<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>威胁棱镜</title>
    <link>https://wechat2rss.xlab.app/feed/63688861efb2362716368e36b7f8b8b61d0394a9.xml</link>
    <description>当威胁照进棱镜，谁来狩猎光谱中的攻击？&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (威胁棱镜)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM7dUwgMJQlzickTed7yuANSJCcxJMq37GFkbRbAXTphIdw/0</url>
      <title>威胁棱镜</title>
      <link>https://wechat2rss.xlab.app/feed/63688861efb2362716368e36b7f8b8b61d0394a9.xml</link>
    </image>
    <item>
      <title>IDA 插件大赛 2025</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488623&amp;idx=1&amp;sn=c370ba85ff9efdf87b1e05c5ba0a6761</link>
      <description>Hex-rays 每年都会为 IDA 举办插件大赛，每年都会涌现出各种类型的插件，来看看 2025 年有什么插件！</description>
      <content:encoded><![CDATA[<p>原创 <span>Avenger</span> <span>2026-05-11 10:25</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7687231d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FOsTASDqnFNiara4MBpFKJiaFd7lQBgmMP5pOvKEnnEqLjSRjia69ZgFV8AasRQhXlv0ISwkicW0DFRianYCgtdkelySKtSzekbcjuWqdLfypRT7E%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>Hex-rays 每年都会为 IDA 举办插件大赛，每年都会涌现出各种类型的插件，来看看 2025 年有什么插件！</p>
  <p data-pm-slice="0 0 []"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Hex-rays </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">每年都会为</span><span lang="EN-US"><span leaf=""> IDA </span></span><span leaf="">举办插件大赛，该大赛每年都会涌现出各种类型的插件，有安全团队也有个人安全研究员，为了解决各种问题从而开发各种插件。</span><span lang="EN-US"><span leaf="">2025 </span></span><span leaf="">年的插件大赛一共入围了二十五款插件。延宕延宕再延宕后，评审团最终评出的前三名为：</span></span></p><p><span leaf="">🥇 </span><span lang="EN-US" style="font-size:12.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:
minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:
AR-SA;" data-pm-slice="0 0 []"><span leaf="">iOSHelper</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:
minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:
AR-SA;" data-pm-slice="0 0 []"><span lang="EN-US" style="font-size:12.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:
minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:
AR-SA;" data-pm-slice="0 0 []"><span leaf="">iOSHelper </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;"><span leaf="">是对 </span><span lang="EN-US"><span leaf="">iOS </span></span><span leaf="">平台的二进制文件进行逆向分析的工具包，在微码级进行调整生成更简洁的伪代码，减轻了对 </span><span lang="EN-US"><span leaf="">iOS </span></span><span leaf="">平台进行漏洞研究的负担。</span></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:
minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:
AR-SA;" data-pm-slice="0 0 []"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.43121387283236995" data-type="png" data-w="865" data-imgfileid="100004964" src="https://wechat2rss.xlab.app/img-proxy/?k=4e0d9bb8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgmVDDt75cElKxwPgVkpFOUpSyUcMViaffB7hh5E1SibC1YtZE7zibt4H7L1V3XFzQJ03mjboGY1CgfXtu1MaS8m3rLnKbiaic9e2w0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p><span leaf="">🥈 </span><span lang="EN-US" style="font-size:12.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:
minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:
AR-SA;" data-pm-slice="0 0 []"><span leaf="">BinSync</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:
minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:
AR-SA;" data-pm-slice="0 0 []"><span lang="EN-US" style="font-size:12.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:
minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:
AR-SA;" data-pm-slice="0 0 []"><span leaf="">BinSync </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;"><span leaf="">是一个逆向工程协作工具，基于 </span><span lang="EN-US"><span leaf="">git </span></span><span leaf="">和 </span><span lang="EN-US"><span leaf="">LibBS </span></span><span leaf="">构建，可同步包括注释在内的各种信息。团队成员无论是使用 </span><span lang="EN-US"><span leaf="">IDA</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Ghidra </span></span><span leaf="">还是 </span><span lang="EN-US"><span leaf="">Binary Ninja</span></span><span leaf="">，都可以通过 </span><span lang="EN-US"><span leaf="">BinSync </span></span><span leaf="">进行协作。</span></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:
minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:
AR-SA;" data-pm-slice="0 0 []"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6069364161849711" data-type="png" data-w="865" data-imgfileid="100004965" src="https://wechat2rss.xlab.app/img-proxy/?k=f193b65f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjPGUs0S8bsr2qxOqibRiaJUibTBogzG769BOqmicbgWLM3D0urLASDNQHn5CVQqblicTS3uH1p2qm7uM5ckbflib1qgVxKFhf83vbuE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span leaf="">🥉 </span><span lang="EN-US" style="font-size:12.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:
minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:
AR-SA;" data-pm-slice="0 0 []"><span leaf="">CrystalRE</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:
minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:
AR-SA;" data-pm-slice="0 0 []"><span leaf="">CrystalRE </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;"><span leaf="">是用于对 </span><span lang="EN-US"><span leaf="">Crystal </span></span><span leaf="">编程语言生成的二进制文件进行逆向分析的工具。由于 </span><span lang="EN-US"><span leaf="">Crystal </span></span><span leaf="">的符号与运行时结构很复杂，该插件可以大大帮助简化对 </span><span lang="EN-US"><span leaf="">Crystal </span></span><span leaf="">二进制文件的分析。</span></span></p><p><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6138728323699422" data-type="png" data-w="865" data-imgfileid="100004966" src="https://wechat2rss.xlab.app/img-proxy/?k=3ff43e68&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjfKcK5Cmqpou8RQCP2KTqfDgSj9PgeY8ianuGByfCUxbgPzibsEtX7xUe3B4hvbraNK7WebW78JGhN5UrE8uFBSJlicuxKAmfnqU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf="">评审团最终还选出了四个新秀：</span></span></p><p data-pm-slice="0 0 []"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">🏅 </span><span leaf="">HappyIDA</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;"><span leaf="">该插件是为反编译器增加易用功能的，例如函数导航、剪贴板助手、</span><span lang="EN-US"><span leaf="">Rust</span></span><span leaf="">字符串美化等。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004968" data-ratio="0.44739884393063584" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=0c030762&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgUTGpcRngiaZBQQTCaPLRAibg8P8CFwqPE6CVACViaziaeO4fj1ibcP1osRic006gLNPHoozBIFZohxwGwXerVXSqMhU2525bweKUw0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf="">🏅 </span><span lang="EN-US" style="font-size:12.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:
minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:
AR-SA;" data-pm-slice="0 0 []"><span leaf="">EmuIt</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:
minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:
AR-SA;" data-pm-slice="0 0 []"><span leaf="">Emult </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;"><span leaf="">是基于</span><span lang="EN-US"><span leaf=""> Unicorn </span></span><span leaf="">构建的</span><span lang="EN-US"><span leaf=""> IDA Pro </span></span><span leaf="">模拟器，支持定位恶意软件中的解密函数并获取所有解密后的字符串等功能。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6404624277456648" data-type="png" data-w="865" data-imgfileid="100004969" src="https://wechat2rss.xlab.app/img-proxy/?k=e74c2dbf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaM0jUpW0r8YMMibDM0vw83iczrTI12ViaibC2EehenVBZVZT1Wa1JxePwicqJ47icmkWlQxcT6ROwibefne39kudRuicOoccs5LibYGACQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span leaf="">🏅 </span><span lang="EN-US" style="font-size:12.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:
minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:
AR-SA;" data-pm-slice="0 0 []"><span leaf="">Sharingan</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf="">简化进行反混淆和字符串</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">数据解密操作的插件，可视化操作对用户十分友好。</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004970" data-ratio="0.5375722543352601" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=3921844b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjXzmchTyqIRC2ezFPCj0frbEWxbNahMgnCOvdvXCxzTBQNZE02B9QPxAvkQlLbDqpSWqFQW5iaAaAUSKic0MChtYsicj85SvL4So%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf="">🏅 </span><span lang="EN-US" style="font-size:12.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:
minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:
AR-SA;" data-pm-slice="0 0 []"><span leaf="">Yarka</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf="">根据用户选定的内容，自动创建 </span><span lang="EN-US"><span leaf="">Yara </span></span><span leaf="">签名。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004971" data-ratio="0.7583815028901734" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=746b95de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgOcyqwsOyTD7FqExpRGtick50Iw5BUhuicaaIiaQSiaFGHsfn0ZARccljD7qSshCJEqUp5wczcdXfudfuJbCkot7clGkibBgpiax28I%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf="">以下是本届插件大赛上二十五款插件的简要介绍：</span></span></p><table interlaced="enabled" style="border-collapse:collapse;border:none;mso-border-alt:solid windowtext .5pt;mso-yfti-tbllook:1184;mso-padding-alt:0cm 5.4pt 0cm 5.4pt;"><tbody><tr class="ue-table-interlace-color-single" style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border: 1pt solid windowtext;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">插件</span></span></span></p></td><td data-colwidth="120" width="120" valign="middle" align="center" style="border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: windowtext windowtext windowtext currentcolor;border-image: initial;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">开发者</span></span></span></p></td><td data-colwidth="279" width="279" valign="middle" align="center" style="border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: windowtext windowtext windowtext currentcolor;border-image: initial;padding: 0cm 5.4pt;"><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><span textstyle="" style="font-weight: bold;">简介</span></span></span></p></td></tr><tr class="ue-table-interlace-color-double" style="mso-yfti-irow:1;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">BinSync</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">mahaloz,   angr team, SEFCOM Lab @ ASU</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">基于</span><span lang="EN-US"><span leaf="">Git</span></span><span leaf="">的跨分析工具（</span><span lang="EN-US"><span leaf="">IDA</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Binary   Ninja</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Ghidra </span></span><span leaf="">和</span><span lang="EN-US"><span leaf="">   angr-management</span></span><span leaf="">）协作逆向分析插件</span></span></p></td></tr><tr class="ue-table-interlace-color-single" style="mso-yfti-irow:2;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">CrystalRE</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Nico   Posada</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">对  </span><span lang="EN-US"><span leaf="">Crystal </span></span><span leaf="">语言二进制文件进行反编译等逆向分析</span></span></p></td></tr><tr class="ue-table-interlace-color-double" style="mso-yfti-irow:3;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">DeepExtract</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Marcos   Oviedo</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通过</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">大模型提取</span><span lang="EN-US"><span leaf="">PE </span></span><span leaf="">结构、反编译和交叉引用</span></span></p></td></tr><tr class="ue-table-interlace-color-single" style="mso-yfti-irow:4;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">DrawIDA</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">idkhidden</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">IDA  </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">内可用的轻量级白板</span></span></p></td></tr><tr class="ue-table-interlace-color-double" style="mso-yfti-irow:5;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">drop   all the files</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Milan   Boháček</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">将文件拖放到</span><span lang="EN-US"><span leaf=""> IDA </span></span><span leaf="">窗口中，插件就会根据文件类型自动处理</span></span></p></td></tr><tr class="ue-table-interlace-color-single" style="mso-yfti-irow:6;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Driver   Buddy Revolutions</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Juan   Sacco</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">快速</span><span lang="EN-US"><span leaf=""> Windows </span></span><span leaf="">内核驱动程序分类插件</span></span></p></td></tr><tr class="ue-table-interlace-color-double" style="mso-yfti-irow:7;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">EmuIt</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">AzzOnFire</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">基于</span><span lang="EN-US"><span leaf=""> Unicorn </span></span><span leaf="">构建的</span><span lang="EN-US"><span leaf=""> IDA </span></span><span leaf="">模拟器</span></span></p></td></tr><tr class="ue-table-interlace-color-single" style="mso-yfti-irow:8;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">enums   helper</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Milan   Boháček</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">简化重命名</span><span lang="EN-US"><span leaf=""> (N)</span></span><span leaf="">、添加</span><span lang="EN-US"><span leaf=""> (A)</span></span><span leaf="">、添加到最近</span><span lang="EN-US"><span leaf="">   (Shift-A)</span></span><span leaf="">操作</span></span></p></td></tr><tr class="ue-table-interlace-color-double" style="mso-yfti-irow:9;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">export   scripts</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Milan   Boháček</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">将脚本片段导出到</span><span lang="EN-US"><span leaf=""> Git </span></span><span leaf="">存储库</span></span></p></td></tr><tr class="ue-table-interlace-color-single" style="mso-yfti-irow:10;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">FeelingLucky</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">terrynini</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">跳转到二进制文件中的随机函数，使用户可以进行无引导的探索</span></span></p></td></tr><tr class="ue-table-interlace-color-double" style="mso-yfti-irow:11;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">FindYara-X</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Milan   Boháček</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">基于</span><span lang="EN-US"><span leaf="">findcrypt-yara</span></span><span leaf="">使用</span><span lang="EN-US"><span leaf=""> YARA-X </span></span><span leaf="">规则扫描已加载的二进制文件，并直接跳转到每个匹配的偏移量</span></span></p></td></tr><tr class="ue-table-interlace-color-single" style="mso-yfti-irow:12;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">HappyIDA</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">HappyIDA   team</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">多个反编译工具的工具包</span></span></p></td></tr><tr class="ue-table-interlace-color-double" style="mso-yfti-irow:13;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">HexLens</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Steven   H. H. Ding</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">大模型通过带标签的图数据库对整个二进制文件进行推理</span></span></p></td></tr><tr class="ue-table-interlace-color-single" style="mso-yfti-irow:14;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">IDA-Spotlight</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Askar   Dyussekeyev</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通过可配置的模式匹配与历史样本相关检查，发现大型二进制文件中的高价值函数</span></span></p></td></tr><tr class="ue-table-interlace-color-double" style="mso-yfti-irow:15;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">ida-security-scanner</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Anthony   Bondu, Symbiotic Security</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">提取伪代码，对其运行</span><span lang="EN-US"><span leaf=""> opengrep </span></span><span leaf="">规则，并在</span><span lang="EN-US"><span leaf=""> IDA </span></span><span leaf="">中显示结果，并提供可选的</span><span lang="EN-US"><span leaf=""> AI </span></span><span leaf="">解释</span></span></p></td></tr><tr class="ue-table-interlace-color-single" style="mso-yfti-irow:16;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">idashare</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">idkhidden</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通过本地</span><span lang="EN-US"><span leaf=""> HTTP </span></span><span leaf="">服务器共享已加载的二进制文件和</span><span lang="EN-US"><span leaf=""> IDA </span></span><span leaf="">数据库</span></span></p></td></tr><tr class="ue-table-interlace-color-double" style="mso-yfti-irow:17;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">iOSHelper</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Yoav   Sternberg</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">适用于</span><span lang="EN-US"><span leaf=""> IDA Pro 9.0+ </span></span><span leaf="">的</span><span lang="EN-US"><span leaf=""> iOS </span></span><span leaf="">分析工具包</span></span></p></td></tr><tr class="ue-table-interlace-color-single" style="mso-yfti-irow:18;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">ReCopilot</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Ch3nYe   (XingTuLab)</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">用于代码推理和同源代码搜索等功能的</span><span lang="EN-US"><span leaf=""> AI </span></span><span leaf="">二进制分析助手</span></span></p></td></tr><tr class="ue-table-interlace-color-double" style="mso-yfti-irow:19;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">REcover</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Chariton   Karamitas</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">从</span><span lang="EN-US"><span leaf="">stripped</span></span><span leaf="">的二进制文件中近似生成编译单元布局</span></span></p></td></tr><tr class="ue-table-interlace-color-single" style="mso-yfti-irow:20;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">renimp</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Milan   Boháček</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Milan   Boháček</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">的多个工具</span></span></p></td></tr><tr class="ue-table-interlace-color-double" style="mso-yfti-irow:21;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Sharingan</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Huy   Minh (n0pex3)</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">可配置的反混淆和解密插件</span></span></p></td></tr><tr class="ue-table-interlace-color-single" style="mso-yfti-irow:22;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Super   Pseudo</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Oliver   Stankiewicz</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">伪代码中内联函数调用的深度递归</span></span></p></td></tr><tr class="ue-table-interlace-color-double" style="mso-yfti-irow:23;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">tc_deer</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">arkup</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">适用于</span><span lang="EN-US"><span leaf=""> IDA Pro </span></span><span leaf="">的 </span><span lang="EN-US"><span leaf="">Tricore </span></span><span leaf="">反编译器</span></span></p></td></tr><tr class="ue-table-interlace-color-single" style="mso-yfti-irow:24;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Yarka</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">AzzOnFire</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">无依赖</span><span lang="EN-US"><span leaf="">Yara</span></span><span leaf="">规则生成工具</span></span></p></td></tr><tr class="ue-table-interlace-color-double" style="mso-yfti-irow:25;mso-yfti-lastrow:yes;"><td data-colwidth="155" width="155" valign="middle" align="center" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">zydisinfo</span></span></p></td><td data-colwidth="120" width="120" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Milan   Boháček</span></span></p></td><td data-colwidth="279" width="279" valign="middle" style="border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor windowtext windowtext currentcolor;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">基于</span><span lang="EN-US"><span leaf="">Zydis</span></span><span leaf="">在光标处显示详细的指令信息</span></span></p></td></tr></tbody></table><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;" data-pm-slice="0 0 []"><span leaf="">点击查看原文跳转</span><span lang="EN-US"><span leaf=""> Hex-Rays </span></span><span leaf="">官网。</span></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://hex-rays.com/plugin-contest/2025">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f72e5764&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488623%26idx%3D1%26sn%3Dc370ba85ff9efdf87b1e05c5ba0a6761">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 11 May 2026 10:25:00 +0800</pubDate>
    </item>
    <item>
      <title>威胁情报生态系统的产出与共享</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488610&amp;idx=1&amp;sn=de9310c0ae3396cb8c0cd9d5559c3f40</link>
      <description>生态系统中威胁情报是如何传递的？谁在产出和消费？</description>
      <content:encoded><![CDATA[<p>原创 <span>Avenger</span> <span>2026-04-13 09:04</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c7237e20&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FOsTASDqnFNiaxExibplTa1awAWAXaG8twVfbFTHsJ2GPHL07IQ7drasydLsPXSX39SMvBqD5qfz14XCnVRxMmbMbjUHD9jFsBkdicibScy0xtjY%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>生态系统中威胁情报是如何传递的？谁在产出和消费？</p>
  <p data-pm-slice="0 0 []"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作来源</span></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">NDSS 2026</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作背景</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">威胁情报市场正以惊人的速度增长，预计到</span><span lang="EN-US"><span leaf="">2026</span></span><span leaf="">年将超过</span><span lang="EN-US"><span leaf="">150</span></span><span leaf="">亿美元。这个生态系统由全球分布的安全厂商、沙箱、杀软引擎和独立贡献者组成，他们通过分析恶意二进制文件、钓鱼网站等提取</span><span lang="EN-US"><span leaf="">IOC</span></span><span leaf="">并进行共享。针对整个威胁情报</span><span leaf="">供应链的拓扑结构、瓶颈节点以及攻击者如何利用该生态的盲区进行逃避，业界缺乏系统性的定量认知。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作准备</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">选取了威胁情报平台（如</span><span lang="EN-US"><span leaf="">VirusTotal</span></span><span leaf="">等）、反病毒厂商（如</span><span lang="EN-US"><span leaf="">Kaspersky</span></span><span leaf="">等）、沙盒服务商（如</span><span lang="EN-US"><span leaf="">Any.Run</span></span><span leaf="">等）共三大类的</span><span lang="EN-US"><span leaf="">30</span></span><span leaf="">家厂商。由于商业保密协议，厂商间共享数据的关系是不会对外公开的。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.3364161849710983" data-type="png" data-w="865" data-imgfileid="100004909" src="https://wechat2rss.xlab.app/img-proxy/?k=d99edca1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjCDib80JQGTKkQxFXtrSr5YxWYCrPm45XibsQ1ibfaHIalu3lWENRjagd8vyOIn9N7f8LibrvicvU16pn6PfAVFXdR61rt9CtvWwKE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作设计</span></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6358381502890174" data-type="png" data-w="865" style="width:504px;height:320px;" data-imgfileid="100004910" src="https://wechat2rss.xlab.app/img-proxy/?k=faaf80cb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNh4dqwmgyAic0LQibibXia1DDs3cqLf9qo8EDxRY441JXln4uVIUP77Uicicdwm12fRz4HFjlMjIhhBSkuZH5PGqNOpriaUgKuicnzicvAA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">研究人员生成无害但具备可疑行为的二进制文件，程序文件会在运行时将系统环境的指纹与执行</span><span lang="EN-US"><span leaf="">ID</span></span><span leaf="">编码在子域名中，通过</span><span lang="EN-US"><span leaf="">HTTP</span></span><span leaf="">请求发送出来。除了网络行为外，二进制文件也会释放副本文件，沙盒如果继续执行副本文件的话，发出的网络请求也会带上父文件信息。外传的信息是基于前人的研究选取的一些特征：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6369942196531792" data-type="png" data-w="865" style="width:474px;height:302px;" data-imgfileid="100004911" src="https://wechat2rss.xlab.app/img-proxy/?k=59b17b7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjne6UrLxxh4XGz781LbMrKT0Fb4dBSByoHgTty6tKDicUoLZ0bY4TZTdnKGhzctx0ZX1KSl6BPx8cwrXYaOIJHXUNKHx7iaFhHs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在自有服务器收集这些发送出来的请求，并且轮询开放的安全信誉列表，查看这些域名与</span><span lang="EN-US"><span leaf="">IP</span></span><span leaf="">什么时候会被拉黑。包括（</span><span lang="EN-US"><span leaf="">1</span></span><span leaf="">）</span><span lang="EN-US"><span leaf="">Google Safe Browsing </span></span><span leaf="">或者</span><span lang="EN-US"><span leaf="">FireHol</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">2</span></span><span leaf="">）</span><span lang="EN-US"><span leaf="">Quad9</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Google</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Cloudflare</span></span><span leaf="">或</span><span lang="EN-US"><span leaf=""> Palo Alto DNS Security</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">3</span></span><span leaf="">）</span><span lang="EN-US"><span leaf="">VirusTotal </span></span><span leaf="">或</span><span lang="EN-US"><span leaf=""> AlienVault Open Threat Exchange</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">4</span></span><span leaf="">）一家商业威胁情报供应商。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17572254335260115" data-type="png" data-w="865" data-imgfileid="100004912" src="https://wechat2rss.xlab.app/img-proxy/?k=98bc4c2b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhtBGFNKa0bKzSV6ickEicPKb56tYkGHFltNBia3cvUDicpwR4tPibiaWbee3OBZWfhCAg9q7LDCPaY6j9y0j51tYLYTOV1kM5IIic3LY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">如</span><span lang="EN-US"><span leaf="">EXT-DE-2</span></span><span leaf="">从</span><span lang="EN-US"><span leaf="">EXT-TI-3</span></span><span leaf="">接收了</span><span lang="EN-US"><span leaf="">Satelite A1</span></span><span leaf="">，执行后生成了</span><span lang="EN-US"><span leaf="">Satelite A2</span></span><span leaf="">，又将</span><span lang="EN-US"><span leaf="">Satelite A2</span></span><span leaf="">共享给</span><span lang="EN-US"><span leaf="">EXT-TI-3</span></span><span leaf="">。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作评估</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">威胁情报平台对样本的执行次数，要远高于沙盒厂商与反病毒引擎厂商。并且，威胁情报平台在多个国家</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">地区都执行了样本，带来了更大的地域多样性。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9260115606936417" data-type="png" data-w="865" style="width:495px;height:458px;" data-imgfileid="100004913" src="https://wechat2rss.xlab.app/img-proxy/?k=34fce0b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhiaxKhks5fOtLQrv0pX8wTeEPvUy7N4JjjKEicHyt6quZdw4QJUaCoqeSZqTj79mRKNa9LIQmO5xQEmNXicPCCM0k04STRD3iaGxY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">聚类发现了将一个供应商拆分成了不同的簇，而没有发现将多个簇归类为同一个供应商。这也是生态系统健康的标志，厂商在尽量提供多样性。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.31676300578034683" data-type="png" data-w="865" style="width:392px;height:124px;" data-imgfileid="100004914" src="https://wechat2rss.xlab.app/img-proxy/?k=72fbd441&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjpt7M5H4SxSB4fOyHbzkoAKAwoEjLcOrL6DHbWeDR26F2xPrG9icqDN6jcj2u4ut1vblRWWDrL3b6tchkL3ibGqN5MuBWIWhcJU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">大多数厂商只有</span><span lang="EN-US"><span leaf="">3</span></span><span leaf="">种以内的执行环境，且大多数尽管执行环境不同但部署的位置是相同的。虽然</span><span lang="EN-US"><span leaf=""> 67% </span></span><span leaf="">的厂商会进行动态分析，但绝大多数厂商根本不执行释放的子文件。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.608092485549133" data-type="png" data-w="865" style="width:452px;height:275px;" data-imgfileid="100004915" src="https://wechat2rss.xlab.app/img-proxy/?k=a389ad86&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgwJ10ic8SODLrIedKo6h5soEJZxYI9Yqic1NlbxgFshIIVeWPMv4qja9rU6aQTlSq11G1qD83SHphPRY68clNeAc1vnJO9VKhlw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">只有约</span><span lang="EN-US"><span leaf=""> 16% </span></span><span leaf="">的厂商愿意向外共享威胁情报。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.44739884393063584" data-type="png" data-w="865" data-imgfileid="100004916" src="https://wechat2rss.xlab.app/img-proxy/?k=856c8331&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjJjjahbJpHaz3h32icjooHjyInvWOV7UDckMVx1WRyLbeicPUDuckjic59KZxTRp7Xc3oiajVwB5UwAIbK68qWqwM7nia01ddVx0P8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">生态系统高度依赖</span><span lang="EN-US"><span leaf=""> 4 </span></span><span leaf="">家核心</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">枢纽厂商</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">，</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">其他大多数厂商和沙盒只</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">消费</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">不</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">贡献</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">。杀软引擎厂商通常不共享数据，威胁情报平台则大量共享数据。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.2549476135040745" data-type="png" data-w="859" style="width:328px;height:412px;" data-imgfileid="100004917" src="https://wechat2rss.xlab.app/img-proxy/?k=d08d4f6e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgdF8J1Ml1GZgQuB1c1WarvCRPSmNYQ9AxlRky0Lalgey3TnpQ6dOooktYzrM7kQnGicPyrwGfGP4kpjuTOzL9iat1afHq7D7ccM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">域名</span><span lang="EN-US"><span leaf="">/URL</span></span><span leaf="">等网络 </span><span lang="EN-US"><span leaf="">IOC </span></span><span leaf="">的共享频率远远高于二进制文件本身。并且，对网络</span><span lang="EN-US"><span leaf="">IOC</span></span><span leaf="">的探查也更加频繁。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.36878612716763004" data-type="png" data-w="865" style="width:478px;height:176px;" data-imgfileid="100004918" src="https://wechat2rss.xlab.app/img-proxy/?k=5e370fc7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiasC1zDbCPtvtlp7ZlQqm5ttiaCj9dnL1NFOo3OsC3OIaw7iaGeFvkmvtRWicCIrJyz4VNYbbBBvibYGsHMA7dMBhnTdHvOjPaicFzA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">虽然沙盒提取</span><span lang="EN-US"><span leaf="">IOC </span></span><span leaf="">只要几分钟，但因为枢纽厂商的延迟，威胁情报的共享往往需要几个小时甚至几天。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9942196531791907" data-type="png" data-w="865" style="width:541px;height:538px;" data-imgfileid="100004919" src="https://wechat2rss.xlab.app/img-proxy/?k=98e6b2f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNguezgJ3DBu0XwRKUAjj7iaiaibC4UibLTZmxq5FjQZT2NmJV8V4EYT6H7I2qg8E5cEoEhQ2LHqTAcGr3icrOGIEnbEMeGrgYFHyXZE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.2242774566473988" data-type="png" data-w="865" style="width:472px;height:578px;" data-imgfileid="100004920" src="https://wechat2rss.xlab.app/img-proxy/?k=97e973fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgH7vRRmUK59gOIuXJVKiaBEEtOt9aRAsdEBuzNRzu0RgNCwhrMRNUONge4Xcav7cdUB2tgLFKb1jvjHHQ9888vrCCrUNCyEdys%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">域名黑名单要间隔数小时，彻底的域名封禁平均需要</span><span lang="EN-US"><span leaf=""> 10 </span></span><span leaf="">天以上。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4890173410404624" data-type="png" data-w="865" style="width:511px;height:250px;" data-imgfileid="100004921" src="https://wechat2rss.xlab.app/img-proxy/?k=be380df6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaDIAyjaM0Bv52ByVn4Q6qZDmzAmxgQg0Va2qVcdcheIOgvP3qiaZ5z6FmD5Kp2UZVvpNicXQOzNbwKRicicTleOCxeMQibd9wFCiaDE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通过威胁情报共享，在厂商间进行共享，最终走向封禁的过程如下所示。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5028901734104047" data-type="png" data-w="865" data-imgfileid="100004922" src="https://wechat2rss.xlab.app/img-proxy/?k=a8ee5007&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjFsxO8K5lzEshEicw1x1bJib3HGDuL20ZicTTjfX3ysntMu5qMbpKVPwMw3xMfyr1sMvTzPyZZxqsd1FYaddjz5rZClywKlkFHL0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">大多数免费沙盒的</span><span lang="EN-US"><span leaf=""> IP </span></span><span leaf="">和系统特征常年不变。在</span><span lang="EN-US"><span leaf=""> VirusTotal </span></span><span leaf="">上通过</span><span lang="EN-US"><span leaf=""> Yara </span></span><span leaf="">规则回溯，发现了</span><span lang="EN-US"><span leaf=""> 800 </span></span><span leaf="">多个真实的恶意软件样本正在主动核对开源的“沙盒</span><span lang="EN-US"><span leaf=""> IP </span></span><span leaf="">黑名单”以进行检测规避。测试显示，哪怕只去掉一个沙盒</span><span lang="EN-US"><span leaf=""> IP</span></span><span leaf="">，下游厂商收到情报的概率就会暴跌</span><span lang="EN-US"><span leaf=""> 60%</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.26936416184971096" data-type="png" data-w="865" data-imgfileid="100004923" src="https://wechat2rss.xlab.app/img-proxy/?k=07eb6649&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNja39p5cfvH16icg33GEu8PnAGkZ1xvPXicAaLtsUU7BDMhYmyeiciajCcic8mKvZJ5znGblfQXFhQkILBD25KkibXdVyWGrTepia7cNw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">研究人员给样本加上常见的</span><span lang="EN-US"><span leaf="">UPX</span></span><span leaf="">壳后，厂商的执行率骤降了</span><span lang="EN-US"><span leaf=""> 35%</span></span><span leaf="">。很多厂商直接给出了</span><span lang="EN-US"><span leaf="">Dropper</span></span><span leaf="">的判定，但并没有实际去脱壳与分析该样本，导致大量</span><span lang="EN-US"><span leaf="">TTP</span></span><span leaf="">情报白白流走。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.0173410404624277" data-type="png" data-w="865" style="width:454px;height:462px;" data-imgfileid="100004924" src="https://wechat2rss.xlab.app/img-proxy/?k=02ae4258&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNj5XTNziafibOY6TlicMOS9SvibOyWSIKZ8NfubcFEpZQMwlfcepW7rNjSggCBxibs9K2V9urlgnjOgCS3odkyLicTs58Vdvm4DT5QKc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作思考</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">独家的高质量威胁情报是安全公司的核心护城河，没有厂商会愿意白白把有价值的内容分享给别人。由于恶意样本量的激增，厂商为了维持分析的吞吐量，也不得不牺牲深度脱壳与执行分析的能力。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.225" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100004925" src="https://wechat2rss.xlab.app/img-proxy/?k=8f1f3ebe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaO1dCHBjZdqGTjIqnia2D2gtia9zUoPBdWpaGnXakPKlicd6nrKrOZzGgkS6x0ib3V0NRDtwqRUwSJJEiaMtkBlVSdWd23tWDtE05c%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e48963cc&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488610%26idx%3D1%26sn%3Dde9310c0ae3396cb8c0cd9d5559c3f40">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 13 Apr 2026 09:04:00 +0800</pubDate>
    </item>
    <item>
      <title>基于视觉大模型的图像地理定位</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488609&amp;idx=1&amp;sn=1cc2853e400a3d5797944817f3f15467</link>
      <description>线上一张照片就能按图索骥线下找到真人吗？</description>
      <content:encoded><![CDATA[<p>原创 <span>Avenger</span> <span>2026-04-10 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=987e6110&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FOsTASDqnFNiaYO63KkeofVZp11fCDlE3bFppOcLuFM08M5iaJqJIFbZPJbdy0B6oK0Kc9cWfGzkUEJN6CHqHuoFhp1Yl7rFjlibqlSdmquTzS0%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>线上一张照片就能按图索骥线下找到真人吗？</p>
  <p data-pm-slice="0 0 []"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作来源</span></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">PETS 2025</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作背景</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在 </span><span lang="EN-US"><span leaf="">OSINT </span></span><span leaf="">开源情报分析领域，通过图片来确定拍摄位置一直是一项高级技能。那么多模态的视觉大语言模型，可不可以基于已有的知识实现这一判断呢？将图片的元数据（</span><span lang="EN-US"><span leaf="">EXIF </span></span><span leaf="">的 </span><span lang="EN-US"><span leaf="">GPS </span></span><span leaf="">坐标等）剥离，仍可以通过图片本身的内容来判断地理与时间细节。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.500578034682081" data-type="png" data-w="865" style="width:415px;height:208px;" data-imgfileid="100004941" src="https://wechat2rss.xlab.app/img-proxy/?k=aefd37c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNg6zyN4ovibt73HqYxmhOAEuN6GRUKR6SYMgwicZTo5s9rvnzzOibXb9WQ4ohOQN7RnFZVEeBwSgI1P96vG8ib1vytWVyWPmbUXVog%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作准备</span></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.30289017341040464" data-type="png" data-w="865" style="width:409px;height:124px;" data-imgfileid="100004940" src="https://wechat2rss.xlab.app/img-proxy/?k=76602739&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNg4ExgtEmmtVPSFNy2TBy8JAANceP1Oq08SJ4ILvrDibDRd0NYBnpbq5q6piboJVXdrXQglbKVzWrdd3oA4ZavYR2sAn9XFicoJCs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">模型准备</span></span></b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">：挑选了过去三年内最前沿的模型，包括传统视觉模型（</span><span lang="EN-US"><span leaf="">StreetClip, GeoClip</span></span><span leaf="">）、开源</span><span lang="EN-US"><span leaf=""> LVLM</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">LLaVA</span></span><span leaf="">）、闭源商业巨头（</span><span lang="EN-US"><span leaf="">GPT-4o</span></span><span leaf="">）以及专用的商业定位工具（</span><span lang="EN-US"><span leaf="">GeoSpy</span></span><span leaf="">）。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.33179190751445087" data-type="png" data-w="865" data-imgfileid="100004939" src="https://wechat2rss.xlab.app/img-proxy/?k=726f7ba3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaqg0KNJW1vKpuvh1bFKKfZicuNGDBRezB1iaDNoa9nttT8lPcpdJG0iagt2A1Xb454ncsTbyJR0zsXKI08FsPiaAd81RSbdMJZWks%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">图片准备</span></span></b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">：现有数据集（</span><span lang="EN-US"><span leaf="">Im2GPS, YFCC26k </span></span><span leaf="">等）中有很多图片不适合该场景使用，研究人员构建了一个 </span><span lang="EN-US"><span leaf="">5 </span></span><span leaf="">万张图片的全新数据集。数据集以国家领土面积作为权重，从</span><span lang="EN-US"><span leaf=""> Google Street View </span></span><span leaf="">进行全球随机采样，确保非洲、南美等常被忽视的地区也能被覆盖。利用</span><span lang="EN-US"><span leaf=""> GPT-4o </span></span><span leaf="">对每一张抓取的图像生成描述，通过关键词过滤掉所有“室内”、“严重遮挡”、“无特征（如纯天空</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">纯地面）”的无效图片。最后还引入了人类专家进行</span><span lang="EN-US"><span leaf=""> 1000 </span></span><span leaf="">张图像的抽样双盲验证（</span><span lang="EN-US"><span leaf="">Kappa </span></span><span leaf="">一致性高达</span><span lang="EN-US"><span leaf=""> 0.82</span></span><span leaf="">）。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.35260115606936415" data-type="png" data-w="865" style="width:469px;height:165px;" data-imgfileid="100004938" src="https://wechat2rss.xlab.app/img-proxy/?k=9deca591&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjMLicnKn4RtyUe2EDheZvTln6fzfxO0iaIRxDndvrI4mlYpVH7LmhrmrMlxwDfFAl70V0XOjQ7G9oUDHDjaWEobZ1Q8okV3AW1w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作设计</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">原生</span><span lang="EN-US"><span leaf=""> LVLM </span></span><span leaf="">具备一定的识别能力，但往往极度依赖</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">标志性建筑</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">，在面对普通街景时表现不佳。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3722543352601156" data-type="png" data-w="865" data-imgfileid="100004937" src="https://wechat2rss.xlab.app/img-proxy/?k=873a4fb2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhNk6ODT87Fcvs4yQPhYBD3beWr30SGhOesFybIAmibMEzSFFOk9UibObHGAlnAZfzmibz0Xy9j8lNVr4ia8DAhfE4HicyIFUwVBj2U%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">为了探究</span><span lang="EN-US"><span leaf=""> LVLM </span></span><span leaf="">攻击的</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">破坏力上限</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">，研究人员提出了一个增强型攻击框架</span><span lang="EN-US"><span leaf="">ETHAN</span></span><span leaf="">。其核心有两大技术：</span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">基于领域数据的微调</span></span></b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">： 使用 </span><span lang="EN-US"><span leaf="">GEOLOCATIONHUB </span></span><span leaf="">中 </span><span lang="EN-US"><span leaf="">3 </span></span><span leaf="">万张带有详细地理描述的图像对 </span><span lang="EN-US"><span leaf="">LVLM </span></span><span leaf="">进行有监督微调，使其真正具备处理全球街景特征的底层视觉直觉。</span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">“专家”级思维链提示工程</span></span></b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">： 研究人员深入分析了</span><span lang="EN-US"><span leaf=""> GeoGuessr</span></span><span leaf="">（著名地理盲猜游戏）人类顶级玩家的思维模式，并将其固化为一段结构化的思维链提示词。</span><span lang="EN-US"><span leaf="">ETHAN </span></span><span leaf="">强制要求大模型在给出最终经纬度之前，必须按顺序从以下四个维度进行分析：</span></span></p><p style="margin-bottom: 8px;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">① 基础设施：分析道路标线颜色、路标语言</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">形状、电线杆样式和车牌特征；</span></span></p><p style="margin-bottom: 8px;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">② 自然元素：分析土壤颜色、植被类型（温带树木还是热带棕榈）、地形地貌（高山、海岸、沙漠）；</span></span></p><p style="margin-bottom: 8px;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">③ 车辆分析：分析常见车型、方向盘位置，甚至涉水喉（说明多雨涝）和生锈模式（说明沿海高盐）；</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">④ 文化指标：分析建筑材料、店铺招牌、路人服饰和涂鸦风格。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作评估</span></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.37803468208092483" data-type="png" data-w="865" data-imgfileid="100004936" src="https://wechat2rss.xlab.app/img-proxy/?k=0e66e69e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaUTA0uiblXV6s6qFB0mOr8erexoAHPvMXbNSG1P2JvaQeAYLiczXSbsnPu7j4NAXhdYQ9kmJyCalUoe0NiahGRxTDhJopHz6RnTI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">超越他人的准确度</span></span></b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">： 在 </span><span lang="EN-US"><span leaf="">GEOLOCATIONHUB </span></span><span leaf="">的 </span><span lang="EN-US"><span leaf="">2 </span></span><span leaf="">万张图片测试数据集上，</span><span lang="EN-US"><span leaf="">ETHAN </span></span><span leaf="">在最严格的街道级（</span><span lang="EN-US"><span leaf="">1</span></span><span leaf="">公里以内）精度上达到了</span><span lang="EN-US"><span leaf=""> 28.7%</span></span><span leaf="">，超过了商业专有工具</span><span lang="EN-US"><span leaf=""> GeoSpy </span></span><span leaf="">的</span><span lang="EN-US"><span leaf=""> 26.5% </span></span><span leaf="">和 </span><span lang="EN-US"><span leaf="">GPT-4o </span></span><span leaf="">的</span><span lang="EN-US"><span leaf=""> 23.2%</span></span><span leaf="">。在城市级（</span><span lang="EN-US"><span leaf="">25</span></span><span leaf="">公里）达到</span><span lang="EN-US"><span leaf=""> 59.2%</span></span><span leaf="">，国家级达到</span><span lang="EN-US"><span leaf=""> 95.6%</span></span><span leaf="">，大洲级高达</span><span lang="EN-US"><span leaf=""> 99.3%</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004935" data-ratio="0.29364161849710985" style="width:425px;height:125px;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=5243959e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaiaAkW0xoicQLV25p50HtwHw1Rbh6KpYuAIaW8V2z8gFKWzYLHicAQw59fcljWdGUMRGp9picsB3AOTmGibDydTKteM0b2N6HhjzeU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">人机大战（</span><span lang="EN-US"><span leaf="">GeoGuessr </span></span><span leaf="">游戏）</span></span></b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">：研究人员编写脚本让</span><span lang="EN-US"><span leaf=""> ETHAN </span></span><span leaf="">直接接入</span><span lang="EN-US"><span leaf=""> GeoGuessr </span></span><span leaf="">游戏平台，与全球真实玩家进行了</span><span lang="EN-US"><span leaf=""> 41 </span></span><span leaf="">轮随机匹配对战。结果</span><span lang="EN-US"><span leaf=""> ETHAN </span></span><span leaf="">取得了 </span><b><span lang="EN-US"><span leaf="">4550.5 </span></span><span leaf="">分的平均分（人类平均仅</span><span lang="EN-US"><span leaf=""> 4120.3</span></span><span leaf="">），胜率高达</span><span lang="EN-US"><span leaf=""> 85.4%</span></span></b><span leaf="">。在一次挪威偏远村庄的测试中，</span><span lang="EN-US"><span leaf="">ETHAN </span></span><span leaf="">仅通过屋顶建筑风格和路标排版，将误差锁定在</span><span lang="EN-US"><span leaf=""> 2 </span></span><span leaf="">公里以内，而人类对手偏差了</span><span lang="EN-US"><span leaf=""> 5 </span></span><span leaf="">公里。</span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">不足与局限</span></span></b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">：在极度低能见度（大雾、黑夜）、缺乏特征的沙漠荒原，以及高度同质化的现代城市住宅区，</span><span lang="EN-US"><span leaf="">ETHAN </span></span><span leaf="">依然会发生严重的误判。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作思考</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通过游戏的 </span><span lang="EN-US"><span leaf="">PK </span></span><span leaf="">测试，说明 </span><span lang="EN-US"><span leaf="">ETHAN </span></span><span leaf="">具备真实环境下的动态对抗能力。其一公里的定位精度也十分恐怖，将目标锁定在</span><span lang="EN-US"><span leaf=""> 1 </span></span><span leaf="">公里范围内，基本上就意味着攻击者可以通过无人机、摄像头或线下踩点轻易完成最后的“收网”了。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">过去的时代，大家常常认为随便一拍的照片怎么会有人能认得出来是哪里，即使有能认出来的人也不会针对我。在大模型时代，看着差不多的照片也能分辨出大概的位置，想保持隐身变得不容易。该技术被用于监控和跟踪会很令人担忧，间谍可以执行定向的暗杀，私生饭可以追踪明星的住宅地址。当然，科技向善，警方也可以利用它快速定位绑架等恶性犯罪受害者的大概位置。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004930" data-ratio="0.44971098265895953" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=51cdf7b8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiatnsNqRQp54mTkUOHgRCyHm2P7EcJE6LjQpsialqlVVOuehAYMZUJCMFWX5ZdKb8BVnxiacKHN5eia0YcwrNfjmhuDnfuSt74ibu8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">根据</span><span lang="EN-US"><span leaf=""> GDPR </span></span><span leaf="">第</span><span lang="EN-US"><span leaf=""> 9 </span></span><span leaf="">条和欧盟《人工智能法案》，此类能够从图像中推断出敏感个人位置的</span><span lang="EN-US"><span leaf=""> AI </span></span><span leaf="">系统，极有可能被归类为高风险应用，存在较大合规与隐私风险。有一些潜在的防御策略：① 在</span><span lang="EN-US"><span leaf=""> LVLM </span></span><span leaf="">训练阶段引入差分隐私或选择性特征抑制，让模型</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">故意遗忘</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">特定的地理敏感特征；② 社交媒体平台（如微信、</span><span lang="EN-US"><span leaf="">Twitter</span></span><span leaf="">）在用户上传图像时，实时运行后台过滤，对高风险的建筑立面或路标进行自动模糊处理；③ 给图像添加人眼不可见的微小对抗噪声（如使用</span><span lang="EN-US"><span leaf=""> SGA </span></span><span leaf="">技术扰乱模型的</span><span lang="EN-US"><span leaf=""> CoT </span></span><span leaf="">注意力机制），可以让模型将美国的自由女神像误认为是法国的埃菲尔铁塔，使得大模型的国家级定位准确率从</span><span lang="EN-US"><span leaf=""> 78.6% </span></span><span leaf="">暴跌至</span><span lang="EN-US"><span leaf=""> 3.4%</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004929" data-ratio="0.38497109826589593" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=27251fa2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjwkjMleWyqhKuIC7JQsmGyz269XNKZeqLLQzb0lvF7J4LcdD5tnIXDquibjDzbjh7IhTsMmm32eF6IaICIMLbTQa91pnDtQfHo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a2e73312&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488609%26idx%3D1%26sn%3D1cc2853e400a3d5797944817f3f15467">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 10 Apr 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>思科如何基于 Llama 3.1 构建安全原生推理大模型</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488608&amp;idx=1&amp;sn=07289b545dc4a6145fed23123a955d9c</link>
      <description>思科安全推理大模型是如何构建的？</description>
      <content:encoded><![CDATA[<p>原创 <span>Avenger</span> <span>2026-04-09 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=0df620be&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FOsTASDqnFNgpsJ9pcb60NibDicO81scziat2a4aqhvL0d4r8MLWOypPASzTq5ibMZX0pp36UEuibib9upyOxMo5TF6y5BBRKvpM9WAibXHwtUeUHxE%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>思科安全推理大模型是如何构建的？</p>
  <p data-pm-slice="0 0 []"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作来源</span></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">arXiv:2601.21051</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作背景</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">以 </span><span lang="EN-US"><span leaf="">DeepSeek-R1 </span></span><span leaf="">与 </span><span lang="EN-US"><span leaf="">OpenAI o1 </span></span><span leaf="">为代表的原生推理模型引领了大模型技术的新范式，通过逐步推理来提升“智能”表现，但这种推理方法在网络安全领域尚不成熟。现有的安全大模型处理直接查询时表现尚可，面对需要多步逻辑分析的复杂任务（威胁情报分析、漏洞评估、事件响应等）时往往力不从心。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在网络安全领域中，</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">如何得出结论</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">和</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">结论本身</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">一样重要。业界需要一种能够“三思而后行”且提供可审计逻辑链的安全大模型，这样才能增强对其输出结果的可信度。思科的 </span><span lang="EN-US"><span leaf="">Foundation AI </span></span><span leaf="">团队顺势而为，在 </span><span lang="EN-US"><span leaf="">2026 </span></span><span leaf="">年年初发布了全球首个专门为网络安全领域打造的开源原生推理大模型。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作准备</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">基于 </span><span lang="EN-US"><span leaf="">Foundation AI </span></span><span leaf="">此前发布的基座模型 </span><span lang="EN-US"><span leaf="">Foundation-Sec-8B</span></span><span leaf="">，该模型基于 </span><span lang="EN-US"><span leaf="">Llama-3.1-8B-Base </span></span><span leaf="">且在</span><span lang="EN-US"><span leaf=""> 80 </span></span><span leaf="">亿</span><span lang="EN-US"><span leaf=""> token </span></span><span leaf="">的私有网络安全语料库上预训练而来。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004956" data-ratio="0.376878612716763" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=f7bdf3d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNggiaicNKp6ejlfn0icDqgpSMZ1MUH4Zn3lCPJWgYrwDDibppLZn23WYwdWIZO2HKeibzVoq93iaY4GsvP3TicYwFdPR5CHc5F4z0xOEk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-bottom: 16px;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">研究人员又利用 </span><span lang="EN-US"><span leaf="">Gemini-2.5-Flash </span></span><span leaf="">构建 </span><span lang="EN-US"><span leaf="">Agent</span></span><span leaf="">，生成了约 </span><span lang="EN-US"><span leaf="">200 </span></span><span leaf="">万个合成数据样本，从而进行第一阶段的微调。这 </span><span lang="EN-US"><span leaf="">200 </span></span><span leaf="">万数据中并非完全是网络安全相关语料，网络安全语料只占到 </span><span lang="EN-US"><span leaf="">26.8%</span></span><span leaf="">。在垂类大模型的训练中，最害怕由于喂了太多网络安全知识，导致模型连最基础的代码和数据逻辑都遗忘了。所以数学和编程数据占到了约三分之一；剩下的则是指令遵循、通用对话、科学和安全对齐数据。</span></span></p><p style="margin-top: 16px;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">用到的网络安全相关评估 </span><span lang="EN-US"><span leaf="">Benchmark</span></span><span leaf="">：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004955" data-ratio="0.34104046242774566" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=2bc32086&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjmW2eh3AzfnNWOE8IlhQt2wJxfamwbNykxoagwwdich9VG49nq068pvyqqQrSo9EiaIKrDwHmCbehQDTnJr1SNGahxcC1ZqjKyg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">用到的通用评估 </span><span lang="EN-US"><span leaf="">Benchmark</span></span><span leaf="">：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004954" data-ratio="0.3375722543352601" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=6c33b33c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjVmtwZwn5c18bebjdAASGs4HJB4zP3DuK9aicoib34EBz8ltJOWiaFB1k1YUlhia8LeKEVzibeomUAfPaWkJbgceuTCneDeBMEfPq0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作设计</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">与传统的指令微调不同，研究人员采用两阶段推理训练模式：</span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">阶段 ① 监督微调（</span><span lang="EN-US"><span leaf="">SFT</span></span><span leaf="">）植入推理本能</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在</span><span lang="EN-US"><span leaf=""> 200 </span></span><span leaf="">万合成数据上进行</span><span lang="EN-US"><span leaf=""> 3 </span></span><span leaf="">个</span><span lang="EN-US"><span leaf="">Epoch </span></span><span leaf="">的微调，使模型学会原生推理行为。之后模型在输出最终答案前，会生成显式的推理轨迹。</span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">阶段 ② 可验证奖励强化学习</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">使用组相对策略优化（</span><span lang="EN-US"><span leaf="">GRPO</span></span><span leaf="">）算法，为每个 </span><span lang="EN-US"><span leaf="">Prompt </span></span><span leaf="">生成 </span><span lang="EN-US"><span leaf="">5 </span></span><span leaf="">个回答，通过任务验证给出二元奖励。研究人员也解决了强化学习中两个常见的痛点：</span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">数据异构性</span></span></b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">：不同任务的输出长度差异巨大，如果简单地将长回答的所有</span><span lang="EN-US"><span leaf=""> Token </span></span><span leaf="">损失求平均，会导致模型在弱势任务上输出冗长、重复的废话来降低</span><span lang="EN-US"><span leaf=""> Loss</span></span><span leaf="">。而 </span><span lang="EN-US"><span leaf="">Dr.GRPO </span></span><span leaf="">提出的</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">样本级损失聚合</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">方法，可以确保长序列和短序列对梯度更新的贡献公平。</span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">奖励破解与格式退化</span></span></b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">：模型也会发现损失会随着输出长度增加而减小，于是为了“偷懒”，它可能只输出最终正确答案，而把思考过程缩短为</span></span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="xml"><code><span leaf=""><span class="code-snippet__tag">&lt;</span><span class="code-snippet__tag"><span class="code-snippet__name">think</span></span><span class="code-snippet__tag">&gt;</span>No<span class="code-snippet__tag">&lt;/</span><span class="code-snippet__tag"><span class="code-snippet__name">think</span></span><span class="code-snippet__tag">&gt;</span></span></code></pre></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span lang="EN-US"><span leaf="">。研究人员在奖励函数中硬编码了格式惩罚，强制要求模型输出的推理思考，必须有实质性内容。从而降低了模型用短答案或者毫无意义的长废话来骗取奖励所带来的影响，这也是训练垂类小模型需要注意的地方。</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作评估</span></span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">网络安全基准测试</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在</span><span lang="EN-US"><span leaf=""> CTIBench-RCM </span></span><span leaf="">这个极其考验底层安全推理的任务上，该模型取得了</span><span lang="EN-US"><span leaf=""> 75.3% </span></span><span leaf="">的好成绩，不仅超过了指令微调版（</span><span lang="EN-US"><span leaf="">70.4%</span></span><span leaf="">），甚至超越了参数量大</span><span lang="EN-US"><span leaf=""> 15 </span></span><span leaf="">倍的</span><span lang="EN-US"><span leaf=""> GPT-OSS-120B</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">71.2%</span></span><span leaf="">）以及</span><span lang="EN-US"><span leaf=""> Llama-3.3-70B-Instruct</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">68.4%</span></span><span leaf="">）。值得注意的是，在其他几个数据集上，该模型未能与其他表现较好的开源模型拉开差距，并且被商业模型 </span><span lang="EN-US"><span leaf="">GPT </span></span><span leaf="">大幅领先。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6219653179190752" data-type="png" data-w="865" data-imgfileid="100004952" src="https://wechat2rss.xlab.app/img-proxy/?k=1019cc73&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjyEyfhY5Cx9hjibUfVxFkJFgTLN5auUicCh3CDFPTQ5zt06jLicgibUWZic0hz4fOpAGGvITRfWNI0kWyvsrvpqcFUGQM9E0zFPL6M%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6219653179190752" data-type="png" data-w="865" data-imgfileid="100004953" src="https://wechat2rss.xlab.app/img-proxy/?k=3ab19d4b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgavCm9M1QicoFfbnOjvTGep4rteskn12hfUjHKbVy76YDibFUFaXYc1KnHjUibwwpF5cYUs94eIctBZGStU9ibuWtr3Maxzegctco%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在最新的未见漏洞预测集</span><span lang="EN-US"><span leaf=""> CWE-PREDICTION </span></span><span leaf="">上，同样拿下了</span><span lang="EN-US"><span leaf=""> 70.4% </span></span><span leaf="">的高分。在其他数据集上的表现也是平平无奇，更是比商业模型差很多。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004951" data-ratio="0.6601156069364161" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=18517e4a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhB0Hwy699eadicODicjH9kc158ib6DLLLbkUiaXdfxgAyR0d4FQhNOqROSic0MJ446sNQYmSdOq6964VvUP35SxiaqRbibCQXUd4jRBk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Foundation-Sec-8B-Reasoning </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">模型表现良好，在多个场景下均取得了不错的效果。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004950" data-ratio="0.6277456647398844" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=64996a1d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjq8BkMtgUJvev077Ggtiass8vRGXVRoDmTk9XQ0P2V36AiaEtzDvo1oXKNUzLXUWuBOIQePuhRITPvQHs7wLkExnaZlLp3rUJng%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">网络安全垂类训练并没有牺牲它的通识能力。经过强化学习训练后，模型在</span><span lang="EN-US"><span leaf=""> 2WikiMultihopQA </span></span><span leaf="">这种长文本逻辑题上实现了较大提升，准确率升至</span><span lang="EN-US"><span leaf=""> 60.5%</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004949" data-ratio="0.2855491329479769" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=2d16bea4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNh0bYOzKe0xfhqAdh63vspXZvKcOksOibhsjOdoVbUAl0zXqqXvXVUxoAf3knoyIz9Ny4MkauWdiabYeJXREutibFz4qAlzS7oJWk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在</span><span lang="EN-US"><span leaf=""> AlpacaEval 2</span></span><span leaf="">场景下，提升了</span><span lang="EN-US"><span leaf=""> 146%</span></span><span leaf="">。唯一的微小代价是代码生成（</span><span lang="EN-US"><span leaf="">HumanEval</span></span><span leaf="">）能力略微下降了约</span><span lang="EN-US"><span leaf=""> 2.4%</span></span><span leaf="">，但这可以用其他专注于</span><span lang="EN-US"><span leaf="">Coding</span></span><span leaf="">的模型来解决。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004948" data-ratio="0.30289017341040464" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=35415682&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNj9oibnRONQiaP9fqp3iaUXd2vCXFOkrSibC82eq2nSmFCAiaLOxUUQEiarWcEIeHUszHwbKAZyDpiapkWRAdz3ibLYBrcvY9qJJicZjRNI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Foundation-Sec-8B-Reasoning </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">模型表现良好，在多个场景下均取得了不错的效果。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004947" data-ratio="0.6127167630057804" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=4cb2eaf6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjpuDCM1xvdFOUWDJt0eH0wOeqMxbIialYUKYV4HQAviag97piaTEl7MqgDx5KdKcYPNVwiav5MVCia4S2fWgv1seA9vDoZU1puz4ia4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通过消融实验对比发现，仅做监督微调的模型在多跳推理上得分惨不忍睹（如</span><span lang="EN-US"><span leaf=""> 2WikiMultihopQA </span></span><span leaf="">仅</span><span lang="EN-US"><span leaf=""> 24.4%</span></span><span leaf="">）。在利用监督微调建立领域知识后，正是强化学习赋予了模型深度解析和指令遵循的能力，让表现得以大幅提升。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004946" data-ratio="1.0307941653160453" style="width: 399px;height: 411px;" data-type="png" data-w="617" src="https://wechat2rss.xlab.app/img-proxy/?k=7ac760bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaoL4dmtPuN12atX1ynia6AAESGYlicfPpzt8W6I5hcgpxgogI1wbTB1zjsGzdLkqRFLYia8nkiaun8I2nKmiavujlzTw5LzaMDRtlU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">由于具备更强的推理能力，该模型如果被黑客利用编写恶意软件将极其危险。为此，团队为其量身定制了名为</span><span lang="EN-US"><span leaf=""> &#34;Metis&#34; </span></span><span leaf="">的系统提示词，严格框定了它的安全边界。加上 </span><span lang="EN-US"><span leaf="">Prompt </span></span><span leaf="">后，模型拒绝恶意请求的通过率达到了</span><span lang="EN-US"><span leaf=""> 93.00%</span></span><span leaf="">；如果外挂</span><span lang="EN-US"><span leaf=""> Llama-Guard-3 </span></span><span leaf="">护栏，防御率高达</span><span lang="EN-US"><span leaf=""> 98.25%</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004945" data-ratio="0.7632398753894081" style="width:433px;height:330px;" data-type="png" data-w="642" src="https://wechat2rss.xlab.app/img-proxy/?k=cace8a6d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNj5m4cOgtlw4dPVcxcQfrP4XdZEU6E6sbldfdUXfKt9Q9h8Qic9YpVI4DBLoRvOIhfMoJZsQJiakejr2eIl6764hWvmUraQDv2uY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">“小模型</span><span lang="EN-US"><span leaf="">+</span></span><span leaf="">强化学习推理”的模式能够在不牺牲广泛通用能力的前提下，在垂类任务上实现对通用大模型的反超。通过将系统提示词设定为</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">拥有高级网络安全专家经验</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的 </span><span lang="EN-US"><span leaf="">Metis </span></span><span leaf="">角色，并要求其在输出云安全配置等关键信息时必须绝对精准并引用来源，可以进一步锁定模型的专业度与安全性。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004943" data-ratio="0.4751445086705202" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=4051c423&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhtiaSHI6KfT6MUVG0ialSGBjsZ4icTtibjyp8ntlRDicQwQ1JoSiaiaWxqK6rg3PGIHO9s9ibicHygvs8NwQpXgDMvONgx6do142EDATDc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作思考</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">现今的评测仍然局限在文本形态的一小类（如威胁情报报告），后续将网络安全领域承载更多信息的形态（如网络流量）接入处理，能力范围将进一步扩展。随着大模型能力的进一步提升，</span><span lang="EN-US"><span leaf="">Agentic Workflows</span></span><span leaf="">可能会越来越有用。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">一方面如果本地部署的安全模型可以比肩规模较大的云端大模型的效果，那么就可以将调用</span><span lang="EN-US"><span leaf="">API</span></span><span leaf="">的费用省下来，并且能更好的保证数据隐私合规。</span></span></p><p style="text-align: center;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004942" data-ratio="0.4751445086705202" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=9dca922b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgnAxPRWmZPv17rfQ8Na4W89aDbqDfyph6ZBpQ7n5qVBwCUPprG7hQaGHBC0BbibqDsbPAvZ9OWwWiaSJfdLmcmCNS9S9l7G0iarQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e1fb2c1c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488608%26idx%3D1%26sn%3D07289b545dc4a6145fed23123a955d9c">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 09 Apr 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>大模型对威胁情报来说可能并不可靠</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488555&amp;idx=1&amp;sn=7fae151c7499b47740586e1522637552</link>
      <description>大模型现在真的可以取代安全分析人员了吗？</description>
      <content:encoded><![CDATA[<p>原创 <span>Avenger</span> <span>2026-03-30 09:01</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e22b32c1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FOsTASDqnFNj7VB2l0xS4tuibbtpRMIL1fs69Wqrahy1p3ibeUYQCiarA4PcUib3Bzhfossc1mgAiaNCpq1oehy6u0GP9cF9lBpPquaAsMphTnX8w%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>大模型现在真的可以取代安全分析人员了吗？</p>
  <p data-pm-slice="0 0 []"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作来源</span></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">ARES 2025</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作背景</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在整个网络安全行业都在疯狂炒作“用大模型取代安全分析师”、“用</span><span lang="EN-US"><span leaf=""> AI </span></span><span leaf="">自动化提取威胁情报”的当下，很多人声称大模型可以完美解决威胁情报报告信息提取的痛点。利用大模型来提取大量的、非结构化的威胁情报报告（如</span><span lang="EN-US"><span leaf=""> Mandiant</span></span><span leaf="">、卡巴斯基发布的</span><span lang="EN-US"><span leaf=""> PDF </span></span><span leaf="">报告或博客技术文章）中的关键实体（如攻击者、恶意软件、漏洞）以及它们之间的关系（</span><span lang="EN-US"><span leaf="">TTPs</span></span><span leaf="">）。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004903" data-ratio="0.3213872832369942" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=4700b0fd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhR0oonr8UKiaTuv9aicvYD32VElTYVfkXpY6JE1gTQPKnSDflZbTUhic2bwzmuibga2Rjth8sawQy4ySG5Mib9ibslFk7puKxAkYEg0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">演示效果较好的场景，往往使用人为截断的短文本段落，而不是动辄几十页的真实的、完整的报告。根据传统的准确率和召回率等表面指标就能够确定有效性吗？能提出来可能远远不够，还必须确保大模型的一致性（每次回答是否一样）以及置信度（对提取结果的自信是否可靠）。想要将大模型作为工业级组件应用到实际场景中，可靠性验证是必备的一环。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004902" data-ratio="0.8416184971098266" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=46f1611f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNh8Was4WWgYVqdY4JP6U0XeI7IiczWyBbrDC2rj947uEiaugdRA6EFiaUj1rLhHI24QPCGSvU9KR0pOlF9YBEfbv9xvZo5Wiaejibvc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作准备</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">研究人员整理了</span><span lang="EN-US"><span leaf="">350</span></span><span leaf="">份真实的、完整的威胁情报报告，这些文件中包含复杂的上下文与难以理解的长文本。选取的</span><span lang="EN-US"><span leaf="">86</span></span><span leaf="">个</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">组织均在</span><span lang="EN-US"><span leaf="">2008</span></span><span leaf="">年至</span><span lang="EN-US"><span leaf="">2020</span></span><span leaf="">年期间发起过至少⼀次攻击活动。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004901" data-ratio="0.3988439306358382" style="width:422px;height:168px;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=1c80628e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNg7JmTWYOs0F7ldrJt4DK711icEicjUBapTu3535MBMic6lcON6acrVHBZytn3Ncme80o3NAhciaP1FZlzNSRGF8JC5TuF87CI0ZQU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">准备了当时最顶级的闭源和开源大模型，包括</span><span lang="EN-US"><span leaf=""> GPT-4o</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">OpenAI</span></span><span leaf="">）、</span><span lang="EN-US"><span leaf="">Gemini 1.5 Pro</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">Google</span></span><span leaf="">）以及</span><span lang="EN-US"><span leaf=""> Mistral Large 2</span></span><span leaf="">。提示词按照常见规范要求进行设计：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004900" data-ratio="0.4751445086705202" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=bf0b9381&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgYHN8uYfccrWP4exOiaGr65FZq1Zaw814vIzO7icpU2F05EaP60DWGflajEBSa3vJPKzV03MH63ibAh0yP90fjNibQzzjxxMkaJOA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作设计</span></span></span></p><p style="margin-bottom: 16px;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">将威胁情报报告的提取任务核心为命名实体识别（</span><span lang="EN-US"><span leaf="">NER</span></span><span leaf="">）与关系提取（</span><span lang="EN-US"><span leaf="">RE</span></span><span leaf="">）：</span></span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">实体：攻击者（</span><span lang="EN-US"><span leaf="">Attacker</span></span><span leaf="">）、恶意软件（</span><span lang="EN-US"><span leaf="">Malware</span></span><span leaf="">）、漏洞（</span><span lang="EN-US"><span leaf="">Vulnerability</span></span><span leaf="">）等；</span></span></p></li><li><p style="margin-bottom: 16px;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">关系：攻击者使用恶意软件（</span><span lang="EN-US"><span leaf="">Uses</span></span><span leaf="">）、恶意软件利用漏洞（</span><span lang="EN-US"><span leaf="">Exploits</span></span><span leaf="">）等。</span></span></p></li></ul><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004899" data-ratio="0.3965317919075145" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=842d774d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjypKZNVqf8iah2rRPa3YuC2BzXpm7znlrEVibUBiaJnmEXLImglXxL2U3XykDxYKTmib59ia0Vgb6JuvFYicDAukbajZjlm6XLlKjoI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">根据三种不同的策略使用大模型：</span></span></p><p style="margin-bottom: 8px;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">① 零样本学习：直接让大模型进行处理。</span></span></p><p style="margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">② 少样本学习：基于检索增强生成（</span><span lang="EN-US"><span leaf="">RAG</span></span><span leaf="">），在</span><span lang="EN-US"><span leaf=""> Prompt </span></span><span leaf="">中动态注入</span><span lang="EN-US"><span leaf=""> 1</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">3 </span></span><span leaf="">或</span><span lang="EN-US"><span leaf=""> 5 </span></span><span leaf="">个相似的标注示例供模型参考。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">③ 模型微调：使用特定数据集对开源模型（如</span><span lang="EN-US"><span leaf=""> Mistral 8x7B</span></span><span leaf="">）进行全参数</span><span lang="EN-US"><span leaf="">/LoRA</span></span><span leaf="">微调。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">与传统的方式不同，研究人员引入了两个新的指标来进行效果评价：</span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">一致性</span></span></b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">：由于大模型存在采样随机性，研究人员使用</span><span lang="EN-US"><span leaf="">Fleiss</span></span><span leaf="">’</span><span lang="EN-US"><span leaf=""> Kappa系数</span></span><span leaf="">来评估模型在多次运行时的稳定性。对于同一份报告、同一个</span><span lang="EN-US"><span leaf=""> Prompt</span></span><span leaf="">，作者让大模型重复提取</span><span lang="EN-US"><span leaf=""> 5 </span></span><span leaf="">次。如果它每次提取的</span><span lang="EN-US"><span leaf=""> APT </span></span><span leaf="">组织名称和</span><span lang="EN-US"><span leaf=""> TTP </span></span><span leaf="">关系都完全一样，就是高一致性。</span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">置信度</span></span></b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">：模型输出结果时，研究人员要求其附带一个</span><span lang="EN-US"><span leaf=""> 0 </span></span><span leaf="">到</span><span lang="EN-US"><span leaf=""> 1 </span></span><span leaf="">之间的自信度评分。然后使用预期校准误差（</span><span lang="EN-US"><span leaf="">ECE</span></span><span leaf="">）与布里尔评分（</span><span lang="EN-US"><span leaf="">BS</span></span><span leaf="">）来对其进行衡量。简而言之，如果模型宣称自己有</span><span lang="EN-US"><span leaf=""> 90% </span></span><span leaf="">的把握，那么它输出的这批结果里，真实准确率是否也达到了</span><span lang="EN-US"><span leaf=""> 90%</span></span><span leaf="">？如果它只有</span><span lang="EN-US"><span leaf=""> 40% </span></span><span leaf="">的准确率却给出了</span><span lang="EN-US"><span leaf=""> 90% </span></span><span leaf="">的自信度，这就是严重的</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">过度自信</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size:12.0pt;font-family:\&#34;微软雅黑\&#34;,sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 18px;font-weight: bold;">工作评估</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">结果是相对悲观的，不宜对其有过高的期待：</span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">基础提取能力低下</span></span></b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">：在面对真实长篇报告时，所有模型在零样本学习场景下的表现堪称灾难，</span><span lang="EN-US"><span leaf="">F1 </span></span><span leaf="">分数极低。使用</span><span lang="EN-US"><span leaf="">RAG</span></span><span leaf="">的少样本学习确实提升了性能，但当示例增加到</span><span lang="EN-US"><span leaf=""> 3 </span></span><span leaf="">到</span><span lang="EN-US"><span leaf=""> 5 </span></span><span leaf="">个时，性能提升就遇到了明显的</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">天花板</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">，远未达到可以完全替代人工的及格线。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.49017341040462425" data-type="png" data-w="865" data-imgfileid="100004898" src="https://wechat2rss.xlab.app/img-proxy/?k=ffac639b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgSiaqRGYgpHOP9v8F3flaT8P8oe0nEnjv8kIYbBFrFCxoO3cTgtxwvKibQwm96bayoaFttuibncg4pVLmk1ibiawacNWyLasKe4jcA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004897" data-ratio="0.6034682080924856" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=89f05cd6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhV4Dn38VN1iaLVgicUrFSgfSzuGoNUHTepxGPEAFcicatMhP2hToRpM8V0wyJLvFnLVibzib6PcBYPJkF38icyicVeL8C9Guvia175uGU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">一致性差</span></span></b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">：大模型是一个十分“善变”的分析人员，实验表明，同一个模型在</span><span lang="EN-US"><span leaf=""> 5 </span></span><span leaf="">次独立运行中，提取出的实体和关系出现了巨大的波动。尤其是面对复杂的</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">关系提取（如</span><span lang="EN-US"><span leaf=""> A </span></span><span leaf="">利用了</span><span lang="EN-US"><span leaf=""> B </span></span><span leaf="">漏洞）</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">时，模型的一致性发生断崖式下跌。相比之下，</span><span lang="EN-US"><span leaf="">GPT-4o </span></span><span leaf="">比</span><span lang="EN-US"><span leaf=""> Gemini </span></span><span leaf="">和</span><span lang="EN-US"><span leaf="">Mistral </span></span><span leaf="">稍微稳定一些，但依然无法满足工业级稳定性要求。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3953757225433526" data-type="png" data-w="865" data-imgfileid="100004895" src="https://wechat2rss.xlab.app/img-proxy/?k=61c964df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjO1k3oWx7h5RLGAbrrEiby3dibLiaAMPms1M4S9Q4zBic657bnm8icQhfmlm33BibrtmWpnd0JqB3ywPicylicvaib9JghEaw0k0HjNeOc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004894" data-ratio="0.4797687861271676" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=6150b7bc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNh7Sk2DSuLIjLfwpgZVTRF0E0aBcHosETaK3wyB8Aic8CkD6h5lRqTPZ8945JHzLgR8gPKaodUiceRkMAKZO7OouQrT2pkmfhTd4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">过度自信</span></span></b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">：所有的</span><span lang="EN-US"><span leaf="">LLM </span></span><span leaf="">都表现出了极度的自大，它们经常给自己的结果打出</span><span lang="EN-US"><span leaf="">90%</span></span><span leaf="">以上的高置信度，而实际准确率往往只有</span><span lang="EN-US"><span leaf=""> 0.4 </span></span><span leaf="">到</span><span lang="EN-US"><span leaf=""> 0.6</span></span><span leaf="">。</span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">微调迷思</span></span></b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">：微调让模型提取的</span><span lang="EN-US"><span leaf=""> F1 </span></span><span leaf="">分数有所上升，但它的置信度校准完全崩盘了。微调后的模型</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">学乖了</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">，它学会了迎合标准答案的格式，导致无论它提取的内容对错，它都近乎</span><span lang="EN-US"><span leaf=""> 100% </span></span><span leaf="">盲目自信。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004893" data-ratio="0.21734104046242775" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=7719d885&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjMTQpNIibMRInic72m9sA5adMK4a7ia7su2myHxXRVicibeiagP8pktN71licX0iayUCNyib5B6JlDJUQnwl2FlcejUYoWvXdNaOVqqJY0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作思考</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">如果我们引入大模型是为了节省人力，但由于它经常在没有把握时瞎编乱造，导致安全分析人员必须逐行去验证它提取的信息，那么验证这种低质量输出所花费的时间，可能比分析人员自己去读报告原文还要长。这也是目前很多企业落地</span><span lang="EN-US"><span leaf=""> AI </span></span><span leaf="">安全产品后，感觉到</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">越用越累</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的根源。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">目前来说，大语言模型可能在威胁情报提取方面还没有那么可靠。它们目前的技术成熟度，可能还无法胜任完全自动化的情报生产。业界可能需要停止对大模型在安全领域的盲目崇拜，重新正视大模型对人的辅助分析能力。（</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size:12.0pt;font-family:\&#34;微软雅黑\&#34;,sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">PS：这个是在 GPT-4o 的时代做的研究，那是2024年5月发布的模型。两年过去了，大模型也在快速进步，尽信书不如无书）</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">很多公司宣称</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">我们用百万级高质量语料微调了专属安全大模型，准确度很高</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">。但实际上，微调过程中的</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">过拟合</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">可能也破坏了基础大模型原本保留的一丝</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">自我怀疑</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">能力。微调后的安全大模型变成了一个</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">傲慢的骗子</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">，这对依赖大模型置信度阈值来进行告警分级的</span><span lang="EN-US"><span leaf=""> SOC </span></span><span leaf="">平台来说，是绝对的毒药。</span></span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="sql"><code><span leaf=""><span class="code-snippet__keyword">LARGE</span> <span class="code-snippet__keyword">LANGUAGE</span> MODELS <span class="code-snippet__keyword">ARE</span> UNRELIABLE <span class="code-snippet__keyword">FOR</span> CYBER THREAT INTELLIGENCE</span></code></pre></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=fa7374ea&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488555%26idx%3D1%26sn%3D7fae151c7499b47740586e1522637552">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 30 Mar 2026 09:01:00 +0800</pubDate>
    </item>
    <item>
      <title>Virus Bulletin 2024 议题慢递</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488540&amp;idx=1&amp;sn=e1caba209ab0c0fcfc0b491b5e4348e2</link>
      <description>Virus Bulletin也是老牌会议，从 1991 年就开始举办，历经三十余载。</description>
      <content:encoded><![CDATA[<p>原创 <span>Avenger</span> <span>2026-03-24 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=18736ca6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FOsTASDqnFNiaG9fze1gGeWlK1yrCcvibW3m2jKswH8p5eXYibicUQfBXNiaj9te04hP6WKXVJNgZVH55zGv3fqWgdRDpWRCicibQmqSmqrkKrLfiasI%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>Virus Bulletin也是老牌会议，从 1991 年就开始举办，历经三十余载。</p>
  <p data-pm-slice="0 0 []"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Virus Bulletin</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">也是老牌会议，从</span><span lang="EN-US"><span leaf=""> 1991 </span></span><span leaf="">年就开始举办，历经三十余载。</span><span lang="EN-US"><span leaf="">2024</span></span><span leaf="">年的</span><span lang="EN-US"><span leaf=""> VB </span></span><span leaf="">是在爱尔兰的都柏林举办的，为期三天。各国各公司的安全专家齐聚一堂，分享对全球威胁的理解与发现。</span></span></p><p data-pm-slice="0 0 []" style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.47630057803468207" data-type="png" data-w="865" data-imgfileid="100004793" src="https://wechat2rss.xlab.app/img-proxy/?k=fd517aac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaD1ZKeMrIXND7iaHxfnaXGPxqpia0mMnlJeGuNHaKecjz6sOfXnV71nwibC19QUQIBCpErMWTcYfrL6HrUkZWvxMH3yx2hVRc3uc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">若是通过本文的介绍，或者是查看官网议程安排后，对其中某些议题感兴趣的话，就可以在官网下载议题对应的材料进行扩展阅读。（</span><span lang="EN-US"><span leaf="">PS</span></span><span leaf="">：笔者根据自身的认知局限与好恶为部分议题打了推荐查看的星级，不代表对议题实际内容高下的评判，只是为部分时间宝贵的读者再节约些时间，这部分议题相对来说可能更加值得一看。）</span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">揭开暗网洞利用市场的神秘面纱 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">暗网市场到底存在多少真实的漏洞利用武器？漏洞利用的经济体系是否遵循与其他合法市场相同的规则？</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在</span><span lang="EN-US"><span leaf=""> 2023 </span></span><span leaf="">年和</span><span lang="EN-US"><span leaf=""> 2024 </span></span><span leaf="">年间，总共发布了约</span><span lang="EN-US"><span leaf=""> 550 </span></span><span leaf="">个漏洞利用，平均每月发布约</span><span lang="EN-US"><span leaf=""> 26 </span></span><span leaf="">个。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5156069364161849" data-type="png" data-w="865" data-imgfileid="100004795" src="https://wechat2rss.xlab.app/img-proxy/?k=fde12c40&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgCglJrUIlQdfVfctLVr0ZXYWcIU1ic6tLGCEYKm0gAST8SpTicVXZXlYNAlD3hQUiaXz7VIrkTXw7yGXyvShLkU3KBIwiaxE1rmdk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">0-day</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">和</span><span lang="EN-US"><span leaf=""> 1-day</span></span><span leaf="">大约占总数的一半到三分之一。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5583815028901734" data-type="png" data-w="865" data-imgfileid="100004796" src="https://wechat2rss.xlab.app/img-proxy/?k=08bfdf12&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhNtfd31j836OSupvXZaXY0nice9BNoxxmokyaSdve07NunhhyrDeVab3EQJ9uqqJaicRd4mxY6ZibFnlkeibo24WWoYQRvLwBQxb8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">影响漏洞在黑市定价的五个关键因素：</span><span lang="EN-US"><span leaf="">1. </span></span><span leaf="">漏洞利用的类型（如</span><span lang="EN-US"><span leaf=""> LPE </span></span><span leaf="">还是</span><span lang="EN-US"><span leaf="">RCE</span></span><span leaf="">）；</span><span lang="EN-US"><span leaf="">2. </span></span><span leaf="">销售数量（独家买断还是批量多卖）；</span><span lang="EN-US"><span leaf="">3. </span></span><span leaf="">目标系统的关键性和普及程度；</span><span lang="EN-US"><span leaf="">4. </span></span><span leaf="">报价的独特性（是否附带源码）；</span><span lang="EN-US"><span leaf="">5. </span></span><span leaf="">卖家的声誉。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6520231213872832" data-type="png" data-w="865" data-imgfileid="100004797" src="https://wechat2rss.xlab.app/img-proxy/?k=5b1d090f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjz6hmFbDBiccB742pp4bLgW0CmNGr6rqwXTib86jUOJUrTjoWpPX4hxMuG747PMKORibiaGOuiaI5GfWTFw4OMIShD6X5dKBDRG5iaQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">本地提权（</span><span lang="EN-US"><span leaf="">LPE</span></span><span leaf="">）漏洞利用的平均价格约为</span><span lang="EN-US"><span leaf="">6</span></span><span leaf="">万美元 ；而远程代码执行（</span><span lang="EN-US"><span leaf="">RCE</span></span><span leaf="">）漏洞利用的平均价格约为</span><span lang="EN-US"><span leaf="">10</span></span><span leaf="">万美元。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6797687861271676" data-type="png" data-w="865" data-imgfileid="100004798" src="https://wechat2rss.xlab.app/img-proxy/?k=1027e7e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaibE8IW2z8IukBSibv8UqrcXicn9RW8oDX37AWXNFFdBZzjc2pmla1FG0JbuM9tj54sk85LPNVBfgEnykh9XrERUBgKOXClWYF5A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">RCE</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">的价格也不都是一样的，目标系统越普及越重要，其价格越高。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5907514450867052" data-type="png" data-w="865" data-imgfileid="100004799" src="https://wechat2rss.xlab.app/img-proxy/?k=b559e47a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjhPKZOucMYlcQ1iabk1kCZRoyzhItciaxO9Ij6jCabp3icpVY57h1SFtuSZz1Qw499qVmEZHyXjVuSsDTIhb20vNRmG8X29s8f60%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">例如卖家出售</span><span lang="EN-US"><span leaf="">Microsoft Outlook RCE 0-day </span></span><span leaf="">漏洞，价格高达</span><span lang="EN-US"><span leaf="">170</span></span><span leaf="">万美元。卖家要求必须通过知名黑客</span><span lang="EN-US"><span leaf=""> ShinyHunters </span></span><span leaf="">作为中间人进行担保，并要求买家先提供</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">资金证明</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">，严禁记者打扰。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4346820809248555" data-type="png" data-w="865" data-imgfileid="100004800" src="https://wechat2rss.xlab.app/img-proxy/?k=d4094d88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNg1L7I7ia9w818icZxVO0Pm2FBiaD8AqXvfC09wDbDynxYZAJ8G7IHA9wvicQOLicjA1O3Aib47cqJbvvKnAvQdDFmPS9E8Zricia7Pxs4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">主要买家群体包括：</span><span lang="EN-US"><span leaf="">APT </span></span><span leaf="">组织、勒索软件团伙、经验丰富的独立黑客、以及受资助的黑客行动主义者。如一买家悬赏</span><span lang="EN-US"><span leaf="">10</span></span><span leaf="">万美元求购</span><span lang="EN-US"><span leaf=""> 0-day </span></span><span leaf="">漏洞，明确点名需求目标为</span><span lang="EN-US"><span leaf=""> Github</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Gitlab</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Twitter</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Snapchat</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Cisco VPN</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Pulse VPN </span></span><span leaf="">等大型平台或企业软件，并承诺给牵线搭桥的中间人</span><span lang="EN-US"><span leaf="">1</span></span><span leaf="">万美元的比特币中介费。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.42890173410404625" data-type="png" data-w="865" data-imgfileid="100004801" src="https://wechat2rss.xlab.app/img-proxy/?k=2f728979&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgiblC2ExzSkbWEibEZsG76LZT0ibD77iaJhx4x6OIOyrW8vhkRTblr6TlGM0Tt4oWGibjTslwZ6oz3MlVxJ1qPHEkn687Vhc9OVWUc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">57%</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">的卖家在平台上只发布过</span><span lang="EN-US"><span leaf=""> 1 </span></span><span leaf="">个漏洞；</span><span lang="EN-US"><span leaf="">36% </span></span><span leaf="">的卖家发布过</span><span lang="EN-US"><span leaf=""> 2 </span></span><span leaf="">个；仅仅只有极少数的</span><span lang="EN-US"><span leaf=""> 7% </span></span><span leaf="">的卖家发布过</span><span lang="EN-US"><span leaf=""> 3 </span></span><span leaf="">个及以上的漏洞。漏洞黑市呈现极其明显的</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">长尾效应</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">，超过一半的卖家属于</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">一锤子买卖</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.0115606936416186" data-type="png" data-w="865" data-imgfileid="100004802" src="https://wechat2rss.xlab.app/img-proxy/?k=61a3699d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaVCGN9QMWBIyYkmFHXSEFuR3a7uJrDb4vEpp6WDT5aOuxvb1x2icn2vZSjEZ14QyQ77h6ctueCYUvVUicGiamKLdBJahH6VC5Py0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">分析了一个典型卖家，他在</span><span lang="EN-US"><span leaf=""> 2024 </span></span><span leaf="">年发布了</span><span lang="EN-US"><span leaf=""> 5 </span></span><span leaf="">个漏洞报价，潜在收入达到</span><span lang="EN-US"><span leaf="">54</span></span><span leaf="">万美元。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2947976878612717" data-type="png" data-w="865" data-imgfileid="100004803" src="https://wechat2rss.xlab.app/img-proxy/?k=8ccc91fa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNg3lomHZ5icazA5yH4ZdzOibEyA9dT87Uc30ORIb1bdq2RdbAuDkq1MMgRcfWlG0PMML0bjGXrDJZpUlQeT9ibq7GrFlvZAr46a4M%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">暗网交易其实严重缺乏流动性。虽然</span><span lang="EN-US"><span leaf=""> 0-day </span></span><span leaf="">在外界被吹得神乎其神，但在暗网茫茫人海中找到一个</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">既懂复杂漏洞技术、又有十几万美金预算、并且愿意信任卖家</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的精准买家其实非常困难。时间拖得越久，被其他研究员</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">撞车</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">发现或者被厂商偷偷静默修复的风险就呈指数级上升。一旦补丁发布，价值</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;class&#34;:&#34;MsoNormal&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size:12.0pt; font-family:\&#34;微软雅黑\&#34;,sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">数</span></span><span leaf="">十万美金的代码瞬间变为废纸。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">0day.today</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">曾是暗网非常有迷惑性的虚假漏洞交易平台。他们通过窃取开源的陈旧安全代码，或拼凑完全无效的伪造</span><span lang="EN-US"><span leaf=""> PoC</span></span><span leaf="">，配上夸张的标题，专门骗取那些技术能力不强、急于求成的新手黑客的比特币。光靠骗人就赚了将近</span><span lang="EN-US"><span leaf=""> 85 </span></span><span leaf="">个比特币，价值近</span><span lang="EN-US"><span leaf=""> 570 </span></span><span leaf="">万美元。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.484393063583815" data-type="png" data-w="865" data-imgfileid="100004804" src="https://wechat2rss.xlab.app/img-proxy/?k=3c27d71a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNia0UpLevCRD1YUtF2YEld7lcOPCzoQ88N3LZo0qMgSHzBsKGlr7jDSzu3wDSfkQLN0VIC2d4oR979ibdIHKwXnblwOOFvTecTQ4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">为了维持交易秩序，暗网衍生出了保证金制度。在账号旁边亮出高额的比特币存款余额，既是向卖家展示</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">我不差钱</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的诚意，同时也是一种极佳的反侦察手段。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2901734104046243" data-type="png" data-w="865" data-imgfileid="100004805" src="https://wechat2rss.xlab.app/img-proxy/?k=ec2b62c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNh2iaDLUWz5QBRb32hXJglSBoavBjENJlicWFhOkHj82n7HMYMDBRoPpuA7OWia3HMqsRS9eQotBACuxia9LibKOTxMIib1HWtC3dpWI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">担保机制也起到了撮合交易作用。买家先把加密货币打给论坛的官方担保人</span><span lang="EN-US"><span leaf=""> -&gt; </span></span><span leaf="">卖家将漏洞利用代码发给担保人</span><span lang="EN-US"><span leaf=""> -&gt; </span></span><span leaf="">担保人（通常懂技术）负责验证代码是否真如描述般有效</span><span lang="EN-US"><span leaf=""> -&gt; </span></span><span leaf="">验证通过后，将代码发给买家，同时扣除中介费后将资金打给卖家。担保人会抽取高额的佣金，通常为交易额的</span><span lang="EN-US"><span leaf=""> 5% </span></span><span leaf="">到</span><span lang="EN-US"><span leaf=""> 15%</span></span><span leaf="">，绝大多数高价值的</span><span lang="EN-US"><span leaf="">0-day </span></span><span leaf="">交易都被强制要求走担保人交易。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8497109826589595" data-type="png" data-w="865" data-imgfileid="100004806" src="https://wechat2rss.xlab.app/img-proxy/?k=425438a1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjrdaHVcib3UKTcicDZa7LX2WXUglnjia5oiaQW8Nk2Uy1XZwQ2J51jJLxt3XNElHUleKQNuZznqtI6KJ3I4ibSXSBXh96QmibUb7tN4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">双方争执不下，暗网平台还提供仲裁机制。暗网通过以上三个机制来使交易双方都认可该平台，从而撮合交易完成。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.24393063583815028" data-type="png" data-w="865" data-imgfileid="100004807" src="https://wechat2rss.xlab.app/img-proxy/?k=883ad428&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNialvXh0lokSmxicNQ2YicPU0EzgiajUNh98a9oAMwA4PWTzH1GBc3obYuOImRicwopfBr5rLumwOXgNOliaRDYYUhUQiaJAE4wgrT7Zo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">顶级</span><span lang="EN-US"><span leaf=""> 0-day </span></span><span leaf="">其实是战略级原材料，将其武器化就脱离了普通黑产、金融犯罪的范畴，升格成为了大国网络空间博弈、顶级</span><span lang="EN-US"><span leaf=""> APT </span></span><span leaf="">组织的核心战略资源。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2994219653179191" data-type="png" data-w="865" data-imgfileid="100004808" src="https://wechat2rss.xlab.app/img-proxy/?k=abc3b8a6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgara4o16IRDaDFeh6JibEzWkh9XAaeMxDO67Tnmp0gL9ia9omDQrVoxdJCW2m8pQJEZa5g6LJjq45WriaII7z7xEf7u7LEMkrKx0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">攻击归因与攻击基础设施分析 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐⭐</span></span></b></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.376878612716763" data-type="png" data-w="865" data-imgfileid="100004810" src="https://wechat2rss.xlab.app/img-proxy/?k=7206c0da&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhHWx2k9H6tTrFebeHP5gRIpkqhgLoThSLPIPPAnC840SqzfDAssguYicngWleE6jwf8AQWpCFhDoQlq5KB5YfJXxShDDUO0Siaw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">研究人员介绍了海量的例子，在此不一一列举，感兴趣可以查看原</span><span lang="EN-US"><span leaf="">PPT</span></span><span leaf="">。例如利用</span><span lang="EN-US"><span leaf="">TLSH</span></span><span leaf="">寻找</span><span lang="EN-US"><span leaf="">Gamaredon</span></span><span leaf="">组织的样本：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6554913294797687" data-type="png" data-w="865" data-imgfileid="100004811" src="https://wechat2rss.xlab.app/img-proxy/?k=28b749e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgVkrTpoFNbjM7YxbSnRd2b41HeBCYDehfFdorF58Q9DyaY22iakxm5AP3YYILK67ic6fibasiaZBQZkXnMCF1CULh1hlLJicxpgGAc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">例如寻找</span><span lang="EN-US"><span leaf="">OILRIG </span></span><span leaf="">组织的</span><span lang="EN-US"><span leaf=""> SAITAMA </span></span><span leaf="">后门：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5838150289017341" data-type="png" data-w="865" data-imgfileid="100004812" src="https://wechat2rss.xlab.app/img-proxy/?k=c8b864d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNj8aCHicf8ZyQwibYibVoKPicv6zu2slNiaDibvsIegpSH3GmqETWP5YlzMPG9FVyzNibp5qzkVzEsrDZp5U57cEAhZreIFic9dnbfQE18%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">例如基于证书检索：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.738728323699422" data-type="png" data-w="865" data-imgfileid="100004813" src="https://wechat2rss.xlab.app/img-proxy/?k=25e0acbe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhs4iaA2vYL7KJ1JLfM29Qtv8u81gcsjpwmuQiazB5I4kOtdmCCL0c8Ee0dC2O1LbehGB8953AlskzsvSGibk54Okj12GgNic9eic1U%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-no-proof:yes;"><v:shape type="#_x0000_t75" style="width:415.2pt;height:306.6pt;visibility:visible;mso-wrap-style:square;"><v:imagedata></v:imagedata></v:shape></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">例如监控</span><span lang="EN-US"><span leaf="">Lazarus</span></span><span leaf="">的独特行为：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5907514450867052" data-type="png" data-w="865" data-imgfileid="100004814" src="https://wechat2rss.xlab.app/img-proxy/?k=b9136ca9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNia8EKpqOtiaf4VN9rPdbD4egcMwpyoicOKyoSF7NHWBicjn0MuicDy8icRS1jCZAEOCXXg9DxPYgAiayetLSjMXNhGHhNsX00OY8eRYI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">例如</span><span lang="EN-US"><span leaf="">APT 42</span></span><span leaf="">重复利用基础设施绑定域名：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4346820809248555" data-type="png" data-w="865" data-imgfileid="100004815" src="https://wechat2rss.xlab.app/img-proxy/?k=f7f03f2c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNian6etCAr0iaFK8vAF91nNudibSibycSDNSNcFHpFnXMtQOGQwMaISI2LulexYMQPfdaicgXsllrjWfdiccIz3oKiaLkbzMhyR5PK6Y0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">例如根据证书跟踪朝鲜黑客组织</span><span lang="EN-US"><span leaf="">Kimsuky</span></span><span leaf="">：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8508670520231214" data-type="png" data-w="865" data-imgfileid="100004816" src="https://wechat2rss.xlab.app/img-proxy/?k=4ee3dbbf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaWAcv8DOicsxOo76wM6LT8ibYtQEZEsx6y8gv44pXXSdNjfia9NucrwLaiahkUXFfpic9CRlcofCbHRic4Je667n7xlqG1FNItiaSrFI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">例如</span><span lang="EN-US"><span leaf="">Storm-0558</span></span><span leaf="">使用和</span><span lang="EN-US"><span leaf="">SoftEther VPN</span></span><span leaf="">相同的</span><span lang="EN-US"><span leaf="">JARM</span></span><span leaf="">指纹且</span><span lang="EN-US"><span leaf="">2037</span></span><span leaf="">年过期，以及签发中并不包含</span><span lang="EN-US"><span leaf="">softether</span></span><span leaf="">相关信息。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6763005780346821" data-type="png" data-w="865" data-imgfileid="100004817" src="https://wechat2rss.xlab.app/img-proxy/?k=b9d7313b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiafyqYM6DRhJrnNE6RgSKSLsmT1PGa46ufLDdq60zjjtpicMFUs8CF0IibzdVocpGJoKQUZVM5mpQREojnAnY6vnf7UyvVtib3HyY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Linux</span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">下利用进程内存与</span><span lang="EN-US"><span leaf="">eBPF</span></span><span leaf="">探针检测共享对象注入攻击 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">共享对象注入攻击示意：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6450867052023121" data-type="png" data-w="865" data-imgfileid="100004818" src="https://wechat2rss.xlab.app/img-proxy/?k=ffb6c7d2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjFP4VpdWCNSqDm658Nkqe25wIBANSic9xBqlBCtOCd8oJwprHbN9PqzOPRMnHc2eWQ0GXRk0nhowdB7wibWib61fDthIWUiaFsZJA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">检测</span><span lang="EN-US"><span leaf=""> DT_NEEDED </span></span><span leaf="">感染策略如下所示，仅靠日志监控</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">存在</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">会导致大量误报，最好是可以精确指出哪个恶意模块</span><span lang="EN-US"><span leaf="">Hook</span></span><span leaf="">了哪个底层函数（如</span><span lang="EN-US"><span leaf="">xstat, readdir</span></span><span leaf="">）及其内存地址。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5283236994219653" data-type="png" data-w="865" data-imgfileid="100004819" src="https://wechat2rss.xlab.app/img-proxy/?k=3efe23df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgIhjILX6NlHicZGzqsfx50aXO6QGWxUcicRql5F3FFWBf7v5ytJ59KyC3lV0Jw8W6ZmlWLAa99P7iaRWAdFpczVAhiaCFvsy3BkBE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">第一步要识别所有导入函数：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5144508670520231" data-type="png" data-w="865" data-imgfileid="100004820" src="https://wechat2rss.xlab.app/img-proxy/?k=cb8e7093&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjexvoosicv85IgAz3b87KkJFrWQkX0xzdUPxOppBzolb6f94p5KkicZ1uZ4YXsECAbPyibIAWy6l7cyzknfnGfYG3stQcPSpiaoag%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">第二步要建立内存中共享对象及其基址的列表：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4508670520231214" data-type="png" data-w="865" data-imgfileid="100004821" src="https://wechat2rss.xlab.app/img-proxy/?k=64b68c5c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhc5Q9vRqq4WsaOpNd47Jrqa40GCA5AnLUax6k2XLbyydI8S4TG9teMQOeZN4AW27G3q8pqXN58j1RycQEaRQywVbUeiaFV0YzM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">第三步要识别预加载共享对象及其导出符号：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5341040462427745" data-type="png" data-w="865" data-imgfileid="100004822" src="https://wechat2rss.xlab.app/img-proxy/?k=daf7c440&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNg7ed4D9Z9iau2NfibF7PmuS4Zt2w8pWNftec3tBeyvHGenT6jLf9Qzn111tA87n6vhq4aLtXnV4iaffyLxgPhBHU8icA5NfokUXos%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">最后符号交叉比对并锁定受害者：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3884393063583815" data-type="png" data-w="865" data-imgfileid="100004823" src="https://wechat2rss.xlab.app/img-proxy/?k=966fe356&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhiaaUsdCyLewKdpdYkh620r3LAWmuPP8D5yNDURcgNtMABX8slX93uvxtGHZ9laSaxIlakWLITzick5XE4cOLAY7hlE16SBKVyE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">研究人员开源了检测工具</span><span lang="EN-US"><span leaf="">ELFieScanner</span></span><span leaf="">，其中包含</span><span lang="EN-US"><span leaf="">43</span></span><span leaf="">种启发式检测逻辑。</span></span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__attr">https</span>:<span class="code-snippet__comment">//github.com/JanielDary/ELFieScanner</span></span></code></pre></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">研究人员列举了好多实战示例，例如使用</span><span lang="EN-US"><span leaf=""> Kprobe </span></span><span leaf="">捕获内核级内存分配。</span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">996</span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">的</span><span lang="EN-US"><span leaf="">IcePeony</span></span><span leaf="">组织</span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2024</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">年</span><span lang="EN-US"><span leaf=""> 7 </span></span><span leaf="">月初，</span><span lang="EN-US"><span leaf="">IcePeony </span></span><span leaf="">的服务器误配成了开放目录，对外暴露了攻击工具、恶意脚本与日志。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.922543352601156" data-type="png" data-w="865" style="width:344px;height:317px;" data-imgfileid="100004824" src="https://wechat2rss.xlab.app/img-proxy/?k=0bf8abce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgkDQ8ibE84icIIBgMaWwfbCgRduXTdlRdF9oNot0lnapXGIDxWz0n8EXm64qlvBibt55EmvdWoI4tJf3qryy4U4Lnic9QIJbxDZEg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">攻击者通过</span><span lang="EN-US"><span leaf=""> C2</span></span><span leaf="">发送请求至受害者的</span><span lang="EN-US"><span leaf=""> IIS </span></span><span leaf="">服务器，随后该模块可能与内网深处的受害者服务器进行内部通信。这种</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">边界中转</span><span lang="EN-US"><span leaf=""> + </span></span><span leaf="">内网直连</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的架构非常隐蔽。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3040462427745665" data-type="png" data-w="865" data-imgfileid="100004825" src="https://wechat2rss.xlab.app/img-proxy/?k=de412f4e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhuVNySJKsMoa8HF5RhT0HbwIwkicvL4LE5KibjcMFbvF8UJicahgDRwfF06PicGbo52CwjbVKYKBgnemHKqKl3ZtNmUAU8Aic7ZLN4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">攻击者的活跃时间集中在早上</span><span lang="EN-US"><span leaf=""> 8 </span></span><span leaf="">点到晚上</span><span lang="EN-US"><span leaf=""> 10 </span></span><span leaf="">点之间，很少有攻击者能够保持这种长达</span><span lang="EN-US"><span leaf=""> 14 </span></span><span leaf="">小时高强度、集中时段的运营。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4647398843930636" data-type="png" data-w="865" data-imgfileid="100004826" src="https://wechat2rss.xlab.app/img-proxy/?k=d6fe1d05&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgELcphg5NoBHc0ibHBz7rnq55MFVUIPxhhicIdiaBRLmaCNdIR9zhgjQrWA2ibsCTfKxu4ZYUhE64KlTRzbLFBQ0XcBMosyr6Nxcc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">攻击者从周一到周六都保持高强度工作状态，周日则基本上肯定会休息。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.47398843930635837" data-type="png" data-w="865" data-imgfileid="100004827" src="https://wechat2rss.xlab.app/img-proxy/?k=9416d320&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgBUdjiaK6vFtdpkxKoCh2D3fu8mibeWeyROOr2OgFCpvQa9gHdjvM5YxWyzp2s6HMggKYHjLcXa0PfETYuV80IZhjIf0ZtSkqhI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">总结其钻石模型：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4647398843930636" data-type="png" data-w="865" data-imgfileid="100004828" src="https://wechat2rss.xlab.app/img-proxy/?k=81b86471&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaic5IxYmxXx1DJvqdMDF6hfxnY3Q04JsEZM3pzMicibDl8BltPibrsrPIic39vUibQ7ibO2w2aXYGrmlJFgJtt5aBntSK1aMW9w23xL4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">揭开向印度尼西亚出口间谍软件的隐秘网络 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">至少在</span><span lang="EN-US"><span leaf="">19</span></span><span leaf="">个国家</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">地区发现了间谍软件的痕迹，商业网络武器是一个全球化、无国界的产业链。</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004891" data-ratio="0.5824074074074074" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=418c057d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNj2UJfQGmTfzzyTqOsibOxosQU7rMiaVz6rJ6m57Bia9yribOB76TBSc99GnfMovnpbV4ZLlHBem62Yyibr0mhxAsMe0oUYBPZYbojg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">印度尼西亚甚至在未与以色列建交的情况下，从相关公司绕路新加坡进口间谍软件。一个名为</span><span lang="EN-US"><span leaf=""> PT. RADIKA KARYA UTAMA </span></span><span leaf="">的供应商在</span><span lang="EN-US"><span leaf=""> 2017 </span></span><span leaf="">年中标了雅加达情报局的采购项目，项目明确标注为</span><span lang="EN-US"><span leaf="">“ZERO CLICK INSTRUCTION SYSTEM</span></span><span leaf="">（零点击指令系统）</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">，合同价值高达</span><span lang="EN-US"><span leaf=""> 989 </span></span><span leaf="">亿印尼盾（约合数百万美元）。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004830" data-ratio="0.15606936416184972" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=4407bf7a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjI7gwiarCKQzTqs1z2IIjRQRYvoyD1RsrmWmdTMbS32x5icRHm0LjgURbqZ59CtxKTtbX0eKYGBkoVLVmYJ0KjANY6IYYI0XNWE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Wintego</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">是一家以色列公司，其产品手册显示：公司的网络情报系统可提取聊天应用、邮件、日历、照片、实时位置等极度详细的个人数据。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004831" data-ratio="0.4254335260115607" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=831b28e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjVpdHsKSpUFoUFfETibLKRuT8SUE8NgO9f6JC6uoypvzez345vFxjkXpdS6SIoZeqXCvakChoS37pIFGB357PtbKunSicyjtiaib8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">海关数据显示，</span><span lang="EN-US"><span leaf="">2019 </span></span><span leaf="">年一套价值</span><span lang="EN-US"><span leaf=""> 559 </span></span><span leaf="">万美元的</span><span lang="EN-US"><span leaf="">“WINT SYSTEM”</span></span><span leaf="">从新加坡</span><span lang="EN-US"><span leaf=""> ESW Systems </span></span><span leaf="">发给了印尼国家警察。该系统号称可通过</span><span lang="EN-US"><span leaf=""> WiFi </span></span><span leaf="">提取目标设备的数据。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004832" data-ratio="0.12485549132947976" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=2e56cc6c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgcxme3qnadF1rwqLnWoMib5Unpt1B8DxaNibjB2tmvkdugUUU6MAGavRv5xlFsyeIQgCbaz8UOicR9Dwq3n9EJyQCZEXB62mEjDA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Intellexa</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">的间谍软件在多地以</span><span lang="EN-US"><span leaf=""> Predator</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Helios </span></span><span leaf="">和</span><span lang="EN-US"><span leaf="">Arrows </span></span><span leaf="">等名字销售。通过全网测绘，研究人员在印尼境内发现了一台服务器，其指纹特征与</span><span lang="EN-US"><span leaf=""> Predator </span></span><span leaf="">间谍软件的后端服务器完全吻合。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2021</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">年底其后端服务器（</span><span lang="EN-US"><span leaf="">103.106.174.99</span></span><span leaf="">）暴露 ；</span><span lang="EN-US"><span leaf="">2022 </span></span><span leaf="">年捕获到其伪造西巴布亚和印尼新闻的域名</span><span lang="EN-US"><span leaf=""> (ewestpapua.org) </span></span><span leaf="">；</span><span lang="EN-US"><span leaf="">2023 </span></span><span leaf="">年捕获到其伪造</span><span lang="EN-US"><span leaf=""> Gelora </span></span><span leaf="">新闻</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">政党的域名</span><span lang="EN-US"><span leaf="">(geloraku.id) </span></span><span leaf="">。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Candiru (Saito Tech) </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">支持针对</span><span lang="EN-US"><span leaf=""> Windows</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">iOS </span></span><span leaf="">和</span><span lang="EN-US"><span leaf="">Android </span></span><span leaf="">平台的攻击，甚至内置了完整的漏洞利用链，用于收集端点设备元数据和社交媒体情报。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5017341040462427" data-type="png" data-w="865" style="width:464px;height:233px;" data-imgfileid="100004833" src="https://wechat2rss.xlab.app/img-proxy/?k=af788a75&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNj7WEo8ZAJFz2JScDox3R2WrGSicibN7Uf1gsM99gWYFs47ib0G2EsFPNDvvv5mdzlXSAzBgyZH55dYwGA7JFbMyrbG8nOhCs3jNM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">数据证实</span><span lang="EN-US"><span leaf=""> 2020 </span></span><span leaf="">至</span><span lang="EN-US"><span leaf=""> 2021 </span></span><span leaf="">年间有针对印尼警方的系统交付。</span><span lang="EN-US"><span leaf="">2021 </span></span><span leaf="">年</span><span lang="EN-US"><span leaf=""> 7 </span></span><span leaf="">月，</span><span lang="EN-US"><span leaf="">CitizenLab</span></span><span leaf="">和微软的报告通过网络扫描也确认了印尼存在疑似客户 。其中一个域名</span><span lang="EN-US"><span leaf=""> indoprogress[.]co </span></span><span leaf="">模仿了印尼的左翼新闻网站</span><span lang="EN-US"><span leaf=""> IndoPROGRESS</span></span><span leaf="">。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">全网扫描发现与</span><span lang="EN-US"><span leaf="">NSO</span></span><span leaf="">关联的防火墙</span><span lang="EN-US"><span leaf=""> IP</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">117.102.x.x</span></span><span leaf="">和</span><span lang="EN-US"><span leaf=""> 203.142.x.x</span></span><span leaf="">）属于印尼的</span><span lang="EN-US"><span leaf="">&#34;RADIKA KARTA UTAMA&#34; </span></span><span leaf="">公司网络，这恰好与前文印尼警方招标数据库中购买</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">零点击</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">系统的中标公司是同一家。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3745664739884393" data-type="png" data-w="865" data-imgfileid="100004834" src="https://wechat2rss.xlab.app/img-proxy/?k=fde69170&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhOJoBly6ndh8uBrFz3eS8Yek7iaV0nHc3KlqznibSKpGAUYssbiaJSKZLeKcQ0GzFb7ckGlOq3U5Tn2ibQ65mT9eADcefus2YWezE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Kimsuky</span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">正在使用</span><span lang="EN-US"><span leaf="">Go</span></span><span leaf="">重写核心恶意软件</span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">S2W</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">内部使用</span><span lang="EN-US"><span leaf="">puNK</span></span><span leaf="">代表朝鲜方向的攻击组织，</span><span lang="EN-US"><span leaf="">Kimsuky </span></span><span leaf="">被细分为</span><span lang="EN-US"><span leaf=""> DragonpuNK, SharkpuNK, </span></span><span leaf="">和</span><span lang="EN-US"><span leaf=""> SeedpuNK</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7159468438538206" data-type="png" data-w="602" style="width:396px;height:284px;" data-imgfileid="100004835" src="https://wechat2rss.xlab.app/img-proxy/?k=222c12d6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaIzooicIrmibHv0IVn1wzetxm8nqJRqkdYbQYtMiasmuxEst0wTzMK6iaySj9tx4h2JYf7JSHHxBP65BPbichCgd9gqqdicqwOqOlTY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">每个攻击小组都有各自的武器库，</span><span lang="EN-US"><span leaf="">SeedpuNK </span></span><span leaf="">被认为是一个专注于开发后门和窃密木马的核心技术团队。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.41502890173410406" data-type="png" data-w="865" data-imgfileid="100004836" src="https://wechat2rss.xlab.app/img-proxy/?k=93fd6cb6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNg4vNu1H05JFroCDp9aNnLlgS0FnUdNHwUS8oJsglvibRzh3BRFB2Lt8gyftLZxeLyicjJpYZBx3qPFuJRLBaKpuj1ZpV3SPibM5k%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">SeedpuNK</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">传统的恶意软件是使用</span><span lang="EN-US"><span leaf="">C/C++</span></span><span leaf="">开发的，只针对</span><span lang="EN-US"><span leaf="">Windows</span></span><span leaf="">系统。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.353757225433526" data-type="png" data-w="865" data-imgfileid="100004837" src="https://wechat2rss.xlab.app/img-proxy/?k=799f582a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgbYr6qrv9cTaf3CgDSYia5iaM44tn7ia3ooPyrkCibjqbtfYUb6VqfBHshwbsQtLFBjY445Rs6hwJ0iaAiaviaqfq1YBVOWVDow9eL6E%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">近期发现</span><span lang="EN-US"><span leaf=""> SeedpuNK </span></span><span leaf="">在使用三种新恶意软件：</span><span lang="EN-US"><span leaf="">AlphaSeed, Troll Stealer </span></span><span leaf="">和</span><span lang="EN-US"><span leaf=""> GoBear</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5156069364161849" data-type="png" data-w="865" data-imgfileid="100004838" src="https://wechat2rss.xlab.app/img-proxy/?k=d485f37a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNge7XuHSbRQvb2mCnQiaa3dhnqnN2CqCoTIsNTAhUQ9SDWxhsInmfzWhzDNzokVibVHDmXlNMMdCPGtClrePyp9bPjFYXn5lfSJg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">传统的利用邮箱做</span><span lang="EN-US"><span leaf=""> C&amp;C </span></span><span leaf="">的木马通常使用</span><span lang="EN-US"><span leaf=""> SMTP/IMAP </span></span><span leaf="">协议，容易被防火墙拦截或被邮件服务商风控。</span><span lang="EN-US"><span leaf="">AlphaSeed</span></span><span leaf="">内置并使用了名为</span><span lang="EN-US"><span leaf="">chromedp</span></span><span leaf="">的无需外部依赖、通过</span><span lang="EN-US"><span leaf=""> Chrome DevTools </span></span><span leaf="">协议驱动浏览器的</span><span lang="EN-US"><span leaf=""> Go</span></span><span leaf="">代码库。在受害者机器上启动一个不可见的</span><span lang="EN-US"><span leaf=""> Chrome </span></span><span leaf="">浏览器，像真人一样在网页版</span><span lang="EN-US"><span leaf=""> Naver </span></span><span leaf="">邮箱里点按钮、写邮件。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2774566473988439" data-type="png" data-w="865" data-imgfileid="100004839" src="https://wechat2rss.xlab.app/img-proxy/?k=d07ddc51&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgiaqr70HmU1icAsaVyYC8CfmkLkO3loWn3XPgOh0DgGNIgLic8vbdGvKSPKdkkhb9pw9QJd0vYKUcibKj8tqk0nTdF8eCzIed7S4w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4069364161849711" data-type="png" data-w="865" data-imgfileid="100004840" src="https://wechat2rss.xlab.app/img-proxy/?k=580ee0af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNg0bYmsVOTEdjA1dnMoEwDwAs1Ppvibd3JnFt2szia0QkjznUe7rucAmVukoMPOSAS1VTibffRn4zSIqH1tM6sMx3IfJxpTYCqcl8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">为什么一个习惯于</span><span lang="EN-US"><span leaf=""> C++ </span></span><span leaf="">的黑客组织能在短时间内高产出如此多基于新语言的恶意软件？微软认为</span><span lang="EN-US"><span leaf="">Kimsuky</span></span><span leaf="">深度利用了大模型。韩国政府也在推行基于</span><span lang="EN-US"><span leaf="">Linux</span></span><span leaf="">的国产操作系统，</span><span lang="EN-US"><span leaf="">Go</span></span><span leaf="">可以更容易地跨平台。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7017341040462428" data-type="png" data-w="865" data-imgfileid="100004841" src="https://wechat2rss.xlab.app/img-proxy/?k=037a30ae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgrtTO09yc2QqCY458LawW7u2OORqDGdQAlVrFOYwnIMJopuSNShBmOOFklhZA4jZMEVW0avVC9CLJ6hIHIa9q35I4bpLBibZGc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Gh0st</span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">的前世今生 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">多个</span><span lang="EN-US"><span leaf="">Gh0st</span></span><span leaf="">的变种演化关系：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5965317919075145" data-type="png" data-w="865" data-imgfileid="100004842" src="https://wechat2rss.xlab.app/img-proxy/?k=bbff8c86&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNj8FiaibjYkSOibibW8Bhyxq6c6icxPfqibvIw2cIj8ibatAotgN94oOGtKbCiatp9b1icP3Dj21mzDXoG50TLbkmhvgXzZ9oq4ns7xbohk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">想要在主机端狩猎，关注那些在历代变种中几乎不怎么改变的核心封装函数，例如自定义的</span><span lang="EN-US"><span leaf=""> MyCreateThread()</span></span><span leaf="">：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5283236994219653" data-type="png" data-w="865" data-imgfileid="100004843" src="https://wechat2rss.xlab.app/img-proxy/?k=9798ed4a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjLFJ7oduhibVjDr0WhpdjLCzrfs7qsF1ncZRTbnZqs8P8RzufkiaxW1eeBFuXPOGqsiaVia7hHEecnQwM57FrfoZq6LicC9gf8Tibib0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">想要在网络侧狩猎，底层的网络包协议结构是固定的：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.36878612716763004" data-type="png" data-w="865" data-imgfileid="100004844" src="https://wechat2rss.xlab.app/img-proxy/?k=c445528f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgFg5KlxvktibicbDHxcbmgd3MLNgehHfMRowH4NReibRlAtkM19OICokjTXdcrkXLMasKibveedaVm9Io6tJibiaHJibib7qD5WTelh70%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">发布的威胁报告在加强互联网防御中的作用 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">分析了</span><span lang="EN-US"><span leaf=""> 2010 </span></span><span leaf="">年至</span><span lang="EN-US"><span leaf=""> 2024 </span></span><span leaf="">年</span><span lang="EN-US"><span leaf=""> 7 </span></span><span leaf="">月期间发布的</span><span lang="EN-US"><span leaf=""> 2264 </span></span><span leaf="">份威胁报告，其中有</span><span lang="EN-US"><span leaf=""> 498 </span></span><span leaf="">份报告提到了</span><span lang="EN-US"><span leaf=""> CVE</span></span><span leaf="">。