Fortinet¼ì²âµ½Deep Panda·Ö·¢Fire ChiliµÄ»î¶¯
°ä²¼¹¦·ò 2022-04-06Fortinet¼ì²âµ½Deep Panda·Ö·¢Fire ChiliµÄ»î¶¯
3ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬Fortinet°ä²¼»ã±¨³ÆÆä¼ì²âµ½APT×éÖ¯Deep PandaµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÀûÓÃLog4Shell·ì϶¹¥»÷VMware Horizon·þÎñÆ÷£¬£¬£¬£¬£¬£¬×îÖÕÖ¼ÔÚ×°ÖÃÒ»¸öÃûΪFire ChiliµÄÐÂÐÍrootkit¡£¡£¡£¡£¡£¡£¸ÃrootkitʹÓÃFrostburn Studios£¨ÓÎÏ·¿ª·¢ÉÌ£©ºÍComodo£¨°²È«Èí¼þ£©µÄÖ¤Êé½øÐÐÊý×ÖÊðÃû£¬£¬£¬£¬£¬£¬Èƹý°²È«¼ì²â¡£¡£¡£¡£¡£¡£µ÷²éDeep Panda»î¶¯Ê±£¬£¬£¬£¬£¬£¬Fortinet·¢ÏÔìäÓëWinntiÓгÁµþ¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÖØÒªÕë¶Ô½ðÈÚ¡¢Ñ§Êõ¡¢»¯×±Æ·ºÍÓÎÀÀÐÐÒµ¡£¡£¡£¡£¡£¡£
https://www.fortinet.com/blog/threat-research/deep-panda-log4shell-fire-chili-rootkits
Kaspersky³ÆLazarusÀûÓÃľÂí»¯DeFi Wallet·Ö·¢ºóÃÅ
KasperskyÔÚ3ÔÂ31ÈÕ°ä²¼»ã±¨³Æ£¬£¬£¬£¬£¬£¬³¯ÏʺڿÍÍÅ»ïLazarusÔÚÀûÓÃľÂí»¯DeFiÀûÓ÷ַ¢ºóÃÅ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±½üÆÚ·¢ÏÖÒ»¸öľÂí»¯DeFi Wallet£¬£¬£¬£¬£¬£¬±àÒëÈÕÆÚΪ2021Äê11Ô£¬£¬£¬£¬£¬£¬Äܹ»ÔÚÖ¸±êϵͳÉÏ×°ÖÃÒ»¸öÖ°ÄÜÆëÈ«µÄºóÃÅ£¬£¬£¬£¬£¬£¬¸ÃºóÃżÙ×°³ÉÁËGoogle Chromeä¯ÀÀÆ÷¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔ¸ÃÀûÓõķַ¢²½Ö裬£¬£¬£¬£¬£¬´§Ä¦¿ÉÄÜÊÇ´¹µöÓʼþ»òͨ¹ýÉ罻ýÌå¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËλÓÚº«¹úµÄ·þÎñÆ÷ÓëºóÃŽøÐÐͨѶ¡£¡£¡£¡£¡£¡£
https://securelist.com/lazarus-trojanized-defi-app/106195/
INKYÔÚ½üÆÚ·¢ÏÖÐÂÒ»ÂÖÀûÓÃCalendlyµÄ´¹µö¹¥»÷»î¶¯
¾ÝýÌå3ÔÂ31ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬INKY×êÑÐÍŶӷ¢ÏÖÀûÓÃCalendlyµÄ´¹µö»î¶¯¡£¡£¡£¡£¡£¡£CalendlyÊÇÒ»¿îÊ¢ÐеÄÃâ·ÑÈÕÀúÀûÓ㬣¬£¬£¬£¬£¬¼¯³ÉÁËZoom£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚÆÌÅÅ»áÒéºÍÔ¼»á¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯Ê¼ÓÚ2Ôµף¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýCalendlyƽ̨ÌìÉú´¹µöÓʼþ¡£¡£¡£¡£¡£¡£Ê×ÏÈÀûÓÃCalendlyÔö³¤×Ô½ç˵Á´½ÓµÄÖ°ÄܲåÈë¶ñÒâÁ´½Ó£¬£¬£¬£¬£¬£¬¸ÃÁ´½ÓǶÈëÔڲ鿴Îĵµ°´¼üÖУ¬£¬£¬£¬£¬£¬Óû§µã»÷ºó»á±»³Á¶¨Ïòµ½´¹µöÒ³Ãæ£¬£¬£¬£¬£¬£¬×îÖÕÇÔȡָ±êµÄMicrosoftµÇ¼ʹ´¦¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/calendly-actively-abused-in-microsoft-credentials-phishing/
