¿¨°Í˹»ù | 2020ÄêQ1 APTÇ÷Ïò»ã±¨
°ä²¼¹¦·ò 2020-05-01¿¨°Í˹»ù°ä²¼2020ÄêµÚÒ»¼¾¶ÈµÄAPT×éÖ¯»î¶¯µÄÇ÷Ïò»ã±¨£¬ÖØÒª×¢Ã÷³Á´óµÄAPT»î¶¯ÒÔ¼°×êÑз¢ÏÖ¡£
0x00 COVID-19 APT»î¶¯
×ÔÊÀ½çÎÀÉú×éÖ¯£¨WHO£©°ä·¢COVID-19³ÉΪÎÁÒßÒÔÀ´£¬ÕâÒ»»°ÌâÒÑÊܵ½·ÖÆç¹¥»÷ÕßÔ½À´Ô½¶àµÄ¹Ø×¢¡£ºÜ¶àÍøÂç´¹µöڿƶ¼ÊÇÓÉÍøÂç·¸×ï·Ö×ÓÌáÒéµÄ£¬ËûÃÇÊÔIJÀûÓÃÈËÃǶԲ¡¶¾µÄÕð¾ªÀ´»ñÀû¡£µ«ÊÇ£¬¹¥»÷ÕßÁбíÖл¹Ô̺¬APT×éÖ¯£¬ÀýÈçKimsuky£¬APT27£¬Lazarus»òViciousPanda£¬Æ¾¾ÝOSINT£¬ËûÃÇÒÔCOVID-19×÷Ϊµö¶ü¶Ô×¼Êܺ¦Õß¡£ÎÒÃÇ×î½ü·¢ÏÖÁË¿ÉÒɵĻù´¡ÉèÊ©¿ÉÓÃÓÚÕë¶ÔÔ̺¬WHOÔÚÄÚµÄÎÀÉúºÍÈË·Ö÷Òå×éÖ¯¡£¾ÝһЩ¸öÈËÐÂÎÅÆðÔ´³Æ£¬Ö»¹Ü»ù´¡ÉèʩĿǰÎÞ·¨¹éÒòÓÚÈκÎÌØ¶¨µÄ×éÖ¯£¬²¢ÇÒÒÑÔÚ2019Äê6ÔÂCOVID-19Σ»ú֮ǰע²á£¬µ«Ëü¿ÉÄÜÓëDarkHotelÓйء£µ«ÊÇ£¬ÎÒÃÇĿǰÎÞ·¨È·ÈÏ´ËÐÅÏ¢¡£ÓÐȤµÄÊÇ£¬Ò»Ð©×éÖ¯ÀûÓõ±Ç°Çé¿öÀ´°ä·¢ËûÃÇÔÚΣ»úÆÚ¼ä²»»áÕë¶ÔÎÀÉú×éÖ¯¡£
0x01 ×îÖµÍ×ÌùÐĵÄÇ÷Ïò
2020Äê1Ô£¬ÎÒÃÇ·¢ÏÖÒ»¸öË®¿Ó¹¥»÷ÀûÓÃÆëÈ«µÄÔ¶³ÌiOS·ì϶¡£Õâ¸öÍøÕ¾µÄÖ÷ÕÅÊÇÆ¾¾ÝÖ¸±êÍøÒ³µÄÄÚÈÝÀ´¶¨Î»ÖйúÏã¸ÛµÄÓû§¡£¹ÌÈ»µ±Ç°ÔÚʹÓõķì϶ÀûÓ÷¨Ê½ÊÇÒÑÖªµÄ£¬µ«ÕƹÜÈËÔ¹ØýÔÚ»ý¼«Åú¸Ä·ì϶ÀûÓù¤¾ß°ü£¬ÒÔÕë¶Ô¸ü¶àµÄiOS°æ±¾ºÍÉ豸¡£ÎÒÃÇÔÚ2ÔÂ7Èչ۲쵽ÁË×îеİ汾¡£¸ÃÏîÄ¿±ÈÎÒÃÇ×î³õÉèÏëµÄÒª¿í·º£¬ËüÖ§³ÖAndroidÖ²È룬²¢ÇÒ¿ÉÄÜÖ§³ÖWindows£¬LinuxºÍMacOSµÄÖ²È롣Ŀǰ£¬ÎÒÃǽ«´ËAPT×éÖ¯³ÆÎªTwoSail Junk¡£ÎÒÃÇÒÔΪÕâÊÇÒ»¸öÖÐÎÄ×éÖ¯£¬ËüÖØÒªÔÚÖйúÏã¸ÛÊØ»¤»ù´¡ÉèÊ©£¬²¢ÔÚÐÂ¼ÓÆÂºÍÉϺ£ÉèÓм¸¸öÖ÷»ú¡£TwoSail Junkͨ¹ýÔÚÂÛ̳°ä²¼Á´½Ó»ò´´½¨×Ô¼ºµÄÐÂÖ÷ÌâÀ´½«½Ó¼ûÕßÊèµ¼ÖÁÆäÀûÓÃÕ¾µã¡£ÖÁ½ñ£¬¼Í¼ÁËÀ´×ÔÖйúÏã¸ÛµÄÊýÊ®´Î½Ó¼û£¬ÆäÖÐÒ»¶ÔÀ´×ÔÖйú°ÄÃÅ¡£
