{"id":64859,"date":"2020-06-17T09:00:00","date_gmt":"2020-06-17T01:00:00","guid":{"rendered":"https:\/\/blog.trendmicro.com.tw\/?p=64859"},"modified":"2020-06-16T11:32:52","modified_gmt":"2020-06-16T03:32:52","slug":"android-%e9%96%93%e8%ab%9c%e8%bb%9f%e9%ab%94actionspy-%e7%94%a8%e6%96%b0%e8%81%9e%e7%b6%b2%e9%a0%81%e7%82%ba%e9%a4%8c%e9%80%b2%e8%a1%8c%e6%bc%8f%e6%b4%9e%e6%94%bb%e6%93%8a","status":"publish","type":"post","link":"https:\/\/blog.trendmicro.com.tw\/?p=64859","title":{"rendered":"Android \u9593\u8adc\u8edf\u9ad4ActionSpy, \u7528\u65b0\u805e\u7db2\u9801\u70ba\u990c\u9032\u884c\u6f0f\u6d1e\u653b\u64ca"},"content":{"rendered":"\n<div class=\"wp-block-image\"><figure class=\"alignright size-large\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/11\/Mobile-200x125.jpg\" alt=\"\"\/><\/figure><\/div>\n\n\n\n<p>\u5728\u8ffd\u8e2aEarth Empura\uff08\u4e5f\u88ab\u7a31\u70ba<a href=\"https:\/\/citizenlab.ca\/2019\/09\/poison-carp-tibetan-groups-targeted-with-1-click-mobile-exploits\/\">POISON CARP<\/a>\/<a href=\"https:\/\/www.volexity.com\/blog\/2019\/09\/02\/digital-crackdown-large-scale-surveillance-and-exploitation-of-uyghurs\/\">Evil Eye<\/a>\uff09\u6642\uff0c<a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2651&amp;name=20110916\">\u8da8\u52e2\u79d1\u6280<\/a>\u767c\u73fe\u4e86\u4e00\u500b\u672a\u88ab\u8a18\u9304\u904e\u7684Android\u9593\u8adc\u8edf\u9ad4\u4e26\u547d\u540d\u70baActionSpy\uff08\u8da8\u52e2\u79d1\u6280\u5075\u6e2c\u70baAndroidOS_ActionSpy.HRX\uff09\u3002\u57282020\u5e74\u7b2c\u4e00\u5b63\uff0c\u6211\u5011\u89c0\u5bdf\u5230Earth Empusa\u99ed\u5ba2\u96c6\u5718\u91dd\u5c0d\u897f\u85cf\u548c\u571f\u8033\u5176\u4f7f\u7528\u8005\u7684\u653b\u64ca\u6d3b\u52d5\uff0c\u7136\u5f8c\u53c8\u5c07\u89f8\u624b\u4f38\u5230\u4e86\u53f0\u7063\u3002\u64da\u5831\u4ed6\u5011\u7684\u653b\u64ca\u6d3b\u52d5\u662f\u900f\u904e\u5165\u4fb5Android\u548ciOS\u884c\u52d5\u88dd\u7f6e\u4f86\u91dd\u5c0d\u7dad\u543e\u723e\u65cf\u76f8\u95dc\u53d7\u5bb3\u8005\u3002\u9019\u500b\u99ed\u5ba2\u96c6\u5718\u5df2\u77e5\u6703\u4f7f\u7528<a href=\"https:\/\/blog.trendmicro.com.tw\/?p=4350\">\u6c34\u5751\u653b\u64ca<\/a>\uff0c\u4f46\u6700\u8fd1\u6211\u5011\u4e5f\u89c0\u5bdf\u5230\u4ed6\u5011\u7528<a href=\"https:\/\/blog.trendmicro.com.tw\/?p=136\">\u7db2\u8def\u91e3\u9b5a(Phishing)<\/a>\u653b\u64ca\u4f86\u6563\u64ad\u60e1\u610f\u8edf\u9ad4\u3002<\/p>\n\n\n\n<p>\u7528\u4f86\u611f\u67d3\u884c\u52d5\u88dd\u7f6e\u7684\u60e1\u610f\u8edf\u9ad4\u88ab\u767c\u73fe\u8207<a href=\"https:\/\/googleprojectzero.blogspot.com\/2019\/08\/a-very-deep-dive-into-ios-exploit.html\">2016\u5e74<\/a>\u4ee5\u4f86\u4e00\u9023\u4e32\u7684iOS\u6f0f\u6d1e\u653b\u64ca\u93c8\u653b\u64ca\u6709\u95dc\u3002\u57282020\u5e744\u6708\uff0c\u6211\u5011\u6ce8\u610f\u5230\u4e00\u500b\u91e3\u9b5a\u7db2\u9801\u507d\u88dd\u6210\u4e00\u6b3e\u897f\u85cfAndroid\u71b1\u9580\u5f71\u7247\u61c9\u7528\u7a0b\u5f0f\u7684\u4e0b\u8f09\u9801\u9762\u3002\u9019\u91e3\u9b5a\u7db2\u9801\u770b\u8d77\u4f86\u662f\u62f7\u8c9d\u81ea\u7b2c\u4e09\u65b9\u7db2\u8def\u5546\u5e97\uff0c\u53ef\u80fd\u662f\u7531Earth Empusa\u5efa\u7acb\u3002\u6703\u9019\u6a23\u63a8\u8ad6\u7684\u539f\u56e0\u662f\u7db2\u9801\u6ce8\u5165\u7684\u60e1\u610f\u8173\u672c\u4e4b\u4e00\u8a17\u7ba1\u5728\u8a72\u99ed\u5ba2\u96c6\u5718\u6240\u6709\u7684\u7db2\u57df\u3002\u6211\u5011\u5728\u6aa2\u67e5\u4e0b\u8f09\u7684Android\u61c9\u7528\u7a0b\u5f0f\u5f8c\u767c\u73fe\u4e86ActionSpy\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-01.png\" alt=\"\"\/><figcaption><em>\u57161. Earth