Vo1d½©Ê¬ÍøÂçбäÖÖ£º´ó¹æÄ£Ï°È¾Android TVÉ豸²¢ÓÃÓÚ·¸·¨»î¶¯
°ä²¼¹¦·ò 2025-02-281. Vo1d½©Ê¬ÍøÂçбäÖÖ£º´ó¹æÄ£Ï°È¾Android TVÉ豸²¢ÓÃÓÚ·¸·¨»î¶¯
2ÔÂ27ÈÕ£¬Vo1d¶ñÒâÈí¼þ½©Ê¬ÍøÂçµÄбäÖÖÒÑϰȾȫÇò226¸ö¹ú¶È/µØÓòµÄ1,590,299̨Android TVÉ豸£¬²¢½«ÆäÕÐļΪÄäÃû´úÀí·þÎñÆ÷ÍøÂçµÄÒ»²¿ÃÅ¡£Xlab×ÔÈ¥Äê11Ô¸ú×ٴ˻£¬·¢Ïָý©Ê¬ÍøÂçÔÚ2025Äê1ÔÂ14ÈÕ´ïµ½¶¥·å£¬Ä¿Ç°Õ¼ÓÐ80Íò»îÔ¾»úеÈË¡£Ð°汾µÄVo1d½©Ê¬ÍøÂçδÊÜÖ®Ç°ÆØ¹âÓ°Ï죬³ÖÐø´ó¹æÄ£ÔË×÷£¬²¢¾ß±¸ÏȽøµÄ¼ÓÃܼ¼Êõ¡¢Óе¯ÐÔµÄDGA»ù´¡ÉèÊ©¼°ÒþÉíÄÜÁ¦¡£Æä¹æÄ£Öش󣬳¬¹ýBigpanziµÈ½©Ê¬ÍøÂç£¬Ï°È¾ÖØÒª¼¯ÖÐÔÚ°ÍÎ÷¡¢ÄÏ·Ç¡¢Ó¡¶ÈÄáÎ÷Ñǵȵء£×êÑÐÈËÔ±·¢ÏÖ£¬½©Ê¬ÍøÂçϰȾÊýÁ¿´æÔÚÏÔÖø¼¤Ôö¾°Ï󣬴§Ä¦Óë¡°×âÁÞ-»Ø±¨¡±ÖÜÆÚÓйأ¬¼´Vo1d½«½©Ê¬ÍøÂç»ù´¡ÉèÊ©³ö×â¸øÆäËû×éÖ¯½øÐз¸·¨»î¶¯¡£´Ë±í£¬Vo1d»¹ÓµÓиæ°×Ú²ÆÖ°ÄÜ£¬Í¨¹ý·ÂÕÕ¸æ°×µã»÷»òÊÓÆµÅÔ¹ÛαÔìÓû§»¥¶¯£¬ÎªÚ²ÆÐÔ¸æ°×ÉÌ´´ÔìÊÕÈë¡£¼øÓÚϰȾÁ´Î´Öª£¬½¨ÒéAndroid TVÓû§²ÉÈ¡ÕûÌ尲ȫ²½Öè¼õÇáVo1dÍþв£¬Ô̺¬´Ó¿¿µÃס¹©¸øÉ̲ɰìÉ豸¡¢×°Öù̼þºÍ°²È«¸üС¢Ô¤·ÀÏÂÔØ·Ç¹Ù·½ÀûÓ÷¨Ê½¡¢½ûÓÃÔ¶³Ì½Ó¼ûÖ°Äܼ°ÀëÏß´æ´¢µÈ¡£
https://www.bleepingcomputer.com/news/security/vo1d-malware-botnet-grows-to-16-million-android-tvs-worldwide/
2. ºÚ¿Í¼ÙÒą̂Íå˰Îñ»ú¹Ø²¿Êð Winos 4.0 ¶ñÒâÈí¼þ