0x02 ¶íÓïÓйصÄAPT×éÖ¯»î¶¯
1Ô£¬ÔÚÒ»¼Ò¶«Å·µçÐŹ«Ë¾Öз¢ÏÖÁ˼¸¸ö×î½ü±àÒëµÄSPLM/XAgentÄ£¿é¡£×î³õµÄ½øÈëµãÊÇδ֪µÄ£¬ËüÃÇÔÚ¸Ã×éÖ¯ÄڵĺáÏò»î¶¯Ò²ÊÇδ֪µÄ¡£Óë´ÓǰµÄSofacy»î¶¯Ë®Æ½Ïà±È£¬ÏÕЩÎÞ·¨¼ø±ðSPLMϰȾ£¬Òò¶øËƺõ¸Ã¹«Ë¾ÄÚÍø¿ÉÄÜÒѾϰȾÁËÒ»¶Î¹¦·ò¡£³ýÁËÕâЩSPLMÄ£¿éÖ®±í£¬Sofacy»¹²¿ÊðÁË.NET XTUNNEL±äÌå¼°Æä¼ÓÔØ·¨Ê½¡£Óë´ÓǰµÄXTUNNELÑù±¾£¨³ÁÁ¿Îª1-2MB£©Ïà±È£¬ÕâЩ20KBµÄXTUNNELÑù±¾×ÔÉíËÆºõºÜÉÙ¡£long-standing Sofacy XTunnel´úÂë¿âÏòC££µÄת±äʹÎÒÃÇÏëÆðZebrocy³ÁбàÂëºÍʹÓöàÖÖ˵»°À´´´Ð³־ÃʹÓõÄÄ£¿éµÄ×ö·¨¡£
GamaredonÊÇÒ»¸ö³ÛÃûµÄAPT×éÖ¯£¬ÖÁÉÙ´Ó2013ÄêÆðÍ·»îÔ¾£¬¹¥»÷Ö¸±êÖØÒªÕë¶ÔÎÚ¿ËÀ¼¡£½ü¼¸¸öÔÂÀ´£¬ÎÒÃÇ·¢ÏÖÁËÒ»¸ö¹¥»÷»î¶¯£¬¹¥»÷Õßͨ¹ýÔ¶³ÌÄ£°å×¢Èë·¢ËͶñÒâÎĵµ£¬´Ó¶ø²¿Êð¶ñÒâ¼ÓÔØ·¨Ê½£¬¸Ã¼ÓÔØ·¨Ê½»á¶¨ÆÚÓëÔ¶³ÌC2ÁªÏµÒÔÏÂÔØÆäËûÑù±¾¡£Æ¾¾Ý֮ǰµÄ×êÑУ¬GamaredonµÄ¹¤¾ß°üÔ̺¬ºÜ¶à·ÖÆçµÄ¶ñÒâÈí¼þ£¬ÓÃÓÚʵÏÖ·ÖÆçµÄÖ¸±ê¡£ÆäÖÐÔ̺¬É¨ÃèÇý¶¯Æ÷ÖеÄÌØ¶¨ÏµÍ³Îļþ£¬²¶»ñÆÁÄ»¿ìÕÕ£¬Ö´ÐÐÔ¶³ÌºÅÁÏÂÔØÆäËûÎļþÒÔ¼°Ê¹ÓÃUltraVNCµÈ·¨Ê½ÖÎÀíÔ¶³ÌÍÆËã»ú¡£ÔÚÕâÖÖÇé¿öÏ£¬ÎÒÃǹ۲쵽һ¸öÓÐȤµÄеĵڶþ½×¶Îpayload£¬ÆäÓµÓд«²¼Ö°ÄÜ£¬ÎÒÃdzÆÖ®Îª¡°Aversome infector¡±¡£¸Ã¶ñÒâÈí¼þ¿ÉÔÚÖ¸±êÍøÂçÖÐά³ÖÓÆ¾ÃÐÔ£¬²¢Í¨¹ýºáÏòÒÆ¶¯Ï°È¾±í²¿Çý¶¯Æ÷ÉϵÄMicrosoft WordºÍExcelÎĵµ¡£
