±ÈÀûʱ³ÆÆä¹ú·À²¿ºÍÄÚÕþ²¿Ôâµ½¶à¸öAPTÍÅ»ïµÄ¹¥»÷

Ðû²¼Ê±¼ä 2022-07-21

1¡¢±ÈÀûʱ³ÆÆä¹ú·À²¿ºÍÄÚÕþ²¿Ôâµ½¶à¸öAPTÍÅ»ïµÄ¹¥»÷

     

¾Ý7ÔÂ20ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬±ÈÀûʱÍâ½»²¿³¤Í¸Â¶ÁËÕë¶ÔFPSÄÚÕþ²¿ºÍ¹ú·À²¿µÄÓ°ÏìÆäÖ÷Ȩ¡¢ÃñÖ÷¡¢Çå¾²ºÍÕû¸öÉç»áµÄ¶ñÒâÍøÂç¹¥»÷»î¶¯¡£¡£ ¡£¡£¡£¡£¡£¡£±ÈÀûʱÕþ¸®µÄÉùÃ÷ÖÐÌáµ½£¬£¬£¬£¬£¬£¬Õë¶ÔÄÚÕþ²¿µÄ¹¥»÷Éæ¼°APT×éÖ¯APT27¡¢APT30¡¢APT31£¬£¬£¬£¬£¬£¬Õë¶Ô¹ú·À²¿µÄ¶ñÒâ»î¶¯ÓëGalliumÓйØ¡£¡£ ¡£¡£¡£¡£¡£¡£GalliumÓÚ2019Äê12ÔÂÊ״α»Åû¶£¬£¬£¬£¬£¬£¬MSTIC³ÆÆäÖ÷ÒªÕë¶ÔÈ«ÇòµÄµçÐÅÌṩÉÌ£¬£¬£¬£¬£¬£¬×Ô2021ÄêÒÔÀ´£¬£¬£¬£¬£¬£¬×îÏȹ¥»÷°¢¸»º¹¡¢°Ä´óÀûÑǺͱÈÀûʱµÈ¹ú¡£¡£ ¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/133425/apt/belgium-claims-china-hit-its-ministries.html


2¡¢½¨²Ä¹«Ë¾KnaufÔâµ½Black BastaÍÅ»ïµÄÀÕË÷¹¥»÷

     

¾ÝýÌå7ÔÂ19ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬½¨²Ä¹«Ë¾¿ÉÄ͸££¨Knauf£©Ôâµ½ÁËBlack BastaµÄÀÕË÷¹¥»÷¡£¡£ ¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ6ÔÂ29ÈÕÍíÉÏ£¬£¬£¬£¬£¬£¬Ó°ÏìÁ˸ù«Ë¾µÄÓªÒµÔËÓª£¬£¬£¬£¬£¬£¬ÆÈʹÆäÈ«ÇòITÍŶӹرÕËùÓÐϵͳÒÔ¾ÙÐиôÀë¡£¡£ ¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬KnaufÈÔÔÚ¾ÙÐÐȡ֤ÊӲ졢ÊÂÎñÏìÓ¦ºÍµ÷½â¡£¡£ ¡£¡£¡£¡£¡£¡£ÀÕË÷ÍÅ»ïBlack BastaÓÚ7ÔÂ16ÈÕÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏÁгö¸Ã¹«Ë¾£¬£¬£¬£¬£¬£¬²¢ÌåÏÖ¶Ô´Ë´ÎÊÂÎñÈÏÕæ¡£¡£ ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÒѹûÕæ±»µÁÎļþµÄ20%£¬£¬£¬£¬£¬£¬°üÀ¨µç×ÓÓʼþ¡¢Óû§Æ¾Ö¤¡¢Ô±¹¤ÁªÏµ·½·¨¡¢Éú²úÎĵµºÍÉí·Ý֤ɨÃè¼þµÄÑù±¾¡£¡£ ¡£¡£¡£¡£¡£¡£   


https://www.bleepingcomputer.com/news/security/building-materials-giant-knauf-hit-by-black-basta-ransomware-gang/


