¶íÂÞ˹µçÐÅRostelecomÐ®ÖÆ¶à¸öÆóÒµµÄÁ÷Á¿£»Î¢ÈíÐû²¼Emotet¹¥»÷°¸Àý±¨¸æ

Ðû²¼Ê±¼ä 2020-04-07

1.DarkHotelʹÓÃÉîÐÅ·þVPNÎó²î¹¥»÷ÎÒ¹úµÄÕþ¸®»ú¹¹


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


¿ËÈÕ£¬ÓÐÐÂÎųƺڿÍ×éÖ¯Darkhotel£¨APT-C-06£©Ê¹ÓÃÉîÐÅ·þSSL VPN×°±¸Îó²î¹¥»÷ÎÒ¹úµÄÕþ¸®»ú¹¹¡£¸Ã¹¥»÷Ô˶¯Ê¼ÓÚ3Ô£¬ÓÐÁè¼Ý200̨VPN·þÎñÆ÷Ôâµ½¹¥»÷£¬ÆäÖÐ174̨λÓÚ±±¾©ºÍÉϺ£µÄÕþ¸®»ú¹¹ÍøÂçÒÔ¼°²¿·ÖÖйúפÍâ»ú¹¹£¬4Ô³õ¹¥»÷Ì¬ÊÆÓÖÔÙÏò±±¾©¡¢ÉϺ£Ïà¹ØÕþ¸®»ú¹¹ÉìÕÅ¡£ÉîÐÅ·þ¹Ù·½ÒÑÓÚ4ÔÂ6ÈÕÕýʽÐû²¼Ç徲ͨ¸æ£¬²¢Æô¶¯Îó²îÏìÓ¦¡£¸ÃÎó²îÊÇ4ÔÂ3ÈÕ360ÏòÉîÐÅ·þÓ¦¼±Çå¾²ÏìÓ¦ÖÐÐı¨¸æµÄÎó²î£¨SRC-2020-281£©£¬ÎªSSL VPN×°±¸Windows¿Í»§¶ËÉý¼¶Ä £¿éÊðÃûÑéÖ¤»úÖÆµÄȱÏÝ£¬µ«¸ÃÎó²îʹÓÃÌõ¼þÊDZØÐèÒѾ­»ñÈ¡¿ØÖÆSSL VPN×°±¸µÄȨÏÞ£¬Òò´ËʹÓÃÄѶȽϸß¡£ÉîÐÅ·þÈ·ÈÏÔËÐй̼þ°æ±¾M6.3R1ºÍM6.1µÄSSL VPN×°±¸Ò×Êܹ¥»÷£¬½¨ÒéÓû§¾ÙÐÐÅŲéºÍÓ¦Óò¹¶¡¸üС£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/darkhotel-hackers-use-vpn-zero-day-to-compromise-chinese-government-agencies/


2.¶íÂÞ˹µçÐŹ«Ë¾RostelecomÐ®ÖÆ¶à¸öÆóÒµµÄ»¥ÁªÍøÁ÷Á¿


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


4ÔÂ1ÈÕ¶íÂÞ˹µçÐŹ«Ë¾RostelecomÐ®ÖÆÁ˹ȸèµÈ¹«Ë¾µÄ»¥ÁªÍøÁ÷Á¿£¬¸ÃÊÂÎñÓ°ÏìÁËÌìÏÂÉÏ×î´óµÄ200¶à¸öCDNÍøÂç¼°ÔÆÍйܷþÎñÉÌ£¬Ò»Á¬ÁËԼĪ1¸öСʱ¡£ÊÜÓ°ÏìµÄÆóÒµ°üÀ¨¹È¸è¡¢ÑÇÂíÑ·¡¢Facebook¡¢Akamai¡¢Cloudflare¡¢GoDaddy¡¢Digital Ocean¡¢Joyent¡¢LeaseWeb¡¢HetznerºÍLinodeµÈ×ÅÃû¹«Ë¾¡£ÕâÊÇÒ»´Îµä·¶µÄBGPÐ®ÖÆÊÂÎñ£¬¸ÃÊÂÎñµÄÔµ¹ÊÔ­ÓÉ¿ÉÄÜÊÇRostelecomµÄÄÚ²¿Á÷Á¿ÐÞÕýϵͳ¹ýʧµØ½«²»×¼È·µÄBGP·ÓÉ̻¶ÔÚ¹«ÍøÉÏ£¬²¢ÇÒ±»ÉÏÓι©Ó¦É̹㲥Ôì³ÉµÄ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/russian-telco-hijacks-internet-traffic-for-google-aws-cloudflare-and-others/


