ʱ¼ä£º2021-11-05

±¾ÎÄ3758×ÖÔĶÁÔ¼Ðè11·ÖÖÓ
¹ú¼Ò¼¶APT£¨AdvancedPersistentThreat£¬£¬£¬£¬£¬£¬¸ß¼¶Ò»Á¬ÐÔÍþв£©×éÖ¯ÊÇÓйú¼ÒÅä¾°Ö§³ÖµÄ¶¥¼âºÚ¿ÍÍŻ£¬£¬£¬£¬£¬×¨×¢ÓÚÕë¶ÔÌØ¶¨Ä¿µÄ¾ÙÐкã¾ÃµÄÒ»Á¬ÐÔÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£
Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!Æìϵĸ߼¶ÍþвÑо¿ÍŶӺìÓêµÎ£¨RedDripTeam£©Ã¿Äê»áÐû²¼È«ÇòAPTÄ걨¡¾1¡¿¡¢Öб¨£¬£¬£¬£¬£¬£¬¶ÔÎôʱ¸÷´óAPTÍÅ»ïµÄÔ˶¯¾ÙÐÐÆÊÎö×ܽᡣ¡£¡£¡£¡£¡£¡£
»¢·ûÖÇ¿âÌØÔ¼Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÆìϺìÓêµÎÍŶӣ¬£¬£¬£¬£¬£¬¿ªÉè“Æðµ×¹ú¼Ò¼¶APT×éÖ¯”À¸Ä¿£¬£¬£¬£¬£¬£¬Öð¸öÆðµ×È«Çò¸÷µØÇø»îÔ¾µÄÖ÷ÒªAPT×éÖ¯¡£¡£¡£¡£¡£¡£¡£±¾´ÎËø¶¨ÊÇÄÏÑǵØÇøÁíÒ»¸öÖÕÄê»îÔ¾µÄ¹ú¼Ò¼¶ºÚ¿ÍÍŻÏìβÉߣ¨Sidewinder£©¡£¡£¡£¡£¡£¡£¡£
06
ÏìβÉß
ÏìβÉßÊǾݳÆÓÐÄÏÑÇÅä¾°µÄAPT×éÖ¯£¬£¬£¬£¬£¬£¬2012ÄêÖÁ½ñÒ»Ö±´¦ÓÚ»îԾ״̬¡£¡£¡£¡£¡£¡£¡£
ÏìβÉß×éÖ¯Ö÷ÒªÕë¶Ô°Í»ù˹̹¡¢Öйú¡¢°¢¸»º¹¡¢Äá²´¶û¡¢ÃϼÓÀµÈ¹ú¼ÒÕö¿ª¹¥»÷£¬£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡Õþ¸®Íâ½»»ú¹¹¡¢¹ú·À¾üʲ¿·Ö¡¢¸ßµÈ½ÌÓý»ú¹¹µÈÁìÓòµÄÉñÃØÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÄÚ²¿¸ú×Ù±àºÅΪAPT-Q-39

Åä¾°
ÏìβÉߣ¬£¬£¬£¬£¬£¬ÓÖÃûSidewinder£¬£¬£¬£¬£¬£¬ÓÉÍâÑóÇå¾²³§ÉÌ¿¨°Í˹»ùÔÚ2018ÄêµÚÒ»¼¾¶ÈAPTÇ÷ÊÆ±¨¸æÖÐÂÊÏÈÅû¶¡£¡£¡£¡£¡£¡£¡£
2018Äê5Ô£¬£¬£¬£¬£¬£¬º£ÄÚijÇå¾²³§ÉÌÒ²±¨¸æÁËÏìβÉßAPT×éÖ¯Õë¶Ô°Í»ù˹̹µÈÄÏÑǹú¼Ò¾üÊÂÄ¿µÄµÄ¶¨Ïò¹¥»÷Ô˶¯¡£¡£¡£¡£¡£¡£¡£¸ÃAPT×éÖ¯×îÔç¹¥»÷Ô˶¯¿É×·Ëݵ½2012Ä꣬£¬£¬£¬£¬£¬ÖÁ½ñÒ»Ö±´¦ÓÚ»îԾ״̬¡£¡£¡£¡£¡£¡£¡£
