¿¨°Í˹»ù | 2020ÄêQ1 APTÇ÷ÊÆ±¨¸æ

Ðû²¼Ê±¼ä 2020-05-01

¿¨°Í˹»ùÐû²¼2020ÄêµÚÒ»¼¾¶ÈµÄAPT×éÖ¯»î¶¯µÄÇ÷ÊÆ±¨¸æ£¬£¬£¬£¬ £¬£¬Ö÷Ҫ˵Ã÷ÖØ´óµÄAPT»î¶¯ÒÔ¼°Ñо¿·¢Ã÷¡£¡£¡£¡£


0x00 COVID-19 APT»î¶¯


×ÔÌìÏÂÎÀÉú×éÖ¯£¨WHO£©Ðû²¼COVID-19³ÉΪÎÁÒßÒÔÀ´£¬£¬£¬£¬ £¬£¬ÕâÒ»»°ÌâÒÑÊܵ½²î±ð¹¥»÷ÕßÔ½À´Ô½¶àµÄ¹Ø×¢¡£¡£¡£¡£Ðí¶àÍøÂç´¹ÂÚÕ©Æ­¶¼ÊÇÓÉÍøÂç·¸·¨·Ö×ÓÌᳫµÄ£¬£¬£¬£¬ £¬£¬ËûÃÇÊÔͼʹÓÃÈËÃǶԲ¡¶¾µÄ¿Ö¾åÀ´×¬Ç®¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬ £¬£¬¹¥»÷ÕßÁбíÖл¹°üÀ¨APT×éÖ¯£¬£¬£¬£¬ £¬£¬ÀýÈçKimsuky£¬£¬£¬£¬ £¬£¬APT27£¬£¬£¬£¬ £¬£¬Lazarus»òViciousPanda£¬£¬£¬£¬ £¬£¬Æ¾Ö¤OSINT£¬£¬£¬£¬ £¬£¬ËûÃÇÒÔCOVID-19×÷ΪÓÕ¶üÃé×¼Êܺ¦Õß¡£¡£¡£¡£ÎÒÃÇ×î½ü·¢Ã÷ÁË¿ÉÒɵĻù´¡ÉèÊ©¿ÉÓÃÓÚÕë¶Ô°üÀ¨WHOÔÚÄÚµÄÎÀÉúºÍÈËÐÔÖ÷Òå×éÖ¯¡£¡£¡£¡£¾ÝһЩ˽ÈËÐÂÎÅȪԴ³Æ£¬£¬£¬£¬ £¬£¬Ö»¹Ü»ù´¡ÉèÊ©ÏÖÔÚÎÞ·¨¹éÒòÓÚÈκÎÌØ¶¨µÄ×éÖ¯£¬£¬£¬£¬ £¬£¬²¢ÇÒÒÑÔÚ2019Äê6ÔÂCOVID-19Σ»£»£»ú֮ǰע²á£¬£¬£¬£¬ £¬£¬µ«Ëü¿ÉÄÜÓëDarkHotelÓйØ¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬ £¬£¬ÎÒÃÇÏÖÔÚÎÞ·¨È·ÈÏ´ËÐÅÏ¢¡£¡£¡£¡£ÓÐȤµÄÊÇ£¬£¬£¬£¬ £¬£¬Ò»Ð©×é֯ʹÓÃÄ¿½ñÇéÐÎÀ´Ðû²¼ËûÃÇÔÚΣ»£»£»úʱ´ú²»»áÕë¶ÔÎÀÉú×éÖ¯¡£¡£¡£¡£


0x01 ×îÖµµÃ×¢ÖØµÄÇ÷ÊÆ


2020Äê1Ô£¬£¬£¬£¬ £¬£¬ÎÒÃÇ·¢Ã÷Ò»¸öË®¿Ó¹¥»÷ʹÓÃÍêÈ«µÄÔ¶³ÌiOSÎó²î¡£¡£¡£¡£Õâ¸öÍøÕ¾µÄÄ¿µÄÊÇÆ¾Ö¤Ä¿µÄÍøÒ³µÄÄÚÈÝÀ´¶¨Î»ÖйúÏã¸ÛµÄÓû§¡£¡£¡£¡£ËäȻĿ½ñÕýÔÚʹÓõÄÎó²îʹÓóÌÐòÊÇÒÑÖªµÄ£¬£¬£¬£¬ £¬£¬µ«ÈÏÕæÖ°Ô±ÕýÔÚÆð¾¢ÐÞ¸ÄÎó²îʹÓù¤¾ß°ü£¬£¬£¬£¬ £¬£¬ÒÔÕë¶Ô¸ü¶àµÄiOS°æ±¾ºÍ×°±¸¡£¡£¡£¡£ÎÒÃÇÔÚ2ÔÂ7ÈÕÊӲ쵽ÁË×îеİ汾¡£¡£¡£¡£¸ÃÏîÄ¿±ÈÎÒÃÇ×î³õÏëÏóµÄÒªÆÕ±é£¬£¬£¬£¬ £¬£¬ËüÖ§³ÖAndroidÖ²È룬£¬£¬£¬ £¬£¬²¢ÇÒ¿ÉÄÜÖ§³ÖWindows£¬£¬£¬£¬ £¬£¬LinuxºÍMacOSµÄÖ²Èë¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬ £¬£¬ÎÒÃǽ«´ËAPT×éÖ¯³ÆÎªTwoSail Junk¡£¡£¡£¡£ÎÒÃÇÒÔΪÕâÊÇÒ»ÆäÖÐÎÄ×éÖ¯£¬£¬£¬£¬ £¬£¬ËüÖ÷ÒªÔÚÖйúÏã¸Ûά»¤»ù´¡ÉèÊ©£¬£¬£¬£¬ £¬£¬²¢ÔÚÐÂ¼ÓÆÂºÍÉϺ£ÉèÓм¸¸öÖ÷»ú¡£¡£¡£¡£TwoSail Junkͨ¹ýÔÚÂÛ̳Ðû²¼Á´½Ó»ò½¨Éè×Ô¼ºµÄÐÂÖ÷ÌâÀ´½«»á¼ûÕßÖ¸µ¼ÖÁÆäʹÓÃÕ¾µã¡£¡£¡£¡£ÖÁ½ñ£¬£¬£¬£¬ £¬£¬¼Í¼ÁËÀ´×ÔÖйúÏã¸ÛµÄÊýÊ®´Î»á¼û£¬£¬£¬£¬ £¬£¬ÆäÖÐÒ»¶ÔÀ´×ÔÖйú°ÄÃÅ¡£¡£¡£¡£


