¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2022.01.31-2022.02.06£©
2022-02-10
Ò»¡¢ ÈÈÃÅ×ÊѶ
1. ¹¥»÷ÕßʹÓÃÍøÂç´¹ÂÚÔ˶¯Èö²¥¶ñÒâÈí¼þSTRRAT
¡¾¸ÅÊö¡¿
еÄÍøÂç´¹ÂÚÔ˶¯Ê¹ÓÃÐéαµÄÔËÊäÓÕ¶üÔÚºÁÎÞ½äÐĵÄÊܺ¦ÕßµÄÅÌËã»úÉÏ×°ÖÃÁË STRRAT Ô¶³Ì»á¼ûľÂí¡£Fortinet ÔÚ¼ì²âµ½Ä£ÄâÈ«Çòº½Ô˾ÞÍ·ÂíÊ¿»ùº½Ô˵«Ê¹Óÿ´ËÆÕæÊµµÄµç×ÓÓʼþµØµãµÄÍøÂç´¹ÂÚµç×ÓÓʼþºóÈ·¶¨ÁËеÄÔ˶¯¡£ STRRAT ÊÇÒ»Öֶ๦ЧԶ³Ì»á¼ûľÂí£¬ÖÁÉÙ¿ÉÒÔ×·Ëݵ½ 2020 ÄêÄêÖС£Ëüͨ³£»ùÓÚ Java£¬Í¨³£Í¨¹ýÍøÂç´¹ÂÚµç×ÓÓʼþ·¢Ë͸øÊܺ¦Õß¡£ÓëÆäËûÍøÂç´¹ÂÚ¹¥»÷Ò»Ñù£¬ÒÔǰµÄ STRAAT ²Ù×÷ʹÓø½¼Óµ½µç×ÓÓʼþµÄÖÐÐÄͶ·ÅÆ÷£¨ÀýÈ磬¶ñÒâ Excel ºê£©£¬ÔÚÉó²éʱÏÂÔØ×îÖÕÓÐÓøºÔØ¡£´ËʾÀý²»Ê¹ÓøÃÒªÁ죬¶øÊǽ«×îÖÕÓÐÓøºÔØÖ±½Ó¸½¼Óµ½ÍøÂç´¹ÂÚµç×ÓÓʼþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNeV
2. ÓëÒÁÀÊÓÐ¹ØµÄ MuddyWater APT×éÖ¯Õë¶ÔÍÁ¶úÆä˽ÈË×éÖ¯ºÍÕþ¸®»ú¹¹Ìᳫ¹¥»÷
¡¾¸ÅÊö¡¿
MuddyWater Õë¶ÔÍÁ¶úÆä¿ªÕ¹µÄ¶ñÒâÈí¼þÔ˶¯Ê¹ÓöñÒâ PDF ºÍ Microsoft Office Îĵµ×÷Ϊ³õʼѬȾǰÑÔ¡£ÓÕ¶üÎļþαװ³ÉÍÁ¶úÆäÎÀÉú²¿ºÍÄÚÕþ²¿µÄÕýµ±Îļþ¡£·¿ªÎĵµºó£¬»ùÓÚ PowerShell µÄ¶ñÒâÏÂÔØÆ÷»á³äµ±Ä¿µÄÍøÂçµÄ³õʼפ×ãµã¡£PowerShell ¾ç±¾ÏÂÔØ²¢Ö´ÐÐפÁôÔÚÎäÆ÷»¯ÎĵµÔªÊý¾ÝÖеĵڶþ½×¶Î PowerShell ¾ç±¾£¬¸Ã¾ç±¾ÓÖÏÂÔØ×îÖÕÔÚÊÜѬȾ¶ËµãÉÏÔËÐеĵÚÈý¸öδʶ±ðµÄ PowerShell ´úÂë¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNfZ
3. ¹¥»÷ÕßʹÓÃÀÕË÷Èí¼þ¹¥»÷µÂ¹úȼÁϹ©Ó¦ÉÌ
¡¾¸ÅÊö¡¿
¹¥»÷ÕßʹÓÃÀÕË÷Èí¼þÌᳫµÄÍøÂç¹¥»÷Òѵ¼ÖÂÕû¸öµÂ¹ú·ºÆðÔÝʱȼÁϹ©Ó¦£¬Ô¤¼Æ½öÔÚ 10 ÌìºóÇéÐβŻáºÃת¡£Oiltanking GmbH Group ºÍ Mabanaft Group ÊÇÉîÊÜÊý×Ö¹¥»÷Ó°ÏìµÄÁ½¼Ò¹«Ë¾£¬µ¼ÖÂÔËÓªÊÖÒÕϵͳ×èÖ¹ÔËÐС£´Ë´Î¹¥»÷Õë¶ÔµÄÊÇ Marquard & Bahls Group µÄ IT »ù´¡ÉèÊ©£¬ËæºóÓ°ÏìÁËÆäÁ½¸ö×Ó¹«Ë¾£¬¼´ Mabanaft Group ºÍ Oiltanking GmbH Group¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNg0
