LazarusÀûÓÃÒÑÖª·ì϶ÂŴι¥»÷ijÈí¼þ¹©¸øÉÌ

°ä²¼¹¦·ò 2023-10-30

1¡¢LazarusÀûÓÃÒÑÖª·ì϶ÂŴι¥»÷ijÈí¼þ¹©¸øÉÌ


KasperskyÔÚ10ÔÂ27ÈÕ°ä²¼»ã±¨£¬£¬£¬£¬£¬£¬Åû¶ÁËLazarusÀûÓÃÒÑÖª·ì϶ÂŴι¥»÷Èí¼þ¹©¸øÉ̵Ļ¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬LazarusÂŴι¥»÷ͳһָ±êÅú×¢£¬£¬£¬£¬£¬£¬ÆäÖ÷ÕÅ¿ÉÄÜÊÇÇÔȡԴ´úÂë»ò³¢ÊÔ¹©¸øÁ´¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ÓÚ7ÔÂÖÐÑ®±»·¢ÏÖ£¬£¬£¬£¬£¬£¬Õë¶ÔµÄÊÇÓÃÓÚ¼ÓÃÜÍøÂçͨѶµÄºÏ·¨°²È«Èí¼þ£¬£¬£¬£¬£¬£¬µ«Êǹ¥»÷ÕßËùѡȡµÄ¾ßÌåÀûÓò½ÖèÒÀȻδ֪¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷»î¶¯Ñ¡È¡Á˸´Ôӵļ¼ÊõÀ´Ìá¸ßÆäÒñ±ÎÐÔ²¢Èƹý¼ì²â£¬£¬£¬£¬£¬£¬×îÖÕ×°ÖÃÁËSIGNBTºÍLPEClientµÈ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£


https://securelist.com/unveiling-lazarus-new-campaign/110888/


2¡¢LockbitÐû³ÆÒÑÈëÇÖ²¨Òô¹«Ë¾²¢Íþв½«Ð¹Â¶±»µÁÊý¾Ý


¾ÝýÌå10ÔÂ27ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬LockbitÐû³ÆÈëÇÖÁ˺½¿Õº½ÌìÔì×÷É̺͹ú·À³Ð°üÉ̲¨Òô¹«Ë¾¡£¡£¡£¡£¡£¡£¡£¡£²¨Òô¹«Ë¾ÔÚ2022ÄêµÄÏúÊÛ¶îΪ666.1ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£LockbitÒѽ«²¨ÒôÔö³¤µ½ÆäTorÍøÕ¾ÖУ¬£¬£¬£¬£¬£¬°µÊ¾ÒѴӸù«Ë¾ÇÔÈ¡ÁË´óÁ¿Êý¾Ý£¬£¬£¬£¬£¬£¬²¢ÍþвÈôÊDz»ÔÚ½ØÖ¹ÈÕÆÚ£¨11ÔÂ2ÈÕ13:25:39£©ÄÚÓëËûÃÇÁªÏµ£¬£¬£¬£¬£¬£¬½«°ä²¼ÕâЩÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£½ØÖÁĿǰ£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïÉÐδ¹«¿ªÈκÎÑù±¾¡£¡£¡£¡£¡£¡£¡£¡£Êê½ðÒªÇóÉÐδÅû¶£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬ÈôÊÇLockBitѡȡеÄÊÕÈëģʽ£¬£¬£¬£¬£¬£¬ÄÇôÊê½ð¿ÉÄÜ»á¸ß´ï18ÒÚÃÀÔª×óÓÒ¡£¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/153149/cyber-crime/lockbit-ransomware-gang-boeing.html


3¡¢ANSSIÅû¶APT28¹¥»÷·¨¹úÆóÒµºÍ´óѧµÈµÄTTP


¾Ý10ÔÂ27ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬·¨¹ú¹ú¶ÈÐÅϢϵͳ°²È«¾ÖANSSI³Æ£¬£¬£¬£¬£¬£¬APT28×Ô2021ÄêϰëÄêÒÔÀ´Ò»Ïò¹¥»÷Æäµ±¾Ö»ú¹¹¡¢ÆóÒµ¡¢´óѧ¡¢×êÑлú¹¹ºÍÖÇ¿âµÈ¡£¡£¡£¡£¡£¡£¡£¡£´óÎÞÊýAPT28»î¶¯¶¼ÀûÓÃÁËÓã²æÊ½´¹µö¹¥»÷ºÍ»ùÓÚ¶ñÒâÈí¼þµÄ¹¥»÷£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÖÁÉÙÁË3ÖÖ¹¥»÷·½Ê½£ºËÑË÷ÁãÈÕ·ì϶¡¢¹¥»÷·ÓÉÆ÷ºÍÓ×ÎÒµç×ÓÓʼþÕÊ»§ÒÔ¼°Ê¹ÓÿªÔ´¹¤¾ßºÍÔÚÏß·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£ANSSIµ÷²éÈ·ÈÏ£¬£¬£¬£¬£¬£¬APT28ÀûÓÃÁËOutlook·ì϶(CVE-2023-23397)ºÍ·ì϶¡°Follina¡±£¨CVE-2022-30190£©µÈ£¬£¬£¬£¬£¬£¬Ê¹ÓÃÁËMimikatzºÍreGeorgµÈ¹¤¾ß£¬£¬£¬£¬£¬£¬»¹Ê¹ÓÃÁËһϵÁÐVPN¿Í»§¶Ë¡£¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/153131/apt/france-anssi-apt28.html