0x02 ¶íÓïÏà¹ØµÄAPT×éÖ¯»î¶¯


1Ô£¬£¬£¬£¬ £¬£¬ÔÚÒ»¼Ò¶«Å·µçÐŹ«Ë¾Öз¢Ã÷Á˼¸¸ö×î½ü±àÒëµÄSPLM/XAgentÄ£¿ £¿£¿£¿£¿£¿é¡£¡£¡£¡£×î³õµÄ½øÈëµãÊÇδ֪µÄ£¬£¬£¬£¬ £¬£¬ËüÃÇÔÚ¸Ã×éÖ¯ÄڵĺáÏòÔ˶¯Ò²ÊÇδ֪µÄ¡£¡£¡£¡£ÓëÒÑÍùµÄSofacy»î¶¯Ë®Æ½Ïà±È£¬£¬£¬£¬ £¬£¬ÏÕЩÎÞ·¨Ê¶±ðSPLMѬȾ£¬£¬£¬£¬ £¬£¬Òò´ËËÆºõ¸Ã¹«Ë¾ÄÚÍø¿ÉÄÜÒѾ­Ñ¬È¾ÁËÒ»¶Îʱ¼ä¡£¡£¡£¡£³ýÁËÕâЩSPLMÄ£¿ £¿£¿£¿£¿£¿éÖ®Í⣬£¬£¬£¬ £¬£¬Sofacy»¹°²ÅÅÁË.NET XTUNNEL±äÌå¼°Æä¼ÓÔØ³ÌÐò¡£¡£¡£¡£ÓëÒÑÍùµÄXTUNNELÑù±¾£¨ÖØÁ¿Îª1-2MB£©Ïà±È£¬£¬£¬£¬ £¬£¬ÕâЩ20KBµÄXTUNNELÑù±¾×Ô¼ºËƺõºÜÉÙ¡£¡£¡£¡£long-standing Sofacy XTunnel´úÂë¿âÏòC££µÄת±äʹÎÒÃÇÏëÆðZebrocyÖØÐ±àÂëºÍʹÓöàÖÖÓïÑÔÀ´Á¢Òìºã¾ÃʹÓõÄÄ£¿ £¿£¿£¿£¿£¿éµÄ×ö·¨¡£¡£¡£¡£


GamaredonÊÇÒ»¸ö×ÅÃûµÄAPT×éÖ¯£¬£¬£¬£¬ £¬£¬ÖÁÉÙ´Ó2013Äê×îÏÈ»îÔ¾£¬£¬£¬£¬ £¬£¬¹¥»÷Ä¿µÄÖ÷ÒªÕë¶ÔÎÚ¿ËÀ¼¡£¡£¡£¡£½ü¼¸¸öÔÂÀ´£¬£¬£¬£¬ £¬£¬ÎÒÃÇ·¢Ã÷ÁËÒ»¸ö¹¥»÷»î¶¯£¬£¬£¬£¬ £¬£¬¹¥»÷Õßͨ¹ýÔ¶³ÌÄ£°å×¢Èë·¢ËͶñÒâÎĵµ£¬£¬£¬£¬ £¬£¬´Ó¶ø°²ÅŶñÒâ¼ÓÔØ³ÌÐò£¬£¬£¬£¬ £¬£¬¸Ã¼ÓÔØ³ÌÐò»á°´ÆÚÓëÔ¶³ÌC2ÁªÏµÒÔÏÂÔØÆäËûÑù±¾¡£¡£¡£¡£Æ¾Ö¤Ö®Ç°µÄÑо¿£¬£¬£¬£¬ £¬£¬GamaredonµÄ¹¤¾ß°ü°üÀ¨Ðí¶à²î±ðµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬ £¬£¬ÓÃÓÚʵÏÖ²î±ðµÄÄ¿µÄ¡£¡£¡£¡£ÆäÖаüÀ¨É¨ÃèÇý¶¯Æ÷ÖеÄÌØ¶¨ÏµÍ³Îļþ£¬£¬£¬£¬ £¬£¬²¶»ñÆÁÄ»¿ìÕÕ£¬£¬£¬£¬ £¬£¬Ö´ÐÐÔ¶³ÌÏÂÁ£¬£¬£¬ £¬£¬ÏÂÔØÆäËûÎļþÒÔ¼°Ê¹ÓÃUltraVNCµÈ³ÌÐòÖÎÀíÔ¶³ÌÅÌËã»ú¡£¡£¡£¡£ÔÚÕâÖÖÇéÐÎÏ£¬£¬£¬£¬ £¬£¬ÎÒÃÇÊӲ쵽һ¸öÓÐȤµÄеĵڶþ½×¶Îpayload£¬£¬£¬£¬ £¬£¬Æä¾ßÓÐÈö²¥¹¦Ð§£¬£¬£¬£¬ £¬£¬ÎÒÃdzÆÖ®Îª¡°Aversome infector¡±¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¿ÉÔÚÄ¿µÄÍøÂçÖмá³Ö³¤ÆÚÐÔ£¬£¬£¬£¬ £¬£¬²¢Í¨¹ýºáÏòÒÆ¶¯Ñ¬È¾ÍⲿÇý¶¯Æ÷ÉϵÄMicrosoft WordºÍExcelÎĵµ¡£¡£¡£¡£


