ʱ¼ä£º2022-01-14
2021.02.04~02.11
¹¥»÷ÍÅ»ïÇ鱨
ÂûÁ黨APT×éÖ¯½üÆÚ¹¥»÷Ô˶¯ÆÊÎö
PatchworkʹÓô¹ÂÚ¹¥»÷Ͷ·ÅBADNEWSľÂíбäÖÖ
ĦڲݽüÆÚÕë¶Ô¹ú·ÀÓëÒ½ÁÆÎÀÉúʵÌåµÄ¹¥»÷Ô˶¯ÆÊÎö
ÒÉËÆÂûÁ黨Õë¶Ô°Í»ù˹̹º½¿Õ²¿·Ö¹¥»÷Ô˶¯ÆÊÎö
KONNIʹÓÃÐÂÊÖ·¨Õë¶Ô¶íÂÞ˹ƫÏòÒ»Á¬Õö¿ª¹¥»÷
¹¥»÷Ðж¯»òÊÂÎñÇ鱨
¹¥»÷ÕßʹÓöñÒâÐ޸ĵÄdnSpy¹¤¾ß¹¥»÷ÊÖÒÕÖ°Ô±
Nanocore¡¢NetwireºÍAsyncRATÈö²¥Ô˶¯Ê¹Óù«¹²ÔÆ»ù´¡ÉèÊ©
Magnitude¡¢UnderminerÎó²î¹¤¾ß°üÕë¶ÔGoogleChromeÌᳫ¹¥»÷
¶ñÒâ´úÂëÇ鱨
RedLine±äÖÖOmicronÒÔCOVIDΪÓÕ¶ü·Å×ÝÈö²¥
FluBot°²×¿¶ñÒâÈí¼þ×îÐÂÆÊÎö
Abcbot½©Ê¬ÍøÂçÉîÈëÆÊÎö
Îó²îÇ鱨
macOSÎó²îpowerdir(CVE-2021-30970)ϸ½ÚÅû¶
Microsoft2022Äê1Ô²¹¶¡Í¨¸æ

¹¥»÷ÍÅ»ïÇ鱨
01
ÂûÁ黨APT×éÖ¯½üÆÚ¹¥»÷Ô˶¯ÆÊÎö
Åû¶ʱ¼ä£º2021Äê01ÔÂ10ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/NLe4JqmjiB58IQ5Kn6DSLQ
Ïà¹ØÐÅÏ¢£º
½üÆÚ£¬£¬£¬£¬£¬£¬£¬360¸ß¼¶ÍþвÑо¿Ôº²¶»ñÁËÂûÁ黨ÒÔ“Datailsofbill”ΪÖ÷ÌâÕë¶ÔÍâÑó¾ü¹¤ÆóҵʵÑéµÄ¹¥»÷Ô˶¯ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬²¢Åû¶ÁËÂûÁ黨ÔÚÔ˶¯ÖÐʹÓõĶàÖÖй¥»÷ÊÖ·¨¼°Ñù±¾¡£¡£¡£¡£¡£¡£ÓëÒÔÍùCHM½¨ÉèÍýÏëʹÃüʵÏÖ³¤ÆÚ»¯Ïà±È£¬£¬£¬£¬£¬£¬£¬´Ë´ÎCHMÑù±¾½«Í¬Ä¿Â¼ÏµÄPEÎļþ¾ÙÐÐ×Ô¸´ÖÆÊµÏÖ³¤ÆÚ»¯²¢ÇÒαװ³ÉϵͳÎļþ£¬£¬£¬£¬£¬£¬£¬¸ü¾ßÓÐÒþ²ØÐÔ¡£¡£¡£¡£¡£¡£±ðµÄÔÚÑо¿Ö°Ô±²¶»ñµÄ.NetµÄRATÖУ¬£¬£¬£¬£¬£¬£¬´úÂë½á¹¹²¢Î´±£´æ´óµÄ±ä»»£¬£¬£¬£¬£¬£¬£¬Ö¸ÁîÃûºÍÖ¸ÁîÊý¾Ý´¦±£´æ¸üС£¡£¡£¡£¡£¡£
´ËÀàת±äÇ÷ÊÆÓëÏìβÉß×éÖ¯ÏàËÆ£¬£¬£¬£¬£¬£¬£¬Á½ÕߵĸüÐÂÆ«Ïò¾ùÔÚÓÚ´úÂëÖ´ÐеIJ¿·Ö£¬£¬£¬£¬£¬£¬£¬¹ØÓÚºóÐøµÄÔ¶¿Ø³ÌÐò£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÒÔÁ÷Á¿»ò´úÂëÌØÕ÷ÈÆ¹ý×÷ΪÓÅ»¯Æ«Ïò¡£¡£¡£¡£¡£¡£ÃæÁÙÕâЩ²ã³ö²»ÇîµÄ¹¥»÷ÊÖ·¨£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÐèÒª³£»£»£»£»£»£»£»³Ð¡ÐÄÖ®ÐÄ¡£¡£¡£¡£¡£¡£

02
PatchworkʹÓô¹ÂÚ¹¥»÷Ͷ·ÅBADNEWSľÂíбäÖÖ
Åû¶ʱ¼ä£º2021Äê01ÔÂ07ÈÕ
Ç鱨ȪԴ£ºhttps://blog.malwarebytes.com/threat-intelligence/2022/01/patchwork-apt-caught-in-its-own-web/
Ïà¹ØÐÅÏ¢£º
PatchworkÊÇÒ»¸öÄÏÑǵØÇøµÄAPT×éÖ¯£¬£¬£¬£¬£¬£¬£¬×Ô2015Äê12ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬£¬Í¨³£Ê¹ÓÃÓã²æÊ½ÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶Ô°Í»ù˹̹¡£¡£¡£¡£¡£¡£ÔÚ2021Äê11ÔÂβÖÁ12Ô³õµÄ×îÐÂÔ˶¯ÖУ¬£¬£¬£¬£¬£¬£¬PatchworkʹÓöñÒâRTFÎļþͶ·ÅÁËBADNEWSÔ¶³ÌÖÎÀíľÂíµÄÒ»¸ö±äÖÖ¡£¡£¡£¡£¡£¡£
