StrelaStealer¹¥»÷Å·Ã˺ÍÃÀ¹úµÄ 100 ¶à¸ö×éÖ¯»òÆóÒµ

°ä²¼¹¦·ò 2024-03-25
1. StrelaStealer¹¥»÷Å·Ã˺ÍÃÀ¹úµÄ 100 ¶à¸ö×éÖ¯»òÆóÒµ


3ÔÂ24ÈÕ £¬ÔÚUnit 42×î½üµÄÒ»·Ý»ã±¨ÖÐPalo Alto Networks µÄ×êÑÐÈËÔ±·¢ÏÖÁËһϵÁÐеÄÍøÂç´¹µö¹¥»÷ £¬Ö¼ÔÚ´«²¼ÃûΪ StrelaStealer µÄ¶ñÒâÈí¼þ ¡£ÕâÒ»ÍþвÒÑÓ°Ï쵽ŷÃ˺ÍÃÀ¹úµÄ 100 ¶à¸ö×éÖ¯ ¡£ÕâЩ¹¥»÷ÊÇͨ¹ý´øÓÐÆô¶¯ StrelaStealer DLL¸ºÔصĸ½¼þµÄÀ¬»øÓʼþÀ´Ö´ÐÐµÄ ¡£ÎªÁËÌӱܼì²â £¬¹¥»÷Õ߻ᶨÆÚ¸ü¸Ä³õʼµç×ÓÓʼþÖи½¼þµÄÎļþÌåʽ ¡£StrelaStealer ÓÚ 2022 Äê 11 Ô³õ´Î¼ì²âµ½ £¬Ö¼ÔÚ´ÓÊ¢ÐеÄÓʼþ¿Í»§¶ËÇÔÈ¡µç×ÓÓʼþÕÊ»§Êý¾Ý £¬²¢½«ÕâЩÐÅÏ¢´«Êäµ½¹¥»÷Õß½ÚÔìϵķþÎñÆ÷ ¡£×ԸöñÒâÈí¼þ³öÏÖÒÔÀ´ £¬×êÑÐÈËÔ±¼Í¼ÁËÁ½´Î²¿Êð¸Ã¶ñÒâÈí¼þµÄ³Á´ó»î¶¯£ºÒ»´ÎÓÚ 2023 Äê 11 Ô £¬ÁíÒ»´ÎÓÚ 2024 Äê 1 Ô ¡£ÕâЩ»î¶¯Õë¶ÔµÄÐÐÒµÔ̺¬¼¼Êõ¡¢½ðÈÚ¡¢×¨ÒµºÍ˾·¨·þÎñ¡¢Ôì×÷¡¢ÄÜÔ´¡¢±£ÏÕ¡¢¹¹ÖþµÈ ¡£


