SambaSpy¶ñÒâÈí¼þͨ¹ý´¹µöµç×ÓÓʼþ¹¥»÷Òâ´óÀûÓû§

°ä²¼¹¦·ò 2024-09-23
1. SambaSpy¶ñÒâÈí¼þͨ¹ý´¹µöµç×ÓÓʼþ¹¥»÷Òâ´óÀûÓû§


9ÔÂ19ÈÕ£¬£¬£¬ £¬£¬¿¨°Í˹»ù³¢ÊÔÊÒ½üÆÚ¸æ·¢ÁËÒ»Ïî¸ß¶È¶¨Ô컯µÄ¶ñÒâÈí¼þ»î¶¯£¬£¬£¬ £¬£¬ÃûΪSambaSpy£¬£¬£¬ £¬£¬Æä¹ÖÒìÖ®´¦ÔÚÓÚ½öÕë¶ÔÒâ´óÀûÓû§ ¡£¡£¡£¡£¡£¡£¡£Õâ¿îÔ¶³Ì½Ó¼ûľÂí£¨RAT£©Í¨¹ý¼Ù×°³ÉÒâ´óÀû·¿µØ²ú¹«Ë¾µÄºÏ·¨Óʼþ´«²¼£¬£¬£¬ £¬£¬ÓʼþÄÚº¬¿´ËÆÎÞº¦µÄ·¢Æ±²é¿´Á´½Ó£¬£¬£¬ £¬£¬ÊµÔòµ¼Ïò¶ñÒâJARÎļþÏÂÔØ ¡£¡£¡£¡£¡£¡£¡£SambaSpyÀûÓÃ˵»°²é³­»úÔ죬£¬£¬ £¬£¬È·±£½öϰȾÒâ´óÀûÓïϵͳ£¬£¬£¬ £¬£¬Õ¹Ê¾Á˹¥»÷Õߵĸ߶ÈרҵÐԺ;«×¼¶¨Î»ÄÜÁ¦ ¡£¡£¡£¡£¡£¡£¡£Ò»µ©×°Ö㬣¬£¬ £¬£¬SambaSpy¸³Óè¹¥»÷Õß¶ÔÊÜϰȾÉ豸µÄÈ«Ãæ½ÚÔìȨ£¬£¬£¬ £¬£¬Ô̺¬ÎļþÖÎÀí¡¢ÍøÂçÉãÏñÍ·¼à¿Ø¡¢¼üÅ̼ͼ¡¢ÆÁÄ»½ØÍ¼¡¢ä¯ÀÀÆ÷ƾ֤ÇÔÈ¡¼°Ô¶³Ì×ÀÃæ²Ù×÷µÈ ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿ £¿£¿ £¿£¿¨°Í˹»ù×·×Ùµ½Á½ÌõϰȾÁ´£¬£¬£¬ £¬£¬¾ùÀûÓõç×ÓÓʼþ×÷ΪÈëÇÖÃÅ»§£¬£¬£¬ £¬£¬ÆäÖÐÒ»Ìõ¸üΪ¸´ÔÓ£¬£¬£¬ £¬£¬Í¨¹ýºÏ·¨Òâ´óÀûÔÆ·¢Æ±·þÎñFattureInCloud×÷ΪÑÚ»¤£¬£¬£¬ £¬£¬½øÒ»²½ºýŪÊܺ¦Õß ¡£¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬ £¬£¬Ö»¹Ü»î¶¯ÖØÒª¾Û½¹ÓÚÒâ´óÀû£¬£¬£¬ £¬£¬µ«·¢ÏֵİÍÎ÷ÆÏÌÑÑÀÓïºÛ¼£¼°¿çµØÓòÁ´½ÓÅú×¢¹¥»÷Õß¿ÉÄÜÕ¼Óиü¿í·ºµÄÒ°ÐÄ ¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñ²»½ö͹ÏÔÁËÍøÂ簲ȫÍþвµÄÒñ±ÎÐÔÓ븴ÔÓÐÔ£¬£¬£¬ £¬£¬Ò²ÌáÐÑÁËÈ«ÇòÓû§Ðè¼ÓÇ¿·À±¸Òâʶ£¬£¬£¬ £¬£¬³ö¸ñÊÇÕë¶Ô¸ß¶È¶¨Ô컯µÄÍøÂç¹¥»÷ ¡£¡£¡£¡£¡£¡£¡£


https://securityonline.info/sambaspy-rat-targets-italian-users-in-a-unique-malware-campaign/


