ºÚ¿ÍÀûÓÃ˼¿ÆSNMP·ì϶ÔÚ»¥»»»úÉϲ¿Êðrootkit

°ä²¼¹¦·ò 2025-10-20

1. ºÚ¿ÍÀûÓÃ˼¿ÆSNMP·ì϶ÔÚ»¥»»»úÉϲ¿Êðrootkit


10ÔÂ16ÈÕ £¬£¬£¬£¬£¬£¬ÍøÂ簲ȫ¹«Ë¾Ç÷Ïò¿Æ¼¼Åû¶ £¬£¬£¬£¬£¬£¬ÍþвÐÐΪÕßÕýÀûÓÃ˼¿ÆIOS/IOS XEϵͳÖÐÒѽ¨²¹µÄÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2025-20352 £¬£¬£¬£¬£¬£¬Õë¶Ô9400¡¢9300¼°´«Í³3750GϵÁÐδ²¿Êð¶Ëµã¼ì²âÏìÓ¦½â¾ö¹æ»®µÄÉ豸ÌáÒé¹¥»÷¡£ ¡£¡£¡£¡£¡£¡£¸Ã·ìÏ¶Éæ¼°SNMPºÍ̸ £¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý»ñÈ¡rootȨÏÞ¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ £¬£¬£¬£¬£¬£¬Ë¼¿ÆÒÑÔÚ10ÔÂ6ÈÕ¸üв¼¸æÖн«ÆäÏóÕ÷ΪÁãÈÕ·ì϶²¢È·ÈÏ´æÔڳɹ¦ÀûÓð¸Àý¡£ ¡£¡£¡£¡£¡£¡£¹¥»÷±»×·×ÙΪ"Operation Zero Disco" £¬£¬£¬£¬£¬£¬ÒòÖ²Èë¶ñÒâÈí¼þʱÉèÖÃÁËÔ̺¬"disco"µÄͨÓýӼûÃÜÂë¡£ ¡£¡£¡£¡£¡£¡£×êÑÐÏÔʾ £¬£¬£¬£¬£¬£¬¹¥»÷Õß²»½öÀûÓÃзì϶ £¬£¬£¬£¬£¬£¬»¹³¢ÊÔ¸´ÓÃÆßÄêǰ¾É·ì϶CVE-2017-3881À©´ó¹¥»÷Ãæ¡£ ¡£¡£¡£¡£¡£¡£³É¹¦ÉøÈëºó £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÖ¸±êϵͳ²¿Êð¾ß±¸Óƾû¯ÄÜÁ¦µÄLinux Rootkit £¬£¬£¬£¬£¬£¬¸Ã¹¤¾ß°ü¼¯³ÉUDP½ÚÔìÆ÷ £¬£¬£¬£¬£¬£¬¿ÉʵÏֶ˿ڼàÌý¡¢ÈÕÖ¾´Û¸Ä¡¢ÈƹýAAAÈÏÖ¤ºÍVTY½Ó¼û½ÚÔìÁÐ±í¡¢¶¯Ì¬Åú¸ÄͨÓÃÃÜÂë¡¢°µ²ØÅäÖÃÏî¼°³ÁÖù¦·ò´ÁµÈ²Ù×÷¡£ ¡£¡£¡£¡£¡£¡£×êÑÐÈËԱǿµ÷ £¬£¬£¬£¬£¬£¬µ±Ç°²»×ã¿¿µÃס¹¤¾ßÏóÕ÷ÊÜϰȾÉ豸 £¬£¬£¬£¬£¬£¬½¨ÒéÒÉ»óÔâÈëÇÖµÄ×éÖ¯Ö´Ðеͼ¶¹Ì¼þ¼°ROMÇøÓòÉî¶Èµ÷²é¡£ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-cisco-snmp-flaw-to-deploy-rootkit-on-switches/


