¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.02.22-2021.02.28£©
2021-03-01
Ò»¡¢ Íþвͨ¸æ
VMware¶à¸ö¸ßΣÎó²î£¨CVE-2021-21972¡¢CVE-2021-21974£©
¡¾Ðû²¼Ê±¼ä¡¿2021-02-25 10:00:00 GMT
¡¾¸ÅÊö¡¿
2021Äê2ÔÂ23ÈÕ£¬VMware¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬Åû¶ÁËvSphere Client¡¢ESXiµÄÁ½¸ö¸ßΣÎó²î¡£CVE-2021-21972£ºvSphere Client£¨HTML5£©ÔÚvCenter Server²å¼þvRealize OperationsÖаüÀ¨Ò»¸öÔ¶³ÌÖ´ÐдúÂëÎó²î£¬CVSSv3ÆÀ·Ö9.8¡£ÊÜÓ°ÏìµÄvRealize Operations²å¼þΪĬÈÏ×°Öá£CVE-2021-21974£ºESXiÖÐʹÓõÄOpenSLP±£´æ¶ÑÒç³öÎó²î£¬CVSSv3ÆÀ·Ö8.8¡£ÓëESXi´¦ÓÚÍ³Ò»Íø¶ÎÖÐÇÒ¿ÉÒÔ»á¼û427¶Ë¿ÚµÄ¹¥»÷Õ߿ɴ¥·¢OpenSLP·þÎñÖеĶÑÒç³öÎÊÌ⣬´Ó¶øµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ¶ñÒâÀ©Õ¹³ÌÐòFriarFox»áÕìÌýFirefoxºÍGmailÏà¹ØÊý¾Ý
¡¾¸ÅÊö¡¿
¿ËÈÕÍøÂç¹¥»÷ͨ¹ýʹÓÃÃûΪFriarFox¶ñÒâÀ©Õ¹³ÌÐò¿ØÖÆÁËÊܺ¦ÕßµÄGmailÕÊ»§£¬¸Ã×Ô½ç˵¶ñÒâ³ÌÐòÊÇMozilla Firefoxä¯ÀÀÆ÷µÄÀ©Õ¹³ÌÐò¡£Ñо¿Ö°Ô±³Æ£¬ÔÚ2021Äê1ÔºÍ2ÔÂÊӲ쵽µÄÍþвÔ˶¯Õë¶Ô²Ø×å×éÖ¯£¬²¢ÓëTA413Óйأ¬TA413ÊÇÒ»¸öÓëÖйúÓйصÄÍþв×éÖ¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/malicious-mozilla-firefox-gmail/164263/
2. ¶íÂÞ˹ºÚ¿Í×éÖ¯°²ÅÅIronPython¶ñÒâÈí¼þ¼ÓÔØ³ÌÐò
¡¾¸ÅÊö¡¿
¶íÂÞ˹ºÚ¿Í×éÖ¯TurlaÕýÔÚ°²ÅÅÒ»¸ö»ùÓÚIronPythonµÄ¶ñÒâÈí¼þ¼ÓÔØÆ÷£¬³ÆÎªIronNetInjector£¬ÐµļÓÔØÆ÷ͨ¹ýʹÓÃIronPythonÖ±½ÓʹÓÃ.NET Framework APIÒÔ¼°Python¿âµÄÄÜÁ¦À´ÌṩComRAT£¨Ò»ÖÖÔ¶³Ì»á¼ûľÂí£©£¬¾ßÓлìÏý¶ñÒâÈí¼þ´úÂëÒÔ¼°¼ÓÃÜÏ¢ÕùÃÜNET×¢ÈëÆ÷ºÍÓÐÓÃÔØºÉµÄ¹¦Ð§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/russian-hacking-group-deploys-ironpython-malware-loader-a-16044
