ClickFix¹¥»÷¿çWindows¡¢LinuxϵͳʵÑéÉç»á¹¤³ÌÓÕÆ
Ðû²¼Ê±¼ä 2025-05-131. ClickFix¹¥»÷¿çWindows¡¢LinuxϵͳʵÑéÉç»á¹¤³ÌÓÕÆ
5ÔÂ12ÈÕ£¬¿ËÈÕ£¬Ò»ÏîʹÓÃClickFix¹¥»÷µÄÐÂÔ˶¯±»·¢Ã÷£¬¸ÃÔ˶¯Õë¶ÔWindowsºÍLinuxϵͳ£¬½ÓÄÉ¿ÉѬȾÈÎÒ»²Ù×÷ϵͳµÄÖ¸Áî¡£ClickFix×÷ΪһÖÖÉç»á¹¤³ÌÕ½ÂÔ£¬Í¨¹ýÐéαÑé֤ϵͳ»òÓ¦ÓóÌÐò¹ýʧÓÕÆÓû§ÔËÐжñÒâÏÂÁî¡£¹Å°åÉÏ£¬´ËÀ๥»÷Ö÷ÒªÕë¶ÔWindowsϵͳ£¬Í¨¹ýÓÕÆÓû§Ö´ÐÐPowerShell¾ç±¾£¬µ¼ÖÂÐÅÏ¢ÇÔÈ¡»òÀÕË÷Èí¼þѬȾ¡£È»¶ø£¬2024ÄêÒÑÓÐÔ˶¯Õë¶ÔmacOSÓû§£¬ÇÒ½üÆÚHunt.ioÑо¿Ö°Ô±·¢Ã÷£¬Óë°Í»ù˹̹ÓйصÄAPT36£¨ÓÖÃû¡°Í¸Ã÷²¿Â䡱£©Íþв×éÖ¯ÌᳫÁËÒ»ÏîÕë¶ÔLinuxϵͳµÄClickFix¹¥»÷¡£¸Ã×é֯ʹÓÃð³äÓ¡¶È¹ú·À²¿µÄÍøÕ¾£¬¸½ÉÏÐéαÐÂΟåÁ´½Ó£¬µ±Óû§µã»÷ºó£¬Æ½Ì¨»áÆÊÎöÆä²Ù×÷ϵͳ²¢Öض¨Ïòµ½ÏìÓ¦µÄ¹¥»÷Á÷¡£ÔÚWindowsϵͳÖУ¬Óû§»á¿´µ½È«ÆÁÖÒÑÔÒ³Ãæ£¬µã»÷¡°¼ÌÐø¡±ºó£¬¶ñÒâJavaScript»á½«MSHTAÏÂÁî¸´ÖÆµ½¼ôÌù°å£¬ÓÕµ¼Óû§Ö´ÐУ¬´Ó¶øÆô¶¯.NET¼ÓÔØ³ÌÐò²¢ÅþÁ¬µ½¹¥»÷Õߵص㡣ÔÚLinuxϵͳÖУ¬Óû§µã»÷¡°ÎÒ²»ÊÇ»úеÈË¡±°´Å¥ºó»á±»Öض¨Ïòµ½CAPTCHAÒ³Ãæ£¬ÓÕµ¼ÆäÖ´ÐÐshellÏÂÁ½«¡°mapeal.sh¡±¸ºÔØÍ¶·Åµ½Ä¿µÄϵͳ¡£Ö»¹ÜÄ¿½ñ°æ±¾µÄ¡°mapeal.sh¡±½ö´Ó¹¥»÷Õß·þÎñÆ÷»ñÈ¡JPEGͼÏñ£¬µ«APT36¿ÉÄÜÕýÔÚ²âÊÔLinuxѬȾÁ´µÄÓÐÓÃÐÔ£¬Î´À´¿ÉÄÜͨ¹ýÌæ»»Í¼ÏñΪshell½ÅÔÀ´×°ÖöñÒâÈí¼þ¡£
https://www.bleepingcomputer.com/news/security/hackers-now-testing-clickfix-attacks-against-linux-targets/
