¶íÂÞ˹µçÐÅRostelecomÐ®ÖÆ¶à¸öÆóÒµµÄÁ÷Á¿£»£» £»Î¢ÈíÐû²¼Emotet¹¥»÷°¸Àý±¨¸æ

Ðû²¼Ê±¼ä 2020-04-07

1.DarkHotelʹÓÃÉîÐÅ·þVPNÎó²î¹¥»÷ÎÒ¹úµÄÕþ¸®»ú¹¹


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¿ËÈÕ£¬£¬£¬£¬ÓÐÐÂÎųƺڿÍ×éÖ¯Darkhotel£¨APT-C-06£©Ê¹ÓÃÉîÐÅ·þSSL VPN×°±¸Îó²î¹¥»÷ÎÒ¹úµÄÕþ¸®»ú¹¹¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯Ê¼ÓÚ3Ô£¬£¬£¬£¬ÓÐÁè¼Ý200̨VPNЧÀÍÆ÷Ôâµ½¹¥»÷£¬£¬£¬£¬ÆäÖÐ174̨λÓÚ±±¾©ºÍÉϺ£µÄÕþ¸®»ú¹¹ÍøÂçÒÔ¼°²¿·ÖÖйúפÍâ»ú¹¹£¬£¬£¬£¬4Ô³õ¹¥»÷Ì¬ÊÆÓÖÔÙÏò±±¾©¡¢ÉϺ£Ïà¹ØÕþ¸®»ú¹¹ÉìÕÅ¡£¡£¡£¡£¡£¡£¡£ÉîÐÅ·þ¹Ù·½ÒÑÓÚ4ÔÂ6ÈÕÕýʽÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬²¢Æô¶¯Îó²îÏìÓ¦¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇ4ÔÂ3ÈÕ360ÏòÉîÐÅ·þÓ¦¼±Çå¾²ÏìÓ¦ÖÐÐı¨¸æµÄÎó²î£¨SRC-2020-281£©£¬£¬£¬£¬ÎªSSL VPN×°±¸Windows¿Í»§¶ËÉý¼¶Ä£¿£¿£¿éÊðÃûÑéÖ¤»úÖÆµÄȱÏÝ£¬£¬£¬£¬µ«¸ÃÎó²îʹÓÃÌõ¼þÊDZØÐèÒѾ­»ñÈ¡¿ØÖÆSSL VPN×°±¸µÄȨÏÞ£¬£¬£¬£¬Òò´ËʹÓÃÄѶȽϸß¡£¡£¡£¡£¡£¡£¡£ÉîÐÅ·þÈ·ÈÏÔËÐй̼þ°æ±¾M6.3R1ºÍM6.1µÄSSL VPN×°±¸Ò×Êܹ¥»÷£¬£¬£¬£¬½¨ÒéÓû§¾ÙÐÐÅŲéºÍÓ¦Óò¹¶¡¸üС£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/darkhotel-hackers-use-vpn-zero-day-to-compromise-chinese-government-agencies/


2.¶íÂÞ˹µçÐŹ«Ë¾RostelecomÐ®ÖÆ¶à¸öÆóÒµµÄ»¥ÁªÍøÁ÷Á¿


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


4ÔÂ1ÈÕ¶íÂÞ˹µçÐŹ«Ë¾RostelecomÐ®ÖÆÁ˹ȸèµÈ¹«Ë¾µÄ»¥ÁªÍøÁ÷Á¿£¬£¬£¬£¬¸ÃÊÂÎñÓ°ÏìÁËÌìÏÂÉÏ×î´óµÄ200¶à¸öCDNÍøÂç¼°ÔÆÍйÜЧÀÍÉÌ£¬£¬£¬£¬Ò»Á¬ÁËԼĪ1¸öСʱ¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÆóÒµ°üÀ¨¹È¸è¡¢ÑÇÂíÑ·¡¢Facebook¡¢Akamai¡¢Cloudflare¡¢GoDaddy¡¢Digital Ocean¡¢Joyent¡¢LeaseWeb¡¢HetznerºÍLinodeµÈ×ÅÃû¹«Ë¾¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»´Îµä·¶µÄBGPÐ®ÖÆÊÂÎñ£¬£¬£¬£¬¸ÃÊÂÎñµÄÔµ¹ÊÔ­ÓÉ¿ÉÄÜÊÇRostelecomµÄÄÚ²¿Á÷Á¿ÐÞÕýϵͳ¹ýʧµØ½«²»×¼È·µÄBGP·ÓÉ̻¶ÔÚ¹«ÍøÉÏ£¬£¬£¬£¬²¢ÇÒ±»ÉÏÓι©Ó¦É̹㲥Ôì³ÉµÄ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/russian-telco-hijacks-internet-traffic-for-google-aws-cloudflare-and-others/