0x03 ÖÐÎÄÏà¹ØµÄ APT ×éÖ¯»î¶¯


CactusPeteÊÇÒ»¸öÓëÖÐÎÄÏà¹ØµÄÍøÂçÌØ¹¤×éÖ¯£¬£¬£¬£¬ £¬£¬ÖÁÉÙ´Ó2012Äê×îÏÈ»îÔ¾£¬£¬£¬£¬ £¬£¬ÆäÌØÕ÷ÊǾßÓÐÖеÈˮƽµÄÊÖÒÕÄÜÁ¦¡£¡£¡£¡£´ÓÀúÊ·ÉÏ¿´£¬£¬£¬£¬ £¬£¬¹¥»÷Ä¿µÄÖ÷ÒªÕë¶Ôº«¹ú£¬£¬£¬£¬ £¬£¬ÈÕ±¾£¬£¬£¬£¬ £¬£¬ÃÀ¹úºÍÖйų́ÍåµÈÉÙÊý¹ú¼Ò/µØÇøµÄ×éÖ¯¡£¡£¡£¡£ÔÚ2019Äêµ×£¬£¬£¬£¬ £¬£¬¸Ã×éÖ¯ËÆºõתÏò¹Ø×¢ÃɹźͶíÂÞ˹£¬£¬£¬£¬ £¬£¬²¢Ê¹ÓÃÃɹÅÓï±àдÁËÒ»¸öÓÕ¶ü¹¥»÷Îĵµ¿ÉÊÍ·ÅFlapjackºóÃÅ£¨tmplogon.exe£¬£¬£¬£¬ £¬£¬Ö÷ÒªÕë¶ÔеĶíÂÞ˹ĿµÄ£©¡£¡£¡£¡£¿ £¿£¿£¿£¿£¿É¼û¸Ã×éÖ¯ÍØÕ¹ÁËÊÖÒÕ¹æÄ££¬£¬£¬£¬ £¬£¬²¢ÇÒʹÓõÄ×ÊÔ´ºÍÒªÁìÒ²±¬·¢ÁËת±ä¡£¡£¡£¡£


×Ô2018ÄêÒÔÀ´£¬£¬£¬£¬ £¬£¬RancorÊÇÒ»¸öÒѾ­¹ûÕæ±¨µÀµÄ×éÖ¯£¬£¬£¬£¬ £¬£¬ÓëDragonOKÓйØÁª¡£¡£¡£¡£¹¥»÷Ä¿µÄרעÓÚ¶«ÄÏÑÇ£¬£¬£¬£¬ £¬£¬¼´¼íÆÒÕ¯£¬£¬£¬£¬ £¬£¬Ô½ÄϺÍÐÂ¼ÓÆÂ¡£¡£¡£¡£ÎÒÃÇ×¢ÖØµ½¸Ã×éÖ¯ÔÚÒÑÍù¼¸¸öÔÂÖеĻÓм¸´¦¸üУ¬£¬£¬£¬ £¬£¬·¢Ã÷ÁËDudell¶ñÒâÈí¼þµÄбäÖÖExDudell£¬£¬£¬£¬ £¬£¬ExDudell¿ÉÒÔÈÆ¹ýUAC£¨Óû§ÕÊ»§¿ØÖÆ£©²¢ÇÒÓÃÓÚ¹¥»÷µÄеĻù´¡¼Ü¹¹¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬ £¬£¬ÎÒÃÇ»¹È·¶¨ÁËÒÔǰͨ¹ýÓʼþ·¢Ë͵ijõʼÓÕ¶üÎĵµÏÖÔÚ¿ÉÔÚTelegram DesktopĿ¼ÖÐÕÒµ½£¬£¬£¬£¬ £¬£¬ÕâÅú×¢¸Ã×éÖ¯¿ÉÄÜÕýÔڸıäÆä³õʼͶµÝ·½·¨¡£¡£¡£¡£


ÔÚ2019Ä꣬£¬£¬£¬ £¬£¬ÎÒÃǼì²âµ½Ò»¸öδ֪×éÖ¯µÄ»î¶¯£¬£¬£¬£¬ £¬£¬ÆäʱÊÇÔÚ´ú±í²Ø×åÀûÒæµÄÍøÕ¾ÉϵÄË®¿Ó¹¥»÷»î¶¯£¬£¬£¬£¬ £¬£¬ÓÕÆ­Êܺ¦Õß×°ÖÃÔÚGitHub´æ´¢¿âÉÏÍйܵļÙAdobe Flash¸üС£¡£¡£¡£¿ £¿£¿£¿£¿£¿¨°Í˹»ùͨ¹ýÓëGitHubÏàÖúÀ´·ÀÓù¹¥»÷¡£¡£¡£¡£Ã»¹ý¶à¾Ã£¬£¬£¬£¬ £¬£¬ÎÒÃÇÓÖ¼ì²âµ½ÐÂÒ»ÂÖË®¿Ó¹¥»÷¡£¡£¡£¡£ÎÒÃǾöÒ齫´Ë»î¶¯µÄ×éÖ¯ÃüÃûΪ¡°Holy Water¡±¡£¡£¡£¡£


×Ô½¨ÉèÖ®ÈÕÆð£¬£¬£¬£¬ £¬£¬¹¥»÷Õß¼òÆÓ¶ø¸»Óд´ÒâµÄ¹¤¾ß¾ÍÔÚÒ»Ö±¿ª·¢ºÍ¸üÐÂÖУ¬£¬£¬£¬ £¬£¬²¢Ê¹ÓÃÁËSojson»ìÏý£¬£¬£¬£¬ £¬£¬NSIS×°ÖóÌÐò£¬£¬£¬£¬ £¬£¬Python£¬£¬£¬£¬ £¬£¬¿ªÔ´´úÂ룬£¬£¬£¬ £¬£¬GitHub¿¯Ðаæ£¬£¬£¬£¬ £¬£¬GoÓïÑÔÒÔ¼°Google DriveµÈÊÖÒÕÊֶΡ£¡£¡£¡£


