ʱ¼ä£º2021-09-10

±¾ÎÄ2751×ÖÔĶÁÔ¼Ðè8ÖÓ
¹ú¼Ò¼¶APT£¨AdvancedPersistentThreat£¬£¬£¬£¬£¬¸ß¼¶Ò»Á¬ÐÔÍþв£©×éÖ¯ÊÇÓйú¼ÒÅä¾°Ö§³ÖµÄ¶¥¼âºÚ¿ÍÍŻ£¬£¬£¬£¬×¨×¢ÓÚÕë¶ÔÌØ¶¨Ä¿µÄ¾ÙÐкã¾ÃµÄÒ»Á¬ÐÔÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£
Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!Æìϵĸ߼¶ÍþвÑо¿ÍŶӺìÓêµÎ£¨RedDripTeam£©Ã¿Äê»áÐû²¼È«ÇòAPTÄ걨¡¾1¡¿¡¢Öб¨£¬£¬£¬£¬£¬¶ÔÎôʱ¸÷´óAPTÍÅ»ïµÄÔ˶¯¾ÙÐÐÆÊÎö×ܽᡣ¡£¡£¡£¡£¡£
»¢·ûÖÇ¿âÌØÔ¼Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÆìϺìÓêµÎÍŶӣ¬£¬£¬£¬£¬¿ªÉè“Æðµ×¹ú¼Ò¼¶APT×éÖ¯”À¸Ä¿£¬£¬£¬£¬£¬Öð¸öÆðµ×È«Çò¸÷µØÇø»îÔ¾µÄÖ÷ÒªAPT×éÖ¯¡£¡£¡£¡£¡£¡£
01
LazarusGroup
LazarusGroupÓÖÃûHIDDENCOBRA¡¢Zinc¡¢APT-C-26¡¢GuardiansofPeaceµÈ³Æºô£¬£¬£¬£¬£¬ÊǶ«ÑǵØÇøÄ³¹ú×î»îÔ¾µÄAPT×éÖ¯Ö®Ò»¡£¡£¡£¡£¡£¡£

Æä¹¥»÷Ä¿µÄÖ÷ÒªÒÔÇÔÈ¡×ʽðΪÖ÷£¬£¬£¬£¬£¬¿°³ÆÈ«Çò½ðÈÚ»ú¹¹µÄ×î´óÍþв¡£¡£¡£¡£¡£¡£
Åä¾°
LazarusGroupÓÖÃûHIDDENCOBRA£¨ÃÀ¹úÇ鱨½çÃüÃû£©¡¢Zinc¡¢APT-C-26¡¢GuardiansofPeaceµÈ³Æºô£¬£¬£¬£¬£¬ÊǶ«ÑǵØÇøÄ³¹ú×î»îÔ¾µÄAPT×éÖ¯Ö®Ò»£¬£¬£¬£¬£¬»ñµÃ¸Ã¹úÇ鱨²¿·ÖµÄ¶¦Á¦´ó¾ÙÖ§³Ö¡£¡£¡£¡£¡£¡£
×Ô2009ÄêÒÔÀ´£¬£¬£¬£¬£¬±»¹éÒòÓÚ¸Ã×éÖ¯µÄ¹¥»÷ÊÂÎñÊýĿѸËÙÔöÌí¡£¡£¡£¡£¡£¡£ÌØÊâÔÚ2017Äêºó£¬£¬£¬£¬£¬LazarusGroup¼Ó´óÁ˹¥»÷Ðж¯Á¦¶È£¬£¬£¬£¬£¬×éÖ¯Á˶àÆðÓ°ÏìÖØ´óµÄ¹¥»÷ÊÂÎñ£¬£¬£¬£¬£¬ÀýÈç¶Ô²¨À¼ºÍÄ«Î÷¸çÒøÐеĹ¥»÷¡¢WannaCry²¡¶¾±¬·¢ÒÔ¼°Õë¶ÔÃÀ¹ú³Ð°üÉ̵ÄÓã²æÊ½ÍøÂç´¹ÂÚÐж¯µÈ¡£¡£¡£¡£¡£¡£
