¿¨°Í˹»ù | 2020ÄêQ1 APTÇ÷ÊÆ±¨¸æ

Ðû²¼Ê±¼ä 2020-05-01

¿¨°Í˹»ùÐû²¼2020ÄêµÚÒ»¼¾¶ÈµÄAPT×éÖ¯»î¶¯µÄÇ÷ÊÆ±¨¸æ £¬Ö÷Ҫ˵Ã÷ÖØ´óµÄAPT»î¶¯ÒÔ¼°Ñо¿·¢Ã÷¡£


0x00 COVID-19 APT»î¶¯


×ÔÌìÏÂÎÀÉú×éÖ¯£¨WHO£©Ðû²¼COVID-19³ÉΪÎÁÒßÒÔÀ´ £¬ÕâÒ»»°ÌâÒÑÊܵ½²î±ð¹¥»÷ÕßÔ½À´Ô½¶àµÄ¹Ø×¢¡£Ðí¶àÍøÂç´¹ÂÚÕ©Æ­¶¼ÊÇÓÉÍøÂç·¸·¨·Ö×ÓÌᳫµÄ £¬ËûÃÇÊÔͼʹÓÃÈËÃǶԲ¡¶¾µÄ¿Ö¾åÀ´×¬Ç®¡£¿ÉÊÇ £¬¹¥»÷ÕßÁбíÖл¹°üÀ¨APT×éÖ¯ £¬ÀýÈçKimsuky £¬APT27 £¬Lazarus»òViciousPanda £¬Æ¾Ö¤OSINT £¬ËûÃÇÒÔCOVID-19×÷ΪÓÕ¶üÃé×¼Êܺ¦Õß¡£ÎÒÃÇ×î½ü·¢Ã÷ÁË¿ÉÒɵĻù´¡ÉèÊ©¿ÉÓÃÓÚÕë¶Ô°üÀ¨WHOÔÚÄÚµÄÎÀÉúºÍÈËÐÔÖ÷Òå×éÖ¯¡£¾ÝһЩ˽ÈËÐÂÎÅȪԴ³Æ £¬Ö»¹Ü»ù´¡ÉèÊ©ÏÖÔÚÎÞ·¨¹éÒòÓÚÈκÎÌØ¶¨µÄ×éÖ¯ £¬²¢ÇÒÒÑÔÚ2019Äê6ÔÂCOVID-19Σ»ú֮ǰע²á £¬µ«Ëü¿ÉÄÜÓëDarkHotelÓйØ¡£¿ÉÊÇ £¬ÎÒÃÇÏÖÔÚÎÞ·¨È·ÈÏ´ËÐÅÏ¢¡£ÓÐȤµÄÊÇ £¬Ò»Ð©×é֯ʹÓÃÄ¿½ñÇéÐÎÀ´Ðû²¼ËûÃÇÔÚΣ»úʱ´ú²»»áÕë¶ÔÎÀÉú×éÖ¯¡£


0x01 ×îÖµµÃ×¢ÖØµÄÇ÷ÊÆ


2020Äê1Ô £¬ÎÒÃÇ·¢Ã÷Ò»¸öË®¿Ó¹¥»÷ʹÓÃÍêÈ«µÄÔ¶³ÌiOSÎó²î¡£Õâ¸öÍøÕ¾µÄÄ¿µÄÊÇÆ¾Ö¤Ä¿µÄÍøÒ³µÄÄÚÈÝÀ´¶¨Î»ÖйúÏã¸ÛµÄÓû§¡£ËäȻĿ½ñÕýÔÚʹÓõÄÎó²îʹÓóÌÐòÊÇÒÑÖªµÄ £¬µ«ÈÏÕæÖ°Ô±ÕýÔÚÆð¾¢ÐÞ¸ÄÎó²îʹÓù¤¾ß°ü £¬ÒÔÕë¶Ô¸ü¶àµÄiOS°æ±¾ºÍ×°±¸¡£ÎÒÃÇÔÚ2ÔÂ7ÈÕÊӲ쵽ÁË×îеİ汾¡£¸ÃÏîÄ¿±ÈÎÒÃÇ×î³õÏëÏóµÄÒªÆÕ±é £¬ËüÖ§³ÖAndroidÖ²Èë £¬²¢ÇÒ¿ÉÄÜÖ§³ÖWindows £¬LinuxºÍMacOSµÄÖ²Èë¡£ÏÖÔÚ £¬ÎÒÃǽ«´ËAPT×éÖ¯³ÆÎªTwoSail Junk¡£ÎÒÃÇÒÔΪÕâÊÇÒ»ÆäÖÐÎÄ×éÖ¯ £¬ËüÖ÷ÒªÔÚÖйúÏã¸Ûά»¤»ù´¡ÉèÊ© £¬²¢ÔÚÐÂ¼ÓÆÂºÍÉϺ£ÉèÓм¸¸öÖ÷»ú¡£TwoSail Junkͨ¹ýÔÚÂÛ̳Ðû²¼Á´½Ó»ò½¨Éè×Ô¼ºµÄÐÂÖ÷ÌâÀ´½«»á¼ûÕßÖ¸µ¼ÖÁÆäʹÓÃÕ¾µã¡£ÖÁ½ñ £¬¼Í¼ÁËÀ´×ÔÖйúÏã¸ÛµÄÊýÊ®´Î»á¼û £¬ÆäÖÐÒ»¶ÔÀ´×ÔÖйú°ÄÃÅ¡£


