¶íÂÞ˹µçÐÅRostelecom½Ù³Ö¶à¸öÆóÒµµÄÁ÷Á¿£»Î¢Èí°ä²¼Emotet¹¥»÷°¸Àý»ã±¨

°ä²¼¹¦·ò 2020-04-07

1.DarkHotelÀûÓÃÉîÕÛ·þVPN·ì϶¹¥»÷ÎÒ¹úÈ·µ±¾Ö»ú¹¹


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½üÈÕ£¬ÓÐÐÂÎųƺڿÍ×éÖ¯Darkhotel£¨APT-C-06£©ÀûÓÃÉîÕÛ·þSSL VPNÉ豸·ì϶¹¥»÷ÎÒ¹úÈ·µ±¾Ö»ú¹¹¡£¸Ã¹¥»÷»î¶¯Ê¼ÓÚ3Ô£¬Óг¬¹ý200̨VPN·þÎñÆ÷Ôâµ½¹¥»÷£¬ÆäÖÐ174̨λÓÚ±±¾©ºÍÉϺ£È·µ±¾Ö»ú¹¹ÍøÂçÒÔ¼°²¿ÃÅÖйúפ±í»ú¹¹£¬4Ô³õ¹¥»÷Ì¬ÊÆÓÖÔÙÏò±±¾©¡¢ÉϺ£Óйص±¾Ö»ú¹¹ÊæÕ¹¡£ÉîÕÛ·þ¹Ù·½ÒÑÓÚ4ÔÂ6ÈÕÕýʽ°ä²¼°²È«²¼¸æ£¬²¢Æô¶¯·ì϶ÏìÓ¦¡£¸Ã·ì϶ÊÇ4ÔÂ3ÈÕ360ÏòÉîÕÛ·þÓ¦¼±°²È«ÏìÓ¦ÖÐÐĻ㱨µÄ·ì϶£¨SRC-2020-281£©£¬ÎªSSL VPNÉ豸Windows¿Í»§¶ËÉý¼¶Ä £¿éÊðÃûÑéÖ¤»úÔìµÄȱµã£¬µ«¸Ã·ì϶ÀûÓÃǰÌáÊDZØÐëÒѾ­»ñÈ¡½ÚÔìSSL VPNÉ豸µÄȨÏÞ£¬Òò¶øÀûÓÃÄѶȽϸß¡£ÉîÕÛ·þÈ·ÈÏÔËÐй̼þ°æ±¾M6.3R1ºÍM6.1µÄSSL VPNÉ豸Ò×Êܹ¥»÷£¬½¨ÒéÓû§½øÐÐÅŲéºÍÀûÓò¹¶¡¸üС£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/darkhotel-hackers-use-vpn-zero-day-to-compromise-chinese-government-agencies/


2.¶íÂÞ˹µçÐŹ«Ë¾Rostelecom½Ù³Ö¶à¸öÆóÒµµÄ»¥ÁªÍøÁ÷Á¿


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


4ÔÂ1ÈÕ¶íÂÞ˹µçÐŹ«Ë¾Rostelecom½Ù³ÖÁ˹ȸèµÈ¹«Ë¾µÄ»¥ÁªÍøÁ÷Á¿£¬¸ÃÊÂÎñÓ°ÏìÁËÊÀ½çÉÏ×î´óµÄ200¶à¸öCDNÍøÂç¼°ÔÆÍйܷþÎñÉÌ£¬³ÖÐøÁËԼĪ1¸öÓ×ʱ¡£ÊÜÓ°ÏìµÄÆóÒµÔ̺¬¹È¸è¡¢ÑÇÂíÑ·¡¢Facebook¡¢Akamai¡¢Cloudflare¡¢GoDaddy¡¢Digital Ocean¡¢Joyent¡¢LeaseWeb¡¢HetznerºÍLinodeµÈ³ÛÃû¹«Ë¾¡£ÕâÊÇÒ»´ÎµäÐ͵ÄBGP½Ù³ÖÊÂÎñ£¬¸ÃÊÂÎñµÄÔ­Òò¿ÉÄÜÊÇRostelecomµÄÄÚ²¿Á÷Á¿½¨¸ÄϵͳÃýÎ󵨽«²»ÕýÈ·µÄBGP·Óɶ³öÔÚ¹«ÍøÉÏ£¬²¢ÇÒ±»ÉÏÓι©¸øÉ̹㲥Ôì³ÉµÄ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/russian-telco-hijacks-internet-traffic-for-google-aws-cloudflare-and-others/


