NCERT°ä²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂç°²È«Ì¬ÊÆ×ÛÊö¡·»ã±¨ £»ÐµÄAndroidľÂíBanker.BRÀûÓø²¸Ç¹¥»÷¶Ô×¼ÒøÐй˿Í

°ä²¼¹¦·ò 2020-04-22

1.CNCERT°ä²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂç°²È«Ì¬ÊÆ×ÛÊö¡·»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹ú¶È»¥ÁªÍøÓ¦¼±ÖÐÐÄ£¨CNCERT£©ÓÚ2020Äê4ÔÂ20ÈÕ°ä²¼ÁË¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂç°²È«Ì¬ÊÆ×ÛÊö¡·»ã±¨¡£¸Ã»ã±¨°²ÉíÓÚCNCERTÍøÂ簲ȫºê¹Û¼à²âÊý¾ÝÓ빤×÷ʵ¼Ê»ã±¨ £¬Éæ¼°2019ÄêµäÐÍÍøÂ簲ȫÊÂÎñ¡¢ÍøÂ簲ȫÐÂÇ÷Ïò¼°ÈÕ³£ÍøÂ簲ȫÊÂÎñÓ¦¼±´ëÖÃʵ¼ÊµÈÄÚÈÝ¡£»ã±¨ÖØÒªÔ̺¬Ëĸö²¿ÃÅ £¬Ò»ÊÇ×ܽá2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂ簲ȫÇé¿ö £¬¶þÊÇÔ¤²â2020ÄêÍøÂ簲ȫÈȵã £¬ÈýÊǽáºÏÍøÂç°²È«Ì¬ÊÆ·ÖÎöÌá³ö¶Ô²ß½¨Òé £¬ËÄÊÇÊáÀíÍøÂ簲ȫ¼à²âÊý¾Ý¡£¸Ã»ã±¨¶ÔÎÒ¹úµ³Õþ»ú¹Ø¡¢ÐÐÒµÆóÒµ¼°È«Éç»áÏàʶÎÒ¹úÍøÂ簲ȫ¾ÖÊÆ £¬Ìá¸ßÍøÂ簲ȫÒâʶ £¬×öºÃÍøÂ簲ȫ¹¤×÷ÌṩÁËÓÐÁ¦²Î¿¼¡£


Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2020-04/20/c_1588932297982643.htm


2.Winnti groupÕë¶ÔµÂ¹ú»¯¹¤¹«Ë¾¹¥»÷Ñù±¾µÄ·ÖÎö»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


1Ô·ÝQuoIntelligence£¨QuoINT£©¼ì²âµ½Ò»¸öеÄWinntiÑù±¾²¢¶ÔÆä½øÐÐÁ˳õ²½µÄ·ÖÎö¡£·ÖÎö·¢ÏÖ £¬¸Ã¶ñÒâÈí¼þ¿ÉÄÜÊÇÔÚ2015Äê±»¿ª·¢³öÀ´µÄ¡£¸ÃÑù±¾±»ÓÃÓÚ¹¥»÷Ò»¼ÒµÂ¹ú»¯¹¤¹«Ë¾ £¬Ä¿Ç°Éв»Ã÷ÏԸù«Ë¾µÄ¾ßÌåÃû³Æ¡£¸ÃÑù±¾Ñ¡È¡ÁËеÄC2¼¼Êõ £¬ÒÀÀµÓÚͨ¹ýiodineÔ´´úÂëʵÏÖµÄDNSËí·½øÐÐͨѶ¡£´Ë±í £¬×êÑÐÈËÔ±»¹·¢ÏÖÁËÒ»¸öÒÔǰδ֪µÄ±»µÁÊý×ÖÖ¤Êé £¬¸ÃÖ¤ÊéÖØÒªÓÃÀ´¶ÔWinntiÓйصÄÇý¶¯·¨Ê½½øÐÐÊý×ÖÊðÃû £¬²¢ÇÒÓÃÓÚ¹¥»÷º«¹úÓÎÏ·¹«Ë¾Gravity¡£


