¿¨°Í˹»ù | 2020ÄêQ1 APTÇ÷ÊÆ±¨¸æ
Ðû²¼Ê±¼ä 2020-05-01¿¨°Í˹»ùÐû²¼2020ÄêµÚÒ»¼¾¶ÈµÄAPT×éÖ¯»î¶¯µÄÇ÷ÊÆ±¨¸æ£¬£¬£¬Ö÷Ҫ˵Ã÷ÖØ´óµÄAPT»î¶¯ÒÔ¼°Ñо¿·¢Ã÷¡£¡£¡£¡£¡£
0x00 COVID-19 APT»î¶¯
×ÔÌìÏÂÎÀÉú×éÖ¯£¨WHO£©Ðû²¼COVID-19³ÉΪÎÁÒßÒÔÀ´£¬£¬£¬ÕâÒ»»°ÌâÒÑÊܵ½²î±ð¹¥»÷ÕßÔ½À´Ô½¶àµÄ¹Ø×¢¡£¡£¡£¡£¡£Ðí¶àÍøÂç´¹ÂÚթƶ¼ÊÇÓÉÍøÂç·¸·¨·Ö×ÓÌᳫµÄ£¬£¬£¬ËûÃÇÊÔͼʹÓÃÈËÃǶԲ¡¶¾µÄ¿Ö¾åÀ´×¬Ç®¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬¹¥»÷ÕßÁбíÖл¹°üÀ¨APT×éÖ¯£¬£¬£¬ÀýÈçKimsuky£¬£¬£¬APT27£¬£¬£¬Lazarus»òViciousPanda£¬£¬£¬Æ¾Ö¤OSINT£¬£¬£¬ËûÃÇÒÔCOVID-19×÷ΪÓÕ¶üÃé×¼Êܺ¦Õß¡£¡£¡£¡£¡£ÎÒÃÇ×î½ü·¢Ã÷ÁË¿ÉÒɵĻù´¡ÉèÊ©¿ÉÓÃÓÚÕë¶Ô°üÀ¨WHOÔÚÄÚµÄÎÀÉúºÍÈËÐÔÖ÷Òå×éÖ¯¡£¡£¡£¡£¡£¾ÝһЩ˽ÈËÐÂÎÅȪԴ³Æ£¬£¬£¬Ö»¹Ü»ù´¡ÉèÊ©ÏÖÔÚÎÞ·¨¹éÒòÓÚÈκÎÌØ¶¨µÄ×éÖ¯£¬£¬£¬²¢ÇÒÒÑÔÚ2019Äê6ÔÂCOVID-19Σ»£»£»£»£»£»ú֮ǰע²á£¬£¬£¬µ«Ëü¿ÉÄÜÓëDarkHotelÓйء£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬ÎÒÃÇÏÖÔÚÎÞ·¨È·ÈÏ´ËÐÅÏ¢¡£¡£¡£¡£¡£ÓÐȤµÄÊÇ£¬£¬£¬Ò»Ð©×é֯ʹÓÃÄ¿½ñÇéÐÎÀ´Ðû²¼ËûÃÇÔÚΣ»£»£»£»£»£»úʱ´ú²»»áÕë¶ÔÎÀÉú×éÖ¯¡£¡£¡£¡£¡£
0x01 ×îÖµµÃ×¢ÖØµÄÇ÷ÊÆ
2020Äê1Ô£¬£¬£¬ÎÒÃÇ·¢Ã÷Ò»¸öË®¿Ó¹¥»÷ʹÓÃÍêÈ«µÄÔ¶³ÌiOSÎó²î¡£¡£¡£¡£¡£Õâ¸öÍøÕ¾µÄÄ¿µÄÊÇÆ¾Ö¤Ä¿µÄÍøÒ³µÄÄÚÈÝÀ´¶¨Î»ÖйúÏã¸ÛµÄÓû§¡£¡£¡£¡£¡£ËäȻĿ½ñÕýÔÚʹÓõÄÎó²îʹÓóÌÐòÊÇÒÑÖªµÄ£¬£¬£¬µ«ÈÏÕæÖ°Ô±ÕýÔÚÆð¾¢ÐÞ¸ÄÎó²îʹÓù¤¾ß°ü£¬£¬£¬ÒÔÕë¶Ô¸ü¶àµÄiOS°æ±¾ºÍ×°±¸¡£¡£¡£¡£¡£ÎÒÃÇÔÚ2ÔÂ7ÈÕÊӲ쵽ÁË×îеİ汾¡£¡£¡£¡£¡£¸ÃÏîÄ¿±ÈÎÒÃÇ×î³õÏëÏóµÄÒªÆÕ±é£¬£¬£¬ËüÖ§³ÖAndroidÖ²È룬£¬£¬²¢ÇÒ¿ÉÄÜÖ§³ÖWindows£¬£¬£¬LinuxºÍMacOSµÄÖ²Èë¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬ÎÒÃǽ«´ËAPT×éÖ¯³ÆÎªTwoSail