Ç×¶íºÚ¿Í¼ÙÒâ¹Ù·½»ú¹¹Ö´ÐÐÍøÂç´¹µö¹¥»÷
°ä²¼¹¦·ò 2026-04-021. Ç×¶íºÚ¿Í¼ÙÒâ¹Ù·½»ú¹¹Ö´ÐÐÍøÂç´¹µö¹¥»÷
3ÔÂ31ÈÕ£¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±ÏìÓ¦Ó××飨CERT-UA£©°ä²¼»ã±¨£¬¸æ·¢Ò»¸ö±àºÅΪUAC-0255µÄÇ×¶íºÚ¿Í×éÖ¯¼ÙÒâ¸Ã»ú¹¹£¬Õë¶Ôµ±¾Ö»ú¹¹¡¢ÆóÒµ¼°ÆäËû×éÖ¯·¢Õ¹ÍøÂç´¹µö¹¥»÷¡£¹¥»÷Õßͨ¹ýαÔì¹Ù·½Óʼþ£¬ÖÒ¸æÊÕ¼þÈ˶íÂÞ˹Õý´òËã¶ÔÎÚ¿ËÀ¼¹Ø¼ü»ù´¡ÉèÊ©·¢Æð¡°´ó¹æÄ£ÍøÂç¹¥»÷¡±£¬²¢ÓÕµ¼Æä´ÓÎļþ¹²Ïí·þÎñFiles.fmÏÂÔØÃÜÂë±£»¤µÄѹËõÎļþ£¬×°ÖÃËùνµÄ¡°°²È«·À»¤Èí¼þ¡±¡£¸ÃÎļþÏÖʵÔ̺¬ÃûΪAgeWheezeµÄÔ¶³ÌÖÎÀí¹¤¾ß£¬¹¥»÷Õ߿ɽè´ËÔ¶³Ì½ÚÔìÊÜϰȾÉ豸£¬Ö´ÐкÅÁî¡¢ÖÎÀíÎļþ¹ý³Ì¡¢´«ÊäÆÁÄ»ÄÚÈÝ¡¢·ÂÕÕÊó±ê¼üÅ̲Ù×÷¼°½Ó¼û¼ôÌù°åµÈ²Ù×÷¡£Õâ´Î¹¥»÷Ö¸±êº¸Çµ±¾Ö»ú¹¹¡¢Ò½ÁÆÖÐÐÄ¡¢½ðÈÚ¹«Ë¾¡¢°²È«¹«Ë¾¡¢´óѧ¼°Èí¼þ¿ª·¢É̵ȶà¸öÐÐÒµ¡£CERT-UAÆÀ¹ÀÒÔΪ£¬Õâ´Î´¹µö»î¶¯ÕûÌ幦ЧÓÐÏÞ£¬½öµ¼ÖÂÉÙÁ¿Ï°È¾£¬ÖØÒª¼¯ÖÐÓÚ½ÌÓý»ú¹¹Ô±¹¤µÄÓ×ÎÒÉ豸¡£µ÷²éÏÔʾ£¬¹¥»÷Ðж¯¿ÉÄÜÓëÐÂÐËÍøÂçÍþв×éÖ¯CyberSerp´æÔÚ¹ØÁª£¬¸Ã×éÖ¯ËæºóÔÚTelegramƵ·Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬²¢Ðû³ÆÒÑÏòÔ¼Ò»°ÙÍòUkr.netÓû§·¢ËͶñÒâÓʼþ£¬ÈëÇÖ³¬20Íǫ̀É豸£¬µ«CERT-UAÉÐδ֤ʵÕâЩÊý×Ö¡£
https://therecord.media/pro-russian-hackers-posing-as-ukrainian-cyber-agency
2. WhatsApp·¢ÏÖÐéαÀûÓÃϰȾ200ÃûÓû§
