当前位置:首页 >英文主页 >中英对照 > 中译版报告详情

卡巴斯基:2022年H2针对工业组织的APT攻击报告(中译版)(14页).pdf

上传人: Kell****reet 编号:145043 2023-01-09 14页 243.47KB

下载:

1、 APT attacks on industrial organizations in H2 2022 24.03.2023 Version 1.0 APT ATTACKS ON INDUSTRIAL ORGANIZATIONS IN H2 2022 1 2023 AO KASPERSKY LAB Southeast Asia and Korean Peninsula.2 DEV-0530 attacks.2 Tropic Trooper attacks.2 GwisinLocker ransomware attacks.3 Lazarus attacks.3 UNC4034/ZINC att

2、acks.5 Middle East.5 UNC3890 attacks.5 POLONIUM attacks.6 Chinese-speaking activity.6 TA428 attacks.6 APT31 attacks.7 TA423/Red Ladon attacks.7 Espionage activity against Asian governments.8 Budworm attacks.8 Earth Longzhi attacks.9 Russian-speaking activity.9 IRIDIUM/Sandworm attacks.9 Cloud Atlas/

3、Inception attacks.10 Other.10 Woody Rat attacks.10 Worok attacks.11 CISA alerts.11 Iran-backed APT actors.11 Military contractor hack.12 This summary provides an overview of APT attacks on industrial enterprises disclosed in H2 2022 and related activity of groups that have been observed attacking in

4、dustrial organizations and critical infrastructure facilities.For each story,we sought to summarize the most significant facts,findings,and conclusions of researchers,which we believe can be of use to experts who address practical issues related to ensuring the cybersecurity of industrial enterprise

5、s.APT ATTACKS ON INDUSTRIAL ORGANIZATIONS IN H2 2022 2 2023 AO KASPERSKY LAB Southeast Asia and Korean Peninsula DEV-0530 attacks Researchers have attributed an emerging ransomware threat to a North Korean based threat actor they call DEV-0530(the group calls itself“H0lyGh0st”).DEV-0530 has targeted

6、 small-to-medium businesses in multiple countries since September 2021,including manufacturing organizations,banks,schools,and event and meeting planning companies.The attackers employ“double extortion”,encrypting data and also threatening to publish data if the target refuses to pay.Researchers hav

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
根据报告的内容,本文主要概括了2022年下半年针对工业组织的APT攻击情况及相关活动。主要内容包括: 1. 东南亚和朝鲜半岛:DEV-0530攻击者针对中小企业,使用双重勒索策略;Tropic Trooper攻击者针对台湾金融机构和制造公司;GwisinLocker勒索软件针对韩国工业和制药公司;Lazarus攻击者利用恶意macOS可执行文件针对工程师。 2. 中东:UNC3890攻击者针对以色列航运、政府、能源和医疗保健组织;POLONIUM攻击者针对以色列多个行业组织。 3. 其他地区:IRIDIUM/Sandworm攻击者针对乌克兰;Cloud Atlas/Inception攻击者针对乌克兰;Woody Rat和Worok攻击者针对乌克兰。 4. CISA警告:伊朗支持的APT行为者;针对军事承包商的网络攻击。 综上所述,本文总结了2022年下半年针对工业组织和关键基础设施设施的APT攻击情况,并分析了相关攻击者的活动。
2022年下半年工业组织APT攻击概述 DEV-0530针对哪些行业发起攻击? POLONIUM APT针对哪些行业进行间谍活动?
客服
商务合作
小程序
服务号
折叠