ArmisÅû¶PTSϵͳÖеÄͳ³ÆÎªPwnedPiperµÄ·ì϶ £»£»£» £»£»£»£»CyCraft°ä²¼Õë¶ÔÀÕË÷Èí¼þPrometheusµÄÃâ·Ñ½âÃÜÆ÷

°ä²¼¹¦·ò 2021-08-03
1.ArmisÅû¶PTSϵͳÖеÄͳ³ÆÎªPwnedPiperµÄ·ì϶


1.jpg


°²È«¹«Ë¾ArmisÅû¶SwissLogµÄTransLogic PTS£¨Æø¶¯¹Üϵͳ) ÖÐͳ³ÆÎªPwnedPiperµÄ9¸ö·ì϶£¬£¬£¬ £¬£¬Ó°ÏìÈ«ÃÀ80%µÄÒ½Ôº¡£¡£¡£¡£¡£¡£¡£TransLogic PTSÓÃÓÚÔÚ´óÖÐÐÍÒ½ÔºÖг¤¾àÀëÔËËÍÒ½ÁÆÎïÆ·£¬£¬£¬ £¬£¬ÒÑÔÚ±±ÃÀ2300¶à¼ÒҽԺʹÓᣡ£¡£¡£¡£¡£¡£ÕâЩ·ì϶ÖÐ×îÑϳÁµÄÊÇδ¾­Éí·ÝÑéÖ¤¡¢Î´¼ÓÃÜ¡¢Î´ÊðÃûµÄ¹Ì¼þÉý¼¶·ì϶£¨CVE-2021-37160£©£¬£¬£¬ £¬£¬¿ÉÓÃÀ´ÔÚϵͳÉÏ×°ÖöñÒâ¹Ì¼þÀ´ÆëÈ«½ÚÔìÖ¸±êϵͳ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬»¹ÓÐÌáȨ·ì϶£¨CVE-2021-37167£©¡¢DoS·ì϶£¨CVE-2021-37166£©ºÍtcpTxThreadÖеÄÈý±¶²Ö¿âÒç³ö£¨CVE-2021-37164£©µÈ·ì϶¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/08/pwnedpiper-pts-security-flaws-threaten.html


2.KasperskyÅû¶ÐµÄGhostEmperorÍÅ»ïÕë¶Ô¶«ÄÏÑÇ


2.jpg


KasperskyÅû¶ÁËÒ»¸öеĺڿÍÍÅ»ïGhostEmperor£¬£¬£¬ £¬£¬ÖØÒªÕë¶Ô¶«ÄÏÑǵØÓòµÄÖ¸±ê£¬£¬£¬ £¬£¬Ô̺¬µ±¾Ö»ú¹¹ºÍ¼¸¼ÒµçÐŹ«Ë¾¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïµÄÈëÇֻÒÀÀµÓÚCheat Engine¿ªÔ´ÏîÖ÷ÕÅÒ»¸ö×é¼þ£¬£¬£¬ £¬£¬Ëü¿ÉÄÜÈÆ¹ýWindowsÇý¶¯·¨Ê½Ç¿ÔìÊðÃû»úÔì¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÖ®ËùÒÔÒìºõѰ³££¬£¬£¬ £¬£¬ÊÇÓÉÓÚËüʹÓÃÁËÒ»¸öÒÔǰ²»ÎªÈËÖªµÄWindowsÄÚºËģʽµÄrootkit£¬£¬£¬ £¬£¬²¢ÇÒѡȡÁ˸´ÔӵĶà½×¶Î¶ñÒâÈí¼þ¿ò¼Ü£¬£¬£¬ £¬£¬Ö¼ÔÚ¶ÔÖ¸±ê·þÎñÆ÷½øÐÐÔ¶³Ì½ÚÔì¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120721/apt/ghostemperor-chinese-speaking-threat-actor.html


3.CiscoÅû¶¶ñÒâÈí¼þSolarmarkerÐÂÒ»ÂֵĹ¥»÷»î¶¯


3.jpg


Cisco TalosÅû¶Á˶ñÒâÈí¼þSolarmarkerÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£ÔÚ2021Äê5Ôµ׺Í6Ô³õ×óÓÒ£¬£¬£¬ £¬£¬Talos¼ì²âµ½ÐÂÒ»ÂÖSolarmarker¹¥»÷»î¶¯¼¤Ôö¡£¡£¡£¡£¡£¡£¡£ÔÚ×î½üµÄÕâЩµü´úÖУ¬£¬£¬ £¬£¬¹¥»÷Õßµ÷ÕûÁ˳õʼdropperµÄÏÂÔØ²½Ö裬£¬£¬ £¬£¬²¢¶Ôstaging×é¼þ£¨´Ë¿Ì³ÆÎªMars£©½øÐÐÁËÉý¼¶¡£¡£¡£¡£¡£¡£¡£ÒÔǰSolarmarker½«´Ó´øÓÐͨÓñêÌâÃû³ÆPdfDocDownloadsPanelµÄÒ³ÃæÏÂÔØ£¬£¬£¬ £¬£¬¶øÕâ´Î»î¶¯ÖеÄÏÂÔØÒ³ÃæÏÖαÔì³ÉÀ´×ԹȸèDriveµÄÏÂÔØÎļþÒªÇ󣬣¬£¬ £¬£¬¿´ÆðÀ´Ô½·¢ºÏ·¨¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/07/threat-spotlight-solarmarker.html


