NCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ£»£»£»£»£»ÐµÄAndroidľÂíBanker.BRʹÓÃÁýÕÖ¹¥»÷Ãé×¼ÒøÐÐÖ÷¹Ë
Ðû²¼Ê±¼ä 2020-04-221.CNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ
¹ú¼Ò»¥ÁªÍøÓ¦¼±ÖÐÐÄ£¨CNCERT£©ÓÚ2020Äê4ÔÂ20ÈÕÐû²¼ÁË¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ¡£¡£¡£¡£¡£¸Ã±¨¸æ×¤×ãÓÚCNCERTÍøÂçÇå¾²ºê¹Û¼à²âÊý¾ÝÓëÊÂÇéʵ¼ù±¨¸æ£¬£¬£¬£¬£¬Éæ¼°2019Äêµä·¶ÍøÂçÇå¾²ÊÂÎñ¡¢ÍøÂçÇå¾²ÐÂÇ÷ÊÆ¼°Ò»Ñùƽ³£ÍøÂçÇå¾²ÊÂÎñÓ¦¼±´¦Öóͷ£Êµ¼ùµÈÄÚÈÝ¡£¡£¡£¡£¡£±¨¸æÖ÷Òª°üÀ¨Ëĸö²¿·Ö£¬£¬£¬£¬£¬Ò»ÊÇ×ܽá2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇ徲״̬£¬£¬£¬£¬£¬¶þÊÇÕ¹Íû2020ÄêÍøÂçÇå¾²ÈÈÃÅ£¬£¬£¬£¬£¬ÈýÊÇÁ¬ÏµÍøÂçÇå¾²Ì¬ÊÆÆÊÎöÌá³ö¶Ô²ß½¨Ò飬£¬£¬£¬£¬ËÄÊÇÊáÀíÍøÂçÇå¾²¼à²âÊý¾Ý¡£¡£¡£¡£¡£¸Ã±¨¸æ¶ÔÎÒ¹úµ³Õþ»ú¹Ø¡¢ÐÐÒµÆóÒµ¼°È«Éç»áÏàʶÎÒ¹úÍøÂçÇå¾²ÐÎÊÆ£¬£¬£¬£¬£¬Ìá¸ßÍøÂçÇå¾²Òâʶ£¬£¬£¬£¬£¬×öºÃÍøÂçÇå¾²ÊÂÇéÌṩÁËÓÐÁ¦²Î¿¼¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2020-04/20/c_1588932297982643.htm
2.Winnti groupÕë¶ÔµÂ¹ú»¯¹¤¹«Ë¾¹¥»÷Ñù±¾µÄÆÊÎö±¨¸æ
1Ô·ÝQuoIntelligence£¨QuoINT£©¼ì²âµ½Ò»¸öеÄWinntiÑù±¾²¢¶ÔÆä¾ÙÐÐÁËÆðÔ´µÄÆÊÎö¡£¡£¡£¡£¡£ÆÊÎö·¢Ã÷£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ¿ÉÄÜÊÇÔÚ2015Äê±»¿ª·¢³öÀ´µÄ¡£¡£¡£¡£¡£¸ÃÑù±¾±»ÓÃÓÚ¹¥»÷Ò»¼ÒµÂ¹ú»¯¹¤¹«Ë¾£¬£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎú¸Ã¹«Ë¾µÄÏêϸÃû³Æ¡£¡£¡£¡£¡£¸ÃÑù±¾½ÓÄÉÁËеÄC2ÊÖÒÕ£¬£¬£¬£¬£¬ÒÀÀµÓÚͨ¹ýiodineÔ´´úÂëʵÏÖµÄDNSËíµÀ¾ÙÐÐͨѶ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹·¢Ã÷ÁËÒ»¸öÒÔǰδ֪µÄ±»µÁÊý×ÖÖ¤Ê飬£¬£¬£¬£¬¸ÃÖ¤ÊéÖ÷ÒªÓÃÀ´¶ÔWinntiÏà¹ØµÄÇý¶¯³ÌÐò¾ÙÐÐÊý×ÖÊðÃû£¬£¬£¬£¬£¬²¢ÇÒÓÃÓÚ¹¥»÷º«¹úÓÎÏ·¹«Ë¾Gravity¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://quointelligence.eu/2020/04/winnti-group-insights-from-the-past/