4. ¹¥»÷Õß¶Ô³¯ÏÊÌá³«ÍøÂç¹¥»÷Ôì³É³¯ÏÊÍøÂç±»ÆÈÖÐÖ¹
¡¾¸ÅÊö¡¿
¹¥»÷ÕßÕë¶Ô³¯ÏÊÌá³«ÍøÂç¹¥»÷µ¼ÖÂÃæÁÙ»¥ÁªÍø¹Ø±Õ£¬¸Ã¹úµÄ»¥ÁªÍøÖÐÖ¹Ò»Á¬ÁËÁù¸öСʱ¡£ÕâÊÇÒÑÍùÁ½ÖÜÄÚµ¼Ö³¯ÏÊ»¥ÁªÍøÖÐÖ¹µÄµÚ¶þÆðÊÂÎñ¡£À´×ÔÓ¢¹úµÄÍøÂçÇ徲ר¼Ò Junaid Ali ÌåÏÖ£¬×î½üµÄÖÐÖ¹¿ÉÄÜÊÇÓÉÓھܾø·þÎñ (DDoS) ¹¥»÷Ôì³ÉµÄ¡£ ÈôÊdz¯ÏʵÄÓû§ÊÔͼÅþÁ¬µ½Ò»¸ö IP µØµã£¬»¥ÁªÍø¾ÍÎÞ·¨½«Êý¾Ý·Óɵ½¸Ã¹ú¡£·þÎñÆ÷ÔÚ DDoS ¹¥»÷ºóµÄ¼¸¸öСʱÄÚ»Ö¸´Õý³£¡£È»¶ø£¬¸öÌå·þÎñÆ÷ÒòÖÐÖ¹¶øÎÞ·¨Õý³£ÔËÐУ¬ÕâЩ·þÎñÆ÷°üÀ¨-Naenara¡¢³¯ÏÊÕþ¸®¹Ù·½ÃÅ»§ÍøÕ¾¡¢¸ßÀöº½¿ÕºÍ³¯ÏÊÊÂÎñ²¿¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNg1
5. APT35ʹÓÃÐÂÐÍPowerShellºóÃÅÌá³«ÍøÂç¹¥»÷
¡¾¸ÅÊö¡¿
Ò»¸öÓëÒÁÀÊÓÐÁªÏµµÄ¸ß¼¶Ò»Á¬ÐÔÍþв×éÖ¯ÒѸüÐÂÆä¶ñÒâÈí¼þ¹¤¾ß¼¯£¬ÒÔ°üÀ¨Ò»ÖÖÃûΪPowerLess BackdoorµÄÐÂÐÍ»ùÓÚ PowerShell µÄÖ²ÈëÎï¡£Õâ¼Ò×ܲ¿Î»ÓÚ²¨Ê¿¶ÙµÄÍøÂçÇå¾²¹«Ë¾½«¶ñÒâÈí¼þ¹é×ïÓÚÒ»¸öÃûΪ Charming Kitten£¨ÓÖÃû Phosphorous¡¢APT35 »òTA453£©µÄºÚ¿Í×éÖ¯£¬Í¬Ê±»¹Ö¸³öÁ˺óÃŹæ±Ü PowerShell µÄÖ´ÐС£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNg2
6. ÃÀ¹úÓªÏú¾ÞÍ·RRDÔÚContiÀÕË÷Èí¼þ¹¥»÷ÖÐÊý¾Ý±»µÁ
¡¾¸ÅÊö¡¿
ÃÀ¹úÓªÏú¾ÞÍ·RR Donnelly£¨RRD)¹«Ë¾ÈÕǰ͸¶£¬¸Ã¹«Ë¾ÔÚÒ»´ÎÍøÂç¹¥»÷Öб»ÇÔÈ¡ÁËÊý¾Ý¡£Êºó¾BleepingComputer֤ʵ£¬ÕâÊÇÒ»´ÎContiÀÕË÷Èí¼þ¹¥»÷¡£ITϵͳµÄ¹Ø±Õµ¼Ö¹«Ë¾µÄ¿Í»§·þÎñÖÐÖ¹£¬Ò»Ð©¿Í»§ÎÞ·¨ÊÕµ½¹©Ó¦É̸¶¿î¡¢Ö§¸¶Ö§Æ±ºÍÎÞа³µÁ¾Ö¤¼þËùÐèµÄ´òÓ¡Îļþ¡£RRD¹«Ë