ʱ¼ä£º2021-09-23

±¾ÎÄ2915×ÖÔĶÁÔ¼Ðè8ÖÓ
¹ú¼Ò¼¶APT£¨AdvancedPersistentThreat£¬£¬£¬£¬£¬¸ß¼¶Ò»Á¬ÐÔÍþв£©×éÖ¯ÊÇÓйú¼ÒÅä¾°Ö§³ÖµÄ¶¥¼âºÚ¿ÍÍŻ£¬£¬£¬£¬×¨×¢ÓÚÕë¶ÔÌØ¶¨Ä¿µÄ¾ÙÐкã¾ÃµÄÒ»Á¬ÐÔÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£
Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!Æìϸ߼¶ÍþвÑо¿ÍŶӺìÓêµÎ£¨RedDripTeam£©Ã¿Äê»áÐû²¼È«ÇòAPTÄ걨¡¾1¡¿¡¢Öб¨£¬£¬£¬£¬£¬¶ÔÎôʱ¸÷´óAPTÍÅ»ïµÄÔ˶¯¾ÙÐÐÆÊÎö×ܽᡣ¡£¡£¡£¡£¡£¡£
»¢·ûÖÇ¿âÌØÔ¼Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÆìϺìÓêµÎÍŶӣ¬£¬£¬£¬£¬¿ªÉè“Æðµ×¹ú¼Ò¼¶APT×éÖ¯”À¸Ä¿£¬£¬£¬£¬£¬Öð¸öÆðµ×È«Çò¸÷µØÇø»îÔ¾µÄÖ÷ÒªAPT×éÖ¯¡£¡£¡£¡£¡£¡£¡£±¾ÆÚËø¶¨Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ºìÓêµÎÍŶÓÖØµã¼à¿ØµÄAPT×éÖ¯Turla¡£¡£¡£¡£¡£¡£¡£
02
Turla
TurlaÊÇרÃÅÕë¶ÔÕþ¸®µÄÖøÃû¹ú¼Ò¼¶ºÚ¿ÍÍŻ£¬£¬£¬£¬ÊôÓÚ¶«Å·Ä³¹úÇ鱨»ú¹¹¡£¡£¡£¡£¡£¡£¡£Æä¹¥»÷Ô˶¯Éæ¼°45¸ö¹ú¼Ò£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÍâ½»²¿·Ö¡¢Õþ¸®»ú¹¹¡¢¾üÊ»ú¹¹¡¢¿ÆÑлú¹¹µÈ×éÖ¯ÇÔÈ¡Ö÷ÒªÇ鱨¡£¡£¡£¡£¡£¡£¡£

Turla±»ÊÓΪÆù½ñΪֹ×îΪ¸ß¼¶µÄÍþв×éÖ¯Ö®Ò»£¬£¬£¬£¬£¬Òò¶øÊÇÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ºìÓêµÎÍŶÓÖØµã¼à¿ØµÄAPT×éÖ¯¡£¡£¡£¡£¡£¡£¡£
Åä¾°
Turla£¬£¬£¬£¬£¬Ò²±»³ÆÎªVenomousBear¡¢WaterbugUroboros£¬£¬£¬£¬£¬ÊÇÆù½ñΪֹ×îΪ¸ß¼¶µÄÍþв×éÖ¯Ö®Ò»£¬£¬£¬£¬£¬±»ÒÔΪÁ¥ÊôÓÚ¶«Å·Ä³¹úÇ鱨»ú¹¹¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯×îÔç¿ÉÒÔËÝÔ´µ½1996Ä꣬£¬£¬£¬£¬µ«ÔÚ2014Äê²Å±»¿¨°Í˹»ùʵÑéÊÒÊ״η¢Ã÷¡£¡£¡£¡£¡£¡£¡£
TurlaÊÇÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ºìÓêµÎÍŶÓÖØµã¼à¿ØµÄAPT×éÖ¯£¬£¬£¬£¬£¬ÄÚ²¿±àºÅΪAPT-Q-78¡£¡£¡£¡£¡£¡£¡£
Turla·¢¶¯µÄ¹¥»÷Ô˶¯Éæ¼°45¸ö¹ú¼Ò£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÍâ½»²¿·Ö¡¢Õþ¸®»ú¹¹¡¢¾üÊ»ú¹¹¡¢¿ÆÑлú¹¹µÈ×éÖ¯ÇÔÈ¡Ö÷ÒªÇ鱨£¬£¬£¬£¬£¬ÏÖÔÚÒÑÖªÊܺ¦µ¥Î»°üÀ¨ÃÀ¹úÖÐÑë˾Á¡¢µÂÍâÑó½»²¿¡¢ÈðÊ¿¾ü¹¤ÆóÒµRUAGµÈ¡£¡£¡£¡£¡£¡£¡£±ðµÄTurla»¹»áÕë¶Ô¶íÂÞ˹¾³ÄÚ±£´æÃÓÀÃÏÓÒɵÄÄ¿µÄ¾ÙÐй¥»÷¡£¡£¡£¡£¡£¡£¡£
¹¥»÷ÌØµãÊֶΡ¢¹¤¾ß
TurlaʹÓõĺóÃż°¹¤¾ßÖÖÀà·±¶àÇÒÄÑÒÔ×·×Ù¡£¡£¡£¡£¡£¡£¡£³£¼û¹¥»÷·½·¨°üÀ¨Óã²æ¹¥»÷¡¢WebÉøÍ¸ÈëÇÖ¡¢ÍøÂçÐ®ÖÆ¡¢Ë®¿Ó¹¥»÷¡¢UÅÌÉç½»¹¥»÷µÈ¡£¡£¡£¡£¡£¡£¡£
£¨Ò»£©¹¥»÷¹¤¾ß
TurlaÔÚÀúÊ·¹¥»÷Ô˶¯ÖÐʹÓù¤¾ß°üÀ¨Êý¾ÝÍøÂçºÍshellÖ´Ðй¦Ð§µÄºóÃÅ¡¢¾ßÓÐÔ¶¿ØºÍ¼à¿Ø¹¦Ð§µÄ×é¼þÒÔ¼°¿ªÔ´¹¤¾ßµÈ¡£¡£¡£¡£¡£¡£¡£
TurlaʹÓõĺóÃż°¹¤¾ßÖÖÀà·±¶àÇÒÄÑÒÔ×·×Ù£¬£¬£¬£¬£¬²»µ«ÓµÓи»ºñµÄ¾üÆ÷¿â»¹ÓµÓдó×Ú¿ª·¢Ö°Ô±£¬£¬£¬£¬£¬Äܹ»ÊµÊ±¾ÙÐÐÊÖÒÕ¸üС£¡£¡£¡£¡£¡£¡£
ÆäʹÓù¤¾ßÓÐÒÔÏÂÌØµã£º
1.TurlaÌᳫµÄÍøÂçÌØ¹¤Ô˶¯Ö÷ÒªÕë¶ÔWindowsƽ̨£¬£¬£¬£¬£¬Ê¹ÓõĶñÒâÈí¼þ½ÏÎªÖØ´ó£¬£¬£¬£¬£¬Äܹ»¿ª·¢¶àÓïÑÔÇéÐεÄ×ÔÑÐÌØÂíºÍ¿ªÔ´Ä¾Âí£¬£¬£¬£¬£¬ÆäÖв¿·ÖÌØÂí¸üеü´úÖÁ½ñÈÔ±»Ê¹Óᣡ£¡£¡£¡£¡£¡£
