<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>白泽安全实验室</title>
    <link>https://wechat2rss.xlab.app/feed/6bdf0d750e8c418f6ddfe8826c7a29f786a74aa4.xml</link>
    <description>专注APT发现、检测、取证、溯源相关网络安全技术研究。发布APT相关威胁情报、分享最新研究成果。&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (白泽安全实验室)</managingEditor>
    <pubDate>Fri, 04 Sep 2026 09:00:41 +0800</pubDate>
    <lastBuildDate>Fri, 04 Sep 2026 09:00:41 +0800</lastBuildDate>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM7WpaBKBoqXbZCyU8W6nvwC6wzGvbAx9btsGickSwiauJPQ/0</url>
      <title>白泽安全实验室</title>
      <link>https://wechat2rss.xlab.app/feed/6bdf0d750e8c418f6ddfe8826c7a29f786a74aa4.xml</link>
    </image>
    <item>
      <title>以AI对抗AI--白泽安全实验室出席第四届网络空间安全（天津）论坛，分享AI原生网络安全防御智能体的落地思考与实践</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492984&amp;idx=1&amp;sn=9b3491a4c2e83f6be3e40639fc978efb</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-09-04 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;" data-pm-slice="0 0 []"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2026年9月2日至3日，第四届网络空间安全（天津）论坛在天津滨海新区隆重举办。本届论坛以“共建网络安全 共治网络空间”为主题，汇聚国内外网络安全领域专家学者、政企代表及行业龙头企业，聚焦 AI 时代网络安全新态势、新型攻防对抗、网络空间综合治理等前沿议题，开展深度研讨与技术交流，白泽安全实验室受邀出席本次盛会。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">作为具有广泛影响力的网络安全专业论坛，本届论坛搭建了产学研用一体化的高端交流平台，同步开展报告发布、主题论坛、技术研讨等系列活动。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">9月2日下午，论坛举行《网络空间安全态势分析报告（2026）》发布仪式，白泽安全实验室作为报告编写成员单位，参与报告调研分析、数据梳理等编撰工作。该报告系统复盘2025—2026年全球网络安全威胁态势与攻防技术演进趋势，深度剖析APT攻击、AI驱动新型网络威胁、国家级网络对抗等核心风险，为行业精准研判安全形势、制定防御策略提供权威参考依据。</span></span></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6352087114337568" data-s="300,640" data-type="png" data-w="551" type="block" data-imgfileid="100009333" src="https://wechat2rss.xlab.app/img-proxy/?k=c44c2d4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FHBRznhxajkbI3qFC11feBLAibpA3KkUdp4eVX8oxOfUSdZLLlz648jicxiaqKLNmhP9bPSjsAYB4BefbKg5uVweib8A8VxgMB1Ld988X7NDnvKM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-align: center;margin: 8px 0px;text-indent: 0px;"><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">图 </span></span></font><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">1 </span></span><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">《网络空间安全态势分析报告（</span></span></font><font face="Arial"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2026</span></span></font><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">）》发布仪式现场</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">9月3日上午，论坛举行“新型威胁与攻防对抗”主题分论坛，聚焦AI技术重塑网络攻防格局的变革趋势，共同探讨新型威胁的防御思路与实战解决方案。白泽安全实验室受邀发表题为《“以AI对抗AI”思路下，网络安全防御侧AI智能体的具体落地思考与实践》的专题演讲，结合实战调研数据、真实攻防案例与自研技术成果，深入剖析AI驱动下攻防范式变革带来的安全困境，分享团队在AI原生安全防御与智能体体系落地方面的创新思路与实战成果。</span></span></font></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100009335" data-ratio="0.6075949367088608" data-s="300,640" type="block" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=2771ec37&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FHBRznhxajkaVoa9FXLfMLtEI3nJCoT8NqM4mQ20scTBXu4PBbNS8YwC9X6p2vVwdlWuC0dBTcc5wh83e8Fk7pwyzD3Qibg9bZB6H4EC83qRQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-align: center;margin: 8px 0px;text-indent: 0px;"><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">图 </span></span></font><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2 </span></span><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">“新型威胁与攻防对抗”主题分论坛主题演讲</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">演讲指出：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">“截至今年上半年，经白泽安全实验室跟踪分析的全球303起APT攻击事件中，至少25%明确涉及AI技术，且已深入漏洞挖掘、载荷生成、C2决策等攻击链核心环节。面对攻击侧AI从辅助工具升级为核心引擎的范式转变，防御侧必须走AI原生路线，而非在旧产品上简单叠加AI插件。”白泽安全实验室提出，通过AI智能体复刻安全专家专业能力，破解行业人才短缺瓶颈；同时立足网络攻击全景视角，覆盖流量、终端、情报三个维度的多源数据，开展批量智能关联分析。该智能体体系基于“大模型+记忆+工具+规划”架构，采用LangChain+Blackboard机制实现多Agent协同，目前已初步落地反编译分析、流量数据包分析、终端日志分析、情报关联分析等多个子智能体系统，并已投入实际业务场景运行。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">作为网络安全领域的积极践行者，白泽安全实验室将持续深耕</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI原生安全防御技术，持续打磨AI智能体分析研判能力，推动行业从&#34;规则驱动&#34;向&#34;智能驱动&#34;转型，助力构建更加安全、智能的网络空间生态。</span></span></font></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9676e4fc&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492984%26idx%3D1%26sn%3D9b3491a4c2e83f6be3e40639fc978efb">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 04 Sep 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>美国网络安全公司通过高仿真系统环境，成功诱捕APT攻击过程</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492978&amp;idx=1&amp;sn=38f528c0d4570f237a18ddcc6a4fc5f2</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-08-28 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.18615751789976134" data-type="png" data-w="838" data-imgfileid="100009327" src="https://wechat2rss.xlab.app/img-proxy/?k=d5a6570a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FHBRznhxajkaGS8uOqEnG6onhsNqJjTics7co6HUfd0B1ibsUBUziaXJntiabIbhADwZZuWY3hkffibZM5GZOGNftAOtpCIaaNXeWH2GFA4JEtpR0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一、事件背景概述</span></span></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">近日，</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">IBM X</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">‑</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Force</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">安全研究团队联合</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Deception.Pro</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">公司，依托欺骗防御技术搭建两套高仿真企业环境，完整捕获</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">ITG27</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">的真实人工渗透全流程。获取到此前未公开的后门样本、完整攻击链路以及攻击者大量人工操作行为数据。同时也梳理该威胁组织工具集、攻击战术与防御对策。本次捕获全程在受控仿真环境内完成，不会对真实业务系统产生任何风险，所有攻击者操作、网络会话、恶意样本执行行为均被完整留存记录。</span></span></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">事件起因是此前安全厂商已经观测到该</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织针对特定行业开展钓鱼渗透活动，攻击者借助主题化诱饵文档投递恶意载荷，具备成熟的后渗透工具链，传统沙箱静态分析仅能拿到恶意样本，难以观测攻击者上线之后的人工交互行为，无法完整还原真实入侵后的操作流程。为获取完整攻击行为证据，研究人员设计了两套高度贴近真实业务的仿真靶标环境，一套模拟电网运营技术企业终端与业务配置，另一套模拟政务机构办公环境。环境内部预置符合业务特征的文件、目录结构、账户配置，同时部署虚假业务文档作为蜜饵。环境配套全量日志采集、进程行为记录、网络会话留存能力，可完整记录命令执行、文件下载、注册表修改、网络外联、桌面远程操作等全部行为。同时也做好了网络隔离，严格限制仿真环境向外的访问边界，保障实验安全。仿真环境搭建完成后，研究人员将该组织过往使用的钓鱼邮件诱饵投递至仿真环境对应的邮件入口，等待攻击者发起入侵接入。</span></span></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二、技术实施与分析过程</span></span></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在技术实施与分析过程中，攻击者成功触发钓鱼链路进入仿真环境后，防御体系全程记录攻击者从载荷落地、权限维持、内网侦察、工具下载、后渗透操作直至最后执行关机重启的全部操作时序。研究人员通过日志统计发现，攻击者所有人工操作行为集中在固定工作日工作时段，操作过程中出现多处命令行输入拼写错误，部分恶意工具首次启动时输入参数格式错误，后续手动修正重新执行，充分证实入侵后绝大多数行为为攻击者人员手动交互式操作，并非脚本自动化执行。整个诱捕实验分为两组独立入侵事件，两组事件中攻击者呈现出差异化的后渗透策略。面向模拟电网运营的仿真环境，攻击者重点部署新型远程桌面类后门，开展交互式系统浏览，尝试提取凭证信息。面向模拟政务机构的仿真环境，攻击者将重心放在文档搜集、压缩加密与批量数据外溢操作。研究人员对捕获到的网络流量、主机日志、恶意二进制样本开展逆向工程与行为分析，解析恶意样本的通信协议、持久化机制、命令集、加解密逻辑，提取</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"> IOC </span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">指标，梳理攻击者完整杀伤链，同时记录攻击者所使用工具的版本迭代细节，获取到一款此前安全行业未公开的</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"> VNC </span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">类型后门程序完整执行链路数据。</span></span></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次捕获还原出完整攻击链。攻击起始阶段为邮件钓鱼入口，攻击者发送带有诱饵</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"> PDF </span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">附件的钓鱼邮件，</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">PDF</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">内部嵌入云存储恶意下载链接，受害者打开文档点击链接后下载压缩包载荷。压缩包内部包含合法可执行程序与恶意</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DLL</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">文件，攻击者利用</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DLL</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">侧加载技术，由正常可执行程序加载名为</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">SolidPDFCreator.dll</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">的</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Claimloader</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">加载器恶意组件。加载器被释放至</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C:\ProgramData\IDM\logs\</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">目录，同时修改用户</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Run</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">注册表项实现开机持久驻留。</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Claimloader</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">加载器借助</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Windows</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">系统枚举回调</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">API</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">执行内存中原始</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Shellcode</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，释放第十代</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Toneshell</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">后门。该版本后门舍弃传统</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Socket</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">通信，采用基于</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TLS</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">加密的</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">WebSocket</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">协议完成命令与控制通信，内置反向</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Shell</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">、文件上传下载会话管理能力，同时该后门还存在</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DLL</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">形态变体。部分变体使用</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">libcef.dll</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">等常见文件名伪装，样本代码中还夹杂大量无业务逻辑的</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">UTF</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">‑</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">16LE</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">垃圾字符串。完成基础后门驻留之后攻击者开展大规模系统与网络侦察，批量执行系统信息查询、账户域信息枚举、进程列表获取、网络配置探测、远程主机</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">ping</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">探测等系列命令，同时检查本机安全软件状态、无线网络配置、诱饵文件权限。在侦察完成后，攻击者根据目标环境差异开展不同后续动作。在第一起入侵事件中，攻击者通过</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">HTTP</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">服务下载全新</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Havencode</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">后门，借助</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DLL</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">侧加载启动该后门。该后门不内置硬编码</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C2</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">地址，需要在启动时通过命令行参数传入服务端地址，内置自定义注册信标、</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">XOR</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">数据包加密、</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TCP/UDP</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">代理隧道。同时具备</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">HVNC</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">与</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AVNC</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">两套</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">VNC</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">服务能力，</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">HVNC</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">能够生成一套独立隐藏桌面供攻击者操作，</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AVNC</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">可直接查看主机原有桌面。攻击者利用该后门持续浏览仿真环境内部浏览器、邮件客户端、密码管理器等应用，尝试获取凭据，过程中还下载额外工具尝试解密浏览器存储凭证。在第二起入侵事件当中，攻击者下载</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">curl</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">、</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">WinRAR</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">等公开合法工具，设置时间过滤条件递归扫描磁盘，筛选指定后缀、特定修改时间的文档，打包生成加密压缩包，随后通过</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">SFTP</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">协议将加密归档向外传输至攻击者控制服务器，完成数据窃取动作。两次入侵事件临近结束阶段，攻击者均执行强制重启关机命令结束本轮入侵活动。</span></span></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从攻击技术特点来看，该威胁组织大量采用</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DLL</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">侧加载作为主要植入手段，利用正常白程序加载恶意</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DLL</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">规避部分静态检测，恶意载荷优先执行内存</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Shellcode</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，减少磁盘落地特征。</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Toneshell v10</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">采用加密</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">WebSocket</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">作为</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C2</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">信道，兼容代理环境，具备完整交互式</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Shell</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">与分阶段文件传输指令集，存在</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Shellcode</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">与</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">PE</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">‑</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DLL</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">多种分发形态，提升工具适配灵活度。新增的</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Havencode</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">后门设计模块化，将</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C2</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">通信、代理隧道、两套不同模式</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">VNC</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">远程桌面能力进行拆分。通信数据包使用自定义头部结构，内置</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">XOR</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">加密与</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">CRC32</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">校验。支持通过命令行参数灵活指定</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C2</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">地址，无需重新编译样本。</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">HVNC</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">模式还会主动修改注册表调整资源管理器配置，优化远程桌面操作体验，同时生成专门日志文件记录</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"> VNC </span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">会话运行事件。攻击者后渗透阶段高度依赖人工键盘交互，会完整开展系统、域账户、进程、网络、安全软件的全维度侦察，优先收集各类文档资产，善于复用系统自带命令与公开开源工具完成压缩、下载、外溢等动作，降低恶意文件特征；攻击者会根据目标环境属性灵活调整攻击目标，在基础设施类环境偏向远程交互式探查，政务类仿真环境则优先执行批量文档窃取流程，入侵结束使用系统自带关机重启指令，清理部分会话痕迹。</span></span></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三、事件总结</span></span></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次事件中，攻击方呈现出明显的工具迭代与战术适配特征。恶意载荷大量运用</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DLL</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">侧加载、内存</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Shellcode</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">规避静态查杀，</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Toneshell</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">、</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Havencode</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">后门采用</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">WebSocket</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">、自定义加密协议提升隐蔽性，新增双模式</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">VNC</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">实现深度交互式操控。整体以人工操作为核心，会依据目标环境调整后渗透动作，善用系统原生工具降低恶意特征。攻击诱捕方则依托高仿真欺骗环境突破传统沙箱局限，不再仅捕获静态样本，完整记录攻击者全链路人工操作时序，捕捉到样本变体、参数错误等真实攻击细节，通过隔离受控环境获取一手实战数据，验证了欺骗防御在</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">行为捕获、威胁情报挖掘上的实战价值，为防御规则打磨提供真实入侵依据。 </span></span></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">基于本次诱捕获取的实战数据，安全研究人员也给出对应防护建议，在邮件层面对云存储类嵌入链接开展沙箱检测，加强高风险主题钓鱼邮件预警；终端侧重点监控</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DLL</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">侧加载行为、非标准路径文件写入、异常</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Run</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">注册表项，监测隐藏桌面创建、资源管理器注册表异常修改行为，针对</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Havencode</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">相关日志文件、样本哈希建立检测规则；网络层面阻断报告披露的威胁域名与</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">IP</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">地址，隔离业务网与运维网络，管控主机对外非授权出站访问；身份安全层面启用多因素认证，监控批量账户枚举、密码暴力测试行为；安全运营方面留存至少</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">90</span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">天终端与网络日志，针对攻击者侦察命令序列建立检测规则，同时建议关键行业可引入欺骗防御技术，部署仿真蜜罐环境，主动捕获</span></span><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"> APT </span></span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织真实入侵行为，补充威胁狩猎数据源。</span></span></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">参考链接：</span></span></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><span lang="EN-US"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://www.ibm.com/think/x-force/trapping-a-mustang-panda" target="_blank">https://www.ibm.com/think/x-force/trapping-a-mustang-panda</a></span></span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a099748a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492978%26idx%3D1%26sn%3D38f528c0d4570f237a18ddcc6a4fc5f2">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 28 Aug 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>疑似Lazarus组织成员遭反向钓鱼设局，渗透全流程被完整捕获</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492974&amp;idx=1&amp;sn=425c3cc0d05bd09d98db2570f89243d0</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-08-21 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一、事件概述</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">近日，网络安全公司联合研究团队发布了一份关于朝鲜</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Lazarus组织下属“Famous Chollima”IT工人渗透网络的深度调查报告。该调查采用主动诱捕（counter-espionage）手法，研究人员虚构了一家DeFi初创企业“Ballena Azul LTD”（蓝鲸有限公司），以招聘区块链开发工程师为名，将多名疑似朝鲜IT工人引入公司，并通过预部署的交互式沙箱环境实时监控其全部工作行为。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该调查延续了</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2025年12月首次公开的Famous Chollima渗透周期研究。第一期调查中，研究人员伪装成“协助者”，帮助朝鲜IT工人获取西方企业远程职位，记录了从招募、伪造文件、寄送笔记本到AI面试辅助和实时翻译的全链条。本次调查将角色从“协助者”转为“雇主”，以创始人身份接触目标，获得了更深入的内部视角——不仅记录了渗透者入职过程，还完整呈现了其入职后的工作协作、资源访问、工具链、远程访问流程、AI使用方式及支撑基础设施。</span></span></font></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100009324" data-ratio="0.9922630560928434" data-s="300,640" type="block" data-type="png" data-w="517" src="https://wechat2rss.xlab.app/img-proxy/?k=af23ff89&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FHBRznhxajkY6GDibickcoEJgHgy6cot9991bf2rTcxPqDjIsdV8lfGnjKaVpCKJ6ZOZ0BykKPKB8WC9QricCXJs2PcDZfr5aF6VicA3giczttGCY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Famous Chollima是Lazarus的分支之一，核心任务是通过合法就业渠道渗透西方企业，主要瞄准加密货币、金融、医疗健康等资金与情报密集行业，近期已扩展至制药、土木工程、建筑等领域。为获取职位，该组织依赖伪造身份、虚假简历、代理面试、远程协助者及“幽灵开发者”的协同配合，使企业相信雇佣者即为声称身份。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">与传统入侵不同，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Famous Chollima旨在成为组织的一部分，而非数小时或数天内攻陷。一次成功渗透可带来持续内部访问权限，覆盖内部系统、源代码、知识产权和企业决策，同时产生合法薪资回流朝鲜。这种模式极其特殊：恶意软件攻击虽可一夜见效，但本质“嘈杂”且暴露风险高；而一名“员工”的存在本身合理，驻留越久，收集情报、影响决策的机会越大。若多名操作人员在同一公司任职，甚至无需利用漏洞即可影响工程决策、代码审查、合并请求和审批等信任机制。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二、侦察过程与攻击者行为技术分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次反向侦察完整复刻了海外企业招聘全流程，从渠道对接、简历面试、入职材料提交，到分配工作环境、开展日常开发，完整捕获了攻击者的整套作业流程。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">1）攻击者对接与面试环节</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研究团队</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">内部</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">人员伪装为</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Ballena Azul LTD项目负责人Andy Jones，此前已在GitHub平台接触到该</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">黑客组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">外联人员</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Angelo Cruz。