😓:Sorry your JavaScript is off or your browser does not support JavaScript 😓
開始試用

資源

白皮書

企業面對 3 大資安挑戰,就交給 MDR 服務!
CISO 資安對策
企業面對 3 大資安挑戰,就交給 MDR 服務!

在經濟前景不明朗、新興技術快速發展的趨勢下,加上俄烏衝突開啟了網路戰的新時代,網路安全專業人員面臨著比以往更大的壓力。許多企業和組織採用美國國家標準技術研究院(NIST)的網路安全框架(Cybersecurity Framework, CSF),做為對網路攻擊與反應的網路安全策略,包含識別( Identify )、防護(Protect)、偵測(Detect)、回應(Response)與復原(Recover)五個功能。然而,資安團隊要能完全發揮效益,就得解決從這五面向衍生而來的議題! 但是,根據 2023 iThome CIO 與資安大調查結果,台灣大型企業 2023 年整體缺口達 79%,其中又以營運與維護類的資安人才缺口占比最高,超過 50%。 資安人力缺口和專業能力,為企業資安帶來以下的挑戰: 挑戰一:如何部署與監控端點? 挑戰二:面對進階攻擊,該如何應變? 挑戰三:該如何緩解事件? 為解決上述挑戰,企業組織應持續補強內部資安團隊的專業度與人力,並尋找外部資安解決方案供應商,強化資安防禦能力 ,尤其是在政府、教育、製造、醫療保健、能源和公用事業等產業。 本份白皮書是基於 TeamT5 杜浦數位安全長期進行威脅偵測應變代管服務(Managed Detection and Response, MDR)的經驗,提出全面分析。並建議企業採購 MDR 服務的重要考量因素,包含 MDR 人員技術能力與專業程度、進階威脅偵測與獵捕能力、事件應變與抑制能力等。 立刻填寫表格,獲得白皮書深度分析與洞見!

認識威脅情資與威脅格局的運用方式
CISO 資安對策
認識威脅情資與威脅格局的運用方式

威脅情資 是網路安全的重要環節,涉及收集、處理和分析有關組織安全的潛在或當前威脅的資料。 這些情資不僅是原始數據,更有助於了解威脅行為者的動機、目標和攻擊行為的脈絡。 它提供了對手的戰術、技巧和程序 (TTP) 的洞察,使組織能夠準備、預防和識別可能濫用數位資產的網路威脅。

洞悉攻擊背後的脈絡:全球資安長不可忽視的亞太威脅情資
CISO 資安對策
洞悉攻擊背後的脈絡:全球資安長不可忽視的亞太威脅情資

網路攻擊行動日趨複雜,而亞太地區正是攻擊者活動的熱點。從國家支持的攻擊團體、商業承包商,到組織化的網路犯罪集團,無論目的是竊取國家機密或是獲取財務利益,攻擊者都能快速調整手法,並重複使用已建立的隱密後門、攻擊路徑等基礎設施,更快遂行其攻擊目的。對全球資安長而言,挑戰不在於缺乏警訊,而是缺乏能解讀攻擊背後脈絡的深度資訊。 本白皮書說明為何「攻擊者導向」的情資視角,是提升亞太地區整體防禦效益的關鍵。重點不在於收集更多指標,而在於理解攻擊者的組成、行為模式、動機與目標。透過結合 TeamT5 長期深耕亞太地區的第一手觀察,並以中國安洵(i-Soon)承包商資料外洩與台灣馬偕紀念醫院勒索事件為例,呈現亞太地區威脅生態的實際樣貌。 下載白皮書(英文),您即可深入了解亞太地區的攻擊者,以全新視角擘劃長期安全的防禦策略。