0x04 Öж«µØÇøµÄ APT »î¶¯


ÎÒÃÇ×î½üÔÚ2020Äê2Ô¼ì²âµ½ÁËStrongPity×éÖ¯Õë¶ÔÍÁ¶úÆäµÄÊý¾Ýй¶»î¶¯¡£¡£¡£¡£Ö»¹ÜStrongPityµÄTTPÔÚÄ¿µÄ£¬£¬£¬£¬ £¬£¬»ù´¡ÉèÊ©ºÍѬȾǰÑÔ·½ÃæÃ»Óиı䣬£¬£¬£¬ £¬£¬µ«ÎÒÃÇÊӲ쵽ËûÃÇÊÔͼй¶µÄÎļþÓÐËù²î±ð¡£¡£¡£¡£Ôڴ˻ÖУ¬£¬£¬£¬ £¬£¬StrongPity¸üÐÂÁË×îеÄÊðÃûºóÃÅ£¬£¬£¬£¬ £¬£¬ÃûΪStrongPity2£¬£¬£¬£¬ £¬£¬²¢Ìí¼ÓÁ˸ü¶àÎļþÒÔÖ²ÈëÆä³£¼ûµÄOfficeºÍPDFÎĵµÁбí£¬£¬£¬£¬ £¬£¬°üÀ¨ÓÃÓÚÏ£²®À´ÕÚÑÚµÄDagesh Pro×Ö´¦Öóͷ£Æ÷Îļþ£¬£¬£¬£¬ £¬£¬ÓÃÓÚºÓÁ÷Á÷Á¿ºÍÇÅÁº½¨Ä£µÄRiverCADÎļþ£¬£¬£¬£¬ £¬£¬´¿Îı¾Îļþ£¬£¬£¬£¬ £¬£¬¹éµµÎļþÒÔ¼°GPG¼ÓÃÜÎļþºÍPGPÃÜÔ¿¡£¡£¡£¡£


3Ô£¬£¬£¬£¬ £¬£¬ÎÒÃÇ·¢Ã÷ÁËWildPressure×éÖ¯Õë¶Ô¹¤ÒµÁìÓò·Ö·¢MilumľÂíµÄ»î¶¯£¬£¬£¬£¬ £¬£¬Ö¼ÔÚ¶ÔÄ¿µÄ×éÖ¯ÖеÄ×°±¸¾ÙÐÐÔ¶³Ì¿ØÖÆ¡£¡£¡£¡£¸Ã»î¶¯×î³õ¿ÉÒÔ×·Ëݵ½2019Äê8Ô¡£¡£¡£¡£µ½ÏÖÔÚΪֹ£¬£¬£¬£¬ £¬£¬ÎÒÃÇ¿´µ½µÄMilumʾÀýÓëÈκÎÒÑÖªµÄAPT»î¶¯Ã»ÓÐÈκδúÂëÏàËÆÐÔ¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þʹ¹¥»÷Õß¿ÉÒÔÔ¶³Ì¿ØÖÆÊÜѬȾµÄ×°±¸£¬£¬£¬£¬ £¬£¬ÔÊÐíÏÂÔØºÍÖ´ÐÐÏÂÁ£¬£¬£¬ £¬£¬ÍøÂçºÍй¶ÐÅÏ¢ÒÔ¼°ÔÚ¶ñÒâÈí¼þÖÐ×°ÖÃÉý¼¶³ÌÐò¡£¡£¡£¡£


ÔÚ2019Äê12ÔÂÏÂÑ®£¬£¬£¬£¬ £¬£¬¿¨°Í˹»ùThreat Attribution Engine¼ì²âµ½ZerocleareµÄбäÌåDustman£¬£¬£¬£¬ £¬£¬±»ÓÃÓÚÕë¶ÔÉ³ÌØ°¢À­²®ÄÜÔ´²¿·ÖµÄ¹¥»÷¡£¡£¡£¡£ÔÚ²Á³ýºÍ·Ö·¢·½Ã棬£¬£¬£¬ £¬£¬ËüÓëZerocleareÏàËÆ£¬£¬£¬£¬ £¬£¬¿ÉÊDZäÁ¿ºÍÊÖÒÕÃû³ÆµÄת±äÅú×¢£¬£¬£¬£¬ £¬£¬Õâ¿ÉÄÜÒѾ­×¼±¸ºÃÓ­½ÓÕë¶Ô¶ñÒâÈí¼þµÄÐÂÒ»²¨¹¥»÷£¬£¬£¬£¬ £¬£¬ÕâЩ¹¥»÷»ùÓÚǶÈëÔÚ¶ñÒâÈí¼þÖеÄÐÂÎźͽ¨ÉèµÄ»¥³âÌ壬£¬£¬£¬ £¬£¬×¨ÃÅÕë¶ÔÉ³ÌØ°¢À­²®µÄÄÜÔ´²¿·Ö¡£¡£¡£¡£Í¨¹ýËü¡£¡£¡£¡£ÓйØDustmanµÄPDBÎļþÅú×¢£¬£¬£¬£¬ £¬£¬¸ÃÆÆËðÐÔ´úÂëÊÇ¿¯Ðаæ£¬£¬£¬£¬ £¬£¬¿ÉÒÔÔÚÄ¿µÄÍøÂçÖа²ÅÅ¡£¡£¡£¡£ÕâЩת±äÇ¡·êÐÂÄê¼ÙÆÚ£¬£¬£¬£¬ £¬£¬ÔÚ´Ëʱ´úÐí¶àÔ±¹¤ÕýÔÚÐݼÙ¡£¡£¡£¡£


