Vo1d½©Ê¬ÍøÂçбäÖÖ£º´ó¹æÄ£Ï°È¾Android TVÉ豸²¢ÓÃÓÚ·¸·¨»î¶¯

°ä²¼¹¦·ò 2025-02-28

1. Vo1d½©Ê¬ÍøÂçбäÖÖ£º´ó¹æÄ£Ï°È¾Android TVÉ豸²¢ÓÃÓÚ·¸·¨»î¶¯


2ÔÂ27ÈÕ £¬Vo1d¶ñÒâÈí¼þ½©Ê¬ÍøÂçµÄбäÖÖÒÑϰȾȫÇò226¸ö¹ú¶È/µØÓòµÄ1,590,299̨Android TVÉ豸 £¬²¢½«ÆäÕÐļΪÄäÃû´úÀí·þÎñÆ÷ÍøÂçµÄÒ»²¿ÃÅ¡£Xlab×ÔÈ¥Äê11Ô¸ú×ٴ˻ £¬·¢Ïָý©Ê¬ÍøÂçÔÚ2025Äê1ÔÂ14ÈÕ´ïµ½¶¥·å £¬Ä¿Ç°Õ¼ÓÐ80Íò»îÔ¾»úеÈË¡£Ð°汾µÄVo1d½©Ê¬ÍøÂçδÊÜÖ®Ç°ÆØ¹âÓ°Ïì £¬³ÖÐø´ó¹æÄ£ÔË×÷ £¬²¢¾ß±¸ÏȽøµÄ¼ÓÃܼ¼Êõ¡¢Óе¯ÐÔµÄDGA»ù´¡ÉèÊ©¼°ÒþÉíÄÜÁ¦¡£Æä¹æÄ£ÖØ´ó £¬³¬¹ýBigpanziµÈ½©Ê¬ÍøÂç £¬Ï°È¾ÖØÒª¼¯ÖÐÔÚ°ÍÎ÷¡¢ÄÏ·Ç¡¢Ó¡¶ÈÄáÎ÷ÑǵȵØ¡£×êÑÐÈËÔ±·¢ÏÖ £¬½©Ê¬ÍøÂçϰȾÊýÁ¿´æÔÚÏÔÖø¼¤Ôö¾°Ïó £¬´§Ä¦Óë¡°×âÁÞ-»Ø±¨¡±ÖÜÆÚÓйØ £¬¼´Vo1d½«½©Ê¬ÍøÂç»ù´¡ÉèÊ©³ö×â¸øÆäËû×éÖ¯½øÐз¸·¨»î¶¯¡£´Ë±í £¬Vo1d»¹ÓµÓиæ°×ڲƭְÄÜ £¬Í¨¹ý·ÂÕÕ¸æ°×µã»÷»òÊÓÆµÅÔ¹ÛαÔìÓû§»¥¶¯ £¬ÎªÚ²Æ­ÐÔ¸æ°×ÉÌ´´ÔìÊÕÈë¡£¼øÓÚϰȾÁ´Î´Öª £¬½¨ÒéAndroid TVÓû§²ÉÈ¡ÕûÌ尲ȫ²½Öè¼õÇáVo1dÍþв £¬Ô̺¬´Ó¿¿µÃס¹©¸øÉ̲ɰìÉ豸¡¢×°Öù̼þºÍ°²È«¸üС¢Ô¤·ÀÏÂÔØ·Ç¹Ù·½ÀûÓ÷¨Ê½¡¢½ûÓÃÔ¶³Ì½Ó¼ûÖ°Äܼ°ÀëÏß´æ´¢µÈ¡£


https://www.bleepingcomputer.com/news/security/vo1d-malware-botnet-grows-to-16-million-android-tvs-worldwide/


2. ºÚ¿Í¼ÙÒą̂Íå˰Îñ»ú¹Ø²¿Êð Winos 4.0 ¶ñÒâÈí¼þ


2ÔÂ27ÈÕ £¬FortiGuard Labs·¢ÏÖÁËÕë¶Ǫ̂ÍåÆóÒµµÄжñÒâÈí¼þ»î¶¯ £¬¸Ã»î¶¯²¿ÊðÁËÒ»¸öÃûΪWinos 4.0µÄ¸ß¼¶¶ñÒâÈí¼þ¿ò¼Ü¡£¸Ã¶ñÒâÈí¼þͨ¹ý¾«ÐÄÉè¼ÆµÄ´¹µöµç×ÓÓʼþ½øÐд«²¼ £¬ÕâЩÓʼþ¼ÙÒą̂Íå¹ú¶È˰Îñ¾Ö²¢Ðû³ÆÔ̺¬Ë°Îñ²é³­¹«Ë¾Ãûµ¥ £¬ÓÕʹÊÕ¼þÈËÏÂÔØÔ̺¬¶ñÒâDLLµÄ¸½¼þ¡£Winos 4.0ѡȡÁ˶à½×¶ÎϰȾ¹ý³Ì £¬Í¨¹ýһϵÁпÉÖ´ÐÐÎļþºÍDLLÎļþ·¢Õ¹¹¥»÷ £¬×îÖÕÖ÷ÕÅÊÇÇÔÈ¡Ãô¸ÐÐÅÏ¢ÒÔÓÃÓÚ½«À´µÄ¶ñÒâ»î¶¯¡£¸Ã¶ñÒâÈí¼þÓµÓи߶ȵĽýÝÐÔºÍÊÊÓ¦ÐÔ £¬¿ÉÄÜÈÆ¹ýUAC¡¢ÍøÂçϵͳÐÅÏ¢¡¢½ûÓÃÆÁÄ»±£»¤·¨Ê½ºÍÊ¡µçÖ°ÄÜ £¬²¢×Ô¶¯¼à¶½ºÍ°Ñ³ÖÓû§»î¶¯ £¬Èç²¶»ñÆÁÄ»½ØÍ¼¡¢¼Í¼»÷¼üºÍ¼ôÌù°åÄÚÈݵÈ¡£ÎªÁ˱£»¤×Ô¼ºÃâÊÜ´ËÀà¶ñÒâÈí¼þµÄÇÖº¦ £¬Óû§±ØÒª¶Ôδ¾­ÒªÇóµÄµç×ÓÓʼþά³Ö¸ß¶È¾¯Ìè £¬Ô¤·À´ò¿ªÑ¹ËõÎļþ¸½¼þ £¬²¢ÆôÓÃʵʱɨÃèÒÔ¼ì²âºÍ×èÖ¹Íþв¡£×¨¼Ò½¨Òéѡȡ¶àµµ´Î·ÀÓù²½Öè £¬½áºÏÓû§½ÌÓýºÍÏȽøµÄÍþв¼ì²â¼¼ÊõÀ´×èÖ¹Éç»á¹¤³Ì¹¥»÷¡£


https://hackread.com/hackers-impersonate-taiwans-tax-authority-winos-4-0-malware/


