Á¢ÌÕÍð¶à¸ö×éÖ¯µÄÍøÕ¾Ôâµ½KillnetÍÅ»ïµÄDDoS¹¥»÷
°ä²¼¹¦·ò 2022-06-301¡¢Á¢ÌÕÍð¶à¸ö×éÖ¯µÄÍøÕ¾Ôâµ½KillnetÍÅ»ïµÄDDoS¹¥»÷
¾ÝýÌå6ÔÂ28ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬Á¢ÌÕÍðµÄ¹ú¶È˰Îñ¼à²ì¾Ö(STI)ºÍ¹ÜÕÊ·þÎñÌṩÉÌB1.ltµÈ¶à¸ö×éÖ¯Ôâµ½ÁËKillnetÍÅ»ïµÄDDoS¹¥»÷¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚ6ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ(NKSC)֤ʵ£¬£¬£¬£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñÓ°ÏìÁ˹ú¶È°²È«Êý¾Ý´«ÊäÍøÂçÒÔ¼°Ë½ÓªºÍ¹«¹²²¿ÃŵÄ×éÖ¯¡£¡£¡£¡£¡£²¢°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ÕâÖÖ¹¥»÷ºÜ¿ÉÄÜ»á³ÖÐø¼¸Ì죬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÊÇÕë¶ÔͨѶ¡¢ÄÜÔ´ºÍ½ðÈÚÁìÓò¡£¡£¡£¡£¡£KillnetÔÚÒ»¶ÎÊÓÆµÖÐÐû³Æ¶Ô´ËÊÂÕÆ¹Ü£¬£¬£¬£¬£¬£¬£¬£¬²¢²¹³ä˵ËûÃÇÒѾ¹¥»÷ÁË1652¸öÍøÂç×ÊÔ´£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ39Ó×ʱÄÚʵÏÖÁ˶Կ¹ÌÕÍð70%µÄÍøÂç»ù´¡ÉèÊ©µÄ¸ôÀë¡£¡£¡£¡£¡£
https://www.hackread.com/russia-killnet-group-lithuania-sites-ddos-attacks/
2¡¢Service Fabric´æÔÚ·ì϶FabricScape£¨CVE-2022-30137)
6ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Unit 42Åû¶ÁË΢ÈíService FabricÖеķì϶FabricScape£¨CVE-2022-30137)µÄÏêÇé¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚÕï¶ÏÍøÂç´úÀí(DCA)×é¼þÖУ¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚÅäÖÃΪӵÓÐÔËÐÐʱ½Ó¼ûȨÏÞµÄÈÝÆ÷Éϱ»ÀûÓ㬣¬£¬£¬£¬£¬£¬£¬¹ÌÈ»´æÔÚÓÚÁ½¸ö²Ù×÷ϵͳƽ̨ÉÏ£¬£¬£¬£¬£¬£¬£¬£¬µ«Ö»ÄÜÔÚLinuxÉϱ»ÀûÓᣡ£¡£¡£¡£Î¢Èíй©³Æ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿É±»ÓÃÀ´ÌáȨ£¬£¬£¬£¬£¬£¬£¬£¬²¢»ñµÃ¶Ô×ÊÔ´Ö÷»úSF½ÚµãºÍÕû¸ö¼¯ÈºµÄ½ÚÔìȨ¡£¡£¡£¡£¡£6ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÒÑÔÚService Fabric 9.0ÀÛ»ý¸üÐÂÖеõ½½¨¸´¡£¡£¡£¡£¡£
https://unit42.paloaltonetworks.com/fabricscape-cve-2022-30137/
3¡¢Zscaler·¢ÏÖEvilnumÍÅ»ï»Ø¹é²¢Õë¶ÔÓ¢¹úºÍÅ·ÖÞµØÓò
ZscalerÔÚ6ÔÂ27Èճƣ¬£¬£¬£¬£¬£¬£¬£¬EvilnumÍÅ»ïÒѾ»Ø¹é£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ¹¥»÷»î¶¯ÖÐʹÓÃÁËеÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½¡£¡£¡£¡£¡£½ñÄê3Ô£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÔìäÖ¸±êÑ¡ÔñÓгÁ´ó¸Ä¹Û£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÔÀ´µÄ½ðÈڿƼ¼ÁìÓòµÄ×é֯ת±äΪ´¦Öùú¼ÊÒÆÃñ·þÎñÈ·µ±¾ÐÄä×éÖ¯¡£¡£¡£¡£¡£¹¥»÷ʹÓõĵö¶üÎļþͨ³£¶¼Ô̺¬ºÏ¹æ£¨compliance£©Ò»´Ê£¬£¬£¬£¬£¬£¬£¬£¬ÆäÄ£°å×¢Èë½×¶ÎʹÓõĻùÓÚºêµÄÎĵ·ûÓÃÁËVBA code stomping¼¼ÊõÀ´Èƹý¾²Ì¬·ÖÎö²¢Ô¤·ÀÄæÏò¹¤³Ì£¬£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÑϳÁ»ìºÏµÄJavaScriptÀ´½âÃܲ¢×°ÖÃpayload¡£¡£¡£¡£¡£
https://www.zscaler.com/blogs/security-research/return-evilnum-apt-updated-ttps-and-new-targets
4¡¢Cyble³ÆÓг¬¹ý90Íò¸öÅäÖÃÃýÎóµÄKubernetes¶³öÔÚÍøÉÏ
