Fortinet¼ì²âµ½Deep Panda·Ö·¢Fire ChiliµÄ»î¶¯

°ä²¼¹¦·ò 2022-04-06

Fortinet¼ì²âµ½Deep Panda·Ö·¢Fire ChiliµÄ»î¶¯


3ÔÂ30ÈÕ£¬ £¬£¬£¬£¬ £¬Fortinet°ä²¼»ã±¨³ÆÆä¼ì²âµ½APT×éÖ¯Deep PandaµÄ¹¥»÷»î¶¯¡£¡£¡£¡£ ¡£¡£¸ÃÍÅ»ïÀûÓÃLog4Shell·ì϶¹¥»÷VMware Horizon·þÎñÆ÷£¬ £¬£¬£¬£¬ £¬×îÖÕÖ¼ÔÚ×°ÖÃÒ»¸öÃûΪFire ChiliµÄÐÂÐÍrootkit¡£¡£¡£¡£ ¡£¡£¸ÃrootkitʹÓÃFrostburn Studios£¨ÓÎÏ·¿ª·¢ÉÌ£©ºÍComodo£¨°²È«Èí¼þ£©µÄÖ¤Êé½øÐÐÊý×ÖÊðÃû£¬ £¬£¬£¬£¬ £¬Èƹý°²È«¼ì²â¡£¡£¡£¡£ ¡£¡£µ÷²éDeep Panda»î¶¯Ê±£¬ £¬£¬£¬£¬ £¬Fortinet·¢ÏÔìäÓëWinntiÓгÁµþ¡£¡£¡£¡£ ¡£¡£Õâ´Î»î¶¯ÖØÒªÕë¶Ô½ðÈÚ¡¢Ñ§Êõ¡¢»¯×±Æ·ºÍÓÎÀÀÐÐÒµ¡£¡£¡£¡£ ¡£¡£


https://www.fortinet.com/blog/threat-research/deep-panda-log4shell-fire-chili-rootkits



Kaspersky³ÆLazarusÀûÓÃľÂí»¯DeFi Wallet·Ö·¢ºóÃÅ


KasperskyÔÚ3ÔÂ31ÈÕ°ä²¼»ã±¨³Æ£¬ £¬£¬£¬£¬ £¬³¯ÏʺڿÍÍÅ»ïLazarusÔÚÀûÓÃľÂí»¯DeFiÀûÓ÷ַ¢ºóÃÅ¡£¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±½üÆÚ·¢ÏÖÒ»¸öľÂí»¯DeFi Wallet£¬ £¬£¬£¬£¬ £¬±àÒëÈÕÆÚΪ2021Äê11Ô£¬ £¬£¬£¬£¬ £¬Äܹ»ÔÚÖ¸±êϵͳÉÏ×°ÖÃÒ»¸öÖ°ÄÜÆëÈ«µÄºóÃÅ£¬ £¬£¬£¬£¬ £¬¸ÃºóÃżÙ×°³ÉÁËGoogle Chromeä¯ÀÀÆ÷¡£¡£¡£¡£ ¡£¡£Ä¿Ç°Éв»Ã÷ÏÔ¸ÃÀûÓõķַ¢²½Ö裬 £¬£¬£¬£¬ £¬´§Ä¦¿ÉÄÜÊÇ´¹µöÓʼþ»òͨ¹ýÉ罻ýÌå¡£¡£¡£¡£ ¡£¡£´Ë±í£¬ £¬£¬£¬£¬ £¬¹¥»÷ÕßʹÓÃÁËλÓÚº«¹úµÄ·þÎñÆ÷ÓëºóÃŽøÐÐͨѶ¡£¡£¡£¡£ ¡£¡£


