AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2020Äê8Ô£©
2020-09-03
8Ô£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬WebSphereÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-4534£©£¨CVE-2020-4534£©Ó°Ïì½Ï´ó¡£¸ÃÎó²îÓÉÓÚδ׼ȷ´¦Öóͷ£UNC·¾¶¶øµ¼Ö£¬ ¾ÓÉÍâµØÉí·ÝÈÏÖ¤ºó£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÍê³É´úÂëÖ´ÐУ¬Îó²îÆÀ·ÖΪ7.8·Ö¡£
ÁíÍ⣬±¾ÔÂ΢ÈíÐÞ¸´120¸öÇå¾²ÎÊÌ⣬CriticalµÄÎó²î¹²ÓÐ16¸ö£¬ImportantµÄÎó²î103¸ö£¬ÇëÏà¹ØÓû§ÊµÊ±¸üв¹¶¡¾ÙÐзÀ»¤¡£
¹¥»÷×éÖ¯·½Ã棬º£Á«»¨“OceaLotus"×é֯ʹÓÃMsMpEng¾ÙÐвàÔØ¹¥»÷£¬TA551¹¥»÷×éÖ¯Õë¶ÔÒÔÓ¢ÓïΪĸÓïµÄÈË·Ö·¢IcedIDÒøÐÐľÂí£¬Transparent Tribe×é֯ʹÓöñÒâÈí¼þNET RATÒÔ¼°Muhstik½©Ê¬ÍøÂçÕë¶Ôº£ÄÚÔÆ·þÎñÆ÷ÐèÒªÒýÆð¹Ø×¢¡£
ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/
Ò»¡¢ Îó²îÌ¬ÊÆ
2020Äê08ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼109Îó²î, ÆäÖиßΣÎó²î27¸ö£¬Î¢Èí¸ßΣÎó²î9¸ö¡£

* Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2020.08.28
×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»
¶þ¡¢ ÍþвÊÂÎñ
1. NSOÌØ¹¤Èí¼þ¹¥»÷¶à¸ç
¡¾±êÇ©¡¿NSO
¡¾Ê±¼ä¡¿2020-08-02
¡¾¼ò½é¡¿
NSOÌØ¹¤Èí¼þ±»¹¥»÷ÕßʹÓù¥»÷¶à¸ç¹«ÃñÉç»á£¬ÆäÖаüÀ¨ÌìÖ÷½ÌÖ÷½Ì¡¢ÄÁʦºÍ×èµ²ÅÉÕþÖμҡ£NSOÌØ¹¤Èí¼þ²úƷͨ³£±»³ÆÎªPegasus£¬ÊÇÒ»ÖÖÊÖ»úºÚ¿Í¹¤¾ß£¬¿É»ñÈ¡¶ÔÄ¿µÄÒÆ¶¯×°±¸µÄÍêÈ«»á¼ûȨÏÞ£¬PegasusÔÊÐí¹¥»÷ÕßÌáÈ¡ÃÜÂë¡¢Îļþ¡¢ÕÕÆ¬¡¢ÍøÂçÀúÊ·¼Í¼¡¢ÁªÏµÈËÒÔ¼°Éí·ÝÊý¾ÝµÈÐÅÏ¢£¬PegasusµÄÄ¿µÄ°üÀ¨ÑÇÖÞ£¬Å·ÖÞ£¬Öж«ºÍ±±ÃÀµÄÊýÊ®¸ö¹ú¼Ò¡£
¡¾²Î¿¼Á´½Ó¡¿
https://citizenlab.ca/2020/08/nothing-sacred-nso-sypware-in-togo/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡4ÌõIOC£¬ÆäÖаüÀ¨4¸öÓòÃû£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
2. TAIDOORľÂíαװΪDLLÎļþѬȾĿµÄϵͳ
¡¾±êÇ©¡¿TAIDOOR
¡¾Ê±¼ä¡¿2020-08-02
¡¾¼ò½é¡¿