Junk¡£¡£¡£¡£¡£ÎÒÃÇÒÔΪÕâÊÇÒ»ÆäÖÐÎÄ×éÖ¯£¬£¬£¬ËüÖ÷ÒªÔÚÖйúÏã¸Ûά»¤»ù´¡ÉèÊ©£¬£¬£¬²¢ÔÚÐÂ¼ÓÆÂºÍÉϺ£ÉèÓм¸¸öÖ÷»ú¡£¡£¡£¡£¡£TwoSail Junkͨ¹ýÔÚÂÛ̳Ðû²¼Á´½Ó»ò½¨Éè×Ô¼ºµÄÐÂÖ÷ÌâÀ´½«»á¼ûÕßÖ¸µ¼ÖÁÆäʹÓÃÕ¾µã¡£¡£¡£¡£¡£ÖÁ½ñ£¬£¬£¬¼Í¼ÁËÀ´×ÔÖйúÏã¸ÛµÄÊýÊ®´Î»á¼û£¬£¬£¬ÆäÖÐÒ»¶ÔÀ´×ÔÖйú°ÄÃÅ¡£¡£¡£¡£¡£
0x02 ¶íÓïÏà¹ØµÄAPT×éÖ¯»î¶¯
1Ô£¬£¬£¬ÔÚÒ»¼Ò¶«Å·µçÐŹ«Ë¾Öз¢Ã÷Á˼¸¸ö×î½ü±àÒëµÄSPLM/XAgentÄ£¿£¿£¿£¿é¡£¡£¡£¡£¡£×î³õµÄ½øÈëµãÊÇδ֪µÄ£¬£¬£¬ËüÃÇÔÚ¸Ã×éÖ¯ÄڵĺáÏòÔ˶¯Ò²ÊÇδ֪µÄ¡£¡£¡£¡£¡£ÓëÒÑÍùµÄSofacy»î¶¯Ë®Æ½Ïà±È£¬£¬£¬ÏÕЩÎÞ·¨Ê¶±ðSPLMѬȾ£¬£¬£¬Òò´ËËÆºõ¸Ã¹«Ë¾ÄÚÍø¿ÉÄÜÒѾѬȾÁËÒ»¶Îʱ¼ä¡£¡£¡£¡£¡£³ýÁËÕâЩSPLMÄ£¿£¿£¿£¿éÖ®Í⣬£¬£¬Sofacy»¹°²ÅÅÁË.NET XTUNNEL±äÌå¼°Æä¼ÓÔØ³ÌÐò¡£¡£¡£¡£¡£ÓëÒÑÍùµÄXTUNNELÑù±¾£¨ÖØÁ¿Îª1-2MB£©Ïà±È£¬£¬£¬ÕâЩ20KBµÄXTUNNELÑù±¾×Ô¼ºËƺõºÜÉÙ¡£¡£¡£¡£¡£long-standing Sofacy XTunnel´úÂë¿âÏòC££µÄת±äʹÎÒÃÇÏëÆðZebrocyÖØÐ±àÂëºÍʹÓöàÖÖÓïÑÔÀ´Á¢Òìºã¾ÃʹÓõÄÄ£¿£¿£¿£¿éµÄ×ö·¨¡£¡£¡£¡£¡£
GamaredonÊÇÒ»¸ö×ÅÃûµÄAPT×éÖ¯£¬£¬£¬ÖÁÉÙ´Ó2013Äê×îÏÈ»îÔ¾£¬£¬£¬¹¥»÷Ä¿µÄÖ÷ÒªÕë¶ÔÎÚ¿ËÀ¼¡£¡£¡£¡£¡£½ü¼¸¸öÔÂÀ´£¬£¬£¬ÎÒÃÇ·¢Ã÷ÁËÒ»¸ö¹¥»÷»î¶¯£¬£¬£¬¹¥»÷Õßͨ¹ýÔ¶³ÌÄ£°å×¢Èë·¢ËͶñÒâÎĵµ£¬£¬£¬´Ó¶ø°²ÅŶñÒâ¼ÓÔØ³ÌÐò£¬£¬£¬¸Ã¼ÓÔØ³ÌÐò»á°´ÆÚÓëÔ¶³ÌC2ÁªÏµÒÔÏÂÔØÆäËûÑù±¾¡£¡£¡£¡£¡£Æ¾Ö¤Ö®Ç°µÄÑо¿£¬£¬£¬GamaredonµÄ¹¤¾ß°ü°üÀ¨Ðí¶à²î±ðµÄ¶ñÒâÈí¼þ£¬£¬£¬ÓÃÓÚʵÏÖ²î±ðµÄÄ¿µÄ¡£¡£¡£¡£¡£ÆäÖаüÀ¨É¨ÃèÇý¶¯Æ÷ÖеÄÌØ¶¨ÏµÍ³Îļþ£¬£¬£¬²¶»ñÆÁÄ»¿ìÕÕ£¬£¬£¬Ö´ÐÐÔ¶³ÌÏÂÁ£¬£¬ÏÂÔØÆäËûÎļþÒÔ¼°Ê¹ÓÃUltraVNCµÈ³ÌÐòÖÎÀíÔ¶³ÌÅÌËã»ú¡£¡£¡£¡£¡£ÔÚÕâÖÖÇéÐÎÏ£¬£¬£¬ÎÒÃÇÊӲ쵽һ¸öÓÐȤµÄеĵڶþ½×¶Îpayload£¬£¬£¬Æä¾ßÓÐÈö²¥¹¦Ð§£¬£¬£¬ÎÒÃdzÆÖ®Îª¡°Aversome infector¡±¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¿ÉÔÚÄ¿µÄÍøÂçÖмá³Ö³¤ÆÚÐÔ£¬£¬£¬²¢Í¨¹ýºáÏòÒÆ¶¯Ñ¬È¾ÍⲿÇý¶¯Æ÷ÉϵÄMicrosoft WordºÍExcelÎĵµ¡£¡£¡£¡£¡£