3. 49,000¸ö½Ó¼ûÖÎÀíϵͳÅäÖÃÃýÎó¶³ö £¬Î£¼°È«ÇòÒþÖÔÓëÎïÀí°²È«


2ÔÂ27ÈÕ £¬ModatµÄ°²È«×êÑÐÈËÔ±·¢ÏÖÈ«ÇòÁìÓòÄÚ´æÔÚ49,000¸öÅäÖÃÃýÎóÇÒ¶³öÔÚ»¥ÁªÍøÉϵĽӼûÖÎÀíϵͳ£¨AMS£© £¬ÕâЩϵͳÕý±¾ÓÃÓÚͨ¹ýÉúÎï¼ø±ð¡¢Éí·ÝÖ¤»ò³µÅƽÚÔìÔ±¹¤¶Ô¹¹ÖþÎï¡¢ÉèÊ©ºÍ½ûÇøµÄ½Ó¼û¡£È»¶ø £¬ÓÉÓÚδÕýÈ·ÅäÖð²È«Éí·ÝÑéÖ¤ £¬ÈκÎÈ˶¼Äܹ»ÇáËɽӼûÕâЩϵͳ £¬µ¼ÖÂÃô¸ÐµÄÔ±¹¤Êý¾Ý£¨ÈçÓ×ÎÒÉí·ÝÐÅÏ¢¡¢ÉúÎïÌØµãÊý¾Ý¡¢ÕÕÆ¬¡¢¹¤×÷¹¦·ò±íºÍ½Ó¼ûÈÕÖ¾£©±»Ð¹Â¶¡£Õâ²»½öΣ¼°ÁËÒþÖÔ°²È« £¬»¹¿ÉÄܶԹؼü»ù´¡ÉèÊ©£¨Èçµ±¾Ö¹¹Öþ¡¢·¢µçÕ¾ºÍË®´¦ÖÃÉèÊ©£©µÄÎïÀí°²È«×é³ÉÍþв¡£´Ë±í £¬Â¶³öµÄÐÅÏ¢»¹¿ÉÄܱ»ÓÃÓÚÕë¶ÔÓйØ×éÖ¯ÌáÒéÍøÂç´¹µöºÍÉç»á¹¤³Ì¹¥»÷¡£ÔÚÒâ´óÀû¡¢Ä«Î÷¸ç¡¢Ô½ÄϺÍÃÀ¹úµÈ¹ú¶È £¬Â¶³öµÄAMSϵͳÊýÁ¿ÓÈΪ͹Æð¡£Ö»¹Ü×êÑÐÈËÔ±ÒÑÁªÏµÏµÍ³ËùÓÐÕß²¢·î¸æ·çÏÕ £¬µ«ÉÐδÊÕµ½»ý¼«»ØÓ¦¡£Ò»Ð©¹©¸øḚ́µÊ¾ÔÚÓëÊÜÓ°ÏìµÄ¿Í»§ºÏ×÷½â¾öÎÊÌâ¡£ModatΪAMSÓû§ÌṩÁ˶àÏȫ½¨Òé £¬Ô̺¬½«ÏµÍ³ÀëÏß»òÖÃÓÚ·À»ðǽºÍVPNºóÃæ¡¢¸ü¸ÄĬÈÏÖÎÀíԱʹ´¦¡¢Ö´Ðжà³É·ÖÉí·ÝÑéÖ¤¡¢ÀûÓÃ×îÐÂÈí¼þºÍ¹Ì¼þ¸üÐÂÒÔ¼°Ï÷¼õ²»ÓÃÒªµÄÍøÂç·þÎñ¡£Í¬Ê± £¬½¨ÒéÒÔ¼ÓÃÜ´ó¾Ö´æ´¢ÉúÎïÌØµãÊý¾ÝºÍPII £¬²¢¶Ï¸ù´ÓǰԱ¹¤µÄÊý¾ÝÒÔÔ¤·Àδ¾­ÊÚȨµÄ½Ó¼û¡£


https://www.bleepingcomputer.com/news/security/over-49-000-misconfigured-building-access-systems-exposed-online/


