Ñо¿Ö°Ô±ÔÚ¶à¸öÄ¿µÄϵͳÉϼì²âµ½Îó²îʹÓù¤¾ßIceApple
Ðû²¼Ê±¼ä 2022-05-13¾ÝýÌå5ÔÂ11ÈÕ±¨µÀ£¬£¬£¬£¬£¬CrowdStrike·¢Ã÷ÁËÒ»ÖÖеÄÎó²îʹÓù¤¾ßIceApple¡£¡£¡£¸Ã¶ñÒâÈí¼þÓÚ2021Äêµ×Ê״α»·¢Ã÷£¬£¬£¬£¬£¬ÏÖÔÚÈÔÔÚÆð¾¢¿ª·¢ÖС£¡£¡£IceAppleÊǹ¥»÷ÕßÔÚ»ñµÃÖÖÖÖÐÐÒµ£¨ÊÖÒÕ¡¢Ñ§ÊõºÍÕþ¸®£©×éÖ¯ÍøÂçµÄ³õʼ»á¼ûȨÏÞºó×°Öõ쬣¬£¬£¬£¬ÏÖÔÚÒÑÔÚ¶à¸öÄ¿µÄµÄMicrosoft Exchange ServerʵÀýÉϼì²âµ½£¬£¬£¬£¬£¬µ«ËüÒ²¿ÉÒÔÔÚIISÉÏÔËÐС£¡£¡£¸Ã¶ñÒâ¿ò¼Ü»ùÓÚ.NET£¬£¬£¬£¬£¬¾ßÓÐÖÁÉÙ18¸öÄ£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬Ã¿¸öÄ£¿£¿£¿£¿£¿£¿éÓÃÓÚÌØ¶¨Ê¹Ãü£¬£¬£¬£¬£¬¿ÉÓÃÀ´·¢Ã÷ÍøÂçÉϵÄÏà¹Ø×°±¸¡¢ÇÔȡƾ֤¡¢É¾³ýÎļþºÍĿ¼ÒÔ¼°ÇÔÈ¡ÓмÛÖµµÄÊý¾Ý¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-iceapple-exploit-toolset-deployed-on-microsoft-exchange-servers/
2¡¢ÐµÄNerbian RATÃé×¼Òâ´óÀûºÍÎ÷°àÑÀµÈÅ·ÖÞ¹ú¼Ò
5ÔÂ11ÈÕ£¬£¬£¬£¬£¬ProofpointÅû¶ÁËÐÂNerbian RATµÄ¹¥»÷»î¶¯µÄϸ½ÚÐÅÏ¢¡£¡£¡£¹¥»÷»î¶¯×Ô4ÔÂ26ÈÕ×îÏÈ£¬£¬£¬£¬£¬Í¨¹ýÒÔCOVID-19ºÍºÍÌìÏÂÎÀÉú×é֯ΪÖ÷ÌâµÄ´¹Âڻ·Ö·¢¶ñÒâÈí¼þ£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÒâ´óÀû¡¢Î÷°àÑÀºÍÓ¢¹úµÄ×éÖ¯¡£¡£¡£NerbianÓÉGoÓïÑÔ±àд£¬£¬£¬£¬£¬Îª64λϵͳ±àÒ룬£¬£¬£¬£¬Ê¹ÓÃÁ˶à¸ö¼ÓÃÜÀú³ÌÈÆ¹ýÇå¾²ÆÊÎö¡£¡£¡£Dropper»¹Ê¹ÓÃÁË¿ªÔ´ChacalµÄ¡°·´VM¿ò¼Ü¡±À´ÔöÌíÄæÏò¹¤³ÌµÄÄѶȡ£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬DropperºÍRAT¶¼ÊÇÓÉͳһ¿ª·¢Õß¿ª·¢µÄ£¬£¬£¬£¬£¬µ«¹¥»÷ÕßµÄÉí·ÝÈÔȻδ֪¡£¡£¡£
