Win 11×îв¹¶¡µ¼ÖÂMalwarebytesÓëChrome²»¼æÈÝ

°ä²¼¹¦·ò 2023-06-16
1¡¢Win 11×îв¹¶¡µ¼ÖÂMalwarebytesÓëChrome²»¼æÈÝ


¾ÝýÌå6ÔÂ14ÈÕ±¨Â·£¬£¬£¬£¬£¬±¾Öܶþ°ä²¼µÄWindows 11 22H2 KB5027231ÀÛ»ý¸üÐÂÓ°ÏìÁËMalwarebytes¿Í»§ÏµÍ³ÉϵÄGoogle Chrome¡£¡£¡£¡£¡£¡£Ò»Î»ÖÎÀíԱ˵£¬£¬£¬£¬£¬×°ÖøüкóChromeä¯ÀÀÆ÷³öÏÖÎÊÌ⣬£¬£¬£¬£¬ÊÔͼͨ¹ýWSUS»Ø¹ö£¬£¬£¬£¬£¬ÊÂÎñ²é¿´Æ÷ÖÐÏÔʾ¡°catastrophic error¡±£¬£¬£¬£¬£¬²¢ÇÒWSUSÏÔʾ²»Äܻعö¡£¡£¡£¡£¡£¡£Chrome¹ý³ÌÏÖʵÉÏÔÚÔËÐУ¬£¬£¬£¬£¬µ«ÓÉÓÚì¶Ü¶øÎÞ·¨ÆëÈ«Æô¶¯ÀûÓ÷¨Ê½ºÍ¼ÓÔØÓû§½çÃæ¡£¡£¡£¡£¡£¡£Malwarebytes°µÊ¾£¬£¬£¬£¬£¬Win 11¸üе¼ÖÂChromeÓë·ì϶ÀûÓñ£»£» £»£»£»£»£»£»¤²úÉúì¶Ü£¬£¬£¬£¬£¬½ø¶øµ¼ÖÂä¯ÀÀÆ÷±ÀÀ£¡£¡£¡£¡£¡£¡£Óöµ½´ËÎÊÌâµÄÓû§Äܹ»´ÓÆäMalwarebytesÊܱ£»£» £»£»£»£»£»£»¤ÀûÓ÷¨Ê½ÁбíÖйعØÍøÂçä¯ÀÀÆ÷¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5027231-update-breaks-google-chrome-for-malwarebytes-users/


2¡¢ÃÀ¹ú¶à¸öµ±¾Ö»ú¹¹Ôâµ½ÀÕË÷ÍÅ»ïClopµÄ¹¥»÷


¾Ý6ÔÂ16ÈÕ±¨Â·£¬£¬£¬£¬£¬ÃÀ¹ú¶à¸öµ±¾Ö»ú¹¹Ôâµ½ÁËÀÕË÷ÍÅ»ïClopµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃÁËMOVEitÎļþ´«Ê乤¾ßÖеķì϶£¬£¬£¬£¬£¬CISA³ÆÆäÔÚºÍFBIÖÂÁ¦ÎªÊ¹ÓÃMOVEitµÄÁª¹ú»ú¹¹ÌṩԮÊÖ£¬£¬£¬£¬£¬È·ÈϹ¥»÷µÄÓ°Ï첢ʵʱ²¹¾È¡£¡£¡£¡£¡£¡£¹Ù·½»Ø¾øÐ¹Â©ÊÜÓ°ÏìµÄ»ú¹¹µÄÃû³ÆºÍÊýÁ¿£¬£¬£¬£¬£¬µ«Ò»Î»ÄÜÔ´²¿½²»°ÈËй©£¬£¬£¬£¬£¬¸Ã²¿ÃÅÊÇÔâµ½ÈëÇֵĶà¸öÁª¹ú»ú¹¹Ö®Ò»¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Ó¢¹úʯÓͺÍÌìÈ»Æø¹«Ë¾¿ÇÅÆÔÚ±¾ÖÜËÄй©ÆäÒ²Ôâµ½ÁËClopÀÕË÷¹¥»÷£¬£¬£¬£¬£¬¸Ã¹«Ë¾È¥ÄêµÄÊÕÈ볬¹ý3810ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£


