eXotic VisitÕë¶ÔÓ¡¶ÈºÍ°Í»ù˹̹µÄ Android Óû§
°ä²¼¹¦·ò 2024-04-161. eXotic VisitÕë¶ÔÓ¡¶ÈºÍ°Í»ù˹̹µÄ Android Óû§
4ÔÂ10ÈÕ£¬Ò»¸öÃûΪ eXotic Visit µÄ»îÔ¾ Android ¶ñÒâÈí¼þ»î¶¯ÖØÒªÕë¶ÔÄÏÑÇÓû§£¬³ö¸ñÊÇÓ¡¶ÈºÍ°Í»ù˹̹µÄÓû§£¬¶ñÒâÈí¼þͨ¹ýרÃÅÍøÕ¾ºÍ Google Play É̵ê·Ö·¢¡£Ä³ÍøÂ簲ȫ¹«Ë¾°µÊ¾£¬ÕâÏî»î¶¯×Ô 2021 Äê 11 ÔÂÒÔÀ´Ò»ÏòÔÚ½øÐУ¬ÓëÈκÎÒÑÖªµÄÍþвÐÐΪÕß»ò×éÖ¯Î޹ء£ËüÔÚ×·×ÙÃûΪVirtual InvadersµÄÐж¯±³ºóµÄ×éÖ¯¡£¾Ý³Æ£¬¸Ã»î¶¯ÓµÓкÜÇ¿µÄÕë¶ÔÐÔ£¬Google Play ÉÏÌṩµÄÀûÓ÷¨Ê½µÄ×°ÖÃÊýÁ¿Î¢ºõÆä΢£¬´Ó 0 µ½ 45 ²»µÈ¡£ÕâЩÀûÓ÷¨Ê½Òѱ»Ï¼ܡ£ÕâЩÐéαµ«ÊµÓõÄÀûÓ÷¨Ê½ÖØÒª¼Ù×°³ÉÐÂÎÅ·þÎñ£¬ÀýÈç Alpha Chat¡¢ChitChat¡¢Defcom¡¢Dink Messenger¡¢Signal Lite¡¢TalkU¡¢WeTalk¡¢Wicker Messenger ºÍ Zaangi Chat¡£¾Ý³Æ£¬Ô¼Äª 380 ÃûÊܺ¦ÕßÏÂÔØÁËÕâЩÀûÓ÷¨Ê½²¢´´½¨ÁËÕÊ»§£¬ÒÔʹÓÃËüÃÇ·¢ËÍÐÂÎÅ¡£
https://thehackernews.com/2024/04/exotic-visit-spyware-campaign-targets.html?&web_view=true
2. GSMA °ä²¼Òƶ¯Íþвµý±¨¿ò¼Ü
4ÔÂ10ÈÕ£¬GSM лáµÄڲƺͰ²È«Ó××é (FASG) °ä²¼Á˳õ°æ¿ò¼Ü£¬ÓÃÓÚÒԽṹ»¯·½Ê½ÃèÊöµÐÊÖÈôºÎƾ¾ÝËûÃÇʹÓõÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½ (TTP) ¹¥»÷ºÍʹÓÃÒÆ¶¯ÍøÂç¡£ÒÆ¶¯Íþвµý±¨¿ò¼Ü (MoTIF) רһÓÚÓëÒÆ¶¯ÍøÂçÓйصĹ¥»÷£¬ÕâЩ¹¥»÷ÉÐδ±»MITRE ATT&CK£¨ºÏÓÃÓÚÆóÒµºÍÒÆ¶¯£©ºÍMITRE FiGHTµÈÏÖÓй«¹²¿ò¼Üº¸Ç¡£ÁìÓòÔ̺¬ 2G¡¢3G¡¢4G¡¢5G£¬Ô̺¬ËùÓÐÀàÐ͵ĵçÕÛ·þÎñÍÆ¶¯Õߣ¨ÀýÈçÖÜÓΡ¢SMS¡¢VoIP£©ºÍ½«À´Òƶ¯¼¼ÊõµÄÑݽø¡£»¹Ô̺¬Õë¶ÔÒÆ¶¯ÍøÂç¼°Æä¿Í»§µÄڲƹ¥»÷¡£MoTIF ×¼ÔòÌṩÁË MoTIF µÄ¸ÅÊö£¬²¢½ç˵ÁË¿ò¼ÜÖÐÖ¸¶¨µÄ¼¼ÊõºÍ×Ó¼¼Êõ¡£
https://www.helpnetsecurity.com/2024/04/10/gsma-mobile-threat-intelligence-framework/?web_view=true
3. µØÔµÕþÖÎÑÏÖØ´óÊÆ¼Ó¾ç OT ÍøÂç¹¥»÷
