StrelaStealer¹¥»÷Å·Ã˺ÍÃÀ¹úµÄ 100 ¶à¸ö×éÖ¯»òÆóÒµ

Ðû²¼Ê±¼ä 2024-03-25
1. StrelaStealer¹¥»÷Å·Ã˺ÍÃÀ¹úµÄ 100 ¶à¸ö×éÖ¯»òÆóÒµ


3ÔÂ24ÈÕ£¬ÔÚUnit 42×î½üµÄÒ»·Ý³ÂËßÖÐPalo Alto Networks µÄÑо¿ÈËÔ±·¢ÏÖÁËһϵÁÐеÄÍøÂçµöÓã¹¥»÷£¬Ö¼ÔÚÁ÷´«ÃûΪ StrelaStealer µÄ¶ñÒâÈí¼þ¡£ÕâÒ»ÍþвÒÑÓ°Ï쵽ŷÃ˺ÍÃÀ¹úµÄ 100 ¶à¸ö×éÖ¯¡£ÕâЩ¹¥»÷ÊÇͨ¹ý´øÓÐÆô¶¯ StrelaStealer DLL¸ºÔصĸ½¼þµÄÀ¬»øÓʼþÀ´Ö´ÐеÄ¡£ÎªÁËÌӱܼì²â£¬¹¥»÷Õ߻ᶨÆÚ¸ü¸Ä³õʼµç×ÓÓʼþÖи½¼þµÄÎļþ¸ñʽ¡£StrelaStealer ÓÚ 2022 Äê 11 ÔÂÊ״μì²âµ½£¬Ö¼ÔÚ´ÓÁ÷ÐеÄÓʼþ¿Í»§¶ËÇÔÈ¡µç×ÓÓʼþÕÊ»§Êý¾Ý£¬²¢½«ÕâЩÐÅÏ¢´«Êäµ½¹¥»÷Õß¿ØÖÆϵķþÎñÆ÷¡£×ԸöñÒâÈí¼þ·ºÆðÒÔÀ´£¬Ñо¿ÈËÔ±¼Ç¼ÁËÁ½´Î²¿Êð¸Ã¶ñÒâÈí¼þµÄÖØ´ó»î¶¯£ºÒ»´ÎÓÚ 2023 Äê 11 Ô£¬ÁíÒ»´ÎÓÚ 2024 Äê 1 Ô¡£ÕâЩ»î¶¯Õë¶ÔµÄÐÐÒµ°üÂÞ¼¼Êõ¡¢½ðÈÚ¡¢×¨ÒµºÍÖ´·¨·þÎñ¡¢ÖÆÔì¡¢ÄÜÔ´¡¢±£ÏÕ¡¢½¨ÖþµÈ¡£


