國家支持的黑客攻擊:什麼是高級持續性威脅以及它們在 2022 年針對的目標是誰?

资讯 2024-07-12 阅读:47 评论:0
美化布局示例

欧易(OKX)最新版本

【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   全球官网 大陆官网

币安(Binance)最新版本

币安交易所app【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   官网地址

火币HTX最新版本

火币老牌交易所【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   官网地址
cyber attacks 2022

2022 年,政府支持的網絡攻擊顯著增加。其中許多攻擊是由所謂的高級持續威脅或 APT 實施的。這些團體與政府合作,也可能開展以營利為目的的非法活動。

In 2022, government-backed cyber attacks increased significantly. Many of these attacks were carried out by so-called high-level threats or APTs.

2022 年,外國實體在 DDoS 攻擊、間諜活動、勒索軟件攻擊和關鍵基礎設施漏洞中攻擊其他外國實體。這些攻擊引發了重大的供應鏈中斷,造成數十億美元的損失,並收集了大量信息作為間諜活動的一部分。

In 2022, foreign entities attacked other foreign entities in DDoS attacks, spy activities, extortion software attacks, and key infrastructure loopholes. These attacks caused major disruptions in the supply chain, causing billions of dollars in losses, and collected a great deal of information as part of the espionage campaign.

著眼於 2023 年世界可能面臨的情況,以下是 2022 年發生的 5 次毀滅性 APT 攻擊:

In view of what might happen to the world in 2023, the following five destructive APT attacks occurred in 2022:

2022 年,最令人震驚的 APT 攻擊之一是由一個名為APT 41 或 Double Dragon的組織實施的。該集團設法從亞洲和非洲的多個國家竊取了價值約 2000 萬美元的 COVID 救助資金。這次攻擊專門針對在大流行期間分發救濟金的銀行、政府機構和其他組織。據信,被盜資金是通過加密貨幣錢包洗錢的,因此難以追踪和追回。

One of the most striking APT attacks in 2022 was the operation of an organization called APT41 or Double Dragon. The group designed to steal about $20 million worth of COVID relief from several countries in Asia and Africa. The attack targeted banks, government institutions, and other organizations that divided grants during the epidemic.

特勤局的聲明表明,APT41 已經活躍了十多年,被認為是國家支持的中國網絡威脅組織,非常擅長執行間諜任務和金融犯罪以謀取私利。網絡專家以及來自多個機構的現任和前任官員已將 APT41 確定為有利於中國政府的網絡間諜活動的“主力軍”。隨著 COVID 救濟基金在 2020 年成為機會的目標,這種威脅變得比以往任何時候都更加相關。

According to a statement by the Secret Service, APT41 has been alive for more than a decade, is considered a state-sponsored Chinese cyber-threat organization, and is very good at spying and financial crimes for personal gain. Internet experts and current and former officials from several institutions have identified APT41 as a “master force” for the Chinese government’s cyber-intelligence activities. With the CIVD Rescue Fund becoming the target of opportunity in 2020, this threat has become more relevant than ever before.

11 月,美國網絡安全和基礎設施安全局 (CISA) 和聯邦調查局 (FBI) 發布了一份關於伊朗高級持續威脅 (APT) 的聯合網絡安全諮詢。名為Rampant Kitten的威脅行為者在 2 月利用一個著名的 Log4Shell 漏洞滲透到 VMware Horizon 服務器。

In November, the United States Cyber Security and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) issued a joint Internet security query on Iran's high-level and persistent threat (APT). The threatening actors called used a well-known Log4shell gap to penetrate VMware Horizon's server in February.

伊朗電腦黑客攻擊

這導致屬於美國績效系統保護委員會的聯邦網絡遭到破壞。作為回應,CISA 已警告所有未能應用 Log4Shell 補救措施的組織,以防止潛在的危害跡象。 《華盛頓郵報》將受影響的機構確定為美國績效系統保護委員會。這些類型的攻擊凸顯了企業和政府需要持續保持警惕並積極主動地保護關鍵基礎設施。

In response, CISA has warned all organizations that have failed to use Log4Shell to prevent potential damage. The Washington Post identified the affected institutions as the U.S.S.C. Protection Commission.