3.΢ÈíÐû²¼Emotet¹¥»÷Fabrikam¹«Ë¾µÄ°¸ÀýÑо¿±¨¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


΢ÈíÔÚ¼ì²âºÍÏìӦС×飨DART£©°¸Àý±¨¸æ002ÖзÖÏíÁËFabrikam¹«Ë¾ÔâÊÜEmotet¹¥»÷µÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ʼÓÚÍøÂç´¹ÂÚÓʼþ£¬£¬£¬£¬µ±ÄÚ²¿Ô±¹¤»á¼ûÁË´¹ÂÚÐÅÏ¢ºó£¬£¬£¬£¬EmotetѬȾÁËÆäϵͳ²¢ºáÏòѬȾÁËÍ³Ò»ÍøÂçÖÐµÄÆäËüϵͳ¡£¡£¡£¡£¡£¡£¡£¸Ã²¡¶¾×èÖ¹ÁËͨ¹ýÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷£¨C2£©¾ÙÐа´ÆÚ¸üжø±»·À²¡¶¾½â¾ö¼Æ»®¼ì²âµ½µÄÇéÐΣ¬£¬£¬£¬²¢ÇÒͨ¹ýʹWindowsÉè±¹ØÁ¬ÄCPUʹÓÃÂʵִﱥºÍÀ´×èÖ¹½¹µãЧÀÍ£¬£¬£¬£¬µ¼Ö¸Ã×éÖ¯µÄ»ù±¾Ð§ÀͺÍÍøÂçÖÐÖ¹ÁË¿ìÒªÒ»ÖܵÄʱ¼ä¡£¡£¡£¡£¡£¡£¡£CPUʹÓÃÂÊÒ»Ö±±¥ºÍʹµÃÅÌËã»ú¹ýÈÈ£¬£¬£¬£¬µ¼ÖÂÄÚ²¿ÏµÍ³¿¨ËÀ¡¢ÖØÆôºÍÍøÂçÅþÁ¬Ï½µ¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýÇÔÈ¡ÖÎÀíÔ±ÕÊ»§Æ¾Ö¤¾ÙÐкáÏòÒÆ¶¯£¬£¬£¬£¬ÔÚ×î³õѬȾºóµÄ8ÌìÖ®ÄÚ£¬£¬£¬£¬FabrikamµÄÕû¸öÍøÂç¾Í±»¹Ø±ÕÁË¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/security/blog/wp-content/uploads/2020/04/Case-study_Full-Operational-Shutdown.pdf


4.PayPalºÍVenmoÓû§½»Á÷Õ½ÂÔÎó²îµ¼ÖºڿÍÐ®ÖÆÓû§


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÆÕÁÖ˹¶Ù´óѧµÄÑо¿Ö°Ô±·¢Ã÷17¼ÒÖ÷Òª¹«Ë¾£¬£¬£¬£¬ÆäÖаüÀ¨Amazon¡¢Paypal¡¢Venmo¡¢Blizzard¡¢Adobe¡¢eBay¡¢SnapchatºÍYahoo£¬£¬£¬£¬ÔÊÐíÓû§Í¨¹ý·¢Ë͵½ÓëËûÃÇÕÊ»§Ïà¹ØÁªµÄµç»°ºÅÂëµÄ¶ÌÐÅÀ´ÖØÖÃÃÜÂ룬£¬£¬£¬ÕâÒâζ×ÅÈôÊǺڿÍͨ¹ýSIM½»Á÷¹¥»÷¿ØÖÆÁËÊܺ¦ÕßµÄÊÖ»úºÅÂ룬£¬£¬£¬ÄÇôºÚ¿Í¾Í¿ÉÒÔʹÓÃÕâÐ©ÍøÕ¾ºÍЧÀÍÈëÇÖÊܺ¦ÕßµÄÔÚÏßÕÊ»§¡£¡£¡£¡£¡£¡£¡£ÔÚ½Óµ½Ñо¿Ö°Ô±µÄÖÒÑÔÖ®ºó£¬£¬£¬£¬°üÀ¨Adobe¡¢±©Ñ©¡¢Ebay¡¢Î¢ÈíºÍSnapchatÔÚÄÚµÄһЩ¹«Ë¾ÐÞ¸´ÁËÕâÒ»ÎÊÌ⣬£¬£¬£¬µ«ÈÔÓÐһЩ¹«Ë¾Ã»ÓÐÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬ÀýÈçÔÊÐíÓû§¾ÙÐÐÉúÒâ²¢ÇÒÓëÒøÐÐÕÊ»§»òÐÅÓÿ¨¹ØÁªµÄÓ¦ÓóÌÐòPaypalºÍVenmo¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¼Ò¹«Ë¾ÉÐδ¾Í´Ë½ÒÏþ̸ÂÛ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.vice.com/en_us/article/pke9zk/paypal-and-venmo-are-letting-sim-swappers-hijack-accounts


