µçÐŹ«Ë¾AT£¦T´óÁ¿ESBCÉ豸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷
°ä²¼¹¦·ò 2021-12-03µçÐŹ«Ë¾AT£¦T´óÁ¿ESBCÉ豸Ôâµ½½©Ê¬ÍøÂçEwDoor¹¥»÷

×êÑÐÍŶÓÔÚ11ÔÂ30ÈÕ¹«¿ªÐ½©Ê¬ÍøÂçEwDoorµÄ¹¥»÷»î¶¯¡£Õâ´Î»î¶¯ÖØÒªÕë¶ÔµçÐŹ«Ë¾AT£¦T EdgeMarcÆóÒµ»á»°Ììǵ½ÚÔìÆ÷(ESBC)±ßÔµÉ豸£¬ÀûÓÃÁË4ÄêǰµÄºÅÁî×¢Èë·ì϶£¨CVE-2017-6079£©¡£ÔÚ½©Ê¬ÍøÂçÇл»µ½ÆäËüC2֮ǰµÄ¶Ì¶Ì3Ó×ʱÄÚ£¬¹²¼ì²âµ½Ô¼5700̨É豸±»Ï°È¾¡£Ä¿Ç°£¬×êÑÐÈËÔ±ÒÑÈ·ÈÏEwDoorµÄ3¸ö±äÌ壬¿É·ÖΪDDoS¹¥»÷ºÍBackdoorÁ½´óÀ࣬²¢´§Ä¦ÆäÖØÒªÖ÷ÕÅÊÇDDoS¹¥»÷£¬ÒÔ¼°ÍøÂçͨ»°¼Í¼µÈÃô¸ÐÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/125143/cyber-crime/ewdoor-botnet.html
ÀÕË÷Èí¼þSabbath¶Ô×¼ÃÀ¹úºÍ¼ÓÄôóµÄ¹Ø¼ü»ù´¡ÉèÊ©

11ÔÂ29ÈÕ£¬MandiantÍŶӳÆÀÕË÷Èí¼þSabbath£¨±ðÃûUNC2190£©×Ô6ÔÂ·ÝÆðÍ·Ò»ÏòÔÚÕë¶ÔÃÀ¹úºÍ¼ÓÄôó¡£UNC2190ÔÚ֮ǰÃûΪArcaneºÍEruption£¬²¢ÔÚ2020Äê7Ô·ַ¢ÀÕË÷Èí¼þROLLCOAST¡£Sabbath£¨54BB47h£©ÓÚ10ÔÂ21ÈÕÕýʽÔËÓª£¬ÖØÒªÖ¸±êÊǹؼü»ù´¡ÉèÊ©£¬Ô̺¬ÃÀ¹úºÍ¼ÓÄôóµÄ½ÌÓý¡¢ÎÀÉúºÍÌìÈ»×ÊÔ´ÐÐÒµ¡£ÓëÆäËûÀÕË÷ÔËÓªÍÅ»ï·ÖÆç£¬Sabbath»¹ÎªÆä´ÓÊô×éÖ¯ÌṩÁËÔ¤ÏÈÅäÖúõÄCobalt Strike BEACONºóÃÅpayload¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/125154/cyber-crime/sabbath-ransomware.html
Symantec³ÆYanluowangÓëºÚ¿ÍÍÅ»ïThieflockÓйØ

SymantecÔÚ11ÔÂ30ÈÕ°ä²¼Á˹ØÓÚÀÕË÷Èí¼þYanluowang½üÆÚ»î¶¯µÄ·ÖÎö»ã±¨¡£Õâ´Î»î¶¯ÆðÍ·ÓÚ8Ô·ݣ¬ÀûÓÃÁ˶ñÒâÈí¼þBazarLoader£¬ÖØÒªÕë¶ÔÃÀ¹úµÄ½ðÈÚÐÐÒµ£¬µ«Ò²Õë¶ÔÔì×÷¡¢IT·þÎñ¡¢Õ÷ѯºÍ¹¤³ÌµÈÐÐÒµµÄ¹«Ë¾¡£×êÑÐÍŶӷÖÎö¹¥»÷ÕßʹÓõŤ¾ß¡¢Õ½ÊõºÍ·¨Ê½(TTP)£¬·¢ÏÔìäÖкܶ඼ÓëThieflockµÄÀÕË÷¹¥»÷»î¶¯Óйأ¬ÕâÅú×¢ËûÃÇ¿ÉÄÜÊôÓÚThieflockµÄÒ»¸ö´ÓÊô×éÖ¯¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/yanluowang-ransomware-thieflock-threat-actor/176640/
Mozilla½¨¸´NSSÖеÄÄÚ´æ°Ü»µ·ì϶CVE-2021-43527

