Î÷ÑÅͼ¸ÛºÍÎ÷ÑÅͼ-Ëþ¿ÆÂí¹ú¼Ê»ú³¡ÒÉÔâÍøÂç¹¥»÷
Ðû²¼Ê±¼ä 2024-08-268ÔÂ25ÈÕ£¬Î÷ÑÅͼ¸ÛÓëÎ÷ÑÅͼ-Ëþ¿ÆÂí¹ú¼Ê»ú³¡Í¬Ê±ÔËÓª£¬½üÆÚÔâÓöÁËÑÏÖصÄÐÅϢϵͳÌôÕ½£¬ÒÉËÆÔâÓöÁËÍøÂç¹¥»÷¡£ÖÜÁùÇ峿£¬¿Ú°¶Ê×ÏÈͨ¹ýÉ罻ýÌåƽ̨ͨ±¨ÁË·þÎñÖжϵÄÇé¿ö£¬Ëæºó»ú³¡¹Ù·½È·ÈÏÔâÓöÁËϵͳÖжϣ¬²¢ÌåÏÖÕâ¿ÉÄÜÔ´ÓÚÒ»´ÎÍøÂç¹¥»÷¡£Ëæ×ÅÊÂ̬Éú³¤ÖÁÖÜÁùÍí¼ä£¬»ú³¡·½ÃæÌåÏÖ·þÎñÖжÏ×´¿öÒÀ¾Éδ½â£¬ÇÒÎÞ·¨Ã÷È·¸ø³ö»Ö¸´È«Ãæ·þÎñµÄʱ¼ä±í¡£Ãæ¶ÔÕâһͻ·¢×´¿ö£¬»ú³¡·½Ãæ»ý¼«Ó¦¶Ô£¬½¨ÒéÂÿÍÀûÓú½¿Õ¹«Ë¾ÌṩµÄÊÖ»úÓ¦Ó÷¨Ê½¹ÜÀíµÇ»úÊÖÐø²¢´òÓ¡µÇ»úÅƼ°ÐÐÀî±êÇ©£¬Í¬Ê±ÌáÐÑ´î¿ÍÌáÇ°µÖ´ï»ú³¡ÒÔÓ¦¶Ô¿ÉÄܵÄÑÓÎó¡£¾ÝTechCrunchµÄ¼¼Êõ·ÖÎö£¬½ØÖÁÖÜÈÕ̫ƽÑóʱ¼äÔ糿£¬Î÷ÑÅͼ¸Û¶ÔÍâ·þÎñµÄÍøÂç»ù´¡ÉèÊ©£¬ÓÈÆäÊÇÆä¹Ù·½ÍøÕ¾£¬ÈÔ´¦ÓÚ²»ÐзÃÎʵÄÀëÏß״̬£¬ÏÔʾ³ö´Ë´ÎÍøÂç¹¥»÷¶Ô¿Ú°¶¼°»ú³¡ÔËÓªÔì³ÉÁËÏÔÖøÓ°Ïì¡£
https://techcrunch.com/2024/08/25/the-port-of-seattle-and-sea-tac-airport-say-theyve-been-hit-by-possible-cyberattack/
2. PEAKLIGHT ¶ñÒâÈí¼þ£ºÒ»ÖÖÐÂÐÍÒþÃØÄÚ´æÍþв·ºÆð
8ÔÂ24ÈÕ£¬MandiantµÄÍøÂçÄþ¾²ÍŶӽÒ¶ÁËÒ»ÖÖÃûΪPEAKLIGHTµÄÅÓ´óÐÂÐͶñÒâÈí¼þ£¬Ëüͨ¹ýһϵÁо«ÐÄÉè¼ÆµÄ¶à½×¶ÎѬȾ¹ý³Ì£¬ÇÄÎÞÉùÏ¢µØÔÚÊܺ¦ÕßµÄϵͳÖÐÁ÷´«°üÂÞLUMMAC.V2¡¢SHADOWLADDERºÍCRYPTBOTÔÚÄڵĶàÖÖÐÅÏ¢ÇÔÈ¡·¨Ê½¡£PEAKLIGHTµÄÈëÇÖʼÓÚαװ³ÉµÁ°æÓ°Ï·µÄ¶ñÒâZIPÎļþ£¬ÄÚº¬Î±×°³ÉýÌåͼ±êµÄLNK¿ì½Ý·½Ê½Îļþ£¬ÓÕµ¼Óû§Ö´ÐÐǶÈëµÄPowerShell½Å±¾£¬½ø¶øÏÂÔز¢Ö´ÐÐÄÚ´æÖеÄJavaScriptÖ²È뷨ʽ¡£¸ÃÖ²È뷨ʽÀûÓÃÄÚÈÝ·Ö·¢ÍøÂ磨CDN£©Íйܣ¬²¢½ÓÄÉ»ìÏý¼¼Êõ¹æ±Ü¼ì²â£¬×îÖÕÏÂÔز¢Ö´ÐÐPEAKLIGHTÏÂÔØ·¨Ê½£¬¸Ã·¨Ê½Æ¾¾ÝϵͳÇé¿öÏÂÔØÌرðµÄ¶ñÒ⸺ÔØ¡£PEAKLIGHT±äÖÖ¶àÑù£¬µ«ºËÐÄÄ¿±êÒ»Ö£ºÒþ±ÎµØ²¿ÊðÐÅÏ¢ÇÔÈ¡¹¤¾ß¡£·ÖÎöÏÔʾ£¬PEAKLIGHTÏÂÔصÄZIPÎļþ°üÂÞSHADOWLADDERºÍCRYPTBOTµÈ¶ñÒâÈí¼þ£¬Í¬Ê±ÀûÓúϷ¨ÊÓƵÎļþ×÷ΪÓÕ¶ü¡£MandiantÇ¿µ÷£¬´ËÀ๥»÷͹ÏÔÁ˱£³Ö¾¯Ìè¡¢½ÓÄɶàÌõÀíÄþ¾²´ëÊ©µÄÖØÒªÐÔ£¬°üÂÞÈí¼þ¸üС¢Ç¿ÃÜÂëºÍ¶àÒòËØÈÏÖ¤£¬ÒÔ¼°²¿ÊðÓÐЧµÄ¶Ëµã±£»¤¡£
https://securityonline.info/peaklight-malware-a-new-stealthy-memory-only-threat-emerges/
3. CISA¾¯¸æVersa Networks©¶´CVE-2024-39717Õý±»»ý¼«ÀûÓÃ
8ÔÂ23ÈÕ£¬ÃÀ¹úÍøÂçÄþ¾²ºÍ»ù´¡ÉèÊ©Äþ¾²¾Ö£¨CISA£©½üÆÚ½ô¼±Ðû²¼Á˹ØÓÚCVE-2024-39717©¶´µÄÄþ¾²¾¯±¨£¬Ö¸³ö¸Ã¸ßÑÏÖØÐÔ©¶´Õý±»»ý¼«ÀûÓ㬶ÔʹÓÃVersa Networks Director GUIµÄϵͳ×é³ÉÖØ´óÍþв¡£´Ë©¶´ÔÊÐí¾ßÓи߼¶¹ÜÀíȨÏÞµÄÓû§Í¨¹ýÉÏ´«Î±×°Îª.pngͼƬµÄ¶ñÒâÎļþ£¬½ø¶ø¿ÉÄÜ»ñȡδÊÚȨ·ÃÎÊȨÏÞ»òÖ´ÐÐÈÎÒâ´úÂë¡£Õâһ©¶´µÄÑÏÖØÐÔÔÚÓÚ£¬ËüÒÑÈ·Èϱ»Ò°Íâ¹¥»÷ÕßÀûÓ㬲¿ÃÅÔÒòÊÇ¿Í»§Î´×ñÑ֮ǰÐû²¼µÄ·À»ðǽָÄÏ¡£¾¡¹Ü¸Ã¶ñÒâÎļþÔÚ¶àÊýÖ÷Á÷ä¯ÀÀÆ÷ÉÏÎÞ·¨Ö±½ÓÖ´ÐУ¬µ«Ç±ÔÚµÄÀûÓÃʵÀý¼°Î´Ö¤ÊµµÄ³ÂËßÈÔ±íÃ÷·çÏÕÁ¬Ðø´æÔÚ¡£CISAÒѽ«CVE-2024-39717ÄÉÈëÒÑÖª±»ÀûÓ鶴Ŀ¼£¬²¢¶Ø´ÙÁª°î»ú¹¹ÔÚ2024Äê9ÔÂ13ÈÕÇ°²¿Êð×îÐÂÄþ¾²²¹¶¡£¬ÒÔ·À·¶Ç±ÔÚµÄÍøÂç¹¥»÷¡£Òò´Ë£¬ËùÓÐʹÓÃVersa Networks Director GUIµÄ×é֯ӦѸËÙÉó²é²¢¼ÓÇ¿ÆäÄþ¾²ÐÒ飬ͬʱÁ¢¼´Ó¦ÓÃËùÓпÉÓõÄÄþ¾²²¹¶¡ºÍ¸üУ¬ÒÔÈ·±£ÍøÂçÄþ¾²ÃâÊÜ´Ë©¶´µÄÇÖº¦¡£
https://securityonline.info/cve-2024-39717-versa-networks-director-gui-flaw-under-active-attack-cisa-issues-urgent-patching-directive/
