ʱ¼ä£º2021-11-24

±¾ÎÄ4851×ÖÔĶÁÔ¼Ðè14·ÖÖÓ
¹ú¼Ò¼¶APT£¨AdvancedPersistentThreat£¬£¬£¬£¬£¬£¬¸ß¼¶Ò»Á¬ÐÔÍþв£©×éÖ¯ÊÇÓйú¼ÒÅä¾°Ö§³ÖµÄ¶¥¼âºÚ¿ÍÍŻ£¬£¬£¬£¬£¬×¨×¢ÓÚÕë¶ÔÌØ¶¨Ä¿µÄ¾ÙÐкã¾ÃµÄÒ»Á¬ÐÔÍøÂç¹¥»÷¡£¡£¡£¡£¡£
Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!Æìϵĸ߼¶ÍþвÑо¿ÍŶӺìÓêµÎ£¨RedDripTeam£©Ã¿Äê»áÐû²¼È«ÇòAPTÄ걨¡¾1¡¿¡¢Öб¨£¬£¬£¬£¬£¬£¬¶ÔÎôʱ¸÷´óAPTÍÅ»ïµÄÔ˶¯¾ÙÐÐÆÊÎö×ܽᡣ¡£¡£¡£¡£
»¢·ûÖÇ¿âÌØÔ¼Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÆìϺìÓêµÎÍŶӣ¬£¬£¬£¬£¬£¬¿ªÉè“Æðµ×¹ú¼Ò¼¶APT×éÖ¯”À¸Ä¿£¬£¬£¬£¬£¬£¬Öð¸öÆðµ×È«Çò¸÷µØÇø»îÔ¾µÄÖ÷ÒªAPT×éÖ¯¡£¡£¡£¡£¡£±¾´ÎÎÒÃÇÒÀÈ»Ëø¶¨ÔÚÄÏÑǵØÇø£¬£¬£¬£¬£¬£¬ÏÈÈÝÍâµØÇøÖÕÄê»îÔ¾µÄÁíÒ»¸ö¹ú¼Ò¼¶ºÚ¿ÍÍŻ¶ÇÄԳ棨DonotTeam£©¡£¡£¡£¡£¡£
08
¶ÇÄÔ³æ
¶ÇÄÔ³æÊǾݳÆÓÐÄÏÑÇÅä¾°µÄAPT×éÖ¯£¬£¬£¬£¬£¬£¬Æä¹¥»÷Ô˶¯×îÔçÓÉÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐÄÓÚ2017ÄêÂÊÏÈ·¢Ã÷²¢¹ûÕæÅû¶¡£¡£¡£¡£¡£
¶ÇÄÔ³æ×éÖ¯Ö÷ÒªÕë¶Ô°Í»ù˹̹¡¢Öйú¡¢Ë¹ÀïÀ¼¿¨¡¢Ì©¹ú£¬£¬£¬£¬£¬£¬ÒÔ¼°¿ËʲÃ×¶ûµØÇøµÈ¹ú¼ÒºÍµØÇøÌᳫ¹¥»÷£¬£¬£¬£¬£¬£¬¶ÔÕþ¸®»ú¹¹¡¢¹ú·À¾üʲ¿·ÖÒÔ¼°ÉÌÎñÁìÓòÖ÷ÒªÈËʿʵÑéÍøÂçÌØ¹¤Ô˶¯¡£¡£¡£¡£¡£Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÄÚ²¿¸ú×Ù±àºÅΪAPT-Q-38

Åä¾°
¶ÇÄԳ棬£¬£¬£¬£¬£¬ÓÖÃûDonotTeam¡¢SectorE02£¬£¬£¬£¬£¬£¬ÊÇÒ»¸ö¾Ý³ÆÓÐÄÏÑÇÅä¾°µÄAPT×éÖ¯£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯µÄ¹¥»÷Ô˶¯×îÔçÓÉÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐÄÓÚ2017ÄêÂÊÏÈ·¢Ã÷²¢¹ûÕæÅû¶¡£¡£¡£¡£¡£¶ÇÄÔ³æ×éÖ¯µÄ¹¥»÷Ô˶¯×îÔç¿É×·Ëݵ½2016Ä꣬£¬£¬£¬£¬£¬Æù½ñΪֹ¸Ã×éÖ¯Ò»Ö±´¦ÓÚ»îԾ״̬¡£¡£¡£¡£¡£
¶ÇÄÔ³æ×éÖ¯Ö÷ÒªÕë¶Ô°Í»ù˹̹¡¢Öйú¡¢¿ËʲÃ×¶ûµØÇø¡¢Ë¹ÀïÀ¼¿¨¡¢Ì©¹úµÈÄÏÑǹú¼ÒºÍµØÇøÌᳫ¹¥»÷£¬£¬£¬£¬£¬£¬¶ÔÕþ¸®»ú¹¹¡¢¹ú·À¾üʲ¿·ÖÒÔ¼°ÉÌÎñÁìÓòÖ÷ÒªÈËʿʵÑéÍøÂçÌØ¹¤Ô˶¯¡£¡£¡£¡£¡£
