Ñо¿ÍŶӹûÕæNSA Equation GroupµÄºóÃÅBvp47µÄϸ½Ú

Ðû²¼Ê±¼ä 2022-02-28

Ñо¿ÍŶӹûÕæNSA Equation GroupµÄºóÃÅBvp47µÄϸ½Ú


¾ÝýÌå2ÔÂ23ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿ÍŶӹûÕæÁËLinuxºóÃÅBvp47µÄÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£¡£ ¡£¡£¸ÃºóÃÅÓÚ2013Äêµ×Ê״α»¼ì²âµ½£¬£¬£¬£¬£¬£¬£¬£¬ÓëNSA Equation GroupÓйØÁª£¬£¬£¬£¬£¬£¬£¬£¬Òò¶à´ÎʹÓÃ×Ö·û´®¡°Bvp¡±ºÍ¼ÓÃÜËã·¨ÖеÄÊýÖµ¡°0x47¡±¶ø±»³ÆÎª¡°Bvp47¡±¡£¡£¡£¡£¡£¡£ ¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬£¬Bvp47Òѱ»ÓÃÓÚ¹¥»÷Öйú¡¢º«¹ú¡¢ÈÕ±¾¡¢µÂ¹ú¡¢Î÷°àÑÀ¡¢Ó¡¶ÈºÍÄ«Î÷¸çµÈ45¸ö¹ú¼ÒµÄѧÊõ¡¢¾­¼Ã¡¢¾üÊ¡¢¿ÆÑ§ºÍµçÐŵÈÐÐÒµµÄ287¸öÄ¿µÄ¡£¡£¡£¡£¡£¡£ ¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Ëü»¹¾ßÓÐÖØ´óµÄ´úÂë¡¢·Ö¶Î¼Ó½âÃÜ¡¢Linux¶à°æ±¾Æ½Ì¨ÊÊÅä¡¢¸»ºñµÄrootkit·´¸ú×ÙÊÖÒÕ£¬£¬£¬£¬£¬£¬£¬£¬²¢¼¯³ÉÁׯ߼¶BPFÒýÇæÒÔ¼°·±ËöµÄͨѶ¼Ó½âÃÜÀú³Ì¡£¡£¡£¡£¡£¡£ ¡£¡£


https://securityaffairs.co/wordpress/128322/apt/equation-group-bvp47-backdoor.html


ESET·¢Ã÷еÄHermeticWiperÕë¶ÔÎÚ¿ËÀ¼µÄ¹¥»÷»î¶¯


ýÌå2ÔÂ23Èճƣ¬£¬£¬£¬£¬£¬£¬£¬Çå¾²¹«Ë¾ESET·¢Ã÷ÁËÕë¶ÔÎÚ¿ËÀ¼µÄÐÂÊý¾Ý²Á³ý¶ñÒâÈí¼þHermeticWiper£¨ÓÖÃûKillDisk.NCV£©¡£¡£¡£¡£¡£¡£ ¡£¡£¸ÃÑù±¾±àÒëÓÚ2021Äê12ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Ëæ×ŶíÂÞ˹µÄ¾üÊÂÐж¯¹¥»÷ÁËÎÚ¿ËÀ¼´ó×ÚIT»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£ ¡£¡£HermeticWiperÊÇʹÓýÒÏþ¸øHermetica Digital LtdµÄÖ¤Êé¾ÙÐÐÊðÃûµÄ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÈí¼þEaseUS Partition MasterÖеÄÕýµ±Çý¶¯³ÌÐòÀ´ÆÆËðÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬È»ºóÖØÐÂÆô¶¯ÅÌËã»ú¡£¡£¡£¡£¡£¡£ ¡£¡£