报告中共提及了</span><span lang="EN-US"><span leaf=""> 1316 </span></span><span leaf="">个</span><span lang="EN-US"><span leaf="">CVE</span></span><span leaf="">，其中去重后为</span><span lang="EN-US"><span leaf=""> 449 </span></span><span leaf="">个独特</span><span lang="EN-US"><span leaf=""> CVE</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.45202312138728323" data-type="png" data-w="865" data-imgfileid="100004845" src="https://wechat2rss.xlab.app/img-proxy/?k=84fa4145&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjeSmfMPMGdyAdagiaA5CibfB783zynwyckeHZUNytIVXZW6dp6gAQuLwJWGVibsr7kUEhboG86km1sib6PfrMm9fYbhL7lVYiamma4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">例如特定漏洞：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3838150289017341" data-type="png" data-w="865" data-imgfileid="100004846" src="https://wechat2rss.xlab.app/img-proxy/?k=52ada242&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgU6ibefYB1NEXvzVwricM2qiad3ze1Znxo97wkZdGPBJu0IqCRbLtxNKKH7HMIB7zpvNNp94ibZsRyPNm6IEhvhlFvibcBHiaHAupL0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3838150289017341" data-type="png" data-w="865" data-imgfileid="100004847" src="https://wechat2rss.xlab.app/img-proxy/?k=224d1b9e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgtbtn71TcD35s4ZpJWo5RM1M7N9aBkxH7jv5DOibDIDt6ZZIEGwAxQG0e4HDUibIEsz7mRwiam6BZBVdc34ZpMiaN72knibJWUgES8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">按受影响的软件来看：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.45433526011560693" data-type="png" data-w="865" data-imgfileid="100004848" src="https://wechat2rss.xlab.app/img-proxy/?k=80883a30&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNg7IRF61mGVJP38Y6WTtic2aQmykgN0XpqPibNB3W55Of2D5wGhMuE8pRJXFfYzKTQYpynb2ic6Lib9qcs1CVOyC5h3tdqSryGP4Ew%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9549132947976878" data-type="png" data-w="865" style="width:302px;height:288px;" data-imgfileid="100004849" src="https://wechat2rss.xlab.app/img-proxy/?k=8f8f4e05&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgz3QnRibpKPgBJL2ZeXJOp7TGwkeJ7nvQibqMaeuGHvNueSmKN3ianzcibGzTMURekCsQTM5OIKrcB1v593TeichPiceYZ7Unl9jmhk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">部分影响力较大的报告：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3838150289017341" data-type="png" data-w="865" data-imgfileid="100004850" src="https://wechat2rss.xlab.app/img-proxy/?k=48b77126&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNglMpS0icROob6YGBv8T2KINtZVjyhawgKGGdOF8iaIOPMHPu7iaXqAc7Y33xZicJhMTFoZNgtKaVscPbf0FY2KCz8QrT3CPfT3nko%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">为什么有些写得很好的报告却无人问津？该漏洞已经是众所周知的旧漏洞，用户早就打过补丁了；在遥测数据中该软件的可见度很差（例如只在特定小国家流行）；或者在报告发布期间，扫描器厂商（如</span><span lang="EN-US"><span leaf=""> Tenable</span></span><span leaf="">）还没有开发出对应的检测插件。</span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">如何利用知识图谱与图神经网络狩猎攻击基础设施 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">从响应式检测前移，构建主动式检测。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3606936416184971" data-type="png" data-w="865" data-imgfileid="100004851" src="https://wechat2rss.xlab.app/img-proxy/?k=b5f3ccd8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhXIpFiaIZmVQMGalHA6sBRpicbwR7fp4soksoe16GUF3ydEJF5YcbibziblyDcDmsFibzwgun6ICp1UEKwiczcnGVCBMHMCq55K1lrs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">恶意主机名</span><span lang="EN-US"><span leaf=""> -&gt; </span></span><span leaf="">分析新注册主机名</span><span lang="EN-US"><span leaf=""> -&gt; </span></span><span leaf="">发现共宿关系（综合</span><span lang="EN-US"><span leaf=""> TLS</span></span><span leaf="">、哈希、</span><span lang="EN-US"><span leaf="">SSH</span></span><span leaf="">、重定向等信息）</span><span lang="EN-US"><span leaf="">-&gt; </span></span><span leaf="">构建知识图谱</span><span lang="EN-US"><span leaf=""> -&gt; </span></span><span leaf="">送入图人工智能（</span><span lang="EN-US"><span leaf="">Graph AI</span></span><span leaf="">）模型</span><span lang="EN-US"><span leaf=""> -&gt; </span></span><span leaf="">预警的恶意域名。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4369942196531792" data-type="png" data-w="865" data-imgfileid="100004852" src="https://wechat2rss.xlab.app/img-proxy/?k=202c4c02&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjThx8DmNxXmibMDyJE6IRGr5icGCPlPLg2F0Ccp5ia24hRbmHBL5GZkzzZBf7ENXrFHicUQ8Q4FNR1bYs3Az9LbRt7EmJEsMics4ME%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">多维度特征工程：词法特征（如包含大厂名字</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">连字符）、托管特征（绑定</span><span lang="EN-US"><span leaf=""> IP </span></span><span leaf="">数量、托管时长）、</span><span lang="EN-US"><span leaf="">WHOIS </span></span><span leaf="">特征（域名注册时间、过期时间、是否开启隐私保护）、证书特征、</span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">特征（</span><span lang="EN-US"><span leaf="">ASN</span></span><span leaf="">、国家代码）、基于网页内容的特征（如是否包含诈骗表单、</span><span lang="EN-US"><span leaf="">iframe </span></span><span leaf="">数量）。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.47630057803468207" data-type="png" data-w="865" data-imgfileid="100004853" src="https://wechat2rss.xlab.app/img-proxy/?k=24a6c018&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgSGeia6eJx3x879x6wibicPibmLqjShg44f9L4micq3GibEnDicSrEcFICAcJa3B8yBibsFvCH6iabnia7ZibcuTodBO0KvbgCPArX4s5U28%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">使用半监督图神经网络进行训练：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5098265895953757" data-type="png" data-w="865" data-imgfileid="100004854" src="https://wechat2rss.xlab.app/img-proxy/?k=bedc6b26&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgRrPI8oyBzT0qBpnJrn3UbEyBRv6yygv0wcxvzEqsI49wJ3ibrtQK2HPGPfnQOXjpbOcAuKEBgEnO8icAaIaqEvhrevRORuFJLk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">效果非常好，如果牺牲一半的检出率（召回率下降），可以获取</span><span lang="EN-US"><span leaf="">99.9%</span></span><span leaf="">的准确率。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.37109826589595374" data-type="png" data-w="865" data-imgfileid="100004855" src="https://wechat2rss.xlab.app/img-proxy/?k=80991b0b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiakJ9rKpFnsrgjR7jsibKIW5IibgTV6TibzZ7ybhqicxvbI6JlhibEez5UWZ7zDLg4LjEXcYP9o6C3MWlNnjjXwxITcSOPLaVL3LSgI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通过</span><span lang="EN-US"><span leaf="">UMAP</span></span><span leaf="">等方式对特征空间进行降维可视化：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.500578034682081" data-type="png" data-w="865" data-imgfileid="100004856" src="https://wechat2rss.xlab.app/img-proxy/?k=0d249e6c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhvZVfc15Bw6UzuraVmI1gmibrXJ4qj8e4QlRF0Zsuayica6tC4nr0LFkEGUp5p8icU05qDdxG9KjcdCuiaRZ7OvR2dkZvIcqC83icw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">基于</span><span lang="EN-US"><span leaf="">Gamaredon</span></span><span leaf="">的少量种子，扩展出对更多基础设施的判断：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5387283236994219" data-type="png" data-w="865" data-imgfileid="100004857" src="https://wechat2rss.xlab.app/img-proxy/?k=add5edb8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjaibkCAoQru0eOdNM8lBflU1z9JI9bXJzdhuUXLibL4kvlyr814QTDaHtzibHczqLkgwOib4GQrOj3ZuibhKGIyDwlsJXwFIYcmeyM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">其中有</span><span lang="EN-US"><span leaf="">34</span></span><span leaf="">个域名后续被标记为恶意：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5468208092485549" data-type="png" data-w="865" data-imgfileid="100004858" src="https://wechat2rss.xlab.app/img-proxy/?k=289bd368&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhZ4AjpepnUh0et7detUGCA4gxwjWtOh3aXFYSfPD2Xib06Ma0WicHZ9rDIlApUS2LBLWy0OxTuKkrjIUCbiaicDcqua05XKtcK84U%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">网络安全中便利的隐形代价 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">容易被远程访问的设备分布：路由器（</span><span lang="EN-US"><span leaf="">29%</span></span><span leaf="">）、智能电视（</span><span lang="EN-US"><span leaf="">29%</span></span><span leaf="">）、</span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">摄像头（</span><span lang="EN-US"><span leaf="">26%</span></span><span leaf="">）、</span><span lang="EN-US"><span leaf="">DVR</span></span><span leaf="">录像机（</span><span lang="EN-US"><span leaf="">6%</span></span><span leaf="">）、机顶盒（</span><span lang="EN-US"><span leaf="">3%</span></span><span leaf="">）等。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5815028901734104" data-type="png" data-w="865" data-imgfileid="100004859" src="https://wechat2rss.xlab.app/img-proxy/?k=cd54d8f5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhBosgzicJu24VIhv7NWeNibg3A4Mej8wofGWv5e0Hk3OiaicEfs6DwUsRkOzsicmgVyWaj0GhATnrXkuydO6Sr68s3iar6BEOicWxW7Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">UPnP</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">问题很多：缺乏身份验证、输入验证不严、内存损坏漏洞、</span><span lang="EN-US"><span leaf="">SQL </span></span><span leaf="">注入、</span><span lang="EN-US"><span leaf="">XML </span></span><span leaf="">外部实体（</span><span lang="EN-US"><span leaf="">XXE</span></span><span leaf="">）攻击、缺乏日志记录等。并且，很多路由器厂商写代码太烂，不仅内网可以调</span><span lang="EN-US"><span leaf=""> UPnP</span></span><span leaf="">，甚至外网也能发指令。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5144508670520231" data-type="png" data-w="865" data-imgfileid="100004860" src="https://wechat2rss.xlab.app/img-proxy/?k=9e54462c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiayXmYO1uicm0DickXYGcyrTjZHuOicenehj161zo2ota0p2LVEYZN2y3tczqYAlxV0BHPQqicw4JQ6qYHT7yR8ojxno5KrVako0CI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">出厂默认使用且不会被修改：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5468208092485549" data-type="png" data-w="865" data-imgfileid="100004861" src="https://wechat2rss.xlab.app/img-proxy/?k=3674abfc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhxPtUz94cFDxbv5Q9LTXD2B4ic43MSYLHiabOvVHP7pW1H9vdHjJpyaqMQnLTkGSq9Q8ytiaFQu2UCKnmcQJpSkplaiaBKLibMeibx4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">超过半数的家庭每天都在经历外部的</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">远程访问</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">，可如果是在默认禁用</span><span lang="EN-US"><span leaf="">UPnP </span></span><span leaf="">的设备中，发生远程访问的骤降至</span><span lang="EN-US"><span leaf=""> 9%</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5884393063583815" data-type="png" data-w="865" data-imgfileid="100004862" src="https://wechat2rss.xlab.app/img-proxy/?k=9397962d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgpcEUhTtCtCVFAAV4yjMpyhepLpvjJTuiccV1qliaYHeYVzazJs4SOlEhom6twcvxVtfiaicFNj9hEFe6kn0iaDZ8iaJhTeaFtFgZ7E%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">攻击者滥用云端集成开发环境构建基础设施</span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">各家都推出了云端集成开发环境</span><span lang="EN-US"><span leaf="">CDE</span></span><span leaf="">：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4254335260115607" data-type="png" data-w="865" data-imgfileid="100004863" src="https://wechat2rss.xlab.app/img-proxy/?k=0598d910&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaYdLDQ4iao1rheXPGRD0l2jOia0OPEzJkZicYETfqVJ0HibxW26IDFh27vxtp429dy4pbtrNnRUVWicOXrvxMddbQbsiaKsOB45Av7s%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">GitHub Codespaces</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">的架构很典型：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5375722543352601" data-type="png" data-w="865" data-imgfileid="100004864" src="https://wechat2rss.xlab.app/img-proxy/?k=42bc3e1e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNg1hrwCc1dhMpjr6IaibZfn7ib2uibGmHL3CeJicKDPllo3tsOnibNVez8Sp0xSFDofict8saJ01EbgkEzPPE6KXAABFCCgXTTZIxark%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">攻击者很简单即可利用公共服务开放暴露特定端口，</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.43583815028901735" data-type="png" data-w="865" data-imgfileid="100004865" src="https://wechat2rss.xlab.app/img-proxy/?k=f8923fc9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhcyicKCovbWic4FuicPqRoeLgohn7HGxuMd9GdxqkMqvUqcHZWMlIvWEcVasibtwIk6WtmIiapNQZ45qkeF1gtg9aygCuRnpQ5AGYQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4890173410404624" data-type="png" data-w="865" data-imgfileid="100004866" src="https://wechat2rss.xlab.app/img-proxy/?k=a32df488&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNj2IWH0Stibxum0LveWlhZticia8tvaBlz94hI7MBVL1dL2H7jicibkVFsJ8ZUvqkHJhNkhn6gF6eBKRMrq4pg4nIjh8KOqC1ia0ZlSo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">访问的子域名还挂在</span><span lang="EN-US"><span leaf="">GitHub</span></span><span leaf="">的官方域名下：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1630057803468208" data-type="png" data-w="865" data-imgfileid="100004867" src="https://wechat2rss.xlab.app/img-proxy/?k=b50924a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNia7N4GGmTIViaBicB4XEdw0Sv4jVibaicxdRJza6LDUEhBYzdrr6V02P3xnlPX4clqibg2YGIiaYroicTp79xJLmKzJZViaO35OM751ltE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">攻击者已经开始滥用该技术，从单一维度转向上下文关联可发现异常：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-type="png" data-w="865" data-imgfileid="100004868" src="https://wechat2rss.xlab.app/img-proxy/?k=bd817ece&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaj7zichJzicqQcrKaYCIEQLRxfsmaehQQHECtiaqD782owQVrX4MISuzEOibEeC3rfgYfwJkP0wyB46OdZRCclJu8rv1ToS2qSovU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">多模态</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">作为网络防御第六感 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐ </span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">基于</span><span lang="EN-US"><span leaf="">GPT-4o</span></span><span leaf="">进行钓鱼邮件检测，编写提示词即可自动分析邮件头、正文与视觉元素，并以极少的样本识别新型钓鱼攻击。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4601156069364162" data-type="png" data-w="865" data-imgfileid="100004869" src="https://wechat2rss.xlab.app/img-proxy/?k=77bcc722&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgwtEORtIWggYgvtqXGZwGyd8qjNBOeNOgURFucg6z5Ipo0A3vp6qiaHFibVABcPM3njNhb5IQ1iaNUxB16iaXv8wMcYhYzl9NSrFI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">例如仿冒</span><span lang="EN-US"><span leaf="">Paypal</span></span><span leaf="">的钓鱼邮件：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.40346820809248557" data-type="png" data-w="865" data-imgfileid="100004870" src="https://wechat2rss.xlab.app/img-proxy/?k=64c7552c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNia2pTsRdiaxOkl3sIMaibF4gjHbwkR5AgRCgib8oianTUqTYqlWHkFYa5Oia5Z2cvRChx58LQwyYPCXpufBNibZ3lsjnb2lmDQ4uy6VY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">对比了传统</span><span lang="EN-US"><span leaf=""> ML</span></span><span leaf="">（随机森林</span><span lang="EN-US"><span leaf=""> RF</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">XGBoost</span></span><span leaf="">）与多模态</span><span lang="EN-US"><span leaf=""> AI (GPT-4o) </span></span><span leaf="">的表现，多模态</span><span lang="EN-US"><span leaf=""> LLM </span></span><span leaf="">掌握了</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">欺骗行为</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的底层逻辑和视觉语义模式，具备极其强大的泛化能力。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.48323699421965316" data-type="png" data-w="865" data-imgfileid="100004871" src="https://wechat2rss.xlab.app/img-proxy/?k=a5c03fdd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaItELF9BTfHcqkNqMosUzOcfnogoR5HaEHGYL7G8dKZ3ujg1ISnzbleQNNaPyzXmNicvKNKa2aTNPuFuia0UtZEtYlYNXXrAYLE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">基于多模态的网站分类流水线：</span><span lang="EN-US"><span leaf="">HTML/</span></span><span leaf="">图像</span><span lang="EN-US"><span leaf=""> -&gt; GPT-4o </span></span><span leaf="">文本描述</span><span lang="EN-US"><span leaf=""> -&gt; OpenAI </span></span><span leaf="">嵌入模型生成数值向量</span><span lang="EN-US"><span leaf=""> -&gt; </span></span><span leaf="">训练随机森林</span><span lang="EN-US"><span leaf="">/XGBoost </span></span><span leaf="">进行分类 。这是一个大模型蒸馏架构，大模型作为</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">高级特征提取器</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">，将复杂的视觉信息降维成文本，再转成向量，最后交给计算成本极低的传统树模型去执行快速分类，以此来平衡检测精度与算力成本。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5479768786127167" data-type="png" data-w="865" data-imgfileid="100004872" src="https://wechat2rss.xlab.app/img-proxy/?k=018afca4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjEUYwicWjyfEQ3tMiaw7EuRfzqRwFzv6Ey8Qjkc9Nw4E0eRUib3ApxBJrgn9smOoShp7AvRLhDhdJyBC9FqYCzakOIdweh5dib7iao%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">顶级</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">组织</span><span lang="EN-US"><span leaf="">The Mask</span></span><span leaf="">重新回归 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">The Mask</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通常被认为是西班牙语国家支持的黑客组织，从过往的攻击目标来看，极有可能是西班牙本土国家级情报机构。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.0335260115606937" data-type="png" data-w="865" data-imgfileid="100004873" src="https://wechat2rss.xlab.app/img-proxy/?k=794f4c18&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhaDbcTeXB4Puveu3NnqOIR4WHFvNkkfaaSCALwuXHEbMpyaRibaqzbGBcGHxOCbaPKjFicOg2AEkibicuKicfMho6mNwgF0wkCIROw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">FIN7</span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">开始使用新型</span><span lang="EN-US"><span leaf="">AI </span></span><span leaf="">深度伪造诱饵 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">FIN7</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">注册了数千个域名，使用了</span><span lang="EN-US"><span leaf=""> 68 </span></span><span leaf="">种不同的顶级域名。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9757225433526011" data-type="png" data-w="865" data-imgfileid="100004874" src="https://wechat2rss.xlab.app/img-proxy/?k=25438a73&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNia9Ju8faBty1ibtVwNUYQmzdn1AIxTGwiaMbqPicClATdk1DKLDlLxF7bkzlQehAKtZYc8UF5b8eaCkSZOibvMAXKINiakLg3ytAwgU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">这些域名托管在</span><span lang="EN-US"><span leaf=""> 90 </span></span><span leaf="">个自治系统上。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6566473988439306" data-type="png" data-w="865" data-imgfileid="100004875" src="https://wechat2rss.xlab.app/img-proxy/?k=e3b3fd99&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgvcFqFIXoUu8MvCqibtUtbicO0Y3R4eAsOicBiaVqIhAEibgusgs0qSGzMB6kVXicn6wLfZqzLYEsqsC2jicPzUyBS8AFv4oPvlKvUZ4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">FIN7</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">正在托管多个蜜罐，例如通过名为</span><span lang="EN-US"><span leaf="">“aiNude.ai”</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">一键脱衣生成器</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">来分发恶意软件。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6023121387283237" data-type="png" data-w="865" data-imgfileid="100004876" src="https://wechat2rss.xlab.app/img-proxy/?k=086b0fce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiajf7fcC2935VdGNmWqI6pyB75NLlWfUiaV0DibkHEta6ffCbIfIhpUqdWobnJwcRvyq6hzpEOUwwJ1iaru9lNeZIGx2icdTLyAVCw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">AI</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">深度伪造蜜罐的代码中包含了来自</span><span lang="EN-US"><span leaf=""> Facebook Audience Network</span></span><span leaf="">与俄罗斯</span><span lang="EN-US"><span leaf=""> Yandex Analytics </span></span><span leaf="">的</span><span lang="EN-US"><span leaf=""> JavaScript </span></span><span leaf="">跟踪代码，但目前尚未发现相关的广告。一方面是帮助黑客监控受害者流量和转化率，另一方面是带有商业追踪代码的页面更容易被安全厂商的自动化爬虫判定为</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">合法的商业网站</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">，从而降低被封堵的概率。</span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">恶意代码签名的早期预测 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">代码签名证书的两大主要用途：标明软件发布者身份、验证软件是否被篡改。曾经</span><span lang="EN-US"><span leaf="">Stuxnet</span></span><span leaf="">这种国家级</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">才会盗用证书，现在各种犯罪团伙都开始这么玩。获取证书的途径分为两种：</span><span lang="EN-US"><span leaf="">1</span></span><span leaf="">、从已有证书的组织窃取（传统常见方法）；</span><span lang="EN-US"><span leaf="">2</span></span><span leaf="">、购买通过各种手段签发的证书（近期激增的方法）。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">暗网中的证书售卖主要集中在拉脱维亚、立陶宛、爱沙尼亚和英国，卖家甚至提供</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">代建壳公司</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">服务。价格不菲，说明攻击的回报其实很高。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5919075144508671" data-type="png" data-w="865" data-imgfileid="100004877" src="https://wechat2rss.xlab.app/img-proxy/?k=8220c37a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgvtqXbDha1qYoA6bfgoupYR5KKbtcWdZTXPuiaKvvibic8K8J8Qeda2ia0xicBIR8WpjOCEt51ht4j9hQ7qMA39eh2vswAxTVRuNU8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">由于有真金白银的投入，所以只要</span><span lang="EN-US"><span leaf="">CA</span></span><span leaf="">没有将证书吊销，攻击者就会持续使用好几个月。攻击者也不会直接就签发恶意样本，而是先签发合法样本提高证书信誉度。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1722543352601156" data-type="png" data-w="865" data-imgfileid="100004878" src="https://wechat2rss.xlab.app/img-proxy/?k=40104d44&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaoY5JZlYd1VQOicP2eHL8dB6FDtY76AG9m89B5M19mT6EZzcN1xBIVoiaVtY4JarFEdMx4aFBJMBNPCalb4U9ffnumwHIp8kLQY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">同一提交者会在同一时间点，提交多个不同证书签发的测试样本。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.376878612716763" data-type="png" data-w="865" data-imgfileid="100004879" src="https://wechat2rss.xlab.app/img-proxy/?k=2337c686&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNg1ICnDib6MI59EHGTa96sow7qlVHDwRWHU6S8L37DMXtWVQpMo4jFgLnehW3KqpibV6hbYCnc4cD0rsvNGcnD92dfAEr2fDohCY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">交者</span><span lang="EN-US"><span leaf=""> E </span></span><span leaf="">在</span><span lang="EN-US"><span leaf=""> 12</span></span><span leaf="">月</span><span lang="EN-US"><span leaf="">21</span></span><span leaf="">日</span><span lang="EN-US"><span leaf=""> 14:59 </span></span><span leaf="">到</span><span lang="EN-US"><span leaf=""> 15:00 </span></span><span leaf="">的短短一分钟内，连续提交了</span><span lang="EN-US"><span leaf=""> 5 </span></span><span leaf="">个由不同公司签发的</span><span lang="EN-US"><span leaf=""> putty </span></span><span leaf="">程序。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3606936416184971" data-type="png" data-w="865" data-imgfileid="100004880" src="https://wechat2rss.xlab.app/img-proxy/?k=a4eab25e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgicvT97CGFsyl45MQqDRkltgibQc5bzCzrL5os4pZrr6pv5weIicTQf6w7L6RVKleBjiaprBv39Lq59sL9VXLSYicJtyxaNdzSW1pI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">进一步找到其他测试样本：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3722543352601156" data-type="png" data-w="865" data-imgfileid="100004881" src="https://wechat2rss.xlab.app/img-proxy/?k=ba03e04f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgs4Ufibc715d4gapj29R5PgMBV8USkRfr3rsGVJlu9HHpUMjdyOnJ9NVpRI5Rs3O0WsFu4HSicM2UfoZBqyHFT2LVPNyMnibEvTo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">测试样本与实际恶意文件出现之间的平均时间差为</span><span lang="EN-US"><span leaf=""> 75.3 </span></span><span leaf="">天，这也为防御方创造了时间差。从各方面信息来看，攻击者应该是仿冒了合法公司，通过了薄弱的身份验证流程。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.41040462427745666" data-type="png" data-w="865" data-imgfileid="100004882" src="https://wechat2rss.xlab.app/img-proxy/?k=e1a26c80&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhe59GmXJkBXhfGMbGdHjThGM0mTdslwuJIiarIicBn2kuYPwb82jfQaKoJ8GvRmAbCkM2a0Or2E86eeKFtHhnbFJkpWTvD5VQNw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">巴基斯坦</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">组织如何武器化</span><span lang="EN-US"><span leaf="">WinRAR</span></span><span leaf="">漏洞 </span></span></b><b><span lang="EN-US" style="font-size:
12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">像</span><span lang="EN-US"><span leaf=""> WinRAR </span></span><span leaf="">这种泛用型软件爆出</span><span lang="EN-US"><span leaf=""> 1day/0day</span></span><span leaf="">，全球攻击者会快速在武器库中投入使用。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.36647398843930634" data-type="png" data-w="865" data-imgfileid="100004883" src="https://wechat2rss.xlab.app/img-proxy/?k=1a72c62c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaJ5RS1RA7ssQPIgG37OwaV8PXDqC0iaTd0V0KSa9pXyfib2To4GIqICAsiaRsXW68j2MPRYpq2VYZic6G3piag1BmmukvVWD27IdTE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">印度政府与军方正在从 </span><span lang="EN-US"><span leaf="">Windows </span></span><span leaf="">过渡到基于</span><span lang="EN-US"><span leaf="">Linux</span></span><span leaf="">开发的国产操作系统，所以攻击者也对应开发了</span><span lang="EN-US"><span leaf="">Linux</span></span><span leaf="">平台的攻击。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4982658959537572" data-type="png" data-w="865" data-imgfileid="100004884" src="https://wechat2rss.xlab.app/img-proxy/?k=458b6968&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgibEhJDH1ibbia4CoaxFso4Vd00zfFtTldcHqbQWho1qvGpV33r0LwicJUcvL00yP01opZzgZ2HrmOQXrjicWiblTeBH9TL1EvummaE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">可以发现其</span><span lang="EN-US"><span leaf="">Linux Stager</span></span><span leaf="">与</span><span lang="EN-US"><span leaf="">APT 36</span></span><span leaf="">的样本逻辑高度一致：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5387283236994219" data-type="png" data-w="865" data-imgfileid="100004885" src="https://wechat2rss.xlab.app/img-proxy/?k=de1aea8e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNj2qwuGEKuP5icvbnLT9yHCFC9vxWbzqu2KzqFME0wef98GA7ibstGOkibVBUlib9k08N5ExWic3fMyfuZ8huVppJIavVLiak3PIYAAw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Crimson RAT</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">是</span><span lang="EN-US"><span leaf="">APT 36</span></span><span leaf="">的核心武器：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.48323699421965316" data-type="png" data-w="865" data-imgfileid="100004886" src="https://wechat2rss.xlab.app/img-proxy/?k=7843e5c6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNia5icrccicHh6jpmORhibhicUdVSubNACSlOyc8ZmCV76a5WZSOewvNRRzg9vxKXkwTePFrK74YENicFPJUGarzTialOgMib6YUmgY8DE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">研究人员发现攻击者的服务器</span><span lang="EN-US"><span leaf=""> campusportals.in </span></span><span leaf="">存在目录遍历漏洞。直接在浏览器中就能看到攻击者存放的恶意</span><span lang="EN-US"><span leaf=""> HTA </span></span><span leaf="">脚本、诱饵文件等后端资源。</span></span></p><p style="text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6161849710982659" data-type="png" data-w="865" data-imgfileid="100004887" src="https://wechat2rss.xlab.app/img-proxy/?k=b109d3c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjBytuMFGqhajtrkVFGdLnuVLpRzEMglCUSSRZTsxeE0ibru5wP7C6O4jEg2WAcIfEjEiar3mIP0GAtfyuwxwOhHljqVEBVl11ns%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1251d206&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488540%26idx%3D1%26sn%3De1caba209ab0c0fcfc0b491b5e4348e2">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 24 Mar 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>Virus Bulletin 2025 议题慢递</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488440&amp;idx=1&amp;sn=22866492db4a3e9126a483d45e1c2bf4</link>
      <description>Virus Bulletin 也是老牌会议，2025 年大家聚在一起聊了什么？</description>
      <content:encoded><![CDATA[<p>原创 <span>Avenger</span> <span>2026-03-10 09:04</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b68ffd3e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FOsTASDqnFNjkqE6EA9Qmxza2ibsC9VmLv32rj2AfeQ09KxtVLRiaDhj4w5yvXLY4NIMYS5Yhs9KhsyE8qxjBqdzxaU820q0suou2xnPeRU1yg%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>Virus Bulletin 也是老牌会议，2025 年大家聚在一起聊了什么？</p>
  <p style="" data-pm-slice="0 0 []"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span mp-original-font-size="16" mp-original-line-height="1.6" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;font-family: 微软雅黑, sans-serif;line-height: 1.6;visibility: visible;" data-pm-slice="0 0 []"><span leaf="">Virus Bulletin </span></span><span mp-original-font-size="16" mp-original-line-height="1.6" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;font-family: 微软雅黑, sans-serif;line-height: 1.6;visibility: visible;"><span leaf="">也是老牌会议，从 </span><span mp-original-font-size="16" mp-original-line-height="1.6" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.6;visibility: visible;"><span leaf="">1991 </span></span><span leaf="">年就开始举办，历经三十余载。</span><span mp-original-font-size="16" mp-original-line-height="1.6" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.6;visibility: visible;"><span leaf="">2025 </span></span><span leaf="">年的 </span><span mp-original-font-size="16" mp-original-line-height="1.6" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 16px;line-height: 1.6;visibility: visible;"><span leaf="">VB </span></span><span leaf="">是在德国柏林举办的，为期三天。各国各公司的安全专家齐聚一堂，分享对全球威胁的理解与发现。</span></span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4962962962962963" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100004653" src="https://wechat2rss.xlab.app/img-proxy/?k=daaa1866&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgydyPlr4D4bBSVTa5aVTATZlNO6DMEIyNUfnH9GAYp2icbI7qZr56uBdgw9dzatxQJs3axyDkKTic7xxZjWicaVBtBPjqrFEYLCg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="" data-pm-slice="0 0 []"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span mp-original-font-size="16" mp-original-line-height="1.6" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 16px;font-family: 微软雅黑, sans-serif;line-height: 1.6;visibility: visible;"><span style="color: rgba(0, 0, 0, 0.9);font-family: 微软雅黑, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">若是通过本文的介绍，或者是查看官网议程安排后，对其中某些议题感兴趣的话，就可以在官网下载议题对应的材料进行扩展阅读。（</span></span><span mp-original-font-size="16" mp-original-line-height="1.6" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: 微软雅黑, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.6;visibility: visible;"><span leaf="">PS</span></span><span style="color: rgba(0, 0, 0, 0.9);font-family: 微软雅黑, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">：笔者根据自身的认知局限与好恶为部分议题打了推荐查看的星级，不代表对议题实际内容高下的评判，只是为部分时间宝贵的读者再节约些时间，这部分议题相对来说可能更加值得一看。）</span></span></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">基于</span><span lang="EN-US"><span leaf="">LLM</span></span><span leaf="">和函数级</span><span lang="EN-US"><span leaf="">Embedding</span></span><span leaf="">跟踪</span><span lang="EN-US"><span leaf="">IoT</span></span><span leaf="">僵尸网络血缘 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">源自朝鲜的</span><span lang="EN-US"><span leaf=""> IoT </span></span><span leaf="">攻击呈稳步上升趋势，国家级</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">组织越来越喜欢劫持民用</span><span lang="EN-US"><span leaf=""> IoT </span></span><span leaf="">设备（路由器、摄像头）作为攻击跳板来掩盖真实来源。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.553757225433526" data-type="png" data-w="865" data-imgfileid="100004654" src="https://wechat2rss.xlab.app/img-proxy/?k=f771225a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNg3wYGaGbA8hHpCqQNXDah6VYvgmRpg99PH3UF3TbDAKLPDQfgynQpO8T64lkOh68BKqmSZEewA6buh8nLzsgCk7H82HjtibK7o%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">构建了基于</span><span lang="EN-US"><span leaf=""> LLM </span></span><span leaf="">的深度二进制分析工具</span><span lang="EN-US"><span leaf="">DBP-L</span></span><span leaf="">，它能过滤噪声函数、测量</span><span lang="EN-US"><span leaf=""> C </span></span><span leaf="">代码相似度、追踪函数历史、分配标签、测量复用率，并提取证据来区分全新威胁还是变种。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.423121387283237" data-type="png" data-w="865" data-imgfileid="100004655" src="https://wechat2rss.xlab.app/img-proxy/?k=3ea6e9b6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgibokcA10LCznHVjlePhicIHjE7smHrCyCOlfap9SJGJXQadgz5CLpiaKfbUBia9x5dtR7yicUsZbQO9jjouTm9nVszJXjVtJluoD8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">反编译为</span><span lang="EN-US"><span leaf="">C</span></span><span leaf="">代码后，进行预处理和分词，再利用</span><span lang="EN-US"><span leaf="">LLM</span></span><span leaf="">进行语义分类，提取</span><span lang="EN-US"><span leaf="">Embedding</span></span><span leaf="">并生成特征向量。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4485549132947977" data-type="png" data-w="865" data-imgfileid="100004656" src="https://wechat2rss.xlab.app/img-proxy/?k=eb11b735&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNg1ozQcyp9a1cGQLWxQODFSPhTG8X2myib1XAPS3IFCKWy0KY2uckdE6AHog3UgmIAm3hpqnYhbX5N4RKaiaV37j5qycDHlUUZxs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">目标文件经</span><span lang="EN-US"><span leaf=""> Ghidra </span></span><span leaf="">反编译</span><span lang="EN-US"><span leaf=""> -&gt; LLM </span></span><span leaf="">筛选恶意函数</span><span lang="EN-US"><span leaf=""> -&gt; </span></span><span leaf="">生成向量</span><span lang="EN-US"><span leaf=""> -&gt; </span></span><span leaf="">生成函数哈希 </span><span lang="EN-US"><span leaf="">-&gt; </span></span><span leaf="">在数据库中查找相同的函数哈希获取家族标签。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4508670520231214" data-type="png" data-w="865" data-imgfileid="100004657" src="https://wechat2rss.xlab.app/img-proxy/?k=07701896&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhjAsueZWFlDsWicYhcCsI7JqYeKLsTrV0ZLpiciaz1LmU44ATF0LTfaAYurbjexWRJtDpzIL85XUbTo7Uq54ibUQRMMpTaq1wAbrs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">为了缩小搜索空间，利用嵌入向量并应用向量量化（</span><span lang="EN-US"><span leaf="">Vector Quantization</span></span><span leaf="">）技术，将相似向量映射为相同的短哈希（如</span><span lang="EN-US"><span leaf="">7ABBB9</span></span><span leaf="">）。通过</span><span lang="EN-US"><span leaf="">LSH</span></span><span leaf="">等量化技术，把浮点运算降维成哈希比对，兼顾了模糊匹配能力和极速检索。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.40346820809248557" data-type="png" data-w="865" data-imgfileid="100004658" src="https://wechat2rss.xlab.app/img-proxy/?k=6da2acac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaZQia03qoibxQjpvpdsBlr3VpeSWCdb3Ro7EZYgib8ymicWhibDicV1U6v2X1wwh0nN6xOwW9u2JONtnlznHHu6B5ryjyHkfem8KHp8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">C&amp;C</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">消息的演进过程：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.44277456647398844" data-type="png" data-w="865" data-imgfileid="100004659" src="https://wechat2rss.xlab.app/img-proxy/?k=1d98b7ab&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgRU8l5zKWq5jI61TAZrsLc6om65QjZhHClOGcs9e5RN4CfLr3Rlf30bgKGO1GNJcNccNRZUaPs4m1wKdAMQYm0bHVHNhia0taM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">完整家族血缘图谱：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4554913294797688" data-type="png" data-w="865" data-imgfileid="100004660" src="https://wechat2rss.xlab.app/img-proxy/?k=365e96e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaFQ54x60qfPnnrmnKURib1SmWyTzpHu9nNJnicIOAniaEyT10Kqa9ibL9a8tkMSTb1h5L1JTFTMGK1sUvK1zPWHFF4HX9oTxDMglc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Rebirth Reborn </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">不是一个独立的家族，而是</span><span lang="EN-US"><span leaf=""> Demon </span></span><span leaf="">家族的直接变异后代。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3976878612716763" data-type="png" data-w="865" data-imgfileid="100004661" src="https://wechat2rss.xlab.app/img-proxy/?k=5afbdcf7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhNqomaK7YEKCjrCMuTia0WDquIslLqFVGwoBURGYR8hRQH7XYSXSZja2EBtWfL7gIayqwLE4N8yzib9QsNX9sWCKP7RpHkZZUYA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">从编译的</span><span lang="EN-US"><span leaf=""> macOS </span></span><span leaf="">恶意软件中提取嵌入式脚本 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">原本是脚本（如</span><span lang="EN-US"><span leaf=""> bash </span></span><span leaf="">或</span><span lang="EN-US"><span leaf=""> Python</span></span><span leaf="">），但被打包成了</span><span lang="EN-US"><span leaf=""> macOS </span></span><span leaf="">的应用程序包（</span><span lang="EN-US"><span leaf="">.app</span></span><span leaf="">）或可执行文件。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7630057803468208" data-type="png" data-w="865" data-imgfileid="100004662" src="https://wechat2rss.xlab.app/img-proxy/?k=b6ff8233&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaur0MtkCj48bvzk3LS7pwKB6rJGJ6K4OlFtH3eiavvxM6mFLnvdkYZhiauPPXoMUvIkj1hRUod8u24zW93TRQKbZK9jTwUibmJP4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">常见的四种将脚本打包为原生应用的主流工具：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4092485549132948" data-type="png" data-w="865" data-imgfileid="100004663" src="https://wechat2rss.xlab.app/img-proxy/?k=4dd5a21b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNg04jjhWqyKnB17cARgHxlMTTn3erAebBmHYMDOhPqpJo7aMXZjkH4TibhIga6YG6dp1U8VrayP4iam0oRChlhhHwZEb3CKQ9Y0o%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Platypus</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">完全不混淆，只单纯套壳，比较简单。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5132947976878612" data-type="png" data-w="865" data-imgfileid="100004664" src="https://wechat2rss.xlab.app/img-proxy/?k=a0fc2c24&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhZdeeAicR7VIibOic6kY8TyDnTMIFibI5oLhSaIkXAICru7Q3zWLR0TNIUw67FY63OkMqS3np5ejiaKIX9uWiaic9ZKAEb9PAxGBrVd0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4913294797687861" data-type="png" data-w="865" data-imgfileid="100004665" src="https://wechat2rss.xlab.app/img-proxy/?k=2e80a489&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhcgG4PpiaKic9lhkiaianAF2IRGibN7licicpLomglLAqjEyju4ovtlkSIiaKLDE7ib4fib51V7Oc9rHLonYyaZVcgAfmvC7eiapkKfed6sY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">PyInstaller</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">也是相对好识别的：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5132947976878612" data-type="png" data-w="865" data-imgfileid="100004666" src="https://wechat2rss.xlab.app/img-proxy/?k=7aede4b3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaagwaUS9diadPFGabdFRiatSPXwQYI79UbfuMuVaJjAOnMbuL1ocUfqERsA3ELv6UGlen4kULSRE2DKevthEEnuVakuua7DA0cE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Electron</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">的应用体积通常会很庞大。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.48786127167630056" data-type="png" data-w="865" data-imgfileid="100004667" src="https://wechat2rss.xlab.app/img-proxy/?k=f7c2c981&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgR5UjtpYWw6UlaAwXDibUsLyM6b1hT7mEj5UdzLHLneekT7MgQNza9iajGvwe8hj6kx1qOCs6XEEAic5s99Gs5jaIrI3NB1TAltU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Tauri</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">默认使用</span><span lang="EN-US"><span leaf=""> Brotli </span></span><span leaf="">算法对</span><span lang="EN-US"><span leaf=""> JS/HTML </span></span><span leaf="">资源进行压缩并硬编码到</span><span lang="EN-US"><span leaf=""> Mach-O </span></span><span leaf="">数据段中。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.48786127167630056" data-type="png" data-w="865" data-imgfileid="100004668" src="https://wechat2rss.xlab.app/img-proxy/?k=2ccc54f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhwkbm5z05v1Cf9r8RlKYEMaSqQ3xkAndiaqRUjnM9oQZapBxmaLCloQlCGnHBrcrVYNkFgckQsibMicIiaibXBhwteLZOvewK6Balw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">苹果原生的</span><span lang="EN-US"><span leaf=""> osacompile </span></span><span leaf="">工具可以将</span><span lang="EN-US"><span leaf=""> AppleScript </span></span><span leaf="">编译成</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">仅运行</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的</span><span lang="EN-US"><span leaf=""> macOS </span></span><span leaf="">应用程序。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.48554913294797686" data-type="png" data-w="865" data-imgfileid="100004669" src="https://wechat2rss.xlab.app/img-proxy/?k=1a52f59f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNj9h9miaXIFPH6sDqCO5CKRQLhXJOyf3xTuic335bbZHyA4MwWEfLz9AX5wfFcS9vqYuBSetHEq4opehickEyjhy0XQTH5uDjJ3SE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">利用</span><span lang="EN-US"><span leaf="">Smali</span></span><span leaf="">字节码的结构特征和控制流狩猎安卓恶意软件</span><span lang="EN-US"><span leaf="">C&amp;C</span></span><span leaf="">指令 </span></span></b><b><span lang="EN-US" style="font-size:
12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">识别的核心在于检测</span><span lang="EN-US"><span leaf="">C&amp;C</span></span><span leaf="">指令的处理模式，主要有四类处理结构：（</span><span lang="EN-US"><span leaf="">1</span></span><span leaf="">）密集的</span><span lang="EN-US"><span leaf=""> if-else </span></span><span leaf="">链或</span><span lang="EN-US"><span leaf=""> switch-case </span></span><span leaf="">块（如</span><span lang="EN-US"><span leaf=""> TgToxic, AhRat, Octo</span></span><span leaf="">）；（</span><span lang="EN-US"><span leaf="">2</span></span><span leaf="">）利用</span><span lang="EN-US"><span leaf=""> HashMap </span></span><span leaf="">将指令映射到函数（如</span><span lang="EN-US"><span leaf=""> XLoader</span></span><span leaf="">）；（</span><span lang="EN-US"><span leaf="">3</span></span><span leaf="">）将指令存储在大型数组中（如</span><span lang="EN-US"><span leaf=""> Copybara</span></span><span leaf="">）；（</span><span lang="EN-US"><span leaf="">4</span></span><span leaf="">）在单个类中嵌入多个常量字符串（如</span><span lang="EN-US"><span leaf=""> Nexus, Cerberus</span></span><span leaf="">）。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">第一类</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5919075144508671" data-type="png" data-w="865" data-imgfileid="100004670" src="https://wechat2rss.xlab.app/img-proxy/?k=0a7d60b1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgZzly7gzk3DEjWs8u2JZfvnPlPfSiaqdfMYgd6G6vGlsOBhwMRAkkIsgJ3ISV2SM9iaDepHnMmvj68twNVMyY4dsSbySNfXr1Ao%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">第二类</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.37803468208092483" data-type="png" data-w="865" data-imgfileid="100004671" src="https://wechat2rss.xlab.app/img-proxy/?k=10061783&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNj0eMParqPR7JpibjQPpyFywxibCno7yLjgZNGGXqic15nZXxGSTNPZoWM0WjA6ia3ub5pwZkPOShSJsiaYmgTsnezibDgBtsumNOicnc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">第三类</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5121387283236994" data-type="png" data-w="865" data-imgfileid="100004672" src="https://wechat2rss.xlab.app/img-proxy/?k=bbf8dc36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNias4EgpHhf9RicWjEuGL9Pct9D04hBch5sXQz4A8xMVicE2ZgK65ibXrwBxMLv6ickOMYvWurTLxck6DHCCgTsMhojR7C39axq5G68%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">第四类</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5815028901734104" data-type="png" data-w="865" data-imgfileid="100004673" src="https://wechat2rss.xlab.app/img-proxy/?k=6d536731&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjvD2XmUbciayEhKGCdOQ5sqD6yV7IeRPLblODTL8fayzvwdQeG50P61ka1WS5gFhCojsiatTno4icfCFhFhxXP1micjEjTibcKFX1g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">核心方法论：解析</span><span lang="EN-US"><span leaf=""> APK/DEX </span></span><span leaf="">的</span><span lang="EN-US"><span leaf=""> Smali </span></span><span leaf="">操作码</span><span lang="EN-US"><span leaf="">-&gt; </span></span><span leaf="">统计特定操作码和</span><span lang="EN-US"><span leaf=""> API </span></span><span leaf="">调用的数量</span><span lang="EN-US"><span leaf=""> -&gt; </span></span><span leaf="">根据阈值标记可能包含</span><span lang="EN-US"><span leaf=""> C&amp;C </span></span><span leaf="">指令的函数。工具必然存在误报，例如某个提取出的函数包含了</span><span lang="EN-US"><span leaf="">rotationX, translationY, alpha </span></span><span leaf="">等字符串。这其实是</span><span lang="EN-US"><span leaf=""> Android </span></span><span leaf="">原生</span><span lang="EN-US"><span leaf=""> UI </span></span><span leaf="">动画库处理属性切换的合法代码。但这在可接受范围内，因为初衷是为了大幅缩小分析师的检索范围。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3653179190751445" data-type="png" data-w="865" data-imgfileid="100004674" src="https://wechat2rss.xlab.app/img-proxy/?k=7f30e3cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaCy5x2fRMH2v2MHpQqfIPVzMLNe88H9C0Iapaj8jxib1eUTXK7uGrTOfqxFgnCrkNQBXjD0jIXCk95DvhwujFdEyd1hTZb7ljI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Hook</span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">伪随机数生成器恢复加密密钥 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">列举了</span><span lang="EN-US"><span leaf="">36</span></span><span leaf="">年来勒索软件的演进，从</span><span lang="EN-US"><span leaf=""> 1989 </span></span><span leaf="">年的</span><span lang="EN-US"><span leaf=""> AIDS Trojan</span></span><span leaf="">，到</span><span lang="EN-US"><span leaf=""> WannaCry</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Conti</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Babuk</span></span><span leaf="">，再到</span><span lang="EN-US"><span leaf=""> 2025 </span></span><span leaf="">年结合</span><span lang="EN-US"><span leaf=""> AI </span></span><span leaf="">的最新变种。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1722543352601156" data-type="png" data-w="865" data-imgfileid="100004675" src="https://wechat2rss.xlab.app/img-proxy/?k=dcc28306&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaqFVzo9jjH0umKXLWQjnC1picBtCXg7Uibmico0OWK7q9KyUblkDeYjxNWEKqKl8XOeQC8icoY55HlibrfpGn8CaAujlgxlGicvFtqY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">伪随机数生成器生成密钥后，一旦对称密钥在内存中被加密并丢弃，如果没有黑客的私钥，数据实际上是不可恢复的。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.4892086330935252" data-type="png" data-w="834" style="width:318px;height:474px;" data-imgfileid="100004676" src="https://wechat2rss.xlab.app/img-proxy/?k=3b4a8446&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhas7GNjjMicT5YWvTqCo9e6JselA12ykzF9hBic9sSyCqb3TvpibTdztj7LfU9eONyPfsMNFMIIbKTb2Vsp9PLpLDf3WK5B6M9Vc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">两种加密机制：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5040462427745664" data-type="png" data-w="865" data-imgfileid="100004677" src="https://wechat2rss.xlab.app/img-proxy/?k=e1f83c2b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjB6ibNP2ECmqKUqOme8ld8nKY3IxQM5p78hUD3rrCiakgQ6PO2oFNFC6R4vXdvolhklly2SEM9mQ4d5MlSed7Y6gFhF5CK3AQAk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4254335260115607" data-type="png" data-w="865" data-imgfileid="100004678" src="https://wechat2rss.xlab.app/img-proxy/?k=4482827f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNia3KUBftUhTdGZQKdRxszb7E4FJa3icAx0BflfibwI3ozjeLHR5K2mkIkpOic1VSAibwYhYTSnpqZ4uom2QlrE3GBLfv5Rkr0NBr9Y%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">这两种方式都各有拥趸：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4393063583815029" data-type="png" data-w="865" data-imgfileid="100004679" src="https://wechat2rss.xlab.app/img-proxy/?k=ea639518&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiatRG0eIUVgTdy8AMfDickFicsyVGqTJuqicVgZicGgkY3zcD85RSiawqUSviaHtVtz2yvDHeyPD1siahv7R7ITWsbYPxOw7ADtctFlFs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">使用开源的</span><span lang="EN-US"><span leaf="">minhook</span></span><span leaf="">库在用户态拦截了</span><span lang="EN-US"><span leaf=""> SystemFunction036 </span></span><span leaf="">的调用。一旦有程序调用它生成随机数，</span><span lang="EN-US"><span leaf="">Hook </span></span><span leaf="">程序就会静默地将生成的随机字节记录到一个指定的日志文件中。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3063583815028902" data-type="png" data-w="865" data-imgfileid="100004680" src="https://wechat2rss.xlab.app/img-proxy/?k=1b903a11&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhwAHFribCOZlzHLB1GZ8zcURGYpf0P5TC8jsd8D8vgrNGsnZ2LbGgXbKpKG68QlaiaJX5Mic3vGxXj9Urbex6ISO1cSSHcv8fDUE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">POC</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">确实可以实现解密：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8728323699421965" data-type="png" data-w="865" data-imgfileid="100004682" src="https://wechat2rss.xlab.app/img-proxy/?k=c1135c3b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhIBiaT3ywKw5ibn6yezgETI9IA26uhWMK9wEExgGUaBL94U4uIoTyNUOW7JI08zv9C4eb4f9iboGUmaibfteWetNtkMNWveh6ic1CQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">揭秘印度背景的</span><span lang="EN-US"><span leaf="">APT</span></span><span leaf="">组织蔓灵花 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">蔓灵花的核心画像：具有印度背景；目标为政府、国防和能源部门；常利用被入侵的政府账号或免费邮箱发信；滥用</span><span lang="EN-US"><span leaf=""> Let&#39;s Encrypt </span></span><span leaf="">证书；利用计划任务建立持久化；武器库包含</span><span lang="EN-US"><span leaf=""> C++ </span></span><span leaf="">和</span><span lang="EN-US"><span leaf=""> .NET </span></span><span leaf="">的远控木马（</span><span lang="EN-US"><span leaf="">RAT</span></span><span leaf="">）以及</span><span lang="EN-US"><span leaf="">CHM </span></span><span leaf="">帮助文件。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">蔓灵花的鱼叉邮件紧跟地缘政治热点，如伪装成中国国防部</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">外交部发给驻华武官的涉外规定信件、伪装韩国外交部发送韩国戒严令局势说明等。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5375722543352601" data-type="png" data-w="865" data-imgfileid="100004683" src="https://wechat2rss.xlab.app/img-proxy/?k=97993d51&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhz5pNjtGMyibH7qKAhia2EyVG7IcKYicLSdama43PnghqQSP4CfMlnLic853ic0ehsMtWHIVLx67lfzw4lyEveUAXwslIHsOG7NGJk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">将主机名和用户名明文或简单拼接放在</span><span lang="EN-US"><span leaf=""> URL </span></span><span leaf="">参数中，是此类南亚</span><span lang="EN-US"><span leaf=""> APT </span></span><span leaf="">的典型特征。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.48786127167630056" data-type="png" data-w="865" data-imgfileid="100004684" src="https://wechat2rss.xlab.app/img-proxy/?k=f6dbd3ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiahZybSNhljaz9nPg7QYZ6yhApJqaPmypPuWhWcFEaJhia8SWD1UBribAAOqYNyPao2qhibjUVmDIW0olicianBxq2ibUsFfnzAM20t0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通过</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">键盘级操作</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">活跃时间、</span><span lang="EN-US"><span leaf="">DNS</span></span><span leaf="">请求活跃时间、证书签发时间、域名注册时间分析，可以发现攻击活动高度集中在印度标准时间周一至周五的上午</span><span lang="EN-US"><span leaf="">9</span></span><span leaf="">点至下午</span><span lang="EN-US"><span leaf="">6</span></span><span leaf="">点左右。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.35028901734104045" data-type="png" data-w="865" data-imgfileid="100004685" src="https://wechat2rss.xlab.app/img-proxy/?k=9eac29cd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhYQCWbjBeCSloyaQlsr1FkoRqJP5SqSxHHX29o8eVc39SVcaBdEdEX6gzZl3dpksPhDz3I0UpOephB0yJAPc1PxMyx8w8KdWg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">其武器库中有较多恶意软件，说明他们有专职的研发团队在持续开发所需的各种类型恶意软件。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.47167630057803467" data-type="png" data-w="865" data-imgfileid="100004686" src="https://wechat2rss.xlab.app/img-proxy/?k=e008295d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgibbd1HNMsM95tIMFmozEVIMibAQswUTgz8ZF8iaa5NGKNGic9xO77UkdAL8rHkgHaRuZnZmWMjXZoD3TF0OLXIc7Ad1CMGowHkwM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">对比了不同时期的恶意软件的</span><span lang="EN-US"><span leaf="">C/C++</span></span><span leaf="">代码，都调用了</span><span lang="EN-US"><span leaf=""> GetComputerName</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">GetUserName</span></span><span leaf="">，并通过查询注册表</span><span lang="EN-US"><span leaf="">SOFTWARE\Microsoft\Windows NT\CurrentVersion </span></span><span leaf="">来获取</span><span lang="EN-US"><span leaf="">ProductName</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5560693641618497" data-type="png" data-w="865" data-imgfileid="100004687" src="https://wechat2rss.xlab.app/img-proxy/?k=552579a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgPRicOXSIO0ibkKia3Gn5L1GUzHyGJrufc3ibMnykL93FeHetYfgciahVgCK5FStQhJpkrHPVEeHMyv99JPcbN8mc7iagXGxwgXcibH8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">各种恶意软件间共用了字符加减混淆、字符异或混淆、</span><span lang="EN-US"><span leaf="">AES</span></span><span leaf="">加密等方式：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.35722543352601155" data-type="png" data-w="865" data-imgfileid="100004688" src="https://wechat2rss.xlab.app/img-proxy/?k=c30d6621&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgibWMyXGOAUQTzYNeU4fVsyusXjCxoW7KJEYm2QRw8tmLGgiaia1VMicLws0iac4XdCibXX6C84QjeaBd1Dib8RvNyuGCwlUWAHgibLQs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在多版本的</span><span lang="EN-US"><span leaf="">MuuyDownloader</span></span><span leaf="">间，攻击者只是微调了代码，例如只是修改了受害者系统信息的拼接分隔符。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.49248554913294795" data-type="png" data-w="865" data-imgfileid="100004689" src="https://wechat2rss.xlab.app/img-proxy/?k=7b189475&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjWAAgmCteh5Gb8DYb5012Lq0FbHOk4y2a1wdRYB5O1VxkBicmXxlP62nrmn8jupZjAopKS81A1jzQTc9nP3CicgeGZrRxdsDZ5Y%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">深入分析发现其使用的</span><span lang="EN-US"><span leaf="">BDarkRAT</span></span><span leaf="">实际上是抄袭自黑客论坛上有着十几年历史的开源</span><span lang="EN-US"><span leaf="">C#</span></span><span leaf="">远控木马</span><span lang="EN-US"><span leaf="">DarkAgent RAT</span></span><span leaf="">，这样可以在攻击时混淆溯源视线。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3468208092485549" data-type="png" data-w="865" data-imgfileid="100004690" src="https://wechat2rss.xlab.app/img-proxy/?k=79a518e6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhRT72oTfuUYWljzd4cDYj3ELfB6eCF2BtEO7kJd3h6xxuynianfpFVXPmCn2c7MTPcJBlHfWL3mph9dxqKEDmIyoTV7rYFVGfM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">为了隐藏意图，攻击者将原本明文的</span><span lang="EN-US"><span leaf="">C&amp;C </span></span><span leaf="">控制指令（如</span><span lang="EN-US"><span leaf=""> &#34;Delete File&#34;</span></span><span leaf="">）替换成了数字代号。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2184971098265896" data-type="png" data-w="865" data-imgfileid="100004691" src="https://wechat2rss.xlab.app/img-proxy/?k=c7dd8393&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNj4EI2kAzHPEaPdiaYXuiaILQicyqOmeoBZHgfDrfaW8JIEsBG75WPYQt3j0MBDG18zqwKMaXCKaN0GibAF8NNzwEiariaickK84AMrLM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Muuy</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">从</span><span lang="EN-US"><span leaf="">C&amp;C</span></span><span leaf="">服务器下载的</span><span lang="EN-US"><span leaf="">Payload</span></span><span leaf="">，是</span><span lang="EN-US"><span leaf="">PE</span></span><span leaf="">文件头破损的文件。下载时故意缺失了</span><span lang="EN-US"><span leaf=""> PE </span></span><span leaf="">文件头部的第一个字节</span><span lang="EN-US"><span leaf=""> M</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">0x4D</span></span><span leaf="">），而在写入受害者磁盘时</span><span lang="EN-US"><span leaf="">Muuy </span></span><span leaf="">会手动将这个</span><span lang="EN-US"><span leaf=""> M </span></span><span leaf="">补全。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6011560693641619" data-type="png" data-w="865" data-imgfileid="100004692" src="https://wechat2rss.xlab.app/img-proxy/?k=0882a08e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgicEZiaGjKtib4j7H8yAhyXJjuxvzrKZncZtOP4zQBw1SgSaBJhxQwlNhHXHqyq96u0LzfuNetQg670C81YEn74oot73umicEJPc0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">分析报告发布后，</span><span lang="EN-US"><span leaf="">APT </span></span><span leaf="">组织往往会立刻切断暴露的攻击基础设施并进入静默期，随后进行武器库的</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">升级改造</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-type="png" data-imgfileid="100004693" src="https://wechat2rss.xlab.app/img-proxy/?k=279565e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjaM7Xibymib5DzgKGibI1skzp77lDetCRibOGKl6SyabAPzm5rHKQjNgZj4UFqf0PmiaYbG3UnR3RGbkFicbp3JjvGlHhU30wqiaTiaIg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">WhisperGate</span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">的归因故事 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在物理军事冲突爆发前夕及初期，伴随着高频、高烈度的关键基础设施破坏。</span><span lang="EN-US"><span leaf="">WiperGate </span></span><span leaf="">的目的不是为了勒索经济利益，而是纯粹的系统瘫痪和制造社会恐慌。各大安全厂商各自为战的命名体系导致同一个组织出现十几个别名。随着时间推移、证据链完善（结合司法监听），真正的操作者才逐渐浮出水面。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4184971098265896" data-type="png" data-w="865" data-imgfileid="100004694" src="https://wechat2rss.xlab.app/img-proxy/?k=5e9d5c83&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNh2w8pvkbDSNvI3iavZ2QGNrM3TU3EGWicJH4KuSchm3BSia54Ka4zoBvxVSt7herBjQttiaLosScv8GcOuRongQjG5rkfjRfZ0IQE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">列举了归因攻击的多个维度：</span><span lang="EN-US"><span leaf="">1</span></span><span leaf="">失陷指标</span><span lang="EN-US"><span leaf=""> (IoC</span></span><span leaf="">，如哈希</span><span lang="EN-US"><span leaf="">/IP)</span></span><span leaf="">；</span><span lang="EN-US"><span leaf="">2</span></span><span leaf="">战术技术与程序</span><span lang="EN-US"><span leaf=""> (TTPs)</span></span><span leaf="">；</span><span lang="EN-US"><span leaf="">3</span></span><span leaf="">代码复用与演进；</span><span lang="EN-US"><span leaf="">4</span></span><span leaf="">变量名</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">语言特征；</span><span lang="EN-US"><span leaf="">5</span></span><span leaf="">攻击者的操作失误；</span><span lang="EN-US"><span leaf="">6</span></span><span leaf="">开源情报追踪；</span><span lang="EN-US"><span leaf="">7</span></span><span leaf="">攻击目标与动机；</span><span lang="EN-US"><span leaf="">8</span></span><span leaf="">地缘政治背景；</span><span lang="EN-US"><span leaf="">9</span></span><span leaf="">文化和时区指标。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.42427745664739885" data-type="png" data-w="865" data-imgfileid="100004695" src="https://wechat2rss.xlab.app/img-proxy/?k=e84a15dd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjHiciaoMpvdMSuLkiaaTnt5MNMFvQibiaEMrwZIVR2pa3AVuHu7HDcFrqMyiaLtZN1YJxUNFzBbwrg193BOmffCqe8UTMTaib4sQricXo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">使用传统机器学习进行归因，除了</span><span lang="EN-US"><span leaf="">GaussianNB</span></span><span leaf="">归因都是错误的。</span><span lang="EN-US"><span leaf="">Ember Bear </span></span><span leaf="">是个新成立的组织，历史样本极少，传统机器学习容易过拟合。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8173410404624277" data-type="png" data-w="865" data-imgfileid="100004696" src="https://wechat2rss.xlab.app/img-proxy/?k=ef84c8a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjYhNMOiaFKoqibDBZsGMAHkcnNOB1slLrWAnHA1ibI0icVAclNMw6hfna3Y0T3oIEicMPRU1Tgbr8pyL5jctLiagwibsE08hCDbiaSkoY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">使用</span><span lang="EN-US"><span leaf="">ChatGPT</span></span><span leaf="">进行零样本归因也是错误的，提供了单个提示后默认归因变成正确了。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5919075144508671" data-type="png" data-w="865" data-imgfileid="100004697" src="https://wechat2rss.xlab.app/img-proxy/?k=e95b8338&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNj8Su026O1cIzmdbjCerxvx4BMx6kk7mgYEOJdlBJ4Uxib6ZEuc9OSLnyxZIaQ8U1n8zuNAZPQZ55diadPf6kcWgHVL7x2IYSLeE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5884393063583815" data-type="png" data-w="865" data-imgfileid="100004698" src="https://wechat2rss.xlab.app/img-proxy/?k=2897325d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjzKglBqwDLo5mk4icjxFmqJnriasFTvs9Q1pLAkzparKa8WInIFtJxic452XqUCOV0zfTr5RuJYyEUIZbfwYh5gscR1uicRibS63xU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">XE Group </span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">长期利用</span><span lang="EN-US"><span leaf="">0day</span></span><span leaf="">漏洞但被低估</span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2020</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">年</span><span lang="EN-US"><span leaf="">7</span></span><span leaf="">月，</span><span lang="EN-US"><span leaf="">MalwareBytes </span></span><span leaf="">首次发布报告。指出该组织针对运行</span><span lang="EN-US"><span leaf=""> ASP.NET </span></span><span leaf="">的</span><span lang="EN-US"><span leaf=""> Microsoft IIS </span></span><span leaf="">服务器。利用</span><span lang="EN-US"><span leaf=""> Progress Telerik UI </span></span><span leaf="">中的已知漏洞</span><span lang="EN-US"><span leaf=""> (CVE-2017-9248) </span></span><span leaf="">上传</span><span lang="EN-US"><span leaf=""> Webshell</span></span><span leaf="">，进行远程代码执行。此时的</span><span lang="EN-US"><span leaf=""> XE Group</span></span><span leaf="">，只是一个利用陈旧</span><span lang="EN-US"><span leaf=""> N-day </span></span><span leaf="">漏洞</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">广撒网</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">捞钱的中低端黑产团伙。</span><span lang="EN-US"><span leaf="">2021</span></span><span leaf="">年</span><span lang="EN-US"><span leaf="">12</span></span><span leaf="">月，</span><span lang="EN-US"><span leaf="">Volexity </span></span><span leaf="">发布报告。指出该组织通过已知漏洞攻陷外网服务并建立反向</span><span lang="EN-US"><span leaf=""> Shell </span></span><span leaf="">。被攻陷的服务器被用于窃取密码或信用卡数据。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6183115338882283" data-type="png" data-w="841" data-imgfileid="100004699" src="https://wechat2rss.xlab.app/img-proxy/?k=f1ee3acb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhbuzbnkyMVibe5B01bxLhtwDMGYwqSTpdtIBdghtz7sLrsTcSwyUhONyS8YeL7kpFNib3Zycq4KwdY6RYKc3juCYvAWzc5Rhp5w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">分析报告认为该组织具有越南背景，在域名、脚本中大量使用</span><span lang="EN-US"><span leaf="">“XE”</span></span><span leaf="">标识。</span><span lang="EN-US"><span leaf="">2023</span></span><span leaf="">年</span><span lang="EN-US"><span leaf="">3</span></span><span leaf="">月，美国网络安全与基础设施安全局</span><span lang="EN-US"><span leaf=""> (CISA) </span></span><span leaf="">披露，</span><span lang="EN-US"><span leaf="">APT </span></span><span leaf="">组织和</span><span lang="EN-US"><span leaf="">XE Group </span></span><span leaf="">利用</span><span lang="EN-US"><span leaf=""> Telerik UI (CVE-2019-18935) </span></span><span leaf="">漏洞，攻陷美国政府的</span><span lang="EN-US"><span leaf=""> IIS </span></span><span leaf="">服务器以收集信息和执行代码。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6404624277456648" data-type="png" data-w="865" data-imgfileid="100004700" src="https://wechat2rss.xlab.app/img-proxy/?k=ba6d1b21&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaTwJFw4bvib9YqSZGvMhnv3bxLYhDCI7e23PsGpf7InXqfxvao3YFyOjicicsZgH4icWLwey9Bo0HQ8hB0Pgcx7HT4dIN7L8JHSpg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2023</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">年</span><span lang="EN-US"><span leaf="">5</span></span><span leaf="">月，</span><span lang="EN-US"><span leaf="">Menlo Security </span></span><span leaf="">报告了其利用</span><span lang="EN-US"><span leaf=""> Magento </span></span><span leaf="">和</span><span lang="EN-US"><span leaf=""> Adobe ColdFusion </span></span><span leaf="">进行供应链注入。最关键的是，安全人员在</span><span lang="EN-US"><span leaf="">Instagram </span></span><span leaf="">上找到了疑似幕后黑手“</span><span lang="EN-US"><span leaf="">xethanh</span></span><span leaf="">”的社交账号。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.40346820809248557" data-type="png" data-w="865" data-imgfileid="100004701" src="https://wechat2rss.xlab.app/img-proxy/?k=791a59b1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiar7Eurz9yjHDvakPX9qxFSoqIgwEia0reMroOOWCkFWly9Y9aGnjLo6mKyHSGSwfZsibsrD1deuG9xbFpLzMPa1OqhDpUThibgYE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">循着线索可以找到更多信息，包括邮箱、用户名与</span><span lang="EN-US"><span leaf="">IP</span></span><span leaf="">地址等：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="2.066350710900474" data-type="png" data-w="633" style="width:371px;height:767px;" data-imgfileid="100004702" src="https://wechat2rss.xlab.app/img-proxy/?k=14b93319&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaia4OPX70CfzADIiaWzAiaeEkOdyosAlZBcmqQx4KVAiaAj8YAeGDJFG3O0aSwfaXIXSdKdrj8W5pEOiaX3fwoiaFg6NNWJl6OYBfIU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">截至到这，该团伙的技术内核依然停留在典型的黑产流水线作业水平。可在</span><span lang="EN-US"><span leaf="">2024</span></span><span leaf="">年</span><span lang="EN-US"><span leaf="">11</span></span><span leaf="">月</span><span lang="EN-US"><span leaf="">6</span></span><span leaf="">日，一次安全告警引起了分析人员的注意。</span><span lang="EN-US"><span leaf="">IIS</span></span><span leaf="">的进程竟然派生出了</span><span lang="EN-US"><span leaf="">cmd.exe</span></span><span leaf="">与</span><span lang="EN-US"><span leaf="">powershell.exe</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2138728323699422" data-type="png" data-w="865" data-imgfileid="100004703" src="https://wechat2rss.xlab.app/img-proxy/?k=b4c11ca3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjnUzIg1j6PZic7nQZYIguXYkZbygemwCiaBw7dnRdL3u2JS9XHTuQzsrndC4aZBXLy2PTvuQo5gPXbkO5nteib7BQsA7cLGCEdicc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">定制的</span><span lang="EN-US"><span leaf="">WebShell</span></span><span leaf="">校验</span><span lang="EN-US"><span leaf="">UserAgent</span></span><span leaf="">中是否包含</span><span lang="EN-US"><span leaf=""> Base64 </span></span><span leaf="">编码的“</span><span lang="EN-US"><span leaf="">TMToday</span></span><span leaf="">”或“</span><span lang="EN-US"><span leaf="">XeThanh | XeGroups</span></span><span leaf="">”。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4635838150289017" data-type="png" data-w="865" data-imgfileid="100004704" src="https://wechat2rss.xlab.app/img-proxy/?k=2018345f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhicM3wbm1BY3awtf6sIic9oNTusfichgCwprj8J4AiaG8FcFPOMUlE6OB6HWmp0JqTaBcerbGCplQyxx17zyYhuwFn3baicZvWl06g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">回溯日志时发现，早在五年前攻击者就利用了当时未知的</span><span lang="EN-US"><span leaf=""> SQL </span></span><span leaf="">注入漏洞</span><span lang="EN-US"><span leaf=""> (CVE-2025-25181) </span></span><span leaf="">和文件上传漏洞</span><span lang="EN-US"><span leaf=""> (CVE-2024-57968)</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3063583815028902" data-type="png" data-w="865" data-imgfileid="100004705" src="https://wechat2rss.xlab.app/img-proxy/?k=52faa80c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgK0QEcq5HichOCGoNLZxIsibo0HPicOeOM5Q57u5em7L9xpDfpxzW1E3UFbBCR3MGkACs5RyL4eYXXasW2nZOOvm73mNaJdHcSF0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">WebShell</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">流量中，攻击者在</span><span lang="EN-US"><span leaf=""> User-Agent </span></span><span leaf="">中肆无忌惮地拼接了</span><span lang="EN-US"><span leaf=""> XeThanh</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">XeGroups</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">TMToday </span></span><span leaf="">等专属标签。这很令人费解，一个有着</span><span lang="EN-US"><span leaf="">0day</span></span><span leaf="">漏洞的攻击组织在网络层如此张扬地留下痕迹。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3063583815028902" data-type="png" data-w="865" data-imgfileid="100004706" src="https://wechat2rss.xlab.app/img-proxy/?k=a2663324&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhn8p9ogsm7Z6WEVicGcTahGzsVMbb1IYo7kwnTjJsC9Rh9zCT0iaTpFaTOadGSC803ibJTTGrwCJTn5ugFuiaibYtuUibic88QYWSjWo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">攻击者从信用卡盗刷转为了针对性的机密信息窃取；放弃了</span><span lang="EN-US"><span leaf=""> N-day</span></span><span leaf="">，转而使用隐秘的</span><span lang="EN-US"><span leaf=""> 0-day </span></span><span leaf="">漏洞并在网络中潜伏数年。永远不要低估对手，你看到的可能仅仅是敌人想让你看到的冰山一角。</span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">深入探讨</span><span lang="EN-US"><span leaf="">Linux Rootkit</span></span><span leaf="">与检测策略 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p style="text-align: justify;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">Linux Rootkit</span></span><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">一直在进化，从最初的用户态升级到内核态，近些年也在利用</span><span lang="EN-US"><span leaf="">eBPF</span></span><span leaf="">和</span><span lang="EN-US"><span leaf="">io_uring</span></span><span leaf="">兴风作浪。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4184971098265896" data-type="png" data-w="865" data-imgfileid="100004707" src="https://wechat2rss.xlab.app/img-proxy/?k=0770f3db&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaK4ib1yAUs0ZMIMFWxjALibS3ibib3gwsfibHG8InibhicFOyibS5bLLFKtO3icRKRCcsv6oO0paT8RicVibkU5LzHFwMIpVUn0uDkxN0MG4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Ftrace</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">和</span><span lang="EN-US"><span leaf="">Kprobes</span></span><span leaf="">已经成为了</span><span lang="EN-US"><span leaf="">Linux Rootkit</span></span><span leaf="">的标配，利用内核自带的、合法的调试功能，隐蔽性相当强。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3583815028901734" data-type="png" data-w="865" data-imgfileid="100004708" src="https://wechat2rss.xlab.app/img-proxy/?k=3edbd25b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjWWt76eDEYH35LkVhiaLKlHVXaialk38MgvcmwtWeDafDIJrKwjia55oStXVXIk9mvjKBpACSnIA7eLthcphPY6OVQmSib0I3Hxhs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">内核态高频系统调用：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.48554913294797686" data-type="png" data-w="865" data-imgfileid="100004709" src="https://wechat2rss.xlab.app/img-proxy/?k=1ac409f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaiaMT2OrkVdzUFPCnX9rmNSmQUkCR0MPHVmM5Irx6LoLfLZVRoJdjduh2oBaXJzWfWwEQkhZIfABMZialeGaicictG2ocLky8YxoA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">内核态高频函数调用：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.507514450867052" data-type="png" data-w="865" data-imgfileid="100004710" src="https://wechat2rss.xlab.app/img-proxy/?k=7852016d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjJcgZtIR7be5S17CprA1ic3JMH6bPHBZCocTPRvu3eibGhBYuwQeTAPC2BZicFDBmWvlpVUKhoM4lFfOtFgLFPEy6XQKKl6mVwAU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">用户态高频函数调用：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.507514450867052" data-type="png" data-w="865" data-imgfileid="100004712" src="https://wechat2rss.xlab.app/img-proxy/?k=8c5470a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhibbrY1eLoCWhcTMpG40ko1wQ7AlZ2565xfpDiaT5nf6GuW6Lhf0ZiaYnaRsQUZZItdzqz7JQ7KdRsY4xOD9EPqaIibXkF4VHEExE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">常见</span><span lang="EN-US"><span leaf="">Rootkit</span></span><span leaf="">看起来检出率很高，但经过简单的符号剥离以及空字节填充后，检出率通常断崖式下跌。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.47398843930635837" data-type="png" data-w="865" data-imgfileid="100004713" src="https://wechat2rss.xlab.app/img-proxy/?k=f3a0f835&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNged3J2PqG8mJkTOUtachAt4cFLNhxwiciarCHXlQibtTh4kZ2wkzr15FtDbEaNbjYic1aGtxNeADrxf1HtFn7Iu8ibJl6u8kOIyuxg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Linux</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在</span><span lang="EN-US"><span leaf="">6.9</span></span><span leaf="">版本升级时修改了</span><span lang="EN-US"><span leaf="">sys_call_table</span></span><span leaf="">，无意间摧毁了</span><span lang="EN-US"><span leaf="">Rootkit</span></span><span leaf="">最经典的攻击面。研究人员设计了</span><span lang="EN-US"><span leaf="">FlipSwitch</span></span><span leaf="">，仍然可以维持</span><span lang="EN-US"><span leaf="">syscall</span></span><span leaf="">表</span><span lang="EN-US"><span leaf="">Hooking</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.44277456647398844" data-type="png" data-w="865" data-imgfileid="100004714" src="https://wechat2rss.xlab.app/img-proxy/?k=493a13e9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhian2RgvH9yEEN9Jkm9fK85JjOsIf23fVSnjW5ChIuE1U02GHBgwpnaTdt0ukctMZ3sB6icHOmfgBydD8OCh2vTHnpyVZmMkfh8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">后面</span><span lang="EN-US"><span leaf="">Elastic</span></span><span leaf="">的研究员介绍了基于行为检测与持久化检测的一些细节，此处不赘述，感兴趣的请看原文。只将缩小攻击面的建议放下：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.376878612716763" data-type="png" data-w="865" data-imgfileid="100004715" src="https://wechat2rss.xlab.app/img-proxy/?k=2cf6e0f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgVbxTyh4vob6ow0aYDViciaOHcGjMwWryEYdfaxOUUlJQXmKD9aW7hrywLrWY3yYR3vvnWkhbUmTrxTtT4CbchbNXJEWhZohQOk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">用户态检测引擎规避技术的猫鼠游戏 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">当前的端点安全检测技术过度依赖用户态</span><span lang="EN-US"><span leaf="">Hook</span></span><span leaf="">，在</span><span lang="EN-US"><span leaf="">ring3</span></span><span leaf="">这一层恶意软件与安全软件拥有相同的权限，这仍然是阿喀琉斯之踵。通常来说，</span><span lang="EN-US"><span leaf="">EDR</span></span><span leaf="">通过注入</span><span lang="EN-US"><span leaf="">DLL</span></span><span leaf="">到目标进程实现监控，利用内联</span><span lang="EN-US"><span leaf="">Hook</span></span><span leaf="">拦截</span><span lang="EN-US"><span leaf="">API</span></span><span leaf="">调用，也依赖</span><span lang="EN-US"><span leaf="">ETW/AMSI</span></span><span leaf="">。这也是用户态规避的基础，攻击者可以读写注入</span><span lang="EN-US"><span leaf="">DLL</span></span><span leaf="">的内存区，也就可以对寄宿在进程中的“寄生虫”摘除。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8023121387283237" data-type="png" data-w="865" data-imgfileid="100004716" src="https://wechat2rss.xlab.app/img-proxy/?k=4bacd027&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNg9ib4xWpulq6dEIwNaXSibEXIPwH4cewKZb4QAEjDOIfNfTjTCNPt8Df9MH8RUDU0F29PEqXBv4mp3Hibhn55KGJR3gW8g9VVWhI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Hook</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">规避可以分为四类：（</span><span lang="EN-US"><span leaf="">1</span></span><span leaf="">）二级</span><span lang="EN-US"><span leaf="">DLL</span></span><span leaf="">映射</span><span lang="EN-US"><span leaf="">/Secondary DLL mapping</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">2</span></span><span leaf="">）二进制重载</span><span lang="EN-US"><span leaf="">/Binary restoration</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">3</span></span><span leaf="">）直接系统调用</span><span lang="EN-US"><span leaf="">/Direct system call invocation</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">4</span></span><span leaf="">）代码拼接</span><span lang="EN-US"><span leaf="">/Code splicing</span></span><span leaf="">。（这里不赘述细节，感兴趣的读者可以看原文）</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">二级</span><span lang="EN-US"><span leaf="">DLL</span></span><span leaf="">映射的检测特征：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.24624277456647398" data-type="png" data-w="865" data-imgfileid="100004717" src="https://wechat2rss.xlab.app/img-proxy/?k=c4bbca5e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjiaiadvnsLpYlhV6rpicezkheMw6NhoXO4hWcykzPJqBUJkQ7jGtkXfGNd2CO4XNg8TdK6o21VYSYdIt69NibUksSZybqRHibluqE4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">二进制重载的检测特征：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-type="png" data-w="865" data-imgfileid="100004718" src="https://wechat2rss.xlab.app/img-proxy/?k=875a920b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNh3ibPZMSw9ANiajlff8xckFAvB0BgslSme92bKg1DCVu803lmTBlJ6FZ24qvYwEBGaIBktFm0urZjAoY7xwGpzFAh4mRCOtNbbc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">直接系统调用的检测特征：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.42196531791907516" data-type="png" data-w="865" data-imgfileid="100004719" src="https://wechat2rss.xlab.app/img-proxy/?k=8d4c941c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgyZwfd3EhV8bBUMgHJfnbYyOA0pYeBrjIYg5XPuMw4cTb44E9oDcmrCWoG5Xnf1wibkRXN5jhLYV3PT00tZR4XEHC3CQqjh7K0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">代码拼接的检测特征：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1722543352601156" data-type="png" data-w="865" data-imgfileid="100004720" src="https://wechat2rss.xlab.app/img-proxy/?k=811c0363&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgjCOYOlC6758l1CehnRSa1rGdBZXMNejrRZJvx4Vh9Z7NibCsdxGn8bbySqdQUQ3D4X5Zoe3Qr0odd9KibEZBiaLicpucZRK6sIv0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">“参数伪造”的核心在于（</span><span lang="EN-US"><span leaf="">Time-Of-Check to Time-Of-Use/TOCTOU</span></span><span leaf="">），即让</span><span lang="EN-US"><span leaf=""> EDR </span></span><span leaf="">检查参数时看到的是“良性”的，但实际执行时变成“恶性”的。通常利用硬件断点或异常处理进行实现。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">“引擎对抗”的方式有（</span><span lang="EN-US"><span leaf="">1</span></span><span leaf="">）利用</span><span lang="EN-US"><span leaf="">FreeLibrary</span></span><span leaf="">或者触发引擎的</span><span lang="EN-US"><span leaf="">unload</span></span><span leaf="">函数（</span><span lang="EN-US"><span leaf="">2</span></span><span leaf="">）</span><span lang="EN-US"><span leaf="">unmap</span></span><span leaf="">所有</span><span lang="EN-US"><span leaf="">DLL</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">3</span></span><span leaf="">）利用进程缓解策略仅允许微软签名的文件</span><span lang="EN-US"><span leaf="">load</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">4</span></span><span leaf="">）在新的子进程中预加载。</span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">韩国应急响应中心威胁分析 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">KISA</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">（韩国互联网振兴院）在国家网络安全架构中出于核心枢纽地位，向上对接总统府（国家安全办公室）、国家情报院（</span><span lang="EN-US"><span leaf="">NCSC</span></span><span leaf="">）、检察院和警察厅等公权力机构；向下联动私营部门，包括三大</span><span lang="EN-US"><span leaf=""> ISP</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">KT, SKB, LGU+</span></span><span leaf="">）、安全厂商（</span><span lang="EN-US"><span leaf="">AhnLab</span></span><span leaf="">等）和全球科技巨头（</span><span lang="EN-US"><span leaf="">Google, MS, </span></span><span leaf="">趋势科技等）；同时开展国际合作（</span><span lang="EN-US"><span leaf="">FIRST, APCERT</span></span><span leaf="">等）。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4797687861271676" data-type="png" data-w="865" data-imgfileid="100004721" src="https://wechat2rss.xlab.app/img-proxy/?k=3333307c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjyRN8Rn6C5fTEHqzic4JTXASNHMSNqTVpxdcIJVwWibo3N18nXqlJPEBbTUOZOaT3iauJl0HicAiavytWX4CRYXroNKJB8KT9C1g4k%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">数据源来自蜜网、恶意网站</span><span lang="EN-US"><span leaf="">/DNS</span></span><span leaf="">检测等，汇入</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">数据湖</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">后，结合外部情报（</span><span lang="EN-US"><span leaf="">Shodan, Criminal IP </span></span><span leaf="">等）进行关系分析。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.43352601156069365" data-type="png" data-w="865" data-imgfileid="100004722" src="https://wechat2rss.xlab.app/img-proxy/?k=c14ee79a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaA01I4ZDgibC1fLMUme5ymsvaeXSZQzuY8wntUQDT9RSc0ExzOaSlAuKRJL0jjrVZgvCCtzm4X9WGm4oXgygvcXNeyUPicxic02g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2024</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">年 </span><span lang="EN-US"><span leaf="">Cyber-Spider</span></span><span leaf="">收集了超</span><span lang="EN-US"><span leaf=""> 1035 </span></span><span leaf="">万条短信，去重后分析了</span><span lang="EN-US"><span leaf=""> 2,136 </span></span><span leaf="">条恶意短信。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1838150289017341" data-type="png" data-w="865" data-imgfileid="100004723" src="https://wechat2rss.xlab.app/img-proxy/?k=ef7f5d87&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaMy86wLanPyn8GNY6ib5enl3iaNz9Nd3WwjmJoU2m4KUTwhBFUxkCJicQZT23dhBYgQkWdrtG888G4e0cMIdLlyg6b1cdsGQNfLw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">形成网络关系图谱，包括政府机构、快递、讣告与金融等。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9641618497109826" data-type="png" data-w="865" data-imgfileid="100004724" src="https://wechat2rss.xlab.app/img-proxy/?k=0c5cbb3d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjHzaqMnoGibbRyKQ2IAX1xIdzRJXMr1F4XMWsM9tFtDwIngVz7MmXNpKuzNkdOnDCkVm9PJyqLiaJRDllkkwWDpmTH8W5wbNbGc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">韩国本地特征十足，讣告占比达到一半。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.446242774566474" data-type="png" data-w="865" data-imgfileid="100004725" src="https://wechat2rss.xlab.app/img-proxy/?k=6e517c87&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaZLiaqb11NErcQdStLrypc1lr3wiciaRNOlIfibmwQUk9j8OeIGYQib7XSib0JO6riassHeJYpjibWiawY4mHgzlZomCNg7ibJbmudIDFqo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">没有用什么正经顶级域名：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3919075144508671" data-type="png" data-w="865" data-imgfileid="100004726" src="https://wechat2rss.xlab.app/img-proxy/?k=22043ea5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjxP6fQpIg9q7MhslUicVK0m3kzleG70Afq4hGdJJib8nvHx8FfbX5TjluibaQUiclLjRquk6GDRcdaNJ2IPVQI3ib01n4iahnXLavLY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">伪造政府域名的</span><span lang="EN-US"><span leaf="">URL</span></span><span leaf="">存在固定模式。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.37109826589595374" data-type="png" data-w="865" data-imgfileid="100004727" src="https://wechat2rss.xlab.app/img-proxy/?k=38e67205&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjYibv3X6LuK0CxIUKCBej3KflghlaiaydIUO38HZgQqbBUPRdmUqOupEW4YY7czhtGY0TgoWB1bWPialyu7KiaETukp57TOk6MKOg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">将规律固化到系统中，自动阻断恶意域名。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3329479768786127" data-type="png" data-w="865" data-imgfileid="100004728" src="https://wechat2rss.xlab.app/img-proxy/?k=65ed557f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiagadqbicbhqjFhOdpC10uWBAKsePvZAwZ2E4abgLqLM9eb8msyQL5mOTfqoDxyXPECnBKPFHO8aeGHZrnRzthrnzKaW50CoZDo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">如何顺藤摸瓜找到黑客？ </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在受害者与勒索软件谈判时，一台名为</span><span lang="EN-US"><span leaf=""> DESKTOP-J8AOTJS </span></span><span leaf="">的机器意外连入了受害者的网络监控系统。目录显示，这台机器的</span><span lang="EN-US"><span leaf=""> Z:\distr\ </span></span><span leaf="">文件夹下塞满了黑客工具：</span><span lang="EN-US"><span leaf="">KMSAuto</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">AnyDesk</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">ProcessHacker</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">mimik.zip </span></span><span leaf="">以及代码相关的压缩包。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5838150289017341" data-type="png" data-w="865" data-imgfileid="100004729" src="https://wechat2rss.xlab.app/img-proxy/?k=f6791eda&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgicC2aBhCwIfxR2L2BdicE1f52Dru5alqb6UCQ34GXAUXFoCdg5QDjComaks5Oh3nlMNsiaibWg3s4iaJeYR5icC3yak0kyoP9C41c8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">这些文件夹的名称可能就是用户名：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.1445086705202312" data-type="png" data-w="865" data-imgfileid="100004730" src="https://wechat2rss.xlab.app/img-proxy/?k=0b80b17d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNg13SUhnGAH07DOtBBVsEZNHcZrMXicw9OZqJBqicibFkWT4BB7hbagQ1aJMib6HrjODd4rkSXYYicK0DvJn6SPj4Il4YPaEgibWfxLE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在俄语恶意软件论坛上，研究员成功找到了名为</span><span lang="EN-US"><span leaf=""> Marti71 </span></span><span leaf="">的用户，该用户在</span><span lang="EN-US"><span leaf=""> 2023 </span></span><span leaf="">年</span><span lang="EN-US"><span leaf=""> 12 </span></span><span leaf="">月发帖求购</span><span lang="EN-US"><span leaf="">AV Killer</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4092485549132948" data-type="png" data-w="865" data-imgfileid="100004731" src="https://wechat2rss.xlab.app/img-proxy/?k=8470ccc7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNj3WUCH09pNKPCDibUHWtVXCWykOzQckM6doxVLjEfpEKicZdiaic9W30WAVZJxowQW3nqWiaKWeXFGckZH8bTuvqwjq7ENIEtZgFSw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">论坛帖子显示，一个名为</span><span lang="EN-US"><span leaf=""> KernelMode </span></span><span leaf="">的用户推销了自己的工具。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.26705202312138726" data-type="png" data-w="865" data-imgfileid="100004732" src="https://wechat2rss.xlab.app/img-proxy/?k=7e11afd4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNh26urIYfcgNicqG7XMQDhialdECgabib12AsdBHxIYoQib0WKOqJoqibRqfDngmfkyfkaBXx0LrYFLRCvNZPIWClYVSxsUC0qqQFL8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">自称其工具的最大优势是：</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">杀毒软件进程不会被结束，表面上保护还在运行，但实际上对文件和内存的扫描已经停止</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">。该工具号称通杀</span><span lang="EN-US"><span leaf=""> Windows 7 </span></span><span leaf="">到</span><span lang="EN-US"><span leaf=""> Win 11</span></span><span leaf="">，支持绕过</span><span lang="EN-US"><span leaf=""> CrowdStrike, Palo Alto, Kaspersky, Defender </span></span><span leaf="">等十几家顶级</span><span lang="EN-US"><span leaf=""> EDR</span></span><span leaf="">。收费标准：每个</span><span lang="EN-US"><span leaf=""> AV/EDR </span></span><span leaf="">绕过包月</span><span lang="EN-US"><span leaf=""> 1500 </span></span><span leaf="">美元，起步价</span><span lang="EN-US"><span leaf=""> 7500 </span></span><span leaf="">美元。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.41965317919075146" data-type="png" data-w="865" data-imgfileid="100004733" src="https://wechat2rss.xlab.app/img-proxy/?k=85321d94&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiarPmzTLHwQias11f7WyneX2rehRZviaUcChJXKqvXlQpW9buurgqZNmibKdo1YPKyQt9CCSFsqcCTr9icJlcMVcMhDa8Y9tGvJiaB8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在这台电脑里，研究员发现了大量极具价值的资料：</span><span lang="EN-US"><span leaf="">Conti </span></span><span leaf="">勒索软件的实战培训手册（</span><span lang="EN-US"><span leaf="">Playbook</span></span><span leaf="">）、工具套件、一段漏洞演示视频和一张</span><span lang="EN-US"><span leaf=""> P-1 </span></span><span leaf="">费用报销单。在这份报销单上，清晰地印着一家位于哈萨克斯坦的有限责任公司的真实名称。报销的内容居然是</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">租赁了</span><span lang="EN-US"><span leaf=""> 30 </span></span><span leaf="">辆奔驰汽车</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的费用明细。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9086705202312139" data-type="png" data-w="865" data-imgfileid="100004734" src="https://wechat2rss.xlab.app/img-proxy/?k=ca9af88e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjurQG0uNRSXfERtbwwPWy8PXNibdmXUiaeliao9C1n9HgEFjQlVUMnQLpae06NpKvxUoMmN4AOQ7ibUX3I8cTuibv2eEqYQLsKEn8Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">演示视频中录制到了测试系统的机器名，并且录下了操作者正在绕过认证并试图安装</span><span lang="EN-US"><span leaf=""> EDR </span></span><span leaf="">代理的整个过程。在操作者电脑底部的</span><span lang="EN-US"><span leaf=""> Windows </span></span><span leaf="">任务栏上，除了正在运行的</span><span lang="EN-US"><span leaf=""> WinBox </span></span><span leaf="">和</span><span lang="EN-US"><span leaf=""> OBS Studio </span></span><span leaf="">录屏软件外，有一个窗口的标题栏暴露了该疑似威胁行为者的加长版用户名。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6369942196531792" data-type="png" data-w="865" data-imgfileid="100004735" src="https://wechat2rss.xlab.app/img-proxy/?k=efaf7daf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiax4MEx3g01cHCf8fmwlILyyP35YWmrL50a3lhicr8YOT90bvoiaznZ8Bd6TfFoDn0xvC9icxiboAVp1vckZEeGhAkXVOeRibZRvicek%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在</span><span lang="EN-US"><span leaf=""> LinkedIn </span></span><span leaf="">上成功找到了一个名为</span><span lang="EN-US"><span leaf=""> Andry </span></span><span leaf="">的人，其履历显示他正就职于那家</span><span lang="EN-US"><span leaf=""> P-1 </span></span><span leaf="">报销单上的公司。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.643765903307888" data-type="png" data-w="786" style="width:342px;height:562px;" data-imgfileid="100004736" src="https://wechat2rss.xlab.app/img-proxy/?k=2606816b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgGt9TMiah2HPcR1oJuORxIjIguhibJY3yt7rw1KUfEM2turBpHJ8ndDaMOqzYvZ4cP7rAnJn1EC3lbkAtMVl4Uf0uNgrxOKSfQ0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">APT 37</span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">开始使用</span><span lang="EN-US"><span leaf="">Rust</span></span><span leaf="">编写后门</span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">研究机构在持续跟踪</span><span lang="EN-US"><span leaf="">ScarCruft</span></span><span leaf="">，</span><span lang="EN-US"><span leaf="">APT37 </span></span><span leaf="">是朝鲜最活跃、最具技术侵略性的国家级黑客组织之一。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.42427745664739885" data-type="png" data-w="865" data-imgfileid="100004737" src="https://wechat2rss.xlab.app/img-proxy/?k=80032e38&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgAvhKicT0u5wB5gqd4Ck7ibD4gyZ4uv8uPk3UvbjHJvibPVra0GymMQ5JuR2kvZH1AAuicYKFiavgD3lekTQAnicgYA9j5A2c0Z2lG8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">研究人员将其进一步细分成三个子组：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.45433526011560693" data-type="png" data-w="865" data-imgfileid="100004738" src="https://wechat2rss.xlab.app/img-proxy/?k=98926a62&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgML4NvlyibvLejWTmYIyKzb2TONYh2OXLMy9ibgeF90WTH7ibhQzsLovyTTA1Z4Z9ZffnfeqlWv8bbPumjI5nZtiaEFAxiav2YHGrY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2025</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">年密集出现的新武器，预示着该组织经历了一次重大的技术栈重构。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5017341040462427" data-type="png" data-w="865" data-imgfileid="100004739" src="https://wechat2rss.xlab.app/img-proxy/?k=2df16318&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgiaIyC28hFe0S8AquIhQ5nGl3VMbQDmL8NxypicVibZCrVT0TFqtCFkqKvvblG4icB5t8OHPYcseo3SYLG4kvKdklXceKNgdicfF7A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">从高级隐蔽边缘设备攻击到缓解 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">动态</span><span lang="EN-US"><span leaf="">Port Knocking</span></span><span leaf="">，要求数据包的前</span><span lang="EN-US"><span leaf="">16</span></span><span leaf="">字节和后</span><span lang="EN-US"><span leaf="">16</span></span><span leaf="">字节进行异或运算后，等于一个预设的常量。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5144508670520231" data-type="png" data-w="865" data-imgfileid="100004740" src="https://wechat2rss.xlab.app/img-proxy/?k=31bf91a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNj6oYf7JEic1vNZxqRQUibnVCIfowic38ukHqqDBWF2sfzAxCrfTicGV8V0XlH1ea2S4GtPoYXNQxKAxn3hWoic1eR7wheKbBTibnpGA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">敲门包不仅用于唤醒，其包含的</span><span lang="EN-US"><span leaf=""> MAGIC_PATTERN </span></span><span leaf="">实际上也是用于解密后续</span><span lang="EN-US"><span leaf=""> C2 </span></span><span leaf="">配置的</span><span lang="EN-US"><span leaf=""> RC4 </span></span><span leaf="">密钥。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3815028901734104" data-type="png" data-w="865" data-imgfileid="100004741" src="https://wechat2rss.xlab.app/img-proxy/?k=735f9ac1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhwuqiavVAW7byHPA2Ack25SnrTDRrA2IiaoT4h98xFwjbTRs8DVhCVnrPvhdahzu7mCuIicCzsmZenHbSweABbBibDhAFuDlyicaoA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">原版</span><span lang="EN-US"><span leaf=""> TSH </span></span><span leaf="">设计方案可以通过数据包嗅探器拦截种子，并结合从样本中提取的密码，直接派生出</span><span lang="EN-US"><span leaf="">AES </span></span><span leaf="">密钥来解密所有的后门流量。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4913294797687861" data-type="png" data-w="865" data-imgfileid="100004742" src="https://wechat2rss.xlab.app/img-proxy/?k=960cb107&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgMO61m2fibjOUA6fRwvPS42BvtmNSibfElYEN4hkKeLX7yxuziaBEuy9V7lO026YdtocDFjomicvsNRTkApy3OCOnhOKumUztickZU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">黑客实现了</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">完全前向保密（</span><span lang="EN-US"><span leaf="">PFS</span></span><span leaf="">）</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">，在代码中硬编码了服务器的</span><span lang="EN-US"><span leaf=""> secp521r1</span></span><span leaf="">（椭圆曲线）公钥。即使拿到了木马样本（含有服务器公钥），只要没有服务器端的私钥，就无法解密截获的网络流量。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5526011560693641" data-type="png" data-w="865" data-imgfileid="100004743" src="https://wechat2rss.xlab.app/img-proxy/?k=3cfe6e97&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaeRUMTiaricZo0TL0gROficdxXxg4Cqrmk0m26Re6kNSWlw81b5RWYytad5c8lpDDPZ39OV83Hpec4ptjUsJWRhtvmoC1oTQWf0I%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">AI</span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">时代的恶意</span><span lang="EN-US"><span leaf="">Chrome</span></span><span leaf="">插件</span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">扩展核心组件架构：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7942196531791907" data-type="png" data-w="865" data-imgfileid="100004744" src="https://wechat2rss.xlab.app/img-proxy/?k=09a2a4ed&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgp5Rfj1saeqibVqibFvHFMaEDjbZhdRujLNXY44ibvFMmePcibMNiahl39pAIxqP3TwPb0OUJ9vhMJjQuk08icO9LgMeohibfTLupJmE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">收到</span><span lang="EN-US"><span leaf="">VP</span></span><span leaf="">发送的即将收购某公司的邮件，并且强调要绝对保密。利用浏览器插件生成回复，就已经将信息泄露出去了。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4797687861271676" data-type="png" data-w="865" data-imgfileid="100004745" src="https://wechat2rss.xlab.app/img-proxy/?k=ac5f8bfd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiajH09iaN0IvekvjfSSTwEUG8j48C5YsCiaCPvia7HErBvNfLonrj62ouSc1kddyeO1AoyWpgAUCjQO7T4rgdI1x4N2TIicEKq8ks0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Frank</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在</span><span lang="EN-US"><span leaf=""> Gmail </span></span><span leaf="">中点开了一封包含</span><span lang="EN-US"><span leaf=""> LinkedIn </span></span><span leaf="">账户重置验证码的邮件。但</span><span lang="EN-US"><span leaf="">Frank </span></span><span leaf="">完全没有点击任何按钮，也会被入侵。恶意的</span><span lang="EN-US"><span leaf=""> Content Script </span></span><span leaf="">是基于页面加载事件触发的，攻击者已经控制了</span><span lang="EN-US"><span leaf=""> Frank </span></span><span leaf="">的</span><span lang="EN-US"><span leaf=""> LinkedIn </span></span><span leaf="">账户。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4624277456647399" data-type="png" data-w="865" data-imgfileid="100004746" src="https://wechat2rss.xlab.app/img-proxy/?k=d37ebf5a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgfLKOpQlGEN9hkDfY9ShOPoJb3ic4zSicpmzj43xRqib0datGdZNOibltHQWLYiaFicsYFw7iaAgSiaK5tLib8OWCric9eQicFXBfibhCDdGY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">攻击者仿冒大火的</span><span lang="EN-US"><span leaf="">DeepSeek</span></span><span leaf="">，甚至还真实提供回复。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5861271676300578" data-type="png" data-w="865" data-imgfileid="100004747" src="https://wechat2rss.xlab.app/img-proxy/?k=a34c4302&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgzueO5uyQvIwWGP7onI9VllV6fpymbjE8icCndxmrnYibjvDlW2zic5XG0xO8kou0wltnlNn38HmicvraQibYJicjUB5PKFCaqObP70%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">刚开始使用无害代码，积累了用户后通过版本更新写入恶意代码。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7283236994219653" data-type="png" data-w="865" data-imgfileid="100004748" src="https://wechat2rss.xlab.app/img-proxy/?k=e134d391&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhVSShxOtHXuGCZFLjDN0WXMjDHMzG0Ul0DCTBPetDk34codMib7skMD96txvMtXrdiadqbwicDcjiaWaubzhfejKWjVz3aUic5fgQM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">伪装成</span><span lang="EN-US"><span leaf=""> Perplexity </span></span><span leaf="">的假扩展，拦截并收集用户绝密提示词数据。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.608092485549133" data-type="png" data-w="865" data-imgfileid="100004749" src="https://wechat2rss.xlab.app/img-proxy/?k=11bbd742&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhAa9JnetOyXmWXfzAaMDicbIWzsbxWfibkIlxywEMkjsc0RZvyvNsngcrbYYicva6dSySCVRzNMpCI1KkibhOeVoY3mdgRvEUYENo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">无声渗透：东亚企业数据暴露的暗网分析 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">如今有个趋势是：攻击者不是黑进来的，而是直接登录进来的。一份真实的</span><span lang="EN-US"><span leaf=""> IAB </span></span><span leaf="">泄露日志示例（源自</span><span lang="EN-US"><span leaf=""> Redline Stealer</span></span><span leaf="">）。包含高价值目标如</span><span lang="EN-US"><span leaf=""> VPN </span></span><span leaf="">入口、</span><span lang="EN-US"><span leaf="">RDP </span></span><span leaf="">远程桌面网关，以及</span><span lang="EN-US"><span leaf=""> Outlook Web Access (OWA) </span></span><span leaf="">的登录</span><span lang="EN-US"><span leaf=""> URL</span></span><span leaf="">、账号和明文密码。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.41040462427745666" data-type="png" data-w="865" data-imgfileid="100004750" src="https://wechat2rss.xlab.app/img-proxy/?k=dba6c4da&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiagymRrFoCSTJDwuTAHAjzL7LHG0Dq39o5R17vluUf0tecOp6nWwmemtNbHILFX0micIgLJSYwjhsG1qI7TGgDY5rfvLNTwE9Wk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">根据中国台湾、日本、韩国、新加坡和中国香港的政府与市值较高的企业（共</span><span lang="EN-US"><span leaf="">849</span></span><span leaf="">个域名），过去三个月内超过</span><span lang="EN-US"><span leaf=""> 7000 </span></span><span leaf="">份初始访问经纪人（</span><span lang="EN-US"><span leaf="">IAB</span></span><span leaf="">）的泄露日志。中国香港和新加坡是做的比较好的，而只看政府相关的网站则是日本和新加坡做的比较好。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.43815028901734104" data-type="png" data-w="865" data-imgfileid="100004751" src="https://wechat2rss.xlab.app/img-proxy/?k=f04db20a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhY1Wic75dYbLlIp7UoSS6WZ5Z9F6xhneCarC4MKweBrxqoPt0IWicHNFrfEGyVvpVkmLwwqmXQewB86aaIqmBI34jBiaJoqOeDOg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">企业数据泄露情况对比如下所示：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2277456647398844" data-type="png" data-w="865" data-imgfileid="100004752" src="https://wechat2rss.xlab.app/img-proxy/?k=f72d371d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaFVq3OMUu8Z8rP06pyTnu4uRmqOG8KcjIGsrR2jkmNYoCxwJhuS4vNm99MMOibXKicp2vn5AqVaj4hwibFOrrAgUzmBrC0QeCMbI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">华尔街盗窃加密货币之狼 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Crypto traffers </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">主要是以俄语为母语的网络犯罪集团，专门对目标进行社会工程学攻击，目的是窃取加密货币和数据。黑产中的典型术语，如工人、导师、猛犸象、鲸鱼等。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8566473988439306" data-type="png" data-w="865" data-imgfileid="100004753" src="https://wechat2rss.xlab.app/img-proxy/?k=43aa9256&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiamsDgxYjaJyBH5S94wicHv7jyZuBLcZhJFqv5JibgMwGFiaZoS7Zw7QeRK0zczSf3jfn3mo106Q6aEGaotdiadPCWryVlkSeyewoI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">招聘广告中指出这是</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">网络诈骗领域的最佳解决方案</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">、</span></span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">“Win/Mac </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">双端窃密马</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">“24/7 </span></span><span leaf="">日志检查与免杀支持</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.5107913669064748" data-type="png" data-w="695" data-imgfileid="100004754" src="https://wechat2rss.xlab.app/img-proxy/?k=c6a34446&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiay0fbL5UpicEIlT8vRQg9hE7VDiax38kTgCz1Otz0oia7vUK1ytzrcGicepulEjRph7bUBpmMw8n8FuSbl0Fx3ibKGE5jwjOFmLqeg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在</span><span lang="EN-US"><span leaf=""> 2022-2025 </span></span><span leaf="">年间从</span><span lang="EN-US"><span leaf=""> 2.4 </span></span><span leaf="">万名受害者手中窃取了超</span><span lang="EN-US"><span leaf=""> 500 </span></span><span leaf="">万美元：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4554913294797688" data-type="png" data-w="865" data-imgfileid="100004755" src="https://wechat2rss.xlab.app/img-proxy/?k=b53321e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgS3TZT8yeBvxXybkvngOUlWrFYcTfbqp5ULmD6HPwuY6jjCxqeicGjRGV9X9DtAftiasssO2qIiaA6T5wu4hfj4C3L4ttSiaRvZNo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">边缘设备暴露</span><span lang="EN-US"><span leaf="">RCE</span></span><span leaf="">漏洞的协作响应 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Shadowserver</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">核心工作是水坑、扫描（</span><span lang="EN-US"><span leaf="">37</span></span><span leaf="">亿</span><span lang="EN-US"><span leaf="">IPv4</span></span><span leaf="">与</span><span lang="EN-US"><span leaf="">32</span></span><span leaf="">亿</span><span lang="EN-US"><span leaf="">IPv6</span></span><span leaf="">）、蜜罐感知与恶意软件沙盒（每天百万级，历史累计</span><span lang="EN-US"><span leaf="">20</span></span><span leaf="">亿个）。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.47398843930635837" data-type="png" data-w="865" data-imgfileid="100004756" src="https://wechat2rss.xlab.app/img-proxy/?k=496b3cff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhlkFOIz211clHI7ia5CaSgX73nRPpeDwZdeOeMUib6CXWiaGUdzEJjxxcmRTBiaKvLAxMqWicep9rTZGLRThX02jmkyics6ymh30XDs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Shadowserver (2020+) </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">数据中心规格：位于加州，</span><span lang="EN-US"><span leaf="">68 </span></span><span leaf="">个机柜，</span><span lang="EN-US"><span leaf="">1078 </span></span><span leaf="">台物理服务器，</span><span lang="EN-US"><span leaf="">14.2 PB </span></span><span leaf="">存储，</span><span lang="EN-US"><span leaf="">3 </span></span><span leaf="">万多核</span><span lang="EN-US"><span leaf=""> CPU</span></span><span leaf="">，设施总值</span><span lang="EN-US"><span leaf=""> 3-4 </span></span><span leaf="">千万美元。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.507514450867052" data-type="png" data-w="865" data-imgfileid="100004757" src="https://wechat2rss.xlab.app/img-proxy/?k=806553f5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhXxBgudMicXhFGWCdv3It97J9k9GKJDly2e9mQamtj50IBpJFWr5xJ1RN8KJF2rkjKUib5oEgfMzEsMiatzbFZLmQjh4YGrmDCNk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在全球部署了数千个蜜罐：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5872832369942197" data-type="png" data-w="865" data-imgfileid="100004758" src="https://wechat2rss.xlab.app/img-proxy/?k=422226de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhIdK623zOWDYkJV7uDMuibX9J9o4X5YjnQFQibsxoicIKpEIXA9XL15HxZPkYjytzEoVld124oPA1BmQectmU4jnMP11p5qoKmp4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">对漏洞利用的持续跟踪：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6" data-type="png" data-w="865" data-imgfileid="100004759" src="https://wechat2rss.xlab.app/img-proxy/?k=08015e56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhcVCsLhiasqUPQOxJ8HO1vEIY2XxgrH7vxuORehibWamFnmSe9sTibib5VWibNSsnTVSF1ulNicLhxawVFwf4xzNgNJuUMyxcegEV0w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">领先他人发现在野漏洞利用：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.46705202312138727" data-type="png" data-w="865" data-imgfileid="100004760" src="https://wechat2rss.xlab.app/img-proxy/?k=b347cfca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNh5wotJRhQcxIf7ZDR6D2r97ybhwZDS284gRIoUn7r18WiaDGtCzPXn8SzIU3Ge3OYorYq9tj7XJyA6jgneKV8Yr8EKACIHbz8c%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">最后举了</span><span lang="EN-US"><span leaf="">Microsoft SharePoint CVE-2025-49706</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Palo Alto PAN-OS CVE-2024-0012</span></span><span leaf="">与</span><span lang="EN-US"><span leaf="">Citrix NetScaler CVE-2023-3519</span></span><span leaf="">的例子，此处不再赘述。</span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">如何利用</span><span lang="EN-US"><span leaf="">DNS4EU</span></span><span leaf="">从请求中捞出威胁 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">其数据处理架构如下所示：采用了</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">集成学习</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的思路，结合基于结构（隔离森林）、基于密度（</span><span lang="EN-US"><span leaf="">DBSCAN</span></span><span leaf="">）和基于概率（</span><span lang="EN-US"><span leaf="">GMM</span></span><span leaf="">）的三种不同算法。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5930635838150289" data-type="png" data-w="865" data-imgfileid="100004761" src="https://wechat2rss.xlab.app/img-proxy/?k=38bde1d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgpYciaaa0PBC50tnMc4XatlSEeviajtUKQsm8w4LWfiaAot7H63FwMUw3UAMzNSEMqVwWLrzHMSR6AU3OIhacCh3KrcNFRmqn11A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">每秒最低处理约</span><span lang="EN-US"><span leaf=""> 15,000 </span></span><span leaf="">次查询。每小时</span><span lang="EN-US"><span leaf=""> 5400 </span></span><span leaf="">万次查询，每天最低</span><span lang="EN-US"><span leaf=""> 12.96 </span></span><span leaf="">亿次查询。每周估算存储约</span><span lang="EN-US"><span leaf=""> 1TB</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.27630057803468205" data-type="png" data-w="865" data-imgfileid="100004762" src="https://wechat2rss.xlab.app/img-proxy/?k=87c7f38a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgA1dGw27OmudPTHrOaCqwyBZGR1YdYQShbX090LEDUe6UyTt7HlI6EYfl1epJ0CMfoDu42DewAvW0bhUKzLrekJlTl3rwI7wM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">特征工程：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.661271676300578" data-type="png" data-w="865" data-imgfileid="100004763" src="https://wechat2rss.xlab.app/img-proxy/?k=7bf71aac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNh1WfrNZrVxhldybRdq36icQc0E9lc1ibaulM5TbWr8rK5WJwibho9CfqBU1Relud1c85JJ1VCgbT6FQ2agcLrOprKwe2nichXiaYks%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">两步走：</span><span lang="EN-US"><span leaf="">1</span></span><span leaf="">、通过聚类找出异常点（隔离森林、</span><span lang="EN-US"><span leaf="">GMM</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">DBSCAN </span></span><span leaf="">模型）。</span><span lang="EN-US"><span leaf="">2</span></span><span leaf="">、利用贝叶斯推断（</span><span lang="EN-US"><span leaf="">Bayesian Inference</span></span><span leaf="">）来降低误报率。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">模型引入了</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">先验信念（</span><span lang="EN-US"><span leaf="">Prior belief</span></span><span leaf="">）</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">。比如预设</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">只有约</span><span lang="EN-US"><span leaf=""> 5% </span></span><span leaf="">的域名是恶意的</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">，或者</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">某个情报源通常很准</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">。并为每个信念赋予置信度权重。当一个新域名带着各种证据（如异常模型告警）到来时，模型会评估这些证据是更符合</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">恶意</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的特征，还是更符合</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">良性</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的特征。每一项证据都会动态向上或向下调整信任度，结合先验概率，计算出最终的</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">后验概率（该域名是恶意的实际概率）</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">采取了</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">次日回溯验证法</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">。对于今天提议拦截的域名，在第二天查询其在</span><span lang="EN-US"><span leaf=""> Tranco </span></span><span leaf="">白名单排名、</span><span lang="EN-US"><span leaf="">15 </span></span><span leaf="">种商业威胁情报源、以及</span><span lang="EN-US"><span leaf=""> VirusTotal / Urlscan </span></span><span leaf="">等</span><span lang="EN-US"><span leaf=""> API </span></span><span leaf="">中的状态 。根据命中情况进行</span><span lang="EN-US"><span leaf=""> 0-5 </span></span><span leaf="">分的打分（例如：如果在</span><span lang="EN-US"><span leaf=""> Tranco </span></span><span leaf="">前列得</span><span lang="EN-US"><span leaf=""> 0 </span></span><span leaf="">分即良性；如果在</span><span lang="EN-US"><span leaf=""> VT </span></span><span leaf="">中被多家检出则得</span><span lang="EN-US"><span leaf=""> 5 </span></span><span leaf="">分即确认为恶意）。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-type="png" data-w="865" data-imgfileid="100004764" src="https://wechat2rss.xlab.app/img-proxy/?k=a7cbb965&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiabGMFC38ZFHp1ZZabYmJZicJiaUVBF10sJZWBriaKgntn9ibxTv1QpvAZ2Y4c9Wu7eMCXwdZKfSsTjGXZ3fsibTKIfZAh1wVARpvag%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">案例一：位列</span><span lang="EN-US"><span leaf=""> Tranco </span></span><span leaf="">全球白名单前</span><span lang="EN-US"><span leaf=""> 10 </span></span><span leaf="">万名以内的域名，被俄罗斯情报总局（</span><span lang="EN-US"><span leaf="">GRU</span></span><span leaf="">）下属的</span><span lang="EN-US"><span leaf=""> APT </span></span><span leaf="">组织</span><span lang="EN-US"><span leaf="">BlueDelta </span></span><span leaf="">用于针对欧洲关键网络的多阶段间谍活动。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5121387283236994" data-type="png" data-w="865" data-imgfileid="100004765" src="https://wechat2rss.xlab.app/img-proxy/?k=57f36096&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgBrpm53BWic4Dlib5z4cibYfl3CHqhTWL2CClLibENLyQRKoN4uIA8uBhzj7OrvJJA4ia3eZe6NrPeS0ZShezsR5aibsD3V0aPLDacc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">案例二：伪造</span><span lang="EN-US"><span leaf="">Adobe</span></span><span leaf="">软件更新域名，该攻击基础设施与</span><span lang="EN-US"><span leaf="">LockBit</span></span><span leaf="">勒索软件有关。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3468208092485549" data-type="png" data-w="865" data-imgfileid="100004766" src="https://wechat2rss.xlab.app/img-proxy/?k=fb3c9c09&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhEqV7xpK4XfzQWsyAblIthKGmYSwicJ23xfRoibOlrxv6zyQZdlrhtA1icBwO0IUnOaIfPNq6fWxQNOLM4mHRBx7ts5IicEKekGEw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">案例三：伪装成</span><span lang="EN-US"><span leaf="">Zoom</span></span><span leaf="">软件更新域名，其</span><span lang="EN-US"><span leaf="">TTL</span></span><span leaf="">值为</span><span lang="EN-US"><span leaf="">1</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4658959537572254" data-type="png" data-w="865" data-imgfileid="100004767" src="https://wechat2rss.xlab.app/img-proxy/?k=bcb967c1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiauq25xau8Uz3ibu3d5Wpwk5RXUf1FHwCGWAXCXohNBVlibaquNCMxqMibfPmE8Hia7VdjXXwGpStrG2O2jeFbGdC8nCqW8xb1JDro%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">案例四：</span><span lang="EN-US"><span leaf="">DNS</span></span><span leaf="">隧道或者</span><span lang="EN-US"><span leaf="">DGA</span></span><span leaf="">域名。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3352601156069364" data-type="png" data-w="865" data-imgfileid="100004768" src="https://wechat2rss.xlab.app/img-proxy/?k=ddee42da&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhlVgaAfp12XFGxjZgvIHFsaTgTFhtfxOSv1KwwmZDxWI4VOeIvxibVxIm2bHLcHusMeHO3QsHxvYpl9TMj5vgzkicm6EZ2MVDKU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">案例五：商业间谍软件</span><span lang="EN-US"><span leaf=""> Predator Spyware</span></span><span leaf="">的恶意域名。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3722543352601156" data-type="png" data-w="865" data-imgfileid="100004769" src="https://wechat2rss.xlab.app/img-proxy/?k=c63f7b32&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhU0x7zSwN3tGRrwN6CrRzZtghGDdun6jiaH63xtJblnsKJS5GCQVBbhcmpfib1cXb2q4PYxaKKhjL4UTKz4R1c7LWTbdiboaWqXY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4578034682080925" data-type="png" data-w="865" data-imgfileid="100004770" src="https://wechat2rss.xlab.app/img-proxy/?k=5c0f2069&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhSib2M1Hvboiam2P6BMqrQVv2MggD5BHQERh8tNjOnPUVwPbDCH3Id8IhrHABdq1BlubYQabKclSia8G25ibnO1xMA19ibg71PqaEY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">案例六：窃密木马</span><span lang="EN-US"><span leaf="">Lumma Stealer。</span></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span lang="EN-US"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3606936416184971" data-type="png" data-w="865" data-imgfileid="100004771" src="https://wechat2rss.xlab.app/img-proxy/?k=5ca36a6b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhsp2pQ7icVlozFoY6icYqKiaIvGsciatqcjZWoia3ndicINGgM6qz831BvJ3ngMWl6wdMstYuRvxgoA5N1INA4PB03YGKwt4PCbqxr8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">DNS4GOV</span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">：欧洲</span><span lang="EN-US"><span leaf="">PDNS </span></span><span leaf="">准备情况 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">DNS4EU</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">旨在通过独立的</span><span lang="EN-US"><span leaf="">DNS </span></span><span leaf="">保护来增强欧洲的数字安全。欧盟委员会的目标是为公民、机构和企业提供安全、符合隐私规范且强大的递归</span><span lang="EN-US"><span leaf="">DNS</span></span><span leaf="">。创建基于欧盟的独立</span><span lang="EN-US"><span leaf=""> DNS</span></span><span leaf="">，并对威胁做出实时反应。此举措凸显欧洲在面临地缘政治风险时，追求</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">数字主权</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">和摆脱对美国科技巨头（如</span><span lang="EN-US"><span leaf="">Google 8.8.8.8 </span></span><span leaf="">或</span><span lang="EN-US"><span leaf=""> Cloudflare 1.1.1.1</span></span><span leaf="">）依赖的急迫性。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">欧盟约有</span><span lang="EN-US"><span leaf=""> 20 </span></span><span leaf="">亿台联网设备，</span><span lang="EN-US"><span leaf="">4.48 </span></span><span leaf="">亿独立用户。并且，超过</span><span lang="EN-US"><span leaf=""> 90% </span></span><span leaf="">的网络攻击依赖于</span><span lang="EN-US"><span leaf=""> DNS</span></span><span leaf="">。项目由</span><span lang="EN-US"><span leaf=""> Whalebone </span></span><span leaf="">牵头，其他成员包括</span><span lang="EN-US"><span leaf=""> CZ.NIC</span></span><span leaf="">、布拉格捷克理工大学、</span><span lang="EN-US"><span leaf="">Time.lex</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">deSEC</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">HUN-REN</span></span><span leaf="">等。还有多个国家的网络安全中心（如罗马尼亚</span><span lang="EN-US"><span leaf=""> DNSC</span></span><span leaf="">、波兰</span><span lang="EN-US"><span leaf="">NASK</span></span><span leaf="">）作为合作伙伴。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.43583815028901735" data-type="png" data-w="865" data-imgfileid="100004772" src="https://wechat2rss.xlab.app/img-proxy/?k=dbcd4cce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhFoyQS1hqRNojztHiaWbNWu2STeEKic6G5zibQNfoOL7QQOOphgUkElOy1BlGyPzgdXE7ZCscZIb9gg3fx92eAtezp1moNXia5xDA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">DNS4GOV</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">针对政府，支持多租户架构的分层部署模式。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.48554913294797686" data-type="png" data-w="865" data-imgfileid="100004773" src="https://wechat2rss.xlab.app/img-proxy/?k=fe162666&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNias7ZQZfa7UPhyqKoFz3G8ib2iabl21T4QVgN5y4cU4326rXILYVUrYicsljQudF2HZfzy8zU6PjsYicgEGOribVpEpf7sdytiaOPUno%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2025</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">年已有</span><span lang="EN-US"><span leaf=""> 20 </span></span><span leaf="">多个国家级网安中心（</span><span lang="EN-US"><span leaf="">NCSC</span></span><span leaf="">）处于后期引入阶段，</span><span lang="EN-US"><span leaf="">18 </span></span><span leaf="">个处于概念验证阶段，且已有</span><span lang="EN-US"><span leaf=""> 14 </span></span><span leaf="">个</span><span lang="EN-US"><span leaf=""> CERT</span></span><span leaf="">接入</span><span lang="EN-US"><span leaf=""> MISP </span></span><span leaf="">威胁情报交换平台。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4277456647398844" data-type="png" data-w="865" data-imgfileid="100004774" src="https://wechat2rss.xlab.app/img-proxy/?k=9e6faf97&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjvExibI9624wAEyJH2XqlDMzJ83x7L6WMict0gnwLfibnjzvDxf9xg1Hv1Thcp2KzGNSd9LVWzwFnmmJvKvaibGicBrHcPsrZhqLhk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">其后端数据处理流水线如下所示。过去一个月屏蔽了超过</span><span lang="EN-US"><span leaf=""> 38 </span></span><span leaf="">亿次恶意域名访问，数据库中拥有</span><span lang="EN-US"><span leaf=""> 2650 </span></span><span leaf="">万个独立恶意域名，每天新增</span><span lang="EN-US"><span leaf=""> 35 </span></span><span leaf="">万个。其中 </span><span lang="EN-US"><span leaf="">56% </span></span><span leaf="">为恶意软件，</span><span lang="EN-US"><span leaf="">18.28%</span></span><span leaf="">为 </span><span lang="EN-US"><span leaf="">C&amp;C </span></span><span leaf="">节点，</span><span lang="EN-US"><span leaf="">12.2% </span></span><span leaf="">为钓鱼网站。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.5481569560047563" data-type="png" data-w="841" data-imgfileid="100004775" src="https://wechat2rss.xlab.app/img-proxy/?k=0aadf442&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaog2l939uHk4q8rXc3kE0h2uUflksrIkc6Yyrm20EozKcicrcKCjALwZ1VcbKdaCmsfmL9L0okcArcEy9zxTiaLkALutY8Bibhs8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">杀伤链中的</span><span lang="EN-US"><span leaf="">EDR Killer</span></span><span leaf="">江湖 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">EDR Killer</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">已经演变成独立的服务，勒索软件的</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">附属分支</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">Affiliate</span></span><span leaf="">）会向</span><span lang="EN-US"><span leaf=""> RansomHub </span></span><span leaf="">控制的服务器请求生成专属的</span><span lang="EN-US"><span leaf=""> EDRKillShifter </span></span><span leaf="">载荷。</span><span lang="EN-US"><span leaf="">Medusa</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">RansomHub</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">BianLian</span></span><span leaf="">和</span><span lang="EN-US"><span leaf=""> Play </span></span><span leaf="">等多个互为竞争对手的勒索团伙，竟然共享了相同的工具。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4936416184971098" data-type="png" data-w="865" data-imgfileid="100004776" src="https://wechat2rss.xlab.app/img-proxy/?k=8008de0e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhicLnjViazw8sTCNE58kYKWJLYJMpVHZM641hnQy4A1yY6lOZMSSrE6p2dGYLzd48gMqeO3uRk4AyJ9ica6BnX7uiah2TJH4gLXDc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通过恶意软件读取的卷序列号，可以发现相同攻击者为多个勒索软件团伙提供工具。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6127167630057804" data-type="png" data-w="865" data-imgfileid="100004777" src="https://wechat2rss.xlab.app/img-proxy/?k=bd7312bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiamjbRakjkRn1je8X20E5Ea2YuiaichVUY8sz24RecIgJNcIkgu1LOD70OYEsZHmU1PezV2psibuX5LwjHCKTDfEILHzrjEb8HtKQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">从攻击者购买的免杀加壳服务</span><span lang="EN-US"><span leaf="">HeartCrypt</span></span><span leaf="">来看，两千多个文件中</span><span lang="EN-US"><span leaf="">EDR Killer</span></span><span leaf="">仅占到</span><span lang="EN-US"><span leaf="">2%</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5479768786127167" data-type="png" data-w="865" data-imgfileid="100004778" src="https://wechat2rss.xlab.app/img-proxy/?k=96412e2f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhaecgMIaGiam9FboU2E7iagXZ2FGjoYI9GBiae6GpL5QEEbsu5PZY8ro9sF04UA3Mf0h4ibshS32dWA40ICicOwM4Oz8D541UZNnEw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">一款名为</span><span lang="EN-US"><span leaf=""> ScorchedHeart </span></span><span leaf="">的恶意驱动程序会主动寻找</span><span lang="EN-US"><span leaf="">5</span></span><span leaf="">个随机字母名字的驱动，并直接删除各大杀软安装目录下的</span><span lang="EN-US"><span leaf=""> .EXE </span></span><span leaf="">文件，同时杀死相关进程。其硬编码的目标列表中包含了</span><span lang="EN-US"><span leaf=""> Eset</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Symantec</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Sophos</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">HitmanPro</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Kaspersky</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">SentinelOne </span></span><span leaf="">等几乎所有主流厂商。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6520231213872832" data-type="png" data-w="865" style="width:431px;height:281px;" data-imgfileid="100004780" src="https://wechat2rss.xlab.app/img-proxy/?k=0165cd50&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgv3GEhplJXxia3Nkuhvic5koiaFTmickMZIGKX7RHN6uyhrsqGbmsx29OmhiaxgpLPS4CGkfR9iaQjyhQyxDzZMUTtQTEdBYichAubXI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">攻击者滥用已经过期或被吊销的代码签名证书，并操纵系统时间，让</span><span lang="EN-US"><span leaf=""> Windows </span></span><span leaf="">误以为驱动是合法的。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5179190751445086" data-type="png" data-w="865" data-imgfileid="100004781" src="https://wechat2rss.xlab.app/img-proxy/?k=b353fa1f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjVByaaImNj3W1wk0Dqd2D77KTAp4HVkv0WiamyCGOYfHuUq6fc7mDiapzFPjA0lPVRicXsDdbGHCbicOCzTIuzUdgwOSmLnstnKE8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">研究人员展示了一个极具创意的逃逸手段：攻击者没有选择杀掉进程，而是部署了合法磁盘管理软件</span><span lang="EN-US"><span leaf=""> Acronis Disk Director</span></span><span leaf="">。通过命令行调用该工具，直接将系统盘强行分割，并将安全软件的目录移动到新分区，导致</span><span lang="EN-US"><span leaf=""> EDR </span></span><span leaf="">软件的各种快捷方式和依赖环境瞬间断裂，使其无法运行。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5502890173410404" data-type="png" data-w="865" data-imgfileid="100004782" src="https://wechat2rss.xlab.app/img-proxy/?k=ebcd3742&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhqujLwHOkOiatnTwO0dN0tUCgiab1v5vC73sjSkyFTQQLU7UPnCVHRKWOhIibOfQ2PVySJMlXciaJIYibxoobRoNbN3NdkotpicaQtA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">现代勒索软件黑产的复杂程度已经远远超出了传统的</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">单一组织结构</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">模型。核心开发者、附属分支机构、初始访问经纪人和免杀工具提供商之间的界限越来越模糊，形成了一个高度液态化的地下黑市。</span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">揭秘</span><span lang="EN-US"><span leaf="">TAG-124</span></span><span leaf="">流量分发系统（</span><span lang="EN-US"><span leaf="">TDS</span></span><span leaf="">） </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">TDS</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">存在已久，用于根据特定因素（如地理位置、浏览器、设备）将受害者的网络流量重定向到恶意内容。其优势在于：目标精准、可扩展性强、灵活性高、规避检测能力极强。</span><span lang="EN-US"><span leaf="">TAG-124 </span></span><span leaf="">是一个操纵</span><span lang="EN-US"><span leaf=""> TDS </span></span><span leaf="">的威胁组织，也被其他安全厂商称为</span><span lang="EN-US"><span leaf=""> LandUpdate808</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">KongTuke </span></span><span leaf="">或</span><span lang="EN-US"><span leaf=""> Chaya_002</span></span><span leaf="">。该组织于</span><span lang="EN-US"><span leaf=""> 2024 </span></span><span leaf="">年初首次被发现，此后用户群稳步扩大。他们运营着数千个被攻陷的</span><span lang="EN-US"><span leaf=""> WordPress </span></span><span leaf="">站点以及自行控制的基础设施。其第一阶段分发服务器的数量变化不明显，可能是由于被检测后主动缩小规模进行技术迭代或者转移到更隐蔽的节点，是攻防对抗中的战术性撤退。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5142487046632125" data-type="png" data-w="772" data-imgfileid="100004783" src="https://wechat2rss.xlab.app/img-proxy/?k=406fc871&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjQDAicic3jTzTibqLkYfDk5vxXlCyUxpbH9cicH7xvSQ1t75vdBhcQfhf6EYBIHLdOlL3BIib9Us6QNdxN2tfoHMRHMhEoGsudtQ8k%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">虽然</span><span lang="EN-US"><span leaf=""> 1% </span></span><span leaf="">的顶级网站占据了</span><span lang="EN-US"><span leaf=""> 90% </span></span><span leaf="">的流量且非常安全，但中小网站占据了</span><span lang="EN-US"><span leaf=""> 10% </span></span><span leaf="">的长尾流量，其中约</span><span lang="EN-US"><span leaf=""> 44% </span></span><span leaf="">使用</span><span lang="EN-US"><span leaf=""> WP</span></span><span leaf="">。在这些</span><span lang="EN-US"><span leaf=""> WP </span></span><span leaf="">网站中，</span><span lang="EN-US"><span leaf="">20-30%</span></span><span leaf="">存在漏洞。结论：任何一次页面浏览，都有</span><span lang="EN-US"><span leaf=""> ~0.9%-1.3% </span></span><span leaf="">的概率命中一个有漏洞的</span><span lang="EN-US"><span leaf=""> WP </span></span><span leaf="">站点。</span><span lang="EN-US"><span leaf="">TAG-124</span></span><span leaf="">的基础设施架构如下所示，通过层层隔离来保持基础设施的稳健。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.44277456647398844" data-type="png" data-w="865" data-imgfileid="100004784" src="https://wechat2rss.xlab.app/img-proxy/?k=39814af7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgyv88HI51dBAjYKWeg4ffVQvVvorVc8NvnU9vtLLNWtFr6cczEHEn0ylIcaH3iaaLmnib0PCfLE6IOvGG86keqh74Fv35U2ZAwQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">TAG-124</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">是暗网上最顶级的流量批发商之一，其客户很多包括勒索软件团伙、顶级黑客组织团伙等。证明其过滤后的流量</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">纯度</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">极高，全是具备高价值内网渗透潜力的高质量主机。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4184971098265896" data-type="png" data-w="865" data-imgfileid="100004785" src="https://wechat2rss.xlab.app/img-proxy/?k=52a9964f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiabm2jdjiaHtDiaHHuHEwGP3UEXlPfh32iaFcIvp1PDzicpngSk2ic5AzhNhZ7YUaCDhquqlo4NIyWgZAibfOCYKBEWVVm9O6FvUIpe8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">ECHidna</span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">利用</span><span lang="EN-US"><span leaf="">ECH</span></span><span leaf="">彻底隐藏</span><span lang="EN-US"><span leaf="">C&amp;C</span></span><span leaf="">流量 </span></span></b><b><span lang="EN-US" style="font-size:
