AndroxGh0st½©Ê¬ÍøÂçÃé×¼AWS¡¢AzureºÍOffice365ƾ֤
Ðû²¼Ê±¼ä 2024-01-191ÔÂ17ÈÕ£¬AndroxGh0stÊÇÒ»ÖÖ»ùÓÚ Python µÄ¶ñÒâÈí¼þ£¬ÓÉ Lacework ÓÚ 2022 Äê 12 ÔÂÊ״μǼ£¬¸Ã¶ñÒâÈí¼þÆô·¢ÁËAlienFox¡¢GreenBot£¨ÓÖÃû Mainance£©¡¢Legion ºÍ Predator µÈ¶à¸öÀàËƹ¤¾ß¡£¸ÃÔƹ¥»÷¹¤¾ßÄܹ»Éø͸Ò×ÊÜÒÑÖªÄþ¾²Â©¶´Ó°ÏìµÄ·þÎñÆ÷£¬ÒÔ·ÃÎÊ Laravel »·¾³Îļþ²¢ÇÔÈ¡ Amazon Web Services (AWS)¡¢Microsoft Office 365¡¢SendGrid ºÍ Twilio µÈÖªÃûÓ¦Ó÷¨Ê½µÄƾ¾Ý¡£¹¥»÷ÕßÀûÓõÄһЩֵµÃ×¢ÒâµÄȱÏÝ°üÂÞCVE-2017-9841 (PHPUnit)¡¢CVE-2021-41773 (Apache HTTP Server) ºÍCVE-2018-15133 (Laravel Framework)¡£AndroxGh0st ¾ßÓжàÖÖ¹¦Ð§£¬¿ÉÒÔʵÏÖ SMTP ÀÄÓá£
2. Ħ¸ù´óͨÃæÁÙÇ°ËùδÓеÄÍøÂçÍþв£¬Ã¿ÈÕ450ÒÚ´ÎÈëÇÖʵÑé
1ÔÂ17ÈÕ£¬»ª¶û½Ö¶¥¼¶½ðÈÚ»ú¹¹Ö®Ò»Ä¦¸ù´óͨĿǰÕýÔÚŬÁ¦Ó¦¶ÔÍøÂç¹¥»÷ÊýÁ¿µÄ¾ªÈËÔö³¤¡£¾Ý±¨µÀ£¬¸Ã¹«Ë¾Ã¿ÌìÃæÁÙ¶à´ï 450 ÒÚ´ÎÍøÂçÈëÇÖʵÑ飬Õâ˵Ã÷ÁËÈ«Çò½ðÈÚ¹«Ë¾Ä¿Ç°ÃæÁÙµÄÍþвµÄÑÏÖØÐÔºÍƵÂÊ¡£È«Çò·¶Î§ÄÚÍøÂç·¸×ïµÄ¼¤ÔöʹµÃĦ¸ù´óͨµÈ»ú¹¹´¦ÓÚ×îÇ°Ïߣ¬Ö´ÐÐÑϸñµÄÄþ¾²´ëÊ©À´±£»¤Ãô¸ÐµÄ½ðÈÚÐÅÏ¢²¢Î¬»¤ÆäϵͳµÄÍêÕûÐÔ¡£Õâ¼ÒÒøÐÐÒµ¾ÞÍ·Åû¶ÁËÆäÿÌìÔâÊܵĴóÁ¿ºÚ¿Í¹¥»÷£¬Í»ÏÔÁËÍøÂç·¸×ï¸ø½ðÈÚ²¿ÃÅ´øÀ´µÄ²»Í£Éý¼¶µÄÌôÕ½¡£ÕâÖÖÇé¿öҲ͹ÏÔÁËÍøÂçÄþ¾²ÔÚµ±½ñÊý×Ö¾¼ÃÖз¢»ÓµÄÒªº¦×÷Óá£
3. ÒÁÀʺڿÍÀûÓÃÐ嵀 MediaPl ¶ñÒâÈí¼þÃé×¼´óѧºÍÑо¿»ú¹¹
