APT40ÀûÓÃScanBox¿úËÅ¿ò¼Ü¹¥»÷°Ä´óÀûÑÇÈ·µ±¾Ö»ú¹¹

°ä²¼¹¦·ò 2022-09-01
1¡¢APT40ÀûÓÃScanBox¿úËÅ¿ò¼Ü¹¥»÷°Ä´óÀûÑÇÈ·µ±¾Ö»ú¹¹

      

ProofpointÔÚ8ÔÂ30ÈÕÅû¶ÁËAPT40½üÆÚµÄ¹¥»÷»î¶¯¡£¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷ÖØÒªÕë¶Ô°Ä´óÀûÑÇ´¦ËùºÍÁª¹úµ±¾Ö»ú¹¹¼°Ã½Ìå»ú¹¹£¬£¬£¬£¬£¬£¬£¬£¬ºÍΪÄϺ£·çÁ¦ÎÐÂÖ»úÌá¹©ÊØ»¤·þÎñµÄÈ«Çò³Á¹¤ÒµÔì×÷ÉÌ¡£¡£¡£¡£ ¡£¡£¡£¡£2022Äê4ÔÂÖÁ6ÔÂÆÚ¼ä£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¼ÙÒâ°Ä´óÀûÑdz¿±¨µÄÔ±¹¤£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ý´¹µö»î¶¯·Ö·¢ScanBox·ì϶ÀûÓÿò¼Ü¡£¡£¡£¡£ ¡£¡£¡£¡£Æ¾¾Ý×îÐÂÖ¤¾Ý£¬£¬£¬£¬£¬£¬£¬£¬ProofpointµÃ³ö½áÂÛ£¬£¬£¬£¬£¬£¬£¬£¬2022ÄêµÄ»î¶¯ÊÇAPT40×Ô2021Äê3ÔÂÒÔÀ´½øÐеÄͳһµý±¨ÍøÂ繤×÷µÄµÚÈý½×¶Î£¬£¬£¬£¬£¬£¬£¬£¬Æäʱ¹¥»÷Õß¼ÙÒâÐÂÎÅýÌ壬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýRTFÄ£°å×¢Èë¼ÓÔØMeterpreter¡£¡£¡£¡£ ¡£¡£¡£¡£


https://www.proofpoint.com/us/blog/threat-insight/chasing-currents-espionage-south-china-sea   


2¡¢Òâ´óÀûʯÓ͹«Ë¾Eni³ÆÆäÄÚ²¿ÍøÂçÔ⵽δ¾­ÊÚȨµÄ½Ó¼û

      

¾Ý8ÔÂ31ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬Òâ´óÀûʯÓ͹«Ë¾Eni³ÆÆäÄÚ²¿±£»£»£»£»£»£»¤ÏµÍ³¼ì²âµ½Õë¶Ô¹«Ë¾ÍøÂçµÄδ¾­ÊÚȨµÄ½Ó¼û¡£¡£¡£¡£ ¡£¡£¡£¡£Ä¿Ç°Ã»Óй¥»÷µÄ¼¼Êõϸ½Ú£¬£¬£¬£¬£¬£¬£¬£¬ÎÞ·¨È·¶¨¹¥»÷ÕßÉí·Ý¡¢ÈôºÎÈëÇÖµÄÒÔ¼°ËûÃǵ͝»ú¡£¡£¡£¡£ ¡£¡£¡£¡£ÖªÁµÈËÊ¿³Æ£¬£¬£¬£¬£¬£¬£¬£¬EniÈçͬÔâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£¡£Òâ´óÀûÄÜÔ´²¿ÃŽüÆÚËÆºõÔâµ½Á˹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÉÏÖÜÄ©£¬£¬£¬£¬£¬£¬£¬£¬¾­ÓªÒâ´óÀûµçÁ¦Êг¡È·µ±¾Ö»ú¹¹Gestore dei Servizi Energetici SpAÔâµ½¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£¡£GSEµÄ»ù´¡ÉèÊ©Êܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬£¬ÍøÕ¾ÈÔ´¦ÓÚÖжÏ״̬¡£¡£¡£¡£ ¡£¡£¡£¡£


https://securityaffairs.co/wordpress/135116/hacking/eni-suffered-cyberattack.html


