Ñо¿ÈËÔ±·¢ÏÖWindowsȱÏݿɵ¼ÖÂÀàËÆRootkitµÄ¹¦Ð§

Ðû²¼Ê±¼ä 2024-04-24

1. Ñо¿ÈËÔ±·¢ÏÖWindowsȱÏݿɵ¼ÖÂÀàËÆRootkitµÄ¹¦Ð§


4ÔÂ22ÈÕ£¬ÍþвÐÐΪÕß¿ÉÒÔÀûÓà DOS µ½ NT ·¾¶×ª»»¹ý³ÌÀ´ÊµÏÖÀàËÆ rootkit µÄ¹¦Ð§£¬ÒÔÒþ²ØºÍÄ£ÄâÎļþ¡¢Ä¿Â¼ºÍ½ø³Ì ¡£Äþ¾²Ñо¿Ô± Or YairÔÚºÚñ´ó»áÉÏ·¢±íµÄÒ»·Ý·ÖÎö³ÂËßÖÐÌåÏÖ£º¡°µ±Óû§ÔÚ Windows ÖÐÖ´ÐдøÓз¾¶²ÎÊýµÄº¯Êýʱ£¬Îļþ»òÎļþ¼ÐËùÔÚµÄ DOS ·¾¶½«×ª»»Îª NT ·¾¶ ¡£¡±ÔÚ´Ëת»»¹ý³ÌÖУ¬´æÔÚÒ»¸öÒÑÖªÎÊÌ⣬¼´¸Ãº¯Êý»áɾ³ýÈκη¾¶ÔªËØÖеÄβËæµãÒÔ¼°×îºóÒ»¸ö·¾¶ÔªËØÖеÄÈκÎβËæ¿Õ¸ñ ¡£´Ë²Ù×÷ÓÉ Windows ÖеĴó¶àÊýÓû§¿Õ¼ä API Íê³É ¡£ÕâЩËùνµÄ MagicDot ·¾¶ÔÊÐíÈκηÇÌØȨÓû§·ÃÎÊÀàËÆ rootkit µÄ¹¦Ð§£¬È»ºóÕâЩÓû§¿ÉÒÔ½«ÆäÎäÆ÷»¯£¬ÔÚûÓйÜÀíԱȨÏÞµÄÇé¿öÏÂÖ´ÐÐһϵÁжñÒâ²Ù×÷£¬¶øÇÒ²»»á±»·¢ÏÖ ¡£


https://thehackernews.com/2024/04/researchers-uncover-windows-flaws.html?&web_view=true


2. ¶íÂÞ˹SandwormºÚ¿ÍÍÅ»ïÃé×¼ÁËÎÚ¿ËÀ¼20¸öÖØÒª×éÖ¯


4ÔÂ22ÈÕ£¬Æ¾¾ÝÎÚ¿ËÀ¼¼ÆËã»ú½ô¼±ÏìӦС×é (CERT-UA) µÄÒ»·Ý³ÂËߣ¬¶íÂÞ˹ºÚ¿Í×éÖ¯ Sandworm Ö¼ÔÚÆÆ»µÎÚ¿ËÀ¼Ô¼ 20 ¸öÒªº¦»ù´¡ÉèÊ©µÄÔËÐÐ ¡£ÕâЩºÚ¿ÍÒ²±»³ÆΪ BlackEnergy¡¢Seashell Blizzard¡¢Voodoo Bear ºÍ APT44£¬¾ÝÐÅÓë¶íÂÞ˹Îä×°¶ÓÎé×ÜÕÕÁϲ¿ (GRU) ÓйØ£¬¶ÔÖÖÖÖÄ¿±ê½øÐÐÍøÂç¼äµý»î¶¯ºÍÆÆ»µÐÔ¹¥»÷ ¡£CERT-UA ³ÂË߳ƣ¬2024 Äê 3 Ô£¬APT44 ½øÐÐÁËÆÆ»µÎÚ¿ËÀ¼ 10 ¸öµØÓòÄÜÔ´¡¢Ë®ºÍ¹©Å¯¹©Ó¦ÉÌÐÅÏ¢ºÍͨÐÅϵͳµÄÐж¯ ¡£¹¥»÷·¢ÉúÔÚÈýÔ·Ý£¬ÔÚijЩÇé¿öÏ£¬ºÚ¿ÍÄܹ»Í¨¹ýÆȺ¦¹©Ó¦Á´À´ÌṩÊÜËð»òÒ×Êܹ¥»÷µÄÈí¼þ£¬»òÕßͨ¹ýÈí¼þÌṩÉÌ·ÃÎÊ×é֯ϵͳ½øÐÐά»¤ºÍ¼¼ÊõÖ§³ÖµÄÄÜÁ¦À´Éø͸Ŀ±êÍøÂç ¡£


https://www.bleepingcomputer.com/news/security/russian-sandworm-hackers-targeted-20-critical-orgs-in-ukraine/


