¶íÂÞ˹UNC5812Íþв×éÖ¯Ãé×¼ÎÚ¾üбø

Ðû²¼Ê±¼ä 2024-10-30

1. ¶íÂÞ˹UNC5812Íþв×éÖ¯Ãé×¼ÎÚ¾üбø


10ÔÂ28ÈÕ£¬¶íÂÞ˹Íþв×éÖ¯¡°UNC5812¡±±»½Ò¶¿ªÕ¹»ìºÏ¼äµý/Ó°Ïì»î¶¯£¬Õë¶ÔÎÚ¿ËÀ¼¾ü¶ÓбøʹÓÃWindowsºÍAndroid¶ñÒâÈí¼þ¡£¸Ã×é֯ͨ¹ý¼Ùð¡°Ãñ·À¡±½ÇÉ«ÉèÁ¢ÍøÕ¾ºÍTelegramƵµÀ£¬Á÷´«ÃûΪ¡°Sunspinner¡±µÄÐé¼ÙÕÐļ¹æ±ÜÓ¦Ó÷¨Ê½£¬ÒÔÊý¾ÝÇÔÈ¡ºÍʵʱ¼àÊÓΪĿµÄ¡£¹È¸èÒÑʵʩ±£»¤´ëÊ©£¬µ«´Ë´ÎÐж¯ÏÔʾÁ˶íÂÞ˹ÔÚÍøÂçÕ½ÁìÓòµÄÁ¬ÐøʹÓú͹㷺ÄÜÁ¦¡£UNC5812²»Ã°³äÕþ¸®»ú¹¹£¬²¢·¢±í×èµ²ÎÚ¿ËÀ¼ÕÐļºÍ·¢¶¯Ðж¯µÄÑÔÂÛ£¬Ö¼ÔÚ¼¤ÆðÃñÖڵIJ»ÐÅÈκͷ´¿¹ÇéÐ÷¡£¸ÃÐé¼ÙÓ¦Ó÷¨Ê½ÌṩWindowsºÍAndroidÏÂÔØ£¬·Ö±ð°²×°¶ñÒâÈí¼þ¼ÓÔØÆ÷Pronsis LoaderºÍÐÅÏ¢ÇÔÈ¡·¨Ê½PureStealer£¬ÒÔ¼°ÉÌÒµºóÃÅCraxsRAT¡£ÎªÁËÖ´ÐжñÒâ»î¶¯£¬¸ÃÓ¦Ó÷¨Ê½ÓÕÆ­Óû§½ûÓÃAndroid·´¶ñÒâÈí¼þ¹¤¾ß²¢ÊÚÓèΣÏÕȨÏÞ¡£GoogleÒѸüÐÂGoogle Play±£»¤¹¦Ð§ºÍChromeµÄ¡°Äþ¾²ä¯ÀÀ¡±¹¦Ð§£¬ÒÔ¼ì²âºÍ×èÖ¹Ïà¹Ø¶ñÒâÈí¼þ¡£https://www.bleepingcomputer.com/news/security/russia-targets-ukrainian-conscripts-with-windows-android-malware/