4. еÄmacOS¶ñÒâÈí¼þCthulhu StealerÃé×¼AppleÓû§Êý¾Ý
8ÔÂ23ÈÕ£¬ÍøÂçÄþ¾²Ñо¿ÈËÔ±·¢ÏÖÁËÒ»ÖÖÕë¶ÔApple macOSµÄÐÂÐÍÐÅÏ¢ÇÔÈ¡·¨Ê½Cthulhu Stealer£¬¸Ã¶ñÒâÈí¼þ×Ô2023Äêµ×ÆðÒÔÿÔÂ500ÃÀÔªµÄMaaS£¨¶ñÒâÈí¼þ¼´·þÎñ£©Ä£Ê½Ìṩ£¬¿É¿çx86_64ÓëArm¼Ü¹¹ÔËÐС£Cthulhu Stealerαװ³ÉºÏ·¨Èí¼þÈçCleanMyMacµÈ£¬ÀûÓÃÓû§ÐÅÈÎÈƹýGatekeeper±£»¤£¬ÓÕµ¼Óû§ÊäÈëÃÜÂ룬½øÒ»²½ÇÔÈ¡MetaMaskÃÜÂë¡¢iCloud Keychain¼°ä¯ÀÀÆ÷cookieµÈÃô¸ÐÊý¾Ý¡£Ëü»¹ÀûÓÃChainbreakerµÈ¹¤¾ßÊÕ¼¯ÏµÍ³ÐÅÏ¢£¬²¢½«Êý¾ÝѹËõºó·¢ËÍÖÁC2·þÎñÆ÷¡£¾¡¹ÜCthulhu StealerÔÚ¼¼ÊõÉϲ¢²»ÅÓ´ó£¬È±·¦¸ß¼¶·´·ÖÎöÊֶΣ¬µ«ËüչʾÁËÍþвÐÐΪÕßÈÕÒæ¹Ø×¢macOSµÄÇ÷ÊÆ¡£ÖµµÃ×¢ÒâµÄÊÇ£¬¸Ã¶ñÒâÈí¼þ±³ºóµÄ¿ª·¢ÕßÒòÄÚ²¿¾À·×ÒÑÍ˳öÊг¡£¬µ«Õâ²¢²»ÅųýδÀ´ÀàËÆÍþвµÄÔÙÏÖ¡£Ãæ¶ÔÕâÒ»·çÏÕ£¬Æ»¹û¹«Ë¾ÒѽÓÄÉ´ëÊ©£¬¼Æ»®ÔÚmacOS SequoiaÖÐÔöÇ¿¶ÔδǩÃû»òδ¹«Ö¤Èí¼þµÄÏÞÖÆ£¬Óû§Ðèͨ¹ýϵͳÉèÖöø·Ç¼òµ¥²Ù×÷À´ÔÊÐíÈí¼þÔËÐУ¬ÒÔÌá¸ßϵͳÄþ¾²ÐÔ¡£Í¬Ê±£¬×¨¼Ò½¨ÒémacOSÓû§½ö´Ó¿ÉÐÅÀ´Ô´ÏÂÔØÈí¼þ£¬±£³Öϵͳ¸üÐÂÖÁ×îа汾¡£
https://thehackernews.com/2024/08/new-macos-malware-cthulhu-stealer.html?&web_view=true
5. QilinÀÕË÷Èí¼þж¯Ïò£ºÇÔÈ¡Chromeƾ֤
8ÔÂ23ÈÕ£¬ÍøÂçÄþ¾²ÁìÓò·ºÆðÁËÒ»ÆðÒýÈËעĿµÄQilinÀÕË÷Èí¼þ¹¥»÷ʼþ¡£¾ÝSophosÍøÂçÄþ¾²¹«Ë¾³ÂËߣ¬´Ë´Î¹¥»÷²»½öÏÞÓÚ´«Í³µÄÎļþ¼ÓÃÜÓëÀÕË÷£¬»¹º±¼ûµØ½áºÏÁËƾ֤ÊÕ¼¯ÊֶΣ¬¶ÔÊܺ¦ÕßµÄGoogle