APT×éÖ¯BlackTechÀûÓÃFlagpro¹¥»÷ÈÕ±¾µÄ¹«Ë¾

°ä²¼¹¦·ò 2021-12-30

APT×éÖ¯BlackTechÀûÓÃFlagpro¹¥»÷ÈÕ±¾µÄ¹«Ë¾


APT×éÖ¯BlackTechÀûÓÃFlagpro¹¥»÷ÈÕ±¾µÄ¹«Ë¾.png


¾ÝýÌå12ÔÂ28ÈÕ±¨Â·£¬¼äµýAPT×éÖ¯BlackTechÀûÓÃFlagpro¹¥»÷ÈÕ±¾µÄ¹«Ë¾¡£Õâ´Î¹¥»÷µÄ³õʼϰȾý½éÊǼÙ×°³ÉÀ´×ÔÖ¸±êºÏ×÷ͬ°éµÄ´¹µöÓʼþ£¬Ö®ºó¹¥»÷Õß»áÀûÓÃFlagpro½øÐÐÍøÂç¿úËÅ¡¢ÆÀ¹ÀÖ¸±ê»·¾³ÒÔ¼°ÏÂÔØ²¢Ö´Ðеڶþ½×¶Î¶ñÒâÈí¼þ¡£¾ÝNTT Security³Æ£¬Õâ´Î»î¶¯ÖÁÉÙʼÓÚ2020Äê10Ô£¬ÒÑÕë¶ÔÈÕ±¾¹«Ë¾Ò»Äê¶à£¬Éæ¼°¹ú·À¼¼Êõ¡¢Ã½ÌåºÍͨѶÐÐÒµÔÚÄڵĶà¸öÁìÓò¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-flagpro-malware-linked-to-chinese-state-backed-hackers/


Morphus Labs·¢ÏÖ¶à¸öÀûÓÃMSBuildµÄ¹¥»÷»î¶¯


Morphus Labs·¢ÏÖ¶à¸öÀûÓÃMSBuildµÄ¹¥»÷»î¶¯.png


12ÔÂ27ÈÕ£¬Morphus LabsºÍSANS ISC°ä²¼»ã±¨³Æ£¬ÔÚ´ÓǰһÖÜÖмì²âµ½2¸öÀûÓÃMicrosoft Build Engine(MSBuild)µÄ¹¥»÷»î¶¯¡£ÔÚÕâЩ»î¶¯ÖУ¬¹¥»÷Õßͨ³£ÏÈÀûÓÃÔ¶³Ì×ÀÃæºÍ̸(RDP)ÕÊ»§½Ó¼ûÖ¸±ê»·¾³£¬¶øºóÀûÓÃÔ¶³ÌWindows·þÎñ(SCM)½øÐкáÏòÒÆ¶¯£¬×îºóÀûÓÃMSBuildÖ´ÐÐCobalt Strike Beacon¡£¹¥»÷ÖÐʹÓõĶñÒâMSBuildÏîÄ¿Äܹ»±àÒëºÍÖ´ÐÐÌØ¶¨µÄC#´úÂ룬½ø¶ø½âÂëºÍÖ´ÐÐCobalt Strike¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/threat-actors-abuse-msbuild-cobalt-strike-beacon-execution


T-MobileÒòÔâµ½SIM»¥»»¹¥»÷£¬Óû§ÐÅÏ¢ÔÙ´Îй¶


T-MobileÒòÔâµ½SIM»¥»»¹¥»÷£¬Óû§ÐÅÏ¢ÔÙ´Îй¶.png


12ÔÂ29ÈÕ£¬T-Mobile½²»°ÈË֤ʵÆä²¿ÃÅÓû§Ôâµ½SIM»¥»»¹¥»÷£¬ÐÅÏ¢¿ÉÄÜÒѾ­Ð¹Â¶¡£T-Mobile³ÆÆäÍŶÓÔÚ·¢ÏÖÎÊÌâºóÂíÉϲÉȡӦ¼±´ëÊ©£¬²¢ÒÑ×Ô¶¯²ÉÈ¡¶î±íµÄ± £»¤´ëÊ©¡£µ±±»ÒªÇóÌṩÓйØÊÜÓ°ÏìÓû§ÊýÁ¿ÒÔ¼°¹¥»÷ÕߵĹ¥»÷·½Ê½Ê±£¬T-Mobile»Ø¾øÌṩ¸ü¶à¾ßÌåÐÅÏ¢¡£T-MobileÒѲúÉúÂÅ´ÎÐÅϢй¶£¬Õâ´ÎÊÂÎñÓë½ñÄê2Ô·ݵÄй¶ÊÂÎñ¼«¶ÈÀàËÆ£¬ÆäʱÒòSIM»¥»»¹¥»÷й¶400¸öÓû§µÄÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/t-mobile-says-new-data-breach-caused-by-sim-swap-attacks/


