卡巴斯基揭示第二季度APT趋势新动态

TAIPEI, TAIWAN - Media OutReach - 4 August 2023 - In Kaspersky's latest report on Advanc...

TAIPEI, TAIWAN - Media OutReach - 4 August 2023 - In Kaspersky's latest report on Advanced Persistent Threats (APTs) trends for the second quarter of 2023, researchers analyze the development of new and existing campaigns. The report highlights APT activity during this period including the updating of toolsets, the creation of new malware variants, and the adoption of fresh techniques by threat actors.

A significant new revelation was the exposure of the long-running "Operation Triangulation" campaign involving the use of a previously unknown iOS malware platform. Experts also observed other interesting developments that they believe everyone should be aware of. Here are key highlights from the report:

Asia-Pacific witnesses a new threat actor – Mysterious Elephant

Kaspersky uncovered a new threat actor belonging to the Elephants family, operating in the Asia-Pacific region, dubbed "Mysterious Elephant". In their latest campaign, the threat actor employed new backdoor families, capable of executing files and commands on the victim's computer, and receive files or commands from a malicious server for execution on the infected system. While Kaspersky researchers have observed overlaps with Confucius and SideWinder, Mysterious Elephant possesses a distinctive and unique set of TTPs, setting them apart from these other groups.

Toolsets upgraded: Lazarus' develops new malware variant, BlueNoroff attacks macOS, and more

Threat actors are constantly improving their techniques, with Lazarus upgrading its MATA framework and introducing a new variant of the sophisticated MATA malware family, MATAv5. BlueNoroff, a financial attack-focused subgroup of Lazarus, now employs new delivery methods and programming languages, including the use of Trojanized PDF readers in recent campaigns, the implementation of macOS malware, and the Rust programming language. Additionally, ScarCruft APT group has developed new infection methods, evading Mark-of-the-Web (MOTW) security mechanism. The ever-evolving tactics of these threat actors present new challenges for cybersecurity professionals.

Geopolitical influences remain primary drivers of APT activity

APT campaigns remain geographically dispersed, with actors concentrating their attacks on regions such as Europe, Latin America, the Middle East and various parts of Asia. Cyber-espionage, with a solid geopolitical backdrop, continues to be a dominant agenda for these endeavors.

Adrian Hia, Managing Director for APAC at Kaspersky said "Kaspersky has been monitoring all the active APT actors in the region that infect mobile devices and are slowly targeting businesses and infrastructure. Our researchers focuses on APT activities to uncover the most sophisticated cyber-attacks. By publishing our findings from our investigation, we hope to be able to help organisations be aware of the latest activities and remain secure in our bid to build a safer world."

"While some threat actors stick to familiar tactics like social engineering, others have evolved, refreshing their toolsets and expanding their activities. Moreover, new advanced actors, such those conducting the 'Operation Triangulation' campaign, constantly emerge. This actor uses a previously unknown iOS malware platform distributed through zero-click iMessage exploits. Staying vigilant with threat intelligence and the right defense tools is crucial for global companies, so they can protect themselves against both existing and emerging threats. Our quarterly reviews are designed to highlight the most significant developments among APT groups to help defenders combat and mitigate related risks," comments David Emm, principal security researcher at Kaspersky's Global Research and Analysis Team (GReAT).

To read the full APT Q2 2023 trends report, please visit Securelist.
In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky researchers recommend implementing the following measures:

Ensuring the security of your system, it is crucial to promptly update your operating system and other third-party software to their latest versions. Maintaining a regular update schedule is essential in order to stay protected from potential vulnerabilities and security risks Upskill your cybersecurity team to tackle the latest targeted threats with Kaspersky online training developed by GReAT experts. Use the latest Threat Intelligence information to stay up-to-date with the actual TTPs used by threat actors. For endpoint level detection, investigation, and timely remediation of incidents, implement EDR solutions such as Kaspersky Endpoint Detection and Response. Dedicated services can help combat high-profile attacks. The Kaspersky Managed Detection and Response service can help identify and stop intrusions in their early stages, before the perpetrators achieve their goals. If you encounter an incident, Kaspersky Incident Response service will help you respond and minimize the consequences, in particular - identify compromised nodes and protect the infrastructure from similar attacks in the future.
Hashtag: #Kaspersky

发行人对本公告内容全权负责。

本文来自作者[访客]投稿,不代表nslqa号立场,如若转载,请注明出处:https://www.nslqa.cn/keji/202507-1332.html

(10)

文章推荐

  • 美国关注乌克兰对俄罗斯的“动机”

      白宫在星期三表示,正在与美国的主要盟友乌克兰进行联系,以进一步了解基辅几个月来对俄罗斯领土的最严重越境入侵的“目的”。白宫新闻秘书让-皮埃尔(KarineJean-Pierre)在被问及此次行动时表示:“我们将与乌克兰军方进行接触,以更深入地了解他们的目

