AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨-2020ÄêµÚ2ÖÜ£¨2020.1.06-2020.1.12£©
2020-01-12
Ò»¡¢ °µÍøÇ鱨
|
·ÖÀà |
·¢Ã÷ʱ¼ä |
°µÍøÉúÒâÎÊÌâ |
|
½ðÈÚ |
2020-01-04 19:30 |
ij²Æ¾ÍøÕ¾×¢²áÓû§70WÌõ¹ÉÃñ½ðÈÚͶ×ÊÀí²ÆÊý¾Ý |
|
»¥ÁªÍø |
2020-01-05 23:28 |
ijÔÚÏß¹ºÎïÍø¹ºÊý¾Ý22W |
|
»¥ÁªÍø |
2020-01-07 10:50 |
Ä³Íø´ûƽ̨ÏÖ½ð´ûÊý¾Ý10W |
|
½ðÈÚ |
2020-01-09 23:29 |
֤ȯ¹ÉÃñÊý¾Ý13Íò_´ø×ʽðÁ¿¹ÉƱº¬Î¢ÐÅ |
|
»¥ÁªÍø |
2020-01-11 22:20 |
ijµçÉÌÆ½Ì¨Ä¸Ó¤Íø¹ºÊý¾Ý20WÌõ |
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. AG¹«Ë¾¿Æ¼¼2019вúÆ·
¡¾¸ÅÊö¡¿
2019ÄêÒѾ»ÉϾäºÅ£¬ÎÒÃÇÀ´ÖðÒ»ÅÌ»õ2019ÄêAG¹«Ë¾¿Æ¼¼ÍƳöÁËÄÄЩвúÆ·¡£
¡¾²Î¿¼Á´½Ó¡¿
https://mp.weixin.qq.com/s/rKKjERJ7AbBs2PYmYopMzA
2. Google PlayÖжñÒâ³ÌÐòʹÓÃCVE-2019-2215Îó²î
¡¾¸ÅÊö¡¿
½üÆÚÔÚGoogle PlayÊÐËÁÖз¢Ã÷ÁËÈý¸ö¶ñÒâÓ¦ÓóÌÐò£¬ËüÃÇ¿ÉÒÔÐͬÊÂÇéÒÔÆÆËðÊܺ¦ÕßµÄ×°±¸²¢ÍøÂçÓû§ÐÅÏ¢£¬ÆäÖÐÒ»¸öÃûΪCameroµÄÓ¦ÓÃʹÓÃÁËCVE-2019-2215Îó²î£¬¸ÃÎó²î±£´æÓÚBinder£¨AndroidÖÐÖ÷ÒªµÄÀú³Ì¼äͨѶϵͳ£©ÖУ¬ÕâÈý¸ö¶ñÒâ³ÌÐòÓëSideWinderÍþв×éÖ¯Óйء£SideWinderÊÇÒ»¸ö´Ó2012ÄêÒÔÀ´Ò»Ö±»îÔ¾µÄÍþв×éÖ¯£¬ÒÉËÆÀ´×ÔÓ¡¶È£¬Ö÷ÒªÕë¶Ô°Í»ù˹̹¼°Öܱ߹ú¼Ò¾ÙÐж¨Ïò¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.trendmicro.com/trendlabs-security-intelligence/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group/
3. Operation AppleJeus-LazarusÍþв×éÖ¯¹¥»÷¼ÓÃÜÇ®±ÒÓªÒµ
¡¾¸ÅÊö¡¿Operation AppleJeus¹¥»÷Ô˶¯´Ó2018ÄêÒ»Á¬ÖÁ½ñ£¬Ö÷ÒªÕë¶Ô¼ÓÃÜÇ®±ÒÓªÒµ£¬ÊÜÓ°ÏìµÄ¹ú¼Ò°üÀ¨Ó¢¹ú¡¢²¨À¼¡¢¶íÂÞ˹ºÍÖйú£¬¹¥»÷Ô˶¯ÓÉLazarusÍþв×éÖ¯Ìᳫ£¬¸Ã×éÖ¯£¨ÓÖÃûHIDDEN COBRA¡¢Guardians of Peace¡¢ZINCºÍNICKEL ACADEMY£©ÊÇÒ»¸ö¹éÊôÓÚ³¯ÏÊÕþ¸®Íþв×éÖ¯£¬ÖÁÉÙ´Ó2009ÄêÒÔÀ´Ò»Ö±»îÔ¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securelist.com/operation-applejeus-sequel/95596/
4. SAIGON-UrsnifÒøÐÐľÂíбäÖÖ
¡¾¸ÅÊö¡¿
½üÆÚ·¢Ã÷UrsnifÒøÐÐľÂíбäÖÖSAIGON£¬¸ÃľÂíÔÚÊÜѬȾµÄÅÌËã»úÉÏÒÔ´æ´¢ÔÚ×¢²á±íÏîÖеÄBase64±àÂëµÄshellcode blobµÄÐÎʽ·ºÆð£¬¸Ã×¢²á±íÏîÊÇʹÓÃPowerShellͨ¹ýÍýÏëʹÃüÆô¶¯µÄ¡£Ursnif£¨ÓÖÃûGozi / Gozi-ISFB£©ÊÇÈÔÔÚ»îÔ¾µÄ×î¹ÅÀϵÄÒøÐжñÒâÈí¼þ¼Ò×åÖ®Ò»¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.fireeye.com/blog/threat-research/2020/01/saigon-mysterious-ursnif-fork.html
5. ÒÁÀÊÍþв×é֯ʹÓÃÊý¾Ý²Á³ý¹¤¾ßDustman¹¥»÷ʯÓ͹«Ë¾
¡¾¸ÅÊö¡¿
2019Äê12ÔÂ29ÈÕ£¬ÒÁÀÊÕþ¸®×ÊÖúµÄºÚ¿Í×éÖ¯ÔÚ°ÍÁÖ¹úӪʯÓ͹«Ë¾BapcoµÄÍøÂçÉϰ²ÅÅÒ»ÖÖÐÂÐ͵ÄÊý¾Ý²Á³ý¶ñÒâÈí¼þDustman£¬¸Ã¶ñÒâÈí¼þÖ¼ÔÚÆô¶¯Ñ¬È¾ÅÌËã»úºóɾ³ýÆäÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.zdnet.com/article/new-iranian-data-wiper-malware-hits-bapco-bahrains-national-oil-company/
6. AmadeyÒøÐÐľÂíÃé×¼·Ç¶íÂÞ˹Óû§
¡¾¸ÅÊö¡¿
AmadeyľÂíÔÚ2018Äê10ÔÂÊ״α»·¢Ã÷£¬¿ÉÓÃÓÚÈö²¥ÆäËû¶ñÒâÈí¼þ£¬Ò²¿ÉÓÃÓÚÍøÂçÊܺ¦ÕßÇéÐÎÖеÄÐÅÏ¢£¬¸ÃľÂíÖ÷Ҫͨ¹ýÎó²îʹÓù¤¾ß°ü£¨ÀýÈçRigEKºÍFallout EK£©ºÍAZORult ¶ñÒâÈí¼þÈö²¥£¬ÈôÊÇÊܺ¦ÕßÅÌËã»úÔÚ¶íÂÞ˹£¬ÔòC2¹¤¾ß½«²»»áÔËÐÐÈκÎʹÃü»ò×°ÖÃÈÎºÎÆäËû¶ñÒâÈí¼þ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatvector.cylance.com/en_us/home/threat-spotlight-amadey-bot.html
7. Operation Goldfish Alpha½«ÃÜÂëÐ®ÖÆ½µµÍ78%
¡¾¸ÅÊö¡¿
Operation Goldfish AlphaÊÇÒ»ÏîΪÆÚÁù¸öÔ¡¢Ö¼ÔÚ±£»¤¶«ÄÏÑǵØÇøµÄ·ÓÉÆ÷×°±¸µÄÐж¯¡£¿ËÈÕ¹ú¼ÊÐ̾¯×éÖ¯Ðû²¼Á˸ÃÐж¯µÄЧ¹û£ºÊ¹Õû¸ö¶«ÄÏÑǵÄÃÜÂëÐ®ÖÆÔ˶¯±È2019Äê6ԼͼµÄˮƽϽµÁË78£¥¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/96190/breaking-news/interpol-goldfish-alpha-cryptojacking.html

AG¹«Ë¾ÔÆ