0x03 ÖÐÎÄÏà¹ØµÄ APT ×éÖ¯»î¶¯
CactusPeteÊÇÒ»¸öÓëÖÐÎÄÏà¹ØµÄÍøÂçÌØ¹¤×éÖ¯£¬£¬£¬ÖÁÉÙ´Ó2012Äê×îÏÈ»îÔ¾£¬£¬£¬ÆäÌØÕ÷ÊǾßÓÐÖеÈˮƽµÄÊÖÒÕÄÜÁ¦¡£¡£¡£¡£¡£´ÓÀúÊ·ÉÏ¿´£¬£¬£¬¹¥»÷Ä¿µÄÖ÷ÒªÕë¶Ôº«¹ú£¬£¬£¬ÈÕ±¾£¬£¬£¬ÃÀ¹úºÍÖйų́ÍåµÈÉÙÊý¹ú¼Ò/µØÇøµÄ×éÖ¯¡£¡£¡£¡£¡£ÔÚ2019Äêµ×£¬£¬£¬¸Ã×éÖ¯ËÆºõתÏò¹Ø×¢ÃɹźͶíÂÞ˹£¬£¬£¬²¢Ê¹ÓÃÃɹÅÓï±àдÁËÒ»¸öÓÕ¶ü¹¥»÷Îĵµ¿ÉÊÍ·ÅFlapjackºóÃÅ£¨tmplogon.exe£¬£¬£¬Ö÷ÒªÕë¶ÔеĶíÂÞ˹ĿµÄ£©¡£¡£¡£¡£¡£¿£¿£¿£¿É¼û¸Ã×éÖ¯ÍØÕ¹ÁËÊÖÒÕ¹æÄ££¬£¬£¬²¢ÇÒʹÓõÄ×ÊÔ´ºÍÒªÁìÒ²±¬·¢ÁËת±ä¡£¡£¡£¡£¡£
×Ô2018ÄêÒÔÀ´£¬£¬£¬RancorÊÇÒ»¸öÒѾ¹ûÕæ±¨µÀµÄ×éÖ¯£¬£¬£¬ÓëDragonOKÓйØÁª¡£¡£¡£¡£¡£¹¥»÷Ä¿µÄרעÓÚ¶«ÄÏÑÇ£¬£¬£¬¼´¼íÆÒÕ¯£¬£¬£¬Ô½ÄϺÍÐÂ¼ÓÆÂ¡£¡£¡£¡£¡£ÎÒÃÇ×¢ÖØµ½¸Ã×éÖ¯ÔÚÒÑÍù¼¸¸öÔÂÖеĻÓм¸´¦¸üУ¬£¬£¬·¢Ã÷ÁËDudell¶ñÒâÈí¼þµÄбäÖÖExDudell£¬£¬£¬ExDudell¿ÉÒÔÈÆ¹ýUAC£¨Óû§ÕÊ»§¿ØÖÆ£©²¢ÇÒÓÃÓÚ¹¥»÷µÄеĻù´¡¼Ü¹¹¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬ÎÒÃÇ»¹È·¶¨ÁËÒÔǰͨ¹ýÓʼþ·¢Ë͵ijõʼÓÕ¶üÎĵµÏÖÔÚ¿ÉÔÚTelegram DesktopĿ¼ÖÐÕÒµ½£¬£¬£¬ÕâÅú×¢¸Ã×éÖ¯¿ÉÄÜÕýÔڸıäÆä³õʼͶµÝ·½·¨¡£¡£¡£¡£¡£
ÔÚ2019Ä꣬£¬£¬ÎÒÃǼì²âµ½Ò»¸öδ֪×éÖ¯µÄ»î¶¯£¬£¬£¬ÆäʱÊÇÔÚ´ú±í²Ø×åÀûÒæµÄÍøÕ¾ÉϵÄË®¿Ó¹¥»÷»î¶¯£¬£¬£¬ÓÕÆÊܺ¦Õß×°ÖÃÔÚGitHub´æ´¢¿âÉÏÍйܵļÙAdobe Flash¸üС£¡£¡£¡£¡£¿£¿£¿£¿¨°Í˹»ùͨ¹ýÓëGitHubÏàÖúÀ´·ÀÓù¹¥»÷¡£¡£¡£¡£¡£Ã»¹ý¶à¾Ã£¬£¬£¬ÎÒÃÇÓÖ¼ì²âµ½ÐÂÒ»ÂÖË®¿Ó¹¥»÷¡£¡£¡£¡£¡£ÎÒÃǾöÒ齫´Ë»î¶¯µÄ×éÖ¯ÃüÃûΪ¡°Holy Water¡±¡£¡£¡£¡£¡£
×Ô½¨ÉèÖ®ÈÕÆð£¬£¬£¬¹¥»÷Õß¼òÆÓ¶ø¸»Óд´ÒâµÄ¹¤¾ß¾ÍÔÚÒ»Ö±¿ª·¢ºÍ¸üÐÂÖУ¬£¬£¬²¢Ê¹ÓÃÁËSojson»ìÏý£¬£¬£¬NSIS×°ÖóÌÐò£¬£¬£¬Python£¬£¬£¬¿ªÔ´´úÂ룬£¬£¬GitHub¿¯Ðа棬£¬£¬GoÓïÑÔÒÔ¼°Google DriveµÈÊÖÒÕÊֶΡ£¡£¡£¡£¡£
