È«Çò70Óà×éÖ¯ÔâVoldemort¼äµýÈí¼þ¹¥»÷

°ä²¼¹¦·ò 2024-09-02

1. È«Çò70Óà×éÖ¯ÔâVoldemort¼äµýÈí¼þ¹¥»÷


9ÔÂ1ÈÕ£¬£¬£¬£¬ £¬£¬Proofpoint ×êÑÐÈËÔ±¸æ·¢ÁËһ·¸´Ôӵļäµý»î¶¯£¬£¬£¬£¬ £¬£¬¸Ã»î¶¯Í¨¹ýÃûΪ¡°Voldemort¡±µÄ¶¨Ôì¶ñÒâÈí¼þ£¬£¬£¬£¬ £¬£¬Ó°ÏìÈ«Çò70¶à¸ö×éÖ¯¡£¡£¡£¡£ ¡£¡£´Ë¶ñÒâÈí¼þͨ¹ý³¬¹ý20,000·â´¹µöÓʼþ´«²¼£¬£¬£¬£¬ £¬£¬³ö¸ñÊÇ8ÔÂ17ÈÕ¼¤Ôö½ü6,000·â£¬£¬£¬£¬ £¬£¬Óʼþ¼Ù×°¶à¹ú˰Îñ»ú¹ØÓÕÆ­Óû§¡£¡£¡£¡£ ¡£¡£¹¥»÷Á´ÀûÓÃGoogle AMP Cache URL¡¢CloudflareËí·¡¢WebDAV¹²Ïí¼°Python¾ç±¾µÈ¼¼Êõ£¬£¬£¬£¬ £¬£¬ÆæÃîÊèµ¼Óû§ÏÂÔØ²¢Ö´ÐжñÒâLNK»òZIPÎļþ¡£¡£¡£¡£ ¡£¡£VoldemortµÄÒ»´óÌØµãÊÇÀûÓÃGoogle±í¸ñ½øÐкÅÁîÓë½ÚÔ죨C2£©£¬£¬£¬£¬ £¬£¬¶ã±Ü´«Í³°²È«¼ì²â£¬£¬£¬£¬ £¬£¬ÏÔʾÁ˸߶ȵÄÒñ±ÎÐԺʹ´ÐÂÐÔ¡£¡£¡£¡£ ¡£¡£ÆäÖ¸±êÖØÒªËø¶¨ÔÚ±£ÏÕ¹«Ë¾¡¢º½¿Õº½Ìì¡¢½»Í¨ÔËÊä¼°´óѧµÈ18¸ö´¹Ö±ÐÐÒµ£¬£¬£¬£¬ £¬£¬ÇÒ¾«×¼¶¨Î»Êܺ¦ÕßÖÁÆä¾Óס¹ú£¬£¬£¬£¬ £¬£¬ÏÔʾ³öÉîµµ´ÎµÄ¼äµý¶¯»ú¡£¡£¡£¡£ ¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬¸Ã¶ñÒâÈí¼þ»¹Ñ¡È¡º±¼ûµÄWindows .search-msÎļþÌåʽ£¬£¬£¬£¬ £¬£¬¼Ù×°Ô¶³ÌÎļþΪ±¾µØÎļþ£¬£¬£¬£¬ £¬£¬½áºÏDLL½Ù³Ö¼¼Êõ£¬£¬£¬£¬ £¬£¬½øÒ»²½Ôö³¤Ï°È¾³É¹¦ÂÊ¡£¡£¡£¡£ ¡£¡£È»¶ø£¬£¬£¬£¬ £¬£¬¹¥»÷»î¶¯ÖÐҲ¶³ö³öһЩ¼òª֮´¦£¬£¬£¬£¬ £¬£¬ÈçʹÓõ¥Ò»µÄÎļþ¶¨ÃûÔ¼¶¨£¬£¬£¬£¬ £¬£¬Ê¹µÃ¸Ã»î¶¯³öÏÖ³ö¡°¸¥À¼¿Ï˹̹ʽ»ìºÏÌ塱µÄÌØµã£¬£¬£¬£¬ £¬£¬ÄÑÒÔÅжÏÍþвÐÐΪÕßµÄÕæÊµ¼¼Êõˮƽ¡£¡£¡£¡£ ¡£¡£


https://securityonline.info/cyber-espionage-campaign-leverages-novel-tactics-and-voldemort-malware-to-target-global-organizations/https://securityonline.info/cyber-espionage-campaign-leverages-novel-tactics-and-voldemort-malware-to-target-global-organizations/