经查，Angelo Cruz长期活跃于GitHub等技术平台，主动寻找合作中间人，意图为</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">成员对接海外企业远程岗位。研究人员顺势对接，向其推送本次虚构的企业招聘岗位。随后，该</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">推送三名渗透人员，分别应聘智能合约、前端、后端开发岗位。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">面试环节中，研究人员部署蜜罐令牌（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Canary Token）二维码，面试人员扫码参会的同时，系统静默抓取其公网IP、浏览器指纹、设备特征等核心取证数据。通过全程观测，研究人员总结出该</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">面试阶段的典型特征：多数人员英语能力薄弱，面试过程中视线频繁离开屏幕，借助第二台显示器运行实时</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI翻译工具辅助应答；所有应聘者均使用虚构履历，统一包装数学专业背景，打造标准化技术人设。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">内部存在成熟的互助背书机制，已通过面试的成员会主动向企业推荐同伙，实现批量人员入驻。此外，首期研究中出现的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">核心人员</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Aaron（代号Blaze）也曾应聘本次虚假企业，但因拒绝提交身份核验材料，最终未完成入职。研究团队还捕捉到该</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">特殊的社会工程学规避手段：当</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI翻译工具故障、无法辅助应答时，渗透人员会刻意假装身体不适、突发眩晕，以此规避面试提问，掩盖自身能力缺陷。</span></span></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9981949458483754" data-s="300,640" data-type="png" data-w="554" type="block" data-imgfileid="100009325" src="https://wechat2rss.xlab.app/img-proxy/?k=fe2e460d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FHBRznhxajkZib87df0ricYjqPHoVGkPJjYKdGHTjdrktx0sFgj4PmOlLKI6k4cI0UrgbIric41F5icB0RuZ9lv5EFHleN08O8ZpSg3o2PokLrmY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2）伪造身份与入职材料欺诈</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">进入签约入职阶段后，三名</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击者</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">批量提交伪造或盗用的身份凭证及银行账户信息，所有薪资收款账户均为洗钱中转账户，用于非法资金分流与回流。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">首位入职人员</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Jack Anderson，提交伪造的美国得克萨斯州驾照、社会安全号码及堪萨斯城银行账户信息；第二名</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">入职人员</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Angelo Espree谎称常住美国得克萨斯州，却提交伪造的加州驾照与纽约花旗银行账户</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">经</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">调研</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">核查，该证件元数据留存</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Google Gemini生成痕迹与SynthID数字水印，可直接证实为AI工具批量生成的虚假证件；第三名后端开发人员Lucas Theo未使用虚构身份，直接盗用真实用户Pui Chin Teoh的证件信息，提交的驾照原图由iPhone 15拍摄，属于公开泄露的真实证件影像。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">依托</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI伪造</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">和</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">盗</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">用相结合的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">身份材料，顺利通过企业</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">KYC入职核验流程，完成合法入职并申领薪资，所有薪资资金最终通过地下渠道回流至</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">幕后控制端。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">3）虚拟桌面环境内的工具与操作行为</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研究团队以实体办公设备尚未到位为由，为三名</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击者</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">分配基于沙箱搭建的虚拟</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">VDI桌面环境。攻击者全程未察觉办公环境为蜜罐环境，所有操作行为、屏幕画面、网络请求均被系统全程实时记录留存。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击者</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">登录虚拟桌面后，严格遵循</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">标准化侦察流程，依次调用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">dxdiag、systeminfo、wmic等系统内置命令，批量读取设备硬件参数、系统版本、设备标识等信息</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">同时访问公网</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">IP查询网站，确认当前设备的对外出口IP与网络环境。完成环境侦察后，攻击者立即安装谷歌远程桌面、AnyDesk等远程控制工具。期间因操作失误，开启谷歌账号同步功能，将个人账号留存的浏览记录、账号密码、浏览器扩展程序等隐私数据同步至蜜罐环境，为研究团队梳理</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">工具链、作业习惯提供了完整线索。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在岗作业期间，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击者</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">高度依赖大模型工具，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">ChatGPT、Google Gemini覆盖代码编写、Node.js报错排查、测试网代币申领等所有开发场景</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">自身专业技术薄弱，输出代码质量差、漏洞多。研究团队人为模拟网络中断、鼠标失灵、人机验证循环、桌面崩溃等故障，测试攻击者应急行为。面对办公故障、文件丢失问题，攻击者未采用正规工单反馈渠道，直接通过系统记事本文本编辑的方式，与研究人员伪装的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">IT运维人员沟通排错。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">网络行为监测显示，攻击者频繁使用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AstrillVPN代理节点跳转网络，规避溯源追踪，同时暴露了该</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">长期复用的一批</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">VPS代理服务器。此类服务器生命周期长、复用率高，多次出现在该组织的跨批次攻击活动中。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次观测完整梳理出</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">的标准化工具集：</span></span></font></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">远程控制：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AnyDesk、Google Remote Desktop</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">网络代理：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Astrill VPN</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI辅助：ChatGPT、Google Gemini、多款GPT辅助浏览器扩展</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">代码开发：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Cursor、VS Code、Remix</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">加密货币：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">MetaMask、Bitget Wallet</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">身份验证共享：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2fa.cn（用于</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">内部共享二次验证码）</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">信息侦察：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">dxdiag、systeminfo、wmic、ip8.com</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">基础设施：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Vultr、Gorilla Servers VPS服务器</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">通信：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Outlook邮箱远程控制：AnyDesk、Google Remote Desktop</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">网络代理：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Astrill VPN</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI辅助：ChatGPT、Google Gemini、多款GPT辅助浏览器扩展</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">代码开发：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Cursor、VS Code、Remix</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">加密货币：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">MetaMask、Bitget Wallet</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">身份验证共享：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2fa.cn（用于</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">内部共享二次验证码）</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">信息侦察：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">dxdiag、systeminfo、wmic、ip8.com</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">基础设施：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Vultr、Gorilla Servers VPS服务器</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">通信：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Outlook邮箱。</span></span></font></p></li></ul><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">4）行动收网与攻击者撤离</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">后续研究团队安排人员扮演企业联合创始人</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Benito，当场核验入职材料、揭露三名人员的身份造假行为。现场对峙过程中，Angelo Cruz第一时间察觉风险、陷入恐慌；Jack Anderson依赖AI翻译工具滞后理解现场情况，随即直接退出会议；Lucas Theo同步快速下线失联。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">事后</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Angelo Cruz私下联系合作中间人核实情况，但始终未意识到本次求职全程为安全团队搭建的蜜罐诱捕行动。直至研究结束，所有</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">涉案人员均未察觉自身的全部操作、屏幕画面、对话记录已被完整取证留存。在身份暴露前，该</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">已预判企业即将获得风投融资，甚至提前规划窃取企业冷钱包私钥、盗取加密资产的攻击链路，恶意攻击意图明确。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三、</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">事件总结</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次观测的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Famous Chollima属于Lazarus APT组织下属分支，该组织摒弃传统漏洞入侵思路，采用&#34;合法雇员渗透&#34;的长周期作战模式。相较于恶意软件攻击容易触发告警、暴露周期短的特点，以员工身份潜伏具备天然信任优势，驻留周期可达数月乃至数年。一旦多名</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">成员成功入职同一企业，无需利用系统漏洞即可干预代码评审、版本合并、工程决策等信任依赖型业务流程，窃取源代码与商业机密，同时领取薪资输送给幕后。该模式对</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Web3加密货币企业构成极高风险。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">的攻击链条已高度</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI化，AI大模型贯穿证件伪造、面试翻译、代码编写、问题排错全流程，大幅降低了攻击者的技术门槛。组织大量使用被盗证件、AI生成伪造证件、骡子银行账户完成入职流程，同时采购VPS服务器、VPN节点搭建跳板基础设施，并持续轮换二次验证码共享网站。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从捕获的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">IOC来看，该</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">拥有一批长期活跃的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">VPS服务器及大量Astrill VPN出口节点，以及相关加密货币钱包地址，威胁情报从业者可将上述IOC纳入检测规则开展威胁狩猎。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">参考链接：</span></span></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/" target="_blank">https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/</a></span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=ac216ecf&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492974%26idx%3D1%26sn%3D425c3cc0d05bd09d98db2570f89243d0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 21 Aug 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>朝鲜APT组织Lazarus发起“Operation Dream Job”攻击，利用0day漏洞渗透全球国防工业</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492968&amp;idx=1&amp;sn=b100b12bd1722918b8cf60ab9db0647e</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-08-14 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一、</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">事件概述</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">近日，网络安全研究人员持续追踪到代号为</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">“Operation Dream Job”的大规模定向攻击活动。该活动由朝鲜关联的Lazarus黑客组织发起，自2026年初以来持续活跃。攻击重点针对全球国防工业，特别是航空航天、无人机、监控传感器及机器人等军事科技领域，波及欧洲、南亚及南美多地。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本轮攻击中，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Lazarus组织的战术与技术能力显著升级。攻击者以虚假招聘为诱饵，通过LinkedIn等社交平台或即时通讯工具冒充知名国防企业HR，诱导目标下载恶意文件。在技术层面，该组织首次利用篡改版PDF阅读器“SecurityPDF”分发新型后门“Troy”；同时，利用Windows内核驱动AFD.sys的0day漏洞（CVE-2026-68820），部署新版FudModule内核级Rootkit，实现SYSTEM权限提升并规避EDR检测。此外，攻击者还利用存在CVE-2025-49113漏洞的Roundcube邮件服务器，植入自研PHP Webshell“RelayShell”搭建多层中转链路，以规避网络审计。部分西欧失陷企业甚至被二次利用，以官方名义群发钓鱼邮件，进一步提升了社工欺诈的成功率。整体攻击链涵盖社工投递、终端驻留、内核提权、远控及隐蔽通信，对全球国防产业链数据安全构成重大威胁。</span></span></font></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100009318" data-ratio="0.5649819494584838" data-s="300,640" type="block" data-type="png" data-w="554" src="https://wechat2rss.xlab.app/img-proxy/?k=c5b531d6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FHBRznhxajkbFg42WoTOSoCpZX7ibtn5nyhEGX2nyTYbfY0Khq2aTchUpS0mic684ice28iaLNSEwtdqjPLr9lOtCk3ygpnEJos17R2cT3eUIxr0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-align: center;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">图 </span></span></font><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">1 </span></span><font face="Arial"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DLL</span></span></font><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">侧载感染链</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二、</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">攻击过程技术分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次攻击构建了从社工诱骗、初始投递、内存级提权到持久化后门的完整攻击链。其</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C2基础设施采用“被入侵合法Web服务器中继”手法，呈现出高隐蔽性、强对抗性与模块化特征。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">1）初始投递：双链路并行的社工攻击</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击初期，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Lazarus组织利用仿冒网站与SEO技术分发木马化应用，使恶意软件在搜索结果中排名靠前，以规避钓鱼检测。研究人员识别出两条并行感染链路：</span></span></font></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">链路一：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DLL侧加载</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">受害者下载加密</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">ZIP包（含合法签名的PDF查看器、恶意DLL libmupdf.dll 及伪装为PDF的加密载荷）。启动查看器时，恶意DLL被自动加载，在后台解密并直接在内存中执行恶意载荷，同时在前台展示诱饵PDF文档。</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">链路二：木马化</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">PDF查看器。</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2026年7月首次被观测到。攻击者冒充Enveil公司发送虚假邀约，诱导受害者下载包含“SecurityPDF”（基于开源MuPDF修改）和特制恶意PDF的ZIP包。SecurityPDF篡改了文件打开与拖放处理逻辑：当打开含特定标记的PDF时，程序自动提取载荷，使用单字节XOR密钥（0x39）解密后写入临时目录并执行，最终反射加载包含Troy后门的DLL。攻击者将查看器分发与恶意文档投递分离，并注册多个仿冒Enveil网站，以降低检测率。</span></span></font></p></li></ul><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2）内存级载荷投递与模块化执行：MISTPEN下载器</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">两条链路最终均指向轻量级内存下载器</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">MISTPEN（最早由Mandiant于2024年披露）。该下载器利用Microsoft Graph API访问攻击者控制的OneDrive账户进行C2通信，交互文件均采用AES加密（上下行使用独立密钥）。其核心能力是将PE DLL反射加载至内存执行，全程不落盘，有效规避文件级检测。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在投递最终后门之前，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">MISTPEN会依次部署多个模块执行侦察任务：GetInfoPlugin收集主机基础信息；PvPlugin枚举进程详情；OneScreenCapture捕获多显示器桌面截图并Base64编码回传。这些模块均无独立网络通信能力，由MISTPEN统一上传至C2。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">3）0day漏洞利用与内核级提权：CVE-2026-68820与FudModule v3.1</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">确认目标价值后，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">MISTPEN加载本地提权（LPE）模块。该模块通过RPC与MISTPEN通信，数据在AES加密外叠加GOST-CBC加密（使用随机16字节会话密钥）。运作分四阶段：采集主机指纹、向C2请求公钥、使用Kyber/ML-KEM后量子算法生成会话密钥、请求并解密执行LPE载荷。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该载荷为</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Lazarus组织的内核提权工具FudModule v3.1（编译时间戳为2026年7月7日），明确针对Windows 11 24H2及25H2版本。其利用AFD.sys驱动中的竞态条件漏洞：当套接字被多线程并发访问时，驱动内部状态信息在缺乏同步保护下被同时操作，触发释放后使用（UAF），攻击者借此获取内核读写原语，实现SYSTEM提权。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">FudModule v3.1保留了完整的安全监测清除能力，可卸载系统回调、终止内核日志、屏蔽蓝屏转储、查杀94款ETW安全日志采集组件，并针对卡巴斯基等部署流量阻断逻辑。该版本新增篡改Smart App Control代码完整性校验策略的能力，同时移除了针对Defender等特定杀软的专属屏蔽模块，统一采用通用压制逻辑以精简体积。提权完成后，FudModule注入SYSTEM权限的msiexec进程以启动高权限MISTPEN，彻底绕过EDR检测。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">4）新型后门Troy：模块化远控能力</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">第二条链路最终部署的是新型模块化远控木马</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Troy（名称源自样本PDB路径）。该后门以64位DLL交付，支持配置三个C2服务器，启动时按序尝试连接，通过验证“CONNECTED”响应及质询-响应握手完成注册。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Troy支持17种命令，覆盖后渗透全阶段：包括驱动/目录/进程枚举、文件增删、压缩外传、交互式命令行（支持目录切换持久化与10秒看门狗）、内存DLL注入、进程终止、休眠控制及配置读写等。任务指令经Base64编码下发，结果以JSON格式回传，超大响应自动分片。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">5）C2基础设施：基于被入侵Web服务器的中继网络</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Lazarus组织大量利用存在CVE-2025-49113漏洞的Roundcube邮件服务器及部分PrestaShop电商网站作为C2基础设施。攻击者可能利用暗网泄露凭证完成认证后，部署自研PHP Webshell“RelayShell”。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">与传统</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Webshell不同，RelayShell充当威胁者与受感染终端间的通信中继。通过HTTP POST请求中的密码区分两种模式：“受害者模式”下，Webshell创建PHP会话，解密外部隐藏配置并向骨干URL注册新会话；“操作员模式”下，提供会话管理、连通性检查及文件操作等命令。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">双方建立会话后，通过基于文件的通道交换数据：消息以临时文件形式存储于受损服务器，发送方写入、接收方读取，从而将</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Web服务器转化为纯中继节点。研究人员已识别出17个唯一标识符，证实至少有17台服务器被用作中继。此外，攻击者还使用ExpressVPN等共享VPN隐匿操作来源。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三、</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">攻击目标与组织归因研判</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">综合攻击手法、技术特征及基础设施分布分析，本次行动高度聚焦全球防务与航空航天领域，特别是涉及监视传感器、无人机及机器人技术的机构。攻击范围覆盖巴西、法国、德国及印度等地。一家法国机构失陷后被用作跳板发起鱼叉式钓鱼，印证了该组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">“以信任机构为跳板”的战术意图。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">基于恶意软件组件、基础设施指纹及历史活动模式，研究人员以高置信度将本次攻击归因于朝鲜</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Lazarus组织。依据包括：MISTPEN下载器已于2024年被披露并关联该组织；FudModule Rootkit自2021年起即为Lazarus标志性提权工具，v3.1版本在代码结构与行为特征上与历史样本高度一致；Troy后门的PDB路径亦与Lazarus历史样本吻合。此外，本次行动在诱饵主题、攻击手法与目标选择上，与该组织历史上的“Operation Dream Job”行动高度延续。该组织已具备定制化恶意软件开发、0day挖掘及复杂基础设施部署的全链条产业化运营能力。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">四、</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">攻击事件总结</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">“Operation Dream Job”攻击表明，Lazarus组织已构建起涵盖社工诱骗、多链路投递、内存级模块化执行、0day提权、内核安全致盲及隐蔽C2通信的完整攻击体系。其突出技术特征体现在三个维度：</span></span></font></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">0day漏洞实战化运用：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">CVE-2026-68820是该组织继CVE-2024-38193后，在AFD.sys驱动中挖掘的又一0day漏洞，且明确针对最新Windows 11版本，反映出其持续获取高价值内核漏洞的能力。</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">投递手法精细化升级：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击者将木马化软件托管与恶意文档投递分离，结合</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">SEO优化、合法数字签名及开源框架伪装，大幅提升了初始投递的隐蔽性与成功率。</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C2架构去中心化设计：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">通过入侵合法</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Web服务器部署RelayShell中继，将恶意通信混入正常Web流量，有效规避了严格的网络监控与流量审计。</span></span></font></p></li></ul><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">参考链接：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/" target="_blank">https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/</a> </span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=deb17e25&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492968%26idx%3D1%26sn%3Db100b12bd1722918b8cf60ab9db0647e">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 14 Aug 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>俄罗斯黑客组织Midnight Blizzard利用酒店Wi-Fi发起全球网络攻击活动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492964&amp;idx=1&amp;sn=66873e66d58e81cca182a6d76a66a626</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-08-07 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一、事件概述</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">近日，网络安全研究人员监测发现，俄罗斯背景威胁组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Midnight Blizzard（又名NOBELIUM）下属子集群Storm-2945正在发起代号为“CaptiveCrunch”的大规模网络攻击活动。该行动自2026年5月初开始活跃，专门针对全球范围内酒店、会议中心等住宿与公共场所Wi-Fi网络实施流量操纵</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">与</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击。与传统的钓鱼或漏洞利用不同，该组织通过入侵或控制公共</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Wi-Fi网络的DNS及HTTP流量，将受害者的网络连接重定向至攻击者控制的基础设施，进而实施中间人攻击（AitM）。在此次行动中，Storm-2945组织不仅利用伪造的浏览器或系统更新提示诱导用户下载恶意软件，还结合设备代码钓鱼（Device Code Phishing）技术窃取Microsoft Entra ID云环境凭证，甚至可能波及Android移动设备。值得注意的是，研究人员评估认为该组织在行动中广泛使用了人工智能技术辅助代码生成与运营支持，显著提升了攻击工具的迭代速度与伪装能力。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">进一步分析显示，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">CaptiveCrunch行动是Midnight Blizzard长期网络攻击活动的最新战术演进。尽管其流量操纵手法与此前披露的Forest Blizzard DNS劫持行动有相似之处，但本次攻击更聚焦于差旅场景下的企业高管与政府人员。攻击者构建了一套完整的工具链，包括名为CornFlake的全功能Go语言远程访问木马（RAT）、基于PowerShell的内存驻留窃密器ChocoShell，以及伪装成合法云管理平台的Web控制台FruitStone。这套体系不仅具备键盘记录、音视频监控、浏览器凭证窃取等传统间谍功能，还能绕过Chrome App-Bound Encryption等最新安全防护机制，直接窃取SSO令牌与会话Cookie。截至报告发布时，该组织仍在持续更新恶意载荷并扩展受控网络节点，对依赖公共网络进行办公的全球商务旅客及政企机构构成严重且紧迫的安全威胁。</span></span></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7341772151898734" data-s="300,640" data-type="png" data-w="553" type="block" data-imgfileid="100009315" src="https://wechat2rss.xlab.app/img-proxy/?k=fe993399&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FHBRznhxajkY38QzVib5gBJsib8BgdwBvDjjp775lib8nvbfcwV8Wbo3do8GsLhHu6O1IT51PU9Bj4Tiaoh6JDd4SbpkPfuESAo2bGPz0jWyUP8Y%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-align: center;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">图 </span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">1 </span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">CaptiveCrunch </span></span><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击流程概述</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二、攻击过程与核心技术分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研究人员针对本次</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">CaptiveCrunch攻击活动构建了从网络层流量劫持到终端持久化控制的立体攻击链条。