Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!

Æðµ×¹ú¼Ò¼¶APT×éÖ¯£ºÏìβÉߣ¨APT-Q-39£©

ʱ¼ä£º2021-11-05 ×÷Õߣº»¢·ûÖÇ¿â

·ÖÏíµ½£º

Æðµ×¹ú¼Ò¼¶APT×éÖ¯£ºÏìβÉߣ¨APT-Q-39£©

    ±¾ÎÄ3758×ÖÔĶÁÔ¼Ðè11·ÖÖÓ

    ¹ú¼Ò¼¶APT£¨AdvancedPersistentThreat £¬£¬£¬£¬£¬¸ß¼¶Ò»Á¬ÐÔÍþв£©×éÖ¯ÊÇÓйú¼ÒÅä¾°Ö§³ÖµÄ¶¥¼âºÚ¿ÍÍÅ»ï £¬£¬£¬£¬£¬×¨×¢ÓÚÕë¶ÔÌØ¶¨Ä¿µÄ¾ÙÐкã¾ÃµÄÒ»Á¬ÐÔÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£

    Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!Æìϵĸ߼¶ÍþвÑо¿ÍŶӺìÓêµÎ£¨RedDripTeam£©Ã¿Äê»áÐû²¼È«ÇòAPTÄ걨¡¾1¡¿¡¢Öб¨ £¬£¬£¬£¬£¬¶ÔÎôʱ¸÷´óAPTÍÅ»ïµÄÔ˶¯¾ÙÐÐÆÊÎö×ܽá¡£¡£¡£¡£¡£¡£¡£¡£

    »¢·ûÖÇ¿âÌØÔ¼Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÆìϺìÓêµÎÍÅ¶Ó £¬£¬£¬£¬£¬¿ªÉè“Æðµ×¹ú¼Ò¼¶APT×éÖ¯”À¸Ä¿ £¬£¬£¬£¬£¬Öð¸öÆðµ×È«Çò¸÷µØÇø»îÔ¾µÄÖ÷ÒªAPT×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡£±¾´ÎËø¶¨ÊÇÄÏÑǵØÇøÁíÒ»¸öÖÕÄê»îÔ¾µÄ¹ú¼Ò¼¶ºÚ¿ÍÍŻÏìβÉߣ¨Sidewinder£©¡£¡£¡£¡£¡£¡£¡£¡£

    06

    ÏìβÉß

    ÏìβÉßÊǾݳÆÓÐÄÏÑÇÅä¾°µÄAPT×éÖ¯ £¬£¬£¬£¬£¬2012ÄêÖÁ½ñÒ»Ö±´¦ÓÚ»îԾ״̬¡£¡£¡£¡£¡£¡£¡£¡£

    ÏìβÉß×éÖ¯Ö÷ÒªÕë¶Ô°Í»ù˹̹¡¢Öйú¡¢°¢¸»º¹¡¢Äá²´¶û¡¢ÃϼÓÀ­µÈ¹ú¼ÒÕö¿ª¹¥»÷ £¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡Õþ¸®Íâ½»»ú¹¹¡¢¹ú·À¾üʲ¿·Ö¡¢¸ßµÈ½ÌÓý»ú¹¹µÈÁìÓòµÄÉñÃØÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÄÚ²¿¸ú×Ù±àºÅΪAPT-Q-39

Æðµ×¹ú¼Ò¼¶APT×éÖ¯£ºÏìβÉߣ¨APT-Q-39£©

    Åä¾°

    ÏìβÉß £¬£¬£¬£¬£¬ÓÖÃûSidewinder £¬£¬£¬£¬£¬ÓÉÍâÑóÇå¾²³§ÉÌ¿¨°Í˹»ùÔÚ2018ÄêµÚÒ»¼¾¶ÈAPTÇ÷ÊÆ±¨¸æÖÐÂÊÏÈÅû¶¡£¡£¡£¡£¡£¡£¡£¡£

    2018Äê5Ô £¬£¬£¬£¬£¬º£ÄÚijÇå¾²³§ÉÌÒ²±¨¸æÁËÏìβÉßAPT×éÖ¯Õë¶Ô°Í»ù˹̹µÈÄÏÑǹú¼Ò¾üÊÂÄ¿µÄµÄ¶¨Ïò¹¥»÷Ô˶¯¡£¡£¡£¡£¡£¡£¡£¡£¸ÃAPT×éÖ¯×îÔç¹¥»÷Ô˶¯¿É×·Ëݵ½2012Äê £¬£¬£¬£¬£¬ÖÁ½ñÒ»Ö±´¦ÓÚ»îԾ״̬¡£¡£¡£¡£¡£¡£¡£¡£

