¶íÂÞ˹µçÐÅRostelecomÐ®ÖÆ¶à¸öÆóÒµµÄÁ÷Á¿£»£»£»£»£» £»Î¢ÈíÐû²¼Emotet¹¥»÷°¸Àý±¨¸æ

Ðû²¼Ê±¼ä 2020-04-07

1.DarkHotelʹÓÃÉîÐÅ·þVPNÎó²î¹¥»÷ÎÒ¹úµÄÕþ¸®»ú¹¹


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


¿ËÈÕ£¬£¬£¬£¬ÓÐÐÂÎųƺڿÍ×éÖ¯Darkhotel£¨APT-C-06£©Ê¹ÓÃÉîÐÅ·þSSL VPN×°±¸Îó²î¹¥»÷ÎÒ¹úµÄÕþ¸®»ú¹¹¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯Ê¼ÓÚ3Ô£¬£¬£¬£¬ÓÐÁè¼Ý200̨VPNЧÀÍÆ÷Ôâµ½¹¥»÷£¬£¬£¬£¬ÆäÖÐ174̨λÓÚ±±¾©ºÍÉϺ£µÄÕþ¸®»ú¹¹ÍøÂçÒÔ¼°²¿·ÖÖйúפÍâ»ú¹¹£¬£¬£¬£¬4Ô³õ¹¥»÷Ì¬ÊÆÓÖÔÙÏò±±¾©¡¢ÉϺ£Ïà¹ØÕþ¸®»ú¹¹ÉìÕÅ¡£¡£¡£¡£¡£ÉîÐÅ·þ¹Ù·½ÒÑÓÚ4ÔÂ6ÈÕÕýʽÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬²¢Æô¶¯Îó²îÏìÓ¦¡£¡£¡£¡£¡£¸ÃÎó²îÊÇ4ÔÂ3ÈÕ360ÏòÉîÐÅ·þÓ¦¼±Çå¾²ÏìÓ¦ÖÐÐı¨¸æµÄÎó²î£¨SRC-2020-281£©£¬£¬£¬£¬ÎªSSL VPN×°±¸Windows¿Í»§¶ËÉý¼¶Ä£¿£¿£¿ £¿éÊðÃûÑéÖ¤»úÖÆµÄȱÏÝ£¬£¬£¬£¬µ«¸ÃÎó²îʹÓÃÌõ¼þÊDZØÐèÒѾ­»ñÈ¡¿ØÖÆSSL VPN×°±¸µÄȨÏÞ£¬£¬£¬£¬Òò´ËʹÓÃÄѶȽϸß¡£¡£¡£¡£¡£ÉîÐÅ·þÈ·ÈÏÔËÐй̼þ°æ±¾M6.3R1ºÍM6.1µÄSSL VPN×°±¸Ò×Êܹ¥»÷£¬£¬£¬£¬½¨ÒéÓû§¾ÙÐÐÅŲéºÍÓ¦Óò¹¶¡¸üС£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/darkhotel-hackers-use-vpn-zero-day-to-compromise-chinese-government-agencies/


2.¶íÂÞ˹µçÐŹ«Ë¾RostelecomÐ®ÖÆ¶à¸öÆóÒµµÄ»¥ÁªÍøÁ÷Á¿


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


4ÔÂ1ÈÕ¶íÂÞ˹µçÐŹ«Ë¾RostelecomÐ®ÖÆÁ˹ȸèµÈ¹«Ë¾µÄ»¥ÁªÍøÁ÷Á¿£¬£¬£¬£¬¸ÃÊÂÎñÓ°ÏìÁËÌìÏÂÉÏ×î´óµÄ200¶à¸öCDNÍøÂç¼°ÔÆÍйÜЧÀÍÉÌ£¬£¬£¬£¬Ò»Á¬ÁËԼĪ1¸öСʱ¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÆóÒµ°üÀ¨¹È¸è¡¢ÑÇÂíÑ·¡¢Facebook¡¢Akamai¡¢Cloudflare¡¢GoDaddy¡¢Digital Ocean¡¢Joyent¡¢LeaseWeb¡¢HetznerºÍLinodeµÈ×ÅÃû¹«Ë¾¡£¡£¡£¡£¡£ÕâÊÇÒ»´Îµä·¶µÄBGPÐ®ÖÆÊÂÎñ£¬£¬£¬£¬¸ÃÊÂÎñµÄÔµ¹ÊÔ­ÓÉ¿ÉÄÜÊÇRostelecomµÄÄÚ²¿Á÷Á¿ÐÞÕýϵͳ¹ýʧµØ½«²»×¼È·µÄBGP·ÓÉ̻¶ÔÚ¹«ÍøÉÏ£¬£¬£¬£¬²¢ÇÒ±»ÉÏÓι©Ó¦É̹㲥Ôì³ÉµÄ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/russian-telco-hijacks-internet-traffic-for-google-aws-cloudflare-and-others/


