ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø

EnglishÈÕ±¾ÕZ

¹¤Òµ»¥ÁªÍøÇ徲רÌâ > Çå¾²×ÊѶ

ÎÚ¿ËÀ¼¶ÏµçÊÂÎñ¡¢NotPetya±¬·¢¡¢Æ½²ý¶¬°Â»áÍøÂç°µÕ½µÄÄ»ºóÖ÷ʹÃûµ¥

×÷Õߣºkirazhou 2020-10-20

×òÌ죬ÃÀ¹ú˾·¨²¿¶ÔÁùÃûGRU£¨¶íÂÞ˹¾üÊÂÇ鱨¾Ö£©74455²¿·Ö¹ÙÔ±ÌᳫÁËÆðËߣ¬Ö¸¿ØËûÃÇÊǺڿÍ×éÖ¯SandwormµÄ³ÉÔ±¡£

1.png

ÒÔÏÂÊDZ»¸æÐÕÃû¼°Ïà¶Ô×ïÃû

2.png

ÃÀ¹ú¹ÙÔ±ÌåÏÖ£¬×÷Ϊ¡°¹ú¼ÒÔÞÖú¡±µÄºÚ¿Í×éÖ¯£¬Õâ6Ãû³ÉÔ±ÔÚ¶íÂÞ˹Õþ¸®µÄÏÂÁîϾÙÐÐÁË¡°ÆÆËðÐÔ¡±ÍøÂç¹¥»÷£¬Ä¿µÄÊÇÆÆËðÆäËû¹ú¼ÒµÄÎȹÌ£¬¸ÉÔ¤Ëû¹úÕþÖβ¢Ôì³ÉÆÆËðºÍÖ±½Ó¿î×ÓËðʧ¡£

Ïà¹Ø¹¥»÷³¤´ïÊ®Ä꣬°üÀ¨Æù½ñΪֹÒÑÖªµÄһЩ´óÐÍÍøÂç¹¥»÷£º

ÎÚ¿ËÀ¼¶Ïµç£º´Ó2015Äê12Ôµ½2016Äê12Ô£¬Sandworm×é֯ʹÓÃÕë¶Ô¹¤Òµ×°±¸µÄ¶ñÒâÈí¼þ£¬È«ÐIJ߻®ÁËÕë¶ÔÎÚ¿ËÀ¼µçÍø¡¢ÎÚ¿ËÀ¼²ÆÎñ²¿µÄÆÆËðÐÔ¶ñÒâÈí¼þ¹¥»÷¡£ÆäÖУ¬2015ÄêºÍ2016Äê»®·ÖʹÓÃBlackEnergyºÍIndustroyer£¬±ðµÄ»¹Ê¹ÓÃÁËKillDisk£¬½ø¶øµ¼ÖÂÊýÊ®ÍòÓû§ÔÚÊ¥µ®½ÚÇ°Á½Ìì±»¶Ïµç¡£

·¨¹ú´óÑ¡£º2017Äê4ÔºÍ5Ô£¬SandwormÕë¶Ô·¨¹ú×ÜͳMacronÈ«ÐIJ߻®ÁËÓã²æÔ˶¯ºÍÏà¹ØµÄhack and leakÐж¯¡£

NotPetyaÀÕË÷Èí¼þ±¬·¢£º2017Ä꣬NotPetyaÀÕË÷Èí¼þ¹¥»÷±¬·¢¡£¸ÃÀÕË÷Èí¼þ×î³õÊÇÕë¶ÔÎÚ¿ËÀ¼¹«Ë¾µÄ£¬ØʺóѸËÙÈö²¥²¢Ó°ÏìÁËÌìϸ÷µØµÄ¹«Ë¾£¬ÆäʱÔì³ÉÁËÁè¼Ý10ÒÚÃÀÔªµÄËðʧ¡£Æ¾Ö¤ÃÀ¹úÉó²é¹ÙµÄ˵·¨£¬NotPetya¹¥»÷µÄÄ»ºóºÚÊÖÕýÊÇSandworm¡£

Õë¶Ôƽ²ý¶¬°Â»áµÄÖ÷Àí·½¡¢¼ÓÈëÕߵȵĹ¥»÷£ºÔÚ2017Äê12ÔÂÖÁ2018Äê2ÔÂÖ®¼ä£¬Sandworm»¹ÌᳫÁËÕë¶Ôº«¹ú¹«Ãñ¡¢¹ÙÔ±¡¢°ÂÁÖÆ¥¿ËÔË·¢¶¯¡¢ÏàÖúͬ°éºÍ·Ã¿ÍµÈµÄÓã²æ¹¥»÷Ðж¯ºÍ¶ñÒâÒƶ¯Ó¦ÓóÌÐò·Ö·¢¡£¶øÔµ¹ÊÔ­ÓɺܿÉÄÜÊÇÌìÏ·´Ð˷ܼÁ×éÖ¯Ðû²¼¶íÂÞ˹ÔË·¢¶¯±»Õ¥È¡¼ÓÈëÌåÓý½ÇÖð£¬ÎÞÔµ¶¬°Â»á¡£

