APT36ͨ¹ý¶à¸öαÔìµÄYouTube APK·Ö·¢CapraRAT

°ä²¼¹¦·ò 2023-09-20

1¡¢APT36ͨ¹ý¶à¸öαÔìµÄYouTube APK·Ö·¢CapraRAT


SentinelLabsÔÚ9ÔÂ18ÈÕ¹«¿ªÁËAPT36£¨ÓÖ³ÆTransparent Tribe£©Ê¹ÓÃÁËÖÁÉÙ3¸öαÔì³ÉYouTubeµÄAndroidÀûÓ÷¨Ê½°ü(APK)·Ö·¢CapraRATµÄ»î¶¯¡£¡£¡£¡£¡£¶ñÒâÈí¼þÒ»µ©×°ÖÃÔÚÖ¸±êÉ豸ÉÏ£¬ £¬£¬£¬£¬ £¬£¬¾ÍÄܹ»ÍøÂçÊý¾Ý¡¢¼Í¹àÒôƵ»òÊÓÆµÒÔ¼°½Ó¼ûͨѶÐÅÏ¢£¬ £¬£¬£¬£¬ £¬£¬ÐÔÖʾÍÏñ¼äµýÈí¼þÒ»Ñù¡£¡£¡£¡£¡£¶ñÒâAPKÔÚGoogle PlayÖ®±í·Ö·¢£¬ £¬£¬£¬£¬ £¬£¬Òò¶ø¿ÉÄÜÊÇͨ¹ýÉ繤¹¥»÷½øÐзַ¢¡£¡£¡£¡£¡£ÕâЩAPKÓÚ2023Äê4Ô¡¢7ÔºÍ8ÔÂÉÏ´«µ½VirusTotal£¬ £¬£¬£¬£¬ £¬£¬ÆäÖÐÁ½¸öÃûΪ¡°YouTube¡±£¬ £¬£¬£¬£¬ £¬£¬Ò»¸ö±»³ÆÎª¡°Piya Sharma¡±¡£¡£¡£¡£¡£


https://www.sentinelone.com/labs/capratube-transparent-tribes-caprarat-mimics-youtube-to-hijack-android-phones/


2¡¢TrendMicro½¨¸´Òѱ»ÀûÓõÄRCE·ì϶CVE-2023-41179


¾ÝýÌå9ÔÂ19ÈÕ±¨Â·£¬ £¬£¬£¬£¬ £¬£¬Trend Micro½¨¸´ÁËApex One¶Ëµã±£»£»£»£»£»£»¤½â¾ö¹æ»®ÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-41179£©¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚ°²È«Èí¼þ¸½´øµÄµÚÈý·½Ð¶ÔØ·¨Ê½Ä£¿£¿£¿£¿£¿£¿£¿£¿éÖУ¬ £¬£¬£¬£¬ £¬£¬ÖµÍ×ÌùÐĵÄÊǹ¥»÷Õß±ØÐëÏÈ»ñµÃÖ¸±êϵͳÉϵÄÖÎÀí½ÚÔį̀½Ó¼ûȨÏÞÄÜÁ¦ÀûÓô˷ì϶¡£¡£¡£¡£¡£Trend Micro³ÆÒѹ۲쵽ÖÁÉÙÓÐÒ»´ÎÕë¶Ô´Ë·ì϶µÄ¹¥»÷»î¶¯£¬ £¬£¬£¬£¬ £¬£¬Ç¿ÁÒ½¨ÒéÓû§¾¡¿ì¸üе½×îа汾¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/trend-micro-fixes-endpoint-protection-zero-day-used-in-attacks/


3¡¢Earth LuscaÀûÓÃSprySOCKSÕë¶Ô¶à¸ö¹ú¶ÈµÄ¹Ù·½ÍøÕ¾


9ÔÂ18ÈÕ£¬ £¬£¬£¬£¬ £¬£¬×êÑÐÈËÔ±³ÆÆä·¢ÏÖÁËEarth LuscaÀûÓÃеÄLinuxºóÃÅSprySOCKSµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£·ÖÎöÅú×¢£¬ £¬£¬£¬£¬ £¬£¬¸ÃºóÃÅÔ´×Ô¿ªÔ´Windows¶ñÒâÈí¼þTrochilus£¬ £¬£¬£¬£¬ £¬£¬ÆäºÜ¶àÖ°Äܱ»ÒÆÖ²µ½LinuxϵͳÉÏ£¬ £¬£¬£¬£¬ £¬£¬C2ͨѶºÍ̸ÀàËÆÓÚWindowsºóÃÅRedLeaves£¬ £¬£¬£¬£¬ £¬£¬½»»¥Ê½shellµÄʵÏÖÔ´×ÔLinux¶ñÒâÈí¼þDerusbi¡£¡£¡£¡£¡£¸Ã»î¶¯ÀûÓÃNday·ì϶װÖÃCobalt Strike beacon£¬ £¬£¬£¬£¬ £¬£¬¶øºó·Ö·¢SprySOCKS¼ÓÔØ·¨Ê½¡£¡£¡£¡£¡£Earth LuscaÔÚ½ñÄêÉϰëÄêÖØÒªÕë¶Ô¶«ÄÏÑÇ¡¢ÖÐÑÇ¡¢°Í¶û¸ÉµÈµØµÄ±í½»ÊÂÎñ¡¢¼¼ÊõºÍµçÐÅÓйصĵÐÔÖʵÌå¡£¡£¡£¡£¡£


