¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2021Äê2Ô£©
2021-03-05
2Ô£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬Windows TCP&IP Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-24074£©ÒÔ¼°VMware¶à¸ö¸ßΣÎó²îÓ°Ïì½Ï´ó¡£Ç°Õ߸ÃÎó²îλÓÚIPv4Դ·ÓÉÖУ¬WindowsĬÈÏÉèÖÃϲ»ÆôÓô˹¦Ð§£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹ÌØÊâµÄIPÊý¾Ý°ü£¬ÔÚÄ¿µÄÖ÷»úÉÏÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£CVSSÆÀ·ÖΪ9.8£»ºóÕßÊÇVMware¹Ù·½Åû¶vSphere Client¡¢ESXiµÄÁ½¸ö¸ßΣÎó²î£ºCVE-2021-21972£ºvSphere Client£¨HTML5£©ÔÚvCenter Server²å¼þvRealize OperationsÖаüÀ¨Ò»¸öÔ¶³ÌÖ´ÐдúÂëÎó²î£¬CVSSv3ÆÀ·Ö9.8£¬ÊÜÓ°ÏìµÄvRealize Operations²å¼þΪĬÈÏ×°Öã»CVE-2021-21974£ºESXiÖÐʹÓõÄOpenSLP±£´æ¶ÑÒç³öÎó²î£¬CVSSv3ÆÀ·Ö8.8¡£ÓëESXi´¦ÓÚÍ³Ò»Íø¶ÎÖÐÇÒ¿ÉÒÔ»á¼û427¶Ë¿ÚµÄ¹¥»÷Õ߿ɴ¥·¢OpenSLP·þÎñÖеĶÑÒç³öÎÊÌ⣬´Ó¶øµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡£
ÁíÍ⣬±¾´Î΢Èí¹²ÐÞ¸´ÁË11¸öCritical¼¶±ðÎó²î£¬43¸öImportant¼¶±ðÎó²î£¬2¸öModerate¼¶Îó²î¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£
ÔÚ±¾ÔµÄÍþвÊÂÎñÖУ¬¾ßÓÐÕþ¸®Åä¾°µÄÍþв×éÖ¯½Ï»îÔ¾£¬ÆäÖаüÀ¨³¯ÏʵÄLazarus×éÖ¯¡¢¶íÂÞ˹µÄTurla×éÖ¯¡¢ÒÔ¼°BlackTechÍþв×éÖ¯£»Ëæ×űÈÌØ±ÒÒ»Á¬ÔöÌí£¬·¢¶¯Êý×ÖÐéÄâÇ®±ÒÊÐÖµÕûÌåìÉý£¬ÍÚ¿óÍÅ»ïÒ²·Ç³£»îÔ¾£¬°üÀ¨TeamTNT¡¢H2MinerÍÅ»ïµÈ£»Í¬Ê±±¾ÔÂÏÄÀú´º½Úʱ´ú£¬ÔÆ·þÎñÊǹ¥»÷Õß½ø¹¥µÄÖØµãÄ¿µÄ¹¤¾ß¡£
ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/
Ò»¡¢ Îó²îÌ¬ÊÆ
2021Äê02ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼262¸öÎó²î, ÆäÖиßΣÎó²î53¸ö£¬Î¢Èí¸ßΣÎó²î13¸ö¡£

* Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2021.02.28
×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»
¶þ¡¢ ÍþвÊÂÎñ
1. Turla×éÖ¯°²ÅÅIronPython¶ñÒâÈí¼þ¼ÓÔØ³ÌÐò
¡¾±êÇ©¡¿IronNetInjector
¡¾Ê±¼ä¡¿2021-02-19
¡¾¼ò½é¡¿
