Aqua SecurityÅû¶¶ñÒâÍÚ¿ó»î¶¯AutomµÄ¼¼Êõϸ½Ú
Ðû²¼Ê±¼ä 2021-12-31Unit42³Æ´ó¶àAPTÍÅ»ïʹÓõÄÓò×¢²áÓÚÊýÄê֮ǰ
Unit42ÔÚ12ÔÂ29ÈÕÐû²¼µÄ×îÐÂÑо¿ÏÔʾ£¬´ó¶àAPTÍÅ»ïʹÓõÄÓò×¢²áÓÚÊýÄê֮ǰ¡£Í¨³££¬ÐÂ×¢²áµÄÓò(NRD) ¸üÓпÉÄÜÊǶñÒâµÄ£¬Òò´ËÄþ¾²½â¾ö·½°¸½«Öصã¼ì²â²¢±êÖ¾ËüÃÇ¡£µ«Unit42Ö¸³ö£¬ÍùÄê×¢²áµÄÓòÊǶñÒâµÄ¿ÉÄÜÐÔ±ÈNRD¸ßÈý±¶¡£ÓÐʱ£¬´ËÀàÓòÃûÔÚÐÝÃßÁ½ÄêÖ®ºóDNSÁ÷Á¿¼¤Ôö165±¶£¬Õâ±íÃ÷¹¥»÷ÕßÒÑÌᳫ¹¥»÷¡£Ñо¿ÈËÔ±ÔÚ9Ô·ݵÄͳ¼Æ½á¹ûÏÔʾ£¬Ô¼3.8%µÄÓòÃûÊǶñÒâµÄ£¬19%ÊÇ¿ÉÒɵģ¬2%µÄ»·¾³²»Äþ¾²¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/strategically-aged-domain-detection/
Aqua SecurityÅû¶¶ñÒâÍÚ¿ó»î¶¯AutomµÄ¼¼Êõϸ½Ú
12ÔÂ29ÈÕ£¬DevSecOpsºÍAqua SecurityÁªºÏÅû¶¶ñÒâÍÚ¿ó»î¶¯AutomµÄ¼¼Êõϸ½Ú¡£¸Ã»î¶¯Ê״ηºÆðÓÚ2019Ä꣬¿ªÊ¼»áÔÚÔËÐÐÔ°æ¾µÏñalpine:latestʱִÐжñÒâÃüÁ²¢ÏÂÔØÃûΪautom.shµÄshell½Å±¾¡£Ö®ºó»áÀûÓøýű¾´´½¨Ò»¸öÐÂÓû§akay²¢½«ÆäȨÏÞÉý¼¶Îªroot£¬Ê¹ÓøÃÓû§ÔÚÄ¿±êÉ豸ÉÏÔËÐÐÈÎÒâÃüÁ²¢ÍÚ¾ò¼ÓÃÜ»õ±Ò¡£³ÂËß»¹Áгö¸Ã»î¶¯µÄMITRE ATT&CKºÍIOC¡£
ÔÎÄÁ´½Ó£º
https://blog.aquasec.com/attack-techniques-autom-cryptomining-campaign
AmnpardazÔÚÒ°·¢ÏÖÕë¶ÔHP iLOµÄÐÂiLOBleed
¾ÝýÌå12ÔÂ28Èճƣ¬ÒÁÀÊÄþ¾²¹«Ë¾AmnpardazÔÚÒ°·¢ÏÖÕë¶Ô»ÝÆÕIntegrated Lights-Out(iLO)µÄжñÒâÈí¼þiLOBleed¡£ÕâÊÇÊ׸öÕë¶ÔiLO¹Ì¼þµÄrootkit£¬Ëü¿ÉÒÔ³¤Ê±¼äµØÒþ²ØÔÚiLOÖжøÇÒ²»»áÔڹ̼þÉý¼¶Öб»É¾³ý¡£iLOBleed×Ô2020ÄêÒÔÀ´Ò»Ö±±»ÓÃÓÚ¹¥»÷£¬¿É¸Ä¶¯¹Ì¼þÄ£¿é²¢É¾³ý±»Ñ¬È¾ÏµÍ³ÖеÄÊý¾Ý¡£Ä¿Ç°¸Ã¶ñÒâÈí¼þ±³ºó¹¥»÷ÕßµÄÉí·ÝÈÔδȷ¶¨£¬µ«AmnpardazÍÆ²âËüÓëij¸öÓɹú¼ÒÖ§³ÖµÄAPT×éÖ¯Óйء£
ÔÎÄÁ´½Ó£º
https://threats.amnpardaz.com/en/2021/12/28/implant-arm-ilobleed-a/
