{"id":62707,"date":"2019-11-25T09:00:50","date_gmt":"2019-11-25T01:00:50","guid":{"rendered":"https:\/\/blog.trendmicro.com.tw\/?p=62707"},"modified":"2019-11-25T14:50:15","modified_gmt":"2019-11-25T06:50:15","slug":"%e9%87%9d%e5%b0%8d%e9%9f%93%e5%9c%8b%e4%bd%bf%e7%94%a8%e8%80%85%e7%9a%84mac%e5%be%8c%e9%96%80%e7%a8%8b%e5%bc%8f","status":"publish","type":"post","link":"https:\/\/blog.trendmicro.com.tw\/?p=62707","title":{"rendered":"\u91dd\u5c0d\u97d3\u570b\u4f7f\u7528\u8005\u7684Mac\u5f8c\u9580\u7a0b\u5f0f"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignleft\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Targeted-attacks-200x200.jpg\" alt=\"\"\/><\/figure><\/div>\n\n\n\n<p>\u72af\u7f6a\u5206\u5b50\u5c0dMacOS\u7684\u8208\u8da3\u8d8a\u4f86\u8d8a\u9ad8\uff0c\u75c5\u6bd2\u4f5c\u8005\u4e0d\u65b7\u5730\u958b\u767c\u66f4\u591a\u653b\u64ca\u71b1\u9580\u4f5c\u696d\u7cfb\u7d71\u7684<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/mac-malware-that-spoofs-trading-app-steals-user-information-uploads-it-to-website\/\">\u60e1\u610f\u5a01\u8105<\/a>\u3002\u4e4b\u524d\u88ab\u767c\u73fe\u4f7f\u7528\u5167\u5d4c\u5de8\u96c6\u7684Microsoft\nExcel\u6a94\u6848\u4f86\u653b\u64ca\u97d3\u570b\u4f7f\u7528\u8005\u7684\u7db2\u8def\u72af\u7f6a\u7d44\u7e54Lazarus,\u8fd1\u65e5\u958b\u59cb\u6563\u64ad\u65b0Mac\u5f8c\u9580\u7a0b\u5f0f\uff08\u8da8\u52e2\u79d1\u6280\u5075\u6e2c\u70baBackdoor.MacOS.NUKESPED.A\uff09\uff0c <\/p>\n\n\n\n<p>\u5ef6\u4f38\u95b1\u8b80:<\/p>\n\n\n\n<table  class=\"wp-block-table is-style-stripes table table-hover\" ><tbody><tr><td><strong> \u5ef6\u4f38\u95b1\u8b80:<\/strong><br><a href=\"https:\/\/blog.trendmicro.com.tw\/?p=62115\">\u507d\u88dd\u6210\u80a1\u7968\u4ea4\u6613\u8edf\u9ad4 Stockfolio \u7aca\u500b\u8cc7\u7684 Mac \u60e1\u610f\u61c9\u7528\u7a0b\u5f0f<\/a> <\/td><\/tr><\/tbody><\/table>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u8207 Lazarus \u524d\u5e7e\u4ee3\u7684\u76f8\u4f3c\u4e4b\u8655<\/strong><\/h4>\n\n\n\n<p><a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2651&amp;name=20110916\">\u8da8\u52e2\u79d1\u6280<\/a>\u5206\u6790\u4e86\u4e00\u500b\u7531Twitter\u4f7f\u7528\u8005cyberwar_15\u6240<a href=\"https:\/\/twitter.com\/cyberwar_15\/status\/1186612111717191680\">\u767c\u73fe<\/a>\u7684\u60e1\u610f\u6a23\u672c\uff0c\u767c\u73fe\u8a72\u6a23\u672c\u4f7f\u7528\u4e86\u5167\u5d4c\u5de8\u96c6\u7684Excel\u6587\u4ef6\uff0c\u9019\u985e\u4f3c\u65bcLazarus\u96c6\u5718<a