Taidoor×÷Ϊ·þÎñ¶¯Ì¬Á´½Ó¿âDLL×°ÖÃÔÚÄ¿µÄϵͳÉÏ£¬²¢ÇÒÓÉÁ½¸öÎļþ×é³É£¬µÚÒ»¸öÎļþÊǼÓÔØ³ÌÐò£¬×÷Ϊ·þÎñÆô¶¯£¬¼ÓÔØ³ÌÐò½âÃܵڶþ¸öÎļþ£¬È»ºóÔÚÄÚ´æÖÐÖ´ÐиÃÎļþ£¬´ËÎļþÊÇÔ¶³Ì»á¼ûľÂí£¨RAT£©¡£
¡¾²Î¿¼Á´½Ó¡¿
https://us-cert.cisa.gov/ncas/analysis-reports/ar20-216a
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡22ÌõIOC£¬ÆäÖаüÀ¨1¸öIP£¬1¸öÓòÃûºÍ20¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
3. NetWalkerÀÕË÷Èí¼þÕë¶ÔÎ÷Å·¹ú¼ÒºÍÃÀ¹ú
¡¾±êÇ©¡¿NetWalker
¡¾Ê±¼ä¡¿2020-08-02
¡¾¼ò½é¡¿
NetWalkerÀÕË÷Èí¼þ×î³õ³ÆÎªMailto£¬×îÔçÔÚ2019Äê8Ô±»·¢Ã÷£¬×Ô¾õÏÖÒÔÀ´Õë¶ÔÐí¶à²î±ðµÄÄ¿µÄ£¬Ö÷ҪλÓÚÎ÷Å·¹ú¼ÒºÍÃÀ¹ú¡£¹¥»÷Ô˶¯ÖÐNetWalkerÀÕË÷Èí¼þ½«Ëæ»úÀ©Õ¹Ãû¸½¼Óµ½ÊÜѬȾµÄÎļþÖУ¬²¢Ê¹ÓÃSalsa20¼ÓÃÜ£¬ËüʹÓÃÒ»ÖÖеķÀÓù¹æ±ÜÊÖÒÕ±»³ÆÎª·´ÉäDLL¼ÓÔØ£¬ÓÃÓÚ´ÓÄÚ´æÖÐ×¢ÈëDLL¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.mcafee.com//blogs/other-blogs/mcafee-labs/take-a-netwalk-on-the-wild-side/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡117ÌõIOC£¬ÆäÖаüÀ¨117¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
4. ÍøÂç´¹ÂÚÓʼþÐ®ÖÆMicrosoft365ÕÊ»§
¡¾±êÇ©¡¿NetWalker
¡¾Ê±¼ä¡¿2020-08-02
¡¾¼ò½é¡¿
ÍøÂç×ï·¸Ô½À´Ô½¶àµØÃ°³äÊÜÐÅÍеÄSaaSƽ̨ºÍ¹©Ó¦ÉÌ¡£×î½ü£¬ÔÚÒ»Æð´¹ÂÚ¹¥»÷Ô˶¯ÖУ¬µç×ÓÓʼþÖÐÓÐÐí¶àÊÔͼÓÕʹÊÕ¼þÈ˵¥»÷¶ñÒâÁ´½Ó£¬¸ÃÁ´½ÓÖ¸Ïò°üÀ¨Æ¾Ö¤ÍøÂç¶ñÒâÈí¼þµÄÒ³Ãæ£¬¹¥»÷ÕßʹÓÃÊÜѬȾµÄMicrosoft 365ÕÊ»§ÔÚ¼¸¸öСʱÄÚ»á¼û¶à¸öÆäËûÕÊ»§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.darktrace.com/en/blog/phishing-from-the-inside-microsoft-365-account-hijack/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡1ÌõIOC£¬ÆäÖаüÀ¨1¸öÓòÃû£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
5. LaoXinWonЯ´øÁ½¸öÀÕË÷²¡¶¾Ñù±¾
¡¾±êÇ©¡¿LaoXinWon
¡¾Ê±¼ä¡¿2020-08-04
¡¾¼ò½é¡¿