RagnatelaÊÇBADNEWSRATµÄÒ»¸öбäÖÖ£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÓã²æÊ½ÍøÂç´¹ÂÚÓʼþÈö²¥¸ø°Í»ù˹̹µÄÏà¹ØÄ¿µÄ¡£¡£¡£¡£¡£¡£RagnatelaRAT¾ßÓÐͨ¹ýcmdÖ´ÐÐÏÂÁî¡¢²¶»ñÆÁÄ»½ØÍ¼¡¢¼Í¼»÷¼ü´ÎÊýµÈ¹¦Ð§¡£¡£¡£¡£¡£¡£RagnatelaÔÚÒâ´óÀûÓïÖÐÒâΪ֩ÖëÍø£¬£¬£¬£¬£¬£¬£¬Ò²ÊÇPatchwork´Ë´Î¶ñÒâÔ˶¯Ê¹ÓõÄÏîÄ¿Ãû³Æ¡£¡£¡£¡£¡£¡£
Ôڴ˴ζñÒâÔ˶¯ÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÊ״ν«Ä¿µÄËø¶¨ÔÚ·Ö×ÓҽѧºÍÉúÎï¿ÆÑ§µÄÑо¿Ö°Ô±ÉíÉÏ¡£¡£¡£¡£¡£¡£¾ßÓм¥Ð¦ÒâζµÄÊÇ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÆäRATѬȾÁË×Ô¼º£¬£¬£¬£¬£¬£¬£¬×îºó»ñµÃµÄÊÇÆäµçÄÔºÍÐéÄâ»úµÄ¼üÅÌ»÷¼ü´ÎÊýºÍÆÁÄ»½ØÍ¼¡£¡£¡£¡£¡£¡£
03
ĦڲݽüÆÚÕë¶Ô¹ú·ÀÓëÒ½ÁÆÎÀÉúʵÌåµÄ¹¥»÷Ô˶¯ÆÊÎö
Åû¶ʱ¼ä£º2021Äê01ÔÂ10ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/ZNhdLN_AgGfjdk8nG8kLmw
Ïà¹ØÐÅÏ¢£º
Patchwork£¨°×Ïó¡¢Ä¦Ú²Ý¡¢APT-C-09¡¢DroppingElephant£©ÊÇÒ»¸öÒÉËÆ¾ßÓÐÄÏÑǵØÇøÅä¾°µÄAPT×éÖ¯£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ºã¾ÃÕë¶ÔÖйú¡¢°Í»ù˹̹µÈÄÏÑǵØÇø¹ú¼ÒµÄÕþ¸®¡¢Ò½ÁÆ¡¢¿ÆÑеÈÁìÓò¾ÙÐÐÍøÂç¹¥»÷ÇÔÃÜÔ˶¯¡£¡£¡£¡£¡£¡£
½üÆÚ°²ºãÍþвÇ鱨ÖÐÐÄÁÔӰʵÑéÊÒ²¶»ñµ½¶à¸öPatchwork×éÖ¯¹¥»÷Ô˶¯Ñù±¾£¬£¬£¬£¬£¬£¬£¬±¾´ÎÑù±¾Ö÷Ҫͨ¹ýÓã²æÊ½´¹ÂÚÓʼþ¾ÙÐÐÈö²¥£¬£¬£¬£¬£¬£¬£¬Ñù±¾ÒÔ“Ò½ÁÆÎÀÉúÆø¹¹¹ÒºÅ±í”¡¢“°Í»ù˹̹¹ú·À¹ÙԱס·¿¹ÒºÅ±í”µÈÏà¹ØÄÚÈÝ×÷ΪÓÕ¶ü£¬£¬£¬£¬£¬£¬£¬Í¨¹ýʹÓÃCVE-2017-11882Îó²î£¬£¬£¬£¬£¬£¬£¬×îÖÕÊÍ·Å“BADNEWS”ºóÃųÌÐò¾ÙÐÐÇÔÃÜÔ˶¯¡£¡£¡£¡£¡£¡£
04
ÒÉËÆÂûÁ黨×éÖ¯Õë¶Ô°Í»ù˹̹º½¿Õ×ۺϲ¿·Ö¹¥»÷Ô˶¯ÆÊÎö
Åû¶ʱ¼ä£º2021Äê01ÔÂ11ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/x1Q7_glLJL_qDnvcO-9yLg
Ïà¹ØÐÅÏ¢£º
ÂûÁ黨(Bitter)ÊÇÒ»¸ö±»ÆÕ±éÒÔΪÀ´×ÔÄÏÑǵØÇøµÄAPT×éÖ¯£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ºã¾ÃÕë¶ÔÎÒ¹ú¼°°Í»ù˹̹µÄÕþ¸®¡¢¾ü¹¤¡¢µçÁ¦¡¢ºËµÈ²¿·Ö·¢¶¯ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡Ãô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬£¬¾ßÓнÏÇ¿µÄÕþÖÎÅä¾°¡£¡£¡£¡£¡£¡£
½üÆÚ°²ºãÍþвÇ鱨ÖÐÐÄÁÔӰʵÑéÊÒ²¶»ñµ½Ò»¸öÒÉËÆÂûÁ黨×éÖ¯Õë¶Ô°Í»ù˹̹“º½¿ÕÁìÓò”µÄ¹¥»÷Ô˶¯Ñù±¾¡£¡£¡£¡£¡£¡£¸ÃÑù±¾Ê¹ÓÃÃûΪ“PACAdvisoryCommitteeReport.doc”µÄÓÕ¶üÎĵµ¾ÙÐй¥»÷¡£¡£¡£¡£¡£¡£²¢ÇÒʹÓÃÒ»¸ö´¦ÓÚʧÏÝ״̬µÄ°Í»ù˹̹¶þÊÖÉúÒâÍøÕ¾Ð§ÀÍÆ÷À´Ï·¢µÚ¶þ½×¶ÎÔØºÉ¡£¡£¡£¡£¡£¡£
