ESET·¢ÏÖSandwormÀûÓÃSwiftSlicer¹¥»÷ÎÚ¿ËÀ¼µÄ»î¶¯

°ä²¼¹¦·ò 2023-01-31
1¡¢ESET·¢ÏÖSandwormÀûÓÃSwiftSlicer¹¥»÷ÎÚ¿ËÀ¼µÄ»î¶¯

      

ESET×êÑÐÈËÔ±ÓÚ1ÔÂ27Èճƣ¬ £¬£¬£¬ £¬£¬£¬ÔÚ×î½üÒ»´ÎÕë¶ÔÎÚ¿ËÀ¼×éÖ¯µÄ¹¥»÷»î¶¯Öз¢ÏÖÁËÒ»ÖÖеÄÊý¾Ý²Á³ý¶ñÒâÈí¼þSwiftSlicer£¬ £¬£¬£¬ £¬£¬£¬²¢½«Æä¹éÒòÓÚAPT×éÖ¯Sandworm¡£¡£ ¡£¡£¡£¡£¡£¡£SwiftSlicerÓÚ1ÔÂ25ÈÕÔÚÖ¸±êµÄÍøÂçÉϱ»·¢ÏÖ£¬ £¬£¬£¬ £¬£¬£¬Ëüͨ¹ý×éÕ½Êõ²¿Ê𣬠£¬£¬£¬ £¬£¬£¬ÕâÅú×¢¹¥»÷ÕßÒѾ­½ÚÔìÁËÖ¸±êµÄActive Directory»·¾³¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÊÇÓÃGo¿ª·¢µÄ£¬ £¬£¬£¬ £¬£¬£¬Ò»µ©Ö´Ðоͻáɾ³ý¾íÓ°¸±±¾²¢¸²¸ÇWindowsϵͳĿ¼ÖеĹؼüÎļþ£¬ £¬£¬£¬ £¬£¬£¬³ö¸ñÊÇÇý¶¯·¨Ê½ºÍActive DirectoryÊý¾Ý¿â¡£¡£ ¡£¡£¡£¡£¡£¡£


https://www.welivesecurity.com/2023/01/27/swiftslicer-new-destructive-wiper-malware-ukraine/ 


2¡¢QNAP°ä²¼¹Ì¼þ¸üн¨¸´ÆäNASÉ豸ÖеÄSQL×¢Èë·ì϶

      

1ÔÂ30ÈÕ£¬ £¬£¬£¬ £¬£¬£¬QNAP°ä²¼ÁËQTSºÍQuTSµÄ¹Ì¼þ¸üУ¬ £¬£¬£¬ £¬£¬£¬ÒÔ½¨¸´¿ÉÔÚÆäNASÉ豸ÖÐ×¢Èë¶ñÒâ´úÂëµÄ·ì϶¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã·ì϶׷×ÙΪCVE-2022-27596£¬ £¬£¬£¬ £¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬ £¬£¬£¬ £¬£¬£¬Ó°ÏìÁËQTS 5.0.1ºÍQuTS hero h5.0.1°æ±¾¡£¡£ ¡£¡£¡£¡£¡£¡£¹©¸øÉÌûÓÐй©Óйظ÷ì϶µÄ¸ü¶àϸ½Ú£¬ £¬£¬£¬ £¬£¬£¬µ«NIST portal½«ÆäÃèÊöΪSQL×¢Èë·ì϶¡£¡£ ¡£¡£¡£¡£¡£¡£´Ë±í£¬ £¬£¬£¬ £¬£¬£¬QNAP°ä²¼ÁËÒ»¸öÃèÊö¸Ã·ì϶ÑϳÁÐÔµÄJSONÎļþ£¬ £¬£¬£¬ £¬£¬£¬Åú×¢¸Ã·ì϶¿É±»Ô¶³Ì¹¥»÷ÕßÔڵ͸´ÔÓˮƽµÄ¹¥»÷ÖÐÀûÓ㬠£¬£¬£¬ £¬£¬£¬¶øÎÞÐèÓû§½»»¥»òÖ¸±êÉ豸ÉϵÄȨÏÞ¡£¡£ ¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/141588/iot/qnap-addresses-critical-flaw.html   


