iClickerƽ̨ÔâClickFix¹¥»÷

°ä²¼¹¦·ò 2025-05-12

1. iClickerƽ̨ÔâClickFix¹¥»÷


5ÔÂ11ÈÕ£¬Ê¢ÐеÄѧÉú²Î¼Óƽ̨iClickerÍøÕ¾Ôâ·êClickFix¹¥»÷£¬¸Ã¹¥»÷ͨ¹ýÐéαCAPTCHAÌáÐÑÓÕÆ­Óû§×°ÖöñÒâÈí¼þ¡£iClickerÊÇÂó¿ËÃ×Â×µÄ×Ó¹«Ë¾£¬×÷ΪÊý×Ö½²Ìù¤¾ß±»ÃÀ¹ú¶àËù´óרԺУ¿í·ºÊ¹Óã¬Éæ¼°5000ÃûÀÏʦºÍ700ÍòÃûѧÉú¡£2025Äê4ÔÂ12ÈÕÖÁ16ÈÕÆÚ¼ä£¬iClickerÍøÕ¾±»ºÚ¿ÍÈëÇÖ£¬ÏÔʾαÔìµÄCAPTCHA£¬ÓÕµ¼Óû§µã»÷¡°ÎÒ²»ÊÇ»úеÈË¡±½øÐÐÑéÖ¤¡£µ±Óû§µã»÷ºó£¬PowerShell¾ç±¾±»¸´Ôìµ½Windows¼ôÌù°å£¬Óû§±»Åúʾ´ò¿ªÔËÐжԻ°¿òÕ³Ìù²¢Ö´Ðиþ籾ÒÔʵÏÖÑéÖ¤¡£Ö»¹Ü¸Ã¹¥»÷ÒѲ»ÔÙÔÚiClickerÍøÕ¾ÉÏÔËÐУ¬µ«RedditÉÏÓÐЧ»§½ÒʾÁËÖ´ÐеÄPowerShellÓÐЧ¸ºÔØ¡£¹¥»÷ÖÐʹÓõÄPowerShellºÅÁî¸ß¶È»ìºÏ£¬Ö´ÐÐʱ»áÏνӵ½Ô¶³Ì·þÎñÆ÷¼ìË÷ÁíÒ»¸öPowerShell¾ç±¾¡£Æ¾¾Ý½Ó¼ûÕßÀàÐÍ£¬¸Ã¾ç±¾»áÏÂÔØ·ÖÆçµÄÄÚÈÝ£º¶ÔÓÚÖ¸±ê·Ã¿Í£¬»áÏÂÔØ¶ñÒâÈí¼þµ½ÍÆËã»úÉÏ£¬ÔÊÐíÍþвÐÐΪÕ߯ëÈ«½Ó¼ûÊÜϰȾÉ豸£»¶ÔÓÚ·ÇÖ¸±ê¶ÔÏó£¬Èç¶ñÒâÈí¼þ·ÖÎöɳÏ䣬Ôò»áÏÂÔØ²¢ÔËÐкϷ¨µÄMicrosoft Visual C++ Redistributable¡£´Ó´Óǰ»î¶¯¿´£¬Õâ´Î¹¥»÷ºÜ¿ÉÄÜ´«²¼ÐÅÏ¢ÇÔÈ¡·¨Ê½£¬ÄÜÇÔÈ¡ä¯ÀÀÆ÷cookie¡¢Í´´¦¡¢ÃÜÂë¡¢ÐÅÓþ¿¨ºÍä¯ÀÀº¹Çà¼Í¼£¬»¹ÄÜÇÔÈ¡¼ÓÃÜÇ®±ÒÇ®°ü¡¢Ë½Ô¿ºÍÃô¸ÐÎı¾Îļþ¡£


https://www.bleepingcomputer.com/news/security/iclicker-hack-targeted-students-with-malware-via-fake-captcha/


