MonikerLink ©¶´Ê¹ Outlook Óû§ÃæÁÙÊý¾Ý͵ÇԺͶñÒâÈí¼þµÄÍþв

Ðû²¼Ê±¼ä 2024-02-19

1. MonikerLink ©¶´Ê¹ Outlook Óû§ÃæÁÙÊý¾Ý͵ÇԺͶñÒâÈí¼þµÄÍþв


2ÔÂ17ÈÕ£¬Check Point Research (CPR) ·¢ÏÖMicrosoft OutlookÖдæÔÚÑÏÖØÄþ¾²Â©¶´ ¡£±»³ÆΪ#MonikerLink£»¸Ã©¶´ÔÊÐíÍþвÐÐΪÕßÔÚÆäÄ¿±êÉ豸ÉÏÖ´ÐÐÈÎÒâ´úÂë ¡£²©¿ÍÎÄÕÂÖÐÏêϸ½éÉÜÁËÕâÏîÑо¿£¬Ç¿µ÷Á˸鶴¿ÉÄÜ»áÀûÓà Outlook ´¦ÖÃijЩ³¬Á´½ÓµÄ·½Ê½ ¡£¸Ã©¶´±»¸ú×ÙΪCVE-2024-21413£¬ CVSS ÆÀ·ÖΪ 9.8£¨Âú·Ö 10£©£¬ÕâÒâζן鶴¾ßÓÐÑÏÖØÑÏÖØÐÔÇҸ߶ȿÉÀûÓ㬿ÉÄÜÔÊÐí¹¥»÷Õßͨ¹ý×îÉÙµÄÓû§½»»¥À´ÆÆ»µÏµÍ³ ¡£Õâ¿ÉÄܻᵼÖÂϵͳÍêÈ«ÊÜË𡢾ܾø·þÎñºÍÊý¾Ýй¶ ¡£´ËÍ⣬¹¥»÷Õß¿ÉÒÔÖ´ÐÐÈÎÒâ´úÂë¡¢ÇÔÈ¡Êý¾ÝºÍ°²×°¶ñÒâÈí¼þ ¡£¸ÃÎÊÌâµÄ·¢ÉúÊÇÓÉÓÚ Outlook ´¦Öá°file://¡±³¬Á´½ÓµÄ·½Ê½Ôì³ÉµÄ£¬´Ó¶øµ¼ÖÂÑÏÖصÄÄþ¾²Òþ»¼ ¡£Íþв¼ÓÈëÕß¿ÉÒÔÔÚÄ¿±êÉ豸ÉÏÖ´ÐÐδ¾­ÊÚȨµÄ´úÂë ¡£CPR µÄÑо¿±íÃ÷£¬#MonikerLink ©¶´ÀÄÓÃÁË Windows ÉϵÄ×é¼þ¹¤¾ßÄ£ÐÍ ( COM )£¬´Ó¶øÔÊÐíÖ´ÐÐδ¾­ÊÚȨµÄ´úÂ벢鶵±µØ NTLM ƾ¾ÝÐÅÏ¢ ¡£¸Ã©¶´ÀûÓÃÓû§µÄ NTLM ƾ¾ÝÀ´Í¨¹ý Windows ÖÐµÄ COM Ö´ÐÐÈÎÒâ´úÂë ¡£µ±Óû§µ¥»÷¶ñÒⳬÁ´½Óʱ£¬Ëü»áÁ¬½Óµ½Óɹ¥»÷Õß¿ØÖƵÄÔ¶³Ì·þÎñÆ÷£¬´Ó¶øÆÆ»µÉí·ÝÑéÖ¤ÏêϸÐÅÏ¢²¢¿ÉÄܵ¼Ö´úÂëÖ´ÐÐ ¡£ÕâʹµÃ¹¥»÷ÕßÄܹ»ÈƹýOffice Ó¦Ó÷¨Ê½ÖеÄÊܱ£»¤ÊÓͼģʽ£¬Ô¶³Ìµ÷Óà COM ¹¤¾ß²¢ÔÚÊܺ¦ÕߵļÆËã»úÉÏÖ´ÐдúÂë ¡£


