APT28 Õë¶ÔÅ·ÖÞ¡¢ÃÀÖÞºÍÑÇÖÞÖ´ÐÐÍøÂçµöÓã¼Æ»®

Ðû²¼Ê±¼ä 2024-03-19
1. APT28 Õë¶ÔÅ·ÖÞ¡¢ÃÀÖÞºÍÑÇÖÞÖ´ÐÐÍøÂçµöÓã¼Æ»®


3ÔÂ18ÈÕ  £¬Óë¶íÂÞ˹ÓйصÄÍþвÐÐΪÕßAPT28Óë¶à¸öÕýÔÚ½øÐеÄÍøÂçµöÓã»î¶¯ÓÐ¹Ø  £¬ÕâЩ»î¶¯Ê¹ÓÃÄ£·ÂÅ·ÖÞ¡¢Äϸ߼ÓË÷¡¢ÖÐÑÇÒÔ¼°±±ÃÀºÍÄÏÃÀÕþ¸®ºÍ·ÇÕþ¸®×éÖ¯ (NGO) µÄÓÕ¶üÎļþ¡£IBM X ÌåÏÖ£º¡°Î´·¢ÏÖµÄÓÕ¶ü°üÂÞÄÚ²¿ºÍ¹ûÈ»ÎļþµÄ»ìºÏÌå  £¬ÒÔ¼°¿ÉÄÜÓɼÓÈëÕßÉú³ÉµÄÓë½ðÈÚ¡¢Òªº¦»ù´¡ÉèÊ©¡¢¸ß¹Ü¼ÓÈë¡¢ÍøÂçÄþ¾²¡¢º£ÊÂÄþ¾²¡¢Ò½ÁƱ£½¡¡¢ÉÌÒµºÍ¹ú·À¹¤ÒµÉú²úÏà¹ØµÄÎļþ¡£¡± ¸Ã¿Æ¼¼¹«Ë¾ÕýÔÚ×·×ÙÃûΪITG05µÄ»î¶¯  £¬¸ÃÃû³ÆÒ²³ÆÎª Blue Athena¡¢BlueDelta¡¢Fancy Bear¡¢Fighting Ursa¡¢Forest Blizzard£¨ÒÔǰ³ÆÎª Strontium£©¡¢FROZENLAKE¡¢Iron Twilight¡¢Pawn Storm¡¢Sednit¡¢Sofacy¡¢TA422 ºÍUAC-028¡£ÕâÒ»Åû¶ÊÇÔÚ¶ÔÊÖ±»·¢ÏÖʹÓÃÓëÕýÔÚ½øÐеÄÒÔÉ«ÁÐ-¹þÂí˹սÕùÏà¹ØµÄÓÕ¶üÀ´ÌṩÃûΪHeadLaceµÄ¶¨ÖƺóÃÅÈý¸ö¶àÔºóÐû²¼µÄ¡£½ñºó  £¬APT28 »¹ÏòÎÚ¿ËÀ¼Õþ¸®ÊµÌåºÍ²¨À¼×éÖ¯·¢ËÍÍøÂçµöÓãÏûÏ¢  £¬ÕâЩÏûÏ¢Ö¼ÔÚ²¿Êð¶¨ÖÆÖ²È뷨ʽºÍÐÅÏ¢ÇÔÈ¡·¨Ê½  £¬ÀýÈçMASEPIE¡¢OCEANMAP ºÍ STEELHOOK¡£


