³¯ÏÊLazarus GroupÀûÓÃChromeÁãÈÕ©¶´Ìᳫ¹¥»÷
Ðû²¼Ê±¼ä 2024-10-2810ÔÂ24ÈÕ£¬³¯ÏʺڿÍ×éÖ¯Lazarus Group±»Ö¸ÀûÓÃGoogle ChromeµÄÏÖÒÑÐÞ²¹Äþ¾²Â©¶´CVE-2024-4947½øÐÐÁãÈÕ¹¥»÷£¬¿ØÖÆÊÜѬȾÉ豸¡£¿¨°Í˹»ù¹«Ë¾ÔÚ2024Äê5Ô·¢ÏÖÁËÒ»ÌõÕë¶Ô¶íÂÞ˹¹«ÃñµÄ¹¥»÷Á´£¬¹¥»÷ͨ¹ýÐé¼ÙµÄ¼ÓÃÜ»õ±ÒÁìÓòÓÎÏ·ÍøÕ¾"detankzone[.]com"´¥·¢Â©¶´¡£¸ÃÍøվαװ³ÉÈ¥ÖÐÐÄ»¯½ðÈÚ£¨DeFi£©NFTµÄ¶àÈËÔÚÏßÕ½¶·¾º¼¼³¡£¨MOBA£©Ì¹¿ËÓÎÏ·£¬ÊµÔò°üÂÞÒþ²Ø½Å±¾£¬ÔÚÓû§ä¯ÀÀÆ÷ÖÐÔËÐЩ¶´£¬Ê¹¹¥»÷Õß»ñµÃ¶ÔÊܺ¦ÕßPCµÄÍêÈ«¿ØÖÆ¡£´ËÍ⣬Lazarus Group»¹±»»³ÒÉÇÔÈ¡ÁËÒ»¿îºÏ·¨Çø¿éÁ´±ßÍæ±ß׬£¨P2E£©ÓÎÏ·µÄÔ´´úÂëºÍ»õ±Ò£¬ÓÃÓÚʵÏÖÆä¹¥»÷Ä¿±ê¡£¿¨°Í˹»ùÖ¸³ö£¬LazarusÊÇ×î»îÔ¾¡¢×îÅÓ´óµÄAPT¹¥»÷ÕßÖ®Ò»£¬¾¼ÃÀûÒæÊÇÆäÖ÷Òª¶¯»ú£¬ÇÒÆä¼ÆıÔÚ²»Í£Ñݱ䣬ÀûÓÃÉú³ÉʽÈ˹¤ÖÇÄܵÈм¼ÊõÌᳫ¸üÅÓ´óµÄ¹¥»÷¡£
https://thehackernews.com/2024/10/lazarus-group-exploits-google-chrome.html
2. Fortinet FortiManager RCEÁãÈÕ©¶´ÔÚÒ°Íâ±»ÀûÓÃ
10ÔÂ24ÈÕ£¬ÍøÂçÄþ¾²¹«Ë¾Fortinet½üÈÕÅû¶ÁËÆäÈí¼þ²úÎïFortiManager´æÔÚÒ»¸öÒªº¦ÁãÈÕ©¶´£¨CVE-2024-47575£©£¬¸Ã©¶´ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýÌØÖÆÇëÇóÖ´ÐÐÈÎÒâ´úÂë»òÃüÁÇÒÒÑÔÚÒ°Íâ±»»ý¼«ÀûÓ᣸鶴µÄCVSS v3ÆÀ·Ö¸ß´ï9.8£¬Ó°Ïì¶à¸ö°æ±¾µÄFortiManager¼°FortiManager Cloud¡£FortinetÒÑÐû²¼²¹¶¡²¢ÌṩÁ˶àÖÖ½â¾öÒªÁì¡£¾Ý³ÂËߣ¬¸Ã©¶´Òѱ»ÓÃÓÚй¶Ãô¸ÐÎļþ£¬°üÂÞIPµØÖ·¡¢Æ¾Ö¤ºÍÉ豸ÅäÖ㬵«ÉÐδ·¢ÏÖ¶ñÒâÈí¼þ»òºóÃÅ°²×°¡£Íþв×éÖ¯UNC5820×Ô2024Äê6ÔÂ27ÈÕÆð¾ÍÀûÓôË©¶´£¬»ñÈ¡ÁËFortiGateÉ豸ÅäÖÃÊý¾Ý£¬°üÂÞÓû§¼ÓÃÜÃÜÂ룬¿ÉÄÜÓÃÓÚ½øÒ»²½ÆÆ»µºÍºáÏòÒƶ¯¡£MandiantÎÞ·¨È·¶¨¹¥»÷ÕßÉí·ÝºÍÄ¿µÄ£¬½¨ÒéËùÓÐ̻¶ÔÚ»¥ÁªÍøÉϵÄFortiManager×éÖ¯Á¢¼´½øÐÐÈ¡Ö¤ÊӲ졣Fortinet¶Ø´ÙÓû§Á¢¼´Éý¼¶ÖÁÄþ¾²°æ±¾£¬²¢½ÓÄÉ×èֹδ֪É豸ע²á¡¢Ê¹ÓÃ×Ô½ç˵֤ÊéÉí·ÝÑéÖ¤µÈ½â¾öÒªÁì¡£
https://cybersecuritynews.com/fortimanager-zero-day-vulnerability/#google_vignette
3. FogÓëAkiraÀÕË÷Èí¼þÀûÓÃSonicWall VPN©¶´Æµ·±ÈëÇÖÆóÒµÍøÂç
10ÔÂ27ÈÕ£¬FogºÍAkiraÀÕË÷Èí¼þÔËÓªÉÌÕýÔ½À´Ô½¶àµØÀûÓÃSonicWall VPNÕÊ»§ÈëÇÖÆóÒµÍøÂ磬Ҫº¦Â©¶´CVE-2024-40766±»ÈÏΪÊÇÆäÈëÇÖµÄÖ÷ҪͨµÀ¡£SonicWallÓÚ2024Äê8ÔÂÏÂÑ®ÐÞ¸´Á˸鶴£¬µ«Ò»Öܺó±ã¾¯¸æ³Æ©¶´Òѱ»»ý¼«ÀûÓᣱ±¼«ÀÇÄþ¾²Ñо¿ÈËÔ±·¢ÏÖ£¬AkiraÀÕË÷Èí¼þÁ¥Êô»ú¹¹ÒÑÀûÓø鶴»ñÈ¡³õʼ·ÃÎÊȨÏÞ¡£¾ÝArctic Wolf³ÂËߣ¬AkiraºÍFogÖÁÉÙ½øÐÐÁË30´ÎÈëÇÖ£¬¾ùʼÓÚͨ¹ýSonicWall VPNÕÊ»§Ô¶³Ì·ÃÎÊ¡£ÆäÖУ¬75%µÄ°¸¼þÓëAkiraÓйأ¬ÆäÓàΪFogËùΪ¡£ÕâÁ½¸ö×éÖ¯Ëƺõ¹²Ïí»ù´¡ÉèÊ©£¬±íÃ÷ÈÔ´æÔÚ·ÇÕýʽºÏ×÷¡£ËùÓб»¹¥ÆƵĶ˵㶼ÔËÐÐÒ×Êܹ¥»÷µÄδÐÞ²¹°æ±¾£¬ÇÒ´ÓÈëÇÖµ½Êý¾Ý¼ÓÃܵÄʱ¼äͨ³£½Ï¶Ì£¬×î¿ì½öÐè1.5-2Сʱ¡£ÍþвÐÐΪÕßͨ¹ýVPN/VPS·ÃÎʶ˵㲢»ìÏýÕæʵIPµØÖ·¡£ÊÜѬȾ×é֯δÆôÓöàÒòËØÉí·ÝÑéÖ¤£¬Ò²Î´ÔÚĬÈ϶˿ÚÉÏÔËÐзþÎñ¡£ÈëÇÖ¹ý³ÌÖУ¬ÊӲ쵽Ìض¨ÏûϢʼþID±íÃ÷Ô¶³ÌÓû§µÇ¼ºÍIP·ÖÅäÀֳɡ£ÍþвÐÐΪÕßÖ÷ÒªÕë¶ÔÐéÄâ»ú¼°Æ䱸·ÝÌᳫ¿ìËÙ¼ÓÃܹ¥»÷£¬²¢ÇÔÈ¡ÎĵµºÍרÓÐÈí¼þ£¬µ«²»¹Ø×¢Áè¼ÝÁù¸öÔ»ò30¸öÔµÄÎļþ¡£
https://www.bleepingcomputer.com/news/security/fog-ransomware-targets-sonicwall-vpns-to-breach-corporate-networks/