0x03 ÖÐÎÄÓÐ¹ØµÄ APT ×éÖ¯»î¶¯
CactusPeteÊÇÒ»¸öÓëÖÐÎÄÓйصÄÍøÂç¼äµý×éÖ¯£¬ÖÁÉÙ´Ó2012ÄêÆðÍ·»îÔ¾£¬ÆäÌØµãÊÇÓµÓÐÖеÈˮƽµÄ¼¼ÊõÄÜÁ¦¡£´Óº¹ÇàÉÏ¿´£¬¹¥»÷Ö¸±êÖØÒªÕë¶Ôº«¹ú£¬ÈÕ±¾£¬ÃÀ¹úºÍÖйų́ÍåµÈÉÙÊý¹ú¶È/µØÓòµÄ×éÖ¯¡£ÔÚ2019Äêµ×£¬¸Ã×éÖ¯ËÆºõתÏò¹Ø×¢ÃɹźͶíÂÞ˹£¬²¢Ê¹ÓÃÃɹÅÓï±àдÁËÒ»¸öµö¶ü¹¥»÷Îĵµ¿É¿ªÊÍFlapjackºóÃÅ£¨tmplogon.exe£¬ÖØÒªÕë¶ÔеĶíÂÞ˹ָ±ê£©¡£¿É¼û¸Ã×éÖ¯ÍØÕ¹Á˼¼ÊõÁìÓò£¬²¢ÇÒʹÓõÄ×ÊÔ´ºÍ²½ÖèÒ²²úÉúÁ˱䶯¡£
×Ô2018ÄêÒÔÀ´£¬RancorÊÇÒ»¸öÒѾ¹«¿ª±¨Â·µÄ×éÖ¯£¬ÓëDragonOKÓйØÁª¡£¹¥»÷Ö¸±êרһÓÚ¶«ÄÏÑÇ£¬¼´¼íÆÒÕ¯£¬Ô½ÄϺÍÐÂ¼ÓÆÂ¡£ÎÒÃǰÑÎȵ½¸Ã×éÖ¯ÔÚ´Óǰ¼¸¸öÔÂÖеĻÓм¸´¦¸üУ¬·¢ÏÖÁËDudell¶ñÒâÈí¼þµÄбäÖÖExDudell£¬ExDudellÄܹ»ÈƹýUAC£¨Óû§ÕÊ»§½ÚÔ죩²¢ÇÒÓÃÓÚ¹¥»÷µÄеĻù´¡¼Ü¹¹¡£³ý´ËÖ®±í£¬ÎÒÃÇ»¹È·¶¨ÁËÒÔǰͨ¹ýÓʼþ·¢Ë͵ijõʼµö¶üÎĵµ´Ë¿Ì¿ÉÔÚTelegram DesktopĿ¼ÖÐÕÒµ½£¬ÕâÅú×¢¸Ã×éÖ¯¿ÉÄÜÔÚŤתÆä³õʼͶµÝ·½Ê½¡£
ÔÚ2019Ä꣬ÎÒÃǼì²âµ½Ò»¸öδ֪×éÖ¯µÄ»î¶¯£¬ÆäʱÊÇÔÚ´ú±í²Ø×åÀûÒæµÄÍøÕ¾ÉϵÄË®¿Ó¹¥»÷»î¶¯£¬ºýŪÊܺ¦Õß×°ÖÃÔÚGitHub´æ´¢¿âÉÏÍйܵļÙAdobe Flash¸üС£¿¨°Í˹»ùͨ¹ýÓëGitHubºÏ×÷À´·ÀÓù¹¥»÷¡£Ã»¹ý¶à¾Ã£¬ÎÒÃÇÓÖ¼ì²âµ½ÐÂÒ»ÂÖË®¿Ó¹¥»÷¡£ÎÒÃǾö¶¨½«´Ë»î¶¯µÄ×éÖ¯¶¨ÃûΪ¡°Holy Water¡±¡£
×Ô³ÉÁ¢Ö®ÈÕÆð£¬¹¥»÷Õßµ¥Ò»¶ø¸»Óд´ÒâµÄ¹¤¾ß¾ÍÔÚ²»ÐÝ¿ª·¢ºÍ¸üÐÂÖУ¬²¢ÀûÓÃÁËSojson»ìºÏ£¬NSIS×°Ö÷¨Ê½£¬Python£¬¿ªÔ´´úÂ룬GitHub¿¯Ðа棬Go˵»°ÒÔ¼°Google DriveµÈ¼¼Êõ¼¿Á©¡£
0x04 Öж«µØÓòµÄ APT »î¶¯
