APT36ͨ¹ý¶à¸öαÔìµÄYouTube APK·Ö·¢CapraRAT

Ðû²¼Ê±¼ä 2023-09-20

1¡¢APT36ͨ¹ý¶à¸öαÔìµÄYouTube APK·Ö·¢CapraRAT


SentinelLabsÔÚ9ÔÂ18ÈÕ¹ûÈ»ÁËAPT36£¨ÓÖ³ÆTransparent Tribe£©Ê¹ÓÃÁËÖÁÉÙ3¸öαÔì³ÉYouTubeµÄAndroidÓ¦Ó÷¨Ê½°ü(APK)·Ö·¢CapraRATµÄ»î¶¯ ¡£¶ñÒâÈí¼þÒ»µ©°²×°ÔÚÄ¿±êÉ豸ÉÏ£¬¾Í¿ÉÒÔÊÕ¼¯Êý¾Ý¡¢¼Ç¼ÒôƵ»òÊÓÆµÒÔ¼°·ÃÎÊͨÐÅÐÅÏ¢£¬±¾ÖʾÍÏñ¼äµýÈí¼þÒ»Ñù ¡£¶ñÒâAPKÔÚGoogle PlayÖ®Íâ·Ö·¢£¬Òò´Ë¿ÉÄÜÊÇͨ¹ýÉ繤¹¥»÷½øÐзַ¢ ¡£ÕâЩAPKÓÚ2023Äê4Ô¡¢7ÔºÍ8ÔÂÉÏ´«µ½VirusTotal£¬ÆäÖÐÁ½¸öÃûΪ¡°YouTube¡±£¬Ò»¸ö±»³ÆÎª¡°Piya Sharma¡± ¡£


https://www.sentinelone.com/labs/capratube-transparent-tribes-caprarat-mimics-youtube-to-hijack-android-phones/


2¡¢TrendMicroÐÞ¸´Òѱ»ÀûÓõÄRCE©¶´CVE-2023-41179


¾ÝýÌå9ÔÂ19ÈÕ±¨µÀ£¬Trend MicroÐÞ¸´ÁËApex One¶Ëµã±£»¤½â¾ö·½°¸ÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2023-41179£© ¡£¸Ã©¶´´æÔÚÓÚÄþ¾²Èí¼þ¸½´øµÄµÚÈý·½Ð¶ÔØ·¨Ê½Ä £¿éÖУ¬ÖµµÃ×¢ÒâµÄÊǹ¥»÷Õß±ØÐëÏÈ»ñµÃÄ¿±êϵͳÉϵĹÜÀí¿ØÖÆÌ¨·ÃÎÊȨÏÞ²ÅÆøÀûÓôË©¶´ ¡£Trend Micro³ÆÒÑÊӲ쵽ÖÁÉÙÓÐÒ»´ÎÕë¶Ô´Ë©¶´µÄ¹¥»÷»î¶¯£¬Ç¿ÁÒ½¨ÒéÓû§¾¡¿ì¸üе½×îа汾 ¡£


https://www.bleepingcomputer.com/news/security/trend-micro-fixes-endpoint-protection-zero-day-used-in-attacks/


3¡¢Earth LuscaÀûÓÃSprySOCKSÕë¶Ô¶à¸ö¹ú¼ÒµÄ¹Ù·½ÍøÕ¾


9ÔÂ18ÈÕ£¬Ñо¿ÈËÔ±³ÆÆä·¢ÏÖÁËEarth LuscaÀûÓÃеÄLinuxºóÃÅSprySOCKSµÄ¹¥»÷»î¶¯ ¡£·ÖÎö±íÃ÷£¬¸ÃºóÃÅÔ´×Ô¿ªÔ´Windows¶ñÒâÈí¼þTrochilus£¬ÆäÐí¶à¹¦Ð§±»ÒÆÖ²µ½LinuxϵͳÉÏ£¬C2ͨÐÅЭÒéÀàËÆÓÚWindowsºóÃÅRedLeaves£¬½»»¥Ê½shellµÄʵÏÖÔ´×ÔLinux¶ñÒâÈí¼þDerusbi ¡£¸Ã»î¶¯ÀûÓÃNday©¶´°²×°Cobalt Strike beacon£¬È»ºó·Ö·¢SprySOCKS¼ÓÔØ·¨Ê½ ¡£Earth LuscaÔÚ½ñÄêÉϰëÄêÖ÷ÒªÕë¶Ô¶«ÄÏÑÇ¡¢ÖÐÑÇ¡¢°Í¶û¸ÉµÈµØµÄÍâ½»ÊÂÎñ¡¢¼¼ÊõºÍµçÐÅÏà¹ØµÄÕþ¸®ÊµÌå ¡£


