Unit 42Åû¶Õë¶ÔÃÀ¹ú¹ú·À³Ð°üÉ̵ĺóÃÅSockDetourµÄϸ½Ú
Ðû²¼Ê±¼ä 2022-03-01Unit 42Åû¶Õë¶ÔÃÀ¹ú¹ú·À³Ð°üÉ̵ĺóÃÅSockDetourµÄϸ½Ú
2ÔÂ24ÈÕ£¬£¬£¬Unit 42Ñо¿Ö°Ô±·¢ÎÄ³ÆÆäÔÚ¸ú×ÙAPT»î¶¯TiltedTempleʱ·¢Ã÷ÁËкóÃÅSockDetour¡£¡£¡£¡£¸ÃºóÃÅÖÁÉÙ×Ô2019Äê7Ô¾ÍÒѾ±£´æ£¬£¬£¬Ö÷Òª±»ÓÃ×÷±¸·ÝºóÃÅÒÔ·ÀÖ÷ºóÃű»É¾¡£¡£¡£¡£ÒòÆäÔÚÄ¿µÄWindowsЧÀÍÆ÷ÉÏÎÞÎļþÇÒÎÞÌ×½Ó×ÖµØÔËÐУ¬£¬£¬ÒÔÊǺÜÄѱ»¼ì²âµ½¡£¡£¡£¡£¾ÝϤ£¬£¬£¬´Ë´Î»î¶¯Ö÷ÒªÃé×¼ÃÀ¹úµÄ¹ú·À³Ð°üÉÌ£¬£¬£¬ÏÖÔÚÖÁÉÙÓÐ4¼Ò´ËÀ๫˾Ôâµ½¹¥»÷¡£¡£¡£¡£ËäÈ»ÉÐ佫ºóÃÅSockDetour¹éÒòÓÚÈκκڿÍ×éÖ¯£¬£¬£¬µ«TiltedTemple»î¶¯ÓëAPT27Óйء£¡£¡£¡£
https://unit42.paloaltonetworks.com/sockdetour/
Ӣΰ´ï³ÆÆäÕýÔÚÊӲ쵼Ö²¿·ÖϵͳÖÐÖ¹2ÌìµÄ¹¥»÷ÊÂÎñ
¾ÝýÌå2ÔÂ25ÈÕ±¨µÀ£¬£¬£¬GPUÖÆÔìÉÌӢΰ´ï£¨Nvidia£©ÕýÔÚÊӲ쵼Ö²¿·ÖϵͳÖÐÖ¹2ÌìµÄ¹¥»÷ÊÂÎñ¡£¡£¡£¡£´Ë´Î¹¥»÷Ó°ÏìÁ˹«Ë¾µÄ¿ª·¢Ö°Ô±¹¤¾ßºÍµç×ÓÓʼþϵͳ£¬£¬£¬µ«ÓªÒµºÍÉÌÒµ»î¶¯²¢Î´Êܵ½Ó°Ïì¡£¡£¡£¡£Éв»ÇåÎúÊÇ·ñÓÐÓªÒµ»ò¿Í»§µÄÐÅÏ¢±»µÁ£¬£¬£¬¸Ã¹«Ë¾ÏÖÔÚÈÔÔÚÆÀ¹ÀÊÂÎñµÄÐÔ×Ӻ͹æÄ£¡£¡£¡£¡£2ÔÂ26ÈÕ£¬£¬£¬Lapsus$ÍÅ»ïÉù³ÆËûÃÇÒÑÈëÇÖNvidiaµÄÍøÂç²¢ÇÔÈ¡ÁË1TBµÄÊý¾Ý£¬£¬£¬»¹¹ûÕæÁËNvidiaËùÓÐÔ±¹¤µÄÃÜÂë¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/gpu-giant-nvidia-is-investigating-a-potential-cyberattack/
NHS±Þ²ßÓû§ÐÞ¸´Okta¿Í»§¶ËÖеÄRCE CVE-2022-24295
Ó¢¹úNHSÊý×Ö»ú¹¹ÔÚ2ÔÂ24ÈÕÐû²¼ÁËͨ¸æ£¬£¬£¬±Þ²ßÓû§¾¡¿ìÐÞ¸´Okta Advanced Server Access Éí·ÝÑéÖ¤ÖÎÀíÆ½Ì¨ÖеÄRCEÎó²î¡£¡£¡£¡£¸ÃÎó²î×·×ÙΪCVE-2022-24295£¬£¬£¬¿ÉÓÃÀ´Í¨¹ýÌØÖÆURLÖ´ÐÐÏÂÁî×¢È룬£¬£¬ÀÖ³ÉʹÓÿɵ¼ÖÂÍêÈ«¿ØÖÆÏµÍ³¡¢Ö´Ðо²Ä¬µÄÊý¾Ýй¶¡¢ºáÏòÒÆ¶¯ÒÔ¼°¶Ô¹«Ë¾ÍøÂçµÄ³õʼ»á¼û¡£¡£¡£¡£NHS»¹ÌáÐÑÖÎÀíÔ±£¬£¬£¬OktaµÄ¼¸¸ö²úÆ·Ò²Êܵ½Log4ShellÎó²îµÄÓ°Ïì¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/nhs-urges-orgs-to-apply-security-update-for-okta-client-rce-bug/
