LanceflyÀûÓúóÃÅMerdoor¹¥»÷ÄÏÑǺͶ«ÄÏÑǵÄ×éÖ¯

°ä²¼¹¦·ò 2023-05-17

1¡¢LanceflyÀûÓúóÃÅMerdoor¹¥»÷ÄÏÑǺͶ«ÄÏÑǵÄ×éÖ¯


SymantecÔÚ5ÔÂ15ÈÕÅû¶ÁËAPT×éÖ¯LanceflyÕë¶ÔÄÏÑǺͶ«ÄÏÑÇÈ·µ±¾Ö¡¢º½¿ÕºÍµçÐÅ×éÖ¯µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£×Ô2018ÄêÒÔÀ´£¬£¬ £¬£¬£¬ £¬£¬LanceflyÒ»ÏòÔÚÕë¶ÔÐԵĹ¥»÷»î¶¯Öзַ¢Òñ±ÎµÄ×Ô½ç˵ºóÃÅMerdoor£¬£¬ £¬£¬£¬ £¬£¬ÒÔÔÚÖ¸±êÍøÂçÉϳÉÁ¢ÓƾÃÐÔ¡¢Ö´ÐкÅÁîºÍ¼Í¼¼üÅÌ¡£¡£¡£¡£¡£Ò»µ©½øÈëÖ¸±êϵͳ£¬£¬ £¬£¬£¬ £¬£¬¹¥»÷Õ߾ͻáͨ¹ýDLL²àÔØ½«MerdoorºóÃÅ×¢ÈëºÏ·¨¹ý³Ìperfhost.exe»òsvchost.exe£¬£¬ £¬£¬£¬ £¬£¬Ö¼ÔÚÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬ £¬£¬¹¥»÷»î¶¯»¹Ê¹ÓÃÁ˸üа汾µÄZXShell rootkit¡£¡£¡£¡£¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/lancefly-merdoor-zxshell-custom-backdoor


2¡¢Check Point·¢ÏÖCamaro Dragon¹¥»÷Å·ÖÞ±í½»×éÖ¯µÄ»î¶¯


5ÔÂ16ÈÕ£¬£¬ £¬£¬£¬ £¬£¬Check Point³ÆÆä·¢ÏÖÁËCamaro Dragonͨ¹ýϰȾסլTP-Link·ÓÉÆ÷£¬£¬ £¬£¬£¬ £¬£¬À´¹¥»÷Å·ÖÞ±í½»ÊÂÎñ×éÖ¯µÄ»î¶¯¡£¡£¡£¡£¡£ÉÐδȷ¶¨¹¥»÷ÕßÈôºÎʹÓöñÒâ¹Ì¼þ¾µÏñϰȾTP-Link·ÓÉÆ÷£¬£¬ £¬£¬£¬ £¬£¬µ«¿ÉÄÜÊÇͨ¹ý·ì϶ÀûÓûò±©Á¦ÆÆ½âÖÎÀíԱʹ´¦¡£¡£¡£¡£¡£µ÷²é·¢ÏÖÁËÁ½¸öľÂí»¯¹Ì¼þ¾µÏñÑù±¾£¬£¬ £¬£¬£¬ £¬£¬ÓëºÏ·¨°æ±¾½øÐбÈÁ¦£¬£¬ £¬£¬£¬ £¬£¬·¢ÏÖÄں˺ÍuBoot²¿ÃÅÊÇÒ»ÑùµÄ¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬ £¬£¬£¬ £¬£¬¶ñÒâ¹Ì¼þʹÓÃÁËÒ»¸ö×Ô½ç˵µÄSquashFSÎļþϵͳ£¬£¬ £¬£¬£¬ £¬£¬¸ÃϵͳÔ̺¬¶î±íµÄ¶ñÒâÎļþ×é¼þ£¬£¬ £¬£¬£¬ £¬£¬×÷ΪHorse ShellºóÃŵÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£


https://research.checkpoint.com/2023/the-dragon-who-sold-his-camaro-analyzing-custom-router-implant/