https://meterpreter.org/strelastealer-attacks-hit-100-organizations/


2. Apple M ϵÁÐоƬ΢¼Ü¹¹ÑϳÁ·ì϶ £¬¿Éµ¼ÖÂMac É豸ÃÜԿй¶


3ÔÂ24ÈÕ £¬×êÑÐÈËÔ±·¢ÏÖÁË Apple M ϵÁÐоƬ΢¼Ü¹¹ÖеÄÒ»¸öÑϳÁ·ì϶ £¬Ê¹·¸×ï·Ö×Ó¿ÉÄÜ´Ó Mac É豸£¨Ô̺¬ÍÆËã»úºÍ±Ê¼Ç±¾µçÄÔ£©ÖÐÌáÈ¡ÃÜÔ¿ ¡£ÎÊÌâµÄÖ¢½áÔÚÓÚ £¬¸Ã·ì϶ÓëоƬÉè¼ÆÓÐÐÔÖÊÁªÏµ £¬½ö¿¿Èí¼þ¸üÐÂÎÞ·¨ÆëÈ«½¨¸´ ¡£¸Ã·ì϶ÓëÊý¾ÝÄÚ´æÔ¤È¡Ö°ÄÜÓÐ¹Ø £¬¸ÃÖ°ÄÜͨ¹ýÔ¤²â½«À´µÄÄÚ´æÒªÇóÀ´ÓÅ»¯ÐÅÏ¢´¦Öà ¡£´ËÖ°ÄÜ¿ÉÄÜ»áÎó»á¼ÓÃÜÃÜÔ¿ £¬´Ó¶øÎªÍ¨¹ýרÃŹ¥»÷ÌáÈ¡ÃÜԿ̯ƽ·· ¡£Ò»¸ö¹ú¼Ê×êÑÐÍŶÓÉè¼ÆÁËÒ»ÖÖÃûΪ GoFetch µÄ¹¥»÷ £¬ËµÁËÈ»ÎÞÐèÉ豸ÖÎÀíȨÏÞ¼´¿ÉÌáÈ¡ÃÜÔ¿µÄ¿ÉÐÐÐÔ ¡£ÕâÖÖ¹¥»÷Äܹ»ÔÚרÓÐµÄ M1 ºÍ M2 оƬÉÏÖ´ÐÐ £¬Ó°Ï촫ͳ¼ÓÃÜËã·¨ºÍµÖ¿¹Á¿×ÓÍÆËãµÄËã·¨ ¡£ÃÜÔ¿ÌáÈ¡¹ý³Ì´Ó²»µ½Ò»Ó×ʱµ½Ê®Ó×ʱ²»µÈ £¬¾ßÌåÈ¡¾öÓÚ¼ÓÃÜÃÜÔ¿µÄÀàÐͺÍËùѡȡµÄËã·¨ ¡£ÕâÅú×¢¸Ã·ì϶¿ÉÄܶã±Ü³ß¶È¼ÓÃÜ·ÀÓù»úÔì ¡£ÎªÁË·À±¸´Ë·ì϶ £¬¼ÓÃÜÈí¼þ¿ª·¢ÈËÔ±±ØÐëÔÚÆäÈí¼þÖÐÖ´Ðжî±íµÄ°²È«»úÔì £¬Õâ¿ÉÄܻᵼÖ¼ÓÃܲÙ×÷ÆÚ¼äµÄ»úÄܽµÂä ¡£ÌáÒéµÄ±£»¤´ëÊ©Ô̺¬Êý¾ÝÆÁ±ÎºÍ½«´¦ÖÃ×ªÒÆµ½Ã»ÓÐ DMP µÄ´¦ÖÃÆ÷ÄÚºË ¡£×êÑÐÈËÔ±»¹Ìá³öÁËÒ»Öֳ־ýâ¾ö¹æ»® £¬Éæ¼°À©´óÓ²¼þºÍÈí¼þ½»»¥ £¬ÒÔ±ãÔڹؼü²Ù×÷ÆÚ¼äÍ£Óà DMP ¡£ÕâÄܹ»Ô®ÊÖ×èÖ¹¹¥»÷ £¬¶ø²»»áÏÔ×ÅÓ°ÏìÕûÌå»úÄÜ ¡£


https://meterpreter.org/unfixable-apple-chip-issue-secret-keys-vulnerable/


3. ΢Èí½«¹Ø¹ØÕë¶Ô¶íÂÞ˹ÆóÒµµÄ 50 ÏîÔÆ·þÎñµÄ½Ó¼û


3ÔÂ23ÈÕ £¬Î¢Èí´òËãÔÚ 3 Ôµ×֮ǰÏ޶ȶíÂÞ˹×éÖ¯¶Ô 50 ¶àÖÖÔÆ²úÆ·µÄ½Ó¼û £¬ÕâÊÇÅ·Ã˼à¹Ü»ú¹¹È¥Äê 12 Ô¶Ըùú°ä²¼µÄÔì²ÃÒªÇóµÄÒ»²¿ÃÅ ¡£ÔÝÍ£×î³õ¶¨ÓÚ 2024 Äê 3 Ô 20 ÈÕ½øÐÐ £¬µ«ºóÀ´ÍƳٵ½±¾ÔÂµ× £¬ÒÔ±ãÊÜÓ°ÏìµÄʵÌåÓиü¶à¹¦·òÀ´Ôì¶©´úÌæ½â¾ö¹æ»® ¡£Óйؼ´½«ÔÝÍ£µÄÐÂÎÅ×îÏÅ×É Softline Group of Companies ±¨Â· £¬¸Ã¹«Ë¾ÊǶíÂÞ˹ÏÖ´æ×î´óµÄ IT ·þÎñÌṩÉÌÖ®Ò» ¡£Î¢ÈíµÄÐÅÖÐûÓоßÌå×¢Ã÷ÄÄЩ·þÎñ½«±»È¡µÞ £¬µ«Ëþ˹ÉçÒѾ­ÁгöÁË 50 ¶àÖÖ²úÆ·µÄÇåµ¥ £¬ÕâЩ²úÆ·½«ÔÚ 3 Ôµ×ÖÕ³¡Ìṩ ¡£ÒÑ Ã÷È· £¬Ðí¿É֤ʧЧӰÏì¶íÂÞ˹´Óʹ¹Öþ¡¢Éè¼Æ¡¢Ê©¹¤¡¢Ôì×÷¡¢Ã½Ìå¡¢½ÌÓýºÍÓéÀÖ¡¢¹¹ÖþÐÅϢģÐÍ£¨BIM£©¡¢ÍÆËã»ú¸¨ÖúÉè¼Æ£¨CAD£©ºÍÍÆËã»ú¸¨ÖúÔì×÷µÄ¹«Ë¾ºÍ×éÖ¯£¨Í¹ÂÖ£© ¡£µ«ÊÇ £¬Ã»Óа䷢ÏÞ¶ÈÓ×ÎÒ½Ó¼ûµÄ´òËã £¬Òò¶øÈç¹ûÉÏÊö²úÆ·ÈԿɹ©Í¨³£Óû§Ê¹Óà ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-to-shut-down-50-cloud-services-for-russian-businesses/


