TA544ÀûÓÃWikiLoaderÕë¶ÔÒâ´óÀûµÄÆóÒµ·Ö·¢Ursnif

°ä²¼¹¦·ò 2023-08-02

1¡¢TA544ÀûÓÃWikiLoaderÕë¶ÔÒâ´óÀûµÄÆóÒµ·Ö·¢Ursnif


ProofpointÔÚ7ÔÂ31ÈÕÅû¶ÁËÀûÓÃжñÒâÈí¼þWikiLoaderÕë¶ÔÒâ´óÀûÆóÒµµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£WikiLoaderÊÇÒ»¸ö¸´ÔÓµÄÏÂÔØ·¨Ê½£¬£¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚËü»áÏòWikipedia·¢³öÒªÇ󲢲鳭ÏìÓ¦ÄÚÈÝÖÐÊÇ·ñÔ̺¬×Ö·û´®¡°The Free¡±¶øµÃÃû¡£¡£¡£¡£¡£ProofpointÓÚ2022Äê12ÔÂ27ÈÕ³õ´ÎÔÚÒ°±í¼ì²âµ½¸Ã¶ñÒâÈí¼þ£¬£¬£¬ £¬£¬£¬£¬£¬ÓÉTA544´«²¼¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬ £¬£¬£¬£¬£¬ÖÁÉÙÓÐ8¸ö»î¶¯ÔÚ·Ö·¢WikiLoader£¬£¬£¬ £¬£¬£¬£¬£¬À´×ÔTA544ºÍTA551£¬£¬£¬ £¬£¬£¬£¬£¬¾ùÕë¶ÔÒâ´óÀûµÄ×éÖ¯¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬£¬£¬¹ÌÈ»´óÎÞÊý¹¥»÷ÕßÒѲ»ÔÙʹÓÃÆôÓúêµÄÎĵ·´´«²¼¶ñÒâÈí¼þ£¬£¬£¬ £¬£¬£¬£¬£¬µ«TA544ÈÔÔÚ¹¥»÷Á´ÖÐʹÓÃËüÃÇ£¬£¬£¬ £¬£¬£¬£¬£¬Ô̺¬´«²¼WikiLoader¡£¡£¡£¡£¡£


https://www.proofpoint.com/us/blog/threat-insight/out-sandbox-wikiloader-digs-sophisticated-evasion


2¡¢ÃÀ¹úÒÂÊι«Ë¾Hot TopicÔ⵽ײ¿â¹¥»÷й¶¿Í»§µÄÐÅÏ¢


¾ÝýÌå8ÔÂ1ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬£¬£¬ÃÀ¹úÒÂÊμ°ÊÚȨÒôÀÖÁãÊÛÁ¬ËøµêHot Topicй©ÆäÔâµ½Á˶àÆð¹¥»÷ÊÂÎñ£¬£¬£¬ £¬£¬£¬£¬£¬µ¼Ö¿ͻ§µÄÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÃÀ¹úÕ¼ÓÐ675¼ÒÉ̵꣬£¬£¬ £¬£¬£¬£¬£¬ÒÔ¼°Ã¿Ô½ü1000Íò½Ó¼ûÁ¿µÄÔÚÏßÉ̵ê¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ú¹ÊÍ˵£¬£¬£¬ £¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃÇÔÈ¡µÄÕÊ»§Í´´¦ÂŴνӼûÁËRewardsƽ̨£¬£¬£¬ £¬£¬£¬£¬£¬¿ÉÄÜ»ñµÃÁ˿ͻ§µÄÊý¾Ý¡£¡£¡£¡£¡£¾­µ÷²é£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÓÚ2023Äê2ÔÂ7ÈÕ¡¢3ÔÂ11ÈÕ¡¢5ÔÂ19ÈÕÖÁ21ÈÕ¡¢5ÔÂ27ÈÕÖÁ28ÈÕºÍ6ÔÂ18ÈÕÖÁ21ÈÕ£¬£¬£¬ £¬£¬£¬£¬£¬Ê¹ÓÃÓÐЧÕÊ»§Í´´¦¶ÔÍøÕ¾ºÍÒÆ¶¯ÀûÓÃÖ´ÐÐÁË×Ô¶¯¹¥»÷¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾£¬£¬£¬ £¬£¬£¬£¬£¬Hot Topic²»ÊÇй¶ƾ֤µÄÆðÔ´£¬£¬£¬ £¬£¬£¬£¬£¬µ«Ò²ÎÞ·¨ÕÒµ½ÆðÔ´¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/retail-chain-hot-topic-discloses-wave-of-credential-stuffing-attacks/