ÏìβÉßAPT×éÖ¯Ö÷ÒªÕë¶Ô°Í»ù˹̹¡¢Öйú¡¢°¢¸»º¹¡¢Äá²´¶û¡¢ÃϼÓÀµÈ¹ú¼ÒÕö¿ª¹¥»÷£¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡Õþ¸®Íâ½»»ú¹¹¡¢¹ú·À¾üʲ¿·Ö¡¢¸ßµÈ½ÌÓý»ú¹¹µÈÁìÓòµÄÉñÃØÐÅϢΪĿµÄ£¬£¬£¬£¬£¬£¬¹¥»÷Ô˶¯¾ßÓÐÇ¿ÁÒµÄÕþÖÎÅä¾°¡£¡£¡£¡£¡£¡£¡£
½üÄêÀ´£¬£¬£¬£¬£¬£¬ÏìβÉßAPT×éÖ¯³£ÓõÄÎó²îΪCVE-2017-0199ºÍCVE-2017-11882¡£¡£¡£¡£¡£¡£¡£µ«ÔÚÀúÊ·¹¥»÷Ô˶¯ÖУ¬£¬£¬£¬£¬£¬Ò²Ê¹ÓùýÆäËûÎó²î£¬£¬£¬£¬£¬£¬ºÃ±ÈÕë¶ÔAndroidƽ̨µÄ¶ñÒâÈí¼þ»ñÈ¡rootȨÏÞʱʹÓÃÁËCVE-2019-2215£¬£¬£¬£¬£¬£¬ÒÔ¼°ÔÚÒ»´Î¶ÔÎÒ¹úij¸ßУµÄ¶¨Ïò¹¥»÷ÖÐʹÓÃÁËä¯ÀÀÆ÷Îó²îCVE-2020-0674¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸öÎó²îÔÚÆäʹÓõÄʱ¼ä½ÔÊôÓÚÒѹûÕæÅû¶µÄÎó²î£¬£¬£¬£¬£¬£¬²¢ÇÒ´ÓÆäÏà¹ØµÄʹÓôúÂëÀ´¿´£¬£¬£¬£¬£¬£¬±£´æ¸Ã×éÖ¯ÒÀÍÐÓÚÍøÂç¾üÆ÷É̵ĿÉÄÜ¡£¡£¡£¡£¡£¡£¡£
¹¥»÷ÊÖ¶ÎÓ빤¾ß
ÏìβÉßAPT×éÖ¯³£Í¨¹ý´¹ÂÚÍøÕ¾ÇÔÈ¡¹¥»÷Ä¿µÄ»ú¹¹Ïà¹ØÖ°Ô±µÄµÇ¼ƾ֤£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÓã²æÓʼþͶµÝLNK¿ì½Ý·½·¨Îļþ»òÕßЯ´øÎó²îµÄ¶ñÒâÎĵµ¡£¡£¡£¡£¡£¡£¡£
ÕâЩ¶ñÒâÎļþÔòͨ¹ýÖ´ÐаüÀ¨js´úÂëµÄhtaÎļþ»òÕßjs¾ç±¾·´Éä¼ÓÔØC#Ä£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬È»ºóÔÚÊܺ¦Õß»úеÉÏÊÍ·ÅľÂí³ÌÐò£¬£¬£¬£¬£¬£¬Ä¾Âí³ÌÐòͨ³£Îª¶ñÒâdllÎļþ£¬£¬£¬£¬£¬£¬Ê¹ÓöÔϵͳÖÐÕý³£exeÎļþµÄdll²à¼ÓÔØÊÖÒÕ£¨¼´“°×¼ÓºÚ”£©Æô¶¯ÔËÐС£¡£¡£¡£¡£¡£¡£
£¨Ò»£©¹¥»÷ÊÖ¶Î
1.´¹ÂÚÍøÕ¾
ÏìβÉߣ¨Sidewinder£©Íйܴ¹ÂÚÍøÒ³µÄЧÀÍÆ÷ÓòÃû»áÄ£Äâ¹¥»÷Ä¿µÄÍøÕ¾µÄÓòÃû£¬£¬£¬£¬£¬£¬ºÃ±È´¹ÂÚÓòÃû“mail-nepalgovnp[.]duckdns[.]org”ÓÃÀ´Î±×°ÎªÄá²´¶ûÕþ¸®Ê¹ÓõÄÓòÃû“mail[.]nepal[.]gov[.]np”¡£¡£¡£¡£¡£¡£¡£´¹ÂÚÍøÒ³´Ó¹¥»÷Ä¿µÄµÄÓʼþÍøÕ¾¸´ÖƶøÀ´£¬£¬£¬£¬£¬£¬¾ÓÉÒ»¶¨µÄÐ޸ĺóÓÃÀ´ÇÔȡĿµÄ»ú¹¹Ïà¹ØÖ°Ô±µÄÓÊÏäµÇ¼ƾ֤¡£¡£¡£¡£¡£¡£¡£
