NoName057(16)£º¶íÂÞ˹ DDoS ×ÌÈÅÕßÃé×¼Î÷·½

Ðû²¼Ê±¼ä 2024-03-05
1. NoName057(16)£º¶íÂÞ˹ DDoS ×ÌÈÅÕßÃé×¼Î÷·½


3ÔÂ3ÈÕ£¬ÎÚ¿ËÀ¼Õ½ÕùÒý·¢ÁËÐÂÐÍÍøÂç³åÍ»£¬ºÚ¿ÍÔ˶¯ÕûÌå³äµ±Á˹ú¼ÒÀûÒæµÄÊðÀíÈË¡£¶íÂÞ˹µÄ NoName057(16) ÒѳÉΪ DDoSia ÏîÄ¿

µÄ´úÃû´Ê£¬ÕâÊÇÒ»ÏîÕë¶ÔÖ§³ÖÎÚ¿ËÀ¼µÄ¹ú¼ÒµÄÒ»Á¬ DDoS ¹¥»÷Ô˶¯¡£ÓëרעÓÚÊý¾Ý͵ÇÔ»òÌع¤Ô˶¯µÄ×éÖ¯²î±ð£¬NoName057(16) ×·Çóѹµ¹ºÍÆÆË𣬽«Êý×ÖÌìÏÂÄð³ÉµØÔµÕþÖÎÕ½ÕùµÄ¹¤¾ß¡£×ÔSEKOIA.IOµ±ÎÒÃÇ×îÏÈ×·×ÙËûÃÇʱ£¬ËûÃǵÄÒªÁìÒѾ­±¬·¢ÁËÑݱ䣬չÏÖÁËËæ×ųåÍ»³±Á÷µÄת±äÒÔ¼°ÓëÎ÷·½¸üÆÕ±éµÄÖ÷ҪʱÊƶø±¬·¢µÄÒ»Á¬ÇÒ˳ӦÐÔÇ¿µÄÍþв¡£2023 Äê 11 Ô 11 ÈÕ£¬DDoSia ÖØ´ó¸üУ¬À©Õ¹Á˶ԸüÆÕ±é×°±¸ºÍ²Ù×÷ϵͳµÄ¼æÈÝÐÔ¡£ÖµµÃ×¢ÖصÄÊÇ£¬ÖÎÀíԱƾ֤µØÀíλÖö¨ÖÆÁË°æ±¾£¬ÖÒÑÔ¶íÂÞ˹Óû§ÔÚ¼ÓÈë¹¥»÷ʱʹÓà VPN À´ÑÚÊÎ×Ô¼ºµÄλÖá£Õâ¸öа汾ÒýÈëÁ˸üÖØ´óµÄÊý¾Ý¼ÓÃÜ£¬¿ÉÒÔ¸üϸÄåµØ¸ú×Ù DDoSia Óû§¡£ÕâЩÊý¾Ý¿ÉÄÜÓÐÖúÓÚÖÎÀíÔ±ÆÀ¹ÀÏîÄ¿µÄÓÐÓÃÐÔ£¬²¢ÇÒ¿ÉÄܳÉΪִ·¨ºÍÍþвÇ鱨ÊÂÇéµÄÃû¹ó×ÊÔ´¡£


