TA544ÀûÓÃWikiLoaderÕë¶ÔÒâ´óÀûµÄÆóÒµ·Ö·¢Ursnif

°ä²¼¹¦·ò 2023-08-02

1¡¢TA544ÀûÓÃWikiLoaderÕë¶ÔÒâ´óÀûµÄÆóÒµ·Ö·¢Ursnif


ProofpointÔÚ7ÔÂ31ÈÕÅû¶ÁËÀûÓÃжñÒâÈí¼þWikiLoaderÕë¶ÔÒâ´óÀûÆóÒµµÄ¹¥»÷»î¶¯¡£WikiLoaderÊÇÒ»¸ö¸´ÔÓµÄÏÂÔØ·¨Ê½£¬ÓÉÓÚËü»áÏòWikipedia·¢³öÒªÇ󲢲鳭ÏìÓ¦ÄÚÈÝÖÐÊÇ·ñÔ̺¬×Ö·û´®¡°The Free¡±¶øµÃÃû¡£ProofpointÓÚ2022Äê12ÔÂ27ÈÕ³õ´ÎÔÚÒ°±í¼ì²âµ½¸Ã¶ñÒâÈí¼þ£¬ÓÉTA544´«²¼¡£×êÑÐÈËÔ±³Æ£¬ÖÁÉÙÓÐ8¸ö»î¶¯ÔÚ·Ö·¢WikiLoader£¬À´×ÔTA544ºÍTA551£¬¾ùÕë¶ÔÒâ´óÀûµÄ×éÖ¯¡£´Ë±í£¬¹ÌÈ»´óÎÞÊý¹¥»÷ÕßÒѲ»ÔÙʹÓÃÆôÓúêµÄÎĵ·´´«²¼¶ñÒâÈí¼þ£¬µ«TA544ÈÔÔÚ¹¥»÷Á´ÖÐʹÓÃËüÃÇ£¬Ô̺¬´«²¼WikiLoader¡£


https://www.proofpoint.com/us/blog/threat-insight/out-sandbox-wikiloader-digs-sophisticated-evasion


2¡¢ÃÀ¹úÒÂÊι«Ë¾Hot TopicÔ⵽ײ¿â¹¥»÷й¶¿Í»§µÄÐÅÏ¢


¾ÝýÌå8ÔÂ1ÈÕ±¨Â·£¬ÃÀ¹úÒÂÊμ°ÊÚȨÒôÀÖÁãÊÛÁ¬ËøµêHot Topicй©ÆäÔâµ½Á˶àÆð¹¥»÷ÊÂÎñ£¬µ¼Ö¿ͻ§µÄÃô¸ÐÐÅϢй¶¡£¸Ã¹«Ë¾ÔÚÃÀ¹úÕ¼ÓÐ675¼ÒÉ̵꣬ÒÔ¼°Ã¿Ô½ü1000Íò½Ó¼ûÁ¿µÄÔÚÏßÉ̵ê¡£¸Ã¹«Ë¾Ú¹ÊÍ˵£¬ºÚ¿ÍʹÓÃÇÔÈ¡µÄÕÊ»§Í´´¦ÂŴνӼûÁËRewardsƽ̨£¬¿ÉÄÜ»ñµÃÁ˿ͻ§µÄÊý¾Ý¡£¾­µ÷²é£¬¹¥»÷ÕßÓÚ2023Äê2ÔÂ7ÈÕ¡¢3ÔÂ11ÈÕ¡¢5ÔÂ19ÈÕÖÁ21ÈÕ¡¢5ÔÂ27ÈÕÖÁ28ÈÕºÍ6ÔÂ18ÈÕÖÁ21ÈÕ£¬Ê¹ÓÃÓÐЧÕÊ»§Í´´¦¶ÔÍøÕ¾ºÍÒÆ¶¯ÀûÓÃÖ´ÐÐÁË×Ô¶¯¹¥»÷¡£¸Ã¹«Ë¾°µÊ¾£¬Hot Topic²»ÊÇй¶ƾ֤µÄÆðÔ´£¬µ«Ò²ÎÞ·¨ÕÒµ½ÆðÔ´¡£


https://www.bleepingcomputer.com/news/security/retail-chain-hot-topic-discloses-wave-of-credential-stuffing-attacks/


3¡¢Henry Ford HealthÔâ´¹µö¹¥»÷½ü17Íò»¼ÕßÐÅϢй¶


¾Ý7ÔÂ27ÈÕ±¨Â·£¬ÃÀ¹úµÄѧÊõÒ½ÁÆ»úHenry Ford Health³ÆÆä3ÃûÔ±¹¤Ôâµ½´¹µö¹¥»÷£¬Ó°ÏìÁË168215¸ö»¼ÕßµÄÐÅÏ¢¡£¸Ã»ú¹¹ÔÚÉêÃ÷ÖаµÊ¾£¬¹¥»÷ÊÂÎñ²úÉúÓÚ3ÔÂ30ÈÕ£¬¸Ã×éÖ¯Òѽ«±»Ó°ÏìµÄµç×ÓÓʼþÕÊ»§±£»¤ÆðÀ´²¢·¢Õ¹µ÷²é¡£5ÔÂ16£¬È·¶¨»¼ÕߵĽ¡È«ÐÅÏ¢Ô̺¬ÔÚµç×ÓÓÊÏäÖУ¬²¢ÇÒ¿ÉÄÜÒѱ»¹¥»÷ÕßÇÔÈ¡£¬Éæ¼°ÐÕÃû¡¢³¢ÊÔÊÒÁ˾֡¢ÊÖÊõÀàÐÍ¡¢Õï¶Ï¡¢µç»°ºÅÂë¡¢²¡ÀúºÅºÍÄÚ²¿¸ú×ٺŵÈÐÅÏ¢¡£¸Ã¹«Ë¾°µÊ¾£¬ËûÃÇÔÚÖ´Ðжî±íµÄ°²È«´ëÊ©£¬²¢½«ÎªÔ±¹¤Ìṩ°²È«Åàѵ¡£


https://www.bankinfosecurity.com/phishing-scam-affects-nearly-170k-henry-ford-health-patients-a-22672 


