NoName057(16)£º¶íÂÞ˹ DDoS ×ÌÈÅÕß¶Ô×¼Î÷·½

°ä²¼¹¦·ò 2024-03-05
1. NoName057(16)£º¶íÂÞ˹ DDoS ×ÌÈÅÕß¶Ô×¼Î÷·½


3ÔÂ3ÈÕ£¬ÎÚ¿ËÀ¼Õ½ÕùÒý·¢ÁËÐÂÐÍÍøÂçì¶Ü£¬ºÚ¿Í»î¶¯¼¯Ìå³äÈÎÁ˹ú¶ÈÀûÒæµÄ´úÀíÈË¡£¶íÂÞ˹µÄ NoName057(16) ÒѳÉΪ DDoSia ÏîÄ¿

µÄ´úÃû´Ê£¬ÕâÊÇÒ»ÏîÕë¶ÔÖ§³ÖÎÚ¿ËÀ¼µÄ¹ú¶ÈµÄ³ÖÐø DDoS ¹¥»÷»î¶¯¡£ÓëרһÓÚÊý¾Ý͵ÇÔ»ò¼äµý»î¶¯µÄ×éÖ¯·ÖÆç£¬NoName057(16) ×·Çóѹµ¹ºÍ·ÛË飬½«Êý×ÖÊÀ½çÔì³ÉµØÔµÕþÖÎÕ½ÕùµÄ¹¤¾ß¡£×ÔSEKOIA.IOµ±ÎÒÃÇÆðÍ·×·×ÙËûÃÇʱ£¬ËûÃǵIJ½ÖèÒѾ­²úÉúÁËÑݱ䣬½ÒʾÁËËæ×Åì¶Ü³±Ë®µÄ±ä¶¯ÒÔ¼°ÓëÎ÷·½¸ü¿í·ºµÄÑÏÖØ´óÊÆ¶ø²úÉúµÄ³ÖÐøÇÒÊÊÓ¦ÐÔÇ¿µÄÍþв¡£2023 Äê 11 Ô 11 ÈÕ£¬DDoSia ³Á´ó¸üУ¬À©´óÁ˶Ըü¿í·ºÉ豸ºÍ²Ù×÷ϵͳµÄ¼æÈÝÐÔ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ÖÎÀíԱƾ¾ÝµØÀíµØÎ»¶¨ÔìÁ˰汾£¬ÖÒ¸æ¶íÂÞ˹Óû§Ôڲμӹ¥»÷ʱʹÓà VPN À´¸²¸Ç×Ô¼ºµÄµØÎ»¡£Õâ¸öа汾ÒýÈëÁ˸ü¸´ÔÓµÄÊý¾Ý¼ÓÃÜ£¬Äܹ»¸ü¾«Ãܵظú×Ù DDoSia Óû§¡£ÕâЩÊý¾Ý¿ÉÄÜÓÐÖúÓÚÖÎÀíÔ±ÆÀ¹ÀÏîÖ÷ÕÅÓÐЧÐÔ£¬²¢ÇÒ¿ÉÄܳÉΪ·¨ÂɺÍÍþвµý±¨¹¤×÷µÄ¹óÖØ×ÊÔ´¡£


