¶ñÒâÈí¼þDollyWayÈëÇÖ³¬20,000¸öWordPressÍøÕ¾
Ðû²¼Ê±¼ä 2025-03-201. ¶ñÒâÈí¼þDollyWayÈëÇÖ³¬20,000¸öWordPressÍøÕ¾
3ÔÂ19ÈÕ£¬×Ô2016ÄêÆð£¬ÃûΪ¡°DollyWay¡±µÄ¶ñÒâÈí¼þÒÑÈëÇÖÈ«ÇòÁè¼Ý20,000¸öWordPressÍøÕ¾£¬Í¨¹ýÖØ¶¨ÏòÓû§ÖÁ¶ñÒâÕ¾µã¾ÙÐÐÚ²ÆÔ˶¯¡£DollyWayÒÑÀú¾¶à´ÎÉý¼¶£¬½ÓÄÉÏȽøµÄÌӱܡ¢ÖØÐÂѬȾºÍÇ®±Ò»¯Õ½ÂÔ¡£×îа汾£¨v3£©×÷Ϊ´óÐÍÕ©ÆÖض¨Ïòϵͳ£¬Ê¹Óòå¼þºÍÖ÷ÌâÎó²î¹¥»÷WordPressÍøÕ¾¡£×èÖ¹2025Äê2Ô£¬DollyWayÿÔ±¬·¢1000Íò´ÎÚ²ÆÐÔչʾ£¬Í¨¹ýÐéαµÄÔ¼»á¡¢¶Ä²©¡¢¼ÓÃÜºÍ³é½±ÍøÕ¾Ó¯Àû£¬Ê¹ÓÃVexTrioºÍLosPollosÁªÊôÍøÂçʵÏÖÁ÷Á¿±äÏÖ¡£¸Ã¶ñÒâÈí¼þͨ¹ýÁ÷Á¿Ö¸µ¼ÏµÍ³É¸Ñ¡·Ã¿Í£¬ÒÀ¾ÝÆäλÖá¢×°±¸ÀàÐͺÍÒý¼öÈªÔ´ÖØ¶¨ÏòÁ÷Á¿¡£¹¥»÷ÕßʹÓá°wp_enqueue_script¡±¾ç±¾×¢ÈëÈëÇÖÍøÕ¾£¬Í¨¹ý¶à½×¶Î²Ù×÷ʵÏÖ×îÖÕÖØ¶¨Ïò¡£DollyWay»¹¾ß±¸×ÔÎÒÔÙѬȾÄÜÁ¦£¬È·±£ÆäÔÚÿ´ÎÒ³Ãæ¼ÓÔØÊ±×Ô¶¯ÖØÐÂÑ¬È¾ÍøÕ¾£¬ÄÑÒÔɨ³ý¡£Ëüͨ¹ýÈö²¥PHP´úÂëÖÁÔ˶¯²å¼þ£¬²¢Ìí¼Ó»ìÏýµÄ¶ñÒâÈí¼þƬ¶ÏµÄWPCode²å¼þ¸±±¾ÊµÏÖ³¤ÆÚÐÔ¡£±ðµÄ£¬DollyWay½¨ÉèÒþ²ØµÄÖÎÀíÔ±Óû§ÕË»§£¬½øÒ»²½ÔöÌí·ÀÓùÄѶȡ£GoDaddyÒÑ·ÖÏíÓëDollyWayÏà¹ØµÄ¹¥»÷Ö¸±êÁÐ±í£¬ÒÔÖú·ÀÓù´ËÍþв£¬²¢½«Ðû²¼¸ü¶àϸ½ÚÕ¹ÏÖÆä»ù´¡ÉèÊ©ºÍת±äÕ½ÂÔ¡£
https://www.bleepingcomputer.com/news/security/malware-campaign-dollyway-breached-20-000-wordpress-sites/
2. ¸ú×ÙÈí¼þSpyXÊý¾Ýй¶£¬½ü200ÍòÓû§¼Í¼ÔâÆØ¹â