4. BlackBastaÀÕË÷Èí¼þÐж¯ÀûÓÃMicrosoft Teams½øÐÐÉç»á¹¤³Ì¹¥»÷
10ÔÂ25ÈÕ£¬BlackBastaÀÕË÷Èí¼þÐж¯×Ô2022Äê4ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬¶ÔÈ«ÇòÊý°ÙÆðÆóÒµ¹¥»÷ÂôÁ¦¡£¸Ã×é֯ͨ¹ý©¶´¡¢ºÏ×÷¡¢¶ñÒâÈí¼þ½©Ê¬ÍøÂçºÍÉç»á¹¤³ÌѧµÈ¶àÖÖÒªÁìÆÆ»µÍøÂç¡£×î½ü£¬BlackBastaµÄÁ¥Êô»ú¹¹½«Éç»á¹¤³Ì¹¥»÷תÒƵ½ÁËMicrosoft TeamsÉÏ£¬ËûÃÇð³ä¹«Ë¾IT×ÊÖų́ÁªÏµÔ±¹¤£¬ÐÖú½â¾öÀ¬»øÓʼþÎÊÌâ¡£¹¥»÷ÕßÊ×ÏÈÓõç×ÓÓʼþÑÍûԱ¹¤µÄÊÕ¼þÏ䣬ȻºóÒÔÍⲿÓû§µÄÉí·Ýͨ¹ýMicrosoft TeamsÁªÏµÔ±¹¤£¬ÕâЩÕÊ»§ÊÇÔÚEntra ID×⻧Ï´´½¨µÄ£¬Ãû³Æ¿´ÆðÀ´ÏñÊÇ×ÊÖų́¡£ÔÚÁÄÌìÖУ¬¹¥»÷Õß·¢ËͶþάÂë»òÓÕÆÓû§°²×°AnyDeskÔ¶³ÌÖ§³Ö¹¤¾ß»òÆô¶¯Windows Quick AssistÔ¶³Ì¿ØÖƺÍÆÁÄ»¹²Ïí¹¤¾ß£¬ÒÔ±ãÔ¶³Ì·ÃÎÊÓû§µÄ¹«Ë¾É豸¡£Ò»µ©Á¬½Ó£¬¹¥»÷Õ߻ᰲװÖÖÖÖÓÐЧÔغɣ¬ÈçScreenConnect¡¢NetSupport ManagerºÍCobalt Strike£¬ÒÔÁ¬ÐøÔ¶³Ì·ÃÎÊÓû§µÄ¹«Ë¾É豸£¬²¢ºáÏòÀ©É¢µ½ÆäËûÉ豸£¬Í¬Ê±ÌáÉýȨÏÞ¡¢ÇÔÈ¡Êý¾Ý£¬²¢×îÖÕ²¿ÊðÀÕË÷Èí¼þ¼ÓÃÜÆ÷¡£ReliaQuest½¨Òé×éÖ¯ÏÞÖÆMicrosoft TeamsÖÐÀ´×ÔÍⲿÓû§µÄͨÐÅ£¬²¢ÆôÓÃÈÕÖ¾¼Ç¼ÒÔ²éÕÒ¿ÉÒÉÁÄÌì¡£
https://www.bleepingcomputer.com/news/security/black-basta-ransomware-poses-as-it-support-on-microsoft-teams-to-breach-networks/
5. ÑÇÂíÑ·²é·âAPT29ºÚ¿Í×éÖ¯¹¥»÷ÓòÃû
10ÔÂ25ÈÕ£¬ÑÇÂíÑ·ÒѲé·â¶íÂÞ˹APT29ºÚ¿Í×éÖ¯ÓÃÓÚÕþ¸®ºÍ¾üÊÂ×éÖ¯Õë¶ÔÐÔ¹¥»÷µÄÓòÃû¡£APT29£¬Óֳơ°Cozy Bear¡±ºÍ¡°Midnight