4ÔÂ15ÈÕ£¬´Óǰ¼¸Ä꣬³öÓÚÕþÖζ¯»ú¡¢Ôì³ÉÈËÉíºó¹ûµÄºÚ¿Í¹¥»÷ÓÐËùÔö³¤¡£ÏÕЩËùÓÐÕâЩϮ»÷¶¼Óë¶íÂÞ˹ÈëÇÖÎÚ¿ËÀ¼»òÔÚ½øÐеÄÒÁÀÊ/ÒÔÉ«ÁÐì¶ÜÓйء£´Óº¹ÇàÉÏ¿´£¬ÕâЩ¹¥»÷²¢²»ÊǼ«¶È¸´ÔÓ£¬µ«Ã¿Ó×ÎÒ¶¼ÔÚ¹Ø×¢´óÐÍ˵»°Ä£ÐÍÈËΪÖÇÄܵijöÏÖ£¬¿´¿´ÕâЩÈËΪÖÇÄÜÊÇ·ñ»áÈúڿÍÐж¯Ö÷ÒåÕß±äµÃÔ½·¢×³´ó¡£ÀÕË÷Èí¼þÊÇ×ï¿ý»öÊס£È»¶ø£¬ÀÕË÷Èí¼þ´ÓÀ´Íƶ¯ÁËÓµÓÐ OT ºó¹ûµÄ¹¥»÷µÄ¸´ºÏÄêÔö³¤Âʸü¸ß¡£19% µÍÓÚÎÒÃǽñÄêµÄÔ¤ÆÚ£¬ÎÒÃǽ«ÕâÒ»²î¾à¹éÒòÓÚÕ½ÊõµÄת±ä¡£ÀÕË÷Èí¼þ¶Ô OT µÄÓ°ÏìºÜ´óÒ»²¿ÃÅÊÇÓÉÓÚÒÀÀµÐÔ¡£ÀÕË÷Èí¼þ¹¥»÷ IT ÍøÂ磬¼ÓÃÜ´óÁ¿ÄÚÈÝ£¬´Ó¶øµ¼Ö´óÁ¿ IT ·þÎñÆ÷ºÍ·þÎṉ̃»¾¡£OT ¹Ø¹Ø¡£ÎªÊ²Ã´£¿ÊÂʵ֤Ã÷£¬GA»Æ½ð¼× OT ×Ô¶¯»¯ÏµÍ³±ØÒªÒ»Ð©ÒṈ̃»¾µÄ IT ·þÎñ¡£
https://www.helpnetsecurity.com/2024/04/15/andrew-ginter-waterfall-security-ot-cyber-attacks/
4. WikiLoader ͨ¹ýÎı¾±à×ëÆ÷ Notepad++ ½øÐд«²¼
4ÔÂ14ÈÕ£¬AhnLab °²È«Ó¦¼±ÏìÓ¦ÖÐÐĵݲȫ×êÑÐÈËÔ±·¢ÏÖÁËÕë¶Ô¿í·ºÊ¹ÓÃµÄ Notepad++ Îı¾±à×ëÆ÷µÄ¸´ÔÓ¶ñÒâÈí¼þ»î¶¯¡£ÕâÖÖ¹¥»÷µÄÖ÷ÌâÊÇÒ»ÖÖ³ÆÎª DLL ½Ù³ÖµÄ¼¼Êõ¡£¹¥»÷Õß°ÂÃØÅú¸ÄÁËĬÈϵÄNotepad++²å¼þ¡°mimeTools.dll¡±£¬ÒÔ±ãÔÚÎı¾±à×ëÆ÷Æô¶¯Ê±Ö´ÐжñÒâ´úÂë¡£ÓÉÓڸòå¼þËæÃ¿¸ö Notepad++ ×°ÖÃһ·Ìṩ£¬Òò¶øÓû§ÔÚʹÓøÃÈí¼þʱ»áÎÞÒâÖд¥·¢Ï°È¾¡£ÔÚ°Ü»µµÄ²å¼þÖУ¬¹¥»÷ÕßÓ×Ðĵذµ²ØÁËËûÃǵÄÓÐЧ¸ºÔØ¡£¼Ù×°³ÉÎÞº¦Ö¤ÊéµÄÎļþ¡°certificate.pem¡±¸²¸ÇÁ˼ÓÃÜµÄ shellcode¡ª¡ª¹¥»÷µÄ³õʼ½×¶Î¡£Ëæ×ŶñÒâÈí¼þ¸²¸ÇÁíÒ»¸ö²å¼þ¡°BingMaps.dll¡±ÖеĴúÂë²¢½«Ïß³Ì×¢ÈëÖ÷Ìâ¡°explorer.exe¡±Windows ¹ý³Ì£¬¸´ÔÓÐÔÒ²»áÔö³¤¡£ÕâÈ·±£ÁËÓÆ¾ÃÐÔ²¢Ê¹¹¥»÷¸üÄÑÒÔ¼ì²â¡£
https://securityonline.info/popular-text-editor-notepad-compromised-in-wikiloader-malware-attack/
5. ¼äµý»î¶¯¾íÍÁ³ÁÀ´£¬LightSpy ¶Ô×¼ÄÏÑÇ
