SantaStealer¶ñÒâÈí¼þÆØ¹â£ºÄÚ´æÔËÐбܼì²â´æ·ì϶

°ä²¼¹¦·ò 2025-12-17

1. SantaStealer¶ñÒâÈí¼þÆØ¹â£ºÄÚ´æÔËÐбܼì²â´æ·ì϶


12ÔÂ15ÈÕ £¬½üÈÕ £¬Ò»ÖÖÃûΪSantaStealerµÄÐÂÐͶñÒâÈí¼þ¼´·þÎñ£¨MaaS£©ÐÅÏ¢ÇÔÈ¡·¨Ê½ÔÚTelegram¼°ºÚ¿ÍÂÛ̳ÉϹ«¿ªÐû´«¡£¸Ã·¨Ê½ÓɶíÓ↑·¢Õß´òÔì £¬»ù´¡¶©ÔļÛ175ÃÀÔª/Ô £¬¸ß¼¶°æ300ÃÀÔª/Ô £¬Ðû³ÆÍ¨¹ýÄÚ´æÔËÐжã±Ü»ùÓÚÎļþµÄ¼ì²â»úÔ졣Ȼ¶ø £¬¾ÝRapid7°²È«ÍŶӷÖÎö £¬ÆäÏÖʵÑù±¾Ô¶Î´´ïµ½¡°ÎÞ·¨¼ì²â¡±µÄÐû³Æ³ÉЧ £¬ÇÒ´æÔÚ²Ù×÷°²È«È±µã £¬Ñù±¾Ð¹Â¶Ê±Ô̺¬Î´¼ÓÃÜ×Ö·û´®ºÍ·ûºÅÃû³Æ £¬Â¶³ö¿ª·¢¹ý³ÌÖеÄÊè©¡£SantaStealerʵΪBluelineStealerÏîÖ÷ÕųÁ°ü×° £¬´òËãÄêµ×ÕýʽÉÏÏß¡£Ëü¼¯³É14¸ö¶ÀÁ¢Ï̵߳ÄÊý¾ÝÍøÂçÄ£¿é £¬¿ÉÇÔÈ¡ä¯ÀÀÆ÷ÃÜÂë¡¢Cookie¡¢ÐÅÓþ¿¨ÐÅÏ¢¡¢Telegram/Discord/SteamÊý¾Ý¡¢¼ÓÃÜÇ®±ÒÇ®°üÄÚÈݼ°Îĵµ £¬²¢½ØÈ¡×ÀÃæ½ØÍ¼¡£Êý¾Ý¾­ÄÚ´æ¹éµµÎªZIPÎļþºó £¬Í¨¹ý6767¶Ë¿Ú·Ö10MBµ¥Ôª´«ÊäÖÁÔ¤ÉèC2¶Ëµã¡£¸Ã¶ñÒâÈí¼þ»¹ÊÔÍ¼ÈÆ¹ýChrome 2024Äê7ÔÂÍÆ³öµÄÀûÓð󶨼ÓÃܱ £»¤ £¬µ«Òѱ»¶à¿îÐÅÏ¢ÇÔÈ¡·¨Ê½Í»ÆÆ¡£Æä½ÚÔìÃæ°åÖ§³ÖÓû§ÅäÖÃÖ¸±êÁìÓò £¬´ÓÈ«Á¿Êý¾ÝÇÔÈ¡µ½¾«¼òÓÐÐ§ÔØºÉ £¬²¢ÔÊÐíÅųý¶ÀÁªÌ嵨Óòϵͳ¼°ÑÓ³¤Ö´ÐÐÒԹƻóÊܺ¦Õß¡£


https://www.bleepingcomputer.com/news/security/new-santastealer-malware-steals-data-from-browsers-crypto-wallets/