ÕâЩ´¹ÂÚÍøÒ³ÔÚÊܺ¦Õß·¢Ë͵Ǽƾ֤ºó´ó´ó¶¼¶¼»áÖØ¶¨Ïòµ½ÔʼµÄÓʼþÍøÕ¾£¬£¬£¬£¬£¬£¬ÉÐÓÐÒ»²¿·Ö»áÖØ¶¨ÏòΪÏÔʾÎĵµ»òÕßÐÂÎÅÍøÒ³£¬£¬£¬£¬£¬£¬ÎĵµÓëÐÂÎŵÄÄÚÈÝÒ»Ñùƽ³£ÓëCOVID-19ÒßÇéºÍÄÏÑǵØÇøµÄÁìÍÁÕù¶ËÓйء£¡£¡£¡£¡£¡£¡£
2.Óã²æ¹¥»÷
ͨ¹ýÓã²æÓʼþͶµÝ¶ñÒâÎĵµÊÇÏìβÉߣ¨Sidewinder£©×éÖ¯×î³£ÓõĹ¥»÷ÊֶΣ¬£¬£¬£¬£¬£¬ÕâЩ×÷ΪÓÕ¶üµÄ¶ñÒâÎĵµ³£¼ûµÄÓÐÈçϼ¸ÖÖÀàÐÍ£º
(1)LNKÎļþ
LNKÎļþµÄÄ¿µÄ³ÌÐò·¾¶±»Ö¸¶¨ÎªÓÃmshta.exeÔ¶³Ì¼ÓÔØÔËÐÐhtaÎļþ£¬£¬£¬£¬£¬£¬½ø¶øÊÍ·ÅÓÕ¶üÎĵµºÍÍê³ÉºóÐøµÄ¶ñÒâÈí¼þÖ²Èë²Ù×÷¡£¡£¡£¡£¡£¡£¡£
(2)Я´øÎó²îµÄOfficeÎĵµ£¬£¬£¬£¬£¬£¬ÆµÈÔʹÓÃÎó²îCVE-2017-11882ºÍCVE-2017-0199¡£¡£¡£¡£¡£¡£¡£
ÔÚÏìβÉß×éÖ¯ÖÆ×÷µÄ¶ñÒâOfficeÎĵµÖУ¬£¬£¬£¬£¬£¬Ò»ÀàÊÇʹÓÃCVE-2017-11882Îó²îÖ´ÐÐ×ÔÉíÊͷŵĻòÕßÔ¶³ÌÏÂÔØµÄhtaÎļþ»òjs¾ç±¾£¬£¬£¬£¬£¬£¬´Ó¶øÍê³ÉºóÐøµÄ¶ñÒâÈí¼þÖ²Èë²Ù×÷£»£»£»£»£»£»£»ÁíÒ»ÀàÔòÊÇʹÓÃCVE-2017-0199Îó²îÔ¶³Ì¼ÓÔØÐ¯´øCVE-2017-11882Îó²îµÄÎĵµ¡£¡£¡£¡£¡£¡£¡£
£¨¶þ£©Ê¹Óù¤¾ß¼°ÊÖÒÕÌØÕ÷
ÏìβÉß×éÖ¯¾ßÓÐWindowsºÍAndroid˫ƽ̨¹¥»÷ÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£ÔÚWindowsƽ̨µÄ¹¥»÷ÊÖ·¨½ÏÁ¿Àο¿£¬£¬£¬£¬£¬£¬ÒÔLNKÎļþ»òÕßÎó²îÎĵµÎª¹¥»÷Èë¿Ú£¬£¬£¬£¬£¬£¬Í¨¹ýÖ´ÐаüÀ¨js´úÂëµÄhtaÎļþ»òjs¾ç±¾·´Éä¼ÓÔØC#dllÎļþ£¬£¬£¬£¬£¬£¬×îºó½èÓɸÃdllÎļþÖ²ÈëľÂí³ÌÐò×é¼þ¡£¡£¡£¡£¡£¡£¡£
ÏìβÉß×éÖ¯µÄ¹¥»÷Á÷³ÌÕûÌå»ù±¾Îȹ̣¬£¬£¬£¬£¬£¬µ«ÎªÁ˶Կ¹Ñо¿Ö°Ô±µÄ·¢Ã÷Åû¶ºÍÇå¾²Èí¼þµÄ¼ì²â²éɱ£¬£¬£¬£¬£¬£¬½üÄêÀ´¸Ã×éÖ¯Ò²Éý¼¶Á˹¥»÷ÊÖ·¨£¬£¬£¬£¬£¬£¬ºÃ±È£º