2.Turla×éÖ¯ÔÚ³¤ÆÚ»¯Éè¼Æ²¿·ÖʹÓöàÖÖ·½·¨£¬£¬£¬£¬£¬È罫PowershellµÄ¹¥»÷½¹µãÔØºÉ´¢ÓÚWindows×¢²á±íÏîÖС¢×¢²á×ÔÆôЧÀÍʵÏÖ³¤ÆÚ»¯µÈ·½·¨£¬£¬£¬£¬£¬ÌåÏÖÁËTurla¹¤¾ß¿ª·¢Ö°Ô±µÄÉè¼ÆÆ«ºÃ¡£¡£¡£¡£¡£¡£¡£
3.ΪÁ˰ü¹ÜÂ䵨¹¥»÷ÔØºÉÊÊÅä¶àÖÖPCÇéÐÎʹÆäÎȹÌÔËÐУ¬£¬£¬£¬£¬Turla×éÖ¯µÄ¹¥»÷×é¼þÖдó¶à±£´æÇéÐÎÊÊÅä¡¢¹¤¾ß̽²â¡¢Çå¾²»úÖÆÈÆ¹ýµÈÏà¹ØµÄ´úÂë¡£¡£¡£¡£¡£¡£¡£
4.TurlaÈëÇÖºóÔØºÉÔÚÔËÐпØÖÆÒÔ¼°ÒþÄäÐÔÉèÖ÷½Ãæ¾ù±£´æÏÔ×ÅÖ¸ÎÆÌØÕ÷£¬£¬£¬£¬£¬ÉÆÓÚÎļþÒþ²Ø¡¢¿ØÖÆÄ¾ÂíÔËÐÐÆµÂÊ¡¢Ê¹ÓÃRPC¼¯Èº¼àÌýµÈ¡£¡£¡£¡£¡£¡£¡£
5.Turla¹¥»÷×é¼þÖÐÔÚ¼ÓÃÜËã·¨µÄÑ¡Ôñ»ò±àд¡¢ÃÜÔ¿ÌìÉúµÈ·½ÃæÌåÏÖµÄÊ®·Ö¸öÐÔ»¯£¬£¬£¬£¬£¬²»Ê¹Óó£¼ûµÄ¹Å°å¼ÓÃÜËã·¨£¬£¬£¬£¬£¬¾ßÓÐ×Ô¼ºÆæÒìµÄ¼ÓÃÜÆø¸Å¡£¡£¡£¡£¡£¡£¡£
ÏÂ±íÆ¾Ö¤¹¥»÷½×¶Î½«ÆäʹÓúóÞÙÐÐÏÈÈÝ£¬£¬£¬£¬£¬°üÀ¨×ÔÑÐÌØÂíºÍ¿ªÔ´Ä¾Âí¡£¡£¡£¡£¡£¡£¡£

£¨¶þ£©¹¥»÷·½·¨
Turla×éÖ¯³£¼û¹¥»÷·½·¨°üÀ¨Óã²æ¹¥»÷¡¢WebÉøÍ¸ÈëÇÖ¡¢ÍøÂçÐ®ÖÆ¡¢Ë®¿Ó¹¥»÷¡¢UÅÌÉç½»¹¥»÷µÈ¡£¡£¡£¡£¡£¡£¡£
Turla³õʼ¹¥»÷ÉÆÓÚʹÓÃÉç»á¹¤³ÌѧÊֶεÄÓã²æ¹¥»÷ÒÔ¼°Ë®¿Ó¹¥»÷À´Í¶µÝ¹¥»÷ÔØºÉ£¬£¬£¬£¬£¬Ê¹ÓúóÃźóÍøÂçPCÊý¾Ý¾öÒéÊÇ·ñ¾ÙÐÐÏÂÒ»½×¶Î¹¥»÷¡£¡£¡£¡£¡£¡£¡£ºóÐø»áÅäºÏ¹¥»÷ÕßÔ¶³Ì½»»¥¾ÙÐоÖÓòÍøÄÚºáÒÆÉøÍ¸£¬£¬£¬£¬£¬Í¨¹ý¹ÜµÀÐÒéµÄRPCͨѶ¾ÙÐоÖÓòÍø¶Î¼àÌý¡£¡£¡£¡£¡£¡£¡£
1.Óã²æ¹¥»÷
TurlaÉÆÓÚʹÓüдø¶ñÒâ³ÌÐòÒÔ¼°Îó²îµÄÎļþͨ¹ýµç×ÓÓʼþ¾ÙÐÐͶµÝ£¬£¬£¬£¬£¬²¢Í¨¹ýÉç»á¹¤³ÌѧÓÕµ¼Óû§µã»÷Ö´ÐÐÎļþ¡£¡£¡£¡£¡£¡£¡£Óã²æ¹¥»÷ÔØºÉͨ³£ÎªÎó²îÎļþ¡¢ºêÎļþ¡¢Î±×°×°Öðü¡£¡£¡£¡£¡£¡£¡£
2.Ë®¿Ó¹¥»÷
