DINODASRAT LINUX ±äÖÖÕë¶ÔÈ«ÇòÓû§

Ðû²¼Ê±¼ä 2024-04-02
1. DINODASRAT LINUX ±äÖÖÕë¶ÔÈ«ÇòÓû§


3ÔÂ31ÈÕ,¿¨°Í˹»ùʵÑéÊÒµÄÑо¿ÈËÔ±·¢ÏÖÁË Linux °æ±¾µÄ¶àƽ̨ºóÃÅ DinodasRAT£¬¸ÃºóÃű»ÓÃÓÚÕë¶ÔÖйú¡¢ÍÁ¶úÆäºÍÎÚ×ȱð¿Ë˹̹¡£DinodasRAT£¨ÓÖÃû XDealer£©ÊÇÓà C++ ±àдµÄ£¬Ö§³Ö¹ã·ºµÄ¹¦Ð§À´¼àÊÓÓû§²¢´ÓÄ¿±êϵͳÇÔÈ¡Ãô¸ÐÊý¾Ý¡£ESET Ñо¿ÈËÔ±³ÂË߳ƣ¬Windows °æ±¾µÄ DinodasRAT ±»ÓÃÓÚÕë¶Ô¹çÑÇÄÇÕþ¸®ÊµÌåµÄ¹¥»÷¡£ESET ÓÚ 2023 Äê 10 ÔÂÊ״η¢ÏÖÐ嵀 Linux °æ±¾µÄ DinodasRAT£¬µ«×¨¼ÒÈÏΪËü×Ô 2022 ÄêÒÔÀ´¾ÍÒ»Ö±»îÔ¾¡£2024 Äê 3 Ô£¬Ç÷ÊƿƼ¼Ñо¿ÈËÔ±ÔÚÊÓ²ìÓëÖйúÏà¹ØµÄ APT Earth Lusca»î¶¯Ê±·¢ÏÖÁËÓɱ»×·×ÙΪ Earth Krahang µÄÍþвÐÐΪÕßÌᳫµÄÅÓ´ó»î¶¯ ¡£¸Ã»î¶¯ÖÁÉÙ´Ó 2022 Äê³õ¿ªÊ¼Ëƺõ¾ÍºÜ»îÔ¾£¬Ö÷ÒªÕë¶ÔÕþ¸®×éÖ¯¡£×Ô 2023 ÄêÆð£¬Earth Krahang תÒƵ½ÁíÒ»¸öºóÃÅ£¨  TeamT5ÃüÃûΪ XDealer  £¬  ESET ÃüÃûΪDinodasRAT  £©¡£Ïà±ÈRESHELL£¬XDealerÌṩÁ˸üÈ«ÃæµÄºóÃŹ¦Ð§¡£´ËÍ⣬ÎÒÃÇ·¢ÏÖÍþвÐÐΪÕßͬʱʹÓà Windows ºÍ Linux °æ±¾µÄ XDealer À´Õë¶Ô²îÒìµÄϵͳ¡£


https://securityaffairs.com/161255/malware/linux-variant-dinodasrat-backdoor.html


