¼ÓÄôóijÌìÈ»Æø¹Ü·Ôâµ½ZaryaµÄ¹¥»÷¿ÉÄܻᱬը

°ä²¼¹¦·ò 2023-04-28

1¡¢¼ÓÄôóijÌìÈ»Æø¹Ü·Ôâµ½ZaryaµÄ¹¥»÷¿ÉÄܻᱬը


¾ÝýÌå4ÔÂ26ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬¼ÓÄôóijÌìÈ»Æø¹ÜÔâµ½¹¥»÷£¬£¬£¬£¬£¬ £¬¿ÉÄÜ»áÒý·¢±¬Õ¨¡£ ¡£¡£¡£¡£¡£¡£Å¦Ô¼Ê±±¨³Æ£¬£¬£¬£¬£¬ £¬Ð¹Â¶µÄÃÀ¹úµý±¨Îļþ½ÒʾÁËÕâÒ»ÊÂÎñ¡£ ¡£¡£¡£¡£¡£¡£ÆäÖÐÒ»·ÝÎļþÔ̺¬ZaryaÓëFSBÔ±¹¤µÄ¶Ô»°£¬£¬£¬£¬£¬ £¬ËûÃÇÔ¤¼Æ³É¹¦µÄ¹¥»÷½«µ¼ÖÂÅ䯸վ²úÉú±¬Õ¨£¬£¬£¬£¬£¬ £¬²¢Ôڼල¼ÓÄôóÐÂÎű¨Â·¿´ÊÇ·ñÓб¬Õ¨¼£Ïó¡£ ¡£¡£¡£¡£¡£¡£¸ÃÎļþµÄÕæÊµÐÔÉÐδµÃµ½Ö¤Êµ¡£ ¡£¡£¡£¡£¡£¡£¼ÓÄôó×ÜÀíÈ·ÈÏÁËÕë¶ÔÌìÈ»Æø¹Ü·µÄÍøÂç¹¥»÷£¬£¬£¬£¬£¬ £¬µ«ËûÖ¸³ö¼ÓÄôóµÄÈκÎÄÜÔ´»ù´¡ÉèÊ©¶¼Ã»ÓÐÊܵ½ÏÖʵÇÖº¦¡£ ¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/145307/cyber-warfare-2/canadian-gas-pipeline-disruptive-attack.html


2¡¢Alloy TaurusÀûÓÃPingPullбäÌå¹¥»÷ÄϷǺÍÄá²´¶û


4ÔÂ26ÈÕ£¬£¬£¬£¬£¬ £¬Unit 42³Æ×î½ü·¢ÏÖAlloy TaurusÍÅ»ïʹÓÃPingPullºóÃŵÄбäÌå¹¥»÷LinuxϵͳµÄ»î¶¯£¬£¬£¬£¬£¬ £¬¸Ã»î¶¯ÖØÒªÕë¶ÔÄϷǺÍÄá²´¶û¡£ ¡£¡£¡£¡£¡£¡£3ÔÂ7ÈÕ£¬£¬£¬£¬£¬ £¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÉÏ´«µ½VirusTotalµÄPingPullµÄLinux±äÌ壬£¬£¬£¬£¬ £¬ËüµÄ¼ì²âÂʼ«¶ÈµÍ¡£ ¡£¡£¡£¡£¡£¡£PingPullÖÐʹÓõĺÅÁî´¦Ö÷¨Ê½ÓëÔÚÁíÒ»¸ö¶ñÒâÈí¼þChina ChopperµÄÖз¢ÏֵĺÅÁî´¦Ö÷¨Ê½ÀàËÆ¡£ ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬Unit 42»¹·¢ÏÖÁËÒ»¸öеÄELFºóÃÅSword2033£¬£¬£¬£¬£¬ £¬Á´½Óµ½Ò»ÑùµÄC2»ù´¡ÉèÊ©£¬£¬£¬£¬£¬ £¬Ö§³ÖÉÏ´«¡¢Ð¹Â¶ÎļþºÍÖ´ÐкÅÁîÈý¸ö¸ù»ùÖ°ÄÜ¡£ ¡£¡£¡£¡£¡£¡£


