MonikerLink ·ì϶ʹ Outlook Óû§Ãæ¶ÔÊý¾Ý͵ÇԺͶñÒâÈí¼þµÄÍþв

°ä²¼¹¦·ò 2024-02-19

1. MonikerLink ·ì϶ʹ Outlook Óû§Ãæ¶ÔÊý¾Ý͵ÇԺͶñÒâÈí¼þµÄÍþв


2ÔÂ17ÈÕ£¬£¬£¬ £¬ £¬ £¬Check Point Research (CPR) ·¢ÏÖMicrosoft OutlookÖдæÔÚÑϳÁ°²È«·ì϶¡£¡£¡£¡£¡£¡£±»³ÆÎª#MonikerLink£»£»£» £»£»¸Ã·ì϶ÔÊÐíÍþвÐÐΪÕßÔÚÆäÖ¸±êÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£²©¿ÍÎÄÕÂÖоßÌå½éÉÜÁËÕâÏî×êÑУ¬£¬£¬ £¬ £¬ £¬Ç¿µ÷Á˸÷ì϶¿ÉÄÜ»áÀûÓà Outlook ´¦ÖÃijЩ³¬Á´½ÓµÄ·½Ê½¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»¸ú×ÙΪCVE-2024-21413£¬£¬£¬ £¬ £¬ £¬ CVSS ÆÀ·ÖΪ 9.8£¨Âú·Ö 10£©£¬£¬£¬ £¬ £¬ £¬ÕâÒâζן÷ì϶ӵÓÐÑϳÁÑϳÁÐÔÇҸ߶ȿÉÀûÓ㬣¬£¬ £¬ £¬ £¬¿ÉÄÜÔÊÐí¹¥»÷Õßͨ¹ýÖÁÉÙµÄÓû§½»»¥À´·ÛËéϵͳ¡£¡£¡£¡£¡£¡£Õâ¿ÉÄܻᵼÖÂϵͳÆëÈ«ÊÜË𡢻ؾø·þÎñºÍÊý¾Ýй¶¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬ £¬ £¬¹¥»÷ÕßÄܹ»Ö´ÐÐËÁÒâ´úÂë¡¢ÇÔÈ¡Êý¾ÝºÍ×°ÖöñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâµÄ²úÉúÊÇÓÉÓÚ Outlook ´¦Öá°file://¡±³¬Á´½ÓµÄ·½Ê½Ôì³ÉµÄ£¬£¬£¬ £¬ £¬ £¬´Ó¶øµ¼ÖÂÑϳÁµÄ°²È«Òþ»¼¡£¡£¡£¡£¡£¡£Íþв²Î¼ÓÕßÄܹ»ÔÚÖ¸±êÉ豸ÉÏÖ´ÐÐδ¾­ÊÚȨµÄ´úÂë¡£¡£¡£¡£¡£¡£CPR µÄ×êÑÐÅú×¢£¬£¬£¬ £¬ £¬ £¬#MonikerLink ·ì϶ÀÄÓÃÁË Windows ÉϵÄ×é¼þ¶ÔÏóÄ£ÐÍ ( COM )£¬£¬£¬ £¬ £¬ £¬´Ó¶øÔÊÐíÖ´ÐÐδ¾­ÊÚȨµÄ´úÂ벢й¶±¾µØ NTLM Í´´¦ÐÅÏ¢¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÀûÓÃÓû§µÄ NTLM Í´´¦À´Í¨¹ý Windows ÖÐµÄ COM Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£µ±Óû§µ¥»÷¶ñÒⳬÁ´½Óʱ£¬£¬£¬ £¬ £¬ £¬Ëü»áÏνӵ½Óɹ¥»÷Õß½ÚÔìµÄÔ¶³Ì·þÎñÆ÷£¬£¬£¬ £¬ £¬ £¬´Ó¶ø·ÛËéÉí·ÝÑéÖ¤¾ßÌåÐÅÏ¢²¢¿ÉÄܵ¼Ö´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£ÕâʹµÃ¹¥»÷Õß¿ÉÄÜÈÆ¹ýOffice ÀûÓ÷¨Ê½ÖеÄÊܱ£»£»£» £»£»¤ÊÓͼģʽ£¬£¬£¬ £¬ £¬ £¬Ô¶³ÌŲÓà COM ¶ÔÏó²¢ÔÚÊܺ¦ÕßµÄÍÆËã»úÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£


