¼ÓÄôóBCÊ¡µÄ¶à¸öÕþ¸®ÏµÍ³Ôâµ½ºÚ¿Í¹¥»÷
Ðû²¼Ê±¼ä 2024-05-145ÔÂ12ÈÕ£¬²»Áе߸çÂ×±ÈÑÇÊ¡¹«¹²·þÎñÂôÁ¦ÈËÐû²¼£¬¸ß¶ÈÈ·ÐÅÓйú¼Ò»ò¹ú¼Ò×ÊÖúµÄ¹¥»÷ÕßÊÔͼÔÚÍøÂç¹¥»÷ÖÐÆÆ»µÕþ¸®ÏµÍ³¡£Ã»ÓÐÖ¤¾Ý±íÃ÷ÍøÂç¹¥»÷ÀֳɻñÈ¡ÁËÃô¸ÐÐÅÏ¢£¬Ò²Ã»ÓÐÌá³öÊê½ðÒªÇó¡£Salter ÌåÏÖ£¬¶ÔÍøÂç¹¥»÷µÄÊӲ콫¼ÌÐø½øÐУ¬²¢Ç¿µ÷ÕýÔÚ·ÖÎöÁè¼Ý 40 TB µÄÊý¾Ý£¬±ÈÃÀ¹ú¹ú»áͼÊé¹ÝÉú´æµÄÊý¾Ý»¹Òª¶à¡£Ä¿Ç°ÍøÂç¹¥»÷±³ºóµÄ¶¯»úÈÔ²»Çå³þ¡£¸ÃÊ¡Ê×ϯÐÅÏ¢¹ÙÒÑָʾ¹«¹²·þÎñÔ±¹¤¸ü¸ÄÃÜÂ룬ÒÔ¡°È·±£Õþ¸®µç×ÓÓʼþϵͳµÄÄþ¾²¡±¡£BC ͼÊé¹ÝÌåÏÖ£¬¸Ã»ú¹¹Ò²³ÉΪһÃûºÚ¿ÍµÄ¹¥»÷Ä¿±ê£¬¸ÃºÚ¿ÍÍþв³Æ£¬Èç¹û²»Ö§¸¶Êê½ð£¬¾Í»áй¶Óû§Êý¾Ý¡£
https://www.cbc.ca/news/canada/british-columbia/bc-government-cyberattack-state-actor-1.7200735
2. ³¯ÏʺڿͲ¿Êð¶ñÒâÈí¼þDurianÃé×¼¼ÓÃÜ»õ±Ò¹«Ë¾
5ÔÂ13ÈÕ£¬¾Ý±¨µÀ£¬³¯ÏʺڿÍÕýÔÚÀûÓÃÒ»ÖÖÃûΪDurianµÄÒýÈËעĿµÄжñÒâÈí¼þ±äÌå¶Ôº«¹ú¼ÓÃÜ»õ±Ò¹«Ë¾Ìᳫ¹¥»÷¡£Æ¾¾ÝÍøÂçÄþ¾²¹«Ë¾¿¨°Í˹»ù 5 Ô 9 ÈÕµÄÍþв³ÂËߣ¬³¯ÏʺڿÍ×éÖ¯ Kimsuky ʹÓÃжñÒâÈí¼þ¶ÔÖÁÉÙÁ½¼Ò¼ÓÃÜ»õ±Ò¹«Ë¾½øÐÐÁËһϵÁÐÓÐÕë¶ÔÐԵĹ¥»÷¡£ÕâÊÇͨ¹ýÀûÓú«¹ú¼ÓÃܹ«Ë¾×¨ÓõĺϷ¨Äþ¾²Èí¼þ½øÐÐÁ¬Ðø¹¥»÷À´Íê³ÉµÄ¡£ÒÔǰδ֪µÄ Durian ¶ñÒâÈí¼þ³äµ±°²×°·¨Ê½£¬²¿ÊðÁ¬ÐøµÄ¶ñÒâÈí¼þÁ÷£¬°üÂÞÃûΪAppleSeedµÄºóÃÅ¡¢ÃûΪ LazyLoad µÄ×Ô½ç˵ÊðÀí¹¤¾ßÒÔ¼° Chrome Ô¶³Ì×ÀÃæµÈÆäËûºÏ·¨¹¤¾ß¡£
https://news.hitb.org/content/north-korean-hackers-deploy-durian-malware-targeting-crypto-firms
3. ¶íÂÞ˹ºÚ¿Í½Ù³ÖÎÚ¿ËÀ¼µçÊǪ́µÄÐźÅת²¥Ê¤ÀûÈÕÔıø