https://unit42.paloaltonetworks.com/alloy-taurus/


3¡¢FIN7ÍÅ»ïÀûÓÃ×î½ü½¨¸´µÄVeeam·ì϶·Ö·¢ºóÃÅLizar


WithSecureÔÚ4ÔÂ26ÈÕÅû¶ÁËFIN7ÍÅ»ïÕë¶ÔVeeam±¸·Ý·þÎñÆ÷µÄ¹¥»÷»î¶¯¡£ ¡£¡£¡£¡£¡£¡£3ÔÂ28ÈÕ£¬£¬£¬£¬£¬ £¬×êÑÐÈËÔ±ÔÚÔËÐÐVeeam Backup & ReplicationÈí¼þµÄ·þÎñÆ÷Éϼì²âµ½³õʼ»î¶¯¡£ ¡£¡£¡£¡£¡£¡£ÓëVeeam BackupÊ·ýÓйصÄSQL·þÎñÆ÷¹ý³Ìsqlservr.exeÖ´ÐÐÁËÒ»¸öshellºÅÁ£¬£¬£¬£¬ £¬¸ÃºÅÁîÔÚÄÚ´æÖÐÏÂÔØ²¢Ö´ÐÐPowerShell¾ç±¾¡£ ¡£¡£¡£¡£¡£¡£ÕâЩPowerShell¾ç±¾µÄËùÓÐÊ·ý¶¼ÊÇPowertrash dropper£¬£¬£¬£¬£¬ £¬ËüÓÃÓÚ·Ö·¢ºóÃÅDiceloader£¨Ò²³ÆÎªLizar£©¡£ ¡£¡£¡£¡£¡£¡£¸Ã»î¶¯µÄ³õʼ½Ó¼ûºÍÖ´ÐкܿÉÄÜÊÇͨ¹ý×î½ü½¨¸´µÄVeeam Backup & Replication·ì϶£¨CVE-2023-27532£©ÊµÏֵġ£ ¡£¡£¡£¡£¡£¡£


https://labs.withsecure.com/publications/fin7-target-veeam-servers


4¡¢ÎÚ¿ËÀ¼¾¯·½¿ÛÁôÔøÏúÊÛ³¬¹ý3ÒÚ¹«ÃñÓ×ÎÒÐÅÏ¢µÄÏÓÒÉÈË


ýÌå4ÔÂ26Èճƣ¬£¬£¬£¬£¬ £¬ÎÚ¿ËÀ¼ÍøÂ羯Ա¿ÛÁôÁËÀ´×ÔNetishynµÄÒ»Ãû36ËêÄÐ×Ó£¬£¬£¬£¬£¬ £¬×ïÃûÊÇÏúÊÛ³¬¹ý3ÒÚÎÚ¿ËÀ¼ºÍÅ·ÖÞÁйú¹«ÃñµÄÓ×ÎÒÐÅÏ¢¡£ ¡£¡£¡£¡£¡£¡£ÏÓÒÉÈËʹÓÃTelegramÏò¸ÐÐËÖµÄÂò¼ÒÍÆÏú±»µÁÊý¾Ý£¬£¬£¬£¬£¬ £¬Æ¾¾ÝÊý¾ÝÁ¿¼°Æä¼ÛÖµ£¬£¬£¬£¬£¬ £¬Òª¼ÛÔÚ500µ½2000ÃÀÔªÖ®¼ä¡£ ¡£¡£¡£¡£¡£¡£Éæ¼°»¤ÕÕÊý¾Ý¡¢ÄÉ˰È˱àºÅ¡¢µ®ÉúÖ¤Ã÷¡¢¼ÝÊ»ÅÆÕÕºÍÒøÐÐÕË»§Êý¾ÝµÈÐÅÏ¢¡£ ¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬ £¬·¨ÂÉÈËÔ±²éÊÕÁË36¸öÓ²ÅÌÇý¶¯Æ÷¡¢ÍÆËã»úºÍ·þÎñÆ÷É豸£¬£¬£¬£¬£¬ £¬ÆäÖÐÔ̺¬¶à¸öÊý¾Ý¿â£¬£¬£¬£¬£¬ £¬ÆäÆðÔ´½«Í¨¹ýºóÐø·ÖÎöÈ·¶¨¡£ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ukrainian-arrested-for-selling-data-of-300m-people-to-russians/


