Vo1d½©Ê¬ÍøÂçбäÖÖ£º´ó¹æÄ£Ñ¬È¾Android TV×°±¸²¢ÓÃÓÚ²»·¨Ô˶¯
Ðû²¼Ê±¼ä 2025-02-281. Vo1d½©Ê¬ÍøÂçбäÖÖ£º´ó¹æÄ£Ñ¬È¾Android TV×°±¸²¢ÓÃÓÚ²»·¨Ô˶¯
2ÔÂ27ÈÕ£¬Vo1d¶ñÒâÈí¼þ½©Ê¬ÍøÂçµÄбäÖÖÒÑѬȾȫÇò226¸ö¹ú¼Ò/µØÇøµÄ1,590,299̨Android TV×°±¸£¬²¢½«ÆäÕÐļΪÄäÃûÊðÀí·þÎñÆ÷ÍøÂçµÄÒ»²¿·Ö¡£Xlab×ÔÈ¥Äê11Ô¸ú×Ù´ËÔ˶¯£¬·¢Ã÷¸Ã½©Ê¬ÍøÂçÔÚ2025Äê1ÔÂ14ÈÕµÖ´ïá۷壬ÏÖÔÚÓµÓÐ80Íò»îÔ¾»úеÈË¡£Ð°汾µÄVo1d½©Ê¬ÍøÂçδÊÜÖ®Ç°ÆØ¹âÓ°Ï죬¼ÌÐø´ó¹æÄ£ÔË×÷£¬²¢¾ß±¸ÏȽøµÄ¼ÓÃÜÊÖÒÕ¡¢Óе¯ÐÔµÄDGA»ù´¡ÉèÊ©¼°ÒþÉíÄÜÁ¦¡£Æä¹æÄ£ÖØ´ó£¬Áè¼ÝBigpanziµÈ½©Ê¬ÍøÂ磬ѬȾÖ÷Òª¼¯ÖÐÔÚ°ÍÎ÷¡¢ÄÏ·Ç¡¢Ó¡¶ÈÄáÎ÷Ñǵȵء£Ñо¿Ö°Ô±·¢Ã÷£¬½©Ê¬ÍøÂçѬȾÊýÄ¿±£´æÏÔÖø¼¤ÔöÕ÷Ïó£¬ÍƲâÓë¡°×âÁÞ-»Ø±¨¡±ÖÜÆÚÓйأ¬¼´Vo1d½«½©Ê¬ÍøÂç»ù´¡ÉèÊ©³ö×â¸øÆäËû×éÖ¯¾ÙÐв»·¨Ô˶¯¡£±ðµÄ£¬Vo1d»¹¾ßÓÐ¹ã¸æÚ²Æ¹¦Ð§£¬Í¨¹ýÄ£Äâ¹ã¸æµã»÷»òÊÓÆµÔ¢Ä¿Î±ÔìÓû§»¥¶¯£¬ÎªÚ²ÆÐÔ¹ã¸æÉÌ´´Á¢ÊÕÈë¡£¼øÓÚѬȾÁ´Î´Öª£¬½¨ÒéAndroid TVÓû§½ÓÄÉÕûÌåÇå¾²ÒªÁì¼õÇáVo1dÍþв£¬°üÀ¨´Ó¿É¿¿¹©Ó¦É̹ºÖÃ×°±¸¡¢×°Öù̼þºÍÇå¾²¸üС¢×èÖ¹ÏÂÔØ·Ç¹Ù·½Ó¦ÓóÌÐò¡¢½ûÓÃÔ¶³Ì»á¼û¹¦Ð§¼°ÀëÏß´æ´¢µÈ¡£
https://www.bleepingcomputer.com/news/security/vo1d-malware-botnet-grows-to-16-million-android-tvs-worldwide/
2. ºÚ¿Íð³ą̈Íå˰Îñ»ú¹Ø°²ÅÅ Winos 4.0 ¶ñÒâÈí¼þ
