卡巴斯基发布2023年第二季度最新APT趋势分析报告

TAIPEI, TAIWAN - Media OutReach - 4 August 2023 - In Kaspersky's latest report on Advanc...

TAIPEI, TAIWAN - Media OutReach - 4 August 2023 - In Kaspersky's latest report on Advanced Persistent Threats (APTs) trends for the second quarter of 2023, researchers analyze the development of new and existing campaigns. The report highlights APT activity during this period including the updating of toolsets, the creation of new malware variants, and the adoption of fresh techniques by threat actors.

A significant new revelation was the exposure of the long-running "Operation Triangulation" campaign involving the use of a previously unknown iOS malware platform. Experts also observed other interesting developments that they believe everyone should be aware of. Here are key highlights from the report:

Asia-Pacific witnesses a new threat actor – Mysterious Elephant

Kaspersky uncovered a new threat actor belonging to the Elephants family, operating in the Asia-Pacific region, dubbed "Mysterious Elephant". In their latest campaign, the threat actor employed new backdoor families, capable of executing files and commands on the victim's computer, and receive files or commands from a malicious server for execution on the infected system. While Kaspersky researchers have observed overlaps with Confucius and SideWinder, Mysterious Elephant possesses a distinctive and unique set of TTPs, setting them apart from these other groups.

Toolsets upgraded: Lazarus' develops new malware variant, BlueNoroff attacks macOS, and more

Threat actors are constantly improving their techniques, with Lazarus upgrading its MATA framework and introducing a new variant of the sophisticated MATA malware family, MATAv5. BlueNoroff, a financial attack-focused subgroup of Lazarus, now employs new delivery methods and programming languages, including the use of Trojanized PDF readers in recent campaigns, the implementation of macOS malware, and the Rust programming language. Additionally, ScarCruft APT group has developed new infection methods, evading Mark-of-the-Web (MOTW) security mechanism. The ever-evolving tactics of these threat actors present new challenges for cybersecurity professionals.

Geopolitical influences remain primary drivers of APT activity

APT campaigns remain geographically dispersed, with actors concentrating their attacks on regions such as Europe, Latin America, the Middle East and various parts of Asia. Cyber-espionage, with a solid geopolitical backdrop, continues to be a dominant agenda for these endeavors.

Adrian Hia, Managing Director for APAC at Kaspersky said "Kaspersky has been monitoring all the active APT actors in the region that infect mobile devices and are slowly targeting businesses and infrastructure. Our researchers focuses on APT activities to uncover the most sophisticated cyber-attacks. By publishing our findings from our investigation, we hope to be able to help organisations be aware of the latest activities and remain secure in our bid to build a safer world."

"While some threat actors stick to familiar tactics like social engineering, others have evolved, refreshing their toolsets and expanding their activities. Moreover, new advanced actors, such those conducting the 'Operation Triangulation' campaign, constantly emerge. This actor uses a previously unknown iOS malware platform distributed through zero-click iMessage exploits. Staying vigilant with threat intelligence and the right defense tools is crucial for global companies, so they can protect themselves against both existing and emerging threats. Our quarterly reviews are designed to highlight the most significant developments among APT groups to help defenders combat and mitigate related risks," comments David Emm, principal security researcher at Kaspersky's Global Research and Analysis Team (GReAT).

To read the full APT Q2 2023 trends report, please visit Securelist.
In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky researchers recommend implementing the following measures:

Ensuring the security of your system, it is crucial to promptly update your operating system and other third-party software to their latest versions. Maintaining a regular update schedule is essential in order to stay protected from potential vulnerabilities and security risks Upskill your cybersecurity team to tackle the latest targeted threats with Kaspersky online training developed by GReAT experts. Use the latest Threat Intelligence information to stay up-to-date with the actual TTPs used by threat actors. For endpoint level detection, investigation, and timely remediation of incidents, implement EDR solutions such as Kaspersky Endpoint Detection and Response. Dedicated services can help combat high-profile attacks. The Kaspersky Managed Detection and Response service can help identify and stop intrusions in their early stages, before the perpetrators achieve their goals. If you encounter an incident, Kaspersky Incident Response service will help you respond and minimize the consequences, in particular - identify compromised nodes and protect the infrastructure from similar attacks in the future.
Hashtag: #Kaspersky

发行人对本公告内容全权负责。

本文来自作者[乐岚]投稿,不代表temtv号立场,如若转载,请注明出处:https://wap.temtv.cn/cshi/202508-3084.html

(2)

文章推荐

  • 索林根音乐节发生持刀袭击事件,数人不幸遇难

    8月24日,索林根(德国):据美国有线电视新闻网报道,在德国西部城市索林根的一个节日里,发生了一起持刀袭击事件,造成至少3人死亡,4人重伤。据欧洲新闻报道,袭击发生在中央广场Fronhof。警方发起了一项搜捕行动,以逮捕正在逃跑的袭击者。警方还没有排除恐怖主义的可能性。美国有线电