2. È«ÇòÃÜÂëÅçÈ÷»î¶¯Õë¶Ô VPN ϵͳ¿Éµ¼ÖÂϵͳËø¶¨


3ÔÂ31ÈÕ,˼¿ÆÒÑÐû²¼¹ØÓÚÕë¶ÔÈ«ÇòÆóҵʹÓõÄÔ¶³Ì·ÃÎÊ VPN (RAVPN) ϵͳµÄ¹ã·ºÃÜÂëÅçÈ÷»î¶¯µÄÑÏÖؾ¯¸æ¡£ÕâÖÖ¹¥»÷¼¤ÔöµÄÄ¿µÄÊÇÓÃͨÓÃÃÜÂëÑÍû VPN µÇ¼£¬¿ÉÄÜ»áËø¶¨ºÏ·¨Óû§²¢ÈÅÂÒÔ¶³ÌÊÂÇé¡£ÃÜÂëÅçÈ÷»î¶¯»áÓ°ÏìÖÖÖÖ VPN ÌṩÉÌ£¬¶ø²»½ö½öÊÇ˼¿Æ¡£ÒÀÀµÔ¶³Ì·ÃÎʵÄÆóÒµÐèÒª±£³Ö¸ß¶È¾¯Ìè¡£ÕâЩ¹¥»÷µÄºó¹û²»½ö½öÊÇδ¾­ÊÚȨµÄ·ÃÎÊ£»ËüÃÇÓпÉÄÜËø¶¨ÕÊ»§²¢Òý·¢ÀàËƾܾø·þÎñ (DoS) µÄÇé¿ö£¬´Ó¶øÆÆ»µÊý×Ö²Ù×÷µÄÎÞ·ìÁ÷³Ì²¢Ëðº¦Äþ¾²Í¨ÐŵÄÍêÕûÐÔ¡£¸Ã»î¶¯Í¹ÏÔÁËÔ¶³Ì·ÃÎʽâ¾ö·½°¸ËùÃæÁÙµÄÁ¬ÐøÍþв¡£×éÖ¯±ØÐëÓÅÏÈ¿¼ÂÇÇ¿´óµÄÉí·ÝÑéÖ¤¡¢¾¯ÌèµÄ¼à¿ØºÍÇ¿´óµÄʼþÏìÓ¦¼Æ»®£¬ÒÔÁìÏÈÓÚ²»Í£±ä»¯µÄ¹¥»÷ÒªÁì¡£


https://securityonline.info/global-password-spraying-campaign-targets-vpn-systems-causing-lockouts/


3. ľÂí»¯ npm Èí¼þ°üÃé×¼¼ÓÃÜ»õ±ÒÇ®°ü


3ÔÂ31ÈÕ,Phylum Ñо¿ÍŶÓ̻¶ÁËÒ»¸öαװ³ÉºÏ·¨¹¤¾ß°üµÄ¶ñÒânpm °ü¡£¸ÃÈí¼þ°üÃûΪ¡°vue2util¡±£¬ÍµÍµµØÖ´ÐÐÁËÒ»ÏîÅÓ´óµÄ¼Æ»®£¬Ö¼ÔÚ´ÓºÁÎÞ½äÐĵļÓÃÜ»õ±ÒÇ®°üÖÐÇÔÈ¡ USDT ´ú±Ò¡£¡°vue2util¡±¿´ÆðÀ´ÏñÊdz߶ÈʵÓú¯ÊýµÄ¼¯ºÏ¡£È»¶ø£¬ËüÒþ²ØÁËÒ»¸öÏÕ¶ñµÄÓÐЧ¸ºÔØ£¬µ±µ¼Èëµ½ÏîÄ¿ÖÐʱ£¬¸ÃÓÐЧ¸ºÔØ»á´ÓÔ¶³Ì·þÎñÆ÷¼ÓÔضñÒâ½Å±¾¡£¼ÓÔصĽű¾ÒÔ±Ò°²ÖÇÄÜÁ´µÄÓû§ÎªÄ¿±ê£¬ËÑË÷³ÖÓÐ USDT ¼ÓÃÜ»õ±ÒµÄÇ®°ü¡£¶ñÒâÈí¼þÀûÓà ERC20 ºÏÔ¼£¨¹ÜÀí USDT£©µÄÉóÅúÁ÷³Ì¡£ËüÔÊÐí×Ô¼ºÎÞÏÞÖƵطÃÎÊÊܺ¦Õß³ÖÓÐµÄ USDT£¬ÎÞÐè½øÒ»²½ÊÚȨ¡£ÎªÁËÔö¼ÓÀֳɵĻú»á£¬¶ñÒâÈí¼þÇÉÃîµØ½«ÆäÖ´ÐÐÁ´½Óµ½Óû§ÍøÒ³Éϱê־Ϊ¡°buy_btn¡±µÄ°´Å¥¡£Ö»Ðèµ¥»÷һϣ¬Êܺ¦Õ߾ͻáÔÚ²»Öª²»¾õÖд¥·¢ÁîÅÆ͵ÇÔ¡£


https://securityonline.info/trojanized-npm-package-targets-cryptocurrency-wallets-steals-usdt/


