SambaSpy¶ñÒâÈí¼þͨ¹ý´¹µöµç×ÓÓʼþ¹¥»÷Òâ´óÀûÓû§
°ä²¼¹¦·ò 2024-09-239ÔÂ19ÈÕ£¬£¬£¬£¬£¬¿¨°Í˹»ù³¢ÊÔÊÒ½üÆÚ¸æ·¢ÁËÒ»Ïî¸ß¶È¶¨Ô컯µÄ¶ñÒâÈí¼þ»î¶¯£¬£¬£¬£¬£¬ÃûΪSambaSpy£¬£¬£¬£¬£¬Æä¹ÖÒìÖ®´¦ÔÚÓÚ½öÕë¶ÔÒâ´óÀûÓû§¡£¡£¡£¡£¡£¡£¡£Õâ¿îÔ¶³Ì½Ó¼ûľÂí£¨RAT£©Í¨¹ý¼Ù×°³ÉÒâ´óÀû·¿µØ²ú¹«Ë¾µÄºÏ·¨Óʼþ´«²¼£¬£¬£¬£¬£¬ÓʼþÄÚº¬¿´ËÆÎÞº¦µÄ·¢Æ±²é¿´Á´½Ó£¬£¬£¬£¬£¬ÊµÔòµ¼Ïò¶ñÒâJARÎļþÏÂÔØ¡£¡£¡£¡£¡£¡£¡£SambaSpyÀûÓÃ˵»°²é³»úÔ죬£¬£¬£¬£¬È·±£½öϰȾÒâ´óÀûÓïϵͳ£¬£¬£¬£¬£¬Õ¹Ê¾Á˹¥»÷Õߵĸ߶ÈרҵÐԺ;«×¼¶¨Î»ÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£Ò»µ©×°Ö㬣¬£¬£¬£¬SambaSpy¸³Óè¹¥»÷Õß¶ÔÊÜϰȾÉ豸µÄÈ«Ãæ½ÚÔìȨ£¬£¬£¬£¬£¬Ô̺¬ÎļþÖÎÀí¡¢ÍøÂçÉãÏñÍ·¼à¿Ø¡¢¼üÅ̼ͼ¡¢ÆÁÄ»½ØÍ¼¡¢ä¯ÀÀÆ÷ƾ֤ÇÔÈ¡¼°Ô¶³Ì×ÀÃæ²Ù×÷µÈ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿¨°Í˹»ù×·×Ùµ½Á½ÌõϰȾÁ´£¬£¬£¬£¬£¬¾ùÀûÓõç×ÓÓʼþ×÷ΪÈëÇÖÃÅ»§£¬£¬£¬£¬£¬ÆäÖÐÒ»Ìõ¸üΪ¸´ÔÓ£¬£¬£¬£¬£¬Í¨¹ýºÏ·¨Òâ´óÀûÔÆ·¢Æ±·þÎñFattureInCloud×÷ΪÑÚ»¤£¬£¬£¬£¬£¬½øÒ»²½ºýŪÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬Ö»¹Ü»î¶¯ÖØÒª¾Û½¹ÓÚÒâ´óÀû£¬£¬£¬£¬£¬µ«·¢ÏֵİÍÎ÷ÆÏÌÑÑÀÓïºÛ¼£¼°¿çµØÓòÁ´½ÓÅú×¢¹¥»÷Õß¿ÉÄÜÕ¼Óиü¿í·ºµÄÒ°ÐÄ¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñ²»½ö͹ÏÔÁËÍøÂ簲ȫÍþвµÄÒñ±ÎÐÔÓ븴ÔÓÐÔ£¬£¬£¬£¬£¬Ò²ÌáÐÑÁËÈ«ÇòÓû§Ðè¼ÓÇ¿·À±¸Òâʶ£¬£¬£¬£¬£¬³ö¸ñÊÇÕë¶Ô¸ß¶È¶¨Ô컯µÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£
https://securityonline.info/sambaspy-rat-targets-italian-users-in-a-unique-malware-campaign/
2. Ivanti CSA 4.6ÑϳÁ·ì϶CVE-2024-8963Òѱ»»ý¼«ÀûÓÃ