2. Marbled DustʹÓÃÁãÈÕÎó²î¹¥»÷Output MessengerÓû§
5ÔÂ12ÈÕ£¬Î¢ÈíÍþвÇ鱨ÆÊÎöʦ¿ËÈÕ·¢Ã÷£¬Ò»¸öÓÉÍÁ¶úÆäÖ§³ÖµÄÍøÂçÌØ¹¤×éÖ¯Marbled Dust£¨ÓÖÃûSea Turtle¡¢SILICONºÍUNC1326£©Ê¹ÓÃÁãÈÕÎó²î¹¥»÷ÓëÒÁÀ¿Ë¿â¶ûµÂ¾ü¶ÓÓйصÄOutput MessengerÓû§¡£¸Ã×éÖ¯·¢Ã÷LANÐÂÎÅת´ïÓ¦ÓóÌÐòOutput Messenger±£´æÄ¿Â¼±éÀúÎó²î£¨CVE-2025-27920£©£¬´ËÎó²î¿Éʹ¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß»á¼ûÄ¿µÄĿ¼ÍâµÄÃô¸ÐÎļþ»òÔÚ·þÎñÆ÷Æô¶¯Îļþ¼ÐÖа²ÅŶñÒâ¸ºÔØ¡£Ó¦ÓóÌÐò¿ª·¢ÉÌSrimaxÔÚ12ÔÂÐû²¼µÄÇ徲ͨ¸æÖÐÖ¸³ö£¬¹¥»÷Õß¿ÉÄܽè´Ë»á¼ûÉèÖÃÎļþ¡¢Ãô¸ÐÓû§Êý¾ÝÉõÖÁÔ´´úÂ룬½ø¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеȽøÒ»²½¹¥»÷¡£¸ÃÎó²îÒÑÔÚOutput Messenger V2.0.63°æ±¾ÖлñµÃÐÞ²¹¡£È»¶ø£¬Marbled DustÔÚ»ñµÃOutput Messenger Server ManagerÓ¦ÓóÌÐò»á¼ûȨÏÞºó£¬ÈÔÕë¶Ôδ¸üÐÂϵͳµÄÓû§Ìᳫ¹¥»÷²¢Ñ¬È¾¶ñÒâÈí¼þ¡£¹¥ÏÝ·þÎñÆ÷ºó£¬¸Ã×éÖ¯¿ÉÇÔÈ¡Ãô¸ÐÊý¾Ý¡¢»á¼ûÓû§Í¨Ñ¶¡¢Ã°³äÓû§¡¢»á¼ûÄÚ²¿ÏµÍ³²¢µ¼ÖÂÔËÓªÖÐÖ¹¡£Î¢ÈíÆÀ¹ÀÒÔΪ£¬Marbled Dust¿ÉÄÜʹÓÃDNSÐ®ÖÆ»òÓòÃûÇÀ×¢ÊÖÒÕ×èµ²¡¢¼Í¼ºÍÖØ¸´Ê¹ÓÃÆ¾Ö¤¡£¹¥»÷ÕßÔÚÊܺ¦Õß×°±¸Éϰ²ÅźóÃųÌÐò£¬¼ì²éÓë¹¥»÷Õß¿ØÖƵÄÏÂÁîºÍ¿ØÖÆÓòµÄÅþÁ¬ÐÔ£¬²¢ÏòÍþвÐÐΪÕßÌṩÐÅÏ¢ÒÔʶ±ðÊܺ¦Õß¡£
