¶ñÒâÈí¼þDollyWayÈëÇÖ³¬20,000¸öWordPressÍøÕ¾

°ä²¼¹¦·ò 2025-03-20

1. ¶ñÒâÈí¼þDollyWayÈëÇÖ³¬20,000¸öWordPressÍøÕ¾


3ÔÂ19ÈÕ £¬×Ô2016ÄêÆð £¬ÃûΪ¡°DollyWay¡±µÄ¶ñÒâÈí¼þÒÑÈëÇÖÈ«Çò³¬¹ý20,000¸öWordPressÍøÕ¾ £¬Í¨¹ý³Á¶¨ÏòÓû§ÖÁ¶ñÒâÕ¾µã½øÐÐڲƭ»î¶¯¡£DollyWayÒÑÀú¾­ÂÅ´ÎÉý¼¶ £¬Ñ¡È¡ÏȽøµÄÌӱܡ¢³ÁÐÂϰȾºÍÇ®±Ò»¯Õ½Êõ¡£×îа汾£¨v3£©×÷Ϊ´óÐÍÚ¿Æ­³Á¶¨Ïòϵͳ £¬ÀûÓòå¼þºÍÖ÷Ìâ·ì϶¹¥»÷WordPressÍøÕ¾¡£½ØÖÁ2025Äê2Ô £¬DollyWayÿÔ²úÉú1000Íò´ÎڲƭÐÔչʾ £¬Í¨¹ýÐéαµÄÔ¼»á¡¢´ò¶Ä¡¢¼ÓÃÜºÍ³é½±ÍøÕ¾Ó¯Àû £¬ÀûÓÃVexTrioºÍLosPollosÁªÊôÍøÂçʵÏÖÁ÷Á¿±äÏÖ¡£¸Ã¶ñÒâÈí¼þͨ¹ýÁ÷Á¿Ê赼ϵͳɸѡ·Ã¿Í £¬Æ¾¾ÝÆäµØÎ»¡¢É豸ÀàÐͺÍÍÆ¼öÆðÔ´³Á¶¨ÏòÁ÷Á¿¡£¹¥»÷ÕßÀûÓá°wp_enqueue_script¡±¾ç±¾×¢ÈëÈëÇÖÍøÕ¾ £¬Í¨¹ý¶à½×¶Î²Ù×÷ʵÏÖ×îÖÕ³Á¶¨Ïò¡£DollyWay»¹¾ß±¸×ÔÎÒÔÙϰȾÄÜÁ¦ £¬È·±£ÆäÔÚÿ´ÎÒ³Ãæ¼ÓÔØÊ±×Ô¶¯³ÁÐÂÏ°È¾ÍøÕ¾ £¬ÄÑÒԶϸù¡£Ëüͨ¹ý´«²¼PHP´úÂëÖÁ»î¶¯²å¼þ £¬²¢Ôö³¤»ìºÏµÄ¶ñÒâÈí¼þƬ¶ÎµÄWPCode²å¼þ¸±±¾ÊµÏÖÓÆ¾ÃÐÔ¡£´Ë±í £¬DollyWay´´½¨°µ²ØµÄÖÎÀíÔ±Óû§ÕË»§ £¬½øÒ»²½Ôö³¤·ÀÓùÄѶÈ¡£GoDaddyÒÑ·ÖÏíÓëDollyWayÓйصĹ¥»÷Ö¸±êÁбí £¬ÒÔÖú·ÀÓù´ËÍþв £¬²¢½«°ä²¼¸ü¶àϸ½Ú½ÒʾÆä»ù´¡ÉèÊ©ºÍת±äÕ½Êõ¡£


https://www.bleepingcomputer.com/news/security/malware-campaign-dollyway-breached-20-000-wordpress-sites/