2. PornHub»áÔ±Êý¾ÝÔâShinyHuntersÀÕË÷


12ÔÂ15ÈÕ £¬³ÉÈËÊÓÆµÆ½Ì¨PornHub½üÈÕÒòµÚÈý·½Êý¾Ý·ÖÎöÉÌMixpanelÊý¾Ýй¶ÊÂÎñÏÝÈëÀÕË÷Î £»ú¡£¾Ý±¨Â· £¬ShinyHuntersÀÕË÷ÍÅ»ïÐû³ÆÇÔÈ¡ÁËPornHub Premium¸ß¼¶»áÔ±µÄ94GBº¹ÇàÊý¾Ý £¬Ô̺¬2.01ÒÚÌõËÑË÷¡¢ÅÔ¹Û¼°ÏÂÔØ¼Í¼ £¬²¢Í¨¹ýÀÕË÷ÓʼþÍþв²»Ö§¸¶Êê½ð½«¹«¿ªÊý¾Ý¡£MixpanelÓÚ2025Äê11ÔÂ8ÈÕÔâ¶ÌÐÅ´¹µö¹¥»÷µ¼ÖÂϵͳÈëÇÖ £¬Æä¿Í»§Êý¾Ýй¶²¨¼°PornHub¡£Ö»¹ÜPornHubÇ¿µ÷×Ô2021ÄêÆðÒÑÖÕÖ¹ÓëMixpanelºÏ×÷ £¬Ð¹Â¶Êý¾ÝΪ2021Äê»ò¸üÔçµÄº¹Çà·ÖÎö¼Í¼ £¬ÇÒÓû§ÃÜÂë¡¢Ö§¸¶¼°²ÆÕþÐÅϢδÊÜÓ°Ïì £¬µ«¸ß¼¶»áÔ±µÄÃô¸Ð»î¶¯¼Í¼ÈÔ±»ÆØ¹â¡£Ð¹Â¶Êý¾ÝÔ̺¬»áÔ±µç×ÓÓʼþµØÖ·¡¢ÊÓÆµURL¡¢¹Ø¼ü´Ê¡¢»î¶¯¹¦·ò¼°µØÀíµØÎ»µÈ £¬²¿ÃÅÑù±¾ÏÔʾÉõÖÁÔ̺¬¶©ÔÄÕßÊÇ·ñÅÔ¹Û/ÏÂÔØÊÓÆµ»òä¯ÀÀƵ·µÄ¾ßÌåÐÐΪ¡£ShinyHunters×÷ΪĻºóºÚÊÖ £¬²»½öÏòPornHub·¢ËÍÀÕË÷Óʼþ £¬»¹¹«¿ªÖ¤ÊµÕâ´Î¹¥»÷ £¬²¢¹ØÁª¶àÆð³Á´óÊý¾Ýй¶ÊÂÎñ¡£


https://www.bleepingcomputer.com/news/security/pornhub-extorted-after-hackers-steal-premium-member-activity-data/


