NCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ£»£»£»£»ÐµÄAndroidľÂíBanker.BRʹÓÃÁýÕÖ¹¥»÷Ãé×¼ÒøÐÐÖ÷¹Ë

Ðû²¼Ê±¼ä 2020-04-22

1.CNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¹ú¼Ò»¥ÁªÍøÓ¦¼±ÖÐÐÄ£¨CNCERT£©ÓÚ2020Äê4ÔÂ20ÈÕÐû²¼ÁË¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ¡£¡£¡£ ¡£¡£¸Ã±¨¸æ×¤×ãÓÚCNCERTÍøÂçÇå¾²ºê¹Û¼à²âÊý¾ÝÓëÊÂÇéʵ¼ù±¨¸æ£¬ £¬ £¬£¬£¬Éæ¼°2019Äêµä·¶ÍøÂçÇå¾²ÊÂÎñ¡¢ÍøÂçÇå¾²ÐÂÇ÷ÊÆ¼°Ò»Ñùƽ³£ÍøÂçÇå¾²ÊÂÎñÓ¦¼±´¦Öóͷ£Êµ¼ùµÈÄÚÈÝ¡£¡£¡£ ¡£¡£±¨¸æÖ÷Òª°üÀ¨Ëĸö²¿·Ö£¬ £¬ £¬£¬£¬Ò»ÊÇ×ܽá2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇ徲״̬£¬ £¬ £¬£¬£¬¶þÊÇÕ¹Íû2020ÄêÍøÂçÇå¾²ÈÈÃÅ£¬ £¬ £¬£¬£¬ÈýÊÇÁ¬ÏµÍøÂçÇå¾²Ì¬ÊÆÆÊÎöÌá³ö¶Ô²ß½¨Ò飬 £¬ £¬£¬£¬ËÄÊÇÊáÀíÍøÂçÇå¾²¼à²âÊý¾Ý¡£¡£¡£ ¡£¡£¸Ã±¨¸æ¶ÔÎÒ¹úµ³Õþ»ú¹Ø¡¢ÐÐÒµÆóÒµ¼°È«Éç»áÏàʶÎÒ¹úÍøÂçÇå¾²ÐÎÊÆ£¬ £¬ £¬£¬£¬Ìá¸ßÍøÂçÇå¾²Òâʶ£¬ £¬ £¬£¬£¬×öºÃÍøÂçÇå¾²ÊÂÇéÌṩÁËÓÐÁ¦²Î¿¼¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2020-04/20/c_1588932297982643.htm


2.Winnti groupÕë¶ÔµÂ¹ú»¯¹¤¹«Ë¾¹¥»÷Ñù±¾µÄÆÊÎö±¨¸æ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


1Ô·ÝQuoIntelligence£¨QuoINT£©¼ì²âµ½Ò»¸öеÄWinntiÑù±¾²¢¶ÔÆä¾ÙÐÐÁËÆðÔ´µÄÆÊÎö¡£¡£¡£ ¡£¡£ÆÊÎö·¢Ã÷£¬ £¬ £¬£¬£¬¸Ã¶ñÒâÈí¼þ¿ÉÄÜÊÇÔÚ2015Äê±»¿ª·¢³öÀ´µÄ¡£¡£¡£ ¡£¡£¸ÃÑù±¾±»ÓÃÓÚ¹¥»÷Ò»¼ÒµÂ¹ú»¯¹¤¹«Ë¾£¬ £¬ £¬£¬£¬ÏÖÔÚÉв»ÇåÎú¸Ã¹«Ë¾µÄÏêϸÃû³Æ¡£¡£¡£ ¡£¡£¸ÃÑù±¾½ÓÄÉÁËеÄC2ÊÖÒÕ£¬ £¬ £¬£¬£¬ÒÀÀµÓÚͨ¹ýiodineÔ´´úÂëʵÏÖµÄDNSËíµÀ¾ÙÐÐͨѶ¡£¡£¡£ ¡£¡£±ðµÄ£¬ £¬ £¬£¬£¬Ñо¿Ö°Ô±»¹·¢Ã÷ÁËÒ»¸öÒÔǰδ֪µÄ±»µÁÊý×ÖÖ¤Ê飬 £¬ £¬£¬£¬¸ÃÖ¤ÊéÖ÷ÒªÓÃÀ´¶ÔWinntiÏà¹ØµÄÇý¶¯³ÌÐò¾ÙÐÐÊý×ÖÊðÃû£¬ £¬ £¬£¬£¬²¢ÇÒÓÃÓÚ¹¥»÷º«¹úÓÎÏ·¹«Ë¾Gravity¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://quointelligence.eu/2020/04/winnti-group-insights-from-the-past/