Empusa\u653b\u64ca\u93c8<\/em><\/figcaption><\/figure>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u5f9e\u56db\u500b\u5373\u6642\u901a\u61c9\u7528\u7a0b\u5f0f\u6536\u96c6\u804a\u5929\u7d00\u9304\u4ee5\u76e3\u807d\u8a0a\u606f<\/strong><strong><\/strong><\/h3>\n\n\n\n<p><br>ActionSpy\u53ef\u80fd\u5f9e2017\u5e74\u958b\u59cb\u5c31\u5df2\u7d93\u5b58\u5728\uff0c\u9019\u662f\u500b\u80fd\u5920\u8b93\u653b\u64ca\u8005\u5f9e\u53d7\u611f\u67d3\u88dd\u7f6e\u6536\u96c6\u8cc7\u8a0a\u7684Android\u9593\u8adc\u8edf\u9ad4\u3002\u5b83\u9084\u5177\u5099\u4e00\u500b\u6a21\u7d44\u4f86\u7528<a href=\"https:\/\/developer.android.com\/guide\/topics\/ui\/accessibility\">Android\u7121\u969c\u7919\u529f\u80fd<\/a>\u5f9e\u56db\u500b\u5373\u6642\u901a\u61c9\u7528\u7a0b\u5f0f\u6536\u96c6\u804a\u5929\u7d00\u9304\u4ee5\u76e3\u807d\u5373\u6642\u901a\u8a0a\u606f\u3002<\/p>\n\n\n\n<p>Earth Empusa\u4f7f\u7528\u7db2\u8def\u91e3\u9b5a\u9801\u9762\u7684\u65b9\u5f0f\u8ddf\u6211\u5011\u6700\u8fd1\u5831\u5c0e\u904e\u7684<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/operation-poisoned-news-hong-kong-users-targeted-with-mobile-malware-via-local-news-links\/\">\u6bd2\u5316\u65b0\u805e\u884c\u52d5\uff08Operation Poisoned News\uff09<\/a>\u985e\u4f3c\uff0c\u4e00\u6a23\u7528\u65b0\u805e\u7db2\u9801\u4f5c\u70ba\u8a98\u990c\u4f86\u5c0d\u884c\u52d5\u88dd\u7f6e\u9032\u884c\u6f0f\u6d1e\u653b\u64ca\u3002Earth Empusa\u9084\u6703\u7528\u793e\u4ea4\u5de5\u7a0b\u8a98\u990c\u4f86\u8a98\u9a19\u76ee\u6a19\u700f\u89bd\u91e3\u9b5a\u7db2\u9801\u3002\u6211\u5011\u57282020\u5e743\u6708\u767c\u73fe\u4ed6\u5011\u7684\u4f3a\u670d\u5668\u51fa\u73fe\u4e86\u62f7\u8c9d\u81ea\u7dad\u543e\u723e\u65cf\u76f8\u95dc\u65b0\u805e\u7db2\u7ad9\u7684\u65b0\u805e\u7db2\u9801\u3002\u6240\u6709\u7db2\u9801\u90fd\u88ab\u6ce8\u5165\u8173\u672c\u4f86\u8f09\u5165\u8de8\u7ad9\u8173\u672c\u6846\u67b6<a href=\"https:\/\/beefproject.com\/\">BeEF<\/a>\u3002\u6211\u5011\u61f7\u7591\u7576\u76ee\u6a19\u53d7\u5bb3\u8005\u700f\u89bd\u4e0a\u8ff0\u7db2\u7ad9\u6642\uff0c\u653b\u64ca\u8005\u6703\u5229\u7528\u8a72\u6846\u67b6\u4f86\u6d3e\u9001\u60e1\u610f\u8173\u672c\u3002\u4e0d\u904e\u7576\u6211\u5011\u8a66\u8457\u700f\u89bd\u4e0a\u8ff0\u91e3\u9b5a\u7db2\u9801\u4f86\u9032\u4e00\u6b65\u8abf\u67e5\u6642\u4e26\u6c92\u6709\u767c\u73fe\u8173\u672c\u51fa\u73fe\u3002\u9019\u4e9b\u7db2\u9801\u7684\u6563\u64ad\u6a5f\u5236\u76ee\u524d\u4ecd\u4e0d\u6e05\u695a\u3002<\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-02.png\" alt=\"\"\/><figcaption><em>\u57162. \u5047\u65b0\u805e\u7db2\u9801\u62f7\u8c9d\u4e16\u754c\u7dad\u543e\u723e\u4ee3\u8868\u5927\u6703\u7db2\u7ad9\u7528\u4f86\u8f09\u5165BeEF\u6846\u67b6<\/em><\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>\u5728 2020\u5e744\u6708\u4e0b\u65ec\u7e7c\u7e8c\u9032\u884c\u8abf\u67e5\u6642\uff0c\u6211\u5011\u767c\u73fe\u53e6\u4e00\u500b\u4f3c\u4e4e\u662f\u62f7\u8c9d\u7b2c\u4e09\u65b9\u7db2\u8def\u5546\u5e97\u7684\u91e3\u9b5a\u7db2\u9801\uff0c\u800c\u4e14\u6703\u6ce8\u5165\u5169\u500b\u8173\u672c\u4f86\u8f09\u5165<a href=\"https:\/\/resources.infosecinstitute.com\/scanbox-framework\/\">ScanBox<\/a>\u548cBeEF\u6846\u67b6\u3002\u9019\u500b\u91e3\u9b5a\u7db2\u9801\u6703\u9080\u8acb\u4f7f\u7528\u8005\u4e0b\u8f09\u85cf\u65cfAndroid\u4f7f\u7528\u8005\u719f\u77e5\u7684\u5f71\u7247\u61c9\u7528\u7a0b\u5f0f\u3002\u6211\u5011\u8a8d\u70ba\u9019\u500b\u7db2\u9801\u662f\u7531Earth Empusa\u6240\u5efa\u7acb\uff0c\u56e0\u70baBeEF\u6846\u67b6\u662f\u904b\u884c\u5728\u64da\u7a31\u5c6c\u65bc\u8a72\u99ed\u5ba2\u96c6\u5718\u7684\u7db2\u57df\u3002\u4e0b\u8f09\u9023\u7d50\u6703\u9023\u5230\u5305\u542bAndroid\u61c9\u7528\u7a0b\u5f0f\u7684\u58d3\u7e2e\u6a94\u3002\u7d93\u904e\u5206\u6790\u5f8c\u767c\u73fe\u9019\u662f\u4e00\u500b\u672a\u88ab\u8a18\u9304\u904e\u7684Android\u9593\u8adc\u8edf\u9ad4\uff0c\u6211\u5011\u5c07\u5176\u547d\u540d\u70baActionSpy\u3002<\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-03.png\"><br><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-03.png\" alt=\"\" width=\"1377\" height=\"733\" srcset=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-03.png 