µçÐŹ«Ë¾AT£¦T´ó×ÚESBC×°±¸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷

Ðû²¼Ê±¼ä 2021-12-03

µçÐŹ«Ë¾AT£¦T´ó×ÚESBC×°±¸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷


µçÐŹ«Ë¾AT£¦T´ó×ÚESBC×°±¸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷.png


Ñо¿ÍŶÓÔÚ11ÔÂ30ÈÕ¹ûÕæÐ½©Ê¬ÍøÂçEwDoorµÄ¹¥»÷»î¶¯ ¡£¡£¡£¡£¡£¡£´Ë´Î»î¶¯Ö÷ÒªÕë¶ÔµçÐŹ«Ë¾AT£¦T EdgeMarcÆóÒµ»á»°½çÏß¿ØÖÆÆ÷(ESBC)±ßÑØ×°±¸£¬£¬ £¬£¬£¬£¬Ê¹ÓÃÁË4ÄêǰµÄÏÂÁî×¢ÈëÎó²î£¨CVE-2017-6079£© ¡£¡£¡£¡£¡£¡£ÔÚ½©Ê¬ÍøÂçÇл»µ½ÆäËüC2֮ǰµÄ¶Ì¶Ì3СʱÄÚ£¬£¬ £¬£¬£¬£¬¹²¼ì²âµ½Ô¼5700̨װ±¸±»Ñ¬È¾ ¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬ £¬£¬£¬£¬Ñо¿Ö°Ô±ÒÑÈ·ÈÏEwDoorµÄ3¸ö±äÌ壬£¬ £¬£¬£¬£¬¿É·ÖΪDDoS¹¥»÷ºÍBackdoorÁ½´óÀ࣬£¬ £¬£¬£¬£¬²¢ÍƲâÆäÖ÷ҪĿµÄÊÇDDoS¹¥»÷£¬£¬ £¬£¬£¬£¬ÒÔ¼°ÍøÂçͨ»°¼Í¼µÈÃô¸ÐÐÅÏ¢ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125143/cyber-crime/ewdoor-botnet.html


ÀÕË÷Èí¼þSabbathÃé×¼ÃÀ¹úºÍ¼ÓÄôóµÄÒªº¦»ù´¡ÉèÊ©


ÀÕË÷Èí¼þSabbathÃé×¼ÃÀ¹úºÍ¼ÓÄôóµÄÒªº¦»ù´¡ÉèÊ©.png


11ÔÂ29ÈÕ£¬£¬ £¬£¬£¬£¬MandiantÍŶӳÆÀÕË÷Èí¼þSabbath£¨ÓÖÃûUNC2190£©×Ô6Ô·Ý×îÏÈÒ»Ö±ÔÚÕë¶ÔÃÀ¹úºÍ¼ÓÄÃ´ó ¡£¡£¡£¡£¡£¡£UNC2190ÔÚ֮ǰÃûΪArcaneºÍEruption£¬£¬ £¬£¬£¬£¬²¢ÔÚ2020Äê7Ô·ַ¢ÀÕË÷Èí¼þROLLCOAST ¡£¡£¡£¡£¡£¡£Sabbath£¨54BB47h£©ÓÚ10ÔÂ21ÈÕÕýʽÔËÓª£¬£¬ £¬£¬£¬£¬Ö÷ҪĿµÄÊÇÒªº¦»ù´¡ÉèÊ©£¬£¬ £¬£¬£¬£¬°üÀ¨ÃÀ¹úºÍ¼ÓÄôóµÄ½ÌÓý¡¢ÎÀÉúºÍ×ÔÈ»×ÊÔ´ÐÐÒµ ¡£¡£¡£¡£¡£¡£ÓëÆäËûÀÕË÷ÔËÓªÍÅ»ï²î±ð£¬£¬ £¬£¬£¬£¬Sabbath»¹ÎªÆäÁ¥Êô×éÖ¯ÌṩÁËÔ¤ÏÈÉèÖúõÄCobalt Strike BEACONºóÃÅpayload ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125154/cyber-crime/sabbath-ransomware.html


Symantec³ÆYanluowangÓëºÚ¿ÍÍÅ»ïThieflockÓйØ


Symantec³ÆYanluowangÓëºÚ¿ÍÍÅ»ïThieflockÓйØ.png


SymantecÔÚ11ÔÂ30ÈÕÐû²¼Á˹ØÓÚÀÕË÷Èí¼þYanluowang½üÆÚ»î¶¯µÄÆÊÎö±¨¸æ ¡£¡£¡£¡£¡£¡£´Ë´Î»î¶¯×îÏÈÓÚ8Ô·Ý£¬£¬ £¬£¬£¬£¬Ê¹ÓÃÁ˶ñÒâÈí¼þBazarLoader£¬£¬ £¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹úµÄ½ðÈÚÐÐÒµ£¬£¬ £¬£¬£¬£¬µ«Ò²Õë¶ÔÖÆÔì¡¢ITЧÀÍ¡¢×ÉѯºÍ¹¤³ÌµÈÐÐÒµµÄ¹«Ë¾ ¡£¡£¡£¡£¡£¡£Ñо¿ÍŶӯÊÎö¹¥»÷ÕßʹÓõŤ¾ß¡¢Õ½ÂԺͳÌÐò(TTP)£¬£¬ £¬£¬£¬£¬·¢Ã÷ÆäÖÐÐí¶à¶¼ÓëThieflockµÄÀÕË÷¹¥»÷»î¶¯ÓйØ£¬£¬ £¬£¬£¬£¬ÕâÅú×¢ËûÃÇ¿ÉÄÜÊôÓÚThieflockµÄÒ»¸öÁ¥Êô×éÖ¯ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/yanluowang-ransomware-thieflock-threat-actor/176640/