05
KONNIʹÓÃÐÂÊÖ·¨Õë¶Ô¶íÂÞ˹ƫÏòÒ»Á¬Õö¿ª¹¥»÷
Åû¶ʱ¼ä£º2021Äê01ÔÂ12ÈÕ
Ç鱨ȪԴ£ºhttps://mp.weixin.qq.com/s/AA4dpzwhSyktQGQ83cMHbA
Ïà¹ØÐÅÏ¢£º
KONNIAPT×éÖ¯ÊÇÒÉËÆÓÉÌØ¶¨Õþ¸®Ö§³ÖµÄºÚ¿Í×éÖ¯£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ºã¾ÃÕë¶Ô¶íÂÞ˹¡¢º«¹úµÈµØÇø¾ÙÐж¨Ïò¹¥»÷Ô˶¯£¬£¬£¬£¬£¬£¬£¬ÆäÉÆÓÚʹÓÃÉç»áÈÈÃÅ»°Ìâ¶ÔÄ¿µÄ¾ÙÐÐÓã²æÊ½ÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£
΢²½Ç鱨¾Ö½üÆÚ¼à²âµ½KONNI×éÖ¯½èÖú“COVID-19ÒßÃç½ÓÖÖ”Ö÷Ìâ¶Ô¶íÂÞ˹ƫÏòµÄ¶¨Ïò¹¥»÷Ô˶¯£¬£¬£¬£¬£¬£¬£¬ÆÊÎöÓÐÈçÏ·¢Ã÷£º
¹¥»÷ÕßÏòÄ¿µÄ·¢ËÍ“ÒßÃç½ÓÖÖÔ¤Ô¼”Ïà¹ØÓÕ¶üÎĵµ£¬£¬£¬£¬£¬£¬£¬²¢¸½´øÄ¾ÂíÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬Æ¾Ö¤Ïà¹ØÓÕ¶üÎļþÄÚÈÝ£¬£¬£¬£¬£¬£¬£¬ÑÐÅй¥»÷Ä¿µÄΪ¶íÂÞ˹ƫÏòÏà¹ØÕûÌ壻£»£»£»£»£»£»
ľÂíʹÓÃDLLÐ®ÖÆµÄÒªÁì½èÖúÏà¹Ø×°Öðü³ÌÐò¡¢PDFÔĶÁÆ÷Ö´ÐУ¬£¬£¬£¬£¬£¬£¬ºóÐø¼ÓÔØÖ´ÐеĶñÒâÄ£¿£¿£¿£¿£¿£¿£¿éÓë¸Ã×éÖ¯ÒÔÍù¹¥»÷Ô˶¯ÖÐËùʹÓõÄÑù±¾¸ß¶ÈÒ»Ö£»£»£»£»£»£»£»
Óë¸Ã×éÖ¯ÒÔÍù¹¥»÷Ô˶¯²î±ðµÄÊÇ£¬£¬£¬£¬£¬£¬£¬ÔÚ±¾´Î¹¥»÷Ô˶¯ÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß²¢Ã»ÓÐʹÓúêÎĵµ¾ÙÐй¥»÷£¬£¬£¬£¬£¬£¬£¬¶øÊǽ«Ä¾ÂíÄ£¿£¿£¿£¿£¿£¿£¿éÓëÕý³£³ÌÐò´ò°üÔÚÒ»Æð¾ÙÐÐDLLÐ®ÖÆ¹¥»÷¡£¡£¡£¡£¡£¡£
¹¥»÷Ðж¯»òÊÂÎñÇ鱨
01
¹¥»÷ÕßʹÓöñÒâÐ޸ĵÄdnSpy¹¤¾ß¹¥»÷ÊÖÒÕÖ°Ô±
Åû¶ʱ¼ä£º2021Äê01ÔÂ12ÈÕ
Ç鱨ȪԴ£ºhttp://noahblog.360.cn/fake-dnspy-when-hackers-have-no-martial-ethics/
Ïà¹ØÐÅÏ¢£º
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÌᳫÁËÒ»³¡Õë¶ÔÍøÂçÇå¾²Ñо¿Ö°Ô±ºÍ¿ª·¢Ö°Ô±µÄ¶ñÒâÈí¼þÔ˶¯£¬£¬£¬£¬£¬£¬£¬¸ÃÔ˶¯·Ö·¢Ò»¸ö¶ñÒâ°æ±¾µÄdnSpy.NETÓ¦ÓóÌÐò£¬£¬£¬£¬£¬£¬£¬ÓÃÀ´×°ÖüÓÃÜÇ®±ÒÇÔÈ¡Èí¼þ¡¢Ô¶¿ØÄ¾ÂíºÍÍÚ¿óÈí¼þ¡£¡£¡£¡£¡£¡£
dnSpyÊÇÒ»¸ö¿ªÔ´¹¤¾ß£¬£¬£¬£¬£¬£¬£¬¿ÉÊÇÏÖÔÚ²»ÔÙÓÉ×î³õµÄ¿ª·¢Õß¿ª·¢£¬£¬£¬£¬£¬£¬£¬µ«ÈκÎÈ˶¼¿ÉÒÔÔÚGitHubÉϿˡºÍÐÞ¸ÄÔʼԴ´úÂë¡£¡£¡£¡£¡£¡£Òò´ËÓй¥»÷ÕßÓÃdnSpyµÄ±àÒë°æ±¾½¨ÉèÁËÒ»¸öGitHub¿â£¬£¬£¬£¬£¬£¬£¬²¢ÔÚÆäÖÐ×°ÖÃÁËһϵÁжñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÇÔÈ¡¼ÓÃÜÇ®±ÒµÄÇÔÃÜÈí¼þ¡¢QuasarľÂí¡¢ÍÚ¿óÈí¼þºÍÖÖÖÖδ֪¸ºÔØ¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹Ê¹ÓÃËÑË÷ÒýÇæ¹ã¸æÀ´ÍƹãÕâ¸ö¶ñÒâµÄGitHub¿â¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬Ïà¹Ø¶ñÒâµÄÍøÕ¾Òѱ»¹Ø±Õ¡£¡£¡£¡£¡£¡£
