DINODASRAT LINUX ±äÖÖÕë¶ÔÈ«ÇòÓû§

°ä²¼¹¦·ò 2024-04-02
1. DINODASRAT LINUX ±äÖÖÕë¶ÔÈ«ÇòÓû§


3ÔÂ31ÈÕ,¿¨°Í˹»ù³¢ÊÔÊÒµÄ×êÑÐÈËÔ±·¢ÏÖÁË Linux °æ±¾µÄ¶àƽ̨ºóÃÅ DinodasRAT£¬£¬ £¬£¬£¬£¬£¬£¬¸ÃºóÃű»ÓÃÓÚÕë¶ÔÖйú¡¢ÍÁ¶úÆäºÍÎÚ×ȱð¿Ë˹̹¡£¡£¡£¡£¡£ ¡£¡£DinodasRAT£¨±ðÃû XDealer£©ÊÇÓà C++ ±àдµÄ£¬£¬ £¬£¬£¬£¬£¬£¬Ö§³Ö¿í·ºµÄÖ°ÄÜÀ´¼à¶½Óû§²¢´ÓÖ¸±êϵͳÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£ ¡£¡£ESET ×êÑÐÈËÔ±»ã±¨³Æ£¬£¬ £¬£¬£¬£¬£¬£¬Windows °æ±¾µÄ DinodasRAT ±»ÓÃÓÚÕë¶Ô¹çÑÇÄǵÐÔÖʵÌåµÄ¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£ESET ÓÚ 2023 Äê 10 Ô³õ´Î·¢ÏÖÐ嵀 Linux °æ±¾µÄ DinodasRAT£¬£¬ £¬£¬£¬£¬£¬£¬µ«×¨¼ÒÒÔΪËü×Ô 2022 ÄêÒÔÀ´¾ÍÒ»Ïò»îÔ¾¡£¡£¡£¡£¡£ ¡£¡£2024 Äê 3 Ô£¬£¬ £¬£¬£¬£¬£¬£¬Ç÷Ïò¿Æ¼¼×êÑÐÈËÔ±ÔÚµ÷²éÓëÖйúÓÐ¹ØµÄ APT Earth Lusca»î¶¯Ê±·¢ÏÖÁËÓɱ»×·×ÙΪ Earth Krahang µÄÍþвÐÐΪÕßÌáÒéµÄ¸´Ôӻ ¡£¡£¡£¡£¡£ ¡£¡£¸Ã»î¶¯ÖÁÉÙ´Ó 2022 ËêÊׯðÍ·ËÆºõ¾ÍºÜ»îÔ¾£¬£¬ £¬£¬£¬£¬£¬£¬ÖØÒªÕë¶Ôµ±¾Ö×éÖ¯¡£¡£¡£¡£¡£ ¡£¡£×Ô 2023 ÄêÆð£¬£¬ £¬£¬£¬£¬£¬£¬Earth Krahang ×ªÒÆµ½ÁíÒ»¸öºóÃÅ£¨  TeamT5¶¨ÃûΪ XDealer  £¬£¬ £¬£¬£¬£¬£¬£¬  ESET ¶¨ÃûΪDinodasRAT  £©¡£¡£¡£¡£¡£ ¡£¡£Ïà±ÈRESHELL£¬£¬ £¬£¬£¬£¬£¬£¬XDealerÌṩÁ˸üÈ«ÃæµÄºóÃÅÖ°ÄÜ¡£¡£¡£¡£¡£ ¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢ÏÖÍþвÐÐΪÕßͬʱʹÓà Windows ºÍ Linux °æ±¾µÄ XDealer À´Õë¶Ô·ÖÆçµÄϵͳ¡£¡£¡£¡£¡£ ¡£¡£


https://securityaffairs.com/161255/malware/linux-variant-dinodasrat-backdoor.html