2. ¶íÂÞ˹Midnight BlizzardºÚ¿Í×éÖ¯ÌᳫÐÂÐÍÐÅÏ¢ÇÔÈ¡»î¶¯


10ÔÂ30ÈÕ£¬¶íÂÞ˹ºÚ¿Í×éÖ¯¡°ÎçÒ¹±©Ñ©¡±£¨Midnight Blizzard£©½üÆÚÕë¶ÔÕþ¸®ÊÂÇéÈËÔ±ÌᳫÐÂÐÍÐÅÏ¢ÇÔÈ¡»î¶¯£¬ÀûÓÃÓã²æʽÍøÂçµöÓãµç×ÓÓʼþ·¢ËÍÔ¶³Ì×ÀÃæЭÒ飨RDP£©ÅäÖÃÎļþ£¬Ê¹Êܺ¦ÕßÉ豸ÔâÊÜÍêÈ«·ÃÎÊȨÏ޵Ĺ¥»÷¡£Î¢ÈíÍþвÇ鱨ÍŶÓ×·×Ùµ½¸Ã»î¶¯×Ô10ÔÂ22ÈÕÆð£¬ÒÑÏòÈ«Çò°üÂÞÓ¢¹ú¡¢Å·ÖÞ¡¢°Ä´óÀûÑǺÍÈÕ±¾µÈÊýÊ®¸ö¹ú¼Ò/µØÓòµÄÕþ¸®¡¢Ñ§Êõ½ç¡¢¹ú·À¡¢·ÇÕþ¸®×éÖ¯µÈ²¿ÃÅ·¢ËÍÊýǧ·â´ËÀàÓʼþ¡£ÕâЩÓʼþÖаüÂÞÃô¸ÐÉèÖ㬿ɵ¼Ö´óÁ¿ÐÅϢй¶£¬ÉõÖÁÄþ¾²ÃÜÔ¿ºÍÏúÊÛµãÉ豸Ҳ¿ÉÄÜÊܵ½Ó°Ïì¡£ºÚ¿Í»¹Í¨¹ýð³ä΢ÈíÔ±¹¤µÈ·½Ê½ÓÕÆ­Êܺ¦Õß´ò¿ªÓʼþ¡£´Ë´Î»î¶¯ÓÈΪÒýÈËעĿ£¬ÒòΪʹÓÃRDPÅäÖÃÎļþÊÇMidnight BlizzardÕ½ÊõµÄнø²½¡£ÑÇÂíÑ·ºÍÎÚ¿ËÀ¼Õþ¸®¼ÆËã»úÓ¦¼±ÏìӦС×éÒ²·¢ÏÖÁËÀàËƻ£¬ÆäÖÐÑÇÂíÑ·Ö¸³ö¶íÂÞ˹Íâ¹úÇ鱨¾Ö£¨SVR£©ÕýÕë¶ÔÕþ¸®»ú¹¹¡¢¹«Ë¾ºÍ¾ü¶ÓÌᳫÍøÂçµöÓã»î¶¯£¬Ö¼ÔÚÇÔÈ¡¶íÂÞ˹¶ÔÊÖµÄƾ֤¡£


https://therecord.media/russia-midnight-blizzard-hackers-target-government-sector


3. ´ó¹æÄ£PSAUXÀÕË÷Èí¼þ¹¥»÷Ãé×¼22,000¸öCyberPanelʵÀý


10ÔÂ29ÈÕ£¬Áè¼Ý22,000¸öCyberPanelʵÀýÒò´æÔÚÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Â©¶´¶ø̻¶ÓÚ·çÏÕÖ®ÖУ¬ÕâЩʵÀýÔÚPSAUXÀÕË÷Èí¼þ¹¥»÷Öм¸ºõÈ«²¿ÂÙÏÝ¡£Äþ¾²Ñо¿Ô±DreyAnd·¢ÏÖCyberPanel 2.3.6£¨¼°¿ÉÄÜÊÜÓ°ÏìµÄ2.3.7°æ±¾£©´æÔÚÉí·ÝÑé֤ȱÏÝ¡¢ÃüÁî×¢Èë¼°Äþ¾²¹ýÂËÆ÷ÈƹýµÈÄþ¾²ÎÊÌ⣬¿Éµ¼ÖÂδ¾­ÊÚȨµÄÔ¶³Ì¸ù·ÃÎÊ¡£ËûÒÑÓÚ2024Äê10ÔÂ23ÈÕÏòCyberPanel¿ª·¢ÈËÔ±Åû¶©¶´²¢ÔÚGitHub ÉÏÌá½»ÁËÕë¶ÔÉí·ÝÑéÖ¤ÎÊÌâµÄÐÞ¸´·¨Ê½¡£Óë´Ëͬʱ£¬ÍþвÇ鱨ËÑË÷ÒýÇæLeakIX³ÂË߳ƣ¬´óÁ¿´æÔÚ©¶´µÄCyberPanelʵÀý±»PSAUXÀÕË÷Èí¼þ¹¥»÷£¬µ¼Ö½üÒ»°ëλÓÚÃÀ¹úµÄʵÀý£¨Ô¼10,170¸ö£©¼°¹ÜÀíµÄÁè¼Ý152,000¸öÓòºÍÊý¾Ý¿âÊܵ½Íþв¡£Ò»Ò¹Ö®¼ä£¬ÊÜÓ°ÏìµÄʵÀýÊýÁ¿´ó·ùϽµ£¬½öÊ£Ô¼400¸ö¿É·ÃÎÊ¡£PSAUXÀÕË÷Èí¼þͨ¹ý©¶´ºÍ´íÎóÅäÖù¥»÷̻¶µÄWeb·þÎñÆ÷£¬¼ÓÃÜ·þÎñÆ÷Îļþ²¢ÁôÏÂÀÕË÷ÐÅ¡£Ä¿Ç°£¬LeakIXÒÑÐû²¼½âÃÜÆ÷ÓÃÓÚ½âÃÜÔڴ˴ι¥»÷ÖмÓÃܵÄÎļþ£¬µ«Ê¹ÓÃÇ°Ð豸·ÝÊý¾Ý²¢²âÊÔÆäÓÐЧÐÔ£¬ÒÔ·ÀÒò´íÎóÃÜÔ¿µ¼ÖÂÊý¾ÝË𻵡£


