Ó¡¶ÈºÚ¿Í×éÖ¯CyberVolk£ºÐÂÐËÀÕË÷Èí¼þÍþвȫÇòÍøÂ簲ȫ

°ä²¼¹¦·ò 2024-09-06

1. Ó¡¶ÈºÚ¿Í×éÖ¯CyberVolk£ºÐÂÐËÀÕË÷Èí¼þÍþвȫÇòÍøÂ簲ȫ


9ÔÂ5ÈÕ£¬Ó¡¶ÈºÚ¿Í×éÖ¯CyberVolk×÷ÎªÍøÂç·¸×ïÁìÓòµÄÐÂÐ㣬ÒÔÆä¸´ÔÓµÄÀÕË÷Èí¼þѸ¿ìáÈÆð²¢Òý·¢¹Ø×¢¡£¸Ã×éÖ¯×Ô2024Äê7ÔÂÍÆ³öÆäÀÕË÷Èí¼þÒÔÀ´£¬Æ¾½èÆäÏȽøµÄ¼ÓÃܼ¼ÊõºÍѸ¿ìÀ©É¢µÄÄÜÁ¦£¬Ñ¸¿ìÔÚÍøÂç·¸×ï½çÉùÃûÀǽå¡£CyberVolkÀÕË÷Èí¼þ²»½öÖ°ÄÜ׳´ó£¬»¹ÒÔÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©´ó¾ÖÁ÷ͨ£¬ÈκÎÈ˾ù¿É×âÓò¢·¢Æð¹¥»÷£¬¼«´óµØÀ©´óÁËÆäÍþвÁìÓò¡£¸ÃÈí¼þµÄ¼ÓÃÜËã·¨²»ÐÝÉý¼¶£¬Ñ¡È¡Ô̺¬ChaCha20-Poly1305¡¢AES¼°¿¹Á¿×Ó¼¼ÊõÔÚÄڵĶà³Á¼ÓÃܼ¿Á©£¬È·±£Êý¾ÝÄÑÒÔ½âÃÜ£¬¼´±ãÃæ¶ÔÁ¿×ÓÍÆËãÌôÕ½Ò಻Àý±í¡£CyberVolkÀÕË÷Èí¼þ×îΪ¹ÖÒìÖ®´¦ÔÚÓÚÆäÎÞÐèC2·þÎñÆ÷¼´¿É¶ÀÁ¢ÔËÐУ¬¼ÓÇ¿ÁËÒñ±ÎÐÔÓë·ÛËéÐÔ¡£Ò»µ©¼ÓÃÜÆô¶¯£¬½«Ñ¸¿ìËø¶¨Îļþ£¬²¢ÉèÖÃÑϸñÊê½ðÆÚÏÞÓë³Í·£»úÔ죬ÈçÊäÈëÃýÎóÃÜÔ¿Ôò×Ô¶¯Ïú»ÙÊý¾Ý£¬ÆÈʹÊܺ¦Õ߾ͷ¶¡£´Ë±í£¬¸ÃÈí¼þ»¹¾ß±¸Ìӱܼì²â¡¢Èä³æÊ½´«²¼µÈÄÜÁ¦£¬ÑϳÁÍþвÆóÒµ¼°Ó×ÎÒÐÅÏ¢°²È«¡£Ö»¹ÜCyberVolkÀÕË÷Èí¼þÉè¼Æ¾«Ãµ«ÍøÂ簲ȫ×êÑлú¹¹ThreatMonÈÔ·¢ÏÖÁËÆä·ì϶£¬Èç¿Éͨ¹ýPowerShellºÅÁîÖÕÖ¹¼ÓÃÜ¡¢Åú¸Ä¹¦·òÎļþµ¢¸éÊê½ðÖ§¸¶ÆÚÏ޵ȣ¬ÎªÓ¦¶Ô¹¥»÷ÌṩÁË¿ÉÄÜÐÔ¡£È»¶ø£¬CyberVolkÀÕË÷Èí¼þµÄ²ÆÕþÊÕÒæ¼¤Ôö£¬ÏÔʾ³öÆä»î¶¯µÄ¿í·ºÓ°ÏìÓë·çÏÕ¡£


https://securityonline.info/cybervolk-ransomware-a-new-and-evolving-threat-to-global-cybersecurity/