3¡¢Í¶×Ê×êÑй«Ë¾ZacksÔâµ½¹¥»÷µ¼ÖÂ82ÍòÓû§µÄÐÅϢй¶

      

¾ÝýÌå1ÔÂ25ÈÕ±¨Â·£¬ £¬£¬£¬ £¬£¬£¬Zacks Investment Research¹«Ë¾µÄÊý¾Ýй¶ÊÂÎñÓ°ÏìÁË820000Ãû¿Í»§¡£¡£ ¡£¡£¡£¡£¡£¡£Zacks·¢ÏÖ²¿Ãſͻ§¼Í¼Ôâµ½ÁËδ¾­ÊÚȨµÄ½Ó¼û£¬ £¬£¬£¬ £¬£¬£¬¾­ÄÚ²¿µ÷²éÈ·¶¨¹¥»÷ÕßÔÚ2021Äê11ÔÂÖÁ2022Äê8ÔÂÖ®¼äµÄij¸ö¹¦·ò½Ó¼ûÁ˸ÃÍøÂç¡£¡£ ¡£¡£¡£¡£¡£¡£Ð¹Â¶ÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç»°¡¢ÓʼþµØÖ·ºÍZacks.comÍøÕ¾µÄÓû§ÃÜÂë¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³ÎÇå˵£¬ £¬£¬£¬ £¬£¬£¬Õâ´ÎÊÂÎñ½öÓ°ÏìÔÚ1999Äê11ÔÂÖÁ2005Äê2Ô²ÎÓëµÄZacks EliteµÄ¿Í»§¡£¡£ ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬ £¬£¬£¬ £¬£¬£¬Zacks³ÁÖÃÁËÊÜÓ°ÏìÓû§µÄÃÜÂ룬 £¬£¬£¬ £¬£¬£¬²¢Ö´ÐÐÁ˶î±íµÄ°²È«´ëÊ©¡£¡£ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/zacks-investment-research-data-breach-affects-820-000-clients/


4¡¢ÀÕË÷Èí¼þMimicÀûÓÃËÑË÷¹¤¾ßEverything²éÕÒÒª¼ÓÃܵÄÎļþ

      

Trend MicroÔÚ1ÔÂ26ÈÕ͸©£¬ £¬£¬£¬ £¬£¬£¬ÐµÄÀÕË÷Èí¼þMimicÀûÓúϷ¨¹¤¾ßEverythingµÄAPIÀ´²éÕÒÒª¼ÓÃܵÄÎļþ¡£¡£ ¡£¡£¡£¡£¡£¡£EverythingÊÇVoidtools¿ª·¢µÄWindowsÎļþÃûËÑË÷ÒýÇæ£¬ £¬£¬£¬ £¬£¬£¬¿ÉÔ®ÊÖMimicÕÒµ½¿É¼ÓÃܵÄÎļþ£¬ £¬£¬£¬ £¬£¬£¬Í¬Ê±ÈÆ¿ªÄÇЩ¼ÓÃܺó»áµ¼ÖÂϵͳÎÞ·¨Æô¶¯µÄÎļþ¡£¡£ ¡£¡£¡£¡£¡£¡£¸ÃÀÕË÷Èí¼þÓÚ2022Äê6Ô³õ´ÎÔÚÒ°±í±»·¢ÏÖ£¬ £¬£¬£¬ £¬£¬£¬ÖØÒªÕë¶Ô¶íÓïºÍÓ¢ÓïÖ¸±ê¡£¡£ ¡£¡£¡£¡£¡£¡£Æä²¿ÃÅ´úÂëÓëÀÕË÷Èí¼þContiÓÐÀàËÆÖ®´¦£¬ £¬£¬£¬ £¬£¬£¬»¹Äܹ»ÀûÓöà¸ö´¦ÖÃÆ÷Ïß³ÌÀ´¼Ó¿ìÊý¾Ý¼ÓÃܹý³Ì£¬ £¬£¬£¬ £¬£¬£¬ÓµÓÐÏÖ´úÀÕË÷Èí¼þµÄ³£¼ûÖ°ÄÜ¡£¡£ ¡£¡£¡£¡£¡£¡£


https://www.trendmicro.com/en_us/research/23/a/new-mimic-ransomware-abuses-everything-apis-for-its-encryption-p.html


