ÖÇÀû½ðÈÚÊг¡Î¯Ô±»áExchangeÔâµ½¹¥»÷²¢¹²ÏíIOC£»SentinelOne·¢ÏÖÕë¶ÔiOS¿ª·¢ÈËÔ±µÄ¹©¸øÁ´¹¥»÷»î¶¯

°ä²¼¹¦·ò 2021-03-19

1.ÖÇÀû½ðÈÚÊг¡Î¯Ô±»áExchangeÔâµ½¹¥»÷²¢¹²ÏíIOC


1.jpg


ÖÇÀû½ðÈÚÊг¡Î¯Ô±»á£¨CMF£©³ÆÆäExchangeÔâµ½¹¥»÷²¢¹²ÏíIOC¡£CMFÊôÓÚÖÇÀû²ÆÕþ²¿£¬ÊÇÖÇÀûÒøÐкͽðÈÚ»ú¹¹µÄ¼à¹ÜÕߺͲ鳭Ա¡£CMFÓÚ3ÔÂ17ÈÕ°ä²¼»ã±¨£¬³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷£¬ºÚ¿ÍÀûÓÃ×î½üÅû¶µÄMicrosoft Exchange·þÎñÆ÷ÖеÄProxyLogon·ì϶װÖÃWeb Shell²¢ÊÔͼÇÔȡʹ´¦Ö®ºó¡£ÎªÁËÔ®ÊÖ×êÑÐÈËÔ±ºÍÆäËûMicrosoft ExchangeÖÎÀíÔ±£¬CMF»¹°ä²¼ÁËWeb ShellµÄIOCºÍÔÚÔâµ½¹¥»÷µÄ·þÎñÆ÷ÉÏÕÒµ½µÄÅú´¦ÖÃÎļþ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/chiles-bank-regulator-shares-iocs-after-microsoft-exchange-hack/


2.SentinelOne·¢ÏÖÕë¶ÔiOS¿ª·¢ÈËÔ±µÄ¹©¸øÁ´¹¥»÷»î¶¯


2.jpg


°²È«¹«Ë¾SentinelOne·¢ÏÖÁËÐµĹ©¸øÁ´¹¥»÷»î¶¯£¬Ê¹ÓÃÃûΪXcodeSpyµÄ¶ñÒâXcodeÏîÄ¿Õë¶ÔiOS¿ª·¢ÈËÔ±¡£XcodeÊÇApple´´½¨µÄ¼¯³É¿ª·¢»·¾³£¨IDE£©£¬¿ª·¢ÈËÔ±¿ÉÀûÓÃÆä´´½¨macOS¡¢iOS¡¢tvOSºÍwatchOSÀûÓ÷¨Ê½¡£Ôڸù¥»÷ÖУ¬ºÚ¿Í¿Ë¡Á˺Ϸ¨µÄTabBarInteractionÏîÄ¿£¬²¢Ôö³¤ÁËÍÌ͵ĶñÒâRun¾ç±¾XcodeSpy£¬ÒÔ½«¹¥»÷ÕßµÄC2·þÎñÆ÷Ïνӵ½¿ª·¢ÈËÔ±µÄÏîÄ¿¡£XcodeSpyÓÚ9ÔÂ4ÈÕ³õ´Î±»ÉÏ´«µ½VirusTotal£¬×êÑÐÈËÔ±ÒÉ»óÕâÊǹ¥»÷ÕßΪ²âÊÔ¼ì²âÂʶø×Ô¼ºÉÏ´«µÄÑù±¾¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-xcodespy-malware-targets-ios-devs-in-supply-chain-attack/


3.×êÑÐÈËÔ±·¢ÏÖÖ¼ÔÚÇÔÈ¡5GÓйؼ¼ÊõµÄDi¨¤nx¨´nÐж¯


3.jpg


×êÑÐÈËÔ±·¢ÏÖÕë¶ÔµçÐŹ«Ë¾µÄDi¨¤nx¨´nÐж¯£¬Ö¼ÔÚÇÔÈ¡5G¼¼ÊõÓйصÄÃô¸ÐÊý¾ÝºÍóÒ×»úÃÜ¡£ÔÚ²¿ÃŹ¥»÷ÖУ¬ºÚ¿Í´î½¨ÁËÒ»¸öαÔì³É»ªÎªÖ°ÒµÒ³ÃæµÄÐéÎ±ÍøÕ¾¡£×êÑÐÈËÔ±³Æ£¬Õâ´ÎÐж¯ËùʹÓõÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½£¨TTP£©ÓëAPT×éÖ¯RedDeltaºÍÒ°Mustang PandaµÄÐж¯ÀàËÆ¡£McAfee ATRÍŶӰµÊ¾×î³õµÄϰȾý½éÉв»ÆëÈ«Ã÷ÏÔ£¬µ«Æä´§Ä¦ºÚ¿Í¿ÉÄÜʹÓô¹µöÍøÕ¾À´·Ö·¢¶ñÒâÈí¼þ£¬²¢ÔÚ¹¥»÷µÄµÚ¶þ½×¶ÎÀûÓûùÓÚFlashµÄ¹¤¼þ¶ñÒâÈí¼þÔÚÊܺ¦ÕßµÄϵͳÉÏÖ´ÐÐ.NET¸ºÔØ¡£    


