÷è÷ëÀÕË÷Èí¼þ×éÖ¯Ðû³ÆÈëÇÖÎÚ¿ËÀ¼±í½»²¿

°ä²¼¹¦·ò 2025-03-07

1. ÷è÷ëÀÕË÷Èí¼þ×éÖ¯Ðû³ÆÈëÇÖÎÚ¿ËÀ¼±í½»²¿


3ÔÂ7ÈÕ £¬÷è÷ëÀÕË÷Èí¼þ×éÖ¯Ðû³ÆÒѳɹ¦ÈëÇÖÎÚ¿ËÀ¼±í½»²¿ £¬ÕâÊÇÒ»´Î³Á´óµÄÍøÂ簲ȫÊÂÎñ¡£¸Ã×éÖ¯Ðû³ÆÇÔÈ¡ÁËÔ̺¬¸öÈËͨѶ¡¢Ó×ÎÒÐÅÏ¢ºÍ¹Ù²½ÖèÁîÔÚÄÚµÄÃô¸ÐÊý¾Ý £¬²¢Òѽ«²¿ÃÅÊý¾ÝÏúÊÛ¸øµÚÈý·½ £¬Í¬Ê±ÔÚÆäTorйÃÜÍøÕ¾Éϰ䲼ÁËһϵÁб»µÁÎļþµÄͼÏñ×÷Ϊ֤¾Ý¡£È»¶ø £¬ÎÚ¿ËÀ¼±í½»²¿ÉÐδ¶ÔÕâÒ»Êý¾Ýй¶ÊÂÎñ½øÐÐ֤ʵ¡£Õâ´Î¹¥»÷±»ÊÓΪ¶íÂÞ˹ºÍÎÚ¿ËÀ¼³ÖÐøÃ¬¶ÜÖлìºÏÕ½ÕùÉý¼¶µÄÒ»²¿ÃÅ £¬¿ÉÄÜÓë¿ËÀïÄ·ÁÖ¹¬Õ½ÊõÒ»ÖµĺڿͻºÍÍøÂç·¸×OÍÅÓйØ¡£÷è÷ëÀÕË÷Èí¼þ×éÖ¯×Ô2022ÄêÆð»îÔ¾ £¬ÔøÒò¹¥»÷Ó¢¹úµ±¾ÖÒ½ÁÆ·þÎñÌṩÉÌSynnovis¶øÊܵ½¹Ø×¢ £¬Í¨³£Ñ¡È¡¡°Ë«³ÁÀÕË÷¡±¼¿Á©¡£×î½ü £¬¸Ã×éÖ¯»¹Ðû³Æ¶ÔÓ°ÏìÊýÊ®¼Ò±¾µØ±¨Ö½µÄÀîÊÏÆóÒµÍøÂç¹¥»÷ÕÆ¹Ü¡£ÀîÊÏÆóÒµÊÇÒ»¼ÒÉÏÊеÄÃÀ¹úýÌ幫˾ £¬ÔÚ¶à¸öÖݳö°æ´óÁ¿±¨Ö½ºÍÖÜ¿¯¡£Õâ´ÎÊÂÎñÔÙ´Î͹ÏÔÁËÍøÂ簲ȫµÄ³ÁÒªÐÔ £¬ÒÔ¼°ÀÕË÷Èí¼þ×éÖ¯¶ÔÈ«ÇòÆóÒµºÍµ±¾Ö»ú¹¹×é³ÉµÄÍþв¡£


https://securityaffairs.com/175025/cyber-crime/qilin-ransomware-ministry-of-foreign-affairs-of-ukraine.html


