MOVEit TransferÐÞ¸´ÆäwebÓ¦ÓÃÖеĶà¸öSQL×¢ÈëÎó²î

Ðû²¼Ê±¼ä 2023-06-12

1¡¢MOVEit TransferÐÞ¸´ÆäwebÓ¦ÓÃÖеĶà¸öSQL×¢ÈëÎó²î


¾Ý6ÔÂ10ÈÕ±¨µÀ£¬Progress SoftwareÔÚÆäMOVEit TransferÍйÜÎļþ´«Êä(MFT)½â¾ö¼Æ»®ÖÐз¢Ã÷Á˶à¸öÑÏÖصÄSQL×¢ÈëÎó²î¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòMOVEit TransferÓ¦ÓóÌÐòÌá½»ÌØÖƵÄpayload£¬À´Ð޸ĺÍй¶MOVEitÊý¾Ý¿âµÄÄÚÈÝ¡£ÕâЩÎó²îÊÇͨ¹ý´úÂëÇå¾²Éó¼Æ·¢Ã÷µÄ£¬Ó°ÏìÁËËùÓÐMOVEit Transfer°æ±¾£¬ÏÖÔÚÉÐδ·¢Ã÷±»Ê¹Óõļ£Ï󡣸ù«Ë¾ÓÚ6ÔÂ9ÈÕÐû²¼ÁËÇå¾²²¹¶¡£¬²¢ÌåÏÖËùÓÐMOVEit Transfer¿Í»§¶¼±ØÐèÓ¦Óô˲¹¶¡¡£


https://thehackernews.com/2023/06/new-critical-moveit-transfer-sql.html


2¡¢¶íÂÞ˹ÒøÐÐÏà¹ØµÄµçÐŹ«Ë¾Infotel JSCÔâµ½´ó¹æÄ£¹¥»÷


¾ÝýÌå6ÔÂ9ÈÕ±¨µÀ£¬ÎÚ¿ËÀ¼ºÚ¿ÍÍÅ»ïCyber.Anarchy.SquadÉù³Æ¹¥»÷Á˶íÂÞ˹µçÐÅÌṩÉÌInfotel JSC²¢µ¼ÖÂÆäå´»ú¡£InfotelÖ÷ÒªÈÏÕæ¶íÂÞ˹ÑëÐÐÓëÆäËü¶íÂÞ˹ÒøÐС¢ÍøÉÏÊÐËÁºÍÐÅ´û»ú¹¹Ö®¼äµÄÅþÁ¬·þÎñ¡£Infotel JSC͸¶´Ë´Î´ó¹æÄ£ºÚ¿Í¹¥»÷Ó°ÏìÁËÆ䲿·ÖÍøÂç×°±¸£¬ÏÖÔÚÕýÔÚÆð¾¢»Ö¸´ÊÜÓ°ÏìµÄϵͳ£¬Íê³ÉÈÕÆÚ½«ÁíÐÐ֪ͨ¡£IODA³Æ·þÎñÓÚUTC 6ÔÂ8ÈÕÉÏÎç11:00×óÓÒÖÐÖ¹¡£ºÚ¿Í»¹Ðû²¼ÁËInfotelϵͳµÄ½Øͼ×÷Ϊ¹¥»÷Ö¤¾Ý£¬°üÀ¨ÍøÂç»ù´¡ÉèʩͼºÍ±»ÈëÇÖµç×ÓÓʼþÕÊ»§¡£


https://www.bleepingcomputer.com/news/security/ukrainian-hackers-take-down-service-provider-for-russian-banks/


3¡¢Ó¢¹úÂü³¹Ë¹ÌØ´óѧÔâµ½¹¥»÷Ô±¹¤ºÍѧÉúÊý¾Ý¿ÉÄÜй¶


ýÌå6ÔÂ9ÈÕ±¨µÀ£¬Ó¢¹úÂü³¹Ë¹ÌØ´óѧÔâµ½¹¥»÷£¬Ô±¹¤ºÍѧÉúµÄÊý¾Ý¿ÉÄÜÒѾ­Ð¹Â¶¡£¸ÃУ³ÆËüÔÚ6ÔÂ6ÈÕ·¢Ã÷ÁËÕâÒ»ÎÊÌ⣬²¢Á¬Ã¦Õö¿ªÊӲ졣¾­È·Èϲ¿·ÖϵͳÒѱ»Î´¾­ÊÚȨµÄµÚÈý·½»á¼û£¬Êý¾Ý¿ÉÄÜÒѱ»¸´ÖÆ¡£±ðµÄ£¬Âü³¹Ë¹ÌØ´óѧÌåÏÖ´Ë´ÎÇå¾²ÊÂÎñÓë×î½üµÄMOVEit TransferÊý¾Ýй¶¹¥»÷ºÍZellisÏà¹Ø¹¥»÷Î޹ء£¸Ã´óѧûÓÐÌṩ¹ØÓÚ¹¥»÷µÄ½øÒ»²½ÐÅÏ¢£¬µ«Ñо¿Ö°Ô±´ÓÐÂÎÅȪԴ»ñϤÕâÊÇÒ»ÆðÀÕË÷¹¥»÷¡£


https://securityaffairs.com/147290/data-breach/university-of-manchester-cyber-attack.html


