{"id":13375,"date":"2015-07-24T11:20:29","date_gmt":"2015-07-24T03:20:29","guid":{"rendered":"https:\/\/blog.trendmicro.com.tw\/?p=13375"},"modified":"2015-09-15T18:07:42","modified_gmt":"2015-09-15T10:07:42","slug":"%e5%8f%af%e7%ab%8a%e8%81%bd%e9%9b%bb%e8%a9%b1%e7%9a%84-hacking-team-rcsandroid-%e9%96%93%e8%ab%9c%e5%b7%a5%e5%85%b7","status":"publish","type":"post","link":"https:\/\/blog.trendmicro.com.tw\/?p=13375","title":{"rendered":"\u6703\u7aca\u807d\u96fb\u8a71\u7684 Hacking Team RCSAndroid \u9593\u8adc\u5de5\u5177"},"content":{"rendered":"<blockquote><p>RCSAndroid \u7a0b\u5f0f\u78bc\u7684\u5916\u6d29\u5df2\u8b93\u5b83\u6210\u70ba\u4e00\u9805\u516c\u958b\u7684\u5546\u696d\u9593\u8adc\u5229\u5668\u3002\u884c\u52d5\u4f7f\u7528\u8005\u6700\u597d\u96a8\u6642\u638c\u63e1\u9019\u9805\u65b0\u805e\u7684\u6700\u65b0\u767c\u5c55\uff0c\u4e26\u4e14\u96a8\u6642\u7559\u610f\u88dd\u7f6e\u662f\u5426\u6709\u906d\u5230\u76e3\u807d\u7684\u8de1\u8c61\u3002\u53ef\u7591\u7684\u8de1\u8c61\u5305\u62ec\u7cfb\u7d71\u51fa\u73fe\u7570\u5e38\u884c\u70ba\uff0c\u4f8b\u5982\uff1a\u4e0d\u6b63\u5e38\u91cd\u65b0\u958b\u6a5f\u3001\u88dd\u7f6e\u4e0a\u51fa\u73fe\u4e00\u4e9b\u83ab\u540d\u5176\u5999\u7684\u61c9\u7528\u7a0b\u5f0f\u3001\u5373\u6642\u901a\u8a0a\u8edf\u9ad4\u7a81\u7136\u7576\u6389\u7b49\u7b49\u3002<\/p>\n<p>\u4e00\u65e6\u88dd\u7f6e\u906d\u5230\u611f\u67d3\uff0c\u9019\u500b\u5f8c\u9580\u7a0b\u5f0f\u5fc5\u9808\u6709\u7cfb\u7d71\u7ba1\u7406\u54e1 (root) \u6b0a\u9650\u624d\u80fd\u79fb\u9664\uff0c\u4f7f\u7528\u8005\u53ef\u80fd\u9700\u8981\u9001\u56de\u539f\u5ee0\u4f86\u8acb\u4ed6\u5011\u91cd\u5237\u97cc\u9ad4\u624d\u884c\u3002<\/p><\/blockquote>\n<p>\u7e7c\u65b0\u805e\u5831\u5c0e\u6307\u51fa <a href=\"https:\/\/www.scmagazine.com\/ios-devices-dont-have-to-be-jailbroken-for-spyware-sold-by-hacking-team-to-be-installed\/article\/426137\/\">iOS \u88dd\u7f6e\u53ef\u80fd\u906d\u5230 Hacking Team \u9593\u8adc\u7a0b\u5f0f\u76e3\u807d<\/a>\u4e4b\u5f8c\uff0c\u73fe\u5728 Android \u88dd\u7f6e\u4e5f\u5c07\u906d\u6b83\u3002<a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2651&amp;name=20110916\">\u8da8\u52e2\u79d1\u6280<\/a>\u5728<a href=\"https:\/\/blog.trendmicro.com.tw\/?s=hacking\"> Hacking Team \u8cc7\u6599\u5916\u6d29<\/a>\u7684\u6a94\u6848\u7576\u4e2d\u767c\u73fe\u5176\u958b\u653e\u539f\u59cb\u78bc\u60e1\u610f\u7a0b\u5f0f\u5957\u4ef6 RCSAndroid (Android \u9060\u7aef\u9059\u63a7\u7cfb\u7d71) \u7684\u7a0b\u5f0f\u78bc\uff0c\u9019\u662f\u8a72\u516c\u53f8\u6240\u8ca9\u8ce3\u7684\u4e00\u9805\u9593\u8adc\u5de5\u5177\u3002<\/p>\n<p>RCSAndroid \u5de5\u5177\u7684\u7a0b\u5f0f\u78bc\u662f\u81f3\u4eca\u66dd\u5149\u7684\u6240\u6709 Android \u60e1\u610f\u7a0b\u5f0f\u7576\u4e2d\u5beb\u5f97\u6700\u5c08\u696d\u3001\u6700\u8907\u96dc\u5de5\u5177\u4e4b\u4e00\u3002\u5176\u7a0b\u5f0f\u78bc\u7684\u66dd\u5149\uff0c\u8b93\u7db2\u8def\u72af\u7f6a\u96c6\u5718\u53c8\u591a\u4e86\u4e00\u9805\u65b0\u7684\u5229\u5668\u53ef\u5f37\u5316\u5176\u9593\u8adc\u884c\u52d5\u3002<\/p>\n<p><a href=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2015\/07\/Hacking-Team-RCSAndroid.