SantaStealer¶ñÒâÈí¼þÆØ¹â£ºÄÚ´æÔËÐбܼì²â´æ·ì϶
°ä²¼¹¦·ò 2025-12-171. SantaStealer¶ñÒâÈí¼þÆØ¹â£ºÄÚ´æÔËÐбܼì²â´æ·ì϶
12ÔÂ15ÈÕ£¬½üÈÕ£¬Ò»ÖÖÃûΪSantaStealerµÄÐÂÐͶñÒâÈí¼þ¼´·þÎñ£¨MaaS£©ÐÅÏ¢ÇÔÈ¡·¨Ê½ÔÚTelegram¼°ºÚ¿ÍÂÛ̳ÉϹ«¿ªÐû´«¡£¸Ã·¨Ê½ÓɶíÓ↑·¢Õß´òÔ죬»ù´¡¶©ÔļÛ175ÃÀÔª/Ô£¬¸ß¼¶°æ300ÃÀÔª/Ô£¬Ðû³ÆÍ¨¹ýÄÚ´æÔËÐжã±Ü»ùÓÚÎļþµÄ¼ì²â»úÔ졣Ȼ¶ø£¬¾ÝRapid7°²È«ÍŶӷÖÎö£¬ÆäÏÖʵÑù±¾Ô¶Î´´ïµ½¡°ÎÞ·¨¼ì²â¡±µÄÐû³Æ³ÉЧ£¬ÇÒ´æÔÚ²Ù×÷°²È«È±µã£¬Ñù±¾Ð¹Â¶Ê±Ô̺¬Î´¼ÓÃÜ×Ö·û´®ºÍ·ûºÅÃû³Æ£¬Â¶³ö¿ª·¢¹ý³ÌÖеÄÊè©¡£SantaStealerʵΪBluelineStealerÏîÖ÷ÕųÁ°ü×°£¬´òËãÄêµ×ÕýʽÉÏÏß¡£Ëü¼¯³É14¸ö¶ÀÁ¢Ï̵߳ÄÊý¾ÝÍøÂçÄ£¿é£¬¿ÉÇÔÈ¡ä¯ÀÀÆ÷ÃÜÂë¡¢Cookie¡¢ÐÅÓþ¿¨ÐÅÏ¢¡¢Telegram/Discord/SteamÊý¾Ý¡¢¼ÓÃÜÇ®±ÒÇ®°üÄÚÈݼ°Îĵµ£¬²¢½ØÈ¡×ÀÃæ½ØÍ¼¡£Êý¾Ý¾ÄÚ´æ¹éµµÎªZIPÎļþºó£¬Í¨¹ý6767¶Ë¿Ú·Ö10MBµ¥Ôª´«ÊäÖÁÔ¤ÉèC2¶Ëµã¡£¸Ã¶ñÒâÈí¼þ»¹ÊÔÍ¼ÈÆ¹ýChrome 2024Äê7ÔÂÍÆ³öµÄÀûÓð󶨼ÓÃܱ£»¤£¬µ«Òѱ»¶à¿îÐÅÏ¢ÇÔÈ¡·¨Ê½Í»ÆÆ¡£Æä½ÚÔìÃæ°åÖ§³ÖÓû§ÅäÖÃÖ¸±êÁìÓò£¬´ÓÈ«Á¿Êý¾ÝÇÔÈ¡µ½¾«¼òÓÐÐ§ÔØºÉ£¬²¢ÔÊÐíÅųý¶ÀÁªÌ嵨Óòϵͳ¼°ÑÓ³¤Ö´ÐÐÒԹƻóÊܺ¦Õß¡£
https://www.bleepingcomputer.com/news/security/new-santastealer-malware-steals-data-from-browsers-crypto-wallets/
2. PornHub»áÔ±Êý¾ÝÔâShinyHuntersÀÕË÷