ÎÒÃÇ×î½üÔÚ2020Äê2Ô¼ì²âµ½ÁËStrongPity×éÖ¯Õë¶ÔÍÁ¶úÆäµÄÊý¾Ýй¶»î¶¯¡£Ö»¹ÜStrongPityµÄTTPÔÚÖ¸±ê£¬»ù´¡ÉèÊ©ºÍϰȾý½é·½ÃæÃ»ÓÐŤת£¬µ«ÎÒÃǹ۲쵽ËûÃÇÊÔͼй¶µÄÎļþÓÐËù·ÖÆç¡£Ôڴ˻ÖУ¬StrongPity¸üÐÂÁË×îеÄÊðÃûºóÃÅ£¬ÃûΪStrongPity2£¬²¢Ôö³¤Á˸ü¶àÎļþÒÔÖ²ÈëÆä³£¼ûµÄOfficeºÍPDFÎĵµÁÐ±í£¬Ô̺¬ÓÃÓÚÏ£²®À´×°µãµÄDagesh Pro×Ö´¦ÖÃÆ÷Îļþ£¬ÓÃÓÚºÓµÀÁ÷Á¿ºÍÇÅÁº½¨Ä£µÄRiverCADÎļþ£¬´¿Îı¾Îļþ£¬¹éµµÎļþÒÔ¼°GPG¼ÓÃÜÎļþºÍPGPÃÜÔ¿¡£
3Ô£¬ÎÒÃÇ·¢ÏÖÁËWildPressure×éÖ¯Õë¶Ô¹¤ÒµÁìÓò·Ö·¢MilumľÂíµÄ»î¶¯£¬Ö¼ÔÚ¶ÔÖ¸±ê×éÖ¯ÖеÄÉ豸½øÐÐÔ¶³Ì½ÚÔì¡£¸Ã»î¶¯×î³õÄܹ»×·Òäµ½2019Äê8Ô¡£µ½Ä¿Ç°ÎªÖ¹£¬ÎÒÃÇ¿´µ½µÄMilumʾÀýÓëÈκÎÒÑÖªµÄAPT»î¶¯Ã»ÓÐÈκδúÂëÀàËÆÐÔ¡£¸Ã¶ñÒâÈí¼þʹ¹¥»÷ÕßÄܹ»Ô¶³Ì½ÚÔìÊÜϰȾµÄÉ豸£¬ÔÊÐíÏÂÔØºÍÖ´ÐкÅÁî£¬ÍøÂçºÍй¶ÐÅÏ¢ÒÔ¼°ÔÚ¶ñÒâÈí¼þÖÐ×°ÖÃÉý¼¶·¨Ê½¡£
ÔÚ2019Äê12ÔÂÏÂÑ®£¬¿¨°Í˹»ùThreat Attribution Engine¼ì²âµ½ZerocleareµÄбäÌåDustman£¬±»ÓÃÓÚÕë¶ÔÉ³ÌØ°¢À²®ÄÜÔ´²¿ÃŵĹ¥»÷¡£ÔÚ²Á³ýºÍ·Ö·¢·½Ã棬ËüÓëZerocleareÀàËÆ£¬µ«ÊDZäÁ¿ºÍ¼¼ÊõÃû³ÆµÄ±ä¶¯Åú×¢£¬Õâ¿ÉÄÜÒѾ³ï±¸ºÃÓ½ÓÕë¶Ô¶ñÒâÈí¼þµÄÐÂÒ»²¨¹¥»÷£¬ÕâЩ¹¥»÷»ùÓÚǶÈëÔÚ¶ñÒâÈí¼þÖеÄÐÂÎźʹ´½¨µÄ»¥³âÌ壬רÃÅÕë¶ÔÉ³ÌØ°¢À²®µÄÄÜÔ´²¿ÃÅ¡£Í¨¹ýËü¡£ÓйØDustmanµÄPDBÎļþÅú×¢£¬¸Ã·ÛËéÐÔ´úÂëÊÇ¿¯Ðа棬Äܹ»ÔÚÖ¸±êÍøÂçÖв¿Êð¡£ÕâЩ±ä¶¯Ç¡·êÐÂÄê¼ÙÆÚ£¬ÔÚ´ËÆÚ¼äºÜ¶àÔ±¹¤ÔÚÐݼ١£
0x05 ¶«ÄÏÑǺͳ¯Ïʰ뵺µÄAPT»î¶¯
