ArmisÅû¶PTSϵͳÖеÄͳ³ÆÎªPwnedPiperµÄÎó²î£»£»£»£»£»CyCraftÐû²¼Õë¶ÔÀÕË÷Èí¼þPrometheusµÄÃ⺬»ìÃÜÆ÷
Ðû²¼Ê±¼ä 2021-08-03
Çå¾²¹«Ë¾ArmisÅû¶SwissLogµÄTransLogic PTS£¨Æø¶¯¹Üϵͳ) ÖÐͳ³ÆÎªPwnedPiperµÄ9¸öÎó²î£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÈ«ÃÀ80%µÄÒ½Ôº¡£¡£¡£¡£TransLogic PTSÓÃÓÚÔÚ´óÖÐÐÍÒ½ÔºÖг¤¾àÀëÔËËÍÒ½ÁÆÎïÆ·£¬£¬£¬£¬£¬£¬£¬ÒÑÔÚ±±ÃÀ2300¶à¼ÒҽԺʹÓᣡ£¡£¡£ÕâЩÎó²îÖÐ×îÑÏÖØµÄÊÇδ¾Éí·ÝÑéÖ¤¡¢Î´¼ÓÃÜ¡¢Î´ÊðÃûµÄ¹Ì¼þÉý¼¶Îó²î£¨CVE-2021-37160£©£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÔÚϵͳÉÏ×°ÖöñÒâ¹Ì¼þÀ´ÍêÈ«¿ØÖÆÄ¿µÄϵͳ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÉÐÓÐÌáȨÎó²î£¨CVE-2021-37167£©¡¢DoSÎó²î£¨CVE-2021-37166£©ºÍtcpTxThreadÖеÄÈý±¶¿ÍÕ»Òç³ö£¨CVE-2021-37164£©µÈÎó²î¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/08/pwnedpiper-pts-security-flaws-threaten.html
2.KasperskyÅû¶ÐµÄGhostEmperorÍÅ»ïÕë¶Ô¶«ÄÏÑÇ

KasperskyÅû¶ÁËÒ»¸öеĺڿÍÍÅ»ïGhostEmperor£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶Ô¶«ÄÏÑǵØÇøµÄÄ¿µÄ£¬£¬£¬£¬£¬£¬£¬°üÀ¨Õþ¸®»ú¹¹ºÍ¼¸¼ÒµçÐŹ«Ë¾¡£¡£¡£¡£¸ÃÍÅ»ïµÄÈëÇֻÒÀÀµÓÚCheat Engine¿ªÔ´ÏîÄ¿µÄÒ»¸ö×é¼þ£¬£¬£¬£¬£¬£¬£¬ËüÄܹ»ÈƹýWindowsÇý¶¯³ÌÐòÇ¿ÖÆÊðÃû»úÖÆ¡£¡£¡£¡£¸ÃÍÅ»ïÖ®ÒÔÊÇÓëÖÚ²î±ð£¬£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚËüʹÓÃÁËÒ»¸öÒÔǰ²»ÎªÈËÖªµÄWindowsÄÚºËģʽµÄrootkit£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ½ÓÄÉÁËÖØ´óµÄ¶à½×¶Î¶ñÒâÈí¼þ¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ¶ÔÄ¿µÄЧÀÍÆ÷¾ÙÐÐÔ¶³Ì¿ØÖÆ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120721/apt/ghostemperor-chinese-speaking-threat-actor.html
3.CiscoÅû¶¶ñÒâÈí¼þSolarmarkerÐÂÒ»ÂֵĹ¥»÷»î¶¯

Cisco TalosÅû¶Á˶ñÒâÈí¼þSolarmarkerÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£¡£¡£¡£ÔÚ2021Äê5ÔÂβºÍ6Ô³õ×óÓÒ£¬£¬£¬£¬£¬£¬£¬Talos¼ì²âµ½ÐÂÒ»ÂÖSolarmarker¹¥»÷»î¶¯¼¤Ôö¡£¡£¡£¡£ÔÚ×î½üµÄÕâЩµü´úÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßµ÷½âÁ˳õʼdropperµÄÏÂÔØÒªÁ죬£¬£¬£¬£¬£¬£¬²¢¶Ôstaging×é¼þ£¨ÏÖÔÚ³ÆÎªMars£©¾ÙÐÐÁËÉý¼¶¡£¡£¡£¡£ÒÔǰSolarmarker½«´Ó´øÓÐͨÓÃÎÊÌâÃû³ÆPdfDocDownloadsPanelµÄÒ³ÃæÏÂÔØ£¬£¬£¬£¬£¬£¬£¬¶ø´Ë´Î»î¶¯ÖеÄÏÂÔØÒ³ÃæÏÖαÔì³ÉÀ´×ԹȸèDriveµÄÏÂÔØÎļþÇëÇ󣬣¬£¬£¬£¬£¬£¬¿´ÆðÀ´Ô½·¢Õýµ±¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/07/threat-spotlight-solarmarker.html
4.CyCraftÐû²¼Õë¶ÔÀÕË÷Èí¼þPrometheusµÄÃ⺬»ìÃÜÆ÷

