TA544ÀûÓÃWikiLoaderÕë¶ÔÒâ´óÀûµÄÆóÒµ·Ö·¢Ursnif

Ðû²¼Ê±¼ä 2023-08-02

1¡¢TA544ÀûÓÃWikiLoaderÕë¶ÔÒâ´óÀûµÄÆóÒµ·Ö·¢Ursnif


ProofpointÔÚ7ÔÂ31ÈÕÅû¶ÁËÀûÓÃжñÒâÈí¼þWikiLoaderÕë¶ÔÒâ´óÀûÆóÒµµÄ¹¥»÷»î¶¯¡£WikiLoaderÊÇÒ»¸öÅÓ´óµÄÏÂÔØ·¨Ê½£¬ÒòΪËü»áÏòWikipedia·¢³öÇëÇó²¢¼ì²éÏìÓ¦ÄÚÈÝÖÐÊÇ·ñ°üÂÞ×Ö·û´®¡°The Free¡±¶øµÃÃû¡£ProofpointÓÚ2022Äê12ÔÂ27ÈÕÊ×´ÎÔÚÒ°Íâ¼ì²âµ½¸Ã¶ñÒâÈí¼þ£¬ÓÉTA544Á÷´«¡£Ñо¿ÈËÔ±³Æ£¬ÖÁÉÙÓÐ8¸ö»î¶¯ÔÚ·Ö·¢WikiLoader£¬À´×ÔTA544ºÍTA551£¬¾ùÕë¶ÔÒâ´óÀûµÄ×éÖ¯¡£´ËÍ⣬ËäÈ»´ó¶àÊý¹¥»÷ÕßÒѲ»ÔÙʹÓÃÆôÓúêµÄÎĵµÀ´Á÷´«¶ñÒâÈí¼þ£¬µ«TA544ÈÔÔÚ¹¥»÷Á´ÖÐʹÓÃËüÃÇ£¬°üÂÞÁ÷´«WikiLoader¡£


https://www.proofpoint.com/us/blog/threat-insight/out-sandbox-wikiloader-digs-sophisticated-evasion


2¡¢ÃÀ¹úÒÂÊι«Ë¾Hot TopicÔ⵽ײ¿â¹¥»÷й¶¿Í»§µÄÐÅÏ¢


¾ÝýÌå8ÔÂ1ÈÕ±¨µÀ£¬ÃÀ¹úÒÂÊμ°ÊÚȨÒôÀÖÁãÊÛÁ¬ËøµêHot Topic͸¶ÆäÔâµ½Á˶àÆð¹¥»÷ʼþ£¬µ¼Ö¿ͻ§µÄÃô¸ÐÐÅϢй¶¡£¸Ã¹«Ë¾ÔÚÃÀ¹úÓµÓÐ675¼ÒÉ̵꣬ÒÔ¼°Ã¿Ô½ü1000Íò·ÃÎÊÁ¿µÄÔÚÏßÉ̵ê¡£¸Ã¹«Ë¾½âÊÍ˵£¬ºÚ¿ÍʹÓÃÇÔÈ¡µÄÕÊ»§Æ¾¾Ý¶à´Î·ÃÎÊÁËRewardsƽ̨£¬¿ÉÄÜ»ñµÃÁ˿ͻ§µÄÊý¾Ý¡£¾­ÊӲ죬¹¥»÷ÕßÓÚ2023Äê2ÔÂ7ÈÕ¡¢3ÔÂ11ÈÕ¡¢5ÔÂ19ÈÕÖÁ21ÈÕ¡¢5ÔÂ27ÈÕÖÁ28ÈÕºÍ6ÔÂ18ÈÕÖÁ21ÈÕ£¬Ê¹ÓÃÓÐЧÕÊ»§Æ¾¾Ý¶ÔÍøÕ¾ºÍÒÆ¶¯Ó¦ÓÃÖ´ÐÐÁË×Ô¶¯¹¥»÷¡£¸Ã¹«Ë¾ÌåÏÖ£¬Hot Topic²»ÊÇй¶ƾ֤µÄÀ´Ô´£¬µ«Ò²ÎÞ·¨ÕÒµ½À´Ô´¡£


https://www.bleepingcomputer.com/news/security/retail-chain-hot-topic-discloses-wave-of-credential-stuffing-attacks/


3¡¢Henry Ford HealthÔâµöÓã¹¥»÷½ü17Íò»¼ÕßÐÅϢй¶


¾Ý7ÔÂ27ÈÕ±¨µÀ£¬ÃÀ¹úµÄѧÊõÒ½ÁÆ»úHenry Ford Health³ÆÆä3ÃûÔ±¹¤Ôâµ½µöÓã¹¥»÷£¬Ó°ÏìÁË168215¸ö»¼ÕßµÄÐÅÏ¢¡£¸Ã»ú¹¹ÔÚÉùÃ÷ÖÐÌåÏÖ£¬¹¥»÷ʼþ·¢ÉúÓÚ3ÔÂ30ÈÕ£¬¸Ã×éÖ¯Òѽ«±»Ó°ÏìµÄµç×ÓÓʼþÕÊ»§±£»¤ÆðÀ´²¢Õ¹¿ªÊӲ졣5ÔÂ16£¬È·¶¨»¼ÕߵĽ¡¿µÐÅÏ¢°üÂÞÔÚµç×ÓÓÊÏäÖУ¬¶øÇÒ¿ÉÄÜÒѱ»¹¥»÷ÕßÇÔÈ¡£¬Éæ¼°ÐÕÃû¡¢ÊµÑéÊÒ½á¹û¡¢ÊÖÊõÀàÐÍ¡¢Õï¶Ï¡¢µç»°ºÅÂë¡¢²¡ÀúºÅºÍÄÚ²¿¸ú×ٺŵÈÐÅÏ¢¡£¸Ã¹«Ë¾ÌåÏÖ£¬ËûÃÇÕýÔÚÊµÊ©ÌØ±ðµÄÄþ¾²´ëÊ©£¬²¢½«ÎªÔ±¹¤ÌṩÄþ¾²Åàѵ¡£


https://www.bankinfosecurity.com/phishing-scam-affects-nearly-170k-henry-ford-health-patients-a-22672 


