¶¶È¦Îª¶Ä¶øÉú

EnglishÈÕ±¾ÕZ

¹¤Òµ»¥ÁªÍøÄþ¾²×¨Ìâ > Äþ¾²×ÊѶ

ÎÚ¿ËÀ¼¶Ïµçʼþ¡¢NotPetya·¢×÷¡¢Æ½²ý¶¬°Â»áÍøÂç°µÕ½µÄÄ»ºóÖ÷ʹÃûµ¥

×÷Õߣºkirazhou 2020-10-20

×òÌì £¬ÃÀ¹ú˾·¨²¿¶ÔÁùÃûGRU£¨¶íÂÞ˹¾üÊÂÇ鱨¾Ö£©74455²¿ÃŹÙÔ±ÌᳫÁËÆðËß £¬Ö¸¿ØËûÃÇÊǺڿÍ×éÖ¯SandwormµÄ³ÉÔ±¡£

1.png

ÒÔÏÂÊDZ»¸æÐÕÃû¼°Ïà¶Ô×ïÃû

2.png

ÃÀ¹ú¹ÙÔ±ÌåÏÖ £¬×÷Ϊ¡°¹ú¼ÒÔÞÖú¡±µÄºÚ¿Í×éÖ¯ £¬Õâ6Ãû³ÉÔ±ÔÚ¶íÂÞ˹Õþ¸®µÄÃüÁîϽøÐÐÁË¡°ÆÆ»µÐÔ¡±ÍøÂç¹¥»÷ £¬Ä¿µÄÊÇÆÆ»µÆäËû¹ú¼ÒµÄÎȶ¨ £¬¸ÉÔ¤Ëû¹úÕþÖβ¢Ôì³ÉÆÆ»µºÍÖ±½Ó½ðÇ®Ëðʧ¡£

Ïà¹Ø¹¥»÷³¤´ïÊ®Äê £¬°üÂÞÆù½ñΪֹÒÑÖªµÄһЩ´óÐÍÍøÂç¹¥»÷£º

ÎÚ¿ËÀ¼¶Ïµç£º´Ó2015Äê12Ôµ½2016Äê12Ô £¬Sandworm×é֯ʹÓÃÕë¶Ô¹¤ÒµÉ豸µÄ¶ñÒâÈí¼þ £¬¾«ÐijïıÁËÕë¶ÔÎÚ¿ËÀ¼µçÍø¡¢ÎÚ¿ËÀ¼²ÆÕþ²¿µÄÆÆ»µÐÔ¶ñÒâÈí¼þ¹¥»÷¡£ÆäÖÐ £¬2015ÄêºÍ2016Äê·Ö±ðÀûÓÃBlackEnergyºÍIndustroyer £¬´ËÍ⻹ʹÓÃÁËKillDisk £¬½ø¶øµ¼ÖÂÊýÊ®ÍòÓû§ÔÚÊ¥µ®½ÚÇ°Á½Ìì±»¶Ïµç¡£

·¨¹ú´óÑ¡£º2017Äê4ÔºÍ5Ô £¬SandwormÕë¶Ô·¨¹ú×ÜͳMacron¾«ÐijïıÁËÓã²æÔ˶¯ºÍÏà¹ØµÄhack and leakÐж¯¡£

NotPetyaÀÕË÷Èí¼þ·¢×÷£º2017Äê £¬NotPetyaÀÕË÷Èí¼þ¹¥»÷·¢×÷¡£¸ÃÀÕË÷Èí¼þ×î³õÊÇÕë¶ÔÎÚ¿ËÀ¼¹«Ë¾µÄ £¬ºóÀ´Ñ¸ËÙÁ÷´«²¢Ó°ÏìÁËÊÀ½ç¸÷µØµÄ¹«Ë¾ £¬ÆäʱÔì³ÉÁËÁè¼Ý10ÒÚÃÀÔªµÄËðʧ¡£Æ¾¾ÝÃÀ¹ú¼ì²ì¹ÙµÄ˵·¨ £¬NotPetya¹¥»÷µÄÄ»ºóºÚÊÖÕýÊÇSandworm¡£

Õë¶Ôƽ²ý¶¬°Â»áµÄÖ÷°ì·½¡¢¼ÓÈëÕߵȵĹ¥»÷£ºÔÚ2017Äê12ÔÂÖÁ2018Äê2ÔÂÖ®¼ä £¬Sandworm»¹ÌᳫÁËÕë¶Ôº«¹ú¹«Ãñ¡¢¹ÙÔ±¡¢°ÂÁÖÆ¥¿ËÔË·¢¶¯¡¢ºÏ×÷»ï°éºÍ·Ã¿ÍµÈµÄÓã²æ¹¥»÷Ðж¯ºÍ¶ñÒâÒƶ¯Ó¦Ó÷¨Ê½·Ö·¢¡£¶øÔ­ÒòºÜ¿ÉÄÜÊÇÊÀ½ç·´Ð˷ܼÁ×éÖ¯Ðû²¼¶íÂÞ˹ÔË·¢¶¯±»½ûÖ¹¼ÓÈëÌåÓý½ÇÖ𠣬ÎÞÔµ¶¬°Â»á¡£