MozillaÓÚ12ÔÂ1ÈÕ°ä²¼¸üУ¬½¨¸´ÁËÆä¿çÆ½Ì¨ÍøÂ簲ȫ·þÎñ(NSS)ÖеÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-43527£©¡£Google project-zero×êÑÐÈËÔ±ÔÚ10ÔÂ24ÈÕÅû¶¸Ã·ì϶µÄϸ½Ú£¬ÔÚʹÓÃNSSµÄÓʼþ¿Í»§¶ËºÍPDF²é¿´Æ÷´¦ÖÃder±àÂëµÄDSA»òRSA-PSSÊðÃûʱ£¬¿ÉÄܻᵼÖ»ùÓڶѵĻº³åÇøÒç³ö¡£×êÑÐÈËÔ±³Æ£¬³É¹¦ÀûÓø÷ì϶¿Éµ¼Ö·¨Ê½±ÀÀ£´úÂëÖ´ÐУ¬ÒÔ¼°Èƹý°²È«¼ì²âÈí¼þ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/mozilla-fixes-critical-bug-in-cross-platform-cryptography-library/
·ÒÀ¼NCSC-FI°ä²¼´ó¹æÄ£·Ö·¢FlubotµÄ»î¶¯µÄ¾¯±¨

11ÔÂ30ÈÕ£¬·ÒÀ¼¹ú¶ÈÍøÂ簲ȫÖÐÐÄ(NCSC-FI)°ä²¼³ÁÒª¾¯±¨£¬ÖÒ¸æÕë¶Ô¸Ã¹úAndroidÓû§´ó¹æÄ£·Ö·¢FlubotµÄ»î¶¯¡£ÕâÊǽñÄêFlubotÔÚ·ÒÀ¼ÌáÒéµÄµÚ¶þ´Î´ó¹æÄ£»î¶¯£¬´Ëǰ´Ó2021Äê6Ô³õÖÁ8ÔÂÖÐÑ®£¬FlubotÿÌìÏòÊýǧ¸ö·ÒÀ¼¹«Ãñ·¢ËÍÀ¬»ø¶ÌÐÅ¡£Ð»ÒÀÈ»ÒÔÒÆ¶¯ÔËÓªÉ̵ÄÓïÒôÓʼþΪÖ÷Ì⣬ÓÕʹAndroidÓû§ÏÂÔØÒ»¸öAPKÀ´×°ÖÃÒøÐжñÒâÈí¼þFlubot£¬¶øiPhoneÓû§Ôò»á±»³Á¶¨Ïòµ½Ö¼ÔÚÇÔÊØÐÅÏ¢µÄ´¹µöÍøÕ¾¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/finland-warns-of-flubot-malware-heavily-targeting-android-users/
Kaspersky°ä²¼2021ÄêAPT¹¥»÷»î¶¯µÄ»ØÊ׻㱨

KasperskyÓÚ11ÔÂ30ÈÕ°ä²¼2021ÄêAPT¹¥»÷»î¶¯µÄ»ØÊ׻㱨¡£×êÑиú×ÙÁË900¶à¸öAPT¹¥»÷»î¶¯£¬Ö¼ÔÚ·ÖÎö´Óǰ12¸öÔÂÖеÄÇ÷ÏòºÍ·¢Õ¹¡£»ã±¨Ö¸³ö£¬È«Çò³¬¹ý30000¸ö¼ÇÕß¡¢ÂÉʦµÈÈËÔ±³ÉΪPegasusµÄÖ¸±ê£»²úÉúÁ˺ܶ౸ÊÜÖõÖ÷ÕŹ©¸øÁ´¹¥»÷£¬ÈçÓ°ÏìÁË18000¶à¸öSolarWinds¿Í»§µÄ¹©¸øÁ´¹¥»÷£»ÀûÓÃExchangeºÍChromeµÈÈí¼þÖеÄÁãÈÕ·ì϶£»ÀûÓù̼þÖеķì϶¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/apt-annual-review-2021/105127/


¾©¹«Íø°²±¸11010802024551ºÅ