ArmisÅû¶PTSϵͳÖеÄͳ³ÆÎªPwnedPiperµÄ·ì϶£»£»£»£»£»£»£»CyCraft°ä²¼Õë¶ÔÀÕË÷Èí¼þPrometheusµÄÃâ·Ñ½âÃÜÆ÷
°ä²¼¹¦·ò 2021-08-03
°²È«¹«Ë¾ArmisÅû¶SwissLogµÄTransLogic PTS£¨Æø¶¯¹Üϵͳ) ÖÐͳ³ÆÎªPwnedPiperµÄ9¸ö·ì϶£¬£¬£¬£¬£¬Ó°ÏìÈ«ÃÀ80%µÄÒ½Ôº¡£¡£¡£¡£¡£¡£¡£TransLogic PTSÓÃÓÚÔÚ´óÖÐÐÍÒ½ÔºÖг¤¾àÀëÔËËÍÒ½ÁÆÎïÆ·£¬£¬£¬£¬£¬ÒÑÔÚ±±ÃÀ2300¶à¼ÒҽԺʹÓᣡ£¡£¡£¡£¡£¡£ÕâЩ·ì϶ÖÐ×îÑϳÁµÄÊÇδ¾Éí·ÝÑéÖ¤¡¢Î´¼ÓÃÜ¡¢Î´ÊðÃûµÄ¹Ì¼þÉý¼¶·ì϶£¨CVE-2021-37160£©£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÔÚϵͳÉÏ×°ÖöñÒâ¹Ì¼þÀ´ÆëÈ«½ÚÔìÖ¸±êϵͳ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬»¹ÓÐÌáȨ·ì϶£¨CVE-2021-37167£©¡¢DoS·ì϶£¨CVE-2021-37166£©ºÍtcpTxThreadÖеÄÈý±¶²Ö¿âÒç³ö£¨CVE-2021-37164£©µÈ·ì϶¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/08/pwnedpiper-pts-security-flaws-threaten.html
2.KasperskyÅû¶ÐµÄGhostEmperorÍÅ»ïÕë¶Ô¶«ÄÏÑÇ

KasperskyÅû¶ÁËÒ»¸öеĺڿÍÍÅ»ïGhostEmperor£¬£¬£¬£¬£¬ÖØÒªÕë¶Ô¶«ÄÏÑǵØÓòµÄÖ¸±ê£¬£¬£¬£¬£¬Ô̺¬µ±¾Ö»ú¹¹ºÍ¼¸¼ÒµçÐŹ«Ë¾¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïµÄÈëÇֻÒÀÀµÓÚCheat Engine¿ªÔ´ÏîÖ÷ÕÅÒ»¸ö×é¼þ£¬£¬£¬£¬£¬Ëü¿ÉÄÜÈÆ¹ýWindowsÇý¶¯·¨Ê½Ç¿ÔìÊðÃû»úÔì¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÖ®ËùÒÔÒìºõѰ³££¬£¬£¬£¬£¬ÊÇÓÉÓÚËüʹÓÃÁËÒ»¸öÒÔǰ²»ÎªÈËÖªµÄWindowsÄÚºËģʽµÄrootkit£¬£¬£¬£¬£¬²¢ÇÒѡȡÁ˸´ÔӵĶà½×¶Î¶ñÒâÈí¼þ¿ò¼Ü£¬£¬£¬£¬£¬Ö¼ÔÚ¶ÔÖ¸±ê·þÎñÆ÷½øÐÐÔ¶³Ì½ÚÔì¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120721/apt/ghostemperor-chinese-speaking-threat-actor.html
3.CiscoÅû¶¶ñÒâÈí¼þSolarmarkerÐÂÒ»ÂֵĹ¥»÷»î¶¯

Cisco TalosÅû¶Á˶ñÒâÈí¼þSolarmarkerÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£ÔÚ2021Äê5Ôµ׺Í6Ô³õ×óÓÒ£¬£¬£¬£¬£¬Talos¼ì²âµ½ÐÂÒ»ÂÖSolarmarker¹¥»÷»î¶¯¼¤Ôö¡£¡£¡£¡£¡£¡£¡£ÔÚ×î½üµÄÕâЩµü´úÖУ¬£¬£¬£¬£¬¹¥»÷Õßµ÷ÕûÁ˳õʼdropperµÄÏÂÔØ²½Ö裬£¬£¬£¬£¬²¢¶Ôstaging×é¼þ£¨´Ë¿Ì³ÆÎªMars£©½øÐÐÁËÉý¼¶¡£¡£¡£¡£¡£¡£¡£ÒÔǰSolarmarker½«´Ó´øÓÐͨÓñêÌâÃû³ÆPdfDocDownloadsPanelµÄÒ³ÃæÏÂÔØ£¬£¬£¬£¬£¬¶øÕâ´Î»î¶¯ÖеÄÏÂÔØÒ³ÃæÏÖαÔì³ÉÀ´×ԹȸèDriveµÄÏÂÔØÎļþÒªÇ󣬣¬£¬£¬£¬¿´ÆðÀ´Ô½·¢ºÏ·¨¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/07/threat-spotlight-solarmarker.html
4.CyCraft°ä²¼Õë¶ÔÀÕË÷Èí¼þPrometheusµÄÃâ·Ñ½âÃÜÆ÷

