ESET·¢ÏÖSandwormÀûÓÃSwiftSlicer¹¥»÷ÎÚ¿ËÀ¼µÄ»î¶¯

°ä²¼¹¦·ò 2023-01-31
1¡¢ESET·¢ÏÖSandwormÀûÓÃSwiftSlicer¹¥»÷ÎÚ¿ËÀ¼µÄ»î¶¯

      

ESET×êÑÐÈËÔ±ÓÚ1ÔÂ27ÈÕ³Æ £¬ÔÚ×î½üÒ»´ÎÕë¶ÔÎÚ¿ËÀ¼×éÖ¯µÄ¹¥»÷»î¶¯Öз¢ÏÖÁËÒ»ÖÖеÄÊý¾Ý²Á³ý¶ñÒâÈí¼þSwiftSlicer £¬²¢½«Æä¹éÒòÓÚAPT×éÖ¯Sandworm¡£SwiftSlicerÓÚ1ÔÂ25ÈÕÔÚÖ¸±êµÄÍøÂçÉϱ»·¢ÏÖ £¬Ëüͨ¹ý×éÕ½Êõ²¿Ê𠣬ÕâÅú×¢¹¥»÷ÕßÒѾ­½ÚÔìÁËÖ¸±êµÄActive Directory»·¾³¡£¸Ã¶ñÒâÈí¼þÊÇÓÃGo¿ª·¢µÄ £¬Ò»µ©Ö´Ðоͻáɾ³ý¾íÓ°¸±±¾²¢¸²¸ÇWindowsϵͳĿ¼ÖеĹؼüÎļþ £¬³ö¸ñÊÇÇý¶¯·¨Ê½ºÍActive DirectoryÊý¾Ý¿â¡£


https://www.welivesecurity.com/2023/01/27/swiftslicer-new-destructive-wiper-malware-ukraine/ 


2¡¢QNAP°ä²¼¹Ì¼þ¸üн¨¸´ÆäNASÉ豸ÖеÄSQL×¢Èë·ì϶

      

1ÔÂ30ÈÕ £¬QNAP°ä²¼ÁËQTSºÍQuTSµÄ¹Ì¼þ¸üР£¬ÒÔ½¨¸´¿ÉÔÚÆäNASÉ豸ÖÐ×¢Èë¶ñÒâ´úÂëµÄ·ì϶¡£¸Ã·ì϶׷×ÙΪCVE-2022-27596 £¬CVSSÆÀ·ÖΪ9.8 £¬Ó°ÏìÁËQTS 5.0.1ºÍQuTS hero h5.0.1°æ±¾¡£¹©¸øÉÌûÓÐй©Óйظ÷ì϶µÄ¸ü¶àϸ½Ú £¬µ«NIST portal½«ÆäÃèÊöΪSQL×¢Èë·ì϶¡£´Ë±í £¬QNAP°ä²¼ÁËÒ»¸öÃèÊö¸Ã·ì϶ÑϳÁÐÔµÄJSONÎļþ £¬Åú×¢¸Ã·ì϶¿É±»Ô¶³Ì¹¥»÷ÕßÔڵ͸´ÔÓˮƽµÄ¹¥»÷ÖÐÀûÓà £¬¶øÎÞÐèÓû§½»»¥»òÖ¸±êÉ豸ÉϵÄȨÏÞ¡£


https://securityaffairs.com/141588/iot/qnap-addresses-critical-flaw.html   


3¡¢Í¶×Ê×êÑй«Ë¾ZacksÔâµ½¹¥»÷µ¼ÖÂ82ÍòÓû§µÄÐÅϢй¶

      

¾ÝýÌå1ÔÂ25ÈÕ±¨Â· £¬Zacks Investment Research¹«Ë¾µÄÊý¾Ýй¶ÊÂÎñÓ°ÏìÁË820000Ãû¿Í»§¡£Zacks·¢ÏÖ²¿Ãſͻ§¼Í¼Ôâµ½ÁËδ¾­ÊÚȨµÄ½Ó¼û £¬¾­ÄÚ²¿µ÷²éÈ·¶¨¹¥»÷ÕßÔÚ2021Äê11ÔÂÖÁ2022Äê8ÔÂÖ®¼äµÄij¸ö¹¦·ò½Ó¼ûÁ˸ÃÍøÂ硣й¶ÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç»°¡¢ÓʼþµØÖ·ºÍZacks.comÍøÕ¾µÄÓû§ÃÜÂë¡£¸Ã¹«Ë¾³ÎÇå˵ £¬Õâ´ÎÊÂÎñ½öÓ°ÏìÔÚ1999Äê11ÔÂÖÁ2005Äê2Ô²ÎÓëµÄZacks EliteµÄ¿Í»§¡£Ä¿Ç° £¬Zacks³ÁÖÃÁËÊÜÓ°ÏìÓû§µÄÃÜÂë £¬²¢Ö´ÐÐÁ˶î±íµÄ°²È«´ëÊ©¡£


https://www.bleepingcomputer.com/news/security/zacks-investment-research-data-breach-affects-820-000-clients/


