ʱ¼ä£º2021-11-04
±¾ÎÄ2915×ÖÔĶÁÔ¼Ðè8ÖÓ
¹ú¼Ò¼¶APT£¨AdvancedPersistentThreat£¬£¬£¬£¬£¬¸ß¼¶Ò»Á¬ÐÔÍþв£©×éÖ¯ÊÇÓйú¼ÒÅä¾°Ö§³ÖµÄ¶¥¼âºÚ¿ÍÍŻ£¬£¬£¬£¬×¨×¢ÓÚÕë¶ÔÌØ¶¨Ä¿µÄ¾ÙÐкã¾ÃµÄÒ»Á¬ÐÔÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!Æìϸ߼¶ÍþвÑо¿ÍŶӺìÓêµÎ£¨RedDripTeam£©Ã¿Äê»áÐû²¼È«ÇòAPTÄ걨¡¾1¡¿¡¢Öб¨£¬£¬£¬£¬£¬¶ÔÎôʱ¸÷´óAPTÍÅ»ïµÄÔ˶¯¾ÙÐÐÆÊÎö×ܽᡣ¡£¡£¡£¡£¡£¡£¡£
»¢·ûÖÇ¿âÌØÔ¼Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÆìϺìÓêµÎÍŶӣ¬£¬£¬£¬£¬¿ªÉè“Æðµ×¹ú¼Ò¼¶APT×éÖ¯”À¸Ä¿£¬£¬£¬£¬£¬Öð¸öÆðµ×È«Çò¸÷µØÇø»îÔ¾µÄÖ÷ÒªAPT×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡£±¾ÆÚËø¶¨Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ºìÓêµÎÍŶÓÖØµã¼à¿ØµÄAPT×éÖ¯Turla¡£¡£¡£¡£¡£¡£¡£¡£
02
Turla
TurlaÊÇרÃÅÕë¶ÔÕþ¸®µÄÖøÃû¹ú¼Ò¼¶ºÚ¿ÍÍŻ£¬£¬£¬£¬ÊôÓÚ¶«Å·Ä³¹úÇ鱨»ú¹¹¡£¡£¡£¡£¡£¡£¡£¡£Æä¹¥»÷Ô˶¯Éæ¼°45¸ö¹ú¼Ò£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÍâ½»²¿·Ö¡¢Õþ¸®»ú¹¹¡¢¾üÊ»ú¹¹¡¢¿ÆÑлú¹¹µÈ×éÖ¯ÇÔÈ¡Ö÷ÒªÇ鱨¡£¡£¡£¡£¡£¡£¡£¡£

Turla±»ÊÓΪÆù½ñΪֹ×îΪ¸ß¼¶µÄÍþв×éÖ¯Ö®Ò»£¬£¬£¬£¬£¬Òò¶øÊÇÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ºìÓêµÎÍŶÓÖØµã¼à¿ØµÄAPT×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡£
Åä¾°
Turla£¬£¬£¬£¬£¬Ò²±»³ÆÎªVenomousBear¡¢WaterbugUroboros£¬£¬£¬£¬£¬ÊÇÆù½ñΪֹ×îΪ¸ß¼¶µÄÍþв×éÖ¯Ö®Ò»£¬£¬£¬£¬£¬±»ÒÔΪÁ¥ÊôÓÚ¶«Å·Ä³¹úÇ鱨»ú¹¹¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯×îÔç¿ÉÒÔËÝÔ´µ½1996Ä꣬£¬£¬£¬£¬µ«ÔÚ2014Äê²Å±»¿¨°Í˹»ùʵÑéÊÒÊ״η¢Ã÷¡£¡£¡£¡£¡£¡£¡£¡£
TurlaÊÇÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ºìÓêµÎÍŶÓÖØµã¼à¿ØµÄAPT×éÖ¯£¬£¬£¬£¬£¬ÄÚ²¿±àºÅΪAPT-Q-78¡£¡£¡£¡£¡£¡£¡£¡£
Turla·¢¶¯µÄ¹¥»÷Ô˶¯Éæ¼°45¸ö¹ú¼Ò£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÍâ½»²¿·Ö¡¢Õþ¸®»ú¹¹¡¢¾üÊ»ú¹¹¡¢¿ÆÑлú¹¹µÈ×éÖ¯ÇÔÈ¡Ö÷ÒªÇ鱨£¬£¬£¬£¬£¬ÏÖÔÚÒÑÖªÊܺ¦µ¥Î»°üÀ¨ÃÀ¹úÖÐÑë˾Á¡¢µÂÍâÑó½»²¿¡¢·¨¹ú¾ü¶Ó¡¢ÈðÊ¿¾ü¹¤ÆóÒµRUAGµÈ¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄTurla»¹»áÕë¶Ô¶íÂÞ˹¾³ÄÚ±£´æÃÓÀÃÏÓÒɵÄÄ¿µÄ¾ÙÐй¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
¹¥»÷ÌØµãÊֶΡ¢¹¤¾ß
TurlaʹÓõĺóÃż°¹¤¾ßÖÖÀà·±¶àÇÒÄÑÒÔ×·×Ù¡£¡£¡£¡£¡£¡£¡£¡£³£¼û¹¥»÷·½·¨°üÀ¨Óã²æ¹¥»÷¡¢WebÉøÍ¸ÈëÇÖ¡¢ÍøÂçÐ®ÖÆ¡¢Ë®¿Ó¹¥»÷¡¢UÅÌÉç½»¹¥»÷µÈ¡£¡£¡£¡£¡£¡£¡£¡£
£¨Ò»£©¹¥»÷¹¤¾ß
TurlaÔÚÀúÊ·¹¥»÷Ô˶¯ÖÐʹÓù¤¾ß°üÀ¨Êý¾ÝÍøÂçºÍshellÖ´Ðй¦Ð§µÄºóÃÅ¡¢¾ßÓÐÔ¶¿ØºÍ¼à¿Ø¹¦Ð§µÄ×é¼þÒÔ¼°¿ªÔ´¹¤¾ßµÈ¡£¡£¡£¡£¡£¡£¡£¡£
TurlaʹÓõĺóÃż°¹¤¾ßÖÖÀà·±¶àÇÒÄÑÒÔ×·×Ù£¬£¬£¬£¬£¬²»µ«ÓµÓи»ºñµÄ¾üÆ÷¿â»¹ÓµÓдó×Ú¿ª·¢Ö°Ô±£¬£¬£¬£¬£¬Äܹ»ÊµÊ±¾ÙÐÐÊÖÒÕ¸üС£¡£¡£¡£¡£¡£¡£¡£
ÆäʹÓù¤¾ßÓÐÒÔÏÂÌØµã£º
1.TurlaÌᳫµÄÍøÂçÌØ¹¤Ô˶¯Ö÷ÒªÕë¶ÔWindowsƽ̨£¬£¬£¬£¬£¬Ê¹ÓõĶñÒâÈí¼þ½ÏÎªÖØ´ó£¬£¬£¬£¬£¬Äܹ»¿ª·¢¶àÓïÑÔÇéÐεÄ×ÔÑÐÌØÂíºÍ¿ªÔ´Ä¾Âí£¬£¬£¬£¬£¬ÆäÖв¿·ÖÌØÂí¸üеü´úÖÁ½ñÈÔ±»Ê¹Óᣡ£¡£¡£¡£¡£¡£¡£
2.Turla×éÖ¯ÔÚ³¤ÆÚ»¯Éè¼Æ²¿·ÖʹÓöàÖÖ·½·¨£¬£¬£¬£¬£¬È罫PowershellµÄ¹¥»÷½¹µãÔØºÉ´¢ÓÚWindows×¢²á±íÏîÖС¢×¢²á×ÔÆôЧÀÍʵÏÖ³¤ÆÚ»¯µÈ·½·¨£¬£¬£¬£¬£¬ÌåÏÖÁËTurla¹¤¾ß¿ª·¢Ö°Ô±µÄÉè¼ÆÆ«ºÃ¡£¡£¡£¡£¡£¡£¡£¡£
