卡巴斯基揭示第二季度APT趋势新动态

TAIPEI, TAIWAN - Media OutReach - 4 August 2023 - In Kaspersky's latest report on Advanc...

TAIPEI, TAIWAN - Media OutReach - 4 August 2023 - In Kaspersky's latest report on Advanced Persistent Threats (APTs) trends for the second quarter of 2023, researchers analyze the development of new and existing campaigns. The report highlights APT activity during this period including the updating of toolsets, the creation of new malware variants, and the adoption of fresh techniques by threat actors.

A significant new revelation was the exposure of the long-running "Operation Triangulation" campaign involving the use of a previously unknown iOS malware platform. Experts also observed other interesting developments that they believe everyone should be aware of. Here are key highlights from the report:

Asia-Pacific witnesses a new threat actor – Mysterious Elephant

Kaspersky uncovered a new threat actor belonging to the Elephants family, operating in the Asia-Pacific region, dubbed "Mysterious Elephant". In their latest campaign, the threat actor employed new backdoor families, capable of executing files and commands on the victim's computer, and receive files or commands from a malicious server for execution on the infected system. While Kaspersky researchers have observed overlaps with Confucius and SideWinder, Mysterious Elephant possesses a distinctive and unique set of TTPs, setting them apart from these other groups.

Toolsets upgraded: Lazarus' develops new malware variant, BlueNoroff attacks macOS, and more

Threat actors are constantly improving their techniques, with Lazarus upgrading its MATA framework and introducing a new variant of the sophisticated MATA malware family, MATAv5. BlueNoroff, a financial attack-focused subgroup of Lazarus, now employs new delivery methods and programming languages, including the use of Trojanized PDF readers in recent campaigns, the implementation of macOS malware, and the Rust programming language. Additionally, ScarCruft APT group has developed new infection methods, evading Mark-of-the-Web (MOTW) security mechanism. The ever-evolving tactics of these threat actors present new challenges for cybersecurity professionals.

Geopolitical influences remain primary drivers of APT activity

APT campaigns remain geographically dispersed, with actors concentrating their attacks on regions such as Europe, Latin America, the Middle East and various parts of Asia. Cyber-espionage, with a solid geopolitical backdrop, continues to be a dominant agenda for these endeavors.

Adrian Hia, Managing Director for APAC at Kaspersky said "Kaspersky has been monitoring all the active APT actors in the region that infect mobile devices and are slowly targeting businesses and infrastructure. Our researchers focuses on APT activities to uncover the most sophisticated cyber-attacks. By publishing our findings from our investigation, we hope to be able to help organisations be aware of the latest activities and remain secure in our bid to build a safer world."

"While some threat actors stick to familiar tactics like social engineering, others have evolved, refreshing their toolsets and expanding their activities. Moreover, new advanced actors, such those conducting the 'Operation Triangulation' campaign, constantly emerge. This actor uses a previously unknown iOS malware platform distributed through zero-click iMessage exploits. Staying vigilant with threat intelligence and the right defense tools is crucial for global companies, so they can protect themselves against both existing and emerging threats. Our quarterly reviews are designed to highlight the most significant developments among APT groups to help defenders combat and mitigate related risks," comments David Emm, principal security researcher at Kaspersky's Global Research and Analysis Team (GReAT).

To read the full APT Q2 2023 trends report, please visit Securelist.
In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky researchers recommend implementing the following measures:

Ensuring the security of your system, it is crucial to promptly update your operating system and other third-party software to their latest versions. Maintaining a regular update schedule is essential in order to stay protected from potential vulnerabilities and security risks Upskill your cybersecurity team to tackle the latest targeted threats with Kaspersky online training developed by GReAT experts. Use the latest Threat Intelligence information to stay up-to-date with the actual TTPs used by threat actors. For endpoint level detection, investigation, and timely remediation of incidents, implement EDR solutions such as Kaspersky Endpoint Detection and Response. Dedicated services can help combat high-profile attacks. The Kaspersky Managed Detection and Response service can help identify and stop intrusions in their early stages, before the perpetrators achieve their goals. If you encounter an incident, Kaspersky Incident Response service will help you respond and minimize the consequences, in particular - identify compromised nodes and protect the infrastructure from similar attacks in the future.
Hashtag: #Kaspersky

发行人对本公告内容全权负责。

本文来自作者[访客]投稿,不代表nslqa号立场,如若转载,请注明出处:https://wap.nslqa.cn/keji/202507-1332.html

(9)

文章推荐

  • 索托格兰德的拉坎查二世遭遇大火焚毁

      9月30日凌晨,位于索托格兰德阿亚拉马球俱乐部的LaCanchaII被大火烧毁。没有人受伤的报道,然而,这家受欢迎的阿根廷烧烤餐厅的结构几乎没有留下痕迹。这家餐厅距离索托格兰德只有几公里,几乎完全由木头建造。消防队员在半夜紧急出动

    2025年06月27日
    5
  • 瓜迪奥拉:凯文是个独特的传奇球员,我还能说什么呢?