0x05 ¶«ÄÏÑǺͳ¯Ïʰ뵺µÄAPT»î¶¯


Òâ´óÀûÇå¾²¹«Ë¾TelsyÔÚ2019Äê11Ô¸ÅÊöÁËLazarus×éÖ¯µÄ»î¶¯£¬£¬£¬£¬ £¬£¬Ê¹ÎÒÃÇÄܹ»½«Õë¶Ô¼ÓÃÜÇ®±ÒÓªÒµµÄÏÈǰ»î¶¯ÁªÏµÆðÀ´¡£¡£¡£¡£Telsy²©¿ÍÉÏÌáµ½µÄ¶ñÒâÈí¼þÊǵÚÒ»½×¶ÎÏÂÔØ³ÌÐò£¬£¬£¬£¬ £¬£¬×Ô2018ÄêÖÐÒÔÀ´Ò»Ö±±»ÊӲ쵽¡£¡£¡£¡£ÎÒÃÇ·¢Ã÷µÚ¶þ½×¶Î¶ñÒâÈí¼þÊÇManuscryptµÄ±äÌ壬£¬£¬£¬ £¬£¬ËüÊÇLazarusµÄ¶ÀÍÌÊôÐÔ£¬£¬£¬£¬ £¬£¬Æä°²ÅÅÁËÁ½ÖÖÀàÐ͵Äpayload¡£¡£¡£¡£µÚÒ»¸öÊÇ¿ÉʹÓõÄUltra VNC³ÌÐò£¬£¬£¬£¬ £¬£¬µÚ¶þ¸öÊǶ༶ºóÃųÌÐò¡£¡£¡£¡£ÕâÖÖÀàÐ͵Ķà½×¶ÎѬȾÀú³ÌÊÇLazarus×éÖ¯¶ñÒâÈí¼þµÄµä·¶ÌØÕ÷£¬£¬£¬£¬ £¬£¬ÓÈÆäÊÇʹÓÃManuscrypt±äÌå¡£¡£¡£¡£Ôڴ˻ÖУ¬£¬£¬£¬ £¬£¬Lazarus×éÖ¯¹¥»÷ÁËÈûÆÖ·˹£¬£¬£¬£¬ £¬£¬ÃÀ¹ú£¬£¬£¬£¬ £¬£¬Öйų́ÍåºÍÖйúÏã¸ÛµÄ¼ÓÃÜÇ®±ÒÓªÒµ£¬£¬£¬£¬ £¬£¬¸Ã»î¶¯Ò»Ö±Ò»Á¬µ½2020ÄêÍ·¡£¡£¡£¡£


×Ô2013ÄêÒÔÀ´ÎÒÃÇÒ»Ö±¸ú×ÙµÄ×éÖ¯KimsukyÔÚ2019ÄêÓÈÆä»îÔ¾¡£¡£¡£¡£12Ô£¬£¬£¬£¬ £¬£¬Î¢Èí×÷·ÏÁ˸Ã×é֯ʹÓõÄ50¸öÓò£¬£¬£¬£¬ £¬£¬²¢ÔÚ¸¥¼ªÄáÑÇÖÝ·¨Ôº¶Ô¹¥»÷ÕßÌáÆðÁËËßËÏ¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬ £¬£¬¸ÃС×é¼ÌÐø¿ªÕ¹»î¶¯£¬£¬£¬£¬ £¬£¬Ã»Óб¬·¢ÖØ´óת±ä¡£¡£¡£¡£ÎÒÃÇ×î½ü·¢Ã÷ÁËÒ»¸öеĻ£¬£¬£¬£¬ £¬£¬ÆäÖÐʹÓÃÁËÒÔÐÂÄêÎʺòΪÖ÷ÌâµÄÓÕ¶üͼƬ£¬£¬£¬£¬ £¬£¬¸ÃͼƬΪ¾ÉÏÂÔØ¹¤¾ßÌṩÁËеľ­ÓÉˢеÄÏÂÒ»½×¶Îpayload£¬£¬£¬£¬ £¬£¬Ö¼ÔÚʹÓÃеļÓÃÜÒªÁìÀ´ÇÔÊØÐÅÏ¢¡£¡£¡£¡£


1ÔÂ⣬£¬£¬£¬ £¬£¬ÎÒÃÇ·¢Ã÷ÁËʹÓÃInternet ExplorerÎó²î£¨CVE-2019-1367£©µÄ¶ñÒâ¾ç±¾¡£¡£¡£¡£ÔÚ×Ðϸ¼ì²épayload²¢·¢Ã÷ÓëÏÈǰ»î¶¯µÄÁªÏµÖ®ºó£¬£¬£¬£¬ £¬£¬ÎÒÃǵóö½áÂÛ£¬£¬£¬£¬ £¬£¬DarkHotelÖ§³Ö´Ë»î¶¯£¬£¬£¬£¬ £¬£¬¸Ã»î¶¯¿ÉÄÜ×Ô2018ÄêÒÔÀ´Ò»Ö±ÔÚ¾ÙÐС£¡£¡£¡£¸Ã»î¶¯¿´µ½DarkHotelʹÓÿª·¢µÄÈí¼þʵÏÖÁ˶à½×¶Î¶þ½øÖÆÑ¬È¾¡£¡£¡£¡£×î³õµÄѬȾ»á½¨ÉèÒ»¸öÏÂÔØ³ÌÐò£¬£¬£¬£¬ £¬£¬¸ÃÏÂÔØ³ÌÐò½«»ñÈ¡ÁíÒ»¸öÏÂÔØ³ÌÐòÒÔÍøÂçϵͳÐÅÏ¢£¬£¬£¬£¬ £¬£¬²¢½öΪ¸ß¼ÛÖµÊܺ¦Õß»ñÈ¡×îÖյĺóÃųÌÐò¡£¡£¡£¡£DarkHotelÔڴ˻ÖÐʹÓÃÁËTTPµÄÆæÒì×éºÏ¡£¡£¡£¡£ÍþвÕßʹÓÃÖÖÖÖ»ù´¡½á¹¹À´ÍйܶñÒâÈí¼þ²¢¿ØÖÆÊÜѬȾµÄÊܺ¦Õߣ¬£¬£¬£¬ £¬£¬°üÀ¨ÊÜѬȾµÄWebЧÀÍÆ÷£¬£¬£¬£¬ £¬£¬ÉÌÒµÍйÜЧÀÍ£¬£¬£¬£¬ £¬£¬Ãâ·ÑÍйÜЧÀͺÍÃâ·ÑÔ´´úÂë¸ú×Ùϵͳ¡£¡£¡£¡£