£¨1£©ºóÐøµÄľÂí³ÌÐò×é¼þ²»ÔÙÖ±½ÓÔÚÍâµØÊÍ·Å£¬£¬£¬£¬£¬£¬¶øÊÇ´ÓÔ¶³ÌЧÀÍÆ÷ÏÂÔØ£¬£¬£¬£¬£¬£¬Ê¹µÃ¸Ã×éÖ¯ÔÚ¹¥»÷Àú³ÌÖÐʵʱ¹ØÍ£Ð§ÀÍÆ÷£¬£¬£¬£¬£¬£¬½µµÍ´úÂë̻¶µÄΣº¦£»£»£»£»£»£»£»
£¨2£©Ìá¸ßÁË´úÂë»ìÏý¶È£¬£¬£¬£¬£¬£¬ºÃ±È×÷ΪÖÐÐÄ×é¼þµÄjs´úÂëͨ¹ýÒýÈë×Ô½ç˵µÄBase64±àÂë¾ÙÐлìÏý£¬£¬£¬£¬£¬£¬C#×é¼þÖк¯ÊýŲÓÃÓÉÖ±½ÓÒýÓÃϵͳAPI±äΪÓÃ×Ô½ç˵·±Ôӵĺ¯ÊýÃû·â×°ËùÐèŲÓõÄAPI¡£¡£¡£¡£¡£¡£¡£
£¨3£©ÏìβÉß×éÖ¯Õë¶ÔAndroidƽ̨µÄ¶ñÒâÈí¼þͨ¹ýÎó²îʹÓûñÈ¡rootȨÏÞ»òÕßÓÕÆÊܺ¦ÕßÊÚȨÒÔ×°ÖÃľÂí³ÌÐòcallCam¡£¡£¡£¡£¡£¡£¡£Ä¾Âí³ÌÐòÍøÂç×°±¸²ÎÊý¡¢Î»Öá¢Îļþ¡¢ÕË»§¡¢Éç½»Èí¼þÊý¾ÝµÈÃô¸ÐÐÅÏ¢²¢ÒÔ¼ÓÃÜÐÎʽÉÏ´«µ½C&CЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£
ÖøÃû¹¥»÷ÊÂÎñ
£¨Ò»£©ÏìβÉߣ¨Sidewinder£©Ê×´ÎÆØ¹â
2018Äê4Ô£¬£¬£¬£¬£¬£¬¿¨°Í˹»ù2018ÄêµÚÒ»¼¾¶ÈAPTÇ÷ÊÆ±¨¸æÌáµ½ÁËÃûΪ“Sidewinder”µÄAPT×éÖ¯¡¾2¡¿£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯¹¥»÷Ä¿µÄΪ°Í»ù˹̹µÄ¾üʲ¿·Ö£¬£¬£¬£¬£¬£¬×îÔç¿É×·ËÝÖÁ2012Äê¡£¡£¡£¡£¡£¡£¡£
2018Äê5ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬º£ÄÚijÇå¾²³§ÉÌÐû²¼±¨¸æÅû¶ÁËÏìβÉß×éÖ¯Õë¶ÔÄÏÑǹ¥»÷Ô˶¯µÄϸ½Ú¡¾3¡¿£ºÊ¹ÓÃCVE-2017-11882Îó²îÔ¶³Ì¼ÓÔØ²¢Ö´ÐÐhtaÎļþ£¬£¬£¬£¬£¬£¬ÎļþÖеľ籾ŲÓÃpowershellÏÂÁîÊÍ·ÅÆäÖÐÉúÑĵÄľÂí³ÌÐò¡£¡£¡£¡£¡£¡£¡£
£¨¶þ£©2019ÄêÕë¶ÔÎÒ¹úµÄ¶à´Î¶¨Ïò¹¥»÷
2019Äê7Ô£¬£¬£¬£¬£¬£¬º£ÄÚijÇå¾²³§ÉÌ·¢Ã÷ÏìβÉß×éÖ¯Õë¶ÔÎÒ¹úµÄ¶¨Ïò¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£Ôڴ˴ι¥»÷ÊÂÎñÖУ¬£¬£¬£¬£¬£¬ÏìβÉßÒÔÎÒ¹ú¹ú·À²¿¹ú¼ÊÏàÖú²¿·Ö·¢Ë͵Ä֪ͨÎļþΪÓÕ¶ü£¬£¬£¬£¬£¬£¬ÏòËû¹úפ»ªÊ¹¹ÝÖ°Ô±Ìᳫ¹¥»÷¡¾4¡¿¡£¡£¡£¡£¡£¡£¡£
