TA453 ÀûÓÃÐÂÐÍ AnvilEcho ¶ñÒâÈí¼þ¹¥»÷ÓÌÌ«ÖªÃûÈËÎï

Ðû²¼Ê±¼ä 2024-08-22
1. TA453 ÀûÓÃÐÂÐÍ AnvilEcho ¶ñÒâÈí¼þ¹¥»÷ÓÌÌ«ÖªÃûÈËÎï


8ÔÂ20ÈÕ£¬ÒÁÀʹú¼ÒÖ§³ÖµÄÍþв×éÖ¯TA453Õë¶ÔÓÌÌ«ÖªÃûÈËÎïÌᳫÁËһϵÁо«ÐijïıµÄÓã²æʽÍøÂçµöÓã»î¶¯¡£´Ë»î¶¯Ö¼ÔÚÁ÷´«ÃûΪAnvilEchoµÄÐÂÐÍÇ鱨ÊÕ¼¯¹¤¾ß£¬¸Ã¹¤¾ßͨ¹ýBlackSmith¶ñÒâÈí¼þ¹¤¾ß°üÁ÷´«£¬²¢Î±×°³ÉºÏ·¨ÑûÇëÒÔ½¨Á¢ÐÅÈΡ£AnvilEcho×÷Ϊһ¿îÇ¿´óµÄPowerShellľÂí£¬¾ß±¸ÏµÍ³Õì²ì¡¢½ØÆÁ¡¢ÏÂÔØÔ¶³ÌÎļþ¼°Ãô¸ÐÊý¾ÝÉÏ´«µÈ¹¦Ð§£¬Ã÷ÏÔ¾Û½¹ÓÚÇ鱨ÊÕ¼¯ºÍй¶¡£´ËÍ⣬¸Ã»î¶¯ÀûÓÃÉç»á¹¤³ÌѧÊֶΣ¬Èçð³äÑо¿»ú¹¹·¢ËÍÐé¼ÙÑûÇëºÍÊÜÃÜÂë±£»¤µÄÎĵµÁ´½Ó£¬ÓÕµ¼Êܺ¦Õßµã»÷¶ñÒâÁ´½ÓºÍÏÂÔز¡¶¾¡£Óë´Ëͬʱ£¬ÁíÒ»Ïî·¢ÏÖ½ÒʾÁËÒ»ÖÖеĻùÓÚGoÓïÑԵĶñÒâÈí¼þCyclops£¬¿ÉÄÜ×÷ΪCharming KittenºóÃÅBellaCiaoµÄºóÐø²úÎ½øÒ»²½±íÃ÷¹¥»÷ÕßÕý»ý¼«¸üÐÂÆäÎäÆ÷¿â¡£CyclopsÖ¼ÔÚͨ¹ýREST API·´ÏòËíµÀ´«ÊäÖÁC2·þÎñÆ÷£¬¿ØÖÆÄ¿±ê»úÆ÷£¬²¢Òѱ»ÓÃÓÚ¹¥»÷Àè°ÍÄۺͰ¢¸»º¹µÄÌض¨×éÖ¯¡£´Ë¶ñÒâÈí¼þµÄÑ¡Ôñ·´Ó³ÁËGoÓïÑÔÔÚ¶ñÒâÈí¼þ¿ª·¢ÕßÖеÄÁ÷ÐУ¬ÇÒÆäµÍ¼ì²âÂʶÔÄþ¾²½â¾ö·½°¸×é³ÉÌôÕ½¡£


