AG¹«Ë¾ÍþвÇ鱨Öܱ¨£¨20200420~20200426£©
2020-04-27
ÈÈÃÅ×ÊѶ
- AG¹«Ë¾¿Æ¼¼20ÖÜÄê | רÌâ»ã×Ü
¡¾¸ÅÊö¡¿2000Ä꣬Åãͬ×ÅÐÂÊÀ¼ÍǧìûÄêµÄÖÓÉù£¬Öйú»¥ÁªÍøºÍÅÌËã»ú¿ÆÑ§ÊÖÒÕÓÀ´¸ßËÙÉúÄ;ã¬Í¬Äê4ÔÂ25ÈÕ£¬AG¹«Ë¾¿Æ¼¼ÔÚ±±¾©½¨Éè¡£2020Äê4ÔÂ25ÈÕ£¬¼ûÖ¤ÖйúÍøÂçÇå¾²ÐÐÒµÉú³¤µÄAG¹«Ë¾¿Æ¼¼¼¯ÍÅ£¨ÒÔϼò³ÆAG¹«Ë¾¿Æ¼¼£©ÓÀ´ÁË20ÖÜËêÉúÈÕ£¬ÒÔ³ÉÄêÈ˵Ä×Ë̬·Ü½øÔÚÏÂÒ»¸ö¶þÊ®ÄêµÄÐÂÕ÷³ÌÉÏ¡£
¡¾²Î¿¼Á´½Ó¡¿http://blog.nsfocus.net/20years-special-topic/
- AG¹«Ë¾¿Æ¼¼ÔÚRSACÈÈÃÅ×êÑÐ»á´øÀ´µÄ¸É»õ
¡¾¸ÅÊö¡¿4ÔÂ17ÈÕÓÉÖйúÅÌËã»úѧ»áÖ÷Àí£¬CCFÅÌËã»úÇ徲רҵίԱ»á¡¢AG¹«Ë¾¿Æ¼¼¼¯ÍźÍ360 ¼¯ÍųаìµÄ“µÚÊ®¶þ½ìÐÅÏ¢Çå¾²¸ß¼¶ÔÆÂÛ̳ôßÃÀ¹úRSAÈÈÃÅ×êÑлᔣ¬ÒÔ“ÒÔÈËΪ±¾”Ϊ»°Ì⣬ԼÇëÁË18λÐÐҵר¼Ò£¬ÅäºÏ·ÖÏí¡¢½â¶Á¶Ô½ñÄê RSAC µÄÃ÷È·ºÍÊÕ»ñ¡£AG¹«Ë¾¿Æ¼¼µÄÈý¸öÒéÌâ£¬ÖØµãÏÈÈݶÔÖÐÃÀÍø°²¹¤ÒµµÄÉî¶ÈÊӲ졢Õë¶Ô½ñÄêÁ¢ÒìɳºÐ¶ÔÍø°²Á¢ÒìÆ«ÏòµÄ½â¶Á£¬ÒÔ¼°´ÓÇå¾²ÔËӪʵÀýÀ´Ì¸¸üÆõºÏ¹úÇé¡¢¶ÔÇå¾²ÊÂÇé¸ü¾ßÖ¸µ¼¼ÛÖµµÄ˼Ë÷¡£
¡¾²Î¿¼Á´½Ó¡¿http://blog.nsfocus.net/rsac-share-0421/
- ¹¥»÷ÕßʹÓÃÎó²î¹¥»÷Edimax WiFiÇŽӯ÷
¡¾¸ÅÊö¡¿2020Äê4ÔÂ14ÈÕ£¬Exploit DBÐû²¼ÁËÒ»¸öÕë¶ÔEdimax WiFiÇŽӯ÷µÄÔ¶³ÌÖ´ÐÐÎó²îµÄʹÓ㬸ÃʹÓôÓshodanËÑË÷Ìõ¼þµ½Ï·¢Ñù±¾ºÜÊÇÏêϸ£¬AG¹«Ë¾¸ñÎïʵÑéÊÒÍŽáÍþвÇ鱨ÖÐÐĶÔÏìӦװ±¸µÄ̻¶ÇéÐξÙÐÐÁËÑéÖ¤£¬·¢Ã÷2020ÄêÖÁ½ñ£¬Æä̻¶ÊýÄ¿×ܼÆÔÚ6000̨ÒÔÉÏ¡£4ÔÂ18ÈÕ²¶»ñµ½Õë¶Ô¸ÃÎó²îµÄ̽²âºÍʹÓÃÐÐΪ£¬²¢·ºÆðÁ˱¬·¢µÄÕ÷Ïó¡£
¡¾²Î¿¼Á´½Ó¡¿https://mp.weixin.qq.com/s/snPYk118J2z_wAuRcs0tfA