    ÏìβÉßAPT×éÖ¯Ö÷ÒªÕë¶Ô°Í»ù˹̹¡¢Öйú¡¢°¢¸»º¹¡¢Äá²´¶û¡¢ÃϼÓÀ­µÈ¹ú¼ÒÕö¿ª¹¥»÷ £¬£¬£¬£¬£¬ÒÔÇÔÈ¡Õþ¸®Íâ½»»ú¹¹¡¢¹ú·À¾üʲ¿·Ö¡¢¸ßµÈ½ÌÓý»ú¹¹µÈÁìÓòµÄÉñÃØÐÅϢΪĿµÄ £¬£¬£¬£¬£¬¹¥»÷Ô˶¯¾ßÓÐÇ¿ÁÒµÄÕþÖÎÅä¾°¡£¡£¡£¡£¡£¡£¡£¡£

    ½üÄêÀ´ £¬£¬£¬£¬£¬ÏìβÉßAPT×éÖ¯³£ÓõÄÎó²îΪCVE-2017-0199ºÍCVE-2017-11882¡£¡£¡£¡£¡£¡£¡£¡£µ«ÔÚÀúÊ·¹¥»÷Ô˶¯ÖÐ £¬£¬£¬£¬£¬Ò²Ê¹ÓùýÆäËûÎó²î £¬£¬£¬£¬£¬ºÃ±ÈÕë¶ÔAndroidƽ̨µÄ¶ñÒâÈí¼þ»ñÈ¡rootȨÏÞʱʹÓÃÁËCVE-2019-2215 £¬£¬£¬£¬£¬ÒÔ¼°ÔÚÒ»´Î¶ÔÎÒ¹úij¸ßУµÄ¶¨Ïò¹¥»÷ÖÐʹÓÃÁËä¯ÀÀÆ÷Îó²îCVE-2020-0674¡£¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸öÎó²îÔÚÆäʹÓõÄʱ¼ä½ÔÊôÓÚÒѹûÕæÅû¶µÄÎó²î £¬£¬£¬£¬£¬²¢ÇÒ´ÓÆäÏà¹ØµÄʹÓôúÂëÀ´¿´ £¬£¬£¬£¬£¬±£´æ¸Ã×éÖ¯ÒÀÍÐÓÚÍøÂç¾üÆ÷É̵ĿÉÄÜ¡£¡£¡£¡£¡£¡£¡£¡£

    ¹¥»÷ÊÖ¶ÎÓ빤¾ß

    ÏìβÉßAPT×éÖ¯³£Í¨¹ý´¹ÂÚÍøÕ¾ÇÔÈ¡¹¥»÷Ä¿µÄ»ú¹¹Ïà¹ØÖ°Ô±µÄµÇ¼ƾ֤ £¬£¬£¬£¬£¬²¢Í¨¹ýÓã²æÓʼþͶµÝLNK¿ì½Ý·½·¨Îļþ»òÕßЯ´øÎó²îµÄ¶ñÒâÎĵµ¡£¡£¡£¡£¡£¡£¡£¡£

    ÕâЩ¶ñÒâÎļþÔòͨ¹ýÖ´ÐаüÀ¨js´úÂëµÄhtaÎļþ»òÕßjs¾ç±¾·´Éä¼ÓÔØC#Ä £¿£¿£¿£¿£¿£¿é £¬£¬£¬£¬£¬È»ºóÔÚÊܺ¦Õß»úеÉÏÊÍ·ÅľÂí³ÌÐò £¬£¬£¬£¬£¬Ä¾Âí³ÌÐòͨ³£Îª¶ñÒâdllÎļþ £¬£¬£¬£¬£¬Ê¹ÓöÔϵͳÖÐÕý³£exeÎļþµÄdll²à¼ÓÔØÊÖÒÕ£¨¼´“°×¼ÓºÚ”£©Æô¶¯ÔËÐС£¡£¡£¡£¡£¡£¡£¡£