0x02 ¶íÓïÏà¹ØµÄAPT×éÖ¯»î¶¯


1Ô £¬ÔÚÒ»¼Ò¶«Å·µçÐŹ«Ë¾Öз¢Ã÷Á˼¸¸ö×î½ü±àÒëµÄSPLM/XAgentÄ£¿é¡£×î³õµÄ½øÈëµãÊÇδ֪µÄ £¬ËüÃÇÔÚ¸Ã×éÖ¯ÄڵĺáÏòÔ˶¯Ò²ÊÇδ֪µÄ¡£ÓëÒÑÍùµÄSofacy»î¶¯Ë®Æ½Ïà±È £¬ÏÕЩÎÞ·¨Ê¶±ðSPLMѬȾ £¬Òò´ËËÆºõ¸Ã¹«Ë¾ÄÚÍø¿ÉÄÜÒѾ­Ñ¬È¾ÁËÒ»¶Îʱ¼ä¡£³ýÁËÕâЩSPLMÄ£¿éÖ®Íâ £¬Sofacy»¹°²ÅÅÁË.NET XTUNNEL±äÌå¼°Æä¼ÓÔØ³ÌÐò¡£ÓëÒÑÍùµÄXTUNNELÑù±¾£¨ÖØÁ¿Îª1-2MB£©Ïà±È £¬ÕâЩ20KBµÄXTUNNELÑù±¾×Ô¼ºËƺõºÜÉÙ¡£long-standing Sofacy XTunnel´úÂë¿âÏòC££µÄת±äʹÎÒÃÇÏëÆðZebrocyÖØÐ±àÂëºÍʹÓöàÖÖÓïÑÔÀ´Á¢Òìºã¾ÃʹÓõÄÄ£¿éµÄ×ö·¨¡£


GamaredonÊÇÒ»¸ö×ÅÃûµÄAPT×éÖ¯ £¬ÖÁÉÙ´Ó2013Äê×îÏÈ»îÔ¾ £¬¹¥»÷Ä¿µÄÖ÷ÒªÕë¶ÔÎÚ¿ËÀ¼¡£½ü¼¸¸öÔÂÀ´ £¬ÎÒÃÇ·¢Ã÷ÁËÒ»¸ö¹¥»÷»î¶¯ £¬¹¥»÷Õßͨ¹ýÔ¶³ÌÄ£°å×¢Èë·¢ËͶñÒâÎĵµ £¬´Ó¶ø°²ÅŶñÒâ¼ÓÔØ³ÌÐò £¬¸Ã¼ÓÔØ³ÌÐò»á°´ÆÚÓëÔ¶³ÌC2ÁªÏµÒÔÏÂÔØÆäËûÑù±¾¡£Æ¾Ö¤Ö®Ç°µÄÑо¿ £¬GamaredonµÄ¹¤¾ß°ü°üÀ¨Ðí¶à²î±ðµÄ¶ñÒâÈí¼þ £¬ÓÃÓÚʵÏÖ²î±ðµÄÄ¿µÄ¡£ÆäÖаüÀ¨É¨ÃèÇý¶¯Æ÷ÖеÄÌØ¶¨ÏµÍ³Îļþ £¬²¶»ñÆÁÄ»¿ìÕÕ £¬Ö´ÐÐÔ¶³ÌÏÂÁî £¬ÏÂÔØÆäËûÎļþÒÔ¼°Ê¹ÓÃUltraVNCµÈ³ÌÐò¹ÜÀíÔ¶³ÌÅÌËã»ú¡£ÔÚÕâÖÖÇéÐÎÏ £¬ÎÒÃÇÊӲ쵽һ¸öÓÐȤµÄеĵڶþ½×¶Îpayload £¬Æä¾ßÓÐÈö²¥¹¦Ð§ £¬ÎÒÃdzÆÖ®Îª¡°Aversome infector¡±¡£¸Ã¶ñÒâÈí¼þ¿ÉÔÚÄ¿µÄÍøÂçÖмá³Ö³¤ÆÚÐÔ £¬²¢Í¨¹ýºáÏòÒÆ¶¯Ñ¬È¾ÍⲿÇý¶¯Æ÷ÉϵÄMicrosoft WordºÍExcelÎĵµ¡£