https://thehackernews.com/2024/03/apt28-hacker-group-targeting-europe.html


2. ÈÕ±¾¸»Ê¿Í¨Í¸Â¶Æä¹«Ë¾ÄÚÍøÑ¬È¾¶ñÒâÈí¼þµ¼ÖÂÊý¾Ýй¶


3ÔÂ17ÈÕ  £¬¸»Ê¿Í¨±¨µÀËûÃÇÔÚÄÚ²¿ÊÓ²ìÆÚ¼ä¼ì²âµ½Á˸öñÒâÈí¼þ¡£·¢ÏÖºó  £¬ËûÃÇÁ¢¼´¸ôÀëÊÜѬȾµÄÉ豸  £¬²¢¼ÓÇ¿Õû¸öϵͳµÄÄþ¾²¼à¿Ø¡£Ä¿Ç°ÕýÔÚ½øÐÐÉîÈëÊÓ²ì  £¬ÒÔÈ·¶¨¶ñÒâÈí¼þµÄÈë¿ÚµãºÍDZÔÚÊý¾Ýй¶µÄÈ«²¿·¶Î§¡£¸Ã¹«Ë¾ÒÑÖ÷¶¯Í¨ÖªÊý¾Ý¿ÉÄܱ»·ÃÎʵĸöÈ˺Ϳͻ§¡£ËûÃÇ»¹Ïò¸öÈËÐÅÏ¢±£»¤Î¯Ô±»áÌá½»ÁËÓйØÇ±ÔÚÊý¾Ýй¶µÄ³ÂËß¡£ÐÒÔ˵ÄÊÇ  £¬¸»Ê¿Í¨ÌåÏÖ  £¬ËûÃÇÉÐδÊӲ쵽ÈκÎÊÜËðÊý¾Ý±»ÓÃÓÚ¶ñÒâÄ¿µÄµÄÇé¿ö¡£¶ÔÓÚ´Ë´ÎʼþÔì³ÉµÄδ±ãºÍµ£ÓÇ  £¬¸»Ê¿Í¨ÏòËùÓÐÊÜÓ°ÏìµÄ¸÷·½ÌåÏÖ³ÏÖ¿µÄǸÒâ¡£


https://securityonline.info/fujitsu-discloses-data-breach-customer-and-personal-information-compromised/


3. ÐÂÐÍÒþÐμÓÔØ·¨Ê½×ÊÖú SPARKRAT ¶ñÒâÈí¼þÌӱܼì²â


3ÔÂ17ÈÕ  £¬Kroll µÄÍøÂçÄþ¾²Ñо¿ÈËÔ±Ðû²¼ÁËÎÛÃûÕÑÖøµÄ SPARKRAT¶ñÒâÈí¼þ¹¤¾ß°üµÄÒ»ÏîÁîÈ˵£ÓǵĽøÕ¹¡£Ò»ÖÖÓà Golang ±àдµÄǰËùδ¼ûµÄмÓÔØ·¨Ê½ÕýÔÚ±»»ý¼«Ê¹Óà  £¬ÒÔ½« SPARKRAT DZÈëÄ¿±êϵͳ  £¬´Ó¶øÊ¹¶ñÒâÈí¼þÄܹ»ÔÚ´«Í³Äþ¾²¹¤¾ßµÄÀ×´ïÏÂÔËÐС£SPARKRAT ÓÉ GitHub ¿ª·¢ÈËÔ± XZB-1248 ÏòÊÀ½çÍÆ³ö  £¬×÷Ϊһ¿î¹¦Ð§¸»ºñµÄ¿ªÔ´Ô¶³Ì¹ÜÀí¹¤¾ß¡£SPARKRAT ÊÇΪ¶à¸öƽ̨±àÒëµÄ  £¬×î³õµÄÄ¿µÄÊÇ×÷ΪһÖÖÁ¼ÐÔ¹¤¾ß¡£È»¶ø  £¬¸ÃÏîÄ¿ÓÚ 2023 Äê 2 Ô±»·ÅÆú  £¬µ«ÔÚ´Ë֮ǰËüÒýÆðÁËÍøÂç·¸×ï·Ö×ÓµÄ×¢Òâ¡£SPARKRAT µÄÐ޸İ汾¿ªÊ¼·ºÆðÔÚÖÖÖÖÈëÇÖÊÓ²ìÖÐ  £¬ÌرðÊÇÔÚÕë¶Ô¶«ÑǸ÷µØ×éÖ¯µÄ¡°DRAGONSPARK¡±»î¶¯ÖС£¸Ã¶ñÒâÈí¼þÔÚÔËÐÐʱ½âÊÍÆäǶÈëʽ Golang Ô´´úÂëµÄÄÜÁ¦Ê¹Æä·ÖÎö±äµÃÅÓ´ó²¢Ìӱܾ²Ì¬¼ì²â  £¬Õâ¶ÔÍøÂçÄþ¾²·ÀÓù×é³ÉÁËÖØ´óÌôÕ½¡£