Galaxy Store´æÔÚ¶à¸öαÔì³ÉShowBoxµÄ¶ñÒâÀûÓÃ


Galaxy Store´æÔÚ¶à¸öαÔì³ÉShowBoxµÄ¶ñÒâÀûÓÃ.png


ýÌå12ÔÂ28Èճƣ¬ÈýÐǵĹٷ½AndroidÀûÓ÷¨Ê½É̵êGalaxy Store´æÔÚ¶à¸ö¶ñÒâÀûÓá£ÕâЩÀûÓüÙ×°³ÉÒÑÓÚ2018ÄêÆÆ²úµÄµÁ°æÀûÓÃShowBox£¬ÒÑÔÚ¶à¸öÓû§µÄÉ豸ÉÏ´¥·¢Google Play Protect¾¯±¨¡£×êÑÐÈËÔ±³Æ£¬ÕâЩÀûÓÃÖ®ËùÒԻᴥ·¢¾¯±¨£¬ÊÇÓÉÓÚËüÃÇÒªÇóÓµÓÐ×°ÖöñÒâÈí¼þ·çÏÕµÄȨÏÞ£¬µ±Óû§ÔÊÐíºóËüÃǾÍÄܹ»½Ó¼ûÁªÏµÈËÁбíºÍͨ»°¼Í¼¡¢Ö´ÐдúÂë¡¢»ñÈ¡¶ñÒâÈí¼þpayloadµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/riskware-android-streaming-apps-found-on-samsungs-galaxy-store/


ÃÀ¹úSLGAÔÚ×ÅÊÖµ÷²éÆäÊ¥µ®½ÚÆÚ¼äÔâµ½µÄÍøÂç¹¥»÷


ÃÀ¹úSLGAÔÚ×ÅÊÖµ÷²éÆäÊ¥µ®½ÚÆÚ¼äÔâµ½µÄÍøÂç¹¥»÷.png


¾ÝýÌå12ÔÂ28ÈÕ±¨Â·£¬ÈøË¹¿¦³¹ÎÂÊ¡¾ÆÀàºÍ²©²ÊÖÎÀí¾Ö£¨SLGA£©ÔÚ×ÅÊÖµ÷²éÆäÔâµ½µÄÍøÂç¹¥»÷¡£SLGAÊÇÃÀ¹ú²ÆÕþ²¿»Ê¹Ú¹«Ë¾ÕƹܷÖÏú¡¢½ÚÔìºÍ¼à¹Ü¾Æ¾«ÒûÁÏ¡¢´óÂéºÍ´óÎÞÊý´ò¶ÄµÄ»ú¹¹£¬Î»ÓÚ¼ÓÄôóµÄÈøË¹¿¦³¹ÎÂÊ¡¡£¹¥»÷²úÉúÔÚ12ÔÂ25ÈÕ£¬SLGA°µÊ¾£¬µ÷²éÏÔʾĿǰûÓÐÈκοͻ§¡¢Ô±¹¤»òÆäËüÊý¾Ý±»ÀÄÓã¬ÔÚʵÏÖ¶Ô¸ÃÊÂÎñµÄÆÀ¹Àºó£¬½«µ±¼´±ãÊÜÓ°ÏìµÄϵͳ³ÁÐÂÉÏÏß¡£


Ô­ÎÄÁ´½Ó£º

https://globalnews.ca/news/8477174/slga-investigating-christmas-day-cybersecurity-incident/


×êÑÐÍŶÓÅû¶EquationʹÓõÄDanderSpritzµÄ¼¼Êõ·ÖÎö


×êÑÐÍŶÓÅû¶EquationʹÓõÄDanderSpritzµÄ¼¼Êõ·ÖÎö.png


12ÔÂ27ÈÕ£¬Check PointÅû¶Equation GroupʹÓõÄȫְÄܶñÒâÈí¼þ¿ò¼ÜDanderSpritzµÄ¼¼Êõ·ÖÎö¡£DanderSpritzÓÚ2017Äê4ÔÂ14ÈÕ±»Shadow Brokers¹«¿ª£¬Ô̺¬ÓÃÓÚÓÆ¾ÃÐÔ¡¢¿úËÅ¡¢ºáÏòÒÆ¶¯¡¢Èƹýɱ¶¾ÒýÇæµÈ»î¶¯µÄ¶àÖÖ¹¤¾ß¡£¸Ã×êÑгÁµã·ÖÎöÆäÖеÄÒ»¸ö×é¼þDoubleFeature£¬ËüÓÃÀ´ÌìÉú¿É×°ÖÃÔÚÖ¸±êÉ豸ÖеŤ¾ßÀàÐ͵ÄÈÕÖ¾ºÍ»ã±¨£¬²¢»áÍøÂç´óÁ¿¸÷ÖÖÀàÐ͵ÄÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://research.checkpoint.com/2021/a-deep-dive-into-doublefeature-equation-groups-post-exploitation-dashboard/