¼ÓÄôóijÌìÈ»Æø¹Ü·Ôâµ½ZaryaµÄ¹¥»÷¿ÉÄܻᱬը

°ä²¼¹¦·ò 2023-04-28

1¡¢¼ÓÄôóijÌìÈ»Æø¹Ü·Ôâµ½ZaryaµÄ¹¥»÷¿ÉÄܻᱬը


¾ÝýÌå4ÔÂ26ÈÕ±¨Â·£¬¼ÓÄôóijÌìÈ»Æø¹ÜÔâµ½¹¥»÷£¬¿ÉÄÜ»áÒý·¢±¬Õ¨¡£Å¦Ô¼Ê±±¨³Æ£¬Ð¹Â¶µÄÃÀ¹úµý±¨Îļþ½ÒʾÁËÕâÒ»ÊÂÎñ¡£ÆäÖÐÒ»·ÝÎļþÔ̺¬ZaryaÓëFSBÔ±¹¤µÄ¶Ô»°£¬ËûÃÇÔ¤¼Æ³É¹¦µÄ¹¥»÷½«µ¼ÖÂÅ䯸վ²úÉú±¬Õ¨£¬²¢Ôڼල¼ÓÄôóÐÂÎű¨Â·¿´ÊÇ·ñÓб¬Õ¨¼£Ï󡣸ÃÎļþµÄÕæÊµÐÔÉÐδµÃµ½Ö¤Êµ¡£¼ÓÄôó×ÜÀíÈ·ÈÏÁËÕë¶ÔÌìÈ»Æø¹Ü·µÄÍøÂç¹¥»÷£¬µ«ËûÖ¸³ö¼ÓÄôóµÄÈκÎÄÜÔ´»ù´¡ÉèÊ©¶¼Ã»ÓÐÊܵ½ÏÖʵÇÖº¦¡£


https://securityaffairs.com/145307/cyber-warfare-2/canadian-gas-pipeline-disruptive-attack.html


2¡¢Alloy TaurusÀûÓÃPingPullбäÌå¹¥»÷ÄϷǺÍÄá²´¶û


4ÔÂ26ÈÕ£¬Unit 42³Æ×î½ü·¢ÏÖAlloy TaurusÍÅ»ïʹÓÃPingPullºóÃŵÄбäÌå¹¥»÷LinuxϵͳµÄ»î¶¯£¬¸Ã»î¶¯ÖØÒªÕë¶ÔÄϷǺÍÄá²´¶û¡£3ÔÂ7ÈÕ£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÉÏ´«µ½VirusTotalµÄPingPullµÄLinux±äÌ壬ËüµÄ¼ì²âÂʼ«¶ÈµÍ¡£PingPullÖÐʹÓõĺÅÁî´¦Ö÷¨Ê½ÓëÔÚÁíÒ»¸ö¶ñÒâÈí¼þChina ChopperµÄÖз¢ÏֵĺÅÁî´¦Ö÷¨Ê½ÀàËÆ¡£´Ë±í£¬Unit 42»¹·¢ÏÖÁËÒ»¸öеÄELFºóÃÅSword2033£¬Á´½Óµ½Ò»ÑùµÄC2»ù´¡ÉèÊ©£¬Ö§³ÖÉÏ´«¡¢Ð¹Â¶ÎļþºÍÖ´ÐкÅÁîÈý¸ö¸ù»ùÖ°ÄÜ¡£


https://unit42.paloaltonetworks.com/alloy-taurus/


3¡¢FIN7ÍÅ»ïÀûÓÃ×î½ü½¨¸´µÄVeeam·ì϶·Ö·¢ºóÃÅLizar


WithSecureÔÚ4ÔÂ26ÈÕÅû¶ÁËFIN7ÍÅ»ïÕë¶ÔVeeam±¸·Ý·þÎñÆ÷µÄ¹¥»÷»î¶¯¡£3ÔÂ28ÈÕ£¬×êÑÐÈËÔ±ÔÚÔËÐÐVeeam Backup & ReplicationÈí¼þµÄ·þÎñÆ÷Éϼì²âµ½³õʼ»î¶¯¡£ÓëVeeam BackupÊ·ýÓйصÄSQL·þÎñÆ÷¹ý³Ìsqlservr.exeÖ´ÐÐÁËÒ»¸öshellºÅÁ¸ÃºÅÁîÔÚÄÚ´æÖÐÏÂÔØ²¢Ö´ÐÐPowerShell¾ç±¾¡£ÕâЩPowerShell¾ç±¾µÄËùÓÐÊ·ý¶¼ÊÇPowertrash dropper£¬ËüÓÃÓÚ·Ö·¢ºóÃÅDiceloader£¨Ò²³ÆÎªLizar£©¡£¸Ã»î¶¯µÄ³õʼ½Ó¼ûºÍÖ´ÐкܿÉÄÜÊÇͨ¹ý×î½ü½¨¸´µÄVeeam Backup & Replication·ì϶£¨CVE-2023-27532£©ÊµÏֵġ£