4. SIGN1 ¶ñÒâÈí¼þ»î¶¯ÒÑϰȾ 39000 ¶à¸ö WORDPRESS ÍøÕ¾


3ÔÂ23ÈÕ £¬Sucuri µÄ Sucurity ×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÃûΪ Sign1 µÄ¶ñÒâÈí¼þ»î¶¯ £¬¸Ã»î¶¯ÔÚ´ÓǰÁù¸öÔÂÄÚÒѾ­·çÏÕÁË 39,000 ¸ö WordPress ÍøÕ¾ ¡£×¨¼ÒÃÇ·¢ÏÖ £¬ÍþвÐÐΪÕßÈëÇÖÁËÍøÕ¾ £¬Ö²Èë¶ñÒâ JavaScript ×¢Èë £¬½«½Ó¼ûÕß³Á¶¨Ïòµ½¶ñÒâÍøÕ¾ ¡£Sign1 ±³ºóµÄÍþв²Î¼ÓÕß½«¶ñÒâ JavaScript ×¢ÈëºÏ·¨²å¼þºÍ HTML Óײ¿¼þÖÐ ¡£×¢ÈëµÄ´úÂëÔ̺¬Ò»¸öÓ²±àÂëµÄÊý×ÖÊý×é £¬ËüʹÓà XOR ±àÂëÀ´»ñÈ¡ÐÂÖµ ¡£×¨¼Ò¶Ô XOR ±àÂëµÄ JavaScript ´úÂë½øÐÐÏàʶÂë £¬·¢ÏÖËüÓÃÓÚÖ´ÐÐÔ¶³Ì·þÎñÆ÷ÉÏÍÐ¹ÜµÄ JavaScript Îļþ ¡£×êÑÐÈËÔ±°ÑÎȵ½ £¬¹¥»÷Õßѡȡ¶¯Ì¬¸ü¸ÄµÄ URL £¬¶¯Ì¬ JavaScript ´úÂëµÄʹÓÃÔÊÐíÿ 10 ·ÖÖÓ¸ü¸ÄÒ»´Î URL ¡£¸Ã´úÂëÔÚ½Ó¼ûÕßµÄä¯ÀÀÆ÷ÖÐÖ´ÐÐ £¬µ¼ÖÂÍøÕ¾½Ó¼ûÕß³öÏÖ²»±ØÒªµÄ³Á¶¨ÏòºÍ¸æ°× ¡£Sign1 »î¶¯×î³õÓÉ×êÑÐÔ±Denis SinegubkoÔÚ 2023 ÄêϰëÄê·¢ÏÖ £¬Sucuri »ã±¨³Æ £¬×Ô 2023 Äê 7 Ô 31 ÈÕÒÔÀ´ £¬ÍþвÐÐΪÕßÀûÓÃÁ˶à´ï 15 ¸ö·ÖÆçµÄÓò ¡£