Lazarus¹¥»÷Ä¿µÄÖ÷ÒªÒÔÇÔÈ¡×ʽðΪÖ÷£¬£¬£¬£¬£¬Õë¶ÔÒøÐС¢±ÈÌØ±ÒÉúÒâËùµÈ½ðÈÚ»ú¹¹¼°Ð¡ÎÒ˽¼ÒʵÑ鶨Ïò¹¥»÷£¬£¬£¬£¬£¬¿°³ÆÈ«Çò½ðÈÚ»ú¹¹µÄ×î´óÍþв¡£¡£¡£¡£¡£¡£Æä´Î£¬£¬£¬£¬£¬Lazarus»¹Õë¶Ôº½¿Õº½Ìì¡¢¹¤³Ì¡¢ÊÖÒÕ¡¢Õþ¸®¡¢Ã½Ìå¡¢µÈ»ú¹¹¼°ÆóÒµ¾ÙÐÐÉøÍ¸£¬£¬£¬£¬£¬µÖ´ïÇÔÈ¡Ö÷Òª×ÊÁϼ°ÆÆËðÀÕË÷µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£
¹¥»÷ÌØµãÊֶΡ¢¹¤¾ß
LazarusÔçÆÚ¶àʹÓý©Ê¬ÍøÂç¶ÔÄ¿µÄ¾ÙÐÐDDos¹¥»÷£»£»£»£»£»£»£»ÖкóÆÚÖ÷Òª¹¥»÷ÊÖ¶ÎתΪÓã²æ¹¥»÷¡¢Ë®¿Ó¹¥»÷¡¢¹©Ó¦Á´¹¥»÷µÈÊÖ·¨£¬£¬£¬£¬£¬»¹Õë¶Ô²î±ðÖ°Ô±½ÓÄɶ¨ÏòÉç»á¹¤³Ìѧ¹¥»÷¡£¡£¡£¡£¡£¡£
Lazarus×éÖ¯µÄ¹¥»÷Ö÷ÒªÓÐÒÔÏÂÌØµã£º
¹¥»÷ÖÜÆÚÆÕ±é½Ï³¤£¬£¬£¬£¬£¬Í¨³£¾ÙÐнϳ¤Ê±¼äDZÔÚ£¬£¬£¬£¬£¬²¢»»²î±ðÒªÁìÓÕʹĿµÄ±»ÈëÇÖ¡£¡£¡£¡£¡£¡£
ͶµÝµÄÓÕ¶üÎļþ¾ßÓм«Ç¿µÄÒÉ»óÐÔºÍÓÕ»óÐÔ£¬£¬£¬£¬£¬µ¼ÖÂÄ¿µÄÎÞ·¨Õç±ð¡£¡£¡£¡£¡£¡£
¹¥»÷Àú³Ì»áʹÓÃÏµÍ³ÆÆËð»òÀÕË÷Ó¦ÓÃ×ÌÈÅÊÂÎñµÄÆÊÎö¡£¡£¡£¡£¡£¡£
ʹÓÃSMBÐÒéÎó²î»òÏà¹ØÈ䳿¹¤¾ßʵÏÖºáÏòÒÆ¶¯ºÍÔØºÉͶ·Å¡£¡£¡£¡£¡£¡£
ÿ´Î¹¥»÷ʹÓù¤¾ß¼¯µÄÔ´´úÂë¶¼»áÐ޸쬣¬£¬£¬£¬²¢ÇÒÍø°²¹«Ë¾Åû¶ºóÒ²»áʵʱÐÞ¸ÄÔ´´úÂë¡£¡£¡£¡£¡£¡£
£¨Ò»£©¹¥»÷ÊÖ¶Î
1.Óã²æ¹¥»÷
ͨ³£ÒÔÓʼþ¼Ð´ø¶ñÒâÎĵµ×÷ΪÓÕ¶ü£¬£¬£¬£¬£¬³£¼ûÎļþÃûÌÃΪDOCX£¬£¬£¬£¬£¬ºóÆÚÔöÌíÁËBMPÃûÌᣡ£¡£¡£¡£¡£ÈëÇÖ·½·¨Ö÷ҪʹÓöñÒâºêÓëOffice³£¼ûÎó²î¡¢0dayÎó²î¡¢Ö²ÈëRATµÄÊÖ·¨¡£¡£¡£¡£¡£¡£
2.Ë®¿Ó¹¥»÷
Lazarusͨ³£Õë¶ÔƶÇîµÄ»òÇ·ÅµØÇøµÄС¹æÄ£ÒøÐнðÈÚ»ú¹¹Ê¹ÓÃË®¿Ó¹¥»÷£¬£¬£¬£¬£¬ÕâÑù¾Í¿ÉÒÔÔÚ¶Ìʱ¼äÄÚ´ó¹æÄ£ÍµÈ¡×ʽ𡣡£¡£¡£¡£¡£
