SambaSpy¶ñÒâÈí¼þͨ¹ýµöÓãµç×ÓÓʼþ¹¥»÷Òâ´óÀûÓû§

Ðû²¼Ê±¼ä 2024-09-23
1. SambaSpy¶ñÒâÈí¼þͨ¹ýµöÓãµç×ÓÓʼþ¹¥»÷Òâ´óÀûÓû§


9ÔÂ19ÈÕ£¬¿¨°Í˹»ùʵÑéÊÒ½üÆÚ½Ò¶ÁËÒ»Ïî¸ß¶È¶¨ÖÆ»¯µÄ¶ñÒâÈí¼þ»î¶¯£¬ÃûΪSambaSpy£¬ÆäÆæÌØÖ®´¦ÔÚÓÚ½öÕë¶ÔÒâ´óÀûÓû§¡£Õâ¿îÔ¶³Ì·ÃÎÊľÂí£¨RAT£©Í¨¹ýαװ³ÉÒâ´óÀû·¿µØ²ú¹«Ë¾µÄºÏ·¨ÓʼþÁ÷´«£¬ÓʼþÄÚº¬¿´ËÆÎÞº¦µÄ·¢Æ±¼ì²ìÁ´½Ó£¬ÊµÔòµ¼Ïò¶ñÒâJARÎļþÏÂÔØ¡£SambaSpyÀûÓÃÓïÑÔ¼ì²é»úÖÆ£¬È·±£½öѬȾÒâ´óÀûÓïϵͳ£¬Õ¹ÏÖÁ˹¥»÷Õߵĸ߶ÈרҵÐԺ;«×¼¶¨Î»ÄÜÁ¦¡£Ò»µ©°²×°£¬SambaSpy¸³Óè¹¥»÷Õ߶ÔÊÜѬȾÉ豸µÄÈ«Ãæ¿ØÖÆȨ£¬°üÂÞÎļþ¹ÜÀí¡¢ÍøÂçÉãÏñÍ·¼à¿Ø¡¢¼üÅ̼Ǽ¡¢ÆÁÄ»½Øͼ¡¢ä¯ÀÀÆ÷ƾ֤ÇÔÈ¡¼°Ô¶³Ì×ÀÃæ²Ù×÷µÈ¡ £¿¨°Í˹»ù×·×Ùµ½Á½ÌõѬȾÁ´£¬¾ùÀûÓõç×ÓÓʼþ×÷ΪÈëÇÖÃÅ»§£¬ÆäÖÐÒ»Ìõ¸üΪÅÓ´ó£¬Í¨¹ýºÏ·¨Òâ´óÀûÔÆ·¢Æ±·þÎñFattureInCloud×÷ΪÑÚ»¤£¬½øÒ»²½ÆÛÆ­Êܺ¦Õß¡£ÖµµÃ×¢ÒâµÄÊÇ£¬¾¡¹Ü»î¶¯Ö÷Òª¾Û½¹ÓÚÒâ´óÀû£¬µ«·¢ÏֵİÍÎ÷ÆÏÌÑÑÀÓïºÛ¼£¼°¿çµØÓòÁ´½Ó±íÃ÷¹¥»÷Õß¿ÉÄÜÓµÓиü¹ã·ºµÄÒ°ÐÄ¡£´Ë´Îʼþ²»½ö͹ÏÔÁËÍøÂçÄþ¾²ÍþвµÄÒþ±ÎÐÔÓëÅÓ´óÐÔ£¬Ò²ÌáÐÑÁËÈ«ÇòÓû§Ðè¼ÓÇ¿·À·¶Òâʶ£¬ÌرðÊÇÕë¶Ô¸ß¶È¶¨ÖÆ»¯µÄÍøÂç¹¥»÷¡£


https://securityonline.info/sambaspy-rat-targets-italian-users-in-a-unique-malware-campaign/