https://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/


4. ¼ÓÄôóË°Îñ¾ÖÊý¾Ýй¶Òý·¢ÐÅÈÎΣ»ú£¬Òþ˽Υ¹æÐÐΪ¼¤Ôö


10ÔÂ29ÈÕ£¬ÔÚ½ñÄêµÄÄÉË°¼¾½Úá¯ÁëÆÚ£¬¼ÓÄôó·¢ÉúÁËÒ»ÆðÑÏÖصÄË°ÎñÊý¾Ýй¶Ê¼þ¡£ºÚ¿ÍÇÔÈ¡ÁËH&R Block CanadaµÄ»úÃÜÊý¾Ý£¬²¢ÀûÓÃÕâЩÐÅϢδ¾­ÊÚȨ·ÃÎÊÁËÊý°ÙÃû¼ÓÄôóÈ˵ĸöÈ˼ÓÄôóË°Îñ¾Ö£¨CRA£©ÕË»§¡£ºÚ¿Í¸ü¸ÄÁËÖ±½Ó´æ¿îÐÅÏ¢£¬Ìá½»ÁËÐé¼ÙÉ걨±í£¬²¢´Ó¹«¿îÖÐÆ­È¡ÁËÁè¼Ý600ÍòÃÀÔªµÄÐé¼ÙÍË¿î¡£´Ë´Îʼþ´Ùʹ¼ÓÄôóË°Îñ¾Ö¼ÓÇ¿ÁËýÌåÇþµÀ×¼±¸£¬ÒÔÓ¦¶Ô¹«ÖÚ¶Ô´Ë´ÎÊý¾Ýй¶¼°¸Ã»ú¹¹ÎªºÎÏòÕ©Æ­ÕßÖ§¸¶Êý°ÙÍòÃÀÔªµÄÎÊÌ⡣Ȼ¶ø£¬¹«ÖÚ²¢Î´»ñϤ´Ë¼Æ»®£¬Ë°Îñ²¿³¤ºÍ¼ÓÄôóË°Îñ¾ÖÒ²¾ùδ»ØÓ¦Ïà¹ØÎÊÌâ¡£H&R Block¹«Ë¾ÌåÏÖ£¬Ã»ÓÐÖ¤¾Ý±íÃ÷´Ë´ÎÈëÇÖʼþÔ´×Ըù«Ë¾£¬ÆäÊý¾Ý¡¢ÏµÍ³¡¢Èí¼þºÍÄþ¾²¾ùδÊܵ½Ë𺦡£¼ÓÄôóË°Îñ¾ÖδÄÜÈ·¶¨ºÚ¿ÍµÄÉí·Ý£¬µ«ÅųýÁË×ÔÉíϵͳ±»ÈëÇÖ»òÄÚ²¿ÈËÔ±¼ÓÈëµÄ¿ÉÄÜÐÔ¡£´ËÍ⣬¼ÓÄôóË°Îñ¾Ö»¹ÃæÁÙÆäËûÑÏÖØÎÊÌ⣬°üÂÞÒþ˽й¶Ê¼þÊýÁ¿¼¤Ôö£¬ÒÔ¼°¹«ÖÚ¶Ô±£»¤ÄÉË°È˽ðÇ®ºÍ¸öÈËÐÅÏ¢µÄ»ú¹¹Ê§È¥ÐÅÈεķçÏÕ¡£