2. ¸ú×ÙÈí¼þSpyXÊý¾Ýй¶ £¬½ü200ÍòÓû§¼Í¼ÔâÆØ¹â


3ÔÂ19ÈÕ £¬Ò»¿îÏû·Ñ¼¶¼äµýÈí¼þSpyXÓÚÈ¥ÄêÔâ·êÊý¾Ýй¶ £¬Ó°ÏìÔ̺¬ÊýǧÃûÆ»¹ûÓû§ÔÚÄڵĽü200ÍòÈË¡£Õâ´Îй¶ÊÂÎñ¿É×·ÒäÖÁ2024Äê6Ô £¬µ«´Ëǰδ±»±¨Â· £¬SpyXÔËÓªÉÌҲδ֪ͨÆä¿Í»§»òÖ¸±êÓû§¡£SpyX¼Ò×å×Ô2017ÄêÒÔÀ´ÒѲúÉú25´ÎÊý¾Ýй¶ £¬Åú×¢Ïû·Ñ¼¶¼äµýÈí¼þÐÐÒµ³ÖÐø¼¤Ôö £¬ÑϳÁÍþвÓ×ÎÒÒþÖÔ¡£Ð¹Â¶Êý¾ÝÔ̺¬197ÍòÌõΨһÕÊ»§¼Í¼¼°µç×ÓÓʼþµØÖ· £¬Éæ¼°SpyX¼°Æä¿Ë¡°æ±¾MSafelyºÍSpyPhone¡£Ô¼40%µÄµç×ÓÓʼþµØÖ·ÒÑÔÚ¡°ÎÒ±»ºÚÁË¡±ÍøÕ¾ÉϳöÏÖ¹ý¡£Õâ´Îй¶»¹º±¼û½â½ÒʾÁËSpyXÈôºÎ¶Ô×¼AppleÓû§ £¬Ð¹Â¶µÄ»º´æÖÐÔ̺¬Ô¼17,000×éÃ÷ÎÄAppleÕÊ»§Óû§ÃûºÍÃÜÂë¡£Êý¾ÝÕæÊµÐÔÒѵõ½²¿ÃÅÊܺ¦ÕßÈ·ÈÏ £¬ÓÐ¹ØÆ¾Ö¤ÒÑÌṩ¸øÆ»¹û¡£¹È¸èÒѳ·ÏÂÓëSpyX»î¶¯ÓйصÄChromeÀ©´ó·¨Ê½¡£TechCrunchΪAndroidÓû§ÌṩÁ˼äµýÈí¼þÒÆ³ýÖ¸ÄÏ £¬½¨ÒéÆôÓÃGoogle Play Protect¡¢Ê¹ÓÃË«³ÁÉí·ÝÑéÖ¤µÈ´ëÊ©±£»¤ÕÊ»§°²È«¡£iPhoneºÍiPadÓû§Ó¦²é³­²¢É¾³ý²»ÒâʶµÄÉ豸 £¬È·±£Ê¹Ó󤶸¹ÖÒìµÄÃÜÂë £¬²¢ÆôÓÃË«³ÁÉí·ÝÑéÖ¤¡£


https://techcrunch.com/2025/03/19/data-breach-at-stalkerware-spyx-affects-close-to-2-million-including-thousands-of-apple-users/


