DINODASRAT LINUX ±äÖÖÕë¶ÔÈ«ÇòÓû§
°ä²¼¹¦·ò 2024-04-023ÔÂ31ÈÕ,¿¨°Í˹»ù³¢ÊÔÊÒµÄ×êÑÐÈËÔ±·¢ÏÖÁË Linux °æ±¾µÄ¶àƽ̨ºóÃÅ DinodasRAT£¬£¬£¬£¬£¬£¬£¬£¬¸ÃºóÃű»ÓÃÓÚÕë¶ÔÖйú¡¢ÍÁ¶úÆäºÍÎÚ×ȱð¿Ë˹̹¡£¡£¡£¡£¡£¡£¡£DinodasRAT£¨±ðÃû XDealer£©ÊÇÓà C++ ±àдµÄ£¬£¬£¬£¬£¬£¬£¬£¬Ö§³Ö¿í·ºµÄÖ°ÄÜÀ´¼à¶½Óû§²¢´ÓÖ¸±êϵͳÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ESET ×êÑÐÈËÔ±»ã±¨³Æ£¬£¬£¬£¬£¬£¬£¬£¬Windows °æ±¾µÄ DinodasRAT ±»ÓÃÓÚÕë¶Ô¹çÑÇÄǵÐÔÖʵÌåµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£ESET ÓÚ 2023 Äê 10 Ô³õ´Î·¢ÏÖÐ嵀 Linux °æ±¾µÄ DinodasRAT£¬£¬£¬£¬£¬£¬£¬£¬µ«×¨¼ÒÒÔΪËü×Ô 2022 ÄêÒÔÀ´¾ÍÒ»Ïò»îÔ¾¡£¡£¡£¡£¡£¡£¡£2024 Äê 3 Ô£¬£¬£¬£¬£¬£¬£¬£¬Ç÷Ïò¿Æ¼¼×êÑÐÈËÔ±ÔÚµ÷²éÓëÖйúÓÐ¹ØµÄ APT Earth Lusca»î¶¯Ê±·¢ÏÖÁËÓɱ»×·×ÙΪ Earth Krahang µÄÍþвÐÐΪÕßÌáÒéµÄ¸´Ôӻ ¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ÖÁÉÙ´Ó 2022 ËêÊׯðÍ·ËÆºõ¾ÍºÜ»îÔ¾£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶Ôµ±¾Ö×éÖ¯¡£¡£¡£¡£¡£¡£¡£×Ô 2023 ÄêÆð£¬£¬£¬£¬£¬£¬£¬£¬Earth Krahang ×ªÒÆµ½ÁíÒ»¸öºóÃÅ£¨ TeamT5¶¨ÃûΪ XDealer £¬£¬£¬£¬£¬£¬£¬£¬ ESET ¶¨ÃûΪDinodasRAT £©¡£¡£¡£¡£¡£¡£¡£Ïà±ÈRESHELL£¬£¬£¬£¬£¬£¬£¬£¬XDealerÌṩÁ˸üÈ«ÃæµÄºóÃÅÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢ÏÖÍþвÐÐΪÕßͬʱʹÓà Windows ºÍ Linux °æ±¾µÄ XDealer À´Õë¶Ô·ÖÆçµÄϵͳ¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/161255/malware/linux-variant-dinodasrat-backdoor.html
2. È«ÇòÃÜÂëÅçÈ÷»î¶¯Õë¶Ô VPN ϵͳ¿Éµ¼ÖÂÏµÍ³Ëø¶¨
3ÔÂ31ÈÕ,˼¿ÆÒѰ䲼¹ØÓÚÕë¶ÔÈ«ÇòÆóҵʹÓõÄÔ¶³Ì½Ó¼û VPN (RAVPN) ϵͳµÄ¿í·ºÃÜÂëÅçÈ÷»î¶¯µÄÑϳÁÖҸ档¡£¡£¡£¡£¡£¡£ÕâÖÖ¹¥»÷¼¤ÔöµÄÖ÷ÕÅÊÇÓÃͨÓÃÃÜÂ븲û VPN µÇ¼£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜ»áËø¶¨ºÏ·¨Óû§²¢ÇÖÈÅÔ¶³Ì¹¤×÷¡£¡£¡£¡£¡£¡£¡£ÃÜÂëÅçÈ÷»î¶¯»áÓ°Ïì¸÷Àà VPN