¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190304
Ðû²¼Ê±¼ä 2019-03-04
ÔÎÄÁ´½Ó£º
https://cyware.com/news/apt-group-bronze-union-comes-up-with-upated-rat-malware-dd4ccb282¡¢Ð·¸·¨ÍÅ»ïPacha Group£¬£¬£¬£¬£¬£¬Ö÷Òª¹¥»÷LinuxЧÀÍÆ÷¾ÙÐÐÍÚ¿ó
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/linux-servers-targeted-by-new-chinese-crypto-mining-group/3¡¢Ð´¹ÂÚ¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬Ö÷ҪʹÓÃXLMºê·Ö·¢FlawedAmmyyľÂí

2019Äê2ÔÂSI-LAB²¶»ñÁ˶à¸ö´øÓжñÒâExcel 4.0ºê£¨Ò²³ÆXLMºê£©µÄExcel´¹ÂÚÑù±¾£¬£¬£¬£¬£¬£¬ÕâЩÑù±¾ÓÃÓÚÏÂÔØºÍÖ´ÐÐFlawedAmmyy RAT¡£¡£¡£¡£¸Ã´¹ÂÚ¹¥»÷±³ºóµÄ¹¥»÷ÕßÊÇ·¸·¨ÍÅ»ïTA505£¬£¬£¬£¬£¬£¬¹¥»÷ÕßµÄC&CЧÀÍÆ÷£¨195.123.209.169£©Î»ÓÚÀÍÑάÑÇ£¬£¬£¬£¬£¬£¬Ä¿½ñ´¦ÓÚÀëÏß״̬¡£¡£¡£¡£Æä·Ö·¢µÄFlawedAmmyy RAT¿ÉÇÔȡĿµÄµÄÎļþ¡¢Æ¾Ö¤¡¢ÆÁÄ»½ØÍ¼ÒÔ¼°»á¼ûÉãÏñÍ·ºÍÂó¿Ë·çµÈ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/81857/malware/flawedammyy-undetected-xlm-macros.html4¡¢Ñо¿Åú×¢Operation Sharpshooter¾ßÓиü¸ßµÄÖØÆ¯ºóºÍ¸ü¹ãµÄ¹æÄ£

McAfeeÑо¿Ö°Ô±ÔÚÒ»·Ýб¨¸æÖÐÖ¸³ö£¬£¬£¬£¬£¬£¬Operation SharpshooterµÄ¹¥»÷»î¶¯ÔÚÖØ´óÐÔ¡¢¹æÄ£ºÍ¹ã¶ÈÉϱÈ֮ǰÒÔΪµÄÒªÔ½·¢ÆÕ±é¡£¡£¡£¡£SharpshooterÓÚ2018Äê12ÔÂÊ״α»Åû¶£¬£¬£¬£¬£¬£¬ÆäÖ÷ÒªÕë¶ÔÈ«ÇòµÄ¹ú·ÀºÍÒªº¦»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬°üÀ¨ºËÄÜ¡¢¹ú·À¡¢ÄÜÔ´ºÍ½ðÈÚÆóÒµ¡£¡£¡£¡£ÐÂÑо¿Åú×¢£¬£¬£¬£¬£¬£¬Sharpshooter×îÔçÓÚ2017Äê9ÔÂ×îÏȻ£¬£¬£¬£¬£¬£¬Õë¶Ô¸ü¶àµÄ¹ú¼ÒºÍÐÐÒµ£¬£¬£¬£¬£¬£¬¸Ã»î¶¯ÏÖÔÚ»¹ÔÚ¾ÙÐÐÖ®ÖС£¡£¡£¡£Êܵ½¹¥»÷×î¶àµÄÄ¿µÄÊǵ¹ú¡¢ÍÁ¶úÆä¡¢Ó¢¹úºÍÃÀ¹ú¡£¡£¡£¡£¸Ã±¨¸æ»¹Ö¸³öSharpshooterÓëAPT×éÖ¯LazarusµÄ¹¥»÷¾ßÓжà¸öÏàËÆÌØÕ÷¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/sharpshooter-complexity-scope/142359/5¡¢ÀÕË÷Èí¼þGarrantyDecryptбäÖÖ£¬£¬£¬£¬£¬£¬Î±×°³ÉÇå¾²ÍŶӾÙÐÐÓÕÆ

2Ô·ÝÑо¿Ö°Ô±Michael Gillespie·¢Ã÷ÀÕË÷Èí¼þGarrantyDecryptµÄÒ»¸öбäÖÖ£¬£¬£¬£¬£¬£¬¸Ã±äÖÖ½ÓÄÉÁËÒ»ÖÖеÄÕ½ÂÔ¾ÙÐÐÓÕÆ£ºÔÚÃûΪSECURITY-ISSUE-INFO.txtµÄÀÕË÷Ʊ¾ÝÖУ¬£¬£¬£¬£¬£¬¹¥»÷ÕßÉù³ÆÄ¿µÄÓû§Ôâµ½¡°ÍⲿְԱ¡±µÄ¹¥»÷£¬£¬£¬£¬£¬£¬¶øProtonÇå¾²ÍŶӵÄSECURE-SERVERЧÀͶÔÓû§µÄÊý¾Ý¾ÙÐÐÁ˱£»£»£»¤ÐԵļÓÃÜ¡£¡£¡£¡£¹¥»÷ÕßÉõÖÁ½«PROTONµÄ°æÈ¨ÉùÃ÷°²ÅÅÔÚÎļþµ×²¿£¬£¬£¬£¬£¬£¬ÒÔÔöÌíÆäÕýµ±ÐÔ¡£¡£¡£¡£¹¥»÷Õß³ÆProtonµÄSECURE-SERVERЧÀÍÐèÒªÊÕÈ¡780ÃÀÔªµÄÓöȲŻª½âÃÜÎļþ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ransomware-pretends-to-be-proton-security-team-securing-data-from-hackers/6¡¢Ñо¿Ö°Ô±Åû¶Windows IoT Core×°±¸ÖеÄÎó²î£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂȨÏÞ±»Ð®ÖÆ
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/new-exploit-lets-attackers-take-control-of-windows-iot-core-devices/ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí