TA544ʹÓÃWikiLoaderÕë¶ÔÒâ´óÀûµÄÆóÒµ·Ö·¢Ursnif
Ðû²¼Ê±¼ä 2023-08-021¡¢TA544ʹÓÃWikiLoaderÕë¶ÔÒâ´óÀûµÄÆóÒµ·Ö·¢Ursnif
ProofpointÔÚ7ÔÂ31ÈÕÅû¶ÁËʹÓÃжñÒâÈí¼þWikiLoaderÕë¶ÔÒâ´óÀûÆóÒµµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£WikiLoaderÊÇÒ»¸öÖØ´óµÄÏÂÔØ³ÌÐò£¬£¬£¬£¬£¬ÓÉÓÚËü»áÏòWikipedia·¢³öÇëÇó²¢¼ì²éÏìÓ¦ÄÚÈÝÖÐÊÇ·ñ°üÀ¨×Ö·û´®¡°The Free¡±¶øµÃÃû¡£¡£¡£¡£¡£ProofpointÓÚ2022Äê12ÔÂ27ÈÕÊ×´ÎÔÚÒ°Íâ¼ì²âµ½¸Ã¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ÓÉTA544Èö²¥¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬ÖÁÉÙÓÐ8¸ö»î¶¯ÔÚ·Ö·¢WikiLoader£¬£¬£¬£¬£¬À´×ÔTA544ºÍTA551£¬£¬£¬£¬£¬¾ùÕë¶ÔÒâ´óÀûµÄ×éÖ¯¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ËäÈ»´ó´ó¶¼¹¥»÷ÕßÒѲ»ÔÙʹÓÃÆôÓúêµÄÎĵµÀ´Èö²¥¶ñÒâÈí¼þ£¬£¬£¬£¬£¬µ«TA544ÈÔÔÚ¹¥»÷Á´ÖÐʹÓÃËüÃÇ£¬£¬£¬£¬£¬°üÀ¨Èö²¥WikiLoader¡£¡£¡£¡£¡£
https://www.proofpoint.com/us/blog/threat-insight/out-sandbox-wikiloader-digs-sophisticated-evasion
2¡¢ÃÀ¹úÒÂÊι«Ë¾Hot TopicÔ⵽ײ¿â¹¥»÷й¶¿Í»§µÄÐÅÏ¢
¾ÝýÌå8ÔÂ1ÈÕ±¨µÀ£¬£¬£¬£¬£¬ÃÀ¹úÒÂÊμ°ÊÚȨÒôÀÖÁãÊÛÁ¬ËøµêHot Topic͸¶ÆäÔâµ½Á˶àÆð¹¥»÷ÊÂÎñ£¬£¬£¬£¬£¬µ¼Ö¿ͻ§µÄÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÃÀ¹úÓµÓÐ675¼ÒÊÐËÁ£¬£¬£¬£¬£¬ÒÔ¼°Ã¿Ô½ü1000Íò»á¼ûÁ¿µÄÔÚÏßÊÐËÁ¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ú¹ÊÍ˵£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃÇÔÈ¡µÄÕÊ»§Æ¾Ö¤¶à´Î»á¼ûÁËRewardsƽ̨£¬£¬£¬£¬£¬¿ÉÄÜ»ñµÃÁ˿ͻ§µÄÊý¾Ý¡£¡£¡£¡£¡£¾ÊӲ죬£¬£¬£¬£¬¹¥»÷ÕßÓÚ2023Äê2ÔÂ7ÈÕ¡¢3ÔÂ11ÈÕ¡¢5ÔÂ19ÈÕÖÁ21ÈÕ¡¢5ÔÂ27ÈÕÖÁ28ÈÕºÍ6ÔÂ18ÈÕÖÁ21ÈÕ£¬£¬£¬£¬£¬Ê¹ÓÃÓÐÓÃÕÊ»§Æ¾Ö¤¶ÔÍøÕ¾ºÍÒÆ¶¯Ó¦ÓÃÖ´ÐÐÁË×Ô¶¯¹¥»÷¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬Hot Topic²»ÊÇй¶ƾ֤µÄȪԴ£¬£¬£¬£¬£¬µ«Ò²ÎÞ·¨ÕÒµ½ÈªÔ´¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/retail-chain-hot-topic-discloses-wave-of-credential-stuffing-attacks/