href=\"https:\/\/www.sentinelone.com\/blog\/lazarus-apt-targets-mac-users-poisoned-word-document\/\">\u4e4b\u524d<\/a>\u7684\u653b\u64ca\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_1_mac_lazarus.jpg\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_1_mac_lazarus.jpg\"\/><\/figure>\n\n\n\n<p>\u57161. \u8a66\u7b97\u8868\u51fa\u73fe\u4e00\u500b\u6709\u540d\u7684\u5fc3\u7406\u6e2c\u9a57\uff08\u985e\u4f3c<a href=\"https:\/\/webcache.googleusercontent.com\/search?q=cache:https:\/\/m.blog.naver.com\/wonderwallsoft\/220795786443\">\u9019\u88e1<\/a>\u627e\u5230\u7684\u6e2c\u9a57\uff09\u3002\u6309\u4e0b\u5de6\u4e0a\u65b9\u7684\u7b11\u81c9\u6703\u6839\u64da\u4f7f\u7528\u8005\u7b54\u6848\u51fa\u73fe\u4e0d\u540c\u56de\u61c9\u3002<\/p>\n\n\n\n<!--more-->\n\n\n\n<p>\u4f46\u4e0d\u540c\u65bc\u4e4b\u524d\u7684\u653b\u64ca\u6703\u6839\u64da\u57f7\u884c\u8a66\u7b97\u8868\u7684\u4f5c\u696d\u7cfb\u7d71\u4e0d\u540c\u800c\u9032\u884c\u4e0d\u540c\u52d5\u4f5c\uff0c\u8a72\u6a94\u6848\u5167\u7684\u5de8\u96c6\u53ea\u6703\u57f7\u884c\u4e00\u500bPowerShell\u8173\u672c\u4f86\u9023\u5230\u99ed\u5ba2\u96c6\u5718\u6240\u8a2d\u7f6e\u7684\u4e09\u53f0C&amp;C\u4f3a\u670d\u5668\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_2_mac_lazarus.jpg\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_2_mac_lazarus.jpg\"\/><\/figure>\n\n\n\n<p>\u57162. \u5de8\u96c6\u6a94\u6848\u6703\u9023\u5230hxxps[:]\/\/crabbedly[.]club\/board[.]php\uff0chxxps[:]\/\/craypot[.]live\/board[.]php\u548chxxps[:]\/\/indagator[.]club\/board[.]php\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_3_mac_lazarus.jpg\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_3_mac_lazarus.jpg\"\/><\/figure>\n\n\n\n<p>\u57163. <a href=\"https:\/\/www.sentinelone.com\/blog\/lazarus-apt-targets-mac-users-poisoned-word-document\/\">SentinelOne<\/a>\u5728\u4e0a\u8ff0\u4e4b\u524d\u653b\u64ca\u6240\u64f7\u53d6\u7684\u60e1\u610f\u5de8\u96c6\u7a0b\u5f0f\u78bc\u7247\u6bb5\uff08\u5de6\uff09\u8207\u6700\u8fd1\u767c\u73fe\u60e1\u610f\u5de8\u96c6\u7a0b\u5f0f\u78bc\u7247\u6bb5\uff08\u53f3\uff09\u7684\u6bd4\u8f03\u3002\u5f8c\u8005\u986f\u793a\u51fa\u5982\u679c\u5728Mac\u5e73\u53f0\u4e0a\u57f7\u884c\u5c07\u4e0d\u6703\u9032\u884c\u4efb\u4f55\u52d5\u4f5c\u3002\u9019\u6b21\u91dd\u5c0dMacOS\u7684#If Mac Then\u653b\u64ca\u4e26\u975e\u5f9e\u60e1\u610f\u5de8\u96c6\u555f\u52d5\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Mac<\/strong><strong>\u61c9\u7528\u7a0b\u5f0f\u5167\u5305\u542b\u4e86\u60e1\u610f\u53ca\u6b63\u5e38\u7684Flash\nPlayer<\/strong><\/h4>\n\n\n\n<p>\u9664\u4e86\u5206\u6790\u7684\u6a23\u672c\u5916\uff0c@cyberwar_15\u53ca<a href=\"https:\/\/twitter.com\/RedDrip7\/status\/1186562944311517184\">Qianxin\nTechnology<\/a>\u9084\u53d6\u5f97\u4e86\u7591\u4f3c\u8207\u8a72\u653b\u64ca\u6709\u95dc\u7684Mac\u61c9\u7528\u7a0b\u5f0f\uff0c\u56e0\u70ba\u5b83\u8207\u60e1\u610f\u8a66\u7b97\u8868\u5171\u7528\u985e\u4f3c\u7684C&amp;C\u4f3a\u670d\u5668\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_4_mac_lazarus.jpg\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_4_mac_lazarus.jpg\"\/><\/figure>\n\n\n\n<p>\u57164. \u6240\u767c\u73fe\u6a23\u672c\u5167\u7684Mac\u61c9\u7528\u7a0b\u5f0f<\/p>\n\n\n\n<p>\u4f46\u9019\u53ea\u662f\u500b\u8a98\u990c\u7a0b\u5f0f\uff0c\u771f\u6b63\u7684Adobe Flash Player\u662f\u88e1\u9762\u8a2d\u70ba\u96b1\u85cf\u7684Mach-O\u6a94\u6848\u3002\u8a72\u61c9\u7528\u7a0b\u5f0f\u5167\u6709\u5169\u500bFlash Player\u6a94\u6848\uff1a\u4e00\u500b\u6b63\u5e38\u7248\u672c\u548c\u4e00\u500b\u60e1\u610f\u7248\u672c\uff08Trojan.MacOS.NUKESPED.B\uff09\u3002\u57f7\u884c\u6642\u6703\u4ee5\u8f03\u5c0f\u7684Flash\nPlayer\u4f5c\u70ba\u4e3b\u8981\u57f7\u884c\u6a94\uff0c\u9019\u662f\u500b\u540d\u7a31\u986f\u793a\u70baFlash Player\u7684\u60e1\u610f\u8edf\u9ad4\u3002\u5b83\u9084\u6703\u57f7\u884c\u6b63\u5e38\u7684Flash Player\u4f86\u63a9\u84cb\u5176\u5be6\u969b\u60e1\u610f\u884c\u70ba\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/FIgure_5_mac_lazarus.jpg\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/FIgure_5_mac_lazarus.jpg\"\/><\/figure>\n\n\n\n<p>\u57165. \u61c9\u7528\u7a0b\u5f0f\u5167\u542b\u5169\u500bFlash Player\u6a94\u6848\uff0c\u4e00\u500b\u6b63\u5e38\u7248\u672c\u548c\u4e00\u500b\u60e1\u610f\u7248\u672c\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_6_mac_lazarus.jpg\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_6_mac_lazarus.jpg\"\/><\/figure>\n\n\n\n<p>\u57166. \u4ed4\u7d30\u67e5\u770b\u61c9\u7528\u7a0b\u5f0f\u6703\u767c\u73fe\u8a72Flash\nPlayer\u61c9\u7528\u7a0b\u5f0f\u662f\u7531\u4e00\u500b\u540d\u53ebOleg Krasilnikov\u7684\u4eba\u6240\u958b\u767c\uff0c\u8207Adobe Inc.\u7121\u95dc\u3002<\/p>\n\n\n\n<p>\u57f7\u884cMac\u61c9\u7528\u7a0b\u5f0f\u6642\uff0c\u60e1\u610fFlash Player\u6703\u57f7\u884c\u6b63\u5e38\u7684Flash Player\u4f86\u64ad\u653e\u4f5c\u70ba\u8a98\u990c\u7684SWF\u5f71\u7247\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_7_mac_lazarus.jpg\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_7_mac_lazarus.jpg\"\/><\/figure>\n\n\n\n<p>\u57167. SWF\u5f71\u7247\u6703\u986f\u793a\u5716\u7247\u5408\u96c6\u53ca\u5728\u80cc\u666f\u64ad\u653e\u97d3\u6587\u6b4c\u3002<\/p>\n\n\n\n<p>\u7d93\u904e\u6a23\u672c\u5206\u6790\u5f8c\u986f\u793a\u5728\u5f71\u7247\u64ad\u653e\u6642\uff0c\u60e1\u610fFlash