攻击者首先控制公共场所Wi-Fi门户基础设施，利用用户对网络连接的信任实施社会工程学欺骗。随后通过高度定制化的恶意工具组合实现深度渗透与数据窃取，整体呈现出极强的场景针对性与技术对抗性。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">1）初始投递与ClickFix社会工程学诱导</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击初始阶段，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Storm-2945组织通过篡改酒店及会议场所Wi-Fi门户的DNS解析或HTTP响应，拦截用户的正常上网请求。当用户尝试连接网络或浏览器自动发起连通性检查（NCSI）时，流量被重定向至攻击者托管的恶意站点。这些站点采用ClickFix技术，伪装成Windows更新、DirectX运行时安装、PDF阅读器或浏览器安全补丁等界面，并附带详细的“手动修复指南”，诱导用户主动复制粘贴恶意命令或下载执行恶意程序。除Windows平台外，部分登录页还包含针对Android设备的APK下载指引，显示出跨平台攻击意图。这种利用公共网络信任关系而非传统邮件钓鱼的投递方式，极大降低了受害者的警惕性，尤其在差旅疲惫状态下更易中招。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2）核心植入体CornFlake与多重持久化机制</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">用户一旦执行恶意载荷，便会释放名为</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">CornFlake的Go语言编写RAT。该程序运行时会弹出逼真的虚假进度窗口（如“正在配置更新”、“磁盘优化中”），掩盖后台恶意行为。CornFlake将自身复制到%APPDATA%\svchost32\目录并注册为名为“Cloud Sync Service”的系统服务，刻意模仿合法进程名称以规避人工排查。为确保长期驻留，样本同时创建了注册表Run键值、计划任务及看门狗进程，任一持久化机制被清除均会自动恢复。在通信层面，CornFlake采用ECDH P-256密钥交换建立加密C2通道，每次会话使用临时密钥，使得流量解密极为困难。其配置文件sync.dat支持热加载，无需重新部署即可动态调整C2地址、监控目录及文件过滤规则。该木马集成了键盘记录、剪贴板监控、屏幕截图、麦克风录音、摄像头拍摄、USB介质扫描及远程Shell等全维度监控能力，并能识别18类主机安全态势信息，为后续攻击提供精准情报。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">3）内存驻留窃密器ChocoShell与凭证窃取技术</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">作为</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">CornFlake的补充，ChocoShell是一款完全在内存中执行的PowerShell窃密脚本，专注于高价值凭证的快速提取。该脚本包含大量开发者注释，明确引用了微软检测签名及规避逻辑，显示出AI辅助编码特征。执行后，ChocoShell首先通过.NET反射禁用AMSI接口，并利用时间差检测沙箱环境。为获取最高权限，它内置三种静默UAC绕过技术（SilentCleanup任务劫持、wsreset.exe COM劫持、sdclt.exe文件夹劫持），失败后才回退至</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">显示</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">提权弹窗。在凭证窃取环节，该脚本不仅能提取传统</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DPAPI保护的浏览器密码，还能通过模拟SYSTEM令牌绕过Chrome v127+版本的App-Bound Encryption（ABE）保护，或通过启动带调试端口的浏览器实例直接调用DevTools协议导出明文Cookie。此外，它还会从Token Broker缓存中提取Microsoft 365 SSO令牌、刷新令牌及WAM令牌，使攻击者无需密码即可接管受害者云账户。所有窃取数据经GZip压缩、Base64编码后上传，并在本地彻底清理痕迹。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">4）C2管理平台FruitStone与设备代码钓鱼滥用</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击者使用名为</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">FruitStone的Web面板统一管理整个行动。该平台伪装成“Acuity Systems CloudSync Console”企业云管理软件，支持多操作员协同、实时状态监控及可视化地图展示。内置的Campaign Builder向导允许攻击者图形化配置CornFlake载荷的各项参数，包括C2地址、窃密模块开关、文件过滤规则及反分析选项，实现了恶意软件的工业化生产。在云访问层面，Storm-2945组织还将设备代码钓鱼集成至CaptiveCrunch流程中。自2026年7月中旬起，部分恶意登录页引导用户在合法的微软登录页面输入攻击者生成的设备代码，从而将受害者的身份验证会话转移给攻击者。这种结合了网络层劫持与身份层滥用的复合战术，使得即便启用了多因素认证（MFA）的用户也难以幸免，因为攻击发生在用户主动配合“网络修复”的认知盲区中。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三、攻击目标与组织归因研判</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">综合攻击链路、技术特征及历史行为模式分析，研究人员以高置信度将</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">CaptiveCrunch行动归因于俄罗斯背景的Midnight Blizzard组织及其子集群Storm-2945。具体依据如下：</span></span></font><font face="宋体"></font></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">首先，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Storm-2945组织在技术栈上与Midnight Blizzard已知子集群Storm-2372高度重叠，两者均长期使用设备代码钓鱼、OAuth令牌滥用及Microsoft Graph邮件窃取技术，且受害者画像均集中于政府、外交、NGO及IT服务商；</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">其次，本次行动中使用的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">ChocoShell脚本风格、C2通信协议及FruitStone面板架构，与该组织过往工具存在显著的代码复用与演进关系；</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">再次，攻击目标精准锁定国际差旅人群，符合该组织通过长期间谍活动收集地缘政治情报的战略诉求，而非单纯的经济牟利。</span></span></font></p></li></ul><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该组织展现出国家级威胁行为体的典型特征：</span></span></font></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">一是战术创新能力强，能将公共</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Wi-Fi基础设施转化为攻击跳板，突破了传统终端防护边界；</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">二是工具研发迭代快，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">CornFlake与ChocoShell在短时间内多次更新，快速适配Chrome ABE等新防御机制；</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">三是运营体系成熟，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">FruitStone平台实现了从载荷生成、分发到数据回收的全流程自动化管理；</span></span></font></p></li><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">四是</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI赋能实战，从代码注释中的AI生成痕迹到运营支持的智能化，表明该组织已将AI深度融入攻击作业流</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">程</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font></p></li></ul><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">与松散的黑产团伙不同，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Midnight Blizzard组织具备稳定的资源支持与战略定力，其行动始终服务于俄罗斯国家利益，CaptiveCrunch正是其在后疫情时代差旅恢复背景下，针对西方关键人员实施的新一轮情报收割行动。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">四、攻击事件总结</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">CaptiveCrunch攻击事件标志着国家级网络间谍活动已从传统的终端渗透延伸至公共网络基础设施层面。Storm-2945组织通过控制酒店及会议场所Wi-Fi门户，构建了覆盖全球的分布式攻击入口，将原本被视为“便利设施”的公共网络转变为精准的间谍陷阱。该行动最显著的特征在于“场景融合”：将网络层流量劫持、终端层恶意软件投放与身份层设备代码钓鱼无缝衔接，形成了一条从物理连接到云账户接管的完整攻击链。同时，攻击工具的高度工程化与AI辅助开发能力，使得防御方难以通过静态特征进行有效拦截。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">针对此类依托公共基础设施的新型威胁，相关机构及个人应彻底摒弃对酒店、机场等场所</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Wi-Fi网络的默认信任。建议差旅人员优先使用个人热点、eSIM或企业级加密隧道接入互联网，严禁在公共网络上执行任何系统更新或安装未知软件。企业层面应强化零信任架构，禁止设备代码流认证或严格限制其使用范围，部署抗钓鱼MFA策略，并通过条件访问策略对来自高风险地理位置或异常IP的登录请求实施阻断。安全团队需重点关注NCSI测试后的异常文件创建行为、svchost32等非标准服务注册、以及指向ms365-device.com等仿冒域名的网络外联，将公共网络接入点纳入威胁狩猎视野，构建涵盖网络层、终端层与身份层的纵深防御体系，以应对日益复杂的国家级混合威胁。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">参考链接：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/" target="_blank">https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/</a> </span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=80187c31&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492964%26idx%3D1%26sn%3D66873e66d58e81cca182a6d76a66a626">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 07 Aug 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>伊朗背景APT组织Mirage Kitten更新武器库，以新型后门与隧道工具持续对中东及非洲地区实施网络攻击活动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492961&amp;idx=1&amp;sn=b2a5eb75a1921313adf93682b03da54c</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-07-31 00:09</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一、事件概述</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">近日，网络安全研究人员在持续威胁监测中，发现长期活跃于中东及非洲地区的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT组织Mirage Kitten（又称UNC1549、Smoke Sandstorm、Nimbus Manticore）部署了一套此前未被公开记录的恶意软件工具集。该工具集由一款名为NightLedger的Windows后门程序和两款基于WebSocket协议的定制隧道代理工具BridgeHead、ArcBridge组成，三者协同构建起覆盖终端侦察、远程命令执行、文件窃取及隐蔽内网穿透的完整攻击链。Mirage Kitten长期针对航空航天、航空运输、国防军工及电信行业实施定向情报窃取，惯用手法包括鱼叉式钓鱼邮件、仿冒知名企业的招聘门户，以及多阶段递进式定制恶意载荷。此次新工具集的曝光表明，该组织在延续既有战术体系的基础上持续迭代其工具集，在隐蔽隧道通信与终端持久化控制方面的工程化程度明显提升。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">进一步分析显示，研究人员在埃及及巴基斯坦某航空航天机构的受害环境中，完整记录了</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">BridgeHead隧道工具在后渗透阶段的部署与运行过程。该部署行动与近期卡巴斯基记录的定向鱼叉式钓鱼活动高度吻合，也与Unit 42及Check Point Research公开披露的该组织作战特征一致。攻击者利用伪装为可信品牌和招聘平台的社会工程学诱饵，以及仿冒视频会议页面的钓鱼站点，诱使受害者下载托管于第三方文件分享服务上的恶意压缩包，从而实现初始入侵。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">值得注意的是，该组织在基础设施层面正逐步从</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Microsoft Azure子域名托管模式转向Cloudflare支持的域名体系，意在增加溯源难度，同时维持弹性可靠的命令控制通信能力。截至报告发布时，该组织多个C2域名及隧道基础设施仍处于活跃状态，持续对中东及非洲多国的政府、军工、航空及电信关键基础设施构成间谍威胁。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二、攻击过程与核心技术分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次攻击活动呈现典型的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT多阶段递进式作战特征。攻击者以定制化社会工程学手段完成初始突破，随后在受害网络内部署后门实施终端侦察与持久控制，并利用WebSocket隧道工具建立隐蔽的内网穿透通道，最终实现对敏感数据的长期窃取与远程操控。整套工具链在代码架构、互斥体命名规范及通信协议设计上保持高度一致，表明由同一团队统一开发维护。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">1）初始投递与社会工程学攻击</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在初始访问阶段，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Mirage Kitten延续了其鱼叉式钓鱼战术。攻击者为目标量身定制社会工程学诱饵，包括伪装为知名企业招聘通知的钓鱼邮件，以及高仿真的视频会议登录页面。受害者点击恶意链接或下载附件后，即被重定向至第三方文件分享服务上的恶意压缩包下载页面。该压缩包内含多阶段加载器，负责在受害终端上静默释放后续恶意载荷。尽管本次研究中大部分样本的初始投递向量尚未完全明确，但研究人员在埃及和巴基斯坦受害环境的后渗透活动中，明确观察到BridgeHead隧道工具的实战部署，其投放时机与钓鱼入侵后的横向渗透阶段紧密衔接，印证了该组织&#34;钓鱼突破、隧道驻留、长期潜伏&#34;的作战节奏。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2）NightLedger后门：终端侦察与持久化控制</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">NightLedger是本次曝光工具集中的核心后门组件。研究人员发现，该后门在代码结构与行为模式上与该组织历史植入物高度相似，据此将其归因于Mirage Kitten。该后门以恶意DLL形式存在，文件名伪装为合法系统组件，利用DLL搜索顺序劫持技术实施加载。具体而言，攻击者选定一个Windows合法二进制程序作为宿主，该程序在调用需要身份验证的RPC接口时会延迟加载某个依赖DLL。攻击者将恶意DLL与宿主程序置于同一目录下，利用系统的DLL搜索顺序使恶意DLL被优先加载；同时，恶意DLL通过转发导出函数维持原DLL的正常行为，从而规避静态检测。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">启动后，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">NightLedger首先创建UUID格式互斥体，确保同一主机上仅运行单一实例，若检测到互斥体已存在则立即退出。在通信层面，后门通过HTTPS协议周期性向C2服务器发起信标请求，并配置主、备两个C2节点，形成双节点容灾通信架构。C2服务器返回的指令载荷采用自定义分隔符&#34;#%%#&#34;进行字段切分，由内置命令调度器解析执行。这一协议设计与该组织此前被GTIG公开记录的后门TWOSTROKE存在明显技术渊源——后者使用十六进制编码并以&#34;@##@&#34;作为字段分隔符，两者在架构理念上一脉相承，但NightLedger的功能覆盖面有明显扩展。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">NightLedger支持涵盖终端侦察、远程操控与数据窃取的完整命令集，具体包括：采集当前用户与主机身份信息、执行任意进程或程序、遍历目录结构、下载文件至受感染系统、收集主机与网络配置信息、复制与删除文件、动态调整信标间隔、截取屏幕截图、加载任意DLL、终止指定进程与线程、通过POST请求向C2上传文件、枚举逻辑驱动器、列出运行进程，以及定向采集日志文件并附带进程列表信息。所有命令执行结果均通过HTTP POST请求回传至C2服务器指定端点，完成数据外泄。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">3）WebSocket隧道工具：ArcBridge与BridgeHead</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">ArcBridge和BridgeHead是两款自定义WebSocket隧道工具，核心功能是将受害主机转化为中继节点。攻击者在C2服务器端运行控制组件，受害主机上部署的代理组件则负责静默转发所有流量，使得出站连接看似源自受害组织内部网络，而非Mirage Kitten自身的基础设施。这种隧道机制使攻击者能够绕过网络边界防御、维持对已入侵环境的隐蔽访问，并显著增加检测难度。两款工具中，BridgeHead最早于2026年4月在针对中东地区受害者的攻击活动中被识别。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三、攻击目标与组织归因研判</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">综合本次攻击活动的受害者分布、目标行业特征及技战术特征（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TTP）分析，Mirage Kitten的打击范围覆盖中东及非洲多个国家的战略关键行业。根据卡巴斯基遥测数据，已确认的受害者遍布埃及、约旦、坦桑尼亚、巴基斯坦、埃塞俄比亚及布基纳法索等国，涉及政府机构、中小型企业、航空航天与航空运输组织、电信运营商以及金融行业实体。这一目标分布与该组织长期聚焦地缘战略情报收集的定位一致，其关注重点涵盖国防军工技术、航空运营数据、电信基础设施架构及政府决策信息，攻击意图指向国家级情报窃取而非经济牟利。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在组织归因层面，研究人员以高置信度将本次新工具集归因于</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Mirage Kitten，归因依据如下：NightLedger后门在代码结构、命令调度逻辑及C2通信协议设计上与该组织历史植入物TWOSTROKE存在直接继承关系，两者均采用自定义分隔符切分C2响应载荷的解析模式；NightLedger与ArcBridge共享UUID格式的互斥体命名规范，该开发习惯与该组织其他已公开工具的特征一致；BridgeHead的企业代理穿越逻辑与该组织此前使用的Retrograde后门及公开报告中记录的MiniFast、MiniUpdate工具在实现细节上高度重叠；两款隧道工具均延续了该组织对WebSocket隧道技术的依赖，与历史报告中记录的LIGHTRAIL和POLLBLEND隧道工具属于同一技术谱系。此外，攻击者在社会工程学层面使用的招聘主题钓鱼诱饵、仿冒视频会议页面等手法，与Unit 42及Check Point Research近期公开披露的Mirage Kitten作战特征完全一致。上述证据相互印证，支撑了归因结论。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">四、攻击事件总结</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次新型工具集的曝光，反映了</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Mirage Kitten网络间谍能力的最新演进。NightLedger后门在保留与TWOSTROKE一脉相承的核心命令功能基础上，新增了屏幕截图捕获及NetSetup.log域环境诊断日志定向采集等能力，表明攻击者正着力获取受害机构内部域架构信息。BridgeHead与ArcBridge两款WebSocket隧道工具的实战部署，延续了该组织将隧道穿透能力作为后渗透阶段标准组件的作战传统，并在代理穿越、定向执行验证及协议隐蔽性方面实现了工程化升级。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">另一值得关注的趋势是基础设施策略的调整。研究人员观察到，该组织正逐步从此前广泛使用的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Microsoft Azure子域名托管模式向Cloudflare支持的域名体系迁移。这一转变在保持C2通信弹性与可用性的同时，增加了安全社区通过云平台元数据进行基础设施关联与溯源的难度。整套工具集从初始钓鱼投递、终端后门驻留、内网隧道穿透到敏感数据外泄，构成了完整的全链路间谍作战体系，对中东及非洲地区航空航天、国防军工、电信及政府关键信息基础设施构成持续性、高隐蔽性的情报窃取威胁。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">参考链接：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://securelist.com/mirage-kitten-new-tools/120811/" target="_blank">https://securelist.com/mirage-kitten-new-tools/120811/</a></span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=be2cd92f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492961%26idx%3D1%26sn%3Db2a5eb75a1921313adf93682b03da54c">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 31 Jul 2026 00:09:00 +0800</pubDate>
    </item>
    <item>
      <title>俄语背景黑客组织依托AI技术打造复合型攻击体系，并发起网络攻击活动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492959&amp;idx=1&amp;sn=0d385ea5a4a551d6b8af8b2104fa9dc2</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-07-24 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一、事件概述</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">近日，网络安全研究人员监测发现，一个俄语背景威胁组织发起了代号为</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">&#34;Operation STANDOFF&#34;的大规模网络攻击行动。该行动不同于传统单一恶意软件攻击模式，在同一套共享基础设施上整合了四项相互支撑的攻击能力：批量分发通用型恶意软件（commodity malware）、将受害设备纳入代理僵尸网络、面向企业内网的人工键盘式渗透（hands-on-keyboard），以及AI驱动的多渠道舆论操控与大规模信息分发平台。上述能力依托共用工具链、统一开发团队及基于GitHub域名的流量隐匿策略紧密耦合，形成覆盖自动化犯罪、定向入侵与舆论操控的完整攻击链条。其中，该组织将AI技术深度嵌入舆论操控环节，搭建起具备自然语言生成与多通道自动分发能力的智能操控平台，能够以较低成本实施大规模协同性虚假信息行动（Coordinated Inauthentic Behavior）。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">进一步分析显示，该组织核心基础设施托管于俄罗斯主机服务商</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TimeWeb Ltd.（AS9123），其C2节点通过将流量重定向至GitHub域名隐匿真实服务器地址。研究人员借助基于虚拟机的全流程动态沙箱分析，完整捕获了恶意样本的进程行为、API调用、内存读写及网络外联等数据，将原本分散的恶意程序、隐蔽C2服务器、定制渗透后台及AI舆论操控平台等线索关联起来，最终发现44台此前未被任何安全厂商识别的C2服务器。该行动将自动化网络犯罪与人工主导的定向入侵相结合，并辅以大规模舆论操控，体现出当前俄语背景威胁组织的攻击能力已超越传统网络犯罪范畴。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">截至本报告发布时，该组织大量受控域名及网络基础设施仍处于活跃状态，可持续对政企内网资产、普通用户终端及社交舆论环境构成威胁，兼具经济牟利、数据窃取与舆论操控等多重目的，构成大范围、多层次的网络安全风险。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二、攻击过程与核心技术分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次攻击活动构建了分层递进的完整攻击链条：攻击者以规模化恶意软件投放为基础，利用隐蔽基础设施进行伪装，通过人工定向渗透深入内网，最终依托自研</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI平台实施舆论操控，各环节相互协同，整体隐蔽性与自动化程度较高。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">1）初始投递与持久化机制</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击初始阶段，该组织依托按安装付费（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Pay-Per-Install, PPI）渠道投放核心恶意载荷，载体为setup_x86_x64_install.exe，采用NSIS打包。该文件并非单一木马程序，而是多载荷集成加载器。程序运行后自动向系统临时目录释放数十个随机命名的恶意可执行文件，在后台静默启动Raccoon Stealer、RedLine、Amadey窃密程序与XMRig挖矿程序，同步达成凭证窃取、算力劫持、终端持续控制等多重目的。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">为维持载荷长期驻留，样本具备完备的防御对抗能力。程序调用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">PowerShell修改Microsoft Defender防护配置，关闭实时保护与云端上报功能，并将恶意目录添加至信任列表；主动检索并终止多款主流安全软件进程；禁用系统更新服务，阻断终端漏洞修复通道。在反溯源与反分析层面，载荷内置反调试、反沙箱逻辑，能够识别虚拟机、沙箱环境与调试工具；通过篡改文件时间戳、使用直接系统调用（Direct Syscall）规避终端监测，并结合进程镂空（Process Hollowing）、内存注入、DLL侧加载等内存对抗技术，增加安全检测与取证难度。此外，恶意程序通过修改注册表、创建伪装计划任务、部署伪装为VirtualBox的系统服务等方式构建多级持久化通道，实现长期隐蔽控制。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2）命令控制基础设施与GitHub流量伪装技术</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">终端失陷后，受害设备主动外联专属</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C2服务器，拉取配置文件与代理列表，随后被纳入该组织控制的僵尸网络，充当流量代理与网络转发节点。为规避网络空间测绘，该组织在俄罗斯TimeWeb机房部署了C2集群，并采用GitHub域名进行流量伪装：C2集群对非目标扫描请求返回301重定向至GitHub页面，仅对特定路径的C2通信请求返回控制指令，通过差异化响应隐藏恶意属性。同时，该组织利用Telegram、Mastodon、Pastebin等合法平台搭建死信箱解析器（Dead Drop Resolvers），确保在核心C2被封禁时仍能更新基础设施地址，维持攻击链路可用。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">3）多操作员协同控制台STANDOFF COORD</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">为支持针对政企</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Active Directory环境的定向渗透，该组织开发了定制化Web管理平台&#34;STANDOFF COORD&#34;。该平台架构参照专业红队工具设计，支持多人协同作业，具备资产管控、凭证存储及任务调度功能。平台可实时监测失陷终端状态，并按内外网及DMZ区域划分目标网段；内置凭证库用于分类存储NTLM哈希、Kerberos票据、会话Cookie及私钥，支持哈希传递（Pass-the-Hash）、票据伪造、密码喷洒及漏洞利用等横向移动手段。此外，平台内置标准化作业流程与积分考核机制，配合俄语知识库与可视化操作手册，形成了体系化的内网渗透作战模式。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">4）AI驱动的认知操纵与规模化传播</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次攻击的核心技术特征在于将</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI深度融入舆论操纵环节，构建了全自动化舆论操控与多渠道分发体系。该体系与僵尸网络及内网渗透设施共享技术栈与代理资源，形成&#34;引流、控量、造势、牟利&#34;的闭环，主要包含以下模块：</span></span></font></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">流量入口与账号农场</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该组织搭建面向俄语区的手游诱饵网站</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">&#34;Мобильная Арена（移动竞技场）&#34;，以福利兑换为诱饵聚集年轻用户群体。在此基础上部署AI驱动的Telegram账号农场，利用自动化脚本与大语言模型完成批量注册、验证码接收、IP隔离及养号操作。系统内置大语言模型引擎，支持自定义人设与文风，自动生成符合社交语境的评论与私信内容，在制造虚假热度的同时隐性推广博彩、欺诈服务及恶意软件。</span></span></font></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">跨平台自动化工作流</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该组织搭建可视化工作流引擎，集成</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Claude大模型API，打通邮件、Telegram、WhatsApp等渠道。攻击者可自定义工作流规则，由AI批量生成推广文案与引流话术，并定时执行群发任务。平台配套凭证仓库统一管理各渠道API密钥，结合僵尸网络代理资源，实现多IP、多账号、全时段的自动化传播。</span></span></font></p></li></ul><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">整套</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI体系具备较强的自主运行与拟人化交互能力，在大幅降低人工成本的同时，显著提升了虚假账号的隐蔽性与传播效能，使舆论操控与网络攻击形成相互支撑的协同效应。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三、攻击目标与组织归因研判</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">综合攻击链路、技术特征及基础设施分布分析，本次</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Operation STANDOFF行动呈现出分层化、精准化的目标体系，影响范围横跨个人用户与政企机构，兼具网络牟利与舆论操控双重属性。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在通用网络犯罪层面，该组织利用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">RedLine Stealer窃取目标终端的各类凭证与敏感数据，部署XMRig挖矿程序劫持计算资源，并将受控主机转化为代理节点为后续攻击提供跳板，波及全球范围内的个人用户及企业终端。在定向渗透层面，该组织借助STANDOFF COORD平台，针对Active Directory域环境实施人工键盘式渗透，完成凭证窃取与横向移动，目标锁定部署域控架构的中大型企业网络，意图获取域管理员等高权限访问。在信息操控层面，该组织依托Telegram账号农场、AI生成的虚拟人设及多渠道自动化分发平台，面向俄语手游玩家群体实施大规模定向信息投放与舆论引导，其意图不止于商业变现，亦可能服务于特定政治宣传目的。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研究人员综合恶意软件组件、基础设施指纹、运营模式及语言时区特征，以高置信度将本次攻击活动归因于具有俄语背景的专业化网络犯罪组织。具体依据如下：该组织全套攻击工具、后台管理界面及操作文档均以俄语编写，并明确要求操作人员以俄语记录工作日志；全部自动化任务调度、</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI工作流编排及系统日志时间戳统一采用莫斯科时区（UTC+3），地域与团队归属指向明确。与此同时，恶意软件分发、僵尸网络运营、政企内网渗透、AI舆论操控四大模块均部署于同一TimeWeb服务商基础设施之上，共享域名标识体系、前后端技术框架及代理网络资源，架构高度一致，印证上述能力系同一开发团队统筹构建、一体化运营。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该组织有别于松散的黑产团伙，展现出成熟的产业化运营能力与较强的自研水平，可独立完成从恶意软件定制、渗透平台开发到</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI自动化体系搭建、规模化舆论运营的全链条作业。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">四、攻击事件总结</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Operation STANDOFF事件表明，当前俄语网络犯罪组织的运作模式已突破传统恶意软件活动的范畴，单一组织即可同时运营通用恶意软件分发、代理僵尸网络、企业内网人工渗透及AI舆论操控四类攻击能力，且各模块共享基础设施与开发资源，耦合程度极高。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该行动最显著的特征在于</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">&#34;融合&#34;：无差别自动化攻击（窃密木马、挖矿程序、代理僵尸网络）与蓄意的人工定向渗透（针对Active Directory的凭据窃取、基于网络分段的横向目标筛选、共享攻击手册、多操作员协同计分板）并行实施，同时叠加依托批量化Telegram账号矩阵、AI生成人设及游戏诱饵的协调性影响力行动。如此广泛的攻击面，结合俄语工具链、莫斯科时区的作业调度规律以及贯穿始终的&#34;ggstandoff&#34;品牌标识，足以高置信度判定这是一个有组织、统一指挥的俄语犯罪组织，同步推进经济牟利与影响力操控双重目标。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">针对此类复合型威胁，相关机构不应仅依赖静态特征匹配的传统防御思路，应着重强化终端行为监控与网络流量异常检测能力，重点关注畸形</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">HTTP请求（如异常User-Agent字段）、非常规GitHub重定向链路，以及来自俄罗斯托管服务商的可疑TLS证书。此外，需警惕AI驱动的虚假社交互动与社会工程学攻击对传统安全边界的侵蚀，将信息操纵行为纳入威胁评估框架，构建涵盖恶意软件防护、入侵检测及信息操作识别的一体化防御体系。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">参考链接：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://www.vmray.com/execution-level-analysis-of-a-russian-speaking-multi-operator-intrusion-campaign-operation-standoff/" target="_blank">https://www.vmray.com/execution-level-analysis-of-a-russian-speaking-multi-operator-intrusion-campaign-operation-standoff/</a></span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=609239ef&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492959%26idx%3D1%26sn%3D0d385ea5a4a551d6b8af8b2104fa9dc2">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 24 Jul 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>黑客组织利用Gemini AI自动化构建与部署C&amp;C僵尸网络展开攻击活动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492957&amp;idx=1&amp;sn=f75188d1363a454cc529690a8f22a872</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-07-17 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一、事件概述</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">网络安全研究</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">人员</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">监测发现，俄语系黑客组织（追踪代号</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">“bandcampro”）近期借助AI技术，实现了网络攻击基础设施的快速自动化构建与迁移。该组织通过越狱版Google Gemini CLI，以俄语自然语言下达指令，由AI代理独立完成架构设计、代码编写、服务器部署及调试排错等全流程技术工作</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">仅用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">6分钟、投入11%的个人工作量，就完成了活跃命令与控制（C&amp;C）僵尸网络的架构迁移。