Turla APTÀÄÓÃMSBuild·Ö·¢TinyTurlaºóÃÅ

°ä²¼¹¦·ò 2024-05-23
1. Turla APTÀÄÓÃMSBuild·Ö·¢TinyTurlaºóÃÅ


5ÔÂ22ÈÕ£¬£¬£¬£¬£¬Ò»¸öÓë¶íÂÞ˹Óйصĸ߼¶³ÖÐøÐÔÍþв (APT) ×éÖ¯Ò»ÏòÔÚÀÄÓà PDF ºÍ MSBuild ÏîÄ¿Îļþ£¬£¬£¬£¬£¬ÀûÓÃÉç½»¹¤³Ìµç×ÓÓʼþ½« TinyTurla ºóÃÅ×÷ΪÎÞÎļþ¸ºÔؽøÐд«²¼¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬¸Ã»î¶¯µÄÎÞ·ì´«²¼·¨Ê½ÔÚ¸´ÔÓÐÔ·½Ãæ»ñµÃÁËÏÔÖøµÄ½øÈ¡¡£¡£¡£¡£¡£Cyble ×êÑÐÈËÔ±ºÍµý±¨³¢ÊÔÊÒ (CRIL) µÄ×êÑÐÈËÔ±·¢ÏÖÁËÕâÒ»»î¶¯£¬£¬£¬£¬£¬¸Ã»î¶¯Ê¹Óõç×ÓÓʼþºÍÔ¼ÇëÈËȨ×êÑлá»òÌṩ¹«¹²Õ÷ѯµÄÎļþ×÷Ϊµö¶ü£¬£¬£¬£¬£¬ÒÔϰȾ TinyTurla Óû§¡£¡£¡£¡£¡£ËûÃÇÔÚ×òÌì°ä²¼µÄÓйظûµÄ²©¿ÍÎÄÕÂÖаµÊ¾£¬£¬£¬£¬£¬¹¥»÷Õß»¹¼ÙÒâºÏ·¨µ±¾Ö£¬£¬£¬£¬£¬ÒÔÒýÓÕÊܺ¦ÕßÊÜÆ­¡£¡£¡£¡£¡£×êÑÐÈËÔ±Ö¸³ö£¬£¬£¬£¬£¬TinyTurla ºóÃÅÓë¶íÂÞ˹ÔÞÖúµÄ³Ö¾ÃÍþв×éÖ¯TurlaÓйØ£¬£¬£¬£¬£¬¸Ã×é֯ͨ³£Õë¶Ô·Çµ±¾Ö×éÖ¯£¬£¬£¬£¬£¬¡°³ö¸ñÊÇÄÇЩÓëÖ§³ÖÎÚ¿ËÀ¼ÓÐÁªÏµµÄ×éÖ¯¡±¡£¡£¡£¡£¡£Ìû×ӳƣ¬£¬£¬£¬£¬ËûÃÇÒÔΪ¸Ã×éÖ¯ÊǶñÒâ¹¥»÷»î¶¯µÄÄ»ºóºÚÊÖ¡£¡£¡£¡£¡£


https://www.darkreading.com/cyberattacks-data-breaches/russia-turla-apt-msbuild-tinyturla-backdoor