https://www.bleepingcomputer.com/news/security/output-messenger-flaw-exploited-as-zero-day-in-espionage-attacks/
3. ¶ñÒânpm°üÕë¶ÔmacOS°æCursor±à¼Æ÷·¢¶¯¹©Ó¦Á´¹¥»÷
5ÔÂ9ÈÕ£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±¿ËÈÕ·¢Ã÷Èý¸ö¶ñÒânpmÈí¼þ°üÕë¶ÔÆ»¹ûmacOS°æÈ˹¤ÖÇÄÜÇý¶¯µÄÔ´´úÂë±à¼Æ÷Cursor·¢¶¯¹¥»÷¡£ÕâЩÈí¼þ°üαװ³É¿ª·¢Õß¹¤¾ß£¬Í¨¹ýÇÔÈ¡Óû§Æ¾Ö¤¡¢´Ó¹¥»÷Õß¿ØÖƵķþÎñÆ÷»ñÈ¡¼ÓÃÜÔØºÉ²¢ÁýÕÖCursorµÄÕýµ±Îļþ£¬½ø¶ø½ûÓÃ×Ô¶¯¸üлúÖÆÒÔά³Ö³¤ÆÚÐÔפÁô¡£ÊÜÓ°ÏìµÄÈí¼þ°ü°üÀ¨sw-cur¡¢sw-cur1ºÍaiide-cur£¬×èÖ¹5ÔÂ9ÈÕÈÔ¿ÉÔÚnpm¿ÍÕ»ÏÂÔØ¡£×°Öúó£¬ÕâЩÈí¼þ°ü»áÇÔÈ¡Óû§ÊäÈëµÄCursorƾ֤£¬²¢´ÓÔ¶³Ì·þÎñÆ÷»ñÈ¡µÚ¶þ½×¶ÎÔØºÉ£¬ÓöñÒâ´úÂëÌæ»»Õýµ±Îļþ£¬ÉõÖÁ½ûÓÃCursorµÄ×Ô¶¯¸üй¦Ð§£¬ÖØÆôÓ¦ÓÃʹ¶ñÒâ´úÂëÉúЧ£¬Ê¹¹¥»÷ÕßÄÜÔÚÆ½Ì¨ÉÏÖ´ÐÐí§Òâ´úÂë¡£Socket¹«Ë¾Ñо¿Ô±Ö¸³ö£¬Õâ·´Ó¦³ö¹¥»÷ÕßÕýͨ¹ý¶ñÒânpm°ü¸Ä¶¯¿ª·¢ÕßϵͳÏÖÓÐÕýµ±Èí¼þµÄÐÂÇ÷ÊÆ£¬×ÝȻɾ³ý¶ñÒâÈí¼þ°ü£¬ÈÔÐèÖØÐÂ×°Öñ»¸Ä¶¯µÄÈí¼þ²Å»ª³¹µ×ɨ³ýÍþв¡£±ðµÄ£¬¹¥»÷Õß»¹Ê¹Óÿª·¢Õß¶ÔAI¹¤¾ßµÄÐËȤʵÑé´¹ÂÚ£¬ÒÔ¡°×î×ÔÖÆCursor API¡±ÎªÓÕ¶üÎüÒýÓû§×°ÖúóÃÅ¡£Í¬Ê±£¬Çå¾²Ñо¿Ô±»¹Åû¶ÁËÁíÍâÁ½¸ö¶ñÒânpm°ü£¬ËüÃÇͨ¹ý¡°°ü×°Æ÷ģʽ¡±Èö²¥Ïàͬ¶ñÒâ´úÂ룬ÇÔÈ¡¼ÓÃÜÇ®±Òƽ̨Êý¾Ý¡£ÁíÍ⣬Çå¾²¹«Ë¾AikidoÒ²·¢Ã÷Õýµ±npm°ü¡°rand-user-agent¡±Ô⹩ӦÁ´¹¥»÷£¬¶ñÒâ°æ±¾Ö²ÈëÔ¶³Ì¿ØÖÆÄ¾Âí£¬Í¨¹ýÓëÍⲿ·þÎñÆ÷ͨѶʵÏÖĿ¼Çл»¡¢ÎļþÉÏ´«ºÍÏÂÁîÖ´ÐС£