TurlaÆ«ÐÒʹÓÃË®¿Ó¹¥»÷£¬£¬£¬£¬£¬ÒýÓÕÄ¿µÄÊܺ¦Õß»á¼ûÆäC2ЧÀÍÆ÷£¬£¬£¬£¬£¬Ö÷Òª·ÖΪÓÕ¶ü´¹ÂÚÒÔ¼°Îó²î¹¥»÷£¬£¬£¬£¬£¬ÆäÖд󲿷ÖÓÃÓÚÖÆÔìË®¿ÓµÄÍøÕ¾¾ùÊÇÕýµ±ÍøÕ¾¡£¡£¡£¡£¡£¡£¡£ÔçÆÚTurlaϲÐÒ¿÷ÍøÕ¾ÖÐǶÈëJavaScript´úÂ룬£¬£¬£¬£¬ÔÚÓû§»á¼ûµÄʱ¼äÖ´ÐУ¬£¬£¬£¬£¬Æä¹¦Ð§´ó¶àΪ»ñÈ¡ä¯ÀÀÆ÷µÄ²å¼þÁÐ±í£¬£¬£¬£¬£¬ÆÁÄ»Çø·ÖÂʵÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£½üÆÚ£¬£¬£¬£¬£¬TurlaµÄ¹¥»÷·½·¨¸üΪֱ½Ó£¬£¬£¬£¬£¬ÔÚ¾ÙÐÐÖ¸ÎÆÊ¶±ðºóÏ·¢¶ñÒâµÄAdobeFlash×°Öðü¡£¡£¡£¡£¡£¡£¡£
3.Êý×ÖÎÀÐǵçÊÓÏµÍ³Ð®ÖÆ
×Ô2007ÄêÒÔÀ´£¬£¬£¬£¬£¬TurlaʹÓÃÎÀÐÇͨѶÖйÌÓеÄÇ徲ȱÏÝ£¬£¬£¬£¬£¬Òþ²ØC2ЧÀÍÆ÷µÄλÖúͿØÖÆÖÐÐÄ¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÇãÏòÓÚÑ¡ÔñʹÓýöÁýÕÖ·ÇÖÞµØÇøµÄÎÀÐÇÌṩÉÌ¡£¡£¡£¡£¡£¡£¡£ÕâʹµÃ·ÇÖÞÒÔÍâ¹ú¼ÒµÄÑо¿Ö°Ô±¼«ÆäÄÑÒÔÊÓ²ìTurlaС×éµÄÔ˶¯£¬£¬£¬£¬£¬ÆäÖÐÎÀÐÇIP¼¯ÖÐÔÚ·ÇÖÞºÍÖж«µØÇø¡£¡£¡£¡£¡£¡£¡£
4.MITMÁ÷Á¿Ð®ÖÆÓë¸Ä¶¯
TurlaÔÚÒ»ÔÙÐж¯ÖУ¬£¬£¬£¬£¬¶¼»áͨ¹ý»ñÈ¡½¹µã·ÓɵÄȨÏÞÉõÖÁÐ®ÖÆÒªº¦½Úµã£¬£¬£¬£¬£¬²¢Í¨¹ýMITM£¨ÖÐÐÄÈ˹¥»÷£©À´Ð®ÖÆAdobeµÄÍøÂç¡£¡£¡£¡£¡£¡£¡£Ê¹µÃÓû§ÔÚÇëÇóÏÂÔØ×îеÄÈí¼þ¸üаüʱ£¬£¬£¬£¬£¬Ìæ»»Óû§µÄÏÂÔØÄÚÈÝ£¬£¬£¬£¬£¬ÔÚÓû§Î޸еÄÇéÐÎÏ£¬£¬£¬£¬£¬ÏÂÔØ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬²¢Íê³É¶ÔÄ¿µÄÖ÷»úµÄ¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£´ËÖÖ·½·¨ÐèÒª»ñÈ¡½¹µã·ÓɵÄȨÏÞ£¬£¬£¬£¬£¬ÉõÖÁÐèÒªÕë¶ÔÆóÒµ/Õþ¸®µÄÒªº¦½Úµã¾ÙÐÐÐ®ÖÆ¡£¡£¡£¡£¡£¡£¡£
×ÅÃû¹¥»÷ÊÂÎñ
£¨Ò»£©MoonlightMazeÔ˶¯
MoonlightMaze¡¾2¡¿ÊÇ90ÄêÔÂÃÀ¹úÔâÊܵÄÒ»´ÎÍøÂç¹¥»÷Ô˶¯¡£¡£¡£¡£¡£¡£¡£¸ÃÔ˶¯×îÖÕÖ¸Ïò¶íÂÞ˹Õþ¸®£¬£¬£¬£¬£¬Ò»Ì¨Î»ÓÚĪ˹¿ÆµÄÅÌËã»úÅþÁ¬ÁËÏà¹Ø´óѧµÄ»úе²¢½«Æä×÷ÎªÌø°å¹¥»÷ÀµÌØ-ÅÁÌØÉ¿Õ¾ü»ùµØ¡£¡£¡£¡£¡£¡£¡£¸ÃÔ˶¯ÔÚ¿¿½ü20Äêºó£¬£¬£¬£¬£¬±»¹ØÁªµ½Turla×éÖ¯¡£¡£¡£¡£¡£¡£¡£2017Ä꣬£¬£¬£¬£¬¿¨°Í˹»ùÔÚһ̨¹ÅÀϵĻúеÖз¢Ã÷ÁËMoonlightMazeľÂí£¬£¬£¬£¬£¬¸ÃľÂíÓëTurla×éÖ¯µÄLinuxºóÃÅPenquinÒ»Ñù£¬£¬£¬£¬£¬»ùÓÚLOKI2ºóÞÙÐпª·¢¡£¡£¡£¡£¡£¡£¡£Ò²ÊÇΨÖðÒ»¸öʹÓÃLOKI2ºóÞÙÐпª·¢µÄAPT×éÖ¯¡£¡£¡£¡£¡£¡£¡£
£¨¶þ£©Agent.BTZÔ˶¯¡¾3¡¿
2008Ä꣬£¬£¬£¬£¬ÔÚÖж«ÃÀ¹ú¾üÊ»ùµØµÄÍ£³µ³¡£¬£¬£¬£¬£¬ÓÐÃÀ¹úÎäÊ¿¼ñµ½Ñ¬È¾ÁËAgent.BTZµÄUÅÌ£¬£¬£¬£¬£¬²¢²åÈëÅþÁ¬µ½ÃÀ¹úÖÐÑë˾ÁµÄÌõ¼Ç±¾µçÄÔÖС£¡£¡£¡£¡£¡£¡£È䳿²¡¶¾´ÓÄÇÀïÈö²¥µ½ÃÀ¹úÎå½Ç´óÂ¥×ܲ¿ÏµÍ³¡£¡£¡£¡£¡£¡£¡£×îºó»¨ÁË¿ìÒª14¸öÔµÄʱ¼ä²Å´Ó¾üÊÂÍøÂçÉÏɨ³ýÁËÈ䳿¡£¡£¡£¡£¡£¡£¡£ºóÐøÑо¿·¢Ã÷£¬£¬£¬£¬£¬Turla×éÖ¯µÄľÂíÓëAgent.BTZÔÚ´úÂëºÍµÄÐÐΪÉϱ£´æ¹ØÁª¡£¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬´Ë´Î¹¥»÷Ô˶¯±»¹éµ½Turla£¬£¬£¬£¬£¬±»ÒÔΪÊÇÊ·ÉÏ×îÖøÃûµÄ¹¥»÷Ô˶¯Ö®Ò»¡£¡£¡£¡£¡£¡£¡£
£¨Èý£©RedOctoberÔ˶¯
2007Äêµ½2013Äêʱ´ú£¬£¬£¬£¬£¬RedOctober¡¾4¡¿¶ñÒâÈí¼þ½ÓÄÉ´¹ÂÚʽ¹¥»÷ģʽ£¬£¬£¬£¬£¬¹¥»÷ÁË39¸ö¹ú¼ÒµÄÍ⽻ʹ¹Ý¡¢Õþ¸®ºÍ¿ÆÑлú¹¹¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿¨°Í˹»ùÆÊÎö±¨¸æ³Æ£¬£¬£¬£¬£¬RedOctoberÄ»ºóÔËÓªÕß¶àÓöíÓïΪ´úÂ룬£¬£¬£¬£¬²¢ÇÒ¹¥»÷Ô˶¯Öлá»ñÈ¡Agent.BTZľÂíËùÊͷŵÄthumb.ddÎļþ£¬£¬£¬£¬£¬Òò´Ë¹éÒòÖÁTurla×éÖ¯¡£¡£¡£¡£¡£¡£¡£