9ÔÂ19ÈÕ£¬£¬£¬£¬£¬ÆóÒµÈí¼þ¾ÞÍ·Ivanti½üÆÚ¸æ·¢ÁËÆäIvanti Connect Secure Appliance£¨CSA£©4.6°æ±¾ÖдæÔÚµÄÒ»¸ö¸ßΣ·ì϶CVE-2024-8963£¬£¬£¬£¬£¬¸Ã·ì϶ÑϳÁÐÔÆÀ¼¶¸ß´ïCVSS 9.4£¬£¬£¬£¬£¬ÇÒÒѱ»·¢ÏÖÕý±»¶ñÒâÀûÓ㬣¬£¬£¬£¬¶ÔʹÓÃÒÑÍ£²ú£¨EOL£©°æ±¾µÄ¿Í»§×é³É³Á´ó°²È«Íþв¡£¡£¡£¡£¡£¡£¡£´Ë·ì϶Ϊõè¾¶±éÀúÀàÐÍ£¬£¬£¬£¬£¬ÔÊÐíδÊÚȨԶ³Ì¹¥»÷Õß·¸·¨½Ó¼ûCSA 4.6µÄÊÜÏÞÇøÓò£¬£¬£¬£¬£¬ÉõÖÁÓëÁíÒ»·ì϶CVE-2024-8190½áºÏʹÓÃʱ£¬£¬£¬£¬£¬ÄÜÈÆ¹ýÉí·ÝÑéÖ¤Ö´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£¼øÓÚCSA 4.6ÒÑÖÕ³¡½Ó¹Ü¹Ù·½°²È«¸üУ¬£¬£¬£¬£¬Ivanti´¹Î£°ä²¼ÁËCSA 4.6²¹¶¡519ÒÔ½¨¸´¸Ã·ì϶£¬£¬£¬£¬£¬µ«´Ë²¹¶¡±ê־ȡ¶Ô¸Ã°æ±¾µÄ×îºóÒ»´ÎÊØ»¤¡£¡£¡£¡£¡£¡£¡£CISAÒѽ«´Ë·ì϶ÁÐΪÒÑÖª±»ÀûÓõķì϶£¬£¬£¬£¬£¬Ç¿ÁÒ½¨Òé¸÷×é֯ѸËÙÐж¯£¬£¬£¬£¬£¬²ÉÈ¡²¹¾È´ëÊ©¡£¡£¡£¡£¡£¡£¡£IvantiÇ¿µ÷£¬£¬£¬£¬£¬³ýÁËÉý¼¶µ½CSA 5.0°æ±¾±í£¬£¬£¬£¬£¬²»»áΪ4.6°æ±¾Ìṩ½øÒ»²½²¹¶¡£¬£¬£¬£¬£¬Òò¶ø£¬£¬£¬£¬£¬Ö»¹Üһʱ²¹¶¡ÌṩÁË¶ÌÆÚ»º½â£¬£¬£¬£¬£¬µ«³¤Ô¶À´¿´£¬£¬£¬£¬£¬Ïòа汾ǨáãÊÇÈ·±£ÏµÍ³°²È«µÄΨһõè¾¶¡£¡£¡£¡£¡£¡£¡£
https://securityonline.info/critical-flaw-in-ivanti-csa-4-6-cve-2024-8963-actively-exploited-urgent-upgrade-required/
3. LockBitÀÕË÷Èí¼þÔÙÏ®eFile.com£¬£¬£¬£¬£¬Êý°ÙÍòÃÀ¹úÈË˰ÎñÊý¾Ý°²È«´¹Î£
9ÔÂ19ÈÕ£¬£¬£¬£¬£¬ÀÕË÷Èí¼þ×éÖ¯LockBit½üÆÚÔٴν«Ö¸±ê¶Ô×¼ÁËÃÀ¹úÔÚÏß±¨Ë°·þÎñeFile.com£¬£¬£¬£¬£¬ÕâÊÇÒ»¸ö¾ÃÀ¹ú¹ú˰¾Ö£¨IRS£©¹Ù·½ÊÚȨµÄ˰ÎñÉ걨ƽ̨¡£¡£¡£¡£¡£¡£¡£¾ÝCyber