{"id":1258,"date":"2021-07-20T15:22:04","date_gmt":"2021-07-20T07:22:04","guid":{"rendered":"https:\/\/blog.billows.com.tw\/?p=1258"},"modified":"2021-07-20T15:25:50","modified_gmt":"2021-07-20T07:25:50","slug":"%e7%be%8e%e5%9c%8b%e6%ad%a3%e5%bc%8f%e8%b5%b7%e8%a8%b4%e4%b8%ad%e5%9c%8b%e6%94%bf%e5%ba%9c%e8%b3%87%e5%8a%a9%e7%9a%84%e9%a7%ad%e5%ae%a2%e7%b5%84%e7%b9%94apt40%e7%9a%84%e5%9b%9b%e5%90%8d%e6%88%90","status":"publish","type":"post","link":"https:\/\/blog.billows.com.tw\/?p=1258","title":{"rendered":"\u7f8e\u570b\u6b63\u5f0f\u8d77\u8a34\u4e2d\u570b\u653f\u5e9c\u8cc7\u52a9\u7684\u99ed\u5ba2\u7d44\u7e54APT 40\u7684\u56db\u540d\u6210\u54e1"},"content":{"rendered":"\n<p>7\u670819\u65e5\u7f8e\u570b\u806f\u5408\u6b50\u76df\u3001\u82f1\u570b\u3001\u6fb3\u6d32\u3001\u52a0\u62ff\u5927\u3001\u7d10\u897f\u862d\u3001\u65e5\u672c\u8207\u5317\u5927\u897f\u6d0b\u516c\u7d04\u7d44\u7e54\uff08NATO\uff09\u6210\u54e1\u570b\uff0c\u5171\u540c<a href=\"https:\/\/www.whitehouse.gov\/briefing-room\/statements-releases\/2021\/07\/19\/the-united-states-joined-by-allies-and-partners-attributes-malicious-cyber-activity-and-irresponsible-state-behavior-to-the-peoples-republic-of-china\/\">\u8b74\u8cac<\/a>\u4e2d\u570b\u767c\u52d5\u60e1\u610f\u7db2\u8def\u653b\u64ca\uff0c\u4ee5\u76dc\u7aca\u53d6\u667a\u6167\u8ca1\u7522\u6b0a\u3001\u5546\u696d\u6a5f\u5bc6\u8207\u50b3\u67d3\u6027\u75be\u75c5\u7814\u7a76\u7b49\uff0c\u540c\u6642\u6b63\u5f0f\u5c073\u6708\u521d\u5229\u7528\u5fae\u8edf<a href=\"https:\/\/blog.billows.com.tw\/?p=941\">Exchange Server\u7684\u6f0f\u6d1e<\/a>\uff0c\u5c0d\u5168\u7403\u6578\u4ee5\u842c\u8a08\u7684\u96fb\u8166\u53ca\u7db2\u8def\u767c\u52d5\u5927\u578b\u7db2\u8def\u9593\u8adc\u884c\u52d5\u6b78\u548e\u65bc\u4e2d\u570b\u570b\u5bb6\u5b89\u5168\u90e8\uff0c\u7f8e\u570b\u53f8\u6cd5\u90e8\u4eca\u5929\u540c\u6b65\u516c\u5e035\u6708\u4e00\u4efd<a href=\"https:\/\/www.justice.gov\/opa\/press-release\/file\/1412916\/download\">\u8d77\u8a34\u66f8<\/a>\uff0c\u6307\u63a7\u56db\u540d\u4e2d\u570b\u516c\u6c11\u4ee3\u8868\u4e2d\u570b\u653f\u5e9c\u5c0d\u4e16\u754c\u5404\u5730\u7684\u516c\u53f8\u3001\u653f\u5e9c\u6a5f\u69cb\u548c\u5927\u5b78\u9032\u884c\u99ed\u5ba2\u653b\u64ca\u3002\u7f8e\u570b\u7a31\uff0c\u9019\u56db\u540d\u5acc\u7591\u4eba\u96b8\u5c6c\u65bc\u4e2d\u570b\u570b\u5bb6\u5b89\u5168\u90e8(China\u2019s Ministry of State Security-MSS)\u4e0b\u5c6c\u7684\u6d77\u5357\u7701\u570b\u5bb6\u5b89\u5168\u5ef3(Hainan State Security Department)\uff0c\u4e26\u4ee5\u4e00\u5bb6\u540d\u70ba\u6d77\u5357\u4ed9\u76fe\u79d1\u6280\u7684\u516c\u53f8\u4f5c\u70ba\u5e4c\u5b50\u516c\u53f8\u5f9e\u4e8b\u99ed\u653b\uff0c\u6839\u64da\u8d77\u8a34\u66f8\uff0c\u81f3\u5c11\u81ea 2011 \u5e74\u4ee5\u4f86\uff0c\u5176\u4e2d\u4e01\u66c9\u967d\u3001\u7a0b\u6176\u6c11\u8207\u6731\u5141\u654f3\u540d\u88ab\u544a\u70ba\u6d77\u5357\u570b\u5b89\u5ef3\u5b98\u54e1\uff0c\u8ca0\u8cac\u5354\u8abf\u3001\u7ba1\u7406\u4e2d\u5171\u570b\u5b89\u90e8\u65d7\u4e0b\u5e4c\u5b50\u516c\u53f8\u5167\u99ed\u5ba2\uff0c\u9032\u884c\u6709\u5229\u4e2d\u570b\u548c\u76f8\u95dc\u4f01\u696d\u7684\u99ed\u5ba2\u884c\u52d5\u3002\u53e6\u4e00\u540d\u88ab\u544a\u5433\u6dd1\u69ae\u5247\u8ca0\u8cac\u88fd\u9020\u60e1\u610f\u8edf\u9ad4\uff0c\u5c0d\u5916\u570b\u653f\u5e9c\u3001\u4f01\u696d\u8207\u5927\u5b78\u96fb\u8166\u7cfb\u7d71\u9032\u884c\u7db2\u653b\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"554\" height=\"651\" src=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2021\/07\/image-20.png\" alt=\"\" class=\"wp-image-1260\" srcset=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2021\/07\/image-20.png 