¶ÇÄÔ³æ×éÖ¯ÔÚһЩ¹¥»÷Ô˶¯ÖÐʹÓõŤ¾ßÌØÕ÷ºÍÍøÂç»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬ÓëÄÏÑÇµÄÆäËû¹¥»÷×éÖ¯£¬£¬£¬£¬£¬£¬ºÃ±ÈÂûÁ黨£¨BITTER£©¡¢Ä¦Ú²Ý£¨Patchwork£©£¬£¬£¬£¬£¬£¬±£´æÖصþ£¬£¬£¬£¬£¬£¬²»É¨³ýÕâЩ×éÖ¯Óɸü¸ß²ã¼¶µÄ»ú¹¹Ïòµ¼Ðµ÷µÄ¿ÉÄÜÐÔ¡£¡£¡£¡£¡£

2021Äê11ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬¾ÙÊÀʱ±¨Åû¶ÄÏÑǵØÇøµÄ¹ú¼Ò¼¶APT×éÖ¯
¹¥»÷ÊÖ¶ÎÓ빤¾ß
¶ÇÄÔ³æ×éÖ¯µÄ¹¥»÷Ô˶¯Éæ¼°WindowsºÍAndroid˫ƽ̨¡£¡£¡£¡£¡£
ÔÚWindowsƽ̨ÉÏ£¬£¬£¬£¬£¬£¬¶ÇÄÔ³æ×éÖ¯³£ÓôøÓкê´úÂë»òÕßÔ¶³ÌÄ£°åµÄ¶ñÒâÎĵµÌᳫ¹¥»÷£¬£¬£¬£¬£¬£¬¹¥»÷Á÷³ÌÒ»Ñùƽ³£Îª¶ñÒâÎĵµÊÍ·ÅÖÐÐÄ×é¼þ£¬£¬£¬£¬£¬£¬ÔÙͨ¹ý¶à½×¶ÎdownloaderÏÂÔØ²å¼þÖ´ÐÐÏêϸµÄľÂí¹¦Ð§¡£¡£¡£¡£¡£ÔÚÕû¸ö¹¥»÷Á÷³ÌÖУ¬£¬£¬£¬£¬£¬Ò»Ð©ÖÐÐĽ׶εÄ×é¼þÔÚ½øÈëÏÂÒ»½×¶Îǰ»áͨ¹ýbat¾ç±¾Ö´ÐÐ×Ôɾ³ý²Ù×÷£¬£¬£¬£¬£¬£¬»òÕߺóÒ»½×¶ÎµÄ×é¼þÔÚÖ´ÐÐÖ®ºó»áɾ³ýǰһ½×¶ÎµÄ×é¼þ£¬£¬£¬£¬£¬£¬´Ó¶ø´ó´ó½µµÍÕû¸ö¹¥»÷Á÷³ÌÖдúÂë̻¶µÄΣº¦¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬¶ÇÄÔ³æ×éÖ¯ÔÚÔçÆÚ¹¥»÷Ô˶¯ÖоÍ×îÏÈÒÔGoogleDocÎĵµÐ§ÀÍÎªÔØÌåת´ïC&CЧÀÍÆ÷ÐÅÏ¢¡£¡£¡£¡£¡£
¶ÇÄÔ³æ×éÖ¯Õë¶ÔAndroidƽ̨µÄ¶ñÒâÈí¼þÓÐʱ»áÍŽᴹÂÚÍøÕ¾¾ÙÐÐÈö²¥¡£¡£¡£¡£¡£¶ñÒâÈí¼þ¾³£¾ÓÉ¶à·½ÃæÎ±×°£º
£¨1£©Èí¼þͼ±êαװ£¬£¬£¬£¬£¬£¬Í¼±êαװΪ¾ßÓÐÕë¶ÔÐÔµÄÓ¦ÓÃÈí¼þ£¨ºÃ±È¿ËʲÃ×¶ûÐÂÎÅ¡¢Ó¡¶ÈÎý¿Ë½ÌµÈÏà¹ØÓ¦Óã©£¬£¬£¬£¬£¬£¬»òÕßαװ³ÉͨÓÃÐÍÓ¦ÓÃÈí¼þ£¨ºÃ±ÈVPN¡¢¹È¸èЧÀÍ£©£»£»£»£»£»£»£»£»
£¨2£©ÔËÐкóÐÐΪαװ£¬£¬£¬£¬£¬£¬ÔËÐкóҪôͨ¹ýչʾÕý³£Ó¦ÓõĹ¦Ð§Òþ²Ø×ÔÉí£¬£¬£¬£¬£¬£¬ÒªÃ´Í¨¹ýÌáÐÑÓÕÆÐÔÐÅÏ¢£¨ÈçÈí¼þÒÑÐ¶ÔØ£©²¢ÇÒÒþ²ØÍ¼±êɾ³ý¿ì½Ý·½·¨ÒÔÒþ²ØÄ¾Âí³ÌÐò¡£¡£¡£¡£¡£
£¨Ò»£©¹¥»÷ÊÖ¶Î
1.Óã²æ¹¥»÷
ͨ¹ýÓã²æÓʼþͶµÝ¶ñÒâÎĵµÊǶÇÄÔ³æ×éÖ¯³£ÓõÄÒ»ÖÖÊֶΡ£¡£¡£¡£¡£ÓëÆäËû¹¥»÷×éÖ¯·×ÆçÑùµÄÊÇ£¬£¬£¬£¬£¬£¬¶ÇÄÔ³æ×éÖ¯ÖÆ×÷µÄ¶ñÒâÎĵµÓÐʱ¼äÊÇ¿ÕȱÄÚÈÝ£¬£¬£¬£¬£¬£¬²»°üÀ¨ÓëÎĵµÃûÏà¹ØµÄÏêϸÓÕ¶üÄÚÈÝ¡£¡£¡£¡£¡£¸Ã×éÖ¯¾³£Ê¹ÓõĶñÒâÎĵµÓÐÈçϼ¸ÖÖÀàÐÍ£º