3.΢Èí°ä²¼Emotet¹¥»÷Fabrikam¹«Ë¾µÄ°¸Àý×êÑл㱨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


΢ÈíÔÚ¼ì²âºÍÏìÓ¦Ó××飨DART£©°¸Àý»ã±¨002ÖзÖÏíÁËFabrikam¹«Ë¾Ôâ·êEmotet¹¥»÷µÄ¾ßÌåÐÅÏ¢¡£¸Ã¹¥»÷ʼÓÚÍøÂç´¹µöÓʼþ£¬µ±ÄÚ²¿Ô±¹¤½Ó¼ûÁË´¹µöÐÅÏ¢ºó£¬EmotetϰȾÁËÆäϵͳ²¢ºáÏòϰȾÁËÍ³Ò»ÍøÂçÖÐµÄÆäËüϵͳ¡£¸Ã²¡¶¾Ô¤·ÀÁËͨ¹ýºÅÁîºÍ½ÚÔì·þÎñÆ÷£¨C2£©½øÐж¨ÆÚ¸üжø±»·À²¡¶¾½â¾ö¹æ»®¼ì²âµ½µÄÇé¿ö£¬²¢ÇÒͨ¹ýʹWindowsÉ豸ÉϵÄCPUʹÓÃÂÊ´ïµ½¹ÄºÍÀ´ÖÕ³¡Ö÷Ìâ·þÎñ£¬µ¼Ö¸Ã×éÖ¯µÄ¸ù»ù·þÎñºÍÍøÂçÖжÏÁ˽«½üÒ»ÖܵŦ·ò¡£CPUʹÓÃÂÊÒ»Ïò¹ÄºÍʹµÃÍÆËã»ú¹ýÈÈ£¬µ¼ÖÂÄÚ²¿ÏµÍ³¿¨ËÀ¡¢³ÁÆôºÍÍøÂçÏνӽµÂä¡£¸Ã¶ñÒâÈí¼þͨ¹ýÇÔÈ¡ÖÎÀíÔ¹ØÊ»§Í´´¦½øÐкáÏòÒÆ¶¯£¬ÔÚ×î³õϰȾºóµÄ8ÌìÖ®ÄÚ£¬FabrikamµÄÕû¸öÍøÂç¾Í±»¹Ø¹ØÁË¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/security/blog/wp-content/uploads/2020/04/Case-study_Full-Operational-Shutdown.pdf


4.PayPalºÍVenmoÓû§»¥»»Õ½Êõ·ì϶µ¼ÖºڿͽٳÖÓû§


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÆÕÁÖ˹¶Ù´óѧµÄ×êÑÐÈËÔ±·¢ÏÖ17¼ÒÖØÒª¹«Ë¾£¬ÆäÖÐÔ̺¬Amazon¡¢Paypal¡¢Venmo¡¢Blizzard¡¢Adobe¡¢eBay¡¢SnapchatºÍYahoo£¬ÔÊÐíÓû§Í¨¹ý·¢Ë͵½ÓëËûÃÇÕÊ»§ÓйØÁªµÄµç»°ºÅÂëµÄ¶ÌÐÅÀ´³ÁÖÃÃÜÂ룬ÕâÒâζ×ÅÈôÊǺڿÍͨ¹ýSIM»¥»»¹¥»÷½ÚÔìÁËÊܺ¦ÕßµÄÊÖ»úºÅÂ룬ÄÇôºÚ¿Í¾ÍÄܹ»ÀûÓÃÕâÐ©ÍøÕ¾ºÍ·þÎñÈëÇÖÊܺ¦ÕßµÄÔÚÏßÕÊ»§¡£ÔÚ½Óµ½×êÑÐÈËÔ±µÄÖÒ¸æÖ®ºó£¬Ô̺¬Adobe¡¢±©Ñ©¡¢Ebay¡¢Î¢ÈíºÍSnapchatÔÚÄÚµÄһЩ¹«Ë¾½¨¸´ÁËÕâÒ»ÎÊÌ⣬µ«ÈÔÓÐһЩ¹«Ë¾Ã»Óн¨¸´¸Ã·ì϶£¬ÀýÈçÔÊÐíÓû§½øÐÐÂòÂô²¢ÇÒÓëÒøÐÐÕÊ»§»òÐÅÓþ¿¨¹ØÁªµÄÀûÓ÷¨Ê½PaypalºÍVenmo¡£ÕâÁ½¼Ò¹«Ë¾ÉÐδ¾Í´Ë°ä·¢ÆÀÂÛ¡£


