APT×éÖ¯BlackTechÀûÓÃFlagpro¹¥»÷ÈÕ±¾µÄ¹«Ë¾

°ä²¼¹¦·ò 2021-12-30

APT×éÖ¯BlackTechÀûÓÃFlagpro¹¥»÷ÈÕ±¾µÄ¹«Ë¾


APT×éÖ¯BlackTechÀûÓÃFlagpro¹¥»÷ÈÕ±¾µÄ¹«Ë¾.png


¾ÝýÌå12ÔÂ28ÈÕ±¨Â· £¬¼äµýAPT×éÖ¯BlackTechÀûÓÃFlagpro¹¥»÷ÈÕ±¾µÄ¹«Ë¾¡£Õâ´Î¹¥»÷µÄ³õʼϰȾý½éÊǼÙ×°³ÉÀ´×ÔÖ¸±êºÏ×÷ͬ°éµÄ´¹µöÓʼþ £¬Ö®ºó¹¥»÷Õß»áÀûÓÃFlagpro½øÐÐÍøÂç¿úËÅ¡¢ÆÀ¹ÀÖ¸±ê»·¾³ÒÔ¼°ÏÂÔØ²¢Ö´Ðеڶþ½×¶Î¶ñÒâÈí¼þ¡£¾ÝNTT Security³Æ £¬Õâ´Î»î¶¯ÖÁÉÙʼÓÚ2020Äê10Ô £¬ÒÑÕë¶ÔÈÕ±¾¹«Ë¾Ò»Äê¶à £¬Éæ¼°¹ú·À¼¼Êõ¡¢Ã½ÌåºÍͨѶÐÐÒµÔÚÄڵĶà¸öÁìÓò¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-flagpro-malware-linked-to-chinese-state-backed-hackers/


Morphus Labs·¢ÏÖ¶à¸öÀûÓÃMSBuildµÄ¹¥»÷»î¶¯


Morphus Labs·¢ÏÖ¶à¸öÀûÓÃMSBuildµÄ¹¥»÷»î¶¯.png


12ÔÂ27ÈÕ £¬Morphus LabsºÍSANS ISC°ä²¼»ã±¨³Æ £¬ÔÚ´ÓǰһÖÜÖмì²âµ½2¸öÀûÓÃMicrosoft Build Engine(MSBuild)µÄ¹¥»÷»î¶¯¡£ÔÚÕâЩ»î¶¯ÖÐ £¬¹¥»÷Õßͨ³£ÏÈÀûÓÃÔ¶³Ì×ÀÃæºÍ̸(RDP)ÕÊ»§½Ó¼ûÖ¸±ê»·¾³ £¬¶øºóÀûÓÃÔ¶³ÌWindows·þÎñ(SCM)½øÐкáÏòÒÆ¶¯ £¬×îºóÀûÓÃMSBuildÖ´ÐÐCobalt Strike Beacon¡£¹¥»÷ÖÐʹÓõĶñÒâMSBuildÏîÄ¿Äܹ»±àÒëºÍÖ´ÐÐÌØ¶¨µÄC#´úÂë £¬½ø¶ø½âÂëºÍÖ´ÐÐCobalt Strike¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/threat-actors-abuse-msbuild-cobalt-strike-beacon-execution


T-MobileÒòÔâµ½SIM»¥»»¹¥»÷ £¬Óû§ÐÅÏ¢ÔÙ´Îй¶


T-MobileÒòÔâµ½SIM»¥»»¹¥»÷£¬Óû§ÐÅÏ¢ÔÙ´Îй¶.png


12ÔÂ29ÈÕ £¬T-Mobile½²»°ÈË֤ʵÆä²¿ÃÅÓû§Ôâµ½SIM»¥»»¹¥»÷ £¬ÐÅÏ¢¿ÉÄÜÒѾ­Ð¹Â¶¡£T-Mobile³ÆÆäÍŶÓÔÚ·¢ÏÖÎÊÌâºóÁ¢¿Ì²ÉȡӦ¼±´ëÊ© £¬²¢ÒÑ×Ô¶¯²ÉÈ¡¶î±íµÄ±£»¤´ëÊ©¡£µ±±»ÒªÇóÌṩÓйØÊÜÓ°ÏìÓû§ÊýÁ¿ÒÔ¼°¹¥»÷ÕߵĹ¥»÷·½Ê½Ê± £¬T-Mobile»Ø¾øÌṩ¸ü¶à¾ßÌåÐÅÏ¢¡£T-MobileÒѲúÉúÂÅ´ÎÐÅϢй¶ £¬Õâ´ÎÊÂÎñÓë½ñÄê2Ô·ݵÄй¶ÊÂÎñ¼«¶ÈÀàËÆ £¬ÆäʱÒòSIM»¥»»¹¥»÷й¶400¸öÓû§µÄÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/t-mobile-says-new-data-breach-caused-by-sim-swap-attacks/


