¸ßͨæçÁúоƬ¸ßΣ·ì϶ £¬¿Éµ¼ÖÂ˽Կй¶£»DMSÔâGandCrab¹¥»÷£»ÍÚ¿óÈí¼þBeapy

°ä²¼¹¦·ò 2019-04-26
1.¸ßͨæçÁúоƬ¸ßΣ·ì϶ £¬¿Éµ¼ÖÂQSEE¼ÓÃÜ˽Կй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¸ßͨоƬ×é´æÔÚÒ»¸ö²àÐÅ·¹¥»÷·ì϶ £¬¸Ã·ì϶£¨CVE-2018-11976£©¿ÉÔÊÐí¹¥»÷Õß´Ó¸ßͨоƬµÄQSEE°²È«ÇøÓòÖмìË÷¼ÓÃÜ˽Կ¡£QSEEÊǸßͨоƬµÄ¿ÉÐÅÖ´Ðл·¾³£¨TEE£© £¬ÀàËÆÓÚÓ¢ÌØ¶ûµÄSGX¡£Æ¾¾ÝNCC×êÑÐÈËÔ±Keegan RyanµÄ±íÊö £¬¸ßͨоƬµÄ¼ÓÃÜÊðÃûËã·¨ECDSA£¨ÍÖÔ²ÇúÏßËã·¨£©´æÔÚ·ì϶ £¬¿Éͨ¹ýËæ»úÊýµÄһЩbit´§Ä¦³ö256λECDSAÃÜÔ¿¡£¸Ã·ì϶µÄÀûÓñØÒªÉ豸µÄrootȨÏÞ¡£ÓÐ46¿î¸ßͨоƬ×éÊܵ½Ó°Ïì £¬Ô̺¬¶à¿îæçÁúоƬ¡£¸Ã·ì϶µÄ½¨¸´²¹¶¡ÒѾ­Ô̺¬ÔÚGoogle°ä²¼µÄ4ÔÂAndroid°²È«¸üÐÂÖС£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/security-flaw-lets-attackers-recover-private-keys-from-qualcomm-chips/

2.DMSÔâGandCrab¹¥»÷ £¬Ô¼38¸öÒ½ÁÆÖÐÐĵÄÊý¾ÝÊÜÓ°Ïì

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ò½ÁÆÕ˵¥·þÎñÌṩÉÌDoctors¡¯ Management Service£¨DMS£©Ôâµ½ÀÕË÷Èí¼þGandCrab¹¥»÷ £¬½ü38¸öÒ½ÁÆÖÐÐĵϼÕßÊý¾ÝÊܵ½Ó°Ïì £¬Ô̺¬±´¸¥Àû±í¿ÆÐ­»á¡¢ÐÂÓ¢¸ñÀ¼Éñ¾­×êÑÐËù¡¢ÐÂÓ¢¸ñÀ¼ÉçÇøÒ½ÁÆ·þÎñµÈ¡£ÊÜËðÊý¾ÝÔ̺¬»¼ÕßµÄÓ×ÎÒÐÅÏ¢ £¬ÀýÈçÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢¼ÝÊ»ÅÆÕÕºÅÂë¡¢±£ÏÕ¡¢Ò½ÁƱ£ÏÕ/Ò½ÁƲ¹ÖúÐÅÏ¢µÈ¡£µ÷²éÁ˾ÖÅú×¢¶ÔDMSÍøÂçµÄ³õʼδÊÚȨ½Ó¼û²úÉúÔÚ2017Äê4ÔÂ1ÈÕ £¬Í¨¹ýDMS¹¤×÷Õ¾ÉϵÄRDPºÍ̸½øÐÐÈëÇÖ¡£DMSÒÑ´Ó±¸·ÝÖи´Ô­ÁËÊý¾Ý £¬ÎÞÐèÖ§¸¶Êê½ð¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/doctors-management-service-hit-with-gandcrab-ransomware-attack-compromising-patient-data-b6eebd02

3.Å·ÖÞÔì×÷ÉÌAebi SchmidtÔâδ֪ÀÕË÷Èí¼þ¹¥»÷

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÈðÊ¿ÊÐÕþºÍũҵ»úеÔì×÷ÉÌAebi Schmidt³ÉΪÀÕË÷Èí¼þ¹¥»÷µÄ×îÐÂÊܺ¦Õß¡£¾ÝTechCrunch±¨Â· £¬ÀÕË÷Èí¼þ¹¥»÷ÑϳÁÓ°ÏìÁËAebi SchmidtµÄÅ·ÖÞ»ùµØ £¬µ¼ÖºܶàϵͳÎÞ·¨ÔËÐÐ £¬Ô̺¬ÓйØÔì×÷ÒµÎñϵͳ¡£¸Ã¹«Ë¾µÄµç×ÓÓʼþ·þÎñÒ²Êܵ½Ó°Ïì £¬²¿ÃÅÔ±¹¤±»ÆÈÆðÍ·ÐÝÎÞн¼Ù¡£Aebi Schmidt³Æ¹¥»÷µÄÔ­ÒòÈÔδȷ¶¨¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/unknown-ransomware-cripples-computer-systems-of-aebi-schmidt-ffa880fb

