¶ñÒâGoogle¹ã¸æÍÆËÍ´øÓÐÒþ²ØºóÃŵļÙIPɨÃèÈí¼þ

Ðû²¼Ê±¼ä 2024-04-19

1. ¶ñÒâGoogle¹ã¸æÍÆËÍ´øÓÐÒþ²ØºóÃŵļÙIPɨÃèÈí¼þ


4ÔÂ18ÈÕ£¬Ð嵀 Google ¶ñÒâ¹ã¸æ»î¶¯ÕýÔÚÀûÓÃÒ»×éÄ£·ÂºÏ·¨ IP ɨÃèÈí¼þµÄÓòÀ´Ìṩһ¸öÒÔǰδ֪µÄÃûΪMadMxShell µÄºóÃÅ¡£ÍþвÐÐΪÕßʹÓÃÎóÖ²¼¼Êõ×¢²áÁ˶à¸öÏàËÆµÄÓòÃû£¬²¢ÀûÓà Google Ads ½«ÕâЩÓòÃûÍÆÖÁÕë¶ÔÌØ¶¨ËÑË÷Òªº¦×ÖµÄËÑË÷ÒýÇæ½á¹ûµÄ¶¥²¿£¬´Ó¶øÒýÓÕÊܺ¦Õß·ÃÎÊÕâÐ©ÍøÕ¾¡£¾Ý³Æ£¬2023 Äê 11 ÔÂÖÁ 2024 Äê 3 ÔÂÆÚ¼ä×¢²áµÄÓòÃû¶à´ï 45 ¸ö£¬ÕâÐ©ÍøÕ¾Î±×°³É¶Ë¿ÚɨÃèºÍ IT ¹ÜÀíÈí¼þ£¬Èç Advanced IP Scanner¡¢Angry IP Scanner¡¢IP ɨÃèÒÇ PRTG ºÍ ManageEngine¡£ËäÈ»Õâ²¢²»ÊÇÍþвÐÐΪÕßµÚÒ»´ÎÀûÓöñÒâ¹ã¸æ¼¼Êõͨ¹ýÏàËÆµÄÍøÕ¾Ìṩ¶ñÒâÈí¼þ·þÎñ£¬µ«ÕâÒ»Éú³¤±ê־׎»¸¶¹¤¾ßÊ״α»ÓÃÀ´Á÷´«ÅÓ´óµÄ Windows ºóÃÅ¡£


https://thehackernews.com/2024/04/malicious-google-ads-pushing-fake-ip.html


2. ¹¥»÷ÕßÀûÓÃOpenMetadataÔÚKubernetesÉϽøÐÐÍÚ¿ó


4ÔÂ17ÈÕ£¬Microsoft Threat Intelligence ·¢ÏÖÁËÕë¶ÔÔËÐÐÁ÷ÐпªÔ´ÔªÊý¾Ýƽ̨ OpenMetadata µÄ Kubernetes ¼¯ÈºµÄй¥»÷»î¶¯¡£¹¥»÷ÕßÕýÔÚÀûÓÃһϵÁÐ×î½üÅû¶µÄÒªº¦Â©¶´À´·ÃÎÊÊÂÇé¸ºÔØ²¢°²×°¼ÓÃÜ»õ±ÒÍÚ¾ò¶ñÒâÈí¼þ¡£¸Ã¹¥»÷ÀûÓÃÁË 1.3.1 ֮ǰµÄ OpenMetadata °æ±¾ÖдæÔڵĶà¸öÄþ¾²Â©¶´£¨CVE-2024-28255¡¢CVE-2024-28847¡¢CVE-2024-28253¡¢CVE-2024-28848¡¢CVE-2024-28254£©¡£ÀÖ³ÉÀûÓøÃ©¶´½«¸³Óè¹¥»÷ÕßÔ¶³ÌÖ´ÐдúÂëµÄÄÜÁ¦£¬´Ó¶øÊ¹ËûÃÇÄܹ»ÍêÈ«¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷ͨ³£´ÓÍøÂç·¸×ï·Ö×ÓɨÃèÔËÐÐÒ×Êܹ¥»÷µÄ OpenMetadata ʵÀýµÄ̻¶ÓÚ»¥ÁªÍøµÄ Kubernetes ÊÂÇé¸ºÔØ¿ªÊ¼¡£Ò»µ©Ê¶±ð³öÄ¿±ê£¬¹¥»÷Õ߾ͻáÀûÓÃÕâЩ©¶´À´¿ØÖÆÍÐ¹Ü OpenMetadata µÄÈÝÆ÷¡£


https://securityonline.info/attackers-exploit-critical-openmetadata-flaws-for-cryptomining-on-kubernetes/


