卡巴斯基发布2023年第二季度最新APT趋势分析报告

TAIPEI, TAIWAN - Media OutReach - 4 August 2023 - In Kaspersky's latest report on Advanc...

TAIPEI, TAIWAN - Media OutReach - 4 August 2023 - In Kaspersky's latest report on Advanced Persistent Threats (APTs) trends for the second quarter of 2023, researchers analyze the development of new and existing campaigns. The report highlights APT activity during this period including the updating of toolsets, the creation of new malware variants, and the adoption of fresh techniques by threat actors.

A significant new revelation was the exposure of the long-running "Operation Triangulation" campaign involving the use of a previously unknown iOS malware platform. Experts also observed other interesting developments that they believe everyone should be aware of. Here are key highlights from the report:

Asia-Pacific witnesses a new threat actor – Mysterious Elephant

Kaspersky uncovered a new threat actor belonging to the Elephants family, operating in the Asia-Pacific region, dubbed "Mysterious Elephant". In their latest campaign, the threat actor employed new backdoor families, capable of executing files and commands on the victim's computer, and receive files or commands from a malicious server for execution on the infected system. While Kaspersky researchers have observed overlaps with Confucius and SideWinder, Mysterious Elephant possesses a distinctive and unique set of TTPs, setting them apart from these other groups.

Toolsets upgraded: Lazarus' develops new malware variant, BlueNoroff attacks macOS, and more

Threat actors are constantly improving their techniques, with Lazarus upgrading its MATA framework and introducing a new variant of the sophisticated MATA malware family, MATAv5. BlueNoroff, a financial attack-focused subgroup of Lazarus, now employs new delivery methods and programming languages, including the use of Trojanized PDF readers in recent campaigns, the implementation of macOS malware, and the Rust programming language. Additionally, ScarCruft APT group has developed new infection methods, evading Mark-of-the-Web (MOTW) security mechanism. The ever-evolving tactics of these threat actors present new challenges for cybersecurity professionals.

Geopolitical influences remain primary drivers of APT activity

APT campaigns remain geographically dispersed, with actors concentrating their attacks on regions such as Europe, Latin America, the Middle East and various parts of Asia. Cyber-espionage, with a solid geopolitical backdrop, continues to be a dominant agenda for these endeavors.

Adrian Hia, Managing Director for APAC at Kaspersky said "Kaspersky has been monitoring all the active APT actors in the region that infect mobile devices and are slowly targeting businesses and infrastructure. Our researchers focuses on APT activities to uncover the most sophisticated cyber-attacks. By publishing our findings from our investigation, we hope to be able to help organisations be aware of the latest activities and remain secure in our bid to build a safer world."

"While some threat actors stick to familiar tactics like social engineering, others have evolved, refreshing their toolsets and expanding their activities. Moreover, new advanced actors, such those conducting the 'Operation Triangulation' campaign, constantly emerge. This actor uses a previously unknown iOS malware platform distributed through zero-click iMessage exploits. Staying vigilant with threat intelligence and the right defense tools is crucial for global companies, so they can protect themselves against both existing and emerging threats. Our quarterly reviews are designed to highlight the most significant developments among APT groups to help defenders combat and mitigate related risks," comments David Emm, principal security researcher at Kaspersky's Global Research and Analysis Team (GReAT).

To read the full APT Q2 2023 trends report, please visit Securelist.
In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky researchers recommend implementing the following measures:

Ensuring the security of your system, it is crucial to promptly update your operating system and other third-party software to their latest versions. Maintaining a regular update schedule is essential in order to stay protected from potential vulnerabilities and security risks Upskill your cybersecurity team to tackle the latest targeted threats with Kaspersky online training developed by GReAT experts. Use the latest Threat Intelligence information to stay up-to-date with the actual TTPs used by threat actors. For endpoint level detection, investigation, and timely remediation of incidents, implement EDR solutions such as Kaspersky Endpoint Detection and Response. Dedicated services can help combat high-profile attacks. The Kaspersky Managed Detection and Response service can help identify and stop intrusions in their early stages, before the perpetrators achieve their goals. If you encounter an incident, Kaspersky Incident Response service will help you respond and minimize the consequences, in particular - identify compromised nodes and protect the infrastructure from similar attacks in the future.
Hashtag: #Kaspersky

发行人对本公告内容全权负责。

本文来自作者[乐岚]投稿,不代表temtv号立场,如若转载,请注明出处:https://www.temtv.cn/cshi/202508-3084.html

(1)

文章推荐

  • 泰国企业对越南经济发展持乐观态度

      在泰国和越南最近举行的商业论坛上,包括8月15日在曼谷举行的泰越商业论坛上,许多泰国企业对越南经济做出了乐观的评估,指出越南经济的基本面强劲,增长速度在今年亚太地区名列前茅。在新冠肺炎疫情后,越南成功推动经济复苏,许多泰国企业对越南经济的光明前景充满信心。

