¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2021Äê7Ô£©
2021-08-02
7Ô£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬EximÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ£¨CVE-2020-28020£©ºÍLinuxÄÚºËȨÏÞÌáÉýÎó²îͨ¸æ£¨CVE-2021-33909£©Ó°Ïì¹æÄ£½Ï´ó¡£Ç°ÕßÔ´ÓÚreceive_msgº¯Êý£¬»ùÓÚEximÕûÊýÒç³öÎó²î£¬¹¥»÷Õß¿ÉÒÔͨ¹ý”\\n”ÈÆ¹ýExim¶ÔÓʼþÍ·¾ÞϸµÄÏÞÖÆ£¬´Ó¶øÔì³ÉÕûÊýÒç³ö£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓôËÎó²îÔì³É¾Ü¾ø·þÎñ»òÔ¶³Ì´úÂëÖ´ÐС£CVSSÆÀ·ÖΪ9.8£»ºóÕßΪLinuxÄں˵Äseq_file½Ó¿Ú±£´æsize_t-to-intÀàÐÍת»»Îó²î£¬ÓÉÓÚfs/seq_file.cûÓÐ׼ȷÏÞÖÆseq»º³åÇø·ÖÅÉ£¬´Ó¶øµ¼ÖÂÕûÊýÒç³ö¡¢Ô½½çдÈëÒÔ¼°È¨ÏÞÌáÉý¡£í§ÒâÓû§È¨Ï޵Ĺ¥»÷Õß¶¼¿ÉÒÔÔÚĬÈÏÉèÖÃÖÐʹÓôËÎó²î£¬´Ó¶ø»ñµÃÊÜÓ°ÏìÖ÷»úµÄrootȨÏÞ¡£¸ÃÎó²îÓ°ÏìÁË×Ô2014ÄêÒÔÀ´Ðû²¼µÄËùÓÐLinuxÄں˰汾£¬ÏÖÔÚPoCÒѹûÕæ£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤£¬CVSS ÆÀ·ÖΪ8.4¡£
ÁíÍ⣬±¾´Î΢ÈíÐÞ¸´ÁË13¸öCritical¼¶±ðÎó²î£¬103¸öImportant¼¶±ðÎó²î£¬Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£
ÔÚ±¾ÔµÄÍþвÊÂÎñÖУ¬¶ÔÏà¹ØÆóÒµ£¬Õþ¸®×éÖ¯µÄ¹¥»÷ÊÂÎñ½ÏÁ¿ÆµÈÔ£¬ÆäÖаüÀ¨¹¥»÷ÕßʹÓÃNetwireRAT¶ñÒâÈí¼þ¶ÔÕþ¸®×éÖ¯Õö¿ªÕë¶ÔÐÔ¹¥»÷£¬ÆäÖй¥»÷Õß½«Ä¿µÄËø¶¨ÔÚ°Í»ù˹̹µÄÖÖÖÖ×éÖ¯£¬NetwiredRC±»ÓÃ×÷Õâ´Î¹¥»÷Ô˶¯µÄ×îÖÕÓÐÓÃÔØºÉ¡£TA402×é֯ʹÓÃжñÒâÈí¼þLastConn¹¥»÷Öж«¸÷¹úÕþ¸®£¬TA402ʹÓÃÕþÖκ;üÊÂÖ÷Ì⣬°üÀ¨¼ÓɳµØ´øÒ»Á¬µÄ³åÍ»£¬ÓÕʹÓû§·¿ª¸½²¢µã»÷¶ñÒâÁ´½Ó¡£PuzzleMaker×éÖ¯¶ÔÈ«ÇòÆóÒµÕö¿ª¹¥»÷Ô˶¯£¬ÕâЩ¹¥»÷¶¼Ê¹ÓÃÁËһϵÁÐGoogleChromeºÍMicrosoftWindows0dayÎó²î¡£DarkCaracalʹÓöñÒâÈí¼þ¹¥»÷Î÷°àÑÀÓï¹ú¼ÒÆóÒµÍøÂçÔ˶¯£¬REvilʹÓù©Ó¦Á´Îó²î¹¥»÷Êý°Ù¼ÒÆóÒµ£¬Õë¶ÔÍйܷþÎñÌṩÉ̵Ŀͻ§ºÍKaseyaVSAÔ¶³Ì¼à¿ØºÍÖÎÀíÆ½Ì¨ÏÖ³¡°æµÄÆóÒµÓû§ÌᳫÁËÒ»¸ö¶ñÒâ¸üаü¡£
ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/
Ò»¡¢ Îó²îÌ¬ÊÆ
2021Äê07ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼603¸öÎó²î,ÆäÖиßΣÎó²î83¸ö£¬Î¢Èí¸ßΣÎó²î35¸ö¡£
*Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2021.08.02
×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»
¶þ¡¢ ÍþвÊÂÎñ
1. Mirai_ptea½©Ê¬ÍøÂçʹÓÃKGUARDDVRÎó²î¾ÙÐй¥»÷ÍøÕ¾
¡¾±êÇ©¡¿Mirai_ptea
¡¾Ê±¼ä¡¿2021-07-01
¡¾¼ò½é¡¿
2021Äê6ÔÂ22ÈÕ£¬ÎÒÃǼì²âµ½Ò»¸öMirai±äÌåÑù±¾£¬½«ÆäÃüÃûΪmirai_ptea½©Ê¬ÍøÂç,¸Ã½©Ê¬ÍøÂç±»ÓÃÓÚÒ»Á¬µÄDDoS¹¥»÷£¬²¢½«´ËÑù±¾Í¨¹ýKGUARDDVRµÄÐÂÎó²î¾ÙÐÐÈö²¥¡£Mirai_ptea½©Ê¬ÍøÂçʹÓÃKGUARDDVRÎó²î¾ÙÐй¥»÷ÍøÕ¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.netlab.360.com/mirai_ptea-botnet-is-exploiting-undisclosed-kguard-dvr-vulnerability-en/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡14ÌõIOC£¬ÆäÖаüÀ¨5¸öIP£¬7¸öÓòÃûºÍ2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
2. REvilʹÓù©Ó¦Á´Îó²î¹¥»÷Êý°Ù¼ÒÆóÒµ
¡¾±êÇ©¡¿REvil
¡¾Ê±¼ä¡¿2021-07-04
¡¾¼ò½é¡¿
7ÔÂ2ÈÕ£¬ËäÈ»Ðí¶àÆóÒµµÄÔ±¹¤ÒªÃ´ÒѾϰ࣬Ҫô׼±¸¶È¹ýÒ»¸ö³¤¼ÙÖÜÄ©£¬REvilÀÕË÷Èí¼þ×éÖ¯µÄÒ»¸öÁ¥Êô»ú¹¹ÌᳫÁËÒ»³¡ÆÕ±éµÄ¼ÓÃÜÀÕË÷Õ½ÂÔ¡£REvil¹¥»÷ÕßʹÓÃKaseyaVSAÔ¶³ÌÖÎÀí·þÎñµÄÎó²î£¬Õë¶ÔÍйܷþÎñÌṩÉ̵Ŀͻ§ºÍKaseyaVSAÔ¶³Ì¼à¿ØºÍÖÎÀíÆ½Ì¨ÏÖ³¡°æµÄÆóÒµÓû§ÌᳫÁËÒ»¸ö¶ñÒâ¸üаü¡£
¡¾²Î¿¼Á´½Ó¡¿
https://news.sophos.com/en-us/2021/07/04/independence-day-revil-uses-supply-chain-exploit-to-attack-hundreds-of-businesses/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡5ÌõIOC£¬ÆäÖаüÀ¨3¸öÓòÃûºÍ2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
3. DarkCaracalʹÓöñÒâÈí¼þ¹¥»÷Î÷°àÑÀÓï¹ú¼ÒÆóÒµÍøÂçÔ˶¯
¡¾±êÇ©¡¿DarkCaracal
¡¾Ê±¼ä¡¿2021-07-07
¡¾¼ò½é¡¿
2021Ä꣬DarkCaracalÕë¶ÔÎ÷°àÑÀÓï¹ú¼ÒÆóÒµÍøÂçµÄÒ»Á¬¹¥»÷Ô˶¯£¬ÆäÖÐ90%µÄ¼ì²â±¬·¢ÔÚίÄÚÈðÀ¡£½«´ËÔ˶¯ÖÐʹÓõĶñÒâÈí¼þÓë֮ǰ¼Í¼µÄÄÚÈݾÙÐнÏÁ¿Ê±£¬ÎÒÃÇ·¢Ã÷Á˴˶ñÒâÈí¼þµÄй¦Ð§£¬³ÆÎªBandook¡£ÎÒÃÇ»¹·¢Ã÷£¬ÕâÏîÕë¶ÔίÄÚÈðÀµÄÔ˶¯×Ô2015ÄêÒÔÀ´Ò»Ö±ºÜ»îÔ¾£¬µ«²»ÖªºÎÒÔÈÔȻûÓмͼ¡£¼øÓÚËùʹÓõĶñÒâÈí¼þºÍÄ¿¿ÚºÅÑÔÇéÐΣ¬ÎÒÃÇÑ¡Ôñ½«´ËÔ˶¯ÃüÃûΪBandidos¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.welivesecurity.com/2021/07/07/bandidos-at-large-spying-campaign-latin-america/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡3ÌõIOC£¬ÆäÖаüÀ¨3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
4. ¹¥»÷ÕßʹÓÃ¿çÆ½Ì¨È䳿²¡¶¾HolesWarm¹¥»÷windowsºÍlinuxϵͳ
¡¾±êÇ©¡¿HolesWarm
¡¾Ê±¼ä¡¿2021-07-12
¡¾¼ò½é¡¿
Çå¾²Ñо¿Ôº½üÆÚÒ»¿îÃûΪHolesWarmµÄ¿çƽ̨È䳿²¡¶¾£¬¸ÃÈ䳿²¡¶¾½üÆÚÀ©É¢Ê®·ÖѸËÙ£¬ËùʹÓõÄÎó²îÎäÆ÷Ôڶ̶ÌÒ»¸öÔµÄʱ¼äÀï¾ÍÁè¼Ý20ÖÖ£¬¿°³Æ“Îó²îʹÓÃÍõÕß”¡£×Ô6ÔÂÉÏÑ®ÒÔÀ´£¬HolesWarmÒÑÔì³É¶à´ÎÈëÇÖá¯Á룬Àۼƹ¥ÏÝÔÆÖ÷»ú¹ýǧ̨£¬¾ÆÊÎö£¬HolesWarm²¡¶¾»áʹÓú£ÄÚʹÓÃÂʽϸߵÄÍøÂç×é¼þ¸ßΣÎó²î¹¥»÷Èö²¥£¬°üÀ¨º£ÄÚ³£ÓõÄÓÃÓÑ¡¢ÖÂÔ¶µÈ°ì¹«×é¼þ£¬ÒÔ¼°Tomcat¡¢Weblogic¡¢Shiro¡¢Structs2¡¢XXL-JOB¡¢Springboot¡¢JenkinsµÈ20Óà¸öÍøÂç×é¼þ¾ùÊÜÓ°Ï죬¹¥»÷Õß½ÓÊÜÔÆ¿Ø·þÎñÆ÷Ö¸ÁîÒ»Ö±¸üй¥»÷Ä£¿éºÍ¹¥»÷Ä¿µÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com/research/report/78
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡9ÌõIOC£¬ÆäÖаüÀ¨1¸öÓòÃûºÍ8¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
5. ¹¥»÷ÕßʹÓÃNetwireRAT¶ñÒâÈí¼þ¶ÔÕþ¸®×éÖ¯Õö¿ªÕë¶ÔÐÔ¹¥»÷
¡¾±êÇ©¡¿NetwireRAT
¡¾Ê±¼ä¡¿2021-07-14
¡¾¼ò½é¡¿
Çå¾²Ñо¿Ô±ÊӲ쵽´Ó2021Äê7ÔÂ×îÏȵÄÒ»¸öÓÐȤµÄÓã²æÊ½ÍøÂç´¹ÂÚÔ˶¯£¬ÆäÖй¥»÷Õß½«Ä¿µÄËø¶¨ÔÚ°Í»ù˹̹µÄÖÖÖÖ×éÖ¯¡£NetwiredRC±»ÓÃ×÷Õâ´Î¹¥»÷Ô˶¯µÄ×îÖÕÓÐÓÃÔØºÉ¡£Óã²æÊ½ÍøÂç´¹ÂÚºÍʹÓÃÐÅÏ¢ÇÔÈ¡RATµÄÍŽáÅú×¢Õâ²»ÊǼòÆÓµÄÍøÂç·¸·¨£¬¶øÊÇÕë¶Ô°Í»ù˹̹¶à¸öÕþ¸®×éÖ¯ÒÔ¼°ÆäËû±ÊÖ±ÐÐÒµµÄ¸ü´óÍøÂç¹¥»÷Ô˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.zscaler.com/blogs/security-research/targeted-attack-government-organizations-delivers-netwire-rat
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡8ÌõIOC£¬ÆäÖаüÀ¨1¸öIPºÍ7¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
