¶à¹úÁªºÏÖ´·¨Ðж¯TOURNIQUETµ·»Ù°µÍøRaidForums

Ðû²¼Ê±¼ä 2022-04-14

1¡¢¶à¹úÁªºÏÖ´·¨Ðж¯TOURNIQUETµ·»Ù°µÍøRaidForums


¾ÝýÌå4ÔÂ12ÈÕ±¨µÀ£¬£¬ £¬£¬£¬£¬ £¬£¬¹ú¼ÊÖ´·¨Ðж¯TOURNIQUETÒѵ·»Ùµ·»Ù°µÍøRaidForums¡£¡£¡£´Ë´ÎÐж¯ÓÉÅ·ÖÞÐ̾¯×é֯Эµ÷£¬£¬ £¬£¬£¬£¬ £¬£¬Éæ¼°ÃÀ¹ú¡¢Ó¢¹ú¡¢Èðµä¡¢ÆÏÌÑÑÀºÍÂÞÂíÄáÑǵÄÖ´·¨»ú¹¹¡£¡£¡£RaidForumsµÄÊ×´´ÈË£¬£¬ £¬£¬£¬£¬ £¬£¬ÆÏÌÑÑÀµÄDiogo Santos Coelho£¨ÓÖÃûOmnipotent£©ÒÑÓÚ1ÔÂ31ÈÕÔÚÓ¢¹ú±»²¶£¬£¬ £¬£¬£¬£¬ £¬£¬Ëû½ñÄê21Ë꣬£¬ £¬£¬£¬£¬ £¬£¬ÕâÒâζ×ÅËûÔÚ2015ÄêÍÆ³öRaidForumsʱÄê½öÓÐ14Ëê¡£¡£¡£ÏÖÔÚ£¬£¬ £¬£¬£¬£¬ £¬£¬¾¯·½ÒѲé»ñÁËÈý¸öÍйÜRaidForumµÄÓòraidforums.com¡¢Rf.wsºÍRaid.Lol¡£¡£¡£


https://securityaffairs.co/wordpress/130131/deep-web/authorities-shut-down-raidforums.html


2¡¢HPÐÞ¸´Teradici PCoIPÖÐÓ°Ïì1500Íò×°±¸µÄ¶à¸öÎó²î


»ÝÆÕÔÚ4ÔÂ11ÈÕÐû²¼Çå¾²¸üУ¬£¬ £¬£¬£¬£¬ £¬£¬ÐÞ¸´Windows¡¢Linux ºÍmacOSµÄTeradici PCoIP¿Í»§¶ËºÍÊðÀíÖеÄ10¸öÎó²î¡£¡£¡£Teradici PCoIP£¨PC over IP£©ÊÇÒ»ÖÖÔ¶³Ì×ÀÃæÐ­Ò飬£¬ £¬£¬£¬£¬ £¬£¬ÒÑ×°ÖÃÔÚ15000000¸ö×°±¸ÖС£¡£¡£´Ë´ÎÐÞ¸´µÄ×îÑÏÖØµÄÎó²îÖ®Ò»ÊÇOpenSSLÖÐÓÉÆÊÎö¶ñÒâÖ¤Êéµ¼ÖµľܾøÐ§ÀÍÎó²î£¨CVE-2022-0778£©¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬ £¬£¬»¹ÐÞ¸´ÁËlibexpatÖеÄ3¸öÕûÊýÒç³öÎó²î£¨CVE-2022-22822¡¢CVE-2022-22823ºÍCVE-2022-22824£©£¬£¬ £¬£¬£¬£¬ £¬£¬¿ÉÄܵ¼ÖÂÎÞ·¨¿ØÖƵÄ×ÊÔ´ÏûºÄ¡¢È¨ÏÞÌáÉýºÍÔ¶³Ì´úÂëÖ´ÐС£¡£¡£


https://www.bleepingcomputer.com/news/security/critical-hp-teradici-pcoip-flaws-impact-15-million-endpoints/


3¡¢HafniumÍÅ»ïʹÓÃжñÒâÈí¼þTarraskÀ´ÈƹýÇå¾²¼ì²â


4ÔÂ12ÈÕ£¬£¬ £¬£¬£¬£¬ £¬£¬Î¢ÈíÐû²¼µÄ×îÐÂÑо¿Ð§¹ûÅû¶Á˺ڿÍÍÅ»ïHafniumʹÓõÄжñÒâÈí¼þTarraskµÄÏêϸÐÅÏ¢¡£¡£¡£Î¢ÈíÓÚ2021Äê8Ôµ½2022Äê2ÔÂʱ´ú£¬£¬ £¬£¬£¬£¬ £¬£¬·¢Ã÷¸ÃÍÅ»ïÕë¶ÔµçÐÅ¡¢»¥ÁªÍøÐ§ÀÍÌṩÉ̺ÍÊý¾ÝЧÀ͵ÈÁìÓòµÄ¹¥»÷»î¶¯¡£¡£¡£½øÒ»²½µÄÊÓ²ìÏÔʾ£¬£¬ £¬£¬£¬£¬ £¬£¬¹¥»÷ÕßʹÓÃÁËÓÃÀ´ºáÏòÒÆ¶¯ºÍÖ´ÐеŤ¾ßImpacket£¬£¬ £¬£¬£¬£¬ £¬£¬ÒÔ¼°ÃûΪTarraskµÄжñÒâÈí¼þ¡£¡£¡£TarraskʹÓÃÁËÒ»¸öÒÔǰδ֪µÄWindowsÎó²î£¬£¬ £¬£¬£¬£¬ £¬£¬Í¨¹ýɾ³ýÏà¹ØµÄÇå¾²ÐÎò·û×¢²á±íÖµÀ´½«Æä´Ó¡°schtasks /query¡±ºÍʹÃüÍýÏë³ÌÐòÖÐÒþ²ØÆðÀ´¡£¡£¡£


https://www.microsoft.com/security/blog/2022/04/12/tarrask-malware-uses-scheduled-tasks-for-defense-evasion/