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">此次事件的核心特征是，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI已从单纯的代码编写辅助工具，转变为攻击行动的核心执行者、技术顾问与交互载体。攻击者无需掌握专业技术，仅通过俄语表达攻击意图，AI即可自主完成从架构设计到故障排查的全流程操作，标志着网络攻击范式发生重大转变。</span></span></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7978339350180506" data-s="300,640" data-type="png" data-w="554" type="block" data-imgfileid="100009308" src="https://wechat2rss.xlab.app/img-proxy/?k=0212d83b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FHBRznhxajkYTIaYmOzzSMXyl2pU18Ha3asCzicHMFxApOuibZ5Bh90ZBMOuMS7DeVl3mjaJYHwFaibHmnDQITtFmbibN09iaVQajfic1UfXWemcjI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-align: center;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">图 </span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">1 </span></span><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">由</span></span></font><font face="Arial"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI</span></span></font><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">创建的新指挥与控制架构</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该攻击框架的核心逻辑被封装在</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">3个纯文本文件中（总计约5KB），具备极强的可复制性和“一次性可丢弃”特性。即便安全团队取缔其服务器，攻击者也能依托这些文件在数分钟内重建攻击环境，大幅削弱了传统打击手段的效果。此外，研究人员分析该组织2026年3月19日至4月21日的200余个Gemini CLI会话日志发现，其攻击活动范围广泛，除僵尸网络控制外，还包括利用AI进行密码破解、入侵WordPress商户，以及策划针对老年人的加密货币电话诈骗。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二、攻击过程分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">此次攻击充分展现了</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI在自动化网络攻击中的赋能作用，攻击过程主要分为C&amp;C架构AI驱动迁移、自然语言控制僵尸网络、核心攻击文件解析及AI辅助拓展犯罪活动四个层面。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.1 C&amp;C架构的AI驱动迁移</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该组织原有的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C&amp;C基础设施因采用Cloudflare隧道，频繁被防火墙及杀毒软件拦截，因此启动架构迁移工作。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">指令下达与知识封装：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2026年3月23日，攻击者先指令AI将旧C&amp;C设置整理为两页纯文本“技能文件”（SKILL.md），文件涵盖服务器功能、僵尸网络连接方式、感染流程等全部核心操作知识，随后仅向Gemini CLI下达“研究C2迁移”的单一指令，启动迁移流程。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">自动化部署与调试：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI读取技能文件后，自主生成包含服务器代码、载荷及配置文件的迁移包，在新VPS上完成解压、服务器启动及Cloudflare隧道配置。针对部署中出现的“502 Bad Gateway”错误，AI自主诊断问题并添加必要HTTP头信息；面对Cloudflare WAF的请求拦截，AI识别出需修改User-Agent头实现绕过，并自动完成配置调整。整个迁移调试过程耗时6分钟，攻击者未参与任何具体技术操作。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">故障排查与恢复：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">迁移完成后，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI检测发现僵尸网络客户端（bots）未成功重连，经诊断确定是Cloudflare负载均衡导致的“脑裂”问题（流量同时分发至新旧两台服务器）。AI随即指导攻击者关闭旧服务器，在攻击者执行操作后，AI确认所有僵尸网络客户端均已成功连接新服务器，整个排查恢复过程耗时约10分钟。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.2 自然语言控制的僵尸网络</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">新</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C&amp;C架构部署完成后，攻击者全程通过自然语言与AI交互，实现对僵尸网络的日常管控，未直接操作任何C&amp;C控制台。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">交互模式：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击者以俄语向</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI下达指令，AI将其转化为C&amp;C服务器可识别的API调用。例如，攻击者询问“检查哪些机器在线”时，AI会查询僵尸网络注册表并反馈活跃主机列表；攻击者要求“获取感染新机器的链接”时，AI可即时生成全新的PowerShell感染命令。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">技术架构：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C&amp;C服务器：采用极简Python HTTP服务器架构，所有运行状态均在内存中维护，不遗留任何磁盘操作痕迹；API路径（如/api/v1/update）设计与OpenAI流量特征相似，以此混淆安全检测。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">受害机器：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">被感染主机运行</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">PowerShell脚本，每5秒向C&amp;C服务器发起一次HTTPS GET请求，通过自定义X-Agent-ID头（包含计算机名与用户名）完成身份标识。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">持久化手段：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">根据获取权限的不同，分别采用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">WMI事件订阅、系统计划任务、修改注册表UserInitMprLogonScript等方式，实现恶意程序的持久化运行。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.3 三大核心文件：可传播的攻击框架</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">整个</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C&amp;C操作的核心逻辑被浓缩在3个纯文本文件中，构成了可快速传播、复用的攻击框架：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">GEMINI.md（越狱文件）：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">向</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI传递“授权渗透测试人员”身份信息，禁用安全免责声明功能，设置凭证自动保存且无需人工确认，规避AI的安全限制。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">SKILL.md（C&amp;C手册）：</span><span textstyle="" style="font-weight: normal;">完整包含攻击架构描述、标准操作流程、感染单行命令、持久化执行命令及故障排查步骤，是AI执行攻击操作的核心依据。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">C2_MIGRATION_GUIDE.md（部署配方）：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">明确</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">6个操作步骤，可支持全新AI会话在新服务器上快速恢复完整攻击能力。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">该攻击模式的危险性凸显：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI普及前，此类攻击需雇佣具备多年经验的专业技术人员实施；如今，核心攻击知识被压缩在5KB文件中，非技术型攻击者也可轻松阅读、使用。攻击基础设施实现“一次性可丢弃”，攻击者可随时替换服务器；与传统恶意软件即服务（MaaS）不同，这些技能文件可通过黑客论坛、即时通讯工具无门槛分享，无需专业技术交接。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.4 更广泛的AI辅助犯罪活动</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">会话日志显示，该组织的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI辅助犯罪活动远超C&amp;C运维范畴。在密码破解领域，其将AI作为大规模凭证变异引擎，从AntiPublic凭证数据库API拉取目标邮箱关联密码后，交由AI模型预测密码变种，生成的猜测方案效率远高于随机猜测，成功用于WordPress管理面板暴力破解。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在针对性入侵方面，攻击者向</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI提供Password数据导出文件后，AI自主识别出受害者所属企业，梳理出企业VPN的使用方式，甚至定位到企业内部管理面板，为后续入侵提供支撑。此外，会话记录还显示，该组织曾与AI探讨针对老年人实施加密货币电话诈骗的可行性，试图借助AI优化诈骗话术与实施流程。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三、事件总结</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次攻击的实施主体为俄语系黑客组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">“bandcampro”，安全厂商通过其社交账号标识完成追踪。该组织还运营着为期5年的“Patriot Bait”舆论欺诈项目，通过搭建Telegram社群，借助AI批量生成舆情内容引流，配套虚假加密货币钱包实施诈骗。值得警惕的是，该组织攻击者并无深厚的底层开发与运维专业能力，完全依托AI补齐技术短板，其攻击模式具备极强的扩散风险。整套攻击模板仅为5KB明文文件，可在黑客论坛、即时通讯工具中无门槛分享，且无中心化恶意软件服务，大幅提升了溯源与归因难度。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击者可随时指令</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI重写全部代码、更换域名、修改注册表项及API路径，导致传统基于静态特征、IOC黑名单的防护手段完全失效，攻击基础设施具备“关停即重建”的快速恢复能力。这是全球首例C&amp;C框架完全通过生成式AI编码代理实现构建、部署与运营的真实案例</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">充分表明：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI时代，网络犯罪的成功与否，不再单纯取决于攻击者的技术技能与经验，更取决于其想象力、创造力，以及与AI代理的协同配合能力，这也为网络安全防护工作带来了全新挑战。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">参考链接：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://www.trendmicro.com/en_us/research/26/g/actor-behind-patriot-bait-used-ai-to-deploy-c2-botnet.html" target="_blank">https://www.trendmicro.com/en_us/research/26/g/actor-behind-patriot-bait-used-ai-to-deploy-c2-botnet.html</a></span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=bb41c420&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492957%26idx%3D1%26sn%3Df75188d1363a454cc529690a8f22a872">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 17 Jul 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>疑似朝鲜APT组织针对苹果设备攻击技术的重大升级，使用新型macOS后门木马利用AI大模型技术展开攻击活动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492954&amp;idx=1&amp;sn=0d59f35eb0656807ebd34853e686ecea</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-07-15 16:19</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一、事件概述</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">近期，网络安全研究人员发现并完成了一款针对</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">macOS平台的新型后门恶意软件的分析工作，将其命名为macOS.Gaslight。该恶意软件采用Rust语言开发，集成了信息窃取、持久化驻留、交互式Shell后门三大核心功能，同时具备完整的加密隐蔽通信能力。其通过Telegram Bot API搭建命令与控制（C2）信道，配套部署自主开发的Python窃取组件及独立运行环境，专门针对macOS终端的浏览器凭证、密钥串、终端操作历史、系统配置等高度敏感数据进行窃取。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次威胁线索最早可追溯至</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2026年5月22日，该恶意软件的Mach-O文件（arm64架构、自签名）被上传至VirusTotal平台。截至本分析报告发布时，主流静态杀毒引擎仍无法识别该样本，可见其隐蔽性极强。2026年6月初，苹果XProtect安全机制率先通过文件哈希值检测到该样本，并以规则“MACOS_BONZAI_COBUCH”实施拦截。研究人员结合该规则特征，将BONZAI签名家族与朝鲜相关威胁活动关联，经高置信度评估认定，macOS.Gaslight隶属于朝鲜（DPRK）相关的macOS恶意软件活动集群。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">与传统恶意软件的沙箱逃逸思路不同，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">macOS.Gaslight的核心创新攻击手段，是针对安全分析师依赖大语言模型（LLM）辅助研判的分析流程，实施提示</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">词</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">注入攻击。该恶意软件内嵌约</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">3.5KB的伪造系统报错载荷，包含38条模仿运维日志和安全告警的虚假“系统”消息，其目的是污染AI分析工具对样本文本的信任边界，诱使大模型判定分析流程异常，进而直接中止或拒绝研判，以此大幅延长安全团队的处置响应时间。这一攻击手法不仅标志着朝鲜APT组织针对苹果终端的攻击技术实现重大升级，更开辟了恶意软件对抗AI安全分析的全新路径，对已全面落地LLM辅助研判的政企、科研及金融机构的macOS资产，构成了重大新型安全风险。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二、攻击过程分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">macOS.Gaslight构建了功能完备的攻击链路，以单一Rust二进制文件作为初始投递载体。该二进制文件采用临时签名（ad hoc signed），携带标识符endpoint-macos-aarch64-5555494492fc075f441637fb9d894913dde3a2ea。其核心功能模块及运作机制具体如下：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">1. 命令与控制（C2）通道</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该木马的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C2通信</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">是</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">基于</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Telegram Bot API的getUpdates轮询机制实现，轮询分支仅在未注册Webhook时触发执行。调度处理器主要识别三种Telegram错误码：BotBlocked、InvalidToken和Conflict。其中，Conflict响应被用于实现单实例锁功能——当同一Bot Token的两个实例同时发起轮询时，Telegram会返回Conflict响应，第二个实例检测到该响应后将立即终止运行，避免多实例冲突。当Bot Token验证通过且轮询循环激活后，攻击者可通过该通道向木马下达各类任务，收集到的敏感数据则通过Telegram的multipart attach://文件上传机制回传至攻击者端。值得注意的是，Bot Token、聊天ID（tg_room_id）及其他攻击者配置信息，均在木马运行时动态提供，并未嵌入样本本身，进一步提升了攻击的隐蔽性。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2. 传输层加固</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">所有</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C2载荷均采用AES-GCM算法加密，加密过程使用纯Rust实现的aes-gcm 0.10.3 crate，每条消息均通过CCRandomGenerateBytes生成全新的随机数（nonce），确保加密的唯一性和安全性。AES密钥由运行时攻击者配置中的aes_key字段提供，避免密钥硬编码带来的泄露风险。在载荷加密的基础上，木马还配置了自定义证书信任锚点，并调用SecTrustSetAnchorCertificatesOnly接口，将TLS信任评估范围限制于该自定义锚点。这一证书锁定机制可有效拒绝标准代理CA发起的连接拦截，阻止网络层面对攻击者流量的监控。同时，木马通过SCDynamicStoreCopyProxies接口读取系统当前活动的代理配置，使C2流量能够适配强制代理出站的企业网络环境，提升了攻击链路的兼容性。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">3. 攻击者访问与交互式 Shell</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">木马验证激活后，攻击者可获得一个交互式</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Shell，通过两个并置的命令菜单实现对目标终端的远程控制，菜单中共定义了六个核心命令：help（显示命令帮助信息）、id（向攻击者标识当前木马实例）、shell（通过execvp执行Shell命令，同时提供posix_spawnp作为备选执行路径）、kill（按进程ID终止指定进程）、upload（通过Telegram文件附加机制向外传输目标文件）、stop（终止木马运行）。此外，研究人员在分析中还发现了第七个命令focus痕迹，但因样本特征限制，未能恢复该命令的更多执行细节。为确保攻击链路的持续性，木马通过IOPMAssertionCreateWithName创建电源管理断言，防止目标系统进入睡眠状态，从而在用户不活动期间，持续维持C2轮询和敏感数据收集操作。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">4. 15字段跨平台攻击者配置</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">木马采用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">serde框架对运行时提供的配置数据块进行反序列化处理，15个配置字段名称以明文形式嵌入二进制文件，具体包括：tg_room_id、github_token、github_repo、github_polling_interval、main_upload_url、main_base_url、aes_key、payload_path_linux、payload_path_macos、persist_name_linux、persist_name_macos、persist_type_linux、persist_type_macos、init_python_enable、persist_enable。经分析发现，其中与Linux和GitHub相关的配置字段在本次macOS样本中并未被使用，这表明该配置架构并非针对单一平台设计，而是面向攻击者的更广泛工具集接口，具备跨平台扩展能力。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">5. Python窃取器与运行时供应链</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">木马内置一个</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">6.6KB的Base64编码Python脚本，作为核心数据收集模块。该脚本解码后，可实现对目标终端多类敏感数据的窃取，具体包括：Chrome、Brave、Firefox和Safari主流浏览器的存储数据；终端命令操作历史；系统已安装应用程序列表；通过ps aux命令获取的运行进程快照；通过system_profiler命令导出的系统软硬件配置文件；以及login.keychain-db的原始副本。收集到的所有数据会被归档至temp/collected_data.zip文件，再通过Telegram平台回传至攻击者。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">同时，木马还集成了一个</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2KB的Base64编码Bash安装程序，该程序可从astral-sh/python-build-standalone项目获取并部署独立的cpython-3.10.18解释器，确保Python窃取脚本能够在无系统原生Python环境的终端上正常运行。该安装程序携带常量PY_VERSION=3.10.18和BUILD_DATE=20250708，同时支持arm64和x86_64两种架构，适配不同硬件配置的macOS终端。值得关注的是，该安装程序代码中大量使用表情符号，且严格遵循固定的注释头格式，这一特征与LLM生成输出的特点高度一致。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">6. 针对分析师的提示词注入攻击</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">macOS.Gaslight最引人注目的特征，是其针对LLM辅助分析流程的提示词注入攻击。该木马并未采用大量传统反分析手段，仅通过dlsym在运行时解析API调用，避免嵌入静态符号表，同时动态定位自身可执行文件路径，而非采用硬编码方式，以此降低被静态分析识别的概率。其核心攻击载荷是一个3.5KB的Markdown围栏格式恶意数据块，包含38条以{{DATA}}令牌分隔的伪造“系统”消息。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该恶意数据块中的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">{{DATA}}令牌和Markdown围栏格式，刻意模仿了LLM</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">triage harness自身的提示词框架，模糊了不可信样本数据与可信分析指令之间的边界。这些伪造的系统消息涵盖令牌过期、内存不足终止、磁盘空间耗尽、重复操作失败等场景，还植入了关于注入漏洞和静态分析标记的虚假警告信息，其核心目标是诱使LLM代理中止、截断或拒绝对该样本的分析。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Check Point于2025年首次公开记录此类针对安全分析师的提示词注入攻击，但当时记录的仅是使用单一直接指令注入的Windows平台概念验证；随后，Socket也记录了Hades供应链载荷通过伪造提示词注入头污染AI辅助分析，以及泄露的Shai-Hulud代码携带“Anthropic Magic String”试图阻止Claude Code分析的案例。这些攻击案例均依赖单一注入块或注入头，与macOS.Gaslight采用的38条消息级联伪装框架存在明显区别，攻击隐蔽性和对抗性更强。此外，该木马在运行时输出中会自动删除其Telegram Bot Token，使得即使获取到运行日志、错误信息或崩溃工件的分析人员，也无法确定该关键Token，而此前多数已记录的Telegram Bot滥用案例中，Token均为可恢复状态。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三、攻击目标及组织归因</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从攻击目标来看，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">macOS.Gaslight明确针对macOS平台用户，其信息窃取功能覆盖主流浏览器数据、终端命令历史、系统配置文件及登录钥匙链等核心敏感信息，具备明确的凭证窃取和会话数据窃取意图，可直接为攻击者获取目标终端控制权、进一步渗透攻击提供支撑。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研究人员基于多方面证据，以高置信度将该恶意软件归因于朝鲜（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DPRK）相关的威胁活动集群，具体依据如下：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">一是苹果</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">XProtect以MACOS_BONZAI_COBUCH规则检测该样本，而SentinelLABS已明确将BONZAI签名家族与朝鲜相关威胁活动关联；</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">二是另一关联</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">BONZAI签名的样本被苹果AIRPIPE规则捕获，该家族同样被SentinelLABS认定与朝鲜威胁活动相关。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">此外，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">macOS.Gaslight所集成的技术能力，包括Rust编写的持久化后门、交互式Shell、自staging Python收集链及加固的Telegram C2通道，均为朝鲜相关威胁组织常用的成熟macOS攻击手法，进一步印证了上述归因结论。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">四、攻击事件总结</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研究人员指出，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">macOS.Gaslight是一款集成多种先进技术的macOS恶意软件，其将凭据与会话数据窃取器、交互式Shell以及自staging Python收集链，整合在单个持久化Rust二进制文件中，攻击功能全面且隐蔽性极强。该木马最具创新性的特征，是针对安全分析师的提示词注入攻击——通过38条伪造系统消息构成的级联伪装框架，将日益普及的 LLM 辅助恶意软件分析流程武器化，实现对抗分析的目的。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">macOS.Gaslight的出现，标志着恶意软件对抗手段迎来新的发展方向：攻击目标从传统的沙箱检测环境，转向了依赖LLM进行辅助分析的安全分析师本身。这一趋势为网络安全行业敲响了警钟，在构建LLM辅助分析工具时，需将所分析的样本内容视为对抗性输入，而非可执行的可信指令，同时做好恶意内容与分析模型的完全隔离工作。随着LLM辅助分析在恶意软件逆向工程领域的应用日益普及，防御者需提前做好应对准备，预期未来将出现更多专门针对此类分析流程设计的恶意样本，进一步提升网络安全防御的难度。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">参考链接：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/" target="_blank">https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/</a> </span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=93ea0e59&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492954%26idx%3D1%26sn%3D0d59f35eb0656807ebd34853e686ecea">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 15 Jul 2026 16:19:00 +0800</pubDate>
    </item>
    <item>
      <title>APT组织Armored Likho利用新型窃密武器针对政府机构、电力能源行业展开攻击活动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492952&amp;idx=1&amp;sn=a9f5852e83ac583edf0dbfe1d1909b79</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-07-10 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一、背景概述</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2025年以来，安全研究人员持续追踪到一个此前未被公开记录的APT组织——Armored Likho（亦称Eagle Werewolf）。据卡巴斯基2026年6月报告，该组织近期发起多轮定向鱼叉式钓鱼攻击，目标涵盖俄罗斯、巴西和哈萨克斯坦的政府机构及电力能源行业，兼具经济牟利与网络间谍双重目的。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Armored Likho</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">区别于传统</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT的显著特点，是将针对个人的资金窃取与针对组织的定向间谍</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">行动相融合。其武器库包含高度混淆的模块化</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">RAT、信息窃取程序，以及Go2Tunnel等隧道工具，可依据受害者类型动态加载适配载荷。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在近期</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">活动</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">中，研究人员首次捕获到</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">其组织使用的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">核心窃密组件</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">——BusySnake Stealer。值得注意的是，BusySnake早期载荷（投放器与stager）中存在大量冗余注释和emoji符号，明显异于人工编写习惯，暗示攻击者可能借助大语言模型辅助生成代码。这种AI辅助手法模糊了TTP特征，增大了归因难度。同时，日志与配置中出现的乌克兰语痕迹为地缘背景提供了线索，但确切起源尚无定论。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从更长周期看，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Armored Likho</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">活动可追溯至</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2023年。其前身Eagle Werewolf集群自2023年5月起持续针对政府和国防机构</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">展开攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，重点关注无人机研发单位。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2026年2月，该组织入侵无人机话题Telegram频道，通过伪装成星链设备激活清单的Rust投放器散布AquilaRAT。2024年6月及2025年1月的多轮攻击中，其工具集持续迭代，技术演进能力明显。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二、技术过程分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">1</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">）初始入侵向量与载荷投递</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">初始入侵依赖鱼叉式钓鱼邮件，邮件主题紧扣政府通告、社会援助申请、人道物资申请及无债务证明等官方场景。本次捕获的恶意附件多为</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">RAR压缩包，文件名如zayavka_gumanitarnayapomosch.rar（人道主义援助申请）极具欺骗性。包内藏有EXE可执行文件或LNK快捷方式，名称与邮件主题一致，诱使用户执行。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">EXE路径下，压缩包内含名为psihologicheskiy_test.exe（心理测试）的文件，实为NSIS制作的SFX自解压归档。双击后，前台显示伪装的心理问卷诱饵程序，后台则将合法文件pnx.exe释放至临时目录并加载。恶意代码通过进程注入将</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">s</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">hellcode写入pnx.exe内存，由注入进程从攻击者控制的GitHub仓库拉取后续载荷。利用GitHub分发载荷，可避免直接暴露C2服务器。仓库中留存有测试样本及旧版代码，且内容更新已自动化，支持快速更换载荷与仓库，运营灵活性较高。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">然后</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">下载的压缩包解压至</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">%appdata%\WindowsHelper，作为后续组件工作区。完整内容包括：核心载荷module.pyw、PyArmor运行时、Python 3.12解释器、get-pip.py（安装pip及依赖库）。依赖安装后，生成两个VBS脚本：wh_selfdelete.vbs删除已执行的投放器，run.vbs通过计划任务每5分钟循环启动module.pyw，实现持久化。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">另一场景中，压缩包内载荷替换为恶意</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">LNK文件，利用已修复的Windows LNK参数显示漏洞（CVE-2025-9491，ZDI-CAN-25373）。攻击者在LNK目标路径中插入换行符或大量空格，将真实恶意命令参数隐匿于可视区域外。用户查看时显示正常，实际指向一段混淆PowerShell命令。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">具体</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">执行流程</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">是</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">LNK通过rundll32调用混淆命令，触发PowerShell下载远程stager并运行。stager首先从C2拉取与邮件主题匹配的DOCX诱饵文档并打开，随后初始化运行环境（远程URL、本地目录、依赖库列表），下载Python 3.12解释器、get-pip.py及包含 module.pyw的data.zip。后续依赖安装、VBS生成、计划任务注册与EXE路径基本一致，最终完成持久化控制。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">）</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">BusySnake Stealer核心功能剖析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">BusySnake Stealer是基于Python3的Windows信息窃取程序，源码经PyArmor Pro v9.2.0深度混淆，采用字节码按需解密</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">函数调用时解密，返回后立即重加密。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">程序</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">以</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">.pyw扩展名运行，无控制台窗口，规避用户与基础监控。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">程序采用模块化事件处理架构，各核心功能由独立</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">handler实现：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">单实例控制与持久化</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">通过文件系统锁</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Roaming\WindowsHelper\screenshots\.lock判断是否被占用。