µçÐŹ«Ë¾AT£¦T´óÁ¿ESBCÉ豸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷

°ä²¼¹¦·ò 2021-12-03

µçÐŹ«Ë¾AT£¦T´óÁ¿ESBCÉ豸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷


µçÐŹ«Ë¾AT£¦T´óÁ¿ESBCÉ豸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷.png


×êÑÐÍŶÓÔÚ11ÔÂ30ÈÕ¹«¿ªÐ½©Ê¬ÍøÂçEwDoorµÄ¹¥»÷»î¶¯¡£¡£ ¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÖØÒªÕë¶ÔµçÐŹ«Ë¾AT£¦T EdgeMarcÆóÒµ»á»°Ììǵ½ÚÔìÆ÷(ESBC)±ßÔµÉ豸£¬£¬£¬£¬£¬£¬£¬£¬ÀûÓÃÁË4ÄêǰµÄºÅÁî×¢Èë·ì϶£¨CVE-2017-6079£©¡£¡£ ¡£¡£¡£¡£¡£ÔÚ½©Ê¬ÍøÂçÇл»µ½ÆäËüC2֮ǰµÄ¶Ì¶Ì3Ó×ʱÄÚ£¬£¬£¬£¬£¬£¬£¬£¬¹²¼ì²âµ½Ô¼5700̨É豸±»Ï°È¾¡£¡£ ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÒÑÈ·ÈÏEwDoorµÄ3¸ö±äÌ壬£¬£¬£¬£¬£¬£¬£¬¿É·ÖΪDDoS¹¥»÷ºÍBackdoorÁ½´óÀ࣬£¬£¬£¬£¬£¬£¬£¬²¢´§Ä¦ÆäÖØÒªÖ÷ÕÅÊÇDDoS¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÍøÂçͨ»°¼Í¼µÈÃô¸ÐÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125143/cyber-crime/ewdoor-botnet.html


ÀÕË÷Èí¼þSabbath¶Ô×¼ÃÀ¹úºÍ¼ÓÄôóµÄ¹Ø¼ü»ù´¡ÉèÊ©


ÀÕË÷Èí¼þSabbath¶Ô×¼ÃÀ¹úºÍ¼ÓÄôóµÄ¹Ø¼ü»ù´¡ÉèÊ©.png


11ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬MandiantÍŶӳÆÀÕË÷Èí¼þSabbath£¨±ðÃûUNC2190£©×Ô6ÔÂ·ÝÆðÍ·Ò»ÏòÔÚÕë¶ÔÃÀ¹úºÍ¼ÓÄô󡣡£ ¡£¡£¡£¡£¡£UNC2190ÔÚ֮ǰÃûΪArcaneºÍEruption£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ2020Äê7Ô·ַ¢ÀÕË÷Èí¼þROLLCOAST¡£¡£ ¡£¡£¡£¡£¡£Sabbath£¨54BB47h£©ÓÚ10ÔÂ21ÈÕÕýʽÔËÓª£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÖ¸±êÊǹؼü»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÃÀ¹úºÍ¼ÓÄôóµÄ½ÌÓý¡¢ÎÀÉúºÍÌìÈ»×ÊÔ´ÐÐÒµ¡£¡£ ¡£¡£¡£¡£¡£ÓëÆäËûÀÕË÷ÔËÓªÍÅ»ï·ÖÆç£¬£¬£¬£¬£¬£¬£¬£¬Sabbath»¹ÎªÆä´ÓÊô×éÖ¯ÌṩÁËÔ¤ÏÈÅäÖúõÄCobalt Strike BEACONºóÃÅpayload¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125154/cyber-crime/sabbath-ransomware.html


Symantec³ÆYanluowangÓëºÚ¿ÍÍÅ»ïThieflockÓйØ


Symantec³ÆYanluowangÓëºÚ¿ÍÍÅ»ïThieflockÓйØ.png


SymantecÔÚ11ÔÂ30ÈÕ°ä²¼Á˹ØÓÚÀÕË÷Èí¼þYanluowang½üÆÚ»î¶¯µÄ·ÖÎö»ã±¨¡£¡£ ¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÆðÍ·ÓÚ8Ô·Ý£¬£¬£¬£¬£¬£¬£¬£¬ÀûÓÃÁ˶ñÒâÈí¼þBazarLoader£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÃÀ¹úµÄ½ðÈÚÐÐÒµ£¬£¬£¬£¬£¬£¬£¬£¬µ«Ò²Õë¶ÔÔì×÷¡¢IT·þÎñ¡¢Õ÷ѯºÍ¹¤³ÌµÈÐÐÒµµÄ¹«Ë¾¡£¡£ ¡£¡£¡£¡£¡£×êÑÐÍŶӷÖÎö¹¥»÷ÕßʹÓõŤ¾ß¡¢Õ½ÊõºÍ·¨Ê½(TTP)£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÔìäÖкܶ඼ÓëThieflockµÄÀÕË÷¹¥»÷»î¶¯ÓйØ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÅú×¢ËûÃÇ¿ÉÄÜÊôÓÚThieflockµÄÒ»¸ö´ÓÊô×éÖ¯¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/yanluowang-ransomware-thieflock-threat-actor/176640/


