ºÚ¿ÍÀûÓÃ˼¿ÆSNMP·ì϶ÔÚ»¥»»»úÉϲ¿Êðrootkit
°ä²¼¹¦·ò 2025-10-201. ºÚ¿ÍÀûÓÃ˼¿ÆSNMP·ì϶ÔÚ»¥»»»úÉϲ¿Êðrootkit
10ÔÂ16ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾Ç÷Ïò¿Æ¼¼Åû¶£¬ÍþвÐÐΪÕßÕýÀûÓÃ˼¿ÆIOS/IOS XEϵͳÖÐÒѽ¨²¹µÄÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2025-20352£¬Õë¶Ô9400¡¢9300¼°´«Í³3750GϵÁÐδ²¿Êð¶Ëµã¼ì²âÏìÓ¦½â¾ö¹æ»®µÄÉ豸ÌáÒé¹¥»÷¡£¸Ã·ìÏ¶Éæ¼°SNMPºÍ̸£¬¹¥»÷Õßͨ¹ý»ñÈ¡rootȨÏÞ¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬Ë¼¿ÆÒÑÔÚ10ÔÂ6ÈÕ¸üв¼¸æÖн«ÆäÏóÕ÷ΪÁãÈÕ·ì϶²¢È·ÈÏ´æÔڳɹ¦ÀûÓð¸Àý¡£¹¥»÷±»×·×ÙΪ"Operation Zero Disco"£¬ÒòÖ²Èë¶ñÒâÈí¼þʱÉèÖÃÁËÔ̺¬"disco"µÄͨÓýӼûÃÜÂë¡£×êÑÐÏÔʾ£¬¹¥»÷Õß²»½öÀûÓÃзì϶£¬»¹³¢ÊÔ¸´ÓÃÆßÄêǰ¾É·ì϶CVE-2017-3881À©´ó¹¥»÷Ãæ¡£³É¹¦ÉøÈëºó£¬¹¥»÷ÕßÔÚÖ¸±êϵͳ²¿Êð¾ß±¸Óƾû¯ÄÜÁ¦µÄLinux Rootkit£¬¸Ã¹¤¾ß°ü¼¯³ÉUDP½ÚÔìÆ÷£¬¿ÉʵÏֶ˿ڼàÌý¡¢ÈÕÖ¾´Û¸Ä¡¢ÈƹýAAAÈÏÖ¤ºÍVTY½Ó¼û½ÚÔìÁÐ±í¡¢¶¯Ì¬Åú¸ÄͨÓÃÃÜÂë¡¢°µ²ØÅäÖÃÏî¼°³ÁÖù¦·ò´ÁµÈ²Ù×÷¡£×êÑÐÈËԱǿµ÷£¬µ±Ç°²»×ã¿¿µÃס¹¤¾ßÏóÕ÷ÊÜϰȾÉ豸£¬½¨ÒéÒÉ»óÔâÈëÇÖµÄ×éÖ¯Ö´Ðеͼ¶¹Ì¼þ¼°ROMÇøÓòÉî¶Èµ÷²é¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-cisco-snmp-flaw-to-deploy-rootkit-on-switches/
2. µÃ¿ËÈøË¹ÖݵçÁ¦ºÏ×÷ÉçÔâ¡°÷è÷롱ÀÕË÷Èí¼þ¹¥»÷
10ÔÂ14ÈÕ£¬ÍøÂç·¸×ïÍŻ÷è÷롱£¨Qilin£©ÔÚ°µÍøÐ¹Â¶ÍøÕ¾Ðû³ÆÒÑÈëÇֵÿËÈøË¹ÖÝÁ½¼ÒµçÁ¦·ÖÏúºÏ×÷É磬ʥ²®ÄɵµçÁ¦ºÏ×÷ÉçÓ뿨¶÷˹µçÁ¦ºÏ×÷É磬²¢Ð¹Â¼ûô¸Ð²ÆÕþÎļþ¡£Ê¥²®ÄɵºÏ×÷ÉçÕ¼ÓÐ3900Ó¢ÀïÅäµçÏß·£¬·þÎñ8ÏØÔ¼2.8Íò»§¼ÒÍ¥£¬ÄêÊÕÈë9250ÍòÃÀÔª£»¿¨¶÷˹ºÏ×÷ÉçÔËÓª½ü5000Ó¢ÀïÏß·£¬¸²¸Ç12ÏØ2.3Íò»§¼ÒÍ¥£¬ÄêÊÕÈë7580ÍòÃÀÔª¡£Á½¼