2ÔÂ27ÈÕ£¬FortiGuard Labs·¢ÏÖÁËÕë¶Ǫ̂ÍåÆóÒµµÄжñÒâÈí¼þ»î¶¯£¬¸Ã»î¶¯²¿ÊðÁËÒ»¸öÃûΪWinos 4.0µÄ¸ß¼¶¶ñÒâÈí¼þ¿ò¼Ü¡£¸Ã¶ñÒâÈí¼þͨ¹ý¾«ÐÄÉè¼ÆµÄ´¹µöµç×ÓÓʼþ½øÐд«²¼£¬ÕâЩÓʼþ¼ÙÒą̂Íå¹ú¶È˰Îñ¾Ö²¢Ðû³ÆÔ̺¬Ë°Îñ²é³¹«Ë¾Ãûµ¥£¬ÓÕʹÊÕ¼þÈËÏÂÔØÔ̺¬¶ñÒâDLLµÄ¸½¼þ¡£Winos 4.0ѡȡÁ˶à½×¶ÎϰȾ¹ý³Ì£¬Í¨¹ýһϵÁпÉÖ´ÐÐÎļþºÍDLLÎļþ·¢Õ¹¹¥»÷£¬×îÖÕÖ÷ÕÅÊÇÇÔÈ¡Ãô¸ÐÐÅÏ¢ÒÔÓÃÓÚ½«À´µÄ¶ñÒâ»î¶¯¡£¸Ã¶ñÒâÈí¼þÓµÓи߶ȵĽýÝÐÔºÍÊÊÓ¦ÐÔ£¬¿ÉÄÜÈÆ¹ýUAC¡¢ÍøÂçϵͳÐÅÏ¢¡¢½ûÓÃÆÁÄ»±£»¤·¨Ê½ºÍÊ¡µçÖ°ÄÜ£¬²¢×Ô¶¯¼à¶½ºÍ°Ñ³ÖÓû§»î¶¯£¬Èç²¶»ñÆÁÄ»½ØÍ¼¡¢¼Í¼»÷¼üºÍ¼ôÌù°åÄÚÈݵȡ£ÎªÁ˱£»¤×Ô¼ºÃâÊÜ´ËÀà¶ñÒâÈí¼þµÄÇÖº¦£¬Óû§±ØÒª¶Ôδ¾ÒªÇóµÄµç×ÓÓʼþά³Ö¸ß¶È¾¯Ì裬Ԥ·À´ò¿ªÑ¹ËõÎļþ¸½¼þ£¬²¢ÆôÓÃʵʱɨÃèÒÔ¼ì²âºÍ×èÖ¹Íþв¡£×¨¼Ò½¨Òéѡȡ¶àµµ´Î·ÀÓù²½Ö裬½áºÏÓû§½ÌÓýºÍÏȽøµÄÍþв¼ì²â¼¼ÊõÀ´×èÖ¹Éç»á¹¤³Ì¹¥»÷¡£
https://hackread.com/hackers-impersonate-taiwans-tax-authority-winos-4-0-malware/
3. 49,000¸ö½Ó¼ûÖÎÀíϵͳÅäÖÃÃýÎó¶³ö£¬Î£¼°È«ÇòÒþÖÔÓëÎïÀí°²È«
2ÔÂ27ÈÕ£¬ModatµÄ°²È«×êÑÐÈËÔ±·¢ÏÖÈ«ÇòÁìÓòÄÚ´æÔÚ49,000¸öÅäÖÃÃýÎóÇÒ¶³öÔÚ»¥ÁªÍøÉϵĽӼûÖÎÀíϵͳ£¨AMS£©£¬ÕâЩϵͳÕý±¾ÓÃÓÚͨ¹ýÉúÎï¼ø±ð¡¢Éí·ÝÖ¤»ò³µÅƽÚÔìÔ±¹¤¶Ô¹¹ÖþÎï¡¢ÉèÊ©ºÍ½ûÇøµÄ½Ó¼û¡£È»¶ø£¬ÓÉÓÚδÕýÈ·ÅäÖð²È«Éí·ÝÑéÖ¤£¬ÈκÎÈ˶¼Äܹ»ÇáËɽӼûÕâЩϵͳ£¬µ¼ÖÂÃô¸ÐµÄÔ±¹¤Êý¾Ý£¨ÈçÓ×ÎÒÉí·ÝÐÅÏ¢¡¢ÉúÎïÌØµãÊý¾Ý¡¢ÕÕÆ¬¡¢