Express±¨Â·£¬£¬£¬£¬£¬LockBitÒªÇóeFileÔÚ14ÌìÄÚÖ§¸¶Êê½ð£¬£¬£¬£¬£¬µ«·ÖÆçÓÚͨÀýÀÕË÷Èí¼þ²Ù×÷£¬£¬£¬£¬£¬Õâ´Î¹¥»÷²¢Î´¹«¿ªÈκα»ÇÔÈ¡Êý¾ÝµÄÑùÀýÀ´Ö¤ÊµÆäÍþв¡£¡£¡£¡£¡£¡£¡£½ØÖÁĿǰ£¬£¬£¬£¬£¬¹ØÓÚ¹¥»÷µÄ¾ßÌ广ģ¡¢Êý¾Ýй¶Çé¿ö¼°·¸×ﶯ»úµÄÐÅÏ¢ÈÔ±£ÃÜ£¬£¬£¬£¬£¬eFile.com¹ÙÍøÔòά³ÖÕý³£ÔË×÷¡£¡£¡£¡£¡£¡£¡£Êý°ÙÍòÒÀÀµeFile±¨Ë°µÄÃÀ¹úÈËÃæ¶ÔDZÔÚ·çÏÕ£¬£¬£¬£¬£¬Ò»µ©¹¥»÷±»È·ÈÏ£¬£¬£¬£¬£¬ÄÉ˰È˵ÄÓ×ÎҺͲÆÕþÊý¾Ý¿ÖÔâй¶£¬£¬£¬£¬£¬ÎªÉí·Ý͵ÇÔ¡¢Ë°ÎñڲƵȷ¸·¨ÐÐΪÌṩδ²¡£¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬eFile²¢·Ç³õ´Î³ÉΪLockBitµÄÁÔÎ£¬£¬£¬£¬ÔçÔÚ2022Äê˰ÎñÉ걨¶¥·åÆÚ£¬£¬£¬£¬£¬LockBit¾ÍÔøÐû³ÆÈëÇÖeFile£¬£¬£¬£¬£¬ÏÔʾ³ö·¸×ï·Ö×Ó¶Ô¸ßÁ÷Á¿Ê±¶ÎµÄ¾«×¼½ø¹¥Òâͼ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬2023ÄêeFile»¹ÔøÔâ·ê¡°efail¡±¶ñÒâÈí¼þÈëÇÖ£¬£¬£¬£¬£¬ÀûÓÃÆ½Ì¨·ì϶ÇÔÈ¡Óû§Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬ÊÂÎñËäʵʱµÃµ½½ÚÔ죬£¬£¬£¬£¬È´ÔÙ´ÎÇÃÏìÁ˽ðÈÚ·þÎñÍøÂ簲ȫ·À»¤µÄ¾¯ÖÓ¡£¡£¡£¡£¡£¡£¡£
https://thecyberexpress.com/u-s-taxpayer-data-lockbit-ransomware-efile/
4. Gleaming PiscesÀûÓÃPyPI·Ö·¢PondRATºóÃÅ
9ÔÂ19ÈÕ£¬£¬£¬£¬£¬Unit 42 ×êÑÐÍŶӸ淢Á˳¯ÏÊ´ÓÊôµÄAPT×éÖ¯Gleaming PiscesÌáÒéµÄÒ»ÏîÐÂÍøÂç¹¥»÷£¬£¬£¬£¬£¬¸Ã×éÖ¯ÀûÓú¬ÓжñÒâ´úÂëµÄPythonÈí¼þ°ü£¬£¬£¬£¬£¬Õë¶ÔLinuxºÍmacOSϵͳÌáÒé¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÕâЩ¶ñÒâÈí¼þ°üͨ¹ýPyPI´æ´¢¿â·Ö·¢£¬£¬£¬£¬£¬Ô̺¬¡°real-ids¡±¡¢¡°coloredtxt¡±µÈ£¬£¬£¬£¬£¬Ò»µ©×°Öü´»á²¿ÊðÃûΪPondRATµÄºóÃÅ·¨Ê½£¬£¬£¬£¬£¬ËüÊÇPOOLRATµÄÇáÁ¿¼¶°æ±¾£¬£¬£¬£¬£¬¾ß±¸Ô¶³Ì½ÚÔìÊܺ¦ÕßϵͳµÄÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýPondRAT¿ÉÉÏ´«ÏÂÔØÎļþ¡¢Ö´ÐкÅÁîÉõÖÁÔÝͣϵͳ²Ù×÷£¬£¬£¬£¬£¬Æä¿çƽ̨¸öÐÔʹµÃ¹¥»÷ÓÈΪΣÏÕ¡£¡£¡£¡£¡£¡£¡£Gleaming