±ÈÀûʱ³ÆÆä¹ú·À²¿ºÍÄÚÕþ²¿Ôâµ½¶à¸öAPTÍÅ»ïµÄ¹¥»÷
Ðû²¼Ê±¼ä 2022-07-211¡¢±ÈÀûʱ³ÆÆä¹ú·À²¿ºÍÄÚÕþ²¿Ôâµ½¶à¸öAPTÍÅ»ïµÄ¹¥»÷
¾Ý7ÔÂ20ÈÕ±¨µÀ£¬±ÈÀûʱÍâ½»²¿³¤Í¸Â¶ÁËÕë¶ÔFPSÄÚÕþ²¿ºÍ¹ú·À²¿µÄÓ°ÏìÆäÖ÷Ȩ¡¢ÃñÖ÷¡¢Äþ¾²ºÍÕû¸öÉç»áµÄ¶ñÒâÍøÂç¹¥»÷»î¶¯¡£±ÈÀûʱÕþ¸®µÄÉùÃ÷ÖÐÌáµ½£¬Õë¶ÔÄÚÕþ²¿µÄ¹¥»÷Éæ¼°APT×éÖ¯APT27¡¢APT30¡¢APT31£¬Õë¶Ô¹ú·À²¿µÄ¶ñÒâ»î¶¯ÓëGalliumÓйء£GalliumÓÚ2019Äê12ÔÂÊ״α»Åû¶£¬MSTIC³ÆÆäÖ÷ÒªÕë¶ÔÈ«ÇòµÄµçÐÅÌṩÉÌ£¬×Ô2021ÄêÒÔÀ´£¬¿ªÊ¼¹¥»÷°¢¸»º¹¡¢°Ä´óÀûÑǺͱÈÀûʱµÈ¹ú¡£
https://securityaffairs.co/wordpress/133425/apt/belgium-claims-china-hit-its-ministries.html
2¡¢½¨²Ä¹«Ë¾KnaufÔâµ½Black BastaÍÅ»ïµÄÀÕË÷¹¥»÷
¾ÝýÌå7ÔÂ19ÈÕ±¨µÀ£¬½¨²Ä¹«Ë¾¿ÉÄ͸££¨Knauf£©Ôâµ½ÁËBlack BastaµÄÀÕË÷¹¥»÷¡£¹¥»÷·¢ÉúÔÚ6ÔÂ29ÈÕÍíÉÏ£¬Ó°ÏìÁ˸ù«Ë¾µÄÒµÎñÔËÓª£¬ÆÈʹÆäÈ«ÇòITÍŶӹرÕËùÓÐϵͳÒÔ½øÐиôÀ롣Ŀǰ£¬KnaufÈÔÔÚ½øÐÐȡ֤ÊӲ졢ʼþÏìÓ¦ºÍµ÷Í£¡£ÀÕË÷ÍÅ»ïBlack BastaÓÚ7ÔÂ16ÈÕÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏÁгö¸Ã¹«Ë¾£¬²¢ÌåÏÖ¶Ô´Ë´ÎʼþÂôÁ¦¡£¹¥»÷ÕßÒѹûÈ»±»µÁÎļþµÄ20%£¬°üÂÞµç×ÓÓʼþ¡¢Óû§Æ¾¾Ý¡¢Ô±¹¤ÁªÏµ·½Ê½¡¢Éú²úÎĵµºÍÉí·Ý֤ɨÃè¼þµÄÑù±¾¡£
https://www.bleepingcomputer.com/news/security/building-materials-giant-knauf-hit-by-black-basta-ransomware-gang/
3¡¢Ñо¿ÈËÔ±ÑÝʾÀûÓÃSATAµçÀÂÔÚÆøÏ¶ÏµÍ³ÇÔÈ¡Êý¾ÝµÄÒªÁì
ýÌå7ÔÂ19Èճƣ¬ÒÔÉ«Áб¾¹ÅÀï°²´óѧµÄÑо¿ÈËÔ±·¢ÏÖÁËÒ»ÖÖ´ÓÆøÏ¶ÏµÍ³ÖÐÇÔÈ¡Êý¾ÝµÄÐÂÒªÁì¡£ÕâÖÖÐµĹ¥»÷ÒªÁì³ÆÎªSATAn£¬ËüʹÓôó¶àÊý¼ÆËã»úÄÚ²¿µÄ´®ÐÐATA(SATA)µçÀÂ×÷ΪÎÞÏßÌìÏߣ¬Í¨¹ýÎÞÏßµçÐźŷ¢ËÍÊý¾Ý¡£ÒªÊ¹SATAn¹¥»÷Àֳɣ¬¹¥»÷ÕßÊ×ÏÈÐèҪѬȾĿ±êÆøÏ¶ÏµÍ³¡£´ËÀ๥»÷Ò²´æÔÚÏÞÖÆ£¬Í¨¹ýÖÖÖÖʵÑéÈ·¶¨£¬´ÓÆøÏ¶ÏµÍ³µ½½ÓÊÕÆ÷µÄ×î´ó¾àÀë²»ÄÜÁè¼Ý120ÀåÃ×£¬·ñÔòÎóÂëÂÊÔö¼ÓÌ«¶à£¬ÎÞ·¨±£Ö¤ÐÅÏ¢µÄÍêÕûÐÔ£¨Áè¼Ý15%£©¡£