4 月,聯邦調查局 (FBI)、網絡安全和基礎設施安全局 (CISA) 和美國財政部 (Treasury) 發布的聯合網絡安全諮詢 (CSA) 警告稱,北方的加密貨幣盜竊行為可能引發網絡威脅韓國國家贊助的高級持續威脅 (APT) 組織稱為Lazarus Group、APT38、BlueNoroff 和 Stardust Chollima。

In April, the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA) and the United States Department of Finance (Treasury) issued a joint Internet security query (CSA) warning that the theft of encrypted currency in the north was a high-level and persistent threat that could lead to cyber threats against Korean countries' support (APT) organizations called Lazarus Group, APT38, Bluenoroff and Stardust Chollima.

至少從 2020 年開始,該組織就一直以區塊鏈技術和加密貨幣行業的組織為目標,例如加密貨幣交易所、DeFi 協議、玩賺錢的加密貨幣視頻遊戲、投資於加密貨幣的風險投資基金或持有大量數字貨幣的個人或有價值的 NFT。

Since at least 2020, the organization has been targeting organizations in the sector chain technology and crypto-currency industry, such as the Encrypted Currency Exchange, the DeFi agreement, a cash-for-money video game of encrypted currency, a venture capital fund for encryption currency, or a personal or valuable NFT holding large amounts of digital currency.

攻擊者一直在通過各種通信平台使用社會工程來說服受害者下載木馬化的加密貨幣應用程序。這使他們能夠訪問受害者的計算機、傳播惡意軟件並竊取私鑰或利用其他安全漏洞來啟動欺詐性區塊鏈交易。

The attackers have been using social projects through various communication platforms to convince victims to download carouseled encrypted currency applications. This has enabled them to interview their computer, spread malignant software and steal private keys or use other security loopholes to trigger fraudulent chain trading.

2022 年 4 月,伊朗高級持續威脅組織MuddyWater/APT 34發動了由政府資助的網絡攻擊,目標是亞洲、非洲、歐洲和北美多個部門的政府和私營部門組織,隸屬於伊朗情報和安全部(MOIS)。

In April 2022, the high-level Iranian threat organization launched a government-funded cyber attack targeting government and private sector organizations in several ministries in Asia, Africa, Europe and North America, belonging to the Iranian Ministry of Intelligence and Security (MOIS).

隨後,在 2020 年 9 月,美國聯邦政府以伊朗政府支持網絡犯罪活動為由對其實施制裁,他們聲稱這些活動是通過幾個高級持續威脅 (APT) 組織進行的。

Then, in September 2020, the US federal government sanctioned Iranian government support for cyber-crime activities that they claimed were carried out through several high-ranking APT organizations.

具體而言,美國財政部外國資產控制辦公室 (OFAC) 指定伊朗情報和安全部 (MOIS) 至少從 2007 年起就“從事針對美國及其盟友的網絡活動”。

Specifically, the U.S. Treasury Foreign Assets Control Office (OFAC) has designated the Iran Intelligence and Security Department (MOIS) to “act on the Internet against the U.S. and its allies” at least since 2007.

至少從 2020 年 1 月到 2022 年 2 月,美國聯邦調查局 (FBI)、國家安全局 (NSA) 和網絡安全與基礎設施安全局 (CISA) 確定了針對美國的常規網絡攻擊模式清除來自俄羅斯國家贊助的演員的國防承包商 (CDC)。

From at least January 2020 to February 2022, the United States Federal Bureau of Investigation (FBI), the National Security Agency (NSA) and the Agency for Cyber Security and Infrastructure Security (CISA) identified

這些攻擊採用了常見但有效的策略,例如魚叉式網絡釣魚、憑據收集、暴力/密碼噴射技術以及利用安全性較弱的帳戶和網絡中的已知漏洞。攻擊者還以 Microsoft 365 (M365) 環境為目標,通過使用合法憑證和惡意軟件進行數據洩露來維持持久性。

These attacks employ common but effective tactics, such as fork fishing, collection of evidence, violence/passport spraying techniques, and the use of known loopholes in less secure accounts and networks. The attackers also target Microsoft 365 (M365) for environmental sustainability by using legal certificates and malignant software.

上述攻擊在全球造成了重大破壞和數十億美元的損失。它們是出於地緣政治原因和貨幣利益而進行的。很明顯,APT 在未來幾年仍將是一種威脅,必須積極應對,以便公共和私營部門的實體可以將進一步的損害降至最低。?

