APT28 Õë¶ÔÅ·ÖÞ¡¢ÃÀÖÞºÍÑÇÖÞÖ´ÐÐÍøÂç´¹µö´òËã

°ä²¼¹¦·ò 2024-03-19
1. APT28 Õë¶ÔÅ·ÖÞ¡¢ÃÀÖÞºÍÑÇÖÞÖ´ÐÐÍøÂç´¹µö´òËã


3ÔÂ18ÈÕ  £¬Óë¶íÂÞ˹ÓйصÄÍþвÐÐΪÕßAPT28Óë¶à¸öÔÚ½øÐеÄÍøÂç´¹µö»î¶¯ÓйØ  £¬ÕâЩ»î¶¯Ê¹Ó÷ÂÕÕÅ·ÖÞ¡¢Äϸ߼ÓË÷¡¢ÖÐÑÇÒÔ¼°±±ÃÀºÍÄÏÃÀµ±¾ÖºÍ·Çµ±¾Ö×éÖ¯ (NGO) µÄµö¶üÎļþ¡£IBM X °µÊ¾£º¡°Î´·¢Ïֵĵö¶üÔ̺¬ÄÚ²¿ºÍ¹«¿ªÎļþµÄ»ìºÏÌå  £¬ÒÔ¼°¿ÉÄÜÓɲμÓÕßÌìÉúµÄÓë½ðÈÚ¡¢¹Ø¼ü»ù´¡ÉèÊ©¡¢¸ß¹Ü²Î¼Ó¡¢ÍøÂ簲ȫ¡¢º£Ê°²È«¡¢Ò½ÁƱ£½¡¡¢Ã³Ò׺͹ú·À¹¤Òµ³ö²úÓйصÄÎļþ¡£¡± ¸Ã¿Æ¼¼¹«Ë¾ÔÚ×·×ÙÃûΪITG05µÄ»î¶¯  £¬¸ÃÃû³ÆÒ²³ÆÎª Blue Athena¡¢BlueDelta¡¢Fancy Bear¡¢Fighting Ursa¡¢Forest Blizzard£¨ÒÔǰ³ÆÎª Strontium£©¡¢FROZENLAKE¡¢Iron Twilight¡¢Pawn Storm¡¢Sednit¡¢Sofacy¡¢TA422 ºÍUAC-028¡£ÕâÒ»Åû¶ÊÇÔÚµÐÊÖ±»·¢ÏÖʹÓÃÓëÔÚ½øÐеÄÒÔÉ«ÁÐ-¹þÂí˹սÕùÓйصĵö¶üÀ´ÌṩÃûΪHeadLaceµÄ¶¨ÔìºóÃÅÈý¸ö¶àÔºó°ä²¼µÄ¡£¶ûºó  £¬APT28 »¹ÏòÎÚ¿ËÀ¼µÐÔÖʵÌåºÍ²¨À¼×éÖ¯·¢ËÍÍøÂç´¹µöÐÂÎÅ  £¬ÕâЩÐÂÎÅÖ¼ÔÚ²¿Êð¶¨ÔìÖ²È뷨ʽºÍÐÅÏ¢ÇÔÈ¡·¨Ê½  £¬ÀýÈçMASEPIE¡¢OCEANMAP ºÍ STEELHOOK¡£


