DINODASRAT LINUX ±äÖÖÕë¶ÔÈ«ÇòÓû§
°ä²¼¹¦·ò 2024-04-023ÔÂ31ÈÕ,¿¨°Í˹»ù³¢ÊÔÊÒµÄ×êÑÐÈËÔ±·¢ÏÖÁË Linux °æ±¾µÄ¶àƽ̨ºóÃÅ DinodasRAT£¬¸ÃºóÃű»ÓÃÓÚÕë¶ÔÖйú¡¢ÍÁ¶úÆäºÍÎÚ×ȱð¿Ë˹̹¡£DinodasRAT£¨±ðÃû XDealer£©ÊÇÓà C++ ±àдµÄ£¬Ö§³Ö¿í·ºµÄÖ°ÄÜÀ´¼à¶½Óû§²¢´ÓÖ¸±êϵͳÇÔÈ¡Ãô¸ÐÊý¾Ý¡£ESET ×êÑÐÈËÔ±»ã±¨³Æ£¬Windows °æ±¾µÄ DinodasRAT ±»ÓÃÓÚÕë¶Ô¹çÑÇÄǵÐÔÖʵÌåµÄ¹¥»÷¡£ESET ÓÚ 2023 Äê 10 Ô³õ´Î·¢ÏÖÐ嵀 Linux °æ±¾µÄ DinodasRAT£¬µ«×¨¼ÒÒÔΪËü×Ô 2022 ÄêÒÔÀ´¾ÍÒ»Ïò»îÔ¾¡£2024 Äê 3 Ô£¬Ç÷Ïò¿Æ¼¼×êÑÐÈËÔ±ÔÚµ÷²éÓëÖйúÓÐ¹ØµÄ APT Earth Lusca»î¶¯Ê±·¢ÏÖÁËÓɱ»×·×ÙΪ Earth Krahang µÄÍþвÐÐΪÕßÌáÒéµÄ¸´Ôӻ ¡£¸Ã»î¶¯ÖÁÉÙ´Ó 2022 ËêÊׯðÍ·ËÆºõ¾ÍºÜ»îÔ¾£¬ÖØÒªÕë¶Ôµ±¾Ö×éÖ¯¡£×Ô 2023 ÄêÆð£¬Earth Krahang ×ªÒÆµ½ÁíÒ»¸öºóÃÅ£¨ TeamT5¶¨ÃûΪ XDealer £¬ ESET ¶¨ÃûΪDinodasRAT £©¡£Ïà±ÈRESHELL£¬XDealerÌṩÁ˸üÈ«ÃæµÄºóÃÅÖ°ÄÜ¡£´Ë±í£¬ÎÒÃÇ·¢ÏÖÍþвÐÐΪÕßͬʱʹÓà Windows ºÍ Linux °æ±¾µÄ XDealer À´Õë¶Ô·ÖÆçµÄϵͳ¡£
https://securityaffairs.com/161255/malware/linux-variant-dinodasrat-backdoor.html
2. È«ÇòÃÜÂëÅçÈ÷»î¶¯Õë¶Ô VPN ϵͳ¿Éµ¼ÖÂÏµÍ³Ëø¶¨
3ÔÂ31ÈÕ,˼¿ÆÒѰ䲼¹ØÓÚÕë¶ÔÈ«ÇòÆóҵʹÓõÄÔ¶³Ì½Ó¼û VPN (RAVPN) ϵͳµÄ¿í·ºÃÜÂëÅçÈ÷»î¶¯µÄÑϳÁÖҸ档ÕâÖÖ¹¥»÷¼¤ÔöµÄÖ÷ÕÅÊÇÓÃͨÓÃÃÜÂ븲û VPN µÇ¼£¬¿ÉÄÜ»áËø¶¨ºÏ·¨Óû§²¢ÇÖÈÅÔ¶³Ì¹¤×÷¡£ÃÜÂëÅçÈ÷»î¶¯»áÓ°Ïì¸÷Àà VPN ÌṩÉÌ£¬¶ø²»½ö½öÊÇ˼¿Æ¡£ÒÀÀµÔ¶³Ì½Ó¼ûµÄÆóÒµ±ØÒªÎ¬³Ö¸ß¶È¾¯Ìè¡£ÕâЩ¹¥»÷µÄºó¹û²»½ö½öÊÇδ¾ÊÚȨµÄ½Ó¼û£»ËüÃÇÓпÉÄÜËø¶¨ÕÊ»§²¢Òý·¢ÀàËÆ»Ø¾ø·þÎñ (DoS) µÄÇé¿ö£¬´Ó¶ø·ÛËéÊý×Ö²Ù×÷µÄÎÞ·ìÁ÷³Ì²¢ÇÖº¦°²È«Í¨Ñ¶µÄÆëÈ«ÐÔ¡£¸Ã»î¶¯Í¹ÏÔÁËÔ¶³Ì½Ó¼û½â¾ö¹æ»®ËùÃæ¶ÔµÄ³ÖÐøÍþв¡£×éÖ¯±ØÐëÓÅÏÈ˼¿¼×³´óµÄÉí·ÝÑéÖ¤¡¢¾¯ÌèµÄ¼à¿ØºÍ׳´óµÄÊÂÎñÏìÓ¦´òË㣬ÒÔµ±ÏÅ×Ú²»Ðݱ䶯µÄ¹¥»÷²½Öè¡£
https://securityonline.info/global-password-spraying-campaign-targets-vpn-systems-causing-lockouts/
3. ľÂí»¯ npm Èí¼þ°ü¶Ô×¼¼ÓÃÜÇ®±ÒÇ®°ü
3ÔÂ31ÈÕ,Phylum ×êÑÐÍŶÓ¶³öÁËÒ»¸ö¼Ù×°³ÉºÏ·¨¹¤¾ß°üµÄ¶ñÒânpm °ü¡£¸ÃÈí¼þ°üÃûΪ¡°vue2util¡±£¬ÍµÍµµØÖ´ÐÐÁËÒ»ÏÔӵĴòË㣬ּÔÚ´ÓºÁÎÞ½äÐĵļÓÃÜÇ®±ÒÇ®°üÖÐÇÔÈ¡ USDT ´ú±Ò¡£¡°vue2util¡±¿´ÆðÀ´ÏñÊdz߶ÈʵÓú¯ÊýµÄ¼¯ÖС£È»¶ø£¬Ëü°µ²ØÁËÒ»¸öÏÕ¶ñµÄÓÐЧ¸ºÔØ£¬µ±µ¼Èëµ½ÏîÄ¿ÖÐʱ£¬¸ÃÓÐЧ¸ºÔØ»á´ÓÔ¶³Ì·þÎñÆ÷¼ÓÔØ¶ñÒâ¾ç±¾¡£¼ÓÔØµÄ¾ç±¾ÒÔ±Ò°²ÖÇÄÜÁ´µÄÓû§ÎªÖ¸±ê£¬ËÑË÷³ÖÓÐ USDT ¼ÓÃÜÇ®±ÒµÄÇ®°ü¡£¶ñÒâÈí¼þÀûÓà ERC20 ºÏÔ¼£¨ÖÎÀí USDT£©µÄÉóÅúÁ÷³Ì¡£ËüÔÊÐí×Ô¼ºÎÞÏ޶ȵؽӼûÊܺ¦Õß³ÖÓÐµÄ USDT£¬ÎÞÐè½øÒ»²½ÊÚȨ¡£ÎªÁËÔö³¤³É¹¦µÄ»úÓö£¬¶ñÒâÈí¼þÆæÃîµØ½«ÆäÖ´ÐÐÁ´½Óµ½Óû§ÍøÒ³ÉÏÏóÕ÷Ϊ¡°buy_btn¡±µÄ°´Å¥¡£Ö»Ðèµ¥»÷һϣ¬Êܺ¦Õ߾ͻáÔÚ²»Öª²»¾õÖд¥·¢ÁîÅÆÍµÇÔ¡£