3. ±öϦ·¨ÄáÑÇÖݽÌÓý¹¤»áÊý¾Ýй¶ӰÏì50ÍòÈË


3ÔÂ19ÈÕ £¬±öϦ·¨ÄáÑÇÖÝ×î´óµÄ¹«¹²²¿Ãʤ»á±öϦ·¨ÄáÑÇÖݽÌÓýЭ»á (PSEA) ÓÚ2024Äê7Ô²úÉúÁËһ·°²È«ÊÂÎñ £¬µ¼Ö³¬¹ý517,487ÃûÓ×ÎÒµÄÐÅÏ¢±»µÁ £¬Ô̺¬ÀÏʦ¡¢Ö§³ÖÈËÔ±¡¢¸ßµµ½ÌÓýÈËÔ±µÈ½ÌÓýרҵÈËÊ¿¡£¾ÝPSEAй© £¬±»µÁÐÅÏ¢¿ÉÄÜÔ̺¬Ó×ÎÒ¡¢²ÆÕþºÍ½¡È«Êý¾Ý £¬ÈçÉç»á°²È«ºÅÂë¡¢Ö§¸¶¿¨ÐÅÏ¢¡¢»¤ÕÕÐÅÏ¢µÈ¡£ÎªÓ¦¶ÔÕâ´ÎÊÂÎñ £¬PSEAΪÊÜÓ°ÏìµÄÓ×ÎÒÌṩÁËÃâ·ÑµÄIDXÐÅÓþ¼à¿ØºÍÉí·Ý¸´Ô­·þÎñ £¬²¢½¨ÒéËûÃÇ¼à¿Ø²ÆÕþÕË»§ºÍÐÅÓþ»ã±¨ £¬ÉèÖÃڲƭ¾¯±¨»ò°²È«¶³½á¡£Ö»¹ÜPSEAδÃ÷È·Ö¸³ö¹¥»÷ÕßÉí·Ý £¬µ«RhysidaÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶ÔÕâ´ÎÈëÇÖÕÆ¹Ü £¬²¢ÒªÇóÖ§¸¶20±ÈÌØ±ÒÊê½ð¡£¹ÌÈ» PSEA ²¢Î´Ð¹Â©ÊÇ·ñÖ§¸¶ÁËÊê½ðÒÔÔ¤·ÀÊý¾Ýй¶ £¬µ«¸ÃÀÕË÷Èí¼þÍÅ»ïÒÑ´ÓÆä°µÍøÐ¹ÃÜÍøÕ¾ÖÐɾ³ýÁËÓйØÌõ¿î¡£CISA ºÍ FBIÖÒ¸æ³Æ £¬Rhysida µÄ´ÓÊô»ú¹¹ÊÇÕë¶Ô¸÷Ðи÷Òµ×éÖ¯ÌáÒéµÄ¶àÆð»úÓöÐÔ¹¥»÷µÄÄ»ºóºÚÊÖ £¬¶øÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿ (HHS) ÔòÒÔΪ RhysidaÓëÕë¶ÔÒ½ÁƱ£½¡×éÖ¯µÄ¹¥»÷ÓйØ¡£


https://www.bleepingcomputer.com/news/security/pennsylvania-education-union-data-breach-hit-500-000-people/


