¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Ô±¨£¨2021Äê9Ô£©
2021-09-30
9Ô£¬AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©Ðû²¼Á˶à¸öÎó²îºÍÍþвÊÂÎñͨ¸æ£¬ÆäÖУ¬MicrosoftMSHTMLÔ¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ£¨CVE-2021-40444£©ºÍVMwarevCenterServerºÍApacheShiroÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îͨ¸æ£¨£¨CVE-2021-41303£©Ó°Ïì¹æÄ£½Ï´ó£¬Ç°Õß¹¥»÷Õß¿Éͨ¹ýÖÆ×÷¶ñÒâµÄActiveX¿Ø¼þ¹©ÍйÜä¯ÀÀÆ÷·ºÆðÒýÇæµÄMicrosoftOfficeÎĵµÊ¹Óã¬ÀÖ³ÉÓÕµ¼Óû§·¿ª¶ñÒâÎĵµºó£¬¿ÉÔÚÄ¿µÄϵͳÉÏÒÔ¸ÃÓû§È¨ÏÞÖ´ÐÐí§Òâ´úÂë¡£CVSSÆÀ·ÖΪ9.5£»ºóÕßµ±ÔÚSpringBootÖÐʹÓÃApacheShiroʱ£¬¹¥»÷Õß¿ÉÒÔ½á¹¹ÌØ¶¨µÄHTTPÇëÇóÈÆ¹ýÉí·ÝÑéÖ¤»á¼ûºǫ́¹¦Ð§£»ÇëÏà¹ØÓû§½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£ApacheShiroÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢ÇÒÒ×ÓÚʹÓõÄJavaÇå¾²¿ò¼Ü£¬¹¦Ð§°üÀ¨Éí·ÝÑéÖ¤¡¢ÊÚȨ¡¢¼ÓÃܺͻỰÖÎÀí¡£Ê¹ÓÃShiroµÄAPI£¬¿ÉÒÔÇáËɵء¢¿ìËٵر£»¤ÈκÎÓ¦ÓóÌÐò£¬¹æÄ£´ÓСÐ͵ÄÒÆ¶¯Ó¦ÓóÌÐòµ½´óÐ͵ÄWebºÍÆóÒµÓ¦ÓóÌÐò¡£CVSSÆÀ·ÖΪ9.0¡£
ÁíÍ⣬±¾´Î΢ÈíÐÞ¸´ÁË86¸öÎó²î£¬°üÀ¨3¸öCritical¼¶±ðÎó²î£¬62¸öImportant¼¶±ðÎó²î£¬1¸öModerate¼¶±ðÎó²î£¬ÆäÖл¹°üÀ¨9Ô³õÐÞ¸´µÄ20¸öMicrosoftEdge(Chromium)Îó²î¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£
ÔÚ±¾ÔµÄÍþвÊÂÎñÖУ¬Õë¶ÔÏà¹ØÆóҵϵͳ¹¥»÷ÊÂÎñ½ÏÁ¿ÆµÈÔ£¬ÆäÖаüÀ¨Lazarus×éÖ¯Õë¶Ô¼ÓÃÜÇ®±ÒÐÐÒµµÄÉ繤¹¥»÷£¬Ñо¿Ö°Ô±²¶»ñµ½ÁËLazarus×éÖ¯Õë¶Ô¼ÓÃÜÇ®±ÒÏà¹ØÐÐÒµµÄÉ繤¹¥»÷Ô˶¯£¬¸Ã×éÖ¯ÔÚѰÕÒµ½¹¥»÷Ä¿µÄÐÅÏ¢ºó£¬ÒÉËÆÍ¨¹ý¼´Ê±Í¨Ñ¶Èí¼þ×