¼ÓÄô󺽿յÄϵͳ±»ÈëÇÖ²¿ÃÅÔ±¹¤µÄÓ×ÎÒÐÅϢй¶

°ä²¼¹¦·ò 2023-09-25

1¡¢¼ÓÄô󺽿յÄϵͳ±»ÈëÇÖ²¿ÃÅÔ±¹¤µÄÓ×ÎÒÐÅϢй¶


¾ÝýÌå9ÔÂ21ÈÕ±¨Â· £¬ £¬£¬ £¬£¬£¬£¬¼ÓÄô󺽿ÕÅû¶ÁËһ·°²È«ÊÂÎñ £¬ £¬£¬ £¬£¬£¬£¬ÆäÖкڿ͡°¶ÌÔݵء±»ñµÃÁËÆäÄÚ²¿ÏµÍ³µÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¾ÝϤ £¬ £¬£¬ £¬£¬£¬£¬Õâ´ÎÊÂÎñµ¼ÖÂÔ±¹¤µÄÓ×ÎÒÐÅÏ¢ºÍ²¿ÃżÍ¼й¶¡£¡£¡£¡£¡£µ«ÊǺ½°àÔËӪϵͳºÍÃæÏò¿Í»§µÄϵͳûÓÐÊܵ½Ó°Ïì £¬ £¬£¬ £¬£¬£¬£¬¿Í»§ÐÅϢҲûÓб»½Ó¼û¡£¡£¡£¡£¡£Ä¿Ç° £¬ £¬£¬ £¬£¬£¬£¬ËùÓÐϵͳ¾ùÒÑÈ«ÃæÔËÐС£¡£¡£¡£¡£²»¾Ãǰ £¬ £¬£¬ £¬£¬£¬£¬ÒòÔâµ½DDoS¹¥»÷ £¬ £¬£¬ £¬£¬£¬£¬¼ÓÄôóÈ«¹ú¸÷µØµÄ±ßÚï²é³­Õ¾Öµ»úͤµÄÍÆËã»ú³öÏÖ¹ÊÕÏ £¬ £¬£¬ £¬£¬£¬£¬µ¼ÖÂÈë¾³´î¿Í°ìÀíÊÖÐøµÄËÙ¶ÈÂýÁËÒ»¸ö¶àÓ×ʱ¡£¡£¡£¡£¡£


https://therecord.media/air-canada-limited-employee-info-accessed 


2¡¢ALPHV³Æ¶Ô³µÔØÒôÏìÔì×÷ÉÌClarionÔâµ½µÄ¹¥»÷ÕÆ¹Ü


¾Ý9ÔÂ24ÈÕ±¨Â· £¬ £¬£¬ £¬£¬£¬£¬AlphvÐû³ÆÈëÇÖÁËÒôƵºÍ¶àýÌåÉ豸µÄÈ«ÇòÔì×÷ÉÌClarion¡£¡£¡£¡£¡£¸Ã¹«Ë¾¿ª·¢¡¢Ôì×÷ºÍÏúÊÛ¸÷Àà²úÆ· £¬ £¬£¬ £¬£¬£¬£¬Ô̺¬Æû³µµ¼º½ÏµÍ³¡¢ÒôƵϵͳ¡¢ÊÓÆµÏµÍ³ºÍºóÊÓÉãÏñÍ·¡£¡£¡£¡£¡£AlphvÔÚ9ÔÂ23ÈÕ½«ClarionÔö³¤µ½ÆäTorÍøÕ¾ÖÐ £¬ £¬£¬ £¬£¬£¬£¬³ÆÓйØÒµÎñºÍºÏ×÷ͬ°éµÄ»úÃÜÒѾ­Êý¾Ýй¶¡£¡£¡£¡£¡£¸ÃÍŻﻹ°µÊ¾Æä»ñµÃÁ˿ͻ§Êý¾Ý £¬ £¬£¬ £¬£¬£¬£¬²¢ÍþвÔÚ9ÔÂ25ÈÕ֮ǰ½«ÕâЩÊý¾ÝÏúÊÛ¸øµÚÈý·½¡£¡£¡£¡£¡£ºÚ¿Í°ä²¼ÁËһЩ±»µÁÎļþµÄ½ØÍ¼×÷Ϊ¹¥»÷µÄÖ¤¾Ý¡£¡£¡£¡£¡£


https://securityaffairs.com/151299/data-breach/alphv-ransomware-hacked-clarion.html


