·¸·¨·Ö×Óð³äÃÀ¹ú¸ß¼¶¹ÙÔ±¾ÙÐÐÐÅÏ¢Õ©Æ­

Ðû²¼Ê±¼ä 2025-12-25

1. ·¸·¨·Ö×Óð³äÃÀ¹ú¸ß¼¶¹ÙÔ±¾ÙÐÐÐÅÏ¢Õ©Æ­


12ÔÂ21ÈÕ£¬ £¬£¬£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö¿ËÈÕÐû²¼ÖÒÑÔ£¬ £¬£¬£¬ÍøÂç·¸·¨·Ö×Ó×Ô2023ÄêÆðÒ»Á¬Ã°³äÖÝÕþ¸®¸ß¼¶¹ÙÔ±¡¢°×¹¬¹ÙÔ±¡¢ÄÚ¸ó³ÉÔ±¼°¹ú¾Û»áÔ±£¬ £¬£¬£¬Ê¹ÓöÌÐÅÓëÈ˹¤ÖÇÄÜÌìÉúµÄÓïÒôÐÅÏ¢£¬ £¬£¬£¬Õë¶Ô¹ÙÔ±¼ÒÈ˼°Ë½ÈËÊìÈËʵÑ龫׼թƭ¡£¡£¡£¡£´ËÀ๥»÷ͨ¹ý¡°¶ÌÐÅ´¹ÂÚ+ÓïÒô¿Ë¡¡±Ë«ÖØÊÖ¶ÎÕö¿ª£º·¸·¨·Ö×ÓÊ×ÏÈ·¢ËÍ¿´ËÆÀ´×ÔȨÍþ»ú¹¹µÄڲƭ¶ÌÐÅ£¬ £¬£¬£¬Ëæºó²¦´òAIÌìÉúµÄÓïÒôµç»°»òÁôÏÂÓïÒôÁôÑÔ£¬ £¬£¬£¬ÒÔÌÖÂÛÊìϤ»°ÌâΪÓÕ¶ü£¬ £¬£¬£¬Ñ¸ËÙÒªÇóÊܺ¦Õß×ªÒÆÖÁSignal¡¢Telegram¡¢WhatsAppµÈ¼ÓÃÜÒÆ¶¯Ó¦ÓþÙÐнøÒ»²½Ïàͬ¡£¡£¡£¡£ÔÚ¼ÓÃÜÓ¦ÓÃÖУ¬ £¬£¬£¬¹¥»÷Õß»áͨ¹ý̸ÂÛÊ±ÊÆ¡¢Ë«±ß¹ØÏµ£¬ £¬£¬£¬»òÐé¹¹¡°¶­Ê»áÌáÃû¡±¡°°²ÅÅÓë×ÜͳÅöÃæ¡±µÈ³¡¾°½¨ÉèÐÅÈΣ¬ £¬£¬£¬½ø¶øË÷ÒªÑéÖ¤ÂëÒÔͬ²½ÁªÏµÈËÁÐ±í¡¢»ñÈ¡»¤ÕÕµÈÃô¸ÐÎļþ¸±±¾¡¢ÒªÇóÏòÍâÑó½ðÈÚ»ú¹¹»ã¿î£¬ £¬£¬£¬»òÓÕµ¼ÏÈÈÝͬ»ï¡£¡£¡£¡£GetReal SecurityÍþвÑо¿Ö÷¹ÜÌÀÄ·¡¤¿ËÂÞ˹ָ³ö£¬ £¬£¬£¬ÍþвÐÐΪÕßÕýʹÓÃÉî¶ÈαÔìÊÖÒÕʵÑéÉç»á¹¤³Ì¹¥»÷£¬ £¬£¬£¬½öÐè30ÃëÓïÒôÑù±¾¼´¿Éͨ¹ýAIÓïÒô¿Ë¡¸ß¶È±ÆÕæÄ£ÄâËûÈË£¬ £¬£¬£¬¶ø¹«Ö°Ö°Ô±ºÍ¸ß¹ÜµÄÓïÒôÑù±¾¼«Ò×ͨ¹ý¹ûÕæÇþµÀ»ñÈ¡¡£¡£¡£¡£


https://cybernews.com/news/criminals-impersonate-senior-us-officials-in-messaging-scams/