0x03 ÖÐÎÄÏà¹ØµÄ APT ×éÖ¯»î¶¯


CactusPeteÊÇÒ»¸öÓëÖÐÎÄÏà¹ØµÄÍøÂçÌØ¹¤×éÖ¯ £¬ÖÁÉÙ´Ó2012Äê×îÏÈ»îÔ¾ £¬ÆäÌØÕ÷ÊǾßÓÐÖеÈˮƽµÄÊÖÒÕÄÜÁ¦¡£´ÓÀúÊ·ÉÏ¿´ £¬¹¥»÷Ä¿µÄÖ÷ÒªÕë¶Ôº«¹ú £¬ÈÕ±¾ £¬ÃÀ¹úºÍÖйų́ÍåµÈÉÙÊý¹ú¼Ò/µØÇøµÄ×éÖ¯¡£ÔÚ2019Äêµ× £¬¸Ã×éÖ¯ËÆºõתÏò¹Ø×¢ÃɹźͶíÂÞ˹ £¬²¢Ê¹ÓÃÃɹÅÓï±àдÁËÒ»¸öÓÕ¶ü¹¥»÷Îĵµ¿ÉÊÍ·ÅFlapjackºóÃÅ£¨tmplogon.exe £¬Ö÷ÒªÕë¶ÔеĶíÂÞ˹ĿµÄ£©¡£¿É¼û¸Ã×éÖ¯ÍØÕ¹ÁËÊÖÒÕ¹æÄ£ £¬²¢ÇÒʹÓõÄ×ÊÔ´ºÍÒªÁìÒ²±¬·¢ÁËת±ä¡£


×Ô2018ÄêÒÔÀ´ £¬RancorÊÇÒ»¸öÒѾ­¹ûÕæ±¨µÀµÄ×éÖ¯ £¬ÓëDragonOKÓйØÁª¡£¹¥»÷Ä¿µÄרעÓÚ¶«ÄÏÑÇ £¬¼´¼íÆÒÕ¯ £¬Ô½ÄϺÍÐÂ¼ÓÆÂ¡£ÎÒÃÇ×¢ÖØµ½¸Ã×éÖ¯ÔÚÒÑÍù¼¸¸öÔÂÖеĻÓм¸´¦¸üР£¬·¢Ã÷ÁËDudell¶ñÒâÈí¼þµÄбäÖÖExDudell £¬ExDudell¿ÉÒÔÈÆ¹ýUAC£¨Óû§ÕÊ»§¿ØÖÆ£©²¢ÇÒÓÃÓÚ¹¥»÷µÄеĻù´¡¼Ü¹¹¡£³ý´ËÖ®Íâ £¬ÎÒÃÇ»¹È·¶¨ÁËÒÔǰͨ¹ýÓʼþ·¢Ë͵ijõʼÓÕ¶üÎĵµÏÖÔÚ¿ÉÔÚTelegram DesktopĿ¼ÖÐÕÒµ½ £¬ÕâÅú×¢¸Ã×éÖ¯¿ÉÄÜÕýÔڸıäÆä³õʼͶµÝ·½·¨¡£


ÔÚ2019Äê £¬ÎÒÃǼì²âµ½Ò»¸öδ֪×éÖ¯µÄ»î¶¯ £¬ÆäʱÊÇÔÚ´ú±í²Ø×åÀûÒæµÄÍøÕ¾ÉϵÄË®¿Ó¹¥»÷»î¶¯ £¬ÓÕÆ­Êܺ¦Õß×°ÖÃÔÚGitHub´æ´¢¿âÉÏÍйܵļÙAdobe Flash¸üС£¿¨°Í˹»ùͨ¹ýÓëGitHubºÏ×÷À´·ÀÓù¹¥»÷¡£Ã»¹ý¶à¾Ã £¬ÎÒÃÇÓÖ¼ì²âµ½ÐÂÒ»ÂÖË®¿Ó¹¥»÷¡£ÎÒÃǾöÒ齫´Ë»î¶¯µÄ×éÖ¯ÃüÃûΪ¡°Holy Water¡±¡£


×Ô½¨ÉèÖ®ÈÕÆð £¬¹¥»÷Õß¼òÆÓ¶ø¸»Óд´ÒâµÄ¹¤¾ß¾ÍÔÚÒ»Ö±¿ª·¢ºÍ¸üÐÂÖÐ £¬²¢Ê¹ÓÃÁËSojson»ìÏý £¬NSIS×°ÖóÌÐò £¬Python £¬¿ªÔ´´úÂë £¬GitHub¿¯Ðаæ £¬GoÓïÑÔÒÔ¼°Google DriveµÈÊÖÒÕÊֶΡ£