Player\u6703\u5efa\u7acb\u53e6\u4e00\u500b\u96b1\u85cf\u6a94\u6848<em>~\/.FlashUpdateCheck<\/em>\uff08Backdoor.MacOS.NUKESPED.A\uff09\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_8_mac_lazarus.jpg\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_8_mac_lazarus.jpg\"\/><\/figure>\n\n\n\n<p>\u57168. \u60e1\u610fFlash Player\u5728\u6b63\u5e38Flash Player\u64ad\u653e\u5f71\u7247\u6642\u5efa\u7acb\u4e00\u500b\u96b1\u85cf\u6a94\u6848<em>~\/.FlashUpdateCheck<\/em>\u3002\u6ce8\u610f\uff1a\u7b26\u865f\uff08~\uff09\u4ee3\u8868\u7576\u524d\u4f7f\u7528\u8005\u7684\u8def\u5f91\u3002<\/p>\n\n\n\n<p>\u63a5\u8457\u6703\u690d\u5165PLIST\u6a94\u6848<em>~\/Library\/Launchagents\/com.adobe.macromedia.plist<\/em>\u4f86\u5efa\u7acb\u6b64\u96b1\u85cf\u6a94\u6848\u7684\u6301\u7e8c\u6027\u6a5f\u5236\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_9_mac_lazarus.jpg\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_9_mac_lazarus.jpg\"\/><\/figure>\n\n\n\n<p>\u57169. \u690d\u5165~\/Library\/Launchagents\/com.adobe.macromedia.plist\u7684\u7a0b\u5f0f\u78bc\u7247\u6bb5\u3002\u96b1\u85cf\u6a94~\/.FlashUpdateCheck\u88ab\u8a2d\u6210\u70ba\u5176\u81ea\u52d5\u57f7\u884c\u76ee\u6a19\u3002<\/p>\n\n\n\n<p>\u9032\u4e00\u6b65\u6aa2\u67e5\u986f\u793a\uff0c\u96b1\u85cf\u6a94~\/.FlashUpdateCheck\u5177\u5099\u8ddf\u5167\u5d4cMacro\u6587\u4ef6\u7684Powershell\u8173\u672c\u6709\u540c\u6a23\u7684\u6548\u679c\u3002\u6211\u5011\u78ba\u8a8d\u4e86\u8207\u4e0b\u5217\u4f3a\u670d\u5668\u9032\u884cC&amp;C\u901a\u8a0a\u7684\u76f8\u95dc\u529f\u80fd\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_10_mac_lazarus.jpg\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_10_mac_lazarus.jpg\"\/><\/figure>\n\n\n\n<p>\u571610. \u4f4d\u65bc\u96b1\u85cf\u6a94_DATA\u5340\u6bb5\u5167\u7684C&amp;C\u4f3a\u670d\u5668<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u60e1\u610f\u8edf\u9ad4\u7684\u5f8c\u9580\u529f\u80fd<\/strong><\/h4>\n\n\n\n<p>\u8981\u89f8\u767cBackdoor.MacOS.NUKESPED.A\u7684\u5f8c\u9580\u529f\u80fd\uff0c\u9996\u5148\u5fc5\u9808\u5148\u8ddf\u4e0a\u8ff0\u7684\u4f3a\u670d\u5668\u5efa\u7acb\u9023\u7dda\uff0ccraypot[.]live\u6392\u5728\u7b2c\u4e00\u4f4d\u3002\u9023\u7dda\u6210\u529f\u5f8c\u6703\u7e7c\u7e8c\u57f7\u884c\u5be6\u969b\u7684\u5f8c\u9580\u884c\u70ba\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_11_mac_lazarus.jpg\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_11_mac_lazarus.jpg\"\/><\/figure