3.ΪÁ˰ü¹ÜÂ䵨¹¥»÷ÔØºÉÊÊÅä¶àÖÖPCÇéÐÎʹÆäÎȹÌÔËÐУ¬£¬£¬£¬£¬Turla×éÖ¯µÄ¹¥»÷×é¼þÖдó¶à±£´æÇéÐÎÊÊÅä¡¢¹¤¾ß̽²â¡¢Çå¾²»úÖÆÈÆ¹ýµÈÏà¹ØµÄ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
4.TurlaÈëÇÖºóÔØºÉÔÚÔËÐпØÖÆÒÔ¼°ÒþÄäÐÔÉèÖ÷½Ãæ¾ù±£´æÏÔ×ÅÖ¸ÎÆÌØÕ÷£¬£¬£¬£¬£¬ÉÆÓÚÎļþÒþ²Ø¡¢¿ØÖÆÄ¾ÂíÔËÐÐÆµÂÊ¡¢Ê¹ÓÃRPC¼¯Èº¼àÌýµÈ¡£¡£¡£¡£¡£¡£¡£¡£
5.Turla¹¥»÷×é¼þÖÐÔÚ¼ÓÃÜËã·¨µÄÑ¡Ôñ»ò±àд¡¢ÃÜÔ¿ÌìÉúµÈ·½ÃæÌåÏÖµÄÊ®·Ö¸öÐÔ»¯£¬£¬£¬£¬£¬²»Ê¹Óó£¼ûµÄ¹Å°å¼ÓÃÜËã·¨£¬£¬£¬£¬£¬¾ßÓÐ×Ô¼ºÆæÒìµÄ¼ÓÃÜÆø¸Å¡£¡£¡£¡£¡£¡£¡£¡£
ÏÂ±íÆ¾Ö¤¹¥»÷½×¶Î½«ÆäʹÓúóÞÙÐÐÏÈÈÝ£¬£¬£¬£¬£¬°üÀ¨×ÔÑÐÌØÂíºÍ¿ªÔ´Ä¾Âí¡£¡£¡£¡£¡£¡£¡£¡£

£¨¶þ£©¹¥»÷·½·¨
Turla×éÖ¯³£¼û¹¥»÷·½·¨°üÀ¨Óã²æ¹¥»÷¡¢WebÉøÍ¸ÈëÇÖ¡¢ÍøÂçÐ®ÖÆ¡¢Ë®¿Ó¹¥»÷¡¢UÅÌÉç½»¹¥»÷µÈ¡£¡£¡£¡£¡£¡£¡£¡£
Turla³õʼ¹¥»÷ÉÆÓÚʹÓÃÉç»á¹¤³ÌѧÊֶεÄÓã²æ¹¥»÷ÒÔ¼°Ë®¿Ó¹¥»÷À´Í¶µÝ¹¥»÷ÔØºÉ£¬£¬£¬£¬£¬Ê¹ÓúóÃźóÍøÂçPCÊý¾Ý¾öÒéÊÇ·ñ¾ÙÐÐÏÂÒ»½×¶Î¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ºóÐø»áÅäºÏ¹¥»÷ÕßÔ¶³Ì½»»¥¾ÙÐоÖÓòÍøÄÚºáÒÆÉøÍ¸£¬£¬£¬£¬£¬Í¨¹ý¹ÜµÀÐÒéµÄRPCͨѶ¾ÙÐоÖÓòÍø¶Î¼àÌý¡£¡£¡£¡£¡£¡£¡£¡£
1.Óã²æ¹¥»÷
TurlaÉÆÓÚʹÓüдø¶ñÒâ³ÌÐòÒÔ¼°Îó²îµÄÎļþͨ¹ýµç×ÓÓʼþ¾ÙÐÐͶµÝ£¬£¬£¬£¬£¬²¢Í¨¹ýÉç»á¹¤³ÌѧÓÕµ¼Óû§µã»÷Ö´ÐÐÎļþ¡£¡£¡£¡£¡£¡£¡£¡£Óã²æ¹¥»÷ÔØºÉͨ³£ÎªÎó²îÎļþ¡¢ºêÎļþ¡¢Î±×°×°Öðü¡£¡£¡£¡£¡£¡£¡£¡£
2.Ë®¿Ó¹¥»÷
