卡巴斯基揭示第二季度APT趋势新动态

TAIPEI, TAIWAN - Media OutReach - 4 August 2023 - In Kaspersky's latest report on Advanc...

TAIPEI, TAIWAN - Media OutReach - 4 August 2023 - In Kaspersky's latest report on Advanced Persistent Threats (APTs) trends for the second quarter of 2023, researchers analyze the development of new and existing campaigns. The report highlights APT activity during this period including the updating of toolsets, the creation of new malware variants, and the adoption of fresh techniques by threat actors.

A significant new revelation was the exposure of the long-running "Operation Triangulation" campaign involving the use of a previously unknown iOS malware platform. Experts also observed other interesting developments that they believe everyone should be aware of. Here are key highlights from the report:

Asia-Pacific witnesses a new threat actor – Mysterious Elephant

Kaspersky uncovered a new threat actor belonging to the Elephants family, operating in the Asia-Pacific region, dubbed "Mysterious Elephant". In their latest campaign, the threat actor employed new backdoor families, capable of executing files and commands on the victim's computer, and receive files or commands from a malicious server for execution on the infected system. While Kaspersky researchers have observed overlaps with Confucius and SideWinder, Mysterious Elephant possesses a distinctive and unique set of TTPs, setting them apart from these other groups.

Toolsets upgraded: Lazarus' develops new malware variant, BlueNoroff attacks macOS, and more

Threat actors are constantly improving their techniques, with Lazarus upgrading its MATA framework and introducing a new variant of the sophisticated MATA malware family, MATAv5. BlueNoroff, a financial attack-focused subgroup of Lazarus, now employs new delivery methods and programming languages, including the use of Trojanized PDF readers in recent campaigns, the implementation of macOS malware, and the Rust programming language. Additionally, ScarCruft APT group has developed new infection methods, evading Mark-of-the-Web (MOTW) security mechanism. The ever-evolving tactics of these threat actors present new challenges for cybersecurity professionals.

Geopolitical influences remain primary drivers of APT activity

APT campaigns remain geographically dispersed, with actors concentrating their attacks on regions such as Europe, Latin America, the Middle East and various parts of Asia. Cyber-espionage, with a solid geopolitical backdrop, continues to be a dominant agenda for these endeavors.

Adrian Hia, Managing Director for APAC at Kaspersky said "Kaspersky has been monitoring all the active APT actors in the region that infect mobile devices and are slowly targeting businesses and infrastructure. Our researchers focuses on APT activities to uncover the most sophisticated cyber-attacks. By publishing our findings from our investigation, we hope to be able to help organisations be aware of the latest activities and remain secure in our bid to build a safer world."

"While some threat actors stick to familiar tactics like social engineering, others have evolved, refreshing their toolsets and expanding their activities. Moreover, new advanced actors, such those conducting the 'Operation Triangulation' campaign, constantly emerge. This actor uses a previously unknown iOS malware platform distributed through zero-click iMessage exploits. Staying vigilant with threat intelligence and the right defense tools is crucial for global companies, so they can protect themselves against both existing and emerging threats. Our quarterly reviews are designed to highlight the most significant developments among APT groups to help defenders combat and mitigate related risks," comments David Emm, principal security researcher at Kaspersky's Global Research and Analysis Team (GReAT).

To read the full APT Q2 2023 trends report, please visit Securelist.
In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky researchers recommend implementing the following measures:

Ensuring the security of your system, it is crucial to promptly update your operating system and other third-party software to their latest versions. Maintaining a regular update schedule is essential in order to stay protected from potential vulnerabilities and security risks Upskill your cybersecurity team to tackle the latest targeted threats with Kaspersky online training developed by GReAT experts. Use the latest Threat Intelligence information to stay up-to-date with the actual TTPs used by threat actors. For endpoint level detection, investigation, and timely remediation of incidents, implement EDR solutions such as Kaspersky Endpoint Detection and Response. Dedicated services can help combat high-profile attacks. The Kaspersky Managed Detection and Response service can help identify and stop intrusions in their early stages, before the perpetrators achieve their goals. If you encounter an incident, Kaspersky Incident Response service will help you respond and minimize the consequences, in particular - identify compromised nodes and protect the infrastructure from similar attacks in the future.
Hashtag: #Kaspersky

发行人对本公告内容全权负责。

本文来自作者[访客]投稿,不代表nslqa号立场,如若转载,请注明出处:https://m.nslqa.cn/keji/202507-1332.html

(11)

文章推荐

  • 蓝桥渡轮:海事联盟警示健康与安全风险

      “康尼马拉”号将留在惠灵顿港的码头,直到新西兰海事局的调查完成。英国海事工会表示,在库克海峡渡轮发生一系列严重事件后,工会“非常担心”工人和乘客的安全。在失去动力并开始在库克海峡漂流大约五个半小时后,蓝桥渡轮康尼马拉今天早上返回惠灵顿。这是库克海峡渡轮一系列中断、延误和问