LaoXinWonµÄÀÕË÷²¡¶¾Í¨¹ýÈõ¿ÚÁî±¬ÆÆ·½·¨¾ÙÐÐÈö²¥£¬ËüͬʱЯ´øÁ½¿îÀÕË÷²¡¶¾Ñù±¾£¬Ò»¿îΪC#±àдµÄÀÕË÷Ä£¿é£¬¼ÓÃÜÌí¼Ó.aesÀ©Õ¹ºó׺£»ÁíÒ»¿îΪDelphi±àдµÄScarabÀÕË÷Ä£¿é£¬¼ÓÃÜÌí¼Ó.lamparÀ©Õ¹ºó׺¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com//research/report/1072.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡2ÌõIOC£¬ÆäÖаüÀ¨2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
6. PyPI ¹Ù·½¿ÍÕ»Ôârequest¶ñÒâ°üͶ¶¾
¡¾±êÇ©¡¿request¶ñÒâ°ü
¡¾Ê±¼ä¡¿2020-08-05
¡¾¼ò½é¡¿
¹¥»÷Õß½«request¶ñÒâ´¹ÂÚ°üÉÏ´«ÖÁPyPI¹Ù·½¿ÍÕ»£¬²¢Í¨¹ý¸Ã´¹ÂÚ°üʵÑéÇÔÈ¡Óû§Ãô¸ÐÐÅÏ¢¼°Êý×ÖÇ®±ÒÃÜÔ¿¡¢ÝªÖ²³¤ÆÚ»¯ºóÃÅ¡¢Ô¶³Ì¿ØÖƵÈһϵÁй¥»÷Ô˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com//research/report/1073.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡3ÌõIOC£¬ÆäÖаüÀ¨1¸öIPºÍ2¸öÓòÃû£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
7. º£Á«»¨“OceaLotus"×é֯ʹÓÃMsMpEng¾ÙÐвàÔØ¹¥»÷
¡¾±êÇ©¡¿º£Á«»¨
¡¾Ê±¼ä¡¿2020-08-06
¡¾¼ò½é¡¿
¿ËÈÕ£¬AG¹«Ë¾ÍþвÇ鱨£¨NTI£©·¢Ã÷ÁËÒ»Æð½èÓÃWindowsDefenderÖ÷Òª×é¼þMsMpEng.exe¾ÙÐвàÔØ¹¥»÷µÄÊÂÎñ¡£Í¨¹ý¶Ô±¾ÊÂÎñÒÔ¼°¶à¸ö¹ØÁªÊÂÎñµÄÆÊÎö£¬È·ÈϸÃϵÁй¥»÷ÊÂÎñµÄÌᳫÕßΪº£Á«»¨£¨OceanLotus£¬APT32£©×éÖ¯¡£³ýͨÀýÊÖ·¨Ö®Í⣬º£Á«»¨×éÖ¯ÔÚÕâÒ»ÔÙ¹¥»÷ÖÐʹÓÃÁËÒ»ÖÖеĻìÏýÊÖÒÕ£¬ÒÔ¼°Ò»¿îеÄÖÐÐÄÔØºÉ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://nti.nsfocus.com/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡11ÌõIOC£¬ÆäÖаüÀ¨11¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
8. Muhstik½©Ê¬ÍøÂçÕë¶Ôº£ÄÚÔÆ·þÎñÆ÷
¡¾±êÇ©¡¿Muhstik
¡¾Ê±¼ä¡¿2020-08-06
¡¾¼ò½é¡¿
¹¥»÷Õßͨ¹ýSSH±¬ÆÆÉϰ¶·þÎñÆ÷Ö´ÐжñÒâÏÂÁîÏÂÔØMuhstik½©Ê¬ÍøÂçľÂí£¬×齨½©Ê¬ÍøÂç²¢¿ØÖÆÊ§ÏÝ·þÎñÆ÷Ö´ÐÐSSHºáÏòÒÆ¶¯¡¢ÏÂÔØÃÅÂÞ±ÒÍÚ¿óľÂíºÍ½ÓÊÜÔ¶³ÌÏÂÁîÌᳫDDoS¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com//research/report/1078.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡26ÌõIOC£¬ÆäÖаüÀ¨3¸öIP£¬2¸öÓòÃûºÍ21¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
9. TA551¹¥»÷×éÖ¯·Ö·¢IcedIDÒøÐÐľÂí
¡¾±êÇ©¡¿TA551
