃÅÀûÓà Log4J ¹¥»÷ VMware Horizon ·þÎñÆ÷


https://news.sophos.com/en-us/2022/03/29/horde-of-miner-bots-and-backdoors-leveraged-log4j-to-attack-vmware-horizon-servers/


Proofpoint·¢ÏÖÕë¶ÔÃÀ¹ú½ÌÓýÐÐÒµµÄ´ó¹æÄ£´¹µö»î¶¯


https://www.proofpoint.com/us/blog/threat-insight/school-hard-knocks-job-fraud-threats-target-university-students