£¨1£©ºê´úÂëÎĵµ
ͨ¹ýÎĵµÖеĺê´úÂëÊͷźóÐø×é¼þ²¢Ö´ÐС£¡£¡£¡£¡£ºê´úÂëÍùÍù»áµ¯ÍÉ»¯ÎóÐÂÎÅÌáÐÑ¿ò£¬£¬£¬£¬£¬£¬ÈÃÊܺ¦ÕßÎóÒÔΪºê´úÂëδÄÜÀÖ³ÉÖ´ÐУ¬£¬£¬£¬£¬£¬½µµÍÊܺ¦ÕßСÐÄÐÄ¡£¡£¡£¡£¡£
£¨2£©Ô¶³ÌÄ£°åÎĵµ
ͨ¹ýÔ¶³ÌÄ£°å×¢ÈëµÄ·½·¨Ô¶³Ì¼ÓÔØÐ¯´øCVE-2017-11882Îó²îµÄÎĵµ£¬£¬£¬£¬£¬£¬È»ºóͨ¹ýÎó²îÎĵµÊͷźóÐø×é¼þ²¢Ö´ÐС£¡£¡£¡£¡£2021Äê¶ÇÄÔ³æ×éÖ¯×îÏÈʹÓÃRTFÎĵµ×¢ÈëÔ¶³ÌÄ£°å£¬£¬£¬£¬£¬£¬½èÖúRTFÎĵµÖеÄunicode±àÂë·½·¨Òþ²ØÔ¶³ÌÄ£°åµÄURL£¬£¬£¬£¬£¬£¬ÒÔÈÆ¹ý¶ÔURLµÄ¾²Ì¬¼ì²â¡£¡£¡£¡£¡£
2.´¹ÂÚÍøÕ¾
¶ÇÄÔ³æ×éÖ¯³£½èÖú´¹ÂÚÍøÕ¾Èö²¥Òƶ¯¶Ë¶ñÒâÈí¼þ¡£¡£¡£¡£¡£ÔÚÊ×´ÎÅû¶µÄÒÆ¶¯¶Ë¹¥»÷Ô˶¯ÖУ¬£¬£¬£¬£¬£¬¶ÇÄÔ³æ×éÖ¯¹¹½¨ÁËÒ»¸ö¼òÆÓµÄ¹¤¾ßÓ¦ÓÃÏÂÔØÍøÒ³ÍйÜÒÆ¶¯¶Ë¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¶ÇÄÔ³æ×éÖ¯»¹¶à´ÎαÔìÕë¶Ô°Í»ù˹̹µÄÔÚÏß½á½»ÍøÕ¾£¬£¬£¬£¬£¬£¬²¢ÔÚÍøÕ¾ÖÐÌṩÏìÓ¦É罻̸ÌìÓ¦ÓõÄÏÂÔØ£¬£¬£¬£¬£¬£¬¶øÕâЩӦÓÃÏÖʵÉÏÊǸÃ×éÖ¯µÄAndroidľÂí¡£¡£¡£¡£¡£
£¨¶þ£©Ê¹Óù¤¾ß¼°ÊÖÒÕÌØÕ÷
¶ÇÄÔ³æ×éÖ¯Õë¶ÔWindowsƽ̨ÏȺóʹÓÃÁËÁ½Ì×¶ÀÍ̵ĶñÒâ´úÂë¿ò¼Ü£ºEHDevelºÍyty£¬£¬£¬£¬£¬£¬ÕâÁ½Ì׿ò¼Ü¾ùÖ§³Öͨ¹ý²å¼þÍØÕ¹Ä¾Âí¹¦Ð§¡£¡£¡£¡£¡£
½üÄêÀ´¸Ã×é֯ʹÓõĶñÒâ´úÂëËäȻһֱÔÚ¸üУ¬£¬£¬£¬£¬£¬µ«ÕûÌå½á¹¹²¢Ã»ÓÐÍÑÀëyty¿ò¼Ü£¬£¬£¬£¬£¬£¬¸Ã¿ò¼ÜµÄ½á¹¹¿É·ÖΪÁ½½×¶ÎdownloaderºÍһϵÁй¦Ð§²å¼þ£º
(1)µÚÒ»½×¶Îdownloader×é¼þ¼ì²âÔËÐÐÇéÐΣ¬£¬£¬£¬£¬£¬ÊµÏÖ³¤ÆÚ»¯£¬£¬£¬£¬£¬£¬½¨Éè¾ßÓÐϵͳÒþ²ØÊôÐÔµÄÎļþĿ¼£¬£¬£¬£¬£¬£¬È»ºóÍøÂçÖÖÖÖÖ÷»úÐÅÏ¢²¢»Ø´«¸øC&CЧÀÍÆ÷£¬£¬£¬£¬£¬£¬ÔÙ´ÓC&CЧÀÍÆ÷ÏÂÔØµÚ¶þ½×¶Îdownloader£»£»£»£»£»£»£»£»
(2)µÚ¶þ½×¶ÎdownloaderÓÃÓÚÏÂÔØÖÖÖÖ¹¦Ð§²å¼þ£¬£¬£¬£¬£¬£¬ÔËÐвå¼þÖ´ÐÐÏêϸµÄľÂí¹¦Ð§¡£¡£¡£¡£¡£
ÆäÖÐyty¿ò¼ÜµÄµÚÒ»½×¶ÎdownloaderÓɶñÒâÎĵµÖ±½ÓÊÍ·Å£¬£¬£¬£¬£¬£¬»òÊǶñÒâÎĵµÏÈÊÍ·ÅÖÐÐÄ×é¼þ£¬£¬£¬£¬£¬£¬ÔÙÓÉÖÐÐÄ×é¼þ½øÒ»²½ÊÍ·Å»òÕß´ÓC&CЧÀÍÆ÷ÏÂÔØ¡£¡£¡£¡£¡£ÏÖÔÚÒÑÖªµÄ²å¼þ¹¦Ð§°üÀ¨£º½ØÍ¼¡¢¼üÅ̼ͼ¡¢ÍøÂçÌØ¶¨ÀàÐÍÎļþ¡¢ä¯ÀÀÆ÷Ãô¸ÐÐÅÏ¢ÇÔÈ¡¡¢ÎļþÉÏ´«µÈ¡£¡£¡£¡£¡£
