ʱ¼ä£º2021-11-05

±¾ÎÄ3758×ÖÔĶÁÔ¼Ðè11·ÖÖÓ
¹ú¼Ò¼¶APT£¨AdvancedPersistentThreat£¬£¬£¬£¬£¬¸ß¼¶Ò»Á¬ÐÔÍþв£©×éÖ¯ÊÇÓйú¼ÒÅä¾°Ö§³ÖµÄ¶¥¼âºÚ¿ÍÍŻ£¬£¬£¬£¬×¨×¢ÓÚÕë¶ÔÌØ¶¨Ä¿µÄ¾ÙÐкã¾ÃµÄÒ»Á¬ÐÔÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!Æìϵĸ߼¶ÍþвÑо¿ÍŶӺìÓêµÎ£¨RedDripTeam£©Ã¿Äê»áÐû²¼È«ÇòAPTÄ걨¡¾1¡¿¡¢Öб¨£¬£¬£¬£¬£¬¶ÔÎôʱ¸÷´óAPTÍÅ»ïµÄÔ˶¯¾ÙÐÐÆÊÎö×ܽᡣ¡£¡£¡£¡£¡£¡£¡£
»¢·ûÖÇ¿âÌØÔ¼Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÆìϺìÓêµÎÍŶӣ¬£¬£¬£¬£¬¿ªÉè“Æðµ×¹ú¼Ò¼¶APT×éÖ¯”À¸Ä¿£¬£¬£¬£¬£¬Öð¸öÆðµ×È«Çò¸÷µØÇø»îÔ¾µÄÖ÷ÒªAPT×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡£±¾´ÎËø¶¨ÊÇÄÏÑǵØÇøÁíÒ»¸öÖÕÄê»îÔ¾µÄ¹ú¼Ò¼¶ºÚ¿ÍÍŻÏìβÉߣ¨Sidewinder£©¡£¡£¡£¡£¡£¡£¡£¡£
06
ÏìβÉß
ÏìβÉßÊǾݳÆÓÐÄÏÑÇÅä¾°µÄAPT×éÖ¯£¬£¬£¬£¬£¬2012ÄêÖÁ½ñÒ»Ö±´¦ÓÚ»îԾ״̬¡£¡£¡£¡£¡£¡£¡£¡£
ÏìβÉß×éÖ¯Ö÷ÒªÕë¶Ô°Í»ù˹̹¡¢Öйú¡¢°¢¸»º¹¡¢Äá²´¶û¡¢ÃϼÓÀµÈ¹ú¼ÒÕö¿ª¹¥»÷£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡Õþ¸®Íâ½»»ú¹¹¡¢¹ú·À¾üʲ¿·Ö¡¢¸ßµÈ½ÌÓý»ú¹¹µÈÁìÓòµÄÉñÃØÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÄÚ²¿¸ú×Ù±àºÅΪAPT-Q-39

Åä¾°
ÏìβÉߣ¬£¬£¬£¬£¬ÓÖÃûSidewinder£¬£¬£¬£¬£¬ÓÉÍâÑóÇå¾²³§ÉÌ¿¨°Í˹»ùÔÚ2018ÄêµÚÒ»¼¾¶ÈAPTÇ÷ÊÆ±¨¸æÖÐÂÊÏÈÅû¶¡£¡£¡£¡£¡£¡£¡£¡£
2018Äê5Ô£¬£¬£¬£¬£¬º£ÄÚijÇå¾²³§ÉÌÒ²±¨¸æÁËÏìβÉßAPT×éÖ¯Õë¶Ô°Í»ù˹̹µÈÄÏÑǹú¼Ò¾üÊÂÄ¿µÄµÄ¶¨Ïò¹¥»÷Ô˶¯¡£¡£¡£¡£¡£¡£¡£¡£¸ÃAPT×éÖ¯×îÔç¹¥»÷Ô˶¯¿É×·Ëݵ½2012Ä꣬£¬£¬£¬£¬ÖÁ½ñÒ»Ö±´¦ÓÚ»îԾ״̬¡£¡£¡£¡£¡£¡£¡£¡£
