APT28 Õë¶ÔÅ·ÖÞ¡¢ÃÀÖÞºÍÑÇÖÞÖ´ÐÐÍøÂç´¹ÂÚÍýÏë

Ðû²¼Ê±¼ä 2024-03-19
1. APT28 Õë¶ÔÅ·ÖÞ¡¢ÃÀÖÞºÍÑÇÖÞÖ´ÐÐÍøÂç´¹ÂÚÍýÏë


3ÔÂ18ÈÕ £¬£¬£¬£¬£¬Óë¶íÂÞ˹ÓйصÄÍþвÐÐΪÕßAPT28Óë¶à¸öÕýÔÚ¾ÙÐеÄÍøÂç´¹ÂڻÓÐ¹Ø £¬£¬£¬£¬£¬ÕâЩ»î¶¯Ê¹ÓÃÄ£ÄâÅ·ÖÞ¡¢Äϸ߼ÓË÷¡¢ÖÐÑÇÒÔ¼°±±ÃÀºÍÄÏÃÀÕþ¸®ºÍ·ÇÕþ¸®×éÖ¯ (NGO) µÄÓÕ¶üÎļþ¡£¡£¡£¡£¡£ ¡£¡£IBM X ÌåÏÖ£º¡°Î´·¢Ã÷µÄÓÕ¶ü°üÀ¨ÄÚ²¿ºÍ¹ûÕæÎļþµÄ»ìÏýÌå £¬£¬£¬£¬£¬ÒÔ¼°¿ÉÄÜÓɼÓÈëÕßÌìÉúµÄÓë½ðÈÚ¡¢Òªº¦»ù´¡ÉèÊ©¡¢¸ß¹Ü¼ÓÈë¡¢ÍøÂçÇå¾²¡¢º£ÊÂÇå¾²¡¢Ò½ÁƱ£½¡¡¢ÉÌÒµºÍ¹ú·À¹¤ÒµÉú²úÏà¹ØµÄÎļþ¡£¡£¡£¡£¡£ ¡£¡£¡± ¸Ã¿Æ¼¼¹«Ë¾ÕýÔÚ×·×ÙÃûΪITG05µÄ»î¶¯ £¬£¬£¬£¬£¬¸ÃÃû³ÆÒ²³ÆÎª Blue Athena¡¢BlueDelta¡¢Fancy Bear¡¢Fighting Ursa¡¢Forest Blizzard£¨ÒÔǰ³ÆÎª Strontium£©¡¢FROZENLAKE¡¢Iron Twilight¡¢Pawn Storm¡¢Sednit¡¢Sofacy¡¢TA422 ºÍUAC-028¡£¡£¡£¡£¡£ ¡£¡£ÕâÒ»Åû¶ÊÇÔÚµÐÊÖ±»·¢Ã÷ʹÓÃÓëÕýÔÚ¾ÙÐеÄÒÔÉ«ÁÐ-¹þÂí˹սÕùÏà¹ØµÄÓÕ¶üÀ´ÌṩÃûΪHeadLaceµÄ¶¨ÖƺóÃÅÈý¸ö¶àÔºóÐû²¼µÄ¡£¡£¡£¡£¡£ ¡£¡£ÒÔºó £¬£¬£¬£¬£¬APT28 »¹ÏòÎÚ¿ËÀ¼Õþ¸®ÊµÌåºÍ²¨À¼×éÖ¯·¢ËÍÍøÂç´¹ÂÚÐÂÎÅ £¬£¬£¬£¬£¬ÕâЩÐÂÎÅÖ¼ÔÚ°²ÅŶ¨ÖÆÖ²Èë³ÌÐòºÍÐÅÏ¢ÇÔÈ¡³ÌÐò £¬£¬£¬£¬£¬ÀýÈçMASEPIE¡¢OCEANMAP ºÍ STEELHOOK¡£¡£¡£¡£¡£ ¡£¡£