12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2024</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">年攻击日本研究机构，将</span><span lang="EN-US"><span leaf="">C&amp;C</span></span><span leaf="">流量伪装成正常的</span><span lang="EN-US"><span leaf="">Cloudflare</span></span><span leaf="">流量。其</span><span lang="EN-US"><span leaf="">RAT</span></span><span leaf="">在内存中解压并反射加载</span><span lang="EN-US"><span leaf="">Payload</span></span><span leaf="">。并且静态链接</span><span lang="EN-US"><span leaf="">BoringSSL</span></span><span leaf="">实现自定义</span><span lang="EN-US"><span leaf="">TLS</span></span><span leaf="">连接。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.32213740458015266" data-type="png" data-w="655" data-imgfileid="100004786" src="https://wechat2rss.xlab.app/img-proxy/?k=519edc7b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaZ8PkrumebS6gWC1t5a697XSJJlHKuhTtgqMG9Z8vDFycQ5NkmWsY0H6AxyKjqNGP5icsSrgdYicH4pG17ibhc4KicluqWVXXSNMo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Chromium 117</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">版本以及</span><span lang="EN-US"><span leaf="">Firefox119</span></span><span leaf="">版本已经默认支持</span><span lang="EN-US"><span leaf="">ECH</span></span><span leaf="">，</span><span lang="EN-US"><span leaf="">Cloudflare</span></span><span leaf="">与</span><span lang="EN-US"><span leaf="">Fastly</span></span><span leaf="">也正在计划支持</span><span lang="EN-US"><span leaf="">ECH</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5606936416184971" data-type="png" data-w="865" data-imgfileid="100004787" src="https://wechat2rss.xlab.app/img-proxy/?k=2d07a431&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhYtlZiaUuH3VibeM1BicmnjbbhuM8QNgpahiaibrOZQdXsCy0dzGEB4MOzwS5ryQr9ic5pNA5jmGbrqmWXLSppQqUvdrOd987vEXBQ4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">该恶意软件的</span><span lang="EN-US"><span leaf="">DNS</span></span><span leaf="">查询都是走的</span><span lang="EN-US"><span leaf="">DoH</span></span><span leaf="">，在多个公共</span><span lang="EN-US"><span leaf="">DoH</span></span><span leaf="">服务器进行轮询。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.47957371225577267" data-type="png" data-w="563" data-imgfileid="100004788" src="https://wechat2rss.xlab.app/img-proxy/?k=a2934e1c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaVxPDWcWUhEy6okxyzZjoVx6vs4EEiawBWO4Zuvln4MltOEEISzYSkGtiacXoAPf6XicuHuoXUVmYmuqVxEfF3svWFrfRn7gIdRA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">可以从三个方面进行检测：</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">（</span><span lang="EN-US"><span leaf="">1</span></span><span leaf="">）返回带有</span><span lang="EN-US"><span leaf="">ech=</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">HTTPS</span></span><span leaf="">响应记录（</span><span lang="EN-US"><span leaf="">2</span></span><span leaf="">）</span><span lang="EN-US"><span leaf="">SNI</span></span><span leaf="">为</span><span lang="EN-US"><span leaf="">cloudflare-ech.com</span></span><span leaf="">且带有</span><span lang="EN-US"><span leaf="">EncryptedClientHello</span></span><span leaf="">扩展（</span><span lang="EN-US"><span leaf="">3</span></span><span leaf="">）特定进程树</span><span lang="EN-US"><span leaf="">explorer.exe </span></span><span leaf="">→</span><span lang="EN-US"><span leaf=""> powershell.exe </span></span><span leaf="">→</span><span lang="EN-US"><span leaf=""> rundll32.exe</span></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=0ef9fb85&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488440%26idx%3D1%26sn%3D22866492db4a3e9126a483d45e1c2bf4">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 10 Mar 2026 09:04:00 +0800</pubDate>
    </item>
    <item>
      <title>Botconf 2025 议题慢递</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488299&amp;idx=1&amp;sn=d2c79447312c2e01c636fa1e52717334</link>
      <description>Botconf 2025 虽迟但到！</description>
      <content:encoded><![CDATA[<p>原创 <span>Avenger</span> <span>2026-03-05 09:05</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=24ba9bbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FOsTASDqnFNjf4HC4qWeeNxBs3QUUUfUouHvpQJYwPxibaKfbfZuaKDOUwU5Wyj3ic3qyFOC1DJUHSc4oIbAicpqsv3jnrlPowx7LMBwVQWvsic8%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>Botconf 2025 虽迟但到！</p>
  <p><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 12pt;font-family: 微软雅黑, sans-serif;visibility: visible;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">2025 </span></span><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 12pt;font-family: 微软雅黑, sans-serif;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">年的第十二届 </span><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">Botconf </span></span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">来到了法国的昂热（不是</span><span leaf="">卡塞尔学院那个老不正经</span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">）。全世界数百位安全研究人员再一次齐聚一堂，热热闹闹地讨论相关议题。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.5217917675544794" data-s="300,640" data-type="png" data-w="826" type="block" data-imgfileid="100004562" src="https://wechat2rss.xlab.app/img-proxy/?k=31a2dd13&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaXMVagBDXypRApoDMvMoibgoXBjoSb0HWT92HDamOmHlpY4E6Pzvd8zV6a50EhDUIPYiaaGeXRLGFtzKPVrQicEgic9mmId2FUtXw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-remoteid="" data-asynid="" src="https://www.botconf.eu/wp-content/uploads/2025/02/affiche-botconf-2025-682x1024.png" data-src="" align="" alt="affiche-botconf-2025" border="" class="rich_pages wxw-img" data-ratio="" data-s="" data-type="" data-w="" aria-label="" aria-braillelabel="" aria-description="" height="" hspace="" ismap="" opacity="" sizes="" style="" title="" type="" usemap="" vspace="" width="" data-width="" data-height="" data-croporisrc="" data-cropx1="" data-cropx2="" data-cropy1="" data-cropy2="" data-cropselx1="" data-cropselx2="" data-cropsely1="" data-cropsely2="" data-backw="" data-backh="" data-copyright="" data-oversubscription-url="" data-before-oversubscription-url="" data-galleryid="" data-gallerysupplier="" data-cardimg="" data-fileid="" data-imgfileid="" data-positionback="" data-imgqrcoded="" data-imgid="" data-upload="" data-fromlib="" data-aiimageid="" data-aiimagesource="" data-cacheurl="" data-aistatus="" data-retry=""><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 12pt;font-family: 微软雅黑, sans-serif;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: 微软雅黑, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;" data-pm-slice="0 0 []">下面只挑选部分议题进行介绍，感兴趣的同学可以去官网查看全部议题进一步了解。一如既往要强调的是，会议要求参会人一定要遵守 </span><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: 微软雅黑, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">TLP </span></span><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: 微软雅黑, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;">要求，本文只简要介绍了部分议题，完整、详细的内容请查看官网或者联系作者。</span></span></p><p style="mso-outline-level:2;" data-pm-slice="0 0 []"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">跨架构的 </span><span lang="EN-US"><span leaf="">Mirai </span></span><span leaf="">配置提取工具 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Mirai</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">也是老熟人了，不过多介绍。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4346820809248555" data-type="png" data-w="865" data-imgfileid="100004566" src="https://wechat2rss.xlab.app/img-proxy/?k=d00e926c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjhOK6esm7ictHoHhCZ661G0N53NCP21OgE7GOfjicmTrQQlohNuZwVU7mM8oo2FiasuJV7BZIhq1aukqwdduBGuuUW189NSIGicT8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.47167630057803467" data-type="png" data-w="865" data-imgfileid="100004568" src="https://wechat2rss.xlab.app/img-proxy/?k=7b231c61&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjT4cEKuordAjOumyZey3blSkwROwnicOq77H1vEurTp8d17eoAL6Bjt65gR7ZTDbOcSvk9mhm7X8zNR4iavNx4KoXyVN90vZ7vI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">现在已经有了一些提取</span><span lang="EN-US"><span leaf="">Mirai</span></span><span leaf="">配置的工具：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.26011560693641617" data-type="png" data-w="865" data-imgfileid="100004569" src="https://wechat2rss.xlab.app/img-proxy/?k=b2fd09d4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiadHQXM8wiaBvYYjp5QHbVlzrZY1hBM4etPrOCw1rNMVDVdtJRMhMFFxS6HNLb1AJrJG7iaubcRBgI64Kib77ictDeibBmZQribBJjAk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">可以看到各有缺陷，所以研究人员要构建一个大一统的工具。基于</span><span lang="EN-US"><span leaf="">NSA </span></span><span leaf="">开源的逆向工具</span><span lang="EN-US"><span leaf="">Ghidra</span></span><span leaf="">，把不同</span><span lang="EN-US"><span leaf=""> CPU </span></span><span leaf="">的机器码翻译成一种统一的中间语言</span><span lang="EN-US"><span leaf=""> P-Code</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.33641618497109826" data-type="png" data-w="865" data-imgfileid="100004570" src="https://wechat2rss.xlab.app/img-proxy/?k=b743994f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNg567h8IY8ibib4OSCEnP3SeSMkzOGfgHlvF8D1sJ7xnym9BHjDIEL78HI2ZO82FicnPNXFPGmibEBvfdEotN9xuM27COmsDQeOlhA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">提取的配置信息如下所示：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5190751445086705" data-type="png" data-w="865" data-imgfileid="100004571" src="https://wechat2rss.xlab.app/img-proxy/?k=459f92e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiangULvP6xuLUTsXwibd7Dc5c9ib44BXEtY4aodrPxbGO0Fg6hONcJibhlWYoFSqlGib3AWibdLvNicIV8IY7qCDu86tGBY5ehaJl0nU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">提取的效果很好：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.26705202312138726" data-type="png" data-w="865" data-imgfileid="100004572" src="https://wechat2rss.xlab.app/img-proxy/?k=6a028a77&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhUjJDdLSoqmInY9230Hc6OMUVUiaroVUTUuFIrH0Dy8Z4e6o3ymZ8s0a7w29BicwWFxpDeMbeoLYgeMKSX9RibfIhGMK54k7aia6o%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">各个架构都能很好地处理：</span></span></p><p style="text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.28670520231213875" data-type="png" data-w="865" data-imgfileid="100004573" src="https://wechat2rss.xlab.app/img-proxy/?k=d79f8e7d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjmgf5PQOtRoafhh28bsysSHQO8bH2NzERXfFTWeNKAc17mqtygpHm0qpHfmsPpsaKRicF7vPx4vQWP7EmpUSknrN1ibrxjnL1hY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf=""><span class="code-snippet__attr">https</span>:<span class="code-snippet__comment">//github.com/iij/mirai-toushi</span></span></code></pre></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="" style="font-weight: bold;font-size: 12pt;font-family: 微软雅黑, sans-serif;">跨越十年的大规模恶意软件比对</span></span><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">此前在法国国家网络安全局（</span><span lang="EN-US"><span leaf="">ANSSI</span></span><span leaf="">）开发了</span><span lang="EN-US"><span leaf="">Machoc</span></span><span leaf="">哈希，几秒钟内可以对比数百个恶意软件。对每个函数提取</span><span lang="EN-US"><span leaf="">CFG</span></span><span leaf="">、内部调用，将这些信息转换成文本表示再计算哈希。缺点是连接公共库会造成大量相似，且短小函数无法处理。最关键的是，在百万级样本下无法计算。</span></span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="bash"><code><span leaf=""><a href="https://github.com/ANSSI-FR/polichombr/blob/dev/docs/MACHOC_HASH.md" target="_blank">https://github.com/ANSSI-FR/polichombr/blob/dev/docs/MACHOC_HASH.md</a></span></code></pre></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span lang="EN-US"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6820809248554913" data-type="png" data-w="865" data-imgfileid="100004574" src="https://wechat2rss.xlab.app/img-proxy/?k=4aa3cb63&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiacvj3Nt8Sic9LgvY7YbibWsMyJuicKtiaCEG4fCuKLFa2nBqdm19KBibdibNfAWEvIcThglfqvREDQ9njxQOHGABN9aUJm7pUW1taRE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">算法升级成</span><span lang="EN-US"><span leaf="">Machoke</span></span><span leaf="">把一个样本里所有函数的哈希值，映射到一个</span><span lang="EN-US"><span leaf="">bitmap</span></span><span leaf="">上。这样就可以将样本间的比对，转换成位运算变得极快。前面也要增加预过滤逻辑，如函数数量要大致相同、大</span><span lang="EN-US"><span leaf="">bitmap</span></span><span leaf="">降维成小</span><span lang="EN-US"><span leaf="">bitmap</span></span><span leaf="">后先确认大概相似再比对大</span><span lang="EN-US"><span leaf="">bitmap</span></span><span leaf="">、静态链接库的</span><span lang="EN-US"><span leaf="">bimap</span></span><span leaf="">算好后从样本的</span><span lang="EN-US"><span leaf="">bitmap</span></span><span leaf="">减去。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3086705202312139" data-type="png" data-w="865" data-imgfileid="100004575" src="https://wechat2rss.xlab.app/img-proxy/?k=3f44b663&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNh3AY3rwMpkwsYXDmboZGR2FdTKEAiaDFhbxfJUvR0IeMuC6rUDKbXQzKM4DsiblxRanoUv9AE13lwq2AXNtmeF1Hq1M1JKYsyKI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">不仅有看整体的</span><span lang="EN-US"><span leaf="">Machoke</span></span><span leaf="">，还有函数级的</span><span lang="EN-US"><span leaf="">Zubat</span></span><span leaf="">。整体的过程是反汇编</span><span lang="EN-US"><span leaf=""> -&gt; CFG -&gt; </span></span><span leaf="">提取核心逻辑</span><span lang="EN-US"><span leaf=""> -&gt; </span></span><span leaf="">中间表示</span><span lang="EN-US"><span leaf=""> -&gt; </span></span><span leaf="">模糊哈希字符串。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.684393063583815" data-type="png" data-w="865" data-imgfileid="100004576" src="https://wechat2rss.xlab.app/img-proxy/?k=fe94eedc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgicn2bsiah0LCst7tp48UmcDDsCTDbeeqibYPuLk6REqiaK3HK4kpXeYRTLdq0yWaeibqqj0DtaX7kSj7WkFKF7Vb9XUqb8txXGOMw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">例如</span><span lang="EN-US"><span leaf="">ZxShell Rootkit</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">x86</span></span><span leaf="">版与</span><span lang="EN-US"><span leaf="">x64</span></span><span leaf="">版的同一函数，相似度为</span><span lang="EN-US"><span leaf="">74%</span></span><span leaf="">。</span><span lang="EN-US"><span leaf="">Zubat</span></span><span leaf="">提取的是语义逻辑，所以可以跨架构进行匹配。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6416184971098265" data-type="png" data-w="865" data-imgfileid="100004577" src="https://wechat2rss.xlab.app/img-proxy/?k=59230603&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhRlQr76icFLwfOXXUF344diamLanw0eX3hiblA8RzKCmjWmiaY2VoHOLL6KJh0RL9QntzmfyibWpXPeUZV0256ScMwo7PNFhQiaeOBs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="bash"><code><span leaf="">- MCRIT (<a href="https://github.com/danielplohmann/mcrit" target="_blank">https://github.com/danielplohmann/mcrit</a> )</span></code><br/><code><span leaf="">- Ghidra Bsim (<a href="https://github.com/NationalSecurityAgency/ghidra/blob/master/GhidraDocs/GhidraClass/BSim/README.md" target="_blank">https://github.com/NationalSecurityAgency/ghidra/blob/master/GhidraDocs/GhidraClass/BSim/README.md</a> )</span></code><br/><code><span leaf="">- <a href="https://github.com/googleprojectzero/functionsimsearch" target="_blank">https://github.com/googleprojectzero/functionsimsearch</a></span></code><br/><code><span leaf="">- TLSH (<a href="https://documents.trendmicro.com/assets/wp/wplocality-sensitive-hash.pdf" target="_blank">https://documents.trendmicro.com/assets/wp/wplocality-sensitive-hash.pdf</a> )</span></code><br/><code><span leaf="">- Kesakode (<a href="https://doc.malcat.fr/analysis/kesakode.html)" target="_blank">https://doc.malcat.fr/analysis/kesakode.html)</a></span></code><br/></pre></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="" style="font-weight: bold;font-size: 12pt;font-family: 微软雅黑, sans-serif;">越南网瘾少年就不能进行网络攻击吗？</span></span><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">分析人员监控了作为</span><span lang="EN-US"><span leaf="">C&amp;C</span></span><span leaf="">信道的</span><span lang="EN-US"><span leaf="">Telegram</span></span><span leaf="">，其受害者位于中国台湾、中国香港、西班牙、斯洛文尼亚等地。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9664739884393063" data-type="png" data-w="865" data-imgfileid="100004578" src="https://wechat2rss.xlab.app/img-proxy/?k=db6bc4af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNia6q8iaRWcibOObY9vSIOZrqvhTBN6icW0keeEfYEoxxLLM68pUSeOFEhI8IY6XemYOHzkn1TqxGdckwf8FXscJKlcjDicImfqjU6s%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">全世界有近三千个受害者，中国台湾地区是受害者最多的地区，其次是韩国和印度。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.37341040462427744" data-type="png" data-w="865" data-imgfileid="100004579" src="https://wechat2rss.xlab.app/img-proxy/?k=845cfd43&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaMeqSBsJdW6G44aKHvqIzQianQfhPDKwE5D7cPYIhf5MbOKxqRyYibh1OUUMicFSIHVrSP6FIYFMjxeJkOFXdrxeD7TzKDic7doro%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通过其</span><span lang="EN-US"><span leaf="">Telegram</span></span><span leaf="">信息可以找到其</span><span lang="EN-US"><span leaf="">GitHub</span></span><span leaf="">账户，声称自己来自越南且正在学</span><span lang="EN-US"><span leaf="">C#</span></span><span leaf="">：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.44046242774566474" data-type="png" data-w="865" data-imgfileid="100004580" src="https://wechat2rss.xlab.app/img-proxy/?k=fe6e38c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhGC0GWiacTgYflnetRlfnN4Gz3Ysmic77qucPykVWlXiaavhiar2fOIgxSGiceXVJhpf4Pq1gm36qRDq0al71gW18vwN8oMg7WicEZM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在</span><span lang="EN-US"><span leaf="">VT</span></span><span leaf="">上可以找到一系列使用</span><span lang="EN-US"><span leaf="">Python</span></span><span leaf="">编写的恶意软件：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.43815028901734104" data-type="png" data-w="865" data-imgfileid="100004581" src="https://wechat2rss.xlab.app/img-proxy/?k=397339e6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgV88gwMuvDzS8qldATkmKr0McJ2ic6gfvxQoWG5QtNVtEia9Oh0iaXAIBobrwf1a8NOIISGHsSEjJtoLqv9FJhrswsQXpWrSR0JE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">攻击者在测试的时候，用自己的机器和越南的</span><span lang="EN-US"><span leaf="">VPS</span></span><span leaf="">测试了上线。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8242774566473988" data-type="png" data-w="865" data-imgfileid="100004582" src="https://wechat2rss.xlab.app/img-proxy/?k=6f732489&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgANxkwCMAQv8B2FIMd5e15E3hicAybw9FPSGYRcT8PL3lGnbTfB4tXG9lemumKDenj6rob59H0QSznZV9bsyibqefMEWDh0nO48%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">他自己的各种账号密码也都上传了上来，</span><span lang="EN-US"><span leaf="">tien</span></span><span leaf="">是越南很常见的名字，如果</span><span lang="EN-US"><span leaf="">2001</span></span><span leaf="">代表出生年份的话，该黑客年仅</span><span lang="EN-US"><span leaf="">24</span></span><span leaf="">岁。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.2867052023121388" data-type="png" data-w="865" data-imgfileid="100004583" src="https://wechat2rss.xlab.app/img-proxy/?k=332e23ce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjqOu9lWE9mvyGY4PAlpjbmz4etcbpV9rz4N2DTEiaeRC9BWR3Da0cTl1rYW2UYUbS2avGfByNcxQAezA3CGwkyTyq68rwiaPHO4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">攻击者的主机配置并不高：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7826589595375723" data-type="png" data-w="865" data-imgfileid="100004584" src="https://wechat2rss.xlab.app/img-proxy/?k=a2b3c348&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjeIH1ZUYzLYIraCIG3iboTpf473pN3Emwq5bibFMeYaBJ01VR08FsU0qWsGvDXKP4m2l3Tf09QHKcW6FxqWI67bftqictStIOXJM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">黑客的桌面显示黑客在玩英雄联盟：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5630057803468208" data-type="png" data-w="865" data-imgfileid="100004585" src="https://wechat2rss.xlab.app/img-proxy/?k=46dc4a34&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNia4xFQAHrDxZAibNQlCV1aWhvzpeqEkWD6h4MSLXOiaQdUf5grr5rPRvXAVskG52H1ic8FSH9kfpv81NJpcA8TAcnl4SrTxIdzuZo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">黑客不仅把自己的账号密码回传了，还把恶意软件的源代码一并回传了。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.553757225433526" data-type="png" data-w="865" data-imgfileid="100004586" src="https://wechat2rss.xlab.app/img-proxy/?k=c482cfec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgXe6L4sXCVaThqheblIRNQVrmBu8KWpAhHwLvhDIiafafXicqwh6QJ3QrUy3ubbjwaC0FD2zT2NquiboAXbg1vqyNhWIGopbbKcs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">剪贴板中新开发的恶意软件也一勺烩了：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6763005780346821" data-type="png" data-w="865" data-imgfileid="100004587" src="https://wechat2rss.xlab.app/img-proxy/?k=67e7c66f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhZQ9bfDA4TDPXXERO2IDI7lE7dN6yWgpDiasXhnLdQN8Kg2ymgrRqtv1CqDibF5nace1yQbx2AUqy1ILjTicAuAISQBryjBfSYtc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">百万级僵尸网络</span><span lang="EN-US"><span leaf="">Bigpanzi</span></span><span leaf="">背后的犯罪集团 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">该团伙最早可追溯到</span><span lang="EN-US"><span leaf="">2016</span></span><span leaf="">年，隐蔽性相当高所以到</span><span lang="EN-US"><span leaf="">2023</span></span><span leaf="">年才被发现。目标设备涵盖</span><span lang="EN-US"><span leaf=""> Android </span></span><span leaf="">机顶盒和</span><span lang="EN-US"><span leaf=""> eCos </span></span><span leaf="">卫星接收器（嵌入式实时操作系统），显示其跨平台开发能力。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Pandoraspear</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">和</span><span lang="EN-US"><span leaf=""> Pcdn </span></span><span leaf="">僵尸网络的日活</span><span lang="EN-US"><span leaf=""> IP </span></span><span leaf="">超过</span><span lang="EN-US"><span leaf="">80 </span></span><span leaf="">万，且 </span><span lang="EN-US"><span leaf="">86% </span></span><span leaf="">的受害者位于巴西。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3132947976878613" data-type="png" data-w="865" data-imgfileid="100004589" src="https://wechat2rss.xlab.app/img-proxy/?k=66385bab&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgCiciaVGs2TdkkHVL2vjKAs7PAatTlhavFD0zaYCfyFLFLnoLwibtpkMBucgHTKFrcGMJVHaPlg9wut2TsX8NACljYBt55ia1NFa4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Vold</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">僵尸网络峰值达到</span><span lang="EN-US"><span leaf=""> 169 </span></span><span leaf="">万，日活</span><span lang="EN-US"><span leaf=""> 90 </span></span><span leaf="">万。分布更全球化，巴西、印度、印尼是重灾区。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.31445086705202313" data-type="png" data-w="865" data-imgfileid="100004590" src="https://wechat2rss.xlab.app/img-proxy/?k=3b23c016&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgNKZthYialdYFjgjoEJrkLH4BWRFRfEYYrYB0NInPc71n9Y4b5jeuojcTiaqx9stP55MLo4o9fOnDWMWngMsyIFHficR26XshmoE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">最初的分析是从一个魔改版</span><span lang="EN-US"><span leaf=""> UPX </span></span><span leaf="">加壳样本开始的，该样本也是基于</span><span lang="EN-US"><span leaf="">Mirai</span></span><span leaf="">的源代码改的。发现是一个在巴西拥有</span><span lang="EN-US"><span leaf="">5w+</span></span><span leaf="">肉鸡的僵尸网络后，研究人员接管了</span><span lang="EN-US"><span leaf="">C2</span></span><span leaf="">服务器，攻击者开始疯狂报复</span><span lang="EN-US"><span leaf="">XLAB</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">Sinkhole</span></span><span leaf="">服务器。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.40346820809248557" data-type="png" data-w="865" data-imgfileid="100004591" src="https://wechat2rss.xlab.app/img-proxy/?k=0354c8ad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhdvsvhGGLuf7uNwWyecSajKZQSdfqRzTuliasGJBbRtvEobnkAGXAJhqx0DByic9Tib7vKTkRUhHFgcY5qgQZ9ib3mkkxia9hVf7hg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">另一个核心僵尸网络</span><span lang="EN-US"><span leaf="">Pandoraspear</span></span><span leaf="">在</span><span lang="EN-US"><span leaf="">2016</span></span><span leaf="">年到</span><span lang="EN-US"><span leaf="">2024</span></span><span leaf="">年间演化了</span><span lang="EN-US"><span leaf="">15</span></span><span leaf="">个版本，持续八年维护的恶意软件，其运营方一定有着稳定的盈利支撑。其作为</span><span lang="EN-US"><span leaf="">Loader</span></span><span leaf="">，具备三大核心功能：劫持</span><span lang="EN-US"><span leaf=""> Hosts</span></span><span leaf="">；启动</span><span lang="EN-US"><span leaf=""> Pcdn</span></span><span leaf="">；执行</span><span lang="EN-US"><span leaf=""> C2</span></span><span leaf="">命令。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">从远程服务器下载加密的</span><span lang="EN-US"><span leaf=""> hosts </span></span><span leaf="">文件并替换本地</span><span lang="EN-US"><span leaf=""> /etc/hosts</span></span><span leaf="">，在底层进行</span><span lang="EN-US"><span leaf=""> DNS </span></span><span leaf="">劫持。其加密算法“借用”了开源后门</span><span lang="EN-US"><span leaf=""> Lyceum </span></span><span leaf="">的代码。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.45895953757225433" data-type="png" data-w="865" data-imgfileid="100004592" src="https://wechat2rss.xlab.app/img-proxy/?k=3ddd6f21&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjnn8ZY99AC4iaKW3QVjqr0TBU6S1t1Efcz59ZNGKE7uKXCVVb15lLzTFu4UDyvdywQicZHY8JWC8mPwr65nFbPjIDCOflNAgzGA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">解密敏感字符串，生成</span><span lang="EN-US"><span leaf=""> shell </span></span><span leaf="">脚本来下载并运行</span><span lang="EN-US"><span leaf=""> pcdn.tar.gz</span></span><span leaf="">。其中包含大量工具，</span><span lang="EN-US"><span leaf="">evils</span></span><span leaf="">支持</span><span lang="EN-US"><span leaf="">RTMP</span></span><span leaf="">将设备转换为非法流媒体服务器、</span><span lang="EN-US"><span leaf="">kcp</span></span><span leaf="">与</span><span lang="EN-US"><span leaf="">ss</span></span><span leaf="">将设备转换为住宅代理节点。</span><span lang="EN-US"><span leaf="">Pcdn</span></span><span leaf="">不仅卖带宽，还兼职</span><span lang="EN-US"><span leaf=""> DDoS</span></span><span leaf="">，这是典型的“一鸡多吃”。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.446242774566474" data-type="png" data-w="865" data-imgfileid="100004593" src="https://wechat2rss.xlab.app/img-proxy/?k=f2fa2f3a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNia7yzF7tnPRangJe9T9WGaxjCuTaH5iby0vUW1YP7nN6CHQesJVoAatx2qumUWcl5pIptnogM50zn6rMZVriapiafz1TYxrBC4mKQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">启动后可以执行</span><span lang="EN-US"><span leaf="">C2</span></span><span leaf="">命令，收集设备的</span><span lang="EN-US"><span leaf="">MAC</span></span><span leaf="">和序列号。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6947976878612717" data-type="png" data-w="865" data-imgfileid="100004594" src="https://wechat2rss.xlab.app/img-proxy/?k=eea51858&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhldmBCeolQULKNxxIm1LYAr17GCQRib7Uib7fLkx0OyxkVxZMUFukJuXJ6PRW7QQ6Pn12buaicKXsDX5Lm9IaOc2anBn4G8NRBN0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">攻击者非常注重痕迹清理，下发了许多命令。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.608092485549133" data-type="png" data-w="865" data-imgfileid="100004595" src="https://wechat2rss.xlab.app/img-proxy/?k=3afcb70c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhYUAichEyjiahpE2prwRgDAskOrY42fmWmIXqbUVDhSNrWNgBN5cxgb8KBgOfoyo6gzS1mqdYOPrQLcV2GiaZyxAb5VyhChz6HCg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">该团伙在</span><span lang="EN-US"><span leaf=""> YouTube </span></span><span leaf="">上有“客户支持团队”频道，教用户如何升级系统。攻击者把传播恶意固件伪装成“售后服务”，利用用户的信任完成感染。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3838150289017341" data-type="png" data-w="865" data-imgfileid="100004596" src="https://wechat2rss.xlab.app/img-proxy/?k=b87302b9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgnzpialU2dDwq3oIxIzvdxesp3kAlcheUdJfbwia2LEC4WevbwG1NbHaxIarsckc6Cjw4ic9DL3Y09ib0af75cSSicWM8tZTdbgzxo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">当住宅代理变成</span><span lang="EN-US"><span leaf="">DDoS</span></span><span leaf="">僵尸网络 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">过去的</span><span lang="EN-US"><span leaf="">DDoS</span></span><span leaf="">时代是以</span><span lang="EN-US"><span leaf="">IoT</span></span><span leaf="">设备为主，百万级</span><span lang="EN-US"><span leaf="">Bot</span></span><span leaf="">对外发起超大规模流量的攻击。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8011560693641618" data-type="png" data-w="865" data-imgfileid="100004597" src="https://wechat2rss.xlab.app/img-proxy/?k=00df8845&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaZ1AwcPVLfHfNicqNkE99zM11hRj93KlFVI1d2EQZdvQqqzsJvH0zZYB66bE9SwhQB5vUbDzPE2K9KPK98ZtXZctKO1ibV6ezK0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">目前新兴的是大量住宅代理（</span><span lang="EN-US"><span leaf="">RESIP</span></span><span leaf="">，如</span><span lang="EN-US"><span leaf="">deepnode, rapidproxy, dataimpulse, ipcola, rayobyte, honeygain, packetstream</span></span><span leaf="">），不仅是爬虫公司在用住宅代理，恶意软件</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">僵尸网络也在使用。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8" data-type="png" data-w="865" data-imgfileid="100004598" src="https://wechat2rss.xlab.app/img-proxy/?k=2e4619c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaCtwmzficluVPEpzWV5s2YZ8piaqXYUK6rfYkdBPCQic8uKen1Heyn1RRAJMMkic1Yn3otXKateV2zVB79GWoCqbNzcv21hibnibpOk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">IoT</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">设备可以通过主动扫描发现，但代理节点很难。</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">公司为了抓取网页数据，大量投入资金购买代理服务。</span><span lang="EN-US"><span leaf="">IoT</span></span><span leaf="">设备可能只在百万级，但住宅代理可以上升到千万级甚至是亿级。</span><span lang="EN-US"><span leaf="">AI </span></span><span leaf="">训练对数据的渴求，间接养肥了卖住宅代理的灰产，而攻击者顺便搭了便车，用这些基建来搞</span><span lang="EN-US"><span leaf="">DDoS</span></span><span leaf="">。</span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">深入剖析</span><span lang="EN-US"><span leaf="">SideCopy</span></span><span leaf="">与</span><span lang="EN-US"><span leaf="">APT 36(Transparent Tribe)</span></span><span leaf="">间的关系 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">SideCopy</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">最初模仿</span><span lang="EN-US"><span leaf="">SideWinder</span></span><span leaf="">，后来已经成功“出师”。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.37803468208092483" data-type="png" data-w="865" data-imgfileid="100004599" src="https://wechat2rss.xlab.app/img-proxy/?k=3ad54417&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgJWAVJtOibrp4Co36X4K2LoPicFB8mibmrrRqu92S5jWIxbwD7jA12MKbHNIbZX1JLluibVcENQHQYqkRZaAHPRWAudywASwicxbfw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">二者代码高度相似：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5283236994219653" data-type="png" data-w="865" data-imgfileid="100004600" src="https://wechat2rss.xlab.app/img-proxy/?k=a0d6f812&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNh0EOsyv2dE57SSgyzZDYVeIwBjyaGha9A3eENTSIfGIsuVtmu6aibBjnkk9rjk8iacjLtqFkYPQ4xpG2NHzOFcaWjOMFPCSkiaN0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通过</span><span lang="EN-US"><span leaf=""> Bindiff </span></span><span leaf="">对比，发现核心功能模块（如</span><span lang="EN-US"><span leaf=""> thumb </span></span><span leaf="">截屏</span><span lang="EN-US"><span leaf="">, file </span></span><span leaf="">文件管理）的相似度极高（</span><span lang="EN-US"><span leaf="">89% - 100%</span></span><span leaf="">）。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.48323699421965316" data-type="png" data-w="865" data-imgfileid="100004601" src="https://wechat2rss.xlab.app/img-proxy/?k=c57eca57&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhaFDAhjib1j8eN0R3Vc4IacAcgV0e9RPn0Nj0RNxMsFjbpw0nqJcHVcZ0Wu6UQTYXiagMn708mak7PAlTomNbs9skdHpg9MZvR0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">由于其操作失误，对外暴露了开放目录泄露了全部攻击工具：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.623121387283237" data-type="png" data-w="865" data-imgfileid="100004602" src="https://wechat2rss.xlab.app/img-proxy/?k=cc46b249&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjvJOfmF2BDuqOLLsqehUD1A0kwMgMEAKRth5cC2hxiaGIpWIZPP7UKsiaTnhCIzFj5icIaeWC7icdjbLThz8gm47n089xCtPqLoWQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">有些与巴基斯坦关联的证据，例如</span><span lang="EN-US"><span leaf="">HTA Stager </span></span><span leaf="">在巴基斯坦</span><span lang="EN-US"><span leaf=""> IP </span></span><span leaf="">上进行了测试，泄露的信息中是巴基斯坦常用语言而且包含了一句乌尔都语</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">旁遮普语的调试信息。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3942196531791908" data-type="png" data-w="865" data-imgfileid="100004603" src="https://wechat2rss.xlab.app/img-proxy/?k=2a032e90&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaq0VqKV45Du5UJR1icFb8jBmK6ap1XgBjYxzAicdzvdvCRb74icfDLB7yvNvicMerpw9BbsTRs00FGvPjTnUbbmXzUWjyxqlIrC54%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">关联关系的总结：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7942196531791907" data-type="png" data-w="865" data-imgfileid="100004604" src="https://wechat2rss.xlab.app/img-proxy/?k=d6641d37&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjxyXkcB5sHZEKnDw7yySfF6d9sbNINHQTOVQPsTHFesJiaftiaCkpgtmibYXJ4n7q9FRQ7VPE8TTeQn6CR7qAE4qoIbicSdnFWEv4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">为远控木马打造一个可长期观测的执行环境 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">传统的沙盒通常只运行几分钟，根本抓不到黑客在</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">后渗透阶段</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的人工操作行为。所以设计了名为</span><span lang="EN-US"><span leaf="">STARDUST</span></span><span leaf="">的平台，这其实就是高交互蜜罐的终极版，虚拟出一个完整的公司的网络（</span><span lang="EN-US"><span leaf="">DMZ</span></span><span leaf="">区、内网区、客户端区、</span><span lang="EN-US"><span leaf="">AD</span></span><span leaf="">域控等）。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5479768786127167" data-type="png" data-w="865" data-imgfileid="100004605" src="https://wechat2rss.xlab.app/img-proxy/?k=96835d02&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgLbM5hicev4XyVm72SehBAAnO2GEo9nHHpn9GbWaqHkGzmZU7IzEIyzBqJoUG7JqiaUw4VDnOqDGLvgSE70qAJGwhasUYMJtQow%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">其基本架构如下所示：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.43583815028901735" data-type="png" data-w="865" data-imgfileid="100004606" src="https://wechat2rss.xlab.app/img-proxy/?k=79fcc46b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjDItxeRib749TibqcOSleDcCrwH3gTEnuMeEquPOZyBylw9kHOIzHEZicvxxyibm7eQQO3iafZFicEkWpAQuDhpFUp8dVyG4wTnlJms%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">选取了</span><span lang="EN-US"><span leaf="">7</span></span><span leaf="">个家族的</span><span lang="EN-US"><span leaf="">41</span></span><span leaf="">个</span><span lang="EN-US"><span leaf="">RAT</span></span><span leaf="">样本，其中由</span><span lang="EN-US"><span leaf="">9</span></span><span leaf="">个</span><span lang="EN-US"><span leaf="">AsyncRAT</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">2</span></span><span leaf="">个</span><span lang="EN-US"><span leaf="">DCRat</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">4</span></span><span leaf="">个</span><span lang="EN-US"><span leaf="">Gh0stRAT</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">1</span></span><span leaf="">个</span><span lang="EN-US"><span leaf="">njRAT</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">4</span></span><span leaf="">个</span><span lang="EN-US"><span leaf="">QuasarRAT</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">19</span></span><span leaf="">个</span><span lang="EN-US"><span leaf="">RemcosRAT</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">2</span></span><span leaf="">个</span><span lang="EN-US"><span leaf="">StrRat</span></span><span leaf="">。最终发现只有</span><span lang="EN-US"><span leaf="">14</span></span><span leaf="">个样本成功连接了</span><span lang="EN-US"><span leaf="">C&amp;C</span></span><span leaf="">服务器，这其中</span><span lang="EN-US"><span leaf="">10</span></span><span leaf="">个存在后渗透行为。连接</span><span lang="EN-US"><span leaf="">C&amp;C</span></span><span leaf="">服务器的时间最短</span><span lang="EN-US"><span leaf="">3</span></span><span leaf="">小时，最长</span><span lang="EN-US"><span leaf="">35</span></span><span leaf="">天。潜伏时间最短</span><span lang="EN-US"><span leaf="">1</span></span><span leaf="">分钟，最长</span><span lang="EN-US"><span leaf="">25</span></span><span leaf="">小时。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5664739884393064" data-type="png" data-w="865" data-imgfileid="100004607" src="https://wechat2rss.xlab.app/img-proxy/?k=0715eaf9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgc8ymDPyccXZS4j2uqKeia6tvsNFSpZFfZrg0Zk5jFTPUspYicZic8yHWqrzCC0lDzWzoM1ibyRm8P5ribkgIpTicd7gbUXu22CdGXM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.47167630057803467" data-type="png" data-w="865" data-imgfileid="100004608" src="https://wechat2rss.xlab.app/img-proxy/?k=d702fca4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhCFEkQia2LZntaEqk7thhvzyhxIEEOsqgWwYBAwPek5Ip4QicPTjGKYdw5nyW29oe8PBxUmlgmoaY44IjnuG2WnLy6ibs4jBaf7w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">曾经的王者</span><span lang="EN-US"><span leaf="">GorillaBot </span></span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">GorillaBot</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在</span><span lang="EN-US"><span leaf="">Mirai</span></span><span leaf="">的基础上增加了一层应用层的握手认证，有内置密钥</span><span lang="EN-US"><span leaf="">K</span></span><span leaf="">的样本才能通过认证。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5167630057803468" data-type="png" data-w="865" data-imgfileid="100004609" src="https://wechat2rss.xlab.app/img-proxy/?k=72fb5503&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNg4ibricx4M37Q08XJLHOhp1J9ibMk8tWOBB0MO3U03YIWS7Iahia03Q84eLibKhYRiaaAric2KyNLTaIibXzQ5CcKITjEZ1ktYIzfjP64%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">搞清楚</span><span lang="EN-US"><span leaf="">C&amp;C</span></span><span leaf="">的原理后，编写了一个脚本来与</span><span lang="EN-US"><span leaf="">C&amp;C</span></span><span leaf="">服务器持续保持通信。从而跟踪僵尸网络的演变：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6023121387283237" data-type="png" data-w="865" data-imgfileid="100004610" src="https://wechat2rss.xlab.app/img-proxy/?k=21477cb3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaMBQxJ3OIEnReEAbcCHrN6X0qSHquibdgEGIEgq7ExTLgzkmXibFOia1zc24tdK3mMZHPxszGQicZKbC25wm1OOWKU8eAGEoMIibicM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">几个月内下发了</span><span lang="EN-US"><span leaf="">150</span></span><span leaf="">万条攻击指令，攻击了</span><span lang="EN-US"><span leaf="">12.1</span></span><span leaf="">万个目标。使用最多的是</span><span lang="EN-US"><span leaf="">UDP</span></span><span leaf="">洪水：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.47861271676300576" data-type="png" data-w="865" data-imgfileid="100004611" src="https://wechat2rss.xlab.app/img-proxy/?k=5e944714&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNia82CA2khQHFbHd6oxTDabzkSnt87PQNOk6icTAJrGLtJadBI2ibV9nJwOBwCZ6CS9ed2UvwQnzOXQ4d8gJkmgz6tiaEoTUnIl6LU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">攻击者将</span><span lang="EN-US"><span leaf="">DDoS</span></span><span leaf="">能力对外售卖，价格又很低廉：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5699421965317919" data-type="png" data-w="865" data-imgfileid="100004612" src="https://wechat2rss.xlab.app/img-proxy/?k=ddd8d72c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgMT02CJ6ibuJG0ONRh29G3gkhh5oqvMiaLYQweaxDr9Qn3sNFh4CeZXia8gJfsFg9vmy50L8plbHC3qstW44q5toIqiasbYbGibos0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">其实该僵尸网络的规模并不大，只有几千个肉鸡。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5687861271676301" data-type="png" data-w="865" data-imgfileid="100004613" src="https://wechat2rss.xlab.app/img-proxy/?k=f748838e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNj8CIic9e1LdHe2shLbjCWicvelfCGiaS5YJfskuXhSNVib3U8N6CfZMNXPJbB0dWQqJw3L4HvVvd2oLVcfFU8KjsDdaQAcOSSupgI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">DVR</span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">生态系统与</span><span lang="EN-US"><span leaf="">IoT</span></span><span leaf="">僵尸网络</span><span lang="EN-US"><span leaf="">RapperBot </span></span></span></b><b><span lang="EN-US" style="font-size:
12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">其构造的扫描包存在特定特征：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.26473988439306356" data-type="png" data-w="865" data-imgfileid="100004614" src="https://wechat2rss.xlab.app/img-proxy/?k=3accd7e2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgoXyjXmLHNfmORVTI0MThQ5XKqGFtPwWia6tcD04F4AGMKbMswQULHMmuw5FIeriaINS3nv2eSZo1Epibiaicy8tLXZiaicrQPXHyxTE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2024</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">年开始</span><span lang="EN-US"><span leaf="">RapperBot</span></span><span leaf="">开始转向</span><span lang="EN-US"><span leaf="">DVR</span></span><span leaf="">设备：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4092485549132948" data-type="png" data-w="865" data-imgfileid="100004615" src="https://wechat2rss.xlab.app/img-proxy/?k=45976264&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhwbkyribCgxlxdqFTrTzWU4LiaAxtHage9ay3UDnlUABfNnhY25GuVlg3yOJWuyAUiaUIicwu88JqZU9y6iaYSuoknicibh1WbiatDZZU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">回扫发现</span><span lang="EN-US"><span leaf="">70%</span></span><span leaf="">都是</span><span lang="EN-US"><span leaf="">DVR</span></span><span leaf="">设备，其中</span><span lang="EN-US"><span leaf="">63%</span></span><span leaf="">都是</span><span lang="EN-US"><span leaf="">HITRON DVR</span></span><span leaf="">。弱口令是常见的攻击向量：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3976878612716763" data-type="png" data-w="865" data-imgfileid="100004616" src="https://wechat2rss.xlab.app/img-proxy/?k=0847daa6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiaic8DUO5VLEt4iaNDFwtUUMJQib43ERFopuCblR3iaNYiaX6r1536wBXWVWgxSgibjF4eS9X6KAh3xGjCiazB719VYNX7zZA762zs230%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">与</span><span lang="EN-US"><span leaf="">Mirai</span></span><span leaf="">原版的比较：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3699421965317919" data-type="png" data-w="865" data-imgfileid="100004617" src="https://wechat2rss.xlab.app/img-proxy/?k=f058afbf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjFARlp3xPxVTibGkfgcicdGkQChAvHeIxtnRkicZvtSVl8wRI0ibWK3ZVmiaGRVpdM8ekRR3Mtf6wGuhvj66XcOAaxXQsVdsPNhHOU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">整体感染架构如下所示：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.48554913294797686" data-type="png" data-w="865" data-imgfileid="100004618" src="https://wechat2rss.xlab.app/img-proxy/?k=9bd0843a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiakHMvhUI1EngC3z8PqnqZVicywjUQVHQboTju2ATsu9kG7LuwvmzI9IY5NibdFJck8k2AqicZ0CgBJUMv2gduZNfyELiaD5rOFtfs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">多个变种演化情况：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.44046242774566474" data-type="png" data-w="865" data-imgfileid="100004619" src="https://wechat2rss.xlab.app/img-proxy/?k=8489f085&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgFjvIzqYq5ofPUQzhqoxiaVDhJcw56us3rwNBU0qAposIZc2AzZuYo3TV2xfxq8Hcvib0gmFyJd4xoyDBys8SgAOxiczKniaL5gY8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">该僵尸网络集中火力攻击中国：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6092485549132948" data-type="png" data-w="865" data-imgfileid="100004620" src="https://wechat2rss.xlab.app/img-proxy/?k=8ed7ea74&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgE5eZsxrZXlZa9P4FWIsCUqJwK7UXibiblBh0ViafVkicWMSG3LVD564VRHSZdhjVF3hZB1BRsSbibM4UaeEibBOSicuRLOeia5ZXMib30%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">也是它造成了</span><span lang="EN-US"><span leaf="">Twitter</span></span><span leaf="">的宕机：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3375722543352601" data-type="png" data-w="865" data-imgfileid="100004621" src="https://wechat2rss.xlab.app/img-proxy/?k=9fdcb514&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhzkLvzaRIiaeDibvxluFNaibfIQjGbPQgxrbTgLG7uVMPzjTwSiaTMhjUecKUDOqn0NibgiaKzhrswb5YzLCbGztExuAoPq495ickWSY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">钓鱼套件</span><span lang="EN-US"><span leaf="">Yara</span></span><span leaf="">规则库 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">PhishingKit-Yara-Rules</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">从</span><span lang="EN-US"><span leaf="">2019</span></span><span leaf="">年开始收集专门检测钓鱼套件压缩包的</span><span lang="EN-US"><span leaf="">Yara</span></span><span leaf="">规则，目前已经有</span><span lang="EN-US"><span leaf="">834</span></span><span leaf="">条</span><span lang="EN-US"><span leaf="">Yara</span></span><span leaf="">规则。配置文件中包含</span><span lang="EN-US"><span leaf="">Telgram</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">Token</span></span><span leaf="">或者邮箱等攻击者相关信息：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5595375722543353" data-type="png" data-w="865" data-imgfileid="100004622" src="https://wechat2rss.xlab.app/img-proxy/?k=f1b15c0e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgyJYiaKuWzm9PVkfrl4aRW1IWIWLfsiboiccoG0u317Q1gkRInFrp6jc8jRWI10CNqdBxNNtrhIkVkMgnbtDqCtpp5PHO3yEnQ4Y%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">即便是很明显的钓鱼套件，杀软检出率也并不高：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4658959537572254" data-type="png" data-w="865" data-imgfileid="100004623" src="https://wechat2rss.xlab.app/img-proxy/?k=96f76aba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgNZ3EvQnDnucnzia5Ftt9icGuCpiaPXqUoibWXJfORbTPpUictLkZ3reqD509FOraN5BEDPVHTfEy1r0iazr1df1pcm9CU6oOTRcQgA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">这些</span><span lang="EN-US"><span leaf="">Yara</span></span><span leaf="">规则不与混淆后的代码纠缠，而是着眼于目录结构，这使得可以检出那些杀软无法检出的恶意样本。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6323699421965318" data-type="png" data-w="865" data-imgfileid="100004624" src="https://wechat2rss.xlab.app/img-proxy/?k=8518237d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgHGhWkrEZcIKQ52DmzXiaZIWG864sJXsc7lQMjmhff5xibDt39BAznmW2nvjHWZzDgqH6CiaWkvenCB1TyPIdEic1c7rsXugoSWt0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">MintsLoader </span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">的混淆措施</span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">MintsLoader</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">是一个投递</span><span lang="EN-US"><span leaf="">AsyncRAT</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Vidar</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">SocGholish</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">StealC</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">Loader</span></span><span leaf="">，使用</span><span lang="EN-US"><span leaf="">JavaScript</span></span><span leaf="">与</span><span lang="EN-US"><span leaf="">PowerShell</span></span><span leaf="">编写。其域名解析从</span><span lang="EN-US"><span leaf=""> BL Networks </span></span><span leaf="">转移到了</span><span lang="EN-US"><span leaf=""> Stark Industry</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">BPH</span></span><span leaf="">），攻击链如下所示：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4913294797687861" data-type="png" data-w="865" data-imgfileid="100004625" src="https://wechat2rss.xlab.app/img-proxy/?k=17366b4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhARwzHl4vibnrFBR8OSJr7T1UTibCxGBHicia2slCO1RCazppia7gUaEdZ3tpCJxI6Vq7ian6Vm8gaUv1mZNMlG0or4hsPREaURXQhc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通常混淆代码都是混淆成随机字符，但</span><span lang="EN-US"><span leaf="">MintsLoader</span></span><span leaf="">混淆成了一堆莫名其妙的单词。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3745664739884393" data-type="png" data-w="865" data-imgfileid="100004626" src="https://wechat2rss.xlab.app/img-proxy/?k=413a5893&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiafrJAtZmjfBf6HxlZyGpcnqiam6tF3oHmOLA4rt35EmqYahMLR6hAc6Jib53xEffzbtytbciaONGawFG3OAaSKf0Vv27KnYXTyHI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">其实是攻击者将名为《</span><span lang="EN-US"><span leaf="">Andrew Melville</span></span><span leaf="">》的书当成了字典表，但这本书太冷门、特征太明显。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.7667071688942892" data-type="png" data-w="823" data-imgfileid="100004627" src="https://wechat2rss.xlab.app/img-proxy/?k=691d90cf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjzIaVJsPQdiajoDygAnZhFcuwSP9rt6CnRicMy8ZZIfiaHGHaYL7EWydd9o6vgNuPmuvOGwib6GOib1jiaTnrPCD9IRNvfJb7a5jDl4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">基于这个特征，可以很容易地在</span><span lang="EN-US"><span leaf="">VT</span></span><span leaf="">上把相关样本全都拉出来。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.47861271676300576" data-type="png" data-w="865" data-imgfileid="100004628" src="https://wechat2rss.xlab.app/img-proxy/?k=9771f34a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgQicXJ6RIXymlMIicCnqMZ2vN4ibaoVrpbCBEXyzZtKG8VSgYbzib9Zy98UL3xzT8w5bhz39aT5Tx0iaprmQfmm72aJtxnnFRBJOLQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">其所使用的</span><span lang="EN-US"><span leaf="">IP</span></span><span leaf="">归属于</span><span lang="EN-US"><span leaf="">STARK-INDUSTRIES</span></span><span leaf="">，这是一个经常被黑产利用的防弹主机服务商。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7606936416184971" data-type="png" data-w="865" data-imgfileid="100004629" src="https://wechat2rss.xlab.app/img-proxy/?k=9243dd6f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNia8xyLicUIe1oaPicRg35A6G12Qu2dRaG6MALHytdJywAqTmx9xevZZmINehmPJclNuNAIuvwfHKHcWuBjVYUsibro4nMJQdkfdos%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">SandiFlux</span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">的</span><span lang="EN-US"><span leaf="">FastFlux</span></span><span leaf="">基础设施</span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">SandiFlux</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">曾经是一个非常著名的</span><span lang="EN-US"><span leaf="">FastFlux</span></span><span leaf="">服务提供商，其</span><span lang="EN-US"><span leaf="">Double Fast Flux</span></span><span leaf="">架构中的域名有多个</span><span lang="EN-US"><span leaf="">A</span></span><span leaf="">记录且</span><span lang="EN-US"><span leaf="">TTL</span></span><span leaf="">很小，并且</span><span lang="EN-US"><span leaf="">Nameserver</span></span><span leaf="">也有多个</span><span lang="EN-US"><span leaf="">A</span></span><span leaf="">记录且</span><span lang="EN-US"><span leaf="">TTL</span></span><span leaf="">很小。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.36184971098265895" data-type="png" data-w="865" data-imgfileid="100004630" src="https://wechat2rss.xlab.app/img-proxy/?k=f531cc4c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjXibXmLTIBjOrhTXxSDwKPhplAj4aGPMfUaoRHrSia2BujQDNtFUaOLedP3K4zlXHL6WgD3QoONjFkgwmSIiaTyna7cvF2CtZKWg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2024</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">年作为基础设施运营 </span><span lang="EN-US"><span leaf="">42 </span></span><span leaf="">个</span><span lang="EN-US"><span leaf="">NameServer</span></span><span leaf="">与</span><span lang="EN-US"><span leaf="">2900+</span></span><span leaf="">个</span><span lang="EN-US"><span leaf="">IP</span></span><span leaf="">为</span><span lang="EN-US"><span leaf="">193</span></span><span leaf="">个域名提供服务。与多个窃密木马</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">僵尸网络有关，如</span><span lang="EN-US"><span leaf="">SmokeLoader, Amadey, LummaC2</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5271676300578034" data-type="png" data-w="865" data-imgfileid="100004631" src="https://wechat2rss.xlab.app/img-proxy/?k=0912d5cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhesic62PbjIfCD8x4G6wBnBtbZmY4w5Sf5wuGPU5tQwVibT7CB2Km6SWjsibPIUDB1uJn0ibicKyibEsM3cypSR9esjibo2ay6VSuGtU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">此前其主要使用东欧的</span><span lang="EN-US"><span leaf="">IP</span></span><span leaf="">，现在则主要集中在美洲。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3976878612716763" data-type="png" data-w="865" data-imgfileid="100004632" src="https://wechat2rss.xlab.app/img-proxy/?k=2e1afd38&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgOicVymVcW4LshkazvZaYlzbicJicKGpV4fHhZ7fJoM6E6cEB76Ga0btvkfRcXtGL77Ef8aqUTSsNwkD3LPauu57YucnYAic0oh4Y%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">DBatLoader</span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在沙盒中的逃逸技术分析 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通常我们认为恶意软件会小心翼翼地检查执行环境，如果可能有问题就退出不执行，但</span><span lang="EN-US"><span leaf=""> DBatLoader </span></span><span leaf="">这个家族却反其道而行之。不仅不退出，还要把沙盒搞崩，或者通过制造大量的错误日志来淹没分析人员。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.24508670520231213" data-type="png" data-w="865" data-imgfileid="100004633" src="https://wechat2rss.xlab.app/img-proxy/?k=d2229dcb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjVWJdwW9mq5LRwyAJ2PYic5DsicU5TCsfly8LTHsB0pBqRicyFcqeWy4VLb11SIrT8GymXRgA2icIApRrkiapibDSE3rXLHkpEJhwf0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">第一招是内存轰炸，一口气申请比大多数沙盒配置都要大的内存，触发内存不足错误。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3086705202312139" data-type="png" data-w="865" data-imgfileid="100004634" src="https://wechat2rss.xlab.app/img-proxy/?k=960eb26c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhDryyHneRUh0xCibkL8zzp8f61pSOR95wU8kwtuZCL7419CyxOeaPRde5zfBa3jEczpRAPfdwPibYNssmDWLGopxXNI1pXDFP5o%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">第二招是内存保护，尝试修改随机地址的权限。有些沙盒会</span><span lang="EN-US"><span leaf="">Hook</span></span><span leaf="">内存保护函数，正常内核返回特定错误码但沙盒可能会返回不同的情况，从而暴露沙盒。即便不暴露，也可以触发大量的错误日志淹没行为数据。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3040462427745665" data-type="png" data-w="865" data-imgfileid="100004635" src="https://wechat2rss.xlab.app/img-proxy/?k=12d1ad93&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiafAZYDsrYGPVBB5w2uBN90wozbfkjdjcG7G1Z7WQ1Rl80Iq97iaD7TVAIglv0NO5euYke1NzS279xUVumt8JqmbKG7sDGV5BBM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">第三招是进程注入，不管有没有权限直接写，写完还尝试释放根本没有权限的内存。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1907514450867052" data-type="png" data-w="865" data-imgfileid="100004636" src="https://wechat2rss.xlab.app/img-proxy/?k=bba2582d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhNGIzQRsx2OWm9H298rmtzSsHrichc19eyPibhthicHonOyRYX0KDlwQFZYkKWyXpgXCN8Em25AN8SibOmxCic32jWlBOGr4jstpzk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">第四招是</span><span lang="EN-US"><span leaf="">AMSI</span></span><span leaf="">修补，恶意软件通常会通过修改内存来禁用</span><span lang="EN-US"><span leaf=""> AMSI</span></span><span leaf="">，但</span><span lang="EN-US"><span leaf="">DBatLoader</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">Patch</span></span><span leaf="">机制有缺陷写错了地址。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.41040462427745666" data-type="png" data-w="865" data-imgfileid="100004637" src="https://wechat2rss.xlab.app/img-proxy/?k=af1b19bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgNbtLC2HKbyg1PdhV38jVXSibdtPA6HGniceqFt0AJeyOKmAx78BvA3c7lCJ6c6WEtjnNZ445LICAFgtlWDc5kPa6rVcGUYLm8Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">被强化的威胁情报 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Harbinger</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">是一套自动化对大量文件进行归因与狩猎的框架，其核心为沙盒</span><span lang="EN-US"><span leaf="">+</span></span><span leaf="">规则引擎</span><span lang="EN-US"><span leaf="">+</span></span><span leaf="">特征库。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2184971098265896" data-type="png" data-w="865" data-imgfileid="100004638" src="https://wechat2rss.xlab.app/img-proxy/?k=7fe0b44b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgUQh16y3ib5GRzONprShxD3xXKdqJVor6yBUuI33AQYz3RIPewLh6OIYFbmJQQllMxEEvnPWA0y74rsVzeAcmGAjPEJTsPwb7s%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">沙盒是基于</span><span lang="EN-US"><span leaf="">CapeMon</span></span><span leaf="">开发的通用脱壳工具与内存扫描工具，基于</span><span lang="EN-US"><span leaf="">C</span></span><span leaf="">语言开发了检测引擎。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.423121387283237" data-type="png" data-w="865" data-imgfileid="100004639" src="https://wechat2rss.xlab.app/img-proxy/?k=6bc89031&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaO1TG3fVRrfdChWT0qN6NqWrok2PCBgBqW26ibM8iaYVxTjiaiasZExKiaIicS1JNBKjWwSyroibLmGjhQLqnGV5WQHK2ZcxTSEodiczw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">用</span><span lang="EN-US"><span leaf="">C</span></span><span leaf="">写的</span><span lang="EN-US"><span leaf="">CVE-2022-37969</span></span><span leaf="">检测规则：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.41040462427745666" data-type="png" data-w="865" data-imgfileid="100004640" src="https://wechat2rss.xlab.app/img-proxy/?k=3f551332&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhIibHPo00icZBicQbnqJyawpq4zDzjjJMIsco6ic0Q11NXC30YzdgZR97Tlw0ERxlSXwjGvCoGNARHhH1YianAicOpFwS0nkb4ltJpI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">大规模运行的闭环工作流：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4647398843930636" data-type="png" data-w="865" data-imgfileid="100004641" src="https://wechat2rss.xlab.app/img-proxy/?k=25d2a1b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNj7Is6lVqIM5O9fD40bfZTlTo7wA8eb7u0icibp3VtHeDlDVacZWZ1VbYcZu2AxoYicjL2L5f6o1rfymnIKMP3D06f8RXib3l4FVdc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2728323699421965" data-type="png" data-w="865" data-imgfileid="100004642" src="https://wechat2rss.xlab.app/img-proxy/?k=1a3fea5e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhPbwObwtq46qH9lsgC2RLTGUWuXzfWyvAuHMeWeBsDibBlUdKf44ATwp3ib2RUOVdg8w0ibiane1ylzOzeGvxGMED4KYqgc6xUVgA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.49017341040462425" data-type="png" data-w="865" data-imgfileid="100004643" src="https://wechat2rss.xlab.app/img-proxy/?k=5f0c9613&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhWzTF7zlzGQSvBakniabCJUFJNeYLbg5ypYN2RiaeIG8g86sgvE8ibh0N0ZicibRGm1fD8jsQxX4UfNMicrUzF8FTQAHgCSbqVwUxV8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">从</span><span lang="EN-US"><span leaf=""> LukaLocker </span></span><span leaf="">到</span><span lang="EN-US"><span leaf=""> Nitrogen </span></span></span></b><b><span lang="EN-US" style="font-size:
12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">法国</span><span lang="EN-US"><span leaf=""> IT </span></span><span leaf="">媒体</span><span lang="EN-US"><span leaf=""> LeMagIT </span></span><span leaf="">的主编</span><span lang="EN-US"><span leaf="">Valery Marchive </span></span><span leaf="">寻找四个勒索软件相关样本之间的关联关系：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8543352601156069" data-type="png" data-w="865" data-imgfileid="100004644" src="https://wechat2rss.xlab.app/img-proxy/?k=59228bc4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNjD1bxcjlej8cZBiaboQkLAPlLAX5cuLZAedarh7icmdwZIMaRJg7legS7rkufIiav5ABsG6nSQtnDUx9k89FNAO6t5grStfoibuVA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">可以看到</span><span lang="EN-US"><span leaf="">Cactus, LukaLocker </span></span><span leaf="">和</span><span lang="EN-US"><span leaf=""> Nitrogen </span></span><span leaf="">似乎共享了一些代码：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.47861271676300576" data-type="png" data-w="865" data-imgfileid="100004645" src="https://wechat2rss.xlab.app/img-proxy/?k=4f763d04&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhEx93n0HcFH3ROGYwwomAuiaN5X1qMia3cu6iaZzI3XmTvldGibibqarm31jgP9GmTb3M4u0590MdxesfzgFf5B22hic6ypQo7I9yLA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通过逆向分析可以在多处确认</span><span lang="EN-US"><span leaf="">LukaLocker </span></span><span leaf="">和</span><span lang="EN-US"><span leaf=""> Nitrogen </span></span><span leaf="">至少是变种关系，二者很可能由同一组织</span><span lang="EN-US"><span leaf="">Volcano Demon</span></span><span leaf="">在运营。</span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">越南黑客的崛起 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">前面一大堆讲具体攻击技术的不在此处复述了，思科的博客都披露的很详细了。只摘录最后一部分归因的。代码和</span><span lang="EN-US"><span leaf="">PDB</span></span><span leaf="">路径中有大量的越南语：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4578034682080925" data-type="png" data-w="865" data-imgfileid="100004646" src="https://wechat2rss.xlab.app/img-proxy/?k=fb212901&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNggWBApp0odpia3qmL4hTd4HznBOUfmRUmLGgCiayOJ6MntxVDmXMIGlVddQ8GFRD9oaabncaTT0enicnqNKYiaibChibr3mx08qiaDTY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">钓鱼网站使用的图片，是从越南图片素材网下载的图片：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6265895953757226" data-type="png" data-w="865" data-imgfileid="100004647" src="https://wechat2rss.xlab.app/img-proxy/?k=353775d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiaenUy9w0BorgIKnBunbtwypJsJPkYuNFWpWgVka19jl5SU8PvkqvI7uddTObEoDcEzN1hEJF0Xeqpr3YIj9W6N04TCymRFFCc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">攻击者把自己的信息也发到了</span><span lang="EN-US"><span leaf="">Telegram</span></span><span leaf="">中，其</span><span lang="EN-US"><span leaf="">IP</span></span><span leaf="">是越南的</span><span lang="EN-US"><span leaf="">IP</span></span><span leaf="">：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004648" data-ratio="0.36878612716763004" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=25a53e39&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNia4XYYxmv38McUc6kFF3r0kZHx1PicjGeSd0q0dReiaqqpSfWDoQSRoKywJU1yhSA3IXBCPw5on3M1Gt744ibZt3Xe4SIknghFRTE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">其电脑截屏上文件夹的名字为越南语，并且使用越南流行的</span><span lang="EN-US"><span leaf="">Unikey</span></span><span leaf="">输入法与</span><span lang="EN-US"><span leaf="">Zalo</span></span><span leaf="">聊天软件。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004649" data-ratio="0.4624277456647399" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=22ee9db1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhiaQXU2PFHaszVkUdPo6WSqFzrrM4ujSTmOXRpWSibZyPsbnvtiak8paL6913QLTeKa6YsWKUFOvytyt9ms65BgdpzD6TwKkX1sI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">截图中还暴露了员工工资、购买流量的成本、购买</span><span lang="EN-US"><span leaf="">PayPal</span></span><span leaf="">账号的渠道等，这说明其是公司化运营的犯罪团伙。</span></span></p><p style="text-align: center;"><span style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgba(0, 0, 0, 0.9);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 12pt;font-family: 微软雅黑, sans-serif;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5583815028901734" data-type="png" data-w="865" data-imgfileid="100004650" src="https://wechat2rss.xlab.app/img-proxy/?k=1b8b16a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgsiauibLdvOr4aViaNooLOS4ADDDfxD7T2iagnhVQqr3jTvad0xXNKGCFrd1Riacxr5WibltugzOu124PPCNlR6gfGhcMXQbiasIktYA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://www.botconf.eu/past-editions/botconf-2025/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=518e9d7a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488299%26idx%3D1%26sn%3Dd2c79447312c2e01c636fa1e52717334">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 05 Mar 2026 09:05:00 +0800</pubDate>
    </item>
    <item>
      <title>大模型驱动的科研插图生成框架 PaperBanana</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488208&amp;idx=1&amp;sn=1e8ce9752abd8223ebabf1444d95fe3f</link>
      <description>对于研究人员来说，写论文时最头疼的环节可能往往不是推导公式或跑实验，而是画图。</description>
      <content:encoded><![CDATA[<p>原创 <span>Avenger</span> <span>2026-02-25 09:04</span> <span style="display: inline-block;">内蒙古</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f8e3dfd8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FOsTASDqnFNj4UCRdQCMhNibyia5rEOKVfC1aibqBEDF4JCEIgPsnsOaIB2ZRH3SGia7QLEMuYOON43tibwB1SgF6XU9ibT0rNtdSRAUKjeyyricZrk%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p data-pm-slice="0 0 []"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">对于研究人员来说，写论文时最头疼的环节可能往往不是推导公式或跑实验，而是画图。研究人员常常要在绘图软件中耗费数小时对齐文本框、调整箭头、修改配色，占据了研究人员大量的精力。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">为了将研究人员从繁琐的</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">作图劳役</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">中解放出来，来自北京大学与</span><span lang="EN-US"><span leaf="">Google Cloud AI Research </span></span><span leaf="">的研究团队设计了</span><span lang="EN-US"><span leaf="">PaperBanana</span></span><span leaf="">。该智能体框架能够将文章中的描述文本，在短短几分钟内自动转化为达到</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">顶会级别</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的高质量学术插图。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">PaperBanana</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">是一个由视觉大语言模型和图像生成模型驱动的</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">虚拟学术插图设计智能体框架</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">。</span></span><span leaf=""> 它</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">能自动理解你的算法逻辑，并输出一张排版精美、逻辑清晰、可直接用于发表的学术架构图。不仅如此，它还能处理数据统计图表，甚至可以用来优化人类手绘的草图。</span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 17px;">多智能体协作</span></span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004559" data-ratio="0.3965317919075145" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=4d05c965&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhSx1VlUUkcrBBjpcjxSA1dFgZ5A1CF52sNmWRkekIicHUWqIHe0UcmGCM1dlgPwX6GZl8kDzj94VoyibZalNYbPicAHFe5bScZ38%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">PaperBanana</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">并不是一个端到端的黑盒，它在内部构建了一个分工明确的工作流，一共有五个角色：</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">（</span><span lang="EN-US"><span leaf="">1</span></span><span leaf="">）</span><span lang="EN-US"><span leaf="">Retriever/</span></span><span leaf="">资料员：在拿到文字描述后，资料员先去由真实顶会优秀插图组成的数据库中寻找灵感，检索那些视觉结构相似的参考图。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">（</span><span lang="EN-US"><span leaf="">2</span></span><span leaf="">）</span><span lang="EN-US"><span leaf="">Planner/</span></span><span leaf="">架构师：架构师阅读文本描述，结合资料员找到的参考图，生成一份尽可能详实的视觉描述。把复杂的学术概念拆解为具体的视觉元素，比如哪里该放矩形框，哪里该用虚线连接，数据流向是怎样的。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">（</span><span lang="EN-US"><span leaf="">3</span></span><span leaf="">）</span><span lang="EN-US"><span leaf="">Stylist/</span></span><span leaf="">美术指导：在不改变科学内容的前提下，优化配色方案、字体排版、图形形状等细节，确保生成的图片符合顶级学术会议的视觉规范。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">（</span><span lang="EN-US"><span leaf="">4</span></span><span leaf="">）</span><span lang="EN-US"><span leaf="">Visualizer/</span></span><span leaf="">绘图员：负责调用强大的图像生成模型，将前述步骤中的设计渲染成高保真的图像。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">（</span><span lang="EN-US"><span leaf="">5</span></span><span leaf="">）</span><span lang="EN-US"><span leaf="">Critic/</span></span><span leaf="">严苛的审稿人：像审稿人一样盯着图片找问题，如 </span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">这里的箭头画反了</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">这两个框的文字重叠了</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">等。发现问题后，它会把修改意见打回给前面的环节。</span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 17px;">评估数据集</span></span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">研究人员构建了一个名为</span><span lang="EN-US"><span leaf="">PaperBananaBench</span></span><span leaf="">的评估数据集，其中包含了从</span><span lang="EN-US"><span leaf=""> NeurIPS 2025 </span></span><span leaf="">的论文中提取的</span><span lang="EN-US"><span leaf="">584</span></span><span leaf="">个复杂图表。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004558" data-ratio="0.4393063583815029" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=5d92b337&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhWnh6QIm4PjGGiczgv8Rm3wOpMAfvicticibm8nw0L97PaE1DQFJrZFqyE5t5rfWsiaFPjHgbcqcKS0D4xEqSanPuCd2NNM0IvmZJ8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 17px;">生成示例</span></span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004554" data-ratio="0.6705202312138728" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=ec03cdb8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgia6O0epRGqBv6mMWIQhZpFibUNa9678fnhicg0SMxIrdFzMxFIBFzzaVP3HVsGJTQvo8k7m8sriaxkkmQhIGPClwr66ZicbIvCvNA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">担心数据统计图生成错误的，框架还支持生成可执行的</span><span lang="EN-US"><span leaf="">Matplotlib</span></span><span leaf="">代码，确保数据的严谨性。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004553" data-ratio="0.6855491329479769" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=13052d88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhmO7Y1SIAwRNd5D0lEE2a55q6dvv3fHBmKKSo51wLkWGjKVayiahRBpR1NHj8DoDibVkpo1q7iaBjhAjLetsoUx1EWib7lZZZZgEQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;b&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size:12.0pt;font-family:\&#34;微软雅黑\&#34;,sans-serif;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 17px;">参考来源</span></span></span></b></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="javascript"><code><span leaf="">官方网站</span></code><br/><code><span leaf=""><span class="code-snippet__attr">https</span>:<span class="code-snippet__comment">//dwzhu-pku.github.io/PaperBanana/</span></span></code><br/><code><span leaf="">论文地址</span></code><br/><code><span leaf=""><span class="code-snippet__attr">https</span>:<span class="code-snippet__comment">//arxiv.org/pdf/2601.23265</span></span></code><br/><code><span leaf="">代码与数据集（后续开放）</span></code><br/><code><span leaf=""><span class="code-snippet__attr">https</span>:<span class="code-snippet__comment">//github.com/dwzhu-pku/PaperBanana</span></span></code><br/></pre></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8fc4e7d5&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488208%26idx%3D1%26sn%3D1e8ce9752abd8223ebabf1444d95fe3f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 25 Feb 2026 09:04:00 +0800</pubDate>
    </item>
    <item>
      <title>Recorded Future 2025 年度威胁情报报告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488196&amp;idx=1&amp;sn=1ac7978a88f25cb89eaced28254f1c5e</link>
      <description>Recorded Future 年度威胁情报报告如期发布。</description>
      <content:encoded><![CDATA[<p>原创 <span>Avenger</span> <span>2026-02-12 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a1d02598&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FOsTASDqnFNhrUx6VIsXsEnMZUU9EvSibV4VJF1JFk4D360bqJWfEVSicMR1ypgIt7ib6VY5lvGGZ6hicx6dH5DpicefCzuzicoaF7scdDtics7Oql8%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>Recorded Future 年度威胁情报报告如期发布。</p>
  <p data-pm-slice="0 0 []"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Recorded Future </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">年度威胁情报报告旨在揭示威胁情报行业现状。一如既往，分析发现在过去一年中，威胁情报对企业网络安全变得更加关键。</span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-weight: bold;">2025 </span></span></span><span leaf=""><span textstyle="" style="font-weight: bold;">年调查了 </span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-weight: bold;">615 </span></span></span><span leaf=""><span textstyle="" style="font-weight: bold;">位网络安全高管与相关从业者</span>，分析了威胁情报的使用、挑战与未来计划。</span></span></p><p data-pm-slice="0 0 []"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">所有受访者均来自员工人数超过一千人的公司。超过半数（</span><span lang="EN-US"><span leaf="">56%</span></span><span leaf="">）来自员工人数在一千到五千人的组织，而</span><span lang="EN-US"><span leaf=""> 44% </span></span><span leaf="">来自员工人数超过五千人的组织。大多数受访者在网络安全领域担任领导职务，包括网络安全经理或总监（</span><span lang="EN-US"><span leaf="">62%</span></span><span leaf="">）与网络安全副总裁或高管（</span><span lang="EN-US"><span leaf="">21%</span></span><span leaf="">），其余受访者均为安全相关从业者。所有受访者都熟悉其公司的威胁情报工具和政策（</span><span lang="EN-US"><span leaf="">81% </span></span><span leaf="">的人表示非常熟悉，</span><span lang="EN-US"><span leaf="">19% </span></span><span leaf="">的人表示比较熟悉）。受访者超过一半来自美国（</span><span lang="EN-US"><span leaf="">52%</span></span><span leaf="">），此外来自英国（</span><span lang="EN-US"><span leaf="">17%</span></span><span leaf="">）、加拿大（</span><span lang="EN-US"><span leaf="">16%</span></span><span leaf="">）和澳大利亚（</span><span lang="EN-US"><span leaf="">16%</span></span><span leaf="">）。</span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 17px;">威胁情报的使用与采纳</span></span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在</span><span lang="EN-US"><span leaf=""> 2025 </span></span><span leaf="">年，战略规划和投资已成为企业组织最常见的威胁情报用例之一。</span><span lang="EN-US"><span leaf="">43% </span></span><span leaf="">的受访人依靠威胁情报来为战略安全投资和规划提供信息，这是一个以前没有被考虑到的用例。虽然大多数企业组织报告了威胁情报的多种用例，但主</span><b><span leaf="">要还是用它来增强现有安全工具的检测能力</span></b><span leaf="">（</span><span lang="EN-US"><span leaf="">68%</span></span><span leaf="">）以及支持事件响应和取证调查（</span><span lang="EN-US"><span leaf="">40%</span></span><span leaf="">）。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6635838150289017" data-type="png" data-w="865" data-imgfileid="100004527" src="https://wechat2rss.xlab.app/img-proxy/?k=cc8dd9a6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhNicCj28JXFnJQkvU6ibibhtnpTebFPkQObpWrZMgv6xgZPQ5sPpSHflywmF8ib45VdqwqmV62lG5iaibZs4wquSM3bpicdqa4CWl0pU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">大多数组织会使用威胁情报来指导与采购、风险评估和资源分配相关的业务决策。近三分之二（</span><span lang="EN-US"><span leaf="">65%</span></span><span leaf="">）的受访人表示，威胁情报与安全技术的采购决策有关。</span><span lang="EN-US"><span leaf="">58% </span></span><span leaf="">表示它会被用于指导业务计划的风险评估，</span><span lang="EN-US"><span leaf="">53% </span></span><span leaf="">表示它会被用于支持事件响应的资源分配。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6057803468208093" data-type="png" data-w="865" data-imgfileid="100004528" src="https://wechat2rss.xlab.app/img-proxy/?k=7f8a333d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNia7B8ylwgoexRMcp7Xq3Ra6DS7Xl0iamMTvR1JPS41iaEhoIfcqLibHFribZXMQupL62KHIEWovd3icJ9q3EkT2skRQVcK34YStiauNc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">几乎所有企业组织都认为威胁情报是一项关键投资。在</span><span lang="EN-US"><span leaf=""> 2025 </span></span><span leaf="">年，</span><b><span leaf="">超过四分之三（</span><span lang="EN-US"><span leaf="">83%</span></span><span leaf="">）的受访人所在公司报告拥有专门负责威胁情报的全职团队</span></b><span leaf="">，而</span><span lang="EN-US"><span leaf=""> 9% </span></span><span leaf="">的公司只有兼职的威胁情报团队，另有</span><span lang="EN-US"><span leaf=""> 1% </span></span><span leaf="">的公司依靠外包团队进行威胁情报工作。目前只有</span><span lang="EN-US"><span leaf=""> 7% </span></span><span leaf="">的公司完全没有专门的威胁情报团队，这与 </span><span lang="EN-US"><span leaf="">2024 </span></span><span leaf="">年的年度报告相呼应。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5942196531791908" data-type="png" data-w="865" data-imgfileid="100004529" src="https://wechat2rss.xlab.app/img-proxy/?k=48a02416&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNg2XW4gYYGmUyucSLV3kDFV1AF5lh0KNGAzx0JtPohuM8yF6cdUyOBot85hj01Km8ungSfuQDfDh0iccsgiaOkQ7TbCia45tXmBW8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">有</span><span lang="EN-US"><span leaf=""> 89% </span></span><span leaf="">的公司在</span><span lang="EN-US"><span leaf=""> 2025 </span></span><span leaf="">年在为威胁情报供应商付费</span></span></b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">，近一半（</span><span lang="EN-US"><span leaf="">48%</span></span><span leaf="">）的受访者为多个供应商付费，而</span><span lang="EN-US"><span leaf=""> 41% </span></span><span leaf="">的受访者只为一个供应商付费。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.48554913294797686" data-type="png" data-w="865" data-imgfileid="100004530" src="https://wechat2rss.xlab.app/img-proxy/?k=7c8ae1bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNh5uqfSD6e5A9xiaMCicGadyMiaglYS5mic3jzyNzs7V7ibyf5XUPbJV0HTE2GAw7EHceuK8FEoRhUgpX7QsicRdqHyf7UdZupkib8KAI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">大多数企业组织频繁依赖威胁情报，这强化了其提供的价值。超过四分之三（</span><span lang="EN-US"><span leaf="">76%</span></span><span leaf="">）的公司中，威胁情报至少每周直接影响其安全决策，其中</span><span lang="EN-US"><span leaf=""> 32% </span></span><span leaf="">表示每天都在影响决策，仅又</span><span lang="EN-US"><span leaf=""> 1% </span></span><span leaf="">的受访者表示威胁情报很少影响决策。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4624277456647399" data-type="png" data-w="865" data-imgfileid="100004531" src="https://wechat2rss.xlab.app/img-proxy/?k=5529bbbf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhwJ8DGxrxG0aZpJtY9Ogw3dGbog4QPNRwT5VUw9fGdJ4IL77ibck9XmeichzicLUpyibHQoC1fDFSQSb00Kvibm7fHhJHYM4QhY5Cw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在大多数企业组织中，会有多个团队依赖威胁情报。四分之三（</span><span lang="EN-US"><span leaf="">73%</span></span><span leaf="">）的受访人表示</span><span lang="EN-US"><span leaf=""> IT </span></span><span leaf="">运营部门在使用威胁情报，</span><span lang="EN-US"><span leaf="">70% </span></span><span leaf="">的情况是安全运营中心（</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">）在使用威胁情报。事件响应团队（</span><span lang="EN-US"><span leaf="">48%</span></span><span leaf="">）、风险管理（</span><span lang="EN-US"><span leaf="">47%</span></span><span leaf="">）和漏洞管理（</span><span lang="EN-US"><span leaf="">46%</span></span><span leaf="">）也都在积极使用威胁情报。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6104046242774567" data-type="png" data-w="865" data-imgfileid="100004532" src="https://wechat2rss.xlab.app/img-proxy/?k=496aeff4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgoxIbOysVPsEHNZXtMWWsMgviaHh4vJf1xIBlRYVV7QmIZF05wAPAscsacHrVsygNlibc08NF2LtbM94nYYbqHVheYFicKHWu5mI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 17px;">威胁情报的支出与评估</span></span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">大多数（</span><span lang="EN-US"><span leaf="">76%</span></span><span leaf="">）受访人表示，其组织每年在外部威胁情报产品（不包括服务）上的投资达到或超过</span><span lang="EN-US"><span leaf=""> 25 </span></span><span leaf="">万美元。</span><span lang="EN-US"><span leaf="">33% </span></span><span leaf="">的公司花费</span><span lang="EN-US"><span leaf=""> 25 </span></span><span leaf="">万至</span><span lang="EN-US"><span leaf=""> 50 </span></span><span leaf="">万美元，</span><span lang="EN-US"><span leaf="">29% </span></span><span leaf="">的公司花费</span><span lang="EN-US"><span leaf=""> 50 </span></span><span leaf="">万至</span><span lang="EN-US"><span leaf=""> 100 </span></span><span leaf="">万美元，</span><span lang="EN-US"><span leaf="">14% </span></span><span leaf="">的公司每年花费超过</span><span lang="EN-US"><span leaf=""> 100 </span></span><span leaf="">万美元。<span textstyle="" style="font-weight: bold;">相</span></span><b><span leaf="">比</span><span lang="EN-US"><span leaf=""> 2024 </span></span><span leaf="">年，总体支出略有下降</span></b><span leaf="">。在</span><span lang="EN-US"><span leaf=""> 2024 </span></span><span leaf="">年，</span><span lang="EN-US"><span leaf="">79% </span></span><span leaf="">的公司每年在外部供应商的威胁情报产品上花费至少</span><span lang="EN-US"><span leaf=""> 25 </span></span><span leaf="">万美元，而</span><span lang="EN-US"><span leaf=""> 17% </span></span><span leaf="">的公司每年花费至少</span><span lang="EN-US"><span leaf=""> 100 </span></span><span leaf="">万美元 。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4531791907514451" data-type="png" data-w="865" data-imgfileid="100004533" src="https://wechat2rss.xlab.app/img-proxy/?k=ab6c74d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhdLAiaDvneMInqx6NMibHiccGcPbZmnQnQlj5tUEFNRuE2wa5ZwkFk9SOicJEnmQYVWXcPJhTjxOH0KAn8KiajzeRMwetCOorPYcHg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在衡量威胁情报计划的成功时，大多数组织关注速度和效率。</span><b><span lang="EN-US"><span leaf="">54% </span></span><span leaf="">的受访人会考虑威胁检测和响应时间的改进</span></b><span leaf="">，而</span><span lang="EN-US"><span leaf=""> 50% </span></span><span leaf="">的公司考虑安全团队效率的提高。</span><span lang="EN-US"><span leaf="">40% </span></span><span leaf="">的公司衡量事件数量的减少，</span><span lang="EN-US"><span leaf="">37% </span></span><span leaf="">的公司考虑安全工作的优先级排序。相比之下，很少有组织使用诸如提高威胁狩猎有效性（</span><span lang="EN-US"><span leaf="">9%</span></span><span leaf="">）和预防事件带来的成本节约（</span><span lang="EN-US"><span leaf="">18%</span></span><span leaf="">）等指标来衡量威胁情报的成功。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6104046242774567" data-type="png" data-w="865" data-imgfileid="100004534" src="https://wechat2rss.xlab.app/img-proxy/?k=254750ee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNjsYxdibEuZ1WrIiasS7vnlwrE0ZehOeLKDdwcuqOaBgLXPLbCgeSDKKhTJALfDy4oQibAgADfsfT0j0yEcpqcpTFuTM54QRqvF9s%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 17px;">威胁情报面临的挑战</span></span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">威胁情报成熟度逐年提高。然而，仍有超过半数的企业组织认为他们的成熟度未达到先进水平 。总共有</span><span lang="EN-US"><span leaf=""> 49% </span></span><span leaf="">的受访人表示他们的成熟度水平是“先进”的。这意味着他们拥有结合多个威胁情报源输出的工具、专门的威胁情报团队，以及将威胁情报与大多数安全活动（包括业务风险评估）集成的自动化工作流程 。</span><span lang="EN-US"><span leaf="">44% </span></span><span leaf="">的人认为他们的威胁情报成熟度处于“中级”。剩下的</span><span lang="EN-US"><span leaf=""> 6% </span></span><span leaf="">将其成熟度水平评为“基础”或“初学者”。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5294797687861271" data-type="png" data-w="865" data-imgfileid="100004535" src="https://wechat2rss.xlab.app/img-proxy/?k=f4b24d64&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNiau9cpc9Fe700yeBNxq0NZ9ZGStns1MPv25gRNp17duq4O3bU4pqQChIc7ouTDFwWFbtibND1nufjSxR9W6yib4E1dRnibDZeHQrg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">随着投资的逐渐增加，企业组织可能会在威胁情报供应商方面遇到一系列问题。可信度、集成和信息过载是主要的困难。事实上，</span><span lang="EN-US"><span leaf="">16% </span></span><span leaf="">的受访者将与现有安全工具集成不佳列为他们当前威胁情报供应商的首要挑战。另有 </span><span lang="EN-US"><span leaf="">16% </span></span><span leaf="">的公司</span><b><span leaf="">将难以确定可信度和准确性列为他们的首要担忧</span></b><span leaf="">。总共有半数受访人表示，难以确定可信度和准确性是其当前威胁情报供应商的三大问题之一。排在前三大挑战之列的还有与现有安全工具集成不佳（</span><span lang="EN-US"><span leaf="">48%</span></span><span leaf="">）、信息过载（</span><span lang="EN-US"><span leaf="">46%</span></span><span leaf="">）以及缺乏针对特定环境的上下文（</span><span lang="EN-US"><span leaf="">46%</span></span><span leaf="">）。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.49017341040462425" data-type="png" data-w="865" data-imgfileid="100004536" src="https://wechat2rss.xlab.app/img-proxy/?k=92b8c6fa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgX391fQI5tSsRIO23hQS1FpRJ12iauesPGqjwHScVjjxUfJ5j2WwgHPuuRzPkhVBibRiatyNfZTmUgjScgc4U2viaXAf047GkoGrk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">相比之下，相对于收到的价值成本过高（</span><span lang="EN-US"><span leaf="">32%</span></span><span leaf="">）是被引用最少的挑战，这表明安全专业人员在很大程度上认为鉴于其创造的价值，其威胁情报供应商的成本是合理的。然而，最大的挑战并不完全与企业组织认为其威胁情报供应商最需要改进的领域相一致。</span><b><span leaf="">三分之一的受访人表示，情报交付速度是其供应商最需要改进的领域</span></b><span leaf="">。五分之一（</span><span lang="EN-US"><span leaf="">22%</span></span><span leaf="">）的人提到与安全工具的集成问题，</span><span lang="EN-US"><span leaf="">21% </span></span><span leaf="">的人将深度分析和上下文列为他们最大的与供应商相关的痛点。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.42427745664739885" data-type="png" data-w="865" data-imgfileid="100004537" src="https://wechat2rss.xlab.app/img-proxy/?k=7a19a90b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhbM9Ao4jQORpILMOViaE06deP8vicoY8Djd8nbvch5WQp3ibIdPkVqPY5nKeOvcZzNJj2ejJTNBZ3To7MGZ7RytIap9cdHNYeuFs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">虽然只有三分之一的安全团队表示高成本是当前威胁情报供应商的挑战，但成本效益是新投资的关键因素。</span><b><span leaf="">在评估威胁情报供应商时，</span><span lang="EN-US"><span leaf="">34% </span></span><span leaf="">的受访者表示成本效益是首要因素</span></b><span leaf="">。</span><span lang="EN-US"><span leaf="">20% </span></span><span leaf="">的公司表示集成能力是首要因素，</span><span lang="EN-US"><span leaf="">14% </span></span><span leaf="">的公司在选择威胁情报供应商时优先考虑分析的深度和可操作性。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5086705202312138" data-type="png" data-w="865" data-imgfileid="100004538" src="https://wechat2rss.xlab.app/img-proxy/?k=a1b788c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNgZhlwlfeXQSLGjickicRuXSV3dydIDpibHWuEsTrhdickbMQtwq8BRvqNBrh9pBVMEEQ4JSGZKUaiap15d8VfPCSjsBBNZHu2Un3js%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 17px;">威胁情报未来的计划</span></span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">供应商整合是大多数企业组织的一个关键目标，</span><b><span lang="EN-US"><span leaf="">81% </span></span><span leaf="">的受访者表示他们打算整合威胁情报供应商</span></b><span leaf="">。倾向于专注于一两个最有用的威胁情报供应商，而不是监控单独的数据源或给已经负担沉重的安全团队增加复杂性。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004539" data-ratio="0.315606936416185" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=508b3ad3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhMoSy8Wm1t3VOsMrSLPCvBTt1D45gGZhicNlk3Ig5IKLf7p1aoxyN424v7lLAHdWMmMVBJo1vCNN82ibEcicibiaJ0Xj12fjXj60MQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">供应商整合不意味着要削减成本，</span><b><span leaf="">绝大多数（</span><span lang="EN-US"><span leaf="">91%</span></span><span leaf="">）受访者表示，他们的组织计划在</span><span lang="EN-US"><span leaf=""> 2026 </span></span><span leaf="">年在威胁情报上投资更多</span></b><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004540" data-ratio="0.3225433526011561" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=d17284fa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNiacIzJFuZr0kFkeG10pAuPTA6u6fSMHBAq2OekcQlzbS18OM9QhUMicqRSo9H9OicTQUgaJo0GSXSmIB6XicNgLrG20adZUaFhLYs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">数据显示，安全团队的威胁情报工作几乎平均分配在五个领域。受访者将</span><span lang="EN-US"><span leaf=""> 22% </span></span><span leaf="">的威胁情报工作用于分析和上下文化针对其组织的威胁，</span><span lang="EN-US"><span leaf="">19% </span></span><span leaf="">用于威胁狩猎和主动检测活动。花费</span><span lang="EN-US"><span leaf=""> 18% </span></span><span leaf="">用于支持事件响应和调查，</span><span lang="EN-US"><span leaf="">18% </span></span><span leaf="">用于漏洞研究和优先级排序，</span><span lang="EN-US"><span leaf="">17% </span></span><span leaf="">用于战略威胁态势分析和报告。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100004541" data-ratio="0.4208092485549133" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=0f7b13b9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNgpRMZ0o2ibrkfDicUG9NfW6qwKN9rwBD8v6picVoticdlyDyEK6JY8sCibRgh8gbRmZevaibYTVoxUN7DFprub7GQuM5iaER4EIwU0B8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">企业组织打算在未来两年内进行一些关键变革，以改进他们使用威胁情报的方式。超过三分之一（</span><span lang="EN-US"><span leaf="">36%</span></span><span leaf="">）的受访者表示，他们计划将威胁情报与在自身环境中检测到的数据相结合，以更好地了解其风险态势并与同行进行比较。四分之一（</span><span lang="EN-US"><span leaf="">25%</span></span><span leaf="">）的公司表示他们计划将威胁情报与其他网络安全工作流程和团队集成——重点关注身份访问管理、欺诈和</span><span lang="EN-US"><span leaf=""> GRC</span></span><span leaf="">（治理、风险与合规）。另有</span><span lang="EN-US"><span leaf=""> 18% </span></span><span leaf="">的公司表示他们旨在加强风险分析。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5352601156069364" data-type="png" data-w="865" data-imgfileid="100004542" src="https://wechat2rss.xlab.app/img-proxy/?k=ebcd4216&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNia0d5M7WRib2n0SRfC7XqDk1kU0krpc1dKkUBibnM2NN1fgZJ0EfkicGgGDbEic8gJicpiasrhMM2WK02cjRN35vDuUF9H7ZicrmD9vn4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">随着威胁情报使用方式的改变，</span><span lang="EN-US"><span leaf="">87% </span></span><span leaf="">的受访者预计其威胁情报成熟度将有适度到显著的演变。只有</span><span lang="EN-US"><span leaf=""> 8% </span></span><span leaf="">的人预计在未来两年内维持当前的成熟度水平。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.446242774566474" data-type="png" data-w="865" data-imgfileid="100004543" src="https://wechat2rss.xlab.app/img-proxy/?k=e344c361&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FOsTASDqnFNhbuiajXiaR2ic69D8cv2KaeW1AHC8NrTtjbCVHjyfvDjAKMBVt1icJV7YlasscRk3Ys48XDJgxlM5moAw4B4KpODM6swnIx5llSoY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">为了达到这些成熟度目标并跟上不断变化的网络安全格局，大多数企业组织预计需要适度到显著的威胁情报改进。超过半数的受访者（</span><span lang="EN-US"><span leaf="">53%</span></span><span leaf="">）预计未来</span><span lang="EN-US"><span leaf=""> 12 </span></span><span leaf="">个月内威胁情报需求将发生适度到显著的变化。</span><b><span leaf="">四分之一（</span><span lang="EN-US"><span leaf="">27%</span></span><span leaf="">）的公司预计需要大量的威胁情报投资和培训</span></b><span leaf="">，</span><span lang="EN-US"><span leaf="">26% </span></span><span leaf="">的公司预计现有能力将适度扩展。另有</span><span lang="EN-US"><span leaf=""> 26% </span></span><span leaf="">的公司预测重点将转向质量而非数量。</span></span></p><p style="text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5167630057803468" data-type="png" data-w="865" data-imgfileid="100004544" src="https://wechat2rss.xlab.app/img-proxy/?k=bb84ea6b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FOsTASDqnFNhy72G56aW8g9UsVRf3kib1SKm6E5Kn70EdPLp1Z9NGLMvFXogxAjlghGuo2lXGQ2Taq0hPuHPAGZjulSDXRicnAsG1Ov82vqRDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=118698d7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488196%26idx%3D1%26sn%3D1ac7978a88f25cb89eaced28254f1c5e">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 12 Feb 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>高级持续性威胁十年嬗变</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488173&amp;idx=1&amp;sn=e6b47ad9109ca245a83ab8670c91b61e</link>
      <description>十年间，APT 有什么趋势性的变化？</description>
      <content:encoded><![CDATA[<p>原创 <span>Avenger</span> <span>2026-01-19 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=21da9218&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXKmXopUdq7baPzbJVXfAn3vR3viaLr5Rd943IF8DhEhBJ7RX56DWicjBtA%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>十年间，APT 有什么趋势性的变化？</p>
  <p style="margin-right: 0cm;margin-left: 0cm;" data-pm-slice="0 0 []"><b><span style="font-size:
14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">工作来源</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">CCS 2025</span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><b><span style="font-size:
14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">工作准备</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">已有的 </span><span lang="EN-US"><span leaf="">APT </span></span><span leaf="">研究往往只盯着某个孤立事件，时间跨度较短。收集整理过去十年（</span><span lang="EN-US"><span leaf="">2014-2023</span></span><span leaf="">）间公开披露的与 </span><span lang="EN-US"><span leaf="">603 </span></span><span leaf="">个攻击组织相关的 </span><span lang="EN-US"><span leaf="">1509 </span></span><span leaf="">份分析报告（共计 </span><span lang="EN-US"><span leaf="">24215 </span></span><span leaf="">页），以及 </span><span lang="EN-US"><span leaf="">177 </span></span><span leaf="">篇新闻内容。利用大模型进行上下文推断，提取相关信息（行业、攻击手段等）。并且使用</span><span lang="EN-US"><span leaf=""> IoCParser </span></span><span leaf="">进行辅助，基于规则提取</span><span lang="EN-US"><span leaf="">CVE</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">MITRE ATT&amp;CK </span></span><span leaf="">技术项与 </span><span lang="EN-US"><span leaf="">Yara </span></span><span leaf="">规则。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.38034682080924853" data-type="png" data-w="865" data-imgfileid="100004505" src="https://wechat2rss.xlab.app/img-proxy/?k=aaed3e20&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXKOhQPG5BE5MsYG0fneHFmzg6EToXKGlOFSE0IsgVLzqPQabqobpkNEA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">从三个来源收集分析报告，一共 </span><span lang="EN-US"><span leaf="">1509 </span></span><span leaf="">份分析报告。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5098265895953757" data-type="png" data-w="865" data-imgfileid="100004506" src="https://wechat2rss.xlab.app/img-proxy/?k=168f9385&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXKqPHLSHUSzowQTtsoL18JdibgmJibLiaLKxCCPq8kSt4ia9Ia3VtVcn1a3w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">TOP 15 </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">的分析报告来源如下所示，卡巴斯基断崖式领先，趋势科技、</span><span lang="EN-US"><span leaf="">FireEye</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Palo Alto</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">ESET </span></span><span leaf="">与赛门铁克均在 </span><span lang="EN-US"><span leaf="">50 </span></span><span leaf="">篇以上。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7352601156069364" data-type="png" data-w="865" data-imgfileid="100004507" src="https://wechat2rss.xlab.app/img-proxy/?k=33a01d77&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXK4LNcpfgtUIJ47oH2EEESJEcfNdYWtwQSWLbZaFwqGQgIdrSjh31Dkg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">从三个来源收集攻击组织信息，一共 </span><span lang="EN-US"><span leaf="">603 </span></span><span leaf="">个攻击组织。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.43352601156069365" data-type="png" data-w="865" data-imgfileid="100004508" src="https://wechat2rss.xlab.app/img-proxy/?k=364d9007&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXKwPqRGYhB80HiahzFPDFsUgjXg1yrvfVib8sKib3NrGV3Q5mCW0ldEiaJBA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><b><span style="font-size:
14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">工作评估</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">随机抽取 </span><span lang="EN-US"><span leaf="">120 </span></span><span leaf="">篇分析报告人工检查，与使用 </span><span lang="EN-US"><span leaf="">Gemini-1.5-Flash</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">GPT-4o </span></span><span leaf="">与 </span><span lang="EN-US"><span leaf="">GPT-4-Turbo </span></span><span leaf="">三个大模型进行对比分析。由此可见，</span><span lang="EN-US"><span leaf="">GPT-4-Turbo </span></span><span leaf="">是最好的（</span><span lang="EN-US"><span leaf="">PS</span></span><span leaf="">：不知道 </span><span lang="EN-US"><span leaf="">Gemini-3-Pro </span></span><span leaf="">的效果）：</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2809248554913295" data-type="png" data-w="865" data-imgfileid="100004509" src="https://wechat2rss.xlab.app/img-proxy/?k=17d827e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXK1XFs01Vt0UKg5KoYB3VAkf4ibY0WZIWM2c4NWJWS6gsaIB0QAgQCpWA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">将 </span><span lang="EN-US"><span leaf="">GPT-4-Turbo </span></span><span leaf="">提取结果与 </span><span lang="EN-US"><span leaf="">IoCParser </span></span><span leaf="">提取结果进行对比，基于规则比基于大模型提取要明显好一大截。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.49710982658959535" data-type="png" data-w="865" data-imgfileid="100004510" src="https://wechat2rss.xlab.app/img-proxy/?k=2b635556&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXKicLtvvY93zntYZkJ3qeUhEXdaw8V1QAInmCofuo8d0RhpujFIZRkaIQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">不是每一篇报告都能提供要提取的各类信息，只有 </span><span lang="EN-US"><span leaf="">8.7% </span></span><span leaf="">的分析报告带有 </span><span lang="EN-US"><span leaf="">Yara </span></span><span leaf="">规则、</span><span lang="EN-US"><span leaf="">11.6% </span></span><span leaf="">的报告带有 </span><span lang="EN-US"><span leaf="">MITRE ATT&amp;CK </span></span><span leaf="">技术项 </span><span lang="EN-US"><span leaf="">ID</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5410404624277456" data-type="png" data-w="865" data-imgfileid="100004511" src="https://wechat2rss.xlab.app/img-proxy/?k=85c65bdf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXK4MZ6hlCzm88jQTOvUK9ZL2IywNvyrF52URc8bcvN4xXOicUHbhlZadQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">总体来说，美国是主要攻击目标、</span><span lang="EN-US"><span leaf="">Lazarus </span></span><span leaf="">是最活跃的攻击组织、恶意文档是最常用的初始攻击方式。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.25780346820809247" data-type="png" data-w="865" data-imgfileid="100004512" src="https://wechat2rss.xlab.app/img-proxy/?k=d2669057&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXKZUyyWd5WmROLE8ABacX2OqvJ2t52FOoxGEod05250vV0CsLOlNpHrA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">1509 </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">篇分析报告共涉及 </span><span lang="EN-US"><span leaf="">154 </span></span><span leaf="">个受害国家，全球超过 </span><span lang="EN-US"><span leaf="">80% </span></span><span leaf="">的国家都成为了 </span><span lang="EN-US"><span leaf="">APT </span></span><span leaf="">攻击的受害者。</span><span lang="EN-US"><span leaf="">TOP 10 </span></span><span leaf="">的国家（美国、印度、韩国、日本、俄罗斯、中国、英国、乌克兰、德国、土耳其）共计 </span><span lang="EN-US"><span leaf="">650 </span></span><span leaf="">篇分析报告，占到 </span><span lang="EN-US"><span leaf="">43.1%</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5838150289017341" data-type="png" data-w="865" data-imgfileid="100004513" src="https://wechat2rss.xlab.app/img-proxy/?k=f3f06efc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXKJZctAqIA9ibgicbl6Lk5ny6zIHdib2ia4aXdiavN5osibTsMvRGDO6ibEscog%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">最活跃的十个攻击组织共发动了 </span><span lang="EN-US"><span leaf="">326 </span></span><span leaf="">次攻击，占所有攻击活动的 </span><span lang="EN-US"><span leaf="">21.6%</span></span><span leaf="">。</span><span lang="EN-US"><span leaf="">Lazarus</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">APT 28 </span></span><span leaf="">与 </span><span lang="EN-US"><span leaf="">APT 29 </span></span><span leaf="">是过去十年中最活跃的攻击组织，这些攻击组织的攻击并不是均匀分布的，而是集中在特定时间内完成。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6820809248554913" data-type="png" data-w="865" data-imgfileid="100004514" src="https://wechat2rss.xlab.app/img-proxy/?k=37caf28e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXKQ3icCAQian2ZwY9ZUh0EQV7RRjU5LzEw30ESF5HdWhIxhUv146Wgpr5Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在 </span><span lang="EN-US"><span leaf="">13.5% </span></span><span leaf="">的攻击活动中，攻击者使用了 </span><span lang="EN-US"><span leaf="">0day </span></span><span leaf="">漏洞。</span><span lang="EN-US"><span leaf="">2018 </span></span><span leaf="">年以来，</span><span lang="EN-US"><span leaf="">0day </span></span><span leaf="">漏洞的使用整体呈现下降趋势。可能是满天飞的 </span><span lang="EN-US"><span leaf="">1day </span></span><span leaf="">漏洞就足够了，也可能是开发 </span><span lang="EN-US"><span leaf="">0day </span></span><span leaf="">漏洞的成本与复杂性不断上升。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">政府和国防行业被攻击最多，其次是商业公司。排名第三的行业每年都在变化，最多的是教育和科研行业。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.530635838150289" data-type="png" data-w="865" data-imgfileid="100004515" src="https://wechat2rss.xlab.app/img-proxy/?k=4c623034&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXKMkPyFypd7broTuWLW3262KevrQiaDSqWfibZAs2uWTj5UALCR2ctq1Xw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">恶意文档、鱼叉邮件与漏洞利用，是攻击者最常用的攻击手段。</span></span></p><p style="text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5491329479768786" data-type="png" data-w="865" data-imgfileid="100004516" src="https://wechat2rss.xlab.app/img-proxy/?k=c79f9e69&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXK07mN8VIjr4a0ER09HDlTSc2bHms0uzgWVEibvBFd2UXgeVzohnlQeuA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在 </span><span lang="EN-US"><span leaf="">175 </span></span><span leaf="">篇分析报告中提取了 </span><span lang="EN-US"><span leaf="">2582 </span></span><span leaf="">个 </span><span lang="EN-US"><span leaf="">MITRE ATT&amp;CK  </span></span><span leaf="">技术项 </span><span lang="EN-US"><span leaf="">ID</span></span><span leaf="">，去重后</span><span lang="EN-US"><span leaf=""> 263 </span></span><span leaf="">个。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4682080924855491" data-type="png" data-w="865" data-imgfileid="100004517" src="https://wechat2rss.xlab.app/img-proxy/?k=bfdb54fa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXKeW9tyWrBibbF2C6RcRZaVjRGhk6LqShMveno6tAiax1qeTgWwibhNaheg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在 </span><span lang="EN-US"><span leaf="">416 </span></span><span leaf="">篇分析报告中提取了 </span><span lang="EN-US"><span leaf="">1088 </span></span><span leaf="">个 </span><span lang="EN-US"><span leaf="">CVE</span></span><span leaf="">，去重后 </span><span lang="EN-US"><span leaf="">431 </span></span><span leaf="">个。这些漏洞当然都是很严重的，评分都很高。</span><span lang="EN-US"><span leaf="">Windows </span></span><span leaf="">与 </span><span lang="EN-US"><span leaf="">Office </span></span><span leaf="">是攻击者最在乎的攻击目标，能占到 </span><span lang="EN-US"><span leaf="">90% </span></span><span leaf="">以上。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5803468208092486" data-type="png" data-w="865" data-imgfileid="100004518" src="https://wechat2rss.xlab.app/img-proxy/?k=cdd82cf6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXKYLMJ82xWIZuyPiaR3uUSfVLKwEZn1DWbwECer2Kn0gvU2Eo7qdrdy1Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">另外，还在 </span><span lang="EN-US"><span leaf="">131 </span></span><span leaf="">篇分析报告中提取了 </span><span lang="EN-US"><span leaf="">419 </span></span><span leaf="">条 </span><span lang="EN-US"><span leaf="">Yara </span></span><span leaf="">规则。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">约有一半的攻击行动持续了五个月甚至更短，最长的攻击行动持续时间近五年，最短的攻击行动仅仅持续一天。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7560693641618497" data-type="png" data-w="865" data-imgfileid="100004519" src="https://wechat2rss.xlab.app/img-proxy/?k=8ae6112e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXKqTrMCDbzkfedoyDXUWSXibfZ0H2KWxrkZ4r11oSLj5to5eFseribh1Qg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">52.3% </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">的情况下是真正的 </span><span lang="EN-US"><span leaf="">0day</span></span><span leaf="">，剩下 </span><span lang="EN-US"><span leaf="">47.7% </span></span><span leaf="">都是 </span><span lang="EN-US"><span leaf="">1day </span></span><span leaf="">或 </span><span lang="EN-US"><span leaf="">nday</span></span><span leaf="">。平均而言，针对 </span><span lang="EN-US"><span leaf="">0day </span></span><span leaf="">漏洞的补丁大概要 </span><span lang="EN-US"><span leaf="">200 </span></span><span leaf="">天。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17341040462427745" data-type="png" data-w="865" data-imgfileid="100004520" src="https://wechat2rss.xlab.app/img-proxy/?k=dabb0782&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXK39ZH7xibwoXuwialQR5v5IFS9QZFMz8PicibGoA5fUpuoZFfhDF2ThFsfw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">自己攻击自己的情况，例如美国的</span><span lang="EN-US"><span leaf=""> Longhorn </span></span><span leaf="">入侵美国主机几小时后就脱离环境擦除痕迹了，这可能是无意中攻击的。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8485549132947977" data-type="png" data-w="865" data-imgfileid="100004521" src="https://wechat2rss.xlab.app/img-proxy/?k=271915ff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZ64JwqjME8oIkRJr0nExXKoAjOeMDTF6ukmwFdBomeAOrJtxHI4DWRMYAmEFqshO1usOUdpL5cIA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><b><span style="font-size:
14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">工作思考</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">不打补丁放任漏洞，无异于把自己拱手送给黑客，使得攻击者不需要多么高精尖的手段就可以入侵。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">这是公开数据披露统计的是西方视野下的 </span><span lang="EN-US"><span leaf="">APT </span></span><span leaf="">视角，不能认为统计数据就是板上钉钉的事实。网络空间中的 </span><span lang="EN-US"><span leaf="">APT </span></span><span leaf="">攻击往往是政治空间的外溢与延伸，例如美国大选和法国大选被入侵、俄罗斯入侵乌克兰电网、</span><span lang="EN-US"><span leaf="">Lazarus </span></span><span leaf="">在 </span><span lang="EN-US"><span leaf="">COVID-19 </span></span><span leaf="">时攻击制药公司。</span></span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="cs"><code><span leaf="">A Decade-<span class="code-snippet__built_in">long</span> Landscape of Advanced Persistent Threats: Longitudinal Analysis <span class="code-snippet__keyword">and</span> Global Trends</span></code></pre></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=37df20c6&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488173%26idx%3D1%26sn%3De6b47ad9109ca245a83ab8670c91b61e">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 19 Jan 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>不须计较劳苦心，万事原来有命</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488151&amp;idx=1&amp;sn=e2efb7b889a559d817c2827a6f1ced31</link>
      <description>再次诚挚感谢各位读者的厚爱，一年又一年呐！</description>
      <content:encoded><![CDATA[<p>原创 <span>Avenger</span> <span>2025-12-25 09:02</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=2beb926c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FdlhiccJOdNYaibI7ZeuUiavMyA7qKkxy2n4icvHicvChH7xh11vKUFDCeqR46WQRuYYAnY2wykKiaMvWmcP63NMCdIjg%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>再次诚挚感谢各位读者的厚爱，一年又一年呐！</p>
  <p data-pm-slice="0 0 []"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">再次诚挚感谢各位读者的厚爱，“威胁棱镜”度过了属于自己的第五个年头。依旧遵循惯例，为过去的一年做个简短的“年终总结”。</span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 17px;">关注情况概览</span></span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">关注者总数目前超过了 </span><span lang="EN-US"><span leaf="">4800</span></span><span leaf="">，相比去年增长了 </span><span lang="EN-US"><span leaf="">18%</span></span><span leaf="">。女性占比在近几年持续缓慢上升，未知性别占比也在增长。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004494" class="rich_pages wxw-img" data-ratio="0.33425925925925926" data-type="png" data-w="1080" height="185" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=eec436db&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYaibI7ZeuUiavMyA7qKkxy2n4IfBe5iapqKHt5I8NlSf18YShoBXUY1hlrJQrrQzo40pSGf4cqvnNriaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">35 </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">岁以下未来希望的比例从 </span><span lang="EN-US"><span leaf="">72.86% </span></span><span leaf="">下降到 </span><span lang="EN-US"><span leaf="">68.62%</span></span><span leaf="">，而 </span><span lang="EN-US"><span leaf="">36 </span></span><span leaf="">岁到 </span><span lang="EN-US"><span leaf="">60 </span></span><span leaf="">岁的中坚力量占比从 </span><span lang="EN-US"><span leaf="">26.47% </span></span><span leaf="">上升至 </span><span lang="EN-US"><span leaf="">30.86%</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004496" alt="图形用户界面, 应用程序