4. ÎÚ¿ËÀ¼¾ü·½³ÉΪÐÂÒ»ÂÖSignalÍøÂç´¹µö¹¥»÷µÄÖ¸±ê


3ÔÂ19ÈÕ £¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±·´Ó³Ó××飨CERT-UA£©·¢³öÖÒ¸æ £¬Ö¸³ö½üÆÚ´æÔڸ߶ÈÕë¶ÔÐԵĹ¥»÷ £¬¹¥»÷ÕßÀûÓñ»ÈëÇÖµÄSignalÕË»§Ïò¹ú·À¹¤Òµ¹«Ë¾ºÍ¹ú¶È¾ü¶Ó³ÉÔ±·¢ËͶñÒâÈí¼þ¡£ÕâЩ¹¥»÷ʼÓÚ±¾Ô £¬Í¨¹ý¼Ù×°³É»áÒé»ã±¨µÄµµ°¸½øÐÐ £¬µµ°¸ÖÐÔ̺¬Ò»¸öPDFºÍÒ»¸ö¿ÉÖ´ÐÐÎļþ £¬ºóÕß±»Ö¤ÊµÎªDarkTortilla¼ÓÃÜÆ÷/¼ÓÔØÆ÷ £¬ÓÃÓÚ½âÃܲ¢Ö´ÐÐÔ¶³Ì½Ó¼ûľÂíDark Crystal RAT (DCRAT)¡£CERT-UAÒѽ«Õâ´Î»î¶¯ÔÚUAC-0200ϽøÐиú×Ù £¬ÕâÊÇÒ»¸ö×Ô2024Äê6ÔÂÒÔÀ´¾ÍÀûÓÃSignal½øÐÐÀàËÆ¹¥»÷µÄÍþв¼¯Èº¡£×î½üµÄ¹¥»÷ÖÐ £¬ÍøÂç´¹µöµö¶üÒѸüР£¬³ÁµãתÏòÓëÎÞÈË»ú¡¢µç×ÓսϵͳºÍÆäËû¾üʼ¼ÊõÓйصÄÖ÷Ì⡣ͬʱ £¬GoogleÍþвµý±¨Ó××é»ã±¨³Æ £¬¶íÂÞ˹ºÚ¿ÍÔÚÀÄÓÃSignalµÄ¡°Á´½ÓÉ豸¡±Ö°ÄÜÀ´Î´¾­ÊÚȨ½Ó¼û¸ÐÐËÖµÄÕÊ»§¡£Òò¶ø £¬CERT-UA½¨ÒéSignalÓû§¹Ø¹Ø¸½¼þµÄ×Ô¶¯ÏÂÔØ £¬¶ÔËùÓÐÐÂÎÅά³ÖÉóÉ÷ £¬²¢¶¨ÆÚ²é³­Á´½ÓÉ豸Áбí¡£´Ë±í £¬Óû§»¹Ó¦½«Í¨Ñ¶ÀûÓ÷¨Ê½¸üе½×îа汾 £¬²¢ÆôÓÃË«³É·ÖÉí·ÝÑéÖ¤ £¬ÒÔ¼ÓÇ¿ÕÊ»§±£»¤¡£


https://www.bleepingcomputer.com/news/security/ukrainian-military-targeted-in-new-signal-spear-phishing-attacks/


5. Arcane¶ñÒâÈí¼þÇÔÈ¡´óÁ¿Óû§Êý¾Ý £¬´«²¼·½Ê½²»ÐÝÑݱä


3ÔÂ19ÈÕ £¬Ð·¢ÏÖµÄArcaneÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þÔÚÇÔÈ¡´óÁ¿Óû§Êý¾Ý £¬Ô̺¬VPNÕÊ»§Í´´¦¡¢ÓÎÏ·¿Í»§¶Ë¡¢ÐÂÎÅÀûÓ÷¨Ê½ºÍÍøÂçä¯ÀÀÆ÷ÖеÄÐÅÏ¢¡£¸Ã¶ñÒâÈí¼þ»î¶¯Ê¼ÓÚ2024Äê11Ô £¬ÖØÒªÏ°È¾¶íÂÞ˹¡¢°×¶íÂÞ˹ºÍ¹þÈø¿Ë˹̹µÄÓû§¡£Arcaneͨ¹ýYouTubeÊÓÆµÐû´«ÓÎÏ·Îè±×ºÍÆÆ½â £¬ÓÕÆ­Óû§ÏÂÔØÊÜÃÜÂë±£»¤µÄµµ°¸ £¬ÆäÖаü·Ñ½âÏýµÄ¾ç±¾ºÍ¶ñÒâ¿ÉÖ´ÐÐÎļþ¡£¸Ã¶ñÒâÈí¼þ»¹»áΪWindows DefenderµÄSmartScreen¹ýÂËÆ÷Ôö³¤ÅųýÏî»òÆëÈ«¹Ø¹ØËü¡£ArcaneµÄ¿í·ºÊý¾ÝÇÔÈ¡ÐÐΪʹÆäÔÚ¶à¶àµÄÐÅÏ¢ÇÔÈ¡Èí¼þÖÐÍÑÓ±¶ø³ö £¬ËüÄܹ»ÇÔȡӲ¼þºÍÈí¼þ¾ßÌåÐÅÏ¢¡¢ÀûÓ÷¨Ê½ÕÊ»§Êý¾Ý¡¢ÅäÖÃÎļþÒÔ¼°ÍøÂçä¯ÀÀÆ÷ÖеĵǼÐÅÏ¢¡¢ÃÜÂëºÍcookie¡£´Ë±í £¬Arcane»¹Äܹ»²¶»ñÆÁÄ»½ØÍ¼ºÍÒѱ£ÁôµÄWi-FiÍøÂçÃÜÂ롣ϰȾArcaneÐÅÏ¢ÇÔÈ¡·¨Ê½ºó¹û²»Ê¤ÉèÏë £¬Óû§Ó¦Ê±¿Ì·þâßÏÂÔØÎ´ÊðÃûµÄµÁ°æºÍÎè±×¹¤¾ßµÄ·çÏÕ £¬²¢ÆëȫԤ·ÀʹÓÃÕâЩ¹¤¾ß¡£