4¡¢SandwormʹÓÃIndustroyer2¹¥»÷ÎÚ¿ËÀ¼Ä³ÄÜÔ´¹«Ë¾


ESETÔÚ4ÔÂ12ÈÕÐû²¼±¨¸æ³Æ£¬£¬ £¬£¬£¬£¬ £¬£¬SandwormʹÓÃIndustroyer2¹¥»÷ÎÚ¿ËÀ¼Ä³ÄÜÔ´¹«Ë¾¡£¡£¡£Industroyer2ÊÇICS¶ñÒâÈí¼þIndustroyerµÄбäÌ壬£¬ £¬£¬£¬£¬ £¬£¬ºóÕßÔøÔÚ2016Äê±»ÓÃÓÚÖÐÖ¹ÎÚ¿ËÀ¼µÄµçÁ¦¹©Ó¦¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬ £¬£¬¹¥»÷Õß»¹Ê¹ÓÃÁËÕë¶ÔLinuxºÍSolarisϵͳµÄOrcshred¡¢SoloshredºÍAwfulshredµÈ¶ñÒâÈí¼þ¼Ò×å¡£¡£¡£ÏÖÔÚ£¬£¬ £¬£¬£¬£¬ £¬£¬¹¥»÷ÕßÈëÇÖÄ¿µÄÒÔ¼°´ÓITÏµÍ³×ªÒÆµ½¹¤Òµ¿ØÖÆÏµÍ³(ICS)µÄ·½·¨Éв»Ã÷È·¡£¡£¡£ 


https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/


5¡¢Ñо¿ÍŶӷ¢Ã÷Õë¶Ô·ÇÖÞ½ðÈÚ»ú¹¹·Ö·¢RemcosRATµÄ´¹Âڻ


4ÔÂ12ÈÕ£¬£¬ £¬£¬£¬£¬ £¬£¬HP Wolf Security¹ûÕæÁËÕë¶Ô·ÇÖÞ½ðÈÚ»ú¹¹µÄ´¹Âڻ¡£¡£¡£´Ë´Î»î¶¯Ö÷ÒªÃé×¼ÒøÐеÄÔ±¹¤£¬£¬ £¬£¬£¬£¬ £¬£¬´¹ÂÚÓʼþαװ³ÉÀ´×ÔÁíÒ»¹«Ë¾£¨Í¨³£ÊǵÐÊÖÒøÐУ©£¬£¬ £¬£¬£¬£¬ £¬£¬Éù³ÆÎªÊÕ¼þÈËÌṩÁËÒ»·Ý³ê½ð·á¸»µÄÊÂÇéʱ»ú£¬£¬ £¬£¬£¬£¬ £¬£¬Ä¿µÄµã»÷ÓʼþÖÐÅþÁ¬ºó»á±»Öض¨Ïòµ½´¹ÂÚÍøÕ¾¡£¡£¡£´Ë´Î»î¶¯Ê¹ÓÃHTML×ß˽À´×°ÖöñÒâÈí¼þpayload£¬£¬ £¬£¬£¬£¬ £¬£¬ÔÚ¾­ÓÉһϵÁжñÒâ´úÂëÖ´ÐкÍWindows APIÀÄÓú󣬣¬ £¬£¬£¬£¬ £¬£¬»áÔÚϵͳÉÏÏÂÔØ²¢Ö´ÐÐGuLoader£¬£¬ £¬£¬£¬£¬ £¬£¬×îÖÕÖ¼ÔÚÏÂÔØRemcosRAT¡£¡£¡£


https://threatresearch.ext.hp.com/malware-campaigns-targeting-african-banking-sector/#


6¡¢KasperskyÐû²¼2021Äê¸ú×ÙÈí¼þÌ¬ÊÆµÄÆÊÎö±¨¸æ


4ÔÂ12ÈÕ£¬£¬ £¬£¬£¬£¬ £¬£¬KasperskyÐû²¼Á˹ØÓÚ2021Äê¸ú×ÙÈí¼þ£¨Stalkerware£©Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¾ÝKasperskyÊý¾ÝÏÔʾ£¬£¬ £¬£¬£¬£¬ £¬£¬2021ÄêÔÚÈ«ÇòÓÐ32694ÃûÓû§Êܵ½¸ú×ÙÈí¼þµÄÓ°Ï죬£¬ £¬£¬£¬£¬ £¬£¬Õâ±È2020ÄêµÄÊý×ÖÓÐËùïÔÌ­£¬£¬ £¬£¬£¬£¬ £¬£¬ÍøÂ籩Á¦³ÊÉÏÉýÇ÷ÊÆ¡£¡£¡£ÊÜÓ°Ïì×îÑÏÖØµÄ¹ú¼ÒÈÔÈ»ÊǶíÂÞ˹¡¢°ÍÎ÷ºÍÃÀ¹ú£¬£¬ £¬£¬£¬£¬ £¬£¬ÕâÓëÒÑÍùÁ½ÄêµÄͳ¼ÆÊý¾ÝÒ»Ö¡£¡£¡£CerberusºÍReptilecusÊÇʹÓÃ×î¶àµÄ¸ú×ÙÈí¼þÓ¦Ó㬣¬ £¬£¬£¬£¬ £¬£¬ÔÚÈ«Çò»®·ÖÓÐ5575ºÍ4417ÃûÊÜÓ°ÏìÓû§¡£¡£¡£


https://securelist.com/the-state-of-stalkerware-in-2021/106193/