ÏìβÉßAPT×éÖ¯Ö÷ÒªÕë¶Ô°Í»ù˹̹¡¢Öйú¡¢°¢¸»º¹¡¢Äá²´¶û¡¢ÃϼÓÀµÈ¹ú¼ÒÕö¿ª¹¥»÷£¬£¬£¬£¬£¬ÒÔÇÔÈ¡Õþ¸®Íâ½»»ú¹¹¡¢¹ú·À¾üʲ¿·Ö¡¢¸ßµÈ½ÌÓý»ú¹¹µÈÁìÓòµÄÉñÃØÐÅϢΪĿµÄ£¬£¬£¬£¬£¬¹¥»÷Ô˶¯¾ßÓÐÇ¿ÁÒµÄÕþÖÎÅä¾°¡£¡£¡£¡£¡£¡£¡£¡£
½üÄêÀ´£¬£¬£¬£¬£¬ÏìβÉßAPT×éÖ¯³£ÓõÄÎó²îΪCVE-2017-0199ºÍCVE-2017-11882¡£¡£¡£¡£¡£¡£¡£¡£µ«ÔÚÀúÊ·¹¥»÷Ô˶¯ÖУ¬£¬£¬£¬£¬Ò²Ê¹ÓùýÆäËûÎó²î£¬£¬£¬£¬£¬ºÃ±ÈÕë¶ÔAndroidƽ̨µÄ¶ñÒâÈí¼þ»ñÈ¡rootȨÏÞʱʹÓÃÁËCVE-2019-2215£¬£¬£¬£¬£¬ÒÔ¼°ÔÚÒ»´Î¶ÔÎÒ¹úij¸ßУµÄ¶¨Ïò¹¥»÷ÖÐʹÓÃÁËä¯ÀÀÆ÷Îó²îCVE-2020-0674¡£¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸öÎó²îÔÚÆäʹÓõÄʱ¼ä½ÔÊôÓÚÒѹûÕæÅû¶µÄÎó²î£¬£¬£¬£¬£¬²¢ÇÒ´ÓÆäÏà¹ØµÄʹÓôúÂëÀ´¿´£¬£¬£¬£¬£¬±£´æ¸Ã×éÖ¯ÒÀÍÐÓÚÍøÂç¾üÆ÷É̵ĿÉÄÜ¡£¡£¡£¡£¡£¡£¡£¡£
¹¥»÷ÊÖ¶ÎÓ빤¾ß
ÏìβÉßAPT×éÖ¯³£Í¨¹ý´¹ÂÚÍøÕ¾ÇÔÈ¡¹¥»÷Ä¿µÄ»ú¹¹Ïà¹ØÖ°Ô±µÄµÇ¼ƾ֤£¬£¬£¬£¬£¬²¢Í¨¹ýÓã²æÓʼþͶµÝLNK¿ì½Ý·½·¨Îļþ»òÕßЯ´øÎó²îµÄ¶ñÒâÎĵµ¡£¡£¡£¡£¡£¡£¡£¡£
ÕâЩ¶ñÒâÎļþÔòͨ¹ýÖ´ÐаüÀ¨js´úÂëµÄhtaÎļþ»òÕßjs¾ç±¾·´Éä¼ÓÔØC#Ä£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬È»ºóÔÚÊܺ¦Õß»úеÉÏÊÍ·ÅľÂí³ÌÐò£¬£¬£¬£¬£¬Ä¾Âí³ÌÐòͨ³£Îª¶ñÒâdllÎļþ£¬£¬£¬£¬£¬Ê¹ÓöÔϵͳÖÐÕý³£exeÎļþµÄdll²à¼ÓÔØÊÖÒÕ£¨¼´“°×¼ÓºÚ”£©Æô¶¯ÔËÐС£¡£¡£¡£¡£¡£¡£¡£
£¨Ò»£©¹¥»÷ÊÖ¶Î
1.´¹ÂÚÍøÕ¾
ÏìβÉߣ¨Sidewinder£©Íйܴ¹ÂÚÍøÒ³µÄЧÀÍÆ÷ÓòÃû»áÄ£Äâ¹¥»÷Ä¿µÄÍøÕ¾µÄÓòÃû£¬£¬£¬£¬£¬ºÃ±È´¹ÂÚÓòÃû“mail-nepalgovnp[.]duckdns[.]org”ÓÃÀ´Î±×°ÎªÄá²´¶ûÕþ¸®Ê¹ÓõÄÓòÃû“mail[.]nepal[.]gov[.]np”¡£¡£¡£¡£¡£¡£¡£¡£´¹ÂÚÍøÒ³´Ó¹¥»÷Ä¿µÄµÄÓʼþÍøÕ¾¸´ÖƶøÀ´£¬£¬£¬£¬£¬¾ÓÉÒ»¶¨µÄÐ޸ĺóÓÃÀ´ÇÔȡĿµÄ»ú¹¹Ïà¹ØÖ°Ô±µÄÓÊÏäµÇ¼ƾ֤¡£¡£¡£¡£¡£¡£¡£¡£
