ÍøÐŰì°ä²¼¡¶ÍøÐŲ¿ÃÅÐÐÕþ·¨ÂÉ·¨Ê½»®¶¨£¨Õ÷Ç󶨼û¸å£©¡·

°ä²¼¹¦·ò 2022-09-09
1¡¢ÍøÐŰì°ä²¼¡¶ÍøÐŲ¿ÃÅÐÐÕþ·¨ÂÉ·¨Ê½»®¶¨£¨Õ÷Ç󶨼û¸å£©¡·

      

9ÔÂ8ÈÕ£¬£¬ £¬£¬£¬ £¬¹ú¶È»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒ°ä²¼¹ØÓÚ¡¶ÍøÐŲ¿ÃÅÐÐÕþ·¨ÂÉ·¨Ê½»®¶¨£¨Õ÷Ç󶨼û¸å£©¡·¹«¿ªÕ÷Ç󶨼ûµÄ֪ͨ¡£¡£¡£¡£¡£¡£¡£ÎªÁ˹淶ºÍ±£ÏÕÍøÐŲ¿ÃÅÒÀ·¨ÍƹãÖ°Ô𣬣¬ £¬£¬£¬ £¬±£»£»£»£»£»¤¹«Ãñ¡¢·¨ÈËºÍÆäËû×éÖ¯µÄºÏ·¨È¨Àû£¬£¬ £¬£¬£¬ £¬ÊØ»¤¹ú¶È°²È«ºÍ¹«¹²ÀûÒæ£¬£¬ £¬£¬£¬ £¬ÍøÐŰì¶Ô¡¶»¥ÁªÍøÐÅÏ¢ÄÚÈÝÖÎÀíÐÐÕþ·¨ÂÉ·¨Ê½»®¶¨¡·½øÐж©Õý£¬£¬ £¬£¬£¬ £¬ÐγÉÁË¡¶ÍøÐŲ¿ÃÅÐÐÕþ·¨ÂÉ·¨Ê½»®¶¨£¨Õ÷Ç󶨼û¸å£©¡·£¬£¬ £¬£¬£¬ £¬ÏÖÏòÉç»á¹«¿ªÕ÷Ç󶨼û¡£¡£¡£¡£¡£¡£¡£¹«¼Ò¿Éͨ¹ýµÇ¼Öйúµ±¾Ö·¨ÔìÐÅÏ¢Íø¡¢·¢Ë͵ç×ÓÓʼþºÍ¼ÄËÍÐź¯µÄ·½Ê½Ìá³ö·´À¡¶¨¼û¡£¡£¡£¡£¡£¡£¡£


http://www.cac.gov.cn/2022-09/08/c_1664174174624227.htm


2¡¢ºÚ¿ÍÔÚ°µÍøÏúÊÛ´ÓÆÏÌÑÑÀÎä×°¶ÓÁÐ×ÜÕÕ·÷²¿ÇÔÈ¡µÄÎļþ

      

¾ÝýÌå9ÔÂ8ÈÕ±¨Â·£¬£¬ £¬£¬£¬ £¬ÆÏÌÑÑÀÎä×°¶ÓÁÐ×ÜÕÕ·÷²¿£¨EMGFA£©Óë±±Ô¼ÓйصĻúÃÜÎļþ±»ÔÚ°µÍøÉÏÏúÊÛ¡£¡£¡£¡£¡£¡£¡£EMGFAÊÇÆÏÌÑÑÀµÄ×î¸ß¾üÊ»ú¹¹£¬£¬ £¬£¬£¬ £¬ËüÕÆ¹ÜÆÏÌÑÑÀÎä×°¶ÓÁеĹ滮¡¢Ö¸»ÓºÍ½ÚÔì¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß°ä²¼Á˱»µÁÎļþµÄÑù±¾×÷Ϊ¹¥»÷Ö¤¾Ý£¬£¬ £¬£¬£¬ £¬ÃÀ¹úÐÅÏ¢·þÎñ²¿·¢ÏÖÁËÕâЩÎļþ£¬£¬ £¬£¬£¬ £¬²¢Í¨ÖªÆÏÌÑÑÀµ±¾Ö¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý³õ´ëÊ©²é£¬£¬ £¬£¬£¬ £¬ÕâЩÎļþÊÇ´ÓEMGFA¡¢°ÂÃØ¾ü¶Ó(CISMIL)ºÍ¹ú·À×ÊÔ´×ֵܾÄϵͳÖÐй¶µÄ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖ£¬£¬ £¬£¬£¬ £¬»úÃÜÎļþ´«ÊäµÄ°²È«¹æ¶¨Òѱ»·ÛË飬£¬ £¬£¬£¬ £¬¹¥»÷Õß¿ÉÄܽӼû¾üÊÂͨѶ×ÛºÏϵͳ(SICOM)£¬£¬ £¬£¬£¬ £¬²¢½Ó¹ÜºÍת·¢»úÃÜÎļþ¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/135480/data-breach/nato-docs-stolen-from-portugal.html