0x04 Öж«µØÇøµÄ APT »î¶¯
ÎÒÃÇ×î½üÔÚ2020Äê2Ô¼ì²âµ½ÁËStrongPity×éÖ¯Õë¶ÔÍÁ¶úÆäµÄÊý¾Ýй¶»î¶¯¡£¡£¡£¡£¡£Ö»¹ÜStrongPityµÄTTPÔÚÄ¿µÄ£¬£¬£¬»ù´¡ÉèÊ©ºÍѬȾǰÑÔ·½ÃæÃ»Óиı䣬£¬£¬µ«ÎÒÃÇÊӲ쵽ËûÃÇÊÔͼй¶µÄÎļþÓÐËù²î±ð¡£¡£¡£¡£¡£Ôڴ˻ÖУ¬£¬£¬StrongPity¸üÐÂÁË×îеÄÊðÃûºóÃÅ£¬£¬£¬ÃûΪStrongPity2£¬£¬£¬²¢Ìí¼ÓÁ˸ü¶àÎļþÒÔÖ²ÈëÆä³£¼ûµÄOfficeºÍPDFÎĵµÁÐ±í£¬£¬£¬°üÀ¨ÓÃÓÚÏ£²®À´ÕÚÑÚµÄDagesh Pro×Ö´¦Öóͷ£Æ÷Îļþ£¬£¬£¬ÓÃÓÚºÓÁ÷Á÷Á¿ºÍÇÅÁº½¨Ä£µÄRiverCADÎļþ£¬£¬£¬´¿Îı¾Îļþ£¬£¬£¬¹éµµÎļþÒÔ¼°GPG¼ÓÃÜÎļþºÍPGPÃÜÔ¿¡£¡£¡£¡£¡£
3Ô£¬£¬£¬ÎÒÃÇ·¢Ã÷ÁËWildPressure×éÖ¯Õë¶Ô¹¤ÒµÁìÓò·Ö·¢MilumľÂíµÄ»î¶¯£¬£¬£¬Ö¼ÔÚ¶ÔÄ¿µÄ×éÖ¯ÖеÄ×°±¸¾ÙÐÐÔ¶³Ì¿ØÖÆ¡£¡£¡£¡£¡£¸Ã»î¶¯×î³õ¿ÉÒÔ×·Ëݵ½2019Äê8Ô¡£¡£¡£¡£¡£µ½ÏÖÔÚΪֹ£¬£¬£¬ÎÒÃÇ¿´µ½µÄMilumʾÀýÓëÈκÎÒÑÖªµÄAPT»î¶¯Ã»ÓÐÈκδúÂëÏàËÆÐÔ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þʹ¹¥»÷Õß¿ÉÒÔÔ¶³Ì¿ØÖÆÊÜѬȾµÄ×°±¸£¬£¬£¬ÔÊÐíÏÂÔØºÍÖ´ÐÐÏÂÁ£¬£¬ÍøÂçºÍй¶ÐÅÏ¢ÒÔ¼°ÔÚ¶ñÒâÈí¼þÖÐ×°ÖÃÉý¼¶³ÌÐò¡£¡£¡£¡£¡£
ÔÚ2019Äê12ÔÂÏÂÑ®£¬£¬£¬¿¨°Í˹»ùThreat Attribution Engine¼ì²âµ½ZerocleareµÄбäÌåDustman£¬£¬£¬±»ÓÃÓÚÕë¶ÔÉ³ÌØ°¢À²®ÄÜÔ´²¿·ÖµÄ¹¥»÷¡£¡£¡£¡£¡£ÔÚ²Á³ýºÍ·Ö·¢·½Ã棬£¬£¬ËüÓëZerocleareÏàËÆ£¬£¬£¬¿ÉÊDZäÁ¿ºÍÊÖÒÕÃû³ÆµÄת±äÅú×¢£¬£¬£¬Õâ¿ÉÄÜÒѾ׼±¸ºÃÓ½ÓÕë¶Ô¶ñÒâÈí¼þµÄÐÂÒ»²¨¹¥»÷£¬£¬£¬ÕâЩ¹¥»÷»ùÓÚǶÈëÔÚ¶ñÒâÈí¼þÖеÄÐÂÎźͽ¨ÉèµÄ»¥³âÌ壬£¬£¬×¨ÃÅÕë¶ÔÉ³ÌØ°¢À²®µÄÄÜÔ´²¿·Ö¡£¡£¡£¡£¡£Í¨¹ýËü¡£¡£¡£¡£¡£ÓйØDustmanµÄPDBÎļþÅú×¢£¬£¬£¬¸ÃÆÆËðÐÔ´úÂëÊÇ¿¯Ðа棬£¬£¬¿ÉÒÔÔÚÄ¿µÄÍøÂçÖа²ÅÅ¡£¡£¡£¡£¡£ÕâЩת±äÇ¡·êÐÂÄê¼ÙÆÚ£¬£¬£¬ÔÚ´Ëʱ´úÐí¶àÔ±¹¤ÕýÔÚÐݼ١£¡£¡£¡£¡£
0x05 ¶«ÄÏÑǺͳ¯Ïʰ뵺µÄAPT»î¶¯