¡¾Ê±¼ä¡¿2020-08-06
¡¾¼ò½é¡¿
TA551×éÖ¯ÔÚ½üÆÚµÄ¹¥»÷Ô˶¯ÖÐÕë¶ÔÒÔÓ¢ÓïΪĸÓïµÄÈË£¬Ê¹ÓÃÀ¬»øÓʼþ·Ö·¢IcedIDÒøÐÐľÂí£¬ÕâЩÓʼþ¸½¼þÊÇ´øÓжñÒâºêµÄWordÎĵµ£¬Ò»µ©Óû§ÆôÓú꣬HTTPͨѶµÄTCPÁ÷¿É¼ìË÷×°ÖöñÒâ³ÌÐòDLL¡£
¡¾²Î¿¼Á´½Ó¡¿
https://isc.sans.edu/diary/26438
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡56ÌõIOC£¬ÆäÖаüÀ¨2¸öIP£¬20¸öÓòÃûºÍ34¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
10. ¿çÎŤ¾ß°üÓÃÓÚÏóÐÎÎÄ×Ö¹¥»÷ÒÔ¾ÙÐÐÐÅÓÿ¨ÐÅÏ¢ÇÔÈ¡
¡¾±êÇ©¡¿Magecart
¡¾Ê±¼ä¡¿2020-08-05
¡¾¼ò½é¡¿
¹¥»÷ÕßʹÓÃÏóÐÎÎÄ×Ö¹¥»÷·½·¨À´ÇÔÊØÐÅÓÿ¨ÐÅÏ¢£¬´Ë¹¥»÷ÊÖÒÕÔÚ¾ßÓÐIDNͬÐÎÒìÒå´Ê¹¥»÷µÄÍøÂç´¹ÂÚÕ©ÆÖÐÒѾ±»Ê¹ÓÃÁËÒ»¶Îʱ¼ä¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.malwarebytes.com/threat-analysis/2020/08/inter-skimming-kit-used-in-homoglyph-attacks/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡5ÌõIOC£¬ÆäÖаüÀ¨1¸öIPºÍ4¸öÓòÃû£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
11. ¹¥»÷ÕßʹÓÃCOVID-19ΪÓÕ¶üÊÕÈ¡Ãô¸ÐÐÅÏ¢
¡¾±êÇ©¡¿COVID-19
¡¾Ê±¼ä¡¿2020-08-09
¡¾¼ò½é¡¿
½üÆÚʹÓÃÐÂÐ͹Ú×´²¡¶¾COVID-19Ö÷Ìâ×÷ΪÓÕ¶üµÄ´¹ÂÚ¹¥»÷Ô˶¯ÒÀÈ»»îÔ¾£¬ÆäÖÐÓй¥»÷Õßͨ¹ýʹÓÃÖ÷ÌâΪ\"Covid-19»ù½ð¾ÈÔ®½±\"£¬»òÕßÀÄÓÃÍŽá¹úµÄ±ê¼ÇÀ´ÓÕµ¼Êܺ¦Õߣ»ÓеĹ¥»÷Ô˶¯ÒÔ±ÈÌØ±ÒÇÔȡΪĿµÄ£¬Í¨¹ý½«Êܺ¦ÕßÖ¸µ¼ÖÁ´¹ÂÚÒ³ÃæÒÔÇÔÈ¡±ÈÌØ±ÒÇ®°üÒÔ¼°ÕË»§Æ¾Ö¤£»ÉÐÓз¢Ã÷ÒÔ\"ÓÉÓÚÐÂÐ͹Ú×´²¡¶¾µ¼ÖÂÑÓ³Ù¸¶¿î\"ΪÖ÷Ì⣬ÓÕʹÊܺ¦Õß·¿ª¸½¼þ£¬È»ºó¶ñÒâÎļþ½«½âѹËõ²¢´ÓGoogleÔÆÅÌÏÂÔØÓÐÓøºÔØNetWire¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.fortinet.com/blog/threat-research/latest-covid-19-variants-from-the-ridiculous-to-the-malicious
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡3ÌõIOC£¬ÆäÖаüÀ¨1¸öÓòÃûºÍ2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
12. »ùÓھ籾µÄ¶ñÒâÈí¼þÕë¶ÔWindows²Ù×÷ϵͳÓû§
¡¾±êÇ©¡¿JScript RAT
¡¾Ê±¼ä¡¿2020-08-10
¡¾¼ò½é¡¿