¾ÌåÏÖ£¬×î³õËûÃDz»ÖªµÀÔÚ¹¥»÷ʱ´úÓпͻ§¶ËÊý¾Ý±»µÁ¡£Ö±µ½2022Äê1ÔÂ15ÈÕ£¬ContiÀÕË÷Èí¼þÍÅ»ï×îÏÈй¶´ÓRRD¹«Ë¾ÇÔÈ¡µÄÓû§Êý¾Ý£¬×ܼÆÎª2.5GB¡£Ëæºó£¬RRD¹«Ë¾¾Íй¶µÄÊý¾ÝÓëContiÍŶÓÕö¿ªÌ¸ÅУ¬ÎÒÃÇÓÐÀíÓÉÐÅÍУ¬ÔÚ½»¸¶Êê½ðºó£¬Ð¹Â¶Êý¾ÝÒѾ»ñµÃɾ³ýÁË¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNg6
7. McMenaminsÔâÊÜContiÀÕË÷Èí¼þ¹¥»÷
¡¾¸ÅÊö¡¿
¾Æ°ÉºÍÁ¬ËøÂÃ¹Ý McMenamins ÔâÊÜÁËConti ÀÕË÷Èí¼þ¹¥»÷£¬ÆÆËðÁËÆä¶à¸öÅÌËã»úϵͳ¡£ÐÅÏ¢Çå¾²ºÍÊÖÒÕÐÂÎÅÍøÕ¾ BleepingComputer ½«Õâ´Î¹¥»÷¹é×ïÓÚ Conti °ïÅÉ¡£ÍøÂç·¸·¨·Ö×ÓûÓд¥¼°¿Í»§Êý¾Ý£¬µ«ËûÃÇ¿ÉÄÜÒѾй¶ÁËÆäÔ±¹¤¼Í¼¡£Æ¾Ö¤ McMenamins µÄ˵·¨£¬Conti ÀÕË÷Èí¼þ¹¥»÷²¢Î´µ¼ÖÂÈκÎËùÔڵĹرա£Ïà·´£¬ÈëÇÖʹÆäÔÚÏßÔ¤¶©ÏµÍ³ÀëÏß¡£Òò´Ë£¬¸Ã¹«Ë¾ÇóÖúÓÚͨ¹ýµç»°Ô¤¶©Âùݡ£¿ÉÊÇ£¬ËüÎÞ·¨Ö´ÐÐÆäËûÔ˶¯£¬ÀýÈç¶Ò»»ÀñÎ│¡¢±¨¼Û·¿¼Û»òÔ¤¶©Ìض¨·¿ÐÍ¡£±ðµÄ£¬Conti ÀÕË÷Èí¼þ¹¥»÷ÆÈʹ¸Ã¹«Ë¾¹Ø±ÕÆä IT ϵͳ¡¢ÆóÒµµç×ÓÓʼþºÍÐÅÓÿ¨ÏúÊÛµãϵͳ¡£Ö»¹ÜÔÆÔÆ£¬¸Ã¹«Ë¾ÒѽÓÄÉÐж¯±ÜÃâ Conti ÀÕË÷Èí¼þ¹¥»÷µÄ½øÒ»²½ÉìÕÅ¡£ÔÚÊý¾Ýй¶·½Ã棬¸Ã¹«Ë¾Éù³Æ¸Ã¹¥»÷¶Ô¿Í»§Ö§¸¶Êý¾ÝûÓÐÓ°Ï졣Ȼ¶ø£¬ÍøÂç·¸·¨·Ö×Ó¿ÉÄÜÒѾӰÏìÁËÆä 2,700 ÃûÔ±¹¤µÄÊý¾Ý£¬°üÀ¨ËûÃǵÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µØµã¡¢µç×ÓÓʼþµØµã¡¢Ö±½Ó´æ¿îÒøÐÐÕË»§ÐÅÏ¢¡¢Éç»áÇå¾²ºÅÂëºÍ¸£Àû¼Í¼¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNg3
8. KPÁãʳÔâÓöÀÕË÷Èí¼þ¹¥»÷
¡¾¸ÅÊö¡¿
KP Snacks ÊÇÓ¢¹ú±ê¼ÇÐÔС³Ô£¨Èç Skips ºÍ Butterkist£©µÄ¹©Ó¦ÉÌ£¬Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ÍþвÖÁÉÙÔÚ 3 ÔÂβ֮ǰ»áÓ°ÏìËÍ»õ¡£¸Ã¹«Ë¾Ðû²¼£¬Conti£¬Ò»¸öºÜÊÇÓÐÓõĶíÓï×éÖ¯£¬ÊÇÕâ´ÎÏ®»÷µÄÄ»ºóºÚÊÖ¡£Óë¸ÃÍÅ»ïµÄµä·¶×ö·¨Ò»Ñù£¬ËûÃÇÔÚË«ÖØÀÕË÷Ðж¯ÖÐÇÔÈ¡Êý¾Ý£¬²¢ÔÚËûÃǵÄйÃÜÍøÕ¾ÉÏÐû²¼ÁËÇÔÈ¡µÄ“Ö¤¾Ý”¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNg4