2024 年威脅態勢回顧:網路攻擊的模糊地帶【英文威脅情資報告】
2024 年威脅態勢回顧:網路攻擊的模糊地帶【英文威脅情資報告】

TeamT5 杜浦數位安全為專精亞太地區威脅情資的領導品牌。於此篇文章中,我們總結 2024 年亞太地區進階持續性威脅(APT)的威脅態勢,不僅提出年度觀察,更指出未來一年值得留意的資安威脅。 本篇文章為節錄版,摘述關鍵數據與威脅情資分析。 欲取得完整《2024年威脅態勢回顧: 網路攻擊的模糊地帶》報告,您可以直接填寫文章末尾表格,我們將透過電子郵件、寄送給您。 欲探索更多亞太地區的威脅情資,立刻申請獲得國際顧問公司肯定的威脅情資平台 ThreatVision 試用機會。請填寫 聯絡我們 表單。 Threat Statistics in 2024: Data & Observations In 2024, until the end of November, TeamT5 actively tracked 30 new vulnerabilities being exploited in the wild, along with around 500 attack operations across 42 countries, which we attributed to 73 known adversaries and more than 200 malware / hacking tools being used. We also identified 45 victims being compromised in 9 countries and tried to notify through our trustworthy partners. And helped 33 IR cases for our customers. You could imagine all the above data contributing to our intelligence reports. Generally speaking, most of them show a tendency of increasing. TeamT5 is actively tracking vulnerability exploitation attacks in the wild. In 2024, 30 widespread attacks were tracked by TeamT5, around 400 victim hosts across 21 countries were identified to be compromised. We would like to highlight that 5 of them are email system related and 14 are exploiting edge devices, indicating they are high priorities of threat actors to access targets. Our research also shows EtherBei (aka Flax Typhoon) to be the most active threat actors to adopt these exploits. During the course of our research, we also discovered some threat actors built their botnet or so called Operation Relay Box network by implanting malware like GobRAT, NatWalk and GenSeven. Lastly, there’s also a tendency that more management services of edge devices are being exploited, such as FortiManager, Versa Director or Palo Alto Firewall, e.t.c., meaning that threat actors might compromise multiple entities by intruding on one device. We believe this is a threat that management service providers or big enterprises should be aware of.

全面剖析臺灣 2024 總統大選面臨之資安威脅
威脅情資
全面剖析臺灣 2024 總統大選面臨之資安威脅

杜浦數位安全 TeamT5 發佈《臺灣 2024 總統大選資安威脅》白皮書(TeamT5 White Paper: Cyber Threats against Taiwan’s 2024 Presidential Election),透過「進階持續性威脅(advanced persistent threat)」與「資訊作戰(influence operation)」的雙重視角,全面剖析 2024 年臺灣大選所面臨的資安威脅。根據 TeamT5 長期以來的追查,我們持高度信心這些攻擊可能都是來自中國相關的威脅行動者。 作為網路威脅情資研究的專家, TeamT5 長期關注亞太地區駭客威脅,以協助我們的客戶掌握關鍵情資,抵禦從未間斷的網路攻擊。 重點摘要: 中國相關威脅行動者的攻擊手法持續演進,於投票日前一週發動綿密的不實資訊攻擊,意圖動搖社會大眾對於民主選舉體制的信任。 中國相關威脅行動者攻擊的目標包含不同產業,近期媒體業更是飽受攻擊。根據 TeamT5 的研究顯示,遭攻擊的媒體公司並無政治立場之分,泛綠與泛藍媒體皆有遭到攻擊。 中國相關威脅行動者仍持續透過社群平台散布不實訊息。但和過去相比,其動員的社群資源更加廣泛,並進一步利用 AI 技術生成內容;同時還架設新聞通訊網站,撰寫原生內容,以大量散播不實資訊。 中國相關威脅行動者還運用了「駭侵與外洩」(Hack and Leak)的手法。先竊取機密資訊後,再有計畫地透過特定管道向大眾披露,試圖操弄社會輿論風向,遭駭產業包含媒體、政府與電信。 綜合來看,中國相關威脅行動者確實能深入掌握台灣政經社會局勢的脈動,再透過進階持續性攻擊與資訊作戰的混合手法,瞄準民主社會可能的弱點。長期而言,網路攻擊的威脅,仍是台灣民主發展揮之不去的陰影。 請填寫以下表格,即可下載完整白皮書(英文)。

