µçÐŹ«Ë¾AT£¦T´óÁ¿ESBCÉ豸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷

Ðû²¼Ê±¼ä 2021-12-03

µçÐŹ«Ë¾AT£¦T´óÁ¿ESBCÉ豸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷


µçÐŹ«Ë¾AT£¦T´óÁ¿ESBCÉ豸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷.png


Ñо¿ÍŶÓÔÚ11ÔÂ30ÈÕ¹ûȻн©Ê¬ÍøÂçEwDoorµÄ¹¥»÷»î¶¯¡£´Ë´Î»î¶¯Ö÷ÒªÕë¶ÔµçÐŹ«Ë¾AT£¦T EdgeMarcÆóÒµ»á»°½çÏÞ¿ØÖÆÆ÷(ESBC)±ßÔµÉ豸£¬ÀûÓÃÁË4ÄêǰµÄÃüÁî×¢Èë©¶´£¨CVE-2017-6079£©¡£ÔÚ½©Ê¬ÍøÂçÇл»µ½ÆäËüC2֮ǰµÄ¶Ì¶Ì3СʱÄÚ£¬¹²¼ì²âµ½Ô¼5700̨É豸±»Ñ¬È¾¡£Ä¿Ç°£¬Ñо¿ÈËÔ±ÒÑÈ·ÈÏEwDoorµÄ3¸ö±äÌ壬¿É·ÖΪDDoS¹¥»÷ºÍBackdoorÁ½´óÀ࣬²¢ÍƲâÆäÖ÷ҪĿµÄÊÇDDoS¹¥»÷£¬ÒÔ¼°ÊÕ¼¯Í¨»°¼Ç¼µÈÃô¸ÐÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125143/cyber-crime/ewdoor-botnet.html


ÀÕË÷Èí¼þSabbathÃé×¼ÃÀ¹úºÍ¼ÓÄôóµÄÒªº¦»ù´¡ÉèÊ©


ÀÕË÷Èí¼þSabbathÃé×¼ÃÀ¹úºÍ¼ÓÄôóµÄÒªº¦»ù´¡ÉèÊ©.png


11ÔÂ29ÈÕ£¬MandiantÍŶӳÆÀÕË÷Èí¼þSabbath£¨ÓÖÃûUNC2190£©×Ô6Ô·ݿªÊ¼Ò»Ö±ÔÚÕë¶ÔÃÀ¹úºÍ¼ÓÄôó¡£UNC2190ÔÚ֮ǰÃûΪArcaneºÍEruption£¬²¢ÔÚ2020Äê7Ô·ַ¢ÀÕË÷Èí¼þROLLCOAST¡£Sabbath£¨54BB47h£©ÓÚ10ÔÂ21ÈÕÕýʽÔËÓª£¬Ö÷ҪĿ±êÊÇÒªº¦»ù´¡ÉèÊ©£¬°üÂÞÃÀ¹úºÍ¼ÓÄôóµÄ½ÌÓý¡¢ÎÀÉúºÍ×ÔÈ»×ÊÔ´ÐÐÒµ¡£ÓëÆäËûÀÕË÷ÔËÓªÍÅ»ï²îÒ죬Sabbath»¹ÎªÆäÁ¥Êô×éÖ¯ÌṩÁËÔ¤ÏÈÅäÖúõÄCobalt Strike BEACONºóÃÅpayload¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125154/cyber-crime/sabbath-ransomware.html


Symantec³ÆYanluowangÓëºÚ¿ÍÍÅ»ïThieflockÓйØ


Symantec³ÆYanluowangÓëºÚ¿ÍÍÅ»ïThieflockÓйØ.png


SymantecÔÚ11ÔÂ30ÈÕÐû²¼Á˹ØÓÚÀÕË÷Èí¼þYanluowang½üÆÚ»î¶¯µÄ·ÖÎö³ÂËß¡£´Ë´Î»î¶¯¿ªÊ¼ÓÚ8Ô·Ý£¬ÀûÓÃÁ˶ñÒâÈí¼þBazarLoader£¬Ö÷ÒªÕë¶ÔÃÀ¹úµÄ½ðÈÚÐÐÒµ£¬µ«Ò²Õë¶ÔÖÆÔì¡¢IT·þÎñ¡¢×ÉѯºÍ¹¤³ÌµÈÐÐÒµµÄ¹«Ë¾¡£Ñо¿ÍŶӷÖÎö¹¥»÷ÕßʹÓõŤ¾ß¡¢¼ÆÄ±ºÍ·¨Ê½(TTP)£¬·¢ÏÖÆäÖÐÐí¶à¶¼ÓëThieflockµÄÀÕË÷¹¥»÷»î¶¯ÓйØ£¬Õâ±íÃ÷ËûÃÇ¿ÉÄÜÊôÓÚThieflockµÄÒ»¸öÁ¥Êô×éÖ¯¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/yanluowang-ransomware-thieflock-threat-actor/176640/