¹¥»÷ʹÓõÄЯ´øCVE-2017-11882Îó²îµÄ¶ñÒâÎĵµÎªRTFÃûÌÃÎļþ£¬£¬£¬£¬£¬£¬Îļþ·¿ªºó»á×Ô¶¯ÊÍ·ÅPackage¹¤¾ßÉúÑĵÄjs¾ç±¾£¬£¬£¬£¬£¬£¬Îó²îʹÓúóÖ´ÐÐÊͷŵÄjs¾ç±¾£¬£¬£¬£¬£¬£¬¾ç±¾¿½±´WindowsϵͳÖÐÕý³£µÄexeÎļþ£¬£¬£¬£¬£¬£¬²¢ÊͷżÓÃܵÄľÂí³ÌÐòÊý¾ÝºÍÓÃÓÚ¼ÓÔØÄ¾Âí³ÌÐòµÄ¶ñÒâdllÎļþ£¬£¬£¬£¬£¬£¬Ó뿽±´µÄexeÎļþ×é³É“°×¼ÓºÚ”×éºÏ¡£¡£¡£¡£¡£¡£¡£
ÒԺ󣬣¬£¬£¬£¬£¬ÏìβÉß¶à´ÎÕë¶ÔÎÒ¹úµÄ¶¨Ïò¹¥»÷±»Åû¶¡¾5¡¢6¡¿£¬£¬£¬£¬£¬£¬°üÀ¨Õë¶Ôº£ÄÚij¹ú·À¿ÆÑÐÆóÒµ£¬£¬£¬£¬£¬£¬ÏòÆäÄÚ²¿·¢ËÍÐéαµÄÇå¾²±£ÃÜÊÖ²áºÍÖÎÀíÎļþ£»£»£»£»£»£»£»½«Î±×°µÄ¡¶ÖйúÈËÃñ½â·Å¾üÎÄÖ°Ö°Ô±ÌõÀý¡·µÄÎĵµÍ¶·ÅÖÁ¹ú¼ÒÕþ¸®²¿·Ö£»£»£»£»£»£»£»Õë¶Ô¹ú·À¼°¾üʵÈÏà¹Ø²¿·Ö£¬£¬£¬£¬£¬£¬ÏòÆä·¢ËÍÐéαµÄ“µÚ¾Å½ì±±¾©ÏãɽÂÛ̳¾Û»á”Òé³Ì¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷ÊÂÎñÖУ¬£¬£¬£¬£¬£¬ÏìβÉß½ÓÄÉÁËÓë¹¥»÷Ëû¹úפ»ªÊ¹¹ÝÏàͬµÄÊÖ·¨¡£¡£¡£¡£¡£¡£¡£
£¨Èý£©Òƶ¯¶Ë¹¥»÷ÎäÆ÷ÆØ¹â
2020Äê1Ô£¬£¬£¬£¬£¬£¬ÍâÑóÇå¾²³§ÉÌÇ÷ÊÆ¿Æ¼¼Åû¶ÁËÏìβÉß×éÖ¯Õë¶ÔAndroidƽ̨µÄ¶ñÒâÈí¼þ¡¾7¡¿¡£¡£¡£¡£¡£¡£¡£
ÕâЩ¶ñÒâÈí¼þÔÚGooglePlayÓ¦ÓÃÊÐËÁÖÐαװΪͼƬºÍÎļþÖÎÀíÆ÷¹¤¾ß£¬£¬£¬£¬£¬£¬¾ÓÉÁ½¸ö½×¶ÎµÄÏÂÔØÀú³ÌÔÚÊܺ¦Õß×°±¸ÉÏÖ²Èë×îÖÕµÄľÂí³ÌÐòcallCam¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÒ»¸ö¶ñÒâÈí¼þͨ¹ýʹÓÃCVE-2019-2215Îó²îºÍMediaTek-SU»ñÈ¡rootȨÏÞ£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÊܺ¦ÕßÎÞ½»»¥µÄÇéÐÎϾ²Ä¬×°ÖÃľÂí³ÌÐò£¬£¬£¬£¬£¬£¬ÆäËû¶ñÒâÈí¼þÔòÓÕÆÊܺ¦ÕßÊÚȨ´Ó¶øÊµÏÖľÂí³ÌÐòµÄ×°Öᣡ£¡£¡£¡£¡£¡£Ä¾Âí³ÌÐòÍøÂç×°±¸ÉÏÉúÑĵÄÃô¸ÐÊý¾Ý²¢¼ÓÃÜÉÏ´«µ½C&CЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£