    £¨Ò»£©¹¥»÷ÊÖ¶Î

    1.´¹ÂÚÍøÕ¾

    ÏìβÉߣ¨Sidewinder£©Íйܴ¹ÂÚÍøÒ³µÄЧÀÍÆ÷ÓòÃû»áÄ£Äâ¹¥»÷Ä¿µÄÍøÕ¾µÄÓòÃû £¬£¬£¬£¬£¬ºÃ±È´¹ÂÚÓòÃû“mail-nepalgovnp[.]duckdns[.]org”ÓÃÀ´Î±×°ÎªÄá²´¶ûÕþ¸®Ê¹ÓõÄÓòÃû“mail[.]nepal[.]gov[.]np”¡£¡£¡£¡£¡£¡£¡£¡£´¹ÂÚÍøÒ³´Ó¹¥»÷Ä¿µÄµÄÓʼþÍøÕ¾¸´ÖƶøÀ´ £¬£¬£¬£¬£¬¾­ÓÉÒ»¶¨µÄÐ޸ĺóÓÃÀ´ÇÔȡĿµÄ»ú¹¹Ïà¹ØÖ°Ô±µÄÓÊÏäµÇ¼ƾ֤¡£¡£¡£¡£¡£¡£¡£¡£

    ÕâЩ´¹ÂÚÍøÒ³ÔÚÊܺ¦Õß·¢Ë͵Ǽƾ֤ºó´ó´ó¶¼¶¼»áÖØ¶¨Ïòµ½Ô­Ê¼µÄÓʼþÍøÕ¾ £¬£¬£¬£¬£¬ÉÐÓÐÒ»²¿·Ö»áÖØ¶¨ÏòΪÏÔʾÎĵµ»òÕßÐÂÎÅÍøÒ³ £¬£¬£¬£¬£¬ÎĵµÓëÐÂÎŵÄÄÚÈÝÒ»Ñùƽ³£ÓëCOVID-19ÒßÇéºÍÄÏÑǵØÇøµÄÁìÍÁÕù¶ËÓйØ¡£¡£¡£¡£¡£¡£¡£¡£

    2.Óã²æ¹¥»÷

    Í¨¹ýÓã²æÓʼþͶµÝ¶ñÒâÎĵµÊÇÏìβÉߣ¨Sidewinder£©×éÖ¯×î³£ÓõĹ¥»÷ÊÖ¶Î £¬£¬£¬£¬£¬ÕâЩ×÷ΪÓÕ¶üµÄ¶ñÒâÎĵµ³£¼ûµÄÓÐÈçϼ¸ÖÖÀàÐÍ£º

    (1)LNKÎļþ

    LNKÎļþµÄÄ¿µÄ³ÌÐò·¾¶±»Ö¸¶¨ÎªÓÃmshta.exeÔ¶³Ì¼ÓÔØÔËÐÐhtaÎļþ £¬£¬£¬£¬£¬½ø¶øÊÍ·ÅÓÕ¶üÎĵµºÍÍê³ÉºóÐøµÄ¶ñÒâÈí¼þÖ²Èë²Ù×÷¡£¡£¡£¡£¡£¡£¡£¡£

    (2)Я´øÎó²îµÄOfficeÎĵµ £¬£¬£¬£¬£¬ÆµÈÔʹÓÃÎó²îCVE-2017-11882ºÍCVE-2017-0199¡£¡£¡£¡£¡£¡£¡£¡£

    ÔÚÏìβÉß×éÖ¯ÖÆ×÷µÄ¶ñÒâOfficeÎĵµÖÐ £¬£¬£¬£¬£¬Ò»ÀàÊÇʹÓÃCVE-2017-11882Îó²îÖ´ÐÐ×ÔÉíÊͷŵĻòÕßÔ¶³ÌÏÂÔØµÄhtaÎļþ»òjs¾ç±¾ £¬£¬£¬£¬£¬´Ó¶øÍê³ÉºóÐøµÄ¶ñÒâÈí¼þÖ²Èë²Ù×÷£»£»£»£»£»£»ÁíÒ»ÀàÔòÊÇʹÓÃCVE-2017-0199Îó²îÔ¶³Ì¼ÓÔØÐ¯´øCVE-2017-11882Îó²îµÄÎĵµ¡£¡£¡£¡£¡£¡£¡£¡£

