Kaspersky·¢Ã÷APT41ʹÓÃMoonBounceµÄ¹¥»÷Ô˶¯

Ðû²¼Ê±¼ä 2022-01-24

Kaspersky·¢Ã÷APT41ʹÓÃMoonBounceµÄ¹¥»÷Ô˶¯


1ÔÂ20ÈÕ £¬KasperskyÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þMoonBounceµÄÆÊÎö±¨¸æ ¡£Ñо¿Ö°Ô±³Æ £¬MoonBounceÊÇÆù½ñΪֹÔÚÒ°Íâ·¢Ã÷µÄ×îÏȽøµÄUEFI¹Ì¼þ¶ñÒâÈí¼þ £¬ÓëºÚ¿Í×éÖ¯APT41£¨Ò²³ÆÎªWinnti£©ÓÐ¹Ø ¡£MoonBounceÖ²ÈëÔÚÖ÷°åµÄSPIÉÁ´æÉÏ £¬Òò´Ë×ÝÈ»Ìæ»»Ó²ÅÌÒ²ÎÞ·¨½«Æä¸ù³ý ¡£ÕâÊǽüÆÚ·¢Ã÷µÄµÚÈý¸öUEFI¶ñÒâÈí¼þ £¬Ö®Ç°Á½¸öΪFinFisherºÍESPecter ¡£KasperskyÌåÏִ˴ι¥»÷¾ßÓи߶ÈÕë¶ÔÐÔ £¬Ä³¸ö¿ØÖÆ×ż¸¼ÒÔËÊäÊÖÒÕÏà¹ØÆóÒµµÄ×éÖ¯ÒѳÉΪ¹¥»÷Ä¿µÄ ¡£


https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/


ContiÍÅ»ïÉù³Æ¶ÔÓ¡¶ÈÄáÎ÷ÑÇÑëÐеÄÀÕË÷¹¥»÷ÈÏÕæ


¾ÝýÌå1ÔÂ20ÈÕ±¨µÀ £¬Ó¡¶ÈÄáÎ÷ÑÇÒøÐУ¨BI£©ÈÏ¿ÉÆäÔâµ½ÀÕË÷¹¥»÷ ¡£¸ÃÐн²»°ÈËÌåÏÖ £¬¹¥»÷±¬·¢ÔÚÉϸöÔ £¬¹¥»÷ÕßÇÔÈ¡Á˲¿·ÖÔ±¹¤µÄÐÅÏ¢ £¬²¢ÔÚÊ®¼¸¸öϵͳÉÏ×°ÖÃÁËÀÕË÷Èí¼þ £¬µ«ÆäÔËÓª²¢Î´Êܵ½Ó°Ïì ¡£ContiÍÅ»ïÉù³Æ¶Ô´ËÊÂÈÏÕæ £¬ÈôÊÇÓ¡ÄáÒøÐв»Ö§¸¶Êê½ð £¬ËûÃǽ«¹ûÕæ¸ÃÒøÐÐ13.88 GBµÄÎļþ ¡£Ç°²»¾Ã £¬Conti»¹¹¥»÷Á˰®¶ûÀ¼DoH¡¢HSE £¬ºÍÓªÏú¹«Ë¾RR Donnelly ¡£


https://www.bleepingcomputer.com/news/security/indonesias-central-bank-confirms-ransomware-attack-conti-leaks-data/


Ñо¿Ö°Ô±³ÆÊýÊ®¸öWordPressÖ÷ÌâºÍ²å¼þÒѱ»Ö²ÈëºóÃÅ


JetPackÔÚ1ÔÂ18ÈÕÐû²¼±¨¸æ £¬³ÆÒÑÔÚÊýÊ®¸öWordPressÖ÷ÌâºÍ²å¼þÖз¢Ã÷ºóÃÅ ¡£Ñо¿Ö°Ô±³Æ £¬¹¥»÷ÕßÒÑÔÚAccessPress ThemesµÄ40¸öÖ÷ÌâºÍ53¸ö²å¼þÖÐÖ²ÈëºóÃÅ ¡£¾­ÓÉÊÓ²ìµÃÖª £¬AccessPress ThemesÓÚ2021Äê9ÔÂÉϰëÔÂÔâµ½¹¥»÷ £¬ÆäÊ±ÍøÕ¾ÉϵÄÀ©Õ¹³ÌÐò±»×¢ÈëÁ˺óÃÅ ¡£ÊÜѬȾµÄÀ©Õ¹³ÌÐò°üÀ¨Ò»¸öwebshell dropper £¬Ê¹¹¥»÷Õß¿ÉÒÔÍêÈ«»á¼ûÄ¿µÄÍøÕ¾ £¬¸ÃÎó²î×·×ÙΪCVE-2021-24867 ¡£


https://thehackernews.com/2022/01/hackers-planted-secret-backdoor-in.html



ʹÓÃCWPµÄÎļþ°üÀ¨ºÍí§ÒâдÈëÎó²î¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ


ýÌå1ÔÂ22ÈÕ±¨µÀ £¬Control Web PanelÖб£´æ2¸öÑÏÖØµÄÎó²î ¡£Control Web Panel£¨ÒÔǰµÄCentOS Web Panel£©ÊÇÒ»¸ö¿ªÔ´µÄLinux¿ØÖÆÃæ°åÈí¼þ £¬ÓÃÓÚ°²ÅÅWebÍйÜÇéÐÎ ¡£µÚÒ»¸öÊÇÎļþ°üÀ¨Îó²î£¨CVE-2021-45467£© £¬¹¥»÷ÕßÖ»ÐèÐÞ¸ÄincludeÓï¾ä¾Í¿ÉÒÔÔ¶³Ì×¢Èë¶ñÒâ´úÂë»òʵÏÖ´úÂëÖ´ÐÐ ¡£µÚ¶þ¸öΪí§ÒâÎļþдÈëÎó²î£¨CVE-2021-45466£© £¬ÍŽáʹÓÃÕâÁ½¸öÎó²î¿ÉÒÔÔÚÒ×Êܹ¥»÷µÄLinux·þÎñÆ÷ÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ ¡£


https://securityaffairs.co/wordpress/127058/hacking/control-web-panel-flaws.html


MoleratsÍÅ»ïʹÓöà¸öÔÆ·þÎñ¶ÔÖж«µØÇø¾ÙÐÐÌØ¹¤¹¥»÷


¾ÝýÌå1ÔÂ22ÈÕ±¨µÀ £¬Çå¾²¹«Ë¾Zscaler·¢Ã÷MoleratsÍÅ»ïÕë¶ÔÖж«µØÇøµÄÌØ¹¤Ô˶¯ ¡£¾ÝϤ £¬¹¥»÷´Ó2021Äê7Ô¾ÍÒÑ×îÏÈ £¬¹¥»÷ÕßʹÓÃÕýµ±µÄÔÆ·þÎñ£¨ÈçGoogle DriveºÍDropbox£©ÍйܶñÒâÈí¼þpayload £¬´ÓÖж«µØÇøµÄÄ¿µÄÖÐÇÔÈ¡Êý¾Ý ¡£´Ë´ÎÔ˶¯Ê¹ÓÃÓëÒÔÉ«ÁкͰÍÀÕ˹̹³åÍ»Ïà¹ØµÄÓÕ¶ü £¬ÔÚÄ¿µÄϵͳÉÏ×°ÖÃ.NETºóÃÅ £¬Ö÷ҪĿµÄ°üÀ¨°ÍÀÕË¹Ì¹ÒøÐÐÒµÔ±¹¤¡¢°ÍÀÕ˹̹Õþµ³³ÉÔ± £¬ÒÔ¼°ÍÁ¶úÆä¼ÇÕßµÈ ¡£


https://thehackernews.com/2022/01/molerats-hackers-hiding-new-espionage.html


×ÖÄ»ÍøÕ¾OpenSubtitles½ü700ÍòÓû§µÄÐÅϢй¶


¾Ý1ÔÂ23ÈÕ±¨µÀ £¬×ÖÄ»ÍøÕ¾OpenSubtitlesÔâµ½¹¥»÷ £¬6783158¸öÓû§µÄÐÅÏ¢ÒѾ­Ð¹Â¶ ¡£2021Äê8Ô £¬ÍøÕ¾¹ÜÀíÔ±ÊÕµ½Êê½ð֪ͨºó²ÅÒâʶµ½ÆäÒÑÔâµ½¹¥»÷ ¡£¹¥»÷Õß»¹ÌåÏÖ»áÌṩ֧³ÖÒÔÐÞ¸´ÍøÕ¾ÖеÄÎó²î £¬µ«ÔÚÖ§¸¶Êê½ðºó¹¥»÷Õß´Óδ×ÊÖúËûÃǼӹÌÍøÕ¾ £¬²¢ÔÚ1ÔÂ11ÈÕ¹ûÕæÁ˱»µÁÊý¾Ý ¡£¾ÝϤ £¬ºÚ¿Íͨ¹ýSQL×¢Èë¹¥»÷»á¼ûÁËÍøÕ¾µÄÊý¾Ý¿â £¬ÇÔÈ¡ÁËÓû§Óʼþ¡¢IPµØÖ·¡¢Óû§Ãû¡¢ËùÔÚ¹ú¼ÒºÍÃÜÂëµÈÐÅÏ¢ ¡£


https://securityaffairs.co/wordpress/127092/data-breach/opensubtitles-data-breach.html



Çå¾²¹¤¾ß


Narthex


ÊÇÒ»¸öÄ£¿é»¯ºÍ×îСµÄ×ÖµäÌìÉúÆ÷ £¬ÓÃÓÚÓà C ºÍ Shell ±àдµÄ Unix ºÍÀà Unix ²Ù×÷ϵͳ ¡£


https://github.com/MichaelDim02/Narthex


Iptable_Evil 


IptablesµÄºóÃÅ £¬Ê¹¶ñÒâÊý¾Ý°üͨ¹ýiptables £¬ÎÞÂÛ·À»ðǽ¹æÔòÔõÑù ¡£


https://github.com/FlamingSpork/iptable_evil



iMonitor


ÊÇÒ»¿î»ùÓÚiMonitorSDKµÄ¶ËµãÐÐΪ¼à¿ØÆÊÎöÈí¼þ ¡£


https://github.com/wecooperate/iMonitor/releases



Çå¾²ÆÊÎö


΢ÈíÐÞ¸´ÁË Windows 10 µÄ Outlook ËÑË÷ÎÊÌâ


΢ÈíÐÞ¸´ÁË×°ÖÃ2021 Äê 11 ÔÂÐû²¼µÄ Windows 10 Çå¾²¸üкóµ¼Ö Outlook Óû§·ºÆðËÑË÷ÎÊÌâµÄÎÊÌâ ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-outlook-search-issues-for-windows-10-users/


WordPress²å¼þ±£´æÎó²î


WP HTML MailÖб£´æÒ»¸öÑÏÖØµÄ¿çÕ¾µã¾ç±¾(XSS)Îó²î £¬Ó°ÏìÁè¼Ý20,000¸öWordPressÍøÕ¾ ¡£


https://threatpost.com/wordpress-insecure-plugin-rest-api/177866/