3ÔÂ19ÈÕ£¬Ò»¿îÏûºÄ¼¶Ìع¤Èí¼þSpyXÓÚÈ¥ÄêÔâÓöÊý¾Ýй¶£¬Ó°Ïì°üÀ¨ÊýǧÃûÆ»¹ûÓû§ÔÚÄڵĽü200ÍòÈË¡£´Ë´Îй¶ÊÂÎñ¿É×·ËÝÖÁ2024Äê6Ô£¬µ«´Ëǰδ±»±¨µÀ£¬SpyXÔËÓªÉÌҲδ֪ͨÆä¿Í»§»òÄ¿µÄÓû§¡£SpyX¼Ò×å×Ô2017ÄêÒÔÀ´Òѱ¬·¢25´ÎÊý¾Ýй¶£¬Åú×¢ÏûºÄ¼¶Ìع¤Èí¼þÐÐÒµÒ»Á¬¼¤Ôö£¬ÑÏÖØÍþвСÎÒ˽¼ÒÒþ˽¡£Ð¹Â¶Êý¾Ý°üÀ¨197ÍòÌõΨһÕÊ»§¼Í¼¼°µç×ÓÓʼþµØµã£¬Éæ¼°SpyX¼°Æä¿Ë¡°æ±¾MSafelyºÍSpyPhone¡£Ô¼40%µÄµç×ÓÓʼþµØµãÒÑÔÚ¡°ÎÒ±»ºÚÁË¡±ÍøÕ¾ÉÏ·ºÆð¹ý¡£´Ë´Îй¶»¹ÓÐÊýµØÕ¹ÏÖÁËSpyXÔõÑùÃé×¼AppleÓû§£¬Ð¹Â¶µÄ»º´æÖаüÀ¨Ô¼17,000×éÃ÷ÎÄAppleÕÊ»§Óû§ÃûºÍÃÜÂë¡£Êý¾ÝÕæÊµÐÔÒÑ»ñµÃ²¿·ÖÊܺ¦ÕßÈ·ÈÏ£¬Ïà¹ØÆ¾Ö¤ÒÑÌṩӦƻ¹û¡£¹È¸èÒѳ·ÏÂÓëSpyXÔ˶¯Ïà¹ØµÄChromeÀ©Õ¹³ÌÐò¡£TechCrunchΪAndroidÓû§ÌṩÁËÌØ¹¤Èí¼þÒÆ³ýÖ¸ÄÏ£¬½¨ÒéÆôÓÃGoogle Play Protect¡¢Ê¹ÓÃË«ÖØÉí·ÝÑéÖ¤µÈ²½·¥±£»¤ÕÊ»§Çå¾²¡£iPhoneºÍiPadÓû§Ó¦¼ì²é²¢É¾³ý²»ÊìϤµÄ×°±¸£¬È·±£Ê¹Óó¤¶øÆæÒìµÄÃÜÂ룬²¢ÆôÓÃË«ÖØÉí·ÝÑéÖ¤¡£
https://techcrunch.com/2025/03/19/data-breach-at-stalkerware-spyx-affects-close-to-2-million-including-thousands-of-apple-users/
3. ±öϦ·¨ÄáÑÇÖݽÌÓý¹¤»áÊý¾Ýй¶ӰÏì50ÍòÈË
3ÔÂ19ÈÕ£¬±öϦ·¨ÄáÑÇÖÝ×î´óµÄ¹«¹²²¿·Ö¹¤»á±öϦ·¨ÄáÑÇÖݽÌÓýлá (PSEA) ÓÚ2024Äê7Ô±¬·¢ÁËÒ»ÆðÇå¾²ÊÂÎñ£¬µ¼ÖÂÁè¼Ý517,487ÃûСÎÒ˽¼ÒµÄÐÅÏ¢±»µÁ£¬°üÀ¨Î÷ϯ¡¢Ö§³ÖÖ°Ô±¡¢¸ßµÈ½ÌÓýÖ°Ô±µÈ½ÌÓýרҵÈËÊ¿¡£¾ÝPSEA͸¶£¬±»µÁÐÅÏ¢¿ÉÄܰüÀ¨Ð¡ÎÒ˽¼Ò¡¢²ÆÎñºÍ¿µ½¡Êý¾Ý£¬ÈçÉç»áÇå¾²ºÅÂë¡¢Ö§¸¶¿¨ÐÅÏ¢¡¢»¤ÕÕÐÅÏ¢µÈ¡£ÎªÓ¦¶Ô´Ë´ÎÊÂÎñ£¬PSEAΪÊÜÓ°ÏìµÄСÎÒ˽¼ÒÌṩÁËÃâ·ÑµÄIDXÐÅÓÃ¼à¿ØºÍÉí·Ý»Ö¸´·þÎñ£¬²¢½¨ÒéËûÃÇ¼à¿Ø²ÆÎñÕË»§ºÍÐÅÓñ¨¸æ£¬ÉèÖÃڲƾ¯±¨»òÇå¾²¶³½á¡£Ö»¹ÜPSEAδÃ÷È·Ö¸³ö¹¥»÷ÕßÉí·Ý£¬µ«RhysidaÀÕË÷Èí¼þÍÅ»ïÉù³Æ¶Ô´Ë´ÎÈëÇÖÈÏÕæ£¬²¢ÒªÇóÖ§¸¶20±ÈÌØ±ÒÊê½ð¡£ËäÈ» PSEA ²¢Î´Í¸Â¶ÊÇ·ñÖ§¸¶ÁËÊê½ðÒÔ±ÜÃâÊý¾Ýй¶£¬µ«¸ÃÀÕË÷Èí¼þÍÅ»ïÒÑ´ÓÆä°µÍøÐ¹ÃÜÍøÕ¾ÖÐɾ³ýÁËÏà¹ØÌõÄ¿¡£CISA ºÍ FBIÖÒÑԳƣ¬Rhysida µÄÁ¥Êô»ú¹¹ÊÇÕë¶Ô¸÷Ðи÷Òµ×éÖ¯ÌᳫµÄ¶àÆðʱ»úÐÔ¹¥»÷µÄÄ»ºóºÚÊÖ£¬¶øÃÀ¹úÎÀÉúÓ빫ÖÚ·þÎñ²¿ (HHS) ÔòÒÔΪ RhysidaÓëÕë¶ÔÒ½ÁƱ£½¡×éÖ¯µÄ¹¥»÷Óйء£
https://www.bleepingcomputer.com/news/security/pennsylvania-education-union-data-breach-hit-500-000-people/
4. ÎÚ¿ËÀ¼¾ü·½³ÉΪÐÂÒ»ÂÖSignalÍøÂç´¹ÂÚ¹¥»÷µÄÄ¿µÄ
3ÔÂ19ÈÕ£¬ÎÚ¿ËÀ¼ÅÌËã»úÓ¦¼±·´Ó¦Ð¡×飨CERT-UA£©·¢³öÖÒÑÔ£¬Ö¸³ö½üÆÚ±£´æ¸ß¶ÈÕë¶ÔÐԵĹ¥»÷£¬¹¥»÷ÕßʹÓñ»ÈëÇÖµÄSignalÕË»§Ïò¹ú·À¹¤Òµ¹«Ë¾ºÍ¹ú¼Ò¾ü¶Ó³ÉÔ±·¢ËͶñÒâÈí¼þ¡£ÕâЩ¹¥»÷ʼÓÚ±¾Ô£¬Í¨¹ýαװ³É¾Û»á±¨¸æµÄµµ°¸¾ÙÐУ¬µµ°¸ÖаüÀ¨Ò»¸öPDFºÍÒ»¸ö¿ÉÖ´ÐÐÎļþ£¬ºóÕß±»Ö¤ÊµÎªDarkTortilla¼ÓÃÜÆ÷/¼ÓÔØÆ÷£¬ÓÃÓÚ½âÃܲ¢Ö´ÐÐÔ¶³Ì»á¼ûľÂíDark Crystal RAT (DCRAT)¡£CERT-UAÒѽ«´Ë´ÎÔ˶¯ÔÚUAC-0200ϾÙÐиú×Ù£¬ÕâÊÇÒ»¸ö×Ô2024Äê6ÔÂÒÔÀ´¾ÍʹÓÃSignal¾ÙÐÐÀàËÆ¹¥»÷µÄÍþв¼¯Èº¡£×î½üµÄ¹¥»÷ÖУ¬ÍøÂç´¹ÂÚÓÕ¶üÒѸüУ¬ÖصãתÏòÓëÎÞÈË»ú¡¢µç×ÓսϵͳºÍÆäËû¾üÊÂÊÖÒÕÏà¹ØµÄÖ÷Ì⡣ͬʱ£¬GoogleÍþвÇ鱨С×鱨¸æ³Æ£¬¶íÂÞ˹ºÚ¿ÍÕýÔÚÀÄÓÃSignalµÄ¡°Á´½Ó×°±¸¡±¹¦Ð§À´Î´¾ÊÚȨ»á¼û¸ÐÐËȤµÄÕÊ»§¡£Òò´Ë£¬CERT-UA½¨ÒéSignalÓû§¹Ø±Õ¸½¼þµÄ×Ô¶¯ÏÂÔØ£¬¶ÔËùÓÐÐÂÎżá³ÖÉóÉ÷£¬²¢°´ÆÚ¼ì²éÁ´½Ó×°±¸ÁÐ±í¡£±ðµÄ£¬Óû§»¹Ó¦½«Í¨Ñ¶Ó¦ÓóÌÐò¸üе½×îа汾£¬²¢ÆôÓÃË«ÒòËØÉí·ÝÑéÖ¤£¬ÒÔÔöÇ¿ÕÊ»§±£»¤¡£
https://www.bleepingcomputer.com/news/security/ukrainian-military-targeted-in-new-signal-spear-phishing-attacks/
5. Arcane¶ñÒâÈí¼þÇÔÈ¡´ó×ÚÓû§Êý¾Ý£¬Èö²¥·½·¨Ò»Ö±Ñݱä
3ÔÂ19ÈÕ£¬Ð·¢Ã÷µÄArcaneÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þÕýÔÚÇÔÈ¡´ó×ÚÓû§Êý¾Ý£¬°üÀ¨VPNÕÊ»§Æ¾Ö¤¡¢ÓÎÏ·¿Í»§¶Ë¡¢ÐÂÎÅÓ¦ÓóÌÐòºÍÍøÂçä¯ÀÀÆ÷ÖеÄÐÅÏ¢¡£¸Ã¶ñÒâÈí¼þÔ˶¯Ê¼ÓÚ2024Äê11Ô£¬Ö÷ҪѬȾ¶íÂÞ˹¡¢°×¶íÂÞ˹ºÍ¹þÈø¿Ë˹̹µÄÓû§¡£Arcaneͨ¹ýYouTubeÊÓÆµÐû´«ÓÎÏ·×÷±×ºÍÆÆ½â£¬ÓÕÆÓû§ÏÂÔØÊÜÃÜÂë±£»¤µÄµµ°¸£¬ÆäÖаüÀ¨»ìÏýµÄ¾ç±¾ºÍ¶ñÒâ¿ÉÖ´ÐÐÎļþ¡£¸Ã¶ñÒâÈí¼þ»¹»áΪWindows DefenderµÄSmartScreen¹ýÂËÆ÷Ìí¼Óɨ³ýÏî»òÍêÈ«¹Ø±ÕËü¡£ArcaneµÄÆÕ±éÊý¾ÝÇÔÈ¡ÐÐΪʹÆäÔÚÖÚ¶àµÄÐÅÏ¢ÇÔÈ¡Èí¼þÖÐÍÑÓ±¶ø³ö£¬Ëü¿ÉÒÔÇÔȡӲ¼þºÍÈí¼þÏêϸÐÅÏ¢¡¢Ó¦ÓóÌÐòÕÊ»§Êý¾Ý¡¢ÉèÖÃÎļþÒÔ¼°ÍøÂçä¯ÀÀÆ÷ÖеĵǼÐÅÏ¢¡¢ÃÜÂëºÍcookie¡£±ðµÄ£¬Arcane»¹¿ÉÒÔ²¶»ñÆÁÄ»½ØÍ¼ºÍÒÑÉúÑĵÄWi-FiÍøÂçÃÜÂ롣ѬȾArcaneÐÅÏ¢ÇÔÈ¡³ÌÐòЧ¹û²»¿°ÉèÏ룬Óû§Ó¦Ê±¿ÌÇмÇÏÂÔØÎ´ÊðÃûµÄµÁ°æºÍ×÷±×¹¤¾ßµÄΣº¦£¬²¢ÍêÈ«×èֹʹÓÃÕâЩ¹¤¾ß¡£