https://thehackernews.com/2024/03/apt28-hacker-group-targeting-europe.html


2. ÈÕ±¾¸»Ê¿Í¨Ð¹Â©Æä¹«Ë¾ÄÚÍøÏ°È¾¶ñÒâÈí¼þµ¼ÖÂÊý¾Ýй¶


3ÔÂ17ÈÕ  £¬¸»Ê¿´«µÝ·ËûÃÇÔÚÄÚ²¿µ÷²éÆÚ¼ä¼ì²âµ½Á˸öñÒâÈí¼þ¡£·¢ÏÖºó  £¬ËûÃÇÁ¢¼´¸ôÀëÊÜϰȾµÄÉ豸  £¬²¢¼ÓÇ¿Õû¸öϵͳµÄ°²È«¼à¿Ø¡£Ä¿Ç°ÔÚ½øÐÐÉî¿Ìµ÷²é  £¬ÒÔÈ·¶¨¶ñÒâÈí¼þµÄÈë¿ÚµãºÍDZÔÚÊý¾Ýй¶µÄÈ«ÊýÁìÓò¡£¸Ã¹«Ë¾ÒÑ×Ô¶¯Í¨ÖªÊý¾Ý¿ÉÄܱ»½Ó¼ûµÄÓ×ÎҺͿͻ§¡£ËûÃÇ»¹ÏòÓ×ÎÒÐÅÏ¢±£»¤Î¯Ô±»áÌá½»ÁËÓйØÇ±ÔÚÊý¾Ýй¶µÄ»ã±¨¡£ÐÒÔ˵ÄÊÇ  £¬¸»Ê¿Í¨°µÊ¾  £¬ËûÃÇÉÐδ¹Û²ìµ½ÈκÎÊÜËðÊý¾Ý±»ÓÃÓÚ¶ñÒâÖ÷ÕŵÄÇé¿ö¡£¶ÔÓÚÕâ´ÎÊÂÎñÔì³ÉµÄ²»±ãºÍÓÇÓô  £¬¸»Ê¿Í¨ÏòËùÓÐÊÜÓ°ÏìµÄ¸÷·½°µÊ¾ÕæÖ¿µÄǸÒâ¡£


https://securityonline.info/fujitsu-discloses-data-breach-customer-and-personal-information-compromised/


3. ÐÂÐÍÒþÐμÓÔØ·¨Ê½Ô®ÊÖ SPARKRAT ¶ñÒâÈí¼þÌӱܼì²â


3ÔÂ17ÈÕ  £¬Kroll µÄÍøÂ簲ȫ×êÑÐÈËÔ±°ä²¼Á˳ôÃûÔ¶ÑïµÄ SPARKRAT¶ñÒâÈí¼þ¹¤¾ß°üµÄÒ»ÏîÁîÈËÓÇÓôµÄ½øÕ¹¡£Ò»ÖÖÓà Golang ±àдµÄǰËùδ¼ûµÄмÓÔØ·¨Ê½ÔÚ±»»ý¼«Ê¹Óà  £¬ÒÔ½« SPARKRAT DZÈëÖ¸±êϵͳ  £¬´Ó¶øÊ¹¶ñÒâÈí¼þ¿ÉÄÜÔÚ´«Í³°²È«¹¤¾ßµÄÀ×´ïÏÂÔËÐС£SPARKRAT ÓÉ GitHub ¿ª·¢ÈËÔ± XZB-1248 ÏòÊÀ½çÍÆ³ö  £¬×÷Ϊһ¿îÖ°ÄÜ·á˶µÄ¿ªÔ´Ô¶³ÌÖÎÀí¹¤¾ß¡£SPARKRAT ÊÇΪ¶à¸öƽ̨±àÒëµÄ  £¬×î³õµÄÖ÷ÕÅÊÇ×÷ΪһÖÖÁ¼ÐÔ¹¤¾ß¡£È»¶ø  £¬¸ÃÏîÄ¿ÓÚ 2023 Äê 2 Ô±»ÉÕ»Ù  £¬µ«ÔÚ´Ë֮ǰËüÒýÆðÁËÍøÂç·¸×ï·Ö×ÓÈ·°ÑÎÈ¡£SPARKRAT µÄÅú¸Ä°æ±¾ÆðÍ·³Ê´Ë¿Ì¸÷ÀàÈëÇÖµ÷²éÖÐ  £¬³ö¸ñÊÇÔÚÕë¶Ô¶«ÑǸ÷µØ×éÖ¯µÄ¡°DRAGONSPARK¡±»î¶¯ÖС£¸Ã¶ñÒâÈí¼þÔÚÔËÐÐʱڹÊÍÆäǶÈëʽ Golang Ô´´úÂëµÄÄÜÁ¦Ê¹Æä·ÖÎö±äµÃ¸´ÔÓ²¢Ìӱܾ²Ì¬¼ì²â  £¬Õâ¶ÔÍøÂ簲ȫ·ÀÓù×é³ÉÁ˳Á´óÌôÕ½¡£


https://securityonline.info/stealthy-new-loader-helps-sparkrat-malware-evade-detection/


