Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!

Æðµ×¹ú¼Ò¼¶APT×éÖ¯ £ºLazarus Group

ʱ¼ä£º2021-09-10 ×÷Õߣº»¢·ûÖÇ¿â

·ÖÏíµ½£º

Æðµ×¹ú¼Ò¼¶APT×éÖ¯ £ºLazarus Group

    ±¾ÎÄ2751×ÖÔĶÁÔ¼Ðè8ÖÓ

    ¹ú¼Ò¼¶APT£¨AdvancedPersistentThreat£¬ £¬£¬£¬£¬¸ß¼¶Ò»Á¬ÐÔÍþв£©×éÖ¯ÊÇÓйú¼ÒÅä¾°Ö§³ÖµÄ¶¥¼âºÚ¿ÍÍŻ £¬£¬£¬£¬×¨×¢ÓÚÕë¶ÔÌØ¶¨Ä¿µÄ¾ÙÐкã¾ÃµÄÒ»Á¬ÐÔÍøÂç¹¥»÷ ¡£¡£¡£¡£¡£¡£

    Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!Æìϵĸ߼¶ÍþвÑо¿ÍŶӺìÓêµÎ£¨RedDripTeam£©Ã¿Äê»áÐû²¼È«ÇòAPTÄ걨¡¾1¡¿¡¢Öб¨£¬ £¬£¬£¬£¬¶ÔÎôʱ¸÷´óAPTÍÅ»ïµÄÔ˶¯¾ÙÐÐÆÊÎö×Ü½á ¡£¡£¡£¡£¡£¡£

    »¢·ûÖÇ¿âÌØÔ¼Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÆìϺìÓêµÎÍŶÓ£¬ £¬£¬£¬£¬¿ªÉè“Æðµ×¹ú¼Ò¼¶APT×éÖ¯”À¸Ä¿£¬ £¬£¬£¬£¬Öð¸öÆðµ×È«Çò¸÷µØÇø»îÔ¾µÄÖ÷ÒªAPT×éÖ¯ ¡£¡£¡£¡£¡£¡£

    01

    LazarusGroup

    LazarusGroupÓÖÃûHIDDENCOBRA¡¢Zinc¡¢APT-C-26¡¢GuardiansofPeaceµÈ³Æºô£¬ £¬£¬£¬£¬ÊǶ«ÑǵØÇøÄ³¹ú×î»îÔ¾µÄAPT×éÖ¯Ö®Ò» ¡£¡£¡£¡£¡£¡£

Æðµ×¹ú¼Ò¼¶APT×éÖ¯ £ºLazarus Group

    Æä¹¥»÷Ä¿µÄÖ÷ÒªÒÔÇÔÈ¡×ʽðΪÖ÷£¬ £¬£¬£¬£¬¿°³ÆÈ«Çò½ðÈÚ»ú¹¹µÄ×î´óÍþв ¡£¡£¡£¡£¡£¡£

    Åä¾°

    LazarusGroupÓÖÃûHIDDENCOBRA£¨ÃÀ¹úÇ鱨½çÃüÃû£©¡¢Zinc¡¢APT-C-26¡¢GuardiansofPeaceµÈ³Æºô£¬ £¬£¬£¬£¬ÊǶ«ÑǵØÇøÄ³¹ú×î»îÔ¾µÄAPT×éÖ¯Ö®Ò»£¬ £¬£¬£¬£¬»ñµÃ¸Ã¹úÇ鱨²¿·ÖµÄ¶¦Á¦´ó¾ÙÖ§³Ö ¡£¡£¡£¡£¡£¡£

    ×Ô2009ÄêÒÔÀ´£¬ £¬£¬£¬£¬±»¹éÒòÓÚ¸Ã×éÖ¯µÄ¹¥»÷ÊÂÎñÊýĿѸËÙÔöÌí ¡£¡£¡£¡£¡£¡£ÌØÊâÔÚ2017Äêºó£¬ £¬£¬£¬£¬LazarusGroup¼Ó´óÁ˹¥»÷Ðж¯Á¦¶È£¬ £¬£¬£¬£¬×éÖ¯Á˶àÆðÓ°ÏìÖØ´óµÄ¹¥»÷ÊÂÎñ£¬ £¬£¬£¬£¬ÀýÈç¶Ô²¨À¼ºÍÄ«Î÷¸çÒøÐеĹ¥»÷¡¢WannaCry²¡¶¾±¬·¢ÒÔ¼°Õë¶ÔÃÀ¹ú³Ð°üÉ̵ÄÓã²æÊ½ÍøÂç´¹ÂÚÐж¯µÈ ¡£¡£¡£¡£¡£¡£