3.½©Ê¬ÍøÂçMootbotʹÓÃ0day¹¥»÷9¿î¹âÏË·ÓÉÆ÷


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ñо¿Ö°Ô±·¢Ã÷×Ô2ÔÂÏÂÑ®Æð£¬ £¬ £¬£¬£¬½©Ê¬ÍøÂçMootbot±ã×îÏÈʹÓÃ0day¹¥»÷9¿î¼ÒÓü°ÉÌÓùâÏË·ÓÉÆ÷£¨°üÀ¨Netlink GPON·ÓÉÆ÷£©¡£¡£¡£ ¡£¡£MoobotÊÇ»ùÓÚMiraiµÄн©Ê¬ÍøÂ磬 £¬ £¬£¬£¬ÆäÄ¿µÄÊÇÎïÁªÍø£¨IoT£©×°±¸¡£¡£¡£ ¡£¡£ÓÉÓÚ´ó´ó¶¼¹©Ó¦É̺ܿÉÄÜÊǽÓÄÉÁËͳһԭʼ¹©Ó¦É̵ÄOEM²úÆ·£¬ £¬ £¬£¬£¬Òò´ËÕâЩ·ÓÉÆ÷ÊÜͳһ0dayÓ°Ïì¡£¡£¡£ ¡£¡£¸ÃÎó²îΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬ £¬ £¬£¬£¬ÆäPoCÒѾ­Ðû²¼£¬ £¬ £¬£¬£¬µ¥¶ÀʹÓøÃÎó²î²»»áÔì³ÉΣº¦£¬ £¬ £¬£¬£¬Ö»ÓÐÓëÁíÒ»¸öÎó²îÒ»ÆðʹÓòŻªÊµÏÖ¹¥»÷¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±Ã»ÓÐÅû¶µÚ¶þ¸öÎó²îµÄÏêϸÐÅÏ¢¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/mootbot-fiber-routers-zero-days/154962/


4.ProofpointÖÒÑÔʹÓÃÊÓÆµ¾Û»á¹«Ë¾µÄ´¹ÂÚ¹¥»÷³ÊÔöÌíÇ÷ÊÆ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ProofpointÑо¿Ö°Ô±·¢Ã÷£¬ £¬ £¬£¬£¬ÒÔÊÓÆµ¾Û»á¹«Ë¾ÎªÖ÷ÌâµÄÍøÂç´¹ÂÚ¹¥»÷ÊýÄ¿³ÊÔöÌíÇ÷ÊÆ£¬ £¬ £¬£¬£¬ÕâЩ¹¥»÷Ö¼ÔÚÇÔÈ¡Óû§µÇ¼ƾ֤ºÍÈö²¥¶ñÒâÈí¼þ¡£¡£¡£ ¡£¡£ProofpointÖÒÑԳƣ¬ £¬ £¬£¬£¬ºÚ¿Í²»»áÖ±½Ó¹¥»÷ÕâЩÊÓÆµ¾Û»áÈí¼þ£¬ £¬ £¬£¬£¬¿ÉÊÇ»áÒÔÊÓÆµ¾Û»á¹«Ë¾µÄÃû³ÆÎªÓÕ¶üÇÔÈ¡Óû§ÕÊ»§Æ¾Ö¤ºÍÈö²¥¶ñÒâÈí¼þ¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±·¢Ã÷µÄ´¹ÂÚ³¡¾°°üÀ¨£ºÎ±ÔìCisco WebExµÄÖÒÑÔÓʼþÀ´ÇÔÈ¡ÃÀ¹úÓû§µÄÕË»§ÐÅÏ¢£»£»£»£»Ã°³äZoom AccountÇÔÈ¡ÃÀ¹úÄÜÔ´¡¢ÖÆÔìºÍÉÌÒµµÈÐÐÒµµÄÓû§Æ¾Ö¤£»£»£»£»ÒÔ"zoom call"ΪÖ÷ÌâÈö²¥ServLoaderºÍNetSupport RATµÈ¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.proofpoint.com/us/threat-insight/post/remote-video-conferencing-themes-credential-theft-and-malware-threats