https://securityonline.info/noname05716-russias-ddos-disruptors-target-the-west/


2. Predator ¼äµýÈí¼þÊæÕ¹£º11 ¸ö¹ú¶ÈÄ¿Ç°Ãæ¶Ô·çÏÕ


3ÔÂ3ÈÕ£¬ Predator ÒÆ¶¯¼äµýÈí¼þ±³ºóµÄ²Ù×÷ÕßÒÀȻûÓб»¹«¼ÒÆØ¹âºÍÉó²éÏŵ¹¡£Recorded Future µÄ Insikt ¼¯ÍÅ×êÑÐÈËÔ±¸æ·¢Á˼äµýÈí¼þ³Á½¨µÄ»ù´¡ÉèÊ©£¬Åú×¢ Predator ¿ÉÄÜÔÚÖÁÉÙ 11 ¸ö¹ú¶È»ý¼«Ê¹Óá£ÁîÈËÓÇÓôµÄÊÇ£¬ÕâÔ̺¬²©´ÄÍßÄɺͷÆÂɱö£¬ÕâЩµØÓòµÄ Predator ¿Í»§´Ëǰ²¢²»ÎªÈËËùÖª¡£ÓÉ Cytrox ¿ª·¢²¢ÓÉ Intellexa ͬÃËÖÎÀíµÄ Predator ×Ô 2019 ÄêÒÔÀ´Ò»ÏòÔÚ¹ÍÓ¶¼äµýÈí¼þÁìÓòÖÐո¶ͷ½Ç¡£¸Ã¹¤¾ßÒѽøÈëÖÁÉÙ 11 ¸ö¹ú¶È£¬Ô̺¬°²¸çÀ­¡¢ÑÇÃÀÄáÑÇ¡¢²©´ÄÍßÄÉ¡¢°£¼°¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢¹þÈø¿Ë˹̹¡¢Ãɹ𢰢Âü¡¢·ÆÂɱö¡¢É³Ìذ¢À­²®¡¢Í¦°ÎÄá´ïºÍ¶à°Í¸ç¡£×¨Îª Android ºÍ iOS É豸Éè¼Æ£¬ÆäÒþÃØÉøÈëÖ°ÄÜʹÆä¿ÉÄÜÔÚÓû§²»ÖªÇéµÄÇé¿öϽӼûÉ豸µÄÂó¿Ë·ç¡¢ÉãÏñÍ·ºÍÃô¸ÐÊý¾Ý¡£ÕâÖÖ¶àÖ°ÄÜÐÔ£¬¼ÓÉÏÆäÄÑÒÔ×½ÃþµÄÐÔÖÊ£¬Ê¹ Predator ³ÉΪ¶ñÒâÐÐΪÕßÊÖÖеÄ׳´ó¹¤¾ß¡£


https://securityonline.info/predator-spyware-spreads-11-countries-now-at-risk/


3. WhatsApp ÆÈʹ Pegasus ¼äµýÈí¼þ·ÖÏíÆä°ÂÃØ´úÂë


3ÔÂ4ÈÕ£¬¾Ý¡¶ÎÀ±¨¡·±¨Â·£¬WhatsApp ºÜ¿ì½«»ñµÃË÷Çó NSO ¼¯ÍÅ Pegasus ¼äµýÈí¼þ¡°È«ÊýÖ°ÄÜ¡±µÄȨÏÞ£¬¸ÃÈí¼þÊÇÒÔÉ«Áйú·À²¿³Ö¾ÃÒÔÀ´Ò»Ïò½«ÆäÊÓΪ¡°¸ß¶È»úÃÜ¡±µÄ¹ú¶È»úÃÜ¡£×Ô 2019 ÄêÒÔÀ´£¬WhatsApp Ðû³Æ Pegasus ±»ÓÃÀ´ÔÚÁ½ÖÜÄڼල 1,400 Ãû WhatsApp Óû§£¬Î´¾­ÊÚȨ½Ó¼ûËûÃǵÄÃô¸ÐÊý¾Ý£¬Ô̺¬¼ÓÃÜÐÂÎÅ£¬¶ûºó£¬WhatsApp Ò»ÏòÒªÇó½Ó¼û NSO µÄ¼äµýÈí¼þ´úÂë¡£Ars Æäʱָ³ö£¬WhatsApp ¸æ×´ NSO ÊÇ¡°Ç°ËùδÓеÄ˾·¨Ðж¯¡±£¬¡°Õë¶ÔµÄÊÇÏòÊÀ½çÁйúµ±¾ÖÏúÊÛ¸´ÔÓ¶ñÒâÈí¼þ·þÎñµÄ²»Êܼà¹ÜµÄÐÐÒµ¡±¡£


https://news.hitb.org/content/whatsapp-finally-forces-pegasus-spyware-maker-share-its-secret-code