ÕâЩ´¹ÂÚÍøÒ³ÔÚÊܺ¦Õß·¢Ë͵Ǽƾ֤ºó´ó´ó¶¼¶¼»áÖØ¶¨Ïòµ½ÔʼµÄÓʼþÍøÕ¾£¬£¬£¬£¬£¬ÉÐÓÐÒ»²¿·Ö»áÖØ¶¨ÏòΪÏÔʾÎĵµ»òÕßÐÂÎÅÍøÒ³£¬£¬£¬£¬£¬ÎĵµÓëÐÂÎŵÄÄÚÈÝÒ»Ñùƽ³£ÓëCOVID-19ÒßÇéºÍÄÏÑǵØÇøµÄÁìÍÁÕù¶ËÓйء£¡£¡£¡£¡£¡£¡£¡£
2.Óã²æ¹¥»÷
ͨ¹ýÓã²æÓʼþͶµÝ¶ñÒâÎĵµÊÇÏìβÉߣ¨Sidewinder£©×éÖ¯×î³£ÓõĹ¥»÷ÊֶΣ¬£¬£¬£¬£¬ÕâЩ×÷ΪÓÕ¶üµÄ¶ñÒâÎĵµ³£¼ûµÄÓÐÈçϼ¸ÖÖÀàÐÍ£º
(1)LNKÎļþ
LNKÎļþµÄÄ¿µÄ³ÌÐò·¾¶±»Ö¸¶¨ÎªÓÃmshta.exeÔ¶³Ì¼ÓÔØÔËÐÐhtaÎļþ£¬£¬£¬£¬£¬½ø¶øÊÍ·ÅÓÕ¶üÎĵµºÍÍê³ÉºóÐøµÄ¶ñÒâÈí¼þÖ²Èë²Ù×÷¡£¡£¡£¡£¡£¡£¡£¡£
(2)Я´øÎó²îµÄOfficeÎĵµ£¬£¬£¬£¬£¬ÆµÈÔʹÓÃÎó²îCVE-2017-11882ºÍCVE-2017-0199¡£¡£¡£¡£¡£¡£¡£¡£
ÔÚÏìβÉß×éÖ¯ÖÆ×÷µÄ¶ñÒâOfficeÎĵµÖУ¬£¬£¬£¬£¬Ò»ÀàÊÇʹÓÃCVE-2017-11882Îó²îÖ´ÐÐ×ÔÉíÊͷŵĻòÕßÔ¶³ÌÏÂÔØµÄhtaÎļþ»òjs¾ç±¾£¬£¬£¬£¬£¬´Ó¶øÍê³ÉºóÐøµÄ¶ñÒâÈí¼þÖ²Èë²Ù×÷£»£»£»£»£»£»ÁíÒ»ÀàÔòÊÇʹÓÃCVE-2017-0199Îó²îÔ¶³Ì¼ÓÔØÐ¯´øCVE-2017-11882Îó²îµÄÎĵµ¡£¡£¡£¡£¡£¡£¡£¡£
£¨¶þ£©Ê¹Óù¤¾ß¼°ÊÖÒÕÌØÕ÷
ÏìβÉß×éÖ¯¾ßÓÐWindowsºÍAndroid˫ƽ̨¹¥»÷ÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£¡£ÔÚWindowsƽ̨µÄ¹¥»÷ÊÖ·¨½ÏÁ¿Àο¿£¬£¬£¬£¬£¬ÒÔLNKÎļþ»òÕßÎó²îÎĵµÎª¹¥»÷Èë¿Ú£¬£¬£¬£¬£¬Í¨¹ýÖ´ÐаüÀ¨js´úÂëµÄhtaÎļþ»òjs¾ç±¾·´Éä¼ÓÔØC#dllÎļþ£¬£¬£¬£¬£¬×îºó½èÓɸÃdllÎļþÖ²ÈëľÂí³ÌÐò×é¼þ¡£¡£¡£¡£¡£¡£¡£¡£