02
Nanocore¡¢NetwireºÍAsyncRATÈö²¥Ô˶¯Ê¹Óù«¹²ÔÆ»ù´¡ÉèÊ©
Åû¶ʱ¼ä£º2021Äê01ÔÂ12ÈÕ
Ç鱨ȪԴ£ºhttps://blog.talosintelligence.com/2022/01/nanocore-netwire-and-asyncrat-spreading.html
Ïà¹ØÐÅÏ¢£º
CiscoTalosÔÚ2021Äê10Ô·¢Ã÷ÁËÈö²¥Nanocore¡¢NetwireºÍAsyncRATs¶ñÒâÈí¼þ±äÖֵĶñÒâÔ˶¯¡£¡£¡£¡£¡£¡£ÕâЩ¶ñÒâÈí¼þ±äÖÖ¾ßÓжàÖÖ¹¦Ð§£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ¿ØÖÆÊܺ¦ÕßµÄÇéÐΣ¬£¬£¬£¬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§ÒâÏÂÁî²¢ÇÔÈ¡Êܺ¦ÕßµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¸ÃÔ˶¯µÄÊܺ¦ÕßÖ÷ÒªÂþÑÜÔÚÃÀ¹ú¡¢Òâ´óÀûºÍÐÂ¼ÓÆÂ¡£¡£¡£¡£¡£¡£
×î³õµÄÑ¬È¾ÔØÌåÊÇ´øÓжñÒâZIP¸½¼þµÄÍøÂç´¹ÂÚµç×ÓÓʼþ¡£¡£¡£¡£¡£¡£ZIPÎļþ°üÀ¨Ò»¸öISO¾µÏñÎļþ£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Ò»¸ö¶ñÒâ»ìÏýµÄÏÂÔØ³ÌÐò¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚÏÂÔØÆ÷µÄ¾ç±¾ÖÐʹÓÃÁËÖØ´óµÄ»ìÏýÊÖÒÕ¡£¡£¡£¡£¡£¡£Ã¿Ò»½×¶ÎµÄÈ¥»ìÏýÀú³ÌЧ¹û¶¼ÓëºóÐø½×¶ÎµÄ½âÃÜÒªÁìÓйأ¬£¬£¬£¬£¬£¬£¬×îÖÕʵÏÖÏÂÔØ¶ñÒâ¸ºÔØ¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷Õß»¹ÀÄÓÃÁË΢ÈíAzureºÍAWSµÈÔÆÐ§ÀÍÒԸ濢Æä¶ñÒâÄ¿µÄ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ»¹Ê¹ÓÃÁËDuckDNS¶¯Ì¬DNSЧÀÍ£¬£¬£¬£¬£¬£¬£¬×öµ½°´ÆÚ¸ü¸ÄC2ЧÀÍÆ÷µÄIPµØµã£¬£¬£¬£¬£¬£¬£¬²¢¿ìËÙÌí¼ÓеÄ×ÓÓò¡£¡£¡£¡£¡£¡£

03
Magnitude¡¢UnderminerÎó²î¹¤¾ß°üÕë¶ÔGoogleChromeÌᳫ¹¥»÷
Åû¶ʱ¼ä£º2021Äê01ÔÂ12ÈÕ
Ç鱨ȪԴ£ºhttps://decoded.avast.io/janvojtesek/exploit-kits-vs-google-chrome/
Ïà¹ØÐÅÏ¢£º
2021Äê10Ô£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷MagnitudeexploitkitÕýÔÚ²âÊÔChromiumÎó²îÁ´¡£¡£¡£¡£¡£¡£Ô¼ÄªÒ»¸öÔº󣬣¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷Underminerexploitkit½ôËæØÊºó£¬£¬£¬£¬£¬£¬£¬Ò²¿ª·¢ÁËÕë¶ÔChromiumÎó²îµÄʹÓù¤¾ß¡£¡£¡£¡£¡£¡£MagnitudeʹÓÃCVE-2021-21224ºÍCVE-2021-31956£¬£¬£¬£¬£¬£¬£¬UnderminerʹÓÃCVE-2021-21224¡¢CVE-2019-0808¡¢CVE-2020-1020ºÍCVE-2020-1054¡£¡£¡£¡£¡£¡£MagnitudeºÍUnderminer¶¼ÀֳɵØÎªWindowsÉϵÄChromium¿ª·¢ÁËÎó²îÁ´¡£¡£¡£¡£¡£¡£