https://www.hackread.com/monikerlink-bug-microsoft-outlook-data-malware/


2. FBI ͨ¼©·¸ Zeus ºÍ IcedID ¶ñÒâÈí¼þÖ÷ıÈÏ×ï


2ÔÂ18ÈÕ£¬Ò»ÃûÎÚ¿ËÀ¼¹«ÃñÔÚÃÀ¹úÈÏ¿É×Ô¼ºÔÚ 2009 Äê 5 ÔÂÖÁ 2021 Äê 2 ÔÂÆÚ¼ä¼ÓÈëÁËÁ½¸ö²îÒìµÄ¶ñÒâÈí¼þ¼Æ»®£¨Zeus ºÍ IcedID£© ¡£37 ËêµÄάÑÇÇÐ˹À­·ò¡¤ÒÁ¸êÁÐάÆ桤Åí³þ¿Æ·òÓÚ 2022 Äê 10 Ô±»ÈðÊ¿Õþ¸®´þ²¶£¬²¢ÓÚÈ¥Äê±»Òý¶Éµ½ÃÀ¹ú ¡£2012Ä꣬Ëû±»ÁÐÈëÁª°îÊÓ²ì¾ÖµÄͨ¼©Ãûµ¥ ¡£ÃÀ¹ú˾·¨²¿ (DoJ)½« PenchukovÃèÊöΪ¡°Á½¸ö¶à²ú¶ñÒâÈí¼þ×éÖ¯µÄÁìµ¼Õß¡±£¬¸Ã×éÖ¯ÓöñÒâÈí¼þѬȾÁËÊýǧ̨¼ÆËã»ú£¬µ¼ÖÂÀÕË÷Èí¼þºÍÊý°ÙÍòÃÀÔª±»µÁ ¡£ÆäÖаüÂÞ Zeus ÒøÐÐľÂí£¬¸ÃľÂíÓÐÖúÓÚÇÔÈ¡ÒøÐÐÕË»§ÐÅÏ¢¡¢ÃÜÂë¡¢¸öÈËʶ±ðÂëÒÔ¼°µÇ¼ÍøÉÏÒøÐÐÕË»§ËùÐèµÄÆäËûÏêϸÐÅÏ¢ ¡£±»¸æ»¹±»Ö¸¿ØÖÁÉÙ´Ó 2018 Äê 11 ÔÂÆð×ÊÖúÁìµ¼Éæ¼°IcedID£¨ÓÖÃû BokBot£©¶ñÒâÈí¼þµÄ¹¥»÷£¬´Ó¶øΪ¶ñÒâ»î¶¯Ìṩ±ãÀû ¡£¸Ã¶ñÒâÈí¼þÄܹ»³äµ±ÐÅÏ¢ÇÔÈ¡·¨Ê½ºÍÆäËûÓÐЧ¸ºÔØ£¨ÀýÈçÀÕË÷Èí¼þ£©µÄ¼ÓÔØ·¨Ê½ ¡£×îÖÕ£¬ÕýÈçÊÓ²ì¼ÇÕß²¼À³¶÷¡¤¿ËÀײ¼Ë¹ (Brian Krebs)ÔÚ 2022 Ä걨µÀµÄÄÇÑù£¬ÓÉÓÚÓëÎÚ¿ËÀ¼Ç°×Üͳά¿ËÍС¤ÑÇŬ¿ÆάÆæ (Victor Yanukovych) µÄÕþÖιØϵ£¬Ëû¶àÄêÀ´ÀÖ³ÉÌÓ±ÜÎÚ¿ËÀ¼ÍøÂç·¸×ïÊÓ²ìÈËÔ±µÄÆðËß ¡£


