DINODASRAT LINUX ±äÖÖÕë¶ÔÈ«ÇòÓû§
Ðû²¼Ê±¼ä 2024-04-023ÔÂ31ÈÕ,¿¨°Í˹»ùʵÑéÊÒµÄÑо¿Ö°Ô±·¢Ã÷ÁË Linux °æ±¾µÄ¶àƽ̨ºóÃÅ DinodasRAT£¬¸ÃºóÃű»ÓÃÓÚÕë¶ÔÖйú¡¢ÍÁ¶úÆäºÍÎÚ×ȱð¿Ë˹̹¡£DinodasRAT£¨ÓÖÃû XDealer£©ÊÇÓà C++ ±àдµÄ£¬Ö§³ÖÆÕ±éµÄ¹¦Ð§À´¼àÊÓÓû§²¢´ÓÄ¿µÄϵͳÇÔÈ¡Ãô¸ÐÊý¾Ý¡£ESET Ñо¿Ö°Ô±±¨¸æ³Æ£¬Windows °æ±¾µÄ DinodasRAT ±»ÓÃÓÚÕë¶Ô¹çÑÇÄÇÕþ¸®ÊµÌåµÄ¹¥»÷¡£ESET ÓÚ 2023 Äê 10 ÔÂÊ״η¢Ã÷Ð嵀 Linux °æ±¾µÄ DinodasRAT£¬µ«×¨¼ÒÒÔΪËü×Ô 2022 ÄêÒÔÀ´¾ÍÒ»Ö±»îÔ¾¡£2024 Äê 3 Ô£¬Ç÷ÊƿƼ¼Ñо¿Ö°Ô±ÔÚÊÓ²ìÓëÖйúÏà¹ØµÄ APT Earth LuscaÔ˶¯Ê±·¢Ã÷ÁËÓɱ»×·×ÙΪ Earth Krahang µÄÍþвÐÐΪÕßÌᳫµÄÖØ´óÔ˶¯ ¡£¸ÃÔ˶¯ÖÁÉÙ´Ó 2022 ÄêÍ·×îÏÈËƺõ¾ÍºÜ»îÔ¾£¬Ö÷ÒªÕë¶ÔÕþ¸®×éÖ¯¡£×Ô 2023 ÄêÆð£¬Earth Krahang תÒƵ½ÁíÒ»¸öºóÃÅ£¨ TeamT5ÃüÃûΪ XDealer £¬ ESET ÃüÃûΪDinodasRAT £©¡£Ïà±ÈRESHELL£¬XDealerÌṩÁ˸üÖÜÈ«µÄºóÃŹ¦Ð§¡£±ðµÄ£¬ÎÒÃÇ·¢Ã÷ÍþвÐÐΪÕßͬʱʹÓà Windows ºÍ Linux °æ±¾µÄ XDealer À´Õë¶Ô²î±ðµÄϵͳ¡£
https://securityaffairs.com/161255/malware/linux-variant-dinodasrat-backdoor.html
2. È«ÇòÃÜÂëÅçÈ÷Ô˶¯Õë¶Ô VPN ϵͳ¿Éµ¼ÖÂϵͳËø¶¨
3ÔÂ31ÈÕ,˼¿ÆÒÑÐû²¼¹ØÓÚÕë¶ÔÈ«ÇòÆóҵʹÓõÄÔ¶³Ì»á¼û VPN (RAVPN) ϵͳµÄÆÕ±éÃÜÂëÅçÈ÷Ô˶¯µÄÑÏÖØÖÒÑÔ¡£ÕâÖÖ¹¥»÷¼¤ÔöµÄÄ¿µÄÊÇÓÃͨÓÃÃÜÂëÑÍû VPN µÇ¼£¬¿ÉÄÜ»áËø¶¨Õýµ±Óû§²¢ÈÅÂÒÔ¶³ÌÊÂÇé¡£ÃÜÂëÅçÈ÷Ô˶¯»áÓ°ÏìÖÖÖÖ VPN ÌṩÉÌ£¬¶ø²»µ«½öÊÇ˼¿Æ¡£ÒÀÀµÔ¶³Ì»á¼ûµÄÆóÒµÐèÒª¼á³Ö¸ß¶ÈСÐÄ¡£ÕâЩ¹¥»÷µÄЧ¹û²»µ«½öÊÇδ¾ÊÚȨµÄ»á¼û£»ËüÃÇÓпÉÄÜËø¶¨ÕÊ»§²¢Òý·¢ÀàËƾܾø·þÎñ (DoS) µÄÇéÐΣ¬´Ó¶øÆÆËðÊý×Ö²Ù×÷µÄÎÞ·ìÁ÷³Ì²¢Ëðº¦Ç徲ͨѶµÄÍêÕûÐÔ¡£¸ÃÔ˶¯Í¹ÏÔÁËÔ¶³Ì»á¿´·¨¾ö¼Æ»®ËùÃæÁÙµÄÒ»Á¬Íþв¡£×éÖ¯±ØÐèÓÅÏÈ˼Á¿Ç¿Ê¢µÄÉí·ÝÑéÖ¤¡¢Ð¡Ðĵļà¿ØºÍÇ¿Ê¢µÄÊÂÎñÏìÓ¦ÍýÏ룬ÒÔÁìÏÈÓÚһֱת±äµÄ¹¥»÷ÒªÁì¡£
https://securityonline.info/global-password-spraying-campaign-targets-vpn-systems-causing-lockouts/
3. ľÂí»¯ npm Èí¼þ°üÃé×¼¼ÓÃÜÇ®±ÒÇ®°ü
3ÔÂ31ÈÕ,Phylum Ñо¿ÍŶÓ̻¶ÁËÒ»¸öαװ³ÉÕýµ±¹¤¾ß°üµÄ¶ñÒânpm °ü¡£¸ÃÈí¼þ°üÃûΪ¡°vue2util¡±£¬ÍµÍµµØÖ´ÐÐÁËÒ»ÏîÖØ´óµÄÍýÏ룬ּÔÚ´ÓºÁÎÞ½äÐĵļÓÃÜÇ®±ÒÇ®°üÖÐÇÔÈ¡ USDT ´ú±Ò¡£¡°vue2util¡±¿´ÆðÀ´ÏñÊDZê×¼ÊÊÓú¯ÊýµÄÜöÝÍ¡£È»¶ø£¬ËüÒþ²ØÁËÒ»¸öа¶ñµÄÓÐÓøºÔØ£¬µ±µ¼Èëµ½ÏîÄ¿ÖÐʱ£¬¸ÃÓÐÓøºÔØ»á´ÓÔ¶³Ì·þÎñÆ÷¼ÓÔضñÒâ¾ç±¾¡£¼ÓÔصľ籾ÒÔ±Ò°²ÖÇÄÜÁ´µÄÓû§ÎªÄ¿µÄ£¬ËÑË÷³ÖÓÐ USDT ¼ÓÃÜÇ®±ÒµÄÇ®°ü¡£¶ñÒâÈí¼þʹÓà ERC20 ºÏÔ¼£¨ÖÎÀí USDT£©µÄÉóÅúÁ÷³Ì¡£ËüÔÊÐí×Ô¼ºÎÞÏÞÖƵػá¼ûÊܺ¦Õß³ÖÓÐµÄ USDT£¬ÎÞÐè½øÒ»²½ÊÚȨ¡£ÎªÁËÔöÌíÀֳɵÄʱ»ú£¬¶ñÒâÈí¼þÇÉÃîµØ½«ÆäÖ´ÐÐÁ´½Óµ½Óû§ÍøÒ³Éϱê¼ÇΪ¡°buy_btn¡±µÄ°´Å¥¡£Ö»Ðèµ¥»÷һϣ¬Êܺ¦Õ߾ͻáÔÚ²»Öª²»¾õÖд¥·¢ÁîÅÆ͵ÇÔ¡£
https://securityonline.info/trojanized-npm-package-targets-cryptocurrency-wallets-steals-usdt/
4. Ñо¿ÍŶӷ¢Ã÷ʹÓà Google Ads ¸ú×Ù¹¦Ð§·Ö·¢¶ñÒâÈí¼þ
4ÔÂ1ÈÕ,AhnLab Çå¾²Ç鱨ÖÐÐÄ (ASEC) ×î½ü¼ì²âµ½Ê¹Óà Google Ads ¸ú×Ù¹¦Ð§·Ö·¢µÄ¶ñÒâÈí¼þ±äÖÖ¡£ÒÑÈ·ÈϵݸÀýÅú×¢£¬¸Ã¶ñÒâÈí¼þÊÇͨ¹ýαװ³É Notion ºÍ Slack µÈÊ¢ÐÐȺ¼þµÄ×°ÖóÌÐòÀ´Èö²¥µÄ¡£Ò»µ©¶ñÒâÈí¼þ×°Öò¢Ö´ÐУ¬Ëü¾Í»á´Ó¹¥»÷ÕߵķþÎñÆ÷ÏÂÔضñÒâÎļþºÍÓÐÓøºÔØ¡£´ËÀà¶ñÒâÈí¼þÒÔ×°ÖóÌÐòÐÎʽ·Ö·¢£¬Í¨³£Îª Inno Setup ×°ÖóÌÐò»ò Nullsoft ¾ç±¾×°ÖÃϵͳ (NSIS) ×°ÖóÌÐò¡£ÆäÖУ¬Notion_software_x64_.exeÎļþÖ±µ½×î½üÓû§ÔÚGoogleÉÏÓÃÒªº¦×Ö¡°notion¡±ËÑË÷ʱ²Å·ºÆð¡£¹¥»÷ÕßʹÓà Google Ads ¸ú×ÙÀ´ÓÕÆÓû§ÒÔΪËûÃÇÕýÔÚ»á¼ûÕýµ±ÍøÕ¾¡£Google Ads ¸ú×ÙÔÊÐí¹ã¸æ¿Í»§²åÈëÍⲿ·ÖÎöÍøÕ¾µØµã£¬ÒÔÍøÂçºÍʹÓûá¼ûÕߵĻá¼ûÏà¹ØÊý¾ÝÀ´ÅÌËã¹ã¸æÁ÷Á¿¡£Google Ads ¸ú×Ù×î³õÓÃÓÚÆÊÎöÍøÕ¾Á÷Á¿¡£¿ÉÊÇ£¬¸ÃÌض¨¹ã¸æ²»°üÀ¨Íⲿ¾²Ì¬Õ¾µã£¬¶øÊÇ°üÀ¨¶ñÒâ´úÂë·Ö·¢Õ¾µã¡£
ÏÖÔÚ¹¥»÷ÕߵĹã¸æÒѱ»É¾³ý¡£
https://asec.ahnlab.com/en/63477/
5. ºÚ¿ÍʹÓà Microsoft OneNote À´²ß»®ÍøÂç¹¥»÷
4ÔÂ1ÈÕ,¸ÃÔ˶¯ÔÚÍøÂçÇ徲ר¼ÒµÄ¹Øעϣ¬Õ¹Ê¾ÁËÍøÂçÍþвµÄÐÂÇ÷ÊÆ£¬¼´Ê¹Óó£Óõİ칫ӦÓóÌÐòδ¾ÊÚȨ»á¼ûÆóÒµÍøÂç¡£pr0xylife Ê×ÏÈÔÚÆä GitHub ´æ´¢¿âÉϼͼÁ˸öñÒâÔ˶¯¡£Ëü½ÒÆÆÁËÕë¶ÔÖÆÔì¡¢ÊÖÒÕ¡¢ÄÜÔ´¡¢ÁãÊÛ¡¢°ü¹ÜºÍÆäËû¼¸¸öÐÐÒµµÄ¹«Ë¾µÄÆÕ±éµç×ÓÓʼþÍøÂç´¹ÂÚ²Ù×÷¡£ÕâЩµç×ÓÓʼþ°üÀ¨Éù³ÆÊÇ¡°Çå¾²ÐÂÎÅ¡±µÄ OneNote ¸½¼þ£¬ÕâÊÇÒ»ÖÖÓÕÆÊÕ¼þÈË·¿ªÎļþµÄ»Ï×Ó¡£¸ÃÔ˶¯Ç¿µ÷ÁËÍøÂçÍþвһֱÑݱäµÄÇéÐΣ¬¹¥»÷ÕßʹÓöԳ£ÓÃÓ¦ÓóÌÐòµÄÐÅÍÐÀ´Èƹý¹Å°åµÄÇå¾²²½·¥¡£Ê¹Óà Microsoft OneNote ÎļþÈö²¥¶ñÒâÈí¼þ´ú±í×ÅÏò¸ü¾ß´´Á¢ÐԵĹ¥»÷Ç°ÑÔµÄת±ä£¬Òò´ËÐèÒªÖØÐÂÆÀ¹ÀÍøÂçÇå¾²Õ½ÂÔÒÔÌá·À´ËÀàÍþв¡£
https://gbhackers.com/microsoft-onenote-orchestrate/
6. TeamCity ÐÞ²¹ÁË 26 ¸öÎó²î²¢±£ÃÜÏêϸÐÅÏ¢
4ÔÂ1ÈÕ,ÔÚ JetBrains µÄÒ»Á¬¼¯³ÉºÍ½»¸¶ (CI/CD) TeamCity ×î½üµÄÈí¼þ¸üÐÂÖУ¬½â¾öÁË 26 ¸öÇå¾²ÎÊÌ⡣Ȼ¶ø£¬¸Ã¹«Ë¾Ñ¡Ôñ²»Í¸Â¶ÓйØÒÑ·¢Ã÷Îó²îµÄÈκÎϸ½Ú£¬Òý·¢ÁËרҵ½çµÄÇ¿ÁÒÌÖÂÛ¡£TeamCity 2024.03 °æ±¾¸üÐÂÖ¼ÔÚ±£»¤Óû§ÃâÊÜDZÔÚÍþв£¬µ«ÍêȫûÓÐÓÐ¹Ø 26 ¸öÎó²îµÄÏêϸÐÅÏ¢£¬×ÅʵÈÃÇ徲ר¼Ò¸ÐÓ¦¾ªÑÈ¡£¸Ã¹«Ë¾È±·¦Í¸Ã÷¶È£¬ÌØÊâÊÇÔÚ Rapid7 µÄר¼ÒÆ·ÆÀ JetBrains ²»·ó¿ª·ÅµÄÊÂÎñÖ®ºó£¬Ò»Ö±Êܵ½ÌØÊâÆ·ÆÀ¡£JetBrains Éù³Æ£¬±£´æÏêϸÐÅÏ¢Ö»ÊÇΪÁ˱£»¤Ê¹Óþɰæ TeamCity µÄ¿Í»§£¬Ö»¹ÜÕâÔÚÒµ½ç²¢Î´»ñµÃÆÕ±é½ÓÊÜ¡£Ö»¹ÜÔÆÔÆ£¬¸Ã¹«Ë¾µÄÒâͼÕվɿÉÒÔÃ÷È·µÄ¡£¹ØÓÚÏëÒª¹¥»÷Èí¼þ¹©Ó¦Á´µÄ·¸·¨·Ö×ÓÀ´Ëµ£¬TeamCity ÈÔÈ»ÊÇÒ»¸öÓÐÎüÒýÁ¦µÄÄ¿µÄ¡£ÀúÊ·Åú×¢£¬´ËÀ๥»÷¿ÉÄܻᱬ·¢ÑÏÖØЧ¹û£¬ÕýÈç SolarWinds µÄ°¸ÀýËùʾ¡£
https://meterpreter.org/teamcity-patches-26-vulnerabilities-keeps-details-secret/