µçÐŹ«Ë¾AT£¦T´ó×ÚESBC×°±¸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷
Ðû²¼Ê±¼ä 2021-12-03µçÐŹ«Ë¾AT£¦T´ó×ÚESBC×°±¸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷

Ñо¿ÍŶÓÔÚ11ÔÂ30ÈÕ¹ûÕæÐ½©Ê¬ÍøÂçEwDoorµÄ¹¥»÷Ô˶¯¡£´Ë´ÎÔ˶¯Ö÷ÒªÕë¶ÔµçÐŹ«Ë¾AT£¦T EdgeMarcÆóÒµ»á»°½çÏß¿ØÖÆÆ÷(ESBC)±ßÑØ×°±¸£¬Ê¹ÓÃÁË4ÄêǰµÄÏÂÁî×¢ÈëÎó²î£¨CVE-2017-6079£©¡£ÔÚ½©Ê¬ÍøÂçÇл»µ½ÆäËüC2֮ǰµÄ¶Ì¶Ì3СʱÄÚ£¬¹²¼ì²âµ½Ô¼5700̨װ±¸±»Ñ¬È¾¡£ÏÖÔÚ£¬Ñо¿Ö°Ô±ÒÑÈ·ÈÏEwDoorµÄ3¸ö±äÌ壬¿É·ÖΪDDoS¹¥»÷ºÍBackdoorÁ½´óÀ࣬²¢ÍƲâÆäÖ÷ҪĿµÄÊÇDDoS¹¥»÷£¬ÒÔ¼°ÍøÂçͨ»°¼Í¼µÈÃô¸ÐÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/125143/cyber-crime/ewdoor-botnet.html
ÀÕË÷Èí¼þSabbathÃé×¼ÃÀ¹úºÍ¼ÓÄôóµÄÒªº¦»ù´¡ÉèÊ©

11ÔÂ29ÈÕ£¬MandiantÍŶӳÆÀÕË÷Èí¼þSabbath£¨ÓÖÃûUNC2190£©×Ô6Ô·Ý×îÏÈÒ»Ö±ÔÚÕë¶ÔÃÀ¹úºÍ¼ÓÄôó¡£UNC2190ÔÚ֮ǰÃûΪArcaneºÍEruption£¬²¢ÔÚ2020Äê7Ô·ַ¢ÀÕË÷Èí¼þROLLCOAST¡£Sabbath£¨54BB47h£©ÓÚ10ÔÂ21ÈÕÕýʽÔËÓª£¬Ö÷ҪĿµÄÊÇÒªº¦»ù´¡ÉèÊ©£¬°üÀ¨ÃÀ¹úºÍ¼ÓÄôóµÄ½ÌÓý¡¢ÎÀÉúºÍ×ÔÈ»×ÊÔ´ÐÐÒµ¡£ÓëÆäËûÀÕË÷ÔËÓªÍÅ»ï²î±ð£¬Sabbath»¹ÎªÆäÁ¥Êô×éÖ¯ÌṩÁËÔ¤ÏÈÉèÖúõÄCobalt Strike BEACONºóÃÅpayload¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/125154/cyber-crime/sabbath-ransomware.html
Symantec³ÆYanluowangÓëºÚ¿ÍÍÅ»ïThieflockÓйØ

SymantecÔÚ11ÔÂ30ÈÕÐû²¼Á˹ØÓÚÀÕË÷Èí¼þYanluowang½üÆÚÔ˶¯µÄÆÊÎö±¨¸æ¡£´Ë´ÎÔ˶¯×îÏÈÓÚ8Ô·ݣ¬Ê¹ÓÃÁ˶ñÒâÈí¼þBazarLoader£¬Ö÷ÒªÕë¶ÔÃÀ¹úµÄ½ðÈÚÐÐÒµ£¬µ«Ò²Õë¶ÔÖÆÔì¡¢IT·þÎñ¡¢×ÉѯºÍ¹¤³ÌµÈÐÐÒµµÄ¹«Ë¾¡£Ñо¿ÍŶӯÊÎö¹¥»÷ÕßʹÓõŤ¾ß¡¢Õ½ÂԺͳÌÐò(TTP)£¬·¢Ã÷ÆäÖÐÐí¶à¶¼ÓëThieflockµÄÀÕË÷¹¥»÷Ô˶¯Óйأ¬ÕâÅú×¢ËûÃÇ¿ÉÄÜÊôÓÚThieflockµÄÒ»¸öÁ¥Êô×éÖ¯¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/yanluowang-ransomware-thieflock-threat-actor/176640/
MozillaÐÞ¸´NSSÖеÄÄÚ´æËð»µÎó²îCVE-2021-43527

