ÒÁÀʺڿÍ×éÖ¯OilRig¶ÔÒÁÀ¿Ëµ±¾ÖÌáÒé¶ñÒâÈí¼þ¹¥»÷
°ä²¼¹¦·ò 2024-09-149ÔÂ12ÈÕ£¬ÒÁÀ¿Ëµ±¾ÖÍøÂç½üÆÚ³ÉΪÒÁÀÊÖ§³ÖµÄÍøÂç×éÖ¯OilRig£¨Òà³ÆAPT34µÈ£©µÄ¾«ÐIJ߶¯¹¥»÷Ö¸±ê¡£¾ÝÍøÂ簲ȫ¹«Ë¾Check Point·ÖÎö£¬Õâ´Î¹¥»÷Õë¶ÔÒÁÀ¿Ë×ÜÀí°ì¹«ÊÒ¼°±í½»²¿µÈ¹Ø¼ü²¿ÃÅ£¬ÀûÓÃжñÒâÈí¼þVeatyºÍSpearal£¬Í¨¹ý¼Ù×°ÎĵµºÍÉç»á¹¤³Ìѧ¼¿Á©ÉøÈëÍøÂç¡£OilRig×Ô2014ÄêÆðÔÚÖж«µØÓò»îÔ¾£¬ÉÆÓÚÍøÂç´¹µöºÍ¶¨ÔìºóÃŹ¥»÷£¬Õâ´ÎÒ²²»Àý±í£¬Õ¹Ê¾ÁËÆä¹ÖÒìµÄºÅÁîÓë½ÚÔì»úÔ죬Ô̺¬×Ô½ç˵DNSËí·ºÍ»ùÓÚ±»Ï°È¾µç×ÓÓʼþµÄC2ͨ·¡£¹¥»÷Á´Í¨¹ýºýŪÐÔÎļþÆô¶¯£¬Ö´ÐÐPowerShell»òPyinstaller¾ç±¾£¬É¾³ýºÛ¼£²¢²¿Êð¶ñÒâÈí¼þ¡£SpearalÀûÓÃDNSËí·ͨѶ£¬VeatyÔòͨ¹ýÌØ¶¨ÓÊÏäÏÂÔØ²¢Ö´ÐкÅÁî¡£´Ë±í£¬»¹·¢ÏÖÓëSSHËí·ºóÃźÍIIS·þÎñÆ÷ºóÃÅÓйصĻ£¬Åú×¢¹¥»÷Õß¼¿Á©¶àÑùÇÒ¼¼ÊõÏȽø¡£Check PointÇ¿µ÷£¬Õâ´ÎÐж¯Í¹ÏÔÁËÒÁÀÊÍþвÐÐΪÕßÔÚµØÓòÄڵijÖÐøºÍ¼¯ÖÐÖÂÁ¦£¬ÒÔ¼°ÆäÔÚ¿ª·¢×¨ÃÅC2»úÔìÉϵÄÐîÒâͶÈë¡£
https://thehackernews.com/2024/09/iranian-cyber-group-oilrig-targets.html
2. TrickMoÒøÐÐľÂíбäÖÔìØ¹â£º¼ÓÇ¿Íþв£¬ÇÔÈ¡ÒþÖÔ
9ÔÂ12ÈÕ£¬Cleafy Íþвµý±¨ÍŶÓ×î½ü¸æ·¢ÁËTrickMoÒøÐÐľÂíµÄÒ»¸öÐÂÐͱäÖÖ£¬ÕâÒ»±äÖÖ²»½ö¼Ì³Ð²¢Ç¿»¯ÁËÆäǰÉíÕë¶ÔAndroidÉè±¸ÒøÐÐÆ¾Ö¤µÄ´«Í³ÍþвÄÜÁ¦£¬»¹ÒýÈëÁËÆÁϼÔì¡¢¼üÅ̼ͼ¼°Ô¶³Ì½ÚÔìµÈ¸ß¼¶Ö°ÄÜ£¬¼«´óµØÀ©´óÁËÆä¹¥»÷ÁìÓòºÍ·ÛËéÁ¦¡£TrickMo×÷ΪTrickBot¼Ò×åµÄÒ»Ô±£¬×Ô2019Äê³õ´Î±»·¢ÏÖÒÔÀ´£¬³ÖÐø½ø»¯£¬ÏÖÒѳÉΪ½ðÈÚڲƺÍÓ×ÎÒÒþÖÔ°²È«µÄ³Á´óÒþ»¼¡£Ð±äÖÖ²»½öÄÜÀ¹½ØÒ»´ÎÐÔÃÜÂë(OTP)ÈÆ¹ýË«³É·ÖÈÏÖ¤(2FA)£¬¸üͨ¹ýÖ±½Ó½ÚÔìÊܺ¦ÕßÉ豸ִÐÐÉ豸ڲÆ(ODF)£¬ºöÊÓ×îçÇÃܵÄÒøÐа²È«·À»¤¡£ÓÈΪÑϳÁµÄÊÇ£¬Cleafy·¢ÏָñäÖÖ»¹´ÓÊÜϰȾÉ豸ÖÐÇÔÈ¡Ãô¸ÐÊý¾Ý£¬²¢½«ÕâЩÊý¾Ý´æ´¢ÔÚÎÞ±£»¤µÄºÅÁîÓë½ÚÔì(C2)·þÎñÆ÷ÉÏ£¬µ¼ÖÂÊý¾Ýй¶·çÏÕ¼¤Ôö£¬ÈκεÚÈý·½¶¼ÄܵÈÏлñÈ¡ÕâЩÊý¾Ý¡£±»µÁÊý¾Ý³¬¹ý 