Òâ´óÀûÇå¾²¹«Ë¾TelsyÔÚ2019Äê11Ô¸ÅÊöÁËLazarus×éÖ¯µÄ»î¶¯£¬£¬£¬Ê¹ÎÒÃÇÄܹ»½«Õë¶Ô¼ÓÃÜÇ®±ÒÓªÒµµÄÏÈǰ»î¶¯ÁªÏµÆðÀ´¡£¡£¡£¡£¡£Telsy²©¿ÍÉÏÌáµ½µÄ¶ñÒâÈí¼þÊǵÚÒ»½×¶ÎÏÂÔØ³ÌÐò£¬£¬£¬×Ô2018ÄêÖÐÒÔÀ´Ò»Ö±±»ÊӲ쵽¡£¡£¡£¡£¡£ÎÒÃÇ·¢Ã÷µÚ¶þ½×¶Î¶ñÒâÈí¼þÊÇManuscryptµÄ±äÌ壬£¬£¬ËüÊÇLazarusµÄ¶ÀÍÌÊôÐÔ£¬£¬£¬Æä°²ÅÅÁËÁ½ÖÖÀàÐ͵Äpayload¡£¡£¡£¡£¡£µÚÒ»¸öÊÇ¿ÉʹÓõÄUltra VNC³ÌÐò£¬£¬£¬µÚ¶þ¸öÊǶ༶ºóÃųÌÐò¡£¡£¡£¡£¡£ÕâÖÖÀàÐ͵Ķà½×¶ÎѬȾÀú³ÌÊÇLazarus×éÖ¯¶ñÒâÈí¼þµÄµä·¶ÌØÕ÷£¬£¬£¬ÓÈÆäÊÇʹÓÃManuscrypt±äÌå¡£¡£¡£¡£¡£Ôڴ˻ÖУ¬£¬£¬Lazarus×éÖ¯¹¥»÷ÁËÈûÆÖ·˹£¬£¬£¬ÃÀ¹ú£¬£¬£¬Öйų́ÍåºÍÖйúÏã¸ÛµÄ¼ÓÃÜÇ®±ÒÓªÒµ£¬£¬£¬¸Ã»î¶¯Ò»Ö±Ò»Á¬µ½2020ÄêÍ·¡£¡£¡£¡£¡£
×Ô2013ÄêÒÔÀ´ÎÒÃÇÒ»Ö±¸ú×ÙµÄ×éÖ¯KimsukyÔÚ2019ÄêÓÈÆä»îÔ¾¡£¡£¡£¡£¡£12Ô£¬£¬£¬Î¢Èí×÷·ÏÁ˸Ã×é֯ʹÓõÄ50¸öÓò£¬£¬£¬²¢ÔÚ¸¥¼ªÄáÑÇÖÝ·¨Ôº¶Ô¹¥»÷ÕßÌáÆðÁËËßËÏ¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬¸ÃС×é¼ÌÐø¿ªÕ¹»î¶¯£¬£¬£¬Ã»Óб¬·¢ÖØ´óת±ä¡£¡£¡£¡£¡£ÎÒÃÇ×î½ü·¢Ã÷ÁËÒ»¸öеĻ£¬£¬£¬ÆäÖÐʹÓÃÁËÒÔÐÂÄêÎʺòΪÖ÷ÌâµÄÓÕ¶üͼƬ£¬£¬£¬¸ÃͼƬΪ¾ÉÏÂÔØ¹¤¾ßÌṩÁËеľÓÉˢеÄÏÂÒ»½×¶Îpayload£¬£¬£¬Ö¼ÔÚʹÓÃеļÓÃÜÒªÁìÀ´ÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£
1ÔÂ⣬£¬£¬ÎÒÃÇ·¢Ã÷ÁËʹÓÃInternet ExplorerÎó²î£¨CVE-2019-1367£©µÄ¶ñÒâ¾ç±¾¡£¡£¡£¡£¡£ÔÚ×Ðϸ¼ì²épayload²¢·¢Ã÷ÓëÏÈǰ»î¶¯µÄÁªÏµÖ®ºó£¬£¬£¬ÎÒÃǵóö½áÂÛ£¬£¬£¬DarkHotelÖ§³Ö´Ë»î¶¯£¬£¬£¬¸Ã»î¶¯¿ÉÄÜ×Ô2018ÄêÒÔÀ´Ò»Ö±ÔÚ¾ÙÐС£¡£¡£¡£¡£¸Ã»î¶¯¿´µ½DarkHotelʹÓÿª·¢µÄÈí¼þʵÏÖÁ˶à½×¶Î¶þ½øÖÆÑ¬È¾¡£¡£¡£¡£¡£×î³õµÄѬȾ»á½¨ÉèÒ»¸öÏÂÔØ³ÌÐò£¬£¬£¬¸ÃÏÂÔØ³ÌÐò½«»ñÈ¡ÁíÒ»¸öÏÂÔØ³ÌÐòÒÔÍøÂçϵͳÐÅÏ¢£¬£¬£¬²¢½öΪ¸ß¼ÛÖµÊܺ¦Õß»ñÈ¡×îÖյĺóÃųÌÐò¡£¡£¡£¡£¡£DarkHotelÔڴ˻ÖÐʹÓÃÁËTTPµÄÆæÒì×éºÏ¡£¡£¡£¡£¡£ÍþвÕßʹÓÃÖÖÖÖ»ù´¡½á¹¹À´ÍйܶñÒâÈí¼þ²¢¿ØÖÆÊÜѬȾµÄÊܺ¦Õߣ¬£¬£¬°üÀ¨ÊÜѬȾµÄWebЧÀÍÆ÷£¬£¬£¬ÉÌÒµÍйÜЧÀÍ£¬£¬£¬Ãâ·ÑÍйÜЧÀͺÍÃâ·ÑÔ´´úÂë¸ú×Ùϵͳ¡£¡£¡£¡£¡£
