StrelaStealer¹¥»÷Å·Ã˺ÍÃÀ¹úµÄ 100 ¶à¸ö×éÖ¯»òÆóÒµ

Ðû²¼Ê±¼ä 2024-03-25
1. StrelaStealer¹¥»÷Å·Ã˺ÍÃÀ¹úµÄ 100 ¶à¸ö×éÖ¯»òÆóÒµ


3ÔÂ24ÈÕ£¬£¬£¬£¬ £¬£¬£¬ÔÚUnit 42×î½üµÄÒ»·Ý±¨¸æÖÐPalo Alto Networks µÄÑо¿Ö°Ô±·¢Ã÷ÁËһϵÁÐеÄÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬ £¬£¬£¬Ö¼ÔÚÈö²¥ÃûΪ StrelaStealer µÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£ ¡£ÕâÒ»ÍþвÒÑÓ°Ï쵽ŷÃ˺ÍÃÀ¹úµÄ 100 ¶à¸ö×éÖ¯¡£¡£¡£¡£¡£ ¡£ÕâЩ¹¥»÷ÊÇͨ¹ý´øÓÐÆô¶¯ StrelaStealer DLL¸ºÔصĸ½¼þµÄÀ¬»øÓʼþÀ´Ö´ÐеÄ¡£¡£¡£¡£¡£ ¡£ÎªÁËÌӱܼì²â£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õ߻ᰴÆÚ¸ü¸Ä³õʼµç×ÓÓʼþÖи½¼þµÄÎļþÃûÌᣡ£¡£¡£¡£ ¡£StrelaStealer ÓÚ 2022 Äê 11 ÔÂÊ״μì²âµ½£¬£¬£¬£¬ £¬£¬£¬Ö¼ÔÚ´ÓÊ¢ÐеÄÓʼþ¿Í»§¶ËÇÔÈ¡µç×ÓÓʼþÕÊ»§Êý¾Ý£¬£¬£¬£¬ £¬£¬£¬²¢½«ÕâЩÐÅÏ¢´«Êäµ½¹¥»÷Õß¿ØÖÆÏµÄЧÀÍÆ÷¡£¡£¡£¡£¡£ ¡£×ԸöñÒâÈí¼þ·ºÆðÒÔÀ´£¬£¬£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±¼Í¼ÁËÁ½´Î°²ÅŸöñÒâÈí¼þµÄÖØ´ó»î¶¯£ºÒ»´ÎÓÚ 2023 Äê 11 Ô£¬£¬£¬£¬ £¬£¬£¬ÁíÒ»´ÎÓÚ 2024 Äê 1 Ô¡£¡£¡£¡£¡£ ¡£ÕâЩ»î¶¯Õë¶ÔµÄÐÐÒµ°üÀ¨ÊÖÒÕ¡¢½ðÈÚ¡¢×¨ÒµºÍÖ´·¨Ð§ÀÍ¡¢ÖÆÔì¡¢ÄÜÔ´¡¢°ü¹Ü¡¢ÐÞ½¨µÈ¡£¡£¡£¡£¡£ ¡£