2. ¾¯Ìè¼ÙÒâNetflixµÄ´¹µöÓʼþ·ºÀÄ


9ÔÂ2ÈÕ£¬AhnLab °²È«µý±¨ÖÐÐÄ£¨ASEC£©½üÆÚ½ÒʾÁËÕë¶Ô³ÛÃûOTTƽ̨NetflixµÄÍøÂç´¹µöÓʼþ»î¶¯¡£Ëæ×ÅOTTƽ̨±é¼°ºÍÓû§»ùÊýµÄÀ©´ó£¬´ËÀà´¹µö¹¥»÷ÈÕÒæ·è¿ñ¡£¹¥»÷Õß¾«ÐÄαÔìNetflix¶©Ôĸ¶¿îʧ°ÜµÄÓʼþ£¬ÓÕµ¼Óû§µã»÷Á´½Ó¸üи¶¿î·½Ê½£¬ÓʼþÉè¼ÆÕæÇУ¬ÉõÖÁʹÓÿ´ËÆÎÞº¦µÄ¡°netflix-team[.]com¡±ÓòÃû¡£È»¶ø£¬Õâ²¢·ÇNetflix¹Ù·½µØÖ·£¬¶øÊÇרΪ´¹µöÉè¼ÆµÄÓòÃû¡£ÓʼþÖÐǶÈëµÄ¡°Ô®ÊÖÖÐÐÄ¡±ºÍ¡°ÁªÏµ·½Ê½¡±Á´½ÓÖ¸Ïò¹Ù·½£¬µ«¹Ø¼üµÄ¡°µ±¼´¸üÐÂÕÊ»§¡±°´Å¥Ôòµ¼ÏòÒѹعصĴ¹µöÍøÕ¾URL£¬Ö»¹Ü¸ÃÍøÕ¾ÎÞ·¨½øÒ»²½·ÖÎö£¬µ«Í¨¹ý¶ÈÎöÓòÃûºÍ×ÓURLÖз¢ÏֵijÛÃûƽ̨CSSÎļþ£¬´§Ä¦¹¥»÷Õß¿ÉÄܹ¹½¨Á˶à¸öÀàËÆ´¹µöÕ¾µã¡£´Ë°¸Àý͹ÏÔÁË´¹µöÓʼþµÄÒñ±ÎÐԺ͸´ÔÓÐÔ£¬¹¥»÷ÕßÀûÓù«¼Ò¶ÔOTTƽ̨µÄÊìϤ¸Ð½µµÍ¾¯Ì衣Ϊ·À±¸´ËÀ๥»÷£¬Óû§ÐèÌáÉý°²È«Òâʶ£¬×Ðϸ²é³­ÓʼþÖеÄURL£¬²¢ÔÚµã»÷ǰͨ¹ý¹Ù·½Çþ·ÑéÖ¤ÐÅÏ¢ÕæÎ±¡£