Ô¶¯ºÍÄ¿µÄÈ¡µÃÁªÏµ£¬²¢·¢ËÍÐ޻ڸĵĿªÔ´PDFÈí¼þ(SecurePDFViewer.exe)ºÍЯ´ø¼ÓÃÜpayloadµÄ¶ñÒâPDFÎļþ(AndroidHardwareWallet.pdf)¡£µ¥¶À·¿ª”SecurePDFViewer.exe”ÎÞ¶ñÒâÐÐΪ£¬”AndroidHardwareWallet.pdf”ÎÞ·¨ÓÃͨÀýÈí¼þ·¿ª£¬ÒÔÊǸÃ×éÖ¯»áʹÓÃÉ繤µÄ·½·¨£¬ÓÕʹ¹¥»÷Ä¿µÄʹÓÃexeÎļþÉó²épdfÎļþ£¬×îÖÕ½âÃܳöºǫ́¶ñÒâ³ÌÐòÖ´ÐУ¬µÖ´ïÔ¶¿ØºÍÇÔÊØÐÅÏ¢µÄÄ¿µÄ¡£ÒÔ¼°Grayfly×é֯ʹÓÃSideWalk¶ñÒâÈí¼þ¹¥»÷µçÐÅÐÐÒµ£¬GrayflyÊÇÒ»¸öÓÐÕë¶ÔÐԵĹ¥»÷×éÖ¯£¬Ä¿µÄÊÇÑÇÖÞ¡¢Å·Ö޺ͱ±ÃÀµÄ¶à¸ö¹ú¼Ò/µØÇø£¬É漰ʳÎï¡¢½ðÈÚ¡¢Ò½ÁƱ£½¡¡¢Âùݡ¢ÖÆÔìºÍµçÐŵȸ÷¸öÐÐÒµ¡£ÔÚ×î½üµÄ¹¥»÷Ô˶¯ÖУ¬Grayfly¼ÌÐø×¨×¢ÓÚµçÐÅ£¬Í¨³££¬GrayflyµÄÄ¿µÄÊÇÃæÏò¹«ÖÚµÄWeb·þÎñÆ÷×°ÖÃWebshellÒÔ¾ÙÐгõʼÈëÇÖ£¬È»ºóÔÚÍøÂçÄÚ½øÒ»²½Èö²¥¡£Ò»µ©ÍøÂçÔâµ½ÈëÇÖ£¬Grayfly»á½«¶ñÒâÈí¼þ×°Öõ½ÆäËûϵͳÉÏ¡£ÕâЩ¹¤¾ßÔÊÐí¹¥»÷ÕßÖÜȫԶ³Ì»á¼ûÍøÂçºÍÊðÀíÅþÁ¬£¬´Ó¶øÔÊÐíËûÃÇ»á¼ûÄ¿µÄÍøÂçÖÐÄÑÒÔµÖ´ïµÄ²¿·Ö¡£ÐÂÍøÂçÌØ¹¤FamousSparrow×éÖ¯¹¥»÷È«ÇòÂùݡ¢Õþ¸®ºÍ˽Ӫ¹«Ë¾£¬¸Ã×éÖ¯ÖÁÉÙ×Ô2019Äê8ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬Ö÷ÒªµÄ¹¥»÷Ä¿µÄÊÇÕë¶ÔÈ«ÇòÂùݣ¬Õþ¸®ºÍ˽Ӫ¹«Ë¾£¬¸Ã×é֯ʹÓÃÁËMicrosoftExchange¡¢MicrosoftSharePointºÍOracleOperaÖÐÒÑÖªµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÓÃÓÚͶ·ÅÖÖÖÖ¶ñÒâÑù±¾¡£Ò»µ©·þÎñÆ÷Ôâµ½ÈëÇÖ£¬¹¥»÷Õ߾ͻᰲÅŶàÖÖ×Ô½ç˵¹¤¾ß¡£
ÒÔÉÏËùÓÐÎó²îÇ鱨ºÍÍþвÊÂÎñÇ鱨¡¢¹¥»÷×éÖ¯Ç鱨£¬ÒÔ¼°¹ØÁªµÄIOC£¬¾ù¿ÉÔÚAG¹«Ë¾ÍþвÇ鱨ÖÐÐÄ»ñÈ¡£¬ÍøÖ·£ºhttps://nti.nsfocus.com/
Ò»¡¢ Îó²îÌ¬ÊÆ
2021Äê09ÔÂAG¹«Ë¾¿Æ¼¼Çå¾²Îó²î¿â¹²ÊÕ¼382¸öÎó²î,ÆäÖиßΣÎó²î23¸ö£¬Î¢Èí¸ßΣÎó²î15¸ö¡£