https://meterpreter.org/strelastealer-attacks-hit-100-organizations/


2. Apple M ϵÁÐоƬ΢¼Ü¹¹ÑÏÖØÎó²î£¬£¬£¬£¬ £¬£¬£¬¿Éµ¼ÖÂMac ×°±¸ÃÜԿй¶


3ÔÂ24ÈÕ£¬£¬£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁË Apple M ϵÁÐоƬ΢¼Ü¹¹ÖеÄÒ»¸öÑÏÖØÎó²î£¬£¬£¬£¬ £¬£¬£¬Ê¹·¸·¨·Ö×ÓÄܹ»´Ó Mac ×°±¸£¨°üÀ¨ÅÌËã»úºÍÌõ¼Ç±¾µçÄÔ£©ÖÐÌáÈ¡ÃÜÔ¿¡£¡£¡£¡£¡£ ¡£ÎÊÌâµÄÖ¢½áÔÚÓÚ£¬£¬£¬£¬ £¬£¬£¬¸ÃÎó²îÓëоƬÉè¼ÆÓÐʵÖÊÁªÏµ£¬£¬£¬£¬ £¬£¬£¬½ö¿¿Èí¼þ¸üÐÂÎÞ·¨ÍêÈ«ÐÞ¸´¡£¡£¡£¡£¡£ ¡£¸ÃÎó²îÓëÊý¾ÝÄÚ´æÔ¤È¡¹¦Ð§Ïà¹Ø£¬£¬£¬£¬ £¬£¬£¬¸Ã¹¦Ð§Í¨¹ýÕ¹ÍûδÀ´µÄÄÚ´æÇëÇóÀ´ÓÅ»¯ÐÅÏ¢´¦Öóͷ£¡£¡£¡£¡£¡£ ¡£´Ë¹¦Ð§¿ÉÄÜ»áÎó½â¼ÓÃÜÃÜÔ¿£¬£¬£¬£¬ £¬£¬£¬´Ó¶øÎªÍ¨¹ýרÃŹ¥»÷ÌáÈ¡ÃÜÔ¿ÆÌƽõè¾¶¡£¡£¡£¡£¡£ ¡£Ò»¸ö¹ú¼ÊÑо¿ÍŶÓÉè¼ÆÁËÒ»ÖÖÃûΪ GoFetch µÄ¹¥»÷£¬£¬£¬£¬ £¬£¬£¬ËµÃ÷ÎúÎÞÐè×°±¸ÖÎÀíȨÏÞ¼´¿ÉÌáÈ¡ÃÜÔ¿µÄ¿ÉÐÐÐÔ¡£¡£¡£¡£¡£ ¡£ÕâÖÖ¹¥»÷¿ÉÒÔÔÚרÓÐµÄ M1 ºÍ M2 оƬÉÏÖ´ÐУ¬£¬£¬£¬ £¬£¬£¬Ó°Ïì¹Å°å¼ÓÃÜËã·¨ºÍ¶Ô¿¹Á¿×ÓÅÌËãµÄËã·¨¡£¡£¡£¡£¡£ ¡£ÃÜÔ¿ÌáÈ¡Àú³Ì´Ó²»µ½Ò»Ð¡Ê±µ½Ê®Ð¡Ê±²»µÈ£¬£¬£¬£¬ £¬£¬£¬Ïêϸȡ¾öÓÚ¼ÓÃÜÃÜÔ¿µÄÀàÐͺÍËù½ÓÄɵÄËã·¨¡£¡£¡£¡£¡£ ¡£ÕâÅú×¢¸ÃÎó²îÄܹ»¹æ±Ü±ê×¼¼ÓÃÜ·ÀÓù»úÖÆ¡£¡£¡£¡£¡£ ¡£ÎªÁËÌá·À´ËÎó²î£¬£¬£¬£¬ £¬£¬£¬¼ÓÃÜÈí¼þ¿ª·¢Ö°Ô±±ØÐèÔÚÆäÈí¼þÖÐʵÑéÌØÁíÍâÇå¾²»úÖÆ£¬£¬£¬£¬ £¬£¬£¬Õâ¿ÉÄܻᵼÖÈÎÃüܲÙ×÷ʱ´úµÄÐÔÄÜϽµ¡£¡£¡£¡£¡£ ¡£ÌáÒéµÄ± £» £»£»£»£»¤²½·¥°üÀ¨Êý¾ÝÆÁÕϺͽ«´¦Öóͷ£×ªÒƵ½Ã»ÓÐ DMP µÄ´¦Öóͷ£Æ÷Äںˡ£¡£¡£¡£¡£ ¡£Ñо¿Ö°Ô±»¹Ìá³öÁËÒ»ÖÖºã¾Ã½â¾ö¼Æ»®£¬£¬£¬£¬ £¬£¬£¬Éæ¼°À©Õ¹Ó²¼þºÍÈí¼þ½»»¥£¬£¬£¬£¬ £¬£¬£¬ÒÔ±ãÔÚÒªº¦²Ù×÷ʱ´úÍ£Óà DMP¡£¡£¡£¡£¡£ ¡£Õâ¿ÉÒÔ×ÊÖú×èÖ¹¹¥»÷£¬£¬£¬£¬ £¬£¬£¬¶ø²»»áÏÔ×ÅÓ°ÏìÕûÌåÐÔÄÜ¡£¡£¡£¡£¡£ ¡£


https://meterpreter.org/unfixable-apple-chip-issue-secret-keys-vulnerable/


3. ΢Èí½«¹Ø±ÕÕë¶Ô¶íÂÞ˹ÆóÒµµÄ 50 ÏîÔÆÐ§À͵Ļá¼û


3ÔÂ23ÈÕ£¬£¬£¬£¬ £¬£¬£¬Î¢ÈíÍýÏëÔÚ 3 ÔÂβ֮ǰÏÞÖÆ¶íÂÞ˹×éÖ¯¶Ô 50 ¶àÖÖÔÆ²úÆ·µÄ»á¼û£¬£¬£¬£¬ £¬£¬£¬ÕâÊÇÅ·ÃËî¿Ïµ»ú¹¹È¥Äê 12 Ô¶ԸùúÐû²¼µÄÖÆ²ÃÒªÇóµÄÒ»²¿·Ö¡£¡£¡£¡£¡£ ¡£ÔÝÍ£×î³õ¶¨ÓÚ 2024 Äê 3 Ô 20 ÈÕ¾ÙÐУ¬£¬£¬£¬ £¬£¬£¬µ«ØÊºóÍÆ³Ùµ½±¾ÔÂ⣬£¬£¬£¬ £¬£¬£¬ÒÔ±ãÊÜÓ°ÏìµÄʵÌåÓиü¶àʱ¼äÀ´Öƶ©Ìæ»»½â¾ö¼Æ»®¡£¡£¡£¡£¡£ ¡£Óйؼ´½«ÔÝÍ£µÄÐÂÎÅ×îÏÈÓÉ Softline Group of Companies ±¨µÀ£¬£¬£¬£¬ £¬£¬£¬¸Ã¹«Ë¾ÊǶíÂÞ˹ÏÖ´æ×î´óµÄ IT ЧÀÍÌṩÉÌÖ®Ò»¡£¡£¡£¡£¡£ ¡£Î¢ÈíµÄÐÅÖÐûÓÐÏêϸ˵Ã÷ÄÄЩЧÀͽ«±»×÷·Ï£¬£¬£¬£¬ £¬£¬£¬µ«Ëþ˹ÉçÒѾ­ÁгöÁË 50 ¶àÖÖ²úÆ·µÄÇåµ¥ £¬£¬£¬£¬ £¬£¬£¬ÕâЩ²úÆ·½«ÔÚ 3 ÔÂβ×èÖ¹Ìṩ¡£¡£¡£¡£¡£ ¡£ÒÑ Ã÷È· £¬£¬£¬£¬ £¬£¬£¬ÔÊÐí֤ʧЧӰÏì¶íÂÞ˹´ÓÊÂÐÞ½¨¡¢Éè¼Æ¡¢Ê©¹¤¡¢ÖÆÔ졢ýÌå¡¢½ÌÓýºÍÓéÀÖ¡¢ÐÞ½¨ÐÅϢģ×Ó£¨BIM£©¡¢ÅÌËã»ú¸¨ÖúÉè¼Æ£¨CAD£©ºÍÅÌËã»ú¸¨ÖúÖÆÔìµÄ¹«Ë¾ºÍ×éÖ¯£¨Í¹ÂÖ£©¡£¡£¡£¡£¡£ ¡£¿ÉÊÇ£¬£¬£¬£¬ £¬£¬£¬Ã»ÓÐÐû²¼ÏÞÖÆÐ¡ÎÒ˽¼Ò»á¼ûµÄÍýÏ룬£¬£¬£¬ £¬£¬£¬Òò´Ë¼ÙÉèÉÏÊö²úÆ·ÈԿɹ©Í¨Ë×Óû§Ê¹Óᣡ£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-to-shut-down-50-cloud-services-for-russian-businesses/


4. SIGN1 ¶ñÒâÈí¼þ»î¶¯ÒÑѬȾ 39000 ¶à¸ö WORDPRESS ÍøÕ¾


3ÔÂ23ÈÕ£¬£¬£¬£¬ £¬£¬£¬Sucuri µÄ Sucurity Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÃûΪ Sign1 µÄ¶ñÒâÈí¼þ»î¶¯£¬£¬£¬£¬ £¬£¬£¬¸Ã»î¶¯ÔÚÒÑÍùÁù¸öÔÂÄÚÒѾ­Î£º¦ÁË 39,000 ¸ö WordPress ÍøÕ¾¡£¡£¡£¡£¡£ ¡£×¨¼ÒÃÇ·¢Ã÷£¬£¬£¬£¬ £¬£¬£¬ÍþвÐÐΪÕßÈëÇÖÁËÍøÕ¾£¬£¬£¬£¬ £¬£¬£¬Ö²Èë¶ñÒâ JavaScript ×¢È룬£¬£¬£¬ £¬£¬£¬½«»á¼ûÕßÖØ¶¨Ïòµ½¶ñÒâÍøÕ¾¡£¡£¡£¡£¡£ ¡£Sign1 ±³ºóµÄÍþв¼ÓÈëÕß½«¶ñÒâ JavaScript ×¢ÈëÕýµ±²å¼þºÍ HTML С²¿¼þÖС£¡£¡£¡£¡£ ¡£×¢ÈëµÄ´úÂë°üÀ¨Ò»¸öÓ²±àÂëµÄÊý×ÖÊý×飬£¬£¬£¬ £¬£¬£¬ËüʹÓà XOR ±àÂëÀ´»ñÈ¡ÐÂÖµ¡£¡£¡£¡£¡£ ¡£×¨¼Ò¶Ô XOR ±àÂëµÄ JavaScript ´úÂë¾ÙÐÐÏàʶÂ룬£¬£¬£¬ £¬£¬£¬·¢Ã÷ËüÓÃÓÚÖ´ÐÐÔ¶³ÌЧÀÍÆ÷ÉÏÍÐ¹ÜµÄ JavaScript Îļþ¡£¡£¡£¡£¡£ ¡£Ñо¿Ö°Ô±×¢Öص½£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß½ÓÄɶ¯Ì¬¸ü¸ÄµÄ URL£¬£¬£¬£¬ £¬£¬£¬¶¯Ì¬ JavaScript ´úÂëµÄʹÓÃÔÊÐíÿ 10 ·ÖÖÓ¸ü¸ÄÒ»´Î URL¡£¡£¡£¡£¡£ ¡£¸Ã´úÂëÔÚ»á¼ûÕßµÄä¯ÀÀÆ÷ÖÐÖ´ÐУ¬£¬£¬£¬ £¬£¬£¬µ¼ÖÂÍøÕ¾»á¼ûÕß·ºÆð²»ÐèÒªµÄÖØ¶¨ÏòºÍ¹ã¸æ¡£¡£¡£¡£¡£ ¡£Sign1 »î¶¯×î³õÓÉÑо¿Ô±Denis SinegubkoÔÚ 2023 ÄêϰëÄê·¢Ã÷£¬£¬£¬£¬ £¬£¬£¬Sucuri ±¨¸æ³Æ£¬£¬£¬£¬ £¬£¬£¬×Ô 2023 Äê 7 Ô 31 ÈÕÒÔÀ´£¬£¬£¬£¬ £¬£¬£¬ÍþвÐÐΪÕßʹÓÃÁ˶à´ï 15 ¸ö²î±ðµÄÓò¡£¡£¡£¡£¡£ ¡£


https://securityaffairs.com/160942/hacking/sign1-malware-campaign.html


5. ÃÀ¹úÕþ¸®Ðû²¼Õë¶Ô¹«¹²²¿·ÖµÄРDDoS ¹¥»÷Ö¸ÄÏ


3ÔÂ22ÈÕ£¬£¬£¬£¬ £¬£¬£¬ÃÀ¹úÕþ¸®Îª¹«¹²²¿·ÖʵÌåÐû²¼ÁËеÄÂþÑÜʽ¾Ü¾øÐ§ÀÍ (DDoS) ¹¥»÷Ö¸ÄÏ£¬£¬£¬£¬ £¬£¬£¬ÒÔ×ÊÖú±ÜÃâÒªº¦Ð§ÀÍÖÐÖ¹¡£¡£¡£¡£¡£ ¡£¸ÃÎļþÖ¼ÔÚ×÷Ϊ×ÛºÏ×ÊÔ´£¬£¬£¬£¬ £¬£¬£¬½â¾öÁª°î¡¢Öݺ͵ط½Õþ¸®»ú¹¹ÔÚ·ÀÓù DDoS ¹¥»÷·½ÃæÃæÁÙµÄÏêϸÐèÇóºÍÌôÕ½¡£¡£¡£¡£¡£ ¡£¸Ãת´ïÖ¸³ö£¬£¬£¬£¬ £¬£¬£¬DDoS ¹¥»÷ÊÇÖ¸´ó×ÚÊÜѬȾµÄÅÌËã»úÏòÄ¿µÄϵͳ·¢ËÍ´ó×ÚÁ÷Á¿»òÇëÇ󣬣¬£¬£¬ £¬£¬£¬µ¼ÖÂÓû§ÎÞ·¨Ê¹Óøù¥»÷£¬£¬£¬£¬ £¬£¬£¬ÕâÖÖ¹¥»÷ºÜÄÑ×·×ÙºÍ×èÖ¹¡£¡£¡£¡£¡£ ¡£ÕâÖÖǰÑÔͨ³£±»³öÓÚÕþÖÎÄîÍ·µÄ¹¥»÷ÕßʹÓ㬣¬£¬£¬ £¬£¬£¬°üÀ¨ºÚ¿Í»î¶¯·Ö×ÓºÍÃñ×å¹ú¼ÒÕûÌ壬£¬£¬£¬ £¬£¬£¬Õþ¸®ÍøÕ¾¾­³£³ÉΪ¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£ ¡£ÀýÈ磬£¬£¬£¬ £¬£¬£¬×Ô 2022 Äê 2 Ô¿ËÀïÄ·ÁÖ¹¬ÈëÇָùúÒÔÀ´£¬£¬£¬£¬ £¬£¬£¬Óë¶íÂÞ˹ºÍÎÚ¿ËÀ¼Óйصĺڿ;­³£Ê¹Óà DDoS ¹¥»÷¶Ô·½Õþ¸®ÍøÕ¾¡£¡£¡£¡£¡£ ¡£2023 Äê 10 Ô£¬£¬£¬£¬ £¬£¬£¬Ó¢¹úÍõÊÒ¹Ù·½ÍøÕ¾Òò DDoS ÊÂÎñ¶øÏÂÏߣ¬£¬£¬£¬ £¬£¬£¬¶íÂÞ˹ºÚ¿Í×éÖ¯ Killnet Éù³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ¡£¡£¡£¡£¡£ ¡£


https://www.infosecurity-magazine.com/news/us-ddos-attack-guidance-public/?&web_view=true


6. ¶íÂÞ˹ºÚ¿ÍʹÓà WineLoader ¶ñÒâÈí¼þÃé×¼µÂ¹úÕþµ³


3ÔÂ23ÈÕ£¬£¬£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±ÖÒÑԳƣ¬£¬£¬£¬ £¬£¬£¬Óë¶íÂÞ˹¶ÔÍâÇ鱨¾Ö£¨SVR£©ÓÐÁªÏµµÄºÚ¿Í×éÖ¯Ê×´ÎÕë¶ÔµÂ¹úÕþµ³£¬£¬£¬£¬ £¬£¬£¬½«Æä½¹µã´Óµä·¶µÄÍ⽻ʹÍÅÄ¿µÄ×ªÒÆ¿ª¡£¡£¡£¡£¡£ ¡£ÍøÂç´¹ÂÚ¹¥»÷Ö¼ÔÚ°²ÅÅÃûΪ WineLoader µÄºóÃŶñÒâÈí¼þ£¬£¬£¬£¬ £¬£¬£¬¸Ã¶ñÒâÈí¼þÔÊÐíÍþвÐÐΪÕßÔ¶³Ì»á¼ûÊÜѬȾµÄ×°±¸ºÍÍøÂç¡£¡£¡£¡£¡£ ¡£APT29£¨Ò²³ÆÎª Midnight Blizzard¡¢NOBELIUM¡¢Cozy Bear£©ÊÇÒ»¸ö¶íÂÞË¹ÌØ¹¤ºÚ¿Í×éÖ¯¡£¡£¡£¡£¡£ ¡£¸ÃºÚ¿Í×éÖ¯ÓëÐí¶àÍøÂç¹¥»÷Óйأ¬£¬£¬£¬ £¬£¬£¬°üÀ¨ 2020 Äê 12 ÔÂÎÛÃûÕÑÖøµÄSolarWinds ¹©Ó¦Á´¹¥»÷¡£¡£¡£¡£¡£ ¡£ÕâЩÄêÀ´£¬£¬£¬£¬ £¬£¬£¬ÍþвÐÐΪÕßÒ»Ö±¼á³Ö»îÔ¾£¬£¬£¬£¬ £¬£¬£¬Í¨³£Ê¹ÓÃһϵÁÐÍøÂç´¹ÂÚÕ½ÂÔ»ò¹©Ó¦Á´Í×ЭÀ´Õë¶ÔÕþ¸®¡¢´óʹ¹Ý¡¢¸ß¼¶¹ÙÔ±ºÍÖÖÖÖʵÌå¡£¡£¡£¡£¡£ ¡£APT29 ×î½üµÄÖØµãÊÇÔÆÐ§ÀÍ£¬£¬£¬£¬ £¬£¬£¬ÆÆËð Microsoft ϵͳ²¢ÇÔÈ¡ Exchange ÕÊ»§µÄÊý¾Ý£¬£¬£¬£¬ £¬£¬£¬²¢ÆÆËðHewlett Packard EnterpriseʹÓÃµÄ MS Office 365 µç×ÓÓʼþÇéÐΡ£¡£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/russian-hackers-target-german-political-parties-with-wineloader-malware/