2. APT×éÖ¯Citrine SleetÀûÓÃChrome 0day²¿ÊðFudModule rootkit


8ÔÂ31ÈÕ£¬£¬£¬£¬ £¬£¬Ó볯ÏÊÓйØÁªµÄAPT×éÖ¯Citrine Sleet£¨Òà³ÆAppleJeus¡¢Labyrinth ChollimaµÈ£©ÀûÓÃн¨²¹µÄGoogle ChromeÁãÈÕ·ì϶CVE-2024-7971£¬£¬£¬£¬ £¬£¬³É¹¦²¿ÊðÁËFudModule rootkit¡£¡£¡£¡£ ¡£¡£¸Ã·ì϶£¨CVSSÆÀ·Ö8.8£©Ó°ÏìÌØ¶¨°æ±¾µÄChromium£¬£¬£¬£¬ £¬£¬ÔÊÐí¹¥»÷ÕßÔÚɳºÐ»¯µÄäÖȾÆ÷¹ý³ÌÖÐÖ´ÐÐÔ¶³Ì´úÂë¡£¡£¡£¡£ ¡£¡£Citrine Sleetͨ¹ý¾«ÐÄÉè¼ÆµÄ´¹µöÕ½Êõ£¬£¬£¬£¬ £¬£¬ÓÕʹÊܺ¦Õß½Ó¼ûÆä½ÚÔìµÄ¶ñÒâÓòÃû£¬£¬£¬£¬ £¬£¬½ø¶ø´¥·¢CVE-2024-7971·ì϶£¬£¬£¬£¬ £¬£¬ÏÂÔØ²¢Ö´ÐÐÔ̺¬WindowsɳºÐÌÓÒÝ·ì϶£¨CVE-2024-38106£©ºÍFudModule rootkitµÄshellcode¡£¡£¡£¡£ ¡£¡£FudModule rootkitѡȡֱ½ÓÄÚ²é¶ÔÏó²Ù×÷£¨DKOM£©¼¼Êõ£¬£¬£¬£¬ £¬£¬´ÓÓû§Ä£Ê½ÔËÐв¢´Û¸ÄÄںˣ¬£¬£¬£¬ £¬£¬×ÌÈŰ²È«»úÔ죬£¬£¬£¬ £¬£¬Ö»¹ÜÔÚÖ¸±êÉ豸ÉÏδ¼ì²âµ½ºóÐø¶ñÒâ»î¶¯¡£¡£¡£¡£ ¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬ £¬£¬CVE-2024-38106ËäÒѽ¨¸´£¬£¬£¬£¬ £¬£¬µ«¿ÉÄÜÓëCitrine SleetµÄÀûÓûÎÞÖ±½Ó¹ØÁª£¬£¬£¬£¬ £¬£¬°µÊ¾¿ÉÄÜ´æÔÚ¡°·ì϶Åöײ¡±¾°Ï󡣡£¡£¡£ ¡£¡£MicrosoftÇ¿µ÷£¬£¬£¬£¬ £¬£¬×é֯Ӧȷ±£ÏµÍ³ÊµÊ±¸üУ¬£¬£¬£¬ £¬£¬²¿Êð¾ß±¸È«ÃæÍøÂç¹¥»÷Á´¿É¼ûÐԵݲȫ½â¾ö¹æ»®£¬£¬£¬£¬ £¬£¬²¢¼ÓÇ¿²Ù×÷»·¾³ÅäÖ㬣¬£¬£¬ £¬£¬ÒÔÓÐЧ¼ì²âºÍ×èÖ¹´ËÀà¸ß¼¶Íþв¡£¡£¡£¡£ ¡£¡£


https://securityaffairs.com/167848/breaking-news/north-korea-linked-apt-exploited-chrome-zero-day-cve-2024-7971.html


