APT40ÀûÓÃScanBoxÕì²ì¿ò¼Ü¹¥»÷°Ä´óÀûÑǵÄÕþ¸®»ú¹¹

Ðû²¼Ê±¼ä 2022-09-01
1¡¢APT40ÀûÓÃScanBoxÕì²ì¿ò¼Ü¹¥»÷°Ä´óÀûÑǵÄÕþ¸®»ú¹¹

      

ProofpointÔÚ8ÔÂ30ÈÕÅû¶ÁËAPT40½üÆڵĹ¥»÷»î¶¯¡£¹¥»÷Ö÷ÒªÕë¶Ô°Ä´óÀûÑǵط½ºÍÁª°îÕþ¸®»ú¹¹¼°Ã½Ìå»ú¹¹   £¬ºÍΪÄϺ£·çÁ¦ÎÐÂÖ»úÌṩά»¤·þÎñµÄÈ«ÇòÖع¤ÒµÖÆÔìÉÌ¡£2022Äê4ÔÂÖÁ6ÔÂÆÚ¼ä   £¬¹¥»÷Õßð³ä°Ä´óÀûÑdz¿±¨µÄÔ±¹¤   £¬Í¨¹ýµöÓã»î¶¯·Ö·¢ScanBox©¶´ÀûÓÿò¼Ü¡£Æ¾¾Ý×îÐÂÖ¤¾Ý   £¬ProofpointµÃ³ö½áÂÛ   £¬2022ÄêµÄ»î¶¯ÊÇAPT40×Ô2021Äê3ÔÂÒÔÀ´½øÐеÄͬһÇ鱨ÊÕ¼¯ÈÎÎñµÄµÚÈý½×¶Î   £¬Æäʱ¹¥»÷Õßð³äÐÂÎÅýÌå   £¬Í¨¹ýRTFÄ£°å×¢Èë¼ÓÔØMeterpreter¡£


https://www.proofpoint.com/us/blog/threat-insight/chasing-currents-espionage-south-china-sea   


2¡¢Òâ´óÀûʯÓ͹«Ë¾Eni³ÆÆäÄÚ²¿ÍøÂçÔ⵽δ¾­ÊÚȨµÄ·ÃÎÊ

      

¾Ý8ÔÂ31ÈÕ±¨µÀ   £¬Òâ´óÀûʯÓ͹«Ë¾Eni³ÆÆäÄÚ²¿± £»¤ÏµÍ³¼ì²âµ½Õë¶Ô¹«Ë¾ÍøÂçµÄδ¾­ÊÚȨµÄ·ÃÎÊ¡£Ä¿Ç°Ã»Óй¥»÷µÄ¼¼Êõϸ½Ú   £¬ÎÞ·¨È·¶¨¹¥»÷ÕßÉí·Ý¡¢ÈçºÎÈëÇÖµÄÒÔ¼°ËûÃǵĶ¯»ú¡£ÖªÇéÈËÊ¿³Æ   £¬EniºÃÏñÔâµ½ÁËÀÕË÷¹¥»÷¡£Òâ´óÀûÄÜÔ´²¿ÃŽüÆÚËƺõÔâµ½Á˹¥»÷   £¬ÉÏÖÜÄ©   £¬¾­ÓªÒâ´óÀûµçÁ¦Êг¡µÄÕþ¸®»ú¹¹Gestore dei Servizi Energetici SpAÔâµ½¹¥»÷¡£GSEµÄ»ù´¡ÉèÊ©Êܵ½Ó°Ïì   £¬ÍøÕ¾ÈÔ´¦ÓÚÖжÏ״̬¡£


https://securityaffairs.co/wordpress/135116/hacking/eni-suffered-cyberattack.html


3¡¢SecuronixÅû¶Ð¶ñÒâÈí¼þ»î¶¯GO#WEBBFUSCATORµÄϸ½Ú

      

¾Ý8ÔÂ30ÈÕ±¨µÀ   £¬Securonix·¢ÏÖÒ»Æð»ùÓÚGolangµÄÁ¬Ðø¹¥»÷»î¶¯GO#WEBBFUSCATOR¡£Ñ¬È¾Ê¼ÓÚÒ»·â´øÓжñÒâÎĵµGeos-Rates.docxµÄµöÓãÓʼþ   £¬Ëü»áÏÂÔØÄ£°åÎļþ¡£¸ÃÎļþ°üÂÞÒ»¸ö¾­¹ý»ìÏýµÄVBSºê   £¬ÆôÓúêºó   £¬´úÂë»á´ÓÔ¶³Ì×ÊÔ´ÏÂÔØJPGͼÏñ   £¬È»ºóʹÓÃcertutil.exe½«Æä½âÂëΪ¿ÉÖ´ÐÐÎļþmsdllupdate.exe²¢Æô¶¯Ëü¡£ÔÚͼÏñ¼ì²ìÆ÷ÖÐ   £¬.JPGÎļþÔòÏÔʾÁËÓÉNASAÓÚ2022Äê7ÔÂÐû²¼µÄÐÇϵÍÅSMACS 0723¡£¶þ½øÖÆmsdllupdate.exe½ÓÄÉÁ˶àÖÖ»ìÏý¼¼ÊõÀ´ÈƹýAVʹ·ÖÎö±äµÃÀ§ÄÑ¡£


https://www.securonix.com/blog/golang-attack-campaign-gowebbfuscator-leverages-office-macros-and-james-webb-images-to-infect-systems/