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-13378\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2015\/07\/Hacking-Team-RCSAndroid.png\" alt=\"Hacking Team RCSAndroid\u624b\u6a5f\u9593\u8adc\" width=\"794\" height=\"415\" \/><\/a><\/p>\n<p>\u6839\u64da\u5916\u6d29\u7684\u7a0b\u5f0f\u78bc\u770b\u4f86\uff0cRCSAndroid \u61c9\u7528\u7a0b\u5f0f\u5177\u5099\u4e0b\u521710 \u500b\u9593\u8adc\u80fd\u529b\uff1a<\/p>\n<ol>\n<li>\u900f\u904e\u300cscreencap\u300d\u9019\u500b\u6307\u4ee4\u64f7\u53d6\u87a2\u5e55\u6293\u5716\uff0c\u4e26\u53ef\u76f4\u63a5\u8b80\u53d6\u87a2\u5e55\u7de9\u885d\u5340\u5167\u5bb9\u3002<\/li>\n<li>\u76e3\u770b\u526a\u8cbc\u7c3f\u7684\u5167\u5bb9\u3002<\/li>\n<li>\u8490\u96c6 Wi-Fi \u7db2\u8def\u8207\u5404\u7a2e\u7db2\u8def\u5e33\u865f\u7684\u5bc6\u78bc\uff0c\u5982\uff1aSkype\u3001Facebook\u3001Twitter\u3001Google\u3001WhatsApp\u3001Mail \u53ca LinkedIn\u3002<\/li>\n<li>\u5229\u7528\u9ea5\u514b\u98a8\u9304\u97f3\u3002<\/li>\n<li>\u8490\u96c6\u7c21\u8a0a\u3001\u591a\u5a92\u9ad4\u7c21\u8a0a\u8207 Gmail \u8a0a\u606f\u3002<\/li>\n<li>\u8490\u96c6\u5b9a\u4f4d\u8cc7\u8a0a\u3002<\/li>\n<li>\u8490\u96c6\u88dd\u7f6e\u8cc7\u8a0a\u3002<\/li>\n<li>\u5229\u7528\u524d\u3001\u5f8c\u93e1\u982d\u62cd\u7167\u3002<\/li>\n<li>\u8490\u96c6\u806f\u7d61\u4eba\uff0c\u89e3\u8b80\u5373\u6642\u901a\u8a0a\u8a0a\u606f\uff0c\u5982\uff1aFacebook Messenger\u3001WhatsApp\u3001Skype\u3001Viber\u3001Line\u3001WeChat\u3001Hangouts\u3001Telegram \u4ee5\u53ca BlackBerry Messenger\u3002<\/li>\n<li>\u6514\u622a\u7cfb\u7d71\u7684 mediaserver \u670d\u52d9\uff0c\u5373\u6642\u9304\u4e0b\u4efb\u4f55\u884c\u52d5\u96fb\u8a71\u8207 App \u7684\u8a9e\u97f3\u901a\u8a71\u3002<\/li>\n<\/ol>\n<p><!--more--><\/p>\n<p><strong>\u7db2\u8def\u4e0a\u6d41\u50b3\u7684 RCSAndroid<\/strong><\/p>\n<p>\u6839\u64da<a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2651&amp;name=20110916\">\u8da8\u52e2\u79d1\u6280<\/a>\u7684\u5206\u6790\uff0c\u9019\u4e00\u7248\u7684 RCSAndroid (AndroidOS_RCSAgent.HRX) \u5f9e 2012 \u5e74\u958b\u59cb\u4fbf\u5df2\u5728\u7db2\u8def\u9593\u6d41\u50b3\u3002\u5728\u4e0b\u5217\u8a2d\u5b9a\u6a94\u4e2d\u53ef\u770b\u5230\u5176\u5148\u524d\u5728\u7db2\u8def\u4e0a\u7684\u8e64\u8de1\uff1a<\/p>\n<ul>\n<li>\u5b83\u88ab\u8a2d\u5b9a\u9023\u4e0a\u4e00\u500b\u4f4d\u65bc\u7f8e\u570b\u7684\u5e55\u5f8c\u64cd\u7e31 (C&amp;C) \u4f3a\u670d\u5668\uff0c\u4f46\u8a72\u4f3a\u670d\u5668\u662f\u5411\u4e00\u5bb6\u4e3b\u6a5f\u670d\u52d9\u4f9b\u61c9\u5546\u63a1\u8cfc\u7684\uff0c\u73fe\u5728\u5df2\u7121\u6cd5\u9023\u4e0a\u3002<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2015\/07\/RCSAndroid_01.png\" alt=\"\" width=\"550\" height=\"126\" \/><\/p>\n<p><em>\u5716 