¿¨°Í˹»ù | 2020ÄêQ1 APTÇ÷ÊÆ±¨¸æ
Ðû²¼Ê±¼ä 2020-05-01¿¨°Í˹»ùÐû²¼2020ÄêµÚÒ»¼¾¶ÈµÄAPT×éÖ¯»î¶¯µÄÇ÷ÊÆ±¨¸æ£¬£¬£¬£¬£¬£¬Ö÷Ҫ˵Ã÷ÖØ´óµÄAPT»î¶¯ÒÔ¼°Ñо¿·¢Ã÷¡£¡£¡£¡£¡£¡£
0x00 COVID-19 APT»î¶¯
×ÔÌìÏÂÎÀÉú×éÖ¯£¨WHO£©Ðû²¼COVID-19³ÉΪÎÁÒßÒÔÀ´£¬£¬£¬£¬£¬£¬ÕâÒ»»°ÌâÒÑÊܵ½²î±ð¹¥»÷ÕßÔ½À´Ô½¶àµÄ¹Ø×¢¡£¡£¡£¡£¡£¡£Ðí¶àÍøÂç´¹ÂÚթƶ¼ÊÇÓÉÍøÂç·¸·¨·Ö×ÓÌᳫµÄ£¬£¬£¬£¬£¬£¬ËûÃÇÊÔͼʹÓÃÈËÃǶԲ¡¶¾µÄ¿Ö¾åÀ´×¬Ç®¡£¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÁбíÖл¹°üÀ¨APT×éÖ¯£¬£¬£¬£¬£¬£¬ÀýÈçKimsuky£¬£¬£¬£¬£¬£¬APT27£¬£¬£¬£¬£¬£¬Lazarus»òViciousPanda£¬£¬£¬£¬£¬£¬Æ¾Ö¤OSINT£¬£¬£¬£¬£¬£¬ËûÃÇÒÔCOVID-19×÷ΪÓÕ¶üÃé×¼Êܺ¦Õß¡£¡£¡£¡£¡£¡£ÎÒÃÇ×î½ü·¢Ã÷ÁË¿ÉÒɵĻù´¡ÉèÊ©¿ÉÓÃÓÚÕë¶Ô°üÀ¨WHOÔÚÄÚµÄÎÀÉúºÍÈËÐÔÖ÷Òå×éÖ¯¡£¡£¡£¡£¡£¡£¾ÝһЩ˽ÈËÐÂÎÅȪԴ³Æ£¬£¬£¬£¬£¬£¬Ö»¹Ü»ù´¡ÉèÊ©ÏÖÔÚÎÞ·¨¹éÒòÓÚÈκÎÌØ¶¨µÄ×éÖ¯£¬£¬£¬£¬£¬£¬²¢ÇÒÒÑÔÚ2019Äê6ÔÂCOVID-19Σ»£»£»£»£»£»ú֮ǰע²á£¬£¬£¬£¬£¬£¬µ«Ëü¿ÉÄÜÓëDarkHotelÓйء£¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬ÎÒÃÇÏÖÔÚÎÞ·¨È·ÈÏ´ËÐÅÏ¢¡£¡£¡£¡£¡£¡£ÓÐȤµÄÊÇ£¬£¬£¬£¬£¬£¬Ò»Ð©×é֯ʹÓÃÄ¿½ñÇéÐÎÀ´Ðû²¼ËûÃÇÔÚΣ»£»£»£»£»£»úʱ´ú²»»áÕë¶ÔÎÀÉú×éÖ¯¡£¡£¡£¡£¡£¡£
0x01 ×îÖµµÃ×¢ÖØµÄÇ÷ÊÆ
2020Äê1Ô£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷Ò»¸öË®¿Ó¹¥»÷ʹÓÃÍêÈ«µÄÔ¶³ÌiOSÎó²î¡£¡£¡£¡£¡£¡£Õâ¸öÍøÕ¾µÄÄ¿µÄÊÇÆ¾Ö¤Ä¿µÄÍøÒ³µÄÄÚÈÝÀ´¶¨Î»ÖйúÏã¸ÛµÄÓû§¡£¡£¡£¡£¡£¡£ËäȻĿ½ñÕýÔÚʹÓõÄÎó²îʹÓóÌÐòÊÇÒÑÖªµÄ£¬£¬£¬£¬£¬£¬µ«ÈÏÕæÖ°Ô±ÕýÔÚÆð¾¢ÐÞ¸ÄÎó²îʹÓù¤¾ß°ü£¬£¬£¬£¬£¬£¬ÒÔÕë¶Ô¸ü¶àµÄiOS°æ±¾ºÍ×°±¸¡£¡£¡£¡£¡£¡£ÎÒÃÇÔÚ2ÔÂ7ÈÕÊӲ쵽ÁË×îеİ汾¡£¡£¡£¡£¡£¡£¸ÃÏîÄ¿±ÈÎÒÃÇ×î³õÏëÏóµÄÒªÆÕ±é£¬£¬£¬£¬£¬£¬ËüÖ§³ÖAndroidÖ²È룬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜÖ§³ÖWindows£¬£¬£¬£¬£¬£¬LinuxºÍMacOSµÄÖ²Èë¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬ÎÒÃǽ«´ËAPT×éÖ¯³ÆÎªTwoSail Junk¡£¡£¡£¡£¡£¡£ÎÒÃÇÒÔΪÕâÊÇÒ»ÆäÖÐÎÄ×éÖ¯£¬£¬£¬£¬£¬£¬ËüÖ÷ÒªÔÚÖйúÏã¸Ûά»¤»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬²¢ÔÚÐÂ¼ÓÆÂºÍÉϺ£ÉèÓм¸¸öÖ÷»ú¡£¡£¡£¡£¡£¡£TwoSail Junkͨ¹ýÔÚÂÛ̳Ðû²¼Á´½Ó»ò½¨Éè×Ô¼ºµÄÐÂÖ÷ÌâÀ´½«»á¼ûÕßÖ¸µ¼ÖÁÆäʹÓÃÕ¾µã¡£¡£¡£¡£¡£¡£ÖÁ½ñ£¬£¬£¬£¬£¬£¬¼Í¼ÁËÀ´×ÔÖйúÏã¸ÛµÄÊýÊ®´Î»á¼û£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»¶ÔÀ´×ÔÖйú°ÄÃÅ¡£¡£¡£¡£¡£¡£