https://securityaffairs.com/160942/hacking/sign1-malware-campaign.html


5. ÃÀ¹úµ±¾Ö°ä²¼Õë¶Ô¹«¹²²¿ÃŵÄРDDoS ¹¥»÷Ö¸ÄÏ


3ÔÂ22ÈÕ £¬ÃÀ¹úµ±¾ÖΪ¹«¹²²¿ÃÅʵÌå°ä²¼ÁËеÄÉ¢²¼Ê½»Ø¾ø·þÎñ (DDoS) ¹¥»÷Ö¸ÄÏ £¬ÒÔÔ®ÊÖÔ¤·À¹Ø¼ü·þÎñÖÐ¶Ï ¡£¸ÃÎļþÖ¼ÔÚ×÷Ϊ×ۺϻïÔ´ £¬½â¾öÁª¹ú¡¢Öݺʹ¦Ëùµ±¾Ö»ú¹¹ÔÚ·ÀÓù DDoS ¹¥»÷·½ÃæÃæ¶ÔµÄ¾ßÌåÐèÒªºÍÌôÕ½ ¡£¸Ã´«µÝÖ¸³ö £¬DDoS ¹¥»÷ÊÇÖ¸´óÁ¿ÊÜϰȾµÄÍÆËã»úÏòÖ¸±êϵͳ·¢ËÍ´óÁ¿Á÷Á¿»òÒªÇó £¬µ¼ÖÂÓû§ÎÞ·¨Ê¹Óøù¥»÷ £¬ÕâÖÖ¹¥»÷ºÜÄÑ×·×ÙºÍ×èÖ¹ ¡£ÕâÖÖý½éͨ³£±»³öÓÚÕþÖζ¯»úµÄ¹¥»÷ÕßʹÓà £¬Ô̺¬ºÚ¿Í»î¶¯·Ö×ÓºÍÃñ×å¹ú¶È¼¯Ìå £¬µ±¾ÖÍøÕ¾Ê±Ê±³ÉΪ¹¥»÷Ö¸±ê ¡£ÀýÈç £¬×Ô 2022 Äê 2 Ô¿ËÀïÄ·ÁÖ¹¬ÈëÇָùúÒÔÀ´ £¬Óë¶íÂÞ˹ºÍÎÚ¿ËÀ¼ÓйصĺڿÍʱʱʹÓà DDoS ¹¥»÷¶Ô·½µ±¾ÖÍøÕ¾ ¡£2023 Äê 10 Ô £¬Ó¢¹úÍõÊÒ¹Ù·½ÍøÕ¾Òò DDoS ÊÂÎñ¶øÏÂÏß £¬¶íÂÞ˹ºÚ¿Í×éÖ¯ Killnet Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü ¡£


https://www.infosecurity-magazine.com/news/us-ddos-attack-guidance-public/?&web_view=true


6. ¶íÂÞ˹ºÚ¿ÍÀûÓà WineLoader ¶ñÒâÈí¼þ¶Ô×¼µÂ¹úÕþµ³


3ÔÂ23ÈÕ £¬×êÑÐÈËÔ±ÖÒ¸æ³Æ £¬Óë¶íÂÞ˹¶Ô±íµý±¨¾Ö£¨SVR£©ÓÐÁªÏµµÄºÚ¿Í×éÖ¯³õ´ÎÕë¶ÔµÂ¹úÕþµ³ £¬½«Æä½¹µã´ÓµäÐÍµÄ±í½»Ê¹ÍÅÖ¸±ê×ªÒÆ¿ª ¡£ÍøÂç´¹µö¹¥»÷Ö¼ÔÚ²¿ÊðÃûΪ WineLoader µÄºóÃŶñÒâÈí¼þ £¬¸Ã¶ñÒâÈí¼þÔÊÐíÍþвÐÐΪÕßÔ¶³Ì½Ó¼ûÊÜϰȾµÄÉ豸ºÍÍøÂç ¡£APT29£¨Ò²³ÆÎª Midnight Blizzard¡¢NOBELIUM¡¢Cozy Bear£©ÊÇÒ»¸ö¶íÂÞ˹¼äµýºÚ¿Í×éÖ¯ ¡£¸ÃºÚ¿Í×éÖ¯ÓëºÜ¶àÍøÂç¹¥»÷ÓÐ¹Ø £¬Ô̺¬ 2020 Äê 12 Ô³ôÃûÔ¶ÑïµÄSolarWinds ¹©¸øÁ´¹¥»÷ ¡£ÕâЩÄêÀ´ £¬ÍþвÐÐΪÕßÒ»Ïòά³Ö»îÔ¾ £¬Í¨³£Ê¹ÓÃһϵÁÐÍøÂç´¹µöÕ½Êõ»ò¹©¸øÁ´Í×ЭÀ´Õë¶Ôµ±¾Ö¡¢´óʹ¹Ý¡¢¸ß¼¶¹ÙÔ±ºÍ¸÷ÀàʵÌå ¡£APT29 ×î½üµÄ³ÁµãÊÇÔÆ·þÎñ £¬·ÛËé Microsoft ϵͳ²¢ÇÔÈ¡ Exchange ÕÊ»§µÄÊý¾Ý £¬²¢·ÛËéHewlett Packard EnterpriseʹÓÃµÄ MS Office 365 µç×ÓÓʼþ»·¾³ ¡£


https://www.bleepingcomputer.com/news/security/russian-hackers-target-german-political-parties-with-wineloader-malware/