1\uff1a\u8a2d\u5b9a\u6a94\u4e2d\u7684 C&amp;C \u4e3b\u6a5f\u3002<\/em><\/p>\n<ul>\n<li>\u5b83\u8a2d\u5b9a\u6210\u900f\u904e\u4e00\u500b\u6377\u514b\u96fb\u8a71\u865f\u78bc\u4f86\u767c\u7c21\u8a0a\u5c07\u5b83\u555f\u52d5\u3002\u99ed\u5ba2\u6703\u767c\u9001\u7279\u5b9a\u7c21\u8a0a\u4f86\u555f\u52d5\u5176\u4ee3\u7406\u7a0b\u5f0f\u4e26\u89f8\u767c\u7279\u5b9a\u52d5\u4f5c\u3002\u6b64\u5916\uff0c\u4e5f\u53ef\u4ee5\u6307\u5b9a\u8981\u8490\u96c6\u4ec0\u9ebc\u6a23\u7684\u8cc7\u8a0a\u3002<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2015\/07\/RCSAndroid_02.png\" alt=\"\" width=\"550\" height=\"70\" \/><\/p>\n<p><em>\u5716 2\uff1a\u8a2d\u5b9a\u6a94\u4e2d\u7684\u6377\u514b\u96fb\u8a71\u865f\u78bc<\/em><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>\u6839\u64da\u5916\u6d29\u7684\u96fb\u5b50\u90f5\u4ef6\u986f\u793a\uff0c\u96fb\u8a71\u865f\u78bc\u6240\u5c6c\u7684\u6377\u514b\u516c\u53f8\u986f\u7136\u9084\u8207<a href=\"https:\/\/blog.trendmicro.com.tw\/?s=hacking\"> Hacking Team \u8cc7\u6599\u5916\u6d29<\/a>\u6709\u696d\u52d9\u5f80\u4f86\uff0c\u5305\u62ec\u5967\u904b\u4e3b\u8fa6\u55ae\u4f4d\u5408\u4f5c\u7684\u4e00\u5bb6\u91cd\u8981 IT \u5ee0\u5546\u3002<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2015\/07\/RCSAndroid_03.png\" alt=\"\" width=\"550\" height=\"174\" \/><\/p>\n<p><em>\u5716 3\uff1a\u4f86\u81ea\u4e00\u5bb6\u6377\u514b\u5ba2\u6236\u7684\u5347\u7d1a\u652f\u63f4\u8acb\u6c42<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><strong>\u6295\u4e0b\u96c6\u675f\u70b8\u5f48<\/strong><\/p>\n<p>RCSAndroid \u7684\u5a01\u8105\u5c31\u50cf\u96c6\u675f\u70b8\u5f48\u4e00\u6a23\uff0c\u6703\u653b\u64ca\u591a\u500b\u5371\u96aa\u7684\u6f0f\u6d1e\u4e26\u4f7f\u7528\u5404\u7a2e\u6280\u5de7\u4f86\u611f\u67d3 Android \u88dd\u7f6e\u3002<a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2651&amp;name=20110916\">\u8da8\u52e2\u79d1\u6280<\/a>\u5728\u5206\u6790\u7a0b\u5f0f\u78bc\u7684\u904e\u7a0b\u4e2d\u767c\u73fe\uff0c\u5176\u6574\u5957\u7cfb\u7d71\u5305\u542b\u56db\u5927\u90e8\u5206\uff1a<\/p>\n<ol>\n<li>\u6ef2\u900f\u5de5\u5177\uff1a\u7d93\u7531\u7c21\u8a0a\/\u96fb\u5b50\u90f5\u4ef6\u6216\u6b63\u5e38\u7684 App \u9032\u5165\u76ee\u6a19\u88dd\u7f6e\u3002<\/li>\n<li>\u4f4e\u968e\u539f\u751f\u7a0b\u5f0f\u78bc\uff1a\u53ef\u7a81\u7834 Android \u5b89\u5168\u67b6\u69cb\u7684\u9032\u968e\u6f0f\u6d1e\u653b\u64ca\u548c\u9593\u8adc\u5de5\u5177\u3002<\/li>\n<li>\u9ad8\u968e Java \u4ee3\u7406\u7a0b\u5f0f\uff1a\u6b64 App \u7684\u60e1\u610f APK \u6a94\u6848\u3002<\/li>\n<li>C&amp;C \u4f3a\u670d\u5668\uff1a\u7528\u4f86\u5f9e\u9060\u7aef\u767c\u9001\/\u63a5\u6536\u60e1\u610f\u6307\u4ee4\u3002<\/li>\n<\/ol>\n<p>\u99ed\u5ba2\u6703\u5229\u7528\u5169\u7a2e\u65b9\u6cd5\u4f86\u5f15\u8a98\u76ee\u6a19\u5c0d\u8c61\u4e0b\u8f09 