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.3212962962962963" data-type="png" data-w="1080" height="178" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=0d251a1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYaibI7ZeuUiavMyA7qKkxy2n4Oa2G0nnn7OEOIJtNd2Ke3rg6QHcxqCTsmtNDGxfmltvjvvlKia1OObg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">本号的读者有近半数在北京、广东与上海这三个省份，但其集中度在持续下降，今年的文章可能吸引了更多其他地区的读者关注。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004497" alt="图片包含 文本

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.375" data-type="png" data-w="1080" height="208" width="555" src="https://wechat2rss.xlab.app/img-proxy/?k=007a15ee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYaibI7ZeuUiavMyA7qKkxy2n47iaMcOY8wDZoI6QOZ9OZq61qd5GWRxsdBfKP04P1TkZIk5zoic4jUIRA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">一方面欢迎各位新读者的关注，另一方面感谢三百余个常读用户的持续关注。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004495" alt="图表, 条形图

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.425" data-type="png" data-w="1080" height="236" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=61afc156&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYaibI7ZeuUiavMyA7qKkxy2n4prym6riagvrXx7aWQic6R3CQHmYYjd2r2YsKNmUWK81PIPnb2crAxt6A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 17px;">内容情况概览</span></span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">这一年发了 </span><span lang="EN-US"><span leaf="">32 </span></span><span leaf="">篇文章，总数量上与前两年基本持平。发文的节奏有待调整，今年有两段合计长达六个月的断更期，承蒙各位不弃。下面是读者用实际点击选出来“优质”文章，有感兴趣又没读过的可以看下（王婆卖瓜</span><span lang="EN-US"><span leaf="">ing</span></span><span leaf="">）。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">按阅读量排行的 </span><span lang="EN-US"><span leaf="">TOP 10 </span></span><span leaf="">如下所示：</span></span></p><table style="width:410.05pt;background:white;border-collapse:collapse;mso-yfti-tbllook:
 1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="425" width="425" valign="top" style="border: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:
  windowtext;"><span leaf="">文章名称</span></span></b></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:
  windowtext;"><span leaf="">阅读量</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">IDA </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">插件大赛</span><span lang="EN-US"><span leaf=""> 2024</span></span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">4299</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">Yara </span></span><span style="font-size:
  12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">退休，</span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">接棒</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">2361</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">2025 </span></span><span style="font-size:
  12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">年第四届国际网络安全挑战赛</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">1570</span></span></p></td></tr><tr style="mso-yfti-irow:4;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">ATT&amp;CK 2025</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:
  windowtext;"><span leaf="">（</span><span lang="EN-US"><span leaf="">ATT&amp;CKCon 6.0</span></span><span leaf="">）议题慢递</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">1504</span></span></p></td></tr><tr style="mso-yfti-irow:5;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">APT </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">域名与基础设施的生命周期</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">1039</span></span></p></td></tr><tr style="mso-yfti-irow:6;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">人工智能网络挑战赛（</span><span lang="EN-US"><span leaf="">AIxCC</span></span><span leaf="">）落幕</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">952</span></span></p></td></tr><tr style="mso-yfti-irow:7;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">威胁情报平台到底是独占还是重合</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">849</span></span></p></td></tr><tr style="mso-yfti-irow:8;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">思科如何构建安全大模型</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">727</span></span></p></td></tr><tr style="mso-yfti-irow:9;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">ZMap </span></span><span style="font-size:
  12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">十年回首</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">692</span></span></p></td></tr><tr style="mso-yfti-irow:10;mso-yfti-lastrow:yes;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">网络侧典型指纹识别算法</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">571</span></span></p></td></tr></tbody></table><p style="margin-top: 8px;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">按点赞</span><span lang="EN-US"><span leaf="">+</span></span><span leaf="">推荐量排行的 </span><span lang="EN-US"><span leaf="">TOP 10 </span></span><span leaf="">如下所示：</span></span></p><table style="width:410.05pt;background:white;border-collapse:collapse;mso-yfti-tbllook:
 1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="425" width="425" valign="top" style="border: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:
  windowtext;"><span leaf="">文章名称</span></span></b></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:
  windowtext;"><span leaf="">点赞</span><span lang="EN-US"><span leaf="">+</span></span><span leaf="">推荐量</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">IDA </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">插件大赛</span><span lang="EN-US"><span leaf=""> 2024</span></span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">106</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">ATT&amp;CK 2025</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:
  windowtext;"><span leaf="">（</span><span lang="EN-US"><span leaf="">ATT&amp;CKCon 6.0</span></span><span leaf="">）议题慢递</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">32</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">Yara </span></span><span style="font-size:
  12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">退休，</span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">接棒</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">18</span></span></p></td></tr><tr style="mso-yfti-irow:4;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">APT </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">域名与基础设施的生命周期</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">17</span></span></p></td></tr><tr style="mso-yfti-irow:5;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">2025 </span></span><span style="font-size:
  12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">年第四届国际网络安全挑战赛</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">14</span></span></p></td></tr><tr style="mso-yfti-irow:6;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">ATT&amp;CK 2024</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:
  windowtext;"><span leaf="">（</span><span lang="EN-US"><span leaf="">ATT&amp;CKCon 5.0</span></span><span leaf="">）议题慢递</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">13</span></span></p></td></tr><tr style="mso-yfti-irow:7;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">美国网络安全与基础设施安全局的前世今生</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">12</span></span></p></td></tr><tr style="mso-yfti-irow:8;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">人工智能网络挑战赛（</span><span lang="EN-US"><span leaf="">AIxCC</span></span><span leaf="">）落幕</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">11</span></span></p></td></tr><tr style="mso-yfti-irow:9;mso-yfti-lastrow:yes;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">实战派第二期沙龙（办公终端安全）随笔</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">9</span></span></p></td></tr></tbody></table><p style="margin-top: 8px;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">按转发量排行的 </span><span lang="EN-US"><span leaf="">TOP 10 </span></span><span leaf="">如下所示：</span></span></p><table style="width:410.05pt;background:white;border-collapse:collapse;mso-yfti-tbllook:
 1184;mso-padding-alt:0cm 0cm 0cm 0cm;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="425" width="425" valign="top" style="border: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><b><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">文章名称</span></span></b></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;padding: 0cm 5.4pt;"><p style="text-align: center;"><b><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">转发量</span></span></b></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">IDA </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">插件大赛</span><span lang="EN-US"><span leaf=""> 2024</span></span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">392</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">ATT&amp;CK 2025</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:
  windowtext;"><span leaf="">（</span><span lang="EN-US"><span leaf="">ATT&amp;CKCon 6.0</span></span><span leaf="">）议题慢递</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">212</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">Yara </span></span><span style="font-size:
  12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">退休，</span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">接棒</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">121</span></span></p></td></tr><tr style="mso-yfti-irow:4;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">APT </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">域名与基础设施的生命周期</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">109</span></span></p></td></tr><tr style="mso-yfti-irow:5;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">人工智能网络挑战赛（</span><span lang="EN-US"><span leaf="">AIxCC</span></span><span leaf="">）落幕</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">95</span></span></p></td></tr><tr style="mso-yfti-irow:6;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">ATT&amp;CK 2024</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:
  windowtext;"><span leaf="">（</span><span lang="EN-US"><span leaf="">ATT&amp;CKCon 5.0</span></span><span leaf="">）议题慢递</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">81</span></span></p></td></tr><tr style="mso-yfti-irow:7;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">网络侧典型指纹识别算法</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">50</span></span></p></td></tr><tr style="mso-yfti-irow:8;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">美军第十八空降军研发人工智能系统</span><span lang="EN-US"><span leaf=""> Maven  </span></span><span leaf="">探秘</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">47</span></span></p></td></tr><tr style="mso-yfti-irow:9;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">威胁情报平台到底是独占还是重合</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">44</span></span></p></td></tr><tr style="mso-yfti-irow:10;mso-yfti-lastrow:yes;"><td data-colwidth="425" width="425" valign="top" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;mso-color-alt:windowtext;"><span leaf="">思科如何构建安全大模型</span></span></p></td><td data-colwidth="122" width="122" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;color: black;"><span leaf="">41</span></span></p></td></tr></tbody></table><p style="margin-top: 16px;"><b><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 17px;">总结</span></span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">前两年微信公众号修改推送逻辑的时候，我就感叹算法凶猛，现在依然是这种感觉。从数据来看，现在很大的大 </span><span lang="EN-US"><span leaf="">V </span></span><span leaf="">转发了文章才能和推荐带来的流量抗衡。否则一般情况下，推荐带来的流量至少要占到一半以上。各家平台全面转向了推荐算法主导，从我个人的角度来说更加敬畏流量。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">今年另一重感受就是 </span><span lang="EN-US"><span leaf="">AI </span></span><span leaf="">技术迭代一日千里，此前一直算是保守派没有广泛使用，今年在 </span><span lang="EN-US"><span leaf="">Deepseek </span></span><span leaf="">炸场后我个人算是正式在日常工作生活中引入大模型驱动的 </span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">PS</span></span><span leaf="">：</span><span lang="EN-US"><span leaf="">Gemini </span></span><span leaf="">确实好用）。各家轮番推出更新更强的大模型产品，不断刷新突破技术边界。拥抱变化是题中应有之义，更多可能也是不得已为之。（</span><span lang="EN-US"><span leaf="">PS</span></span><span leaf="">：本公众号的文章还不能让大模型代劳，等到大模型能代写的时候可能就不需要再写文了）</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在未来的一年，公众号仍然会持续更新。已经五年了，肯定不会跑的是不是。尽可能地带来有价值的内容也是初衷，希望这些文章可以帮助到有需要的人或者能够为各位带来一点点启迪。今年有很多高校等科研单位的读者关注，希望能在各位学术研究的道路上做一个坚定的同行人。如果有想要沟通和提出建议的，可以在私信告诉我有什么需要改进的地方。一定虚心接受，但有可能坚决不改。</span><span lang="EN-US"><span leaf="">(^_^)</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">同时，今年也在尝试走出去，和更多业界的人进行交流与讨论。在此也特别感谢实战派的几位大佬与多位业界同仁，没有你们的帮助俺可不中啦。如果有想要沟通和讨论的，欢迎私信沟通或者加好友私聊，随时恭候各位大驾光临。（</span><span lang="EN-US"><span leaf="">PS</span></span><span leaf="">：拉群的问题有相当多的人私信，但现在到短期的未来内仍然不打算拉群，还是谨言慎行的好）</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004498" class="rich_pages wxw-img" data-ratio="0.5462962962962963" data-type="png" data-w="1080" height="302" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=df1e8ef8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYaibI7ZeuUiavMyA7qKkxy2n4TjeKnnQ2FgXTAsxAgcboq8Cc5ZHL1pRzrMY0RHuiaUAoXCXBW8HIibog%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">标题用了朱敦儒的西江月，结尾就用苏轼的满庭芳吧。万事看开，身体健康与生活幸福最重要。</span></span></p><p style="text-align: center;margin-bottom: 0px;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">蜗角虚名，蝇头微利，算来著甚干忙。</span></span></p><p style="text-align: center;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">事皆前定，谁弱又谁强。</span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f3df49e3&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488151%26idx%3D1%26sn%3De2efb7b889a559d817c2827a6f1ced31">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 25 Dec 2025 09:02:00 +0800</pubDate>
    </item>
    <item>
      <title>从 Llama 3 的训练了解大规模 AI 基础设施的可靠性</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488141&amp;idx=1&amp;sn=2b86f6ef9f02eb20ecf233106656c7dc</link>
      <description>规模效应带来了可靠性危机，训练用到的显卡规模庞大，自身也经常会出问题。</description>
      <content:encoded><![CDATA[<p>原创 <span>Avenger</span> <span>2025-12-23 09:01</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=6b18f636&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FdlhiccJOdNYbiaVcJq8vZwpgiaE6u9pI0eu9xMiaYpPwHbItlQ77hTSjySanDBxdvafb9R9xCnyr28veRtrKVYBZag%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>规模效应带来了可靠性危机，训练用到的显卡规模庞大，自身也经常会出问题。</p>
  <p data-pm-slice="0 0 []"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作来源</span></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">DSN 2025</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Large-Scale AI Infra Reliability: Challenges, Strategies, and Llama 3 Training Experience</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作背景</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">规模效应带来了可靠性危机，大模型的训练要用到成千上万个 </span><span lang="EN-US"><span leaf="">GPU </span></span><span leaf="">组成的庞大集群，例如 </span><span lang="EN-US"><span leaf="">Llama 3 405B </span></span><span leaf="">模型就是 </span><span lang="EN-US"><span leaf="">Meta </span></span><span leaf="">在一万六千张 </span><span lang="EN-US"><span leaf="">GPU </span></span><span leaf="">的集群上训练的。</span><span lang="EN-US"><span leaf="">GPU </span></span><span leaf="">集群要高度互联且同步运行，单卡故障可能影响整体的训练任务。在各家的信息披露中，网络故障也是被提到的主要问题之一。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100004487" data-ratio="0.36324167872648333" width="553" data-type="png" data-w="691" height="201" src="https://wechat2rss.xlab.app/img-proxy/?k=ef17d7f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYbiaVcJq8vZwpgiaE6u9pI0eumJZvxUubJdYuQ2KsNKZn7quNcjZkcvgRz0Sj0MSXGqBsLpE7nUR2xQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Meta </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在 </span><span lang="EN-US"><span leaf="">16384 </span></span><span leaf="">张 </span><span lang="EN-US"><span leaf="">H100 GPU </span></span><span leaf="">上训练 </span><span lang="EN-US"><span leaf="">405B </span></span><span leaf="">的 </span><span lang="EN-US"><span leaf="">Llama 3 </span></span><span leaf="">时，</span><span lang="EN-US"><span leaf="">54 </span></span><span leaf="">天里遇到 </span><span lang="EN-US"><span leaf="">466 次故障中断。其中最常见的问题就是 </span></span><span lang="EN-US"><span leaf="">GPU </span></span><span leaf="">故障：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004483" class="rich_pages wxw-img" data-ratio="0.6046176046176046" data-type="png" data-w="693" height="335" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=fc31da21&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYbiaVcJq8vZwpgiaE6u9pI0euYMxve7yb2B0ypCOoI6O7zp5yr4oeFABdc5RFt1W8vAtnKezNGjfjYQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">阿里巴巴在 </span><span lang="EN-US"><span leaf="">H800 GPU </span></span><span leaf="">上进行训练，消耗资源最多的 </span><span lang="EN-US"><span leaf="">5% </span></span><span leaf="">任务失败率高达 </span><span lang="EN-US"><span leaf="">43.4%</span></span><span leaf="">，最常见的问题是 </span><span lang="EN-US"><span leaf="">NCCL Timeout</span></span><span leaf="">：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004486" class="rich_pages wxw-img" data-ratio="0.7041847041847041" data-type="png" data-w="693" height="390" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=bbc99feb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYbiaVcJq8vZwpgiaE6u9pI0eup45lrFyfFibsaQS2bstlR7d36VibJlxoCWib5wUql7zTGY8lsLOFGIW4Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作准备</span></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Llama 3 </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在一万六千余张 </span><span lang="EN-US"><span leaf="">H100 GPU </span></span><span leaf="">上进⾏训练，每个 </span><span lang="EN-US"><span leaf="">GPU </span></span><span leaf="">配备 </span><span lang="EN-US"><span leaf="">80GB HBM3 </span></span><span leaf="">显存，使⽤ </span><span lang="EN-US"><span leaf="">Meta </span></span><span leaf="">的 </span><span lang="EN-US"><span leaf="">Grand Teton AI </span></span><span leaf="">平台。每台服务器配备 </span><span lang="EN-US"><span leaf="">8 </span></span><span leaf="">个 </span><span lang="EN-US"><span leaf="">GPU </span></span><span leaf="">和 </span><span lang="EN-US"><span leaf="">2 </span></span><span leaf="">个 </span><span lang="EN-US"><span leaf="">CPU</span></span><span leaf="">。在同⼀台服务器内，</span><span lang="EN-US"><span leaf="">8 </span></span><span leaf="">个 </span><span lang="EN-US"><span leaf="">GPU </span></span><span leaf="">通过 </span><span lang="EN-US"><span leaf="">NVLink </span></span><span leaf="">连接。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">工作评估</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">硬件中断的趋势和总体中断的趋势高度吻合，硬件故障是导致训练中断的主要原因。（注：异常尖峰是可修复的软件问题）</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004485" class="rich_pages wxw-img" data-ratio="0.5982658959537572" data-type="png" data-w="692" height="331" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=297eeaa3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYbiaVcJq8vZwpgiaE6u9pI0euaR48GOhp1oLAsscMowRTYibp9SDPI3icuSyrxTib1Qv3pdqPDUJH0T5kQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">用于训练的服务器中平均每日每千台服务器中断 </span><span lang="EN-US"><span leaf="">4.5 </span></span><span leaf="">次，硬件导致的中断占 </span><span lang="EN-US"><span leaf="">50%</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004484" class="rich_pages wxw-img" data-ratio="0.5930735930735931" data-type="png" data-w="693" height="329" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=622286aa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYbiaVcJq8vZwpgiaE6u9pI0euwdicq6sGREZdTBZicibhicAwjps9PuCaa31b8ibG3rF5wLWNja4gSkgeG0g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">GPU </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">相关的问题最常见的是“掉卡（</span><span lang="EN-US"><span leaf="">GPU </span></span><span leaf="">从总线上消失）”、“</span><span lang="EN-US"><span leaf="">ECC </span></span><span leaf="">内存错误”、“时钟频率节流（单个 </span><span lang="EN-US"><span leaf="">GPU </span></span><span leaf="">时钟被压制后拖慢所有 </span><span lang="EN-US"><span leaf="">GPU</span></span><span leaf="">）”，其他错误感兴趣的读者请移步原文。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004488" class="rich_pages wxw-img" data-ratio="0.6026011560693642" data-type="png" data-w="692" height="334" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=c89712e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYbiaVcJq8vZwpgiaE6u9pI0euRdnU21NHZa2wMNWiapG9mB4mxygBhKNVb6psqUtuafbX5XbgibI8P8Gw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">可靠性增强的三种策略：</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">1</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">、<span textstyle="" style="font-weight: bold;">硬件验证</span>：在训练任务开始前或系统空闲时，通过一系列测试来主动发现有问题的硬件，防患于未然。</span><span lang="EN-US"><span leaf="">Google </span></span><span leaf="">在 </span><span lang="EN-US"><span leaf="">TPU </span></span><span leaf="">上会执行检查，微软开发了基准测试集合，字节跳动会执行轻量级诊断测试。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">、<span textstyle="" style="font-weight: bold;">故障检测</span>：在任务运行时，快速、实时地检测硬件故障，以便尽快恢复。使用 </span><span lang="EN-US"><span leaf="">NVIDIA DCGM </span></span><span leaf="">工具集来监控 </span><span lang="EN-US"><span leaf="">GPU </span></span><span leaf="">的温度、功耗、内存使用等，各家也在开发各种工具检测缓解静默数据损坏</span><span lang="EN-US"><span leaf="">/SDC </span></span><span leaf="">等错误。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">3</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">、<span textstyle="" style="font-weight: bold;">检查恢复</span>：定期保存训练状态（检查点），在发生故障后可以从最近的检查点恢复，而不是从头开始。微软 </span><span lang="EN-US"><span leaf="">DeepSpeed</span></span><span leaf="">、字节跳动 </span><span lang="EN-US"><span leaf="">MegaScale </span></span><span leaf="">都使用所有节点同步暂停保存状态的方式，而 </span><span lang="EN-US"><span leaf="">Acme </span></span><span leaf="">采用各节点独立保存检查点的方式。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作思考</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在超大规模集群上训练大模型，对可靠性提出了巨大挑战。各家的监控指标不同，</span><span lang="EN-US"><span leaf="">Meta </span></span><span leaf="">内部发现有效训练时间（</span><span lang="EN-US"><span leaf="">ETT</span></span><span leaf="">）和 </span><span lang="EN-US"><span leaf="">Goodput </span></span><span leaf="">这类指标更有用，业界也急需建立一套共识标准。</span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4c46c6aa&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488141%26idx%3D1%26sn%3D2b86f6ef9f02eb20ecf233106656c7dc">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 23 Dec 2025 09:01:00 +0800</pubDate>
    </item>
    <item>
      <title>Yara 退休，Yara-X 接棒</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488130&amp;idx=1&amp;sn=61edd91f11250d33b26f465f97235385</link>
      <description>Yara 已经服役十五年，新生代 Yara-X 接下责任。</description>
      <content:encoded><![CDATA[<p>原创 <span>Avenger</span> <span>2025-12-17 09:00</span> <span style="display: inline-block;">北京</span></p>




