跳到正文
原文
Microsoft Security Blog· Microsoft Threat Intelligence·· 9 天前精选AI 评分78

Microsoft Threat Intelligence 追踪勒索软件附属组织 Storm-2570 的跨部署攻击手法

Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

AI 导读

Microsoft Threat Intelligence 观察到勒索软件附属组织 Storm-2570 在 Qilin、DragonForce、Anubis 和 BERT 部署中持续使用相似的入侵手法、工具和基础设施。

推荐理由

文章基于多起入侵调查,梳理了跨勒索软件生态反复出现的工具、基础设施和行为,并提供检测、狩猎查询与防护建议,适合安全团队建立持续追踪和事件响应基线。

来源:Microsoft Security Blog · microsoft.com