    £¨¶þ£©Ê¹Óù¤¾ß¼°ÊÖÒÕÌØÕ÷

    ÏìβÉß×éÖ¯¾ßÓÐWindowsºÍAndroid˫ƽ̨¹¥»÷ÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£¡£ÔÚWindowsƽ̨µÄ¹¥»÷ÊÖ·¨½ÏÁ¿Àο¿ £¬£¬£¬£¬£¬ÒÔLNKÎļþ»òÕßÎó²îÎĵµÎª¹¥»÷Èë¿Ú £¬£¬£¬£¬£¬Í¨¹ýÖ´ÐаüÀ¨js´úÂëµÄhtaÎļþ»òjs¾ç±¾·´Éä¼ÓÔØC#dllÎļþ £¬£¬£¬£¬£¬×îºó½èÓɸÃdllÎļþÖ²ÈëľÂí³ÌÐò×é¼þ¡£¡£¡£¡£¡£¡£¡£¡£

    ÏìβÉß×éÖ¯µÄ¹¥»÷Á÷³ÌÕûÌå»ù±¾ÎÈ¹Ì £¬£¬£¬£¬£¬µ«ÎªÁ˶Կ¹Ñо¿Ö°Ô±µÄ·¢Ã÷Åû¶ºÍÇå¾²Èí¼þµÄ¼ì²â²éɱ £¬£¬£¬£¬£¬½üÄêÀ´¸Ã×éÖ¯Ò²Éý¼¶Á˹¥»÷ÊÖ·¨ £¬£¬£¬£¬£¬ºÃ±È£º

    £¨1£©ºóÐøµÄľÂí³ÌÐò×é¼þ²»ÔÙÖ±½ÓÔÚÍâµØÊÍ·Å £¬£¬£¬£¬£¬¶øÊÇ´ÓÔ¶³ÌЧÀÍÆ÷ÏÂÔØ £¬£¬£¬£¬£¬Ê¹µÃ¸Ã×éÖ¯ÔÚ¹¥»÷Àú³ÌÖÐʵʱ¹ØÍ£Ð§ÀÍÆ÷ £¬£¬£¬£¬£¬½µµÍ´úÂë̻¶µÄΣº¦£»£»£»£»£»£»

    £¨2£©Ìá¸ßÁË´úÂë»ìÏý¶È £¬£¬£¬£¬£¬ºÃ±È×÷ΪÖÐÐÄ×é¼þµÄjs´úÂëͨ¹ýÒýÈë×Ô½ç˵µÄBase64±àÂë¾ÙÐлìÏý £¬£¬£¬£¬£¬C#×é¼þÖк¯ÊýŲÓÃÓÉÖ±½ÓÒýÓÃϵͳAPI±äΪÓÃ×Ô½ç˵·±Ôӵĺ¯ÊýÃû·â×°ËùÐèŲÓõÄAPI¡£¡£¡£¡£¡£¡£¡£¡£

    £¨3£©ÏìβÉß×éÖ¯Õë¶ÔAndroidƽ̨µÄ¶ñÒâÈí¼þͨ¹ýÎó²îʹÓûñÈ¡rootȨÏÞ»òÕßÓÕÆ­Êܺ¦ÕßÊÚȨÒÔ×°ÖÃľÂí³ÌÐòcallCam¡£¡£¡£¡£¡£¡£¡£¡£Ä¾Âí³ÌÐòÍøÂç×°±¸²ÎÊý¡¢Î»Öá¢Îļþ¡¢ÕË»§¡¢Éç½»Èí¼þÊý¾ÝµÈÃô¸ÐÐÅÏ¢²¢ÒÔ¼ÓÃÜÐÎʽÉÏ´«µ½C&CЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£¡£

    ÖøÃû¹¥»÷ÊÂÎñ

    £¨Ò»£©ÏìβÉߣ¨Sidewinder£©Ê×´ÎÆØ¹â

    2018Äê4Ô £¬£¬£¬£¬£¬¿¨°Í˹»ù2018ÄêµÚÒ»¼¾¶ÈAPTÇ÷ÊÆ±¨¸æÌáµ½ÁËÃûΪ“Sidewinder”µÄAPT×éÖ¯¡¾2¡¿ £¬£¬£¬£¬£¬¸Ã×éÖ¯¹¥»÷Ä¿µÄΪ°Í»ù˹̹µÄ¾üʲ¿·Ö £¬£¬£¬£¬£¬×îÔç¿É×·ËÝÖÁ2012Äê¡£¡£¡£¡£¡£¡£¡£¡£

