NoName057(16)£º¶íÂÞ˹ DDoS ×ÌÈÅÕßÃé×¼Î÷·½
Ðû²¼Ê±¼ä 2024-03-053ÔÂ3ÈÕ£¬ÎÚ¿ËÀ¼Õ½ÕùÒý·¢ÁËÐÂÐÍÍøÂç³åÍ»£¬ºÚ¿Í»î¶¯ÍÅÌå³äµ±Á˹ú¼ÒÀûÒæµÄÊðÀíÈË¡£¶íÂÞ˹µÄ NoName057(16) ÒѳÉΪ DDoSia ÏîÄ¿
µÄ´úÃû´Ê£¬ÕâÊÇÒ»ÏîÕë¶ÔÖ§³ÖÎÚ¿ËÀ¼µÄ¹ú¼ÒµÄÁ¬Ðø DDoS ¹¥»÷»î¶¯¡£ÓëרעÓÚÊý¾Ý͵ÇÔ»ò¼äµý»î¶¯µÄ×éÖ¯²îÒ죬NoName057(16) Ñ°Çóѹµ¹ºÍÆÆ»µ£¬½«Êý×ÖÊÀ½çÄð³ÉµØÔµÕþÖÎÕ½ÕùµÄ¹¤¾ß¡£×ÔSEKOIA.IOµ±ÎÒÃÇ¿ªÊ¼×·×ÙËûÃÇʱ£¬ËûÃǵÄÒªÁìÒѾ·¢ÉúÁËÑݱ䣬½ÒʾÁËËæ×ųåÍ»³±Ë®µÄ±ä»¯ÒÔ¼°ÓëÎ÷·½¸ü¹ã·ºµÄ½ôÕžÖÊƶø·¢ÉúµÄÁ¬ÐøÇÒÊÊÓ¦ÐÔÇ¿µÄÍþв¡£2023 Äê 11 Ô 11 ÈÕ£¬DDoSia ÖØ´ó¸üУ¬À©Õ¹Á˶Ըü¹ã·ºÉ豸ºÍ²Ù×÷ϵͳµÄ¼æÈÝÐÔ¡£ÖµµÃ×¢ÒâµÄÊÇ£¬¹ÜÀíԱƾ¾ÝµØÀíλÖö¨ÖÆÁË°æ±¾£¬¾¯¸æ¶íÂÞ˹Óû§ÔÚ¼ÓÈë¹¥»÷ʱʹÓà VPN À´ÑÚ¸Ç×Ô¼ºµÄλÖá£Õâ¸öа汾ÒýÈëÁ˸üÅÓ´óµÄÊý¾Ý¼ÓÃÜ£¬¿ÉÒÔ¸ü¾«Ï¸µØ¸ú×Ù DDoSia Óû§¡£ÕâЩÊý¾Ý¿ÉÄÜÓÐÖúÓÚ¹ÜÀíÔ±ÆÀ¹ÀÏîÄ¿µÄÓÐЧÐÔ£¬¶øÇÒ¿ÉÄܳÉΪִ·¨ºÍÍþвÇ鱨ÊÂÇéµÄÃû¹ó×ÊÔ´¡£
https://securityonline.info/noname05716-russias-ddos-disruptors-target-the-west/
2. Predator ¼äµýÈí¼þÂûÑÓ£º11 ¸ö¹ú¼ÒÄ¿Ç°ÃæÁÙ·çÏÕ
3ÔÂ3ÈÕ£¬ Predator Òƶ¯¼äµýÈí¼þ±³ºóµÄ²Ù×÷ÕßÈÔȻûÓб»¹«ÖÚÆعâºÍÉó²éÏŵ¹¡£Recorded Future µÄ Insikt ¼¯ÍÅÑо¿ÈËÔ±½Ò¶Á˼äµýÈí¼þÖؽ¨µÄ»ù´¡ÉèÊ©£¬±íÃ÷ Predator ¿ÉÄÜÔÚÖÁÉÙ 11 ¸ö¹ú¼Ò»ý¼«Ê¹Óá£ÁîÈ˵£ÓǵÄÊÇ£¬Õâ°üÂÞ²©´ÄÍßÄɺͷÆÂɱö£¬ÕâЩµØÓòµÄ Predator ¿Í»§´ËÇ°²¢²»ÎªÈËËùÖª¡£ÓÉ Cytrox ¿ª·¢²¢ÓÉ Intellexa ÁªÃ˹ÜÀíµÄ Predator ×Ô 2019 ÄêÒÔÀ´Ò»Ö±ÔÚ¹ÍÓ¶¼äµýÈí¼þÁìÓòÖÐո¶ͷ½Ç¡£¸Ã¹¤¾ßÒѽøÈëÖÁÉÙ 11 ¸ö¹ú¼Ò£¬°üÂÞ°²¸çÀ¡¢ÑÇÃÀÄáÑÇ¡¢²©´ÄÍßÄÉ¡¢°£¼°¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢¹þÈø¿Ë˹̹¡¢Ãɹš¢°¢Âü¡¢·ÆÂɱö¡¢É³ÌØ°¢À²®¡¢ÌØÁ¢Äá´ïºÍ¶à°Í¸ç¡£×¨Îª Android ºÍ iOS É豸Éè¼Æ£¬ÆäÒþÃØÉø͸¹¦Ð§Ê¹ÆäÄܹ»ÔÚÓû§²»ÖªÇéµÄÇé¿öÏ·ÃÎÊÉ豸µÄÂó¿Ë·ç¡¢ÉãÏñÍ·ºÍÃô¸ÐÊý¾Ý¡£ÕâÖֶ๦ЧÐÔ£¬¼ÓÉÏÆäÄÑÒÔ×½ÃþµÄÐÔÖÊ£¬Ê¹ Predator ³ÉΪ¶ñÒâÐÐΪÕßÊÖÖеÄÇ¿´ó¹¤¾ß¡£
https://securityonline.info/predator-spyware-spreads-11-countries-now-at-risk/
3. WhatsApp ÆÈʹ Pegasus ¼äµýÈí¼þ·ÖÏíÆäÃØÃÜ´úÂë
3ÔÂ4ÈÕ£¬¾Ý¡¶ÎÀ±¨¡·±¨µÀ£¬WhatsApp ºÜ¿ì½«»ñµÃ̽Ë÷ NSO ¼¯ÍÅ Pegasus ¼äµýÈí¼þ¡°È«²¿¹¦Ð§¡±µÄȨÏÞ£¬¸ÃÈí¼þÊÇÒÔÉ«Áйú·À²¿ºã¾ÃÒÔÀ´Ò»Ö±½«ÆäÊÓΪ¡°¸ß¶È»úÃÜ¡±µÄ¹ú¼Ò»úÃÜ¡£×Ô 2019 ÄêÒÔÀ´£¬WhatsApp Éù³Æ Pegasus ±»ÓÃÀ´ÔÚÁ½ÖÜÄÚ¼àÊÓ 1,400 Ãû WhatsApp Óû§£¬Î´¾ÊÚȨ·ÃÎÊËûÃǵÄÃô¸ÐÊý¾Ý£¬°üÂÞ¼ÓÃÜÏûÏ¢£¬½ñºó£¬WhatsApp Ò»Ö±ÒªÇó·ÃÎÊ NSO µÄ¼äµýÈí¼þ´úÂë¡£Ars Æäʱָ³ö£¬WhatsApp ÆðËß NSO ÊÇ¡°Ç°ËùδÓеÄÖ´·¨Ðж¯¡±£¬¡°Õë¶ÔµÄÊÇÏòÊÀ½ç¸÷¹úÕþ¸®³öÊÛÅÓ´ó¶ñÒâÈí¼þ·þÎñµÄ²»Êܼà¹ÜµÄÐÐÒµ¡±¡£
https://news.hitb.org/content/whatsapp-finally-forces-pegasus-spyware-maker-share-its-secret-code
4. Õë¶ÔÓëÓ¡¶ÈÍâ½»»î¶¯ÓйصÄÅ·ÖÞ¹ÙÔ±µÄкóÃÅWINELOADER