3¡¢Ñо¿Ö°Ô±ÑÝʾʹÓÃSATAµçÀÂÔÚÆøÏ¶ÏµÍ³ÇÔÈ¡Êý¾ÝµÄÒªÁì

     

ýÌå7ÔÂ19Èճƣ¬£¬£¬£¬£¬£¬ÒÔÉ«Áб¾¹ÅÀï°²´óѧµÄÑо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖ´ÓÆøÏ¶ÏµÍ³ÖÐÇÔÈ¡Êý¾ÝµÄÐÂÒªÁì¡£¡£ ¡£¡£¡£¡£¡£¡£ÕâÖÖÐµĹ¥»÷ÒªÁì³ÆÎªSATAn£¬£¬£¬£¬£¬£¬ËüʹÓôó´ó¶¼ÅÌËã»úÄÚ²¿µÄ´®ÐÐATA(SATA)µçÀÂ×÷ΪÎÞÏßÌìÏߣ¬£¬£¬£¬£¬£¬Í¨¹ýÎÞÏßµçÐźŷ¢ËÍÊý¾Ý¡£¡£ ¡£¡£¡£¡£¡£¡£ÒªÊ¹SATAn¹¥»÷Àֳɣ¬£¬£¬£¬£¬£¬¹¥»÷ÕßÊ×ÏÈÐèҪѬȾĿµÄÆøÏ¶ÏµÍ³¡£¡£ ¡£¡£¡£¡£¡£¡£´ËÀ๥»÷Ò²±£´æÏÞÖÆ£¬£¬£¬£¬£¬£¬Í¨¹ýÖÖÖÖʵÑéÈ·¶¨£¬£¬£¬£¬£¬£¬´ÓÆøÏ¶ÏµÍ³µ½ÎüÊÕÆ÷µÄ×î´ó¾àÀë²»¿ÉÁè¼Ý120ÀåÃ×£¬£¬£¬£¬£¬£¬²»È»ÎóÂëÂÊÔöÌíÌ«¶à£¬£¬£¬£¬£¬£¬ÎÞ·¨°ü¹ÜÐÅÏ¢µÄÍêÕûÐÔ£¨Áè¼Ý15%£©¡£¡£ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/air-gapped-systems-leak-data-via-sata-cable-wifi-antennas/


4¡¢APT29ʹÓÃGoogle DriveµÈÕýµ±ÔÆÐ§ÀÍ·Ö·¢¶ñÒâÈí¼þ


Unit 42ÔÚ7ÔÂ19ÈÕÅû¶Á˶íÂÞ˹ºÚ¿ÍÍÅ»ïAPT29ʹÓÃÔÚÏߴ洢ЧÀÍ£¨DropBoxºÍGoogle Drive£©·Ö·¢¶ñÒâÈí¼þµÄ´¹ÂÚ¹¥»÷¡£¡£ ¡£¡£¡£¡£¡£¡£¾ÝÐÅ£¬£¬£¬£¬£¬£¬ÕâЩ»î¶¯ÔÚ2022Äê5ÔÂÖÁ6ÔÂʱ´úÕë¶ÔÎ÷·½µÄ¶à¸öÍ⽻ʹÍÅ£¬£¬£¬£¬£¬£¬»î¶¯ÖÐʹÓõÄÓÕ¶üÅú×¢£¬£¬£¬£¬£¬£¬ÆäÖ÷ÒªÕë¶ÔµÄÊÇÍâ¹úפÆÏÌÑÑÀ´óʹ¹ÝºÍÍâ¹úפ°ÍÎ÷´óʹ¹Ý¡£¡£ ¡£¡£¡£¡£¡£¡£´¹ÂÚÎĵµ°üÀ¨Ö¸Ïò¶ñÒâHTMLÎļþ(EnvyScout)µÄÁ´½Ó£¬£¬£¬£¬£¬£¬¸ÃÎļþ³äµ±ÆäËü¶ñÒâÎļþµÄdropper£¬£¬£¬£¬£¬£¬°üÀ¨Cobalt Strike payload¡£¡£ ¡£¡£¡£¡£¡£¡£


https://unit42.paloaltonetworks.com/cloaked-ursa-online-storage-services-campaigns/


