Ó¡¶ÈºÚ¿Í×éÖ¯CyberVolk£ºÐÂÐËÀÕË÷Èí¼þÍþвȫÇòÍøÂ簲ȫ

°ä²¼¹¦·ò 2024-09-06

1. Ó¡¶ÈºÚ¿Í×éÖ¯CyberVolk£ºÐÂÐËÀÕË÷Èí¼þÍþвȫÇòÍøÂ簲ȫ


9ÔÂ5ÈÕ  £¬Ó¡¶ÈºÚ¿Í×éÖ¯CyberVolk×÷ÎªÍøÂç·¸×ïÁìÓòµÄÐÂÐã  £¬ÒÔÆä¸´ÔÓµÄÀÕË÷Èí¼þѸËÙáÈÆð²¢Òý·¢¹Ø×¢¡£¸Ã×éÖ¯×Ô2024Äê7ÔÂÍÆ³öÆäÀÕË÷Èí¼þÒÔÀ´  £¬Æ¾½èÆäÏȽøµÄ¼ÓÃܼ¼ÊõºÍѸËÙÀ©É¢µÄÄÜÁ¦  £¬Ñ¸ËÙÔÚÍøÂç·¸×ï½çÉùÃûÀǽå¡£CyberVolkÀÕË÷Èí¼þ²»½öÖ°ÄÜ׳´ó  £¬»¹ÒÔÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©´ó¾ÖÁ÷ͨ  £¬ÈκÎÈ˾ù¿É×âÓò¢·¢Æð¹¥»÷  £¬¼«´óµØÀ©´óÁËÆäÍþвÁìÓò¡£¸ÃÈí¼þµÄ¼ÓÃÜËã·¨²»ÐÝÉý¼¶  £¬Ñ¡È¡Ô̺¬ChaCha20-Poly1305¡¢AES¼°¿¹Á¿×Ó¼¼ÊõÔÚÄڵĶà³Á¼ÓÃܼ¿Á©  £¬È·±£Êý¾ÝÄÑÒÔ½âÃÜ  £¬¼´±ãÃæ¶ÔÁ¿×ÓÍÆËãÌôÕ½Ò಻Àý±í¡£CyberVolkÀÕË÷Èí¼þ×îΪ¹ÖÒìÖ®´¦ÔÚÓÚÆäÎÞÐèC2·þÎñÆ÷¼´¿É¶ÀÁ¢ÔËÐÐ  £¬¼ÓÇ¿ÁËÒñ±ÎÐÔÓë·ÛËéÐÔ¡£Ò»µ©¼ÓÃÜÆô¶¯  £¬½«Ñ¸ËÙËø¶¨Îļþ  £¬²¢ÉèÖÃÑϸñÊê½ðÆÚÏÞÓë³Í· £»úÔì  £¬ÈçÊäÈëÃýÎóÃÜÔ¿Ôò×Ô¶¯Ïú»ÙÊý¾Ý  £¬ÆÈʹÊܺ¦Õ߾ͷ¶¡£´Ë±í  £¬¸ÃÈí¼þ»¹¾ß±¸Ìӱܼì²â¡¢Èä³æÊ½´«²¼µÈÄÜÁ¦  £¬ÑϳÁÍþвÆóÒµ¼°Ó×ÎÒÐÅÏ¢°²È«¡£Ö»¹ÜCyberVolkÀÕË÷Èí¼þÉè¼Æ¾«Ãî  £¬µ«ÍøÂ簲ȫ×êÑлú¹¹ThreatMonÈÔ·¢ÏÖÁËÆä·ì϶  £¬Èç¿Éͨ¹ýPowerShellºÅÁîÖÕÖ¹¼ÓÃÜ¡¢Åú¸Ä¹¦·òÎļþµ¢¸éÊê½ðÖ§¸¶ÆÚÏÞµÈ  £¬ÎªÓ¦¶Ô¹¥»÷ÌṩÁË¿ÉÄÜÐÔ¡£È»¶ø  £¬CyberVolkÀÕË÷Èí¼þµÄ²ÆÕþÊÕÒæ¼¤Ôö  £¬ÏÔʾ³öÆä»î¶¯µÄ¿í·ºÓ°ÏìÓë·çÏÕ¡£


https://securityonline.info/cybervolk-ransomware-a-new-and-evolving-threat-to-global-cybersecurity/