PaloAlto Networks¶Ô¿Í»§ÌṩµÄ¼¼ÊõÖ§³ÖÐÅÏ¢Òâ±íй¶
ýÌå3ÔÂ31ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬PaloAlto Networks(PAN) Ö§³ÖϵͳÖÐÅäÖÃÃýÎóµ¼Ö¿ͻ§µÄÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâÓÉPANµÄÒ»¸ö¿Í»§ÔÚ±¾Ô·¢ÏÖ£¬£¬£¬£¬£¬£¬Ëû³ÆÄܹ»¿´µ½Ô¼Äª1989¸ö²»ÊôÓÚËûÃǵÄ×éÖ¯µÄ¼¼ÊõÖ§³ÖÊÂÎñ¼Í¼£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÓÃÓÚÅųýÃýÎóµÄ·À»ðǽÈÕÖ¾¡¢ÅäÖÃת´¢ºÍÍøÂ簲ȫ×é(NSG)²¼¾ÖµÈ¡£¡£¡£¡£¡£¡£PAN°µÊ¾Ã»ÓÐÈκÎÊý¾Ý±»ÏÂÔØ£¬£¬£¬£¬£¬£¬²¢°µÊ¾Õâ´Îй¶ÊÂÎñµÄÁìÓò½öÏÞÓÚһλ¿Í»§¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬¸ÃÎÊÌâµÄ½¨¸´Ô¼Äª±ØÒª8Ì칦·ò¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/palo-alto-networks-error-exposed-customer-support-cases-attachments/
Aqua°ä²¼Õë¶ÔJupyter NotebookµÄÀÕË÷Èí¼þµÄ·ÖÎö»ã±¨
Aqua SecurityÓÚ3ÔÂ29ÈÕ°ä²¼ÁËÕë¶ÔJupyterµÄ»ùÓÚPythonµÄÀÕË÷Èí¼þµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£Jupyter NotebookÊÇÊý¾ÝרҵÈËÔ±ÓÃÀ´´¦ÖÃÊý¾Ý¡¢±àдºÍÖ´ÐдúÂëÒÔ¼°¿ÉÊÓ»¯Á˾ֵĿªÔ´WebÀûÓᣡ£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈͨ¹ýÅäÖÃÃýÎóµÄÀûÓýӼû·þÎñÆ÷£¬£¬£¬£¬£¬£¬ÏÂÔØÓÃÓÚ¹¥»÷µÄ¿âºÍ¹¤¾ß£¨ÀýÈç¼ÓÃÜ·¨Ê½£©£¬£¬£¬£¬£¬£¬¶øºóͨ¹ýÕ³ÌùPython´úÂë²¢Ö´Ðо籾ÊÖ¶¯´´½¨ÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßµÄÉí·ÝÉв»Ã÷È·£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÒÔΪ¿ÉÄÜÓë¶íÂÞ˹µÄºÚ¿ÍÍÅ»ïÓйء£¡£¡£¡£¡£¡£
https://blog.aquasec.com/python-ransomware-jupyter-notebook
Lab52°ä²¼ÓëTurlaÓйصÄAndroid¼äµýÈí¼þµÄ¼¼Êõ»ã±¨
4ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬Lab52°ä²¼ÓëTurlaÓйصÄAndroid¼äµýÈí¼þµÄ¼¼Êõ»ã±¨¡£¡£¡£¡£¡£¡£½üÆÚ£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÃûΪProcess ManagerµÄ¶ñÒâAPK¡£¡£¡£¡£¡£¡£Ò»µ©×°Ö㬣¬£¬£¬£¬£¬Ëü»áʹÓóÝÂÖÐÎͼ±ê°µ²ØÔÚAndroidÉ豸ÉÏ£¬£¬£¬£¬£¬£¬¼Ù×°³Éϵͳ×é¼þ£¬£¬£¬£¬£¬£¬²¢ÒªÇó»ñÈ¡É豸µÄµØÎ»¡¢·¢ËͺÍÔĶÁÎı¾¡¢½Ó¼û´æ´¢¡¢Ê¹ÓÃÏà»úÅÄÕÕÒÔ¼°Â¼ÔìÒôƵµÈ18ÏîȨÏÞ¡£¡£¡£¡£¡£¡£Ëü»¹»áÏÂÔØÆäËüµÄpayload£¬£¬£¬£¬£¬£¬ÀýÈçRoz Dhan£¬£¬£¬£¬£¬£¬¸Ã¼äµýÈí¼þ¿ÉÄÜ»áͨ¹ý´ËÖÖ·½Ê½£¬£¬£¬£¬£¬£¬×¬È¡ÍƼöÀûÓõÄÓ¶½ð¡£¡£¡£¡£¡£¡£
https://lab52.io/blog/complete-dissection-of-an-apk-with-a-suspicious-c2-server/
°²È«¹¤¾ß
Socid-Extractor
´ÓÓ×ÎÒ×ÊÁÏÍøÒ³/API ÏìÓ¦ÖÐÌáÈ¡ÓйØÓû§µÄÐÅÏ¢£¬£¬£¬£¬£¬£¬²¢½«Æä±£ÁôΪ»úе¿É¶ÁÌåʽ¡£¡£¡£¡£¡£¡£
https://github.com/soxoj/socid-extractor
GitBleed Tools
ÓÃÓÚ´Ó¾µÏñ git ´æ´¢¿âÖÐÌáÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£
https://github.com/nightwatchcybersecurity/gitbleed_tools
ggshield
ÊÇÒ»¸ö CLI ÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬¼ì²âÔ´´úÂëÖеÄÃÜÂë¡£¡£¡£¡£¡£¡£
https://github.com/GitGuardian/ggshield
PackMyPayload
ÓÃÓÚ½«payload´ò°üµ½×÷Ϊ´æµµ/ÈÝÆ÷µÄÊä³öÎļþÖÓ×£¡£¡£¡£¡£¡£
https://securityonline.info/packmypayload-packages-payloads-into-output-containers/
°²È«·ÖÎö
ºÚ¿ÍÂÛ̳ÉÏÏúÊÛµÄРBlackGuard ÃÜÂëÇÔÈ¡¶ñÒâÈí¼þ
https://www.bleepingcomputer.com/news/security/new-blackguard-password-stealing-malware-sold-on-hacker-forums/
FORCEDENTRY£ºÉ³ºÐÌÓÒÝ
https://googleprojectzero.blogspot.com/2022/03/forcedentry-sandbox-escape.html
Microsoft Build ½«ÓÚ 5 Ô 24 ÈÕÆô¶¯
https://news.softpedia.com/news/microsoft-build-will-kick-off-on-may-24-535139.shtml
Atento³ÆÈ¥ÄêµÄLockBitÀÕË÷¹¥»÷Ôì³É4200ÍòÃÀÔªËðʧ
https://www.bleepingcomputer.com/news/security/lockbit-victim-estimates-cost-of-ransomware-attack-to-be-42-million/
Anonymous¹¥»÷¶íÂÞ˹Ͷ×ʹ«Ë¾Thozis Corp
https://securityaffairs.co/wordpress/129651/hacktivism/anonymous-hacked-thozis-corp.html
ÍøÂç´¹µöʹÓà Azure ¾²Ì¬ÍøÒ³¼ÙÒâ΢Èí
https://www.bleepingcomputer.com/news/microsoft/phishing-uses-azure-static-web-pages-to-impersonate-microsoft/


¾©¹«Íø°²±¸11010802024551ºÅ