https://www.proofpoint.com/us/blog/threat-insight/nerbian-rat-using-covid-19-themes-features-sophisticated-evasion-techniques
3¡¢Ó¢¹úÄÐ×Ó±»Ö¸¿ØÈëÇÖÃÀ¹úij½ðÈÚ»ú¹¹ËðʧÁè¼Ý500ÍòÃÀÔª
¾Ý5ÔÂ11ÈÕ±¨µÀ£¬£¬£¬£¬£¬32ËêµÄÓ¢¹úÄÐ×ÓIdris Dayo Mustapha±»Ö¸¿ØÈëÇÖÃÀ¹úij½ðÈÚ»ú¹¹£¬£¬£¬£¬£¬Ôì³ÉÁè¼Ý500ÍòÃÀÔªµÄËðʧ¡£¡£¡£5ÔÂ10ÈÕ¹ûÕæµÄͶËßÏÔʾ£¬£¬£¬£¬£¬¸ÃÄÐ×ÓÊÇijºÚ¿ÍÍÅ»ïµÄÒ»Ô±£¬£¬£¬£¬£¬ËûÃÇÔÚ2011Äê1ÔÂÖÁ2018Äê3ÔÂʱ´úʹÓô¹Âڵȹ¥»÷·½·¨»ñÈ¡Óû§Æ¾Ö¤£¬£¬£¬£¬£¬ÒÔÇÔÈ¡ÍøÉÏÒøÐÐÕË»§ºÍ֤ȯ¾¼ÍÕË»§ÖеÄ×ʽ𡣡£¡£ÈôÊÇ×ïÃû½¨É裬£¬£¬£¬£¬Mustapha½«Òòµç»ãÕ©Æ¡¢Ö¤È¯Õ©ÆºÍÏ´Ç®µÈÖ¸¿ØÃæÁÙ³¤´ï20ÄêµÄî¿Ïµ¡£¡£¡£
https://www.infosecurity-magazine.com/news/british-charged-hacking-us-bank/
4¡¢ÄϷǹ«Ë¾Dis-ChemÔâµ½¹¥»÷й¶Áè¼Ý360ÍòÈ˵ÄÐÅÏ¢
ýÌå5ÔÂ11ÈÕ±¨µÀ£¬£¬£¬£¬£¬ÄÏ·Ç×î´óµÄÒ©Æ·ÁãÊÛÉÌÖ®Ò»Dis-ChemÒÑй¶Áè¼Ý360ÍòÈ˵ÄÐÅÏ¢¡£¡£¡£¾Ý¸Ã¹«Ë¾³Æ£¬£¬£¬£¬£¬´Ë´ÎÊÂÎñÊÇÓÉÆäµÚÈý·½Ð§ÀÍÌṩÉÌÔâµ½ÍøÂç¹¥»÷µ¼Öµģ¬£¬£¬£¬£¬Éæ¼°¿Í»§µÄÐÕÃû¡¢ÓʼþµØµãºÍÊÖ»úºÅÂëµÈÐÅÏ¢¡£¡£¡£Ð¹Â¶±¬·¢ÔÚ4ÔÂ28ÈÕ£¬£¬£¬£¬£¬ÔÚ5ÔÂ1Èղű»·¢Ã÷¡£¡£¡£½üÆÚ£¬£¬£¬£¬£¬¹¥»÷ÕßÔ½À´Ô½¶àµØÕë¶ÔÄϷǵÄ×éÖ¯£¬£¬£¬£¬£¬2¸öÔÂǰ£¬£¬£¬£¬£¬ÃÀ¹úÏûºÄÕßÐÅÓñ¨¸æ»ú¹¹TransUnion³ÆÆäλÓÚÄϷǵÄЧÀÍÆ÷±»ÈëÇÖ£¬£¬£¬£¬£¬Ð¹Â¶ÁË5400ÍòÓû§µÄÐÅÏ¢¡£¡£¡£
https://www.itweb.co.za/content/PmxVE7KEABOqQY85
