ArmisÅû¶PTSϵͳÖеÄͳ³ÆΪPwnedPiperµÄ©¶´£»CyCraftÐû²¼Õë¶ÔÀÕË÷Èí¼þPrometheusµÄÃâ·Ñ½âÃÜÆ÷
Ðû²¼Ê±¼ä 2021-08-03Äþ¾²¹«Ë¾ArmisÅû¶SwissLogµÄTransLogic PTS£¨Æø¶¯¹Üϵͳ) ÖÐͳ³ÆΪPwnedPiperµÄ9¸ö©¶´£¬Ó°ÏìÈ«ÃÀ80%µÄÒ½Ôº¡£TransLogic PTSÓÃÓÚÔÚ´óÖÐÐÍÒ½ÔºÖг¤¾àÀëÔËËÍÒ½ÁÆÎïÆ·£¬ÒÑÔÚ±±ÃÀ2300¶à¼ÒҽԺʹÓá£ÕâЩ©¶´ÖÐ×îÑÏÖصÄÊÇδ¾Éí·ÝÑéÖ¤¡¢Î´¼ÓÃÜ¡¢Î´Ç©ÃûµÄ¹Ì¼þÉý¼¶Â©¶´£¨CVE-2021-37160£©£¬¿ÉÓÃÀ´ÔÚϵͳÉÏ°²×°¶ñÒâ¹Ì¼þÀ´ÍêÈ«¿ØÖÆÄ¿±êϵͳ¡£´ËÍ⣬»¹ÓÐÌáȨ©¶´£¨CVE-2021-37167£©¡¢DoS©¶´£¨CVE-2021-37166£©ºÍtcpTxThreadÖеÄÈý±¶¶ÑÕ»Òç³ö£¨CVE-2021-37164£©µÈ©¶´¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/08/pwnedpiper-pts-security-flaws-threaten.html
2.KasperskyÅû¶ÐµÄGhostEmperorÍÅ»ïÕë¶Ô¶«ÄÏÑÇ
KasperskyÅû¶ÁËÒ»¸öеĺڿÍÍÅ»ïGhostEmperor£¬Ö÷ÒªÕë¶Ô¶«ÄÏÑǵØÓòµÄÄ¿±ê£¬°üÂÞÕþ¸®»ú¹¹ºÍ¼¸¼ÒµçÐŹ«Ë¾¡£¸ÃÍÅ»ïµÄÈëÇֻÒÀÀµÓÚCheat Engine¿ªÔ´ÏîÄ¿µÄÒ»¸ö×é¼þ£¬ËüÄܹ»ÈƹýWindowsÇý¶¯·¨Ê½Ç¿ÖÆÇ©Ãû»úÖÆ¡£¸ÃÍÅ»ïÖ®ËùÒÔÓëÖÚ²îÒ죬ÊÇÒòΪËüʹÓÃÁËÒ»¸öÒÔÇ°²»ÎªÈËÖªµÄWindowsÄÚºËģʽµÄrootkit£¬¶øÇÒ½ÓÄÉÁËÅÓ´óµÄ¶à½×¶Î¶ñÒâÈí¼þ¿ò¼Ü£¬Ö¼ÔÚ¶ÔÄ¿±ê·þÎñÆ÷½øÐÐÔ¶³Ì¿ØÖÆ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120721/apt/ghostemperor-chinese-speaking-threat-actor.html
3.CiscoÅû¶¶ñÒâÈí¼þSolarmarkerÐÂÒ»ÂֵĹ¥»÷»î¶¯
Cisco TalosÅû¶Á˶ñÒâÈí¼þSolarmarkerÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£ÔÚ2021Äê5Ôµ׺Í6Ô³õ×óÓÒ£¬Talos¼ì²âµ½ÐÂÒ»ÂÖSolarmarker¹¥»÷»î¶¯¼¤Ôö¡£ÔÚ×î½üµÄÕâЩµü´úÖУ¬¹¥»÷Õßµ÷ÕûÁ˳õʼdropperµÄÏÂÔØÒªÁ죬²¢¶Ôstaging×é¼þ£¨ÏÖÔÚ³ÆΪMars£©½øÐÐÁËÉý¼¶¡£ÒÔÇ°Solarmarker½«´Ó´øÓÐͨÓñêÌâÃû³ÆPdfDocDownloadsPanelµÄÒ³ÃæÏÂÔØ£¬¶ø´Ë´Î»î¶¯ÖеÄÏÂÔØÒ³ÃæÏÖαÔì³ÉÀ´×ԹȸèDriveµÄÏÂÔØÎļþÇëÇ󣬿´ÆðÀ´Ô½·¢ºÏ·¨¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/07/threat-spotlight-solarmarker.html
