AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2020.12£©
2021-01-05
12Ô£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬Windows NTFSÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17096£©ÒÔ¼°Apache StrutsÔ¶³Ì´úÂëÖ´ÐÐÎó²îS2-061£¨CVE-2020-17530£©Ó°Ïì½Ï´ó¡£Ç°ÕßÓÉÓÚWindows NTFS±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÍâµØ¹¥»÷Õß¿Éͨ¹ýÔËÐÐÌØÖÆµÄÓ¦ÓóÌÐò£¬´Ó¶øÌáÉýÓû§µÄȨÏÞ£¬¾ßÓÐSMBv2»á¼ûȨÏÞµÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÍøÂç·¢ËÍÌØÖÆµÄÇëÇó£¬Ê¹ÓôËÎó²îÔÚÄ¿µÄϵͳÉÏÖ´ÐдúÂ룻ºóÕßÓÉÓÚµ±¿ª·¢Ö°Ô±Ê¹ÓÃÁË%{…}Óï·¨¾ÙÐÐÇ¿ÖÆOGNLÆÊÎöʱ£¬Ä³Ð©ÌØÊâµÄTAGÊôÐÔ¿ÉÄܻᱻ¶þ´ÎÆÊÎö£¬¹¥»÷Õ߿ɽṹ¶ñÒâµÄOGNL±í´ïʽ´¥·¢Îó²î£¬Ôì³ÉÔ¶³Ì´úÂëÖ´ÐÐ ¡£
ÁíÍ⣬±¾´Î΢Èí¹²ÐÞ¸´ÁË9¸öCritical¼¶±ðÎó²î£¬4¸öImportant ¼¶±ðÎó²î£¬2¸öModerate¼¶Îó²î¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£
ÔÚ±¾ÔµÄÍþвÊÂÎñÖУ¬ÍÚ¿óºÍÐÅÏ¢ÇÔÈ¡ÒÀ¾ÉÊǺڿͽø¹¥µÄÖØµã£¬ËµÃ÷ÀûÒæÊǺڿÍ×î´óµÄ¶¯Á¦£»Æä´ÎÊǶÔFireEyeºì¶Ó¹¤¾ßµÄÇÔÈ¡¡£¹¥»÷Êֶη½Ã棬ÀÕË÷ºÍ´¹ÂÚÊDZ¾Ô¹¥»÷ÊÂÎñµÄ³£ÓÃÊֶΣ¬Ò²·ºÆðÁËͨ¹ýÆÆËðSolarWindsµÄOrionÍøÂçÖÎÀí²úÆ·ÇÖÈëÁª°î»ú¹¹ºÍFireEyeÍøÂçµÄÐÂÊֶΡ£¹¥»÷×éÖ¯·½Ã棬ºã¾ÃÕë¶ÔÖж«µØÇøµÄAPT×é֯˫βЫÒÔCIA×ÊÖú¹þÂí˹Ïà¹ØÐÅÏ¢×÷ΪÓÕ¶üµÄ¹¥»÷Ô˶¯ÐèÒªÒýÆð¹Ø×¢¡£
ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/
Ò»¡¢ Îó²îÌ¬ÊÆ
2020Äê12ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼294¸öÎó²î, ÆäÖиßΣÎó²î81¸ö£¬Î¢Èí¸ßΣÎó²î31¸ö¡£

* Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2020.12.27
×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»
¶þ¡¢ ÍþвÊÂÎñ
1. ˫βЫAPT×éÖ¯ÒÔCIA×ÊÖú¹þÂí˹Ïà¹ØÐÅϢΪÓÕ¶üµÄ¹¥»÷Ô˶¯
¡¾±êÇ©¡¿APT
¡¾Ê±¼ä¡¿2020-12-06
¡¾¼ò½é¡¿
˫βЫAPTÍÅ»ïÊÇÒ»¸öºã¾ÃÕë¶ÔÖж«µØÇøµÄ¸ß¼¶Íþв×éÖ¯£¬Æä×îÔçÓÚ2017Äê±»Åû¶¡£ÆäÖÁÉÙ×Ô2016Äê5ÔÂÆð£¬±ãÒ»Á¬Õë¶Ô°ÍÀÕ˹̹½ÌÓý»ú¹¹¡¢¾üÊ»ú¹¹µÈÖ÷ÒªÁìÓò¿ªÕ¹ÁËÓÐ×éÖ¯£¬ÓÐÍýÏ룬ÓÐÕë¶ÔÐԵĹ¥»÷£¬¸Ã×éÖ¯ÓµÓÐÕë¶ÔWindowsºÍAndroid˫ƽ̨¹¥»÷ÄÜÁ¦¡£¿ËÈÕ£¬Ä³Ñо¿ÍŶӲ¶»ñ¶à¸öαװ³ÉÊÓÆµ¡¢ÎĵµºÍͼƬµÄ¿ÉÖ´ÐÐÎļþ£¬´ËÀàÑù±¾½«Í¼±êÉèÖÃΪ¶ÔÓ¦µÄÓÕ¶üÀàÐÍ£¬ÓÕµ¼Êܺ¦Õßµã»÷Ö´ÐС£