>\n\n\n\n<p>\u571611. \u5728\u6b64\u52d5\u4f5c\u4e2d\uff0c\u6a94\u6848\u6703\u8a55\u4f30\u4f3a\u670d\u5668\u56de\u61c9\u4e26\u6839\u64da\u6536\u5230\u7684\u547d\u4ee4\u865f\u78bc\u57f7\u884c\u7279\u5b9a\u51fd\u6578\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_12_mac_lazarus.jpg\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_12_mac_lazarus.jpg\"\/><\/figure>\n\n\n\n<p>\u571612. \u5f8c\u9580\u51fd\u657811\u300112\u548c14\u7684\u53cd\u7d44\u8b6f\u865b\u64ec\u78bc<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_13_mac_lazarus.jpg\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_13_mac_lazarus.jpg\"\/><\/figure>\n\n\n\n<p>\u571613. \u5f8c\u9580\u51fd\u657818\u300119\u300120\u300121\u300124\u548c25\u7684\u53cd\u7d44\u8b6f\u865b\u64ec\u78bc<\/p>\n\n\n\n<table  class=\"wp-block-table table table-hover\" ><tbody><tr><td>\n  <strong>\u5f8c\u9580\u5207\u63db\u547d\u4ee4<\/strong>\n  <\/td><td>\n  <strong>\u529f\u80fd<\/strong>\n  <\/td><\/tr><tr><td>\n  2\n  <\/td><td>\n  \u8a2d\u5b9a\u7761\u7720\n  <\/td><\/tr><tr><td>\n  3\n  <\/td><td>\n  \u7d42\u6b62\u7a0b\u5e8f\n  <\/td><\/tr><tr><td>\n  11\n  <\/td><td>\n  \u53d6\u5f97\u4e3b\u6a5f\u8cc7\u8a0a\n  <\/td><\/tr><tr><td>\n  12, 14\n  <\/td><td>\n  \u6aa2\u67e5\u76ee\u524d\u5f8c\u9580\u8a2d\u5b9a\n  <\/td><\/tr><tr><td>\n  15\n  <\/td><td>\n  \u66f4\u65b0C2\u548c\u5f8c\u9580\u8a2d\u5b9a\n  <\/td><\/tr><tr><td>\n  18, 19\n  <\/td><td>\n  \u57f7\u884cShell\u547d\u4ee4\n  <\/td><\/tr><tr><td>\n  20\n  <\/td><td>\n  \u4e0a\u50b3\u6a94\u6848\n  <\/td><\/tr><tr><td>\n  21\n  <\/td><td>\n  \u4e0b\u8f09\u6a94\u6848\n  <\/td><\/tr><tr><td>\n  24, 25\n  <\/td><td>\n  \u76f4\u63a5\u57f7\u884c\u56de\u61c9\n  <\/td><\/tr><\/tbody><\/table>\n\n\n\n<p>\u88681. Backdoor.MacOS.NUKESPED.A\u7684\u5b8c\u6574\u5f8c\u9580\u529f\u80fd<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_14_mac_lazarus.jpg\" alt=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Figure_14_mac_lazarus.jpg\"\/><\/figure>\n\n\n\n<p>\u571614. MacOS\u96b1\u85cf\u6a94\u5177\u5099\u8ddfExcel\u6a23\u672c\u5167\u96b1\u85cfPowerShell\u8173\u672c\u985e\u4f3c\u7684\u5f8c\u9580\u529f\u80fd\uff08\u4f8b\u5982\uff0c\u5169\u8005\u7684\u547d\u4ee411\u90fd\u662fGetHostInfo\u51fd\u6578\uff09\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u7d50\u8ad6<\/strong><\/h4>\n\n\n\n<p>\u8207Lazarus\u65e9\u671f\u5229\u7528\u5de8\u96c6\u4e0b\u8f09\u5f8c\u9580Mac\u6a94\u6848\u7684\u4f5c\u6cd5\u4e0d\u540c\uff0c\u6211\u5011\u5206\u6790\u7684\u6a23\u672c\u986f\u793a\u51fa\u6b64\u6b21\u653b\u