TurlaÆ«ÐÒʹÓÃË®¿Ó¹¥»÷£¬£¬£¬£¬£¬ÒýÓÕÄ¿µÄÊܺ¦Õß»á¼ûÆäC2ЧÀÍÆ÷£¬£¬£¬£¬£¬Ö÷Òª·ÖΪÓÕ¶ü´¹ÂÚÒÔ¼°Îó²î¹¥»÷£¬£¬£¬£¬£¬ÆäÖд󲿷ÖÓÃÓÚÖÆÔìË®¿ÓµÄÍøÕ¾¾ùÊÇÕýµ±ÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¡£ÔçÆÚTurlaϲÐÒ¿÷ÍøÕ¾ÖÐǶÈëJavaScript´úÂ룬£¬£¬£¬£¬ÔÚÓû§»á¼ûµÄʱ¼äÖ´ÐУ¬£¬£¬£¬£¬Æä¹¦Ð§´ó¶àΪ»ñÈ¡ä¯ÀÀÆ÷µÄ²å¼þÁÐ±í£¬£¬£¬£¬£¬ÆÁÄ»Çø·ÖÂʵÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£½üÆÚ£¬£¬£¬£¬£¬TurlaµÄ¹¥»÷·½·¨¸üΪֱ½Ó£¬£¬£¬£¬£¬ÔÚ¾ÙÐÐÖ¸ÎÆÊ¶±ðºóÏ·¢¶ñÒâµÄAdobeFlash×°Öðü¡£¡£¡£¡£¡£¡£¡£¡£
3.Êý×ÖÎÀÐǵçÊÓÏµÍ³Ð®ÖÆ
×Ô2007ÄêÒÔÀ´£¬£¬£¬£¬£¬TurlaʹÓÃÎÀÐÇͨѶÖйÌÓеÄÇ徲ȱÏÝ£¬£¬£¬£¬£¬Òþ²ØC2ЧÀÍÆ÷µÄλÖúͿØÖÆÖÐÐÄ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÇãÏòÓÚÑ¡ÔñʹÓýöÁýÕÖ·ÇÖÞµØÇøµÄÎÀÐÇÌṩÉÌ¡£¡£¡£¡£¡£¡£¡£¡£ÕâʹµÃ·ÇÖÞÒÔÍâ¹ú¼ÒµÄÑо¿Ö°Ô±¼«ÆäÄÑÒÔÊÓ²ìTurlaС×éµÄÔ˶¯£¬£¬£¬£¬£¬ÆäÖÐÎÀÐÇIP¼¯ÖÐÔÚ·ÇÖÞºÍÖж«µØÇø¡£¡£¡£¡£¡£¡£¡£¡£
4.MITMÁ÷Á¿Ð®ÖÆÓë¸Ä¶¯
TurlaÔÚÒ»ÔÙÐж¯ÖУ¬£¬£¬£¬£¬¶¼»áͨ¹ý»ñÈ¡½¹µã·ÓɵÄȨÏÞÉõÖÁÐ®ÖÆÒªº¦½Úµã£¬£¬£¬£¬£¬²¢Í¨¹ýMITM£¨ÖÐÐÄÈ˹¥»÷£©À´Ð®ÖÆAdobeµÄÍøÂç¡£¡£¡£¡£¡£¡£¡£¡£Ê¹µÃÓû§ÔÚÇëÇóÏÂÔØ×îеÄÈí¼þ¸üаüʱ£¬£¬£¬£¬£¬Ìæ»»Óû§µÄÏÂÔØÄÚÈÝ£¬£¬£¬£¬£¬ÔÚÓû§Î޸еÄÇéÐÎÏ£¬£¬£¬£¬£¬ÏÂÔØ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬²¢Íê³É¶ÔÄ¿µÄÖ÷»úµÄ¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£¡£´ËÖÖ·½·¨ÐèÒª»ñÈ¡½¹µã·ÓɵÄȨÏÞ£¬£¬£¬£¬£¬ÉõÖÁÐèÒªÕë¶ÔÆóÒµ/Õþ¸®µÄÒªº¦½Úµã¾ÙÐÐÐ®ÖÆ¡£¡£¡£¡£¡£¡£¡£¡£
×ÅÃû¹¥»÷ÊÂÎñ
£¨Ò»£©MoonlightMazeÔ˶¯