3.½©Ê¬ÍøÂçMootbotʹÓÃ0day¹¥»÷9¿î¹âÏË·ÓÉÆ÷
Ñо¿Ö°Ô±·¢Ã÷×Ô2ÔÂÏÂÑ®Æð£¬£¬£¬£¬£¬½©Ê¬ÍøÂçMootbot±ã×îÏÈʹÓÃ0day¹¥»÷9¿î¼ÒÓü°ÉÌÓùâÏË·ÓÉÆ÷£¨°üÀ¨Netlink GPON·ÓÉÆ÷£©¡£¡£¡£¡£¡£MoobotÊÇ»ùÓÚMiraiµÄн©Ê¬ÍøÂ磬£¬£¬£¬£¬ÆäÄ¿µÄÊÇÎïÁªÍø£¨IoT£©×°±¸¡£¡£¡£¡£¡£ÓÉÓÚ´ó´ó¶¼¹©Ó¦É̺ܿÉÄÜÊǽÓÄÉÁËͳһÔʼ¹©Ó¦É̵ÄOEM²úÆ·£¬£¬£¬£¬£¬Òò´ËÕâЩ·ÓÉÆ÷ÊÜͳһ0dayÓ°Ïì¡£¡£¡£¡£¡£¸ÃÎó²îΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬ÆäPoCÒѾÐû²¼£¬£¬£¬£¬£¬µ¥¶ÀʹÓøÃÎó²î²»»áÔì³ÉΣº¦£¬£¬£¬£¬£¬Ö»ÓÐÓëÁíÒ»¸öÎó²îÒ»ÆðʹÓòŻªÊµÏÖ¹¥»÷¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ã»ÓÐÅû¶µÚ¶þ¸öÎó²îµÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/mootbot-fiber-routers-zero-days/154962/
4.ProofpointÖÒÑÔʹÓÃÊÓÆµ¾Û»á¹«Ë¾µÄ´¹ÂÚ¹¥»÷³ÊÔöÌíÇ÷ÊÆ
ProofpointÑо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬ÒÔÊÓÆµ¾Û»á¹«Ë¾ÎªÖ÷ÌâµÄÍøÂç´¹ÂÚ¹¥»÷ÊýÄ¿³ÊÔöÌíÇ÷ÊÆ£¬£¬£¬£¬£¬ÕâЩ¹¥»÷Ö¼ÔÚÇÔÈ¡Óû§µÇ¼ƾ֤ºÍÈö²¥¶ñÒâÈí¼þ¡£¡£¡£¡£¡£ProofpointÖÒÑԳƣ¬£¬£¬£¬£¬ºÚ¿Í²»»áÖ±½Ó¹¥»÷ÕâЩÊÓÆµ¾Û»áÈí¼þ£¬£¬£¬£¬£¬¿ÉÊÇ»áÒÔÊÓÆµ¾Û»á¹«Ë¾µÄÃû³ÆÎªÓÕ¶üÇÔÈ¡Óû§ÕÊ»§Æ¾Ö¤ºÍÈö²¥¶ñÒâÈí¼þ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷µÄ´¹ÂÚ³¡¾°°üÀ¨£ºÎ±ÔìCisco WebExµÄÖÒÑÔÓʼþÀ´ÇÔÈ¡ÃÀ¹úÓû§µÄÕË»§ÐÅÏ¢£»£»£»£»£»Ã°³äZoom AccountÇÔÈ¡ÃÀ¹úÄÜÔ´¡¢ÖÆÔìºÍÉÌÒµµÈÐÐÒµµÄÓû§Æ¾Ö¤£»£»£»£»£»ÒÔ"zoom call"ΪÖ÷ÌâÈö²¥ServLoaderºÍNetSupport RATµÈ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.proofpoint.com/us/threat-insight/post/remote-video-conferencing-themes-credential-theft-and-malware-threats
5.FoxitÐÞ¸´PDF Reader¼°PhantomPDFÖеĶà¸öÎó²î