¶ÇÄÔ³æ×éÖ¯Õë¶ÔAndroidƽ̨µÄ¶ñÒâÈí¼þͨ³£Î±×°ÎªÕý³£Ó¦ÓÃÓÕʹÊܺ¦Õß×°ÖÃÈ»ºóÒþ²ØÔËÐУ¬£¬£¬£¬£¬£¬¸Ã×éÖ¯µÄAndroidľÂí»ñÈ¡Êܺ¦Õß×°±¸µÄµØÀíλÖá¢Í¨»°Â¼Òô¡¢Í¨Ñ¶Â¼¡¢¶ÌÐŵÈÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¶ÇÄÔ³æ×éÖ¯Ò»Ö±Éý¼¶Òƶ¯¶Ë¹¥»÷ÊÖ·¨£¬£¬£¬£¬£¬£¬×Ô2020ÄêÆð×îÏȽèÖúGoogleFirebaseCloudMessaging(FCM)ЧÀÍÏò¶ñÒâÈí¼þÏ·¢ÏÂÔØºóÐøÔØºÉµÄURL£¬£¬£¬£¬£¬£¬²»µ«ÔöÌíÁËÒþ²ØÐÔ£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔ×öµ½ËæÊ±Ìæ»»C&CЧÀÍÆ÷ÒÔ¼á³Ö¶ÔѬȾװ±¸µÄ¿ØÖÆ¡£¡£¡£¡£¡£
ÖøÃû¹¥»÷ÊÂÎñ
£¨Ò»£©¶ÇÄÔ³æ×éÖ¯Ê×´ÎÆØ¹â
2017Äê3Ô£¬£¬£¬£¬£¬£¬º£ÄÚijÇå¾²³§ÉÌ·¢Ã÷ÁËÒ»ÀඨÏò¹¥»÷µÄÑù±¾£¬£¬£¬£¬£¬£¬ÒÉËÆÊÇδ֪µÄAPT×éÖ¯µÄ¹¥»÷Ðж¯Ñù±¾¡£¡£¡£¡£¡£Í¬Äê6Ô£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐĺìÓêµÎÍŶÓÈ·Èϲ¢ÆØ¹âÁ˸ÃAPT×éÖ¯Õë¶Ô°Í»ù˹̹µÄ¶¨Ïò¹¥»÷Ô˶¯£¬£¬£¬£¬£¬£¬²¢ÏêϸÆÊÎöºÍÅû¶Á˸Ã×é֯ʹÓõĶÀÍ̵ÄEHDevel¶ñÒâ´úÂë¿ò¼Ü¡¾2¡¿¡£¡£¡£¡£¡£
2018Äê3Ô£¬£¬£¬£¬£¬£¬ÍâÑóÇå¾²ÍŶÓASERT¼ÌÐøÅû¶Á˸Ã×é֯еĶñÒâ´úÂë¿ò¼Üyty£¬£¬£¬£¬£¬£¬²¢Æ¾Ö¤PDB·¾¶ÖеĻúеÓû§Ãû½«¸Ã×éÖ¯ÃüÃûΪDonot¡¾3¡¿¡£¡£¡£¡£¡£Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐĽ«¸ÃAPT×éÖ¯ÕýʽÃüÃûΪ“¶ÇÄÔ³æ”×éÖ¯£¨DonotµÄÒôÒ룩¡£¡£¡£¡£¡£

ͼ1ASERTÅû¶µÄyty¶ñÒâ´úÂë×é¼þ¡¾3¡¿
£¨¶þ£©Òƶ¯¶Ë¹¥»÷Ô˶¯Ê×´ÎÅû¶
2018Äê8Ô£¬£¬£¬£¬£¬£¬¶ÇÄÔ³æ×éÖ¯Õë¶ÔÒÆ¶¯¶ËµÄ¹¥»÷Ô˶¯Ê×´ÎÅû¶¡¾4¡¿¡£¡£¡£¡£¡£Ôڴ˴ι¥»÷Ô˶¯ÖУ¬£¬£¬£¬£¬£¬¶ÇÄÔ³æ×éÖ¯½«¶ñÒâAPPαװΪÈçKNSLite(¿ËʲÃ×¶ûÐÂÎÅЧÀÍ)¡¢VPN¡¢¹È¸èЧÀ͵ÈÓ¦Ó㬣¬£¬£¬£¬£¬²¢ÔÚÃâ·ÑÔÚÏßÍøÕ¾Æ½Ì¨WeeblyÉϴÁËÒ»¸ö¼òÆÓµÄ´¹ÂÚÍøÕ¾ÓÃÓÚÈö²¥¶ñÒâÈí¼þ¡£¡£¡£¡£¡£