ÌṩÉÌ£¬£¬£¬£¬£¬£¬£¬£¬¶ø²»½ö½öÊÇ˼¿Æ¡£¡£¡£¡£¡£¡£¡£ÒÀÀµÔ¶³Ì½Ó¼ûµÄÆóÒµ±ØÒªÎ¬³Ö¸ß¶È¾¯Ìè¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷µÄºó¹û²»½ö½öÊÇδ¾ÊÚȨµÄ½Ó¼û£»£»£»£»£»£»£»£»ËüÃÇÓпÉÄÜËø¶¨ÕÊ»§²¢Òý·¢ÀàËÆ»Ø¾ø·þÎñ (DoS) µÄÇé¿ö£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶ø·ÛËéÊý×Ö²Ù×÷µÄÎÞ·ìÁ÷³Ì²¢ÇÖº¦°²È«Í¨Ñ¶µÄÆëÈ«ÐÔ¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Í¹ÏÔÁËÔ¶³Ì½Ó¼û½â¾ö¹æ»®ËùÃæ¶ÔµÄ³ÖÐøÍþв¡£¡£¡£¡£¡£¡£¡£×éÖ¯±ØÐëÓÅÏÈ˼¿¼×³´óµÄÉí·ÝÑéÖ¤¡¢¾¯ÌèµÄ¼à¿ØºÍ׳´óµÄÊÂÎñÏìÓ¦´òË㣬£¬£¬£¬£¬£¬£¬£¬ÒÔµ±ÏÅ×Ú²»Ðݱ䶯µÄ¹¥»÷²½Öè¡£¡£¡£¡£¡£¡£¡£
https://securityonline.info/global-password-spraying-campaign-targets-vpn-systems-causing-lockouts/
3. ľÂí»¯ npm Èí¼þ°ü¶Ô×¼¼ÓÃÜÇ®±ÒÇ®°ü
3ÔÂ31ÈÕ,Phylum ×êÑÐÍŶÓ¶³öÁËÒ»¸ö¼Ù×°³ÉºÏ·¨¹¤¾ß°üµÄ¶ñÒânpm °ü¡£¡£¡£¡£¡£¡£¡£¸ÃÈí¼þ°üÃûΪ¡°vue2util¡±£¬£¬£¬£¬£¬£¬£¬£¬ÍµÍµµØÖ´ÐÐÁËÒ»ÏÔӵĴòË㣬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ´ÓºÁÎÞ½äÐĵļÓÃÜÇ®±ÒÇ®°üÖÐÇÔÈ¡ USDT ´ú±Ò¡£¡£¡£¡£¡£¡£¡£¡°vue2util¡±¿´ÆðÀ´ÏñÊdz߶ÈʵÓú¯ÊýµÄ¼¯ÖС£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬£¬£¬Ëü°µ²ØÁËÒ»¸öÏÕ¶ñµÄÓÐЧ¸ºÔØ£¬£¬£¬£¬£¬£¬£¬£¬µ±µ¼Èëµ½ÏîÄ¿ÖÐʱ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÓÐЧ¸ºÔØ»á´ÓÔ¶³Ì·þÎñÆ÷¼ÓÔØ¶ñÒâ¾ç±¾¡£¡£¡£¡£¡£¡£¡£¼ÓÔØµÄ¾ç±¾ÒÔ±Ò°²ÖÇÄÜÁ´µÄÓû§ÎªÖ¸±ê£¬£¬£¬£¬£¬£¬£¬£¬ËÑË÷³ÖÓÐ USDT ¼ÓÃÜÇ®±ÒµÄÇ®°ü¡£¡£¡£¡£¡£¡£¡£¶ñÒâÈí¼þÀûÓà ERC20 ºÏÔ¼£¨ÖÎÀí USDT£©µÄÉóÅúÁ÷³Ì¡£¡£¡£¡£¡£¡£¡£ËüÔÊÐí×Ô¼ºÎÞÏ޶ȵؽӼûÊܺ¦Õß³ÖÓÐµÄ USDT£¬£¬£¬£¬£¬£¬£¬£¬ÎÞÐè½øÒ»²½ÊÚȨ¡£¡£¡£¡£¡£¡£¡£ÎªÁËÔö³¤³É¹¦µÄ»úÓö£¬£¬£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þÆæÃîµØ½«ÆäÖ´ÐÐÁ´½Óµ½Óû§ÍøÒ³ÉÏÏóÕ÷Ϊ¡°buy_btn¡±µÄ°´Å¥¡£¡£¡£¡£¡£¡£¡£Ö»Ðèµ¥»÷һϣ¬£¬£¬£¬£¬£¬£¬£¬Êܺ¦Õ߾ͻáÔÚ²»Öª²»¾õÖд¥·¢ÁîÅÆÍµÇÔ¡£¡£¡£¡£¡£¡£¡£
https://securityonline.info/trojanized-npm-package-targets-cryptocurrency-wallets-steals-usdt/