3. KUBERNETESZAO¼¯ÈºÔâÍÚ¿óľÂíͻϮ
¡¾¸ÅÊö¡¿
TeamTNTÊÇÒ»¸öÖ÷ÒªÈëÇÖÔÚÏßÈÝÆ÷²¢Í¨¹ýÍÚ¿óºÍDDoS¾ÙÐÐIJÀûµÄ¹¥»÷ÍŻ2021ÄêÄêÍ·£¬¸ÃÍŻﱻ·¢Ã÷ÈëÇÖÁËijKubernetes¼¯Èº£¬Í¨¹ýÍŽá¾ç±¾ºÍÏÖÓй¤¾ß£¬×îÖÕÔÚÈÝÆ÷ÄÚÖ²ÈëÍÚ¿óľÂí¡£Õë¶ÔKubernetes¼¯ÈºµÄ¹¥»÷ÊÂÎñ¼°ºóÐø±¬·¢ÔÚ¼¯ÈºÄÚ²¿µÄľÂíÈö²¥ÊÂÎñ£¬ÒÔ·ºÆðÍøÂçºÚ²úÍÅ»ïÕë¶ÔÔÚÏß¼¯ÈºµÄ¹¥»÷·½·¨¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/kuberneteszao%e9%9b%86%e7%be%a4%e9%81%ad%e6%8c%96%e7%9f%bf%e6%9c%a8%e9%a9%ac%e7%aa%81%e8%a2%ad/
4. LazyScripterÍþв×éÖ¯ÆÊÎö±¨¸æ
¡¾¸ÅÊö¡¿
LazyScripterÊÇÒ»¸öÐÂÍþв×éÖ¯£¬¿É×·ËÝÖÁ2018ÄêµÄÕë¶ÔÐÔÀ¬»øÓʼþÔ˶¯£¬Ê¹ÓÃÍøÂç´¹ÂÚÓÕ¶ü£¬ÓʼþÖ÷Ìâ²»µ«Õë¶Ô×·ÇóÒÆÃñµ½¼ÓÄôó¾ÍÒµµÄÈË£¬²¢ÇÒ»¹Õë¶Ôº½¿Õ¹«Ë¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/
5. LAZARUS¼ÈÍù¹¥»÷¹¤¾ßTORISMAÓëDRATZARUSÆÊÎö
¡¾¸ÅÊö¡¿
ÔÚ½ñÄê1ÔÂÓÉGoogleÅû¶µÄÒ»ÆðAPT¹¥»÷Ô˶¯ÖУ¬³¯ÏÊAPT×éÖ¯Lazarus¶ÔÌìϸ÷¹úµÄÇå¾²Ñо¿Ö°Ô±¾ÙÐÐÁ˺ã¾ÃµÄÉøÍ¸¹¥»÷¡£·üӰʵÑéÊÒ¶Ô¸ÃÊÂÎñÖзºÆðµÄ¹¥»÷ÔØºÉ¾ÙÐÐÁËÉîÈëÆÊÎö£¬²¢½«Ö÷ÌåľÂí³ÌÐòÃüÃûΪSTUMPzarus¡£STUMPzarusÓëLazarus×éÖ¯¼ÈÍù¹¥»÷¹¤¾ßÔÚ´úÂëÂß¼¡¢Í¨Ñ¶ÃûÌá¢CnCÃûÌõȷ½ÃæµÄ¸ß¶ÈÏàËÆÐÔ£¬²¢ÓÉ´Ë×ܽáÁËLazarus×éÖ¯¿ª·¢ÕßÔÚ³ÌÐòÉè¼ÆÉϵĴó×ÚÌØÕ÷¡£ÔÚ¹ØÁªÀú³ÌÖУ¬ÎÒÃÇÖ÷Òª²ÎÕÕµÄLazarus×éÖ¯¹¥»÷ÔØºÉ°üÀ¨TorismaÏÂÔØÕßľÂíºÍDRATzarusÔ¶¿ØÄ¾Âí¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/analysis-of-torisma-and-dratzarus-the-former-attack-tools-of-lazarus/
6. APT32Íþв×éÖ¯ÓÃÌØ¹¤Èí¼þ¹¥»÷ÈËȨº´ÎÀÕß
¡¾¸ÅÊö¡¿