2. Ivanti CSA 4.6ÑÏÖØ©¶´CVE-2024-8963Òѱ»»ý¼«ÀûÓÃ


9ÔÂ19ÈÕ£¬ÆóÒµÈí¼þ¾ÞÍ·Ivanti½üÆÚ½Ò¶ÁËÆäIvanti Connect Secure Appliance£¨CSA£©4.6°æ±¾ÖдæÔÚµÄÒ»¸ö¸ßΣ©¶´CVE-2024-8963£¬¸Ã©¶´ÑÏÖØÐÔÆÀ¼¶¸ß´ïCVSS 9.4£¬ÇÒÒѱ»·¢ÏÖÕý±»¶ñÒâÀûÓ㬶ÔʹÓÃÒÑÍ£²ú£¨EOL£©°æ±¾µÄ¿Í»§×é³ÉÖØ´óÄþ¾²Íþв¡£´Ë©¶´ÎªÂ·¾¶±éÀúÀàÐÍ£¬ÔÊÐíδÊÚȨԶ³Ì¹¥»÷Õß·Ç·¨·ÃÎÊCSA 4.6µÄÊÜÏÞÇøÓò£¬ÉõÖÁÓëÁíһ©¶´CVE-2024-8190½áºÏʹÓÃʱ£¬ÄÜÈƹýÉí·ÝÑéÖ¤Ö´ÐÐÈÎÒâÃüÁî¡£¼øÓÚCSA 4.6ÒÑÍ£Ö¹½ÓÊÕ¹Ù·½Äþ¾²¸üУ¬Ivanti½ô¼±Ðû²¼ÁËCSA 4.6²¹¶¡519ÒÔÐÞ¸´¸Ã©¶´£¬µ«´Ë²¹¶¡±êÖ¾×ŶԸð汾µÄ×îºóÒ»´Îά»¤¡£CISAÒѽ«´Ë©¶´ÁÐΪÒÑÖª±»ÀûÓõÄ©¶´£¬Ç¿ÁÒ½¨Òé¸÷×é֯ѸËÙÐж¯£¬½ÓÄɵ÷Í£´ëÊ©¡£IvantiÇ¿µ÷£¬³ýÁËÉý¼¶µ½CSA 5.0°æ±¾Í⣬²»»áΪ4.6°æ±¾Ìṩ½øÒ»²½²¹¶¡£¬Òò´Ë£¬¾¡¹ÜÁÙʱ²¹¶¡ÌṩÁ˶ÌÆÚ»º½â£¬µ«¾ÃÔ¶À´¿´£¬Ïòа汾ǨÒÆÊÇÈ·±£ÏµÍ³Äþ¾²µÄΨһ;¾¶¡£


https://securityonline.info/critical-flaw-in-ivanti-csa-4-6-cve-2024-8963-actively-exploited-urgent-upgrade-required/


3. LockBitÀÕË÷Èí¼þÔÙÏ®eFile.com£¬Êý°ÙÍòÃÀ¹úÈËË°ÎñÊý¾ÝÄþ¾²½ô¼±


9ÔÂ19ÈÕ£¬ÀÕË÷Èí¼þ×éÖ¯LockBit½üÆÚÔٴν«Ä¿±êÃé×¼ÁËÃÀ¹úÔÚÏß±¨Ë°·þÎñeFile.com£¬ÕâÊÇÒ»¸ö¾­ÃÀ¹ú¹úË°¾Ö£¨IRS£©¹Ù·½ÊÚȨµÄË°ÎñÉ걨ƽ̨¡£¾ÝCyber Express±¨µÀ£¬LockBitÒªÇóeFileÔÚ14ÌìÄÚÖ§¸¶Êê½ð£¬µ«²îÒìÓÚͨÀýÀÕË÷Èí¼þ²Ù×÷£¬´Ë´Î¹¥»÷²¢Î´¹ûÈ»Èκα»ÇÔÈ¡Êý¾ÝµÄÑùÀýÀ´Ö¤ÊµÆäÍþв¡£½ØÖÁÄ¿Ç°£¬¹ØÓÚ¹¥»÷µÄ¾ßÌå¹æÄ£¡¢Êý¾Ýй¶Çé¿ö¼°·¸×ﶯ»úµÄÐÅÏ¢ÈÔ±£ÃÜ£¬eFile.com¹ÙÍøÔò±£³ÖÕý³£ÔË×÷¡£Êý°ÙÍòÒÀÀµeFile±¨Ë°µÄÃÀ¹úÈËÃæÁÙDZÔÚ·çÏÕ£¬Ò»µ©¹¥»÷±»È·ÈÏ£¬ÄÉË°È˵ĸöÈ˺ͲÆÕþÊý¾Ý¿ÖÔâй¶£¬ÎªÉí·Ý͵ÇÔ¡¢Ë°ÎñÆÛÕ©µÈ·Ç·¨ÐÐΪÌṩδ²¡£ÖµµÃ×¢ÒâµÄÊÇ£¬eFile²¢·ÇÊ״γÉΪLockBitµÄÁÔÎÔçÔÚ2022ÄêË°ÎñÉ걨á¯ÁëÆÚ£¬LockBit¾ÍÔøÉù³ÆÈëÇÖeFile£¬ÏÔʾ³ö·¸×ï·Ö×Ó¶Ô¸ßÁ÷Á¿Ê±¶ÎµÄ¾«×¼¹¥»÷Òâͼ¡£´ËÍ⣬2023ÄêeFile»¹ÔøÔâÓö¡°efail¡±¶ñÒâÈí¼þÈëÇÖ£¬ÀûÓÃƽ̨©¶´ÇÔÈ¡Óû§Ãô¸ÐÐÅÏ¢£¬Ê¼þË估ʱµÃµ½¿ØÖÆ£¬È´ÔÙ´ÎÇÃÏìÁ˽ðÈÚ·þÎñÍøÂçÄþ¾²·À»¤µÄ¾¯ÖÓ¡£