https://securityonline.info/trojanized-npm-package-targets-cryptocurrency-wallets-steals-usdt/
4. ×êÑÐÍŶӷ¢ÏÖʹÓà Google Ads ¸ú×ÙÖ°ÄÜ·Ö·¢¶ñÒâÈí¼þ
4ÔÂ1ÈÕ,AhnLab °²È«µý±¨ÖÐÐÄ (ASEC) ×î½ü¼ì²âµ½Ê¹Óà Google Ads ¸ú×ÙÖ°ÄÜ·Ö·¢µÄ¶ñÒâÈí¼þ±äÖÖ¡£ÒÑÈ·ÈϵݸÀýÅú×¢£¬¸Ã¶ñÒâÈí¼þÊÇͨ¹ý¼Ù×°³É Notion ºÍ Slack µÈÊ¢ÐÐȺ¼þµÄ×°Ö÷¨Ê½À´´«²¼µÄ¡£Ò»µ©¶ñÒâÈí¼þ×°Öò¢Ö´ÐУ¬Ëü¾Í»á´Ó¹¥»÷ÕߵķþÎñÆ÷ÏÂÔØ¶ñÒâÎļþºÍÓÐЧ¸ºÔØ¡£´ËÀà¶ñÒâÈí¼þÒÔ×°Ö÷¨Ê½´ó¾Ö·Ö·¢£¬Í¨³£Îª Inno Setup ×°Ö÷¨Ê½»ò Nullsoft ¾ç±¾×°ÖÃϵͳ (NSIS) ×°Ö÷¨Ê½¡£ÆäÖУ¬Notion_software_x64_.exeÎļþÖ±µ½×î½üÓû§ÔÚGoogleÉÏÓùؼü×Ö¡°notion¡±ËÑË÷ʱ²Å³öÏÖ¡£¹¥»÷ÕßʹÓà Google Ads ¸ú×ÙÀ´ÓÕÆÓû§ÒÔΪËûÃÇÔÚ½Ó¼ûºÏ·¨ÍøÕ¾¡£Google Ads ¸ú×ÙÔÊÐí¸æ°×¿Í»§²åÈë±í²¿ÃÅÎöÍøÕ¾µØÖ·£¬ÒÔÍøÂçºÍʹÓýӼûÕߵĽӼûÓйØÊý¾ÝÀ´ÍÆËã¸æ°×Á÷Á¿¡£Google Ads ¸ú×Ù×î³õÓÃÓÚ·ÖÎöÍøÕ¾Á÷Á¿¡£µ«ÊÇ£¬¸ÃÌØ¶¨¸æ°×²»Ô̺¬±í²¿¾²Ì¬Õ¾µã£¬¶øÊÇÔ̺¬¶ñÒâ´úÂë·Ö·¢Õ¾µã¡£
Ŀǰ¹¥»÷Õߵĸæ°×Òѱ»É¾³ý¡£
https://asec.ahnlab.com/en/63477/
5. ºÚ¿ÍʹÓà Microsoft OneNote À´²ß¶¯ÍøÂç¹¥»÷
4ÔÂ1ÈÕ,¸Ã»î¶¯ÔÚÍøÂ簲ȫר¼ÒµÄ¹Ø×¢Ï£¬Õ¹Ê¾ÁËÍøÂçÍþвµÄÐÂÇ÷Ïò£¬¼´ÀûÓó£Óõİ칫ÀûÓ÷¨Ê½Î´¾ÊÚȨ½Ó¼ûÆóÒµÍøÂç¡£pr0xylife Ê×ÏÈÔÚÆä GitHub ´æ´¢¿âÉϼͼÁ˸öñÒâ»î¶¯¡£Ëü¸æ·¢ÁËÕë¶ÔÔì×÷¡¢¼¼Êõ¡¢ÄÜÔ´¡¢ÁãÊÛ¡¢±£ÏÕºÍÆäËû¼¸¸öÐÐÒµµÄ¹«Ë¾µÄ¿í·ºµç×ÓÓʼþÍøÂç´¹µö²Ù×÷¡£ÕâЩµç×ÓÓʼþÔ̺¬Ðû³ÆÊÇ¡°°²È«ÐÂÎÅ¡±µÄ OneNote ¸½¼þ£¬ÕâÊÇÒ»ÖÖºýŪÊÕ¼þÈË´ò¿ªÎļþµÄ»Ï×Ó¡£¸Ã»î¶¯Ç¿µ÷ÁËÍøÂçÍþв²»ÐÝÑݱäµÄÇé¿ö£¬¹¥»÷ÕßÀûÓöԳ£ÓÃÀûÓ÷¨Ê½µÄÐÅÀµÀ´Èƹý´«Í³µÄ°²È«´ëÊ©¡£Ê¹Óà Microsoft OneNote Îļþ´«²¼¶ñÒâÈí¼þ´ú±í×ÅÏò¸ü¾ß´´ÔìÐԵĹ¥»÷ý½éµÄת±ä£¬Òò¶ø±ØÒª³ÁÐÂÆÀ¹ÀÍøÂ簲ȫսÊõÒÔ·À±¸´ËÀàÍþв¡£
https://gbhackers.com/microsoft-onenote-orchestrate/
6. TeamCity ½¨²¹ÁË 26 ¸ö·ì϶²¢±£ÃܾßÌåÐÅÏ¢
4ÔÂ1ÈÕ,ÔÚ JetBrains µÄ³ÖÐø¼¯³ÉºÍ½»¸¶ (CI/CD) TeamCity ×î½üµÄÈí¼þ¸üÐÂÖУ¬½â¾öÁË 26 ¸ö°²È«ÎÊÌ⡣Ȼ¶ø£¬¸Ã¹«Ë¾Ñ¡Ôñ²»Ð¹Â©ÓйØÒÑ·¢ÏÖ·ì϶µÄÈκÎϸ½Ú£¬Òý·¢ÁËרҵ½çµÄÇ¿ÁÒ»áÉÌ¡£TeamCity 2024.03 °æ±¾¸üÐÂÖ¼ÔÚ±£»¤Óû§ÃâÊÜDZÔÚÍþв£¬µ«ÆëȫûÓÐÓÐ¹Ø 26 ¸ö·ì϶µÄ¾ßÌåÐÅÏ¢£¬×ÅʵÈð²È«×¨¼Ò¸ÐÓ¦¾ªÑÈ¡£¸Ã¹«Ë¾²»×ãͨÃ÷¶È£¬³ö¸ñÊÇÔÚ Rapid7 µÄר¼ÒÆ·ÆÀ JetBrains ²»¹»Ê¢¿ªµÄÊÂÎñÖ®ºó£¬Ò»ÏòÊܵ½³ö¸ñÆ·ÆÀ¡£JetBrains Ðû³Æ£¬±£Áô¾ßÌåÐÅÏ¢Ö»ÊÇΪÁ˱£»¤Ê¹Óþɰæ TeamCity µÄ¿Í»§£¬Ö»¹ÜÕâÔÚÒµ½ç²¢Î´µÃµ½¿í·º½ÓÊÜ¡£Ö»¹ÜÈç´Ë£¬¸Ã¹«Ë¾µÄÒâͼ»¹ÊÇÄܹ»Àí½âµÄ¡£¶ÔÓÚÏëÒª¹¥»÷Èí¼þ¹©¸øÁ´µÄ·¸×ï·Ö×ÓÀ´Ëµ£¬TeamCity ÒÀÈ»ÊÇÒ»¸öÓÐÎüÒýÁ¦µÄÖ¸±ê¡£º¹ÇàÅú×¢£¬´ËÀ๥»÷¿ÉÄÜ»á²úÉúÑϳÁºó¹û£¬ÕýÈç SolarWinds µÄ°¸ÀýËùʾ¡£
https://meterpreter.org/teamcity-patches-26-vulnerabilities-keeps-details-secret/


¾©¹«Íø°²±¸11010802024551ºÅ