Ò»ú¹¹¾ùÊôÃÀ¹ú¹Ø¼ü»ù´¡ÉèÊ©£¬Æä°²È«Ö±½Ó¹ØÏµ¹ú¶È°²È«¡£¡°÷è÷롱ÔÚÐ¹Â¶ÍøÕ¾°ä²¼ÁËÊý¾ÝÑù±¾£¬Ô̺¬Ê¥²®Äɵµijõ´ÎÊÂÎñ»ã±¨£¨º¬ÈËԱȫÃû¡¢µç»°¼°ÊÂÎñÏêÇ飩¡¢Äê¶ÈÔ¤Ëã¡¢±£ÏÕÎļþ¡¢·ÑÂʰ¸ÓöȻ㱨µÈ£»¿¨¶÷˹·½ÃæÔòй¶Á˶Ê»á³ÉÔ±Ãûµ¥£¨º¬µØÖ·¡¢ÁªÏµ·½Ê½£©¡¢³öÈëÓà¶î»ã±¨¡¢×éÖ¯³ÉÔ±Êý¾ÝµÈ¡£Ö»¹ÜÊý¾ÝÕæÊµÐÔÉÐδºËʵ£¬µ«ÈôÊôʵ£¬½«Â¶³öÆóÒµ¶¨¼ÛÕ½Êõ¡¢Òý·¢ÐÅÀµÎ£»ú»ò¾ºÕùÁÓÊÆ£¬Ó×ÎÒÉí·ÝÐÅÏ¢£¨PII£©¸ü¿ÉÄܱ»ÓÃÓÚÉí·Ý͵ÇÔ¡¢É§Èż°Éç»á¹¤³Ì¹¥»÷£¬ÓÈÆä¶Ô¶Ê»á³ÉÔ±·çÏÕ¼«¸ß¡£
https://cybernews.com/security/texas-electric-coops-ransomware-attack/
3. F5Åû¶³Á´ó°²È«·ì϶£¬È«Çò³¬26ÍòBIG-IPÉè±¸Ãæ¶Ô·çÏÕ
10ÔÂ17ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾F5½üÈÕÅû¶£¬·ÇͶ»ú×éÖ¯Shadowserver Foundation·¢ÏÖÈ«Çò³¬¹ý26.6Íò¸öF5 BIG-IPÊ·ý¶³öÓÚ»¥ÁªÍø£¬ÆäÖÐÃÀ¹úÕ¼14.2Íò¸ö£¬Å·ÖÞºÍÑÇÖÞ¹²Ô¼10Íò¸ö¡£F5֤ʵÆäÍøÂçÔâ¹ú¶ÈºÚ¿ÍÈëÇÖ£¬ÇÔÈ¡ÁËδ¹«¿ªµÄBIG-IP°²È«·ì϶Դ´úÂë¼°ÓйØÐÅÏ¢£¬µ«Î´·¢ÏÖ¹¥»÷ÕßÀûÓÃÕâЩ·ì϶µÄÖ¤¾Ý¡£ÎªÓ¦¶ÔÍþв£¬F5´¹Î£°ä²¼²¹¶¡½¨¸´44¸ö·ì϶£¨º¬±»ÇÔÈ¡·ì϶£©£¬²¢¶½´Ù¿Í»§¸üÐÂBIG-IP¡¢F5OS¡¢BIG-IP Next for KubernetesµÈϵÁвúÆ·¡£F5 »¹Ò»ÏòÔÚÓëÆä¿Í»§·ÖÏíÒ»·ÝÍþвËÑË÷Ö¸ÄÏ£¬Éæ¼°BrickstormºóÃÅ·¨Ê½¼°UNC5291Íþв×éÖ¯¡£ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Í¬²½°ä²¼´¹Î£Ö¸ÁҪÇóÁª¹ú»ú¹¹ÔÚ10ÔÂ22ÈÕǰΪF5OS¡¢BIG-IP TMOS¡¢BIG-IQºÍBNK/CNF²úÆ·×°ÖÃ×îв¹¶¡£¬²¢½«ÆäËûF5É豸µÄ¸üнØÖ¹ÈÕÆÚµ¢¸éÖÁ10ÔÂ31ÈÕ¡£CISAÇ¿µ÷£¬»ú¹¹ÐèÅ̵ãËùÓÐF5 BIG-IPÉ豸£¬ÆÀ¹ÀÍøÂçÖÎÀí½Ó¿ÚµÄ»¥ÁªÍøÂ¶³öÇé¿ö£¬²¢Í£ÓÃÒÑÖÕÖ¹Ö§³ÖµÄÉ豸¡£
https://www.bleepingcomputer.com/news/security/over-266-000-f5-big-ip-instances-exposed-to-remote-attacks/
