1、 APT attacks on industrial organizations in H2 2022 24.03.2023 Version 1.0 APT ATTACKS ON INDUSTRIAL ORGANIZATIONS IN H2 2022 1 2023 AO KASPERSKY LAB Southeast Asia and Korean Peninsula.2 DEV-0530 attacks.2 Tropic Trooper attacks.2 GwisinLocker ransomware attacks.3 Lazarus attacks.3 UNC4034/ZINC att
2、acks.5 Middle East.5 UNC3890 attacks.5 POLONIUM attacks.6 Chinese-speaking activity.6 TA428 attacks.6 APT31 attacks.7 TA423/Red Ladon attacks.7 Espionage activity against Asian governments.8 Budworm attacks.8 Earth Longzhi attacks.9 Russian-speaking activity.9 IRIDIUM/Sandworm attacks.9 Cloud Atlas/
3、Inception attacks.10 Other.10 Woody Rat attacks.10 Worok attacks.11 CISA alerts.11 Iran-backed APT actors.11 Military contractor hack.12 This summary provides an overview of APT attacks on industrial enterprises disclosed in H2 2022 and related activity of groups that have been observed attacking in
4、dustrial organizations and critical infrastructure facilities.For each story,we sought to summarize the most significant facts,findings,and conclusions of researchers,which we believe can be of use to experts who address practical issues related to ensuring the cybersecurity of industrial enterprise
5、s.APT ATTACKS ON INDUSTRIAL ORGANIZATIONS IN H2 2022 2 2023 AO KASPERSKY LAB Southeast Asia and Korean Peninsula DEV-0530 attacks Researchers have attributed an emerging ransomware threat to a North Korean based threat actor they call DEV-0530(the group calls itself“H0lyGh0st”).DEV-0530 has targeted
6、 small-to-medium businesses in multiple countries since September 2021,including manufacturing organizations,banks,schools,and event and meeting planning companies.The attackers employ“double extortion”,encrypting data and also threatening to publish data if the target refuses to pay.Researchers hav