4.жñÒâÍÚ¿óÈí¼þBeapy £¬ÒÑϰȾ³¬¹ý1.2Íò¸öÓû§

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÈüÃÅÌú¿Ë×êÑÐÈËÔ±·¢ÏÖжñÒâÍÚ¿óÈí¼þBeapyµÄ¹¥»÷»î¶¯ÔÚ½üÆÚì­Éý¡£Beapy³õ´Î³öÏÖÓÚ1ÔÂ·Ý £¬×ÔÈýÔ·ÝÒÔÀ´ÒѾ­ÔÚ732¸öÆóÒµÖÐÒý·¢Á˳¬¹ý1.2ÍòÆðϰȾÊÂÎñ¡£¸Ã¶ñÒâÈí¼þͨ¹ý´¹µöÓʼþ´«²¼ £¬Ò»µ©Êܺ¦Õß´ò¿ª¶ñÒ⸽¼þ £¬¶ñÒ⸽¼þ¾Í»á¿ªÊÍNSAºÚ¿Í¹¤¾ßDoublePulsar £¬ÔÚÊÜϰȾµÄÍÆËã»úÉÏ´´½¨ºóÃŲ¢Ê¹ÓÃNSAµÄEternalBlue·ì϶ÀûÓúáÏò´«²¼¡£×êÑÐÈËÔ±³Æ³¬¹ý80£¥µÄBeapyϰȾ¶¼²úÉúÔÚÖйú¡£


Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2019/04/25/cryptojacking-nsa-malware/

5.¹¥»÷ÕßÀÄÓÃGitHub·þÎñÍйÜÍøÂç´¹µö¹¤¾ß°ü


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Proofpoint×êÑÐÍŶӷ¢ÏÖ¶ñÒâ¹¥»÷ÕßÀÄÓÃGitHubµÄÍøÒ³¼Ä·Å·þÎñÀ´ÍйÜÍøÂç´¹µö¹¤¾ß°ü¡£ÕâÖÖ²½ÖèʹµÃ¹¥»÷ÕßÄܹ»ÀûÓÃgithub.ioÓòÃûÈÆ¹ý°×Ãûµ¥µÈ·ÀÓù´ëÊ©¡£×êÑÐÈËÔ±·¢ÏÖÕâЩ´¹µö¹¤¾ß°ü´óÎÞÊýÓÃÓÚÍøÂçÊܺ¦ÕßµÄÍ´´¦£¨ÀýÈçÒøÐÐÕË»§Í´´¦£©µÈÃô¸ÐÐÅÏ¢²¢·¢ËÍÖÁ¹¥»÷ÕߵķþÎñÆ÷¡£GitHubÒÑÔÚ4ÔÂ19ÈÕ²ÉÈ¡´ëÊ©½ûÓÃÁËÕâЩ¶ñÒâÕË»§¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/github-service-abused-by-attackers-to-host-phishing-kits/

6.TA505ÀûÓÃLOLBinsºÍServHelper¶Ô×¼½ðÈÚ¹«Ë¾


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Cybereason×êÑÐÈËÔ±·¢ÏÖ·¸×ïÍÅ»ïTA505µÄй¥»÷»î¶¯ÀûÓöàÖÖºýŪ¼¼Êõ¶Ô×¼½ðÈÚ»ú¹¹¡£¸ÃÍÅ»ïѡȡÁ˶àÖÖÕ½ÊõÀ´Ìӱܼì²â £¬ÖØÒªÕë¶Ô½ðÈÚÆóÒµµÄÌØ¶¨ÕË»§½øÐд¹µö¹¥»÷¡£¹¥»÷ÕßʹÓÃÁ˶à¸öC2ÓòÃûÒÔÈÆ¹ýºÚÃûµ¥¼ì²â £¬²¢ÔÚÖ¸±êϵͳÉÏ¿ªÊÍServHelperºóÃÅ¡£¸ÃServHelper±äÌåÒÀÀµÓÚËĸöLOLBinsºÍ±¾µØÏµÍ³¹ý³ÌÖ´ÐжñÒâ»î¶¯ £¬´Ë±í £¬ServHelper»¹Ê¹ÓÃÁËSectigo RSA Code Signing CAÊðÃûµÄÓÐЧ֤ÊéÀ´Ìӱܼì²â¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/ta505-group-uses-lolbins-and-servhelper-backdoor-to-compromise-financial-firms-00550f4d