0x02 ¶íÓïÏà¹ØµÄAPT×éÖ¯»î¶¯
1Ô£¬£¬£¬£¬£¬£¬ÔÚÒ»¼Ò¶«Å·µçÐŹ«Ë¾Öз¢Ã÷Á˼¸¸ö×î½ü±àÒëµÄSPLM/XAgentÄ£¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£¡£×î³õµÄ½øÈëµãÊÇδ֪µÄ£¬£¬£¬£¬£¬£¬ËüÃÇÔÚ¸Ã×éÖ¯ÄڵĺáÏòÔ˶¯Ò²ÊÇδ֪µÄ¡£¡£¡£¡£¡£¡£ÓëÒÑÍùµÄSofacy»î¶¯Ë®Æ½Ïà±È£¬£¬£¬£¬£¬£¬ÏÕЩÎÞ·¨Ê¶±ðSPLMѬȾ£¬£¬£¬£¬£¬£¬Òò´ËËÆºõ¸Ã¹«Ë¾ÄÚÍø¿ÉÄÜÒѾѬȾÁËÒ»¶Îʱ¼ä¡£¡£¡£¡£¡£¡£³ýÁËÕâЩSPLMÄ£¿£¿£¿£¿£¿£¿£¿éÖ®Í⣬£¬£¬£¬£¬£¬Sofacy»¹°²ÅÅÁË.NET XTUNNEL±äÌå¼°Æä¼ÓÔØ³ÌÐò¡£¡£¡£¡£¡£¡£ÓëÒÑÍùµÄXTUNNELÑù±¾£¨ÖØÁ¿Îª1-2MB£©Ïà±È£¬£¬£¬£¬£¬£¬ÕâЩ20KBµÄXTUNNELÑù±¾×Ô¼ºËƺõºÜÉÙ¡£¡£¡£¡£¡£¡£long-standing Sofacy XTunnel´úÂë¿âÏòC££µÄת±äʹÎÒÃÇÏëÆðZebrocyÖØÐ±àÂëºÍʹÓöàÖÖÓïÑÔÀ´Á¢Òìºã¾ÃʹÓõÄÄ£¿£¿£¿£¿£¿£¿£¿éµÄ×ö·¨¡£¡£¡£¡£¡£¡£
GamaredonÊÇÒ»¸ö×ÅÃûµÄAPT×éÖ¯£¬£¬£¬£¬£¬£¬ÖÁÉÙ´Ó2013Äê×îÏÈ»îÔ¾£¬£¬£¬£¬£¬£¬¹¥»÷Ä¿µÄÖ÷ÒªÕë¶ÔÎÚ¿ËÀ¼¡£¡£¡£¡£¡£¡£½ü¼¸¸öÔÂÀ´£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷ÁËÒ»¸ö¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÔ¶³ÌÄ£°å×¢Èë·¢ËͶñÒâÎĵµ£¬£¬£¬£¬£¬£¬´Ó¶ø°²ÅŶñÒâ¼ÓÔØ³ÌÐò£¬£¬£¬£¬£¬£¬¸Ã¼ÓÔØ³ÌÐò»á°´ÆÚÓëÔ¶³ÌC2ÁªÏµÒÔÏÂÔØÆäËûÑù±¾¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ö®Ç°µÄÑо¿£¬£¬£¬£¬£¬£¬GamaredonµÄ¹¤¾ß°ü°üÀ¨Ðí¶à²î±ðµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬ÓÃÓÚʵÏÖ²î±ðµÄÄ¿µÄ¡£¡£¡£¡£¡£¡£ÆäÖаüÀ¨É¨ÃèÇý¶¯Æ÷ÖеÄÌØ¶¨ÏµÍ³Îļþ£¬£¬£¬£¬£¬£¬²¶»ñÆÁÄ»¿ìÕÕ£¬£¬£¬£¬£¬£¬Ö´ÐÐÔ¶³ÌÏÂÁ£¬£¬£¬£¬£¬ÏÂÔØÆäËûÎļþÒÔ¼°Ê¹ÓÃUltraVNCµÈ³ÌÐòÖÎÀíÔ¶³ÌÅÌËã»ú¡£¡£¡£¡£¡£¡£ÔÚÕâÖÖÇéÐÎÏ£¬£¬£¬£¬£¬£¬ÎÒÃÇÊӲ쵽һ¸öÓÐȤµÄеĵڶþ½×¶Îpayload£¬£¬£¬£¬£¬£¬Æä¾ßÓÐÈö²¥¹¦Ð§£¬£¬£¬£¬£¬£¬ÎÒÃdzÆÖ®Îª¡°Aversome infector¡±¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¿ÉÔÚÄ¿µÄÍøÂçÖмá³Ö³¤ÆÚÐÔ£¬£¬£¬£¬£¬£¬²¢Í¨¹ýºáÏòÒÆ¶¯Ñ¬È¾ÍⲿÇý¶¯Æ÷ÉϵÄMicrosoft WordºÍExcelÎĵµ¡£¡£¡£¡£¡£¡£