https://thehackernews.com/2022/02/new-wiper-malware-targeting-ukraine.html


Ó¢ÃÀÕþ¸®³ÆCyclops BlinkÓëAPT×éÖ¯SandwormÓйØ


2ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÃÀÓ¢»ú¹¹NCSC¡¢FBI¡¢CISAºÍNSAÁªºÏÐû²¼ÁËÒ»·ÝÇå¾²×Éѯ£¬£¬£¬£¬£¬£¬£¬£¬³ÆÐ¶ñÒâÈí¼þCyclops BlinkÓë¶íÂÞ˹SandwormÓйء£¡£¡£¡£¡£¡£ ¡£¡£¸ÃAPT×éÖ¯×Ô2000ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÓɶíÂÞ˹GRUÌØÊâÊÖÒÕÖÐÐÄ(GTsST)µÄ74455²½¶ÓÔËÓª¡£¡£¡£¡£¡£¡£ ¡£¡£×ÉѯÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬Cyclops BlinkËÆºõÊÇ2018Äê·¢Ã÷µÄVPNFilterµÄÌæ»»Æ·£¬£¬£¬£¬£¬£¬£¬£¬×°ÖÃÔÚÔÊÐíSandwormÔ¶³Ì»á¼ûµÄÍøÂçÖУ¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ý¹Ì¼þ¸üÐÂÔÚÄ¿µÄ×°±¸Öмá³Ö³¤ÆÚÐÔ¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/us-uk-link-new-cyclops-blink-malware-to-russian-state-hackers/


Ñо¿Ö°Ô±³ÆÖÁÉÙÓÐ1ÒÚ²¿ÈýÐÇÊÖ»úµÄÃÜÂëÉè¼Æ±£´æÈ±ÏÝ


¾Ý2ÔÂ23ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬ÌØÀ­Î¬·ò´óѧµÄÑо¿Ö°Ô±·¢Ã÷ÁËÈýÐÇÊÖ»úµÄÃÜÂëÉè¼Æ±£´æÈ±ÏÝ¡£¡£¡£¡£¡£¡£ ¡£¡£¸ÃȱÏݱ£´æÓÚ´ÓGalaxy S8µ½Galaxy S21µÄÖÖÖÖÐͺÅÖУ¬£¬£¬£¬£¬£¬£¬£¬¾ÝÔ¤¼ÆÓ°ÏìÁË1ÒÚ²¿ÖÇÄÜÊÖ»ú¡£¡£¡£¡£¡£¡£ ¡£¡£¸ÃÎÊÌâÖ÷񻃾¼°µ½Ê¹ÓÃARMµÄTrustZoneÊÖÒÕµÄ×°±¸£¬£¬£¬£¬£¬£¬£¬£¬²»µ«¿ÉÒÔÓÃÀ´ÇÔÈ¡´æ´¢ÔÚÉè±¹ØÁ¬Ä¼ÓÃÜÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔÓÃÀ´ÈƹýFIDO2µÈÇå¾²±ê×¼¡£¡£¡£¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±Ô¤¼Æ»áÔÚ8Ô¾ÙÐеÄ2022ÄêUSENIXÇå¾²×êÑлáÉÏÏêϸÏÈÈÝÕâЩÎó²î¡£¡£¡£¡£¡£¡£ ¡£¡£


https://threatpost.com/samsung-shattered-encryption-on-100m-phones/178606/


DragosÐû²¼2021ÄêICSÍøÂçÇå¾²Ì¬ÊÆµÄ»ØÊ×±¨¸æ


¹¤ÒµÇå¾²¹«Ë¾ÔÚ2ÔÂ23ÈÕÐû²¼ÁË2021ÄêICSÍøÂçÇå¾²Ì¬ÊÆµÄ»ØÊ×±¨¸æ¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾Ö÷Òª¼à²âÁ˹¤ÒµÁìÓòµÄÍþв»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬·¢Ã÷ÀÕË÷ÍÅ»ï×î³£¼ûµÄÄ¿µÄÊÇÖÆÔìÒµ£¨¹²ÓÐ211´Î¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Õ¼±È65%£©£¬£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇʳÎïºÍÒûÁÏÐÐÒµ£¨35´Î£©ºÍ½»Í¨ÔËÊäÐÐÒµ£¨27´Î£©¡£¡£¡£¡£¡£¡£ ¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïLockBitºÍContiÊÇÈ¥Ä깤ҵÁìÓòµÄÍ·ºÅÍþв¡£¡£¡£¡£¡£¡£ ¡£¡£±¨¸æ»¹Õ¹ÏÖÁËÒ»¸öÁîÈ˵£ÐĵÄÕ÷Ï󣬣¬£¬£¬£¬£¬£¬£¬Ðí¶à×éÖ¯µÄ»ù´¡¼Ü¹¹µÄ¿É¼ûÐÔȱ·¦ £¬£¬£¬£¬£¬£¬£¬£¬Î´ÄÜ׼ȷ֧½âÍøÂç½çÏߣ¬£¬£¬£¬£¬£¬£¬£¬Ðí¶àÍⲿÅþÁ¬µÄ×°±¸£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ITºÍOTÇéÐÎÖ®¼äÓдó×Ú¹²ÏíÆ¾Ö¤¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.dragos.com/year-in-review/