Ô­ÎÄÁ´½Ó£º

https://quointelligence.eu/2020/04/winnti-group-insights-from-the-past/


3.½©Ê¬ÍøÂçMootbotÀûÓÃ0day¹¥»÷9¿î¹âÏË·ÓÉÆ÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖ×Ô2ÔÂÏÂÑ®Æð £¬½©Ê¬ÍøÂçMootbot±ãÆðÍ·ÀûÓÃ0day¹¥»÷9¿î¼ÒÓü°ÉÌÓùâÏË·ÓÉÆ÷£¨Ô̺¬Netlink GPON·ÓÉÆ÷£©¡£MoobotÊÇ»ùÓÚMiraiµÄн©Ê¬ÍøÂç £¬ÆäÖ¸±êÊÇÎïÁªÍø£¨IoT£©É豸¡£ÓÉÓÚ´óÎÞÊý¹©¸øÉ̺ܿÉÄÜÊÇѡȡÁËͳһԭʼ¹©¸øÉ̵ÄOEM²úÆ· £¬Òò¶øÕâЩ·ÓÉÆ÷ÊÜͳһ0dayÓ°Ïì¡£¸Ã·ì϶ΪԶ³Ì´úÂëÖ´Ðзì϶ £¬ÆäPoCÒѾ­°ä²¼ £¬µ¥¶ÀÀûÓø÷ì϶²»»áÔì³É·çÏÕ £¬Ö»ÓÐÓëÁíÒ»¸ö·ì϶һ·ʹÓÃÄÜÁ¦ÊµÏÖ¹¥»÷¡£×êÑÐÈËԱûÓÐÅû¶µÚ¶þ¸ö·ì϶µÄ¾ßÌåÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/mootbot-fiber-routers-zero-days/154962/


4.ProofpointÖÒ¸æÀûÓÃÊÓÆµ»áÒ鹫˾µÄ´¹µö¹¥»÷³ÊÔö³¤Ç÷Ïò


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Proofpoint×êÑÐÈËÔ±·¢ÏÖ £¬ÒÔÊÓÆµ»áÒ鹫˾ΪÖ÷ÌâµÄÍøÂç´¹µö¹¥»÷ÊýÁ¿³ÊÔö³¤Ç÷Ïò £¬ÕâЩ¹¥»÷Ö¼ÔÚÇÔÈ¡Óû§µÇ¼ƾ֤ºÍ´«²¼¶ñÒâÈí¼þ¡£ProofpointÖÒ¸æ³Æ £¬ºÚ¿Í²»»áÖ±½Ó¹¥»÷ÕâЩÊÓÆµ»áÒéÈí¼þ £¬µ«ÊÇ»áÒÔÊÓÆµ»áÒ鹫˾µÄÃû³ÆÎªµö¶üÇÔÈ¡Óû§ÕÊ»§Í´´¦ºÍ´«²¼¶ñÒâÈí¼þ¡£×êÑÐÈËÔ±·¢ÏֵĴ¹µö³¡¾°Ô̺¬£ºÎ±ÔìCisco WebExµÄÖÒ¸æÓʼþÀ´ÇÔÈ¡ÃÀ¹úÓû§µÄÕË»§ÐÅÏ¢ £»¼ÙÒâZoom AccountÇÔÈ¡ÃÀ¹úÄÜÔ´¡¢Ôì×÷ºÍóÒ×µÈÐÐÒµµÄÓû§Æ¾Ö¤ £»ÒÔ"zoom call"ΪÖ÷Ìâ´«²¼ServLoaderºÍNetSupport RATµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.proofpoint.com/us/threat-insight/post/remote-video-conferencing-themes-credential-theft-and-malware-threats