2. ¾¯Ìè¼ÙÒâNetflixµÄ´¹µöÓʼþ·ºÀÄ


9ÔÂ2ÈÕ  £¬AhnLab °²È«µý±¨ÖÐÐÄ£¨ASEC£©½üÆÚ½ÒʾÁËÕë¶Ô³ÛÃûOTTƽ̨NetflixµÄÍøÂç´¹µöÓʼþ»î¶¯¡£Ëæ×ÅOTTƽ̨±é¼°ºÍÓû§»ùÊýµÄÀ©´ó  £¬´ËÀà´¹µö¹¥»÷ÈÕÒæ·è¿ñ¡£¹¥»÷Õß¾«ÐÄαÔìNetflix¶©Ôĸ¶¿îʧ°ÜµÄÓʼþ  £¬ÓÕµ¼Óû§µã»÷Á´½Ó¸üи¶¿î·½Ê½  £¬ÓʼþÉè¼ÆÕæÇÐ  £¬ÉõÖÁʹÓÿ´ËÆÎÞº¦µÄ¡°netflix-team[.]com¡±ÓòÃû¡£È»¶ø  £¬Õâ²¢·ÇNetflix¹Ù·½µØÖ·  £¬¶øÊÇרΪ´¹µöÉè¼ÆµÄÓòÃû¡£ÓʼþÖÐǶÈëµÄ¡°Ô®ÊÖÖÐÐÄ¡±ºÍ¡°ÁªÏµ·½Ê½¡±Á´½ÓÖ¸Ïò¹Ù·½  £¬µ«¹Ø¼üµÄ¡°Á¢¼´¸üÐÂÕÊ»§¡±°´Å¥Ôòµ¼ÏòÒѹعصĴ¹µöÍøÕ¾URL  £¬Ö»¹Ü¸ÃÍøÕ¾ÎÞ·¨½øÒ»²½·ÖÎö  £¬µ«Í¨¹ý¶ÈÎöÓòÃûºÍ×ÓURLÖз¢ÏֵijÛÃûƽ̨CSSÎļþ  £¬´§Ä¦¹¥»÷Õß¿ÉÄܹ¹½¨Á˶à¸öÀàËÆ´¹µöÕ¾µã¡£´Ë°¸Àý͹ÏÔÁË´¹µöÓʼþµÄÒñ±ÎÐԺ͸´ÔÓÐÔ  £¬¹¥»÷ÕßÀûÓù«¼Ò¶ÔOTTƽ̨µÄÊìϤ¸Ð½µµÍ¾¯Ì衣Ϊ·À±¸´ËÀ๥»÷  £¬Óû§ÐèÌáÉý°²È«Òâʶ  £¬×Ðϸ²é³­ÓʼþÖеÄURL  £¬²¢ÔÚµã»÷ǰͨ¹ý¹Ù·½Çþ·ÑéÖ¤ÐÅÏ¢ÕæÎ±¡£


https://asec.ahnlab.com/en/82969/


3. FBIÖҸ泯ÏʺڿͶÔ×¼¼ÓÃÜÇ®±ÒÁìÓò  £¬Éç»á¹¤³Ì¹¥»÷Ƶ·¢


9ÔÂ3ÈÕ  £¬ÃÀ¹úÁª¹úµ÷²é¾Ö½üÈÕ·¢³ö´¹Î£ÖÒ¸æ  £¬Ö¸³ö³¯ÏʺڿÍ×éÖ¯Õý»ý¼«Õë¶Ô¼ÓÃÜÇ®±ÒÁìÓòÌáÒé¸ß¶È¸´ÔÓµÄÉç»á¹¤³Ì¹¥»÷  £¬Ö¼ÔÚÇÔÈ¡¼ÓÃÜ×ʲú¡£ÕâЩ¹¥»÷¼«¾ßÒñ±ÎÐÔ  £¬¼´¾ÍÊÇÍøÂ簲ȫר¼ÒÒ²ÄÑÒÔµÈÏоõ²ì¡£³¯ÏʺڿÍÊÂÏȶԼÓÃÜÇ®±ÒÂòÂôËùÂòÂô»ù½ð£¨ETF£©¼°ÓйØÓ×ÎÒ½øÐÐÏ꾡µ÷ÑÐ  £¬ÏÔʾ³öÆä¶ÔDZÔÚÖ¸±êµÄÉî¿ÌÏàʶºÍÈ«Ãæ³ï±¸¡£ËûÃDz»½ö¶Ô×¼¼ÓÃÜÇ®±Ò¹«Ë¾  £¬»¹Õë¶Ô´¦ÖôóÁ¿¼ÓÃÜ×ʲúµÄ×éÖ¯ÌáÒéÍøÂçÈëÇÖ  £¬Ì°Í¼µÁÈ¡×ʽð¡£FBIÇ¿µ÷  £¬³¯ÏʺڿÍÉÆÓÚͨ¹ý¾«ÐIJ߶¯µÄÉç»á¹¤³Ì¼¿Á©  £¬¼Ù×°³ÉÕÐÆ¸ÈËÔ±»ò³ÛÃûÐÐÒµÈËÊ¿  £¬ÀûÓÃÓÕÈ˵ľÍÒµºÍͶ×Ê»úÓöÓÕÆ­Ô±¹¤ÖмÆ¡£ËûÃÇʹÓÃÁ÷³©µÄÓ¢ÓרҵµÄ¼ÓÃÜÇ®±Ò֪ʶ¼°Î±ÔìµÄÉí·ÝÐÅÏ¢  £¬¼«´óÌáÉýÁ˹¥»÷µÄ¿ÉÐŶÈ¡£´Ë±í  £¬ºÚ¿Í»¹ÉÆÓÚ¹¹½¨¿´ËƺϷ¨µÄÍøÕ¾ºÍµÁÓÃͼƬ  £¬ÒÔ»ìºÏÊÓÌý¡£ÎªÓ¦¶ÔÕâÒ»Íþв  £¬FBIÁгöÁ˳¯ÏÊÉç»á¹¤³Ì»î¶¯µÄDZÔÚ¼£Ïó  £¬²¢Îª¼ÓÃÜÇ®±ÒÐÐÒµ¼°ÆäÔ±¹¤ÌṩÁË·À±¸½¨Òé  £¬Ô̺¬×ÐϸºË²éÓʼþÆðÔ´¡¢Ô¤·Àµã»÷²»Ã÷Á´½Ó¡¢Í¨¹ý¹Ù·½Çþ·ÑéÖ¤ÐÅÏ¢µÈ¡£


https://www.bleepingcomputer.com/news/security/fbi-warns-crypto-firms-of-aggressive-social-engineering-attacks/?&web_view=true


4. BlindEagleÀûÓÃBlotchyQuasar¹¥»÷¸çÂ×±ÈÑDZ£ÏÕÒµ


9ÔÂ5ÈÕ  £¬Zscaler ThreatLabz½üÆÚ¼ì²âµ½BlindEagle£¨Ò²±»³ÆÎªAguilaCiega¡¢APT-C-36ºÍAPT-Q-98£©ÕâÒ»¸ß¼¶³ÖÐøÐÔÍþв£¨APT£©ÐÐΪÕßµÄл¡£BlindEagleÖØÒª½«Ö¸±êËø¶¨ÔÚÄÏÃÀÖÞ  £¬³ö¸ñÊǸçÂ×±ÈÑǺͶò¹Ï¶à¶ûÈ·µ±¾ÖºÍ½ðÈÚ²¿ÃÅ×éÖ¯¼°Ó×ÎÒ¡£Æäͨ¹ý¾«ÐÄÉè¼ÆµÄÍøÂç´¹µöµç×ÓÓʼþ»ñÈ¡³õʼ½Ó¼ûȨÏÞ  £¬ËæºóÀûÓÃÉÌÆ·»¯µÄ.NETÔ¶³Ì½Ó¼ûľÂí£¨RAT£©ÈçAsyncRAT¡¢RemcosRAT¼°¶¨Ôì±äÌåBlotchyQuasarÇÔÈ¡ÒøÐзþÎñÌṩÉ̵ÄÍ´´¦¡£Õâ´Î¹¥»÷³ö¸ñÕë¶Ô¸çÂ×±ÈÑDZ£ÏÕÒµ  £¬ÍþвÐÐΪÕß¼Ù×°³É¸çÂ×±ÈÑÇ˰Îñ»ú¹Ø£¨DIAN£©·¢ËÍ´¹Î£Í¨Öª  £¬Ðû³ÆÒòδ¸¶Ë°¿î¶ø·¢³ö¿ÛѺÁî  £¬ÆÈʹÊܺ¦ÕßÁ¢¼´Ðж¯¡£Êܺ¦Õß±»ÓÕµ¼ÏÂÔØ²¢ÔËÐÐÒ»¸öÊÜÃÜÂë± £»¤µÄZIP´æµµ  £¬¸Ã´æµµÔ̺¬BlotchyQuasar¶ñÒâÈí¼þ¡£BlotchyQuasarÓµÓÐ׳´óµÄÖ°ÄÜ  £¬Èç¼üÅ̼ͼ¡¢¼à¿ØÒøÐзþÎñ´°¿Ú±êÌâÒÔ¼°Ö´ÐÐshellºÅÁî  £¬´Ó¶øÇÔȡ֧¸¶ÓйØÊý¾Ý¡£ThreatLabzÒÔΪÕâ´Î¹¥»÷¸ß¶È¿ÉÐŵØÓÉBlindEagleÌáÒé  £¬ÒòÆäÇкϸÃ×éÖ¯ÒÑÖªµÄ×÷°¸ÊÖ·¨ºÍÖ¸±êÌØµã¡£


https://www.zscaler.com/blogs/security-research/blindeagle-targets-colombian-insurance-sector-blotchyquasar


5. LiteSpeed Cache·ì϶µ¼ÖÂ600Íò¸öWordPressÍøÕ¾Ãæ¶ÔÕË»§ÊÕÊÜ·çÏÕ


9ÔÂ5ÈÕ  £¬WordPress¼Ó¿ì²å¼þLiteSpeed Cache½üÆÚÆØ³öÑϳÁ°²È«·ì϶CVE-2024-44000  £¬Ó°Ï쳬600ÍòWordPressÍøÕ¾°²È«¡£¸Ã·ì϶ÊôÓÚδ¾­Éí·ÝÑéÖ¤µÄÕÊ»§ÊÕÊÜÎÊÌâ  £¬Ô´ÓÚ²å¼þµÄµ÷ÊÔÈÕÖ¾Ö°Äܲ»µ±´¦ÖÃÓû§»á»°cookie¡£µ±¸ÃÖ°ÄÜÆôÓÃʱ  £¬ËùÓÐHTTPÏìӦͷ£¨º¬Ãô¸Ðcookie£©±»Ð´ÈëδÊܱ £»¤µÄÈÕÖ¾Îļþ  £¬¹¥»÷Õßͨ¹ý½Ó¼û¸ÃÎļþ¿ÉÇÔÈ¡cookie  £¬½ø¶ø¼ÙÒâÖÎÀíÔ±½ÚÔìÍøÕ¾¡£LiteSpeed TechnologiesѸËÙÏìÓ¦  £¬°ä²¼6.5.0.1°æ±¾½¨¸´·ì϶  £¬Ô̺¬½«ÈÕÖ¾ÒÆÖÁרÓÃÎļþ¼Ó×¢Ëæ»ú»¯ÎļþÃû¡¢ÒƳýcookie¼Í¼ѡÏî¼°ÔöÉè± £»¤Îļþ¡£Óû§±»½¨Òé¶Ï¸ù¾ÉÈÕÖ¾Îļþ²¢ÉèÖÃ.htaccess¹æ¶¨Ô¤·ÀÖ±½Ó½Ó¼û  £¬ÒÔ·ÀDZÔÚ¹¥»÷¡£´Ë±í  £¬¸Ã²å¼þ½üÆÚÒÑÂŴα»ÆØ³ö°²È«·ì϶  £¬Ô̺¬Î´ÑéÖ¤¿çÕ¾¾ç±¾ºÍȨÏÞÉý¼¶·ì϶  £¬ºÚ¿Í»î¶¯ÆµÈÔ  £¬´Óǰ24Ó×ʱÄÚ¹¥»÷´ÎÊý¸ß´ï34Íò´Î  £¬Í¹ÏÔÁËʵʱ¸üкͼӹ̰²È«´ëÊ©µÄ³ÁÒªÐÔ¡£WordPressÉçÇøºÍÓû§ÐèÇ×êǹØ×¢²¢²ÉÈ¡ÏàÓ¦·À»¤´ëÊ©  £¬ÒÔÈ·±£ÍøÕ¾°²È«¡£


https://www.bleepingcomputer.com/news/security/litespeed-cache-bug-exposes-6-million-wordpress-sites-to-takeover-attacks/