4. Å·ÖÞµ·»Ù¿ç¹ú·¸·¨SIM¿¨ºÐÍøÂç£¬ÆÆ»ñ³¬3200Æðڲư¸
10ÔÂ17ÈÕ£¬Å·ÖÞÐ̾¯×éÖ¯½áºÏ¶à¹ú·¨Âɲ¿ÃÅ·¢Õ¹µÄ"SIMCARTEL"Ðж¯ÖУ¬³É¹¦µ·»ÙÒ»¸öÉæ¼°80Óà¹úµÄ·¸·¨SIM¿¨ºÐ·þÎñÍøÂç¡£¸Ã·¸×ï×éÖ¯ÔËÓªgogetsms.comºÍapisim.comÁ½¸öÍøÕ¾£¬²¿Êð1,200̨SIMºÐÉ豸¼°40,000ÕÅSIM¿¨£¬ÎªÈ«Çò·¸×ï·Ö×ÓÌṩÐéαµç»°ºÅÂëÒÔ´´½¨ºÍÑéÖ¤Ú²ÆÐÔÔÚÏßÕË»§£¬ÓÃÓÚÖ´ÐÐÍøÂç´¹µö¡¢Í¶×ÊÚ¿Æ¡¢¼ÙÒ⹫¼ì·¨¡¢ÀÕË÷¼°ÍµÔËÒÆÃñµÈ·¸×ï»î¶¯¡£¾ÝÅ·ÖÞÐ̾¯×éÖ¯´«µÝ£¬¸Ã·þÎñÖ±½Ó¹ØÁª°ÂµØÀû1,700Æð¡¢ÀÍÑάÑÇ1,500Æðڲư¸¼þ£¬ÀÛ¼ÆÔì³É¾¼ÃËðʧ³¬450ÍòÅ·Ôª¡£Æä¼¼Êõ¼Ü¹¹¸´ÔÓ£¬¿É°µ²ØÓû§ÕæÊµÉí·ÝºÍµØÎ»£¬Öú³¤´´½¨4,900Íò¸öÐéÎ±ÍøÂçÕË»§£¬Éæ¼°µçÐÅÚ¿Æ¡¢WhatsApp"Ç×ÊôÚ¿Æ"¡¢ÐéαͶ×ÊÆ½Ì¨Ú¿ÆµÈ¶àÖÖ·¸×ï״̬¡£10ÔÂ10ÈÕÐж¯ÖУ¬¾¯·½ÔڰµØÀû¡¢°®É³ÄáÑÇ¡¢·ÒÀ¼¡¢ÀÍÑάÑÇËĹúͬ²½·¢Õ¹26´ÎËѲ飬¿ÛÁô5ÃûÀÍÑάÑǼ®Ö÷·¸¼°2Ãû¹²·¸£¬½É»ñ¼ÛÖµÊý°ÙÍòÅ·ÔªµÄ×ʲú£ºÔ̺¬1,200̨SIMºÐÉ豸¡¢ÊýÊ®ÍòÕÅSIM¿¨¡¢5̨·þÎñÆ÷¡¢¶³½áÒøÐÐÕË»§43.1ÍòÅ·Ôª¼°¼ÓÃÜÇ®±ÒÕË»§33.3ÍòÃÀÔª£¬²¢¿ÛѺ4Á¾ÉÝ»ª³µ¡£Ä¿Ç°£¬±»²é·âµÄ·þÎñÆ÷Õý½øÐÐȡ֤·ÖÎöÒÔ×·Òä¿Í»§Éí·Ý¡£
https://www.bleepingcomputer.com/news/security/europol-dismantles-sim-box-operation-renting-numbers-for-cybercrime/
5. ÃÀ¹úº½¿Õ×Ó¹«Ë¾Envoy AirÔâClopÀÕË÷ÍŻ﹥»÷
10ÔÂ17ÈÕ£¬ÃÀ¹úº½¿ÕÆìÏÂÇøÓòº½¿Õ¹«Ë¾Envoy Air֤ʵ£¬ÆäOracle E-Business SuiteÀûÓ÷¨Ê½Êý¾ÝÔâClopÀÕË÷ÍÅ»ïй¶¡£Envoy Air°µÊ¾£¬µ÷²éºóÈ·ÈϽöÉÙÁ¿Ã³Ò×ÐÅÏ¢¼°ÁªÏµ·½Ê½±íй£¬ÎÞÃô¸Ð»ò¿Í»§Êý¾ÝÊÜÓ°Ïì¡£¸Ã¹«Ë¾ÒÑÁªÏµ·¨Âɲ¿ÃŲ¢·¢Õ¹È«ÃæÉó²é¡£Õâ´ÎÊÂÎñÓëClopÍÅ»ï8ÔÂÆô¶¯µÄÊý¾Ý͵ÇԻÓйأ¬¸ÃÍÅ»ïͨ¹ýµç×ÓÓʼþÏòÊܺ¦ÆóÒµ·¢ËÍÀÕË÷ÒªÇó£¬Ðû³ÆÇÔÈ¡ÁËOracle