https://www.hackread.com/monikerlink-bug-microsoft-outlook-data-malware/


2. FBI ͨ¼©·¸ Zeus ºÍ IcedID ¶ñÒâÈí¼þÖ÷ıÈÏ×ï


2ÔÂ18ÈÕ£¬£¬£¬ £¬ £¬ £¬Ò»ÃûÎÚ¿ËÀ¼¹«ÃñÔÚÃÀ¹úÈÏ¿É×Ô¼ºÔÚ 2009 Äê 5 ÔÂÖÁ 2021 Äê 2 ÔÂÆÚ¼ä²Î¼ÓÁËÁ½¸ö·ÖÆçµÄ¶ñÒâÈí¼þ´òË㣨Zeus ºÍ IcedID£©¡£¡£¡£¡£¡£¡£37 ËêµÄάÑÇÇÐ˹À­·ò¡¤ÒÁ¸êÁÐÎ¬Ææ¡¤Åí³þ¿Æ·òÓÚ 2022 Äê 10 Ô±»ÈðÊ¿µ±¾Ö¿ÛÁô£¬£¬£¬ £¬ £¬ £¬²¢ÓÚÈ¥Äê±»Òý¶Éµ½ÃÀ¹ú¡£¡£¡£¡£¡£¡£2012Ä꣬£¬£¬ £¬ £¬ £¬Ëû±»ÁÐÈëÁª¹úµ÷²é¾ÖµÄͨ¼©Ãûµ¥¡£¡£¡£¡£¡£¡£ÃÀ¹ú˾·¨²¿ (DoJ)½« PenchukovÃèÊöΪ¡°Á½¸ö¶à²ú¶ñÒâÈí¼þ×éÖ¯µÄ¸¨µ¼Õß¡±£¬£¬£¬ £¬ £¬ £¬¸Ã×éÖ¯ÓöñÒâÈí¼þϰȾÁËÊýÇ§Ì¨ÍÆËã»ú£¬£¬£¬ £¬ £¬ £¬µ¼ÖÂÀÕË÷Èí¼þºÍÊý°ÙÍòÃÀÔª±»µÁ¡£¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬ Zeus ÒøÐÐľÂí£¬£¬£¬ £¬ £¬ £¬¸ÃľÂíÓÐÖúÓÚÇÔÈ¡ÒøÐÐÕË»§ÐÅÏ¢¡¢ÃÜÂë¡¢Ó×ÎÒ¼ø±ðÂëÒÔ¼°µÇÂ¼ÍøÉÏÒøÐÐÕË»§ËùÐèµÄÆäËû¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£±»¸æ»¹±»Ö¸¿ØÖÁÉÙ´Ó 2018 Äê 11 ÔÂÆðÔ®ÊÖ¸¨µ¼Éæ¼°IcedID£¨±ðÃû BokBot£©¶ñÒâÈí¼þµÄ¹¥»÷£¬£¬£¬ £¬ £¬ £¬´Ó¶øÎª¶ñÒâ»î¶¯Ìṩ·½±ã¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¿ÉÄܳäÈÎÐÅÏ¢ÇÔÈ¡·¨Ê½ºÍÆäËûÓÐЧ¸ºÔØ£¨ÀýÈçÀÕË÷Èí¼þ£©µÄ¼ÓÔØ·¨Ê½¡£¡£¡£¡£¡£¡£×îÖÕ£¬£¬£¬ £¬ £¬ £¬ÕýÈçµ÷²é¼ÇÕß²¼À³¶÷¡¤¿ËÀײ¼Ë¹ (Brian Krebs)ÔÚ 2022 Ä걨·µÄÄÇÑù£¬£¬£¬ £¬ £¬ £¬ÓÉÓÚÓëÎÚ¿ËÀ¼Ç°×Üͳά¿ËÍÓפÑÇŬ¿ÆÎ¬Ææ (Victor Yanukovych) µÄÕþÖιØÏµ£¬£¬£¬ £¬ £¬ £¬Ëû¶àÄêÀ´³É¹¦ÌÓ±ÜÎÚ¿ËÀ¼ÍøÂç·¸×ïµ÷²éÈËÔ±µÄ¸æ×´¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2024/02/fbis-most-wanted-zeus-and-icedid.html


