±ÈÀûʱ³ÆÆä¹ú·À²¿ºÍÄÚÕþ²¿Ôâµ½¶à¸öAPTÍÅ»ïµÄ¹¥»÷
°ä²¼¹¦·ò 2022-07-211¡¢±ÈÀûʱ³ÆÆä¹ú·À²¿ºÍÄÚÕþ²¿Ôâµ½¶à¸öAPTÍÅ»ïµÄ¹¥»÷
¾Ý7ÔÂ20ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬±ÈÀûʱ±í½»²¿³¤Ð¹Â©ÁËÕë¶ÔFPSÄÚÕþ²¿ºÍ¹ú·À²¿µÄÓ°ÏìÆäÖ÷Ȩ¡¢ÃñÖ÷¡¢°²È«ºÍÕû¸öÉç»áµÄ¶ñÒâÍøÂç¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£±ÈÀûʱµ±¾ÖµÄÉêÃ÷ÖÐÌáµ½£¬£¬£¬£¬£¬£¬£¬£¬Õë¶ÔÄÚÕþ²¿µÄ¹¥»÷Éæ¼°APT×éÖ¯APT27¡¢APT30¡¢APT31£¬£¬£¬£¬£¬£¬£¬£¬Õë¶Ô¹ú·À²¿µÄ¶ñÒâ»î¶¯ÓëGalliumÓйء£¡£¡£¡£¡£¡£¡£¡£GalliumÓÚ2019Äê12Ô³õ´Î±»Åû¶£¬£¬£¬£¬£¬£¬£¬£¬MSTIC³ÆÆäÖØÒªÕë¶ÔÈ«ÇòµÄµçÐÅÌṩÉÌ£¬£¬£¬£¬£¬£¬£¬£¬×Ô2021ÄêÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬ÆðÍ·¹¥»÷°¢¸»º¹¡¢°Ä´óÀûÑǺͱÈÀûʱµÈ¹ú¡£¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/133425/apt/belgium-claims-china-hit-its-ministries.html
2¡¢½¨²Ä¹«Ë¾KnaufÔâµ½Black BastaÍÅ»ïµÄÀÕË÷¹¥»÷
¾ÝýÌå7ÔÂ19ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬½¨²Ä¹«Ë¾¿ÉÄ͸££¨Knauf£©Ôâµ½ÁËBlack BastaµÄÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚ6ÔÂ29ÈÕÍíÉÏ£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁ˸ù«Ë¾µÄÒµÎñÔËÓª£¬£¬£¬£¬£¬£¬£¬£¬ÆÈʹÆäÈ«ÇòITÍŶӹعØËùÓÐϵͳÒÔ½øÐиôÀë¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬KnaufÈÔÔÚ½øÐÐȡ֤µ÷²é¡¢ÊÂÎñÏìÓ¦ºÍ²¹¾È¡£¡£¡£¡£¡£¡£¡£¡£ÀÕË÷ÍÅ»ïBlack BastaÓÚ7ÔÂ16ÈÕÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏÁгö¸Ã¹«Ë¾£¬£¬£¬£¬£¬£¬£¬£¬²¢°µÊ¾¶ÔÕâ´ÎÊÂÎñÕÆ¹Ü¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÒѹ«¿ª±»µÁÎļþµÄ20%£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬µç×ÓÓʼþ¡¢Óû§Í´´¦¡¢Ô±¹¤ÁªÏµ·½Ê½¡¢³ö²úÎĵµºÍÉí·Ý֤ɨÃè¼þµÄÑù±¾¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/building-materials-giant-knauf-hit-by-black-basta-ransomware-gang/
3¡¢×êÑÐÈËÔ±ÑÝʾÀûÓÃSATAµçÀÂÔÚÆøÏ¶ÏµÍ³ÇÔÈ¡Êý¾ÝµÄ²½Öè
ýÌå7ÔÂ19Èճƣ¬£¬£¬£¬£¬£¬£¬£¬ÒÔÉ«Áб¾¹ÅÀï°²´óѧµÄ×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÖÖ´ÓÆøÏ¶ÏµÍ³ÖÐÇÔÈ¡Êý¾ÝµÄв½Öè¡£¡£¡£¡£¡£¡£¡£¡£ÕâÖÖÐµĹ¥»÷²½Öè³ÆÎªSATAn£¬£¬£¬£¬£¬£¬£¬£¬ËüʹÓôóÎÞÊýÍÆËã»úÄÚ²¿µÄ´®ÐÐATA(SATA)µçÀÂ×÷ΪÎÞÏßÌìÏߣ¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÎÞÏßµçÐźŷ¢ËÍÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£ÒªÊ¹SATAn¹¥»÷³É¹¦£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÊ×ÏȱØÒªÏ°È¾Ö¸±êÆøÏ¶ÏµÍ³¡£¡£¡£¡£¡£¡£¡£¡£´ËÀ๥»÷Ò²´æÔÚÏÞ¶È£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ý¸÷Àà³¢ÊÔÈ·¶¨£¬£¬£¬£¬£¬£¬£¬£¬´ÓÆøÏ¶ÏµÍ³µ½½Ó¹ÜÆ÷µÄ×î´ó¾àÀë²»Äܳ¬¹ý120ÀåÃ×£¬£¬£¬£¬£¬£¬£¬£¬²»È»ÎóÂëÂÊÔö³¤Ì«¶à£¬£¬£¬£¬£¬£¬£¬£¬ÎÞ·¨±£ÕÏÐÅÏ¢µÄÆëÈ«ÐÔ£¨³¬¹ý15%£©¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/air-gapped-systems-leak-data-via-sata-cable-wifi-antennas/