2ÔÂ27ÈÕ£¬FortiGuard Labs·¢Ã÷ÁËÕë¶Ǫ̂ÍåÆóÒµµÄжñÒâÈí¼þÔ˶¯£¬¸ÃÔ˶¯°²ÅÅÁËÒ»¸öÃûΪWinos 4.0µÄ¸ß¼¶¶ñÒâÈí¼þ¿ò¼Ü¡£¸Ã¶ñÒâÈí¼þͨ¹ýÈ«ÐÄÉè¼ÆµÄ´¹ÂÚµç×ÓÓʼþ¾ÙÐÐÈö²¥£¬ÕâЩÓʼþð³ą̈Íå¹ú¼Ò˰Îñ¾Ö²¢Éù³Æ°üÀ¨Ë°Îñ¼ì²é¹«Ë¾Ãûµ¥£¬ÓÕʹÊÕ¼þÈËÏÂÔØ°üÀ¨¶ñÒâDLLµÄ¸½¼þ¡£Winos 4.0½ÓÄÉÁ˶à½×¶ÎѬȾÀú³Ì£¬Í¨¹ýһϵÁпÉÖ´ÐÐÎļþºÍDLLÎļþÕö¿ª¹¥»÷£¬×îÖÕÄ¿µÄÊÇÇÔÈ¡Ãô¸ÐÐÅÏ¢ÒÔÓÃÓÚδÀ´µÄ¶ñÒâÔ˶¯¡£¸Ã¶ñÒâÈí¼þ¾ßÓи߶ȵÄÎÞаÐÔºÍ˳ӦÐÔ£¬Äܹ»ÈƹýUAC¡¢ÍøÂçϵͳÐÅÏ¢¡¢½ûÓÃÆÁÄ»±£»¤³ÌÐòºÍÊ¡µç¹¦Ð§£¬²¢×Ô¶¯¼àÊÓºÍʹÓÃÓû§Ô˶¯£¬Èç²¶»ñÆÁÄ»½ØÍ¼¡¢¼Í¼»÷¼üºÍ¼ôÌù°åÄÚÈݵȡ£ÎªÁ˱£»¤×Ô¼ºÃâÊÜ´ËÀà¶ñÒâÈí¼þµÄË𺦣¬Óû§ÐèÒª¶Ôδ¾ÇëÇóµÄµç×ÓÓʼþ¼á³Ö¸ß¶ÈСÐÄ£¬×èÖ¹·¿ªÑ¹ËõÎļþ¸½¼þ£¬²¢ÆôÓÃʵʱɨÃèÒÔ¼ì²âºÍ×èÖ¹Íþв¡£×¨¼Ò½¨Òé½ÓÄɶàÌõÀí·ÀÓùÒªÁ죬½áÊÊÓû§½ÌÓýºÍÏȽøµÄÍþв¼ì²âÊÖÒÕÀ´×èÖ¹Éç»á¹¤³Ì¹¥»÷¡£
https://hackread.com/hackers-impersonate-taiwans-tax-authority-winos-4-0-malware/
3. 49,000¸ö»á¼ûÖÎÀíϵͳÉèÖùýʧ̻¶£¬Î£¼°È«ÇòÒþ˽ÓëÎïÀíÇå¾²
2ÔÂ27ÈÕ£¬ModatµÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷È«Çò¹æÄ£ÄÚ±£´æ49,000¸öÉèÖùýʧÇÒ̻¶ÔÚ»¥ÁªÍøÉϵĻá¼ûÖÎÀíϵͳ£¨AMS£©£¬ÕâЩϵͳԱ¾ÓÃÓÚͨ¹ýÉúÎïʶ±ð¡¢Éí·ÝÖ¤»ò³µÅÆ¿ØÖÆÔ±¹¤¶ÔÐÞ½¨Îï¡¢ÉèÊ©ºÍ½ûÇøµÄ»á¼û¡£È»¶ø£¬ÓÉÓÚδ׼ȷÉèÖÃÇå¾²Éí·ÝÑéÖ¤£¬ÈκÎÈ˶¼¿ÉÒÔÇáËÉ»á¼ûÕâЩϵͳ£¬µ¼ÖÂÃô¸ÐµÄÔ±¹¤Êý¾Ý£¨ÈçСÎÒ˽¼ÒÉí·ÝÐÅÏ¢¡¢ÉúÎïÌØÕ÷Êý¾Ý¡¢ÕÕÆ¬¡¢ÊÂÇéʱ¼ä±íºÍ»á¼ûÈÕÖ¾£©±»Ð¹Â¶¡£Õâ²»µ«Î£¼°ÁËÒþ˽Çå¾²£¬»¹¿ÉÄܶÔÒªº¦»ù´¡ÉèÊ©£¨ÈçÕþ¸®ÐÞ½¨¡¢·¢µçÕ¾ºÍË®´¦Öóͷ£ÉèÊ©£©µÄÎïÀíÇå¾²×é³ÉÍþв¡£±ðµÄ£¬Ì»Â¶µÄÐÅÏ¢»¹¿ÉÄܱ»ÓÃÓÚÕë¶ÔÏà¹Ø×éÖ¯Ìá³«ÍøÂç´¹ÂÚºÍÉç»á¹¤³Ì¹¥»÷¡£ÔÚÒâ´óÀû¡¢Ä«Î÷¸ç¡¢Ô½ÄϺÍÃÀ¹úµÈ¹ú¼Ò£¬Ì»Â¶µÄAMSϵͳÊýÄ¿ÓÈΪͻ³ö¡£Ö»¹ÜÑо¿Ö°Ô±ÒÑÁªÏµÏµÍ³ËùÓÐÕß²¢¼û¸æÎ£º¦£¬µ«ÉÐδÊÕµ½Æð¾¢»ØÓ¦¡£Ò»Ð©¹©Ó¦ÉÌÌåÏÖÕýÔÚÓëÊÜÓ°ÏìµÄ¿Í»§ÏàÖú½â¾öÎÊÌâ¡£ModatΪAMSÓû§ÌṩÁ˶àÏîÇå¾²½¨Ò飬°üÀ¨½«ÏµÍ³ÀëÏß»òÖÃÓÚ·À»ðǽºÍVPNºóÃæ¡¢¸ü¸ÄĬÈÏÖÎÀíԱƾ֤¡¢ÊµÑé¶àÒòËØÉí·ÝÑéÖ¤¡¢Ó¦ÓÃ×îÐÂÈí¼þºÍ¹Ì¼þ¸üÐÂÒÔ¼°ïÔ̲»ÐëÒªµÄÍøÂç·þÎñ¡£Í¬Ê±£¬½¨ÒéÒÔ¼ÓÃÜÐÎʽ´æ´¢ÉúÎïÌØÕ÷Êý¾ÝºÍPII£¬²¢É¨³ýÒÑÍùÔ±¹¤µÄÊý¾ÝÒÔ×èֹδ¾ÊÚȨµÄ»á¼û¡£
https://www.bleepingcomputer.com/news/security/over-49-000-misconfigured-building-access-systems-exposed-online/
4. ·ÆÂɱö¾ü·½È·ÈÏÆäÍøÂçÔâÊܺڿ͹¥»÷
2ÔÂ27ÈÕ£¬·ÆÂɱö¾ü·½È·ÈÏÆäÍøÂçÔâÊÜÁËÒ»´Î¡°²»·¨»á¼ûÍýÏ롱µÄ¹¥»÷£¬¾Ý³ÆÓÉÒ»¸öÃûΪExodus SecurityµÄºÚ¿Í×éÖ¯Ìᳫ¡£Ö»¹Ü¾ü·½Ñ¸ËÙ×èÖ¹Á˹¥»÷£¬µ«ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡10,000ÌõÏÖÒÛºÍÍËÒÛÎäÊ¿µÄ¼Í¼£¬°üÀ¨Ãô¸ÐµÄСÎÒ˽¼ÒºÍ¾üÊÂÐÅÏ¢¡£Ö»¹ÜÊý¾ÝµÄÕæÊµÐÔºÍÈ·ÇÐÊýÄ¿ÉÐδ»ñµÃºËʵ£¬µ«ºÚ¿ÍÖÒÑÔ˵£¬ÈôÊÇÍâµØºÚ¿ÍÄܹ»ÊµÏÖÕâÑùµÄÉøÍ¸£¬ÄÇôÍâ¹ú¹ú¼ÒÖ§³ÖµÄÍþвÐÐΪÕß¿ÉÄÜ»á×öµÃ¸üÔã¡£Exodus