¶ñÒâAPP×îÔç·ºÆðÓÚ2017Äê7Ô£¬£¬£¬£¬£¬£¬ÔÚ2018Äê½øÈë»îÔ¾ÆÚ£¬£¬£¬£¬£¬£¬¹¥»÷Ä¿µÄΪ¿ËʲÃ×¶ûµØÇø¡£¡£¡£¡£¡£ÕâЩ¶ñÒâAPP¾ùΪAndroidľÂí£¬£¬£¬£¬£¬£¬Äܹ»ÏìÓ¦Ô¶³Ì¹¥»÷Ö¸ÁîÖ´ÐмÒô¡¢ÉÏ´«ÁªÏµÈË/ͨ»°¼Í¼/¶ÌÐŵȲÙ×÷£¬£¬£¬£¬£¬£¬ÍøÂçµÄÊܺ¦ÕßÐÅÏ¢¿ÉÄÜÓÃÓÚºóÐøµÄÓã²æÓʼþºÍ¶ÌÐÅͶµÝ¡£¡£¡£¡£¡£
£¨Èý£©Õë¶ÔÔÚ»ª°Í»ù˹̹ÉÌÎñÈËÊ¿µÄ¶¨Ïò¹¥»÷
2018Äê12Ô£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!Åû¶Á˶ÇÄÔ³æ×éÖ¯¶ÔÔÚÎÒ¹ú¾³Äڵİͻù˹̹Ö÷ÒªÉÌÎñÈËÊ¿µÄ¶¨Ïò¹¥»÷Ô˶¯¡¾5¡¿£¬£¬£¬£¬£¬£¬¸ÃÂÖ¹¥»÷Ô˶¯×îÔ籬·¢ÔÚ2018Äê5Ô¡£¡£¡£¡£¡£Ôڴ˴ι¥»÷ÖУ¬£¬£¬£¬£¬£¬¹¥»÷Õß¼ÌÐøÊ¹ÓöñÒâ´úÂë¿ò¼Üyty£¬£¬£¬£¬£¬£¬Í¨¹ýÓã²æ´¹ÂÚÓʼþÓÕÆ¹¥»÷Ä¿µÄ·¿ª´øÓжñÒâºê´úÂëµÄÎĵµ£¬£¬£¬£¬£¬£¬ÊͷŵÄľÂí¶Ô¹¥»÷Ä¿µÄ»úе¾ÙÐÐÁ˳¤Ê±¼äµÄ¿ØÖÆ¡£¡£¡£¡£¡£¶ÇÄÔ³æ×éÖ¯Ôڴ˹¥»÷Ô˶¯ÖÐÒÀÈ»ÈÃÖÐÐÄ×é¼þÖ´ÐÐ×Ôɾ³ý²Ù×÷£¬£¬£¬£¬£¬£¬ÊÔͼïÔ̹¥»÷ºÛ¼£¡£¡£¡£¡£¡£
´Ó²¶»ñµÄ¹¥»÷Ô˶¯À´¿´£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ÈÔÒÔ°Í»ù˹̹Ïà¹ØÈËÊ¿×÷ΪÖ÷Òª¹¥»÷Ä¿µÄ£¬£¬£¬£¬£¬£¬ÉõÖÁ½«¹¥»÷¹æÄ£À©´óµ½°üÀ¨ÔÚ»ªµÄ°Í»ù˹ְ̹ԱºÍ»ú¹¹¡£¡£¡£¡£¡£

ͼ2¶ÇÄÔ³æ×éÖ¯Õë¶ÔÔÚ»ª°Í»ù˹̹ÉÌÎñÈËÊ¿µÄ¶¨Ïò¹¥»÷Á÷³Ì¡¾5¡¿
£¨ËÄ£©¶Ô°Í»ù˹̹Õþ¸®µÄÓã²æ¹¥»÷
2019Äê3ÔÂÖÁ7ÔÂʱ´ú¶ÇÄÔ³æ×éÖ¯¶Ô°Í»ù˹̹Õþ¸®»ú¹¹¡¢¹ú·ÀÇ鱨²¿·ÖÒ»Á¬ÊµÑéÓã²æ¹¥»÷¡¾6¡¿¡£¡£¡£¡£¡£¶ÇÄÔ³æ×éÖ¯Ôڴ˴ι¥»÷ºóÆÚ½×¶ÎͶµÝµÄÓÕ¶üÎĵµ»áͨ¹ýºê´úÂ뵯³ö“ÎļþÒÑË𻵔µÈ¹ýʧÐÅÏ¢ÓÕÆÊܺ¦Õߣ¬£¬£¬£¬£¬£¬½µµÍÊܺ¦ÕßµÄСÐÄÐÄ¡£¡£¡£¡£¡£
¶ÇÄÔ³æÔÚÕâ´Î¹¥»÷ÖÐʹÓõÄyty¿ò¼Ü¾ßÓÐÓëÕë¶ÔÔÚ»ª°Í»ù˹̹ÉÌÎñÈËÊ¿¹¥»÷Ô˶¯ÖÐÏàͬµÄÌØÕ÷£º
£¨1£©ÏÂÔØ¹¦Ð§²å¼þµÄURLÃûÌÃΪ“/orderme/[ÅÌËã»úÃû]-[Ëæ»úÊý]”£¬£¬£¬£¬£¬£¬[ÅÌËã»úÃû]-[Ëæ»úÊý]ÔÚľÂíÖ´ÐÐʱÌìÉú²¢ÉúÑÄÔÚÎļþÖУ¬£¬£¬£¬£¬£¬ÓÃÓÚÇø·Ö²î±ðµÄѬȾװ±¸£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÆ¾Ö¤URLÖ¸¶¨Ìض¨µÄѬȾÕß»ñÈ¡ºóÐø²å¼þ£»£»£»£»£»£»£»£»
£¨2£©ÏÂÔØ²å¼þµÄdownloader´ÓC&CЧÀÍÆ÷»ñÈ¡3ÖÖÀàÐ͵ÄÏìÓ¦£¬£¬£¬£¬£¬£¬»®·ÖÊÇ£º“Content-Type:application”,“Content-Type:cmdline”ºÍ“Content-Type:batcmd”¡£¡£¡£¡£¡£