https://meterpreter.org/strelastealer-attacks-hit-100-organizations/


2. Apple M ϵÁÐоƬ΢¼Ü¹¹ÑÏÖØ©¶´£¬¿Éµ¼ÖÂMac É豸ÃÜԿй¶


3ÔÂ24ÈÕ£¬Ñо¿ÈËÔ±·¢ÏÖÁË Apple M ϵÁÐоƬ΢¼Ü¹¹ÖеÄÒ»¸öÑÏÖØ©¶´£¬Ê¹·¸×ï·Ö×ÓÄܹ»´Ó Mac É豸£¨°üÂÞ¼ÆËã»úºÍÌõ¼Ç±¾µçÄÔ£©ÖÐÌáÈ¡ÃÜÔ¿¡£ÎÊÌâµÄÖ¢½áÔÚÓÚ£¬¸Ã©¶´ÓëоƬÉè¼ÆÓб¾ÖÊÁªÏµ£¬½ö¿¿Èí¼þ¸üÐÂÎÞ·¨ÍêÈ«ÐÞ¸´¡£¸Ã©¶´ÓëÊý¾ÝÄÚ´æԤȡ¹¦Ð§Ïà¹Ø£¬¸Ã¹¦Ð§Í¨¹ýÔ¤²âδÀ´µÄÄÚ´æÇëÇóÀ´ÓÅ»¯ÐÅÏ¢´¦Öᣴ˹¦Ð§¿ÉÄÜ»áÎó½â¼ÓÃÜÃÜÔ¿£¬´Ó¶øΪͨ¹ýרÃŹ¥»÷ÌáÈ¡ÃÜÔ¿ÆÌƽÃÅ·¡£Ò»¸ö¹ú¼ÊÑо¿ÍŶÓÉè¼ÆÁËÒ»ÖÖÃûΪ GoFetch µÄ¹¥»÷£¬ËµÃ÷ÁËÎÞÐèÉ豸¹ÜÀíȨÏÞ¼´¿ÉÌáÈ¡ÃÜÔ¿µÄ¿ÉÐÐÐÔ¡£ÕâÖÖ¹¥»÷¿ÉÒÔÔÚרÓÐµÄ M1 ºÍ M2 оƬÉÏÖ´ÐУ¬Ó°Ï촫ͳ¼ÓÃÜËã·¨ºÍ·´¿¹Á¿×Ó¼ÆËãµÄËã·¨¡£ÃÜÔ¿ÌáÈ¡¹ý³Ì´Ó²»µ½Ò»Ð¡Ê±µ½Ê®Ð¡Ê±²»µÈ£¬¾ßÌåÈ¡¾öÓÚ¼ÓÃÜÃÜÔ¿µÄÀàÐͺÍËù½ÓÄɵÄËã·¨¡£Õâ±íÃ÷¸Ã©¶´Äܹ»¹æ±Ü³ß¶È¼ÓÃÜ·ÀÓù»úÖÆ¡£ÎªÁË·À·¶´Ë©¶´£¬¼ÓÃÜÈí¼þ¿ª·¢ÈËÔ±±ØÐëÔÚÆäÈí¼þÖÐʵʩÌرðµÄÄþ¾²»úÖÆ£¬Õâ¿ÉÄܻᵼÖ¼ÓÃܲÙ×÷ÆÚ¼äµÄÐÔÄÜϽµ¡£ÌáÒéµÄ±£»¤´ëÊ©°üÂÞÊý¾ÝÆÁ±ÎºÍ½«´¦ÖÃתÒƵ½Ã»ÓÐ DMP µÄ´¦ÖÃÆ÷Äںˡ£Ñо¿ÈËÔ±»¹Ìá³öÁËÒ»ÖÖºã¾Ã½â¾ö·½°¸£¬Éæ¼°À©Õ¹Ó²¼þºÍÈí¼þ½»»¥£¬ÒÔ±ãÔÚÒªº¦²Ù×÷ÆÚ¼äÍ£Óà DMP¡£Õâ¿ÉÒÔ×ÊÖú×èÖ¹¹¥»÷£¬¶ø²»»áÏÔ×ÅÓ°ÏìÕûÌåÐÔÄÜ¡£


https://meterpreter.org/unfixable-apple-chip-issue-secret-keys-vulnerable/


3. ΢Èí½«¹Ø±ÕÕë¶Ô¶íÂÞ˹ÆóÒµµÄ 50 ÏîÔÆ·þÎñµÄ·ÃÎÊ


3ÔÂ23ÈÕ£¬Î¢Èí¼Æ»®ÔÚ 3 Ôµ×֮ǰÏÞÖƶíÂÞ˹×éÖ¯¶Ô 50 ¶àÖÖÔƲúÎïµÄ·ÃÎÊ£¬ÕâÊÇÅ·Ã˼à¹Ü»ú¹¹È¥Äê 12 Ô¶ԸùúÐû²¼µÄÖƲÃÒªÇóµÄÒ»²¿ÃÅ¡£ÔÝÍ£×î³õ¶¨ÓÚ 2024 Äê 3 Ô 20 ÈÕ½øÐУ¬µ«ºóÀ´ÍƳٵ½±¾Ôµ×£¬ÒÔ±ãÊÜÓ°ÏìµÄʵÌåÓиü¶àʱ¼äÀ´Öƶ¨Ìæ´ú½â¾ö·½°¸¡£Óйؼ´½«ÔÝÍ£µÄÏûÏ¢×îÏÈÓÉ Softline Group of Companies ±¨µÀ£¬¸Ã¹«Ë¾ÊǶíÂÞ˹ÏÖ´æ×î´óµÄ IT ·þÎñÌṩÉÌÖ®Ò»¡£Î¢ÈíµÄÐÅÖÐûÓоßÌå˵Ã÷ÄÄЩ·þÎñ½«±»È¡Ïû£¬µ«Ëþ˹ÉçÒѾ­ÁгöÁË 50 ¶àÖÖ²úÎïµÄÇåµ¥ £¬ÕâЩ²úÎォÔÚ 3 Ôµ×Í£Ö¹Ìṩ¡£ÒÑ Ã÷È· £¬Ðí¿É֤ʧЧӰÏì¶íÂÞ˹´Óʽ¨Öþ¡¢Éè¼Æ¡¢Ê©¹¤¡¢ÖÆÔ졢ýÌå¡¢½ÌÓýºÍÓéÀÖ¡¢½¨ÖþÐÅϢģÐÍ£¨BIM£©¡¢¼ÆËã»ú¸¨ÖúÉè¼Æ£¨CAD£©ºÍ¼ÆËã»ú¸¨ÖúÖÆÔìµÄ¹«Ë¾ºÍ×éÖ¯£¨Í¹ÂÖ£©¡£µ«ÊÇ£¬Ã»ÓÐÐû²¼ÏÞÖƸöÈË·ÃÎʵļƻ®£¬Òò´Ë¼ÙÉèÉÏÊö²úÎïÈԿɹ©ÆÕͨÓû§Ê¹Óá£