Çå¾²¹«Ë¾CyCraftÐû²¼Ã⺬»ìÃÜÆ÷£¬£¬£¬£¬£¬£¬£¬×ÊÖúÀÕË÷Èí¼þPrometheusµÄÊܺ¦Õ߻ָ´Ï¢ÕùÃÜÎļþ¡£¡£¡£¡£CyCraftÌåÏÖ£¬£¬£¬£¬£¬£¬£¬PrometheusʹÓÃÁËSalsa20ºÍ»ùÓÚtickcountµÄËæÉñÃØÂëÀ´¼ÓÃÜÎļþ¡£¡£¡£¡£ËæÉñÃØÂëµÄ¾ÞϸΪ32×Ö½Ú£¬£¬£¬£¬£¬£¬£¬Ã¿¸ö×Ö·û¶¼Êǿɼû×Ö·û£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÓÉÓÚÃÜÂëÒÔtickcount×÷ΪÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬ÒÔÊÇ¿ÉÒÔʹÓñ©Á¦ÆÆ½â¡£¡£¡£¡£Emsisoft¹«Ë¾ÌåÏָýâÃÜÆ÷ΨһµÄÈõµãÊÇÖ»ÄÜÆÆ½âСÎļþµÄ½âÃÜÃÜÔ¿¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬½âÃÜÆ÷Ðû²¼²»¾Ãºó£¬£¬£¬£¬£¬£¬£¬PrometheusÍÅ»ïËÆºõÒѾ×èÖ¹ÁËÐж¯¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/decryptor-released-for-prometheus-ransomware-victims/
5.SonicWallÐû²¼2021ÄêÉϰëÄêÍøÂçÌ¬ÊÆµÄÆÊÎö±¨¸æ

SonicWallÐû²¼ÁË2021ÄêÉϰëÄêÍøÂçÌ¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þ¹¥»÷ÔÚ2021ÄêÉϰëÄêÊ®·Ö·Å×Ý£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾¼ì²âµ½µÄ¹¥»÷ʵÑéµÖ´ï3.047ÒڴΣ¬£¬£¬£¬£¬£¬£¬ Áè¼ÝÁË2020ÕûÄêµÄ¹¥»÷×ÜÊý¡£¡£¡£¡£ÃÀ¹ú¡¢Ó¢¹ú¡¢µÂ¹ú¡¢ÄϷǺͰÍÎ÷µÈ¹ú¼ÒÊÇÊÜÀÕË÷Èí¼þ¹¥»÷×îÑÏÖØµÄ¹ú¼Ò£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÃÀ¹úÊÜÓ°Ïì½Ï´óµÄµØÇøÊÇ·ðÂÞÀï´ïÖÝ£¬£¬£¬£¬£¬£¬£¬ÓÐ1.111Òڴι¥»÷ʵÑé¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÀÕË÷¹¥»÷×î³£¼ûµÄÄ¿µÄÊǽðÈÚ»ú¹¹ÒÔ¼°¹ú·ÀµÈÖ÷ÒªµÄÕþ¸®×éÖ¯£¬£¬£¬£¬£¬£¬£¬¶øÕë¶Ô½ÌÓýÐÐÒµµÄ¹¥»÷Ôò¼¤ÔöÁË615%¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.sonicwall.com/2021-cyber-threat-report/
6.DeepinstinctÐû²¼2021ÄêÖÐÍøÂçÍþÐ²Ì¬ÊÆÆÊÎö±¨¸æ

Deep InstinctÐû²¼ÁË2021ÄêÖÐÍøÂçÍþÐ²Ì¬ÊÆÆÊÎö±¨¸æ¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þÒ»Ö±ÊÇÕû¸ö2021ÄêµÄÖ÷µ¼Ç÷ÊÆ£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÖ÷ÒªÍþвΪSTOP(Djvu)¡¢RyukºÍSodinokibi(REvil)µÈ¡£¡£¡£¡£ÒøÐÐľÂí»î¶¯µÄÖ÷ÒªÍþвΪEmotetµÄ¼ÌÈÎÕߣ¬£¬£¬£¬£¬£¬£¬ÀýÈçRamnit¡¢QbotºÍIcedID¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Õë¶ÔColonial PipelineµÄ¹¥»÷³ÉΪȫÇòµÄ½¹µã£¬£¬£¬£¬£¬£¬£¬µ«ÕâÖ»Êǹ¥»÷Òªº¦»ù´¡ÉèÊ©µÄÖڶ๥»÷ʵÑéÖ®Ò»£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÔ¤¼ÆÕâÖÖ¹¥»÷Õ½ÂÔ½üÆÚÄÚ²»»á±¬·¢¸Ä±ä¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.deepinstinct.com/2021/07/22/2021-mid-year-cyber-threat-landscape-report/


¾©¹«Íø°²±¸11010802024551ºÅ