£¨Î壩ӡ°Í¿ËʲÃ×¶û³åͻʱ´úÈö²¥AndroidľÂí
2019Äê4Ô£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!¸ß¼¶ÍþвÑо¿ÍŶӲ¶»ñµ½Óë¶ÇÄÔ³æ×éÖ¯Ïà¹ØµÄAndroidľÂíÑù±¾£¬£¬£¬£¬£¬£¬·¢Ã÷¸Ã×éÖ¯¶ÔʹÓõĶñÒⰲ׿APK¿ò¼Ü¾ÙÐдó¹æÄ£Éý¼¶¡¾7¡¿¡£¡£¡£¡£¡£Ð¯´øÄ¾ÂíµÄ¶ñÒâAPPÃûΪ“KashmirVoice”(¿ËʲÃ×¶ûÖ®Éù)£¬£¬£¬£¬£¬£¬Æäʱӡ¶ÈºÍ°Í»ù˹̹ÔÚ¿ËʲÃ×¶ûµØÇøµÄĦ²Á¼Ó¾ç£¬£¬£¬£¬£¬£¬¶ø¿ËʲÃ×¶ûÖ®Éù×Ô¼ºÊÇÓÃÓÚÐû´«Ó¡¶È¾ü·½±©Á¦ÐÐΪµÄÍøÕ¾£¬£¬£¬£¬£¬£¬ÒÉËÆÓɰͻù˹̹½¨É裬£¬£¬£¬£¬£¬Òò´Ë¸ÃAPPÓкܿÉÄÜÊÇÕë¶ÔһЩ»á»á¼û¸ÃÍøÕ¾µÄ°Í»ù˹̹ÈËËùÈ«Ð͍×ö¡£¡£¡£¡£¡£
2019Äê9Ô£¬£¬£¬£¬£¬£¬Ó¡°ÍÔÚ¿ËʲÃ×¶ûµØÇø³åͻһֱÉý¼¶£¬£¬£¬£¬£¬£¬¶ÇÄÔ³æÍ¨¹ý·ÂðKashmirNewsService£¨¿ËʲÃ×¶ûÐÂÎÅЧÀÍ£©µÄAPP“KNS”Èö²¥Ä¾Âí¡¾8¡¿¡£¡£¡£¡£¡£¶ñÒâAPPÔËÐÐÒԺ󣬣¬£¬£¬£¬£¬²¢Ã»ÓÐÏñÒÔÍùÒ»ÑùÒþ²Ø×ÔÉíͼ±ê£¬£¬£¬£¬£¬£¬¶øÊÇͨ¹ý·ÂðKashmirNewsService£¨¿ËʲÃ×¶ûÐÂÎÅЧÀÍ£©Õ¹ÏÖ¸øÓû§ÍêÕûµÄÐÂÎÅAPP¹¦Ð§£¬£¬£¬£¬£¬£¬´Ó¶øÈÃÊܺ¦Õß¶¨ÐÄʹÓ㬣¬£¬£¬£¬£¬ÔöÌí×ÔÉíµÄÒþ²ØÐÔ¡£¡£¡£¡£¡£
£¨Áù£©Ê¹Óô¹ÂÚÍøÕ¾ºÍÉç½»Èí¼þÌá³«ÒÆ¶¯¹¥»÷
2020Äê4Ô£¬£¬£¬£¬£¬£¬º£ÄÚÇå¾²³§É̼à²âµ½¶ÇÄÔ³æ×é֯ͨ¹ý½«¶ñÒâÈí¼þαװ³ÉÔÚÏß̸Ì칤¾ßRapidChat£¬£¬£¬£¬£¬£¬Ê¹Óô¹ÂÚÍøÕ¾ºÍÉç½»Èí¼þÌá³«ÍøÂç¹¥»÷¡¾9¡¿¡£¡£¡£¡£¡£´Ë´Î¹¥»÷Ô˶¯ÖУ¬£¬£¬£¬£¬£¬¹¥»÷ÕߴÁËÃûΪRapidChatÔÚÏß̸Ì칦ЧµÄ´¹ÂÚÍøÕ¾£¬£¬£¬£¬£¬£¬ÍøÕ¾Ê×Ò³ÏÈÈÝ³ÆÆäΪȫÌìϰͻù˹̹ÈË×îϲ»¶µÄ̸Ì쳡ºÏ£¬£¬£¬£¬£¬£¬Î±ÔìÁ˶àÃûÂþÑÜÔÚÌìϸ÷µØ°Í»ù˹̹ÐéαÈËÎï¡£¡£¡£¡£¡£ÍøÕ¾»¹ÌṩÁËÏìÓ¦µÄ̸ÌìAPPÈí¼þÏÂÔØ¡£¡£¡£¡£¡£
ͨ¹ý¸ÃÁ´½ÓÏÂÔØµÄAPPÈí¼þÏÖʵÉÏΪAndroidľÂí£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷Ñù±¾µÄ¶ñÒ⹦ЧºÍÔÆ¶ËÖ´ÐÐÏÂÁîÓë¶ÇÄÔ³æÖ®Ç°µÄAndroidƽ̨¹¥»÷Ñù±¾ÍêȫһÖ£¬£¬£¬£¬£¬£¬²»¹ý¹¥»÷ÕßÔڴ˴ι¥»÷Ñù±¾ÖÐÌí¼ÓÁ˺ǫ́ÑÓʱÔËÐеÄÏà¹Ø°ü£¬£¬£¬£¬£¬£¬ÒÔÖ§³ÖÆäÔڸ߰汾AndroidϵͳÉÏʵÏÖºǫ́ÔËÐС£¡£¡£¡£¡£
£¨Æß£©Òƶ¯¶ËÎäÆ÷¿âÉý¼¶ÔÙ¶ÈÌᳫ¹¥»÷
2020Äê10Ô£¬£¬£¬£¬£¬£¬º£ÄÚÍâÇå¾²³§É̾ù·¢Ã÷¶ÇÄÔ³æ×éÖ¯µÄAndroidľÂí×îÏÈʹÓÃGoogleFirebaseCloudMessaging(FCM)ЧÀÍÏ·¢ÓÃÓÚÏÂÔØºóÐøÔØºÉµÄC&CЧÀÍÆ÷ÐÅÏ¢¡¾10,11¡¿¡£¡£¡£¡£¡£

ͼ3¶ÇÄÔ³æ×éÖ¯ÔÚÒÆ¶¯¶Ë¹¥»÷Ô˶¯ÖÐʹÓÃGoogleFCMЧÀÍ¡¾10¡¿
Ôڴ˴ι¥»÷Ô˶¯ÖУ¬£¬£¬£¬£¬£¬¶ÇÄÔ³æ×é֯ʹÓÃαװ³É°Í»ù˹̹ʢÐеÄÔÚÏß½á½»ÍøÕ¾LoveHabibiµÄ´¹ÂÚÍøÕ¾Èö²¥¶ñÒâAPP¡£¡£¡£¡£¡£Æ¾Ö¤¶ÔÊܺ¦ÕßµØÀíλÖÃµÄÆÊÎö£¬£¬£¬£¬£¬£¬¶ÇÄÔ³æ´Ë´Î¹¥»÷µÄÄ¿µÄÖ÷ҪΪ°Í»ù˹̹ºÍ¿ËʲÃ×¶ûµØÇø£¬£¬£¬£¬£¬£¬²¢ÇÒÊܺ¦Õß¿ÉÄܰüÀ¨¾üÊÂÅä¾°Ö°Ô±¡£¡£¡£¡£¡£¹¥»÷ÖÐʹÓõĶñÒâÈí¼þ¾ßÓÐÒÔÏÂÌØµã£º
(1)¹¥»÷Õß¿ÉÒÔÆ¾Ö¤´ÓѬȾװ±¸»Ø´«µÄÐÅϢѡÔñÌØ¶¨Êܺ¦ÕßÏÂÔØºóÐøÔØºÉ£¬£¬£¬£¬£¬£¬ïÔÌÁ˺óÐøÔØºÉ̻¶µÄΣº¦£»£»£»£»£»£»£»£»
(2)½èÖúFCMЧÀÍÏ·¢C&CЧÀÍÆ÷ÐÅÏ¢£¬£¬£¬£¬£¬£¬Òþ²ØÐÔÇ¿£¬£¬£¬£¬£¬£¬²¢ÇÒ×ÝÈ»ÏÖÓÐC&CЧÀÍÆ÷̻¶£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒ²¿ÉÒÔʵʱÇл»µ½ÐµÄC&CЧÀÍÆ÷£¬£¬£¬£¬£¬£¬Î¬³Ö¶ÔѬȾװ±¸µÄ¿ØÖÆ¡£¡£¡£¡£¡£
×ܽá
ºã¾ÃÒÔÀ´£¬£¬£¬£¬£¬£¬¶ÇÄÔ³æ×éÖ¯Õë¶ÔÄÏÑǶà¹úµÄÕþ¸®¡¢¾üʲ¿·Ö¾ÙÐÐÆµÈÔµÄÍøÂçÌØ¹¤Ô˶¯£¬£¬£¬£¬£¬£¬¹¥»÷Ô˶¯¾ßÓÐÇ¿ÁÒµÄÕþÖÎÅä¾°¡£¡£¡£¡£¡£¸Ã×é֯ʹÓõĹ¥»÷ÊÖ·¨ÕûÌåÉϽÏÁ¿Àο¿ÇÒ¾ßÓÐ×Ô¼ºµÄÌØÉ«¡£¡£¡£¡£¡£
ΪÁ˶Կ¹Çå¾²Èí¼þµÄ¼ì²â²éɱºÍÇå¾²Ö°Ô±µÄÆÊÎö×·×Ù£¬£¬£¬£¬£¬£¬¶ÇÄÔ³æ×éÖ¯ÈÔÔÚÒ»Á¬Ò»Ö±µØÉý¼¶¸üÐÂ×Ô¼ºµÄÎäÆ÷¿âºÍ¹¥»÷ÊֶΣ¬£¬£¬£¬£¬£¬ÒÔ°ü¹Ü¹¥»÷Àú³ÌµÄÒþ²ØÐÔ£¬£¬£¬£¬£¬£¬ïÔ̺óÐø¹¥»÷ÔØºÉ̻¶µÄΣº¦¡£¡£¡£¡£¡£
ÓÉÓÚ¶ÇÄÔ³æ×éÖ¯ºÍÄÏÑÇÆäËû¹¥»÷×éÖ¯±£´æÁªÏµ£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ÔÚδÀ´µÄ¹¥»÷Ô˶¯ÖпÉÄÜ»á½ÓÄÉÔ½·¢¶àÑù»¯µÄ¹¥»÷ÊÖ·¨¡£¡£¡£¡£¡£
×¢½â
https://ti.qianxin.com/uploads/2021/02/08/dd941ecf98c7cb9bf0111a8416131aa1.pdf
https://ti.qianxin.com/blog/articles/pakistan-targeted-apt-campaign/
https://www.netscout.com/blog/asert/donot-team-leverages-new-modular-malware-framework-south-asia