    2018Äê5ÔÂ23ÈÕ £¬£¬£¬£¬£¬º£ÄÚijÇå¾²³§ÉÌÐû²¼±¨¸æÅû¶ÁËÏìβÉß×éÖ¯Õë¶ÔÄÏÑǹ¥»÷Ô˶¯µÄϸ½Ú¡¾3¡¿£ºÊ¹ÓÃCVE-2017-11882Îó²îÔ¶³Ì¼ÓÔØ²¢Ö´ÐÐhtaÎļþ £¬£¬£¬£¬£¬ÎļþÖеľ籾ŲÓÃpowershellÏÂÁîÊÍ·ÅÆäÖÐÉúÑĵÄľÂí³ÌÐò¡£¡£¡£¡£¡£¡£¡£¡£

    £¨¶þ£©2019ÄêÕë¶ÔÎÒ¹úµÄ¶à´Î¶¨Ïò¹¥»÷

    2019Äê7Ô £¬£¬£¬£¬£¬º£ÄÚijÇå¾²³§ÉÌ·¢Ã÷ÏìβÉß×éÖ¯Õë¶ÔÎÒ¹úµÄ¶¨Ïò¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¡£Ôڴ˴ι¥»÷ÊÂÎñÖÐ £¬£¬£¬£¬£¬ÏìβÉßÒÔÎÒ¹ú¹ú·À²¿¹ú¼ÊÏàÖú²¿·Ö·¢Ë͵Ä֪ͨÎļþΪÓÕ¶ü £¬£¬£¬£¬£¬ÏòËû¹úפ»ªÊ¹¹ÝÖ°Ô±Ìᳫ¹¥»÷¡¾4¡¿¡£¡£¡£¡£¡£¡£¡£¡£

    ¹¥»÷ʹÓõÄЯ´øCVE-2017-11882Îó²îµÄ¶ñÒâÎĵµÎªRTFÃûÌÃÎļþ £¬£¬£¬£¬£¬Îļþ·­¿ªºó»á×Ô¶¯ÊÍ·ÅPackage¹¤¾ßÉúÑĵÄjs¾ç±¾ £¬£¬£¬£¬£¬Îó²îʹÓúóÖ´ÐÐÊͷŵÄjs¾ç±¾ £¬£¬£¬£¬£¬¾ç±¾¿½±´WindowsϵͳÖÐÕý³£µÄexeÎļþ £¬£¬£¬£¬£¬²¢ÊͷżÓÃܵÄľÂí³ÌÐòÊý¾ÝºÍÓÃÓÚ¼ÓÔØÄ¾Âí³ÌÐòµÄ¶ñÒâdllÎļþ £¬£¬£¬£¬£¬Ó뿽±´µÄexeÎļþ×é³É“°×¼ÓºÚ”×éºÏ¡£¡£¡£¡£¡£¡£¡£¡£

    ÒÔºó £¬£¬£¬£¬£¬ÏìβÉß¶à´ÎÕë¶ÔÎÒ¹úµÄ¶¨Ïò¹¥»÷±»Åû¶¡¾5¡¢6¡¿ £¬£¬£¬£¬£¬°üÀ¨Õë¶Ôº£ÄÚij¹ú·À¿ÆÑÐÆóÒµ £¬£¬£¬£¬£¬ÏòÆäÄÚ²¿·¢ËÍÐéαµÄÇå¾²±£ÃÜÊÖ²áºÍÖÎÀíÎļþ£»£»£»£»£»£»½«Î±×°µÄ¡¶ÖйúÈËÃñ½â·Å¾üÎÄÖ°Ö°Ô±ÌõÀý¡·µÄÎĵµÍ¶·ÅÖÁ¹ú¼ÒÕþ¸®²¿·Ö£»£»£»£»£»£»Õë¶Ô¹ú·À¼°¾üʵÈÏà¹Ø²¿·Ö £¬£¬£¬£¬£¬ÏòÆä·¢ËÍÐéαµÄ“µÚ¾Å½ì±±¾©ÏãɽÂÛ̳¾Û»á”Òé³Ì¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷ÊÂÎñÖÐ £¬£¬£¬£¬£¬ÏìβÉß½ÓÄÉÁËÓë¹¥»÷Ëû¹úפ»ªÊ¹¹ÝÏàͬµÄÊÖ·¨¡£¡£¡£¡£¡£¡£¡£¡£