*Êý¾ÝȪԴ£ºAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¬±¾±íÊý¾Ý×èÖ¹µ½2021.09.30
×¢£ºAG¹«Ë¾¿Æ¼¼Îó²î¿â°üÀ¨Ó¦ÓóÌÐòÎó²î¡¢Çå¾²²úÆ·Îó²î¡¢²Ù×÷ϵͳÎó²î¡¢Êý¾Ý¿âÎó²î¡¢ÍøÂç×°±¸Îó²îµÈ£»
¶þ¡¢ ÍþвÊÂÎñ
1. ¹¥»÷ÕßʹÓöñÒâÑù±¾ÎªVBAºê´úÂëµÄEXCELÎĵµ¹¥»÷Ó¡¶È¹ú·À²¿
¡¾±êÇ©¡¿VBA
¡¾Ê±¼ä¡¿2021-08-25
¡¾¼ò½é¡¿
¿ËÈÕ£¬ÍþвÑо¿Ö°Ô±·¢Ã÷ÁËÒ»ÆðÒÔ“CSDhire°ËÔ¹ºÖÃÇåµ¥”ΪÓÕ¶üÖ÷ÌâÕë¶ÔÄÏÑǵØÇøµÄ¹¥»÷Ô˶¯¡£Æ¾Ö¤Ñо¿Ö°Ô±¸ú×ÙÆÊÎö£¬´Ë´ÎÔ˶¯µÄ¹¥»÷Ä¿µÄÊÇÓ¡¶È¹ú·À²¿£¬¹¥»÷ÕßʹÓöñÒâÑù±¾ÎªVBAºê´úÂëµÄEXCELÎĵµ£¬µ±Êܺ¦Õßµã»÷ÆôÓú꣬¶ñÒâºê´úÂ뽫×Ô¶¯Ö´ÐУ¬Ê×ÏÈ»ñȡӡ¶È¹ú·À²¿ÅÌËã»úϵͳµÄÊ±ÇøÐÅÏ¢£¬µ±ÅжÏÏµÍ³Ê±ÇøÊôÓÚChennai,Kolkata,Mumbai,NewDelhi£¬¾ùÊôÓÚÓ¡¶Èºó£¬»áÏÂÔØºóÐø¶ñÒâ.NET¿ÉÖ´ÐÐÎļþºÍÓÕ¶üÎļþ£¬×îÖÕÊͷżÓÔØRATѬȾĿµÄÖ÷»ú¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.qianxin.com/blog/articles/Another-Targeted-Attack-on-India's-Defense-Ministry/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡6ÌõIOC£¬ÆäÖаüÀ¨1¸öIPºÍ1¸öÓòÃûºÍ4¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
2. ¹¥»÷Õßͨ¹ýʹÓÃÐéαCOVID-19ÒßÃçÓÕ¶üÎļþ¶Ôɳר³ÌÓòÌᳫ¹¥»÷
¡¾±êÇ©¡¿COVID-19
¡¾Ê±¼ä¡¿2021-08-31
¡¾¼ò½é¡¿
¿ËÈÕ£¬Ñо¿Ö°Ô±¼ì²âµ½¶àÆðÒÔйÚÒßÃçCOVID-19ΪÖ÷ÌâµÄ¹¥»÷Ô˶¯¡£¹¥»÷Õß´ó¶àÒÔÐéαÓʼþΪÓÕ¶üµÄ¶ñÒâÎļþÏòÓû§·¢ËͶñÒâ½á¹¹µÄÑù±¾ÓÕÆÓû§µã»÷£¬´Ë´ÎÓÕ¶üÎļþÃû×ÖΪ“ɳר³ÌÓò
¡¾²Î¿¼Á´½Ó¡¿
https://ti.qianxin.com/blog/articles/Suspected-Russian-speaking-attackers-use-COVID19-vaccine-decoys-against-Middle-East/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡10ÌõIOC£¬ÆäÖаüÀ¨1¸öÓòÃûºÍ9¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
