Android¶ñÒâÓ¦ÓÃCamScannerÏÂÔØÁ¿³¬1ÒÚ£»£»£» £»£»£»xHelperÔÚ4¸öÔÂÄÚѬȾ3.2Íò¸öÖÇÄÜ×°±¸

Ðû²¼Ê±¼ä 2019-08-29

1.Android¶ñÒâÓ¦ÓÃCamScannerÏÂÔØÁ¿³¬1ÒÚ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¿¨°Í˹»ùÑо¿Ö°Ô±·¢Ã÷CamScannerµÄÃâ·Ñ°æ±£´æÒ»¸öÒþ²ØµÄTrojan DropperÄ£¿£¿£¿£¿£¿£¿é£¬ £¬£¬£¬£¬£¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÓû§²»ÖªÇéµÄÇéÐÎÏÂÏÂÔØºÍ×°ÖöñÒâ³ÌÐò¡£¡£¡£¡£CamScannerÊÇÒ»¿îÊܽӴýµÄÊÖ»úPDF½¨ÉèAPP£¬ £¬£¬£¬£¬£¬ËüÔÚGoogle PlayÊÐËÁµÄÏÂÔØÁ¿Áè¼Ý1ÒÚ¡£¡£¡£¡£¶ñÒâÄ£¿£¿£¿£¿£¿£¿éÏÖʵÉϲ¢²»±£´æÓÚCamScanner×Ô¼ºµÄ´úÂëÖУ¬ £¬£¬£¬£¬£¬¶øÊÇÔÚµÚÈý·½¹ã¸æ¿âÖУ¬ £¬£¬£¬£¬£¬Òò´Ë¿ÉÒÔÍÆ¶ÏÕâÊÇÈí¼þ¿ª·¢ÕߺͲ»Æ·µÂµÄ¹ã¸æÉÌÏàÖúµÄЧ¹û¡£¡£¡£¡£¸ÃÄ£¿£¿£¿£¿£¿£¿é¿ÉÒÔͨ¹ý¶àÖÖ·½·¨Ê¹ÓÃÊÜѬȾµÄ×°±¸£¬ £¬£¬£¬£¬£¬´ÓÏÔʾÇÖÈëÐÔ¹ã¸æµ½¸¶·Ñ¶©ÔÄÇÔÈ¡»°·ÑµÈ¡£¡£¡£¡£Ó¦¸Ã×¢ÖØµÄÊÇ£¬ £¬£¬£¬£¬£¬CamScannerµÄ¸¶·Ñ°æ±¾²»°üÀ¨µÚÈý·½¹ã¸æ¿â¡£¡£¡£¡£GoogleÒѾ­´Ó¹Ù·½PlayÊÐËÁÖÐɾ³ýÁ˸ÃAPP¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/08/android-camscanner-malware.html


2.AndroidľÂíxHelperÔÚ4¸öÔÂÄÚѬȾ3.2Íò¸öÖÇÄÜ×°±¸


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Malwarebytes Labs·¢Ã÷ÐÂAndroidľÂíDropper.xHelper£¬ £¬£¬£¬£¬£¬×Ô5Ô·ÝÒÔÀ´£¬ £¬£¬£¬£¬£¬Ôڶ̶Ì4¸öÔÂÄÚxHelperÒѾ­Ñ¬È¾ÁËÁè¼Ý3.2Íǫ̀ÖÇÄÜÊÖ»úÇå¾²°å×°±¸¡£¡£¡£¡£¼øÓÚÆä¿ìËÙѬȾÐÂ×°±¸µÄÄÜÁ¦£¬ £¬£¬£¬£¬£¬xHelperÊÇÒ»¸öÐèÒªÈÏÕæ¿´´ýµÄÍþв¡£¡£¡£¡£ËäÈ»ÉÐδ·¢Ã÷׼ȷµÄÑ¬È¾ÔØÌ壬 £¬£¬£¬£¬£¬µ«ÆÊÎöÏÔʾxHelperÍйÜÔÚÃÀ¹úµÄIPµØµãÉÏ£¬ £¬£¬£¬£¬£¬ÆäÖÐÒ»¸öλÓÚŦԼ£¬ £¬£¬£¬£¬£¬ÁíÒ»¸öÔڵ¿ËÈøË¹ÖÝ´ïÀ­Ë¹¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒԿ϶¨µØËµÕâÊÇÕë¶ÔÃÀ¹úµÄ¹¥»÷£¬ £¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹µÃ³ö½áÂÛÕâÖÖÒÆ¶¯Ñ¬È¾ÕýÔÚͨ¹ýÍøÂçÖØ¶¨ÏòÈö²¥¡£¡£¡£¡£ÓÉÓÚ´úÂë±»ÑÏÖØ»ìÏý£¬ £¬£¬£¬£¬£¬ºÜÄÑÈ·ÇеØÖ¸³öxHelperµÄÄ¿µÄÊÇʲô£¬ £¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±ÒÔΪÆäÖ÷Òª¹¦Ð§ÊǽÓÊÜÔ¶³ÌÏÂÁ £¬£¬£¬£¬£¬ÀàËÆÓÚºóÃÅ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/android-trojan-infects-tens-of-thousands-of-devices-in-4-months/