12ÔÂ15ÈÕ£¬³ÉÈËÊÓÆµÆ½Ì¨PornHub½üÈÕÒòµÚÈý·½Êý¾Ý·ÖÎöÉÌMixpanelÊý¾Ýй¶ÊÂÎñÏÝÈëÀÕË÷Σ»ú¡£¾Ý±¨Â·£¬ShinyHuntersÀÕË÷ÍÅ»ïÐû³ÆÇÔÈ¡ÁËPornHub Premium¸ß¼¶»áÔ±µÄ94GBº¹ÇàÊý¾Ý£¬Ô̺¬2.01ÒÚÌõËÑË÷¡¢ÅÔ¹Û¼°ÏÂÔØ¼Í¼£¬²¢Í¨¹ýÀÕË÷ÓʼþÍþв²»Ö§¸¶Êê½ð½«¹«¿ªÊý¾Ý¡£MixpanelÓÚ2025Äê11ÔÂ8ÈÕÔâ¶ÌÐÅ´¹µö¹¥»÷µ¼ÖÂϵͳÈëÇÖ£¬Æä¿Í»§Êý¾Ýй¶²¨¼°PornHub¡£Ö»¹ÜPornHubÇ¿µ÷×Ô2021ÄêÆðÒÑÖÕÖ¹ÓëMixpanelºÏ×÷£¬Ð¹Â¶Êý¾ÝΪ2021Äê»ò¸üÔçµÄº¹Çà·ÖÎö¼Í¼£¬ÇÒÓû§ÃÜÂë¡¢Ö§¸¶¼°²ÆÕþÐÅϢδÊÜÓ°Ï죬µ«¸ß¼¶»áÔ±µÄÃô¸Ð»î¶¯¼Í¼ÈÔ±»ÆØ¹â¡£Ð¹Â¶Êý¾ÝÔ̺¬»áÔ±µç×ÓÓʼþµØÖ·¡¢ÊÓÆµURL¡¢¹Ø¼ü´Ê¡¢»î¶¯¹¦·ò¼°µØÀíµØÎ»µÈ£¬²¿ÃÅÑù±¾ÏÔʾÉõÖÁÔ̺¬¶©ÔÄÕßÊÇ·ñÅÔ¹Û/ÏÂÔØÊÓÆµ»òä¯ÀÀƵ·µÄ¾ßÌåÐÐΪ¡£ShinyHunters×÷ΪĻºóºÚÊÖ£¬²»½öÏòPornHub·¢ËÍÀÕË÷Óʼþ£¬»¹¹«¿ªÖ¤ÊµÕâ´Î¹¥»÷£¬²¢¹ØÁª¶àÆð³Á´óÊý¾Ýй¶ÊÂÎñ¡£
https://www.bleepingcomputer.com/news/security/pornhub-extorted-after-hackers-steal-premium-member-activity-data/
3. Frogblight°²×¿Ä¾Âí¼Ù×°µ±¾ÖÍøÕ¾ÇÔÊØÐÅÏ¢
12ÔÂ15ÈÕ£¬½üÆÚ£¬Ò»¿îÃûΪ¡°Frogblight¡±µÄ¸´ÔÓ°²×¿ÒøÐÐľÂíÔÚÍÁ¶úÆäÒý·¢³Á´ó°²È«Íþв£¬Æäͨ¹ý¾«ÐÄÉè¼ÆµÄÉç»á¹¤³Ì¼¿Á©ÇÔÈ¡ÒøÐÐÆ¾Ö¤ÓëÓ×ÎÒÊý¾Ý£¬²¢Õ¹Ê¾³ö³ÖÐø½ø»¯Ìص㡣¸ÃľÂí×î³õ¼Ù×°³ÉÍÁ¶úÆä¹Ù·½µ±¾ÖÃÅ»§ÀûÓã¬Ðû³Æ¿É½Ó¼û·¨Í¥°¸¼þÎļþ£¬ºóÑݱäΪ·ÂðChromeµÈÊ¢ÐÐÀûÓã¬Í¨¹ý´¹µö¶ÌÐÅ´«²¼£¬Êܺ¦ÕßÊÕµ½Ðéα·¨Í¥°¸¼þ֪ͨ¶ÌÐÅ£¬µã»÷Á´½Óºó±»µ¼Ïò¶ñÒâÍøÕ¾²¢ÓÕµ¼ÏÂÔØÀûÓá£×°Öúó£¬Frogblight»áÒªÇó¶