    £¨Èý£©Òƶ¯¶Ë¹¥»÷ÎäÆ÷ÆØ¹â

    2020Äê1Ô £¬£¬£¬£¬£¬ÍâÑóÇå¾²³§ÉÌÇ÷ÊÆ¿Æ¼¼Åû¶ÁËÏìβÉß×éÖ¯Õë¶ÔAndroidƽ̨µÄ¶ñÒâÈí¼þ¡¾7¡¿¡£¡£¡£¡£¡£¡£¡£¡£

    ÕâЩ¶ñÒâÈí¼þÔÚGooglePlayÓ¦ÓÃÊÐËÁÖÐαװΪͼƬºÍÎļþÖÎÀíÆ÷¹¤¾ß £¬£¬£¬£¬£¬¾­ÓÉÁ½¸ö½×¶ÎµÄÏÂÔØÀú³ÌÔÚÊܺ¦Õß×°±¸ÉÏÖ²Èë×îÖÕµÄľÂí³ÌÐòcallCam¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÒ»¸ö¶ñÒâÈí¼þͨ¹ýʹÓÃCVE-2019-2215Îó²îºÍMediaTek-SU»ñÈ¡rootȨÏÞ £¬£¬£¬£¬£¬¿ÉÒÔÔÚÊܺ¦ÕßÎÞ½»»¥µÄÇéÐÎϾ²Ä¬×°ÖÃľÂí³ÌÐò £¬£¬£¬£¬£¬ÆäËû¶ñÒâÈí¼þÔòÓÕÆ­Êܺ¦ÕßÊÚȨ´Ó¶øÊµÏÖľÂí³ÌÐòµÄ×°Öᣡ£¡£¡£¡£¡£¡£¡£Ä¾Âí³ÌÐòÍøÂç×°±¸ÉÏÉúÑĵÄÃô¸ÐÊý¾Ý²¢¼ÓÃÜÉÏ´«µ½C&CЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£¡£

    £¨ËÄ£©Ê¹ÓÃÒßÇéÐÅÏ¢¶Ô°Í»ù˹̹µÈ¹úµÄ¹¥»÷Ô˶¯

    2020Äê5Ô £¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐIJ¶»ñµ½ÏìβÉß×é֯ʹÓÃÒßÇéÏà¹ØÐÅÏ¢×÷ΪÓÕ¶üµÄ¶ñÒâLNKÑù±¾¡¾8¡¿ £¬£¬£¬£¬£¬´ËÀàÑù±¾ÒÔÊܺ¦¹ú¼ÒµÄ¾ü·½¿¹»÷ÒßÇéÕ½ÂÔ¡¢¿Õ¾ü´óѧÒßÇéʱ´úÍøÂçÔÚÏ߿γÌÕþ²ßµÈÈÈÃÅÐÅÏ¢×÷Ϊαװ¡£¡£¡£¡£¡£¡£¡£¡£

    Ò»µ©Êܺ¦ÕßÖ´ÐдËÀà¶ñÒâÑù±¾ £¬£¬£¬£¬£¬LNKÎļþ½«´ÓÔ¶³ÌЧÀÍÆ÷ÏÂÔØ¶ñÒâhta¾ç±¾ÎļþÖ´ÐÐ £¬£¬£¬£¬£¬¶ñÒâ¾ç±¾½«ÊÍ·ÅչʾÕý³£µÄÓÕ¶üÎĵµÒÔÒÉ»óÊܺ¦Õß £¬£¬£¬£¬£¬²¢¼ÌÐø´ÓÔ¶³Ì»ñÈ¡µÚ¶þ½×¶Î¶ñÒâhta¾ç±¾ÎļþÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£µÚ¶þ½×¶Î¶ñÒâ¾ç±¾½«ÔÚÊܺ¦ÕßÅÌËã»úÉϰ²ÅÅÏà¹Ø¶ñÒâÈí¼þ £¬£¬£¬£¬£¬²¢Í¨¹ý°×¼ÓºÚµÄ·½·¨¼ÓÔØ×îÖÕµÄÔ¶³ÌľÂí £¬£¬£¬£¬£¬¿ØÖÆÊܺ¦Õß»úе £¬£¬£¬£¬£¬´Ó¶øÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£