2. CISA ÖÒ¸æÀûÓÃMirth Connect·ì϶µÄ¹¥»÷»î¶¯


5ÔÂ21ÈÕ£¬£¬£¬£¬£¬Mirth Connect ÊÇÒ»ÖÖ¿í·ºÊ¹ÓÃµÄ¿çÆ½Ì¨½çÃæÒýÇæ£¬£¬£¬£¬£¬Ò½ÁƱ£½¡×éÖ¯½«ÆäÓÃÓÚÐÅÏ¢ÖÎÀí¡£¡£¡£¡£¡£Ó°Ï쿪Դ²úÆ·µÄ·ì϶ CVE-2023-43208 ÊÇÒ»¸öÊý¾Ý·´ÐòÁл¯ÎÊÌ⣬£¬£¬£¬£¬¿Éµ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£4.4.1 °æ°ä²¼Ê±ÒÑÍÆ³ö²¹¶¡¡£¡£¡£¡£¡£¸Ã·ì϶ÓÚ 2023 Äê 10 ÔÂÆØ¹â£¬£¬£¬£¬£¬ÆäÊ±ÍøÂ簲ȫ¹«Ë¾ Horizon3.ai ÖÒ¸æ³Æ¸Ã·ì϶¿ÉÄܶÔÒ½ÁƱ£½¡¹«Ë¾Ôì³ÉÓ°Ïì¡£¡£¡£¡£¡£CVE-2023-43208 ÊÇ CVE-2023-37679 µÄÒ»¸ö±äÌ壬£¬£¬£¬£¬Mirth Connect ¿ª·¢ÈËԱ֮ǰÒÑÔÚ 4.4.0 °æ°ä²¼Ê±¶Ô¸Ã·ì϶½øÐÐÁ˽¨²¹¡£¡£¡£¡£¡£Horizon3.ai Æäʱ½«¸Ã·ìϼûèÊöΪÒ×ÓÚÀûÓ㬣¬£¬£¬£¬²¢ÖÒ¸æ³Æ¡°¹¥»÷ÕߺܿÉÄÜÀûÓô˷ì϶½øÐгõʼ½Ó¼û»ò·ÛËéÃô¸ÐµÄÒ½ÁÆÊý¾Ý¡±¡£¡£¡£¡£¡£¸Ã°²È«¹«Ë¾»¹Ö¸³ö£¬£¬£¬£¬£¬·¢ÏÖÁË 1,200 ¶à¸ö¶³öÔÚ»¥ÁªÍøÉ쵀 NextGen Mirth Connect Ê·ý¡£¡£¡£¡£¡£


https://www.securityweek.com/cisa-warns-of-attacks-exploiting-nextgen-healthcare-mirth-connect-flaw/


3. ºÚ¿ÍÍÅ»ïÀûÓÃÀÕË÷Èí¼þ¹¥»÷·ÆÂɱöµ±¾Ö


5ÔÂ22ÈÕ£¬£¬£¬£¬£¬ºÚ¿ÍÔÚÀûÓÃй¶µÄÀÕË÷Èí¼þ¹¹½¨Õß¶Ô·ÆÂɱöµÄ¹Ø¼ü»ù´¡ÉèÊ©ÌáÒé¹¥»÷¡ª¡ªÕâÊdzöÓÚÕþÖζ¯»úµÄ¼¯ÌåµÄÇ÷ÏòµÄÒ»²¿ÃÅ£¬£¬£¬£¬£¬ËûÃÇÔ½À´Ô½¶àµØÊÔͼÇÖÈÅÕâ¸ö¶«ÄÏÑǹú¶ÈµÄÉúÑÄ¡£¡£¡£¡£¡£ÍøÂ簲ȫ¹«Ë¾ SentinelOneµÄ×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬Ò»¸öÃûΪ¡°Ikaruz Red Team¡±µÄ×éÖ¯ÊÇÉÙÊý¼¸¸öÕë¶Ô·ÆÂɱöµ±¾ÖÖ¸±êµÄºÚ¿Í×éÖ¯Ö®Ò»¡£¡£¡£¡£¡£¸ÃÐж¯ÀûÓÃÁ˶àÖÖÀÕË÷Èí¼þ¹¹½¨Õß¡ª¡ªÔ̺¬ LockBit¡¢Vice Society¡¢Clop ºÍ AlphV¡ª¡ªÌáÒé¡°Ó×¹æÄ£¡±¹¥»÷¡£¡£¡£¡£¡£Ëü»¹ÔÚÍøÉÏÐû´«·ÆÂɱö¶à¸ö×éÖ¯µÄÊý¾Ýй¶Çé¿ö¡£¡£¡£¡£¡£SentinelOne °µÊ¾£¬£¬£¬£¬£¬Êܺ¦ÕߵıãÌõÏÕЩȫÊýØâÇÔ×Ôԭʼ LockBit Ä£°å£¬£¬£¬£¬£¬¶¥²¿µÄÃû×ÖÖ®±í¡£¡£¡£¡£¡£Î´ÌṩÁªÏµÐÅÏ¢¡£¡£¡£¡£¡£