    2025年06月29日
    7
  • 避免这9个园艺误区,保护你的草坪——今年秋天的必知事项

    秋季和冬季对园丁来说是一个棘手的时期,所以人们应该注意确保他们遵循了最好的建议。关于草坪和花园护理的常见误解可能会导致人们走上错误的道路,并可能在春天再次到来时留下不太理想的结果。人们可能会被9个常见的误解所欺骗,了解它们是什么很重要。两位专家告诉BetterHo

    2025年07月13日
    11
  • 调查揭示:英国消费者对新政府的警告感到恐慌

    路透伦敦8月12日电---周五公布的一项调查显示,英国首相斯塔默对英国经济状况的警告,以及下个月预算可能需要增税,导致本月消费者信心大跌。GfK消费者信心指数从8月的-13降至9月的六个月低点-20,这是近三年来的最高水平。路透对经济学家的调查

    2025年07月15日
    12
  • 莫斯科致命枪击案:俄罗斯拘留24名嫌疑人

    重铸24还押在押,增加新的弗拉迪斯拉夫引用,pix,背景周五,莫斯科市中心发生枪战,造成两人死亡,俄罗斯下令拘留24人,其中包括一名车臣综合格斗选手。周三,一群男子出现在俄罗斯零售巨头Wildberries的办公室,首席执行官塔季扬娜·巴卡尔丘克称

    2025年07月18日
    7
  • 内马尔首场亮相,阿尔希拉尔以6-1狂胜利雅得

    利雅得,9月16日——周五,巴西历史上进球最多的球员内马尔在沙特职业联赛首次代表阿尔希拉尔出场,在他的新俱乐部6-1大胜利雅得的比赛中替补出场,打满了最后26分钟。这位31岁的球员上个月以9000万欧元(合4.4495亿令吉)从巴

    2025年07月30日
    10
  • 消逝的Guaidó幽影

      美国再次恢复了其老策略之一,即承认反对派候选人——这次是埃德蒙多González——是委内瑞拉最新总统选举的获胜者,尽管官方计票结果并非如此。美国国务卿安东尼·布林肯在周四发表的一份声明中宣布了这一决定,他在引用据称对González有利的“压倒性证据”之前呼吁和平过渡权力。美国

    2025年07月31日
    10
  • 10月1日的太平洋新闻

      (文件图片)图瓦卢语图瓦卢语言周在新西兰奥特罗阿开始。今年的主题是“维护你的语言和方言,因为这是你的身份”。根据2018年的人口普查,居住在新西兰的图瓦卢人中有48%会说加纳图瓦卢语。包括语言指南、活动日程和文化内容在内的资源将在太平洋人民事务部的网站上提供。

    2025年08月05日
    11
  • 今日实测“广客麻将可以开挂吗安卓”分享装挂步骤

    广客麻将可以开挂吗安卓是一款可以让一直输的玩家,快速成为一个“必胜”的ai辅助神器,有需要的用户可以加我微下载使用。手机打牌可以一键让你轻松成为“必赢”。其操作方式十分简单,打开这个应用便可以自定义手机打牌系统规律,只需要输入自己想要的开挂功能,一键便可以生成

    2025年08月10日
    16
  • 重大通报“微乐麻将如何开挂打麻将”太坑人了,真的有挂

    微乐麻将如何开挂打麻将是一款可以让一直输的玩家,快速成为一个“必胜”的ai辅助神器,有需要的用户可以加我微下载使用。微乐麻将可以一键让你轻松成为“必赢”。其操作方式十分简单,打开这个应用便可以自定义微乐麻将系统规律,只需要输入自己想要的开挂功能,一键便可以生成

    2025年08月10日
    10
  • Insight Vacations推出2025年100多个小型团体旅行计划

    旅游公司旗下的商务舱旅游品牌InsightVacations在2024年销售一空后,增加了2025年的小团体旅游产品。InsightVacations的团队游平均只有20位客人(最多不超过24位),其中包括新推出的女性小型团队游系列,将向游客介绍100条全球行程,

    2025年08月11日
    8

发表回复

本站作者后才能评论

评论列表(4条)

  • 访客
    访客 2025年07月23日

    我是nslqa号的签约作者“访客”!

  • 访客
    访客 2025年07月23日

    希望本篇文章《卡巴斯基揭示第二季度APT趋势新动态》能对你有所帮助!

  • 访客
    访客 2025年07月23日

    本站[nslqa号]内容主要涵盖:国足,欧洲杯,世界杯,篮球,欧冠,亚冠,英超,足球,综合体育

  • 访客
    访客 2025年07月23日

    本文概览:TAIPEI, TAIWAN - Media OutReach - 4 August 2023 - In Kaspersky's latest report on Advanc...

    联系我们

    邮件:nslqa号@sina.com

    工作时间:周一至周五,9:30-18:30,节假日休息

    关注我们