3. APT28 ÀûÓà Windows ´òÓ¡ºǫ́´¦Ö÷¨Ê½È±Ïݲ¿ÊðGooseEgg


4ÔÂ23ÈÕ£¬APT28½« Microsoft Windows Print Spooler ×é¼þÖеÄÄþ¾²Â©¶´ÎäÆ÷»¯£¬ÒÔÁ÷´«Ò»ÖÖÃûΪ GooseEgg µÄÏÈǰδ֪µÄ×Ô½ç˵¶ñÒâÈí¼þ ¡£¾Ý³Æ£¬¸Ãй¶ºó¹¤¾ßÖÁÉÙ´Ó 2020 Äê 6 Ô¿ªÊ¼Ê¹Ó㬿ÉÄÜ×îÔç´Ó 2019 Äê 4 Ô¿ªÊ¼Ê¹Óã¬ËüÀûÓÃÁËÒ»¸öÏÖÒÑÐÞ²¹µÄȱÏÝ£¬ÔÊÐíȨÏÞÉý¼¶£¨CVE-2022-38028£¬CVSS ÆÀ·Ö£º7.8£© ¡£Microsoft ÔÚ 2022 Äê 10 ÔÂÐû²¼µÄ¸üÐÂÖнâ¾öÁËÕâ¸öÎÊÌ⣬ÃÀ¹ú¹ú¼ÒÄþ¾²¾Ö (NSA) Æäʱ³ÂËßÁ˸ÃȱÏÝ ¡£Æ¾¾ÝÕâ¼Ò¿Æ¼¼¾ÞÍ·ÍþвÇ鱨ÍŶӵÄ×îз¢ÏÖ£¬APT28£¨Ò²³ÆΪ Fancy Bear ºÍ Forest Blizzard£¨ÒÔÇ°³ÆΪ Strontium£©£©½«¸Ã©¶´ÎäÆ÷»¯£¬ÓÃÓÚÕë¶ÔÎÚ¿ËÀ¼¡¢Î÷Å·ºÍ±±ÃÀÕþ¸®¡¢·ÇÕþ¸®¡¢½ÌÓýºÍ½»Í¨µÄ¹¥»÷²¿ÃÅ×éÖ¯ ¡£½ü¼¸¸öÔÂÀ´£¬APT28 ºÚ¿Í»¹ÀÄÓÃÁËMicrosoft Outlook ÖеÄȨÏÞÉý¼¶Â©¶´£¨CVE-2023-23397£¬CVSS µÃ·Ö£º9.8£©ºÍ WinRAR ÖеĴúÂëÖ´ÐЩ¶´£¨CVE-2023-38831£¬CVSS µÃ·Ö£º7.8£© ¡£


https://thehackernews.com/2024/04/russias-apt28-exploited-windows-print.html


4. ToddyCat APT ÕýÔÚÊÕ¼¯ÑÇÌ«µØÓò¹¤¿ØÐÐÒµµÄÊý¾Ý


4ÔÂ23ÈÕ£¬Ò»¸öÃûΪ ToddyCat µÄ¸ß¼¶Á¬ÐøÍþв (APT) ×éÖ¯ÕýÔÚ´ÓÑÇÌ«µØÓòµÄÕþ¸®ºÍ¹ú·ÀÄ¿±êÊÕ¼¯¹¤Òµ¹æÄ£»¯µÄÊý¾Ý ¡ £¿¨°Í˹»ùʵÑéÊÒ¸ú×ٸûµÄÑо¿ÈËÔ±±¾Öܽ«ÍþвÐÐΪÕßÃèÊöΪʹÓöà¸öͬʱÁ¬½Óµ½Êܺ¦Õß»·¾³À´Î¬³Ö³Ö¾ÃÐÔ²¢´ÓÖÐÇÔÈ¡Êý¾Ý ¡£ËûÃÇ»¹·¢ÏÖÁË ToddyCatʹÓõÄÒ»×éй¤¾ß£¬ÓÃÓÚ´ÓÊܺ¦ÕßϵͳºÍä¯ÀÀÆ÷ÊÕ¼¯Êý¾Ý ¡£ToddyCat ºÜ¿ÉÄÜÊÇÒ»¸ö½²ÖÐÎĵÄÍþвÐÐΪÕߣ¬¿¨°Í˹»ùÒѽ«ÆäÓëÖÁÉÙ¿É×·Ëݵ½ 2020 Äê 12 ÔµĹ¥»÷ÁªÏµÆðÀ´ ¡£ÔÚ×î³õ½×¶Î£¬¸Ã×éÖ¯ËƺõÖ»¹Øע̨ÍåºÍÔ½ÄϵÄÉÙÊý×éÖ¯ ¡£µ«ÔÚ 2021 Äê 2 Ô¹ûÈ»Åû¶ Microsoft Exchange Server ÖеÄËùνProxyLogon ©¶´ºó£¬ÍþвÐÐΪÕßѸËÙ¼Ó´óÁ˹¥»÷Á¦¶È ¡£


https://www.darkreading.com/cyber-risk/-toddycat-apt-is-stealing-data-on-an-industrial-scale-