https://www.cbc.ca/news/canada/canada-revenue-agency-taxpayer-accounts-hacked-1.7363440


5. й¤¾ß¿ÉÈƹýGoogle ChromeµÄÐÂCookie¼ÓÃÜϵͳ


10ÔÂ28ÈÕ£¬ÍøÂçÄþ¾²Ñо¿Ô±ÑÇÀúɽ´ó-¹þ¸ùÄÉÐû²¼ÁËÒ»¿îÃûΪ¡°Chrome-App-Bound-Encryption-Decryption¡±µÄ¹¤¾ß£¬¸Ã¹¤¾ßÄÜÈƹý¹È¸èÐÂÍƳöµÄÓ¦Ó÷¨Ê½°ó¶¨¼ÓÃܼ¼Êõ£¬´ÓChromeä¯ÀÀÆ÷ÖÐÌáÈ¡ÒÑÉú´æµÄƾ¾Ý£¬Ôö¼ÓÁËChromeÓû§µÄ·çÏÕ¡£¹È¸èÔÚ7ÔÂÍƳöµÄÕâÒ»¼ÓÃܼ¼Êõ£¬Ö¼ÔÚͨ¹ýWindows·þÎñÒÔϵͳȨÏÞ¶Ôcookies½øÐмÓÃÜ£¬±£»¤Ãô¸ÐÐÅÏ¢ÃâÊܶñÒâÈí¼þ¹¥»÷¡£È»¶ø£¬9ÔÂʱÒÑÓжà¸öÐÅÏ¢ÇÔÈ¡ÕßÕÒµ½ÈƹýÒªÁì¡£×òÌ죬¹þ¸ùÄÉÔÚGitHubÉϹûÈ»ÁËÕâ¿îÅÔ·¹¤¾ß¼°ÆäÔ´´úÂë¡£¸Ã¹¤¾ßÀûÓÃChromeä¯ÀÀÆ÷ÄÚ²¿µÄIElevator·þÎñ£¬½âÃÜ´æ´¢ÔÚµ±µØ״̬ÎļþÖеÄApp-Bound¼ÓÃÜÃÜÔ¿¡£ËäȻʹÓøù¤¾ßÐèÒª¹ÜÀíԱȨÏÞ£¬µ«Ðí¶àWindowsÓû§¶¼Ê¹ÓþßÓйÜÀíȨÏÞµÄÕË»§£¬Òò´ËÕâͨ³£ÈÝÒ×ʵÏÖ¡£¾Ý¶ñÒâÈí¼þ·ÖÎöʦ³Æ£¬¹þ¸ùÄɵÄÒªÁìÓëÔçÆÚÐÅÏ¢ÇÔÈ¡Õß½ÓÄɵÄÈƹýÒªÁìÀàËÆ£¬ËäÈ»¹È¸èÒ»Ö±ÔÚŬÁ¦¸ïзÀÓù´ëÊ©£¬µ«Ê¹ÓÃй¤¾ßÈÔÄÜÇáÒ×ÇÔÈ¡Chromeä¯ÀÀÆ÷ÖеÄÓû§ÃØÃÜ¡£¹È¸èÌåÏÖ£¬ËäÈ»Õâ¶Î´úÂëÐèÒª¹ÜÀíԱȨÏÞ£¬µ«¶ñÒâÈí¼þµÄÊýÁ¿ÈÔÔÚÔö¼Ó£¬ËüÃÇͨ¹ý²îÒ췽ʽËø¶¨Óû§¡£


https://www.bleepingcomputer.com/news/security/new-tool-bypasses-google-chromes-new-cookie-encryption-system/


6. Discord Bots±»¶ñÒâÀûÓãºPySilon RATÍþвÍøÂçÄþ¾²


10ÔÂ29ÈÕ£¬ÍøÂçÄþ¾²¹«Ë¾AhnLabÔÚ×î½üµÄÒ»·Ý³ÂËßÖÐÖ¸³ö£¬Ô­±¾ÓÃÓÚÁ¼ÐÔ·þÎñÆ÷¹ÜÀíµÄDiscord BotsÏÖÔÚ±»ÓÃÓÚ²¿ÊðÔ¶³Ì·ÃÎÊľÂí£¨RAT£©£¬ÆäÖÐ×îÐµİ¸ÀýÉæ¼°ÃûΪPySilonµÄ¶ñÒâÈí¼þ±äÖÖ¡£PySilonÊÇÒ»ÖÖÀûÓÃDiscord Botƽ̨Éø͸ϵͳ²¢»ñÈ¡Ãô¸ÐÊý¾ÝµÄRAT£¬ËüŤÇúÁËDiscord BotÔ­±¾ÌṩµÄ·þÎñÆ÷¹ÜÀí¡¢×Ô¶¯ÏûÏ¢ÏìÓ¦µÈ¹¦Ð§£¬ÔÚDiscord»ù´¡ÉèÊ©ÄÚ¶ñÒâÔËÐС£Õâ¿îʹÓÃPython¿ª·¢µÄRAT¶ñÒâÈí¼þ¿ÉÔÚGitHubÉÏ·ÃÎÊ£¬ÍþвÐÐΪÕß¿ÉÒÔÇáËɹ¹½¨×Ô½ç˵°æ±¾£¬²¢Í¨¹ýµ÷Õû·þÎñÆ÷IDºÍ»úÆ÷ÈËÁîÅƵÈÏêϸÐÅÏ¢£¬Ê¹Óù¹½¨Æ÷·¨Ê½´´½¨¸öÐÔ»¯µÄ¶ñÒâÈí¼þ°æ±¾¡£Ö´Ðкó£¬PySilon»áÔÚ¹¥»÷ÕߵķþÎñÆ÷ÄÚ´´½¨Ò»¸öÐÂͨµÀ£¬½«³õʼϵͳÐÅϢת·¢¸ø²Ù×÷Ô±£¬´Ó¶øʵÏÖºÚ¿ÍÓëÊÜѬȾÉ豸µÄ³Ö¾ÃͨÐÅÁ´½Ó¡£PySilon¾ßÓй㷺µÄÃüÁΧ£¬¿ÉÓÃÓÚ¼äµý¡¢Êý¾ÝÇÔÈ¡ºÍÆÆ»µµÈ»î¶¯£¬°üÂÞÊÕ¼¯¸öÈ˺ÍϵͳÐÅÏ¢¡¢ÆÁÄ»ºÍÒôƵ¼Ç¼¡¢¼üÅ̼ǼÒÔ¼°Îļþ¼Ð¼ÓÃܵÈ¡£AhnLabÇ¿µ÷£¬¼ì²â´ËÀàÍþв¾ßÓÐÌôÕ½ÐÔ£¬ÒòΪÊý¾ÝÊÇʹÓÃΪÕý³£»úÆ÷È˹¦Ð§ÊµÊ©µÄ¹Ù·½Discord·þÎñÆ÷´«ÊäµÄ£¬ÑÚ¸ÇÁËÆä¶ñÒâÐÔÖÊ¡£


https://securityonline.info/pysilon-a-discord-bot-turned-malicious-rat-for-data-theft-and-surveillance/