Magnet Goblin ºÚ¿Í×éÖ¯ÀûÓ÷ì϶²¿Êð Nerbian RAT
°ä²¼¹¦·ò 2024-03-123ÔÂ11ÈÕ£¬Ò»¸öÃûΪMagnet GoblinµÄ³öÓÚ¾¼Ã¶¯»úµÄÍþвÐÐΪÕßÔÚѸ¿ì½«1day°²È«·ì϶ÄÉÈëÆä±øÆ÷¿â£¬ÒÔ±ãËÅ»ú·ÛËé±ßÔµÉ豸ºÍÃæÏò¹«¼ÒµÄ·þÎñ£¬²¢ÔÚÊÜϰȾµÄÖ÷»úÉϲ¿Êð¶ñÒâÈí¼þ¡£µÐÊÖÌáÒéµÄ¹¥»÷ÀûÓÃ佨²¹µÄ Ivanti Connect Secure VPN¡¢Magento¡¢Qlik Sense ÒÔ¼°¿ÉÄÜµÄ Apache ActiveMQ ·þÎñÆ÷×÷Ϊ³õʼϰȾý½éÀ´»ñµÃδ¾ÊÚȨµÄ½Ó¼û¡£¾Ý³Æ¸Ã×éÖ¯ÖÁÉÙ×Ô 2022 Äê 1 ÔÂÆð¾ÍÒ»Ïò»îÔ¾¡£³É¹¦ÀûÓô˷ì϶ºó£¬»á²¿ÊðÒ»¸öÃûΪ Nerbian RAT µÄ¿çƽ̨Զ³Ì½Ó¼ûľÂí (RAT)£¬¸ÃľÂíÓÉ Proofpoint ÓÚ 2022 Äê 5 Ô³õ´ÎÅû¶£¬Æä¼ò»¯±äÖÖΪ MiniNerbian¡£DarktraceÖ®Ç°ÔøÇ¿µ÷¹ý Linux °æ±¾ Nerbian RAT µÄʹÓá£ÕâÁ½ÖÖ²¡¶¾¶¼ÔÊÐíÖ´ÐдӺÅÁîÓë½ÚÔì (C2) ·þÎñÆ÷½Ó¹ÜµÄËÁÒâºÅÁ²¢Ð¹Â¶·µ»Ø¸øËüµÄÁ˾֡£Magnet Goblin ʹÓÃµÄÆäËûһЩ¹¤¾ßÔ̺¬WARPWIRE JavaScript ƾ֤ÇÔÈ¡·¨Ê½¡¢»ùÓÚ Go µÄËí·Èí¼þ Ligolo£¬ÒÔ¼°ºÏ·¨µÄÔ¶³Ì×ÀÃæ²úÆ·£¨ÀýÈç AnyDesk ºÍ ScreenConnect£©¡£
https://thehackernews.com/2024/03/magnet-goblin-hacker-group-leveraging-1.html
2. Õë¶ÔÃÀ¹úºÍÅ·ÖÞÆóÒµµÄРDoNex ÀÕË÷Èí¼þ
3ÔÂ11ÈÕ£¬ÃÀ¹úºÍÅ·ÖÞ¸÷µØµÄÆóÒµ¶¼´¦Óڸ߶Ⱦ¯Ìè״̬£¬ÓÉÓÚÒ»ÖÖ±»³ÆÎª¡°DoNex¡±µÄÐÂÐÍÀÕË÷Èí¼þÒ»ÏòÔÚ»ý¼«·çÏÕÆóÒµ²¢Ðû³ÆÊܺ¦Õß¡£¶ÔÓÚÕâÖÖÍ»·¢Íþв£¬ÍøÂ簲ȫר¼Ò¼Ó°à¼ÓµãµØÏàʶ¹¥»÷µÄÈ«ÊýÁìÓò²¢Ôì¶©¶Ô²ß¡£DoNex ÀÕË÷Èí¼þ×é֯ͨ¹ýÔÚÆä°µÍøÃÅ»§£¨¿Éͨ¹ý Onion ÍøÂç½Ó¼û£©´ó½«¶à¼Ò¹«Ë¾ÁÐΪÊܺ¦Õß¶øÎÅÃû¡£¸ÃÍÅ»ïµÄ¼¿Á©ÓÈΪÒõÏÕ£¬Ñ¡È¡Ë«³ÁÀÕË÷¼¿Á©¡£Õâ²»½öÉæ¼°Îļþ¼ÓÃÜ£¬¶øºó¸½¼ÓÒ»¸öΨһµÄ¡£VictimID À©´ó£¬²¢ÇÒ»¹»áй¼ûô¸ÐÊý¾Ý£¬½«Æä×÷ΪÈËÖÊ£¬ÒÔÏòÊܺ¦ÕßÊ©¼Ó¶î±íѹÁ¦£¬ÒªÇóÆäÖ§¸¶Êê½ð¡£ÊÜÓ°ÏìµÄ¹«Ë¾ÔÚÆäϵͳÉÏ·¢ÏÖÁËÃûΪ Readme.VictimID.txt µÄÀÕË÷×ÖÌõ£¬¸Ã×ÖÌõÅúʾËûÃÇͨ¹ý Tox Messenger Óë DoNex ×éÖ¯³ÉÁ¢ÁªÏµ£¬Tox Messenger ÊÇÒ»ÖÖµã¶Ôµã¼´Ê±ÐÂÎÅ·þÎñ£¬ÒÔÆä°²È«ºÍÄäÃûÖ°ÄܶøÎÅÃû¡£