3. Lazarus×éÖ¯Õë¶Ô¼ÓÃÜÇ®±ÒÐÐÒµµÄÉ繤¹¥»÷
¡¾±êÇ©¡¿Lazarus×éÖ¯
¡¾Ê±¼ä¡¿2021-09-02
¡¾¼ò½é¡¿
½üÆÚÑо¿Ö°Ô±²¶»ñµ½ÁËLazarus×éÖ¯Õë¶Ô¼ÓÃÜÇ®±ÒÏà¹ØÐÐÒµµÄÉ繤¹¥»÷Ô˶¯£¬¸Ã×éÖ¯ÔÚѰÕÒµ½¹¥»÷Ä¿µÄÐÅÏ¢ºó£¬ÒÉËÆÍ¨¹ý¼´Ê±Í¨Ñ¶Èí¼þ×Ô¶¯ºÍÄ¿µÄÈ¡µÃÁªÏµ£¬²¢·¢ËÍÐ޻ڸĵĿªÔ´PDFÈí¼þ(SecurePDFViewer.exe)ºÍЯ´ø¼ÓÃÜpayloadµÄ¶ñÒâPDFÎļþ(AndroidHardwareWallet.pdf)¡£µ¥¶À·¿ª”SecurePDFViewer.exe”ÎÞ¶ñÒâÐÐΪ£¬”AndroidHardwareWallet.pdf”ÎÞ·¨ÓÃͨÀýÈí¼þ·¿ª£¬ÒÔÊǸÃ×éÖ¯»áʹÓÃÉ繤µÄ·½·¨£¬ÓÕʹ¹¥»÷Ä¿µÄʹÓÃexeÎļþÉó²épdfÎļþ£¬×îÖÕ½âÃܳöºǫ́¶ñÒâ³ÌÐòÖ´ÐУ¬µÖ´ïÔ¶¿ØºÍÇÔÊØÐÅÏ¢µÄÄ¿µÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.secpulse.com/archives/165499.html
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡3ÌõIOC£¬ÆäÖаüÀ¨1¸öÓòÃûºÍ2¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
4. BladeHawk×éÖ¯Õë¶Ô¿â¶ûµÂ×åȺÓÐÕë¶ÔÐÔÌᳫ¹¥»÷
¡¾±êÇ©¡¿BladeHawk×éÖ¯
¡¾Ê±¼ä¡¿2021-09-07
¡¾¼ò½é¡¿
ESETÑо¿Ö°Ô±·¢Ã÷£¬Õë¶Ô¿â¶ûµÂ×åȺµÄÓÐÕë¶ÔÐÔµÄÒÆ¶¯Ìع¤Ô˶¯£¬¸ÃÔ˶¯½öÕë¶ÔAndroidÓû§£¬BladeHawk×éÖ¯Õë¶Ô¿â¶ûµÂ×åȺAndroidÓû§ÓÐÕë¶ÔÐÔÌᳫ¹¥»÷¡£¹¥»÷ÕßרעÓÚÁ½¸öÉÌÒµAndroidRAT¹¤¾ß——888RATºÍSpyNote¡£Ê¹ÓÃAndroid888RATÄܹ»Ö´ÐÐ´ÓÆäC·þÎñÆ÷ÊÕµ½µÄ42¸öÏÂÁ´Ó×°±¸ÖÐÇÔÈ¡ºÍɾ³ýÎļþ¡¢½ØÈ¡ÆÁÄ»½ØÍ¼¡¢»ñȡװ±¸Î»Öᢴ¹ÂÚFacebookƾ֤¡¢»ñÈ¡ÒÑ×°ÖõÄÓ¦ÓóÌÐòÁÐ±í¡¢ÇÔÈ¡Óû§ÕÕÆ¬¡¢ÕÕÏà¡¢¼Í¼ÖÜΧµÄÒôƵºÍµç»°¡¢²¦´òµç»°¡¢ÇÔÈ¡¶ÌÐÅÐÅÏ¢¡¢ÇÔȡװ±¸µÄÁªÏµÈËÁÐ±í¡¢·¢ËͶÌÐŵȡ£
¡¾²Î¿¼Á´½Ó¡¿