MoonlightMaze¡¾2¡¿ÊÇ90ÄêÔÂÃÀ¹úÔâÊܵÄÒ»´ÎÍøÂç¹¥»÷Ô˶¯¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÔ˶¯×îÖÕÖ¸Ïò¶íÂÞ˹Õþ¸®£¬£¬£¬£¬£¬Ò»Ì¨Î»ÓÚĪ˹¿ÆµÄÅÌËã»úÅþÁ¬ÁËÏà¹Ø´óѧµÄ»úе²¢½«Æä×÷ÎªÌø°å¹¥»÷ÀµÌØ-ÅÁÌØÉ¿Õ¾ü»ùµØ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÔ˶¯ÔÚ¿¿½ü20Äêºó£¬£¬£¬£¬£¬±»¹ØÁªµ½Turla×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡£2017Ä꣬£¬£¬£¬£¬¿¨°Í˹»ùÔÚһ̨¹ÅÀϵĻúеÖз¢Ã÷ÁËMoonlightMazeľÂí£¬£¬£¬£¬£¬¸ÃľÂíÓëTurla×éÖ¯µÄLinuxºóÃÅPenquinÒ»Ñù£¬£¬£¬£¬£¬»ùÓÚLOKI2ºóÞÙÐпª·¢¡£¡£¡£¡£¡£¡£¡£¡£Ò²ÊÇΨÖðÒ»¸öʹÓÃLOKI2ºóÞÙÐпª·¢µÄAPT×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡£
£¨¶þ£©Agent.BTZÔ˶¯¡¾3¡¿
2008Ä꣬£¬£¬£¬£¬ÔÚÖж«ÃÀ¹ú¾üÊ»ùµØµÄÍ£³µ³¡£¬£¬£¬£¬£¬ÓÐÃÀ¹úÎäÊ¿¼ñµ½Ñ¬È¾ÁËAgent.BTZµÄUÅÌ£¬£¬£¬£¬£¬²¢²åÈëÅþÁ¬µ½ÃÀ¹úÖÐÑë˾ÁµÄÌõ¼Ç±¾µçÄÔÖС£¡£¡£¡£¡£¡£¡£¡£È䳿²¡¶¾´ÓÄÇÀïÈö²¥µ½ÃÀ¹úÎå½Ç´óÂ¥×ܲ¿ÏµÍ³¡£¡£¡£¡£¡£¡£¡£¡£×îºó»¨ÁË¿ìÒª14¸öÔµÄʱ¼ä²Å´Ó¾üÊÂÍøÂçÉÏɨ³ýÁËÈ䳿¡£¡£¡£¡£¡£¡£¡£¡£ºóÐøÑо¿·¢Ã÷£¬£¬£¬£¬£¬Turla×éÖ¯µÄľÂíÓëAgent.BTZÔÚ´úÂëºÍµÄÐÐΪÉϱ£´æ¹ØÁª¡£¡£¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬´Ë´Î¹¥»÷Ô˶¯±»¹éµ½Turla£¬£¬£¬£¬£¬±»ÒÔΪÊÇÊ·ÉÏ×îÖøÃûµÄ¹¥»÷Ô˶¯Ö®Ò»¡£¡£¡£¡£¡£¡£¡£¡£
£¨Èý£©RedOctoberÔ˶¯
2007Äêµ½2013Äêʱ´ú£¬£¬£¬£¬£¬RedOctober¡¾4¡¿¶ñÒâÈí¼þ½ÓÄÉ´¹ÂÚʽ¹¥»÷ģʽ£¬£¬£¬£¬£¬¹¥»÷ÁË39¸ö¹ú¼ÒµÄÍ⽻ʹ¹Ý¡¢Õþ¸®ºÍ¿ÆÑлú¹¹¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿¨°Í˹»ùÆÊÎö±¨¸æ³Æ£¬£¬£¬£¬£¬RedOctoberÄ»ºóÔËÓªÕß¶àÓöíÓïΪ´úÂ룬£¬£¬£¬£¬²¢ÇÒ¹¥»÷Ô˶¯Öлá»ñÈ¡Agent.BTZľÂíËùÊͷŵÄthumb.ddÎļþ£¬£¬£¬£¬£¬Òò´Ë¹éÒòÖÁTurla×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡£