554w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2021\/07\/image-20-255x300.png 255w\" sizes=\"auto, (max-width: 554px) 100vw, 554px\" \/><\/figure>\n\n\n\n<p>\u6839\u64da<a href=\"https:\/\/www.justice.gov\/opa\/press-release\/file\/1412916\/download\">\u6cd5\u5ead\u6587\u4ef6<\/a>\uff0c\u5728APT40\u9032\u884c\u5165\u4fb5\u6642\uff0c\u5e38\u4f7f\u7528 Tor \u7db2\u8def\u4f86\u5b58\u53d6\u548c\u64cd\u4f5c\u4ed6\u5011\u7684\u60e1\u610f\u8edf\u9ad4(BADFLICK, PHOTO, MURKYTOP, \u548c HOMEFRY\u548c\u99ed\u5ba2\u57fa\u790e\u8a2d\u65bd(\u5305\u542b\u4f3a\u670d\u5668\u3001\u7db2\u57df\u3001\u96fb\u5b50\u90f5\u4ef6\u3001GitHub \u548c Dropbox \u5e33\u6236\u3002)\u8a72\u7d44\u7e54\u7d93\u5e38\u4f7f\u7528 GitHub \u4f86\u5b58\u5132\u60e1\u610f\u8edf\u9ad4\u548c\u88ab\u76dc\u6578\u64da\uff0c\u4e26\u4f7f\u7528\u5716\u50cf\u96b1\u78bc\u8853(Steganography)\u4f86\u96b1\u85cf\u7a0b\u5f0f\u78bc\uff0c\u5c07\u6578\u64da\u96b1\u85cf\u5728\u5716\u50cf\u4e2d\u3002\u7531\u65bc\u5927\u591a\u6578\u516c\u53f8\u4e0d\u6703\u5c07 Dropbox \u6d41\u91cf\u8996\u70ba\u60e1\u610f\u6d41\u91cf\uff0cAPT40\u9084\u7d93\u5e38\u6feb\u7528 Dropbox \u5e33\u6236\u4f5c\u70ba\u88ab\u76dc\u6578\u64da\u7684\u6536\u96c6\u9ede\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"554\" height=\"316\" src=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2021\/07\/image-21.png\" alt=\"\" class=\"wp-image-1261\" srcset=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2021\/07\/image-21.png 554w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2021\/07\/image-21-300x171.png 300w\" sizes=\"auto, (max-width: 554px) 100vw, 554px\" \/><\/figure>\n\n\n\n<p>\u8d77\u8a34\u66f8\u6307\u51fa\uff0c\u53d7\u5bb3\u8005\u904d\u53ca\u7f8e\u570b\u3001\u82f1\u570b\u3001\u745e\u58eb\u3001\u5967\u5730\u5229\u3001\u67ec\u57d4\u5be8\u3001\u52a0\u62ff\u5927\u3001\u5fb7\u570b\u3001\u5370\u5ea6\u5c3c\u897f\u4e9e\u3001\u99ac\u4f86\u897f\u4e9e\u3001\u632a\u5a01\u3001\u6c99\u7279\u963f\u62c9\u4f2f\u7b4912\u570b\uff0c\u906d\u9396\u5b9a\u7522\u696d\u4e5f\u6a6b\u8de8\u822a\u7a7a\u3001\u570b\u9632\u3001\u653f\u5e9c\u8207\u751f\u7269\u88fd\u85e5\u7b49\uff0c\u88ab\u76dc\u7684\u5546\u696d\u6a5f\u5bc6\u548c\u6578\u64da\u5305\u62ec\u7528\u65bc\u6f5b\u6c34\u5668(submersibles)\u548c\u81ea\u52d5\u99d5\u99db\u6c7d\u8eca\u7684\u6a5f\u5bc6\u6280\u8853\u3001\u7279\u6b8a\u5316\u5b78\u914d\u65b9\u3001\u5546\u7528\u98db\u6a5f\u7dad\u4fee\u3001\u5c08\u6709\u57fa\u56e0\u5b9a\u5e8f\u6280\u8853\u7b49\u3002APT40 \u9084\u6d89\u5acc\u5f9e\u7814\u7a76\u6a5f\u69cb\u548c\u5927\u5b78\u7aca\u53d6\u91dd\u5c0d\u8207\u4f0a\u6ce2\u62c9\u75c5\u6bd2\u4e2d\u6771\u547c\u5438\u75c7\u5019\u7fa4\u51a0\u72c0\u75c5\u6bd2\u3001\u611b\u6ecb\u75c5\u3001\u99ac\u5821\u75c5\u6bd2\u548c\u5154\u71b1\u75c5\u7b49\u76f8\u95dc\u7684\u50b3\u67d3\u75c5\u7814\u7a76\u6578\u64da\u3002\u6b64\u5916\uff0c\u7f8e\u570b\u8abf\u67e5\u4eba\u54e1\u8868\u793a\uff0cAPT40 \u8207\u6d77\u5357\u548c\u4e2d\u570b\u5404\u5730\u7684\u591a\u6240\u5927\u5b78\u5bc6\u5207\u5408\u4f5c\u3002\u8a72\u7d44\u7e54\u5229\u7528\u4ed6\u5011\u7684\u6d77\u5357\u4ed9\u76fe\u516c\u53f8\uff0c\u8207\u5927\u5b78\u5de5\u4f5c\u4eba\u54e1\u5408\u4f5c\uff0c\u5f9e\u5927\u5b78\u4e2d\u62db\u52df\u99ed\u5ba2\u548c\u8a9e\u8a00\u5b78\u5bb6\uff0c\u4ee5\u52a9\u4ed6\u5011\u672a\u4f86\u7684\u5165\u4fb5\u3002<\/p>\n\n\n\n<p>\u53e6\u5916\uff0c\u5728\u767d\u5bae\u5ba3\u5e03\u548c\u53f8\u6cd5\u90e8\u6307\u63a7\u4e4b\u5f8c\uff0cCISA\u3001\u570b\u571f\u5b89\u5168\u90e8\u548c\u806f\u90a6\u8abf\u67e5\u5c40<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa21-200a\">\u806f\u5408<\/a>\u767c\u5e03\u4e86\u4e00\u4efd\u6aa2\u6e2c APT40 \u5165\u4fb5\u548c\u6d3b\u52d5\u7684<a href=\"https:\/\/media.defense.gov\/2021\/Jul\/19\/2002805003\/-1\/-1\/1\/CSA_CHINESE_STATE-SPONSORED_CYBER_TTPS.PDF\">\u6280\u8853\u6307\u5357<\/a>\uff0c\u5176\u4e2d\u5305\u542b <a href=\"https:\/\/media.defense.gov\/2021\/Jul\/19\/2002805003\/-1\/-1\/1\/CSA_CHINESE_STATE-SPONSORED_CYBER_TTPS.PDF\">50 \u591a\u7a2e<\/a>\u89c0\u5bdf\u5230\u4e2d\u570b\u7db2\u8ecd\u4f7f\u7528\u7684\u7db2\u8def\u653b\u64ca\u6230\u8853\u6d41\u7a0b(Tactics, Techniques and Procedures)\uff0c\u5165\u4fb5\u6307\u6a19( IOCs)\u548c\u7de9\u89e3\u63aa\u65bd\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"554\" height=\"440\" src=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2021\/07\/image-19.png\" alt=\"\" class=\"wp-image-1259\" srcset=\"https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2021\/07\/image-19.png 554w, https:\/\/blog.billows.com.tw\/wp-content\/uploads\/2021\/07\/image-19-300x238.png 300w\" sizes=\"auto, (max-width: 554px) 100vw, 554px\" \/><\/figure>\n\n\n\n<p>\u6709\u95dc\u60c5\u8cc7:<\/p>\n\n\n\n<p><a href=\"https:\/\/otx.alienvault.com\/pulse\/60f597533e911956a673717b\">Tactics, Techniques, and Procedures of Indicted APT40 Actors Associated with China\u2019s MSS Hainan State Security Department | CISA<\/a><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>7\u670819\u65e5\u7f8e\u570b\u806f\u5408\u6b50\u76df\u3001\u82f1\u570b\u3001\u6fb3\u6d32\u3001\u52a0\u62ff\u5927\u3001\u7d10\u897f\u862d\u3001\u65e5\u672c\u8207\u5317\u5927\u897f\u6d0b\u516c\u7d04\u7d44\u7e54\uff08NATO\uff09\u6210\u54e1\u570b\uff0c\u5171\u540c\u8b74\u8cac\u4e2d\u570b\u767c\u52d5 <a class=\"read-more\" href=\"https:\/\/blog.billows.com.tw\/?p=1258\">READ MORE<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[160,112],"class_list":["post-1258","post","type-post","status-publish","format-standard","hentry","category-6","tag-apt40","tag-112"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/1258","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1258"}],"version-history":[{"count":2,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/1258\/revisions"}],"predecessor-version":[{"id":1263,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/1258\/revisions\/1263"}],"wp:attachment":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1258"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1258"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1258"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}