3. Frogblight°²×¿Ä¾Âí¼Ù×°µ±¾ÖÍøÕ¾ÇÔÊØÐÅÏ¢


12ÔÂ15ÈÕ £¬½üÆÚ £¬Ò»¿îÃûΪ¡°Frogblight¡±µÄ¸´ÔÓ°²×¿ÒøÐÐľÂíÔÚÍÁ¶úÆäÒý·¢³Á´ó°²È«Íþв £¬Æäͨ¹ý¾«ÐÄÉè¼ÆµÄÉç»á¹¤³Ì¼¿Á©ÇÔÈ¡ÒøÐÐÆ¾Ö¤ÓëÓ×ÎÒÊý¾Ý £¬²¢Õ¹Ê¾³ö³ÖÐø½ø»¯Ìصã¡£¸ÃľÂí×î³õ¼Ù×°³ÉÍÁ¶úÆä¹Ù·½µ±¾ÖÃÅ»§ÀûÓà £¬Ðû³Æ¿É½Ó¼û·¨Í¥°¸¼þÎļþ £¬ºóÑݱäΪ·ÂðChromeµÈÊ¢ÐÐÀûÓà £¬Í¨¹ý´¹µö¶ÌÐÅ´«²¼ £¬Êܺ¦ÕßÊÕµ½Ðéα·¨Í¥°¸¼þ֪ͨ¶ÌÐÅ £¬µã»÷Á´½Óºó±»µ¼Ïò¶ñÒâÍøÕ¾²¢ÓÕµ¼ÏÂÔØÀûÓá£×°Öúó £¬Frogblight»áÒªÇó¶ÁÈ¡¶ÌÐÅ¡¢½Ó¼û´æ´¢¿Õ¼ä¼°»ñÈ¡É豸ÐÅÏ¢µÈÃô¸ÐȨÏÞ¡£Æô¶¯Ê± £¬Æäͨ¹ýǶÈëʽä¯ÀÀÆ÷ÊÓͼÏÔÊ¾ÕæÊµµ±¾ÖÍøÒ³Ôì×÷¡°ºÏ·¨¼ÙÏó¡± £¬Í¬Ê±ÔÚºó¶Ü¼à¿ØÓû§²Ù×÷¡£¸ÃľÂí¾ß±¸Ë«³ÁÖ°ÄÜ£º¼È×÷ÎªÒøÐÐľÂíÇÔÈ¡ÔÚÏßÒøÐеǼÐÅÏ¢ £¬Ó־߱¸¼äµýÈí¼þ¸öÐÔ £¬¼à¿Ø¶ÌÐÅ¡¢¸ú×ÙÒÑ×°ÖÃÀûÓá¢É¨ÃèÎļþϵͳ £¬ÉõÖÁ¿ÉÏò±í·¢ËÍËÁÒâÎı¾ÐÂÎÅ¡£¼¼Êõ²ãÃæ £¬Frogblightͨ¹ýWebView×¢ÈëJavaScript´úÂë²¶»ñÓû§ÊäÈë £¬Óë½ÚÔì·þÎñÆ÷ͨѶѡȡRetrofit¿âµÄREST APIŲÓà £¬ºóÆÚ±äÖÖתÏòWebSocketÏνÓÒÔ¼ÓÇ¿Òñ±ÎÐÔ¡£


https://cybersecuritynews.com/new-android-malware-frogblight-mimics-as-official-government-websites/


4. ίÄÚÈðÀ­¹ú¶ÈʯÓ͹«Ë¾PDVSAÔâÍøÂç¹¥»÷


12ÔÂ16ÈÕ £¬½üÈÕ £¬Î¯ÄÚÈðÀ­¹ú¶ÈʯÓ͹«Ë¾£¨PDVSA£©Ôâ·êÍøÂç¹¥»÷µ¼Ö³ö¿ÚÒµÎñ¶ÌÔÝÖÐ¶Ï £¬µ«¸Ã¹«Ë¾Ç¿µ÷Õâ´ÎÊÂÎñ½öÓ°Ï첿ÃÅÐÐÕþÖÎÀíϵͳ £¬Î´²¨¼°ÈÕ³£ÔËÓª¡£PDVSAÔÚTelegramÉêÃ÷ÖÐÖ¸³ö £¬°²È«ºÍ̸³É¹¦×èÖ¹Á˹©¸øÖÐ¶Ï £¬²¢½«¸ÃÊÂÎñ¶¨ÐÔΪ¡°ÓëÃÀ¹ṵ́ͼ´Û¶áίÄÚÈðÀ­Ê¯ÓÍÓйصÄÇÖÂÔÐÐΪ¡± £¬³Æ¡°¶ÏÈ»»Ø¾ø±í¹úÈ¨ÊÆ²ß¶¯µÄ¶ñ¶ñϰ¾¶¡±¡£Î¯ÄÚÈðÀ­µ±¾Ö½øÒ»²½½«ÊÂÎñÉÏÉýΪ¶Ô¡°Ö÷ȨÄÜÔ´¿ª·¢È¨¡±µÄ¹¥»÷ £¬Ö±Ö¸ÃÀ¹úÓ뼫¶ËÈ¨ÊÆÍŽá·ÛËé¹ú¶È²»±ä¡£ÎªÓ¦¶Ô·çÏÕ £¬PDVSAÒªÇóÔ±¹¤¹Ø¹ØµçÄÔ¡¢¶Ï¿ª±í²¿É豸¡¢½ûÓÃWiFi¼°ÐÇÁ´ÏÎ½Ó £¬²¢Ç¿»¯ÉèÊ©°²±£¡£Åí²©ÉçÔ®ÒýÄÚ²¿±¸Íü¼³Æ £¬×ÔÖÜÈÕÒÔÀ´°²±£´ëÊ©ÒÑÈ«ÃæÉý¼¶¡£¹«Ë¾ÖÜÒ»°ä²¼ÉêÃ÷³ÆÒÑ´ì°Ü¡°·ÛËḛ́ͼ¡± £¬Ê¯ÓͲúÁ¿Î´ÊÜÓ°Ï졣Ȼ¶ø £¬Â·Í¸ÉçÐÂÎÅԴй© £¬Õâ´Î¹¥»÷ʵΪÀÕË÷Èí¼þ¹¥»÷ £¬·´²¡¶¾½¨¸´¹¤×÷µ¼ÖÂÖÎÀíϵͳ̱»¾ £¬»õÎï½»¸¶Åö±Ú¡£ÊÂÎñ²úÉúÔÚÃÀί¹ØÏµ³ÖÐøÑÏÖØ²¼¾°Ï¡£´Ëǰ £¬ÃÀ¹ú¿ÛѺһËÒÔØÓÐίÄÚÈðÀ­Ô­Ó͵ÄÊÜÔì²ÃÓÍÂÖ £¬ÕâÊÇ×Ô2019ÄêÃÀ¹ú²ÆÕþ²¿¶ÔPDVSAÖ´ÐÐÔì²ÃÒÔÀ´³õ´Î¿ÛѺÓÍÂÖ¡£


