µçÐŹ«Ë¾AT£¦T´óÁ¿ESBCÉ豸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷
°ä²¼¹¦·ò 2021-12-03µçÐŹ«Ë¾AT£¦T´óÁ¿ESBCÉ豸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷

×êÑÐÍŶÓÔÚ11ÔÂ30ÈÕ¹«¿ªÐ½©Ê¬ÍøÂçEwDoorµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÖØÒªÕë¶ÔµçÐŹ«Ë¾AT£¦T EdgeMarcÆóÒµ»á»°Ììǵ½ÚÔìÆ÷(ESBC)±ßÔµÉ豸£¬£¬£¬£¬£¬£¬£¬£¬ÀûÓÃÁË4ÄêǰµÄºÅÁî×¢Èë·ì϶£¨CVE-2017-6079£©¡£¡£¡£¡£¡£¡£¡£ÔÚ½©Ê¬ÍøÂçÇл»µ½ÆäËüC2֮ǰµÄ¶Ì¶Ì3Ó×ʱÄÚ£¬£¬£¬£¬£¬£¬£¬£¬¹²¼ì²âµ½Ô¼5700̨É豸±»Ï°È¾¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÒÑÈ·ÈÏEwDoorµÄ3¸ö±äÌ壬£¬£¬£¬£¬£¬£¬£¬¿É·ÖΪDDoS¹¥»÷ºÍBackdoorÁ½´óÀ࣬£¬£¬£¬£¬£¬£¬£¬²¢´§Ä¦ÆäÖØÒªÖ÷ÕÅÊÇDDoS¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÍøÂçͨ»°¼Í¼µÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/125143/cyber-crime/ewdoor-botnet.html
ÀÕË÷Èí¼þSabbath¶Ô×¼ÃÀ¹úºÍ¼ÓÄôóµÄ¹Ø¼ü»ù´¡ÉèÊ©

11ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬MandiantÍŶӳÆÀÕË÷Èí¼þSabbath£¨±ðÃûUNC2190£©×Ô6ÔÂ·ÝÆðÍ·Ò»ÏòÔÚÕë¶ÔÃÀ¹úºÍ¼ÓÄô󡣡£¡£¡£¡£¡£¡£UNC2190ÔÚ֮ǰÃûΪArcaneºÍEruption£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ2020Äê7Ô·ַ¢ÀÕË÷Èí¼þROLLCOAST¡£¡£¡£¡£¡£¡£¡£Sabbath£¨54BB47h£©ÓÚ10ÔÂ21ÈÕÕýʽÔËÓª£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÖ¸±êÊǹؼü»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÃÀ¹úºÍ¼ÓÄôóµÄ½ÌÓý¡¢ÎÀÉúºÍÌìÈ»×ÊÔ´ÐÐÒµ¡£¡£¡£¡£¡£¡£¡£ÓëÆäËûÀÕË÷ÔËÓªÍÅ»ï·ÖÆç£¬£¬£¬£¬£¬£¬£¬£¬Sabbath»¹ÎªÆä´ÓÊô×éÖ¯ÌṩÁËÔ¤ÏÈÅäÖúõÄCobalt Strike BEACONºóÃÅpayload¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/125154/cyber-crime/sabbath-ransomware.html
Symantec³ÆYanluowangÓëºÚ¿ÍÍÅ»ïThieflockÓйØ

SymantecÔÚ11ÔÂ30ÈÕ°ä²¼Á˹ØÓÚÀÕË÷Èí¼þYanluowang½üÆÚ»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÆðÍ·ÓÚ8Ô·ݣ¬£¬£¬£¬£¬£¬£¬£¬ÀûÓÃÁ˶ñÒâÈí¼þBazarLoader£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÃÀ¹úµÄ½ðÈÚÐÐÒµ£¬£¬£¬£¬£¬£¬£¬£¬µ«Ò²Õë¶ÔÔì×÷¡¢IT·þÎñ¡¢Õ÷ѯºÍ¹¤³ÌµÈÐÐÒµµÄ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£×êÑÐÍŶӷÖÎö¹¥»÷ÕßʹÓõŤ¾ß¡¢Õ½ÊõºÍ·¨Ê½(TTP)£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÔìäÖкܶ඼ÓëThieflockµÄÀÕË÷¹¥»÷»î¶¯Óйأ¬£¬£¬£¬£¬£¬£¬£¬ÕâÅú×¢ËûÃÇ¿ÉÄÜÊôÓÚThieflockµÄÒ»¸ö´ÓÊô×éÖ¯¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/yanluowang-ransomware-thieflock-threat-actor/176640/
Mozilla½¨¸´NSSÖеÄÄÚ´æ°Ü»µ·ì϶CVE-2021-43527