https://gbhackers.com/donex-ransomware-observed/
3. ¼Ù×°³É Notion ×°Ö÷¨Ê½µÄ MSIX ¶ñÒâÈí¼þ
3ÔÂ11ÈÕ£¬¼Ù×°³É Notion ×°Ö÷¨Ê½µÄ MSIX ¶ñÒâÈí¼þÔÚ·Ö·¢¡£·Ö·¢ÍøÕ¾¿´ÆðÀ´ÓëÏÖʵµÄ Notion Ö÷Ò³ÀàËÆ¡£×°Öúó£¬StartingScriptWrapper.ps1 ºÍrefresh.ps1 Îļþ½«ÔÚÀûÓ÷¨Ê½µÄõè¾¶ÄÚ´´½¨¡£StartingScriptWrapper.ps1 ÎļþÊÇÒ»¸öºÏ·¨Îļþ£¬Ô̺¬ MS ÊðÃû£¬ÓµÓÐÖ´ÐÐ×÷Ϊ²ÎÊý¸ø³öµÄ Powershell ¾ç±¾µÄÖ°ÄÜ¡£¸ÃÎļþÔÊÐíÔÚ×°Öùý³ÌºÍÖ´ÐÐÌØ¶¨ Powershell ¾ç±¾ÆÚ¼ä¶ÁÈ¡°üÄÚµÄ config.json ÅäÖÃÎļþ¡£´ËºÅÁî´Ó C2 ·þÎñÆ÷ÏÂÔØ¸½¼Ó Powershell ºÅÁî²¢Ö´ÐÐËüÃÇ¡£C2·þÎñÆ÷ĿǰûÓÐÕýÈ·ÏìÓ¦£¬µ«·ÖÎöÍŶÓÔÚ³õ²½·ÖÎöÆÚ¼äÈ·ÈÏÁËLummaC2¶ñÒâÈí¼þµÄÉ¢²¼¡£ÔÚÔËÐÐÎļþ֮ǰ£¬Óû§Ó¦¸Ã²é³ÎļþÊÇ·ñÀ´×Ô¹Ù·½ÍøÕ¾µÄÓò£¬¼´±ãÎļþÊÇʹÓúϷ¨Ö¤ÊéÊðÃûµÄ£¬Ò²Òª²é³ÊðÃû×÷Õß¡£½¨ÒéÔÚÖ´ÐÐ MSIX Îļþʱ¸ñ±íÓ×ÐÄ£¬ÓÉÓÚ¶àÖÖ¶ñÒâ±äÌå²»½ö»á¼Ù×° Notion£¬»¹»á¼Ù×° Slack¡¢WinRar ºÍ Bandicam µÅצÓ÷¨Ê½¡£
https://asec.ahnlab.com/en/62815/
4. ÈÕ±¾½« PyPI ¹©¸øÁ´ÍøÂç¹¥»÷¹é×ïÓÚ³¯ÏÊ
3ÔÂ11ÈÕ£¬ÈÕ±¾ÍøÂ簲ȫ¹ÙÔ±ÖÒ¸æ³Æ£¬³¯ÏʳôÃûÔ¶ÑïµÄ Lazarus Group ºÚ¿ÍÍŶÓ×î½üÕë¶Ô Python ÀûÓ÷¨Ê½µÄ PyPI Èí¼þ´æ´¢¿â·¢ÆðÁ˹©¸øÁ´¹¥»÷¡£Íþв²Î¼ÓÕßÉÏ´«ÁËÃûΪ¡°pycryptoenv¡±ºÍ¡°pycryptoconf¡±µÈÊÜ´«È¾µÄ°ü£¬ÆäÃû³ÆÓëºÏ·¨µÄ Python ¼ÓÃܹ¤¾ß°ü¡°pycrypto¡±ÀàËÆ¡£±»ÓÕÆ½«¶ñÒâÈí¼þ°üÏÂÔØµ½ Windows ÍÆËã»úÉϵĿª·¢ÈËÔ±»áϰȾһÖÖÃûΪ Comebacker µÄΣÏÕÌØÂåÒÁľÂí¡£Gartner ¸ß¼¶×Ü¼à¼æ·ÖÎöʦ Dale Gardner ½« Comebacker ÃèÊöΪһÖÖͨÓÃľÂí£¬ÓÃÓÚͶ·ÅÀÕË÷Èí¼þ¡¢ÇÔȡƾ֤ºÍÉøÈ뿪·¢Á÷³Ì¡£Comebacker Òѱ»²¿ÊðÔÚÓ볯ÏÊÓÐ¹ØµÄÆäËûÍøÂç¹¥»÷ÖУ¬Ô̺¬¶Ô npm Èí¼þ¿ª·¢´æ´¢¿âµÄ¹¥»÷¡£