Chromeä¯ÀÀÆ÷ÖеÄÃô¸ÐÐÅÏ¢×é³ÉÍþв¡£¹¥»÷ÕßÀûÓÃVPNÃÅ»§Ð¹Â¶µÄ¡¢È±·¦¶àÒòËØÈÏÖ¤µÄƾ¾Ý£¬ÀÖ³ÉÉø͸Ŀ±êÍøÂ磬²¢ÔÚÊ×´ÎÈëÇÖºóDZ·ü18Ìì½øÐÐÉî¶ÈºóÀûÓ᣹¥»÷ÕßÇÉÃîµØ±à¼ÁËÓò¿ØÖÆÆ÷ÖеÄĬÈÏÓò¼Æı£¬ÒýÈëÁËÁ½¸öÒªº¦½Å±¾£ºÒ»ÊÇÓÃÓÚËѼ¯Chromeä¯ÀÀÆ÷´æ´¢Æ¾Ö¤µÄPowerShell½Å±¾¡°IPScanner.ps1¡±£¬¶þÊÇ´¥·¢¸Ã½Å±¾Ö´ÐеÄÅú´¦ÖÃÎļþ¡°logon.bat¡±¡£ÕâЩ½Å±¾Í¨¹ýµÇ¼ʱµÄ×é¼Æı¹¤¾ß£¨GPO£©×Ô¶¯Ö´ÐУ¬Ê¹µÃÿ´ÎÓû§µÇ¼ʱ¶¼¿ÉÄÜÔÚ²»ÖªÇéµÄÇé¿öÏ´¥·¢Æ¾Ö¤ÇÔÈ¡£¬Á¬ÐøÈýÌìÖ®¾Ã£¬¼«´óµØÔö¼ÓÁËÐÅϢй¶µÄ·çÏÕ¡£Ëæºó£¬¹¥»÷Õß²»½ö¼ÓÃÜÁËÎļþ¡¢·ÅÖÃÀÕË÷ÐÅ£¬»¹ÇÔÈ¡ÁËÊÕ¼¯µ½µÄƾ֤£¬²¢Çå³ý»î¶¯ºÛ¼£¡£Chromeƾ֤µÄʧÇÔÆÈʹÊܺ¦ÕßÐèÔÚ¶à¸öµÚÈý·½·þÎñÉÏÖØÖÃÕË»§ÃÜÂ룬½øÒ»²½¼Ó¾çÁËʼþµÄÅÓ´óÐÔºÍÓ°Ï췶Χ¡£
https://thehackernews.com/2024/08/new-qilin-ransomware-attack-uses-vpn.html
6. Android¶ñÒâÈí¼þNGateÀûÓÃNFC¼¼ÊõÓÃÓÚATMÈ¡¿î
8ÔÂ23ÈÕ£¬ÔÚ¹ýÈ¥¾Å¸öÔÂÖУ¬Ë¹Âå·¥¿ËÍøÂçÄþ¾²¹«Ë¾ESET½Ò¶ÁËÒ»ÆðÕë¶Ô½Ý¿ËÈý¼ÒÒøÐеÄÖØ´óÍøÂç·¸×ï»î¶¯¡£·¸×ï·Ö×ÓÀûÓÃÃûΪNGateµÄ¶ñÒâÈí¼þ£¬Í¨¹ý¾«ÐÄÉè¼ÆµÄµöÓãÓʼþÓÕÆAndroidÉ豸Óû§ÏÂÔØαװ³ÉÒøÐÐÓ¦ÓõĶñÒⷨʽ¡£Õâ¿îÈí¼þ²»½öÄÜÇÔÈ¡Óû§µÄÒøÐÐÐÅÏ¢£¬»¹½ÓÄÉÁËÒ»ÖÖÇ°ËùδÓеÄNFCÖм̼¼Êõ£¬ÄÜ´ÓÊܺ¦ÕßµÄʵÌåÖ§¸¶¿¨ÖÐÔ¶³Ì´«Êä½ü³¡Í¨ÐÅÊý¾ÝÖÁ¹¥»÷ÕßÉ豸£¬½ø¶øÖ´ÐÐATM½»Ò×»òתÒÆ×ʽ𡣴˶ñÒâÈí¼þ´ÓδÉϼÜGoogle PlayÉ̵꣬Ö÷Ҫͨ¹ýµöÓãÓʼþÖеķǹٷ½Á´½ÓÁ÷´«¡£Êܺ¦Õß±»ÓÕµ¼¿ªÆôNFC¹¦Ð§²¢·ÅÖÃÖ§¸¶¿¨ÓÚÊÖ»ú±³²¿£¬ÒÔÍê³É¿¨ÐÅÏ¢µÄ·Ç·¨»ñÈ¡¡£ESET×Ô2023Äê11ÔÂÆð×·×Ù¸Ã×éÖ¯£¬·¢ÏÖÆä»î¶¯ÔÚÒ»Ãû³ÉÔ±±»²¶ºó¶ÌÔÝÍ£ÖÍ£¬µ«´ËÀàAndroid¶ñÒâÈí¼þµÄй¦Ð§ÈÔÊôÊ×´ÎÔÚÒ°Íâ±»·¢ÏÖ¡£×¨¼Ò¾¯¸æ¹«ÖÚÐèÌá¸ß¾¯Ì裬¼ì²éÍøÕ¾URL¡¢Í×ÉƱ£¹ÜPINÂ룬²¢ÔÚ·ÇÐëҪʱ¹Ø±ÕNFC¹¦Ð§£¬ÍƼöʹÓÃÐéÄ⿨ÒÔ¼õÉÙ·çÏÕ¡£
https://therecord.media/android-malware-atm-stealing-czech-banks