Symantec·¢ÏÖLazarusÕë¶Ô»¯¹¤ÐÐÒµµÄ¹¥»÷»î¶¯

Ðû²¼Ê±¼ä 2022-04-18

1¡¢Symantec·¢ÏÖLazarusÍÅ»ïÕë¶Ô»¯¹¤ÐÐÒµµÄ¹¥»÷»î¶¯


4ÔÂ14ÈÕ£¬SymantecÐû²¼Á˹ØÓÚ³¯ÏʺڿÍÍÅ»ïLazarus×îлµÄ·ÖÎö³ÂËß¡£´Ë´Î»î¶¯ËƺõÊÇOperation Dream JobµÄÑÓÐø£¬×Ô2022Äê1Ô¿ªÊ¼£¬Ö÷ÒªÕë¶Ô»¯Ñ§ÐÐÒµµÄ×éÖ¯¡£¹¥»÷ʼÓÚ¶ñÒâHTMÎļþ£¬¿ÉÄÜÊÇͨ¹ýÓʼþÖеĶñÒâÁ´½Ó»òWeb·Ö·¢µÄ¡£HTMÎļþ»á±»¸´ÖƵ½DLLÎļþscskapplink.dllÖУ¬²¢×¢Èëµ½ºÏ·¨µÄϵͳ¹ÜÀíÈí¼þINISAFE Web EX ClientÖС£scskapplink.dllÎļþͨ³£ÊÇ´øÓжñÒâµ¼³öµÄÇ©ÃûľÂí¹¤¾ß£¬¹¥»÷ÕßʹÓõÄÇ©Ãû°üÂÞDOCTER USA,INCºÍ¡°A¡± MEDICAL OFFICE,PLLC¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/lazarus-dream-job-chemical


2¡¢CiscoÐÞ¸´ÆäWLCÖеÄÉí·ÝÑéÖ¤Èƹý©¶´CVE-2022-20695


ýÌå4ÔÂ14ÈÕ±¨µÀ£¬CiscoÒÑÐÞ¸´ÆäÎÞÏßLAN¿ØÖÆÆ÷(WLC)ÖеÄÉí·ÝÑéÖ¤Èƹý©¶´¡£¸Ã©¶´×·×ÙΪCVE-2022-20695£¬CVSSÆÀ·ÖΪ10£¬¿É±»ÓÃÀ´ÈƹýÉí·ÝÑéÖ¤¿ØÖƲ¢Í¨¹ýWLCµÄ¹ÜÀí½çÃæµÇ¼É豸¡£CiscoÔÚͨ¸æÖгÆ£¬Õâ¸ö©¶´ÊÇÓÉÓÚÃÜÂëÑéÖ¤Ë㷨ʵʩ²»Í×Ôì³ÉµÄ£¬¹¥»÷Õß¿ÉÒÔʹÓÃÌØÖƵÄƾ¾ÝÀ´ÀûÓôË©¶´£¬ÀÖ³ÉÀûÓúó¿É»ñµÃ¹ÜÀíԱȨÏÞ²¢ÍêÈ«¿ØÖÆÄ¿±êÉ豸¡£¸Ã¹«Ë¾½¨ÒéÓû§¸üе½°æ±¾8.10.171.0ÒÔÐÞ¸´¸Ã©¶´¡£


https://thehackernews.com/2022/04/critical-auth-bypass-bug-reported-in.html


3¡¢ÎÚ¿ËÀ¼CERT-UA¼ì²âµ½Á½ÆðÕë¶ÔÆä¹Ù·½»ú¹¹µÄ¹¥»÷»î¶¯


¾Ý4ÔÂ14Èյı¨µÀ£¬ÎÚ¿ËÀ¼¼ÆËã»úÓ¦¼±ÏìӦС×é(CERT-UA)¼ì²âµ½Á½ÆðÕë¶ÔÆä¹Ù·½»ú¹¹µÄл¡£µÚÒ»ÆðµöÓã»î¶¯Í¨¹ýÃûΪMobilization Register.xlsµÄExcelÎĵµ·Ö·¢IcedID£¨ÓÖÃûBankBot£©£¬¸Ã»î¶¯ÓëUAC-0041ÍÅ»ïÓйØ¡£µÚ¶þÆðµöÓã»î¶¯ÒÔ×ÜͳV.ZelenskyΪÎä×°¶ÓÎé³ÉÔ±·¢±íÑ«ÕÂ×÷ΪÓÕ¶ü£¬ÀûÓÃÁËZimbra Collaboration SuiteÖеÄXSS©¶´(CVE-2018-6882) ¹¥»÷Õþ¸®×éÖ¯¡£


https://www.bleepingcomputer.com/news/security/hackers-target-ukrainian-govt-with-icedid-malware-zimbra-exploits/