    2025年07月13日
    7
  • 普京批准新法,正式将俄罗斯的加密货币挖矿合法化

      根据政府法律信息门户网站上发布的一份文件,俄罗斯总统弗拉基米尔·普京周四签署了一项法律,从2024年11月起正式将该国的加密货币挖矿合法化。根据新法律,在俄罗斯数字发展部注册的法人实体和个人企业家将被允许从事加密货币挖矿。未注册的个人也可以从事挖矿,前提是他

    2025年07月24日
    7
  • 旁遮普邦首席部长指责国大党与人民党在哈里亚纳邦暗中合作

    旁遮普首席部长BhagwantMann周日表示,在野的国大党和执政的人民党在哈里亚纳邦的选举中相互勾结,让公众受苦。“哈里亚纳邦需要像德里和旁遮普邦一样书写新的故事,”曼恩对这里的贸易商说。邦AamAadmi党(AAP)副主席AnuragDha

    2025年07月24日
    8
  • 拉塞尔·霍华德分享与山姆·尼尔的猪有关的右转按摩趣事

      这位明星将在2024年重返新西兰,这是他自历史性的流感泡沫之旅以来的首次回归。在这些演出之前,英国的单口相声探讨了灾难、新西兰的喜剧伙伴,以及如何正确地抚摸山姆·尼尔的猪。我上次见到英国喜剧演员拉塞尔·霍华德时,他只能向左转。就像一个上了发条的

    2025年07月25日
    7
  • 显然,众议院共和党内部对议长迈克·约翰逊的态度开始出现分歧

    本文为《时代》周刊政治时事通讯《华盛顿简报》的一部分。在这里注册,这样的故事就会发送到你的收件箱。如果众议院共和党人今天被迫投票决定由谁来领导他们,国会山普遍认为,迈克·约翰逊(MikeJohnson)将很难继续担任众议院议长这一不令人羡慕的职位。简而言之:蜜月期结

    2025年08月03日
    7
  • 利比亚为濒危瞪羚提供了新的栖息地

    法尔瓦,利比亚——8只小羚羊——一种原生于北非的濒危物种——被装在白色袋子里,依偎在志愿者的怀里,被转移到利比亚一个无人居住的岛屿上。环保人士希望它们在突尼斯附近法尔瓦岛的新家能成为这些脆弱动物的避难所。细长角的瞪羚也被称为Gazellalepto

    2025年08月05日
    7
  • 加沙地区以色列与巴勒斯坦冲突的时间线

    周六早些时候,巴勒斯坦伊斯兰恐怖组织哈马斯对以色列发动了多年来最大规模的袭击,从加沙发射了一连串火箭弹,并派遣武装人员越过边境。以色列表示,它已处于战争状态,并开始对加沙地带的哈马斯目标发动自己的袭击。以色列媒体报道,巴勒斯坦武装分子和以色列南部的安全部队之间发生

    2025年08月10日
    7
  • 玩家实测“哈灵麻将挂怎么弄”分享装挂技巧步骤

    哈灵麻将挂怎么弄是一款可以让一直输的玩家,快速成为一个“必胜”的ai辅助神器,有需要的用户可以加我微下载使用。哈灵麻将挂怎么弄可以一键让你轻松成为“必赢”。其操作方式十分简单,打开这个应用便可以自定义手机程序系统规律,只需要输入自己想要的开挂功能,一键便可以生

    2025年08月18日
    9
  • 盘点一款“捕鱼辅助作弊版下载”(其实真的能开挂)

    网上科普有关“捕鱼辅助作弊版下载”话题很是火热,小编也是针对微乐麻将的技术支持和安全性寻找了一些与之相关的一些信息进行分析,如果能碰巧解决你现在面临的问题,希望能够帮助到您。您好,捕鱼辅助作弊版下载这款游戏可以开挂的,确实是有挂的,通过微信【游戏】很多

    2025年08月18日
    4
  • 主权黄金债券:投资者将在8月5日的下一次赎回中享受12%的收益率

    主权黄金债券:主权黄金债券(SGB)计划的下一部分最初于2016年8月5日启动,计划于2024年8月5日赎回,为期8年。这些债券以每克3119卢比的价格购买,为投资者提供了可观的回报。在最初购买的2.6吨中,5年后赎回了225.322公斤,剩下2.75吨尚未赎回。

    2025年08月18日
    4

发表回复

本站作者后才能评论

评论列表(4条)

  • 乐岚
    乐岚 2025年08月19日

    我是temtv号的签约作者“乐岚”!

  • 乐岚
    乐岚 2025年08月19日

    希望本篇文章《卡巴斯基发布2023年第二季度最新APT趋势分析报告》能对你有所帮助!

  • 乐岚
    乐岚 2025年08月19日

    本站[temtv号]内容主要涵盖:国足,欧洲杯,世界杯,篮球,欧冠,亚冠,英超,足球,综合体育

  • 乐岚
    乐岚 2025年08月19日

    本文概览:TAIPEI, TAIWAN - Media OutReach - 4 August 2023 - In Kaspersky's latest report on Advanc...

    联系我们

    邮件:temtv号@sina.com

    工作时间:周一至周五,9:30-18:30,节假日休息

    关注我们