Ñо¿Ö°Ô±ÔÚ¶à¸öÄ¿µÄϵͳÉϼì²âµ½Îó²îʹÓù¤¾ßIceApple

Ðû²¼Ê±¼ä 2022-05-13
1¡¢Ñо¿Ö°Ô±ÔÚ¶à¸öÄ¿µÄϵͳÉϼì²âµ½Îó²îʹÓù¤¾ßIceApple


¾ÝýÌå5ÔÂ11ÈÕ±¨µÀ£¬CrowdStrike·¢Ã÷ÁËÒ»ÖÖеÄÎó²îʹÓù¤¾ßIceApple ¡£¸Ã¶ñÒâÈí¼þÓÚ2021Äêµ×Ê״α»·¢Ã÷£¬ÏÖÔÚÈÔÔÚÆð¾¢¿ª·¢ÖÐ ¡£IceAppleÊǹ¥»÷ÕßÔÚ»ñµÃÖÖÖÖÐÐÒµ£¨ÊÖÒÕ¡¢Ñ§ÊõºÍÕþ¸®£©×éÖ¯ÍøÂçµÄ³õʼ»á¼ûȨÏÞºó×°ÖõÄ£¬ÏÖÔÚÒÑÔÚ¶à¸öÄ¿µÄµÄMicrosoft Exchange ServerʵÀýÉϼì²âµ½£¬µ«ËüÒ²¿ÉÒÔÔÚIISÉÏÔËÐÐ ¡£¸Ã¶ñÒâ¿ò¼Ü»ùÓÚ.NET£¬¾ßÓÐÖÁÉÙ18¸öÄ £¿é£¬Ã¿¸öÄ £¿éÓÃÓÚÌØ¶¨Ê¹Ãü£¬¿ÉÓÃÀ´·¢Ã÷ÍøÂçÉϵÄÏà¹Ø×°±¸¡¢ÇÔȡƾ֤¡¢É¾³ýÎļþºÍĿ¼ÒÔ¼°ÇÔÈ¡ÓмÛÖµµÄÊý¾Ý ¡£


https://www.bleepingcomputer.com/news/security/new-iceapple-exploit-toolset-deployed-on-microsoft-exchange-servers/


2¡¢ÐµÄNerbian RATÃé×¼Òâ´óÀûºÍÎ÷°àÑÀµÈÅ·ÖÞ¹ú¼Ò


5ÔÂ11ÈÕ£¬ProofpointÅû¶ÁËÐÂNerbian RATµÄ¹¥»÷Ô˶¯µÄϸ½ÚÐÅÏ¢ ¡£¹¥»÷Ô˶¯×Ô4ÔÂ26ÈÕ×îÏÈ£¬Í¨¹ýÒÔCOVID-19ºÍºÍÌìÏÂÎÀÉú×é֯ΪÖ÷ÌâµÄ´¹ÂÚÔ˶¯·Ö·¢¶ñÒâÈí¼þ£¬Ö÷ÒªÕë¶ÔÒâ´óÀû¡¢Î÷°àÑÀºÍÓ¢¹úµÄ×éÖ¯ ¡£NerbianÓÉGoÓïÑÔ±àд£¬Îª64λϵͳ±àÒ룬ʹÓÃÁ˶à¸ö¼ÓÃÜÀú³ÌÈÆ¹ýÇå¾²ÆÊÎö ¡£Dropper»¹Ê¹ÓÃÁË¿ªÔ´ChacalµÄ¡°·´VM¿ò¼Ü¡±À´ÔöÌíÄæÏò¹¤³ÌµÄÄÑ¶È ¡£¾ÝϤ£¬DropperºÍRAT¶¼ÊÇÓÉͳһ¿ª·¢Õß¿ª·¢µÄ£¬µ«¹¥»÷ÕßµÄÉí·ÝÈÔȻδ֪ ¡£


https://www.proofpoint.com/us/blog/threat-insight/nerbian-rat-using-covid-19-themes-features-sophisticated-evasion-techniques


3¡¢Ó¢¹úÄÐ×Ó±»Ö¸¿ØÈëÇÖÃÀ¹úij½ðÈÚ»ú¹¹ËðʧÁè¼Ý500ÍòÃÀÔª


¾Ý5ÔÂ11ÈÕ±¨µÀ£¬32ËêµÄÓ¢¹úÄÐ×ÓIdris Dayo Mustapha±»Ö¸¿ØÈëÇÖÃÀ¹úij½ðÈÚ»ú¹¹£¬Ôì³ÉÁè¼Ý500ÍòÃÀÔªµÄËðʧ ¡£5ÔÂ10ÈÕ¹ûÕæµÄͶËßÏÔʾ£¬¸ÃÄÐ×ÓÊÇijºÚ¿ÍÍÅ»ïµÄÒ»Ô±£¬ËûÃÇÔÚ2011Äê1ÔÂÖÁ2018Äê3ÔÂʱ´úʹÓô¹Âڵȹ¥»÷·½·¨»ñÈ¡Óû§Æ¾Ö¤£¬ÒÔÇÔÈ¡ÍøÉÏÒøÐÐÕË»§ºÍ֤ȯ¾­¼ÍÕË»§ÖеÄ×ʽð ¡£ÈôÊÇ×ïÃû½¨É裬Mustapha½«Òòµç»ãÕ©Æ­¡¢Ö¤È¯Õ©Æ­ºÍÏ´Ç®µÈÖ¸¿ØÃæÁÙ³¤´ï20ÄêµÄî¿Ïµ ¡£


