APT28 Õë¶ÔÅ·ÖÞ¡¢ÃÀÖÞºÍÑÇÖÞÖ´ÐÐÍøÂç´¹µö´òËã
°ä²¼¹¦·ò 2024-03-193ÔÂ18ÈÕ£¬Óë¶íÂÞ˹ÓйصÄÍþвÐÐΪÕßAPT28Óë¶à¸öÔÚ½øÐеÄÍøÂç´¹µö»î¶¯Óйأ¬ÕâЩ»î¶¯Ê¹Ó÷ÂÕÕÅ·ÖÞ¡¢Äϸ߼ÓË÷¡¢ÖÐÑÇÒÔ¼°±±ÃÀºÍÄÏÃÀµ±¾ÖºÍ·Çµ±¾Ö×éÖ¯ (NGO) µÄµö¶üÎļþ¡£IBM X °µÊ¾£º¡°Î´·¢Ïֵĵö¶üÔ̺¬ÄÚ²¿ºÍ¹«¿ªÎļþµÄ»ìºÏÌ壬ÒÔ¼°¿ÉÄÜÓɲμÓÕßÌìÉúµÄÓë½ðÈÚ¡¢¹Ø¼ü»ù´¡ÉèÊ©¡¢¸ß¹Ü²Î¼Ó¡¢ÍøÂ簲ȫ¡¢º£Ê°²È«¡¢Ò½ÁƱ£½¡¡¢Ã³Ò׺͹ú·À¹¤Òµ³ö²úÓйصÄÎļþ¡£¡± ¸Ã¿Æ¼¼¹«Ë¾ÔÚ×·×ÙÃûΪITG05µÄ»î¶¯£¬¸ÃÃû³ÆÒ²³ÆÎª Blue Athena¡¢BlueDelta¡¢Fancy Bear¡¢Fighting Ursa¡¢Forest Blizzard£¨ÒÔǰ³ÆÎª Strontium£©¡¢FROZENLAKE¡¢Iron Twilight¡¢Pawn Storm¡¢Sednit¡¢Sofacy¡¢TA422 ºÍUAC-028¡£ÕâÒ»Åû¶ÊÇÔÚµÐÊÖ±»·¢ÏÖʹÓÃÓëÔÚ½øÐеÄÒÔÉ«ÁÐ-¹þÂí˹սÕùÓйصĵö¶üÀ´ÌṩÃûΪHeadLaceµÄ¶¨ÔìºóÃÅÈý¸ö¶àÔºó°ä²¼µÄ¡£¶ûºó£¬APT28 »¹ÏòÎÚ¿ËÀ¼µÐÔÖʵÌåºÍ²¨À¼×éÖ¯·¢ËÍÍøÂç´¹µöÐÂÎÅ£¬ÕâЩÐÂÎÅÖ¼ÔÚ²¿Êð¶¨ÔìÖ²È뷨ʽºÍÐÅÏ¢ÇÔÈ¡·¨Ê½£¬ÀýÈçMASEPIE¡¢OCEANMAP ºÍ STEELHOOK¡£
https://thehackernews.com/2024/03/apt28-hacker-group-targeting-europe.html
2. ÈÕ±¾¸»Ê¿Í¨Ð¹Â©Æä¹«Ë¾ÄÚÍøÏ°È¾¶ñÒâÈí¼þµ¼ÖÂÊý¾Ýй¶
3ÔÂ17ÈÕ£¬¸»Ê¿´«µÝ·ËûÃÇÔÚÄÚ²¿µ÷²éÆÚ¼ä¼ì²âµ½Á˸öñÒâÈí¼þ¡£·¢ÏÖºó£¬ËûÃǵ±¼´¸ôÀëÊÜϰȾµÄÉ豸£¬²¢¼ÓÇ¿Õû¸öϵͳµÄ°²È«¼à¿Ø¡£Ä¿Ç°ÔÚ½øÐÐÉî¿Ìµ÷²é£¬ÒÔÈ·¶¨¶ñÒâÈí¼þµÄÈë¿ÚµãºÍDZÔÚÊý¾Ýй¶µÄÈ«ÊýÁìÓò¡£¸Ã¹«Ë¾ÒÑ×Ô¶¯Í¨ÖªÊý¾Ý¿ÉÄܱ»½Ó¼ûµÄÓ×ÎҺͿͻ§¡£ËûÃÇ»¹ÏòÓ×ÎÒÐÅÏ¢±£»¤Î¯Ô±»áÌá½»ÁËÓйØÇ±ÔÚÊý¾Ýй¶µÄ»ã±¨¡£ÐÒÔ˵ÄÊÇ£¬¸»Ê¿Í¨°µÊ¾£¬ËûÃÇÉÐδ¹Û²ìµ½ÈκÎÊÜËðÊý¾Ý±»ÓÃÓÚ¶ñÒâÖ÷ÕŵÄÇé¿ö¡£¶ÔÓÚÕâ´ÎÊÂÎñÔì³ÉµÄ²»±ãºÍÓÇÓô£¬¸»Ê¿Í¨ÏòËùÓÐÊÜÓ°ÏìµÄ¸÷·½°µÊ¾ÕæÖ¿µÄǸÒâ¡£
https://securityonline.info/fujitsu-discloses-data-breach-customer-and-personal-information-compromised/
