Symantec³ÆBillbug¹¥»÷ÑÇÖÞµØÇøµÄÊý×ÖÖ¤Êé½ÒÏþ»ú¹¹
Ðû²¼Ê±¼ä 2022-11-17SymantecÔÚ11ÔÂ15ÈÕ³ÆÆä·¢Ã÷Billbug¹¥»÷ÁËÑÇÖ޵Ķà¸öÕþ¸®»ú¹¹£¬£¬£¬ÆäÖаüÀ¨Ò»¸öÊý×ÖÖ¤Êé½ÒÏþ»ú¹¹¡£¡£¡£¸ÃÍÅ»ï×Ô2009ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬Symantec 2019ÄêË꼵ĻÖÐÏêϸÏÈÈÝÁ˸ÃÍÅ»ïÔõÑùʹÓúóÃÅHannotogºÍSagerunexµÄ£¬£¬£¬ÕâЩ¹¤¾ßÔÚ×î½üµÄ»î¶¯ÖÐÒ²ÓзºÆð¡£¡£¡£´Ë´Î»î¶¯ÖÁÉÙ´Ó3Ô¾ÍÒÑ×îÏÈ£¬£¬£¬Óм£ÏóÅú×¢¹¥»÷ÕßÕýÔÚʹÓÃÃæÏò¹«ÖÚµÄÓ¦ÓóÌÐòÀ´»ñµÃ¶ÔÄ¿µÄÍøÂçµÄ³õʼ»á¼ûȨÏÞ¡£¡£¡£Óë֮ǰµÄ»î¶¯Ò»Ñù£¬£¬£¬¹¥»÷ÕßҲʹÓÃÁ˶àÖÖÁ½Óù¤¾ß¼°×Ô½ç˵¶ñÒâÈí¼þ£¬£¬£¬ÈçAdFind¡¢Directory¡¢Winmail¡¢WinRAR¡¢PingºÍTracertµÈ¡£¡£¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments-cert-authority
2¡¢VaronisÅû¶Zendesk ExploreÖÐSQL×¢ÈëµÈÎó²îµÄϸ½Ú
VaronisÔÚ11ÔÂ15ÈÕÅû¶ÁËZendesk ExploreÖÐÁ½¸öÎó²îµÄϸ½Ú¡£¡£¡£ÆäÖÐÒ»¸öÊÇSQL×¢ÈëÎó²î£¬£¬£¬¸ÃÎó²îÉæ¼°ÆäGraphQL APIÖеÄSQL×¢È룬£¬£¬¿É±»ÓÃÀ´Ð¹Â¶×÷ΪÖÎÀíÔ±´æ´¢ÔÚÊý¾Ý¿âÖеÄËùÓÐÐÅÏ¢£¬£¬£¬°üÀ¨ÓʼþµØµã¡¢¹¤µ¥ÒÔ¼°ÓëʵʱÊðÀíµÄ¶Ô»°µÈ¡£¡£¡£ÁíÒ»¸öÎó²îÊÇÉæ¼°ÓëÅÌÎÊÖ´ÐÐAPIÏà¹ØµÄÂß¼»á¼ûÎÊÌ⣬£¬£¬¸ÃAPI±»ÉèÖÃΪÔËÐÐÅÌÎÊ£¬£¬£¬¶ø²»¼ì²é¾ÙÐÐŲÓõÄÓû§ÊÇ·ñÓÐ×ã¹»µÄȨÏÞÕâÑù×ö¡£¡£¡£ÏÖÔÚ£¬£¬£¬ÕâЩÎó²îÒѱ»ÐÞ¸´¡£¡£¡£
https://securityaffairs.co/wordpress/138579/hacking/zendesk-explore-critical-flaws.html
3¡¢LazarusʹÓúóÃÅDTrack¹¥»÷Å·ÖÞºÍÀ¶¡ÃÀÖÞµÄ×éÖ¯
¾Ý11ÔÂ15ÈÕ±¨µÀ£¬£¬£¬³¯ÏʺڿÍÍÅ»ïLazarusÕýÔÚʹÓÃа汾µÄDTrackºóÃÅÀ´¹¥»÷Å·ÖÞºÍÀ¶¡ÃÀÖÞµÄ×éÖ¯¡£¡£¡£Ä¿µÄÐÐÒµ°üÀ¨Ñо¿ÖÐÐÄ¡¢Õþ²ß»ú¹¹¡¢»¯Ñ§Æ·ÖÆÔìÉÌ¡¢ITЧÀÍÌṩÉÌ¡¢µçÐÅÌṩÉÌ¡¢¹«ÓÃÊÂҵЧÀÍÌṩÉ̺ͽÌÓý¡£¡£¡£ÔÚеĻÖУ¬£¬£¬DTrackͨ³£Ê¹ÓÃÓëÕýµ±ÎļþÏà¹ØµÄÎļþÃû¾ÙÐзַ¢£¬£¬£¬ÈçÒ»¸öÑù±¾ÒÔ¡°NvContainer.exe¡±ÎªÃû·Ö·¢£¬£¬£¬ËüÓëÕýµ±µÄNVIDIAÎļþͬÃû¡£¡£¡£±ðµÄ£¬£¬£¬DTrackÈÔ¼ÌÐøÍ¨¹ýÇÔÈ¡µÄƾ֤ÈëÇÖÍøÂç»òʹÓÃÍøÉÏ̻¶µÄЧÀÍÆ÷À´¾ÙÐзַ¢¡£¡£¡£
https://securelist.com/dtrack-targeting-europe-latin-america/107798/