¹¥»÷ÕßÊ×ÏÈ»áÔÚÕýµ±ÍøÕ¾ÉϹºÖÃ¹ã¸æ£¬£¬£¬£¬£¬£¬£¬Ä¿µÄÊÇÓпÉÄܱ»ËûÃÇʹÓõÄÓû§£¨ÀýÈçInternetExplorerÓû§£©¡£¡£¡£¡£¡£¡£ÕâЩ¹ã¸æ°üÀ¨×Ô¶¯Ö´ÐеÄJavaScript´úÂ룬£¬£¬£¬£¬£¬£¬Õâ¶Î´úÂë»á½øÒ»²½ÆÊÎöÊܺ¦ÕßµÄä¯ÀÀÆ÷ÇéÐΣ¬£¬£¬£¬£¬£¬£¬²¢Îª¸ÃÇéÐÎÑ¡ÔñÒ»¸öºÏÊʵÄÎó²î¡£¡£¡£¡£¡£¡£ÈôÊÇʹÓÃÀֳɣ¬£¬£¬£¬£¬£¬£¬Ò»¸ö¶ñÒâµÄÓÐÓÃÔØºÉ½«±»°²Åŵ½Êܺ¦ÕßµÄÍøÂçÇéÐΡ£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬£¬¾Í±»Ê¹ÓõÄÊܺ¦ÕßµÄÊýÄ¿¶øÑÔ£¬£¬£¬£¬£¬£¬£¬ÕâЩʹÓÃÁ´¶¼²»ÊÇÌØÊâÀֳɡ£¡£¡£¡£¡£¡£Ê¹ÓÃChromiumÎó²îÁ´Ê§°ÜµÄÔµ¹ÊÔÓÉÓпÉÄÜÊǹ¥»÷Õß¶ÔÎó²îµÄʹÓÃÊÙÃüÔ¤ÆÚ¹ý¸ß¡£¡£¡£¡£¡£¡£Chromeä¯ÀÀÆ÷ÔÚÒ»¸öÔÂÄÚ»á¶à´Î¸øÓû§ÍÆËÍ֪ͨ£¬£¬£¬£¬£¬£¬£¬ÈÃÓû§×°ÖÃä¯ÀÀÆ÷²¹¶¡£¬£¬£¬£¬£¬£¬£¬ÕâÒ»ÐÐΪ´ó´ó½µµÍÁËÎó²î±»Ê¹ÓõĸÅÂÊ¡£¡£¡£¡£¡£¡£

¶ñÒâ´úÂëÇ鱨
01
RedLine±äÖÖOmicronÒÔCOVIDΪÓÕ¶ü·Å×ÝÈö²¥
Åû¶ʱ¼ä£º2021Äê01ÔÂ10ÈÕ
Ç鱨ȪԴ£ºhttps://www.fortinet.com/blog/threat-research/omicron-variant-lure-used-to-distribute-redline-stealer
Ïà¹ØÐÅÏ¢£º
Ñо¿Ö°Ô±×î½ü²¶»ñµ½ÁËRedlineStealer¶ñÒâÈí¼þµÄÒ»¸ö±äÖÖ"OmicronStats.exe"¡£¡£¡£¡£¡£¡£¹ØÓÚRedLineStealerµÄµÚÒ»·Ý±¨¸æ¿ÉÒÔ×·Ëݵ½2020Äê3Ô£¬£¬£¬£¬£¬£¬£¬ËüºÜ¿ì³ÉΪÁ˰µÍøÊг¡ÉÏ×îÊܽӴýµÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£ÓÉRedLineStealer»ñÈ¡µÄÐÅÏ¢ÔÚ°µÍøÊг¡ÉÏÒÔÿÌ×Óû§Æ¾Ö¤10ÃÀÔªµÄµÍ¼Û³öÊÛ¡£¡£¡£¡£¡£¡£Êܺ¦ÕßϵͳѬȾRedlineStealerÖ®ºó£¬£¬£¬£¬£¬£¬£¬ÆäÕË»§ÃÜÂëºÍÍêÕûµÄä¯ÀÀÆ÷ϸ½Ú¶¼»á±»¼Í¼¡£¡£¡£¡£¡£¡£
Ò»Ñùƽ³£À´Ëµ£¬£¬£¬£¬£¬£¬£¬Ã¿¸öÓû§µÄ×ÊÁϰüÀ¨ÔÚÏßÖ§¸¶ÃÅ»§¡¢µç×ÓÒøÐÐЧÀÍ¡¢Îļþ¹²Ïí»òÉç½»ÍøÂçÆ½Ì¨µÄÕË»§Éϰ¶Æ¾Ö¤¡£¡£¡£¡£¡£¡£ËäÈ»Ñо¿Ö°Ô±ÏÖÔÚÎÞ·¨È·¶¨Õâ¸öOmicron±äÌåµÄÑ¬È¾ÔØÌ壬£¬£¬£¬£¬£¬£¬µ«ÐÅÍÐËüÊÇͨ¹ýµç×ÓÓʼþÈö²¥µÄ¡£¡£¡£¡£¡£¡£¾ÝÏàʶ£¬£¬£¬£¬£¬£¬£¬ÒÑÍùµÄRedLineStealer±äÌåÊÇÔÚÒÔCOVIDΪÖ÷ÌâµÄµç×ÓÓʼþÖÐÈö²¥µÄ£¬£¬£¬£¬£¬£¬£¬ÒÔÒýÓÕÊܺ¦Õß¡£¡£¡£¡£¡£¡£ÏÖÔÚÕâ¸ö±äÖÖµÄÎļþÃû"OmicronStats.exe"£¬£¬£¬£¬£¬£¬£¬¾ÍÔÚOmicron±äÖÖ³ÉΪȫÇò¹Ø×¢µÄ½¹µãʱʹÓ㬣¬£¬£¬£¬£¬£¬×ñÕÕÁËÒÔǰ±äÖÖµÄģʽ¡£¡£¡£¡£¡£¡£
¼øÓÚÕâ¸ö¶ñÒâÈí¼þ±»Ç¶Èëµ½Ò»¸ö±»Êܺ¦Õß·¿ªµÄÎļþÖУ¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÒÔΪµç×ÓÓʼþÊÇÕâ¸ö±äÖÖµÄÑ¬È¾ÔØÌå¡£¡£¡£¡£¡£¡£´Ë´Î¶ñÒâÔ˶¯µÄDZÔÚÊܺ¦ÕßÂþÑÜÔÚ12¸ö¹ú¼Ò£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß²¢Ã»ÓÐÕë¶ÔÌØ¶¨µÄ×éÖ¯»òСÎÒ˽¼Ò¡£¡£¡£¡£¡£¡£