https://www.welivesecurity.com/2021/09/07/bladehawk-android-espionage-kurdish/
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡12ÌõIOC£¬ÆäÖаüÀ¨12¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
5. ¹¥»÷ÕßʹÓÃConfluenceÔ¶³Ì´úÂëÖ´ÐÐÎó²î¿ÉÍêÈ«¿ØÖÆ·þÎñÆ÷
¡¾±êÇ©¡¿kwroksminerÍÚ¿óľÂí¼Ò×å
¡¾Ê±¼ä¡¿2021-09-07
¡¾¼ò½é¡¿
8ÔÂ26ÈÕ£¬Atlassian¹Ù·½Ðû²¼Í¨¸æ£¬Åû¶ÁËÒ»¸öAtlassianConfluenceÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-26084)£¬¹¥»÷ÕßʹÓÃÎó²î¿ÉÍêÈ«¿ØÖÆ·þÎñÆ÷¡£ÏÖÔÚÖÁÉÙÓÐ7¸öÍøÂçºÚ²úÍÅ»ïÔÚʹÓøÃÎó²îÌᳫµÄ¹¥»÷Ðж¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.oschina.net/news/159040
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡15ÌõIOC£¬ÆäÖаüÀ¨15¸öIP£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
6. Grayfly×é֯ʹÓÃSideWalk¶ñÒâÈí¼þ¹¥»÷µçÐÅÐÐÒµ
¡¾±êÇ©¡¿Grayfly×éÖ¯
¡¾Ê±¼ä¡¿2021-09-09
¡¾¼ò½é¡¿
GrayflyÊÇÒ»¸öÓÐÕë¶ÔÐԵĹ¥»÷×éÖ¯£¬Ä¿µÄÊÇÑÇÖÞ¡¢Å·Ö޺ͱ±ÃÀµÄ¶à¸ö¹ú¼Ò/µØÇø£¬É漰ʳÎï¡¢½ðÈÚ¡¢Ò½ÁƱ£½¡¡¢Âùݡ¢ÖÆÔìºÍµçÐŵȸ÷¸öÐÐÒµ¡£ÔÚ×î½üµÄ¹¥»÷Ô˶¯ÖУ¬Grayfly¼ÌÐø×¨×¢ÓÚµçÐÅ£¬Í¨³££¬GrayflyµÄÄ¿µÄÊÇÃæÏò¹«ÖÚµÄWeb·þÎñÆ÷×°ÖÃWebshellÒÔ¾ÙÐгõʼÈëÇÖ£¬È»ºóÔÚÍøÂçÄÚ½øÒ»²½Èö²¥¡£Ò»µ©ÍøÂçÔâµ½ÈëÇÖ£¬Grayfly»á½«¶ñÒâÈí¼þ×°Öõ½ÆäËûϵͳÉÏ¡£ÕâЩ¹¤¾ßÔÊÐí¹¥»÷ÕßÖÜȫԶ³Ì»á¼ûÍøÂçºÍÊðÀíÅþÁ¬£¬´Ó¶øÔÊÐíËûÃÇ»á¼ûÄ¿µÄÍøÂçÖÐÄÑÒÔµÖ´ïµÄ²¿·Ö¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMRR
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡5ÌõIOC£¬ÆäÖаüÀ¨5¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