1377w, https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-03-200x106.png 200w, https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-03-1024x545.png 1024w, https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-03-768x409.png 768w, https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-03-640x341.png 640w, https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-03-900x479.png 900w, https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-03-440x234.png 440w, https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-03-380x202.png 380w\"><\/a><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-04.png\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-04.png\" alt=\"\" class=\"wp-image-87521\"\/><\/a><figcaption><em>\u57163\u548c\u57164. \u5047Android\u61c9\u7528\u7a0b\u5f0f\u4e0b\u8f09\u7db2\u9801\uff08\u539f\u6587\u548c\u82f1\u6587\u7ffb\u8b6f\uff09<\/em><\/figcaption><\/figure><\/div>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-05.png\" alt=\"\"\/><figcaption><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-05.png\"><\/figcaption><\/figure>\n\n\n\n<p><em>\u5716<\/em><em>5. <\/em><em>\u91e3\u9b5a\u7db2\u9801\u6ce8\u5165\u7684<\/em><em>ScanBox<\/em><em>\uff08\u4e0a\uff09\u548c<\/em><em>BeEF<\/em><em>\uff08\u4e0b\uff09\u986f\u793a\u8207<\/em><em>Earth Empusa<\/em><em>\u7db2\u57df\u91cd\u758a\u4e4b\u8655<\/em><em><\/em><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u6df1\u5165ActionSpy<\/strong><\/h3>\n\n\n\n<p><br>\u9019\u500b\u60e1\u610f\u8edf\u9ad4\u507d\u88dd\u6210\u4e00\u500b\u7dad\u543e\u723e\u65cf\u5f71\u7247\u61c9\u7528\u7a0b\u5f0fEkran\u3002\u5b83\u5177\u5099\u4e86\u8ddf\u6b63\u7248\u76f8\u540c\u7684\u5916\u89c0\u548c\u529f\u80fd\uff0c\u9019\u9ede\u662f\u5229\u7528<a href=\"https:\/\/github.com\/asLody\/VirtualApp\">VirtualApp<\/a>\u4f86\u505a\u5230\u3002\u6b64\u5916\u5b83\u9084\u5229\u7528<a href=\"https:\/\/dev.bangcle.com\/\">Bangcle<\/a>\u4fdd\u8b77\u4f86\u8eb2\u907f\u975c\u614b\u5206\u6790\u548c\u5075\u6e2c\u3002<\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-06.png\" alt=\"\"\/><figcaption><em>\u57166. ActionSpy\u7684\u5716\u793a\uff08\u5de6\uff09\u548c\u5916\u89c0\uff08\u53f3\uff09<\/em><\/figcaption><\/figure>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-07.png\" alt=\"\"\/><figcaption><em>\u57167. ActionSpy\u4f7f\u7528Bangcle\u9032\u884c\u4fdd\u8b77<\/em><\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>\u6b63\u5e38\u7684Ekran APK\u6a94\u6848\u88ab\u5167\u5d4c\u5728ActionSpy\u7684assets\u8cc7\u6599\u593e\uff0c\u6703\u5728ActionSpy\u9996\u6b21\u555f\u52d5\u6e96\u5099\u597dVirtualApp\u5f8c\u5b89\u88dd\u5165\u865b\u64ec\u74b0\u5883\u3002<\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-08.png\" alt=\"\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-08.png\" alt=\"\"\/><figcaption><em>\u57168\u548c9. \u5b89\u88dd\u771f\u6b63\u7684Ekran\uff08\u4e0a\uff09\u4e26\u555f\u52d5\uff08\u4e0b\uff09<\/em><\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>ActionSpy\u7684\u8a2d\u5b9a\uff08\u5305\u62ec\u5176C&amp;C\u4f3a\u670d\u5668\u5730\u5740\uff09\u4f7f\u7528DES\u52a0\u5bc6\u3002\u89e3\u5bc6\u91d1\u9470\u662f\u7528\u539f\u751f\u7a0b\u5f0f\u78bc\u7522\u751f\u3002\u9019\u8b93ActionSpy\u96e3\u4ee5\u9032\u884c\u975c\u614b\u5206\u6790\u3002<\/p>\n\n\n\n<p><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>ActionSpy\u6bcf\u969430\u79d2\u5c31\u6703\u6536\u96c6\u57fa\u672c\u88dd\u7f6e\u8cc7\u8a0a<\/strong><\/h3>\n\n\n\n<p><br>ActionSpy\u6bcf\u969430\u79d2\u5c31\u6703\u6536\u96c6\u57fa\u672c\u88dd\u7f6e\u8cc7\u8a0a\uff08\u5982IMEI\u3001\u96fb\u8a71\u865f\u78bc\u3001\u88fd\u9020\u5546\u3001\u96fb\u6c60\u72c