4. ·ÆÂɱö¾ü·½È·ÈÏÆäÍøÂçÔâ·êºÚ¿Í¹¥»÷


2ÔÂ27ÈÕ £¬·ÆÂɱö¾ü·½È·ÈÏÆäÍøÂçÔâ·êÁËÒ»´Î¡°·¸·¨½Ó¼ṵ̂ͼ¡±µÄ¹¥»÷ £¬¾Ý³ÆÓÉÒ»¸öÃûΪExodus SecurityµÄºÚ¿Í×éÖ¯ÌáÒé¡£Ö»¹Ü¾ü·½Ñ¸¿ì¶ôÔìÁ˹¥»÷ £¬µ«ºÚ¿ÍÐû³ÆÒÑÇÔÈ¡10,000ÌõÏÖÒÛºÍÍËÒÛÎäÊ¿µÄ¼Í¼ £¬Ô̺¬Ãô¸ÐµÄÓ×ÎҺ;üÊÂÐÅÏ¢¡£Ö»¹ÜÊý¾ÝµÄÕæÊµÐÔºÍÈ·ÇÐÊýÁ¿ÉÐδµÃµ½ºËʵ £¬µ«ºÚ¿ÍÖÒ¸æËµ £¬ÈôÊDZ¾µØºÚ¿Í¿ÉÄÜʵÏÖÕâÑùµÄÉøÈë £¬ÄÇô±í¹ú¹ú¶ÈÖ§³ÖµÄÍþвÐÐΪÕß¿ÉÄÜ»á×öµÃ¸üÔã¡£Exodus SecurityÊǸõØÓò×î»îÔ¾µÄºÚ¿Í×éÖ¯Ö®Ò» £¬½ñÄêÔçЩʱ³½»¹Ðû³Æ¶Ô·ÆÂɱöˮʦµÄÏ®»÷ÊÂÎñÕÆ¹Ü¡£·ÆÂɱöµ±¾Ö×î½ü»¹·¢ÏÖ±í¹úÊÔͼ»ñÈ¡µý±¨Êý¾Ý £¬²¢¿ÛÁôÁËÈýÃûÉæÏӶԹؼü»ù´¡ÉèÊ©½øÐмලµÄÏÓÒÉÈË¡£Ëæ×ŵØÓòµØÔµÕþÖÎÑÏÖØ´óÊÆÉý¼¶ £¬·ÆÂɱöµÄÍøÂç¹¥»÷ºÍÐéαÐÅÏ¢»î¶¯¼±¾çÔö³¤ £¬´ó²¿ÃŻ¹é×ïÓÚÊÔͼ·ÛËéÈËÃǶԵ±¾Ö»ú¹¹ÐÅÄîµÄºÚ¿Í»î¶¯¼¯Ìå¡£


https://therecord.media/philippines-army-confirms-hack


5. Angry Likho APTÍøÂç¼äµý×éÖ¯ÔÙÏÆ¹¥»÷º£³± £¬ÖØÒªÕë¶Ô¶í°××éÖ¯


2ÔÂ27ÈÕ £¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖ £¬ÃûΪAngry Likho APT£¨Ò²±»³Æ×÷Sticky Werewolf£©µÄÍøÂç¼äµý×éÖ¯ÔٴλîÔ¾ £¬ÖØÒªÕë¶Ô¶íÂÞ˹ºÍ°×¶íÂÞ˹µÄ×éÖ¯ÌáÒéÐÂÒ»²¨ÍøÂç¹¥»÷¡£¸Ã×éÖ¯×Ô2023ÄêÒÔÀ´Ò»Ïò»îÔ¾ £¬Í¨¹ý·¢ËÍÕë¶ÔÐÔ¼«Ç¿µÄÓã²æÊ½ÍøÂç´¹µöµç×ÓÓʼþ £¬¸½´ø¶ñÒâRARÎļþ £¬´¥·¢¸´ÔÓµÄϰȾÁ´ £¬×îÖÕ²¿ÊðÃûΪLumma StealerµÄÇÔÈ¡¶ñÒâÈí¼þ¡£ÕâЩÓʼþºÍµö¶üÎļþʹÓÃÁ÷³©µÄ¶íÓï±àд £¬Åú×¢¹¥»÷Õß¿ÉÄÜÊǶíÓïĸÓïÈËÊ¿¡£¹ÌÈ»´óÎÞÊýÊܺ¦Õß¶¼ÔÚ¶íÂÞ˹ºÍ°×¶íÂÞ˹ £¬µ«Ò²·¢ÏÖÁËһЩÆäËû¹ú¶ÈµÄÎÞÒâÖ¸±ê¡£Lumma StealerÖ¼ÔÚ´ÓÊÜϰȾµÄÉ豸ÖлñÈ¡Ãô¸ÐÊý¾Ý £¬Ô̺¬ÏµÍ³ÐÅÏ¢¡¢Ó×ÎÒÊý¾ÝÒÔ¼°À´×ÔÊ¢ÐÐä¯ÀÀÆ÷ºÍ¼ÓÃÜÇ®±ÒÇ®°üµÄÊý¾Ý¡£×î½ü £¬¶íÂÞË¹ÍøÂ簲ȫ¹«Ë¾F6»ã±¨ÁËAngry Likho APTµÄй¥»÷ £¬Éæ¼°Ô̺¬Base64±àÂëµÄ¶ñÒâ¸ºÔØµÄͼÏñÎļþ £¬²¢·¢ÏÖÁ˸Ã×é֯ʹÓõöкÅÁî·þÎñÆ÷¡£Ö»¹Ü¸Ã×é֯ÿ´Î¹¥»÷³ÇÊÐ×ö³öÇá΢Ťת £¬µ«Æä²½ÖèʼÖÕÈçÒ» £¬¼´ÓÐÕë¶ÔÐԵĴ¹µöµç×ÓÓʼþ¡¢×Ô½âѹ´æµµºÍÖ¼ÔÚÇÔÈ¡Ãô¸ÐÊý¾ÝµÄ×îÖÕÓÐÐ§ÔØºÉ¡£


