¶ñÒâGoogle¸æ°×ÍÆËÍ´øÓаµ²ØºóÃŵļÙIPɨÃèÈí¼þ
°ä²¼¹¦·ò 2024-04-191. ¶ñÒâGoogle¸æ°×ÍÆËÍ´øÓаµ²ØºóÃŵļÙIPɨÃèÈí¼þ
4ÔÂ18ÈÕ£¬Ð嵀 Google ¶ñÒâ¸æ°×»î¶¯ÔÚÀûÓÃÒ»×é·ÂÕպϷ¨ IP ɨÃèÈí¼þµÄÓòÀ´Ìṩһ¸öÒÔǰδ֪µÄÃûΪMadMxShell µÄºóÃÅ¡£ÍþвÐÐΪÕßʹÓÃÎóÖ²¼¼Êõ×¢²áÁ˶à¸öÀàËÆµÄÓòÃû£¬²¢ÀûÓà Google Ads ½«ÕâЩÓòÃûÍÆÖÁÕë¶ÔÌØ¶¨ËÑË÷¹Ø¼ü×ÖµÄËÑË÷ÒýÇæÁ˾ֵĶ¥²¿£¬´Ó¶øÒýÓÕÊܺ¦Õß½Ó¼ûÕâÐ©ÍøÕ¾¡£¾Ý³Æ£¬2023 Äê 11 ÔÂÖÁ 2024 Äê 3 ÔÂÆÚ¼ä×¢²áµÄÓòÃû¶à´ï 45 ¸ö£¬ÕâÐ©ÍøÕ¾¼Ù×°³É¶Ë¿ÚɨÃèºÍ IT ÖÎÀíÈí¼þ£¬Èç Advanced IP Scanner¡¢Angry IP Scanner¡¢IP ɨÃèÒÇ PRTG ºÍ ManageEngine¡£¹ÌÈ»Õâ²¢²»ÊÇÍþвÐÐΪÕßµÚÒ»´ÎÀûÓöñÒâ¸æ°×¼¼Êõͨ¹ýÀàËÆµÄÍøÕ¾Ìṩ¶ñÒâÈí¼þ·þÎñ£¬µ«ÕâÒ»·¢Õ¹±ê־ȡ½»¸¶¹¤¾ß³õ´Î±»ÓÃÀ´´«²¼¸´Ô Windows ºóÃÅ¡£
https://thehackernews.com/2024/04/malicious-google-ads-pushing-fake-ip.html
2. ¹¥»÷ÕßÀûÓÃOpenMetadataÔÚKubernetesÉϽøÐÐÍÚ¿ó
4ÔÂ17ÈÕ£¬Microsoft Threat Intelligence ·¢ÏÖÁËÕë¶ÔÔËÐÐÊ¢ÐпªÔ´ÔªÊý¾Ýƽ̨ OpenMetadata µÄ Kubernetes ¼¯ÈºµÄй¥»÷»î¶¯¡£¹¥»÷ÕßÔÚÀûÓÃһϵÁÐ×î½üÅû¶µÄ¹Ø¼ü·ì϶À´½Ó¼û¹¤×÷¸ºÔز¢×°ÖüÓÃÜÇ®±ÒÍÚ¾ò¶ñÒâÈí¼þ¡£¸Ã¹¥»÷ÀûÓÃÁË 1.3.1 ֮ǰµÄ OpenMetadata °æ±¾ÖдæÔڵĶà¸ö°²È«·ì϶£¨CVE-2024-28255¡¢CVE-2024-28847¡¢CVE-2024-28253¡¢CVE-2024-28848¡¢CVE-2024-28254£©¡£³É¹¦ÀûÓø÷ì϶½«¸³Óè¹¥»÷ÕßÔ¶³ÌÖ´ÐдúÂëµÄÄÜÁ¦£¬´Ó¶øÊ¹ËûÃÇ¿ÉÄÜÆëÈ«½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷ͨ³£´ÓÍøÂç·¸×ï·Ö×ÓɨÃèÔËÐÐÒ×Êܹ¥»÷µÄ OpenMetadata Ê·ýµÄ¶³öÓÚ»¥ÁªÍøµÄ Kubernetes ¹¤×÷¸ºÔØÆðÍ·¡£Ò»µ©¼ø±ð³öÖ¸±ê£¬¹¥»÷Õ߾ͻáÀûÓÃÕâЩ·ì϶À´½ÚÔìÍÐ¹Ü OpenMetadata µÄÈÝÆ÷¡£
https://securityonline.info/attackers-exploit-critical-openmetadata-flaws-for-cryptomining-on-kubernetes/