RCSAndroid \u7a0b\u5f0f\u3002<\/p>\n<p>\u7b2c\u4e00\u7a2e\u65b9\u6cd5\u662f\u900f\u904e\u7c21\u8a0a\u6216\u96fb\u5b50\u90f5\u4ef6\u767c\u9001\u4e00\u500b\u7279\u6b8a\u7684\u7db2\u5740\u7d66\u76ee\u6a19\u5c0d\u8c61\u3002\u6b64\u7db2\u5740\u9023\u4e0a\u7684\u7db2\u7ad9\u6703\u653b\u64ca Android 4.0 Ice Cream Sandwich \u5230 4.3 Jelly Bean \u9810\u8a2d\u700f\u89bd\u5668\u7684 <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2012-2825\">CVE-2012-2825<\/a> (\u8b80\u53d6\u4efb\u610f\u8a18\u61b6\u9ad4\u4f4d\u7f6e) \u53ca <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2012-2871\">CVE-2012-2871<\/a> (\u8a18\u61b6\u9ad4\u7de9\u885d\u5340\u6ea2\u4f4d) \u5169\u500b\u6f0f\u6d1e\uff0c\u9032\u800c\u8b93\u99ed\u5ba2\u653b\u64ca\u53e6\u4e00\u500b\u53ef\u53d6\u5f97\u672c\u5730\u7aef\u7ba1\u7406\u54e1\u6b0a\u9650\u7684\u6f0f\u6d1e\u3002\u5728\u53d6\u5f97\u7cfb\u7d71\u7ba1\u7406\u54e1 (root) \u6b0a\u9650\u4e4b\u5f8c\uff0c\u5c31\u6703\u5b89\u88dd\u4e00\u500b shell \u5f8c\u9580\u7a0b\u5f0f\u548c RCSAndroid \u4ee3\u7406\u7a0b\u5f0f\u7684 APK \u6a94\u6848\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2015\/07\/RCSAndroid_04.png\" alt=\"\" width=\"493\" height=\"801\" \/><\/p>\n<p><em>\u5716 4\uff1a\u5916\u6d29\u8cc7\u6599\u7576\u4e2d\u7d66\u5ba2\u6236\u7684\u9060\u7aef\u6f0f\u6d1e\u653b\u64ca\u8aaa\u660e<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>\u7b2c\u4e8c\u7a2e\u65b9\u6cd5\u662f\u5229\u7528\u4e00\u500b\u96b1\u533f\u7684\u5f8c\u9580 App \u7a0b\u5f0f (\u5982 <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/ANDROIDOS_HTBENEWS.A\">ANDROIDOS_HTBENEWS.A<\/a>)\uff0c\u8a72\u7a0b\u5f0f\u53ef\u907f\u958b Google Play \u7684\u6a5f\u5236\u3002<\/p>\n<p>ANDROIDOS_HTBENEWS.A \u548c\u7b2c\u4e00\u7a2e\u65b9\u6cd5\u4e2d\u63d0\u5230\u7684\u60e1\u610f APK \u6a94\u6848\u662f\u7528\u4f86\u653b\u64ca Android \u88dd\u7f6e\u7684\u4e00\u500b\u672c\u5730\u7aef\u63d0\u5347\u6b0a\u9650\u7684\u6f0f\u6d1e\u3002<a href=\"https:\/\/blog.trendmicro.com.tw\/?s=hacking\"> Hacking Team \u8cc7\u6599\u5916\u6d29<\/a>\u904e\u53bb\u5c31\u66fe\u5728\u653b\u64ca\u884c\u52d5\u7576\u4e2d\u5229\u7528 CVE-2014-3153 \u548c CVE-2013-6282 \u5169\u500b\u6f0f\u6d1e\u3002\u9019\u5169\u500b\u6f0f\u6d1e\u53ef\u7834\u89e3 (root) \u88dd\u7f6e\uff0c\u7136\u5f8c\u518d\u5b89\u88dd\u4e00\u500b shell \u5f8c\u9580\u7a0b\u5f0f\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2015\/07\/RCSAndroid_05.png\" alt=\"\" width=\"550\" height=\"294\" \/><\/p>\n<p><em>\u5716 5\uff1ashell \u5f8c\u9580\u7a0b\u5f0f\u7684\u6307\u4ee4\u6e05\u55ae<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>\u9019\u500b shell \u5f8c\u9580\u7a0b\u5f0f\u63a5\u8457\u5b89\u88dd RCSAndroid \u4ee3\u7406\u7a0b\u5f0f\u3002\u6b64\u4ee3\u7406\u7a0b\u5f0f\u5206\u6210\u5169\u500b\u6a21\u7d44\uff1aEvidence