Òâ´óÀû°²È«¹«Ë¾TelsyÔÚ2019Äê11Ô¸ÅÊöÁËLazarus×éÖ¯µÄ»î¶¯£¬Ê¹ÎÒÃÇ¿ÉÄܽ«Õë¶Ô¼ÓÃÜÇ®±ÒÒµÎñµÄÏÈǰ»î¶¯ÁªÏµÆðÀ´¡£Telsy²©¿ÍÉÏÌáµ½µÄ¶ñÒâÈí¼þÊǵÚÒ»½×¶ÎÏÂÔØ·¨Ê½£¬×Ô2018ÄêÖÐÒÔÀ´Ò»Ïò±»¹Û²ìµ½¡£ÎÒÃÇ·¢ÏÖµÚ¶þ½×¶Î¶ñÒâÈí¼þÊÇManuscryptµÄ±äÌ壬ËüÊÇLazarusµÄ¶ÀÓÐÊôÐÔ£¬Æä²¿ÊðÁËÁ½ÖÖÀàÐ͵Äpayload¡£µÚÒ»¸öÊǿɰѳֵÄUltra VNC·¨Ê½£¬µÚ¶þ¸öÊǶ༶ºóÃÅ·¨Ê½¡£ÕâÖÖÀàÐ͵Ķà½×¶ÎϰȾ¹ý³ÌÊÇLazarus×éÖ¯¶ñÒâÈí¼þµÄµäÐÍÌØµã£¬ÓÈÆäÊÇʹÓÃManuscrypt±äÌå¡£Ôڴ˻ÖУ¬Lazarus×éÖ¯¹¥»÷ÁËÈûÆÖ·˹£¬ÃÀ¹ú£¬Öйų́ÍåºÍÖйúÏã¸ÛµÄ¼ÓÃÜÇ®±ÒÒµÎñ£¬¸Ã»î¶¯Ò»Ïò³ÖÐøµ½2020ËêÊס£
×Ô2013ÄêÒÔÀ´ÎÒÃÇÒ»Ïò¸ú×ÙµÄ×éÖ¯KimsukyÔÚ2019ÄêÓÈÆä»îÔ¾¡£12Ô£¬Î¢Èí³·ÏúÁ˸Ã×é֯ʹÓõÄ50¸öÓò£¬²¢ÔÚ¸¥¼ªÄáÑÇÖÝ·¨Ôº¶Ô¹¥»÷ÕßÌáÆðÁËËßËÏ¡£µ«ÊÇ£¬¸ÃÓ××é³ÖÐø·¢Õ¹»î¶¯£¬Ã»ÓвúÉú³Á´ó±ä¶¯¡£ÎÒÃÇ×î½ü·¢ÏÖÁËÒ»¸öеĻ£¬ÆäÖÐʹÓÃÁËÒÔÐÂÄêÎʺòΪÖ÷ÌâµÄµö¶üͼƬ£¬¸ÃͼƬΪ¾ÉÏÂÔØ¹¤¾ßÌṩÁËеľ¹ý¸Ä½øµÄÏÂÒ»½×¶Îpayload£¬Ö¼ÔÚÀûÓÃеļÓÃܲ½ÖèÀ´ÇÔÊØÐÅÏ¢¡£
1Ôµף¬ÎÒÃÇ·¢ÏÖÁËÀûÓÃInternet Explorer·ì϶£¨CVE-2019-1367£©µÄ¶ñÒâ¾ç±¾¡£ÔÚ×Ðϸ²é³payload²¢·¢ÏÖÓëÏÈǰ»î¶¯µÄÁªÏµÖ®ºó£¬ÎÒÃǵóö½áÂÛ£¬DarkHotelÖ§³Ö´Ë»î¶¯£¬¸Ã»î¶¯¿ÉÄÜ×Ô2018ÄêÒÔÀ´Ò»ÏòÔÚ½øÐС£¸Ã»î¶¯¿´µ½DarkHotelÀûÓÿª·¢µÄÈí¼þʵÏÖÁ˶à½×¶Î¶þ½øÔìϰȾ¡£×î³õµÄϰȾ»á´´½¨Ò»¸öÏÂÔØ·¨Ê½£¬¸ÃÏÂÔØ·¨Ê½½«»ñÈ¡ÁíÒ»¸öÏÂÔØ·¨Ê½ÒÔÍøÂçϵͳÐÅÏ¢£¬²¢½öΪ¸ß¼ÛÖµÊܺ¦Õß»ñÈ¡×îÖյĺóÃÅ·¨Ê½¡£DarkHotelÔڴ˻ÖÐʹÓÃÁËTTPµÄ¹ÖÒì×éºÏ¡£ÍþвÕßʹÓø÷Àà»ù´¡½á¹¹À´ÍйܶñÒâÈí¼þ²¢½ÚÔìÊÜϰȾµÄÊܺ¦Õߣ¬Ô̺¬ÊÜϰȾµÄWeb·þÎñÆ÷£¬Ã³Ò×ÍйܷþÎñ£¬Ãâ·ÑÍйܷþÎñºÍÃâ·ÑÔ´´úÂë¸ú×Ùϵͳ¡£