5¡¢Linux°æ±¾µÄRTM LockerÕë¶ÔVMware ESXi·þÎñÆ÷


UptycsÔÚ4ÔÂ26ÈÕ°ä²¼ÁËÒ»·Ý»ã±¨£¬£¬£¬£¬£¬ £¬·ÖÎöÁËRTM LockerµÄÒ»¸öLinux±äÌ壬£¬£¬£¬£¬ £¬¸Ã±äÌå»ùÓÚÏÖÒÑDzɢµÄBabukÀÕË÷Èí¼þµÄÔ´´úÂë¡£ ¡£¡£¡£¡£¡£¡£RTM LockerµÄLinux°æ±¾¼ÓÃÜ·¨Ê½ËƺõÊÇרÃÅΪ¹¥»÷VMware ESXiϵͳ¿ª·¢µÄ£¬£¬£¬£¬£¬ £¬ÓÉÓÚËüÔ̺¬Á˺ܶàÓÃÓÚÖÎÀíÐé¹¹»úµÄºÅÁî¡£ ¡£¡£¡£¡£¡£¡£ÓëBabukÒ»Ñù£¬£¬£¬£¬£¬ £¬RTMʹÓÃËæ»úÊýÌìÉúºÍECDH¶ÔCurve25519½øÐзǶԳƼÓÃÜ£¬£¬£¬£¬£¬ £¬µ«ËüûÓÐʹÓÃSosemanuk£¬£¬£¬£¬£¬ £¬¶øÊÇÒÀ¸½ChaCha20½øÐжԳƼÓÃÜ¡£ ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬ £¬ESXi°æ±¾µÄ´æÔÚ£¬£¬£¬£¬£¬ £¬×ãÒÔ½«RTM Locker¹éÀàΪÕë¶ÔÆóÒµµÄ³Á´óÍþв¡£ ¡£¡£¡£¡£¡£¡£


https://www.uptycs.com/blog/rtm-locker-ransomware-as-a-service-raas-linux


6¡¢LayerX°ä²¼¹ØÓÚ2023Äêä¯ÀÀÆ÷°²È«µÄµ÷²é·ÖÎö»ã±¨


¾Ý4ÔÂ26ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬LayerX°ä²¼¹ØÓÚ2023Äêä¯ÀÀÆ÷°²È«µÄµ÷²é·ÖÎö»ã±¨¡£ ¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ £¬ÔÚ´Óǰ12¸öÔÂÖУ¬£¬£¬£¬£¬ £¬87%µÄall-SaaSºÍ79%»ìºÏ»·¾³ÖеÄCISO¶¼¾­Àú¹ý°²È«ÊÂÎñ¡£ ¡£¡£¡£¡£¡£¡£ÕÊ»§ÊÕÊÜÊÇ×îÁîÈËÓÇÓôµÄÎÊÌ⣬£¬£¬£¬£¬ £¬48%µÄÈ˽«Í´´¦ÍøÂç´¹µöÁÐΪ·çÏÕ×î¸ßµÄä¯ÀÀÆ÷Íþв£¬£¬£¬£¬£¬ £¬Æä´ÎÊǶñÒâä¯ÀÀÆ÷À©´ó(37%)¡¢¶ñÒâÈí¼þÏÂÔØ(9%)ºÍä¯ÀÀÆ÷·ì϶(6%)¡£ ¡£¡£¡£¡£¡£¡£´óÎÞÊý×é֯ѡȡÖÁÉÙÁ½ÖÖ°²È«´ëÊ©À´Õмܴ¹µö¹¥»÷£¬£¬£¬£¬£¬ £¬79%ʹÓÃÍøÂ簲ȫ¹¤¾ß£¬£¬£¬£¬£¬ £¬ÀýÈç·À»ðǽºÍSWG¡£ ¡£¡£¡£¡£¡£¡£


https://go.layerxsecurity.com/2023-browser-security-survey