SecurityÊǸõØÇø×î»îÔ¾µÄºÚ¿Í×éÖ¯Ö®Ò»£¬½ñÄêÔçЩʱ¼ä»¹Éù³Æ¶Ô·ÆÂɱöˮʦµÄÏ®»÷ÊÂÎñÈÏÕæ¡£·ÆÂɱöÕþ¸®×î½ü»¹·¢Ã÷Íâ¹úÊÔͼ»ñÈ¡Ç鱨Êý¾Ý£¬²¢¾Ð²¶ÁËÈýÃûÉæÏÓ¶ÔÒªº¦»ù´¡ÉèÊ©¾ÙÐмàÊÓµÄÏÓÒÉÈË¡£Ëæ×ŵØÇøµØÔµÕþÖÎÖ÷ÒªÊ±ÊÆÉý¼¶£¬·ÆÂɱöµÄÍøÂç¹¥»÷ºÍÐéαÐÅÏ¢Ô˶¯¼±¾çÔöÌí£¬´ó²¿·ÖÔ˶¯¹é×ïÓÚÊÔÍ¼ÆÆËðÈËÃǶÔÕþ¸®»ú¹¹ÐÅÐĵĺڿÍÔ˶¯ÕûÌå¡£
https://therecord.media/philippines-army-confirms-hack
5. Angry Likho APTÍøÂçÌØ¹¤×éÖ¯ÔÙÏÆ¹¥»÷À˳±£¬Ö÷ÒªÕë¶Ô¶í°××éÖ¯
2ÔÂ27ÈÕ£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷£¬ÃûΪAngry Likho APT£¨Ò²±»³Æ×÷Sticky Werewolf£©µÄÍøÂçÌØ¹¤×éÖ¯ÔٴλîÔ¾£¬Ö÷ÒªÕë¶Ô¶íÂÞ˹ºÍ°×¶íÂÞ˹µÄ×éÖ¯ÌᳫÐÂÒ»²¨ÍøÂç¹¥»÷¡£¸Ã×éÖ¯×Ô2023ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬Í¨¹ý·¢ËÍÕë¶ÔÐÔ¼«Ç¿µÄÓã²æÊ½ÍøÂç´¹ÂÚµç×ÓÓʼþ£¬¸½´ø¶ñÒâRARÎļþ£¬´¥·¢ÖØ´óµÄѬȾÁ´£¬×îÖÕ°²ÅÅÃûΪLumma StealerµÄÇÔÈ¡¶ñÒâÈí¼þ¡£ÕâЩÓʼþºÍÓÕ¶üÎļþʹÓÃÁ÷ÀûµÄ¶íÓï±àд£¬Åú×¢¹¥»÷Õß¿ÉÄÜÊǶíÓïĸÓïÈËÊ¿¡£ËäÈ»´ó´ó¶¼Êܺ¦Õß¶¼ÔÚ¶íÂÞ˹ºÍ°×¶íÂÞ˹£¬µ«Ò²·¢Ã÷ÁËһЩÆäËû¹ú¼ÒµÄÎÞÒâÄ¿µÄ¡£Lumma StealerÖ¼ÔÚ´ÓÊÜѬȾµÄ×°±¸ÖлñÈ¡Ãô¸ÐÊý¾Ý£¬°üÀ¨ÏµÍ³ÐÅÏ¢¡¢Ð¡ÎÒ˽¼ÒÊý¾ÝÒÔ¼°À´×ÔÊ¢ÐÐä¯ÀÀÆ÷ºÍ¼ÓÃÜÇ®±ÒÇ®°üµÄÊý¾Ý¡£×î½ü£¬¶íÂÞË¹ÍøÂçÇå¾²¹«Ë¾F6±¨¸æÁËAngry