3. ÐÂÐÍÒþÐμÓÔØ·¨Ê½Ô®ÊÖ SPARKRAT ¶ñÒâÈí¼þÌӱܼì²â
3ÔÂ17ÈÕ£¬Kroll µÄÍøÂ簲ȫ×êÑÐÈËÔ±°ä²¼Á˳ôÃûÔ¶ÑïµÄ SPARKRAT¶ñÒâÈí¼þ¹¤¾ß°üµÄÒ»ÏîÁîÈËÓÇÓôµÄ½øÕ¹¡£Ò»ÖÖÓà Golang ±àдµÄǰËùδ¼ûµÄмÓÔØ·¨Ê½ÔÚ±»»ý¼«Ê¹Óã¬ÒÔ½« SPARKRAT DZÈëÖ¸±êϵͳ£¬´Ó¶øÊ¹¶ñÒâÈí¼þ¿ÉÄÜÔÚ´«Í³°²È«¹¤¾ßµÄÀ×´ïÏÂÔËÐС£SPARKRAT ÓÉ GitHub ¿ª·¢ÈËÔ± XZB-1248 ÏòÊÀ½çÍÆ³ö£¬×÷Ϊһ¿îÖ°ÄÜ·á˶µÄ¿ªÔ´Ô¶³ÌÖÎÀí¹¤¾ß¡£SPARKRAT ÊÇΪ¶à¸öƽ̨±àÒëµÄ£¬×î³õµÄÖ÷ÕÅÊÇ×÷ΪһÖÖÁ¼ÐÔ¹¤¾ß¡£È»¶ø£¬¸ÃÏîÄ¿ÓÚ 2023 Äê 2 Ô±»ÉÕ»Ù£¬µ«ÔÚ´Ë֮ǰËüÒýÆðÁËÍøÂç·¸×ï·Ö×ÓÈ·°ÑÎÈ¡£SPARKRAT µÄÅú¸Ä°æ±¾ÆðÍ·³Ê´Ë¿Ì¸÷ÀàÈëÇÖµ÷²éÖУ¬³ö¸ñÊÇÔÚÕë¶Ô¶«ÑǸ÷µØ×éÖ¯µÄ¡°DRAGONSPARK¡±»î¶¯ÖС£¸Ã¶ñÒâÈí¼þÔÚÔËÐÐʱڹÊÍÆäǶÈëʽ Golang Ô´´úÂëµÄÄÜÁ¦Ê¹Æä·ÖÎö±äµÃ¸´ÔÓ²¢Ìӱܾ²Ì¬¼ì²â£¬Õâ¶ÔÍøÂ簲ȫ·ÀÓù×é³ÉÁ˳Á´óÌôÕ½¡£
https://securityonline.info/stealthy-new-loader-helps-sparkrat-malware-evade-detection/
4. ÍþвÐÐΪÕßй¶7ǧÍò¶àÌõ¾Ý³Æ´Ó AT&T ÇÔÈ¡µÄ¼Í¼
3ÔÂ17ÈÕ£¬vx-underground µÄ×êÑÐÈËÔ±Ê×ÏȰÑÎȵ½£¬À´×Ô AT&T µÄ³¬¹ý 70,000,000 ±Ê¼Í¼ÔÚ Breached ºÚ¿ÍÂÛ̳Éϱ»Ð¹Â¶¡£×êÑÐÈËԱ֤ʵй¶µÄÊý¾ÝÊÇÕæÊµµÄ£¬µ«Ä¿Ç°Éв»Ã÷ÏÔÕâЩÐÅÏ¢ÊÇ·ñÊÇ´ÓÓë AT&T ÓйصĵÚÈý·½×éÖ¯ÇÔÈ¡µÄ¡£Âô¼ÒÒÔ MajorNelson µÄÃûÒåÔÚÍøÉÏÐû³Æ£¬ÕâЩÊý¾ÝÊÇ @ShinyHuntersÓÚ 2021 Äê´ÓÒ»¸öδй©ÐÕÃûµÄ AT&T ²¿ÃÅ»ñµÃµÄ¡£¸Ãµµ°¸Ô̺¬ 73.481.539 ±Ê¼Í¼¡£2021 Äê 8 Ô£¬ShinyHunters ×éÖ¯Ðû³ÆÕ¼ÓÐÒ»¸öÊý¾Ý¿â£¬ÆäÖÐÔ̺¬Ô¼Äª 7000 Íò AT&T ¿Í»§µÄ¸öÈËÐÅÏ¢£¬µ«¸Ã¹«Ë¾·ñ¶¨ÕâЩÐÅÏ¢ÒÑ´ÓÆäϵͳÖб»µÁ¡£ShinyHunters ÊÇÒ»¸öÊÜӽӵĺڿÍ×éÖ¯£¬¶àËùÖÜÖª£¬ËûÃÇÏúÊÛ´Ó Tokopedia¡¢ Homechef¡¢ Chatbooks.com¡¢ MicrosoftºÍ MintedµÈÊýÊ®¸öÖØÒª×éÖ¯ÇÔÈ¡µÄÊý¾Ý¡£