2. ΢Èíɾ³ý¶ñÒâ¸æ°×»î¶¯ËùÓÃGitHub´æ´¢¿â £¬½ü°ÙÍòÉ豸ÊÜÓ°Ïì


3ÔÂ6ÈÕ £¬Î¢ÈíÔÚ2024Äê12Ô³õ¼ì²âµ½Ò»´Î´ó¹æÄ£¶ñÒâ¸æ°×»î¶¯ £¬¸Ã»î¶¯Ó°ÏìÁËÈ«Çò½üÒ»°ÙÍǫ̀É豸¡£¹¥»÷Õßͨ¹ýÔÚ·¸·¨µÁ°æÁ÷ýÌåÍøÕ¾µÄÊÓÆµÖÐ×¢Èë¶ñÒâ¸æ°×³Á¶¨ÏòÆ÷ £¬½«Ç±ÔÚÊܺ¦Õß³Á¶¨Ïòµ½ËûÃǽÚÔìµÄ¶ñÒâGitHub´æ´¢¿â¡£ÕâЩ´æ´¢¿âÖеĶñÒâÈí¼þ»áϰȾÓû§ÏµÍ³ £¬Ö´ÐÐϵͳ·¢ÏÖ¡¢ÍøÂç¾ßÌåµÄϵͳÐÅÏ¢ £¬²¢ÔÚ²¿Êð¶î±íµÄµÚ¶þ½×¶ÎÓÐÐ§ÔØºÉʱÇÔÈ¡Êý¾Ý¡£ÔÚµÚÈý½×¶Î £¬¹¥»÷Õß»áÏÂÔØNetSupportÔ¶³Ì½Ó¼ûľÂí£¨RAT£©ºÍÆäËûÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ £¬ÈçLummaºÍDoenerium £¬À´ÇÔÈ¡Óû§Êý¾ÝºÍä¯ÀÀÆ÷Í´´¦¡£¹ÌÈ»GitHubÊÇÕâ´Î»î¶¯µÚÒ»½×¶Î½»¸¶ÓÐÐ§ÔØºÉµÄÖØÒªÆ½Ì¨ £¬µ«Microsoft Threat IntelligenceÒ²¹Û²ìµ½ÔÚDropboxºÍDiscordÉÏÍйܵÄÓÐÐ§ÔØºÉ¡£Õâ´Î¹¥»÷»î¶¯ÓµÓÐÎÞ²î¾àÐÔ £¬Ó°ÏìÁË¿í·ºµÄ×éÖ¯ºÍÐÐÒµ £¬Ô̺¬Ïû·ÑÕßºÍÆóÒµÉ豸¡£Î¢ÈíÓá°Storm-0408¡¹Øâ¸ö×ܳÆÀ´×·×ÙÕâÒ»»î¶¯ £¬²¢ÌṩÁËÓйØÕâ´Î¸´ÔÓ¶ñÒâ¸æ°×»î¶¯µÄ¶à½×¶Î¹¥»÷Á´Öй¥»÷µÄ¸÷¸ö½×¶ÎºÍËùʹÓõÄÓÐÐ§ÔØºÉµÄ¾ßÌåÐÅÏ¢¡£


https://www.bleepingcomputer.com/news/security/microsoft-says-malvertising-campaign-impacted-1-million-pcs/