3¡¢SandmanÍÅ»ïÀûÓÃкóÃÅLuaDreamÖØÒªÕë¶ÔµçÐÅÌṩÉÌ


9ÔÂ21ÈÕ £¬ £¬£¬ £¬£¬£¬£¬SentinelLabs³ÆSandmanÀûÓÃÄ£¿ £¿£¿£¿£¿£¿é»¯ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þLuaDream¹¥»÷µçÕÛ·þÎñÌṩÉÌ¡£¡£¡£¡£¡£¸Ã»î¶¯ÓÚ8Ô·ݱ»·¢ÏÖ £¬ £¬£¬ £¬£¬£¬£¬ÖØÒªÕë¶ÔÖж«¡¢Î÷Å·ºÍÄÏÑÇ¡£¡£¡£¡£¡£SandmanÀûÓÃLuaJITƽ̨²¿ÊðÁËÐÂÐͺóÃÅLuaDream £¬ £¬£¬ £¬£¬£¬£¬¸ÃºóÃÅÓÉ34¸ö×é¼þ×é³É £¬ £¬£¬ £¬£¬£¬£¬Ô̺¬13¸öÖ÷Ìâ×é¼þºÍ21¸öÖ§³Ö×é¼þ £¬ £¬£¬ £¬£¬£¬£¬ËüÃÇͨ¹ýffi¿âʹÓÃLuaJIT×Ö½ÚÂëºÍWindows API¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄ¿ª·¢ËƺõºÜ»îÔ¾ £¬ £¬£¬ £¬£¬£¬£¬°æ±¾ºÅΪ"12.0.2.5.23.29" £¬ £¬£¬ £¬£¬£¬£¬×îÔç¿É×·Òäµ½2022Äê6Ô¡£¡£¡£¡£¡£


https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/


4¡¢³¬¹ý200ÍòÃû°Í»ù˹̹¹«ÃñµÄÓ×ÎÒÐÅÏ¢±»ºÚ¿ÍÏúÊÛ


9ÔÂ21ÈÕ±¨Â·³Æ £¬ £¬£¬ £¬£¬£¬£¬ºÚ¿ÍÈëÇÖÁ˰ͻù˹̹Êý°Ù¼Ò²ÍÌüʹÓõĸöÈ˹«Ë¾Ôì×÷µÄÊý¾Ý¿â £¬ £¬£¬ £¬£¬£¬£¬µ¼Ö³¬¹ý200Íò¹«ÃñÃæ¶Ô×ÅÓ×ÎÒÐÅϢй¶µÄ·çÏÕ¡£¡£¡£¡£¡£¸ÃÊÂÎñÓ°ÏìÁ˲ÍÌüµÄ¿Í»§ £¬ £¬£¬ £¬£¬£¬£¬Ð¹Â¶ÁËÐÅÓþ¿¨¡¢µØÖ·ºÍÒøÐоßÌåÐÅÏ¢µÈÊý¾Ý¡£¡£¡£¡£¡£ºÚ¿ÍÔÚÒÔ2±ÈÌØ±ÒµÄ¼ÛÖµÏúÊÛ±»µÁÊý¾Ý¡£¡£¡£¡£¡£ºÚ¿ÍÔÚµãÃûij¶¥¼¶²ÍÌüʱй© £¬ £¬£¬ £¬£¬£¬£¬ËûÃÇÒÑÈëÇÖÁË250¶à¼Ò²ÍÌüµÄÊý¾Ý¿â¡£¡£¡£¡£¡£ÁíÒ»·½Ãæ £¬ £¬£¬ £¬£¬£¬£¬Áª¹úµ÷²éÈËÔ±°µÊ¾ £¬ £¬£¬ £¬£¬£¬£¬ËûÃÇûÓÐÊÕµ½Õâ·½ÃæµÄͶËß¡£¡£¡£¡£¡£


https://en.dailypakistan.com.pk/21-Sep-2023/hackers-put-over-2-million-pakistanis-private-data-for-sale-after-restaurant-software-breach