¶íÂÞ˹ºÚ¿Í×éÖ¯TurlaÕýÔÚ°²ÅÅÒ»¸ö»ùÓÚIronPythonµÄ¶ñÒâÈí¼þ¼ÓÔØÆ÷£¬³ÆÎªIronNetInjector£¬ÐµļÓÔØÆ÷ͨ¹ýʹÓÃIronPythonÖ±½ÓʹÓÃ.NET Framework APIÒÔ¼°Python¿âµÄÄÜÁ¦À´ÌṩComRAT£¨Ò»ÖÖÔ¶³Ì»á¼ûľÂí£©£¬¾ßÓлìÏý¶ñÒâÈí¼þ´úÂëÒÔ¼°¼ÓÃÜÏ¢ÕùÃÜNET×¢ÈëÆ÷ºÍÓÐÓÃÔØºÉµÄ¹¦Ð§¡£
¡¾¹ØÁªµÄ¹¥»÷×éÖ¯¡¿
Turla GroupÊÇÒ»¸ö¶íÂÞ˹Íþв×éÖ¯£¬×Ô2014ÄêÒÔÀ´ÒÑѬȾÁè¼Ý45¸ö¹ú¼ÒÊý̨ÅÌËã»ú£¬ÆäÖаüÀ¨Õþ¸®¡¢¾üÊ¡¢Íâ½»¡¢½ÌÓýºÍÒ½Ò©ÐÐÒµ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://unit42.paloaltonetworks.com/ironnetinjector/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡15ÌõIOC£¬ÆäÖаüÀ¨15¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
2. LazarusʹÓÃInternet Explorer 0dayÎó²î¹¥»÷Çå¾²Ñо¿ÕßµÄÔ˶¯
¡¾±êÇ©¡¿Lazarus
¡¾Ê±¼ä¡¿2021-02-04
¡¾¼ò½é¡¿
½üÆÚ£¬º«¹úÇå¾²¹«Ë¾ENKIÅû¶ÁËÒ»ÆðʹÓÃInternet Explorer 0dayÎó²î¹¥»÷Çå¾²Ñо¿ÕßµÄÔ˶¯¡£¸ÃÔ˶¯ÊÇÓɹȸ跢Ã÷µÄ³¯ÏÊ×éÖ¯Õë¶ÔÇå¾²Ö°Ô±¹¥»÷ÊÂÎñµÄÒ»²¿·Ö£¬¹¥»÷ÕßÒѱ»È·ÒÔΪ³¯ÏÊAPT×éÖ¯Lazarus¡£ÔÚ¹¥»÷Ô˶¯ÖУ¬Lazarus½á¹¹ÁËÒ»¸ö´øÓÐÓÕ¶üÄÚÈݺͶñÒâÁ´½ÓµÄmhtÎļþ£¬³ÆÎª“Chrome_85_RCE_Full_Exploit_Code.mht”£¬¾ÓÉSNSµÈÇþµÀ·¢Ë͸øÇå¾²Ñо¿Õߣ¬¸ÃmhtÎļþЯ´ø¶ñÒâµÄJSÄÚÈÝ£¬»áͨ¹ýÖ¸¶¨urlÏÂÔØJSľÂí£¬×îÖÕͶµÝ´øÓÐInternet Explorer 0dayÎó²îµÄ¹¥»÷ÔØºÉ£¬½«shellcodeľÂíÖ²ÈëÊܺ¦ÕßÖ÷»úµ±ÖС£
¡¾¹ØÁªµÄ¹¥»÷×éÖ¯¡¿
Lazarus Group£¨ÓÖÃû HIDDEN COBRA¡¢Guardians of Peace¡¢ZINC ºÍ NICKEL ACADEMY£©ÊÇÒ»¸öÍþв ×éÖ¯£¬¹éÊôÓÚ³¯ÏÊÕþ¸®£¬¸Ã×éÖ¯ÖÁÉÙ´Ó 2009 ÄêÒÔÀ´Ò»Ö±»îÔ¾¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/stumpzarus-apt-lazarus/
https://enki.co.kr/blog/2021/02/04/ie_0day.html
https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡5ÌõIOC£¬ÆäÖаüÀ¨5¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
3. KUBERNETES¼¯ÈºÔâÍÚ¿óľÂíͻϮ
¡¾±êÇ©¡¿KUBERNETES
¡¾Ê±¼ä¡¿2021-02-23
¡¾¼ò½é¡¿
2021ÄêÄêÍ·£¬TeamTNTÍŻﱻ·¢Ã÷ÈëÇÖÁËijKubernetes¼¯Èº£¬Í¨¹ýÍŽá¾ç±¾ºÍÏÖÓй¤¾ß£¬×îÖÕÔÚÈÝÆ÷ÄÚÖ²ÈëÃÅÂÞ±ÒÍÚ¿óľÂí¡£
¡¾¹ØÁªµÄ¹¥»÷×éÖ¯¡¿