Õë¶Ôƽ²ý¶¬°Â»áITϵͳµÄ¹¥»÷£¨OlympicDestroyer£©£º´Ó2017Äê12Ôµ½2018Äê2Ô £¬Sandworm¾«ÐijïıÁ˶Ô2018Äêƽ²ý¶¬°Â»áµÄ¼ÆËã»úϵͳµÄÈëÇÖ £¬¸ÃÐж¯ÔÚ2018Äê2ÔÂ9ÈÕµ½´ïÁËáÛ·å £¬²¢Ðû²¼ÁËÆÆ»µÐԵĶñÒâÈí¼þOlympicDestroyer¡£µ±Ìì £¬»¥ÁªÍø¡¢¹ã²¥ÏµÍ³ºÍ°ÂÔË»áÍøÕ¾¶¼·ºÆðÁËÎÊÌâ¡£Ðí¶à¹ÛÖÚÎÞ·¨´òÓ¡ËûÃǵÄÈ볡ȯ £¬µ¼ÖÂ×ùλ¿ÕÖá£

´ËÍâ £¬»¹ÓÐNovichokÉñ¾­¶¾¼Á¹¥»÷ʼþ¡¢¸ñ³¼ªÑÇÒé»áÍøÂç¹¥»÷ʼþµÄÄ»ºóÖ÷ʹ¶¼±»ÃÀ¹úÖ¸Ïò¶íÂÞ˹¡£

Èç¹ûÕâЩ³ÉÔ±±»Òý¶Éµ½ÃÀ¹ú £¬ËûÃǽ«ÃæÁÙÊýÊ®ÄêµÄ¼à½ûʱ¼ä¡£µ«Æ¾¾ÝÁª°îÊÓ²ìÈËÔ±µÄ˵·¨ £¬ËùÓÐÁùÃûÏÓÒÉÈ˶¼ÊǶíÂÞ˹¾ÓÃñ¡£Òò´Ë £¬ÔÚ²»Ì«¿ÉÄܽøÐдþ²¶»òÒý¶ÉµÄÇé¿öÏ £¬ÆðËßÊé¸ü¶àµØÊÇÏò¸Ã¹úÕþ¸®ÔÞÖúµÄºÚ¿Í·¢³ö¾¯¸æ £¬¼û¸æÆäÉí·Ý²»»áÓÀÔ¶±»Òþ²Ø¡£

ÁíÍâ £¬ÔÚͨ¸æÖÐûÓÐÃ÷ȷ˵Ã÷ÃÀ¹úÈçºÎʶ±ðÏÓÒÉ·¸¡£µ«ÊÇFBIÓë°üÂÞÓ¢¹úÇ鱨·þÎñ²¿ÃÅÔÚÄڵĹúÍâÖ´·¨»ú¹¹ºÏ×÷ £¬²¢ÓëCiscoºÍGoogleµÄÄþ¾²Ñо¿ÈËÔ±ºÏ×÷ £¬ÒÔ·¢ÏÖ¸Ã×éÖ¯µÄ»î¶¯¡£

×îºó £¬½áºÏ¶«¾©°ÂÔË»áµÄ³ï±¸£¨ÒÑÍƳٵ½Ã÷Ä꣩ £¬Ó¢¹ú·½ÃæÌåÏÖ £¬¶íÂÞ˹ÕýÔÚ×¼±¸Õë¶Ô¶«¾©°ÂÔË»áµÄÍøÂç¹¥»÷ £¬ÕâÒ»¿¼ÂDz¢²»ÊÇûÓÐÔ­Àí £¬Ô¤¼Æ¹¥»÷ÈÔÈ»ÊÇÕë¶Ô¾Ù°ì·½¡¢¼ÓÈëÕßÒÔ¼°¼ÆËãϵͳÉèÊ©µÄ £¬¶ÔÓÚSandwormµÄ¾¯ÌèºÍ·À·¶ÐèÒª¼ÓÇ¿¡£

²Î¿¼À´Ô´£º

zdnet


£¨×ªÔØÀ´×Ô£ºFreeBuf.com£©

ÉÏһƪ ÏÂһƪ

7*24Сʱ·þÎñÈÈÏß

400-624-3900


ÍøÕ¾µØͼ