¹¤×÷¹¦·ò±íºÍ½Ó¼ûÈÕÖ¾£©±»Ð¹Â¶¡£Õâ²»½öΣ¼°ÁËÒþÖÔ°²È«£¬»¹¿ÉÄܶԹؼü»ù´¡ÉèÊ©£¨Èçµ±¾Ö¹¹Öþ¡¢·¢µçÕ¾ºÍË®´¦ÖÃÉèÊ©£©µÄÎïÀí°²È«×é³ÉÍþв¡£´Ë±í£¬Â¶³öµÄÐÅÏ¢»¹¿ÉÄܱ»ÓÃÓÚÕë¶ÔÓйØ×éÖ¯ÌáÒéÍøÂç´¹µöºÍÉç»á¹¤³Ì¹¥»÷¡£ÔÚÒâ´óÀû¡¢Ä«Î÷¸ç¡¢Ô½ÄϺÍÃÀ¹úµÈ¹ú¶È£¬Â¶³öµÄAMSϵͳÊýÁ¿ÓÈΪ͹Æð¡£Ö»¹Ü×êÑÐÈËÔ±ÒÑÁªÏµÏµÍ³ËùÓÐÕß²¢·î¸æ·çÏÕ£¬µ«ÉÐδÊÕµ½»ý¼«»ØÓ¦¡£Ò»Ð©¹©¸øḚ́µÊ¾ÔÚÓëÊÜÓ°ÏìµÄ¿Í»§ºÏ×÷½â¾öÎÊÌâ¡£ModatΪAMSÓû§ÌṩÁ˶àÏȫ½¨Ò飬Ô̺¬½«ÏµÍ³ÀëÏß»òÖÃÓÚ·À»ðǽºÍVPNºóÃæ¡¢¸ü¸ÄĬÈÏÖÎÀíԱʹ´¦¡¢Ö´Ðжà³É·ÖÉí·ÝÑéÖ¤¡¢ÀûÓÃ×îÐÂÈí¼þºÍ¹Ì¼þ¸üÐÂÒÔ¼°Ï÷¼õ²»ÓÃÒªµÄÍøÂç·þÎñ¡£Í¬Ê±£¬½¨ÒéÒÔ¼ÓÃÜ´ó¾Ö´æ´¢ÉúÎïÌØµãÊý¾ÝºÍPII£¬²¢¶Ï¸ù´ÓǰԱ¹¤µÄÊý¾ÝÒÔÔ¤·Àδ¾ÊÚȨµÄ½Ó¼û¡£
https://www.bleepingcomputer.com/news/security/over-49-000-misconfigured-building-access-systems-exposed-online/
4. ·ÆÂɱö¾ü·½È·ÈÏÆäÍøÂçÔâ·êºÚ¿Í¹¥»÷
2ÔÂ27ÈÕ£¬·ÆÂɱö¾ü·½È·ÈÏÆäÍøÂçÔâ·êÁËÒ»´Î¡°·¸·¨½Ó¼ṵ̂ͼ¡±µÄ¹¥»÷£¬¾Ý³ÆÓÉÒ»¸öÃûΪExodus SecurityµÄºÚ¿Í×éÖ¯ÌáÒé¡£Ö»¹Ü¾ü·½Ñ¸¿ì¶ôÔìÁ˹¥»÷£¬µ«ºÚ¿ÍÐû³ÆÒÑÇÔÈ¡10,000ÌõÏÖÒÛºÍÍËÒÛÎäÊ¿µÄ¼Í¼£¬Ô̺¬Ãô¸ÐµÄÓ×ÎҺ;üÊÂÐÅÏ¢¡£Ö»¹ÜÊý¾ÝµÄÕæÊµÐÔºÍÈ·ÇÐÊýÁ¿ÉÐδµÃµ½ºËʵ£¬µ«ºÚ¿ÍÖÒ¸æËµ£¬ÈôÊDZ¾µØºÚ¿Í¿ÉÄÜʵÏÖÕâÑùµÄÉøÈ룬ÄÇô±í¹ú¹ú¶ÈÖ§³ÖµÄÍþвÐÐΪÕß¿ÉÄÜ»á×öµÃ¸üÔã¡£Exodus