若未被占用，读取锁内PID，若对应进程不存在且系统启动时间晚于锁文件修改时间，则重建锁并启动。持久化通过ensure_schtask检查计划任务，若缺失则自动重建VBS脚本并注册任务，确保重启后恢复。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">剪贴板监控与键盘记录</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">start_key_clipboard_logger持续监控剪贴板更新，检测到变化时将时间戳和内容按[Clipboard] {timestamp} {escaped_content}格式写入本地日志，可捕获密码、加密货币地址、API密钥等敏感文本。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">文件系统枚举与</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">HEX密钥提取</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">start_inventory_background递归遍历文件系统，在Roaming\WindowsHelper下创建SQLite数据库inventory_state.db，建表scanned_files（路径、修改时间、大小）。遍历排除系统目录、超过16MB的大文件及忽略扩展名列表中的类型。发现的文件传入extract_hex64_from_file，用正则搜索64位十六进制字符串（加密货币私钥、API令牌等），结果存入SQLite、日志并上传C2。扫描完成后输出乌克兰语日志，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">这些内容</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">成为归因</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">重要</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">线索。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">用户文档定向窃取</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">start_send_documents_priority_background枚举所有逻辑驱动器，确定系统盘后遍历用户目录下的Desktop、Documents、Downloads。排除以$开头或含System Volume Information的子目录，过滤已上传及超过5MB的文件，剩余文件加密传输至C2。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">浏览器密码与</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">Cookie窃取</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">支持</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Chromium内核（Chrome、Edge、Opera、Brave等）及Firefox的密码提取。对Chromium，定位用户数据目录，找到含主密钥的Login State文件，通过DPAPI（win32crypt.CryptUnprotectData）解密主密钥，再SQL查询SELECT origin_url, username_value, password_value FROM logins并用主密钥解密密码，保存为chromium_passwords.json。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">对</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Firefox，遍历Mozilla\Firefox\Profiles，检查logins.json和key4.db。读取加密用户名和密码字段，构造SECItem，调用NSS库NSS_Init()初始化，自动加载key4.db密钥，用PK11SDR_Decrypt()解密。利用的是Firefox未设主密码时可自动解密的缺陷。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Cookie窃取</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">过程是，当</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">收到</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C2命令handle_collect_and_send_cookies后，从Chromium Cookies数据库和Firefox cookies.sqlite提取解密，保存为all_browser_data.json回传。另</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">外还有个</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">激进方案</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">当</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">收到</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">handle_extract_cookies_v7_command后，从GitHub下载加密Python模块，启动本地Web服务器（127.0.0.1:8000），构造含manifest.json和sw.js的浏览器扩展，通过命令行启动Chrome加载扩展，扩展读取cookie回传本地服务器，再上传C2。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">反向</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">SSH隧道与远程控制</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">将</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Go2Tunnel反向SSH隧道功能利用合法工具使恶意流量混入</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">合法流量</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">当</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">收到</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">handle_start_proxy_command后，向/tunnel/create/请求获取SSH私钥及连接命令，在受害主机建立反向隧道，穿透防火墙和NAT。远程桌面方面，集成RustDesk利用。handle_remote_control_command检测是否已安装RustDesk，若未安装则从GitHub下载，已安装则强制重启生成新凭据（ID和密码），截图捕获凭据并上传C2。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">OTP密钥搜索与加密货币钱包窃取</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">handle_search_2fa_secrets_command扫描剪贴板和文件系统，搜索otpauth:// 协议前缀（TOTP导出格式），提取密钥保存至2fa_secrets.txt。handle_search_wallet_jsons_command搜索用户目录下所有.json钱包文件。handle_split_and_send_tdata_command强制结束telegram.exe，复制tdata目录下会话和账户数据，打包上传，实现Telegram账户接管。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">C2通信与任务调度</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">通过</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">poll_task轮询C2，向/get_task?client_id=DESKTOP-{hostname}发起GET请求，伪装Edge User-Agent。C2面板采用Web表单登录，以下发命令名称方式调度对应handler。任务执行后向/report_status提交JSON状态报告（含客户端ID、命令名、状态、注释）。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">后续版本</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">中攻击者</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">调整</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">了</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">计划任务创建逻辑，通过</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">win32com.client调用Schedule.Service COM接口实现任务下发。该版本新增两项具备隐蔽性的设计：一是自定义任务唯一标识，二是四阶段任务生命周期状态管理（SCHEDULED、IN_PROGRESS、SUCCEEDED、FAILED）；同时对C2通信端点完成重构，升级为RESTful规范接口，路径为/api/v1/client/{id}/commands/。工具新增poll_tasks轮询模块，可接收任意Python载荷脚本，在独立进程内存空间直接解释执行、全程无磁盘落写操作，这一改造让BusySnake脱离单一信息窃取工具定位，升级为支持插件加载、可灵活拓展功能的模块化恶意平台。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三、攻击溯源归因</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研究人员的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">综合技术分析，确认</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">BusySnake与Armored Likho存在中度置信度关联</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">具体归因</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">依据如下：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">隧道机制同源性：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Armored Likho</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">先前广泛使用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Go语言编写的Go2Tunnel反向SSH隧道工具，而BusySnake以内置函数形式集成相同功能。两者均向C2请求SSH私钥和连接参数，SSH命令行参数完全一致，API端点结构相似，代码层面复制排除了偶然性。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">架构相似性：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">BusySnake与AquilaRAT均采用C2命令驱动的handler事件处理架构，功能封装为独立函数，由统一分发层调度。任务状态回传端点与数据格式一致。持久化命名伪装策略相同，均模仿Microsoft官方组件。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">基础设施重叠：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">BI.ZONE追踪的Eagle Werewolf与Armored Likho</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">明显重叠。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Eagle Werewolf自2023年起针对政府和国防机构，关注无人机领域，惯用钓鱼邮件和RAT，2026年2月通过Starlink伪装投放器传播AquilaRAT并使用Go2Tunnel，手法与Armored Likho高度吻合。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">语言与地域特征：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">BusySnake文件枚举日志使用乌克兰语，表明开发者或运营者具备乌克兰语能力。攻击目标分布在俄罗斯、巴西、哈萨克斯坦，以俄罗斯政府与能源为主，符合东欧地区APT行动特征。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">四、攻击影响与结论</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Armored Likho</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">的攻击行动揭示了</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT领域的若干重要趋势。该组织“金融窃取与网络间谍融合”的模式模糊了传统APT与犯罪团伙的边界</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">同一平台既可窃取浏览器凭据、加密货币获取收益，又能通过文件遍历、文档外泄和反向隧道实现政企深度渗透，对基于单一威胁模型的防御体系构成根本挑战。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">技术对抗层面，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Armored Likho</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">展示了多层反检测策略：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">PyArmor Pro商业混淆与按需解密使静态分析困难；LNK漏洞（CVE-2025-9491）隐藏恶意命令；GitHub分发将恶意流量混入合法请求；利用RustDesk等合法工具包装远程控制。传统特征匹配与静态分析方案难以应对。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">最后，研究人员发现</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">截至</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2026年6月，Armored Likho仍高度活跃，基础设施持续在线，工具链从Go2Tunnel到AquilaRAT再到BusySnake不断演进，功能与隐蔽性双向提升。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">参考链接：</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="Calibri"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://securelist.ru/tr/armored-likho-apt-with-busysnake-stealer/116058/" target="_blank">https://securelist.ru/tr/armored-likho-apt-with-busysnake-stealer/116058/</a></span></span></font></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e4e74cb1&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492952%26idx%3D1%26sn%3Da9f5852e83ac583edf0dbfe1d1909b79">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 10 Jul 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>APT组织Turla最新网络攻击武器StockStay深度分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492950&amp;idx=1&amp;sn=1e5615b8a94c3c0e5e6d95141d678fa7</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-07-03 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一、</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">背景概述</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2022年12月以来，俄罗斯背景的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Turla（又名SUMMIT、Secret Blizzard、VENOMOUS BEAR、UAC-0194）持续开发并部署了一款名为STOCKSTAY的.NET后门。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">近日，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">GTIG</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">安全研究人员近期对其进行了详细</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">且深入</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">分析</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该后门主要针对乌克兰政府机构、军事单位以及意大利外交政策相关实体，用于长期网络间谍活动。其</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">程序的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">代码结构与功能特性与此前归因于</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Turla的成熟工具包KAZUAR存在明显重合。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Turla</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">是已知活动时间最长的国家级网络间谍</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织之一，可疑行动可追溯至</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2004年。该组织至今仍保持活跃，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">手法</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">也</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">不断翻新</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">——例如部署专用脚本截获Signal即时通讯用户的加密通信、劫持已废弃的犯罪僵尸网络攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">高价值</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">目标，以及近期利用高度复杂的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">KAZUAR工具包针对军事国防领域发动攻击。美国CISA曾公开将Turla（尤其是其长期使用的Snake植入物）归因于俄罗斯联邦安全局（FSB）第16中心。作为我们对Turla持续追踪工作的一部分，本</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">次任务是</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">梳理了</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">STOCKSTAY的分析结果，给出了关键开发节点和行动时间线，并对比了其与KAZUAR的相似之处，以便将该新型工具纳入Turla不断扩展的攻击武器库中加以定位。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">STOCKSTAY是一款基于.NET Framework、采用Windows Forms框架编写的多组件后门。它通过安全WebSocket与C2服务器通信，底层使用了开源库websocket-sharp。其后端由多个独立组件构成，组件之间借助WM_COPYDATA消息机制实现IPC通信。早期版本被设计成股票市场行情查看工具的模样，文件名方案、配置结构以及控制消息和响应数据的存储格式都围绕这一伪装展开。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研究人员</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">捕获的早期样本虽仍保留该类内部特征，但到</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2025年，已发现变种开始伪装成PDF阅读器、计算器等更为普通的应用程序。</span></span></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6137184115523465" data-s="300,640" data-type="png" data-w="554" type="block" data-imgfileid="100009301" src="https://wechat2rss.xlab.app/img-proxy/?k=19a72d41&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FHBRznhxajkZ1qIe02wwCzLicgc3L8GgTdY6hYPph83HiaJWrlqnWqsnalVx9daj3DyCicnDdtoWK7EapB0Nb9NNO5JsIkS2AOSp4x2rHUevIvs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-align: center;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">图 </span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">1 </span></span><font face="Arial"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">STOCKSTAY</span></span></font><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">观测时间线</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二、</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">技术</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">过程</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">技术</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">架构层面看，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">STOCKSTAY采用了高度模块化设计，由四个相互协作的组件构成：</span></span></font><font face="宋体"></font></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">StockStay.MarketMaker：作为加载器负责投递与部署，在后台运行并从远程服务器拉取完整恶意组件，同时设置开机自启项。</span></span></font></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">StockStay.StockBroker：网络隧道组件，可通过代理服务器与攻击者控制的C2建立稳定的加密WebSocket连接。</span></span></font></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">StockStay.StockTrader：核心后门模块，执行具体恶意操作，包括文件下载与上传、屏幕截图、注册表修改、进程创建及系统信息采集等。</span></span></font></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">StockStay.StockMarket：统筹调度模块，负责解析加密配置文件、设定任务执行间隔及休眠周期，以规避检测。</span></span></font></p></li></ul><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">各组件之间通过</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">WM_COPYDATA消息进行进程间通信。通信安全方面，后门利用websocket-sharp库建立WSS连接，并采用4096位RSA密钥对进行非对称加密。值得注意的是，其配置文件采用“环境密钥”（environmental keying）方式加密，只有匹配特定目标环境的条件下才能解密成功——这一设计有效防止了分析人员在非目标环境中还原配置内容。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">初始入侵阶段，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Turla</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">运用了多种社工手段：通过被入侵的乌克兰大学邮箱发送钓鱼邮件；利用伪装成国防培训学院的恶意</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">RDP配置文件，引诱受害者连接至攻击者控制的基础设施；2025年11月的一次大规模钓鱼活动中，攻击者向约20个乌克兰目标投递了利用WinRAR路径遍历漏洞（CVE-2025-8088）的恶意RAR压缩包。此外，攻击者还借助被入侵的乌克兰国家监管服务网站及境内WordPress服务器托管并投递载荷——这种利用本地可信基础设施的做法使流量检测难度大幅增加。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">运营层面，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">STOCKSTAY的隐蔽策略同样值得关注。恶意软件仅在周一至周五的9:00至18:00之间运行，刻意与正常办公时段保持一致，以降低异常行为告警触发的概率。早期版本伪装成股票数据查看工具，2025年已演变为假冒PDF阅读器、计算器等日常软件。部分攻击场景中，研究人员还观察到攻击者将后门组件重命名为“MicrosoftUpdateOneDrive.exe”等看似正常的系统进程名，以规避进程监控。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研究人员</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">的分析还发现，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">STOCKSTAY与Turla此前使用的KAZUAR间谍工具之间存在明显的代码和功能重叠。两者均采用多组件模块化结构，且组件角色高度对应——KAZUAR由Kernel、Bridge、Worker三部分构成，与STOCKSTAY的StockMarket、StockBroker、StockTrader在功能划分上几乎一致。这进一步印证了两款工具出自同一开发团队。在实际攻防场景中，STOCKSTAY通常部署于攻击行动的后期阶段，即攻击者已通过KAZUAR完成对目标网络的全面侦察之后才投入使用。这表明Turla正有意将STOCKSTAY作为备用或升级选项进行实战测试，以防既有攻击通道被乌方安全人员封堵。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三、</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">攻击溯源归因</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">经安全研究人员溯源分析，确认</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">STOCKSTAY恶意程序生态体系及其相关攻击活动，与Turla</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">存在高度可信</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">关联，具体溯源依据如下：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">首先，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">STOCKSTAY恶意程序在指令解析与执行流程中，全程采用Windows-1251编码格式。该编码专为西里尔字符集适配设计，是具备高度辨识度的地域特征编码，能够佐证该恶意程序的开发环境、调试运行场景大概率关联东欧、巴尔干半岛及中亚区域，与Turla</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">的地缘背景特征高度契合。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">其次，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">STOCKSTAY与Turla</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">专属工具包</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">KAZUAR存在核心代码特征重合。在近期的迭代更新中，两款恶意工具在同一时间周期内同步集成了K1MORPHER字符串混淆技术，用以规避静态查杀、隐藏程序核心逻辑，这种高度一致的技术迭代特征，进一步印证了二者的同源性。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">再者，研究人员在威胁监测中发现，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">STOCKSTAY的载荷投递链路依托于一批已被攻陷的网络基础设施。经交叉核验，该批受控基础设施同时承载着Turla</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">KAZUAR工具的命令与控制（C2）服务，是其针对目标受害者开展远程操控的核心C2节点，二者共用攻击基础设施的特征明确。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">最后，从攻击目标与武器链部署维度可佐证关联。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Turla</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">长期将乌克兰国防、军事类组织机构作为核心攻击目标</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">相关安全厂商</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">近期处置的多起安全事件中，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">安全研究</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">团队多次捕获该</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">的完整攻击链路</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">其在入侵过程中会批量部署</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">STOCKSTAY、WILDDAY、DIAMONDBACK及KAZUAR等多款自研专属恶意软件，形成成套的恶意工具武器链。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">参考链接：</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering" target="_blank">https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering</a></span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b7ff5c57&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492950%26idx%3D1%26sn%3D1e5615b8a94c3c0e5e6d95141d678fa7">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 03 Jul 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>疑似越南APT组织APT32（海莲花/OceanLotus）作战重心转向越南国内</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492947&amp;idx=1&amp;sn=cfca46d8e8b986821fa0edb7cc146854</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-06-26 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;" data-pm-slice="0 0 []"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">近日，国际知名网络安全厂商发布专项威胁研究报告，完整梳理</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2024年年中至2026年3月越南APT组织海莲花（又称：APT32，OceanLotus）全系列攻击活动，明确该组织作战战略发生重大调整</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">即</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">大幅收缩面向境外目标的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">网络</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">间谍攻击行动，将核心资源倾斜至越南</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">国内</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">实体，并依托自研后门</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">SPECTRALVIPER</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">实施</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">两起长期潜伏</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">网络攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">行动</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击对象分别为越南</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">国内</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">基建交通龙头企业</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">和</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">证券投资软件供应链，两起行动目标与越南</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">国内</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">反腐、金融市场专项整治工作高度匹配。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">海莲花</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">是存续周期超</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">14年的老牌国家级APT</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织，业界可追溯的公开追踪记录最早始于</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2012年</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">长期被全球安全厂商认定为承接越南</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">政府部门</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">情报搜集需求</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">传统攻击重心长期锁定中国、东南亚</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">等</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">多国</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">的政府</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">机构、企业及相关人员。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2017至2020年，该组织多次发起大规模水坑攻击、跨国企业内网入侵</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">等</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，同时</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">也</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">定向针对旅居境外的越南异议人士、人权工作者实施</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">信息</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">窃</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">取攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2020年Facebook曝光其线下掩护企业后，该组织对外活动</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">部分</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">转入静默，公开曝光事件数量大幅下降。