3. AkiraÀÕË÷Èí¼þÍÅ»ïÀûÓÃÍøÂçÉãÏñÍ·ÈÆ¹ýEDRÌáÒé¹¥»÷


3ÔÂ6ÈÕ £¬AkiraÀÕË÷Èí¼þÍÅ»ïѡȡÁËÒ»ÖÖ²»Ñ°³£µÄ¹¥»÷²½Öè £¬ÀûÓò»°²È«µÄÍøÂçÉãÏñÍ·¶ÔÊܺ¦ÕßÍøÂçÌáÒé¼ÓÃܹ¥»÷ £¬³É¹¦ÈƹýÁËWindowsÖеĶ˵ã¼ì²âºÍÏìÓ¦£¨EDR£©¹¤¾ß¡£ÍøÂ簲ȫ¹«Ë¾S-RMÔÚÒ»´ÎÊÂÎñÏìÓ¦Öз¢ÏÖÁËÕâÒ»¹¥»÷·½Ê½¡£AkiraÍÅ»ïÊ×ÏÈͨ¹ýÔ¶³Ì½Ó¼û½â¾ö¹æ»®½øÈë¹«Ë¾ÍøÂç £¬²¿ÊðºÏ·¨µÄÔ¶³Ì½Ó¼û¹¤¾ßAnyDeskÇÔÈ¡Êý¾Ý £¬²¢Ê¹ÓÃÔ¶³Ì×ÀÃæºÍ̸£¨RDP£©½øÐкáÏòÒÆ¶¯¡£È»¶ø £¬µ±ËûÃÇÔÚWindowsÉϲ¿ÊðÀÕË÷Èí¼þ¸ºÔØÊ±±»EDR¹¤¾ß×èÖ¹¡£Ëæºó £¬AkiraɨÃèÍøÂçѰÕÒÆäËûÉ豸 £¬·¢ÏÖÁËÒ×Êܹ¥»÷µÄÍøÂçÉãÏñÍ·ºÍÖ¸ÎÆÉ¨ÃèÒÇ¡£ÓÉÓÚÍøÂçÉãÏñÍ·ÔËÐÐLinux²Ù×÷ϵͳÇÒûÓÐEDR´úÀí £¬AkiraÑ¡ÔñÀûÓÃËü¹ÒÔØ¹«Ë¾ÆäËûÉ豸µÄWindows SMBÍøÂç¹²Ïí £¬²¢ÔÚÍøÂçÉãÏñÍ·ÉÏÆô¶¯Linux¼ÓÃÜÆ÷ £¬³É¹¦¼ÓÃÜÁËSMBÉϵÄÍøÂç¹²ÏíÎļþ¡£S-RMÖ¸³ö £¬ÒÑÓÐÕë¶ÔÍøÂçÉãÏñÍ··ì϶µÄ²¹¶¡ £¬Åú×¢Õâ´Î¹¥»÷ÊÇ¿ÉÔ¤·ÀµÄ¡£´Ë°¸ÀýÇ¿µ÷ÁËEDR±£»¤²¢·ÇÈ«Ãæ°²È«½â¾ö¹æ»® £¬ÎïÁªÍøÉ豸ҲӦÓëÃô¸ÐÍøÂç¸ôÀë²¢¶¨ÆÚ¸üй̼þÒÔ½¨²¹·ì϶¡£


https://www.bleepingcomputer.com/news/security/akira-ransomware-encrypted-network-from-a-webcam-to-bypass-edr/