    2025年07月10日
    8
  • 欧元与单一市场的奠基人雅克·德洛尔逝世,享年98岁

      前欧盟委员会主席雅克·德洛尔于98岁时去世,他在欧元的构思和单一市场的建立中起到了至关重要的作用。德洛尔去世的消息确认后,法国总统马克龙称赞他是“影响法国命运的政治家”。德洛尔在1985年至

    2025年07月10日
    7
  • 特斯拉拟自制电池以支持赛博卡车和自动驾驶出租车

      据知情人士周四透露,特斯拉正在研发四种新型内部电池,以为赛博卡车、即将推出的机器人出租车及其他电动车型提供动力。这家由埃隆·马斯克(ElonMusk)领导的公司目前主要从松下能源(PanasonicEnergy)和LG能源(LGEnergy)等企业采

    2025年07月21日
    9
  • 国家牛肉福利计划向农民发放1420万欧元

    根据国家牛肉福利计划,将向15,834名农民发放款项。这些款项价值1420万欧元。付款将在未来几天出现在银行账户中。行动该计划旨在提高乳猪场的经济效益,并加强动物卫生和畜牧业。该方案中有两个操作,

    2025年07月26日
    9
  • 券商青睐:L&T Finance、IndiGo与Zydus Lifesciences成热门投资选择

      剧情概述AxisCapital将IndiGo的评级从买入调整为增持,同时将目标价从4700卢比提升至5100卢比。评级的下调反映出其上涨空间有限,AxisCapital指出了供应方面的挑战,并提到由于负载因子已达到80%的最佳水平,进一步改善可能会受到限制

    2025年07月27日
    7
  • 揭开伊丽莎白·弗里茨的神秘面纱:她的现状如何?

    即使对于那些熟悉真实犯罪和人类深渊堕落的人来说,有些故事也难以置信和理性。“地下室里的女孩”伊丽莎白·弗里茨(ElisabethFritzl)就是这样一个例子,她所遭受的痛苦超出了我们大多数人的理解能力。简短的故事是这样的:2008年4月26

    2025年07月30日
    8
  • 哈里王子独自旅行时展现出如同“兴奋孩子”的快乐

    周日晚上,哈里王子在洛杉矶观看梅西在迈阿密国际米兰队的比赛时,看起来就像一个“圣诞节兴奋的孩子”。在BMO体育场,哈里坐在那里,手里拿着一条洛杉矶足球俱乐部的黑金色围巾,开心地观看比赛,尽管他的妻子梅根·马克尔没有和他在一起。在X(以前的推特)上发

    2025年08月05日
    8
  • 以色列总理甘茨:美国对阿克莱之死的调查存在失误

    以色列国防部长甘茨星期一在一份声明中说,以色列不会配合美国对巴勒斯坦裔美国记者希琳·阿布·阿克莱被杀一事的调查。阿布·阿克勒(AbuAkleh)是半岛电视台(AlJazeera)新闻网络的记者,今年5月在报道以色列在约旦河西岸的一次军事袭击时被杀。据目击者和接

    2025年08月10日
    7
  • 今日教程“乐乐四川麻将有没有挂”详细分享开挂步骤

    您好:乐乐四川麻将有没有挂这款游戏是可以开挂的,软件加微信【添加图中微信】确实是有挂的,很多玩家在这款游戏中打牌都会发现很多用户的牌特别好,总是好牌,而且好像能看到其他人的牌一样。所以很多小伙伴就怀疑这款游戏是不是有挂,实际上这款游戏确实是有挂的,添加客服微信

    2025年08月16日
    8
  • 玩家实测“九尾牛牛有挂吗”分享装挂详细步

    九尾牛牛有挂吗是一款可以让一直输的玩家,快速成为一个“必胜”的ai辅助神器,有需要的用户可以加我微下载使用。九尾牛牛有挂吗可以一键让你轻松成为“必赢”。其操作方式十分简单,打开这个应用便可以自定义大贰小程序系统规律,只需要输入自己想要的开挂功能,一键便可以生成

    2025年08月17日
    8

发表回复

本站作者后才能评论

评论列表(4条)

  • 乐岚
    乐岚 2025年08月19日

    我是temtv号的签约作者“乐岚”!

  • 乐岚
    乐岚 2025年08月19日

    希望本篇文章《卡巴斯基发布2023年第二季度最新APT趋势分析报告》能对你有所帮助!

  • 乐岚
    乐岚 2025年08月19日

    本站[temtv号]内容主要涵盖:国足,欧洲杯,世界杯,篮球,欧冠,亚冠,英超,足球,综合体育

  • 乐岚
    乐岚 2025年08月19日

    本文概览:TAIPEI, TAIWAN - Media OutReach - 4 August 2023 - In Kaspersky's latest report on Advanc...

    联系我们

    邮件:temtv号@sina.com

    工作时间:周一至周五,9:30-18:30,节假日休息

    关注我们