Ô½ÄϹ«Ë¾ONUSÔâÀÕË÷¹¥»÷£¬¾Ü¾øÖ§¸¶500ÍòÃÀÔªÊê½ð
¾ÝýÌå12ÔÂ29ÈÕ±¨µÀ£¬Ô½ÄϵĽðÈڿƼ¼¹«Ë¾ONUSÔâµ½ÀÕË÷¹¥»÷¡£12ÔÂ11ÈÕÖÁ13ÈÕÆÚ¼ä£¬¹¥»÷ÕßÀÖ³ÉÀûÓÃONUS Cyclos·þÎñÆ÷ÉϵÄLog4Shell©¶´£¬²¢Ö²ÈëºóÃÅ¡£CyclosÔÚ13ÈÕÐû²¼Í¨¸æ³ÆÐÞ¸´Æäϵͳ£¬µ«´ËʱΪʱÒÑÍí¡£¹¥»÷ÕßÒÑÇÔÈ¡¸Ã¹«Ë¾½ü200ÍòÌõ¿Í»§¼Ç¼£¬°üÂÞE-KYCÊý¾Ý¡¢¸öÈËÐÅÏ¢ºÍÃÜÂë¡£12ÔÂ25ÈÕ£¬ONUS¾Ü¾øÖ§¸¶500ÍòÃÀÔªµÄÊê½ðÖ®ºó£¬¹¥»÷Õß¿ªÊ¼³öÊÛÇÔÈ¡µÄÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fintech-firm-hit-by-log4j-hack-refuses-to-pay-5-million-ransom/
AvosLockerÔÚÈëÇÖÃÀ¹ú¾¯²ì¾ÖºóÏòÆäÌṩ½âÃÜÆ÷
ýÌå12ÔÂ29Èճƣ¬AvosLockerÒÑÃâ·ÑÏòÃÀ¹ú¾¯²ì¾ÖÌṩ½âÃÜÆ÷¡£¸ÃÍÅ»ïÔÚÉϸöÔÂÒÑÈëÇÖÃÀ¹úµÄ¾¯²ì¾Ö£¬¹¥»÷ÆÚ¼äÇÔÈ¡¸Ã»ú¹¹µÄÊý¾Ý²¢¼ÓÃÜÆäÉ豸¡£AvosLockerÔÚµÃÖª¶Ô·½ÊÇÕþ¸®»ú¹¹ºóÁ¢¿ÌÖÂǸ£¬²¢Ãâ·ÑÌṩ½âÃÜÆ÷¡£¸ÃÍÅ»ïµÄ³ÉÔ±ÌåÏÖ£¬ËûÃÇûÓоßÌåµÄÕë¶ÔÄ¿±êµÄÕþ²ß£¬µ«Í¨³£»áÖÆÖ¹¶ÔÕþ¸®»ú¹¹ºÍÒ½Ôº½øÐй¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ransomware-gang-coughs-up-decryptor-after-realizing-they-hit-the-police/
Òò»ÝÆÕ³¬ËãµÄ±¸·Ýϵͳ´íÎ󣬾©¶¼´óѧ¶ªÊ§77TBÊý¾Ý
¾ÝýÌåÓÚ12ÔÂ30ÈÕ±¨µÀ£¬ÓÉÓÚ»ÝÆÕ¹«Ë¾³¬¼¶¼ÆËã»úµÄ±¸·Ýϵͳ·ºÆð´íÎ󣬵¼ÖÂÈÕ±¾¾©¶¼´óѧԼ77TBµÄ¿ÆÑÐÊý¾Ý±»Îóɾ¡£¸Ãʼþ·¢ÉúÔÚ2021Äê12ÔÂ14ÈÕÖÁ16ÈÕ£¬14¸ö¿ÆÑÐС×éµÄ3400Íò·ÝÎļþ´ÓϵͳºÍ±¸·ÝÎļþÖб»É¾³ý¡£¾ÝϤ£¬±¸·Ý·¨Ê½±¾Ó¦Ê¹ÓÃfindÃüÁîɾ³ýÁè¼Ý10ÌìµÄ¾ÉÈÕÖ¾£¬µ«Æä´íÎóµØÖ´ÐÐÁ˰üÂÞδ½ç˵±äÁ¿µÄfindÃüÁɾ³ýÁË/LARGE0Ŀ¼ÏµÄÕý³£Îļþ¡£Ä¿Ç°£¬¸Ã´óѧÒÑ·ÏÆú¸Ã±¸·Ýϵͳ£¬²¢¼Æ»®ÔÚ2022Äê1ÔÂÖØÐÂÒýÈë¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/university-loses-77tb-of-research-data-due-to-backup-error/