Magnet Goblin ºÚ¿Í×é֯ʹÓÃÎó²î°²ÅÅ Nerbian RAT
Ðû²¼Ê±¼ä 2024-03-123ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬Ò»¸öÃûΪMagnet GoblinµÄ³öÓÚ¾¼ÃÄîÍ·µÄÍþвÐÐΪÕßÕýÔÚѸËÙ½«1dayÇå¾²Îó²îÄÉÈëÆäÎäÆ÷¿â£¬£¬£¬£¬£¬£¬ÒÔ±ãËÅ»úÆÆËð±ßÑØ×°±¸ºÍÃæÏò¹«ÖÚµÄЧÀÍ£¬£¬£¬£¬£¬£¬²¢ÔÚÊÜѬȾµÄÖ÷»úÉϰ²ÅŶñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£µÐÊÖÌᳫµÄ¹¥»÷ʹÓÃδÐÞ²¹µÄ Ivanti Connect Secure VPN¡¢Magento¡¢Qlik Sense ÒÔ¼°¿ÉÄÜµÄ Apache ActiveMQ ЧÀÍÆ÷×÷Ϊ³õʼѬȾǰÑÔÀ´»ñµÃδ¾ÊÚȨµÄ»á¼û¡£¡£¡£¡£¡£¡£¡£¡£¾Ý³Æ¸Ã×éÖ¯ÖÁÉÙ×Ô 2022 Äê 1 ÔÂÆð¾ÍÒ»Ö±»îÔ¾¡£¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îºó£¬£¬£¬£¬£¬£¬»á°²ÅÅÒ»¸öÃûΪ Nerbian RAT µÄ¿çƽ̨Զ³Ì»á¼ûľÂí (RAT)£¬£¬£¬£¬£¬£¬¸ÃľÂíÓÉ Proofpoint ÓÚ 2022 Äê 5 ÔÂÊ×´ÎÅû¶£¬£¬£¬£¬£¬£¬Æä¼ò»¯±äÖÖΪ MiniNerbian¡£¡£¡£¡£¡£¡£¡£¡£DarktraceÖ®Ç°ÔøÇ¿µ÷¹ý Linux °æ±¾ Nerbian RAT µÄʹÓᣡ£¡£¡£¡£¡£¡£¡£ÕâÁ½ÖÖ²¡¶¾¶¼ÔÊÐíÖ´ÐдÓÏÂÁîÓë¿ØÖÆ (C2) ЧÀÍÆ÷ÎüÊÕµÄí§ÒâÏÂÁ£¬£¬£¬£¬£¬²¢Ð¹Â¶·µ»Ø¸øËüµÄЧ¹û¡£¡£¡£¡£¡£¡£¡£¡£Magnet Goblin ʹÓÃµÄÆäËûһЩ¹¤¾ß°üÀ¨WARPWIRE JavaScript ƾ֤ÇÔÈ¡³ÌÐò¡¢»ùÓÚ Go µÄËíµÀÈí¼þ Ligolo£¬£¬£¬£¬£¬£¬ÒÔ¼°Õýµ±µÄÔ¶³Ì×ÀÃæ²úÆ·£¨ÀýÈç AnyDesk ºÍ ScreenConnect£©¡£¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2024/03/magnet-goblin-hacker-group-leveraging-1.html
2. Õë¶ÔÃÀ¹úºÍÅ·ÖÞÆóÒµµÄРDoNex ÀÕË÷Èí¼þ
3ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬ÃÀ¹úºÍÅ·ÖÞ¸÷µØµÄÆóÒµ¶¼´¦Óڸ߶Ⱦ¯±¸×´Ì¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÒ»ÖÖ±»³ÆÎª¡°DoNex¡±µÄÐÂÐÍÀÕË÷Èí¼þÒ»Ö±ÔÚÆð¾¢Î£º¦ÆóÒµ²¢Éù³ÆÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£¡£¹ØÓÚÕâÖÖÍ»·¢Íþв£¬£¬£¬£¬£¬£¬ÍøÂçÇ徲ר¼Ò¼Ó°à¼ÓµãµØÏàʶ¹¥»÷µÄËùÓйæÄ£²¢Öƶ©¶Ô²ß¡£¡£¡£¡£¡£¡£¡£¡£DoNex ÀÕË÷Èí¼þ×é֯ͨ¹ýÔÚÆä°µÍøÃÅ»§£¨¿Éͨ¹ý