2. Ivanti CSA 4.6ÑϳÁ·ì϶CVE-2024-8963Òѱ»»ý¼«ÀûÓÃ


9ÔÂ19ÈÕ£¬£¬£¬ £¬£¬ÆóÒµÈí¼þ¾ÞÍ·Ivanti½üÆÚ¸æ·¢ÁËÆäIvanti Connect Secure Appliance£¨CSA£©4.6°æ±¾ÖдæÔÚµÄÒ»¸ö¸ßΣ·ì϶CVE-2024-8963£¬£¬£¬ £¬£¬¸Ã·ì϶ÑϳÁÐÔÆÀ¼¶¸ß´ïCVSS 9.4£¬£¬£¬ £¬£¬ÇÒÒѱ»·¢ÏÖÕý±»¶ñÒâÀûÓ㬣¬£¬ £¬£¬¶ÔʹÓÃÒÑÍ£²ú£¨EOL£©°æ±¾µÄ¿Í»§×é³É³Á´ó°²È«Íþв ¡£¡£¡£¡£¡£¡£¡£´Ë·ì϶Ϊõè¾¶±éÀúÀàÐÍ£¬£¬£¬ £¬£¬ÔÊÐíδÊÚȨԶ³Ì¹¥»÷Õß·¸·¨½Ó¼ûCSA 4.6µÄÊÜÏÞÇøÓò£¬£¬£¬ £¬£¬ÉõÖÁÓëÁíÒ»·ì϶CVE-2024-8190½áºÏʹÓÃʱ£¬£¬£¬ £¬£¬ÄÜÈÆ¹ýÉí·ÝÑéÖ¤Ö´ÐÐËÁÒâºÅÁî ¡£¡£¡£¡£¡£¡£¡£¼øÓÚCSA 4.6ÒÑÖÕ³¡½Ó¹Ü¹Ù·½°²È«¸üУ¬£¬£¬ £¬£¬Ivanti´¹Î£°ä²¼ÁËCSA 4.6²¹¶¡519ÒÔ½¨¸´¸Ã·ì϶£¬£¬£¬ £¬£¬µ«´Ë²¹¶¡±ê־ȡ¶Ô¸Ã°æ±¾µÄ×îºóÒ»´ÎÊØ»¤ ¡£¡£¡£¡£¡£¡£¡£CISAÒѽ«´Ë·ì϶ÁÐΪÒÑÖª±»ÀûÓõķì϶£¬£¬£¬ £¬£¬Ç¿ÁÒ½¨Òé¸÷×é֯ѸËÙÐж¯£¬£¬£¬ £¬£¬²ÉÈ¡²¹¾È´ëÊ© ¡£¡£¡£¡£¡£¡£¡£IvantiÇ¿µ÷£¬£¬£¬ £¬£¬³ýÁËÉý¼¶µ½CSA 5.0°æ±¾±í£¬£¬£¬ £¬£¬²»»áΪ4.6°æ±¾Ìṩ½øÒ»²½²¹¶¡£¬£¬£¬ £¬£¬Òò¶ø£¬£¬£¬ £¬£¬Ö»¹Üһʱ²¹¶¡ÌṩÁË¶ÌÆÚ»º½â£¬£¬£¬ £¬£¬µ«³¤Ô¶À´¿´£¬£¬£¬ £¬£¬Ïòа汾ǨáãÊÇÈ·±£ÏµÍ³°²È«µÄΨһõè¾¶ ¡£¡£¡£¡£¡£¡£¡£


https://securityonline.info/critical-flaw-in-ivanti-csa-4-6-cve-2024-8963-actively-exploited-urgent-upgrade-required/