3. CISA ³Æ Akira ÀÕË÷ÍÅ»ïÔÚÀûÓà Cisco ASA/FTD ·ì϶CVE-2020-3259 


2ÔÂ17ÈÕ£¬£¬£¬ £¬ £¬ £¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö (CISA)ÔÚÆäÒÑÖªÀûÓ÷ì϶Ŀ¼ÖÐÔö³¤ÁË Ò»¸ö Cisco ASA ºÍ FTD ·ì϶£¬£¬£¬ £¬ £¬ £¬±àºÅΪCVE-2020-3259  £¨CVSS ÆÀ·Ö£º7.5£©¡£¡£¡£¡£¡£¡£·ì϶ CVE-2020-3259 ÊÇÒ»¸ö´æÔÚÓÚ ASA ºÍ FTD Web ·þÎñ½Ó¿ÚÖеÄÐÅϢй¶ÎÊÌâ¡£¡£¡£¡£¡£¡£Ë¼¿ÆÓÚ 2020 Äê 5 Ô½¨¸´Á˸÷ì϶¡£¡£¡£¡£¡£¡£CISA ½«¸ÃÎÊÌâÁÐΪÒÑÖªÓÃÓÚÀÕË÷Èí¼þ»î¶¯µÄÎÊÌ⣬£¬£¬ £¬ £¬ £¬µ«¸Ã»ú¹¹Ã»ÓÐй©ÄÄЩÀÕË÷Èí¼þ×éÖ¯ÔÚ»ý¼«ÀûÓøÃÎÊÌâ¡£¡£¡£¡£¡£¡£Truesec CSIRT ÍÅ¶Ó ·¢ÏÖȡ֤Êý¾ÝÅú×¢ Akira ÀÕË÷Èí¼þ×éÖ¯¿ÉÄÜÔÚ»ý¼«ÀûÓÃ¾ÉµÄ Cisco ASA£¨×ÔÊÊÓ¦°²È«É豸£©ºÍ FTD£¨Firepower Íþв·ÀÓù£©·ì϶£¬£¬£¬ £¬ £¬ £¬¸ú×Ù±àºÅΪ CVE-2020-3259¡£¡£¡£¡£¡£¡£Akira ÀÕË÷Èí¼þ ×Ô 2023 Äê 3 ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬ £¬ £¬ £¬¸Ã¶ñÒâÈí¼þ±³ºóµÄÍþвÐÐΪÕßÐû³ÆÒѾ­ÈëÇÖÁ˶à¸öÐÐÒµµÄ¶à¸ö×éÖ¯£¬£¬£¬ £¬ £¬ £¬Ô̺¬½ÌÓý¡¢½ðÈںͷ¿µØ²ú¡£¡£¡£¡£¡£¡£ÓëÆäËûÀÕË÷Èí¼þÍÅ»ïÒ»Ñù£¬£¬£¬ £¬ £¬ £¬¸Ã×éÖ¯¿ª·¢ÁËÒ»¿îÕë¶Ô VMware ESXi ·þÎñÆ÷µÄ Linux ¼ÓÃÜÆ÷¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/159244/cyber-crime/cisa-cisco-cve-2020-3259-akira-ransomware.html