½üÆÚÑо¿Ö°Ô±Í¨¹ýInternet Explorerä¯ÀÀÆ÷Îó²î¼ì²âµ½ÖØ´ó»ùÓھ籾µÄ¶ñÒâÈí¼þ£¬ÕâЩ¶ñÒâÈí¼þÕë¶ÔWindows²Ù×÷ϵͳÓû§£¬¶ñÒâ¾ç±¾Ê¹ÓÃÁËCVE-2019-0752Îó²î£¬ÆäÖÐÒ»¸öJScriptÔ¶³Ì»á¼ûľÂí¿ÉÒÔÈ·±£ÔÚÄ¿µÄϵͳÉϵij¤ÆÚÐÔ£¬È»ºóÅþÁ¬µ½Ô¶³Ì·þÎñÆ÷£¬¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄÅÌËãÉÏÖ´ÐÐí§ÒâÏÂÁÒѾÙÐÐÍêÈ«¿ØÖÆ£¬µÚ¶þ¸öAutoITÏÂÔØÆ÷ʹÓÃÍøÂçÅþÁ¬ºÍ¾ç±¾¹¦Ð§À´ÏÂÔØºÍÖ´ÐжñÒâÈí¼þ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://unit42.paloaltonetworks.com/script-based-malware/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡4ÌõIOC£¬ÆäÖаüÀ¨1¸öÏà¹ØÁªÎó²îºÍ3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
13. PowerFallÔ˶¯Ê¹ÓÃInternet ExplorerÎó²îºÍWindowsÎó²îÕë¶Ôº«¹ú
¡¾±êÇ©¡¿PowerFall
¡¾Ê±¼ä¡¿2020-08-11
¡¾¼ò½é¡¿
Operation PowerFallÕ½ÕùÖй¥»÷ÕßʹÓÃÁ½¸ö0dayÎó²îÕë¶Ôº«¹ú¾ÙÐй¥»÷£¬ÕâÁ½¸öÎó²î»®·Ö£ºInternet ExplorerµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2020-1380)£¬¸ÃÎó²îÔÚJavaScriptÒýÇæÖй¥»÷ÕßÄܹ»Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룻WindowsÌØÈ¨ÌáÉýÎó²î(CVE-2020-0986)£¬¸ÃÎó²îÔÚ²Ù×÷ϵͳ·þÎñÖб»¼ì²âµ½£¬¹¥»÷Õß¿ÉÒÔÌáÉýÌØÈ¨²¢Ö´ÐÐδ¾ÊÚȨµÄ²Ù×÷¡£´Ë´Î¹¥»÷Ô˶¯ÒÔWindows10µÄ×îа汾ΪĿµÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securelist.com/ie-and-windows-zero-day-operation-powerfall/97976/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡14ÌõIOC£¬ÆäÖаüÀ¨6¸öÏà¹ØÁªÎó²îºÍ8¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
14. BisonalºóÃÅÕë¶Ô¶«Å·µÄ½ðÈں;üÊÂ×éÖ¯
¡¾±êÇ©¡¿Bisonal
¡¾Ê±¼ä¡¿2020-08-12
¡¾¼ò½é¡¿
CactusPete£¬Ò²±»³ÆÎªKarma PandaºÍTonto