Ê׿ÀÕË÷¡¢Ìع¤¡¢ÒøÐÐľÂíÓÚÒ»ÌåµÄÐÂÐÍ×ÛºÏÐÍAndroid²¡¶¾Éî¶ÈÆÊÎö

Ðû²¼Ê±¼ä 2018-09-21

Ò»¡¢¼òÊö


c7c7ÓéÀÖÆ½Ì¨ADLab½üÆÚ·¢Ã÷Ò»¿î¼¯ÀÕË÷¼ÓÃܲ¡¶¾¡¢Ìع¤Èí¼þ¡¢ÒøÐÐľÂíÓÚÒ»ÌåµÄÐÂÐÍAndroid¶ñÒâ´úÂë,×ÅʵÏÖÁËÈç¼ÓÃÜÀÕË÷£¨Ransomware£©¡¢¼üÅ̼ͼ£¨keylogger£©¡¢Ô¶³Ì»á¼ûľÂí£¨RAT£©¡¢¶ÌÐÅ×èµ²¡¢ºô½Ð×ªÒÆºÍËø¶¨ÆÁÄ»µÈ¶àÖÖ¹¦Ð§¡£¡£¡£¡£
ÏêϸÆÊÎö¸Ã¶ñÒâ´úÂëºó·¢Ã÷£¬£¬ £¬£¬£¬¸Ã¶ñÒâ´úÂëбäÖÖ¿ÉÐ®ÖÆÏÕЩº­¸ÇÈ«Ììϸ÷´ó½ðÈÚ»ú¹¹µÄÊÖ»úAPP£¬£¬ £¬£¬£¬×ÜÊýÓÐ300¶à¸ö£¬£¬ £¬£¬£¬Éæ¼°Öйú¡¢ÃÀ¹ú¡¢Ó¢¹ú¡¢ÈÕ±¾¡¢ÖйúÏã¸Û¡¢·¨¹úµÈ40¶à¸ö¹ú¼ÒºÍµØÇø¡£¡£¡£¡£¸Ã¶ñÒâ´úÂ뻹¾ßÓÐÀÕË÷Èí¼þµÄ¹¦Ð§£¬£¬ £¬£¬£¬»áʹÓÃ256λ¶Ô³ÆÃÜÔ¿¶ÔÊܺ¦Óû§µÄÊÖ»úÎļþ¾ÙÐмÓÃÜ´¦Öóͷ££¬£¬ £¬£¬£¬²¢ÇÒÒÔ¡°.AnubisCrypt¡±×÷Ϊ¼ÓÃÜÎļþµÄÀ©Õ¹Ãû£¬£¬ £¬£¬£¬Í¬Ê±»¹Î±ÔìÁËFBIÖÒÑÔ½çÃæÍ¨ÖªÊܺ¦Óû§ÒÔ±ÈÌØ±ÒµÄ·½·¨Ö§¸¶·£½ð·½¿É¶ÔÎļþ¾ÙÐнâÃÜ¡£¡£¡£¡£ÁíÍ⣬£¬ £¬£¬£¬Ëü»¹Äܹ»±»ÓÃÓÚ¾ÙÐÐÍøÂçÌØ¹¤»î¶¯£¬£¬ £¬£¬£¬ÀýÈ磺¼àÊÓÊÜѬȾװ±¸Ö÷´°¿Ú»î¶¯¡¢¾ÙÐÐÆÁÄ»½ØÍ¼²¢·¢Ë͸ø¹¥»÷Õß¡¢Ê¹ÓÃÄÚÖÃÂó¿Ë·ç¼àÌýÊÜѬȾװ±¸ÖÜΧÇéÐÎÖеÄÉùÒôµÈµÈ¡£¡£¡£¡£