Onion ÍøÂç»á¼û£©ÉϽ«¶à¼Ò¹«Ë¾ÁÐΪÊܺ¦Õß¶øÖøÃû¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïµÄÊÖ¶ÎÓÈΪÒõÏÕ£¬£¬£¬£¬£¬£¬½ÓÄÉË«ÖØÀÕË÷ÊֶΡ£¡£¡£¡£¡£¡£¡£¡£Õâ²»µ«Éæ¼°Îļþ¼ÓÃÜ£¬£¬£¬£¬£¬£¬È»ºó¸½¼ÓÒ»¸öΨһµÄ¡£¡£¡£¡£¡£¡£¡£¡£VictimID À©Õ¹£¬£¬£¬£¬£¬£¬²¢ÇÒ»¹»áй¶Ãô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬½«Æä×÷ΪÈËÖÊ£¬£¬£¬£¬£¬£¬ÒÔÏòÊܺ¦ÕßÊ©¼ÓÌØÊâѹÁ¦£¬£¬£¬£¬£¬£¬ÒªÇóÆäÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¹«Ë¾ÔÚÆäϵͳÉÏ·¢Ã÷ÁËÃûΪ Readme.VictimID.txt µÄÀÕË÷×ÖÌõ£¬£¬£¬£¬£¬£¬¸Ã×ÖÌõָʾËûÃÇͨ¹ý Tox Messenger Óë DoNex ×éÖ¯½¨ÉèÁªÏµ£¬£¬£¬£¬£¬£¬Tox Messenger ÊÇÒ»ÖÖµã¶Ôµã¼´Ê±ÐÂÎÅЧÀÍ£¬£¬£¬£¬£¬£¬ÒÔÆäÇå¾²ºÍÄäÃû¹¦Ð§¶øÖøÃû¡£¡£¡£¡£¡£¡£¡£¡£
https://gbhackers.com/donex-ransomware-observed/
3. αװ³É Notion ×°ÖóÌÐòµÄ MSIX ¶ñÒâÈí¼þ
3ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬Î±×°³É Notion ×°ÖóÌÐòµÄ MSIX ¶ñÒâÈí¼þÕýÔÚ·Ö·¢¡£¡£¡£¡£¡£¡£¡£¡£·Ö·¢ÍøÕ¾¿´ÆðÀ´ÓëÏÖʵµÄ Notion Ö÷Ò³ÏàËÆ¡£¡£¡£¡£¡£¡£¡£¡£×°Öú󣬣¬£¬£¬£¬£¬StartingScriptWrapper.ps1 ºÍrefresh.ps1 Îļþ½«ÔÚÓ¦ÓóÌÐòµÄ·¾¶ÄÚ½¨Éè¡£¡£¡£¡£¡£¡£¡£¡£StartingScriptWrapper.ps1 ÎļþÊÇÒ»¸öÕýµ±Îļþ£¬£¬£¬£¬£¬£¬°üÀ¨ MS ÊðÃû£¬£¬£¬£¬£¬£¬¾ßÓÐÖ´ÐÐ×÷Ϊ²ÎÊý¸ø³öµÄ Powershell ¾ç±¾µÄ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎļþÔÊÐíÔÚ×°ÖÃÀú³ÌºÍÖ´ÐÐÌØ¶¨ Powershell ¾ç±¾Ê±´ú¶ÁÈ¡°üÄÚµÄ config.json ÉèÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£¡£´ËÏÂÁî´Ó C2 ЧÀÍÆ÷ÏÂÔØ¸½¼Ó Powershell ÏÂÁî²¢Ö´ÐÐËüÃÇ¡£¡£¡£¡£¡£¡£¡£¡£C2ЧÀÍÆ÷ÏÖÔÚûÓÐ׼ȷÏìÓ¦£¬£¬£¬£¬£¬£¬µ«ÆÊÎöÍŶÓÔÚÆðÔ´ÆÊÎöʱ´úÈ·ÈÏÁËLummaC2¶ñÒâÈí¼þµÄÂþÑÜ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÔËÐÐÎļþ֮ǰ£¬£¬£¬£¬£¬£¬Óû§Ó¦¸Ã¼ì²éÎļþÊÇ·ñÀ´×Ô¹Ù·½ÍøÕ¾µÄÓò£¬£¬£¬£¬£¬£¬×ÝÈ»ÎļþÊÇʹÓÃÕýµ±Ö¤ÊéÊðÃûµÄ£¬£¬£¬£¬£¬£¬Ò²Òª¼ì²éÊðÃû×÷Õß¡£¡£¡£¡£¡£¡£¡£¡£½¨ÒéÔÚÖ´ÐÐ MSIX Îļþʱ¸ñÍâСÐÄ£¬£¬£¬£¬£¬£¬ÓÉÓÚ¶àÖÖ¶ñÒâ±äÌå²»µ«»áαװ Notion£¬£¬£¬£¬£¬£¬»¹»áαװ Slack¡¢WinRar ºÍ Bandicam µÈÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¡£¡£¡£