2. È«ÇòÃÜÂëÅçÈ÷»î¶¯Õë¶Ô VPN ϵͳ¿Éµ¼ÖÂÏµÍ³Ëø¶¨


3ÔÂ31ÈÕ,˼¿ÆÒѰ䲼¹ØÓÚÕë¶ÔÈ«ÇòÆóҵʹÓõÄÔ¶³Ì½Ó¼û VPN (RAVPN) ϵͳµÄ¿í·ºÃÜÂëÅçÈ÷»î¶¯µÄÑϳÁÖҸ档¡£¡£¡£¡£ ¡£¡£ÕâÖÖ¹¥»÷¼¤ÔöµÄÖ÷ÕÅÊÇÓÃͨÓÃÃÜÂ븲û VPN µÇ¼£¬£¬ £¬£¬£¬£¬£¬£¬¿ÉÄÜ»áËø¶¨ºÏ·¨Óû§²¢ÇÖÈÅÔ¶³Ì¹¤×÷¡£¡£¡£¡£¡£ ¡£¡£ÃÜÂëÅçÈ÷»î¶¯»áÓ°Ïì¸÷Àà VPN ÌṩÉÌ£¬£¬ £¬£¬£¬£¬£¬£¬¶ø²»½ö½öÊÇ˼¿Æ¡£¡£¡£¡£¡£ ¡£¡£ÒÀÀµÔ¶³Ì½Ó¼ûµÄÆóÒµ±ØÒªÎ¬³Ö¸ß¶È¾¯Ìè¡£¡£¡£¡£¡£ ¡£¡£ÕâЩ¹¥»÷µÄºó¹û²»½ö½öÊÇδ¾­ÊÚȨµÄ½Ó¼û£»£»£»£»£»£»£» £»ËüÃÇÓпÉÄÜËø¶¨ÕÊ»§²¢Òý·¢ÀàËÆ»Ø¾ø·þÎñ (DoS) µÄÇé¿ö£¬£¬ £¬£¬£¬£¬£¬£¬´Ó¶ø·ÛËéÊý×Ö²Ù×÷µÄÎÞ·ìÁ÷³Ì²¢ÇÖº¦°²È«Í¨Ñ¶µÄÆëÈ«ÐÔ¡£¡£¡£¡£¡£ ¡£¡£¸Ã»î¶¯Í¹ÏÔÁËÔ¶³Ì½Ó¼û½â¾ö¹æ»®ËùÃæ¶ÔµÄ³ÖÐøÍþв¡£¡£¡£¡£¡£ ¡£¡£×éÖ¯±ØÐëÓÅÏÈ˼¿¼×³´óµÄÉí·ÝÑéÖ¤¡¢¾¯ÌèµÄ¼à¿ØºÍ׳´óµÄÊÂÎñÏìÓ¦´òË㣬£¬ £¬£¬£¬£¬£¬£¬ÒÔµ±ÏÅ×Ú²»Ðݱ䶯µÄ¹¥»÷²½Öè¡£¡£¡£¡£¡£ ¡£¡£


https://securityonline.info/global-password-spraying-campaign-targets-vpn-systems-causing-lockouts/