1ÔÂ17ÈÕ£¬Î¢ÈíÌåÏÖ£¬Ò»ÈººÚ¿ÍÕýÔÚÕë¶ÔÅ·ÖÞºÍÃÀ¹úÑо¿»ú¹¹ºÍ´óѧµÄÖªÃûÔ±¹¤½øÐÐÓã²æʽÍøÂç¹¥»÷£¬ÍÆËÍеĺóÃŶñÒâÈí¼þ¡£ÕâЩ¹¥»÷ÕßÊÇÎÛÃûÕÑÖøµÄ APT35£¨Ò²³ÆΪ Charming Kitten ºÍ Phosphorus£©µÄÒ»¸ö×Ó×éÖ¯£¬ËûÃÇͨ¹ý֮ǰ±»ÈëÇÖµÄÕÊ»§·¢ËͶ¨ÖÆÇÒÄÑÒÔ¼ì²âµÄÍøÂçµöÓãµç×ÓÓʼþ¡£ÔÚÕâ´Î»î¶¯ÖУ¬Mint Sandstorm ʹÓö¨ÖƵÄÍøÂçµöÓãÓÕ¶ü£¬ÊÔͼͨ¹ýÉç»á¹¤³ÌÊÖ¶ÎÈÃÄ¿±êÏÂÔضñÒâÎļþ¡£MediaPl ¶ñÒâÈí¼þʹÓüÓÃܵÄͨÐÅͨµÀÓëÆäÃüÁîºÍ¿ØÖÆ (C2) ·þÎñÆ÷½»»»ÐÅÏ¢£¬Ö¼ÔÚαװ³É Windows Media Player ÒÔÈƹý¼ì²â¡£
4. Have I Been Pwned ÔöÌí7100Íò¸öÒѾ鶵ÄÓʼþÕ˺Å
1ÔÂ17ÈÕ£¬Have I Been Pwned Òѽ« Naz.API Êý¾Ý¼¯ÖÐÓë±»µÁÕÊ»§Ïà¹ØµÄ½ü 7100 Íò¸öµç×ÓÓʼþµØÖ·Ìí¼Óµ½ÆäÊý¾Ýй¶֪ͨ·þÎñÖС£Naz.API Êý¾Ý¼¯ÊÇʹÓÃײ¿âÁбíºÍÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þÇÔÈ¡µÄÊý¾Ý±àÒë¶ø³ÉµÄ 10 ÒÚ¸öƾ֤µÄÅӴ󼯺ϡ£×²¿âÁбíÊÇ´Ó֮ǰµÄÊý¾Ýй¶Ê¼þÖÐÇÔÈ¡µÄµÇ¼ÃûºÍÃÜÂë¶ÔµÄ¼¯ºÏ£¬ÕâЩÊý¾Ýй¶Ê¼þÓÃÓÚÆÆ»µÆäËüÍøÕ¾ÉϵÄÕÊ»§¡£±»µÁÊý¾Ý±»ÊÕ¼¯ÔÚÎı¾ÎļþºÍͼÏñÖУ¬ÕâЩÎļþ´æ´¢ÔÚ³ÆΪ¡°ÈÕÖ¾¡±µÄµµ°¸ÖС£È»ºó£¬ÕâЩÈÕÖ¾»áÉÏ´«µ½Ô¶³Ì·þÎñÆ÷£¬ÒԱ㹥»÷ÕßÉÔºóÊÕ¼¯¡£ÎÞÂÛƾ֤ÈçºÎ±»µÁ£¬ËüÃǶ¼Êб»ÓÃÀ´ÆÆ»µÊܺ¦ÕßÓµÓеÄÕÊ»§£¬³öÊÛ¸øÍøÂç·¸×ïÊг¡ÉϵÄÆäËûÍþвÐÐΪÕߣ¬»òÔÚºÚ¿ÍÂÛ̳ÉÏÃâ·ÑÐû²¼ÒÔÔÚºÚ¿ÍÉçÇøÖлñµÃÉùÓþ¡£