3Ô£¬À´×ÔGoogleµÄ×êÑÐÈËԱй©£¬Ò»×éºÚ¿ÍÔÚ2019ÄêʹÓÃÁËÎå¸ö0day¹¥»÷Ö¸±êÕë¶Ô³¯ÏÊÈ˺ÍÒÔ³¯Ïʱ¨´ðÖÐÐĵÄרҵÈËÔ±¡£¸ÃÓ××éÀûÓÃInternet Explorer£¬ChromeºÍWindowsÖеķì϶À´½øÐÐÍøÂç´¹µöºÍ·Ö·¢µç×ÓÓʼþ£¬ÕâЩµç×ÓÓʼþÖÐÔ̺¬¶ñÒ⸽¼þ»òÓë¶ñÒâÁ´½ÓÒÔ¼°Ë®¿Ó¹¥»÷¡£ÎÒÃÇ¿ÉÄܽ«ÆäÖеÄÁ½¸ö·ì϶±ðÀëΪIEÖеÄÒ»¸ö·ì϶ºÍWindowsÖеÄÒ»¸ö·ì϶ÓëDarkHotel×é֯ƥÅäÉÏ¡£
FunnyDream×éÖ¯»î¶¯Ê¼ÓÚ2018ÄêÖУ¬Õë¶ÔÂíÀ´Î÷ÑÇ£¬Öйų́ÍåºÍ·ÆÂɱöµÄ³ÛÃû×éÖ¯£¬ÆäÖдóÎÞÊýÊܺ¦ÕßÀ´×ÔÔ½ÄÏ¡£·ÖÎöÅú×¢£¬ÕâÖ»ÊÇÒ»Ïî¸ü¿í·º¹¥»÷»î¶¯µÄÒ»²¿ÃÅ£¬¸Ã»î¶¯Äܹ»×·Òäµ½¼¸Äêǰ£¬²¢Õë¶Ô¶«ÄÏÑǹú¶ÈÈ·µ±¾Ö³ö¸ñÊDZí¹ú×éÖ¯¡£¹¥»÷ÕߵĺóÃÅ´ÓC2ÏÂÔØÎļþºÍÏòC2ÉÏ´«Îļþ£¬Ö´ÐкÅÁî²¢ÔÚÊܺ¦ÕßϵͳÖÐÔËÐÐйý³Ì¡£Ëü»¹ÍøÂçÓйØÍøÂçÉÏÆäËûÖ÷»úµÄÐÅÏ¢£¬²¢Í¨¹ýÔ¶³ÌÖ´ÐÐÀûÓ÷¨Ê½½«Æä´«µÝ¸øÐÂÖ÷»ú¡£¹¥»÷Õß»¹Ê¹ÓÃÁËRTLºóÃźÍChinoxyºóÃÅ¡£×Ô2018ÄêÄêÖÐÒÔÀ´£¬C2»ù´¡ÉèʩһÏò´¦ÓÚ»îԾ״̬£¬²¢ÇÒdomainsÓëFFRAT¶ñÒâÈí¼þ¼Ò×å³Áµþ¡£
Operation AppleJeusÊÇLazarus×îÓÐÓ°ÏìÁ¦µÄ»î¶¯Ö®Ò»£¬ÖØÒªÀûÓÃMacOS¶ñÒâÈí¼þ½øÐй¥»÷¡£1Ô·ݵĺóÐø×êÑнÒʾÁ˸Ã×éÖ¯¹¥»÷²½ÖèµÄ³Á´ó±ä¶¯£ºÐ¿ª·¢µÄmacOS¶ñÒâÈí¼þºÍÒ»ÖÖÉí·ÝÑéÖ¤»úÔ죬Äܹ»ÉóÉ÷µØ½»¸¶ÏÂÒ»½×¶ÎµÄpayload£¬ÒÔ¼°ÔÚ²»½Ó´¥´ÅÅ̵ÄÇé¿öϼÓÔØÏÂÒ»½×¶ÎµÄpayload¡£ÎªÁ˹¥»÷WindowsÊܺ¦Õߣ¬¸Ã×éÖ¯Ôì¶©ÁËÒ»¸ö¶à½×¶ÎϰȾ·¨Ê½²¢¸ü¸ÄÁË×îÖÕpayload¡£ÎÒÃÇÒÔΪ£¬×Ô´ÓAppleJeus»î¶¯ÒÔÀ´£¬LazarusÔÚ¹¥»÷·½ÃæÔ½·¢ÉóÉ÷£¬²¢²ÉÈ¡Á˶àÖÖ²½ÖèÀ´Ô¤·À±»·¢ÏÖ¡£ÎÒÃÇÔÚÓ¢¹ú£¬²¨À¼£¬¶íÂÞ˹ºÍÖйúÈ·¶¨Á˼¸ÃûÊܺ¦Õß¡£´Ë±í£¬ÎÒÃÇ¿ÉÄÜÈ·ÈÏһЩÊܺ¦ÕßÓë¼ÓÃÜÇ®±Ò×éÖ¯Óйء£