直至</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2023年，安全</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">厂商再</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">次披露其新型后门</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">SPECTRALVIPER针对越南</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">国内</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">企业的攻击样本，海莲花</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">才重新进入行业视野</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研究人员</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">持续近两年的追踪监测，完整还原该组织全新作战布局。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次监测周期内，海莲花</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织主要</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">依托</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">SPECTRALVIPER执行</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">了</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">两起核心间谍行动，覆盖越南</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">国内</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">基建、金融证券两大关键领域。第一起长期入侵行动始于</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2024年11月，攻击者持续渗透一家越南大型基建交通建设集团内网，潜伏周期长达15个月，直至2026年2月逐步停止全部恶意</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">活动。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该攻击活动，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研究</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">人员并未</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">直接捕获初始入侵完整链路</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">不过，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">结合受害企业暴露的公网服务器资产</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">分析</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研判，攻击者极有可能利用微软</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">SQL服务器远程代码执行漏洞完成初始访问。攻击者在</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">受害企业</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">内网</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">里</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">投放</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">了</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">多</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">个不同版本的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">SPECTRALVIPER变种</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">后门木马</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">来</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">适配不同终端</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">设备系统</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">环境</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">以带有合法数字签名的商用工具</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Toolbox.exe作为DLL侧加载载体，篡改程序文件名伪装为Genuine.exe、AutoCAD242.exe等常用办公软件</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">搭配定制命令行参数加载恶意后门载荷</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DtlCrashCatch.dll，随后将恶意程序注入系统进程实现无痕迹持久化驻留。攻击者同步搭建多组专属C2域名与管控服务器用于数据加密外</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">传</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，并在攻击不同阶段持续更换域名，规避流量审计设备检测。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">第二起攻击为典型软件供应链投毒</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">事件，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击者主要是</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">瞄准越南</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">国内</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">头部金融科技企业</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">FireAnt旗下专业数据分析</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">工具</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">FireAnt MetaKit，活动周期自2025年10月延续至2026年3月。该专业数据分析工具</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">被大量的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">个人投资者</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">和</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">机构量化团队</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">用于</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">对接多款主流量化分析软件，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">获取</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">实时股市行情与历史交易数据。攻击者</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">通过远程控制</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">官方平台更新服务器，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">并</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">篡改</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">了</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">正版</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">程序</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">更新分发链路</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">然后，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">利用软件更新机制存在的两</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">个</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">高危安全缺陷实施投毒</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">一是版本配置文件</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">version.xml未配置任何文件完整性校验机制，系统无法识别被篡改的更新安装包；二是版本文件、更新程序传输链路全程未启用SSL/TLS加密，尽管本次攻击者未实施流量劫持，但原生架构本身存在极高被劫持风险。</span></span></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7129963898916968" data-s="300,640" data-type="png" data-w="554" type="block" data-imgfileid="100009298" src="https://wechat2rss.xlab.app/img-proxy/?k=fa5dd420&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FHBRznhxajkZCtCQcCR5loJ5RWrQMZzTfQoGlzXsgq5wTfxym6icAJUb5FZluIUXYzcvyBleH2aZpcg1gkdwnFuxwbYUslf3MUk7Ot0RXsGK8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-align: center;margin: 8px 0px;text-indent: 0px;"><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">图 </span></span></font><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">1 </span></span><font face="Arial"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">FireAnt </span></span></font><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">供应链攻击的执行链</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次供应链攻击分为测试迭代、稳定投放两个阶段。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2025年10月2日，攻击者上线首轮测试下载器，未做代码混淆处理，复用历史后门样本与旧攻击基础设施，仅用于验证分发链路可用性</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2025年</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">10月17日切换至稳定版本，对下载器实施高强度代码混淆，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">并</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">采用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">API接口动态远程拉取载荷</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击者</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">搭建全新独立</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C2服务器，注册伪装域名financemachinelearning.com，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">并</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">伪装成金融机器学习站点，贴合股民群体正常网络访问特征。普通投资者执行软件常规更新时，被篡改的合法更新程序将自动启动恶意下载器</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">工具先采集本机软硬件基础信息并上传至中转节点，再远程拉取完整</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">SPECTRALVIPER后门载荷</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">然后</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">通过</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DLL侧加载机制伪造驱动程序IntelAudioService.exe，将恶意DLL注入OneDrive同步服务进程</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">中</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，实现长期后台静默潜伏。恶意后门</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">木马</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">全程通过</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">HTTPS加密信道与C2服务器通信，在请求Cookie字段嵌入加密主机标识信息，使用全新流量标记前缀zd_cs_pm=区分载荷流量，与该组织过</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">去</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">惯用的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">euconsent-v2标识形成差异化攻击者特征指纹。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">值得重点关注</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">的是，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">尽管本次供应链投毒可覆盖平台全部用户，但攻击者</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">确</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">采用定向选择性分发策略，仅向少量投资者终端推送完整后门载荷，并非</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">采用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">无差别全域感染</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">模式。这种攻击策略，也</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">印证</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">了</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">海莲花</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">当前</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">采用的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">精准定向情报窃取的作战思路。研究</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">人员</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">多次向</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">FireAnt厂商同步安全事件预警，始终未收到企业官方回应</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">不过，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">截至</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">到</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">报告发布</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">时</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，该供应链恶意分发链路已停止推送恶意载荷。除此之外，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2025年7月第三方情报机构披露海莲花</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">曾向</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Python官方包索引</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">PyPI</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">），</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">上传恶意程序包发起供应链攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">但</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研究人员</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">全球遥测数据未捕获对应受害终端，无法独立佐证该攻击归属。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">背景</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">动机</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">分析，海莲花</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">大规模转向越南</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">国内</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击的时间线，与越南全国反腐专项行动</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">“熔炉行动”高度重合。自2016年起越南持续推进公职人员、企业贪腐整治，2023年先后两名国家主席因相关腐败丑闻离任</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">仅</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2025全年，就有9600名党员干部因经济犯罪、滥用职权问题受到党纪处分。同年10月，越南金融监管机构披露近十年间70家</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">国内</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">大型企业存在债券申报造假问题，事件直接引发该国股指大幅下跌，监管层面同步强化证券市场违规案件排查力度。海莲花</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">针对基建国企、证券投资者的两起间谍行动，恰好对应国内反腐、金融违规核查两大治理方向</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研究人员判断该组织调整攻击重心，或与越南本土经济案件、金融犯罪调查的情报搜集需求直接相关。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击事件的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研究实现关键技术突破，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">主要</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">源于海莲花</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">一处典型作战安全疏漏：部分</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">SPECTRALVIPER样本未清除RTTI（Run-Time Type Information，运行时类型信息）</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研究人员</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">才</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">得以完整逆向还原后门整体架构。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">SPECTRALVIPER基于组织自研XGU开发框架构建，内置Pivot内网跳板调度模块、Feature远程操控模块</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">等</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，支持多终端内网横向渗透</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">程序通过命名管道在多台沦陷主机间分发指令，选取一台主机作为总调度节点对接外部</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C2服务器，其余终端仅接收内网指令，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">这样就能</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">大幅</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">度</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">降低外联暴露概率。后门</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">程序</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">同时集成</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">ProcessManager、ProcessReflector进程反射注入工具套件，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">可以</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">支持任意系统进程注入、第三方恶意载荷下发</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">并</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">执行</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该后门程序是</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">集持久化驻留、动态载荷加载、内网渗透多重攻击能力于一体</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">所有对外通信均采用加密</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">HTTPS协议</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击者会根据不同攻击场景定制行业伪装域名，模拟目标业务正常流量特征，规避终端、边界安全设备检测。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">安全研究人员指出，海莲花组织已积累十余年恶意工具研发与迭代经验，长期维护适配</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Windows、Linux双平台的后门套件</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">武器库</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。该组织以往</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">常会自研独有网络通信协议，或是针对特定作战目标定制化开发数据窃取功能。其标志性恶意工具包含：</span></span></font><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Denis（别名SOUNDBITE），依靠DNS隧道实现命令与控制信道通信</span></span><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">；</span></span></font><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">PHOREAL借助ICMP协议搭建命令控制通道；WINDSHIELD内置特殊代理绕过机制</span></span><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">不过，该事件攻击者使用的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">其主力后门程序</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">SPECTRALVIPER，在内网协同渗透、网络流量伪装两大核心能力上</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">都</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">完成了显著技术升级。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">参考链接：</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/" target="_blank">https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/</a></span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link mp_article_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=ad81f7f0&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492947%26idx%3D1%26sn%3Dcfca46d8e8b986821fa0edb7cc146854">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 26 Jun 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>TeamPCP组织2025-2026全球软件供应链攻击活动综合分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492944&amp;idx=1&amp;sn=8c6e632ee5384847be174290f4d81ae0</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-06-12 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <h1 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一、背景概述</span></span></font></b></h1><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2025年底至2026年5月，一个被称为TeamPCP的威胁组织在全球范围内发起了一场规模空前、手法精密的软件供应链攻击行动。该组织以云原生基础设施和开发者生态系统为核心攻击目标，通过系统性地渗透和污染全球广泛使用的开源安全工具、AI开发框架、企业级SDK和代码编辑器扩展，构建了一条从单点入侵到全域失守的完整攻击链路。截至2026年5月底，该攻击活动已确认涉及至少十余波攻击序列（Campaign Wave），污染超过600个npm和PyPI软件包，覆盖超过50万台设备和服务器，窃取超过50万条各类凭证，直接和间接经济损失超过10亿美元。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TeamPCP并非孤立的黑产团伙。该组织也被业内同步追踪命名为DeadCatx3、PCPcat、ShellForce，并与CipherForce、Vect勒索软件组织存在关联。其攻击动机呈现出经济利益与地缘政治目标并存的双重特征：既通过凭证窃取和勒索变现获取非法收益，也针对特定国家和地区部署破坏性擦除载荷。在长达半年的活跃期内，TeamPCP逐步将其攻击能力从最初的云原生容器入侵，演进为具备自我传播功能的蠕虫级供应链攻击平台，并最终于2026年5月将完整的攻击框架源代码公开发布至GitHub，引发全球范围内的复制模仿潮。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次攻击活动的核心特征在于其对</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">&#34;信任关系&#34;的系统性利用。TeamPCP没有选择直接攻击最终用户，而是集中于渗透开发者与企业默认信任的环节——漏洞扫描器、CI/CD流水线、AI网关、官方SDK、代码编辑器扩展等。通过在这些高权限、高信任度的组件中植入恶意代码，攻击者实现了对全球开发环境的大规模、无感知渗透，彻底击穿了现行DevSecOps安全体系的底层信任假设。全球多家顶级安全厂商——包括Elastic、Trend Micro、Forcepoint、SentinelLabs、Wiz、Sysdig、Snyk、Socket、Endor Labs、Datadog等——均发布了针对该组织的专题分析报告。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次攻击的完整时间线横跨</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2025年12月至2026年5月，在GitHub平台内部代码库泄露、微软官方SDK被投毒、AI领域核心工具被植入后门等标志性事件中达到高潮，并向全球安全界提出了一道无解的命题：当安全工具本身不再可信、当官方发布渠道无法保障安全、当数字签名和构建证明可以被伪造——我们的软件开发与分发体系，究竟还能依赖什么？</span></span></font></p><h1 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二</span></span></font><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">、攻击活动时间线与关键事件</span></span></font></b></h1><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TeamPCP的攻击行动经历了从云原生环境初始渗透、到供应链投毒大规模爆发、再到攻击框架开源化扩散的完整演进过程。根据全球多家安全厂商的追踪记录，可将其攻击活动划分为以下六个关键阶段：</span></span></font></p><h2 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.1 </span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">第一阶段：云原生初始渗透（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2025年12月—2026年2月）</span></span></font></b></h2><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TeamPCP的首次公开曝光始于2025年12月底，安全研究人员观察到一场针对云原生环境的&#34;蠕虫驱动&#34;大规模攻击活动。攻击者利用暴露的Docker API接口、Kubernetes集群、Ray仪表板和Redis服务器等云原生基础设施组件，系统性建立恶意网络，用于后续的网络犯罪活动。这一阶段的攻击特征以凭证窃取和持久化后门植入为主，攻击者通过批量扫描互联网暴露的云服务端口获取初始访问权限。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2026年2月，TeamPCP进一步演化其攻击手段，开始利用窃取的云凭据进行横向移动，并在被攻陷的环境中部署名为CanisterWorm的后门程序。Elastic Security在这一时期发布了针对TeamPCP容器攻击场景的专题检测工程分析，详细记录了攻击者从初始漏洞利用、容器逃逸到集群横向移动的完整攻击链路。</span></span></font></p><h2 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.2 第二阶段：Trivy供应链投毒及连锁反应（2026年3月）</span></span></font></b></h2><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2026年3月18日至19日，TeamPCP发动了其攻击生涯中最具影响力的单次行动——对全球顶级开源漏洞扫描器Trivy的全链路供应链投毒。Trivy由Aqua Security公司维护，在GitHub上拥有超过3.3万Star，Docker Hub累计下载量超1亿次，是全球DevSecOps体系中的核心安全组件。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击者通过前期窃取的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Aqua Security相关仓库的高权限维护凭证，对Trivy的GitHub Actions组件（trivy-action、setup-trivy）发起强制推送攻击，批量篡改仓库中76个版本标签中的75个，仅0.35.0版本侥幸未受影响。同步地，攻击者向Docker Hub推送了无官方发布记录的v0.69.5、v0.69.6恶意镜像，并向GitHub Releases、GHCR和ECR等所有分发渠道同步投毒。由于攻击者在恶意代码中完整保留了Trivy的正常扫描功能，仅在扫描逻辑执行前静默植入凭证窃取程序，绝大多数用户在使用过程中完全无法察觉异常。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">此次攻击的直接波及范围创下近年纪录：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">GitHub生态中超10万个开源项目调用了受污染的Trivy Actions；Docker Hub恶意镜像累计拉取量超百万次。更为严重的是，攻击者从失陷的CI/CD流水线中窃取了数十万条高价值凭证，为后续更大规模的供应链攻击储备了充足的&#34;弹药&#34;。此事件被追踪为CVE-2026-33634（CVSS评分9.4）。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">3月19日起，TeamPCP利用从Trivy事件中窃取的凭证，接连发起针对多个知名开源项目的精准打击：3月23日至24日，利用窃取的GitHub PAT令牌入侵Checkmarx公司KICS静态分析工具的GitHub Actions工作流和OpenVSX扩展市场，同时攻击AI网关LiteLLM的PyPI包（1.82.7和1.82.8版本），在40分钟内窃取超过50万条凭证；3月27日，入侵PyPI包Telnyx（v4.87.1/v4.87.2），累计影响超74.2万次下载。在上述攻击中，TeamPCP均采用Python的.pth文件机制或npm的postinstall钩子实现安装时即自动执行恶意代码。</span></span></font></p><h2 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.3 第三阶段：CanisterWorm蠕虫扩散与勒索变现尝试（2026年3月下旬—4月中旬）</span></span></font></b></h2><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">CanisterWorm是TeamPCP开发的具备自我传播能力的供应链蠕虫，标志着该组织的攻击能力从&#34;手动定向投毒&#34;升级为&#34;自动化生态级扩散&#34;。该蠕虫的核心逻辑极为精妙：利用从Trivy等事件中窃取的npm发布凭证，自动登录受害者账号，遍历该账号下所有开源包，逐一推送植入同源恶意代码的patch版本。新的恶意包被下载后会继续窃取新的凭证，形成指数级扩散链条。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">CanisterWorm最独特的技术特征是其对ICP（Internet Computer）区块链的创造性滥用。攻击者将C2逻辑编写成智能合约（Canister）部署在ICP区块链上，恶意代码通过与智能合约交互获取指令和上传数据。由于区块链的去中心化特性，该C2基础设施无法通过传统的域名封禁或IP封锁方式关停，极大提升了防御方的溯源与反制难度。这是全球首次公开记录的利用ICP区块链进行恶意命令控制的案例。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2026年3月下旬，TeamPCP在CanisterWorm的载荷中新增了针对伊朗的定向数据擦除功能（被称为&#34;kamikaze.sh&#34;）。该破坏性载荷通过双重检测机制——系统时区是否为Asia/Tehran以及默认语言是否为波斯语——精确识别伊朗环境。对匹配的Kubernetes集群，部署名为host-provisioner-iran的特权DaemonSet，挂载主机根文件系统后删除所有顶层目录并强制重启；对非Kubernetes的伊朗系统，直接执行rm -rf /命令。对非伊朗系统则仅保持静默后门，不做破坏。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2026年4月15日，与TeamPCP关联的Vect勒索软件组织开始在暗网发布受害者数据，受害者数量达25个，标志着TeamPCP将窃取的凭证正式转化为勒索变现渠道。然而，截至5月底，Vect和CipherForce的受害者网站均保持长期静默，多家安全厂商推测其勒索变现渠道已受损。</span></span></font></p><h2 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.4 第四阶段：多波次精准打击与杀伤链精炼（2026年4月22日—5月11日）</span></span></font></b></h2><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2026年4月下旬至5月上旬，TeamPCP连续发动了至少七波经Trend Micro确认的供应链攻击，这一阶段的攻击呈现出三个显著特征：一是从单一渠道投毒升级为多通道同步污染；二是攻击目标从开源工具向企业级商业SDK和AI基础设施扩展；三是攻击框架从定制化工具向标准化、模块化平台演进。