2. ÐéαAIÊÓÆµ¹¤¾ß´«²¼Noodlophile¶ñÒâÈí¼þ


5ÔÂ10ÈÕ£¬½üÆÚ£¬ÐéαÈËΪÖÇÄÜÊÓÆµÌìÉú¹¤¾ß±»ÍøÂç·¸×ï·Ö×ÓÀûÓ㬴«²¼ÃûΪ¡°Noodlophile¡±µÄÐÂÐÍÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ¼Ò×å¡£ÕâЩ¶ñÒâÍøÕ¾Ê¹Óá°ÍýÏë»úе¡±µÅ×ÕÈËÃû³Æ£¬ÔÚFacebookÓâÔ½Ãû¶ÈȺ×éÖдò¸æ°×£¬¼ÙÒâÏȽøÈËΪÖÇÄܹ¤¾ß£¬ÓÕÆ­Óû§ÉÏ´«ÎļþÒÔÌìÉúÊÓÆµ¡£Morphisec·¢ÏÖ£¬NoodlophileÔÚ°µÍøÂÛ̳ÉÏÏúÊÛ£¬³£Óë¡°»ñÈ¡Cookie+Pass¡±·þÎñ°ó¸¿£¬ÓëÔ½ÄÏÓïÔËÓªÉÌÓйØ£¬ÊÇÒ»ÖÖÐÂÐͶñÒâÈí¼þ¼´·þÎñÐж¯¡£ÆäϰȾÁ´Îª¶à½×¶Î¹ý³Ì£ºÊܺ¦Õß½Ó¼û¶ñÒâÍøÕ¾²¢ÉÏ´«Îļþºó£¬»áÊÕµ½Ò»¸öÔÌÃÔºýŪÐÔ¿ÉÖ´ÐÐÎļþ£¨Video Dream MachineAI.mp4.exe£©µÄZIP´æµµ£¬¸ÃÎļþ¿´ËÆMP4ÊÓÆµ£¬ÊµÎª³ÁÐÂÀûÓõÄCapCutÊÓÆµ±à×빤¾ß°æ±¾£¬ÓÃÒÔÌÓ±ÜÓû§ÒÉ»óºÍ²¿ÃŰ²È«½â¾ö¹æ»®¼ì²â¡£Ë«»÷¸ÃÎļþºó£¬»áÖ´ÐÐһϵÁпÉÖ´ÐÐÎļþ£¬×îÖÕÆô¶¯Åú´¦Öþ籾£¬ÀûÓúϷ¨Windows¹¤¾ß½âÂë²¢ÌáÈ¡ÊÜÃÜÂë±£»¤µÄRARÎļþ£¬Í¬Ê±Ôö³¤×¢²á±íÏîÒÔʵÏÖÓÆ¾ÃÐÔ¡£Ëæºó£¬Ö´ÐдÓÔ¶³Ì·þÎñÆ÷»ñÈ¡µÄ»ìºÏPython¾ç±¾£¬ÔÚÄÚ´æÖÐÖ´ÐÐNoodlophile Stealer¡£NoodlophileÖ¼ÔÚÇÔÈ¡ÍøÂçä¯ÀÀÆ÷ÉÏ´æ´¢µÄÊý¾Ý£¬ÈçÕË»§Í´´¦¡¢»á»°cookie¡¢ÁîÅÆºÍ¼ÓÃÜÇ®±ÒÇ®°üÎļþ£¬²¢Í¨¹ýTelegram»úеÈËй¶Êý¾Ý£¬¸Ã»úеÈ˳äÈÎÒñ±ÎµÄºÅÁîºÍ½ÚÔì·þÎñÆ÷¡£


https://www.bleepingcomputer.com/news/security/fake-ai-video-generators-drop-new-noodlophile-infostealer-malware/


