NCC³Æ½ü2000̨Citrix NetScaler·þÎñÆ÷Òѱ»Ö²ÈëºóÃÅ

°ä²¼¹¦·ò 2023-08-17

1¡¢NCC³Æ½ü2000̨Citrix NetScaler·þÎñÆ÷Òѱ»Ö²ÈëºóÃÅ


¾Ý8ÔÂ16ÈÕ±¨Â· £¬NCC Group·¢ÏÖÁËCitrix NetScaler·ì϶µÄ´ó¹æÄ£ÀûÓû¡£¹¥»÷ÕßÒÔ×Ô¶¯»¯·½Ê½ÀûÓÃÁË·ì϶£¨CVE-2023-3519£© £¬ÔÚNetscaler·þÎñÆ÷ÖÐÖ²ÈëÁËWebshell¡£¼´±ãNetScalerÒÑ´ò²¹¶¡»ò³ÁÆô £¬¹¥»÷ÕßÒ²Äܹ»Ê¹ÓôËWebshellÖ´ÐÐËÁÒâºÅÁî¡£×êÑÐÈËÔ±×ܹ²ÔÚ1952¸ö·ÖÆçµÄNetScalerÖз¢ÏÖÁË2491¸öWebshell £¬´óÎÞÊýλÓڵ¹ú¡¢·¨¹ú¡¢ÈðÊ¿¡¢ÈÕ±¾ºÍÒâ´óÀûµÈ¹ú¡£½ØÖÁ8ÔÂ14ÈÕ £¬ÈÔÓÐ1828¸öNetScaler´æÔÚºóÃÅ £¬ÆäÖÐÔ¼1248̨ÒѾ­Õë¶Ô¸Ã·ì϶½øÐÐÁ˽¨¸´¡£


https://thehackernews.com/2023/08/nearly-2000-citrix-netscaler-instances.html


2¡¢´óÁ¿LinkedInÓû§³ÆÆäÕË»§±»½Ù³Ö»òËø¶¨²¿ÃÅÒª½»Êê½ð


¾ÝýÌå8ÔÂ15ÈÕ±¨Â· £¬CyberintÔÚ×î½ü¼¸ÖÜ·¢ÏÖÁËÒ»³¡³ÖÐøµÄ¹¥»÷»î¶¯ÖØÒªÕë¶ÔLinkedInÕÊ»§¡£¸Ã»î¶¯µÄÓ°ÏìÁìÓò¸²¸ÇÈ«Çò £¬µ¼Ö´óÁ¿Óû§ÎÞ·¨½Ó¼ûÆäÕÊ»§¡£ºÜ¶àLinkedInÓû§±§Ô¹ÆäÕË»§±»ÊÕÊÜ»òËø¶¨ £¬²¢ÇÒÎÞ·¨Í¨¹ýLinkedInµÄÖ§³Ö·þÎñ½â¾ö¡£ÓÐЩÈËÉõÖÁ±»ÆÈ½»Êê½ðÄÜÁ¦³ÁлñµÃ½ÚÔìȨ £¬»òÕßÃæ¶ÔÕË»§±»ÓÀԶɾ³ýµÄÇé¿ö¡£¹ÌÈ»LinkedInÉÐδ°ä²¼Õýʽ²¼¸æ £¬µ«ËûÃǵÄÖ§³ÖÏìÓ¦¹¦·òËÆºõÒѾ­µ¢¸é £¬Óб¨Â·³ÆÖ§³ÖÒªÇóµÄÊýÁ¿ºÜ´ó¡£


https://www.bleepingcomputer.com/news/security/linkedin-accounts-hacked-in-widespread-hijacking-campaign/


3¡¢ÃÀ¹ú¸ßÀÖÊÏ(Clorox)Ôâµ½¹¥»÷µ¼ÖÂÔËÓªÁÙʱÖжÏ


8ÔÂ16ÈÕ±¨Â·³Æ £¬ÃÀ¹úÈÕÓÃÆ·³ö²úÉ̸ßÀÖÊÏ(Clorox)Ôâµ½¹¥»÷ £¬µ¼ÖÂÔËÓªÁÙʱÖжÏ¡£¸Ã¹«Ë¾ÔÚ2022ÄêµÄÊÕÈ볬¹ý70ÒÚÃÀÔª¡£Õâ´Î¹¥»÷ÓÚ8ÔÂ14ÈÕ±»¼ì²âµ½ £¬Cloroxµ±¼´²ÉÈ¡Ðж¯ £¬¹Ø¹ØÁËÊÜÓ°ÏìµÄϵͳ¡£¸ÃÊÂÎñµÄµ÷²éÈÔÔÚÔçÆÚ½×¶Î £¬Éв»Ã÷ÏÔÊÇÄÄÖÖÀàÐ͵Ĺ¥»÷¡£È»¶øÏÖÓÐÐÅÏ¢Åú×¢ £¬Õâ¿ÉÄÜÊÇÀÕË÷¹¥»÷¡£Õâ´Î¹¥»÷Ó°ÏìÁËCloroxµÄÔì×÷ºÍÏúÊÛÁ÷³Ì £¬ÒÔ¼°ÆäÍÆ¹ã¶©µ¥ºÍά³ÖÕý³£ÔËÓªµÄÄÜÁ¦¡£