3. LockBitÀÕË÷Èí¼þÔÙÏ®eFile.com£¬£¬£¬ £¬£¬Êý°ÙÍòÃÀ¹úÈË˰ÎñÊý¾Ý°²È«´¹Î£


9ÔÂ19ÈÕ£¬£¬£¬ £¬£¬ÀÕË÷Èí¼þ×éÖ¯LockBit½üÆÚÔٴν«Ö¸±ê¶Ô×¼ÁËÃÀ¹úÔÚÏß±¨Ë°·þÎñeFile.com£¬£¬£¬ £¬£¬ÕâÊÇÒ»¸ö¾­ÃÀ¹ú¹ú˰¾Ö£¨IRS£©¹Ù·½ÊÚȨµÄ˰ÎñÉ걨ƽ̨ ¡£¡£¡£¡£¡£¡£¡£¾ÝCyber Express±¨Â·£¬£¬£¬ £¬£¬LockBitÒªÇóeFileÔÚ14ÌìÄÚÖ§¸¶Êê½ð£¬£¬£¬ £¬£¬µ«·ÖÆçÓÚͨÀýÀÕË÷Èí¼þ²Ù×÷£¬£¬£¬ £¬£¬Õâ´Î¹¥»÷²¢Î´¹«¿ªÈκα»ÇÔÈ¡Êý¾ÝµÄÑùÀýÀ´Ö¤ÊµÆäÍþв ¡£¡£¡£¡£¡£¡£¡£½ØÖÁĿǰ£¬£¬£¬ £¬£¬¹ØÓÚ¹¥»÷µÄ¾ßÌ广ģ¡¢Êý¾Ýй¶Çé¿ö¼°·¸×ﶯ»úµÄÐÅÏ¢ÈÔ±£ÃÜ£¬£¬£¬ £¬£¬eFile.com¹ÙÍøÔòά³ÖÕý³£ÔË×÷ ¡£¡£¡£¡£¡£¡£¡£Êý°ÙÍòÒÀÀµeFile±¨Ë°µÄÃÀ¹úÈËÃæ¶ÔDZÔÚ·çÏÕ£¬£¬£¬ £¬£¬Ò»µ©¹¥»÷±»È·ÈÏ£¬£¬£¬ £¬£¬ÄÉ˰È˵ÄÓ×ÎҺͲÆÕþÊý¾Ý¿ÖÔâй¶£¬£¬£¬ £¬£¬ÎªÉí·Ý͵ÇÔ¡¢Ë°ÎñڲƭµÈ·¸·¨ÐÐΪÌṩδ² ¡£¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬ £¬£¬eFile²¢·Ç³õ´Î³ÉΪLockBitµÄÁÔÎ£¬£¬ £¬£¬ÔçÔÚ2022Äê˰ÎñÉ걨¶¥·åÆÚ£¬£¬£¬ £¬£¬LockBit¾ÍÔøÐû³ÆÈëÇÖeFile£¬£¬£¬ £¬£¬ÏÔʾ³ö·¸×ï·Ö×Ó¶Ô¸ßÁ÷Á¿Ê±¶ÎµÄ¾«×¼½ø¹¥Òâͼ ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬2023ÄêeFile»¹ÔøÔâ·ê¡°efail¡±¶ñÒâÈí¼þÈëÇÖ£¬£¬£¬ £¬£¬ÀûÓÃÆ½Ì¨·ì϶ÇÔÈ¡Óû§Ãô¸ÐÐÅÏ¢£¬£¬£¬ £¬£¬ÊÂÎñËäʵʱµÃµ½½ÚÔ죬£¬£¬ £¬£¬È´ÔÙ´ÎÇÃÏìÁ˽ðÈÚ·þÎñÍøÂ簲ȫ·À»¤µÄ¾¯ÖÓ ¡£¡£¡£¡£¡£¡£¡£


