APT×éÖ¯BlackTechÀûÓÃFlagpro¹¥»÷ÈÕ±¾µÄ¹«Ë¾

°ä²¼¹¦·ò 2021-12-30

APT×éÖ¯BlackTechÀûÓÃFlagpro¹¥»÷ÈÕ±¾µÄ¹«Ë¾


APT×éÖ¯BlackTechÀûÓÃFlagpro¹¥»÷ÈÕ±¾µÄ¹«Ë¾.png


¾ÝýÌå12ÔÂ28ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬¼äµýAPT×éÖ¯BlackTechÀûÓÃFlagpro¹¥»÷ÈÕ±¾µÄ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£ ¡£Õâ´Î¹¥»÷µÄ³õʼϰȾý½éÊǼÙ×°³ÉÀ´×ÔÖ¸±êºÏ×÷ͬ°éµÄ´¹µöÓʼþ£¬£¬£¬£¬£¬£¬£¬Ö®ºó¹¥»÷Õß»áÀûÓÃFlagpro½øÐÐÍøÂç¿úËÅ¡¢ÆÀ¹ÀÖ¸±ê»·¾³ÒÔ¼°ÏÂÔØ²¢Ö´Ðеڶþ½×¶Î¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£ ¡£¾ÝNTT Security³Æ£¬£¬£¬£¬£¬£¬£¬Õâ´Î»î¶¯ÖÁÉÙʼÓÚ2020Äê10Ô£¬£¬£¬£¬£¬£¬£¬ÒÑÕë¶ÔÈÕ±¾¹«Ë¾Ò»Äê¶à£¬£¬£¬£¬£¬£¬£¬Éæ¼°¹ú·À¼¼Êõ¡¢Ã½ÌåºÍͨѶÐÐÒµÔÚÄڵĶà¸öÁìÓò¡£¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-flagpro-malware-linked-to-chinese-state-backed-hackers/


Morphus Labs·¢ÏÖ¶à¸öÀûÓÃMSBuildµÄ¹¥»÷»î¶¯


Morphus Labs·¢ÏÖ¶à¸öÀûÓÃMSBuildµÄ¹¥»÷»î¶¯.png


12ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬£¬Morphus LabsºÍSANS ISC°ä²¼»ã±¨³Æ£¬£¬£¬£¬£¬£¬£¬ÔÚ´ÓǰһÖÜÖмì²âµ½2¸öÀûÓÃMicrosoft Build Engine(MSBuild)µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£ ¡£ÔÚÕâЩ»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ³£ÏÈÀûÓÃÔ¶³Ì×ÀÃæºÍ̸(RDP)ÕÊ»§½Ó¼ûÖ¸±ê»·¾³£¬£¬£¬£¬£¬£¬£¬¶øºóÀûÓÃÔ¶³ÌWindows·þÎñ(SCM)½øÐкáÏòÒÆ¶¯£¬£¬£¬£¬£¬£¬£¬×îºóÀûÓÃMSBuildÖ´ÐÐCobalt Strike Beacon¡£¡£¡£¡£¡£¡£¡£ ¡£¹¥»÷ÖÐʹÓõĶñÒâMSBuildÏîÄ¿Äܹ»±àÒëºÍÖ´ÐÐÌØ¶¨µÄC#´úÂ룬£¬£¬£¬£¬£¬£¬½ø¶ø½âÂëºÍÖ´ÐÐCobalt Strike¡£¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/threat-actors-abuse-msbuild-cobalt-strike-beacon-execution


T-MobileÒòÔâµ½SIM»¥»»¹¥»÷£¬£¬£¬£¬£¬£¬£¬Óû§ÐÅÏ¢ÔÙ´Îй¶


T-MobileÒòÔâµ½SIM»¥»»¹¥»÷£¬£¬£¬£¬£¬£¬£¬Óû§ÐÅÏ¢ÔÙ´Îй¶.png


12ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬£¬T-Mobile½²»°ÈË֤ʵÆä²¿ÃÅÓû§Ôâµ½SIM»¥»»¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÐÅÏ¢¿ÉÄÜÒѾ­Ð¹Â¶¡£¡£¡£¡£¡£¡£¡£ ¡£T-Mobile³ÆÆäÍŶÓÔÚ·¢ÏÖÎÊÌâºóÁ¢¿Ì²ÉȡӦ¼±´ëÊ©£¬£¬£¬£¬£¬£¬£¬²¢ÒÑ×Ô¶¯²ÉÈ¡¶î±íµÄ±£»£»£»£»£»£»¤´ëÊ©¡£¡£¡£¡£¡£¡£¡£ ¡£µ±±»ÒªÇóÌṩÓйØÊÜÓ°ÏìÓû§ÊýÁ¿ÒÔ¼°¹¥»÷ÕߵĹ¥»÷·½Ê½Ê±£¬£¬£¬£¬£¬£¬£¬T-Mobile»Ø¾øÌṩ¸ü¶à¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ ¡£T-MobileÒѲúÉúÂÅ´ÎÐÅϢй¶£¬£¬£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñÓë½ñÄê2Ô·ݵÄй¶ÊÂÎñ¼«¶ÈÀàËÆ£¬£¬£¬£¬£¬£¬£¬ÆäʱÒòSIM»¥»»¹¥»÷й¶400¸öÓû§µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/t-mobile-says-new-data-breach-caused-by-sim-swap-attacks/