4¡¢ÀÕË÷Èí¼þMimicÀûÓÃËÑË÷¹¤¾ßEverything²éÕÒÒª¼ÓÃܵÄÎļþ

      

Trend MicroÔÚ1ÔÂ26ÈÕ͸© £¬ÐµÄÀÕË÷Èí¼þMimicÀûÓúϷ¨¹¤¾ßEverythingµÄAPIÀ´²éÕÒÒª¼ÓÃܵÄÎļþ¡£EverythingÊÇVoidtools¿ª·¢µÄWindowsÎļþÃûËÑË÷ÒýÇæ £¬¿ÉÔ®ÊÖMimicÕÒµ½¿É¼ÓÃܵÄÎļþ £¬Í¬Ê±ÈÆ¿ªÄÇЩ¼ÓÃܺó»áµ¼ÖÂϵͳÎÞ·¨Æô¶¯µÄÎļþ¡£¸ÃÀÕË÷Èí¼þÓÚ2022Äê6Ô³õ´ÎÔÚÒ°±í±»·¢ÏÖ £¬ÖØÒªÕë¶Ô¶íÓïºÍÓ¢ÓïÖ¸±ê¡£Æä²¿ÃÅ´úÂëÓëÀÕË÷Èí¼þContiÓÐÀàËÆÖ®´¦ £¬»¹Äܹ»ÀûÓöà¸ö´¦ÖÃÆ÷Ïß³ÌÀ´¼Ó¿ìÊý¾Ý¼ÓÃܹý³Ì £¬ÓµÓÐÏÖ´úÀÕË÷Èí¼þµÄ³£¼ûÖ°ÄÜ¡£


https://www.trendmicro.com/en_us/research/23/a/new-mimic-ransomware-abuses-everything-apis-for-its-encryption-p.html


5¡¢×êÑÐÈËÔ±ÔÚBlack Basta¹¥»÷»î¶¯Öз¢ÏÖPlugXбäÌå

      

¾Ý1ÔÂ27ÈÕ±¨Â· £¬×êÑÐÈËÔ±ÔÚÒ»´ÎBlack BastaµÄ¹¥»÷»î¶¯Öз¢ÏÖÁ˶ñÒâÈí¼þPlugXµÄбäÌå¡£¸Ã±äÌåÄܹ»ÔÚUSBÉ豸Éϰµ²Ø¶ñÒâÎļþ £¬¶øºóϰȾËüÃÇÏνӵÄWindowsÖ÷»ú¡£ÔÚÕâ´Î»î¶¯ÖÐ £¬¹¥»÷ÕßʹÓÃ32λ°æ±¾µÄWindowsµ÷ÊÔ¹¤¾ßx64dbg.exeºÍÖж¾°æ±¾µÄx32bridge.dll £¬À´¼ÓÔØPlugX payload£¨x32bridge.dat£©¡£Ä¿Ç° £¬ÔÚVirus TotalɨÃèÆ½Ì¨ÉϵÄ61ÖÖ²úÆ·ÖÐ £¬½öÓÐ9ÖÖÄܹ»½«ÆäÏóÕ÷Ϊ¶ñÒâÎļþ¡£


https://www.bleepingcomputer.com/news/security/plugx-malware-hides-on-usb-devices-to-infect-new-windows-hosts/


6¡¢Mandiant°ä²¼¹ØÓÚGootkit¹¥»÷»î¶¯ÑݱäµÄ·ÖÎö»ã±¨

      

MandiantÔÚ1ÔÂ26ÈÕ°ä²¼Á˹ØÓÚGootkit¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£×Ô2021Äê1ÔÂÒÔÀ´ £¬MandiantÒ»ÏòÔÚ¸ú×ÙUNC2565µÄGootkitµÄ»î¶¯¡£×êÑÐÈËÔ±·¢ÏÖ £¬´Ó2022ÄêÆðÍ·UNC2565¶ÔÆä»î¶¯ÖÐʹÓõÄTTP½øÐиü¸Ä £¬Ô̺¬Ê¹ÓÃFONELAUNCH launcherµÄ¶à¸ö±äÌå¡¢·Ö·¢ÐµĺóÐøpayloadÒÔ¼°¶ÔGootkitÏÂÔØ·¨Ê½ºÍϰȾÁ´µÄ¸ü¸Ä¡£´Ë±í £¬»ã±¨»¹½éÉÜÁ˶ñÒâÈí¼þÓÃÀ´°µ²ØÆä´úÂëµÄ¶àÖÖ²½Öè £¬²¢ÌṩÄܹ»×Ô¶¯Ö´Ðз´»ìºÏ¹ý³ÌµÄ¾ç±¾¡£


https://www.mandiant.com/resources/blog/tracking-evolution-gootloader-operations