0x03 ÖÐÎÄÏà¹ØµÄ APT ×éÖ¯»î¶¯
CactusPeteÊÇÒ»¸öÓëÖÐÎÄÏà¹ØµÄÍøÂçÌØ¹¤×éÖ¯£¬£¬£¬£¬£¬£¬ÖÁÉÙ´Ó2012Äê×îÏÈ»îÔ¾£¬£¬£¬£¬£¬£¬ÆäÌØÕ÷ÊǾßÓÐÖеÈˮƽµÄÊÖÒÕÄÜÁ¦¡£¡£¡£¡£¡£¡£´ÓÀúÊ·ÉÏ¿´£¬£¬£¬£¬£¬£¬¹¥»÷Ä¿µÄÖ÷ÒªÕë¶Ôº«¹ú£¬£¬£¬£¬£¬£¬ÈÕ±¾£¬£¬£¬£¬£¬£¬ÃÀ¹úºÍÖйų́ÍåµÈÉÙÊý¹ú¼Ò/µØÇøµÄ×éÖ¯¡£¡£¡£¡£¡£¡£ÔÚ2019Äêµ×£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ËÆºõתÏò¹Ø×¢ÃɹźͶíÂÞ˹£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÃɹÅÓï±àдÁËÒ»¸öÓÕ¶ü¹¥»÷Îĵµ¿ÉÊÍ·ÅFlapjackºóÃÅ£¨tmplogon.exe£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔеĶíÂÞ˹ĿµÄ£©¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿É¼û¸Ã×éÖ¯ÍØÕ¹ÁËÊÖÒÕ¹æÄ££¬£¬£¬£¬£¬£¬²¢ÇÒʹÓõÄ×ÊÔ´ºÍÒªÁìÒ²±¬·¢ÁËת±ä¡£¡£¡£¡£¡£¡£
×Ô2018ÄêÒÔÀ´£¬£¬£¬£¬£¬£¬RancorÊÇÒ»¸öÒѾ¹ûÕæ±¨µÀµÄ×éÖ¯£¬£¬£¬£¬£¬£¬ÓëDragonOKÓйØÁª¡£¡£¡£¡£¡£¡£¹¥»÷Ä¿µÄרעÓÚ¶«ÄÏÑÇ£¬£¬£¬£¬£¬£¬¼´¼íÆÒÕ¯£¬£¬£¬£¬£¬£¬Ô½ÄϺÍÐÂ¼ÓÆÂ¡£¡£¡£¡£¡£¡£ÎÒÃÇ×¢ÖØµ½¸Ã×éÖ¯ÔÚÒÑÍù¼¸¸öÔÂÖеĻÓм¸´¦¸üУ¬£¬£¬£¬£¬£¬·¢Ã÷ÁËDudell¶ñÒâÈí¼þµÄбäÖÖExDudell£¬£¬£¬£¬£¬£¬ExDudell¿ÉÒÔÈÆ¹ýUAC£¨Óû§ÕÊ»§¿ØÖÆ£©²¢ÇÒÓÃÓÚ¹¥»÷µÄеĻù´¡¼Ü¹¹¡£¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬£¬£¬ÎÒÃÇ»¹È·¶¨ÁËÒÔǰͨ¹ýÓʼþ·¢Ë͵ijõʼÓÕ¶üÎĵµÏÖÔÚ¿ÉÔÚTelegram DesktopĿ¼ÖÐÕÒµ½£¬£¬£¬£¬£¬£¬ÕâÅú×¢¸Ã×éÖ¯¿ÉÄÜÕýÔڸıäÆä³õʼͶµÝ·½·¨¡£¡£¡£¡£¡£¡£
ÔÚ2019Ä꣬£¬£¬£¬£¬£¬ÎÒÃǼì²âµ½Ò»¸öδ֪×éÖ¯µÄ»î¶¯£¬£¬£¬£¬£¬£¬ÆäʱÊÇÔÚ´ú±í²Ø×åÀûÒæµÄÍøÕ¾ÉϵÄË®¿Ó¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬ÓÕÆÊܺ¦Õß×°ÖÃÔÚGitHub´æ´¢¿âÉÏÍйܵļÙAdobe Flash¸üС£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿¨°Í˹»ùͨ¹ýÓëGitHubÏàÖúÀ´·ÀÓù¹¥»÷¡£¡£¡£¡£¡£¡£Ã»¹ý¶à¾Ã£¬£¬£¬£¬£¬£¬ÎÒÃÇÓÖ¼ì²âµ½ÐÂÒ»ÂÖË®¿Ó¹¥»÷¡£¡£¡£¡£¡£¡£ÎÒÃǾöÒ齫´Ë»î¶¯µÄ×éÖ¯ÃüÃûΪ¡°Holy Water¡±¡£¡£¡£¡£¡£¡£
