¼ÓÄôóij×ÔÈ»Æø¹ÜµÀÔâµ½ZaryaµÄ¹¥»÷¿ÉÄܻᱬը
Ðû²¼Ê±¼ä 2023-04-281¡¢¼ÓÄôóij×ÔÈ»Æø¹ÜµÀÔâµ½ZaryaµÄ¹¥»÷¿ÉÄܻᱬը
¾ÝýÌå4ÔÂ26ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬¼ÓÄôóij×ÔÈ»Æø¹ÜÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜ»áÒý·¢±¬Õ¨¡£¡£¡£¡£Å¦Ô¼Ê±±¨³Æ£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÃÀ¹úÇ鱨ÎļþÕ¹ÏÖÁËÕâÒ»ÊÂÎñ¡£¡£¡£¡£ÆäÖÐÒ»·ÝÎļþ°üÀ¨ZaryaÓëFSBÔ±¹¤µÄ¶Ô»°£¬£¬£¬£¬£¬£¬£¬ËûÃÇÔ¤¼ÆÀֳɵĹ¥»÷½«µ¼ÖÂÅ䯸վ±¬·¢±¬Õ¨£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ¼àÊÓ¼ÓÄôóÐÂÎű¨µÀ¿´ÊÇ·ñÓб¬Õ¨¼£Ï󡣡£¡£¡£¸ÃÎļþµÄÕæÊµÐÔÉÐδ»ñµÃ֤ʵ¡£¡£¡£¡£¼ÓÄôó×ÜÀíÈ·ÈÏÁËÕë¶Ô×ÔÈ»Æø¹ÜµÀµÄÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ«ËûÖ¸³ö¼ÓÄôóµÄÈκÎÄÜÔ´»ù´¡ÉèÊ©¶¼Ã»ÓÐÊܵ½ÏÖʵË𺦡£¡£¡£¡£
https://securityaffairs.com/145307/cyber-warfare-2/canadian-gas-pipeline-disruptive-attack.html
2¡¢Alloy TaurusʹÓÃPingPullбäÌå¹¥»÷ÄϷǺÍÄá²´¶û
4ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬£¬Unit 42³Æ×î½ü·¢Ã÷Alloy TaurusÍÅ»ïʹÓÃPingPullºóÃŵÄбäÌå¹¥»÷LinuxϵͳµÄ»î¶¯£¬£¬£¬£¬£¬£¬£¬¸Ã»î¶¯Ö÷ÒªÕë¶ÔÄϷǺÍÄá²´¶û¡£¡£¡£¡£3ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öÉÏ´«µ½VirusTotalµÄPingPullµÄLinux±äÌ壬£¬£¬£¬£¬£¬£¬ËüµÄ¼ì²âÂʺÜÊǵ͡£¡£¡£¡£PingPullÖÐʹÓõÄÏÂÁî´¦Öóͷ£³ÌÐòÓëÔÚÁíÒ»¸ö¶ñÒâÈí¼þChina ChopperµÄÖз¢Ã÷µÄÏÂÁî´¦Öóͷ£³ÌÐòÏàËÆ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Unit 42»¹·¢Ã÷ÁËÒ»¸öеÄELFºóÃÅSword2033£¬£¬£¬£¬£¬£¬£¬Á´½Óµ½ÏàͬµÄC2»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬Ö§³ÖÉÏ´«¡¢Ð¹Â¶ÎļþºÍÖ´ÐÐÏÂÁîÈý¸ö»ù±¾¹¦Ð§¡£¡£¡£¡£
https://unit42.paloaltonetworks.com/alloy-taurus/
3¡¢FIN7ÍÅ»ïʹÓÃ×î½üÐÞ¸´µÄVeeamÎó²î·Ö·¢ºóÃÅLizar
WithSecureÔÚ4ÔÂ26ÈÕÅû¶ÁËFIN7ÍÅ»ïÕë¶ÔVeeam±¸·ÝЧÀÍÆ÷µÄ¹¥»÷»î¶¯¡£¡£¡£¡£3ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÔÚÔËÐÐVeeam Backup & ReplicationÈí¼þµÄЧÀÍÆ÷Éϼì²âµ½³õʼ»î¶¯¡£¡£¡£¡£ÓëVeeam BackupʵÀýÏà¹ØµÄSQLЧÀÍÆ÷Àú³Ìsqlservr.exeÖ´ÐÐÁËÒ»¸öshellÏÂÁ£¬£¬£¬£¬£¬£¬¸ÃÏÂÁîÔÚÄÚ´æÖÐÏÂÔØ²¢Ö´ÐÐPowerShell¾ç±¾¡£¡£¡£¡£ÕâЩPowerShell¾ç±¾µÄËùÓÐʵÀý¶¼ÊÇPowertrash dropper£¬£¬£¬£¬£¬£¬£¬ËüÓÃÓÚ·Ö·¢ºóÃÅDiceloader£¨Ò²³ÆÎªLizar£©¡£¡£¡£¡£¸Ã»î¶¯µÄ³õʼ»á¼ûºÍÖ´ÐкܿÉÄÜÊÇͨ¹ý×î½üÐÞ¸´µÄVeeam Backup & ReplicationÎó²î£¨CVE-2023-27532£©ÊµÏֵġ£¡£¡£¡£
https://labs.withsecure.com/publications/fin7-target-veeam-servers
4¡¢ÎÚ¿ËÀ¼¾¯·½¾Ð²¶Ôø³öÊÛÁè¼Ý3ÒÚ¹«ÃñСÎÒ˽¼ÒÐÅÏ¢µÄÏÓÒÉÈË