3. GitHub ÔâÀÄÓãºÊýǧÌõÐéὨ¸´ÆÀÂÛ·Ö·¢Lumma Stealer¶ñÒâÈí¼þ


8ÔÂ31ÈÕ£¬£¬£¬£¬ £¬£¬GitHub ƽ̨½üÆÚÔâ·êÁËÀÄÓ㬣¬£¬£¬ £¬£¬·¸·¨·Ö×Óͨ¹ýÔÚÏîÄ¿ÆÀÂÛÖа䲼ÐéὨ¸´·¨Ê½µÄ·½Ê½£¬£¬£¬£¬ £¬£¬¿í·º·Ö·¢ Lumma Stealer ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ¡£¡£¡£¡£ ¡£¡£ÕâÒ»»î¶¯×î³õÓÉteloxide rust¿âµÄ¹±Ï×ÕßÔÚRedditÉϸ淢£¬£¬£¬£¬ £¬£¬ËæºóBleepingComputerÉî¿Ìµ÷²é·¢ÏÖ£¬£¬£¬£¬ £¬£¬ÊýǧÌõÀàËÆÆÀÂÛÒѱ鲼GitHub¶à¸öÏîÄ¿£¬£¬£¬£¬ £¬£¬ÓÕµ¼Óû§ÏÂÔØ²¢Ö´ÐÐÔ̺¬¶ñÒâÈí¼þµÄÎļþ¡£¡£¡£¡£ ¡£¡£ÕâЩÆÀÂÛ¼Ù×°³ÉÎÊÌâ½â¾ö¹æ»®£¬£¬£¬£¬ £¬£¬ÓÕÆ­Óû§´Ómediafire.com»òbit.lyÁ´½ÓÏÂÔØÃûΪ¡°fix.zip¡±µÄ¼ÓÃÜ´æµµ£¬£¬£¬£¬ £¬£¬²¢ÌáÐÑʹÓÃͳһÃÜÂë¡°changeme¡±½âËø¡£¡£¡£¡£ ¡£¡£ÈýÌìÄÚ£¬£¬£¬£¬ £¬£¬´ËÀàÍÆ¹ã¶ñÒâÈí¼þµÄÆÀÂÛÊýÁ¿¼¤ÔöÖÁ³¬¹ý29,000Ìõ¡£¡£¡£¡£ ¡£¡£ÏÂÔØµÄ´æµµÖÐÔ̺¬DLLÎļþºÍ¿ÉÖ´ÐÐÎļþx86_64-w64-ranlib.exe£¬£¬£¬£¬ £¬£¬¾­·ÖÎöÈ·ÒÔΪLumma Stealer£¬£¬£¬£¬ £¬£¬Ò»ÖÖ¿ÉÄÜÉî¿ÌÓû§ä¯ÀÀÆ÷ÇÔÈ¡Ãô¸ÐÐÅÏ¢µÄ¸ß¼¶ÐÅÏ¢ÇÔÈ¡¹¤¾ß¡£¡£¡£¡£ ¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬Ëü»¹Õë¶Ô¼ÓÃÜÇ®±ÒÇ®°üºÍÌØ¶¨ÊýÃûµÄÎı¾Îļþ½øÐÐËÑË÷£¬£¬£¬£¬ £¬£¬ÍøÂç¿ÉÄÜÔ̺¬Ë½Ô¿ºÍÃÜÂëµÄÊý¾Ý¡£¡£¡£¡£ ¡£¡£Ö»¹ÜGitHubѸËÙÏìÓ¦²¢É¾³ýÁËÕâЩ¶ñÒâÆÀÂÛ£¬£¬£¬£¬ £¬£¬µ«ÒÑÓÐЧ»§Êܺ¦¡£¡£¡£¡£ ¡£¡£ÊÜÓ°ÏìÓû§ÐèÁ¢¼´ÎªËùÓÐÕË»§¸ü»»Î¨Ò»ÃÜÂ룬£¬£¬£¬ £¬£¬²¢½«¼ÓÃÜÇ®±Ò×ªÒÆÖÁÐÂÇ®°ü¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/github-comments-abused-to-push-password-stealing-malware-masked-as-fixes/


