ArmisÅû¶PTSϵͳÖеÄͳ³ÆÎªPwnedPiperµÄ·ì϶ £»CyCraft°ä²¼Õë¶ÔÀÕË÷Èí¼þPrometheusµÄÃâ·Ñ½âÃÜÆ÷

°ä²¼¹¦·ò 2021-08-03
1.ArmisÅû¶PTSϵͳÖеÄͳ³ÆÎªPwnedPiperµÄ·ì϶


1.jpg


°²È«¹«Ë¾ArmisÅû¶SwissLogµÄTransLogic PTS£¨Æø¶¯¹Üϵͳ) ÖÐͳ³ÆÎªPwnedPiperµÄ9¸ö·ì϶ £¬Ó°ÏìÈ«ÃÀ80%µÄÒ½Ôº¡£TransLogic PTSÓÃÓÚÔÚ´óÖÐÐÍÒ½ÔºÖг¤¾àÀëÔËËÍÒ½ÁÆÎïÆ· £¬ÒÑÔÚ±±ÃÀ2300¶à¼ÒҽԺʹÓá£ÕâЩ·ì϶ÖÐ×îÑϳÁµÄÊÇδ¾­Éí·ÝÑéÖ¤¡¢Î´¼ÓÃÜ¡¢Î´ÊðÃûµÄ¹Ì¼þÉý¼¶·ì϶£¨CVE-2021-37160£© £¬¿ÉÓÃÀ´ÔÚϵͳÉÏ×°ÖöñÒâ¹Ì¼þÀ´ÆëÈ«½ÚÔìÖ¸±êϵͳ¡£´Ë±í £¬»¹ÓÐÌáȨ·ì϶£¨CVE-2021-37167£©¡¢DoS·ì϶£¨CVE-2021-37166£©ºÍtcpTxThreadÖеÄÈý±¶²Ö¿âÒç³ö£¨CVE-2021-37164£©µÈ·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/08/pwnedpiper-pts-security-flaws-threaten.html


2.KasperskyÅû¶ÐµÄGhostEmperorÍÅ»ïÕë¶Ô¶«ÄÏÑÇ


2.jpg


KasperskyÅû¶ÁËÒ»¸öеĺڿÍÍÅ»ïGhostEmperor £¬ÖØÒªÕë¶Ô¶«ÄÏÑǵØÓòµÄÖ¸±ê £¬Ô̺¬µ±¾Ö»ú¹¹ºÍ¼¸¼ÒµçÐŹ«Ë¾¡£¸ÃÍÅ»ïµÄÈëÇֻÒÀÀµÓÚCheat Engine¿ªÔ´ÏîÖ÷ÕÅÒ»¸ö×é¼þ £¬Ëü¿ÉÄÜÈÆ¹ýWindowsÇý¶¯·¨Ê½Ç¿ÔìÊðÃû»úÔì¡£¸ÃÍÅ»ïÖ®ËùÒÔÒìºõѰ³£ £¬ÊÇÓÉÓÚËüʹÓÃÁËÒ»¸öÒÔǰ²»ÎªÈËÖªµÄWindowsÄÚºËģʽµÄrootkit £¬²¢ÇÒѡȡÁ˸´ÔӵĶà½×¶Î¶ñÒâÈí¼þ¿ò¼Ü £¬Ö¼ÔÚ¶ÔÖ¸±ê·þÎñÆ÷½øÐÐÔ¶³Ì½ÚÔì¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120721/apt/ghostemperor-chinese-speaking-threat-actor.html


3.CiscoÅû¶¶ñÒâÈí¼þSolarmarkerÐÂÒ»ÂֵĹ¥»÷»î¶¯


3.jpg


Cisco TalosÅû¶Á˶ñÒâÈí¼þSolarmarkerÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£ÔÚ2021Äê5Ôµ׺Í6Ô³õ×óÓÒ £¬Talos¼ì²âµ½ÐÂÒ»ÂÖSolarmarker¹¥»÷»î¶¯¼¤Ôö¡£ÔÚ×î½üµÄÕâЩµü´úÖÐ £¬¹¥»÷Õßµ÷ÕûÁ˳õʼdropperµÄÏÂÔØ²½Öè £¬²¢¶Ôstaging×é¼þ£¨´Ë¿Ì³ÆÎªMars£©½øÐÐÁËÉý¼¶¡£ÒÔǰSolarmarker½«´Ó´øÓÐͨÓñêÌâÃû³ÆPdfDocDownloadsPanelµÄÒ³ÃæÏÂÔØ £¬¶øÕâ´Î»î¶¯ÖеÄÏÂÔØÒ³ÃæÏÖαÔì³ÉÀ´×ԹȸèDriveµÄÏÂÔØÎļþÒªÇó £¬¿´ÆðÀ´Ô½·¢ºÏ·¨¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/07/threat-spotlight-solarmarker.html