EBSϵͳÖеÄÊý¾Ý¡£OracleÅû¶£¬¹¥»÷ÀûÓÃÁ˱àºÅΪCVE-2025-61882ºÍCVE-2025-61884µÄÁãÈÕ·ì϶£¬ÆäÖÐCVE-2025-61884ÓÚÉÏÖܱ»ÍµÍµ½¨²¹£¬µ«Î´¹«¿ªÆäÔø±»»ý¼«ÀûÓá£CrowdStrikeºÍMandiant֤ʵ£¬ClopÔÚ8Ô³õÀûÓÃÕâЩ·ì϶ÈëÇÖϵͳ²¢²¿Êð¶ñÒâÈí¼þ¡£×÷Ϊͳһ¹¥»÷Á´µÄÒ»²¿ÃÅ£¬¹þ·ð´óѧҲÔâClopÀÕË÷£¬¸ÃУ³Æ½ö¡°Ó×ÐÍÐÐÕþµ¥ÔªÓйط½¡±ÊÜÓ°Ïì¡£
https://www.bleepingcomputer.com/news/security/american-airlines-subsidiary-envoy-confirms-oracle-data-theft-attack/
6. macOSαÔìÆ½Ì¨¹¥»÷ÏÖÐÂÍþв£ºAMOSÓëOdysseyÇÔÈ¡Èí¼þËÁŰ
10ÔÂ18ÈÕ£¬½üÈÕ£¬Õë¶ÔmacOS¿ª·¢ÈËÔ±µÄ¶ñÒâ»î¶¯ÀûÓÃαÔìHomebrew¡¢LogMeInºÍTradingViewƽ̨´«²¼AMOS£¨Atomic macOS Stealer£©¼°OdysseyµÈÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ¡£¹¥»÷Õßѡȡ¡°ClickFix¡±¼¼Êõ£¬Í¨¹ýGoogle AdsÍÆ¹ãµÄ85¸öðÃûÓòÃûÓÕÆÓû§¸´ÔìcurlºÅÁî×°ÖöñÒⷨʽ¡£ÀýÈ磬TradingViewÐéÎ±ÍøÕ¾ÒÔ¡°°²È«È·ÈÏ¡±Îª»Ï×Ó£¬ÏÖʵ½«base64±àÂëµÄ×°ÖúÅÁÔìµ½¼ôÌù°å£¬Ö´ÐкóÏÂÔØ²¢½âÂë¡°install.sh¡±Îļþ£¬ÈƹýGatekeeper·À»¤»úÔ죬×îÖÕ¼ÓÔØAMOS»òOdyssey¶ñÒâÈí¼þ¡£ÕâЩ¶ñÒâÈí¼þ¾ß±¸·´Ðé¹¹»ú¼ì²âÄÜÁ¦£¬ÔËÐкóÊ×ÏÈÒÔrootȨÏÞÍøÂçÖ÷»úÓ²¼þ¡¢ÄÚ´æÐÅÏ¢£¬²¢Í¨¹ý°Ñ³Öϵͳ·þÎñ£¨ÈçÖÕÖ¹OneDriveÊØ»¤¹ý³Ì£©¼°ÓëmacOS XPC·þÎñ½»»¥£¬½«¶ñÒâ»î¶¯¼Ù×°³ÉºÏ·¨¹ý³Ì¡£×îÖÕ¼¤»îÐÅÏ¢ÇÔÈ¡×é¼þ£¬ÇÔÈ¡ä¯ÀÀÆ÷´æ´¢µÄÃô¸ÐÊý¾Ý¡¢¼ÓÃÜÇ®±ÒÇ®°üƾ֤¡¢Ô¿³×´®ÄÚÈݼ°Ó×ÎÒÎļþ£¬ÒÔZIPÌåʽ»Ø´«ÖÁ¹¥»÷Õß½ÚÔìµÄC2·þÎñÆ÷¡£
https://www.bleepingcomputer.com/news/security/google-ads-for-fake-homebrew-logmein-sites-push-infostealers/


¾©¹«Íø°²±¸11010802024551ºÅ