3¡¢SecuronixÅû¶Ð¶ñÒâÈí¼þ»î¶¯GO#WEBBFUSCATORµÄϸ½Ú

      

¾Ý8ÔÂ30ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬Securonix·¢ÏÖһ·»ùÓÚGolangµÄ³ÖÐø¹¥»÷»î¶¯GO#WEBBFUSCATOR¡£¡£¡£¡£ ¡£¡£¡£¡£Ï°È¾Ê¼ÓÚÒ»·â´øÓжñÒâÎĵµGeos-Rates.docxµÄ´¹µöÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬Ëü»áÏÂÔØÄ£°åÎļþ¡£¡£¡£¡£ ¡£¡£¡£¡£¸ÃÎļþÔ̺¬Ò»¸ö¾­¹ý»ìºÏµÄVBSºê£¬£¬£¬£¬£¬£¬£¬£¬ÆôÓúêºó£¬£¬£¬£¬£¬£¬£¬£¬´úÂë»á´ÓÔ¶³Ì×ÊÔ´ÏÂÔØJPGͼÏñ£¬£¬£¬£¬£¬£¬£¬£¬¶øºóʹÓÃcertutil.exe½«Æä½âÂëΪ¿ÉÖ´ÐÐÎļþmsdllupdate.exe²¢Æô¶¯Ëü¡£¡£¡£¡£ ¡£¡£¡£¡£ÔÚͼÏñ²é¿´Æ÷ÖУ¬£¬£¬£¬£¬£¬£¬£¬.JPGÎļþÔòÏÔʾÁËÓÉNASAÓÚ2022Äê7Ô°䲼µÄÐÇϵÍÅSMACS 0723¡£¡£¡£¡£ ¡£¡£¡£¡£¶þ½øÔìmsdllupdate.exeѡȡÁ˶àÖÖ»ìºÏ¼¼ÊõÀ´ÈƹýAVʹ·ÖÎö±äµÃÄÑÌâ¡£¡£¡£¡£ ¡£¡£¡£¡£


https://www.securonix.com/blog/golang-attack-campaign-gowebbfuscator-leverages-office-macros-and-james-webb-images-to-infect-systems/


4¡¢McAfee·¢ÏÖ5¸ö¶ñÒâChromeÀ©´óÒѱ»×°Öó¬¹ý140Íò´Î

      

McAfeeÔÚ8ÔÂ29ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁË5¸öÄܹ»ÇÔÈ¡Óû§ä¯ÀÀ»î¶¯µÄGoogle ChromeÀ©´ó·¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬×ÜÏÂÔØÁ¿Òѳ¬¹ý140Íò´Î¡£¡£¡£¡£ ¡£¡£¡£¡£ÕâЩ¶ñÒâÀ©´óµÄÖ÷ÕÅÊÇ¼à¿ØÓû§½Ó¼ûµçÉÌÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬²¢Åú¸Ä½Ó¼ûÕßµÄcookie£¬£¬£¬£¬£¬£¬£¬£¬Ê¹Æä¿´ÆðÀ´ÊÇͨ¹ýÍÆ¼öÁ´½ÓÀ´µÄ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÑù£¬£¬£¬£¬£¬£¬£¬£¬À©´ó·¨Ê½µÄ¿ª·¢ÈËÔ±Äܹ»ÔÚÕâЩ²É°ì»î¶¯ÖлñµÃÁªÓª·Ñ¡£¡£¡£¡£ ¡£¡£¡£¡£¶ñÒâÀ©´ó±ðÀëΪNetflix Party¡¢Netflix Party 2¡¢Full Page Screenshot Capture¡¢FlipShopeºÍAutoBuy Flash Sales£¬£¬£¬£¬£¬£¬£¬£¬¹ÌÈ»ËüÃDz»»áÖ±½ÓÓ°ÏìÓû§£¬£¬£¬£¬£¬£¬£¬£¬µ«»á´øÀ´ÑϳÁµÄÒþÖÔ·çÏÕ¡£¡£¡£¡£ ¡£¡£¡£¡£


https://www.mcafee.com/blogs/other-blogs/mcafee-labs/malicious-cookie-stuffing-chrome-extensions-with-1-4-million-users/