×Ô½¨ÉèÖ®ÈÕÆð£¬£¬£¬£¬£¬£¬¹¥»÷Õß¼òÆÓ¶ø¸»Óд´ÒâµÄ¹¤¾ß¾ÍÔÚÒ»Ö±¿ª·¢ºÍ¸üÐÂÖУ¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÁËSojson»ìÏý£¬£¬£¬£¬£¬£¬NSIS×°ÖóÌÐò£¬£¬£¬£¬£¬£¬Python£¬£¬£¬£¬£¬£¬¿ªÔ´´úÂ룬£¬£¬£¬£¬£¬GitHub¿¯Ðа棬£¬£¬£¬£¬£¬GoÓïÑÔÒÔ¼°Google DriveµÈÊÖÒÕÊֶΡ£¡£¡£¡£¡£¡£
0x04 Öж«µØÇøµÄ APT »î¶¯
ÎÒÃÇ×î½üÔÚ2020Äê2Ô¼ì²âµ½ÁËStrongPity×éÖ¯Õë¶ÔÍÁ¶úÆäµÄÊý¾Ýй¶»î¶¯¡£¡£¡£¡£¡£¡£Ö»¹ÜStrongPityµÄTTPÔÚÄ¿µÄ£¬£¬£¬£¬£¬£¬»ù´¡ÉèÊ©ºÍѬȾǰÑÔ·½ÃæÃ»Óиı䣬£¬£¬£¬£¬£¬µ«ÎÒÃÇÊӲ쵽ËûÃÇÊÔͼй¶µÄÎļþÓÐËù²î±ð¡£¡£¡£¡£¡£¡£Ôڴ˻ÖУ¬£¬£¬£¬£¬£¬StrongPity¸üÐÂÁË×îеÄÊðÃûºóÃÅ£¬£¬£¬£¬£¬£¬ÃûΪStrongPity2£¬£¬£¬£¬£¬£¬²¢Ìí¼ÓÁ˸ü¶àÎļþÒÔÖ²ÈëÆä³£¼ûµÄOfficeºÍPDFÎĵµÁÐ±í£¬£¬£¬£¬£¬£¬°üÀ¨ÓÃÓÚÏ£²®À´ÕÚÑÚµÄDagesh Pro×Ö´¦Öóͷ£Æ÷Îļþ£¬£¬£¬£¬£¬£¬ÓÃÓÚºÓÁ÷Á÷Á¿ºÍÇÅÁº½¨Ä£µÄRiverCADÎļþ£¬£¬£¬£¬£¬£¬´¿Îı¾Îļþ£¬£¬£¬£¬£¬£¬¹éµµÎļþÒÔ¼°GPG¼ÓÃÜÎļþºÍPGPÃÜÔ¿¡£¡£¡£¡£¡£¡£
3Ô£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷ÁËWildPressure×éÖ¯Õë¶Ô¹¤ÒµÁìÓò·Ö·¢MilumľÂíµÄ»î¶¯£¬£¬£¬£¬£¬£¬Ö¼ÔÚ¶ÔÄ¿µÄ×éÖ¯ÖеÄ×°±¸¾ÙÐÐÔ¶³Ì¿ØÖÆ¡£¡£¡£¡£¡£¡£¸Ã»î¶¯×î³õ¿ÉÒÔ×·Ëݵ½2019Äê8Ô¡£¡£¡£¡£¡£¡£µ½ÏÖÔÚΪֹ£¬£¬£¬£¬£¬£¬ÎÒÃÇ¿´µ½µÄMilumʾÀýÓëÈκÎÒÑÖªµÄAPT»î¶¯Ã»ÓÐÈκδúÂëÏàËÆÐÔ¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þʹ¹¥»÷Õß¿ÉÒÔÔ¶³Ì¿ØÖÆÊÜѬȾµÄ×°±¸£¬£¬£¬£¬£¬£¬ÔÊÐíÏÂÔØºÍÖ´ÐÐÏÂÁ£¬£¬£¬£¬£¬ÍøÂçºÍй¶ÐÅÏ¢ÒÔ¼°ÔÚ¶ñÒâÈí¼þÖÐ×°ÖÃÉý¼¶³ÌÐò¡£¡£¡£¡£¡£¡£
ÔÚ2019Äê12ÔÂÏÂÑ®£¬£¬£¬£¬£¬£¬¿¨°Í˹»ùThreat Attribution Engine¼ì²âµ½ZerocleareµÄбäÌåDustman£¬£¬£¬£¬£¬£¬±»ÓÃÓÚÕë¶ÔÉ³ÌØ°¢À²®ÄÜÔ´²¿·ÖµÄ¹¥»÷¡£¡£¡£¡£¡£¡£ÔÚ²Á³ýºÍ·Ö·¢·½Ã棬£¬£¬£¬£¬£¬ËüÓëZerocleareÏàËÆ£¬£¬£¬£¬£¬£¬¿ÉÊDZäÁ¿ºÍÊÖÒÕÃû³ÆµÄת±äÅú×¢£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÒѾ׼±¸ºÃÓ½ÓÕë¶Ô¶ñÒâÈí¼þµÄÐÂÒ»²¨¹¥»÷£¬£¬£¬£¬£¬£¬ÕâЩ¹¥»÷»ùÓÚǶÈëÔÚ¶ñÒâÈí¼þÖеÄÐÂÎźͽ¨ÉèµÄ»¥³âÌ壬£¬£¬£¬£¬£¬×¨ÃÅÕë¶ÔÉ³ÌØ°¢À²®µÄÄÜÔ´²¿·Ö¡£¡£¡£¡£¡£¡£Í¨¹ýËü¡£¡£¡£¡£¡£¡£ÓйØDustmanµÄPDBÎļþÅú×¢£¬£¬£¬£¬£¬£¬¸ÃÆÆËðÐÔ´úÂëÊÇ¿¯Ðа棬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÄ¿µÄÍøÂçÖа²ÅÅ¡£¡£¡£¡£¡£¡£ÕâЩת±äÇ¡·êÐÂÄê¼ÙÆÚ£¬£¬£¬£¬£¬£¬ÔÚ´Ëʱ´úÐí¶àÔ±¹¤ÕýÔÚÐݼ١£¡£¡£¡£¡£¡£