  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=3b500f30&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FdlhiccJOdNYY96xib6oW8ern2lnZuYGxictgOj2FIPd92smeQ5xDOYEWicJDwcmHMGfia03csprxzmxwh2eLZPvktGQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>Yara 已经服役十五年，新生代 Yara-X 接下责任。</p>
  <p data-pm-slice="0 0 []"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">十五年来，</span><span lang="EN-US"><span leaf="">Yara </span></span><span leaf="">已然成为全球恶意软件分析、威胁情报、威胁狩猎以及数字取证领域的基石。研究人员通过其灵活的语法和强大的模块化设计，定义基于文本或二进制模式的规则来分类和识别恶意软件。随着形势的变化，</span><span lang="EN-US"><span leaf="">Yara </span></span><span leaf="">面临着日益严峻的挑战。随着规则数量的爆炸式增长（达到数万甚至数十万条）以及待扫描文件体积和数量的剧增，</span><span lang="EN-US"><span leaf="">C </span></span><span leaf="">语言编写的 </span><span lang="EN-US"><span leaf="">Yara </span></span><span leaf="">在内存安全管理、并发处理以及代码维护性方面的固有局限性开始暴露。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004472" class="rich_pages wxw-img" data-ratio="0.7254335260115607" data-type="png" data-w="692" height="402" style="width:444px;height:322px;" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=48f6b1f9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYY96xib6oW8ern2lnZuYGxictiaZMrpbPp1TgNBK3GK2bIic0HsboBQFQZibbrHtwCQd9ynmCLvWzEXWEA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 17px;font-weight: bold;">重大改进</span></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2025 </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">年 </span><span lang="EN-US"><span leaf="">6 </span></span><span leaf="">月 </span><span lang="EN-US"><span leaf="">4 </span></span><span leaf="">日 </span><span lang="EN-US"><span leaf="">YARA-X 1.0.0 </span></span><span leaf="">版本发布，</span><span lang="EN-US"><span leaf="">VirusTotal </span></span><span leaf="">宣布原 </span><span lang="EN-US"><span leaf="">Yara </span></span><span leaf="">项目正式进入</span><span lang="EN-US"><span leaf="">&#34;</span></span><span leaf="">维护模式。</span><span lang="EN-US"><span leaf="">VirusTotal </span></span><span leaf="">期望通过 </span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">解决历史三大核心问题：</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">① </span><span lang="EN-US"><span leaf="">Yara </span></span><span leaf="">处理不可信输入文件的安全工具，</span><span lang="EN-US"><span leaf="">C </span></span><span leaf="">语言的内存管理机制会带来内存安全性问题。在 </span><span lang="EN-US"><span leaf="">C </span></span><span leaf="">语言实现中，解析畸形的 </span><span lang="EN-US"><span leaf="">PE </span></span><span leaf="">文件或构造精巧的恶意样本时，解析器往往面临崩溃风险，甚至可能被利用执行任意代码。</span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">使用 </span><span lang="EN-US"><span leaf="">Rust </span></span><span leaf="">重写，在编译阶段杜绝了绝大多数内存安全问题，从而显著提升了引擎的鲁棒性。基于 </span><span lang="EN-US"><span leaf="">Rust </span></span><span leaf="">的语言特性，重新将 </span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">的扫描器设计为无状态的，在多核机器上实现近乎线性的性能扩展。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">② </span><span lang="EN-US"><span leaf="">Yara </span></span><span leaf="">在处理包含复杂循环或大规模正则表达式的规则时，性能急剧下降后容易导致扫描超时。</span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">引入 </span><span lang="EN-US"><span leaf="">WebAssembly </span></span><span leaf="">作为中间层，将规则解析为抽象语法树并编译为 </span><span lang="EN-US"><span leaf="">WASM </span></span><span leaf="">字节码，进而通过 </span><span lang="EN-US"><span leaf="">JIT/AOT </span></span><span leaf="">转换为原生机器码，极大地提升了执行效率。另外，使用 </span><span lang="EN-US"><span leaf="">WASM </span></span><span leaf="">后也可以支持跨平台以及沙箱隔离。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">③ </span><span lang="EN-US"><span leaf="">Yara </span></span><span leaf="">不同功能的代码紧密耦合在一起，难以进行扩展和重构。</span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">将解析器、编译器和扫描器分离，通过模块化设计降低二开与集成的门槛。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004473" class="rich_pages wxw-img" data-ratio="0.9075144508670521" data-type="png" data-w="692" height="502" style="width:504px;height:457px;" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=941ff776&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYY96xib6oW8ern2lnZuYGxict6n8fD2m4psrnDsgY3S7w1Hc9x9iaFXSSCP8icHjKGrEFyfHV9ibEDIaEA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 17px;font-weight: bold;">性能提升</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">经过数月的生产环境测试，</span><span lang="EN-US"><span leaf="">VirusTotal </span></span><span leaf="">已经将 </span><span lang="EN-US"><span leaf="">LiveHunt</span></span><span leaf="">（实时扫描）与 </span><span lang="EN-US"><span leaf="">RetroHunt</span></span><span leaf="">（历史回扫）全量迁移到 </span><span lang="EN-US"><span leaf="">Yara-X</span></span><span leaf="">。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在 </span><span lang="EN-US"><span leaf="">Yara </span></span><span leaf="">时代，扫描超时的文件大约有 </span><span lang="EN-US"><span leaf="">2%</span></span><span leaf="">。在 </span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">时代，扫描超时文件的比例下降到 </span><span lang="EN-US"><span leaf="">0.2%</span></span><span leaf="">。这意味着原本无法完成扫描的文件现在可以被成功检测，直接提升了威胁检测的覆盖率。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">针对那些包含大量正则表达式和循环的</span><span lang="EN-US"><span leaf="">&#34;</span></span><span leaf="">复杂</span><span lang="EN-US"><span leaf="">&#34;</span></span><span leaf="">规则，</span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">表现出了</span><span lang="EN-US"><span leaf=""> 5 </span></span><span leaf="">至 </span><span lang="EN-US"><span leaf="">10 </span></span><span leaf="">倍的速度提升（注：纯文本或者简单十六进制场景，</span><span lang="EN-US"><span leaf="">Yara </span></span><span leaf="">仍然比 </span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">快 </span><span lang="EN-US"><span leaf="">2 到 3 </span></span><span leaf="">倍）。在 </span><span lang="EN-US"><span leaf="">Yara </span></span><span leaf="">时代，出于稳定性的考虑，这些可能导致性能下降的规则会抛出告警并在特定场景下拒绝加载这些规则。在 </span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">时代，这些规则也能够正常加载运行，这让研究人员可以更好地专注于检测逻辑。例如检测比特币地址的规则，在 </span><span lang="EN-US"><span leaf="">200MB </span></span><span leaf="">的文件上 </span><span lang="EN-US"><span leaf="">Yara </span></span><span leaf="">需要运行 </span><span lang="EN-US"><span leaf="">20 </span></span><span leaf="">秒，</span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">只需要不到 </span><span lang="EN-US"><span leaf="">1 </span></span><span leaf="">秒即可。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004471" alt="图形用户界面, 应用程序