¶þ¡¢¶ñÒâ´úÂë·¢Ã÷

2018Äê8ÔÂ⣬£¬ £¬£¬£¬c7c7ÓéÀÖÆ½Ì¨ADLab¼à²âµ½Ò»¸öµ±ÔÂÐÂ×¢²áµÄÒì³£TwitterÕË»§£¬£¬ £¬£¬£¬¸ÃÕË»§ÔÚTwitterÉÏÐû²¼ÁËһЩÀàËÆÓÃbase64±àÂëµÄÍÆÎÄ¡£¡£¡£¡£Æä2018Äê8ÔÂ27ÈÕÐû²¼ÁËÁ½ÌõËÆºõÍêÈ«ÏàͬµÄÍÆÎÄ£¬£¬ £¬£¬£¬²¢ÇÒÔÚÎÒÃÇ·¢Ã÷µ±Ì죬£¬ £¬£¬£¬ÓÖÒ»Á¬Ðû²¼Á½Ìõ²î±ðµÄÍÆÎÄ£¨¼ûͼ1£©¡£¡£¡£¡£

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ1 ¿ÉÒÉTwitterÕË»§ÍÆÎÄ


ÎÒÃÇͨ¹ýbase64½âÂëÕâÐ©ÍÆÎĺ󣬣¬ £¬£¬£¬ÈÔÈ»¿´²»µ½ÈκÎÓÐÒâÒåµÄÊý¾Ý¡£¡£¡£¡£Òò´Ë£¬£¬ £¬£¬£¬ÎÒÃÇͨ¹ý¸ÃTwitterÁ´½Ó¡°https://twitter.com/sHybzhzZWJgdbdj¡±À´×ö¹ØÁªÆÊÎö£¬£¬ £¬£¬£¬²¢ÇÒ·¢Ã÷ÁËһЩ¿ÉÒɵÄapkÎļþ£¬£¬ £¬£¬£¬Í¨Ì«¹ýÎöÈ·ÈϸÃapkÎļþΪAndroidƽ̨ÏÂÒ»¿îΣº¦ÐÔ¼«´óµÄ¶ñÒâAPP£¬£¬ £¬£¬£¬²¢ÇÒÏÖÔÚ»¹´¦ÓÚ»îԾ״̬¡£¡£¡£¡£Í¨¹ýÉîÈëÆÊÎöÎÒÃÇ·¢Ã÷£¬£¬ £¬£¬£¬¸Ã¶ñÒâAPP»áÅþÁ¬¸ÃTwitterÁ´½Ó¡°https://twitter.com/sHybzhzZWJgdbdj¡±»ñÈ¡ÍÆÎÄ£¬£¬ £¬£¬£¬²¢½«Æä½âÃܳÉΪC&CµØµã£¬£¬ £¬£¬£¬Æä½âÃÜË㷨ģÄâÁËbase64µÄЧ¹û£¬£¬ £¬£¬£¬µ«²¢·ÇΪbase64Ëã·¨£¬£¬ £¬£¬£¬ÒÔ´ËÒÉ»ó·¢Ã÷Òì³£ÍÆÎĵįÊÎöÖ°Ô±¡£¡£¡£¡£½âÃܺóµÄ×Ö·û´®Èç±í1Ëùʾ£º

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

±í1 ÍÆÎĵĽâÃÜ


Ò»Ö±µ½9ÔÂ2ÈÕ£¬£¬ £¬£¬£¬ºÚ¿Íɾ³ýÁËÆäÖеÄ3ÌõÍÆÎÄ£¬£¬ £¬£¬£¬Ö»ÁôÏÂ×î½üµÄÒ»ÌõÍÆÎÄ£¨¼ûͼ2£©¡£¡£¡£¡£ËµÃ÷ʹÓøöñÒâ´úÂë¾ÙÐеÄÍøÂç¹¥»÷»î¶¯ÕýÔÚ¾ÙÐС£¡£¡£¡£