TeamTNTÊÇÒ»¸öÖ÷ÒªÈëÇÖÔÚÏßÈÝÆ÷²¢Í¨¹ýÍÚ¿óºÍDDoS¾ÙÐÐIJÀûµÄ¹¥»÷ÍŻ
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/kubernetes%e9%9b%86%e7%be%a4%e9%81%ad%e6%8c%96%e7%9f%bf%e6%9c%a8%e9%a9%ac%e7%aa%81%e8%a2%ad/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡31ÌõIOC£¬ÆäÖаüÀ¨7¸öIP£¬5¸öÓòÃûºÍ19¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
4. Kasablanka×éÖ¯Õë¶ÔWindowsºÍAndroidƽ̨µÄ¹¥»÷Ô˶¯
¡¾±êÇ©¡¿Kasablanka
¡¾Ê±¼ä¡¿2021-02-09
¡¾¼ò½é¡¿
LodaRATа汾Ìí¼ÓAndroid×÷ΪĿµÄƽ̨£¬²¢ÔÚÕë¶ÔWindowsµÄа汾ÖÐÌí¼ÓµÈ¼Òô¹¦Ð§¡£½üÆÚKasablanka×é֯ʹÓÃLodaRATа汾Õë¶ÔÃϼÓÀ¹ú¾ÙÐÐÍøÂçÌØ¹¤Ô˶¯£¬Ö¼´ÓAndroidºÍWindowsƽ̨ÖÐÍøÂçÃô¸ÐÐÅÏ¢¡£
¡¾¹ØÁªµÄ¹¥»÷×éÖ¯¡¿
Kasablanka£¬ÓÖÃûKasablanca£¬ÊÇÒ»¸öÒÔÐÅÏ¢ÇÔȡΪĿµÄµÄÍþв×éÖ¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.talosintelligence.com/2021/02/kasablanka-lodarat.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡25ÌõIOC£¬ÆäÖаüÀ¨3¸öIP£¬8¸öÓòÃûºÍ14¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
5. ¹¥»÷ÕßʹÓÃBendyBearÕë¶Ô¶à¸ö¶«ÑÇÕþ¸®×éÖ¯
¡¾±êÇ©¡¿BendyBear
¡¾Õë¶ÔÐÐÒµ¡¿Õþ¸®
¡¾Ê±¼ä¡¿2021-02-09
¡¾¼ò½é¡¿
½üÆÚ¹¥»÷ÕßʹÓÃBendyBear¶ñÒâÈí¼þÕë¶Ô¶à¸ö¶«ÑÇÕþ¸®×éÖ¯Ìᳫ¹¥»÷Ô˶¯£¬´Ë´Î¹¥»÷Ô˶¯ÒÉËÆÓÐBlackTech×éÖ¯Óйأ¬¸Ã×éÖ¯×îÔç¿É×·Ëݵ½2014Äê¡£
¡¾¹ØÁªµÄ¹¥»÷×éÖ¯¡¿
BlackTechÊÇÒ»¸ö×îÔç»îÔ¾ÓÚ2014Äê7ÔµÄÍøÂçÌØ¹¤×éÖ¯£¬Ö÷ÒªÕë¶Ô¶«ÑÇ£¨ÓÈÆäÊÇ̨Í壩¾ÙÐÐÌØ¹¤Ô˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://unit42.paloaltonetworks.com/bendybear-shellcode-blacktech/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡7ÌõIOC£¬ÆäÖаüÀ¨7¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
6. ºÚ¿ÍʹÓÃMassloggerľÂí±äÖÖÇÔÈ¡Óû§Æ¾Ö¤µÄ¹¥»÷Ô˶¯
¡¾±êÇ©¡¿Masslogger
¡¾Ê±¼ä¡¿2021-02-17
¡¾¼ò½é¡¿