4¡¢APT29ÀûÓÃGoogle DriveµÈºÏ·¨ÔÆ·þÎñ·Ö·¢¶ñÒâÈí¼þ
Unit 42ÔÚ7ÔÂ19ÈÕÅû¶Á˶íÂÞ˹ºÚ¿ÍÍÅ»ïAPT29ÀûÓÃÔÚÏß´æ´¢·þÎñ£¨DropBoxºÍGoogle Drive£©·Ö·¢¶ñÒâÈí¼þµÄ´¹µö¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¾ÝÐÅ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ»î¶¯ÔÚ2022Äê5ÔÂÖÁ6ÔÂÆÚ¼äÕë¶ÔÎ÷·½µÄ¶à¸ö±í½»Ê¹ÍÅ£¬£¬£¬£¬£¬£¬£¬£¬»î¶¯ÖÐʹÓõĵö¶üÅú×¢£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖØÒªÕë¶ÔµÄÊDZí¹úפÆÏÌÑÑÀ´óʹ¹ÝºÍ±í¹úפ°ÍÎ÷´óʹ¹Ý¡£¡£¡£¡£¡£¡£¡£¡£´¹µöÎĵµÔ̺¬Ö¸Ïò¶ñÒâHTMLÎļþ(EnvyScout)µÄÁ´½Ó£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþ³äÈÎÆäËü¶ñÒâÎļþµÄdropper£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Cobalt Strike payload¡£¡£¡£¡£¡£¡£¡£¡£
https://unit42.paloaltonetworks.com/cloaked-ursa-online-storage-services-campaigns/
5¡¢ESET·¢ÏÖÕë¶Ômac OSµÄжñÒâÈí¼þCloudMensis
7ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ESET°ä²¼Á˹ØÓÚÕë¶ÔmacOSµÄжñÒâÈí¼þCloudMensisµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ2022Äê4Ô³õ´Î·¢ÏÖÕâÖÖжñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬ËüʹÓù«¹²ÔÆ´æ´¢·þÎñpCloud¡¢Yandex DiskºÍDropbox½øÐÐC2ͨѶ¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖ°ÄÜÅú×¢£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßµÄÖØÒªÖ¸±êÊÇͨ¹ýÇÔÈ¡Îĵµ¡¢»÷¼ü¼Í¼ºÍÆÁÄ»½ØÍ¼µÈ·½Ê½´ÓÖ¸±êMacÖÐÍøÂçÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£CloudMensisÊÇÓÃObjective-C¿ª·¢µÄ£¬£¬£¬£¬£¬£¬£¬£¬ESET·ÖÎöµÄÑù±¾ÊÇÕë¶ÔIntelºÍApple¼Ü¹¹±àÒëµÄ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷µÄ³õʼϰȾý½éºÍÖ¸±êÒÀȻδ֪¡£¡£¡£¡£¡£¡£¡£¡£
https://www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware/
6¡¢8220 GangµÄÔÆ½©Ê¬ÍøÂçÒѽٳÖ3Íò¶ą̀Ö÷»úÀ´ÍÚ¿ó
SentinelLabsÔÚ7ÔÂ18Èճƣ¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ï8220 GangµÄÔÆ½©Ê¬ÍøÂç¹æÄ£ÒÑ´Ó2021ÄêÖÐÆÚµÄ2000̨Ö÷»úÀ©´óµ½30000̨¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï×Ô2017ÄêÆðÍ·»îÔ¾£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÍ¨¹ýÒÑÖª·ì϶ºÍÔ¶³Ì½Ó¼û±©Á¦ÆÆ½âÀ´Ï°È¾ÔÆÖ÷»ú£¬£¬£¬£¬£¬£¬£¬£¬²¢²Ù¿Ø½©Ê¬ÍøÂçºÍ¼ÓÃܿ󹤡£¡£¡£¡£¡£¡£¡£¡£ÔÚ×î½üµÄÒ»´Î¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïÀûÓÃÁËа汾µÄIRC½©Ê¬ÍøÂç¡¢PwnRig¼ÓÃܿ󹤼°ÆäͨÓÃϰȾ¾ç±¾¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬¼ÓÃÜÇ®±Ò¼ÛÖµµÄ×ÅÂäÆÈʹ¹¥»÷ÕßÀ©´óÆäÐж¯¹æÄ££¬£¬£¬£¬£¬£¬£¬£¬ÒÔά³ÖÒ»ÑùµÄÀûÈ󡣡£¡£¡£¡£¡£¡£¡£
https://www.sentinelone.com/blog/from-the-front-lines-8220-gang-massively-expands-cloud-botnet-to-30000-infected-hosts/


¾©¹«Íø°²±¸11010802024551ºÅ