0\u614b\u7b49\uff09\u50b3\u9001\u7d66C&amp;C\u4f3a\u670d\u5668\u3002\u4f3a\u670d\u5668\u53ef\u80fd\u6703\u8fd4\u56de\u5728\u53d7\u611f\u67d3\u88dd\u7f6e\u4e0a\u57f7\u884c\u7684\u547d\u4ee4\u3002C&amp;C\u8207ActionSpy\u9593\u7684\u901a\u8a0a\u6d41\u91cf\u90fd\u7d93\u904eRSA\u52a0\u5bc6\u4e26\u900f\u904eHTTP\u50b3\u8f38\u3002<\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-10.png\" alt=\"\"\/><figcaption><em>\u571610. \u6536\u96c6\u7684\u88dd\u7f6e\u8cc7\u8a0a<\/em><\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>ActionSpy\u652f\u63f4\u4e0b\u5217\u6a21\u7d44\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table  class=\" table table-hover\" ><tbody><tr><td><strong>\u6a21\u7d44\u540d\u7a31<\/strong><\/td><td><strong>\u6558\u8ff0<\/strong><\/td><\/tr><tr><td>location<\/td><td>\u53d6\u5f97\u88dd\u7f6e\u4f4d\u7f6e\u7d93\u7def\u5ea6<\/td><\/tr><tr><td>geo<\/td><td>\u53d6\u5f97\u5730\u7406\u5340\u57df\u5982\u7701\u3001\u5e02\u3001\u5340\u3001\u8857\u9053\u5730\u5740<\/td><\/tr><tr><td>contacts<\/td><td>\u53d6\u5f97\u806f\u7d61\u4eba\u8cc7\u8a0a<\/td><\/tr><tr><td>calling<\/td><td>\u53d6\u5f97\u96fb\u8a71\u7d00\u9304<\/td><\/tr><tr><td>sms<\/td><td>\u53d6\u5f97\u7c21\u8a0a<\/td><\/tr><tr><td>nettrace<\/td><td>\u53d6\u5f97\u700f\u89bd\u5668\u66f8\u7c64<\/td><\/tr><tr><td>software<\/td><td>\u53d6\u5f97\u5df2\u5b89\u88dd\u61c9\u7528\u7a0b\u5f0f\u8cc7\u8a0a<\/td><\/tr><tr><td>process<\/td><td>\u53d6\u5f97\u57f7\u884c\u4e2d\u7a0b\u5e8f\u8cc7\u8a0a<\/td><\/tr><tr><td>wifi connect<\/td><td>\u8b93\u88dd\u7f6e\u9023\u63a5\u6307\u5b9a\u7121\u7dda\u71b1\u9ede<\/td><\/tr><tr><td>wifi disconnect<\/td><td>\u8b93\u88dd\u7f6e\u4e2d\u65b7\u7121\u7dda\u7db2\u8def<\/td><\/tr><tr><td>wifi list<\/td><td>\u53d6\u5f97\u6240\u6709\u53ef\u7528\u7121\u7dda\u71b1\u9ede\u8cc7\u8a0a<\/td><\/tr><tr><td>dir<\/td><td>\u6536\u96c6SD\u5361\u4e0a\u6307\u5b9a\u985e\u578b\u6a94\u6848\u7684\u5217\u8868\uff0c\u5982txt\u3001jpg\u3001mp4\u3001doc\u3001xls\u2026<\/td><\/tr><tr><td>file<\/td><td>\u4e0a\u50b3\u88dd\u7f6e\u6a94\u6848\u5230C&amp;C\u4f3a\u670d\u5668<\/td><\/tr><tr><td>voice<\/td><td>\u9304\u74b0\u5883\u97f3<\/td><\/tr><tr><td>camera<\/td><td>\u7528\u93e1\u982d\u62cd\u7167<\/td><\/tr><tr><td>screen<\/td><td>\u87a2\u5e55\u622a\u5716<\/td><\/tr><tr><td>wechat<\/td><td>\u53d6\u5f97\u5fae\u4fe1\u8cc7\u6599\u593e\u7d50\u69cb<\/td><\/tr><tr><td>wxfile<\/td><td>\u53d6\u5f97\u5fae\u4fe1\u63a5\u6536\u6216\u9001\u51fa\u7684\u6a94\u6848<\/td><\/tr><tr><td>wxrecord<\/td><td>\u53d6\u5f97\u5fae\u4fe1\u3001QQ\u3001WhatsApp\u548cViber\u7684\u804a\u5929\u7d00\u9304<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u8981\u6c42\u958b\u555f\u7121\u969c\u7919\u670d\u52d9\uff0c\u8072\u7a31\u662f\u8a18\u61b6\u9ad4\u5783\u573e\u6e05\u7406\u670d\u52d9<\/strong><strong><\/strong><\/h3>\n\n\n\n<p><br>\u4e00\u822c\u4f86\u8aaa\uff0c\u5728Android\u4e0a\u7684\u7b2c\u4e09\u65b9\u61c9\u7528\u7a0b\u5f0f\u4e0d\u80fd\u5b58\u53d6\u4e0d\u5c6c\u65bc\u81ea\u5df1\u7684\u6a94\u6848\u3002\u9019\u8b93ActionSpy\u96e3\u4ee5\u5728\u6c92\u6709root\u6b0a\u9650\u4e0b\u7aca\u53d6\u5fae\u4fe1\u7b49\u5373\u6642\u901a\u61c9\u7528\u7a0b\u5f0f\u7684\u804a\u5929\u7d00\u9304\u6a94\u3002\u6240\u4ee5ActionSpy\u7528\u4e86\u9593\u63a5\u4f5c\u6cd5\uff1a\u8981\u6c42\u4f7f\u7528\u8005\u958b\u555f\u7121\u969c\u7919\u670d\u52d9\uff0c\u8072\u7a31\u81ea\u5df1\u662f\u8a18\u61b6\u9ad4\u5783\u573e\u6e05\u7406\u670d\u52d9\u3002<\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-11.png\" alt=\"\"\/><figcaption><em>\u571611. \u63d0\u793a\u958b\u555f\u7121\u969c\u7919\u529f\u80fd<\/em><\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>\u4e00\u65e6\u4f7f\u7528\u8005\u958b\u555f\u7121\u969c\u7919\u529f\u80fd\u670d\u52d9\u5f8c\uff0cActionSpy\u6703\u76e3\u8996\u88dd\u7f6e\u7684\u7121\u969c\u7919\u529f\u80fd\u4e8b\u4ef6\uff0c\u51fa\u73fe\u5728\u4f7f\u7528\u8005\u4ecb\u9762\u51fa\u73fe<a