3¡¢Henry Ford HealthÔâ´¹ÂÚ¹¥»÷½ü17Íò»¼ÕßÐÅϢй¶
¾Ý7ÔÂ27ÈÕ±¨µÀ£¬£¬£¬£¬£¬ÃÀ¹úµÄѧÊõÒ½ÁÆ»úHenry Ford Health³ÆÆä3ÃûÔ±¹¤Ôâµ½´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬Ó°ÏìÁË168215¸ö»¼ÕßµÄÐÅÏ¢¡£¡£¡£¡£¡£¸Ã»ú¹¹ÔÚÉùÃ÷ÖÐÌåÏÖ£¬£¬£¬£¬£¬¹¥»÷ÊÂÎñ±¬·¢ÓÚ3ÔÂ30ÈÕ£¬£¬£¬£¬£¬¸Ã×éÖ¯Òѽ«±»Ó°ÏìµÄµç×ÓÓʼþÕÊ»§±£»£»£»£»£»£»¤ÆðÀ´²¢Õö¿ªÊӲ졣¡£¡£¡£¡£5ÔÂ16£¬£¬£¬£¬£¬È·¶¨»¼ÕߵĿµ½¡ÐÅÏ¢°üÀ¨ÔÚµç×ÓÓÊÏäÖУ¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜÒѱ»¹¥»÷ÕßÇÔÈ¡£¬£¬£¬£¬£¬Éæ¼°ÐÕÃû¡¢ÊµÑéÊÒЧ¹û¡¢ÊÖÊõÀàÐÍ¡¢Õï¶Ï¡¢µç»°ºÅÂë¡¢²¡ÀúºÅºÍÄÚ²¿¸ú×ٺŵÈÐÅÏ¢¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬ËûÃÇÕýÔÚʵÑéÌØÁíÍâÇå¾²²½·¥£¬£¬£¬£¬£¬²¢½«ÎªÔ±¹¤ÌṩÇå¾²Åàѵ¡£¡£¡£¡£¡£
https://www.bankinfosecurity.com/phishing-scam-affects-nearly-170k-henry-ford-health-patients-a-22672
4¡¢Cado·¢Ã÷¿ÉÕë¶ÔRedisЧÀÍÆ÷µÄP2PInfectÈ䳿бäÌå
7ÔÂ31ÈÕ£¬£¬£¬£¬£¬Cado·¢Ã÷ÁËÒ»ÖÖÕë¶ÔRedisµÄÐÂÐͶñÒâÈí¼þ»î¶¯¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ±»¿ª·¢ÕßÃüÃûΪP2Pinfect£¬£¬£¬£¬£¬ÓÃRust¿ª·¢£¬£¬£¬£¬£¬³äµ±½©Ê¬ÍøÂçÊðÀí¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÆÊÎöµÄÑù±¾°üÀ¨Ò»¸öǶÈëʽPEÎļþÒÔ¼°Ò»¸öELF¶þ½øÖÆÎļþ£¬£¬£¬£¬£¬ÕâÅú×¢ÎúWindowsºÍLinuxÖ®¼ä¾ßÓÐ¿çÆ½Ì¨¼æÈÝÐÔ¡£¡£¡£¡£¡£Ëü»¹Ê¹Óø´Öƹ¦Ð§À´¹¥»÷RedisÊý¾Ý´æ´¢µÄʵÀý¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬P2PinfectÊÔͼͨ¹ýCronδ¾Éí·ÝÑéÖ¤µÄRCE»úÖÆ¹¥»÷RedisÖ÷»ú¡£¡£¡£¡£¡£¸Ã»î¶¯±³ºóµÄ¹¥»÷ÕßÉí·ÝÉв»ÇåÎú£¬£¬£¬£¬£¬P2PInfectµÄÄ¿µÄÒ²²»ÇåÎú¡£¡£¡£¡£¡£