ÁÈ¡¶ÌÐÅ¡¢½Ó¼û´æ´¢¿Õ¼ä¼°»ñÈ¡É豸ÐÅÏ¢µÈÃô¸ÐȨÏÞ¡£Æô¶¯Ê±£¬Æäͨ¹ýǶÈëʽä¯ÀÀÆ÷ÊÓͼÏÔÊ¾ÕæÊµµ±¾ÖÍøÒ³Ôì×÷¡°ºÏ·¨¼ÙÏó¡±£¬Í¬Ê±ÔÚºó¶Ü¼à¿ØÓû§²Ù×÷¡£¸ÃľÂí¾ß±¸Ë«³ÁÖ°ÄÜ£º¼È×÷ÎªÒøÐÐľÂíÇÔÈ¡ÔÚÏßÒøÐеǼÐÅÏ¢£¬Ó־߱¸¼äµýÈí¼þ¸öÐÔ£¬¼à¿Ø¶ÌÐÅ¡¢¸ú×ÙÒÑ×°ÖÃÀûÓá¢É¨ÃèÎļþϵͳ£¬ÉõÖÁ¿ÉÏò±í·¢ËÍËÁÒâÎı¾ÐÂÎÅ¡£¼¼Êõ²ãÃæ£¬Frogblightͨ¹ýWebView×¢ÈëJavaScript´úÂë²¶»ñÓû§ÊäÈ룬Óë½ÚÔì·þÎñÆ÷ͨѶѡȡRetrofit¿âµÄREST APIŲÓ㬺óÆÚ±äÖÖתÏòWebSocketÏνÓÒÔ¼ÓÇ¿Òñ±ÎÐÔ¡£
https://cybersecuritynews.com/new-android-malware-frogblight-mimics-as-official-government-websites/
4. ίÄÚÈðÀ¹ú¶ÈʯÓ͹«Ë¾PDVSAÔâÍøÂç¹¥»÷
12ÔÂ16ÈÕ£¬½üÈÕ£¬Î¯ÄÚÈðÀ¹ú¶ÈʯÓ͹«Ë¾£¨PDVSA£©Ôâ·êÍøÂç¹¥»÷µ¼Ö³ö¿ÚÒµÎñ¶ÌÔÝÖжϣ¬µ«¸Ã¹«Ë¾Ç¿µ÷Õâ´ÎÊÂÎñ½öÓ°Ï첿ÃÅÐÐÕþÖÎÀíϵͳ£¬Î´²¨¼°ÈÕ³£ÔËÓª¡£PDVSAÔÚTelegramÉêÃ÷ÖÐÖ¸³ö£¬°²È«ºÍ̸³É¹¦×èÖ¹Á˹©¸øÖжϣ¬²¢½«¸ÃÊÂÎñ¶¨ÐÔΪ¡°ÓëÃÀ¹ṵ́ͼ´Û¶áίÄÚÈðÀʯÓÍÓйصÄÇÖÂÔÐÐΪ¡±£¬³Æ¡°¶ÏÈ»»Ø¾ø±í¹úÈ¨ÊÆ²ß¶¯µÄ¶ñ¶ñϰ¾¶¡±¡£Î¯ÄÚÈðÀµ±¾Ö½øÒ»²½½«ÊÂÎñÉÏÉýΪ¶Ô¡°Ö÷ȨÄÜÔ´¿ª·¢È¨¡±µÄ¹¥»÷£¬Ö±Ö¸ÃÀ¹úÓ뼫¶ËÈ¨ÊÆÍŽá·ÛËé¹ú¶È²»±ä¡£ÎªÓ¦¶Ô·çÏÕ£¬PDVSAÒªÇóÔ±¹¤¹Ø¹ØµçÄÔ¡¢¶Ï¿ª±í²¿É豸¡¢½ûÓÃWiFi¼°ÐÇÁ´Ïνӣ¬²¢Ç¿»¯ÉèÊ©°²±£¡£Åí²©ÉçÔ®ÒýÄÚ²¿±¸Íü¼³Æ£¬×ÔÖÜÈÕÒÔÀ´°²±£´ëÊ©ÒÑÈ«ÃæÉý¼¶¡£¹«Ë¾ÖÜÒ»°ä²¼ÉêÃ÷³ÆÒÑ´ì°Ü¡°·ÛËḛ́ͼ¡±£¬Ê¯ÓͲúÁ¿Î´ÊÜÓ°Ï졣Ȼ¶ø£¬Â·Í¸ÉçÐÂÎÅԴй©£¬Õâ´Î¹¥»÷ʵΪÀÕË÷Èí¼þ¹¥»÷£¬·´²¡¶¾½¨¸´¹¤×÷µ¼ÖÂÖÎÀíϵͳ̱»¾£¬»õÎï½»¸¶Åö±Ú¡£ÊÂÎñ²úÉúÔÚÃÀί¹ØÏµ³ÖÐøÑÏÖØ²¼¾°Ï¡£´Ëǰ£¬ÃÀ¹ú¿ÛѺһËÒÔØÓÐίÄÚÈðÀÔÓ͵ÄÊÜÔì²ÃÓÍÂÖ£¬ÕâÊÇ×Ô2019ÄêÃÀ¹ú²ÆÕþ²¿¶ÔPDVSAÖ´ÐÐÔì²ÃÒÔÀ´³õ´Î¿ÛѺÓÍÂÖ¡£
https://securityaffairs.com/185755/security/a-cyber-attack-hit-petroleos-de-venezuela-pdvsa-disrupting-export-operations.html
5. ºÚ¿ÍÀûÓÃнü½¨¸´µÄFortinetÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶
12ÔÂ16ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾Arctic Wolf¼à²âµ½ºÚ¿ÍÕýÀûÓÃFortinetÆì϶à¸ö²úÆ·µÄÑϳÁ·ì϶·¸·¨½Ó¼ûÖÎÀíÔ¹ØË»§²¢ÇÔȡϵͳÅäÖÃÎļþ¡£Õâ´Î¶³öµÄÁ½¸ö¸ßΣ·ì϶±ðÀëΪCVE-2025-59718£¨Ó°ÏìFortiOS¡¢FortiProxy¡¢FortiSwitchManager£©ºÍCVE-2025-59719£¨Ó°ÏìFortiWeb£©£¬¾ùÔ´ÓÚSAMLÐÂÎżÓÃÜÊðÃûÑéÖ¤²»µ±£¬¹¥»÷Õ߿ɻú¹Ø¶ñÒâSAML¶ÏÑÔÈÆ¹ýÉí·ÝÑéÖ¤£¬ÔÚδÊÚȨÇé¿öϵǼÖÎÀíÔ¹ØË»§¡£·ì϶´¥·¢ÐèÉ豸ÆôÓÃFortiCloudµ¥µãµÇ¼£¨SSO£©Ö°ÄÜ£¬¸ÃÖ°ÄÜËä·ÇĬÈÏÉèÖ㬵«Í¨¹ýFortiCare×¢²áÉ豸ʱ»á×Ô¶¯¼¤»î£¬³ý·ÇÊÖ¶¯½ûÓá£×Ô12ÔÂ12ÈÕÆð£¬ºÚ¿Íͨ¹ýÓëThe Constant Company¡¢BL Networks¡¢Kaopu Cloud HK¹ØÁªµÄIPµØÖ·ÌáÒé¹¥»÷£¬ÀûÓöñÒâSSO»ñÈ¡ÖÎÀíԱȨÏÞºó£¬Í¨¹ýWebÖÎÀí½çÃæÏÂÔØÏµÍ³ÅäÖÃÎļþ¡£ÕâЩÎļþÔ̺¬ÍøÂç²¼¾Ö¡¢»¥ÁªÍø·þÎñ¶Ë¿Ú¡¢·À»ðǽսÊõ¡¢Â·ÓÉ±í¼°Ç±ÔÚÃÜÂë¹þÏ£µÈÃô¸ÐÐÅÏ¢£¬¿ÉÄÜÐ¹Â¶ÍøÂç¼Ü¹¹Ï¸½Ú£¬ÎªºóÐø¹¥»÷Ìṩ֧³Ö¡£·ì϶ӰÏìFortiOS¡¢FortiWebµÈ¶à¸ö°æ±¾£¬Fortinet½¨ÒéÖÎÀíÔ±µ±¼´½ûÓÃFortiCloud