https://securityaffairs.com/185755/security/a-cyber-attack-hit-petroleos-de-venezuela-pdvsa-disrupting-export-operations.html


5. ºÚ¿ÍÀûÓÃнü½¨¸´µÄFortinetÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶


12ÔÂ16ÈÕ £¬ÍøÂ簲ȫ¹«Ë¾Arctic Wolf¼à²âµ½ºÚ¿ÍÕýÀûÓÃFortinetÆì϶à¸ö²úÆ·µÄÑϳÁ·ì϶·¸·¨½Ó¼ûÖÎÀíÔ¹ØË»§²¢ÇÔȡϵͳÅäÖÃÎļþ¡£Õâ´Î¶³öµÄÁ½¸ö¸ßΣ·ì϶±ðÀëΪCVE-2025-59718£¨Ó°ÏìFortiOS¡¢FortiProxy¡¢FortiSwitchManager£©ºÍCVE-2025-59719£¨Ó°ÏìFortiWeb£© £¬¾ùÔ´ÓÚSAMLÐÂÎżÓÃÜÊðÃûÑéÖ¤²»µ± £¬¹¥»÷Õ߿ɻú¹Ø¶ñÒâSAML¶ÏÑÔÈÆ¹ýÉí·ÝÑéÖ¤ £¬ÔÚδÊÚȨÇé¿öϵǼÖÎÀíÔ¹ØË»§¡£·ì϶´¥·¢ÐèÉ豸ÆôÓÃFortiCloudµ¥µãµÇ¼£¨SSO£©Ö°ÄÜ £¬¸ÃÖ°ÄÜËä·ÇĬÈÏÉèÖà £¬µ«Í¨¹ýFortiCare×¢²áÉ豸ʱ»á×Ô¶¯¼¤»î £¬³ý·ÇÊÖ¶¯½ûÓá£×Ô12ÔÂ12ÈÕÆð £¬ºÚ¿Íͨ¹ýÓëThe Constant Company¡¢BL Networks¡¢Kaopu Cloud HK¹ØÁªµÄIPµØÖ·ÌáÒé¹¥»÷ £¬ÀûÓöñÒâSSO»ñÈ¡ÖÎÀíԱȨÏÞºó £¬Í¨¹ýWebÖÎÀí½çÃæÏÂÔØÏµÍ³ÅäÖÃÎļþ¡£ÕâЩÎļþÔ̺¬ÍøÂç²¼¾Ö¡¢»¥ÁªÍø·þÎñ¶Ë¿Ú¡¢·À»ðǽսÊõ¡¢Â·ÓÉ±í¼°Ç±ÔÚÃÜÂë¹þÏ£µÈÃô¸ÐÐÅÏ¢ £¬¿ÉÄÜÐ¹Â¶ÍøÂç¼Ü¹¹Ï¸½Ú £¬ÎªºóÐø¹¥»÷Ìṩ֧³Ö¡£·ì϶ӰÏìFortiOS¡¢FortiWebµÈ¶à¸ö°æ±¾ £¬Fortinet½¨ÒéÖÎÀíÔ±µ±¼´½ûÓÃFortiCloud SSOµÇ¼ְÄÜ £¬²¢Éý¼¶ÖÁ½¨¸´°æ±¾¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-newly-patched-fortinet-auth-bypass-flaws/


