BlackCat¹¥»÷ÖÐÅ·µÄÄÜÔ´¹«Ë¾Creos Luxembourg SA
Ðû²¼Ê±¼ä 2022-08-02
¾ÝýÌå8ÔÂ1ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïBlackCatÉù³Æ¶ÔÉÏÖÜÖÐÅ·¹ú¼ÒÌìÈ»Æø¹ÜµÀºÍµçÁ¦ÍøÂçÔËÓªÉÌCreos Luxembourg SAµÄ¹¥»÷ÂôÁ¦¡£CreosÊÇ5¸öÅ·Ã˹ú¼ÒµÄÄÜÔ´¹©Ó¦ÉÌ£¬Æäĸ¹«Ë¾EncevoÓÚ7ÔÂ25ÈÕ͸¶£¬ËûÃÇÔÚ7ÔÂ22ÈÕÖÁ23ÈÕÔâµ½¹¥»÷¡£¹¥»÷µ¼ÖÂEncevoºÍCreosµÄ¿Í»§ÃÅ»§ÎÞ·¨·ÃÎÊ£¬µ«·þÎñ²¢Î´Öжϡ£BlackCatÓÚÉÏÖÜÁù½«CreosÌí¼Óµ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾£¬²¢ÍþвҪ¹ûÈ»180000¸ö͵ȡµÄÎļþ£¬×ܾÞϸΪ150GB£¬Éæ¼°ºÏͬ¡¢ÐÒé¡¢»¤ÕÕ¡¢Õ˵¥ºÍµç×ÓÓʼþµÈÄÚÈÝ¡£
https://www.bleepingcomputer.com/news/security/blackcat-ransomware-claims-attack-on-european-gas-pipeline/
2¡¢Group-IB·¢ÏÖÓÉÉÏÍò¸öÓò×é³ÉÕë¶ÔÅ·ÖÞµÄÐé¼ÙͶ×ÊÆ¾Ö
Group-IBÔÚ7ÔÂ29ÈÕ³ÆÆä·¢ÏÖÁËÒ»¸öÓÉ11000¶à¸öÓò×é³ÉµÄ¾Þ´óÍøÂ磬ÓÃÓÚÏòÅ·ÖÞµÄÓû§½øÐÐÐé¼ÙͶ×Êթƻ¡£ÕâЩƽ̨ÀûÓÃαÔìµÄÖ¸»Ö¤¾ÝºÍÃûÈË´úÑÔ£¬ÓªÔì³öºÏ·¨µÄÐÎÏó²¢ÒýÓÕ¸ü¶àÄ¿±ê¡£¸Ã¹¥»÷»î¶¯ÒÔ»ñµÃ¸ß»Ø±¨Í¶×ʵĻú»áΪÓÕ¶ü£¬Ëµ·þÄ¿±ê´æÈëÖÁÉÙ250Å·ÔªÀ´×¢²á·þÎñ¡£Ä¿Ç°£¬Áè¼Ý5000¸ö¶ñÒâÓòÈÔÈ»´¦Óڻ״̬£¬Ö÷ÒªÕë¶ÔÓ¢¹ú¡¢±ÈÀûʱ¡¢µÂ¹ú¡¢ºÉÀ¼¡¢ÆÏÌÑÑÀ¡¢²¨À¼¡¢Å²Íþ¡¢ÈðµäºÍ½Ý¿Ë¹²ºÍ¹ú¡£
https://blog.group-ib.com/investment-scams-europe
3¡¢LockBit¿ÉÀûÓÃWindows DefenderÀ´¼ÓÔØCobalt Strike
Sentinel LabsÔÚ7ÔÂ28ÈÕ͸¶£¬LockBitÀûÓÃMicrosoft DefenderµÄMpCmdRun.exeÀ´½âÃܲ¢°²×°Cobalt Strike¡£MpCmdRun.exeÊÇWindows DefenderµÄÃüÁîÐй¤¾ß£¬Ö´ÐÐʱ£¬Ëü½«¼ÓÔØÃûΪmpclient.dllµÄºÏ·¨DLL¡£¹¥»÷Õß¿ª·¢ÁËÎäÆ÷»¯µÄmpclient.dll£¬²¢½«Æä·ÅÔÚÓÅÏȼÓÔØ¶ñÒâDLLÎļþµÄλÖã¬Ö´ÐеĴúÂë´Óc0000015.logÎļþ½âÃܲ¢¼ÓÔØCobalt Strike payload¡£Ä¿Ç°£¬Éв»Çå³þLockBitΪºÎ´ÓʹÓÃVMwareÇл»µ½Ê¹ÓÃWindows DefenderÃüÁîÐй¤¾ßÀ´¼ÓÔØCobalt Strike¡£
https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/