2017Ä꣬£¬£¬£¬£¬Lazarus¶Ô²¨À¼½ðÈÚî¿Ïµ»ú¹¹·¢¶¯Ë®¿Ó¹¥»÷£¬£¬£¬£¬£¬ÔÚÍøÕ¾¹Ù·½ÍøÕ¾Ö²Èë¶ñÒâµÄJavaScriptÎó²î£¬£¬£¬£¬£¬µ¼Ö²¨À¼¶à¼ÒÒøÐб»Ö²Èë¶ñÒâ³Ìʽ¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ѬȾÁË31¸ö¹ú¼ÒµÄ104¸ö×éÖ¯£¬£¬£¬£¬£¬´ó´ó¶¼Ä¿µÄÊÇλÓÚ²¨À¼¡¢ÖÇÀû¡¢ÃÀ¹ú¡¢Ä«Î÷¸çºÍ°ÍÎ÷µÄ½ðÈÚ»ú¹¹¡£¡£¡£¡£¡£¡£
3.É繤¹¥»÷
LazarusÉÆÓÚ½«É繤ÊÖÒÕÔËÓõ½¹¥»÷ÖÜÆÚÖУ¬£¬£¬£¬£¬ÎÞÂÛÊÇͶµÝµÄÓÕ¶üÕÕ¾ÉÉí·Ýαװ£¬£¬£¬£¬£¬¶¼ÁîÊܺ¦ÕßÎÞ·¨Õç±ð£¬£¬£¬£¬£¬´Ó¶øµôÈëËüµÄÏÝÚåÖС£¡£¡£¡£¡£¡£
2020Äêʱ´ú£¬£¬£¬£¬£¬LazarusÔÚÁìÓ¢ÍøÕ¾Î±×°ÕÐÆ¸¼ÓÃÜÇ®±ÒÊÂÇéÖ°Ô±²¢·¢ËͶñÒâÎĵµ£¬£¬£¬£¬£¬Ö¼ÔÚ»ñȡƾ֤´Ó¶øÍµÈ¡Ä¿µÄ¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£
2021Ä꣬£¬£¬£¬£¬LazarusGourpÒÔÍøÂçÇå¾²Ö°Ô±Éí·ÝDZÔÚÔÚTwitterÖУ¬£¬£¬£¬£¬ËÅ»ú·¢ËÍǶÓжñÒâ´úÂëµÄ¹¤³ÌÎļþ¹¥»÷ÙÉÐÐÖ°Ô±¡£¡£¡£¡£¡£¡£´ÓÕâЩ°¸Àý¿ÉÒÔ¿´³ö£¬£¬£¬£¬£¬LazarusÕë¶ÔµÄÄ¿µÄÔ½À´Ô½Ã÷È·£¬£¬£¬£¬£¬Ê¹ÓÃÊÖ·¨Ò²Ô½À´Ô½ÎÞаֱ½Ó¡£¡£¡£¡£¡£¡£
£¨¶þ£©¹¥»÷ʹÓù¤¾ß¼°ÊÖÒÕÌØÕ÷
LazarusʹÓõÄÍøÂçÎäÆ÷ÖаüÀ¨´ó×Ú¶¨Öƹ¤¾ß£¬£¬£¬£¬£¬²¢ÇÒʹÓôúÂëÓÐÐí¶àÏàËÆÖ®´¦¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£Ò»¶¨µØËµ£¬£¬£¬£¬£¬ÕâЩÈí¼þÀ´×ÔÏàͬµÄ¿ª·¢Ö°Ô±£¬£¬£¬£¬£¬¿ÉÒÔ˵Ã÷Lazarus±³ºóÓÐÎȹ̵ĴóÐÍ¿ª·¢ÍŶӡ£¡£¡£¡£¡£¡£
LazarusÓµÓеĹ¥»÷ÄÜÁ¦ºÍ¹¤¾ß°üÀ¨DDoSbotnets¡¢keyloggers¡¢RATs¡¢wipermalware£¬£¬£¬£¬£¬Ê¹ÓõĶñÒâ´úÂë°üÀ¨Destover¡¢DuuzerºÍHangmanµÈ¡£¡£¡£¡£¡£¡£
̫ͨ¹ýÎö¹¥»÷°¸Àý¿ÉÒÔ¿´³öLazarus¹¥»÷µÄÊÖÒÕÌØÕ÷£º
1.ÉÆÓÚʹÓöàÖÖ¼ÓÃÜËã·¨£¬£¬£¬£¬£¬°üÀ¨RC4£¬£¬£¬£¬£¬AES£¬£¬£¬£¬£¬SpritzµÈ±ê×¼Ëã·¨£¬£¬£¬£¬£¬Ò²Ê¹ÓÃXOR¼°×Ô½ç˵×Ö·û±ä»»Ëã·¨¡£¡£¡£¡£¡£¡£
2.Ö÷ҪʹÓÃÐéα½á¹¹µÄTLSÐÒ飬£¬£¬£¬£¬Í¨¹ýÔÚSNIrecordÖÐдÈë°×ÓòÃûÀ´BypassIDS£¬£¬£¬£¬£¬Ò²Ê¹ÓÃIRC¡¢HTTPÐÒé¡£¡£¡£¡£¡£¡£
3.ͨ¹ýÆÆËðMBR¡¢·ÖÇø±í»òÕßÏòÉÈÇøÐ´ÈëÀ¬»øÊý¾Ý´Ó¶øÆÆËðϵͳ¡£¡£¡£¡£¡£¡£
4.Æä¹¤¾ß°üÐí¶à×é¼þ¶¼°üÀ¨×Ôɾ³ý¾ç±¾
5.TCPºóÃÅÖ§³ÖÊýÊ®¸öÏÂÁî
×ÅÃû¹¥»÷ÊÂÎñ
£¨Ò»£©ÌØÂåÒÁºÍÆáºÚÊ×¶ûÐж¯
2009ÄêÖÁ2012Ä꣬£¬£¬£¬£¬LazarusGroupÕë¶Ôº«¹úÎä×°²½¶ÓºÍÕþ¸®Õö¿ªºã¾ÃÍøÂçÌØ¹¤Ðж¯£¬£¬£¬£¬£¬´ËÔ˶¯ºó±»ÃüÃûΪ“ÌØÂåÒÁÐж¯”¡¾2¡¿¡£¡£¡£¡£¡£¡£2013Ä꣬£¬£¬£¬£¬LazarusGroup¶Ôº«¹ú½ðÈÚÐÐÒµ¿ªÕ¹µÚ¶þ´Î¹¥»÷£¬£¬£¬£¬£¬ºó±»³ÆÎª“ÆáºÚÊ×¶ûÐж¯”¡¾3¡¿¡£¡£¡£¡£¡£¡£ÕâÁ½´ÎÔ˶¯µÄÅû¶ʹµÃLazarusGroupÊ״γÉΪ¹«ÖÚ¹Ø×¢µÄ½¹µã¡£¡£¡£¡£¡£¡£ÕâЩÔ˶¯Ê¹ÓõĶñÒâÈíÀàËÆÓÚWin32/Spy.Keydoor»òÕßWin64/Spy.Keydoor.¡£¡£¡£¡£¡£¡£
£¨¶þ£©Ë÷Äṫ˾¹¥»÷ÊÂÎñ
2014£¬£¬£¬£¬£¬Ë÷ÄáÓ°ÊÓÓéÀÖ¹«Ë¾Ðû²¼ÉÏÓ³¡¶´Ìɱ½ðijij¡·Ó°Ï·£¬£¬£¬£¬£¬ÒýÆð¸Ã¹úÇ¿ÁÒ²»Âú¡£¡£¡£¡£¡£¡£Ëæºó£¬£¬£¬£¬£¬LazarusGroupÈëÇÖË÷Äᣬ£¬£¬£¬£¬¾ÙÐÐÁËÅê»÷ʽµÄÆÆË𣬣¬£¬£¬£¬Ðí¶àÄÚ²¿ÎļþºÍÎļþ±»ÇÔÈ¡¡¢Ð¹Â¶»òɾ³ý¡¾4¡¿¡£¡£¡£¡£¡£¡£ËæºóµÄÁ½Ä꣬£¬£¬£¬£¬¶à¼ÒÇå¾²¹«Ë¾¼ÓÈëÊӲ죬£¬£¬£¬£¬×îÖÕͨ¹ýLazarusʹÓùýµÄ×Ôɾ³ýÎļþ¡¢TCPºóÃÅÖеÄÃûÌÃ×Ö·û´®¡¢¶¯Ì¬API¼ÓÔØÀý³Ì¡¢»ìÏýº¯ÊýÃûºÍʹÓÃÐéαTLSͨѶµÈһϵÁÐÖ¤¾Ý£¬£¬£¬£¬£¬½«´ËǰÐí¶àÆð¹¥»÷ÊÂÎñÓëË÷Äá¹¥»÷ÊÂÎñÒ»Æð¹éÒòÖÁLazarus¡£¡£¡£¡£¡£¡£