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ2 ¹¥»÷ÕßµÄÍÆÎÄֻʣÏÂÒ»ÌõC&C


ÎÒÃÇ×¢ÖØµ½£¬£¬ £¬£¬£¬¸ÃTwitterÕË»§Ê¹ÓÃÁ˱»³ÆÎª¡°È«ÌìÏÂ×î´óµÄÆ­×Ó¡±µÄ¶íÂÞ˹½ðÈÚÕ©Æ­·¸Sergei MavrodiµÄÕÕÆ¬×÷ΪͼÏñ£¬£¬ £¬£¬£¬ÍƲ⹥»÷ÕߺܿÉÄÜÊÇSergei MavrodiµÄ·ÛË¿¡£¡£¡£¡£Sergei Mavrodi£¨1955Äê8ÔÂ11ÈÕ- 2018Äê3ÔÂ26ÈÕ£©ÉúÓÚĪ˹¿Æ£¬£¬ £¬£¬£¬1989Ä꽨ÉèÁËMMM¹«Ë¾£¬£¬ £¬£¬£¬MMMÐû³ÆÒÔ´Ý»ÙÌìϲ»¹«ÕýµÄ½ðÈÚϵͳΪĿµÄ£¬£¬ £¬£¬£¬ÏÖʵÉÏÊÇÍæÁËÒ»¸ö¡°¹«¹²¼¯×Ê¡±µÄÅÓÊÏȦÌ×ÓÎÏ·¡£¡£¡£¡£º£ÄÚµÄe×ⱦ¡¢Ç®±¦ÍøµÈÒ²¶¼±»È϶¨ÊÇÅÓÊÏȦÌס£¡£¡£¡£ÔÚSergei MavrodiºÍÆäMMM¹«Ë¾½«¶íÂÞ˹ÏÕЩÄÜÆ­µÄÈ˶¼Æ­ÍêÁËÖ®ºó£¬£¬ £¬£¬£¬2015ÄêSergei Mavrodi½«ËûµÄÓÎÏ·´øÈëÁËÖйú£¬£¬ £¬£¬£¬²¢ÇÒΪÁËÌÓ±Üî¿Ïµ£¬£¬ £¬£¬£¬Sergei MavrodiÍŶӡ°Á¢ÒìµØ¡±½«±ÈÌØ±ÒÖ§¸¶ÒýÈëÁËÆäÖ§¸¶ÏµÍ³£¬£¬ £¬£¬£¬ÃãÀøÍ¶×ÊÕßʹÓñÈÌØ±Ò¾ÙÐÐתÕËÉúÒ⣬£¬ £¬£¬£¬²¢Îª´ËÌØÒâÖÆ×÷Á˱ÈÌØ±ÒɨäÊÓÆµ£¬£¬ £¬£¬£¬¼ûͼ3¡£¡£¡£¡£

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ3 Sergei MavrodiÍŶÓÖÆ×÷µÄ±ÈÌØ±ÒɨäÊÓÆµ


Èý¡¢Ñù±¾ÑÝ»¯


ƾ֤Ñù±¾¹ØÁªÆÊÎö£¬£¬ £¬£¬£¬ÎÒÃÇ·¢Ã÷¸Ã¶ñÒâ´úÂëÑù±¾ÎªAnubisµÄÒ»¸öбäÖÖ¡£¡£¡£¡£


2017Äê1Ô£¬£¬ £¬£¬£¬Çå¾²¹«Ë¾Dr.WebÔø·¢³öÖÒÑÔ£¬£¬ £¬£¬£¬ÒøÐÐľÂíBankBotµÄÔ´´úÂë±»¹ûÕæÐû²¼ÔÚÁËÒ»¸öÂÛ̳ÉÏ¡£¡£¡£¡£Ëæºó£¬£¬ £¬£¬£¬ÓÐÍøÂç·¸·¨·Ö×ÓʹÓøÃÔ´Â뽨ÉèÁ˰²×¿ÒøÐÐľÂíAndroid.BankBot.149.origin£¬£¬ £¬£¬£¬±ËʱµÄBankBot»¹½öÊÇÒ»¸öµä·¶µÄÒøÐÐľÂí£¬£¬ £¬£¬£¬Äܹ»Ê¹ÓÃÍøÂç´¹ÂÚ¶Ô»°¿òÇÔȡѬȾÓû§ÊÖ»úÒøÐеÄÃô¸ÐÐÅÏ¢£¬£¬ £¬£¬£¬ÈçÒøÐÐÏêϸÐÅÏ¢ºÍÐÅÓÿ¨Êý¾Ý¡£¡£¡£¡£