    Lazarus¹¥»÷Ä¿µÄÖ÷ÒªÒÔÇÔÈ¡×ʽðΪÖ÷£¬ £¬£¬£¬£¬Õë¶ÔÒøÐС¢±ÈÌØ±ÒÉúÒâËùµÈ½ðÈÚ»ú¹¹¼°Ð¡ÎÒ˽¼ÒʵÑ鶨Ïò¹¥»÷£¬ £¬£¬£¬£¬¿°³ÆÈ«Çò½ðÈÚ»ú¹¹µÄ×î´óÍþв ¡£¡£¡£¡£¡£¡£Æä´Î£¬ £¬£¬£¬£¬Lazarus»¹Õë¶Ôº½¿Õº½Ìì¡¢¹¤³Ì¡¢ÊÖÒÕ¡¢Õþ¸®¡¢Ã½Ìå¡¢µÈ»ú¹¹¼°ÆóÒµ¾ÙÐÐÉøÍ¸£¬ £¬£¬£¬£¬µÖ´ïÇÔÈ¡Ö÷Òª×ÊÁϼ°ÆÆËðÀÕË÷µÄÄ¿µÄ ¡£¡£¡£¡£¡£¡£

    ¹¥»÷ÌØµãÊֶΡ¢¹¤¾ß

    LazarusÔçÆÚ¶àʹÓý©Ê¬ÍøÂç¶ÔÄ¿µÄ¾ÙÐÐDDos¹¥»÷£»£» £» £»£»£»£»ÖкóÆÚÖ÷Òª¹¥»÷ÊÖ¶ÎתΪÓã²æ¹¥»÷¡¢Ë®¿Ó¹¥»÷¡¢¹©Ó¦Á´¹¥»÷µÈÊÖ·¨£¬ £¬£¬£¬£¬»¹Õë¶Ô²î±ðÖ°Ô±½ÓÄɶ¨ÏòÉç»á¹¤³Ìѧ¹¥»÷ ¡£¡£¡£¡£¡£¡£

    Lazarus×éÖ¯µÄ¹¥»÷Ö÷ÒªÓÐÒÔÏÂÌØµã£º

    ¹¥»÷ÖÜÆÚÆÕ±é½Ï³¤£¬ £¬£¬£¬£¬Í¨³£¾ÙÐнϳ¤Ê±¼äDZÔÚ£¬ £¬£¬£¬£¬²¢»»²î±ðÒªÁìÓÕʹĿµÄ±»ÈëÇÖ ¡£¡£¡£¡£¡£¡£

    Í¶µÝµÄÓÕ¶üÎļþ¾ßÓм«Ç¿µÄÒÉ»óÐÔºÍÓÕ»óÐÔ£¬ £¬£¬£¬£¬µ¼ÖÂÄ¿µÄÎÞ·¨Õç±ð ¡£¡£¡£¡£¡£¡£

    ¹¥»÷Àú³Ì»áʹÓÃÏµÍ³ÆÆËð»òÀÕË÷Ó¦ÓÃ×ÌÈÅÊÂÎñµÄÆÊÎö ¡£¡£¡£¡£¡£¡£

    Ê¹ÓÃSMBЭÒéÎó²î»òÏà¹ØÈ䳿¹¤¾ßʵÏÖºáÏòÒÆ¶¯ºÍÔØºÉͶ·Å ¡£¡£¡£¡£¡£¡£

    Ã¿´Î¹¥»÷ʹÓù¤¾ß¼¯µÄÔ´´úÂë¶¼»áÐ޸ģ¬ £¬£¬£¬£¬²¢ÇÒÍø°²¹«Ë¾Åû¶ºóÒ²»áʵʱÐÞ¸ÄÔ´´úÂë ¡£¡£¡£¡£¡£¡£