MassloggerÊÇÒ»¸öÓÃ.NET±àдµÄÌØ¹¤Èí¼þ³ÌÐò£¬Ö÷ÒªÊÇ´Óä¯ÀÀÆ÷ÖÐÇÔÈ¡Óû§Æ¾Ö¤£¬»¹´ÓһЩʢÐеÄÐÂÎÅÊÕ·¢Ó¦ÓóÌÐòºÍµç×ÓÓʼþ¿Í»§¶ËÖÐÇÔÈ¡Óû§Æ¾Ö¤¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.talosintelligence.com/2021/02/masslogger-cred-exfil.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡13ÌõIOC£¬ÆäÖаüÀ¨13¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
7. FreakOutʹÓÃ×îÐÂÎó²î½¨Éè½©Ê¬ÍøÂç
¡¾±êÇ©¡¿FreakOut
¡¾Ê±¼ä¡¿2021-02-19
¡¾¼ò½é¡¿
2021Äê1ÔÂÉÏÑ®£¬CNCERTÎïÁªÍøÍþвÆÊÎöÍŶÓͨ¹ýʵʱÔËתµÄÊý¾Ýƽ̨²¶»ñµ½Ò»ÖÖδ֪¶ñÒâ³ÌÐòout.py£¬ËüµÄµä·¶Èö²¥ÓòÃûΪgxbrowser.net¡£AG¹«Ë¾¿Æ¼¼·üӰʵÑéÊҶԸóÌÐòÑù±¾¡¢Èö²¥PayloadµÈ¾ÙÐÐÉîÈëÑо¿£¬²¢Ó뿪ԴÇ鱨¾ÙÐбȶԣ¬È·ÈÏËüÊÇÒ»ÖÖÐÂÐͽ©Ê¬ÍøÂç¼Ò×å¡£1ÔÂÖÐÏÂÑ®£¬¶à¼Òº£ÄÚÍ⹫˾Ҳ·¢Ã÷ÁËÕâ¸ö¶ñÒâ³ÌÐò£¬ÓÉÓÚËüµÄÃû³ÆÎªout.py£¬ÇÒ¹ØÁªµ½µÄ¹¥»÷Õß´úºÅΪFreak£¬Òò´Ë¸Ã¼Ò×å±»ÃüÃûΪFreakOut£¬¸Ã¶ñÒâ³ÌÐòÔÚÈö²¥ÖÐʹÓÃÁËCVE-2020-28188¡¢CVE-2020-7961ºÍCVE-2021-3007Èý¸öÎó²î¡£
¡¾²Î¿¼Á´½Ó¡¿
https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡4ÌõIOC£¬ÆäÖаüÀ¨4¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
8. H2MinerÍÚ¿óÍÅ»ïʹÓöà¸öÎó²îÎäÆ÷¹¥»÷ÔÆÉÏÖ÷»ú
¡¾±êÇ©¡¿H2Miner
¡¾Ê±¼ä¡¿2021-02-22
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±¼ì²âµ½´º½Úʱ´úH2MinerÍÚ¿óÍÅ»ïÒì³£»îÔ¾£¬¸ÃÍÅ»ïʹÓöà¸öÎó²îÎäÆ÷¹¥»÷ÔÆÉÏÖ÷»úÍڿ󣬳ýʹÓøÃÍÅ»ïϰÓõÄXXL-JOBδÊÚȨÏÂÁîÖ´Ðй¥»÷Ö®Í⣬»¹Ê¹ÓÃÁËPHPUnitÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2017-9841)¡¢SupervisordÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2017-11610£©ºÍThinkPHP 5.XÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¾ÙÐй¥»÷À©É¢£¬×îÖÕͶµÝÃûΪkdevtmpfsiµÄXMRÃÅÂÞ±Ò¿ó»ú×é¼þÍÚ¿óIJÀû¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com//research/report/1254.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡6ÌõIOC£¬ÆäÖаüÀ¨2¸öIP£¬1¸öÓòÃûºÍ3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
9. NightScouÕë¶ÔÑÇÖÞÔÚÏßÓÎÏ·ÉçÇøµÄÍøÂçÌØ¹¤Ô˶¯
¡¾±êÇ©¡¿NightScou
¡¾Õë¶ÔÐÐÒµ¡¿ÔÚÏßÓÎÏ·ÉçÇø
¡¾Ê±¼ä¡¿2021-02-01
¡¾¼ò½é¡¿