£¨ËÄ£©SolarWinds¹¥»÷Ô˶¯
2020Äê12ÔÂ13ÈÕ£¬£¬£¬£¬£¬FireEyeÐû²¼Á˹ØÓÚSolarWinds¡¾5¡¿¹©Ó¦Á´¹¥»÷µÄͨ¸æ£¬£¬£¬£¬£¬»ù´¡ÍøÂçÖÎÀíÈí¼þ¹©Ó¦ÉÌSolarWindsOrionÈí¼þ¸üаüÖб»ºÚ¿ÍÖ²ÈëºóÃÅ¡£¡£¡£¡£¡£¡£¡£±¾´Î¹©Ó¦Á´¹¥»÷ÊÂÎñ²¨¼°¹æÄ£¼«´ó£¬£¬£¬£¬£¬°üÀ¨Õþ¸®²¿·Ö£¬£¬£¬£¬£¬Òªº¦»ù´¡ÉèÊ©ÒÔ¼°¶à¼ÒÈ«Çò500Ç¿ÆóÒµ£¬£¬£¬£¬£¬Ôì³ÉµÄÑÏÖØÓ°Ïì¡£¡£¡£¡£¡£¡£¡£Ëæºó£¬£¬£¬£¬£¬ÃÀÊÓ²ì»ú¹¹Ðû²¼ÍŽáÉùÃ÷³ÆÍøÂç¹¥»÷¿ÉÄÜÔ´×Ô¶íÂÞ˹¡£¡£¡£¡£¡£¡£¡£2021Äê1Ô£¬£¬£¬£¬£¬¿¨°Í˹»ùÐû²¼±¨¸æ³Æ¡¾6¡¿£¬£¬£¬£¬£¬SolarWinds¹©Ó¦Á´¹¥»÷ÊÂÎñÖеÄSunburstºóÃÅ´úÂëÓë¶íÂÞ˹APT×éÖ¯³£ÓÃľÂíKazuarºóÃű£´æ´úÂëÖØµþ£¬£¬£¬£¬£¬Ö¤ÊµÁËÃÀ¹úµÄ½áÂÛ£¬£¬£¬£¬£¬Òò´ËSolarWinds¹©Ó¦Á´ÊÂÎñ¿ÉÄÜÀ´×ÔTurla¡£¡£¡£¡£¡£¡£¡£
×ܽá
Turla±³ºóÓÐ×ÅǿʢµÄÕþ¸®×ÊÔ´£¬£¬£¬£¬£¬Äܹ»ÎªÆäÌṩ¸»ºñµÄÍøÂçÎäÆ÷ºÍÈËÁ¦Ö§³Ö¡£¡£¡£¡£¡£¡£¡£ÕâÒ»Çе¼ÖÂTurlaµÄ¹¥»÷Àú³Ì·±Ëö£¬£¬£¬£¬£¬Ô˶¯¹ì¼£Òþ²ØÐÔ£¬£¬£¬£¬£¬ÄÑÒÔ×·×Ù¡£¡£¡£¡£¡£¡£¡£
´Ó¹¥»÷Ä¿µÄºÍ¹¥»÷ÊÂÎñÀ´¿´£¬£¬£¬£¬£¬¸Ã×éÖ¯Ö÷ÒªÎ§ÈÆ×ÅÕþÖΡ¢Íâ½»ºÍ¾üÇéÈý·½Ãæ¾ÙÐй¥»÷£»£»£»£»£»£»Í¬Ê±£¬£¬£¬£¬£¬ÉÆÓÚ¶Ô¹¥»÷ÊֶξÙÐÐÁ¢Ò쿪·¢£¬£¬£¬£¬£¬ÕûÌå¶øÑÔÊôÓÚAPT×éÖ¯ÖеÄÁìÏÈÕߺÍÁ¢ÒìÕß¡£¡£¡£¡£¡£¡£¡£
×¢½â
https://ti.qianxin.com/uploads/2021/02/08/dd941ecf98c7cb9bf0111a8416131aa1.pdf
https://www.kaspersky.com/blog/moonlight-maze-the-lessons/6713/
https://securelist.com/agent-btz-a-source-of-inspiration/58551/