CISAÐû²¼¹ØÓÚÒÁÀÊMuddyWaterµÄÌØ¹¤»î¶¯µÄͨ¸æ
2ÔÂ24ÈÕ£¬£¬£¬CISA¡¢FBI¡¢CNMF¡¢NCSC-UKºÍNSAÐû²¼ÁËÒ»·ÝÁªºÏÍøÂçÇå¾²×Éѯ¡£¡£¡£¡£¸Ã×ÉѯÅû¶ÁËÒÁÀÊAPT×éÖ¯MuddyWatterÔÚÕë¶ÔÈ«ÇòÒªº¦»ù´¡ÉèÊ©µÄ¹¥»÷ÖÐʹÓõÄжñÒâÈí¼þµÄÐÅÏ¢¡£¡£¡£¡£¸Ã»î¶¯Õë¶ÔÑÇÖÞ¡¢·ÇÖÞ¡¢Å·Ö޺ͱ±ÃÀµÄµçÐÅ¡¢¹ú·À¡¢Ê¯ÓÍ¡¢×ÔÈ»ÆøÐÐÒµºÍµØ·½Õþ¸®×éÖ¯£¬£¬£¬Ê¹ÓÃÁËÖîÈçPowGoop¡¢Canopy/Starwhale¡¢Mori¡¢POWERSTATSµÈ¶àÖÖ¶ñÒâÈí¼þ¡£¡£¡£¡£Í¨¸æ»¹ÖصãÏÈÈÝÁËPythonºóÃÅSmall SieveºÍÓÃÓÚ¼ÓÃÜC2ͨѶͨµÀµÄÒ»¸öPowerShellºóÃÅ¡£¡£¡£¡£
https://www.cisa.gov/uscert/ncas/current-activity/2022/02/24/iranian-government-sponsored-muddywater-actors-conducting
Check PointÐû²¼Ð¶ñÒâÈí¼þElectron BotµÄÆÊÎö±¨¸æ
2ÔÂ24ÈÕ£¬£¬£¬Check Point Research(CPR)Åû¶ÁËжñÒâÈí¼þElectron BotµÄÊÖÒÕϸ½Ú¡£¡£¡£¡£¸Ã»î¶¯»î¶¯Ê¼ÓÚ2018Äêµ×£¬£¬£¬Î±Ôì³É2Temple RunºÍSubway SurferµÈÈÈÃÅÓÎÏ·£¬£¬£¬Í¨¹ýMicrosoft Store¾ÙÐÐÈö²¥£¬£¬£¬ÏÖÔÚÒÑѬȾÁËÈðµä¡¢±£¼ÓÀûÑÇ¡¢¶íÂÞ˹¡¢°ÙĽ´óºÍÎ÷°àÑÀµÄ5000¶ą̀ÅÌËã»ú¡£¡£¡£¡£Electron BotÊÇÒ»ÖÖÄ£¿£¿£¿£¿£¿é»¯µÄ SEO Öж¾¶ñÒâÈí¼þ£¬£¬£¬Ö÷ÒªÓÃÓÚÉ罻ýÌåÍÆ¹ãºÍµã»÷ڲƻ¡£¡£¡£¡£
https://research.checkpoint.com/2022/new-malware-capable-of-controlling-social-media-accounts-infects-5000-machines-and-is-actively-being-distributed-via-gaming-applications-on-microsofts-official-store/
CiscoÐû²¼Çå¾²¸üУ¬£¬£¬ÐÞ¸´Æä¶à¸ö²úÆ·ÖеÄÎó²î
2ÔÂ23ÈÕ£¬£¬£¬CiscoÐû²¼Çå¾²¸üУ¬£¬£¬ÐÞ¸´Á˶à¿î²úÆ·ÖеÄÎó²î¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇ˼¿ÆNX-OSÈí¼þNX-APIÏÂÁî×¢ÈëÎó²î£¨CVE-2022-20650£©£¬£¬£¬Ô´ÓÚ¶ÔÓû§ÌṩµÄÊý¾Ýȱ·¦×ã¹»µÄÊäÈëÑéÖ¤£»£»£»£»ÒÔ¼°Cisco Fabric Services Over IP (CFSoIP)ÖеľܾøÐ§ÀÍÎó²î£¨CVE-2022-20624£©ºÍNexus 9000ϵÁн»Á÷»úË«Ïòת·¢¼ì²â(BFD)Á÷Á¿¹¦Ð§ÖеľܾøÐ§ÀÍÎó²î£¨CVE-2022-20623£©¡£¡£¡£¡£