4.CyCraftÐû²¼Õë¶ÔÀÕË÷Èí¼þPrometheusµÄÃâ·Ñ½âÃÜÆ÷
Äþ¾²¹«Ë¾CyCraftÐû²¼Ãâ·Ñ½âÃÜÆ÷£¬×ÊÖúÀÕË÷Èí¼þPrometheusµÄÊܺ¦Õ߻ָ´ºÍ½âÃÜÎļþ¡£CyCraftÌåÏÖ£¬PrometheusʹÓÃÁËSalsa20ºÍ»ùÓÚtickcountµÄËæ»úÃÜÂëÀ´¼ÓÃÜÎļþ¡£Ëæ»úÃÜÂëµÄ¾ÞϸΪ32×Ö½Ú£¬Ã¿¸ö×Ö·û¶¼Êǿɼû×Ö·û£¬¶øÇÒÒòΪÃÜÂëÒÔtickcount×÷ΪÃÜÔ¿£¬ËùÒÔ¿ÉÒÔʹÓñ©Á¦Æƽ⡣Emsisoft¹«Ë¾ÌåÏָýâÃÜÆ÷ΨһµÄȱµãÊÇÖ»ÄÜÆƽâСÎļþµÄ½âÃÜÃÜÔ¿¡£´ËÍ⣬½âÃÜÆ÷Ðû²¼²»¾Ãºó£¬PrometheusÍÅ»ïËƺõÒѾֹͣÁËÐж¯¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/decryptor-released-for-prometheus-ransomware-victims/
5.SonicWallÐû²¼2021ÄêÉÏ°ëÄêÍøÂç̬ÊƵķÖÎö³ÂËß
SonicWallÐû²¼ÁË2021ÄêÉÏ°ëÄêÍøÂç̬ÊƵķÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬ÀÕË÷Èí¼þ¹¥»÷ÔÚ2021ÄêÉÏ°ëÄêÊ®·Ö·ÅËÁ£¬¸Ã¹«Ë¾¼ì²âµ½µÄ¹¥»÷ʵÑéµ½´ï3.047ÒڴΣ¬ Áè¼ÝÁË2020È«ÄêµÄ¹¥»÷×ÜÊý¡£ÃÀ¹ú¡¢Ó¢¹ú¡¢µÂ¹ú¡¢ÄϷǺͰÍÎ÷µÈ¹ú¼ÒÊÇÊÜÀÕË÷Èí¼þ¹¥»÷×îÑÏÖصĹú¼Ò£¬ÆäÖÐÃÀ¹úÊÜÓ°Ïì½Ï´óµÄµØÓòÊÇ·ðÂÞÀï´ïÖÝ£¬ÓÐ1.111Òڴι¥»÷ʵÑé¡£´ËÍ⣬ÀÕË÷¹¥»÷×î³£¼ûµÄÄ¿±êÊǽðÈÚ»ú¹¹ÒÔ¼°¹ú·ÀµÈÖØÒªµÄÕþ¸®×éÖ¯£¬¶øÕë¶Ô½ÌÓýÐÐÒµµÄ¹¥»÷Ôò¼¤ÔöÁË615%¡£
ÔÎÄÁ´½Ó£º
https://www.sonicwall.com/2021-cyber-threat-report/
6.DeepinstinctÐû²¼2021ÄêÖÐÍøÂçÍþв̬ÊÆ·ÖÎö³ÂËß
Deep InstinctÐû²¼ÁË2021ÄêÖÐÍøÂçÍþв̬ÊÆ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬ÀÕË÷Èí¼þÒ»Ö±ÊÇÕû¸ö2021ÄêµÄÖ÷µ¼Ç÷ÊÆ£¬ÆäÖÐÖ÷ÒªÍþвΪSTOP(Djvu)¡¢RyukºÍSodinokibi(REvil)µÈ¡£ÒøÐÐľÂí»î¶¯µÄÖ÷ÒªÍþвΪEmotetµÄ¼ÌÈÎÕߣ¬ÀýÈçRamnit¡¢QbotºÍIcedID¡£´ËÍ⣬Õë¶ÔColonial PipelineµÄ¹¥»÷³ÉΪȫÇòµÄ½¹µã£¬µ«ÕâÖ»Êǹ¥»÷Òªº¦»ù´¡ÉèÊ©µÄÖڶ๥»÷ʵÑéÖ®Ò»£¬¶øÇÒÔ¤¼ÆÕâÖÖ¹¥»÷¼Æı½üÆÚÄÚ²»»á·¢Éú¸Ä±ä¡£
ÔÎÄÁ´½Ó£º
https://www.deepinstinct.com/2021/07/22/2021-mid-year-cyber-threat-landscape-report/