3. ľÂí»¯ npm Èí¼þ°ü¶Ô×¼¼ÓÃÜÇ®±ÒÇ®°ü


3ÔÂ31ÈÕ,Phylum ×êÑÐÍŶÓ¶³öÁËÒ»¸ö¼Ù×°³ÉºÏ·¨¹¤¾ß°üµÄ¶ñÒânpm °ü¡£¡£¡£¡£¡£ ¡£¡£¸ÃÈí¼þ°üÃûΪ¡°vue2util¡±£¬£¬ £¬£¬£¬£¬£¬£¬ÍµÍµµØÖ´ÐÐÁËÒ»ÏÔӵĴòË㣬£¬ £¬£¬£¬£¬£¬£¬Ö¼ÔÚ´ÓºÁÎÞ½äÐĵļÓÃÜÇ®±ÒÇ®°üÖÐÇÔÈ¡ USDT ´ú±Ò¡£¡£¡£¡£¡£ ¡£¡£¡°vue2util¡±¿´ÆðÀ´ÏñÊdz߶ÈʵÓú¯ÊýµÄ¼¯ÖС£¡£¡£¡£¡£ ¡£¡£È»¶ø£¬£¬ £¬£¬£¬£¬£¬£¬Ëü°µ²ØÁËÒ»¸öÏÕ¶ñµÄÓÐЧ¸ºÔØ£¬£¬ £¬£¬£¬£¬£¬£¬µ±µ¼Èëµ½ÏîÄ¿ÖÐʱ£¬£¬ £¬£¬£¬£¬£¬£¬¸ÃÓÐЧ¸ºÔØ»á´ÓÔ¶³Ì·þÎñÆ÷¼ÓÔØ¶ñÒâ¾ç±¾¡£¡£¡£¡£¡£ ¡£¡£¼ÓÔØµÄ¾ç±¾ÒÔ±Ò°²ÖÇÄÜÁ´µÄÓû§ÎªÖ¸±ê£¬£¬ £¬£¬£¬£¬£¬£¬ËÑË÷³ÖÓÐ USDT ¼ÓÃÜÇ®±ÒµÄÇ®°ü¡£¡£¡£¡£¡£ ¡£¡£¶ñÒâÈí¼þÀûÓà ERC20 ºÏÔ¼£¨ÖÎÀí USDT£©µÄÉóÅúÁ÷³Ì¡£¡£¡£¡£¡£ ¡£¡£ËüÔÊÐí×Ô¼ºÎÞÏ޶ȵؽӼûÊܺ¦Õß³ÖÓÐµÄ USDT£¬£¬ £¬£¬£¬£¬£¬£¬ÎÞÐè½øÒ»²½ÊÚȨ¡£¡£¡£¡£¡£ ¡£¡£ÎªÁËÔö³¤³É¹¦µÄ»úÓö£¬£¬ £¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þÆæÃîµØ½«ÆäÖ´ÐÐÁ´½Óµ½Óû§ÍøÒ³ÉÏÏóÕ÷Ϊ¡°buy_btn¡±µÄ°´Å¥¡£¡£¡£¡£¡£ ¡£¡£Ö»Ðèµ¥»÷һϣ¬£¬ £¬£¬£¬£¬£¬£¬Êܺ¦Õ߾ͻáÔÚ²»Öª²»¾õÖд¥·¢ÁîÅÆÍµÇÔ¡£¡£¡£¡£¡£ ¡£¡£


https://securityonline.info/trojanized-npm-package-targets-cryptocurrency-wallets-steals-usdt/


4. ×êÑÐÍŶӷ¢ÏÖʹÓà Google Ads ¸ú×ÙÖ°ÄÜ·Ö·¢¶ñÒâÈí¼þ


4ÔÂ1ÈÕ,AhnLab °²È«µý±¨ÖÐÐÄ (ASEC) ×î½ü¼ì²âµ½Ê¹Óà Google Ads ¸ú×ÙÖ°ÄÜ·Ö·¢µÄ¶ñÒâÈí¼þ±äÖÖ¡£¡£¡£¡£¡£ ¡£¡£ÒÑÈ·ÈϵݸÀýÅú×¢£¬£¬ £¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÊÇͨ¹ý¼Ù×°³É Notion ºÍ Slack µÈÊ¢ÐÐȺ¼þµÄ×°Ö÷¨Ê½À´´«²¼µÄ¡£¡£¡£¡£¡£ ¡£¡£Ò»µ©¶ñÒâÈí¼þ×°Öò¢Ö´ÐУ¬£¬ £¬£¬£¬£¬£¬£¬Ëü¾Í»á´Ó¹¥»÷ÕߵķþÎñÆ÷ÏÂÔØ¶ñÒâÎļþºÍÓÐЧ¸ºÔØ¡£¡£¡£¡£¡£ ¡£¡£´ËÀà¶ñÒâÈí¼þÒÔ×°Ö÷¨Ê½´ó¾Ö·Ö·¢£¬£¬ £¬£¬£¬£¬£¬£¬Í¨³£Îª Inno Setup ×°Ö÷¨Ê½»ò Nullsoft ¾ç±¾×°ÖÃϵͳ (NSIS) ×°Ö÷¨Ê½¡£¡£¡£¡£¡£ ¡£¡£ÆäÖУ¬£¬ £¬£¬£¬£¬£¬£¬Notion_software_x64_.exeÎļþÖ±µ½×î½üÓû§ÔÚGoogleÉÏÓùؼü×Ö¡°notion¡±ËÑË÷ʱ²Å³öÏÖ¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßʹÓà Google Ads ¸ú×ÙÀ´ÓÕÆ­Óû§ÒÔΪËûÃÇÔÚ½Ó¼ûºÏ·¨ÍøÕ¾¡£¡£¡£¡£¡£ ¡£¡£Google Ads ¸ú×ÙÔÊÐí¸æ°×¿Í»§²åÈë±í²¿ÃÅÎöÍøÕ¾µØÖ·£¬£¬ £¬£¬£¬£¬£¬£¬ÒÔÍøÂçºÍʹÓýӼûÕߵĽӼûÓйØÊý¾ÝÀ´ÍÆËã¸æ°×Á÷Á¿¡£¡£¡£¡£¡£ ¡£¡£Google Ads ¸ú×Ù×î³õÓÃÓÚ·ÖÎöÍøÕ¾Á÷Á¿¡£¡£¡£¡£¡£ ¡£¡£µ«ÊÇ£¬£¬ £¬£¬£¬£¬£¬£¬¸ÃÌØ¶¨¸æ°×²»Ô̺¬±í²¿¾²Ì¬Õ¾µã£¬£¬ £¬£¬£¬£¬£¬£¬¶øÊÇÔ̺¬¶ñÒâ´úÂë·Ö·¢Õ¾µã¡£¡£¡£¡£¡£ ¡£¡£