2018Äê3ÔÂ5ÈÕ£¬£¬ £¬£¬£¬PhishLabs·¢Ã÷ÁËÒøÐÐľÂíBankBotµÄÒ»¸öбäÖÖ£¬£¬ £¬£¬£¬²¢µÚÒ»´Î½«ÆäÃüÃûΪAnubis£¬£¬ £¬£¬£¬AnubisͬÑù»ùÓÚBankBotÔ´Â뿪·¢£¬£¬ £¬£¬£¬²¢ÕûºÏÁËÖÚ¶à²î±ðÀàÐͶñÒâÈí¼þµÄ¹¦Ð§ÓÚÒ»Éí¡£¡£¡£¡£


2018Äê7Ô£¬£¬ £¬£¬£¬IBM X-ForceµÄÒÆ¶¯¶ñÒâÈí¼þÑо¿Ö°Ô±ÊӲ쵽ÁË´ó×ÚµÄAndroid¶ñÒâÈí¼þÏÂÔØÆ÷±»ÉÏ´«µ½ÁËGoogle Play¡£¡£¡£¡£ÕâЩ¶ñÒâÈí¼þÏÂÔØÆ÷»áÔÚÊÜѬȾװ±¸ÉÏ×°ÖÃAnubis¡£¡£¡£¡£ÕâÅú×¢Ò»¸öÌØ¶¨µÄ¶ñÒâÈí¼þ·ÖÏúÉÌÒѾ­´ÓʹÓÃMarcherתÏòÁË·Ö·¢Anubis¡£¡£¡£¡£


ËÄ¡¢¹¦Ð§ÏÈÈÝ


AnubisбäÖÖÕûºÏÁ˶àÖÖÀàÐͶñÒâÈí¼þ¹¦Ð§ÓÚÒ»Éí£¬£¬ £¬£¬£¬Í¼4ÊÇÆä¹¦Ð§Ê¾Òâͼ£¬£¬ £¬£¬£¬¸Ã±äÖÖ°üÀ¨ÀÕË÷Èí¼þ¹¦Ð§¡¢¼üÅ̼ͼ¹¦Ð§¡¢RAT¹¦Ð§¡¢¶ÌÐÅ×èµ²¹¦Ð§ºÍºô½Ð×ªÒÆ¹¦Ð§µÈ¡£¡£¡£¡£Í¬Ê±£¬£¬ £¬£¬£¬Anubis»¹¿ÉÒÔÇÔÈ¡Êܺ¦Óû§µÄͨѶ¼¡¢¶ÌÐŵÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬¹¥»÷Õß»¹¿ÉÒÔÔ¶³Ì¿ØÖÆÊÜѬȾװ±¸£¬£¬ £¬£¬£¬Ê¹ÓÃÊÜѬȾװ±¸Ïò¹¥»÷ÕßÖ¸¶¨µÄÄ¿µÄ·¢ËÍÌØ¶¨¶ÌÐÅ¡£¡£¡£¡£²»ÄÑÏëÏ󣬣¬ £¬£¬£¬¹¥»÷ÕßÍêÈ«¿ÉÒÔ¶ÔÊܺ¦ÕßµÄÉç½»ÍøÂç¾ÙÐÐÈ«·½Î»ÉøÍ¸ºÍڲƭ¡£¡£¡£¡£