4¡¢Ñо¿ÍŶӷ¢ÏÖͳ³ÆÎªDawDropperµÄ¶à¸ö¶ñÒâÈí¼þ·Ö·¢Ä¾Âí
Trend MicroÔÚ7ÔÂ29ÈÕÐû²¼³ÂËߣ¬³ÆÆä·¢ÏÖÁËÒ»Æð¶ñÒâ»î¶¯£¬ÀûÓÃGoogle PlayÉ̵êÖеÄ17¸ö¿´ËÆÎÞº¦µÄAndroid dropper£¨Í³³ÆÎªDawDropper£©À´·Ö·¢ÒøÐÐľÂí¡£ÕâЩӦÓÃαװ³ÉÀýÈçÎĵµÉ¨Ã蹤¾ß¡¢VPN·þÎñ¡¢¶þάÂëɨÃ蹤¾ßºÍͨ»°¼Ç¼¹¤¾ßµÈ¡£DawDropperʹÓõÚÈý·½ÔÆ·þÎñFirebaseʵʱÊý¾Ý¿âÀ´Èƹý¼ì²â²¢¶¯Ì¬»ñµÃpayloadµÄÏÂÔØµØÖ·£¬Ëü»¹ÔÚGitHubÉÏÍйܶñÒâpayload¡£Æ¾¾ÝÊӲ죬DawDropperµÄ±äÌå¿ÉÒÔ·Ö·¢4ÖÖÀàÐ͵ÄÒøÐÐľÂí£¬°üÂÞOcto¡¢Hydra¡¢ErmacºÍTeaBot¡£
https://www.trendmicro.com/en_us/research/22/g/examining-new-dawdropper-banking-dropper-and-daas-on-the-dark-we.html
5¡¢ÃÀ¹úFCCÌáÐÑÖ¼ÔÚÇÔÈ¡ÐÅÏ¢»ò½ðÈÚթƵÄÍøÂç¹¥»÷Ôö¼Ó
¾Ý8ÔÂ1ÈÕ±¨µÀ£¬ÃÀ¹úÁª°îͨÐÅίԱ»á(FCC)ÌáÐÑ£¬Ô½À´Ô½¶àµÄSMSµöÓã»î¶¯ÊÔͼÇÔȡĿ±êµÄ¸öÈËÐÅÏ¢ºÍ½ðÇ®¡£´ËÀ๥»÷Ò²³ÆÎªsmishing»òrobotsexts£¬¹¥»÷ÕßÀûÓÃÖÖÖÖ·½Ê½ÓÕʹĿ±ê½»³ö»úÃÜÐÅÏ¢¡£FCC³Æ½üÄêÀ´¶ÔÀ¬»ø¶ÌÐŵÄͶËßÊýÁ¿ÎȲ½ÉÏÉý£¬´Ó2019ÄêµÄÔ¼5700Æð¡¢2020ÄêµÄ14000Æð¡¢2021ÄêµÄ15300Æðµ½2022Äê6ÔÂ30ÈÕµÄ8500Æð¡£´ËÍ⣬¾ÝһЩ¶ÀÁ¢³ÂËßÔ¤¼Æ£¬Ã¿ÔÂÓÐÊýÊ®ÒÚÌõrobotext£¬ÈçRoboKillerÔ¤¼ÆÓû§ÔÚ6Ô·ÝÊÕµ½ÁËÁè¼Ý120ÒÚÌõrobotext¡£
https://securityaffairs.co/wordpress/133865/cyber-crime/fcc-warns-smishing-attacks.html
6¡¢KasperskyÐû²¼2022ÄêµÚ¶þ¼¾¶ÈAPT¹¥»÷Ì¬ÊÆµÄ·ÖÎö³ÂËß
7ÔÂ28ÈÕ£¬KasperskyÐû²¼Á˹ØÓÚ2022ÄêµÚ¶þ¼¾¶ÈAPT¹¥»÷Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬µØÔµÕþÖÎÈÔÈ»ÊÇAPTÉú³¤µÄÇý¶¯Á¦Ö®Ò»£¬¶ø¾¼ÃÀûÒæÊÇAPT¹¥»÷±³ºóµÄÁ¬Ðø¶¯»úÖ®Ò»¡£2021Äê·¢ÏÖÁËÁ½¸öUEFIÖ²È뷨ʽ£¬±¾¼¾¶È·¢ÏÖÁËÁíÒ»¸ö¶ñÒâUEFI×é¼þCosmicStrand¡£³ÂËß»¹½éÉÜÁËÕâÒ»¼¾¶ÈµÄAPT¹¥»÷»î¶¯£¬°üÂÞ¶íÂÞ˹UNC1151Õë¶ÔÅ·ÖÞÕþ¸®»ú¹¹·Ö·¢Ä¾ÂíSunseed£»Storm CloudÍÅ»ïÀûÓÃGimmick¹¥»÷macOSÓû§£»TransparentTribe¶ÔÓ¡¶ÈÕþ¸®ÊÂÇéÈËÔ±½øÐÐÐÂÒ»Âֵļäµý¹¥»÷µÈ¡£
https://securelist.com/apt-trends-report-q2-2022/106995/