ÏìβÉß×éÖ¯µÄ¹¥»÷Á÷³ÌÕûÌå»ù±¾Îȹ̣¬£¬£¬£¬£¬µ«ÎªÁ˶Կ¹Ñо¿Ö°Ô±µÄ·¢Ã÷Åû¶ºÍÇå¾²Èí¼þµÄ¼ì²â²éɱ£¬£¬£¬£¬£¬½üÄêÀ´¸Ã×éÖ¯Ò²Éý¼¶Á˹¥»÷ÊÖ·¨£¬£¬£¬£¬£¬ºÃ±È£º
£¨1£©ºóÐøµÄľÂí³ÌÐò×é¼þ²»ÔÙÖ±½ÓÔÚÍâµØÊÍ·Å£¬£¬£¬£¬£¬¶øÊÇ´ÓÔ¶³ÌЧÀÍÆ÷ÏÂÔØ£¬£¬£¬£¬£¬Ê¹µÃ¸Ã×éÖ¯ÔÚ¹¥»÷Àú³ÌÖÐʵʱ¹ØÍ£Ð§ÀÍÆ÷£¬£¬£¬£¬£¬½µµÍ´úÂë̻¶µÄΣº¦£»£»£»£»£»£»
£¨2£©Ìá¸ßÁË´úÂë»ìÏý¶È£¬£¬£¬£¬£¬ºÃ±È×÷ΪÖÐÐÄ×é¼þµÄjs´úÂëͨ¹ýÒýÈë×Ô½ç˵µÄBase64±àÂë¾ÙÐлìÏý£¬£¬£¬£¬£¬C#×é¼þÖк¯ÊýŲÓÃÓÉÖ±½ÓÒýÓÃϵͳAPI±äΪÓÃ×Ô½ç˵·±Ôӵĺ¯ÊýÃû·â×°ËùÐèŲÓõÄAPI¡£¡£¡£¡£¡£¡£¡£¡£
£¨3£©ÏìβÉß×éÖ¯Õë¶ÔAndroidƽ̨µÄ¶ñÒâÈí¼þͨ¹ýÎó²îʹÓûñÈ¡rootȨÏÞ»òÕßÓÕÆÊܺ¦ÕßÊÚȨÒÔ×°ÖÃľÂí³ÌÐòcallCam¡£¡£¡£¡£¡£¡£¡£¡£Ä¾Âí³ÌÐòÍøÂç×°±¸²ÎÊý¡¢Î»Öá¢Îļþ¡¢ÕË»§¡¢Éç½»Èí¼þÊý¾ÝµÈÃô¸ÐÐÅÏ¢²¢ÒÔ¼ÓÃÜÐÎʽÉÏ´«µ½C&CЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£¡£
ÖøÃû¹¥»÷ÊÂÎñ
£¨Ò»£©ÏìβÉߣ¨Sidewinder£©Ê×´ÎÆØ¹â
2018Äê4Ô£¬£¬£¬£¬£¬¿¨°Í˹»ù2018ÄêµÚÒ»¼¾¶ÈAPTÇ÷ÊÆ±¨¸æÌáµ½ÁËÃûΪ“Sidewinder”µÄAPT×éÖ¯¡¾2¡¿£¬£¬£¬£¬£¬¸Ã×éÖ¯¹¥»÷Ä¿µÄΪ°Í»ù˹̹µÄ¾üʲ¿·Ö£¬£¬£¬£¬£¬×îÔç¿É×·ËÝÖÁ2012Äê¡£¡£¡£¡£¡£¡£¡£¡£
2018Äê5ÔÂ23ÈÕ£¬£¬£¬£¬£¬º£ÄÚijÇå¾²³§ÉÌÐû²¼±¨¸æÅû¶ÁËÏìβÉß×éÖ¯Õë¶ÔÄÏÑǹ¥»÷Ô˶¯µÄϸ½Ú¡¾3¡¿£ºÊ¹ÓÃCVE-2017-11882Îó²îÔ¶³Ì¼ÓÔØ²¢Ö´ÐÐhtaÎļþ£¬£¬£¬£¬£¬ÎļþÖеľ籾ŲÓÃpowershellÏÂÁîÊÍ·ÅÆäÖÐÉúÑĵÄľÂí³ÌÐò¡£¡£¡£¡£¡£¡£¡£¡£
£¨¶þ£©2019ÄêÕë¶ÔÎÒ¹úµÄ¶à´Î¶¨Ïò¹¥»÷
2019Äê7Ô£¬£¬£¬£¬£¬º£ÄÚijÇå¾²³§ÉÌ·¢Ã÷ÏìβÉß×éÖ¯Õë¶ÔÎÒ¹úµÄ¶¨Ïò¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¡£Ôڴ˴ι¥»÷ÊÂÎñÖУ¬£¬£¬£¬£¬ÏìβÉßÒÔÎÒ¹ú¹ú·À²¿¹ú¼ÊÏàÖú²¿·Ö·¢Ë͵Ä֪ͨÎļþΪÓÕ¶ü£¬£¬£¬£¬£¬ÏòËû¹úפ»ªÊ¹¹ÝÖ°Ô±Ìᳫ¹¥»÷¡¾4¡¿¡£¡£¡£¡£¡£¡£¡£¡£