3¡¢Henry Ford HealthÔâ´¹µö¹¥»÷½ü17Íò»¼ÕßÐÅϢй¶


¾Ý7ÔÂ27ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬£¬£¬ÃÀ¹úµÄѧÊõÒ½ÁÆ»úHenry Ford Health³ÆÆä3ÃûÔ±¹¤Ôâµ½´¹µö¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬Ó°ÏìÁË168215¸ö»¼ÕßµÄÐÅÏ¢¡£¡£¡£¡£¡£¸Ã»ú¹¹ÔÚÉêÃ÷ÖаµÊ¾£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÊÂÎñ²úÉúÓÚ3ÔÂ30ÈÕ£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã×éÖ¯Òѽ«±»Ó°ÏìµÄµç×ÓÓʼþÕÊ»§±£»£»£»£»£» £»£»¤ÆðÀ´²¢·¢Õ¹µ÷²é¡£¡£¡£¡£¡£5ÔÂ16£¬£¬£¬ £¬£¬£¬£¬£¬È·¶¨»¼ÕߵĽ¡È«ÐÅÏ¢Ô̺¬ÔÚµç×ÓÓÊÏäÖУ¬£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜÒѱ»¹¥»÷ÕßÇÔÈ¡£¬£¬£¬ £¬£¬£¬£¬£¬Éæ¼°ÐÕÃû¡¢³¢ÊÔÊÒÁ˾֡¢ÊÖÊõÀàÐÍ¡¢Õï¶Ï¡¢µç»°ºÅÂë¡¢²¡ÀúºÅºÍÄÚ²¿¸ú×ٺŵÈÐÅÏ¢¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾£¬£¬£¬ £¬£¬£¬£¬£¬ËûÃÇÔÚÖ´Ðжî±íµÄ°²È«´ëÊ©£¬£¬£¬ £¬£¬£¬£¬£¬²¢½«ÎªÔ±¹¤Ìṩ°²È«Åàѵ¡£¡£¡£¡£¡£


https://www.bankinfosecurity.com/phishing-scam-affects-nearly-170k-henry-ford-health-patients-a-22672 


4¡¢Cado·¢ÏÖ¿ÉÕë¶ÔRedis·þÎñÆ÷µÄP2PInfectÈ䳿бäÌå


7ÔÂ31ÈÕ£¬£¬£¬ £¬£¬£¬£¬£¬Cado·¢ÏÖÁËÒ»ÖÖÕë¶ÔRedisµÄÐÂÐͶñÒâÈí¼þ»î¶¯¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ±»¿ª·¢Õß¶¨ÃûΪP2Pinfect£¬£¬£¬ £¬£¬£¬£¬£¬ÓÃRust¿ª·¢£¬£¬£¬ £¬£¬£¬£¬£¬³äÈν©Ê¬ÍøÂç´úÀí¡£¡£¡£¡£¡£×êÑÐÈËÔ±·ÖÎöµÄÑù±¾Ô̺¬Ò»¸öǶÈëʽPEÎļþÒÔ¼°Ò»¸öELF¶þ½øÔìÎļþ£¬£¬£¬ £¬£¬£¬£¬£¬Õâ½²ÁËÈ»WindowsºÍLinuxÖ®¼äÓµÓÐ¿çÆ½Ì¨¼æÈÝÐÔ¡£¡£¡£¡£¡£Ëü»¹ÀûÓø´ÔìÖ°ÄÜÀ´¹¥»÷RedisÊý¾Ý´æ´¢µÄÊ·ý¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬£¬£¬P2PinfectÊÔͼͨ¹ýCronδ¾­Éí·ÝÑéÖ¤µÄRCE»úÔì¹¥»÷RedisÖ÷»ú¡£¡£¡£¡£¡£¸Ã»î¶¯±³ºóµÄ¹¥»÷ÕßÉí·ÝÉв»Ã÷ÏÔ£¬£¬£¬ £¬£¬£¬£¬£¬P2PInfectµÄÖ÷ÕÅÒ²²»Ã÷ÏÔ¡£¡£¡£¡£¡£