Mozilla½¨¸´NSSÖеÄÄÚ´æ°Ü»µ·ì϶CVE-2021-43527


Mozilla½¨¸´NSSÖеÄÄÚ´æ°Ü»µ·ì϶CVE-2021-43527.png


MozillaÓÚ12ÔÂ1ÈÕ°ä²¼¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËÆä¿çÆ½Ì¨ÍøÂ簲ȫ·þÎñ(NSS)ÖеÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-43527£©¡£¡£ ¡£¡£¡£¡£¡£Google project-zero×êÑÐÈËÔ±ÔÚ10ÔÂ24ÈÕÅû¶¸Ã·ì϶µÄϸ½Ú£¬£¬£¬£¬£¬£¬£¬£¬ÔÚʹÓÃNSSµÄÓʼþ¿Í»§¶ËºÍPDF²é¿´Æ÷´¦ÖÃder±àÂëµÄDSA»òRSA-PSSÊðÃûʱ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܻᵼÖ»ùÓڶѵĻº³åÇøÒç³ö¡£¡£ ¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓø÷ì϶¿Éµ¼Ö·¨Ê½±ÀÀ£´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Èƹý°²È«¼ì²âÈí¼þ¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/mozilla-fixes-critical-bug-in-cross-platform-cryptography-library/


·ÒÀ¼NCSC-FI°ä²¼´ó¹æÄ£·Ö·¢FlubotµÄ»î¶¯µÄ¾¯±¨


·ÒÀ¼NCSC-FI°ä²¼´ó¹æÄ£·Ö·¢FlubotµÄ»î¶¯µÄ¾¯±¨.png


11ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬·ÒÀ¼¹ú¶ÈÍøÂ簲ȫÖÐÐÄ(NCSC-FI)°ä²¼³ÁÒª¾¯±¨£¬£¬£¬£¬£¬£¬£¬£¬ÖÒ¸æÕë¶Ô¸Ã¹úAndroidÓû§´ó¹æÄ£·Ö·¢FlubotµÄ»î¶¯¡£¡£ ¡£¡£¡£¡£¡£ÕâÊǽñÄêFlubotÔÚ·ÒÀ¼ÌáÒéµÄµÚ¶þ´Î´ó¹æÄ£» £»£»£»£»£»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬´Ëǰ´Ó2021Äê6Ô³õÖÁ8ÔÂÖÐÑ®£¬£¬£¬£¬£¬£¬£¬£¬FlubotÿÌìÏòÊýǧ¸ö·ÒÀ¼¹«Ãñ·¢ËÍÀ¬»ø¶ÌÐÅ¡£¡£ ¡£¡£¡£¡£¡£Ð»ÒÀÈ»ÒÔÒÆ¶¯ÔËÓªÉ̵ÄÓïÒôÓʼþΪÖ÷Ì⣬£¬£¬£¬£¬£¬£¬£¬ÓÕʹAndroidÓû§ÏÂÔØÒ»¸öAPKÀ´×°ÖÃÒøÐжñÒâÈí¼þFlubot£¬£¬£¬£¬£¬£¬£¬£¬¶øiPhoneÓû§Ôò»á±»³Á¶¨Ïòµ½Ö¼ÔÚÇÔÊØÐÅÏ¢µÄ´¹µöÍøÕ¾¡£¡£ ¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/finland-warns-of-flubot-malware-heavily-targeting-android-users/


Kaspersky°ä²¼2021ÄêAPT¹¥»÷»î¶¯µÄ»ØÊ׻㱨


Kaspersky°ä²¼2021ÄêAPT¹¥»÷»î¶¯µÄ»ØÊ׻㱨.png


KasperskyÓÚ11ÔÂ30ÈÕ°ä²¼2021ÄêAPT¹¥»÷»î¶¯µÄ»ØÊ׻㱨¡£¡£ ¡£¡£¡£¡£¡£×êÑиú×ÙÁË900¶à¸öAPT¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ·ÖÎö´Óǰ12¸öÔÂÖеÄÇ÷ÏòºÍ·¢Õ¹¡£¡£ ¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬È«Çò³¬¹ý30000¸ö¼ÇÕß¡¢ÂÉʦµÈÈËÔ±³ÉΪPegasusµÄÖ¸±ê£» £»£»£»£»£»²úÉúÁ˺ܶ౸ÊÜÖõÖ÷ÕŹ©¸øÁ´¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÈçÓ°ÏìÁË18000¶à¸öSolarWinds¿Í»§µÄ¹©¸øÁ´¹¥»÷£» £»£»£»£»£»ÀûÓÃExchangeºÍChromeµÈÈí¼þÖеÄÁãÈÕ·ì϶£» £»£»£»£»£»ÀûÓù̼þÖеķì϶¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/apt-annual-review-2021/105127/