SSOµÇ¼ְÄÜ£¬²¢Éý¼¶ÖÁ½¨¸´°æ±¾¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-newly-patched-fortinet-auth-bypass-flaws/
6. ÐÂÐÍAndroid¶ñÒâÈí¼þCellikÏÖÉíµØÏÂÂÛ̳
12ÔÂ16ÈÕ£¬Òƶ¯°²È«¹«Ë¾iVerifyÔÚµØÏÂÍøÂç·¸×ïÂÛ̳·¢ÏÖÒ»¿îÃûΪCellikµÄÐÂÐÍAndroid¶ñÒâÈí¼þ¼´·þÎñ£¨MaaS£©ÔÚ¹«¿ªÐû´«¡£¸ÃÈí¼þÒÔÿÔÂ150ÃÀÔª»òƽÉú900ÃÀÔªµÄ¼ÛÖµÏúÊÛ£¬ÌṩÁËÒ»Ì×׳´óµÄÖ°ÄÜ×éºÏ£¬×îÒýÈËÖõÖ÷ÕÅÊÇÆäAPK¹¹½¨Æ÷¿É¼¯³ÉGoogle PlayÉ̵꣬¹¥»÷ÕßÄÜÖ±½Ó´Ó¹Ù·½ÀûÓÃÉ̵êÑ¡ÔñËÁÒâÀûÓ㬴´½¨±í±í¿ÉÐŵÄľÂí°æ±¾£¬Í¬Ê±±£ÁôÔÀûÓõĽçÃæºÍÖ°ÄÜ£¬´Ó¶øµ¢¸é¶ñÒâÈí¼þµÄÂñ·üÆÚ¡£Cellik¾ß±¸ÊµÊ±ÆÁÄ»²¶»ñ¡¢Í¨ÖªÀ¹½Ø¡¢Îļþϵͳä¯ÀÀ¡¢Êý¾ÝÇÔÈ¡¡¢Ô¶³Ì²Á³ý¼°¼ÓÃÜͨ·ͨѶµÈÖ÷ÌâÖ°ÄÜ¡£Æä°µ²Øä¯ÀÀÆ÷ģʽÔÊÐí¹¥»÷ÕßÀûÓÃÊܺ¦ÕßÉ豸´æ´¢µÄcookie½Ó¼ûÍøÕ¾£»ÀûÓÃ×¢ÈëϵͳÔò¿ÉÔÚËÁÒâÀûÓÃÖеþ¼ÓÐéαµÇÂ¼Ò³Ãæ»ò×¢Èë¶ñÒâ´úÂ룬ÇÔÈ¡ÕË»§Í´´¦£»¶øÏòÒÑ×°ÖÃÀûÓÃ×¢ÈëÓÐÐ§ÔØºÉµÄÖ°ÄÜ£¬¸üʹϰȾԴÄÑÒÔ×·Ò䣬³Ö¾ÃÊÜÐÅÀµµÄÀûÓÿÉÄܺöÈ»±äΪµØÆ¦Èí¼þ¡£Âô¼ÒÐû³Æ£¬Í¨¹ý½«¶ñÒâÔØºÉ°ü¹üÔÚÊÜÐÅÀµµÄÀûÓ÷¨Ê½ÖУ¬Cellik¿ÉÈÆ¹ýGoogle Play ProtectµÄ¼ì²â»úÔì¡£
https://www.bleepingcomputer.com/news/security/cellik-android-malware-builds-malicious-versions-from-google-play-apps/


¾©¹«Íø°²±¸11010802024551ºÅ