3Ô£¬£¬£¬£¬ £¬£¬À´×ÔGoogleµÄÑо¿Ö°Ô±Í¸Â¶£¬£¬£¬£¬ £¬£¬Ò»×éºÚ¿ÍÔÚ2019ÄêʹÓÃÁËÎå¸ö0day¹¥»÷Ä¿µÄÕë¶Ô³¯ÏÊÈ˺ÍÒÔ³¯ÏÊÈËΪÖÐÐĵÄרҵְԱ¡£¡£¡£¡£¸ÃС×éʹÓÃInternet Explorer£¬£¬£¬£¬ £¬£¬ChromeºÍWindowsÖеÄÎó²îÀ´¾ÙÐÐÍøÂç´¹Âںͷַ¢µç×ÓÓʼþ£¬£¬£¬£¬ £¬£¬ÕâЩµç×ÓÓʼþÖаüÀ¨¶ñÒ⸽¼þ»òÓë¶ñÒâÁ´½ÓÒÔ¼°Ë®¿Ó¹¥»÷¡£¡£¡£¡£ÎÒÃÇÄܹ»½«ÆäÖеÄÁ½¸öÎó²î»®·ÖΪIEÖеÄÒ»¸öÎó²îºÍWindowsÖеÄÒ»¸öÎó²îÓëDarkHotel×é֯ƥÅäÉÏ¡£¡£¡£¡£


FunnyDream×éÖ¯»î¶¯Ê¼ÓÚ2018ÄêÖУ¬£¬£¬£¬ £¬£¬Õë¶ÔÂíÀ´Î÷ÑÇ£¬£¬£¬£¬ £¬£¬Öйų́ÍåºÍ·ÆÂɱöµÄ×ÅÃû×éÖ¯£¬£¬£¬£¬ £¬£¬ÆäÖдó´ó¶¼Êܺ¦ÕßÀ´×ÔÔ½ÄÏ¡£¡£¡£¡£ÆÊÎöÅú×¢£¬£¬£¬£¬ £¬£¬ÕâÖ»ÊÇÒ»Ïî¸üÆÕ±é¹¥»÷»î¶¯µÄÒ»²¿·Ö£¬£¬£¬£¬ £¬£¬¸Ã»î¶¯¿ÉÒÔ×·Ëݵ½¼¸Äêǰ£¬£¬£¬£¬ £¬£¬²¢Õë¶Ô¶«ÄÏÑǹú¼ÒµÄÕþ¸®ÌØÊâÊÇÍâ¹ú×éÖ¯¡£¡£¡£¡£¹¥»÷ÕߵĺóÃÅ´ÓC2ÏÂÔØÎļþºÍÏòC2ÉÏ´«Îļþ£¬£¬£¬£¬ £¬£¬Ö´ÐÐÏÂÁî²¢ÔÚÊܺ¦ÕßϵͳÖÐÔËÐÐÐÂÀú³Ì¡£¡£¡£¡£Ëü»¹ÍøÂçÓйØÍøÂçÉÏÆäËûÖ÷»úµÄÐÅÏ¢£¬£¬£¬£¬ £¬£¬²¢Í¨¹ýÔ¶³ÌÖ´ÐÐÓ¦ÓóÌÐò½«Æäת´ï¸øÐÂÖ÷»ú¡£¡£¡£¡£¹¥»÷Õß»¹Ê¹ÓÃÁËRTLºóÃźÍChinoxyºóÃÅ¡£¡£¡£¡£×Ô2018ÄêÄêÖÐÒÔÀ´£¬£¬£¬£¬ £¬£¬C2»ù´¡Éèʩһֱ´¦ÓÚ»îԾ״̬£¬£¬£¬£¬ £¬£¬²¢ÇÒdomainsÓëFFRAT¶ñÒâÈí¼þ¼Ò×åÖØµþ¡£¡£¡£¡£


Operation AppleJeusÊÇLazarus×îÓÐÓ°ÏìÁ¦µÄ»î¶¯Ö®Ò»£¬£¬£¬£¬ £¬£¬Ö÷ҪʹÓÃMacOS¶ñÒâÈí¼þ¾ÙÐй¥»÷¡£¡£¡£¡£1Ô·ݵĺóÐøÑо¿Õ¹ÏÖÁ˸Ã×éÖ¯¹¥»÷ÒªÁìµÄÖØ´óת±ä£ºÐ¿ª·¢µÄmacOS¶ñÒâÈí¼þºÍÒ»ÖÖÉí·ÝÑéÖ¤»úÖÆ£¬£¬£¬£¬ £¬£¬¿ÉÒÔÉóÉ÷µØ½»¸¶ÏÂÒ»½×¶ÎµÄpayload£¬£¬£¬£¬ £¬£¬ÒÔ¼°ÔÚ²»½Ó´¥´ÅÅ̵ÄÇéÐÎϼÓÔØÏÂÒ»½×¶ÎµÄpayload¡£¡£¡£¡£ÎªÁ˹¥»÷WindowsÊܺ¦Õߣ¬£¬£¬£¬ £¬£¬¸Ã×éÖ¯ÖÆ¶©ÁËÒ»¸ö¶à½×¶ÎѬȾ³ÌÐò²¢¸ü¸ÄÁË×îÖÕpayload¡£¡£¡£¡£ÎÒÃÇÒÔΪ£¬£¬£¬£¬ £¬£¬×Ô´ÓAppleJeus»î¶¯ÒÔÀ´£¬£¬£¬£¬ £¬£¬LazarusÔÚ¹¥»÷·½ÃæÔ½·¢ÉóÉ÷£¬£¬£¬£¬ £¬£¬²¢½ÓÄÉÁ˶àÖÖÒªÁìÀ´×èÖ¹±»·¢Ã÷¡£¡£¡£¡£ÎÒÃÇÔÚÓ¢¹ú£¬£¬£¬£¬ £¬£¬²¨À¼£¬£¬£¬£¬ £¬£¬¶íÂÞ˹ºÍÖйúÈ·¶¨Á˼¸ÃûÊܺ¦Õß¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬ÎÒÃÇÄܹ»È·ÈÏһЩÊܺ¦ÕßÓë¼ÓÃÜÇ®±Ò×éÖ¯ÓйØ¡£¡£¡£¡£