https://www.cadosecurity.com/redis-p2pinfect/


5¡¢Minecraft mod·ì϶BleedingPipeÒѱ»´ó¹æÄ£ÀûÓÃ


ýÌå7ÔÂ31ÈÕ±¨Â·³Æ£¬£¬£¬ £¬£¬£¬£¬£¬ºÚ¿ÍÔÚÀûÓÃMinecraft modÖеÄRCE·ì϶BleedingPipeÔÚ·þÎñÆ÷ºÍ¿Í»§¶ËÖ´ÐжñÒâºÅÁ£¬£¬ £¬£¬£¬£¬£¬´Ó¶ø½ÚÔìÉ豸¡£¡£¡£¡£¡£BleedingPipe·ì϶×î³õÓÚ2022Äê3Ô±»ÀûÓ㬣¬£¬ £¬£¬£¬£¬£¬µ«ºÜ¿ì¾Í±»mod¿ª·¢Õß½¨¸´ÁË¡£¡£¡£¡£¡£È»¶øÔÚ7ÔÂÔçЩʱ³½£¬£¬£¬ £¬£¬£¬£¬£¬ForgeÂÛ̳µÄһƪÌû×ӳƣ¬£¬£¬ £¬£¬£¬£¬£¬ÓÐÈËÀûÓÃδ֪RCEÀ´´ó¹æÄ£ÇÔÈ¡Íæ¼ÒµÄDiscordºÍSteam»á»°cookie¡£¡£¡£¡£¡£½øÒ»²½×êÑз¢ÏÖ£¬£¬£¬ £¬£¬£¬£¬£¬¶à¸öMinecraft modÖÐÒ²´æÔÚBleedingPipe·ì϶¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚɨÃèÊܸ÷ì϶ӰÏìµÄMinecraft·þÎñÆ÷²¢Ö´Ðй¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬Òò¶ø½¨¸´·þÎñÆ÷ÉÏÒ×±»¹¥»÷µÄmodÖÁ¹Ø³ÁÒª¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-bleedingpipe-rce-to-target-minecraft-servers-players/


6¡¢Bahamutͨ¹ý¼ÙðµÄAndroidÀûÓÃSafeChatÇÔÊØÐÅÏ¢


7ÔÂ28ÈÕ£¬£¬£¬ £¬£¬£¬£¬£¬CYFIRMA³ÆÆä·¢ÏÖÁËÒ»¸ö¿ÉÒɵÄAndroid¶ñÒâÈí¼þ£¬£¬£¬ £¬£¬£¬£¬£¬¼Ù×°³ÉÐéαµÄ̸ÌìÀûÓÃSafeChat£¬£¬£¬ £¬£¬£¬£¬£¬ÇÔÈ¡ÊÖ»úµÄͨ»°¼Í¼¡¢¶ÌÐźÍGPSµØÎ»µÈÊý¾Ý¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ±»ÒÉ»óÊÇCoverlmµÄ±äÖÖ£¬£¬£¬ £¬£¬£¬£¬£¬»áÇÔÈ¡Telegram¡¢Signal¡¢WhatsApp¡¢ViberºÍFacebook MessengerµÈͨѶÀûÓõÄÊý¾Ý¡£¡£¡£¡£¡£¸Ã»î¶¯ÓëÓ¡¶ÈºÚ¿ÍÍÅ»ïBahamutÓйØ£¬£¬£¬ £¬£¬£¬£¬£¬ÖØÒªÍ¨¹ýWhatsAppÉϵÄÓã²æÊ½´¹µöÐÂÎŽøÐУ¬£¬£¬ £¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÄÏÑǵØÓò¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã»î¶¯ÓëÓ¡¶ÈµÄÁíÒ»¸öºÚ¿ÍÍÅ»ïDoNotµÄ»î¶¯ÓÐÀàËÆÖ®´¦¡£¡£¡£¡£¡£


https://www.cyfirma.com/outofband/apt-bahamut-targets-individuals-with-android-malware-using-spear-messaging/