¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190304
°ä²¼¹¦·ò 2019-03-04
ÔÎÄÁ´½Ó£º
https://cyware.com/news/apt-group-bronze-union-comes-up-with-upated-rat-malware-dd4ccb282¡¢Ð·¸×ïÍÅ»ïPacha Group£¬£¬£¬£¬£¬£¬£¬ÖØÒª¹¥»÷Linux·þÎñÆ÷½øÐÐÍÚ¿ó
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/linux-servers-targeted-by-new-chinese-crypto-mining-group/3¡¢Ð´¹µö¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬ÖØÒªÀûÓÃXLMºê·Ö·¢FlawedAmmyyľÂí
2019Äê2ÔÂSI-LAB²¶»ñÁ˶à¸ö´øÓжñÒâExcel 4.0ºê£¨Ò²³ÆXLMºê£©µÄExcel´¹µöÑù±¾£¬£¬£¬£¬£¬£¬£¬ÕâЩÑù±¾ÓÃÓÚÏÂÔØºÍÖ´ÐÐFlawedAmmyy RAT¡£¡£¡£¡£¡£¡£¡£¡£¸Ã´¹µö¹¥»÷±³ºóµÄ¹¥»÷ÕßÊÇ·¸×ïÍÅ»ïTA505£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßµÄC&C·þÎñÆ÷£¨195.123.209.169£©Î»ÓÚÀÍÑάÑÇ£¬£¬£¬£¬£¬£¬£¬µ±Ç°´¦ÓÚÀëÏß״̬¡£¡£¡£¡£¡£¡£¡£¡£Æä·Ö·¢µÄFlawedAmmyy RAT¿ÉÇÔȡָ±êµÄÎļþ¡¢Í´´¦¡¢ÆÁÄ»½ØÍ¼ÒÔ¼°½Ó¼ûÉãÏñÍ·ºÍÂó¿Ë·çµÈ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/81857/malware/flawedammyy-undetected-xlm-macros.html4¡¢×êÑÐÅú×¢Operation SharpshooterÓµÓиü¸ßµÄ¸´ÔӶȺ͸ü¹ãµÄÁìÓò

McAfee×êÑÐÈËÔ±ÔÚÒ»·Ýл㱨ÖÐÖ¸³ö£¬£¬£¬£¬£¬£¬£¬Operation SharpshooterµÄ¹¥»÷»î¶¯ÔÚ¸´ÔÓÐÔ¡¢ÁìÓòºÍ¹ã¶ÈÉϱÈ֮ǰÒÔΪµÄÒªÔ½·¢¿í·º¡£¡£¡£¡£¡£¡£¡£¡£SharpshooterÓÚ2018Äê12Ô³õ´Î±»Åû¶£¬£¬£¬£¬£¬£¬£¬ÆäÖØÒªÕë¶ÔÈ«ÇòµÄ¹ú·ÀºÍ¹Ø¼ü»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬Ô̺¬ºËÄÜ¡¢¹ú·À¡¢ÄÜÔ´ºÍ½ðÈÚÆóÒµ¡£¡£¡£¡£¡£¡£¡£¡£ÐÂ×êÑÐÅú×¢£¬£¬£¬£¬£¬£¬£¬Sharpshooter×îÔçÓÚ2017Äê9ÔÂÆðÍ·»î¶¯£¬£¬£¬£¬£¬£¬£¬Õë¶Ô¸ü¶àµÄ¹ú¶ÈºÍÐÐÒµ£¬£¬£¬£¬£¬£¬£¬¸Ã»î¶¯Ä¿Ç°»¹ÔÚ½øÐÐÖ®ÖÓ×£¡£¡£¡£¡£¡£¡£¡£Êܵ½¹¥»÷×î¶àµÄÖ¸±êÊǵ¹ú¡¢ÍÁ¶úÆä¡¢Ó¢¹úºÍÃÀ¹ú¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»ã±¨»¹Ö¸³öSharpshooterÓëAPT×éÖ¯LazarusµÄ¹¥»÷ÓµÓжà¸öÀàËÆÌØµã¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/sharpshooter-complexity-scope/142359/5¡¢ÀÕË÷Èí¼þGarrantyDecryptбäÖÖ£¬£¬£¬£¬£¬£¬£¬¼Ù×°³É°²È«ÍŶӽøÐкýŪ
2Ô·Ý×êÑÐÈËÔ±Michael Gillespie·¢ÏÖÀÕË÷Èí¼þGarrantyDecryptµÄÒ»¸öбäÖÖ£¬£¬£¬£¬£¬£¬£¬¸Ã±äÖÖѡȡÁËÒ»ÖÖеÄÕ½Êõ½øÐкýŪ£ºÔÚÃûΪSECURITY-ISSUE-INFO.txtµÄÀÕË÷µ¥¾ÝÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÐû³ÆÖ¸±êÓû§Ôâµ½¡°±í²¿ÈËÔ±¡±µÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬¶øProton°²È«ÍŶӵÄSECURE-SERVER·þÎñ¶ÔÓû§µÄÊý¾Ý½øÐÐÁ˱£»£»£»£»£»£»£»¤ÐԵļÓÃÜ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÉõÖÁ½«PROTONµÄ°æÈ¨ÉêÃ÷¸éÖÃÔÚÎļþµ×²¿£¬£¬£¬£¬£¬£¬£¬ÒÔÔö³¤ÆäºÏ·¨ÐÔ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß³ÆProtonµÄSECURE-SERVER·þÎñ±ØÒªÊÕÈ¡780ÃÀÔªµÄÓöÈÄÜÁ¦½âÃÜÎļþ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ransomware-pretends-to-be-proton-security-team-securing-data-from-hackers/6¡¢×êÑÐÈËÔ±Åû¶Windows IoT CoreÉ豸Öеķì϶£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂȨÏÞ±»½Ù³Ö
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/new-exploit-lets-attackers-take-control-of-windows-iot-core-devices/ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