2. µÃ¿ËÈøË¹ÖݵçÁ¦ºÏ×÷ÉçÔâ¡°÷è÷롱ÀÕË÷Èí¼þ¹¥»÷


10ÔÂ14ÈÕ £¬£¬£¬£¬£¬£¬ÍøÂç·¸×ïÍŻ÷è÷롱£¨Qilin£©ÔÚ°µÍøÐ¹Â¶ÍøÕ¾Ðû³ÆÒÑÈëÇֵÿËÈøË¹ÖÝÁ½¼ÒµçÁ¦·ÖÏúºÏ×÷Éç £¬£¬£¬£¬£¬£¬Ê¥²®ÄɵµçÁ¦ºÏ×÷ÉçÓ뿨¶÷˹µçÁ¦ºÏ×÷Éç £¬£¬£¬£¬£¬£¬²¢Ð¹Â¼ûô¸Ð²ÆÕþÎļþ¡£ ¡£¡£¡£¡£¡£¡£Ê¥²®ÄɵºÏ×÷ÉçÕ¼ÓÐ3900Ó¢ÀïÅäµçÏß· £¬£¬£¬£¬£¬£¬·þÎñ8ÏØÔ¼2.8Íò»§¼ÒÍ¥ £¬£¬£¬£¬£¬£¬ÄêÊÕÈë9250ÍòÃÀÔª£»£»£»£»£»£»£»¿¨¶÷˹ºÏ×÷ÉçÔËÓª½ü5000Ó¢ÀïÏß· £¬£¬£¬£¬£¬£¬¸²¸Ç12ÏØ2.3Íò»§¼ÒÍ¥ £¬£¬£¬£¬£¬£¬ÄêÊÕÈë7580ÍòÃÀÔª¡£ ¡£¡£¡£¡£¡£¡£Á½¼Ò»ú¹¹¾ùÊôÃÀ¹ú¹Ø¼ü»ù´¡ÉèÊ© £¬£¬£¬£¬£¬£¬Æä°²È«Ö±½Ó¹ØÏµ¹ú¶È°²È«¡£ ¡£¡£¡£¡£¡£¡£¡°÷è÷롱ÔÚÐ¹Â¶ÍøÕ¾°ä²¼ÁËÊý¾ÝÑù±¾ £¬£¬£¬£¬£¬£¬Ô̺¬Ê¥²®Äɵµijõ´ÎÊÂÎñ»ã±¨£¨º¬ÈËԱȫÃû¡¢µç»°¼°ÊÂÎñÏêÇ飩¡¢Äê¶ÈÔ¤Ëã¡¢±£ÏÕÎļþ¡¢·ÑÂʰ¸ÓöȻ㱨µÈ£»£»£»£»£»£»£»¿¨¶÷˹·½ÃæÔòй¶Á˶­Ê»á³ÉÔ±Ãûµ¥£¨º¬µØÖ·¡¢ÁªÏµ·½Ê½£©¡¢³öÈëÓà¶î»ã±¨¡¢×éÖ¯³ÉÔ±Êý¾ÝµÈ¡£ ¡£¡£¡£¡£¡£¡£Ö»¹ÜÊý¾ÝÕæÊµÐÔÉÐδºËʵ £¬£¬£¬£¬£¬£¬µ«ÈôÊôʵ £¬£¬£¬£¬£¬£¬½«Â¶³öÆóÒµ¶¨¼ÛÕ½Êõ¡¢Òý·¢ÐÅÀµÎ£»£»£»£»£»£»£»ú»ò¾ºÕùÁÓÊÆ £¬£¬£¬£¬£¬£¬Ó×ÎÒÉí·ÝÐÅÏ¢£¨PII£©¸ü¿ÉÄܱ»ÓÃÓÚÉí·Ý͵ÇÔ¡¢É§Èż°Éç»á¹¤³Ì¹¥»÷ £¬£¬£¬£¬£¬£¬ÓÈÆä¶Ô¶­Ê»á³ÉÔ±·çÏÕ¼«¸ß¡£ ¡£¡£¡£¡£¡£¡£