https://www.bleepingcomputer.com/news/microsoft/microsoft-to-shut-down-50-cloud-services-for-russian-businesses/


4. SIGN1 ¶ñÒâÈí¼þ»î¶¯ÒÑѬȾ 39000 ¶à¸ö WORDPRESS ÍøÕ¾


3ÔÂ23ÈÕ£¬Sucuri µÄ Sucurity Ñо¿ÈËÔ±·¢ÏÖÁËÒ»¸öÃûΪ Sign1 µÄ¶ñÒâÈí¼þ»î¶¯£¬¸Ã»î¶¯ÔÚ¹ýÈ¥Áù¸öÔÂÄÚÒѾ­Î£º¦ÁË 39,000 ¸ö WordPress ÍøÕ¾¡£×¨¼ÒÃÇ·¢ÏÖ£¬ÍþвÐÐΪÕßÈëÇÖÁËÍøÕ¾£¬Ö²Èë¶ñÒâ JavaScript ×¢È룬½«·ÃÎÊÕßÖض¨Ïòµ½¶ñÒâÍøÕ¾¡£Sign1 ±³ºóµÄÍþв¼ÓÈëÕß½«¶ñÒâ JavaScript ×¢ÈëºÏ·¨²å¼þºÍ HTML С²¿¼þÖС£×¢ÈëµÄ´úÂë°üÂÞÒ»¸öÓ²±àÂëµÄÊý×ÖÊý×飬ËüʹÓà XOR ±àÂëÀ´»ñÈ¡ÐÂÖµ¡£×¨¼Ò¶Ô XOR ±àÂëµÄ JavaScript ´úÂë½øÐÐÁ˽âÂ룬·¢ÏÖËüÓÃÓÚÖ´ÐÐÔ¶³Ì·þÎñÆ÷ÉÏÍÐ¹ÜµÄ JavaScript Îļþ¡£Ñо¿ÈËÔ±×¢Òâµ½£¬¹¥»÷Õß½ÓÄɶ¯Ì¬¸ü¸ÄµÄ URL£¬¶¯Ì¬ JavaScript ´úÂëµÄʹÓÃÔÊÐíÿ 10 ·ÖÖÓ¸ü¸ÄÒ»´Î URL¡£¸Ã´úÂëÔÚ·ÃÎÊÕßµÄä¯ÀÀÆ÷ÖÐÖ´ÐУ¬µ¼ÖÂÍøÕ¾·ÃÎÊÕß·ºÆð²»ÐèÒªµÄÖض¨ÏòºÍ¹ã¸æ¡£Sign1 »î¶¯×î³õÓÉÑо¿Ô±Denis SinegubkoÔÚ 2023 ÄêÏ°ëÄê·¢ÏÖ£¬Sucuri ³ÂË߳ƣ¬×Ô 2023 Äê 7 Ô 31 ÈÕÒÔÀ´£¬ÍþвÐÐΪÕßÀûÓÃÁ˶à´ï 15 ¸ö²îÒìµÄÓò¡£