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.2991329479768786" data-type="png" data-w="692" height="166" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=491b44d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYY96xib6oW8ern2lnZuYGxictRSUCP6FoD2jzkAxxveZHia9whwTYvaLtMg5L7TztoIR3X1UAibQyWBjA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 17px;font-weight: bold;">迁移差异</span></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">VirusTotal </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">提供了 </span><span lang="EN-US"><span leaf="">yara-x check </span></span><span leaf="">功能，可以批量扫描现有的规则库并检查语法错误。典型的差异如下所示：</span></span></p><p style="margin-bottom: 0px;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">① 现在使用负数索引（</span><span lang="EN-US"><span leaf="">@a[-1]</span></span><span leaf="">）会报错</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">② 现在使用重复修饰符（</span><span lang="EN-US"><span leaf="">global global rule</span></span><span leaf="">）会报错</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">③ 现在要求 </span><span lang="EN-US"><span leaf="">base64 </span></span><span leaf="">的字符串最短长度为 </span><span lang="EN-US"><span leaf="">3 </span></span><span leaf="">个字符，并且在同一字符串上应用 </span><span lang="EN-US"><span leaf="">base64 </span></span><span leaf="">和 </span><span lang="EN-US"><span leaf="">base64wide </span></span><span leaf="">并分别指定不同的自定义字母表</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">④ 现在无效的转义字符串会报错，强制要求使用双反斜杠表示字面反斜杠，消除 </span><span lang="EN-US"><span leaf="">Windows </span></span><span leaf="">路径匹配中可能带来的歧义</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004470" class="rich_pages wxw-img" data-ratio="1.879120879120879" data-type="png" data-w="273" height="513" style="width:219px;height:412px;" width="273" src="https://wechat2rss.xlab.app/img-proxy/?k=eb63f253&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYY96xib6oW8ern2lnZuYGxictcoGteB3xtatI0p76WiaY0dGZpbg6RIdHpaUKibgD5LeWrBk4icOREmicZQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Yara </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">时代，模块的结构体定义硬编码在 </span><span lang="EN-US"><span leaf="">C </span></span><span leaf="">代码中，缺乏灵活性且难以与其他语言交互。</span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">时代，强制要求每个模块通过 </span><span lang="EN-US"><span leaf="">Protobuf </span></span><span leaf="">来定义其输出结构。</span><span leaf=""><span textstyle="" style="text-decoration: none;">典型的模块更新包括：基于 </span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="text-decoration: none;">Ru</span>st </span></span><span leaf="">的 </span><span lang="EN-US"><span leaf="">nom </span></span><span leaf="">库，重写了 </span><span lang="EN-US"><span leaf="">Mach-O </span></span><span leaf="">模块。新增了 </span><span lang="EN-US"><span leaf="">LNK</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">DEX </span></span><span leaf="">模块，重写了 </span><span lang="EN-US"><span leaf="">PE </span></span><span leaf="">模块与 </span><span lang="EN-US"><span leaf="">ELF </span></span><span leaf="">模块。并且，</span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">已经不再推荐使用 </span><span lang="EN-US"><span leaf="">Magic </span></span><span leaf="">模块和 </span><span lang="EN-US"><span leaf="">Cuckoo </span></span><span leaf="">模块。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">参考 </span><span lang="EN-US"><span leaf="">Rust </span></span><span leaf="">编译器的输出风格，重构了新版本的命令行工具，会为用户输出上下文、行号以及修复建议。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004474" alt="文本