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ4 Anubis¹¦Ð§Ê¾Òâͼ


ͼ5ÊÇÎÒÃÇץȡµ½µÄ¸Ã¶ñÒâ´úÂë±äÖÖºÍC&CЧÀÍÆ÷ͨѶµÄÊý¾Ý°ü£¬£¬ £¬£¬£¬´ÓͼÖпÉÒÔ¿´³ö£¬£¬ £¬£¬£¬¸Ã±äÖÖʹÓÃhttpЭæÅºÍC&CЧÀÍÆ÷¾ÙÐÐͨѶ£¬£¬ £¬£¬£¬Í¨Ñ¶Êý¾Ý±»¼ÓÃÜ´¦Öóͷ£ºó¾ÙÐд«Êä¡£¡£¡£¡£ÎÒÃÇʹÓÃÆÊÎö³öµÄ½âÃÜËã·¨¶ÔͼÖмÓÃÜÊý¾Ý¾ÙÐнâÃÜ£¬£¬ £¬£¬£¬»®·Ö»ñµÃ¡°aa5193bdfeb39625:(CHINA  MOBILE):4.4.4:cn::AOSP on HammerHead (aosp_hammerhead):V::0:0:¡±ºÍ¡°|OK|¡±£¬£¬ £¬£¬£¬ºÜÏÔÈ»ÊÇÒ»¸öľÂíÉÏÏß°ü¡£¡£¡£¡£

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ5 C&CÉÏÏß°ü


C&CÏÂÁîºÍÆä¸½¼ÓÊý¾Ý½ÓÄÉͬÑùµÄ¼ÓÃܼƻ®´«Ê䣬£¬ £¬£¬£¬ÎÒÃǽ«¸Ã¶ñÒâ´úÂë±äÖÖ°üÀ¨µÄÖ÷ÒªC&CÏÂÁî¼°Æä¼ÄÒå¹éÄɵ½Á˱í2£º

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

±í2 Ö÷ÒªµÄC&CÏÂÁîºÍ¹¦Ð§


Îå¡¢µä·¶ÐÐΪÆÊÎö

5.1¡¢ÇÔÈ¡Êܺ¦ÕßÒøÐÐÕË»§Æ¾Ö¤


Anubis¼àÊÓÄ¿µÄÓ¦ÓóÌÐòÆô¶¯£¬£¬ £¬£¬£¬È»ºóʹÓöÔÓ¦µÄ´¹ÂÚÆÁÄ»ÁýÕÖµôÕýµ±µÄÓ¦ÓóÌÐòÒÔÇÔÈ¡Êܺ¦ÕßµÄÕË»§Æ¾Ö¤£¨¼ûͼ6ºÍͼ7£©£¬£¬ £¬£¬£¬Í¬Ê±»áʹÓöÌÐÅ×èµ²¹¦Ð§À´×èµ²ÒøÐз¢Ë͸øÊܺ¦ÕßµÄËùÓжÌÐÅ£¨¼ûͼ8£©£¬£¬ £¬£¬£¬ÕâÑù¹¥»÷Õß¾ÍÈÆ¹ýÁËÒøÐеÄË«²ãÉí·ÝÈÏÖ¤£¬£¬ £¬£¬£¬ÀֳɶÔÊܺ¦ÕߵĹ¤Òµ¾ÙÐÐÏ´½Ù¡£¡£¡£¡£