6. APT×éÖ¯FIN7ʹÓÃWINDOWS11»°ÌâÓÕ¶üµÄÓã²æ¹¥»÷Ô˶¯
¡¾±êÇ©¡¿FIN7
¡¾Ê±¼ä¡¿2021-07-16
¡¾¼ò½é¡¿
½üÆÚ£¬·üӰʵÑéÊÒ²¶»ñÁ˶à¸öʹÓÃwindows11Ïà¹Ø»°Ìâ×÷ΪÓÕ¶üµÄ´¹ÂÚÎĵµ¡£ÕâЩ´¹ÂÚÎĵµÏÔʾÁËһЩ²î±ðÓÚ³£¼û´¹ÂÚ¹¥»÷µÄ˼Ð÷ºÍ¼¼ÇÉ¡£Í¨¹ýÉîÈëÆÊÎö£¬·üӰʵÑéÊÒ·¢Ã÷ÕâЩ´¹ÂÚÎĵµÊÇFIN7×éÖ¯ÕýÔÚ¾ÙÐеĴó¹æÄ£Óã²æ¹¥»÷Ô˶¯µÄÒ»²¿·Ö£¬ÆäÊͷŵÄľÂíÏÖʵÉÏÊǸÃ×éÖ¯³£ÓõÄGriffonľÂíµÄ½ÏбäÖÖ¡£´¹ÂÚÎĵµÓëºóÐø¹¥»÷×é¼þµÄÊÖÒÕϸ½ÚÏÔʾ£¬FIN7×éÖ¯ÔÚ±¾´ÎÓã²æ¹¥»÷Ô˶¯ÖÐ×îÏȸüƵÈԵؼì²âÖ÷»úÇéÐΣ¬²¢ÔÚÑÚÊι¥»÷ºÛ¼£·½ÃæÆÆ·ÑÁ˸ü¶à¾«Éñ¡£ÕâЩ´¹ÂÚÎĵµÔÙ´Î֤ʵ£¬FIN7×éÖ¯²¢Î´Òò2018ÄêµÄ¼¯ÖÐ×¥²¶Ðж¯¶øÇýÖ𣬶øÊÇÔڸıäÁËı»®Ä£Ê½ºó£¬¸üÉóÉ÷µØ¾ÙÐÐÒÔ͵ȡ½ðÈÚ×ʲúΪÖ÷µÄÍøÂç·¸·¨Ô˶¯¡£Çå¾²³§ÉÌÓ¦Ç×½ü×¢ÖØÊ¹ÓÃFIN7×éÖ¯ÒÑÖª¹¥»÷¹¤¾ßµÄÖÖÖÖ¹¥»÷Ô˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/apt-windows11/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡12ÌõIOC£¬ÆäÖаüÀ¨2¸öIP£¬1¸öÓòÃûºÍ9¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
7. ¹¥»÷ÕßʹÓÃURLËõ¶ÌÆ÷·þÎñÏòAndroidÓû§·Ö·¢¶ñÒâÈí¼þFakeAdBlocker
¡¾±êÇ©¡¿FakeAdBlocker
¡¾Ê±¼ä¡¿2021-07-20
¡¾¼ò½é¡¿
ÍþвÑо¿Ô±½üÆÚ·¢Ã÷£¬Óû§ÊÕµ½Ò»Ð©URLµã»÷ºó»áµ¯³ö¹ã¸æ£¬ÕâЩ¹ã¸æÊ¹ÓõÄÊÇһЩÁ´½ÓËõ¶Ì·þÎñʹÓü¤½øµÄ¹ã¸æÊÖÒÕ£¬Í¨ÖªÓû§ËûÃǵÄ×°±¸Ñ¬È¾ÁËΣÏյĶñÒâÈí¼þ£¬Ö¸µ¼Óû§´ÓGooglePlayÊÐËÁÏÂÔØ¿ÉÒɵÄÓ¦ÓóÌÐò»ò¼ÓÈë¿ÉÒɵÄÊӲ죬Ìṩ³ÉÈËÄÚÈÝ£¬Ìṩ×îÏȸ߼¶SMS·þÎñ¶©ÔÄ£¬ÆôÓÃä¯ÀÀÆ÷֪ͨµÈ¡£»¹·¢Ã÷ÁËһЩÁ´½ÓËõ¶Ì·þÎñ½«“ÈÕÀú”ÎļþÍÆË͵½iOS×°±¸²¢·Ö·¢Android¶ñÒâÈí¼þ——ÎÒÃǽ«ÆäÃüÃûΪAndroid/FakeAdBlockerµÄ¶ñÒâÈí¼þ£¬ËüÏÂÔØ²¢Ö´ÐÐÌØÁíÍâÓÐÓÃÔØºÉ£¨ÀýÈçÒøÐÐľÂí¡¢¶ÌÐÅľÂí¡¢ºÍ¹¥»÷ÐÔ¹ã¸æÈí¼þ£©´ÓÆäC·þÎñÆ÷ÊÕµ½¡£
¡¾²Î¿¼Á´½Ó¡¿
7https://www.welivesecurity.com/2021/07/20/url-shortener-services-android-malware-banking-sms-trojans/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡18ÌõIOC£¬ÆäÖаüÀ¨15¸öÓòÃûºÍ3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
8. ¹¥»÷ÕßʹÓöñÒâÈí¼þXLoaderÇÔÈ¡WindowsºÍmacOSµÄ·þÎñÐÅÏ¢