https://cybernews.com/security/texas-electric-coops-ransomware-attack/


3. F5Åû¶³Á´ó°²È«·ì϶ £¬£¬£¬£¬£¬£¬È«Çò³¬26ÍòBIG-IPÉè±¸Ãæ¶Ô·çÏÕ


10ÔÂ17ÈÕ £¬£¬£¬£¬£¬£¬ÍøÂ簲ȫ¹«Ë¾F5½üÈÕÅû¶ £¬£¬£¬£¬£¬£¬·ÇͶ»ú×éÖ¯Shadowserver Foundation·¢ÏÖÈ«Çò³¬¹ý26.6Íò¸öF5 BIG-IPÊ·ý¶³öÓÚ»¥ÁªÍø £¬£¬£¬£¬£¬£¬ÆäÖÐÃÀ¹úÕ¼14.2Íò¸ö £¬£¬£¬£¬£¬£¬Å·ÖÞºÍÑÇÖÞ¹²Ô¼10Íò¸ö¡£ ¡£¡£¡£¡£¡£¡£F5֤ʵÆäÍøÂçÔâ¹ú¶ÈºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬£¬ÇÔÈ¡ÁËδ¹«¿ªµÄBIG-IP°²È«·ì϶Դ´úÂë¼°ÓйØÐÅÏ¢ £¬£¬£¬£¬£¬£¬µ«Î´·¢ÏÖ¹¥»÷ÕßÀûÓÃÕâЩ·ì϶µÄÖ¤¾Ý¡£ ¡£¡£¡£¡£¡£¡£ÎªÓ¦¶ÔÍþв £¬£¬£¬£¬£¬£¬F5´¹Î£°ä²¼²¹¶¡½¨¸´44¸ö·ì϶£¨º¬±»ÇÔÈ¡·ì϶£© £¬£¬£¬£¬£¬£¬²¢¶½´Ù¿Í»§¸üÐÂBIG-IP¡¢F5OS¡¢BIG-IP Next for KubernetesµÈϵÁвúÆ·¡£ ¡£¡£¡£¡£¡£¡£F5 »¹Ò»ÏòÔÚÓëÆä¿Í»§·ÖÏíÒ»·ÝÍþвËÑË÷Ö¸ÄÏ £¬£¬£¬£¬£¬£¬Éæ¼°BrickstormºóÃÅ·¨Ê½¼°UNC5291Íþв×éÖ¯¡£ ¡£¡£¡£¡£¡£¡£ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Í¬²½°ä²¼´¹Î£Ö¸Áî £¬£¬£¬£¬£¬£¬ÒªÇóÁª¹ú»ú¹¹ÔÚ10ÔÂ22ÈÕǰΪF5OS¡¢BIG-IP TMOS¡¢BIG-IQºÍBNK/CNF²úÆ·×°ÖÃ×îв¹¶¡ £¬£¬£¬£¬£¬£¬²¢½«ÆäËûF5É豸µÄ¸üнØÖ¹ÈÕÆÚµ¢¸éÖÁ10ÔÂ31ÈÕ¡£ ¡£¡£¡£¡£¡£¡£CISAÇ¿µ÷ £¬£¬£¬£¬£¬£¬»ú¹¹ÐèÅ̵ãËùÓÐF5 BIG-IPÉ豸 £¬£¬£¬£¬£¬£¬ÆÀ¹ÀÍøÂçÖÎÀí½Ó¿ÚµÄ»¥ÁªÍøÂ¶³öÇé¿ö £¬£¬£¬£¬£¬£¬²¢Í£ÓÃÒÑÖÕÖ¹Ö§³ÖµÄÉ豸¡£ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/over-266-000-f5-big-ip-instances-exposed-to-remote-attacks/