    £¨Ò»£©¹¥»÷ÊÖ¶Î

    1.Óã²æ¹¥»÷

    Í¨³£ÒÔÓʼþ¼Ð´ø¶ñÒâÎĵµ×÷ΪÓÕ¶ü£¬ £¬£¬£¬£¬³£¼ûÎļþÃûÌÃΪDOCX£¬ £¬£¬£¬£¬ºóÆÚÔöÌíÁËBMPÃûÌà ¡£¡£¡£¡£¡£¡£ÈëÇÖ·½·¨Ö÷ҪʹÓöñÒâºêÓëOffice³£¼ûÎó²î¡¢0dayÎó²î¡¢Ö²ÈëRATµÄÊÖ·¨ ¡£¡£¡£¡£¡£¡£

    2.Ë®¿Ó¹¥»÷

    Lazarusͨ³£Õë¶ÔƶÇîµÄ»òÇ·ÅµØÇøµÄС¹æÄ£ÒøÐнðÈÚ»ú¹¹Ê¹ÓÃË®¿Ó¹¥»÷£¬ £¬£¬£¬£¬ÕâÑù¾Í¿ÉÒÔÔÚ¶Ìʱ¼äÄÚ´ó¹æÄ£ÍµÈ¡×ʽ𠡣¡£¡£¡£¡£¡£

    2017Ä꣬ £¬£¬£¬£¬Lazarus¶Ô²¨À¼½ðÈÚî¿Ïµ»ú¹¹·¢¶¯Ë®¿Ó¹¥»÷£¬ £¬£¬£¬£¬ÔÚÍøÕ¾¹Ù·½ÍøÕ¾Ö²Èë¶ñÒâµÄJavaScriptÎó²î£¬ £¬£¬£¬£¬µ¼Ö²¨À¼¶à¼ÒÒøÐб»Ö²Èë¶ñÒâ³Ìʽ ¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ѬȾÁË31¸ö¹ú¼ÒµÄ104¸ö×éÖ¯£¬ £¬£¬£¬£¬´ó´ó¶¼Ä¿µÄÊÇλÓÚ²¨À¼¡¢ÖÇÀû¡¢ÃÀ¹ú¡¢Ä«Î÷¸çºÍ°ÍÎ÷µÄ½ðÈÚ»ú¹¹ ¡£¡£¡£¡£¡£¡£

    3.É繤¹¥»÷

    LazarusÉÆÓÚ½«É繤ÊÖÒÕÔËÓõ½¹¥»÷ÖÜÆÚÖУ¬ £¬£¬£¬£¬ÎÞÂÛÊÇͶµÝµÄÓÕ¶üÕÕ¾ÉÉí·Ýαװ£¬ £¬£¬£¬£¬¶¼ÁîÊܺ¦ÕßÎÞ·¨Õç±ð£¬ £¬£¬£¬£¬´Ó¶øµôÈëËüµÄÏÝÚåÖÐ ¡£¡£¡£¡£¡£¡£

    2020Äêʱ´ú£¬ £¬£¬£¬£¬LazarusÔÚÁìÓ¢ÍøÕ¾Î±×°ÕÐÆ¸¼ÓÃÜÇ®±ÒÊÂÇéÖ°Ô±²¢·¢ËͶñÒâÎĵµ£¬ £¬£¬£¬£¬Ö¼ÔÚ»ñȡƾ֤´Ó¶øÍµÈ¡Ä¿µÄ¼ÓÃÜÇ®±Ò ¡£¡£¡£¡£¡£¡£

    2021Ä꣬ £¬£¬£¬£¬LazarusGourpÒÔÍøÂçÇå¾²Ö°Ô±Éí·ÝDZÔÚÔÚTwitterÖУ¬ £¬£¬£¬£¬ËÅ»ú·¢ËÍǶÓжñÒâ´úÂëµÄ¹¤³ÌÎļþ¹¥»÷ÙÉÐÐÖ°Ô± ¡£¡£¡£¡£¡£¡£´ÓÕâЩ°¸Àý¿ÉÒÔ¿´³ö£¬ £¬£¬£¬£¬LazarusÕë¶ÔµÄÄ¿µÄÔ½À´Ô½Ã÷È·£¬ £¬£¬£¬£¬Ê¹ÓÃÊÖ·¨Ò²Ô½À´Ô½ÎÞаֱ½Ó ¡£¡£¡£¡£¡£¡£