4. StubHubƱÎñÔ±¹¤µÁÊÛǧÓàÕÅÒôÀÖ»áÃÅÆ±Ôâ¸æ×´


3ÔÂ6ÈÕ £¬Å¦Ô¼¼ì²ì¹ÙÖ¸¿ØStubHubÔÚÏ߯±ÎñÊг¡µÄÁ½ÃûµÚÈý·½³Ð°üÉ̹¤×÷ÈËÔ±ÉæÏÓ͵ÇÔ²¢×ªÊÛ½ü1000ÕŸ߼ÛÖµÒôÀÖ»áÃÅÆ± £¬×¬È¡635,000ÃÀÔª¡£ÕâЩÃÅÆ±´óÎÞÊýÊÇÌ©ÀÕ¡¤Ë¹Íþ·òÌØµÄEras TourÃÅÆ± £¬ÒÔ¼°ÆäËû³ÛÃû»î¶¯ÈçEd Sheeran¡¢AdeleÑݳª»á¡¢NBA½ÇÖðºÍÃÀ¹úÍøÇò¹«¿ªÈüµÄÃÅÆ±¡£Á½Ãû±»ÎÕ±ðÀëÊÇ20ËêµÄ̩¡¡¤ÂÞ˹ºÍ31ËêµÄɯÂêÀ­¡¤Î÷ÃÉ˹ £¬ËûÃÇÔÚÑÀÂò¼ÓÈøÉªÀ¼È«Çò·þÎñ¹«Ë¾¹¤×÷ £¬ÀûÓÃÀ밶ƱÎñ¹©¸øÉÌÆ½Ì¨µÄ·ì϶À¹½ØÁËÔ¼350·ÝStubHub¶©µ¥ £¬ÇÔÈ¡ÃÅÆ±¡£ËûÃǾݳÆÍ¨¹ý½Ó¼ûStubHubÍÆËã»úϵͳ £¬ÕÒµ½ºóÃŽøÈëÍøÂç°²È«ÇøÓò £¬½«ÒÑÊÛ³öÃÅÆ±µÄURL³Á¶¨Ïòµ½Í¬Ä±µÄµç×ÓÓʼþÉÏ¡£Á½ÈËÒÑÔÚŦԼÊб»²¶ £¬²¢Ãæ¶Ô¶àÏîÐÌÊÂÖ¸¿Ø £¬Ò»µ©×ïÃû³ÉÁ¢ £¬½«Ãæ¶Ô×î¸ß15ÄêµÄ½ûïÀ¡£Õâ´Î½ø¹¥Ðж¯Í¹ÏÔÁË´¦Ëù¼ì²ì¹Ù°ì¹«ÊÒ¶ÔÍøÂç·¸×ïµÄ¾¯ÌèÐÔ £¬ÒÔ¼°ÓëÐÐÒµºÏ×÷ͬ°é½ø¹¥Ú²Æ­»î¶¯ºÍÈ·±£Ïû·ÑÕß±£»¤µÄ³ÁÒªÐÔ¡£µ÷²éÈÔÔÚ½øÐÐÖÐ £¬ÒÔÈ·¶¨Õâ´ÎÐж¯µÄ¹æÄ£ºÍÆäËûDZÔÚͬı¡£


https://www.bleepingcomputer.com/news/security/cybercrime-crew-stole-635-000-in-taylor-swift-concert-tickets/


5. PyPIÉϵÄÒÔÌ«·»Ë½Ô¿ÇÔÈ¡·¨Ê½±»ÏÂÔØ³¬¹ý 1,000 ´Î


3ÔÂ6ÈÕ £¬Ò»¸öÃûΪ¡°set-utils¡±µÄ¶ñÒâPython°üÔÚPyPIÉϱ»·¢ÏÖ £¬¸Ã°ü¼Ù×°³ÉʵÓõŤ¾ß°ü £¬Í¨¹ýÀ¹½ØÒÔÌ«·»Ç®°ü´´½¨Ö°ÄÜÇÔȡ˽Կ £¬²¢Í¨¹ýPolygonÇø¿éÁ´½«Æäй¶¡£×Ô2025Äê1ÔÂ29ÈÕÌá½»ÒÔÀ´ £¬¸Ã°üÒѱ»ÏÂÔØÒ»Ç§ÂÅ´Î £¬ÖØÒªÕë¶ÔÇø¿éÁ´¿ª·¢ÈËÔ±¡¢»ùÓÚPythonµÄDeFiÏîÄ¿¡¢Ö§³ÖÒÔÌ«·»µÄWeb3ÀûÓ÷¨Ê½ÒÔ¼°Ê¹ÓÃPython×Ô¶¯»¯µÄÓ×ÎÒÇ®°ü¡£¸Ã¶ñÒâ°üǶÈëÁ˹¥»÷ÕßµÄRSA¹«Ô¿ £¬ÓÃÓÚ¼ÓÃܱ»µÁµÄ˽Կ £¬²¢½«ÆäǶÈëµ½ÒÔÌ«·»ÂòÂôµÄÊý¾Ý×Ö¶ÎÖÐ £¬Í¨¹ýPolygon RPC¶Ëµã·¢Ë͵½¹¥»÷ÕßµÄÕÊ»§¡£ÕâÖÖ²½ÖèÏà¶ÔÒñ±Î £¬²»Ò×±»·À»ðǽºÍ·À²¡¶¾¹¤¾ß¼ì²âµ½¡£Ò»µ©Êý¾Ýй¶¹ý³ÌʵÏÖ £¬¹¥»÷ÕßÄܹ»ËæÊ±¼ìË÷±»µÁÊý¾Ý £¬ÓÉÓÚ±»µÁÐÅÏ¢»áÓÀÔ¶´æ´¢ÔÚÇø¿éÁ´ÉÏ¡£Ö»¹Ü¸Ã°üÒѱ»´ÓPyPIÖÐɾ³ý £¬µ«Òѽ«ÆäÄÉÈëÏîÖ÷ÕÅÓû§ºÍÈí¼þ¿ª·¢ÈËÔ±¸Ãµ±¼´Ð¶ÔØËü £¬²¢Èç¹û´´½¨µÄÈκÎÒÔÌ«·»Ç®°ü¶¼ÒÑÊܵ½Íþв £¬¾¡¿ì×ªÒÆ×ʽðÒÔÔ¤·À±»µÁ·çÏÕ¡£