4ÔÂ2ÈÕ£¬WhatsApp°ä·¢ÒÑ֪ͨԼ200ÃûÓû§£¬ËûÃǵÄÉ豸Òò×°ÖôøÓмäµýÈí¼þµÄ¼ÙðWhatsAppÀûÓöøÔâµ½ÈëÇÖ¡£¸ÃÐéαÀûÓÃÓÉÒâ´óÀû¼äµýÈí¼þÔì×÷ÉÌSIOרÃÅΪiPhoneÉè¼Æ£¬ÊÜÓ°ÏìµÄÓû§ÖØÒª¼¯ÖÐÔÚÒâ´óÀû¡£WhatsApp°µÊ¾£¬Õâ´Î¹¥»÷²¢·ÇÔ´ÓÚÆä×ÔÉí·ì϶£¬¶øÊÇÍþвÐÐΪÕßͨ¹ý¸ß¶ÈÕë¶ÔÐÔµÄÉç»á¹¤³Ì¼¿Á©£¬ÓÕʹÓû§ÔÚ¹Ù·½ÀûÓÃÉ̵êÖ®±íÏÂÔØ¶ñÒâÈí¼þ¡£WhatsAppµÄ°²È«ÍŶÓ×Ô¶¯·¢ÏÖÁËÕâÒ»ÐéαÀûÓ㬲¢½«Æä¹é×ïÓÚSIOµÄ×Ó¹«Ë¾ASIGINT¡£Ä¿Ç°£¬SIOºÍÆ»¹û¹«Ë¾¾ùδ¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£WhatsAppÒѽ«ÊÜÓ°ÏìµÄ200ÃûÓû§µÇ³ö£¬²¢ÌáÐÑÓû§ÏÂÔØ·Ç¹Ù·½¿Í»§¶Ë´æÔÚÒþÖԺͰ²È«·çÏÕ£¬½¨Òéɾ³ý¼ÙðÀûÓò¢×°Öùٷ½°æ±¾¡£SIOÔÚÆä¹ÙÍøÉÏ×Ô³ÆÊÇ·¨Âɲ¿ÃÅ¡¢µ±¾Ö»ú¹¹ÒÔ¼°¾¯Ô±ºÍµý±¨»ú¹¹µÄ¡°ºÏ×÷ͬ°é¡±£¬´ËǰÒÑÓÐÀàËÆÐÐΪ¼Í¼¡£È¥Ä꣬TechCrunchÔø±¨Â·SIO¿ª·¢Á˶à¿îÖ²Èë¼äµýÈí¼þµÄ°²×¿ÀûÓá£
https://therecord.media/whatsapp-warns-users-of-fake-app-used-for-spyware
3. CrystalRAT¶ñÒâÈí¼þ¼´·þÎñÉÏÏßTelegram
4ÔÂ1ÈÕ£¬Ò»ÖÖÃûΪCrystalRATµÄÐÂÐͶñÒâÈí¼þ¼´·þÎñ£¨MaaS£©ÔÚTelegramÉÏÍÆ¹ã£¬ÌṩԶ³Ì½Ó¼û¡¢Êý¾ÝÇÔÈ¡¡¢¼üÅ̼ͼºÍ¼ôÌù°å½Ù³ÖµÈÖ°ÄÜ¡£¸Ã¶ñÒâÈí¼þÓÚ1Ô³öÏÖ£¬Ñ¡È¡·Ö¼¶¶©ÔÄģʽ£¬³ýÁËTelegramƵ·±í£¬»¹Í¨¹ýרÃŵÄYouTubeÓªÏúƵ·½øÐÐÍÆ¹ã¡£CrystalRATÌṩÁËÒ»¸öÓû§¶ØÄÀµÄ½ÚÔìÃæ°åºÍ×Ô¶¯»¯¹¹½¨¹¤¾ß£¬Ö§³ÖµØÀí¹Ø±Õ¡¢¿ÉÖ´ÐÐÎļþ×Ô½