https://therecord.media/philippines-hacktivist-groups-leaked-versions-ransomware


4. GhostEngine ÍÚ¿ó¹¥»÷ÀûÓÃÒ×Êܹ¥»÷µÄÇý¶¯


5ÔÂ22ÈÕ£¬£¬£¬£¬£¬ÒÑ·¢ÏÖ´úºÅΪ¡°REF4578¡±µÄ¶ñÒâ¼ÓÃÜÇ®±ÒÍÚ¾ò»î¶¯²¿ÊðÁËÃûΪ GhostEngine µÄ¶ñÒâ¸ºÔØ£¬£¬£¬£¬£¬¸Ã¸ºÔØÊ¹ÓÃÒ×Êܹ¥»÷µÄÇý¶¯·¨Ê½À´¹Ø¹Ø°²È«²úÆ·²¢²¿Êð XMRig ÍÚ¿ó·¨Ê½¡£¡£¡£¡£¡£Elastic Security Labs ºÍ °²ÌìµÄ×êÑÐÈËÔ±  ÔÚµ¥¶ÀµÄ»ã±¨ºÍ¹²ÏíµÄ¼ì²â¹æ¶¨ÖÐÇ¿µ÷ÁËÕâЩ¼ÓÃÜÇ®±ÒÍÚ¾ò¹¥»÷µÄÒì³£¸´ÔÓÐÔ£¬£¬£¬£¬£¬ÒÔÔ®ÊÖ·ÀÓùÕß¼ø±ðºÍ×èÖ¹ËüÃÇ¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬Á½·Ý»ã±¨¾ù佫¸Ã»î¶¯¹é×ïÓÚÒÑÖªµÄÍþвÐÐΪÕߣ¬£¬£¬£¬£¬Ò²Î´·ÖÏíÓйØÖ¸±ê/Êܺ¦ÕߵľßÌåÐÅÏ¢£¬£¬£¬£¬£¬Òò¶ø¸Ã»î¶¯µÄ·¢Ô´ºÍÁìÓòÒÀȻδ֪¡£¡£¡£¡£¡£¹ÌÈ»Éв»Ã÷ÏÔ·þÎñÆ÷×î³õÊÇÈôºÎ±»·ÛËéµÄ£¬£¬£¬£¬£¬µ«ÍþвÐÐΪÕߵĹ¥»÷´ÓÖ´ÐÐÃûΪ¡°Tiworker.exe¡±µÄÎļþÆðÍ·£¬£¬£¬£¬£¬¸ÃÎļþ¼Ù×°³ÉºÏ·¨µÄ Windows Îļþ¡£¡£¡£¡£¡£¸Ã¿ÉÖ´ÐÐÎļþÊÇ GhostEngine µÄ³õʼµÇ̨ÓÐЧ¸ºÔØ£¬£¬£¬£¬£¬GhostEngine ÊÇÒ»¸ö PowerShell ¾ç±¾£¬£¬£¬£¬£¬¿ÉÏÂÔØ¸÷ÀàÄ£¿£¿£¿£¿£¿ £¿éÒÔÔÚÊÜϰȾµÄÉ豸ÉÏÖ´ÐÐ·ÖÆçµÄÐÐΪ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ghostengine-mining-attacks-kill-edr-security-using-vulnerable-drivers/