0x05 ¶«ÄÏÑǺͳ¯Ïʰ뵺µÄAPT»î¶¯
Òâ´óÀûÇå¾²¹«Ë¾TelsyÔÚ2019Äê11Ô¸ÅÊöÁËLazarus×éÖ¯µÄ»î¶¯£¬£¬£¬£¬£¬£¬Ê¹ÎÒÃÇÄܹ»½«Õë¶Ô¼ÓÃÜÇ®±ÒÓªÒµµÄÏÈǰ»î¶¯ÁªÏµÆðÀ´¡£¡£¡£¡£¡£¡£Telsy²©¿ÍÉÏÌáµ½µÄ¶ñÒâÈí¼þÊǵÚÒ»½×¶ÎÏÂÔØ³ÌÐò£¬£¬£¬£¬£¬£¬×Ô2018ÄêÖÐÒÔÀ´Ò»Ö±±»ÊӲ쵽¡£¡£¡£¡£¡£¡£ÎÒÃÇ·¢Ã÷µÚ¶þ½×¶Î¶ñÒâÈí¼þÊÇManuscryptµÄ±äÌ壬£¬£¬£¬£¬£¬ËüÊÇLazarusµÄ¶ÀÍÌÊôÐÔ£¬£¬£¬£¬£¬£¬Æä°²ÅÅÁËÁ½ÖÖÀàÐ͵Äpayload¡£¡£¡£¡£¡£¡£µÚÒ»¸öÊÇ¿ÉʹÓõÄUltra VNC³ÌÐò£¬£¬£¬£¬£¬£¬µÚ¶þ¸öÊǶ༶ºóÃųÌÐò¡£¡£¡£¡£¡£¡£ÕâÖÖÀàÐ͵Ķà½×¶ÎѬȾÀú³ÌÊÇLazarus×éÖ¯¶ñÒâÈí¼þµÄµä·¶ÌØÕ÷£¬£¬£¬£¬£¬£¬ÓÈÆäÊÇʹÓÃManuscrypt±äÌå¡£¡£¡£¡£¡£¡£Ôڴ˻ÖУ¬£¬£¬£¬£¬£¬Lazarus×éÖ¯¹¥»÷ÁËÈûÆÖ·˹£¬£¬£¬£¬£¬£¬ÃÀ¹ú£¬£¬£¬£¬£¬£¬Öйų́ÍåºÍÖйúÏã¸ÛµÄ¼ÓÃÜÇ®±ÒÓªÒµ£¬£¬£¬£¬£¬£¬¸Ã»î¶¯Ò»Ö±Ò»Á¬µ½2020ÄêÍ·¡£¡£¡£¡£¡£¡£
×Ô2013ÄêÒÔÀ´ÎÒÃÇÒ»Ö±¸ú×ÙµÄ×éÖ¯KimsukyÔÚ2019ÄêÓÈÆä»îÔ¾¡£¡£¡£¡£¡£¡£12Ô£¬£¬£¬£¬£¬£¬Î¢Èí×÷·ÏÁ˸Ã×é֯ʹÓõÄ50¸öÓò£¬£¬£¬£¬£¬£¬²¢ÔÚ¸¥¼ªÄáÑÇÖÝ·¨Ôº¶Ô¹¥»÷ÕßÌáÆðÁËËßËÏ¡£¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬¸ÃС×é¼ÌÐø¿ªÕ¹»î¶¯£¬£¬£¬£¬£¬£¬Ã»Óб¬·¢ÖØ´óת±ä¡£¡£¡£¡£¡£¡£ÎÒÃÇ×î½ü·¢Ã÷ÁËÒ»¸öеĻ£¬£¬£¬£¬£¬£¬ÆäÖÐʹÓÃÁËÒÔÐÂÄêÎʺòΪÖ÷ÌâµÄÓÕ¶üͼƬ£¬£¬£¬£¬£¬£¬¸ÃͼƬΪ¾ÉÏÂÔØ¹¤¾ßÌṩÁËеľÓÉˢеÄÏÂÒ»½×¶Îpayload£¬£¬£¬£¬£¬£¬Ö¼ÔÚʹÓÃеļÓÃÜÒªÁìÀ´ÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£¡£
1ÔÂ⣬£¬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷ÁËʹÓÃInternet ExplorerÎó²î£¨CVE-2019-1367£©µÄ¶ñÒâ¾ç±¾¡£¡£¡£¡£¡£¡£ÔÚ×Ðϸ¼ì²épayload²¢·¢Ã÷ÓëÏÈǰ»î¶¯µÄÁªÏµÖ®ºó£¬£¬£¬£¬£¬£¬ÎÒÃǵóö½áÂÛ£¬£¬£¬£¬£¬£¬DarkHotelÖ§³Ö´Ë»î¶¯£¬£¬£¬£¬£¬£¬¸Ã»î¶¯¿ÉÄÜ×Ô2018ÄêÒÔÀ´Ò»Ö±ÔÚ¾ÙÐС£¡£¡£¡£¡£¡£¸Ã»î¶¯¿´µ½DarkHotelʹÓÿª·¢µÄÈí¼þʵÏÖÁ˶à½×¶Î¶þ½øÖÆÑ¬È¾¡£¡£¡£¡£¡£¡£×î³õµÄѬȾ»á½¨ÉèÒ»¸öÏÂÔØ³ÌÐò£¬£¬£¬£¬£¬£¬¸ÃÏÂÔØ³ÌÐò½«»ñÈ¡ÁíÒ»¸öÏÂÔØ³ÌÐòÒÔÍøÂçϵͳÐÅÏ¢£¬£¬£¬£¬£¬£¬²¢½öΪ¸ß¼ÛÖµÊܺ¦Õß»ñÈ¡×îÖյĺóÃųÌÐò¡£¡£¡£¡£¡£¡£DarkHotelÔڴ˻ÖÐʹÓÃÁËTTPµÄÆæÒì×éºÏ¡£¡£¡£¡£¡£¡£ÍþвÕßʹÓÃÖÖÖÖ»ù´¡½á¹¹À´ÍйܶñÒâÈí¼þ²¢¿ØÖÆÊÜѬȾµÄÊܺ¦Õߣ¬£¬£¬£¬£¬£¬°üÀ¨ÊÜѬȾµÄWebЧÀÍÆ÷£¬£¬£¬£¬£¬£¬ÉÌÒµÍйÜЧÀÍ£¬£¬£¬£¬£¬£¬Ãâ·ÑÍйÜЧÀͺÍÃâ·ÑÔ´´úÂë¸ú×Ùϵͳ¡£¡£¡£¡£¡£¡£