4. ¸´ÔÓÍøÂç´¹µö¹¥»÷¸æ·¢£ºAsyncRATÓëInfostealerÁªÊÖÍþвÓû§°²È«


8ÔÂ31ÈÕ£¬£¬£¬£¬ £¬£¬eSentire ÍþвÏìÓ¦²¿ÃÅ£¨TRU£©µÄ×êÑÐÈËÔ±¸æ·¢ÁËÒ»ÏÔÓµÄÍøÂç´¹µö¹¥»÷£¬£¬£¬£¬ £¬£¬¸Ã¹¥»÷ÀûÓþ«ÐÄÉè¼ÆµÄϰȾÁ´·Ö·¢ AsyncRAT Ô¶³Ì½Ó¼ûľÂí£¨RAT£©¼°ÆäÐÅÏ¢ÇÔÈ¡²å¼þ Infostealer¡£¡£¡£¡£ ¡£¡£¹¥»÷ʼÓÚÒ»·â¿´ËÆÎÞº¦µÄ´¹µöÓʼþ£¬£¬£¬£¬ £¬£¬ÄÚº¬¼Ù×°³ÉÕý³£ÎļþµÄ¶ñÒâ´æµµ¡£¡£¡£¡£ ¡£¡£Ö´Ðк󣬣¬£¬£¬ £¬£¬ÕâÒ»´æµµ´¥·¢ÁËһϵÁи´ÔÓ²Ù×÷£¬£¬£¬£¬ £¬£¬Ô̺¬ÏÂÔØ²¢Ö´ÐлìºÏµÄ VBScript ºÍ PowerShell ¾ç±¾£¬£¬£¬£¬ £¬£¬×îÖÕ²¿Êð AsyncRAT ¼°Æä²å¼þ¡£¡£¡£¡£ ¡£¡£¹¥»÷¹ý³ÌÖУ¬£¬£¬£¬ £¬£¬¶ñÒâÈí¼þͨ¹ýÏÂÔØ¿´ËÆÎÞº¦µÄͼÏñÎļþ£¨ÊµÎª ZIP ´æµµ£©²¢½âѹ³ö¸ü¶à¶ñÒâ¾ç±¾ºÍ¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬ £¬£¬ÔÚÊܺ¦ÕßϵͳÖÐÔú¸ù¡£¡£¡£¡£ ¡£¡£ËüÀûÓôòË㹤×÷ά³ÖÓÆ¾ÃÐÔ£¬£¬£¬£¬ £¬£¬Ã¿Á½·ÖÖÓÖ´ÐÐÒ»´Î¶ñÒâ´úÂ룬£¬£¬£¬ £¬£¬²¢Í¨¹ý¹ý³Ì¿ÕÐÄ»¯¼¼Êõ½« AsyncRAT ×¢ÈëºÏ·¨¹ý³ÌÖÐÒÔÌӱܼì²â¡£¡£¡£¡£ ¡£¡£AsyncRAT ²»½öΪ¹¥»÷ÕßÌṩ¶ÔÊÜϰȾϵͳµÄÔ¶³Ì½ÚÔìȨ£¬£¬£¬£¬ £¬£¬»¹´îÔØÁË Infostealer ²å¼þ£¬£¬£¬£¬ £¬£¬¸Ã²å¼þרÃŶÔ×¼ÍøÂçä¯ÀÀÆ÷ÖеļÓÃÜÇ®°üÀ©´óºÍ2FAÑéÖ¤¹¤¾ß£¬£¬£¬£¬ £¬£¬Ö¼ÔÚÇÔÈ¡Ô̺¬ÃÜÂ롢ʹ´¦ºÍ¼ÓÃÜÇ®±ÒÇ®°üÔÚÄڵĹóÖØÊý¾Ý¡£¡£¡£¡£ ¡£¡£eSentire TRU ºôÓõÓû§Î¬³Ö¸ß¶È¾¯Ìè¡£¡£¡£¡£ ¡£¡£


https://securityonline.info/evasive-phishing-campaign-delivers-asyncrat-and-infostealer/