12 GB£¬Ô̺¬Ó×ÎÒÉí·ÝÖ¤¼þ¡¢²ÆÕþÐÅÏ¢£¬ÉõÖÁÊܺ¦ÕßµÄ˽ÃÜÕÕÆ¬¡£TrickMoͨ¹ýÀÄÓÃAndroidµÄ¸¨ÖúÖ°ÄÜ·þÎñ£¬ÊµÏÖÎÞÉùÎÞÏ¢µÄȨÏÞÌáÉýÓë¹¥»÷Ö´ÐУ¬½øÒ»²½¼Ó¾çÁËÆäÍþвµÄÒñ±ÎÐÔ΢·çÏÕÐÔ¡£
https://securityonline.info/beware-the-new-trickmo-banking-trojan-enhanced-features-increased-danger/
3. ÍøÂçÍþвж¯Ïò£ººÏ·¨Python¿â³É¹¥»÷ÀûÆ÷
9ÔÂ12ÈÕ£¬°²È«×êÑÐÈËÔ±Mertens½üÆÚ°ä²¼ÁËÒ»·Ý»ã±¨£¬½ÒʾÁËÍøÂçÍþвÁìÓòµÄÒ»ÏîÑϸñÇ÷Ïò£ºÍøÂç·¸×ï·Ö×ÓÕýÈÕ񾮾ÃîµØÀûÓúϷ¨µÄPython¿âÖ´ÐжñÒâ»î¶¯¡£ÕâЩ¿â£¬ÈçpyWinhook¡¢psutil¡¢win32guiºÍpyperclip£¬Õý±¾ÓÃÓÚÈí¼þ¿ª·¢ºÍ×Ô¶¯»¯£¬È´±»·¸×ï·Ö×ÓÀÄÓÃÒÔÖ´ÐмüÅ̼ͼ¡¢ÏµÍ³¼à¿Ø¡¢¼ôÌù°å½Ù³ÖµÈ¶ñÒâÐÐΪ¡£MertensÖ¸³ö£¬PyPi.orgµÈÖØ´ó¿âÉú̬ϵͳµÄ´æÔÚ£¬Îª¶ñÒâÈí¼þ¿ª·¢ÕßÌṩÁË·á˶µÄ×ÊÔ´¡£Ö»¹ÜÕâЩ¿â×ÔÉíÎÞº¦£¬µ«ËüÃǵÄ׳´óÖ°Äܱ»·¸·¨·Ö×ÓÀûÓã¬ÒÔÌӱܼì²â£¬ÊµÏÖ´úÂë×¢Èë¡¢Êý¾Ýй¶µÈÖ÷ÕÅ¡£ÀýÈ磬discord¿â±»³ÁаüװΪC2ƽ̨£¬ftplib¡¢dropboxµÈ¹¤¾ßÔò³ÉΪÊý¾Ýй¶µÄצÑÀ¡£¸üÁîÈËÓÇÓôµÄÊÇ£¬¹¥»÷Õß»¹Ñ¡È¡Python»ìºÏ¼¼Êõ£¬ÈçmarshalºÍpy_compile£¬½øÒ»²½ÍÌͶñÒâ´úÂ룬Ôö³¤ÄæÏò¹¤³ÌµÄÄѶȡ£ÕâÖÖÕ½ÊõʹµÃ¶ñÒâÈí¼þ¸üÄѱ»°²È«·ÖÎöʦ¾õ²ì£¬´Ó¶ø¼Ó¾çÁËÍøÂ簲ȫ·ÀÓùµÄ¸´ÔÓÐÔ¡£
https://securityonline.info/cybersecurity-alert-python-libraries-exploited-for-malicious-intent/
4. Î÷ÑÅͼ¸ÛÔâRhysidaÀÕË÷Èí¼þ¹¥»÷