- ˼¿Æ¹ûÕæZoom CommunicationsÖеÄÓû§Ã¶¾ÙÎó²î
¡¾¸ÅÊö¡¿2020Äê4ÔÂ21ÈÕ˼¿Æ¹ûÕæÁËZoom CommunicationsÖеÄÒ»¸öÓû§Ã¶¾ÙÎó²î£¬¸ÃÎó²î¿ÉÄÜÔÊÐí¶ñÒâÓû§»ñÈ¡ÌØ¶¨×éÖ¯ÄÚµÄZoomÓû§µÄÍêÕûÁÐ±í¡£
¡¾²Î¿¼Á´½Ó¡¿https://blog.talosintelligence.com/2020/04/zoom-user-enumeration.html
- GafgytÑù±¾±äÖÖCoronaÌᳫ½©Ê¬ÍøÂç¹¥»÷
¡¾¸ÅÊö¡¿ÏÖÔÚÍøÂçÉÏÒÑ·¢Ã÷µÄÒÔйڲ¡¶¾ÈÈÃÅΪàåÍ·µÄ¹¥»÷£¬»ù±¾ÊÇÒÔÓʼþ·½·¨·¢ËÍÍøÂç´¹ÂÚ£¬ÇÒ¹¥»÷Ä¿µÄÖ÷ÒªÊÇwindows·þÎñÆ÷£¬AG¹«Ë¾¿Æ¼¼·üӰʵÑéÊÒ½üÆÚ²¶»ñµ½Õë¶ÔlinuxÄÚºËϵͳARM7¼Ü¹¹µÄÒÔCoronaйڲ¡¶¾ÃüÃûµÄGafgytÑù±¾±äÖÖ¡£¹¥»÷Õß¶¨Î»ÎªÎ÷Å·¹ú¼Ò£¬Õë¶Ôº£ÄÚÄÜÔ´¡¢µçÐÅÐÐÒµ£¬¾ÙÐн©Ê¬ÍøÂç¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿http://blog.nsfocus.net/
- APT32×é֯ʹÓÃCOVID-19Õë¶ÔÖйúµÄ¹¥»÷
¡¾¸ÅÊö¡¿APT32£¬Ò²±»³ÆÎªOcean Lotus¡¢Ocean BuffaloºÍSeaLotus£¬ÊÇÒ»¸öÓëÔ½ÄÏÓйصÄÍþв×éÖ¯£¬Ö÷Òª¹Ø×¢Ô½ÄÏ¡¢·ÆÂɱö¡¢ÀÏÎκͼíÆÒÕ¯µÈ¶«ÄÏÑǹú¼Ò¡£ÔÚ2020Äê1ÔÂÖÁ2020Äê4ÔÂʱ´ú£¬APT32×é֯ʹÓÃCOVID-19ÒßÇéÏòÖйúÌᳫÓã²æÊ½ÍøÂç´¹ÂÚ¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿https://www.fireeye.com/blog/threat-research/2020/04/apt32-targeting-chinese-government-in-covid-19-related-espionage.html
- Evil Eye×é֯ͨ¹ýiOSÎó²î¹¥»÷Õë¶ÔάÎá¶ûÓïÍøÕ¾
