Ñо¿ÍŶӷ¢ÏÖÀûÓÃÀ¬»øÓʼþ·Ö·¢¶ñÒâÈí¼þMETAµÄ»î¶¯

Ðû²¼Ê±¼ä 2022-04-13

Ñо¿ÍŶӷ¢ÏÖÀûÓÃÀ¬»øÓʼþ·Ö·¢¶ñÒâÈí¼þMETAµÄ»î¶¯


¾ÝýÌå4ÔÂ10ÈÕ±¨µÀ £¬ÐÂÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þMETAÕýÔÚͨ¹ýÀ¬»øÓʼþ»î¶¯·Ö·¢¡£¸Ã¶ñÒâÈí¼þÀûÓôøÓкêµÄExcelµç×Ó±í¸ñѬȾĿ±ê £¬ÒÔÐé¼ÙµÄתÕË֪ͨΪÓÕ¶ü £¬Ö¼ÔÚÇÔÈ¡´æ´¢ÔÚChrome¡¢Edge¡¢FirefoxÒÔ¼°¼ÓÃÜ»õ±ÒÇ®°üÖеÄÃÜÂë¡£´ËÍâ £¬META¿Éͨ¹ýPowerShell¸Ä¶¯Windows DefenderÒÔ½«.exeÎļþÅųýÔÚɨÃ跶Χ֮Íâ £¬ÒÔÈƹýÄþ¾²¼ì²â¡£META¡¢Mars StealerºÍBlackGuardÊÇÐÂÐÍÐÅÏ¢ÇÔÈ¡Èí¼þÖ®Ò» £¬¹¥»÷ÕßÏ£ÍûÀûÓÃRaccoon StealerÍ˳öÊг¡µÄ»ú»á £¬Ê¹Æä³ÉΪ¼ÌÈÎÕß¡£


https://www.bleepingcomputer.com/news/security/new-meta-information-stealer-distributed-in-malspam-campaign/


NB65ÍÅ»ï»ùÓÚConti¿ª·¢µÄÐÂÀÕË÷Èí¼þÒÔ¶íÂÞ˹ΪĿ±ê


ýÌå4ÔÂ10ÈÕ±¨µÀ £¬ºÚ¿ÍÍÅ»ïNB65ʹÓûùÓÚConti¿ª·¢µÄÐÂÀÕË÷Èí¼þ¹¥»÷¶íÂÞ˹¡£ÔÚ¹ýÈ¥µÄÒ»¸öÔÂÀï £¬NB65¹¥»÷Á˶íÂÞ˹µÄ¶à¸ö×éÖ¯ £¬°üÂÞÎļþ¹ÜÀíÔËÓªÉÌTensor¡¢º½Ìì¾ÖRoscosmosºÍ¹ã²¥µçÊǪ́VGTRK¡£×Ô3Ôµ×ÒÔÀ´¹¥»÷ÕßתÏòʹÓÃÒ»ÖÖмÆı £¬ÆäÀûÓÃ鶵ÄContiÀÕË÷Èí¼þµÄÔ´´úÂë´´½¨ÁË×Ô¼ºµÄÀÕË÷Èí¼þ¡£Ñо¿ÈËÔ±ÉÏÖÜÄ©ÔÚVirusTotal·¢ÏÖÁ˸ÃÑù±¾ £¬²¢È·¶¨ËüÓëContiÑù±¾66%µÄ´úÂëÏàͬ¡£


https://securityaffairs.co/wordpress/130051/hacktivism/nb65-modified-version-conti-ransomware.html