3¡¢º½¿Õ¹«Ë¾airBaltic½«²¿Ãų˿͵ÄÔ¤Ô¼ÐÅÏ¢·¢Ë͸øÆäËûÈË


¾ÝýÌå5ÔÂ15ÈÕ±¨Â·£¬£¬ £¬£¬£¬ £¬£¬À­ÍÑάÑÇµÄÆì½¢º½¿Õ¹«Ë¾airBalticÒò¼¼ÊõÃýÎ󣬣¬ £¬£¬£¬ £¬£¬½«²¿Ãų˿͵ÄÔ¤Ô¼ÐÅÏ¢·¢Ë͸øÆäËû³Ë¿Í¡£¡£¡£¡£¡£5ÔÂ14ÈÕ£¬£¬ £¬£¬£¬ £¬£¬¶àÃûairBaltic³Ë¿Í³ÆÆäÊÕµ½ÁË·¢¸øÆäËûÈ˵ĵç×ÓÓʼþ¡£¡£¡£¡£¡£Ð¹Â¶ÐÅÏ¢Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚºÍÓʼþµØÖ·µÈ¡£¡£¡£¡£¡£airBalticй©¸ÃÊÂÎñ²¢·ÇÓÉÍøÂç¹¥»÷ÒýÆð£¬£¬ £¬£¬£¬ £¬£¬5ÔÂ12ÈÕ£¬£¬ £¬£¬£¬ £¬£¬ÔÚairBalticµÄÓʼþ·Ö·¢ÏµÍ³Öмì²âµ½ÄÚ²¿¼¼ÊõÎÊÌ⣬£¬ £¬£¬£¬ £¬£¬Òò¶øÉÙÊý³Ë¿Í£¨Ô¼Õ¼0.009%µÄÔ¤Ô¼£©ÊÕµ½ÁËÃýÎóµÄÓʼþ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/airline-exposes-passenger-info-to-others-due-to-a-technical-error/


4¡¢CiscoÅû¶RA GroupÕë¶ÔÃÀ¹úºÍº«¹ú¹«Ë¾µÄ¹¥»÷»î¶¯


Cisco TalosÓÚ5ÔÂ15ÈÕÅû¶ÁËÐÂÀÕË÷ÍÅ»ïRA GroupµÄ¹¥»÷»î¶¯£¬£¬ £¬£¬£¬ £¬£¬ÈëÇÖÁËÈý¸öÃÀ¹úµÄ×éÖ¯ºÍÒ»¸öº«¹úµÄ×éÖ¯¡£¡£¡£¡£¡£¸Ã»î¶¯ÖÁÉÙ´Ó4ÔÂ22ÈÕÆðÍ·»îÔ¾£¬£¬ £¬£¬£¬ £¬£¬Éæ¼°¶à¸ö´¹Ö±ÐÐÒµ£¬£¬ £¬£¬£¬ £¬£¬Ô̺¬ÔìÒ©¡¢±£ÏÕ¡¢²Æ¸»ÖÎÀíºÍÔì×÷¹«Ë¾¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁËй¶µÄÀÕË÷Èí¼þBabukµÄÔ´´úÂë¡£¡£¡£¡£¡£RA GroupµÄ¼ÓÃÜ·¨Ê½Ñ¡È¡¼äЪ¼ÓÃÜ£¬£¬ £¬£¬£¬ £¬£¬¼ÓÃÜÊý¾Ýʱ£¬£¬ £¬£¬£¬ £¬£¬»áʹÓÃcurve25519ºÍeSTREAM cipher hc-128Ëã·¨¡£¡£¡£¡£¡£×êÑÐÈËԱй©¸Ã»î¶¯Õý´¦ÓÚÔçÆÚ½×¶Î¡£¡£¡£¡£¡£