https://therecord.media/several-us-federal-agencies-affected-by-moveit-breach


3¡¢HP¹«¿ªÃ÷¹ý¶ñÒâÍøÕ¾·Ö·¢ChromeÀ©´óShampooµÄ»î¶¯


6ÔÂ14ÈÕ±¨Â·£¬£¬£¬£¬£¬HP¹«¿ªÁËÒ»¸öÔÚ½øÐÐÖеÄÐÂChromeLoader»î¶¯¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Ê¼ÓÚ3Ô£¬£¬£¬£¬£¬Í¨¹ýÐû³Æ¿ÉÃâ·ÑÏÂÔØµÁ°æÒôÀÖ¡¢µçÓ°»òÓÎÏ·µÄ¶ñÒâÍøÕ¾·Ö·¢ChromeLoader¡£¡£¡£¡£¡£¡£ÓÕʹָ±êÏÂÔØÖ´ÐÐPowerShell¾ç±¾µÄVBScript£¬£¬£¬£¬£¬¸Ã¾ç±¾ÉèÖÃÒÔ¡°chrome_¡±ÎªÇ°×ºµÄ´òË㹤×÷¡£¡£¡£¡£¡£¡£´Ë¹¤×÷»á´¥·¢Ò»ÏµÁо籾£¬£¬£¬£¬£¬½«ÐµÄPowerShell¾ç±¾ÏÂÔØ²¢±£Áôµ½×¢²á±íÖУ¬£¬£¬£¬£¬Í¬Ê±»á»ñÈ¡¶ñÒâChromeÀ©´óShampoo¡£¡£¡£¡£¡£¡£ShampooÊÇChromeLoaderµÄ±äÌ壬£¬£¬£¬£¬¿ÉÄÜÔÚÖ¸±ê½Ó¼ûµÄÍøÕ¾ÉÏ×¢Èë¸æ°×²¢Ö´ÐÐËÑË÷²éÎʳÁ¶¨Ïò¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-shampoo-chromeloader-malware-pushed-via-fake-warez-sites/


4¡¢Trellix³ÆÐÂÇÔÈ¡·¨Ê½SkuldÕë¶ÔÅ·ÃÀºÍ¶«ÄÏÑǵȵØ


TrellixÔÚ6ÔÂ13ÈÕ³ÆÆä·¢ÏÖÁËÐÂÐÍGolangÇÔÈ¡·¨Ê½Skuld£¬£¬£¬£¬£¬ÒÑÈëÇÖÅ·ÖÞ¡¢¶«ÄÏÑǺÍÃÀ¹úµÄWindowsϵͳ¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ×Ô4ÔÂÏÂÑ®ÆðÍ··¢×÷£¬£¬£¬£¬£¬»áËÑË÷´æ´¢ÔÚDiscordºÍä¯ÀÀÆ÷µÅצÓÃÖеÄÊý¾Ý£¬£¬£¬£¬£¬ÒÔ¼°ÏµÍ³µÄÐÅÏ¢ºÍÎļþ¼ÐÖеÄÎļþ¡£¡£¡£¡£¡£¡£²¿ÃÅÑù±¾ÉõÖÁÔ̺¬ÇÔÈ¡¼ÓÃÜÇ®±ÒµÄÄ£¿£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬µ«×êÑÐÈËÔ±ÒÔΪ¸ÃÄ£¿£¿£¿£¿£¿£¿£¿£¿éÈÔÔÚ¿ª·¢ÖС£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬¿ª·¢ÈËÔ±Deathined´Ó¶à¸ö¿ªÔ´ÏîÄ¿ºÍ¶ñÒâÈí¼þÑù±¾ÖÐÂÞÖÂÁé¸Ð£¬£¬£¬£¬£¬½«Ö°ÄÜÒÆÖ²µ½GolangÀ´¹¹½¨Skuld¡£¡£¡£¡£¡£¡£


https://www.trellix.com/en-us/about/newsroom/stories/research/skuld-the-infostealer-that-speaks-golang.html