Roaming MantisÊÇÒ»¸ö³öÓÚ¾­¼ÃÄîÍ·µÄAPT×éÖ¯£¬£¬£¬£¬ £¬£¬ÓÚ2017ÄêÊ״ᨵÀ£¬£¬£¬£¬ £¬£¬Æäʱ¸Ã¹«Ë¾Ê¹ÓÃSMS½«Æä¶ñÒâÈí¼þ·Ö·¢¸øÎ»ÓÚº«¹úµÄAndroid×°±¸¡£¡£¡£¡£ØÊºó¸Ã×éÖ¯µÄ»î¶¯¹æÄ£À©´ó£¬£¬£¬£¬ £¬£¬Ö§³Ö27ÖÖÓïÑÔ£¬£¬£¬£¬ £¬£¬ÒÔiOSºÍAndroidΪĿµÄ£¬£¬£¬£¬ £¬£¬ÉõÖÁÍÚ¾ò¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¸Ã×éÖ¯»¹Ê¹ÓÃÁËеĶñÒâÈí¼þ¼Ò×壬£¬£¬£¬ £¬£¬°üÀ¨FakecopºÍWroba.j£¬£¬£¬£¬ £¬£¬²¢ÇÒÈÔÔÚʹÓá°SMiShing¡±¾ÙÐÐAndroid¶ñÒâÈí¼þ·Ö·¢¡£¡£¡£¡£ÔÚ×î½üµÄÒ»Ïî»î¶¯ÖУ¬£¬£¬£¬ £¬£¬Ëü·Ö·¢ÁËαװ³ÉÊܽӴýµÄ¿ìµÝ¹«Ë¾µÄ¶ñÒâAPK£¬£¬£¬£¬ £¬£¬Ö÷ÒªÕë¶ÔÈÕ±¾£¬£¬£¬£¬ £¬£¬Öйų́Í壬£¬£¬£¬ £¬£¬º«¹úºÍ¶íÂÞ˹¡£¡£¡£¡£


0x06 ÆäËü


TransparentTribeÓÚ2019ÄêÍ·×îÏÈʹÓÃÃûΪUSBWormµÄÐÂÄ£¿ £¿£¿£¿£¿£¿é£¬£¬£¬£¬ £¬£¬²¢¶ÔÆäÃûΪCrimsonRATµÄ×Ô½ç˵.NET¹¤¾ß¾ÙÐÐÁËˢС£¡£¡£¡£Æ¾Ö¤ÈËÉú¾ÍÊDz©Ò£²â·¢Ã÷£¬£¬£¬£¬ £¬£¬USBWorm±»ÓÃÀ´Ñ¬È¾³ÉǧÉÏÍòµÄÊܺ¦Õߣ¬£¬£¬£¬ £¬£¬ÆäÖдó´ó¶¼Î»ÓÚ°¢¸»º¹ºÍÓ¡¶È£¬£¬£¬£¬ £¬£¬Ê¹¹¥»÷ÕßÄܹ»ÏÂÔØºÍÖ´ÐÐí§ÒâÎļþ£¬£¬£¬£¬ £¬£¬Èö²¥µ½¿ÉÒÆ¶¯×°±¸²¢´ÓÊÜѬȾµÄÖ÷»úÇÔÈ¡¸ÐÐËȤµÄÎļþ¡£¡£¡£¡£ÕýÈçÎÒÃÇ֮ǰ±¨µÀµÄÄÇÑù£¬£¬£¬£¬ £¬£¬¸ÃС×éÖ÷Òª¹Ø×¢¾üÊÂÄ¿µÄ£¬£¬£¬£¬ £¬£¬ÕâЩĿµÄͨ³£Êܵ½OfficeÎĵµÖжñÒâVBAºÍPeppy RAT¡¢CrimsonRATµÈ¿ªÔ´¶ñÒâÈí¼þµÄ¹¥»÷¡£¡£¡£¡£×î½üµÄлÖУ¬£¬£¬£¬ £¬£¬ÎÒÃÇ×¢ÖØµ½¸ÃС×éµÄÖØµã¸ü¶àµØ×ªÏòÁËÕë¶ÔÓ¡¶ÈÒÔÍâµÄ°¢¸»º¹¡£¡£¡£¡£


