ÖÇÀû½ðÈÚÊг¡Î¯Ô±»áExchangeÔâµ½¹¥»÷²¢¹²ÏíIOC£»SentinelOne·¢ÏÖÕë¶ÔiOS¿ª·¢ÈËÔ±µÄ¹©¸øÁ´¹¥»÷»î¶¯
°ä²¼¹¦·ò 2021-03-191.ÖÇÀû½ðÈÚÊг¡Î¯Ô±»áExchangeÔâµ½¹¥»÷²¢¹²ÏíIOC

ÖÇÀû½ðÈÚÊг¡Î¯Ô±»á£¨CMF£©³ÆÆäExchangeÔâµ½¹¥»÷²¢¹²ÏíIOC¡£CMFÊôÓÚÖÇÀû²ÆÕþ²¿£¬ÊÇÖÇÀûÒøÐкͽðÈÚ»ú¹¹µÄ¼à¹ÜÕߺͲé³Ô±¡£CMFÓÚ3ÔÂ17ÈÕ°ä²¼»ã±¨£¬³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷£¬ºÚ¿ÍÀûÓÃ×î½üÅû¶µÄMicrosoft Exchange·þÎñÆ÷ÖеÄProxyLogon·ì϶װÖÃWeb Shell²¢ÊÔͼÇÔȡʹ´¦Ö®ºó¡£ÎªÁËÔ®ÊÖ×êÑÐÈËÔ±ºÍÆäËûMicrosoft ExchangeÖÎÀíÔ±£¬CMF»¹°ä²¼ÁËWeb ShellµÄIOCºÍÔÚÔâµ½¹¥»÷µÄ·þÎñÆ÷ÉÏÕÒµ½µÄÅú´¦ÖÃÎļþ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/chiles-bank-regulator-shares-iocs-after-microsoft-exchange-hack/
2.SentinelOne·¢ÏÖÕë¶ÔiOS¿ª·¢ÈËÔ±µÄ¹©¸øÁ´¹¥»÷»î¶¯

°²È«¹«Ë¾SentinelOne·¢ÏÖÁËÐµĹ©¸øÁ´¹¥»÷»î¶¯£¬Ê¹ÓÃÃûΪXcodeSpyµÄ¶ñÒâXcodeÏîÄ¿Õë¶ÔiOS¿ª·¢ÈËÔ±¡£XcodeÊÇApple´´½¨µÄ¼¯³É¿ª·¢»·¾³£¨IDE£©£¬¿ª·¢ÈËÔ±¿ÉÀûÓÃÆä´´½¨macOS¡¢iOS¡¢tvOSºÍwatchOSÀûÓ÷¨Ê½¡£Ôڸù¥»÷ÖУ¬ºÚ¿Í¿Ë¡Á˺Ϸ¨µÄTabBarInteractionÏîÄ¿£¬²¢Ôö³¤ÁËÍÌ͵ĶñÒâRun¾ç±¾XcodeSpy£¬ÒÔ½«¹¥»÷ÕßµÄC2·þÎñÆ÷Ïνӵ½¿ª·¢ÈËÔ±µÄÏîÄ¿¡£XcodeSpyÓÚ9ÔÂ4ÈÕ³õ´Î±»ÉÏ´«µ½VirusTotal£¬×êÑÐÈËÔ±ÒÉ»óÕâÊǹ¥»÷ÕßΪ²âÊÔ¼ì²âÂʶø×Ô¼ºÉÏ´«µÄÑù±¾¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-xcodespy-malware-targets-ios-devs-in-supply-chain-attack/
3.×êÑÐÈËÔ±·¢ÏÖÖ¼ÔÚÇÔÈ¡5GÓйؼ¼ÊõµÄDi¨¤nx¨´nÐж¯

×êÑÐÈËÔ±·¢ÏÖÕë¶ÔµçÐŹ«Ë¾µÄDi¨¤nx¨´nÐж¯£¬Ö¼ÔÚÇÔÈ¡5G¼¼ÊõÓйصÄÃô¸ÐÊý¾ÝºÍóÒ×»úÃÜ¡£ÔÚ²¿ÃŹ¥»÷ÖУ¬ºÚ¿Í´î½¨ÁËÒ»¸öαÔì³É»ªÎªÖ°ÒµÒ³ÃæµÄÐéÎ±ÍøÕ¾¡£×êÑÐÈËÔ±³Æ£¬Õâ´ÎÐж¯ËùʹÓõÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½£¨TTP£©ÓëAPT×éÖ¯RedDeltaºÍÒ°Mustang PandaµÄÐж¯ÀàËÆ¡£McAfee ATRÍŶӰµÊ¾×î³õµÄϰȾý½éÉв»ÆëÈ«Ã÷ÏÔ£¬µ«Æä´§Ä¦ºÚ¿Í¿ÉÄÜʹÓô¹µöÍøÕ¾À´·Ö·¢¶ñÒâÈí¼þ£¬²¢ÔÚ¹¥»÷µÄµÚ¶þ½×¶ÎÀûÓûùÓÚFlashµÄ¹¤¼þ¶ñÒâÈí¼þÔÚÊܺ¦ÕßµÄϵͳÉÏÖ´ÐÐ.NET¸ºÔØ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/115693/apt/chinese-hackers-5g.html
4.ŦԼÖݶà¸öÏØÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Êý¾Ý»òÒÑй¶