https://www.darkreading.com/application-security/japan-blames-north-korea-for-pypi-supply-chain-cyberattack
5. ºÚ¿ÍÀûÓà WordPress ²å¼þȱµãÓöñÒâÈí¼þϰȾ 3300 ¸öÍøÕ¾
3ÔÂ10ÈÕ£¬ºÚ¿ÍÀûÓà Popup Builder ²å¼þ¹ýÆÚ°æ±¾Öеķì϶ÈëÇÖ WordPress ÍøÕ¾£¬ÓöñÒâ´úÂëϰȾ 3,300 ¶à¸öÍøÕ¾¡£¹¥»÷ÖÐÀûÓõÄȱµã±»×·×ÙΪ CVE-2023-6000£¬ÕâÊÇÒ»¸öÓ°Ïì Popup Builder °æ±¾ 4.2.3 ¼°¸üÔç°æ±¾µÄ¿çÕ¾µã¾ç±¾ (XSS) ·ì϶£¬×î³õÓÚ 2023 Äê 11 ÔÂÅû¶¡£½ñÄêËêÊ×·¢ÏÖµÄ Balada Injector »î¶¯ÀûÓøÃÌØ¶¨·ì϶ϰȾÁË 6,700 ¶à¸öÍøÕ¾£¬ÕâÅú×¢ºÜ¶àÍøÕ¾ÖÎÀíԱûÓÐ×ã¹»¿ìµØ½¨²¹²¹¶¡¡£Sucuri ´Ë¿Ì »ã±¨ ·¢ÏÖÒ»¸öеĻÔÚ´ÓǰÈýÖÜÄÚÏÔ×ÅÔö³¤£¬Õë¶ÔµÄÊÇ WordPress ²å¼þÉϵÄÒ»Ñù·ì϶¡£Æ¾¾Ý PublicWWW µÄÁ˾֣¬ÔÚ3,329 ¸ö WordPress ÍøÕ¾Öз¢ÏÖÁËÓëÕâÒ»×îлÓйصĴúÂë×¢Èë £¬Sucuri ×Ô¼ºµÄɨÃèÒǼì²âµ½ÁË 1,170 ¸öϰȾ¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-wordpress-plugin-flaw-to-infect-3-300-sites-with-malware/
6. ÔóÎ÷µº½ðÈÚ·þÎñίԱ»áµÄÊý¾Ýй¶
3ÔÂ7ÈÕ£¬ÔóÎ÷µº½ðÈÚ·þÎñίԱ»áµÄÊý¾Ýй¶µ¼Ö·ǹ«¿ªÐÕÃûºÍµØÖ·µÄ½Ó¼û¡£¸Ã×éÖ¯ÓÚ 1 Ô 23 ÈÕÈ·ÈÏÆä×¢²áϵͳÖмì²âµ½Ò»¸ö¡°·ì϶¡±¡£¸Ã¹«Ë¾°µÊ¾£¬Õâ´ÎйÃÜÊÂÎñ²¢Î´½«ÈκÎÓ×ÎÒÓë×¢²áʵÌå»òËùµ£ÈεĽÇÉ«ÁªÏµÆðÀ´£¬²¢ÇÒÒѵ¥¶ÀдПøÄÇЩÐÕÃûºÍµØÖ·±»Ð¹Â¶µÄÈË¡£³õ²½·¨Ò½Éó²é·¢ÏÖй©ÊÇÓÉÓÚµÚÈý·½ÌṩµÄ×¢²áϵͳÅäÖÃÃýÎóÔì³ÉµÄ¡£¸Ã×éÖ¯°µÊ¾£º¡°ÎÒÃǶԲúÉúÕâÖÖÇé¿öÉî¸ÐÒź¶£¬Ä¿Ç°ÔÚ½øÒ»´ëÊ©²éÒÔÈ·¶¨ÕâÊÇÈôºÎ²úÉúµÄ¡£¡±JFSC °µÊ¾ÔÚÓëÔóÎ÷µºÐÅϢרԱ°ì¹«ÊÒºÏ×÷¡£ÕƹܽðÈÚ·þÎñµÄ¸±²¿³¤ÒÁ¶÷¡¤¸êË¹ÌØ°µÊ¾£¬Õâ´Îй¶ӰÏìÁËϵͳÖÓ×°ÓÐÏÞÊýÁ¿µÄÌõ¿î¡±¡£Ëû²¹³ä·£º¡°ÎÒ¶Ô²úÉúÕâÒ»ÃýÎó¸ÐÓ¦±§À¢£¬ÎÒÏàʶ½áºÏ½ðÈÚ·þÎñίԱ»áÔÚ½øÐÐ×î³¹µ×µÄµ÷²é£¬ÒÔÈ·±£ÂÞÖ½Ìѵ£¬²¢¸Ä½øºÍ¼ÓÇ¿µÇ¼Ç²áµÄÉè¼Æ¡£
https://www.bbc.com/news/articles/cnk5zyypw24o?&web_view=true


¾©¹«Íø°²±¸11010802024551ºÅ