https://thehackernews.com/2024/02/fbis-most-wanted-zeus-and-icedid.html


3. CISA ³Æ Akira ÀÕË÷ÍÅ»ïÕýÔÚÀûÓà Cisco ASA/FTD ©¶´CVE-2020-3259 


2ÔÂ17ÈÕ£¬ÃÀ¹úÍøÂçÄþ¾²ºÍ»ù´¡ÉèÊ©Äþ¾²¾Ö (CISA)ÔÚÆäÒÑÖªÀûÓ鶴Ŀ¼ÖÐÌí¼ÓÁË Ò»¸ö Cisco ASA ºÍ FTD ©¶´£¬±àºÅΪCVE-2020-3259  £¨CVSS ÆÀ·Ö£º7.5£© ¡£Â©¶´ CVE-2020-3259 ÊÇÒ»¸ö´æÔÚÓÚ ASA ºÍ FTD Web ·þÎñ½Ó¿ÚÖеÄÐÅϢй¶ÎÊÌâ ¡£Ë¼¿ÆÓÚ 2020 Äê 5 ÔÂÐÞ¸´Á˸鶴 ¡£CISA ½«¸ÃÎÊÌâÁÐΪÒÑÖªÓÃÓÚÀÕË÷Èí¼þ»î¶¯µÄÎÊÌ⣬µ«¸Ã»ú¹¹Ã»ÓÐ͸¶ÄÄЩÀÕË÷Èí¼þ×éÖ¯ÕýÔÚ»ý¼«ÀûÓøÃÎÊÌâ ¡£Truesec CSIRT ÍÅ¶Ó ·¢ÏÖÈ¡Ö¤Êý¾Ý±íÃ÷ Akira ÀÕË÷Èí¼þ×éÖ¯¿ÉÄÜÕýÔÚ»ý¼«ÀûÓÃ¾ÉµÄ Cisco ASA£¨×ÔÊÊÓ¦Äþ¾²É豸£©ºÍ FTD£¨Firepower Íþв·ÀÓù£©Â©¶´£¬¸ú×Ù±àºÅΪ CVE-2020-3259 ¡£Akira ÀÕË÷Èí¼þ ×Ô 2023 Äê 3 ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬¸Ã¶ñÒâÈí¼þ±³ºóµÄÍþвÐÐΪÕßÉù³ÆÒѾ­ÈëÇÖÁ˶à¸öÐÐÒµµÄ¶à¸ö×éÖ¯£¬°üÂÞ½ÌÓý¡¢½ðÈںͷ¿µØ²ú ¡£ÓëÆäËûÀÕË÷Èí¼þÍÅ»ïÒ»Ñù£¬¸Ã×éÖ¯¿ª·¢ÁËÒ»¿îÕë¶Ô VMware ESXi ·þÎñÆ÷µÄ Linux ¼ÓÃÜÆ÷ ¡£


https://securityaffairs.com/159244/cyber-crime/cisa-cisco-cve-2020-3259-akira-ransomware.html