5¡¢×êÑÐÈËÔ±ÔÚBlack Basta¹¥»÷»î¶¯Öз¢ÏÖPlugXбäÌå

      

¾Ý1ÔÂ27ÈÕ±¨Â·£¬ £¬£¬£¬ £¬£¬£¬×êÑÐÈËÔ±ÔÚÒ»´ÎBlack BastaµÄ¹¥»÷»î¶¯Öз¢ÏÖÁ˶ñÒâÈí¼þPlugXµÄбäÌå¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã±äÌåÄܹ»ÔÚUSBÉ豸Éϰµ²Ø¶ñÒâÎļþ£¬ £¬£¬£¬ £¬£¬£¬¶øºóϰȾËüÃÇÏνӵÄWindowsÖ÷»ú¡£¡£ ¡£¡£¡£¡£¡£¡£ÔÚÕâ´Î»î¶¯ÖУ¬ £¬£¬£¬ £¬£¬£¬¹¥»÷ÕßʹÓÃ32λ°æ±¾µÄWindowsµ÷ÊÔ¹¤¾ßx64dbg.exeºÍÖж¾°æ±¾µÄx32bridge.dll£¬ £¬£¬£¬ £¬£¬£¬À´¼ÓÔØPlugX payload£¨x32bridge.dat£©¡£¡£ ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬ £¬£¬£¬ £¬£¬£¬ÔÚVirus TotalɨÃèÆ½Ì¨ÉϵÄ61ÖÖ²úÆ·ÖУ¬ £¬£¬£¬ £¬£¬£¬½öÓÐ9ÖÖÄܹ»½«ÆäÏóÕ÷Ϊ¶ñÒâÎļþ¡£¡£ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/plugx-malware-hides-on-usb-devices-to-infect-new-windows-hosts/


6¡¢Mandiant°ä²¼¹ØÓÚGootkit¹¥»÷»î¶¯ÑݱäµÄ·ÖÎö»ã±¨

      

MandiantÔÚ1ÔÂ26ÈÕ°ä²¼Á˹ØÓÚGootkit¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£ ¡£¡£¡£¡£¡£¡£×Ô2021Äê1ÔÂÒÔÀ´£¬ £¬£¬£¬ £¬£¬£¬MandiantÒ»ÏòÔÚ¸ú×ÙUNC2565µÄGootkitµÄ»î¶¯¡£¡£ ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖ£¬ £¬£¬£¬ £¬£¬£¬´Ó2022ÄêÆðÍ·UNC2565¶ÔÆä»î¶¯ÖÐʹÓõÄTTP½øÐиü¸Ä£¬ £¬£¬£¬ £¬£¬£¬Ô̺¬Ê¹ÓÃFONELAUNCH launcherµÄ¶à¸ö±äÌå¡¢·Ö·¢ÐµĺóÐøpayloadÒÔ¼°¶ÔGootkitÏÂÔØ·¨Ê½ºÍϰȾÁ´µÄ¸ü¸Ä¡£¡£ ¡£¡£¡£¡£¡£¡£´Ë±í£¬ £¬£¬£¬ £¬£¬£¬»ã±¨»¹½éÉÜÁ˶ñÒâÈí¼þÓÃÀ´°µ²ØÆä´úÂëµÄ¶àÖÖ²½Ö裬 £¬£¬£¬ £¬£¬£¬²¢ÌṩÄܹ»×Ô¶¯Ö´Ðз´»ìºÏ¹ý³ÌµÄ¾ç±¾¡£¡£ ¡£¡£¡£¡£¡£¡£


https://www.mandiant.com/resources/blog/tracking-evolution-gootloader-operations