Galaxy Store´æÔÚ¶à¸öαÔì³ÉShowBoxµÄ¶ñÒâÀûÓÃ


Galaxy Store´æÔÚ¶à¸öαÔì³ÉShowBoxµÄ¶ñÒâÀûÓÃ.png


ýÌå12ÔÂ28Èճƣ¬£¬£¬£¬£¬£¬£¬ÈýÐǵĹٷ½AndroidÀûÓ÷¨Ê½É̵êGalaxy Store´æÔÚ¶à¸ö¶ñÒâÀûÓᣡ£¡£¡£¡£¡£¡£ ¡£ÕâЩÀûÓüÙ×°³ÉÒÑÓÚ2018ÄêÆÆ²úµÄµÁ°æÀûÓÃShowBox£¬£¬£¬£¬£¬£¬£¬ÒÑÔÚ¶à¸öÓû§µÄÉ豸ÉÏ´¥·¢Google Play Protect¾¯±¨¡£¡£¡£¡£¡£¡£¡£ ¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬ÕâЩÀûÓÃÖ®ËùÒԻᴥ·¢¾¯±¨£¬£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚËüÃÇÒªÇóÓµÓÐ×°ÖöñÒâÈí¼þ·çÏÕµÄȨÏÞ£¬£¬£¬£¬£¬£¬£¬µ±Óû§ÔÊÐíºóËüÃǾÍÄܹ»½Ó¼ûÁªÏµÈËÁбíºÍͨ»°¼Í¼¡¢Ö´ÐдúÂë¡¢»ñÈ¡¶ñÒâÈí¼þpayloadµÈ¡£¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/riskware-android-streaming-apps-found-on-samsungs-galaxy-store/


ÃÀ¹úSLGAÔÚ×ÅÊÖµ÷²éÆäÊ¥µ®½ÚÆÚ¼äÔâµ½µÄÍøÂç¹¥»÷


ÃÀ¹úSLGAÔÚ×ÅÊÖµ÷²éÆäÊ¥µ®½ÚÆÚ¼äÔâµ½µÄÍøÂç¹¥»÷.png


¾ÝýÌå12ÔÂ28ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬ÈøË¹¿¦³¹ÎÂÊ¡¾ÆÀàºÍ²©²ÊÖÎÀí¾Ö£¨SLGA£©ÔÚ×ÅÊÖµ÷²éÆäÔâµ½µÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£ ¡£SLGAÊÇÃÀ¹ú²ÆÕþ²¿»Ê¹Ú¹«Ë¾ÕƹܷÖÏú¡¢½ÚÔìºÍ¼à¹Ü¾Æ¾«ÒûÁÏ¡¢´óÂéºÍ´óÎÞÊý´ò¶ÄµÄ»ú¹¹£¬£¬£¬£¬£¬£¬£¬Î»ÓÚ¼ÓÄôóµÄÈøË¹¿¦³¹ÎÂÊ¡¡£¡£¡£¡£¡£¡£¡£ ¡£¹¥»÷²úÉúÔÚ12ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬£¬SLGA°µÊ¾£¬£¬£¬£¬£¬£¬£¬µ÷²éÏÔʾĿǰûÓÐÈκοͻ§¡¢Ô±¹¤»òÆäËüÊý¾Ý±»ÀÄÓ㬣¬£¬£¬£¬£¬£¬ÔÚʵÏÖ¶Ô¸ÃÊÂÎñµÄÆÀ¹Àºó£¬£¬£¬£¬£¬£¬£¬½«Á¢¼´±ãÊÜÓ°ÏìµÄϵͳ³ÁÐÂÉÏÏß¡£¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://globalnews.ca/news/8477174/slga-investigating-christmas-day-cybersecurity-incident/


×êÑÐÍŶÓÅû¶EquationʹÓõÄDanderSpritzµÄ¼¼Êõ·ÖÎö


×êÑÐÍŶÓÅû¶EquationʹÓõÄDanderSpritzµÄ¼¼Êõ·ÖÎö.png


12ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬£¬Check PointÅû¶Equation GroupʹÓõÄȫְÄܶñÒâÈí¼þ¿ò¼ÜDanderSpritzµÄ¼¼Êõ·ÖÎö¡£¡£¡£¡£¡£¡£¡£ ¡£DanderSpritzÓÚ2017Äê4ÔÂ14ÈÕ±»Shadow Brokers¹«¿ª£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÓÃÓÚÓÆ¾ÃÐÔ¡¢¿úËÅ¡¢ºáÏòÒÆ¶¯¡¢Èƹýɱ¶¾ÒýÇæµÈ»î¶¯µÄ¶àÖÖ¹¤¾ß¡£¡£¡£¡£¡£¡£¡£ ¡£¸Ã×êÑгÁµã·ÖÎöÆäÖеÄÒ»¸ö×é¼þDoubleFeature£¬£¬£¬£¬£¬£¬£¬ËüÓÃÀ´ÌìÉú¿É×°ÖÃÔÚÖ¸±êÉ豸ÖеŤ¾ßÀàÐ͵ÄÈÕÖ¾ºÍ»ã±¨£¬£¬£¬£¬£¬£¬£¬²¢»áÍøÂç´óÁ¿¸÷ÖÖÀàÐ͵ÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://research.checkpoint.com/2021/a-deep-dive-into-doublefeature-equation-groups-post-exploitation-dashboard/