Turla APTÀÄÓÃMSBuild·Ö·¢TinyTurlaºóÃÅ

Ðû²¼Ê±¼ä 2024-05-23
1. Turla APTÀÄÓÃMSBuild·Ö·¢TinyTurlaºóÃÅ


5ÔÂ22ÈÕ£¬Ò»¸öÓë¶íÂÞ˹Óйصĸ߼¶Á¬ÐøÐÔÍþв (APT) ×éÖ¯Ò»Ö±ÔÚÀÄÓà PDF ºÍ MSBuild ÏîÄ¿Îļþ£¬ÀûÓÃÉç½»¹¤³Ìµç×ÓÓʼþ½« TinyTurla ºóÃÅ×÷ΪÎÞÎļþ¸ºÔؽøÐÐÁ÷´«¡£Ñо¿ÈËÔ±ÌåÏÖ£¬¸Ã»î¶¯µÄÎÞ·ìÁ÷´«·¨Ê½ÔÚÅÓ´óÐÔ·½ÃæÈ¡µÃÁËÏÔÖøµÄ½ø²½¡£Cyble Ñо¿ÈËÔ±ºÍÇ鱨ʵÑéÊÒ (CRIL) µÄÑо¿ÈËÔ±·¢ÏÖÁËÕâÒ»»î¶¯£¬¸Ã»î¶¯Ê¹Óõç×ÓÓʼþºÍÑûÇëÈËȨÑÐÌÖ»á»òÌṩ¹«¹²×ÉѯµÄÎļþ×÷ΪÓÕ¶ü£¬ÒÔѬȾ TinyTurla Óû§¡£ËûÃÇÔÚ×òÌìÐû²¼µÄÓйظûµÄ²©¿ÍÎÄÕÂÖÐÌåÏÖ£¬¹¥»÷Õß»¹Ã°³äºÏ·¨Õþ¸®£¬ÒÔÒýÓÕÊܺ¦ÕßÉϵ±¡£Ñо¿ÈËÔ±Ö¸³ö£¬TinyTurla ºóÃÅÓë¶íÂÞ˹×ÊÖúµÄºã¾ÃÍþв×éÖ¯TurlaÓйØ£¬¸Ã×é֯ͨ³£Õë¶Ô·ÇÕþ¸®×éÖ¯£¬¡°ÌرðÊÇÄÇЩÓëÖ§³ÖÎÚ¿ËÀ¼ÓÐÁªÏµµÄ×éÖ¯¡±¡£Ìû×ӳƣ¬ËûÃÇÈÏΪ¸Ã×éÖ¯ÊǶñÒâ¹¥»÷»î¶¯µÄÄ»ºóºÚÊÖ¡£


https://www.darkreading.com/cyberattacks-data-breaches/russia-turla-apt-msbuild-tinyturla-backdoor


2. CISA ¾¯¸æÀûÓÃMirth Connect©¶´µÄ¹¥»÷»î¶¯


5ÔÂ21ÈÕ£¬Mirth Connect ÊÇÒ»Öֹ㷺ʹÓõĿçƽ̨½çÃæÒýÇ棬ҽÁƱ£½¡×éÖ¯½«ÆäÓÃÓÚÐÅÏ¢¹ÜÀí¡£Ó°Ï쿪Դ²úÎïµÄ©¶´ CVE-2023-43208 ÊÇÒ»¸öÊý¾Ý·´ÐòÁл¯ÎÊÌ⣬¿Éµ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐС£4.4.1 °æÐû²¼Ê±ÒÑÍƳö²¹¶¡¡£¸Ã©¶´ÓÚ 2023 Äê 10 ÔÂÆع⣬ÆäʱÍøÂçÄþ¾²¹«Ë¾ Horizon3.ai ¾¯¸æ³Æ¸Ã©¶´¿ÉÄܶÔÒ½ÁƱ£½¡¹«Ë¾Ôì³ÉÓ°Ïì¡£CVE-2023-43208 ÊÇ CVE-2023-37679 µÄÒ»¸ö±äÌ壬Mirth Connect ¿ª·¢ÈËԱ֮ǰÒÑÔÚ 4.4.0 °æÐû²¼Ê±¶Ô¸Ã©¶´½øÐÐÁËÐÞ²¹¡£Horizon3.ai Æäʱ½«¸Ã©¶´ÃèÊöΪÒ×ÓÚÀûÓ㬲¢¾¯¸æ³Æ¡°¹¥»÷ÕߺܿÉÄÜÀûÓôË©¶´½øÐгõʼ·ÃÎÊ»òÆÆ»µÃô¸ÐµÄÒ½ÁÆÊý¾Ý¡±¡£¸ÃÄþ¾²¹«Ë¾»¹Ö¸³ö£¬·¢ÏÖÁË 1,200 ¶à¸ö̻¶ÔÚ»¥ÁªÍøÉ쵀 NextGen Mirth Connect ʵÀý¡£


https://www.securityweek.com/cisa-warns-of-attacks-exploiting-nextgen-healthcare-mirth-connect-flaw/