3Ô£¬£¬£¬£¬£¬£¬À´×ÔGoogleµÄÑо¿Ö°Ô±Í¸Â¶£¬£¬£¬£¬£¬£¬Ò»×éºÚ¿ÍÔÚ2019ÄêʹÓÃÁËÎå¸ö0day¹¥»÷Ä¿µÄÕë¶Ô³¯ÏÊÈ˺ÍÒÔ³¯ÏÊÈËΪÖÐÐĵÄרҵְԱ¡£¡£¡£¡£¡£¡£¸ÃС×éʹÓÃInternet Explorer£¬£¬£¬£¬£¬£¬ChromeºÍWindowsÖеÄÎó²îÀ´¾ÙÐÐÍøÂç´¹Âںͷַ¢µç×ÓÓʼþ£¬£¬£¬£¬£¬£¬ÕâЩµç×ÓÓʼþÖаüÀ¨¶ñÒ⸽¼þ»òÓë¶ñÒâÁ´½ÓÒÔ¼°Ë®¿Ó¹¥»÷¡£¡£¡£¡£¡£¡£ÎÒÃÇÄܹ»½«ÆäÖеÄÁ½¸öÎó²î»®·ÖΪIEÖеÄÒ»¸öÎó²îºÍWindowsÖеÄÒ»¸öÎó²îÓëDarkHotel×é֯ƥÅäÉÏ¡£¡£¡£¡£¡£¡£
FunnyDream×éÖ¯»î¶¯Ê¼ÓÚ2018ÄêÖУ¬£¬£¬£¬£¬£¬Õë¶ÔÂíÀ´Î÷ÑÇ£¬£¬£¬£¬£¬£¬Öйų́ÍåºÍ·ÆÂɱöµÄ×ÅÃû×éÖ¯£¬£¬£¬£¬£¬£¬ÆäÖдó´ó¶¼Êܺ¦ÕßÀ´×ÔÔ½ÄÏ¡£¡£¡£¡£¡£¡£ÆÊÎöÅú×¢£¬£¬£¬£¬£¬£¬ÕâÖ»ÊÇÒ»Ïî¸üÆÕ±é¹¥»÷»î¶¯µÄÒ»²¿·Ö£¬£¬£¬£¬£¬£¬¸Ã»î¶¯¿ÉÒÔ×·Ëݵ½¼¸Äêǰ£¬£¬£¬£¬£¬£¬²¢Õë¶Ô¶«ÄÏÑǹú¼ÒµÄÕþ¸®ÌØÊâÊÇÍâ¹ú×éÖ¯¡£¡£¡£¡£¡£¡£¹¥»÷ÕߵĺóÃÅ´ÓC2ÏÂÔØÎļþºÍÏòC2ÉÏ´«Îļþ£¬£¬£¬£¬£¬£¬Ö´ÐÐÏÂÁî²¢ÔÚÊܺ¦ÕßϵͳÖÐÔËÐÐÐÂÀú³Ì¡£¡£¡£¡£¡£¡£Ëü»¹ÍøÂçÓйØÍøÂçÉÏÆäËûÖ÷»úµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÔ¶³ÌÖ´ÐÐÓ¦ÓóÌÐò½«Æäת´ï¸øÐÂÖ÷»ú¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹Ê¹ÓÃÁËRTLºóÃźÍChinoxyºóÃÅ¡£¡£¡£¡£¡£¡£×Ô2018ÄêÄêÖÐÒÔÀ´£¬£¬£¬£¬£¬£¬C2»ù´¡Éèʩһֱ´¦ÓÚ»îԾ״̬£¬£¬£¬£¬£¬£¬²¢ÇÒdomainsÓëFFRAT¶ñÒâÈí¼þ¼Ò×åÖØµþ¡£¡£¡£¡£¡£¡£
Operation AppleJeusÊÇLazarus×îÓÐÓ°ÏìÁ¦µÄ»î¶¯Ö®Ò»£¬£¬£¬£¬£¬£¬Ö÷ҪʹÓÃMacOS¶ñÒâÈí¼þ¾ÙÐй¥»÷¡£¡£¡£¡£¡£¡£1Ô·ݵĺóÐøÑо¿Õ¹ÏÖÁ˸Ã×éÖ¯¹¥»÷ÒªÁìµÄÖØ´óת±ä£ºÐ¿ª·¢µÄmacOS¶ñÒâÈí¼þºÍÒ»ÖÖÉí·ÝÑéÖ¤»úÖÆ£¬£¬£¬£¬£¬£¬¿ÉÒÔÉóÉ÷µØ½»¸¶ÏÂÒ»½×¶ÎµÄpayload£¬£¬£¬£¬£¬£¬ÒÔ¼°ÔÚ²»½Ó´¥´ÅÅ̵ÄÇéÐÎϼÓÔØÏÂÒ»½×¶ÎµÄpayload¡£¡£¡£¡£¡£¡£ÎªÁ˹¥»÷WindowsÊܺ¦Õߣ¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ÖÆ¶©ÁËÒ»¸ö¶à½×¶ÎѬȾ³ÌÐò²¢¸ü¸ÄÁË×îÖÕpayload¡£¡£¡£¡£¡£¡£ÎÒÃÇÒÔΪ£¬£¬£¬