µ±Ñù±¾Ö´Ðк󣬽«ÊÍ·ÅչʾÏà¹ØÓÕ¶üÒÉ»óÊܺ¦Õß¡£ÊÍ·ÅչʾµÄÓÕ¶ü°üÀ¨CIA¶Ô¹þÂí˹֧³ÖµÄÏà¹ØÕþÖÎÀàÓÕ¶ü¡¢°ÍÀÕ˹̹µØÇøÓñÈËÊÓÆµÍ¼Æ¬¡¢¼òÀúÏà¹ØÎĵµµÈ¡£´Ë´Î²¶»ñÑù±¾ÒÉËÆ¾ùÀ´×ÔAPT×éÖ¯£ºË«Î²Ð«¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.qianxin.com/blog/articles/analysis-of-APT-C-23-CIA-funding-for-Hamas-information-as-bait/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡26ÌõIOC£¬ÆäÖаüÀ¨9¸öÓòÃûºÍ17¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
2. “ÄäÓ°”ÍÚ¿óÍÅ»ïʹÓÃÀÕË÷×é¼þCryptoJoker¾ÙÐв»·¨Ä²ÀûµÄ¹¥»÷Ô˶¯
¡¾±êÇ©¡¿CryptoJoker
¡¾Ê±¼ä¡¿2020-12-06
¡¾¼ò½é¡¿
“ÄäÓ°”ÍÚ¿óÍÅ»ïµÄ¹¥»÷Ô˶¯Éý¼¶£¬¸ÃÍÅ»ïʹÓüÓÃÜÀÕË÷×é¼þCryptoJoker£¬´Ó֮ǰµÄÍÚ¿óÅÌËãתÏòÀÕË÷¹¥»÷£¬¾ÙÐв»·¨Ä²Àû¡£ÄäÓ°×éÖ¯Èö²¥µÄÀÕË÷²¡¶¾×é¼þÔÚÖ´ÐÐÀú³ÌÖнÓÄÉÎÞÎļþ¹¥»÷ÊÖÒÕ£¬¹¥»÷Àú³ÌÖÐÈ«³ÌÎÞÑù±¾ÎļþÂ䵨£¬ÇÒÔÚ¼ÓÃÜÊý¾ÝÍê³ÉÖ®ºó»áÕûÀí׼ʱʹÃü£¬ÁîÊÂÎñËÝÔ´Ê®·ÖÄÑÌâ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com//research/report/1191.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡5ÌõIOC£¬ÆäÖаüÀ¨3¸öÓòÃûºÍ2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
3. FireEyeÔâAPT×éÖ¯ÈëÇÖ£¬ºì¶Ó¹¤¾ß±»ÇÔ
¡¾±êÇ©¡¿FireEye
¡¾Ê±¼ä¡¿2020-12-08
¡¾¼ò½é¡¿
2020Äê12ÔÂ8ÈÕ£¬Çå¾²¹«Ë¾ FireEye Ðû²¼²©¿ÍÌåÏÖ£¬Ä³¸öÓɹú¼ÒÔÞÖúµÄ APT ×é֯͵ȡÁË FireEye µÄºì¶Ó¹¤¾ßÏä¡£ÓÉÓÚÔÝʱÎÞ·¨È·¶¨¹¥»÷Õß»á×Ô¼ºÊ¹Óã¬ÕվɹûÕæÅû¶¹¤¾ßÏ䣬Ϊ°ü¹Ü¸÷Çå¾²ÉçÇøÄÜÌáǰ½ÓÄÉÓ¦¶Ô²½·¥£¬FireEye ¹ûÕæÁ˱»µÁ¹¤¾ßµÄ¼ì²â¹æÔò£¬ÒÔ½µµÍ¶ñÒâÓû§ÀÄÓúì¶Ó¹¤¾ßÏäµÄÍþв¡£ ±¾´ÎFireeyeºì¶Ó¹¤¾ßÏäÖаüÀ¨60 ¸öÒÔÉϵĹ¥»÷¹¤¾ß£¬ÆäÖÐÆ¾Ö¤ÇÔÈ¡À๤¾ß°üÓÐ ADP£¬ASHUNT£¬SAFETYKATZ µÈ£¬ºóÃÅÔ¶¿ØÀ๤¾ß°üÓÐ BEACON£¬DSHEL£¬REDFLARE (Gorat)µÈ£¬±ðµÄÉÐÓÐÓÃÓÚ×Ô¶¯Õì̽µÄdzÒ׾籾£¬ÒÔ¼° CobaltSrike¡¢Metasploit Ö®ÀàµÄÎó²îʹÓÿò¼Ü¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.secrss.com/articles/27716
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡637ÌõIOC£¬ÆäÖаüÀ¨621¸öÑù±¾ºÍ16¸öÎó²î£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
4. ºÚ¿Íͨ¹ýÆÆËðSolarWindsµÄOrionÍøÂçÖÎÀí²úÆ·ÇÖÈëÁª°î»ú¹¹ºÍFireEyeÍøÂç