5¡¢ESET·¢Ã÷Õë¶Ômac OSµÄжñÒâÈí¼þCloudMensis

     

7ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬ESETÐû²¼Á˹ØÓÚÕë¶ÔmacOSµÄжñÒâÈí¼þCloudMensisµÄÆÊÎö±¨¸æ¡£¡£ ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ2022Äê4ÔÂÊ״η¢Ã÷ÕâÖÖжñÒâÈí¼þ£¬£¬£¬£¬£¬£¬ËüʹÓù«¹²Ôƴ洢ЧÀÍpCloud¡¢Yandex DiskºÍDropbox¾ÙÐÐC2ͨѶ¡£¡£ ¡£¡£¡£¡£¡£¡£Æä¹¦Ð§Åú×¢£¬£¬£¬£¬£¬£¬¹¥»÷ÕßµÄÖ÷ҪĿµÄÊÇͨ¹ýÇÔÈ¡Îĵµ¡¢»÷¼ü¼Í¼ºÍÆÁÄ»½ØÍ¼µÈ·½·¨´ÓÄ¿µÄMacÖÐÍøÂçÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¡£¡£CloudMensisÊÇÓÃObjective-C¿ª·¢µÄ£¬£¬£¬£¬£¬£¬ESETÆÊÎöµÄÑù±¾ÊÇÕë¶ÔIntelºÍApple¼Ü¹¹±àÒëµÄ¡£¡£ ¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬¹¥»÷µÄ³õʼѬȾǰÑÔºÍÄ¿µÄÈÔȻδ֪¡£¡£ ¡£¡£¡£¡£¡£¡£


https://www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware/


6¡¢8220 GangµÄÔÆ½©Ê¬ÍøÂçÒÑÐ®ÖÆ3Íò¶ą̀Ö÷»úÀ´ÍÚ¿ó

     

SentinelLabsÔÚ7ÔÂ18Èճƣ¬£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ï8220 GangµÄÔÆ½©Ê¬ÍøÂç¹æÄ£ÒÑ´Ó2021ÄêÖÐÆÚµÄ2000̨Ö÷»úÀ©´óµ½30000̨¡£¡£ ¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï×Ô2017Äê×îÏÈ»îÔ¾£¬£¬£¬£¬£¬£¬Ö÷Ҫͨ¹ýÒÑÖªÎó²îºÍÔ¶³Ì»á¼û±©Á¦ÆÆ½âÀ´Ñ¬È¾ÔÆÖ÷»ú£¬£¬£¬£¬£¬£¬²¢²Ù¿Ø½©Ê¬ÍøÂçºÍ¼ÓÃܿ󹤡£¡£ ¡£¡£¡£¡£¡£¡£ÔÚ×î½üµÄÒ»´Î¹¥»÷ÖУ¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïʹÓÃÁËа汾µÄIRC½©Ê¬ÍøÂç¡¢PwnRig¼ÓÃܿ󹤼°ÆäͨÓÃѬȾ¾ç±¾¡£¡£ ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬¼ÓÃÜÇ®±Ò¼ÛÇ®µÄϵøÆÈʹ¹¥»÷ÕßÀ©´óÆäÐж¯¹æÄ££¬£¬£¬£¬£¬£¬ÒÔ¼á³ÖÏàͬµÄÀûÈ󡣡£ ¡£¡£¡£¡£¡£¡£


https://www.sentinelone.com/blog/from-the-front-lines-8220-gang-massively-expands-cloud-botnet-to-30000-infected-hosts/