    £¨Î壩ʹÓÃä¯ÀÀÆ÷Îó²î¹¥»÷ÎÒ¹úij¸ßУ

    2020Ä꺣ÄÚijÇå¾²ÍŶÓÅû¶ÁËÏìβÉß×éÖ¯Õë¶ÔÎÒ¹úij¸ßУµÄ¹¥»÷Ô˶¯¡¾9¡¿ £¬£¬£¬£¬£¬ÓÕ¶üÎĵµÄÚÈÝΪ2020Äê´º¼¾ÒßÇé·À¿ØÊÂÇéµÄÓÅÒìÎ÷Ï¯ÍÆ¼öÃûµ¥¡£¡£¡£¡£¡£¡£¡£¡£

    Ôڴ˴ι¥»÷Ô˶¯ÖÐ £¬£¬£¬£¬£¬ÏìβÉßʹÓÃÁËÓëÒÔÍù²î±ðµÄ¹¥»÷ÊÖ·¨£º

    £¨1£©Ê×ÏȶñÒâÎĵµÍ¨¹ýÔ¶³ÌÄ£°å×¢ÈëµÄ·½·¨¼ÓÔØÐ¯´øCVE-2017-0199Îó²îµÄÎĵµ£»£»£»£»£»£»

    £¨2£©È»ºóCVE-2017-0199Îó²îÎĵµÔÙÔ¶³Ì¼ÓÔØhtaÎļþ£»£»£»£»£»£»

    £¨3£©htaÎļþÖаüÀ¨2020ÄêÍ·¹ûÕæÅû¶µÄä¯ÀÀÆ÷Îó²îCVE-2020-0674ʹÓôúÂë £¬£¬£¬£¬£¬Îó²îʹÓÃÀֳɺóÊÍ·ÅľÂí×é¼þ¡£¡£¡£¡£¡£¡£¡£¡£

    £¨Áù£©¶Ô¶à¹úʵÑé´¹ÂÚ¹¥»÷

    2020Äê12Ô £¬£¬£¬£¬£¬ÍâÑóÇå¾²³§ÉÌÇ÷ÊÆ¿Æ¼¼Ðû²¼±¨¸æÅû¶ÁËÏìβÉß×éÖ¯ºã¾Ã¶ÔÄá²´¶û¡¢°¢¸»º¹¡¢ÖйúµÈ¶à¸ö¹ú¼ÒµÄÕþ¸®¡¢Íâ½»¡¢¹ú·À¾üÊ»ú¹¹Õö¿ª´¹ÂÚ¹¥»÷Ô˶¯¡¾10¡¿¡£¡£¡£¡£¡£¡£¡£¡£

    ÏìβÉß×é֯ͨ¹ýÄ£Äâ¹¥»÷Ä¿µÄµÄÓòÃû½¨ÉèÍйܴ¹ÂÚÒ³ÃæµÄÓòÃû £¬£¬£¬£¬£¬¸´ÖÆÄ¿µÄ»ú¹¹ÓʼþÍøÕ¾µÄÍøÒ³²¢ÖÆ×÷´¹ÂÚÒ³Ãæ £¬£¬£¬£¬£¬´Ó¶øÇÔÈ¡Ïà¹ØÖ°Ô±µÄÓÊÏäµÇ¼ƾ֤ £¬£¬£¬£¬£¬ÎªºóÐøµÄ¶¨Ïò¹¥»÷Ô˶¯×ö×¼±¸¡£¡£¡£¡£¡£¡£¡£¡£

    ×ܽá

    ×ÔÊ×´ÎÆØ¹âÒÔÀ´ £¬£¬£¬£¬£¬ÏìβÉߣ¨Sidewinder£©×é֯ƵÈÔÔ˶¯ £¬£¬£¬£¬£¬¹¥»÷Ä¿µÄ¼¯ÖÐÔÚÄÏÑǶà¹úºÍÖйúµÄÕþ¸®¡¢Íâ½»¡¢¾üÊÂÁìÓò £¬£¬£¬£¬£¬ÌåÏÖÁ˸Ã×éÖ¯¹¥»÷Ô˶¯ÖÐÇ¿ÁÒµÄÕþÖÎÄîÍ·ºÍ±³ºóµÄ¹ú¼ÒʵÁ¦Ö§³Ö¡£¡£¡£¡£¡£¡£¡£¡£