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115693/apt/chinese-hackers-5g.html


4.ŦԼÖݶà¸öÏØÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Êý¾Ý»òÒÑй¶


4.jpg


ŦԼÖݵݶû°ÍÄá¡¢ÈøÀ­ÍмӺÍÂ×˹ÀÕµÈÏØÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Êý¾Ý»òÒÑй¶¡£°Â¶û°ÍÄáÏØ¾¯³¤°ì¹«ÊÒ°µÊ¾¹¥»÷²úÉúÔÚ±¾ÖܶþÍíÉÏ9µã30·Ö×óÓÒ£¬ÌØÀïÏØ¹«¹²°²È«ÍøÂçϰȾÁËÀÕË÷Èí¼þ£¬Ó°ÏìÁ˶à¸öÏØ³Ç¡£¾Ý±¨Â·£¬Computer Aidedµ÷¶È£¨CAD£©·þÎñÊܵ½ÁËÓ°Ï죬ÆäÔÚͨ¹ý±¸·Ý½øÐгÁ½¨¡£¸ÃÏØ¹ÙÔ±°µÊ¾£¬Ä¿Ç°±¸ÓÃϵͳÈÔÕý³£ÔËÐв¢ÇÒ¿ÉÒÔΪÌṩ911·þÎñ£¬µ«ÊDz¿ÃÅÊý¾Ý¿ÉÄÜÒѾ­Ð¹Â¶¡£


Ô­ÎÄÁ´½Ó£º

https://www.news10.com/news/tri-county-sheriff-dispatch-hit-with-ransomware-attack/


5.ÈÕ¾­ÖйúÏã¸Û·Ö¹«Ë¾³ÆÆäÔâµ½¹¥»÷£¬Óû§ÐÅÏ¢¿ÉÄÜй¶


5.jpg


ÈÕ¾­(Nikkei)±¾ÖÜÈý°µÊ¾ÆäÖйúÏã¸Û·Ö¹«Ë¾Ôâµ½¹¥»÷£¬Óû§ÐÅÏ¢¿ÉÄÜй¶¡£Õâ´ÎÊÂÎñʼÓÚ2020Äê10Ô£¬¸Ã·Ö¹«Ë¾µÄ²¿Ãŵç×ÓÓʼþÕË»§Ô⵽δ¾­ÊÚȨµÄ½Ó¼û¡£ÈÕ¾­¹ú¼Ê°æ¡¢ÍøÂç°æºÍÈÕ¾­ÑÇÖÞ°æ¡¢ÈÕ¾­ÖйúµÄº£±í¶©»§µÄÓ×ÎÒÐÅÏ¢¿ÉÄÜÒѾ­Ð¹Â¶£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¹«Ë¾Ãû³Æ¡¢µØÖ·ºÍµç»°ºÅÂ룬ÒÔ¼°²¿Ãſͻ§µÄÐÅÓþ¿¨ÐÅÏ¢¡£Ä¿Ç°£¬ÈÕ¾­Öйú¹«Ë¾Òѽ«´ËÊÂÎñ»ã±¨¸øÏã¸ÛµÄÓ×ÎÒÐÅÏ¢±£»¤µ±¾Ö¡£


Ô­ÎÄÁ´½Ó£º

https://asia.nikkei.com/Business/Companies/Nikkei-s-Hong-Kong-affiliate-hit-by-unauthorized-access


6.Unit42°ä²¼2021ÄêÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨


6.jpg


Unit42°ä²¼ÁË2021ÄêÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨£¬Ö¼ÔÚÆÀ¹ÀÀÕË÷Èí¼þ¹¥»÷µÄÁìÓò²¢Ìṩ¿É½µµÍ·çÏյIJÙ×÷²½Öè¡£»ã±¨Ö¸³ö£¬¾ùÔÈÊê½ð´Ó2019ÄêµÄ115123ÃÀÔªÔö³¤µ½2020ÄêµÄ312493ÃÀÔª£¬×î¸ßÊê½ð´Ó1500ÍòÃÀÔªÔö³¤µ½3000ÍòÃÀÔª£»ºÚ¿ÍÖØÒªÕë¶ÔÒ½ÁƱ£½¡²¿ÃÅ£»Ë«³ÁÀÕË÷µÄÇé¿öÓÐËùÔö³¤£¬³¬¹ý16ÖÖ·ÖÆçµÄÀÕË÷Èí¼þ±äÖÖ¶¼ÔÚʹÓÃÕâÖÖ²½Ö裬ÆäÖÐNetwalkerÕ¼±È×î´ó£¬Ð¹Â¶ÁËÒ»°Ù¶àÃûÊܺ¦ÕßµÄÐÅÏ¢¡£    


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/ransomware-threat-assessments/