·¸·¨·Ö×Óð³äÃÀ¹ú¸ß¼¶¹ÙÔ±¾ÙÐÐÐÅÏ¢Õ©Æ­

Ðû²¼Ê±¼ä 2025-12-25

1. ·¸·¨·Ö×Óð³äÃÀ¹ú¸ß¼¶¹ÙÔ±¾ÙÐÐÐÅÏ¢Õ©Æ­


12ÔÂ21ÈÕ£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö¿ËÈÕÐû²¼ÖÒÑÔ£¬ÍøÂç·¸·¨·Ö×Ó×Ô2023ÄêÆðÒ»Á¬Ã°³äÖÝÕþ¸®¸ß¼¶¹ÙÔ±¡¢°×¹¬¹ÙÔ±¡¢ÄÚ¸ó³ÉÔ±¼°¹ú¾Û»áÔ±£¬Ê¹ÓöÌÐÅÓëÈ˹¤ÖÇÄÜÌìÉúµÄÓïÒôÐÅÏ¢£¬Õë¶Ô¹ÙÔ±¼ÒÈ˼°Ë½ÈËÊìÈËʵÑ龫׼թƭ¡£´ËÀ๥»÷ͨ¹ý¡°¶ÌÐÅ´¹ÂÚ+ÓïÒô¿Ë¡¡±Ë«ÖØÊÖ¶ÎÕö¿ª£º·¸·¨·Ö×ÓÊ×ÏÈ·¢ËÍ¿´ËÆÀ´×ÔȨÍþ»ú¹¹µÄڲƭ¶ÌÐÅ£¬Ëæºó²¦´òAIÌìÉúµÄÓïÒôµç»°»òÁôÏÂÓïÒôÁôÑÔ£¬ÒÔÌÖÂÛÊìϤ»°ÌâΪÓÕ¶ü£¬Ñ¸ËÙÒªÇóÊܺ¦Õß×ªÒÆÖÁSignal¡¢Telegram¡¢WhatsAppµÈ¼ÓÃÜÒÆ¶¯Ó¦ÓþÙÐнøÒ»²½Ïàͬ¡£ÔÚ¼ÓÃÜÓ¦ÓÃÖУ¬¹¥»÷Õß»áͨ¹ý̸ÂÛÊ±ÊÆ¡¢Ë«±ß¹ØÏµ£¬»òÐé¹¹¡°¶­Ê»áÌáÃû¡±¡°°²ÅÅÓë×ÜͳÅöÃæ¡±µÈ³¡¾°½¨ÉèÐÅÍУ¬½ø¶øË÷ÒªÑéÖ¤ÂëÒÔͬ²½ÁªÏµÈËÁÐ±í¡¢»ñÈ¡»¤ÕÕµÈÃô¸ÐÎļþ¸±±¾¡¢ÒªÇóÏòÍâÑó½ðÈÚ»ú¹¹»ã¿î£¬»òÓÕµ¼ÏÈÈÝͬ»ï¡£GetReal SecurityÍþвÑо¿Ö÷¹ÜÌÀÄ·¡¤¿ËÂÞ˹ָ³ö£¬ÍþвÐÐΪÕßÕýʹÓÃÉî¶ÈαÔìÊÖÒÕʵÑéÉç»á¹¤³Ì¹¥»÷£¬½öÐè30ÃëÓïÒôÑù±¾¼´¿Éͨ¹ýAIÓïÒô¿Ë¡¸ß¶È±ÆÕæÄ£ÄâËûÈË£¬¶ø¹«Ö°Ö°Ô±ºÍ¸ß¹ÜµÄÓïÒôÑù±¾¼«Ò×ͨ¹ý¹ûÕæÇþµÀ»ñÈ¡¡£


https://cybernews.com/news/criminals-impersonate-senior-us-officials-in-messaging-scams/


