Magnet Goblin ºÚ¿Í×éÖ¯ÀûÓ鶴²¿Êð Nerbian RAT

Ðû²¼Ê±¼ä 2024-03-12
1. Magnet Goblin ºÚ¿Í×éÖ¯ÀûÓ鶴²¿Êð Nerbian RAT


3ÔÂ11ÈÕ£¬Ò»¸öÃûΪMagnet GoblinµÄ³öÓÚ¾­¼Ã¶¯»úµÄÍþвÐÐΪÕßÕýÔÚѸËÙ½«1dayÄþ¾²Â©¶´ÄÉÈëÆäÎäÆ÷¿â£¬ÒÔ±ãËÅ»úÆÆ»µ±ßÔµÉ豸ºÍÃæÏò¹«ÖڵķþÎñ£¬²¢ÔÚÊÜѬȾµÄÖ÷»úÉϲ¿Êð¶ñÒâÈí¼þ¡£¶ÔÊÖÌᳫµÄ¹¥»÷ÀûÓÃδÐÞ²¹µÄ Ivanti Connect Secure VPN¡¢Magento¡¢Qlik Sense ÒÔ¼°¿ÉÄÜµÄ Apache ActiveMQ ·þÎñÆ÷×÷Ϊ³õʼѬȾý½éÀ´»ñµÃδ¾­ÊÚȨµÄ·ÃÎÊ¡£¾Ý³Æ¸Ã×éÖ¯ÖÁÉÙ×Ô 2022 Äê 1 ÔÂÆð¾ÍÒ»Ö±»îÔ¾¡£ÀÖ³ÉÀûÓôË©¶´ºó£¬»á²¿ÊðÒ»¸öÃûΪ Nerbian RAT µÄ¿çƽ̨Զ³Ì·ÃÎÊľÂí (RAT)£¬¸ÃľÂíÓÉ Proofpoint ÓÚ 2022 Äê 5 ÔÂÊ×´ÎÅû¶£¬Æä¼ò»¯±äÖÖΪ MiniNerbian¡£Darktrace֮ǰÔøÇ¿µ÷¹ý Linux °æ±¾ Nerbian RAT µÄʹÓá£ÕâÁ½ÖÖ²¡¶¾¶¼ÔÊÐíÖ´ÐдÓÃüÁîÓë¿ØÖÆ (C2) ·þÎñÆ÷½ÓÊÕµÄÈÎÒâÃüÁ²¢Ð¹Â¶·µ»Ø¸øËüµÄ½á¹û¡£Magnet Goblin ʹÓõÄÆäËûһЩ¹¤¾ß°üÂÞWARPWIRE JavaScript ƾ֤ÇÔÈ¡·¨Ê½¡¢»ùÓÚ Go µÄËíµÀÈí¼þ Ligolo£¬ÒÔ¼°ºÏ·¨µÄÔ¶³Ì×ÀÃæ²úÎÀýÈç AnyDesk ºÍ ScreenConnect£©¡£ 