      瓜迪奥拉表示,他已经无言以对曼城的“传奇”凯文·德布鲁因。这位比利时中场替补出场,帮助曼城扳平比分,随后在补时阶段为奥斯卡·鲍勃打入制胜球,这是这位挪威小将在英超的首个进球,比赛在圣詹姆斯公园球场以戏剧性的方式结束。德布鲁因在经历了五个月的伤

    2025年07月20日
    11
  • 阿萨姆邦首席部长希曼塔·比斯瓦·萨尔马依据国家食品安全法案向超过400万新受益者发放配给卡

    周二,阿萨姆邦首席部长HimantaBiswaSarma出席了根据《国家粮食安全法》向4285745名新受益人分发配给卡的仪式,该活动在古瓦哈提的马里加翁的博里帕拉地区举行。首席部长希曼塔·比斯瓦·萨尔马在活动上说,在国家食品安全保障计划下,该邦又增加了400多万受益人,这是

    2025年07月27日
    9
  • 邦妮:为马来西亚的金牌,我战胜了艰难

    巴黎——今天,在2024年巴黎残奥会男子72公斤级举重比赛中,国家举重明星邦妮·邦尤·古斯汀克服了严重的左肩疼痛,保住了金牌。邦妮从上周开始就一直在与伤病作斗争,她透露,疼痛是在拉夏贝尔门体育馆训练时开始的,导致了明显的肿胀。“第一次举起来很痛苦,每次

    2025年07月28日
    8
  • 目击三名小偷在博物馆盗取20万美元手枪的瞬间

    两个地点都建立了犯罪现场,隶属于国家犯罪司令部毒品和火器小组的侦探调查了这起事件。毒品和枪支小组指挥官,侦探警司约翰·沃森说,人们确实担心这些枪支可能在诺拉、利特戈和更广泛的社区。“这起犯罪与新南威尔士州的多个地区有关,所以

    2025年07月31日
    7
  • 易捷航空向爱丁堡机场度假旅客发出重要干扰提示

      意大利交通和基础设施部警告称,意大利易捷航空公司的飞行员计划本月晚些时候罢工。罢工定于10月27日星期日举行,将影响易捷航空飞往米兰、那不勒斯和威尼斯的航班,这些都是度假者逃离寒冷天气和黑暗夜晚的热门目的地。该活动将在当地时间当天下午1点到5点之间进行。然而,由于“多米诺骨

    2025年08月04日
    9
  • Gosport Asda超市遭窃,价值1.3万英镑香烟被盗

    一家商店价值1.3万英镑的香烟被盗,警方正在追捕一群黑衣男子。汉普郡警察局的警官正在调查今天凌晨发生的两起盗窃案。商店是强行进入的,但目前还不认为有什么东西被盗。第二起事件发生在凌晨1点20分左右,地点是戈斯波特码头路的阿斯达商店。

    2025年08月09日
    131
  • 我们如今如同寄生生物 - 赖默

      牛肉岛上的主要机场。通信和工程部长kyyeRymer批评了英属维尔京群岛对邻近岛屿空运通道的依赖,称这种行为是寄生的。赖默在众议院发表讲话时强调了投资于该地区旅游基础设施的紧迫性,特别是在其他加勒比国家扩建机场和服务的情况下。“我们现在看起来就像寄生虫一样,”赖默说。他指

    2025年08月11日
    7
  • 玩家攻略“雀神麻将开挂神器下载软件”确实是有挂

    雀神麻将开挂神器下载软件是一款可以让一直输的玩家,快速成为一个“必胜”的ai辅助神器,有需要的用户可以加我微下载使用。雀神麻将开挂神器下载软件可以一键让你轻松成为“必赢”。其操作方式十分简单,打开这个应用便可以自定义大贰小程序系统规律,只需要输入自己想要的开挂

    2025年08月12日
    5
  • 教程分享“微乐辽宁斗地主有挂吗”爆光开挂猫腻详情

    >亲,微乐辽宁斗地主有挂吗这款游戏原来确实可以开挂,详细开挂教程1、起手看牌2、随意选牌3、控制牌型4、注明,就是全场,公司软件防封号、防检测、 正版软件、非诚勿扰。2022首推。全网独家,诚信可靠,无效果全额退款,本司推出的多功能作 

    2025年08月12日
    5

发表回复

本站作者后才能评论

评论列表(4条)

  • 访客
    访客 2025年07月23日

    我是nslqa号的签约作者“访客”!

  • 访客
    访客 2025年07月23日

    希望本篇文章《卡巴斯基揭示第二季度APT趋势新动态》能对你有所帮助!

  • 访客
    访客 2025年07月23日

    本站[nslqa号]内容主要涵盖:国足,欧洲杯,世界杯,篮球,欧冠,亚冠,英超,足球,综合体育

  • 访客
    访客 2025年07月23日

    本文概览:TAIPEI, TAIWAN - Media OutReach - 4 August 2023 - In Kaspersky's latest report on Advanc...

    联系我们

    邮件:nslqa号@sina.com

    工作时间:周一至周五,9:30-18:30,节假日休息

    关注我们