Mandiant³ÆCubaʹÓÃExchangeÎó²îÃé×¼ÃÀ¹úºÍ¼ÓÄôó


MandiantÔÚ2ÔÂ23ÈÕµÄÒ»·Ý±¨¸æÖгÆCubaÕýÔÚÃé×¼ÃÀ¹úºÍ¼ÓÄô󡣡£¡£¡£¡£¡£ ¡£¡£¸ÃÍÅ»ï×·×ÙΪUNC2596£¬£¬£¬£¬£¬£¬£¬£¬ÆäʹÓõÄÀÕË÷Èí¼þÊÇCOLDDRAW£¨Í¨³£±»³ÆÎªCuba£©¡£¡£¡£¡£¡£¡£ ¡£¡£MandiantÈ·¶¨´Ë´Î¹¥»÷ʹÓÃÁËMicrosoft ExchangeÖеÄÎó²î£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨ProxyShellºÍProxyLogon£¬£¬£¬£¬£¬£¬£¬£¬Ö²ÈëµÄºóÃŰüÀ¨Cobalt Strike»òNetSupport Manager£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ËûÃÇ×Ô¼ºµÄBughatch¡¢Wedgecut¡¢eck.exeºÍBurntcigar¡£¡£¡£¡£¡£¡£ ¡£¡£Ô¼80%µÄÄ¿µÄ×é֯λÓÚ±±ÃÀ£¬£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊǼÓÄô󡣡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/microsoft-exchange-servers-hacked-to-deploy-cuba-ransomware/


Çå¾²¹¤¾ß


Cloudsploit


ÔÆÇ徲ɨÃ蹤¾ß¡£¡£¡£¡£¡£¡£ ¡£¡£


https://github.com/aquasecurity/cloudsploit


Dive


ÓÃÓÚ̽Ë÷ Docker Ó³Ïñ¡¢Í¼²ãÄÚÈݺͷ¢Ã÷ËõС Docker/OCI Ó³Ïñ¾ÞϸµÄÒªÁìµÄ¹¤¾ß¡£¡£¡£¡£¡£¡£ ¡£¡£


https://github.com/wagoodman/dive


TerraGoat


ÊÇ Bridgecrew µÄ¡°Éè¼ÆÎó²î¡±Terraform ´æ´¢¿â¡£¡£¡£¡£¡£¡£ ¡£¡£


https://github.com/bridgecrewio/terragoat


vortex


VPN ÕûÌåÕì̽¡¢²âÊÔ¡¢Ã¶¾ÙºÍʹÓù¤¾ß°ü¡£¡£¡£¡£¡£¡£ ¡£¡£


https://github.com/klezVirus/vortex


EDRSandblast


Óà C ÓïÑÔ±àдµÄ¹¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬¿É½«ÊðÃûÇý¶¯³ÌÐòÎäÆ÷»¯ÒÔÈÆ¹ýEDR ¼ì²âºÍ LSASS ±£»£»£» £»£»¤¡£¡£¡£¡£¡£¡£ ¡£¡£


https://github.com/wavestone-cdt/EDRSandblast


Çå¾²ÆÊÎö


ʹÓüòÀúºÍ°æÈ¨Ïà¹Øµç×ÓÓʼþ·Ö·¢ LockBit ÀÕË÷Èí¼þ


https://asec.ahnlab.com/en/32054/


¹È¸èÕýÔÚïÔÌ­ Android µÄ Chrome Lite ģʽ


https://news.softpedia.com/news/google-is-retiring-the-chrome-lite-mode-for-android-534933.shtml


Microsoft Defender for Cloud ¿ÉÒÔ±£»£»£» £»£»¤ Google Cloud 


https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-for-cloud-can-now-protect-google-cloud-resources/


NCSC ΪÐÞ½¨ÒµÐû²¼Ê׸öÍøÂçÇå¾²Ö¸ÄÏ


https://www.infosecurity-magazine.com/news/ncsc-guidance-construction/


ÀÕË÷Èí¼þ Entropy Óë¶ñÒâÈí¼þ Dridex ÓйØ


https://thehackernews.com/2022/02/dridex-malware-deploying-entropy.html


FTC£º2021 ÄêÃÀ¹úÒòڲƭËðʧÁè¼Ý 58 ÒÚÃÀÔª


https://www.bleepingcomputer.com/news/security/ftc-americans-report-losing-over-58-billion-to-fraud-in-2021/