4.CyCraft°ä²¼Õë¶ÔÀÕË÷Èí¼þPrometheusµÄÃâ·Ñ½âÃÜÆ÷


4.jpg


°²È«¹«Ë¾CyCraft°ä²¼Ãâ·Ñ½âÃÜÆ÷£¬£¬£¬ £¬£¬Ô®ÊÖÀÕË÷Èí¼þPrometheusµÄÊܺ¦Õ߸´Ô­ºÍ½âÃÜÎļþ¡£¡£¡£¡£¡£¡£¡£CyCraft°µÊ¾£¬£¬£¬ £¬£¬PrometheusʹÓÃÁËSalsa20ºÍ»ùÓÚtickcountµÄËæ»úÃÜÂëÀ´¼ÓÃÜÎļþ¡£¡£¡£¡£¡£¡£¡£Ëæ»úÃÜÂëµÄ´óÓ×Ϊ32×Ö½Ú£¬£¬£¬ £¬£¬Ã¿¸ö×Ö·û¶¼Êǿɼû×Ö·û£¬£¬£¬ £¬£¬²¢ÇÒÓÉÓÚÃÜÂëÒÔtickcount×÷ΪÃÜÔ¿£¬£¬£¬ £¬£¬ËùÒÔÄܹ»Ê¹Óñ©Á¦ÆÆ½â¡£¡£¡£¡£¡£¡£¡£Emsisoft¹«Ë¾°µÊ¾¸Ã½âÃÜÆ÷ΨһµÄ±×¶ËÊÇÖ»ÄÜÆÆ½âÓ×ÎļþµÄ½âÃÜÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬½âÃÜÆ÷°ä²¼²»¾Ãºó£¬£¬£¬ £¬£¬PrometheusÍÅ»ïËÆºõÒѾ­ÖÕ³¡ÁËÐж¯¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/decryptor-released-for-prometheus-ransomware-victims/


5.SonicWall°ä²¼2021ÄêÉϰëÄêÍøÂçÌ¬ÊÆµÄ·ÖÎö»ã±¨


5.jpg


SonicWall°ä²¼ÁË2021ÄêÉϰëÄêÍøÂçÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬ £¬£¬ÀÕË÷Èí¼þ¹¥»÷ÔÚ2021ÄêÉϰëÄ꼫¶È·è¿ñ£¬£¬£¬ £¬£¬¸Ã¹«Ë¾¼ì²âµ½µÄ¹¥»÷³¢ÊÔ´ïµ½3.047ÒڴΣ¬£¬£¬ £¬£¬ ³¬¹ýÁË2020ÕûÄêµÄ¹¥»÷×ÜÊý¡£¡£¡£¡£¡£¡£¡£ÃÀ¹ú¡¢Ó¢¹ú¡¢µÂ¹ú¡¢ÄϷǺͰÍÎ÷µÈ¹ú¶ÈÊÇÊÜÀÕË÷Èí¼þ¹¥»÷×îÑϳÁµÄ¹ú¶È£¬£¬£¬ £¬£¬ÆäÖÐÃÀ¹úÊÜÓ°Ïì½Ï´óµÄµØÓòÊÇ·ðÂÞÀï´ïÖÝ£¬£¬£¬ £¬£¬ÓÐ1.111Òڴι¥»÷³¢ÊÔ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬ÀÕË÷¹¥»÷×î³£¼ûµÄÖ¸±êÊǽðÈÚ»ú¹¹ÒÔ¼°¹ú·ÀµÈ³ÁҪȷµ±¾Ö×éÖ¯£¬£¬£¬ £¬£¬¶øÕë¶Ô½ÌÓýÐÐÒµµÄ¹¥»÷Ôò¼¤ÔöÁË615%¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.sonicwall.com/2021-cyber-threat-report/


6.Deepinstinct°ä²¼2021ÄêÖÐÍøÂçÍþÐ²Ì¬ÊÆ·ÖÎö»ã±¨


6.jpg


Deep Instinct°ä²¼ÁË2021ÄêÖÐÍøÂçÍþÐ²Ì¬ÊÆ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬ £¬£¬ÀÕË÷Èí¼þÒ»ÏòÊÇÕû¸ö2021ÄêµÄÖ÷µ¼Ç÷Ïò£¬£¬£¬ £¬£¬ÆäÖÐÖØÒªÍþвΪSTOP(Djvu)¡¢RyukºÍSodinokibi(REvil)µÈ¡£¡£¡£¡£¡£¡£¡£ÒøÐÐľÂí»î¶¯µÄÖØÒªÍþвΪEmotetµÄ¼ÌÈÎÕߣ¬£¬£¬ £¬£¬ÀýÈçRamnit¡¢QbotºÍIcedID¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬Õë¶ÔColonial PipelineµÄ¹¥»÷³ÉΪȫÇòµÄ½¹µã£¬£¬£¬ £¬£¬µ«ÕâÖ»Êǹ¥»÷¹Ø¼ü»ù´¡ÉèÊ©µÄ¶à¶à¹¥»÷³¢ÊÔÖ®Ò»£¬£¬£¬ £¬£¬²¢ÇÒÔ¤¼ÆÕâÖÖ¹¥»÷Õ½Êõ½üÆÚÄÚ²»»á²úÉúŤת¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.deepinstinct.com/2021/07/22/2021-mid-year-cyber-threat-landscape-report/