4. ÒÔÉ«ÁÐ NSO ×éÖ¯ÉæÏÓ¶Ô WhatsApp ½øÐС°²ÊÐÅÖ¸ÎÆ¡±¹¥»÷


2ÔÂ16ÈÕ£¬ÒÔÉ«ÁмäµýÈí¼þ¹«Ë¾ NSO Group ÉæÏÓÀûÓÃÒ»ÖÖÐÂÓ±µÄ¡°²ÊÐÅÖ¸ÎÆ¡±¹¥»÷À´Õë¶Ô WhatsApp ÉÏδ¾­»³ÒɵÄÓû§£¬ÎÞÐèÓû§½»»¥¼´¿É̻¶ËûÃǵÄÉ豸ÐÅÏ¢ ¡£¸Ã¹«Ë¾ÓÚ 2023 Äê 15 ÈÕÐÇÆÚËÄÏò Hackread.com ·ÖÏíµÄ³ÂËßÏÔʾ£¬WhatsApp ÔÚ 2019 Äê 5 Ô·¢ÏÖÆäϵͳ´æÔÚ©¶´£¬ÔÊÐí¹¥»÷ÕßÔÚÓû§É豸ÉÏ°²×° Pegasus ¼äµýÈí¼þ ¡£Ëæºó£¬¸Ã©¶´±»ÀûÓÃÀ´Õë¶ÔÈ«ÇòµÄÕþ¸®¹ÙÔ±ºÍ»î¸ÐÈËÊ¿ ¡£WhatsApp ¾ÍÕâÖÖÀûÓÃÐÐΪÆðËßNSO ¼¯ÍÅ£¬µ«ÔÚÃÀ¹úÉÏËß·¨ÔººÍ×î¸ß·¨ÔºÉÏËß¾ùʧ°Ü ¡£Enea ÌᳫÁËÒ»ÏîÊӲ죬ÒÔ²éÃ÷²ÊÐÅÖ¸Îƹ¥»÷ÊÇÈçºÎ·¢ÉúµÄ ¡£ËûÃÇ·¢ÏÖ£¬Ëü¿ÉÒÔͨ¹ý·¢ËͲÊÐÅÀ´ÏÔʾĿ±êÉ豸ºÍ²Ù×÷ϵͳ°æ±¾£¬¶øÎÞÐèÓû§½»»¥ ¡£MMS UserAgent ÊÇÒ»¸ö±êʶ²Ù×÷ϵͳºÍÉ豸£¨ÀýÈçÔËÐÐ Android µÄÈýÐÇÊÖ»ú£©µÄ×Ö·û´®£¬¶ñÒâÐÐΪÕß¿ÉÒÔÀûÓà MMS UserAgent À´ÀûÓ鶴¡¢¶¨ÖƶñÒ⸺ÔØ»ò³ïıÍøÂçµöÓã»î¶¯ ¡£


https://www.hackread.com/israeli-nso-group-mms-fingerprint-attack-whatsapp/


5. Ñо¿ÍŶӷ¢ÏÖTurla APT ²¿ÊðÐ嵀 TinyTurla-NG ºóÃÅ


2ÔÂ17ÈÕ£¬Ë¼¿Æ Talos µÄר¼Ò·¢ÏÖÓÉ Turla APT ×éÖ¯³ïıµÄÕë¶Ô²¨À¼·ÇÕþ¸®×éÖ¯µÄ»î¶¯ ¡£Õâ´Î¹¥»÷ÀûÓÃÁËÒ»ÖÖÐÂÓ±µÄºóÃÅ£¬TinyTurla-NG ¡£TinyTurla-NG µÄÒ»¸öÏÔÖøÌØÕ÷ÊÇËüÄܹ»³äµ±ºóÃÅ£¬µ±¼ì²âµ½»ò×èÖ¹ÆäËûºÚ¿ÍÒªÁìʱ£¬ºóÞͻᱻ¼¤»î ¡£¼Ç¼ÔÚ°¸µÄ¹¥»÷»î¶¯´Ó 2023 Äê 12 Ô 18 ÈÕÁ¬Ðøµ½ 2024 Äê 1 Ô 27 ÈÕ£¬²»ÍâÓÐÈËÍƲ⹥»÷¿ÉÄÜÔçÔÚ 2023 Äê 11 Ô¾ͿªÊ¼ÁË ¡£²¡¶¾Í¨¹ýÊÜѬȾµÄ WordPress ÍøÕ¾Á÷´«£¬¸ÃÍøÕ¾³äµ±ÃüÁîºÍ¿ØÖÆ (C2) ·þÎñÆ÷ ¡£TinyTurla-NG Äܹ»´Ó C2 ·þÎñÆ÷Ö´ÐÐÃüÁî¡¢ÉÏ´«ºÍÏÂÔØÎļþÒÔ¼°²¿Êð½Å±¾ÒÔ´ÓÃÜÂë¹ÜÀíÊý¾Ý¿âÇÔÈ¡ÃÜÂë ¡£´ËÍ⣬TinyTurla-NG ³äµ±½»¸¶ PowerShell ½Å±¾µÄÇþµÀ£¬³ÆΪ TurlaPower-NG£¬Ö¼ÔÚÌáÈ¡ÓÃÓÚ±£»¤Á÷ÐÐÃÜÂë¹ÜÀíÆ÷Êý¾Ý¿âµÄÐÅÏ¢ ¡£