¡¾±êÇ©¡¿SolarWinds
¡¾Ê±¼ä¡¿2020-12-13
¡¾¼ò½é¡¿
IT¹«Ë¾SolarWinds¹«Ë¾Í¨³£ÏòÕþ¸®»ú¹¹¡¢¾üʺÍÇ鱨²¿·ÖÌṩÆäÍøÂçÖÎÀí²úÆ·¡£½üÆÚ¸Ã¹«Ë¾Ðû²¼µÄ¸üб» APT29 »òAPT Cozy Bear×éÖ¯¸Ä¶¯¡£ ÉæÏÓÓë¶íÂÞ˹ÓÐÁªÏµµÄºÚ¿Í¹¥»÷µÄÃñ×å¹ú¼ÒÐÐΪÕßÒѾËðº¦Á˰üÀ¨ÃÀ¹ú²ÆÎñ²¿£¬ÉÌÎñ²¿¹ú¼ÒµçÐźÍÐÅÏ¢ÖÎÀí¾Ö£¨NTIA£©ÔÚÄڵĶà¸öÃÀ¹úÕþ¸®»ú¹¹µÄÍøÂç¡£ºÚ¿Í¹¥»÷ʹÍþв¼ÓÈëÕß¿ÉÒÔ¼àÊÓÄÚ²¿µç×ÓÓʼþÁ÷Á¿¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/112275/apt/solarwinds-supply-chain-attack.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡55ÌõIOC£¬ÆäÖаüÀ¨10¸öIP£¬17¸öÓòÃûºÍ28¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
5. Ks3_MinerľÂíͨ¹ý±¬ÆÆSSHÈëÇÖÔÆ·þÎñÆ÷ÍÚ¿ó
¡¾±êÇ©¡¿Ks3_Miner
¡¾Ê±¼ä¡¿2020-12-15
¡¾¼ò½é¡¿
Ks3ÍÚ¿óľÂí¹¥»÷ÔÆ·þÎñÆ÷£¬¹¥»÷ÍÅ»ïͨ¹ýɨÃèÍøÂçÖдó×Ú¿ª·ÅµÄSSH·þÎñ£¬¶ÔÆä¾ÙÐб¬ÆÆ¹¥»÷£¬ÀֳɺóÖ²ÈëÍÚ¿ó¶ñÒâ¾ç±¾¾ÙÐÐÃÅÂÞ±ÒÍÚ¿ó¡£ÒòÍÚ¿óľÂíÖ÷¾ç±¾ÃûΪks3£¬Ñо¿Ö°Ô±½«ÆäÃüÃûΪKs3_Miner¡£¸ÃÍÚ¿óľÂí×÷ҵʱ£¬»á´ó×ÚÕ¼Ó÷þÎñÆ÷×ÊÔ´£¬Ê¹ÔÆ·þÎñÆ÷ÎÞ·¨ÌṩÕý³£µÄÍøÂç·þÎñ¡£Í¬Ê±£¬¸ÃľÂíÒ²»á¿¢ÊÂÆäËûÍÚ¿óľÂíÀú³Ì£¬É¾³ýÆäËûÍÚ¿óľÂíÎļþ£¬ÒÔ¶ÀÍÌ·þÎñÆ÷×ÊÔ´¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com//research/report/1203.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡7ÌõIOC£¬ÆäÖаüÀ¨2¸öIPºÍ5¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
6. GoontactµÄÌØ¹¤Èí¼þÕë¶ÔiOSºÍAndroidÓû§
¡¾±êÇ©¡¿Goontact
¡¾Ê±¼ä¡¿2020-12-15
¡¾¼ò½é¡¿
½üÆÚ·¢Ã÷ÁËÒ»ÖÖÕë¶ÔÖÐÎĹú¼Ò¡¢º«¹úºÍÈÕ±¾µÄiOSºÍAndroidÓû§µÄеÄÒÆ¶¯Ó¦ÓÃÍþв£¬½«ÆäÃüÃûΪGoontact¡£GoontactÌØ¹¤Èí¼þÕë¶Ôͨ³£Ìṩ»¤ËÍ·þÎñµÄ²»·¨Õ¾µãµÄÓû§£¬²¢´ÓÆäÒÆ¶¯×°±¸ÖÐÇÔȡСÎÒ˽¼ÒÐÅÏ¢¡£ÓÃÓÚ·Ö·¢ÕâЩ¶ñÒâÓ¦ÓóÌÐòµÄÍøÕ¾ÀàÐͺÍй¶µÄÐÅÏ¢Åú×¢£¬×îÖÕÄ¿µÄÊÇÀÕË÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.lookout.com/lookout-discovers-new-spyware-goontact-used-by-sextortionists-for-blackmail
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡131ÌõIOC£¬ÆäÖаüÀ¨29¸öÓòÃûºÍ102¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

AG¹«Ë¾ÔÆ