4. Õë¶ÔÓëÓ¡¶È±í½»»î¶¯ÓйصÄÅ·ÖÞ¹ÙÔ±µÄкóÃÅWINELOADER


2ÔÂ29ÈÕ£¬¾Ý¹Û²ì£¬Ò»¸öÃûΪSPIKEDWINEµÄÏÈǰÎÞÖ¤ÍþвÐÐΪÕßʹÓÃÃûΪWINELOADERµÄкóÃÅÕë¶ÔפÓÐÓ¡¶È±í½»Ê¹ÍŵÄÅ·ÖÞ¹ú¶ÈµÄ¹ÙÔ±¡£Æ¾¾ÝZscaler ThreatLabz µÄ»ã±¨£¬µÐÊÖÔÚµç×ÓÓʼþÖÐʹÓÃÁËÒ»¸ö¿´ËÆÀ´×ÔÓ¡¶È´óʹµÄ PDF Îļþ£¬Ô¼Çë±í½»ÈËÔ±²ÎÓë 2024 Äê 2 Ô 2 Èյį·¾Æ»î¶¯¡£¸ÃPDF ÎĵµÓÚ 2024 Äê 1 Ô 30 ÈÕ´ÓÀ­ÍÑάÑÇÉÏ´«µ½ VirusTotal¡£Ò²¾ÍÊÇ˵£¬ÓÐÖ¤¾ÝÅú×¢£¬¸Ã»î¶¯¿ÉÄÜÖÁÉÙ´Ó 2023 Äê 7 Ô 6 ÈÕÆð¾ÍÆðÍ·»îÔ¾£¬ÓÉÓÚ·¢ÏÖÁË´Óͳһ¸ö¹ú¶È¡£°²È«×êÑÐÈËÔ±ËÕµÏÆÕ¡¤ÐÁ¸ñ (Sudeep Singh) ºÍÂÞÒÁ¡¤Ì© (Roy Tay) °µÊ¾£º¡°Õâ´Î¹¥»÷µÄÌØµãÊǹ¥»÷Á¿¼«¶ÈÓ×£¬²¢ÇÒÔÚ¶ñÒâÈí¼þºÍºÅÁîÓë½ÚÔì (C2) »ù´¡ÉèÊ©µ±Ñ¡È¡ÁËÏȽøµÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½ (TTP)¡£¡¹Øâ´ÎÐÂÐ͹¥»÷µÄÖ÷ÌâÊÇ PDF Îļþ£¬¸ÃÎļþǶÈëÁËÒ»¸ö¼Ù×°³Éµ÷²éÎʾíµÄ¶ñÒâÁ´½Ó£¬¶½´ÙÊÕ¼þÈËÌîд¸ÃÁ´½ÓÄÜÁ¦²Î¼Ó¡£µ¥»÷¸ÃÁ´½Ó½«Îª°ü·Ñ½âÏýµÄ JavaScript ´úÂëµÄ HTML ÀûÓ÷¨Ê½£¨¡°wine.hta¡±£©Ì¯Æ½Â·Â·£¬ÒÔ´ÓͳһÓò¼ìË÷Ô̺¬ WINELOADER µÄ±àÂë ZIP ´æµµ¡£


https://thehackernews.com/2024/02/new-backdoor-targeting-european.html


5. Êý°ÙÍò¸ö GitHub ´æ´¢¿â±»·¢ÏÖϰȾ¶ñÒâ´úÂë


2ÔÂ29ÈÕ£¬°²È«×êÑÐÈËÔ±ÔÚ GitHub ÉÏ·¢ÏÖÁË´ó¹æÄ£µÄ´æ´¢¿â»ìºÏ¹¥»÷»î¶¯£¬Ó°ÏìÁ˳¬¹ý 100,000 ¸ö´æ´¢¿â£¬ÉõÖÁ¿ÉÄÜ»¹º±¼û°ÙÍòÈË¡£ÕâÖÖ¸´ÔÓµÄÍøÂç¹¥»÷ͨ¹ýÓÕÆ­¿ª·¢ÈËÔ±ÏÂÔØºÍʹÓüÙ×°³ÉºÏ·¨´æ´¢¿âµÄ¶ñÒâ´æ´¢¿âÀ´Õë¶Ô¿ª·¢ÈËÔ±¡£Apiiro ¿ª·¢ÁËÒ»ÖÖ¶ñÒâ´úÂë¼ì²âϵͳ£¬¸Ãϵͳ¿É¼à¿Ø´úÂë¿â²¢Ê¹ÓÃÉî¶È´úÂë·ÖÎöºÍ·´»ìºÏµÈÏȽø¼¼ÊõÀ´¼ø±ðºÍÔ¤·À´ËÀ๥»÷¡£ÄúÄܹ»Ê¹ÓÃANY.RUN ¶ñÒâÈí¼þɳÏäºÍÍþвµý±¨²éÕÒÀ´·ÖÎö¶ñÒâÈí¼þÎļþ¡¢ÍøÂ硢ģ¿éºÍ×¢²á±í»î¶¯£¬´Ó¶øÊ¹ÄúÄܹ»Ö±½Ó´Óä¯ÀÀÆ÷Óë²Ù×÷ϵͳ½øÐн»»¥¡£ÕâЩ´æ´¢¿â»á×Ô¶¯·Ö²æÊýǧ´Î£¬²¢ÔÚ¸÷ÀàÔÚÏ߯½Ì¨ÉϽøÐÐÍÆ¹ã£¬ÒÔÌá¸ßÆä¿É¼ûÐԺͱ»¿ª·¢ÈËÔ±ÃýÎóʹÓõĿÉÄÜÐÔ¡£