4¡¢McAfee·¢ÏÖ5¸ö¶ñÒâChromeÀ©Õ¹Òѱ»°²×°Áè¼Ý140Íò´Î

      

McAfeeÔÚ8ÔÂ29ÈÕ±¨µÀ   £¬Ñо¿ÈËÔ±·¢ÏÖÁË5¸ö¿ÉÒÔÇÔÈ¡Óû§ä¯ÀÀ»î¶¯µÄGoogle ChromeÀ©Õ¹·¨Ê½   £¬×ÜÏÂÔØÁ¿ÒÑÁè¼Ý140Íò´Î¡£ÕâЩ¶ñÒâÀ©Õ¹µÄÄ¿µÄÊǼà¿ØÓû§·ÃÎʵçÉÌÍøÕ¾   £¬²¢Ð޸ķÃÎÊÕßµÄcookie   £¬Ê¹Æä¿´ÆðÀ´ÊÇͨ¹ýÍƼöÁ´½ÓÀ´µÄ   £¬ÕâÑù   £¬À©Õ¹·¨Ê½µÄ¿ª·¢ÈËÔ±¿ÉÒÔÔÚÕâЩ¹ºÖûÖлñµÃÁªÓª·Ñ¡£¶ñÒâÀ©Õ¹·Ö±ðΪNetflix Party¡¢Netflix Party 2¡¢Full Page Screenshot Capture¡¢FlipShopeºÍAutoBuy Flash Sales   £¬ËäÈ»ËüÃDz»»áÖ±½ÓÓ°ÏìÓû§   £¬µ«»á´øÀ´ÑÏÖصÄÒþ˽·çÏÕ¡£


https://www.mcafee.com/blogs/other-blogs/mcafee-labs/malicious-cookie-stuffing-chrome-extensions-with-1-4-million-users/


5¡¢ÎÚ¿ËÀ¼¹ú¼Ò¾¯²ì¹Ø±ÕijºÚ¿ÍÍÅ»ïʹÓõĺô½ÐÖÐÐÄÍøÂç

      

ýÌå8ÔÂ30ÈÕ³Æ   £¬ÎÚ¿ËÀ¼¹ú¼Ò¾¯²ì(NPU)¹Ø±ÕÁËÒ»¸öºÚ¿ÍÍÅ»ïʹÓõĺô½ÐÖÐÐÄÍøÂç¡£¾Ý³Æ   £¬¸ÃÍŻﻹÉæÏÓÕ©Æ­¶Ô¼ÓÃÜ»õ±Ò¡¢Ö¤È¯¡¢»Æ½ðºÍʯÓÍͶ×ʸÐÐËȤµÄÎÚ¿ËÀ¼ºÍÅ·Ã˹ú¼ÒµÄ¹«Ãñ¡£ÔÚÕ©Æ­»î¶¯ÖÐ   £¬¹¥»÷ÕßʹÓÃÁËÈí¼þºÍ¸ß¿Æ¼¼É豸   £¬Ã°³ä¹úÓÐÒøÐлú¹¹µÄÔ±¹¤   £¬ÇÃÕ©Ä¿±êµÄÒøÐп¨»úÃÜÊý¾Ý¡£È»ºó   £¬ÔÚÓÕÆ­Ä¿±ê½«×ʽðתÒƵ½¹¥»÷ÕßµÄÕË»§ºóÖжÏËùÓÐͨÐÅ¡£Ö´·¨ÈËÔ±ËѲéÁËÓë´Ë´Î»î¶¯Ïà¹ØµÄ¶à¸öºô½ÐÖÐÐIJ¢Ã»ÊÕÁ˼ÆËã»ú¡¢ÊÖ»úºÍÊý¾Ý¼Ç¼   £¬Ïà¹ØÏÓÒÉÈ˽«ÃæÁÙ×î¸ß12ÄêµÄ¼à½û¡£


https://www.bleepingcomputer.com/news/security/ukraine-takes-down-cybercrime-group-hitting-crypto-fraud-victims/


6¡¢CiscoÐû²¼3¸ö·Ö·¢¶àÖÖ¶ñÒâÈí¼þµÄ»î¶¯µÄ·ÖÎö³ÂËß

      

8ÔÂ30ÈÕ   £¬Cisco TalosÐû²¼³ÂËß³ÆÊӲ쵽2022Äê3ÔÂÖÁ6ÔÂÆÚ¼äµÄ3¸ö¶ÀÁ¢µ«Ïà¹ØµÄ¹¥»÷»î¶¯¡£ÕâЩ»î¶¯·Ö·¢Á˶à¸ö¶ñÒâÈí¼þ   £¬°üÂÞModernLoader bot¡¢ÐÅÏ¢ÇÔÈ¡·¨Ê½RedLineºÍÍÚ¿ó¶ñÒâÈí¼þ¡£¹¥»÷ÕßʹÓÃPowerShell¡¢.NET·¨Ê½¼¯ÒÔ¼°HTAºÍVBSÎļþÔÚÄ¿±êÖÐÁ÷´«   £¬×îÖÕ°²×°ÆäËü¶ñÒâÈí¼þ   £¬ÈçSystemBCľÂíºÍDCRAT¡£×îÖÕµÄpayloadËƺõÊÇModernLoader   £¬Ëü¿Éͨ¹ýÊÕ¼¯ÏµÍ³ÐÅÏ¢ºÍ°²×°ÖÖÖÖÄ£¿éÀ´³äµ±Ô¶³Ì·ÃÎÊľÂí¡£


https://blog.talosintelligence.com/2022/08/modernloader-delivers-multiple-stealers.html