5.AppleÐÞ¸´SafariÖжà¸öÎó²î£¬£¬£¬£¬¿É±»ºÚ¿Í¿ØÖÆÉãÏñÍ·


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ö°Ô±Ryan PickrenÔÚSafariÖз¢Ã÷ÁË7¸ö0day£¬£¬£¬£¬°üÀ¨CVE-2020-3852¡¢CVE-2020-3864¡¢CVE-2020-3865¡¢CVE-2020-3885¡¢CVE-2020-3887£¬£¬£¬£¬CVE-2020-9784ºÍCVE-2020-9787¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÆäÖеÄ3¸öÎó²î×éºÏ£¬£¬£¬£¬»á¼ûiOSºÍmacOSÉè±¹ØÁ¬ÄÉãÏñÍ·ºÍÂó¿Ë·ç²¢¼àÊÓÓû§¡£¡£¡£¡£¡£¡£¡£Õâ3¸öÎó²îÓëSafariÆÊÎöURI¡¢ÖÎÀíWebÔ´ÒÔ¼°³õʼ»¯Çå¾²ÉÏÏÂÎĵķ½·¨ÓйØ£¬£¬£¬£¬¿ÉÔÊÐí¶ñÒâÍøÕ¾ÔÚSafariÉÏαװ³ÉÊÜÐÅÈεÄÍøÕ¾Ìᳫ¹¥»÷¡£¡£¡£¡£¡£¡£¡£AppleÔÚ1ÔÂ28ÈÕÐû²¼µÄSafari 13.0.5ÖÐÐÞ²¹ÁËÕâ3¸öÎó²î£¬£¬£¬£¬²¢ÔÚ3ÔÂ24ÈÕÐû²¼µÄSafari 13.1ÖÐÐÞ¸´ÁËÆäÓàÎó²î¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/vulnerabilities---threats/researcher-hijacks-ios-macos-camera-with-three-safari-zero-days/d/d-id/1337486


6.EuropolÓëInterpolÐû²¼ÓëCOVID-19Ïà¹ØµÄÍøÂç·¸·¨×ª´ï


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Å·ÖÞÐ̾¯×éÖ¯£¨Europol£©ÔÚ×îеÄÇå¾²×ÉѯÖÐÏêϸÏÈÈÝÁËCOVID-19ÓйصÄÍøÂç·¸·¨»î¶¯£¬£¬£¬£¬ÁгöÁË´ÙʹÓëCOVIDÓйصÄÍøÂç·¸·¨»î¶¯×ª±äµÄÁù¸öÒòËØ£º¶ÔijЩÉÌÆ·¡¢·À»¤×°±¸ºÍÒ©Æ·µÄ¸ßÐèÇ󣻣» £»¹«ÃñÔ½À´Ô½ÒÀÀµÊý×Ö½â¾ö¼Æ»®¾ÙÐÐÔ¶³Ì°ì¹«£»£» £»½¹ÂǺͿ־åÐÄÀí£»£» £»ÊÕÖ§Å·Ã˵ÄÖ°Ô±Á÷¶¯ïÔÌ­£»£» £»¹«¹²³¡ºÏ»î¶¯ÊÜÏÞ£¬£¬£¬£¬Ê¹Ò»Ð©·¸·¨»î¶¯×ªÒƵּÒÍ¥»òÔÚÏßÇéÐΣ»£» £»Å·ÃËijЩ²»·¨ÉÌÆ·µÄ¹©Ó¦ïÔÌ­¡£¡£¡£¡£¡£¡£¡£Óë´Ëͬʱ£¬£¬£¬£¬¹ú¼ÊÐ̾¯×éÖ¯£¨Interpol£©ÖÒÑÔÀÕË÷Èí¼þ¹¥»÷ÒѾ­×îÏÈÕë¶ÔÒ½ÔºµÈÓëCOVID-19ÓÐ¹ØµÄÆäËü»ú¹¹¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.europol.europa.eu/publications-documents/catching-virus-cybercrime-disinformation-and-covid-19-pandemic