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.861271676300578" data-type="png" data-w="692" height="477" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=3eb15b19&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYY96xib6oW8ern2lnZuYGxictEYXLfATxykmyDG7VwwuqWx1iaJ2fVoGFWT4C25Oic8bJSvybicKQq0EKA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">引入 </span><span lang="EN-US"><span leaf="">fmt </span></span><span leaf="">格式化工具，自动调整缩进、空格和对齐，为多人协作提供统一的规则风格。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004475" class="rich_pages wxw-img" data-ratio="0.615606936416185" data-type="png" data-w="692" height="341" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=9dafe78e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYY96xib6oW8ern2lnZuYGxict0we99mplLqsOLrS9abfe5icwMxRkVTCHick65pb7HibwUTdGjzRiaTfPzQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">说了这么多好处，接下来谈一谈大家的担忧：</span></span></p><p style="margin-bottom: 0px;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">1</span></span><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">、大家担心 </span><span lang="EN-US"><span leaf="">Rust </span></span><span leaf="">陡峭的学习曲线会阻碍第三方模块的生态繁荣。</span></span></p><p style="margin-bottom: 0px;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">2</span></span><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">、大家担心会像 </span><span lang="EN-US"><span leaf="">Python3 </span></span><span leaf="">与 </span><span lang="EN-US"><span leaf="">Python2 </span></span><span leaf="">一样导致生态割裂。</span></span></p><p style="margin-bottom: 0px;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">3</span></span><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">、大家担心 </span><span lang="EN-US"><span leaf="">Python </span></span><span leaf="">接口库的变迁会带来适配工作量。</span></span></p><p style="margin-top: 16px;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><span textstyle="" style="font-size: 17px;font-weight: bold;">未来发展</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">摆脱了 </span><span lang="EN-US"><span leaf="">C </span></span><span leaf="">语言后，</span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">后续可能会基于 </span><span lang="EN-US"><span leaf="">Rust </span></span><span leaf="">语言特性引入更多高级功能。例如在规则匹配命中后，执行轻量级的操作。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">VirusTotal </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">打算推出基于 </span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">解析器的语言服务器协议（</span><span lang="EN-US"><span leaf="">LSP</span></span><span leaf="">），帮助 </span><span lang="EN-US"><span leaf="">VS Code </span></span><span leaf="">等 </span><span lang="EN-US"><span leaf="">IDE </span></span><span leaf="">提供自动补全、自动跳转、即时错误检查等功能。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">模块设计标准化后，社区可能会出现更多的模块来丰富 </span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">的功能。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 17px;font-weight: bold;">总结</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">对于任何致力于构建现代化、可扩展威胁检测能力的安全团队而言，拥抱 </span><span lang="EN-US"><span leaf="">Yara-X </span></span><span leaf="">不仅是技术升级的选择，更是应对未来复杂威胁的必经之路。</span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247488130">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=75a2385a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488130%26idx%3D1%26sn%3D61edd91f11250d33b26f465f97235385">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 17 Dec 2025 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>人工智能网络挑战赛（AIxCC）落幕</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488117&amp;idx=1&amp;sn=94aa023dc5433df5c1b44d8a3e3b50bd</link>
      <description>人工智能网络挑战赛（AIxCC）不仅是一场技术竞赛，更是全球网络安全防御范式转移的里程碑。</description>
      <content:encoded><![CDATA[<p>原创 <span>Avenger</span> <span>2025-12-15 09:00</span> <span style="display: inline-block;">北京</span></p>




  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=6a575be3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FdlhiccJOdNYYjPAgCLGd7pM7Q2Z1ZfMBJ8K7xGqFHomGaQIoC8nD3OvHY11Z1ShCM0Qd13tOIYcyJERJl3JHH3A%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p data-pm-slice="0 0 []"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">人工智能网络挑战赛（</span><span lang="EN-US"><span leaf="">AIxCC</span></span><span leaf="">）不仅是一场技术竞赛，更是全球网络安全防御范式转移的里程碑。自 </span><span lang="EN-US"><span leaf="">2016 </span></span><span leaf="">年 </span><span lang="EN-US"><span leaf="">DARPA </span></span><span leaf="">举办 </span><span lang="EN-US"><span leaf="">Cyber Grand Challenge</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">CGC</span></span><span leaf="">） 比赛以来，自动化攻防技术虽然取得了一定进展，但始终受限于传统程序分析技术（如符号执行、污点分析）的可扩展性瓶颈。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img alt="徽标, 公司名称

描述已自动生成" class="rich_pages wxw-img" data-imgfileid="100004458" data-ratio="0.6832971800433839" width="369" data-type="png" data-w="461" height="252" src="https://wechat2rss.xlab.app/img-proxy/?k=dde48c5a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYjPAgCLGd7pM7Q2Z1ZfMBJokibPPGeJUUD7XSQiciaRH5fTb8fHWcKRTLUrOQID8meveht0TvXRQgAg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">随着大语言模型（</span><span lang="EN-US"><span leaf="">LLM</span></span><span leaf="">）的爆发，</span><span lang="EN-US"><span leaf="">DARPA </span></span><span leaf="">敏锐地捕捉到了将生成式人工智能与传统形式化方法结合的契机，旨在攻克困扰行业数十年的核心难题：如何以机器的速度和规模，自动发现并修复关键基础设施软件中的漏洞。</span><span lang="EN-US"><span leaf="">AIxCC </span></span><span leaf="">旨在证明，通过构建</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">网络推理系统</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">Cyber Reasoning Systems, CRS</span></span><span leaf="">），可以将漏洞修复周期从</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">数月</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">压缩至</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">分钟</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">级，从而根本性地改变攻防的时间维度。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004461" class="rich_pages wxw-img" data-ratio="0.4558610709117221" data-type="png" data-w="691" height="252" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=f952cf2d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYjPAgCLGd7pM7Q2Z1ZfMBJIjl7kAaR0tSOP2qELib2mKlrmdrKSpwcXsjQvs7OaFg6MEuspMibhoQg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">AIxCC </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">分为两个赛段，即 </span><span lang="EN-US"><span leaf="">2024 </span></span><span leaf="">年的半决赛和 </span><span lang="EN-US"><span leaf="">2025 </span></span><span leaf="">年的决赛：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">半决赛（</span><span lang="EN-US"><span leaf="">2024 </span></span><span leaf="">年 </span><span lang="EN-US"><span leaf="">8 </span></span><span leaf="">月）：</span><span lang="EN-US"><span leaf="">42 </span></span><span leaf="">支队伍在 </span><span lang="EN-US"><span leaf="">DEF CON 32 </span></span><span leaf="">上角逐，最终 </span><span lang="EN-US"><span leaf="">7 </span></span><span leaf="">支队伍脱颖而出，每队获得 </span><span lang="EN-US"><span leaf="">200 </span></span><span leaf="">万美元的研发资金以备战决赛。</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin-bottom: 16px;"><span style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf="">决赛（</span><span lang="EN-US"><span leaf="">2025 </span></span><span leaf="">年 </span><span lang="EN-US"><span leaf="">8 </span></span><span leaf="">月）：决赛在 </span><span lang="EN-US"><span leaf="">DEF CON 33 </span></span><span leaf="">期间举行，环境更为严苛。系统被置于完全隔离的环境中运行，参赛团队在比赛开始后无法对系统进行任何干预。</span></span></p></li></ul><table style="border-collapse:collapse;border:none;mso-border-alt:solid windowtext .5pt;mso-yfti-tbllook:1184;mso-padding-alt:0cm 5.4pt 0cm 5.4pt;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="138" width="138" style="border: 1pt solid windowtext;padding: 0cm 5.4pt;"></td><td data-colwidth="138" width="138" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">半决赛</span></span></p></td><td data-colwidth="138" width="138" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">决赛</span></span></p></td><td data-colwidth="138" width="138" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">提升幅度</span></span></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="138" width="138" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">漏洞检出</span></span></p></td><td data-colwidth="138" width="138" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">37%</span></span></p></td><td data-colwidth="138" width="138" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">77%</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">（</span><span lang="EN-US"><span leaf="">54</span></span><span leaf="">个）</span></span></p></td><td data-colwidth="138" width="138" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">超过</span><span lang="EN-US"><span leaf="">2</span></span><span leaf="">倍</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="138" width="138" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">漏洞修复</span></span></p></td><td data-colwidth="138" width="138" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">25%</span></span></p></td><td data-colwidth="138" width="138" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">61%</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">（</span><span lang="EN-US"><span leaf="">43</span></span><span leaf="">个）</span></span></p></td><td data-colwidth="138" width="138" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">超过</span><span lang="EN-US"><span leaf="">2</span></span><span leaf="">倍</span></span></p></td></tr><tr style="mso-yfti-irow:3;mso-yfti-lastrow:yes;"><td data-colwidth="138" width="138" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">平均修复时间</span></span></p></td><td data-colwidth="138" width="138" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">数小时</span></span></p></td><td data-colwidth="138" width="138" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">45 </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">分钟</span></span></p></td><td data-colwidth="138" width="138" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">显著缩短</span></span></p></td></tr></tbody></table><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">与以往使用小型合成程序的 </span><span lang="EN-US"><span leaf="">CTF </span></span><span leaf="">比赛不同，</span><span lang="EN-US"><span leaf="">AIxCC </span></span><span leaf="">直接使用了支撑全球数字经济的真实开源软件作为靶场。</span><span lang="EN-US"><span leaf="">2023 </span></span><span leaf="">年</span><span lang="EN-US"><span leaf=""> AIxCC </span></span><span leaf="">初创时，组织者雄心勃勃地想要测试多种编程语言编写的项目。然而经过多次考量和多轮反馈，最终只保留了与</span><span lang="EN-US"><span leaf=""> OSS-Fuzz </span></span><span leaf="">兼容的</span><span lang="EN-US"><span leaf=""> C </span></span><span leaf="">和 </span><span lang="EN-US"><span leaf="">Java </span></span><span leaf="">项目，甚至</span><span lang="EN-US"><span leaf=""> Linux </span></span><span leaf="">内核项目也被移除了。</span><span lang="EN-US"><span leaf="">DARPA </span></span><span leaf="">在这些代码库中植入了七十个漏洞，基本涵盖了各类常见漏洞。参赛系统的任务不仅是发现这些漏洞，还要应对代码库中原本可能存在的、未知的 </span><span lang="EN-US"><span leaf="">0day </span></span><span leaf="">漏洞。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">决赛中，七支队伍的 </span><span lang="EN-US"><span leaf="">CRS </span></span><span leaf="">系统在没有人类干预的情况下，成功发现了绝大多数的植入漏洞。更令人瞩目的是，系统发现了 </span><span lang="EN-US"><span leaf="">18 </span></span><span leaf="">个此前未知的 </span><span lang="EN-US"><span leaf="">0day </span></span><span leaf="">漏洞（</span><span lang="EN-US"><span leaf="">6 </span></span><span leaf="">个</span><span lang="EN-US"><span leaf="">C/C++ </span></span><span leaf="">漏洞和 </span><span lang="EN-US"><span leaf="">12 </span></span><span leaf="">个 </span><span lang="EN-US"><span leaf="">Java </span></span><span leaf="">漏洞），并成功修复了其中的 </span><span lang="EN-US"><span leaf="">11 </span></span><span leaf="">个。这一结果打破了“</span><span lang="EN-US"><span leaf="">AI </span></span><span leaf="">只能发现浅层模式漏洞”的质疑，证明了自动化系统已具备深入挖掘复杂逻辑漏洞的能力。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004460" alt="地图

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.5924855491329479" data-type="png" data-w="692" height="328" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=978229bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYjPAgCLGd7pM7Q2Z1ZfMBJwTyf9fsc7UibkY0pJreYVfdPfmNmzkdI4t90sWC5jbAKFQT7K1W6LFw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><table style="border-collapse:collapse;border:none;mso-border-alt:solid windowtext .5pt;mso-yfti-tbllook:1184;mso-padding-alt:0cm 5.4pt 0cm 5.4pt;width:567px;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="60" width="46" style="border: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><span style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">排名</span></span></p></td><td data-colwidth="188" width="131" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><span style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">队伍</span></span></p></td><td data-colwidth="224" width="195" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><span style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">机构背景</span></span></p></td><td data-colwidth="95" width="71" style="border-top: 1pt solid windowtext;border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-image: initial;border-left: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><span style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">奖金</span></span></p></td></tr><tr style="mso-yfti-irow:1;"><td data-colwidth="60" width="46" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">1</span></span></p></td><td data-colwidth="188" width="131" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;layout-grid-mode:
  char;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Team Atlanta</span></span></p></td><td data-colwidth="224" width="195" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;layout-grid-mode:
  char;"><span style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">佐治亚理工</span><span lang="EN-US"><span leaf="">,   Samsung, KAIST, POSTECH</span></span></span></p></td><td data-colwidth="95" width="71" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">$400</span></span><span style="font-family:
  &#34;微软雅黑&#34;,sans-serif;"><span leaf="">万</span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td data-colwidth="60" width="46" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2</span></span></p></td><td data-colwidth="188" width="131" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;layout-grid-mode:
  char;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Trail of Bits</span></span></p></td><td data-colwidth="224" width="195" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;layout-grid-mode:
  char;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Trail of Bits (</span></span><span style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">商业安全公司</span><span lang="EN-US"><span leaf="">)</span></span></span></p></td><td data-colwidth="95" width="71" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">$300</span></span><span style="font-family:
  &#34;微软雅黑&#34;,sans-serif;"><span leaf="">万</span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td data-colwidth="60" width="46" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">3</span></span></p></td><td data-colwidth="188" width="131" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;layout-grid-mode:
  char;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Theori</span></span></p></td><td data-colwidth="224" width="195" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;layout-grid-mode:
  char;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Theori (</span></span><span style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">安全研究机构</span><span lang="EN-US"><span leaf="">)</span></span></span></p></td><td data-colwidth="95" width="71" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">$150</span></span><span style="font-family:
  &#34;微软雅黑&#34;,sans-serif;"><span leaf="">万</span></span></p></td></tr><tr style="mso-yfti-irow:4;"><td data-colwidth="60" width="46" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">4</span></span></p></td><td data-colwidth="188" width="131" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;layout-grid-mode:
  char;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">All You Need Is   A Fuzzing Brain</span></span></p></td><td data-colwidth="224" width="195" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;layout-grid-mode:
  char;"><span style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">德州农工大学等</span></span></p></td><td data-colwidth="95" width="71" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">-</span></span></p></td></tr><tr style="mso-yfti-irow:5;"><td data-colwidth="60" width="46" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">5</span></span></p></td><td data-colwidth="188" width="131" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;layout-grid-mode:
  char;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Shellphish</span></span></p></td><td data-colwidth="224" width="195" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;layout-grid-mode:
  char;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">UCSB (</span></span><span style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">加州大学圣巴巴拉分校</span><span lang="EN-US"><span leaf="">)</span></span></span></p></td><td data-colwidth="95" width="71" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">-</span></span></p></td></tr><tr style="mso-yfti-irow:6;"><td data-colwidth="60" width="46" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">6</span></span></p></td><td data-colwidth="188" width="131" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;layout-grid-mode:
  char;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">42-b3yond-6ug</span></span></p></td><td data-colwidth="224" width="195" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;layout-grid-mode:
  char;"><span style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">西北大学等</span></span></p></td><td data-colwidth="95" width="71" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">-</span></span></p></td></tr><tr style="mso-yfti-irow:7;mso-yfti-lastrow:yes;"><td data-colwidth="60" width="46" style="border-right: 1pt solid windowtext;border-bottom: 1pt solid windowtext;border-left: 1pt solid windowtext;border-image: initial;border-top: none;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">7</span></span></p></td><td data-colwidth="188" width="131" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;layout-grid-mode:
  char;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Lacrosse</span></span></p></td><td data-colwidth="224" width="195" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;layout-grid-mode:
  char;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">SIFT </span></span><span style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">等</span></span></p></td><td data-colwidth="95" width="71" style="border-top: none;border-left: none;border-bottom: 1pt solid windowtext;border-right: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="text-align:center;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">-</span></span></p></td></tr></tbody></table><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004459" alt="徽标

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.16040462427745664" data-type="png" data-w="692" height="89" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=f8e410bc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYjPAgCLGd7pM7Q2Z1ZfMBJH6Isyed6nKfrtpgsKDHziclmYYN47qrxYcMXp5Q6j44EKoqlnJ1NCDw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">此处不过多介绍每个队伍的详细架构设计，只简单介绍一下个人觉得有意思的点。他们都发布了大量相关的材料来进行详细介绍，值得一读。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">① </span><span lang="EN-US"><span leaf="">Atlanta </span></span><span leaf="">发现，直接要求 </span><span lang="EN-US"><span leaf="">LLM“</span></span><span leaf="">修复漏洞</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">往往效果不佳，需要进一步设计提示工程技术。在 </span><span lang="EN-US"><span leaf="">Prompt </span></span><span leaf="">中强制 </span><span lang="EN-US"><span leaf="">LLM </span></span><span leaf="">扮演特定角色，如</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">你是一位来自 </span><span lang="EN-US"><span leaf="">Google DeepMind </span></span><span leaf="">的资深安全研究员</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">或</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">你是一位严谨的代码维护者</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">。实验表明，这种心理暗示能显著提升 </span><span lang="EN-US"><span leaf="">LLM </span></span><span leaf="">生成代码的质量和安全性。甚至在表示“我会给你 </span><span lang="EN-US"><span leaf="">200 </span></span><span leaf="">美元的小费</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">后，大模型生成了更长、更详细的回答。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">② </span><span lang="EN-US"><span leaf="">Atlanta </span></span><span leaf="">的研究人员发现 </span><span lang="EN-US"><span leaf="">80 </span></span><span leaf="">亿参数级别的模型（如 </span><span lang="EN-US"><span leaf="">GPT-4o-mini</span></span><span leaf="">）在代码模式识别任务上往往优于超大模型。小模型足以理解代码结构，且更少出现“过度思考”导致的简单问题复杂化。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">③ 与竞争对手大量使用昂贵的推理模型不同，</span><span lang="EN-US"><span leaf="">Buttercup </span></span><span leaf="">坚持使用成本较低的非推理模型。</span><span lang="EN-US"><span leaf="">Buttercup </span></span><span leaf="">在获得亚军的同时，将每分成本控制在惊人的</span><span lang="EN-US"><span leaf="">  $181</span></span><span leaf="">。这说明只要工程架构得当，无需天价算力也能实现顶级的自动化安全能力。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">④ </span><span lang="EN-US"><span leaf="">Buttercup </span></span><span leaf="">在自动修复方面表现卓越。比赛中，它成功生成并提交了一个长达</span><span lang="EN-US"><span leaf=""> 300 </span></span><span leaf="">多行代码的补丁，成功修复了一个极度复杂的漏洞。这打破了“自动修复只能处理单行代码错误”的刻板印象，展示了 </span><span lang="EN-US"><span leaf="">AI </span></span><span leaf="">系统处理复杂逻辑重构的潜力。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">⑤ </span><span lang="EN-US"><span leaf="">Theori </span></span><span leaf="">在使用纯静态分析不进行 </span><span lang="EN-US"><span leaf="">PoV </span></span><span leaf="">验证的情况下，生成了三个正确的补丁，大模型对代码语义的理解是惊人的。并且 </span><span lang="EN-US"><span leaf="">Theori </span></span><span leaf="">重度使用 </span><span lang="EN-US"><span leaf="">Infer</span></span><span leaf="">，但它的误报率约为</span><span lang="EN-US"><span leaf=""> 99.9%</span></span><span leaf="">。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">⑥ </span><span lang="EN-US"><span leaf="">All You Need Is A Fuzzing Brain </span></span><span leaf="">构建的系统，其超过 </span><span lang="EN-US"><span leaf="">90% </span></span><span leaf="">的代码都是 </span><span lang="EN-US"><span leaf="">AI </span></span><span leaf="">辅助编写的。该系统通过一百个虚拟机的高并发，发现了最多的 </span><span lang="EN-US"><span leaf="">0day </span></span><span leaf="">漏洞。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004462" class="rich_pages wxw-img" data-ratio="0.4638728323699422" data-type="png" data-w="692" height="257" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=e7ec0183&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYjPAgCLGd7pM7Q2Z1ZfMBJ4ZOiciaGE4bpgJsUSXZZH7RePDe5Dfo8dwkuianoXXKDdML6dnR3uicKSw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">CRS </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">完成任务的开销可以低到</span><span lang="EN-US"><span leaf=""> 152 </span></span><span leaf="">美元，当防御成本大幅度降低时，防御者首次在经济曲线上具备了对抗攻击者的潜力。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004463" alt="表格

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.4653179190751445" data-type="png" data-w="692" height="258" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=46df8e4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYjPAgCLGd7pM7Q2Z1ZfMBJ1ibyOWwNCvvmQyz2icMvyKic2kAybic1qicNqAKUkLuRIYEmMDf7UXA3Kgw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">主办方</span><span lang="EN-US"><span leaf=""> DARPA </span></span><span leaf="">与 </span><span lang="EN-US"><span leaf="">Anthropic</span></span><span leaf="">、谷歌、微软和</span><span lang="EN-US"><span leaf=""> OpenAI </span></span><span leaf="">合作举办这场挑战赛，力求推进网络安全与人工智能的产业融合和技术创新。成功进入半决赛的七支队伍，每队获得了</span><span lang="EN-US"><span leaf=""> 200 </span></span><span leaf="">万美元的奖金。总决赛的前三名，分别得到</span><span lang="EN-US"><span leaf=""> 400 </span></span><span leaf="">万美元、</span><span lang="EN-US"><span leaf="">300 </span></span><span leaf="">万美元和</span><span lang="EN-US"><span leaf=""> 150 </span></span><span leaf="">万美元的奖金。合计</span><span lang="EN-US"><span leaf=""> 2250 </span></span><span leaf="">万的奖金加上此前资助七个小微企业赛道的</span><span lang="EN-US"><span leaf=""> 700 </span></span><span leaf="">万美元，再加上决赛后 </span><span lang="EN-US"><span leaf="">DARPA </span></span><span leaf="">又追加的 </span><span lang="EN-US"><span leaf="">140 </span></span><span leaf="">万美元（奖励给进入决赛的其他参赛队伍，以帮助他们将其系统应用于现实世界的关键基础设施组织），</span><span lang="EN-US"><span leaf="">DARPA </span></span><span leaf="">一口气拿出了 </span><span lang="EN-US"><span leaf="">3090 </span></span><span leaf="">万美元（约合</span><span lang="EN-US"><span leaf=""> 2.18 </span></span><span leaf="">亿人民币）。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Anthropic</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">、谷歌、微软和</span><span lang="EN-US"><span leaf="">OpenAI </span></span><span leaf="">共同为本次比赛提供了技术支持，以及每个队伍价值</span><span lang="EN-US"><span leaf="">35</span></span><span leaf="">万美元的大型语言模型额度，确保参赛队伍拥有所需的计算能力。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004464" class="rich_pages wxw-img" data-ratio="0.33910533910533913" data-type="png" data-w="693" height="188" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=2ef3d0e1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYjPAgCLGd7pM7Q2Z1ZfMBJQSHkAQedoL4rMJ5ZJkUqVuwuJDgLnTTCq9fo0lcalJXJmOCS7v3Z3Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">按照现行的规则，在决赛后两周内获奖的队伍要按照开源促进协会（</span><span lang="EN-US"><span leaf="">OSI</span></span><span leaf="">）的许可将 </span><span lang="EN-US"><span leaf="">CRS </span></span><span leaf="">作为开源软件发布。</span></span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="bash"><code><span leaf=""><a href="https://archive.aicyberchallenge.com/" target="_blank">https://archive.aicyberchallenge.com/</a></span></code><br/><code><span leaf=""><a href="https://team-atlanta.github.io/blog/post-afc/" target="_blank">https://team-atlanta.github.io/blog/post-afc/</a></span></code><br/><code><span leaf=""><a href="https://team-atlanta.github.io/artifacts/" target="_blank">https://team-atlanta.github.io/artifacts/</a></span></code><br/><code><span leaf=""><a href="https://taesoo.kim/pubs/2025/kim:atlantis.pdf" target="_blank">https://taesoo.kim/pubs/2025/kim:atlantis.pdf</a></span></code><br/><code><span leaf=""><a href="https://blog.trailofbits.com/2025/08/09/trail-of-bits-buttercup-wins-2nd-place-in-aixcc-challenge/" target="_blank">https://blog.trailofbits.com/2025/08/09/trail-of-bits-buttercup-wins-2nd-place-in-aixcc-challenge/</a></span></code><br/><code><span leaf=""><a href="https://ringzer0.training/countermeasure25-buttercup-and-darpas-ai-cyber-challenge/" target="_blank">https://ringzer0.training/countermeasure25-buttercup-and-darpas-ai-cyber-challenge/</a></span></code><br/><code><span leaf=""><a href="https://theori.io/blog/aixcc-and-roboduck-63447" target="_blank">https://theori.io/blog/aixcc-and-roboduck-63447</a></span></code><br/><code><span leaf=""><a href="https://all-you-need-is-a-fuzzing-brain.github.io/" target="_blank">https://all-you-need-is-a-fuzzing-brain.github.io/</a></span></code><br/><code><span leaf=""><a href="https://b3yond.org/crs" target="_blank">https://b3yond.org/crs</a></span></code><br/></pre></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">DARPA AIxCC 2025 </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">不仅是一场比赛的结束，更是一个时代的开始。它标志着网络安全防御从</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">人力密集型</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的手工时代，正式迈入了</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">计算密集型</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的智能自动化时代。</span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247488117">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=609657eb&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488117%26idx%3D1%26sn%3D94aa023dc5433df5c1b44d8a3e3b50bd">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 15 Dec 2025 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>2025 年第四届国际网络安全挑战赛</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488105&amp;idx=1&amp;sn=20294442e02e6ebafe072cca4668668f</link>
      <description>国际网络安全挑战赛（ICC）是首个全球级 CTF 比赛，今年已经办到第四届。</description>
      <content:encoded><![CDATA[<p>原创 <span>Avenger</span> <span>2025-12-10 09:01</span> <span style="display: inline-block;">北京</span></p>




  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=008a0b16&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FdlhiccJOdNYbdT5dxukQiaQKicRk2hffgDxRP1rMo3VaAoESSNuUeibrmEdh5yvj1kPgia0PKTlzqkRBQP2PyCXbIvg%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>国际网络安全挑战赛（ICC）是首个全球级 CTF 比赛，今年已经办到第四届。</p>
  <p data-pm-slice="0 0 []"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">国际网络安全挑战赛（</span><span lang="EN-US"><span leaf="">ICC</span></span><span leaf="">）是首个全球级</span><span lang="EN-US"><span leaf=""> CTF </span></span><span leaf="">比赛，由欧盟网络安全局（</span><span lang="EN-US"><span leaf="">ENISA</span></span><span leaf="">）与代表八十多个国家的区域组织共同举办。不同于一般的商业 </span><span lang="EN-US"><span leaf="">CTF </span></span><span leaf="">比赛，其核心目标在于构建一个全球性的人才输送管道，通过高强度的对抗演练，选拔并打磨那些能够应对未来 </span><span lang="EN-US"><span leaf="">APT </span></span><span leaf="">威胁的顶尖青年人才（规定参赛者年龄不能超过 </span><span lang="EN-US"><span leaf="">27 </span></span><span leaf="">岁）。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004446" class="rich_pages wxw-img" data-ratio="0.5346820809248555" data-type="png" data-w="692" height="296" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=4ba23e4c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYbdT5dxukQiaQKicRk2hffgDxTf9otqnbMQSkC1BeIyOwWy1Oiakb8ibUH45kZdLibxlmD5j260Vtx3X2w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2025 </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">年 </span><span lang="EN-US"><span leaf="">11 </span></span><span leaf="">月 </span><span lang="EN-US"><span leaf="">11 </span></span><span leaf="">日至 </span><span lang="EN-US"><span leaf="">14 </span></span><span leaf="">日，由日本国家网络安全事件应对与战略研究中心（</span><span lang="EN-US"><span leaf="">NISC</span></span><span leaf="">）主办的第四届国际网络安全挑战赛在东京千叶县幕张成功举办。</span><span lang="EN-US"><span leaf="">ICC 2025 </span></span><span leaf="">不仅汇聚了来自欧洲、亚洲、美国、大洋洲、加拿大、拉丁美洲、非洲及东盟共八大区域的顶尖战队，更成为检验各区域网络攻防实战能力、人才选拔机制有效性以及前沿技术应用水平的“试金石”。</span></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100004443" alt="Image" class="rich_pages wxw-img" data-ratio="0.5627705627705628" data-type="jpeg" data-w="693" height="312" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=a4e09b27&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FdlhiccJOdNYbdT5dxukQiaQKicRk2hffgDx6hWbpytnu1nNns8ZVicOOgIY7XsII9sibbiaKgdicWZdjOvlWUPTK75dDw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">第四届 </span><span lang="EN-US"><span leaf="">ICC </span></span><span leaf="">由日本政府内阁网络安全中心（</span><span lang="EN-US"><span leaf="">NISC</span></span><span leaf="">）主办，这体现了极高的行政规格。</span><span lang="EN-US"><span leaf="">NISC </span></span><span leaf="">作为日本网络安全战略的最高指挥机构，其直接参与确保了赛事在资源调配、基础设施建设及国际协调方面的顺畅 。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004444" alt="图片包含 徽标

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.18759018759018758" data-type="png" data-w="693" height="104" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=6b721cdf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYbdT5dxukQiaQKicRk2hffgDxibl74iaQPia7nChCHL4asviaI7RfPVsuUwu8Mdcxb043nVtf7gpvp8s1jA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">自 </span><span lang="EN-US"><span leaf="">2022 </span></span><span leaf="">年创办以来，</span><span lang="EN-US"><span leaf="">ICC </span></span><span leaf="">迅速确立了其作为</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">网络安全奥运会</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的地位。该赛事的举办地和冠军归属，往往映射出各大洲在网络安全领域的投入力度与组织能力。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2022 </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">年（希腊雅典）：首届赛事，欧洲队夺冠。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2023 </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">年（美国圣地亚哥）：美洲主场，欧洲队卫冕，大洋洲队异军突起获得亚军。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2024 </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">年（智利圣地亚哥）：拉丁美洲主场，欧洲队三连冠，全球各区域代表队格局初步形成。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">2025 </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">年（日本东京）：首次登陆亚洲，不仅参赛队伍扩充至 </span><span lang="EN-US"><span leaf="">8 </span></span><span leaf="">支（新增东盟队）。也更贴近真实世界与前沿科技，模拟了工业控制系统（</span><span lang="EN-US"><span leaf="">ICS</span></span><span leaf="">）环境。</span></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100004445" alt="图像" class="rich_pages wxw-img" data-ratio="0.6661849710982659" data-type="jpeg" data-w="692" height="369" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=a4b6036e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FdlhiccJOdNYbdT5dxukQiaQKicRk2hffgDxNfJoludA7d8Bx3sLEhN4whhrqdfoicp2M0c6RVZfyUB81SLSfhFKLmA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">欧洲队凭借其成熟的跨国选拔体系，成功实现“四连冠”，确立了其在青年人才培养领域的绝对统治地位；东道主亚洲队斩获亚军，展现了该区域在网络实战能力上的显著跃升；美国队位列第三，可能是单打独斗相比多国协作仍略显乏力。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004442" alt="图片包含 图表

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.523121387283237" data-type="png" data-w="692" height="290" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=6bffe091&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYbdT5dxukQiaQKicRk2hffgDxicdqelL7SSRhfoDToDLnUgwZ1jicdbyHcaAl21e94AtC1zuSWfrWSpUg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">比赛分为解题赛和攻防赛两部分，欧洲队、亚洲队和美国队均位列前三：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004447" alt="表格

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.7079646017699115" data-type="png" data-w="565" height="392" style="width:415px;height:294px;" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=e2e86335&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYbdT5dxukQiaQKicRk2hffgDxK2bmpI91mwKR2OeTIfSxNhO0l4gibJVyW2BYaYxicVogrDRODKCGIcicQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004448" alt="表格

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.5592485549132948" data-type="png" data-w="692" height="310" style="width:464px;height:259px;" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=db362b18&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYbdT5dxukQiaQKicRk2hffgDxtFeCpUm2XoJUpauNEThYPud20ibWmdksBSkCm000LSpc1nLm8mjgpvg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">这是东盟地区首次大规模独立组队，超过了拉美队和非洲队，显示了东南亚（如新加坡、越南、印尼）在网络安全教育方面的快速进步。另外非洲队和拉美队与前三名的巨大分差（分数相差 </span><span lang="EN-US"><span leaf="">2-3 </span></span><span leaf="">倍），直观地展示了全球网络防御能力的差距之大。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004451" class="rich_pages wxw-img" data-ratio="0.6401734104046243" data-type="png" data-w="692" height="354" style="width:501px;height:321px;" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=8a500b6a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYbdT5dxukQiaQKicRk2hffgDxUdDKlTClibAbseA1nyghFTmt0MR9nzdBlMMBcG9t6c82BALrgjWTCQw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style=""><span style="font-size:
12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">相当于原来的亚洲队拆分出去了东盟队，亚洲队现在剩下印度、日本、韩国、蒙古与中国台湾。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004449" alt="图片包含 公司名称

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.5809248554913294" data-type="png" data-w="692" height="322" style="width:447px;height:260px;" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=0f91ff14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYbdT5dxukQiaQKicRk2hffgDxF5OCy8k1jKicPqpWlOsITfNTGdPsheIMAF7eGicp2nC1acNzSHxDxvpg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在本届比赛中，</span><span lang="EN-US"><span leaf="">ENISA </span></span><span leaf="">及 </span><span lang="EN-US"><span leaf="">ICC </span></span><span leaf="">组委会特别设立了 </span><span lang="EN-US"><span leaf="">Kunoichi Cyber Games</span></span><span leaf="">（“女忍者”网络安全挑战赛）。</span><span lang="EN-US"><span leaf="">“Kunoichi”</span></span><span leaf="">在日语中意为</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">女忍者</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">，象征着女性在网络空间中同样具备敏捷与力量</span><span leaf="">。本届只有欧洲队、美国队、日本队、英国队共四支队伍，欧洲队同样夺冠。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004450" class="rich_pages wxw-img" data-ratio="0.38872832369942195" data-type="png" data-w="692" height="215" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=8050324d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYbdT5dxukQiaQKicRk2hffgDxrrtYErdmHZZLmdLgz1AicDj0Ro0j3k2hiazzWzYkRMVibOq1b3SB3v3MQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">早在 </span><span lang="EN-US"><span leaf="">2024 </span></span><span leaf="">年 </span><span lang="EN-US"><span leaf="">10 </span></span><span leaf="">月，</span><span lang="EN-US"><span leaf="">ENISA </span></span><span leaf="">就专门组织了全女子集训营，邀请前欧洲网络安全挑战赛（</span><span lang="EN-US"><span leaf="">ECSC</span></span><span leaf="">）的优胜者担任导师。这种针对性的资源投入，使得欧洲女队在技术自信心和团队配合上远超其他队伍。值得注意的是，</span><span lang="EN-US"><span leaf="">ENISA </span></span><span leaf="">将于 </span><span lang="EN-US"><span leaf="">2026 </span></span><span leaf="">年夏季在都柏林举办一场国际女性</span><span lang="EN-US"><span leaf=""> CTF </span></span><span leaf="">比赛，届时将汇聚来自欧洲及合作国家</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">地区的顶尖女性网络安全人才。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004452" class="rich_pages wxw-img" data-ratio="0.630057803468208" data-type="png" data-w="692" height="349" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=6483d276&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYbdT5dxukQiaQKicRk2hffgDxibLicI0iaZT6oQicGgSqbia5VxHSIfFruzcyntnJJeu5bNJXYZC0kWE8vzw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">ICC </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">不仅是比赛，更是培养“下一代网络安全专业人员”的关键机制。就像</span><span lang="EN-US"><span leaf="">ENISA </span></span><span leaf="">执行主任 </span><span lang="EN-US"><span leaf="">Juhan Lepassaar </span></span><span leaf="">所说，才华横溢的年轻人是欧洲的宝贵资产，</span><span lang="EN-US"><span leaf="">ICC </span></span><span leaf="">是确保这些优质资产增值的必要手段。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">希望不久的将来，我们也可以派出我们自己的人才加入亚洲队，和中国香港地区、中国澳门地区、中国台湾地区的同胞并肩作战。也希望，下一次网络安全“奥运会”再回到亚洲举办时，可以在中国的某个城市举办。</span></span></p><blockquote class="js_blockquote_wrap"><div class="js_blockquote_digest"><p><span leaf="">2024 年第三届国际网络安全挑战赛</span></p></div><p class="blockquote_info js_blockquote_source" data-json="%7B%22type%22%3A%22inner%22%2C%22article%22%3A%7B%22title%22%3A%222024%20%E5%B9%B4%E7%AC%AC%E4%B8%89%E5%B1%8A%E5%9B%BD%E9%99%85%E7%BD%91%E7%BB%9C%E5%AE%89%E5%85%A8%E6%8C%91%E6%88%98%E8%B5%9B%22%2C%22url%22%3A%22http%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247487589%26idx%3D1%26sn%3D2560524db45e1c8d14d74f04ef45132e%26chksm%3Dc1e9e7a9f69e6ebfd479db656f8b04447a04ada5af57fbf8666f480075c50abcfc3bfc889b77%23rd%22%2C%22nickname%22%3A%22%E5%A8%81%E8%83%81%E6%A3%B1%E9%95%9C%22%2C%22authorName%22%3A%22Avenger%22%7D%7D"><span class="blockquote_biz">Avenger，公众号：威胁棱镜<a class="blockquote_article" href="http://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247487589&amp;idx=1&amp;sn=2560524db45e1c8d14d74f04ef45132e&amp;chksm=c1e9e7a9f69e6ebfd479db656f8b04447a04ada5af57fbf8666f480075c50abcfc3bfc889b77#rd">2024 年第三届国际网络安全挑战赛</a></span></p></blockquote><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247488105">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=90d8a542&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488105%26idx%3D1%26sn%3D20294442e02e6ebafe072cca4668668f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 10 Dec 2025 09:01:00 +0800</pubDate>
    </item>
    <item>
      <title>Censys 新旧之变</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488089&amp;idx=1&amp;sn=9ef1d57bc99ef1d73e44954bd19d3409</link>
      <description>Censys 十余年已经大变样，如今如何？</description>
      <content:encoded><![CDATA[<p>
原创 <span>Avenger</span> <span>2025-12-04 09:00</span> <span style="display: inline-block;">北京</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=99265aa9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FdlhiccJOdNYZk5SoicSGj18OS3L32K6Y7KzIqEv3v3eT41BicW4tUUdEsrGj6BNstmkKGTFY3n7UIicrcFxKBLzHCw%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>Censys 十余年已经大变样，如今如何？</p>

<p data-pm-slice="0 0 []"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;">工作来源</span></span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">SIGCOMM 2025</span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;">工作背景</span></span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">最初 </span><span lang="EN-US"><span leaf="">Censys </span></span><span leaf="">只是一个提供网络空间扫描数据的学术项目，逐渐对外提供商业服务后，数据的准确性和时效性要比数据的广度更重要。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">现实中，大量服务运行在非标准端口，服务生命周期极短（尤其在云环境中）。并且，由于扫描位置的视野局限，扫描数据不可避免地会存在盲区。</span></span></p><p><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;">工作评估</span></span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Censys </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">不再对用户直接暴露原始的扫描数据，而是以主机（</span><span lang="EN-US"><span leaf="">Host</span></span><span leaf="">）、网络资产与证书三类实体进行数据组织。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">首先进行的 </span><span lang="EN-US"><span leaf="">L4 </span></span><span leaf="">服务探测分为四部分：① 常规扫描，针对 </span><span lang="EN-US"><span leaf="">100 </span></span><span leaf="">个常见端口和 </span><span lang="EN-US"><span leaf="">100 </span></span><span leaf="">个 </span><span lang="EN-US"><span leaf="">IANA </span></span><span leaf="">分配的重要端口；② 高频扫描，针对云服务商的 </span><span lang="EN-US"><span leaf="">300 </span></span><span leaf="">个常用端口；③ 全端口扫描，大约九个月会扫描（</span><span lang="EN-US"><span leaf="">8Gbps </span></span><span leaf="">速度）一遍 </span><span lang="EN-US"><span leaf="">IPv4 </span></span><span leaf="">空间的全部 </span><span lang="EN-US"><span leaf="">65535 </span></span><span leaf="">个端口；④ 预测式扫描，机器学习模型预测非标准端口。后续进行的 </span><span lang="EN-US"><span leaf="">L7 </span></span><span leaf="">服务探测主要是对应用层协议进行识别，支持约 </span><span lang="EN-US"><span leaf="">200 </span></span><span leaf="">种协议。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100004433" data-ratio="0.29624277456647397" width="554" data-type="png" data-w="692" height="164" src="https://wechat2rss.xlab.app/img-proxy/?k=f8ed2349&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZk5SoicSGj18OS3L32K6Y7KMI3EY69jFClbhbH5v0AOJh5b1UpAibTicH9QZmINYJHfBSTiaaIuWYjqw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">整体采用命令查询责任分离（</span><span lang="EN-US"><span leaf="">CQRS</span></span><span leaf="">）架构，写入侧可以高吞吐地接收和处理海量的扫描数据，数据存储在谷歌云的 </span><span lang="EN-US"><span leaf="">Bigtable </span></span><span leaf="">中（</span><span lang="EN-US"><span leaf="">delta encoding </span></span><span leaf="">存储变化），读取侧富化上下文（地理位置、软件指纹等）。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Censys </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">现在在北美（芝加哥）、欧洲（法兰克福）、亚洲（香港）部署了多个扫描点，对扫描路径进行持续优化和调整。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Censys </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">现在使用 </span><span lang="EN-US"><span leaf="">Go </span></span><span leaf="">语言编写的新引擎替换 </span><span lang="EN-US"><span leaf="">Zmap</span></span><span leaf="">，每秒发送 </span><span lang="EN-US"><span leaf="">2650 </span></span><span leaf="">万次探测请求，平均每秒识别 </span><span lang="EN-US"><span leaf="">1.1 </span></span><span leaf="">万个服务（每天 </span><span lang="EN-US"><span leaf="">9.5 </span></span><span leaf="">亿）。</span><span lang="EN-US"><span leaf="">Greynoise </span></span><span leaf="">披露，其蜜罐平均每分钟收到 </span><span lang="EN-US"><span leaf="">20 </span></span><span leaf="">次扫描探测。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">IP </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">服务至少每日刷新一次，</span><span lang="EN-US"><span leaf="">Web </span></span><span leaf="">资产至少每月刷新一次。如果一个服务在一次扫描中无响应，会在 </span><span lang="EN-US"><span leaf="">24 </span></span><span leaf="">小时内从其他扫描点进行探测尝试，同时被标记为待移除，</span><span lang="EN-US"><span leaf="">72 </span></span><span leaf="">小时后仍然无法访问就会被正式移除。</span><span lang="EN-US"><span leaf="">Censys </span></span><span leaf="">的设计是准确性要优先于覆盖率，尽量保证查到的数据都鲜活准确。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">其他网空引擎宣布的服务数量远远超过 </span><span lang="EN-US"><span leaf="">Censys</span></span><span leaf="">，但其中含有大量过时数据。</span><span lang="EN-US"><span leaf="">ZoomEye </span></span><span leaf="">返回的服务中只有 </span><span lang="EN-US"><span leaf="">10% </span></span><span leaf="">是实际在线的，但 </span><span lang="EN-US"><span leaf="">Censys </span></span><span leaf="">这一数值为 </span><span lang="EN-US"><span leaf="">92%</span></span><span leaf="">。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">过滤掉过时数据与重复数据，</span><span lang="EN-US"><span leaf="">Censys </span></span><span leaf="">的活跃服务覆盖率遥遥领先。据估算，</span><span lang="EN-US"><span leaf="">Censys </span></span><span leaf="">覆盖了 </span><span lang="EN-US"><span leaf="">TOP10 </span></span><span leaf="">端口上 </span><span lang="EN-US"><span leaf="">98% </span></span><span leaf="">的服务、</span><span lang="EN-US"><span leaf="">TOP100 </span></span><span leaf="">端口上 </span><span lang="EN-US"><span leaf="">97% </span></span><span leaf="">的服务、全部端口上 </span><span lang="EN-US"><span leaf="">62% </span></span><span leaf="">的服务。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100004430" data-ratio="0.25289017341040465" width="554" data-type="png" data-w="692" height="140" src="https://wechat2rss.xlab.app/img-proxy/?k=0d68b3a6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZk5SoicSGj18OS3L32K6Y7KB2sUIRHAh7sueKwqHlKV7FBNBldHRqd1ibo3VQjGBLPg9yvgxNqdXZw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004431" class="rich_pages wxw-img" data-ratio="0.3236994219653179" data-type="png" data-w="692" height="179" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=a395c259&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZk5SoicSGj18OS3L32K6Y7KhxWfog4MHS9EjddEcdgGicPZu2icSwmWQJUH8D5XjNnT1MCTsYt6NC5g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100004432" data-ratio="0.3901734104046243" width="554" data-type="png" data-w="692" height="216" src="https://wechat2rss.xlab.app/img-proxy/?k=2fdcda30&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZk5SoicSGj18OS3L32K6Y7KpJdu2AYBTTNicTt1VIY1FtazeUj2zKCaKpxp2OnTXgAtTr6MpXZWRlg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004434" class="rich_pages wxw-img" data-ratio="0.7969348659003831" data-type="png" data-w="522" height="333" width="418" src="https://wechat2rss.xlab.app/img-proxy/?k=68be9672&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZk5SoicSGj18OS3L32K6Y7KFVgQh09pG3FLENgJHIVGQ6ONtDcMYw6xmuIKSG7lqsUZEjW3xbZBPA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100004436" data-ratio="0.9739884393063584" width="554" data-type="png" data-w="692" height="539" src="https://wechat2rss.xlab.app/img-proxy/?k=ef848e04&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZk5SoicSGj18OS3L32K6Y7Kof1t4k2b1YE09cS5cW3QqK7vkTvRDHxFspk1SWtDz6PEQwiaicPMUw7g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">部署蜜罐，</span><span lang="EN-US"><span leaf="">Censys </span></span><span leaf="">发现新服务的平均时间为 </span><span lang="EN-US"><span leaf="">12.3 </span></span><span leaf="">小时，而 </span><span lang="EN-US"><span leaf="">Shodan </span></span><span leaf="">需要 </span><span lang="EN-US"><span leaf="">76.5 </span></span><span leaf="">小时。</span><span lang="EN-US"><span leaf="">ZMap </span></span><span leaf="">是以损失 </span><span lang="EN-US"><span leaf="">3% </span></span><span leaf="">响应服务为代价，换取极致的扫描性能的。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100004435" data-ratio="0.9149377593360996" width="386" data-type="png" data-w="482" height="353" src="https://wechat2rss.xlab.app/img-proxy/?k=89bf2e15&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZk5SoicSGj18OS3L32K6Y7KtTCrmp2XYxVHUyKTF48N3gAiaIFt9OggEbY2AibibOgYibU3WuzTB2xnwg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">对 </span><span lang="EN-US"><span leaf="">IPv6 </span></span><span leaf="">的扫描依赖于从 </span><span lang="EN-US"><span leaf="">DNS</span></span><span leaf="">、证书等渠道获取已知的地址，全部 </span><span lang="EN-US"><span leaf="">IPv6 </span></span><span leaf="">空间全面扫描是个巨大挑战。最近也开始采用类似 </span><span lang="EN-US"><span leaf="">6sense </span></span><span leaf="">的方式进行 </span><span lang="EN-US"><span leaf="">IPv6 </span></span><span leaf="">空间扫描，后续会进行扩展。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作思考</span></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Censys </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">早已不是十年前那个 </span><span lang="EN-US"><span leaf="">Censys </span></span><span leaf="">了，</span><span lang="EN-US"><span leaf="">ZMap </span></span><span leaf="">和 </span><span lang="EN-US"><span leaf="">ZGrab </span></span><span leaf="">也都用 </span><span lang="EN-US"><span leaf="">Go </span></span><span leaf="">重写了。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">现在 </span><span lang="EN-US"><span leaf="">Censys </span></span><span leaf="">每年新增 </span><span lang="EN-US"><span leaf="">500TB </span></span><span leaf="">的数据，也在努力开放给社区使用。从 </span><span lang="EN-US"><span leaf="">2018 年</span></span><span leaf="">到 </span><span lang="EN-US"><span leaf="">2024 </span></span><span leaf="">年一共处理了 </span><span lang="EN-US"><span leaf="">959 </span></span><span leaf="">次数据使用申请，为 </span><span lang="EN-US"><span leaf="">1221 </span></span><span leaf="">名研究人员提供了访问权限。截至 </span><span lang="EN-US"><span leaf="">2024 </span></span><span leaf="">年 </span><span lang="EN-US"><span leaf="">11 </span></span><span leaf="">月，仍然有 </span><span lang="EN-US"><span leaf="">239 </span></span><span leaf="">个组织的 </span><span lang="EN-US"><span leaf="">433 </span></span><span leaf="">名研究人员保有访问权限。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Censys </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">也在大力推进公私合作，例如 </span><span lang="EN-US"><span leaf="">2024 </span></span><span leaf="">年 </span><span lang="EN-US"><span leaf="">10 </span></span><span leaf="">月，</span><span lang="EN-US"><span leaf="">Censys </span></span><span leaf="">发现美国 </span><span lang="EN-US"><span leaf="">268 </span></span><span leaf="">个城镇的供水系统可以被未经身份验证的控制。</span><span lang="EN-US"><span leaf="">Censys </span></span><span leaf="">通过与美国环境保护署合作，删除了 </span><span lang="EN-US"><span leaf="">97% </span></span><span leaf="">的威胁。</span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247488089">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=d44460f7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488089%26idx%3D1%26sn%3D9ef1d57bc99ef1d73e44954bd19d3409">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 04 Dec 2025 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>揭开搜索引擎的黑盒子</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488077&amp;idx=1&amp;sn=61eed6d195557be0525101d3f3ecbb6b</link>
      <description>常见的四个网空搜索引擎如何运作？</description>
      <content:encoded><![CDATA[<p>
原创 <span>Avenger</span> <span>2025-12-03 09:00</span> <span style="display: inline-block;">北京</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=9ae61991&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FdlhiccJOdNYZZvo5hQqoC3Fnfr5C5UPsUgIM6tcRrKmZia2Xc1qtEibfqxz7Oq4ZflDiaIzw7uY7kHtTZDAVU7Z1YQ%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>常见的四个网空搜索引擎如何运作？</p>