2. ƴд¹ýʧÓòÃûÒý·¢Cosmali Loader¶ñÒâÈí¼þѬȾ


12ÔÂ24ÈÕ£¬ £¬£¬£¬¿ËÈÕ£¬ £¬£¬£¬ÍøÂçÇå¾²ÁìÓòÆØ³öÒ»ÒòÓÉÓòÃûƴд¹ýʧµ¼ÖµĶñÒâÈí¼þѬȾÊÂÎñ¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÓû§ÊäÈëÊèºö£¬ £¬£¬£¬ÇÀ×¢Óë΢Èí¼¤»î¾ç±¾£¨MAS£©¹Ù·½ÓòÃû¸ß¶ÈÏàËÆµÄÓòÃû¡°get.activate[.]win¡±£¬ £¬£¬£¬½ö±È¹Ù·½ÓòÃû¡°get.activated.win¡±ÉÙÒ»¸ö×Öĸ¡°d¡±£¬ £¬£¬£¬ÓÕµ¼Óû§»á¼û²¢Ö´ÐжñÒâPowerShell¾ç±¾£¬ £¬£¬£¬×îÖÕµ¼ÖÂWindowsϵͳ±»¡°Cosmali Loader¡±¶ñÒâÈí¼þѬȾ¡£¡£¡£¡£¾Ý±¨µÀ£¬ £¬£¬£¬¶àÃûMASÓû§ÒÑÔÚRedditƽ̨±¨¸æÏµÍ³·ºÆðCosmali LoaderѬȾµÄµ¯³öÖÒÑÔ¡£¡£¡£¡£Çå¾²Ñо¿Ô±RussianPandaÆÊÎö·¢Ã÷£¬ £¬£¬£¬¸Ã¶ñÒâÈí¼þ¿ØÖÆÃæ°å±£´æÇå¾²Îó²î£¬ £¬£¬£¬¹¥»÷Õ߿ɽè´ËÔ¶³Ì»á¼ûÊܺ¦ÕßÅÌËã»ú£¬ £¬£¬£¬²¢°²ÅżÓÃÜÇ®±ÒÍڿ󹤾߼°XWormÔ¶³Ì»á¼ûľÂí£¨RAT£©¡£¡£¡£¡£GDATA¶ñÒâÈí¼þÆÊÎöʦKarsten Hahn´ËǰҲ·¢Ã÷¹ýÀàËÆµ¯³ö֪ͨ£¬ £¬£¬£¬½øÒ»²½Ö¤Êµ´Ë´ÎÊÂÎñÓ뿪ԴCosmali Loader¶ñÒâÈí¼þ±£´æ¹ØÁª¡£¡£¡£¡£MAS×÷Ϊ¿ªÔ´PowerShell¾ç±¾ÜöÝÍ£¬ £¬£¬£¬Í¨¹ýHWID¼¤»î¡¢KMSÄ£ÄâµÈÊÖÒÕʵÏÖWindows¼°OfficeµÄ×Ô¶¯¼¤»î£¬ £¬£¬£¬µ«Î¢ÈíÃ÷È·½«ÆäÊÓΪµÁ°æ¹¤¾ß£¬ £¬£¬£¬ÒòÆä½ÓÄÉδÊÚȨÊÖ¶ÎÈÆ¹ýÔÊÐíϵͳ¡£¡£¡£¡£ÏîĿά»¤ÕßÒÑÏòÓû§·¢³öÖÒÑÔ£¬ £¬£¬£¬Ç¿µ÷Ö´ÐÐÏÂÁîǰÐè×ÐϸºË¶ÔÓòÃûƴд£¬ £¬£¬£¬×èÖ¹ÒòÊäÈë¹ýʧ»á¼û¶ñÒâÓòÃû¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fake-mas-windows-activation-domain-used-to-spread-powershell-malware/