64ca\u6703\u4f7f\u7528\u5e36\u6709\u8a98\u990c\u7684\u61c9\u7528\u7a0b\u5f0f\uff0c\u518d\u540c\u6642\u904b\u884c\u60e1\u610f\u7a0b\u5f0f\u4f86\u5206\u9694\u6574\u500bMac\u653b\u64ca\u93c8\u3002<\/p>\n\n\n\n<p>\u985e\u4f3cLazarus\u9019\u6a23\u7684\u7db2\u8def\u72af\u7f6a\u96c6\u5718\u6b63\u5728\u91dd\u5c0d\u4e0d\u540c\u5e73\u53f0\u4f86\u64f4\u5927\u5176\u653b\u64ca\u7bc4\u570d\u3002Lazarus\u96c6\u5718\u5f9e\u4f7f\u7528\u55ae\u4e00\u8de8\u5e73\u53f0\u4f5c\u6cd5\u555f\u52d5\u653b\u64ca\u93c8\u8f49\u5411\u6703\u91dd\u5c0d\u4e0d\u540cOS\u4f86\u88fd\u4f5c\u60e1\u610f\u8edf\u9ad4\uff0c\u9019\u662f\u4ef6\u503c\u5f97\u6ce8\u610f\u7684\u4e8b\u60c5\uff0c\u4e5f\u662f\u5728\u672a\u4f86\u985e\u4f3c\u6848\u4ef6\u4e2d\u6240\u80fd\u5920\u9810\u671f\u770b\u5230\u7684\u4e8b\u60c5\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u5b89\u5168\u5efa\u8b70<\/strong><\/h4>\n\n\n\n<p>\u70ba\u4e86\u907f\u514d\u906d\u53d7Backdoor.MacOS.NUKESPED.A\u76f8\u95dc\u7684\u653b\u64ca\uff0c\u4f7f\u7528\u8005\u61c9\u8a72\u53ea\u5f9e\u5b98\u65b9\u4f86\u6e90\u4e0b\u8f09\u61c9\u7528\u7a0b\u5f0f\u3002\u9019\u7a2e\u505a\u6cd5\u96d6\u7c21\u55ae\u537b\u53ef\u4ee5\u5927\u5927\u6e1b\u4f4e\u4e0b\u8f09\u5230\u60e1\u610f\u61c9\u7528\u7a0b\u5f0f\u7684\u6a5f\u6703\u3002\u4f7f\u7528\u8005\u9084\u53ef\u4ee5\u5229\u7528<a href=\"https:\/\/t.rend.tw\/?i=ODAzMw\">\u8da8\u52e2\u79d1\u6280PC-cillin for Mac<\/a>\u9019\u6a23\u7684\u5b89\u5168\u89e3\u6c7a\u65b9\u6848\uff0c\u5b83\u53ef\u4ee5\u4fdd\u8b77\u591a\u500b\u88dd\u7f6e\uff0c\u540c\u6642\u63d0\u4f9b\u5168\u9762\u6027\u7684\u5b89\u5168\u9632\u8b77\u4f86\u62b5\u79a6\u7db2\u8def\u5a01\u8105\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/t.rend.tw\/?i=ODAzMw\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2015\/08\/Windows10Banner-540x90v5.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>\u5c0d\u65bc\u4f01\u696d\u800c\u8a00\uff0c\u53ef\u4ee5\u63a1\u7528\u5177\u5099XGen\u5b89\u5168\u9632\u8b77\u6280\u8853\u7684\u8da8\u52e2\u79d1\u6280<a href=\"https:\/\/www.trendmicro.tw\/tw\/business\/complete-software-protection\/index.html\">Smart Protection\nNetwork&#x2122;<\/a>\uff0c\u5b83\u878d\u5408\u4e86\u9ad8\u4fdd\u771f<a href=\"https:\/\/blog.trendmicro.com.tw\/?p=55169\">\u6a5f\u5668\u5b78\u7fd2(Machine learning,ML)<\/a>\u8207\u5a01\u8105\u9632\u8b77\u6280\u8853\u4f86\u6d88\u9664\u4f7f\u7528\u8005\u6d3b\u52d5\u6216\u7aef\u9ede\u9593\u7684\u5b89\u5168\u6f0f\u6d1e\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u5165\u4fb5\u6307\u6a19\uff08IoC<\/strong><strong>\uff09<\/strong><\/h4>\n\n\n\n<table  