2019年10月11日,深圳市网络与信息安全信息通报中心发出紧急通告,指出目前知名远程办公工具TeamViewer已经被境外黑客组织APT41攻破,提醒企业组织做好防护措施。也就是说,APT41已经攻破TeamViewer公司的所有防护体,并取得有相关数据权限,危险等级非常高。
请大家可以采取以下措施进行主动防御:
1、近期停止使用TeamViewer远程管理软件并卸载;
2、在防火墙中禁止用于TeamViewer远程通讯的5938端口;
3、通过web应用防火墙或其它设备禁止主机回连teamviewer.com域名。
On October 11, 2019, Shenzhen Network and Information Security Information Center issued an urgent notice stating that the well-known remote office tool TeamViewer has been attacked by the overseas hacker organization APT41, and reminding enterprises to take protective measures. In other words, APT41 has broken all the shields of TeamViewer and obtained relevant data rights, and the hazard level is very high.
Please take the following measures as active defense:
1. Stop using TeamViewer remote management software and uninstall it for recent period;
2. Prohibit 5938 port used for TeamViewer remote communication in the firewall;
3. Disable the host to connect back to the domain name "teamviewer.com" through a web application firewall or other devices.
新闻资讯链接:http://finance.sina.com.cn/stock/relnews/cn/2019-10-12/doc-iicezuev1670460.shtml