¶íÂÞ˹UNC5812Íþв×éÖ¯Ãé×¼ÎÚ¾üбø

Ðû²¼Ê±¼ä 2024-10-30

1. ¶íÂÞ˹UNC5812Íþв×éÖ¯Ãé×¼ÎÚ¾üбø


10ÔÂ28ÈÕ£¬¶íÂÞ˹Íþв×éÖ¯¡°UNC5812¡±±»½ÒÆÆ¿ªÕ¹»ìÏýÌع¤/Ó°ÏìÔ˶¯£¬Õë¶ÔÎÚ¿ËÀ¼¾ü¶ÓбøʹÓÃWindowsºÍAndroid¶ñÒâÈí¼þ¡£¸Ã×é֯ͨ¹ýð³ä¡°Ãñ·À¡±½ÇÉ«ÉèÁ¢ÍøÕ¾ºÍTelegramƵµÀ£¬Èö²¥ÃûΪ¡°Sunspinner¡±µÄÐéαÕÐļ¹æ±ÜÓ¦ÓóÌÐò£¬ÒÔÊý¾ÝÇÔÈ¡ºÍʵʱ¼àÊÓΪĿµÄ¡£¹È¸èÒÑʵÑé±£»¤²½·¥£¬µ«´Ë´ÎÐж¯ÏÔʾÁ˶íÂÞ˹ÔÚÍøÂçÕ½ÁìÓòµÄÒ»Á¬Ê¹ÓúÍÆÕ±éÄÜÁ¦¡£UNC5812²»Ã°³äÕþ¸®»ú¹¹£¬²¢½ÒÏþ×èµ²ÎÚ¿ËÀ¼ÕÐļºÍ·¢¶¯Ðж¯µÄÑÔÂÛ£¬Ö¼ÔÚ¼¤ÆðÃñÖڵIJ»ÐÅÍкͶԿ¹ÇéÐ÷¡£¸ÃÐéαӦÓóÌÐòÌṩWindowsºÍAndroidÏÂÔØ£¬»®·Ö×°ÖöñÒâÈí¼þ¼ÓÔØÆ÷Pronsis LoaderºÍÐÅÏ¢ÇÔÈ¡³ÌÐòPureStealer£¬ÒÔ¼°ÉÌÒµºóÃÅCraxsRAT¡£ÎªÁËÖ´ÐжñÒâÔ˶¯£¬¸ÃÓ¦ÓóÌÐòÓÕÆ­Óû§½ûÓÃAndroid·´¶ñÒâÈí¼þ¹¤¾ß²¢ÊÚÓèΣÏÕȨÏÞ¡£GoogleÒѸüÐÂGoogle Play±£»¤¹¦Ð§ºÍChromeµÄ¡°Çå¾²ä¯ÀÀ¡±¹¦Ð§£¬ÒÔ¼ì²âºÍ×èÖ¹Ïà¹Ø¶ñÒâÈí¼þ¡£https://www.bleepingcomputer.com/news/security/russia-targets-ukrainian-conscripts-with-windows-android-malware/