Ŀǰ¹¥»÷Õߵĸæ°×Òѱ»É¾³ý¡£¡£¡£¡£¡£ ¡£¡£


https://asec.ahnlab.com/en/63477/


5. ºÚ¿ÍʹÓà Microsoft OneNote À´²ß¶¯ÍøÂç¹¥»÷


4ÔÂ1ÈÕ,¸Ã»î¶¯ÔÚÍøÂ簲ȫר¼ÒµÄ¹Ø×¢Ï£¬£¬ £¬£¬£¬£¬£¬£¬Õ¹Ê¾ÁËÍøÂçÍþвµÄÐÂÇ÷Ïò£¬£¬ £¬£¬£¬£¬£¬£¬¼´ÀûÓó£Óõİ칫ÀûÓ÷¨Ê½Î´¾­ÊÚȨ½Ó¼ûÆóÒµÍøÂç¡£¡£¡£¡£¡£ ¡£¡£pr0xylife Ê×ÏÈÔÚÆä GitHub ´æ´¢¿âÉϼͼÁ˸öñÒâ»î¶¯¡£¡£¡£¡£¡£ ¡£¡£Ëü¸æ·¢ÁËÕë¶ÔÔì×÷¡¢¼¼Êõ¡¢ÄÜÔ´¡¢ÁãÊÛ¡¢±£ÏÕºÍÆäËû¼¸¸öÐÐÒµµÄ¹«Ë¾µÄ¿í·ºµç×ÓÓʼþÍøÂç´¹µö²Ù×÷¡£¡£¡£¡£¡£ ¡£¡£ÕâЩµç×ÓÓʼþÔ̺¬Ðû³ÆÊÇ¡°°²È«ÐÂÎÅ¡±µÄ OneNote ¸½¼þ£¬£¬ £¬£¬£¬£¬£¬£¬ÕâÊÇÒ»ÖÖºýŪÊÕ¼þÈË´ò¿ªÎļþµÄ»Ï×Ó¡£¡£¡£¡£¡£ ¡£¡£¸Ã»î¶¯Ç¿µ÷ÁËÍøÂçÍþв²»ÐÝÑݱäµÄÇé¿ö£¬£¬ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓöԳ£ÓÃÀûÓ÷¨Ê½µÄÐÅÀµÀ´Èƹý´«Í³µÄ°²È«´ëÊ©¡£¡£¡£¡£¡£ ¡£¡£Ê¹Óà Microsoft OneNote Îļþ´«²¼¶ñÒâÈí¼þ´ú±í×ÅÏò¸ü¾ß´´ÔìÐԵĹ¥»÷ý½éµÄת±ä£¬£¬ £¬£¬£¬£¬£¬£¬Òò¶ø±ØÒª³ÁÐÂÆÀ¹ÀÍøÂ簲ȫսÊõÒÔ·À±¸´ËÀàÍþв¡£¡£¡£¡£¡£ ¡£¡£