¹¥»÷ʹÓõÄЯ´øCVE-2017-11882Îó²îµÄ¶ñÒâÎĵµÎªRTFÃûÌÃÎļþ£¬£¬£¬£¬£¬Îļþ·¿ªºó»á×Ô¶¯ÊÍ·ÅPackage¹¤¾ßÉúÑĵÄjs¾ç±¾£¬£¬£¬£¬£¬Îó²îʹÓúóÖ´ÐÐÊͷŵÄjs¾ç±¾£¬£¬£¬£¬£¬¾ç±¾¿½±´WindowsϵͳÖÐÕý³£µÄexeÎļþ£¬£¬£¬£¬£¬²¢ÊͷżÓÃܵÄľÂí³ÌÐòÊý¾ÝºÍÓÃÓÚ¼ÓÔØÄ¾Âí³ÌÐòµÄ¶ñÒâdllÎļþ£¬£¬£¬£¬£¬Ó뿽±´µÄexeÎļþ×é³É“°×¼ÓºÚ”×éºÏ¡£¡£¡£¡£¡£¡£¡£¡£
ÒԺ󣬣¬£¬£¬£¬ÏìβÉß¶à´ÎÕë¶ÔÎÒ¹úµÄ¶¨Ïò¹¥»÷±»Åû¶¡¾5¡¢6¡¿£¬£¬£¬£¬£¬°üÀ¨Õë¶Ôº£ÄÚij¹ú·À¿ÆÑÐÆóÒµ£¬£¬£¬£¬£¬ÏòÆäÄÚ²¿·¢ËÍÐéαµÄÇå¾²±£ÃÜÊÖ²áºÍÖÎÀíÎļþ£»£»£»£»£»£»½«Î±×°µÄ¡¶ÖйúÈËÃñ½â·Å¾üÎÄÖ°Ö°Ô±ÌõÀý¡·µÄÎĵµÍ¶·ÅÖÁ¹ú¼ÒÕþ¸®²¿·Ö£»£»£»£»£»£»Õë¶Ô¹ú·À¼°¾üʵÈÏà¹Ø²¿·Ö£¬£¬£¬£¬£¬ÏòÆä·¢ËÍÐéαµÄ“µÚ¾Å½ì±±¾©ÏãɽÂÛ̳¾Û»á”Òé³Ì¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷ÊÂÎñÖУ¬£¬£¬£¬£¬ÏìβÉß½ÓÄÉÁËÓë¹¥»÷Ëû¹úפ»ªÊ¹¹ÝÏàͬµÄÊÖ·¨¡£¡£¡£¡£¡£¡£¡£¡£
£¨Èý£©Òƶ¯¶Ë¹¥»÷ÎäÆ÷ÆØ¹â
2020Äê1Ô£¬£¬£¬£¬£¬ÍâÑóÇå¾²³§ÉÌÇ÷ÊÆ¿Æ¼¼Åû¶ÁËÏìβÉß×éÖ¯Õë¶ÔAndroidƽ̨µÄ¶ñÒâÈí¼þ¡¾7¡¿¡£¡£¡£¡£¡£¡£¡£¡£
ÕâЩ¶ñÒâÈí¼þÔÚGooglePlayÓ¦ÓÃÊÐËÁÖÐαװΪͼƬºÍÎļþÖÎÀíÆ÷¹¤¾ß£¬£¬£¬£¬£¬¾ÓÉÁ½¸ö½×¶ÎµÄÏÂÔØÀú³ÌÔÚÊܺ¦Õß×°±¸ÉÏÖ²Èë×îÖÕµÄľÂí³ÌÐòcallCam¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÒ»¸ö¶ñÒâÈí¼þͨ¹ýʹÓÃCVE-2019-2215Îó²îºÍMediaTek-SU»ñÈ¡rootȨÏÞ£¬£¬£¬£¬£¬¿ÉÒÔÔÚÊܺ¦ÕßÎÞ½»»¥µÄÇéÐÎϾ²Ä¬×°ÖÃľÂí³ÌÐò£¬£¬£¬£¬£¬ÆäËû¶ñÒâÈí¼þÔòÓÕÆÊܺ¦ÕßÊÚȨ´Ó¶øÊµÏÖľÂí³ÌÐòµÄ×°Öᣡ£¡£¡£¡£¡£¡£¡£Ä¾Âí³ÌÐòÍøÂç×°±¸ÉÏÉúÑĵÄÃô¸ÐÊý¾Ý²¢¼ÓÃÜÉÏ´«µ½C&CЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£¡£