https://blog.talosintelligence.com/ra-group-ransomware/


5¡¢Academy MortgageÔâµ½BlackCatÍÅ»ïµÄÀÕË÷¹¥»÷


ýÌå5ÔÂ15ÈÕ±¨Â·£¬£¬ £¬£¬£¬ £¬£¬Academy MortgageÔâµ½ÁËÀÕË÷ÍÅ»ïBlackCatµÄ¹¥»÷¡£¡£¡£¡£¡£ÔÚÔÞ³ÉÖ§¸¶3850ÍòÃÀÔªÒÔ½â¾öÁª¹úÖ¸¿ØµÄ¼¸¸öԺ󣬣¬ £¬£¬£¬ £¬£¬Academy MortgageÓÖÔâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£¡£¡£5ÔÂ14ÈÕ£¬£¬ £¬£¬£¬ £¬£¬ÀÕË÷ÍŻォAcademy MortgageÔö³¤µ½ÆäÍøÕ¾£¬£¬ £¬£¬£¬ £¬£¬³ÆÆä»ñµÃÁË»úÃÜÊý¾Ý²¢³ï±¸°ä²¼£¬£¬ £¬£¬£¬ £¬£¬Ô̺¬¿Í»§/ºÏ×÷ͬ°éµÄÊý¾Ý¡¢Ó×ÎÒÐÅÏ¢¡¢²ÆÕþºÍ»úÃÜÊý¾ÝµÈ¡£¡£¡£¡£¡£¹¥»÷Õß»¹Ìáµ½Á˸ù«Ë¾Ö®Ç°µÄÂé·³£¬£¬ £¬£¬£¬ £¬£¬³ÆË¼¿¼µ½¹ó¹«Ë¾ÔÚ2022Äê12ÔÂÃæ¶ÔµÄÖ¸¿Ø£¬£¬ £¬£¬£¬ £¬£¬Êý¾Ýй¶¿ÉÄÜ»á¶Ô¹«Ë¾µÄÃûÓþºÍŵÑÔÔì³É¸²ÃðÐÔÓ°Ïì¡£¡£¡£¡£¡£BlackCat°µÊ¾¸Ã¹«Ë¾»Ø¾øÖ§¸¶ÈκÎÓöÈ¡£¡£¡£¡£¡£


https://www.databreaches.net/only-months-after-dealing-with-one-problem-academy-mortgage-gets-hit-with-a-ransomware-attack/


6¡¢Group-IB°ä²¼¹ØÓÚÀÕË÷Èí¼þQilinµÄ¼¼Êõ·ÖÎö»ã±¨


5ÔÂ15ÈÕ£¬£¬ £¬£¬£¬ £¬£¬Group-IB°ä²¼Á˹ØÓÚÀÕË÷Èí¼þQilinµÄRaaS·¨Ê½µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£Qilin£¬£¬ £¬£¬£¬ £¬£¬±ðÃûAgenda£¬£¬ £¬£¬£¬ £¬£¬ÔÚ2022Äê8Ô±»·¢ÏÖ£¬£¬ £¬£¬£¬ £¬£¬Ò»Ö¹Øë¶Ô¹Ø¼üÐÐÒµµÄ¹«Ë¾£¬£¬ £¬£¬£¬ £¬£¬Ê¹ÓÃRustºÍGo˵»°£¨Golang£©¿ª·¢µÄÀÕË÷Èí¼þ¡£¡£¡£¡£¡£3Ô£¬£¬ £¬£¬£¬ £¬£¬Group-IB·¢ÏÖQilinÔÚRaaSģʽÏÂÔË×÷£¬£¬ £¬£¬£¬ £¬£¬²¢ÎªÆä´ÓÊô×éÖ¯ÌṩÖÎÀíÃæ°å£¬£¬ £¬£¬£¬ £¬£¬·ÖΪargets¡¢Blogs¡¢Stuffers¡¢News¡¢PaymentsºÍFAQsµÈ²¿ÃÅ£¬£¬ £¬£¬£¬ £¬£¬ÒÔ¸üÓÐЧµØÖÎÀí¹¥»÷¡£¡£¡£¡£¡£¾ÝϤ£¬£¬ £¬£¬£¬ £¬£¬ÕâЩ´ÓÊô×éÖ¯¿É´Óÿ±ÊÊê½ðÖÐ׬ȡ80%ÖÁ85%µÄÊÕÒæ¡£¡£¡£¡£¡£


https://www.group-ib.com/blog/qilin-ransomware/