9ÔÂ13ÈÕ£¬Î÷ÑÅͼ¸Û×÷Ϊ¼à¹ÜÎ÷ÑÅͼµØÓòº£¸ÛÓë»ú³¡µÄ³ÁÒªµ±¾Ö»ú¹¹£¬½üÆÚÈ·ÈÏÆäϵͳÔÚ´ÓǰÈýÖÜÄÚÔâ·êÁËRhysidaÀÕË÷Èí¼þÍÅ»ïµÄ¶ñÒâ¹¥»÷¡£¸Ã¹¥»÷ʼÓÚ8Ô£¬ÆÈʹ¸Û¿Ú´¹Î£¸ôÀ벿ÃŹؼüϵͳÒÔ¶ôÔìÓ°Ï죬ֱ½Ó×ÌÈÅÁËÎ÷ÑÅͼ-Ëþ¿ÆÂí¹ú¼Ê»ú³¡µÄº½°àÔ¤Ô¼ÓëµÇ»úÁ÷³Ì£¬µ¼Öº½°àÑÓÎó¡£ÈýÖܺ󣬸ۿڹٸÕÕýʽָÈÏRhysidaΪĻºó×ï¿ý£¬²¢ÉêÃ÷×ÔÊ·¢ºóϵͳδÔÙÊÜеÄδÊÚȨ»î¶¯ÇÖÈÅ£¬»ú³¡¼°¸Û¿ÚÉèÊ©ÈÔÊô°²È«¡£Õâ´Î¹¥»÷ÖУ¬RhysidaÍÅ»ï³É¹¦ÉøÈë¸Û¿ÚÍÆËã»úϵͳ£¬¼ÓÃܹؼüÊý¾Ý£¬µ¼ÖÂÔ̺¬ÐÐÀî´¦Öá¢×ÔÖ÷·þÎñ¡¢Wi-FiÍøÂç¡¢ÐÅÏ¢ÏÔʾµÈ¶à¸ö·þÎñÖжϡ£Ö»¹Ü¸Û¿ÚѸ¿ìÏìÓ¦£¬¸´ÔÁË´ó²¿ÃÅϵͳ£¬µ«ÈÔÔÚÈ«Á¦½¨¸´Èç¹Ù·½ÍøÕ¾¡¢·Ã¿Íͨ³©Ö¤·þÎñµÈ¹Ø¼üÖ°ÄÜ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬¸Û¿Ú¼á¶¨»Ø¾øÖ§¸¶Êê½ð£¬ÕÃÏÔÁËÆäÊØ»¤¹«¹²×ʽð°²È«¡¢²»Ïò·¸×ïÍ×еÄ̬¶È¡£Rhysida×÷ΪһÖÖÐÂÐ˵ÄÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©£¬×Ô½ñÄê5Ô»îÔ¾ÒÔÀ´£¬ÒÑÂŴζÔÈ«Çò¶à¸öÁìÓòÌáÒé¹¥»÷¡££¬CISAÓëFBIµÈ»ú¹¹ÒÑ·¢³öÖҸ棬ÌáÐѸ÷ÐÐÒµ¼ÓÇ¿ÍøÂ簲ȫ·À»¤£¬¹²Í¬ÕмÜÀÕË÷Èí¼þµÄÇÖº¦¡£
https://www.bleepingcomputer.com/news/security/port-of-seattle-says-rhysida-ransomware-was-behind-august-attack/
5. Ivanti CSA¸ßΣ·ì϶ÔâÀûÓã¬Áª¹ú»ú¹¹ÆÚÏÞ½¨²¹
9ÔÂ13ÈÕ£¬IvantiÈ·ÈÏÆäÔÆ·þÎñÉ豸£¨CSA£©½â¾ö¹æ»®ÖдæÔÚ¸ßΣ·ì϶CVE-2024-8190£¬¸Ã·ì϶ÒÑÔâ¹¥»÷ÕßÀûÓá£Æð³õ£¬Ivanti»ã±¨³ÆÎ´·¢ÏÖ¿Í»§ÊÜÓ°Ï죬µ«ËæºóÈ·ÈÏÉÙÊý¿Í»§ÒÑÖÐÕС£¸Ã·ì϶ÔÊÐíÔ¶³ÌÈÏÖ¤µÄÖÎÀíԱͨ¹ýºÅÁî×¢ÈëÔÚCSA 4.6°æ±¾ÉÏÖ´ÐÐÔ¶³Ì´úÂë¡£Ivanti½¨ÒéÑ¡È¡ÌØ¶¨ÅäÖýµµÍ·çÏÕ£¬²¢²é³ÖÎÀíÓû§È¨ÏÞ¼°ÏµÍ³ÈÕÖ¾ÒÔ¼ì²â¹¥»÷³¢ÊÔ¡£Í¬Ê±£¬¹«Ë¾¶½´Ù¿Í»§´ÓÒÑÖÕÖ¹Ö§³ÖµÄCSA 4.6.xÉý¼¶µ½CSA 5.0°æ±¾£¬»òÖÁÉÙ¸üÐÂÖÁCSA 4.6µÄPatch 