3.΢ÈíÐû²¼Emotet¹¥»÷Fabrikam¹«Ë¾µÄ°¸ÀýÑо¿±¨¸æ


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


΢ÈíÔÚ¼ì²âºÍÏìӦС×飨DART£©°¸Àý±¨¸æ002ÖзÖÏíÁËFabrikam¹«Ë¾ÔâÊÜEmotet¹¥»÷µÄÏêϸÐÅÏ¢¡£¸Ã¹¥»÷ʼÓÚÍøÂç´¹ÂÚÓʼþ£¬µ±ÄÚ²¿Ô±¹¤»á¼ûÁË´¹ÂÚÐÅÏ¢ºó£¬EmotetѬȾÁËÆäϵͳ²¢ºáÏòѬȾÁËÍ³Ò»ÍøÂçÖÐµÄÆäËüϵͳ¡£¸Ã²¡¶¾×èÖ¹ÁËͨ¹ýÏÂÁîºÍ¿ØÖÆ·þÎñÆ÷£¨C2£©¾ÙÐа´ÆÚ¸üжø±»·À²¡¶¾½â¾ö¼Æ»®¼ì²âµ½µÄÇéÐΣ¬²¢ÇÒͨ¹ýʹWindowsÉè±¹ØÁ¬ÄCPUʹÓÃÂʵִﱥºÍÀ´×èÖ¹½¹µã·þÎñ£¬µ¼Ö¸Ã×éÖ¯µÄ»ù±¾·þÎñºÍÍøÂçÖÐÖ¹ÁË¿ìÒªÒ»ÖܵÄʱ¼ä¡£CPUʹÓÃÂÊÒ»Ö±±¥ºÍʹµÃÅÌËã»ú¹ýÈÈ£¬µ¼ÖÂÄÚ²¿ÏµÍ³¿¨ËÀ¡¢ÖØÆôºÍÍøÂçÅþÁ¬Ï½µ¡£¸Ã¶ñÒâÈí¼þͨ¹ýÇÔÈ¡ÖÎÀíÔ±ÕÊ»§Æ¾Ö¤¾ÙÐкáÏòÒÆ¶¯£¬ÔÚ×î³õѬȾºóµÄ8ÌìÖ®ÄÚ£¬FabrikamµÄÕû¸öÍøÂç¾Í±»¹Ø±ÕÁË¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/security/blog/wp-content/uploads/2020/04/Case-study_Full-Operational-Shutdown.pdf


4.PayPalºÍVenmoÓû§½»Á÷Õ½ÂÔÎó²îµ¼ÖºڿÍÐ®ÖÆÓû§


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÆÕÁÖ˹¶Ù´óѧµÄÑо¿Ö°Ô±·¢Ã÷17¼ÒÖ÷Òª¹«Ë¾£¬ÆäÖаüÀ¨Amazon¡¢Paypal¡¢Venmo¡¢Blizzard¡¢Adobe¡¢eBay¡¢SnapchatºÍYahoo£¬ÔÊÐíÓû§Í¨¹ý·¢Ë͵½ÓëËûÃÇÕÊ»§Ïà¹ØÁªµÄµç»°ºÅÂëµÄ¶ÌÐÅÀ´ÖØÖÃÃÜÂ룬ÕâÒâζ×ÅÈôÊǺڿÍͨ¹ýSIM½»Á÷¹¥»÷¿ØÖÆÁËÊܺ¦ÕßµÄÊÖ»úºÅÂ룬ÄÇôºÚ¿Í¾Í¿ÉÒÔʹÓÃÕâÐ©ÍøÕ¾ºÍ·þÎñÈëÇÖÊܺ¦ÕßµÄÔÚÏßÕÊ»§¡£ÔÚ½Óµ½Ñо¿Ö°Ô±µÄÖÒÑÔÖ®ºó£¬°üÀ¨Adobe¡¢±©Ñ©¡¢Ebay¡¢Î¢ÈíºÍSnapchatÔÚÄÚµÄһЩ¹«Ë¾ÐÞ¸´ÁËÕâÒ»ÎÊÌ⣬µ«ÈÔÓÐһЩ¹«Ë¾Ã»ÓÐÐÞ¸´¸ÃÎó²î£¬ÀýÈçÔÊÐíÓû§¾ÙÐÐÉúÒâ²¢ÇÒÓëÒøÐÐÕÊ»§»òÐÅÓÿ¨¹ØÁªµÄÓ¦ÓóÌÐòPaypalºÍVenmo¡£ÕâÁ½¼Ò¹«Ë¾ÉÐδ¾Í´Ë½ÒÏþ̸ÂÛ¡£