https://thehackernews.com/2025/05/malicious-npm-packages-infect-3200.html
4. ASUS DriverHubÆØÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬½¨ÒéÓû§¾¡¿ì¸üÐÂ
5ÔÂ12ÈÕ£¬ASUS DriverHubÇý¶¯³ÌÐòÖÎÀíÊÊÓóÌÐò±»ÆØ±£´æÑÏÖØÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¸ÃÎó²îÓÉÐÂÎ÷À¼×ÔÁ¦ÍøÂçÇå¾²Ñо¿Ô±±£ÂÞ·¢Ã÷¡£DriverHub×÷Ϊ»ªË¶¹Ù·½Çý¶¯³ÌÐòÖÎÀí¹¤¾ß£¬»áÔÚijЩ»ªË¶Ö÷°åÊ×´ÎϵͳÆô¶¯Ê±×Ô¶¯×°Ö㬲¢ÔÚºǫ́ͨ¹ý¶Ë¿Ú53000ÔËÐУ¬Ò»Á¬¼ì²éÇý¶¯³ÌÐò¸üС£È»¶ø£¬¸ÃÈí¼þ¶Ô·¢Ë͵½ºǫ́·þÎñµÄÏÂÁîÑé֤ȱ·¦£¬¹¥»÷Õß¿ÉʹÓÃCVE-2025-3462ºÍCVE-2025-3463Îó²î½¨ÉèÎó²îʹÓÃÁ´£¬ÈƹýÔ´Õ¾ÑéÖ¤£¬ÔÚÄ¿µÄ×°±¸ÉÏ´¥·¢Ô¶³Ì´úÂëÖ´ÐС£Îó²îµÄÒªº¦ÔÚÓÚÈí¼þ¶ÔOrigin HeaderµÄ¼ì²éÖ´Ðв»Á¦£¬ÈκΰüÀ¨¡°driverhub.asus.com¡±×Ö·û´®µÄÍøÕ¾ÇëÇ󶼻ᱻ½ÓÊÜ£¬×ÝÈ»Ó뻪˶¹Ù·½ÃÅ»§²»ÍêȫƥÅä¡£±ðµÄ£¬UpdateApp¶ËµãÔÊÐí´Ó¡°.asus.com¡±URLÏÂÔØ²¢ÔËÐÐ.exeÎļþ£¬ÎÞÐèÓû§È·ÈÏ£¬½øÒ»²½¼Ó¾çÁËΣº¦¡£¹¥»÷Õß¿ÉÓÕÆÓû§»á¼û¶ñÒâÍøÕ¾£¬Í¨¹ýÓÕÆOrigin HeaderÈÆ¹ýÑéÖ¤£¬ÏòÍâµØ·þÎñ·¢ËͶñÒâÇëÇó£¬ÏÂÔØ²¢Ö´ÐжñÒâÎļþ¡£»ªË¶ÓÚ2025Äê4ÔÂ8ÈÕÊÕµ½±¨¸æ£¬4ÔÂ18ÈÕʵÑéÐÞ¸´£¬µ«CVEÐÎòÖб£´æÎóµ¼ÐÔÉùÃ÷£¬³ÆÎÊÌâ½öÏÞÓÚÖ÷°å£¬¶øÏÖʵÉÏ»áÓ°Ïì×°ÖÃÁËDriverHubµÄÌõ¼Ç±¾µçÄÔºĮ́ʽµçÄÔ¡£»ªË¶Ç徲ͨ¸æ½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£Èô¶Ôºǫ́·þÎñ×Ô¶¯»ñȡDZÔÚΣÏÕÎļþ²»Âú£¬¿É´ÓBIOSÉèÖÃÖнûÓÃDriverHub¡£