Blizzard¡±£¬Óë¶íÂÞ˹¶ÔÍâÇ鱨¾ÖÓÐÁªÏµ£¬Éó¤Ê¹ÓÃÍøÂçµöÓãºÍ¶ñÒâÈí¼þÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£´Ë´Î¹¥»÷ÖУ¬APT29ͨ¹ýαװ³ÉAWSÓòÃûµÄÍøÂçµöÓãÒ³Ã棬ÓÕÆÄ¿±êÏàÐŲ¢Ê¹ÓöñÒâÔ¶³Ì×ÀÃæÐÒéÁ¬½ÓÎļþ£¬ÒÔÇÔÈ¡Windowsƾ֤ºÍÊý¾Ý¡£¾¡¹ÜÑÇÂíÑ·³ÎÇåÆäÔÆƽ̨²¢·ÇÖ±½ÓÄ¿±ê£¬µ«ÈÔÁ¢¼´Æô¶¯Á˲é·âð³äAWSÓòÃûµÄ·¨Ê½¡£APT29ÒԸ߶ÈÅÓ´óµÄ¹¥»÷ÎÅÃû£¬Õë¶ÔÈ«ÇòÕþ¸®¡¢ÖÇ¿âºÍÑо¿»ú¹¹£¬ÇÒ×î½ü»î¶¯·¶Î§¹ã·º£¬°üÂÞÏò¸ü¶àÄ¿±ê·¢ËÍÍøÂçµöÓãµç×ÓÓʼþ¡£ÎÚ¿ËÀ¼¼ÆËã»úÓ¦¼±·´Ó³Ð¡×éÒ²Ðû²¼ÁËÏà¹Ø¾¯¸æ£¬²¢½¨Òé½ÓÄɶàÏî´ëÊ©¼õÉÙ¹¥»÷Ã棬Èç×èÖ¹¡°.rdp¡±Îļþ¡¢ÏÞÖÆRDPÁ¬½ÓµÈ¡£APT29ÈÔÊǶíÂÞ˹×îÇ¿´óµÄÍøÂçÍþв֮һ£¬¹ýÈ¥Ò»ÄêÖÐÔøÈëÇÖ¶à¸öÖØÒªÈí¼þ¹©Ó¦ÉÌ£¬²¢ÀûÓ÷þÎñÆ÷©¶´ÈëÇÖÈ«ÇòÖØÒª×éÖ¯¡£
https://www.bleepingcomputer.com/news/security/amazon-seizes-domains-used-in-rogue-remote-desktop-campaign-to-steal-data/
6. RansomHubºÚ¿Í×éÖ¯Éù³Æ¶ÔÄ«Î÷¸ç13¸ö»ú³¡ÔËÓªÉÌÌᳫ¹¥»÷
10ÔÂ26ÈÕ£¬ºÚ¿Í×éÖ¯RansomHub×î½üÉù³Æ¶ÔÄ«Î÷¸ç13¸ö»ú³¡ÔËÓªÉÌGrupo Aeroportuario del Centro Norte£¨OMA£©µÄÍøÂç¹¥»÷ÂôÁ¦£¬²¢ÍþвÈç¹û²»Ö§¸¶Êê½ð£¬½«Ð¹Â¶3TB±»µÁÊý¾Ý¡£OMAÔËÓª×ÅÄ«Î÷¸çÖв¿ºÍ±±²¿µØÓòµÄ»ú³¡£¬½ñÄêÒѽӴý³¬1900ÍòÃû´î¿Í¡£´Ë´ÎÍøÂçʼþÆÈʹOMAתÏò±¸ÓÃϵͳÒÔά³ÖÔËÓª£¬µ«ÏÔʾº½°àº½Õ¾Â¥Î»ÖõÄÆÁÄ»ÈÔÎÞ·¨Ê¹Óá£OMAÌåÏÖÕýÔÚÓëÍⲿÍøÂçÄþ¾²×¨¼ÒºÏ×÷ÊÓ²ìʼþ·¶Î§£¬²¢ÒÑÖð²½»Ö¸´Ä³Ð©·þÎñ£¬µ«¶Ô¹«Ë¾ÔËÓªºÍ²ÆÕþ×´¿öδÔì³ÉÖØ´óµ¹Ã¹Ó°Ï졣΢Èí±¾ÖÜÖ¸³ö£¬RansomHubÈÔÊÇÀÕË÷Èí¼þÁìÓò×î»îÔ¾µÄÍþв֮һ£¬¶à¸öÆäËûÍþвÐÐΪÕßÒ²¼ÌÐøʹÓÃÆä¶ñÒâÈí¼þ½øÐй¥»÷¡£
https://therecord.media/ransomhub-gang-behind-attack-mexican-airport-operator