5. Î÷ϤÄá´óѧÔâµ½ºÚ¿Í¹¥»÷²¿ÃÅѧÉúÊý¾Ýй¶


5ÔÂ21ÈÕ£¬£¬£¬£¬£¬ÔÚÍþвÐÐΪÕß·ÛËéÁËÆä Microsoft 365 ºÍ Sharepoint »·¾³ºó£¬£¬£¬£¬£¬Î÷ϤÄá´óѧ (WSU) ÒÑÏòѧÉúºÍѧÊõÈËÔ±´«µÝÁËÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£WSU ÊǰĴóÀûÑǵÄÒ»Ëù½ÌÓý»ú¹¹£¬£¬£¬£¬£¬Ìṩ¿çѧ¿ÆµÄ¿í·º±¾¿Æ¡¢×êÑÐÉúºÍ×êÑпγ̡£¡£¡£¡£¡£ËüÕ¼ÓÐ 47,000 ÃûѧÉúºÍ 4,500 ¶àÃûÕýʽºÍ¼¾½ÚÐÔÔ±¹¤£¬£¬£¬£¬£¬ÔËÓªÔ¤ËãΪ 6 ÒÚÃÀÔª¡£¡£¡£¡£¡£Î÷ϤÄá´óÑ§ÍøÕ¾½ñÈÕ°ä²¼²¼¸æ£¬£¬£¬£¬£¬ÖÒ¸æ³ÆºÚ¿ÍÒѽӼûÆä Microsoft Office 365 »·¾³£¬£¬£¬£¬£¬Ô̺¬µç×ÓÓʼþÕÊ»§ºÍ SharePoint Îļþ¡£¡£¡£¡£¡£Ëù¶³öµÄÊý¾ÝÒòÈ˶øÒ죬£¬£¬£¬£¬¾ßÌåÈ¡¾öÓÚµç×ÓÓʼþͨѶµÄÄÚÈÝÒÔ¼°´óѧ SharePoint »·¾³Öд洢µÄÎĵµ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/western-sydney-university-data-breach-exposed-student-data/#google_vignette


6. Void Manticore¶Ô×¼ÒÔÉ«ÁкͰ¢¶û°ÍÄáÑÇ


5ÔÂ22ÈÕ£¬£¬£¬£¬£¬¸Ã×éÖ¯ÃûΪ Void Manticore (Storm-0842)£¬£¬£¬£¬£¬ÔÚ·ÖÆç¹ú¶ÈÒÔ¸÷À໯Ãû·¢Õ¹»î¶¯¡£¡£¡£¡£¡£×î³ÛÃûµÄ±ðºÅÔ̺¬Õë¶Ô°¢¶û°ÍÄáÑÇÏ®»÷µÄ¡°ºÓɽÕýÒ塱ºÍÕë¶ÔÒÔÉ«ÁÐÐж¯µÄ¡°Òò¹û±¨Ó¦¡±¡£¡£¡£¡£¡£Õë¶Ô·ÖÆçµÄÇøÓò£¬£¬£¬£¬£¬Õë¶Ôÿ¸öÖ¸±êѡȡ¹ÖÒìµÄ²½Öè¡£¡£¡£¡£¡£¸Ã×éÖ¯µÄ»î¶¯ÓëÁíÒ»¸öÒÁÀÊ×éÖ¯ Scarred Manticore µÄ»î¶¯³Áµþ£¬£¬£¬£¬£¬ÕâÅúעЭºÍгϵͳµÄÊܺ¦ÕßÑ¡ÔñÊÇËûÃÇΪÒÁÀʵý±¨ºÍ°²È«Êý (MOIS) ¹¤×÷µÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£×¨¼ÒÖÒ¸æËµ£¬£¬£¬£¬£¬Ðé¿ÕЫʨ¶ÔÈκηñ¾öÒÁÀÊÀûÒæµÄÈË×é³É³Á´óÍþв¡£¡£¡£¡£¡£¸Ã×éÖ¯ÀûÓø´ÔӵϝÃûÍøÂç¡¢Õ½ÊõºÏ×÷ºÍ¸´ÔӵĹ¥»÷²½Öè¡£¡£¡£¡£¡£¸Ã×éÖ¯ÒÔÆäË«³ÁÍøÂç¹¥»÷·½Ê½¶øÎÅÃû£¬£¬£¬£¬£¬½«ÎïÀíÊý¾Ý·ÛËéÓëÉúÀíѹÁ¦Ïà½áºÏ¡£¡£¡£¡£¡£Void Manticore ʹÓÃÎåÖÖ·ÖÆçµÄ²½Ö裬£¬£¬£¬£¬Ô̺¬Õë¶Ô Windows ºÍ Linux µÄ×Ô½ç˵²Á³ýÆ÷£¬£¬£¬£¬£¬Í¨¹ýɾ³ýÎļþºÍ°Ñ³Ö¹²Ïí´ÅÅÌÀ´·ÛËéϵͳ¡£¡£¡£¡£¡£


https://meterpreter.org/void-manticore-iranian-state-sponsored-hackers-target-israel-albania/