GREFͨ¹ýľÂí»¯SignalºÍTelegram·Ö·¢BadBazaar

Ðû²¼Ê±¼ä 2023-09-01

1¡¢GREFͨ¹ýľÂí»¯SignalºÍTelegram·Ö·¢BadBazaar


ESETÔÚ8ÔÂ30ÈÕÅû¶ÁËGREFͨ¹ýGoogle PlayºÍGalaxyÊÐËÁµÄľÂí»¯SignalºÍTelegram·Ö·¢BadBazaarµÄÔ˶¯¡£´Ë´ÎÔ˶¯»®·Ö×Ô2020Äê7ÔºÍ2022Äê7ÔÂÒÔÀ´×îÏÈ»îÔ¾£¬Õë¶ÔÎÚ¿ËÀ¼¡¢²¨À¼¡¢ºÉÀ¼¡¢Î÷°àÑÀ¡¢ÆÏÌÑÑÀ¡¢µÂ¹úºÍÃÀ¹úµÈ¡£GREFµÄÁ½¸öÓ¦Óû®·ÖÊÇSignal Plus MessengerºÍFlyGram£¬ËüÃÇÊÇ¿ªÔ´IMÓ¦ÓóÌÐòSignalºÍTelegramµÄľÂí»¯°æ±¾¡£ÆäÖУ¬FlyGram¿ÉÇÔÈ¡ÁªÏµÈËÁÐ±í¡¢Í¨»°¼Í¼¡¢GoogleÕÊ»§ºÍWiFiµÈÊý¾Ý£¬Signal Plus Messenger³ýÁËÇÔÊØÐÅÏ¢»¹¼àÊÓÄ¿µÄµÄSignalͨѶ¡£ÏÖÔÚ£¬Google PlayÒÑɾ³ý¶ñÒâÓ¦Ó㬵«GalaxyÊÐËÁÈÔÈ»±£´æ¡£


https://www.welivesecurity.com/en/eset-research/badbazaar-espionage-tool-targets-android-users-trojanized-signal-telegram-apps/


2¡¢ÃÀ¹úNSCÉèÖùýʧй¶Լ2000¼Ò¹«Ë¾µÄ½üÍò¸öÓÊÏäºÍÃÜÂë


¾ÝýÌå8ÔÂ31ÈÕ±¨µÀ£¬¹ú¼ÒÇ徲ίԱ»á(NSC)й¶ÁËÆä³ÉÔ±µÄ½üÍò¸öÓÊÏäºÍÃÜÂë¡£NSCÊÇÃÀ¹úµÄÒ»¸ö·ÇÓªÀû»ú¹¹£¬ÌṩÊÂÇ鳡ºÏºÍ¼ÝÊ»Çå¾²Åàѵ¡£Ñо¿Ö°Ô±ÔÚ3ÔÂ7ÈÕ·¢Ã÷ÁËNSCÍøÕ¾µÄÒ»¸ö×ÓÓò£¬¹ûÕæÁËÆäWebĿ¼Áбí¡£ÔÚ¿É»á¼ûµÄÎļþÖУ¬Ñо¿Ö°Ô±·¢Ã÷ÁË´æ´¢Óû§ÓʼþºÍÃÜÂëµÄÊý¾Ý¿â±¸·Ý£¬°üÀ¨Ô¼9500¸öÕÊ»§¼°Æäƾ֤¡£Ó°ÏìÁËÔ¼2000¼Ò´óÐ͹«Ë¾ºÍÕþ¸®»ú¹¹£¬Èç¿ÇÅÆ¡¢Ó¢Ìضû¡¢²¨Òô¹«Ë¾¡¢Ë¾·¨²¿ºÍFBIµÈ¡£Ð¹Â¶Æ¾Ö¤¿ÉÄܱ»ÓÃÓÚײ¿â¹¥»÷À´ÈëÇÖÄ¿µÄ¹«Ë¾¡£ÕâЩÊý¾Ý¿É±»¹ûÕæ»á¼ûʱ¼ä³¤´ï5¸öÔ£¬ÏÖÔÚ¸ÃÎÊÌâÒѱ»½â¾ö¡£


https://securityaffairs.com/150138/security/nasa-tesla-doj-verizon-2k-leaks.html


3¡¢Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓÃWindowsÈÝÆ÷¸ôÀë¿ò¼ÜÈƹý¼ì²â


¾Ý8ÔÂ31ÈÕ±¨µÀ£¬Ñо¿Ö°Ô±Daniel AvinoamÑÝʾÁËÔõÑùʹÓÃWindowsÈÝÆ÷¸ôÀë¿ò¼ÜÀ´ÈƹýÖÕ¶ËÇå¾²½â¾ö¼Æ»®¡£Ñо¿Ö°Ô±Ú¹ÊÍ˵£¬Windows OS½«Ã¿¸öÈÝÆ÷µ½Ö÷»úµÄÎļþϵͳÍÑÀ룬×èÖ¹ÁËϵͳÎļþµÄÖظ´¡£Ã¿¸öÈÝÆ÷¶¼Ê¹Óö¯Ì¬ÌìÉúµÄ¾µÏñ£¬¸Ã¾µÏñʹÓÃÖØÐÂÆÊÎöµãÖ¸Ïòԭʼ¾µÏñ¡£Ð§¹ûÊǾµÏñ°üÀ¨"ÓÄÁéÎļþ"£¬ÕâЩÎļþ²»´æ´¢ÏÖʵÊý¾Ý£¬µ«Á´½Óµ½ÎļþϵͳÉϵÄÁíÒ»¸ö¾í¡£È»ºó£¬Ñо¿Ö°Ô±ÊÔͼʹÓÃÕâÖÖÖض¨Ïò»úÖÆÀ´»ìÏýÎļþϵͳ²Ù×÷£¬²¢ÈƹýÇå¾²²úÆ·¡£


https://securityaffairs.com/150111/hacking/windows-container-isolation-framework-abuse.html