href=\"https:\/\/developer.android.com\/reference\/android\/view\/accessibility\/AccessibilityEvent\">\u201d\u986f\u8457\u201d\u8b8a\u5316<\/a>\uff08\u5982\u9ede\u64ca\u6309\u9215\u3001\u8f38\u5165\u6587\u5b57\u6216\u756b\u9762\u6539\u8b8a\uff09\u6642\u3002\u7576\u6536\u5230\u7121\u969c\u7919\u529f\u80fd\u4e8b\u4ef6\uff0cActionSpy\u6703\u6aa2\u67e5\u4e8b\u4ef6\u985e\u578b\u662f\u5426\u70ba<a href=\"https:\/\/developer.android.com\/reference\/android\/view\/accessibility\/AccessibilityEvent#TYPE_VIEW_SCROLLED\">VIEW_SCROLLED<\/a>\u6216<a href=\"https:\/\/developer.android.com\/reference\/android\/view\/accessibility\/AccessibilityEvent#TYPE_WINDOW_CONTENT_CHANGED\">WINDOW_CONTENT_CHANGED<\/a>\uff0c\u7136\u5f8c\u6aa2\u67e5\u4e8b\u4ef6\u662f\u5426\u4f86\u81ea\u5982\u5fae\u4fe1\u3001QQ\u3001WhatsApp\u548cViber\u7b49\u76ee\u6a19\u61c9\u7528\u7a0b\u5f0f\u3002\u5982\u679c\u6eff\u8db3\u4ee5\u4e0a\u689d\u4ef6\uff0c\u5247ActionSpy\u6703\u5206\u6790\u7576\u524d\u6d3b\u52d5\u5167\u5bb9\u4e26\u63d0\u53d6\u5982\u66b1\u7a31\u3001\u804a\u5929\u5167\u5bb9\u548c\u804a\u5929\u6642\u9593\u7b49\u8cc7\u8a0a\u3002\u6240\u6709\u7684\u804a\u5929\u8cc7\u8a0a\u90fd\u6703\u7d93\u904e\u6574\u7406\u4e26\u5132\u5b58\u5230\u4e00\u500b\u672c\u5730\u7aefSQLite\u8cc7\u6599\u5eab\u3002\u7576\u9001\u51fawxrecord\u547d\u4ee4\u6642\uff0cActionSpy\u6703\u6536\u96c6\u8cc7\u6599\u5eab\u5167\u7684\u804a\u5929\u8a18\u9304\u4e26\u8f49\u6210JSON\u683c\u5f0f\uff0c\u63a5\u8457\u50b3\u9001\u5230C&amp;C\u4f3a\u670d\u5668\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-12.png\" alt=\"\"\/><figcaption><em>\u571612. \u89e3\u6790\u804a\u5929\u8cc7\u8a0a\u7528\u7684\u7a0b\u5f0f\u78bc<\/em><\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>\u6839\u64da\u5176\u6191\u8b49\u7c3d\u7ae0\u6642\u9593\uff082017-07-10\uff09\uff0c\u6211\u5011\u8a8d\u70baActionSpy\u81f3\u5c11\u5df2\u7d93\u5b58\u5728\u4e86\u4e09\u5e74\u3002\u6211\u5011\u9084\u627e\u5230\u4e00\u4e9b\u57282017\u5e74\u88fd\u4f5c\u7684\u820aActionSpy\u7248\u672c\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-13.png\" alt=\"\"\/><figcaption><em>\u571613. \u6191\u8b49\u8cc7\u8a0a<\/em><\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-14a.png\" alt=\"\"\/><figcaption><em>\u571614. \u65e9\u671f\u7248\u672c\uff08\u88fd\u4f5c\u65bc2017\u5e74\uff09<\/em><\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Earth Empusa<\/strong><strong>\u91dd\u5c0d<\/strong><strong>iOS<\/strong><strong>\u7cfb\u7d71\u7684\u6c34\u5751\u653b\u64ca<\/strong><strong><\/strong><\/h3>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Earth Empusa\u9084\u6703\u7528\u6c34\u5751\u653b\u64ca\u4f86\u5165\u4fb5iOS\u88dd\u7f6e\u3002\u99ed\u5ba2\u96c6\u5718\u5c07\u60e1\u610f\u8173\u672c\u6ce8\u5165\u5230\u76ee\u6a19\u53ef\u80fd\u700f\u89bd\u7684\u7db2\u7ad9\u4f86\u8f09\u5165\u6ce8\u5165\u8173\u672c\u3002\u6211\u5011\u767c\u73fe\u4ed6\u5011\u5c0d\u5165\u4fb5\u7db2\u7ad9\u6ce8\u5165\u4e86\u5169\u7a2e\u653b\u64ca\uff1a<\/p>\n\n\n\n<ul><li>\u4e00\u7a2e\u662f\u7528ScanBox\u6846\u67b6\u4f86\u5c0d\u7db2\u7ad9\u8a2a\u5ba2\u6536\u96c6\u8cc7\u8a0a\uff0c\u8a72\u6846\u67b6\u6703\u5229\u7528JavaScript\u8a18\u9304\u6309\u9375\u4e26\u5f9e\u5ba2\u6236\u7aef\u74b0\u5883\u6536\u96c6\u4f5c\u696d\u7cfb\u7d71\u3001\u700f\u89bd\u5668\u548c\u700f\u89bd\u5668\u64f4\u5145\u5957\u4ef6\u7684\u914d\u7f6e\u6a94\u6848\u3002\u9019\u500b\u6846\u67b6\u901a\u5e38\u88ab\u7528\u5728\u5075\u5bdf\u968e\u6bb5\uff0c\u597d\u4e86\u89e3\u76ee\u6a19\u4e26\u70ba\u4e0b\u4e00\u968e\u6bb5\u7684\u653b\u64ca\u505a\u6e96\u5099\u3002<\/li><li>\u53e6\u4e00\u7a2e\u662f\u4ed6\u5011\u7684\u6f0f\u6d1e\u653b\u64ca\u93c8\u6846\u67b6\uff0c\u5b83\u6703\u653b\u64