5. People Data Labs1.7ÒÚÌõÃô¸ÐÐÅÏ¢ÎÞÃÜÂë¶³ö


8ÔÂ30ÈÕ£¬£¬£¬£¬ £¬£¬Cybernews×êÑÐÍŶӽüÆÚ·¢ÏÖÁËÒ»Ïî³Á´óÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬ £¬£¬Éæ¼°³¬¹ý1.7ÒÚÌõÃô¸ÐÓ×ÎÒÐÅÏ¢ÔÚ»¥ÁªÍøÉϹ«¿ªÂ¶³ö£¬£¬£¬£¬ £¬£¬Êý¾ÝÄÚÈÝÏ꾡£¡£¡£¡£ ¡£¡£¬£¬£¬£¬ £¬£¬Ô̺¬È«Ãû¡¢ÁªÏµ·½Ê½¡¢µØÖ·¡¢½ÌÓý²¼¾°¼°¹¤×÷¾­ÀúµÈ¡£¡£¡£¡£ ¡£¡£Õâ´Îй¶µÄÊý¾Ý¼¯±êÓÓ×°PDL¡±±êʶ£¬£¬£¬£¬ £¬£¬Ö¸Ïò¾É½ðɽµÄÊý¾Ý¾­¼Í¹«Ë¾People Data Labs£¨PDL£©£¬£¬£¬£¬ £¬£¬¸Ã¹«Ë¾×Ô³ÆÕ¼ÓÐ15ÒÚÓ×ÎÒµµ°¸Êý¾Ý¿â£¬£¬£¬£¬ £¬£¬·þÎñÓÚÆóÒµÓªÏú¡¢ÏúÊÛ¼°ÕÐÆ¸µÈÁìÓò¡£¡£¡£¡£ ¡£¡£Ö»¹ÜÊý¾Ýй¶ԴͷÉÐδÃ÷È·£¬£¬£¬£¬ £¬£¬µ«Elasticsearch·þÎñÆ÷δÉèÃÜÂëµÄÑϳÁ°²È«·ì϶³ÉΪ½¹µã£¬£¬£¬£¬ £¬£¬ÕâÖÖÅäÖü«Ò×±»ºÚ¿ÍÀûÓ㬣¬£¬£¬ £¬£¬Ñ¸ËÙÇÔÈ¡Êý¾Ý£¬£¬£¬£¬ £¬£¬¶ÔÓ×ÎÒÒþÖÔ×é³É³Á´óÍþв£¬£¬£¬£¬ £¬£¬Ôö³¤Éí·Ý͵ÇÔ¡¢Ú²Æ­¼°ÍøÂç´¹µö·çÏÕ¡£¡£¡£¡£ ¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬ £¬£¬PDL´ËǰÒѲúÉú¹ýÀàËÆµÄÊý¾Ýй¶±äÂÒ£¬£¬£¬£¬ £¬£¬Í¬ÑùÒòδ±£»£»£»£»£»¤µÄElasticsearch·þÎñÆ÷µ¼Ö£¬£¬£¬£¬ £¬£¬Éæ¼°Êý¾Ý¹æÄ£¸üÎªÖØ´ó¡£¡£¡£¡£ ¡£¡£Õâ´Îй¶µÄ¡°Version 26.2¡±Êý¾Ý¼¯¿ÉÄÜÓë´ËǰÊÂÎñÓйØÁª£¬£¬£¬£¬ £¬£¬Ôٴζ³öÁËPDLÔÚÊý¾Ý°²È«·½ÃæµÄ³Á´óȱµã¡£¡£¡£¡£ ¡£¡£