Roaming MantisÊÇÒ»¸ö³öÓÚ¾¼Ã¶¯»úµÄAPT×éÖ¯£¬ÓÚ2017Äê³õ´Î±¨Â·£¬Æäʱ¸Ã¹«Ë¾Ê¹ÓÃSMS½«Æä¶ñÒâÈí¼þ·Ö·¢¸øÎ»ÓÚº«¹úµÄAndroidÉ豸¡£ºóÀ´¸Ã×éÖ¯µÄ»î¶¯ÁìÓòÀ©´ó£¬Ö§³Ö27ÖÖ˵»°£¬ÒÔiOSºÍAndroidΪָ±ê£¬ÉõÖÁÍÚ¾ò¼ÓÃÜÇ®±Ò¡£¸Ã×éÖ¯»¹Ê¹ÓÃÁËеĶñÒâÈí¼þ¼Ò×壬Ô̺¬FakecopºÍWroba.j£¬²¢ÇÒÈÔÔÚʹÓá°SMiShing¡±½øÐÐAndroid¶ñÒâÈí¼þ·Ö·¢¡£ÔÚ×î½üµÄÒ»Ïî»î¶¯ÖУ¬Ëü·Ö·¢Á˼Ù×°³ÉÊÜӽӵĿìµÝ¹«Ë¾µÄ¶ñÒâAPK£¬ÖØÒªÕë¶ÔÈÕ±¾£¬Öйų́Í壬º«¹úºÍ¶íÂÞ˹¡£
0x06 ÆäËü
TransparentTribeÓÚ2019ËêÊׯðͷʹÓÃÃûΪUSBWormµÄÐÂÄ£¿é£¬²¢¶ÔÆäÃûΪCrimsonRATµÄ×Ô½ç˵.NET¹¤¾ß½øÐÐÁ˸Ľø¡£Æ¾¾ÝGA»Æ½ð¼×Ò£²â·¢ÏÖ£¬USBWorm±»ÓÃÀ´Ï°È¾³ÉǧÉÏÍòµÄÊܺ¦Õߣ¬ÆäÖдóÎÞÊýλÓÚ°¢¸»º¹ºÍÓ¡¶È£¬Ê¹¹¥»÷Õß¿ÉÄÜÏÂÔØºÍÖ´ÐÐËÁÒâÎļþ£¬´«²¼µ½¿ÉÒÆ¶¯É豸²¢´ÓÊÜϰȾµÄÖ÷»úÇÔÈ¡¸ÐÐËÖµÄÎļþ¡£ÕýÈçÎÒÃÇ֮ǰ±¨Â·µÄÄÇÑù£¬¸ÃÓ××éÖØÒª¹Ø×¢¾üÊÂÖ¸±ê£¬ÕâЩָ±êͨ³£Êܵ½OfficeÎĵµÖжñÒâVBAºÍPeppy RAT¡¢CrimsonRATµÈ¿ªÔ´¶ñÒâÈí¼þµÄ¹¥»÷¡£×î½üµÄлÖУ¬ÎÒÃǰÑÎȵ½¸ÃÓ××éµÄ³Áµã¸ü¶àµØ×ªÏòÁËÕë¶ÔÓ¡¶ÈÒÔ±íµÄ°¢¸»º¹¡£
ÔÚ2019ÄêµÄ×îºó¼¸¸öÔÂÖУ¬ÎÒÃǹ۲쵽ÁËFishing ElephantÔÚ½øÐеÄÒ»Ïî»î¶¯¡£¸ÃÓ××é³ÖÐøÊ¹ÓÃHerokuºÍDropboxÀ´½»¸¶ÆäÑ¡ÔñµÄ¹¤¾ßAresRAT¡£ÎÒÃÇ·¢ÏÖ£¬²Î¼ÓÕßÔÚÆä²Ù×÷µ±Ñ¡È¡ÁËÒ»Ïîм¼Êõ£¬¸Ã¼¼ÊõÖ¼ÔÚ×èÖ¹ÊÖ¶¯ºÍ×Ô¶¯·ÖÎögeo-fencingºÍ½«¿ÉÖ´ÐÐÎļþ°µ²ØÔÚÖ¤ÊéÎļþÖС£ÔÚGA»Æ½ð¼××êÑйý³ÌÖУ¬ÎÒÃÇ»¹·¢ÏÖÊܺ¦Õߵı䶯¿ÉÄÜ·´Ó³Á˹¥»÷ÕßÈ·µ±Ç°ÀûÒæ£¬¸Ã×éÖ¯µÄÖ¸±êÊÇÍÁ¶úÆä£¬°Í»ù˹̹£¬ÃϼÓÀ¹ú£¬ÎÚ¿ËÀ¼ºÍÖйúÈ·µ±¾ÖºÍ±í½»»ú¹¹¡£
