¶ñÒâÈí¼þDollyWayÈëÇÖ³¬20,000¸öWordPressÍøÕ¾
°ä²¼¹¦·ò 2025-03-201. ¶ñÒâÈí¼þDollyWayÈëÇÖ³¬20,000¸öWordPressÍøÕ¾
3ÔÂ19ÈÕ£¬×Ô2016ÄêÆð£¬ÃûΪ¡°DollyWay¡±µÄ¶ñÒâÈí¼þÒÑÈëÇÖÈ«Çò³¬¹ý20,000¸öWordPressÍøÕ¾£¬Í¨¹ý³Á¶¨ÏòÓû§ÖÁ¶ñÒâÕ¾µã½øÐÐڲƻ¡£DollyWayÒÑÀú¾ÂÅ´ÎÉý¼¶£¬Ñ¡È¡ÏȽøµÄÌӱܡ¢³ÁÐÂϰȾºÍÇ®±Ò»¯Õ½Êõ¡£×îа汾£¨v3£©×÷Ϊ´óÐÍڿƳÁ¶¨Ïòϵͳ£¬ÀûÓòå¼þºÍÖ÷Ìâ·ì϶¹¥»÷WordPressÍøÕ¾¡£½ØÖÁ2025Äê2Ô£¬DollyWayÿÔ²úÉú1000Íò´ÎÚ²ÆÐÔչʾ£¬Í¨¹ýÐéαµÄÔ¼»á¡¢´ò¶Ä¡¢¼ÓÃÜºÍ³é½±ÍøÕ¾Ó¯Àû£¬ÀûÓÃVexTrioºÍLosPollosÁªÊôÍøÂçʵÏÖÁ÷Á¿±äÏÖ¡£¸Ã¶ñÒâÈí¼þͨ¹ýÁ÷Á¿Ê赼ϵͳɸѡ·Ã¿Í£¬Æ¾¾ÝÆäµØÎ»¡¢É豸ÀàÐͺÍÍÆ¼öÆðÔ´³Á¶¨ÏòÁ÷Á¿¡£¹¥»÷ÕßÀûÓá°wp_enqueue_script¡±¾ç±¾×¢ÈëÈëÇÖÍøÕ¾£¬Í¨¹ý¶à½×¶Î²Ù×÷ʵÏÖ×îÖÕ³Á¶¨Ïò¡£DollyWay»¹¾ß±¸×ÔÎÒÔÙϰȾÄÜÁ¦£¬È·±£ÆäÔÚÿ´ÎÒ³Ãæ¼ÓÔØÊ±×Ô¶¯³ÁÐÂÏ°È¾ÍøÕ¾£¬ÄÑÒԶϸù¡£Ëüͨ¹ý´«²¼PHP´úÂëÖÁ»î¶¯²å¼þ£¬²¢Ôö³¤»ìºÏµÄ¶ñÒâÈí¼þƬ¶ÎµÄWPCode²å¼þ¸±±¾ÊµÏÖÓÆ¾ÃÐÔ¡£´Ë±í£¬DollyWay´´½¨°µ²ØµÄÖÎÀíÔ±Óû§ÕË»§£¬½øÒ»²½Ôö³¤·ÀÓùÄѶȡ£GoDaddyÒÑ·ÖÏíÓëDollyWayÓйصĹ¥»÷Ö¸±êÁÐ±í£¬ÒÔÖú·ÀÓù´ËÍþв£¬²¢½«°ä²¼¸ü¶àϸ½Ú½ÒʾÆä»ù´¡ÉèÊ©ºÍת±äÕ½Êõ¡£
https://www.bleepingcomputer.com/news/security/malware-campaign-dollyway-breached-20-000-wordpress-sites/
2. ¸ú×ÙÈí¼þSpyXÊý¾Ýй¶£¬½ü200ÍòÓû§¼Í¼ÔâÆØ¹â
