ÖÇÀû½ðÈÚÊг¡Î¯Ô±»áExchangeÔâµ½¹¥»÷²¢¹²ÏíIOC£»SentinelOne·¢ÏÖÕë¶ÔiOS¿ª·¢ÈËÔ±µÄ¹©Ó¦Á´¹¥»÷»î¶¯

Ðû²¼Ê±¼ä 2021-03-19

1.ÖÇÀû½ðÈÚÊг¡Î¯Ô±»áExchangeÔâµ½¹¥»÷²¢¹²ÏíIOC


1.jpg


ÖÇÀû½ðÈÚÊг¡Î¯Ô±»á£¨CMF£©³ÆÆäExchangeÔâµ½¹¥»÷²¢¹²ÏíIOC¡£CMFÊôÓÚÖÇÀû²ÆÕþ²¿£¬ÊÇÖÇÀûÒøÐкͽðÈÚ»ú¹¹µÄ¼à¹ÜÕߺͼì²éÔ±¡£CMFÓÚ3ÔÂ17ÈÕÐû²¼³ÂËߣ¬³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷£¬ºÚ¿ÍÀûÓÃ×î½üÅû¶µÄMicrosoft Exchange·þÎñÆ÷ÖеÄProxyLogon©¶´°²×°Web Shell²¢ÊÔͼÇÔȡƾ¾ÝÖ®ºó¡£ÎªÁË×ÊÖúÑо¿ÈËÔ±ºÍÆäËûMicrosoft Exchange¹ÜÀíÔ±£¬CMF»¹Ðû²¼ÁËWeb ShellµÄIOCºÍÔÚÔâµ½¹¥»÷µÄ·þÎñÆ÷ÉÏÕÒµ½µÄÅú´¦ÖÃÎļþ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/chiles-bank-regulator-shares-iocs-after-microsoft-exchange-hack/


2.SentinelOne·¢ÏÖÕë¶ÔiOS¿ª·¢ÈËÔ±µÄ¹©Ó¦Á´¹¥»÷»î¶¯


2.jpg


Äþ¾²¹«Ë¾SentinelOne·¢ÏÖÁËÐµĹ©Ó¦Á´¹¥»÷»î¶¯£¬Ê¹ÓÃÃûΪXcodeSpyµÄ¶ñÒâXcodeÏîÄ¿Õë¶ÔiOS¿ª·¢ÈËÔ±¡£XcodeÊÇApple´´½¨µÄ¼¯³É¿ª·¢»·¾³£¨IDE£©£¬¿ª·¢ÈËÔ±¿ÉÀûÓÃÆä´´½¨macOS¡¢iOS¡¢tvOSºÍwatchOSÓ¦Ó÷¨Ê½¡£Ôڸù¥»÷ÖУ¬ºÚ¿Í¿Ë¡Á˺Ϸ¨µÄTabBarInteractionÏîÄ¿£¬²¢Ìí¼ÓÁËÄ£ºýµÄ¶ñÒâRun½Å±¾XcodeSpy£¬ÒÔ½«¹¥»÷ÕßµÄC2·þÎñÆ÷Á¬½Óµ½¿ª·¢ÈËÔ±µÄÏîÄ¿¡£XcodeSpyÓÚ9ÔÂ4ÈÕÊ״α»ÉÏ´«µ½VirusTotal£¬Ñо¿ÈËÔ±»³ÒÉÕâÊǹ¥»÷ÕßΪ²âÊÔ¼ì²âÂʶø×Ô¼ºÉÏ´«µÄÑù±¾¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-xcodespy-malware-targets-ios-devs-in-supply-chain-attack/


3.Ñо¿ÈËÔ±·¢ÏÖÖ¼ÔÚÇÔÈ¡5GÏà¹Ø¼¼ÊõµÄDi¨¤nx¨´nÐж¯


3.jpg


Ñо¿ÈËÔ±·¢ÏÖÕë¶ÔµçÐŹ«Ë¾µÄDi¨¤nx¨´nÐж¯£¬Ö¼ÔÚÇÔÈ¡5G¼¼ÊõÏà¹ØµÄÃô¸ÐÊý¾ÝºÍÉÌÒµ»úÃÜ¡£ÔÚ²¿ÃŹ¥»÷ÖУ¬ºÚ¿Í´î½¨ÁËÒ»¸öαÔì³É»ªÎªÖ°ÒµÒ³ÃæµÄÐé¼ÙÍøÕ¾¡£Ñо¿ÈËÔ±³Æ£¬´Ë´ÎÐж¯ËùʹÓõÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½£¨TTP£©ÓëAPT×éÖ¯RedDeltaºÍÒ°Mustang PandaµÄÐж¯ÏàËÆ¡£McAfee ATRÍŶÓÌåÏÖ×î³õµÄѬȾý½éÉв»ÍêÈ«Çå³þ£¬µ«ÆäÍÆ²âºÚ¿Í¿ÉÄÜʹÓõöÓãÍøÕ¾À´·Ö·¢¶ñÒâÈí¼þ£¬²¢ÔÚ¹¥»÷µÄµÚ¶þ½×¶ÎÀûÓûùÓÚFlashµÄ¹¤¼þ¶ñÒâÈí¼þÔÚÊܺ¦ÕßµÄϵͳÉÏÖ´ÐÐ.NET¸ºÔØ¡£    