0x07 ½áÓï
Ö»¹ÜÍþв¾ÖÊÆ²¢²»×ÜÊdzä³â¡°Í»ÆÆÐÔ¡±ÊÂÎñ£¬µ«µ±ÎÒÃǽ«ÑÛ¹âͶÏòAPTÍþвÐÐΪÕߵĻʱ£¬×ÜÊÇ»áÓÐÓÐȤµÄ·¢Õ¹¡£GA»Æ½ð¼×¶¨ÆÚ¼¾¶ÈÉó²éÖ¼ÔÚÇ¿µ÷¹Ø¼üµÄ·¢Õ¹¡£
ÕâЩÊǵ½Ä¿Ç°ÎªÖ¹ÎÒÃǽñÄêÒѾ¿´µ½µÄÒ»Ð©ÖØÒªÇ÷Ïò¡£
¡ñ µØÔµÕþÖÎÒÀÈ»ÊÇAPT»î¶¯µÄÖØÒªÖúÍÆÁ¦¡£
¡ñ LazarusºÍRoaming MantisµÄ»î¶¯Ö¤Ã÷£¬¾¼ÃÀûÒæÒÀÈ»ÊÇijЩ¹¥»÷Õߵ͝»ú¡£
¡ñ ¾ÍAPT»î¶¯¶øÑÔ£¬¶«ÄÏÑÇÊÇ×î»îÔ¾µÄµØÓò£¬Ô̺¬Lazarus£¬DarkHotelºÍKimsukyµÈ×éÖ¯£¬ÒÔ¼°Cloud SnooperºÍFishing ElephantµÈÐÂÐË×éÖ¯¡£
¡ñ APT×éÖ¯£¬ÀýÈçCactusPete£¬TwoSail Junk£¬FunnyDreamºÍDarkHotel£¬³ÖÐøÀûÓÃÈí¼þ·ì϶¡£
¡ñ APT×éÖ¯³ÖÐø½«mobile implantsÄÉÈëÆä±øÆ÷¿â¡£
¡ñ APT×éÖ¯£¨ÀýÈ絫²»ÏÞÓÚKimsuky£¬HadesºÍDarkHotel£©ÒÔ¼°»úÓöÖ÷Òå×ï·¸ÔÚÀûÓÃCOVID-19¡£
×ܶøÑÔÖ®£¬ÎÒÃÇ¿´µ½ÁËÑÇÖÞ¹¥»÷»î¶¯µÄ³ÖÐøÔö³¤£¬Ê¹ÓÃÒÆ¶¯Æ½Ì¨Ï°È¾ºÍ´«²¼¶ñÒâÈí¼þµÄÇ÷ÏòÔÚÉÏÉý¡£
Ŀǰ£¬COVID-19Êܵ½Ã¿Ó×ÎҵĹØ×¢£¬¶øAPT×éÖ¯Ò²Ò»ÏòÔÚ³¢ÊÔÔÚÓã²æÊ½ÍøÂç´¹µö»î¶¯ÖÐÀûÓÃÕâÒ»Ö÷Ìâ¡£ÎÒÃÇÒÔΪÕâ²¢²»´ú±íTTP²úÉúÁËÓÐÒâ˼µÄ±ä¶¯£ºËûÃÇÖ»Êǽ«ÆäÓÃ×÷ÓµÓÐÐÂÎżÛÖµµÄ»°ÌâÀ´ÎüÒýÊܺ¦Õß¡£µ«ÊÇ£¬ÎÒÃÇÔÚÇ×êǼල´óÊÆ¡£
0x08 ²Î¿¼Á´½Ó
https://securelist.com/apt-trends-report-q1-2020/96826/
0x09 ¹¦·òÏß
2020-05-01 VSRC°ä²¼»ã±¨


¾©¹«Íø°²±¸11010802024551ºÅ