2023 年威脅態勢回顧:網路攻擊的新策略、新常態、新技術和新領域【英文威脅情資報告】
威脅情資
2023 年威脅態勢回顧:網路攻擊的新策略、新常態、新技術和新領域【英文威脅情資報告】

TeamT5 杜浦數位安全為專精亞太地區威脅情資的領導品牌。於此篇文章中,我們總結 2023 年亞太地區進階持續性威脅 (APT) 的威脅態勢,不僅提出年度觀察,更指出未來一年值得留意的資安威脅。 本篇文章為節錄版,摘述關鍵數據與威脅情資分析。欲取得完整《2023年威脅態勢回顧》報告,您可以直接填寫文章末尾表格,我們將透過電子郵件、寄送給您。 本篇文章改寫自《2023 H2 Campaign Tracking Report: APT Threat Landscape in Asia》,探索與此相關的報告與更多亞太地區的威脅情資,立刻申請威脅情資平台 ThreatVision 試用機會。請在 ThreatVision 頁面說明您希望申請試用。 Preface TeamT5’s cyber threat intelligence research based on well-built data collection and analysis flow. We collect data from multiple sources - malware databases, sandboxes, crawlers, and our threat forensic analysis platform ThreatSonar etc. With careful and rigorous analysis, we come up with intelligence reports for clients and the public to notify potential threats. For 2023, based on TeamT5 data collection and analysis, we found: 411 attack operations in 39 countries 60 known adversary groups tracked 210 malware / hacking tools used Closer Look at Exploits In 2023, we have observed at least 37 CVE exploits that were abused in the wild by threat actors. We see a tendency that more and more exploits targeting edge devices appear, which we marked with color yellow in the right table. These edge devices have no security products to monitor them so threat actors could effectively intrude their target network environments. There are still lots of attacks achieved spear phishing emails but the corresponding tricks are old fashioned, such as: Template Injection Microsoft LNK CHM Macro documents Phishing CVE-2018-0798, CVE-2022-30190, CVE-2023-38831 Closer Look at Malwares We listed the malware distribution in all attacks. Below is the ranking of Top 10 Malwares in 2023 H1 and Top 15 Malwares in 2023 H2 . We compare these two ranks with 4 aspects - Shared tools, Webshell, Cross platform RAT, Shared Quartermaster of Chinese APT. Here is our analysis. 1. About shared tools There are more and more threat actors adopting public or open source tools in their operations. This could effectively reduce their effort to develop their own weapons and also increase the barrier for researchers like us to achieve an effective attribution. 2. About Webshell Web server exploitations have become more and more common nowadays and the importance of webshell keeps increasing. Godzilla, a full featured webshell made by Chinese threat actors, has become the favorite of Chinese APT. It is usually deployed jointly with a small webshell like China Chopper to effectively bypass detections. 3. About Cross Platform RAT There are more and more cross platform or multi platform RAT. The reason behind is nowadays threat actors don’t only focus on Windows platform but will intrude from every possible platform like Linux, MacOS or even Android or iOS. 4. Shared Quartermaster of Chinese APT We have observed an interesting code or feature sharing between different malware used by Chinese APT. This kind of finding makes us highly suspect there is an entity or even private company that is responsible for producing all these remote administration tools and distributing them secretly to various Chinese APT groups. Closer Look at Targeted Countries / Regions by APT Groups From countries / regions aspects, our data shows Taiwan, South Korea, and Japan are the most targeted countries by APT groups. Following them are countries in South or Southeast Asia, such as Vietnam, Philippine, Thailand, or Malaysia, etc. Based on this statistic, we will discuss 3 different victim areas and corresponding active threat actors, they are Taiwan, Northeast Asia, and South/Southeast Asia. No.1 Targeted Country / Region: Taiwan Taiwan is the most targeted country in Asia Pacific. This chart shows the distribution of targeted industry sectors. Compared with our data in the past 2 years (2021-2022), we don’t see dramastic changes. Government, IT, education, or critical infrastructure are still on the top list. People might wonder why APT actors are so interested in the IT sector. We believe the reason is that there are more and more supply chain attacks and these IT companies possess good channels or privileges to access big companies or government entities. It makes the IT sector a perfect hopping point. And one interesting phenomena we have observed is the surging attack against the healthcare industry. We suspect the reason behind the attacks are the Taiwanese government’s effort to join WHA, or China’s ambition to collect personal identification information. In the threat actors' part, there are at least 21 known groups aiming at Taiwan in 2023. Among them are Huapi, Amoeba, and Polaris - they are old faces that are on the top list hitting Taiwan. In the meantime, there is a new face, SLIME13 (also known as FlaxTyphoon by Microsoft). SLIME13’s operations became so wild in 2023 that we have observed more than 100 victim entities in Taiwan. This APT group also aggressively expands their attacks to other countries such as Hong Kong, Japan or South Korea, etc. No.2 Targeted Country / Region: Northeast Asia In the Northeast Asia region, the geopolitical situation has changed dramatically in the past 2 years because Japan and South Korea are united together with the U.S. to defend against their enemies in the neighborhood. For this reason, the topmost targeted sectors include government, think tank, and education. These sectors often hold political documents or do sensitive research for their governments. Another interesting phenomena would be China’s attacks against South Korea which were stealthy and low profile in the past. But now China’s attacks turned to become high profile and public, threat actors such as 曉騎營 or 騰蛇 are some good example. Cryptocurrency sectors in this area are targeted and infiltrated by North Korean actors. For the threat actors part, China and North Korea actors dominate this area. North Korean actors are busy collecting geopolitical intelligence and another mission: earning money for their country. In contrast, Chinese APT operations become more stealthy and harder to detect; there are several big campaigns of Barracuda, Fortigate, Citrix or ArrayVPN vulnerabilities. Many of the events are still under investigation or even uncovered yet. No.3 Targeted Country / Region: South Asia & Southeast Asia The third target country / region is the South Asia and Southeast Asia region. Our observations show attacks in this area are driven by issues of the South China Sea, border issues or belt & road and shift of international organization’s factory. That was reflected in the most targeted sectors - military and critical infrastructure are all closely bundled with these issues. In the southeast Asia region, threat actors from China such as Polaris, Amoeba, Gudiao and Vietnam originated groups such as SLIME43 or OceanLotus are very active in these regions. The interesting part regarding Vietnamese APT groups is that they are not only a big concern of neighboring countries but also the domestic people in Vietnam. Our engagement with Vietnamese customers shows their great fear of being intruded by OceanLotus. In the South Asia region, China is also busy attacking and monitoring their neighbors. People might consider Pakistan to be a good friend of China so they could be spared. In contrast, our data shows Pakistan to be highly targeted and infiltrated by China. Another interesting thing is that India and Pakistan both have their own cyber actors and they are fighting with each other a lot. Conclusion 2023 is a busy year, both for threat actors and defenders. Also, more tensions in geopolitics will keep bringing more cyber attacks. New technology might solve human’s problems, but not for attack and defense scenarios. New technology becomes a new opportunity for attackers as well (e.g. cloud services, AI). The reason is that targeted attacks are human-driven; defenders should address human problems by adopting threat intelligence. No one can be spared in the war in the cyber world, so be prepared! 本篇文章為節錄版,摘述關鍵數據與威脅情資分析。欲取得完整《2023年威脅態勢回顧》報告,您可以直接填寫文章末尾表格,我們將透過電子郵件、寄送給您。 本篇文章改寫自《2023 H2 Campaign Tracking Report: APT Threat Landscape in Asia》,探索與此相關的報告與更多亞太地區的威脅情資,立刻申請威脅情資平台 ThreatVision 試用機會。請在 ThreatVision 頁面說明您希望申請試用。