ArmisÅû¶PTSϵͳÖеÄͳ³ÆÎªPwnedPiperµÄ·ì϶£»CyCraft°ä²¼Õë¶ÔÀÕË÷Èí¼þPrometheusµÄÃâ·Ñ½âÃÜÆ÷
°ä²¼¹¦·ò 2021-08-03
°²È«¹«Ë¾ArmisÅû¶SwissLogµÄTransLogic PTS£¨Æø¶¯¹Üϵͳ) ÖÐͳ³ÆÎªPwnedPiperµÄ9¸ö·ì϶£¬Ó°ÏìÈ«ÃÀ80%µÄÒ½Ôº¡£TransLogic PTSÓÃÓÚÔÚ´óÖÐÐÍÒ½ÔºÖг¤¾àÀëÔËËÍÒ½ÁÆÎïÆ·£¬ÒÑÔÚ±±ÃÀ2300¶à¼ÒҽԺʹÓá£ÕâЩ·ì϶ÖÐ×îÑϳÁµÄÊÇδ¾Éí·ÝÑéÖ¤¡¢Î´¼ÓÃÜ¡¢Î´ÊðÃûµÄ¹Ì¼þÉý¼¶·ì϶£¨CVE-2021-37160£©£¬¿ÉÓÃÀ´ÔÚϵͳÉÏ×°ÖöñÒâ¹Ì¼þÀ´ÆëÈ«½ÚÔìÖ¸±êϵͳ¡£´Ë±í£¬»¹ÓÐÌáȨ·ì϶£¨CVE-2021-37167£©¡¢DoS·ì϶£¨CVE-2021-37166£©ºÍtcpTxThreadÖеÄÈý±¶²Ö¿âÒç³ö£¨CVE-2021-37164£©µÈ·ì϶¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/08/pwnedpiper-pts-security-flaws-threaten.html
2.KasperskyÅû¶ÐµÄGhostEmperorÍÅ»ïÕë¶Ô¶«ÄÏÑÇ

KasperskyÅû¶ÁËÒ»¸öеĺڿÍÍÅ»ïGhostEmperor£¬ÖØÒªÕë¶Ô¶«ÄÏÑǵØÓòµÄÖ¸±ê£¬Ô̺¬µ±¾Ö»ú¹¹ºÍ¼¸¼ÒµçÐŹ«Ë¾¡£¸ÃÍÅ»ïµÄÈëÇֻÒÀÀµÓÚCheat Engine¿ªÔ´ÏîÖ÷ÕÅÒ»¸ö×é¼þ£¬Ëü¿ÉÄÜÈÆ¹ýWindowsÇý¶¯·¨Ê½Ç¿ÔìÊðÃû»úÔì¡£¸ÃÍÅ»ïÖ®ËùÒÔÒìºõѰ³££¬ÊÇÓÉÓÚËüʹÓÃÁËÒ»¸öÒÔǰ²»ÎªÈËÖªµÄWindowsÄÚºËģʽµÄrootkit£¬²¢ÇÒѡȡÁ˸´ÔӵĶà½×¶Î¶ñÒâÈí¼þ¿ò¼Ü£¬Ö¼ÔÚ¶ÔÖ¸±ê·þÎñÆ÷½øÐÐÔ¶³Ì½ÚÔì¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120721/apt/ghostemperor-chinese-speaking-threat-actor.html
3.CiscoÅû¶¶ñÒâÈí¼þSolarmarkerÐÂÒ»ÂֵĹ¥»÷»î¶¯

Cisco TalosÅû¶Á˶ñÒâÈí¼þSolarmarkerÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£ÔÚ2021Äê5Ôµ׺Í6Ô³õ×óÓÒ£¬Talos¼ì²âµ½ÐÂÒ»ÂÖSolarmarker¹¥»÷»î¶¯¼¤Ôö¡£ÔÚ×î½üµÄÕâЩµü´úÖУ¬¹¥»÷Õßµ÷ÕûÁ˳õʼdropperµÄÏÂÔØ²½Ö裬²¢¶Ôstaging×é¼þ£¨´Ë¿Ì³ÆÎªMars£©½øÐÐÁËÉý¼¶¡£ÒÔǰSolarmarker½«´Ó´øÓÐͨÓñêÌâÃû³ÆPdfDocDownloadsPanelµÄÒ³ÃæÏÂÔØ£¬¶øÕâ´Î»î¶¯ÖеÄÏÂÔØÒ³ÃæÏÖαÔì³ÉÀ´×ԹȸèDriveµÄÏÂÔØÎļþÒªÇ󣬿´ÆðÀ´Ô½·¢ºÏ·¨¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/07/threat-spotlight-solarmarker.html
4.CyCraft°ä²¼Õë¶ÔÀÕË÷Èí¼þPrometheusµÄÃâ·Ñ½âÃÜÆ÷