¾Ý6ÔÂ29ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬CybleµÄÒ»Ïî·ÖÎö·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬Óг¬¹ý900000¸öKubernetes¶³öÔÚÍøÉÏ¡£¡£¡£¡£¡£KubernetesÊÇÒ»¸ö¸ß¶ÈͨÓõĿªÔ´ÈÝÆ÷±àÅÅϵͳ£¬£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÅäÖò»ÕýÈ·£¬£¬£¬£¬£¬£¬£¬£¬¿É±»Ô¶³Ì¹¥»÷Õß½Ó¼ûÄÚ²¿×ÊÔ´ºÍ˽ÓÐ×ʲú¡£¡£¡£¡£¡£×êÑÐÈËԱʹÓÃÓë¹¥»÷ÕßÀàËÆµÄɨÃ蹤¾ßºÍËÑË÷²éÎÊÀ´¶¨Î»Â¶³öµÄKubernetesÊ·ý£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÔìäÖÐ65%£¨585000̨£©Î»ÓÚÃÀ¹ú£¬£¬£¬£¬£¬£¬£¬£¬9%λÓڵ¹ú£¬£¬£¬£¬£¬£¬£¬£¬¶øºÉÀ¼ºÍ°®¶ûÀ¼¸÷Õ¼6%£»£»£»£»£»£»£»Â¶³ö×î¶àµÄTCP¶Ë¿ÚÊÇ443£¬£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊǶ˿Ú10250ºÍ6443¡£¡£¡£¡£¡£
https://www.infosecurity-magazine.com/news/misconfigured-kubernetes-exposed/
5¡¢ÐÂľÂíZuoRATÖØÒªÕë¶ÔλÓÚ±±ÃÀºÍÅ·ÖÞµÄSOHO·ÓÉÆ÷
Lumen Black Lotus LabsÔÚ6ÔÂ28ÈÕй©£¬£¬£¬£¬£¬£¬£¬£¬×Ô2020ÄêÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬ÐµĶ༶Զ³Ì½Ó¼ûľÂíZuoRATÒѱ»ÓÃÓÚͨ¹ýλÓÚ±±ÃÀºÍÅ·ÖÞµÄSOHO·ÓÉÆ÷¹¥»÷Ô¶³Ì¹¤×÷ÈËÔ±¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈͨ¹ýɨÃèÒÑÖªµÄ佨²¹·ì϶¶Ô·ÓÉÆ÷µÄ½øÐгõʼ½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬¶øºó×°ÖÃCobalt Strike beacons£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°2¸ö×Ô½ç˵ºóÃÅ£º»ùÓÚC++µÄCBeacon£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔWindowsϵͳ£»£»£»£»£»£»£»»ùÓÚGoµÄGoBeacon£¬£¬£¬£¬£¬£¬£¬£¬Õë¶ÔLinuxºÍMacϵͳ¡£¡£¡£¡£¡£ZuoRAT»¹Äܹ»¼à¿ØDNSºÍHTTPSÁ÷Á¿£¬£¬£¬£¬£¬£¬£¬£¬À´½Ù³ÖÒªÇó²¢Ê¹ÓÃÌìÉúµÄÔ¤Éè¹æ¶¨½«Ö¸±ê³Á¶¨Ïòµ½¶ñÒâÓò£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ×ÌÈÅȡ֤·ÖÎö¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-zuorat-malware-targets-soho-routers-in-north-america-europe/
6¡¢Symantec°ä²¼¹ØÓÚ¼ÓÔØ·¨Ê½BumblebeeµÄ·ÖÎö»ã±¨
6ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Symantec°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þ¼ÓÔØ·¨Ê½BumblebeeµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£Í¨¹ý¶ÈÎö×î½üÉæ¼°BumblebeeµÄ¹¥»÷ÖÐʹÓÃµÄÆäËüÈý¸ö¹¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±½«ÆäÓëConti¡¢QuantumºÍMountlocker ÔÚÄڵĺܶàÀÕË÷ÍÅ»ïÁªÏµÆðÀ´¡£¡£¡£¡£¡£Æ¾¾ÝÕâЩ½ÏÔçµÄ¹¥»÷ÖÐʹÓõÄTTPs´§Ä¦£¬£¬£¬£¬£¬£¬£¬£¬Bumblebee¿ÉÄÜÊÇ×÷ΪTrickbotºÍBazarLoaderµÄ´úÌæ¼ÓÔØ·¨Ê½ÍƳöµÄ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ±»µ÷²éµÄ¹¥»÷µÄÁíÒ»¸ö¹²Í¬µãÊǺϷ¨Èí¼þʹÓõÄÔö³¤£¬£¬£¬£¬£¬£¬£¬£¬ConnectWise¡¢Atera¡¢SplashtopºÍAnyDeskµÈÔ¶³Ì×ÀÃæ¹¤¾ßʱʱ³Ê´Ë¿Ì´ËÀ๥»÷ÖС£¡£¡£¡£¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/bumblebee-loader-cybercrime


¾©¹«Íø°²±¸11010802024551ºÅ