https://asec.ahnlab.com/en/82969/


3. FBIÖҸ泯ÏʺڿͶÔ×¼¼ÓÃÜÇ®±ÒÁìÓò£¬Éç»á¹¤³Ì¹¥»÷Ƶ·¢


9ÔÂ3ÈÕ£¬ÃÀ¹úÁª¹úµ÷²é¾Ö½üÈÕ·¢³ö´¹Î£ÖҸ棬ָ³ö³¯ÏʺڿÍ×éÖ¯Õý»ý¼«Õë¶Ô¼ÓÃÜÇ®±ÒÁìÓòÌáÒé¸ß¶È¸´ÔÓµÄÉç»á¹¤³Ì¹¥»÷£¬Ö¼ÔÚÇÔÈ¡¼ÓÃÜ×ʲú¡£ÕâЩ¹¥»÷¼«¾ßÒñ±ÎÐÔ£¬¼´¾ÍÊÇÍøÂ簲ȫר¼ÒÒ²ÄÑÒÔµÈÏоõ²ì¡£³¯ÏʺڿÍÊÂÏȶԼÓÃÜÇ®±ÒÂòÂôËùÂòÂô»ù½ð£¨ETF£©¼°ÓйØÓ×ÎÒ½øÐÐÏ꾡µ÷ÑУ¬ÏÔʾ³öÆä¶ÔDZÔÚÖ¸±êµÄÉî¿ÌÏàʶºÍÈ«Ãæ³ï±¸¡£ËûÃDz»½ö¶Ô×¼¼ÓÃÜÇ®±Ò¹«Ë¾£¬»¹Õë¶Ô´¦ÖôóÁ¿¼ÓÃÜ×ʲúµÄ×éÖ¯ÌáÒéÍøÂçÈëÇÖ£¬Ì°Í¼µÁÈ¡×ʽð¡£FBIÇ¿µ÷£¬³¯ÏʺڿÍÉÆÓÚͨ¹ý¾«ÐIJ߶¯µÄÉç»á¹¤³Ì¼¿Á©£¬¼Ù×°³ÉÕÐÆ¸ÈËÔ±»ò³ÛÃûÐÐÒµÈËÊ¿£¬ÀûÓÃÓÕÈ˵ľÍÒµºÍͶ×Ê»úÓöÓÕÆ­Ô±¹¤ÖмÆ¡£ËûÃÇʹÓÃÁ÷³©µÄÓ¢ÓרҵµÄ¼ÓÃÜÇ®±Ò֪ʶ¼°Î±ÔìµÄÉí·ÝÐÅÏ¢£¬¼«´óÌáÉýÁ˹¥»÷µÄ¿ÉÐŶÈ¡£´Ë±í£¬ºÚ¿Í»¹ÉÆÓÚ¹¹½¨¿´ËƺϷ¨µÄÍøÕ¾ºÍµÁÓÃͼƬ£¬ÒÔ»ìºÏÊÓÌý¡£ÎªÓ¦¶ÔÕâÒ»Íþв£¬FBIÁгöÁ˳¯ÏÊÉç»á¹¤³Ì»î¶¯µÄDZÔÚ¼£Ï󣬲¢Îª¼ÓÃÜÇ®±ÒÐÐÒµ¼°ÆäÔ±¹¤ÌṩÁË·À±¸½¨Ò飬Ô̺¬×ÐϸºË²éÓʼþÆðÔ´¡¢Ô¤·Àµã»÷²»Ã÷Á´½Ó¡¢Í¨¹ý¹Ù·½Çþ·ÑéÖ¤ÐÅÏ¢µÈ¡£


https://www.bleepingcomputer.com/news/security/fbi-warns-crypto-firms-of-aggressive-social-engineering-attacks/?&web_view=true