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">4月22日，TeamPCP同时对Checkmarx KICS的三个分发渠道发动攻击：修改Docker Hub上的六个官方镜像标签（alpine、debian、latest、v2.1.20、v2.1.20-debian以及伪造的v2.1.21），向OpenVSX推送恶意VS Code扩展（cx-dev-assist和ast-results），修改GitHub Actions工作流以序列化全部仓库密钥。三个渠道的载荷均下载Bun运行时并执行约10MB的JavaScript凭证窃取程序mcpAddon.js，窃取目标涵盖GitHub PAT、npm Token、AWS/Azure/GCP云凭证、SSH私钥、AI和MCP配置文件以及Shell历史记录。24小时内，攻击者即利用窃取的npm令牌发布了恶意Bitwarden CLI版本（v2026.4.0），约334次下载发生在93分钟的暴露窗口内。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">4月24日，TeamPCP通过一次极为简洁的GitHub Actions脚本注入攻击攻陷了elementary-data项目（PyPI月下载量超110万次）。攻击者仅在一个Pull Request的评论区中发布了一条curl管道到bash的命令，利用workflow中未经过滤的${{ github.event.comment.body }}表达式直接在CI Runner上执行了任意命令。利用Runner持有的GITHUB_TOKEN，攻击者伪造了带标签的发布提交并触发了项目自身的合法发布流水线——最终生成并签名了一个包含恶意.pth文件的&#34;官方&#34;版本，通过了PyPI所有标准校验。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">4月30日，TeamPCP入侵PyTorch Lightning的PyPI账号，发布恶意版本2.6.2和2.6.3。恶意代码在import lightning时自动激活，18分钟后即被Socket安全团队检测并下架，但期间已有数万次下载。同期的攻击目标还包括Axios、SAP官方npm SDK、Intercom官方包和Xinference PyPI包等，实现了从前端生态到企业级软件的全覆盖。</span></span></font></p><h2 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.5 第五阶段：Mini Shai-Hulud蠕虫爆发与攻击框架开源化（2026年5月11日—5月24日）</span></span></font></b></h2><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2026年5月11日，TeamPCP发动了其最具破坏性的单次攻击——Mini Shai-Hulud蠕虫攻击。当日攻击者劫持了TanStack官方发布流水线，在短短六分钟内通过OIDC令牌滥用机制向npm推送了42个@tanstack命名空间下包的84个恶意版本，其中包括每周下载量超过千万级的@tanstack/react-router。这一波攻击创造了供应链攻击史上两项&#34;首次&#34;：首次携带有有效SLSA Build Level 3构建签名的恶意npm包，以及首次在单个小时内实现如此高密度的恶意版本发布。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Mini Shai-Hulud具备完全自动化的自我复制能力，其传播机制打破了传统供应链攻击的边界：每个被感染的开发者不仅自身凭证被窃取，其维护的所有npm包也将在无人干预的情况下被自动植入同源恶意代码。蠕虫载荷在npm install期间即执行（通过preinstall钩子），窃取超过20类凭证——GitHub和npm Token、AWS密钥、GCP和Azure令牌、SSH密钥、Kubernetes服务账户、HashiCorp Vault密钥、Stripe API密钥以及1Password和Bitwarden本地密码库。持久化机制通过在~/.claude/settings.json和.vscode/tasks.json中植入钩子，使恶意代码在IDE和AI编码助手启动时重新激活。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">5月12日，TeamPCP将Mini Shai-Hulud的完整框架源代码公开发布至GitHub，仓库README中明确标注&#34;Love - TeamPCP&#34;和&#34;Change keys and C2 as needed&#34;。这是一次蓄意的攻击能力扩散行为。Datadog Security Labs的分析显示，这是一个模块化的TypeScript/Bun工具包，涵盖凭证收割、供应链投毒和加密外传的完整功能。在源码发布的数小时内，至少出现了三个独立的复制分支，其中一个甚至增加了FreeBSD支持。截至5月19日，已有47个可独立运行的变种被全球安全厂商确认，影响范围从前端npm生态迅速蔓延至PyPI、Packagist、RubyGems等多个开源包管理平台。</span></span></font></p><h2 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.6 第六阶段：</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">GitHub内部入侵与微软SDK投毒（2026年5月18日—5月24日）</span></span></font></b></h2><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2026年5月18日，TeamPCP通过一条精心设计的多级攻击链入侵了GitHub内部系统。攻击者利用5月11日TanStack事件中通过OIDC滥用（追踪为CVE-2026-45321）窃取的凭证，向Visual Studio Marketplace推送了恶意Nx Console VS Code扩展（v18.95.0，发布者nrwl.angular-console，带有verified-publisher徽章，约220万安装量）。该恶意扩展在市场上存活了约18分钟，但由于VS Code的自动更新机制，GitHub一名员工的开发端点在此期间完成了自动升级。攻击者通过该端点窃取了开发者密钥，随后横向移动进入GitHub内部CI/CD系统，最终外传了约3,800个GitHub内部代码仓库。GitHub CISO Alexis Wales于5月21日公开确认此事，并指出OpenAI、Grafana Labs和Mistral AI为下游受害者。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">5月19日，攻击进一步升级：TeamPCP向PyPI发布了微软官方durabletask Python SDK（Azure Durable Functions客户端，月下载量约41.7万次）的恶意版本1.4.1至1.4.3，恶意代码在约35分钟的窗口内存活。该载荷的第二阶段被独立报告描述为携带Linux磁盘擦除器，同时具备凭证窃取和云环境内自传播功能（通过AWS SSM在EC2内部传播、通过kubectl exec在Kubernetes内部传播）。同日，TeamPCP通过攻陷的维护者账号&#34;atool&#34;，向@antv npm生态发布了639个恶意包版本（涵盖323个独立包），包括每周下载量约110万的echarts-for-react和约420万的size-sensor。其中42个恶意包在npm UI中展示了伪造的Sigstore验证徽章。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">5月22日，Shai-Hulud框架源码在GitHub公开发布并被多个独立攻击者复制使用，引发了全球范围内对TeamPCP攻击手法的大规模模仿。5月24日的ISC SANS日记中，安全研究员Kenneth Hartman以&#34;单周内三次叠加升级&#34;为标题总结了这一阶段：GitHub内部入侵、微软官方SDK被投毒、@antv npm生态遭史上最大单波污染，三项事件在72小时内密集发生。</span></span></font></p><h1 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三、攻击技战术深度分析</span></span></font></b></h1><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TeamPCP的攻击技术体系呈现出高度专业化、模块化和持续演进的显著特征。其技战术（TTPs）经过至少五轮迭代优化，已从最初的手动容器入侵发展为具备自我传播能力的自动化供应链攻击平台。综合全球多家安全厂商的技术分析，可将该组织的核心攻击技法归纳为以下七个方面：</span></span></font></p><h2 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">3.1 </span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">初始访问：多层次凭证窃取与信任关系渗透</span></span></font></b></h2><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TeamPCP不依赖零日漏洞进行初始突破，而是系统性地利用现代软件开发体系中的信任关系和权限缺口获取初始访问权。其主要入口向量包括：通过钓鱼邮件和社会工程学攻击窃取开源项目维护者的账号凭证和API令牌；扫描互联网暴露的Docker API（端口2375）、Kubernetes集群、Ray仪表板和Redis服务器等未授权访问的云原生服务；利用前期攻击中窃取的GitHub PAT和npm Token进行凭证复用（Credential Stuffing）；以及通过GitHub Actions工作流中的Pull Request评论注入漏洞在CI Runner上执行任意命令。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">elementary-data事件中，攻击者仅通过一条Pull Request评论就获得了CI Runner的完整控制权，无需窃取任何维护者凭证即可利用项目自身的签名基础设施发布恶意版本。在微软durabletask事件中，攻击者则直接通过窃取的PyPI发布令牌向官方仓库推送恶意版本，表明其已经成功渗透了项目维护者的凭证体系。</span></span></font></p><h2 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">3.2 执行机制：三运行时多态引导与隐式代码执行</span></span></font></b></h2><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TeamPCP开发了一套覆盖JavaScript/Bun、Python和Bash三种运行时的多态载荷引导体系，确保恶意代码能在最广泛的CI/CD和开发环境中实现自动执行。在npm生态中，攻击者通过package.json的preinstall或postinstall脚本在包安装时即触发恶意代码执行，利用Bun运行时的高性能特性在正常安装时间窗口内完成全量凭证扫描。在Python生态中，攻击者通过.pth文件（如litellm_init.pth、elementary.pth）注入恶意代码——任何以&#34;import&#34;开头的.pth文件行将在Python解释器启动时自动执行，无需用户显式导入被污染的包，影响范围覆盖该主机上所有Python进程。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Sha1-Hulud（即Shai-Hulud的公开版本）的源代码分析揭示了三个完全独立的引导路径：Bun/JavaScript主路径、Python备选路径和Bash三级路径。每次攻击活动中，攻击者都会轮换载荷文件名和执行钩子，通过操作层面的多态性规避基于哈希和文件名的静态检测规则。</span></span></font></p><h2 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">3.3 凭证窃取：从环境变量到进程内存的全维度收割</span></span></font></b></h2><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">凭证窃取是</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TeamPCP所有攻击活动的基础目标，其窃密载荷的覆盖范围远超常规信息窃取木马。在文件系统层面，载荷扫描超过100个预定义路径，涵盖~/.ssh/私钥、~/.kube/config集群凭证、~/.docker/config.json容器仓库凭证、~/.npmrc和.pypirc包注册表令牌、~/.aws/credentials和~/.azure/云凭证文件、~/.git-credentials Git认证信息、Shell历史记录（.bash_history、.zsh_history）以及AI编码助手配置文件（~/.claude.json、~/.claude/mcp.json、~/.claude/settings.json）。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在环境变量层面，载荷遍历所有进程环境变量，批量匹配包含</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">KEY、TOKEN、SECRET、PASSWORD、CREDENTIALS等关键词的敏感值。在云API层面，载荷通过完整的AWS SigV4凭证解析链（环境变量→INI配置文件→IRSA OIDC→ECS容器元数据→EC2 IMDS）实现自动化的云环境适配，并通过AWS SSM和Secrets Manager API在跨区域维度上进行全量密钥枚举。在进程内存层面，最危险的技术是Runner Secret Dump——载荷通过sudo python3 -c执行AES-256-GCM加密的Python脚本，读取GitHub Actions Runner Worker和Listener进程内存，提取所有被注入的Secret，包括被GitHub标记为masked的敏感值。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">所有窃取的数据经</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AES-256-GCM（随机会话密钥）加密后，会话密钥再通过攻击者的RSA-OAEP公钥加密，最后以Base64编码外传。在KICS事件中还引入了通过创建公开GitHub仓库（以沙丘系列小说中的词汇命名）作为辅助死信箱的传输机制。</span></span></font></p><h2 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">3.4 命令与控制：ICP区块链C2与多层基础设施轮换</span></span></font></b></h2><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TeamPCP在C2架构设计中展现了极高的对抗性思维。其最具创新性的技术是利用ICP区块链的智能合约（Canister）作为C2服务器——将C2逻辑编写为部署在去中心化网络上的不可删除的智能合约，恶意代码通过与智能合约的标准API交互获取命令并上传数据，通信流量在外观上与正常的区块链交易无异。CanisterWorm使用的ICP Canister地址为tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在传统</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">HTTP C2方面，TeamPCP通过Cloudflare隧道域名进行载荷分发和C2通信轮换，增加了网络层拦截难度。Bitwarden CLI恶意版本还引入了C2域名恢复机制：如果主C2不可达，载荷会通过GitHub Commit Search API搜索特定的commit marker字符串，自动检索RSA签名的备用外传域名，实现基础设施热切换。此外，TeamPCP在整个攻击活动中使用了大量一致的特征标记，包括：X-Rise-To-The-Trinny: agree和X-Filename: tpcp.tar.gz等品牌化HTTP头、tpcp.tar.gz统一归档文件名、以沙丘词汇命名的GitHub仓库、commit message标志&#34;LongLiveTheResistanceAgainstMachines&#34;、以及复用的Session Messenger标识符作为XOR加密密钥种子。</span></span></font></p><h2 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">3.5 持久化机制：IDE与AI编码助手注入</span></span></font></b></h2><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TeamPCP设计了一套覆盖开发者工作环境全生命周期的持久化体系，远超传统恶意软件对操作系统启动项的依赖。在IDE层面，攻击者在.vscode/tasks.json中植入恶意任务定义，使VS Code在特定触发条件下自动执行恶意代码。在AI编码助手层面，攻击者在~/.claude/settings.json中注入配置，使Anthropic Claude编码助手在启动时激活恶意载荷。在Python层面，通过site-packages中的.pth文件实现在每次Python解释器启动时重新激活。在系统服务层面，恶意代码安装名为internal-monitor或pgmonitor的systemd服务，以及在Windows Startup文件夹中植入启动项，确保跨操作系统的持久化。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">LiteLLM v1.82.8版本中引入的Sysmon.py持久化模块实现了一个基于轮询的远程代码执行后门：首次启动时休眠300秒，随后每50分钟（3000秒）检查hxxps[://]checkmarx[.]zone/raw，如果响应中包含以&#34;http&#34;开头的URL，则下载文件至/tmp/pglog并作为后台进程执行。</span></span></font></p><h2 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">3.6 横向移动与蠕虫传播：从单点到生态级的攻击扩散</span></span></font></b></h2><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TeamPCP设计了多层次的横向移动和自传播机制。在npm/PyPI生态层面，CanisterWorm和Mini Shai-Hulud蠕虫利用窃取的包注册表令牌，自动扫描受害者可发布的所有包，逐包推送植入恶意代码的新版本，实现无人干预的自动化扩散。在云环境层面，载荷通过AWS SSM在EC2实例之间、通过kubectl exec在Kubernetes Pod之间进行横向移动。在SSH层面，最新版擦除器载荷（第三版）解析SSH认证日志识别曾连接的机器，窃取私钥后尝试重新连接并传播载荷。在Docker层面，载荷扫描本地子网2375端口暴露的Docker API，向未授权的Docker守护进程部署恶意容器。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Mini Shai-Hulud的&#34;受害者变传播者&#34;机制是这一体系的核心创新：每个被感染的开发者和CI/CD流水线都成为蠕虫的传播节点。攻击者还利用GitHub Actions的OIDC令牌机制（id-token: write权限配合pull_request_target触发器），在合法的CI/CD流程内生成附带有效Sigstore签名的恶意包，使其通过npm audit签名校验，传统SCA工具完全无法检测。</span></span></font></p><h2 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">3.7 防御规避：签名伪造、全兼容投毒与多态混淆</span></span></font></b></h2><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TeamPCP在防御规避领域的投入不亚于其攻击能力。在签名伪造方面，Mini Shai-Hulud通过劫持的OIDC令牌生成了通过SLSA Build Level 3认证的有效Sigstore构建签名，42个@antv恶意包在npm UI中展示了伪造的Sigstore验证徽章，从两方面同时对软件供应链的签名信任体系发起冲击。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在投毒隐蔽性方面，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TeamPCP始终坚持&#34;全兼容&#34;投毒原则——恶意代码完整保留被污染工具的正常功能（如Trivy继续正常扫描、LiteLLM继续正常代理API），使用户体验完全不受影响，从行为层面消除可疑信号。在代码混淆方面，载荷通过AES-256-GCM加密所有敏感字符串常量，加之操作层面的多态性（文件名、钩子类型、外传路径的持续轮换），使基于静态特征的安全检测大面积失效。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在环境检测方面，载荷通过多重反调试和反沙箱机制（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">GetTickCount时间检测、CheckRemoteDebuggerPresent调试器检测、进程列表枚举排查Wireshark/Process Monitor等分析工具）识别安全分析环境，一旦确认即主动终止执行。攻击者还在LiteLLM和Xinference等载荷中嵌入复用的Session Messenger标识符作为XOR加密密钥种子，该标识符同时作为操作者联系方式，成为跨攻击波次的关键关联标记。</span></span></font></p><h1 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">四、事件影响评估</span></span></font></b></h1><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TeamPCP发起的这起持续性供应链攻击行动，其影响已远超单次安全事件的范畴，对整个全球软件开发与安全体系产生了深层次的冲击：</span></span></font></p><h2 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">4.1 </span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">直接影响：超大规模失陷与凭证泄露</span></span></font></b></h2><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从量化维度来看，本次攻击行动的直接影响堪称近年来供应链安全领域的极端事件。超过</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">600个npm和PyPI软件包被植入恶意代码，50万台以上设备和服务器受到影响，超过50万条各类凭证被窃取，涵盖GitHub Token、云平台AccessKey、npm/PyPI发布令牌、SSH私钥、Kubernetes集群凭证、密码管理器数据库等核心安全资产。GitHub内部约3,800个私有代码仓库源码被外传，欧盟委员会超过90GB的敏感数据被窃取。直接和间接经济损失初步估计超过10亿美元。受影响企业和机构涵盖GitHub、微软、OpenAI、Mistral AI、Grafana Labs、SAP、Intercom、Bitwarden、Checkmarx、Aqua Security、Cisco等全球知名组织。</span></span></font></p><h2 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">4.2 信任体系崩塌：安全工具不再保证安全</span></span></font></b></h2><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TeamPCP的攻击在本质上是针对现代软件开发信任体系的精准打击。长久以来，开发者社区对&#34;安全工具自带安全性&#34;的假设根深蒂固——漏洞扫描器、静态分析工具、密码管理器等被视为安全防线最可信赖的组成部分，被赋予了最高的系统权限。Trivy和KICS事件的讽刺在于：安全工具本身变成了最大的攻击载体，攻击者通过投毒安全工具获得了对企业CI/CD流水线的&#34;万能钥匙&#34;级访问权限。正如安全界广为流传的评论所言：&#34;你用Trivy来扫描漏洞、防范供应链攻击，而Trivy本身就是最大的供应链攻击载体。&#34;这种信任悖论从根本上动摇了DevSecOps的理论前提。</span></span></font></p><h2 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">4.3 数字签名体系遭受双重攻击</span></span></font></b></h2><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Mini Shai-Hulud攻击在软件供应链安全领域引发了一场关于签名信任的危机。该攻击同时从两个方向击穿了现有的数字签名验证体系：一方面，通过劫持合法的发布流水线产生附带有效SLSA签名和Sigstore构建证明的恶意包；另一方面，在npm UI中展示伪造的Sigstore验证徽章误导开发者。这组攻击证明了：发布者账户的合法性与单次发布事件的安全性是完全不同的两个维度，而现有的验证体系将两者混为一谈。elementary-data事件进一步揭示了深度问题——即使是项目自身CI基础设施签名发布的包，也可以是恶意的。</span></span></font></p><h2 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">4.4 攻击能力扩散：从APT级能力到&#34;开源攻击平台&#34;</span></span></font></b></h2><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TeamPCP于2026年5月12日将Shai-Hulud框架完整源代码公开发布至GitHub，标志着其攻击策略从&#34;保持技术优势&#34;转向&#34;蓄意扩散攻击能力&#34;。截止5月19日，全球已出现47个可独立运行的变种，至少3个复制分支在代码发布后数小时内即开始活跃部署。这一行为将原本属于高级威胁组织专属能力的供应链蠕虫攻击技术，转化为任何具有基础编程能力的攻击者都可以获取并部署的标准化工具。对于防御方而言，这意味着基于TeamPCP特定框架构件的检测规则将面临大规模误报——无法区分TeamPCP本体的攻击与模仿者的攻击，归因难度呈指数级增加。</span></span></font></p><h1 style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">五、总结与展望</span></span></font></b></h1><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TeamPCP组织在2025年底至2026年5月间发起的这场持续性全球软件供应链攻击行动，是有史以来规模最大、链条最长、创新密度最高的供应链安全事件之一。它从根本上改写了行业对供应链安全威胁模型的认知，揭示出现行DevSecOps体系在信任架构层面的结构性缺陷。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该组织的攻击行动呈现出四个核心特征：其一，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">&#34;上游突破、下游感染&#34;的策略实现了以最小攻击成本换取最大化影响范围；其二，&#34;全兼容、无感知&#34;的投毒设计让传统安全检测手段大面积失效；其三，从手动投毒到蠕虫自动传播、从单点攻击到生态级扩散的能力跃迁，展现了惊人的攻击策略迭代速度；其四，攻击框架的开源化发布，标志着一个新的威胁时代到来——高级供应链攻击能力已经完成从专属到普惠的蜕变。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">面对</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TeamPCP所揭示的行业痛点，安全界必须从三个维度展开系统性变革。在信任架构层面，必须全面转向零信任原则——不再默认信任任何组件、任何发布者、任何签名，对所有引入的第三方代码和工件执行哈希校验、数字签名验证和行为基线评估。在工具链安全层面，必须对CI/CD流水线和安全工具本身实施与生产环境同等严格的安全管控——禁止force-push覆盖已发布标签，实现版本不可变性，对安全工具的行为进行实时监控与异常审计。在平台责任层面，GitHub、npm、PyPI、Docker Hub等平台必须将供应链安全能力内置为基础功能——默认开启分支保护和标签保护，默认要求制品签名校验，默认拦截敏感环境变量批量读取和未知外部域名访问等恶意行为。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">正如</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Trend Micro在其分析报告中所指出的：&#34;TeamPCP并不依赖传统漏洞进行攻击。它滥用了开发者、CI/CD流水线和包注册表之间的信任关系——而这些关系正是现代软件供应链得以正常运行的基础。&#34;在信任被系统性地武器化之后，重建信任将是整个行业未来数年面临的核心命题。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">参考来源：</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">1. ISC SANS Diary: TeamPCP Supply Chain Campaign Activity Through 2026-05-24 (Kenneth Hartman, 2026-05-25)</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2. ISC SANS Diary: TeamPCP Supply Chain Campaign Activity Through 2026-05-17 (Kenneth Hartman, 2026-05-18)</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">3. Trend Micro: Analyzing TeamPCP Supply Chain Attacks - Checkmarx KICS and elementary-data (May 13, 2026)</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">4. Forcepoint: How TeamPCP Turned LiteLLM into a Credential Harvesting Tool (Prashant Kumar, 2026-05-18)</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">5. PolySwarm: Inside TeamPCP Supply Chain Offensive (The Hivemind)</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">6. Phoenix Security: Sha1-Hulud / Shai-Hulud Full Technical Dissection (2026-05-13)</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">7. Elastic Security: TeamPCP Container Attack Scenario (Ruben Groenewoud, 2026-03-20)</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">8. FreeBuf: TeamPCP组织部署针对伊朗的Kubernetes擦除器，破坏性CanisterWorm攻击升级 (2026-03-26)</span></span></font></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=d780abcc&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492944%26idx%3D1%26sn%3D8c6e632ee5384847be174290f4d81ae0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 12 Jun 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>疑似巴基斯坦关联的APT36组织针对Linux平台展开攻击活动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492942&amp;idx=1&amp;sn=88d028f565c8fd80b3f58090db47f48e</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-06-05 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一、背景概述</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2026年5月，安全研究人员披露了一起疑似</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">与</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">巴基斯坦关联</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT组织APT36（又名Transparent Tribe，中文通用名：透明部落）发起的高级持续性威胁攻击活动，该攻击行动被命名为“Vibeware”。该组织将印度军事基础设施作为核心攻击目标，围绕T-72、T-90主战坦克现代化升级这一高度敏感的军事采购议题，依托WhatsApp社交工程手段，结合武器化Linux桌面启动器文件，针对Linux平台发起了兼具多重隐蔽机制与先进反取证能力的网络间谍攻击活动。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT36是长期活跃于南亚地区的高危APT组织，具备明确的巴基斯坦国家背景，多年来持续针对</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">多国</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">政府、国防、外交、教育及科研机构开展定向网络间谍活动。本次</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">“Vibeware”攻击行动在目标选取、攻击手法、载荷架构、基础设施部署等维度，展现出高度成熟的技战术水平，也充分印证了该组织已从传统的Windows平台攻击，完成向Linux平台渗透作战的重要战术演进。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次攻击以印度装甲车辆采购项目为核心诱饵场景。攻击者伪造了一批依托</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">T-72/T-90主战坦克现代化升级项目背景的军事采购伪装文档，通过WhatsApp社交渠道进行扩散传播。此次攻击采用精准定向社交工程与广谱泛化传播相结合的混合投递模式，既试图突破印度传统国防体系内部网络，也意在扩大感染范围，渗透至军事供应链关联从业人员，实现间接链路突破。该攻击活动的诱饵主题设计、目标定位逻辑，与APT36</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">既往针对印度国防实体的攻击特征高度吻合，可中高置信度判定为该组织的持续性系列攻击行为。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二、攻击过程技术分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从攻击技术链来看，完整入侵流程可划分为初始投递、多阶段解码执行、持久化部署、指挥控制通信、数据窃取与远程执行五个核心阶段。各阶段之间环环相扣，攻击者综合运用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Linux桌面环境特性滥用、多层嵌套编解码混淆、无文件内存执行、应用层自定义加密等成熟攻击技术，构建了一条高度隐蔽且具备强抗打击能力的完整攻击链。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.1 初始投递：伪装PDF的武器化.desktop文件</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次攻击链的初始感染载体为一份精心构造的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Linux .desktop桌面启动器配置文件。.desktop是Linux桌面环境下定义应用程序快捷方式的标准文件格式，广泛应用于Ubuntu、Debian、Fedora等主流Linux发行版。攻击者利用该文件格式的合法属性与用户认知习惯，将恶意文件伪装成与印度装甲车辆采购相关的军事资料，同时配置PDF文档图标（Icon=application-pdf），让该文件在文件管理器中与普通PDF文档视觉效果完全一致，以此迷惑受害者。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">受害者双击该伪装</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">“文档”后，并不会打开PDF文件，而是直接触发.desktop文件中的Exec执行指令，启动文件内嵌套的恶意Shell脚本执行链路，完成初始恶意触发行为。该恶意.desktop文件具备典型的反逆向、反分析特征，规避检测与溯源的针对性极强。该文件整体体积异常臃肿，全文共计约18000行内容，远大于正常合规的Linux桌面配置文件的常规体量。文件中大量内容以#</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">字符</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">注释行填充，注释区域内嵌大量经过</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Base64编码且刻意破坏的PNG图像数据块。这批破损的图像数据无法正常解析渲染，攻击者借此实现两大目的：一是干扰安全人员的人工分析研判，二是大幅膨胀文件体积，规避各类自动化安全扫描工具的检测规则。而文件真正的恶意执行逻辑，仅隐藏在第9497行至9508行的非注释代码段落中。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击者通过双层</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Base64嵌套编码、Shell变量动态展开、内联命令求值等多重代码混淆手段，对后续阶段的恶意载荷进行加密处理，最终在内存中完成载荷重构与动态执行，整个攻击过程无任何中间文件落地，有效规避静态查杀与磁盘溯源检测。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.2 多阶段载荷部署与解码执行</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">第一阶段</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Shell载荷完成解码后，攻击者采用双载荷并行下载的架构实施后续攻击。第一载荷（payload-1）通过curl命令从C2服务器bossmaya.xyz拉取client.txt文件，对该文件依次执行ASCII85解码与bzip2解压操作后，获取用于下一阶段攻击的可执行恶意载荷。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">第二载荷（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">payload-2）为一款设计精巧的视觉伪装型文件载荷。该载荷运行后，会主动唤起Firefox浏览器，并跳转至印度政府新闻信息局的官方合法页面，展示一则印度国防部坦克采购相关的官方新闻稿。该新闻内容与攻击诱饵场景高度契合，能够有效降低受害者的警惕心理。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在受害者注意力被前台合法官方页面吸引、放松戒备的同时，第一载荷下载的恶意文件将在后台静默完成解码、解压与执行全流程，实现恶意载荷的落地与部署。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">这种</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">“前台展示合法内容+后台静默恶意执行”的视听分离式欺骗架构，是传统社会工程学与网络攻击技术深度融合的典型攻击范式。该攻击模式摒弃了传统攻击依赖受害者手动点击触发的单一方式，构建了完整的心理欺骗闭环</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">即</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">利用用户对政府官方页面的固有信任，形成认知误导，掩盖系统后台的异常行为，让恶意载荷的执行过程完全隐匿在用户的认知盲区中，大幅提升了攻击成功率与隐蔽性。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.3 核心植入体DeskRAT功能分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">第三阶段载荷</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">client.txt为Go语言编译生成的ELF格式可执行文件，安全研究人员将该恶意样本命名为DeskRAT。作为本次攻击链路中的核心远控木马落地载荷，DeskRAT集成持久化驻留、主机信息窃取、远程命令执行、文件上下行传输、心跳保活等完整远控功能组件，具备成熟的工程化开发特征。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">程序初始化阶段，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DeskRAT优先校验启动参数中是否存在--hidden标识位。该标识是攻击者实现流程分流的定制化分支控制逻辑</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">样本首次落地运行时无此入参，程序走入持久化安装逻辑</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">经持久化机制触发拉起的后续进程实例，会自动附带该参数并直接切换至隐蔽运行模式。该架构设计既可规避恶意程序反复自安装，降低磁盘落地写入行为留下的痕迹，还能保障恶意进程每次启动后的运行逻辑统一、行为可控。