https://thehackernews.com/2024/08/iranian-cyber-group-ta453-targets.html


2. Xeon SenderÔƹ¥»÷¹¤¾ß£¬ÀûÓúϷ¨·þÎñ·ÅËÁ½øÐжÌÐŵöÓã


8ÔÂ19ÈÕ£¬¶ñÒâÐÐΪÕßÕýÀûÓÃÃûΪXeon SenderµÄÔƹ¥»÷¹¤¾ß£¬Í¨¹ýÀÄÓúϷ¨ÔÆ·þÎñ½øÐдó¹æÄ£µÄ¶ÌÐŵöÓãºÍÀ¬»øÓʼþ»î¶¯¡£Õâ¿î¹¤¾ßÀûÓöà¸öÈí¼þ¼´·þÎñ£¨SaaS£©ÌṩÉ̵ÄÓÐЧƾ֤£¬Í¨¹ýºÏ·¨API½Ó¿Ú·¢ËÍÀ¬»øÐÅÏ¢£¬¶ø²»ÒÀÀµÈκιÌÓÐÈõµã¡£SentinelOneÄþ¾²Ñо¿Ô±Ö¸³ö£¬Xeon Sender¼°Æä±äÌåÈçXeonV5ºÍSVG Sender£¬ÀûÓðüÂÞÑÇÂíѷ֪ͨ·þÎñ£¨SNS£©ÔÚÄڵĶà¸ö¶ÌÐÅ·Ö·¢Æ½Ì¨£¬Í¨¹ýTelegramºÍºÚ¿ÍÂÛ̳Á÷´«¡£×îа汾µÄXeon SenderÔÚÃûΪOrion ToolxhubµÄTelegramƵµÀÉÏÐû²¼£¬¸ÃƵµÀ»¹ÌṩÆäËûºÚ¿Í¹¤¾ß¡£Xeon Sender²»½öÏÞÓÚ¶ÌÐÅ·¢ËÍ£¬»¹¾ß±¸ÑéÖ¤ÕË»§Æ¾Ö¤¡¢Éú³Éµç»°ºÅÂë¼°¼ì²éºÅÂëÓÐЧÐԵȹ¦Ð§¡£Æä»ùÓÚPythonµÄÃüÁîÐнçÃæÔÊÐíÓû§ÇáËÉÓëAPIͨÐÅ£¬Ð­µ÷¹¥»÷¡£¸Ã¹¤¾ßËäȻԴ´úÂë»ìÂÒ£¬µ«ÓÐЧ½µµÍÁ˼¼ÊõÃż÷£¬Ê¹µÃµÍ¼¼Äܹ¥»÷ÕßÒ²ÄÜÀûÓá£ÓÉÓÚXeon SenderʹÓÃÌض¨¹©Ó¦ÉÌ¿â½øÐÐAPIÇëÇ󣬼ì²âÄѶÈÔö¼Ó£¬ÆóÒµÐè½ÓÄÉ×ÛºÏÊֶΣ¬°üÂÞAPIÈÕÖ¾·ÖÎöºÍÐÐΪ¼à¿Ø£¬ÒÔʶ±ð²¢·ÀÓù´ËÀ๥»÷¡£


