¼ÓÄôóijÌìÈ»Æø¹ÜµÀÔâµ½ZaryaµÄ¹¥»÷¿ÉÄܻᱬը
Ðû²¼Ê±¼ä 2023-04-281¡¢¼ÓÄôóijÌìÈ»Æø¹ÜµÀÔâµ½ZaryaµÄ¹¥»÷¿ÉÄܻᱬը
¾ÝýÌå4ÔÂ26ÈÕ±¨µÀ£¬¼ÓÄôóijÌìÈ»Æø¹ÜÔâµ½¹¥»÷£¬¿ÉÄÜ»áÒý·¢±¬Õ¨¡£Å¦Ô¼Ê±±¨³Æ£¬Ð¹Â¶µÄÃÀ¹úÇ鱨Îļþ½ÒʾÁËÕâһʼþ¡£ÆäÖÐÒ»·ÝÎļþ°üÂÞZaryaÓëFSBÔ±¹¤µÄ¶Ô»°£¬ËûÃÇÔ¤¼ÆÀֳɵĹ¥»÷½«µ¼ÖÂÅ䯸վ·¢Éú±¬Õ¨£¬²¢ÔÚ¼àÊÓ¼ÓÄôóÐÂÎű¨µÀ¿´ÊÇ·ñÓб¬Õ¨¼£Ï󡣸ÃÎļþµÄÕæÊµÐÔÉÐδµÃµ½Ö¤Êµ¡£¼ÓÄôó×ÜÀíÈ·ÈÏÁËÕë¶ÔÌìÈ»Æø¹ÜµÀµÄÍøÂç¹¥»÷£¬µ«ËûÖ¸³ö¼ÓÄôóµÄÈκÎÄÜÔ´»ù´¡ÉèÊ©¶¼Ã»ÓÐÊܵ½Êµ¼ÊË𺦡£
https://securityaffairs.com/145307/cyber-warfare-2/canadian-gas-pipeline-disruptive-attack.html
2¡¢Alloy TaurusÀûÓÃPingPullбäÌå¹¥»÷ÄϷǺÍÄá²´¶û
4ÔÂ26ÈÕ£¬Unit 42³Æ×î½ü·¢ÏÖAlloy TaurusÍÅ»ïʹÓÃPingPullºóÃŵÄбäÌå¹¥»÷LinuxϵͳµÄ»î¶¯£¬¸Ã»î¶¯Ö÷ÒªÕë¶ÔÄϷǺÍÄá²´¶û¡£3ÔÂ7ÈÕ£¬Ñо¿ÈËÔ±·¢ÏÖÁËÒ»¸öÉÏ´«µ½VirusTotalµÄPingPullµÄLinux±äÌ壬ËüµÄ¼ì²âÂʷdz£µÍ¡£PingPullÖÐʹÓõÄÃüÁî´¦Ö÷¨Ê½ÓëÔÚÁíÒ»¸ö¶ñÒâÈí¼þChina ChopperµÄÖз¢ÏÖµÄÃüÁî´¦Ö÷¨Ê½ÏàËÆ¡£´ËÍ⣬Unit 42»¹·¢ÏÖÁËÒ»¸öеÄELFºóÃÅSword2033£¬Á´½Óµ½ÏàͬµÄC2»ù´¡ÉèÊ©£¬Ö§³ÖÉÏ´«¡¢Ð¹Â¶ÎļþºÍÖ´ÐÐÃüÁîÈý¸ö»ù±¾¹¦Ð§¡£
https://unit42.paloaltonetworks.com/alloy-taurus/
3¡¢FIN7ÍÅ»ïÀûÓÃ×î½üÐÞ¸´µÄVeeam©¶´·Ö·¢ºóÃÅLizar
WithSecureÔÚ4ÔÂ26ÈÕÅû¶ÁËFIN7ÍÅ»ïÕë¶ÔVeeam±¸·Ý·þÎñÆ÷µÄ¹¥»÷»î¶¯¡£3ÔÂ28ÈÕ£¬Ñо¿ÈËÔ±ÔÚÔËÐÐVeeam Backup & ReplicationÈí¼þµÄ·þÎñÆ÷Éϼì²âµ½³õʼ»î¶¯¡£ÓëVeeam BackupʵÀýÏà¹ØµÄSQL·þÎñÆ÷½ø³Ìsqlservr.exeÖ´ÐÐÁËÒ»¸öshellÃüÁ¸ÃÃüÁîÔÚÄÚ´æÖÐÏÂÔØ²¢Ö´ÐÐPowerShell½Å±¾¡£ÕâЩPowerShell½Å±¾µÄËùÓÐʵÀý¶¼ÊÇPowertrash dropper£¬ËüÓÃÓÚ·Ö·¢ºóÃÅDiceloader£¨Ò²³ÆÎªLizar£©¡£¸Ã»î¶¯µÄ³õʼ·ÃÎʺÍÖ´ÐкܿÉÄÜÊÇͨ¹ý×î½üÐÞ¸´µÄVeeam Backup & Replication©¶´£¨CVE-2023-27532£©ÊµÏֵġ£
https://labs.withsecure.com/publications/fin7-target-veeam-servers