Likho APTµÄй¥»÷£¬Éæ¼°°üÀ¨Base64±àÂëµÄ¶ñÒâ¸ºÔØµÄͼÏñÎļþ£¬²¢·¢Ã÷Á˸Ã×é֯ʹÓõöÐÂÏÂÁî·þÎñÆ÷¡£Ö»¹Ü¸Ã×é֯ÿ´Î¹¥»÷¶¼»á×ö³öϸ΢¸Ä±ä£¬µ«ÆäÒªÁìʼÖÕÈçÒ»£¬¼´ÓÐÕë¶ÔÐԵĴ¹ÂÚµç×ÓÓʼþ¡¢×Ô½âѹ´æµµºÍÖ¼ÔÚÇÔÈ¡Ãô¸ÐÊý¾ÝµÄ×îÖÕÓÐÓÃÔØºÉ¡£
https://hackread.com/angry-likho-apt-lumma-stealer-attacks-on-russia/
6. CERT-UAÖÒÑÔUAC-0173ʹÓÃDCRatΣº¦ÎÚ¿ËÀ¼¹«Ö¤»ú¹¹
2ÔÂ26ÈÕ£¬ÎÚ¿ËÀ¼ÅÌËã»úÓ¦¼±·´Ó¦Ð¡×飨CERT-UA£©ÖÒÑԳƣ¬ÓÐ×éÖ¯·¸·¨¼¯ÍÅUAC-0173ÔÙ´ÎÌᳫ¹¥»÷£¬Ê¹ÓÃDCRat£¨DarkCrystal RAT£©Ô¶³Ì»á¼ûľÂíѬȾÅÌËã»ú£¬×îй¥»÷ʼÓÚ2025Äê1ÔÂÖÐÑ®£¬Õë¶ÔÎÚ¿ËÀ¼¹«Ö¤Ô±¡£¹¥»÷Õßͨ¹ýÉù³Æ´ú±íÎÚ¿ËÀ¼Ë¾·¨²¿·¢Ë͵ÄÍøÂç´¹ÂÚÓʼþ£¬ÓÕµ¼ÊÕ¼þÈËÏÂÔØ¿ÉÖ´ÐÐÎļþ£¬°²ÅÅDCRat¶ñÒâÈí¼þ£¬²¢Ê¹ÓÃRDPWRAPPERµÈ¹¤¾ßʵÏÖ²¢ÐÐRDP»á»°£¬ÍŽáBOREÊÊÓóÌÐò½¨ÉèRDPÅþÁ¬¡£±ðµÄ£¬¹¥»÷»¹Éæ¼°FIDDLER×èµ²Éí·ÝÑéÖ¤Êý¾Ý¡¢NMAPÍøÂçɨÃè¡¢XWormÇÔÈ¡Ãô¸ÐÊý¾ÝµÈ¡£ÊÜѬȾϵͳ±»ÓÃ×÷·¢ËͶñÒâÓʼþµÄÇþµÀ¡£Í¬Ê±£¬CERT-UA»¹¹é×ïÓÚSandwormºÚ¿Í×éÖ¯×Ó¼¯ÈºÊ¹ÓÃÒÑÐÞ²¹µÄMicrosoft WindowsÇå¾²Îó²îÌᳫ¹¥»÷£¬Õë¶ÔÈû¶ûάÑÇ¡¢½Ý¿Ë¹²ºÍ¹úºÍÎÚ¿ËÀ¼µÄ¹©Ó¦É̹«Ë¾¡£StrikeReadyʵÑéÊÒºÍ΢ÈíÒѼͼ²¿·Ö¹¥»÷£¬Î¢ÈíÕýÔÚ×·×Ù´úºÅΪBadPilotµÄÍþв×éÖ¯¡£
https://thehackernews.com/2025/02/cert-ua-warns-of-uac-0173-attacks.html


¾©¹«Íø°²±¸11010802024551ºÅ