5¡¢CiscoÐû²¼BitterÍŻ﹥»÷ÃϼÓÀÕþ¸®Ä³»ú¹¹µÄ±¨¸æ
Cisco TalosÔÚ5ÔÂ11ÈÕÐû²¼Á˹ØÓÚAPT×éÖ¯Bitter¹¥»÷ÃϼÓÀ¹úµÄÆÊÎö±¨¸æ¡£¡£¡£¹¥»÷»î¶¯×îÏÈ×Ô2021Äê8Ô£¬£¬£¬£¬£¬Õë¶ÔÃϼÓÀÄÚ²¿µÄÖÖÖÖ×éÖ¯£¬£¬£¬£¬£¬¾ßÓÐÁ½ÌõѬȾÁ´£¬£¬£¬£¬£¬¾ùͨ¹ýÓã²æÊ½´¹Âڻ¾ÙÐС£¡£¡£´¹ÂÚÓʼþÀ´×Ô°Í»ù˹̹µÄÕþ¸®»ú¹¹£¬£¬£¬£¬£¬Õâ¿ÉÄÜÊÇʹÓÃÓʼþЧÀÍÆ÷ZimbraÖеÄÒ»¸öÎó²îÀ´ÊµÏÖ¡£¡£¡£Á½ÌõѬȾÁ´Ö®¼äµÄÇø±ðÔÚÓÚ¸½¼ÓµÄ¶ñÒâÎļþÀàÐÍ£ºÒ»¸öÊÇ.RTF£¬£¬£¬£¬£¬ÁíÒ»¸öÊÇ.XLSXÎĵµ¡£¡£¡£RTFÎĵµÊ¹ÓÃÁËÎó²îCVE-2017-11882²¢ÔÚÄ¿µÄÖÐÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬ExcelÎĵµ´¥·¢Á˶ÔCVE-2018-0798ºÍCVE-2018-0802µÄÎó²îʹÓᣡ£¡£
https://blog.talosintelligence.com/2022/05/bitter-apt-adds-bangladesh-to-their.html
6¡¢¶à¹úÕþ¸®Ðû²¼Õë¶ÔMSP¼°Æä¿Í»§µÄÍøÂçÍþвµÄÁªºÏ×Éѯ
5ÔÂ11ÈÕ£¬£¬£¬£¬£¬°Ä´óÀûÑÇ¡¢¼ÓÄôó¡¢ÐÂÎ÷À¼¡¢Ó¢¹úºÍÃÀ¹úµÄ¶à¸öÍøÂçÇå¾²»ú¹¹Ðû²¼ÁËÕë¶ÔÍйÜЧÀÍÌṩÉÌ(MSP)¼°Æä¿Í»§µÄÍøÂçÍþвµÄÁªºÏ×Éѯ¡£¡£¡£MSPÒѳÉΪ¹¥»÷ÕßÀ©´ó¹¥»÷¹æÄ£µÄ;¾¶£¬£¬£¬£¬£¬ÓÉÓÚÒ×Êܹ¥»÷µÄÌṩÉÌ¿ÉÒÔ±»ÎäÆ÷»¯²¢×÷Ϊ³õʼ»á¼ûÔØÌ壬£¬£¬£¬£¬ÒÔͬʱ¹¥»÷¶à¸öÏÂÓοͻ§¡£¡£¡£×ÉѯÖн¨Ò飬£¬£¬£¬£¬Ê¶±ðºÍ½ûÓò»ÔÙʹÓõÄÕÊ»§£»£»£»£»£»£»¶Ô»á¼û¿Í»§ÇéÐεÄMSPÕË»§ÊµÑéMFA£¬£¬£¬£¬£¬²¢¼à²âδڹÊ͵Äʧ°ÜÈÏÖ¤£»£»£»£»£»£»È·±£MSP¿Í»§ÌõÔ¼Ã÷È·ÐÅÏ¢ºÍͨѶÊÖÒÕ(ICT)Çå¾²½ÇÉ«ºÍÔðÈεÄËùÓÐȨ¡£¡£¡£
https://thehackernews.com/2022/05/government-agencies-warned-of-increase.html