5. ¿¨°Í˹»ùÐû²¼iOS¼ì²â¼äµýÈí¼þµÄ¿ªÔ´¹¤¾ßiShutdown
1ÔÂ17ÈÕ£¬´ÓÀúÊ·ÉÏ¿´£¬¼ì²â¶ñÒâÈí¼þÐèÒª¶Ô iPhone ½øÐÐÍêÕû±¸·Ý£¬È»ºó³¹µ×¼ì²é±¸·ÝÊý¾ÝÊÇ·ñ´æÔÚÒì³£¡£È»¶ø£¬¿¨°Í˹»ùÏÖÔÚÉè¼ÆÁËÒ»ÖÖ¸ü¼ò»¯µÄÒªÁ죬ÃûΪ¡°iShutdown¡±¡£¿¨°Í˹»ùÒѾÐû²¼ÁËiShutdown ÊÇÒ»¸ö¿ªÔ´½Å±¾£¬Ö¼ÔÚ¿ìËÙ¼ì²â iOS É豸ÖеÄÊÇ·ñѬȾ¼äµýÈí¼þ¡£Õâ¸öÃûΪ shutdown.log µÄÈÕÖ¾Îļþ³ÉΪ¿¨°Í˹»ù¶ÔÒÔÉ«ÁмäµýÈí¼þ¿ª·¢ÉÌ£¨°üÂÞ NSO Group µÄ Pegasus¡¢QuaDream µÄ Reign ºÍ Intellexa µÄ Predator£©Ñо¿µÄ½¹µã¡£·¢ÏÖÕâЩ¼äµýÈí¼þ·¨Ê½µÄ¹²ÐÔ¡£¾³£ÖØÐÂÆô¶¯ iPhone µÄÓû§¸üÓпÉÄÜÊÓ²ìÈÕÖ¾ÖеÄÏà¹ØÌõÄ¿¡£Òò´Ë£¬ÌáÈ¡ shutdown.log Îļþ×ãÒÔ·ÖÎö iPhone ÊÇ·ñÊܵ½¼äµýÈí¼þµÄΣº¦¡£
6. ColdRiver APTÐû²¼¶¨ÖÆ°æºóÃŶñÒâÈí¼þSpica
1ÔÂ19ÈÕ£¬ ColdRiver µÄ¸ß¼¶Á¬ÐøÍþв (APT) ÒÑÉîÈ붨ÖƶñÒâÈí¼þÁìÓò£¬ÍƳöÁËÃûΪSpicaµÄרÓкóÃÅ¡£ColdRiver£¨ÓÖÃû Blue Charlie¡¢Callisto¡¢Star Blizzard »ò UNC4057£©Í¨³£ÒÔ·ÇÕþ¸®×éÖ¯¡¢Ç°Ç鱨ºÍ¾üʹÙÔ±ÒÔ¼°±±Ô¼Õþ¸®ÎªÄ¿±ê½øÐÐÍøÂç¼äµý»î¶¯¡£µ±Ä¿±ê²»ÐÐÖÆÖ¹µØ»ØӦ˵ËûÃÇÎÞ·¨¶ÁÈ¡¼ÓÃÜÎĵµÊ±£¬ColdRiver »á·¢ËÍÒ»¸öÁ´½Ó£¬ÇÉÃîµØÉù³Æ¿ÉÒÔͨÍù¡°½âÃÜ¡±ÊµÓ÷¨Ê½¡ª¡ªËäÈ»£¬Õâʵ¼ÊÉÏÊÇ Spica ¶ñÒâÈí¼þ¡£Ò»µ©Ö´ÐУ¬Spica ¾Í»á´ò¿ªÒ»¸öËùν¡°ÒѽâÂ롱µÄ PDF ×÷ΪÓÕ¶ü£¬Í¬Ê±ÇÄÇĵؽ¨Á¢³Ö¾ÃÐÔ²¢ÓëÆäÃüÁîºÍ¿ØÖÆ·þÎñÆ÷ (C2) Á¬½Ó¡£