µçÐŹ«Ë¾AT£¦T´óÁ¿ESBCÉ豸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷

°ä²¼¹¦·ò 2021-12-03

µçÐŹ«Ë¾AT£¦T´óÁ¿ESBCÉ豸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷


µçÐŹ«Ë¾AT£¦T´óÁ¿ESBCÉ豸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷.png


×êÑÐÍŶÓÔÚ11ÔÂ30ÈÕ¹«¿ªÐ½©Ê¬ÍøÂçEwDoorµÄ¹¥»÷»î¶¯ ¡£Õâ´Î»î¶¯ÖØÒªÕë¶ÔµçÐŹ«Ë¾AT£¦T EdgeMarcÆóÒµ»á»°Ììǵ½ÚÔìÆ÷(ESBC)±ßÔµÉ豸£¬ÀûÓÃÁË4ÄêǰµÄºÅÁî×¢Èë·ì϶£¨CVE-2017-6079£© ¡£ÔÚ½©Ê¬ÍøÂçÇл»µ½ÆäËüC2֮ǰµÄ¶Ì¶Ì3Ó×ʱÄÚ£¬¹²¼ì²âµ½Ô¼5700̨É豸±»Ï°È¾ ¡£Ä¿Ç°£¬×êÑÐÈËÔ±ÒÑÈ·ÈÏEwDoorµÄ3¸ö±äÌ壬¿É·ÖΪDDoS¹¥»÷ºÍBackdoorÁ½´óÀ࣬²¢´§Ä¦ÆäÖØÒªÖ÷ÕÅÊÇDDoS¹¥»÷£¬ÒÔ¼°ÍøÂçͨ»°¼Í¼µÈÃô¸ÐÐÅÏ¢ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125143/cyber-crime/ewdoor-botnet.html


ÀÕË÷Èí¼þSabbath¶Ô×¼ÃÀ¹úºÍ¼ÓÄôóµÄ¹Ø¼ü»ù´¡ÉèÊ©


ÀÕË÷Èí¼þSabbath¶Ô×¼ÃÀ¹úºÍ¼ÓÄôóµÄ¹Ø¼ü»ù´¡ÉèÊ©.png


11ÔÂ29ÈÕ£¬MandiantÍŶӳÆÀÕË÷Èí¼þSabbath£¨±ðÃûUNC2190£©×Ô6ÔÂ·ÝÆðÍ·Ò»ÏòÔÚÕë¶ÔÃÀ¹úºÍ¼ÓÄôó ¡£UNC2190ÔÚ֮ǰÃûΪArcaneºÍEruption£¬²¢ÔÚ2020Äê7Ô·ַ¢ÀÕË÷Èí¼þROLLCOAST ¡£Sabbath£¨54BB47h£©ÓÚ10ÔÂ21ÈÕÕýʽÔËÓª£¬ÖØÒªÖ¸±êÊǹؼü»ù´¡ÉèÊ©£¬Ô̺¬ÃÀ¹úºÍ¼ÓÄôóµÄ½ÌÓý¡¢ÎÀÉúºÍÌìÈ»×ÊÔ´ÐÐÒµ ¡£ÓëÆäËûÀÕË÷ÔËÓªÍÅ»ï·ÖÆç£¬Sabbath»¹ÎªÆä´ÓÊô×éÖ¯ÌṩÁËÔ¤ÏÈÅäÖúõÄCobalt Strike BEACONºóÃÅpayload ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125154/cyber-crime/sabbath-ransomware.html


Symantec³ÆYanluowangÓëºÚ¿ÍÍÅ»ïThieflockÓйØ


Symantec³ÆYanluowangÓëºÚ¿ÍÍÅ»ïThieflockÓйØ.png


SymantecÔÚ11ÔÂ30ÈÕ°ä²¼Á˹ØÓÚÀÕË÷Èí¼þYanluowang½üÆÚ»î¶¯µÄ·ÖÎö»ã±¨ ¡£Õâ´Î»î¶¯ÆðÍ·ÓÚ8Ô·Ý£¬ÀûÓÃÁ˶ñÒâÈí¼þBazarLoader£¬ÖØÒªÕë¶ÔÃÀ¹úµÄ½ðÈÚÐÐÒµ£¬µ«Ò²Õë¶ÔÔì×÷¡¢IT·þÎñ¡¢Õ÷ѯºÍ¹¤³ÌµÈÐÐÒµµÄ¹«Ë¾ ¡£×êÑÐÍŶӷÖÎö¹¥»÷ÕßʹÓõŤ¾ß¡¢Õ½ÊõºÍ·¨Ê½(TTP)£¬·¢ÏÔìäÖкܶ඼ÓëThieflockµÄÀÕË÷¹¥»÷»î¶¯ÓйØ£¬ÕâÅú×¢ËûÃÇ¿ÉÄÜÊôÓÚThieflockµÄÒ»¸ö´ÓÊô×éÖ¯ ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/yanluowang-ransomware-thieflock-threat-actor/176640/