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ6 ¼ÓÔØ´¹ÂÚÒ³ÃæµÄ´úÂë


AnubisαÔìµÄ´¹ÂÚÒ³Ãæ£º

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ7 αÔìµÄ´¹ÂÚÒ³Ãæ


¶ñÒâ´úÂ뽫×ÔÉíÉèÖóÉĬÈ϶ÌÐÅÓ¦Ó㬣¬ £¬£¬£¬×èµ²Óû§¶ÌÐÅ£º

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ8 ×èµ²Óû§¶ÌÐÅ


¹¥»÷ÕßµÄÐ®ÖÆÄ¿µÄÏÕЩº­¸ÇÈ«Ììϸ÷´ó½ðÈÚ»ú¹¹µÄÊÖ»úAPP£¬£¬ £¬£¬£¬×ÜÊýµÖ´ïÁË300¶à¸ö£¬£¬ £¬£¬£¬Éæ¼°Öйú¡¢ÃÀ¹ú¡¢Ó¢¹ú¡¢ÈÕ±¾¡¢ÖйúÏã¸Û¡¢·¨¹úµÈ40¶à¸ö¹ú¼ÒºÍµØÇø£¬£¬ £¬£¬£¬²¿·ÖÄ¿µÄ½ðÈÚAPPµÄ°üÃû¼û±í3£º

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

±í3 ²¿·ÖÄ¿µÄ½ðÈÚAPP


5.2¡¢¼ÓÃÜÊÜѬȾװ±¸Îļþ£¬£¬ £¬£¬£¬¶ÔÊܺ¦Õß¾ÙÐÐÀÕË÷


²î±ðÓÚ³£¼ûµÄÖ»ÊǼòÆÓեȡÊܺ¦Õß»á¼ûÊÖ»ú½çÃæµÄËø¶¨ÆÁÄ»µÄÀÕË÷Èí¼þ£¬£¬ £¬£¬£¬Anubis¶ÔÊܺ¦Óû§µÄÎļþ¾ÙÐÐÁ˼ÓÃÜ£¬£¬ £¬£¬£¬¼ÓÃܵÄĿ¼°üÀ¨¡°/mnt¡±¡¢¡°/mount¡±¡¢¡°/sdcard¡±¡¢¡°/storage¡±ÒÔ¼°Óû§µÄÄÚÔÚ´æ´¢¿¨Ä¿Â¼£¬£¬ £¬£¬£¬¼ûͼ9¡£¡£¡£¡£

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ9 ¼ÓÃܵÄÎļþĿ¼


AnubisµÄÄ£¿£¿£¿£¿éʹÓÃ256λ¶Ô³ÆÃÜÔ¿¶ÔÎļþ¾ÙÐмÓÃÜ´¦Öóͷ££¬£¬ £¬£¬£¬²¢ÒÔ¡°.AnubisCrypt¡±×÷Ϊ¼ÓÃÜÎļþµÄÀ©Õ¹Ãû£¬£¬ £¬£¬£¬¼ûͼ10¡£¡£¡£¡£

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ10 ¼ÓÃܲÙ×÷


ÔÚÍê³ÉÎļþ¼ÓÃܺ󣬣¬ £¬£¬£¬Anubis»á¼ÓÔØÆäËø¶¨Ò³Ã棨ͼ11£©£¬£¬ £¬£¬£¬ÌáÐÑÊܺ¦Óû§µÄÊÖ»úÒѾ­±»Ëø¶¨²¢ÇÒÎļþ±»¼ÓÃÜ£¬£¬ £¬£¬£¬ÐèÒªÊܺ¦Óû§Ö§¸¶±ÈÌØ±Ò·½¿É¶ÔÎļþ¾ÙÐнâÃÜ¡£¡£¡£¡£

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ11 ¼ÓÔØËø¶¨Ò³Ãæ


Ëø¶¨Ò³ÃæhtmllockerÊÇ´ÓÔ¶³ÌЧÀÍÆ÷¶¯Ì¬»ñÈ¡µ½µÄ²¢ÉúÑÄÔÚÆäÉèÖÃÎļþset.xmlÖУ¬£¬ £¬£¬£¬Èçͼ12£¬£¬ £¬£¬£¬ÎÒÃÇ¿ÉÒÔ¿´µ½FBI WARNINGµÄÀÕË÷ÐÅÏ¢£º¼û¸æÊܺ¦Óû§µÄÊÖ»ú±»Ëø¶¨£¬£¬ £¬£¬£¬²¢ÇÒËùÓеÄÎļþ±»¼ÓÃÜ£¬£¬ £¬£¬£¬Óû§µÄÊý¾Ý½«»á±»´«Ë͵½FBI£¬£¬ £¬£¬£¬³ý·ÇÊܺ¦Óû§Ö§¸¶·£½ð·½¿É½âÃÜ¡£¡£¡£¡£