£¨ËÄ£©Ê¹ÓÃÒßÇéÐÅÏ¢¶Ô°Í»ù˹̹µÈ¹úµÄ¹¥»÷Ô˶¯
2020Äê5Ô£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐIJ¶»ñµ½ÏìβÉß×é֯ʹÓÃÒßÇéÏà¹ØÐÅÏ¢×÷ΪÓÕ¶üµÄ¶ñÒâLNKÑù±¾¡¾8¡¿£¬£¬£¬£¬£¬´ËÀàÑù±¾ÒÔÊܺ¦¹ú¼ÒµÄ¾ü·½¿¹»÷ÒßÇéÕ½ÂÔ¡¢¿Õ¾ü´óѧÒßÇéʱ´úÍøÂçÔÚÏ߿γÌÕþ²ßµÈÈÈÃÅÐÅÏ¢×÷Ϊαװ¡£¡£¡£¡£¡£¡£¡£¡£
Ò»µ©Êܺ¦ÕßÖ´ÐдËÀà¶ñÒâÑù±¾£¬£¬£¬£¬£¬LNKÎļþ½«´ÓÔ¶³ÌЧÀÍÆ÷ÏÂÔØ¶ñÒâhta¾ç±¾ÎļþÖ´ÐУ¬£¬£¬£¬£¬¶ñÒâ¾ç±¾½«ÊÍ·ÅչʾÕý³£µÄÓÕ¶üÎĵµÒÔÒÉ»óÊܺ¦Õߣ¬£¬£¬£¬£¬²¢¼ÌÐø´ÓÔ¶³Ì»ñÈ¡µÚ¶þ½×¶Î¶ñÒâhta¾ç±¾ÎļþÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£µÚ¶þ½×¶Î¶ñÒâ¾ç±¾½«ÔÚÊܺ¦ÕßÅÌËã»úÉϰ²ÅÅÏà¹Ø¶ñÒâÈí¼þ£¬£¬£¬£¬£¬²¢Í¨¹ý°×¼ÓºÚµÄ·½·¨¼ÓÔØ×îÖÕµÄÔ¶³ÌľÂí£¬£¬£¬£¬£¬¿ØÖÆÊܺ¦Õß»úе£¬£¬£¬£¬£¬´Ó¶øÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£
£¨Î壩ʹÓÃä¯ÀÀÆ÷Îó²î¹¥»÷ÎÒ¹úij¸ßУ
2020Ä꺣ÄÚijÇå¾²ÍŶÓÅû¶ÁËÏìβÉß×éÖ¯Õë¶ÔÎÒ¹úij¸ßУµÄ¹¥»÷Ô˶¯¡¾9¡¿£¬£¬£¬£¬£¬ÓÕ¶üÎĵµÄÚÈÝΪ2020Äê´º¼¾ÒßÇé·À¿ØÊÂÇéµÄÓÅÒìÎ÷Ï¯ÍÆ¼öÃûµ¥¡£¡£¡£¡£¡£¡£¡£¡£
Ôڴ˴ι¥»÷Ô˶¯ÖУ¬£¬£¬£¬£¬ÏìβÉßʹÓÃÁËÓëÒÔÍù²î±ðµÄ¹¥»÷ÊÖ·¨£º
£¨1£©Ê×ÏȶñÒâÎĵµÍ¨¹ýÔ¶³ÌÄ£°å×¢ÈëµÄ·½·¨¼ÓÔØÐ¯´øCVE-2017-0199Îó²îµÄÎĵµ£»£»£»£»£»£»
£¨2£©È»ºóCVE-2017-0199Îó²îÎĵµÔÙÔ¶³Ì¼ÓÔØhtaÎļþ£»£»£»£»£»£»
£¨3£©htaÎļþÖаüÀ¨2020ÄêÍ·¹ûÕæÅû¶µÄä¯ÀÀÆ÷Îó²îCVE-2020-0674ʹÓôúÂ룬£¬£¬£¬£¬Îó²îʹÓÃÀֳɺóÊÍ·ÅľÂí×é¼þ¡£¡£¡£¡£¡£¡£¡£¡£
