LATRODECTUS²»Ðݸüв¢·Ö·¢ICEDIDºÍÆäËû¶ñÒâÈí¼þ
°ä²¼¹¦·ò 2024-05-225ÔÂ21ÈÕ£¬LATRODECTUSÓÚ 2023 Äê 10 ÔÂÓÉÎÖ¶ûÂê×êÑÐÈËÔ±³õ´Î·¢ÏÖ£¬ÊÇÒ»ÖÖÔÚÍøÂç·¸×ï·Ö×ÓÖÐÔ½À´Ô½Ê¢ÐеĶñÒâÈí¼þ¼ÓÔØ·¨Ê½¡£¹ÌÈ»Õâ±»ÒÔΪÊÇÒ»¸öеļÒ×壬µ«ÓÉÓÚÐÐΪºÍ·¢Õ¹ÀàËÆÐÔ£¬LATRODECTUS ºÍICEDIDÖ®¼ä´æÔÚçÇÃÜÁªÏµ£¬Ô̺¬ÏÂÔØºÍÖ´ÐмÓÃܸºÔØ£¨Èç ICEDID£©µÄºÅÁî´¦Ö÷¨Ê½¡£Proofpoint ºÍ Team Cymru »ùÓÚÕâÖÖÁªÏµ£¬·¢ÏÖÁËICEDID ºÍ LATRODECTUS ÔËÓªÉÌʹÓõÄÍøÂç»ù´¡Éèʩ֮¼ä´æÔÚçÇÃÜÁªÏµ¡£LATRODECTUS ÌṩÁËһϵÁÐÈ«ÃæµÄ³ß¶ÈÖ°ÄÜ£¬ÍþвÐÐΪÕßÄܹ»ÀûÓÃÕâЩְÄÜÀ´²¿Êð¸ü¶àµÄÓÐЧ¸ºÔØ£¬ÔÚ³õ²½ÈëÇÖºóÖ´Ðи÷Àà»î¶¯¡£´úÂë¿âδ¾¹ý»ìºÏ£¬½öÔ̺¬ 11 ¸öרһÓÚö¾ÙºÍÖ´ÐеĺÅÁî´¦Ö÷¨Ê½¡£ÕâÖÖÀàÐ͵ļÓÔØÆ÷´ú±íÁËÎÒÃÇÍŶÓ×î½ü¹Û²ìµ½µÄº£³±£¬ÀýÈçPIKABOT£¬ÆäÖдúÂëÔ½·¢ÇáÁ¿¼¶ºÍÖ±½Ó£¬´¦Ö÷¨Ê½ÊýÁ¿ÓÐÏÞ¡£
https://www.elastic.co/security-labs/spring-cleaning-with-latrodectus?&web_view=true
2. Kinsing¹¥»÷Apache Tomcat²¿ÊðÍÚ¿ó·¨Ê½
5ÔÂ20ÈÕ£¬Kinsing ¶ñÒâÈí¼þÒÔÀûÓà Linux ÔÆ·þÎñÆ÷Éϵķì϶²¿ÊðºóÃźͼÓÃÜÇ®±ÒÍÚ¿ó·¨Ê½¶øÎÅÃû£¬×î½ü½«ÆäÖ¸±êÀ©´óµ½Ô̺¬ Apache Tomcat ·þÎñÆ÷¡£¸Ã¶ñÒâÈí¼þÀûÓÃÐÂÏʵļ¼ÊõÀ´Ìӱܼì²â£¬½«×ÔÉí°µ²ØÔÚ¿´ËÆÎÞº¦µÄϵͳÎļþÖУ¬Ê¹ÆäÔÚÊÜϰȾµÄϵͳÉÏÓÆ¾Ã´æÔÚ£¬Í¹ÆðÁË Kinsing ²»ÐÝ·¢Õ¹µÄÕ½Êõ£¬²¢Ç¿µ÷ϵͳÖÎÀíÔ±±ØÒª¶ÔÕâЩÐÂÐËÍþвά³Ö¾¯Ìè¡£Kinsing ÀûÓÃÈÝÆ÷ºÍ·þÎñÆ÷Öеķì϶À´²¿ÊðºóÃźͼÓÃÜÍÚ¿ó·¨Ê½£¬µ÷²éÁ˾ÖÏÔʾ¶à¸ö·þÎñÆ÷Êܵ½Ï°È¾£¬ÆäÖÐÔ̺¬ÓµÓÐÑϳÁȱµãµÄ Apache Tomcat¡£Tomcat ÊÇÒ»¿î¿É¹«¿ª½Ó¼ûµÄ¾²Ì¬ÄÚÈÝ¿ªÔ´·þÎñÆ÷£¬ÓÉÓÚÆäÔÚ»¥ÁªÍøÉϵͳö¶ø³ÉÎªÖØÒª¹¥»÷Ö¸±ê£¬ÕâʹµÃ Kinsing Äܹ»ÉøÈ뵽ϵͳÖв¢³ÉÁ¢°µ²ØµÄºóÃÅÒÔʵÏÖÓÆ¾ÃÐÔ£¬Í¬Ê±²¿Êð¼ÓÃÜ¿ó¹¤À´ÇÔÈ¡ÍÆËã×ÊÔ´ÒÔ½øÐмÓÃÜÇ®±ÒÍÚ¾ò¡£
https://gbhackers.com/kinsing-malware-apache-tomcat-servers/
3. SECÒªÇó½ðÈÚ×éÖ¯±ØÒªÔÚ 30 ÌìÄÚÅû¶Êý¾Ýй¶ÊÂÎñ