https://securityonline.info/noname05716-russias-ddos-disruptors-target-the-west/


2. Predator Ìع¤Èí¼þÉìÕÅ£º11 ¸ö¹ú¼ÒÏÖÔÚÃæÁÙΣº¦


3ÔÂ3ÈÕ£¬ Predator Òƶ¯Ìع¤Èí¼þ±³ºóµÄ²Ù×÷ÕßÈÔȻûÓб»¹«ÖÚÆعâºÍÉó²éÏŵ¹¡£Recorded Future µÄ Insikt ¼¯ÍÅÑо¿Ö°Ô±½ÒÆÆÁËÌع¤Èí¼þÖØÐ޵Ļù´¡ÉèÊ©£¬Åú×¢ Predator ¿ÉÄÜÔÚÖÁÉÙ 11 ¸ö¹ú¼ÒÆð¾¢Ê¹Óá£ÁîÈ˵£ÐĵÄÊÇ£¬Õâ°üÀ¨²©´ÄÍßÄɺͷÆÂɱö£¬ÕâЩµØÇøµÄ Predator ¿Í»§´ËÇ°²¢²»ÎªÈËËùÖª¡£ÓÉ Cytrox ¿ª·¢²¢ÓÉ Intellexa ͬÃËÖÎÀíµÄ Predator ×Ô 2019 ÄêÒÔÀ´Ò»Ö±ÔÚ¹ÍÓ¶Ìع¤Èí¼þÁìÓòÖÐո¶ͷ½Ç¡£¸Ã¹¤¾ßÒѽøÈëÖÁÉÙ 11 ¸ö¹ú¼Ò£¬°üÀ¨°²¸çÀ­¡¢ÑÇÃÀÄáÑÇ¡¢²©´ÄÍßÄÉ¡¢°£¼°¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢¹þÈø¿Ë˹̹¡¢Ãɹš¢°¢Âü¡¢·ÆÂɱö¡¢É³ÌØ°¢À­²®¡¢ÌØÁ¢Äá´ïºÍ¶à°Í¸ç¡£×¨Îª Android ºÍ iOS ×°±¸Éè¼Æ£¬ÆäÒþÃØÉø͸¹¦Ð§Ê¹ÆäÄܹ»ÔÚÓû§²»ÖªÇéµÄÇéÐÎÏ»á¼û×°±¸µÄÂó¿Ë·ç¡¢ÉãÏñÍ·ºÍÃô¸ÐÊý¾Ý¡£ÕâÖֶ๦ЧÐÔ£¬¼ÓÉÏÆäÄÑÒÔ×½ÃþµÄÐÔ×Ó£¬Ê¹ Predator ³ÉΪ¶ñÒâÐÐΪÕßÊÖÖеÄÇ¿Ê¢¹¤¾ß¡£


https://securityonline.info/predator-spyware-spreads-11-countries-now-at-risk/


3. WhatsApp ÆÈʹ Pegasus Ìع¤Èí¼þ·ÖÏíÆäÉñÃØ´úÂë


3ÔÂ4ÈÕ£¬¾Ý¡¶ÎÀ±¨¡·±¨µÀ£¬WhatsApp ºÜ¿ì½«»ñµÃ̽Ë÷ NSO ¼¯ÍÅ Pegasus Ìع¤Èí¼þ¡°ËùÓй¦Ð§¡±µÄȨÏÞ£¬¸ÃÈí¼þÊÇÒÔÉ«Áйú·À²¿ºã¾ÃÒÔÀ´Ò»Ö±½«ÆäÊÓΪ¡°¸ß¶ÈÉñÃØ¡±µÄ¹ú¼ÒÉñÃØ¡£×Ô 2019 ÄêÒÔÀ´£¬WhatsApp Éù³Æ Pegasus ±»ÓÃÀ´ÔÚÁ½ÖÜÄÚ¼àÊÓ 1,400 Ãû WhatsApp Óû§£¬Î´¾­ÊÚȨ»á¼ûËûÃǵÄÃô¸ÐÊý¾Ý£¬°üÀ¨¼ÓÃÜÐÂÎÅ£¬ÒÔºó£¬WhatsApp Ò»Ö±ÒªÇó»á¼û NSO µÄÌع¤Èí¼þ´úÂë¡£Ars Æäʱָ³ö£¬WhatsApp ÆðËß NSO ÊÇ¡°Ø¨¹ÅδÓеÄÖ´·¨Ðж¯¡±£¬¡°Õë¶ÔµÄÊÇÏòÌìϸ÷¹úÕþ¸®³öÊÛÖØ´ó¶ñÒâÈí¼þ·þÎñµÄ²»ÊÜî¿ÏµµÄÐÐÒµ¡±¡£


https://news.hitb.org/content/whatsapp-finally-forces-pegasus-spyware-maker-share-its-secret-code