https://www.bleepingcomputer.com/news/security/asus-driverhub-flaw-let-malicious-sites-run-commands-with-admin-rights/
5. ÀÕË÷ÍÅ»ï÷è÷ë´Ó¶íº¥¶íÖݾ¯³¤°ì¹«ÊÒÇÔÈ¡°ÙGBÎļþ
5ÔÂ9ÈÕ£¬Ò»¸ö¶íÂÞ˹ÀÕË÷Èí¼þÍŶÓ÷è÷ëÐû³Æ´Ó¶íº¥¶íÖݺºÃܶû¶ÙÏØ¾¯³¤°ì¹«ÊÒÇÔÈ¡Á˽ü100GBÎļþ£¬ÆäÖоݳưüÀ¨¹«¹²Çå¾²ÐÅÏ¢¡£÷è÷ëÊÇÎÛÃûÕÑÖøµÄÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©×éÖ¯£¬ÓÚ5ÔÂ4ÈÕÔÚÆäµØÏÂÍøÕ¾ÉÏÐû²¼Ð¹ÃÜ֪ͨ£¬Éù³Æ³ÖÓдӾ¯³¤ÏµÍ³ÇÔÈ¡µÄ128,294¸öÎļþ¡£¸ÃÍÅ»ïÒÔʵÑéË«ÖØÀÕË÷¶øÖøÃû£¬ÒªÇóÊܺ¦ÕßÖ§¸¶ÓöÈÒÔ½âËøÏµÍ³ºÍ±ÜÃâÊý¾Ýй¶£¬²»È»»á½«ÎļþÉÏ´«µ½ÍøÉÏ¡£÷è÷ëÉù³ÆÇÔÈ¡µÄÎļþ°üÀ¨7ÔÂ4ÈÕ¹«¹²Çå¾²ÍýÏëµÄÇ鱨£¬¿ÉÄÜÉæ¼°ÓÎÐÐõè¾¶¡¢ÈËȺ¿ØÖÆÒÔ¼°½ÚÈÕʱ´ú¾¯Ô±Öµ°à°²ÅÅ£¬»¹Éù³ÆÕÆÎÕÁ˾¯³¤°ì¹«ÊÒÕÐÆ¸ÆôʵÄÄÚ²¿ÐÅÏ¢¡£ÖµµÃ×¢ÖØµÄÊÇ£¬¸ÃÏØ°ì¹«ÊÒÏÖÔÚÕýÔÚ×·µ¿Ò»Î»ºã¾ÃÈÎÖ°µÄ¸±¾¯³¤ÀÀºàµÂÉ£¬ËûÓÚ5ÔÂ2ÈÕÔÚÒ»³¡³µ»öÖб»¾ÓÐÄɱ¾¡£÷è÷ë×Ô2022ÄêÊ״ηºÆðÔÚÀÕË÷Èí¼þȦÖÐÒÔÀ´£¬¾ÍÒòÏ®»÷Ò½Ôº¶ø¹ãΪÈËÖª£¬Ôø¶ÔÓ¢¹ú¹úÃñÒ½ÁÆ·þÎñϵͳ£¨NHS£©ÏàÖúͬ°éSynnovisʵÑéÊÒ·¢¶¯ºÚ¿Í¹¥»÷£¬µ¼ÖÂÂ×¶ØÎå¼Ò¹«Á¢Ò½ÔºÒªº¦·þÎṉ̃»¾¡£÷è÷ëÊÇ×î»îÔ¾µÄÀÕË÷Èí¼þÍÅ»ïÖ®Ò»£¬ÒÑÓÐ403ÃûÊܺ¦Õß¡£
https://cybernews.com/cybercrime/hamilton-county-sheriff-ransomware-attack/