2ÔÂ29ÈÕ£¬¾ÝÊӲ죬һ¸öÃûΪSPIKEDWINEµÄÏÈÇ°ÎÞÖ¤ÍþвÐÐΪÕßʹÓÃÃûΪWINELOADERµÄкóÃÅÕë¶ÔפÓÐÓ¡¶ÈÍ⽻ʹÍŵÄÅ·ÖÞ¹ú¼ÒµÄ¹ÙÔ±¡£Æ¾¾ÝZscaler ThreatLabz µÄ³ÂËߣ¬¶ÔÊÖÔÚµç×ÓÓʼþÖÐʹÓÃÁËÒ»¸ö¿´ËÆÀ´×ÔÓ¡¶È´óʹµÄ PDF Îļþ£¬ÑûÇëÍâ½»ÈËÔ±¼ÓÈë 2024 Äê 2 Ô 2 ÈÕµÄÆ·¾Æ»î¶¯¡£¸ÃPDF ÎĵµÓÚ 2024 Äê 1 Ô 30 ÈÕ´ÓÀÍÑάÑÇÉÏ´«µ½ VirusTotal¡£Ò²¾ÍÊÇ˵£¬ÓÐÖ¤¾Ý±íÃ÷£¬¸Ã»î¶¯¿ÉÄÜÖÁÉÙ´Ó 2023 Äê 7 Ô 6 ÈÕÆð¾Í¿ªÊ¼»îÔ¾£¬ÒòΪ·¢ÏÖÁË´Óͬһ¸ö¹ú¼Ò¡£Äþ¾²Ñо¿ÈËÔ±ËÕµÏÆÕ¡¤ÐÁ¸ñ (Sudeep Singh) ºÍÂÞÒÁ¡¤Ì© (Roy Tay) ÌåÏÖ£º¡°´Ë´Î¹¥»÷µÄÌصãÊǹ¥»÷Á¿·Ç³£Ð¡£¬¶øÇÒÔÚ¶ñÒâÈí¼þºÍÃüÁîÓë¿ØÖÆ (C2) »ù´¡ÉèÊ©ÖнÓÄÉÁËÏȽøµÄ¼Æı¡¢¼¼ÊõºÍ·¨Ê½ (TTP)¡£¡±Õâ´ÎÐÂÐ͹¥»÷µÄºËÐÄÊÇ PDF Îļþ£¬¸ÃÎļþǶÈëÁËÒ»¸öαװ³Éµ÷ÅÌÎʾíµÄ¶ñÒâÁ´½Ó£¬¶Ø´ÙÊÕ¼þÈËÌîд¸ÃÁ´½Ó²ÅÆø¼ÓÈë¡£µ¥»÷¸ÃÁ´½Ó½«Îª°üÂÞ»ìÏýµÄ JavaScript ´úÂëµÄ HTML Ó¦Ó÷¨Ê½£¨¡°wine.hta¡±£©ÆÌƽÃÅ·£¬ÒÔ´ÓͬһÓò¼ìË÷°üÂÞ WINELOADER µÄ±àÂë ZIP ´æµµ¡£
https://thehackernews.com/2024/02/new-backdoor-targeting-european.html
5. Êý°ÙÍò¸ö GitHub ´æ´¢¿â±»·¢ÏÖѬȾ¶ñÒâ´úÂë
2ÔÂ29ÈÕ£¬Äþ¾²Ñо¿ÈËÔ±ÔÚ GitHub ÉÏ·¢ÏÖÁË´ó¹æÄ£µÄ´æ´¢¿â»ìÏý¹¥»÷»î¶¯£¬Ó°ÏìÁËÁè¼Ý 100,000 ¸ö´æ´¢¿â£¬ÉõÖÁ¿ÉÄÜ»¹ÓÐÊý°ÙÍòÈË¡£ÕâÖÖÅÓ´óµÄÍøÂç¹¥»÷ͨ¹ýÓÕÆ¿ª·¢ÈËÔ±ÏÂÔغÍʹÓÃαװ³ÉºÏ·¨´æ´¢¿âµÄ¶ñÒâ´æ´¢¿âÀ´Õë¶Ô¿ª·¢ÈËÔ±¡£Apiiro ¿ª·¢ÁËÒ»ÖÖ¶ñÒâ´úÂë¼ì²âϵͳ£¬¸Ãϵͳ¿É¼à¿Ø´úÂë¿â²¢Ê¹ÓÃÉî¶È´úÂë·ÖÎöºÍ·´»ìÏýµÈÏȽø¼¼ÊõÀ´Ê¶±ðºÍ·ÀÖ¹´ËÀ๥»÷¡£Äú¿ÉÒÔʹÓÃANY.RUN ¶ñÒâÈí¼þɳÏäºÍÍþвÇ鱨²éÕÒÀ´·ÖÎö¶ñÒâÈí¼þÎļþ¡¢ÍøÂ硢ģ¿éºÍ×¢²á±í»î¶¯£¬´Ó¶øʹÄú¿ÉÒÔÖ±½Ó´Óä¯ÀÀÆ÷Óë²Ù×÷ϵͳ½øÐн»»¥¡£ÕâЩ´æ´¢¿â»á×Ô¶¯·Ö²æÊýǧ´Î£¬²¢ÔÚÖÖÖÖÔÚÏßƽ̨ÉϽøÐÐÍƹ㣬ÒÔÌá¸ßÆä¿É¼ûÐԺͱ»¿ª·¢ÈËÔ±´íÎóʹÓõĿÉÄÜÐÔ¡£