2. ƴд¹ýʧÓòÃûÒý·¢Cosmali Loader¶ñÒâÈí¼þѬȾ


12ÔÂ24ÈÕ£¬¿ËÈÕ£¬ÍøÂçÇå¾²ÁìÓòÆØ³öÒ»ÒòÓÉÓòÃûƴд¹ýʧµ¼ÖµĶñÒâÈí¼þѬȾÊÂÎñ¡£¹¥»÷ÕßʹÓÃÓû§ÊäÈëÊèºö£¬ÇÀ×¢Óë΢Èí¼¤»î¾ç±¾£¨MAS£©¹Ù·½ÓòÃû¸ß¶ÈÏàËÆµÄÓòÃû¡°get.activate[.]win¡±£¬½ö±È¹Ù·½ÓòÃû¡°get.activated.win¡±ÉÙÒ»¸ö×Öĸ¡°d¡±£¬ÓÕµ¼Óû§»á¼û²¢Ö´ÐжñÒâPowerShell¾ç±¾£¬×îÖÕµ¼ÖÂWindowsϵͳ±»¡°Cosmali Loader¡±¶ñÒâÈí¼þѬȾ¡£¾Ý±¨µÀ£¬¶àÃûMASÓû§ÒÑÔÚRedditƽ̨±¨¸æÏµÍ³·ºÆðCosmali LoaderѬȾµÄµ¯³öÖÒÑÔ¡£Çå¾²Ñо¿Ô±RussianPandaÆÊÎö·¢Ã÷£¬¸Ã¶ñÒâÈí¼þ¿ØÖÆÃæ°å±£´æÇå¾²Îó²î£¬¹¥»÷Õ߿ɽè´ËÔ¶³Ì»á¼ûÊܺ¦ÕßÅÌËã»ú£¬²¢°²ÅżÓÃÜÇ®±ÒÍڿ󹤾߼°XWormÔ¶³Ì»á¼ûľÂí£¨RAT£©¡£GDATA¶ñÒâÈí¼þÆÊÎöʦKarsten Hahn´ËǰҲ·¢Ã÷¹ýÀàËÆµ¯³ö֪ͨ£¬½øÒ»²½Ö¤Êµ´Ë´ÎÊÂÎñÓ뿪ԴCosmali Loader¶ñÒâÈí¼þ±£´æ¹ØÁª¡£MAS×÷Ϊ¿ªÔ´PowerShell¾ç±¾ÜöÝÍ£¬Í¨¹ýHWID¼¤»î¡¢KMSÄ£ÄâµÈÊÖÒÕʵÏÖWindows¼°OfficeµÄ×Ô¶¯¼¤»î£¬µ«Î¢ÈíÃ÷È·½«ÆäÊÓΪµÁ°æ¹¤¾ß£¬ÒòÆä½ÓÄÉδÊÚȨÊÖ¶ÎÈÆ¹ýÔÊÐíϵͳ¡£ÏîĿά»¤ÕßÒÑÏòÓû§·¢³öÖÒÑÔ£¬Ç¿µ÷Ö´ÐÐÏÂÁîǰÐè×ÐϸºË¶ÔÓòÃûƴд£¬×èÖ¹ÒòÊäÈë¹ýʧ»á¼û¶ñÒâÓòÃû¡£


https://www.bleepingcomputer.com/news/security/fake-mas-windows-activation-domain-used-to-spread-powershell-malware/


3. FBI²é·âweb3adspanels[.]orgÓòÃû


12ÔÂ24ÈÕ£¬¿ËÈÕ£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö£¨FBI£©²é·âÁËÓòÃû¡°web3adspanels[.]org¡±¼°ÆäÊý¾Ý¿â£¬¸ÃÓòÃû±»·¸·¨ÍÅ»ïÓÃÓÚ´æ´¢ºÍ¸Ä¶¯´ÓÃÀ¹úÊܺ¦Õß´¦ÇÔÈ¡µÄÒøÐеǼƾ֤£¬½ø¶øÊµÑé´ó¹æÄ£ÒøÐÐÕË»§µÁÓÃÕ©Æ­¡£¾Ý˾·¨²¿Åû¶£¬¸Ã·¸·¨ÍÅ»ïͨ¹ýÔڹȸ衢±ØÓ¦µÈËÑË÷ÒýÇæÍ¶·ÅÐéα¹ã¸æ£¬Ä£ÄâÕæÊµÒøÐÐ¹ã¸æÓÕµ¼Óû§µã»÷¡£Êܺ¦Õßµã»÷ºó»á±»Öض¨ÏòÖÁÓÉ·¸·¨·Ö×Ó¿ØÖƵÄÚ²Æ­ÍøÕ¾£¬µ±Óû§ÊäÈëÒøÐеǼƾ֤ʱ£¬ÍøÕ¾ÉϵĶñÒâÈí¼þ»áÁ¬Ã¦ÇÔÈ¡ÕâЩÐÅÏ¢¡£·¸·¨·Ö×ÓËæºóʹÓÃÇÔÈ¡µÄƾ֤µÇÂ¼ÕæÊµÒøÐÐÍøÕ¾£¬ÍµÈ¡ÕË»§×ʽð¡£ÊÓ²ìÏÔʾ£¬¸ÃÓòÃû×÷Ϊºó¶ËÍøÂçÃæ°å£¬ÍйÜÁËÊýǧ¸ö±»µÁµÄÒøÐеǼƾ֤£¬²¢Ò»Á¬ÔËÓªÖÁ2025Äê11Ô¡£°®É³ÄáÑÇÕþ¸®ÒÑÉúÑIJ¢ÍøÂçÁËÍйܴ¹ÂÚÒ³ÃæµÄ·þÎñÆ÷Êý¾Ý¼°±»µÁƾ֤£¬ÎªºóÐøÊÓ²ìÌṩҪº¦Ö¤¾Ý¡£FBIÈ·ÈÏ£¬ÖÁÉÙ19ÃûÃÀ¹úÊܺ¦ÕßÒò¸ÃȦÌ×ËðʧԼ1460ÍòÃÀÔª£¬²¢ÃæÁÙ2800ÍòÃÀÔªµÄδËìËðʧ¡£


