·¸·¨·Ö×Óð³äÃÀ¹ú¸ß¼¶¹ÙÔ±¾ÙÐÐÐÅÏ¢Õ©Æ­

Ðû²¼Ê±¼ä 2025-12-25

1. ·¸·¨·Ö×Óð³äÃÀ¹ú¸ß¼¶¹ÙÔ±¾ÙÐÐÐÅÏ¢Õ©Æ­


12ÔÂ21ÈÕ£¬£¬£¬£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö¿ËÈÕÐû²¼ÖÒÑÔ£¬£¬£¬£¬ÍøÂç·¸·¨·Ö×Ó×Ô2023ÄêÆðÒ»Á¬Ã°³äÖÝÕþ¸®¸ß¼¶¹ÙÔ±¡¢°×¹¬¹ÙÔ±¡¢ÄÚ¸ó³ÉÔ±¼°¹ú¾Û»áÔ±£¬£¬£¬£¬Ê¹ÓöÌÐÅÓëÈ˹¤ÖÇÄÜÌìÉúµÄÓïÒôÐÅÏ¢£¬£¬£¬£¬Õë¶Ô¹ÙÔ±¼ÒÈ˼°Ë½ÈËÊìÈËʵÑ龫׼թƭ¡£¡£¡£´ËÀ๥»÷ͨ¹ý¡°¶ÌÐÅ´¹ÂÚ+ÓïÒô¿Ë¡¡±Ë«ÖØÊÖ¶ÎÕö¿ª£º·¸·¨·Ö×ÓÊ×ÏÈ·¢ËÍ¿´ËÆÀ´×ÔȨÍþ»ú¹¹µÄڲƭ¶ÌÐÅ£¬£¬£¬£¬Ëæºó²¦´òAIÌìÉúµÄÓïÒôµç»°»òÁôÏÂÓïÒôÁôÑÔ£¬£¬£¬£¬ÒÔÌÖÂÛÊìϤ»°ÌâΪÓÕ¶ü£¬£¬£¬£¬Ñ¸ËÙÒªÇóÊܺ¦Õß×ªÒÆÖÁSignal¡¢Telegram¡¢WhatsAppµÈ¼ÓÃÜÒÆ¶¯Ó¦ÓþÙÐнøÒ»²½Ïàͬ¡£¡£¡£ÔÚ¼ÓÃÜÓ¦ÓÃÖУ¬£¬£¬£¬¹¥»÷Õß»áͨ¹ý̸ÂÛÊ±ÊÆ¡¢Ë«±ß¹ØÏµ£¬£¬£¬£¬»òÐé¹¹¡°¶­Ê»áÌáÃû¡±¡°°²ÅÅÓë×ÜͳÅöÃæ¡±µÈ³¡¾°½¨ÉèÐÅÈΣ¬£¬£¬£¬½ø¶øË÷ÒªÑéÖ¤ÂëÒÔͬ²½ÁªÏµÈËÁÐ±í¡¢»ñÈ¡»¤ÕÕµÈÃô¸ÐÎļþ¸±±¾¡¢ÒªÇóÏòÍâÑó½ðÈÚ»ú¹¹»ã¿î£¬£¬£¬£¬»òÓÕµ¼ÏÈÈÝͬ»ï¡£¡£¡£GetReal SecurityÍþвÑо¿Ö÷¹ÜÌÀÄ·¡¤¿ËÂÞ˹ָ³ö£¬£¬£¬£¬ÍþвÐÐΪÕßÕýʹÓÃÉî¶ÈαÔìÊÖÒÕʵÑéÉç»á¹¤³Ì¹¥»÷£¬£¬£¬£¬½öÐè30ÃëÓïÒôÑù±¾¼´¿Éͨ¹ýAIÓïÒô¿Ë¡¸ß¶È±ÆÕæÄ£ÄâËûÈË£¬£¬£¬£¬¶ø¹«Ö°Ö°Ô±ºÍ¸ß¹ÜµÄÓïÒôÑù±¾¼«Ò×ͨ¹ý¹ûÕæÇþµÀ»ñÈ¡¡£¡£¡£


https://cybernews.com/news/criminals-impersonate-senior-us-officials-in-messaging-scams/