4¡¢Cado·¢ÏÖ¿ÉÕë¶ÔRedis·þÎñÆ÷µÄP2PInfectÈ䳿бäÌå


7ÔÂ31ÈÕ£¬Cado·¢ÏÖÁËÒ»ÖÖÕë¶ÔRedisµÄÐÂÐͶñÒâÈí¼þ»î¶¯¡£¸Ã¶ñÒâÈí¼þ±»¿ª·¢Õß¶¨ÃûΪP2Pinfect£¬ÓÃRust¿ª·¢£¬³äÈν©Ê¬ÍøÂç´úÀí¡£×êÑÐÈËÔ±·ÖÎöµÄÑù±¾Ô̺¬Ò»¸öǶÈëʽPEÎļþÒÔ¼°Ò»¸öELF¶þ½øÔìÎļþ£¬Õâ½²ÁËÈ»WindowsºÍLinuxÖ®¼äÓµÓÐ¿çÆ½Ì¨¼æÈÝÐÔ¡£Ëü»¹ÀûÓø´ÔìÖ°ÄÜÀ´¹¥»÷RedisÊý¾Ý´æ´¢µÄÊ·ý¡£´Ë±í£¬P2PinfectÊÔͼͨ¹ýCronδ¾­Éí·ÝÑéÖ¤µÄRCE»úÔì¹¥»÷RedisÖ÷»ú¡£¸Ã»î¶¯±³ºóµÄ¹¥»÷ÕßÉí·ÝÉв»Ã÷ÏÔ£¬P2PInfectµÄÖ÷ÕÅÒ²²»Ã÷ÏÔ¡£


https://www.cadosecurity.com/redis-p2pinfect/


5¡¢Minecraft mod·ì϶BleedingPipeÒѱ»´ó¹æÄ£ÀûÓÃ


ýÌå7ÔÂ31ÈÕ±¨Â·³Æ£¬ºÚ¿ÍÔÚÀûÓÃMinecraft modÖеÄRCE·ì϶BleedingPipeÔÚ·þÎñÆ÷ºÍ¿Í»§¶ËÖ´ÐжñÒâºÅÁ´Ó¶ø½ÚÔìÉ豸¡£BleedingPipe·ì϶×î³õÓÚ2022Äê3Ô±»ÀûÓ㬵«ºÜ¿ì¾Í±»mod¿ª·¢Õß½¨¸´ÁË¡£È»¶øÔÚ7ÔÂÔçЩʱ³½£¬ForgeÂÛ̳µÄһƪÌû×ӳƣ¬ÓÐÈËÀûÓÃδ֪RCEÀ´´ó¹æÄ£ÇÔÈ¡Íæ¼ÒµÄDiscordºÍSteam»á»°cookie¡£½øÒ»²½×êÑз¢ÏÖ£¬¶à¸öMinecraft modÖÐÒ²´æÔÚBleedingPipe·ì϶¡£¹¥»÷ÕßÔÚɨÃèÊܸ÷ì϶ӰÏìµÄMinecraft·þÎñÆ÷²¢Ö´Ðй¥»÷£¬Òò¶ø½¨¸´·þÎñÆ÷ÉÏÒ×±»¹¥»÷µÄmodÖÁ¹Ø³ÁÒª¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-bleedingpipe-rce-to-target-minecraft-servers-players/


6¡¢Bahamutͨ¹ý¼ÙðµÄAndroidÀûÓÃSafeChatÇÔÊØÐÅÏ¢


7ÔÂ28ÈÕ£¬CYFIRMA³ÆÆä·¢ÏÖÁËÒ»¸ö¿ÉÒɵÄAndroid¶ñÒâÈí¼þ£¬¼Ù×°³ÉÐéαµÄ̸ÌìÀûÓÃSafeChat£¬ÇÔÈ¡ÊÖ»úµÄͨ»°¼Í¼¡¢¶ÌÐźÍGPSµØÎ»µÈÊý¾Ý¡£¸Ã¶ñÒâÈí¼þ±»ÒÉ»óÊÇCoverlmµÄ±äÖÖ£¬»áÇÔÈ¡Telegram¡¢Signal¡¢WhatsApp¡¢ViberºÍFacebook MessengerµÈͨѶÀûÓõÄÊý¾Ý¡£¸Ã»î¶¯ÓëÓ¡¶ÈºÚ¿ÍÍÅ»ïBahamutÓйØ£¬ÖØÒªÍ¨¹ýWhatsAppÉϵÄÓã²æÊ½´¹µöÐÂÎŽøÐУ¬ÖØÒªÕë¶ÔÄÏÑǵØÓò¡£´Ë±í£¬¸Ã»î¶¯ÓëÓ¡¶ÈµÄÁíÒ»¸öºÚ¿ÍÍÅ»ïDoNotµÄ»î¶¯ÓÐÀàËÆÖ®´¦¡£


https://www.cyfirma.com/outofband/apt-bahamut-targets-individuals-with-android-malware-using-spear-messaging/