https://thecyberexpress.com/u-s-taxpayer-data-lockbit-ransomware-efile/


4. Gleaming PiscesÀûÓÃPyPI·Ö·¢PondRATºóÃÅ


9ÔÂ19ÈÕ£¬Unit 42 Ñо¿ÍŶӽÒ¶Á˳¯ÏÊÁ¥ÊôµÄAPT×éÖ¯Gleaming PiscesÌᳫµÄÒ»ÏîÐÂÍøÂç¹¥»÷£¬¸Ã×éÖ¯ÀûÓú¬ÓжñÒâ´úÂëµÄPythonÈí¼þ°ü£¬Õë¶ÔLinuxºÍmacOSϵͳÌᳫ¹¥»÷¡£ÕâЩ¶ñÒâÈí¼þ°üͨ¹ýPyPI´æ´¢¿â·Ö·¢£¬°üÂÞ¡°real-ids¡±¡¢¡°coloredtxt¡±µÈ£¬Ò»µ©°²×°¼´»á²¿ÊðÃûΪPondRATµÄºóÃÅ·¨Ê½£¬ËüÊÇPOOLRATµÄÇáÁ¿¼¶°æ±¾£¬¾ß±¸Ô¶³Ì¿ØÖÆÊܺ¦ÕßϵͳµÄÄÜÁ¦¡£¹¥»÷Õßͨ¹ýPondRAT¿ÉÉÏ´«ÏÂÔØÎļþ¡¢Ö´ÐÐÃüÁîÉõÖÁÔÝͣϵͳ²Ù×÷£¬Æä¿çƽ̨ÌØÐÔʹµÃ¹¥»÷ÓÈΪΣÏÕ¡£Gleaming PiscesÒÔÆäÓëÕì²ì×ֵܾĹØÁª¼°ÔÚ¼ÓÃÜ»õ±ÒÁìÓòµÄÅÓ´ó¹¥»÷»î¶¯Öø³Æ£¬ÌرðÊÇͨ¹ýAppleJeus»î¶¯·Ö·¢¼Ùð¼ÓÃÜ»õ±ÒÈí¼þ¡£´Ë´Î¹¥»÷ÖУ¬PondRATÓëAppleJeus¶ñÒâÈí¼þ´æÔÚ´úÂëÏàËÆÐÔ£¬±íÃ÷ÊÇGleaming PiscesÁ¬ÐøÉø͸¹©Ó¦Á´µÄÒ»²¿ÃÅ¡£¾¡¹ÜPyPIÒÑÒƳýÏà¹Ø¶ñÒâ°ü£¬µ«Öж¾Èí¼þ°üµÄÍþвÒÀ¾É²»ÈݺöÊÓ¡£ÎªÓ¦¶Ô´ËÀàÍþв£¬×éÖ¯Ðè¼ÓÇ¿Äþ¾²´ëÊ©£¬°üÂÞÔÚÒýÈëµÚÈý·½Èí¼þ°üʱ½øÐÐÑϸñµÄ´úÂëÉó²éºÍÑéÖ¤£¬ÒÔ¼°ÊµÊ©ÔËÐÐʱ¼à¿Ø¡£


https://securityonline.info/north-korean-hackers-gleaming-pisces-poisoned-python-packages-target-linux-macos/