https://securityaffairs.com/160942/hacking/sign1-malware-campaign.html


5. ÃÀ¹úÕþ¸®Ðû²¼Õë¶Ô¹«¹²²¿ÃŵÄРDDoS ¹¥»÷Ö¸ÄÏ


3ÔÂ22ÈÕ£¬ÃÀ¹úÕþ¸®Îª¹«¹²²¿ÃÅʵÌåÐû²¼ÁËеÄÂþÑÜʽ¾Ü¾ø·þÎñ (DDoS) ¹¥»÷Ö¸ÄÏ£¬ÒÔ×ÊÖú·ÀÖ¹Òªº¦·þÎñÖжÏ¡£¸ÃÎļþÖ¼ÔÚ×÷Ϊ×ÛºÏ×ÊÔ´£¬½â¾öÁª°î¡¢Öݺ͵ط½Õþ¸®»ú¹¹ÔÚ·ÀÓù DDoS ¹¥»÷·½ÃæÃæÁٵľßÌåÐèÇóºÍÌôÕ½¡£¸Ãͨ±¨Ö¸³ö£¬DDoS ¹¥»÷ÊÇÖ¸´óÁ¿ÊÜѬȾµÄ¼ÆËã»úÏòÄ¿±êϵͳ·¢ËÍ´óÁ¿Á÷Á¿»òÇëÇ󣬵¼ÖÂÓû§ÎÞ·¨Ê¹Óøù¥»÷£¬ÕâÖÖ¹¥»÷ºÜÄÑ×·×ÙºÍ×èÖ¹¡£ÕâÖÖý½éͨ³£±»³öÓÚÕþÖζ¯»úµÄ¹¥»÷ÕßʹÓ㬰üÂ޺ڿͻ·Ö×ÓºÍÃñ×å¹ú¼ÒÍÅÌ壬Õþ¸®ÍøÕ¾¾­³£³ÉΪ¹¥»÷Ä¿±ê¡£ÀýÈ磬×Ô 2022 Äê 2 Ô¿ËÀïÄ·ÁÖ¹¬ÈëÇָùúÒÔÀ´£¬Óë¶íÂÞ˹ºÍÎÚ¿ËÀ¼Óйصĺڿ;­³£Ê¹Óà DDoS ¹¥»÷¶Ô·½Õþ¸®ÍøÕ¾¡£2023 Äê 10 Ô£¬Ó¢¹úÍõÊÒ¹Ù·½ÍøÕ¾Òò DDoS ʼþ¶øÏÂÏߣ¬¶íÂÞ˹ºÚ¿Í×éÖ¯ Killnet Éù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦¡£


https://www.infosecurity-magazine.com/news/us-ddos-attack-guidance-public/?&web_view=true


6. ¶íÂÞ˹ºÚ¿ÍÀûÓà WineLoader ¶ñÒâÈí¼þÃé×¼µÂ¹úÕþµ³


3ÔÂ23ÈÕ£¬Ñо¿ÈËÔ±¾¯¸æ³Æ£¬Óë¶íÂÞ˹¶ÔÍâÇ鱨¾Ö£¨SVR£©ÓÐÁªÏµµÄºÚ¿Í×éÖ¯Ê×´ÎÕë¶ÔµÂ¹úÕþµ³£¬½«Æä½¹µã´ÓµäÐ͵ÄÍ⽻ʹÍÅÄ¿±êתÒÆ¿ª¡£ÍøÂçµöÓã¹¥»÷Ö¼ÔÚ²¿ÊðÃûΪ WineLoader µÄºóÃŶñÒâÈí¼þ£¬¸Ã¶ñÒâÈí¼þÔÊÐíÍþвÐÐΪÕßÔ¶³Ì·ÃÎÊÊÜѬȾµÄÉ豸ºÍÍøÂç¡£APT29£¨Ò²³ÆΪ Midnight Blizzard¡¢NOBELIUM¡¢Cozy Bear£©ÊÇÒ»¸ö¶íÂÞ˹¼äµýºÚ¿Í×éÖ¯¡£¸ÃºÚ¿Í×éÖ¯ÓëÐí¶àÍøÂç¹¥»÷ÓйØ£¬°üÂÞ 2020 Äê 12 ÔÂÎÛÃûÕÑÖøµÄSolarWinds ¹©Ó¦Á´¹¥»÷¡£ÕâЩÄêÀ´£¬ÍþвÐÐΪÕßÒ»Ö±±£³Ö»îÔ¾£¬Í¨³£Ê¹ÓÃһϵÁÐÍøÂçµöÓã¼Æı»ò¹©Ó¦Á´Í×ЭÀ´Õë¶ÔÕþ¸®¡¢´óʹ¹Ý¡¢¸ß¼¶¹ÙÔ±ºÍÖÖÖÖʵÌå¡£APT29 ×î½üµÄÖصãÊÇÔÆ·þÎñ£¬ÆÆ»µ Microsoft ϵͳ²¢ÇÔÈ¡ Exchange ÕÊ»§µÄÊý¾Ý£¬²¢ÆÆ»µHewlett Packard EnterpriseʹÓÃµÄ MS Office 365 µç×ÓÓʼþ»·¾³¡£


https://www.bleepingcomputer.com/news/security/russian-hackers-target-german-political-parties-with-wineloader-malware/