¶íÂÞ˹µçÐÅRostelecomÐ®ÖÆ¶à¸öÆóÒµµÄÁ÷Á¿£»£»£»£»£»Î¢ÈíÐû²¼Emotet¹¥»÷°¸Àý±¨¸æ

Ðû²¼Ê±¼ä 2020-04-07

1.DarkHotelʹÓÃÉîÐÅ·þVPNÎó²î¹¥»÷ÎÒ¹úµÄÕþ¸®»ú¹¹


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¿ËÈÕ£¬£¬£¬£¬£¬£¬ÓÐÐÂÎųƺڿÍ×éÖ¯Darkhotel£¨APT-C-06£©Ê¹ÓÃÉîÐÅ·þSSL VPN×°±¸Îó²î¹¥»÷ÎÒ¹úµÄÕþ¸®»ú¹¹¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯Ê¼ÓÚ3Ô£¬£¬£¬£¬£¬£¬ÓÐÁè¼Ý200̨VPNЧÀÍÆ÷Ôâµ½¹¥»÷£¬£¬£¬£¬£¬£¬ÆäÖÐ174̨λÓÚ±±¾©ºÍÉϺ£µÄÕþ¸®»ú¹¹ÍøÂçÒÔ¼°²¿·ÖÖйúפÍâ»ú¹¹£¬£¬£¬£¬£¬£¬4Ô³õ¹¥»÷Ì¬ÊÆÓÖÔÙÏò±±¾©¡¢ÉϺ£Ïà¹ØÕþ¸®»ú¹¹ÉìÕÅ¡£¡£¡£¡£¡£¡£ÉîÐÅ·þ¹Ù·½ÒÑÓÚ4ÔÂ6ÈÕÕýʽÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬²¢Æô¶¯Îó²îÏìÓ¦¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇ4ÔÂ3ÈÕ360ÏòÉîÐÅ·þÓ¦¼±Çå¾²ÏìÓ¦ÖÐÐı¨¸æµÄÎó²î£¨SRC-2020-281£©£¬£¬£¬£¬£¬£¬ÎªSSL VPN×°±¸Windows¿Í»§¶ËÉý¼¶Ä£¿£¿£¿£¿éÊðÃûÑéÖ¤»úÖÆµÄȱÏÝ£¬£¬£¬£¬£¬£¬µ«¸ÃÎó²îʹÓÃÌõ¼þÊDZØÐèÒѾ­»ñÈ¡¿ØÖÆSSL VPN×°±¸µÄȨÏÞ£¬£¬£¬£¬£¬£¬Òò´ËʹÓÃÄѶȽϸߡ£¡£¡£¡£¡£¡£ÉîÐÅ·þÈ·ÈÏÔËÐй̼þ°æ±¾M6.3R1ºÍM6.1µÄSSL VPN×°±¸Ò×Êܹ¥»÷£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾ÙÐÐÅŲéºÍÓ¦Óò¹¶¡¸üС£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/darkhotel-hackers-use-vpn-zero-day-to-compromise-chinese-government-agencies/


2.¶íÂÞ˹µçÐŹ«Ë¾RostelecomÐ®ÖÆ¶à¸öÆóÒµµÄ»¥ÁªÍøÁ÷Á¿


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


4ÔÂ1ÈÕ¶íÂÞ˹µçÐŹ«Ë¾RostelecomÐ®ÖÆÁ˹ȸèµÈ¹«Ë¾µÄ»¥ÁªÍøÁ÷Á¿£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÓ°ÏìÁËÌìÏÂÉÏ×î´óµÄ200¶à¸öCDNÍøÂç¼°ÔÆÍйÜЧÀÍÉÌ£¬£¬£¬£¬£¬£¬Ò»Á¬ÁËԼĪ1¸öСʱ¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÆóÒµ°üÀ¨¹È¸è¡¢ÑÇÂíÑ·¡¢Facebook¡¢Akamai¡¢Cloudflare¡¢GoDaddy¡¢Digital Ocean¡¢Joyent¡¢LeaseWeb¡¢HetznerºÍLinodeµÈ×ÅÃû¹«Ë¾¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»´Îµä·¶µÄBGPÐ®ÖÆÊÂÎñ£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñµÄÔµ¹ÊÔ­ÓÉ¿ÉÄÜÊÇRostelecomµÄÄÚ²¿Á÷Á¿ÐÞÕýϵͳ¹ýʧµØ½«²»×¼È·µÄBGP·ÓÉ̻¶ÔÚ¹«ÍøÉÏ£¬£¬£¬£¬£¬£¬²¢ÇÒ±»ÉÏÓι©Ó¦É̹㲥Ôì³ÉµÄ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/russian-telco-hijacks-internet-traffic-for-google-aws-cloudflare-and-others/