SecurityÊǸõØÓò×î»îÔ¾µÄºÚ¿Í×éÖ¯Ö®Ò»£¬½ñÄêÔçЩʱ³½»¹Ðû³Æ¶Ô·ÆÂɱöˮʦµÄÏ®»÷ÊÂÎñÕÆ¹Ü¡£·ÆÂɱöµ±¾Ö×î½ü»¹·¢ÏÖ±í¹úÊÔͼ»ñÈ¡µý±¨Êý¾Ý£¬²¢¿ÛÁôÁËÈýÃûÉæÏӶԹؼü»ù´¡ÉèÊ©½øÐмලµÄÏÓÒÉÈË¡£Ëæ×ŵØÓòµØÔµÕþÖÎÑÏÖØ´óÊÆÉý¼¶£¬·ÆÂɱöµÄÍøÂç¹¥»÷ºÍÐéαÐÅÏ¢»î¶¯¼±¾çÔö³¤£¬´ó²¿ÃŻ¹é×ïÓÚÊÔͼ·ÛËéÈËÃǶԵ±¾Ö»ú¹¹ÐÅÄîµÄºÚ¿Í»î¶¯¼¯Ìå¡£
https://therecord.media/philippines-army-confirms-hack
5. Angry Likho APTÍøÂç¼äµý×éÖ¯ÔÙÏÆ¹¥»÷º£³±£¬ÖØÒªÕë¶Ô¶í°××éÖ¯
2ÔÂ27ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖ£¬ÃûΪAngry Likho APT£¨Ò²±»³Æ×÷Sticky Werewolf£©µÄÍøÂç¼äµý×éÖ¯ÔٴλîÔ¾£¬ÖØÒªÕë¶Ô¶íÂÞ˹ºÍ°×¶íÂÞ˹µÄ×éÖ¯ÌáÒéÐÂÒ»²¨ÍøÂç¹¥»÷¡£¸Ã×éÖ¯×Ô2023ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬Í¨¹ý·¢ËÍÕë¶ÔÐÔ¼«Ç¿µÄÓã²æÊ½ÍøÂç´¹µöµç×ÓÓʼþ£¬¸½´ø¶ñÒâRARÎļþ£¬´¥·¢¸´ÔÓµÄϰȾÁ´£¬×îÖÕ²¿ÊðÃûΪLumma StealerµÄÇÔÈ¡¶ñÒâÈí¼þ¡£ÕâЩÓʼþºÍµö¶üÎļþʹÓÃÁ÷³©µÄ¶íÓï±àд£¬Åú×¢¹¥»÷Õß¿ÉÄÜÊǶíÓïĸÓïÈËÊ¿¡£¹ÌÈ»´óÎÞÊýÊܺ¦Õß¶¼ÔÚ¶íÂÞ˹ºÍ°×¶íÂÞ˹£¬µ«Ò²·¢ÏÖÁËһЩÆäËû¹ú¶ÈµÄÎÞÒâÖ¸±ê¡£Lumma StealerÖ¼ÔÚ´ÓÊÜϰȾµÄÉ豸ÖлñÈ¡Ãô¸ÐÊý¾Ý£¬Ô̺¬ÏµÍ³ÐÅÏ¢¡¢Ó×ÎÒÊý¾ÝÒÔ¼°À´×ÔÊ¢ÐÐä¯ÀÀÆ÷ºÍ¼ÓÃÜÇ®±ÒÇ®°üµÄÊý¾Ý¡£×î½ü£¬¶íÂÞË¹ÍøÂ簲ȫ¹«Ë¾F6»ã±¨ÁËAngry Likho APTµÄй¥»÷£¬Éæ¼°Ô̺¬Base64±àÂëµÄ¶ñÒâ¸ºÔØµÄͼÏñÎļþ£¬²¢·¢ÏÖÁ˸Ã×é֯ʹÓõöкÅÁî·þÎñÆ÷¡£Ö»¹Ü¸Ã×é֯ÿ´Î¹¥»÷³ÇÊÐ×ö³öÇá΢Ťת£¬µ«Æä²½ÖèʼÖÕÈçÒ»£¬¼´ÓÐÕë¶ÔÐԵĴ¹µöµç×ÓÓʼþ¡¢×Ô½âѹ´æµµºÍÖ¼ÔÚÇÔÈ¡Ãô¸ÐÊý¾ÝµÄ×îÖÕÓÐÐ§ÔØºÉ¡£