MozillaÐÞ¸´NSSÖеÄÄÚ´æËð»µÂ©¶´CVE-2021-43527


MozillaÐÞ¸´NSSÖеÄÄÚ´æËð»µÂ©¶´CVE-2021-43527.png


MozillaÓÚ12ÔÂ1ÈÕÐû²¼¸üУ¬ÐÞ¸´ÁËÆä¿çÆ½Ì¨ÍøÂçÄþ¾²·þÎñ(NSS)ÖеÄÄÚ´æËð»µÂ©¶´£¨CVE-2021-43527£©¡£Google project-zeroÑо¿ÈËÔ±ÔÚ10ÔÂ24ÈÕÅû¶¸Ã©¶´µÄϸ½Ú£¬ÔÚʹÓÃNSSµÄÓʼþ¿Í»§¶ËºÍPDF¼ì²ìÆ÷´¦ÖÃder±àÂëµÄDSA»òRSA-PSSÇ©Ãûʱ£¬¿ÉÄܻᵼÖ»ùÓڶѵĻº³åÇøÒç³ö¡£Ñо¿ÈËÔ±³Æ£¬ÀÖ³ÉÀûÓøÃ©¶´¿Éµ¼Ö·¨Ê½Íß½â´úÂëÖ´ÐУ¬ÒÔ¼°ÈƹýÄþ¾²¼ì²âÈí¼þ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/mozilla-fixes-critical-bug-in-cross-platform-cryptography-library/


·ÒÀ¼NCSC-FIÐû²¼´ó¹æÄ£·Ö·¢FlubotµÄ»î¶¯µÄ¾¯±¨


·ÒÀ¼NCSC-FIÐû²¼´ó¹æÄ£·Ö·¢FlubotµÄ»î¶¯µÄ¾¯±¨.png


11ÔÂ30ÈÕ£¬·ÒÀ¼¹ú¼ÒÍøÂçÄþ¾²ÖÐÐÄ(NCSC-FI)Ðû²¼ÖØÒª¾¯±¨£¬¾¯¸æÕë¶Ô¸Ã¹úAndroidÓû§´ó¹æÄ£·Ö·¢FlubotµÄ»î¶¯¡£ÕâÊǽñÄêFlubotÔÚ·ÒÀ¼ÌᳫµÄµÚ¶þ´Î´ó¹æÄ£»î¶¯£¬´Ëǰ´Ó2021Äê6Ô³õÖÁ8ÔÂÖÐÑ®£¬FlubotÿÌìÏòÊýǧ¸ö·ÒÀ¼¹«Ãñ·¢ËÍÀ¬»ø¶ÌÐÅ¡£Ð»ÒÀÈ»ÒÔÒÆ¶¯ÔËÓªÉ̵ÄÓïÒôÓʼþΪÖ÷Ì⣬ÓÕʹAndroidÓû§ÏÂÔØÒ»¸öAPKÀ´°²×°ÒøÐжñÒâÈí¼þFlubot£¬¶øiPhoneÓû§Ôò»á±»Öض¨Ïòµ½Ö¼ÔÚÇÔÈ¡ÐÅÏ¢µÄµöÓãÍøÕ¾¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/finland-warns-of-flubot-malware-heavily-targeting-android-users/


KasperskyÐû²¼2021ÄêAPT¹¥»÷»î¶¯µÄ»Ø¹Ë³ÂËß


KasperskyÐû²¼2021ÄêAPT¹¥»÷»î¶¯µÄ»Ø¹Ë³ÂËß.png


KasperskyÓÚ11ÔÂ30ÈÕÐû²¼2021ÄêAPT¹¥»÷»î¶¯µÄ»Ø¹Ë³ÂËß¡£Ñо¿¸ú×ÙÁË900¶à¸öAPT¹¥»÷»î¶¯£¬Ö¼ÔÚ·ÖÎö¹ýÈ¥12¸öÔÂÖеÄÇ÷ÊÆºÍÉú³¤¡£³ÂËßÖ¸³ö£¬È«ÇòÁè¼Ý30000¸ö¼ÇÕß¡¢ÂÉʦµÈÈËÔ±³ÉΪPegasusµÄÄ¿±ê£»·¢ÉúÁËÐí¶à±¸ÊÜÖõÄ¿µÄ¹©Ó¦Á´¹¥»÷£¬ÈçÓ°ÏìÁË18000¶à¸öSolarWinds¿Í»§µÄ¹©Ó¦Á´¹¥»÷£»ÀûÓÃExchangeºÍChromeµÈÈí¼þÖеÄÁãÈÕ©¶´£»ÀûÓù̼þÖеÄ©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/apt-annual-review-2021/105127/