£¨Èý£©SWIFTϵͳ͵ȡÃÀ½ð
2016Ä꣬£¬£¬£¬£¬LazarusGroupͨ¹ýAlreay¹¥»÷×é¼þ£¬£¬£¬£¬£¬¸Ä¶¯SWIFTÈí¼þ£¬£¬£¬£¬£¬Ê¹µÃÆäÄܹ»²Ù×÷ÒøÐÐÕ˺Åí§Òâ¾ÙÐÐתÕË£¬£¬£¬£¬£¬ÇÔÈ¡ÃϼÓÀÑëÐÐ8100ÍòÃÀÔª¡¾5¡¿¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ʹÓõÄ×Ôɨ³ýÎļþÓë¹¥»÷Ë÷Äṫ˾µÄÎļþÏàËÆ£¬£¬£¬£¬£¬Òò´Ë¹éÒòÓÚLazarus¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Õâ´Î¹¥»÷µÄÁ÷³ÌÓëÔçÄê¼äÔ½ÄÏ¡¢¶ò¹Ï¶à¶ûµÈ¶à¹úÒøÐб»µÁÊÂÎñ¹¥»÷Á÷³ÌÏàËÆ£¬£¬£¬£¬£¬Ò²Í¬Ñù¹éÒòÓÚLazarus¡£¡£¡£¡£¡£¡£
£¨ËÄ£©Wannacryϯ¾íÈ«Çò
2017Äê5Ô£¬£¬£¬£¬£¬ÀÕË÷²¡¶¾“WannaCry”ѬȾÊÂÎñ±¬·¢£¬£¬£¬£¬£¬È«Çò¹æÄ£½ü°Ù¸ö¹ú¼ÒÔâµ½´ó¹æÄ£ÍøÂç¹¥»÷¡¾6¡¿£¬£¬£¬£¬£¬LazarusʹÓÃNSAй¶“ÓÀºãÖ®À¶”Îó²îÉ¢²¥ÀÕË÷²¡¶¾“WannaCry”£¬£¬£¬£¬£¬µ¼ÖÂÄ¿µÄµçÄÔÖдó×ÚÎļþ±»¼ÓÃÜ£¬£¬£¬£¬£¬²¢±»ÒªÇóÖ§¸¶±ÈÌØ±ÒÒÔ½âÃÜÎļþ¡£¡£¡£¡£¡£¡£¹È¸èÍŶÓÔÚWannaCry´úÂëÖз¢Ã÷ÁËÀ´×ÔLazarus¼¯Íźڿ͹¤¾ßµÄÏàËÆÐÔ£¬£¬£¬£¬£¬Òò´Ë¹éÒòLazarus¡£¡£¡£¡£¡£¡£2018ÄêÖÁ2020Äêʱ´ú£¬£¬£¬£¬£¬ÃÀ¹ú˾·¨²¿ÆðËß3ÃûLazarus³ÉÔ±¡£¡£¡£¡£¡£¡£
£¨Î壩LazarusÈëÇÖÓ¡¶ÈºËµçϵͳ
2019Äê9Ô£¬£¬£¬£¬£¬LazarusÀÖ³ÉÈëÇÖÓ¡¶ÈºËµçϵͳ£¬£¬£¬£¬£¬ÓÉ´ËÓ¡¶È½ôÆÈ¹Ø±ÕÁËÒ»×ùºËµçÕ¾¡¾7¡¿¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷Ö÷ÒªÕë¶ÔÓ¡¶ÈÔ×ÓÄÜÖÎÀíίԱ»á³ÉԱʹÓÃÓã²æÊ½¹¥»÷£¬£¬£¬£¬£¬Ã°³äÓ¡¶ÈºËÄÜ×éÖ¯·¢ËÍÓÕ¶üµç×ÓÓʼþ£¬£