6. ºÚ¿ÍÏÝÚ壺αÔìOnlyFans¹¤¾ß°µ²ØLumma¶ñÒâÈí¼þ


9ÔÂ5ÈÕ  £¬ºÚ¿ÍÃǽüÆÚѡȡÁËÒ»Öֵ󻬵ÄÕ½Êõ  £¬ÀûÓÃαÔìµÄOnlyFansÕË»§²é³­¹¤¾ß×÷Ϊµö¶ü  £¬Ö¸±êÖ±Ö¸ÆäËûºÚ¿ÍȺÌå¡£ÕâЩ¹¤¾ßÐû³ÆÄÜÑéÖ¤²¢ÇÔÈ¡OnlyFansÕË»§  £¬ÊµÔò°µ²ØLummaÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ  £¬Í¨¹ýGitHubµÈÇþ·´«²¼¡£Lumma×÷ΪһÖָ߼¶µÄMaaS£¨¶ñÒâÈí¼þ¼´·þÎñ£©  £¬²»½ö¾ß±¸×³´óµÄÐÅÏ¢ÇÔÈ¡ÄÜÁ¦  £¬»¹ÄܼÓÔØÆäËû¶ñÒâ¸ºÔØ  £¬¶ÔÊܺ¦ÕßµÄϵͳÔì³ÉÉî¶ÈÇÖº¦¡£Õâ´ÎÊÂÎñÖÐ  £¬ºÚ¿ÍÃǾ«ÐÄÉè¼ÆÁËÏÝÚå  £¬Ê¹ÍþвÐÐΪÕßÔÚ³¢ÊÔÑéÖ¤OnlyFansÕË»§Ê±  £¬²»Öª²»¾õÖÐϰȾÁËLumma  £¬½ø¶øÂ¶³öÁË×ÔÉíµÄÃô¸ÐÐÅÏ¢¡£Lumma»¹Í¨¹ýÆä½Ã½ÝµÄ´«²¼·½Ê½  £¬Èç¶ñÒâ¸æ°×¡¢É罻ýÌåÆÀÂÛµÈ  £¬²»ÐÝÀ©´óÆäÓ°ÏìÁìÓò¡£ÖµÍ×ÌùÐĵÄÊÇ  £¬¸Ã¶ñÒâÈí¼þ²»½öÄÜÇÔÈ¡ÃÜÂë¡¢ÐÅÓþ¿¨ÐÅÏ¢µÈ´«Í³Êý¾Ý  £¬»¹Äܸ´Ô­¹ýÆÚµÄGoogle»á»°ÁîÅÆ  £¬ÏÔʾ³öÆä¸ß¶ÈµÄ¼¼Êõ¸´ÔÓÐÔ΢·çÏÕÐÔ¡£Õâ´Î¹¥»÷²»½öÏÞÓÚOnlyFansÕË»§  £¬»¹À©´óµ½Disney+¡¢InstagramµÈ¶à¸öƽ̨  £¬ÉõÖÁÔ̺¬Mirai½©Ê¬ÍøÂç¹¹½¨Æ÷µÄ´«²¼  £¬ÏÔʾÁ˹¥»÷Õß¿í·º¶ø¶àÑùµÄÖ¸±êÑ¡Ôñ¡£´Ë±í  £¬¹¥»÷Õß»¹ÀûÓÃGitHubµÈ¿ªÔ´Æ½Ì¨ÍйܶñÒâ¸ºÔØ  £¬½øÒ»²½Ôö³¤ÁËÒñ±ÎÐԺʹ«²¼Ð§ÄÜ¡£


https://www.bleepingcomputer.com/news/security/hacker-trap-fake-onlyfans-tool-backstabs-cybercriminals-steals-passwords/