4. Ñо¿ÍŶӷ¢ÏÖʹÓà Google Ads ¸ú×Ù¹¦Ð§·Ö·¢¶ñÒâÈí¼þ


4ÔÂ1ÈÕ,AhnLab Äþ¾²Ç鱨ÖÐÐÄ (ASEC) ×î½ü¼ì²âµ½Ê¹Óà Google Ads ¸ú×Ù¹¦Ð§·Ö·¢µÄ¶ñÒâÈí¼þ±äÖÖ¡£ÒÑÈ·ÈϵݸÀý±íÃ÷£¬¸Ã¶ñÒâÈí¼þÊÇͨ¹ýαװ³É Notion ºÍ Slack µÈÁ÷ÐÐȺ¼þµÄ°²×°·¨Ê½À´Á÷´«µÄ¡£Ò»µ©¶ñÒâÈí¼þ°²×°²¢Ö´ÐУ¬Ëü¾Í»á´Ó¹¥»÷ÕߵķþÎñÆ÷ÏÂÔضñÒâÎļþºÍÓÐЧ¸ºÔØ¡£´ËÀà¶ñÒâÈí¼þÒÔ°²×°·¨Ê½ÐÎʽ·Ö·¢£¬Í¨³£Îª Inno Setup °²×°·¨Ê½»ò Nullsoft ½Å±¾°²×°ÏµÍ³ (NSIS) °²×°·¨Ê½¡£ÆäÖУ¬Notion_software_x64_.exeÎļþÖ±µ½×î½üÓû§ÔÚGoogleÉÏÓÃÒªº¦×Ö¡°notion¡±ËÑË÷ʱ²Å·ºÆð¡£¹¥»÷ÕßʹÓà Google Ads ¸ú×ÙÀ´ÓÕÆ­Óû§ÈÏΪËûÃÇÕýÔÚ·ÃÎʺϷ¨ÍøÕ¾¡£Google Ads ¸ú×ÙÔÊÐí¹ã¸æ¿Í»§²åÈëÍⲿÃÅÎöÍøÕ¾µØÖ·£¬ÒÔÊÕ¼¯ºÍʹÓ÷ÃÎÊÕߵķÃÎÊÏà¹ØÊý¾ÝÀ´¼ÆËã¹ã¸æÁ÷Á¿¡£Google Ads ¸ú×Ù×î³õÓÃÓÚ·ÖÎöÍøÕ¾Á÷Á¿¡£µ«ÊÇ£¬¸ÃÌض¨¹ã¸æ²»°üÂÞÍⲿ¾²Ì¬Õ¾µã£¬¶øÊÇ°üÂÞ¶ñÒâ´úÂë·Ö·¢Õ¾µã¡£