0x04 Öж«µØÇøµÄ APT »î¶¯


ÎÒÃÇ×î½üÔÚ2020Äê2Ô¼ì²âµ½ÁËStrongPity×éÖ¯Õë¶ÔÍÁ¶úÆäµÄÊý¾Ýй¶»î¶¯¡£Ö»¹ÜStrongPityµÄTTPÔÚÄ¿µÄ £¬»ù´¡ÉèÊ©ºÍѬȾǰÑÔ·½ÃæÃ»Óиıä £¬µ«ÎÒÃÇÊӲ쵽ËûÃÇÊÔͼй¶µÄÎļþÓÐËù²î±ð¡£Ôڴ˻ÖÐ £¬StrongPity¸üÐÂÁË×îеÄÊðÃûºóÃÅ £¬ÃûΪStrongPity2 £¬²¢Ìí¼ÓÁ˸ü¶àÎļþÒÔÖ²ÈëÆä³£¼ûµÄOfficeºÍPDFÎĵµÁбí £¬°üÀ¨ÓÃÓÚÏ£²®À´ÕÚÑÚµÄDagesh Pro×Ö´¦Öóͷ£Æ÷Îļþ £¬ÓÃÓÚºÓÁ÷Á÷Á¿ºÍÇÅÁº½¨Ä£µÄRiverCADÎļþ £¬´¿Îı¾Îļþ £¬¹éµµÎļþÒÔ¼°GPG¼ÓÃÜÎļþºÍPGPÃÜÔ¿¡£


3Ô £¬ÎÒÃÇ·¢Ã÷ÁËWildPressure×éÖ¯Õë¶Ô¹¤ÒµÁìÓò·Ö·¢MilumľÂíµÄ»î¶¯ £¬Ö¼ÔÚ¶ÔÄ¿µÄ×éÖ¯ÖеÄ×°±¸¾ÙÐÐÔ¶³Ì¿ØÖÆ¡£¸Ã»î¶¯×î³õ¿ÉÒÔ×·Ëݵ½2019Äê8Ô¡£µ½ÏÖÔÚΪֹ £¬ÎÒÃÇ¿´µ½µÄMilumʾÀýÓëÈκÎÒÑÖªµÄAPT»î¶¯Ã»ÓÐÈκδúÂëÏàËÆÐÔ¡£¸Ã¶ñÒâÈí¼þʹ¹¥»÷Õß¿ÉÒÔÔ¶³Ì¿ØÖÆÊÜѬȾµÄ×°±¸ £¬ÔÊÐíÏÂÔØºÍÖ´ÐÐÏÂÁî £¬ÍøÂçºÍй¶ÐÅÏ¢ÒÔ¼°ÔÚ¶ñÒâÈí¼þÖÐ×°ÖÃÉý¼¶³ÌÐò¡£


ÔÚ2019Äê12ÔÂÏÂÑ® £¬¿¨°Í˹»ùThreat Attribution Engine¼ì²âµ½ZerocleareµÄбäÌåDustman £¬±»ÓÃÓÚÕë¶ÔÉ³ÌØ°¢À­²®ÄÜÔ´²¿·ÖµÄ¹¥»÷¡£ÔÚ²Á³ýºÍ·Ö·¢·½Ãæ £¬ËüÓëZerocleareÏàËÆ £¬¿ÉÊDZäÁ¿ºÍÊÖÒÕÃû³ÆµÄת±äÅú×¢ £¬Õâ¿ÉÄÜÒѾ­×¼±¸ºÃÓ­½ÓÕë¶Ô¶ñÒâÈí¼þµÄÐÂÒ»²¨¹¥»÷ £¬ÕâЩ¹¥»÷»ùÓÚǶÈëÔÚ¶ñÒâÈí¼þÖеÄÐÂÎźͽ¨ÉèµÄ»¥³âÌå £¬×¨ÃÅÕë¶ÔÉ³ÌØ°¢À­²®µÄÄÜÔ´²¿·Ö¡£Í¨¹ýËü¡£ÓйØDustmanµÄPDBÎļþÅú×¢ £¬¸ÃÆÆËðÐÔ´úÂëÊÇ¿¯Ðаæ £¬¿ÉÒÔÔÚÄ¿µÄÍøÂçÖа²ÅÅ¡£ÕâЩת±äÇ¡·êÐÂÄê¼ÙÆÚ £¬ÔÚ´Ëʱ´úÐí¶àÔ±¹¤ÕýÔÚÐݼÙ¡£