Team£¬ÊÇÒ»¸öÖÁÉÙ´Ó2013Äê»îÔ¾ÖÁ½ñµÄÍþв×éÖ¯£¬ºã¾ÃÄ¿µÄÕë¶ÔÑÇÖ޺Ͷ«Å·µÄ¾üÊ¡¢Íâ½»ºÍ»ù´¡ÉèÊ©¡£½üÆÚCactusPete×é֯ʹÓÃBisonalºóÃÅбäÖÖÃé×¼¶«Å·µÄ½ðÈں;üʲ¿·Ö£¬¸Ã×é֯ͨ¹ý´øÓжñÒ⸽¼þµÄÓã²æÊ½ÍøÂç´¹ÂÚÓʼþµÄ·½·¨À´×ª´ï¶ñÒâÈí¼þBisonal£¬¸Ã¶ñÒâÈí¼þÒÔ»ñÈ¡Êܺ¦ÕßµÄÃô¸ÐÊý¾ÝµÄ»á¼ûȨÏÞΪĿµÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securelist.com/cactuspete-apt-groups-updated-bisonal-backdoor/97962/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡4ÌõIOC£¬ÆäÖаüÀ¨1¸ö¹ØÁªÎó²îºÍ3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
15. Continente and WortenÆ·ÅÆµÄÍøÂç´¹ÂÚÔ˶¯
¡¾±êÇ©¡¿Continente and Worten
¡¾Ê±¼ä¡¿2020-08-16
¡¾¼ò½é¡¿
´ú±íContinente and WortenÆ·ÅÆµÄ¹ã¸æÏµÁÐÕýÔÚͨ¹ýSMS£¨smishing£©¾ÙÐй²Ïí£¬´ËÔ˶¯ÏÖÔÚÕýÔÚÆÏÌÑÑÀÈö²¥£¬¸ÃÔ˶¯²»µ«Õë¶ÔÆÏÌÑÑÀÆ·ÅÆºÍ×éÖ¯»¹½«ÆäËûÆ·ÅÆºÍ¹ú¼Ò×÷ΪĿµÄ£¬ÀýÈçÎ÷°àÑÀ£¬ÃÀ¹ú£¬¼ÓÄôó£¬Ó¢¹ú£¬ÐÙÑÀÀûµÈ¡£¹¥»÷Õßͨ¹ý½«Êܺ¦ÕßÖ¸µ¼µ½Ä¿µÄÉϰ¶Ò³ÃæµÄ·þÎñÆ÷À´ÍøÂçÊܺ¦ÕßµÄÏêϸÐÅÏ¢¡£ ÕâÖÖÐÅÏ¢¿ÉÄÜ»áÓÃÔÚÕâÖÖÐÔ×ÓµÄδÀ´Ô˶¯ÖÐ £¬ËüÊÇͨ¹ýÉç»á¹¤³ÌÕë¶ÔÊܺ¦Õߵģ¬ÒÔʹÓÃеÄÍøÂç´¹ÂÚÀ˳±»ò¿ÉÄÜÉæ¼°¶ñÒâÈí¼þµÄÔ˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://seguranca-informatica.pt/campanhas-de-phishing-em-nome-da-marca-continente-e-worten-atualmente-a-serem-disseminadas-em-portugal/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡8ÌõIOC£¬ÆäÖаüÀ¨1¸öIP£¬6¸öÑù±¾ºÍ1¸öÏà¹ØÁªµÄÓÊÏ䣻AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
16. Transparent Tribe×é֯ʹÓöñÒâÈí¼þNET RAT
¡¾±êÇ©¡¿Transparent Tribe
¡¾Ê±¼ä¡¿2020-08-19
¡¾¼ò½é¡¿
Transparent TribeÊÇÒ»¸ö¶à²úµÄ×éÖ¯£¬¸Ã×éÖ¯ÔÚÒÑÍùÒ»ÄêÀïÕýÔÚÑݱ䣬ÔöÇ¿ÁËÔ˶¯£¬×îÏÈÁË´ó¹æÄ£µÄѬȾÔ˶¯¡£ËûÃǵÄÖ÷Òª¶ñÒâÈí¼þÊÇ×Ô½ç˵µÄNET RAT£¬ÓÖ³ÆCrimson RAT£¬ÉÐÓÐÆäËû×Ô½ç˵NET¶ñÒâÈí¼þºÍ»ùÓÚPythonµÄRAT PeppyµÄʹÓ᣹¥»÷Õßͨ¹ýʹÓÃÓÉÖÖÖÖ×é¼þ×é³ÉµÄCrimsonÔÚÊÜѬȾµÄÅÌËã»úÉÏÖ´ÐжàÖÖÔ˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securelist.com/transparent-tribe-part-1/98127/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡21ÌõIOC£¬ÆäÖаüÀ¨4¸öIP£¬2¸öÓòÃûºÍ15¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

AG¹«Ë¾ÔÆ