5ÔÂ21ÈÕ£¬ÃÀ¹ú֤ȯÂòÂôίԱ»á£¨SEC£©¶Ô SP ÂÉÀý½øÐÐÁËÅú¸Ä£¬ÒªÇó½ðÈÚ¹«Ë¾ÔÚ 30 ÌìÄڻ㱨Êý¾Ýй¶Çé¿ö¡£ÕâÊDZ£»¤Ïû·ÑÕßµÄÒ»ÃͽøÈ¡¡£ÕâÏîл®¶¨½«ÓÚ 2024 Äê 5 Ô 15 ÈÕÉúЧ£¬Ö¼ÔÚ¼ÓÇ¿ºÍ¸üжÔÏû·ÑÕß½ðÈÚÐÅÏ¢µÄ±£»¤¡£×Ô 2000 ÄêÍÆ³öÒÔÀ´£¬SEC ¼à¹Ü SPÒªÇó¾¼ÍÂòÂôÉÌ¡¢Í¶×ʹ«Ë¾ºÍ³ÖÅÆÍ¶×ÊÕÕ·÷ͨ¹ýÊéÃæÕþ²ßºÍ·¨Ê½±£»¤¿Í»§¼Í¼ºÍÐÅÏ¢¡£¸Ã¹æ¶¨»¹Ú¹ÊÏçËÈôºÎÕýȷɾ³ýÏû·ÑÕ߻㱨ÐÅÏ¢£¬²¢ÒªÇóÒþÖÔÕþ²ß֪ͨºÍÑ¡ÔñÍ˳öÑ¡Ïî¡£¶àÄêÀ´£¬¼¼ÊõµÄ½øÈ¡Ê¹µÃÊý¾Ýй¶µÄ¿ÉÄÜÐÔ¸ü´ó£¬Õâ¾ÍÊDZØÒªÕâЩŤתµÄÔÒò¡£
https://gbhackers.com/financial-organizations-data-breach/
4. Git Ô¶³Ì´úÂëÖ´Ðзì϶CVE-2024-32002
5ÔÂ21ÈÕ£¬×êÑÐÍŶӷ¢ÏÖÁËÒ»¸öÑϳÁµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶±»Ö¸¶¨Îª CVE-2024-32002£¬ÑϳÁˮƽΪ 9.0£¨ÑϳÁ£©¡£Õâ¸öÌØÊâµÄ·ì϶´æÔÚÓÚ¿í·ºÊ¹ÓõÄcloneºÅÁîÖС£Git ÉÏÖܰ䲼ÁËÒ»·Ý°²È«²¼¸æ£¬ÆäÖÐÖ¸³öÁËÓйØÔ¶³Ì´úÂëÖ´ÐеÄÎÊÌâ¡£³ý´ËÖ®±í£¬¸Ã·ì϶±»ÃèÊöΪÓÉÓÚÄܹ»ÒÔÌØ¶¨·½Ê½²ÝÄâµÄ×ÓÄ£¿é¶ø´æÔÚ£¬´Ó¶ø¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£²»ÍâÕâ¸ö·ì϶ÒѾ±»git½¨¸´£¬²¢ÇÒ°ä²¼Á˽¨²¹°æ±¾¡£Æ¾¾ÝÍøÂ簲ȫÐÂÎÅ·ÖÏíµÄ»ã±¨£¬git ʹÓÃ×ÓÄ£¿é£¬ÕâЩ×ÓÄ£¿éÊÇǶÌ×ÔÚÆäËû´æ´¢¿âÖеĴ洢¿â¡£Ã¿¸ö×ÓÄ£¿éÔÚÖ÷Ŀ¼Öж¼ÓÐÒ»¸öÖ¸¶¨µÄĿ¼õè¾¶£¬¸ÃĿ¼õè¾¶»á±»¸ú×ÙÒÔÈ·±£ÕýÈ·¼Í¼¸ü¸Ä¡£½øÒ»²½¹Û²ì·¢ÏÖ£¬Windows£¨A/modules/x£©ºÍmacOS£¨a/modules/x£©µÄĬÈÏÉèÖÃÖдæÔÚ²»·Ö±æ´óÓ×дµÄÎļþϵͳ¡£ÕâÁ½¸öõè¾¶µÄ´¦Ö÷½Ê½Ò»Ñù£¬ÕâÊÇÔ¶³Ì´úÂëÖ´Ðб³ºóµÄÖØÒªÔÒò¡£
https://gbhackers.com/git-flaw-remote-code-execution/
5. Fluent Bit ÑϳÁȱµãÓ°ÏìËùÓÐÖØÒªÔÆÌṩÉÌ