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ12 ÉèÖÃÎļþÖеÄËø¶¨Ò³Ãæ´úÂë


ͼ13ÊÇhtmllocker´úÂë¼ÓÔØºóµÄÒ³Ãæ£¬£¬ £¬£¬£¬¸ÃÒ³Ãæ×öµÄÏ൱±ÆÕ棬£¬ £¬£¬£¬ÔÚ¡°FBI WARNING¡±ÎÄ×ÖÉÏ·½ÊÇ¡°FBI¡±µÄLOGO £¬£¬ £¬£¬£¬Ï·½¼´ÊÇͼ12ÉèÖÃÎļþÖеÄÄÇÒ»¶ÎÀÕË÷ÐÅÏ¢¡£¡£¡£¡£

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ13 Ëø¶¨Ò³Ãæ


5.3¡¢Ê¹ÓÃ×°±¸²¦ºÅÓ¦ÓÃÖ´ÐÐUSSDÏÂÁî


USSDΪGSMϵͳËùʹÓõÄÒ»ÖÖͨѶЭÒ飬£¬ £¬£¬£¬Óû§¿ÉÒÔͨ¹ýÊÖ»ú²¦ºÅ³ÌÐòÊäÈëÌØ¶¨µÄÖ¸ÁîÈ¡µÃϵͳЧÀÍÉÌÌṩµÄЧÀÍ£¬£¬ £¬£¬£¬ºÃ±ÈÅÌÎÊÔ¤¸¶¿¨Óà¶îµÈ£¬£¬ £¬£¬£¬Ò²¿ÉÒÔÓÃÓÚÅÌÎÊÊÖ»úÄÚ²¿ÐÅÏ¢£¬£¬ £¬£¬£¬Èç¡°*#06#¡±¿ÉÒÔÅÌÎÊÊÖ»úµÄIMEIÂë¡£¡£¡£¡£Ò²Óв¿±ðÀë»ú³§ÉÌʹÓÃ×Ô½ç˵µÄUSSDÖ¸ÁîµÐÊÖ»ú×öÌØÊâµÄÉ趨»ò²Ù×÷£¬£¬ £¬£¬£¬ÀýÈ罫ÊÖ»ú»Ö¸´Îª³ö³§ÉèÖ㬣¬ £¬£¬£¬¿ªÆôÊÖ»úµÄ¹¤³ÌģʽµÈ¡£¡£¡£¡£


¸Ã±äÖÖʹÓÃÊÜѬȾװ±¸µÄ²¦ºÅ³ÌÐòÀ´Ö´ÐÐÔ¶³ÌЧÀÍÆ÷´«À´µÄÖ¸Á£¬ £¬£¬£¬´Óͼ14ÖÐÎÒÃÇ¿ÉÒÔ¿´µ½£¬£¬ £¬£¬£¬¹¥»÷ÕßÊ×ÏÈ·­¿ª²¦ºÅ³ÌÐò£¬£¬ £¬£¬£¬È»ºóÊäÈë´ÓC&C»ñÈ¡µ½µÄ¶ñÒâÖ¸Á£¬ £¬£¬£¬²î±ðµÄÖ¸Áî¶ÔÓ¦²î±ðµÄ¹¦Ð§¡£¡£¡£¡£²»É¨³ý¹¥»÷Õß¶ÔÊÜѬȾװ±¸»Ö¸´³ö³§Ä£Ê½»òÕß¶ñÒâÃûÌû¯ÊÜѬȾװ±¸´æ´¢¿¨µÈ¿ÉÄÜÐÔ¡£¡£¡£¡£

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ14 ʹÓÃ×°±¸²¦ºÅÓ¦ÓÃÖ´ÐÐUSSDÏÂÁî