02
FluBot°²×¿¶ñÒâÈí¼þ×îÐÂÆÊÎö
Åû¶ʱ¼ä£º2021Äê01ÔÂ12ÈÕ
Ç鱨ȪԴ£ºhttps://www.f5.com/labs/articles/threat-intelligence/flubots-authors-employ-creative-and-sophisticated-techniques-to-achieve-their-goals-in-version-50-and-beyond
Ïà¹ØÐÅÏ¢£º
FluBotÊÇÒ»¸ö2020ÄêÍ··ºÆðµÄ°²×¿¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¿ÉÒÔÔ¶³Ì¿ØÖÆÑ¬È¾×°±¸£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£×î³õ£¬£¬£¬£¬£¬£¬£¬FluBotÖ÷ÒªÕë¶ÔÎ÷°àÑÀÒøÐУ¬£¬£¬£¬£¬£¬£¬µ«ØÊºóÆäÄ¿µÄÀ©´óµ½°Ä´óÀûÑÇ¡¢µÂ¹ú¡¢²¨À¼ºÍÓ¢¹úµÄÒøÐС£¡£¡£¡£¡£¡£
FluBotÓжàÖÖÈö²¥·½·¨£¬£¬£¬£¬£¬£¬£¬Í¨³£ÊÇͨ¹ý´¹ÂÚ¶ÌÐÅ¡£¡£¡£¡£¡£¡£¶ÌÐÅÖ¸ÏòÒ»¸ö¶ñÒâÍøÕ¾£¬£¬£¬£¬£¬£¬£¬Ò»µ©»á¼û£¬£¬£¬£¬£¬£¬£¬Êܺ¦Õ߻ᱻÓÕµ¼×°ÖÃFluBot¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£Êܺ¦ÕßÀÖ³É×°Öò¢·¿ªFluBotºó£¬£¬£¬£¬£¬£¬£¬FluBot»á»á¼ûÊܺ¦ÕßµÄÁªÏµÈËÁÐ±í£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäÉÏ´«µ½C2ЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬¼Ì¶øÏòеÄÄ¿µÄÁªÏµÈËÁÐ±í·¢ËÍ´¹ÂÚ¶ÌÐÅ£¬£¬£¬£¬£¬£¬£¬Íê³ÉÀ©É¢¡£¡£¡£¡£¡£¡£
FluBotΪÁ˱ÜÃâ±»ÆÊÎöʹÓÃÁËÐí¶àÖØ´óµÄÊÖÒÕ£¬£¬£¬£¬£¬£¬£¬ÈçMultiDex¡¢DGA¡¢DNS-over-HTTPS¡¢RSA+RC4×éºÏ¼ÓÃÜ¡£¡£¡£¡£¡£¡£ÏÖÔÚÒѾÐû²¼µ½5.2°æ±¾¡£¡£¡£¡£¡£¡£

03
Abcbot½©Ê¬ÍøÂçÉîÈëÆÊÎö
Åû¶ʱ¼ä£º2021Äê01ÔÂ14ÈÕ
Ç鱨ȪԴ£ºhttps://www.cadosecurity.com/abcbot-an-evolution-of-xanthe/
Ïà¹ØÐÅÏ¢£º
½üÆÚ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÐÂÐ˽©Ê¬ÍøÂçAbcbotÓ뼸Äêǰ»ùÓÚXanthe¶ñÒâÈí¼þµÄ¼ÓÃÜÐ®ÖÆÔ˶¯±£´æÏÔ×ÅÁªÏµ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ£¬£¬£¬£¬£¬£¬£¬XantheºÍAbcbotÓÉͳһ¹¥»÷Õß¿ª·¢£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÆäÔ˶¯Ä¿µÄ±¬·¢ÁËת±ä£¬£¬£¬£¬£¬£¬£¬´ÓÔÚÊÜѬȾÖ÷»úÉÏÍÚ¾ò¼ÓÃÜÇ®±Ò£¬£¬£¬£¬£¬£¬£¬×ªÏò¸ü¹Å°åµÄÓë½©Ê¬ÍøÂçÏà¹ØµÄÔ˶¯£¬£¬£¬£¬£¬£¬£¬ÀýÈçDDoS¹¥»÷¡£¡£¡£¡£¡£¡£XantheÊÇÒ»¸ö¼ÓÃÜÐ®ÖÆµÄ¶ñÒâÈí¼þ¼Ò×壬£¬£¬£¬£¬£¬£¬ÆäÖ÷ҪĿµÄÊÇÐ®ÖÆÏµÍ³×ÊÔ´ÒÔÍÚ¾òMonero¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£XantheËÑË÷²¢Ñ¬È¾Ì»Â¶µÄDockerAPI¶Ëµã¡£¡£¡£¡£¡£¡£