3.TrickBotбäÖÖÃé×¼ÃÀ¹úÒÆ¶¯ÔËÓªÉÌ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


TrickBotбäÖÖÕýÔÚÊÔͼÇÔÈ¡ÃÀ¹úÒÆ¶¯ÔËÓªÉÌVerizon¡¢T-MobileºÍSprintÓû§µÄPINÂ룬 £¬£¬£¬£¬£¬²¢ÌᳫSIM¿¨½»Á÷¹¥»÷¡£¡£¡£¡£´÷¶ûSecureworksÑо¿ÍŶÓÖÒÑԳƣ¬ £¬£¬£¬£¬£¬¸Ã±äÖÖʹÓÃÒ»¸öÐÂÄ£¿£¿£¿£¿£¿£¿éÀ´×èµ²ÊÜѬȾϵͳÉϵÄÍøÂç»á»°£¬ £¬£¬£¬£¬£¬²¢ÔÚÕâЩÔËÓªÉ̵ÄÍøÕ¾ÉÏ×¢Èë´úÂ룬 £¬£¬£¬£¬£¬ÓÃÓÚÇÔÈ¡Óû§µÄÕË»§ÃÜÂë¡¢PINÂëµÈƾ֤¡£¡£¡£¡£ÕâÖÖڲƭÐÐΪÔÊÐí¹¥»÷Õß¿ØÖÆÊܺ¦Õߵĵ绰ºÅÂ룬 £¬£¬£¬£¬£¬°üÀ¨ËùÓÐÈëÕ¾ºÍ³öÕ¾¶ÌÐźÍÓïÒôͨѶ¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ8Ô·ÝÊӲ쵽ÕâЩ¹¥»÷»î¶¯£¬ £¬£¬£¬£¬£¬°üÀ¨Õë¶ÔVerizon Wireless£¨8ÔÂ5ÈÕ£©¡¢T-Mobile£¨8ÔÂ12ÈÕ£©ºÍSprint£¨8ÔÂ19ÈÕ£©¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-trickbot-variant-targets-verizon-t-mobile-and-sprint-users/


4.·¨¹ú¾¯·½´Ó85Íǫ̀PCÖÐÔ¶³Ìɨ³ý¶ñÒâÈí¼þRETADUP


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


·¨¹úÖ´·¨»ú¹¹National GendarmerieÐû²¼Àֳɵ·»Ù½©Ê¬ÍøÂçRETADUP£¬ £¬£¬£¬£¬£¬²¢ÔÚAvastµÄ×ÊÖú϶ÔÈ«ÇòÁè¼Ý85Íǫ̀ÅÌËã»ú¾ÙÐÐÁËÔ¶³Ìɱ¶¾¡£¡£¡£¡£½ñÄêÔçЩʱ¼äAvast·¢Ã÷RETADUPµÄC£¦CЭÒéÖб£´æÒ»¸öÉè¼ÆÈ±ÏÝ£¬ £¬£¬£¬£¬£¬¿ÉÓÃÓÚ´ÓÊܺ¦ÕßµÄÅÌËã»úÖÐɾ³ý¸Ã¶ñÒâÈí¼þ¡£¡£¡£¡£Òò´ËAvastÁªÏµÁË·¨¹ú¾¯·½£¬ £¬£¬£¬£¬£¬²¢ÔÚ7Ô·ݿØÖÆÁËRETADUPµÄC£¦CЧÀÍÆ÷£¬ £¬£¬£¬£¬£¬Ì滻Ϊһ¸öɱ¶¾°æ±¾£¬ £¬£¬£¬£¬£¬¸ÃЧÀÍÆ÷¿ÉʹÓÃÆäЭÒéÖеÄȱÏÝÏÂÁîÊÜѬȾÅÌËã»úÉϵÄRETADUP×Ô»Ù¡£¡£¡£¡£×èÖ¹ÎÄÕÂÐû²¼Ê±£¬ £¬£¬£¬£¬£¬Õþ¸®ÒѾ­É¨³ýÁËÁè¼Ý85Íò¸öѬȾʵÀý£¬ £¬£¬£¬£¬£¬ÆäÖдó´ó¶¼Êܺ¦ÕßÀ´×ÔÓÚ½²Î÷°àÑÀÓïµÄÀ­¶¡ÃÀÖÞ¹ú¼Ò¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/08/retadup-botnet-malware.html