3¡¢Î¢ÈíÅû¶DEV-0270½üÆÚµÄÀÕË÷¹¥»÷±³ºóµÄÕ½ÊõºÍ¼¼Êõ

      

΢ÈíÓÚ9ÔÂ7ÈÕ³ÆÆäÍþвµý±¨ÍŶÓÒ»ÏòÔÚ¸ú×Ù¶à¸öÀÕË÷¹¥»÷»î¶¯£¬£¬ £¬£¬£¬ £¬²¢½«ÕâЩ¹¥»÷ÓëDEV-0270£¨Ò²³ÆNemesis Kitten£©ÁªÏµÆðÀ´¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÊÇÒÁÀÊPHOSPHORUSµÄÒ»¸ö×Ó×éÖ¯£¬£¬ £¬£¬£¬ £¬ÓÉÒ»¼ÒÒÔ¹«¿ª±ðºÅSecnerd£¨secnerd[.]ir£©ºÍLifeweb£¨lifeweb[.]ir£©ÔË×÷µÄ¹«Ë¾ÔËÓª¡£¡£¡£¡£¡£¡£¡£DEV-0270ÔÚ¹¥»÷Á´ÖÐ¿í·ºµØÀûÓÃÁËÔ¶³Ì¶þ½øÔìÎļþ(LOLBIN)½øÐпúËźÍÍ´´¦½Ó¼û£¬£¬ £¬£¬£¬ £¬²¢ÀÄÓÃÄÚÖõÄBitLocker¹¤¾ßÀ´¼ÓÃÜÖ¸±êÉ豸ÉϵÄÎļþ¡£¡£¡£¡£¡£¡£¡£


https://www.microsoft.com/security/blog/2022/09/07/profiling-dev-0270-phosphorus-ransomware-operations/


4¡¢LazarusÀûÓÃжñÒâÈí¼þMagicRA¹¥»÷È«ÇòµÄ×éÖ¯

      

Cisco TalosÔÚ9ÔÂ7ÈÕÅû¶ÐµÄÔ¶³Ì½Ó¼ûľÂíMagicRATÓ볯ÏÊLazarusÓйØ¡£¡£¡£¡£¡£¡£¡£ÐÂRAT×î³õÊÇͨ¹ý¶³öµÄVMware Horizonƽ̨ÈëÇÖÖ¸±ê£¬£¬ £¬£¬£¬ £¬ËüÓµÓÐÏà¶Ôµ¥Ò»µÄRATÖ°ÄÜ£¬£¬ £¬£¬£¬ £¬½èÖúQt¿ò¼Ü¹¹½¨£¬£¬ £¬£¬£¬ £¬²¢ÇÒ²»Ì«¿ÉÄÜͨ¹ý»úе½ø½¨ºÍÆô·¢Ê½½øÐÐ×Ô¶¯¼ì²â¡£¡£¡£¡£¡£¡£¡£MagicRATÒ»µ©×°ÖþͻáÖ´Ðжî±íµÄpayload£¬£¬ £¬£¬£¬ £¬ÀýÈ綨ÔìµÄ¶Ë¿ÚɨÃ蹤¾ß¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬ £¬MagicRATµÄC2»ù´¡ÉèÊ©»¹ÓÃÓÚÍйÜLazarusÖ²È뷨ʽµÄ±äÌ壬£¬ £¬£¬£¬ £¬ÈçTigerRAT¡£¡£¡£¡£¡£¡£¡£ÔÚÒ°±í·¢ÏÖµÄMagicRATÅú×¢LazarusÓж¯»ú¼±¾ç¹¹½¨ÐµÄ×Ô½ç˵¶ñÒâÈí¼þ£¬£¬ £¬£¬£¬ £¬ÓÃÓÚÓëÆä֮ǰµÄ¶ñÒâÈí¼þ£¨ÈçTigerRAT£©Ò»Â·ÀûÓ㬣¬ £¬£¬£¬ £¬À´¹¥»÷È«ÇòµÄ×éÖ¯¡£¡£¡£¡£¡£¡£¡£


https://blog.talosintelligence.com/2022/09/lazarus-magicrat.html


5¡¢¹È¸è³ÆContiǰ³ÉÔ±½«Æä¼¼Êõ³ÁÐÂÓÃÓÚÕë¶ÔÎÚ¿ËÀ¼µÄ»î¶¯

      