4. Å·ÖÞµ·»Ù¿ç¹ú·¸·¨SIM¿¨ºÐÍøÂç £¬£¬£¬£¬£¬£¬ÆÆ»ñ³¬3200Æðڲƭ°¸


10ÔÂ17ÈÕ £¬£¬£¬£¬£¬£¬Å·ÖÞÐ̾¯×éÖ¯½áºÏ¶à¹ú·¨Âɲ¿ÃÅ·¢Õ¹µÄ"SIMCARTEL"Ðж¯ÖÐ £¬£¬£¬£¬£¬£¬³É¹¦µ·»ÙÒ»¸öÉæ¼°80Óà¹úµÄ·¸·¨SIM¿¨ºÐ·þÎñÍøÂç¡£ ¡£¡£¡£¡£¡£¡£¸Ã·¸×ï×éÖ¯ÔËÓªgogetsms.comºÍapisim.comÁ½¸öÍøÕ¾ £¬£¬£¬£¬£¬£¬²¿Êð1,200̨SIMºÐÉ豸¼°40,000ÕÅSIM¿¨ £¬£¬£¬£¬£¬£¬ÎªÈ«Çò·¸×ï·Ö×ÓÌṩÐéαµç»°ºÅÂëÒÔ´´½¨ºÍÑé֤ڲƭÐÔÔÚÏßÕË»§ £¬£¬£¬£¬£¬£¬ÓÃÓÚÖ´ÐÐÍøÂç´¹µö¡¢Í¶×ÊÚ¿Æ­¡¢¼ÙÒ⹫¼ì·¨¡¢ÀÕË÷¼°ÍµÔËÒÆÃñµÈ·¸×ï»î¶¯¡£ ¡£¡£¡£¡£¡£¡£¾ÝÅ·ÖÞÐ̾¯×éÖ¯´«µÝ £¬£¬£¬£¬£¬£¬¸Ã·þÎñÖ±½Ó¹ØÁª°ÂµØÀû1,700Æð¡¢À­ÍÑάÑÇ1,500Æðڲƭ°¸¼þ £¬£¬£¬£¬£¬£¬ÀÛ¼ÆÔì³É¾­¼ÃËðʧ³¬450ÍòÅ·Ôª¡£ ¡£¡£¡£¡£¡£¡£Æä¼¼Êõ¼Ü¹¹¸´ÔÓ £¬£¬£¬£¬£¬£¬¿É°µ²ØÓû§ÕæÊµÉí·ÝºÍµØÎ» £¬£¬£¬£¬£¬£¬Öú³¤´´½¨4,900Íò¸öÐéÎ±ÍøÂçÕË»§ £¬£¬£¬£¬£¬£¬Éæ¼°µçÐÅÚ¿Æ­¡¢WhatsApp"Ç×ÊôÚ¿Æ­"¡¢ÐéαͶ×ÊÆ½Ì¨Ú¿Æ­µÈ¶àÖÖ·¸×ï״̬¡£ ¡£¡£¡£¡£¡£¡£10ÔÂ10ÈÕÐж¯ÖÐ £¬£¬£¬£¬£¬£¬¾¯·½ÔڰµØÀû¡¢°®É³ÄáÑÇ¡¢·ÒÀ¼¡¢À­ÍÑάÑÇËĹúͬ²½·¢Õ¹26´ÎËÑ²é £¬£¬£¬£¬£¬£¬¿ÛÁô5ÃûÀ­ÍÑάÑǼ®Ö÷·¸¼°2Ãû¹²·¸ £¬£¬£¬£¬£¬£¬½É»ñ¼ÛÖµÊý°ÙÍòÅ·ÔªµÄ×ʲú£ºÔ̺¬1,200̨SIMºÐÉ豸¡¢ÊýÊ®ÍòÕÅSIM¿¨¡¢5̨·þÎñÆ÷¡¢¶³½áÒøÐÐÕË»§43.1ÍòÅ·Ôª¼°¼ÓÃÜÇ®±ÒÕË»§33.3ÍòÃÀÔª £¬£¬£¬£¬£¬£¬²¢¿ÛѺ4Á¾ºÀ»ª³µ¡£ ¡£¡£¡£¡£¡£¡£Ä¿Ç° £¬£¬£¬£¬£¬£¬±»²é·âµÄ·þÎñÆ÷Õý½øÐÐȡ֤·ÖÎöÒÔ×·Òä¿Í»§Éí·Ý¡£ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/europol-dismantles-sim-box-operation-renting-numbers-for-cybercrime/


5. ÃÀ¹úº½¿Õ×Ó¹«Ë¾Envoy AirÔâClopÀÕË÷ÍŻ﹥»÷


10ÔÂ17ÈÕ £¬£¬£¬£¬£¬£¬ÃÀ¹úº½¿ÕÆìÏÂÇøÓòº½¿Õ¹«Ë¾Envoy Air֤ʵ £¬£¬£¬£¬£¬£¬ÆäOracle E-Business SuiteÀûÓ÷¨Ê½Êý¾ÝÔâClopÀÕË÷ÍÅ»ïй¶¡£ ¡£¡£¡£¡£¡£¡£Envoy Air°µÊ¾ £¬£¬£¬£¬£¬£¬µ÷²éºóÈ·ÈϽöÉÙÁ¿Ã³Ò×ÐÅÏ¢¼°ÁªÏµ·½Ê½±íй £¬£¬£¬£¬£¬£¬ÎÞÃô¸Ð»ò¿Í»§Êý¾ÝÊÜÓ°Ïì¡£ ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒÑÁªÏµ·¨Âɲ¿ÃŲ¢·¢Õ¹È«ÃæÉó²é¡£ ¡£¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñÓëClopÍÅ»ï8ÔÂÆô¶¯µÄÊý¾Ý͵ÇԻÓÐ¹Ø £¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïͨ¹ýµç×ÓÓʼþÏòÊܺ¦ÆóÒµ·¢ËÍÀÕË÷ÒªÇó £¬£¬£¬£¬£¬£¬Ðû³ÆÇÔÈ¡ÁËOracle EBSϵͳÖеÄÊý¾Ý¡£ ¡£¡£¡£¡£¡£¡£OracleÅû¶ £¬£¬£¬£¬£¬£¬¹¥»÷ÀûÓÃÁ˱àºÅΪCVE-2025-61882ºÍCVE-2025-61884µÄÁãÈÕ·ì϶ £¬£¬£¬£¬£¬£¬ÆäÖÐCVE-2025-61884ÓÚÉÏÖܱ»ÍµÍµ½¨²¹ £¬£¬£¬£¬£¬£¬µ«Î´¹«¿ªÆäÔø±»»ý¼«ÀûÓᣠ¡£¡£¡£¡£¡£¡£CrowdStrikeºÍMandiant֤ʵ £¬£¬£¬£¬£¬£¬ClopÔÚ8Ô³õÀûÓÃÕâЩ·ì϶ÈëÇÖϵͳ²¢²¿Êð¶ñÒâÈí¼þ¡£ ¡£¡£¡£¡£¡£¡£×÷Ϊͳһ¹¥»÷Á´µÄÒ»²¿ÃÅ £¬£¬£¬£¬£¬£¬¹þ·ð´óѧҲÔâClopÀÕË÷ £¬£¬£¬£¬£¬£¬¸ÃУ³Æ½ö¡°Ó×ÐÍÐÐÕþµ¥ÔªÓйط½¡±ÊÜÓ°Ïì¡£ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/american-airlines-subsidiary-envoy-confirms-oracle-data-theft-attack/


6. macOSαÔìÆ½Ì¨¹¥»÷ÏÖÐÂÍþв£ºAMOSÓëOdysseyÇÔÈ¡Èí¼þËÁŰ


10ÔÂ18ÈÕ £¬£¬£¬£¬£¬£¬½üÈÕ £¬£¬£¬£¬£¬£¬Õë¶ÔmacOS¿ª·¢ÈËÔ±µÄ¶ñÒâ»î¶¯ÀûÓÃαÔìHomebrew¡¢LogMeInºÍTradingViewƽ̨´«²¼AMOS£¨Atomic macOS Stealer£©¼°OdysseyµÈÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ¡£ ¡£¡£¡£¡£¡£¡£¹¥»÷Õßѡȡ¡°ClickFix¡±¼¼Êõ £¬£¬£¬£¬£¬£¬Í¨¹ýGoogle AdsÍÆ¹ãµÄ85¸öðÃûÓòÃûÓÕÆ­Óû§¸´ÔìcurlºÅÁî×°ÖöñÒⷨʽ¡£ ¡£¡£¡£¡£¡£¡£ÀýÈç £¬£¬£¬£¬£¬£¬TradingViewÐéÎ±ÍøÕ¾ÒÔ¡°°²È«È·ÈÏ¡±Îª»Ï×Ó £¬£¬£¬£¬£¬£¬ÏÖʵ½«base64±àÂëµÄ×°ÖúÅÁÔìµ½¼ôÌù°å £¬£¬£¬£¬£¬£¬Ö´ÐкóÏÂÔØ²¢½âÂë¡°install.sh¡±Îļþ £¬£¬£¬£¬£¬£¬ÈƹýGatekeeper·À»¤»úÔì £¬£¬£¬£¬£¬£¬×îÖÕ¼ÓÔØAMOS»òOdyssey¶ñÒâÈí¼þ¡£ ¡£¡£¡£¡£¡£¡£ÕâЩ¶ñÒâÈí¼þ¾ß±¸·´Ðé¹¹»ú¼ì²âÄÜÁ¦ £¬£¬£¬£¬£¬£¬ÔËÐкóÊ×ÏÈÒÔrootȨÏÞÍøÂçÖ÷»úÓ²¼þ¡¢ÄÚ´æÐÅÏ¢ £¬£¬£¬£¬£¬£¬²¢Í¨¹ý°Ñ³Öϵͳ·þÎñ£¨ÈçÖÕÖ¹OneDriveÊØ»¤¹ý³Ì£©¼°ÓëmacOS XPC·þÎñ½»»¥ £¬£¬£¬£¬£¬£¬½«¶ñÒâ»î¶¯¼Ù×°³ÉºÏ·¨¹ý³Ì¡£ ¡£¡£¡£¡£¡£¡£×îÖÕ¼¤»îÐÅÏ¢ÇÔÈ¡×é¼þ £¬£¬£¬£¬£¬£¬ÇÔÈ¡ä¯ÀÀÆ÷´æ´¢µÄÃô¸ÐÊý¾Ý¡¢¼ÓÃÜÇ®±ÒÇ®°üƾ֤¡¢Ô¿³×´®ÄÚÈݼ°Ó×ÎÒÎļþ £¬£¬£¬£¬£¬£¬ÒÔZIPÌåʽ»Ø´«ÖÁ¹¥»÷Õß½ÚÔìµÄC2·þÎñÆ÷¡£ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/google-ads-for-fake-homebrew-logmein-sites-push-infostealers/