    £¨¶þ£©¹¥»÷ʹÓù¤¾ß¼°ÊÖÒÕÌØÕ÷

    LazarusʹÓõÄÍøÂçÎäÆ÷ÖаüÀ¨´ó×Ú¶¨Öƹ¤¾ß£¬ £¬£¬£¬£¬²¢ÇÒʹÓôúÂëÓÐÐí¶àÏàËÆÖ®´¦ ¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£Ò»¶¨µØËµ£¬ £¬£¬£¬£¬ÕâЩÈí¼þÀ´×ÔÏàͬµÄ¿ª·¢Ö°Ô±£¬ £¬£¬£¬£¬¿ÉÒÔ˵Ã÷Lazarus±³ºóÓÐÎȹ̵ĴóÐÍ¿ª·¢ÍÅ¶Ó ¡£¡£¡£¡£¡£¡£

    LazarusÓµÓеĹ¥»÷ÄÜÁ¦ºÍ¹¤¾ß°üÀ¨DDoSbotnets¡¢keyloggers¡¢RATs¡¢wipermalware£¬ £¬£¬£¬£¬Ê¹ÓõĶñÒâ´úÂë°üÀ¨Destover¡¢DuuzerºÍHangmanµÈ ¡£¡£¡£¡£¡£¡£

    Í¨Ì«¹ýÎö¹¥»÷°¸Àý¿ÉÒÔ¿´³öLazarus¹¥»÷µÄÊÖÒÕÌØÕ÷£º

    1.ÉÆÓÚʹÓöàÖÖ¼ÓÃÜËã·¨£¬ £¬£¬£¬£¬°üÀ¨RC4£¬ £¬£¬£¬£¬AES£¬ £¬£¬£¬£¬SpritzµÈ±ê×¼Ëã·¨£¬ £¬£¬£¬£¬Ò²Ê¹ÓÃXOR¼°×Ô½ç˵×Ö·û±ä»»Ëã·¨ ¡£¡£¡£¡£¡£¡£

    2.Ö÷ҪʹÓÃÐéα½á¹¹µÄTLSЭÒ飬 £¬£¬£¬£¬Í¨¹ýÔÚSNIrecordÖÐдÈë°×ÓòÃûÀ´BypassIDS£¬ £¬£¬£¬£¬Ò²Ê¹ÓÃIRC¡¢HTTPЭÒé ¡£¡£¡£¡£¡£¡£

    3.ͨ¹ýÆÆËðMBR¡¢·ÖÇø±í»òÕßÏòÉÈÇøÐ´ÈëÀ¬»øÊý¾Ý´Ó¶øÆÆËðϵͳ ¡£¡£¡£¡£¡£¡£

    4.Æä¹¤¾ß°üÐí¶à×é¼þ¶¼°üÀ¨×Ôɾ³ý¾ç±¾

    5.TCPºóÃÅÖ§³ÖÊýÊ®¸öÏÂÁî

    ×ÅÃû¹¥»÷ÊÂÎñ

    £¨Ò»£©ÌØÂåÒÁºÍÆáºÚÊ×¶ûÐж¯

    2009ÄêÖÁ2012Ä꣬ £¬£¬£¬£¬LazarusGroupÕë¶Ôº«¹úÎä×°²½¶ÓºÍÕþ¸®Õö¿ªºã¾ÃÍøÂçÌØ¹¤Ðж¯£¬ £¬£¬£¬£¬´ËÔ˶¯ºó±»ÃüÃûΪ“ÌØÂåÒÁÐж¯”¡¾2¡¿ ¡£¡£¡£¡£¡£¡£2013Ä꣬ £¬£¬£¬£¬LazarusGroup¶Ôº«¹ú½ðÈÚÐÐÒµ¿ªÕ¹µÚ¶þ´Î¹¥»÷£¬ £¬£¬£¬£¬ºó±»³ÆÎª“ÆáºÚÊ×¶ûÐж¯”¡¾3¡¿ ¡£¡£¡£¡£¡£¡£ÕâÁ½´ÎÔ˶¯µÄÅû¶ʹµÃLazarusGroupÊ״γÉΪ¹«ÖÚ¹Ø×¢µÄ½¹µã ¡£¡£¡£¡£¡£¡£ÕâЩÔ˶¯Ê¹ÓõĶñÒâÈíÀàËÆÓÚWin32/Spy.Keydoor»òÕßWin64/Spy.Keydoor. ¡£¡£¡£¡£¡£¡£