https://thehackernews.com/2024/08/xeon-sender-tool-exploits-cloud-apis.html


3. CERT-UA¾¯¸æ£ºÐÂÐÍÍøÂçµöÓã¹¥»÷ÀûÓÃVermin¼¯ÈºÁ÷´«¶ñÒâÈí¼þ


8ÔÂ21ÈÕ£¬ÎÚ¿ËÀ¼¼ÆËã»úÓ¦¼±·´Ó³Ð¡×飨CERT-UA£©½üÈÕ·¢³ö¾¯¸æ£¬Ö¸³öÒ»ÖÖеÄÍøÂçµöÓã¹¥»÷ÕýÔÚ»îÔ¾£¬¸Ã¹¥»÷ÀûÓöñÒâÈí¼þÆóͼѬȾÓû§É豸£¬Æä±³ºóÍþв¼¯Èº±»±ê־ΪUAC-0020£¬ÓÖ³ÆVermin¡£¾¡¹Ü¹¥»÷µÄ¾ßÌå¹æÄ£ºÍ·¶Î§Éв»Ã÷ÀÊ£¬µ«ÒÑÖªÆäͨ¹ýαװ³É¿â¶û˹¿ËµØÓòÕ½·ýÕÕƬµÄÍøÂçµöÓãÓʼþÌᳫ£¬ÓÕµ¼Óû§µã»÷Á´½ÓÏÂÔØZIPÎļþ¡£ÕâЩZIPÎļþÄÚº¬Ç¶ÓÐJavaScript´úÂëµÄMicrosoft CHMÎļþ£¬¸Ã´úÂë½øÒ»²½´¥·¢»ìÏýµÄPowerShell½Å±¾Ö´ÐС£Ò»µ©Óû§´ò¿ªÕâЩÎļþ£¬²»½ö»á°²×°ÒÑÖª¼äµýÈí¼þSPECTRµÄ×é¼þ£¬»¹»áÒýÈëÃûΪFIRMACHAGENTµÄжñÒâÈí¼þ¡£FIRMACHAGENTµÄÖ÷ÒªÈÎÎñÊÇËѼ¯SPECTRÇÔÈ¡µÄÊý¾Ý£¬²¢½«Æä»Ø´«ÖÁÔ¶³Ì·þÎñÆ÷¡£SPECTR×÷Ϊһ¿î¹¦Ð§Ç¿´óµÄ¶ñÒâÈí¼þ£¬×Ô2019ÄêÆð±ãÓëVermin×éÖ¯Ïà¹ØÁª£¬ÇÒ¾ÝÐÅÓ문Ê˹¿ËÈËÃñ¹²ºÍ¹ú£¨LPR£©µÄÄþ¾²»ú¹¹ÓÐÁªÏµ¡£SPECTRÄܹ»¹ã·ºÊÕ¼¯Óû§ÐÅÏ¢£¬°üÂÞµ«²»ÏÞÓÚ¼´Ê±Í¨Ñ¶Ó¦Óã¨Element¡¢Signal¡¢Skype¡¢TelegramµÈ£©ÖеÄÎļþ¡¢ÆÁÄ»½Øͼ¡¢µÇ¼ƾ֤¼°Ãô¸ÐÊý¾Ý¡£


https://thehackernews.com/2024/08/cert-ua-warns-of-new-vermin-linked.html


4. CannonDesignÔâÀÕË÷Èí¼þAvos Locker¹¥»÷£¬1.3 Íò¿Í»§Êý¾Ýй¶


8ÔÂ20ÈÕ£¬ÖªÃûÃÀ¹ú½¨ÖþÉè¼Æ¹«Ë¾CannonDesign½üÆÚÏòÆäÅÓ´óµÄ13,000ÓàÃû¿Í»§Èº·¢ËÍÁËÊý¾Ýй¶֪ͨ£¬½ÒʾÁË2023Äê³õÔâÓöµÄÖØ´óÍøÂçÄþ¾²Ê¼þ¡£¸Ãʼþ·¢ÉúÔÚ1ÔÂ19ÈÕÖÁ25ÈÕÖ®¼ä£¬ºÚ¿Í·Ç·¨ÇÖÈëÁ˹«Ë¾ÏµÍ³²¢ÇÔÈ¡ÁËÊý¾Ý£¬¾¡¹Ü¹«Ë¾Ñ¸ËÙÓÚ1ÔÂ25ÈÕ·¢ÏÖ²¢½éÈ룬µ«È«ÃæµÄÊÓ²ìÊÂÇéÖ±ÖÁ2024Äê5ÔÂ3ÈղŸæÒ»¶ÎÂä¡£¾Ýͨ±¨£¬Ð¹Â¶µÄÐÅÏ¢¿ÉÄÜ°üÂÞ¿Í»§µÄÃô¸Ð¸öÈË×ÊÁÏ£¬ÈçÐÕÃû¡¢µØÖ·¡¢Éç»áÄþ¾²ºÅÂë¼°¼ÝʻִÕպţ¬¶Ô´Ë£¬CannonDesign¾ö¶¨ÎªÊܺ¦ÕßÌṩΪÆÚ24¸öÔµÄÐÅÓüà¿Ø·þÎñ¡£´Ë´ÎÊý¾Ýй¶ÓëAvos LockerÀÕË÷Èí¼þ¹¥»÷½ôÃÜÏà¹Ø£¬¸ÃÍÅ»ïÓÚ2023Äê2Ô¹ûÈ»Ðû³Æ¹¥»÷ÁËCannonDesign²¢ÕÆÎÕ5.7 TB µÄ±»µÁÊý¾Ý£¬°üÂÞ¹«Ë¾ºÍ¿Í»§Îļþ¡£ÔÚÀÕË÷δ¹ûºó£¬Êý¾Ý±»×ª½»¸øÁËDark Angels ÀÕË÷Èí¼þ×éÖ¯µÄÊý¾Ýй¶ÍøÕ¾ Dunghill Leaks£¬¸Ã×éÖ¯Ðû²¼ÁËÉæ¼°¿Í»§ÏêÇé¡¢ÏîÄ¿×ÊÁϼ°¹«Ë¾ÄÚ²¿ÐÅÏ¢µÈ2TB Êý¾Ý¡£2024 Äê 2 Ô£¬Í¬Ò»Êý¾Ý¼¯ÔÚ°µÍøÖеĺڿÍÂÛ̳ÉÏÐû²¼£¬°üÂÞ ClubHydra£¬¶øÊý¾Ý¼¯µÄÒ»²¿ÃÅÔÚ 2024 Äê 7 ÔÂͨ¹ý torrent ÔÚ Breached Forums ÉÏ·ÖÏí¡£


https://www.bleepingcomputer.com/news/security/cannondesign-confirms-avos-locker-ransomware-data-breach/


5. Chrome½ô¼±ÐÞ²¹ÒÑÔâºÚ¿Í»ý¼«ÀûÓõÄÁãÈÕ©¶´CVE-2024-7971


8ÔÂ21ÈÕ£¬Google½üÆÚ½ô¼±Ðû²¼ÁËChromeä¯ÀÀÆ÷µÄ×îа汾£¨128.0.6613.84/85£©£¬Ö÷ÒªÊÇΪÁËÓ¦¶ÔÒ»¸öÒѱ»ºÚ¿Í»ý¼«ÀûÓõÄÁãÈÕ©¶´CVE-2024-7971¡£ÕâÒ»¸ßΣ©¶´´æÔÚÓÚV8 JavaScriptÒýÇæÖУ¬¾ßÌåÌåÏÖΪÀàÐÍ»ìÏýÎÊÌ⣬ËüÔÊÐí¹¥»÷ÕßÔÚ·Ç·¨·ÃÎÊÓû§É豸ʱִÐжñÒâ´úÂ룬ÑÏÖØÍþвÓû§Êý¾ÝÄþ¾²£¬¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢·Ç·¨·ÃÎÊ»ò¶ñÒâÈí¼þÖ²Èë¡£¼øÓڸ鶴ÒÑÔÚÏÖʵÖÐÔâµ½ÀûÓ㬴˴θüÐÂÏÔµÃÓÈΪÆÈÇС£³ýÁËÕë¶ÔCVE-2024-7971µÄÐÞ¸´Í⣬Chrome 128°æ±¾»¹Ò»²¢½â¾öÁË°üÂÞCVE-2024-7964ºÍCVE-2024-7965ÔÚÄڵĶà¸ö¸ßÑÏÖØÐÔÄþ¾²Â©¶´¡£ËùÓÐChromeÓû§±»Ç¿ÁÒ½¨ÒéÁ¢¼´ÊÖ¶¯¼ì²é²¢¸üÐÂÖÁ128.0.6613.84»ò¸ü¸ß°æ±¾¡£´ËÍ⣬¶ÔÓÚÒÀÀµChrome´¦ÖÃÃô¸ÐÊý¾ÝµÄ×éÖ¯¶øÑÔ£¬Ñ¸ËÙÓ¦Óô˸üв¢¿¼ÂÇʵʩÌرðµÄÄþ¾²·À»¤´ëÊ©£¨ÈçÓ¦ÓÃɳºÐ¸ôÀ롢ǿ»¯ÍøÂç·Ö¶ÎµÈ£©±äµÃÓÈΪҪº¦£¬ÒÔ½øÒ»²½½µµÍCVE-2024-7971¼°ÆäËûDZÔÚ©¶´´øÀ´µÄÄþ¾²·çÏÕ¡£


https://securityonline.info/urgent-chrome-update-active-zero-day-exploit-detected-cve-2024-7971/


