NCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ£»£»£»ÐµÄAndroidľÂíBanker.BRʹÓÃÁýÕÖ¹¥»÷Ãé×¼ÒøÐÐÖ÷¹Ë
Ðû²¼Ê±¼ä 2020-04-221.CNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ
¹ú¼Ò»¥ÁªÍøÓ¦¼±ÖÐÐÄ£¨CNCERT£©ÓÚ2020Äê4ÔÂ20ÈÕÐû²¼ÁË¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ¡£¡£¡£¡£¸Ã±¨¸æ×¤×ãÓÚCNCERTÍøÂçÇå¾²ºê¹Û¼à²âÊý¾ÝÓëÊÂÇéʵ¼ù±¨¸æ£¬£¬£¬£¬£¬£¬£¬Éæ¼°2019Äêµä·¶ÍøÂçÇå¾²ÊÂÎñ¡¢ÍøÂçÇå¾²ÐÂÇ÷ÊÆ¼°Ò»Ñùƽ³£ÍøÂçÇå¾²ÊÂÎñÓ¦¼±´¦Öóͷ£Êµ¼ùµÈÄÚÈÝ¡£¡£¡£¡£±¨¸æÖ÷Òª°üÀ¨Ëĸö²¿·Ö£¬£¬£¬£¬£¬£¬£¬Ò»ÊÇ×ܽá2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇ徲״̬£¬£¬£¬£¬£¬£¬£¬¶þÊÇÕ¹Íû2020ÄêÍøÂçÇå¾²ÈÈÃÅ£¬£¬£¬£¬£¬£¬£¬ÈýÊÇÁ¬ÏµÍøÂçÇå¾²Ì¬ÊÆÆÊÎöÌá³ö¶Ô²ß½¨Ò飬£¬£¬£¬£¬£¬£¬ËÄÊÇÊáÀíÍøÂçÇå¾²¼à²âÊý¾Ý¡£¡£¡£¡£¸Ã±¨¸æ¶ÔÎÒ¹úµ³Õþ»ú¹Ø¡¢ÐÐÒµÆóÒµ¼°È«Éç»áÏàʶÎÒ¹úÍøÂçÇå¾²ÐÎÊÆ£¬£¬£¬£¬£¬£¬£¬Ìá¸ßÍøÂçÇå¾²Òâʶ£¬£¬£¬£¬£¬£¬£¬×öºÃÍøÂçÇå¾²ÊÂÇéÌṩÁËÓÐÁ¦²Î¿¼¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2020-04/20/c_1588932297982643.htm
2.Winnti groupÕë¶ÔµÂ¹ú»¯¹¤¹«Ë¾¹¥»÷Ñù±¾µÄÆÊÎö±¨¸æ
1Ô·ÝQuoIntelligence£¨QuoINT£©¼ì²âµ½Ò»¸öеÄWinntiÑù±¾²¢¶ÔÆä¾ÙÐÐÁËÆðÔ´µÄÆÊÎö¡£¡£¡£¡£ÆÊÎö·¢Ã÷£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ¿ÉÄÜÊÇÔÚ2015Äê±»¿ª·¢³öÀ´µÄ¡£¡£¡£¡£¸ÃÑù±¾±»ÓÃÓÚ¹¥»÷Ò»¼ÒµÂ¹ú»¯¹¤¹«Ë¾£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎú¸Ã¹«Ë¾µÄÏêϸÃû³Æ¡£¡£¡£¡£¸ÃÑù±¾½ÓÄÉÁËеÄC2ÊÖÒÕ£¬£¬£¬£¬£¬£¬£¬ÒÀÀµÓÚͨ¹ýiodineÔ´´úÂëʵÏÖµÄDNSËíµÀ¾ÙÐÐͨѶ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹·¢Ã÷ÁËÒ»¸öÒÔǰδ֪µÄ±»µÁÊý×ÖÖ¤Ê飬£¬£¬£¬£¬£¬£¬¸ÃÖ¤ÊéÖ÷ÒªÓÃÀ´¶ÔWinntiÏà¹ØµÄÇý¶¯³ÌÐò¾ÙÐÐÊý×ÖÊðÃû£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÓÃÓÚ¹¥»÷º«¹úÓÎÏ·¹«Ë¾Gravity¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://quointelligence.eu/2020/04/winnti-group-insights-from-the-past/