6. FreeDrain´¹ÂÚȦÌ×µ¼ÖÈÎÃüÜÇ®±Òϲ»¶ÕßÇ®°ü±»Çå¿Õ
5ÔÂ12ÈÕ£¬Ò»ÏîÃûΪFreeDrainµÄÖØ´ó´¹ÂÚÍýÏë×Ô2022ÄêÆðÒ»Á¬Õë¶ÔWeb3ÏîÄ¿£¬´ó¹æÄ£Çå¿Õ¼ÓÃÜÇ®±ÒÇ®°ü¡£¸ÃÍýÏë×î³õÓÚ2024Äê4Ô±»Validin¼ì²âΪ¼òÆÓµÄ¼ÓÃÜ´¹ÂÚÍøÕ¾ÍøÂ磬µ«ËæºóÕ¹ÏÖ³ö¸ü¸ßÖØ´óÐԺ͸ü´ó¹æÄ££¬´Ùʹ»¥ÁªÍøÇ鱨ƽ̨ÌṩÉÌÓëSentinelOneµÄÑо¿ÍŶÓSentinelLabsÏàÖúÊӲ졣FreeDrainÍýÏëδÒÀÀµ´¹ÂÚÓʼþ¡¢¶ÌÐÅ´¹Âڵȳ£¼ûÊֶΣ¬¶øÊÇͨ¹ýSEOʹÓá¢Ãâ·Ñ²ã¼¶ÍøÂç·þÎñºÍ·Ö²ãÖØ¶¨ÏòÊÖÒÕÃé×¼¼ÓÃÜÇ®±ÒÇ®°ü¡£Êܺ¦ÕßÔÚµã»÷¸ßÅÅÃûËÑË÷ÒýÇæÐ§¹ûºó£¬ÊÔͼ¼ì²éÇ®°üÓà¶îʱ£¬»áÎÞÒâ¼ä½«Ç®°üÖú¼Ç´ÊÌá½»ÖÁ´¹ÂÚÍøÕ¾¡£Öú¼Ç´ÊÊǻָ´¼ÓÃÜÇ®±ÒÇ®°ü²¢»á¼û×ʽðµÄÒªº¦£¬±»µÁ×ʲúѸËÙͨ¹ý¼ÓÃÜÇ®±Ò»ì±ÒÆ÷×ªÒÆ£¬Ê¹µÃ×·×ÙºÍ×·»ØÏÕЩ²»¿ÉÄÜ¡£Ñо¿Ö°Ô±·¢Ã÷£¬FreeDrainÐж¯Í¨¹ýÔÆ»ù´¡ÉèÊ©Íйܴó×ÚÓÕ¶üÒ³Ãæ£¬Ä£ÄâÕýµ±¼ÓÃÜÇ®±ÒÇ®°ü½çÃæ£¬²¢×ÛºÏÔËÓöàÖÖÊÖÒÕÓÕʹÊܺ¦ÕßÎóÒÔÎªÍøÕ¾Õýµ±¡£±ðµÄ£¬ÔËÓªÕß»¹Í¨¹ýÔÚά»¤²»ÉƵÄÍøÕ¾ÉϾÙÐдó¹æÄ£Ì¸ÂÛ¹àË®£¬ÌáÉýÓÕ¶üÒ³ÃæµÄ¿É¼û¶È¡£ÊÓ²ìÏÔʾ£¬FreeDrainʹÓÃÔÝʱ»ù´¡ÉèÊ©ºÍ¹²ÏíÃâ·Ñ·þÎñ£¬ËÝÔ´Ðж¯¾ßÓÐÌôÕ½ÐÔ£¬µ«Ñо¿Ö°Ô±Í¨Ì«¹ýÎö¿ÍÕ»ÔªÊý¾Ý¡¢ÐÐΪÐźźÍʱ¼äºÛ¼££¬ÀֳɻñÈ¡ÁËÔËÓªÕßÌØÕ÷µÄÖ÷ÒªÏßË÷£¬Åú×¢¸ÃÐж¯¼«¿ÉÄÜÓÉÓ¡¶È¾³ÄÚÖ°Ô±ÔÚ±ê×¼ÊÂÇéÈÕʱ¶ÎʵÑé¡£
https://www.infosecurity-magazine.com/news/freedrain-phishing-scam-crypto/


¾©¹«Íø°²±¸11010802024551ºÅ