2. ƴд¹ýʧÓòÃûÒý·¢Cosmali Loader¶ñÒâÈí¼þѬȾ


12ÔÂ24ÈÕ£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬ÍøÂçÇå¾²ÁìÓòÆØ³öÒ»ÒòÓÉÓòÃûƴд¹ýʧµ¼ÖµĶñÒâÈí¼þѬȾÊÂÎñ¡£¡£¡£¹¥»÷ÕßʹÓÃÓû§ÊäÈëÊèºö£¬£¬£¬£¬ÇÀ×¢Óë΢Èí¼¤»î¾ç±¾£¨MAS£©¹Ù·½ÓòÃû¸ß¶ÈÏàËÆµÄÓòÃû¡°get.activate[.]win¡±£¬£¬£¬£¬½ö±È¹Ù·½ÓòÃû¡°get.activated.win¡±ÉÙÒ»¸ö×Öĸ¡°d¡±£¬£¬£¬£¬ÓÕµ¼Óû§»á¼û²¢Ö´ÐжñÒâPowerShell¾ç±¾£¬£¬£¬£¬×îÖÕµ¼ÖÂWindowsϵͳ±»¡°Cosmali Loader¡±¶ñÒâÈí¼þѬȾ¡£¡£¡£¾Ý±¨µÀ£¬£¬£¬£¬¶àÃûMASÓû§ÒÑÔÚRedditƽ̨±¨¸æÏµÍ³·ºÆðCosmali LoaderѬȾµÄµ¯³öÖÒÑÔ¡£¡£¡£Çå¾²Ñо¿Ô±RussianPandaÆÊÎö·¢Ã÷£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ¿ØÖÆÃæ°å±£´æÇå¾²Îó²î£¬£¬£¬£¬¹¥»÷Õ߿ɽè´ËÔ¶³Ì»á¼ûÊܺ¦ÕßÅÌËã»ú£¬£¬£¬£¬²¢°²ÅżÓÃÜÇ®±ÒÍڿ󹤾߼°XWormÔ¶³Ì»á¼ûľÂí£¨RAT£©¡£¡£¡£GDATA¶ñÒâÈí¼þÆÊÎöʦKarsten Hahn´ËǰҲ·¢Ã÷¹ýÀàËÆµ¯³ö֪ͨ£¬£¬£¬£¬½øÒ»²½Ö¤Êµ´Ë´ÎÊÂÎñÓ뿪ԴCosmali Loader¶ñÒâÈí¼þ±£´æ¹ØÁª¡£¡£¡£MAS×÷Ϊ¿ªÔ´PowerShell¾ç±¾ÜöÝÍ£¬£¬£¬£¬Í¨¹ýHWID¼¤»î¡¢KMSÄ£ÄâµÈÊÖÒÕʵÏÖWindows¼°OfficeµÄ×Ô¶¯¼¤»î£¬£¬£¬£¬µ«Î¢ÈíÃ÷È·½«ÆäÊÓΪµÁ°æ¹¤¾ß£¬£¬£¬£¬ÒòÆä½ÓÄÉδÊÚȨÊÖ¶ÎÈÆ¹ýÔÊÐíϵͳ¡£¡£¡£ÏîĿά»¤ÕßÒÑÏòÓû§·¢³öÖÒÑÔ£¬£¬£¬£¬Ç¿µ÷Ö´ÐÐÏÂÁîǰÐè×ÐϸºË¶ÔÓòÃûƴд£¬£¬£¬£¬×èÖ¹ÒòÊäÈë¹ýʧ»á¼û¶ñÒâÓòÃû¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fake-mas-windows-activation-domain-used-to-spread-powershell-malware/