ÔÚ2019ÄêµÄ×îºó¼¸¸öÔÂÖУ¬£¬£¬£¬ £¬£¬ÎÒÃÇÊӲ쵽ÁËFishing ElephantÕýÔÚ¾ÙÐеÄÒ»Ïî»î¶¯¡£¡£¡£¡£¸ÃС×é¼ÌÐøÊ¹ÓÃHerokuºÍDropboxÀ´½»¸¶ÆäÑ¡ÔñµÄ¹¤¾ßAresRAT¡£¡£¡£¡£ÎÒÃÇ·¢Ã÷£¬£¬£¬£¬ £¬£¬¼ÓÈëÕßÔÚÆä²Ù×÷ÖнÓÄÉÁËÒ»ÏîÐÂÊÖÒÕ£¬£¬£¬£¬ £¬£¬¸ÃÊÖÒÕÖ¼ÔÚ×èÖ¹ÊÖ¶¯ºÍ×Ô¶¯ÆÊÎögeo-fencingºÍ½«¿ÉÖ´ÐÐÎļþÒþ²ØÔÚÖ¤ÊéÎļþÖС£¡£¡£¡£ÔÚÈËÉú¾ÍÊDz©Ñо¿Àú³ÌÖУ¬£¬£¬£¬ £¬£¬ÎÒÃÇ»¹·¢Ã÷Êܺ¦ÕßµÄת±ä¿ÉÄÜ·´Ó¦Á˹¥»÷ÕßµÄÄ¿½ñÀûÒæ£¬£¬£¬£¬ £¬£¬¸Ã×éÖ¯µÄÄ¿µÄÊÇÍÁ¶úÆä£¬£¬£¬£¬ £¬£¬°Í»ù˹̹£¬£¬£¬£¬ £¬£¬ÃϼÓÀ­¹ú£¬£¬£¬£¬ £¬£¬ÎÚ¿ËÀ¼ºÍÖйúµÄÕþ¸®ºÍÍâ½»»ú¹¹¡£¡£¡£¡£


0x07 ½áÓï


Ö»¹ÜÍþвÐÎÊÆ²¢²»×ÜÊdzäÂú¡°Í»ÆÆÐÔ¡±ÊÂÎñ£¬£¬£¬£¬ £¬£¬µ«µ±ÎÒÃǽ«ÑÛ¹âͶÏòAPTÍþвÐÐΪÕߵĻʱ£¬£¬£¬£¬ £¬£¬×ÜÊÇ»áÓÐÓÐȤµÄÉú³¤¡£¡£¡£¡£ÈËÉú¾ÍÊDz©°´ÆÚ¼¾¶ÈÉó²éÖ¼ÔÚÇ¿µ÷Òªº¦µÄÉú³¤¡£¡£¡£¡£


ÕâЩÊǵ½ÏÖÔÚΪֹÎÒÃǽñÄêÒѾ­¿´µ½µÄһЩÖ÷ÒªÇ÷ÊÆ¡£¡£¡£¡£

¡ñ µØÔµÕþÖÎÈÔÈ»ÊÇAPT»î¶¯µÄÖ÷ÒªÖúÍÆÁ¦¡£¡£¡£¡£

¡ñ LazarusºÍRoaming MantisµÄ»î¶¯Ö¤Êµ£¬£¬£¬£¬ £¬£¬¾­¼ÃÀûÒæÈÔÈ»ÊÇijЩ¹¥»÷ÕßµÄÄîÍ·¡£¡£¡£¡£

¡ñ ¾ÍAPT»î¶¯¶øÑÔ£¬£¬£¬£¬ £¬£¬¶«ÄÏÑÇÊÇ×î»îÔ¾µÄµØÇø£¬£¬£¬£¬ £¬£¬°üÀ¨Lazarus£¬£¬£¬£¬ £¬£¬DarkHotelºÍKimsukyµÈ×éÖ¯£¬£¬£¬£¬ £¬£¬ÒÔ¼°Cloud SnooperºÍFishing ElephantµÈÐÂÐË×éÖ¯¡£¡£¡£¡£

¡ñ APT×éÖ¯£¬£¬£¬£¬ £¬£¬ÀýÈçCactusPete£¬£¬£¬£¬ £¬£¬TwoSail Junk£¬£¬£¬£¬ £¬£¬FunnyDreamºÍDarkHotel£¬£¬£¬£¬ £¬£¬¼ÌÐøÊ¹ÓÃÈí¼þÎó²î¡£¡£¡£¡£

¡ñ APT×éÖ¯¼ÌÐø½«mobile implantsÄÉÈëÆäÎäÆ÷¿â¡£¡£¡£¡£

¡ñ APT×éÖ¯£¨ÀýÈ絫²»ÏÞÓÚKimsuky£¬£¬£¬£¬ £¬£¬HadesºÍDarkHotel£©ÒÔʵʱ»úÖ÷Òå×ï·¸ÕýÔÚʹÓÃCOVID-19¡£¡£¡£¡£


×ܶøÑÔÖ®£¬£¬£¬£¬ £¬£¬ÎÒÃÇ¿´µ½ÁËÑÇÖÞ¹¥»÷»î¶¯µÄÒ»Á¬ÔöÌí£¬£¬£¬£¬ £¬£¬Ê¹ÓÃÒÆ¶¯Æ½Ì¨Ñ¬È¾ºÍÈö²¥¶ñÒâÈí¼þµÄÇ÷ÊÆÕýÔÚÉÏÉý¡£¡£¡£¡£


ÏÖÔÚ£¬£¬£¬£¬ £¬£¬COVID-19Êܵ½Ã¿Ð¡ÎÒ˽¼ÒµÄ¹Ø×¢£¬£¬£¬£¬ £¬£¬¶øAPT×éÖ¯Ò²Ò»Ö±ÔÚʵÑéÔÚÓã²æÊ½ÍøÂç´¹ÂڻÖÐʹÓÃÕâÒ»Ö÷Ìâ¡£¡£¡£¡£ÎÒÃÇÒÔΪÕâ²¢²»´ú±íTTP±¬·¢ÁËÓÐÒâÒåµÄת±ä£ºËûÃÇÖ»Êǽ«ÆäÓÃ×÷¾ßÓÐÐÂÎżÛÖµµÄ»°ÌâÀ´ÎüÒýÊܺ¦Õß¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬ £¬£¬ÎÒÃÇÕýÔÚÇ×½ü¼àÊÓÊ±ÊÆ¡£¡£¡£¡£


0x08 ²Î¿¼Á´½Ó


https://securelist.com/apt-trends-report-q1-2020/96826/


0x09 ʱ¼äÏß


2020-05-01  VSRCÐû²¼±¨¸æ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø