StrelaStealer¹¥»÷Å·Ã˺ÍÃÀ¹úµÄ 100 ¶à¸ö×éÖ¯»òÆóÒµ

°ä²¼¹¦·ò 2024-03-25
1. StrelaStealer¹¥»÷Å·Ã˺ÍÃÀ¹úµÄ 100 ¶à¸ö×éÖ¯»òÆóÒµ


3ÔÂ24ÈÕ£¬ÔÚUnit 42×î½üµÄÒ»·Ý»ã±¨ÖÐPalo Alto Networks µÄ×êÑÐÈËÔ±·¢ÏÖÁËһϵÁÐеÄÍøÂç´¹µö¹¥»÷£¬Ö¼ÔÚ´«²¼ÃûΪ StrelaStealer µÄ¶ñÒâÈí¼þ¡£ÕâÒ»ÍþвÒÑÓ°Ï쵽ŷÃ˺ÍÃÀ¹úµÄ 100 ¶à¸ö×éÖ¯¡£ÕâЩ¹¥»÷ÊÇͨ¹ý´øÓÐÆô¶¯ StrelaStealer DLL¸ºÔصĸ½¼þµÄÀ¬»øÓʼþÀ´Ö´ÐеÄ¡£ÎªÁËÌӱܼì²â£¬¹¥»÷Õ߻ᶨÆÚ¸ü¸Ä³õʼµç×ÓÓʼþÖи½¼þµÄÎļþÌåʽ¡£StrelaStealer ÓÚ 2022 Äê 11 Ô³õ´Î¼ì²âµ½£¬Ö¼ÔÚ´ÓÊ¢ÐеÄÓʼþ¿Í»§¶ËÇÔÈ¡µç×ÓÓʼþÕÊ»§Êý¾Ý£¬²¢½«ÕâЩÐÅÏ¢´«Êäµ½¹¥»÷Õß½ÚÔìϵķþÎñÆ÷¡£×ԸöñÒâÈí¼þ³öÏÖÒÔÀ´£¬×êÑÐÈËÔ±¼Í¼ÁËÁ½´Î²¿Êð¸Ã¶ñÒâÈí¼þµÄ³Á´ó»î¶¯£ºÒ»´ÎÓÚ 2023 Äê 11 Ô£¬ÁíÒ»´ÎÓÚ 2024 Äê 1 Ô¡£ÕâЩ»î¶¯Õë¶ÔµÄÐÐÒµÔ̺¬¼¼Êõ¡¢½ðÈÚ¡¢×¨ÒµºÍ˾·¨·þÎñ¡¢Ôì×÷¡¢ÄÜÔ´¡¢±£ÏÕ¡¢¹¹ÖþµÈ¡£


https://meterpreter.org/strelastealer-attacks-hit-100-organizations/


2. Apple M ϵÁÐоƬ΢¼Ü¹¹ÑϳÁ·ì϶£¬¿Éµ¼ÖÂMac É豸ÃÜԿй¶


3ÔÂ24ÈÕ£¬×êÑÐÈËÔ±·¢ÏÖÁË Apple M ϵÁÐоƬ΢¼Ü¹¹ÖеÄÒ»¸öÑϳÁ·ì϶£¬Ê¹·¸×ï·Ö×Ó¿ÉÄÜ´Ó Mac É豸£¨Ô̺¬ÍÆËã»úºÍ±Ê¼Ç±¾µçÄÔ£©ÖÐÌáÈ¡ÃÜÔ¿¡£ÎÊÌâµÄÖ¢½áÔÚÓÚ£¬¸Ã·ì϶ÓëоƬÉè¼ÆÓÐÐÔÖÊÁªÏµ£¬½ö¿¿Èí¼þ¸üÐÂÎÞ·¨ÆëÈ«½¨¸´¡£¸Ã·ì϶ÓëÊý¾ÝÄÚ´æÔ¤È¡Ö°ÄÜÓйØ£¬¸ÃÖ°ÄÜͨ¹ýÔ¤²â½«À´µÄÄÚ´æÒªÇóÀ´ÓÅ»¯ÐÅÏ¢´¦ÖᣴËÖ°ÄÜ¿ÉÄÜ»áÎó»á¼ÓÃÜÃÜÔ¿£¬´Ó¶øÎªÍ¨¹ýרÃŹ¥»÷ÌáÈ¡ÃÜԿ̯ƽ··¡£Ò»¸ö¹ú¼Ê×êÑÐÍŶÓÉè¼ÆÁËÒ»ÖÖÃûΪ GoFetch µÄ¹¥»÷£¬ËµÁËÈ»ÎÞÐèÉ豸ÖÎÀíȨÏÞ¼´¿ÉÌáÈ¡ÃÜÔ¿µÄ¿ÉÐÐÐÔ¡£ÕâÖÖ¹¥»÷Äܹ»ÔÚרÓÐµÄ M1 ºÍ M2 оƬÉÏÖ´ÐУ¬Ó°Ï촫ͳ¼ÓÃÜËã·¨ºÍµÖ¿¹Á¿×ÓÍÆËãµÄËã·¨¡£ÃÜÔ¿ÌáÈ¡¹ý³Ì´Ó²»µ½Ò»Ó×ʱµ½Ê®Ó×ʱ²»µÈ£¬¾ßÌåÈ¡¾öÓÚ¼ÓÃÜÃÜÔ¿µÄÀàÐͺÍËùѡȡµÄËã·¨¡£ÕâÅú×¢¸Ã·ì϶¿ÉÄܶã±Ü³ß¶È¼ÓÃÜ·ÀÓù»úÔ졣ΪÁË·À±¸´Ë·ì϶£¬¼ÓÃÜÈí¼þ¿ª·¢ÈËÔ±±ØÐëÔÚÆäÈí¼þÖÐÖ´Ðжî±íµÄ°²È«»úÔ죬Õâ¿ÉÄܻᵼÖ¼ÓÃܲÙ×÷ÆÚ¼äµÄ»úÄܽµÂä¡£ÌáÒéµÄ±£»¤´ëÊ©Ô̺¬Êý¾ÝÆÁ±ÎºÍ½«´¦ÖÃ×ªÒÆµ½Ã»ÓÐ DMP µÄ´¦ÖÃÆ÷Äںˡ£×êÑÐÈËÔ±»¹Ìá³öÁËÒ»Öֳ־ýâ¾ö¹æ»®£¬Éæ¼°À©´óÓ²¼þºÍÈí¼þ½»»¥£¬ÒÔ±ãÔڹؼü²Ù×÷ÆÚ¼äÍ£Óà DMP¡£ÕâÄܹ»Ô®ÊÖ×èÖ¹¹¥»÷£¬¶ø²»»áÏÔ×ÅÓ°ÏìÕûÌå»úÄÜ¡£


https://meterpreter.org/unfixable-apple-chip-issue-secret-keys-vulnerable/


3. ΢Èí½«¹Ø¹ØÕë¶Ô¶íÂÞ˹ÆóÒµµÄ 50 ÏîÔÆ·þÎñµÄ½Ó¼û


3ÔÂ23ÈÕ£¬Î¢Èí´òËãÔÚ 3 Ôµ×֮ǰÏ޶ȶíÂÞ˹×éÖ¯¶Ô 50 ¶àÖÖÔÆ²úÆ·µÄ½Ó¼û£¬ÕâÊÇÅ·Ã˼à¹Ü»ú¹¹È¥Äê 12 Ô¶Ըùú°ä²¼µÄÔì²ÃÒªÇóµÄÒ»²¿ÃÅ¡£ÔÝÍ£×î³õ¶¨ÓÚ 2024 Äê 3 Ô 20 ÈÕ½øÐУ¬µ«ºóÀ´ÍƳٵ½±¾Ôµ×£¬ÒÔ±ãÊÜÓ°ÏìµÄʵÌåÓиü¶à¹¦·òÀ´Ôì¶©´úÌæ½â¾ö¹æ»®¡£Óйؼ´½«ÔÝÍ£µÄÐÂÎÅ×îÏÅ×É Softline Group of Companies ±¨Â·£¬¸Ã¹«Ë¾ÊǶíÂÞ˹ÏÖ´æ×î´óµÄ IT ·þÎñÌṩÉÌÖ®Ò»¡£Î¢ÈíµÄÐÅÖÐûÓоßÌå×¢Ã÷ÄÄЩ·þÎñ½«±»È¡µÞ£¬µ«Ëþ˹ÉçÒѾ­ÁгöÁË 50 ¶àÖÖ²úÆ·µÄÇåµ¥ £¬ÕâЩ²úÆ·½«ÔÚ 3 Ôµ×ÖÕ³¡Ìṩ¡£ÒÑ Ã÷È· £¬Ðí¿É֤ʧЧӰÏì¶íÂÞ˹´Óʹ¹Öþ¡¢Éè¼Æ¡¢Ê©¹¤¡¢Ôì×÷¡¢Ã½Ìå¡¢½ÌÓýºÍÓéÀÖ¡¢¹¹ÖþÐÅϢģÐÍ£¨BIM£©¡¢ÍÆËã»ú¸¨ÖúÉè¼Æ£¨CAD£©ºÍÍÆËã»ú¸¨ÖúÔì×÷µÄ¹«Ë¾ºÍ×éÖ¯£¨Í¹ÂÖ£©¡£µ«ÊÇ£¬Ã»Óа䷢ÏÞ¶ÈÓ×ÎÒ½Ó¼ûµÄ´òË㣬Òò¶øÈç¹ûÉÏÊö²úÆ·ÈԿɹ©Í¨³£Óû§Ê¹Óá£


https://www.bleepingcomputer.com/news/microsoft/microsoft-to-shut-down-50-cloud-services-for-russian-businesses/


4. SIGN1 ¶ñÒâÈí¼þ»î¶¯ÒÑϰȾ 39000 ¶à¸ö WORDPRESS ÍøÕ¾


3ÔÂ23ÈÕ£¬Sucuri µÄ Sucurity ×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÃûΪ Sign1 µÄ¶ñÒâÈí¼þ»î¶¯£¬¸Ã»î¶¯ÔÚ´ÓǰÁù¸öÔÂÄÚÒѾ­·çÏÕÁË 39,000 ¸ö WordPress ÍøÕ¾¡£×¨¼ÒÃÇ·¢ÏÖ£¬ÍþвÐÐΪÕßÈëÇÖÁËÍøÕ¾£¬Ö²Èë¶ñÒâ JavaScript ×¢È룬½«½Ó¼ûÕß³Á¶¨Ïòµ½¶ñÒâÍøÕ¾¡£Sign1 ±³ºóµÄÍþв²Î¼ÓÕß½«¶ñÒâ JavaScript ×¢ÈëºÏ·¨²å¼þºÍ HTML Óײ¿¼þÖС£×¢ÈëµÄ´úÂëÔ̺¬Ò»¸öÓ²±àÂëµÄÊý×ÖÊý×飬ËüʹÓà XOR ±àÂëÀ´»ñÈ¡ÐÂÖµ¡£×¨¼Ò¶Ô XOR ±àÂëµÄ JavaScript ´úÂë½øÐÐÏàʶÂ룬·¢ÏÖËüÓÃÓÚÖ´ÐÐÔ¶³Ì·þÎñÆ÷ÉÏÍÐ¹ÜµÄ JavaScript Îļþ¡£×êÑÐÈËÔ±°ÑÎȵ½£¬¹¥»÷Õßѡȡ¶¯Ì¬¸ü¸ÄµÄ URL£¬¶¯Ì¬ JavaScript ´úÂëµÄʹÓÃÔÊÐíÿ 10 ·ÖÖÓ¸ü¸ÄÒ»´Î URL¡£¸Ã´úÂëÔÚ½Ó¼ûÕßµÄä¯ÀÀÆ÷ÖÐÖ´ÐУ¬µ¼ÖÂÍøÕ¾½Ó¼ûÕß³öÏÖ²»±ØÒªµÄ³Á¶¨ÏòºÍ¸æ°×¡£Sign1 »î¶¯×î³õÓÉ×êÑÐÔ±Denis SinegubkoÔÚ 2023 ÄêϰëÄê·¢ÏÖ£¬Sucuri »ã±¨³Æ£¬×Ô 2023 Äê 7 Ô 31 ÈÕÒÔÀ´£¬ÍþвÐÐΪÕßÀûÓÃÁ˶à´ï 15 ¸ö·ÖÆçµÄÓò¡£