£¨ËÄ£©Ê¹ÓÃÒßÇéÐÅÏ¢¶Ô°Í»ù˹̹µÈ¹úµÄ¹¥»÷Ô˶¯
2020Äê5Ô£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐIJ¶»ñµ½ÏìβÉß×é֯ʹÓÃÒßÇéÏà¹ØÐÅÏ¢×÷ΪÓÕ¶üµÄ¶ñÒâLNKÑù±¾¡¾8¡¿£¬£¬£¬£¬£¬£¬´ËÀàÑù±¾ÒÔÊܺ¦¹ú¼ÒµÄ¾ü·½¿¹»÷ÒßÇéÕ½ÂÔ¡¢¿Õ¾ü´óѧÒßÇéʱ´úÍøÂçÔÚÏ߿γÌÕþ²ßµÈÈÈÃÅÐÅÏ¢×÷Ϊαװ¡£¡£¡£¡£¡£¡£¡£
Ò»µ©Êܺ¦ÕßÖ´ÐдËÀà¶ñÒâÑù±¾£¬£¬£¬£¬£¬£¬LNKÎļþ½«´ÓÔ¶³ÌЧÀÍÆ÷ÏÂÔØ¶ñÒâhta¾ç±¾ÎļþÖ´ÐУ¬£¬£¬£¬£¬£¬¶ñÒâ¾ç±¾½«ÊÍ·ÅչʾÕý³£µÄÓÕ¶üÎĵµÒÔÒÉ»óÊܺ¦Õߣ¬£¬£¬£¬£¬£¬²¢¼ÌÐø´ÓÔ¶³Ì»ñÈ¡µÚ¶þ½×¶Î¶ñÒâhta¾ç±¾ÎļþÖ´ÐС£¡£¡£¡£¡£¡£¡£µÚ¶þ½×¶Î¶ñÒâ¾ç±¾½«ÔÚÊܺ¦ÕßÅÌËã»úÉϰ²ÅÅÏà¹Ø¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬²¢Í¨¹ý°×¼ÓºÚµÄ·½·¨¼ÓÔØ×îÖÕµÄÔ¶³ÌľÂí£¬£¬£¬£¬£¬£¬¿ØÖÆÊܺ¦Õß»úе£¬£¬£¬£¬£¬£¬´Ó¶øÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
£¨Î壩ʹÓÃä¯ÀÀÆ÷Îó²î¹¥»÷ÎÒ¹úij¸ßУ
2020Ä꺣ÄÚijÇå¾²ÍŶÓÅû¶ÁËÏìβÉß×éÖ¯Õë¶ÔÎÒ¹úij¸ßУµÄ¹¥»÷Ô˶¯¡¾9¡¿£¬£¬£¬£¬£¬£¬ÓÕ¶üÎĵµÄÚÈÝΪ2020Äê´º¼¾ÒßÇé·À¿ØÊÂÇéµÄÓÅÒìÎ÷Ï¯ÍÆ¼öÃûµ¥¡£¡£¡£¡£¡£¡£¡£
Ôڴ˴ι¥»÷Ô˶¯ÖУ¬£¬£¬£¬£¬£¬ÏìβÉßʹÓÃÁËÓëÒÔÍù²î±ðµÄ¹¥»÷ÊÖ·¨£º
£¨1£©Ê×ÏȶñÒâÎĵµÍ¨¹ýÔ¶³ÌÄ£°å×¢ÈëµÄ·½·¨¼ÓÔØÐ¯´øCVE-2017-0199Îó²îµÄÎĵµ£»£»£»£»£»£»£»
£¨2£©È»ºóCVE-2017-0199Îó²îÎĵµÔÙÔ¶³Ì¼ÓÔØhtaÎļþ£»£»£»£»£»£»£»
£¨3£©htaÎļþÖаüÀ¨2020ÄêÍ·¹ûÕæÅû¶µÄä¯ÀÀÆ÷Îó²îCVE-2020-0674ʹÓôúÂ룬£¬£¬£¬£¬£¬Îó²îʹÓÃÀֳɺóÊÍ·ÅľÂí×é¼þ¡£¡£¡£¡£¡£¡£¡£
£¨Áù£©¶Ô¶à¹úʵÑé´¹ÂÚ¹¥»÷