3. ºÚ¿ÍÍÅ»ïÀûÓÃÀÕË÷Èí¼þ¹¥»÷·ÆÂɱöÕþ¸®


5ÔÂ22ÈÕ£¬ºÚ¿ÍÕýÔÚÀûÓÃ鶵ÄÀÕË÷Èí¼þ¹¹½¨Õ߶ԷÆÂɱöµÄÒªº¦»ù´¡ÉèÊ©Ìᳫ¹¥»÷¡ª¡ªÕâÊdzöÓÚÕþÖζ¯»úµÄÍÅÌåµÄÇ÷ÊƵÄÒ»²¿ÃÅ£¬ËûÃÇÔ½À´Ô½¶àµØÊÔͼÈÅÂÒÕâ¸ö¶«ÄÏÑǹú¼ÒµÄÉú»î¡£ÍøÂçÄþ¾²¹«Ë¾ SentinelOneµÄÑо¿ÈËÔ±ÌåÏÖ£¬Ò»¸öÃûΪ¡°Ikaruz Red Team¡±µÄ×éÖ¯ÊÇÉÙÊý¼¸¸öÕë¶Ô·ÆÂɱöÕþ¸®Ä¿±êµÄºÚ¿Í×éÖ¯Ö®Ò»¡£¸ÃÐж¯ÀûÓÃÁ˶àÖÖÀÕË÷Èí¼þ¹¹½¨Õß¡ª¡ª°üÂÞ LockBit¡¢Vice Society¡¢Clop ºÍ AlphV¡ª¡ªÌᳫ¡°Ð¡¹æÄ£¡±¹¥»÷¡£Ëü»¹ÔÚÍøÉÏÐû´«·ÆÂɱö¶à¸ö×éÖ¯µÄÊý¾Ýй¶Çé¿ö¡£SentinelOne ÌåÏÖ£¬Êܺ¦ÕߵıãÌõ¼¸ºõÈ«²¿³­Ï®×Ôԭʼ LockBit Ä£°å£¬¶¥²¿µÄÃû×Ö³ýÍ⡣δÌṩÁªÏµÐÅÏ¢¡£


https://therecord.media/philippines-hacktivist-groups-leaked-versions-ransomware


4. GhostEngine ÍÚ¿ó¹¥»÷ÀûÓÃÒ×Êܹ¥»÷µÄÇý¶¯


5ÔÂ22ÈÕ£¬ÒÑ·¢ÏÖ´úºÅΪ¡°REF4578¡±µÄ¶ñÒâ¼ÓÃÜ»õ±ÒÍÚ¾ò»î¶¯²¿ÊðÁËÃûΪ GhostEngine µÄ¶ñÒ⸺ÔØ£¬¸Ã¸ºÔØʹÓÃÒ×Êܹ¥»÷µÄÇý¶¯·¨Ê½À´¹Ø±ÕÄþ¾²²úÎï²¢²¿Êð XMRig ÍÚ¿ó·¨Ê½¡£Elastic Security Labs ºÍ °²ÌìµÄÑо¿ÈËÔ±  ÔÚµ¥¶ÀµÄ³ÂËߺ͹²ÏíµÄ¼ì²â¹æÔòÖÐÇ¿µ÷ÁËÕâЩ¼ÓÃÜ»õ±ÒÍÚ¾ò¹¥»÷µÄÒì³£ÅÓ´óÐÔ£¬ÒÔ×ÊÖú·ÀÓùÕßʶ±ðºÍ×èÖ¹ËüÃÇ¡£È»¶ø£¬Á½·Ý³ÂËß¾ù佫¸Ã»î¶¯¹é¾ÌÓÚÒÑÖªµÄÍþвÐÐΪÕߣ¬Ò²Î´·ÖÏíÓйØÄ¿±ê/Êܺ¦ÕßµÄÏêϸÐÅÏ¢£¬Òò´Ë¸Ã»î¶¯µÄÆðÔ´ºÍ·¶Î§ÈÔȻδ֪¡£ËäÈ»Éв»Çå³þ·þÎñÆ÷×î³õÊÇÈçºÎ±»ÆÆ»µµÄ£¬µ«ÍþвÐÐΪÕߵĹ¥»÷´ÓÖ´ÐÐÃûΪ¡°Tiworker.exe¡±µÄÎļþ¿ªÊ¼£¬¸ÃÎļþαװ³ÉºÏ·¨µÄ Windows Îļþ¡£¸Ã¿ÉÖ´ÐÐÎļþÊÇ GhostEngine µÄ³õʼµÇ̨ÓÐЧ¸ºÔØ£¬GhostEngine ÊÇÒ»¸ö PowerShell ½Å±¾£¬¿ÉÏÂÔØÖÖÖÖÄ£¿éÒÔÔÚÊÜѬȾµÄÉ豸ÉÏÖ´ÐвîÒìµÄÐÐΪ¡£


https://www.bleepingcomputer.com/news/security/ghostengine-mining-attacks-kill-edr-security-using-vulnerable-drivers/