4. ÍþвÐÐΪÕßй¶7ǧÍò¶àÌõ¾Ý³Æ´Ó AT&T ÇÔÈ¡µÄ¼Í¼


3ÔÂ17ÈÕ  £¬vx-underground µÄ×êÑÐÈËÔ±Ê×ÏȰÑÎȵ½  £¬À´×Ô AT&T µÄ³¬¹ý 70,000,000 ±Ê¼Í¼ÔÚ Breached ºÚ¿ÍÂÛ̳Éϱ»Ð¹Â¶¡£×êÑÐÈËԱ֤ʵй¶µÄÊý¾ÝÊÇÕæÊµµÄ  £¬µ«Ä¿Ç°Éв»Ã÷ÏÔÕâЩÐÅÏ¢ÊÇ·ñÊÇ´ÓÓë AT&T ÓйصĵÚÈý·½×éÖ¯ÇÔÈ¡µÄ¡£Âô¼ÒÒÔ MajorNelson µÄÃûÒåÔÚÍøÉÏÐû³Æ  £¬ÕâЩÊý¾ÝÊÇ @ShinyHuntersÓÚ 2021 Äê´ÓÒ»¸öδй©ÐÕÃûµÄ AT&T ²¿ÃÅ»ñµÃµÄ¡£¸Ãµµ°¸Ô̺¬ 73.481.539 ±Ê¼Í¼¡£2021 Äê 8 Ô  £¬ShinyHunters ×éÖ¯Ðû³ÆÕ¼ÓÐÒ»¸öÊý¾Ý¿â  £¬ÆäÖÐÔ̺¬Ô¼Äª 7000 Íò AT&T ¿Í»§µÄ¸öÈËÐÅÏ¢  £¬µ«¸Ã¹«Ë¾·ñ¶¨ÕâЩÐÅÏ¢ÒÑ´ÓÆäϵͳÖб»µÁ¡£ShinyHunters ÊÇÒ»¸öÊÜÓ­½ÓµÄºÚ¿Í×éÖ¯  £¬¶àËùÖÜÖª  £¬ËûÃÇÏúÊÛ´Ó Tokopedia¡¢  Homechef¡¢  Chatbooks.com¡¢  MicrosoftºÍ MintedµÈÊýÊ®¸öÖØÒª×éÖ¯ÇÔÈ¡µÄÊý¾Ý¡£