https://thehackernews.com/2024/03/apt28-hacker-group-targeting-europe.html


2. ÈÕ±¾¸»Ê¿Í¨Í¸Â¶Æä¹«Ë¾ÄÚÍøÑ¬È¾¶ñÒâÈí¼þµ¼ÖÂÊý¾Ýй¶


3ÔÂ17ÈÕ £¬£¬£¬£¬£¬¸»Ê¿×ª´ïµÀËûÃÇÔÚÄÚ²¿ÊÓ²ìʱ´ú¼ì²âµ½Á˸öñÒâÈí¼þ¡£¡£¡£¡£¡£ ¡£¡£·¢Ã÷ºó £¬£¬£¬£¬£¬ËûÃÇÁ¬Ã¦¸ôÀëÊÜѬȾµÄ×°±¸ £¬£¬£¬£¬£¬²¢ÔöÇ¿Õû¸öϵͳµÄÇå¾²¼à¿Ø¡£¡£¡£¡£¡£ ¡£¡£ÏÖÔÚÕýÔÚ¾ÙÐÐÉîÈëÊÓ²ì £¬£¬£¬£¬£¬ÒÔÈ·¶¨¶ñÒâÈí¼þµÄÈë¿ÚµãºÍDZÔÚÊý¾Ýй¶µÄËùÓйæÄ£¡£¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾ÒÑ×Ô¶¯Í¨ÖªÊý¾Ý¿ÉÄܱ»»á¼ûµÄСÎÒ˽¼ÒºÍ¿Í»§¡£¡£¡£¡£¡£ ¡£¡£ËûÃÇ»¹ÏòСÎÒ˽¼ÒÐÅÏ¢±£»£»£»£»£»£»£»¤Î¯Ô±»áÌá½»ÁËÓйØÇ±ÔÚÊý¾Ýй¶µÄ±¨¸æ¡£¡£¡£¡£¡£ ¡£¡£ÐÒÔ˵ÄÊÇ £¬£¬£¬£¬£¬¸»Ê¿Í¨ÌåÏÖ £¬£¬£¬£¬£¬ËûÃÇÉÐδÊӲ쵽ÈκÎÊÜËðÊý¾Ý±»ÓÃÓÚ¶ñÒâÄ¿µÄµÄÇéÐΡ£¡£¡£¡£¡£ ¡£¡£¹ØÓÚ´Ë´ÎÊÂÎñÔì³ÉµÄδ±ãºÍµ£ÐÄ £¬£¬£¬£¬£¬¸»Ê¿Í¨ÏòËùÓÐÊÜÓ°ÏìµÄ¸÷·½ÌåÏÖÕæÖ¿µÄǸÒâ¡£¡£¡£¡£¡£ ¡£¡£


https://securityonline.info/fujitsu-discloses-data-breach-customer-and-personal-information-compromised/


3. ÐÂÐÍÒþÐμÓÔØ³ÌÐò×ÊÖú SPARKRAT ¶ñÒâÈí¼þÌӱܼì²â


3ÔÂ17ÈÕ £¬£¬£¬£¬£¬Kroll µÄÍøÂçÇå¾²Ñо¿Ö°Ô±Ðû²¼ÁËÎÛÃûÕÑÖøµÄ SPARKRAT¶ñÒâÈí¼þ¹¤¾ß°üµÄÒ»ÏîÁîÈ˵£ÐĵÄÏ£Íû¡£¡£¡£¡£¡£ ¡£¡£Ò»ÖÖÓà Golang ±àдµÄǰËùδ¼ûµÄмÓÔØ³ÌÐòÕýÔÚ±»Æð¾¢Ê¹Óà £¬£¬£¬£¬£¬ÒÔ½« SPARKRAT DZÈëÄ¿µÄϵͳ £¬£¬£¬£¬£¬´Ó¶øÊ¹¶ñÒâÈí¼þÄܹ»ÔڹŰåÇå¾²¹¤¾ßµÄÀ×´ïÏÂÔËÐС£¡£¡£¡£¡£ ¡£¡£SPARKRAT ÓÉ GitHub ¿ª·¢Ö°Ô± XZB-1248 ÏòÌìÏÂÍÆ³ö £¬£¬£¬£¬£¬×÷Ϊһ¿î¹¦Ð§¸»ºñµÄ¿ªÔ´Ô¶³ÌÖÎÀí¹¤¾ß¡£¡£¡£¡£¡£ ¡£¡£SPARKRAT ÊÇΪ¶à¸öƽ̨±àÒëµÄ £¬£¬£¬£¬£¬×î³õµÄÄ¿µÄÊÇ×÷ΪһÖÖÁ¼ÐÔ¹¤¾ß¡£¡£¡£¡£¡£ ¡£¡£È»¶ø £¬£¬£¬£¬£¬¸ÃÏîÄ¿ÓÚ 2023 Äê 2 Ô±»·ÅÆú £¬£¬£¬£¬£¬µ«ÔÚ´Ë֮ǰËüÒýÆðÁËÍøÂç·¸·¨·Ö×ÓµÄ×¢ÖØ¡£¡£¡£¡£¡£ ¡£¡£SPARKRAT µÄÐ޸İ汾×îÏÈ·ºÆðÔÚÖÖÖÖÈëÇÖÊÓ²ìÖÐ £¬£¬£¬£¬£¬ÌØÊâÊÇÔÚÕë¶Ô¶«ÑǸ÷µØ×éÖ¯µÄ¡°DRAGONSPARK¡±»î¶¯ÖС£¡£¡£¡£¡£ ¡£¡£¸Ã¶ñÒâÈí¼þÔÚÔËÐÐʱڹÊÍÆäǶÈëʽ Golang Ô´´úÂëµÄÄÜÁ¦Ê¹ÆäÆÊÎö±äµÃÖØ´ó²¢Ìӱܾ²Ì¬¼ì²â £¬£¬£¬£¬£¬Õâ¶ÔÍøÂçÇå¾²·ÀÓù×é³ÉÁËÖØ´óÌôÕ½¡£¡£¡£¡£¡£ ¡£¡£