ESETµÄÑо¿Ö°Ô±·¢Ã÷ÁËÒ»¸ö¹©Ó¦Á´¹¥»÷£¬ÓÃÓÚÕë¶ÔÑÇÖÞÔÚÏßÓÎÏ·ÉçÇøµÄÍøÂçÌØ¹¤Ðж¯¡£2021Äê1Ô£¬¸ÃÍŶӷ¢Ã÷ÁËÒ»¸öÐµĹ©Ó¦Á´¹¥»÷£¬²¢ÇÒÆÆËðÁËNoxPlayerµÄ¸üлúÖÆ£¬NoxPlayerÊÇÒ»¸öÓÃÓÚpcºÍmacµÄAndroid·ÂÕæÆ÷£¬ÊÇBigNox²úƷϵÁеÄÒ»²¿·Ö£¬ÔÚÈ«ÇòÓµÓÐÁè¼Ý1.5ÒÚÓû§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.welivesecurity.com/2021/02/01/operation-nightscout-supply-chain-attack-online-gaming-asia/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡11ÌõIOC£¬ÆäÖаüÀ¨4¸öIP£¬3¸öÓòÃûºÍ4¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
10. ¹¥»÷ÕßʹÓÃKobalos¶ñÒâÈí¼þÕë¶Ô¸ßÐÔÄÜÅÌË㼯Ⱥ£¨HPC£©µÄ¹¥»÷Ô˶¯
¡¾±êÇ©¡¿Kobalos
¡¾Ê±¼ä¡¿2021-02-02
¡¾¼ò½é¡¿
ESETµÄÑо¿Ö°Ô±ÆÊÎöÁËÕë¶Ô¸ßÐÔÄÜÅÌË㣨HPC£©¼¯ÈººÍÆäËû¸ß¹Ø×¢Ä¿µÄµÄ¶ñÒâÈí¼þ¡£ËûÃǶÔÕâ¸öС¶øÖØ´óµÄ¶ñÒâÈí¼þ¾ÙÐÐÁË·´Ïò¹¤³Ì£¬¶ñÒâÈí¼þ¿ÉÒÔÒÆÖ²µ½Ðí¶à²Ù×÷ϵͳ£¬°üÀ¨Linux¡¢BSD¡¢Solaris£¬ÉõÖÁAIXºÍWindows¡£ËûÃǽ«Õâ¸ö¶ñÒâÈí¼þÃüÃûΪKobalos¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.welivesecurity.com/2021/02/02/kobalos-complex-linux-threat-high-performance-computing-infrastructure/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡10ÌõIOC£¬ÆäÖаüÀ¨10¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
11. ÍøÂç×ﷸʹÓÃAccelion FTA¾ÙÐÐÊý¾Ý͵ÇÔºÍÀÕË÷µÄ¹¥»÷Ô˶¯
¡¾±êÇ©¡¿Accelion FTA
¡¾Ê±¼ä¡¿2021-02-22
¡¾¼ò½é¡¿
´Ó2020Äê12ÔÂÖÐÑ®×îÏÈ£¬MandiantÔÚUNC2546¸ú×ٵĶñÒâÐÐΪÕßʹÓÃÁËAccellionµÄ¾ÉʽÎļþ´«Êä×°±¸£¨FTA£©ÖеĶà¸öÁãÈÕÎó²î£¬×°ÖÃÁËÒ»¸öз¢Ã÷µÄÃûΪDEWMODEµÄWeb Shell£¬ÔÚÔËÐоɰæFTA²úÆ·£¨ÈçUNC2546£©Ê±Ê¹ÓÃAccellion FTAÎó²î¾ÙÐÐÊý¾Ý͵ÇÔ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.fireeye.com/blog/threat-research/2021/02/accellion-fta-exploited-for-data-theft-and-extortion.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡8ÌõIOC£¬ÆäÖаüÀ¨6¸öIPºÍ2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

AG¹«Ë¾ÔÆ