FoxitÐÞ¸´ÁËWindows°æ±¾µÄFoxit ReaderºÍFoxit PhantomPDFÖеÄ20¸öCVEÎó²î¡£¡£¡£¡£¡£Ê×ÏÈ£¬£¬£¬£¬£¬FoxitÔÚPDF Reader 9.7.2°æ±¾ÖÐÐÞ¸´Á˶à¸öRCEÎó²î£¬£¬£¬£¬£¬°üÀ¨XFAÄ£°å´¦Öóͷ£Àú³ÌÖеÄRCEÎó²î£¨CVE-2020-10899¡¢ CVE-2020-10907£©£¬£¬£¬£¬£¬AcroFormsÖеÄRCEÎó²î£¨CVE-2020-10900£©ÒÔ¼°resetFormÖеÄRCEÎó²î£¨CVE-2020-10906£©¡£¡£¡£¡£¡£¹ØÓÚPhantomPDF£¬£¬£¬£¬£¬´Ë´Î¸üÐÂÐÞ¸´ÁËAPIͨѶÖеÄÁ½¸öÒ×±»Ê¹ÓõÄí§ÒâÎļþдÈëÎó²î£¨CVE-2020-10890ºÍCVE-2020-10892£©£¬£¬£¬£¬£¬ÒÔ¼°Á½¸öÓйØSetFieldValueÏÂÁî´¦Öóͷ£µÄ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-10912ºÍCVE-2020-10912£©¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬´Ë´Î¸üл¹ÐÞ¸´ÁËU3DBrowser²å¼þÖеÄ11¸öÎó²î¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/foxit-pdf-reader-phantompdf-remote-code-execution/154942/
6.еÄAndroidľÂíBanker.BRʹÓÃÆÁÄ»ÁýÕÖ¹¥»÷Ãé×¼ÒøÐпͻ§
IBM X-ForceÑо¿Ö°Ô±·¢Ã÷еÄAndroidľÂíBanker.BR£¬£¬£¬£¬£¬ÆäʹÓÃÆÁÄ»ÁýÕÖ¹¥»÷Õë¶ÔʹÓÃÎ÷°àÑÀÓï»òÆÏÌÑÑÀÓ°üÀ¨Î÷°àÑÀ¡¢ÆÏÌÑÑÀ¡¢°ÍÎ÷ºÍÀ¶¡ÃÀÖÞÆäËûµØÇø£©µÄÒøÐпͻ§£¬£¬£¬£¬£¬ÍýÏëÇÔÈ¡Óû§Æ¾Ö¤²¢ÍµÈ¡ÆäÕË»§¡£¡£¡£¡£¡£Ñо¿·¢Ã÷£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þµÄÔçÆÚ°æ±¾½ö¾ßÓлù±¾µÄSMSÇÔÈ¡¹¦Ð§£¬£¬£¬£¬£¬¿ÉÊÇBanker.BR¸üΪϸÄ壬£¬£¬£¬£¬¾ßÓÐÁýÕÖ¹¥»÷µÄ¹¦Ð§²¢ÇÒÓÐȫеĴúÂ룬£¬£¬£¬£¬²»ÒÀÀµÓÚÏÈǰ×ß©µÄ´úÂë»òÏÖÓеÄÒÆ¶¯¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýÓÕʹÓû§ÏÂÔØÃ°³äµÄÒøÐÐÇå¾²Ó¦ÓóÌÐò¾ÙÐÐÈö²¥£¬£¬£¬£¬£¬µÈÓû§ÀÖ³É×°Öúó±ã»áÇÔÈ¡Óû§×°±¸ÐÅÏ¢£¬£¬£¬£¬£¬°üÀ¨µç»°ºÅÂë¡¢¹ú¼ÊÒÆ¶¯×°±¸Ê¶±ðÂ루IMEI£©¡¢¹ú¼ÊÒÆ¶¯Óû§Ê¶±ðÂ루IMSI£©ºÍSIMÐòÁкţ¬£¬£¬£¬£¬²¢½«ÐÅÏ¢·¢Ë͸øC2ЧÀÍÆ÷¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÒÀÈ»ÔÚ¿ª·¢ÖС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/android-banking-br-trojan-credential-stealing/154990/


¾©¹«Íø°²±¸11010802024551ºÅ