£¨Áù£©¶Ô¶à¹úʵÑé´¹ÂÚ¹¥»÷
2020Äê12Ô£¬£¬£¬£¬£¬ÍâÑóÇå¾²³§ÉÌÇ÷ÊÆ¿Æ¼¼Ðû²¼±¨¸æÅû¶ÁËÏìβÉß×éÖ¯ºã¾Ã¶ÔÄá²´¶û¡¢°¢¸»º¹¡¢ÖйúµÈ¶à¸ö¹ú¼ÒµÄÕþ¸®¡¢Íâ½»¡¢¹ú·À¾üÊ»ú¹¹Õö¿ª´¹ÂÚ¹¥»÷Ô˶¯¡¾10¡¿¡£¡£¡£¡£¡£¡£¡£¡£
ÏìβÉß×é֯ͨ¹ýÄ£Äâ¹¥»÷Ä¿µÄµÄÓòÃû½¨ÉèÍйܴ¹ÂÚÒ³ÃæµÄÓòÃû£¬£¬£¬£¬£¬¸´ÖÆÄ¿µÄ»ú¹¹ÓʼþÍøÕ¾µÄÍøÒ³²¢ÖÆ×÷´¹ÂÚÒ³Ãæ£¬£¬£¬£¬£¬´Ó¶øÇÔÈ¡Ïà¹ØÖ°Ô±µÄÓÊÏäµÇ¼ƾ֤£¬£¬£¬£¬£¬ÎªºóÐøµÄ¶¨Ïò¹¥»÷Ô˶¯×ö×¼±¸¡£¡£¡£¡£¡£¡£¡£¡£
×ܽá
×ÔÊ×´ÎÆØ¹âÒÔÀ´£¬£¬£¬£¬£¬ÏìβÉߣ¨Sidewinder£©×é֯ƵÈÔÔ˶¯£¬£¬£¬£¬£¬¹¥»÷Ä¿µÄ¼¯ÖÐÔÚÄÏÑǶà¹úºÍÖйúµÄÕþ¸®¡¢Íâ½»¡¢¾üÊÂÁìÓò£¬£¬£¬£¬£¬ÌåÏÖÁ˸Ã×éÖ¯¹¥»÷Ô˶¯ÖÐÇ¿ÁÒµÄÕþÖÎÄîÍ·ºÍ±³ºóµÄ¹ú¼ÒʵÁ¦Ö§³Ö¡£¡£¡£¡£¡£¡£¡£¡£
¶àÄêÀ´£¬£¬£¬£¬£¬ÏìβÉß×éÖ¯µÄ¹¥»÷Á÷³ÌÕûÌåûÓÐÌ«´óת±ä£¬£¬£¬£¬£¬µ«ÎªÁ˶Կ¹Çå¾²Èí¼þ¼ì²âºÍÆÊÎöÖ°Ô±×·×Ù£¬£¬£¬£¬£¬¸Ã×éÖ¯Ò²ÔÚһֱˢÐÂÉý¼¶¹¥»÷ÊÖ·¨¡£¡£¡£¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬ÏìβÉß×éÖ¯ÔÚÀúÊ·¹¥»÷Ô˶¯ÖÐʹÓõÄÎó²îÅú×¢£¬£¬£¬£¬£¬¸Ã×éÖ¯¿ÉÄÜÓëÍøÂç¾üÆ÷É̱£´æ¹ØÁª¡£¡£¡£¡£¡£¡£¡£¡£
ÏÖÔÚ£¬£¬£¬£¬£¬¸Ã×éÖ¯¶Ô°üÀ¨ÎÒ¹úÔÚÄڵĶà¸ö¹ú¼ÒÈÔÈ»×é³ÉÑÏÖØÍþв£¬£¬£¬£¬£¬ÐèÒªÎÒÃÇÒ»Á¬¸ú×Ù¹Ø×¢¡£¡£¡£¡£¡£¡£¡£¡£
×¢½â
https://ti.qianxin.com/uploads/2021/02/08/dd941ecf98c7cb9bf0111a8416131aa1.pdf
https://securelist.com/apt-trends-report-q1-2018/85280/
https://s.tencent.com/research/report/479
https://www.secrss.com/articles/13390
https://ti.dbappsecurity.com.cn/blog/articles/2019/08/30/sidewinder-apt-group-attack-embassy-in-china-disclosed/