2. ¶íÂÞ˹Midnight BlizzardºÚ¿Í×éÖ¯ÌᳫÐÂÐÍÐÅÏ¢ÇÔÈ¡Ô˶¯


10ÔÂ30ÈÕ£¬¶íÂÞ˹ºÚ¿Í×éÖ¯¡°ÎçÒ¹±©Ñ©¡±£¨Midnight Blizzard£©½üÆÚÕë¶ÔÕþ¸®ÊÂÇéÖ°Ô±ÌᳫÐÂÐÍÐÅÏ¢ÇÔÈ¡Ô˶¯£¬Ê¹ÓÃÓã²æʽÍøÂç´¹ÂÚµç×ÓÓʼþ·¢ËÍÔ¶³Ì×ÀÃæЭÒ飨RDP£©ÉèÖÃÎļþ£¬Ê¹Êܺ¦Õß×°±¸ÔâÊÜÍêÈ«»á¼ûȨÏ޵Ĺ¥»÷¡£Î¢ÈíÍþвÇ鱨ÍŶÓ×·×Ùµ½¸ÃÔ˶¯×Ô10ÔÂ22ÈÕÆð£¬ÒÑÏòÈ«Çò°üÀ¨Ó¢¹ú¡¢Å·ÖÞ¡¢°Ä´óÀûÑǺÍÈÕ±¾µÈÊýÊ®¸ö¹ú¼Ò/µØÇøµÄÕþ¸®¡¢Ñ§Êõ½ç¡¢¹ú·À¡¢·ÇÕþ¸®×éÖ¯µÈ²¿·Ö·¢ËÍÊýǧ·â´ËÀàÓʼþ¡£ÕâЩÓʼþÖаüÀ¨Ãô¸ÐÉèÖ㬿ɵ¼Ö´ó×ÚÐÅϢй¶£¬ÉõÖÁÇå¾²ÃÜÔ¿ºÍÏúÊÛµã×°±¸Ò²¿ÉÄÜÊܵ½Ó°Ïì¡£ºÚ¿Í»¹Í¨¹ýð³ä΢ÈíÔ±¹¤µÈ·½·¨ÓÕÆ­Êܺ¦Õß·­¿ªÓʼþ¡£´Ë´ÎÔ˶¯ÓÈΪÒýÈËעĿ£¬ÓÉÓÚʹÓÃRDPÉèÖÃÎļþÊÇMidnight BlizzardÕ½ÊõµÄÐÂÇ°½ø¡£ÑÇÂíÑ·ºÍÎÚ¿ËÀ¼Õþ¸®ÅÌËã»úÓ¦¼±ÏìӦС×éÒ²·¢Ã÷ÁËÀàËÆÔ˶¯£¬ÆäÖÐÑÇÂíÑ·Ö¸³ö¶íÂÞ˹Íâ¹úÇ鱨¾Ö£¨SVR£©ÕýÕë¶ÔÕþ¸®»ú¹¹¡¢¹«Ë¾ºÍ¾ü¶ÓÌᳫÍøÂç´¹ÂÚÔ˶¯£¬Ö¼ÔÚÇÔÈ¡¶íÂÞ˹µÐÊÖµÄƾ֤¡£


https://therecord.media/russia-midnight-blizzard-hackers-target-government-sector


3. ´ó¹æÄ£PSAUXÀÕË÷Èí¼þ¹¥»÷Ãé×¼22,000¸öCyberPanelʵÀý


10ÔÂ29ÈÕ£¬Áè¼Ý22,000¸öCyberPanelʵÀýÒò±£´æÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î¶ø̻¶ÓÚΣº¦Ö®ÖУ¬ÕâЩʵÀýÔÚPSAUXÀÕË÷Èí¼þ¹¥»÷ÖÐÏÕЩËùÓÐÏÝÂä¡£Çå¾²Ñо¿Ô±DreyAnd·¢Ã÷CyberPanel 2.3.6£¨¼°¿ÉÄÜÊÜÓ°ÏìµÄ2.3.7°æ±¾£©±£´æÉí·ÝÑé֤ȱÏÝ¡¢ÏÂÁî×¢Èë¼°Çå¾²¹ýÂËÆ÷ÈƹýµÈÇå¾²ÎÊÌ⣬¿Éµ¼ÖÂδ¾­ÊÚȨµÄÔ¶³Ì¸ù»á¼û¡£ËûÒÑÓÚ2024Äê10ÔÂ23ÈÕÏòCyberPanel¿ª·¢Ö°Ô±Åû¶Îó²î²¢ÔÚGitHub ÉÏÌá½»ÁËÕë¶ÔÉí·ÝÑéÖ¤ÎÊÌâµÄÐÞ¸´³ÌÐò¡£Óë´Ëͬʱ£¬ÍþвÇ鱨ËÑË÷ÒýÇæLeakIX±¨¸æ³Æ£¬´ó×Ú±£´æÎó²îµÄCyberPanelʵÀý±»PSAUXÀÕË÷Èí¼þ¹¥»÷£¬µ¼Ö½üÒ»°ëλÓÚÃÀ¹úµÄʵÀý£¨Ô¼10,170¸ö£©¼°ÖÎÀíµÄÁè¼Ý152,000¸öÓòºÍÊý¾Ý¿âÊܵ½Íþв¡£Ò»Ò¹Ö®¼ä£¬ÊÜÓ°ÏìµÄʵÀýÊýÄ¿´ó·ùϽµ£¬½öÊ£Ô¼400¸ö¿É»á¼û¡£PSAUXÀÕË÷Èí¼þͨ¹ýÎó²îºÍ¹ýʧÉèÖù¥»÷̻¶µÄWeb·þÎñÆ÷£¬¼ÓÃÜ·þÎñÆ÷Îļþ²¢ÁôÏÂÀÕË÷ÐÅ¡£ÏÖÔÚ£¬LeakIXÒÑÐû²¼½âÃÜÆ÷ÓÃÓÚ½âÃÜÔڴ˴ι¥»÷ÖмÓÃܵÄÎļþ£¬µ«Ê¹ÓÃÇ°Ð豸·ÝÊý¾Ý²¢²âÊÔÆäÓÐÓÃÐÔ£¬ÒÔ·ÀÒò¹ýʧÃÜÔ¿µ¼ÖÂÊý¾ÝË𻵡£