https://meterpreter.org/turla-apt-deploys-new-tinyturla-ng-backdoor/


6. Alpha ÀÕË÷Èí¼þ´Ó NetWalker »Ò½ýÖÐáÈÆð


2ÔÂ16ÈÕ£¬Alpha ÊÇÒ»ÖÖÐÂÀÕË÷Èí¼þ£¬ÓÚ 2023 Äê 2 ÔÂÊ״ηºÆ𣬲¢ÔÚ×î½ü¼¸ÖܼÓÇ¿ÁËÔË×÷£¬ÓëÔçÒѲ»´æÔÚµÄ NetWalker ÀÕË÷Èí¼þ·Ç³£ÏàËÆ£¬NetWalker ÀÕË÷Èí¼þÓÚ 2021 Äê 1 ÔÂÔÚÒ»´Î ¹ú¼ÊÖ´·¨Ðж¯ºóÏûʧ ¡£¶Ô Alpha µÄ·ÖÎö½ÒʾÁËÓë¾É°æ NetWalker ÀÕË÷Èí¼þµÄÏÔÖøÏàËÆÖ®´¦ ¡£ÕâÁ½ÖÖÍþв¶¼Ê¹ÓÃÀàËƵĻùÓÚ PowerShell µÄ¼ÓÔØ·¨Ê½À´Í¨±¨ÓÐЧ¸ºÔØ ¡£³ý´ËÖ®Í⣬Alpha ºÍ NetWalker ÓÐЧ¸ºÔØÖ®¼ä´æÔÚ´óÁ¿´úÂëÖصþ ¡£Õâ°üÂÞ£ºÁ½¸öÓÐЧ¸ºÔØÖ÷Òª¹¦Ð§µÄÒ»°ãÖ´ÐÐÁ÷³Ì£»ÔÚµ¥¸öÏß³ÌÖд¦ÖÃÁ½¸ö¹¦Ð§£º½ø³ÌÖÕÖ¹ºÍ·þÎñÖÕÖ¹£»ÒѽâÎö API µÄÀàËÆÁбí ¡£ËäÈ» API ÊÇʹÓùþÏ£Öµ½âÎöµÄ£¬µ«ËùʹÓõĹþÏ£Öµ²¢²»Ïàͬ£»Á½¸öÓÐЧ¸ºÔؾßÓÐÏàËƵÄÅäÖ㬰üÂÞÌø¹ýµÄÎļþ¼Ð¡¢ÎļþºÍÀ©Õ¹ÃûµÄÁбí£»ÒÔ¼°ÒªkillµÄ½ø³ÌºÍ·þÎñµÄÁбí£»¼ÓÃÜÍê³Éºó£¬Á½¸öÓÐЧ¸ºÔض¼ÊÐʹÓÃÁÙʱÅú´¦ÖÃÎļþɾ³ý×ÔÉí£»Á½Õ߶¼ÓÐÀàËƵÄÖ§¸¶ÃÅ»§£¬°üÂÞÏàͬµÄÏûÏ¢£º¡°ÈçÐèÊäÈ룬ÇëʹÓÃÓû§´úÂ롱 ¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/alpha-netwalker-ransomware?web_view=true