Mozilla½¨¸´NSSÖеÄÄÚ´æ°Ü»µ·ì϶CVE-2021-43527


Mozilla½¨¸´NSSÖеÄÄÚ´æ°Ü»µ·ì϶CVE-2021-43527.png


MozillaÓÚ12ÔÂ1ÈÕ°ä²¼¸üУ¬½¨¸´ÁËÆä¿çÆ½Ì¨ÍøÂ簲ȫ·þÎñ(NSS)ÖеÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-43527£© ¡£Google project-zero×êÑÐÈËÔ±ÔÚ10ÔÂ24ÈÕÅû¶¸Ã·ì϶µÄϸ½Ú£¬ÔÚʹÓÃNSSµÄÓʼþ¿Í»§¶ËºÍPDF²é¿´Æ÷´¦ÖÃder±àÂëµÄDSA»òRSA-PSSÊðÃûʱ£¬¿ÉÄܻᵼÖ»ùÓڶѵĻº³åÇøÒç³ö ¡£×êÑÐÈËÔ±³Æ£¬³É¹¦ÀûÓø÷ì϶¿Éµ¼Ö·¨Ê½±ÀÀ£´úÂëÖ´ÐУ¬ÒÔ¼°Èƹý°²È«¼ì²âÈí¼þ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/mozilla-fixes-critical-bug-in-cross-platform-cryptography-library/


·ÒÀ¼NCSC-FI°ä²¼´ó¹æÄ£·Ö·¢FlubotµÄ»î¶¯µÄ¾¯±¨


·ÒÀ¼NCSC-FI°ä²¼´ó¹æÄ£·Ö·¢FlubotµÄ»î¶¯µÄ¾¯±¨.png


11ÔÂ30ÈÕ£¬·ÒÀ¼¹ú¶ÈÍøÂ簲ȫÖÐÐÄ(NCSC-FI)°ä²¼³ÁÒª¾¯±¨£¬ÖÒ¸æÕë¶Ô¸Ã¹úAndroidÓû§´ó¹æÄ£·Ö·¢FlubotµÄ»î¶¯ ¡£ÕâÊǽñÄêFlubotÔÚ·ÒÀ¼ÌáÒéµÄµÚ¶þ´Î´ó¹æÄ£»î¶¯£¬´Ëǰ´Ó2021Äê6Ô³õÖÁ8ÔÂÖÐÑ®£¬FlubotÿÌìÏòÊýǧ¸ö·ÒÀ¼¹«Ãñ·¢ËÍÀ¬»ø¶ÌÐÅ ¡£Ð»ÒÀÈ»ÒÔÒÆ¶¯ÔËÓªÉ̵ÄÓïÒôÓʼþΪÖ÷Ì⣬ÓÕʹAndroidÓû§ÏÂÔØÒ»¸öAPKÀ´×°ÖÃÒøÐжñÒâÈí¼þFlubot£¬¶øiPhoneÓû§Ôò»á±»³Á¶¨Ïòµ½Ö¼ÔÚÇÔÊØÐÅÏ¢µÄ´¹µöÍøÕ¾ ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/finland-warns-of-flubot-malware-heavily-targeting-android-users/


Kaspersky°ä²¼2021ÄêAPT¹¥»÷»î¶¯µÄ»ØÊ׻㱨


Kaspersky°ä²¼2021ÄêAPT¹¥»÷»î¶¯µÄ»ØÊ׻㱨.png


KasperskyÓÚ11ÔÂ30ÈÕ°ä²¼2021ÄêAPT¹¥»÷»î¶¯µÄ»ØÊ׻㱨 ¡£×êÑиú×ÙÁË900¶à¸öAPT¹¥»÷»î¶¯£¬Ö¼ÔÚ·ÖÎö´Óǰ12¸öÔÂÖеÄÇ÷ÏòºÍ·¢Õ¹ ¡£»ã±¨Ö¸³ö£¬È«Çò³¬¹ý30000¸ö¼ÇÕß¡¢ÂÉʦµÈÈËÔ±³ÉΪPegasusµÄÖ¸±ê£»²úÉúÁ˺ܶ౸ÊÜÖõÖ÷ÕŹ©¸øÁ´¹¥»÷£¬ÈçÓ°ÏìÁË18000¶à¸öSolarWinds¿Í»§µÄ¹©¸øÁ´¹¥»÷£»ÀûÓÃExchangeºÍChromeµÈÈí¼þÖеÄÁãÈÕ·ì϶£»ÀûÓù̼þÖеķì϶ ¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/apt-annual-review-2021/105127/