https://www.bleepingcomputer.com/news/security/new-arcane-infostealer-infects-youtube-discord-users-via-game-cheats/


6. ClearFakeÀûÓÃreCAPTCHAºÍTurnstile·Ö·¢¶ñÒâÈí¼þ


3ÔÂ19ÈÕ £¬ClearFakeÊÇÒ»¸öÍþв»î¶¯¼¯Èº £¬×Ô2023Äê7Ô³õ´ÎÆØ¹âÒÔÀ´ £¬Ò»ÏòʹÓÃÐéαµÄÍøÂçä¯ÀÀÆ÷¸üС¢reCAPTCHA»òCloudflare TurnstileÑéÖ¤µÅ×Õ¶ü·Ö·¢Lumma StealerºÍVidar StealerµÈ¶ñÒâÈí¼þ¡£¸Ã»î¶¯Ñ¡È¡EtherHiding¼¼ÊõºÍClickFixÕ½Êõ £¬ÀûÓñҰ²ÖÇÄÜÁ´ºÏÔ¼»ñÈ¡ÓÐÐ§ÔØºÉ £¬Ê¹¹¥»÷Á´¸ü¾ßµ¯ÐÔ¡£×îа汾ÒýÈëWeb3Ö°ÄÜÀ´µÖ¿¹·ÖÎö²¢¼ÓÃÜHTML´úÂë¡£½ØÖÁ2024Äê5Ô £¬ClearFake¹¥»÷ÒÑϰȾ³¬¹ý9,300¸öÍøÕ¾ £¬2024Äê7ÔÂÔ¼ÓÐ200,000Ãû¶ÀÁ¢Óû§¿ÉÄÜÊܵ½¹¥»÷¡£´Ë±í £¬³¬¹ý100¼ÒÆû³µ¾­ÏúÉÌÍøÕ¾Êܵ½ClickFixµö¶ü¹¥»÷ £¬µ¼ÖÂSectopRAT¶ñÒâÈí¼þ²¿Êð¡£°²È«×êÑÐÔ±Ö¸³ö £¬ÕâЩϰȾÍùÍù²úÉúÔÚµÚÈý·½·þÎñÉÏ £¬ÈçLES AutomotiveµÄÊÓÆµ·þÎñ¡£ClearFake»¹Ó뼸ÆðÍøÂç´¹µö»î¶¯ÓйØ £¬Ö¼ÔÚÍÆ¹ã¶ñÒâÈí¼þ¼Ò×å²¢½øÐÐÆ¾Ö¤ÍøÂç¡£Ëæ×ÅÉç»á¹¤³Ì»î¶¯±äµÃÔ½À´Ô½¸´ÔÓ £¬×éÖ¯ºÍÆóÒµ±ØÐëÖ´ÐÐ׳´óµÄÉí·ÝÑéÖ¤ºÍ½Ó¼û½ÚÔì»úÔìÀ´Õмܹ¥»÷¡£


https://thehackernews.com/2025/03/clearfake-infects-9300-sites-uses-fake.html