¹È¸èTAGÔÚ9ÔÂ7ÈÕ¹«¿ªÁË2022Äê4ÔÂÖÁ8ÔÂÆÚ¼ä·¢Õ¹µÄ5¸öÓëUAC-0098ÓйصĻµÄϸ½Ú¡£¡£¡£¡£¡£¡£¡£UAC-0098ÊÇÒ»¸ö³õʼ½Ó¼û´úÀí£¬£¬ £¬£¬£¬ £¬ÀûÓÃIcedIDΪÀÕË÷ÍÅ»ïÌṩ¶ÔÆóҵϵͳµÄ½Ó¼û¡£¡£¡£¡£¡£¡£¡£TAG´§¶ÈUAC-0098µÄһЩ³ÉÔ±ÊÇContiÍÅ»ïµÄǰ³ÉÔ±£¬£¬ £¬£¬£¬ £¬ËûÃǽ«Æä¼¼Êõ³ÁÐÂÓÃÓÚÕë¶ÔÎÚ¿ËÀ¼µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£2022Äê4ÔÂÏÂÑ®£¬£¬ £¬£¬£¬ £¬×êÑÐÈËÔ±·¢ÏÖÁË´«²¼AnchorMail£¨±»³ÆÎª¡°LackeyBuilder¡±£©µÄ´¹µö»î¶¯£¬£¬ £¬£¬£¬ £¬Ö®ºóÆðÍ·¸ú×ÙUAC-0098¡£¡£¡£¡£¡£¡£¡£ÔÚºóÐøµÄ»î¶¯ÖУ¬£¬ £¬£¬£¬ £¬UAC-0098»¹¹¥»÷ÁËÎÚ¿ËÀ¼×éÖ¯ºÍÅ·Ö޷ǵ±¾Ö×éÖ¯¡£¡£¡£¡£¡£¡£¡£


https://blog.google/threat-analysis-group/initial-access-broker-repurposing-techniques-in-targeted-attacks-against-ukraine/


6¡¢Kaspersky°ä²¼2022ÄêÓëÓÎÏ·ÓйصÄÍøÂçÍþвµÄ¸ÅÊö

      

9ÔÂ6ÈÕ£¬£¬ £¬£¬£¬ £¬Kaspersky°ä²¼ÁË2022ÄêÓëÓÎÏ·ÓйصÄÍøÂçÍþвµÄ¸ÅÊö¡£¡£¡£¡£¡£¡£¡£2021Äê1ÔÂÖÁ2022Äê6ÔÂÆÚ¼ä£¬£¬ £¬£¬£¬ £¬Óöµ½ÓëÓÎÏ·ÓйصĶñÒâÈí¼þºÍÀ¬»øÈí¼þµÄÓû§×ÜÊýΪ384224ÈË£»£»£»£»£»ÓëMinecraftÓйصÄÎļþԼռͨ¹ýÓÎÏ·ÀÄÓô«²¼µÄ¶ñÒâÎļþµÄ25%£¬£¬ £¬£¬£¬ £¬Æä´ÎÊÇFIFA(11%)¡¢Roblox(9.5%)¡¢Far Cry(9.4%£©ºÍʹÃüºô»½£¨9%£©¡£¡£¡£¡£¡£¡£¡£2022ÄêÉϰëÄ꣬£¬ £¬£¬£¬ £¬±»ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ¹¥»÷µÄÓû§ÊýÁ¿ÏÔÖøÔö³¤£¬£¬ £¬£¬£¬ £¬±È2021ÄêÉϰëÄêÔö³¤ÁË13%£»£»£»£»£»¹¥»÷Õß¼Ó´óÁË·Ö·¢Trojan-PSWµÄÁ¦¶È£¬£¬ £¬£¬£¬ £¬77%µÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þµÄϰȾ°¸ÀýÓëTrojan-PSWÓйØ¡£¡£¡£¡£¡£¡£¡£


https://securelist.com/gaming-related-cyberthreats-2021-2022/107346/