    £¨¶þ£©Ë÷Äṫ˾¹¥»÷ÊÂÎñ

    2014£¬ £¬£¬£¬£¬Ë÷ÄáÓ°ÊÓÓéÀÖ¹«Ë¾Ðû²¼ÉÏÓ³¡¶´Ìɱ½ðijij¡·Ó°Ï·£¬ £¬£¬£¬£¬ÒýÆð¸Ã¹úÇ¿ÁÒ²»Âú ¡£¡£¡£¡£¡£¡£Ëæºó£¬ £¬£¬£¬£¬LazarusGroupÈëÇÖË÷Äᣬ £¬£¬£¬£¬¾ÙÐÐÁËÅê»÷ʽµÄÆÆË𣬠£¬£¬£¬£¬Ðí¶àÄÚ²¿ÎļþºÍÎļþ±»ÇÔÈ¡¡¢Ð¹Â¶»òɾ³ý¡¾4¡¿ ¡£¡£¡£¡£¡£¡£ËæºóµÄÁ½Ä꣬ £¬£¬£¬£¬¶à¼ÒÇå¾²¹«Ë¾¼ÓÈëÊӲ죬 £¬£¬£¬£¬×îÖÕͨ¹ýLazarusʹÓùýµÄ×Ôɾ³ýÎļþ¡¢TCPºóÃÅÖеÄÃûÌÃ×Ö·û´®¡¢¶¯Ì¬API¼ÓÔØÀý³Ì¡¢»ìÏýº¯ÊýÃûºÍʹÓÃÐéαTLSͨѶµÈһϵÁÐÖ¤¾Ý£¬ £¬£¬£¬£¬½«´ËǰÐí¶àÆð¹¥»÷ÊÂÎñÓëË÷Äá¹¥»÷ÊÂÎñÒ»Æð¹éÒòÖÁLazarus ¡£¡£¡£¡£¡£¡£

    £¨Èý£©SWIFTϵͳ͵ȡÃÀ½ð

    2016Ä꣬ £¬£¬£¬£¬LazarusGroupͨ¹ýAlreay¹¥»÷×é¼þ£¬ £¬£¬£¬£¬¸Ä¶¯SWIFTÈí¼þ£¬ £¬£¬£¬£¬Ê¹µÃÆäÄܹ»²Ù×÷ÒøÐÐÕ˺Åí§Òâ¾ÙÐÐתÕË£¬ £¬£¬£¬£¬ÇÔÈ¡ÃϼÓÀ­ÑëÐÐ8100ÍòÃÀÔª¡¾5¡¿ ¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ʹÓõÄ×Ôɨ³ýÎļþÓë¹¥»÷Ë÷Äṫ˾µÄÎļþÏàËÆ£¬ £¬£¬£¬£¬Òò´Ë¹éÒòÓÚLazarus ¡£¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬Õâ´Î¹¥»÷µÄÁ÷³ÌÓëÔçÄê¼äÔ½ÄÏ¡¢¶ò¹Ï¶à¶ûµÈ¶à¹úÒøÐб»µÁÊÂÎñ¹¥»÷Á÷³ÌÏàËÆ£¬ £¬£¬£¬£¬Ò²Í¬Ñù¹éÒòÓÚLazarus ¡£¡£¡£¡£¡£¡£

