¼ÓÄôóijÌìÈ»Æø¹Ü·Ôâµ½ZaryaµÄ¹¥»÷¿ÉÄܻᱬը
°ä²¼¹¦·ò 2023-04-281¡¢¼ÓÄôóijÌìÈ»Æø¹Ü·Ôâµ½ZaryaµÄ¹¥»÷¿ÉÄܻᱬը
¾ÝýÌå4ÔÂ26ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬¼ÓÄôóijÌìÈ»Æø¹ÜÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬¿ÉÄÜ»áÒý·¢±¬Õ¨¡£¡£¡£¡£¡£¡£¡£Å¦Ô¼Ê±±¨³Æ£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÃÀ¹úµý±¨Îļþ½ÒʾÁËÕâÒ»ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÒ»·ÝÎļþÔ̺¬ZaryaÓëFSBÔ±¹¤µÄ¶Ô»°£¬£¬£¬£¬£¬£¬ËûÃÇÔ¤¼Æ³É¹¦µÄ¹¥»÷½«µ¼ÖÂÅ䯸վ²úÉú±¬Õ¨£¬£¬£¬£¬£¬£¬²¢Ôڼල¼ÓÄôóÐÂÎű¨Â·¿´ÊÇ·ñÓб¬Õ¨¼£Ï󡣡£¡£¡£¡£¡£¡£¸ÃÎļþµÄÕæÊµÐÔÉÐδµÃµ½Ö¤Êµ¡£¡£¡£¡£¡£¡£¡£¼ÓÄôó×ÜÀíÈ·ÈÏÁËÕë¶ÔÌìÈ»Æø¹Ü·µÄÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬µ«ËûÖ¸³ö¼ÓÄôóµÄÈκÎÄÜÔ´»ù´¡ÉèÊ©¶¼Ã»ÓÐÊܵ½ÏÖʵÇÖº¦¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/145307/cyber-warfare-2/canadian-gas-pipeline-disruptive-attack.html
2¡¢Alloy TaurusÀûÓÃPingPullбäÌå¹¥»÷ÄϷǺÍÄá²´¶û
4ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬Unit 42³Æ×î½ü·¢ÏÖAlloy TaurusÍÅ»ïʹÓÃPingPullºóÃŵÄбäÌå¹¥»÷LinuxϵͳµÄ»î¶¯£¬£¬£¬£¬£¬£¬¸Ã»î¶¯ÖØÒªÕë¶ÔÄϷǺÍÄá²´¶û¡£¡£¡£¡£¡£¡£¡£3ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÉÏ´«µ½VirusTotalµÄPingPullµÄLinux±äÌ壬£¬£¬£¬£¬£¬ËüµÄ¼ì²âÂʼ«¶ÈµÍ¡£¡£¡£¡£¡£¡£¡£PingPullÖÐʹÓõĺÅÁî´¦Ö÷¨Ê½ÓëÔÚÁíÒ»¸ö¶ñÒâÈí¼þChina ChopperµÄÖз¢ÏֵĺÅÁî´¦Ö÷¨Ê½ÀàËÆ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬Unit 42»¹·¢ÏÖÁËÒ»¸öеÄELFºóÃÅSword2033£¬£¬£¬£¬£¬£¬Á´½Óµ½Ò»ÑùµÄC2»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬Ö§³ÖÉÏ´«¡¢Ð¹Â¶ÎļþºÍÖ´ÐкÅÁîÈý¸ö¸ù»ùÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£
https://unit42.paloaltonetworks.com/alloy-taurus/
3¡¢FIN7ÍÅ»ïÀûÓÃ×î½ü½¨¸´µÄVeeam·ì϶·Ö·¢ºóÃÅLizar
WithSecureÔÚ4ÔÂ26ÈÕÅû¶ÁËFIN7ÍÅ»ïÕë¶ÔVeeam±¸·Ý·þÎñÆ÷µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£3ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÔÚÔËÐÐVeeam Backup & ReplicationÈí¼þµÄ·þÎñÆ÷Éϼì²âµ½³õʼ»î¶¯¡£¡£¡£¡£¡£¡£¡£ÓëVeeam BackupÊ·ýÓйصÄSQL·þÎñÆ÷¹ý³Ìsqlservr.exeÖ´ÐÐÁËÒ»¸öshellºÅÁ£¬£¬£¬£¬£¬¸ÃºÅÁîÔÚÄÚ´æÖÐÏÂÔØ²¢Ö´ÐÐPowerShell¾ç±¾¡£¡£¡£¡£¡£¡£¡£ÕâЩPowerShell¾ç±¾µÄËùÓÐÊ·ý¶¼ÊÇPowertrash dropper£¬£¬£¬£¬£¬£¬ËüÓÃÓÚ·Ö·¢ºóÃÅDiceloader£¨Ò²³ÆÎªLizar£©¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯µÄ³õʼ½Ó¼ûºÍÖ´ÐкܿÉÄÜÊÇͨ¹ý×î½ü½¨¸´µÄVeeam Backup & Replication·ì϶£¨CVE-2023-27532£©ÊµÏֵġ£¡£¡£¡£¡£¡£¡£