3. FBI²é·âweb3adspanels[.]orgÓòÃû


12ÔÂ24ÈÕ£¬ £¬£¬£¬¿ËÈÕ£¬ £¬£¬£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö£¨FBI£©²é·âÁËÓòÃû¡°web3adspanels[.]org¡±¼°ÆäÊý¾Ý¿â£¬ £¬£¬£¬¸ÃÓòÃû±»·¸·¨ÍÅ»ïÓÃÓÚ´æ´¢ºÍ¸Ä¶¯´ÓÃÀ¹úÊܺ¦Õß´¦ÇÔÈ¡µÄÒøÐеǼƾ֤£¬ £¬£¬£¬½ø¶øÊµÑé´ó¹æÄ£ÒøÐÐÕË»§µÁÓÃÕ©Æ­¡£¡£¡£¡£¾Ý˾·¨²¿Åû¶£¬ £¬£¬£¬¸Ã·¸·¨ÍÅ»ïͨ¹ýÔڹȸ衢±ØÓ¦µÈËÑË÷ÒýÇæÍ¶·ÅÐéα¹ã¸æ£¬ £¬£¬£¬Ä£ÄâÕæÊµÒøÐÐ¹ã¸æÓÕµ¼Óû§µã»÷¡£¡£¡£¡£Êܺ¦Õßµã»÷ºó»á±»Öض¨ÏòÖÁÓÉ·¸·¨·Ö×Ó¿ØÖƵÄÚ²Æ­ÍøÕ¾£¬ £¬£¬£¬µ±Óû§ÊäÈëÒøÐеǼƾ֤ʱ£¬ £¬£¬£¬ÍøÕ¾ÉϵĶñÒâÈí¼þ»áÁ¬Ã¦ÇÔÈ¡ÕâЩÐÅÏ¢¡£¡£¡£¡£·¸·¨·Ö×ÓËæºóʹÓÃÇÔÈ¡µÄƾ֤µÇÂ¼ÕæÊµÒøÐÐÍøÕ¾£¬ £¬£¬£¬ÍµÈ¡ÕË»§×ʽ𡣡£¡£¡£ÊÓ²ìÏÔʾ£¬ £¬£¬£¬¸ÃÓòÃû×÷Ϊºó¶ËÍøÂçÃæ°å£¬ £¬£¬£¬ÍйÜÁËÊýǧ¸ö±»µÁµÄÒøÐеǼƾ֤£¬ £¬£¬£¬²¢Ò»Á¬ÔËÓªÖÁ2025Äê11Ô¡£¡£¡£¡£°®É³ÄáÑÇÕþ¸®ÒÑÉúÑIJ¢ÍøÂçÁËÍйܴ¹ÂÚÒ³ÃæµÄЧÀÍÆ÷Êý¾Ý¼°±»µÁƾ֤£¬ £¬£¬£¬ÎªºóÐøÊÓ²ìÌṩҪº¦Ö¤¾Ý¡£¡£¡£¡£FBIÈ·ÈÏ£¬ £¬£¬£¬ÖÁÉÙ19ÃûÃÀ¹úÊܺ¦ÕßÒò¸ÃȦÌ×ËðʧԼ1460ÍòÃÀÔª£¬ £¬£¬£¬²¢ÃæÁÙ2800ÍòÃÀÔªµÄδËìËðʧ¡£¡£¡£¡£


https://securityaffairs.com/186094/cyber-crime/fbi-seized-web3adspanels-org-hosting-stolen-logins.html