Ô­ÎÄÁ´½Ó£º

https://www.vice.com/en_us/article/pke9zk/paypal-and-venmo-are-letting-sim-swappers-hijack-accounts


5.AppleÐÞ¸´SafariÖжà¸öÎó²î£¬¿É±»ºÚ¿Í¿ØÖÆÉãÏñÍ·


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Çå¾²Ñо¿Ö°Ô±Ryan PickrenÔÚSafariÖз¢Ã÷ÁË7¸ö0day£¬°üÀ¨CVE-2020-3852¡¢CVE-2020-3864¡¢CVE-2020-3865¡¢CVE-2020-3885¡¢CVE-2020-3887£¬CVE-2020-9784ºÍCVE-2020-9787¡£¹¥»÷Õß¿ÉʹÓÃÆäÖеÄ3¸öÎó²î×éºÏ£¬»á¼ûiOSºÍmacOSÉè±¹ØÁ¬ÄÉãÏñÍ·ºÍÂó¿Ë·ç²¢¼àÊÓÓû§¡£Õâ3¸öÎó²îÓëSafariÆÊÎöURI¡¢ÖÎÀíWebÔ´ÒÔ¼°³õʼ»¯Çå¾²ÉÏÏÂÎĵķ½·¨ÓйØ£¬¿ÉÔÊÐí¶ñÒâÍøÕ¾ÔÚSafariÉÏαװ³ÉÊÜÐÅÍеÄÍøÕ¾Ìᳫ¹¥»÷¡£AppleÔÚ1ÔÂ28ÈÕÐû²¼µÄSafari 13.0.5ÖÐÐÞ²¹ÁËÕâ3¸öÎó²î£¬²¢ÔÚ3ÔÂ24ÈÕÐû²¼µÄSafari 13.1ÖÐÐÞ¸´ÁËÆäÓàÎó²î¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/vulnerabilities---threats/researcher-hijacks-ios-macos-camera-with-three-safari-zero-days/d/d-id/1337486


6.EuropolÓëInterpolÐû²¼ÓëCOVID-19Ïà¹ØµÄÍøÂç·¸·¨×ª´ï


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Å·ÖÞÐ̾¯×éÖ¯£¨Europol£©ÔÚ×îеÄÇå¾²×ÉѯÖÐÏêϸÏÈÈÝÁËCOVID-19ÓйصÄÍøÂç·¸·¨Ô˶¯£¬ÁгöÁË´ÙʹÓëCOVIDÓйصÄÍøÂç·¸·¨Ô˶¯×ª±äµÄÁù¸öÒòËØ£º¶ÔijЩÉÌÆ·¡¢·À»¤×°±¸ºÍÒ©Æ·µÄ¸ßÐèÇó£»¹«ÃñÔ½À´Ô½ÒÀÀµÊý×Ö½â¾ö¼Æ»®¾ÙÐÐÔ¶³Ì°ì¹«£»½¹ÂǺͿ־åÐÄÀí£»ÊÕÖ§Å·Ã˵ÄÖ°Ô±Á÷¶¯ïÔÌ­£»¹«¹²³¡ºÏÔ˶¯ÊÜÏÞ£¬Ê¹Ò»Ð©·¸·¨Ô˶¯×ªÒƵּÒÍ¥»òÔÚÏßÇéÐΣ»Å·ÃËijЩ²»·¨ÉÌÆ·µÄ¹©Ó¦ïÔÌ­¡£Óë´Ëͬʱ£¬¹ú¼ÊÐ̾¯×éÖ¯£¨Interpol£©ÖÒÑÔÀÕË÷Èí¼þ¹¥»÷ÒѾ­×îÏÈÕë¶ÔÒ½ÔºµÈÓëCOVID-19ÓÐ¹ØµÄÆäËü»ú¹¹¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.europol.europa.eu/publications-documents/catching-virus-cybercrime-disinformation-and-covid-19-pandemic