MozillaÓÚ12ÔÂ1ÈÕ°ä²¼¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËÆä¿çÆ½Ì¨ÍøÂ簲ȫ·þÎñ(NSS)ÖеÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-43527£©¡£¡£¡£¡£¡£¡£¡£Google project-zero×êÑÐÈËÔ±ÔÚ10ÔÂ24ÈÕÅû¶¸Ã·ì϶µÄϸ½Ú£¬£¬£¬£¬£¬£¬£¬£¬ÔÚʹÓÃNSSµÄÓʼþ¿Í»§¶ËºÍPDF²é¿´Æ÷´¦ÖÃder±àÂëµÄDSA»òRSA-PSSÊðÃûʱ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܻᵼÖ»ùÓڶѵĻº³åÇøÒç³ö¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓø÷ì϶¿Éµ¼Ö·¨Ê½±ÀÀ£´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Èƹý°²È«¼ì²âÈí¼þ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/mozilla-fixes-critical-bug-in-cross-platform-cryptography-library/
·ÒÀ¼NCSC-FI°ä²¼´ó¹æÄ£·Ö·¢FlubotµÄ»î¶¯µÄ¾¯±¨

11ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬·ÒÀ¼¹ú¶ÈÍøÂ簲ȫÖÐÐÄ(NCSC-FI)°ä²¼³ÁÒª¾¯±¨£¬£¬£¬£¬£¬£¬£¬£¬ÖÒ¸æÕë¶Ô¸Ã¹úAndroidÓû§´ó¹æÄ£·Ö·¢FlubotµÄ»î¶¯¡£¡£¡£¡£¡£¡£¡£ÕâÊǽñÄêFlubotÔÚ·ÒÀ¼ÌáÒéµÄµÚ¶þ´Î´ó¹æÄ£»£»£»£»£»£»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬´Ëǰ´Ó2021Äê6Ô³õÖÁ8ÔÂÖÐÑ®£¬£¬£¬£¬£¬£¬£¬£¬FlubotÿÌìÏòÊýǧ¸ö·ÒÀ¼¹«Ãñ·¢ËÍÀ¬»ø¶ÌÐÅ¡£¡£¡£¡£¡£¡£¡£Ð»ÒÀÈ»ÒÔÒÆ¶¯ÔËÓªÉ̵ÄÓïÒôÓʼþΪÖ÷Ì⣬£¬£¬£¬£¬£¬£¬£¬ÓÕʹAndroidÓû§ÏÂÔØÒ»¸öAPKÀ´×°ÖÃÒøÐжñÒâÈí¼þFlubot£¬£¬£¬£¬£¬£¬£¬£¬¶øiPhoneÓû§Ôò»á±»³Á¶¨Ïòµ½Ö¼ÔÚÇÔÊØÐÅÏ¢µÄ´¹µöÍøÕ¾¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/finland-warns-of-flubot-malware-heavily-targeting-android-users/
Kaspersky°ä²¼2021ÄêAPT¹¥»÷»î¶¯µÄ»ØÊ׻㱨

KasperskyÓÚ11ÔÂ30ÈÕ°ä²¼2021ÄêAPT¹¥»÷»î¶¯µÄ»ØÊ׻㱨¡£¡£¡£¡£¡£¡£¡£×êÑиú×ÙÁË900¶à¸öAPT¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ·ÖÎö´Óǰ12¸öÔÂÖеÄÇ÷ÏòºÍ·¢Õ¹¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬È«Çò³¬¹ý30000¸ö¼ÇÕß¡¢ÂÉʦµÈÈËÔ±³ÉΪPegasusµÄÖ¸±ê£»£»£»£»£»£»²úÉúÁ˺ܶ౸ÊÜÖõÖ÷ÕŹ©¸øÁ´¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÈçÓ°ÏìÁË18000¶à¸öSolarWinds¿Í»§µÄ¹©¸øÁ´¹¥»÷£»£»£»£»£»£»ÀûÓÃExchangeºÍChromeµÈÈí¼þÖеÄÁãÈÕ·ì϶£»£»£»£»£»£»ÀûÓù̼þÖеķì϶¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/apt-annual-review-2021/105127/


¾©¹«Íø°²±¸11010802024551ºÅ