7. ¹¥»÷ÕßʹÓÃDridexľÂí¶ñÒâÈí¼þ´Ó»úеÖÐÇÔÈ¡Ãô¸ÐÐÅÏ¢²¢×ª´ïºÍÖ´ÐжñÒâÄ£¿é
¡¾±êÇ©¡¿DridexľÂí¶ñÒâÈí¼þ
¡¾Ê±¼ä¡¿2021-09-10
¡¾¼ò½é¡¿
×î½üÍþвÑо¿ÔºÔÚÒ°Íâ²¶»ñÁËеÄÍøÂç´¹ÂÚµç×ÓÓʼþÔ˶¯£¬¹¥»÷ÕßʹÓÃDridexľÂí¶ñÒâÈí¼þ´Ó»úеÖÐÇÔÈ¡Ãô¸ÐÐÅÏ¢²¢×ª´ïºÍÖ´ÐжñÒâÄ£¿é£¬¹¥»÷Õß½«Ò»·â¶ñÒâµÄÍøÂç´¹ÂÚµç×ÓÓʼþαװ³ÉÏò¿Í»§·¢ËÍÈë¿Ú¹ØË°Êý¾Ý£¬È»ºóÒªÇó¿Í»§Í¨¹ý·¿ª¸½¼ÓµÄExcelÎļþ£¬¿Í»§Ò»µ©·¿ª¶ñÒâExcelÎĵµ£¬Ëü¾Í»áÏÂÔØDridexµÄбäÖÖ¡£È»ºó¹¥»÷Õß´ÓÊܺ¦ÕßµÄÊÜѬȾװ±¸ÍøÂçÃô¸ÐÊý¾Ý£¬È»ºó½«Æä·ÅÈëÃûÌû¯µÄÊý¾Ý°üÖУ¬¼ÓÃܲ¢·¢Ë͵½C2·þÎñÆ÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMRQ
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡6ÌõIOC£¬ÆäÖаüÀ¨3¸öIPºÍ3¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
8. ÐÂÍøÂçÌØ¹¤×éÖ¯FamousSparrow×éÖ¯¹¥»÷È«ÇòÂùݡ¢Õþ¸®ºÍ˽Ӫ¹«Ë¾
¡¾±êÇ©¡¿FamousSparrow×éÖ¯
¡¾Ê±¼ä¡¿2021-09-23
¡¾¼ò½é¡¿
Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÕë¶ÔÈ«ÇòÂùݡ¢Õþ¸®ºÍ˽Ӫ¹«Ë¾µÄÐÂÍøÂçÌØ¹¤×éÖ¯¡£¸Ã×é֯ΪFamousSparrow£¬¸Ã×éÖ¯ÖÁÉÙ×Ô2019Äê8ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬Ö÷ÒªÕë¶ÔÈ«ÇòÂùݣ¬Õþ¸®ºÍ˽Ӫ¹«Ë¾£¬FamousSparrow×é֯ʹÓÃÁËMicrosoftExchange¡¢MicrosoftSharePointºÍOracleOperaÖÐÒÑÖªµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÓÃÓÚͶ·ÅÖÖÖÖ¶ñÒâÑù±¾¡£Ò»µ©·þÎñÆ÷Ôâµ½ÈëÇÖ£¬¹¥»÷Õ߾ͻᰲÅŶàÖÖ×Ô½ç˵¹¤¾ß£º
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMUB
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡11ÌõIOC£¬ÆäÖаüÀ¨1¸öÓòÃûºÍ10¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
9. TurlaAPT×é֯ͨ¹ý°²ÅÅеĶñÒâÈí¼þÏòÓû§·Ö·¢¶ñÒâÔØºÉ
¡¾±êÇ©¡¿TurlaAPT×éÖ¯
¡¾Ê±¼ä¡¿2021-09-21
¡¾¼ò½é¡¿
CiscoTalos×î½ü·¢Ã÷Á˶íÂÞ˹TurlaAPT×é֯ʹÓõÄÒ»¸öжñÒâÈí¼þ£¬ÒÔ¼á³Ö¶ÔϵͳµÄ»á¼û£¬×ÝÈ»Ö÷Òª¶ñÒâÈí¼þÒѱ»É¾³ý¡£ËüÒ²¿ÉÒÔÓÃ×÷µÚ¶þ½×¶ÎµÄÊÍ·ÅÆ÷£¬ÓÃÆäËû¶ñÒâÈí¼þѬȾϵͳ¡£¹¥»÷Õß½«¶ñÒâÈí¼þ×÷Ϊ·þÎñ×°ÖÃÔÚÊÜѬȾµÄ»úеÉÏ¡£ËûÃÇÊÔͼͨ¹ý½«·þÎñÃüÃûΪ“Windowsʱ¼ä·þÎñ”ÔËÐУ¬¾ÍÏñÏÖÓеÄWindows·þÎñÒ»Ñù£¬¹¥»÷Õß¿ÉÒÔÉÏ´«ºÍÖ´ÐÐÎļþ»ò´ÓÊÜѬȾϵͳÖÐÇÔÈ¡Îļþ¡£ÔÚÎÒÃǶԸöñÒâÈí¼þµÄÉó²éÖУ¬Ã¿ÎåÃëͨ¹ýHTTPS¼ÓÃÜͨµÀÁªÏµÏÂÁîºÍ¿ØÖÆ(C2)·þÎñÆ÷£¬ÒÔ¼ì²éÊÇ·ñÓÐÀ´×Ô²Ù×÷Ô±µÄÐÂÏÂÁî¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMUA
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡1ÌõIOC£¬ÆäÖаüÀ¨1¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£
10. Sora-Miral±äÖÖľÂíʹÓÃF5BIG-IP¸ßΣÎó²î¹¥»÷ÔÆÖ÷»ú
¡¾±êÇ©¡¿Sora-Miral±äÖÖľÂí
¡¾Ê±¼ä¡¿2021-09-22
¡¾¼ò½é¡¿
Çå¾²Ñо¿Ô±¼ì²âµ½£¬Óй¥»÷ÕßʹÓÃF5BIG-IPÔ¶³Ì´úÂë¸ßΣÎó²î£¨CVE-2021-22986)¶ÔÔÆÖ÷»úÕö¿ª¹¥»÷£¬Èô¹¥»÷Àֳɻá·Ö·¢Sora-Miral±äÖÖľÂí£¬Sora-Miral±äÖÖľÂíÖ÷Òª¿ØÖÆ×齨½©Ê¬ÍøÂçÌᳫDDOS¹¥»÷£¬»òͨ¹ýÍÚ¿óIJÀû£¬¹¥»÷Õß»áͨ¹ýTelentÈõ¿ÚÁî±¬ÆÆ¾ÙÐÐÈä³æÊ½À©É¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://ti.nsfocus.com/security-news/IlMUz
¡¾·À»¤²½·¥¡¿
AG¹«Ë¾ÍþвÇ鱨ÖÐÐĹØÓÚ¸ÃÊÂÎñÌáÈ¡22ÌõIOC£¬ÆäÖаüÀ¨1¸öIPºÍ21¸öÑù±¾£»AG¹«Ë¾Ç徲ƽ̨Óë×°±¸ÒѼ¯³ÉÏìÓ¦Ç鱨Êý¾Ý£¬Îª¿Í»§ÌṩÏà¹Ø·ÀÓù¼ì²âÄÜÁ¦¡£

AG¹«Ë¾ÔÆ