3.½©Ê¬ÍøÂçMootbotʹÓÃ0day¹¥»÷9¿î¹âÏË·ÓÉÆ÷
Ñо¿Ö°Ô±·¢Ã÷×Ô2ÔÂÏÂÑ®Æð£¬£¬£¬£¬£¬£¬£¬½©Ê¬ÍøÂçMootbot±ã×îÏÈʹÓÃ0day¹¥»÷9¿î¼ÒÓü°ÉÌÓùâÏË·ÓÉÆ÷£¨°üÀ¨Netlink GPON·ÓÉÆ÷£©¡£¡£¡£¡£MoobotÊÇ»ùÓÚMiraiµÄн©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬£¬ÆäÄ¿µÄÊÇÎïÁªÍø£¨IoT£©×°±¸¡£¡£¡£¡£ÓÉÓÚ´ó´ó¶¼¹©Ó¦É̺ܿÉÄÜÊǽÓÄÉÁËͳһÔʼ¹©Ó¦É̵ÄOEM²úÆ·£¬£¬£¬£¬£¬£¬£¬Òò´ËÕâЩ·ÓÉÆ÷ÊÜͳһ0dayÓ°Ïì¡£¡£¡£¡£¸ÃÎó²îΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäPoCÒѾÐû²¼£¬£¬£¬£¬£¬£¬£¬µ¥¶ÀʹÓøÃÎó²î²»»áÔì³ÉΣº¦£¬£¬£¬£¬£¬£¬£¬Ö»ÓÐÓëÁíÒ»¸öÎó²îÒ»ÆðʹÓòŻªÊµÏÖ¹¥»÷¡£¡£¡£¡£Ñо¿Ö°Ô±Ã»ÓÐÅû¶µÚ¶þ¸öÎó²îµÄÏêϸÐÅÏ¢¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/mootbot-fiber-routers-zero-days/154962/
4.ProofpointÖÒÑÔʹÓÃÊÓÆµ¾Û»á¹«Ë¾µÄ´¹ÂÚ¹¥»÷³ÊÔöÌíÇ÷ÊÆ
ProofpointÑо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬£¬ÒÔÊÓÆµ¾Û»á¹«Ë¾ÎªÖ÷ÌâµÄÍøÂç´¹ÂÚ¹¥»÷ÊýÄ¿³ÊÔöÌíÇ÷ÊÆ£¬£¬£¬£¬£¬£¬£¬ÕâЩ¹¥»÷Ö¼ÔÚÇÔÈ¡Óû§µÇ¼ƾ֤ºÍÈö²¥¶ñÒâÈí¼þ¡£¡£¡£¡£ProofpointÖÒÑԳƣ¬£¬£¬£¬£¬£¬£¬ºÚ¿Í²»»áÖ±½Ó¹¥»÷ÕâЩÊÓÆµ¾Û»áÈí¼þ£¬£¬£¬£¬£¬£¬£¬¿ÉÊÇ»áÒÔÊÓÆµ¾Û»á¹«Ë¾µÄÃû³ÆÎªÓÕ¶üÇÔÈ¡Óû§ÕÊ»§Æ¾Ö¤ºÍÈö²¥¶ñÒâÈí¼þ¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷µÄ´¹ÂÚ³¡¾°°üÀ¨£ºÎ±ÔìCisco WebExµÄÖÒÑÔÓʼþÀ´ÇÔÈ¡ÃÀ¹úÓû§µÄÕË»§ÐÅÏ¢£»£»£»Ã°³äZoom AccountÇÔÈ¡ÃÀ¹úÄÜÔ´¡¢ÖÆÔìºÍÉÌÒµµÈÐÐÒµµÄÓû§Æ¾Ö¤£»£»£»ÒÔ"zoom call"ΪÖ÷ÌâÈö²¥ServLoaderºÍNetSupport RATµÈ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.proofpoint.com/us/threat-insight/post/remote-video-conferencing-themes-credential-theft-and-malware-threats
5.FoxitÐÞ¸´PDF Reader¼°PhantomPDFÖеĶà¸öÎó²î