3. SoumniBot ¶ñÒâÈí¼þÀûÓà Android ·ì϶À´Èƹý¼ì²â
4ÔÂ17ÈÕ£¬Ò»ÖÖÃûΪ¡°SoumniBot¡±µÄРAndroid ÒøÐжñÒâÈí¼þͨ¹ýÀûÓà Android Çåµ¥ÌáÈ¡ºÍ½âÎö¹ý³ÌÖеÄÈõµã£¬Ê¹ÓÃÒ»ÖÖ²»Ì«³£¼ûµÄ»ìºÏ²½Öè¡£¸Ã²½Öèʹ SoumniBot ¿ÉÄܶã±Ü Android ÊÖ»úÖеij߶Ȱ²È«´ëÊ©²¢Ö´ÐÐÐÅÏ¢ÇÔÈ¡²Ù×÷¡£¸Ã¶ñÒâÈí¼þÓÉ¿¨°Í˹»ù×êÑÐÈËÔ±·¢ÏÖ²¢·ÖÎö£¬ËûÃÇÌṩÁË ¸Ã¶ñÒâÈí¼þÀûÓà Android Àý³Ì½âÎöºÍÌáÈ¡ APK Çåµ¥µÄ²½ÖèµÄ¼¼Êõϸ½Ú¡£Çåµ¥Îļþ£¨¡°AndroidManifest.xml¡±£©Î»ÓÚÿ¸öÀûÓ÷¨Ê½µÄ¸ùĿ¼ÖУ¬Ô̺¬ÓйØ×é¼þ£¨·þÎñ¡¢¹ã²¥½Ó¹ÜÆ÷¡¢ÄÚÈÝÌṩ·¨Ê½£©¡¢È¨ÏÞºÍÀûÓ÷¨Ê½Êý¾ÝµÄ¾ßÌåÐÅÏ¢¡£¹ÌÈ»¶ñÒâ APK Äܹ»Ê¹Óà Zimperium µÄ¸÷ÀàѹËõ¼¼ÇÉÀ´ÓÞŪ°²È«¹¤¾ß²¢ÌӱܷÖÎö£¬µ«¿¨°Í˹»ù·ÖÎöʦ·¢ÏÖ SoumniBot ʹÓÃÈýÖÖ·ÖÆçµÄ²½ÖèÀ´Èƹý½âÎöÆ÷²é³£¬ÆäÖÐÉæ¼°°Ñ³ÖÇåµ¥ÎļþµÄѹËõºÍ´óÓס£
https://www.bleepingcomputer.com/news/security/soumnibot-malware-exploits-android-bugs-to-evade-detection/
4. FIN7 Õë¶ÔÃÀ¹úÆû³µÔì×÷ÉÌµÄ IT Ô±¹¤ÌáÒéÍøÂç´¹µö¹¥»÷
4ÔÂ17ÈÕ£¬³öÓÚ¾¼Ã¶¯»úµÄÍþв×éÖ¯ FIN7 Õë¶ÔÒ»¼ÒÃÀ¹ú´óÐÍÆû³µÔì×÷ÉÌ£¬Ïò IT ²¿ÃŵÄÔ±¹¤·¢ËÍÓã²æÊ½ÍøÂç´¹µöµç×ÓÓʼþ£¬ÒÔÀûÓà Anunak ºóÃÅϰȾϵͳ¡£¾ÝºÚÝ®×êÑÐÈËÔ±³Æ£¬Õâ´Î¹¥»÷²úÉúÔÚÈ¥Äêµ×£¬²¢ÇÒÒÀÀµÓڷDZ¾µØ¶þ½øÔìÎļþ¡¢¾ç±¾ºÍ¿â (LoLBas)¡£ÍþвÐÐΪÕß½«³Áµã·ÅÔÚÓµÓи߼¶È¨ÏÞµÄÖ¸±êÉÏ£¬Í¨¹ý¼ÙÒâºÏ·¨¸ß¼¶ IP ɨÃèÆ÷¹¤¾ßµÄ¶ñÒâ URL Á´½ÓÀ´ÒýÓÕËûÃÇ¡£ºÚÝ®¸ß¶ÈÈ·ÐÅÕâ´Î¹¥»÷ÊÇÓÉ FIN7 ÌáÒéµÄ£¬ÓÉÓڸù¥»÷ʹÓÃÁ˹ÖÒìµÄ PowerShell ¾ç±¾£¬¸Ã¾ç±¾Ê¹ÓÃÁ˵ÐÊÖµÄÊðÃû¡°PowerTrash¡±»ìºÏµÄ shellcode ŲÓ÷¨Ê½£¬¸Ã¾ç±¾³õ´Î³Ê´Ë¿Ì 2022 ÄêµÄÒ»´Î»î¶¯ÖС£ÔÚ´Ë֮ǰ£¬FIN7 ±»·¢ÏÖÒÔ¶³öµÄVeeam ±¸·ÝºÍMicrosoft Exchange·þÎñÆ÷Ϊָ±ê£¬²¢½«Black BastaºÍClop ÀÕË÷Èí¼þ¸ºÔز¿Êðµ½ÆóÒµÍøÂçÉÏ¡£
https://www.bleepingcomputer.com/news/security/fin7-targets-american-automakers-it-staff-in-phishing-attacks/