4. ÒÔÉ«ÁÐ NSO ×é֝ɿÏÓ¶Ô WhatsApp ½øÐÓ×°²ÊÐÅÖ¸ÎÆ¡±¹¥»÷


2ÔÂ16ÈÕ£¬£¬£¬ £¬ £¬ £¬ÒÔÉ«ÁмäµýÈí¼þ¹«Ë¾ NSO Group ÉæÏÓÀûÓÃÒ»ÖÖÐÂÏʵġ°²ÊÐÅÖ¸ÎÆ¡±¹¥»÷À´Õë¶Ô WhatsApp ÉÏδ¾­ÒÉ»óµÄÓû§£¬£¬£¬ £¬ £¬ £¬ÎÞÐèÓû§½»»¥¼´¿É¶³öËûÃǵÄÉ豸ÐÅÏ¢¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ 2023 Äê 15 ÈÕÐÇÆÚËÄÏò Hackread.com ·ÖÏíµÄ»ã±¨ÏÔʾ£¬£¬£¬ £¬ £¬ £¬WhatsApp ÔÚ 2019 Äê 5 Ô·¢ÏÔìäϵͳ´æÔÚ·ì϶£¬£¬£¬ £¬ £¬ £¬ÔÊÐí¹¥»÷ÕßÔÚÓû§É豸ÉÏ×°Öà Pegasus ¼äµýÈí¼þ¡£¡£¡£¡£¡£¡£Ëæºó£¬£¬£¬ £¬ £¬ £¬¸Ã·ì϶±»ÀûÓÃÀ´Õë¶ÔÈ«ÇòÈ·µ±¾Ö¹ÙÔ±ºÍ»î¶¯ÈËÊ¿¡£¡£¡£¡£¡£¡£WhatsApp ¾ÍÕâÖÖÀûÓÃÐÐΪ¸æ×´NSO ¼¯ÍÅ£¬£¬£¬ £¬ £¬ £¬µ«ÔÚÃÀ¹úÉÏËß·¨ÔººÍ×î¸ß·¨ÔºÉÏËß¾ùʧ°Ü¡£¡£¡£¡£¡£¡£Enea ÌáÒéÁËÒ»Ïîµ÷²é£¬£¬£¬ £¬ £¬ £¬ÒÔ²éÃ÷²ÊÐÅÖ¸ÎÆ¹¥»÷ÊÇÈôºÎ²úÉúµÄ¡£¡£¡£¡£¡£¡£ËûÃÇ·¢ÏÖ£¬£¬£¬ £¬ £¬ £¬ËüÄܹ»Í¨¹ý·¢ËͲÊÐÅÀ´ÏÔʾָ±êÉ豸ºÍ²Ù×÷ϵͳ°æ±¾£¬£¬£¬ £¬ £¬ £¬¶øÎÞÐèÓû§½»»¥¡£¡£¡£¡£¡£¡£MMS UserAgent ÊÇÒ»¸ö±êʶ²Ù×÷ϵͳºÍÉ豸£¨ÀýÈçÔËÐÐ Android µÄÈýÐÇÊÖ»ú£©µÄ×Ö·û´®£¬£¬£¬ £¬ £¬ £¬¶ñÒâÐÐΪÕßÄܹ»ÀûÓà MMS UserAgent À´ÀûÓ÷ì϶¡¢¶¨Ôì¶ñÒâ¸ºÔØ»ò²ß¶¯ÍøÂç´¹µö»î¶¯¡£¡£¡£¡£¡£¡£


https://www.hackread.com/israeli-nso-group-mms-fingerprint-attack-whatsapp/


5. ×êÑÐÍŶӷ¢ÏÖTurla APT ²¿ÊðÐ嵀 TinyTurla-NG ºóÃÅ


2ÔÂ17ÈÕ£¬£¬£¬ £¬ £¬ £¬Ë¼¿Æ Talos µÄר¼Ò·¢ÏÖÓÉ Turla APT ×éÖ¯²ß¶¯µÄÕë¶Ô²¨À¼·Çµ±¾Ö×éÖ¯µÄ»î¶¯¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ÀûÓÃÁËÒ»ÖÖÐÂÏʵĺóÃÅ£¬£¬£¬ £¬ £¬ £¬TinyTurla-NG¡£¡£¡£¡£¡£¡£TinyTurla-NG µÄÒ»¸öÏÔÖøÌØµãÊÇËü¿ÉÄܳäÈκóÃÅ£¬£¬£¬ £¬ £¬ £¬µ±¼ì²âµ½»ò×èÖ¹ÆäËûºÚ¿Í²½Öèʱ£¬£¬£¬ £¬ £¬ £¬ºóÞͻᱻ¼¤»î¡£¡£¡£¡£¡£¡£¼Í¼ÔÚ°¸µÄ¹¥»÷»î¶¯´Ó 2023 Äê 12 Ô 18 ÈÕ³ÖÐøµ½ 2024 Äê 1 Ô 27 ÈÕ£¬£¬£¬ £¬ £¬ £¬²»ÍâÓÐÈ˲²⹥»÷¿ÉÄÜÔçÔÚ 2023 Äê 11 ÔÂ¾ÍÆðÍ·ÁË¡£¡£¡£¡£¡£¡£²¡¶¾Í¨¹ýÊÜϰȾµÄ WordPress ÍøÕ¾´«²¼£¬£¬£¬ £¬ £¬ £¬¸ÃÍøÕ¾³äÈκÅÁîºÍ½ÚÔì (C2) ·þÎñÆ÷¡£¡£¡£¡£¡£¡£TinyTurla-NG ¿ÉÄÜ´Ó C2 ·þÎñÆ÷Ö´ÐкÅÁî¡¢ÉÏ´«ºÍÏÂÔØÎļþÒÔ¼°²¿Êð¾ç±¾ÒÔ´ÓÃÜÂëÖÎÀíÊý¾Ý¿âÇÔÈ¡ÃÜÂë¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬ £¬ £¬TinyTurla-NG ³äÈν»¸¶ PowerShell ¾ç±¾µÄÇþ·£¬£¬£¬ £¬ £¬ £¬³ÆÎª TurlaPower-NG£¬£¬£¬ £¬ £¬ £¬Ö¼ÔÚÌáÈ¡ÓÃÓÚ±£»£»£» £»£»¤Ê¢ÐÐÃÜÂëÖÎÀíÆ÷Êý¾Ý¿âµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£