2020Äê12Ô£¬£¬£¬£¬£¬£¬ÍâÑóÇå¾²³§ÉÌÇ÷ÊÆ¿Æ¼¼Ðû²¼±¨¸æÅû¶ÁËÏìβÉß×éÖ¯ºã¾Ã¶ÔÄá²´¶û¡¢°¢¸»º¹¡¢ÖйúµÈ¶à¸ö¹ú¼ÒµÄÕþ¸®¡¢Íâ½»¡¢¹ú·À¾üÊ»ú¹¹Õö¿ª´¹ÂÚ¹¥»÷Ô˶¯¡¾10¡¿¡£¡£¡£¡£¡£¡£¡£
ÏìβÉß×é֯ͨ¹ýÄ£Äâ¹¥»÷Ä¿µÄµÄÓòÃû½¨ÉèÍйܴ¹ÂÚÒ³ÃæµÄÓòÃû£¬£¬£¬£¬£¬£¬¸´ÖÆÄ¿µÄ»ú¹¹ÓʼþÍøÕ¾µÄÍøÒ³²¢ÖÆ×÷´¹ÂÚÒ³Ãæ£¬£¬£¬£¬£¬£¬´Ó¶øÇÔÈ¡Ïà¹ØÖ°Ô±µÄÓÊÏäµÇ¼ƾ֤£¬£¬£¬£¬£¬£¬ÎªºóÐøµÄ¶¨Ïò¹¥»÷Ô˶¯×ö×¼±¸¡£¡£¡£¡£¡£¡£¡£
×ܽá
×ÔÊ×´ÎÆØ¹âÒÔÀ´£¬£¬£¬£¬£¬£¬ÏìβÉߣ¨Sidewinder£©×é֯ƵÈÔÔ˶¯£¬£¬£¬£¬£¬£¬¹¥»÷Ä¿µÄ¼¯ÖÐÔÚÄÏÑǶà¹úºÍÖйúµÄÕþ¸®¡¢Íâ½»¡¢¾üÊÂÁìÓò£¬£¬£¬£¬£¬£¬ÌåÏÖÁ˸Ã×éÖ¯¹¥»÷Ô˶¯ÖÐÇ¿ÁÒµÄÕþÖÎÄîÍ·ºÍ±³ºóµÄ¹ú¼ÒʵÁ¦Ö§³Ö¡£¡£¡£¡£¡£¡£¡£
¶àÄêÀ´£¬£¬£¬£¬£¬£¬ÏìβÉß×éÖ¯µÄ¹¥»÷Á÷³ÌÕûÌåûÓÐÌ«´óת±ä£¬£¬£¬£¬£¬£¬µ«ÎªÁ˶Կ¹Çå¾²Èí¼þ¼ì²âºÍÆÊÎöÖ°Ô±×·×Ù£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯Ò²ÔÚһֱˢÐÂÉý¼¶¹¥»÷ÊÖ·¨¡£¡£¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬ÏìβÉß×éÖ¯ÔÚÀúÊ·¹¥»÷Ô˶¯ÖÐʹÓõÄÎó²îÅú×¢£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯¿ÉÄÜÓëÍøÂç¾üÆ÷É̱£´æ¹ØÁª¡£¡£¡£¡£¡£¡£¡£
ÏÖÔÚ£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯¶Ô°üÀ¨ÎÒ¹úÔÚÄڵĶà¸ö¹ú¼ÒÈÔÈ»×é³ÉÑÏÖØÍþв£¬£¬£¬£¬£¬£¬ÐèÒªÎÒÃÇÒ»Á¬¸ú×Ù¹Ø×¢¡£¡£¡£¡£¡£¡£¡£
×¢½â
https://ti.qianxin.com/uploads/2021/02/08/dd941ecf98c7cb9bf0111a8416131aa1.pdf
https://securelist.com/apt-trends-report-q1-2018/85280/
https://s.tencent.com/research/report/479
https://www.secrss.com/articles/13390