caiOS\u88dd\u7f6e\u7684\u6f0f\u6d1e\u3002\u8a72\u6846\u67b6\u6703\u6aa2\u67e5HTTP\u8acb\u6c42\u7684User-Agent\u6a19\u982d\u4f86\u5224\u5b9a\u53d7\u5bb3\u8005\u88dd\u7f6e\u7684iOS\u7248\u672c\uff0c\u4e26\u7528\u5c0d\u61c9\u7684\u6f0f\u6d1e\u653b\u64ca\u78bc\u4f86\u9032\u884c\u56de\u61c9\u3002\u5982\u679cUser-Agent\u4e0d\u5c6c\u65bc\u76ee\u6a19iOS\u7248\u672c\u4e4b\u5167\uff0c\u5247\u8a72\u6846\u67b6\u4e0d\u6703\u9001\u51fa\u4efb\u4f55\u60e1\u610f\u64cb\u6848\u3002<\/li><\/ul>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-15.png\" alt=\"\"\/><figcaption><em>\u571615. iOS\u6f0f\u6d1e\u653b\u64ca\u93c8\u6d41\u91cf\u6a23\u672c<\/em><\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>\u57282020\u5e74\u7b2c\u4e00\u5b63\uff0c\u6f0f\u6d1e\u653b\u64ca\u93c8\u6846\u67b6\u5347\u7d1a\u5305\u542b\u4e86\u91dd\u5c0diOS 12.3\u300112.3.1\u548c12.3.2\u7684\u65b0iOS\u6f0f\u6d1e\u653b\u64ca\u78bc\u3002\u5176\u4ed6\u7814\u7a76\u4eba\u54e1\u4e5f<a href=\"https:\/\/www.volexity.com\/blog\/2020\/04\/21\/evil-eye-threat-actor-resurfaces-with-ios-exploit-and-updated-implant\/\">\u767c\u8868<\/a>\u4e86\u95dc\u65bc\u6b64\u66f4\u65b0\u6f0f\u6d1e\u653b\u64ca\u78bc\u7684\u8a73\u7d30\u8cc7\u8a0a\u3002<\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-16.png\" alt=\"\"\/><figcaption><em>\u571616. \u7528\u4f86\u5224\u5b9aiOS\u7248\u672c\u548c\u555f\u52d5\u6f0f\u6d1e\u653b\u64ca\u78bc\u7684\u8173\u672c<\/em><\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>\u6211\u5011\u81ea2020\u5e74\u521d\u5c31\u958b\u59cb\u5728\u591a\u500b\u7dad\u543e\u723e\u65cf\u76f8\u95dc\u7db2\u7ad9\u89c0\u5bdf\u5230\u9019\u4e9b\u6ce8\u5165\u653b\u64ca\u3002\u6b64\u5916\uff0c\u6211\u5011\u4e5f\u767c\u73fe\u5230\u571f\u8033\u5176\u7684\u65b0\u805e\u7db2\u7ad9\u548c\u653f\u9ee8\u7db2\u7ad9\u88ab\u5165\u4fb5\u4e26\u906d\u9047\u76f8\u540c\u7684\u6ce8\u5165\u653b\u64ca\u3002\u6700\u65b0\u767c\u5c55\u5247\u662f\u6211\u5011\u57282020\u5e743\u6708\u5728\u53f0\u7063\u7684\u5927\u5b78\u7db2\u7ad9\u548c\u65c5\u884c\u793e\u7db2\u7ad9\u767c\u73fe\u76f8\u540c\u7684\u6ce8\u5165\u653b\u64ca\u3002\u9019\u4e9b\u767c\u5c55\u8b93\u4eba\u76f8\u4fe1Earth Empusa\u6b63\u5728\u64f4\u5927\u5176\u76ee\u6a19\u7bc4\u570d\u3002<\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u6700\u4f73\u5be6\u4f5c\u548c\u89e3\u6c7a\u65b9\u6848<\/strong><strong><\/strong><\/h3>\n\n\n\n<p>Earth Empusa\u4ecd\u7136\u76f8\u7576\u7684\u6d3b\u8e8d\u3002\u96a8\u8457\u99ed\u5ba2\u96c6\u5718\u4e0d\u65b7\u5730\u958b\u767c\u653b\u64ca\u76ee\u6a19\u7684\u65b0\u65b9\u6cd5\uff0c\u6211\u5011\u4e5f\u6703\u6301\u7e8c\u5730\u9032\u884c\u8ffd\u8e64\u548c\u76e3\u8996\u3002<\/p>\n\n\n\n<p>\u5efa\u8b70iOS\u7684\u4f7f\u7528\u8005\u8981\u8a18\u5f97\u66f4\u65b0\u7cfb\u7d71\u3002\u6b64\u5916\u4e5f\u5efa\u8b70Android\u4f7f\u7528\u8005\u53ea\u5f9e\u53d7\u4fe1\u4efb\u4f86\u6e90\uff08\u5982Google Play\uff09\u5b89\u88dd\u61c9\u7528\u7a0b\u5f0f\u4f86\u907f\u514d\u9047\u5230\u60e1\u610f\u8edf\u9ad4\u3002<\/p>\n\n\n\n<p>\u4f7f\u7528\u8005\u9084\u53ef\u4ee5\u5b89\u88dd\u5982 <a href=\"https:\/\/t.rend.tw\/?i=ODUxNQ\">\u8da8\u52e2\u79d1\u6280\u884c\u52d5\u5b89\u5168\u9632\u8b77<\/a>\u7b49\u80fd\u5920\u5c01\u9396\u60e1\u610f\u61c9\u7528\u7a0b\u5f0f\u7684\u5b89\u5168\u89e3\u6c7a\u65b9\u6848\u3002\u4e00\u822c\u4f7f\u7528\u8005\u53ef\u4ee5\u5f97\u76ca\u65bc\u5176\u591a\u5c64\u6b21\u5b89\u5168\u9632\u8b77\u529f\u80fd\u4f86\u4fdd\u8b77\u88dd\u7f6e\u64c1\u6709\u8005\u7684\u8cc7\u6599\u548c\u96b1\u79c1\uff0c\u4e26\u63d0\u4f9b\u80fd\u5920\u62b5\u79a6\u52d2\u7d22\u8edf\u9ad4\u3001\u8a50\u9a19\u7db2\u7ad9\u548c\u8eab\u4efd\u7aca\u53d6\u7b49\u5a01\u8105\u7684\u9632\u8b77\u529f\u80fd\u3002<\/p>\n\n\n\n<p>\u5c0d\u65bc\u4f01\u696d\uff0c<a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/user-protection\/sps.html\">\u8da8\u52e2\u79d1\u6280\u7684\u884c\u52d5\u5b89\u5168\u9632\u8b77\u4f01\u696d\u7248<\/a>\u63d0\u4f9b\u4e86\u88dd\u7f6e\u3001\u5408\u898f\u6027\u548c\u61c9\u7528\u7a0b\u5f0f\u7ba1\u7406\uff0c\u8cc7\u6599\u4fdd\u8b77\u548c\u8a2d\u5b9a\u914d\u7f6e\uff0c\u540c\u6642\u80fd\u5920\u4fdd\u8b77\u88dd\u7f6e\u62b5\u79a6\u6f0f\u6d1e\u653b\u64ca\uff0c\u9632\u6b62\u5c0d\u61c9\u7528\u7a0b\u5f0f\u672a\u7d93\u6388\u6b0a\u7684\u5b58\u53d6\u4ee5\u53ca\u5075\u6e2c\u4e26\u5c01\u9396\u60e1\u610f\u8edf\u9ad4\u548c\u8a50\u9a19\u7db2\u7ad9\u3002<a