5. мÓÆÂBingXƽ̨ÔâºÚ¿Í¹¥»÷£¬Ëðʧ³¬4400ÍòÃÀÔª


9ÔÂ21ÈÕ£¬Ð¼ÓƼÓÃÜ»õ±Ò½»Ò×ƽ̨BingXÖÜÎåÈ·ÈÏ£¬Æäƽ̨ÔÚÔâÊÜÍøÂç¹¥»÷ºó£¬ËðʧÁËÁè¼Ý4400ÍòÃÀÔªµÄ¼ÓÃÜ»õ±Ò¡£ÖÜËÄÍí¼ä£¬Çø¿éÁ´Äþ¾²¹«Ë¾¼à²âµ½×ʽðÒì³£Á÷¶¯£¬ËæºóBingXÐû²¼Òò¡°Ç®°üά»¤¡±ÔÝÍ£·þÎñ£¬²¢Ðû²¼ÉùÃ÷³Æ¼ì²âµ½ÈÈÇ®°ü¿ÉÄÜÔâÊܺڿ͹¥»÷£¬Òѽô¼±×ªÒÆ×ʲú²¢ÔÝÍ£Ìá¿î·þÎñ¡£¿ª¶Ë¹ÀËãÏÔʾ£¬Ö±½ÓËðʧԼΪ4470ÍòÃÀÔª£¬µ«¾ßÌåÊý¶îÈÔÔÚºËʵÖС£BingXÊ×ϯ²úÎï¹ÙVivien Linͨ¹ýÉ罻ýÌåÌåÏÖ£¬¹«Ë¾½«ÓÃ×ÔÓÐ×ʽðÈ«¶îÃÖ²¹Ëðʧ£¬²¢Ç¿µ÷ÒµÎñÔËӪδÊÜÓ°Ï죬Ìá¿îºÍ´æ¿î·þÎñÔ¤¼Æ24СʱÄÚ»Ö¸´¡£Í¬Ê±£¬BingXÕýÓëSlowMistºÍChainalysisµÈÄþ¾²¹«Ë¾ºÏ×÷×·×Ù±»µÁ×ʽð¡£½üÆÚ£¬ÑÇÖÞµØÓò¶à¼Ò¼ÓÃÜƽ̨Ƶ·¢Äþ¾²Ê¼þ£¬×ʽ𱻵Á½ð¶î¾Þ´ó£¬Ö´·¨»ú¹¹ÒѼÓÇ¿¶Ô´ËÀà·¸×ïµÄ¹¥»÷Á¦¶È¡£ÕâһϵÁÐʼþÔÙ´Î͹ÏÔÁ˼ÓÃÜ»õ±ÒÐÐÒµÔÚÄþ¾²ÐÔ·½ÃæÃæÁÙµÄÌôÕ½¡£


https://therecord.media/44-million-stolen-from-crypto-platform-singapore


6. AsyncRAT¶ñÒâÈí¼þαװÆƽâÈí¼þÓÕÆ­Óû§ÏÂÔØ


9ÔÂ21ÈÕ£¬McAfee Labs½ÒʾÁËÒ»¸öÑϾþµÄÍøÂçÄþ¾²Ç÷ÊÆ£ºÍøÂç·¸×ï·Ö×Óͨ¹ýαװÁ÷ÐÐÆƽâÈí¼þÈçCCleaner¡¢EaseUS Partition MasterµÈ£¬Á÷´«ÃûΪAsyncRATµÄ¶ñÒâÈí¼þ¡£ÕâЩ¼ÙðӦÓÃÀûÓÃÁËÓû§×·ÇóÃâ·Ñ¸ß¼¶Èí¼þµÄÐÄÀí£¬ÊµÔòÄÚº¬ÅÓ´óµÄÔ¶³Ì·ÃÎÊľÂí¡£AsyncRATͨ¹ý¾«ÐÄÉè¼ÆµÄαװ¼Æı£¬°üÂÞǶÈëºÏ·¨Èí¼þ¿ÉÖ´ÐÐÎļþ£¬ÀÖ³ÉÆÛÆ­Óû§ÏÂÔز¢Ö´ÐС£°²×°ºó£¬¸Ã¶ñÒâÈí¼þ»áÀûÓÃWindows DefenderÅųýÏîºÍ»ìÏý¼¼Êõ¶ã±Ü¼ì²â£¬²¢Í¨¹ý»·¾³±äÁ¿²Ù×÷ºÍÒþ±ÎµÄbatÎļþά³ÖÆä²Ù×÷²»±»·¢ÏÖ¡£ÆäÖ÷ҪĿµÄÊǽ¨Á¢¶ÔÊÜѬȾ»úÆ÷µÄÔ¶³ÌÁ¬½Ó£¬Èù¥»÷ÕßÄܽøÐа´¼ü¼Ç¼¡¢Êý¾ÝÇÔÈ¡µÈ¶ñÒâ»î¶¯¡£AsyncRAT»¹½ÓÄÉAES½âÃܺÍGzip½âѹËõÀ´Òþ²ØÅäÖã¬ÔöÇ¿ÆäÒþ±ÎÐÔ¡£×Ô2024Äê3ÔÂÒÔÀ´£¬ÕâÖÖÍþвÔÚÈ«Çò·¶Î§ÄÚѸËÙÂûÑÓ£¬ÏÔʾ³öÍøÂç·¸×ï·Ö×ÓÀûÓÃÓû§ÐÄÀíÈõµãÁ÷´«¶ñÒâÈí¼þµÄ¸ßÃ÷ÊֶΡ£


https://securityonline.info/beware-of-fake-downloads-asyncrat-spreads-via-popular-software-cracks/