https://asec.ahnlab.com/en/62815/
4. ÈÕ±¾½« PyPI ¹©Ó¦Á´ÍøÂç¹¥»÷¹é×ïÓÚ³¯ÏÊ
3ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬ÈÕ±¾ÍøÂçÇå¾²¹ÙÔ±ÖÒÑԳƣ¬£¬£¬£¬£¬£¬³¯ÏÊÎÛÃûÕÑÖøµÄ Lazarus Group ºÚ¿ÍÍŶÓ×î½üÕë¶Ô Python Ó¦ÓóÌÐòµÄ PyPI Èí¼þ´æ´¢¿â·¢¶¯Á˹©Ó¦Á´¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Íþв¼ÓÈëÕßÉÏ´«ÁËÃûΪ¡°pycryptoenv¡±ºÍ¡°pycryptoconf¡±µÈÊÜÎÛȾµÄ°ü£¬£¬£¬£¬£¬£¬ÆäÃû³ÆÓëÕýµ±µÄ Python ¼ÓÃܹ¤¾ß°ü¡°pycrypto¡±ÀàËÆ¡£¡£¡£¡£¡£¡£¡£¡£±»ÓÕÆ½«¶ñÒâÈí¼þ°üÏÂÔØµ½ Windows ÅÌËã»úÉϵĿª·¢Ö°Ô±»áѬȾһÖÖÃûΪ Comebacker µÄΣÏÕÌØÂåÒÁľÂí¡£¡£¡£¡£¡£¡£¡£¡£Gartner ¸ß¼¶×Ü¼à¼æÆÊÎöʦ Dale Gardner ½« Comebacker ÐÎòΪһÖÖͨÓÃľÂí£¬£¬£¬£¬£¬£¬ÓÃÓÚͶ·ÅÀÕË÷Èí¼þ¡¢ÇÔȡƾ֤ºÍÉøÍ¸¿ª·¢Á÷³Ì¡£¡£¡£¡£¡£¡£¡£¡£Comebacker Òѱ»°²ÅÅÔÚÓ볯ÏÊÓÐ¹ØµÄÆäËûÍøÂç¹¥»÷ÖУ¬£¬£¬£¬£¬£¬°üÀ¨¶Ô npm Èí¼þ¿ª·¢´æ´¢¿âµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
https://www.darkreading.com/application-security/japan-blames-north-korea-for-pypi-supply-chain-cyberattack
5. ºÚ¿ÍʹÓà WordPress ²å¼þȱÏÝÓöñÒâÈí¼þѬȾ 3300 ¸öÍøÕ¾
3ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓà Popup Builder ²å¼þ¹ýʱ°æ±¾ÖеÄÎó²îÈëÇÖ WordPress ÍøÕ¾£¬£¬£¬£¬£¬£¬ÓöñÒâ´úÂëѬȾ 3,300 ¶à¸öÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÖÐʹÓõÄȱÏݱ»×·×ÙΪ CVE-2023-6000£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öÓ°Ïì Popup Builder °æ±¾ 4.2.3 ¼°¸üÔç°æ±¾µÄ¿çÕ¾µã¾ç±¾ (XSS) Îó²î£¬£¬£¬£¬£¬£¬×î³õÓÚ 2023 Äê 11 ÔÂÅû¶¡£¡£¡£¡£¡£¡£¡£¡£½ñÄêÄêÍ··¢Ã÷µÄ Balada Injector »î¶¯Ê¹ÓøÃÌØ¶¨Îó²îѬȾÁË 6,700 ¶à¸öÍøÕ¾£¬£¬£¬£¬£¬£¬ÕâÅú×¢Ðí¶àÍøÕ¾ÖÎÀíԱûÓÐ×ã¹»¿ìµØÐÞ²¹²¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£Sucuri ÏÖÔÚ ±¨¸æ ·¢Ã÷Ò»¸öеĻÔÚÒÑÍùÈýÖÜÄÚÏÔ×ÅÔöÌí£¬£¬£¬£¬£¬£¬Õë¶ÔµÄÊÇ WordPress ²å¼þÉϵÄÏàͬÎó²î¡£¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤ PublicWWW µÄЧ¹û£¬£¬£¬£¬£¬£¬ÔÚ3,329 ¸ö WordPress ÍøÕ¾Öз¢Ã÷ÁËÓëÕâÒ»×îлÏà¹ØµÄ´úÂë×¢Èë £¬£¬£¬£¬£¬£¬Sucuri ×Ô¼ºµÄɨÃèÒǼì²âµ½ÁË 1,170 ¸öѬȾ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-wordpress-plugin-flaw-to-infect-3-300-sites-with-malware/
6. ÔóÎ÷µº½ðÈÚЧÀÍίԱ»áµÄÊý¾Ýй¶
3ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬ÔóÎ÷µº½ðÈÚЧÀÍίԱ»áµÄÊý¾Ýй¶µ¼Ö·ǹûÕæÐÕÃûºÍµØµãµÄ»á¼û¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÓÚ 1 Ô 23 ÈÕÈ·ÈÏÆä×¢²áϵͳÖмì²âµ½Ò»¸ö¡°Îó²î¡±¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬´Ë´ÎйÃÜÊÂÎñ²¢Î´½«ÈκÎСÎÒ˽¼ÒÓë×¢²áʵÌå»òËùµ£µ±µÄ½ÇÉ«ÁªÏµÆðÀ´£¬£¬£¬£¬£¬£¬²¢ÇÒÒѵ¥¶ÀдПøÄÇЩÐÕÃûºÍµØµã±»Ð¹Â¶µÄÈË¡£¡£¡£¡£¡£¡£¡£¡£ÆðÔ´·¨Ò½Éó²é·¢Ã÷×ß©ÊÇÓÉÓÚµÚÈý·½ÌṩµÄ×¢²áϵͳÉèÖùýʧÔì³ÉµÄ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÌåÏÖ£º¡°ÎÒÃǶԱ¬·¢ÕâÖÖÇéÐÎÉî¸ÐÒź¶£¬£¬£¬£¬£¬£¬ÏÖÔÚÕýÔÚ½øÒ»³ÌÐò²éÒÔÈ·¶¨ÕâÊÇÔõÑù±¬·¢µÄ¡£¡£¡£¡£¡£¡£¡£¡£¡±JFSC ÌåÏÖÕýÔÚÓëÔóÎ÷µºÐÅϢרԱ°ì¹«ÊÒÏàÖú¡£¡£¡£¡£¡£¡£¡£¡£ÈÏÕæ½ðÈÚЧÀ͵ĸ±²¿³¤ÒÁ¶÷¡¤¸êË¹ÌØÌåÏÖ£¬£¬£¬£¬£¬£¬´Ë´Îй¶ӰÏìÁËϵͳÖС°ÓÐÏÞÊýÄ¿µÄÌõÄ¿¡±¡£¡£¡£¡£¡£¡£¡£¡£ËûÔö²¹µÀ£º¡°ÎÒ¶Ô±¬·¢ÕâÒ»¹ýʧ¸ÐÓ¦Ç¸ØÆ£¬£¬£¬£¬£¬£¬ÎÒÏàʶÁªºÏ½ðÈÚЧÀÍίԱ»áÕýÔÚ¾ÙÐÐ×î³¹µ×µÄÊӲ죬£¬£¬£¬£¬£¬ÒÔÈ·±£ÂÞÖ½Ìѵ£¬£¬£¬£¬£¬£¬²¢Ë¢ÐºÍÔöÇ¿¹ÒºÅ²áµÄÉè¼Æ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bbc.com/news/articles/cnk5zyypw24o?&web_view=true


¾©¹«Íø°²±¸11010802024551ºÅ