href=\"https:\/\/mars.trendmicro.com\/\">\u8da8\u52e2\u79d1\u6280\u7684\u884c\u52d5\u61c9\u7528\u7a0b\u5f0f\u4fe1\u8b7d\u8a55\u6bd4\u670d\u52d9<\/a>\uff08MARS\uff09\u4f7f\u7528\u696d\u754c\u9818\u5148\u7684\u6c99\u7bb1\u548c<a href=\"https:\/\/blog.trendmicro.com.tw\/?p=55169\">\u6a5f\u5668\u5b78\u7fd2(Machine learning,ML)<\/a>\u6280\u8853\u4f86\u6db5\u84cbAndroid\u548ciOS\u4e0a\u7684\u5a01\u8105\u3002\u80fd\u5920\u4fdd\u8b77\u4f7f\u7528\u8005\u89e3\u6c7a\u60e1\u610f\u8edf\u9ad4\u3001\u96f6\u6642\u5dee\u653b\u64ca\u548c\u5df2\u77e5\u6f0f\u6d1e\u653b\u64ca\u3001\u96b1\u79c1\u5916\u6d29\u53ca\u61c9\u7528\u7a0b\u5f0f\u6f0f\u6d1e\u7b49\u554f\u984c\u3002<\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u5165\u4fb5\u6307\u6a19<\/strong><strong><\/strong><\/h3>\n\n\n\n<p>\u4e0b\u5217\u7684\u60e1\u610f\u8edf\u9ad4\u90fd\u88ab\u5075\u6e2c\u70baAndroidOS_ActionSpy.HRX\u3002<\/p>\n\n\n\n<style>\n   table {border-collapse:collapse; table-layout:fixed; width:310px;}\n   table td {border:solid 1px ; width:100px; word-wrap:break-word;}\n   <\/style>\n\n<figure class=\"wp-block-table\"><table  class=\" table table-hover\" ><tbody><tr><td><strong>SHA256<\/strong><\/td><td><strong>\u5957\u4ef6\u540d\u7a31<\/strong><\/td><td><strong>\u6a19\u7c64<\/strong><\/td><\/tr><tr><td>56a2562426e504f42ad9aa2bd53445d8e299935c817805b0d9b9431521769271<\/td><td>com.omn.vvi<\/td><td>Ekran<\/td><\/tr><tr><td>b6e2fdbf022cd009585f62a3de71464014edd58125eb7bc15c2c670d6d5d3590<\/td><td>com.isyjv.klxblnwc.r<\/td><td>\u7cfb\u7edf\u4f18\u5316<\/td><\/tr><tr><td>de6065c63f05f8cddaec2f43a3789cca7d8e16221bd04bf3ce8092809b146ebe<\/td><td>com.isyjv.klxblnwc.r<\/td><td>\u7cfb\u7edf\u4f18\u5316<\/td><\/tr><tr><td>2117e2252fe268136a2833202d746d67bf592de819cc1600ac8d9f2738d8d4d6<\/td><td>com.isyjv.klxblnwc<\/td><td>Service Runtime Library<\/td><\/tr><tr><td>588b62a2e0bffa8935cd08ae46255a972b0af4966483967a3046a5df59d38406<\/td><td>com.isyjv.klxblnwc<\/td><td>Service Runtime Library<\/td><\/tr><tr><td>d6478b4b7f0ea38947d894b1a87baf4bed7a1ece934fff9dfc233610de232814<\/td><td>com.isyjv.klxblnwc<\/td><td>Service Runtime Library<\/td><\/tr><tr><td>8d0a123e0fe91637fb41d9d9650a4b9c75b6ce77a2b51ac36f05a337da7afd80<\/td><td>com.ecs.esap<\/td><td>Service Runtime Library<\/td><\/tr><tr><td>9bc16f635fde4ff0b6b02b445a706d885779611b7813c5607ab88fdff43fcc2f<\/td><td>com.cd.weixin<\/td><td>VWechat<\/td><\/tr><tr><td>334dbd15289aaeaf3763f1702003de52ff709515246902f51ee87a41467a8e55<\/td><td>com.android.dmp.rec<\/td><td>Recording<\/td><\/tr><tr><td>50c10ab93910a6e617c85a03f8c38a10a7c363e2d37b745964e696da8f98a93d<\/td><td>com.android.dmp.rec<\/td><td>Recording<\/td><\/tr><tr><td>6575eeda2a8f76170fb6034944eeda5c88dac8009edccc880124fa729dd3c1fd<\/td><td>com.android.dmp.l<\/td><td>Location<\/td><\/tr><tr><td>eff30f6cc2d5d04ce4aef0c50f1fb375fb817a803bf3e8e08c847f04658185ba<\/td><td>com.android.dmp.l<\/td><td>Location<\/td><\/tr><tr><td>a0a48d7e0762ab24b2ec3ec488b011db866992db5392926fe43dd3d1c398e30d<\/td><td>com.android.dmp.cm<\/td><td>Camera<\/td><\/tr><tr><td>088769a80b39d0da26c676a5a52eaccdb805dc67cba85e562785c375c642b501<\/td><td>com.android.dmp.c<\/td><td>Core<\/td><\/tr><tr><td>87306b59aaaba0ea92ea6a05feb9366eeb625e8da08ed3ef6c86a5cf394fada5<\/td><td>com.android.dmp.c<\/td><td>Core<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<figure