5¡¢ÎÚ¿ËÀ¼¹ú¶È¾¯Ô±¹Ø¹ØÄ³ºÚ¿ÍÍÅ»ïʹÓõĺô½ÐÖÐÐÄÍøÂç

      

ýÌå8ÔÂ30Èճƣ¬£¬£¬£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼¹ú¶È¾¯Ô±(NPU)¹Ø¹ØÁËÒ»¸öºÚ¿ÍÍÅ»ïʹÓõĺô½ÐÖÐÐÄÍøÂç¡£¡£¡£¡£ ¡£¡£¡£¡£¾Ý³Æ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ï»¹ÉæÏÓÚ¿Æ­¶Ô¼ÓÃÜÇ®±Ò¡¢Ö¤È¯¡¢»Æ½ðºÍʯÓÍͶ×ʸÐÐËÖµÄÎÚ¿ËÀ¼ºÍÅ·Ã˹ú¶ÈµÄ¹«Ãñ¡£¡£¡£¡£ ¡£¡£¡£¡£ÔÚÚ¿Æ­»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËÈí¼þºÍ¸ß¿Æ¼¼É豸£¬£¬£¬£¬£¬£¬£¬£¬¼ÙÒâ¹úÓÐÒøÐлú¹¹µÄÔ±¹¤£¬£¬£¬£¬£¬£¬£¬£¬Ú²Æ­Ö¸±êµÄÒøÐп¨»úÃÜÊý¾Ý¡£¡£¡£¡£ ¡£¡£¡£¡£¶øºó£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÓÕÆ­Ö¸±ê½«×ʽð×ªÒÆµ½¹¥»÷ÕßµÄÕË»§ºóÖжÏËùÓÐͨѶ¡£¡£¡£¡£ ¡£¡£¡£¡£·¨ÂÉÈËÔ±ËѲéÁËÓëÕâ´Î»î¶¯ÓйصĶà¸öºô½ÐÖÐÐIJ¢³ä¹«ÁËÍÆËã»ú¡¢ÊÖ»úºÍÊý¾Ý¼Í¼£¬£¬£¬£¬£¬£¬£¬£¬ÓйØÏÓÒÉÈ˽«Ãæ¶Ô×î¸ß12ÄêµÄ½ûïÀ¡£¡£¡£¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ukraine-takes-down-cybercrime-group-hitting-crypto-fraud-victims/


6¡¢Cisco°ä²¼3¸ö·Ö·¢¶àÖÖ¶ñÒâÈí¼þµÄ»î¶¯µÄ·ÖÎö»ã±¨

      

8ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Cisco Talos°ä²¼»ã±¨³Æ¹Û²ìµ½2022Äê3ÔÂÖÁ6ÔÂÆÚ¼äµÄ3¸ö¶ÀÁ¢µ«ÓйصĹ¥»÷»î¶¯¡£¡£¡£¡£ ¡£¡£¡£¡£ÕâЩ»î¶¯·Ö·¢Á˶à¸ö¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ModernLoader bot¡¢ÐÅÏ¢ÇÔÈ¡·¨Ê½RedLineºÍÍÚ¿ó¶ñÒâÈí¼þ¡£¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷ÕßʹÓÃPowerShell¡¢.NET·¨Ê½¼¯ÒÔ¼°HTAºÍVBSÎļþÔÚÖ¸±êÖд«²¼£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕ×°ÖÃÆäËü¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÈçSystemBCľÂíºÍDCRAT¡£¡£¡£¡£ ¡£¡£¡£¡£×îÖÕµÄpayloadËÆºõÊÇModernLoader£¬£¬£¬£¬£¬£¬£¬£¬Ëü¿Éͨ¹ýÍøÂçϵͳÐÅÏ¢ºÍ×°Öø÷ÀàÄ£¿£¿£¿£¿£¿£¿£¿éÀ´³äÈÎÔ¶³Ì½Ó¼ûľÂí¡£¡£¡£¡£ ¡£¡£¡£¡£


https://blog.talosintelligence.com/2022/08/modernloader-delivers-multiple-stealers.html