ÐÂÉ繤¹¥»÷½èÓû§Ï°¹ß´«²¼DarkGate¶ñÒâÈí¼þ

°ä²¼¹¦·ò 2025-12-19

1. ÐÂÉ繤¹¥»÷½èÓû§Ï°¹ß´«²¼DarkGate¶ñÒâÈí¼þ


12ÔÂ17ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±½üÈÕÅû¶һÖÖÃûΪClickFixµÄÐÂÐÍÉç»á¹¤³Ì¹¥»÷ÊÖ·¨£¬¸Ã¹¥»÷ÀûÓÃÓû§¶Ô³£¼û¼¼ÊõÌáÐѵÄÐÅÀµÉúÀí£¬ÓÕÆ­ÆäÊÖ¶¯Ö´ÐжñÒâºÅÁîÒÔ´«²¼DarkGateÔ¶³Ì½Ó¼û¶ñÒâÈí¼þ¡£¹¥»÷ʼÓÚÐéαÌáÐÑ£¬Óû§±»Îóµ¼ÒÔΪ¶Ìȱ"Word Online"ä¯ÀÀÆ÷À©´ó£¬µ±µã»÷"ÈôºÎ½¨¸´"°´Å¥Ê±£¬ÍøÕ¾»áͨ¹ýJavaScript½«¶ñÒâPowerShellºÅÁî°ÂÃØ¸´Ôìµ½Óû§¼ôÌù°å¡£Ëæºó¹¥»÷ÕßÊèµ¼Óû§°´ÏÂWindows+R´ò¿ªÔËÐжԻ°¿ò£¬²¢Í¨¹ýCtrl+VÕ³Ìù¸´ÔìµÄÎı¾Ö´ÐкÅÁî¡£ÓÉÓڸòÙ×÷ÓÉÓû§×Ô¶¯´¥·¢£¬°²È«»úÔì¿ÉÄܲ»»á½«Æä¼ø±ðΪÍþв¡£¹¥»÷Á´½øÒ»²½·¢Õ¹£ºÖ´ÐкóµÄPowerShell¾ç±¾»áÏνÓlinktoxic34.com·þÎñÆ÷ÏÂÔØnC.htaÎļþ£¬¸ÃÎļþ±£ÁôÔÚCÅ̹«¹²Ä¿Â¼¡£Í¨¹ý¶à²ãbase64±àÂëºÍ·´Ïòº¯Êý»ìºÏ£¬ºÚ¿Í³É¹¦¶ã±Ü¼ì²â¡£¾ç±¾ÔËÐкó»á×Ô¶¯´´½¨CÅÌĿ¼£¬²¿ÊðAutoIt¿ÉÖ´ÐÐÎļþºÍscript.a3x¾ç±¾£¬ÔÚÎÞÐèÓû§½»»¥µÄÇé¿öϳÖÐø¹¥»÷Á÷³Ì¡£DarkGate¶ñÒâÈí¼þÒ»µ©ÔËÐУ¬½«³ÉÁ¢ÓƾÃÐÔ»úÔìÈ·±£³ÁÆôºóÈÔ´æÔÚ£¬Í¬Ê±ÇÔÈ¡Óû§Ãô¸ÐÐÅÏ¢²¢±íй£¬Ê¹ÓÃDES¼ÓÃܰµ²Ø¶ñÒâÎļþ£¬µ¼ÖÂϵͳ³öÏÖ¿¨¶Ù¡¢±ÀÀ£¡¢Î´¾­ÊÚȨ¹¤¾ßÀ¸¼°´óÁ¿µ¯³ö¸æ°×µÈÖ¢×´¡£