https://gbhackers.com/millions-of-github-repos-found-infected/


6. ÒþÐÎ GTPDOOR Linux ¶ñÒâÈí¼þÕë¶ÔÒÆ¶¯ÔËÓªÉÌÍøÂç


3ÔÂ3ÈÕ£¬°²È«×êÑÐÈËÔ± HaxRob ·¢ÏÖÁËÒ»¸öÒÔǰδ֪µÄ Linux ºóÃÅ£¬ÃûΪ GTPDOOR£¬×¨ÎªÒƶ¯ÔËÓªÉÌÍøÂçÄڵİÂÃØ²Ù×÷¶øÉè¼Æ¡£GTPDOOR ±³ºóµÄÍþвÐÐΪÕß±»ÒÔΪÒÔ GPRS ÖÜÓλ¥»» (GRX) ×ó½üµÄϵͳΪָ±ê£¬ÀýÈç SGSN¡¢GGSN ºÍ P-GW£¬ÕâЩϵͳ¿ÉÒÔΪ¹¥»÷ÕßÌṩ¶ÔµçÐÅÖ÷ÌâÍøÂçµÄÖ±½Ó½Ó¼û¡£GRX ÊÇÒÆ¶¯µçÐŵÄÒ»¸ö×é¼þ£¬¿ÉÍÆ½ø¿ç·ÖÆçµØÀíÇøÓòºÍÍøÂçµÄÊý¾ÝÖÜÓηþÎñ¡£·þÎñ GPRS Ö§³Ö½Úµã (SGSN)¡¢Íø¹Ø GPRS Ö§³Ö½Úµã (GGSN) ºÍ P-GW£¨·Ö×éÊý¾ÝÍøÂçÍø¹Ø£¨ÓÃÓÚ 4G LTE£©£©ÊÇÒÆ¶¯ÔËÓªÉÌÍøÂç»ù´¡ÉèÊ©ÄÚµÄ×é¼þ£¬Ã¿¸ö×é¼þÔÚÒÆ¶¯Í¨Ñ¶ÖвûÑï·ÖÆçµÄ×÷Óá£ÓÉÓÚSGSN¡¢GGSNºÍP-GWÍøÂç¸ü¶àµØÂ¶³öÔÚ¹«¼Ò¿ÌÏ£¬IPµØÖ·ÁìÓòÁÐÔÚ¹«¿ªÎļþÖУ¬×êÑÐÈËÔ±ÒÔΪËüÃÇ¿ÉÄÜÊÇ»ñµÃÒÆ¶¯ÔËÓªÉÌÍøÂç³õʼ½Ó¼ûȨÏÞµÄÖ¸±ê¡£GTPDOOR ÊÇÒ»ÖÖרΪµçÐÅÍøÂçÁ¿Éí¶¨ÔìµÄ¸´ÔÓºóÃŶñÒâÈí¼þ£¬ÀûÓà GPRS Ëí·ºÍ̸½ÚÔìÆ½Ãæ (GTP-C) ½øÐÐÒñ±ÎºÅÁîºÍ½ÚÔì (C2) ͨѶ¡£ËüÉè¼ÆÓÃÓÚ²¿ÊðÔÚÓë GRX ÏàÁڵĻùÓÚ Linux µÄϵͳÖУ¬ÕƹÜ·ÓɺÍת·¢ÖÜÓÎÓйصÄÐÅÁîºÍÓû§Æ½ÃæÁ÷Á¿¡£Ê¹Óà GTP-C ½øÐÐͨѶÔÊÐí GTPDOOR ÓëºÏ·¨ÍøÂçÁ÷Á¿»ìºÏ£¬²¢ÀûÓò»Êܳ߶Ȱ²È«½â¾ö¹æ»®¼à¿ØµÄÒÑÔÊÐí¶Ë¿Ú¡£ÎªÁËÌá¸ßÒñ±ÎÐÔ£¬GTPDOOR Äܹ»¸ü¸ÄÆä¹ý³ÌÃû³ÆÒÔ·ÂÕպϷ¨µÄϵͳ¹ý³Ì¡£


https://www.bleepingcomputer.com/news/security/stealthy-gtpdoor-linux-malware-targets-mobile-operator-networks/