ÐÂÀÕË÷Èí¼þMalasLockerÒªÇóÄ¿µÄÏò´ÈÉÆ»ú¹¹¾èÇ®
Ðû²¼Ê±¼ä 2023-05-191¡¢ÐÂÀÕË÷Èí¼þMalasLockerÒªÇóÄ¿µÄÏò´ÈÉÆ»ú¹¹¾èÇ®
¾ÝýÌå5ÔÂ17ÈÕ±¨µÀ£¬ÐÂÀÕË÷Èí¼þMalasLockerͨ¹ýÈëÇÖZimbra·þÎñÆ÷À´ÇÔÈ¡Óʼþ²¢¼ÓÃÜÎļþ¡£µ«¹¥»÷Õß²¢Ã»ÓÐÒªÇóÄ¿µÄ½»Êê½ð£¬¶øÊÇÒªÇóËûÃÇÏòÖ¸¶¨µÄ·ÇÓªÀû´ÈÉÆ»ú¹¹¾èÇ®¡£¸ÃÔ˶¯Ê¼ÓÚ3ÔÂ⣬ÔÚ¼ÓÃܵç×ÓÓʼþʱ£¬Ëü²»»áÔÚÎļþÃû¸½¼ÓÌØÁíÍâÀ©Õ¹Ãû¡£µ«ËûÃÇÔÚÿ¸ö¼ÓÃÜÎļþµÄĩβ¶¼¸½¼ÓÁËÒ»¸ö"´ËÎļþÒѼÓÃÜ£¬ÇëÉó²éREADME.txtÏàʶ½âÃÜ˵Ã÷"µÄÐÅÏ¢¡£ÏÖÔÚÉв»ÇåÎú¹¥»÷ÕßÊÇÔõÑùÈëÇÖZimbra·þÎñÆ÷¡£MalasLockerµÄÍøÕ¾Ä¿ÒѹûÕæÈý¼Ò¹«Ë¾µÄÊý¾ÝºÍÆäËû169¸ö±»¹¥»÷ÕßµÄZimbraÉèÖá£
https://www.bleepingcomputer.com/news/security/malaslocker-ransomware-targets-zimbra-servers-demands-charity-donation/
2¡¢AppleÐÞ¸´iPhone¡¢MacºÍiPadÖÐÈý¸öÒѱ»Ê¹ÓõÄÎó²î
5ÔÂ18ÈÕ£¬AppleÐû²¼Çå¾²¸üУ¬ÐÞ¸´ÁËiPhone¡¢MacºÍiPadÖÐÈý¸öÒѱ»Ê¹ÓõÄÎó²î¡£ÕâЩÎó²î¾ùÔÚ¶àÆ½Ì¨WebKitä¯ÀÀÆ÷ÒýÇæÖб»·¢Ã÷£¬»®·ÖÊÇ¿ÉÓÃÀ´Í»ÆÆWebÄÚÈÝɳÏäµÄɳÏäÌÓÒÝÎó²î£¨CVE-2023-32409£©¡¢»á¼ûÃô¸ÐÐÅÏ¢µÄÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2023-28204£©ºÍÖ´ÐÐí§Òâ´úÂëµÄÊͷźóʹÓÃÎó²î£¨CVE-2023-32373£©¡£Appleͨ¹ýˢнçÏß¼ì²é¡¢ÊäÈëÑéÖ¤ºÍÄÚ´æÖÎÃ÷È·¾öÁËÕâЩÎÊÌ⣬ûÓйûÕæÓйØÕâЩ¹¥»÷µÄÏêϸÐÅÏ¢¡£×ÔÄêÍ·ÒÔÀ´£¬AppleÒÑÐÞ¸´ÁË6¸öÁãÈÕÎó²î¡£
https://securityaffairs.com/146411/security/apple-3-new-zero-day-bugs.html
3¡¢BatLoaderÔÚ½üÆÚ¹¥»÷ÖÐð³äChatGPTºÍMidjourney
eSentireÔÚ5ÔÂ16ÈÕ³ÆÆä·¢Ã÷ÁËBatLoaderð³äChatGPTºÍMidjourneyµÄ¹¥»÷Ô˶¯¡£Ñо¿Ö°Ô±³Æ£¬ÕâÁ½ÖÖAI·þÎñ¶¼ºÜÊÇÊܽӴý£¬¿ÉÊÇûÓйٷ½µÄ×ÔÁ¦Ó¦ÓóÌÐò£¬Óû§Ö»ÄÜͨ¹ýÍøÂç½çÃæºÍDiscordÓëChatGPTºÍMidjourney½»»¥¡£¹¥»÷ÕßʹÓÃÁËÕâÖÖ¿Õȱ£¬½«ËÑË÷AIÓ¦ÓóÌÐòµÄÓû§Òýµ½Ã°ÅÆÍøÒ³¡£ÔÚð³äChatGPTµÄÔ˶¯ÖУ¬BatLoaderͨ¹ýMSIX Windows App InstallerÎļþºÍRedline StealerÀ´Ñ¬È¾×°±¸¡£ÔÚð³äMidjourneyµÄÔ˶¯ÖУ¬»áÏÂÔØÓÉAshana Global Ltd.ÊðÃûµÄWindowsÓ¦ÓóÌÐò°ü¡£