5. Î÷ϤÄá´óѧÔâµ½ºÚ¿Í¹¥»÷²¿ÃÅѧÉúÊý¾Ýй¶


5ÔÂ21ÈÕ£¬ÔÚÍþвÐÐΪÕßÆÆ»µÁËÆä Microsoft 365 ºÍ Sharepoint »·¾³ºó£¬Î÷ϤÄá´óѧ (WSU) ÒÑÏòѧÉúºÍѧÊõÈËԱͨ±¨ÁËÊý¾Ýй¶Ê¼þ¡£WSU ÊÇ°Ä´óÀûÑǵÄÒ»Ëù½ÌÓý»ú¹¹£¬Ìṩ¿çѧ¿ÆµÄ¹ã·º±¾¿Æ¡¢Ñо¿ÉúºÍÑо¿¿Î³Ì¡£ËüÓµÓÐ 47,000 ÃûѧÉúºÍ 4,500 ¶àÃûÕýʽºÍ¼¾½ÚÐÔÔ±¹¤£¬ÔËÓªÔ¤ËãΪ 6 ÒÚÃÀÔª¡£Î÷ϤÄá´óѧÍøÕ¾½ñÈÕÐû²¼Í¨¸æ£¬¾¯¸æ³ÆºÚ¿ÍÒÑ·ÃÎÊÆä Microsoft Office 365 »·¾³£¬°üÂÞµç×ÓÓʼþÕÊ»§ºÍ SharePoint Îļþ¡£Ëù̻¶µÄÊý¾ÝÒòÈ˶øÒ죬¾ßÌåÈ¡¾öÓÚµç×ÓÓʼþͨÐŵÄÄÚÈÝÒÔ¼°´óѧ SharePoint »·¾³Öд洢µÄÎĵµ¡£


https://www.bleepingcomputer.com/news/security/western-sydney-university-data-breach-exposed-student-data/#google_vignette


6. Void ManticoreÃé×¼ÒÔÉ«ÁкͰ¢¶û°ÍÄáÑÇ


5ÔÂ22ÈÕ£¬¸Ã×éÖ¯ÃûΪ Void Manticore (Storm-0842)£¬ÔÚ²îÒì¹ú¼ÒÒÔÖÖÖÖ»¯Ãû¿ªÕ¹»î¶¯¡£×îÖøÃûµÄ±ðÃû°üÂÞÕë¶Ô°¢¶û°ÍÄáÑÇÏ®»÷µÄ¡°¹úÍÁÕýÒ塱ºÍÕë¶ÔÒÔÉ«ÁÐÐж¯µÄ¡°Òò¹û±¨Ó¦¡±¡£Õë¶Ô²îÒìµÄÇøÓò£¬Õë¶Ôÿ¸öÄ¿±ê½ÓÄÉÆæÌصÄÒªÁì¡£¸Ã×éÖ¯µÄ»î¶¯ÓëÁíÒ»¸öÒÁÀÊ×éÖ¯ Scarred Manticore µÄ»î¶¯Öصþ£¬Õâ±íÃ÷Эµ÷ºÍϵͳµÄÊܺ¦ÕßÑ¡ÔñÊÇËûÃÇΪÒÁÀÊÇ鱨ºÍÄþ¾²²¿ (MOIS) ÊÂÇéµÄÒ»²¿ÃÅ¡£×¨¼Ò¾¯¸æ˵£¬Ðé¿ÕЫʨ¶ÔÈκÎ×èµ²ÒÁÀÊÀûÒæµÄÈË×é³ÉÖØ´óÍþв¡£¸Ã×éÖ¯ÀûÓÃÅÓ´óµÄ¼ÙÃûÍøÂç¡¢Õ½ÂÔЭ×÷ºÍÅÓ´óµÄ¹¥»÷ÒªÁì¡£¸Ã×éÖ¯ÒÔÆäË«ÖØÍøÂç¹¥»÷·½Ê½¶øÎÅÃû£¬½«ÎïÀíÊý¾ÝÆÆ»µÓëÐÄÀíѹÁ¦Ïà½áºÏ¡£Void Manticore ʹÓÃÎåÖÖ²îÒìµÄÒªÁ죬°üÂÞÕë¶Ô Windows ºÍ Linux µÄ×Ô½ç˵²Á³ýÆ÷£¬Í¨¹ýɾ³ýÎļþºÍÀûÓù²Ïí´ÅÅÌÀ´ÆÆ»µÏµÍ³¡£


https://meterpreter.org/void-manticore-iranian-state-sponsored-hackers-target-israel-albania/