5.È«ÇòÁè¼Ý80¸öµç×ÓÉÌÎñÍøÕ¾Ñ¬È¾Magecart¾ç±¾


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ƾ֤ÖÜÈýAite GroupºÍArxan TechnologiesÐû²¼µÄÑо¿Ð§¹û£¬ £¬£¬£¬£¬£¬È«ÇòÁè¼Ý80¸öµç×ÓÉÌÎñÍøÕ¾ÔâMagecart¾ç±¾ÈëÇÖ£¬ £¬£¬£¬£¬£¬ÕâÐ©ÍøÕ¾ÖÐÓÐËÄ·ÖÖ®Ò»£¨25£¥£©ÊôÓÚÈü³µÔ˶¯ºÍÉÝ³ÞÆ·´ò°çµÄ×ÅÃûÆ·ÅÆ¡£¡£¡£¡£ÊÜÓ°ÏìµÄÍøÕ¾±é²¼Õû¸öÃÀ¹ú¡¢¼ÓÄôó¡¢Å·ÖÞ¡¢À­¶¡ÃÀÖÞºÍÑÇÖÞ¡£¡£¡£¡£¸ÃÑо¿Åú×¢£¬ £¬£¬£¬£¬£¬ËùÓÐÕâÐ©ÍøÕ¾¶¼ÔËÐÐ×ÅMagentoµç×ÓÉÌÎñƽ̨µÄ¹ýʱ°æ±¾£¬ £¬£¬£¬£¬£¬°üÀ¨1.5¡¢1.7»ò1.9£¬ £¬£¬£¬£¬£¬ÕâЩ°æ±¾Ò×Êܶà¸öÎļþÉÏ´«¡¢Ô¶³Ì´úÂëÖ´ÐкÍCSRFÎó²îÓ°Ïì¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/magecart-ecommerce-card-skimming-bonanza/147765/


6.ÐÂIoT½©Ê¬ÍøÂçAresÃé×¼Android»ú¶¥ºÐ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÐÂIoT½©Ê¬ÍøÂçAresÕýÔÚѬȾ»ùÓÚAndroidµÄ×°±¸£¬ £¬£¬£¬£¬£¬Æ¾Ö¤WootCloudµÄ˵·¨£¬ £¬£¬£¬£¬£¬¸Ã½©Ê¬ÍøÂç×î³£¼ûµÄÄ¿µÄÊÇÓÉHiSilicon¡¢CubetekºÍQezyMediaÖÆÔìµÄAndroid»ú¶¥ºÐ¡£¡£¡£¡£Ares²¢Î´Ê¹ÓÃAndroid²Ù×÷ϵͳÖеÄÎó²î£¬ £¬£¬£¬£¬£¬¶øÊÇʹÓÃÕâЩ»ú¶¥ºÐÖÐÆôÓÃÁ˵«Î´Êܱ£»£»£» £»£»£»¤µÄADBµ÷ÊÔЧÀÍ¡£¡£¡£¡£ÕâЩ¹¥»÷ʼÓÚ7Ô£¬ £¬£¬£¬£¬£¬WootCloudÊ×ϯÊÖÒÕ¹ÙSrinivas Akella³ÆÒ²²»É¨³ýÆäËûÀàÐ͵ÄAndroidϵͳÊܵ½Ñ¬È¾µÄ¿ÉÄÜÐÔ¡£¡£¡£¡£AresµÄ×îÖÕÄ¿µÄδ֪£¬ £¬£¬£¬£¬£¬µ«ÓÉÓÚÆä»ùÓÚ½ÏÀϵÄMirai£¬ £¬£¬£¬£¬£¬¿ÉÒÔÔ¤¼Æ¸Ã½©Ê¬ÍøÂ罫±»ÓÃÓÚÌᳫDDoS¹¥»÷ºÍÓÃ×÷Á÷Á¿ÊðÀí¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/a-new-iot-botnet-is-infecting-android-based-set-top-boxes/