5ÔÂ11ÈÕ£¬ºÚ¿Í½Ù³ÖÁ˼¸¼ÒÎÚ¿ËÀ¼µçÊÓƵµÀ£¬×ª²¥ÄªË¹¿ÆʤÀûÈÕÓÎÐУ¬¼ÍÄî¶þÕ½ÖÐÄÉ´âµÂ¹úµÄÕ½°Ü¡£¾ÝÎÚ¿ËÀ¼ÂôÁ¦µçÊӺ͹㲥µÄ»ú¹¹ Nacrada ³Æ£¬ºÚ¿Í½Ù³ÖÁËÐǹâýÌåÆìÏÂÖÁÉÙ 15 ¸öµçÊÓƵµÀµÄ¹ã²¥¡£¸Ã»ú¹¹ÌåÏÖ£¬ºÚ¿Í×ÌÈÅÁˬɱ¤ SES ¹«Ë¾ÓµÓкÍÔËÓªµÄ Astra ͨÐÅÎÀÐǵÄÔËÐС£ÄÉ¿ËÀ´ïÌåÏÖ£¬Æ¾¾Ý SES µÄ˵·¨£¬´ËÀà¸ÉÔ¤¡°Ò»Ö±ÔÚ·¢Éú¡±£¬¶øÇÒͨ³£À´×Ô¶íÂÞ˹¡£ÎÚ¿ËÀ¼½¨Òé¹ã²¥¹«Ë¾Ê¹Óá°Ìæ´úÒªÁ족½ÓÊÕÐźŲ¢¼°Ê±ÏìÓ¦¸ÉÔ¤´ëÊ©¡£ÀÍÑάÑǹú¼Òµç×ÓýÌåίԱ»á (NEPLP) Ö÷ϯÒÁÍ߶û˹¡¤°¢²©ÁÖ˹ (Ivars Abolins) ÌåÏÖ£¬ÖÜËÄ£¬ºÚ¿Í»¹½Ù³ÖÁËÀÍÑάÑǵçÊÓÍøÂç Balticom À´×ª²¥ÄªË¹¿ÆµÄÔıøʽ¡£¾Ý NEPLP ³Æ£¬Balticom ×Ô¼ºµÄ»ù´¡ÉèÊ©²¢Î´Êܵ½Ë𺦣¬µ«ÍøÂç¹¥»÷Õë¶ÔµÄÊÇ Balticom λÓÚ±£¼ÓÀûÑǵĻ¥¶¯µçÊÓ·þÎñÆ÷¡£
https://therecord.media/russian-hackers-hijack-ukraine-tv
4. Ñо¿ÍŶӷ¢ÏÖCaretoʱ¸ô 10 Äêºó¾íÍÁÖØÀ´
5ÔÂ11ÈÕ£¬Ê®¶àÄêÀ´Ê§×ٵĸ߼¶Á¬ÐøÍþв (APT) ×é֯ͻȻÔÚÕë¶ÔÀ¶¡ÃÀÖÞºÍÖзÇ×éÖ¯µÄÍøÂç¼äµý»î¶¯ÖÐÖØзºÆ𡣸Ã×éÖ¯ÃûΪ¡°Careto¡±»ò¡° The Mask ¡±£¬ÓÚ 2007 Ä꿪ʼÔË×÷£¬È»ºóÔÚ 2013 ÄêËƺõÏûʧµÃÎÞÓ°ÎÞ×Ù¡£ÔÚ´ËÆڼ䣬Õâ¸ö½²Î÷°àÑÀÓïµÄÍþвÐÐΪÕßÔÚÃÀ¹ú¡¢Ó¢¹úµÈ 31 ¸ö¹ú¼Ò/µØÓòÔì³ÉÁËÔ¼ 380 Ãû²îÒìµÄÊܺ¦Õß¡£¿¨°Í˹»ùÑо¿ÈËÔ±ÔÚ 10 ÄêÇ°×·×Ù¹ý Careto£¬×î½üÒ²·¢ÏÖÁËËüµÄй¥»÷£¬ËûÃÇ·¢ÏÖCareto ֮ǰµÄÊܺ¦Õß°üÂÞÕþ¸®»ú¹¹¡¢Íâ½»»ú¹¹ºÍ´óʹ¹Ý¡¢ÄÜÔ´¡¢Ê¯ÓͺÍÌìÈ»Æø¹«Ë¾¡¢Ñо¿»ú¹¹ºÍ˽ļ¹ÉȨ¹«Ë¾¡£
https://www.darkreading.com/cyberattacks-data-breaches/-the-mask-espionage-group-resurfaces-after-10-year-hiatus?&web_view=true
5. FIN7ÀûÓöñÒâ Google ¹ã¸æÁ÷´« NetSupport RAT
