µÂ¹úÊÖ»ú³§ÉÌGigasetÔâµ½¹©Ó¦Á´¹¥»÷£¬¸üзþÎñÆ÷±»½Ù³Ö£»Äþ¾²ÍŶÓÅû¶Õë¶ÔFortinet VPNµÄÐÂÀÕË÷Èí¼þCring
Ðû²¼Ê±¼ä 2021-04-091.µÂ¹úÊÖ»ú³§ÉÌGigasetÔâµ½¹©Ó¦Á´¹¥»÷£¬¸üзþÎñÆ÷±»½Ù³Ö
µÂ¹úÊÖ»úÖÆÔìÉÌGigasetÔâµ½¹©Ó¦Á´¹¥»÷£¬ÖÁÉÙÒ»¸ö¸üзþÎñÆ÷±»½Ù³ÖÓÃÀ´·Ö·¢¶ñÒâÈí¼þ¡£Gigaset AGµÄǰÉíΪÎ÷ÃÅ×Ó¼ÒÍ¥ºÍ°ì¹«ÊÒͨѶÉ豸¹«Ë¾£¬ÖÆÔìDECTµç»°£¬ÔÚ2018ÄêµÄÊÕÈëΪ2.8ÒÚÅ·Ôª¡£´Ë´Î¹¥»÷Õë¶ÔµÄÊÇGigasetÆìÏÂAndroidϵͳÖÇÄÜÊÖ»ú£¬·¢ÉúÔÚ3ÔÂ27ÈÕ×óÓÒ£¬Óû§·¢ÏÖÃûΪeasenfµÄδ֪ӦÓÃÔÚ±»É¾³ýºó±ã»á×Ô¶¯ÖØÐ°²×°¡£¾ÝϤ£¬easynfÊÇͨ¹ýÉ豸µÄϵͳ¸üÐÂÓ¦Óð²×°µÄ£¬´ËÍ⻹·¢ÏÖÁËÆäËû¶ñÒâÓ¦Ó㬰üÂÞgem¡¢smartºÍxiaoanµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2021/04/07/gigaset_supply_chain_malware_android_phones/
2.LazarusÍÅ»ïÀûÓÃжñÒâÈí¼þVyveva¹¥»÷ÄϷǵĻõÔ˹«Ë¾
³¯ÏʺڿÍ×éÖ¯LazarusʹÓÃÁËÐÂÐͶñÒâÈí¼þVyveva£¬¶ÔÄÏ·ÇÒ»¼Ò»õÔËÎïÁ÷¹«Ë¾Ìᳫ¶¨Ïò¹¥»÷¡£ESET·¢ÏÖ£¬Lazarus×î³õÊÇÔÚ2020Äê6ÔµĹ¥»÷ÖÐʹÓÃVyveva£¬µ«ÔÚ2018Äê12ÔÂ֮ǰµÄ¹¥»÷ÖоÍÒ»Ö±ÔÚ²¿ÊðËü¡£Vyveva¾ßÓкóÃŹ¦Ð§£¬¿ÉÖ´ÐÐÈÎÒâ¶ñÒâ´úÂë²¢Ö§³Öʱ¼ä´ÁÃüÁî¡£Ñо¿ÈËÔ±·¢ÏÖVyveva½öѬȾÁËÁ½Ì¨ÊôÓÚͬһ¼Ò»õÔ˹«Ë¾µÄ·þÎñÆ÷£¬¶øÇÒÊÇÊ×´ÎÔÚÒ°Íâ±»ÀûÓã¬Òò´ËÍÆ²âÆä¿ÉÄܻᱻÓÃÓÚÆäËûÓÐÕë¶ÔÐԵļäµý»î¶¯¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/north-korean-hackers-use-new-vyveva-malware-to-attack-freighters/
3.Äþ¾²ÍŶÓÅû¶Õë¶ÔFortinet VPNµÄÐÂÀÕË÷Èí¼þCring
ÈðÊ¿µçÐŵÄCSIRTÍŶÓÅû¶ÁËÕë¶ÔFortinet VPNµÄÐÂÀÕË÷Èí¼þCring£¨Ò²³ÆÎªCrypt3r¡¢Vjiszy1lo¡¢GhostºÍPhantom£©¡£¸Ã¶ñÒâÈí¼þÀûÓÃÁËFortiOSµÄSSL VPNÃÅ»§ÍøÕ¾µÄ·¾¶±éÀú©¶´£¨CVE-2018-13379£©£¬Õë¶ÔÅ·ÖÞ¸÷¹úµÄ¹¤Òµ¹«Ë¾¡£¹¥»÷ÕßÔÚ»ñµÃ³õʼ·ÃÎÊȨÏÞºó»áÏÂÔØ¶¨ÖƵÄMimikatzºÍCobaltStrike£¬²¢Í¨¹ýʹÓúϷ¨µÄWindows CertUtilÖ¤Êé¹ÜÀíÆ÷ÈÆ¹ýÄþ¾²Èí¼þ£¬À´ÏÂÔØ²¢°²×°ÀÕË÷Èí¼þ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/116480/cyber-crime/cring-ransomware-fortinet-vpn-flaw.html