ŦԼÖݵݶû°ÍÄá¡¢ÈøÀÍмӺÍÂ×˹ÀÕµÈÏØÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Êý¾Ý»òÒÑй¶¡£°Â¶û°ÍÄáÏØ¾¯³¤°ì¹«ÊÒ°µÊ¾¹¥»÷²úÉúÔÚ±¾ÖܶþÍíÉÏ9µã30·Ö×óÓÒ£¬ÌØÀïÏØ¹«¹²°²È«ÍøÂçϰȾÁËÀÕË÷Èí¼þ£¬Ó°ÏìÁ˶à¸öÏØ³Ç¡£¾Ý±¨Â·£¬Computer Aidedµ÷¶È£¨CAD£©·þÎñÊܵ½ÁËÓ°Ï죬ÆäÔÚͨ¹ý±¸·Ý½øÐгÁ½¨¡£¸ÃÏØ¹ÙÔ±°µÊ¾£¬Ä¿Ç°±¸ÓÃϵͳÈÔÕý³£ÔËÐв¢ÇÒ¿ÉÒÔΪÌṩ911·þÎñ£¬µ«ÊDz¿ÃÅÊý¾Ý¿ÉÄÜÒѾй¶¡£
ÔÎÄÁ´½Ó£º
https://www.news10.com/news/tri-county-sheriff-dispatch-hit-with-ransomware-attack/
5.ÈÕ¾ÖйúÏã¸Û·Ö¹«Ë¾³ÆÆäÔâµ½¹¥»÷£¬Óû§ÐÅÏ¢¿ÉÄÜй¶

ÈÕ¾(Nikkei)±¾ÖÜÈý°µÊ¾ÆäÖйúÏã¸Û·Ö¹«Ë¾Ôâµ½¹¥»÷£¬Óû§ÐÅÏ¢¿ÉÄÜй¶¡£Õâ´ÎÊÂÎñʼÓÚ2020Äê10Ô£¬¸Ã·Ö¹«Ë¾µÄ²¿Ãŵç×ÓÓʼþÕË»§Ô⵽δ¾ÊÚȨµÄ½Ó¼û¡£ÈÕ¾¹ú¼Ê°æ¡¢ÍøÂç°æºÍÈÕ¾ÑÇÖÞ°æ¡¢ÈÕ¾ÖйúµÄº£±í¶©»§µÄÓ×ÎÒÐÅÏ¢¿ÉÄÜÒѾй¶£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¹«Ë¾Ãû³Æ¡¢µØÖ·ºÍµç»°ºÅÂ룬ÒÔ¼°²¿Ãſͻ§µÄÐÅÓþ¿¨ÐÅÏ¢¡£Ä¿Ç°£¬ÈÕ¾Öйú¹«Ë¾Òѽ«´ËÊÂÎñ»ã±¨¸øÏã¸ÛµÄÓ×ÎÒÐÅÏ¢±£»¤µ±¾Ö¡£
ÔÎÄÁ´½Ó£º
https://asia.nikkei.com/Business/Companies/Nikkei-s-Hong-Kong-affiliate-hit-by-unauthorized-access
6.Unit42°ä²¼2021ÄêÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨

Unit42°ä²¼ÁË2021ÄêÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨£¬Ö¼ÔÚÆÀ¹ÀÀÕË÷Èí¼þ¹¥»÷µÄÁìÓò²¢Ìṩ¿É½µµÍ·çÏյIJÙ×÷²½Öè¡£»ã±¨Ö¸³ö£¬¾ùÔÈÊê½ð´Ó2019ÄêµÄ115123ÃÀÔªÔö³¤µ½2020ÄêµÄ312493ÃÀÔª£¬×î¸ßÊê½ð´Ó1500ÍòÃÀÔªÔö³¤µ½3000ÍòÃÀÔª£»ºÚ¿ÍÖØÒªÕë¶ÔÒ½ÁƱ£½¡²¿ÃÅ£»Ë«³ÁÀÕË÷µÄÇé¿öÓÐËùÔö³¤£¬³¬¹ý16ÖÖ·ÖÆçµÄÀÕË÷Èí¼þ±äÖÖ¶¼ÔÚʹÓÃÕâÖÖ²½Ö裬ÆäÖÐNetwalkerÕ¼±È×î´ó£¬Ð¹Â¶ÁËÒ»°Ù¶àÃûÊܺ¦ÕßµÄÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/ransomware-threat-assessments/


¾©¹«Íø°²±¸11010802024551ºÅ