https://www.bleepingcomputer.com/news/security/air-gapped-systems-leak-data-via-sata-cable-wifi-antennas/
4¡¢APT29ÀûÓÃGoogle DriveµÈºÏ·¨ÔÆ·þÎñ·Ö·¢¶ñÒâÈí¼þ
Unit 42ÔÚ7ÔÂ19ÈÕÅû¶Á˶íÂÞ˹ºÚ¿ÍÍÅ»ïAPT29ÀûÓÃÔÚÏß´æ´¢·þÎñ£¨DropBoxºÍGoogle Drive£©·Ö·¢¶ñÒâÈí¼þµÄµöÓã¹¥»÷¡£¾ÝÐÅ£¬ÕâЩ»î¶¯ÔÚ2022Äê5ÔÂÖÁ6ÔÂÆÚ¼äÕë¶ÔÎ÷·½µÄ¶à¸öÍ⽻ʹÍÅ£¬»î¶¯ÖÐʹÓõÄÓÕ¶ü±íÃ÷£¬ÆäÖ÷ÒªÕë¶ÔµÄÊÇÍâ¹úפÆÏÌÑÑÀ´óʹ¹ÝºÍÍâ¹úפ°ÍÎ÷´óʹ¹Ý¡£µöÓãÎĵµ°üÂÞÖ¸Ïò¶ñÒâHTMLÎļþ(EnvyScout)µÄÁ´½Ó£¬¸ÃÎļþ³äµ±ÆäËü¶ñÒâÎļþµÄdropper£¬°üÂÞCobalt Strike payload¡£
https://unit42.paloaltonetworks.com/cloaked-ursa-online-storage-services-campaigns/
5¡¢ESET·¢ÏÖÕë¶Ômac OSµÄжñÒâÈí¼þCloudMensis
7ÔÂ19ÈÕ£¬ESETÐû²¼Á˹ØÓÚÕë¶ÔmacOSµÄжñÒâÈí¼þCloudMensisµÄ·ÖÎö³ÂËß¡£Ñо¿ÈËÔ±ÓÚ2022Äê4ÔÂÊ״η¢ÏÖÕâÖÖжñÒâÈí¼þ£¬ËüʹÓù«¹²ÔÆ´æ´¢·þÎñpCloud¡¢Yandex DiskºÍDropbox½øÐÐC2ͨÐÅ¡£Æä¹¦Ð§±íÃ÷£¬¹¥»÷ÕßµÄÖ÷ҪĿ±êÊÇͨ¹ýÇÔÈ¡Îĵµ¡¢»÷¼ü¼Ç¼ºÍÆÁÄ»½ØÍ¼µÈ·½Ê½´ÓÄ¿±êMacÖÐÊÕ¼¯ÐÅÏ¢¡£CloudMensisÊÇÓÃObjective-C¿ª·¢µÄ£¬ESET·ÖÎöµÄÑù±¾ÊÇÕë¶ÔIntelºÍApple¼Ü¹¹±àÒëµÄ¡£Ä¿Ç°£¬¹¥»÷µÄ³õʼѬȾý½éºÍÄ¿±êÈÔȻδ֪¡£
https://www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware/
6¡¢8220 GangµÄÔÆ½©Ê¬ÍøÂçÒѽٳÖ3Íò¶ą̀Ö÷»úÀ´ÍÚ¿ó
SentinelLabsÔÚ7ÔÂ18Èճƣ¬ºÚ¿ÍÍÅ»ï8220 GangµÄÔÆ½©Ê¬ÍøÂç¹æÄ£ÒÑ´Ó2021ÄêÖÐÆÚµÄ2000̨Ö÷»úÀ©´óµ½30000̨¡£¸ÃÍÅ»ï×Ô2017Ä꿪ʼ»îÔ¾£¬Ö÷Ҫͨ¹ýÒÑ֪©¶´ºÍÔ¶³Ì·ÃÎʱ©Á¦ÆÆ½âÀ´Ñ¬È¾ÔÆÖ÷»ú£¬²¢²Ù¿Ø½©Ê¬ÍøÂçºÍ¼ÓÃܿ󹤡£ÔÚ×î½üµÄÒ»´Î¹¥»÷ÖУ¬¸ÃÍÅ»ïÀûÓÃÁËа汾µÄIRC½©Ê¬ÍøÂç¡¢PwnRig¼ÓÃܿ󹤼°ÆäͨÓÃѬȾ½Å±¾¡£Ñо¿ÈËÔ±ÌåÏÖ£¬¼ÓÃÜ»õ±Ò¼Û¸ñµÄϵøÆÈʹ¹¥»÷ÕßÀ©´óÆäÐж¯¹æÄ££¬ÒÔ±£³ÖÏàͬµÄÀûÈó¡£
https://www.sentinelone.com/blog/from-the-front-lines-8220-gang-massively-expands-cloud-botnet-to-30000-infected-hosts/