5.Foxit½¨¸´PDF Reader¼°PhantomPDFÖеĶà¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Foxit½¨¸´ÁËWindows°æ±¾µÄFoxit ReaderºÍFoxit PhantomPDFÖеÄ20¸öCVE·ì϶¡£Ê×ÏÈ £¬FoxitÔÚPDF Reader 9.7.2°æ±¾Öн¨¸´Á˶à¸öRCE·ì϶ £¬Ô̺¬XFAÄ£°å´¦Öùý³ÌÖеÄRCE·ì϶£¨CVE-2020-10899¡¢ CVE-2020-10907£© £¬AcroFormsÖеÄRCE·ì϶£¨CVE-2020-10900£©ÒÔ¼°resetFormÖеÄRCE·ì϶£¨CVE-2020-10906£©¡£¶ÔÓÚPhantomPDF £¬Õâ´Î¸üн¨¸´ÁËAPIͨѶÖеÄÁ½¸öÒ×±»ÀûÓõÄËÁÒâÎļþдÈë·ì϶£¨CVE-2020-10890ºÍCVE-2020-10892£© £¬ÒÔ¼°Á½¸öÓйØSetFieldValueºÅÁî´¦ÖõĴúÂëÖ´Ðзì϶£¨CVE-2020-10912ºÍCVE-2020-10912£©¡£´Ë±í £¬Õâ´Î¸üл¹½¨¸´ÁËU3DBrowser²å¼þÖеÄ11¸ö·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/foxit-pdf-reader-phantompdf-remote-code-execution/154942/


6.еÄAndroidľÂíBanker.BRÀûÓÃÆÁÄ»¸²¸Ç¹¥»÷¶Ô×¼ÒøÐпͻ§


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


IBM X-Force×êÑÐÈËÔ±·¢ÏÖеÄAndroidľÂíBanker.BR £¬ÆäÀûÓÃÆÁÄ»¸²¸Ç¹¥»÷Õë¶ÔʹÓÃÎ÷°àÑÀÓï»òÆÏÌÑÑÀÓÔ̺¬Î÷°àÑÀ¡¢ÆÏÌÑÑÀ¡¢°ÍÎ÷ºÍÀ­¶¡ÃÀÖÞÆäËûµØÓò£©µÄÒøÐпͻ§ £¬Ì°Í¼ÇÔÈ¡Óû§Æ¾Ö¤²¢µÁÈ¡ÆäÕË»§¡£×êÑз¢ÏÖ £¬¸Ã¶ñÒâÈí¼þµÄÔçÆÚ°æ±¾½öÓµÓиù»ùµÄSMSÇÔȡְÄÜ £¬µ«ÊÇBanker.BR¸üΪ¾«ÃÜ £¬ÓµÓи²¸Ç¹¥»÷µÄÖ°Äܲ¢ÇÒÓÐȫеĴúÂë £¬²»ÒÀÀµÓÚÏÈǰй©µÄ´úÂë»òÏÖÓеÄÒÆ¶¯¶ñÒâÈí¼þ¡£¸Ã¶ñÒâÈí¼þͨ¹ýÓÕʹÓû§ÏÂÔØ¼ÙðµÄÒøÐа²È«ÀûÓ÷¨Ê½½øÐд«²¼ £¬µÅ×û§³É¹¦×°Öúó±ã»áÇÔÈ¡Óû§É豸ÐÅÏ¢ £¬Ô̺¬µç»°ºÅÂë¡¢¹ú¼ÊÒÆ¶¯É豸¼ø±ðÂ루IMEI£©¡¢¹ú¼ÊÒÆ¶¯Óû§¼ø±ðÂ루IMSI£©ºÍSIMÐòÁкŠ£¬²¢½«ÐÅÏ¢·¢Ë͸øC2·þÎñÆ÷¡£×êÑÐÈËÔ±°µÊ¾ £¬¸Ã¶ñÒâÈí¼þÒÀÈ»ÔÚ¿ª·¢ÖС£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/android-banking-br-trojan-credential-stealing/154990/