4.VISA·¢ÏÖÀûÓÃWeb ShellÇÔÈ¡ÐÅÓÿ¨ÐÅÏ¢µÄÐÂÇ÷ÊÆ
È«ÇòÖ§¸¶´¦ÖÃÉÌVISA³Æ£¬ÆäÖ§¸¶ÆÛÕ©ÖжÏ(PFD)ÔÚ2020Äê·¢ÏÖÁËÒ»ÖÖÐÂÇ÷ÊÆ£¬¼´Ô½À´Ô½¶àµÄeSkimming¹¥»÷ʹÓÃÁËweb shellÀ´´´½¨C2¡£VISAÊӲ췢ÏÖ£¬×ÔÈ¥ÄêÒÔÀ´£¬°²×°ÔÚ±»ÈëÇֵķþÎñÆ÷ÉϵÄWeb ShellÊýÁ¿¼¸ºõÔö¼ÓÁËÒ»±¶£¬´Ó2020Äê8Ôµ½2021Äê1Ô£¬Æ½¾ùÿÔ¿ɼì²âµ½14Íò¸ö´ËÀ๤¾ß¡£´ËÍ⣬VISA PFD³ÆÔÚ2020ÄêÖÁÉÙÓÐ45´ÎeSkimming¹¥»÷ʹÓÃÁËweb shell£¬¹¥»÷ÕßÔÚÈëÇÖÔÚÏßÉ̵êµÄ·þÎñÆ÷ºó°²×°ºóÃŲ¢½¨Á¢C2·þÎñÆ÷£¬ÒÔÇÔÈ¡ÐÅÓÿ¨ÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/visa-hackers-increasingly-using-web-shells-to-steal-credit-cards/
5.Group-IB·¢ÏÖÀûÓÃTelegramºÍGoogle FormsµÄµöÓã»î¶¯
Group-IBµÄÑо¿ÈËÔ±ÔÚ·ÖÎöÍøÂçµöÓ㹤¾ß°üʱ·¢ÏÖ£¬Ô½À´Ô½¶àµÄ¹¤¾ß¿ªÊ¼Ê¹ÓÃGoogle FormsºÍTelegramµÈºÏ·¨·þÎñÀ´ÊÕ¼¯Óû§Êý¾Ý¡£´ËÀ෽ʽ±»ÊÓΪ»ñÈ¡Êý¾ÝµÄÌæ´úÒªÁ죬ռ±ÈԼΪ6%£¬¶øÇÒÕâÒ»±ÈÀýÔÚ¶ÌÆÚÄÚ¿ÉÄÜ»áÔö¼Ó¡£´ËÍ⣬Group-IBÔÚÈ¥Äê·¢ÏÖÁËÕë¶Ô260¶à¸öÆ·ÅÆµÄÍøÂçµöÓ㹤¾ß°ü£¬Ö÷ÒªÕë¶ÔMicrosoft¡¢PayPal¡¢GoogleºÍYahooµÈÆ·ÅÆ¡£¹¥»÷ÕßµÄÖ÷ҪĿ±êÊÇÔÚÏß·þÎñ£¨30.7£¥£©¡¢Æä´ÎÊǵç×ÓÓʼþ·þÎñ£¨22.8£¥£©ºÍ½ðÈÚ»ú¹¹£¨20£¥£©¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/116459/cyber-crime/telegram-bots-google-forms-phishing.html
6.¶ñÒâÈí¼þFlixOnlineαװ³ÉNetflixÓ¦ÓÃÕë¶ÔWhatsApp
Check Point Research£¨CPR£©·¢ÏÖÃûΪFlixOnlineµÄAndroid¶ñÒâÈí¼þαװ³ÉNetflixµÄÓ¦ÓÃÕë¶ÔWhatsApp¡£Ä¿Ç°£¬GoogleÒѽ«¸Ã¶ñÒâÈí¼þ´ÓPlayÉ̵êÖÐɾ³ý¡£Ò»µ©°²×°FlixOnlineºó£¬¸ÃÓ¦ÓþͻáÇëÇóÁýÕÖ¡¢µç³ØÓÅ»¯ºöÂÔºÍ֪ͨȨÏÞ£¬Ö¼ÔÚÉú³ÉÓÃÓÚ͵ȡƾ¾ÝµÄÁýÕÖ´°¿Ú¡¢×èÖ¹É豸ÒòÓÅ»¯ÄܺĶø¹Ø±ÕÆä½ø³Ì¡¢·ÃÎÊÓ¦ÓÃ֪ͨ²¢¹ÜÀíºÍ»Ø¸´ÏûÏ¢¡£Ö®ºó¿ªÊ¼¼àÌýWhatsApp֪ͨ²¢×Ô¶¯»Ø¸´´«ÈëµÄÏûÏ¢£¬À´½«Êܺ¦ÕßÖØ¶¨Ïòµ½Î±ÔìµÄNetflixÍøÕ¾£¬ÇÔÈ¡Æäƾ¾ÝºÍÐÅÓÿ¨ÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/new-android-malware-poses-as-netflix-to-hijack-whatsapp-sessions/