https://securityaffairs.com/186094/cyber-crime/fbi-seized-web3adspanels-org-hosting-stolen-logins.html


4. MongoDB½ôÆÈͨ¸æ¸ßΣRCEÎó²îÐèÁ¬Ã¦ÐÞ¸´


12ÔÂ24ÈÕ£¬MongoDB¿ËÈÕÐû²¼½ôÆÈÇ徲ͨ¸æ£¬ÖÒÑÔITÖÎÀíÔ±±ØÐèÁ¬Ã¦ÐÞ¸´±àºÅΪCVE-2025-14847µÄ¸ßΣÎó²î¡£¸ÃÎó²îÓ°ÏìMongoDB 8.2.0ÖÁ8.2.3¡¢8.0.0ÖÁ8.0.16¡¢7.0.0ÖÁ7.0.26¡¢6.0.0ÖÁ6.0.26¡¢5.0.0ÖÁ5.0.31¡¢4.4.0ÖÁ4.4.29¼°ËùÓÐv4.2¡¢v4.0¡¢v3.6°æ±¾£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓôËÎó²îÌᳫµÍÖØÆ¯ºóÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷£¬ÎÞÐèÓû§½»»¥¼´¿É¿ØÖÆÄ¿µÄ·þÎñÆ÷¡£Îó²îȪԴÔÚÓÚMongoDB·þÎñÆ÷¶Ô³¤¶È²ÎÊýµÄ·×ÆçÖ´¦Öóͷ£»úÖÆ£¬¹¥»÷Õß¿Éͨ¹ý¸Ä¶¯zlibѹËõʵÏÖÖеÄÊý¾Ý°ü£¬´¥·¢Î´³õʼ»¯µÄ¶ÑÄÚ´æ»á¼û£¬½ø¶øÖ´ÐÐí§Òâ´úÂë¡£MongoDBÇå¾²ÍŶÓÇ¿µ÷£¬¸ÃÎó²îÒѾ߱¸±»´ó¹æÄ£Ê¹ÓõÄÌõ¼þ£¬½¨ÒéÖÎÀíÔ±Á¬Ã¦Éý¼¶ÖÁÒÑÐÞ¸´°æ±¾£º8.2.3¡¢8.0.17¡¢7.0.28¡¢6.0.27¡¢5.0.32»ò4.4.30¡£ÈôÎÞ·¨Á¬Ã¦Éý¼¶£¬ÐèÔÚÆô¶¯mongod/mongosʱͨ¹ýnetworkMessageCompressors»ònet.compression.compressors²ÎÊýÏÔʽ½ûÓÃzlibѹËõ¹¦Ð§¡£


https://www.bleepingcomputer.com/news/security/mongodb-warns-admins-to-patch-severe-rce-flaw-immediately/