£¨ËÄ£©SolarWinds¹¥»÷Ô˶¯
2020Äê12ÔÂ13ÈÕ£¬£¬£¬£¬£¬FireEyeÐû²¼Á˹ØÓÚSolarWinds¡¾5¡¿¹©Ó¦Á´¹¥»÷µÄͨ¸æ£¬£¬£¬£¬£¬»ù´¡ÍøÂçÖÎÀíÈí¼þ¹©Ó¦ÉÌSolarWindsOrionÈí¼þ¸üаüÖб»ºÚ¿ÍÖ²ÈëºóÃÅ¡£¡£¡£¡£¡£¡£¡£¡£±¾´Î¹©Ó¦Á´¹¥»÷ÊÂÎñ²¨¼°¹æÄ£¼«´ó£¬£¬£¬£¬£¬°üÀ¨Õþ¸®²¿·Ö£¬£¬£¬£¬£¬Òªº¦»ù´¡ÉèÊ©ÒÔ¼°¶à¼ÒÈ«Çò500Ç¿ÆóÒµ£¬£¬£¬£¬£¬Ôì³ÉµÄÑÏÖØÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£Ëæºó£¬£¬£¬£¬£¬ÃÀÊÓ²ì»ú¹¹Ðû²¼ÍŽáÉùÃ÷³ÆÍøÂç¹¥»÷¿ÉÄÜÔ´×Ô¶íÂÞ˹¡£¡£¡£¡£¡£¡£¡£¡£2021Äê1Ô£¬£¬£¬£¬£¬¿¨°Í˹»ùÐû²¼±¨¸æ³Æ¡¾6¡¿£¬£¬£¬£¬£¬SolarWinds¹©Ó¦Á´¹¥»÷ÊÂÎñÖеÄSunburstºóÃÅ´úÂëÓë¶íÂÞ˹APT×éÖ¯³£ÓÃľÂíKazuarºóÃű£´æ´úÂëÖØµþ£¬£¬£¬£¬£¬Ö¤ÊµÁËÃÀ¹úµÄ½áÂÛ£¬£¬£¬£¬£¬Òò´ËSolarWinds¹©Ó¦Á´ÊÂÎñ¿ÉÄÜÀ´×ÔTurla¡£¡£¡£¡£¡£¡£¡£¡£
×ܽá
Turla±³ºóÓÐ×ÅǿʢµÄÕþ¸®×ÊÔ´£¬£¬£¬£¬£¬Äܹ»ÎªÆäÌṩ¸»ºñµÄÍøÂçÎäÆ÷ºÍÈËÁ¦Ö§³Ö¡£¡£¡£¡£¡£¡£¡£¡£ÕâÒ»Çе¼ÖÂTurlaµÄ¹¥»÷Àú³Ì·±Ëö£¬£¬£¬£¬£¬Ô˶¯¹ì¼£Òþ²ØÐÔ£¬£¬£¬£¬£¬ÄÑÒÔ×·×Ù¡£¡£¡£¡£¡£¡£¡£¡£
´Ó¹¥»÷Ä¿µÄºÍ¹¥»÷ÊÂÎñÀ´¿´£¬£¬£¬£¬£¬¸Ã×éÖ¯Ö÷ÒªÎ§ÈÆ×ÅÕþÖΡ¢Íâ½»ºÍ¾üÇéÈý·½Ãæ¾ÙÐй¥»÷£»£»£»£»£»£»£»Í¬Ê±£¬£¬£¬£¬£¬ÉÆÓÚ¶Ô¹¥»÷ÊֶξÙÐÐÁ¢Ò쿪·¢£¬£¬£¬£¬£¬ÕûÌå¶øÑÔÊôÓÚAPT×éÖ¯ÖеÄÁìÏÈÕߺÍÁ¢ÒìÕß¡£¡£¡£¡£¡£¡£¡£¡£
×¢½â
https://ti.qianxin.com/uploads/2021/02/08/dd941ecf98c7cb9bf0111a8416131aa1.pdf