https://www.kaspersky.com/about/press-releases/2013_kaspersky-lab-identifies-operation--red-october--an-advanced-cyber-espionage-campaign-targeting-diplomatic-and-government-institutions-worldwide
https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html
https://usa.kaspersky.com/about/press-releases/2020_na-kaspersky-experts-connect-solar-winds-attack-with-kazuar-backdoor
¹ØÓÚ×÷Õß
Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ºìÓêµÎÍŶӣ¨RedDripTeam£¬£¬£¬£¬£¬@RedDrip7£©£¬£¬£¬£¬£¬ÒÀÍÐÈ«ÇòÁìÏȵÄÇå¾²´óÊý¾ÝÄÜÁ¦¡¢¶àά¶È¶àȪԴµÄÇå¾²Êý¾ÝºÍרҵÆÊÎöʦµÄ¸»ºñÂÄÀú£¬£¬£¬£¬£¬×Ô2015ÄêÒ»Á¬·¢Ã÷¶à¸ö°üÀ¨º£Á«»¨ÔÚÄÚµÄAPT×éÖ¯ÔÚÖйú¾³Äڵĺã¾ÃÔ˶¯£¬£¬£¬£¬£¬²¢Ðû²¼º£ÄÚÊ׸ö×éÖ¯²ãÃæµÄAPTÊÂÎñ½ÒÆÆ±¨¸æ£¬£¬£¬£¬£¬¿ª´´Á˺£ÄÚAPT¹¥»÷Àà¸ß¼¶Íþвϵͳ»¯½ÒÆÆµÄÏȺӡ£¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬Ò»Á¬¸ú×ÙÆÊÎöµÄÖ÷ÒªAPTÍÅ»ïÁè¼Ý46¸ö£¬£¬£¬£¬£¬×ÔÁ¦·¢Ã÷APT×éÖ¯13¸ö£¬£¬£¬£¬£¬Ò»Á¬Ðû²¼APT×éÖ¯µÄ¸ú×Ù±¨¸æÁè¼Ý90ƪ£¬£¬£¬£¬£¬°´ÆÚÊä³ö°ëÄêºÍÕûÄêÈ«ÇòAPTÔ˶¯×ÛºÏÐÔÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£
ʱ¼ä£º2026-04-22
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-18
Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ
ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