3.΢ÈíÐû²¼Emotet¹¥»÷Fabrikam¹«Ë¾µÄ°¸ÀýÑо¿±¨¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


΢ÈíÔÚ¼ì²âºÍÏìӦС×飨DART£©°¸Àý±¨¸æ002ÖзÖÏíÁËFabrikam¹«Ë¾ÔâÊÜEmotet¹¥»÷µÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ʼÓÚÍøÂç´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬µ±ÄÚ²¿Ô±¹¤»á¼ûÁË´¹ÂÚÐÅÏ¢ºó£¬£¬£¬£¬£¬£¬EmotetѬȾÁËÆäϵͳ²¢ºáÏòѬȾÁËÍ³Ò»ÍøÂçÖÐµÄÆäËüϵͳ¡£¡£¡£¡£¡£¡£¸Ã²¡¶¾×èÖ¹ÁËͨ¹ýÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷£¨C2£©¾ÙÐа´ÆÚ¸üжø±»·À²¡¶¾½â¾ö¼Æ»®¼ì²âµ½µÄÇéÐΣ¬£¬£¬£¬£¬£¬²¢ÇÒͨ¹ýʹWindowsÉè±¹ØÁ¬ÄCPUʹÓÃÂʵִﱥºÍÀ´×èÖ¹½¹µãЧÀÍ£¬£¬£¬£¬£¬£¬µ¼Ö¸Ã×éÖ¯µÄ»ù±¾Ð§ÀͺÍÍøÂçÖÐÖ¹ÁË¿ìÒªÒ»ÖܵÄʱ¼ä¡£¡£¡£¡£¡£¡£CPUʹÓÃÂÊÒ»Ö±±¥ºÍʹµÃÅÌËã»ú¹ýÈÈ£¬£¬£¬£¬£¬£¬µ¼ÖÂÄÚ²¿ÏµÍ³¿¨ËÀ¡¢ÖØÆôºÍÍøÂçÅþÁ¬Ï½µ¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýÇÔÈ¡ÖÎÀíÔ±ÕÊ»§Æ¾Ö¤¾ÙÐкáÏòÒÆ¶¯£¬£¬£¬£¬£¬£¬ÔÚ×î³õѬȾºóµÄ8ÌìÖ®ÄÚ£¬£¬£¬£¬£¬£¬FabrikamµÄÕû¸öÍøÂç¾Í±»¹Ø±ÕÁË¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/security/blog/wp-content/uploads/2020/04/Case-study_Full-Operational-Shutdown.pdf


4.PayPalºÍVenmoÓû§½»Á÷Õ½ÂÔÎó²îµ¼ÖºڿÍÐ®ÖÆÓû§


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÆÕÁÖ˹¶Ù´óѧµÄÑо¿Ö°Ô±·¢Ã÷17¼ÒÖ÷Òª¹«Ë¾£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Amazon¡¢Paypal¡¢Venmo¡¢Blizzard¡¢Adobe¡¢eBay¡¢SnapchatºÍYahoo£¬£¬£¬£¬£¬£¬ÔÊÐíÓû§Í¨¹ý·¢Ë͵½ÓëËûÃÇÕÊ»§Ïà¹ØÁªµÄµç»°ºÅÂëµÄ¶ÌÐÅÀ´ÖØÖÃÃÜÂ룬£¬£¬£¬£¬£¬ÕâÒâζ×ÅÈôÊǺڿÍͨ¹ýSIM½»Á÷¹¥»÷¿ØÖÆÁËÊܺ¦ÕßµÄÊÖ»úºÅÂ룬£¬£¬£¬£¬£¬ÄÇôºÚ¿Í¾Í¿ÉÒÔʹÓÃÕâÐ©ÍøÕ¾ºÍЧÀÍÈëÇÖÊܺ¦ÕßµÄÔÚÏßÕÊ»§¡£¡£¡£¡£¡£¡£ÔÚ½Óµ½Ñо¿Ö°Ô±µÄÖÒÑÔÖ®ºó£¬£¬£¬£¬£¬£¬°üÀ¨Adobe¡¢±©Ñ©¡¢Ebay¡¢Î¢ÈíºÍSnapchatÔÚÄÚµÄһЩ¹«Ë¾ÐÞ¸´ÁËÕâÒ»ÎÊÌ⣬£¬£¬£¬£¬£¬µ«ÈÔÓÐһЩ¹«Ë¾Ã»ÓÐÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬£¬ÀýÈçÔÊÐíÓû§¾ÙÐÐÉúÒâ²¢ÇÒÓëÒøÐÐÕÊ»§»òÐÅÓÿ¨¹ØÁªµÄÓ¦ÓóÌÐòPaypalºÍVenmo¡£¡£¡£¡£¡£¡£ÕâÁ½¼Ò¹«Ë¾ÉÐδ¾Í´Ë½ÒÏþ̸ÂÛ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.vice.com/en_us/article/pke9zk/paypal-and-venmo-are-letting-sim-swappers-hijack-accounts