ýÌå4ÔÂ26Èճƣ¬£¬£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼ÍøÂ羯Ա¾Ð²¶ÁËÀ´×ÔNetishynµÄÒ»Ãû36ËêÄÐ×Ó£¬£¬£¬£¬£¬£¬£¬×ïÃûÊdzöÊÛÁè¼Ý3ÒÚÎÚ¿ËÀ¼ºÍÅ·ÖÞ¸÷¹ú¹«ÃñµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£ÏÓÒÉÈËʹÓÃTelegramÏò¸ÐÐËȤµÄÂò¼ÒÍÆÏú±»µÁÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Æ¾Ö¤Êý¾ÝÁ¿¼°Æä¼ÛÖµ£¬£¬£¬£¬£¬£¬£¬Òª¼ÛÔÚ500µ½2000ÃÀÔªÖ®¼ä¡£¡£¡£¡£Éæ¼°»¤ÕÕÊý¾Ý¡¢ÄÉ˰È˱àºÅ¡¢³öÉú֤ʵ¡¢¼ÝʻִÕÕºÍÒøÐÐÕË»§Êý¾ÝµÈÐÅÏ¢¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬Ö´·¨Ö°Ô±²éÊÕÁË36¸öÓ²ÅÌÇý¶¯Æ÷¡¢ÅÌËã»úºÍЧÀÍÆ÷×°±¸£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨¶à¸öÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬ÆäȪԴ½«Í¨ÊºóÐøÆÊÎöÈ·¶¨¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/ukrainian-arrested-for-selling-data-of-300m-people-to-russians/
5¡¢Linux°æ±¾µÄRTM LockerÕë¶ÔVMware ESXiЧÀÍÆ÷
UptycsÔÚ4ÔÂ26ÈÕÐû²¼ÁËÒ»·Ý±¨¸æ£¬£¬£¬£¬£¬£¬£¬ÆÊÎöÁËRTM LockerµÄÒ»¸öLinux±äÌ壬£¬£¬£¬£¬£¬£¬¸Ã±äÌå»ùÓÚÏÖÒÑÇýÖðµÄBabukÀÕË÷Èí¼þµÄÔ´´úÂë¡£¡£¡£¡£RTM LockerµÄLinux°æ±¾¼ÓÃܳÌÐòËÆºõÊÇרÃÅΪ¹¥»÷VMware ESXiϵͳ¿ª·¢µÄ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËü°üÀ¨ÁËÐí¶àÓÃÓÚÖÎÀíÐéÄâ»úµÄÏÂÁî¡£¡£¡£¡£ÓëBabukÒ»Ñù£¬£¬£¬£¬£¬£¬£¬RTMʹÓÃËæ»úÊýÌìÉúºÍECDH¶ÔCurve25519¾ÙÐзǶԳƼÓÃÜ£¬£¬£¬£¬£¬£¬£¬µ«ËüûÓÐʹÓÃSosemanuk£¬£¬£¬£¬£¬£¬£¬¶øÊÇÒÀÀµChaCha20¾ÙÐжԳƼÓÃÜ¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬£¬£¬ESXi°æ±¾µÄ±£´æ£¬£¬£¬£¬£¬£¬£¬×ãÒÔ½«RTM Locker¹éÀàΪÕë¶ÔÆóÒµµÄÖØ´óÍþв¡£¡£¡£¡£
https://www.uptycs.com/blog/rtm-locker-ransomware-as-a-service-raas-linux
6¡¢LayerXÐû²¼¹ØÓÚ2023Äêä¯ÀÀÆ÷Çå¾²µÄÊÓ²ìÆÊÎö±¨¸æ
¾Ý4ÔÂ26ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬LayerXÐû²¼¹ØÓÚ2023Äêä¯ÀÀÆ÷Çå¾²µÄÊÓ²ìÆÊÎö±¨¸æ¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬ÔÚÒÑÍù12¸öÔÂÖУ¬£¬£¬£¬£¬£¬£¬87%µÄall-SaaSºÍ79%»ìÏýÇéÐÎÖеÄCISO¶¼ÂÄÀú¹ýÇå¾²ÊÂÎñ¡£¡£¡£¡£ÕÊ»§½ÓÊÜÊÇ×îÁîÈ˵£ÐĵÄÎÊÌ⣬£¬£¬£¬£¬£¬£¬48%µÄÈ˽«Æ¾Ö¤ÍøÂç´¹ÂÚÁÐΪΣº¦×î¸ßµÄä¯ÀÀÆ÷Íþв£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊǶñÒâä¯ÀÀÆ÷À©Õ¹(37%)¡¢¶ñÒâÈí¼þÏÂÔØ(9%)ºÍä¯ÀÀÆ÷Îó²î(6%)¡£¡£¡£¡£´ó´ó¶¼×éÖ¯½ÓÄÉÖÁÉÙÁ½ÖÖÇå¾²²½·¥À´µÖÓù´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬79%ʹÓÃÍøÂçÇå¾²¹¤¾ß£¬£¬£¬£¬£¬£¬£¬ÀýÈç·À»ðǽºÍSWG¡£¡£¡£¡£
https://go.layerxsecurity.com/2023-browser-security-survey


¾©¹«Íø°²±¸11010802024551ºÅ