https://thehackernews.com/2024/03/magnet-goblin-hacker-group-leveraging-1.html


2. Õë¶ÔÃÀ¹úºÍÅ·ÖÞÆóÒµµÄРDoNex ÀÕË÷Èí¼þ


3ÔÂ11ÈÕ£¬ÃÀ¹úºÍÅ·ÖÞ¸÷µØµÄÆóÒµ¶¼´¦Óڸ߶Ƚ䱸״̬£¬ÒòΪһÖÖ±»³ÆΪ¡°DoNex¡±µÄÐÂÐÍÀÕË÷Èí¼þÒ»Ö±ÔÚ»ý¼«Î£º¦ÆóÒµ²¢Éù³ÆÊܺ¦Õß¡£¶ÔÓÚÕâÖÖÍ»·¢Íþв£¬ÍøÂçÄþ¾²×¨¼Ò¼Ó°à¼ÓµãµØÁ˽⹥»÷µÄÈ«²¿·¶Î§²¢Öƶ¨¶Ô²ß¡£DoNex ÀÕË÷Èí¼þ×é֯ͨ¹ýÔÚÆä°µÍøÃÅ»§£¨¿Éͨ¹ý Onion ÍøÂç·ÃÎÊ£©ÉϽ«¶à¼Ò¹«Ë¾ÁÐΪÊܺ¦Õ߶øÎÅÃû¡£¸ÃÍÅ»ïµÄÊÖ¶ÎÓÈΪÒõÏÕ£¬½ÓÄÉË«ÖØÀÕË÷ÊֶΡ£Õâ²»½öÉæ¼°Îļþ¼ÓÃÜ£¬È»ºó¸½¼ÓÒ»¸öΨһµÄ¡£VictimID À©Õ¹£¬¶øÇÒ»¹»áй¶Ãô¸ÐÊý¾Ý£¬½«Æä×÷ΪÈËÖÊ£¬ÒÔÏòÊܺ¦ÕßÊ©¼ÓÌرðѹÁ¦£¬ÒªÇóÆäÖ§¸¶Êê½ð¡£ÊÜÓ°ÏìµÄ¹«Ë¾ÔÚÆäϵͳÉÏ·¢ÏÖÁËÃûΪ Readme.VictimID.txt µÄÀÕË÷×ÖÌõ£¬¸Ã×ÖÌõָʾËûÃÇͨ¹ý Tox Messenger Óë DoNex ×éÖ¯½¨Á¢ÁªÏµ£¬Tox Messenger ÊÇÒ»ÖÖµã¶Ôµã¼´Ê±ÏûÏ¢·þÎñ£¬ÒÔÆäÄþ¾²ºÍÄäÃû¹¦Ð§¶øÎÅÃû¡£


https://gbhackers.com/donex-ransomware-observed/


3. αװ³É Notion °²×°·¨Ê½µÄ MSIX ¶ñÒâÈí¼þ


3ÔÂ11ÈÕ£¬Î±×°³É Notion °²×°·¨Ê½µÄ MSIX ¶ñÒâÈí¼þÕýÔÚ·Ö·¢¡£·Ö·¢ÍøÕ¾¿´ÆðÀ´Óëʵ¼ÊµÄ Notion Ö÷Ò³ÏàËÆ¡£°²×°ºó£¬StartingScriptWrapper.ps1 ºÍrefresh.ps1 Îļþ½«ÔÚÓ¦Ó÷¨Ê½µÄ·¾¶ÄÚ´´½¨¡£StartingScriptWrapper.ps1 ÎļþÊÇÒ»¸öºÏ·¨Îļþ£¬°üÂÞ MS Ç©Ãû£¬¾ßÓÐÖ´ÐÐ×÷Ϊ²ÎÊý¸ø³öµÄ Powershell ½Å±¾µÄ¹¦Ð§¡£¸ÃÎļþÔÊÐíÔÚ°²×°¹ý³ÌºÍÖ´ÐÐÌض¨ Powershell ½Å±¾ÆÚ¼ä¶ÁÈ¡°üÄÚµÄ config.json ÅäÖÃÎļþ¡£´ËÃüÁî´Ó C2 ·þÎñÆ÷ÏÂÔظ½¼Ó Powershell ÃüÁî²¢Ö´ÐÐËüÃÇ¡£C2·þÎñÆ÷ĿǰûÓÐÕýÈ·ÏìÓ¦£¬µ«·ÖÎöÍŶÓÔÚ¿ª¶Ë·ÖÎöÆÚ¼äÈ·ÈÏÁËLummaC2¶ñÒâÈí¼þµÄÂþÑÜ¡£ÔÚÔËÐÐÎļþ֮ǰ£¬Óû§Ó¦¸Ã¼ì²éÎļþÊÇ·ñÀ´×Ô¹Ù·½ÍøÕ¾µÄÓò£¬¼´Ê¹ÎļþÊÇʹÓúϷ¨Ö¤ÊéÇ©ÃûµÄ£¬Ò²Òª¼ì²éÇ©Ãû×÷Õß¡£½¨ÒéÔÚÖ´ÐÐ MSIX Îļþʱ¸ñÍâСÐÄ£¬ÒòΪ¶àÖÖ¶ñÒâ±äÌå²»½ö»áαװ Notion£¬»¹»áαװ Slack¡¢WinRar ºÍ Bandicam µÈÓ¦Ó÷¨Ê½¡£