3ÔÂ19ÈÕ£¬Ò»¿îÏû·Ñ¼¶¼äµýÈí¼þSpyXÓÚÈ¥ÄêÔâ·êÊý¾Ýй¶£¬Ó°ÏìÔ̺¬ÊýǧÃûÆ»¹ûÓû§ÔÚÄڵĽü200ÍòÈË¡£Õâ´Îй¶ÊÂÎñ¿É×·ÒäÖÁ2024Äê6Ô£¬µ«´Ëǰδ±»±¨Â·£¬SpyXÔËÓªÉÌҲδ֪ͨÆä¿Í»§»òÖ¸±êÓû§¡£SpyX¼Ò×å×Ô2017ÄêÒÔÀ´ÒѲúÉú25´ÎÊý¾Ýй¶£¬Åú×¢Ïû·Ñ¼¶¼äµýÈí¼þÐÐÒµ³ÖÐø¼¤Ôö£¬ÑϳÁÍþвÓ×ÎÒÒþÖÔ¡£Ð¹Â¶Êý¾ÝÔ̺¬197ÍòÌõΨһÕÊ»§¼Í¼¼°µç×ÓÓʼþµØÖ·£¬Éæ¼°SpyX¼°Æä¿Ë¡°æ±¾MSafelyºÍSpyPhone¡£Ô¼40%µÄµç×ÓÓʼþµØÖ·ÒÑÔÚ¡°ÎÒ±»ºÚÁË¡±ÍøÕ¾ÉϳöÏÖ¹ý¡£Õâ´Îй¶»¹º±¼û½â½ÒʾÁËSpyXÈôºÎ¶Ô×¼AppleÓû§£¬Ð¹Â¶µÄ»º´æÖÐÔ̺¬Ô¼17,000×éÃ÷ÎÄAppleÕÊ»§Óû§ÃûºÍÃÜÂë¡£Êý¾ÝÕæÊµÐÔÒѵõ½²¿ÃÅÊܺ¦ÕßÈ·ÈÏ£¬ÓÐ¹ØÆ¾Ö¤ÒÑÌṩ¸øÆ»¹û¡£¹È¸èÒѳ·ÏÂÓëSpyX»î¶¯ÓйصÄChromeÀ©´ó·¨Ê½¡£TechCrunchΪAndroidÓû§ÌṩÁ˼äµýÈí¼þÒÆ³ýÖ¸ÄÏ£¬½¨ÒéÆôÓÃGoogle Play Protect¡¢Ê¹ÓÃË«³ÁÉí·ÝÑéÖ¤µÈ´ëÊ©±£»¤ÕÊ»§°²È«¡£iPhoneºÍiPadÓû§Ó¦²é³²¢É¾³ý²»ÒâʶµÄÉ豸£¬È·±£Ê¹Ó󤶸¹ÖÒìµÄÃÜÂ룬²¢ÆôÓÃË«³ÁÉí·ÝÑéÖ¤¡£
https://techcrunch.com/2025/03/19/data-breach-at-stalkerware-spyx-affects-close-to-2-million-including-thousands-of-apple-users/
3. ±öϦ·¨ÄáÑÇÖݽÌÓý¹¤»áÊý¾Ýй¶ӰÏì50ÍòÈË
3ÔÂ19ÈÕ£¬±öϦ·¨ÄáÑÇÖÝ×î´óµÄ¹«¹²²¿Ãʤ»á±öϦ·¨ÄáÑÇÖݽÌÓýлá (PSEA) ÓÚ2024Äê7Ô²úÉúÁËһ·°²È«ÊÂÎñ£¬µ¼Ö³¬¹ý517,487ÃûÓ×ÎÒµÄÐÅÏ¢±»µÁ£¬Ô̺¬ÀÏʦ¡¢Ö§³ÖÈËÔ±¡¢¸ßµµ½ÌÓýÈËÔ±µÈ½ÌÓýרҵÈËÊ¿¡£¾ÝPSEAй©£¬±»µÁÐÅÏ¢¿ÉÄÜÔ̺¬Ó×ÎÒ¡¢²ÆÕþºÍ½¡È«Êý¾Ý£¬ÈçÉç»á°²È«ºÅÂë¡¢Ö§¸¶¿¨ÐÅÏ¢