Collector (\u8b49\u64da\u8490\u96c6\u6a21\u7d44) \u548c Event Action Trigger (\u4e8b\u4ef6\u52d5\u4f5c\u89f8\u767c\u6a21\u7d44)\u3002<\/p>\n<ul>\n<li>Evidence Collector \u6a21\u7d44\u8ca0\u8cac\u57f7\u884c\u524d\u8ff0\u7684\u9593\u8adc\u884c\u52d5\uff0c\u5176\u4e2d\u6700\u91cd\u8981\u7684\u4e00\u9805\u5c31\u662f\u6514\u622a\u300cmediaserver\u300d\u7cfb\u7d71\u670d\u52d9\u4f86\u5373\u6642\u64f7\u53d6\u8a9e\u97f3\u901a\u8a71\u5167\u5bb9\u3002\u57fa\u672c\u4e0a\u5c31\u662f\u6514\u622a mediaserver \u7576\u4e2d\u7684\u8a9e\u97f3\u901a\u8a71\u57f7\u884c\u7a0b\u5e8f\u3002\n<ul>\n<li>\u4ee5\u8a9e\u97f3\u901a\u8a71\u64ad\u653e\u7a0b\u5e8f\u70ba\u4f8b\uff0cmediaserver \u6703\u5148\u5efa\u7acb\u4e00\u500b\u65b0\u7684\u975e\u91cd\u8907\u97f3\u8ecc\uff0c\u7136\u5f8c\u64ad\u653e\u8a72\u97f3\u8ecc\uff0c\u518d\u5faa\u74b0\u64ad\u653e\u6240\u6709\u97f3\u8a0a\u7de9\u885d\u5340\u4e2d\u7684\u5167\u5bb9\uff0c\u6700\u5f8c\u505c\u6b62\u64ad\u653e\u3002\u539f\u59cb\u7684WAVE\u97f3\u8a0a\u7de9\u885d\u5340\u5167\u5bb9\u53ef\u5229\u7528 getNextBuffer() \u51fd\u5f0f\u4f86\u64f7\u53d6\u3002\u85c9\u7531\u958b\u653e\u539f\u59cb\u78bc <a href=\"https:\/\/github.com\/crmulliner\/adbi\">Android Dynamic Binary Instrumentation Toolkit<\/a> (\u52d5\u614b\u4e8c\u9032\u4f4d\u7a0b\u5f0f\u5be6\u4f5c\u5de5\u5177\u5957\u4ef6) \u7684\u8f14\u52a9\uff0c\u518d\u52a0\u4e0a\u7cfb\u7d71\u7ba1\u7406\u54e1 (root) \u6b0a\u9650\uff0c\u99ed\u5ba2\u5c31\u80fd\u6514\u622a\u4efb\u4f55\u51fd\u5f0f\u7684\u57f7\u884c\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2015\/07\/RCSAndroid_06.png\" alt=\"\" width=\"550\" height=\"250\" \/><\/p>\n<p><em>\u5716 6\uff1a\u8a9e\u97f3\u901a\u8a71\u64ad\u653e\u6514\u622a\u6d41\u7a0b<\/em><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>Event Action Trigger \u6a21\u7d44\u6703\u6839\u64da\u67d0\u4e9b\u7279\u5b9a\u4e8b\u4ef6\u4f86\u89f8\u767c\u60e1\u610f\u884c\u70ba\u3002\u9019\u4e9b\u4e8b\u4ef6\u7684\u89f8\u767c\u689d\u4ef6\u5305\u62ec\uff1a\u6642\u9593\u3001\u5145\u96fb\u6216\u96fb\u6c60\u72c0\u614b\u3001\u5730\u7406\u4f4d\u7f6e\u3001\u9023\u7dda\u72c0\u614b\u3001\u57f7\u884c\u4e2d\u7684 App\u3001\u53d6\u5f97\u7126\u9ede\u7684 App\u3001SIM \u5361\u72c0\u614b\u3001\u6536\u5230\u5305\u542b\u7279\u5b9a\u95dc\u9375\u5b57\u7684\u7c21\u8a0a\u4ee5\u53ca\u87a2\u5e55\u958b\u555f\u3002\n<ul>\n<li>\u5c31\u8a2d\u5b9a\u6a94\u4e2d\u7684\u5167\u5bb9\u4f86\u770b\uff0c\u67d0\u4e9b\u4e8b\u4ef6\u6703\u89f8\u767c\u4e0b\u5217\u52d5\u4f5c\uff1a\n<ol>\n<li>\u540c\u6b65\u8a2d\u5b9a\u8cc7\u6599\u3001\u5347\u7d1a\u6a21\u7d44\u3001\u4e0b\u8f09\u65b0\u7684\u60e1\u610f\u7a0b\u5f0f (\u900f\u904e ZProtocol \u50b3\u8f38\u5354\u5b9a\u4e26\u4f7f\u7528 AES\/CBC\/PKCS5Padding\u52a0\u5bc6\u4f86\u8207 C&amp;C \u4f3a\u670d\u5668\u901a\u8a0a)\u3002<\/li>\n<li>\u4e0a\u50b3\u53ca\u6e05\u9664\u8490\u96c6\u5230\u7684\u8b49\u64da\u3002<\/li>\n<li>\u91cd\u8a2d\u9396\u5b9a\u5bc6\u78bc\u4f86\u7834\u58de\u88dd\u7f6e\u3002<\/li>\n<li>\u57f7\u884c shell \u6307\u4ee4\u3002<\/li>\n<li>\u767c\u9001\u7279\u5b9a\u5167\u5bb9\u6216\u5730\u9ede\u7684\u7c21\u8a0a\u3002<\/li>\n<li>\u95dc\u9589\u7db2\u8def\u3002<\/li>\n<li>\u95dc\u9589 root\u3002<\/li>\n<li>\u89e3\u9664\u5b89\u88dd\u6bad\u5c4d\u7a0b\u5f0f\u3002<\/li>\n<\/ol>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>\u70ba\u4e86\u8eb2\u907f\u5075\u6e2c\u4e26\u9632\u6b62\u8a18\u61b6\u9ad4\u4e2d\u7684\u4ee3\u7406\u7a0b\u5f0f App \u906d\u5230\u79fb\u9664\uff0cRCSAndroid \u5957\u4ef6\u9084\u6703\u5075\u6e2c\u6a21\u64ec\u5668\u548c\u6c99\u76d2\u74b0\u5883\u3001\u5229\u7528 DexGuard \u5c07\u7a0b\u5f0f\u7de8\u78bc\u3001\u5229\u7528 ELF \u5b57\u4e32\u7de8\u78bc\u5668\uff0c\u4e26\u4e14\u7be1\u6539 OOM (\u8a18\u61b6\u9ad4\u4e0d\u8db3) \u72c0\u614b\u3002\u6709\u8da3\u7684\u662f\uff0c\u8a72 App \u7a0b\u5f0f\u9084\u6709\u4e00\u9805\u672a\u4f7f\u7528\u7684\u529f\u80fd\u662f\u7be1\u6539 Android \u5c01\u88dd\u7ba1\u7406\u54e1 (package manager) \u7684\u8cc7\u6599\u4f86\u65b0\u589e\u6216\u79fb\u9664\u67d0\u4e9b\u6b0a\u9650\u548c\u5143\u4ef6\u4e26\u96b1\u85cf App \u5716\u793a\u3002<\/p>\n<p><strong>\u5efa\u8b70<\/strong><\/p>\n<p>\u50cf Android \u9019\u6a23\u71b1\u9580\u7684\u884c\u52d5\u88dd\u7f6e\u5e73\u53f0\u4e00\u76f4\u662f\u7d44\u7e54\u6027\u6216\u5546\u696d\u6027\u9593\u8adc\u884c\u52d5\u7d93\u5e38\u9396\u5b9a\u7684\u76ee\u6a19\u3002\u99ed\u5ba2\u6df1\u77e5\uff0c\u5229\u7528\u60e1\u610f\u7a0b\u5f0f\u4f86\u653b\u64ca\u6f0f\u6d1e\u4e26\u7834\u89e3 (root) \u88dd\u7f6e\uff0c\u662f\u53d6\u5f97\u88dd\u7f6e\u63a7\u5236\u6b0a\u3001\u9032\u800c\u8490\u96c6\u8cc7\u8a0a\u7684\u6709\u6548\u65b9\u6cd5\u3002\u88dd\u7f6e\u4e00\u65e6\u7d93\u904e\u7834\u89e3\uff0c\u5c31\u7b49\u65bc\u6beb\u7121\u5b89\u5168\u6027\u53ef\u8a00\u3002<\/p>\n<p>\u8acb\u990a\u6210\u4e0b\u5217\u826f\u597d\u7fd2\u6163\u4f86\u9632\u6b62\u60a8\u7684\u88dd\u7f6e\u906d\u5230\u9019\u9805\u5a01\u8105\uff1a<\/p>\n<ul>\n<li>\u4e0d\u8981\u5141\u8a31\u5b89\u88dd\u4f86\u6e90\u4e0d\u660e\u7684\u61c9\u7528\u7a0b\u5f0f\u3002<\/li>\n<li>\u96a8\u6642\u66f4\u65b0\u5230\u6700\u65b0\u7684Android\u7248\u672c\u4ee5\u9632\u7bc4\u6f0f\u6d1e\uff0c\u5c24\u5176\uff0cRCSAndroid \u53ef\u5f71\u97ff\u7684\u6700\u9ad8\u7248\u672c\u70ba Android 4.4.4 KitKat\u3002\u4e0d\u904e\u8acb\u6ce8\u610f\uff0c\u6839\u64da Hacking Team \u5916\u6d29\u7684\u4e00\u5c01\u5ba2\u6236\u8a62\u554f\u96fb\u5b50\u90f5\u4ef6\uff0c\u8a72\u516c\u53f8\u6b63\u5728\u958b\u767c\u53ef\u5c0d\u61c9 Android 5.0 Lollipop \u7684\u7a0b\u5f0f\u78bc\u3002<\/li>\n<li>\u5b89\u88dd\u4e00\u5957\u884c\u52d5\u5b89\u5168\u9632\u8b77\u4f86\u4fdd\u8b77\u60a8\u7684\u88dd\u7f6e\u4e26\u9632\u7bc4\u5a01\u8105\u3002<\/li>\n<\/ul>\n<p>RCSAndroid \u7a0b\u5f0f\u78bc\u7684\u5916\u6d29\u5df2\u8b93\u5b83\u6210\u70ba\u4e00\u9805\u516c\u958b\u7684\u5546\u696d\u9593\u8adc\u5229\u5668\u3002\u884c\u52d5\u4f7f\u7528\u8005\u6700\u597d\u96a8\u6642\u638c\u63e1\u9019\u9805\u65b0\u805e\u7684\u6700\u65b0\u767c\u5c55\uff0c\u4e26\u4e14\u96a8\u6642\u7559\u610f\u88dd\u7f6e\u662f\u5426\u6709\u906d\u5230\u76e3\u807d\u7684\u8de1\u8c61\u3002\u53ef\u7591\u7684\u8de1\u8c61\u5305\u62ec\u7cfb\u7d71\u51fa\u73fe\u7570\u5e38\u884c\u70ba\uff0c\u4f8b\u5982\uff1a\u4e0d\u6b63\u5e38\u91cd\u65b0\u958b\u6a5f\u3001\u88dd\u7f6e\u4e0a\u51fa\u73fe\u4e00\u4e9b\u83ab\u540d\u5176\u5999\u7684\u61c9\u7528\u7a0b\u5f0f\u3001\u5373\u6642\u901a\u8a0a\u8edf\u9ad4\u7a81\u7136\u7576\u6389\u7b49\u7b49\u3002<\/p>\n<p>\u4e00\u65e6\u88dd\u7f6e\u906d\u5230\u611f\u67d3\uff0c\u9019\u500b\u5f8c\u9580\u7a0b\u5f0f\u5fc5\u9808\u6709\u7cfb\u7d71\u7ba1\u7406\u54e1 (root) \u6b0a\u9650\u624d\u80fd\u79fb\u9664\uff0c\u4f7f\u7528\u8005\u53ef\u80fd\u9700\u8981\u9001\u56de\u539f\u5ee0\u4f86\u8acb\u4ed6\u5011\u91cd\u5237\u97cc\u9ad4\u624d\u884c\u3002<\/p>\n<p>\u8da8\u52e2\u79d1\u6280\u7684\u5b89\u5168<a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=3382&amp;name=20141014\">\u8da8\u52e2\u79d1\u6280\u300c\u5b89\u5168\u9054\u4eba\u300d\u514d\u8cbb\u884c\u52d5\u9632\u8b77App<\/a>( <a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=3382&amp;name=20141014\">Android <\/a>\u00a0\/ <a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=3381&amp;name=20141014\">iOS <\/a>) <a href=\"https:\/\/www.trendmicro.com\/us\/home\/products\/mobile-solutions\/android-security\/\">Android\u2122 \u884c\u52d5\u5b89\u5168\u9632\u8b77<\/a> \u5373\u53ef\u9632\u7bc4\u9019\u985e\u653b\u64ca\u3002\u8acb\u53c3\u95b1\u6211\u5011\u300c<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/mobile-safety\/7-android-security-hacks-you-need-to-do-right-now\">\u4e03\u500b\u60a8\u61c9\u7acb\u5373\u63a1\u53d6\u7684 Android \u5b89\u5168\u63aa\u65bd (7 Android Security Hacks You Need to Do Right Now)<\/a>\u300d\u4e00\u6587\u4f86\u4fdd\u8b77\u884c\u52d5\u88dd\u7f6e\u7684\u8cc7\u6599\u5b89\u5168\u3002<\/p>\n<p>\u539f\u6587\u51fa\u8655\uff1a<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/hacking-team-rcsandroid-spying-tool-listens-to-calls-roots-devices-to-get-in\/\">Hacking Team RCSAndroid Spying Tool Listens to Calls; Roots Devices to Get In<\/a>| \u00a0\u00a0\u00a0\u4f5c\u8005\uff1a<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/author\/veozhang\/\">Veo Zhang (\u884c\u52d5\u88dd\u7f6e\u5a01\u8105\u5206\u6790\u5e2b)<\/a> \u4e0a\u5348 02:01 (UTC-7)\u00a0\u00a0 | \u00a0\u00a0\u00a0\u4f5c\u8005\uff1a<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/author\/veozhang\/\">Veo Zhang (\u884c\u52d5\u88dd\u7f6e\u5a01\u8105\u5206\u6790\u5e2b)<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>\u60f3\u4e86\u89e3\u66f4\u591a\u95dc\u65bc\u7db2\u8def\u5b89\u5168\u7684\u79d8\u8a23\u548c\u5efa\u8b70\uff0c\u53ea\u8981\u5230<a