Ä¿Ç°¹¥»÷ÕߵĹã¸æÒѱ»É¾³ý¡£


https://asec.ahnlab.com/en/63477/


5. ºÚ¿ÍʹÓà Microsoft OneNote À´³ïıÍøÂç¹¥»÷


4ÔÂ1ÈÕ,¸Ã»î¶¯ÔÚÍøÂçÄþ¾²×¨¼ÒµÄ¹Øעϣ¬Õ¹Ê¾ÁËÍøÂçÍþвµÄÐÂÇ÷ÊÆ£¬¼´ÀûÓó£Óõİ칫ӦÓ÷¨Ê½Î´¾­ÊÚȨ·ÃÎÊÆóÒµÍøÂç¡£pr0xylife Ê×ÏÈÔÚÆä GitHub ´æ´¢¿âÉϼǼÁ˸öñÒâ»î¶¯¡£Ëü½Ò¶ÁËÕë¶ÔÖÆÔì¡¢¼¼Êõ¡¢ÄÜÔ´¡¢ÁãÊÛ¡¢±£ÏÕºÍÆäËû¼¸¸öÐÐÒµµÄ¹«Ë¾µÄ¹ã·ºµç×ÓÓʼþÍøÂçµöÓã²Ù×÷¡£ÕâЩµç×ÓÓʼþ°üÂÞÉù³ÆÊÇ¡°Äþ¾²ÏûÏ¢¡±µÄ OneNote ¸½¼þ£¬ÕâÊÇÒ»ÖÖÆÛÆ­ÊÕ¼þÈË´ò¿ªÎļþµÄ»Ï×Ó¡£¸Ã»î¶¯Ç¿µ÷ÁËÍøÂçÍþв²»Í£ÑݱäµÄÇé¿ö£¬¹¥»÷ÕßÀûÓöԳ£ÓÃÓ¦Ó÷¨Ê½µÄÐÅÈÎÀ´Èƹý´«Í³µÄÄþ¾²´ëÊ©¡£Ê¹Óà Microsoft OneNote ÎļþÁ÷´«¶ñÒâÈí¼þ´ú±í×ÅÏò¸ü¾ßµÞÔìÐԵĹ¥»÷ý½éµÄת±ä£¬Òò´ËÐèÒªÖØÐÂÆÀ¹ÀÍøÂçÄþ¾²¼ÆıÒÔ·À·¶´ËÀàÍþв¡£


https://gbhackers.com/microsoft-onenote-orchestrate/


6. TeamCity ÐÞ²¹ÁË 26 ¸ö©¶´²¢±£ÃÜÏêϸÐÅÏ¢


4ÔÂ1ÈÕ,ÔÚ JetBrains µÄÁ¬Ðø¼¯³ÉºÍ½»¸¶ (CI/CD) TeamCity ×î½üµÄÈí¼þ¸üÐÂÖУ¬½â¾öÁË 26 ¸öÄþ¾²ÎÊÌ⡣Ȼ¶ø£¬¸Ã¹«Ë¾Ñ¡Ôñ²»Í¸Â¶ÓйØÒÑ·¢ÏÖ©¶´µÄÈκÎϸ½Ú£¬Òý·¢ÁËרҵ½çµÄ¼¤ÁÒÌÖÂÛ¡£TeamCity 2024.03 °æ±¾¸üÐÂÖ¼ÔÚ±£»¤Óû§ÃâÊÜDZÔÚÍþв£¬µ«ÍêȫûÓÐÓÐ¹Ø 26 ¸ö©¶´µÄÏêϸÐÅÏ¢£¬×ÅʵÈÃÄþ¾²×¨¼Ò¸ÐÓ¦¾ªÑÈ¡£¸Ã¹«Ë¾È±·¦Í¸Ã÷¶È£¬ÌرðÊÇÔÚ Rapid7 µÄר¼ÒÅúÆÀ JetBrains ²»¹»¿ª·ÅµÄʼþÖ®ºó£¬Ò»Ö±Êܵ½ÌرðÅúÆÀ¡£JetBrains Éù³Æ£¬±£ÁôÏêϸÐÅÏ¢Ö»ÊÇΪÁ˱£»¤Ê¹Óþɰæ TeamCity µÄ¿Í»§£¬¾¡¹ÜÕâÔÚÒµ½ç²¢Î´µÃµ½¹ã·º½ÓÊÜ¡£¾¡¹ÜÈç´Ë£¬¸Ã¹«Ë¾µÄÒâͼ»¹ÊÇ¿ÉÒÔÀí½âµÄ¡£¶ÔÓÚÏëÒª¹¥»÷Èí¼þ¹©Ó¦Á´µÄ·¸×ï·Ö×ÓÀ´Ëµ£¬TeamCity ÈÔÈ»ÊÇÒ»¸öÓÐÎüÒýÁ¦µÄÄ¿±ê¡£ÀúÊ·±íÃ÷£¬´ËÀ๥»÷¿ÉÄܻᷢÉúÑÏÖغó¹û£¬ÕýÈç SolarWinds µÄ°¸ÀýËùʾ¡£


https://meterpreter.org/teamcity-patches-26-vulnerabilities-keeps-details-secret/