5ÔÂ21ÈÕ£¬¿ÉÔڻؾø·þÎñºÍÔ¶³Ì´úÂëÖ´Ðй¥»÷ÖÐÀûÓõĹؼü Fluent Bit ·ì϶ӰÏìÁËËùÓÐÖØÒªÔÆÌṩÉ̺ͺܶ༼Êõ¾ÞÍ·¡£Fluent Bit ÊÇÒ»ÖÖ¼«¶ÈÊ¢ÐеÄÈÕÖ¾¼Í¼ºÍÖ¸±ê½â¾ö¹æ»®£¬ºÏÓÃÓÚ Windows¡¢Linux ºÍ macOS£¬Ç¶ÈëÔÚÖØÒª Kubernetes ¿¯ÐаæÖУ¬Ô̺¬À´×Ô Amazon AWS¡¢Google GCP ºÍ Microsoft Azure µÄ¿¯Ðа档½ØÖÁ 2024 Äê 3 Ô£¬Fluent Bit µÄÏÂÔØºÍ²¿Êð´ÎÊý³¬¹ý 130 ÒڴΣ¬½Ï 2022 Äê 10 Ô±¨Â·µÄ30 ÒÚ´ÎÏÂÔØÁ¿´ó·ùÔö³¤¡£Fluent Bit Ò²±» Crowdstrike ºÍ Trend Micro µÈÍøÂ簲ȫ¹«Ë¾ÒÔ¼°Ë¼¿Æ¡¢VMware¡¢Ó¢Ìضû¡¢Adobe ºÍ´÷¶ûµÈºÜ¶à¿Æ¼¼¹«Ë¾Ê¹Óá£Õâ¸öÑϳÁµÄÄÚ´æ°Ü»µ·ì϶±»¸ú×ÙΪCVE-2024-4323£¬²¢±»·¢Ïָ÷ì϶µÄ Tenable °²È«×êÑÐÈËÔ±³ÆÎªLinguistic Lumberjack£¬ËüÊÇÔÚ°æ±¾ 2.0.7 ÖÐÒýÈëµÄ£¬ÊÇÓÉ Fluent Bit µÄǶÈëʽ HTTP ·þÎñÆ÷½âÎö¸ú×ÙÒªÇóÖеĶѻº³åÇøÒç¶Âí½ÅÒýÆðµÄ¡£Ö»¹Üδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÇáËÉÀûÓøð²È«·ì϶À´´¥·¢»Ø¾ø·þÎñ»òÔ¶³Ì²¶»ñÃô¸ÐÐÅÏ¢£¬µ«ÈôÊÇÓÐÊʵ±µÄǰÌáºÍ×ã¹»µÄ¹¦·òÀ´´´½¨¿¿µÃסµÄ·ì϶£¬ËûÃÇÒ²Äܹ»Ê¹ÓÃËüÀ´»ñµÃÔ¶³Ì´úÂëÖ´ÐС£
https://www.bleepingcomputer.com/news/security/critical-fluent-bit-flaw-impacts-all-major-cloud-providers/
6. AntidotľÂí¼Ù×°³ÉGoogle Play¸üУ¬ÇÔÈ¡ÒøÐÐÊý¾Ý
5ÔÂ22ÈÕ£¬CybleµÄ×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÖÖÕë¶Ô Android É豸µÄÐÂÒøÐÐľÂí¡£ÕâÖÖ¸´ÔӵĶñÒâÈí¼þÓµÓжàÖÖΣÏÕÖ°ÄÜ£¬Ô̺¬¸²¸Ç¹¥»÷¡¢¼üÅ̼ͼºÍ»ìºÏ¼¼Êõ¡£¸ÃľÂíÆ¾¾ÝÆäÔ´´úÂëÖеÄ×Ö·û´®¶¨ÃûΪ¡°Antidot¡±£¬ÒÔ¼Ù×°³É¹Ù·½ Google Play ¸üв¢Ö§³Ö¶àÖÖ˵»°¶øÎÅÃû£¬Ô̺¬Ó¢Óï¡¢µÂÓï¡¢·¨Óï¡¢Î÷°àÑÀÓï¡¢ÆÏÌÑÑÀÓï¡¢ÂÞÂíÄáÑÇÓÉõÖÁ¶íÓï¡£¸Ã¶ñÒâÈí¼þ×÷Ϊ Google Play µÄ¸üнøÐзַ¢£¬²¢ÒÔ¡°Ð°汾¡±µÄÃû³Æ³Ê´Ë¿ÌÊܺ¦ÕßµÄÉ豸ÉÏ¡£×°Öúͳõ´ÎÆô¶¯ºó£¬Óû§»á¿´µ½Ò»¸ö¼ÙÒ³Ãæ£¬¾Ý³ÆÀ´×Ô Google Play£¬ÆäÖÐÔ̺¬ÊµÏÖ¸üÐÂËùÐè²Ù×÷µÄ¾ßÌå×¢Ã÷¡£
https://meterpreter.org/new-antidot-trojan-masquerades-as-google-play-update-steals-banking-data/


¾©¹«Íø°²±¸11010802024551ºÅ