4. MongoDB½ôÆÈͨ¸æ¸ßΣRCEÎó²îÐèÁ¬Ã¦ÐÞ¸´


12ÔÂ24ÈÕ£¬ £¬£¬£¬MongoDB¿ËÈÕÐû²¼½ôÆÈÇ徲ͨ¸æ£¬ £¬£¬£¬ÖÒÑÔITÖÎÀíÔ±±ØÐèÁ¬Ã¦ÐÞ¸´±àºÅΪCVE-2025-14847µÄ¸ßΣÎó²î¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìMongoDB 8.2.0ÖÁ8.2.3¡¢8.0.0ÖÁ8.0.16¡¢7.0.0ÖÁ7.0.26¡¢6.0.0ÖÁ6.0.26¡¢5.0.0ÖÁ5.0.31¡¢4.4.0ÖÁ4.4.29¼°ËùÓÐv4.2¡¢v4.0¡¢v3.6°æ±¾£¬ £¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓôËÎó²îÌᳫµÍÖØÆ¯ºóÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷£¬ £¬£¬£¬ÎÞÐèÓû§½»»¥¼´¿É¿ØÖÆÄ¿µÄЧÀÍÆ÷¡£¡£¡£¡£Îó²îȪԴÔÚÓÚMongoDBЧÀÍÆ÷¶Ô³¤¶È²ÎÊýµÄ·×ÆçÖ´¦Öóͷ£»úÖÆ£¬ £¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¸Ä¶¯zlibѹËõʵÏÖÖеÄÊý¾Ý°ü£¬ £¬£¬£¬´¥·¢Î´³õʼ»¯µÄ¶ÑÄÚ´æ»á¼û£¬ £¬£¬£¬½ø¶øÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£MongoDBÇå¾²ÍŶÓÇ¿µ÷£¬ £¬£¬£¬¸ÃÎó²îÒѾ߱¸±»´ó¹æÄ£Ê¹ÓõÄÌõ¼þ£¬ £¬£¬£¬½¨ÒéÖÎÀíÔ±Á¬Ã¦Éý¼¶ÖÁÒÑÐÞ¸´°æ±¾£º8.2.3¡¢8.0.17¡¢7.0.28¡¢6.0.27¡¢5.0.32»ò4.4.30¡£¡£¡£¡£ÈôÎÞ·¨Á¬Ã¦Éý¼¶£¬ £¬£¬£¬ÐèÔÚÆô¶¯mongod/mongosʱͨ¹ýnetworkMessageCompressors»ònet.compression.compressors²ÎÊýÏÔʽ½ûÓÃzlibѹËõ¹¦Ð§¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/mongodb-warns-admins-to-patch-severe-rce-flaw-immediately/


5. MarquisÔâºÚ¿Í¹¥»÷Ö¶à¼ÒÒøÐпͻ§Êý¾Ýй¶


12ÔÂ24ÈÕ£¬ £¬£¬£¬¿ËÈÕ£¬ £¬£¬£¬Á½¼ÒÃÀ¹úÒøÐÐVeraBankºÍArtisans' BankÏà¼ÌÅû¶ÒòµÚÈý·½¹©Ó¦ÉÌMarquis Software SolutionsÔâÊܺڿ͹¥»÷£¬ £¬£¬£¬µ¼Ö´ó×Ú¿Í»§ÐÅϢй¶¡£¡£¡£¡£×ܲ¿Î»Óڵ¿ËÈøË¹ÖݵÄVeraBank͸¶£¬ £¬£¬£¬´Ë´ÎÊÂÎñÓ°Ïì37,318Ãû¿Í»§£¬ £¬£¬£¬Ð¹Â¶ÐÅÏ¢°üÀ¨ÐÕÃû¼°ÆäËûδÃ÷ȷ˵Ã÷µÄСÎÒ˽¼ÒÐÅÏ¢£¬ £¬£¬£¬Ïêϸй¶ÄÚÈÝÒò¿Í»§¶øÒì¡£¡£¡£¡£ÌØÀ­»ªÖݵÄArtisans' BankÔòÌåÏÖ£¬ £¬£¬£¬32,344Ãû¿Í»§µÄÐÕÃûºÍÉç»á°ü¹ÜºÅÂë¿ÉÄÜÔâδ¾­ÊÚȨ»á¼û¡£¡£¡£¡£Á½¼ÒÒøÐоùÇ¿µ÷£¬ £¬£¬£¬¹¥»÷½öÏÞÓÚMarquisϵͳ£¬ £¬£¬£¬Æä×ÔÉíϵͳδÊÜÓ°Ïì¡£¡£¡£¡£Marquis·½ÃæÌåÏÖ£¬ £¬£¬£¬ÒѾÍ8ÔÂ14ÈÕ±¬·¢µÄÊý¾Ýй¶ÊÂÎñÕö¿ªÄÚ²¿ÊӲ첢ִ֪ͨ·¨²¿·Ö¡£¡£¡£¡£È»¶ø£¬ £¬£¬£¬Artisans' BankÖ±ÖÁ10ÔÂÏÂÑ®²Å»ñϤ´ËÊ£¬ £¬£¬£¬½üÆÚ²ÅÒâʶµ½¿Í»§ÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£¡£11Ô£¬ £¬£¬£¬Å²Íþ´¢±¸ÒøÐУ¨NSB£©ÔøÒòMarquisÔâÊÜÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬µ¼ÖÂ51,000Ãû¿Í»§ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Éç»á°ü¹ÜºÅÂ롢˰ÎñʶÓÖÃûÂë¼°²ÆÎñÕË»§ÐÅÏ¢µÈÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£