https://asec.ahnlab.com/en/62815/


4. ÈÕ±¾½« PyPI ¹©Ó¦Á´ÍøÂç¹¥»÷¹é¾ÌÓÚ³¯ÏÊ


3ÔÂ11ÈÕ£¬ÈÕ±¾ÍøÂçÄþ¾²¹ÙÔ±¾¯¸æ³Æ£¬³¯ÏÊÎÛÃûÕÑÖøµÄ Lazarus Group ºÚ¿ÍÍŶÓ×î½üÕë¶Ô Python Ó¦Ó÷¨Ê½µÄ PyPI Èí¼þ´æ´¢¿â·¢¶¯Á˹©Ó¦Á´¹¥»÷¡£Íþв¼ÓÈëÕßÉÏ´«ÁËÃûΪ¡°pycryptoenv¡±ºÍ¡°pycryptoconf¡±µÈÊÜÎÛȾµÄ°ü£¬ÆäÃû³ÆÓëºÏ·¨µÄ Python ¼ÓÃܹ¤¾ß°ü¡°pycrypto¡±ÀàËÆ¡£±»ÓÕÆ­½«¶ñÒâÈí¼þ°üÏÂÔص½ Windows ¼ÆËã»úÉϵĿª·¢ÈËÔ±»áѬȾһÖÖÃûΪ Comebacker µÄΣÏÕÌØÂåÒÁľÂí¡£Gartner ¸ß¼¶×ܼà¼æ·ÖÎöʦ Dale Gardner ½« Comebacker ÃèÊöΪһÖÖͨÓÃľÂí£¬ÓÃÓÚͶ·ÅÀÕË÷Èí¼þ¡¢ÇÔȡƾ֤ºÍÉø͸¿ª·¢Á÷³Ì¡£Comebacker Òѱ»²¿ÊðÔÚÓ볯ÏÊÓйصÄÆäËûÍøÂç¹¥»÷ÖУ¬°üÂÞ¶Ô npm Èí¼þ¿ª·¢´æ´¢¿âµÄ¹¥»÷¡£


https://www.darkreading.com/application-security/japan-blames-north-korea-for-pypi-supply-chain-cyberattack