¡¾¸ÅÊö¡¿Evil EyeÍþв×éÖ¯ÔøÌᳫÔÚ°²×¿ÊÖ»úÉÏ×°ÖöñÒâÈí¼þÖ²ÈëµÄ¹¥»÷£¬µ½2020Äê1Ô³õ£¬¸Ã×éÖ¯±»·¢Ã÷Õë¶ÔÖйúάÎá¶ûÍøÕ¾Ê¹ÓÃIRONSQUIRREL¿ªÔ´¿ò¼ÜÀ´Æô¶¯¹¥»÷Á´£¬Ê¹ÓÃWebKitÖеÄÎó²îÕë¶ÔÄ¿µÄÆ»¹ûiOS²Ù×÷ϵͳ£¬Í¨¹ý¶ñÒâµÄiframe¼ÓÔØµ½Êܹ¥»÷µÄÍøÕ¾ÉÏÀ´¾ÙÐй¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿https://www.volexity.com/blog/2020/04/21/evil-eye-threat-actor-resurfaces-with-ios-exploit-and-updated-implant/
- VictoryGate½©Ê¬ÍøÂçͨ¹ý¿ÉÒÆ¶¯×°±¸Èö²¥¾ÙÐÐÍÚ¿óÔ˶¯
¡¾¸ÅÊö¡¿VictoryGateÊÇÒ»¸ö×Ô2019Äê5ÔÂÒÔÀ´Ò»Ö±»îÔ¾µÄ½©Ê¬ÍøÂ磬Ö÷ÒªÓÉÀ¶¡ÃÀÖÞ£¨ÌØÊâÊÇÃØÂ³£©µÄ×°±¸×é³É£¬90%ÒÔÉϵÄÊÜѬȾװ±¸Î»ÓڸõØÇø¡£VictoryGate½öʹÓÃÔÚ¶¯Ì¬DNSÌṩÉÌNo-IPÉÏ×¢²áµÄ×ÓÓòÒÔ¸üºÃ¿ØÖÆÆä½©Ê¬ÍøÂ磬Ëüͨ¹ý¿ÉÒÆ¶¯×°±¸Èö²¥£¬Ö÷ҪĿµÄ¾ÙÐÐMoneroÍÚ¿óÔ˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿https://www.welivesecurity.com/2020/04/23/eset-discovery-monero-mining-botnet-disrupted/
- ¹¥»÷ÕßʹÓÃAgent TeslaľÂíÕë¶ÔÄÜÔ´ÐÐÒµ
¡¾¸ÅÊö¡¿¹¥»÷Õß×î½üʹÓÃʯÓͺÍ×ÔÈ»ÆøÎ£»úÌᳫÁËÓã²æÊ½ÍøÂç´¹ÂÚ¹¥»÷Ô˶¯£¬Î±×°³ÉÖøÃûµÄ°£¼°¹¤³Ì³Ð°üÉÌEnppi·¢ËÍÔ¼ÇëÓʼþ£¬ÔÚÓʼþ¸½¼þÖÐÌí¼ÓAgent TeslaľÂí¾ÙÐзַ¢£¬¹¥»÷Ãé×¼ÂíÀ´Î÷ÑÇ¡¢ÃÀ¹ú¡¢ÒÁÀÊ¡¢ÄÏ·Ç¡¢°¢ÂüºÍÍÁ¶úÆäµÈµØµÄÄÜÔ´ÐÐÒµ¡£ÁíÍâ·ÆÂɱöµÄ´¬Ô˹«Ë¾Ò²±»ÏàͬµÄÊֶι¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿https://labs.bitdefender.com/2020/04/oil-gas-spearphishing-campaigns-drop-agent-tesla-spyware-in-advance-of-historic-opec-deal/

AG¹«Ë¾ÔÆ