5.AppleÐÞ¸´SafariÖжà¸öÎó²î£¬£¬£¬£¬£¬£¬¿É±»ºÚ¿Í¿ØÖÆÉãÏñÍ·


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ö°Ô±Ryan PickrenÔÚSafariÖз¢Ã÷ÁË7¸ö0day£¬£¬£¬£¬£¬£¬°üÀ¨CVE-2020-3852¡¢CVE-2020-3864¡¢CVE-2020-3865¡¢CVE-2020-3885¡¢CVE-2020-3887£¬£¬£¬£¬£¬£¬CVE-2020-9784ºÍCVE-2020-9787¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÆäÖеÄ3¸öÎó²î×éºÏ£¬£¬£¬£¬£¬£¬»á¼ûiOSºÍmacOSÉè±¹ØÁ¬ÄÉãÏñÍ·ºÍÂó¿Ë·ç²¢¼àÊÓÓû§¡£¡£¡£¡£¡£¡£Õâ3¸öÎó²îÓëSafariÆÊÎöURI¡¢ÖÎÀíWebÔ´ÒÔ¼°³õʼ»¯Çå¾²ÉÏÏÂÎĵķ½·¨ÓйØ£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¶ñÒâÍøÕ¾ÔÚSafariÉÏαװ³ÉÊÜÐÅÈεÄÍøÕ¾Ìᳫ¹¥»÷¡£¡£¡£¡£¡£¡£AppleÔÚ1ÔÂ28ÈÕÐû²¼µÄSafari 13.0.5ÖÐÐÞ²¹ÁËÕâ3¸öÎó²î£¬£¬£¬£¬£¬£¬²¢ÔÚ3ÔÂ24ÈÕÐû²¼µÄSafari 13.1ÖÐÐÞ¸´ÁËÆäÓàÎó²î¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/vulnerabilities---threats/researcher-hijacks-ios-macos-camera-with-three-safari-zero-days/d/d-id/1337486


6.EuropolÓëInterpolÐû²¼ÓëCOVID-19Ïà¹ØµÄÍøÂç·¸·¨×ª´ï


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Å·ÖÞÐ̾¯×éÖ¯£¨Europol£©ÔÚ×îеÄÇå¾²×ÉѯÖÐÏêϸÏÈÈÝÁËCOVID-19ÓйصÄÍøÂç·¸·¨»î¶¯£¬£¬£¬£¬£¬£¬ÁгöÁË´ÙʹÓëCOVIDÓйصÄÍøÂç·¸·¨»î¶¯×ª±äµÄÁù¸öÒòËØ£º¶ÔijЩÉÌÆ·¡¢·À»¤×°±¸ºÍÒ©Æ·µÄ¸ßÐèÇ󣻣»£»£»£»¹«ÃñÔ½À´Ô½ÒÀÀµÊý×Ö½â¾ö¼Æ»®¾ÙÐÐÔ¶³Ì°ì¹«£»£»£»£»£»½¹ÂǺͿ־åÐÄÀí£»£»£»£»£»ÊÕÖ§Å·Ã˵ÄÖ°Ô±Á÷¶¯ïÔÌ­£»£»£»£»£»¹«¹²³¡ºÏ»î¶¯ÊÜÏÞ£¬£¬£¬£¬£¬£¬Ê¹Ò»Ð©·¸·¨»î¶¯×ªÒƵּÒÍ¥»òÔÚÏßÇéÐΣ»£»£»£»£»Å·ÃËijЩ²»·¨ÉÌÆ·µÄ¹©Ó¦ïÔÌ­¡£¡£¡£¡£¡£¡£Óë´Ëͬʱ£¬£¬£¬£¬£¬£¬¹ú¼ÊÐ̾¯×éÖ¯£¨Interpol£©ÖÒÑÔÀÕË÷Èí¼þ¹¥»÷ÒѾ­×îÏÈÕë¶ÔÒ½ÔºµÈÓëCOVID-19ÓÐ¹ØµÄÆäËü»ú¹¹¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.europol.europa.eu/publications-documents/catching-virus-cybercrime-disinformation-and-covid-19-pandemic