https://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/


4. ¼ÓÄôóË°Îñ¾ÖÊý¾Ýй¶Òý·¢ÐÅÍÐΣ»ú£¬Òþ˽Υ¹æÐÐΪ¼¤Ôö


10ÔÂ29ÈÕ£¬ÔÚ½ñÄêµÄÄÉË°¼¾½Úá¯ÁëÆÚ£¬¼ÓÄô󱬷¢ÁËÒ»ÆðÑÏÖصÄË°ÎñÊý¾Ýй¶ÊÂÎñ¡£ºÚ¿ÍÇÔÈ¡ÁËH&R Block CanadaµÄÉñÃØÊý¾Ý£¬²¢Ê¹ÓÃÕâЩÐÅϢδ¾­ÊÚȨ»á¼ûÁËÊý°ÙÃû¼ÓÄôóÈ˵ÄСÎÒ˽¼Ò¼ÓÄôóË°Îñ¾Ö£¨CRA£©ÕË»§¡£ºÚ¿Í¸ü¸ÄÁËÖ±½Ó´æ¿îÐÅÏ¢£¬Ìá½»ÁËÐéαÉ걨±í£¬²¢´Ó¹«¿îÖÐÆ­È¡ÁËÁè¼Ý600ÍòÃÀÔªµÄÐéαÍË¿î¡£´Ë´ÎÊÂÎñ´Ùʹ¼ÓÄôóË°Îñ¾ÖÔöÇ¿ÁËýÌåÇþµÀ×¼±¸£¬ÒÔÓ¦¶Ô¹«ÖÚ¶Ô´Ë´ÎÊý¾Ýй¶¼°¸Ã»ú¹¹ÎªºÎÏòÕ©Æ­ÕßÖ§¸¶Êý°ÙÍòÃÀÔªµÄÎÊÌ⡣Ȼ¶ø£¬¹«ÖÚ²¢Î´»ñϤ´ËÍýÏ룬˰Îñ²¿³¤ºÍ¼ÓÄôóË°Îñ¾ÖÒ²¾ùδ»ØÓ¦Ïà¹ØÎÊÌâ¡£H&R Block¹«Ë¾ÌåÏÖ£¬Ã»ÓÐÖ¤¾ÝÅú×¢´Ë´ÎÈëÇÖÊÂÎñÔ´×Ըù«Ë¾£¬ÆäÊý¾Ý¡¢ÏµÍ³¡¢Èí¼þºÍÇå¾²¾ùδÊܵ½Ë𺦡£¼ÓÄôóË°Îñ¾ÖδÄÜÈ·¶¨ºÚ¿ÍµÄÉí·Ý£¬µ«É¨³ýÁË×ÔÉíϵͳ±»ÈëÇÖ»òÄÚ²¿Ö°Ô±¼ÓÈëµÄ¿ÉÄÜÐÔ¡£±ðµÄ£¬¼ÓÄôóË°Îñ¾Ö»¹ÃæÁÙÆäËûÑÏÖØÎÊÌ⣬°üÀ¨Òþ˽й¶ÊÂÎñÊýÄ¿¼¤Ôö£¬ÒÔ¼°¹«ÖÚ¶Ô±£»¤ÄÉË°ÈË¿î×ÓºÍСÎÒ˽¼ÒÐÅÏ¢µÄ»ú¹¹Ê§È¥ÐÅÍеÄΣº¦¡£


https://www.cbc.ca/news/canada/canada-revenue-agency-taxpayer-accounts-hacked-1.7363440


5. й¤¾ß¿ÉÈƹýGoogle ChromeµÄÐÂCookie¼ÓÃÜϵͳ


10ÔÂ28ÈÕ£¬ÍøÂçÇå¾²Ñо¿Ô±ÑÇÀúɽ´ó-¹þ¸ùÄÉÐû²¼ÁËÒ»¿îÃûΪ¡°Chrome-App-Bound-Encryption-Decryption¡±µÄ¹¤¾ß£¬¸Ã¹¤¾ßÄÜÈƹý¹È¸èÐÂÍƳöµÄÓ¦ÓóÌÐò°ó¶¨¼ÓÃÜÊÖÒÕ£¬´ÓChromeä¯ÀÀÆ÷ÖÐÌáÈ¡ÒÑÉúÑĵÄƾ֤£¬ÔöÌíÁËChromeÓû§µÄΣº¦¡£¹È¸èÔÚ7ÔÂÍƳöµÄÕâÒ»¼ÓÃÜÊÖÒÕ£¬Ö¼ÔÚͨ¹ýWindows·þÎñÒÔϵͳȨÏÞ¶Ôcookies¾ÙÐмÓÃÜ£¬±£»¤Ãô¸ÐÐÅÏ¢ÃâÊܶñÒâÈí¼þ¹¥»÷¡£È»¶ø£¬9ÔÂʱÒÑÓжà¸öÐÅÏ¢ÇÔÈ¡ÕßÕÒµ½ÈƹýÒªÁì¡£×òÌ죬¹þ¸ùÄÉÔÚGitHubÉϹûÕæÁËÕâ¿îÅÔ·¹¤¾ß¼°ÆäÔ´´úÂë¡£¸Ã¹¤¾ßʹÓÃChromeä¯ÀÀÆ÷ÄÚ²¿µÄIElevator·þÎñ£¬½âÃÜ´æ´¢ÔÚÍâµØ״̬ÎļþÖеÄApp-Bound¼ÓÃÜÃÜÔ¿¡£ËäȻʹÓøù¤¾ßÐèÒªÖÎÀíԱȨÏÞ£¬µ«Ðí¶àWindowsÓû§¶¼Ê¹ÓþßÓÐÖÎÀíȨÏÞµÄÕË»§£¬Òò´ËÕâͨ³£ÈÝÒ×ʵÏÖ¡£¾Ý¶ñÒâÈí¼þÆÊÎöʦ³Æ£¬¹þ¸ùÄɵÄÒªÁìÓëÔçÆÚÐÅÏ¢ÇÔÈ¡Õß½ÓÄɵÄÈƹýÒªÁìÀàËÆ£¬ËäÈ»¹È¸èÒ»Ö±ÔÚÆð¾¢Ë¢Ð·ÀÓù²½·¥£¬µ«Ê¹ÓÃй¤¾ßÈÔÄÜÈÝÒ×ÇÔÈ¡Chromeä¯ÀÀÆ÷ÖеÄÓû§ÉñÃØ¡£¹È¸èÌåÏÖ£¬ËäÈ»Õâ¶Î´úÂëÐèÒªÖÎÀíԱȨÏÞ£¬µ«¶ñÒâÈí¼þµÄÊýÄ¿ÈÔÔÚÔöÌí£¬ËüÃÇͨ¹ý²î±ð·½·¨Ëø¶¨Óû§¡£


https://www.bleepingcomputer.com/news/security/new-tool-bypasses-google-chromes-new-cookie-encryption-system/