0x05 ¶«ÄÏÑǺͳ¯Ïʰ뵺µÄAPT»î¶¯


Òâ´óÀûÇå¾²¹«Ë¾TelsyÔÚ2019Äê11Ô¸ÅÊöÁËLazarus×éÖ¯µÄ»î¶¯ £¬Ê¹ÎÒÃÇÄܹ»½«Õë¶Ô¼ÓÃÜÇ®±ÒÓªÒµµÄÏÈǰ»î¶¯ÁªÏµÆðÀ´¡£Telsy²©¿ÍÉÏÌáµ½µÄ¶ñÒâÈí¼þÊǵÚÒ»½×¶ÎÏÂÔØ³ÌÐò £¬×Ô2018ÄêÖÐÒÔÀ´Ò»Ö±±»ÊӲ쵽¡£ÎÒÃÇ·¢Ã÷µÚ¶þ½×¶Î¶ñÒâÈí¼þÊÇManuscryptµÄ±äÌå £¬ËüÊÇLazarusµÄ¶ÀÍÌÊôÐÔ £¬Æä°²ÅÅÁËÁ½ÖÖÀàÐ͵Äpayload¡£µÚÒ»¸öÊÇ¿ÉʹÓõÄUltra VNC³ÌÐò £¬µÚ¶þ¸öÊǶ༶ºóÃųÌÐò¡£ÕâÖÖÀàÐ͵Ķà½×¶ÎѬȾÀú³ÌÊÇLazarus×éÖ¯¶ñÒâÈí¼þµÄµä·¶ÌØÕ÷ £¬ÓÈÆäÊÇʹÓÃManuscrypt±äÌå¡£Ôڴ˻ÖÐ £¬Lazarus×éÖ¯¹¥»÷ÁËÈûÆÖ·˹ £¬ÃÀ¹ú £¬Öйų́ÍåºÍÖйúÏã¸ÛµÄ¼ÓÃÜÇ®±ÒÓªÒµ £¬¸Ã»î¶¯Ò»Ö±Ò»Á¬µ½2020ÄêÍ·¡£


×Ô2013ÄêÒÔÀ´ÎÒÃÇÒ»Ö±¸ú×ÙµÄ×éÖ¯KimsukyÔÚ2019ÄêÓÈÆä»îÔ¾¡£12Ô £¬Î¢Èí×÷·ÏÁ˸Ã×é֯ʹÓõÄ50¸öÓò £¬²¢ÔÚ¸¥¼ªÄáÑÇÖÝ·¨Ôº¶Ô¹¥»÷ÕßÌáÆðÁËËßËÏ¡£¿ÉÊÇ £¬¸ÃС×é¼ÌÐø¿ªÕ¹»î¶¯ £¬Ã»Óб¬·¢ÖØ´óת±ä¡£ÎÒÃÇ×î½ü·¢Ã÷ÁËÒ»¸öеĻ £¬ÆäÖÐʹÓÃÁËÒÔÐÂÄêÎʺòΪÖ÷ÌâµÄÓÕ¶üͼƬ £¬¸ÃͼƬΪ¾ÉÏÂÔØ¹¤¾ßÌṩÁËеľ­ÓÉˢеÄÏÂÒ»½×¶Îpayload £¬Ö¼ÔÚʹÓÃеļÓÃÜÒªÁìÀ´ÇÔÊØÐÅÏ¢¡£


1ÔÂβ £¬ÎÒÃÇ·¢Ã÷ÁËʹÓÃInternet ExplorerÎó²î£¨CVE-2019-1367£©µÄ¶ñÒâ¾ç±¾¡£ÔÚ×Ðϸ¼ì²épayload²¢·¢Ã÷ÓëÏÈǰ»î¶¯µÄÁªÏµÖ®ºó £¬ÎÒÃǵóö½áÂÛ £¬DarkHotelÖ§³Ö´Ë»î¶¯ £¬¸Ã»î¶¯¿ÉÄÜ×Ô2018ÄêÒÔÀ´Ò»Ö±ÔÚ¾ÙÐС£¸Ã»î¶¯¿´µ½DarkHotelʹÓÿª·¢µÄÈí¼þʵÏÖÁ˶à½×¶Î¶þ½øÖÆÑ¬È¾¡£×î³õµÄѬȾ»á½¨ÉèÒ»¸öÏÂÔØ³ÌÐò £¬¸ÃÏÂÔØ³ÌÐò½«»ñÈ¡ÁíÒ»¸öÏÂÔØ³ÌÐòÒÔÍøÂçϵͳÐÅÏ¢ £¬²¢½öΪ¸ß¼ÛÖµÊܺ¦Õß»ñÈ¡×îÖյĺóÃųÌÐò¡£DarkHotelÔڴ˻ÖÐʹÓÃÁËTTPµÄÆæÒì×éºÏ¡£ÍþвÕßʹÓÃÖÖÖÖ»ù´¡½á¹¹À´ÍйܶñÒâÈí¼þ²¢¿ØÖÆÊÜѬȾµÄÊܺ¦Õß £¬°üÀ¨ÊÜѬȾµÄWeb·þÎñÆ÷ £¬ÉÌÒµÍйܷþÎñ £¬Ãâ·ÑÍйܷþÎñºÍÃâ·ÑÔ´´úÂë¸ú×Ùϵͳ¡£