4. Õë¶ÔÓëÓ¡¶ÈÍâ½»Ô˶¯ÓйصÄÅ·ÖÞ¹ÙÔ±µÄкóÃÅWINELOADER


2ÔÂ29ÈÕ£¬¾ÝÊӲ죬һ¸öÃûΪSPIKEDWINEµÄÏÈÇ°ÎÞÖ¤ÍþвÐÐΪÕßʹÓÃÃûΪWINELOADERµÄкóÃÅÕë¶ÔפÓÐÓ¡¶ÈÍ⽻ʹÍŵÄÅ·ÖÞ¹ú¼ÒµÄ¹ÙÔ±¡£Æ¾Ö¤Zscaler ThreatLabz µÄ±¨¸æ£¬µÐÊÖÔÚµç×ÓÓʼþÖÐʹÓÃÁËÒ»¸ö¿´ËÆÀ´×ÔÓ¡¶È´óʹµÄ PDF Îļþ£¬Ô¼ÇëÍâ½»Ö°Ô±¼ÓÈë 2024 Äê 2 Ô 2 ÈÕµÄÆ·¾ÆÔ˶¯¡£¸ÃPDF ÎĵµÓÚ 2024 Äê 1 Ô 30 ÈÕ´ÓÀ­ÍÑάÑÇÉÏ´«µ½ VirusTotal¡£Ò²¾ÍÊÇ˵£¬ÓÐÖ¤¾ÝÅú×¢£¬¸ÃÔ˶¯¿ÉÄÜÖÁÉÙ´Ó 2023 Äê 7 Ô 6 ÈÕÆð¾Í×îÏÈ»îÔ¾£¬ÓÉÓÚ·¢Ã÷ÁË´Óͳһ¸ö¹ú¼Ò¡£Çå¾²Ñо¿Ö°Ô±ËÕµÏÆÕ¡¤ÐÁ¸ñ (Sudeep Singh) ºÍÂÞÒÁ¡¤Ì© (Roy Tay) ÌåÏÖ£º¡°´Ë´Î¹¥»÷µÄÌصãÊǹ¥»÷Á¿ºÜÊÇС£¬²¢ÇÒÔÚ¶ñÒâÈí¼þºÍÏÂÁîÓë¿ØÖÆ (C2) »ù´¡ÉèÊ©ÖнÓÄÉÁËÏȽøµÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐò (TTP)¡£¡±Õâ´ÎÐÂÐ͹¥»÷µÄ½¹µãÊÇ PDF Îļþ£¬¸ÃÎļþǶÈëÁËÒ»¸öαװ³Éµ÷ÅÌÎʾíµÄ¶ñÒâÁ´½Ó£¬±Þ²ßÊÕ¼þÈËÌîд¸ÃÁ´½Ó²Å»ª¼ÓÈë¡£µ¥»÷¸ÃÁ´½Ó½«Îª°üÀ¨»ìÏýµÄ JavaScript ´úÂëµÄ HTML Ó¦ÓóÌÐò£¨¡°wine.hta¡±£©ÆÌƽõ辶£¬ÒÔ´ÓͳһÓò¼ìË÷°üÀ¨ WINELOADER µÄ±àÂë ZIP ´æµµ¡£


https://thehackernews.com/2024/02/new-backdoor-targeting-european.html


5. Êý°ÙÍò¸ö GitHub ´æ´¢¿â±»·¢Ã÷ѬȾ¶ñÒâ´úÂë


2ÔÂ29ÈÕ£¬Çå¾²Ñо¿Ö°Ô±ÔÚ GitHub ÉÏ·¢Ã÷ÁË´ó¹æÄ£µÄ´æ´¢¿â»ìÏý¹¥»÷Ô˶¯£¬Ó°ÏìÁËÁè¼Ý 100,000 ¸ö´æ´¢¿â£¬ÉõÖÁ¿ÉÄÜÉÐÓÐÊý°ÙÍòÈË¡£ÕâÖÖÖØ´óµÄÍøÂç¹¥»÷ͨ¹ýÓÕÆ­¿ª·¢Ö°Ô±ÏÂÔغÍʹÓÃαװ³ÉÕýµ±´æ´¢¿âµÄ¶ñÒâ´æ´¢¿âÀ´Õë¶Ô¿ª·¢Ö°Ô±¡£Apiiro ¿ª·¢ÁËÒ»ÖÖ¶ñÒâ´úÂë¼ì²âϵͳ£¬¸Ãϵͳ¿É¼à¿Ø´úÂë¿â²¢Ê¹ÓÃÉî¶È´úÂëÆÊÎöºÍ·´»ìÏýµÈÏȽøÊÖÒÕÀ´Ê¶±ðºÍ±ÜÃâ´ËÀ๥»÷¡£Äú¿ÉÒÔʹÓÃANY.RUN ¶ñÒâÈí¼þɳÏäºÍÍþвÇ鱨²éÕÒÀ´ÆÊÎö¶ñÒâÈí¼þÎļþ¡¢ÍøÂ硢ģ¿éºÍ×¢²á±íÔ˶¯£¬´Ó¶øʹÄú¿ÉÒÔÖ±½Ó´Óä¯ÀÀÆ÷Óë²Ù×÷ϵͳ¾ÙÐн»»¥¡£ÕâЩ´æ´¢¿â»á×Ô¶¯·Ö²æÊýǧ´Î£¬²¢ÔÚÖÖÖÖÔÚÏßƽ̨ÉϾÙÐÐÍƹ㣬ÒÔÌá¸ßÆä¿É¼ûÐԺͱ»¿ª·¢Ö°Ô±¹ýʧʹÓõĿÉÄÜÐÔ¡£