4¡¢Ñо¿ÍŶӷ¢Ã÷¿ÉÓ°Ï캽ÌìÆ÷ºÍ·É»úµÄ¹¥»÷·½·¨PCspooF
ýÌå11ÔÂ15ÈÕ±¨µÀ£¬£¬£¬Ñо¿ÍŶӷ¢Ã÷ÁËÒ»ÖÖÕë¶Ôʱ¼ä´¥·¢ÒÔÌ«Íø(TTE)µÄÐÂÐ͹¥»÷ÒªÁì¡£¡£¡£TTEÊôÓÚ»ìÏýÒªº¦ÐÔÍøÂçµÄÍøÂçÊÖÒÕÖ®Ò»£¬£¬£¬ÆäÖоßÓвî±ðʱÐòºÍÈÝ´íÒªÇóµÄÁ÷Á¿¹²´æÓÚͳһÎïÀíÍøÂçÖС£¡£¡£¸ÃÊÖÒÕÓÃÓÚÇå¾²»ù´¡ÉèÊ©£¬£¬£¬¿Éµ¼ÖÂΪº½ÌìÆ÷ºÍ·É»úÌṩ¶¯Á¦µÄϵͳ·ºÆð¹ÊÕÏ¡£¡£¡£ÕâÊÇʹÓöñÒâ×°±¸Í¨¹ýÒÔÌ«ÍøµçÀ½«µç´Å×ÌÈÅ(EMI)×¢ÈëTTE½»Á÷»úÀ´ÊµÏֵ쬣¬£¬¿ÉÓÐÓõØÓÕʹ½»Á÷»ú·¢ËÍ¿´ËÆÕæÊµµÄͬ²½ÐÂÎŲ¢ÈÃËüÃDZ»ÆäËûTTE×°±¸½ÓÊÜ¡£¡£¡£×÷Ϊ»º½â²½·¥£¬£¬£¬Ñо¿Ö°Ô±½¨ÒéʹÓùâñîºÏÆ÷»òÀËÓ¿±£»£»£»¤Æ÷À´×èÖ¹µç´Å×ÌÈÅ¡£¡£¡£
https://thehackernews.com/2022/11/pcspoof-new-vulnerability-affects.html
5¡¢ÒÁÀÊÏà¹ØºÚ¿ÍʹÓÃLog4ShellÎó²îÈëÇÖÃÀ¹úÕþ¸®»ú¹¹
11ÔÂ16ÈÕ£¬£¬£¬FBIºÍCISAÁªºÏÐû²¼ÁËÒ»·Ýͨ¸æ£¬£¬£¬³ÆÓëÒÁÀÊÏà¹ØµÄºÚ¿ÍÈëÇÖÁËÒ»¸öÕþ¸®»ú¹¹²¢×°ÖÃÁËXMRig¿ó¹¤¶ñÒâÈí¼þ¡£¡£¡£Í¨¸æ³Æ£¬£¬£¬´Ó2022Äê6ÔÂÖÐÑ®µ½7Ô£¬£¬£¬CISAÔÚÁª°îÃñÓÃÐÐÕþ²¿·Ö(FCEB)×éÖ¯ÖÐÊӲ쵽ÁË¿ÉÒɵÄAPT»î¶¯¡£¡£¡£¹¥»÷ÕßʹÓÃδÐÞ¸´µÄVMware HorizonЧÀÍÆ÷ÖеÄLog4ShellÎó²î£¬£¬£¬×°ÖÃXMRig¿ó¹¤Èí¼þ£¬£¬£¬ºáÏòÒÆ¶¯µ½Óò¿ØÖÆÆ÷(DC)£¬£¬£¬ÇÔȡƾ֤£¬£¬£¬È»ºóÖ²ÈëNgrok·´ÏòÊðÀíÀ´ÔÚ¶à¸ö×°±¸Éϼá³Ö³¤ÆÚÐÔ¡£¡£¡£CISA ºÍ FBI Ðû²¼´ËCSAÌṩºÚ¿ÍµÄTTPºÍIOC£¬£¬£¬ÒÔ×ÊÖú×éÖ¯¼ì²âºÍ·ÀÓùÏà¹ØµÄ¹¥»÷¡£¡£¡£
https://www.cisa.gov/uscert/ncas/alerts/aa22-320a
6¡¢KasperskyÐû²¼¹ØÓÚ2023ÄêAPT¹¥»÷»î¶¯µÄÕ¹Íû±¨¸æ
KasperskyÔÚ11ÔÂ14ÈÕÐû²¼Á˹ØÓÚ2023ÄêAPT¹¥»÷»î¶¯µÄÕ¹Íû±¨¸æ¡£¡£¡£±¨¸æÕ¹ÍûÔÚ2023Ä꣬£¬£¬½«·ºÆð´ó×򵀮ÆËðÐÔÍøÂç¹¥»÷£¬£¬£¬Ó°ÏìÕþ¸®²¿·ÖºÍÒªº¦ÐÐÒµ£»£»£»ÓʼþЧÀÍÆ÷½«³ÉΪÖ÷ҪĿµÄ£¬£¬£¬ºÜ¿ÉÄÜËùÓÐÖ÷Òªµç×ÓÓʼþÈí¼þ¶¼·ºÆð0-day£»£»£»Ò»Ð©¾ßÓÐÓ°ÏìÁ¦µÄ²¡¶¾Ã¿6-7Ä걬·¢Ò»´Î£¬£¬£¬¿ÉÄÜ·ºÆðÏÂÒ»¸öWannaCry£»£»£»APT¹¥»÷ÍŻォĿµÄתÏòÎÀÐÇÊÖÒÕ¡¢Éú²úÉ̺ÍÔËÓªÉÌ£»£»£»¸ü¶àAPT×éÖ¯½«´ÓCobaltStrike×ªÒÆµ½ÆäËüÌæ»»¼Æ»®µÈ¡£¡£¡£
https://securelist.com/advanced-threat-predictions-for-2023/107939/