https://gbhackers.com/millions-of-github-repos-found-infected/
6. ÒþÐÎ GTPDOOR Linux ¶ñÒâÈí¼þÕë¶ÔÒƶ¯ÔËÓªÉÌÍøÂç
3ÔÂ3ÈÕ£¬Äþ¾²Ñо¿ÈËÔ± HaxRob ·¢ÏÖÁËÒ»¸öÒÔǰδ֪µÄ Linux ºóÃÅ£¬ÃûΪ GTPDOOR£¬×¨ÎªÒƶ¯ÔËÓªÉÌÍøÂçÄÚµÄÃØÃܲÙ×÷¶øÉè¼Æ¡£GTPDOOR ±³ºóµÄÍþвÐÐΪÕß±»ÈÏΪÒÔ GPRS ÂþÓν»»» (GRX) ËÄÖܵÄϵͳΪĿ±ê£¬ÀýÈç SGSN¡¢GGSN ºÍ P-GW£¬ÕâЩϵͳ¿ÉÒÔΪ¹¥»÷ÕßÌṩ¶ÔµçÐźËÐÄÍøÂçµÄÖ±½Ó·ÃÎÊ¡£GRX ÊÇÒƶ¯µçÐŵÄÒ»¸ö×é¼þ£¬¿É´Ù½ø¿ç²îÒìµØÀíÇøÓòºÍÍøÂçµÄÊý¾ÝÂþÓηþÎñ¡£·þÎñ GPRS Ö§³Ö½Úµã (SGSN)¡¢Íø¹Ø GPRS Ö§³Ö½Úµã (GGSN) ºÍ P-GW£¨·Ö×éÊý¾ÝÍøÂçÍø¹Ø£¨ÓÃÓÚ 4G LTE£©£©ÊÇÒƶ¯ÔËÓªÉÌÍøÂç»ù´¡ÉèÊ©ÄÚµÄ×é¼þ£¬Ã¿¸ö×é¼þÔÚÒƶ¯Í¨ÐÅÖз¢»Ó²îÒìµÄ×÷Óá£ÓÉÓÚSGSN¡¢GGSNºÍP-GWÍøÂç¸ü¶àµØ̻¶ÔÚ¹«ÖÚÃæÇ°£¬IPµØÖ··¶Î§ÁÐÔÚ¹ûÈ»ÎļþÖУ¬Ñо¿ÈËÔ±ÈÏΪËüÃÇ¿ÉÄÜÊÇ»ñµÃÒƶ¯ÔËÓªÉÌÍøÂç³õʼ·ÃÎÊȨÏÞµÄÄ¿±ê¡£GTPDOOR ÊÇÒ»ÖÖרΪµçÐÅÍøÂçÁ¿Éí¶¨ÖƵÄÅÓ´óºóÃŶñÒâÈí¼þ£¬ÀûÓà GPRS ËíµÀÐÒé¿ØÖÆƽÃæ (GTP-C) ½øÐÐÒþ±ÎÃüÁîºÍ¿ØÖÆ (C2) ͨÐÅ¡£ËüÉè¼ÆÓÃÓÚ²¿ÊðÔÚÓë GRX ÏàÁڵĻùÓÚ Linux µÄϵͳÖУ¬ÂôÁ¦Â·ÓɺÍת·¢ÂþÓÎÏà¹ØµÄÐÅÁîºÍÓû§Æ½ÃæÁ÷Á¿¡£Ê¹Óà GTP-C ½øÐÐͨÐÅÔÊÐí GTPDOOR ÓëºÏ·¨ÍøÂçÁ÷Á¿»ìºÏ£¬²¢ÀûÓò»Êܳ߶ÈÄþ¾²½â¾ö·½°¸¼à¿ØµÄÒÑÔÊÐí¶Ë¿Ú¡£ÎªÁËÌá¸ßÒþ±ÎÐÔ£¬GTPDOOR ¿ÉÒÔ¸ü¸ÄÆä½ø³ÌÃû³ÆÒÔÄ£·ÂºÏ·¨µÄϵͳ½ø³Ì¡£
https://www.bleepingcomputer.com/news/security/stealthy-gtpdoor-linux-malware-targets-mobile-operator-networks/