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115693/apt/chinese-hackers-5g.html


4.ŦԼÖݶà¸öÏØÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Êý¾Ý»òÒÑй¶


4.jpg


ŦԼÖݵݶû°ÍÄá¡¢ÈøÀ­ÍмӺÍÂ×˹ÀÕµÈÏØÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Êý¾Ý»òÒÑй¶¡£°Â¶û°ÍÄáÏØ¾¯³¤°ì¹«ÊÒÌåÏÖ¹¥»÷·¢ÉúÔÚ±¾ÖܶþÍíÉÏ9µã30·Ö×óÓÒ£¬ÌØÀïÏØ¹«¹²Äþ¾²ÍøÂçѬȾÁËÀÕË÷Èí¼þ£¬Ó°ÏìÁ˶à¸öÏØ³Ç¡£¾Ý±¨µÀ£¬Computer Aidedµ÷ÖΣ¨CAD£©·þÎñÊܵ½ÁËÓ°Ï죬ÆäÕýÔÚͨ¹ý±¸·Ý½øÐÐÖØ½¨¡£¸ÃÏØ¹ÙÔ±ÌåÏÖ£¬Ä¿Ç°±¸ÓÃϵͳÈÔÕý³£ÔËÐжøÇÒ¿ÉÒÔΪÌṩ911·þÎñ£¬µ«ÊDz¿ÃÅÊý¾Ý¿ÉÄÜÒѾ­Ð¹Â¶¡£


Ô­ÎÄÁ´½Ó£º

https://www.news10.com/news/tri-county-sheriff-dispatch-hit-with-ransomware-attack/


5.ÈÕ¾­ÖйúÏã¸Û·Ö¹«Ë¾³ÆÆäÔâµ½¹¥»÷£¬Óû§ÐÅÏ¢¿ÉÄÜй¶


5.jpg


ÈÕ¾­(Nikkei)±¾ÖÜÈýÌåÏÖÆäÖйúÏã¸Û·Ö¹«Ë¾Ôâµ½¹¥»÷£¬Óû§ÐÅÏ¢¿ÉÄÜй¶¡£´Ë´ÎʼþʼÓÚ2020Äê10Ô£¬¸Ã·Ö¹«Ë¾µÄ²¿Ãŵç×ÓÓʼþÕË»§Ô⵽δ¾­ÊÚȨµÄ·ÃÎÊ¡£ÈÕ¾­¹ú¼Ê°æ¡¢ÍøÂç°æºÍÈÕ¾­ÑÇÖÞ°æ¡¢ÈÕ¾­ÖйúµÄº£Íâ¶©»§µÄ¸öÈËÐÅÏ¢¿ÉÄÜÒѾ­Ð¹Â¶£¬°üÂÞÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¹«Ë¾Ãû³Æ¡¢µØÖ·ºÍµç»°ºÅÂ룬ÒÔ¼°²¿Ãſͻ§µÄÐÅÓÿ¨ÐÅÏ¢¡£Ä¿Ç°£¬ÈÕ¾­Öйú¹«Ë¾Òѽ«´Ëʼþ³ÂË߸øÏã¸ÛµÄ¸öÈËÐÅÏ¢±£»¤Õþ¸®¡£


Ô­ÎÄÁ´½Ó£º

https://asia.nikkei.com/Business/Companies/Nikkei-s-Hong-Kong-affiliate-hit-by-unauthorized-access


6.Unit42Ðû²¼2021ÄêÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö³ÂËß


6.jpg


Unit42Ðû²¼ÁË2021ÄêÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö³ÂËߣ¬Ö¼ÔÚÆÀ¹ÀÀÕË÷Èí¼þ¹¥»÷µÄ·¶Î§²¢Ìṩ¿É½µµÍ·çÏյIJÙ×÷²½Öè¡£³ÂËßÖ¸³ö£¬Æ½¾ùÊê½ð´Ó2019ÄêµÄ115123ÃÀÔªÔö¼Óµ½2020ÄêµÄ312493ÃÀÔª£¬×î¸ßÊê½ð´Ó1500ÍòÃÀÔªÔö³¤µ½3000ÍòÃÀÔª£»ºÚ¿ÍÖ÷ÒªÕë¶ÔÒ½ÁƱ£½¡²¿ÃÅ£»Ë«ÖØÀÕË÷µÄÇé¿öÓÐËùÔö¼Ó£¬Áè¼Ý16ÖÖ²îÒìµÄÀÕË÷Èí¼þ±äÖÖ¶¼ÔÚʹÓÃÕâÖÖÒªÁ죬ÆäÖÐNetwalkerÕ¼±È×î´ó£¬Ð¹Â¶ÁËÒ»°Ù¶àÃûÊܺ¦ÕßµÄÐÅÏ¢¡£    


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/ransomware-threat-assessments/