£¬£¬£¬×Ô´ÓAppleJeus»î¶¯ÒÔÀ´£¬£¬£¬£¬£¬£¬LazarusÔÚ¹¥»÷·½ÃæÔ½·¢ÉóÉ÷£¬£¬£¬£¬£¬£¬²¢½ÓÄÉÁ˶àÖÖÒªÁìÀ´×èÖ¹±»·¢Ã÷¡£¡£¡£¡£¡£¡£ÎÒÃÇÔÚÓ¢¹ú£¬£¬£¬£¬£¬£¬²¨À¼£¬£¬£¬£¬£¬£¬¶íÂÞ˹ºÍÖйúÈ·¶¨Á˼¸ÃûÊܺ¦Õß¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÎÒÃÇÄܹ»È·ÈÏһЩÊܺ¦ÕßÓë¼ÓÃÜÇ®±Ò×éÖ¯Óйء£¡£¡£¡£¡£¡£
Roaming MantisÊÇÒ»¸ö³öÓÚ¾¼ÃÄîÍ·µÄAPT×éÖ¯£¬£¬£¬£¬£¬£¬ÓÚ2017ÄêÊ״ᨵÀ£¬£¬£¬£¬£¬£¬Æäʱ¸Ã¹«Ë¾Ê¹ÓÃSMS½«Æä¶ñÒâÈí¼þ·Ö·¢¸øÎ»ÓÚº«¹úµÄAndroid×°±¸¡£¡£¡£¡£¡£¡£ØÊºó¸Ã×éÖ¯µÄ»î¶¯¹æÄ£À©´ó£¬£¬£¬£¬£¬£¬Ö§³Ö27ÖÖÓïÑÔ£¬£¬£¬£¬£¬£¬ÒÔiOSºÍAndroidΪĿµÄ£¬£¬£¬£¬£¬£¬ÉõÖÁÍÚ¾ò¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯»¹Ê¹ÓÃÁËеĶñÒâÈí¼þ¼Ò×壬£¬£¬£¬£¬£¬°üÀ¨FakecopºÍWroba.j£¬£¬£¬£¬£¬£¬²¢ÇÒÈÔÔÚʹÓá°SMiShing¡±¾ÙÐÐAndroid¶ñÒâÈí¼þ·Ö·¢¡£¡£¡£¡£¡£¡£ÔÚ×î½üµÄÒ»Ïî»î¶¯ÖУ¬£¬£¬£¬£¬£¬Ëü·Ö·¢ÁËαװ³ÉÊܽӴýµÄ¿ìµÝ¹«Ë¾µÄ¶ñÒâAPK£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÈÕ±¾£¬£¬£¬£¬£¬£¬Öйų́Í壬£¬£¬£¬£¬£¬º«¹úºÍ¶íÂÞ˹¡£¡£¡£¡£¡£¡£
0x06 ÆäËü
TransparentTribeÓÚ2019ÄêÍ·×îÏÈʹÓÃÃûΪUSBWormµÄÐÂÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬²¢¶ÔÆäÃûΪCrimsonRATµÄ×Ô½ç˵.NET¹¤¾ß¾ÙÐÐÁËˢС£¡£¡£¡£¡£¡£Æ¾Ö¤Z6×ðÁú¿Ê±Ò£²â·¢Ã÷£¬£¬£¬£¬£¬£¬USBWorm±»ÓÃÀ´Ñ¬È¾³ÉǧÉÏÍòµÄÊܺ¦Õߣ¬£¬£¬£¬£¬£¬ÆäÖдó´ó¶¼Î»ÓÚ°¢¸»º¹ºÍÓ¡¶È£¬£¬£¬£¬£¬£¬Ê¹¹¥»÷ÕßÄܹ»ÏÂÔØºÍÖ´ÐÐí§ÒâÎļþ£¬£¬£¬£¬£¬£¬Èö²¥µ½¿ÉÒÆ¶¯×°±¸²¢´ÓÊÜѬȾµÄÖ÷»úÇÔÈ¡¸ÐÐËȤµÄÎļþ¡£¡£¡£¡£¡£¡£ÕýÈçÎÒÃÇ֮ǰ±¨µÀµÄÄÇÑù£¬£¬£¬£¬£¬£¬¸ÃС×éÖ÷Òª¹Ø×¢¾üÊÂÄ¿µÄ£¬£¬£¬£¬£¬£¬ÕâЩĿµÄͨ³£Êܵ½OfficeÎĵµÖжñÒâVBAºÍPeppy RAT¡¢CrimsonRATµÈ¿ªÔ´¶ñÒâÈí¼þµÄ¹¥»÷¡£¡£¡£¡£¡£¡£×î½üµÄлÖУ¬£¬£¬£¬£¬£¬ÎÒÃÇ×¢ÖØµ½¸ÃС×éµÄÖØµã¸ü¶àµØ×ªÏòÁËÕë¶ÔÓ¡¶ÈÒÔÍâµÄ°¢¸»º¹¡£¡£¡£¡£¡£¡£