6. ÐÂÐÍAndroid¶ñÒâÈí¼þCellikÏÖÉíµØÏÂÂÛ̳


12ÔÂ16ÈÕ £¬Òƶ¯°²È«¹«Ë¾iVerifyÔÚµØÏÂÍøÂç·¸×ïÂÛ̳·¢ÏÖÒ»¿îÃûΪCellikµÄÐÂÐÍAndroid¶ñÒâÈí¼þ¼´·þÎñ£¨MaaS£©ÔÚ¹«¿ªÐû´«¡£¸ÃÈí¼þÒÔÿÔÂ150ÃÀÔª»òƽÉú900ÃÀÔªµÄ¼ÛÖµÏúÊÛ £¬ÌṩÁËÒ»Ì×׳´óµÄÖ°ÄÜ×éºÏ £¬×îÒýÈËÖõÖ÷ÕÅÊÇÆäAPK¹¹½¨Æ÷¿É¼¯³ÉGoogle PlayÉ̵ê £¬¹¥»÷ÕßÄÜÖ±½Ó´Ó¹Ù·½ÀûÓÃÉ̵êÑ¡ÔñËÁÒâÀûÓà £¬´´½¨±í±í¿ÉÐŵÄľÂí°æ±¾ £¬Í¬Ê±±£ÁôÔ­ÀûÓõĽçÃæºÍÖ°ÄÜ £¬´Ó¶øµ¢¸é¶ñÒâÈí¼þµÄÂñ·üÆÚ¡£Cellik¾ß±¸ÊµÊ±ÆÁÄ»²¶»ñ¡¢Í¨ÖªÀ¹½Ø¡¢Îļþϵͳä¯ÀÀ¡¢Êý¾ÝÇÔÈ¡¡¢Ô¶³Ì²Á³ý¼°¼ÓÃÜͨ·ͨѶµÈÖ÷ÌâÖ°ÄÜ¡£Æä°µ²Øä¯ÀÀÆ÷ģʽÔÊÐí¹¥»÷ÕßÀûÓÃÊܺ¦ÕßÉ豸´æ´¢µÄcookie½Ó¼ûÍøÕ¾ £»ÀûÓÃ×¢ÈëϵͳÔò¿ÉÔÚËÁÒâÀûÓÃÖеþ¼ÓÐéαµÇÂ¼Ò³Ãæ»ò×¢Èë¶ñÒâ´úÂë £¬ÇÔÈ¡ÕË»§Í´´¦ £»¶øÏòÒÑ×°ÖÃÀûÓÃ×¢ÈëÓÐÐ§ÔØºÉµÄÖ°ÄÜ £¬¸üʹϰȾԴÄÑÒÔ×·Òä £¬³Ö¾ÃÊÜÐÅÀµµÄÀûÓÿÉÄܺöÈ»±äΪµØÆ¦Èí¼þ¡£Âô¼ÒÐû³Æ £¬Í¨¹ý½«¶ñÒâÔØºÉ°ü¹üÔÚÊÜÐÅÀµµÄÀûÓ÷¨Ê½ÖÐ £¬Cellik¿ÉÈÆ¹ýGoogle Play ProtectµÄ¼ì²â»úÔì¡£


https://www.bleepingcomputer.com/news/security/cellik-android-malware-builds-malicious-versions-from-google-play-apps/