ç˵ºÍ·´·ÖÎöÖ°ÄÜ¡£ÌìÉúµÄÓÐÐ§ÔØºÉ¾¹ýzlibѹËõ£¬²¢Ê¹ÓÃChaCha20¶Ô³ÆÁ÷ÃÜÂë½øÐмÓÃÜ¡£¸Ã¶ñÒâÈí¼þͨ¹ýWebSocketÏνӵ½ºÅÁîÓë½ÚÔ죨C2£©·þÎñÆ÷£¬²¢·¢ËÍÖ÷»úÐÅÏ¢ÓÃÓÚϰȾ¸ú×Ù¡£Ä¿Ç°ÆäÐÅÏ¢ÇÔÈ¡×é¼þÁÙʱ±»½ûÓã¬ÔÚ½øÐÐÉý¼¶³ï±¸£¬¸Ã×é¼þ¿Éͨ¹ýChromeElevator¹¤¾ßÒÔ¼°Yandex¡¢OperaµÈ»ùÓÚChromiumµÄä¯ÀÀÆ÷½øÐй¥»÷£¬Í¬Ê±´ÓSteam¡¢DiscordºÍTelegramµÈ×ÀÃæÀûÓ÷¨Ê½ÍøÂçÊý¾Ý¡£Ô¶³Ì½Ó¼ûÄ£¿éÖ§³Öͨ¹ýCMDÖ´ÐкÅÁî¡¢ÉÏ´«/ÏÂÔØÎļþ¡¢ä¯ÀÀÎļþϵͳ£¬²¢Í¨¹ýÄÚÖÃVNCʵ¼¾½ÚÔì»úе¡£´Ë±í£¬¸Ã¶ñÒâÈí¼þ»¹Äܲ¶»ñÂó¿Ë·çµÄÊÓÆµºÍÒôƵ£¬½¨ÉèµÄ¼üÅ̼ͼÆ÷¿É½«»÷¼üʵʱ´«ÊäÖÁC2·þÎñÆ÷£¬¼ôÌù°å¹¤¾ßÔòʹÓÃÕýÔò±í°×ʽ¼ì²â¼ôÌù°åÖеÄÇ®°üµØÖ·²¢´úÌæÎª¹¥»÷ÕßÌṩµÄµØÖ·¡£
https://www.bleepingcomputer.com/news/security/new-crystalrat-malware-adds-rat-stealer-and-prankware-features/
4. TrueChaosÐж¯ÀûÓÃÁãÈÕ·ì϶¹¥»÷TrueConf·þÎñÆ÷
4ÔÂ1ÈÕ£¬ºÚ¿ÍÀûÓñàºÅΪCVE-2026-3502µÄÁãÈÕ·ì϶¹¥»÷TrueConf»áÒé·þÎñÆ÷£¬´Ó¶øÔÚËùÓÐÏνӵĶ˵ãÉÏÖ´ÐÐËÁÒâÎļþ¡£¸Ã·ì϶ÑϳÁˮƽÆÀ¼¶ÎªÖеȣ¬Ô´ÓÚÈí¼þ¸üлúÔìÖжÌȱÆëÈ«ÐԲ鳣¬¹¥»÷Õ߿ɽ«ºÏ·¨¸üдúÌæÎª¶ñÒâ±äÖÖ¡£TrueConfÊÇÒ»¸öÊÓÆµ»áÒéÆ½Ì¨£¬¿É×÷Ϊ×ÔÍйܷþÎñÆ÷ÔËÐУ¬Í¨³£Îª·â¹ØµÄÀëÏß»·¾³Éè¼Æ¡£CheckPoint×êÑÐÈËÔ±×·×Ùµ½Ò»¸öÃûΪTrueChaosµÄ»î¶¯£¬×Ô½ñÄêËêÊ×ÒÔÀ´£¬¸Ã»î¶¯ÀûÓÃCVE-2026-3502·ì϶¶Ô¶«ÄÏÑǵÐÔÖʵÌåÌáÒéÁãÈÕ¹¥»÷¡£¹¥»÷ÕßÈô½ÚÔìÁ˱¾µØTrueConf·þÎñÆ÷£¬¿É½«Ô¤ÆÚ¸üаü´úÌæÎªËÁÒâ¿ÉÖ´ÐÐÎļþ²¢¼Ù×°³Éµ±Ç°ÀûÓ÷¨Ê½°æ±¾£¬·Ö·¢¸øËùÓÐÏνӵĿͻ§¶Ë¡£ÓÉÓÚ¿Í»§¶Ëδ½øÐÐÊʵ±ÑéÖ¤¼´ÐÅÀµ·þÎñÆ÷ÌṩµÄ¸üУ¬¶ñÒâÎļþ¿É¼Ù×°³ÉºÏ·¨TrueConf¸üжø±»´«µÝºÍÖ´ÐС£¸Ã·ì϶ӰÏìTrueConf°æ±¾8.1.0ÖÁ8.5.2£¬½¨¸´·¨Ê½ÓÚ2026Äê3ÔÂÔÚ8.5.3°æ±¾Öа䲼¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-trueconf-zero-day-to-push-malicious-software-updates/
5. NoVoice°²×¿¶ñÒâÈí¼þ²ØÉíGoogle Play³¬50¿îÀûÓÃ
4ÔÂ1ÈÕ£¬Ò»ÖÖÃûΪNoVoiceµÄÐÂÐͰ²×¿¶ñÒâÈí¼þÔÚGoogle PlayÉϱ»·¢ÏÖ£¬°µ²ØÔÚ50¶à¿îÀÛ¼ÆÏÂÔØÁ¿´ï230Íò´ÎµÄÀûÓ÷¨Ê½ÖС£ÕâЩÀûÓÃÔ̺¬ËãÕʹ¤¾ß¡¢Í¼Æ¬¿âºÍÓÎÏ·£¬±í±íÉÏÎÞÐè¿ÉÒÉȨÏÞÇÒÌṩÕý³£Ö°ÄÜ¡£¾ÝMcAfee×êÑÐÈËÔ±·ÖÎö£¬¸Ã¶ñÒâÈí¼þÀûÓÃ2016ÄêÖÁ2021Äê¼äÒѽ¨¸´µÄ¾É°æ°²×¿·ì϶£¬ÊÔͼ»ñÈ¡É豸rootȨÏÞ¡£Æô¶¯ÊÜϰȾÀûÓú󣬶ñÒâÈí¼þ½«¼ÓÃÜÓÐÐ§ÔØºÉ°µ²ØÔÚPNGͼÏñÎļþÖУ¬ÌáÈ¡¼ÓÔØºó¶Ï¸ùÖÐÑëÎļþÒÔ½â³ýºÛ¼£¡£¹¥»÷Õß»áÔ¤·ÀϰȾ±±¾©¡¢Àö½µÈÌØ¶¨µØÓòÉ豸£¬²¢¶Ô·ÂÕÕÆ÷¡¢µ÷ÊÔÆ÷ºÍVPNÖ´ÐÐ15Ïî²é³¡£¶ñÒâÈí¼þÏνӺÅÁîÓë½ÚÔ죨C2£©·þÎñÆ÷ÍøÂçÉ豸ÐÅÏ¢£¬Ã¿60ÃëÂÖѯһ´Î²¢ÏÂÔØÕë¶ÔÌØ¶¨É豸µÄ·ì϶ÀûÓÃ×é¼þ¡£McAfee·¢ÏÖÁË22¸ö·ì϶£¬¹¥»÷Õ߿ɽè´Ë»ñÈ¡rootȨÏÞ²¢½ûÓÃSELinuxÇ¿ÔìÖ´ÐУ¬¼õÈõÉ豸¸ù»ù°²È«±£»¤¡£É豸±»rootºó£¬¹Ø¼üϵͳ¿â±»´úÌæÎªhook°ü×°Æ÷£¬À¹½ØÏµÍ³Å²Óò¢½«Ö´ÐгÁ¶¨ÏòÖÁ¹¥»÷´úÂë¡£ÔÚºóÉøÈë½×¶Î£¬¹¥»÷Õß½«½ÚÔì´úÂë×¢ÈëÉ豸ÉÏÆô¶¯µÄÿ¸öÀûÓ÷¨Ê½£¬ÖØÒª²¿ÊðÁ½¸ö×é¼þ£ºÒ»¸öÓÃÓÚ¾²Ä¬×°ÖûòÐ¶ÔØÀûÓã¬ÁíÒ»¸öÔÚÖ°ºÎÄܽӼû»¥ÁªÍøµÄÀûÓÃÖÐÔËÐУ¬×÷ÎªÖØÒªÕë¶ÔWhatsAppÊý¾ÝÇÔÈ¡»úÔì¡£
https://www.bleepingcomputer.com/news/security/novoice-android-malware-on-google-play-infected-23-million-devices/
6. º¢Ö®±¦ÔâÍøÂç¹¥»÷ÖÂÒµÎñÖжÏ
4ÔÂ1ÈÕ£¬Íæ¾ßºÍÓÎÏ·¾ÞÍ·º¢Ö®±¦ÖÜÈý»ã±¨³Æ£¬¸Ã¹«Ë¾Ôâ·êÍøÂç¹¥»÷£¬µ¼Ö²¿ÃÅÒµÎñÁ÷³ÌÖжϡ£Æ¾¾ÝÌá½»¸øÃÀ¹ú֤ȯÂòÂôίԱ»áµÄÎļþ£¬º¢Ö®±¦ÓÚ3ÔÂ28ÈÕ¼ì²âµ½ÆäÍøÂçÔ⵽δ¾ÊÚȨµÄ½Ó¼û£¬×÷ΪÊÂÎñÏìÓ¦´ëÊ©µÄÒ»²¿ÃÅ£¬²¿ÃÅϵͳÒѱ»ÀëÏß¡£Ä¿Ç°£¬¹«Ë¾Õý½èÖú±í²¿ÍøÂ簲ȫר¼ÒµÄÁ¦Á¿·¢Õ¹µ÷²é£¬Ö¸±êÖ®Ò»ÊÇÈ·¶¨Õâ´ÎÊÂÎñµÄÈ«ÊýÓ°ÏìÁìÓò£¬Ô̺¬ÊÇ·ñÓÐÈκÎÎļþÔ⵽й¶¡£º¢Ö®±¦°µÊ¾£¬¹«Ë¾ÒÑÖ´Ðв¢½«³ÖÐøÖ´ÐÐÒµÎñÂ½ÐøÐÔ´òË㣬ÒÔÈ·±£ÔÚ½â¾öµ±Ç°Çé¿öµÄͬʱ¿ÉÄܳÖÐø½ÓÊܶ©µ¥¡¢·¢»õºÍ·¢Õ¹ÆäËû¹Ø¼üÒµÎñ¡£ÉêÃ÷²¹³ä³Æ£¬ÔÚÇé¿öÆëÈ«½â¾ö֮ǰ£¬¿ÉÄܱØÒª³ÖÐøÊýÖܹ¦·òÖ´ÐÐÕâЩһʱ´ëÊ©£¬Õâ¿ÉÄܻᵼÖÂһЩÑÓÎó¡£½ØÖÁĿǰ£¬ÉÐÎÞÍøÂç·¸×ïÍÅ»ïÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£º¢Ö®±¦°µÊ¾£¬¹«Ë¾ÔÚÖÂÁ¦¼Óǿϵͳ°²È«£¬²¢½«Æ¾¾Ýµ÷²éÁ˾ֲÉÈ¡ÆäËû´ëÊ©£¬Ô̺¬°ä²¼±ØÒªµÄ֪ͨ¡£
https://www.securityweek.com/toy-giant-hasbro-hit-by-cyberattack/


¾©¹«Íø°²±¸11010802024551ºÅ