5ÔÂ12ÈÕ£¬¾ÝÊӲ죬³öÓÚ¾¼Ã¶¯»úµÄÍþвÐÐΪÕßFIN7ÀûÓÃÆÛƺϷ¨Æ·ÅƵĶñÒâ Google ¹ã¸æ×÷ΪÌṩ MSIX °²×°·¨Ê½µÄÊֶΣ¬×îÖÕ²¿ÊðNetSupport RAT¡£ÍøÂçÄþ¾²¹«Ë¾ eSentireÔÚ±¾ÖÜÔçЩʱºòÐû²¼µÄÒ»·Ý³ÂËßÖÐÌåÏÖ£º¡°ÍþвÐÐΪÕßÀûÓöñÒâÍøվð³äÖªÃûÆ·ÅÆ£¬°üÂÞ AnyDesk¡¢WinSCP¡¢BlackRock¡¢Asana¡¢Concur¡¢»ª¶û½ÖÈÕ±¨¡¢Workable ºÍ Google Meet¡£¡±FIN7£¨ÓÖÃû Carbon Spider ºÍ Sangria Tempest£©ÊÇÒ»¸öÁ¬Ðø´æÔڵĵç×Ó·¸×ï×éÖ¯£¬×Ô 2013 ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬×î³õÉæ×ãÕë¶ÔÏúÊÛµã (PoS) É豸µÄ¹¥»÷ÒÔÇÔÈ¡Ö§¸¶Êý¾Ý£¬ºóÀ´×ªÏòͨ¹ýÀÕË÷Èí¼þ»î¶¯ÆÆ»µ´óÐ͹«Ë¾¡£¶àÄêÀ´£¬ÍþвÐÐΪÕ߸ïÐÂÁËÆä¼ÆıºÍ¶ñÒâÈí¼þ¿â£¬½ÓÄÉÁËÖÖÖÖ ×Ô½ç˵¶ñÒâÈí¼þϵÁУ¬ÀýÈç BIRDWATCH¡¢Carbanak¡¢DICELOADER£¨ÓÖÃû Lizar ºÍ Tirion£©¡¢POWERPLANT¡¢POWERTRASH ºÍ TERMITE µÈ¡£FIN7 ¶ñÒâÈí¼þͨ³£Í¨¹ýÓã²æʽÍøÂçµöÓã»î¶¯²¿Êð£¬×÷ΪĿ±êÍøÂç»òÖ÷»úµÄÈë¿Ú£¬¾¡¹Ü×î½ü¼¸¸öÔ¸Ã×éÖ¯ÒÑÀûÓöñÒâ¹ã¸æ¼¼ÊõÀ´Æô¶¯¹¥»÷Á´¡£
https://thehackernews.com/2024/05/fin7-hacker-group-leverages-malicious.html
6. ¼ÓÃÜÓʼþ·þÎñ Proton Ôٴν«ÏÓÒÉÈ˵ÄÐÅÏ¢½»¸ø¾¯·½
5ÔÂ13ÈÕ£¬¼ÓÃܵç×ÓÓʼþ·þÎñ Proton Mail ÔÚijЩ·½ÃæÔÙ´ÎÏÝÈëÀ§¾³£¬¶øÇÒ֮ǰҲÔøÔâÊܹýÅúÆÀ£º½«Óû§Êý¾ÝÒƽ»¸øÖ´·¨²¿ÃÅ¡£Proton Ìṩ¶àÏî×Ô³ÆÄþ¾²¿É¿¿µÄ·þÎñ£¬ÆäÖаüÂ޶˵½¶Ë¼ÓÃܵç×ÓÓʼþ²úÎï¡£ÍâòÉÏÊÇΪÁËÒþ˽Òâʶ¶øÉè¼ÆµÄ£¬Proton Éù³ÆÎÞ·¨ÔĶÁµç×ÓÓʼþºÍ¸½¼þµÄÄÚÈÝ£¬Ã»Óиú×ÙÆ÷ºÍ¹ã¸æ£¬¶øÇÒÓµÓС°×î¸ßµÄÒþ˽³ß¶È¡±¡£¾¡¹ÜÈç´Ë£¬Proton ÈÔÈ»¿ÉÒÔ·ÃÎʲ¢±»ÆÈй¶Óû§ÐÅÏ¢¡£2021 Ä꣬Õâ¼ÒÈðÊ¿¹©Ó¦ÉÌÏòÈðÊ¿¾¯·½ÌṩÁ˾¯·½ÊÔͼʶ´ËÍâÒ»ÃûÍøÃñµÄ IP µØÖ·ºÍÉ豸ÏêϸÐÅÏ¢¡£¸ÃÈËÊÇÒ»Ãû·¨¹úÆøºò»î¶¯¼Ò£¬ºóÀ´ÔÚ Proton Óë·¨¹ú¾¯·½·ÖÏíÏàͬÊý¾Ýºó±»²¶¡£Õⳡ»ìÂÒ·¢Éúºó²»¾Ã£¬Proton¾Íɾ³ýÁËÆäÍøÕ¾ÉÏδ¸ú×ÙÓû§ IP µØÖ·µÄÉùÃ÷¡£´ËÇ°»¹±»Ö¸¿ØÏòÕþ¸®ÌṩÓû§ÊµÊ±¼à¿Ø¡£
https://www.theregister.com/2024/05/13/infosec_in_brief/