https://www.infosecurity-magazine.com/news/british-charged-hacking-us-bank/


4¡¢ÄϷǹ«Ë¾Dis-ChemÔâµ½¹¥»÷й¶Áè¼Ý360ÍòÈ˵ÄÐÅÏ¢


ýÌå5ÔÂ11ÈÕ±¨µÀ£¬ÄÏ·Ç×î´óµÄÒ©Æ·ÁãÊÛÉÌÖ®Ò»Dis-ChemÒÑй¶Áè¼Ý360ÍòÈ˵ÄÐÅÏ¢ ¡£¾Ý¸Ã¹«Ë¾³Æ£¬´Ë´ÎÊÂÎñÊÇÓÉÆäµÚÈý·½·þÎñÌṩÉÌÔâµ½ÍøÂç¹¥»÷µ¼ÖµÄ£¬Éæ¼°¿Í»§µÄÐÕÃû¡¢ÓʼþµØµãºÍÊÖ»úºÅÂëµÈÐÅÏ¢ ¡£Ð¹Â¶±¬·¢ÔÚ4ÔÂ28ÈÕ£¬ÔÚ5ÔÂ1Èղű»·¢Ã÷ ¡£½üÆÚ£¬¹¥»÷ÕßÔ½À´Ô½¶àµØÕë¶ÔÄϷǵÄ×éÖ¯£¬2¸öÔÂǰ£¬ÃÀ¹úÏûºÄÕßÐÅÓñ¨¸æ»ú¹¹TransUnion³ÆÆäλÓÚÄϷǵķþÎñÆ÷±»ÈëÇÖ£¬Ð¹Â¶ÁË5400ÍòÓû§µÄÐÅÏ¢ ¡£


https://www.itweb.co.za/content/PmxVE7KEABOqQY85


5¡¢CiscoÐû²¼BitterÍŻ﹥»÷ÃϼÓÀ­Õþ¸®Ä³»ú¹¹µÄ±¨¸æ


Cisco TalosÔÚ5ÔÂ11ÈÕÐû²¼Á˹ØÓÚAPT×éÖ¯Bitter¹¥»÷ÃϼÓÀ­¹úµÄÆÊÎö±¨¸æ ¡£¹¥»÷Ô˶¯×îÏÈ×Ô2021Äê8Ô£¬Õë¶ÔÃϼÓÀ­ÄÚ²¿µÄÖÖÖÖ×éÖ¯£¬¾ßÓÐÁ½ÌõѬȾÁ´£¬¾ùͨ¹ýÓã²æÊ½´¹ÂÚÔ˶¯¾ÙÐÐ ¡£´¹ÂÚÓʼþÀ´×Ô°Í»ù˹̹µÄÕþ¸®»ú¹¹£¬Õâ¿ÉÄÜÊÇʹÓÃÓʼþ·þÎñÆ÷ZimbraÖеÄÒ»¸öÎó²îÀ´ÊµÏÖ ¡£Á½ÌõѬȾÁ´Ö®¼äµÄÇø±ðÔÚÓÚ¸½¼ÓµÄ¶ñÒâÎļþÀàÐÍ£ºÒ»¸öÊÇ.RTF£¬ÁíÒ»¸öÊÇ.XLSXÎĵµ ¡£RTFÎĵµÊ¹ÓÃÁËÎó²îCVE-2017-11882²¢ÔÚÄ¿µÄÖÐÔ¶³ÌÖ´ÐдúÂ룬ExcelÎĵµ´¥·¢Á˶ÔCVE-2018-0798ºÍCVE-2018-0802µÄÎó²îʹÓà ¡£


https://blog.talosintelligence.com/2022/05/bitter-apt-adds-bangladesh-to-their.html


6¡¢¶à¹úÕþ¸®Ðû²¼Õë¶ÔMSP¼°Æä¿Í»§µÄÍøÂçÍþвµÄÍŽá×Éѯ 


5ÔÂ11ÈÕ£¬°Ä´óÀûÑÇ¡¢¼ÓÄôó¡¢ÐÂÎ÷À¼¡¢Ó¢¹úºÍÃÀ¹úµÄ¶à¸öÍøÂçÇå¾²»ú¹¹Ðû²¼ÁËÕë¶ÔÍйܷþÎñÌṩÉÌ(MSP)¼°Æä¿Í»§µÄÍøÂçÍþвµÄÍŽá×Éѯ ¡£MSPÒѳÉΪ¹¥»÷ÕßÀ©´ó¹¥»÷¹æÄ£µÄ;¾¶£¬ÓÉÓÚÒ×Êܹ¥»÷µÄÌṩÉÌ¿ÉÒÔ±»ÎäÆ÷»¯²¢×÷Ϊ³õʼ»á¼ûÔØÌ壬ÒÔͬʱ¹¥»÷¶à¸öÏÂÓοͻ§ ¡£×ÉѯÖн¨Ò飬ʶ±ðºÍ½ûÓò»ÔÙʹÓõÄÕÊ»§£»¶Ô»á¼û¿Í»§ÇéÐεÄMSPÕË»§ÊµÑéMFA£¬²¢¼à²âδڹÊ͵Äʧ°ÜÈÏÖ¤£»È·±£MSP¿Í»§ÌõÔ¼Ã÷È·ÐÅÏ¢ºÍͨѶÊÖÒÕ(ICT)Çå¾²½ÇÉ«ºÍÔðÈεÄËùÓÐȨ ¡£


https://thehackernews.com/2022/05/government-agencies-warned-of-increase.html