<p data-pm-slice="0 0 []"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作来源</span></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">NDSS 2025</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作背景</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">网空搜索引擎已经成为了分析人员最常用的工具之一，但业界对这些网空搜索引擎的运作方式仍一无所知。</span></span></p><p><span leaf="" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span textstyle="" style="font-size: 18px;font-weight: bold;">工作设计</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">为了日志便利，某些网络服务会在 </span><span lang="EN-US"><span leaf="">Banner </span></span><span leaf="">中反带出请求者的 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">地址。当扫描方的 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">地址扫描特定服务时，服务会返回一个包含扫描 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">地址的响应信息。这个响应信息可以被公开检索到，信息中的 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">地址也就是扫描的 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">地址。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004414" class="rich_pages wxw-img" data-ratio="0.24566473988439305" data-type="png" data-w="692" height="136" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=f685aa02&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZZvo5hQqoC3Fnfr5C5UPsUdiakLibzsZ11DgUDOJhcxCQApxO362YAv28iaBvIvsksotDCk1tYLhic2w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">基于这种方式，研究人员收集了 </span><span lang="EN-US"><span leaf="">Shodan</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Censys</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">FOFA </span></span><span leaf="">与 </span><span lang="EN-US"><span leaf="">ZoomEye </span></span><span leaf="">共计 </span><span lang="EN-US"><span leaf="">1407 </span></span><span leaf="">个 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">地址（</span><span lang="EN-US"><span leaf="">FOFA</span></span><span leaf="">：</span><span lang="EN-US"><span leaf="">665</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">ZoomEye</span></span><span leaf="">：</span><span lang="EN-US"><span leaf="">166</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Censys</span></span><span leaf="">：</span><span lang="EN-US"><span leaf="">140</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Shodan</span></span><span leaf="">：</span><span lang="EN-US"><span leaf="">91</span></span><span leaf="">）。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100004418" data-ratio="0.7456647398843931" width="554" data-type="png" data-w="692" height="413" src="https://wechat2rss.xlab.app/img-proxy/?k=772b0636&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZZvo5hQqoC3Fnfr5C5UPsUMbqicV2cB1icfEpw51OyAu1PqSzOWMTNhCpsScJDtmPHa6eqHKibSGzwQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">网空搜索引擎也知道此类镜像服务会泄露扫描的 </span><span lang="EN-US"><span leaf="">IP</span></span><span leaf="">，</span><span lang="EN-US"><span leaf="">ZoomEye </span></span><span leaf="">和 </span><span lang="EN-US"><span leaf="">FOFA </span></span><span leaf="">用占位符对扫描 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">进行了替换，但仍然有一些在结果中是可见的。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">值得注意的是，不是所有匹配命中的结果都是正确的，有些蜜罐可能会伪造响应。还要进行过滤：① 有效 </span><span lang="EN-US"><span leaf="">IPv4 </span></span><span leaf="">地址，而非私有地址、多播地址、保留地址 ② 扫描 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">与服务器 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">应该不相同。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通过对数据的分析运营，除了最初的五种镜像服务，还发现了 </span><span lang="EN-US"><span leaf="">74 </span></span><span leaf="">种新的镜像服务。如 </span><span lang="EN-US"><span leaf="">Redis </span></span><span leaf="">的非法访客告警、</span><span lang="EN-US"><span leaf="">ZXFS FTP </span></span><span leaf="">的 </span><span lang="EN-US"><span leaf="">Banner </span></span><span leaf="">等。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100004416" data-ratio="0.32947976878612717" width="554" data-type="png" data-w="692" height="182" src="https://wechat2rss.xlab.app/img-proxy/?k=86717cfc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZZvo5hQqoC3Fnfr5C5UPsUu0Mu5plRt8CibNS4r50uyLuYDGM3m0yfRgLkJqqS1icXoyNlv6bWpQPw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">ZoomEye </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">与 </span><span lang="EN-US"><span leaf="">FOFA </span></span><span leaf="">大约有七成扫描 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">都在中国，</span><span lang="EN-US"><span leaf="">Shodan </span></span><span leaf="">和 </span><span lang="EN-US"><span leaf="">Censys </span></span><span leaf="">的扫描 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">位于美国。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100004417" data-ratio="0.683371298405467" width="351" data-type="png" data-w="439" height="240" src="https://wechat2rss.xlab.app/img-proxy/?k=3534201f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZZvo5hQqoC3Fnfr5C5UPsUToEd9077MMGMMt6ZtoDXNtQdTLYu97D2PuV3eVuk02K6BwMUxeXKsw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作评估</span></span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004415" class="rich_pages wxw-img" data-ratio="0.2398843930635838" data-type="png" data-w="692" height="133" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=0a574bdd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZZvo5hQqoC3Fnfr5C5UPsUv1jZWV1D1jaXdRV1KAR6FFCoqDssklYL5J9wuA2myHjicglCkB4E8Zg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通过位于东京、新加坡、北京与深圳的 </span><span lang="EN-US"><span leaf="">28 </span></span><span leaf="">个蜜罐，一年内收集了和 </span><span lang="EN-US"><span leaf="">Shodan</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Censys</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">FOFA </span></span><span leaf="">与 </span><span lang="EN-US"><span leaf="">ZoomEye </span></span><span leaf="">共 </span><span lang="EN-US"><span leaf="">839 </span></span><span leaf="">个扫描 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">相关的 </span><span lang="EN-US"><span leaf="">740 </span></span><span leaf="">万次扫描。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100004419" data-ratio="0.21676300578034682" width="554" data-type="png" data-w="692" height="120" src="https://wechat2rss.xlab.app/img-proxy/?k=706b9c51&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZZvo5hQqoC3Fnfr5C5UPsU4Wsl2T9kGFOV39VaBtRc4Ulsr9iaq4sPUeBYVsqJuJ3hwmgVR1DmctQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">由于这些 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">地址会大量被标记为“扫描”、“恶意”，固定不变的 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">地址极容易被拉黑。在 </span><span lang="EN-US"><span leaf="">AbuseIPDB </span></span><span leaf="">中，</span><span lang="EN-US"><span leaf="">665 </span></span><span leaf="">个（</span><span lang="EN-US"><span leaf="">47.26%</span></span><span leaf="">）</span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">地址都被打上了标记。</span><span lang="EN-US"><span leaf="">FOFA </span></span><span leaf="">与 </span><span lang="EN-US"><span leaf="">ZoomEye </span></span><span leaf="">根本不使用固定的 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">进行扫描，</span><span lang="EN-US"><span leaf="">FOFA </span></span><span leaf="">大约每三个月就会轮换整个 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">池，而 </span><span lang="EN-US"><span leaf="">ZoomEye </span></span><span leaf="">的 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">是 </span><span lang="EN-US"><span leaf="">ISP </span></span><span leaf="">动态分配的。</span><span lang="EN-US"><span leaf="">Shodan </span></span><span leaf="">和 </span><span lang="EN-US"><span leaf="">Censys </span></span><span leaf="">的扫描 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">则相对稳定。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">大家最关注的端口服务大体类似，基本上都是最常见互联网端口服务。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100004423" data-ratio="0.5844155844155844" width="554" data-type="png" data-w="693" height="324" src="https://wechat2rss.xlab.app/img-proxy/?k=25b5faf5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZZvo5hQqoC3Fnfr5C5UPsUIjwNTPvXTiaqTpf53j1PHTsfibUIc25JJTialHBxiay0o2CMQBMeyaWX0Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">扫描引擎不会傻乎乎地只扫描特定端口，往往会采取两种策略：① 扫描临近端口，例如扫描 </span><span lang="EN-US"><span leaf="">RDP </span></span><span leaf="">时同时覆盖 </span><span lang="EN-US"><span leaf="">3388</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">3389</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">3390 </span></span><span leaf="">三个端口；② 回退尝试其他，在某个端口无法识别协议时尝试其他常见协议（所有引擎都会尝试 </span><span lang="EN-US"><span leaf="">HTTP </span></span><span leaf="">与 </span><span lang="EN-US"><span leaf="">HTTPS</span></span><span leaf="">，</span><span lang="EN-US"><span leaf="">FOFA </span></span><span leaf="">会尝试 </span><span lang="EN-US"><span leaf="">FTP</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">ZoomEye </span></span><span leaf="">会尝试 </span><span lang="EN-US"><span leaf="">RDP</span></span><span leaf="">）。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100004422" data-ratio="0.5216763005780347" width="554" data-type="png" data-w="692" height="289" src="https://wechat2rss.xlab.app/img-proxy/?k=e47cf0dc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZZvo5hQqoC3Fnfr5C5UPsUxic3bVCuKg2AsuibdwLLKOnhpXhTx9SDyzAI7xy7q4AwDvNibM0yaP1YQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">分类识别了 </span><span lang="EN-US"><span leaf="">60 </span></span><span leaf="">种 </span><span lang="EN-US"><span leaf="">TCP </span></span><span leaf="">探测与 </span><span lang="EN-US"><span leaf="">67 </span></span><span leaf="">种 </span><span lang="EN-US"><span leaf="">UDP </span></span><span leaf="">探测，覆盖 </span><span lang="EN-US"><span leaf="">94.8% </span></span><span leaf="">的数据包。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004421" class="rich_pages wxw-img" data-ratio="0.26734104046242774" data-type="png" data-w="692" height="148" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=8fd01e4d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZZvo5hQqoC3Fnfr5C5UPsUmuIMMvAIM5Rfia91Dyicjo88vLZBusJLX5pZRpVtiaMj3L1J6SEgAdOXA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">每个引擎有自己的侧重点，</span><span lang="EN-US"><span leaf="">Shodan </span></span><span leaf="">更关注 </span><span lang="EN-US"><span leaf="">HTTP </span></span><span leaf="">协议、</span><span lang="EN-US"><span leaf="">FOFA </span></span><span leaf="">更关注 </span><span lang="EN-US"><span leaf="">FTP </span></span><span leaf="">协议、</span><span lang="EN-US"><span leaf="">ZoomEye </span></span><span leaf="">更关注 </span><span lang="EN-US"><span leaf="">RDP </span></span><span leaf="">协议。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004420" class="rich_pages wxw-img" data-ratio="0.14450867052023122" data-type="png" data-w="692" height="80" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=51c23ad8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZZvo5hQqoC3Fnfr5C5UPsUlibcdcdx3dKnBianmHaXMORYkvtE8redCSY2PmksGP7nqxibsQleiatnzg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004424" class="rich_pages wxw-img" data-ratio="0.7742402315484804" data-type="png" data-w="691" height="428" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=c96ac0eb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYZZvo5hQqoC3Fnfr5C5UPsUKX3iayHgwH2MKULm4zaJLz793J9JDNYRwhDHRXahI9BnG3ISiaLaR7Qg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">网空扫描缺乏透明度：①</span><span lang="EN-US"><span leaf=""> FOFA </span></span><span leaf="">与 </span><span lang="EN-US"><span leaf="">ZoomEye </span></span><span leaf="">对外不提供扫描 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">的 </span><span lang="EN-US"><span leaf="">WHOIS </span></span><span leaf="">与 </span><span lang="EN-US"><span leaf="">rDNS </span></span><span leaf="">信息 ② 只有 </span><span lang="EN-US"><span leaf="">Censys </span></span><span leaf="">提供了退出选项 ③</span><span lang="EN-US"><span leaf=""> FOFA </span></span><span leaf="">建议想要退出扫描的人“不要把设备放到互联网上” ④</span><span lang="EN-US"><span leaf=""> Censys </span></span><span leaf="">连自己声明的最佳实践都没有做到。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">网空扫描缺乏无害性：①</span><span lang="EN-US"><span leaf=""> ZoomEye </span></span><span leaf="">会发送畸形 </span><span lang="EN-US"><span leaf="">HTTP </span></span><span leaf="">请求 ② 探测未授权访问（获取 </span><span lang="EN-US"><span leaf="">redis </span></span><span leaf="">所有 </span><span lang="EN-US"><span leaf="">key</span></span><span leaf="">、获取 </span><span lang="EN-US"><span leaf="">ES </span></span><span leaf="">所有索引等）③ 除了</span><span lang="EN-US"><span leaf=""> Censys </span></span><span leaf="">都在使用</span><span lang="EN-US"><span leaf=""> rdp-ntlm-info </span></span><span leaf="">中 </span><span lang="EN-US"><span leaf="">CVSS </span></span><span leaf="">评分为 </span><span lang="EN-US"><span leaf="">9.8 </span></span><span leaf="">的漏洞。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">网空扫描缺乏匿名性：①</span><span lang="EN-US"><span leaf=""> Shodan </span></span><span leaf="">列出了 </span><span lang="EN-US"><span leaf="">69543 </span></span><span leaf="">个 </span><span lang="EN-US"><span leaf="">Redis </span></span><span leaf="">的 </span><span lang="EN-US"><span leaf="">key</span></span><span leaf="">，并且付费提供超过全球九十万个摄像头的快照和 </span><span lang="EN-US"><span leaf="">RDP </span></span><span leaf="">截图 ②</span><span lang="EN-US"><span leaf=""> Censys </span></span><span leaf="">泄露了 </span><span lang="EN-US"><span leaf="">230 </span></span><span leaf="">个 </span><span lang="EN-US"><span leaf="">LDAP </span></span><span leaf="">用户的信息 ③</span><span lang="EN-US"><span leaf=""> Shodan </span></span><span leaf="">与 </span><span lang="EN-US"><span leaf="">FOFA </span></span><span leaf="">列出了 </span><span lang="EN-US"><span leaf="">14.5 </span></span><span leaf="">万个 </span><span lang="EN-US"><span leaf="">ES </span></span><span leaf="">数据库索引、</span><span lang="EN-US"><span leaf="">17.8 </span></span><span leaf="">万个 </span><span lang="EN-US"><span leaf="">MongoDB </span></span><span leaf="">索引。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf=""><span textstyle="" style="font-size: 18px;font-weight: bold;">工作思考</span></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">负责任地对外披露对彼此都是一件大好事，研究人员也发现了对扫描进行仿冒和伪造的行为，无法区分正用 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">和废弃 </span><span lang="EN-US"><span leaf="">IP </span></span><span leaf="">不也是与对外披露不透明相关的吗？</span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247488077">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=c99b6ed6&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488077%26idx%3D1%26sn%3D61eed6d195557be0525101d3f3ecbb6b">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 03 Dec 2025 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>ATT&amp;CK 2023（ATT&amp;CKCon 4.0）议题慢递</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488061&amp;idx=1&amp;sn=23563682c3e93ca3e904c864194fd5c5</link>
      <description>ATT&amp;CKCon 4.0 上大家聊了什么？</description>
      <content:encoded><![CDATA[<p>
原创 <span>Avenger</span> <span>2025-11-28 09:00</span> <span style="display: inline-block;">北京</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b25d47ec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKcIh8uNzEdvibgNichY5iaibEX4AdtW93vbfFSGTMZYs9s8TJ8CKoPSXA4Q%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>ATT&CKCon 4.0 上大家聊了什么？</p>

<p data-pm-slice="0 0 []"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">MITRE </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">每年都会开一个名为 </span><span lang="EN-US"><span leaf="">The MITRE ATT&amp;CK® Conference (ATT&amp;CKcon) </span></span><span leaf="">的研讨会，</span><span lang="EN-US"><span leaf="">2023 </span></span><span leaf="">年在弗吉尼亚州召开。</span></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img alt="ATT&amp;CKcon Banner" class="rich_pages wxw-img" data-imgfileid="100004367" data-ratio="0.434971098265896" width="554" data-type="png" data-w="692" height="241" src="https://wechat2rss.xlab.app/img-proxy/?k=10353a60&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKAljekFAteLmRTDcJVzfoPJyXlwypBicib3QneYLBcicOI5ibrjYhxr31fg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">必须强调的是，在提供了公开材料的议题中，只选取了部分议题进行介绍。很多议题也只能选择其中较为亮点的、重要的部分进行一笔带过式的介绍，甚至有些议题没有在本文中被提及，请各位读者见谅。感兴趣的读者可以跳转官网查看完整议程安排。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">若是通过本文的介绍，或者是查看官网议程安排后，对其中某些议题感兴趣的话，就可以在官网下载议题对应的材料进行扩展阅读。</span><span lang="EN-US"><span leaf="">(PS</span></span><span leaf="">：笔者根据自身的认知局限与好恶为部分议题打了推荐查看的星级，不代表对议题实际内容高下的评判，只是为部分时间宝贵的读者再节约些时间，这部分议题相对来说可能更加值得一看</span><span lang="EN-US"><span leaf="">)</span></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">将软件工程实践引入安全检测，释放检测工程潜力 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">检测工程循环：假设情景、调查研究、构建分析逻辑、实施验证、报告修订。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004368" class="rich_pages wxw-img" data-ratio="0.5151953690303908" data-type="png" data-w="691" height="285" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=a7cb68f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKVVujgsPErlf6ezUVT7Rp0APzYOYYTicqz6X2BN4BMhbeicicaq5SmgRibQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">检测即代码，要跟踪谁修改了规则？改了什么？修改会影响检测吗？什么时候修改的？上次修改是什么时候？能保证检测的质量吗？检测逻辑还按预期生效吗？核心在于：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004366" class="rich_pages wxw-img" data-ratio="0.19913419913419914" data-type="png" data-w="693" height="110" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=48c02ef2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKV5yAa7TiagHIc1bYnjubRRgFsdZAibsFQuQcYDibrcPJOGBEIGo5Zib1DA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">构建敏捷流程：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004365" class="rich_pages wxw-img" data-ratio="0.3511560693641618" data-type="png" data-w="692" height="194" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=d09814d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKYC83hAFOEuj1DRSDOArIU2l0Peicanhutz5uYiaDNGrnIcm6lVsdLUvA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">例如使用</span><span lang="EN-US"><span leaf=""> Azure DevOps Boards </span></span><span leaf="">来管理检测规则的生命周期，使其透明化、可视化。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004369" class="rich_pages wxw-img" data-ratio="0.7471098265895953" data-type="png" data-w="692" height="414" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=230b77a1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKatALczKXDibvI0Bnb55jIwloBs06ePIpExMQJqjRxxiaOajwSpa54pVg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">检测规则尽量要选择易于维护的机器可读格式，如</span><span lang="EN-US"><span leaf=""> YAML</span></span><span leaf="">。一定要确定 </span><span lang="EN-US"><span leaf="">Schema</span></span><span leaf="">，方便进行验证和管理。基于 </span><span lang="EN-US"><span leaf="">YAML </span></span><span leaf="">文件，也可以直接生成所有规则的文档知识库。示例：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004372" class="rich_pages wxw-img" data-ratio="0.523121387283237" data-type="png" data-w="692" height="290" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=05897c10&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFK9Lh4FzAOrz2Qm4MZjZKOic1WaTtwlvUV0qpDE78uGvzB5RLmicfFrrDw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">也要保持灵活可配置：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004371" class="rich_pages wxw-img" data-ratio="0.37716763005780346" data-type="png" data-w="692" height="209" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=c9684ce2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKyfCibiaM9jK2l6wcH1nLZTajRLTvpib6JhkUZDA9QpHFLl0icBuhuZXdSg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">使用 </span><span lang="EN-US"><span leaf="">Azure DevOps </span></span><span leaf="">进行版本控制与 </span><span lang="EN-US"><span leaf="">Peer review</span></span><span leaf="">：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004374" class="rich_pages wxw-img" data-ratio="0.4444444444444444" data-type="png" data-w="693" height="246" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=542cdb4b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFK8xVkrUu54p5crynOsKVKhNtX5xIj4yI2Ric7hwY2mZBzrnNL9vWc7Wg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">构建自动验证流水线：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004373" class="rich_pages wxw-img" data-ratio="0.5800865800865801" data-type="png" data-w="693" height="322" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=c1a6af77&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFK2XK1q3jetISyANZTTicn80E7LkibIKibUb80KxpGBwmSm7bhARlJsTfrg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="perl"><code><span leaf="">https:<span class="code-snippet__regexp">//m</span>edium.com/falconforce/deploying-detections-at-scale-part-<span class="code-snippet__number">0x01</span>-<span class="code-snippet__keyword">use</span>-case-<span class="code-snippet__keyword">format</span>-<span class="code-snippet__keyword">and</span>-automated-validation-7bc76bea0f43</span></code></pre></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">单元测试不仅是要测试规则逻辑，也要测试整个数据管道。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004370" class="rich_pages wxw-img" data-ratio="0.3554913294797688" data-type="png" data-w="692" height="197" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=40b5b7b1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKiaIiaFk00sicbR9e72xRqLXoPx0ic61eVBXFNI1PzfPictRrZxnT6RszftQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004376" class="rich_pages wxw-img" data-ratio="0.492040520984081" data-type="png" data-w="691" height="272" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=81183416&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKjWEuWU1HvfTQh5Cuo9sCpUPuXjuhqsd2EfyEFTl7HfzraDE9frkX2w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">测试用例的示例：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004375" class="rich_pages wxw-img" data-ratio="0.3852813852813853" data-type="png" data-w="693" height="214" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=e3f669d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKGJL2Nlvnmgj56CPPvGeIgRC6JCXxvNZSEEAoNHdcjHLiaYB5Kr8QKqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004377" class="rich_pages wxw-img" data-ratio="0.49206349206349204" data-type="png" data-w="693" height="273" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=01970ddc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFK4pyqXtzqkXqkZhUAeWNR3ehDNTRdsSHb0CSz0RSrICuD6yfhUJA1Jg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">向 </span><span lang="EN-US"><span leaf="">CFO </span></span><span leaf="">汇报的艺术 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">技术人员往往沉迷于攻击技术细节，而</span><span lang="EN-US"><span leaf=""> CFO </span></span><span leaf="">只关心</span><span lang="EN-US"><span leaf=""> ROI</span></span><span leaf="">（投资回报率）和风险降低。如何将</span><span lang="EN-US"><span leaf=""> ATT&amp;CK </span></span><span leaf="">的价值转化为</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">钱</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的语言，是每个</span><span lang="EN-US"><span leaf=""> CISO </span></span><span leaf="">的必修课。对 </span><span lang="EN-US"><span leaf="">CFO </span></span><span leaf="">来说，</span><span lang="EN-US"><span leaf="">MITRE ATT&amp;CK </span></span><span leaf="">是专业且深奥的。</span><span lang="EN-US"><span leaf="">CFO </span></span><span leaf="">并不需要了解具体的技术手法，他需要知道</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">我们为什么要花这笔钱，花了之后风险降低了多少</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">。</span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">ATT&amp;CK </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">矩阵的热力图信息过载，缺乏重点，无法直观展示价值。换一个可视化展示方法可能会更好，例如用桑基图。左侧是控制措施，右侧是风险，可以直观展示左侧投资到底在防御哪些风险。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004379" class="rich_pages wxw-img" data-ratio="0.8338150289017341" data-type="png" data-w="692" height="462" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=a7ca3af7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKcTBRsCWFEib2Hyy5V7TydRz6VmE80JoPpMDUxxgSEhyukGGTSLbC7MA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">将抽象的</span><span lang="EN-US"><span leaf=""> ATT&amp;CK </span></span><span leaf="">矩阵转化为动态的攻击流，例如将 </span><span lang="EN-US"><span leaf="">Lazarus </span></span><span leaf="">攻击组织的攻击路径可视化。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004378" class="rich_pages wxw-img" data-ratio="0.2861271676300578" data-type="png" data-w="692" height="158" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=a9ee0ed4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKXSuFQcs8I7SW9HdjxlvDiaFNtr82FUGBF6sob1n2lHp1JxiaZ2aUggSg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">这样一来可以给 </span><span lang="EN-US"><span leaf="">CFO </span></span><span leaf="">解释，如果购买了某些防御措施，可以切断多少攻击路径，风险敞口会减少多少。</span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">利用</span><span lang="EN-US"><span leaf=""> EDR </span></span><span leaf="">遥测验证</span><span lang="EN-US"><span leaf=""> ATT&amp;CK </span></span><span leaf="">技术覆盖率 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">示例为一个</span><span lang="EN-US"><span leaf=""> PowerShell </span></span><span leaf="">命令执行时产生的各类遥测数据：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100004380" data-ratio="0.4790764790764791" width="554" data-type="png" data-w="693" height="266" src="https://wechat2rss.xlab.app/img-proxy/?k=30185b2d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKxGvYpod9gdtqFbkAUzeysAro8kASfcUubQKsaHRlg40MOE9yPWJ2Ng%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">各家数据会被标准化：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004382" class="rich_pages wxw-img" data-ratio="0.319364161849711" data-type="png" data-w="692" height="177" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=49c74c17&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKooxEJVHFH0Er2kGg2aicIFPVibGHiaX0B5GjY2mSxJwcOxUlgPeMZeRqw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">展示了不同数据组件覆盖了多少百分比的</span><span lang="EN-US"><span leaf=""> ATT&amp;CK </span></span><span leaf="">技术：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004381" class="rich_pages wxw-img" data-ratio="0.41389290882778584" data-type="png" data-w="691" height="229" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=b06d0f38&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKsBmyolFhSjULnVhWapjiaHDRjum8ibsdtPianQ61QW9lwCKPI0NLnNl5g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">要构建自动化验证架构：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004384" class="rich_pages wxw-img" data-ratio="0.44653179190751446" data-type="png" data-w="692" height="247" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=176c72ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKC8OJ47s8G8ZKbaf4XJOOibjLwPKmbLuwl2CC08Ymn4R150wR8CuXVqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">很多人认为</span><span lang="EN-US"><span leaf=""> EDR </span></span><span leaf="">记录了“所有事情”，但实际上</span><span lang="EN-US"><span leaf=""> EDR </span></span><span leaf="">为了性能和成本，会丢弃大量数据（特别是文件和注册表操作会被大量过滤）。某些高价值行为（如从浏览器获取凭证）产生的遥测非常嘈杂，通常</span><span lang="EN-US"><span leaf=""> EDR </span></span><span leaf="">只有在生成警报时才会有相关记录，而缺乏原始遥测。如果在验证测试中发现数据丢失，不一定是故障，可能是</span><span lang="EN-US"><span leaf=""> EDR </span></span><span leaf="">的设计特性</span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">如何使用</span><span lang="EN-US"><span leaf=""> MITRE ATT&amp;CK </span></span><span leaf="">框架来评估和提升</span><span lang="EN-US"><span leaf=""> SOC </span></span><span leaf="">成熟度 </span></span></b><b><span lang="EN-US" style="font-size:
12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">SOC </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">的四大支柱：运营、程序、工具与协作。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004383" class="rich_pages wxw-img" data-ratio="0.41125541125541126" data-type="png" data-w="693" height="228" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=e0e27afb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKq6RpB8MJ6TZeY0bvTvSv7I1AkUiawOj9cAOY6fGuGnuib63bjv3dciaVQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">SOC </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">评估工作流：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004385" class="rich_pages wxw-img" data-ratio="0.1936416184971098" data-type="png" data-w="692" height="107" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=9bf5d229&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKH2HmgeYmBZlEJaNNpQ0MdQ03YbOnicpugEJWOicYKcwVHwEAGoNyb8fg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">评估与规划：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004386" class="rich_pages wxw-img" data-ratio="0.32127351664254705" data-type="png" data-w="691" height="178" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=75aca089&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKXfq73CEBWic8rEGzRfcNhUk4LwXfFnVW79T26eQIZSTiahNQjXVBhK4A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">用雷达图衡量当前、一年、两年的维度变化，安全投入要转化成覆盖面积的扩大才能让管理层更好地支持预算。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004388" class="rich_pages wxw-img" data-ratio="0.5007215007215007" data-type="png" data-w="693" height="278" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=20614529&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKic9icR4O5ibXw0ULcaNstia7xeyRicUFlMGky2mmGm8AvD94IO3Vx7UxGGg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">利用</span><span lang="EN-US"><span leaf=""> ATT&amp;CK </span></span><span leaf="">在真实数据中创造攻击者</span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">与其费力搭建靶场，不如直接生成日志。对于训练分析人员使用</span><span lang="EN-US"><span leaf=""> SIEM </span></span><span leaf="">来说，只要日志看着是真的，后台是否有真实的虚拟机并不重要。这种方法极大地降低了成本并提高了扩展性。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">厂商公开报告后，</span><span lang="EN-US"><span leaf="">KC7 </span></span><span leaf="">将其快速转变为配置文件，生成对应的日志供学生练习。培训内容与最新的威胁保持同步。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004387" class="rich_pages wxw-img" data-ratio="0.43867243867243866" data-type="png" data-w="693" height="243" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=5f227b16&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKXLxIHqVRMBnAqeibhetW7ZPSKYUDziasIRPZ3GYrGag9gJryj06L6Mzw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">可以积木化地将攻击生成出来，例如 </span><span lang="EN-US"><span leaf="">T1563 (Remote Service Session Hijacking) </span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">T1560 (Archive Collected Data)</span></span><span leaf="">。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004389" class="rich_pages wxw-img" data-ratio="0.4399421128798842" data-type="png" data-w="691" height="243" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=21242420&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKYm5AGxniagfbX9AkibdmNWdQJSzvn4pOFH4LgDHdW7jLacHcT8pkb3sQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004390" class="rich_pages wxw-img" data-ratio="0.48191027496382055" data-type="png" data-w="691" height="266" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=06c26a86&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKiafybZiagnecPKkt7PJQInovAwf6OX5bzCYdU98HX6p63eFsPFibeP2ug%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通过 </span><span lang="EN-US"><span leaf="">CTF </span></span><span leaf="">的形式，引导学生分析数据：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004393" class="rich_pages wxw-img" data-ratio="0.4083694083694084" data-type="png" data-w="693" height="226" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=a29ed432&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFK6T0gSn4pialRfib11V0qh5aIDhibVLj604t4DfbHG2nVu3T9CIicPxLX4w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">KC7 </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">底层仍然使用标准的 </span><span lang="EN-US"><span leaf="">ATT&amp;CK </span></span><span leaf="">技术与 </span><span lang="EN-US"><span leaf="">JSON </span></span><span leaf="">日志，上层用一个有趣的虚构场景套壳。这种游戏化设计极大地提高了学习者的参与度，特别是对于初学者和年轻学生。</span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">航空电子设备中 </span><span lang="EN-US"><span leaf="">EFB </span></span><span leaf="">的威胁分析 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">航司的攻击面极大，出问题会严重影响业务运营和乘客体验。各种乱七八糟的系统很多，</span><span lang="EN-US"><span leaf="">EFB </span></span><span leaf="">只是这个庞大攻击面中的一个。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004391" class="rich_pages wxw-img" data-ratio="0.6758321273516642" data-type="png" data-w="691" height="374" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=837241e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKdpFltq5TQs4GO5RiaERt5ZQzrRJZDyOib1ZszhwFicIqh5G0wDAVIygxQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">供应链商的第三方也众多，如飞机制造商、维护维修组织</span><span lang="EN-US"><span leaf=""> (MRO)</span></span><span leaf="">、空中交通管制</span><span lang="EN-US"><span leaf=""> (ATC)</span></span><span leaf="">、燃油供应商、地面服务、气象服务等，这种信任关系也为航司带来了极大的风险。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004392" class="rich_pages wxw-img" data-ratio="0.6464646464646465" data-type="png" data-w="693" height="358" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=2f651b91&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKFvfvmbutQ0hMS9OsjZYl0fdvCl6iaYC2wX2sQVXIibU2paObQ95KjGYQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">EFB </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">是连接</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">地面</span><span lang="EN-US"><span leaf=""> IT </span></span><span leaf="">网络</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">和</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">飞机航空电子网络</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的桥梁，也是飞行员获取数据的核心终端。如果是老旧的嵌入式系统，可能运行着过时的操作系统（如</span><span lang="EN-US"><span leaf=""> Windows CE </span></span><span leaf="">或旧版</span><span lang="EN-US"><span leaf=""> Android</span></span><span leaf="">），存在大量已知漏洞。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004394" class="rich_pages wxw-img" data-ratio="0.9942196531791907" data-type="png" data-w="692" height="550" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=3cca04a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKwc5TU7sGt7nzJMupdey0Wc71dRZy6UVbazCibP3XBiaY5tjILwLXp9iaw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">EFB </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">的威胁概览：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004396" class="rich_pages wxw-img" data-ratio="0.4508670520231214" data-type="png" data-w="692" height="250" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=5a40aec8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKTDibdqyp0xgDH8H6hH8SfjRJ6xKrZZibCXRh3qRI7lZRpXPSr3QFPJXg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">相关的 </span><span lang="EN-US"><span leaf="">ATT&amp;CK </span></span><span leaf="">矩阵如下所示：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004398" class="rich_pages wxw-img" data-ratio="0.4869942196531792" data-type="png" data-w="692" height="270" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=36ac13b3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKRxjqIiccj4VEWWjZSJBeGUpibNmDXLqQu1Rib9uWsZobQjwkGzhFy4uIQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在网络数据中寻找关系 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">从风险到控制再到战术数据的分层架构：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004399" class="rich_pages wxw-img" data-ratio="0.4725433526011561" data-type="png" data-w="692" height="262" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=94da67e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKuiaCFrMuIQ1rPavpc3osISPVH6ib8dPsuuPich1eYB234nLkj0Uhxaq3Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">利用有限资源构建不断演变的威胁情报库 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">威胁研究的四大：深度、广度、速度、准确性。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004395" class="rich_pages wxw-img" data-ratio="0.2239884393063584" data-type="png" data-w="692" height="124" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=16cbbd22&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKJkPvy3rtsYNGl2ynRzpRnl18pg7Z2H1icRUzazRKwnoSp9xk5drvcUQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">以</span><span lang="EN-US"><span leaf=""> MITRE </span></span><span leaf="">为基座，在此之上添加私有情报。如果私有情报与官方情报冲突，以私有情报为准。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004397" class="rich_pages wxw-img" data-ratio="0.48917748917748916" data-type="png" data-w="693" height="271" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=071a19cb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKRh0jm3czdfXvvaXttpkVBeZjlSSbfn9mEqo9picatM7vXvHbsTibGiang%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">核心范式转变是将威胁情报作为代码进行管理，可以利用</span><span lang="EN-US"><span leaf=""> Git + Python (Jupyter) + CI/CD (GitHub Actions) </span></span><span leaf="">进行构建和校验。</span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">推动</span><span lang="EN-US"><span leaf=""> Linux </span></span><span leaf="">环境下的</span><span lang="EN-US"><span leaf=""> ATT&amp;CK </span></span><span leaf="">发展 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">如下所示，近年来 </span><span lang="EN-US"><span leaf="">Linux </span></span><span leaf="">环境的威胁日益增加。主要可分为五类：僵尸网络与挖矿木马、访问代理、勒索软件、云</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">供应链威胁、高级威胁。但 </span><span lang="EN-US"><span leaf="">ATT&amp;CK </span></span><span leaf="">目前在 </span><span lang="EN-US"><span leaf="">Linux </span></span><span leaf="">上的技战术并不完整。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004402" class="rich_pages wxw-img" data-ratio="0.4682080924855491" data-type="png" data-w="692" height="259" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=71e3fb9d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKGRNp77CtmsI1bSqrbcibvZia84tEibYlNOEkgUjhBQWsqdfljneGQnWLQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Lazarus </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">和 </span><span lang="EN-US"><span leaf="">LightBasin </span></span><span leaf="">使用了与 </span><span lang="EN-US"><span leaf="">2001 </span></span><span leaf="">年开源代码几乎相同的工具，针对 </span><span lang="EN-US"><span leaf="">AIX </span></span><span leaf="">系统运行支付软件进行攻击、针对电信运营商的 </span><span lang="EN-US"><span leaf="">Solaris </span></span><span leaf="">和 </span><span lang="EN-US"><span leaf="">Linux </span></span><span leaf="">系统进行攻击。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">类似 </span><span lang="EN-US"><span leaf="">TRAM</span></span><span leaf="">，通过词频分析在报告中提取：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004400" class="rich_pages wxw-img" data-ratio="0.4196816208393632" data-type="png" data-w="691" height="232" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=be287ff4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKl61FTO9CguYWXA6V2tFHMNVtp6OdEsq2QO6VZHYvJ3IBN4g3wA9GTA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">可以发现，</span><span lang="EN-US"><span leaf="">Go </span></span><span leaf="">在恶意软件开发中越来越普及；更多恶意软件选择只在内存中运行；开始使用 </span><span lang="EN-US"><span leaf="">eBPF </span></span><span leaf="">等现代内核特性进行深层潜伏。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004401" class="rich_pages wxw-img" data-ratio="0.5043352601156069" data-type="png" data-w="692" height="279" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=ee45616b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFK1flK6SkaCib5BS8TuiaBQqbJOibkQvwNgBYANcp1wX7cKvYZFmcxkuMXA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">应对</span><span lang="EN-US"><span leaf=""> MITRE ATT&amp;CK </span></span><span leaf="">的不同细节层级 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">有些没有数据源的，应该排除，相关人员无法编写检测规则。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004404" class="rich_pages wxw-img" data-ratio="0.5542691751085383" data-type="png" data-w="691" height="306" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=af08166a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKFUCbtfS8gQXLuglvLMhnIO2qovIqdUHpKkJ2SaSEKwibibnb9ee8Ihibw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">要区分</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">理论上可检测</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">和</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">企业内部可检测</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">。除了超大型科技公司，大多数不具备全球视野的机构无法检测。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004403" class="rich_pages wxw-img" data-ratio="0.5332369942196532" data-type="png" data-w="692" height="295" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=5cebe9e5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKOiaMqtZ9VTTRTedwpZn9bn1gSBkmwiacP3RGXnicLIaCgiarWSsSVP4iaPQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">经过层层过滤（无数据源、不可收集、太宽泛、重复等），剩下的矩阵才是检测工程团队真正应该聚焦的核心区域。关注有用的检测规则，而不是所有可检测的检测规则。</span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">模仿复杂攻击者的恶意软件以增强防御能力 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">CrowdStrike </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">的仿真方法论：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004405" class="rich_pages wxw-img" data-ratio="0.43352601156069365" data-type="png" data-w="692" height="240" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=96fe6114&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKQpoibB9ricwArluVW2YXDrFGnrFRSTTUnqWD2kic9M3dpgl4Kepr0R2SQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">“微仿真“是弥合原子测试和完整仿真的平衡点，既容易自动化，又能测试检测逻辑的关联能力。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004407" class="rich_pages wxw-img" data-ratio="0.56998556998557" data-type="png" data-w="693" height="316" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=4fb32f93&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKxFJKiadVbLOBAU6kaX1Zu91icfH5KQv7JjGiacmTH4fkpGHPu1HeDc7vw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">检测与响应策略：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004406" class="rich_pages wxw-img" data-ratio="0.3265895953757225" data-type="png" data-w="692" height="181" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=4e581c64&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKE82PEMOJ35DNYRPVoOjiaJW0ZThIDEfCCeY5ibKfLdNugz39ak7LAjYQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">如何传达威胁情报才能争夺有限注意力 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">现在快速变化的内容减少了我们的注意力容量，干扰打断专注后需要 </span><span lang="EN-US"><span leaf="">23 </span></span><span leaf="">分钟才能重新完全集中注意力。我们正在失去阅读长文的能力，但业界的分析报告却越来越长。可视化比文字更有吸引力，大家最爱看的就是信息图。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">可以尝试将 </span><span lang="EN-US"><span leaf="">ATT&amp;CK </span></span><span leaf="">重构为信息图、热力图：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004408" class="rich_pages wxw-img" data-ratio="1.1690751445086704" data-type="png" data-w="692" height="647" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=862bea2b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFK9fDgm9lDUsbfCMPKvyGrMvdg8XT27vIAib41b6CAibcSqz0pibs1bibPwQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">如果要和高管沟通，</span><span lang="EN-US"><span leaf="">TTP (</span></span><span leaf="">战术、技术、过程</span><span lang="EN-US"><span leaf="">) </span></span><span leaf="">应该转化为 </span><span lang="EN-US"><span leaf="">Risk (</span></span><span leaf="">风险</span><span lang="EN-US"><span leaf="">) </span></span><span leaf="">和 </span><span lang="EN-US"><span leaf="">Cost (</span></span><span leaf="">成本</span><span lang="EN-US"><span leaf="">)</span></span><span leaf="">。不要告诉他们</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">攻击者使用了 </span><span lang="EN-US"><span leaf="">PowerShell”</span></span><span leaf="">，要告诉他们</span><span lang="EN-US"><span leaf="">“</span></span><span leaf="">我们需要投资端点防护，因为 </span><span lang="EN-US"><span leaf="">80% </span></span><span leaf="">的攻击都利用了 </span><span lang="EN-US"><span leaf="">xx </span></span><span leaf="">技术</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">注：完整日程可以点击阅读原文跳转查看。</span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://attack.mitre.org/resources/attackcon/october-2023/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=ca6779e1&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488061%26idx%3D1%26sn%3D23563682c3e93ca3e904c864194fd5c5">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 28 Nov 2025 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>ATT&amp;CK 2024（ATT&amp;CKCon 5.0）议题慢递</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkyMzE5ODExNQ==&amp;mid=2247488012&amp;idx=1&amp;sn=12da242efd6cee3bca6e44a4c9709b45</link>
      <description>ATT&amp;CKCon 5.0 上大家聊了什么？</description>
      <content:encoded><![CDATA[<p>
原创 <span>Avenger</span> <span>2025-11-27 09:00</span> <span style="display: inline-block;">北京</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=22c6cd8e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKeyx0YD4jB7Kx2J7nmEEoIVIico3YjlBn8TNnibXrUjS3ovbeoj8IPGiaQ%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>ATT&CKCon 5.0 上大家聊了什么？</p>

<p data-pm-slice="0 0 []"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">MITRE </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">每年都会开一个名为 </span><span lang="EN-US"><span leaf="">The MITRE ATT&amp;CK® Conference (ATT&amp;CKcon) </span></span><span leaf="">的研讨会，</span><span lang="EN-US"><span leaf="">2024 </span></span><span leaf="">年在弗吉尼亚州 </span><span lang="EN-US"><span leaf="">McLean </span></span><span leaf="">召开。</span></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100004314" alt="ATT&amp;CKcon Banner" class="rich_pages wxw-img" data-ratio="0.32514450867052025" data-type="png" data-w="692" height="180" style="width:476px;height:155px;" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=511bc9ee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKZT1u7Yh0x81aA4fzib2gX75UwmOLaut9oSXmyeJT8xCHTTX45XelvxQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">必须强调的是，在提供了公开材料的议题中，只选取了部分议题进行介绍。很多议题也只能选择其中较为亮点的、重要的部分进行一笔带过式的介绍，甚至有些议题没有在本文中被提及，请各位读者见谅。感兴趣的读者可以跳转官网查看完整议程安排。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">若是通过本文的介绍，或者是查看官网议程安排后，对其中某些议题感兴趣的话，就可以在官网下载议题对应的材料进行扩展阅读。</span><span lang="EN-US"><span leaf="">(PS</span></span><span leaf="">：笔者根据自身的认知局限与好恶为部分议题打了推荐查看的星级，不代表对议题实际内容高下的评判，只是为部分时间宝贵的读者再节约些时间，这部分议题相对来说可能更加值得一看</span><span lang="EN-US"><span leaf="">)</span></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">ATT&amp;CK </span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">与端点检测规则 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">不要把 </span><span lang="EN-US"><span leaf="">ATT&amp;CK </span></span><span leaf="">当作清单使用！对技术项的覆盖度并没有提供给用户能够检测多少 </span><span lang="EN-US"><span leaf="">Procedural </span></span><span leaf="">级威胁的感知。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004318" alt="图形用户界面, 文本, 应用程序, 聊天或短信

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.38672438672438675" data-type="png" data-w="693" height="214" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=869de35f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKGsqM3m820Q9n0RB3jFaxpa6VIVQXjWiaMz2GK89ic06KpfkYvs9Pe7nQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">分析实际 </span><span lang="EN-US"><span leaf="">EDR </span></span><span leaf="">是如何与 </span><span lang="EN-US"><span leaf="">ATT&amp;CK </span></span><span leaf="">结合的。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004317" alt="表格

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.4407514450867052" data-type="png" data-w="692" height="244" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=3bab1dfc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKibxBEatPWOiaqNqQkXgFMt6pC8TIibHT7XKgDScvXx0xfzNBadGyNg2kA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">不同产品在战术和技术上其实大体类似，但每一家都没有做到完全覆盖，且取并集也无法完全覆盖。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004315" alt="图表, 条形图

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.3930635838150289" data-type="png" data-w="692" height="218" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=21231623&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKwX6kgWtAbxZdiasiaUNrl8g3rvsDFlaZAD4PRicZBp2YiaxRZOsJOehBicw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">大量规则其实局限在一小部分技术上，不同产品在技术项的选择上也基本上一致。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004316" alt="图表, 日程表

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.4985549132947977" data-type="png" data-w="692" height="276" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=c5de181d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKAODB25CVA5TF4FpIIFI9D7zre7JaOsv5B6hibPD1qicnR6GiaQIaQuXbw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">不同产品在不同指标上存在很大差异：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004319" alt="图表

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.26695526695526695" data-type="png" data-w="693" height="148" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=9acc2403&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKYP9IEQrCWC21HMqJjKEm2IdL94oskFVGYhxTQSQsSZvaic3vKkVCnoQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">过滤掉中低风险的规则，</span><span lang="EN-US"><span leaf="">Splunk </span></span><span leaf="">和 </span><span lang="EN-US"><span leaf="">Elastic </span></span><span leaf="">的规则数量都减半了。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004322" alt="表格

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.48554913294797686" data-type="png" data-w="692" height="269" style="width:431px;height:209px;" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=7bb7650a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKhiaibxRtEGVs8GeXSGicn4I36MO6SefKdnoAVCmTDIxia5k56507hp64KA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">几款产品都没有覆盖的 </span><span lang="EN-US"><span leaf="">53 </span></span><span leaf="">项技术，有些确实非常难以检测。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004321" class="rich_pages wxw-img" data-ratio="0.8309248554913294" data-type="png" data-w="692" height="460" style="width:404px;height:336px;" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=efc4c3d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKpbibG9vXevzrrD3fGCu060JX2r2IJdiaib9jBiaOSGUqwI36PrM6rhSuaQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">其中，</span><span lang="EN-US"><span leaf="">39.6% </span></span><span leaf="">的技术项都很难检测、</span><span lang="EN-US"><span leaf="">24.5% </span></span><span leaf="">的技术项不适合在端点侧检测。还有一小部分（</span><span lang="EN-US"><span leaf="">17.0%</span></span><span leaf="">）技术项，想要检测需要了解客户特定的信息。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004320" alt="表格

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.37283236994219654" data-type="png" data-w="692" height="206" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=bf6f5d03&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFK4Oo1cib8bibsXgBzvOSefWfRbicBGibAibfibziaI0QwNpFB8X9Yt2IDdQ2Ww%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">不同产品检测相同的威胁，也很少是通过相同的技术项实现的检测。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004323" alt="图表, 气泡图

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="1.05635838150289" data-type="png" data-w="692" height="585" style="width:414px;height:437px;" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=3ec2f49d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKlPXZG6z1pMFUBNQquR0o2JjJJV7gkf1fBgeVUFTPwvdic7696YRWBCQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">与 </span><span lang="EN-US"><span leaf="">Meterpreter </span></span><span leaf="">相关的命名管道检测：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004326" alt="图形用户界面, 文本, 应用程序

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.7167630057803468" data-type="png" data-w="692" height="397" style="width: 416px;height: 298px;" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=c664ed08&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFK2iblTY7SJaVibHMOI4kz3icLwibruUQF1k1vO6FQp83DBUzAxPuCNl4sUA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">与 </span><span lang="EN-US"><span leaf="">FIN7/SUNBURST </span></span><span leaf="">相关的潜在恶意 </span><span lang="EN-US"><span leaf="">DNS </span></span><span leaf="">活动：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004328" alt="文本

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.7687861271676301" data-type="png" data-w="692" height="426" style="width:381px;height:293px;" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=352a6c8e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKnda9vjI3bjZRSzyo1lFq5L4LX7BmY4zHMFWBApjhTbycoTL6Ydv2Tg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">使用“攀登金字塔”框架评估威胁检测弹性 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">回顾一下“痛苦金字塔”：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004325" alt="图示

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.4479768786127168" data-type="png" data-w="692" height="248" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=461af0ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKN64sCJapmZTatWa7FbKfUxP9RJRRY88iadOYYuxMXFBPHOhiaP0qopXw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">不是所有的检测方式都是等同的，要根据攻击者规避检测的难易程度来评估威胁检测规则。越下面的规避越容易，核心技术规避代价很大。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004327" alt="图片包含 图示

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.7142857142857143" data-type="png" data-w="693" height="396" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=3c9a6b45&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKRnI8eIj2UkXl7jvAZtl2n58b3cmmW6uSPjkqibYE0QQbXut3MJp4piaw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">据此，埃森哲可以对厂商的检测响应能力进行比较。以 </span><span lang="EN-US"><span leaf="">Hermetic Wiper </span></span><span leaf="">为例：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004324" class="rich_pages wxw-img" data-ratio="0.43786127167630057" data-type="png" data-w="692" height="242" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=24b164bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKGgu8OIVbwG6HSgupKhoUVCicwPkjHacHRAJmZmOvwMSUfk5iaEx8KfLQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">一个更具体的例子，针对 </span><span lang="EN-US"><span leaf="">T1003.001 </span></span><span leaf="">的检测分级：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004331" class="rich_pages wxw-img" data-ratio="0.8395953757225434" data-type="png" data-w="692" height="465" style="width:389px;height:327px;" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=aef32dc8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKYFxwBLIh6Xp2tRRN9hhtD4GwRI7ia443aLjl7aeYyfIqwHmNQau9wyA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">在某个客户实践“攀登金字塔“框架，其检测规则绝大多数都是 </span><span lang="EN-US"><span leaf="">StP </span></span><span leaf="">小的（容易被规避的）检测规则。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004333" alt="日程表

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.5079365079365079" data-type="png" data-w="693" height="282" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=446cfe05&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFK5VXQ12On5QSKqTXQOoSNFn3Wx5CkiapT5qhvEEZ7MfEgLrMYLBf4pbw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">优秀的运营团队如何转型并赢得胜利 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">SecOps </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">如何推动起来运营：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004330" alt="图形用户界面, 文本

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.9465317919075145" data-type="png" data-w="692" height="524" style="width:478px;height:452px;" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=833cffa6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKU8ShsX4TKDibGiaZqXkSNiaYbMAicKPicbet0s4zOkUd8zbxMLc5M5GDoSQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004332" alt="图形用户界面, 文本, 应用程序

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="1.1849710982658959" data-type="png" data-w="692" height="656" style="width: 516px;height: 611px;" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=d9950d83&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKXCEzZp6Bu2kXsrhSdgDCVlibTsh009gjs3XMdld3zHmTwnOK9vMQklQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">改变与攻击者的博弈局面 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">威胁知情防御（</span><span lang="EN-US"><span leaf="">Threat-Informed Defense</span></span><span leaf="">）旨在系统性地对攻击者技战术进行深刻理解，以改善防御情况。</span><span lang="EN-US"><span leaf="">M3TID </span></span><span leaf="">分为三个部分：威胁情报、防御措施、测试与评估。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004329" alt="图片包含 图示

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.3800578034682081" data-type="png" data-w="692" height="210" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=fb2b8931&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKdcdmohGVk0ibHh9tfZwEL8rorkj2d5ZAPWqMtXPXGAiaAb23QO46kh9g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">每个维度有五个关键组件：</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">威胁情报：① 威胁数据的深度 ② 威胁数据的广度 ③ 威胁数据的相关性 ④ 威胁数据的利用 ⑤ 威胁报告的分发。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">防御措施：① 基础安全 ② 数据收集 ③ 检测工程 ④ 应急响应 ⑤ 欺骗行动。</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">测试与评估：① 测试类型 ② 测试频率 ③ 测试计划 ④ 测试执行 ⑤ 测试结果。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004334" alt="图形用户界面, 应用程序

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.31213872832369943" data-type="png" data-w="692" height="173" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=5b6c8330&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKHyx6D89rkSyqtGn4B25WW1ib4tO8QQQDvKfD8LxADGOOOoDFf1Sibehw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">每个组件还有五级成熟度：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004336" alt="图形用户界面, 应用程序

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.6459537572254336" data-type="png" data-w="692" height="358" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=ac283bd9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKicexOG3X4Nbicxu5ibp3zgKAibLdwaaEsF0QBbM4UIYiaqsnJ8t872icM5Kg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">威胁知情防御中心开展协作研发，包括 </span><span lang="EN-US"><span leaf="">Bank of America, CrowdStrike, Microsoft, Google Cloud, Siemens, Verizon, J.P. Morgan </span></span><span leaf="">等。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004338" alt="图示

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.36075036075036077" data-type="png" data-w="693" height="200" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=73a4f2c5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKN2VAtEuOefucvJI5ZPibib9wxwiccO8rlWyOQym2MpIhM5O3AFwn0LiaibQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">网络安全与保险 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">网络安全是一项商业决策，在评估网络安全支出时公司需要了解 ① 实施需要花费多少成本？② 不实施的话要付出多少代价？</span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">区分网络事件与商业事件，网络事件影响网络基础设施，商业事件会直接产生商业问题。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004337" class="rich_pages wxw-img" data-ratio="0.4624277456647399" data-type="png" data-w="692" height="256" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=003d82cf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFK70QaFhc0ZW1wzJyNwsAguFRqcgj20kcaP1iaD82L4TglhXh83dnyEcQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">保险行业推出 </span><span lang="EN-US"><span leaf="">MMC </span></span><span leaf="">索赔数据模型，红框部分即为 </span><span lang="EN-US"><span leaf="">ATT&amp;CK </span></span><span leaf="">用处。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004335" class="rich_pages wxw-img" data-ratio="0.4508670520231214" data-type="png" data-w="692" height="250" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=6b1de07a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKdE9ZoaK9aCcjt3YWAjnicn9xLHibAJ8rW5gyTsbwTf9xXZWBRfEoZFuQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">ATT&amp;CK </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">可不可以与商业价值挂钩，这样也许可以更直观地进行衡量。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004341" class="rich_pages wxw-img" data-ratio="0.35260115606936415" data-type="png" data-w="692" height="195" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=5765216b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKwn2pc9OXPlxqUz3ribeGAibZKSkOqicvExicnwJVKwiaDWcVIquyDMIjzzg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">每朵云都有“紫色”的希望 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">使用 </span><span lang="EN-US"><span leaf="">ATT&amp;CK </span></span><span leaf="">来分析攻击者技战术，使用 </span><span lang="EN-US"><span leaf="">D3FEND</span></span><span leaf="">（建模、加固、检测、隔离、欺骗、驱逐、恢复）来分析防御对策。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004340" alt="图示

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.3800578034682081" data-type="png" data-w="692" height="210" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=991bdfbb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKw9QicZemibSVD6BtLhKHY7XCjbCtlWT6RXLicGtJLyUwDo6fcQibtUSqug%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">紫队演练流程：①</span><span lang="EN-US"><span leaf=""> ATT&amp;CK </span></span><span leaf="">计划 ② 模拟需求 ③ 取证需求 ④ 攻击者模拟 ⑤ 应急响应 ⑥ 整体分析。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004339" alt="日程表

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.3939393939393939" data-type="png" data-w="693" height="218" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=341f3076&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKFMXJKLpo41t3VfLc0azP7uejklj0afNgrzNJdorAdiasiaUXm1sJfrTA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">利用 </span><span lang="EN-US"><span leaf="">Vector </span></span><span leaf="">对红蓝队攻防与 </span><span lang="EN-US"><span leaf="">ATT&amp;CK </span></span><span leaf="">覆盖度进行跟踪：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004343" alt="图示

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.4031791907514451" data-type="png" data-w="692" height="223" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=3d67cde0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKt5jzeyE22mEpatU6vAdIibQsVGn06siaJ8Go9GkAW1Cszhz3ficmHTib8Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">三位一体协作实现联邦云威胁检测：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004342" alt="图示

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.4725433526011561" data-type="png" data-w="692" height="262" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=92ab7902&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFK28Ws77CbLqHFvicIcibqRLsIuPeBvCAN8coMtGU92KqvACGib2FRsoj5w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">下一代威胁防御中心（</span><span lang="EN-US"><span leaf="">Threat-Informed Defense</span></span><span leaf="">） </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004348" class="rich_pages wxw-img" data-ratio="0.9494219653179191" data-type="png" data-w="692" height="526" style="width:343px;height:326px;" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=cca72339&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFK8CrgACX8L12O4p8k7iaiaMzibtH3KpEib1BQqIfMsXWvnkb2tP4O7WsmSw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">假象一家医疗机构被勒索软件入侵，传统方式威胁情报团队、红队蓝队配合的模式如下所示：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004344" class="rich_pages wxw-img" data-ratio="0.39363241678726485" data-type="png" data-w="691" height="218" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=d76e7eec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFK2zJJtg8FpLjb2RURQF5IKyGaw6y9eyfUfchXwLxedQseRr6UicFGAoA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">引入 </span><span lang="EN-US"><span leaf="">AI Agent </span></span><span leaf="">的模式如下所示：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004346" class="rich_pages wxw-img" data-ratio="0.38872832369942195" data-type="png" data-w="692" height="215" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=4be2d9e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKZ1dmYQNx1VyojdIeCvibmu8cTH3fWN3St1z93ofBzVhDgTQyaQLliaRw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">适用于 </span><span lang="EN-US"><span leaf="">SaaS </span></span><span leaf="">的 </span><span lang="EN-US"><span leaf="">ATT&amp;CK </span></span></span></b><b><span lang="EN-US" style="font-size:
12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">几张示例图：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004345" class="rich_pages wxw-img" data-ratio="0.5621387283236994" data-type="png" data-w="692" height="311" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=ec967a83&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKYhFKEtxfudicLJDPeLFZzQLAYClfPkkAiaTdlNZicS7LU588YP1r9lS1A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004347" class="rich_pages wxw-img" data-ratio="0.5613275613275613" data-type="png" data-w="693" height="311" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=844c923d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKDRUA0sicxnNfSBtCgrj2QOdOlH1B6vzU18shS5knrerHfSb9OKZ1wew%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004353" class="rich_pages wxw-img" data-ratio="0.5520231213872833" data-type="png" data-w="692" height="306" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=37986a12&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKbGia7M7sAARzXW6tS7ic9eDJzLzg1PYMqsu7ZAD7OUYYicnyzGic9HOibFg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">MITRE ATT&amp;CK </span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">现状 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">三十多个 </span><span lang="EN-US"><span leaf="">MITRE </span></span><span leaf="">员工和不断壮大的社区在发展 </span><span lang="EN-US"><span leaf="">ATT&amp;CK</span></span><span leaf="">：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004350" class="rich_pages wxw-img" data-ratio="0.2481962481962482" data-type="png" data-w="693" height="138" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=712d43b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKnH4jibMqGkPBtotj5zWz7FJuJ6OL2Gm05q5L3OttDqGHyeOreKFNEYw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">新增 </span><span lang="EN-US"><span leaf="">44 </span></span><span leaf="">项技术项</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">子技术项、</span><span lang="EN-US"><span leaf="">20 </span></span><span leaf="">个攻击组织；更新 </span><span lang="EN-US"><span leaf="">267 </span></span><span leaf="">项技术项</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">子技术项、</span><span lang="EN-US"><span leaf="">96 </span></span><span leaf="">个攻击组织。</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004351" class="rich_pages wxw-img" data-ratio="0.38439306358381503" data-type="png" data-w="692" height="213" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=ff993830&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKDqyZIn0Bpicn4RVD9PVsIghGcr7X8lRSc5WicuA8OSYeaIK6RFA77OEw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">所在行业通常来说并不影响威胁 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:
微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">行业检出量如下所示：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004349" class="rich_pages wxw-img" data-ratio="0.4725433526011561" data-type="png" data-w="692" height="262" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=9e303f12&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKXvID4NABwD5bjy7vBROshTZXGicpVn8mZjcjCNIVQDogZOvu7EcdnDQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">行业每个客户检出量：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004352" class="rich_pages wxw-img" data-ratio="0.5390173410404624" data-type="png" data-w="692" height="298" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=fc0db378&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKT2tnic0O3k2aJm6Pia6QQIyyVFFCzIsmjpG3GF0L7WmpvmgEV4NQia5wA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">TOP10 </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">技术变迁：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004356" class="rich_pages wxw-img" data-ratio="0.3930635838150289" data-type="png" data-w="692" height="218" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=fa6ec9b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKZicACeEjmBYNzGnnticuUicjovSA150KIKhQkw4ylPh4rmWJwUcvrh2Hg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">通过 </span><span lang="EN-US"><span leaf="">ATT&amp;CK </span></span><span leaf="">深入研究 </span><span lang="EN-US"><span leaf="">Akira </span></span><span leaf="">的 </span><span lang="EN-US"><span leaf="">Linux </span></span><span leaf="">变种 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Linux </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">平台现在勒索软件众多：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004358" class="rich_pages wxw-img" data-ratio="0.3453757225433526" data-type="png" data-w="692" height="191" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=556bc69e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKuBxZ9OTayfKU9iadto97eiaaLic8jccDMlI79jHVMPqTGGPh7UnpjFWwg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">ATT&amp;CK </span></span></b><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">的基本原则 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">本体与数据源：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004355" alt="图示

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.3901734104046243" data-type="png" data-w="692" height="216" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=27cf17dc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKUcRqHsiaSVqgzR6RsaOqdz4D6ibBOnWZc1DOnfWK1nDKCmDWKndZyJpg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">Procedures </span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">逻辑：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004354" alt="图示

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.3569364161849711" data-type="png" data-w="692" height="198" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=011dcb48&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKsqNHoBhAicmBEBLnwqwPj5n4PHBYUVJTEFwYsgpD9VF1gib2yNib9Sp7w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">编写成代码：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004357" alt="手机屏幕截图

AI 生成的内容可能不正确。" class="rich_pages wxw-img" data-ratio="0.5939306358381503" data-type="png" data-w="692" height="329" style="width:449px;height:267px;" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=1f4cc95b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKa1zwnnhXczfIWoicjWgbFVN9VX9zxibF30aW3YCiatFXFnmEf0ibt9H4MQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p style="mso-outline-level:2;"><b><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">利用</span><span lang="EN-US"><span leaf=""> Atomic Red Team</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Sigma </span></span><span leaf="">和</span><span lang="EN-US"><span leaf=""> MITRE ATT&amp;CK </span></span><span leaf="">增强检测覆盖率 </span></span></b><b><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Segoe UI Emoji&#34;,sans-serif;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:&#34;Segoe UI Emoji&#34;;"><span leaf="">⭐</span></span></b></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">利用 </span><span lang="EN-US"><span leaf="">Zircolite </span></span><span leaf="">基于 </span><span lang="EN-US"><span leaf="">SIGMA </span></span><span leaf="">对大型数据集进行快速检测。其大体工作流：</span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 12pt;font-family: 微软雅黑, sans-serif;"><span leaf=""><img data-imgfileid="100004359" class="rich_pages wxw-img" data-ratio="0.9451659451659452" data-type="png" data-w="693" height="524" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=3d734564&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdlhiccJOdNYYStrDyOB4RovROq7iapzgFKWf0ItKwmKP4NaW5kep2bJxAbFUbqlT9mA9EWaJ14ibdMRv7lmGsWZzg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;"><span leaf="">注：完整日程可以点击阅读原文跳转查看。</span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://attack.mitre.org/resources/attackcon/october-2024/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1ef0ffdf&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkyMzE5ODExNQ%3D%3D%26mid%3D2247488012%26idx%3D1%26sn%3D12da242efd6cee3bca6e44a4c9709b45">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 27 Nov 2025 09:00:00 +0800</pubDate>
    </item>
  </channel>
</rss>