https://securityonline.info/stealthy-new-loader-helps-sparkrat-malware-evade-detection/


4. ÍþвÐÐΪÕßй¶7ÍòÍò¶àÌõ¾Ý³Æ´Ó AT&T ÇÔÈ¡µÄ¼Í¼


3ÔÂ17ÈÕ £¬£¬£¬£¬£¬vx-underground µÄÑо¿Ö°Ô±Ê×ÏÈ×¢ÖØµ½ £¬£¬£¬£¬£¬À´×Ô AT&T µÄÁè¼Ý 70,000,000 Ìõ¼Í¼ÔÚ Breached ºÚ¿ÍÂÛ̳Éϱ»Ð¹Â¶¡£¡£¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±Ö¤ÊµÐ¹Â¶µÄÊý¾ÝÊÇÕæÊµµÄ £¬£¬£¬£¬£¬µ«ÏÖÔÚÉв»ÇåÎúÕâЩÐÅÏ¢ÊÇ·ñÊÇ´ÓÓë AT&T Ïà¹ØµÄµÚÈý·½×éÖ¯ÇÔÈ¡µÄ¡£¡£¡£¡£¡£ ¡£¡£Âô¼ÒÒÔ MajorNelson µÄÃûÒåÔÚÍøÉÏÉù³Æ £¬£¬£¬£¬£¬ÕâЩÊý¾ÝÊÇ @ShinyHuntersÓÚ 2021 Äê´ÓÒ»¸öδ͸¶ÐÕÃûµÄ AT&T ²¿·Ö»ñµÃµÄ¡£¡£¡£¡£¡£ ¡£¡£¸Ãµµ°¸°üÀ¨ 73.481.539 Ìõ¼Í¼¡£¡£¡£¡£¡£ ¡£¡£2021 Äê 8 Ô £¬£¬£¬£¬£¬ShinyHunters ×éÖ¯Éù³ÆÓµÓÐÒ»¸öÊý¾Ý¿â £¬£¬£¬£¬£¬ÆäÖаüÀ¨Ô¼Äª 7000 Íò AT&T ¿Í»§µÄ˽ÈËÐÅÏ¢ £¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾·ñ¶¨ÕâЩÐÅÏ¢ÒÑ´ÓÆäϵͳÖб»µÁ¡£¡£¡£¡£¡£ ¡£¡£ShinyHunters ÊÇÒ»¸öÊܽӴýµÄºÚ¿Í×éÖ¯ £¬£¬£¬£¬£¬ÖÚËùÖÜÖª £¬£¬£¬£¬£¬ËûÃdzöÊÛ´Ó Tokopedia¡¢  Homechef¡¢  Chatbooks.com¡¢  MicrosoftºÍ MintedµÈÊýÊ®¸öÖ÷Òª×éÖ¯ÇÔÈ¡µÄÊý¾Ý¡£¡£¡£¡£¡£ ¡£¡£


