Magnet Goblin ºÚ¿Í×éÖ¯ÀûÓ÷ì϶²¿Êð Nerbian RAT
°ä²¼¹¦·ò 2024-03-123ÔÂ11ÈÕ£¬£¬£¬£¬£¬Ò»¸öÃûΪMagnet GoblinµÄ³öÓÚ¾¼Ã¶¯»úµÄÍþвÐÐΪÕßÔÚѸËÙ½«1day°²È«·ì϶ÄÉÈëÆä±øÆ÷¿â£¬£¬£¬£¬£¬ÒÔ±ãËÅ»ú·ÛËé±ßÔµÉ豸ºÍÃæÏò¹«¼ÒµÄ·þÎñ£¬£¬£¬£¬£¬²¢ÔÚÊÜϰȾµÄÖ÷»úÉϲ¿Êð¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£µÐÊÖÌáÒéµÄ¹¥»÷ÀûÓÃ佨²¹µÄ Ivanti Connect Secure VPN¡¢Magento¡¢Qlik Sense ÒÔ¼°¿ÉÄÜµÄ Apache ActiveMQ ·þÎñÆ÷×÷Ϊ³õʼϰȾý½éÀ´»ñµÃδ¾ÊÚȨµÄ½Ó¼û¡£¡£¡£¡£¡£¡£¡£¡£¾Ý³Æ¸Ã×éÖ¯ÖÁÉÙ×Ô 2022 Äê 1 ÔÂÆð¾ÍÒ»Ïò»îÔ¾¡£¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶ºó£¬£¬£¬£¬£¬»á²¿ÊðÒ»¸öÃûΪ Nerbian RAT µÄ¿çƽ̨Զ³Ì½Ó¼ûľÂí (RAT)£¬£¬£¬£¬£¬¸ÃľÂíÓÉ Proofpoint ÓÚ 2022 Äê 5 Ô³õ´ÎÅû¶£¬£¬£¬£¬£¬Æä¼ò»¯±äÖÖΪ MiniNerbian¡£¡£¡£¡£¡£¡£¡£¡£DarktraceÖ®Ç°ÔøÇ¿µ÷¹ý Linux °æ±¾ Nerbian RAT µÄʹÓᣡ£¡£¡£¡£¡£¡£¡£ÕâÁ½ÖÖ²¡¶¾¶¼ÔÊÐíÖ´ÐдӺÅÁîÓë½ÚÔì (C2) ·þÎñÆ÷½Ó¹ÜµÄËÁÒâºÅÁ£¬£¬£¬£¬²¢Ð¹Â¶·µ»Ø¸øËüµÄÁ˾֡£¡£¡£¡£¡£¡£¡£¡£Magnet Goblin ʹÓÃµÄÆäËûһЩ¹¤¾ßÔ̺¬WARPWIRE JavaScript ƾ֤ÇÔÈ¡·¨Ê½¡¢»ùÓÚ Go µÄËí·Èí¼þ Ligolo£¬£¬£¬£¬£¬ÒÔ¼°ºÏ·¨µÄÔ¶³Ì×ÀÃæ²úÆ·£¨ÀýÈç AnyDesk ºÍ ScreenConnect£©¡£¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2024/03/magnet-goblin-hacker-group-leveraging-1.html
2. Õë¶ÔÃÀ¹úºÍÅ·ÖÞÆóÒµµÄРDoNex ÀÕË÷Èí¼þ
3ÔÂ11ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úºÍÅ·ÖÞ¸÷µØµÄÆóÒµ¶¼´¦Óڸ߶Ⱦ¯Ìè״̬£¬£¬£¬£¬£¬ÓÉÓÚÒ»ÖÖ±»³ÆÎª¡°DoNex¡±µÄÐÂÐÍÀÕË÷Èí¼þÒ»ÏòÔÚ»ý¼«·çÏÕÆóÒµ²¢Ðû³ÆÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£¡£¶ÔÓÚÕâÖÖÍ»·¢Íþв£¬£¬£¬£¬£¬ÍøÂ簲ȫר¼Ò¼Ó°à¼ÓµãµØÏàʶ¹¥»÷µÄÈ«ÊýÁìÓò²¢Ôì¶©¶Ô²ß¡£¡£¡£¡£¡£¡£¡£¡£DoNex ÀÕË÷Èí¼þ×é֯ͨ¹ýÔÚÆä°µÍøÃÅ»§£¨¿Éͨ¹ý Onion