当前位置:首页 > 报告详情

无论何时何地……盲鹰袭击:暗影矢量案.pdf

上传人: S** 编号:1241047 2026-05-16 20页 1MB

1、1 Acronis 2026Whenever,Wherever Blind Eagle Attacks:The Shadow Vector CaseSantiago PontiroliThreat Intelligence Research Lead3 Acronis 2026The Unusual AttachmentThis campaign used scalable vector graphics(SVG),which render like imagesBut they can contain links and scriptsThat one format choice bypas

2、sed traditional defenses4 Acronis 2026A Tiny Starting PointNo advanced malware familyNo obvious threat actorNo prior indicatorsJust a suspicious attachmentToo little data to draw conclusions.5 Acronis 2026Defenders shift left.Attackers shift right.SVG is an XML based format,not a static imageWhen th

3、e user opens the file,the link executes in the browserNo exploit required,just normal user behaviorWe try to stop attacks earlier in the chain and SVG smuggling flips that model6 Acronis 20267 Acronis 2026Social Engineering FirstLocal language and institutionsThe emails impersonated Colombian courts

4、Legal notices and urgent summonsThe attackers understood their audience8 Acronis 2026“The Judicial Branch is being used by cybercriminals to steal valuable information from citizens through emails.At the Superior Council of the Judiciary,we are committed to the cybersecurity of the public.”9 Acronis

5、 2026Tactics That Keep Shifting10 Acronis 2026Under the HoodScripts,loaders,and fileless executionSimple scripts pulled additional stagesDriver-based privilege escalation using vulnerable kernel-mode driversA classic layered delivery chain for remote control and credential theft11 Acronis 202612 Acr

6、onis 202613 Acronis 2026A Familiar FingerprintLegitimate applications abused to load codeAttempts to elevate privilegesProcess hollowing and persistenceNot flashy,but effectivehttps:/ Acronis 2026Staging hosted on common platformsBitbucket,Dropbox,Discord CDNFiles blended with no

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
1. **SVG攻击绕过防御**:攻击者利用可缩放矢量图形(SVG)作为附件,因SVG可包含链接和脚本,绕过传统防御,无需漏洞利用即可在浏览器中执行链接。 2. **社会工程学精准 targeting**:邮件冒充哥伦比亚法院,使用本地语言和法律紧急通知,针对哥伦比亚受害者。 3. **多层交付链**:通过脚本加载后续阶段,利用脆弱内核驱动提权,采用经典分层传递链实现远程控制和凭证窃取。 4. **滥用合法服务**:托管阶段使用Bitbucket、Dropbox、Discord CDN等公共平台,文件混合正常流量,规避声誉防御。 5. **TTPs重于工具**:尽管使用商品化RAT和Katz Loader等工具,但长期行为模式(如持续针对哥伦比亚、类似社会工程学)指向同一威胁活动(ShadowVector),归属应基于行为而非二进制文件。
**SVG攻击之谜** **鸭子测试溯源法** **工具≠威胁本质**
客服
商务合作
小程序
服务号
折叠