FoxitÐÞ¸´ÁËWindows°æ±¾µÄFoxit ReaderºÍFoxit PhantomPDFÖеÄ20¸öCVEÎó²î¡£¡£¡£¡£Ê×ÏÈ£¬£¬£¬£¬£¬£¬£¬FoxitÔÚPDF Reader 9.7.2°æ±¾ÖÐÐÞ¸´Á˶à¸öRCEÎó²î£¬£¬£¬£¬£¬£¬£¬°üÀ¨XFAÄ£°å´¦Öóͷ£Àú³ÌÖеÄRCEÎó²î£¨CVE-2020-10899¡¢ CVE-2020-10907£©£¬£¬£¬£¬£¬£¬£¬AcroFormsÖеÄRCEÎó²î£¨CVE-2020-10900£©ÒÔ¼°resetFormÖеÄRCEÎó²î£¨CVE-2020-10906£©¡£¡£¡£¡£¹ØÓÚPhantomPDF£¬£¬£¬£¬£¬£¬£¬´Ë´Î¸üÐÂÐÞ¸´ÁËAPIͨѶÖеÄÁ½¸öÒ×±»Ê¹ÓõÄí§ÒâÎļþдÈëÎó²î£¨CVE-2020-10890ºÍCVE-2020-10892£©£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Á½¸öÓйØSetFieldValueÏÂÁî´¦Öóͷ£µÄ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-10912ºÍCVE-2020-10912£©¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬´Ë´Î¸üл¹ÐÞ¸´ÁËU3DBrowser²å¼þÖеÄ11¸öÎó²î¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/foxit-pdf-reader-phantompdf-remote-code-execution/154942/
6.еÄAndroidľÂíBanker.BRʹÓÃÆÁÄ»ÁýÕÖ¹¥»÷Ãé×¼ÒøÐпͻ§
IBM X-ForceÑо¿Ö°Ô±·¢Ã÷еÄAndroidľÂíBanker.BR£¬£¬£¬£¬£¬£¬£¬ÆäʹÓÃÆÁÄ»ÁýÕÖ¹¥»÷Õë¶ÔʹÓÃÎ÷°àÑÀÓï»òÆÏÌÑÑÀÓ°üÀ¨Î÷°àÑÀ¡¢ÆÏÌÑÑÀ¡¢°ÍÎ÷ºÍÀ¶¡ÃÀÖÞÆäËûµØÇø£©µÄÒøÐпͻ§£¬£¬£¬£¬£¬£¬£¬ÍýÏëÇÔÈ¡Óû§Æ¾Ö¤²¢ÍµÈ¡ÆäÕË»§¡£¡£¡£¡£Ñо¿·¢Ã÷£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þµÄÔçÆÚ°æ±¾½ö¾ßÓлù±¾µÄSMSÇÔÈ¡¹¦Ð§£¬£¬£¬£¬£¬£¬£¬¿ÉÊÇBanker.BR¸üΪϸÄ壬£¬£¬£¬£¬£¬£¬¾ßÓÐÁýÕÖ¹¥»÷µÄ¹¦Ð§²¢ÇÒÓÐȫеĴúÂ룬£¬£¬£¬£¬£¬£¬²»ÒÀÀµÓÚÏÈǰ×ß©µÄ´úÂë»òÏÖÓеÄÒÆ¶¯¶ñÒâÈí¼þ¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýÓÕʹÓû§ÏÂÔØÃ°³äµÄÒøÐÐÇå¾²Ó¦ÓóÌÐò¾ÙÐÐÈö²¥£¬£¬£¬£¬£¬£¬£¬µÈÓû§ÀÖ³É×°Öúó±ã»áÇÔÈ¡Óû§×°±¸ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬°üÀ¨µç»°ºÅÂë¡¢¹ú¼ÊÒÆ¶¯×°±¸Ê¶±ðÂ루IMEI£©¡¢¹ú¼ÊÒÆ¶¯Óû§Ê¶±ðÂ루IMSI£©ºÍSIMÐòÁкţ¬£¬£¬£¬£¬£¬£¬²¢½«ÐÅÏ¢·¢Ë͸øC2ЧÀÍÆ÷¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÒÀÈ»ÔÚ¿ª·¢ÖС£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/android-banking-br-trojan-credential-stealing/154990/