4¡¢ÎÚ¿ËÀ¼¾¯·½´þ²¶Ôø³öÊÛÁè¼Ý3ÒÚ¹«Ãñ¸öÈËÐÅÏ¢µÄÏÓÒÉÈË
ýÌå4ÔÂ26Èճƣ¬ÎÚ¿ËÀ¼ÍøÂ羯²ì´þ²¶ÁËÀ´×ÔNetishynµÄÒ»Ãû36ËêÄÐ×Ó£¬×ïÃûÊdzöÊÛÁè¼Ý3ÒÚÎÚ¿ËÀ¼ºÍÅ·ÖÞ¸÷¹ú¹«ÃñµÄ¸öÈËÐÅÏ¢¡£ÏÓÒÉÈËʹÓÃTelegramÏò¸ÐÐËȤµÄÂò¼ÒÍÆÏú±»µÁÊý¾Ý£¬Æ¾¾ÝÊý¾ÝÁ¿¼°Æä¼ÛÖµ£¬Òª¼ÛÔÚ500µ½2000ÃÀÔªÖ®¼ä¡£Éæ¼°»¤ÕÕÊý¾Ý¡¢ÄÉ˰È˱àºÅ¡¢³öÉúÖ¤Ã÷¡¢¼ÝʻִÕÕºÍÒøÐÐÕË»§Êý¾ÝµÈÐÅÏ¢¡£¾ÝϤ£¬Ö´·¨ÈËÔ±²éÊÕÁË36¸öÓ²ÅÌÇý¶¯Æ÷¡¢¼ÆËã»úºÍ·þÎñÆ÷É豸£¬ÆäÖаüÂÞ¶à¸öÊý¾Ý¿â£¬ÆäÀ´Ô´½«Í¨¹ýºóÐø·ÖÎöÈ·¶¨¡£
https://www.bleepingcomputer.com/news/security/ukrainian-arrested-for-selling-data-of-300m-people-to-russians/
5¡¢Linux°æ±¾µÄRTM LockerÕë¶ÔVMware ESXi·þÎñÆ÷
UptycsÔÚ4ÔÂ26ÈÕÐû²¼ÁËÒ»·Ý³ÂËߣ¬·ÖÎöÁËRTM LockerµÄÒ»¸öLinux±äÌ壬¸Ã±äÌå»ùÓÚÏÖÒѽâÉ¢µÄBabukÀÕË÷Èí¼þµÄÔ´´úÂë¡£RTM LockerµÄLinux°æ±¾¼ÓÃÜ·¨Ê½ËƺõÊÇרÃÅΪ¹¥»÷VMware ESXiϵͳ¿ª·¢µÄ£¬ÒòΪËü°üÂÞÁËÐí¶àÓÃÓÚ¹ÜÀíÐéÄâ»úµÄÃüÁî¡£ÓëBabukÒ»Ñù£¬RTMʹÓÃËæ»úÊýÉú³ÉºÍECDH¶ÔCurve25519½øÐзǶԳƼÓÃÜ£¬µ«ËüûÓÐʹÓÃSosemanuk£¬¶øÊÇÒÀ¿¿ChaCha20½øÐжԳƼÓÃÜ¡£Ñо¿ÈËÔ±³Æ£¬ESXi°æ±¾µÄ´æÔÚ£¬×ãÒÔ½«RTM Locker¹éÀàΪÕë¶ÔÆóÒµµÄÖØ´óÍþв¡£
https://www.uptycs.com/blog/rtm-locker-ransomware-as-a-service-raas-linux
6¡¢LayerXÐû²¼¹ØÓÚ2023Äêä¯ÀÀÆ÷Äþ¾²µÄÊÓ²ì·ÖÎö³ÂËß
¾Ý4ÔÂ26ÈÕ±¨µÀ£¬LayerXÐû²¼¹ØÓÚ2023Äêä¯ÀÀÆ÷Äþ¾²µÄÊÓ²ì·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬ÔÚ¹ýÈ¥12¸öÔÂÖУ¬87%µÄall-SaaSºÍ79%»ìºÏ»·¾³ÖеÄCISO¶¼¾Àú¹ýÄþ¾²Ê¼þ¡£ÕÊ»§½Ó¹ÜÊÇ×îÁîÈ˵£ÓǵÄÎÊÌ⣬48%µÄÈ˽«Æ¾¾ÝÍøÂçµöÓãÁÐΪ·çÏÕ×î¸ßµÄä¯ÀÀÆ÷Íþв£¬Æä´ÎÊǶñÒâä¯ÀÀÆ÷À©Õ¹(37%)¡¢¶ñÒâÈí¼þÏÂÔØ(9%)ºÍä¯ÀÀÆ÷©¶´(6%)¡£´ó¶àÊý×éÖ¯½ÓÄÉÖÁÉÙÁ½ÖÖÄþ¾²´ëÊ©À´µÖÓùµöÓã¹¥»÷£¬79%ʹÓÃÍøÂçÄþ¾²¹¤¾ß£¬ÀýÈç·À»ðǽºÍSWG¡£
https://go.layerxsecurity.com/2023-browser-security-survey