Abcbot×î³õÓÚ2021Äê7Ô±»ÊӲ쵽£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÔÚÆÊÎöAbcbotµÄ»ù´¡¼Ü¹¹Ê±£¬£¬£¬£¬£¬£¬£¬·¢Ã÷ÁËÓëXanthe¶ñÒâÈí¼þÔ˶¯Ö®¼äµÄÁªÏµ¡£¡£¡£¡£¡£¡£ÔÚ½ÏÁ¿À´×ÔÁ½¸öÔ˶¯µÄ¶ñÒâÈí¼þÑù±¾ºó£¬£¬£¬£¬£¬£¬£¬·¢Ã÷Á½¸ö¶ñÒâÈí¼þ¼Ò×åµÄ´úÂëºÍ¹¦Ð§¼¯Ò²ÓкÜÏÔ×ŵÄÏàËÆÐÔ¡£¡£¡£¡£¡£¡£Á½¸ö¶ñÒâÈí¼þ¼Ò×å¾ßÓÐÏàËÆµÄ±àÂëÆø¸Å£¬£¬£¬£¬£¬£¬£¬º¯ÊýÔÚÎļþ¶¥²¿ÉùÃ÷£¬£¬£¬£¬£¬£¬£¬ÔÚºóÃæ¾ÙÐÐŲÓ㬣¬£¬£¬£¬£¬£¬²¢ÇÒ¹²ÏíÏàËÆµÄº¯ÊýÃû³Æ¡£¡£¡£¡£¡£¡£
ÕâÁ½¸ö¶ñÒâÈí¼þ¼Ò×å¶¼ÔÚÊÜѬȾµÄϵͳÉϽ¨ÉèÁËËĸö¾ßÓÐÍêÈ«ÏàͬÃû³ÆµÄ¶ñÒâÓû§£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¶¼ËÑË÷ºÍɾ³ý¿ÉÄÜÓëÆä¾ºÕùµÄÓû§¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Á½¸ö¶ñÒâÈí¼þÑù±¾¶¼ÊÇ¿ÉÒÔÇáËɸ´ÖƵÄshell¾ç±¾£¬£¬£¬£¬£¬£¬£¬ÌåÏÖ³ö¿ÉÒÔ´úÂëÖØÓõÄÌØµã¡£¡£¡£¡£¡£¡£

Îó²îÏà¹Ø
01
macOSÎó²îpowerdir(CVE-2021-30970)ϸ½ÚÅû¶
Åû¶ʱ¼ä£º2021Äê01ÔÂ10ÈÕ
Ç鱨ȪԴ£ºhttps://www.microsoft.com/security/blog/2022/01/10/new-macos-vulnerability-powerdir-could-lead-to-unauthorized-user-data-access/
Ïà¹ØÐÅÏ¢£º
1ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬£¬Î¢ÈíÐû²¼¹ØÓÚmacOSÖеÄÎó²îpowerdir(CVE-2021-30970)µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£Î¢ÈíÌåÏÖ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÈÆ¹ý͸Ã÷¡¢Ô޳ɺͿØÖÆ(TCC)ÊÖÒÕÀ´»á¼ûÓû§µÄÊý¾Ý¡£¡£¡£¡£¡£¡£
Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý±à³ÌµÄ·½·¨¸Ä¶¯Ä¿µÄÓû§Ö÷Ŀ¼²¢Ö²ÈëαTCCÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îƾ֤Óû§Êܱ£»£»£»£»£»£»£»¤µÄСÎÒ˽¼ÒÊý¾Ý²ß»®¹¥»÷¡£¡£¡£¡£¡£¡£Î¢ÈíÍŶÓÔÚ2021Äê7ÔÂ15ÈÕ½«Îó²î±¨¸æ¸øApple¹«Ë¾£¬£¬£¬£¬£¬£¬£¬AppleÔÚ12ÔÂ13ÈÕÐû²¼µÄÇå¾²¸üÐÂÖÐÐÞ¸´¡£¡£¡£¡£¡£¡£
Microsoft2022Äê1Ô²¹¶¡Í¨¸æ
Åû¶ʱ¼ä£º2021Äê01ÔÂ14ÈÕ
Ç鱨ȪԴ£ºhttps://msrc.microsoft.com/update-guide/
Ïà¹ØÐÅÏ¢£º
MicrosoftÔÚ1Ô·ݵIJ¹¶¡ÈÕÐû²¼ÁË97¸öÎó²îµÄÐÞ¸´²¹¶¡£¬£¬£¬£¬£¬£¬£¬Éæ¼°µ½MicrosoftDefender¡¢MicrosoftDevices¡¢MicrosoftOffice¡¢MicrosoftPowerShell¡¢WindowsNTFSµÈ¶à¿î²úÆ·»ò×é¼þ£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ9¸öÎó²î±»±ê¼ÇΪÑÏÖØÎó²î£¬£¬£¬£¬£¬£¬£¬88¸ö±»±ê¼ÇΪ¸ßΣÎó²î¡£¡£¡£¡£¡£¡£