https://www.kaspersky.com/blog/moonlight-maze-the-lessons/6713/
https://securelist.com/agent-btz-a-source-of-inspiration/58551/
https://www.kaspersky.com/about/press-releases/2013_kaspersky-lab-identifies-operation--red-october--an-advanced-cyber-espionage-campaign-targeting-diplomatic-and-government-institutions-worldwide
https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html
https://usa.kaspersky.com/about/press-releases/2020_na-kaspersky-experts-connect-solar-winds-attack-with-kazuar-backdoor
¹ØÓÚ×÷Õß
Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ºìÓêµÎÍŶӣ¨RedDripTeam£¬£¬£¬£¬£¬@RedDrip7£©£¬£¬£¬£¬£¬ÒÀÍÐÈ«ÇòÁìÏȵÄÇå¾²´óÊý¾ÝÄÜÁ¦¡¢¶àά¶È¶àȪԴµÄÇå¾²Êý¾ÝºÍרҵÆÊÎöʦµÄ¸»ºñÂÄÀú£¬£¬£¬£¬£¬×Ô2015ÄêÒ»Á¬·¢Ã÷¶à¸ö°üÀ¨º£Á«»¨ÔÚÄÚµÄAPT×éÖ¯ÔÚÖйú¾³Äڵĺã¾ÃÔ˶¯£¬£¬£¬£¬£¬²¢Ðû²¼º£ÄÚÊ׸ö×éÖ¯²ãÃæµÄAPTÊÂÎñ½ÒÆÆ±¨¸æ£¬£¬£¬£¬£¬¿ª´´Á˺£ÄÚAPT¹¥»÷Àà¸ß¼¶Íþвϵͳ»¯½ÒÆÆµÄÏȺӡ£¡£¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬Ò»Á¬¸ú×ÙÆÊÎöµÄÖ÷ÒªAPTÍÅ»ïÁè¼Ý46¸ö£¬£¬£¬£¬£¬×ÔÁ¦·¢Ã÷APT×éÖ¯13¸ö£¬£¬£¬£¬£¬Ò»Á¬Ðû²¼APT×éÖ¯µÄ¸ú×Ù±¨¸æÁè¼Ý90ƪ£¬£¬£¬£¬£¬°´ÆÚÊä³ö°ëÄêºÍÕûÄêÈ«ÇòAPTÔ˶¯×ÛºÏÐÔÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£
ʱ¼ä£º2026-04-22
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-18
Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ
ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