4. ×êÑÐÍŶӷ¢ÏÖʹÓà Google Ads ¸ú×ÙÖ°ÄÜ·Ö·¢¶ñÒâÈí¼þ
4ÔÂ1ÈÕ,AhnLab °²È«µý±¨ÖÐÐÄ (ASEC) ×î½ü¼ì²âµ½Ê¹Óà Google Ads ¸ú×ÙÖ°ÄÜ·Ö·¢µÄ¶ñÒâÈí¼þ±äÖÖ¡£¡£¡£¡£¡£¡£¡£ÒÑÈ·ÈϵݸÀýÅú×¢£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÊÇͨ¹ý¼Ù×°³É Notion ºÍ Slack µÈÊ¢ÐÐȺ¼þµÄ×°Ö÷¨Ê½À´´«²¼µÄ¡£¡£¡£¡£¡£¡£¡£Ò»µ©¶ñÒâÈí¼þ×°Öò¢Ö´ÐУ¬£¬£¬£¬£¬£¬£¬£¬Ëü¾Í»á´Ó¹¥»÷ÕߵķþÎñÆ÷ÏÂÔØ¶ñÒâÎļþºÍÓÐЧ¸ºÔØ¡£¡£¡£¡£¡£¡£¡£´ËÀà¶ñÒâÈí¼þÒÔ×°Ö÷¨Ê½´ó¾Ö·Ö·¢£¬£¬£¬£¬£¬£¬£¬£¬Í¨³£Îª Inno Setup ×°Ö÷¨Ê½»ò Nullsoft ¾ç±¾×°ÖÃϵͳ (NSIS) ×°Ö÷¨Ê½¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬£¬Notion_software_x64_.exeÎļþÖ±µ½×î½üÓû§ÔÚGoogleÉÏÓùؼü×Ö¡°notion¡±ËÑË÷ʱ²Å³öÏÖ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓà Google Ads ¸ú×ÙÀ´ÓÕÆÓû§ÒÔΪËûÃÇÔÚ½Ó¼ûºÏ·¨ÍøÕ¾¡£¡£¡£¡£¡£¡£¡£Google Ads ¸ú×ÙÔÊÐí¸æ°×¿Í»§²åÈë±í²¿ÃÅÎöÍøÕ¾µØÖ·£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÍøÂçºÍʹÓýӼûÕߵĽӼûÓйØÊý¾ÝÀ´ÍÆËã¸æ°×Á÷Á¿¡£¡£¡£¡£¡£¡£¡£Google Ads ¸ú×Ù×î³õÓÃÓÚ·ÖÎöÍøÕ¾Á÷Á¿¡£¡£¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÌØ¶¨¸æ°×²»Ô̺¬±í²¿¾²Ì¬Õ¾µã£¬£¬£¬£¬£¬£¬£¬£¬¶øÊÇÔ̺¬¶ñÒâ´úÂë·Ö·¢Õ¾µã¡£¡£¡£¡£¡£¡£¡£
Ŀǰ¹¥»÷Õߵĸæ°×Òѱ»É¾³ý¡£¡£¡£¡£¡£¡£¡£
https://asec.ahnlab.com/en/63477/
5. ºÚ¿ÍʹÓà Microsoft OneNote À´²ß¶¯ÍøÂç¹¥»÷
4ÔÂ1ÈÕ,¸Ã»î¶¯ÔÚÍøÂ簲ȫר¼ÒµÄ¹Ø×¢Ï£¬£¬£¬£¬£¬£¬£¬£¬Õ¹Ê¾ÁËÍøÂçÍþвµÄÐÂÇ÷Ïò£¬£¬£¬£¬£¬£¬£¬£¬¼´ÀûÓó£Óõİ칫ÀûÓ÷¨Ê½Î´¾ÊÚȨ½Ó¼ûÆóÒµÍøÂç¡£¡£¡£¡£¡£¡£¡£pr0xylife Ê×ÏÈÔÚÆä GitHub ´æ´¢¿âÉϼͼÁ˸öñÒâ»î¶¯¡£¡£¡£¡£¡£¡£¡£Ëü¸æ·¢ÁËÕë¶ÔÔì×÷¡¢¼¼Êõ¡¢ÄÜÔ´¡¢ÁãÊÛ¡¢±£ÏÕºÍÆäËû¼¸¸öÐÐÒµµÄ¹«Ë¾µÄ¿í·ºµç×ÓÓʼþÍøÂç´¹µö²Ù×÷¡£¡£¡£¡£¡£¡£¡£ÕâЩµç×ÓÓʼþÔ̺¬Ðû³ÆÊÇ¡°°²È«ÐÂÎÅ¡±µÄ OneNote ¸½¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»ÖÖºýŪÊÕ¼þÈË´ò¿ªÎļþµÄ»Ï×Ó¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Ç¿µ÷ÁËÍøÂçÍþв²»ÐÝÑݱäµÄÇé¿ö£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓöԳ£ÓÃÀûÓ÷¨Ê½µÄÐÅÀµÀ´Èƹý´«Í³µÄ°²È«´ëÊ©¡£¡£¡£¡£¡£¡£¡£Ê¹Óà Microsoft OneNote Îļþ´«²¼¶ñÒâÈí¼þ´ú±í×ÅÏò¸ü¾ß´´ÔìÐԵĹ¥»÷ý½éµÄת±ä£¬£¬£¬£¬£¬£¬£¬£¬Òò¶ø±ØÒª³ÁÐÂÆÀ¹ÀÍøÂ簲ȫսÊõÒÔ·À±¸´ËÀàÍþв¡£¡£¡£¡£¡£¡£¡£
https://gbhackers.com/microsoft-onenote-orchestrate/
6. TeamCity ½¨²¹ÁË 26 ¸ö·ì϶²¢±£ÃܾßÌåÐÅÏ¢
4ÔÂ1ÈÕ,ÔÚ JetBrains µÄ³ÖÐø¼¯³ÉºÍ½»¸¶ (CI/CD) TeamCity ×î½üµÄÈí¼þ¸üÐÂÖУ¬£¬£¬£¬£¬£¬£¬£¬½â¾öÁË 26 ¸ö°²È«ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ñ¡Ôñ²»Ð¹Â©ÓйØÒÑ·¢ÏÖ·ì϶µÄÈκÎϸ½Ú£¬£¬£¬£¬£¬£¬£¬£¬Òý·¢ÁËרҵ½çµÄÇ¿ÁÒ»áÉÌ¡£¡£¡£¡£¡£¡£¡£TeamCity 2024.03 °æ±¾¸üÐÂÖ¼ÔÚ±£»£»£»£»£»£»£»£»¤Óû§ÃâÊÜDZÔÚÍþв£¬£¬£¬£¬£¬£¬£¬£¬µ«ÆëȫûÓÐÓÐ¹Ø 26 ¸ö·ì϶µÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬×ÅʵÈð²È«×¨¼Ò¸ÐÓ¦¾ªÑÈ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾²»×ãͨÃ÷¶È£¬£¬£¬£¬£¬£¬£¬£¬³ö¸ñÊÇÔÚ Rapid7 µÄר¼ÒÆ·ÆÀ JetBrains ²»¹»Ê¢¿ªµÄÊÂÎñÖ®ºó£¬£¬£¬£¬£¬£¬£¬£¬Ò»ÏòÊܵ½³ö¸ñÆ·ÆÀ¡£¡£¡£¡£¡£¡£¡£JetBrains Ðû³Æ£¬£¬£¬£¬£¬£¬£¬£¬±£Áô¾ßÌåÐÅÏ¢Ö»ÊÇΪÁ˱£»£»£»£»£»£»£»£»¤Ê¹Óþɰæ TeamCity µÄ¿Í»§£¬£¬£¬£¬£¬£¬£¬£¬Ö»¹ÜÕâÔÚÒµ½ç²¢Î´µÃµ½¿í·º½ÓÊÜ¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÈç´Ë£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄÒâͼ»¹ÊÇÄܹ»Àí½âµÄ¡£¡£¡£¡£¡£¡£¡£¶ÔÓÚÏëÒª¹¥»÷Èí¼þ¹©¸øÁ´µÄ·¸×ï·Ö×ÓÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬£¬TeamCity ÒÀÈ»ÊÇÒ»¸öÓÐÎüÒýÁ¦µÄÖ¸±ê¡£¡£¡£¡£¡£¡£¡£º¹ÇàÅú×¢£¬£¬£¬£¬£¬£¬£¬£¬´ËÀ๥»÷¿ÉÄÜ»á²úÉúÑϳÁºó¹û£¬£¬£¬£¬£¬£¬£¬£¬ÕýÈç SolarWinds µÄ°¸ÀýËùʾ¡£¡£¡£¡£¡£¡£¡£
https://meterpreter.org/teamcity-patches-26-vulnerabilities-keeps-details-secret/


¾©¹«Íø°²±¸11010802024551ºÅ