¡¾±êÇ©¡¿XLoader
¡¾Ê±¼ä¡¿2021-07-26
¡¾¼ò½é¡¿
¹¥»÷ÕßÕë¶ÔÏÖÔÚÖ÷Òª²Ù×÷ϵͳ¹©Ó¦É̶ԶñÒâÈí¼þ¾ÙÐÐÏà¹Øµ÷½â£¬¿ÉÒÔÔÚÒ»¸öƽ̨ÉϱàÒëÌìÉúÕë¶Ô¶à¸öƽ̨µÄ¿ÉÖ´ÐÐÎļþ¡£Ñо¿Ö°Ô±×îз¢Ã÷µÄ¶ñÒâÈí¼þÊÇXLoader£¬³Æ´Ë¶ñÒâÈí¼þXLoaderÊÇͨ¹ýFormBookÖпª·¢³öÀ´µÄ¡£¼´·þÎñÐÅÏ¢ÇÔÈ¡Æ÷ºÍ¼üÅ̼ͼÆ÷£¬¹¥»÷Õß¿ÉÒÔʹÓöñÒâÈí¼þXLoaderͬʱÔÚWindowsºÍmacOS°æ±¾ÉÏÇÔÈ¡·þÎñÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.sentinelone.com/blog/detecting-xloader-a-macos-malware-as-a-service-info-stealer-and-keylogger/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡13ÌõIOC£¬ÆäÖаüÀ¨10¸öIPºÍ3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
9. ¹¥»÷ÕßʹÓÃPlugX±äÌå¹¥»÷MicrosoftExchangeServer
¡¾±êÇ©¡¿PlugX
¡¾Ê±¼ä¡¿2021-07-27
¡¾¼ò½é¡¿
2021Äê3Ô£¬Ñо¿Ö°Ô±ÔÚ¼à²âMicrosoftExchangeServer¹¥»÷ʱ£¬·¢Ã÷ÁËÒ»ÖÖPlugXбäÌ壬¹¥»÷ÕßʹÓÃPlugXбäÌå¹¥»÷MicrosoftExchangeServer¡£¸ÃPlugX±äÌåÊÇ×÷Ϊһ¸ö±»¹¥»÷·þÎñÆ÷ʹÓúóÔ¶³Ì»á¼û¹¤¾ß(RAT)´«Ë͵½ÆäÖÐһ̨·þÎñÆ÷¡£PlugX±äÌ寿ÒìÖ®´¦ÔÚÓÚ¶Ô½¹µãÔ´´úÂëµÄ¸ü¸Ä¡£
¡¾²Î¿¼Á´½Ó¡¿
https://unit42.paloaltonetworks.com/thor-plugx-variant/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡120ÌõIOC£¬ÆäÖаüÀ¨18¸öIP£¬23¸öÓòÃûºÍ79¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
10. Outlawͨ¹ýÈëÇÖSSH¹«Ô¿´ó¹æÄ£¹¥»÷ÔÆÖ÷»ú
¡¾±êÇ©¡¿Outlaw
¡¾Ê±¼ä¡¿2021-07-28
¡¾¼ò½é¡¿
Çå¾²Ñо¿Ô±ÆÊÎöÖ÷»úÇå¾²¼à²âÊý¾Ýʱ·¢Ã÷£¬Outlaw½©Ê¬ÍøÂçÍÅ»ïÔÚ½ñÌìÆÆÏþ×óÓÒͨ¹ýÈëÇÖSSH¹«Ô¿¶ÔÔÆÖ÷»úÌᳫ´ó¹æÄ£¹¥»÷£¬¹¥»÷ÕßÖ÷Ҫͨ¹ýÈëÇÖSSH¹«Ô¿»ñÈ¡µÇ¼ÃÜÂëºóдÈëSSH¹«Ô¿£¬È»ºóÖ´ÐжñÒâ³ÌÐò£¬Ò»µ©¹¥»÷ÔÆÖ÷»úÀֳɣ¬¹¥»÷Õß»áдÈëеÄSSH¹«Ô¿£¬ÉèÖÃÔ¶³ÌµÇ¼ÍêÈ«¿ØÖÆ·þÎñÆ÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com/research/report/91
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡2ÌõIOC£¬ÆäÖаüÀ¨2¸öIP£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

AG¹«Ë¾ÔÆ