http://hackread.com/clickfix-attack-fake-browser-install-darkgate-malware/


2. ǧÍò¼¶ChromeÀ©´ó±»ÆØÇÔÈ¡AI¶Ô»°Êý¾Ý


12ÔÂ17ÈÕ£¬ÍøÂ簲ȫ¹«Ë¾Koi×êÑз¢ÏÖ£¬Ò»¿îÃûΪUrban VPN ProxyµÄChromeÀ©´ó·¨Ê½Õý°ÂÃØÇÔÈ¡Óû§ÓëAI̸Ìì»úеÈ˵ĶԻ°¼Í¼£¬Éæ¼°ChatGPT¡¢Claude¡¢GeminiµÈÖÁÉÙÊ®¸öÖ÷Á÷ƽ̨¡£¸ÃÀ©´óÕ¼Óг¬600ÍòÓû§£¬ÆÀ·ÖΪ4.7ÐÇ£¬²¢»ñµÃGoogle"¾«Ñ¡"»ÕÕÂÈÏÖ¤£¬×Ô³ÆÌṩÃâ·ÑVPN·þÎñÒÔ¼ÓÇ¿ÒþÖÔ°²È«£¬ÊµÔò°µ²ØÊý¾ÝÍøÂçÄ£¿é¡£×êÑÐÈËÔ±·¢ÏÖ£¬À©´ó·¨Ê½Í¨¹ýÓ²±àÂëÅäÖñê־ĬÈÏÆôÓÃÊý¾ÝÍøÂçÖ°ÄÜ£¬Óû§ÎÞ·¨Í¨¹ýÉèÖýûÓã¬Ö»ÄÜͨ¹ýÐ¶ÔØÍ˳ö¡£¸ÃÖ°ÄÜÓÚ2025Äê7ÔÂ9ÈÕ°ä²¼µÄ5.5.0°æ±¾ÖÐÒýÈ룬´Ëǰ°æ±¾ÎÞ´ËÐÐΪ¡£ÓÉÓÚChromeÀ©´ó×Ô¶¯¸üлúÔ죬ÒÑ×°ÖÃÓû§»áÔÚÎÞÃ÷ȷ֪ͨµÄÇé¿öÏ»ñµÃÐÂÖ°ÄÜ¡£¸üÁîÈËÕ𾪵ÄÊÇ£¬Í³Ò»¿¯ÐÐÉÌÍÆ³öµÄÆäËûÆß¿îÀ©´ó·¨Ê½¾ùÔ̺¬Ò»ÑùµÄAIÊý¾Ý²É¼¯Ö°ÄÜ£¬×ÜÓû§Êý´ï800Íò¡£ÕâЩÀ©´óº­¸ÇVPN¡¢¸æ°×À¹½ØÆ÷¡¢°²È«¹¤¾ßµÈ¶à¸öÀà±ð£¬ÇÒÎÞÊý´øÓÐGoogle»òMicrosoftµÄ"¾«Ñ¡"»ÕÕ£¬Åúעƽ̨ÉóºË»úÔì´æÔÚÑϳÁ·ì϶¡£


https://cybernews.com/security/ai-chat-vpn-extension-spying/


3. ϤÄá´óѧÔâºÚ¿ÍÈëÇÖÖ³¬2.7ÍòÈËÊý¾Ýй¶


12ÔÂ18ÈÕ£¬½üÈÕ£¬°Ä´óÀûÑÇϤÄá´óѧÔâ·êÑϳÁÍøÂ簲ȫÊÂÎñ£¬ºÚ¿ÍÈëÇÔìäÔÚÏß´úÂë¿â²¢ÇÔÈ¡Ô̺¬½ÌÈËÔ±¹¤¡¢Ñ§Éú¼°Ð£ÓÑÓ×ÎÒÐÅÏ¢µÄÎļþ¡£¸ÃÊÂÎñÓÚÉÏÖܱ»¼ì²âµ½£¬´óѧµ±¼´¹Ø¹ØÎ´¾­ÊÚȨµÄ½Ó¼ûͨ·£¬²¢Í¬²½´«µÝÐÂÄÏÍþ¶ûÊ¿ÖÝÒþÖÔרԱ¡¢°Ä´óÀûÑÇÍøÂ簲ȫÖÐÐļ°½ÌÓý¼à¹Ü»ú¹¹¡£¾­ºË²é£¬Õâ´ÎÐ¹Â¶Éæ¼°³¬¹ý27,000ÃûÈËÔ±£¬¾ßÌåÔ̺¬£º½ØÖÁ2018Äê9ÔÂ4ÈÕµÄ10,000ÃûÏÖÔ±¹¤¼°´ÓÊô»ú¹¹ÈËÔ±¡¢12,500ÃûǰԱ¹¤¼°´ÓÊôÈËÔ±¡¢Ô¼2010ÄêÖÁ2019Äê¼äµÄ5,000ÃûѧÉúºÍУÓÑ£¬ÒÔ¼°6ÃûÖ§³ÖÕß¡£Ð¹Â¶Êý¾Ýº­¸ÇÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢¼Òͥסַ¡¢¹¤×÷ÏêÇéµÈÃô¸ÐÐÅÏ¢¡£´óѧǿµ÷£¬ËäÈ·ÈÏÊý¾ÝÒѱ»½Ó¼ûÏÂÔØ£¬µ«Î´·¢ÏÖ¹«¿ª´«²¼»òÀÄÓÃÖ¤¾Ý¡£×÷Ϊ°Ä´óÀûÑǹæÄ£×î´óµÄ¹«Á¢´óѧ֮һ£¬Ï¤Äá´óѧռÓÐ7ÍòÃûѧÉúºÍ1ÍòÃû½ÌÈËÔ±¹¤¡£Ä¿Ç°£¬¸ÃУÒÑÆô¶¯¸öÐÔ»¯Í¨Öª·¨Ê½£¬Ô¤¼ÆÏÂÔÂʵÏÖ¶ÔÊÜÓ°ÏìÈËÔ±µÄ·î¸æ¹¤×÷£¬²¢ÉèÁ¢×¨ÃÅÖ§³Ö·þÎñÌṩÕ÷ѯÔöÔ®£¬Í¬Ê±°ä²¼¶¯Ì¬¸üеij£¼ûÎÊÌâ½â´ðÒ³Ãæ¡£¹Ù·½½¨ÒéÊÜÓ°ÏìÕß¾¯ÌèδÊÚȨͨѶ¡¢ÊµÊ±Åú¸ÄÕ˺ÅÃÜÂë²¢ÆôÓöà³É·ÖÈÏÖ¤¡£


https://www.bleepingcomputer.com/news/security/university-of-sydney-suffers-data-breach-exposing-student-and-staff-info/


4. ClopÍÅ»ï¶Ô×¼Gladinet CentreStack·þÎñÆ÷Ö´ÐÐÊý¾ÝÇÔÈ¡


12ÔÂ18ÈÕ£¬½üÆÚ£¬ClopÀÕË÷Èí¼þÍÅ»ïÕýÕë¶Ô¶³öÓÚ»¥ÁªÍøµÄGladinet CentreStackÎļþ·þÎñÆ÷ÌáÒéÐÂÒ»ÂÖÊý¾ÝÇÔÈ¡¹¥»÷¡£¸Ã·þÎñÆ÷ÔÊÐíÆóҵͨ¹ýWebä¯ÀÀÆ÷¡¢Òƶ¯ÀûÓûòÓ³ÉäÇý¶¯Æ÷°²È«¹²Ïí±¾µØÎļþ£¬ÎÞÐèVPN£¬Òѱ»49¹úÊýǧ¼ÒÆóҵѡȡ¡£×Ô4ÔÂÆð£¬GladinetËäÒѰ䲼°²È«¸üн¨¸´¶à¸ö±»ÀûÓ÷ì϶£¬µ«ClopÈÔͨ¹ýɨÃè²¢ÈëÇÖδÊܱ£»¤µÄCentreStack·þÎñÆ÷Ö´Ðй¥»÷£¬ÔÚÊÜϰȾ·þÎñÆ÷ÉÏÁôÏÂÀÕË÷ÐÅ¡£Ä¿Ç°£¬¹¥»÷ÕßÀûÓõľßÌå·ì϶ÉÐδÃ÷È·£¬¿ÉÄÜÊÇÁãÈÕ·ì϶»òδʵʱ½¨¸´µÄÒÑÖª·ì϶¡£Íþвµý±¨»ú¹¹Curated IntelÅû¶£¬ÖÁÉÙ200¸öÔËÐÓ×°CentreStack-Login¡±HTTPÒªÇóµÄIPµØÖ·ÒѳÉΪDZÔÚÖ¸±ê¡£ClopµÄ¹¥»÷ģʽһÁ¬Æäº¹ÇàÕ½Êõ£¬ÏÈÇÔÈ¡Ãô¸ÐÊý¾Ý£¬ÔÙͨ¹ý°µÍøÐ¹Â¶ÍøÕ¾¼°Torrent°ä²¼£¬ÒÔ´ËÀÕË÷Êܺ¦Õß¡£


https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-gladinet-centrestack-servers-for-extortion/