3. AscensionÊý¾Ýй¶ӰÏ쳬43ÍòÃû»¼Õß


5ÔÂ9ÈÕ£¬ÃÀ¹úAscensionÒ½ÁƱ£½¡ÏµÍ³½üÈÕй©£¬ÉϸöÔ²úÉúÁËһ·³Á´óÊý¾Ýй¶ÊÂÎñ£¬³¬¹ý43ÍòÃû»¼ÕßµÄÓ×ÎÒºÍÒ½ÁƱ£½¡ÐÅÏ¢Ô⵽й¶¡£¾ÝAscensionÔÚ4Ô·ݷ¢Ë͸øÊÜÓ°ÏìÕßµÄ֪ͨÐÅÏÔʾ£¬ÕâЩÐÅÏ¢ÔÚÈ¥Äê12ÔµÄÒ»´ÎÊý¾Ý͵ÇÔ¹¥»÷Öб»µÁ£¬¹¥»÷Éæ¼°AscensionµÄһλǰóÒ×ͬ°é¡£¹¥»÷Õß»ñÈ¡ÁËÓ뻼ÕßסԺ¾ÍÕïÓйصÄÓ×ÎÒ½¡È«ÐÅÏ¢£¬ÈçÒ½ÉúÐÕÃû¡¢ÈëÔººÍ³öÔºÈÕÆÚ¡¢Õï¶ÏºÍÕ˵¥´úÂëµÈ£¬»¹Ô̺¬»¼ÕßµÄÓ×ÎÒÐÅÏ¢£¬ÈçÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢µ®ÉúÈÕÆÚ¡¢ÖÖ×å¡¢ÐÔ±ðºÍÉç»á°²È«ºÅÂëµÈ¡£AscensionÔÚ»ñϤDZÔÚ°²È«ÊÂÎñºóµ±¼´·¢Õ¹µ÷²é£¬²¢ÓÚ½ñÄê1ÔÂ21ÈÕÈ·¶¨£¬ÆäÎÞÒâÖÐÏòǰóÒ×ͬ°éй¶ÁËÐÅÏ¢£¬ÇÒ²¿ÃÅÐÅÏ¢¿ÉÄÜÒòǰóÒ×ͬ°éʹÓõĵÚÈý·½Èí¼þ·ì϶¶ø±»ÇÔÈ¡¡£Ö»¹ÜAscensionÆäʱδй©ÊÜÓ°Ïì×ÜÈËÊý£¬µ«ºóÐøÎļþÏÔʾ£¬Õâ´ÎÊÂÎñÓ°ÏìÁ˵¿ËÈøË¹ÖݵÄ11Íò¶àÈË£¬ÂíÈøÖîÈûÖÝÒ²ÓÐ96Ãû¾ÓÃñµÄÒ½ÁƼͼºÍÉç»á°²È«ºÅÂ뱻й¶¡£´Ë±í£¬Ascension»¹ÏòÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿Ìá½»µÄÎļþÖÐÅû¶£¬Õâ´ÎÊý¾Ýй¶¹²Ó°ÏìÁË43Íò¶àÈË¡£AscensionΪÊÜÓ°ÏìÓû§ÌṩÁËÁ½ÄêµÄÃâ·ÑÉí·Ý¼à¿Ø·þÎñ¡£


https://www.bleepingcomputer.com/news/security/ascension-says-recent-data-breach-affects-over-430-000-patients/


4. ·¨Âɲ¿ÃÅ·ÛËéÔËÓª20ÄêµÄ½©Ê¬ÍøÂç


5ÔÂ9ÈÕ£¬·¨Âɲ¿ÃŽüÈÕ·ÛËéÁËÒ»¸öÔËÓª20ÄêµÄ½©Ê¬ÍøÂ磬¸ÃÍøÂçͨ¹ý¶ñÒâÈí¼þϰȾÁËÊýǧ̨¾ÉʽÎÞÏß»¥ÁªÍøÂ·ÓÉÆ÷£¬²¢³ÉÁ¢ÁËAnyproxyºÍ5socksÁ½¸öסլ´úÀíÍøÂç¡£ÃÀ¹ú˾·¨²¿¸æ×´ÁËÈýÃû¶íÂÞ˹¹«ÃñºÍÒ»Ãû¹þÈø¿Ë˹̹¹«Ãñ£¬Ö¸¿ØËûÃDzμÓÔËÓª²¢´ÓÖлñÀû¡£Õâ´ÎÐж¯ÓÉÃÀ¹úµ±¾ÖÓëºÉÀ¼¹ú¶È¾¯Ô±¾Ö¡¢ºÉÀ¼¹«¹²¼ì²ì»ú¹Ø¡¢Ì©¹ú»Ê¼Ò¾¯Ô±¾Ö¼°Lumen TechnologiesÆìÏÂBlack Lotus Labs·ÖÎöʦ½áºÏ·¢Õ¹¡£½©Ê¬ÍøÂç×Ô2004ÄêÆð·½±ãÓöñÒâÈí¼þϰȾ·ÓÉÆ÷£¬ÔÊÐíδ¾­ÊÚȨ½Ó¼ûÉ豸£¬²¢½«Æä×÷Ϊ´úÀí·þÎñÆ÷ÏúÊÛ¡£Óû§ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÖ±½ÓÏνӴúÀí£¬µ¼Ö´óÁ¿¶ñÒâÐÐΪÕß¿ÉÄÜ»ñµÃÃâ·Ñ½Ó¼ûȨÏÞ¡£´ËÀà´úÀí·þÎñÒñ±ÎÐÔÇ¿£¬ÄܱܿªÍøÂç¼à¿Ø¹¤¾ß£¬±»ÓÃÓÚ¸æ°×ڲƭ¡¢DDoS¹¥»÷µÈ¶àÖÖ·¸·¨ÐÐΪ¡£Óû§ÐèÖ§¸¶¶©ÔÄ·Ñ£¬¶øËÄÃû±»¸æÍ¨¹ýÏúÊÛ¶ÔAnyproxy½©Ê¬ÍøÂçÊÜϰȾ·ÓÉÆ÷²¿ÃŵĽӼûȨÏÞ£¬ÊÕÈ¡Á˾޶î×ʽð¡£ËûÃÇʹÓöíÂÞ˹ºÍºÉÀ¼µÈµØµÄ·þÎñÆ÷À´ÔËÓªÍøÕ¾ºÍÖÎÀí½©Ê¬ÍøÂç¡£ËÄÈ˾ù±»Ö¸¿Ø·¸ÓÐͬı×ïºÍ·ÛËéÊܱ£»¤ÍÆËã»ú×ÆäÖÐÁ½ÈË»¹±»Ö¸¿ØÐéαע²áÓòÃû¡£