4.CyCraft°ä²¼Õë¶ÔÀÕË÷Èí¼þPrometheusµÄÃâ·Ñ½âÃÜÆ÷


4.jpg


°²È«¹«Ë¾CyCraft°ä²¼Ãâ·Ñ½âÃÜÆ÷ £¬Ô®ÊÖÀÕË÷Èí¼þPrometheusµÄÊܺ¦Õ߸´Ô­ºÍ½âÃÜÎļþ¡£CyCraft°µÊ¾ £¬PrometheusʹÓÃÁËSalsa20ºÍ»ùÓÚtickcountµÄËæ»úÃÜÂëÀ´¼ÓÃÜÎļþ¡£Ëæ»úÃÜÂëµÄ´óÓ×Ϊ32×Ö½Ú £¬Ã¿¸ö×Ö·û¶¼Êǿɼû×Ö·û £¬²¢ÇÒÓÉÓÚÃÜÂëÒÔtickcount×÷ΪÃÜÔ¿ £¬ËùÒÔÄܹ»Ê¹Óñ©Á¦ÆÆ½â¡£Emsisoft¹«Ë¾°µÊ¾¸Ã½âÃÜÆ÷ΨһµÄ±×¶ËÊÇÖ»ÄÜÆÆ½âÓ×ÎļþµÄ½âÃÜÃÜÔ¿¡£´Ë±í £¬½âÃÜÆ÷°ä²¼²»¾Ãºó £¬PrometheusÍÅ»ïËÆºõÒѾ­ÖÕ³¡ÁËÐж¯¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/decryptor-released-for-prometheus-ransomware-victims/


5.SonicWall°ä²¼2021ÄêÉϰëÄêÍøÂçÌ¬ÊÆµÄ·ÖÎö»ã±¨


5.jpg


SonicWall°ä²¼ÁË2021ÄêÉϰëÄêÍøÂçÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö £¬ÀÕË÷Èí¼þ¹¥»÷ÔÚ2021ÄêÉϰëÄ꼫¶È·è¿ñ £¬¸Ã¹«Ë¾¼ì²âµ½µÄ¹¥»÷³¢ÊÔ´ïµ½3.047ÒÚ´Î £¬ ³¬¹ýÁË2020ÕûÄêµÄ¹¥»÷×ÜÊý¡£ÃÀ¹ú¡¢Ó¢¹ú¡¢µÂ¹ú¡¢ÄϷǺͰÍÎ÷µÈ¹ú¶ÈÊÇÊÜÀÕË÷Èí¼þ¹¥»÷×îÑϳÁµÄ¹ú¶È £¬ÆäÖÐÃÀ¹úÊÜÓ°Ïì½Ï´óµÄµØÓòÊÇ·ðÂÞÀï´ïÖÝ £¬ÓÐ1.111Òڴι¥»÷³¢ÊÔ¡£´Ë±í £¬ÀÕË÷¹¥»÷×î³£¼ûµÄÖ¸±êÊǽðÈÚ»ú¹¹ÒÔ¼°¹ú·ÀµÈ³ÁҪȷµ±¾Ö×éÖ¯ £¬¶øÕë¶Ô½ÌÓýÐÐÒµµÄ¹¥»÷Ôò¼¤ÔöÁË615%¡£


Ô­ÎÄÁ´½Ó£º

https://www.sonicwall.com/2021-cyber-threat-report/


6.Deepinstinct°ä²¼2021ÄêÖÐÍøÂçÍþÐ²Ì¬ÊÆ·ÖÎö»ã±¨


6.jpg


Deep Instinct°ä²¼ÁË2021ÄêÖÐÍøÂçÍþÐ²Ì¬ÊÆ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö £¬ÀÕË÷Èí¼þÒ»ÏòÊÇÕû¸ö2021ÄêµÄÖ÷µ¼Ç÷Ïò £¬ÆäÖÐÖØÒªÍþвΪSTOP(Djvu)¡¢RyukºÍSodinokibi(REvil)µÈ¡£ÒøÐÐľÂí»î¶¯µÄÖØÒªÍþвΪEmotetµÄ¼ÌÈÎÕß £¬ÀýÈçRamnit¡¢QbotºÍIcedID¡£´Ë±í £¬Õë¶ÔColonial PipelineµÄ¹¥»÷³ÉΪȫÇòµÄ½¹µã £¬µ«ÕâÖ»Êǹ¥»÷¹Ø¼ü»ù´¡ÉèÊ©µÄ¶à¶à¹¥»÷³¢ÊÔÖ®Ò» £¬²¢ÇÒÔ¤¼ÆÕâÖÖ¹¥»÷Õ½Êõ½üÆÚÄÚ²»»á²úÉúŤת¡£


Ô­ÎÄÁ´½Ó£º

https://www.deepinstinct.com/2021/07/22/2021-mid-year-cyber-threat-landscape-report/