3. FBI²é·âweb3adspanels[.]orgÓòÃû


12ÔÂ24ÈÕ£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬ÃÀ¹úÁª°îÊÓ²ì¾Ö£¨FBI£©²é·âÁËÓòÃû¡°web3adspanels[.]org¡±¼°ÆäÊý¾Ý¿â£¬£¬£¬£¬¸ÃÓòÃû±»·¸·¨ÍÅ»ïÓÃÓÚ´æ´¢ºÍ¸Ä¶¯´ÓÃÀ¹úÊܺ¦Õß´¦ÇÔÈ¡µÄÒøÐеǼƾ֤£¬£¬£¬£¬½ø¶øÊµÑé´ó¹æÄ£ÒøÐÐÕË»§µÁÓÃÕ©Æ­¡£¡£¡£¾Ý˾·¨²¿Åû¶£¬£¬£¬£¬¸Ã·¸·¨ÍÅ»ïͨ¹ýÔڹȸ衢±ØÓ¦µÈËÑË÷ÒýÇæÍ¶·ÅÐéα¹ã¸æ£¬£¬£¬£¬Ä£ÄâÕæÊµÒøÐÐ¹ã¸æÓÕµ¼Óû§µã»÷¡£¡£¡£Êܺ¦Õßµã»÷ºó»á±»Öض¨ÏòÖÁÓÉ·¸·¨·Ö×Ó¿ØÖƵÄÚ²Æ­ÍøÕ¾£¬£¬£¬£¬µ±Óû§ÊäÈëÒøÐеǼƾ֤ʱ£¬£¬£¬£¬ÍøÕ¾ÉϵĶñÒâÈí¼þ»áÁ¬Ã¦ÇÔÈ¡ÕâЩÐÅÏ¢¡£¡£¡£·¸·¨·Ö×ÓËæºóʹÓÃÇÔÈ¡µÄƾ֤µÇÂ¼ÕæÊµÒøÐÐÍøÕ¾£¬£¬£¬£¬ÍµÈ¡ÕË»§×ʽ𡣡£¡£ÊÓ²ìÏÔʾ£¬£¬£¬£¬¸ÃÓòÃû×÷Ϊºó¶ËÍøÂçÃæ°å£¬£¬£¬£¬ÍйÜÁËÊýǧ¸ö±»µÁµÄÒøÐеǼƾ֤£¬£¬£¬£¬²¢Ò»Á¬ÔËÓªÖÁ2025Äê11Ô¡£¡£¡£°®É³ÄáÑÇÕþ¸®ÒÑÉúÑIJ¢ÍøÂçÁËÍйܴ¹ÂÚÒ³ÃæµÄЧÀÍÆ÷Êý¾Ý¼°±»µÁƾ֤£¬£¬£¬£¬ÎªºóÐøÊÓ²ìÌṩҪº¦Ö¤¾Ý¡£¡£¡£FBIÈ·ÈÏ£¬£¬£¬£¬ÖÁÉÙ19ÃûÃÀ¹úÊܺ¦ÕßÒò¸ÃȦÌ×ËðʧԼ1460ÍòÃÀÔª£¬£¬£¬£¬²¢ÃæÁÙ2800ÍòÃÀÔªµÄδËìËðʧ¡£¡£¡£


https://securityaffairs.com/186094/cyber-crime/fbi-seized-web3adspanels-org-hosting-stolen-logins.html