ÓëÔ½ÄÏÓйصÄAPT32£¨ÓÖÃûº£Á«»¨£©×éÖ¯ÔÚ2018Äê2ÔÂÖÁ2020Äê11ÔÂÖ®¼äÕë¶ÔÔ½ÄÏȨº´ÎÀÕߣ¨HRD£©ºÍÒ»¸ö·ÇÓªÀû×éÖ¯£¨NPO£©ÈËȨ×éÖ¯¿ªÕ¹Á˺ã¾ÃÍøÂçÌØ¹¤Ô˶¯¡£APT32ÊÇÒ»¸ö´Ó2014×îÏÈ»îÔ¾ÖÁ½ñµÄÍþв×éÖ¯£¬Ö÷ÒªÕë¶Ô˽Æó¡¢Õþ¸®»ú¹¹¡¢³Ö²î±ðÕþ¼ûÈËÊ¿ºÍÐÂÎÅÊÂÇéÕߣ¬ÖØµã¹Ø×¢Ô½ÄÏ¡¢·ÆÂɱö¡¢ÀÏÎεȶ«ÄÏÑǹú¼Ò¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/114973/malware/apt32-spyware-human-rights-defenders.html
7. ÉÏÍòÃû΢Èíµç×ÓÓʼþÓû§Ôâ´¹ÂÚ¹¥»÷
¡¾¸ÅÊö¡¿
½üÆÚÓÐÕë¶ÔÖÁÉÙ10000¸ö΢Èíµç×ÓÓʼþÓû§µÄÍøÂç´¹ÂÚ¹¥»÷£¬¹¥»÷Õßð³äÀ´×Ô×ÅÃûµÄÓʼþ¿ìµÝ¹«Ë¾£¬°üÀ¨FedExºÍDHL Express£¬Ö¼ÔÚÇÔÈ¡Óû§µÄƾ֤ÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/microsoft-fedex-phishing-attack/164143/
8. FIN11ÍøÂç·¸·¨×éÖ¯Ö§³ÖÕë¶ÔFTA·þÎñÆ÷µÄ¹¥»÷
¡¾¸ÅÊö¡¿
FireEyeר¼ÒÒÔΪÕë¶ÔAccellion File Transfer Appliance£¨FTA£©·þÎñÆ÷µÄһϵÁй¥»÷ÓëÍøÂç·¸·¨×éÖ¯UNC2546£¨Ò²³ÆÎªFIN11£©Ïà¹Ø¡£×Ô2020Äê12ÔÂÖÐÑ®×îÏÈ£¬¹¥»÷ÕßʹÓÃAccellion File Transfer Appliance£¨FTA£©Èí¼þÖеĶà¸öÁãÈÕÎó²îÔÚÄ¿µÄÍøÂçÉϰ²ÅÅÃûΪDEWMODEµÄÍâ¿Ç£¬´ÓÄ¿µÄϵͳÖÐÇÔÈ¡Ãô¸ÐÊý¾Ý£¬È»ºóʹÓÃCLOPÀÕË÷Èí¼þÒªÇóÊܺ¦ÕßÒÔ±ÈÌØ±ÒÐÎʽ֧¸¶Êê½ð¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/114933/apt/fin11-fta-servers-atatcks.html
9. Ê®ÍòÃûCityBeeÓû§µÄµÇ¼ƾ֤Ôâ×ß©
¡¾¸ÅÊö¡¿
½üÆÚÖøÃûµÄÆû³µ¹²ÏíÆ½Ì¨CityBeeÔâÊÜÊý¾Ýй¶£¬°üÀ¨Áè¼Ý110,313µÄÃô¸ÐÊý¾Ý¡£ÆäÖÐÊÇÆä×¢²á¿Í»§µÄµÇ¼ƾ֤µÄСÎÒ˽¼ÒÊý¾Ý£¬°üÀ¨ÐÕÃû¡¢Ð¡ÎÒ˽¼ÒÃÜÂë¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþ¡¢ÆÜÉíµØµã¡¢¼ÝʻִÕÕºÅÂë¡¢¼ÓÃÜÃÜÂëµÈ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.hackread.com/citybee-database-login-credentials-leaked-online/

AG¹«Ë¾ÔÆ