3Ô£¬£¬£¬À´×ÔGoogleµÄÑо¿Ö°Ô±Í¸Â¶£¬£¬£¬Ò»×éºÚ¿ÍÔÚ2019ÄêʹÓÃÁËÎå¸ö0day¹¥»÷Ä¿µÄÕë¶Ô³¯ÏÊÈ˺ÍÒÔ³¯ÏÊÈËΪÖÐÐĵÄרҵְԱ¡£¡£¡£¡£¡£¸ÃС×éʹÓÃInternet Explorer£¬£¬£¬ChromeºÍWindowsÖеÄÎó²îÀ´¾ÙÐÐÍøÂç´¹Âںͷַ¢µç×ÓÓʼþ£¬£¬£¬ÕâЩµç×ÓÓʼþÖаüÀ¨¶ñÒ⸽¼þ»òÓë¶ñÒâÁ´½ÓÒÔ¼°Ë®¿Ó¹¥»÷¡£¡£¡£¡£¡£ÎÒÃÇÄܹ»½«ÆäÖеÄÁ½¸öÎó²î»®·ÖΪIEÖеÄÒ»¸öÎó²îºÍWindowsÖеÄÒ»¸öÎó²îÓëDarkHotel×é֯ƥÅäÉÏ¡£¡£¡£¡£¡£
FunnyDream×éÖ¯»î¶¯Ê¼ÓÚ2018ÄêÖУ¬£¬£¬Õë¶ÔÂíÀ´Î÷ÑÇ£¬£¬£¬Öйų́ÍåºÍ·ÆÂɱöµÄ×ÅÃû×éÖ¯£¬£¬£¬ÆäÖдó´ó¶¼Êܺ¦ÕßÀ´×ÔÔ½ÄÏ¡£¡£¡£¡£¡£ÆÊÎöÅú×¢£¬£¬£¬ÕâÖ»ÊÇÒ»Ïî¸üÆÕ±é¹¥»÷»î¶¯µÄÒ»²¿·Ö£¬£¬£¬¸Ã»î¶¯¿ÉÒÔ×·Ëݵ½¼¸Äêǰ£¬£¬£¬²¢Õë¶Ô¶«ÄÏÑǹú¼ÒµÄÕþ¸®ÌØÊâÊÇÍâ¹ú×éÖ¯¡£¡£¡£¡£¡£¹¥»÷ÕߵĺóÃÅ´ÓC2ÏÂÔØÎļþºÍÏòC2ÉÏ´«Îļþ£¬£¬£¬Ö´ÐÐÏÂÁî²¢ÔÚÊܺ¦ÕßϵͳÖÐÔËÐÐÐÂÀú³Ì¡£¡£¡£¡£¡£Ëü»¹ÍøÂçÓйØÍøÂçÉÏÆäËûÖ÷»úµÄÐÅÏ¢£¬£¬£¬²¢Í¨¹ýÔ¶³ÌÖ´ÐÐÓ¦ÓóÌÐò½«Æäת´ï¸øÐÂÖ÷»ú¡£¡£¡£¡£¡£¹¥»÷Õß»¹Ê¹ÓÃÁËRTLºóÃźÍChinoxyºóÃÅ¡£¡£¡£¡£¡£×Ô2018ÄêÄêÖÐÒÔÀ´£¬£¬£¬C2»ù´¡Éèʩһֱ´¦ÓÚ»îԾ״̬£¬£¬£¬²¢ÇÒdomainsÓëFFRAT¶ñÒâÈí¼þ¼Ò×åÖØµþ¡£¡£¡£¡£¡£
Operation AppleJeusÊÇLazarus×îÓÐÓ°ÏìÁ¦µÄ»î¶¯Ö®Ò»£¬£¬£¬Ö÷ҪʹÓÃMacOS¶ñÒâÈí¼þ¾ÙÐй¥»÷¡£¡£¡£¡£¡£1Ô·ݵĺóÐøÑо¿Õ¹ÏÖÁ˸Ã×éÖ¯¹¥»÷ÒªÁìµÄÖØ´óת±ä£ºÐ¿ª·¢µÄmacOS¶ñÒâÈí¼þºÍÒ»ÖÖÉí·ÝÑéÖ¤»úÖÆ£¬£¬£¬¿ÉÒÔÉóÉ÷µØ½»¸¶ÏÂÒ»½×¶ÎµÄpayload£¬£¬£¬ÒÔ¼°ÔÚ²»½Ó´¥´ÅÅ̵ÄÇéÐÎϼÓÔØÏÂÒ»½×¶ÎµÄpayload¡£¡£¡£¡£¡£ÎªÁ˹¥»÷WindowsÊܺ¦Õߣ¬£¬£¬¸Ã×éÖ¯ÖÆ¶©ÁËÒ»¸ö¶à½×¶ÎѬȾ³ÌÐò²¢¸ü¸ÄÁË×îÖÕpayload¡£¡£¡£¡£¡£ÎÒÃÇÒÔΪ£¬£¬£¬×Ô´ÓAppleJeus»î¶¯ÒÔÀ´£¬£¬£¬LazarusÔÚ¹¥»÷·½ÃæÔ½·¢ÉóÉ÷£¬£¬£¬²¢½ÓÄÉÁ˶àÖÖÒªÁìÀ´×èÖ¹±»·¢Ã÷¡£¡£¡£¡£¡£ÎÒÃÇÔÚÓ¢¹ú£¬£¬£¬²¨À¼£¬£¬£¬¶íÂÞ˹ºÍÖйúÈ·¶¨Á˼¸ÃûÊܺ¦Õß¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ÎÒÃÇÄܹ»È·ÈÏһЩÊܺ¦ÕßÓë¼ÓÃÜÇ®±Ò×éÖ¯Óйء£¡£¡£¡£¡£