4ÔÂ14ÈÕ£¬LightSpy ×î³õÓÚ 2020 ÄêÔÚÏã¸ÛÑÏÖØ´óÊÆ¼Ó¾çÆÚ¼ä±»·¢ÏÖ£¬ÒÔÆäÀàËÆ¼¤¹âµÄ¾Û½¹ÄÜÁ¦ºÍ׳´óµÄÊý¾ÝÍøÂçÄÜÁ¦¶øÎÅÃû¡£×îеİ汾±»³ÆÎª¡°F_Warehouse¡±£¬³öÏÖ³öÊÊÓ¦ÐÔ¸üÇ¿µÄÍþв¡£Ëüѡȡ¼´²å¼´ÓÃÄ£¿éÉè¼Æ£¬ÔÊÐí¹¥»÷Õß×Ô½ç˵¼à¶½ÒÔÂú×ãÌØ¶¨Ö¸±ê£º¿´²»¼ûµÄ¼à¶½¡¢Éî¶ÈÊý¾ÝÉøÈëºÍÔ¶³Ì½ÚÔìµÄÍþв¡£LightSpy ѡȡ֤Êé¹Ì¶¨µÈ¸´ÔÓ¼¼ÊõÀ´Ìӱܼì²â¡£ËüÖØÒªÍ¨¹ýÊÜËðµÄÐÂÎÅÍøÕ¾´«²¼£¬ÕâÐ©ÍøÕ¾Ô̺¬ÓëÃô¸ÐÕþÖÎÎÊÌâÓйصÄÄÚÈÝ£¬ÀýÈç֮ǰÔÚÏã¸Û¿¹ÒéÆÚ¼ä¹Û²ìµ½µÄÎÊÌâ¡£Ò»µ©É豸Êܵ½ÇÖº¦£¬LightSpy ¾Í»á²¿Êð¶à½×¶ÎÖ²Èë¹ý³Ì£¬Ö𲽿ªÊÍÆäÈ«Êý¼äµýÖ°ÄÜ¡£
https://securityonline.info/espionage-campaign-returns-lightspy-targets-southern-asia/
6. CISA½«D-LINK¶à¸ö·ì϶Ôö³¤µ½ÒÑÖªÀûÓõķì϶Ŀ¼
4ÔÂ11ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö (CISA) ½«ÒÔÏ D-Link ¶à NAS É豸ȱµãÔö³¤µ½ÆäÒÑÖª¿ÉÀûÓ÷ì϶ (KEV) Ŀ¼ÖУºD-Link ¶à¸ö NAS É豸ʹÓÃÓ²±àÂëÍ´´¦·ì϶£¨CVE-2024-3272£©ºÍD-Link ¶à¸ö NAS É豸ºÅÁî×¢Èë·ì϶£¨CVE-2024-3273£©¡£CVE-2024-3272 ÊÇÓ°Ïì D-Link ¶à¸ö NAS É豸µÄÓ²±àÂëÍ´´¦Ê¹Ó÷ì϶¡£¸ÃȱµãÓ°Ïì D-Link DNS-320L¡¢DNS-325¡¢DNS-327L ºÍ DNS-340L£¬ÕâЩÉ豸Ô̺¬Ó²±àÂëÍ´´¦£¬ÔÊÐí¹¥»÷Õß½øÐо¹ýÉí·ÝÑéÖ¤µÄºÅÁî×¢È룬´Ó¶øµ¼ÖÂÔ¶³Ì¡¢Î´¾ÊÚȨµÄ´úÂëÖ´ÐС£CISA Ö¸³ö£¬¸ÃȱµãÓ°ÏìÒÑ´ïµ½ÐÔÃüÖÜÆÚÖÕÖ¹ (EOL) »ò·þÎñÖÕÖ¹ (EOS) ÐÔÃüÖÜÆÚµÄ D-Link ²úÆ·£¬Òò¶ø£¬Ó¦Æ¾¾Ý¹©¸øÉ̵ÄÅúʾÍËÒÛ²¢¸ü»»ÕâЩ²úÆ·¡£È±µã CVE-2024-3272 ÊÇÓ°Ïì D-Link ¶à¸ö NAS É豸µÄºÅÁî×¢Èë·ì϶¡£¸Ã·ì϶ӰÏìD-Link DNS-320L¡¢DNS-325¡¢DNS-327L ºÍ DNS-340L£¬ÆäÖÐÔ̺¬ºÅÁî×¢Èë·ì϶¡£
https://securityaffairs.com/161739/security/cisa-d-link-multiple-nas-devices-bugs-known-exploited-vulnerabilities-catalog.html?web_view=true


¾©¹«Íø°²±¸11010802024551ºÅ