https://www.bleepingcomputer.com/news/security/ethereum-private-key-stealer-on-pypi-downloaded-over-1-000-times/


6. ³¬¹ý1000¸öWordPressÍøÕ¾Ôâ¶ñÒâJavaScript´úÂë¹¥»÷


3ÔÂ6ÈÕ £¬³¬¹ý1000¸öÓÉWordPressÖ§³ÖµÄÍøÕ¾±»µÚÈý·½JavaScript´úÂëϰȾ £¬¸Ã´úÂëÖ²ÈëÁËËĸö¶ÀÁ¢ºóÃÅ £¬Îª¹¥»÷ÕßÌṩ¶à³ÁÈëÇÖõè¾¶¡£ÕâЩºóÃÅÔ̺¬Ò»¸öÃûΪ¡°Ultra SEO Processor¡±µÄÐéα²å¼þ £¬ÓÃÓÚÖ´Ðй¥»÷ÕߺÅÁÏòwp-config.php×¢Èë¶ñÒâJavaScript£»Ïò~/.ssh/authorized_keysÔö³¤SSHÃÜÔ¿ÒÔʵÏÖÔ¶³Ì½Ó¼û£»ÒÔ¼°´Ógsocket[.]io»ñÈ¡ÔØºÉÒÔ´ò¿ª·´Ïòshell¡£Îª½µµÍ·çÏÕ £¬Óû§±»½¨Òéɾ³ýδÊÚȨSSHÃÜÔ¿¡¢¸ü»»WordPressÖÎÀíÔ±ÃÜÂë £¬²¢¼à¿ØÈÕÖ¾¡£´Ëǰ £¬ÒÑÓг¬¹ý35000¸öÍøÕ¾Ôâ¶ñÒâJavaScriptÈëÇÖ £¬µ¼Ö½ӼûÕß±»³Á¶¨ÏòÖÁÖÐÎÄ´ò¶Äƽ̨¡£Í¬Ê± £¬ÃûΪScreamedJungleµÄÍþвÐÐΪÕßͨ¹ý×¢ÈëBablosoft JS¾ç±¾ £¬Ó°ÏìÁË115¸öÒÔÉϵÄMagentoÍøÕ¾ £¬ÍøÂçÓû§Ö¸ÎÆÐÅÏ¢¡£¹¥»÷ÕßÀûÓÃÒÑÖª·ì϶ £¬ÈçCVE-2024-34102ºÍCVE-2024-20720 £¬½øÐÐÍøÕ¾ÈëÇÖ¡£Group-IBÖ¸³ö £¬ä¯ÀÀÆ÷Ö¸ÎÆ¼ø±ð¼¼ÊõËä³£ÓÃÓÚÓû§¸ú×ÙºÍÓªÏúÕ½Êõ £¬µ«Ò²±»·¸×ï·Ö×ÓÓÃÓÚ·ÂÕպϷ¨Óû§¡¢Ìӱܰ²È«´ëÊ©¼°Ö´ÐÐڲƭ¡£


https://thehackernews.com/2025/03/over-1000-wordpress-sites-infected-with.html