Ñо¿ÈËÔ±·¢ÏÖÊ׸öÕë¶ÔAWS LambdaµÄ¶ñÒâÈí¼þDenonia


¾Ý4ÔÂ7ÈÕ±¨µÀ £¬Cado Security·¢ÏÖÁËÊ׸öÕë¶ÔAWS LambdaÔÆ»·¾³µÄ¶ñÒâÈí¼þDenonia¡£AWS LambdaÊÇÒ»¸öÎÞ·þÎñÆ÷¼ÆËãƽ̨ £¬ÓÃÓÚÔËÐÐÀ´×ÔÊý°Ù¸öAWS SaaSÓ¦Ó÷¨Ê½µÄ´úÂë¡£DenoniaÊÇÒ»¸ö»ùÓÚGoµÄ·â×°·¨Ê½ £¬Òѱ»ÓÃÓÚ¹¥»÷»î¶¯ÖÐ £¬Ö¼ÔÚ²¿ÊðÒ»¸ö×Ô½ç˵µÄXMRig¼ÓÃܿ󹤡£Ñо¿ÈËÔ±·¢ÏÖÓÚ1Ô·ÝÉÏ´«µ½VirusTotalµÄÑù±¾ £¬ËµÃ÷¹¥»÷ÖÁÉÙÁ¬ÐøÁ˼¸¸öÔ¡£Ä¿Ç°Ñ¬È¾Ã½½éÉв»Ã÷È· £¬Ñо¿ÈËÔ±ÍƶϹ¥»÷Õß¿ÉÄÜʹÓÃÁË鶵ÄAWSÃÜÔ¿¡£


https://www.bleepingcomputer.com/news/security/new-malware-targets-serverless-aws-lambda-with-cryptominers/


ÃÀ¹úSuperCareÔâδ¾­ÊÚȨ·ÃÎÊй¶Áè¼Ý30ÍòÈ˵ÄÐÅÏ¢


ýÌå4ÔÂ11ÈÕ³Æ £¬ÃÀ¹ú¼ÓÀû¸£ÄáÑǵÄSuperCare Healthй¶318379È˵ÄÐÅÏ¢¡£¸ÃʼþÔÚ2021Äê7ÔÂ27ÈÕ±»·¢ÏÖ £¬ÆäʱÆä¶à¸öϵͳÉϼì²âµ½Î´¾­ÊÚȨµÄ»î¶¯¡£ËæºóµÄÊÓ²ìÏÔʾ £¬²¿ÃÅϵͳÔÚ7ÔÂ23ÈÕÖÁ7ÔÂ27ÈÕÒѱ»·ÃÎÊ¡£½ñÄê2ÔÂ4ÈÕ £¬¸Ã¹«Ë¾È·¶¨Ð¹Â¶ÐÅÏ¢°üÂÞ»¼ÕßÐÕÃû¡¢µØÖ·¡¢²¡ÀúºÅ¡¢Ò½ÔºÕ˺š¢½¡¿µºÍÀíÅâÏà¹ØÐÅÏ¢µÈ¡£SuperCareÓÚ3ÔÂ25ÈÕÏòÊÜÓ°ÏìµÄ¸öÈË·¢³öÁ˸ÃʼþµÄ֪ͨ £¬²¢ÌåÏÖ鶵ÄÊý¾ÝÄ¿Ç°²¢Î´±»ÀÄÓá£


https://www.infosecurity-magazine.com/news/supercare-data-breach-300000/


AvastÐû²¼¹ØÓÚеÄParrot TDS·Ö·¢RATµÄ·ÖÎö³ÂËß


4ÔÂ7ÈÕ £¬AvastÐû²¼¹ØÓÚÒ»ÖÖÃûΪParrotµÄÐÂÐͽ»Í¨Ö¸»Óϵͳ(TDS)µÄ·ÖÎö³ÂËß¡£ËüÄ¿Ç°Õý±»ÓÃÓÚ¹¥»÷»î¶¯FakeUpdate £¬¸Ã»î¶¯Í¨¹ýÐé¼ÙµÄä¯ÀÀÆ÷¸üÐÂ֪ͨ·Ö·¢RAT¡£Parrot TDSÒÑѬȾÍйÜÁË16500¶à¸öÍøÕ¾µÄ¶à¸öWeb·þÎñÆ÷ £¬Éæ¼°¸öÈ˲©¿ÍÍøÕ¾¡¢´óѧÍøÕ¾ºÍµØ·½Õþ¸®ÍøÕ¾µÈ¡£¸Ã»î¶¯ËƺõÓÚ2022Äê2Ô¿ªÊ¼ £¬µ«Parrot×îÔç¿É×·Ëݵ½2021Äê10Ô¡£Parrot TDS ÓëÆäËüTDSÖ÷ÒªÇø±ðÖ®Ò»ÊÇËüµÄ¹ã·ºÐÔ £¬±»Ñ¬È¾ÍøÕ¾¼äËƺõûÓÐÈκÎÅäºÏµã¡£    


https://decoded.avast.io/janrubin/parrot-tds-takes-over-web-servers-and-threatens-millions/