href=\"https:\/\/www.facebook.com\/trendmicrotaiwan\">\u8da8\u52e2\u79d1\u6280\u7c89\u7d72\u7db2\u9801<\/a> \u6216\u4e0b\u9762\u7684\u6309\u9215\u6309\u8b9a<\/p>\n<p><iframe loading=\"lazy\" style=\"border: none; overflow: hidden; width: 350px; height: 62px;\" src=\"https:\/\/www.facebook.com\/plugins\/likebox.php?id=255176705131&amp;width=350&amp;connections=0&amp;stream=false&amp;header=false&amp;height=62\" width=\"300\" height=\"150\" frameborder=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p><span style=\"color: red;\"><b>\u300a\u63d0\u9192\u300b<\/b><\/span>\u5728\u7c89\u7d72\u9801\u6a6b\u5e45,\u8b9a\u7684\u53f3\u908a\u4e09\u89d2\u5f62\u9078\u64c7<strong>\u63a5\u6536\u901a\u77e5<\/strong>\u548c<strong>\u65b0\u589e\u5230\u8208\u8da3\u4e3b\u984c\u6e05\u55ae<\/strong>,\u91cd\u8981\u901a\u77e5\u8207\u597d\u5eb7\u4e0d\u6f0f\u63a5<\/p>\n<p>\u60f3\u4e86\u89e3\u66f4\u591a\u95dc\u65bc\u7db2\u8def\u5b89\u5168\u7684\u79d8\u8a23\u548c\u5efa\u8b70\uff0c\u53ea\u8981\u5230<a href=\"https:\/\/www.facebook.com\/trendmicrotaiwan\">\u8da8\u52e2\u79d1\u6280\u7c89\u7d72\u7db2\u9801<\/a> \u6216\u4e0b\u9762\u7684\u6309\u9215\u6309\u8b9a<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>RCSAndroid \u7a0b\u5f0f\u78bc\u7684\u5916\u6d29\u5df2\u8b93\u5b83\u6210\u70ba\u4e00\u9805\u516c\u958b\u7684\u5546\u696d\u9593\u8adc\u5229\u5668\u3002\u884c\u52d5\u4f7f\u7528\u8005\u6700\u597d\u96a8\u6642\u638c\u63e1\u9019\u9805\u65b0\u805e\u7684\u6700\u65b0\u767c\u5c55\uff0c [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wpscppro_dont_share_socialmedia":false,"_wpscppro_custom_social_share_image":0,"_facebook_share_type":"","_twitter_share_type":"","_linkedin_share_type":"","_pinterest_share_type":"","_linkedin_share_type_page":"","_instagram_share_type":"","_medium_share_type":"","_threads_share_type":"","_google_business_share_type":"","_selected_social_profile":[],"_wpsp_enable_custom_social_template":false,"_wpsp_social_scheduling":{"enabled":false,"datetime":null,"platforms":[],"status":"template_only","dateOption":"today","timeOption":"now","customDays":"","customHours":"","customDate":"","customTime":"","schedulingType":"absolute"},"_wpsp_active_default_template":true},"categories":[2197,15,156,8,179],"tags":[2274,2187,2198,2215,2214,152],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/13375"}],"collection":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=13375"}],"version-history":[{"count":0,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/13375\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=13375"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=13375"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=13375"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}