https://labs.withsecure.com/publications/fin7-target-veeam-servers
4¡¢ÎÚ¿ËÀ¼¾¯·½¿ÛÁôÔøÏúÊÛ³¬¹ý3ÒÚ¹«ÃñÓ×ÎÒÐÅÏ¢µÄÏÓÒÉÈË
ýÌå4ÔÂ26Èճƣ¬£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼ÍøÂ羯Ա¿ÛÁôÁËÀ´×ÔNetishynµÄÒ»Ãû36ËêÄÐ×Ó£¬£¬£¬£¬£¬£¬×ïÃûÊÇÏúÊÛ³¬¹ý3ÒÚÎÚ¿ËÀ¼ºÍÅ·ÖÞÁйú¹«ÃñµÄÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÏÓÒÉÈËʹÓÃTelegramÏò¸ÐÐËÖµÄÂò¼ÒÍÆÏú±»µÁÊý¾Ý£¬£¬£¬£¬£¬£¬Æ¾¾ÝÊý¾ÝÁ¿¼°Æä¼ÛÖµ£¬£¬£¬£¬£¬£¬Òª¼ÛÔÚ500µ½2000ÃÀÔªÖ®¼ä¡£¡£¡£¡£¡£¡£¡£Éæ¼°»¤ÕÕÊý¾Ý¡¢ÄÉ˰È˱àºÅ¡¢µ®ÉúÖ¤Ã÷¡¢¼ÝÊ»ÅÆÕÕºÍÒøÐÐÕË»§Êý¾ÝµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬·¨ÂÉÈËÔ±²éÊÕÁË36¸öÓ²ÅÌÇý¶¯Æ÷¡¢ÍÆËã»úºÍ·þÎñÆ÷É豸£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬¶à¸öÊý¾Ý¿â£¬£¬£¬£¬£¬£¬ÆäÆðÔ´½«Í¨¹ýºóÐø·ÖÎöÈ·¶¨¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/ukrainian-arrested-for-selling-data-of-300m-people-to-russians/
5¡¢Linux°æ±¾µÄRTM LockerÕë¶ÔVMware ESXi·þÎñÆ÷
UptycsÔÚ4ÔÂ26ÈÕ°ä²¼ÁËÒ»·Ý»ã±¨£¬£¬£¬£¬£¬£¬·ÖÎöÁËRTM LockerµÄÒ»¸öLinux±äÌ壬£¬£¬£¬£¬£¬¸Ã±äÌå»ùÓÚÏÖÒÑDzɢµÄBabukÀÕË÷Èí¼þµÄÔ´´úÂë¡£¡£¡£¡£¡£¡£¡£RTM LockerµÄLinux°æ±¾¼ÓÃÜ·¨Ê½ËƺõÊÇרÃÅΪ¹¥»÷VMware ESXiϵͳ¿ª·¢µÄ£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÔ̺¬Á˺ܶàÓÃÓÚÖÎÀíÐé¹¹»úµÄºÅÁî¡£¡£¡£¡£¡£¡£¡£ÓëBabukÒ»Ñù£¬£¬£¬£¬£¬£¬RTMʹÓÃËæ»úÊýÌìÉúºÍECDH¶ÔCurve25519½øÐзǶԳƼÓÃÜ£¬£¬£¬£¬£¬£¬µ«ËüûÓÐʹÓÃSosemanuk£¬£¬£¬£¬£¬£¬¶øÊÇÒÀ¸½ChaCha20½øÐжԳƼÓÃÜ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬ESXi°æ±¾µÄ´æÔÚ£¬£¬£¬£¬£¬£¬×ãÒÔ½«RTM Locker¹éÀàΪÕë¶ÔÆóÒµµÄ³Á´óÍþв¡£¡£¡£¡£¡£¡£¡£
https://www.uptycs.com/blog/rtm-locker-ransomware-as-a-service-raas-linux
6¡¢LayerX°ä²¼¹ØÓÚ2023Äêä¯ÀÀÆ÷°²È«µÄµ÷²é·ÖÎö»ã±¨
¾Ý4ÔÂ26ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬LayerX°ä²¼¹ØÓÚ2023Äêä¯ÀÀÆ÷°²È«µÄµ÷²é·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬ÔÚ´Óǰ12¸öÔÂÖУ¬£¬£¬£¬£¬£¬87%µÄall-SaaSºÍ79%»ìºÏ»·¾³ÖеÄCISO¶¼¾Àú¹ý°²È«ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£ÕÊ»§ÊÕÊÜÊÇ×îÁîÈËÓÇÓôµÄÎÊÌ⣬£¬£¬£¬£¬£¬48%µÄÈ˽«Í´´¦ÍøÂç´¹µöÁÐΪ·çÏÕ×î¸ßµÄä¯ÀÀÆ÷Íþв£¬£¬£¬£¬£¬£¬Æä´ÎÊǶñÒâä¯ÀÀÆ÷À©´ó(37%)¡¢¶ñÒâÈí¼þÏÂÔØ(9%)ºÍä¯ÀÀÆ÷·ì϶(6%)¡£¡£¡£¡£¡£¡£¡£´óÎÞÊý×é֯ѡȡÖÁÉÙÁ½ÖÖ°²È«´ëÊ©À´Õмܴ¹µö¹¥»÷£¬£¬£¬£¬£¬£¬79%ʹÓÃÍøÂ簲ȫ¹¤¾ß£¬£¬£¬£¬£¬£¬ÀýÈç·À»ðǽºÍSWG¡£¡£¡£¡£¡£¡£¡£
https://go.layerxsecurity.com/2023-browser-security-survey


¾©¹«Íø°²±¸11010802024551ºÅ