PiscesÒÔÆäÓë¿úËÅ×ֵܾĹØÁª¼°ÔÚ¼ÓÃÜÇ®±ÒÁìÓòµÄ¸´ÔÓ¹¥»÷»î¶¯Öø³Æ£¬£¬£¬£¬£¬³ö¸ñÊÇͨ¹ýAppleJeus»î¶¯·Ö·¢¼Ùð¼ÓÃÜÇ®±ÒÈí¼þ¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ÖУ¬£¬£¬£¬£¬PondRATÓëAppleJeus¶ñÒâÈí¼þ´æÔÚ´úÂëÀàËÆÐÔ£¬£¬£¬£¬£¬Åú×¢ÊÇGleaming Pisces³ÖÐøÉøÈ빩¸øÁ´µÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜPyPIÒÑÒÆ³ýÓйضñÒâ°ü£¬£¬£¬£¬£¬µ«Öж¾Èí¼þ°üµÄÍþвÈԾɲ»ÈݺöÊÓ¡£¡£¡£¡£¡£¡£¡£ÎªÓ¦¶Ô´ËÀàÍþв£¬£¬£¬£¬£¬×éÖ¯Ðè¼ÓÇ¿°²È«´ëÊ©£¬£¬£¬£¬£¬Ô̺¬ÔÚÒýÈëµÚÈý·½Èí¼þ°üʱ½øÐÐÑϸñµÄ´úÂëÉó²éºÍÑéÖ¤£¬£¬£¬£¬£¬ÒÔ¼°Ê©×ßÔËÐÐʱ¼à¿Ø¡£¡£¡£¡£¡£¡£¡£
https://securityonline.info/north-korean-hackers-gleaming-pisces-poisoned-python-packages-target-linux-macos/
5. ÐÂ¼ÓÆÂBingXƽ̨ÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬Ëðʧ³¬4400ÍòÃÀÔª
9ÔÂ21ÈÕ£¬£¬£¬£¬£¬ÐÂ¼ÓÆÂ¼ÓÃÜÇ®±ÒÂòÂôƽ̨BingXÖÜÎåÈ·ÈÏ£¬£¬£¬£¬£¬Æäƽ̨ÔÚÔâ·êÍøÂç¹¥»÷ºó£¬£¬£¬£¬£¬ËðʧÁ˳¬¹ý4400ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£¡£ÖÜËÄÍí¼ä£¬£¬£¬£¬£¬Çø¿éÁ´°²È«¹«Ë¾¼à²âµ½×ʽðÒì³£Á÷¶¯£¬£¬£¬£¬£¬ËæºóBingX°ä·¢Òò¡°Ç®°üÊØ»¤¡±ÔÝÍ£·þÎñ£¬£¬£¬£¬£¬²¢°ä²¼ÉêÃ÷³Æ¼ì²âµ½ÈÈÇ®°ü¿ÉÄÜÔâ·êºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬ÒÑ´¹Î£×ªÒÆ×ʲú²¢ÔÝÍ£Ìá¿î·þÎñ¡£¡£¡£¡£¡£¡£¡£³õ²½¹ÀËãÏÔʾ£¬£¬£¬£¬£¬Ö±½ÓËðʧԼΪ4470ÍòÃÀÔª£¬£¬£¬£¬£¬µ«¾ßÌåÊý¶îÈÔÔÚºËʵÖС£¡£¡£¡£¡£¡£¡£BingXÊ×ϯ²úÆ·¹ÙVivien Linͨ¹ýÉ罻ýÌ尵ʾ£¬£¬£¬£¬£¬¹«Ë¾½«ÓÃ×ÔÓÐ×ʽðÈ«¶îÌí²¹Ëðʧ£¬£¬£¬£¬£¬²¢Ç¿µ÷ÒµÎñÔËӪδÊÜÓ°Ï죬£¬£¬£¬£¬Ìá¿îºÍ´æ¿î·þÎñÔ¤¼Æ24Ó×ʱÄÚ¸´Ô¡£¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬BingXÕýÓëSlowMistºÍChainalysisµÈ°²È«¹«Ë¾ºÏ×÷×·×Ù±»µÁ×