3Ô £¬À´×ÔGoogleµÄÑо¿Ö°Ô±Í¸Â¶ £¬Ò»×éºÚ¿ÍÔÚ2019ÄêʹÓÃÁËÎå¸ö0day¹¥»÷Ä¿µÄÕë¶Ô³¯ÏÊÈ˺ÍÒÔ³¯ÏÊÈËΪÖÐÐĵÄרҵְԱ¡£¸ÃС×éʹÓÃInternet Explorer £¬ChromeºÍWindowsÖеÄÎó²îÀ´¾ÙÐÐÍøÂç´¹Âںͷַ¢µç×ÓÓʼþ £¬ÕâЩµç×ÓÓʼþÖаüÀ¨¶ñÒ⸽¼þ»òÓë¶ñÒâÁ´½ÓÒÔ¼°Ë®¿Ó¹¥»÷¡£ÎÒÃÇÄܹ»½«ÆäÖеÄÁ½¸öÎó²î»®·ÖΪIEÖеÄÒ»¸öÎó²îºÍWindowsÖеÄÒ»¸öÎó²îÓëDarkHotel×é֯ƥÅäÉÏ¡£


FunnyDream×éÖ¯»î¶¯Ê¼ÓÚ2018ÄêÖÐ £¬Õë¶ÔÂíÀ´Î÷ÑÇ £¬Öйų́ÍåºÍ·ÆÂɱöµÄ×ÅÃû×éÖ¯ £¬ÆäÖдó´ó¶¼Êܺ¦ÕßÀ´×ÔÔ½ÄÏ¡£ÆÊÎöÅú×¢ £¬ÕâÖ»ÊÇÒ»Ïî¸üÆÕ±é¹¥»÷»î¶¯µÄÒ»²¿·Ö £¬¸Ã»î¶¯¿ÉÒÔ×·Ëݵ½¼¸Äêǰ £¬²¢Õë¶Ô¶«ÄÏÑǹú¼ÒµÄÕþ¸®ÌØÊâÊÇÍâ¹ú×éÖ¯¡£¹¥»÷ÕߵĺóÃÅ´ÓC2ÏÂÔØÎļþºÍÏòC2ÉÏ´«Îļþ £¬Ö´ÐÐÏÂÁî²¢ÔÚÊܺ¦ÕßϵͳÖÐÔËÐÐÐÂÀú³Ì¡£Ëü»¹ÍøÂçÓйØÍøÂçÉÏÆäËûÖ÷»úµÄÐÅÏ¢ £¬²¢Í¨¹ýÔ¶³ÌÖ´ÐÐÓ¦ÓóÌÐò½«Æäת´ï¸øÐÂÖ÷»ú¡£¹¥»÷Õß»¹Ê¹ÓÃÁËRTLºóÃźÍChinoxyºóÃÅ¡£×Ô2018ÄêÄêÖÐÒÔÀ´ £¬C2»ù´¡Éèʩһֱ´¦ÓÚ»îԾ״̬ £¬²¢ÇÒdomainsÓëFFRAT¶ñÒâÈí¼þ¼Ò×åÖØµþ¡£


Operation AppleJeusÊÇLazarus×îÓÐÓ°ÏìÁ¦µÄ»î¶¯Ö®Ò» £¬Ö÷ҪʹÓÃMacOS¶ñÒâÈí¼þ¾ÙÐй¥»÷¡£1Ô·ݵĺóÐøÑо¿Õ¹ÏÖÁ˸Ã×éÖ¯¹¥»÷ÒªÁìµÄÖØ´óת±ä£ºÐ¿ª·¢µÄmacOS¶ñÒâÈí¼þºÍÒ»ÖÖÉí·ÝÑéÖ¤»úÖÆ £¬¿ÉÒÔÉóÉ÷µØ½»¸¶ÏÂÒ»½×¶ÎµÄpayload £¬ÒÔ¼°ÔÚ²»½Ó´¥´ÅÅ̵ÄÇéÐÎϼÓÔØÏÂÒ»½×¶ÎµÄpayload¡£ÎªÁ˹¥»÷WindowsÊܺ¦Õß £¬¸Ã×éÖ¯ÖÆ¶©ÁËÒ»¸ö¶à½×¶ÎѬȾ³ÌÐò²¢¸ü¸ÄÁË×îÖÕpayload¡£ÎÒÃÇÒÔΪ £¬×Ô´ÓAppleJeus»î¶¯ÒÔÀ´ £¬LazarusÔÚ¹¥»÷·½ÃæÔ½·¢ÉóÉ÷ £¬²¢½ÓÄÉÁ˶àÖÖÒªÁìÀ´×èÖ¹±»·¢Ã÷¡£ÎÒÃÇÔÚÓ¢¹ú £¬²¨À¼ £¬¶íÂÞ˹ºÍÖйúÈ·¶¨Á˼¸ÃûÊܺ¦Õß¡£±ðµÄ £¬ÎÒÃÇÄܹ»È·ÈÏһЩÊܺ¦ÕßÓë¼ÓÃÜÇ®±Ò×éÖ¯ÓйØ¡£