https://gbhackers.com/millions-of-github-repos-found-infected/


6. ÒþÐÎ GTPDOOR Linux ¶ñÒâÈí¼þÕë¶ÔÒƶ¯ÔËÓªÉÌÍøÂç


3ÔÂ3ÈÕ£¬Çå¾²Ñо¿Ö°Ô± HaxRob ·¢Ã÷ÁËÒ»¸öÒÔǰδ֪µÄ Linux ºóÃÅ£¬ÃûΪ GTPDOOR£¬×¨ÎªÒƶ¯ÔËÓªÉÌÍøÂçÄÚµÄÉñÃزÙ×÷¶øÉè¼Æ¡£GTPDOOR ±³ºóµÄÍþвÐÐΪÕß±»ÒÔΪÒÔ GPRS ÖÜÓν»Á÷ (GRX) ÖÜΧµÄϵͳΪĿµÄ£¬ÀýÈç SGSN¡¢GGSN ºÍ P-GW£¬ÕâЩϵͳ¿ÉÒÔΪ¹¥»÷ÕßÌṩ¶ÔµçÐŽ¹µãÍøÂçµÄÖ±½Ó»á¼û¡£GRX ÊÇÒƶ¯µçÐŵÄÒ»¸ö×é¼þ£¬¿ÉÔö½ø¿ç²î±ðµØÀíÇøÓòºÍÍøÂçµÄÊý¾ÝÖÜÓηþÎñ¡£·þÎñ GPRS Ö§³Ö½Úµã (SGSN)¡¢Íø¹Ø GPRS Ö§³Ö½Úµã (GGSN) ºÍ P-GW£¨·Ö×éÊý¾ÝÍøÂçÍø¹Ø£¨ÓÃÓÚ 4G LTE£©£©ÊÇÒƶ¯ÔËÓªÉÌÍøÂç»ù´¡ÉèÊ©ÄÚµÄ×é¼þ£¬Ã¿¸ö×é¼þÔÚÒƶ¯Í¨Ñ¶ÖÐÊ©Õ¹²î±ðµÄ×÷Óá£ÓÉÓÚSGSN¡¢GGSNºÍP-GWÍøÂç¸ü¶àµØ̻¶ÔÚ¹«ÖÚÑÛÇ°£¬IPµØµã¹æÄ£ÁÐÔÚ¹ûÕæÎļþÖУ¬Ñо¿Ö°Ô±ÒÔΪËüÃÇ¿ÉÄÜÊÇ»ñµÃÒƶ¯ÔËÓªÉÌÍøÂç³õʼ»á¼ûȨÏÞµÄÄ¿µÄ¡£GTPDOOR ÊÇÒ»ÖÖרΪµçÐÅÍøÂçÁ¿Éí¶¨ÖƵÄÖØ´óºóÃŶñÒâÈí¼þ£¬Ê¹Óà GPRS ËíµÀЭÒé¿ØÖÆƽÃæ (GTP-C) ¾ÙÐÐÒþ²ØÏÂÁîºÍ¿ØÖÆ (C2) ͨѶ¡£ËüÉè¼ÆÓÃÓÚ°²ÅÅÔÚÓë GRX ÏàÁڵĻùÓÚ Linux µÄϵͳÖУ¬ÈÏÕæ·ÓɺÍת·¢ÖÜÓÎÏà¹ØµÄÐÅÁîºÍÓû§Æ½ÃæÁ÷Á¿¡£Ê¹Óà GTP-C ¾ÙÐÐͨѶÔÊÐí GTPDOOR ÓëÕýµ±ÍøÂçÁ÷Á¿»ìÏý£¬²¢Ê¹Óò»Êܱê×¼Çå¾²½â¾ö¼Æ»®¼à¿ØµÄÒÑÔÊÐí¶Ë¿Ú¡£ÎªÁËÌá¸ßÒþ²ØÐÔ£¬GTPDOOR ¿ÉÒÔ¸ü¸ÄÆäÀú³ÌÃû³ÆÒÔÄ£ÄâÕýµ±µÄϵͳÀú³Ì¡£


https://www.bleepingcomputer.com/news/security/stealthy-gtpdoor-linux-malware-targets-mobile-operator-networks/