4. BlindEagleÀûÓÃBlotchyQuasar¹¥»÷¸çÂ×±ÈÑDZ£ÏÕÒµ


9ÔÂ5ÈÕ£¬Zscaler ThreatLabz½üÆÚ¼ì²âµ½BlindEagle£¨Ò²±»³ÆÎªAguilaCiega¡¢APT-C-36ºÍAPT-Q-98£©ÕâÒ»¸ß¼¶³ÖÐøÐÔÍþв£¨APT£©ÐÐΪÕßµÄл¡£BlindEagleÖØÒª½«Ö¸±êËø¶¨ÔÚÄÏÃÀÖÞ£¬³ö¸ñÊǸçÂ×±ÈÑǺͶò¹Ï¶à¶ûÈ·µ±¾ÖºÍ½ðÈÚ²¿ÃÅ×éÖ¯¼°Ó×ÎÒ¡£Æäͨ¹ý¾«ÐÄÉè¼ÆµÄÍøÂç´¹µöµç×ÓÓʼþ»ñÈ¡³õʼ½Ó¼ûȨÏÞ£¬ËæºóÀûÓÃÉÌÆ·»¯µÄ.NETÔ¶³Ì½Ó¼ûľÂí£¨RAT£©ÈçAsyncRAT¡¢RemcosRAT¼°¶¨Ôì±äÌåBlotchyQuasarÇÔÈ¡ÒøÐзþÎñÌṩÉ̵ÄÍ´´¦¡£Õâ´Î¹¥»÷³ö¸ñÕë¶Ô¸çÂ×±ÈÑDZ£ÏÕÒµ£¬ÍþвÐÐΪÕß¼Ù×°³É¸çÂ×±ÈÑÇ˰Îñ»ú¹Ø£¨DIAN£©·¢ËÍ´¹Î£Í¨Öª£¬Ðû³ÆÒòδ¸¶Ë°¿î¶ø·¢³ö¿ÛѺÁÆÈʹÊܺ¦Õßµ±¼´Ðж¯¡£Êܺ¦Õß±»ÓÕµ¼ÏÂÔØ²¢ÔËÐÐÒ»¸öÊÜÃÜÂë±£»¤µÄZIP´æµµ£¬¸Ã´æµµÔ̺¬BlotchyQuasar¶ñÒâÈí¼þ¡£BlotchyQuasarÓµÓÐ׳´óµÄÖ°ÄÜ£¬Èç¼üÅ̼ͼ¡¢¼à¿ØÒøÐзþÎñ´°¿Ú±êÌâÒÔ¼°Ö´ÐÐshellºÅÁ´Ó¶øÇÔȡ֧¸¶ÓйØÊý¾Ý¡£ThreatLabzÒÔΪÕâ´Î¹¥»÷¸ß¶È¿ÉÐŵØÓÉBlindEagleÌáÒ飬ÒòÆäÇкϸÃ×éÖ¯ÒÑÖªµÄ×÷°¸ÊÖ·¨ºÍÖ¸±êÌØµã¡£


https://www.zscaler.com/blogs/security-research/blindeagle-targets-colombian-insurance-sector-blotchyquasar


5. LiteSpeed Cache·ì϶µ¼ÖÂ600Íò¸öWordPressÍøÕ¾Ãæ¶ÔÕË»§ÊÕÊÜ·çÏÕ


9ÔÂ5ÈÕ£¬WordPress¼Ó¿ì²å¼þLiteSpeed Cache½üÆÚÆØ³öÑϳÁ°²È«·ì϶CVE-2024-44000£¬Ó°Ï쳬600ÍòWordPressÍøÕ¾°²È«¡£¸Ã·ì϶ÊôÓÚδ¾­Éí·ÝÑéÖ¤µÄÕÊ»§ÊÕÊÜÎÊÌ⣬ԴÓÚ²å¼þµÄµ÷ÊÔÈÕÖ¾Ö°Äܲ»µ±´¦ÖÃÓû§»á»°cookie¡£µ±¸ÃÖ°ÄÜÆôÓÃʱ£¬ËùÓÐHTTPÏìӦͷ£¨º¬Ãô¸Ðcookie£©±»Ð´ÈëδÊܱ£»¤µÄÈÕÖ¾Îļþ£¬¹¥»÷Õßͨ¹ý½Ó¼û¸ÃÎļþ¿ÉÇÔÈ¡cookie£¬½ø¶ø¼ÙÒâÖÎÀíÔ±½ÚÔìÍøÕ¾¡£LiteSpeed TechnologiesѸ¿ìÏìÓ¦£¬°ä²¼6.5.0.1°æ±¾½¨¸´·ì϶£¬Ô̺¬½«ÈÕÖ¾ÒÆÖÁרÓÃÎļþ¼Ó×¢Ëæ»ú»¯ÎļþÃû¡¢ÒƳýcookie¼Í¼ѡÏî¼°ÔöÉè±£»¤Îļþ¡£Óû§±»½¨Òé¶Ï¸ù¾ÉÈÕÖ¾Îļþ²¢ÉèÖÃ.htaccess¹æ¶¨Ô¤·ÀÖ±½Ó½Ó¼û£¬ÒÔ·ÀDZÔÚ¹¥»÷¡£´Ë±í£¬¸Ã²å¼þ½üÆÚÒÑÂŴα»ÆØ³ö°²È«·ì϶£¬Ô̺¬Î´ÑéÖ¤¿çÕ¾¾ç±¾ºÍȨÏÞÉý¼¶·ì϶£¬ºÚ¿Í»î¶¯ÆµÈÔ£¬´Óǰ24Ó×ʱÄÚ¹¥»÷´ÎÊý¸ß´ï34Íò´Î£¬Í¹ÏÔÁËʵʱ¸üкͼӹ̰²È«´ëÊ©µÄ³ÁÒªÐÔ¡£WordPressÉçÇøºÍÓû§ÐèÇ×êǹØ×¢²¢²ÉÈ¡ÏàÓ¦·À»¤´ëÊ©£¬ÒÔÈ·±£ÍøÕ¾°²È«¡£


https://www.bleepingcomputer.com/news/security/litespeed-cache-bug-exposes-6-million-wordpress-sites-to-takeover-attacks/