https://www.bleepingcomputer.com/news/security/new-arcane-infostealer-infects-youtube-discord-users-via-game-cheats/
6. ClearFakeʹÓÃreCAPTCHAºÍTurnstile·Ö·¢¶ñÒâÈí¼þ
3ÔÂ19ÈÕ£¬ClearFakeÊÇÒ»¸öÍþвÔ˶¯¼¯Èº£¬×Ô2023Äê7ÔÂÊ×´ÎÆØ¹âÒÔÀ´£¬Ò»Ö±Ê¹ÓÃÐéαµÄÍøÂçä¯ÀÀÆ÷¸üС¢reCAPTCHA»òCloudflare TurnstileÑéÖ¤µÈÓÕ¶ü·Ö·¢Lumma StealerºÍVidar StealerµÈ¶ñÒâÈí¼þ¡£¸ÃÔ˶¯½ÓÄÉEtherHidingÊÖÒÕºÍClickFixÕ½ÂÔ£¬Ê¹ÓñҰ²ÖÇÄÜÁ´ºÏÔ¼»ñÈ¡ÓÐÓÃÔØºÉ£¬Ê¹¹¥»÷Á´¸ü¾ßµ¯ÐÔ¡£×îа汾ÒýÈëWeb3¹¦Ð§À´¶Ô¿¹ÆÊÎö²¢¼ÓÃÜHTML´úÂë¡£×èÖ¹2024Äê5Ô£¬ClearFake¹¥»÷ÒÑѬȾÁè¼Ý9,300¸öÍøÕ¾£¬2024Äê7ÔÂÔ¼ÓÐ200,000Ãû×ÔÁ¦Óû§¿ÉÄÜÊܵ½¹¥»÷¡£±ðµÄ£¬Áè¼Ý100¼ÒÆû³µ¾ÏúÉÌÍøÕ¾Êܵ½ClickFixÓÕ¶ü¹¥»÷£¬µ¼ÖÂSectopRAT¶ñÒâÈí¼þ°²ÅÅ¡£Çå¾²Ñо¿Ô±Ö¸³ö£¬ÕâЩѬȾÍùÍù±¬·¢ÔÚµÚÈý·½·þÎñÉÏ£¬ÈçLES AutomotiveµÄÊÓÆµ·þÎñ¡£ClearFake»¹Ó뼸ÆðÍøÂç´¹ÂÚÔ˶¯Ïà¹Ø£¬Ö¼ÔÚÍÆ¹ã¶ñÒâÈí¼þ¼Ò×å²¢¾ÙÐÐÆ¾Ö¤ÍøÂç¡£Ëæ×ÅÉç»á¹¤³ÌÔ˶¯±äµÃÔ½À´Ô½ÖØ´ó£¬×éÖ¯ºÍÆóÒµ±ØÐèʵÑéǿʢµÄÉí·ÝÑéÖ¤ºÍ»á¼û¿ØÖÆ»úÖÆÀ´µÖÓù¹¥»÷¡£
https://thehackernews.com/2025/03/clearfake-infects-9300-sites-uses-fake.html


¾©¹«Íø°²±¸11010802024551ºÅ