https://www.esentire.com/blog/batloader-impersonates-midjourney-chatgpt-in-drive-by-cyberattacks
4¡¢ÊÖÒÕÌṩÉÌScanSourceÔâµ½ÀÕË÷¹¥»÷ÍøÕ¾ÔÝʱÎÞ·¨»á¼û
¾Ý5ÔÂ17ÈÕ±¨µÀ£¬ÊÖÒÕÌṩÉÌScanSource͸¶ÆäÔâµ½ÀÕË÷¹¥»÷£¬²¿·Öϵͳ¡¢ÓªÒµÔËÓªºÍ¿Í»§ÃÅ»§Êܵ½Ó°Ïì¡£5ÔÂ15ÈÕ×îÏÈ£¬ScanSourceµÄ¿Í»§³ÆÎÞ·¨»á¼û¹«Ë¾µÄÍøÕ¾¡£Ö®ºó£¬¸Ã¹«Ë¾Ö¤ÊµËûÔÚ5ÔÂ14ÈÕÔâµ½ÁËÀÕË÷¹¥»÷¡£´Ë´Î¹¥»÷µÄÓ°ÏìÊÇÖØ´óµÄ£¬ÓÉÓڸù«Ë¾Ëµ£¬ÔÚδÀ´Ò»¶Îʱ¼äÄÚ£¬Ïò¿Í»§ÌṩµÄ·þÎñ½«»á·ºÆðÑÓ³Ù£¬Ô¤¼Æ½«Ó°Ïì±±ÃÀºÍ°ÍÎ÷µÄÓªÒµ¡£±ðµÄ£¬Æä¹É¼ÛÔÚ5ÔÂ17ÈÕϵøÁË1.42%£¬Õâ¿ÉÄÜÊǹ¥»÷Ôì³ÉµÄÓ°Ïì¡£
https://www.bleepingcomputer.com/news/security/scansource-says-ransomware-attack-behind-multi-day-outages/
5¡¢KasperskyÅû¶¶ñÒâ¿ó¹¤Minas¹¥»÷Ô˶¯µÄÊÖÒÕϸ½Ú
KasperskyÓÚ5ÔÂ17ÈÕÅû¶Á˶ñÒâ¿ó¹¤Minas¹¥»÷Ô˶¯µÄÊÖÒÕϸ½Ú¡£Ñо¿Ö°Ô±´ÓÖ´ÐÐPowerShell×îÏÈÖØÐÞÁËËüµÄѬȾÁ´£ºPowerShell¾ç±¾Í¨¹ýʹÃüÍýÏë³ÌÐòÔËÐУ¬²¢´ÓÔ¶³Ì·þÎñÆ÷ÏÂÔØlgntoerr.gifÎļþ£¬½âÃܺóÌìÉú.NET DLL£¬²¢´ÓÆä×ÊÔ´ÖÐÌáȡϢÕùÃÜÈý¸öÎļþ£¬×îºó»áÔÚÄÚ´æÖÐÌáÈ¡²¢Æô¶¯¿ó¹¤DLL¡£Ñо¿Ö°Ô±³Æ£¬MinasÊÇÒ»¸öʹÓñê׼ʵÏֵĿ󹤣¬Ö¼ÔÚÒþ²ØÆä±£´æ¡£ÏÖÔÚÎÞ·¨Íêȫȷ¶¨×î³õµÄPowerShellÏÂÁîÊÇÔõÑùÖ´Ðе쬵«ÖÖÖÖ¼£ÏóÅú×¢ÊÇͨ¹ýGPOÖ´Ðеġ£
https://securelist.com/minas-miner-on-the-way-to-complexity/109692/
6¡¢Trend MicroÐû²¼¹ØÓÚ8220 GangÐÂÕ½ÂÔµÄÆÊÎö±¨¸æ
5ÔÂ16ÈÕ£¬Trend MicroÐû²¼Á˹ØÓÚ8220 GangÐÂÕ½ÂÔµÄÆÊÎö±¨¸æ¡£¸ÃÍÅ»ï×î½ü¼¸¸öÔÂÒ»Ö±ºÜ»îÔ¾£¬ËüʹÓÃÁËOracle WebLogic ServerÖеÄÎó²î£¨CVE-2017-3506£©À´·Ö·¢PowerShell£¬È»ºóÔÚÄÚ´æÖн¨ÉèÁíÒ»¸ö»ìÏýµÄPowerShell¾ç±¾¡£Õâ¸öеľ籾»á½ûÓÃWindows AMSI¼ì²â²¢Æô¶¯Ò»¸öWindows¶þ½øÖÆÎļþ£¬ËüËæºó»áÅþÁ¬µ½Ô¶³Ì·þÎñÆ÷ÒÔ¼ìË÷payload¡£±ðµÄ£¬¹¥»÷»¹Ê¹ÓÃÁËÒ»ÖÖÕýµ±Linux¹¤¾ßlwp-download£¬ÓÃÓÚÔÚÄ¿µÄÖ÷»úÉÏÉúÑÄí§ÒâÎļþ¡£
https://www.trendmicro.com/en_us/research/23/e/8220-gang-evolution-new-strategies-adapted.html


¾©¹«Íø°²±¸11010802024551ºÅ