https://securityaffairs.com/160942/hacking/sign1-malware-campaign.html


5. ÃÀ¹úµ±¾Ö°ä²¼Õë¶Ô¹«¹²²¿ÃŵÄРDDoS ¹¥»÷Ö¸ÄÏ


3ÔÂ22ÈÕ£¬ÃÀ¹úµ±¾ÖΪ¹«¹²²¿ÃÅʵÌå°ä²¼ÁËеÄÉ¢²¼Ê½»Ø¾ø·þÎñ (DDoS) ¹¥»÷Ö¸ÄÏ£¬ÒÔÔ®ÊÖÔ¤·À¹Ø¼ü·þÎñÖжÏ¡£¸ÃÎļþÖ¼ÔÚ×÷Ϊ×ۺϻïÔ´£¬½â¾öÁª¹ú¡¢Öݺʹ¦Ëùµ±¾Ö»ú¹¹ÔÚ·ÀÓù DDoS ¹¥»÷·½ÃæÃæ¶ÔµÄ¾ßÌåÐèÒªºÍÌôÕ½¡£¸Ã´«µÝÖ¸³ö£¬DDoS ¹¥»÷ÊÇÖ¸´óÁ¿ÊÜϰȾµÄÍÆËã»úÏòÖ¸±êϵͳ·¢ËÍ´óÁ¿Á÷Á¿»òÒªÇ󣬵¼ÖÂÓû§ÎÞ·¨Ê¹Óøù¥»÷£¬ÕâÖÖ¹¥»÷ºÜÄÑ×·×ÙºÍ×èÖ¹¡£ÕâÖÖý½éͨ³£±»³öÓÚÕþÖζ¯»úµÄ¹¥»÷ÕßʹÓã¬Ô̺¬ºÚ¿Í»î¶¯·Ö×ÓºÍÃñ×å¹ú¶È¼¯Ì壬µ±¾ÖÍøÕ¾Ê±Ê±³ÉΪ¹¥»÷Ö¸±ê¡£ÀýÈ磬×Ô 2022 Äê 2 Ô¿ËÀïÄ·ÁÖ¹¬ÈëÇָùúÒÔÀ´£¬Óë¶íÂÞ˹ºÍÎÚ¿ËÀ¼ÓйصĺڿÍʱʱʹÓà DDoS ¹¥»÷¶Ô·½µ±¾ÖÍøÕ¾¡£2023 Äê 10 Ô£¬Ó¢¹úÍõÊÒ¹Ù·½ÍøÕ¾Òò DDoS ÊÂÎñ¶øÏÂÏߣ¬¶íÂÞ˹ºÚ¿Í×éÖ¯ Killnet Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£


https://www.infosecurity-magazine.com/news/us-ddos-attack-guidance-public/?&web_view=true


6. ¶íÂÞ˹ºÚ¿ÍÀûÓà WineLoader ¶ñÒâÈí¼þ¶Ô×¼µÂ¹úÕþµ³


3ÔÂ23ÈÕ£¬×êÑÐÈËÔ±ÖÒ¸æ³Æ£¬Óë¶íÂÞ˹¶Ô±íµý±¨¾Ö£¨SVR£©ÓÐÁªÏµµÄºÚ¿Í×éÖ¯³õ´ÎÕë¶ÔµÂ¹úÕþµ³£¬½«Æä½¹µã´ÓµäÐÍµÄ±í½»Ê¹ÍÅÖ¸±ê×ªÒÆ¿ª¡£ÍøÂç´¹µö¹¥»÷Ö¼ÔÚ²¿ÊðÃûΪ WineLoader µÄºóÃŶñÒâÈí¼þ£¬¸Ã¶ñÒâÈí¼þÔÊÐíÍþвÐÐΪÕßÔ¶³Ì½Ó¼ûÊÜϰȾµÄÉ豸ºÍÍøÂç¡£APT29£¨Ò²³ÆÎª Midnight Blizzard¡¢NOBELIUM¡¢Cozy Bear£©ÊÇÒ»¸ö¶íÂÞ˹¼äµýºÚ¿Í×éÖ¯¡£¸ÃºÚ¿Í×éÖ¯ÓëºÜ¶àÍøÂç¹¥»÷ÓйØ£¬Ô̺¬ 2020 Äê 12 Ô³ôÃûÔ¶ÑïµÄSolarWinds ¹©¸øÁ´¹¥»÷¡£ÕâЩÄêÀ´£¬ÍþвÐÐΪÕßÒ»Ïòά³Ö»îÔ¾£¬Í¨³£Ê¹ÓÃһϵÁÐÍøÂç´¹µöÕ½Êõ»ò¹©¸øÁ´Í×ЭÀ´Õë¶Ôµ±¾Ö¡¢´óʹ¹Ý¡¢¸ß¼¶¹ÙÔ±ºÍ¸÷ÀàʵÌå¡£APT29 ×î½üµÄ³ÁµãÊÇÔÆ·þÎñ£¬·ÛËé Microsoft ϵͳ²¢ÇÔÈ¡ Exchange ÕÊ»§µÄÊý¾Ý£¬²¢·ÛËéHewlett Packard EnterpriseʹÓÃµÄ MS Office 365 µç×ÓÓʼþ»·¾³¡£


https://www.bleepingcomputer.com/news/security/russian-hackers-target-german-political-parties-with-wineloader-malware/