1、 APT and financial attacks on industrial organizations in H1 2023 25.09.2023 Version 1.0 APT AND FINANCIAL ATTACKS ON INDUSTRIAL ORGANIZATIONS IN H1 2023 1 2023 AO KASPERSKY LAB Korean-speaking activity.2 Lazarus attacks.2 3CX supply chain attack.3 APT43 attacks.4 Andariel attacks.4 MATA attacks.4 C
2、hinese-speaking activity.5 Blackfly/APT41 attacks.5 Volt Typhoon/VANGUARD PANDA attacks.5 Earth Longzhi attacks.7 Lancefly attacks.7 Cyberattacks on Taiwan.7 Russian-speaking activity.8 YoroTrooper attacks.8 COSMICENERGY tool.8 BlueDelta/Sofacy attacks.8 Midnight Blizzard attacks.9 Middle East-relat
3、ed activity.9 Mint Sandstorm/Charming Kitten attacks.9 Watering hole attack on shipping and logistics websites.10 Other.10 Vice Society Ransomware Group attacks.10 Royal ransomware.10 APT attacks with CommonMagic and CloudWizard framework.11 RA Group attacks.12 Void Rabisu attacks.12 CISA alerts.12
4、CISA Royal ransomware alert.12 CISA advisory on Snake malware.13 APT AND FINANCIAL ATTACKS ON INDUSTRIAL ORGANIZATIONS IN H1 2023 2 2023 AO KASPERSKY LAB This summary provides an overview of reports of APT and financial attacks on industrial enterprises that were disclosed in H1 2023,as well as rela
5、ted activities of groups that have been observed attacking industrial organizations and critical infrastructure facilities.For each topic,we have sought to summarize the key facts,findings,and conclusions of the researchers that we believe may be of use to professionals addressing the practical issu
6、es of cybersecurity for industrial enterprises.Korean-speaking activity Lazarus attacks Kaspersky researchers observed a Lazarus campaign,active until January 2023,leveraging a backdoored UltraVNC client to deliver an updated BLINDINCAN payload.The payload has new features,including plug-in-based ex