5.4¡¢ÉèÖúô½Ðת½Ó


ÉèÖÃÊÜѬȾװ±¸µÄºô½Ðת½ÓºÅÂëΪ¹¥»÷ÕßÔ¶³ÌÖ¸¶¨µÄÊÖ»úºÅÂ루¼ûͼ15£©¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈ·­¿ªÊÜѬȾװ±¸µÄ²¦ºÅ³ÌÐò£¬£¬ £¬£¬£¬È»ºóͨ¹ýÊäÈë¡°*21*ÊÖ»úºÅÂë#¡±¶ÔÊÜѬȾװ±¸ÉèÖúô½Ðת½Ó¡£¡£¡£¡£ÕâÑù£¬£¬ £¬£¬£¬¹¥»÷Õ߾ͿÉÒÔÀÖ³É×èµ²Êܺ¦Óû§µÄÊÖ»úÀ´µç£¬£¬ £¬£¬£¬²¢ÇÒ¿ÉÒÔʹÓô˹¦Ð§¶ÔÊܺ¦Óû§¾ÙÐÐڲƭ¡£¡£¡£¡£

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ͼ15 ÉèÖúô½Ðת½Ó


Áù¡¢½¨Òé


½¨ÒéÓû§²»ÒªÈÝÒ×µã»÷¶ÌÐÅÖеIJ»Ã÷Á´½Ó£¬£¬ £¬£¬£¬²»Òª×°Öò»Ã÷ȪԴµÄAPP¡£¡£¡£¡£¶ÔÉêÇë¿ÉÒÉȨÏÞÓÈÆäÊǶÌÐŶÁд¡¢´òµç»°ÒÔ¼°ÐèÒª¼¤»î×°±¸ÖÎÀíÆ÷µÄAPPÒªÌØÊâ×¢ÖØ£¬£¬ £¬£¬£¬Éæ¼°µ½¿î×ӵIJÙ×÷Òª¸ñÍâÉóÉ÷¡£¡£¡£¡£Óöµ½²Ù×÷Òì³££¬£¬ £¬£¬£¬Ó¦µ±ÊµÊ±Ê¹ÓÃɱ¶¾Èí¼þ²éɱ»òÕÒרÈË´¦Öóͷ£¡£¡£¡£¡£ÏÖÔÚ»¥ÁªÍøÉÏÒ²³äÂú×ÅÐÎÐÎɫɫµÄµÚÈý·½APPÏÂÔØÕ¾µã£¬£¬ £¬£¬£¬Ðí¶àÉõÖÁ³ÉÁ˶ñÒâÓ¦ÓõÄÅú·¢¼¯É¢µØ¡£¡£¡£¡£Óû§Ó¦ÌØÊâ×¢ÖØ²»Ó¦ÈÝÒ×µÄÔÚһЩÏÂÔØÕ¾µãÏÂÔØAPP£¬£¬ £¬£¬£¬Ö»¹Ü´Ó¹ÙÍøÏÂÔØËùÐèAPPÓ¦Ó㬣¬ £¬£¬£¬ÔÚ²»µÃ²»´ÓµÚÈý·½ÏÂÔØÕ¾µãÏÂÔØÈí¼þʱ£¬£¬ £¬£¬£¬Òª¸ß¶È¼á³ÖСÐÄ£¬£¬ £¬£¬£¬ÈÏÕæÕç±ð£¬£¬ £¬£¬£¬±ÜÃâÎó϶ñÒâÓ¦Ó㬣¬ £¬£¬£¬¸ø×Ô¼ºÔì³É²»ÐëÒªµÄƶÀ§ºÍËðʧ¡£¡£¡£¡£


²Î¿¼Á´½Ó£º
https://securityintelligence.com/anubis-strikes-again-mobile-malware-continues-to-plague-users-in-official-app-stores/

https://blogs.quickheal.com/android-malware-combines-banking-trojan-keylogger-ransomware-one-package/