https://securityaffairs.com/160627/data-breach/70m-att-records-leaked.html
5. GITGUB¶ñÒâÈí¼þ»î¶¯ÀûÓà RISEPRO Õë¶Ô GITHUB Óû§
3ÔÂ17ÈÕ£¬G-Data ×êÑÐÈËÔ±·¢ÏÖÖÁÉÙ 13 ¸ö´ËÀà Github ´æ´¢¿âÍйÜ×ÅÖ¼ÔÚÌṩ RisePro ÐÅÏ¢ÇÔÈ¡·¨Ê½µÄÆÆ½âÈí¼þ¡£×¨¼Ò°ÑÎȵ½£¬¸Ã»î¶¯±»ÆäÔËÓªÕß¶¨ÃûΪ¡°gitgub¡±¡£×êÑÐÈËԱƾ¾Ý Arstechnica¹ØÓÚ¶ñÒâ Github ´æ´¢¿âµÄ¹ÊÊÂÆðÍ·Á˵÷²é ¡£×¨¼ÒÃÇ´´½¨ÁËÒ»¸öÍþв׷×Ù¹¤¾ß£¬Ê¹ËûÃÇ¿ÉÄܼø±ð²Î¼Ó´Ë»î¶¯µÄ´æ´¢¿â¡£×êÑÐÈËÔ±°ÑÎȵ½£¬ËùÓд洢¿â¶¼ÊÇд´½¨µÄ´æ´¢¿â£¬µ¼ÖÂÒ»ÑùµÄÏÂÔØÁ´½Ó¡£ÕâЩ´æ´¢¿â¿´ÆðÀ´ºÜÀàËÆ£¬¶¼ÓÐÒ»¸ö README.md Îļþ£¬²¢³ÐŵÌṩÃâ·ÑÆÆ½âÈí¼þ¡£Github Éϳ£ÓÃÂÌÉ«ºÍºìɫԲȦÀ´ÏÔʾ×Ô¶¯¹¹½¨µÄ״̬¡£×êÑÐÈËÔ±°ÑÎȵ½£¬Óû§±ØÐëʹÓà README.md ÎļþÖÐÌṩµÄÃÜÂë¡°GIT1HUB1FREE¡±½âѹ¶à²ãµµ°¸£¬ÄÜÁ¦½Ó¼ûÃûΪ¡°Installer_Mega_v0.7.4t.msi¡±µÄ×°Ö÷¨Ê½¡£
https://securityaffairs.com/160596/hacking/risepro-info-stealer-targets-github-users.html
6. ÄϷǵ±¾ÖÔÚµ÷²éÑøÀϽð»ú¹¹Êý¾Ýй¶ÊÂÎñ
3ÔÂ18ÈÕ£¬ÄϷǵ±¾Ö¹ÙÔ¹ØýÔÚµ÷²éÓйØÀÕË÷Èí¼þÍÅ»ïÇÔÈ¡²¢ÔÚÍøÉÏй¶ 668GB Ãô¸Ð¹úÃñÑøÀϽðÊý¾ÝµÄ±¨Â·¡£3ÔÂ11ÈÕÉæÏÓй¶µ±¾ÖÑøÀϽðÖÎÀí¾Ö£¨GPAA£©Êý¾ÝµÄÊÂÎñÉÐδµÃµ½¹«¿ªÖ¤Êµ£¬µ«¸ÃÊÂÎñÒѳÉΪÄÏ·ÇÈ«¹úÐÂÎÅ¡£ÄϷǵ±¾Ö¹ÍÔ±ÑøÀÏ»ù½ð (GEPF) Ⱦָµ÷²é³ôÃûÔ¶ÑïµÄ LockBit ÍøÂç·¸×ïÍÅ»ïµÄÖ¸¿Ø¡£GEPFÊÇÄϷǶ¥¼¶ÑøÀÏ»ù½ð£¬Æä¿Í»§Ô̺¬120ÍòÃûÏÖÈε±¾Ö¹ÍÔ±ÒÔ¼°47.3ÍòÃûÑøÀϽðÁìÈ¡ÕßºÍÆäËûÊÜÒæÈË¡£¸ÃÑøÀÏ»ù½ðÔÚÒ»·Ý¹«¿ªÉêÃ÷ÖаµÊ¾£º¡°GEPF ÔÚÓë GPAA ¼°Æä¼à¶½»ú¹¹¡¢¹ú¶È²ÆÕþ²¿ºÏ×÷£¬ÒÔÈ·¶¨Ëù»ã±¨µÄÊý¾Ýй¶ÊÂÎñµÄÕýÈ·ÐÔºÍÓ°Ï죬²¢½«ÔÚÊʵ±µÄʱ³½Ìṩ½øÒ»²½µÄ¸üС£¡±
https://www.darkreading.com/cyberattacks-data-breaches/south-african-government-pension-data-leak-fears-spark-probe


¾©¹«Íø°²±¸11010802024551ºÅ