https://securelist.com/lazarus-trojanized-defi-app/106195/



INKYÔÚ½üÆÚ·¢ÏÖÐÂÒ»ÂÖÀûÓÃCalendlyµÄ´¹µö¹¥»÷»î¶¯


¾ÝýÌå3ÔÂ31ÈÕ±¨Â·£¬ £¬£¬£¬£¬ £¬INKY×êÑÐÍŶӷ¢ÏÖÀûÓÃCalendlyµÄ´¹µö»î¶¯¡£¡£¡£¡£ ¡£¡£CalendlyÊÇÒ»¿îÊ¢ÐеÄÃâ·ÑÈÕÀúÀûÓ㬠£¬£¬£¬£¬ £¬¼¯³ÉÁËZoom£¬ £¬£¬£¬£¬ £¬¿ÉÓÃÓÚÆÌÅÅ»áÒéºÍÔ¼»á¡£¡£¡£¡£ ¡£¡£Õâ´Î»î¶¯Ê¼ÓÚ2Ôµ×£¬ £¬£¬£¬£¬ £¬¹¥»÷Õßͨ¹ýCalendlyƽ̨ÌìÉú´¹µöÓʼþ¡£¡£¡£¡£ ¡£¡£Ê×ÏÈÀûÓÃCalendlyÔö³¤×Ô½ç˵Á´½ÓµÄÖ°ÄܲåÈë¶ñÒâÁ´½Ó£¬ £¬£¬£¬£¬ £¬¸ÃÁ´½ÓǶÈëÔڲ鿴Îĵµ°´¼üÖУ¬ £¬£¬£¬£¬ £¬Óû§µã»÷ºó»á±»³Á¶¨Ïòµ½´¹µöÒ³Ãæ£¬ £¬£¬£¬£¬ £¬×îÖÕÇÔȡָ±êµÄMicrosoftµÇ¼ʹ´¦¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/calendly-actively-abused-in-microsoft-credentials-phishing/ 



PaloAlto Networks¶Ô¿Í»§ÌṩµÄ¼¼ÊõÖ§³ÖÐÅÏ¢Òâ±íй¶


ýÌå3ÔÂ31ÈÕ±¨Â·£¬ £¬£¬£¬£¬ £¬PaloAlto Networks(PAN) Ö§³ÖϵͳÖÐÅäÖÃÃýÎóµ¼Ö¿ͻ§µÄÃô¸ÐÐÅϢй¶¡£¡£¡£¡£ ¡£¡£¸ÃÎÊÌâÓÉPANµÄÒ»¸ö¿Í»§ÔÚ±¾Ô·¢ÏÖ£¬ £¬£¬£¬£¬ £¬Ëû³ÆÄܹ»¿´µ½Ô¼Äª1989¸ö²»ÊôÓÚËûÃǵÄ×éÖ¯µÄ¼¼ÊõÖ§³ÖÊÂÎñ¼Í¼£¬ £¬£¬£¬£¬ £¬ÆäÖÐÔ̺¬ÓÃÓÚÅųýÃýÎóµÄ·À»ðǽÈÕÖ¾¡¢ÅäÖÃת´¢ºÍÍøÂ簲ȫ×é(NSG)²¼¾ÖµÈ¡£¡£¡£¡£ ¡£¡£PAN°µÊ¾Ã»ÓÐÈκÎÊý¾Ý±»ÏÂÔØ£¬ £¬£¬£¬£¬ £¬²¢°µÊ¾Õâ´Îй¶ÊÂÎñµÄÁìÓò½öÏÞÓÚһλ¿Í»§¡£¡£¡£¡£ ¡£¡£¾ÝϤ£¬ £¬£¬£¬£¬ £¬¸ÃÎÊÌâµÄ½¨¸´Ô¼Äª±ØÒª8Ì칦·ò¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/palo-alto-networks-error-exposed-customer-support-cases-attachments/



Aqua°ä²¼Õë¶ÔJupyter NotebookµÄÀÕË÷Èí¼þµÄ·ÖÎö»ã±¨


Aqua SecurityÓÚ3ÔÂ29ÈÕ°ä²¼ÁËÕë¶ÔJupyterµÄ»ùÓÚPythonµÄÀÕË÷Èí¼þµÄ·ÖÎö»ã±¨¡£¡£¡£¡£ ¡£¡£Jupyter NotebookÊÇÊý¾ÝרҵÈËÔ±ÓÃÀ´´¦ÖÃÊý¾Ý¡¢±àдºÍÖ´ÐдúÂëÒÔ¼°¿ÉÊÓ»¯Á˾ֵĿªÔ´WebÀûÓᣡ£¡£¡£ ¡£¡£¹¥»÷ÕßÊ×ÏÈͨ¹ýÅäÖÃÃýÎóµÄÀûÓýӼû·þÎñÆ÷£¬ £¬£¬£¬£¬ £¬ÏÂÔØÓÃÓÚ¹¥»÷µÄ¿âºÍ¹¤¾ß£¨ÀýÈç¼ÓÃÜ·¨Ê½£©£¬ £¬£¬£¬£¬ £¬¶øºóͨ¹ýÕ³ÌùPython´úÂë²¢Ö´Ðо籾ÊÖ¶¯´´½¨ÀÕË÷Èí¼þ¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßµÄÉí·ÝÉв»Ã÷È·£¬ £¬£¬£¬£¬ £¬×êÑÐÈËÔ±ÒÔΪ¿ÉÄÜÓë¶íÂÞ˹µÄºÚ¿ÍÍÅ»ïÓйء£¡£¡£¡£ ¡£¡£