5¡¢Î¢Èí°ä²¼¹ØÓÚºÚ¿ÍÍÅ»ïCadet BlizzardµÄ·ÖÎö»ã±¨


6ÔÂ14ÈÕ£¬£¬£¬£¬£¬Î¢Èí°ä²¼Á˹ØÓÚºÚ¿ÍÍÅ»ïCadet BlizzardµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¾ÝÐÅ£¬£¬£¬£¬£¬¸Ã×éÖ¯ÓÚ2020ÄêÆðÍ·ÔËÓª£¬£¬£¬£¬£¬Óë¶íÂÞ˹GRUÓйØ£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÎÚ¿ËÀ¼È·µ±¾Ö·þÎñ¡¢·¨ÂÉ»ú¹¹¡¢·ÇͶ»ú/·Çµ±¾Ö×éÖ¯¡¢IT·þÎñÌṩÉÌ/Õ÷ѯ¹«Ë¾ºÍ´¹Î£·þÎñ¡£¡£¡£¡£¡£¡£²¢½«ÆäÓë2022Äê1ÔÂ13ÈÕÕë¶ÔÎÚ¿ËÀ¼µÄWhisperGate¹¥»÷ÁªÆðÀ´¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÔÚ2022Äê6ÔÂÖ®ºóÖð²½µ­³öÈËÃǵÄÊÓÏߣ¬£¬£¬£¬£¬µ«ÔÚ2023ËêÊ׳Áи¡³öË®Ãæ¡£¡£¡£¡£¡£¡£Î¢Èí°µÊ¾£¬£¬£¬£¬£¬ÓëAPT28ºÍSandwormµÈÆäËüGRUÓйغڿÍÍÅ»ïÏà±È£¬£¬£¬£¬£¬Cadet Blizzard¹¥»÷µÄ³É¹¦ÂÊÏà¶Ô½ÏµÍ¡£¡£¡£¡£¡£¡£


https://www.microsoft.com/en-us/security/blog/2023/06/14/cadet-blizzard-emerges-as-a-novel-and-distinct-russian-threat-actor/


6¡¢StairwellÅû¶ChamelGangÖ²È뷨ʽChamelDoHµÄϸ½Ú


6ÔÂ13ÈÕ£¬£¬£¬£¬£¬StairwellÅû¶ºÚ¿ÍÍÅ»ïChamelGangµÄÐÂÖ²È뷨ʽChamelDoHµÄϸ½Ú¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»ÖÖÓÃC++¿ª·¢µÄLinuxÖ²È뷨ʽ£¬£¬£¬£¬£¬ÓÃÓÚÔ¶³Ì½Ó¼ûÖ¸±êϵͳ£¬£¬£¬£¬£¬²¢Í¨¹ýDNS-over-HTTPS (DoH)Ëí·ÓëÅäÖõÄC2»ù´¡ÉèʩͨѶ¡£¡£¡£¡£¡£¡£ËùÓжñÒâÈí¼þµÄͨѶ¶¼Ê¹ÓÃAES128ºÍÅú¸ÄºóµÄbase64±àÂë¼ÓÃÜ£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬·Ç×ÖĸÊý×Ö×Ö·ûµÄ´úÌæ¡£¡£¡£¡£¡£¡£¸ÃÖ²Èë·¨Ê½ÍøÂçϵͳµÄÐÅÏ¢À´·ÖÎö±»Ï°È¾µÄÖ¸±ê£¬£¬£¬£¬£¬²¢¿ÉÄܽøÐиù»ùµÄÔ¶³Ì½Ó¼û½ÚÔ죬£¬£¬£¬£¬ÀýÈçÎļþÉÏ´«¡¢ÏÂÔØ¡¢É¾³ýºÍÖ´ÐС£¡£¡£¡£¡£¡£


https://stairwell.com/news/chamelgang-and-chameldoh-a-dns-over-https-implant/