4¡¢Cado·¢ÏÖ¿ÉÕë¶ÔRedis·þÎñÆ÷µÄP2PInfectÈ䳿бäÌå


7ÔÂ31ÈÕ£¬Cado·¢ÏÖÁËÒ»ÖÖÕë¶ÔRedisµÄÐÂÐͶñÒâÈí¼þ»î¶¯¡£¸Ã¶ñÒâÈí¼þ±»¿ª·¢ÕßÃüÃûΪP2Pinfect£¬ÓÃRust¿ª·¢£¬³äµ±½©Ê¬ÍøÂçÊðÀí¡£Ñо¿ÈËÔ±·ÖÎöµÄÑù±¾°üÂÞÒ»¸öǶÈëʽPEÎļþÒÔ¼°Ò»¸öELF¶þ½øÖÆÎļþ£¬Õâ±íÃ÷ÁËWindowsºÍLinuxÖ®¼ä¾ßÓÐ¿çÆ½Ì¨¼æÈÝÐÔ¡£Ëü»¹ÀûÓø´Öƹ¦Ð§À´¹¥»÷RedisÊý¾Ý´æ´¢µÄʵÀý¡£´ËÍ⣬P2PinfectÊÔͼͨ¹ýCronδ¾­Éí·ÝÑéÖ¤µÄRCE»úÖÆ¹¥»÷RedisÖ÷»ú¡£¸Ã»î¶¯±³ºóµÄ¹¥»÷ÕßÉí·ÝÉв»Çå³þ£¬P2PInfectµÄÄ¿µÄÒ²²»Çå³þ¡£


https://www.cadosecurity.com/redis-p2pinfect/


5¡¢Minecraft mod©¶´BleedingPipeÒѱ»´ó¹æÄ£ÀûÓÃ


ýÌå7ÔÂ31ÈÕ±¨µÀ³Æ£¬ºÚ¿ÍÕýÔÚÀûÓÃMinecraft modÖеÄRCE©¶´BleedingPipeÔÚ·þÎñÆ÷ºÍ¿Í»§¶ËÖ´ÐжñÒâÃüÁ´Ó¶ø¿ØÖÆÉ豸¡£BleedingPipe©¶´×î³õÓÚ2022Äê3Ô±»ÀûÓ㬵«ºÜ¿ì¾Í±»mod¿ª·¢ÕßÐÞ¸´ÁË¡£È»¶øÔÚ7ÔÂÔçЩʱºò£¬ForgeÂÛ̳µÄһƪÌû×ӳƣ¬ÓÐÈËÀûÓÃδ֪RCEÀ´´ó¹æÄ£ÇÔÈ¡Íæ¼ÒµÄDiscordºÍSteam»á»°cookie¡£½øÒ»²½Ñо¿·¢ÏÖ£¬¶à¸öMinecraft modÖÐÒ²´æÔÚBleedingPipe©¶´¡£¹¥»÷ÕßÕýÔÚɨÃèÊܸé¶´Ó°ÏìµÄMinecraft·þÎñÆ÷²¢Ö´Ðй¥»÷£¬Òò´ËÐÞ¸´·þÎñÆ÷ÉÏÒ×±»¹¥»÷µÄmodÖÁ¹ØÖØÒª¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-bleedingpipe-rce-to-target-minecraft-servers-players/


6¡¢Bahamutͨ¹ý¼ÙðµÄAndroidÓ¦ÓÃSafeChatÇÔÈ¡ÐÅÏ¢


7ÔÂ28ÈÕ£¬CYFIRMA³ÆÆä·¢ÏÖÁËÒ»¸ö¿ÉÒɵÄAndroid¶ñÒâÈí¼þ£¬Î±×°³ÉÐé¼ÙµÄÁÄÌìÓ¦ÓÃSafeChat£¬ÇÔÈ¡ÊÖ»úµÄͨ»°¼Ç¼¡¢¶ÌÐźÍGPSλÖõÈÊý¾Ý¡£¸Ã¶ñÒâÈí¼þ±»»³ÒÉÊÇCoverlmµÄ±äÖÖ£¬»áÇÔÈ¡Telegram¡¢Signal¡¢WhatsApp¡¢ViberºÍFacebook MessengerµÈͨѶӦÓõÄÊý¾Ý¡£¸Ã»î¶¯ÓëÓ¡¶ÈºÚ¿ÍÍÅ»ïBahamutÓйØ£¬Ö÷Ҫͨ¹ýWhatsAppÉϵÄÓã²æÊ½µöÓãÏûÏ¢½øÐУ¬Ö÷ÒªÕë¶ÔÄÏÑǵØÓò¡£´ËÍ⣬¸Ã»î¶¯ÓëÓ¡¶ÈµÄÁíÒ»¸öºÚ¿ÍÍÅ»ïDoNotµÄ»î¶¯ÓÐÏàËÆÖ®´¦¡£


https://www.cyfirma.com/outofband/apt-bahamut-targets-individuals-with-android-malware-using-spear-messaging/