5.FoxitÐÞ¸´PDF Reader¼°PhantomPDFÖеĶà¸öÎó²î


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


FoxitÐÞ¸´ÁËWindows°æ±¾µÄFoxit ReaderºÍFoxit PhantomPDFÖеÄ20¸öCVEÎó²î¡£¡£¡£ ¡£¡£Ê×ÏÈ£¬ £¬ £¬£¬£¬FoxitÔÚPDF Reader 9.7.2°æ±¾ÖÐÐÞ¸´Á˶à¸öRCEÎó²î£¬ £¬ £¬£¬£¬°üÀ¨XFAÄ£°å´¦Öóͷ£Àú³ÌÖеÄRCEÎó²î£¨CVE-2020-10899¡¢ CVE-2020-10907£©£¬ £¬ £¬£¬£¬AcroFormsÖеÄRCEÎó²î£¨CVE-2020-10900£©ÒÔ¼°resetFormÖеÄRCEÎó²î£¨CVE-2020-10906£©¡£¡£¡£ ¡£¡£¹ØÓÚPhantomPDF£¬ £¬ £¬£¬£¬´Ë´Î¸üÐÂÐÞ¸´ÁËAPIͨѶÖеÄÁ½¸öÒ×±»Ê¹ÓõÄí§ÒâÎļþдÈëÎó²î£¨CVE-2020-10890ºÍCVE-2020-10892£©£¬ £¬ £¬£¬£¬ÒÔ¼°Á½¸öÓйØSetFieldValueÏÂÁî´¦Öóͷ£µÄ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-10912ºÍCVE-2020-10912£©¡£¡£¡£ ¡£¡£±ðµÄ£¬ £¬ £¬£¬£¬´Ë´Î¸üл¹ÐÞ¸´ÁËU3DBrowser²å¼þÖеÄ11¸öÎó²î¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/foxit-pdf-reader-phantompdf-remote-code-execution/154942/


6.еÄAndroidľÂíBanker.BRʹÓÃÆÁÄ»ÁýÕÖ¹¥»÷Ãé×¼ÒøÐпͻ§


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


IBM X-ForceÑо¿Ö°Ô±·¢Ã÷еÄAndroidľÂíBanker.BR£¬ £¬ £¬£¬£¬ÆäʹÓÃÆÁÄ»ÁýÕÖ¹¥»÷Õë¶ÔʹÓÃÎ÷°àÑÀÓï»òÆÏÌÑÑÀÓ°üÀ¨Î÷°àÑÀ¡¢ÆÏÌÑÑÀ¡¢°ÍÎ÷ºÍÀ­¶¡ÃÀÖÞÆäËûµØÇø£©µÄÒøÐпͻ§£¬ £¬ £¬£¬£¬ÍýÏëÇÔÈ¡Óû§Æ¾Ö¤²¢ÍµÈ¡ÆäÕË»§¡£¡£¡£ ¡£¡£Ñо¿·¢Ã÷£¬ £¬ £¬£¬£¬¸Ã¶ñÒâÈí¼þµÄÔçÆÚ°æ±¾½ö¾ßÓлù±¾µÄSMSÇÔÈ¡¹¦Ð§£¬ £¬ £¬£¬£¬¿ÉÊÇBanker.BR¸üΪϸÄ壬 £¬ £¬£¬£¬¾ßÓÐÁýÕÖ¹¥»÷µÄ¹¦Ð§²¢ÇÒÓÐȫеĴúÂ룬 £¬ £¬£¬£¬²»ÒÀÀµÓÚÏÈǰ×ß©µÄ´úÂë»òÏÖÓеÄÒÆ¶¯¶ñÒâÈí¼þ¡£¡£¡£ ¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýÓÕʹÓû§ÏÂÔØÃ°³äµÄÒøÐÐÇå¾²Ó¦ÓóÌÐò¾ÙÐÐÈö²¥£¬ £¬ £¬£¬£¬µÈÓû§ÀÖ³É×°Öúó±ã»áÇÔÈ¡Óû§×°±¸ÐÅÏ¢£¬ £¬ £¬£¬£¬°üÀ¨µç»°ºÅÂë¡¢¹ú¼ÊÒÆ¶¯×°±¸Ê¶±ðÂ루IMEI£©¡¢¹ú¼ÊÒÆ¶¯Óû§Ê¶±ðÂ루IMSI£©ºÍSIMÐòÁкÅ£¬ £¬ £¬£¬£¬²¢½«ÐÅÏ¢·¢Ë͸øC2ЧÀÍÆ÷¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬ £¬ £¬£¬£¬¸Ã¶ñÒâÈí¼þÒÀÈ»ÔÚ¿ª·¢ÖС£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/android-banking-br-trojan-credential-stealing/154990/