¬£¬£¬£¬½«´øÖøÃûΪ“Dtrack”µÄ¶ñÒâÈí¼þµÄÁ´½Ó¸½ÔÚÓʼþÖУ¬£¬£¬£¬£¬Ò»µ©µã»÷Á´½Ó»á½«¶ñÒâÈí¼þÏÂÔØµ½ÅÌËã»úÉÏ¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ʹÓõĶñÒâÈí¼þ“DTrack”Óë“ÆáºÚÊ×¶û”ÓÐÖî¶àÏàËÆÖ®´¦£¬£¬£¬£¬£¬ÊµÏÖ¹¦Ð§µÄ·½·¨Óë´úÂë±àÐ´Æø¸Å¾ùÏàͬ£¬£¬£¬£¬£¬¹éÒò´ËÊÂÎñ³ö×ÔLazarusÖ®ÊÖ¡£¡£¡£¡£¡£¡£
£¨Áù£©Õë¶ÔÎó²îÑо¿Ö°Ô±·¢¶¯¶¨Ïò¹¥»÷
2021Äê1Ô£¬£¬£¬£¬£¬¹È¸èÇå¾²ÍŶӷ¢Ã÷Lazarusºã¾ÃDZÔÚÔÚTwitter¡¢LinkedIn¡¢TelegramµÈÉ罻ýÌ壬£¬£¬£¬£¬Ê¹ÓÃÐéαÉí·Ýαװ³É»îÔ¾µÄÒµÄÚÎó²îÑо¿×¨¼Ò£¬£¬£¬£¬£¬²©È¡ÒµÄÚÐÅÍдӶø¶ÔÆäËûÎó²îÑо¿Ö°Ô±·¢¶¯0day¹¥»÷¡¾8¡¿¡£¡£¡£¡£¡£¡£ÒÔºó¿ÉÒÔ¿´³öLazarusÏÖʵÉÏÊÇÏëÇÔÈ¡¸ß¼ÛÖµµÄ0DayÎó²îÐÅÏ¢£¬£¬£¬£¬£¬´Ó¶ø·´Ó¦³öÆä¿ª·¢ÍøÂçÎäÆ÷µÄÖ°Ô±µÄ¿ÉÄÜÒѾ“Ç¿֮¼¼”¡£¡£¡£¡£¡£¡£
×ܽá
Lazarus¹¥»÷Ö÷ҪĿµÄÒÔÇÔÈ¡×ʽðºÍʵÏÖÕþÖÎÄ¿µÄΪÆðµã£¬£¬£¬£¬£¬ÎÞÂÛÊÇÔÚÍøÂçÎäÆ÷·½ÃæºÍ¹¥»÷Êֶη½Ãæ¶¼ÄÜ¿´³ö¸Ã¹úÍø¾üµÄʵÁ¦¡£¡£¡£¡£¡£¡£
Ëæ×Źú¼Ê¶ÔLazarusµÄÊÖ¶ÎÔ½À´Ô½Ã÷Îú£¬£¬£¬£¬£¬Æä¹¥»÷µÄÄѶÈÒ²»áÖ𽥼Ӵ󣬣¬£¬£¬£¬Î´À´Lazarus»áºã¾Ãêé0dayÎó²îµÈÇ鱨×ÊÁÏ£¬£¬£¬£¬£¬Ò»Ö±À©³äÆä¾üÆ÷¿â£¬£¬£¬£¬£¬´Ó¶øÌáÉýÎäÆ÷´¢±¸ÄÜÁ¦¡£¡£¡£¡£¡£¡£
×¢½â
https://ti.qianxin.com/uploads/2021/02/08/dd941ecf98c7cb9bf0111a8416131aa1.pdf
https://www.theguardian.com/world/2009/jul/08/south-korea-cyber-attack
https://www.symantec.com/connect/blogs/four-years-darkseoul-cyberattacks-against-south-korea-continue-anniversary-korean-war