https://securityaffairs.com/160627/data-breach/70m-att-records-leaked.html


5. GITGUB¶ñÒâÈí¼þ»î¶¯ÀûÓà RISEPRO Õë¶Ô GITHUB Óû§


3ÔÂ17ÈÕ  £¬G-Data ×êÑÐÈËÔ±·¢ÏÖÖÁÉÙ 13 ¸ö´ËÀà Github ´æ´¢¿âÍйÜ×ÅÖ¼ÔÚÌṩ RisePro ÐÅÏ¢ÇÔÈ¡·¨Ê½µÄÆÆ½âÈí¼þ¡£×¨¼Ò°ÑÎȵ½  £¬¸Ã»î¶¯±»ÆäÔËÓªÕß¶¨ÃûΪ¡°gitgub¡±¡£×êÑÐÈËԱƾ¾Ý Arstechnica¹ØÓÚ¶ñÒâ Github ´æ´¢¿âµÄ¹ÊÊÂÆðÍ·Á˵÷²é ¡£×¨¼ÒÃÇ´´½¨ÁËÒ»¸öÍþв׷×Ù¹¤¾ß  £¬Ê¹ËûÃÇ¿ÉÄܼø±ð²Î¼Ó´Ë»î¶¯µÄ´æ´¢¿â¡£×êÑÐÈËÔ±°ÑÎȵ½  £¬ËùÓд洢¿â¶¼ÊÇд´½¨µÄ´æ´¢¿â  £¬µ¼ÖÂÒ»ÑùµÄÏÂÔØÁ´½Ó¡£ÕâЩ´æ´¢¿â¿´ÆðÀ´ºÜÀàËÆ  £¬¶¼ÓÐÒ»¸ö README.md Îļþ  £¬²¢³ÐŵÌṩÃâ·ÑÆÆ½âÈí¼þ¡£Github Éϳ£ÓÃÂÌÉ«ºÍºìɫԲȦÀ´ÏÔʾ×Ô¶¯¹¹½¨µÄ״̬¡£×êÑÐÈËÔ±°ÑÎȵ½  £¬Óû§±ØÐëʹÓà README.md ÎļþÖÐÌṩµÄÃÜÂë¡°GIT1HUB1FREE¡±½âѹ¶à²ãµµ°¸  £¬ÄÜÁ¦½Ó¼ûÃûΪ¡°Installer_Mega_v0.7.4t.msi¡±µÄ×°Ö÷¨Ê½¡£ 


https://securityaffairs.com/160596/hacking/risepro-info-stealer-targets-github-users.html


6. ÄϷǵ±¾ÖÔÚµ÷²éÑøÀϽð»ú¹¹Êý¾Ýй¶ÊÂÎñ


3ÔÂ18ÈÕ  £¬ÄϷǵ±¾Ö¹ÙÔ¹ØýÔÚµ÷²éÓйØÀÕË÷Èí¼þÍÅ»ïÇÔÈ¡²¢ÔÚÍøÉÏй¶ 668GB Ãô¸Ð¹úÃñÑøÀϽðÊý¾ÝµÄ±¨Â·¡£3ÔÂ11ÈÕÉæÏÓй¶µ±¾ÖÑøÀϽðÖÎÀí¾Ö£¨GPAA£©Êý¾ÝµÄÊÂÎñÉÐδµÃµ½¹«¿ªÖ¤Êµ  £¬µ«¸ÃÊÂÎñÒѳÉΪÄÏ·ÇÈ«¹úÐÂÎÅ¡£ÄϷǵ±¾Ö¹ÍÔ±ÑøÀÏ»ù½ð (GEPF) Ⱦָµ÷²é³ôÃûÔ¶ÑïµÄ LockBit ÍøÂç·¸×ïÍÅ»ïµÄÖ¸¿Ø¡£GEPFÊÇÄϷǶ¥¼¶ÑøÀÏ»ù½ð  £¬Æä¿Í»§Ô̺¬120ÍòÃûÏÖÈε±¾Ö¹ÍÔ±ÒÔ¼°47.3ÍòÃûÑøÀϽðÁìÈ¡ÕßºÍÆäËûÊÜÒæÈË¡£¸ÃÑøÀÏ»ù½ðÔÚÒ»·Ý¹«¿ªÉêÃ÷ÖаµÊ¾£º¡°GEPF ÔÚÓë GPAA ¼°Æä¼à¶½»ú¹¹¡¢¹ú¶È²ÆÕþ²¿ºÏ×÷  £¬ÒÔÈ·¶¨Ëù»ã±¨µÄÊý¾Ýй¶ÊÂÎñµÄÕýÈ·ÐÔºÍÓ°Ïì  £¬²¢½«ÔÚÊʵ±µÄʱ³½Ìṩ½øÒ»²½µÄ¸üС£¡±


https://www.darkreading.com/cyberattacks-data-breaches/south-african-government-pension-data-leak-fears-spark-probe