http://it.rising.com.cn/dongtai/19656.html
https://www.trendmicro.com/en_us/research/20/a/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group.html
https://ti.qianxin.com/blog/articles/the-recent-rattlesnake-apt-organized-attacks-on-neighboring-countries-and-regions/
https://bbs.pediy.com/thread-260640.htm
https://www.trendmicro.com/en_us/research/20/l/sidewinder-leverages-south-asian-territorial-issues-for-spear-ph.html
¹ØÓÚ×÷Õß
Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ºìÓêµÎÍŶӣ¨RedDripTeam£¬£¬£¬£¬£¬@RedDrip7£©£¬£¬£¬£¬£¬ÒÀÍÐÈ«ÇòÁìÏȵÄÇå¾²´óÊý¾ÝÄÜÁ¦¡¢¶àά¶È¶àȪԴµÄÇå¾²Êý¾ÝºÍרҵÆÊÎöʦµÄ¸»ºñÂÄÀú£¬£¬£¬£¬£¬×Ô2015ÄêÒ»Á¬·¢Ã÷¶à¸ö°üÀ¨º£Á«»¨ÔÚÄÚµÄAPT×éÖ¯ÔÚÖйú¾³Äڵĺã¾ÃÔ˶¯£¬£¬£¬£¬£¬²¢Ðû²¼º£ÄÚÊ׸ö×éÖ¯²ãÃæµÄAPTÊÂÎñ½ÒÆÆ±¨¸æ£¬£¬£¬£¬£¬¿ª´´Á˺£ÄÚAPT¹¥»÷Àà¸ß¼¶Íþвϵͳ»¯½ÒÆÆµÄÏȺӡ£¡£¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬Ò»Á¬¸ú×ÙÆÊÎöµÄÖ÷ÒªAPTÍÅ»ïÁè¼Ý47¸ö£¬£¬£¬£¬£¬×ÔÁ¦·¢Ã÷APT×éÖ¯14¸ö£¬£¬£¬£¬£¬Ò»Á¬Ðû²¼APT×éÖ¯µÄ¸ú×Ù±¨¸æÁè¼Ý90ƪ£¬£¬£¬£¬£¬°´ÆÚÊä³ö°ëÄêºÍÕûÄêÈ«ÇòAPTÔ˶¯×ÛºÏÐÔÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£
ʱ¼ä£º2026-04-22
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-18
Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ
ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