Õë¶Ôƽ²ý¶¬°Â»áITϵͳµÄ¹¥»÷£¨OlympicDestroyer£©£º´Ó2017Äê12Ôµ½2018Äê2Ô£¬SandwormÈ«ÐIJ߻®Á˶Ô2018Äêƽ²ý¶¬°Â»áµÄÅÌËã»úϵͳµÄÈëÇÖ£¬¸ÃÐж¯ÔÚ2018Äê2ÔÂ9ÈÕµÖ´ïÁËá۷壬²¢Ðû²¼ÁËÆÆËðÐԵĶñÒâÈí¼þOlympicDestroyer¡£µ±Ì죬»¥ÁªÍø¡¢¹ã²¥ÏµÍ³ºÍ°ÂÔË»áÍøÕ¾¶¼·ºÆðÁËÎÊÌâ¡£Ðí¶à¹ÛÖÚÎÞ·¨´òÓ¡ËûÃǵÄÈ볡ȯ£¬µ¼ÖÂ×ùλ¿ÕÖá£

±ðµÄ£¬ÉÐÓÐNovichokÉñ¾­¶¾¼Á¹¥»÷ÊÂÎñ¡¢¸ñ³¼ªÑÇÒé»áÍøÂç¹¥»÷ÊÂÎñµÄÄ»ºóÖ÷ʹ¶¼±»ÃÀ¹úÖ¸Ïò¶íÂÞ˹¡£

ÈôÊÇÕâЩ³ÉÔ±±»Òý¶Éµ½ÃÀ¹ú£¬ËûÃǽ«ÃæÁÙÊýÊ®ÄêµÄî¿ÏµÊ±¼ä¡£µ«Æ¾Ö¤Áª°îÊÓ²ìÖ°Ô±µÄ˵·¨£¬ËùÓÐÁùÃûÏÓÒÉÈ˶¼ÊǶíÂÞ˹סÃñ¡£Òò´Ë£¬ÔÚ²»Ì«¿ÉÄܾÙÐоⶻòÒý¶ÉµÄÇéÐÎÏ£¬ÆðËßÊé¸ü¶àµØÊÇÏò¸Ã¹úÕþ¸®ÔÞÖúµÄºÚ¿Í·¢³öÖÒÑÔ£¬¼û¸æÆäÉí·Ý²»»áÓÀÔ¶±»Òþ²Ø¡£

ÁíÍ⣬ÔÚͨ¸æÖÐûÓÐÃ÷ȷ˵Ã÷ÃÀ¹úÔõÑùʶ±ðÏÓÒÉ·¸¡£¿ÉÊÇFBIÓë°üÀ¨Ó¢¹úÇ鱨·þÎñ²¿·ÖÔÚÄÚµÄÍâÑóÖ´·¨»ú¹¹ÏàÖú£¬²¢ÓëCiscoºÍGoogleµÄÇå¾²Ñо¿Ö°Ô±ÏàÖú£¬ÒÔ·¢Ã÷¸Ã×éÖ¯µÄÔ˶¯¡£

×îºó£¬ÍŽᶫ¾©°ÂÔË»áµÄ×¼±¸£¨ÒÑÍƳٵ½Ã÷Ä꣩£¬Ó¢¹ú·½ÃæÌåÏÖ£¬¶íÂÞ˹ÕýÔÚ×¼±¸Õë¶Ô¶«¾©°ÂÔË»áµÄÍøÂç¹¥»÷£¬Õâһ˼Á¿²¢²»ÊÇûÓÐÔ­Àí£¬Ô¤¼Æ¹¥»÷ÈÔÈ»ÊÇÕë¶Ô¾ÙÐз½¡¢¼ÓÈëÕßÒÔ¼°ÅÌËãϵͳÉèÊ©µÄ£¬¹ØÓÚSandwormµÄСÐĺÍÌá·ÀÐèÒªÔöÇ¿¡£

²Î¿¼ÈªÔ´£º

zdnet


£¨×ªÔØÀ´×Ô£ºFreeBuf.com£©

ÉÏһƪ ÏÂһƪ

·þÎñÈÈÏß

400-624-3900



ÍøÕ¾µØͼ