6. ³¯ÏʺڿÍUAT-5394²¿ÊðÐÂÐͶñÒâÈí¼þMoonPeak


8ÔÂ21ÈÕ£¬Ò»ÖÖÐÂÐÍÔ¶³Ì·ÃÎÊľÂíMoonPeak±»½Ò¶Ϊ¹ú¼ÒÖ§³ÖµÄ³¯ÏÊÍþв»î¶¯¼¯ÍŵÄй¤¾ß¡£Ë¼¿ÆTalos½«ÆäÓë±àºÅΪUAT-5394µÄºÚ¿Í×éÖ¯ÁªÏµÆðÀ´£¬¸Ã×éÖ¯ÔÚÕ½ÊõÉÏÓëÒÑÖªµÄKimsuky¹ú¼ÒÐÐΪÕß´æÔÚ½»¼¯¡£MoonPeak×÷ΪXeno RAT¶ñÒâÈí¼þµÄ±äÖÖ£¬±»Éè¼ÆÓÃÓÚ´ÓÔÆ·þÎñÖмìË÷¶ñÒ⸺ÔØ£¬¾ß±¸¼ÓÔزå¼þ¡¢¿ØÖƽø³Ì¼°ÓëC2·þÎñÆ÷ͨÐŵȹ¦Ð§¡£Talos·ÖÎöÖ¸³ö£¬UAT-5394¿ÉÄÜÊÇKimsukyµÄ·ÖÖ§»ò³¯ÏÊÍøÂç»ú¹¹ÄÚÁíÒ»½ÓÄÉÏàËÆÕ½ÊõµÄÍŶÓ¡£´Ë´Î»î¶¯ÏÔÖøÌصãÊǹ¹½¨ÁËеĻù´¡ÉèÊ©£¬°üÂÞC2·þÎñÆ÷¡¢¸ºÔØÍйܵãºÍ²âÊÔ»·¾³£¬ÒÔÖ§³ÖMoonPeakµÄÁ¬Ðøµü´ú¡£Ñо¿ÈËÔ±ÊӲ쵽£¬ÍþвÐÐΪÕßƵ·±¸üзþÎñÆ÷ÉϵĶñÒâÎļþ£¬²¢ÊÕ¼¯Ñ¬È¾ÈÕÖ¾£¬ÏÔʾ³ö¸ß¶ÈµÄÁé»îÐÔºÍÒþ±ÎÐÔ¡£ÖµµÃ×¢ÒâµÄÊÇ£¬MoonPeakµÄ½ø»¯Óëлù´¡ÉèÊ©µÄ½¨Á¢½ôÃÜÏàÁ¬£¬Ã¿´Î¸üж¼ÒýÈë¸ü¶à»ìÏý¼¼Êõ£¬ÒÔ×è°­·ÖÎöºÍ¸Ä±äͨÐÅ»úÖÆ¡£ÕâÖÖÉè¼ÆÈ·±£ÁËMoonPeakµÄÌض¨°æ±¾½öÓëÆ¥ÅäµÄC2·þÎñÆ÷ЭͬÊÂÇ飬Ôö¼ÓÁË·ÀÓùÄѶÈ¡£UAT-5394ѸËÙ¹¹½¨Ð»ù´¡ÉèÊ©µÄÄÜÁ¦±íÃ÷£¬¸Ã×éÖ¯Õý»ý¼«À©´ó»î¶¯·¶Î§£¬ÔöÉèͶ·ÅµãºÍC2·þÎñÆ÷¡£²»Í⣬ĿǰÉв»Çå³þ´Ë´Î»î¶¯µÄÄ¿±ê¡£


https://thehackernews.com/2024/08/north-korean-hackers-deploy-new.html