ʽ𡣡£¡£¡£¡£¡£¡£½üÆÚ£¬£¬£¬£¬£¬ÑÇÖÞµØÓò¶à¼Ò¼ÓÃÜÆ½Ì¨Æµ·¢°²È«ÊÂÎñ£¬£¬£¬£¬£¬×ʽ𱻵Á½ð¶î¾Þ´ó£¬£¬£¬£¬£¬·¨ÂÉ»ú¹¹ÒѼÓÇ¿¶Ô´ËÀà·¸×ïµÄ½ø¹¥Á¦¶È¡£¡£¡£¡£¡£¡£¡£ÕâһϵÁÐÊÂÎñÔÙ´Î͹ÏÔÁ˼ÓÃÜÇ®±ÒÐÐÒµÔÚ°²È«ÐÔ·½ÃæÃæ¶ÔµÄÌôÕ½¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/44-million-stolen-from-crypto-platform-singapore
6. AsyncRAT¶ñÒâÈí¼þ¼Ù×°ÆÆ½âÈí¼þÓÕÆÓû§ÏÂÔØ
9ÔÂ21ÈÕ£¬£¬£¬£¬£¬McAfee Labs½ÒʾÁËÒ»¸öÑϸñµÄÍøÂ簲ȫÇ÷Ïò£ºÍøÂç·¸×ï·Ö×Óͨ¹ý¼Ù×°Ê¢ÐÐÆÆ½âÈí¼þÈçCCleaner¡¢EaseUS Partition MasterµÈ£¬£¬£¬£¬£¬´«²¼ÃûΪAsyncRATµÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£ÕâЩ¼ÙðÀûÓÃÀûÓÃÁËÓû§×êÓªÃâ·Ñ¸ß¼¶Èí¼þµÄÉúÀí£¬£¬£¬£¬£¬ÊµÔòÄÚº¬¸´ÔÓµÄÔ¶³Ì½Ó¼ûľÂí¡£¡£¡£¡£¡£¡£¡£AsyncRATͨ¹ý¾«ÐÄÉè¼ÆµÄ¼Ù×°Õ½Êõ£¬£¬£¬£¬£¬Ô̺¬Ç¶ÈëºÏ·¨Èí¼þ¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬³É¹¦ºýŪÓû§ÏÂÔØ²¢Ö´ÐС£¡£¡£¡£¡£¡£¡£×°Öú󣬣¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ»áÀûÓÃWindows DefenderÅųýÏîºÍ»ìºÏ¼¼Êõ¶ã±Ü¼ì²â£¬£¬£¬£¬£¬²¢Í¨¹ý»·¾³±äÁ¿²Ù×÷ºÍÒñ±ÎµÄbatÎļþά³Ôìä²Ù×÷²»±»·¢ÏÖ¡£¡£¡£¡£¡£¡£¡£ÆäÖØÒªÖ÷ÕÅÊdzÉÁ¢¶ÔÊÜϰȾ»úеµÄÔ¶³ÌÏνӣ¬£¬£¬£¬£¬Èù¥»÷ÕßÄܽøÐа´¼ü¼Í¼¡¢Êý¾ÝÇÔÈ¡µÈ¶ñÒâ»î¶¯¡£¡£¡£¡£¡£¡£¡£AsyncRAT»¹Ñ¡È¡AES½âÃܺÍGzip½âѹËõÀ´°µ²ØÅäÖ㬣¬£¬£¬£¬¼ÓÇ¿ÆäÒñ±ÎÐÔ¡£¡£¡£¡£¡£¡£¡£×Ô2024Äê3ÔÂÒÔÀ´£¬£¬£¬£¬£¬ÕâÖÖÍþвÔÚÈ«ÇòÁìÓòÄÚѸËÙÊæÕ¹£¬£¬£¬£¬£¬ÏÔʾ³öÍøÂç·¸×ï·Ö×ÓÀûÓÃÓû§ÉúÀíÈõµã´«²¼¶ñÒâÈí¼þµÄ¸ßÃ÷¼¿Á©¡£¡£¡£¡£¡£¡£¡£
https://securityonline.info/beware-of-fake-downloads-asyncrat-spreads-via-popular-software-cracks/


¾©¹«Íø°²±¸11010802024551ºÅ