5. GlobalProtectÓëCisco SSL VPNÔâ´ó¹æÄ£Æ¾Ö¤Ì½²â


12ÔÂ18ÈÕ£¬½üÆÚ£¬Ò»³¡Õë¶Ô¶à¸öVPNƽ̨µÄ×Ô¶¯»¯Æ¾Ö¤¹¥»÷»î¶¯Òý·¢¹Ø×¢¡£Íþв¼à¿ØÆ½Ì¨GreyNoiseÓÚ12ÔÂ11Èչ۲⵽£¬Õë¶ÔPalo Alto Networks GlobalProtectÃÅ»§µÄµÇ¼³¢ÊÔÔÚ16Ó×ʱÄÚ¼¤ÔöÖÁ170Íò´Î£¬Éæ¼°³¬10,000¸ö·ÖÆçIPµØÖ·£¬ÖØÒª¹¥»÷Ö¸±êλÓÚÃÀ¹ú¡¢Ä«Î÷¸çºÍ°Í»ù˹̹µÄ»ù´¡ÉèÊ©¡£¶ñÒâÁ÷Á¿ÏÕЩȫÊýÔ´×Ե¹ú3xK GmbHµÄIPµØÖ·¿Õ¼ä£¬°µÊ¾´æÔÚ¼¯ÖÐÊ½ÔÆ»ù´¡Éèʩ֧³Ö¡£¹¥»÷ÌØµãÏÔʾ£¬ÍþвÐÐΪÕß³Á¸´Ê¹Óó£¼ûÓû§ÃûºÍÃÜÂë×éºÏ£¬ÇÒÎÞÊýÒªÇó¼Ù×°³ÉFirefoxÓû§´úÀí¡£Óû§´úÀí¡¢ÒªÇó½á¹¹¼°¹¦·òµÄÒ»ÖÂÐÔÅú×¢£¬ÕâÊÇÖ¼ÔÚ¼ø±ð¶³ö»ò±£»¤ÓÄ΢µÄGlobalProtectÃÅ»§µÄ¾ç±¾»¯Æ¾Ö¤Ì½²â£¬¶ø·Ç½»»¥Ê½½Ó¼û»ò·ì϶ÀûÓá£12ÔÂ12ÈÕ£¬Í³Ò»ÍйÜÌṩÉ̵Ĺ¥»÷תÏòCisco SSL VPN¶Ëµã£¬Î¨Ò»¹¥»÷IPµØÖ·ÊýÁ¿´Ó²»¼°200¸öÔ¾ÉýÖÁ1,273¸ö£¬ÕâÊÇ´Óǰ12ÖÜÄÚ³õ´Î´ó¹æÄ£Ê¹ÓÃ3xKÍйÜIPÕë¶ÔCisco SSL VPNµÄ¹¥»÷¡£µÇ¼ÓÐÐ§ÔØºÉ×ñÑ­Õý³£SSL VPNÉí·ÝÑéÖ¤Á÷³Ì£¬½øÒ»²½Ö¤ÊµÕâÊÇ×Ô¶¯»¯Í´´¦¹¥»÷¶ø·Ç·ì϶ÀûÓá£


https://www.bleepingcomputer.com/news/security/new-password-spraying-attacks-target-cisco-pan-vpn-gateways/


6. ¸¥¼ªÄáÑÇÖÝRBHAÔâÀÕË÷¹¥»÷Ö³¬11ÍòÈËÊý¾Ýй¶


12ÔÂ18ÈÕ£¬¸¥¼ªÄáÑÇÏçÕòÊ¿ÂúÐÐΪ½¡È«ÖÎÀí¾Ö£¨RBHA£©½üÈÕÅû¶£¬ÆäÓÚ9ÔÂ29ÈÕÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬µ¼Ö²¿ÃÅÍøÂç±»¼ÓÃÜ£¬³¬11.3ÍòÈËÓ×ÎÒÐÅÏ¢Ãæ¶Ôй¶·çÏÕ¡£×÷ΪÀïÊ¿ÂúÊй«¹²»ú¹¹£¬RBHAÌṩÉúÀí½¡È«Ö§³Ö¡¢Î£»ú»¤Àí¡¢Ò©ÎïÀÄÓÃÔ¤·ÀµÈ¹Ø¼ü·þÎñ¡£¹¥»÷´ÎÈÕ£¬¸Ã»ú¹¹¼´·¢ÏÖÊÂÎñ²¢Ñ¸¿ì±÷³ý¹¥»÷Õߣ¬µ«ÍþвÐÐΪÕß¿ÉÄÜÒÑ»ñÈ¡Ô̺¬ÐÕÃû¡¢Éç»á±£ÏÕºÅÂë¡¢»¤ÕÕºÅÂë¡¢½ðÈÚÕË»§¼°½¡È«ÐÅÏ¢ÔÚÄÚµÄÃô¸ÐÊý¾Ý¡£¾ÝÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿»ã±¨£¬Õâ´ÎÊÂÎñÓ°Ïì113,232Ãû¸ö±ð¡£RBHAÔÚ¹ÙÍø°ä²¼µÄÊÂÎñ֪ͨÖÐÇ¿µ÷£¬ËäÎÞÈ·ÔäÖ¤¾ÝÅú×¢Êý¾ÝÒѱ»½Ó¼û£¬µ«³öÓÚÉóÉ÷ÈÔÌáÐÑÊÜÓ°ÏìÕß¼ÓÇ¿¾¯Ì裬½¨Ò鶨ÆÚºË²éÕË»§¶ÔÕ˵¥¡¢¼à¿ØÐÅÓþ»ã±¨ÒÔ·À±¸Éí·Ý͵ÇÔ¼°Ú²Æ­ÐÐΪ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ÀÕË÷Èí¼þ×éÖ¯¡°÷è÷롱ÒÑÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬²¢½«RBHAÁÐÈëÆä»ùÓÚTorµÄй¶վµã¡£¸Ã×éÖ¯Ëæºó°ä²¼Á˾ݳÆÇÔÈ¡µÄ192GBÊý¾Ý£¬º¬³¬39.3Íò·ÝÎļþ£¬½øÒ»²½¼Ó¾çÁËÊý¾ÝÀÄÓ÷çÏÕ¡£


https://www.securityweek.com/113000-impacted-by-data-breach-at-virginia-mental-health-authority/