Roaming MantisÊÇÒ»¸ö³öÓÚ¾­¼ÃÄîÍ·µÄAPT×éÖ¯ £¬ÓÚ2017ÄêÊ״ᨵÀ £¬Æäʱ¸Ã¹«Ë¾Ê¹ÓÃSMS½«Æä¶ñÒâÈí¼þ·Ö·¢¸øÎ»ÓÚº«¹úµÄAndroid×°±¸¡£ØÊºó¸Ã×éÖ¯µÄ»î¶¯¹æÄ£À©´ó £¬Ö§³Ö27ÖÖÓïÑÔ £¬ÒÔiOSºÍAndroidΪĿµÄ £¬ÉõÖÁÍÚ¾ò¼ÓÃÜÇ®±Ò¡£¸Ã×éÖ¯»¹Ê¹ÓÃÁËеĶñÒâÈí¼þ¼Ò×å £¬°üÀ¨FakecopºÍWroba.j £¬²¢ÇÒÈÔÔÚʹÓá°SMiShing¡±¾ÙÐÐAndroid¶ñÒâÈí¼þ·Ö·¢¡£ÔÚ×î½üµÄÒ»Ïî»î¶¯ÖÐ £¬Ëü·Ö·¢ÁËαװ³ÉÊܽӴýµÄ¿ìµÝ¹«Ë¾µÄ¶ñÒâAPK £¬Ö÷ÒªÕë¶ÔÈÕ±¾ £¬Öйų́Íå £¬º«¹úºÍ¶íÂÞ˹¡£


0x06 ÆäËü


TransparentTribeÓÚ2019ÄêÍ·×îÏÈʹÓÃÃûΪUSBWormµÄÐÂÄ£¿é £¬²¢¶ÔÆäÃûΪCrimsonRATµÄ×Ô½ç˵.NET¹¤¾ß¾ÙÐÐÁËˢС£Æ¾Ö¤ÎÒÃǵÄÒ£²â·¢Ã÷ £¬USBWorm±»ÓÃÀ´Ñ¬È¾³ÉǧÉÏÍòµÄÊܺ¦Õß £¬ÆäÖдó´ó¶¼Î»ÓÚ°¢¸»º¹ºÍÓ¡¶È £¬Ê¹¹¥»÷ÕßÄܹ»ÏÂÔØºÍÖ´ÐÐí§ÒâÎļþ £¬Èö²¥µ½¿ÉÒÆ¶¯×°±¸²¢´ÓÊÜѬȾµÄÖ÷»úÇÔÈ¡¸ÐÐËȤµÄÎļþ¡£ÕýÈçÎÒÃÇ֮ǰ±¨µÀµÄÄÇÑù £¬¸ÃС×éÖ÷Òª¹Ø×¢¾üÊÂÄ¿µÄ £¬ÕâЩĿµÄͨ³£Êܵ½OfficeÎĵµÖжñÒâVBAºÍPeppy RAT¡¢CrimsonRATµÈ¿ªÔ´¶ñÒâÈí¼þµÄ¹¥»÷¡£×î½üµÄлÖÐ £¬ÎÒÃÇ×¢ÖØµ½¸ÃС×éµÄÖØµã¸ü¶àµØ×ªÏòÁËÕë¶ÔÓ¡¶ÈÒÔÍâµÄ°¢¸»º¹¡£


