¸ßͨæçÁúоƬ¸ßΣ·ì϶£¬¿Éµ¼ÖÂ˽Կй¶£»DMSÔâGandCrab¹¥»÷£»ÍÚ¿óÈí¼þBeapy
°ä²¼¹¦·ò 2019-04-26
¸ßͨоƬ×é´æÔÚÒ»¸ö²àÐÅ·¹¥»÷·ì϶£¬¸Ã·ì϶£¨CVE-2018-11976£©¿ÉÔÊÐí¹¥»÷Õß´Ó¸ßͨоƬµÄQSEE°²È«ÇøÓòÖмìË÷¼ÓÃÜ˽Կ¡£QSEEÊǸßͨоƬµÄ¿ÉÐÅÖ´Ðл·¾³£¨TEE£©£¬ÀàËÆÓÚÓ¢ÌØ¶ûµÄSGX¡£Æ¾¾ÝNCC×êÑÐÈËÔ±Keegan RyanµÄ±íÊö£¬¸ßͨоƬµÄ¼ÓÃÜÊðÃûËã·¨ECDSA£¨ÍÖÔ²ÇúÏßËã·¨£©´æÔÚ·ì϶£¬¿Éͨ¹ýËæ»úÊýµÄһЩbit´§Ä¦³ö256λECDSAÃÜÔ¿¡£¸Ã·ì϶µÄÀûÓñØÒªÉ豸µÄrootȨÏÞ¡£ÓÐ46¿î¸ßͨоƬ×éÊܵ½Ó°Ï죬Ô̺¬¶à¿îæçÁúоƬ¡£¸Ã·ì϶µÄ½¨¸´²¹¶¡ÒѾÔ̺¬ÔÚGoogle°ä²¼µÄ4ÔÂAndroid°²È«¸üÐÂÖС£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/security-flaw-lets-attackers-recover-private-keys-from-qualcomm-chips/2.DMSÔâGandCrab¹¥»÷£¬Ô¼38¸öÒ½ÁÆÖÐÐĵÄÊý¾ÝÊÜÓ°Ïì
ÔÎÄÁ´½Ó£º
https://cyware.com/news/doctors-management-service-hit-with-gandcrab-ransomware-attack-compromising-patient-data-b6eebd023.Å·ÖÞÔì×÷ÉÌAebi SchmidtÔâδ֪ÀÕË÷Èí¼þ¹¥»÷
ÈðÊ¿ÊÐÕþºÍũҵ»úеÔì×÷ÉÌAebi Schmidt³ÉΪÀÕË÷Èí¼þ¹¥»÷µÄ×îÐÂÊܺ¦Õß¡£¾ÝTechCrunch±¨Â·£¬ÀÕË÷Èí¼þ¹¥»÷ÑϳÁÓ°ÏìÁËAebi SchmidtµÄÅ·ÖÞ»ùµØ£¬µ¼ÖºܶàϵͳÎÞ·¨ÔËÐУ¬Ô̺¬ÓйØÔì×÷ÒµÎñϵͳ¡£¸Ã¹«Ë¾µÄµç×ÓÓʼþ·þÎñÒ²Êܵ½Ó°Ï죬²¿ÃÅÔ±¹¤±»ÆÈÆðÍ·ÐÝÎÞн¼Ù¡£Aebi Schmidt³Æ¹¥»÷µÄÔÒòÈÔδȷ¶¨¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/unknown-ransomware-cripples-computer-systems-of-aebi-schmidt-ffa880fb4.жñÒâÍÚ¿óÈí¼þBeapy£¬ÒÑϰȾ³¬¹ý1.2Íò¸öÓû§
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2019/04/25/cryptojacking-nsa-malware/5.¹¥»÷ÕßÀÄÓÃGitHub·þÎñÍйÜÍøÂç´¹µö¹¤¾ß°ü
Proofpoint×êÑÐÍŶӷ¢ÏÖ¶ñÒâ¹¥»÷ÕßÀÄÓÃGitHubµÄÍøÒ³¼Ä·Å·þÎñÀ´ÍйÜÍøÂç´¹µö¹¤¾ß°ü¡£ÕâÖÖ²½ÖèʹµÃ¹¥»÷ÕßÄܹ»ÀûÓÃgithub.ioÓòÃûÈÆ¹ý°×Ãûµ¥µÈ·ÀÓù´ëÊ©¡£×êÑÐÈËÔ±·¢ÏÖÕâЩ´¹µö¹¤¾ß°ü´óÎÞÊýÓÃÓÚÍøÂçÊܺ¦ÕßµÄÍ´´¦£¨ÀýÈçÒøÐÐÕË»§Í´´¦£©µÈÃô¸ÐÐÅÏ¢²¢·¢ËÍÖÁ¹¥»÷ÕߵķþÎñÆ÷¡£GitHubÒÑÔÚ4ÔÂ19ÈÕ²ÉÈ¡´ëÊ©½ûÓÃÁËÕâЩ¶ñÒâÕË»§¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/github-service-abused-by-attackers-to-host-phishing-kits/6.TA505ÀûÓÃLOLBinsºÍServHelper¶Ô×¼½ðÈÚ¹«Ë¾
Cybereason×êÑÐÈËÔ±·¢ÏÖ·¸×ïÍÅ»ïTA505µÄй¥»÷»î¶¯ÀûÓöàÖÖºýŪ¼¼Êõ¶Ô×¼½ðÈÚ»ú¹¹¡£¸ÃÍÅ»ïѡȡÁ˶àÖÖÕ½ÊõÀ´Ìӱܼì²â£¬ÖØÒªÕë¶Ô½ðÈÚÆóÒµµÄÌØ¶¨ÕË»§½øÐд¹µö¹¥»÷¡£¹¥»÷ÕßʹÓÃÁ˶à¸öC2ÓòÃûÒÔÈÆ¹ýºÚÃûµ¥¼ì²â£¬²¢ÔÚÖ¸±êϵͳÉÏ¿ªÊÍServHelperºóÃÅ¡£¸ÃServHelper±äÌåÒÀÀµÓÚËĸöLOLBinsºÍ±¾µØÏµÍ³¹ý³ÌÖ´ÐжñÒâ»î¶¯£¬´Ë±í£¬ServHelper»¹Ê¹ÓÃÁËSectigo RSA Code Signing CAÊðÃûµÄÓÐЧ֤ÊéÀ´Ìӱܼì²â¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/ta505-group-uses-lolbins-and-servhelper-backdoor-to-compromise-financial-firms-00550f4d


¾©¹«Íø°²±¸11010802024551ºÅ