3. SoumniBot ¶ñÒâÈí¼þÀûÓà Android ©¶´À´Èƹý¼ì²â


4ÔÂ17ÈÕ£¬Ò»ÖÖÃûΪ¡°SoumniBot¡±µÄРAndroid ÒøÐжñÒâÈí¼þͨ¹ýÀûÓà Android Çåµ¥ÌáÈ¡ºÍ½âÎö¹ý³ÌÖеÄÈõµã£¬Ê¹ÓÃÒ»ÖÖ²»Ì«³£¼ûµÄ»ìÏýÒªÁì¡£¸ÃÒªÁìʹ SoumniBot Äܹ»¹æ±Ü Android ÊÖ»úÖеij߶ÈÄþ¾²´ëÊ©²¢Ö´ÐÐÐÅÏ¢ÇÔÈ¡²Ù×÷¡£¸Ã¶ñÒâÈí¼þÓÉ¿¨°Í˹»ùÑо¿ÈËÔ±·¢ÏÖ²¢·ÖÎö£¬ËûÃÇÌṩÁË ¸Ã¶ñÒâÈí¼þÀûÓà Android Àý³Ì½âÎöºÍÌáÈ¡ APK Çåµ¥µÄÒªÁìµÄ¼¼Êõϸ½Ú¡£Çåµ¥Îļþ£¨¡°AndroidManifest.xml¡±£©Î»ÓÚÿ¸öÓ¦Ó÷¨Ê½µÄ¸ùĿ¼ÖУ¬°üÂÞÓйØ×é¼þ£¨·þÎñ¡¢¹ã²¥½ÓÊÕÆ÷¡¢ÄÚÈÝÌṩ·¨Ê½£©¡¢È¨ÏÞºÍÓ¦Ó÷¨Ê½Êý¾ÝµÄÏêϸÐÅÏ¢¡£ËäÈ»¶ñÒâ APK ¿ÉÒÔʹÓà Zimperium µÄÖÖÖÖѹËõ¼¼ÇÉÀ´ÓÞŪÄþ¾²¹¤¾ß²¢ÌӱܷÖÎö£¬µ«¿¨°Í˹»ù·ÖÎöʦ·¢ÏÖ SoumniBot ʹÓÃÈýÖÖ²îÒìµÄÒªÁìÀ´Èƹý½âÎöÆ÷¼ì²é£¬ÆäÖÐÉæ¼°ÀûÓÃÇåµ¥ÎļþµÄѹËõºÍ¾Þϸ¡£


https://www.bleepingcomputer.com/news/security/soumnibot-malware-exploits-android-bugs-to-evade-detection/


4. FIN7 Õë¶ÔÃÀ¹úÆû³µÖÆÔìÉÌµÄ IT Ô±¹¤Ìá³«ÍøÂçµöÓã¹¥»÷


4ÔÂ17ÈÕ£¬³öÓÚ¾­¼Ã¶¯»úµÄÍþв×éÖ¯ FIN7 Õë¶ÔÒ»¼ÒÃÀ¹ú´óÐÍÆû³µÖÆÔìÉÌ£¬Ïò IT ²¿ÃŵÄÔ±¹¤·¢ËÍÓã²æÊ½ÍøÂçµöÓãµç×ÓÓʼþ£¬ÒÔÀûÓà Anunak ºóÃÅѬȾϵͳ¡£¾ÝºÚÝ®Ñо¿ÈËÔ±³Æ£¬Õâ´Î¹¥»÷·¢ÉúÔÚÈ¥Äêµ×£¬¶øÇÒÒÀÀµÓڷǵ±µØ¶þ½øÖÆÎļþ¡¢½Å±¾ºÍ¿â (LoLBas)¡£ÍþвÐÐΪÕß½«Öصã·ÅÔÚ¾ßÓи߼¶È¨ÏÞµÄÄ¿±êÉÏ£¬Í¨¹ýð³äºÏ·¨¸ß¼¶ IP ɨÃèÆ÷¹¤¾ßµÄ¶ñÒâ URL Á´½ÓÀ´ÒýÓÕËûÃÇ¡£ºÚÝ®¸ß¶ÈÈ·ÐŴ˴ι¥»÷ÊÇÓÉ FIN7 ÌᳫµÄ£¬ÒòΪ¸Ã¹¥»÷ʹÓÃÁËÆæÌØµÄ PowerShell ½Å±¾£¬¸Ã½Å±¾Ê¹ÓÃÁ˶ÔÊÖµÄÇ©Ãû¡°PowerTrash¡±»ìÏýµÄ shellcode µ÷Ó÷¨Ê½£¬¸Ã½Å±¾Ê״ηºÆðÔÚ 2022 ÄêµÄÒ»´Î»î¶¯ÖС£ÔÚ´Ë֮ǰ£¬FIN7 ±»·¢ÏÖÒÔ̻¶µÄVeeam ±¸·ÝºÍMicrosoft Exchange·þÎñÆ÷ΪĿ±ê£¬²¢½«Black BastaºÍClop ÀÕË÷Èí¼þ¸ºÔز¿Êðµ½ÆóÒµÍøÂçÉÏ¡£


https://www.bleepingcomputer.com/news/security/fin7-targets-american-automakers-it-staff-in-phishing-attacks/


5. Óë¶íÂÞ˹ÓйصÄSandworm ¹¥»÷¾ü»ð¿âÖеÄкóÃÅKapeka


4ÔÂ17ÈÕ£¬³ýÁË΢ÈíÓÚ 2024 Äê 2 Ô 14 ÈÕÐû²¼µÄ¹ØÓÚ·¢ÏÖÒ»¸öÃûΪ KnuckleTouch µÄкóÃŵļò¶ÌÃèÊöÖ®Í⣬Ŀǰ¹«ÖÚ¶Ô Kapeka ºóÃŵÄÁ˽⼸ºõΪÁ㡣΢Èí½« KnuckleTouch ºóÃŹé¾ÌÓÚ SeaShell Blizzard£¬ÕâÊÇÆä¶Ô Sandworm µÄÃû³Æ¡£Microsoft ÉÐδ¶Ô´Ë¶ñÒâÈí¼þ½øÐзÖÎö£¬µ« WithSecure È·ÐÅ KnuckleTouch ¾ÍÊÇ Kapeka¡£Î¢ÈíºÍ WithSecure ÈÏΪ¸Ã¶ñÒâÈí¼þ×Ô 2022 ÄêÒÔÀ´Ò»Ö±ÔÚʹÓ㬵«³ýÁË WithSecure ·ÖÎöÖ®Í⣬ÈËÃÇ¶Ô Kapeka ÖªÖ®ÉõÉÙ¡£WithSecure Æù½ñΪֹֻ·¢ÏÖÁËÁ½¸öÒ°ÍâÑù±¾¡£¿¼Âǵ½µ±Ç°µÄµØÔµÕþÖΣ¬Êܺ¦ÕßѧҲ±íÃ÷ÆäÆðÔ´ÓÚ¶íÂÞ˹£º°®É³ÄáÑǺÍÎÚ¿ËÀ¼¡£ÕâÖÖÓÐÏÞµÄÒ£²â¿ÉÄÜÊÇÒòΪ¸Ã¶ñÒâÈí¼þÉÐδ¹ã·ºÊ¹Óã¬Ò²¿ÉÄÜÊÇÒòΪ Kapeka ÆëÐÄЭÁ¦±£³ÖÒþÃØ¡£ 


https://www.securityweek.com/kapeka-a-new-backdoor-in-sandworms-arsenal-of-aggression/


6. VisaÕë¶Ô½ðÈÚ»ú¹¹µÄJSOutProxÈÕÒæÔö¼ÓµÄÍþв·¢³öͨ¸æ


4ÔÂ17ÈÕ£¬Visa ×î½üÐû²¼Á˹ØÓÚÌØ±ðΣÏÕµÄJSOutProx ¶ñÒâÈí¼þ»î¶¯ÏÔ×ÅÔö¼ÓµÄÑÏÖØÄþ¾²¾¯±¨¡£ÕâÖÖÔ¶³Ì·ÃÎÊľÂí ( RAT ) ÒÔÆä¶Ô½ðÈÚ»ú¹¹¼°Æä¿Í»§µÄÅÓ´ó¹¥»÷ÄÜÁ¦¶øÎÅÃû£¬ÌرðÊÇÕë¶ÔÄÏÑǺͶ«ÄÏÑÇ¡¢Öж«ºÍ·ÇÖÞµØÓò¡£JSOutProx ÓÚ 2019 Äê 12 ÔÂÊ״α»·¢ÏÖ£¬ÊÇÒ»Öָ߶ȻìÏýµÄ JavaScript ºóÃÅ£¬Ê¹ÍøÂç·¸×ï·Ö×ÓÄܹ»Ö´ÐдóÁ¿¶ñÒâ»î¶¯¡£ÆäÖаüÂÞÔËÐÐ shell ÃüÁî¡¢ÏÂÔØÌØ±ðµÄÓк¦¸ºÔØ¡¢Ö´ÐÐÎļþ¡¢²¶×½ÆÁÄ»½ØÍ¼ÒÔ¼°ÍêÈ«¿ØÖÆÊÜѬȾÉ豸µÄ¼üÅ̺ÍÊó±ê¡£Ëæ×Åʱ¼äµÄÍÆÒÆ£¬JSOutProx ²»Í£Éú³¤£¬ÔöÇ¿ÁËÆä¹æ±Ü¼¼ÊõÒÔÖÆÖ¹¼ì²â²¢ÔöÇ¿ÁËÆäÆÆ»µÄÜÁ¦¡£JSOutProx µÄ³õʼÓÐЧ¸ºÔØÖ§³Ö»ù±¾µ«Òªº¦µÄ¹¦Ð§£¬Ê¹¹¥»÷ÕßÄܹ»¶ÔÊÜѬȾµÄϵͳ½øÐÐÏ൱´óµÄ¿ØÖÆ¡£


https://securityboulevard.com/2024/04/jsoutprox-malware-variant-targeting-financial-orgs-warns-visa/#google_vignette