https://meterpreter.org/turla-apt-deploys-new-tinyturla-ng-backdoor/


6. Alpha ÀÕË÷Èí¼þ´Ó NetWalker »Ò½ýÖÐáÈÆð


2ÔÂ16ÈÕ£¬£¬£¬ £¬ £¬ £¬Alpha ÊÇÒ»ÖÖÐÂÀÕË÷Èí¼þ£¬£¬£¬ £¬ £¬ £¬ÓÚ 2023 Äê 2 Ô³õ´Î³öÏÖ£¬£¬£¬ £¬ £¬ £¬²¢ÔÚ×î½ü¼¸ÖܼÓÇ¿ÁËÔË×÷£¬£¬£¬ £¬ £¬ £¬ÓëÔçÒѲ»´æÔÚµÄ NetWalker ÀÕË÷Èí¼þ¼«¶ÈÀàËÆ£¬£¬£¬ £¬ £¬ £¬NetWalker ÀÕË÷Èí¼þÓÚ 2021 Äê 1 ÔÂÔÚÒ»´Î ¹ú¼Ê·¨ÂÉÐж¯ºóÒþû¡£¡£¡£¡£¡£¡£¶Ô Alpha µÄ·ÖÎö½ÒʾÁËÓë¾É°æ NetWalker ÀÕË÷Èí¼þµÄÏÔÖøÀàËÆÖ®´¦¡£¡£¡£¡£¡£¡£ÕâÁ½ÖÖÍþв¶¼Ê¹ÓÃÀàËÆµÄ»ùÓÚ PowerShell µÄ¼ÓÔØ·¨Ê½À´´«µÝÓÐЧ¸ºÔØ¡£¡£¡£¡£¡£¡£³ý´ËÖ®±í£¬£¬£¬ £¬ £¬ £¬Alpha ºÍ NetWalker ÓÐЧ¸ºÔØÖ®¼ä´æÔÚ´óÁ¿´úÂë³Áµþ¡£¡£¡£¡£¡£¡£ÕâÔ̺¬£ºÁ½¸öÓÐЧ¸ºÔØÖØÒªÖ°ÄܵÄͨ³£Ö´ÐÐÁ÷³Ì£»£»£» £»£»ÔÚµ¥¸öÏß³ÌÖд¦ÖÃÁ½¸öÖ°ÄÜ£º¹ý³ÌÖÕÖ¹ºÍ·þÎñÖÕÖ¹£»£»£» £»£»ÒѽâÎö API µÄÀàËÆÁÐ±í¡£¡£¡£¡£¡£¡£¹ÌÈ» API ÊÇʹÓùþÏ£Öµ½âÎöµÄ£¬£¬£¬ £¬ £¬ £¬µ«ËùʹÓõĹþÏ£Öµ²¢²»Ò»Ñù£»£»£» £»£»Á½¸öÓÐЧ¸ºÔØÓµÓÐÀàËÆµÄÅäÖ㬣¬£¬ £¬ £¬ £¬Ô̺¬Ìø¹ýµÄÎļþ¼Ó×¢ÎļþºÍÀ©´óÃûµÄÁÐ±í£»£»£» £»£»ÒÔ¼°ÒªkillµÄ¹ý³ÌºÍ·þÎñµÄÁÐ±í£»£»£» £»£»¼ÓÃÜʵÏֺ󣬣¬£¬ £¬ £¬ £¬Á½¸öÓÐЧ¸ºÔسÇÊÐʹÓÃһʱÅú´¦ÖÃÎļþɾ³ý×ÔÉí£»£»£» £»£»Á½Õß¶¼ÓÐÀàËÆµÄÖ§¸¼ûÅ»§£¬£¬£¬ £¬ £¬ £¬Ô̺¬Ò»ÑùµÄÐÂÎÅ£º¡°ÈçÐèÊäÈ룬£¬£¬ £¬ £¬ £¬ÇëʹÓÃÓû§´úÂ롱¡£¡£¡£¡£¡£¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/alpha-netwalker-ransomware?web_view=true