5. Synlab Italia ÒòÀÕË÷Èí¼þ¹¥»÷¶øÔÝÍ£ÔËÓª


4ÔÂ22ÈÕ£¬ÔÚÀÕË÷Èí¼þ¹¥»÷ÆÈʹ IT ϵͳÀëÏߺó£¬Synlab Italia ÔÝÍ£ÁËËùÓÐÒ½ÁÆÕï¶ÏºÍ²âÊÔ·þÎñ ¡£Synlab Italia ÍøÂçÁ¥ÊôÓڱ鲼ȫÇò 30 ¸ö¹ú¼Ò/µØÓòµÄ Synlab ¼¯ÍÅ£¬ÔÚÒâ´óÀû¸÷µØÔËÓª×Å 380 ¸öʵÑéÊÒºÍÒ½ÁÆÖÐÐÄ ¡£ËüµÄÄêÓªÒµ¶îΪ 4.26 ÒÚÃÀÔª£¬Ã¿Äê½øÐÐ 3500 Íò´Î·ÖÎö ¡£¸Ã¹«Ë¾Ðû²¼ÔÚ 4 Ô 18 ÈÕÁ賿ÔâÓöÄþ¾²Â©¶´£¬ÆÈʹÆä¹Ø±ÕËùÓмÆËã»úÒÔÏÞÖÆÆÆ»µ»î¶¯ ¡£¾¡¹Ü¸Ã¹«Ë¾ÉÐδ֤ʵ£¬µ«Ò»Ð©Ãô¸ÐµÄÒ½ÁÆÊý¾Ý¿ÉÄÜÒÑ̻¶¸ø¹¥»÷Õß ¡£ÉÐÎÞÖ÷ÒªÀÕË÷Èí¼þÍÅ»ïÉù³Æ¶Ô Synlab Italia µÄÍøÂç¹¥»÷ÂôÁ¦ ¡£


https://www.bleepingcomputer.com/news/security/synlab-italia-suspends-operations-following-ransomware-attack/


6. ÃÀ¹ú¹ú¼ÒÄþ¾²¾Ö (NSA) Ðû²¼Äþ¾²È˹¤ÖÇÄܲ¿ÊðÖ¸ÄÏ


4ÔÂ22ÈÕ£¬ÃÀ¹ú¹ú¼ÒÄþ¾²¾ÖÓëÃÀ¹úºÍÆäËûÎåÑÛ¹ú¼ÒµÄÁù¸öÕþ¸®»ú¹¹ºÏ×÷Ðû²¼ÁËÓйØÈçºÎÄþ¾²²¿ÊðÈ˹¤ÖÇÄÜϵͳµÄÐÂÖ¸ÄÏ ¡£ËüÌṩÁË·ÖΪÈýÀàµÄ×î¼Ñʵ¼ùÁбí£¬Éæ¼°È˹¤ÖÇÄܲ¿ÊðµÄÈý¸öÖ÷Òª²½Ö裺±£»¤²¿Êð»·¾³¡¢Á¬Ðø±£»¤AIϵͳºÍÄþ¾²AIÔËά ¡£±£»¤È˹¤ÖÇÄÜϵͳÉ漰ʶ±ð·çÏÕ¡¢ÊµÊ©Êʵ±µÄ»º½â´ëÊ©ºÍ¼à¿ØÎÊÌâµÄÁ¬Ðø¹ý³Ì ¡£Í¨¹ý½ÓÄɱ¾³ÂËßÖиÅÊöµÄ²½ÖèÀ´È·±£È˹¤ÖÇÄÜϵͳµÄ²¿ÊðºÍÔËÐÐÄþ¾²£¬×éÖ¯¿ÉÒÔÏÔ׎µµÍËùÉæ¼°µÄ·çÏÕ ¡£ÕâЩ²½ÖèÓÐÖúÓÚ±£»¤×éÖ¯µÄ֪ʶ²úȨ¡¢Ä£ÐͺÍÊý¾ÝÃâÔâ͵ÇÔ»òÀÄÓà ¡£


https://www.infosecurity-magazine.com/news/nsa-launches-guidance-secure-ai/