Roaming MantisÊÇÒ»¸ö³öÓÚ¾¼ÃÄîÍ·µÄAPT×éÖ¯£¬£¬£¬ÓÚ2017ÄêÊ״ᨵÀ£¬£¬£¬Æäʱ¸Ã¹«Ë¾Ê¹ÓÃSMS½«Æä¶ñÒâÈí¼þ·Ö·¢¸øÎ»ÓÚº«¹úµÄAndroid×°±¸¡£¡£¡£¡£¡£ØÊºó¸Ã×éÖ¯µÄ»î¶¯¹æÄ£À©´ó£¬£¬£¬Ö§³Ö27ÖÖÓïÑÔ£¬£¬£¬ÒÔiOSºÍAndroidΪĿµÄ£¬£¬£¬ÉõÖÁÍÚ¾ò¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¸Ã×éÖ¯»¹Ê¹ÓÃÁËеĶñÒâÈí¼þ¼Ò×壬£¬£¬°üÀ¨FakecopºÍWroba.j£¬£¬£¬²¢ÇÒÈÔÔÚʹÓá°SMiShing¡±¾ÙÐÐAndroid¶ñÒâÈí¼þ·Ö·¢¡£¡£¡£¡£¡£ÔÚ×î½üµÄÒ»Ïî»î¶¯ÖУ¬£¬£¬Ëü·Ö·¢ÁËαװ³ÉÊܽӴýµÄ¿ìµÝ¹«Ë¾µÄ¶ñÒâAPK£¬£¬£¬Ö÷ÒªÕë¶ÔÈÕ±¾£¬£¬£¬Öйų́Í壬£¬£¬º«¹úºÍ¶íÂÞ˹¡£¡£¡£¡£¡£
0x06 ÆäËü
TransparentTribeÓÚ2019ÄêÍ·×îÏÈʹÓÃÃûΪUSBWormµÄÐÂÄ£¿£¿£¿£¿é£¬£¬£¬²¢¶ÔÆäÃûΪCrimsonRATµÄ×Ô½ç˵.NET¹¤¾ß¾ÙÐÐÁËˢС£¡£¡£¡£¡£Æ¾Ö¤¼øºÚµ£±£ÍøÒ£²â·¢Ã÷£¬£¬£¬USBWorm±»ÓÃÀ´Ñ¬È¾³ÉǧÉÏÍòµÄÊܺ¦Õߣ¬£¬£¬ÆäÖдó´ó¶¼Î»ÓÚ°¢¸»º¹ºÍÓ¡¶È£¬£¬£¬Ê¹¹¥»÷ÕßÄܹ»ÏÂÔØºÍÖ´ÐÐí§ÒâÎļþ£¬£¬£¬Èö²¥µ½¿ÉÒÆ¶¯×°±¸²¢´ÓÊÜѬȾµÄÖ÷»úÇÔÈ¡¸ÐÐËȤµÄÎļþ¡£¡£¡£¡£¡£ÕýÈçÎÒÃÇ֮ǰ±¨µÀµÄÄÇÑù£¬£¬£¬¸ÃС×éÖ÷Òª¹Ø×¢¾üÊÂÄ¿µÄ£¬£¬£¬ÕâЩĿµÄͨ³£Êܵ½OfficeÎĵµÖжñÒâVBAºÍPeppy RAT¡¢CrimsonRATµÈ¿ªÔ´¶ñÒâÈí¼þµÄ¹¥»÷¡£¡£¡£¡£¡£×î½üµÄлÖУ¬£¬£¬ÎÒÃÇ×¢ÖØµ½¸ÃС×éµÄÖØµã¸ü¶àµØ×ªÏòÁËÕë¶ÔÓ¡¶ÈÒÔÍâµÄ°¢¸»º¹¡£¡£¡£¡£¡£
ÔÚ2019ÄêµÄ×îºó¼¸¸öÔÂÖУ¬£¬£¬ÎÒÃÇÊӲ쵽ÁËFishing ElephantÕýÔÚ¾ÙÐеÄÒ»Ïî»î¶¯¡£¡£¡£¡£¡£¸ÃС×é¼ÌÐøÊ¹ÓÃHerokuºÍDropboxÀ´½»¸¶ÆäÑ¡ÔñµÄ¹¤¾ßAresRAT¡£¡£¡£¡£¡£ÎÒÃÇ·¢Ã÷£¬£¬£¬¼ÓÈëÕßÔÚÆä²Ù×÷ÖнÓÄÉÁËÒ»ÏîÐÂÊÖÒÕ£¬£¬£¬¸ÃÊÖÒÕÖ¼ÔÚ×èÖ¹ÊÖ¶¯ºÍ×Ô¶¯ÆÊÎögeo-fencingºÍ½«¿ÉÖ´ÐÐÎļþÒþ²ØÔÚÖ¤ÊéÎļþÖС£¡£¡£¡£¡£ÔÚ¼øºÚµ£±£ÍøÑо¿Àú³ÌÖУ¬£¬£¬ÎÒÃÇ»¹·¢Ã÷Êܺ¦ÕßµÄת±ä¿ÉÄÜ·´Ó¦Á˹¥»÷ÕßµÄÄ¿½ñÀûÒæ£¬£¬£¬¸Ã×éÖ¯µÄÄ¿µÄÊÇÍÁ¶úÆä£¬£¬£¬°Í»ù˹̹£¬£¬£¬ÃϼÓÀ¹ú£¬£¬£¬ÎÚ¿ËÀ¼ºÍÖйúµÄÕþ¸®ºÍÍâ½»»ú¹¹¡£¡£¡£¡£¡£