https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Report.pdf
https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07180244/Lazarus_Under_The_Hood_PDF_final.pdf
https://www.dropbox.com/s/hpr9fas9xbzo2uz/WhitepaperWannaCryRansomware.pdf
https://www.teiss.co.uk/nuclear-power-plant-dtrack-malware/
https://blog.google/threat-analysis-group/update-campaign-targeting-security-researchers/
¹ØÓÚ×÷Õß
Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ºìÓêµÎÍŶӣ¨RedDripTeam£¬£¬£¬£¬£¬@RedDrip7£©£¬£¬£¬£¬£¬ÒÀÍÐÈ«ÇòÁìÏȵÄÇå¾²´óÊý¾ÝÄÜÁ¦¡¢¶àά¶È¶àȪԴµÄÇå¾²Êý¾ÝºÍרҵÆÊÎöʦµÄ¸»ºñÂÄÀú£¬£¬£¬£¬£¬×Ô2015ÄêÒ»Á¬·¢Ã÷¶à¸ö°üÀ¨º£Á«»¨ÔÚÄÚµÄAPT×éÖ¯ÔÚÖйú¾³Äڵĺã¾ÃÔ˶¯£¬£¬£¬£¬£¬²¢Ðû²¼º£ÄÚÊ׸ö×éÖ¯²ãÃæµÄAPTÊÂÎñ½ÒÆÆ±¨¸æ£¬£¬£¬£¬£¬¿ª´´Á˺£ÄÚAPT¹¥»÷Àà¸ß¼¶Íþвϵͳ»¯½ÒÆÆµÄÏȺӡ£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬Ò»Á¬¸ú×ÙÆÊÎöµÄÖ÷ÒªAPTÍÅ»ïÁè¼Ý46¸ö£¬£¬£¬£¬£¬×ÔÁ¦·¢Ã÷APT×éÖ¯13¸ö£¬£¬£¬£¬£¬Ò»Á¬Ðû²¼APT×éÖ¯µÄ¸ú×Ù±¨¸æÁè¼Ý90ƪ£¬£¬£¬£¬£¬°´ÆÚÊä³ö°ëÄêºÍÕûÄêÈ«ÇòAPTÔ˶¯×ÛºÏÐÔÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£
ʱ¼ä£º2026-04-22
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-18
Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ
ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