https://securityaffairs.com/160627/data-breach/70m-att-records-leaked.html


5. GITGUB¶ñÒâÈí¼þ»î¶¯Ê¹Óà RISEPRO Õë¶Ô GITHUB Óû§


3ÔÂ17ÈÕ £¬£¬£¬£¬£¬G-Data Ñо¿Ö°Ô±·¢Ã÷ÖÁÉÙ 13 ¸ö´ËÀà Github ´æ´¢¿âÍйÜ×ÅÖ¼ÔÚÌṩ RisePro ÐÅÏ¢ÇÔÈ¡³ÌÐòµÄÆÆ½âÈí¼þ¡£¡£¡£¡£¡£ ¡£¡£×¨¼Ò×¢ÖØµ½ £¬£¬£¬£¬£¬¸Ã»î¶¯±»ÆäÔËÓªÕßÃüÃûΪ¡°gitgub¡±¡£¡£¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±Æ¾Ö¤ Arstechnica¹ØÓÚ¶ñÒâ Github ´æ´¢¿âµÄ¹ÊÊÂ×îÏÈÁËÊÓ²ì ¡£¡£¡£¡£¡£ ¡£¡£×¨¼ÒÃǽ¨ÉèÁËÒ»¸öÍþв׷×Ù¹¤¾ß £¬£¬£¬£¬£¬Ê¹ËûÃÇÄܹ»Ê¶±ð¼ÓÈë´Ë»î¶¯µÄ´æ´¢¿â¡£¡£¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±×¢Öص½ £¬£¬£¬£¬£¬ËùÓд洢¿â¶¼ÊÇн¨ÉèµÄ´æ´¢¿â £¬£¬£¬£¬£¬µ¼ÖÂÏàͬµÄÏÂÔØÁ´½Ó¡£¡£¡£¡£¡£ ¡£¡£ÕâЩ´æ´¢¿â¿´ÆðÀ´ºÜÏàËÆ £¬£¬£¬£¬£¬¶¼ÓÐÒ»¸ö README.md Îļþ £¬£¬£¬£¬£¬²¢ÔÊÐíÌṩÃâ·ÑÆÆ½âÈí¼þ¡£¡£¡£¡£¡£ ¡£¡£Github Éϳ£ÓÃÂÌÉ«ºÍºìɫԲȦÀ´ÏÔʾ×Ô¶¯¹¹½¨µÄ״̬¡£¡£¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±×¢Öص½ £¬£¬£¬£¬£¬Óû§±ØÐèʹÓà README.md ÎļþÖÐÌṩµÄÃÜÂë¡°GIT1HUB1FREE¡±½âѹ¶à²ãµµ°¸ £¬£¬£¬£¬£¬²Å»ª»á¼ûÃûΪ¡°Installer_Mega_v0.7.4t.msi¡±µÄ×°ÖóÌÐò¡£¡£¡£¡£¡£ ¡£¡£ 


https://securityaffairs.com/160596/hacking/risepro-info-stealer-targets-github-users.html


6. ÄÏ·ÇÕþ¸®ÕýÔÚÊÓ²ìÑøÀϽð»ú¹¹Êý¾Ýй¶ÊÂÎñ


3ÔÂ18ÈÕ £¬£¬£¬£¬£¬ÄÏ·ÇÕþ¸®¹ÙÔ±ÕýÔÚÊÓ²ìÓйØÀÕË÷Èí¼þÍÅ»ïÇÔÈ¡²¢ÔÚÍøÉÏй¶ 668GB Ãô¸Ð¹úÃñÑøÀϽðÊý¾ÝµÄ±¨µÀ¡£¡£¡£¡£¡£ ¡£¡£3ÔÂ11ÈÕÉæÏÓй¶Õþ¸®ÑøÀϽðÖÎÀí¾Ö£¨GPAA£©Êý¾ÝµÄÊÂÎñÉÐδ»ñµÃ¹ûÕæÖ¤Êµ £¬£¬£¬£¬£¬µ«¸ÃÊÂÎñÒѳÉΪÄÏ·ÇÌìÏÂÐÂÎÅ¡£¡£¡£¡£¡£ ¡£¡£ÄÏ·ÇÕþ¸®¹ÍÔ±ÑøÀÏ»ù½ð (GEPF) ½éÈëÊÓ²ìÎÛÃûÕÑÖøµÄ LockBit ÍøÂç·¸·¨ÍÅ»ïµÄÖ¸¿Ø¡£¡£¡£¡£¡£ ¡£¡£GEPFÊÇÄϷǶ¥¼¶ÑøÀÏ»ù½ð £¬£¬£¬£¬£¬Æä¿Í»§°üÀ¨120ÍòÃûÏÖÈÎÕþ¸®¹ÍÔ±ÒÔ¼°47.3ÍòÃûÑøÀϽðÁìÈ¡ÕßºÍÆäËûÊÜÒæÈË¡£¡£¡£¡£¡£ ¡£¡£¸ÃÑøÀÏ»ù½ðÔÚÒ»·Ý¹ûÕæÉùÃ÷ÖÐÌåÏÖ£º¡°GEPF ÕýÔÚÓë GPAA ¼°Æä¼àÊÓ»ú¹¹¡¢¹ú¼Ò²ÆÎñ²¿ÏàÖú £¬£¬£¬£¬£¬ÒÔÈ·¶¨Ëù±¨¸æµÄÊý¾Ýй¶ÊÂÎñµÄ׼ȷÐÔºÍÓ°Ïì £¬£¬£¬£¬£¬²¢½«ÔÚÊʵ±µÄʱ¼äÌṩ½øÒ»²½µÄ¸üС£¡£¡£¡£¡£ ¡£¡£¡±


https://www.darkreading.com/cyberattacks-data-breaches/south-african-government-pension-data-leak-fears-spark-probe