https://thehackernews.com/2022/02/new-flaws-discovered-in-ciscos-network.html
Çå¾²¹¤¾ß
Win Brute Logon
ÔÚûÓÐÈκÎȨÏÞµÄÇéÐÎÏÂÆÆ½âÈκΠMicrosoft Windows Óû§ÃÜÂ루°üÀ¨·Ã¿ÍÕÊ»§£©¡£¡£¡£¡£
https://github.com/DarkCoderSc/win-brute-logon
PHP Malware Finder
¾¡ÆäËùÄܵؼì²âÄ£ºýµÄ´úÂ룬£¬£¬ÒÔ¼°ÔÚ¶ñÒâÈí¼þºÍwebshellÖо³£Ê¹ÓõÄPHPº¯ÊýÎļþ¡£¡£¡£¡£
https://github.com/jvoisin/php-malware-finder
LDAP Password Hunter
Ëü°ü×°ÁË getTGT.py (Impacket) ºÍ ldapsearch µÄ¹¦Ð§£¬£¬£¬ÒÔ±ã²éÕÒ´æ´¢ÔÚ LDAP Êý¾Ý¿âÖеÄÃÜÂë¡£¡£¡£¡£
https://github.com/oldboy21/LDAP-Password-Hunter
Collabfiltrator
ÊÇÒ»ÖÖͨ¹ý Burp Collaborator ͨ¹ý DNS ÇÔȡԶ³Ì´úÂëÖ´ÐÐÊä³öµÄ¹¤¾ß
https://packetstormsecurity.com/files/166062/Collabfiltrator-2.1.zip
ostorlab
Ò»¸öÇ徲ɨÃèÆ½Ì¨£¬£¬£¬Äܹ»ÒÔ¼òÆÓ¡¢¿ÉÀ©Õ¹ºÍÂþÑÜʽµÄ·½·¨ÔËÐÐÉæ¼°¶à¸ö¹¤¾ßµÄÖØ´óÇ徲ɨÃèʹÃü¡£¡£¡£¡£
https://docs.ostorlab.co/
Çå¾²ÆÊÎö
΢ÈíÖÒÑÔÐ嵀 Windows 11 ÖØÖùýʧ
https://news.softpedia.com/news/microsoft-warns-of-new-windows-11-reset-bug-534943.shtml
Ãâ·ÑµÄ Android Ó¦ÓÿÉÈüì²â Apple AirTag ¸ú×Ù
https://www.bleepingcomputer.com/news/security/free-android-app-lets-users-detect-apple-airtag-tracking/
Android É쵀 Visual Voice Mail ¿ÉÄÜÈÝÒ×±»ÇÔÌý
https://www.bleepingcomputer.com/news/security/visual-voice-mail-on-android-may-be-vulnerable-to-eavesdropping/
΢Èí£º1 Ô Windows Server ¸üе¼Ö Netlogon ÎÊÌâ
https://www.bleepingcomputer.com/news/microsoft/microsoft-january-windows-server-updates-cause-netlogon-issues/
ÍøÂçºÚ¿ÍרעÓÚÔÚÃÀ¹úÏúÊ۸߼ÛֵĿµÄ
https://www.bleepingcomputer.com/news/security/network-hackers-focus-on-selling-high-value-targets-in-the-us/


¾©¹«Íø°²±¸11010802024551ºÅ