https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html


4¡¢¼ÓÄôóÕþ¸®ºÍ½ðÈÚµÈÁìÓòÔâNoName057(16)µÄDDoS¹¥»÷


¾Ý9ÔÂ18ÈÕ±¨µÀ£¬¼ÓÄôóµÄ¶à¸öʵÌåÔâµ½ÁËNoName057(16)µÄDDoS¹¥»÷ ¡£¼ÓÄôóÍøÂçÖÐÐÄÌåÏÖ£¬×Ô9ÔÂ13ÈÕÒÔÀ´£¬ÆäÁ˽ⲢÏìÓ¦ÁËÕë¶Ô¼ÓÄôóÕþ¸®ÄÚ²¿ÒÔ¼°½ðÈÚºÍÔËÊ䲿ÃŵĶàÆðDDoS¹¥»÷»î¶¯ ¡£½ñÄê2Ô·Ý£¬¸ÃÖÐÐÄÊӲ쵽Õë¶ÔÆäËü¹ú¼ÒµÄÀàËÆDDoS¹¥»÷»î¶¯ ¡£NoName057(16)ͨ³£Ê¹Óý©Ê¬ÍøÂçÀ´¹¥»÷Ä¿±êµÄWeb·þÎñÆ÷£¬È»ºó¿äÒ«Æä¶ñÒâ»î¶¯ ¡£


https://www.cyber.gc.ca/en/alerts-advisories/distributed-denial-service-campaign-targeting-multiple-canadian-sectors


5¡¢SysdigÅû¶Õë¶Ô²»³£¼ûAWS·þÎñµÄ¹¥»÷»î¶¯AMBERSQUID


SysdigÓÚ9ÔÂ18ÈÕÅû¶ÁËÒ»ÖÖеÄÔÆÔ­Éú¼ÓÃܽٳֹ¥»÷»î¶¯AMBERSQUID ¡£´Ë»î¶¯Ö÷ÒªÕë¶Ô²»³£ÓõÄAWS·þÎñ£¬ÀýÈçAWS Amplify¡¢AWS FargateºÍAmazon SageMaker ¡£²»³£ÓÃÒâζ×Å´ÓÄþ¾²½Ç¶ÈÀ´¿´ÕâЩ·þÎñ¾­³£±»ºöÊÓ£¬¶øAMBERSQUID»î¶¯¿ÉÄÜ»áÈÃÄ¿±êÿÌìËðʧÁè¼Ý10000ÃÀÔª ¡£¸Ã»î¶¯Äܹ»ÀûÓÃÔÆ·þÎñ£¬¶ø²»»á´¥·¢AWSÅú×¼¸ü¶à×ÊÔ´µÄÇëÇó ¡£SysdigÌåÏÖËüÔÚ·ÖÎöÁËDocker HubÉϵÄ170Íò¸ö¾µÏñºó·¢ÏÖÁ˸û£¬²¢½«Æä¹éÒòÓÚÓ¡ÄáÏà¹ØµÄ¹¥»÷Õß ¡£


https://sysdig.com/blog/ambersquid/


6¡¢Intel 471Ðû²¼BumblebeeÀûÓÃ4shared WebDAVµÄ·ÖÎö


9ÔÂ15ÈÕ£¬Intel 471Ðû²¼Á˹ØÓÚBumblebeeÀûÓÃ4shared WebDAVµÄ·ÖÎö³ÂËß ¡£BumblebeeÔÚÔÝÍ£Á½¸öÔºó£¬ÓÚ8Ôµ׻ָ´ÔËÓª ¡£ÕâÒ»Âֻ¿ªÊ¼ÓÚ9ÔÂ7ÈÕ£¬ÒÀ¿¿Î±×°³ÉɨÃè¼þ¡¢·¢Æ±ºÍ֪ͨµÄÀ¬»øÓʼþÀ´ÓÕʹÊÕ¼þÈËÏÂÔØ¶ñÒ⸽¼þ ¡£´ó¶àÊý¸½¼þÊÇLNKÎļþ£¬´ò¿ªºó»áÔÚÄ¿±ê¼ÆËã»úÆô¶¯Ò»ÏµÁÐÃüÁÊ×ÏÈÊÇʹÓÃ4shared¹²Ïí´æ´¢ÕÊ»§µÄÓ²±àÂëÆ¾¾ÝÔÚÍøÂçÇý¶¯Æ÷Éϰ²×°WebDAVÎļþ¼Ð£¬×îÖÕ»áÏÂÔØÍйÜÔÚWebDAV·þÎñÆ÷ÉϵÄBumblebee ¡£  


https://intel471.com/blog/bumblebee-loader-resurfaces-in-new-campaign