    £¨ËÄ£©Wannacryϯ¾íÈ«Çò

    2017Äê5Ô£¬ £¬£¬£¬£¬ÀÕË÷²¡¶¾“WannaCry”ѬȾÊÂÎñ±¬·¢£¬ £¬£¬£¬£¬È«Çò¹æÄ£½ü°Ù¸ö¹ú¼ÒÔâµ½´ó¹æÄ£ÍøÂç¹¥»÷¡¾6¡¿£¬ £¬£¬£¬£¬LazarusʹÓÃNSAй¶“ÓÀºãÖ®À¶”Îó²îÉ¢²¥ÀÕË÷²¡¶¾“WannaCry”£¬ £¬£¬£¬£¬µ¼ÖÂÄ¿µÄµçÄÔÖдó×ÚÎļþ±»¼ÓÃÜ£¬ £¬£¬£¬£¬²¢±»ÒªÇóÖ§¸¶±ÈÌØ±ÒÒÔ½âÃÜÎļþ ¡£¡£¡£¡£¡£¡£¹È¸èÍŶÓÔÚWannaCry´úÂëÖз¢Ã÷ÁËÀ´×ÔLazarus¼¯Íźڿ͹¤¾ßµÄÏàËÆÐÔ£¬ £¬£¬£¬£¬Òò´Ë¹éÒòLazarus ¡£¡£¡£¡£¡£¡£2018ÄêÖÁ2020Äêʱ´ú£¬ £¬£¬£¬£¬ÃÀ¹ú˾·¨²¿ÆðËß3ÃûLazarus³ÉÔ± ¡£¡£¡£¡£¡£¡£

    £¨Î壩LazarusÈëÇÖÓ¡¶ÈºËµçϵͳ

    2019Äê9Ô£¬ £¬£¬£¬£¬LazarusÀÖ³ÉÈëÇÖÓ¡¶ÈºËµçϵͳ£¬ £¬£¬£¬£¬ÓÉ´ËÓ¡¶È½ôÆÈ¹Ø±ÕÁËÒ»×ùºËµçÕ¾¡¾7¡¿ ¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷Ö÷ÒªÕë¶ÔÓ¡¶ÈÔ­×ÓÄÜÖÎÀíίԱ»á³ÉԱʹÓÃÓã²æÊ½¹¥»÷£¬ £¬£¬£¬£¬Ã°³äÓ¡¶ÈºËÄÜ×éÖ¯·¢ËÍÓÕ¶üµç×ÓÓʼþ£¬ £¬£¬£¬£¬½«´øÖøÃûΪ“Dtrack”µÄ¶ñÒâÈí¼þµÄÁ´½Ó¸½ÔÚÓʼþÖУ¬ £¬£¬£¬£¬Ò»µ©µã»÷Á´½Ó»á½«¶ñÒâÈí¼þÏÂÔØµ½ÅÌËã»úÉÏ ¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ʹÓõĶñÒâÈí¼þ“DTrack”Óë“ÆáºÚÊ×¶û”ÓÐÖî¶àÏàËÆÖ®´¦£¬ £¬£¬£¬£¬ÊµÏÖ¹¦Ð§µÄ·½·¨Óë´úÂë±àÐ´Æø¸Å¾ùÏàͬ£¬ £¬£¬£¬£¬¹éÒò´ËÊÂÎñ³ö×ÔLazarusÖ®ÊÖ ¡£¡£¡£¡£¡£¡£

    £¨Áù£©Õë¶ÔÎó²îÑо¿Ö°Ô±·¢¶¯¶¨Ïò¹¥»÷

    2021Äê1Ô£¬ £¬£¬£¬£¬¹È¸èÇå¾²ÍŶӷ¢Ã÷Lazarusºã¾ÃDZÔÚÔÚTwitter¡¢LinkedIn¡¢TelegramµÈÉ罻ýÌ壬 £¬£¬£¬£¬Ê¹ÓÃÐéαÉí·Ýαװ³É»îÔ¾µÄÒµÄÚÎó²îÑо¿×¨¼Ò£¬ £¬£¬£¬£¬²©È¡ÒµÄÚÐÅÍдӶø¶ÔÆäËûÎó²îÑо¿Ö°Ô±·¢¶¯0day¹¥»÷¡¾8¡¿ ¡£¡£¡£¡£¡£¡£ÒÔºó¿ÉÒÔ¿´³öLazarusÏÖʵÉÏÊÇÏëÇÔÈ¡¸ß¼ÛÖµµÄ0DayÎó²îÐÅÏ¢£¬ £¬£¬£¬£¬´Ó¶ø·´Ó¦³öÆä¿ª·¢ÍøÂçÎäÆ÷µÄÖ°Ô±µÄ¿ÉÄÜÒѾ­“ǭ¿֮¼¼” ¡£¡£¡£¡£¡£¡£