5¡¢Unit 42Åû¶GelsemiumÕë¶Ô¶«ÄÏÑÇ»ú¹¹µÄ¹¥»÷»î¶¯


Unit 42ÔÚ9ÔÂ22ÈÕÅû¶ÁËGelsemiumÕë¶Ô¶«ÄÏÑǵ±¾Ö»ú¹¹µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚ±»Ï°È¾µÄWeb·þÎñÆ÷ÉÏ×°ÖÃÁ˶à¸öWeb shellÀ´»ñµÃϵͳ½Ó¼ûȨÏÞ £¬ £¬£¬ £¬£¬£¬£¬Ô̺¬¹«¿ª¿ÉÓõÄreGeorg¡¢China ChopperºÍAspxSpy¡£¡£¡£¡£¡£¹¥»÷ÕßÓÃÓÚºáÏòÒÆ¶¯¡¢Êý¾ÝÍøÂçºÍÌáȨµÄ¹¤¾ßÔ̺¬OwlProxy¡¢SessionManager¡¢Cobalt Strike¡¢SpoolFoolºÍEarthWorm¡£¡£¡£¡£¡£×êÑÐÈËԱͨ¹ýOwlProxyºÍSessionManager´§¶ÈÕâ´Î¹¥»÷»î¶¯ÓëGelsemiumÓйØ¡£¡£¡£¡£¡£


https://unit42.paloaltonetworks.com/rare-possible-gelsemium-attack-targets-se-asia/


6¡¢ESET³ÆStealth FalconÀûÓÃDeadglyph¹¥»÷Öж«µÄʵÌå


9ÔÂ22ÈÕ £¬ £¬£¬ £¬£¬£¬£¬ESET°ä²¼»ã±¨³ÆStealth FalconÀûÓÃDeadglyph¹¥»÷Öж«µÄʵÌå¡£¡£¡£¡£¡£DeadglyphµÄ¼Ü¹¹Óɶà¸öºÏ×÷×é¼þ×é³É £¬ £¬£¬ £¬£¬£¬£¬Ô̺¬±¾µØx64¶þ½øÔì×é¼þºÍ.NET·¨Ê½¼¯¡£¡£¡£¡£¡£Óë½öʹÓÃÒ»ÖÖ±à³Ì˵»°¿ª·¢µÄ³£¼û¶ñÒâÈí¼þ·ÖÆç £¬ £¬£¬ £¬£¬£¬£¬DeadglyphʹÓÃÁË·ÖÆçµÄ˵»°¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÒÔ¸½¼ÓÄ£¿ £¿£¿£¿£¿£¿éµÄ´ó¾Ö´ÓC2¶¯Ì¬½Ó¹ÜºÅÁî £¬ £¬£¬ £¬£¬£¬£¬»¹Ö§³Ö¶àÖÖÈÆ¹ýÖ°ÄÜ¡£¡£¡£¡£¡£¸Ã»ã±¨·ÖÎöµÄÊÇÕë¶ÔÖж«Ä³µÐÔÖʵÌåµÄ¹¥»÷ £¬ £¬£¬ £¬£¬£¬£¬ÉÐδȷ¶¨ºóÃŵľßÌå´«²¼·½Ê½¡£¡£¡£¡£¡£


https://www.welivesecurity.com/en/eset-research/stealth-falcon-preying-middle-eastern-skies-deadglyph/