These attacks have caused major damage and billions of dollars in losses around the world. They are being carried out for geopolitical reasons and currency interests. Clearly, the APT will remain a threat in the coming years and must be actively addressed so that the public and private sector entities can minimize further damage.

美化布局示例

欧易(OKX)最新版本

【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   全球官网 大陆官网

币安(Binance)最新版本

币安交易所app【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   官网地址

火币HTX最新版本

火币老牌交易所【遇到注册下载问题请加文章最下面的客服微信】永久享受返佣20%手续费!

APP下载   官网地址
文字格式和图片示例

注册有任何问题请添加 微信:MVIP619 拉你进入群

弹窗与图片大小一致 文章转载注明

分享:

扫一扫在手机阅读、分享本文

发表评论
平台列表
美化布局示例

欧易(OKX)

  全球官网 大陆官网

币安(Binance)

  官网

火币(HTX)

  官网

Gate.io

  官网

Bitget

  官网

deepcoin

  官网
热门文章
  • 0.00003374个比特币等于多少人民币/美金

    0.00003374个比特币等于多少人民币/美金
    0.00003374比特币等于多少人民币?根据比特币对人民币的最新汇率,0.00003374比特币等于2.2826 1222美元/16.5261124728人民币。比特币(BTC)美元(USDT)人民币(CNY)0.00003374克洛克-0/22216.5261124728比特币对人民币的最新汇率为:489807.72 CNY(1比特币=489807.72人民币)(1美元=7.24人民币)(0.00003374USDT=0.0002442776 CNY)。汇率更新于2024...
  • 0.00006694个比特币等于多少人民币/美金

    0.00006694个比特币等于多少人民币/美金
    0.00006694比特币等于多少人民币?根据比特币对人民币的最新汇率,0.00006694比特币等于4.53424784美元/32.5436 16人民币。比特币(BTC)美元(USDT)人民币(CNY)0.000066944.53424784【比特币密码】32.82795436 16比特币对人民币的最新汇率为:490408.64 CNY(1比特币=490408.64人民币)(1美元=7.24人民币)(0.00006694USDT=0.0004846456 CNY)汇率更新时...
  • 0.00015693个比特币等于多少人民币/美金

    0.00015693个比特币等于多少人民币/美金
    0.000 15693比特币等于多少人民币?根据比特币对人民币的最新汇率,0.000 15693比特币等于10.6 1678529美元/76.86554996人民币。比特币(BTC)【比特币价格翻倍】美元(USDT)人民币(CNY)0.000/克洛克-0/5693【数字货币矿机】10.6 167852976.8655254996比特币对人民币的最新汇率为:489,807.72 CNY(1比特币= 489,807.72人民币)(1美元=7.24人民币)(0.00015693 U...
  • 2000年美国GDP占世界的304%,中国GDP仅占35%,现在呢?

    2000年美国GDP占世界的304%,中国GDP仅占35%,现在呢?
    GDP作为全球公认的实力基准,就像是一个大国实力的代言人,它是布雷顿森林体系下全球团结的声音。它不仅仅是数字的累积,更是大国综合实力的人格化,默默诉说着每个国家的辉煌与荣耀。虽然GDP不是衡量一个国家综合实力的唯一标准,但无疑是最关键的指标之一。作为一面镜子,它反映了国家的经济实力和发展水平,是国家综合实力的重要体现,不容忽视。2000年,中国GDP迈过/克洛克-0/万亿美元的重要门槛,达到/克洛克-0/。2/克洛克-0/万亿美元(折合人民币7。7万亿元)。然而,在全球经济的...
  • 币圈院士:5.20比特币(BTC)以太坊(ETH)行情分析

    币圈院士:5.20比特币(BTC)以太坊(ETH)行情分析
    利空出尽?华尔街多头坚信美股将摆脱泥潭 经济衰退风险被夸大A lot of people on Wall Street believe that beauty will escape the quagmire; the risk of recession is exaggerated. 从目前美国经济的情况加上美股先有的走势来判断,确信通胀已经或即将见顶,这为价格压力回落铺平了道路,这最终将使美联储得以放缓...
标签列表