°²È«¹«Ë¾CyCraft°ä²¼Ãâ·Ñ½âÃÜÆ÷£¬Ô®ÊÖÀÕË÷Èí¼þPrometheusµÄÊܺ¦Õ߸´ÔºÍ½âÃÜÎļþ¡£CyCraft°µÊ¾£¬PrometheusʹÓÃÁËSalsa20ºÍ»ùÓÚtickcountµÄËæ»úÃÜÂëÀ´¼ÓÃÜÎļþ¡£Ëæ»úÃÜÂëµÄ´óÓ×Ϊ32×Ö½Ú£¬Ã¿¸ö×Ö·û¶¼Êǿɼû×Ö·û£¬²¢ÇÒÓÉÓÚÃÜÂëÒÔtickcount×÷ΪÃÜÔ¿£¬ËùÒÔÄܹ»Ê¹Óñ©Á¦ÆÆ½â¡£Emsisoft¹«Ë¾°µÊ¾¸Ã½âÃÜÆ÷ΨһµÄ±×¶ËÊÇÖ»ÄÜÆÆ½âÓ×ÎļþµÄ½âÃÜÃÜÔ¿¡£´Ë±í£¬½âÃÜÆ÷°ä²¼²»¾Ãºó£¬PrometheusÍÅ»ïËÆºõÒѾÖÕ³¡ÁËÐж¯¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/decryptor-released-for-prometheus-ransomware-victims/
5.SonicWall°ä²¼2021ÄêÉϰëÄêÍøÂçÌ¬ÊÆµÄ·ÖÎö»ã±¨

SonicWall°ä²¼ÁË2021ÄêÉϰëÄêÍøÂçÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬ÀÕË÷Èí¼þ¹¥»÷ÔÚ2021ÄêÉϰëÄ꼫¶È·è¿ñ£¬¸Ã¹«Ë¾¼ì²âµ½µÄ¹¥»÷³¢ÊÔ´ïµ½3.047ÒڴΣ¬ ³¬¹ýÁË2020ÕûÄêµÄ¹¥»÷×ÜÊý¡£ÃÀ¹ú¡¢Ó¢¹ú¡¢µÂ¹ú¡¢ÄϷǺͰÍÎ÷µÈ¹ú¶ÈÊÇÊÜÀÕË÷Èí¼þ¹¥»÷×îÑϳÁµÄ¹ú¶È£¬ÆäÖÐÃÀ¹úÊÜÓ°Ïì½Ï´óµÄµØÓòÊÇ·ðÂÞÀï´ïÖÝ£¬ÓÐ1.111Òڴι¥»÷³¢ÊÔ¡£´Ë±í£¬ÀÕË÷¹¥»÷×î³£¼ûµÄÖ¸±êÊǽðÈÚ»ú¹¹ÒÔ¼°¹ú·ÀµÈ³ÁҪȷµ±¾Ö×éÖ¯£¬¶øÕë¶Ô½ÌÓýÐÐÒµµÄ¹¥»÷Ôò¼¤ÔöÁË615%¡£
ÔÎÄÁ´½Ó£º
https://www.sonicwall.com/2021-cyber-threat-report/
6.Deepinstinct°ä²¼2021ÄêÖÐÍøÂçÍþÐ²Ì¬ÊÆ·ÖÎö»ã±¨

Deep Instinct°ä²¼ÁË2021ÄêÖÐÍøÂçÍþÐ²Ì¬ÊÆ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬ÀÕË÷Èí¼þÒ»ÏòÊÇÕû¸ö2021ÄêµÄÖ÷µ¼Ç÷Ïò£¬ÆäÖÐÖØÒªÍþвΪSTOP(Djvu)¡¢RyukºÍSodinokibi(REvil)µÈ¡£ÒøÐÐľÂí»î¶¯µÄÖØÒªÍþвΪEmotetµÄ¼ÌÈÎÕߣ¬ÀýÈçRamnit¡¢QbotºÍIcedID¡£´Ë±í£¬Õë¶ÔColonial PipelineµÄ¹¥»÷³ÉΪȫÇòµÄ½¹µã£¬µ«ÕâÖ»Êǹ¥»÷¹Ø¼ü»ù´¡ÉèÊ©µÄ¶à¶à¹¥»÷³¢ÊÔÖ®Ò»£¬²¢ÇÒÔ¤¼ÆÕâÖÖ¹¥»÷Õ½Êõ½üÆÚÄÚ²»»á²úÉúŤת¡£
ÔÎÄÁ´½Ó£º
https://www.deepinstinct.com/2021/07/22/2021-mid-year-cyber-threat-landscape-report/


¾©¹«Íø°²±¸11010802024551ºÅ