https://cybernews.com/security/people-data-labs-data-leak/


6. Roblox¿ª·¢ÈËԱƵÔâ¹¥»÷£¬£¬£¬£¬ £¬£¬Î±Ôìnpm°ü´«²¼¶ñÒâÈí¼þ


9ÔÂ2ÈÕ£¬£¬£¬£¬ £¬£¬Roblox ¿ª·¢ÈËÔ±³ÉΪһϵÁжñÒâ¹¥»÷µÄÖ¸±ê£¬£¬£¬£¬ £¬£¬ÕâЩ¹¥»÷ͨ¹ýαÔì npm °ü£¬£¬£¬£¬ £¬£¬ÓÈÆäÊÇ·ÂÕÕÊ¢ÐÐµÄ noblox.js ¿â£¬£¬£¬£¬ £¬£¬Ì°Í¼ÇÔÈ¡Ãô¸ÐÊý¾ÝºÍ·ÛËéϵͳ¡£¡£¡£¡£ ¡£¡£×Ô½ñËêÊ×ÒÔÀ´£¬£¬£¬£¬ £¬£¬¶à¸öÃûΪ noblox.js ±äÖÖµÄÈí¼þ°ü±»È·ÒÔΪ¶ñÒ⣬£¬£¬£¬ £¬£¬Ô̺¬ noblox.js-proxy-server ºÍ noblox-ts£¬£¬£¬£¬ £¬£¬ËüÃÇͨ¹ýÆ·ÅÆ½Ù³Ö¡¢×éºÏÇÀ×¢ºÍÐǺŽٳֵȼ¼Êõ¼Ù×°³ÉºÏ·¨¿â£¬£¬£¬£¬ £¬£¬ÓÕµ¼¿ª·¢ÕßÏÂÔØ¡£¡£¡£¡£ ¡£¡£ÕâЩ¶ñÒâ°üÈç noblox.js-async¡¢noblox.js-thread µÈ£¬£¬£¬£¬ £¬£¬Ö»¹ÜÏÂÔØÁ¿ÓÐÏÞ£¬£¬£¬£¬ £¬£¬È´³É¹¦ºýŪÁËÓû§¡£¡£¡£¡£ ¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬¹¥»÷Õß»¹Ñ¡È¡ starjacking ÊÖ·¨£¬£¬£¬£¬ £¬£¬½«ÐéαÈí¼þ°üµÄÔ´´æ´¢¿âÏóÕ÷ΪÏÖʵ noblox.js ¿â£¬£¬£¬£¬ £¬£¬¼ÓÇ¿ÐÅÀµ¶È¡£¡£¡£¡£ ¡£¡£ÕâЩ¶ñÒâÈí¼þ°üÄÚǶµÄ´úÂë²»½öÇÔÈ¡ Discord ÁîÅÆ£¬£¬£¬£¬ £¬£¬»¹Í¨¹ýÅú¸Ä Windows ×¢²á±íºÍ¸üзÀ²¡¶¾ÅųýÁбíÀ´Ìӱܼì²âºÍά³ÖÓÆ¾ÃÐÔ¡£¡£¡£¡£ ¡£¡£Ã¿µ±Óû§³¢ÊÔ´ò¿ª Windows ÉèÖÃÀûÓÃʱ£¬£¬£¬£¬ £¬£¬¶ñÒâÈí¼þ±ã»á±»¼¤»î¡£¡£¡£¡£ ¡£¡£×îÖÕÖ¸±êÊDz¿Êð Quasar RAT£¬£¬£¬£¬ £¬£¬Ê¹¹¥»÷ÕßÄÜÔ¶³Ì½ÚÔìÊÜϰȾϵͳ£¬£¬£¬£¬ £¬£¬²¢½«ÍøÂçµ½µÄÐÅϢͨ¹ý Discord webhook ·¢ËÍÖÁ C2 ·þÎñÆ÷¡£¡£¡£¡£ ¡£¡£Ö»¹ÜÒÑÓдëÊ©¶Ï¸ùÕâЩ¶ñÒâÈí¼þ£¬£¬£¬£¬ £¬£¬µ«ÐÂÈí¼þ°üÈÔ²»ÐݳöÏÖ£¬£¬£¬£¬ £¬£¬ÌáÐÑ¿ª·¢ÈËÔ±Ðèά³Ö¸ß¶È¾¯Ìè¡£¡£¡£¡£ ¡£¡£


https://thehackernews.com/2024/09/malicious-npm-packages-mimicking.html