https://www.bleepingcomputer.com/news/security/police-dismantles-botnet-selling-hacked-routers-as-residential-proxies/


5. ÍøÂç´¹µö¹¥»÷ÀûÓÃBlob URIÈÆ¹ý°²È«ÇÔȡʹ´¦


5ÔÂ9ÈÕ£¬Cofense Intelligence½ÒʾÁËÒ»ÖÖÐÂÐÍÍøÂç´¹µö¼¼Êõ£¬¸Ã¼¼ÊõÀûÓÃblob URIÔÚÓû§ä¯ÀÀÆ÷Öд´½¨±¾µØÐéαµÇÂ¼Ò³Ãæ£¬ÒÔÈÆ¹ýµç×ÓÓʼþ°²È«»úÔì²¢ÇÔÈ¡Óû§Í´´¦¡£ÕâÖÖ¼¼Êõ×Ô2022ÄêÖÐÆÚ³öÏÖÒÔÀ´£¬ÕýÈÕÒæ±»ÍøÂç·¸×ï·Ö×ÓËùÀûÓã¬ËûÃÇͨ¹ýµç×ÓÓʼþ½«Æ¾Ö¤´¹µöÒ³ÃæÖ±½Ó·¢Ë͵½Óû§ÊÕ¼þÏä¡£Blob URIÕý±¾ÊÇÖ¸Ïòä¯ÀÀÆ÷±£ÁôÔÚÓû§ÍÆËã»úÉϵÄһʱÊý¾ÝµÄµØÖ·£¬³£ÓÃÓںϷ¨WebÖ°ÄÜ£¬ÈçYouTubeµÄÊÓÆµÊý¾Ýһʱ´æ´¢¡£È»¶ø£¬Æä±¾µØ»¯¸öÐÔ£¬¼´Ò»¸öä¯ÀÀÆ÷´´½¨µÄBlob URIÎÞ·¨±»ÆäËûä¯ÀÀÆ÷½Ó¼û£¬È´±»ÍþвÐÐΪÕßÀûÓÃÀ´Ö´ÐжñÒâ¹¥»÷¡£ÓÉÓÚBlob URIÊý¾Ý²»ÔÚͨÀý»¥ÁªÍøÉÏ£¬µç×ÓÓʼþ°²ÕûϵͳÄÑÒÔ¼ì²âµ½ÆäÖеÄÓк¦ÐéαµÇÂ¼Ò³Ãæ¡£µ±Óû§µã»÷´¹µöÓʼþÖеÄÁ´½Óʱ£¬ËûÃÇͨ³£»á±»Êèµ¼ÖÁÒ»¸öÊÜÐÅÀµµÄÕæÊµÍøÕ¾£¬ËæºóÔÙ±»³Á¶¨Ïòµ½¹¥»÷Õß½ÚÔìµÄ°µ²ØÍøÒ³¡£Õâ¸ö°µ²ØÍøÒ³»áÀûÓÃBlob URIÔÚÓû§ä¯ÀÀÆ÷ÖÐÖ±½Ó´´½¨ÐéαµÇÂ¼Ò³Ãæ£¬ÇÔÈ¡Óû§ÃûºÍÃÜÂë¡£ÕâÖÖ¼¼Êõ¶Ô×Ô¶¯»¯°²Õûϵͳ£¬ÓÈÆäÊǰ²È«µç×ÓÓʼþÍø¹Ø(SEG)×é³ÉÁËÌôÕ½£¬ÓÉÓÚ»ùÓÚÈËΪÖÇÄܵݲȫģÐÍ¿ÉÄÜÉÐδ³ä·ÖѵÁ·ÒÔ·Ö±æBlob URIµÄºÏ·¨Óë¶ñÒâÓô¦¡£


