×êÑÐÍŶӹ«¿ªNSA Equation GroupµÄºóÃÅBvp47µÄϸ½Ú
°ä²¼¹¦·ò 2022-02-28×êÑÐÍŶӹ«¿ªNSA Equation GroupµÄºóÃÅBvp47µÄϸ½Ú
¾ÝýÌå2ÔÂ23ÈÕ±¨Â·£¬£¬£¬£¬£¬×êÑÐÍŶӹ«¿ªÁËLinuxºóÃÅBvp47µÄ¼¼Êõϸ½Ú¡£¡£¡£¡£¡£¸ÃºóÃÅÓÚ2013Äêµ×³õ´Î±»¼ì²âµ½£¬£¬£¬£¬£¬ÓëNSA Equation GroupÓйØÁª£¬£¬£¬£¬£¬ÒòÂÅ´ÎʹÓÃ×Ö·û´®¡°Bvp¡±ºÍ¼ÓÃÜËã·¨ÖеÄÊýÖµ¡°0x47¡±¶ø±»³ÆÎª¡°Bvp47¡±¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬Bvp47Òѱ»ÓÃÓÚ¹¥»÷Öйú¡¢º«¹ú¡¢ÈÕ±¾¡¢µÂ¹ú¡¢Î÷°àÑÀ¡¢Ó¡¶ÈºÍÄ«Î÷¸çµÈ45¸ö¹ú¶ÈµÄѧÊõ¡¢¾¼Ã¡¢¾üÊ¡¢¿ÆÑ§ºÍµçÐŵÈÐÐÒµµÄ287¸öÖ¸±ê¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Ëü»¹ÓµÓи´ÔӵĴúÂë¡¢·Ö¶Î¼Ó½âÃÜ¡¢Linux¶à°æ±¾Æ½Ì¨ÊÊÅä¡¢·á˶µÄrootkit·´¸ú×Ù¼¼Êõ£¬£¬£¬£¬£¬²¢¼¯³ÉÁ¶¯ß¼¶BPFÒýÇæÒÔ¼°·±ËöµÄͨѶ¼Ó½âÃܹý³Ì¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/128322/apt/equation-group-bvp47-backdoor.html
ESET·¢ÏÖеÄHermeticWiperÕë¶ÔÎÚ¿ËÀ¼µÄ¹¥»÷»î¶¯
ýÌå2ÔÂ23Èճƣ¬£¬£¬£¬£¬°²È«¹«Ë¾ESET·¢ÏÖÁËÕë¶ÔÎÚ¿ËÀ¼µÄÐÂÊý¾Ý²Á³ý¶ñÒâÈí¼þHermeticWiper£¨±ðÃûKillDisk.NCV£©¡£¡£¡£¡£¡£¸ÃÑù±¾±àÒëÓÚ2021Äê12ÔÂ28ÈÕ£¬£¬£¬£¬£¬Ëæ×ŶíÂÞ˹µÄ¾üÊÂÐж¯¹¥»÷ÁËÎÚ¿ËÀ¼´óÁ¿IT»ù´¡ÉèÊ©¡£¡£¡£¡£¡£HermeticWiperÊÇʹÓÃÐû¸æ¸øHermetica Digital LtdµÄÖ¤Êé½øÐÐÊðÃûµÄ£¬£¬£¬£¬£¬ÀûÓÃÈí¼þEaseUS Partition MasterÖеĺϷ¨Çý¶¯·¨Ê½À´·ÛËéÊý¾Ý£¬£¬£¬£¬£¬¶øºó³ÁÐÂÆô¶¯ÍÆËã»ú¡£¡£¡£¡£¡£
https://thehackernews.com/2022/02/new-wiper-malware-targeting-ukraine.html
Ó¢ÃÀµ±¾Ö³ÆCyclops BlinkÓëAPT×éÖ¯SandwormÓйØ
2ÔÂ22ÈÕ£¬£¬£¬£¬£¬ÃÀÓ¢»ú¹¹NCSC¡¢FBI¡¢CISAºÍNSA½áºÏ°ä²¼ÁËÒ»·Ý°²È«Õ÷ѯ£¬£¬£¬£¬£¬³ÆÐ¶ñÒâÈí¼þCyclops BlinkÓë¶íÂÞ˹SandwormÓйء£¡£¡£¡£¡£¸ÃAPT×éÖ¯×Ô2000ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬ÖØÒªÓɶíÂÞ˹GRUÌØÊâ¼¼ÊõÖÐÐÄ(GTsST)µÄ74455¶ÓÁÐÔËÓª¡£¡£¡£¡£¡£Õ÷ѯ°µÊ¾£¬£¬£¬£¬£¬Cyclops BlinkËÆºõÊÇ2018Äê·¢ÏÖµÄVPNFilterµÄ´úÌæÆ·£¬£¬£¬£¬£¬×°ÖÃÔÚÔÊÐíSandwormÔ¶³Ì½Ó¼ûµÄÍøÂçÖУ¬£¬£¬£¬£¬²¢Í¨¹ý¹Ì¼þ¸üÐÂÔÚÖ¸±êÉ豸ÖÐά³ÖÓÆ¾ÃÐÔ¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/us-uk-link-new-cyclops-blink-malware-to-russian-state-hackers/