https://blog.aquasec.com/python-ransomware-jupyter-notebook



Lab52°ä²¼ÓëTurlaÓйصÄAndroid¼äµýÈí¼þµÄ¼¼Êõ»ã±¨


4ÔÂ1ÈÕ£¬ £¬£¬£¬£¬ £¬Lab52°ä²¼ÓëTurlaÓйصÄAndroid¼äµýÈí¼þµÄ¼¼Êõ»ã±¨¡£¡£¡£¡£ ¡£¡£½üÆÚ£¬ £¬£¬£¬£¬ £¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÃûΪProcess ManagerµÄ¶ñÒâAPK¡£¡£¡£¡£ ¡£¡£Ò»µ©×°Ö㬠£¬£¬£¬£¬ £¬Ëü»áʹÓóÝÂÖÐÎͼ±ê°µ²ØÔÚAndroidÉ豸ÉÏ£¬ £¬£¬£¬£¬ £¬¼Ù×°³Éϵͳ×é¼þ£¬ £¬£¬£¬£¬ £¬²¢ÒªÇó»ñÈ¡É豸µÄµØÎ»¡¢·¢ËͺÍÔĶÁÎı¾¡¢½Ó¼û´æ´¢¡¢Ê¹ÓÃÏà»úÅÄÕÕÒÔ¼°Â¼ÔìÒôƵµÈ18ÏîȨÏÞ¡£¡£¡£¡£ ¡£¡£Ëü»¹»áÏÂÔØÆäËüµÄpayload£¬ £¬£¬£¬£¬ £¬ÀýÈçRoz Dhan£¬ £¬£¬£¬£¬ £¬¸Ã¼äµýÈí¼þ¿ÉÄÜ»áͨ¹ý´ËÖÖ·½Ê½£¬ £¬£¬£¬£¬ £¬×¬È¡ÍƼöÀûÓõÄÓ¶½ð¡£¡£¡£¡£ ¡£¡£


https://lab52.io/blog/complete-dissection-of-an-apk-with-a-suspicious-c2-server/




°²È«¹¤¾ß


Socid-Extractor


´ÓÓ×ÎÒ×ÊÁÏÍøÒ³/API ÏìÓ¦ÖÐÌáÈ¡ÓйØÓû§µÄÐÅÏ¢£¬ £¬£¬£¬£¬ £¬²¢½«Æä±£ÁôΪ»úе¿É¶ÁÌåʽ¡£¡£¡£¡£ ¡£¡£


https://github.com/soxoj/socid-extractor


GitBleed Tools


ÓÃÓÚ´Ó¾µÏñ git ´æ´¢¿âÖÐÌáÈ¡Êý¾Ý¡£¡£¡£¡£ ¡£¡£


https://github.com/nightwatchcybersecurity/gitbleed_tools


ggshield


ÊÇÒ»¸ö CLI ÀûÓ÷¨Ê½£¬ £¬£¬£¬£¬ £¬¼ì²âÔ´´úÂëÖеÄÃÜÂë¡£¡£¡£¡£ ¡£¡£


https://github.com/GitGuardian/ggshield


PackMyPayload


ÓÃÓÚ½«payload´ò°üµ½×÷Ϊ´æµµ/ÈÝÆ÷µÄÊä³öÎļþÖÓ×£¡£¡£¡£ ¡£¡£


https://securityonline.info/packmypayload-packages-payloads-into-output-containers/




°²È«·ÖÎö


ºÚ¿ÍÂÛ̳ÉÏÏúÊÛµÄРBlackGuard ÃÜÂëÇÔÈ¡¶ñÒâÈí¼þ


https://www.bleepingcomputer.com/news/security/new-blackguard-password-stealing-malware-sold-on-hacker-forums/


FORCEDENTRY£ºÉ³ºÐÌÓÒÝ


https://googleprojectzero.blogspot.com/2022/03/forcedentry-sandbox-escape.html


Microsoft Build ½«ÓÚ 5 Ô 24 ÈÕÆô¶¯


https://news.softpedia.com/news/microsoft-build-will-kick-off-on-may-24-535139.shtml


Atento³ÆÈ¥ÄêµÄLockBitÀÕË÷¹¥»÷Ôì³É4200ÍòÃÀÔªËðʧ


https://www.bleepingcomputer.com/news/security/lockbit-victim-estimates-cost-of-ransomware-attack-to-be-42-million/


Anonymous¹¥»÷¶íÂÞ˹Ͷ×ʹ«Ë¾Thozis Corp


https://securityaffairs.co/wordpress/129651/hacktivism/anonymous-hacked-thozis-corp.html


ÍøÂç´¹µöʹÓà Azure ¾²Ì¬ÍøÒ³¼ÙÒâ΢Èí


https://www.bleepingcomputer.com/news/microsoft/phishing-uses-azure-static-web-pages-to-impersonate-microsoft/