9. Ó¡ÄáÑëÐÐÈ·ÈÏÔâÊÜÀÕË÷Èí¼þ¹¥»÷
¡¾¸ÅÊö¡¿
1ÔÂ20ÈÕ£¬Ó¡¶ÈÄáÎ÷Ñǹ²ºÍ¹úÖÐÑëÒøÐЗ—Ó¡¶ÈÄáÎ÷ÑÇÒøÐУ¨BANK INDONESIA£©Í¨Ñ¶²¿Ö´ÐÐÖ÷ÈÎErwin Haryono֤ʵ£¬ÒøÐÐÓÚÉϸöÔÂÔâÊÜÁËÀÕË÷Èí¼þ¹¥»÷¡£ÖÐÑëÒøÐÐÓÐ×ÅÖÎÀíÇ®±Ò²¿·Ö¡¢Î¬³ÖÖ§¸¶ÏµÍ³ºÍ½ðÈÚϵͳÎȹ̵ÄÖØÈΣ¬±»¹¥»÷һʷÇͬС¿É¡£¾Ý±¨µÀ£¬¹¥»÷±¬·¢ÔÚËÕÃÅ´ðÀ°µºµÄÓ¡¶ÈÄáÎ÷ÑÇÒøÐзþÎñ´¦£¬¹¥»÷ÕßÔÚÒøÐÐϵͳÉϰ²ÅÅÀÕË÷Èí¼þ£¬²¢ÇÔÈ¡ÁËÓ¡¶ÈÄáÎ÷ÑÇÒøÐÐÔ±¹¤µÄ“·ÇÒªº¦Êý¾Ý“¡£Ó¡¶ÈÄáÎ÷ÑÇÒøÐгƣ¬ÔÚ½ÓÄɲ½·¥ºó£¬ÊÂÎñûÓÐÔì³ÉÌ«´óÓ°Ï죬ûÓÐй¶ÈκÎÖ÷ÒªÊý¾Ý£¬¸üÖ÷ÒªµÄÊÇÒøÐеĹ«¹²·þÎñÍêȫûÓÐÖÐÖ¹¡£Ó¡¶ÈÄáÎ÷ÑÇÒøÐÐûÓн«Õâ´Î¹¥»÷¹é×ïÓÚÌØ¶¨µÄÀÕË÷Èí¼þÍŻµ«Conti×éÖ¯ÌåÏÖ¶Ô´ËÈÏÕæ£¬ÆäÍþв³ÆÈôÓ¡¶ÈÄáÎ÷ÑÇÒøÐв»Ö§¸¶Êê½ð£¬Conti½«Ð¹Â¶ÊÖÖеÄ13.88GBÎļþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNeD
10. ¹¥»÷ÕßʹÓöñÒâÈí¼þAsyncRATÌá³«ÍøÂç´¹ÂÚÔ˶¯
¡¾¸ÅÊö¡¿
ÎÛÃûÕÑÖøµÄ¶ñÒâÈí¼þ AsyncRAT ͨ¹ýÍøÂç´¹ÂÚÔ˶¯ÔٴηºÆðÔÚÍøÉÏ¡£ÕâÒ»´Î£¬¹¥»÷ÕßÉè¼ÆÁËÒ»ÖÖ͵͵ÃþÃþµÄÕ½ÂÔÀ´Ìӱܴó´ó¶¼Çå¾²¹¤¾ßµÄ¼ì²â¡£´«Ë͵ĶñÒâÈí¼þµÄÍøÂç´¹ÂÚµç×ÓÓʼþ°üÀ¨Ò»¸ö HTML ¸½¼þ£¬·¿ªºó»áÌáÐÑÓû§ÏÂÔØ ISO Îļþ¡£ËäÈ»Êܺ¦Õß»áÒÔΪÏÂÔØµÄÎļþ»áͨ¹ýÇå¾²¼ì²é£¬µ«ÏÖʵÉÏËü»áËùÓÐÌÓ×ß¡£ÕâÊÇÓÉÓÚ ISO Îļþ´Ó²»À´×Ô·þÎñÆ÷£¬¶øÊÇÀ´×Ô HTML ¸½¼þ¡£·¿ª´Ë ISO Îļþ»áÖ´ÐÐ×¢Èë¶ñÒâÈí¼þ dropper£¨.NET Ä£¿é£©µÄÏÂÒ»²½£¬È»ºóÖ´ÐÐÖÖÖÖ¹æ±Ü¼ì²éÒÔÌø¹ý¼ì²â¡£×îÖÕ£¬AsyncRAT ¶ñÒâÈí¼þ×÷Ϊ×îÖÕ¸ºÔصִï×°±¸¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlNfY

AG¹«Ë¾ÔÆ