×êÑÐÈËÔ±³ÆÖÁÉÙÓÐ1ÒÚ²¿ÈýÐÇÊÖ»úµÄÃÜÂëÉè¼Æ´æÔÚȱµã
¾Ý2ÔÂ23ÈÕ±¨Â·£¬£¬£¬£¬£¬ÌØÀά·ò´óѧµÄ×êÑÐÈËÔ±·¢ÏÖÁËÈýÐÇÊÖ»úµÄÃÜÂëÉè¼Æ´æÔÚȱµã¡£¡£¡£¡£¡£¸Ãȱµã´æÔÚÓÚ´ÓGalaxy S8µ½Galaxy S21µÄ¸÷ÀàÐͺÅÖУ¬£¬£¬£¬£¬¾Ý¹À¼ÆÓ°ÏìÁË1ÒÚ²¿ÖÇÄÜÊÖ»ú¡£¡£¡£¡£¡£¸ÃÎÊÌâÖØÒªÉæ¼°µ½Ê¹ÓÃARMµÄTrustZone¼¼ÊõµÄÉ豸£¬£¬£¬£¬£¬²»½öÄܹ»ÓÃÀ´ÇÔÈ¡´æ´¢ÔÚÉ豸ÉϵļÓÃÜÃÜÔ¿£¬£¬£¬£¬£¬»¹Äܹ»ÓÃÀ´ÈƹýFIDO2µÈ°²È«³ß¶È¡£¡£¡£¡£¡£×êÑÐÈËÔ±Ô¤¼Æ»áÔÚ8Ô½øÐеÄ2022ÄêUSENIX°²È«×êÑлáÉϾßÌå½éÉÜÕâЩ·ì϶¡£¡£¡£¡£¡£
https://threatpost.com/samsung-shattered-encryption-on-100m-phones/178606/
Dragos°ä²¼2021ÄêICSÍøÂç°²È«Ì¬ÊÆµÄ»ØÊ׻㱨
¹¤Òµ°²È«¹«Ë¾ÔÚ2ÔÂ23ÈÕ°ä²¼ÁË2021ÄêICSÍøÂç°²È«Ì¬ÊÆµÄ»ØÊ׻㱨¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÖØÒª¼à²âÁ˹¤ÒµÁìÓòµÄÍþв»î¶¯£¬£¬£¬£¬£¬·¢ÏÖÀÕË÷ÍÅ»ï×î³£¼ûµÄÖ¸±êÊÇÔì×÷Òµ£¨¹²ÓÐ211´Î¹¥»÷£¬£¬£¬£¬£¬Õ¼±È65%£©£¬£¬£¬£¬£¬Æä´ÎÊÇʳƷºÍÒûÁÏÐÐÒµ£¨35´Î£©ºÍ½»Í¨ÔËÊäÐÐÒµ£¨27´Î£©¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïLockBitºÍContiÊÇÈ¥Ä깤ҵÁìÓòµÄÍ·ºÅÍþв¡£¡£¡£¡£¡£»ã±¨»¹½ÒʾÁËÒ»¸öÁîÈ˲»°²µÄ¾°Ï󣬣¬£¬£¬£¬ºÜ¶à×éÖ¯µÄ»ù´¡¼Ü¹¹µÄ¿É¼ûÐÔ²»¼° £¬£¬£¬£¬£¬Î´ÄÜÕýÈ·Ô׸îÍøÂçÌìǵ£¬£¬£¬£¬£¬ºÜ¶à±í²¿ÏνӵÄÉ豸£¬£¬£¬£¬£¬ÒÔ¼°ITºÍOT»·¾³Ö®¼äÓдóÁ¿¹²ÏíÆ¾Ö¤¡£¡£¡£¡£¡£
https://www.dragos.com/year-in-review/
Mandiant³ÆCubaÀûÓÃExchange·ì϶¶Ô×¼ÃÀ¹úºÍ¼ÓÄôó