https://hackread.com/angry-likho-apt-lumma-stealer-attacks-on-russia/
6. CERT-UAÖÒ¸æUAC-0173ÀûÓÃDCRat·çÏÕÎÚ¿ËÀ¼¹«Ö¤»ú¹¹
2ÔÂ26ÈÕ£¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±·´Ó³Ó××飨CERT-UA£©ÖÒ¸æ³Æ£¬ÓÐ×éÖ¯·¸×OÍÅUAC-0173ÔÙ´ÎÌáÒé¹¥»÷£¬Ê¹ÓÃDCRat£¨DarkCrystal RAT£©Ô¶³Ì½Ó¼ûľÂíÏ°È¾ÍÆËã»ú£¬×îй¥»÷ʼÓÚ2025Äê1ÔÂÖÐÑ®£¬Õë¶ÔÎÚ¿ËÀ¼¹«Ö¤Ô±¡£¹¥»÷Õßͨ¹ýÐû³Æ´ú±íÎÚ¿ËÀ¼Ë¾·¨²¿·¢Ë͵ÄÍøÂç´¹µöÓʼþ£¬ÓÕµ¼ÊÕ¼þÈËÏÂÔØ¿ÉÖ´ÐÐÎļþ£¬²¿ÊðDCRat¶ñÒâÈí¼þ£¬²¢ÀûÓÃRDPWRAPPERµÈ¹¤¾ßʵÏÖ²¢ÐÐRDP»á»°£¬½áºÏBOREʵÓ÷¨Ê½³ÉÁ¢RDPÏνӡ£´Ë±í£¬¹¥»÷»¹Éæ¼°FIDDLERÀ¹½ØÉí·ÝÑéÖ¤Êý¾Ý¡¢NMAPÍøÂçɨÃè¡¢XWormÇÔÈ¡Ãô¸ÐÊý¾ÝµÈ¡£ÊÜϰȾϵͳ±»ÓÃ×÷·¢ËͶñÒâÓʼþµÄÇþ·¡£Í¬Ê±£¬CERT-UA»¹¹é×ïÓÚSandwormºÚ¿Í×éÖ¯×Ó¼¯ÈºÀûÓÃÒѽ¨²¹µÄMicrosoft Windows°²È«·ì϶ÌáÒé¹¥»÷£¬Õë¶ÔÈû¶ûάÑÇ¡¢½Ý¿Ë¹²ºÍ¹úºÍÎÚ¿ËÀ¼µÄ¹©¸øÉ̹«Ë¾¡£StrikeReady³¢ÊÔÊÒºÍ΢ÈíÒѼͼ²¿ÃŹ¥»÷£¬Î¢ÈíÔÚ×·×Ù´úºÅΪBadPilotµÄÍþв×éÖ¯¡£
https://thehackernews.com/2025/02/cert-ua-warns-of-uac-0173-attacks.html


¾©¹«Íø°²±¸11010802024551ºÅ