4¡¢TortoiseshellÐÂÒ»ÂÖË®¿Ó¹¥»÷Ö¼ÔÚ·Ö·¢IMAPLoader


ýÌå10ÔÂ26Èճƣ¬£¬£¬£¬£¬£¬PwC¼ì²âµ½ÒÁÀʹ¥»÷ÍÅ»ïTortoiseshellµÄÐÂÒ»ÂÖË®¿Ó¹¥»÷£¬£¬£¬£¬£¬£¬Ö¼ÔÚ·Ö·¢IMAPLoader¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï×Ô2018ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬£¬2022ÄêÖÁ2023ÄêµÄ×îлÔÚÖ¸±êÍøÕ¾ÖÐǶÈë¶ñÒâJavaScript£¬£¬£¬£¬£¬£¬À´ÍøÂçÓû§µÄµØÎ»¡¢É豸ÐÅÏ¢ºÍ½Ó¼û¹¦·òµÈÐÅÏ¢£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔµØÖк£µÄº£Ê¡¢º½Ô˺ÍÎïÁ÷ÁìÓò¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷»î¶¯·Ö·¢µÄIMAPLoaderÊÇÒ»ÖÖ.NET¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬¿ÉÄÜʹÓñ¾»úWindows·¨Ê½¶ÔÖ¸±êϵͳ½øÐÐÖ¸ÎÆ¼ø±ð£¬£¬£¬£¬£¬£¬²¢³äÈÎÏÂÒ»²½payloadµÄÏÂÔØ·¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2023/10/iranian-group-tortoiseshell-launches.html


5¡¢Î¢Èí¹«¿ª¹ØÓÚOcto Tempest¹¥»÷»î¶¯µÄ¼¼Êõϸ½Ú


10ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬Î¢Èí¹«¿ªÁ˹ØÓÚOcto TempestÍŻ﹥»÷»î¶¯µÄ¼¼Êõϸ½Ú¡£¡£¡£¡£¡£¡£¡£¡£×Ô2022ËêÊ×ÒÔÀ´£¬£¬£¬£¬£¬£¬Octo TempestµÄ¹¥»÷ÎȲ½·¢Õ¹£¬£¬£¬£¬£¬£¬½«¹¥»÷ÁìÓòÀ©´óµ½ÌṩÓÐÏßµçÐÅ¡¢µç×ÓÓʼþºÍ¼¼Êõ·þÎñµÄ¹«Ë¾£¬£¬£¬£¬£¬£¬²¢ÓëÀÕË÷ÍÅ»ïALPHV/BlackCatºÏ×÷¡£¡£¡£¡£¡£¡£¡£¡£½ñÄêÔçЩʱ³½£¬£¬£¬£¬£¬£¬¸ÃÍŻ﹥»÷ÁËÓÎÏ·¡¢¾Æµê¡¢ÁãÊÛ¡¢Ôì×÷¡¢¼¼ÊõºÍ½ðÈÚÁìÓòµÄ¹«Ë¾ÒÔ¼°ÍйܷþÎñÌṩÉÌ(MSP)¡£¡£¡£¡£¡£¡£¡£¡£Octo Tempest»¹ÀûÓÃÁË´ó¶àÍŻﲻ³£ÓõĹ¥»÷·½Ê½£¬£¬£¬£¬£¬£¬ÀýÈç¶ÌÐÅ´¹µö¡¢SIM»¥»»¹¥»÷ºÍ¸´ÔÓÉ繤¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£


https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/


6¡¢ESET°ä²¼2023ÄêQ2ÖÁQ3µÄAPT»î¶¯µÄ·ÖÎö»ã±¨


10ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬ESET°ä²¼ÁË2023ÄêµÚ¶þ¼¾¶ÈÖÁµÚÈý¼¾¶ÈAPT»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ4ÔÂÖÁ9Ô£¬£¬£¬£¬£¬£¬¼ì²âµ½APTÍÅ»ïÀûÓÃÒÑÖª·ì϶´Óµ±¾Ö»ú¹¹»òÓйØÊµÌåÇÔÈ¡Êý¾ÝµÄÕ½Êõ¡£¡£¡£¡£¡£¡£¡£¡£Sednit¡¢Sandworm¡¢Konni¡¢Winter VivernºÍSturgeonPhisher£¬£¬£¬£¬£¬£¬×¥×¡»úÓöÀûÓÃÁËWinRAR¡¢Roundcube¡¢ZimbraºÍOutlookÖзì϶£¬£¬£¬£¬£¬£¬Õë¶ÔÎÚ¿ËÀ¼¡¢Å·ÖÞºÍÖÐÑǵȵØÓò¡£¡£¡£¡£¡£¡£¡£¡£GALLIUM¿ÉÄÜÀûÓÃÁËMicrosoft Exchange·þÎñÆ÷»òIIS·þÎñÆ÷µÄ·ì϶£¬£¬£¬£¬£¬£¬MirrorFaceÀûÓÃÁËProselfÔÚÏß´æ´¢·þÎñÖеķì϶£¬£¬£¬£¬£¬£¬TA410ÀûÓÃÁËAdobe ColdFusionÀûÓ÷þÎñÆ÷Öеķì϶¡£¡£¡£¡£¡£¡£¡£¡£


https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q2-q3-2023/