https://thecyberexpress.com/u-s-taxpayer-data-lockbit-ransomware-efile/


4. Gleaming PiscesÀûÓÃPyPI·Ö·¢PondRATºóÃÅ


9ÔÂ19ÈÕ£¬£¬£¬ £¬£¬Unit 42 ×êÑÐÍŶӸ淢Á˳¯ÏÊ´ÓÊôµÄAPT×éÖ¯Gleaming PiscesÌáÒéµÄÒ»ÏîÐÂÍøÂç¹¥»÷£¬£¬£¬ £¬£¬¸Ã×éÖ¯ÀûÓú¬ÓжñÒâ´úÂëµÄPythonÈí¼þ°ü£¬£¬£¬ £¬£¬Õë¶ÔLinuxºÍmacOSϵͳÌáÒé¹¥»÷ ¡£¡£¡£¡£¡£¡£¡£ÕâЩ¶ñÒâÈí¼þ°üͨ¹ýPyPI´æ´¢¿â·Ö·¢£¬£¬£¬ £¬£¬Ô̺¬¡°real-ids¡±¡¢¡°coloredtxt¡±µÈ£¬£¬£¬ £¬£¬Ò»µ©×°Öü´»á²¿ÊðÃûΪPondRATµÄºóÃÅ·¨Ê½£¬£¬£¬ £¬£¬ËüÊÇPOOLRATµÄÇáÁ¿¼¶°æ±¾£¬£¬£¬ £¬£¬¾ß±¸Ô¶³Ì½ÚÔìÊܺ¦ÕßϵͳµÄÄÜÁ¦ ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýPondRAT¿ÉÉÏ´«ÏÂÔØÎļþ¡¢Ö´ÐкÅÁîÉõÖÁÔÝͣϵͳ²Ù×÷£¬£¬£¬ £¬£¬Æä¿çƽ̨¸öÐÔʹµÃ¹¥»÷ÓÈΪΣÏÕ ¡£¡£¡£¡£¡£¡£¡£Gleaming PiscesÒÔÆäÓë¿úËÅ×ֵܾĹØÁª¼°ÔÚ¼ÓÃÜÇ®±ÒÁìÓòµÄ¸´ÔÓ¹¥»÷»î¶¯Öø³Æ£¬£¬£¬ £¬£¬³ö¸ñÊÇͨ¹ýAppleJeus»î¶¯·Ö·¢¼Ùð¼ÓÃÜÇ®±ÒÈí¼þ ¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ÖУ¬£¬£¬ £¬£¬PondRATÓëAppleJeus¶ñÒâÈí¼þ´æÔÚ´úÂëÀàËÆÐÔ£¬£¬£¬ £¬£¬Åú×¢ÊÇGleaming Pisces³ÖÐøÉøÈ빩¸øÁ´µÄÒ»²¿ÃÅ ¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜPyPIÒÑÒÆ³ýÓйضñÒâ°ü£¬£¬£¬ £¬£¬µ«Öж¾Èí¼þ°üµÄÍþвÈԾɲ»ÈݺöÊÓ ¡£¡£¡£¡£¡£¡£¡£ÎªÓ¦¶Ô´ËÀàÍþв£¬£¬£¬ £¬£¬×éÖ¯Ðè¼ÓÇ¿°²È«´ëÊ©£¬£¬£¬ £¬£¬Ô̺¬ÔÚÒýÈëµÚÈý·½Èí¼þ°üʱ½øÐÐÑϸñµÄ´úÂëÉó²éºÍÑéÖ¤£¬£¬£¬ £¬£¬ÒÔ¼°Ê©×ßÔËÐÐʱ¼à¿Ø ¡£¡£¡£¡£¡£¡£¡£


https://securityonline.info/north-korean-hackers-gleaming-pisces-poisoned-python-packages-target-linux-macos/


5. ÐÂ¼ÓÆÂBingXƽ̨ÔâºÚ¿Í¹¥»÷£¬£¬£¬ £¬£¬Ëðʧ³¬4400ÍòÃÀÔª


9ÔÂ21ÈÕ£¬£¬£¬ £¬£¬ÐÂ¼ÓÆÂ¼ÓÃÜÇ®±ÒÂòÂôƽ̨BingXÖÜÎåÈ·ÈÏ£¬£¬£¬ £¬£¬Æäƽ̨ÔÚÔâ·êÍøÂç¹¥»÷ºó£¬£¬£¬ £¬£¬ËðʧÁ˳¬¹ý4400ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò ¡£¡£¡£¡£¡£¡£¡£ÖÜËÄÍí¼ä£¬£¬£¬ £¬£¬Çø¿éÁ´°²È«¹«Ë¾¼à²âµ½×ʽðÒì³£Á÷¶¯£¬£¬£¬ £¬£¬ËæºóBingX°ä·¢Òò¡°Ç®°üÊØ»¤¡±ÔÝÍ£·þÎñ£¬£¬£¬ £¬£¬²¢°ä²¼ÉêÃ÷³Æ¼ì²âµ½ÈÈÇ®°ü¿ÉÄÜÔâ·êºÚ¿Í¹¥»÷£¬£¬£¬ £¬£¬ÒÑ´¹Î£×ªÒÆ×ʲú²¢ÔÝÍ£Ìá¿î·þÎñ ¡£¡£¡£¡£¡£¡£¡£³õ²½¹ÀËãÏÔʾ£¬£¬£¬ £¬£¬Ö±½ÓËðʧԼΪ4470ÍòÃÀÔª£¬£¬£¬ £¬£¬µ«¾ßÌåÊý¶îÈÔÔÚºËʵÖÐ ¡£¡£¡£¡£¡£¡£¡£BingXÊ×ϯ²úÆ·¹ÙVivien Linͨ¹ýÉ罻ýÌ尵ʾ£¬£¬£¬ £¬£¬¹«Ë¾½«ÓÃ×ÔÓÐ×ʽðÈ«¶îÌí²¹Ëðʧ£¬£¬£¬ £¬£¬²¢Ç¿µ÷ÒµÎñÔËӪδÊÜÓ°Ï죬£¬£¬ £¬£¬Ìá¿îºÍ´æ¿î·þÎñÔ¤¼Æ24Ó×ʱÄÚ¸´Ô­ ¡£¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬ £¬£¬BingXÕýÓëSlowMistºÍChainalysisµÈ°²È«¹«Ë¾ºÏ×÷×·×Ù±»µÁ×ʽ𠡣¡£¡£¡£¡£¡£¡£½üÆÚ£¬£¬£¬ £¬£¬ÑÇÖÞµØÓò¶à¼Ò¼ÓÃÜÆ½Ì¨Æµ·¢°²È«ÊÂÎñ£¬£¬£¬ £¬£¬×ʽ𱻵Á½ð¶î¾Þ´ó£¬£¬£¬ £¬£¬·¨ÂÉ»ú¹¹ÒѼÓÇ¿¶Ô´ËÀà·¸×ïµÄ½ø¹¥Á¦¶È ¡£¡£¡£¡£¡£¡£¡£ÕâһϵÁÐÊÂÎñÔÙ´Î͹ÏÔÁ˼ÓÃÜÇ®±ÒÐÐÒµÔÚ°²È«ÐÔ·½ÃæÃæ¶ÔµÄÌôÕ½ ¡£¡£¡£¡£¡£¡£¡£