KasperskyÐû²¼¹ØÓÚBlackCatÍÅ»ïµÄ¼¼Êõ·ÖÎö³ÂËß


KasperskÓÚ4ÔÂ7ÈÕÐû²¼Á˹ØÓÚºÚ¿ÍÍÅ»ïBlackCatµÄ¼¼Êõ·ÖÎö³ÂËß¡£BlackCatÒ²³ÆALPHV £¬ÓÚ2021Äê12Ô³õ¿ªÊ¼»îÔ¾¡£ÓëÆäËüÀÕË÷Èí¼þ×î´óÇø±ðÖ®Ò»ÊÇBlackCatÊÇÓÃRust±àдµÄ £¬ËûÃǵĻù´¡ÉèÊ©ÍøÕ¾µÄ¿ª·¢·½Ê½Ò²ÓëÆäËüÍÅ»ï²îÒì £¬WindowsºÍLinuxÑù±¾¾ùÓС£´ËÍâ £¬BlackCatʹÓÃÁË×Ô½ç˵¹¤¾ßFendrµÄ±äÌå £¬Ö¤Ã÷ÆäÓëBlackMatterÓйØÁª¡£³ÂËß»¹·ÖÎöÁËBlackCatÖ´Ðй¥»÷ʱµÄ¼¼Êõϸ½Ú¡£


https://securelist.com/a-bad-luck-blackcat/106254/





Äþ¾²¹¤¾ß


vmlinux-to-elf


´Ë¹¤¾ßÔÊÐí´Ó vmlinux/vmlinuz/bzImage/zImage ÄÚºËÓ³Ïñ»ñÈ¡ÍêÈ«¿É·ÖÎöµÄ .ELF Îļþ¡£


https://github.com/marin-m/vmlinux-to-elf


DumpSMBShare


´Ó Windows SMB ¹²ÏíÔ¶³Ìת´¢ÎļþºÍÎļþ¼Ð¡£


https://github.com/p0dalirius/DumpSMBShare


Skanuvaty 


ΣÏյĿìËÙ dns/ÍøÂç/¶Ë¿ÚɨÃèÒÇ £¬¶àºÏÒ»¡£


https://github.com/Esc4iCEscEsc/skanuvaty





Äþ¾²·ÖÎö


Microsoft µÄРAutopatch ¹¦Ð§¿É×ÊÖúÆóÒµ±£³Öϵͳ¸üÐÂ


https://thehackernews.com/2022/04/microsofts-new-autopatch-feature-to.html


Windows 11 µÄй¦Ð§


https://www.bleepingcomputer.com/news/microsoft/here-are-the-new-features-coming-to-windows-11/


¹È¸èͨ¹ýеĿª·¢¼Æı¸ü¸ÄÌá¸ß Android µÄÄþ¾²ÐÔ


https://www.bleepingcomputer.com/news/security/google-boosts-android-security-with-new-set-of-dev-policy-changes/


GitHub Action ¿É·ÀÖ¹ÔÚ´úÂëÖÐÌí¼ÓÒÑ֪©¶´


https://securityaffairs.co/wordpress/130067/security/dependency-review-github-action.html


CVE-2022-22292 ¿ÉÓÃÓÚÈëÇÖÈýÐÇ Android É豸


https://securityaffairs.co/wordpress/129942/hacking/cve-2022-22292-hack-samsung-android-devices.html


Ð嵀 SolarMarker (Jupyter) »î¶¯


https://unit42.paloaltonetworks.com/solarmarker-malware/