5. ºÚ¿ÍÀûÓà WordPress ²å¼þȱÏÝÓöñÒâÈí¼þѬȾ 3300 ¸öÍøÕ¾


3ÔÂ10ÈÕ£¬ºÚ¿ÍÀûÓà Popup Builder ²å¼þ¹ýʱ°æ±¾ÖеÄ©¶´ÈëÇÖ WordPress ÍøÕ¾£¬ÓöñÒâ´úÂëѬȾ 3,300 ¶à¸öÍøÕ¾¡£¹¥»÷ÖÐÀûÓõÄȱÏݱ»×·×ÙΪ CVE-2023-6000£¬ÕâÊÇÒ»¸öÓ°Ïì Popup Builder °æ±¾ 4.2.3 ¼°¸üÔç°æ±¾µÄ¿çÕ¾µã½Å±¾ (XSS) ©¶´£¬×î³õÓÚ 2023 Äê 11 ÔÂÅû¶¡£½ñÄêÄê³õ·¢ÏÖµÄ Balada Injector »î¶¯ÀûÓøÃÌض¨Â©¶´Ñ¬È¾ÁË 6,700 ¶à¸öÍøÕ¾£¬Õâ±íÃ÷Ðí¶àÍøÕ¾¹ÜÀíԱûÓÐ×ã¹»¿ìµØÐÞ²¹²¹¶¡¡£Sucuri ÏÖÔÚ ³ÂËß ·¢ÏÖÒ»¸öеĻÔÚ¹ýÈ¥ÈýÖÜÄÚÏÔ×ÅÔö¼Ó£¬Õë¶ÔµÄÊÇ WordPress ²å¼þÉϵÄÏàͬ©¶´¡£Æ¾¾Ý PublicWWW µÄ½á¹û£¬ÔÚ3,329 ¸ö WordPress ÍøÕ¾Öз¢ÏÖÁËÓëÕâÒ»×îлÏà¹ØµÄ´úÂë×¢Èë £¬Sucuri ×Ô¼ºµÄɨÃèÒǼì²âµ½ÁË 1,170 ¸öѬȾ¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-wordpress-plugin-flaw-to-infect-3-300-sites-with-malware/


6. ÔóÎ÷µº½ðÈÚ·þÎñίԱ»áµÄÊý¾Ýй¶


3ÔÂ7ÈÕ£¬ÔóÎ÷µº½ðÈÚ·þÎñίԱ»áµÄÊý¾Ý鶵¼Ö·ǹûÈ»ÐÕÃûºÍµØÖ·µÄ·ÃÎÊ¡£¸Ã×éÖ¯ÓÚ 1 Ô 23 ÈÕÈ·ÈÏÆä×¢²áϵͳÖмì²âµ½Ò»¸ö¡°Â©¶´¡±¡£¸Ã¹«Ë¾ÌåÏÖ£¬´Ë´ÎйÃÜʼþ²¢Î´½«ÈκθöÈËÓë×¢²áʵÌå»òËùµ£ÈεĽÇÉ«ÁªÏµÆðÀ´£¬¶øÇÒÒѵ¥¶ÀдПøÄÇЩÐÕÃûºÍµØÖ·±»Ð¹Â¶µÄÈË¡£¿ª¶Ë·¨Ò½Éó²é·¢ÏÖй©ÊÇÓÉÓÚµÚÈý·½ÌṩµÄ×¢²áϵͳÅäÖôíÎóÔì³ÉµÄ¡£¸Ã×éÖ¯ÌåÏÖ£º¡°ÎÒÃǶԷ¢ÉúÕâÖÖÇé¿öÉî¸ÐÒź¶£¬Ä¿Ç°ÕýÔÚ½øÒ»·¨Ê½²éÒÔÈ·¶¨ÕâÊÇÈçºÎ·¢ÉúµÄ¡£¡±JFSC ÌåÏÖÕýÔÚÓëÔóÎ÷µºÐÅϢרԱ°ì¹«ÊÒºÏ×÷¡£ÂôÁ¦½ðÈÚ·þÎñµÄ¸±²¿³¤ÒÁ¶÷¡¤¸ê˹ÌØÌåÏÖ£¬´Ë´Îй¶ӰÏìÁËϵͳÖС°ÓÐÏÞÊýÁ¿µÄÌõÄ¿¡±¡£ËûÔö²¹µÀ£º¡°ÎÒ¶Ô·¢ÉúÕâÒ»´íÎó¸ÐӦǸØÆ£¬ÎÒÁ˽âÁªºÏ½ðÈÚ·þÎñίԱ»áÕýÔÚ½øÐÐ×î³¹µ×µÄÊӲ죬ÒÔÈ·±£¼³È¡½Ìѵ£¬²¢¸ïкͼÓÇ¿¹ÒºÅ²áµÄÉè¼Æ¡£


https://www.bbc.com/news/articles/cnk5zyypw24o?&web_view=true