¡¢»¤ÕÕÐÅÏ¢µÈ¡£ÎªÓ¦¶ÔÕâ´ÎÊÂÎñ£¬PSEAΪÊÜÓ°ÏìµÄÓ×ÎÒÌṩÁËÃâ·ÑµÄIDXÐÅÓþ¼à¿ØºÍÉí·Ý¸´Ô·þÎñ£¬²¢½¨ÒéËûÃÇ¼à¿Ø²ÆÕþÕË»§ºÍÐÅÓþ»ã±¨£¬ÉèÖÃڲƾ¯±¨»ò°²È«¶³½á¡£Ö»¹ÜPSEAδÃ÷È·Ö¸³ö¹¥»÷ÕßÉí·Ý£¬µ«RhysidaÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶ÔÕâ´ÎÈëÇÖÕÆ¹Ü£¬²¢ÒªÇóÖ§¸¶20±ÈÌØ±ÒÊê½ð¡£¹ÌÈ» PSEA ²¢Î´Ð¹Â©ÊÇ·ñÖ§¸¶ÁËÊê½ðÒÔÔ¤·ÀÊý¾Ýй¶£¬µ«¸ÃÀÕË÷Èí¼þÍÅ»ïÒÑ´ÓÆä°µÍøÐ¹ÃÜÍøÕ¾ÖÐɾ³ýÁËÓйØÌõ¿î¡£CISA ºÍ FBIÖÒ¸æ³Æ£¬Rhysida µÄ´ÓÊô»ú¹¹ÊÇÕë¶Ô¸÷Ðи÷Òµ×éÖ¯ÌáÒéµÄ¶àÆð»úÓöÐÔ¹¥»÷µÄÄ»ºóºÚÊÖ£¬¶øÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿ (HHS) ÔòÒÔΪ RhysidaÓëÕë¶ÔÒ½ÁƱ£½¡×éÖ¯µÄ¹¥»÷Óйء£
https://www.bleepingcomputer.com/news/security/pennsylvania-education-union-data-breach-hit-500-000-people/
4. ÎÚ¿ËÀ¼¾ü·½³ÉΪÐÂÒ»ÂÖSignalÍøÂç´¹µö¹¥»÷µÄÖ¸±ê
3ÔÂ19ÈÕ£¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±·´Ó³Ó××飨CERT-UA£©·¢³öÖҸ棬ָ³ö½üÆÚ´æÔڸ߶ÈÕë¶ÔÐԵĹ¥»÷£¬¹¥»÷ÕßÀûÓñ»ÈëÇÖµÄSignalÕË»§Ïò¹ú·À¹¤Òµ¹«Ë¾ºÍ¹ú¶È¾ü¶Ó³ÉÔ±·¢ËͶñÒâÈí¼þ¡£ÕâЩ¹¥»÷ʼÓÚ±¾Ô£¬Í¨¹ý¼Ù×°³É»áÒé»ã±¨µÄµµ°¸½øÐУ¬µµ°¸ÖÐÔ̺¬Ò»¸öPDFºÍÒ»¸ö¿ÉÖ´ÐÐÎļþ£¬ºóÕß±»Ö¤ÊµÎªDarkTortilla¼ÓÃÜÆ÷/¼ÓÔØÆ÷£¬ÓÃÓÚ½âÃܲ¢Ö´ÐÐÔ¶³Ì½Ó¼ûľÂíDark Crystal RAT (DCRAT)¡£CERT-UAÒѽ«Õâ´Î»î¶¯ÔÚUAC-0200ϽøÐиú×Ù£¬ÕâÊÇÒ»¸ö×Ô2024Äê6ÔÂÒÔÀ´¾ÍÀûÓÃSignal½øÐÐÀàËÆ¹¥»÷µÄÍþв¼¯Èº¡£×î½üµÄ¹¥»÷ÖУ¬ÍøÂç´¹µöµö¶üÒѸüУ¬³ÁµãתÏòÓëÎÞÈË»ú¡¢µç×ÓսϵͳºÍÆäËû¾üʼ¼ÊõÓйصÄÖ÷Ì⡣ͬʱ£¬GoogleÍþвµý±¨Ó××é»ã±¨³Æ£¬¶íÂÞ˹ºÚ¿ÍÔÚÀÄÓÃSignalµÄ¡°Á´½ÓÉ豸¡±Ö°ÄÜÀ´Î´¾ÊÚȨ½Ó¼û¸ÐÐËÖµÄÕÊ»§¡£Òò¶ø£¬CERT-UA½¨ÒéSignalÓû§¹Ø¹Ø¸½¼þµÄ×Ô¶¯ÏÂÔØ£¬¶ÔËùÓÐÐÂÎÅά³ÖÉóÉ÷£¬²¢¶¨ÆÚ²é³Á´½ÓÉ豸ÁÐ±í¡£´Ë±í£¬Óû§»¹Ó¦½«Í¨Ñ¶ÀûÓ÷¨Ê½¸üе½×îа汾£¬²¢ÆôÓÃË«³É·ÖÉí·ÝÑéÖ¤£¬ÒÔ¼ÓÇ¿ÕÊ»§±£»¤¡£
https://www.bleepingcomputer.com/news/security/ukrainian-military-targeted-in-new-signal-spear-phishing-attacks/
5. Arcane¶ñÒâÈí¼þÇÔÈ¡´óÁ¿Óû§Êý¾Ý£¬´«²¼·½Ê½²»ÐÝÑݱä
3ÔÂ19ÈÕ£¬Ð·¢ÏÖµÄArcaneÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þÔÚÇÔÈ¡´óÁ¿Óû§Êý¾Ý£¬Ô̺¬VPNÕÊ»§Í´´¦¡¢ÓÎÏ·¿Í»§¶Ë¡¢ÐÂÎÅÀûÓ÷¨Ê½ºÍÍøÂçä¯ÀÀÆ÷ÖеÄÐÅÏ¢¡£¸Ã¶ñÒâÈí¼þ»î¶¯Ê¼ÓÚ2024Äê11Ô£¬ÖØÒªÏ°È¾¶íÂÞ˹¡¢°×¶íÂÞ˹ºÍ¹þÈø¿Ë˹̹µÄÓû§¡£Arcaneͨ¹ýYouTubeÊÓÆµÐû´«ÓÎÏ·Îè±×ºÍÆÆ½â£¬ÓÕÆÓû§ÏÂÔØÊÜÃÜÂë±£»¤µÄµµ°¸£¬ÆäÖаü·Ñ½âÏýµÄ¾ç±¾ºÍ¶ñÒâ¿ÉÖ´ÐÐÎļþ¡£¸Ã¶ñÒâÈí¼þ»¹»áΪWindows DefenderµÄSmartScreen¹ýÂËÆ÷Ôö³¤ÅųýÏî»òÆëÈ«¹Ø¹ØËü¡£ArcaneµÄ¿í·ºÊý¾ÝÇÔÈ¡ÐÐΪʹÆäÔÚ¶à¶àµÄÐÅÏ¢ÇÔÈ¡Èí¼þÖÐÍÑÓ±¶ø³ö£¬ËüÄܹ»ÇÔȡӲ¼þºÍÈí¼þ¾ßÌåÐÅÏ¢¡¢ÀûÓ÷¨Ê½ÕÊ»§Êý¾Ý¡¢ÅäÖÃÎļþÒÔ¼°ÍøÂçä¯ÀÀÆ÷ÖеĵǼÐÅÏ¢¡¢ÃÜÂëºÍcookie¡£´Ë±í£¬Arcane»¹Äܹ»²¶»ñÆÁÄ»½ØÍ¼ºÍÒѱ£ÁôµÄWi-FiÍøÂçÃÜÂ롣ϰȾArcaneÐÅÏ¢ÇÔÈ¡·¨Ê½ºó¹û²»Ê¤ÉèÏ룬Óû§Ó¦Ê±¿Ì·þâßÏÂÔØÎ´ÊðÃûµÄµÁ°æºÍÎè±×¹¤¾ßµÄ·çÏÕ£¬²¢ÆëȫԤ·ÀʹÓÃÕâЩ¹¤¾ß¡£