6. Discord Bots±»¶ñÒâʹÓãºPySilon RATÍþвÍøÂçÇå¾²


10ÔÂ29ÈÕ£¬ÍøÂçÇå¾²¹«Ë¾AhnLabÔÚ×î½üµÄÒ»·Ý±¨¸æÖÐÖ¸³ö£¬Ô­±¾ÓÃÓÚÁ¼ÐÔ·þÎñÆ÷ÖÎÀíµÄDiscord BotsÏÖÔÚ±»ÓÃÓÚ°²ÅÅÔ¶³Ì»á¼ûľÂí£¨RAT£©£¬ÆäÖÐ×îÐµİ¸ÀýÉæ¼°ÃûΪPySilonµÄ¶ñÒâÈí¼þ±äÖÖ¡£PySilonÊÇÒ»ÖÖʹÓÃDiscord Botƽ̨Éø͸ϵͳ²¢»ñÈ¡Ãô¸ÐÊý¾ÝµÄRAT£¬ËüŤÇúÁËDiscord BotÔ­±¾ÌṩµÄ·þÎñÆ÷ÖÎÀí¡¢×Ô¶¯ÐÂÎÅÏìÓ¦µÈ¹¦Ð§£¬ÔÚDiscord»ù´¡ÉèÊ©ÄÚ¶ñÒâÔËÐС£Õâ¿îʹÓÃPython¿ª·¢µÄRAT¶ñÒâÈí¼þ¿ÉÔÚGitHubÉÏ»á¼û£¬ÍþвÐÐΪÕß¿ÉÒÔÇáËɹ¹½¨×Ô½ç˵°æ±¾£¬²¢Í¨¹ýµ÷½â·þÎñÆ÷IDºÍ»úеÈËÁîÅƵÈÏêϸÐÅÏ¢£¬Ê¹Óù¹½¨Æ÷³ÌÐò½¨Éè¸öÐÔ»¯µÄ¶ñÒâÈí¼þ°æ±¾¡£Ö´Ðкó£¬PySilon»áÔÚ¹¥»÷ÕߵķþÎñÆ÷ÄÚ½¨ÉèÒ»¸öÐÂͨµÀ£¬½«³õʼϵͳÐÅϢת·¢¸ø²Ù×÷Ô±£¬´Ó¶øʵÏÖºÚ¿ÍÓëÊÜѬȾװ±¸µÄ³¤ÆÚͨѶÁ´½Ó¡£PySilon¾ßÓÐÆÕ±éµÄÏÂÁî¹æÄ££¬¿ÉÓÃÓÚÌع¤¡¢Êý¾ÝÇÔÈ¡ºÍÆÆËðµÈÔ˶¯£¬°üÀ¨ÍøÂçСÎÒ˽¼ÒºÍϵͳÐÅÏ¢¡¢ÆÁÄ»ºÍÒôƵ¼Í¼¡¢¼üÅ̼ͼÒÔ¼°Îļþ¼Ð¼ÓÃܵÈ¡£AhnLabÇ¿µ÷£¬¼ì²â´ËÀàÍþв¾ßÓÐÌôÕ½ÐÔ£¬ÓÉÓÚÊý¾ÝÊÇʹÓÃΪÕý³£»úеÈ˹¦Ð§ÊµÑéµÄ¹Ù·½Discord·þÎñÆ÷´«ÊäµÄ£¬ÑÚÊÎÁËÆä¶ñÒâÐÔ×Ó¡£


https://securityonline.info/pysilon-a-discord-bot-turned-malicious-rat-for-data-theft-and-surveillance/