Kaspersky·¢ÏÖAPT41ÀûÓÃMoonBounceµÄ¹¥»÷»î¶¯

Ðû²¼Ê±¼ä 2022-01-24

Kaspersky·¢ÏÖAPT41ÀûÓÃMoonBounceµÄ¹¥»÷»î¶¯


1ÔÂ20ÈÕ£¬KasperskyÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þMoonBounceµÄ·ÖÎö³ÂËß ¡£Ñо¿ÈËÔ±³Æ£¬MoonBounceÊÇÆù½ñΪֹÔÚÒ°Íâ·¢ÏÖµÄ×îÏȽøµÄUEFI¹Ì¼þ¶ñÒâÈí¼þ£¬ÓëºÚ¿Í×éÖ¯APT41£¨Ò²³ÆÎªWinnti£©ÓÐ¹Ø ¡£MoonBounceÖ²ÈëÔÚÖ÷°åµÄSPIÉÁ´æÉÏ£¬Òò´Ë¼´Ê¹¸ü»»Ó²ÅÌÒ²ÎÞ·¨½«Æä¸ù³ý ¡£ÕâÊǽüÆÚ·¢ÏֵĵÚÈý¸öUEFI¶ñÒâÈí¼þ£¬Ö®Ç°Á½¸öΪFinFisherºÍESPecter ¡£KasperskyÌåÏִ˴ι¥»÷¾ßÓи߶ÈÕë¶ÔÐÔ£¬Ä³¸ö¿ØÖÆ×ż¸¼ÒÔËÊä¼¼ÊõÏà¹ØÆóÒµµÄ×éÖ¯ÒѳÉΪ¹¥»÷Ä¿±ê ¡£


https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/


ContiÍÅ»ïÉù³Æ¶ÔÓ¡¶ÈÄáÎ÷ÑÇÑëÐеÄÀÕË÷¹¥»÷ÂôÁ¦


¾ÝýÌå1ÔÂ20ÈÕ±¨µÀ£¬Ó¡¶ÈÄáÎ÷ÑÇÒøÐУ¨BI£©ÈÏ¿ÉÆäÔâµ½ÀÕË÷¹¥»÷ ¡£¸ÃÐз¢ÑÔÈËÌåÏÖ£¬¹¥»÷·¢ÉúÔÚÉϸöÔ£¬¹¥»÷ÕßÇÔÈ¡Á˲¿ÃÅÔ±¹¤µÄÐÅÏ¢£¬²¢ÔÚÊ®¼¸¸öϵͳÉϰ²×°ÁËÀÕË÷Èí¼þ£¬µ«ÆäÔËÓª²¢Î´Êܵ½Ó°Ïì ¡£ContiÍÅ»ïÉù³Æ¶Ô´ËÊÂÂôÁ¦£¬Èç¹ûÓ¡ÄáÒøÐв»Ö§¸¶Êê½ð£¬ËûÃǽ«¹ûÈ»¸ÃÒøÐÐ13.88 GBµÄÎļþ ¡£Ç°²»¾Ã£¬Conti»¹¹¥»÷Á˰®¶ûÀ¼DoH¡¢HSE£¬ºÍÓªÏú¹«Ë¾RR Donnelly ¡£


https://www.bleepingcomputer.com/news/security/indonesias-central-bank-confirms-ransomware-attack-conti-leaks-data/


Ñо¿ÈËÔ±³ÆÊýÊ®¸öWordPressÖ÷ÌâºÍ²å¼þÒѱ»Ö²ÈëºóÃÅ


JetPackÔÚ1ÔÂ18ÈÕÐû²¼³ÂËߣ¬³ÆÒÑÔÚÊýÊ®¸öWordPressÖ÷ÌâºÍ²å¼þÖз¢ÏÖºóÃÅ ¡£Ñо¿ÈËÔ±³Æ£¬¹¥»÷ÕßÒÑÔÚAccessPress ThemesµÄ40¸öÖ÷ÌâºÍ53¸ö²å¼þÖÐÖ²ÈëºóÃÅ ¡£¾­¹ýÊÓ²ìµÃÖª£¬AccessPress ThemesÓÚ2021Äê9ÔÂÉϰëÔÂÔâµ½¹¥»÷£¬ÆäÊ±ÍøÕ¾ÉϵÄÀ©Õ¹·¨Ê½±»×¢ÈëÁ˺óÃÅ ¡£ÊÜѬȾµÄÀ©Õ¹·¨Ê½°üÂÞÒ»¸öwebshell dropper£¬Ê¹¹¥»÷Õß¿ÉÒÔÍêÈ«·ÃÎÊÄ¿±êÍøÕ¾£¬¸Ã©¶´×·×ÙΪCVE-2021-24867 ¡£


https://thehackernews.com/2022/01/hackers-planted-secret-backdoor-in.html



ÀûÓÃCWPµÄÎļþ°üÂÞºÍÈÎÒâдÈë©¶´¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ


ýÌå1ÔÂ22ÈÕ±¨µÀ£¬Control Web PanelÖдæÔÚ2¸öÑÏÖØµÄ©¶´ ¡£Control Web Panel£¨ÒÔǰµÄCentOS Web Panel£©ÊÇÒ»¸ö¿ªÔ´µÄLinux¿ØÖÆÃæ°åÈí¼þ£¬ÓÃÓÚ²¿ÊðWebÍйܻ·¾³ ¡£µÚÒ»¸öÊÇÎļþ°üÂÞ©¶´£¨CVE-2021-45467£©£¬¹¥»÷ÕßÖ»ÐèÐÞ¸ÄincludeÓï¾ä¾Í¿ÉÒÔÔ¶³Ì×¢Èë¶ñÒâ´úÂë»òʵÏÖ´úÂëÖ´ÐÐ ¡£µÚ¶þ¸öΪÈÎÒâÎļþдÈë©¶´£¨CVE-2021-45466£©£¬½áºÏÀûÓÃÕâÁ½¸ö©¶´¿ÉÒÔÔÚÒ×Êܹ¥»÷µÄLinux·þÎñÆ÷ÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ ¡£


https://securityaffairs.co/wordpress/127058/hacking/control-web-panel-flaws.html


MoleratsÍÅ»ïÀûÓöà¸öÔÆ·þÎñ¶ÔÖж«µØÓò½øÐмäµý¹¥»÷


¾ÝýÌå1ÔÂ22ÈÕ±¨µÀ£¬Äþ¾²¹«Ë¾Zscaler·¢ÏÖMoleratsÍÅ»ïÕë¶ÔÖж«µØÓòµÄ¼äµý»î¶¯ ¡£¾ÝϤ£¬¹¥»÷´Ó2021Äê7Ô¾ÍÒÑ¿ªÊ¼£¬¹¥»÷ÕßÀûÓúϷ¨µÄÔÆ·þÎñ£¨ÈçGoogle DriveºÍDropbox£©ÍйܶñÒâÈí¼þpayload£¬´ÓÖж«µØÓòµÄÄ¿±êÖÐÇÔÈ¡Êý¾Ý ¡£´Ë´Î»î¶¯ÀûÓÃÓëÒÔÉ«ÁкͰÍÀÕ˹̹³åÍ»Ïà¹ØµÄÓÕ¶ü£¬ÔÚÄ¿±êϵͳÉϰ²×°.NETºóÃÅ£¬Ö÷ҪĿ±ê°üÂÞ°ÍÀÕË¹Ì¹ÒøÐÐÒµÔ±¹¤¡¢°ÍÀÕ˹̹Õþµ³³ÉÔ±£¬ÒÔ¼°ÍÁ¶úÆä¼ÇÕßµÈ ¡£


https://thehackernews.com/2022/01/molerats-hackers-hiding-new-espionage.html


×ÖÄ»ÍøÕ¾OpenSubtitles½ü700ÍòÓû§µÄÐÅϢй¶


¾Ý1ÔÂ23ÈÕ±¨µÀ£¬×ÖÄ»ÍøÕ¾OpenSubtitlesÔâµ½¹¥»÷£¬6783158¸öÓû§µÄÐÅÏ¢ÒѾ­Ð¹Â¶ ¡£2021Äê8Ô£¬ÍøÕ¾¹ÜÀíÔ±ÊÕµ½Êê½ð֪ͨºó²ÅÒâʶµ½ÆäÒÑÔâµ½¹¥»÷ ¡£¹¥»÷Õß»¹ÌåÏÖ»áÌṩ֧³ÖÒÔÐÞ¸´ÍøÕ¾ÖеÄ©¶´£¬µ«ÔÚÖ§¸¶Êê½ðºó¹¥»÷Õß´Óδ×ÊÖúËûÃǼӹÌÍøÕ¾£¬²¢ÔÚ1ÔÂ11ÈÕ¹ûÈ»Á˱»µÁÊý¾Ý ¡£¾ÝϤ£¬ºÚ¿Íͨ¹ýSQL×¢Èë¹¥»÷·ÃÎÊÁËÍøÕ¾µÄÊý¾Ý¿â£¬ÇÔÈ¡ÁËÓû§Óʼþ¡¢IPµØÖ·¡¢Óû§Ãû¡¢ËùÔÚ¹ú¼ÒºÍÃÜÂëµÈÐÅÏ¢ ¡£


https://securityaffairs.co/wordpress/127092/data-breach/opensubtitles-data-breach.html



Äþ¾²¹¤¾ß


Narthex


ÊÇÒ»¸öÄ£¿é»¯ºÍ×îСµÄ×ÖµäÉú³ÉÆ÷£¬ÓÃÓÚÓà C ºÍ Shell ±àдµÄ Unix ºÍÀà Unix ²Ù×÷ϵͳ ¡£


https://github.com/MichaelDim02/Narthex


Iptable_Evil 


IptablesµÄºóÃÅ£¬Ê¹¶ñÒâÊý¾Ý°üͨ¹ýiptables£¬ÎÞÂÛ·À»ðǽ¹æÔòÈçºÎ ¡£


https://github.com/FlamingSpork/iptable_evil



iMonitor


ÊÇÒ»¿î»ùÓÚiMonitorSDKµÄ¶ËµãÐÐΪ¼à¿Ø·ÖÎöÈí¼þ ¡£


https://github.com/wecooperate/iMonitor/releases



Äþ¾²·ÖÎö


΢ÈíÐÞ¸´ÁË Windows 10 µÄ Outlook ËÑË÷ÎÊÌâ


΢ÈíÐÞ¸´Á˰²×°2021 Äê 11 ÔÂÐû²¼µÄ Windows 10 Äþ¾²¸üкóµ¼Ö Outlook Óû§·ºÆðËÑË÷ÎÊÌâµÄÎÊÌâ ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-outlook-search-issues-for-windows-10-users/


WordPress²å¼þ´æÔÚ©¶´


WP HTML MailÖдæÔÚÒ»¸öÑÏÖØµÄ¿çÕ¾µã½Å±¾(XSS)©¶´£¬Ó°ÏìÁè¼Ý20,000¸öWordPressÍøÕ¾ ¡£


https://threatpost.com/wordpress-insecure-plugin-rest-api/177866/