MozillaÓÚ12ÔÂ1ÈÕÐû²¼¸üУ¬ÐÞ¸´ÁËÆä¿çÆ½Ì¨ÍøÂçÇå¾²·þÎñ(NSS)ÖеÄÄÚ´æËð»µÎó²î£¨CVE-2021-43527£©¡£Google project-zeroÑо¿Ö°Ô±ÔÚ10ÔÂ24ÈÕÅû¶¸ÃÎó²îµÄϸ½Ú£¬ÔÚʹÓÃNSSµÄÓʼþ¿Í»§¶ËºÍPDFÉó²éÆ÷´¦Öóͷ£der±àÂëµÄDSA»òRSA-PSSÊðÃûʱ£¬¿ÉÄܻᵼÖ»ùÓڶѵĻº³åÇøÒç³ö¡£Ñо¿Ö°Ô±³Æ£¬ÀÖ³ÉʹÓøÃÎó²î¿Éµ¼Ö³ÌÐòÍß½â´úÂëÖ´ÐУ¬ÒÔ¼°ÈƹýÇå¾²¼ì²âÈí¼þ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/mozilla-fixes-critical-bug-in-cross-platform-cryptography-library/
·ÒÀ¼NCSC-FIÐû²¼´ó¹æÄ£·Ö·¢FlubotµÄÔ˶¯µÄ¾¯±¨

11ÔÂ30ÈÕ£¬·ÒÀ¼¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ(NCSC-FI)Ðû²¼Ö÷Òª¾¯±¨£¬ÖÒÑÔÕë¶Ô¸Ã¹úAndroidÓû§´ó¹æÄ£·Ö·¢FlubotµÄÔ˶¯¡£ÕâÊǽñÄêFlubotÔÚ·ÒÀ¼ÌᳫµÄµÚ¶þ´Î´ó¹æÄ£Ô˶¯£¬´Ëǰ´Ó2021Äê6Ô³õÖÁ8ÔÂÖÐÑ®£¬FlubotÌìÌìÏòÊýǧ¸ö·ÒÀ¼¹«Ãñ·¢ËÍÀ¬»ø¶ÌÐÅ¡£ÐÂÔ˶¯ÒÀÈ»ÒÔÒÆ¶¯ÔËÓªÉ̵ÄÓïÒôÓʼþΪÖ÷Ì⣬ÓÕʹAndroidÓû§ÏÂÔØÒ»¸öAPKÀ´×°ÖÃÒøÐжñÒâÈí¼þFlubot£¬¶øiPhoneÓû§Ôò»á±»Öض¨Ïòµ½Ö¼ÔÚÇÔÊØÐÅÏ¢µÄ´¹ÂÚÍøÕ¾¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/finland-warns-of-flubot-malware-heavily-targeting-android-users/
KasperskyÐû²¼2021ÄêAPT¹¥»÷Ô˶¯µÄ»ØÊ×±¨¸æ

KasperskyÓÚ11ÔÂ30ÈÕÐû²¼2021ÄêAPT¹¥»÷Ô˶¯µÄ»ØÊ×±¨¸æ¡£Ñо¿¸ú×ÙÁË900¶à¸öAPT¹¥»÷Ô˶¯£¬Ö¼ÔÚÆÊÎöÒÑÍù12¸öÔÂÖеÄÇ÷ÊÆºÍÉú³¤¡£±¨¸æÖ¸³ö£¬È«ÇòÁè¼Ý30000¸ö¼ÇÕß¡¢×´Ê¦µÈÖ°Ô±³ÉΪPegasusµÄÄ¿µÄ£»±¬·¢ÁËÐí¶à±¸ÊÜÖõÄ¿µÄ¹©Ó¦Á´¹¥»÷£¬ÈçÓ°ÏìÁË18000¶à¸öSolarWinds¿Í»§µÄ¹©Ó¦Á´¹¥»÷£»Ê¹ÓÃExchangeºÍChromeµÈÈí¼þÖеÄÁãÈÕÎó²î£»Ê¹Óù̼þÖеÄÎó²î¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/apt-annual-review-2021/105127/


¾©¹«Íø°²±¸11010802024551ºÅ