ÍøÂç½Ó¼û£©´ó½«¶à¼Ò¹«Ë¾ÁÐΪÊܺ¦Õß¶øÎÅÃû¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïµÄ¼¿Á©ÓÈΪÒõÏÕ£¬£¬£¬£¬£¬Ñ¡È¡Ë«³ÁÀÕË÷¼¿Á©¡£¡£¡£¡£¡£¡£¡£¡£Õâ²»½öÉæ¼°Îļþ¼ÓÃÜ£¬£¬£¬£¬£¬¶øºó¸½¼ÓÒ»¸öΨһµÄ¡£¡£¡£¡£¡£¡£¡£¡£VictimID À©´ó£¬£¬£¬£¬£¬²¢ÇÒ»¹»áй¼ûô¸ÐÊý¾Ý£¬£¬£¬£¬£¬½«Æä×÷ΪÈËÖÊ£¬£¬£¬£¬£¬ÒÔÏòÊܺ¦ÕßÊ©¼Ó¶î±íѹÁ¦£¬£¬£¬£¬£¬ÒªÇóÆäÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¹«Ë¾ÔÚÆäϵͳÉÏ·¢ÏÖÁËÃûΪ Readme.VictimID.txt µÄÀÕË÷×ÖÌõ£¬£¬£¬£¬£¬¸Ã×ÖÌõÅúʾËûÃÇͨ¹ý Tox Messenger Óë DoNex ×éÖ¯³ÉÁ¢ÁªÏµ£¬£¬£¬£¬£¬Tox Messenger ÊÇÒ»ÖÖµã¶Ôµã¼´Ê±ÐÂÎÅ·þÎñ£¬£¬£¬£¬£¬ÒÔÆä°²È«ºÍÄäÃûÖ°ÄܶøÎÅÃû¡£¡£¡£¡£¡£¡£¡£¡£
https://gbhackers.com/donex-ransomware-observed/
3. ¼Ù×°³É Notion ×°Ö÷¨Ê½µÄ MSIX ¶ñÒâÈí¼þ
3ÔÂ11ÈÕ£¬£¬£¬£¬£¬¼Ù×°³É Notion ×°Ö÷¨Ê½µÄ MSIX ¶ñÒâÈí¼þÔÚ·Ö·¢¡£¡£¡£¡£¡£¡£¡£¡£·Ö·¢ÍøÕ¾¿´ÆðÀ´ÓëÏÖʵµÄ Notion Ö÷Ò³ÀàËÆ¡£¡£¡£¡£¡£¡£¡£¡£×°Öú󣬣¬£¬£¬£¬StartingScriptWrapper.ps1 ºÍrefresh.ps1 Îļþ½«ÔÚÀûÓ÷¨Ê½µÄõè¾¶ÄÚ´´½¨¡£¡£¡£¡£¡£¡£¡£¡£StartingScriptWrapper.ps1 ÎļþÊÇÒ»¸öºÏ·¨Îļþ£¬£¬£¬£¬£¬Ô̺¬ MS ÊðÃû£¬£¬£¬£¬£¬ÓµÓÐÖ´ÐÐ×÷Ϊ²ÎÊý¸ø³öµÄ Powershell ¾ç±¾µÄÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎļþÔÊÐíÔÚ×°Öùý³ÌºÍÖ´ÐÐÌØ¶¨ Powershell ¾ç±¾ÆÚ¼ä¶ÁÈ¡°üÄÚµÄ config.json ÅäÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£¡£´ËºÅÁî´Ó C2 ·þÎñÆ÷ÏÂÔØ¸½¼Ó Powershell ºÅÁî²¢Ö´ÐÐËüÃÇ¡£¡£¡£¡£¡£¡£¡£¡£C2·þÎñÆ÷ĿǰûÓÐÕýÈ·ÏìÓ¦£¬£¬£¬£¬£¬µ«·ÖÎöÍŶÓÔÚ³õ²½·ÖÎöÆÚ¼äÈ·ÈÏÁËLummaC2¶ñÒâÈí¼þµÄÉ¢²¼¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÔËÐÐÎļþ֮ǰ£¬£¬£¬£¬£¬Óû§Ó¦¸Ã²é³ÎļþÊÇ·ñÀ´×Ô¹Ù·½ÍøÕ¾µÄÓò£¬£¬£¬£¬£¬¼´±ãÎļþÊÇʹÓúϷ¨Ö¤ÊéÊðÃûµÄ£¬£¬£¬£¬£¬Ò²Òª²é³ÊðÃû×÷Õß¡£¡£¡£¡£¡£¡£¡£¡£½¨ÒéÔÚÖ´ÐÐ MSIX Îļþʱ¸ñ±íÓ×ÐÄ£¬£¬£¬£¬£¬ÓÉÓÚ¶àÖÖ¶ñÒâ±äÌå²»½ö»á¼Ù×° Notion£¬£¬£¬£¬£¬»¹»á¼Ù×° Slack¡¢WinRar ºÍ Bandicam µÅצÓ÷¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£