5. MarquisÔâºÚ¿Í¹¥»÷Ö¶à¼ÒÒøÐпͻ§Êý¾Ýй¶


12ÔÂ24ÈÕ£¬¿ËÈÕ£¬Á½¼ÒÃÀ¹úÒøÐÐVeraBankºÍArtisans' BankÏà¼ÌÅû¶ÒòµÚÈý·½¹©Ó¦ÉÌMarquis Software SolutionsÔâÊܺڿ͹¥»÷£¬µ¼Ö´ó×Ú¿Í»§ÐÅϢй¶¡£×ܲ¿Î»Óڵ¿ËÈøË¹ÖݵÄVeraBank͸¶£¬´Ë´ÎÊÂÎñÓ°Ïì37,318Ãû¿Í»§£¬Ð¹Â¶ÐÅÏ¢°üÀ¨ÐÕÃû¼°ÆäËûδÃ÷ȷ˵Ã÷µÄСÎÒ˽¼ÒÐÅÏ¢£¬Ïêϸй¶ÄÚÈÝÒò¿Í»§¶øÒì¡£ÌØÀ­»ªÖݵÄArtisans' BankÔòÌåÏÖ£¬32,344Ãû¿Í»§µÄÐÕÃûºÍÉç»á°ü¹ÜºÅÂë¿ÉÄÜÔâδ¾­ÊÚȨ»á¼û¡£Á½¼ÒÒøÐоùÇ¿µ÷£¬¹¥»÷½öÏÞÓÚMarquisϵͳ£¬Æä×ÔÉíϵͳδÊÜÓ°Ïì¡£Marquis·½ÃæÌåÏÖ£¬ÒѾÍ8ÔÂ14ÈÕ±¬·¢µÄÊý¾Ýй¶ÊÂÎñÕö¿ªÄÚ²¿ÊӲ첢ִ֪ͨ·¨²¿·Ö¡£È»¶ø£¬Artisans' BankÖ±ÖÁ10ÔÂÏÂÑ®²Å»ñϤ´ËÊ£¬½üÆÚ²ÅÒâʶµ½¿Í»§ÐÅÏ¢¿ÉÄÜй¶¡£11Ô£¬Å²Íþ´¢±¸ÒøÐУ¨NSB£©ÔøÒòMarquisÔâÊÜÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂ51,000Ãû¿Í»§ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Éç»á°ü¹ÜºÅÂ롢˰ÎñʶÓÖÃûÂë¼°²ÆÎñÕË»§ÐÅÏ¢µÈÃô¸ÐÊý¾Ýй¶¡£


https://cybernews.com/news/bank-marquis-software-vendor-attack/


6. Evasive PandaÕë¶Ô¶à¹úʵÑé¾«×¼ÉøÍ¸


12ÔÂ25ÈÕ£¬¿¨°Í˹»ùʵÑéÊÒ¿ËÈÕÐû²¼±¨¸æ£¬½ÒÆÆÎÛÃûÕÑÖøµÄÍøÂçÌØ¹¤×éÖ¯Evasive PandaÔÚ2022Äê11ÔÂÖÁ2024Äê11ÔÂʱ´ú£¬Õë¶ÔÖйú¡¢Ó¡¶È¼°ÍÁ¶úÆäÌᳫÐÂÒ»ÂÖÖØ´ó¹¥»÷¡£¸Ã×éÖ¯×Ô2012ÄêÆð»îÔ¾£¬Í¨¹ýDNSÐ®ÖÆ¡¢ÖÐÐÄÈ˹¥»÷£¨AitM£©¼°Î±×°Èí¼þ¸üеÈÊֶΣ¬Èö²¥±ê¼ÇÐÔºóÃųÌÐòMgBot£¬ÊµÏÖºã¾ÃϵͳפÁôÓëÊý¾ÝÇÔÈ¡¡£¹¥»÷Á´ÌõʼÓÚÈ«ÐÄÉè¼ÆµÄ¡°Õýµ±Î±×°¡±£º¹¥»÷Õßð³äËѺüÊÓÆµ¡¢°®ÆæÒÕÊÓÆµ¡¢IObit Smart Defrag¼°ÌÚѶQQµÈÈÈÃÅÈí¼þµÄ¸üгÌÐò£¬ÔÚÕýµ±×°ÖÃÎļþ¼ÐÖÐÖ²Èë¶ñÒâ´úÂ룬ÓÉÊÜÐÅÍÐϵͳ·þÎñÖ´ÐС£¸üÒþ²ØµÄÊÇ£¬×é֯ʹÓÃAitMÊÖÒÕÐ®ÖÆÍøÂçÁ÷Á¿£¬Í¨¹ý¸Ä¶¯DNSÏìÓ¦£¬½«Óû§¶Ôdictionary.comµÄ»á¼ûÖØ¶¨ÏòÖÁ¹¥»÷Õß¿ØÖƵķþÎñÆ÷£¬ÒÔαװ³ÉPNGÎļþµÄ¼ÓÃÜshellcodeÐÎʽ¼ÓÔØµÚ¶þ½×¶ÎÓÐÓÃÔØºÉ¡£ÕâÖÖ»ùÓÚµØÀíλÖúÍISPµÄ¶¨ÏòͶ·ÅÕ½ÂÔ£¬Ê¹¹¥»÷¼«¾ßÕë¶ÔÐÔÇÒÄÑÒÔÔÚʵÑéÊÒ¸´ÏÖ¡£Ð¿ª·¢µÄ¼ÓÔØÆ÷αװ³ÉWindows¿âÎļþ£¬Í¨¹ýDLL²à¼ÓÔØÊÖÒÕ½«MgBot×¢Èësvchost.exeµÈϵͳÀú³Ì£¬ÉõÖÁʹÓÃÊ®ÄêǰµÄÊðÃû¿ÉÖ´ÐÐÎļþÌӱܼì²â¡£


https://securityonline.info/evasive-panda-apt-hijacks-dictionary-com-and-app-updates-in-two-year-spree/