0x07 ½áÓï
Ö»¹ÜÍþвÐÎÊÆ²¢²»×ÜÊdzäÂú¡°Í»ÆÆÐÔ¡±ÊÂÎñ£¬£¬£¬µ«µ±ÎÒÃǽ«ÑÛ¹âͶÏòAPTÍþвÐÐΪÕߵĻʱ£¬£¬£¬×ÜÊÇ»áÓÐÓÐȤµÄÉú³¤¡£¡£¡£¡£¡£¼øºÚµ£±£Íø°´ÆÚ¼¾¶ÈÉó²éÖ¼ÔÚÇ¿µ÷Òªº¦µÄÉú³¤¡£¡£¡£¡£¡£
ÕâЩÊǵ½ÏÖÔÚΪֹÎÒÃǽñÄêÒѾ¿´µ½µÄһЩÖ÷ÒªÇ÷ÊÆ¡£¡£¡£¡£¡£
¡ñ µØÔµÕþÖÎÈÔÈ»ÊÇAPT»î¶¯µÄÖ÷ÒªÖúÍÆÁ¦¡£¡£¡£¡£¡£
¡ñ LazarusºÍRoaming MantisµÄ»î¶¯Ö¤Êµ£¬£¬£¬¾¼ÃÀûÒæÈÔÈ»ÊÇijЩ¹¥»÷ÕßµÄÄîÍ·¡£¡£¡£¡£¡£
¡ñ ¾ÍAPT»î¶¯¶øÑÔ£¬£¬£¬¶«ÄÏÑÇÊÇ×î»îÔ¾µÄµØÇø£¬£¬£¬°üÀ¨Lazarus£¬£¬£¬DarkHotelºÍKimsukyµÈ×éÖ¯£¬£¬£¬ÒÔ¼°Cloud SnooperºÍFishing ElephantµÈÐÂÐË×éÖ¯¡£¡£¡£¡£¡£
¡ñ APT×éÖ¯£¬£¬£¬ÀýÈçCactusPete£¬£¬£¬TwoSail Junk£¬£¬£¬FunnyDreamºÍDarkHotel£¬£¬£¬¼ÌÐøÊ¹ÓÃÈí¼þÎó²î¡£¡£¡£¡£¡£
¡ñ APT×éÖ¯¼ÌÐø½«mobile implantsÄÉÈëÆäÎäÆ÷¿â¡£¡£¡£¡£¡£
¡ñ APT×éÖ¯£¨ÀýÈ絫²»ÏÞÓÚKimsuky£¬£¬£¬HadesºÍDarkHotel£©ÒÔʵʱ»úÖ÷Òå×ï·¸ÕýÔÚʹÓÃCOVID-19¡£¡£¡£¡£¡£
×ܶøÑÔÖ®£¬£¬£¬ÎÒÃÇ¿´µ½ÁËÑÇÖÞ¹¥»÷»î¶¯µÄÒ»Á¬ÔöÌí£¬£¬£¬Ê¹ÓÃÒÆ¶¯Æ½Ì¨Ñ¬È¾ºÍÈö²¥¶ñÒâÈí¼þµÄÇ÷ÊÆÕýÔÚÉÏÉý¡£¡£¡£¡£¡£
ÏÖÔÚ£¬£¬£¬COVID-19Êܵ½Ã¿Ð¡ÎÒ˽¼ÒµÄ¹Ø×¢£¬£¬£¬¶øAPT×éÖ¯Ò²Ò»Ö±ÔÚʵÑéÔÚÓã²æÊ½ÍøÂç´¹ÂڻÖÐʹÓÃÕâÒ»Ö÷Ìâ¡£¡£¡£¡£¡£ÎÒÃÇÒÔΪÕâ²¢²»´ú±íTTP±¬·¢ÁËÓÐÒâÒåµÄת±ä£ºËûÃÇÖ»Êǽ«ÆäÓÃ×÷¾ßÓÐÐÂÎżÛÖµµÄ»°ÌâÀ´ÎüÒýÊܺ¦Õß¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬ÎÒÃÇÕýÔÚÇ×½ü¼àÊÓÊ±ÊÆ¡£¡£¡£¡£¡£
0x08 ²Î¿¼Á´½Ó
https://securelist.com/apt-trends-report-q1-2020/96826/
0x09 ʱ¼äÏß
2020-05-01 VSRCÐû²¼±¨¸æ