´Ë´ÎÐÞ¸´µÄ×îÑÏÖØµÄÊÇHTTPÐÒéÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-21907£©£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâÊý¾Ý°üµ½Ä¿µÄЧÀÍÆ÷À´Ê¹ÓøÃÎó²î¡£¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬£¬¸üл¹ÐÞ¸´ÁË6¸ö0day£¬£¬£¬£¬£¬£¬£¬°üÀ¨¿ªÔ´Curl¿âÖеÄRCE£¨CVE-2021-22947£©¡¢¿ªÔ´Libarchive¿âÖеÄRCE£¨CVE-2021-36976£©ºÍÍâµØWindowsÇå¾²ÖÐÐÄAPIÖеÄRCE£¨CVE-2022-21874£©µÈ¡£¡£¡£¡£¡£¡£
0dayÎó²î˵Ã÷£º
CVE-2021-22947OpenSourceCurlÔ¶³Ì´úÂëÖ´ÐÐÎó²î£º´ËCVEÊǹØÓÚWindowsʹÓõÄcurl¿ªÔ´¿âÖеÄÒ»¸öÎó²î¡£¡£¡£¡£¡£¡£ËüµÄCVSSÆÀ·ÖΪ5.9£¬£¬£¬£¬£¬£¬£¬Î£º¦Æ·¼¶Öеȡ£¡£¡£¡£¡£¡£
µ±curl>=7.20.0ºÍ
CVE-2021-36976LibarchiveÔ¶³Ì´úÂëÖ´ÐÐÎó²î£ºCVE-2021-36976ÊǹØÓÚWindowsʹÓõÄlibarchive¿ªÔ´¿âÖеÄÒ»¸öÎó²î¡£¡£¡£¡£¡£¡£ËüµÄCVSSÆÀ·ÖΪ6.5£¬£¬£¬£¬£¬£¬£¬Î£º¦Æ·¼¶Öеȡ£¡£¡£¡£¡£¡£
CVE-2022-21919WindowsUserProfileServiceÌØÈ¨ÌáÉýÎó²î£ºCVE-2022-21919ÊÇWindowsUserProfileServiceµÄÌØÈ¨ÌáÉýÎó²î¡£¡£¡£¡£¡£¡£ËüµÄCVSSÆÀ·ÖΪ7.0£¬£¬£¬£¬£¬£¬£¬Î£º¦Æ·¼¶¸ß¡£¡£¡£¡£¡£¡£¸ÃÎó²îΪȥÄêÍâÑóÇå¾²Ñо¿Ô±¹ûÕæµÄ0dayÎó²î£¬£¬£¬£¬£¬£¬£¬ÏÖÒÑÐÞ¸´¡£¡£¡£¡£¡£¡£
ÆäËûÖ÷ÒªÎó²î˵Ã÷£º
CVE-2022-21907HTTPÐÒé¿ÍÕ»Ô¶³ÌÖ´ÐдúÂëÎó²î£ºCVE-2022-21907µÄCVSSÆÀ·ÖΪ9.8·Ö£¬£¬£¬£¬£¬£¬£¬Î£º¦Æ·¼¶¸ß£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÈ䳿»¯Ê¹Óᣡ£¡£¡£¡£¡£ÀÖ³ÉʹÓÃÐèÒª¹¥»÷Õß½«¶ñÒâÖÆ×÷µÄÊý¾Ý°ü·¢Ë͵½Ä¿µÄWindowsЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬ÕâЩЧÀÍÆ÷ʹÓÃÒ×Êܹ¥»÷µÄHTTPÐÒéÕ»À´´¦Öóͷ£Êý¾Ý°ü¡£¡£¡£¡£¡£¡£Î¢Èí½¨ÒéÓû§ÓÅÏÈÔÚËùÓÐÊÜÓ°ÏìµÄЧÀÍÆ÷ÉÏÐÞ²¹´ËÎó²î£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËü¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚµÍÖØÆ¯ºó¹¥»÷ÖÐÔ¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬£¬²¢ÇÒ“ÔÚ´ó´ó¶¼ÇéÐÎÏ”£¬£¬£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°Ïì×îеÄ×ÀÃæºÍЧÀÍÆ÷Windows°æ±¾£¬£¬£¬£¬£¬£¬£¬°üÀ¨Windows11ºÍWindowsServer2022¡£¡£¡£¡£¡£¡£¸ÃÎó²îÏÖÔÚ²¢Î´Êܵ½Æð¾¢Ê¹Ó㬣¬£¬£¬£¬£¬£¬Ò²Ã»ÓйûÕæÅû¶µÄPOC(¿´·¨ÑéÖ¤´úÂ룩ʹÓᣡ£¡£¡£¡£¡£
ʱ¼ä£º2026-04-22
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-18
Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ
ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