    2025年06月29日
    5
  • 迪尔沃斯补偿计划未涵盖贩毒恋童癖团伙的受害者

    迪尔沃斯学校的赔偿计划排除了一个贩卖毒品的恋童癖团伙的受害者,一些幸存者的倡导者说这个过程严重缺乏透明度。但迪尔沃斯表示,在制定该计划之前,他们征求了广泛的反馈意见,并努力确保幸存者及其家人受到保护。一个虐待儿童团伙涉及现已入狱的韦恩·吉尔曼·穆尼,据称

    2025年07月04日
    8
  • 逃往法国的拳击手被判刑四年半

    ITV新闻的罗伯特·墨菲从布里斯托尔刑事法庭发回报道一名男子在逃往法国之前一拳打死了一名父亲,他被判入狱四年半。2022年2月,在布里斯托尔一家民谣俱乐部,59岁的加里·塞尔伍德对69岁的保罗·卡特进行了“无缘无故”和“无理”的殴打。

    2025年07月07日
    10
  • 澳大利亚的跳鼠与亚洲缺乏袋鼠的背后原因

    澳大利亚的动物与亚洲的动物大不相同。这是不言而喻的;我们知道澳大利亚到处都是地球上其他地方找不到的奇怪而奇妙的生物,比如鸭嘴兽和考拉。但你可能会惊讶地发现,我们的许多最具代表性的动物都来自亚洲,而且是最近才到达的(至少在地质学上是这

    2025年07月15日
    11
  • 天朝福利解决方案公司成功签署CityWestPlace租约

      一家人力资源技术公司与CityWestPlace达成了租约,使得位于休斯顿西部的39英亩办公园区的入住率达到了令人瞩目的98%。EmpyreanBenefitSolutions在4号楼租用了41,667平方英尺的空间,计划于2025年初入驻。CityWes

    2025年07月22日
    12
  • 阿卡普尔科居民在援助不足的情况下自我救助

    阿卡普尔科,墨西哥(美联社)——在一个没有水,电和汽油的城市,自从飓风奥蒂斯袭击阿卡普尔科以来,绝望的人们被允许甚至鼓励从受损的商店里购买必需品,州警察RaúlGallardo守卫着一座多余的山。加拉多解释说,在某些情况下,当局一直在区分人们可以拿走的东西和他最

    2025年08月04日
    7
  • 莫迪3.0时代:推动官僚横向流动,引入45位领域专家

    新德里,8月17日(IANS):在本周的重大官僚机构改组中,总理纳伦德拉·莫迪领导的制度为在联合秘书和政府部门其他高级职位上拥有专业知识的专业人士打开了大门。横向入职申请涉及24个中央部委的至少45个联合秘书、主任和副秘书职位。值得注意

    2025年08月04日
    9
  • Z世代的浪漫新解:炖约会究竟是什么?

    约会应用QuackQuack's对z世代约会模式和倾向的最新研究发现,47%的z世代约会者喜欢采取慢节奏的方式,称之为“慢炖约会”。“这种趋势侧重于逐渐积累,在寻找伴侣时强调耐心。”“慢炖约会是一个慢慢了解彼此、探索彼此关系的过程,而不是急于承诺和排他性的过程。这是关于让关系有机

    2025年08月07日
    7
  • 科普一下“微乐麻将作弊开挂”分享装挂步骤

    微乐麻将作弊开挂是一款可以让一直输的玩家,快速成为一个“必胜”的ai辅助神器,有需要的用户可以加我微下载使用。微乐麻将可以一键让你轻松成为“必赢”。其操作方式十分简单,打开这个应用便可以自定义微乐麻将系统规律,只需要输入自己想要的开挂功能,一键便可以生成出微乐

    2025年08月11日
    11
  • 终于找到“边锋斗地主挂在哪个位置”确实果然有挂

    边锋斗地主挂在哪个位置是一款可以让一直输的玩家,快速成为一个“必胜”的ai辅助神器,有需要的用户可以加我微下载使用。手机打牌可以一键让你轻松成为“必赢”。其操作方式十分简单,打开这个应用便可以自定义手机打牌系统规律,只需要输入自己想要的开挂功能,一键便可以生成

    2025年08月11日
    9

发表回复

本站作者后才能评论

评论列表(4条)

  • 访客
    访客 2025年07月23日

    我是nslqa号的签约作者“访客”!

  • 访客
    访客 2025年07月23日

    希望本篇文章《卡巴斯基揭示第二季度APT趋势新动态》能对你有所帮助!

  • 访客
    访客 2025年07月23日

    本站[nslqa号]内容主要涵盖:国足,欧洲杯,世界杯,篮球,欧冠,亚冠,英超,足球,综合体育

  • 访客
    访客 2025年07月23日

    本文概览:TAIPEI, TAIWAN - Media OutReach - 4 August 2023 - In Kaspersky's latest report on Advanc...

    联系我们

    邮件:nslqa号@sina.com

    工作时间:周一至周五,9:30-18:30,节假日休息

    关注我们