3.΢ÈíÐû²¼Emotet¹¥»÷Fabrikam¹«Ë¾µÄ°¸ÀýÑо¿±¨¸æ


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


΢ÈíÔÚ¼ì²âºÍÏìӦС×飨DART£©°¸Àý±¨¸æ002ÖзÖÏíÁËFabrikam¹«Ë¾ÔâÊÜEmotet¹¥»÷µÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¸Ã¹¥»÷ʼÓÚÍøÂç´¹ÂÚÓʼþ£¬£¬£¬£¬µ±ÄÚ²¿Ô±¹¤»á¼ûÁË´¹ÂÚÐÅÏ¢ºó£¬£¬£¬£¬EmotetѬȾÁËÆäϵͳ²¢ºáÏòѬȾÁËÍ³Ò»ÍøÂçÖÐµÄÆäËüϵͳ¡£¡£¡£¡£¡£¸Ã²¡¶¾×èÖ¹ÁËͨ¹ýÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷£¨C2£©¾ÙÐа´ÆÚ¸üжø±»·À²¡¶¾½â¾ö¼Æ»®¼ì²âµ½µÄÇéÐΣ¬£¬£¬£¬²¢ÇÒͨ¹ýʹWindowsÉè±¹ØÁ¬ÄCPUʹÓÃÂʵִﱥºÍÀ´×èÖ¹½¹µãЧÀÍ£¬£¬£¬£¬µ¼Ö¸Ã×éÖ¯µÄ»ù±¾Ð§ÀͺÍÍøÂçÖÐÖ¹ÁË¿ìÒªÒ»ÖܵÄʱ¼ä¡£¡£¡£¡£¡£CPUʹÓÃÂÊÒ»Ö±±¥ºÍʹµÃÅÌËã»ú¹ýÈÈ£¬£¬£¬£¬µ¼ÖÂÄÚ²¿ÏµÍ³¿¨ËÀ¡¢ÖØÆôºÍÍøÂçÅþÁ¬Ï½µ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýÇÔÈ¡ÖÎÀíÔ±ÕÊ»§Æ¾Ö¤¾ÙÐкáÏòÒÆ¶¯£¬£¬£¬£¬ÔÚ×î³õѬȾºóµÄ8ÌìÖ®ÄÚ£¬£¬£¬£¬FabrikamµÄÕû¸öÍøÂç¾Í±»¹Ø±ÕÁË¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/security/blog/wp-content/uploads/2020/04/Case-study_Full-Operational-Shutdown.pdf


4.PayPalºÍVenmoÓû§½»Á÷Õ½ÂÔÎó²îµ¼ÖºڿÍÐ®ÖÆÓû§


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÆÕÁÖ˹¶Ù´óѧµÄÑо¿Ö°Ô±·¢Ã÷17¼ÒÖ÷Òª¹«Ë¾£¬£¬£¬£¬ÆäÖаüÀ¨Amazon¡¢Paypal¡¢Venmo¡¢Blizzard¡¢Adobe¡¢eBay¡¢SnapchatºÍYahoo£¬£¬£¬£¬ÔÊÐíÓû§Í¨¹ý·¢Ë͵½ÓëËûÃÇÕÊ»§Ïà¹ØÁªµÄµç»°ºÅÂëµÄ¶ÌÐÅÀ´ÖØÖÃÃÜÂ룬£¬£¬£¬ÕâÒâζ×ÅÈôÊǺڿÍͨ¹ýSIM½»Á÷¹¥»÷¿ØÖÆÁËÊܺ¦ÕßµÄÊÖ»úºÅÂ룬£¬£¬£¬ÄÇôºÚ¿Í¾Í¿ÉÒÔʹÓÃÕâÐ©ÍøÕ¾ºÍЧÀÍÈëÇÖÊܺ¦ÕßµÄÔÚÏßÕÊ»§¡£¡£¡£¡£¡£ÔÚ½Óµ½Ñо¿Ö°Ô±µÄÖÒÑÔÖ®ºó£¬£¬£¬£¬°üÀ¨Adobe¡¢±©Ñ©¡¢Ebay¡¢Î¢ÈíºÍSnapchatÔÚÄÚµÄһЩ¹«Ë¾ÐÞ¸´ÁËÕâÒ»ÎÊÌ⣬£¬£¬£¬µ«ÈÔÓÐһЩ¹«Ë¾Ã»ÓÐÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬ÀýÈçÔÊÐíÓû§¾ÙÐÐÉúÒâ²¢ÇÒÓëÒøÐÐÕÊ»§»òÐÅÓÿ¨¹ØÁªµÄÓ¦ÓóÌÐòPaypalºÍVenmo¡£¡£¡£¡£¡£ÕâÁ½¼Ò¹«Ë¾ÉÐδ¾Í´Ë½ÒÏþ̸ÂÛ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.vice.com/en_us/article/pke9zk/paypal-and-venmo-are-letting-sim-swappers-hijack-accounts