5. Óë¶íÂÞ˹ÓйصÄSandworm ¹¥»÷¾üе¿âÖеÄкóÃÅKapeka
4ÔÂ17ÈÕ£¬³ýÁË΢ÈíÓÚ 2024 Äê 2 Ô 14 ÈÕ°ä²¼µÄ¹ØÓÚ·¢ÏÖÒ»¸öÃûΪ KnuckleTouch µÄкóÃŵļò¶ÌÃèÊöÖ®±í£¬Ä¿Ç°¹«¼Ò¶Ô Kapeka ºóÃŵÄÏàʶÏÕЩΪÁ㡣΢Èí½« KnuckleTouch ºóÃŹé×ïÓÚ SeaShell Blizzard£¬ÕâÊÇÆä¶Ô Sandworm µÄÃû³Æ¡£Microsoft ÉÐδ¶Ô´Ë¶ñÒâÈí¼þ½øÐзÖÎö£¬µ« WithSecure È·ÐÅ KnuckleTouch ¾ÍÊÇ Kapeka¡£Î¢ÈíºÍ WithSecure ÒÔΪ¸Ã¶ñÒâÈí¼þ×Ô 2022 ÄêÒÔÀ´Ò»ÏòÔÚʹÓ㬵«³ýÁË WithSecure ·ÖÎöÖ®±í£¬ÈËÃÇ¶Ô Kapeka ÖªÖ®ÉõÉÙ¡£WithSecure Æù½ñΪֹֻ·¢ÏÖÁËÁ½¸öÒ°±íÑù±¾¡£Ë¼¿¼µ½µ±Ç°µÄµØÔµÕþÖΣ¬Êܺ¦ÕßѧҲÅú×¢Æä·¢Ô´ÓÚ¶íÂÞ˹£º°®É³ÄáÑǺÍÎÚ¿ËÀ¼¡£ÕâÖÖÓÐÏÞµÄÒ£²â¿ÉÄÜÊÇÓÉÓڸöñÒâÈí¼þÉÐδ¿í·ºÊ¹Óã¬Ò²¿ÉÄÜÊÇÓÉÓÚ Kapeka Ⱥ²ßȺÁ¦Î¬³ÖÒþÃØ¡£
https://www.securityweek.com/kapeka-a-new-backdoor-in-sandworms-arsenal-of-aggression/
6. VisaÕë¶Ô½ðÈÚ»ú¹¹µÄJSOutProxÈÕÒæÔö³¤µÄÍþв·¢³ö¹«¸æ
4ÔÂ17ÈÕ£¬Visa ×î½ü°ä²¼Á˹ØÓÚ³ö¸ñΣÏÕµÄJSOutProx ¶ñÒâÈí¼þ»î¶¯ÏÔ×ÅÔö³¤µÄÑϳÁ°²È«¾¯±¨¡£ÕâÖÖÔ¶³Ì½Ó¼ûľÂí ( RAT ) ÒÔÆä¶Ô½ðÈÚ»ú¹¹¼°Æä¿Í»§µÄ¸´ÔÓ¹¥»÷ÄÜÁ¦¶øÎÅÃû£¬³ö¸ñÊÇÕë¶ÔÄÏÑǺͶ«ÄÏÑÇ¡¢Öж«ºÍ·ÇÖÞµØÓò¡£JSOutProx ÓÚ 2019 Äê 12 Ô³õ´Î±»·¢ÏÖ£¬ÊÇÒ»Öָ߶ȻìºÏµÄ JavaScript ºóÃÅ£¬Ê¹ÍøÂç·¸×ï·Ö×Ó¿ÉÄÜÖ´ÐдóÁ¿¶ñÒâ»î¶¯¡£ÆäÖÐÔ̺¬ÔËÐÐ shell ºÅÁî¡¢ÏÂÔØ¶î±íµÄÓк¦¸ºÔØ¡¢Ö´ÐÐÎļþ¡¢²¶»ñÆÁÄ»½ØÍ¼ÒÔ¼°ÆëÈ«½ÚÔìÊÜϰȾÉ豸µÄ¼üÅ̺ÍÊó±ê¡£Ëæ×ʦ·òµÄÍÆÒÆ£¬JSOutProx ²»ÐÝ·¢Õ¹£¬¼ÓÇ¿ÁËÆä¶ã±Ü¼¼ÊõÒÔÔ¤·À¼ì²â²¢¼ÓÇ¿ÁËÆä·ÛËéÄÜÁ¦¡£JSOutProx µÄ³õʼÓÐЧ¸ºÔØÖ§³Ö¸ù»ùµ«¹Ø¼üµÄÖ°ÄÜ£¬Ê¹¹¥»÷Õß¿ÉÄܶÔÊÜϰȾµÄϵͳ½øÐÐÏ൱´óµÄ½ÚÔì¡£
https://securityboulevard.com/2024/04/jsoutprox-malware-variant-targeting-financial-orgs-warns-visa/#google_vignette


¾©¹«Íø°²±¸11010802024551ºÅ