https://www.bleepingcomputer.com/news/security/new-arcane-infostealer-infects-youtube-discord-users-via-game-cheats/
6. ClearFakeÀûÓÃreCAPTCHAºÍTurnstile·Ö·¢¶ñÒâÈí¼þ
3ÔÂ19ÈÕ£¬ClearFakeÊÇÒ»¸öÍþв»î¶¯¼¯Èº£¬×Ô2023Äê7Ô³õ´ÎÆØ¹âÒÔÀ´£¬Ò»ÏòʹÓÃÐéαµÄÍøÂçä¯ÀÀÆ÷¸üС¢reCAPTCHA»òCloudflare TurnstileÑéÖ¤µÅ×Õ¶ü·Ö·¢Lumma StealerºÍVidar StealerµÈ¶ñÒâÈí¼þ¡£¸Ã»î¶¯Ñ¡È¡EtherHiding¼¼ÊõºÍClickFixÕ½Êõ£¬ÀûÓñҰ²ÖÇÄÜÁ´ºÏÔ¼»ñÈ¡ÓÐÐ§ÔØºÉ£¬Ê¹¹¥»÷Á´¸ü¾ßµ¯ÐÔ¡£×îа汾ÒýÈëWeb3Ö°ÄÜÀ´µÖ¿¹·ÖÎö²¢¼ÓÃÜHTML´úÂë¡£½ØÖÁ2024Äê5Ô£¬ClearFake¹¥»÷ÒÑϰȾ³¬¹ý9,300¸öÍøÕ¾£¬2024Äê7ÔÂÔ¼ÓÐ200,000Ãû¶ÀÁ¢Óû§¿ÉÄÜÊܵ½¹¥»÷¡£´Ë±í£¬³¬¹ý100¼ÒÆû³µ¾ÏúÉÌÍøÕ¾Êܵ½ClickFixµö¶ü¹¥»÷£¬µ¼ÖÂSectopRAT¶ñÒâÈí¼þ²¿Êð¡£°²È«×êÑÐÔ±Ö¸³ö£¬ÕâЩϰȾÍùÍù²úÉúÔÚµÚÈý·½·þÎñÉÏ£¬ÈçLES AutomotiveµÄÊÓÆµ·þÎñ¡£ClearFake»¹Ó뼸ÆðÍøÂç´¹µö»î¶¯Óйأ¬Ö¼ÔÚÍÆ¹ã¶ñÒâÈí¼þ¼Ò×å²¢½øÐÐÆ¾Ö¤ÍøÂç¡£Ëæ×ÅÉç»á¹¤³Ì»î¶¯±äµÃÔ½À´Ô½¸´ÔÓ£¬×éÖ¯ºÍÆóÒµ±ØÐëÖ´ÐÐ׳´óµÄÉí·ÝÑéÖ¤ºÍ½Ó¼û½ÚÔì»úÔìÀ´Õмܹ¥»÷¡£
https://thehackernews.com/2025/03/clearfake-infects-9300-sites-uses-fake.html


¾©¹«Íø°²±¸11010802024551ºÅ