Ô­ÎÄÁ´½Ó£º

https://www.vice.com/en_us/article/pke9zk/paypal-and-venmo-are-letting-sim-swappers-hijack-accounts


5.Apple½¨¸´SafariÖжà¸ö·ì϶£¬¿É±»ºÚ¿Í½ÚÔìÉãÏñÍ·


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÈËÔ±Ryan PickrenÔÚSafariÖз¢ÏÖÁË7¸ö0day£¬Ô̺¬CVE-2020-3852¡¢CVE-2020-3864¡¢CVE-2020-3865¡¢CVE-2020-3885¡¢CVE-2020-3887£¬CVE-2020-9784ºÍCVE-2020-9787¡£¹¥»÷Õß¿ÉÀûÓÃÆäÖеÄ3¸ö·ì϶×éºÏ£¬½Ó¼ûiOSºÍmacOSÉ豸ÉϵÄÉãÏñÍ·ºÍÂó¿Ë·ç²¢¼à¶½Óû§¡£Õâ3¸ö·ì϶ÓëSafari½âÎöURI¡¢ÖÎÀíWebÔ´ÒÔ¼°³õʼ»¯°²È«¸ßµÍÎĵķ½Ê½ÓйØ£¬¿ÉÔÊÐí¶ñÒâÍøÕ¾ÔÚSafariÉϼÙ×°³ÉÊÜÐÅÀµµÄÍøÕ¾ÌáÒé¹¥»÷¡£AppleÔÚ1ÔÂ28ÈÕ°ä²¼µÄSafari 13.0.5Öн¨²¹ÁËÕâ3¸ö·ì϶£¬²¢ÔÚ3ÔÂ24ÈÕ°ä²¼µÄSafari 13.1Öн¨¸´ÁËÆäÓà·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/vulnerabilities---threats/researcher-hijacks-ios-macos-camera-with-three-safari-zero-days/d/d-id/1337486


6.EuropolÓëInterpol°ä²¼ÓëCOVID-19ÓйصÄÍøÂç·¸×ï´«µÝ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Å·ÖÞÐ̾¯×éÖ¯£¨Europol£©ÔÚ×îÐµİ²È«Õ÷ѯÖоßÌå½éÉÜÁËCOVID-19ÓйصÄÍøÂç·¸×ï»î¶¯£¬ÁгöÁË´ÙʹÓëCOVIDÓйصÄÍøÂç·¸×ï»î¶¯±ä¶¯µÄÁù¸ö³É·Ö£º¶ÔijЩÉÌÆ·¡¢·À»¤É豸ºÍÒ©Æ·µÄ¸ßÐèÒª£»¹«ÃñÔ½À´Ô½ÒÀÀµÊý×Ö½â¾ö¹æ»®½øÐÐÔ¶³Ì°ì¹«£»½¹ÂǺÍÕð¾ªÉúÀí£»½ø³öÅ·Ã˵ÄÈËÔ±Á÷¶¯Ï÷¼õ£»¹«¹²³¡Ëù»î¶¯ÊÜÏÞ£¬Ê¹Ò»Ð©·¸×ï»î¶¯×ªÒƵ½¼ÒÍ¥»òÔÚÏß»·¾³£»Å·ÃËijЩ·¸·¨ÉÌÆ·µÄ¹©¸øÏ÷¼õ¡£Óë´Ëͬʱ£¬¹ú¼ÊÐ̾¯×éÖ¯£¨Interpol£©ÖÒ¸æÀÕË÷Èí¼þ¹¥»÷ÒѾ­ÆðÍ·Õë¶ÔÒ½ÔºµÅ×ëCOVID-19ÓÐ¹ØµÄÆäËü»ú¹¹¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.europol.europa.eu/publications-documents/catching-virus-cybercrime-disinformation-and-covid-19-pandemic