https://hackread.com/angry-likho-apt-lumma-stealer-attacks-on-russia/


6. CERT-UAÖÒ¸æUAC-0173ÀûÓÃDCRat·çÏÕÎÚ¿ËÀ¼¹«Ö¤»ú¹¹


2ÔÂ26ÈÕ £¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±·´Ó³Ó××飨CERT-UA£©ÖÒ¸æ³Æ £¬ÓÐ×éÖ¯·¸×OÍÅUAC-0173ÔÙ´ÎÌáÒé¹¥»÷ £¬Ê¹ÓÃDCRat£¨DarkCrystal RAT£©Ô¶³Ì½Ó¼ûľÂíÏ°È¾ÍÆËã»ú £¬×îй¥»÷ʼÓÚ2025Äê1ÔÂÖÐÑ® £¬Õë¶ÔÎÚ¿ËÀ¼¹«Ö¤Ô±¡£¹¥»÷Õßͨ¹ýÐû³Æ´ú±íÎÚ¿ËÀ¼Ë¾·¨²¿·¢Ë͵ÄÍøÂç´¹µöÓʼþ £¬ÓÕµ¼ÊÕ¼þÈËÏÂÔØ¿ÉÖ´ÐÐÎļþ £¬²¿ÊðDCRat¶ñÒâÈí¼þ £¬²¢ÀûÓÃRDPWRAPPERµÈ¹¤¾ßʵÏÖ²¢ÐÐRDP»á»° £¬½áºÏBOREʵÓ÷¨Ê½³ÉÁ¢RDPÏνÓ¡£´Ë±í £¬¹¥»÷»¹Éæ¼°FIDDLERÀ¹½ØÉí·ÝÑéÖ¤Êý¾Ý¡¢NMAPÍøÂçɨÃè¡¢XWormÇÔÈ¡Ãô¸ÐÊý¾ÝµÈ¡£ÊÜϰȾϵͳ±»ÓÃ×÷·¢ËͶñÒâÓʼþµÄÇþ·¡£Í¬Ê± £¬CERT-UA»¹¹é×ïÓÚSandwormºÚ¿Í×éÖ¯×Ó¼¯ÈºÀûÓÃÒѽ¨²¹µÄMicrosoft Windows°²È«·ì϶ÌáÒé¹¥»÷ £¬Õë¶ÔÈû¶ûάÑÇ¡¢½Ý¿Ë¹²ºÍ¹úºÍÎÚ¿ËÀ¼µÄ¹©¸øÉ̹«Ë¾¡£StrikeReady³¢ÊÔÊÒºÍ΢ÈíÒѼͼ²¿ÃŹ¥»÷ £¬Î¢ÈíÔÚ×·×Ù´úºÅΪBadPilotµÄÍþв×éÖ¯¡£


https://thehackernews.com/2025/02/cert-ua-warns-of-uac-0173-attacks.html