ÔÚ2019ÄêµÄ×îºó¼¸¸öÔÂÖÐ £¬ÎÒÃÇÊӲ쵽ÁËFishing ElephantÕýÔÚ¾ÙÐеÄÒ»Ïî»î¶¯¡£¸ÃС×é¼ÌÐøÊ¹ÓÃHerokuºÍDropboxÀ´½»¸¶ÆäÑ¡ÔñµÄ¹¤¾ßAresRAT¡£ÎÒÃÇ·¢Ã÷ £¬¼ÓÈëÕßÔÚÆä²Ù×÷ÖнÓÄÉÁËÒ»ÏîÐÂÊÖÒÕ £¬¸ÃÊÖÒÕÖ¼ÔÚ×èÖ¹ÊÖ¶¯ºÍ×Ô¶¯ÆÊÎögeo-fencingºÍ½«¿ÉÖ´ÐÐÎļþÒþ²ØÔÚÖ¤ÊéÎļþÖС£ÔÚÎÒÃǵÄÑо¿Àú³ÌÖÐ £¬ÎÒÃÇ»¹·¢Ã÷Êܺ¦ÕßµÄת±ä¿ÉÄÜ·´Ó¦Á˹¥»÷ÕßµÄÄ¿½ñÀûÒæ £¬¸Ã×éÖ¯µÄÄ¿µÄÊÇÍÁ¶úÆä £¬°Í»ù˹̹ £¬ÃϼÓÀ­¹ú £¬ÎÚ¿ËÀ¼ºÍÖйúµÄÕþ¸®ºÍÍâ½»»ú¹¹¡£


0x07 ½áÓï


Ö»¹ÜÍþвÐÎÊÆ²¢²»×ÜÊdzäÂú¡°Í»ÆÆÐÔ¡±ÊÂÎñ £¬µ«µ±ÎÒÃǽ«ÑÛ¹âͶÏòAPTÍþвÐÐΪÕߵĻʱ £¬×ÜÊÇ»áÓÐÓÐȤµÄÉú³¤¡£ÎÒÃǵİ´ÆÚ¼¾¶ÈÉó²éÖ¼ÔÚÇ¿µ÷Òªº¦µÄÉú³¤¡£


ÕâЩÊǵ½ÏÖÔÚΪֹÎÒÃǽñÄêÒѾ­¿´µ½µÄһЩÖ÷ÒªÇ÷ÊÆ¡£

¡ñ µØÔµÕþÖÎÈÔÈ»ÊÇAPT»î¶¯µÄÖ÷ÒªÖúÍÆÁ¦¡£

¡ñ LazarusºÍRoaming MantisµÄ»î¶¯Ö¤Êµ £¬¾­¼ÃÀûÒæÈÔÈ»ÊÇijЩ¹¥»÷ÕßµÄÄîÍ·¡£

¡ñ ¾ÍAPT»î¶¯¶øÑÔ £¬¶«ÄÏÑÇÊÇ×î»îÔ¾µÄµØÇø £¬°üÀ¨Lazarus £¬DarkHotelºÍKimsukyµÈ×éÖ¯ £¬ÒÔ¼°Cloud SnooperºÍFishing ElephantµÈÐÂÐË×éÖ¯¡£

¡ñ APT×éÖ¯ £¬ÀýÈçCactusPete £¬TwoSail Junk £¬FunnyDreamºÍDarkHotel £¬¼ÌÐøÊ¹ÓÃÈí¼þÎó²î¡£

¡ñ APT×éÖ¯¼ÌÐø½«mobile implantsÄÉÈëÆäÎäÆ÷¿â¡£

¡ñ APT×éÖ¯£¨ÀýÈ絫²»ÏÞÓÚKimsuky £¬HadesºÍDarkHotel£©ÒÔʵʱ»úÖ÷Òå×ï·¸ÕýÔÚʹÓÃCOVID-19¡£


×ܶøÑÔÖ® £¬ÎÒÃÇ¿´µ½ÁËÑÇÖÞ¹¥»÷»î¶¯µÄÒ»Á¬ÔöÌí £¬Ê¹ÓÃÒÆ¶¯Æ½Ì¨Ñ¬È¾ºÍÈö²¥¶ñÒâÈí¼þµÄÇ÷ÊÆÕýÔÚÉÏÉý¡£


ÏÖÔÚ £¬COVID-19Êܵ½Ã¿Ð¡ÎÒ˽¼ÒµÄ¹Ø×¢ £¬¶øAPT×éÖ¯Ò²Ò»Ö±ÔÚʵÑéÔÚÓã²æÊ½ÍøÂç´¹ÂڻÖÐʹÓÃÕâÒ»Ö÷Ìâ¡£ÎÒÃÇÒÔΪÕâ²¢²»´ú±íTTP±¬·¢ÁËÓÐÒâÒåµÄת±ä£ºËûÃÇÖ»Êǽ«ÆäÓÃ×÷¾ßÓÐÐÂÎżÛÖµµÄ»°ÌâÀ´ÎüÒýÊܺ¦Õß¡£¿ÉÊÇ £¬ÎÒÃÇÕýÔÚÇ×½ü¼àÊÓÊ±ÊÆ¡£


0x08 ²Î¿¼Á´½Ó


https://securelist.com/apt-trends-report-q1-2020/96826/


0x09 ʱ¼äÏß


2020-05-01  VSRCÐû²¼±¨¸æ


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£