https://www.infosecurity-magazine.com/news/clorox-disrupted-cyber-attack/


4¡¢´Óǰ°ëÄêCloudflare R2ÍйܵĴ¹µöÍøÒ³Á÷Á¿Ôö³¤61±¶


NetskopeÔÚ8ÔÂ14ÈÕ³Æ £¬´Ó½ñÄê2Ôµ½7Ô £¬Cloudflare R2ÖÐÍйܵĴ¹µöÒ³ÃæÁ÷Á¿Ôö³¤ÁË61±¶¡£´óÎÞÊý´¹µö»î¶¯¶¼Õë¶ÔMicrosoftµÇ¼ʹ´¦ £¬µ«Ò²ÓÐһЩÕë¶ÔAdobe¡¢DropboxºÍÆäËüÔÆÀûÓ÷¨Ê½¡£ÕâЩ¹¥»÷ÖØÒªÕë¶Ô±±ÃÀºÍÑÇÖÞ £¬Éæ¼°¸÷ÀàÁìÓò £¬ÒÔ¼¼Êõ¡¢½ðÈÚ·þÎñºÍÒøÐÐҵΪÊס£ÕâЩ´¹µö»î¶¯²»½öÀûÓÃCloudflare R2·Ö·¢¾²Ì¬´¹µöÒ³Ãæ £¬»¹ÀûÓøù«Ë¾µÄTurnstile²úÆ·À´Èƹý¼ì²â¡£


https://www.netskope.com/blog/evasive-phishing-campaign-steals-cloud-credentials-using-cloudflare-r2-and-turnstile


5¡¢AhnLab·¢ÏÖHakuna MatataÕë¶Ôº«¹úÆóÒµµÄ¹¥»÷»î¶¯


8ÔÂ16ÈÕ £¬AhnLabй©ÀÕË÷Èí¼þHakuna MatataÕý±»ÓÃÀ´¹¥»÷º«¹úµÄÆóÒµ¡£Hakuna MatataÊǽüÆÚ¿ª·¢µÄÀÕË÷Èí¼þ £¬ÓÚ7ÔÂ6ÈÕ³õ´Î±»Åû¶¡£Hakuna MatataÓëÆäËü´«Í³ÀÕË÷Èí¼þµÄ·ÖÆçÖ®´¦ÔÚÓÚ £¬ËüÓµÓÐClipBankerÖ°ÄÜ¡£¼´±ãÔÚ¼ÓÃÜÖ®ºó £¬ËüÒÀÈ»±£ÁôÔÚϵͳÖÐ £¬½«±ÈÌØ±ÒÇ®°üµØÖ·¸ü¸ÄΪ¹¥»÷ÕߵĵØÖ·¡£¼ÓÃÜϵͳºó £¬¹¥»÷Õß»áɾ³ý¹¥»÷ÖÐʹÓõÄÊÂÎñÈÕÖ¾ºÍ¶ñÒâÈí¼þ £¬Òò¶øºÜÄÑ»ñµÃÈ·ÇеÄÐÅÏ¢¡£µ«ÊÇ £¬Æ¾¾Ý¸÷ÀàÇé¿ö £¬´§Ä¦Ô¶³Ì×ÀÃæºÍ̸£¨RDP£©±»×÷Ϊ³õʼ¹¥»÷ÔØÌå¡£


https://asec.ahnlab.com/en/56010/


6¡¢Group-IB°ä²¼¹ØÓÚ¶ñÒâÈí¼þGigabudµÄ·ÖÎö»ã±¨


8ÔÂ14ÈÕ £¬Group-IB°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þGigabudµÄ·ÖÎö»ã±¨¡£ËüÖØÒªÕë¶ÔÌ©¹ú¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢Ô½ÄÏ¡¢·ÆÂɱöºÍÃØÂ³µÄ½ðÈÚ»ú¹¹¡£Gigabud RATÔÚÓû§±»ÊÚȨ½øÈë¶ñÒâÀûÓÃ֮ǰ²»»áÖ´ÐÐÈκζñÒâ»î¶¯ £¬Õâ¼Ó´óÁ˼ì²âµÄÄѶÈ¡£ËüÖØÒªÍ¨¹ýÆÁϼÔìÀ´ÍøÂçÃô¸ÐÐÅÏ¢ £¬¶ø²»ÊÇHTML¸²¸Ç¹¥»÷¡£³ÖÐøµ÷²é·¢ÏÖÁËÁíÒ»¸ö²»¾ß±¸RATÖ°ÄܵÄÑù±¾ £¬´úºÅΪGigabud.Loan £¬ÕâÊÇÒ»¸öαÔìµÄ´û¿îÀûÓà £¬»áÇÔÈ¡Óû§ÊäÈëµÄÊý¾Ý¡£


https://www.group-ib.com/blog/gigabud-banking-malware/