    ×ܽá

    Lazarus¹¥»÷Ö÷ҪĿµÄÒÔÇÔÈ¡×ʽðºÍʵÏÖÕþÖÎÄ¿µÄΪÆðµã£¬ £¬£¬£¬£¬ÎÞÂÛÊÇÔÚÍøÂçÎäÆ÷·½ÃæºÍ¹¥»÷Êֶη½Ãæ¶¼ÄÜ¿´³ö¸Ã¹úÍø¾üµÄʵÁ¦ ¡£¡£¡£¡£¡£¡£

    Ëæ×Źú¼Ê¶ÔLazarusµÄÊÖ¶ÎÔ½À´Ô½Ã÷Îú£¬ £¬£¬£¬£¬Æä¹¥»÷µÄÄѶÈÒ²»áÖð½¥¼Ó´ó£¬ £¬£¬£¬£¬Î´À´Lazarus»áºã¾Ãêé0dayÎó²îµÈÇ鱨×ÊÁÏ£¬ £¬£¬£¬£¬Ò»Ö±À©³äÆä¾üÆ÷¿â£¬ £¬£¬£¬£¬´Ó¶øÌáÉýÎäÆ÷´¢±¸ÄÜÁ¦ ¡£¡£¡£¡£¡£¡£

    ×¢½â

    https://ti.qianxin.com/uploads/2021/02/08/dd941ecf98c7cb9bf0111a8416131aa1.pdf

    https://www.theguardian.com/world/2009/jul/08/south-korea-cyber-attack

    https://www.symantec.com/connect/blogs/four-years-darkseoul-cyberattacks-against-south-korea-continue-anniversary-korean-war

    https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Report.pdf

    https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07180244/Lazarus_Under_The_Hood_PDF_final.pdf

    https://www.dropbox.com/s/hpr9fas9xbzo2uz/WhitepaperWannaCryRansomware.pdf

    https://www.teiss.co.uk/nuclear-power-plant-dtrack-malware/

    https://blog.google/threat-analysis-group/update-campaign-targeting-security-researchers/

    ¹ØÓÚ×÷Õß

    Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ºìÓêµÎÍŶӣ¨RedDripTeam£¬ £¬£¬£¬£¬@RedDrip7£©£¬ £¬£¬£¬£¬ÒÀÍÐÈ«ÇòÁìÏȵÄÇå¾²´óÊý¾ÝÄÜÁ¦¡¢¶àά¶È¶àȪԴµÄÇå¾²Êý¾ÝºÍרҵÆÊÎöʦµÄ¸»ºñÂÄÀú£¬ £¬£¬£¬£¬×Ô2015ÄêÒ»Á¬·¢Ã÷¶à¸ö°üÀ¨º£Á«»¨ÔÚÄÚµÄAPT×éÖ¯ÔÚÖйú¾³Äڵĺã¾ÃÔ˶¯£¬ £¬£¬£¬£¬²¢Ðû²¼º£ÄÚÊ׸ö×éÖ¯²ãÃæµÄAPTÊÂÎñ½ÒÆÆ±¨¸æ£¬ £¬£¬£¬£¬¿ª´´Á˺£ÄÚAPT¹¥»÷Àà¸ß¼¶Íþвϵͳ»¯½ÒÆÆµÄÏÈºÓ ¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬ £¬£¬£¬£¬Ò»Á¬¸ú×ÙÆÊÎöµÄÖ÷ÒªAPTÍÅ»ïÁè¼Ý46¸ö£¬ £¬£¬£¬£¬×ÔÁ¦·¢Ã÷APT×éÖ¯13¸ö£¬ £¬£¬£¬£¬Ò»Á¬Ðû²¼APT×éÖ¯µÄ¸ú×Ù±¨¸æÁè¼Ý90ƪ£¬ £¬£¬£¬£¬°´ÆÚÊä³ö°ëÄêºÍÕûÄêÈ«ÇòAPTÔ˶¯×ÛºÏÐÔÆÊÎö±¨¸æ ¡£¡£¡£¡£¡£¡£

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015ÍøÂçÇ徲ЧÀÍÈÈÏß

95015ÍøÂçÇ徲ЧÀÍÈÈÏß

ɨһɨ¹Ø×¢

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! ÔÚÏ߿ͷþ Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015

Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ

ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