https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html


4¡¢¼ÓÄô󵱾ֺͽðÈÚµÈÁìÓòÔâNoName057(16)µÄDDoS¹¥»÷


¾Ý9ÔÂ18ÈÕ±¨Â·£¬ £¬£¬£¬£¬ £¬£¬¼ÓÄôóµÄ¶à¸öʵÌåÔâµ½ÁËNoName057(16)µÄDDoS¹¥»÷¡£¡£¡£¡£¡£¼ÓÄôóÍøÂçÖÐÐݵʾ£¬ £¬£¬£¬£¬ £¬£¬×Ô9ÔÂ13ÈÕÒÔÀ´£¬ £¬£¬£¬£¬ £¬£¬ÆäÏàʶ²¢ÏìÓ¦ÁËÕë¶Ô¼ÓÄô󵱾ÖÄÚ²¿ÒÔ¼°½ðÈÚºÍÔËÊ䲿ÃŵĶàÆðDDoS¹¥»÷»î¶¯¡£¡£¡£¡£¡£½ñÄê2Ô·Ý£¬ £¬£¬£¬£¬ £¬£¬¸ÃÖÐÐĹ۲쵽Õë¶ÔÆäËü¹ú¶ÈµÄÀàËÆDDoS¹¥»÷»î¶¯¡£¡£¡£¡£¡£NoName057(16)ͨ³£Ê¹Óý©Ê¬ÍøÂçÀ´¹¥»÷Ö¸±êµÄWeb·þÎñÆ÷£¬ £¬£¬£¬£¬ £¬£¬¶øºó¿äÒ«Æä¶ñÒâ»î¶¯¡£¡£¡£¡£¡£


https://www.cyber.gc.ca/en/alerts-advisories/distributed-denial-service-campaign-targeting-multiple-canadian-sectors


5¡¢SysdigÅû¶Õë¶Ô²»³£¼ûAWS·þÎñµÄ¹¥»÷»î¶¯AMBERSQUID


SysdigÓÚ9ÔÂ18ÈÕÅû¶ÁËÒ»ÖÖеÄÔÆÔ­Éú¼ÓÃܽٳֹ¥»÷»î¶¯AMBERSQUID¡£¡£¡£¡£¡£´Ë»î¶¯ÖØÒªÕë¶Ô²»³£ÓõÄAWS·þÎñ£¬ £¬£¬£¬£¬ £¬£¬ÀýÈçAWS Amplify¡¢AWS FargateºÍAmazon SageMaker¡£¡£¡£¡£¡£²»³£ÓÃÒâζ×Å´Ó°²È«½Ç¶ÈÀ´¿´ÕâЩ·þÎñʱʱ±»ºöÊÓ£¬ £¬£¬£¬£¬ £¬£¬¶øAMBERSQUID»î¶¯¿ÉÄÜ»áÈÃÖ¸±êÿÌìËðʧ³¬¹ý10000ÃÀÔª¡£¡£¡£¡£¡£¸Ã»î¶¯¿ÉÄÜÀûÓÃÔÆ·þÎñ£¬ £¬£¬£¬£¬ £¬£¬¶ø²»»á´¥·¢AWSºË×¼¸ü¶à×ÊÔ´µÄÒªÇ󡣡£¡£¡£¡£Sysdig°µÊ¾ËüÔÚ·ÖÎöÁËDocker HubÉϵÄ170Íò¸ö¾µÏñºó·¢ÏÖÁ˸û£¬ £¬£¬£¬£¬ £¬£¬²¢½«Æä¹éÒòÓÚÓ¡ÄáÓйصĹ¥»÷Õß¡£¡£¡£¡£¡£


https://sysdig.com/blog/ambersquid/


6¡¢Intel 471°ä²¼BumblebeeÀûÓÃ4shared WebDAVµÄ·ÖÎö


9ÔÂ15ÈÕ£¬ £¬£¬£¬£¬ £¬£¬Intel 471°ä²¼Á˹ØÓÚBumblebeeÀûÓÃ4shared WebDAVµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£BumblebeeÔÚÔÝÍ£Á½¸öÔºó£¬ £¬£¬£¬£¬ £¬£¬ÓÚ8Ôµ׸´Ô­ÔËÓª¡£¡£¡£¡£¡£ÕâÒ»ÂֻÆðÍ·ÓÚ9ÔÂ7ÈÕ£¬ £¬£¬£¬£¬ £¬£¬ÒÀ¸½¼Ù×°³ÉɨÃè¼þ¡¢·¢Æ±ºÍ֪ͨµÄÀ¬»øÓʼþÀ´ÓÕʹÊÕ¼þÈËÏÂÔØ¶ñÒ⸽¼þ¡£¡£¡£¡£¡£´óÎÞÊý¸½¼þÊÇLNKÎļþ£¬ £¬£¬£¬£¬ £¬£¬´ò¿ªºó»áÔÚÖ¸±êÍÆËã»úÆô¶¯Ò»ÏµÁкÅÁ £¬£¬£¬£¬ £¬£¬Ê×ÏÈÊÇʹÓÃ4shared¹²Ïí´æ´¢ÕÊ»§µÄÓ²±àÂëÍ´´¦ÔÚÍøÂçÇý¶¯Æ÷ÉÏ×°ÖÃWebDAVÎļþ¼Ð£¬ £¬£¬£¬£¬ £¬£¬×îÖÕ»áÏÂÔØÍйÜÔÚWebDAV·þÎñÆ÷ÉϵÄBumblebee¡£¡£¡£¡£¡£  


https://intel471.com/blog/bumblebee-loader-resurfaces-in-new-campaign