MozillaÐÞ¸´NSSÖеÄÄÚ´æËð»µÎó²îCVE-2021-43527


MozillaÐÞ¸´NSSÖеÄÄÚ´æËð»µÎó²îCVE-2021-43527.png


MozillaÓÚ12ÔÂ1ÈÕÐû²¼¸üУ¬£¬ £¬£¬£¬£¬ÐÞ¸´ÁËÆä¿çÆ½Ì¨ÍøÂçÇ徲ЧÀÍ(NSS)ÖеÄÄÚ´æËð»µÎó²î£¨CVE-2021-43527£© ¡£¡£¡£¡£¡£¡£Google project-zeroÑо¿Ö°Ô±ÔÚ10ÔÂ24ÈÕÅû¶¸ÃÎó²îµÄϸ½Ú£¬£¬ £¬£¬£¬£¬ÔÚʹÓÃNSSµÄÓʼþ¿Í»§¶ËºÍPDFÉó²éÆ÷´¦Öóͷ£der±àÂëµÄDSA»òRSA-PSSÊðÃûʱ£¬£¬ £¬£¬£¬£¬¿ÉÄܻᵼÖ»ùÓڶѵĻº³åÇøÒç³ö ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬ £¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿Éµ¼Ö³ÌÐòÍß½â´úÂëÖ´ÐУ¬£¬ £¬£¬£¬£¬ÒÔ¼°ÈƹýÇå¾²¼ì²âÈí¼þ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/mozilla-fixes-critical-bug-in-cross-platform-cryptography-library/


·ÒÀ¼NCSC-FIÐû²¼´ó¹æÄ£·Ö·¢FlubotµÄ»î¶¯µÄ¾¯±¨


·ÒÀ¼NCSC-FIÐû²¼´ó¹æÄ£·Ö·¢FlubotµÄ»î¶¯µÄ¾¯±¨.png


11ÔÂ30ÈÕ£¬£¬ £¬£¬£¬£¬·ÒÀ¼¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ(NCSC-FI)Ðû²¼Ö÷Òª¾¯±¨£¬£¬ £¬£¬£¬£¬ÖÒÑÔÕë¶Ô¸Ã¹úAndroidÓû§´ó¹æÄ£·Ö·¢FlubotµÄ»î¶¯ ¡£¡£¡£¡£¡£¡£ÕâÊǽñÄêFlubotÔÚ·ÒÀ¼ÌᳫµÄµÚ¶þ´Î´ó¹æÄ£»£»£»î¶¯£¬£¬ £¬£¬£¬£¬´Ëǰ´Ó2021Äê6Ô³õÖÁ8ÔÂÖÐÑ®£¬£¬ £¬£¬£¬£¬FlubotÌìÌìÏòÊýǧ¸ö·ÒÀ¼¹«Ãñ·¢ËÍÀ¬»ø¶ÌÐÅ ¡£¡£¡£¡£¡£¡£Ð»ÒÀÈ»ÒÔÒÆ¶¯ÔËÓªÉ̵ÄÓïÒôÓʼþΪÖ÷Ì⣬£¬ £¬£¬£¬£¬ÓÕʹAndroidÓû§ÏÂÔØÒ»¸öAPKÀ´×°ÖÃÒøÐжñÒâÈí¼þFlubot£¬£¬ £¬£¬£¬£¬¶øiPhoneÓû§Ôò»á±»Öض¨Ïòµ½Ö¼ÔÚÇÔÊØÐÅÏ¢µÄ´¹ÂÚÍøÕ¾ ¡£¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/finland-warns-of-flubot-malware-heavily-targeting-android-users/


KasperskyÐû²¼2021ÄêAPT¹¥»÷»î¶¯µÄ»ØÊ×±¨¸æ


KasperskyÐû²¼2021ÄêAPT¹¥»÷»î¶¯µÄ»ØÊ×±¨¸æ.png


KasperskyÓÚ11ÔÂ30ÈÕÐû²¼2021ÄêAPT¹¥»÷»î¶¯µÄ»ØÊ×±¨¸æ ¡£¡£¡£¡£¡£¡£Ñо¿¸ú×ÙÁË900¶à¸öAPT¹¥»÷»î¶¯£¬£¬ £¬£¬£¬£¬Ö¼ÔÚÆÊÎöÒÑÍù12¸öÔÂÖеÄÇ÷ÊÆºÍÉú³¤ ¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬ £¬£¬£¬£¬È«ÇòÁè¼Ý30000¸ö¼ÇÕß¡¢×´Ê¦µÈÖ°Ô±³ÉΪPegasusµÄÄ¿µÄ£»£»£»±¬·¢ÁËÐí¶à±¸ÊÜÖõÄ¿µÄ¹©Ó¦Á´¹¥»÷£¬£¬ £¬£¬£¬£¬ÈçÓ°ÏìÁË18000¶à¸öSolarWinds¿Í»§µÄ¹©Ó¦Á´¹¥»÷£»£»£»Ê¹ÓÃExchangeºÍChromeµÈÈí¼þÖеÄÁãÈÕÎó²î£»£»£»Ê¹Óù̼þÖеÄÎó²î ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/apt-annual-review-2021/105127/