class=\"wp-block-table table table-hover\" ><tbody><tr><td>\n  \u6a94\u6848\n  <\/td><td>\n  SHA256\n  <\/td><td>\n  \u5075\u6e2c\u540d\u7a31\n  <\/td><\/tr><tr><td>\n  Album.app\n  <\/td><td>\n  d91c233b2f1177357387c29d92bd3f29fab7b90760e59a893a0f447ef2cb4715\n  <\/td><td>\n  Trojan.MacOS.NUKESPED.B\n  <\/td><\/tr><tr><td>\n  Flash\n  Player\n  <\/td><td>\n  735365ef9aa6cca946cfef9a4b85f68e7f9f03011da0cf5f5ab517a381e40d02\n  <\/td><td>\n  Trojan.MacOS.NUKESPED.B\n  <\/td><\/tr><tr><td>\n  .FlashUpdateCheck\n  <\/td><td>\n  6f7a5f1d52d3bfc6f175bf2bbb665e4bd99b0453e2d2e27712fe9b71c55962dc\n  <\/td><td>\n  Backdoor.MacOS.NUKESPED.A\n  <\/td><\/tr><\/tbody><\/table>\n\n\n\n<p>@\u539f\u6587\u51fa\u8655\uff1a<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/mac-backdoor-linked-to-lazarus-targets-korean-users\/\">Mac Backdoor Linked to Lazarus Targets Korean Users<\/a> \u4f5c\u8005\uff1aGabrielle Joyce Mabutas<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u72af\u7f6a\u5206\u5b50\u5c0dMacOS\u7684\u8208\u8da3\u8d8a\u4f86\u8d8a\u9ad8\uff0c\u75c5\u6bd2\u4f5c\u8005\u4e0d\u65b7\u5730\u958b\u767c\u66f4\u591a\u653b\u64ca\u71b1\u9580\u4f5c\u696d\u7cfb\u7d71\u7684\u60e1\u610f\u5a01\u8105\u3002\u4e4b\u524d\u88ab\u767c\u73fe\u4f7f\u7528\u5167\u5d4c\u5de8\u96c6\u7684 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wpscppro_dont_share_socialmedia":false,"_wpscppro_custom_social_share_image":0,"_facebook_share_type":"","_twitter_share_type":"","_linkedin_share_type":"","_pinterest_share_type":"","_linkedin_share_type_page":"","_instagram_share_type":"","_medium_share_type":"","_threads_share_type":"","_google_business_share_type":"","_selected_social_profile":[],"_wpsp_enable_custom_social_template":false,"_wpsp_social_scheduling":{"enabled":false,"datetime":null,"platforms":[],"status":"template_only","dateOption":"today","timeOption":"now","customDays":"","customHours":"","customDate":"","customTime":"","schedulingType":"absolute"},"_wpsp_active_default_template":true},"categories":[3943,378,398,1],"tags":[351,223,381,2149],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/62707"}],"collection":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=62707"}],"version-history":[{"count":0,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/62707\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=62707"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=62707"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=62707"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}