https://securityonline.info/stealthy-new-loader-helps-sparkrat-malware-evade-detection/


4. ÍþвÐÐΪÕßй¶7ǧÍò¶àÌõ¾Ý³Æ´Ó AT&T ÇÔÈ¡µÄ¼Ç¼


3ÔÂ17ÈÕ  £¬vx-underground µÄÑо¿ÈËÔ±Ê×ÏÈ×¢Òâµ½  £¬À´×Ô AT&T µÄÁè¼Ý 70,000,000 Ìõ¼Ç¼ÔÚ Breached ºÚ¿ÍÂÛ̳Éϱ»Ð¹Â¶¡£Ñо¿ÈËԱ֤ʵй¶µÄÊý¾ÝÊÇÕæÊµµÄ  £¬µ«Ä¿Ç°Éв»Çå³þÕâЩÐÅÏ¢ÊÇ·ñÊÇ´ÓÓë AT&T Ïà¹ØµÄµÚÈý·½×éÖ¯ÇÔÈ¡µÄ¡£Âô¼ÒÒÔ MajorNelson µÄÃûÒåÔÚÍøÉÏÉù³Æ  £¬ÕâЩÊý¾ÝÊÇ @ShinyHuntersÓÚ 2021 Äê´ÓÒ»¸öδ͸¶ÐÕÃûµÄ AT&T ²¿ÃÅ»ñµÃµÄ¡£¸Ãµµ°¸°üÂÞ 73.481.539 Ìõ¼Ç¼¡£2021 Äê 8 Ô  £¬ShinyHunters ×éÖ¯Éù³ÆÓµÓÐÒ»¸öÊý¾Ý¿â  £¬ÆäÖаüÂÞԼĪ 7000 Íò AT&T ¿Í»§µÄ˽ÈËÐÅÏ¢  £¬µ«¸Ã¹«Ë¾·ñÈÏÕâЩÐÅÏ¢ÒÑ´ÓÆäϵͳÖб»µÁ¡£ShinyHunters ÊÇÒ»¸öÊÜ»¶Ó­µÄºÚ¿Í×éÖ¯  £¬ÖÚËùÖÜÖª  £¬ËûÃdzöÊÛ´Ó Tokopedia¡¢  Homechef¡¢  Chatbooks.com¡¢  MicrosoftºÍ MintedµÈÊýÊ®¸öÖ÷Òª×éÖ¯ÇÔÈ¡µÄÊý¾Ý¡£