https://ti.dbappsecurity.com.cn/blog/articles/2019/08/30/sidewinder-apt-group-attack-embassy-in-china-disclosed/
http://it.rising.com.cn/dongtai/19656.html
https://www.trendmicro.com/en_us/research/20/a/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group.html
https://ti.qianxin.com/blog/articles/the-recent-rattlesnake-apt-organized-attacks-on-neighboring-countries-and-regions/
https://bbs.pediy.com/thread-260640.htm
https://www.trendmicro.com/en_us/research/20/l/sidewinder-leverages-south-asian-territorial-issues-for-spear-ph.html
¹ØÓÚ×÷Õß
Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ºìÓêµÎÍŶӣ¨RedDripTeam£¬£¬£¬£¬£¬£¬@RedDrip7£©£¬£¬£¬£¬£¬£¬ÒÀÍÐÈ«ÇòÁìÏȵÄÇå¾²´óÊý¾ÝÄÜÁ¦¡¢¶àά¶È¶àȪԴµÄÇå¾²Êý¾ÝºÍרҵÆÊÎöʦµÄ¸»ºñÂÄÀú£¬£¬£¬£¬£¬£¬×Ô2015ÄêÒ»Á¬·¢Ã÷¶à¸ö°üÀ¨º£Á«»¨ÔÚÄÚµÄAPT×éÖ¯ÔÚÖйú¾³Äڵĺã¾ÃÔ˶¯£¬£¬£¬£¬£¬£¬²¢Ðû²¼º£ÄÚÊ׸ö×éÖ¯²ãÃæµÄAPTÊÂÎñ½ÒÆÆ±¨¸æ£¬£¬£¬£¬£¬£¬¿ª´´Á˺£ÄÚAPT¹¥»÷Àà¸ß¼¶Íþвϵͳ»¯½ÒÆÆµÄÏȺӡ£¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬Ò»Á¬¸ú×ÙÆÊÎöµÄÖ÷ÒªAPTÍÅ»ïÁè¼Ý47¸ö£¬£¬£¬£¬£¬£¬×ÔÁ¦·¢Ã÷APT×éÖ¯14¸ö£¬£¬£¬£¬£¬£¬Ò»Á¬Ðû²¼APT×éÖ¯µÄ¸ú×Ù±¨¸æÁè¼Ý90ƪ£¬£¬£¬£¬£¬£¬°´ÆÚÊä³ö°ëÄêºÍÕûÄêÈ«ÇòAPTÔ˶¯×ÛºÏÐÔÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£
ʱ¼ä£º2026-04-22
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-18
Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ
ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