Galaxy Store´æÔÚ¶à¸öαÔì³ÉShowBoxµÄ¶ñÒâÀûÓÃ


Galaxy Store´æÔÚ¶à¸öαÔì³ÉShowBoxµÄ¶ñÒâÀûÓÃ.png


ýÌå12ÔÂ28ÈÕ³Æ £¬ÈýÐǵĹٷ½AndroidÀûÓ÷¨Ê½É̵êGalaxy Store´æÔÚ¶à¸ö¶ñÒâÀûÓá£ÕâЩÀûÓüÙ×°³ÉÒÑÓÚ2018ÄêÆÆ²úµÄµÁ°æÀûÓÃShowBox £¬ÒÑÔÚ¶à¸öÓû§µÄÉ豸ÉÏ´¥·¢Google Play Protect¾¯±¨¡£×êÑÐÈËÔ±³Æ £¬ÕâЩÀûÓÃÖ®ËùÒԻᴥ·¢¾¯±¨ £¬ÊÇÓÉÓÚËüÃÇÒªÇóÓµÓÐ×°ÖöñÒâÈí¼þ·çÏÕµÄȨÏÞ £¬µ±Óû§ÔÊÐíºóËüÃǾÍÄܹ»½Ó¼ûÁªÏµÈËÁбíºÍͨ»°¼Í¼¡¢Ö´ÐдúÂë¡¢»ñÈ¡¶ñÒâÈí¼þpayloadµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/riskware-android-streaming-apps-found-on-samsungs-galaxy-store/


ÃÀ¹úSLGAÔÚ×ÅÊÖµ÷²éÆäÊ¥µ®½ÚÆÚ¼äÔâµ½µÄÍøÂç¹¥»÷


ÃÀ¹úSLGAÔÚ×ÅÊÖµ÷²éÆäÊ¥µ®½ÚÆÚ¼äÔâµ½µÄÍøÂç¹¥»÷.png


¾ÝýÌå12ÔÂ28ÈÕ±¨Â· £¬ÈøË¹¿¦³¹ÎÂÊ¡¾ÆÀàºÍ²©²ÊÖÎÀí¾Ö£¨SLGA£©ÔÚ×ÅÊÖµ÷²éÆäÔâµ½µÄÍøÂç¹¥»÷¡£SLGAÊÇÃÀ¹ú²ÆÕþ²¿»Ê¹Ú¹«Ë¾ÕƹܷÖÏú¡¢½ÚÔìºÍ¼à¹Ü¾Æ¾«ÒûÁÏ¡¢´óÂéºÍ´óÎÞÊý´ò¶ÄµÄ»ú¹¹ £¬Î»ÓÚ¼ÓÄôóµÄÈøË¹¿¦³¹ÎÂÊ¡¡£¹¥»÷²úÉúÔÚ12ÔÂ25ÈÕ £¬SLGA°µÊ¾ £¬µ÷²éÏÔʾĿǰûÓÐÈκοͻ§¡¢Ô±¹¤»òÆäËüÊý¾Ý±»ÀÄÓà £¬ÔÚʵÏÖ¶Ô¸ÃÊÂÎñµÄÆÀ¹Àºó £¬½«Á¢¼´±ãÊÜÓ°ÏìµÄϵͳ³ÁÐÂÉÏÏß¡£


Ô­ÎÄÁ´½Ó£º

https://globalnews.ca/news/8477174/slga-investigating-christmas-day-cybersecurity-incident/


×êÑÐÍŶÓÅû¶EquationʹÓõÄDanderSpritzµÄ¼¼Êõ·ÖÎö


×êÑÐÍŶÓÅû¶EquationʹÓõÄDanderSpritzµÄ¼¼Êõ·ÖÎö.png


12ÔÂ27ÈÕ £¬Check PointÅû¶Equation GroupʹÓõÄȫְÄܶñÒâÈí¼þ¿ò¼ÜDanderSpritzµÄ¼¼Êõ·ÖÎö¡£DanderSpritzÓÚ2017Äê4ÔÂ14ÈÕ±»Shadow Brokers¹«¿ª £¬Ô̺¬ÓÃÓÚÓÆ¾ÃÐÔ¡¢¿úËÅ¡¢ºáÏòÒÆ¶¯¡¢Èƹýɱ¶¾ÒýÇæµÈ»î¶¯µÄ¶àÖÖ¹¤¾ß¡£¸Ã×êÑгÁµã·ÖÎöÆäÖеÄÒ»¸ö×é¼þDoubleFeature £¬ËüÓÃÀ´ÌìÉú¿É×°ÖÃÔÚÖ¸±êÉ豸ÖеŤ¾ßÀàÐ͵ÄÈÕÖ¾ºÍ»ã±¨ £¬²¢»áÍøÂç´óÁ¿¸÷ÖÖÀàÐ͵ÄÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://research.checkpoint.com/2021/a-deep-dive-into-doublefeature-equation-groups-post-exploitation-dashboard/