4. MongoDB½ôÆÈͨ¸æ¸ßΣRCEÎó²îÐèÁ¬Ã¦ÐÞ¸´


12ÔÂ24ÈÕ£¬£¬£¬£¬MongoDB¿ËÈÕÐû²¼½ôÆÈÇ徲ͨ¸æ£¬£¬£¬£¬ÖÒÑÔITÖÎÀíÔ±±ØÐèÁ¬Ã¦ÐÞ¸´±àºÅΪCVE-2025-14847µÄ¸ßΣÎó²î¡£¡£¡£¸ÃÎó²îÓ°ÏìMongoDB 8.2.0ÖÁ8.2.3¡¢8.0.0ÖÁ8.0.16¡¢7.0.0ÖÁ7.0.26¡¢6.0.0ÖÁ6.0.26¡¢5.0.0ÖÁ5.0.31¡¢4.4.0ÖÁ4.4.29¼°ËùÓÐv4.2¡¢v4.0¡¢v3.6°æ±¾£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓôËÎó²îÌᳫµÍÖØÆ¯ºóÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷£¬£¬£¬£¬ÎÞÐèÓû§½»»¥¼´¿É¿ØÖÆÄ¿µÄЧÀÍÆ÷¡£¡£¡£Îó²îȪԴÔÚÓÚMongoDBЧÀÍÆ÷¶Ô³¤¶È²ÎÊýµÄ·×ÆçÖ´¦Öóͷ£»úÖÆ£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¸Ä¶¯zlibѹËõʵÏÖÖеÄÊý¾Ý°ü£¬£¬£¬£¬´¥·¢Î´³õʼ»¯µÄ¶ÑÄÚ´æ»á¼û£¬£¬£¬£¬½ø¶øÖ´ÐÐí§Òâ´úÂë¡£¡£¡£MongoDBÇå¾²ÍŶÓÇ¿µ÷£¬£¬£¬£¬¸ÃÎó²îÒѾ߱¸±»´ó¹æÄ£Ê¹ÓõÄÌõ¼þ£¬£¬£¬£¬½¨ÒéÖÎÀíÔ±Á¬Ã¦Éý¼¶ÖÁÒÑÐÞ¸´°æ±¾£º8.2.3¡¢8.0.17¡¢7.0.28¡¢6.0.27¡¢5.0.32»ò4.4.30¡£¡£¡£ÈôÎÞ·¨Á¬Ã¦Éý¼¶£¬£¬£¬£¬ÐèÔÚÆô¶¯mongod/mongosʱͨ¹ýnetworkMessageCompressors»ònet.compression.compressors²ÎÊýÏÔʽ½ûÓÃzlibѹËõ¹¦Ð§¡£¡£¡£


https://www.bleepingcomputer.com/news/security/mongodb-warns-admins-to-patch-severe-rce-flaw-immediately/


5. MarquisÔâºÚ¿Í¹¥»÷Ö¶à¼ÒÒøÐпͻ§Êý¾Ýй¶


12ÔÂ24ÈÕ£¬£¬£¬£¬¿ËÈÕ£¬£¬£¬£¬Á½¼ÒÃÀ¹úÒøÐÐVeraBankºÍArtisans' BankÏà¼ÌÅû¶ÒòµÚÈý·½¹©Ó¦ÉÌMarquis Software SolutionsÔâÊܺڿ͹¥»÷£¬£¬£¬£¬µ¼Ö´ó×Ú¿Í»§ÐÅϢй¶¡£¡£¡£×ܲ¿Î»Óڵ¿ËÈøË¹ÖݵÄVeraBank͸¶£¬£¬£¬£¬´Ë´ÎÊÂÎñÓ°Ïì37,318Ãû¿Í»§£¬£¬£¬£¬Ð¹Â¶ÐÅÏ¢°üÀ¨ÐÕÃû¼°ÆäËûδÃ÷ȷ˵Ã÷µÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬Ïêϸй¶ÄÚÈÝÒò¿Í»§¶øÒì¡£¡£¡£ÌØÀ­»ªÖݵÄArtisans' BankÔòÌåÏÖ£¬£¬£¬£¬32,344Ãû¿Í»§µÄÐÕÃûºÍÉç»á°ü¹ÜºÅÂë¿ÉÄÜÔâδ¾­ÊÚȨ»á¼û¡£¡£¡£Á½¼ÒÒøÐоùÇ¿µ÷£¬£¬£¬£¬¹¥»÷½öÏÞÓÚMarquisϵͳ£¬£¬£¬£¬Æä×ÔÉíϵͳδÊÜÓ°Ïì¡£¡£¡£Marquis·½ÃæÌåÏÖ£¬£¬£¬£¬ÒѾÍ8ÔÂ14ÈÕ±¬·¢µÄÊý¾Ýй¶ÊÂÎñÕö¿ªÄÚ²¿ÊӲ첢ִ֪ͨ·¨²¿·Ö¡£¡£¡£È»¶ø£¬£¬£¬£¬Artisans' BankÖ±ÖÁ10ÔÂÏÂÑ®²Å»ñϤ´ËÊ£¬£¬£¬£¬½üÆÚ²ÅÒâʶµ½¿Í»§ÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£11Ô£¬£¬£¬£¬Å²Íþ´¢±¸ÒøÐУ¨NSB£©ÔøÒòMarquisÔâÊÜÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬µ¼ÖÂ51,000Ãû¿Í»§ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Éç»á°ü¹ÜºÅÂ롢˰ÎñʶÓÖÃûÂë¼°²ÆÎñÕË»§ÐÅÏ¢µÈÃô¸ÐÊý¾Ýй¶¡£¡£¡£