    ¶àÄêÀ´ £¬£¬£¬£¬£¬ÏìβÉß×éÖ¯µÄ¹¥»÷Á÷³ÌÕûÌåûÓÐÌ«´óת±ä £¬£¬£¬£¬£¬µ«ÎªÁ˶Կ¹Çå¾²Èí¼þ¼ì²âºÍÆÊÎöÖ°Ô±×·×Ù £¬£¬£¬£¬£¬¸Ã×éÖ¯Ò²ÔÚһֱˢÐÂÉý¼¶¹¥»÷ÊÖ·¨¡£¡£¡£¡£¡£¡£¡£¡£

    ±ðµÄ £¬£¬£¬£¬£¬ÏìβÉß×éÖ¯ÔÚÀúÊ·¹¥»÷Ô˶¯ÖÐʹÓõÄÎó²îÅú×¢ £¬£¬£¬£¬£¬¸Ã×éÖ¯¿ÉÄÜÓëÍøÂç¾üÆ÷É̱£´æ¹ØÁª¡£¡£¡£¡£¡£¡£¡£¡£

    ÏÖÔÚ £¬£¬£¬£¬£¬¸Ã×éÖ¯¶Ô°üÀ¨ÎÒ¹úÔÚÄڵĶà¸ö¹ú¼ÒÈÔÈ»×é³ÉÑÏÖØÍþв £¬£¬£¬£¬£¬ÐèÒªÎÒÃÇÒ»Á¬¸ú×Ù¹Ø×¢¡£¡£¡£¡£¡£¡£¡£¡£

    ×¢½â

    https://ti.qianxin.com/uploads/2021/02/08/dd941ecf98c7cb9bf0111a8416131aa1.pdf

    https://securelist.com/apt-trends-report-q1-2018/85280/

    https://s.tencent.com/research/report/479

    https://www.secrss.com/articles/13390

    https://ti.dbappsecurity.com.cn/blog/articles/2019/08/30/sidewinder-apt-group-attack-embassy-in-china-disclosed/

    http://it.rising.com.cn/dongtai/19656.html

    https://www.trendmicro.com/en_us/research/20/a/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group.html

    https://ti.qianxin.com/blog/articles/the-recent-rattlesnake-apt-organized-attacks-on-neighboring-countries-and-regions/

    https://bbs.pediy.com/thread-260640.htm

    https://www.trendmicro.com/en_us/research/20/l/sidewinder-leverages-south-asian-territorial-issues-for-spear-ph.html

    ¹ØÓÚ×÷Õß

    Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ºìÓêµÎÍŶӣ¨RedDripTeam £¬£¬£¬£¬£¬@RedDrip7£© £¬£¬£¬£¬£¬ÒÀÍÐÈ«ÇòÁìÏȵÄÇå¾²´óÊý¾ÝÄÜÁ¦¡¢¶àά¶È¶àȪԴµÄÇå¾²Êý¾ÝºÍרҵÆÊÎöʦµÄ¸»ºñÂÄÀú £¬£¬£¬£¬£¬×Ô2015ÄêÒ»Á¬·¢Ã÷¶à¸ö°üÀ¨º£Á«»¨ÔÚÄÚµÄAPT×éÖ¯ÔÚÖйú¾³Äڵĺã¾ÃÔ˶¯ £¬£¬£¬£¬£¬²¢Ðû²¼º£ÄÚÊ׸ö×éÖ¯²ãÃæµÄAPTÊÂÎñ½ÒÆÆ±¨¸æ £¬£¬£¬£¬£¬¿ª´´Á˺£ÄÚAPT¹¥»÷Àà¸ß¼¶Íþвϵͳ»¯½ÒÆÆµÄÏȺÓ¡£¡£¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ £¬£¬£¬£¬£¬Ò»Á¬¸ú×ÙÆÊÎöµÄÖ÷ÒªAPTÍÅ»ïÁè¼Ý47¸ö £¬£¬£¬£¬£¬×ÔÁ¦·¢Ã÷APT×éÖ¯14¸ö £¬£¬£¬£¬£¬Ò»Á¬Ðû²¼APT×éÖ¯µÄ¸ú×Ù±¨¸æÁè¼Ý90ƪ £¬£¬£¬£¬£¬°´ÆÚÊä³ö°ëÄêºÍÕûÄêÈ«ÇòAPTÔ˶¯×ÛºÏÐÔÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015ÍøÂçÇ徲ЧÀÍÈÈÏß

95015ÍøÂçÇ徲ЧÀÍÈÈÏß

ɨһɨ¹Ø×¢

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! ÔÚÏ߿ͷþ Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015

Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ

ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