4¡¢ÀÕË÷ÍÅ»ïOldGremlinÀûÓÃкóÃÅTinyFluffÃé×¼¶íÂÞ˹


ýÌå4ÔÂ14Èճƣ¬Group-IB·¢ÏÖÁËÀÕË÷ÍÅ»ïOldGremlinÕë¶Ô¶íÂÞ˹µÄÐÂÒ»ÂÖµöÓã¹¥»÷¡£¹¥»÷Õßð³ä¶íÂÞ˹һ¼Ò½ðÈÚ»ú¹¹µÄ¸ß¼¶»á¼Æʦ£¬Éù³Æ½üÆÚ¶Ô¶íÂÞ˹ʵʩµÄÖƲý«ÔÝÍ£VisaºÍMastercardÖ§¸¶´¦ÖÃϵͳµÄÔËÓª¡£µöÓãÓʼþ½«ÊÕ¼þÈËÖض¨Ïòµ½´æ´¢ÔÚDropboxÖеĶñÒâÎĵµ£¬²¢ÏÂÔØÒ»¸öÃûΪTinyFluffµÄ×Ô½ç˵ºóÃÅ£¬¸ÃºóÃÅÊÇTinyNodeµÄбäÖÖ£¬Ëü»áÆô¶¯Node.js½âÊÍÆ÷²¢Ê¹¹¥»÷ÕßÔ¶³Ì·ÃÎÊÄ¿±êϵͳ¡£


https://www.bleepingcomputer.com/news/security/oldgremlin-ransomware-gang-targets-russia-with-new-malware/


5¡¢Î÷°àÑÀ×ãЭRFEFÔâµ½¹¥»÷µ¼ÖÂÓʼþºÍÒôƵµÈÊý¾Ýй¶


¾ÝýÌå4ÔÂ15ÈÕ±¨µÀ£¬Î÷°àÑÀ»Ê¼Ò×ãÇòЭ»á£¨RFEF£©Ïò¾¯·½³ÂËßÆäÔâµ½ÍøÂç¹¥»÷¡£´Ë´Î¹¥»÷µ¼ÖÂЭ»áÖ÷ϯLuis RubialesºÍÃØÊ鳤Andreu CampsÔÚÄڵĸ߼¶¹ÜÀíÈËÔ±µÄµç×ÓÓʼþÕÊ»§¡¢Ë½ÈËÎı¾ºÍÒôƵ¶Ô»°µÈÏà¹ØÐÅϢй¶¡£RFEFÔÚÉÏÖÜËĵÄÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬±»µÁÐÅÏ¢ºÜ¿ÉÄÜÒÑÌṩӦ²îÒìµÄýÌå¡£ÓÐýÌåÉù³ÆÒÑͨ¹ýµÚÈý·½ÊÕµ½ÁË»úÃܺÏͬ¡¢Ë½ÈËWhatsApp¶Ô»°¡¢µç×ÓÓʼþºÍ´óÁ¿ÓйØRFEF¹ÜÀíµÄÎļþ¡£


https://www.espn.com/soccer/spain-esp/story/4642921/spanish-fa-report-cyber-attack-to-police-after-email-accounts-private-texts-stolen


6¡¢Segran?a-InformaticaÐû²¼ÀÕË÷Èí¼þSunnyDay·ÖÎö³ÂËß


4ÔÂ11ÈÕ£¬Segran?a-InformaticaÐû²¼Á˹ØÓÚÀÕË÷Èí¼þSunnyDayµÄ¼¼Êõ·ÖÎö³ÂËß¡£ËüÊÇÒ»¸ö»ùÓÚSALSA20Á÷ÃÜÂëµÄ¼òµ¥ÀÕË÷Èí¼þ£¬´øÓÐǶÈëµÄRSA¹«Ô¿blob£¬ÓÃÓÚ¼ÓÃܶԳÆSALSA20ʹÓõÄÉú³ÉÃÜÔ¿£¬¸ÃÃÜÔ¿ÓÃÀ´¼ÓÃÜÄ¿±êÉ豸ÖеÄËùÓпÉÓÃÎļþ¡£·ÖÎö·¢ÏÖ£¬SunnyDayÓëÆäËüÀÕË÷Èí¼þÑù±¾Ö®¼ä´æÔÚÏàËÆÖ®´¦£¬ÀýÈçEver101¡¢Medusa Locker¡¢CuratorºÍPayment45£¬µ«ÈÔÎÞ·¨¶ÔÆä½øÐйéÒò¡£


https://seguranca-informatica.pt/analysis-of-the-sunnyday-ransomware/