4¡¢WPÊý¾ÝǨáã²å¼þÖÐÎó²îCVE-2023-40004¿Éµ¼ÖÂÊý¾Ýй¶


ýÌå8ÔÂ30Èճƣ¬All-in-One WP Migration²å¼þÖеĻá¼û¿ØÖÆÎó²î£¨CVE-2023-40004£©¿Éµ¼ÖÂÊý¾Ýй¶¡£ÕâÊÇÒ»¿îWordPressÍøվǨá㹤¾ß£¬ÓµÓÐ500Íò¸ö»îÔ¾µÄ×°Öá£Patchstack³Æ£¬¸Ã²å¼þÌṩÉÌServMaskµÄÖÖÖָ߼¶À©Õ¹¶¼°üÀ¨ÏàͬµÄÒ×±»¹¥»÷´úÂ룬ÕâЩ´úÂëÔÚinitº¯ÊýÖÐȱ·¦È¨ÏÞºÍËæ»úÊýÑéÖ¤¡£¸ÃÎó²î¿É±»ÓÃÀ´»á¼ûºÍ¿ØÖÆÊÜÓ°ÏìÀ©Õ¹µÄÁîÅÆÉèÖ㬴Ӷø½«ÍøվǨáãÊý¾ÝתÒƵ½×Ô¼ºµÄµÚÈý·½ÔÆ·þÎñÕÊ»§»ò»Ö¸´¶ñÒⱸ·Ý£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÊý¾Ýй¶¡£Ñо¿Ö°Ô±ÔÚ7ÔÂ18ÈÕ·¢Ã÷ÁËÕâ¸öÎó²î£¬¸ÃÎó²îÔÚ7ÔÂ26ÈÕ±»ÐÞ¸´¡£

https://www.bleepingcomputer.com/news/security/wordpress-migration-add-on-flaw-could-lead-to-data-breaches/


5¡¢Trend MicroÐû²¼Earth Estries¹¥»÷Ô˶¯µÄÆÊÎö±¨¸æ


8ÔÂ30ÈÕ£¬Trend MicroÐû²¼Á˹ØÓÚEarth Estries¹¥»÷Ô˶¯µÄÆÊÎö±¨¸æ¡£¸ÃÍÅ»ïÖÁÉÙ×Ô2020Äê¾Í×îÏÈ»îÔ¾£¬ÆäTTPÓëÁíÒ»¸öºÚ¿ÍÍÅ»ïFamousSparrow±£´æһЩÖصþ¡£¹¥»÷Õßͨ³ £»áÔÚÈëÇÖÄ¿µÄµÄÄÚ²¿·þÎñÆ÷ºóÆÆËðÖÎÀíÔ±ÕÊ»§¡£È»ºóºáÏòÒƶ¯²¢×°ÖúóÃźÍÆäËü¹¤¾ß£¬²¢ÍøÂçºÍй¶ÓмÛÖµµÄÊý¾Ý¡£¸ÃÍÅ»ïʹÓöñÒâÈí¼þ°üÀ¨ºóÃÅZingdoor¡¢ÐÅÏ¢ÇÔÈ¡³ÌÐòTrillClientºÍºóÃÅHemiGate¡£±ðµÄ£¬Earth EstriesµÄC&C»ù´¡ÉèÊ©ÒÀÀµÓÚFastly CDN·þÎñ£¬¸Ã·þÎñÔø±»ÓëAPT41Ïà¹ØµÄÍÅ»ïʹÓᣠ


https://www.trendmicro.com/en_us/research/23/h/earth-estries-targets-government-tech-for-cyberespionage.html


6¡¢KasperskyÐû²¼2023ÄêQ2 ITÍþв̬ÊƵÄÆÊÎö±¨¸æ


8ÔÂ30ÈÕ£¬KasperskyÐû²¼2023ÄêµÚ¶þ¼¾¶ÈITÍþв̬ÊƵÄÆÊÎö±¨¸æ¡£±¨¸æ¼òÊöÁËһЩÓÐÕë¶ÔÐԵĹ¥»÷°üÀ¨£¬Í¨¹ý3CX¹©Ó¦Á´¹¥»÷°²ÅÅGopuramºóÃÅ¡¢LazarusµÄDeathNoteÔ˶¯¡¢TomirisµÄ¹¥»÷Ô˶¯ÒÔ¼°TriangulationÔ˶¯µÈ¡£±¨¸æ»¹ÁгöÁËÆäËü¶ñÒâÈí¼þµÄÍþв£¬ÀýÈçʹÓÃWindows 0dayµÄNokoyawaÀÕË÷¹¥»÷¡¢QBotľÂíѬȾ¼¤Ôö¡¢Minas×ßÏòÖØ´ó֮·¡¢SatacomÍƳö¿ÉÇÔÈ¡¼ÓÃÜÇ®±ÒµÄä¯ÀÀÆ÷À©Õ¹ÒÔ¼°DoubleFingerÓÃÓÚÇÔÈ¡¼ÓÃÜÇ®±ÒµÈ¡£


https://securelist.com/it-threat-evolution-q2-2023/110355/