https://blogs.360.cn/post/analysis-of-apt-c-35.html
https://ti.qianxin.com/blog/articles/donot-group-is-targeting-pakistani-businessman-working-in-china/
https://redalert.nshc.net/2019/08/02/sectore02-updates-yty-framework-in-new-targeted-campaign-against-pakistan-government/
https://ti.qianxin.com/blog/articles/stealjob-new-android-malware-used-by-donot-apt-group/
https://ti.qianxin.com/blog/articles/analysis-of-the-attack-activity-of-donot-apt-organization-(bornar-Insects)-camouflage-kmisch-news-app/
https://blogs.360.cn/post/APT-C-35_target_%20at_Pakistan.html
https://blog.talosintelligence.com/2020/10/donot-firestarter.html
https://blogs.360.cn/post/APT-C-35_target_at_armed_forces_in_Pakistan.html
¹ØÓÚ×÷Õß
Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ºìÓêµÎÍŶӣ¨RedDripTeam£¬£¬£¬£¬£¬£¬@RedDrip7£©£¬£¬£¬£¬£¬£¬ÒÀÍÐÈ«ÇòÁìÏȵÄÇå¾²´óÊý¾ÝÄÜÁ¦¡¢¶àά¶È¶àȪԴµÄÇå¾²Êý¾ÝºÍרҵÆÊÎöʦµÄ¸»ºñÂÄÀú£¬£¬£¬£¬£¬£¬×Ô2015ÄêÒ»Á¬·¢Ã÷¶à¸ö°üÀ¨º£Á«»¨ÔÚÄÚµÄAPT×éÖ¯ÔÚÖйú¾³Äڵĺã¾ÃÔ˶¯£¬£¬£¬£¬£¬£¬²¢Ðû²¼º£ÄÚÊ׸ö×éÖ¯²ãÃæµÄAPTÊÂÎñ½ÒÆÆ±¨¸æ£¬£¬£¬£¬£¬£¬¿ª´´Á˺£ÄÚAPT¹¥»÷Àà¸ß¼¶Íþвϵͳ»¯½ÒÆÆµÄÏȺӡ£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬Ò»Á¬¸ú×ÙÆÊÎöµÄÖ÷ÒªAPTÍÅ»ïÁè¼Ý47¸ö£¬£¬£¬£¬£¬£¬×ÔÁ¦·¢Ã÷APT×éÖ¯14¸ö£¬£¬£¬£¬£¬£¬Ò»Á¬Ðû²¼APT×éÖ¯µÄ¸ú×Ù±¨¸æÁè¼Ý90ƪ£¬£¬£¬£¬£¬£¬°´ÆÚÊä³ö°ëÄêºÍÕûÄêÈ«ÇòAPTÔ˶¯×ÛºÏÐÔÆÊÎö±¨¸æ¡£¡£¡£¡£¡£
ʱ¼ä£º2026-04-22
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-18
Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ
ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