°²È«¹«Ë¾CyCraft°ä²¼Ãâ·Ñ½âÃÜÆ÷£¬£¬£¬£¬£¬Ô®ÊÖÀÕË÷Èí¼þPrometheusµÄÊܺ¦Õ߸´ÔºÍ½âÃÜÎļþ¡£¡£¡£¡£¡£¡£¡£CyCraft°µÊ¾£¬£¬£¬£¬£¬PrometheusʹÓÃÁËSalsa20ºÍ»ùÓÚtickcountµÄËæ»úÃÜÂëÀ´¼ÓÃÜÎļþ¡£¡£¡£¡£¡£¡£¡£Ëæ»úÃÜÂëµÄ´óÓ×Ϊ32×Ö½Ú£¬£¬£¬£¬£¬Ã¿¸ö×Ö·û¶¼Êǿɼû×Ö·û£¬£¬£¬£¬£¬²¢ÇÒÓÉÓÚÃÜÂëÒÔtickcount×÷ΪÃÜÔ¿£¬£¬£¬£¬£¬ËùÒÔÄܹ»Ê¹Óñ©Á¦ÆÆ½â¡£¡£¡£¡£¡£¡£¡£Emsisoft¹«Ë¾°µÊ¾¸Ã½âÃÜÆ÷ΨһµÄ±×¶ËÊÇÖ»ÄÜÆÆ½âÓ×ÎļþµÄ½âÃÜÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬½âÃÜÆ÷°ä²¼²»¾Ãºó£¬£¬£¬£¬£¬PrometheusÍÅ»ïËÆºõÒѾÖÕ³¡ÁËÐж¯¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/decryptor-released-for-prometheus-ransomware-victims/
5.SonicWall°ä²¼2021ÄêÉϰëÄêÍøÂçÌ¬ÊÆµÄ·ÖÎö»ã±¨

SonicWall°ä²¼ÁË2021ÄêÉϰëÄêÍøÂçÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ÀÕË÷Èí¼þ¹¥»÷ÔÚ2021ÄêÉϰëÄ꼫¶È·è¿ñ£¬£¬£¬£¬£¬¸Ã¹«Ë¾¼ì²âµ½µÄ¹¥»÷³¢ÊÔ´ïµ½3.047ÒڴΣ¬£¬£¬£¬£¬ ³¬¹ýÁË2020ÕûÄêµÄ¹¥»÷×ÜÊý¡£¡£¡£¡£¡£¡£¡£ÃÀ¹ú¡¢Ó¢¹ú¡¢µÂ¹ú¡¢ÄϷǺͰÍÎ÷µÈ¹ú¶ÈÊÇÊÜÀÕË÷Èí¼þ¹¥»÷×îÑϳÁµÄ¹ú¶È£¬£¬£¬£¬£¬ÆäÖÐÃÀ¹úÊÜÓ°Ïì½Ï´óµÄµØÓòÊÇ·ðÂÞÀï´ïÖÝ£¬£¬£¬£¬£¬ÓÐ1.111Òڴι¥»÷³¢ÊÔ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ÀÕË÷¹¥»÷×î³£¼ûµÄÖ¸±êÊǽðÈÚ»ú¹¹ÒÔ¼°¹ú·ÀµÈ³ÁҪȷµ±¾Ö×éÖ¯£¬£¬£¬£¬£¬¶øÕë¶Ô½ÌÓýÐÐÒµµÄ¹¥»÷Ôò¼¤ÔöÁË615%¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.sonicwall.com/2021-cyber-threat-report/
6.Deepinstinct°ä²¼2021ÄêÖÐÍøÂçÍþÐ²Ì¬ÊÆ·ÖÎö»ã±¨

Deep Instinct°ä²¼ÁË2021ÄêÖÐÍøÂçÍþÐ²Ì¬ÊÆ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ÀÕË÷Èí¼þÒ»ÏòÊÇÕû¸ö2021ÄêµÄÖ÷µ¼Ç÷Ïò£¬£¬£¬£¬£¬ÆäÖÐÖØÒªÍþвΪSTOP(Djvu)¡¢RyukºÍSodinokibi(REvil)µÈ¡£¡£¡£¡£¡£¡£¡£ÒøÐÐľÂí»î¶¯µÄÖØÒªÍþвΪEmotetµÄ¼ÌÈÎÕߣ¬£¬£¬£¬£¬ÀýÈçRamnit¡¢QbotºÍIcedID¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Õë¶ÔColonial PipelineµÄ¹¥»÷³ÉΪȫÇòµÄ½¹µã£¬£¬£¬£¬£¬µ«ÕâÖ»Êǹ¥»÷¹Ø¼ü»ù´¡ÉèÊ©µÄ¶à¶à¹¥»÷³¢ÊÔÖ®Ò»£¬£¬£¬£¬£¬²¢ÇÒÔ¤¼ÆÕâÖÖ¹¥»÷Õ½Êõ½üÆÚÄÚ²»»á²úÉúŤת¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.deepinstinct.com/2021/07/22/2021-mid-year-cyber-threat-landscape-report/


¾©¹«Íø°²±¸11010802024551ºÅ