519¡£´Ë±í£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Òѽ«CVE-2024-8190²ÎÓëÆäÒÑÖª±»ÀûÓ÷ì϶Ŀ¼£¬ÒªÇóÁª¹ú»ú¹¹ÔÚ10ÔÂ4ÈÕǰ½¨¸´¡£CISAÇ¿µ÷´ËÀà·ì϶´ºÁª¹úÆóÒµ×é³É³Á´óÍþв¡£IvantiÔÚÈ«ÇòÕ¼ÓÐ¿í·ºµÄºÏ×÷ͬ°éÍøÂ磬Æä²úÆ·ºÍ·þÎñ±»³¬¹ý40,000¼Ò¹«Ë¾ÓÃÓÚϵͳÖÎÀí£¬Õâ´ÎÊÂÎñÔÙ´Î͹ÏÔÁËʵʱ½¨¸´°²È«·ì϶µÄ³ÁÒªÐÔ¡£
https://www.bleepingcomputer.com/news/security/ivanti-warns-high-severity-csa-flaw-is-now-exploited-in-attacks/
6. Trojan Ajina.BankerËÁŰÖÐÑÇ£º¼Ù×°ºÏ·¨ÀûÓÃÇÔÈ¡ÒøÐÐÐÅÏ¢
9ÔÂ13ÈÕ£¬ÃûΪTrojan Ajina.BankerµÄÐÂÐÍAndroid¶ñÒâÈí¼þÕýËÁŰÖÐÑǵØÓò£¬ÒÔÎÚ×ȱð¿Ë˹̹Éñ»°ÖеÄÒõ¶¾¾«Á鶨Ãû£¬Í¨¹ý¼Ù×°³ÉºÏ·¨ÀûÓ÷¨Ê½ÈçÒøÐзþÎñºÍµ±¾ÖÃÅ»§£¬ÀûÓÃTelegramµÈƽ̨ÉϵÄÉç½»¹¤³ÌÕ½ÊõÓÕµ¼Óû§ÏÂÔØ²¢ÔËÐжñÒâÎļþ¡£×Ô2023Äê11ÔÂÒÔÀ´£¬ÒÑ·¢ÏÖÔ¼1,400ÖÖ±äÖÖ£¬ÖØÒªÖ¸±êΪÎÚ×ȱð¿Ë˹̹Óû§£¬µ«¹¥»÷ÁìÓòÒÑÀ©É¢ÖÁ¶à¸ö¹ú¶È¡£Ajina.Bankerͨ¹ý·¢ËÍÓÕÈËÓŻݺʹÙÏúÐÅÏ¢µÄ¶ñÒâÁ´½Ó£¬ÒÔ¼°·ÖÏíÍйܶñÒâÈí¼þµÄƵ·Á´½Ó£¬ÀûÓÃÓû§µÄºÃÆæÐĽøÐд«²¼¡£Æä±¾µØ»¯ÍƹãÕ½ÊõÔÚÇøÓòÉçÇøÖÐÔì×÷½ôÆÈ¸Ð£¬´ÙʹÓû§²»¾Ë¼ÂǼ´µã»÷Á´½Ó¡£¸Ã¶ñÒâÈí¼þ²»½öÄÜÍøÂç½ðÈÚÀûÓÃÐÅÏ¢¡¢SIM¿¨ÏêÇ飬»¹ÄÜÀ¹½Ø¶ÌÐÅÒÔ»ñÈ¡2FAÑéÖ¤Â룬չʾ³ö¸ß¶ÈÊÊÓ¦ÐԺͽø»¯ÄÜÁ¦¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Ajina.BankerѡȡͬÃË´òËãģʽÔËÓª£¬Ö÷ÌâÍŶÓÓëͬÃËÍøÂçºÏ×÷£¬Í¨¹ý¶ÈÏí±»µÁ×ʽð¼¤Àø·Ö·¢ºÍϰȾÁ´µÄÀ©´ó¡£Ãæ¶ÔÕâÒ»Íþв£¬×¨¼Ò½¨Òéά³Ö¾¯Ì裬Ԥ·Àµã»÷δ¾ÒªÇóµÄÐÂÎźÍÏÂÔØÁ´½Ó£¬¶ÔÖÅʹÓùٷ½ÀûÓÃÉ̵êÏÂÔØÀûÓ㬲¢×Ðϸ²é³ÀûÓÃȨÏÞ¡£
https://hackread.com/android-malware-ajina-banker-steal-2fa-codes-telegram/


¾©¹«Íø°²±¸11010802024551ºÅ