class=\"wp-block-table\"><table  class=\" table table-hover\" ><tbody><tr><td><strong>\u6307\u647d<\/strong><\/td><td><strong>\u985e\u578b<\/strong><\/td><\/tr><tr><td>gotossl.ml<\/td><td>Earth Empusa\u7528\u7684\u7db2\u57df<\/td><\/tr><tr><td>goforssl.top<\/td><td>Earth Empusa\u7528\u7684\u7db2\u57df<\/td><\/tr><tr><td>geo2ipapi.org<\/td><td>Earth Empusa\u7528\u7684\u7db2\u57df<\/td><\/tr><tr><td>appbuliki.com<\/td><td>Earth Empusa\u7528\u7684\u7db2\u57df<\/td><\/tr><tr><td>umutyole.com<\/td><td>Earth Empusa\u7528\u7684\u7db2\u57df<\/td><\/tr><tr><td>t.freenunn.com<\/td><td>Earth Empusa\u7528\u7684\u7db2\u57df<\/td><\/tr><tr><td>start.apiforssl.com<\/td><td>Earth Empusa\u7528\u7684\u7db2\u57df<\/td><\/tr><tr><td>bloomberg.com.cm<\/td><td>Earth Empusa\u7528\u7684\u7db2\u57df<\/td><\/tr><tr><td>static.apiforssl.com<\/td><td>Earth Empusa\u7528\u7684\u7db2\u57df<\/td><\/tr><tr><td>cdn.doublesclick.me<\/td><td>Earth Empusa\u7528\u7684\u7db2\u57df<\/td><\/tr><tr><td>static.doublesclick.info<\/td><td>Earth Empusa\u7528\u7684\u7db2\u57df<\/td><\/tr><tr><td>status.search-sslkey-flush.com<\/td><td>Earth Empusa\u7528\u7684\u7db2\u57df<\/td><\/tr><tr><td>https:\/\/114.215.41.93\/<\/td><td>ActionSpy\u7684C&amp;C\u7db2\u5740<\/td><\/tr><tr><td>https:\/\/static.doubles.click:8082\/<\/td><td>ActionSpy\u7684C&amp;C\u7db2\u5740<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>MITRE ATT&amp;CK<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"\" alt=\"\"\/><\/figure>\n\n\n\n<p><a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2020\/06\/earth-empusa-17.png\"><\/a><\/p>\n\n\n\n<p>@\u539f\u6587\u51fa\u8655\uff1a<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/new-android-spyware-actionspy-revealed-via-phishing-attacks-from-earth-empusa\/\" target=\"_blank\" rel=\"noreferrer noopener\">New Android Spyware ActionSpy Revealed via Phishing Attacks from Earth Empusa<\/a> \u4f5c\u8005\uff1aEcular Xu\u548cJoseph C. Chen\uff08<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/author\/trend-micro\/\">\u8da8\u52e2\u79d1\u6280<\/a>\uff09<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5728\u8ffd\u8e2aEarth Empura\uff08\u4e5f\u88ab\u7a31\u70baPOISON CARP\/Evil Eye\uff09\u6642\uff0c\u8da8\u52e2\u79d1\u6280\u767c\u73fe\u4e86\u4e00\u500b\u672a\u88ab\u8a18 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wpscppro_dont_share_socialmedia":false,"_wpscppro_custom_social_share_image":0,"_facebook_share_type":"","_twitter_share_type":"","_linkedin_share_type":"","_pinterest_share_type":"","_linkedin_share_type_page":"","_instagram_share_type":"","_medium_share_type":"","_threads_share_type":"","_google_business_share_type":"","_selected_social_profile":[],"_wpsp_enable_custom_social_template":false,"_wpsp_social_scheduling":{"enabled":false,"datetime":null,"platforms":[],"status":"template_only","dateOption":"today","timeOption":"now","customDays":"","customHours":"","customDate":"","customTime":"","schedulingType":"absolute"},"_wpsp_active_default_template":true},"categories":[17,15,1944],"tags":[3171,19],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/64859"}],"collection":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=64859"}],"version-history":[{"count":3,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/64859\/revisions"}],"predecessor-version":[{"id":64863,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/64859\/revisions\/64863"}],"wp:attachment":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=64859"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=64859"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=64859"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}