4¡¢Elastic·¢Ã÷Ö÷ÒªÕë¶ÔÔ½ÄÏÆóÒµµÄкóÃÅSPECTRALVIPER 


ElasticÔÚ6ÔÂ9ÈÕ³ÆÆä·¢Ã÷ÁËÒ»¸öÐÂÐͺóÃÅSPECTRALVIPER£¬Ö÷ÒªÓÃÓÚÕë¶ÔÔ½ÄÏÉÏÊй«Ë¾µÄ¹¥»÷Ô˶¯¡£PECTRALVIPERÊÇÒ»¸ö»ìÏýµÄx64ºóÃÅ£¬Ëü¾ßÓÐPE¼ÓÔغÍ×¢Èë¡¢ÎļþÉÏ´«ºÍÏÂÔØ¡¢ÎļþºÍĿ¼¿ØÖÆÒÔ¼°ÁîÅÆÄ£Ä⹦Ч¡£Ñо¿Ö°Ô±½«¸ÃÔ˶¯¹éÒòÓÚÔ½ÄϵĹ¥»÷ÍÅ»ïREF2754¡£×îÐÂѬȾÁ´ÖУ¬Ê¹ÓÃÁËSysInternals ProcDumpÊÊÓóÌÐò¼ÓÔØ°üÀ¨DONUTLOADERµÄδÊðÃûDLLÎļþ£¬´ËºóÕßÓÖ±»ÉèÖÃΪ¼ÓÔØSPECTRALVIPERºÍÆäËü¶ñÒâÈí¼þ£¬ÀýÈçP8LOADER»òPOWERSEAL¡£


https://www.elastic.co/cn/security-labs/elastic-charms-spectralviper


5¡¢Sorgu Paneli¿É¹ûÕæ¼ìË÷Ô¼8500ÍòÍÁ¶úÆäסÃñµÄÐÅÏ¢


6ÔÂ10ÈÕ±¨µÀ£¬8500ÍòÍÁ¶úÆäסÃñµÄÃô¸ÐÐÅϢй¶¡£ÍÁ¶úÆäµÄƽ̨Free Web TurkeyÆعâÁËÒ»¸öÃûΪSorgu PaneliµÄÍøÕ¾£¬¿É²»ÊÜÏÞÖƵػá¼ûСÎÒ˽¼ÒÐÅÏ¢£¬ÀýÈçÉí·ÝÖ¤ºÅÂë¡¢ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂëÉõÖÁÒøÐÐÕË»§ÏêϸÐÅÏ¢£¬ÒÔ»»È¡Ãâ·Ñ»áÔ±×ʸñ¡£¸¶·Ñ»áÔ±¿ÉÒÔ»ñµÃ¸ü¶àÐÅÏ¢£¬ÀýÈçլȯ¡£¸ÃÍøÕ¾ÔÚÓòÃûSorgu.liveÏÂÔËÓª£¬ÏÖÔÚ¹²ÓÐ5195ÃûÓû§£¬²¢ÔÚTelegramºÍDiscordÉÏÌṩÀàËƵķþÎñ¡£¾ÝÔ¤¼Æ£¬Ô¼ÓÐ8500ÍòÍÁ¶úÆ乫ÃñµÄÐÅÏ¢Êܵ½Ó°Ïì¡£


https://medyanews.net/website-leak-exposes-sensitive-data-of-85-million-turkish-residents-report/


6¡¢Check Point¹ûÕæʹÓÃStealth Soldier¹¥»÷±±·ÇµÄÔ˶¯


6ÔÂ8ÈÕ£¬Check Point¹ûÕæÁËÒ»ÆðÕë¶ÔÐÔºÜÇ¿µÄÌع¤¹¥»÷£¬Ê¹ÓÃÁËеĶ¨ÖÆÄ £¿é»¯ºóÃÅStealth Soldier¡£¸Ã¶ñÒâÈí¼þÖ÷ÒªÔËÐмàÊÓ¹¦Ð§£¬ÀýÈçÎļþй¶¡¢ÆÁÄ»ºÍÂó¿Ë·ç¼ÖÆ¡¢¼üÅ̼ͼºÍÇÔÈ¡ä¯ÀÀÆ÷ÐÅÏ¢¡£Stealth SoldierÓëThe Eye on the NileµÄ»ù´¡ÉèÊ©Óв¿·ÖÖصþ£¬¹¥»÷ÕßʹÓÃÁËαװ³ÉÀû±ÈÑÇÍâ½»²¿ÍøÕ¾µÄC2Óò¡£Ñо¿Ö°Ô±³Æ£¬Ñ¬È¾Á´´ÓºÜÖØ´ó£¬Éæ¼°´ÓC&C·þÎñÆ÷ÏÂÔصÄÁù¸öÎļþ£¬°üÀ¨Loader( MSDataV5.16945.exe)¡¢Watchdog(MSCheck.exe)ºÍPayload(MShc.txt)µÈ¡£


https://research.checkpoint.com/2023/stealth-soldier-backdoor-used-in-targeted-espionage-attacks-in-north-africa/