https://www.cadosecurity.com/redis-p2pinfect/
5¡¢Minecraft modÎó²îBleedingPipeÒѱ»´ó¹æÄ£Ê¹ÓÃ
ýÌå7ÔÂ31ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬ºÚ¿ÍÕýÔÚʹÓÃMinecraft modÖеÄRCEÎó²îBleedingPipeÔÚЧÀÍÆ÷ºÍ¿Í»§¶ËÖ´ÐжñÒâÏÂÁ£¬£¬£¬£¬´Ó¶ø¿ØÖÆ×°±¸¡£¡£¡£¡£¡£BleedingPipeÎó²î×î³õÓÚ2022Äê3Ô±»Ê¹Ó㬣¬£¬£¬£¬µ«ºÜ¿ì¾Í±»mod¿ª·¢ÕßÐÞ¸´ÁË¡£¡£¡£¡£¡£È»¶øÔÚ7ÔÂÔçЩʱ¼ä£¬£¬£¬£¬£¬ForgeÂÛ̳µÄһƪÌû×ӳƣ¬£¬£¬£¬£¬ÓÐÈËʹÓÃδ֪RCEÀ´´ó¹æÄ£ÇÔÈ¡Íæ¼ÒµÄDiscordºÍSteam»á»°cookie¡£¡£¡£¡£¡£½øÒ»²½Ñо¿·¢Ã÷£¬£¬£¬£¬£¬¶à¸öMinecraft modÖÐÒ²±£´æBleedingPipeÎó²î¡£¡£¡£¡£¡£¹¥»÷ÕßÕýÔÚɨÃèÊܸÃÎó²îÓ°ÏìµÄMinecraftЧÀÍÆ÷²¢Ö´Ðй¥»÷£¬£¬£¬£¬£¬Òò´ËÐÞ¸´Ð§ÀÍÆ÷ÉÏÒ×±»¹¥»÷µÄmodÖÁ¹ØÖ÷Òª¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-bleedingpipe-rce-to-target-minecraft-servers-players/
6¡¢Bahamutͨ¹ýð³äµÄAndroidÓ¦ÓÃSafeChatÇÔÊØÐÅÏ¢
7ÔÂ28ÈÕ£¬£¬£¬£¬£¬CYFIRMA³ÆÆä·¢Ã÷ÁËÒ»¸ö¿ÉÒɵÄAndroid¶ñÒâÈí¼þ£¬£¬£¬£¬£¬Î±×°³ÉÐéαµÄ̸ÌìÓ¦ÓÃSafeChat£¬£¬£¬£¬£¬ÇÔÈ¡ÊÖ»úµÄͨ»°¼Í¼¡¢¶ÌÐźÍGPSλÖõÈÊý¾Ý¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ±»ÏÓÒÉÊÇCoverlmµÄ±äÖÖ£¬£¬£¬£¬£¬»áÇÔÈ¡Telegram¡¢Signal¡¢WhatsApp¡¢ViberºÍFacebook MessengerµÈͨѶӦÓõÄÊý¾Ý¡£¡£¡£¡£¡£¸Ã»î¶¯ÓëÓ¡¶ÈºÚ¿ÍÍÅ»ïBahamutÓйأ¬£¬£¬£¬£¬Ö÷Ҫͨ¹ýWhatsAppÉϵÄÓã²æÊ½´¹ÂÚÐÂΞÙÐУ¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÄÏÑǵØÇø¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¸Ã»î¶¯ÓëÓ¡¶ÈµÄÁíÒ»¸öºÚ¿ÍÍÅ»ïDoNotµÄ»î¶¯ÓÐÏàËÆÖ®´¦¡£¡£¡£¡£¡£
https://www.cyfirma.com/outofband/apt-bahamut-targets-individuals-with-android-malware-using-spear-messaging/


¾©¹«Íø°²±¸11010802024551ºÅ