MandiantÔÚ2ÔÂ23ÈÕµÄÒ»·Ý»ã±¨ÖгÆCubaÔÚ¶Ô×¼ÃÀ¹úºÍ¼ÓÄô󡣡£¡£¡£¡£¸ÃÍÅ»ï×·×ÙΪUNC2596£¬£¬£¬£¬£¬ÆäʹÓõÄÀÕË÷Èí¼þÊÇCOLDDRAW£¨Í¨³£±»³ÆÎªCuba£©¡£¡£¡£¡£¡£MandiantÈ·¶¨Õâ´Î¹¥»÷ÀûÓÃÁËMicrosoft ExchangeÖеķì϶£¬£¬£¬£¬£¬Ô̺¬ProxyShellºÍProxyLogon£¬£¬£¬£¬£¬Ö²ÈëµÄºóÃÅÔ̺¬Cobalt Strike»òNetSupport Manager£¬£¬£¬£¬£¬ÒÔ¼°ËûÃÇ×Ô¼ºµÄBughatch¡¢Wedgecut¡¢eck.exeºÍBurntcigar¡£¡£¡£¡£¡£Ô¼80%µÄÖ¸±ê×é֯λÓÚ±±ÃÀ£¬£¬£¬£¬£¬Æä´ÎÊǼÓÄô󡣡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/microsoft-exchange-servers-hacked-to-deploy-cuba-ransomware/
°²È«¹¤¾ß
Cloudsploit
ÔÆ°²È«É¨Ã蹤¾ß¡£¡£¡£¡£¡£
https://github.com/aquasecurity/cloudsploit
Dive
ÓÃÓÚË÷Çó Docker Ó³Ïñ¡¢Í¼²ãÄÚÈݺͷ¢ÏÖËõÓ× Docker/OCI Ó³Ïñ´óÓ׵IJ½ÖèµÄ¹¤¾ß¡£¡£¡£¡£¡£
https://github.com/wagoodman/dive
TerraGoat
ÊÇ Bridgecrew µÄ¡°Éè¼Æ·ì϶¡±Terraform ´æ´¢¿â¡£¡£¡£¡£¡£
https://github.com/bridgecrewio/terragoat
vortex
VPN ÕûÌå¿úËÅ¡¢²âÊÔ¡¢Ã¶¾ÙºÍÀûÓù¤¾ß°ü¡£¡£¡£¡£¡£
https://github.com/klezVirus/vortex
EDRSandblast
Óà C ˵»°±àдµÄ¹¤¾ß£¬£¬£¬£¬£¬¿É½«ÊðÃûÇý¶¯·¨Ê½±øÆ÷»¯ÒÔÈÆ¹ýEDR ¼ì²âºÍ LSASS ±£»£»£»£»£»£»£»¤¡£¡£¡£¡£¡£
https://github.com/wavestone-cdt/EDRSandblast
°²È«·ÖÎö
ʹÓüòÀúºÍ°æÈ¨Óйصç×ÓÓʼþ·Ö·¢ LockBit ÀÕË÷Èí¼þ
https://asec.ahnlab.com/en/32054/
¹È¸èÔڲüõ Android µÄ Chrome Lite ģʽ
https://news.softpedia.com/news/google-is-retiring-the-chrome-lite-mode-for-android-534933.shtml
Microsoft Defender for Cloud Äܹ»±£»£»£»£»£»£»£»¤ Google Cloud
https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-for-cloud-can-now-protect-google-cloud-resources/
NCSC Ϊ¹¹ÖþÒµ°ä²¼Ê׸öÍøÂ簲ȫָÄÏ
https://www.infosecurity-magazine.com/news/ncsc-guidance-construction/
ÀÕË÷Èí¼þ Entropy Óë¶ñÒâÈí¼þ Dridex ÓйØ
https://thehackernews.com/2022/02/dridex-malware-deploying-entropy.html
FTC£º2021 ÄêÃÀ¹úÒòÚ²ÆËðʧ³¬¹ý 58 ÒÚÃÀÔª
https://www.bleepingcomputer.com/news/security/ftc-americans-report-losing-over-58-billion-to-fraud-in-2021/


¾©¹«Íø°²±¸11010802024551ºÅ