Kaspersky·¢ÏÖAPT41ÀûÓÃMoonBounceµÄ¹¥»÷»î¶¯

°ä²¼¹¦·ò 2022-01-24

Kaspersky·¢ÏÖAPT41ÀûÓÃMoonBounceµÄ¹¥»÷»î¶¯


1ÔÂ20ÈÕ £¬Kaspersky°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þMoonBounceµÄ·ÖÎö»ã±¨¡£×êÑÐÈËÔ±³Æ £¬MoonBounceÊÇÆù½ñΪֹÔÚÒ°±í·¢ÏÖµÄ×îÏȽøµÄUEFI¹Ì¼þ¶ñÒâÈí¼þ £¬ÓëºÚ¿Í×éÖ¯APT41£¨Ò²³ÆÎªWinnti£©ÓйØ¡£MoonBounceÖ²ÈëÔÚÖ÷°åµÄSPIÉÁ´æÉÏ £¬Òò¶ø¼´±ã¸ü»»Ó²ÅÌÒ²ÎÞ·¨½«Æä¸ù³ý¡£ÕâÊǽüÆÚ·¢ÏֵĵÚÈý¸öUEFI¶ñÒâÈí¼þ £¬Ö®Ç°Á½¸öΪFinFisherºÍESPecter¡£Kaspersky°µÊ¾Õâ´Î¹¥»÷ÓµÓи߶ÈÕë¶ÔÐÔ £¬Ä³¸ö½ÚÔì׿¸¼ÒÔËÊä¼¼ÊõÓÐ¹ØÆóÒµµÄ×éÖ¯ÒѳÉΪ¹¥»÷Ö¸±ê¡£


https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/


ContiÍÅ»ïÐû³Æ¶ÔÓ¡¶ÈÄáÎ÷ÑÇÑëÐеÄÀÕË÷¹¥»÷ÕÆ¹Ü


¾ÝýÌå1ÔÂ20ÈÕ±¨Â· £¬Ó¡¶ÈÄáÎ÷ÑÇÒøÐУ¨BI£©ÈÏ¿ÉÆäÔâµ½ÀÕË÷¹¥»÷¡£¸ÃÐн²»°È˰µÊ¾ £¬¹¥»÷²úÉúÔÚÉϸöÔ £¬¹¥»÷ÕßÇÔÈ¡Á˲¿ÃÅÔ±¹¤µÄÐÅÏ¢ £¬²¢ÔÚÊ®¼¸¸öϵͳÉÏ×°ÖÃÁËÀÕË÷Èí¼þ £¬µ«ÆäÔËÓª²¢Î´Êܵ½Ó°Ïì¡£ContiÍÅ»ïÐû³Æ¶Ô´ËÊÂÕÆ¹Ü £¬ÈôÊÇÓ¡ÄáÒøÐв»Ö§¸¶Êê½ð £¬ËûÃǽ«¹«¿ª¸ÃÒøÐÐ13.88 GBµÄÎļþ¡£Ç°²»¾Ã £¬Conti»¹¹¥»÷Á˰®¶ûÀ¼DoH¡¢HSE £¬ºÍÓªÏú¹«Ë¾RR Donnelly¡£


https://www.bleepingcomputer.com/news/security/indonesias-central-bank-confirms-ransomware-attack-conti-leaks-data/


×êÑÐÈËÔ±³ÆÊýÊ®¸öWordPressÖ÷ÌâºÍ²å¼þÒѱ»Ö²ÈëºóÃÅ


JetPackÔÚ1ÔÂ18ÈÕ°ä²¼»ã±¨ £¬³ÆÒÑÔÚÊýÊ®¸öWordPressÖ÷ÌâºÍ²å¼þÖз¢ÏÖºóÃÅ¡£×êÑÐÈËÔ±³Æ £¬¹¥»÷ÕßÒÑÔÚAccessPress ThemesµÄ40¸öÖ÷ÌâºÍ53¸ö²å¼þÖÐÖ²ÈëºóÃÅ¡£¾­¹ýµ÷²éµÃÖª £¬AccessPress ThemesÓÚ2021Äê9ÔÂÉϰëÔÂÔâµ½¹¥»÷ £¬ÆäÊ±ÍøÕ¾ÉϵÄÀ©´ó·¨Ê½±»×¢ÈëÁ˺óÃÅ¡£ÊÜϰȾµÄÀ©´ó·¨Ê½Ô̺¬Ò»¸öwebshell dropper £¬Ê¹¹¥»÷ÕßÄܹ»ÆëÈ«½Ó¼ûÖ¸±êÍøÕ¾ £¬¸Ã·ì϶׷×ÙΪCVE-2021-24867¡£


https://thehackernews.com/2022/01/hackers-planted-secret-backdoor-in.html



ÀûÓÃCWPµÄÎļþÔ̺¬ºÍËÁÒâдÈë·ì϶¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ


ýÌå1ÔÂ22ÈÕ±¨Â· £¬Control Web PanelÖдæÔÚ2¸öÑϳÁµÄ·ì϶¡£Control Web Panel£¨ÒÔǰµÄCentOS Web Panel£©ÊÇÒ»¸ö¿ªÔ´µÄLinux½ÚÔìÃæ°åÈí¼þ £¬ÓÃÓÚ²¿ÊðWebÍйܻ·¾³¡£µÚÒ»¸öÊÇÎļþÔ̺¬·ì϶£¨CVE-2021-45467£© £¬¹¥»÷ÕßÖ»ÐèÅú¸ÄincludeÓï¾ä¾ÍÄܹ»Ô¶³Ì×¢Èë¶ñÒâ´úÂë»òʵÏÖ´úÂëÖ´ÐС£µÚ¶þ¸öΪËÁÒâÎļþдÈë·ì϶£¨CVE-2021-45466£© £¬½áºÏÀûÓÃÕâÁ½¸ö·ì϶Äܹ»ÔÚÒ×Êܹ¥»÷µÄLinux·þÎñÆ÷ÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐС£


https://securityaffairs.co/wordpress/127058/hacking/control-web-panel-flaws.html


MoleratsÍÅ»ïÀûÓöà¸öÔÆ·þÎñ¶ÔÖж«µØÓò½øÐмäµý¹¥»÷


¾ÝýÌå1ÔÂ22ÈÕ±¨Â· £¬°²È«¹«Ë¾Zscaler·¢ÏÖMoleratsÍÅ»ïÕë¶ÔÖж«µØÓòµÄ¼äµý»î¶¯¡£¾ÝϤ £¬¹¥»÷´Ó2021Äê7Ô¾ÍÒÑÆðÍ· £¬¹¥»÷ÕßÀûÓúϷ¨µÄÔÆ·þÎñ£¨ÈçGoogle DriveºÍDropbox£©ÍйܶñÒâÈí¼þpayload £¬´ÓÖж«µØÓòµÄÖ¸±êÖÐÇÔÈ¡Êý¾Ý¡£Õâ´Î»î¶¯ÀûÓÃÓëÒÔÉ«ÁкͰÍÀÕ˹̹ì¶ÜÓйصĵö¶ü £¬ÔÚÖ¸±êϵͳÉÏ×°ÖÃ.NETºóÃÅ £¬ÖØÒªÖ¸±êÔ̺¬°ÍÀÕË¹Ì¹ÒøÐÐÒµÔ±¹¤¡¢°ÍÀÕ˹̹Õþµ³³ÉÔ± £¬ÒÔ¼°ÍÁ¶úÆä¼ÇÕߵȡ£


https://thehackernews.com/2022/01/molerats-hackers-hiding-new-espionage.html


×ÖÄ»ÍøÕ¾OpenSubtitles½ü700ÍòÓû§µÄÐÅϢй¶


¾Ý1ÔÂ23ÈÕ±¨Â· £¬×ÖÄ»ÍøÕ¾OpenSubtitlesÔâµ½¹¥»÷ £¬6783158¸öÓû§µÄÐÅÏ¢ÒѾ­Ð¹Â¶¡£2021Äê8Ô £¬ÍøÕ¾ÖÎÀíÔ±ÊÕµ½Êê½ð֪ͨºó²ÅÒâʶµ½ÆäÒÑÔâµ½¹¥»÷¡£¹¥»÷Õß»¹°µÊ¾»áÌṩ֧³ÖÒÔ½¨¸´ÍøÕ¾Öеķì϶ £¬µ«ÔÚÖ§¸¶Êê½ðºó¹¥»÷Õß´ÓδԮÊÖËûÃǼӹÌÍøÕ¾ £¬²¢ÔÚ1ÔÂ11ÈÕ¹«¿ªÁ˱»µÁÊý¾Ý¡£¾ÝϤ £¬ºÚ¿Íͨ¹ýSQL×¢Èë¹¥»÷½Ó¼ûÁËÍøÕ¾µÄÊý¾Ý¿â £¬ÇÔÈ¡ÁËÓû§Óʼþ¡¢IPµØÖ·¡¢Óû§Ãû¡¢µØµã¹ú¶ÈºÍÃÜÂëµÈÐÅÏ¢¡£


https://securityaffairs.co/wordpress/127092/data-breach/opensubtitles-data-breach.html



°²È«¹¤¾ß


Narthex


ÊÇÒ»¸öÄ£¿é»¯ºÍ×îÓ×µÄ×ÖµäÌìÉúÆ÷ £¬ÓÃÓÚÓà C ºÍ Shell ±àдµÄ Unix ºÍÀà Unix ²Ù×÷ϵͳ¡£


https://github.com/MichaelDim02/Narthex


Iptable_Evil 


IptablesµÄºóÃÅ £¬Ê¹¶ñÒâÊý¾Ý°üͨ¹ýiptables £¬ÎÞÂÛ·À»ðǽ¹æ¶¨ÈôºÎ¡£


https://github.com/FlamingSpork/iptable_evil



iMonitor


ÊÇÒ»¿î»ùÓÚiMonitorSDKµÄ¶ËµãÐÐΪ¼à¿Ø·ÖÎöÈí¼þ¡£


https://github.com/wecooperate/iMonitor/releases



°²È«·ÖÎö


΢Èí½¨¸´ÁË Windows 10 µÄ Outlook ËÑË÷ÎÊÌâ


΢Èí½¨¸´ÁË×°ÖÃ2021 Äê 11 Ô°䲼µÄ Windows 10 °²È«¸üкóµ¼Ö Outlook Óû§³öÏÖËÑË÷ÎÊÌâµÄÎÊÌâ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-outlook-search-issues-for-windows-10-users/


WordPress²å¼þ´æÔÚ·ì϶


WP HTML MailÖдæÔÚÒ»¸öÑϳÁµÄ¿çÕ¾µã¾ç±¾(XSS)·ì϶ £¬Ó°Ï쳬¹ý20,000¸öWordPressÍøÕ¾¡£


https://threatpost.com/wordpress-insecure-plugin-rest-api/177866/