https://therecord.media/44-million-stolen-from-crypto-platform-singapore


6. AsyncRAT¶ñÒâÈí¼þ¼Ù×°ÆÆ½âÈí¼þÓÕÆ­Óû§ÏÂÔØ


9ÔÂ21ÈÕ£¬£¬£¬ £¬£¬McAfee Labs½ÒʾÁËÒ»¸öÑϸñµÄÍøÂ簲ȫÇ÷Ïò£ºÍøÂç·¸×ï·Ö×Óͨ¹ý¼Ù×°Ê¢ÐÐÆÆ½âÈí¼þÈçCCleaner¡¢EaseUS Partition MasterµÈ£¬£¬£¬ £¬£¬´«²¼ÃûΪAsyncRATµÄ¶ñÒâÈí¼þ ¡£¡£¡£¡£¡£¡£¡£ÕâЩ¼ÙðÀûÓÃÀûÓÃÁËÓû§×êÓªÃâ·Ñ¸ß¼¶Èí¼þµÄÉúÀí£¬£¬£¬ £¬£¬ÊµÔòÄÚº¬¸´ÔÓµÄÔ¶³Ì½Ó¼ûľÂí ¡£¡£¡£¡£¡£¡£¡£AsyncRATͨ¹ý¾«ÐÄÉè¼ÆµÄ¼Ù×°Õ½Êõ£¬£¬£¬ £¬£¬Ô̺¬Ç¶ÈëºÏ·¨Èí¼þ¿ÉÖ´ÐÐÎļþ£¬£¬£¬ £¬£¬³É¹¦ºýŪÓû§ÏÂÔØ²¢Ö´ÐÐ ¡£¡£¡£¡£¡£¡£¡£×°Öú󣬣¬£¬ £¬£¬¸Ã¶ñÒâÈí¼þ»áÀûÓÃWindows DefenderÅųýÏîºÍ»ìºÏ¼¼Êõ¶ã±Ü¼ì²â£¬£¬£¬ £¬£¬²¢Í¨¹ý»·¾³±äÁ¿²Ù×÷ºÍÒñ±ÎµÄbatÎļþά³Ôìä²Ù×÷²»±»·¢ÏÖ ¡£¡£¡£¡£¡£¡£¡£ÆäÖØÒªÖ÷ÕÅÊdzÉÁ¢¶ÔÊÜϰȾ»úеµÄÔ¶³ÌÏνÓ£¬£¬£¬ £¬£¬Èù¥»÷ÕßÄܽøÐа´¼ü¼Í¼¡¢Êý¾ÝÇÔÈ¡µÈ¶ñÒâ»î¶¯ ¡£¡£¡£¡£¡£¡£¡£AsyncRAT»¹Ñ¡È¡AES½âÃܺÍGzip½âѹËõÀ´°µ²ØÅäÖ㬣¬£¬ £¬£¬¼ÓÇ¿ÆäÒñ±ÎÐÔ ¡£¡£¡£¡£¡£¡£¡£×Ô2024Äê3ÔÂÒÔÀ´£¬£¬£¬ £¬£¬ÕâÖÖÍþвÔÚÈ«ÇòÁìÓòÄÚѸËÙÊæÕ¹£¬£¬£¬ £¬£¬ÏÔʾ³öÍøÂç·¸×ï·Ö×ÓÀûÓÃÓû§ÉúÀíÈõµã´«²¼¶ñÒâÈí¼þµÄ¸ßÃ÷¼¿Á© ¡£¡£¡£¡£¡£¡£¡£


https://securityonline.info/beware-of-fake-downloads-asyncrat-spreads-via-popular-software-cracks/