https://labs.withsecure.com/publications/fin7-target-veeam-servers


4¡¢ÎÚ¿ËÀ¼¾¯·½¿ÛÁôÔøÏúÊÛ³¬¹ý3ÒÚ¹«ÃñÓ×ÎÒÐÅÏ¢µÄÏÓÒÉÈË


ýÌå4ÔÂ26Èճƣ¬ÎÚ¿ËÀ¼ÍøÂ羯Ա¿ÛÁôÁËÀ´×ÔNetishynµÄÒ»Ãû36ËêÄÐ×Ó£¬×ïÃûÊÇÏúÊÛ³¬¹ý3ÒÚÎÚ¿ËÀ¼ºÍÅ·ÖÞÁйú¹«ÃñµÄÓ×ÎÒÐÅÏ¢¡£ÏÓÒÉÈËʹÓÃTelegramÏò¸ÐÐËÖµÄÂò¼ÒÍÆÏú±»µÁÊý¾Ý£¬Æ¾¾ÝÊý¾ÝÁ¿¼°Æä¼ÛÖµ£¬Òª¼ÛÔÚ500µ½2000ÃÀÔªÖ®¼ä¡£Éæ¼°»¤ÕÕÊý¾Ý¡¢ÄÉ˰È˱àºÅ¡¢µ®ÉúÖ¤Ã÷¡¢¼ÝÊ»ÅÆÕÕºÍÒøÐÐÕË»§Êý¾ÝµÈÐÅÏ¢¡£¾ÝϤ£¬·¨ÂÉÈËÔ±²éÊÕÁË36¸öÓ²ÅÌÇý¶¯Æ÷¡¢ÍÆËã»úºÍ·þÎñÆ÷É豸£¬ÆäÖÐÔ̺¬¶à¸öÊý¾Ý¿â£¬ÆäÆðÔ´½«Í¨¹ýºóÐø·ÖÎöÈ·¶¨¡£


https://www.bleepingcomputer.com/news/security/ukrainian-arrested-for-selling-data-of-300m-people-to-russians/


5¡¢Linux°æ±¾µÄRTM LockerÕë¶ÔVMware ESXi·þÎñÆ÷


UptycsÔÚ4ÔÂ26ÈÕ°ä²¼ÁËÒ»·Ý»ã±¨£¬·ÖÎöÁËRTM LockerµÄÒ»¸öLinux±äÌ壬¸Ã±äÌå»ùÓÚÏÖÒÑDzɢµÄBabukÀÕË÷Èí¼þµÄÔ´´úÂë¡£RTM LockerµÄLinux°æ±¾¼ÓÃÜ·¨Ê½ËƺõÊÇרÃÅΪ¹¥»÷VMware ESXiϵͳ¿ª·¢µÄ£¬ÓÉÓÚËüÔ̺¬Á˺ܶàÓÃÓÚÖÎÀíÐé¹¹»úµÄºÅÁî¡£ÓëBabukÒ»Ñù£¬RTMʹÓÃËæ»úÊýÌìÉúºÍECDH¶ÔCurve25519½øÐзǶԳƼÓÃÜ£¬µ«ËüûÓÐʹÓÃSosemanuk£¬¶øÊÇÒÀ¸½ChaCha20½øÐжԳƼÓÃÜ¡£×êÑÐÈËÔ±³Æ£¬ESXi°æ±¾µÄ´æÔÚ£¬×ãÒÔ½«RTM Locker¹éÀàΪÕë¶ÔÆóÒµµÄ³Á´óÍþв¡£


https://www.uptycs.com/blog/rtm-locker-ransomware-as-a-service-raas-linux


6¡¢LayerX°ä²¼¹ØÓÚ2023Äêä¯ÀÀÆ÷°²È«µÄµ÷²é·ÖÎö»ã±¨


¾Ý4ÔÂ26ÈÕ±¨Â·£¬LayerX°ä²¼¹ØÓÚ2023Äêä¯ÀÀÆ÷°²È«µÄµ÷²é·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬ÔÚ´Óǰ12¸öÔÂÖУ¬87%µÄall-SaaSºÍ79%»ìºÏ»·¾³ÖеÄCISO¶¼¾­Àú¹ý°²È«ÊÂÎñ¡£ÕÊ»§ÊÕÊÜÊÇ×îÁîÈËÓÇÓôµÄÎÊÌ⣬48%µÄÈ˽«Í´´¦ÍøÂç´¹µöÁÐΪ·çÏÕ×î¸ßµÄä¯ÀÀÆ÷Íþв£¬Æä´ÎÊǶñÒâä¯ÀÀÆ÷À©´ó(37%)¡¢¶ñÒâÈí¼þÏÂÔØ(9%)ºÍä¯ÀÀÆ÷·ì϶(6%)¡£´óÎÞÊý×é֯ѡȡÖÁÉÙÁ½ÖÖ°²È«´ëÊ©À´Õмܴ¹µö¹¥»÷£¬79%ʹÓÃÍøÂ簲ȫ¹¤¾ß£¬ÀýÈç·À»ðǽºÍSWG¡£


https://go.layerxsecurity.com/2023-browser-security-survey