https://gbhackers.com/microsoft-onenote-orchestrate/


6. TeamCity ½¨²¹ÁË 26 ¸ö·ì϶²¢±£ÃܾßÌåÐÅÏ¢


4ÔÂ1ÈÕ,ÔÚ JetBrains µÄ³ÖÐø¼¯³ÉºÍ½»¸¶ (CI/CD) TeamCity ×î½üµÄÈí¼þ¸üÐÂÖУ¬£¬ £¬£¬£¬£¬£¬£¬½â¾öÁË 26 ¸ö°²È«ÎÊÌâ¡£¡£¡£¡£¡£ ¡£¡£È»¶ø£¬£¬ £¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ñ¡Ôñ²»Ð¹Â©ÓйØÒÑ·¢ÏÖ·ì϶µÄÈκÎϸ½Ú£¬£¬ £¬£¬£¬£¬£¬£¬Òý·¢ÁËרҵ½çµÄÇ¿ÁÒ»áÉÌ¡£¡£¡£¡£¡£ ¡£¡£TeamCity 2024.03 °æ±¾¸üÐÂÖ¼ÔÚ±£»£»£»£»£»£»£» £»¤Óû§ÃâÊÜDZÔÚÍþв£¬£¬ £¬£¬£¬£¬£¬£¬µ«ÆëȫûÓÐÓÐ¹Ø 26 ¸ö·ì϶µÄ¾ßÌåÐÅÏ¢£¬£¬ £¬£¬£¬£¬£¬£¬×ÅʵÈð²È«×¨¼Ò¸ÐÓ¦¾ªÑÈ¡£¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾²»×ãͨÃ÷¶È£¬£¬ £¬£¬£¬£¬£¬£¬³ö¸ñÊÇÔÚ Rapid7 µÄר¼ÒÆ·ÆÀ JetBrains ²»¹»Ê¢¿ªµÄÊÂÎñÖ®ºó£¬£¬ £¬£¬£¬£¬£¬£¬Ò»ÏòÊܵ½³ö¸ñÆ·ÆÀ¡£¡£¡£¡£¡£ ¡£¡£JetBrains Ðû³Æ£¬£¬ £¬£¬£¬£¬£¬£¬±£Áô¾ßÌåÐÅÏ¢Ö»ÊÇΪÁ˱£»£»£»£»£»£»£» £»¤Ê¹Óþɰæ TeamCity µÄ¿Í»§£¬£¬ £¬£¬£¬£¬£¬£¬Ö»¹ÜÕâÔÚÒµ½ç²¢Î´µÃµ½¿í·º½ÓÊÜ¡£¡£¡£¡£¡£ ¡£¡£Ö»¹ÜÈç´Ë£¬£¬ £¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄÒâͼ»¹ÊÇÄܹ»Àí½âµÄ¡£¡£¡£¡£¡£ ¡£¡£¶ÔÓÚÏëÒª¹¥»÷Èí¼þ¹©¸øÁ´µÄ·¸×ï·Ö×ÓÀ´Ëµ£¬£¬ £¬£¬£¬£¬£¬£¬TeamCity ÒÀÈ»ÊÇÒ»¸öÓÐÎüÒýÁ¦µÄÖ¸±ê¡£¡£¡£¡£¡£ ¡£¡£º¹ÇàÅú×¢£¬£¬ £¬£¬£¬£¬£¬£¬´ËÀ๥»÷¿ÉÄÜ»á²úÉúÑϳÁºó¹û£¬£¬ £¬£¬£¬£¬£¬£¬ÕýÈç SolarWinds µÄ°¸ÀýËùʾ¡£¡£¡£¡£¡£ ¡£¡£


https://meterpreter.org/teamcity-patches-26-vulnerabilities-keeps-details-secret/