https://asec.ahnlab.com/en/62815/
4. ÈÕ±¾½« PyPI ¹©¸øÁ´ÍøÂç¹¥»÷¹é×ïÓÚ³¯ÏÊ
3ÔÂ11ÈÕ£¬£¬£¬£¬£¬ÈÕ±¾ÍøÂ簲ȫ¹ÙÔ±ÖÒ¸æ³Æ£¬£¬£¬£¬£¬³¯ÏʳôÃûÔ¶ÑïµÄ Lazarus Group ºÚ¿ÍÍŶÓ×î½üÕë¶Ô Python ÀûÓ÷¨Ê½µÄ PyPI Èí¼þ´æ´¢¿â·¢ÆðÁ˹©¸øÁ´¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Íþв²Î¼ÓÕßÉÏ´«ÁËÃûΪ¡°pycryptoenv¡±ºÍ¡°pycryptoconf¡±µÈÊÜ´«È¾µÄ°ü£¬£¬£¬£¬£¬ÆäÃû³ÆÓëºÏ·¨µÄ Python ¼ÓÃܹ¤¾ß°ü¡°pycrypto¡±ÀàËÆ¡£¡£¡£¡£¡£¡£¡£¡£±»ÓÕÆ½«¶ñÒâÈí¼þ°üÏÂÔØµ½ Windows ÍÆËã»úÉϵĿª·¢ÈËÔ±»áϰȾһÖÖÃûΪ Comebacker µÄΣÏÕÌØÂåÒÁľÂí¡£¡£¡£¡£¡£¡£¡£¡£Gartner ¸ß¼¶×Ü¼à¼æ·ÖÎöʦ Dale Gardner ½« Comebacker ÃèÊöΪһÖÖͨÓÃľÂí£¬£¬£¬£¬£¬ÓÃÓÚͶ·ÅÀÕË÷Èí¼þ¡¢ÇÔȡƾ֤ºÍÉøÈ뿪·¢Á÷³Ì¡£¡£¡£¡£¡£¡£¡£¡£Comebacker Òѱ»²¿ÊðÔÚÓ볯ÏÊÓÐ¹ØµÄÆäËûÍøÂç¹¥»÷ÖУ¬£¬£¬£¬£¬Ô̺¬¶Ô npm Èí¼þ¿ª·¢´æ´¢¿âµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
https://www.darkreading.com/application-security/japan-blames-north-korea-for-pypi-supply-chain-cyberattack
5. ºÚ¿ÍÀûÓà WordPress ²å¼þȱµãÓöñÒâÈí¼þϰȾ 3300 ¸öÍøÕ¾
3ÔÂ10ÈÕ£¬£¬£¬£¬£¬ºÚ¿ÍÀûÓà Popup Builder ²å¼þ¹ýÆÚ°æ±¾Öеķì϶ÈëÇÖ WordPress ÍøÕ¾£¬£¬£¬£¬£¬ÓöñÒâ´úÂëϰȾ 3,300 ¶à¸öÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÖÐÀûÓõÄȱµã±»×·×ÙΪ CVE-2023-6000£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öÓ°Ïì Popup Builder °æ±¾ 4.2.3 ¼°¸üÔç°æ±¾µÄ¿çÕ¾µã¾ç±¾ (XSS) ·ì϶£¬£¬£¬£¬£¬×î³õÓÚ 2023 Äê 11 ÔÂÅû¶¡£¡£¡£¡£¡£¡£¡£¡£½ñÄêËêÊ×·¢ÏÖµÄ Balada Injector »î¶¯ÀûÓøÃÌØ¶¨·ì϶ϰȾÁË 6,700 ¶à¸öÍøÕ¾£¬£¬£¬£¬£¬ÕâÅú×¢ºÜ¶àÍøÕ¾ÖÎÀíԱûÓÐ×ã¹»¿ìµØ½¨²¹²¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£Sucuri ´Ë¿Ì »ã±¨ ·¢ÏÖÒ»¸öеĻÔÚ´ÓǰÈýÖÜÄÚÏÔ×ÅÔö³¤£¬£¬£¬£¬£¬Õë¶ÔµÄÊÇ WordPress ²å¼þÉϵÄÒ»Ñù·ì϶¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý PublicWWW µÄÁ˾֣¬£¬£¬£¬£¬ÔÚ3,329 ¸ö WordPress ÍøÕ¾Öз¢ÏÖÁËÓëÕâÒ»×îлÓйصĴúÂë×¢Èë £¬£¬£¬£¬£¬Sucuri ×Ô¼ºµÄɨÃèÒǼì²âµ½ÁË 1,170 ¸öϰȾ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-wordpress-plugin-flaw-to-infect-3-300-sites-with-malware/
6. ÔóÎ÷µº½ðÈÚ·þÎñίԱ»áµÄÊý¾Ýй¶
3ÔÂ7ÈÕ£¬£¬£¬£¬£¬ÔóÎ÷µº½ðÈÚ·þÎñίԱ»áµÄÊý¾Ýй¶µ¼Ö·ǹ«¿ªÐÕÃûºÍµØÖ·µÄ½Ó¼û¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÓÚ 1 Ô 23 ÈÕÈ·ÈÏÆä×¢²áϵͳÖмì²âµ½Ò»¸ö¡°·ì϶¡±¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬Õâ´ÎйÃÜÊÂÎñ²¢Î´½«ÈκÎÓ×ÎÒÓë×¢²áʵÌå»òËùµ£ÈεĽÇÉ«ÁªÏµÆðÀ´£¬£¬£¬£¬£¬²¢ÇÒÒѵ¥¶ÀдПøÄÇЩÐÕÃûºÍµØÖ·±»Ð¹Â¶µÄÈË¡£¡£¡£¡£¡£¡£¡£¡£³õ²½·¨Ò½Éó²é·¢ÏÖй©ÊÇÓÉÓÚµÚÈý·½ÌṩµÄ×¢²áϵͳÅäÖÃÃýÎóÔì³ÉµÄ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯°µÊ¾£º¡°ÎÒÃǶԲúÉúÕâÖÖÇé¿öÉî¸ÐÒź¶£¬£¬£¬£¬£¬Ä¿Ç°ÔÚ½øÒ»´ëÊ©²éÒÔÈ·¶¨ÕâÊÇÈôºÎ²úÉúµÄ¡£¡£¡£¡£¡£¡£¡£¡£¡±JFSC °µÊ¾ÔÚÓëÔóÎ÷µºÐÅϢרԱ°ì¹«ÊÒºÏ×÷¡£¡£¡£¡£¡£¡£¡£¡£ÕƹܽðÈÚ·þÎñµÄ¸±²¿³¤ÒÁ¶÷¡¤¸êË¹ÌØ°µÊ¾£¬£¬£¬£¬£¬Õâ´Îй¶ӰÏìÁËϵͳÖÓ×°ÓÐÏÞÊýÁ¿µÄÌõ¿î¡±¡£¡£¡£¡£¡£¡£¡£¡£Ëû²¹³ä·£º¡°ÎÒ¶Ô²úÉúÕâÒ»ÃýÎó¸ÐÓ¦±§À¢£¬£¬£¬£¬£¬ÎÒÏàʶ½áºÏ½ðÈÚ·þÎñίԱ»áÔÚ½øÐÐ×î³¹µ×µÄµ÷²é£¬£¬£¬£¬£¬ÒÔÈ·±£ÂÞÖ½Ìѵ£¬£¬£¬£¬£¬²¢¸Ä½øºÍ¼ÓÇ¿µÇ¼Ç²áµÄÉè¼Æ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bbc.com/news/articles/cnk5zyypw24o?&web_view=true


¾©¹«Íø°²±¸11010802024551ºÅ