1、 APT attacks on industrial companies in H2 2021 28.02.2022 Version 1.0 APT ATTACKS ON INDUSTRIAL COMPANIES IN H2 2021 1 2022 AO KASPERSKY LAB Threat groups linked to China.2 Lazarus attacks.2 WildPressure attacks.3 TortoiseShell.3 Bandook RAT spying campaign in Latin America.3 APT31.4 Attacks on Ira
2、nian railway system and gas stations.5 Operation Layover targeting aviation industry.5 FamousSparrow group and attacks on engineering firms.5 APT actors exploiting vulnerabilities in Zoho ManageEngine.7 APT-C-36 attacks.8 DarkOxide targeting the semiconductor industry.8 ChamelGang attacks.8 PseudoMa
3、nuscrypt:a mass-scale spyware attack campaign.9 Operation GhostShell.9 TA2722 attacks.10 Attacks of Iranian state-sponsored APT actors.10 Tardigrade malware attacks on Biomanufacturing companies.11 Tropic Trooper targets transportation and government.11 Karakurt group attacks.12 This summary provide
4、s an overview of APT attacks on industrial enterprises disclosed in H2 2021 and related activity of groups that have been observed attacking industrial organizations and critical infrastructure facilities.For each story,we sought to summarize the most significant facts,findings,and conclusions of re
5、searchers,which we believe can be of use to experts who address practical issues related to ensuring the cybersecurity of industrial enterprises.APT ATTACKS ON INDUSTRIAL COMPANIES IN H2 2021 2 2022 AO KASPERSKY LAB Threat groups linked to China During 2020 and 2021,Kaspersky detected a new ShadowPa
6、d loader module,dubbed ShadowShredder.The module was used against critical infrastructure in multiple countries,including but not limited to India,China,Canada,Afghanistan,and Ukraine.Upon further investigation,additional implants deployed through both ShadowPad and ShadowShredder,such as the Quaria