https://securityaffairs.com/160627/data-breach/70m-att-records-leaked.html


5. GITGUB¶ñÒâÈí¼þ»î¶¯ÀûÓà RISEPRO Õë¶Ô GITHUB Óû§


3ÔÂ17ÈÕ  £¬G-Data Ñо¿ÈËÔ±·¢ÏÖÖÁÉÙ 13 ¸ö´ËÀà Github ´æ´¢¿âÍйÜ×ÅÖ¼ÔÚÌṩ RisePro ÐÅÏ¢ÇÔÈ¡·¨Ê½µÄÆÆ½âÈí¼þ¡£×¨¼Ò×¢Òâµ½  £¬¸Ã»î¶¯±»ÆäÔËÓªÕßÃüÃûΪ¡°gitgub¡±¡£Ñо¿ÈËԱƾ¾Ý Arstechnica¹ØÓÚ¶ñÒâ Github ´æ´¢¿âµÄ¹ÊÊ¿ªÊ¼ÁËÊÓ²ì ¡£×¨¼ÒÃÇ´´½¨ÁËÒ»¸öÍþв׷×Ù¹¤¾ß  £¬Ê¹ËûÃÇÄܹ»Ê¶±ð¼ÓÈë´Ë»î¶¯µÄ´æ´¢¿â¡£Ñо¿ÈËÔ±×¢Òâµ½  £¬ËùÓд洢¿â¶¼ÊÇд´½¨µÄ´æ´¢¿â  £¬µ¼ÖÂÏàͬµÄÏÂÔØÁ´½Ó¡£ÕâЩ´æ´¢¿â¿´ÆðÀ´ºÜÏàËÆ  £¬¶¼ÓÐÒ»¸ö README.md Îļþ  £¬²¢ÔÊÐíÌṩÃâ·ÑÆÆ½âÈí¼þ¡£Github Éϳ£ÓÃÂÌÉ«ºÍºìɫԲȦÀ´ÏÔʾ×Ô¶¯¹¹½¨µÄ״̬¡£Ñо¿ÈËÔ±×¢Òâµ½  £¬Óû§±ØÐëʹÓà README.md ÎļþÖÐÌṩµÄÃÜÂë¡°GIT1HUB1FREE¡±½âѹ¶à²ãµµ°¸  £¬²ÅÆø·ÃÎÊÃûΪ¡°Installer_Mega_v0.7.4t.msi¡±µÄ°²×°·¨Ê½¡£ 


https://securityaffairs.com/160596/hacking/risepro-info-stealer-targets-github-users.html


6. ÄÏ·ÇÕþ¸®ÕýÔÚÊÓ²ìÑøÀϽð»ú¹¹Êý¾Ýй¶Ê¼þ


3ÔÂ18ÈÕ  £¬ÄÏ·ÇÕþ¸®¹ÙÔ±ÕýÔÚÊÓ²ìÓйØÀÕË÷Èí¼þÍÅ»ïÇÔÈ¡²¢ÔÚÍøÉÏй¶ 668GB Ãô¸Ð¹úÃñÑøÀϽðÊý¾ÝµÄ±¨µÀ¡£3ÔÂ11ÈÕÉæÏÓй¶Õþ¸®ÑøÀϽð¹ÜÀí¾Ö£¨GPAA£©Êý¾ÝµÄʼþÉÐδµÃµ½¹ûȻ֤ʵ  £¬µ«¸ÃʼþÒѳÉΪÄÏ·ÇÈ«¹úÐÂÎÅ¡£ÄÏ·ÇÕþ¸®¹ÍÔ±ÑøÀÏ»ù½ð (GEPF) ½éÈëÊÓ²ìÎÛÃûÕÑÖøµÄ LockBit ÍøÂç·¸×ïÍÅ»ïµÄÖ¸¿Ø¡£GEPFÊÇÄϷǶ¥¼¶ÑøÀÏ»ù½ð  £¬Æä¿Í»§°üÂÞ120ÍòÃûÏÖÈÎÕþ¸®¹ÍÔ±ÒÔ¼°47.3ÍòÃûÑøÀϽðÁìÈ¡ÕßºÍÆäËûÊÜÒæÈË¡£¸ÃÑøÀÏ»ù½ðÔÚÒ»·Ý¹ûÈ»ÉùÃ÷ÖÐÌåÏÖ£º¡°GEPF ÕýÔÚÓë GPAA ¼°Æä¼à¶½»ú¹¹¡¢¹ú¼Ò²ÆÕþ²¿ºÏ×÷  £¬ÒÔÈ·¶¨Ëù³ÂËßµÄÊý¾Ýй¶Ê¼þµÄ׼ȷÐÔºÍÓ°Ïì  £¬²¢½«ÔÚÊʵ±µÄʱºòÌṩ½øÒ»²½µÄ¸üС£¡±


https://www.darkreading.com/cyberattacks-data-breaches/south-african-government-pension-data-leak-fears-spark-probe