https://cybernews.com/news/bank-marquis-software-vendor-attack/


6. Evasive PandaÕë¶Ô¶à¹úʵÑé¾«×¼ÉøÍ¸


12ÔÂ25ÈÕ£¬ £¬£¬£¬¿¨°Í˹»ùʵÑéÊÒ¿ËÈÕÐû²¼±¨¸æ£¬ £¬£¬£¬½ÒÆÆÎÛÃûÕÑÖøµÄÍøÂçÌØ¹¤×éÖ¯Evasive PandaÔÚ2022Äê11ÔÂÖÁ2024Äê11ÔÂʱ´ú£¬ £¬£¬£¬Õë¶ÔÖйú¡¢Ó¡¶È¼°ÍÁ¶úÆäÌᳫÐÂÒ»ÂÖÖØ´ó¹¥»÷¡£¡£¡£¡£¸Ã×éÖ¯×Ô2012ÄêÆð»îÔ¾£¬ £¬£¬£¬Í¨¹ýDNSÐ®ÖÆ¡¢ÖÐÐÄÈ˹¥»÷£¨AitM£©¼°Î±×°Èí¼þ¸üеÈÊֶΣ¬ £¬£¬£¬Èö²¥±ê¼ÇÐÔºóÃųÌÐòMgBot£¬ £¬£¬£¬ÊµÏÖºã¾ÃϵͳפÁôÓëÊý¾ÝÇÔÈ¡¡£¡£¡£¡£¹¥»÷Á´ÌõʼÓÚÈ«ÐÄÉè¼ÆµÄ¡°Õýµ±Î±×°¡±£º¹¥»÷Õßð³äËѺüÊÓÆµ¡¢°®ÆæÒÕÊÓÆµ¡¢IObit Smart Defrag¼°ÌÚѶQQµÈÈÈÃÅÈí¼þµÄ¸üгÌÐò£¬ £¬£¬£¬ÔÚÕýµ±×°ÖÃÎļþ¼ÐÖÐÖ²Èë¶ñÒâ´úÂ룬 £¬£¬£¬ÓÉÊÜÐÅÈÎϵͳЧÀÍÖ´ÐС£¡£¡£¡£¸üÒþ²ØµÄÊÇ£¬ £¬£¬£¬×é֯ʹÓÃAitMÊÖÒÕÐ®ÖÆÍøÂçÁ÷Á¿£¬ £¬£¬£¬Í¨¹ý¸Ä¶¯DNSÏìÓ¦£¬ £¬£¬£¬½«Óû§¶Ôdictionary.comµÄ»á¼ûÖØ¶¨ÏòÖÁ¹¥»÷Õß¿ØÖƵÄЧÀÍÆ÷£¬ £¬£¬£¬ÒÔαװ³ÉPNGÎļþµÄ¼ÓÃÜshellcodeÐÎʽ¼ÓÔØµÚ¶þ½×¶ÎÓÐÓÃÔØºÉ¡£¡£¡£¡£ÕâÖÖ»ùÓÚµØÀíλÖúÍISPµÄ¶¨ÏòͶ·ÅÕ½ÂÔ£¬ £¬£¬£¬Ê¹¹¥»÷¼«¾ßÕë¶ÔÐÔÇÒÄÑÒÔÔÚʵÑéÊÒ¸´ÏÖ¡£¡£¡£¡£Ð¿ª·¢µÄ¼ÓÔØÆ÷αװ³ÉWindows¿âÎļþ£¬ £¬£¬£¬Í¨¹ýDLL²à¼ÓÔØÊÖÒÕ½«MgBot×¢Èësvchost.exeµÈϵͳÀú³Ì£¬ £¬£¬£¬ÉõÖÁʹÓÃÊ®ÄêǰµÄÊðÃû¿ÉÖ´ÐÐÎļþÌӱܼì²â¡£¡£¡£¡£


https://securityonline.info/evasive-panda-apt-hijacks-dictionary-com-and-app-updates-in-two-year-spree/