https://cybernews.com/news/bank-marquis-software-vendor-attack/


6. Evasive PandaÕë¶Ô¶à¹úʵÑé¾«×¼ÉøÍ¸


12ÔÂ25ÈÕ£¬£¬£¬£¬¿¨°Í˹»ùʵÑéÊÒ¿ËÈÕÐû²¼±¨¸æ£¬£¬£¬£¬½ÒÆÆÎÛÃûÕÑÖøµÄÍøÂçÌØ¹¤×éÖ¯Evasive PandaÔÚ2022Äê11ÔÂÖÁ2024Äê11ÔÂʱ´ú£¬£¬£¬£¬Õë¶ÔÖйú¡¢Ó¡¶È¼°ÍÁ¶úÆäÌᳫÐÂÒ»ÂÖÖØ´ó¹¥»÷¡£¡£¡£¸Ã×éÖ¯×Ô2012ÄêÆð»îÔ¾£¬£¬£¬£¬Í¨¹ýDNSÐ®ÖÆ¡¢ÖÐÐÄÈ˹¥»÷£¨AitM£©¼°Î±×°Èí¼þ¸üеÈÊֶΣ¬£¬£¬£¬Èö²¥±ê¼ÇÐÔºóÃųÌÐòMgBot£¬£¬£¬£¬ÊµÏÖºã¾ÃϵͳפÁôÓëÊý¾ÝÇÔÈ¡¡£¡£¡£¹¥»÷Á´ÌõʼÓÚÈ«ÐÄÉè¼ÆµÄ¡°Õýµ±Î±×°¡±£º¹¥»÷Õßð³äËѺüÊÓÆµ¡¢°®ÆæÒÕÊÓÆµ¡¢IObit Smart Defrag¼°ÌÚѶQQµÈÈÈÃÅÈí¼þµÄ¸üгÌÐò£¬£¬£¬£¬ÔÚÕýµ±×°ÖÃÎļþ¼ÐÖÐÖ²Èë¶ñÒâ´úÂ룬£¬£¬£¬ÓÉÊÜÐÅÈÎϵͳЧÀÍÖ´ÐС£¡£¡£¸üÒþ²ØµÄÊÇ£¬£¬£¬£¬×é֯ʹÓÃAitMÊÖÒÕÐ®ÖÆÍøÂçÁ÷Á¿£¬£¬£¬£¬Í¨¹ý¸Ä¶¯DNSÏìÓ¦£¬£¬£¬£¬½«Óû§¶Ôdictionary.comµÄ»á¼ûÖØ¶¨ÏòÖÁ¹¥»÷Õß¿ØÖƵÄЧÀÍÆ÷£¬£¬£¬£¬ÒÔαװ³ÉPNGÎļþµÄ¼ÓÃÜshellcodeÐÎʽ¼ÓÔØµÚ¶þ½×¶ÎÓÐÓÃÔØºÉ¡£¡£¡£ÕâÖÖ»ùÓÚµØÀíλÖúÍISPµÄ¶¨ÏòͶ·ÅÕ½ÂÔ£¬£¬£¬£¬Ê¹¹¥»÷¼«¾ßÕë¶ÔÐÔÇÒÄÑÒÔÔÚʵÑéÊÒ¸´ÏÖ¡£¡£¡£Ð¿ª·¢µÄ¼ÓÔØÆ÷αװ³ÉWindows¿âÎļþ£¬£¬£¬£¬Í¨¹ýDLL²à¼ÓÔØÊÖÒÕ½«MgBot×¢Èësvchost.exeµÈϵͳÀú³Ì£¬£¬£¬£¬ÉõÖÁʹÓÃÊ®ÄêǰµÄÊðÃû¿ÉÖ´ÐÐÎļþÌӱܼì²â¡£¡£¡£


https://securityonline.info/evasive-panda-apt-hijacks-dictionary-com-and-app-updates-in-two-year-spree/