6. ºÚ¿ÍÏÝÚ壺αÔìOnlyFans¹¤¾ß°µ²ØLumma¶ñÒâÈí¼þ


9ÔÂ5ÈÕ£¬ºÚ¿ÍÃǽüÆÚѡȡÁËÒ»Öֵ󻬵ÄÕ½Êõ£¬ÀûÓÃαÔìµÄOnlyFansÕË»§²é³­¹¤¾ß×÷Ϊµö¶ü£¬Ö¸±êÖ±Ö¸ÆäËûºÚ¿ÍȺÌå¡£ÕâЩ¹¤¾ßÐû³ÆÄÜÑéÖ¤²¢ÇÔÈ¡OnlyFansÕË»§£¬ÊµÔò°µ²ØLummaÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¬Í¨¹ýGitHubµÈÇþ·´«²¼¡£Lumma×÷ΪһÖָ߼¶µÄMaaS£¨¶ñÒâÈí¼þ¼´·þÎñ£©£¬²»½ö¾ß±¸×³´óµÄÐÅÏ¢ÇÔÈ¡ÄÜÁ¦£¬»¹ÄܼÓÔØÆäËû¶ñÒâ¸ºÔØ£¬¶ÔÊܺ¦ÕßµÄϵͳÔì³ÉÉî¶ÈÇÖº¦¡£Õâ´ÎÊÂÎñÖУ¬ºÚ¿ÍÃǾ«ÐÄÉè¼ÆÁËÏÝÚ壬ʹÍþвÐÐΪÕßÔÚ³¢ÊÔÑéÖ¤OnlyFansÕË»§Ê±£¬²»Öª²»¾õÖÐϰȾÁËLumma£¬½ø¶øÂ¶³öÁË×ÔÉíµÄÃô¸ÐÐÅÏ¢¡£Lumma»¹Í¨¹ýÆä½Ã½ÝµÄ´«²¼·½Ê½£¬Èç¶ñÒâ¸æ°×¡¢É罻ýÌåÆÀÂ۵ȣ¬²»ÐÝÀ©´óÆäÓ°ÏìÁìÓò¡£ÖµÍ×ÌùÐĵÄÊÇ£¬¸Ã¶ñÒâÈí¼þ²»½öÄÜÇÔÈ¡ÃÜÂë¡¢ÐÅÓþ¿¨ÐÅÏ¢µÈ´«Í³Êý¾Ý£¬»¹Äܸ´Ô­¹ýÆÚµÄGoogle»á»°ÁîÅÆ£¬ÏÔʾ³öÆä¸ß¶ÈµÄ¼¼Êõ¸´ÔÓÐÔ΢·çÏÕÐÔ¡£Õâ´Î¹¥»÷²»½öÏÞÓÚOnlyFansÕË»§£¬»¹À©´óµ½Disney+¡¢InstagramµÈ¶à¸öƽ̨£¬ÉõÖÁÔ̺¬Mirai½©Ê¬ÍøÂç¹¹½¨Æ÷µÄ´«²¼£¬ÏÔʾÁ˹¥»÷Õß¿í·º¶ø¶àÑùµÄÖ¸±êÑ¡Ôñ¡£´Ë±í£¬¹¥»÷Õß»¹ÀûÓÃGitHubµÈ¿ªÔ´Æ½Ì¨ÍйܶñÒâ¸ºÔØ£¬½øÒ»²½Ôö³¤ÁËÒñ±ÎÐԺʹ«²¼Ð§ÄÜ¡£


https://www.bleepingcomputer.com/news/security/hacker-trap-fake-onlyfans-tool-backstabs-cybercriminals-steals-passwords/