ÔÚ2019ÄêµÄ×îºó¼¸¸öÔÂÖУ¬£¬£¬£¬£¬£¬ÎÒÃÇÊӲ쵽ÁËFishing ElephantÕýÔÚ¾ÙÐеÄÒ»Ïî»î¶¯¡£¡£¡£¡£¡£¡£¸ÃС×é¼ÌÐøÊ¹ÓÃHerokuºÍDropboxÀ´½»¸¶ÆäÑ¡ÔñµÄ¹¤¾ßAresRAT¡£¡£¡£¡£¡£¡£ÎÒÃÇ·¢Ã÷£¬£¬£¬£¬£¬£¬¼ÓÈëÕßÔÚÆä²Ù×÷ÖнÓÄÉÁËÒ»ÏîÐÂÊÖÒÕ£¬£¬£¬£¬£¬£¬¸ÃÊÖÒÕÖ¼ÔÚ×èÖ¹ÊÖ¶¯ºÍ×Ô¶¯ÆÊÎögeo-fencingºÍ½«¿ÉÖ´ÐÐÎļþÒþ²ØÔÚÖ¤ÊéÎļþÖС£¡£¡£¡£¡£¡£ÔÚZ6×ðÁú¿Ê±Ñо¿Àú³ÌÖУ¬£¬£¬£¬£¬£¬ÎÒÃÇ»¹·¢Ã÷Êܺ¦ÕßµÄת±ä¿ÉÄÜ·´Ó¦Á˹¥»÷ÕßµÄÄ¿½ñÀûÒæ£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯µÄÄ¿µÄÊÇÍÁ¶úÆä£¬£¬£¬£¬£¬£¬°Í»ù˹̹£¬£¬£¬£¬£¬£¬ÃϼÓÀ¹ú£¬£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼ºÍÖйúµÄÕþ¸®ºÍÍâ½»»ú¹¹¡£¡£¡£¡£¡£¡£
0x07 ½áÓï
Ö»¹ÜÍþвÐÎÊÆ²¢²»×ÜÊdzäÂú¡°Í»ÆÆÐÔ¡±ÊÂÎñ£¬£¬£¬£¬£¬£¬µ«µ±ÎÒÃǽ«ÑÛ¹âͶÏòAPTÍþвÐÐΪÕߵĻʱ£¬£¬£¬£¬£¬£¬×ÜÊÇ»áÓÐÓÐȤµÄÉú³¤¡£¡£¡£¡£¡£¡£Z6×ðÁú¿Ê±°´ÆÚ¼¾¶ÈÉó²éÖ¼ÔÚÇ¿µ÷Òªº¦µÄÉú³¤¡£¡£¡£¡£¡£¡£
ÕâЩÊǵ½ÏÖÔÚΪֹÎÒÃǽñÄêÒѾ¿´µ½µÄһЩÖ÷ÒªÇ÷ÊÆ¡£¡£¡£¡£¡£¡£
¡ñ µØÔµÕþÖÎÈÔÈ»ÊÇAPT»î¶¯µÄÖ÷ÒªÖúÍÆÁ¦¡£¡£¡£¡£¡£¡£
¡ñ LazarusºÍRoaming MantisµÄ»î¶¯Ö¤Êµ£¬£¬£¬£¬£¬£¬¾¼ÃÀûÒæÈÔÈ»ÊÇijЩ¹¥»÷ÕßµÄÄîÍ·¡£¡£¡£¡£¡£¡£
¡ñ ¾ÍAPT»î¶¯¶øÑÔ£¬£¬£¬£¬£¬£¬¶«ÄÏÑÇÊÇ×î»îÔ¾µÄµØÇø£¬£¬£¬£¬£¬£¬°üÀ¨Lazarus£¬£¬£¬£¬£¬£¬DarkHotelºÍKimsukyµÈ×éÖ¯£¬£¬£¬£¬£¬£¬ÒÔ¼°Cloud SnooperºÍFishing ElephantµÈÐÂÐË×éÖ¯¡£¡£¡£¡£¡£¡£
¡ñ APT×éÖ¯£¬£¬£¬£¬£¬£¬ÀýÈçCactusPete£¬£¬£¬£¬£¬£¬TwoSail Junk£¬£¬£¬£¬£¬£¬FunnyDreamºÍDarkHotel£¬£¬£¬£¬£¬£¬¼ÌÐøÊ¹ÓÃÈí¼þÎó²î¡£¡£¡£¡£¡£¡£
¡ñ APT×éÖ¯¼ÌÐø½«mobile implantsÄÉÈëÆäÎäÆ÷¿â¡£¡£¡£¡£¡£¡£
¡ñ APT×éÖ¯£¨ÀýÈ絫²»ÏÞÓÚKimsuky£¬£¬£¬£¬£¬£¬HadesºÍDarkHotel£©ÒÔʵʱ»úÖ÷Òå×ï·¸ÕýÔÚʹÓÃCOVID-19¡£¡£¡£¡£¡£¡£
×ܶøÑÔÖ®£¬£¬£¬£¬£¬£¬ÎÒÃÇ¿´µ½ÁËÑÇÖÞ¹¥»÷»î¶¯µÄÒ»Á¬ÔöÌí£¬£¬£¬£¬£¬£¬Ê¹ÓÃÒÆ¶¯Æ½Ì¨Ñ¬È¾ºÍÈö²¥¶ñÒâÈí¼þµÄÇ÷ÊÆÕýÔÚÉÏÉý¡£¡£¡£¡£¡£¡£
ÏÖÔÚ£¬£¬£¬£¬£¬£¬COVID-19Êܵ½Ã¿Ð¡ÎÒ˽¼ÒµÄ¹Ø×¢£¬£¬£¬£¬£¬£¬¶øAPT×éÖ¯Ò²Ò»Ö±ÔÚʵÑéÔÚÓã²æÊ½ÍøÂç´¹ÂڻÖÐʹÓÃÕâÒ»Ö÷Ìâ¡£¡£¡£¡£¡£¡£ÎÒÃÇÒÔΪÕâ²¢²»´ú±íTTP±¬·¢ÁËÓÐÒâÒåµÄת±ä£ºËûÃÇÖ»Êǽ«ÆäÓÃ×÷¾ßÓÐÐÂÎżÛÖµµÄ»°ÌâÀ´ÎüÒýÊܺ¦Õß¡£¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬ÎÒÃÇÕýÔÚÇ×½ü¼àÊÓÊ±ÊÆ¡£¡£¡£¡£¡£¡£
0x08 ²Î¿¼Á´½Ó
https://securelist.com/apt-trends-report-q1-2020/96826/
0x09 ʱ¼äÏß
2020-05-01 VSRCÐû²¼±¨¸æ


¾©¹«Íø°²±¸11010802024551ºÅ