https://hackread.com/phishing-attack-blob-uri-fake-login-pages-browser/


6. ÄϷǺ½¿ÕÔâÍøÂç¹¥»÷ÖÂϵͳ̱»¾


5ÔÂ8ÈÕ£¬ÄϷǺ½¿Õ½üÈÕÔâ·êÍøÂç¹¥»÷£¬µ¼ÖÂÆä¹Ù·½ÍøÕ¾¡¢¶à¸öÄÚ²¿ÔËӪϵͳ¼°Òƶ¯ÀûÓ÷¨Ê½ÁÙʱÖжÏ¡£²»Í⣬¹«Ë¾ITÍŶÓÒѽÚÔìÊÂ̬£¬²¢½«Ö÷Ì⺽°àÔËÓªµÄ×ÌÈŽµÖÁ×îµÍ¡£ÔÚÖܶþ°ä²¼µÄÉêÃ÷ÖУ¬ÄϷǺ½¿ÕÇ¿µ÷¹Ø¼ü¿Í·þÇþ·Èç¿Í»§·þÎñÖÐÐĺÍÏúÊ۰칫ÊÒ³ÖÐøÔËÐУ¬ÇÒËùÓÐÊÜÓ°ÏìÆ½Ì¨ÒѸ´Ô­Õý³£Ö°ÄÜ¡£¹ØÓÚÕâ´ÎÊÂÎñÊÇ·ñÉæ¼°ÀÕË÷Èí¼þ£¬¹«Ë¾Î´Óè»ØÓ¦¡£Ê×ϯִÐйÙÔ¼º²¡¤À­ÄªÀ­°µÊ¾£¬¹«Ë¾ÔÚµ÷²éÊÂÎñµ××ÓÔ­Òò£¬²¢ºË²éÃô¸ÐÐÅÏ¢ÊÇ·ñ±íй£¬Í¬Ê±ÒÑÏò¹ú¶È°²È«¾Ö¡¢ÄϷǾ¯Ô±¾Ö¼°ÐÅÏ¢¼à¹Ü»ú¹¹»ã±¨´ËÊ¡£ÄϷǺ½¿Õ³Ðŵ£¬ÈôÈ·ÈÏ´æÔÚÐÅÏ¢±»µÁ½«Í¨ÖªÊÜÓ°ÏìÈËÔ±¡£Õâ´Î¹¥»÷ÊÇÄϷǹؼü»ú¹¹³ÖÐøÔâ·êÍøÂç·¸×ï³å»÷µÄÓÖÒ»°¸Àý£¬´ËǰÀÕË÷ÍÅ»ïÔøÐ¹Â¶×ÜͳÓ×ÎÒÁªÏµ·½Ê½¡¢ÇÔÈ¡¹ú·À²¿Êý¾Ý£¬¹úÓÐÒøÐÓ×¢ÄÜÔ´¾ÞÓŵÈÒ²½ÓÁ¬ÓöÏ®¡£Ãæ¶ÔÓúÑÝÓúÁÒµÄÍøÂçÍþв£¬ÄϷǵ±¾ÖÓÚ½ñÄê4Ô³ǫ̈йæ£¬Ç¿ÔìÒªÇóËùÓлú¹¹ÏòÐÅÏ¢¼à¹Ü»ú¹¹»ã±¨ÍøÂç¹¥»÷£¬ÒÔ¼ÓÇ¿Ó×ÎÒÐÅÏ¢°²È«ÊÂÎñµÄ¼à¿Ø¡£ÕâÏîÁ¢·¨³ǫ֮̈¼Ê£¬ÕýÖµÄϷǺ½¿ÕµÈ¹úÓÐÆóÒµ´Ó³Ö¾Ã²ÆÕþΣ»úÖи´ËյĹؼüʱÆÚ£¬¸Ãº½Ë¾2024Äê²ÅʵÏÖ13ÄêÀ´³õ´ÎÓ¯Àû£¬´ËǰÒÑÀۼƽÓÊܵ±¾Ö×¢×ÊÔ¼137ÒÚÔªÈËÃñ±Ò¡£


https://therecord.media/south-african-airways-cyberattack-disrupted