5.AppleÐÞ¸´SafariÖжà¸öÎó²î£¬£¬£¬£¬¿É±»ºÚ¿Í¿ØÖÆÉãÏñÍ·


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Çå¾²Ñо¿Ö°Ô±Ryan PickrenÔÚSafariÖз¢Ã÷ÁË7¸ö0day£¬£¬£¬£¬°üÀ¨CVE-2020-3852¡¢CVE-2020-3864¡¢CVE-2020-3865¡¢CVE-2020-3885¡¢CVE-2020-3887£¬£¬£¬£¬CVE-2020-9784ºÍCVE-2020-9787¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÆäÖеÄ3¸öÎó²î×éºÏ£¬£¬£¬£¬»á¼ûiOSºÍmacOSÉè±¹ØÁ¬ÄÉãÏñÍ·ºÍÂó¿Ë·ç²¢¼àÊÓÓû§¡£¡£¡£¡£¡£Õâ3¸öÎó²îÓëSafariÆÊÎöURI¡¢ÖÎÀíWebÔ´ÒÔ¼°³õʼ»¯Çå¾²ÉÏÏÂÎĵķ½·¨ÓйØ£¬£¬£¬£¬¿ÉÔÊÐí¶ñÒâÍøÕ¾ÔÚSafariÉÏαװ³ÉÊÜÐÅÈεÄÍøÕ¾Ìᳫ¹¥»÷¡£¡£¡£¡£¡£AppleÔÚ1ÔÂ28ÈÕÐû²¼µÄSafari 13.0.5ÖÐÐÞ²¹ÁËÕâ3¸öÎó²î£¬£¬£¬£¬²¢ÔÚ3ÔÂ24ÈÕÐû²¼µÄSafari 13.1ÖÐÐÞ¸´ÁËÆäÓàÎó²î¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/vulnerabilities---threats/researcher-hijacks-ios-macos-camera-with-three-safari-zero-days/d/d-id/1337486


6.EuropolÓëInterpolÐû²¼ÓëCOVID-19Ïà¹ØµÄÍøÂç·¸·¨×ª´ï


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Å·ÖÞÐ̾¯×éÖ¯£¨Europol£©ÔÚ×îеÄÇå¾²×ÉѯÖÐÏêϸÏÈÈÝÁËCOVID-19ÓйصÄÍøÂç·¸·¨»î¶¯£¬£¬£¬£¬ÁгöÁË´ÙʹÓëCOVIDÓйصÄÍøÂç·¸·¨»î¶¯×ª±äµÄÁù¸öÒòËØ£º¶ÔijЩÉÌÆ·¡¢·À»¤×°±¸ºÍÒ©Æ·µÄ¸ßÐèÇ󣻣»£»£»£» £»¹«ÃñÔ½À´Ô½ÒÀÀµÊý×Ö½â¾ö¼Æ»®¾ÙÐÐÔ¶³Ì°ì¹«£»£»£»£»£» £»½¹ÂǺͿ־åÐÄÀí£»£»£»£»£» £»ÊÕÖ§Å·Ã˵ÄÖ°Ô±Á÷¶¯ïÔÌ­£»£»£»£»£» £»¹«¹²³¡ºÏ»î¶¯ÊÜÏÞ£¬£¬£¬£¬Ê¹Ò»Ð©·¸·¨»î¶¯×ªÒƵּÒÍ¥»òÔÚÏßÇéÐΣ»£»£»£»£» £»Å·ÃËijЩ²»·¨ÉÌÆ·µÄ¹©Ó¦ïÔÌ­¡£¡£¡£¡£¡£Óë´Ëͬʱ£¬£¬£¬£¬¹ú¼ÊÐ̾¯×éÖ¯£¨Interpol£©ÖÒÑÔÀÕË÷Èí¼þ¹¥»÷ÒѾ­×îÏÈÕë¶ÔÒ½ÔºµÈÓëCOVID-19ÓÐ¹ØµÄÆäËü»ú¹¹¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.europol.europa.eu/publications-documents/catching-virus-cybercrime-disinformation-and-covid-19-pandemic