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.3.1 三重持久化机制</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DeskRAT部署了三套相互独立、互为冗余的持久化驻留方案，覆盖多维度开机自启场景，保障恶意程序长期驻留受害主机。具体实现方式如下：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">其</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">一，注册</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">XDG桌面自启项。该恶意程序通过创建~/.config/autostart/system-backup.desktop桌面配置文件，利用Linux桌面环境的固有特性——用户登录桌面时，自动加载执行autostart目录下的所有桌面启动条目，实现恶意程序随用户桌面登录自动启动，完成桌面环境维度的持久化驻留。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">其</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">二，注入</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Shell会话自启脚本。恶意程序在~/.config/system-backup/目录下生成startup.sh启动脚本，并将自身启动指令写入用户Shell配置文件（如~/.bashrc）。每当用户新建终端会话时，配置文件将自动加载执行恶意程序指令，实现终端会话维度的自动运行。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">其</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">三，添加系统级定时重启任务。恶意程序调用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">crontab -l读取用户已存在的定时任务，在原有任务基础上追加@reboot全局重启触发条目，配置启动指令/path/to/binary --hidden &gt;/dev/null 2&gt;&amp;1，让恶意程序在系统开机重启时自动后台运行，实现系统级开机自启。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">上述三套持久化机制分别作用于桌面环境启动、</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Shell终端会话启动、系统内核开机启动三个独立层级，相互兜底、互不干扰。即便其中某一套机制被安全策略清理、失效，剩余两套机制仍可正常生效，确保攻击者持续维持对受害主机的远程访问权限。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.3.2 抗打击C2通信架构</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DeskRAT的指挥与控制（C2）通信架构，充分体现出攻击者具备成熟的网络对抗思维与实战经验。该恶意程序核心C2依托Gorilla WebSocket库搭建ws://明文通道，通过WebSocket长连接实现与服务端的全双工通信。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该样本的高危特征在于，代码中硬编码了备用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">IP地址用于DNS解析异常、失效场景下的降级兜底通信。这一设计意味着，即便防御方针对</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C2域名</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">实施</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DNS阻断、域名劫持等常规处置手段，恶意程序可自动切换至直连IP的通信模式，保障C2通信链路不中断。因此，防御方需同时封禁对应域名与备用IP地址，才能彻底切断其指挥控制通道，足以说明攻击者针对域名接管、DNS拦截等安全应急响应手段做了完备的前置对抗规划。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">经溯源查询，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">IP地址反向解析域名指向shareef.com，该IP资源托管于英国伦敦的AlexHost S.r.l.（ASN：200019）。AlexHost是业内典型的防弹托管服务商（Bulletproof Hosting），此类服务的核心特征为拒不配合网络违规投诉、拒绝协助执法取证，规避监管属性极强。攻击者选用该基础设施，是基于长期网络对抗经验做出的针对性规避部署，具备极强的隐蔽对抗意图。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">此外，该恶意程序虽采用未加密的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">ws://协议开展通信，但并非攻击者的设计疏漏，而是刻意的反取证、反监测规避方案。攻击者在应用层自主实现ChaCha20流加密算法完成数据加密，规避了TLS证书指纹识别、证书透明度（Certificate Transparency，CT）日志审计等主流被动监测手段，大幅提升了恶意通信的隐蔽性，规避检测能力极强。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.3.3 远程载荷投放与异构脚本执行</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DeskRAT远控木马具备强悍的远程文件下发与落地执行能力，攻击者可在恶意代码驻留阶段动态投递各类辅助载荷。其handleUploadExecute函数支持对三类格式数据做解码处理：原始字节数组、Base64编码字符串、经JSON反序列化解析得到的float64类型切片，以此适配不同C2通信链路的编码规范。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">载荷文件落地后，恶意程序调用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">os.Stat接口获取文件基础属性信息</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">若需完整性核验，通常会配套哈希算法校验文件哈希值，随后异步调用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">executeFile函数启动文件执行流程。executeFile函数依据目标文件后缀匹配对应的解释器或启动程序：.py文件调用python3解析运行，.sh脚本依托bash执行，.desktop桌面配置文件通过gtk-launch程序唤起。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该样本会留存</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">.desktop文件的调用执行路径，该行为具备较高风险</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击者能够在已被控主机上，复用初次入侵时使用的武器化</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">.desktop文件作为二次攻击载荷，实现攻击链路的循环复用。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.3.4 系统信息采集与隐蔽外传</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DeskRAT在建立WebSocket连接后，会第一时间调用sendClientInfo函数，向C2服务器上报受害者主机的全量信息。数据采集范围包含IP地址、系统用户名、主机名、操作系统版本、当前工作目录，以及基于IP解析的地理位置信息。其中，该样本采用多源冗余查询+UDP降级探测的专属策略获取主机公网IP</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">程序会按优先级依次调用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">api.ipify.org、checkip.amazonaws.com、icanhazip.com三款公网IP查询接口，只要任意一个接口成功返回数据，即终止后续查询请求。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">若三条</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">HTTP查询通道全部失效（常见于受害者主机处于严格出站访问控制的受限网络环境），程序将自动降级为UDP拨号探测机制。该机制会向1.1.1.1:80、208.67.222.222:80两个地址发起UDP连接请求，依托操作系统底层自动匹配出口网卡、分配本地网络地址的运行机制，直接从套接字中读取主机本地IP地址，全程无需发送任何实际数据包。该探测方式可适配各类高受限网络环境，同时不会在出口防火墙留存明显的恶意连接日志，隐蔽性极强。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在数据外传能力层面，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DeskRAT通过sendFileInChunks函数实现文件分块传输功能，依托browseFiles函数实现远程目录遍历功能。样本所有外传数据均采用统一的JSON封装格式，字段包含消息类型标识、受害主机唯一UUID客户端ID、数据载荷及RFC3339标准格式时间戳。其中，客户端ID为首次感染时一次性生成的UUID，在主机全程感染周期内永久固定。即便受害者主机因网络切换导致IP地址变更，攻击者仍可通过固定UUID精准关联、追踪单台受害主机的所有行为数据。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">除此之外，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DeskRAT内置独立的心跳保活机制，默认心跳发送间隔为30秒。每次发起心跳请求前，程序会校验isExecuting、isCollecting两大状态标志位；若主机当前正在执行文件上传、数据采集等操作，则跳过当次心跳发送，避免心跳数据与业务指令传输产生冲突，体现了该恶意程序在工程实现上的精细化设计与规避对抗思维。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2.4 攻击基础设施特征分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从攻击基础设施维度分析，本次</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Vibeware</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">行动采用了典型的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT高阶对抗基础设施部署策略。本次</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">行动将载荷下载服务器域名与</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C2主控域名进行分离部署，即便安全研究人员封堵载荷下载通道，已成功落地并激活的DeskRAT远控程序，仍可通过独立的C2通信链路维持与攻击者的连接，保障恶意程序持续受控。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击行动</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">使用的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C2域名延续了APT36组织一贯的域名命名特征，偏好采用无明确语义、口语化且便于记忆的拼音类域名。同时，攻击者借助防弹托管服务商AlexHost，将核心基础设施部署于英国伦敦，利用各国司法管辖权的地域差异，大幅提升了安全溯源、应急处置的难度，拉长了安全响应的时间周期。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从开发溯源维度分析，研究人员在</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DeskRAT恶意二进制文件中，提取到残留的程序构建路径信息（D:/bossmaya/our/newlinuxblkul/client/main.go），据此可明确攻击者的开发环境特征。该路径中出现的“bossmaya”标识，与载荷下载域名bossmaya.xyz高度吻合，可判定为攻击者的内部项目代号或操作账号标识，为后续开展线索关联、溯源归因分析提供了核心锚点。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">此外，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Payload-1与Payload-2两份载荷的代码结构、注释风格均存在显著的AI辅助生成特征，这也是本次攻击行动被内部命名为“Vibeware”的核心原因，充分体现出该APT组织已常态化将AI辅助开发技术融入恶意软件研发流程的新型攻击趋势。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三、攻击技术亮点深度解析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">综合审视</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Vibeware</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">行动的全技术链路，本次攻击在以下五个维度展现出值得深度关注的技战术亮点。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">1</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">）</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">Linux平台攻击链的完整武器化</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">传统</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT攻击高度集中于Windows平台，而Vibeware完整利用了Linux桌面环境的.desktop文件格式、XDG自动启动规范、crontab定时任务、bashrc Shell配置等原生机制，无需引入任何第三方依赖即可完成从初始投递到持久化部署的全链条攻击。这标志着APT36</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">已完成向</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Linux平台的重要战术迁移，为后续同类攻击提供了可复用的技术模板。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">2</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">）反分析混淆与干扰的多层纵深设计</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从约</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">18,000行的巨型.desktop文件加载大量损坏PNG数据以干扰分析师，到嵌套Base64编码和ASCII85/Bzip2多层编解码混淆，再到应用层ChaCha20加密规避TLS指纹识别，攻击者在攻击链的每个环节都设置了反分析屏障。这种纵深干扰策略使得安全分析人员必须逐层剥离混淆才能触及核心恶意逻辑，显著延长了分析响应的时间窗口。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">3</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">）心理欺骗与攻击执行的视听分离设计</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">第二载荷通过打开真实印度政府网站展示与诱饵主题相符的官方页面，将受害者的视觉注意力引导至</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">“合法内容”，同时后台静默完成恶意载荷下载和执行。这种非传统的“前台掩护+后台执行”分离模式突破了传统的“隐藏自身”防御思维，转而采用了“主动提供可验证的合法内容来证明安全”的精妙心理学策略，大幅降低了受害者的异常感知概率。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">4</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">）抗打击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">C2架构的冗余设计</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">域名</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">/IP双通道降级回退、防弹托管基础设施选择、避开TLS证书指纹的应用层加密、以及三套独立持久化机制的冗余部署，共同构成了一个具有高韧性的抗打击体系。攻击者从实战角度出发，为域名接管、IP封禁、单点持久化清除等常规应急响应手段逐一准备了应对方案，显著提升了清除完整感染链的操作难度和协调成本。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">（</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">5</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">）</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">AI辅助恶意软件开发趋势的显现。</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">恶意</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">载荷代码中呈现出典型的人工智能辅助生成模式特征，包括过度注释、代码结构风格一致但略显刻板、变量命名缺乏人类直觉特征等。这一发现揭示了国家级</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT组织已开始将大语言模型等AI工具纳入恶意软件开发工作流的趋势，意味着恶意代码的生产效率、变种迭代速度和混淆规避能力可能在未来实现阶跃式提升，对传统基于签名和特征的检测体系构成长期挑战。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">四、事件影响与安全启示</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Vibeware攻击行动是APT36组织持续迭代升级自身网络间谍能力的最新佐证，也是近年来为数不多的、基于完整武器化Linux平台开展的APT攻击典型案例。本次攻击行动清晰暴露了当下网络安全领域的三大关键发展趋势：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">其</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">一，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT攻击载体正从Windows平台加速向Linux平台蔓延。随着关键基础设施、军政等高价值目标场景中，Linux系统部署占比持续提升，国家级APT组织均在快速搭建、完善Linux平台专属武器体系与攻击能力。但目前多数政企机构的安全防护体系仍以Windows防护为核心，Linux终端普遍存在EDR覆盖不足、威胁检测规则不完善、应急响应流程不成熟等突出防护短板，整体防御体系存在明显薄弱环节。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">其</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">二，社交工程攻击的场景适配性与迷惑性持续升级。攻击者依托真实军事采购文件，结合可公开核验的政府官方新闻页面，搭建了区别于传统钓鱼邮件的多模态信任链验证攻击模式，大幅提升了攻击可信度与欺骗性。传统安全意识培训中</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">“不点击可疑邮件链接”的基础防护准则，已无法有效抵御此类新型复合式钓鱼攻击。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">其</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">三，攻击者通过防弹基础设施与多层</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">C2冗余架构设计，让整体攻击链路具备极强的抗打击、抗溯源能力。这意味着防御方需构建跨境基础设施协同处置能力，配套落地多维度、立体化的阻断防御策略，而非单纯依赖域名劫持、IP封禁等单一被动防御手段。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Vibeware攻击行动的分析研究，为安全业界研判APT36组织最新技战术水平提供了重要参考。攻击者使用的多层代码混淆体系、Linux桌面环境武器化利用手段、视听分离式社会工程学欺骗手法，均具备极高的研究价值，值得网络安全从业者深入剖析，并针对性纳入防御体系建设、前置风险防控的核心考量范围。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">信息</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">参考链接：</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="微软雅黑"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://medium.com/@tarunrd77/pakistans-apt36-vibeware-targets-indian-military-infrastructure-75a853437c03" target="_blank">https://medium.com/@tarunrd77/pakistans-apt36-vibeware-targets-indian-military-infrastructure-75a853437c03</a></span></span></font></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=74ef35b3&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492942%26idx%3D1%26sn%3D88d028f565c8fd80b3f58090db47f48e">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 05 Jun 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>Kimsuky组织高级攻击技术分析报告——JSONPing、Webex 仿冒与新型HttpSpy变种</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492940&amp;idx=1&amp;sn=3b9748ce9b5684dcadc0c93a0fb12723</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-05-29 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一、事件概述</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2026年上半年，朝鲜背景APT组织Kimsuky针对韩国军方、企业及相关机构人员发起多轮定向网络攻击，相关活动由韩国ENKI WhiteHat威胁研究团队完整捕获并披露。Kimsuky自2013年被首次发现以来，长期以韩国军政、科研、关键信息基础设施为核心目标，具备成熟的社会工程学能力与定制化恶意软件开发能力。在本轮攻击活动中，该组织进一步升级攻击手段</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">将仿冒安全软件、窃取真实会议信息伪造</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Webex页面、JSONPing实时感染检测、模块化HttpSpy远控木马相结合，形成高度场景化、强隐蔽性、高成功率的完整攻击链路</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击行为呈现出精准侦察、流程标准化、技术持续迭代的典型</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT特征，对韩国境内政企机构终端安全与数据安全构成显著威胁。</span></span></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5866425992779783" data-s="300,640" data-type="png" data-w="554" type="block" data-imgfileid="100009291" src="https://wechat2rss.xlab.app/img-proxy/?k=50fb0ed8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FHBRznhxajkYTP4mW7iaPVl1Lgp99BT88QXTicT6KibjibT2UxUlcoH1Z5L22oib59InxIKRfUia6PEVnunZoACE54vJDSPf6CShL01boXGHcof1Es%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-align: center;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">图 </span></span><b><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">1 </span></span></b><b><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击示意图</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二、攻击过程与技术分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Kimsuky在本次攻击中采用双重社会工程学诱饵完成初始入侵，分别为仿冒企业级安全软件安装页面与伪造Webex在线会议页面。攻击者复制银行与正规安全厂商的页面布局与视觉样式，搭建虚假安装站点，提供伪装成个人防火墙、键盘安全软件的安装程序下载入口，诱导目标人员点击下载。与此同时，攻击者利用已攻陷主机窃取真实会议日程信息，制作与官方Webex高度一致的虚假入会页面，以摄像头故障需安装补丁脚本为由，诱导用户下载并执行恶意压缩包与脚本文件，执行后会自动跳转至真实会议页面，以此降低目标人员的安全警惕。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在载荷投递与执行阶段，攻击流程呈现多层嵌套、无窗口静默执行、实时感染校验的特点。虚假页面提供的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">astx‑setup.exe与nos‑setup.exe程序，表面为正常安全软件安装包，实际为dropper载体，运行后会在显示正常安装界面的同时，于后台解密释放恶意文件MemLoader.dll，并利用regsvr32.exe完成无窗口执行。该加载器会为受害主机生成唯一UID标识，注册以ChromeUpdate、EdgeUpdate为名的计划任务，实现持久化驻留。更为关键的是，攻击者引入JSONPing技术，由恶意代码在本地62001或16106端口启动临时HTTP服务</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">仿冒页面通过</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">JSONP跨域方式向本地服务发起请求，根据回调结果判断恶意程序是否成功执行，未成功则持续弹窗诱导安装，实现感染状态的实时监控与闭环控制。与此同时，载荷内置抗沙箱与抗调试机制，通过读取注册表信息识别VMware、VirtualBox虚拟机环境，枚举进程列表与窗口标题，一旦发现Wireshark、Process Monitor、x64dbg等分析工具便立即终止运行，规避动态检测与逆向分析。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在最终载荷落地环节，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Kimsuky放弃传统单文件远控结构，采用全新三阶段模块化HttpSpy变种，显著提升隐蔽性与抗检测能力。第一阶段为spyInster.dll，以engine.dat形态存在，负责完成安装配置、字符串解密、API地址解析，并将主模块写入指定路径，同时以备用数据流形式存储配置信息，添加注册表自启动项；第二阶段为spyLoader.dll，以cacheMon.dat形态存在，通过内存反射方式加载HttpSpy主模块，定位并调用该家族标志性的hello导出函数，启动主程序；第三阶段为httpSpy.dll主模块，具备完整远控能力，支持命令执行、文件上传下载、屏幕截图、远程进程注入、数据窃取等功能，与C2服务器采用HTTP POST协议通信，传输数据经RC4加密与Base64编码处理，通信参数与格式高度固定，可稳定接收指令并回传数据。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从攻击基础设施来看，本次活动与</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Kimsuky历史行为存在强关联，攻击者复用XAMPP默认HTTPS证书，C2与分发服务器集中于该组织长期使用的ASN 19318、26666网段，域名大量使用韩国免费域名服务，采用与官方域名高度相似的混淆字符，具备明显的家族标识与资源复用特征。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三、事件关联与影响判定</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">综合代码特征、加密密钥、基础设施与战术流程，可高置信度判定本次攻击归属</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Kimsuky组织。攻击样本中复用了该家族长期使用的RC4加密密钥，保留hello导出函数、XOR字符串混淆、API哈希解析等标志性代码特征，jse脚本加载器结构、文件释放路径、执行流程与2021年以来的攻击样本高度一致，基础设施的证书、网段、域名模式均与历史活动完全匹配。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次攻击将传统鱼叉钓鱼升级为场景化精准诱骗，结合真实信息仿冒与实时感染检测，大幅降低攻击暴露风险，提升入侵成功率。模块化分离的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">HttpSpy变种采用内存加载、合法进程伪装、数据流隐藏等手段，可有效绕过传统特征码查杀与终端检测工具，防御难度显著提升。攻击目标从传统军政核心人员扩展至普通企业员工、会议参与</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">者等泛化目标，攻击边界持续扩大，一旦攻陷终端，可实现内网横向渗透、敏感数据窃取、业务系统操控，对机构运营与信息安全构成持续性威胁。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">参考链接</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="Times New Roman"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://www.enki.co.kr/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant" target="_blank">https://www.enki.co.kr/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant</a></span></span></font></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f22330f7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492940%26idx%3D1%26sn%3D3b9748ce9b5684dcadc0c93a0fb12723">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 29 May 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>黑客组织UNG0002针对国内大学发起鱼叉式钓鱼攻击活动分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492937&amp;idx=1&amp;sn=466fc6b4ed08ed5d1ecfc80ea3b215f7</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-05-22 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一、背景概述</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">近日，网络安全厂商</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Seqrite Labs发布安全分析报告，披露黑客组织UNG0002发起的代号为“Operation Dragon Whistle”的定向网络攻击活动。该组织以国内高校为核心攻击目标，依托国内高校普遍落地执行的《国家学生体质健康标准》测试制度，结合高场景贴合度的社会工程学手段，开展高度定向的鱼叉式钓鱼攻击。攻击者通过滥用合规软件、多层隐蔽文件投递、内存驻留载荷加载等成熟攻击技术，最终植入Cobalt Strike远程控制木马并建立指挥控制通道，充分体现出该组织针对国内教育学术领域的精准侦察能力与完备的APT攻击技术体系。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次攻击活动的发起</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">方</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">为</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">UNG0002组织，其本次攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">活动</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">的战术、技术与流程（</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">TTPs）与此前曝光的“Operation Cobalt Whisper”高度吻合，可中高置信度判定为同一组织的持续性攻击行为。本次攻击核心瞄准国内</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">高校</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">领域，主要覆盖高校及下属体育院系、教务管理部门、涉学术类政府机构，同时将需参与体测的在校本科生纳入攻击范围。本次攻击</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">活动</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">以某高校</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2026年度学生体质健康测试为核心诱饵场景，由于体测成绩直接关联学生毕业资格，成绩不达标将按肄业相关规定处理，该强约束性校园制度为攻击者提供了高可信度的诱导条件，极大提升了受害者点击、执行恶意文件的概率。</span></span></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.0228310502283104" data-s="300,640" data-type="png" data-w="438" type="block" data-imgfileid="100009288" src="https://wechat2rss.xlab.app/img-proxy/?k=79e094e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FHBRznhxajkbpJX9Ip6HicEnz72QeqEVDxKrH6YMwqTSVSkjNZcJ4Aho0OsZ9dXloEKUUqSfSa9zicLYNyE7C3EAhgWUWZvF1rv7SBibiaeAOkF0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-align: center;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">图 </span></span></font><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">1 </span></span><font face="Arial"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">UNG0002</span></span></font><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击示意图</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二、攻击过程技术分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从攻击技术链路来看，完整入侵流程可划分为初始投递、多层执行、防御规避、载荷落地四个核心阶段。在初始访问环节，攻击者使用网易</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">163免费邮箱发送钓鱼邮件，以此规避企业级邮件安全设备对陌生外部域名的拦截筛查机制。钓鱼邮件伪装为</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">高校体育学院官方通知，附件为命名为</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">“**大学2026年《国家学生体质健康标准》测试通知最终版.zip”的压缩包文件。压缩包内诱饵内容包含真实教职工姓名、联系电话、官方公章及校内QQ工作群号，细节高度贴合高校行政办公场景与工作规范，且相关公开信息可通过官方渠道核验，极大消解了师生的安全警惕性。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在载荷执行阶段，攻击者采用多层隐蔽机制规避终端安全检测。压缩包内核心恶意载体为伪装成</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">PDF文档的双扩展名LNK快捷方式文件，并搭配四层模拟macOS元数据目录命名规则的嵌套文件夹，将恶意载荷深度隐藏，规避自动化安全扫描工具检测。受害者点击伪装后的LNK文件后，会调用系统合法进程explorer.exe执行深层目录下的chromedo.vbs脚本，以此规避终端检测与响应（EDR）工具对wscript.exe、cscript.exe等常规脚本进程的专项拦截。该VBS脚本仅1KB，内置双重执行逻辑：运行后会优先打开真实的体测通知PDF文档迷惑受害者，同时延迟800毫秒在后台静默调用正规压缩软件Bandizip.exe，全程无弹窗、无进程可视化闪现，有效规避用户主观警觉。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">防御规避环节中，攻击者整合运用多种高级反分析、反检测技术。其一，采用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DLL侧加载技术，将恶意ark.x64.dll文件与正版Bandizip.exe程序放置于同一隐藏目录，利用Windows系统DLL搜索优先级特性，通过合法可信进程加载恶意DLL文件，实现恶意代码的进程伪装与合法运行。其二，恶意DLL内置多重反调试、反沙箱机制，可调用GetTickCount、CheckRemoteDebuggerPresent等系统接口检测调试环境</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">同时枚举系统进程列表，排查</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Wireshark、Process Monitor等逆向分析、流量监控工具，一旦识别出仿真分析、人工调试环境，便主动终止运行，规避动态分析。其三，采用内存字符串动态混淆、实时解密技术，对进程名称、核心API接口等关键特征信息进行加密处理，防止静态分析工具直接提取恶意特征，进一步规避特征库比对检测。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">载荷落地阶段全程采用无磁盘驻留的内存加载技术，隐蔽性极强。恶意</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">DLL完成环境安全校验、确认无监控调试环境后，自动解密自解压（SFX）载荷并直接加载至系统内存，全程无任何恶意文件落地写入本地磁盘。载荷运行过程中，主动绕过Windows反恶意软件扫描接口（AMSI）、Windows事件追踪（ETW）等系统安全机制，阻断系统日志记录与实时安全扫描，规避杀毒软件、终端安全检测工具的监控审计。最终解密并加载Cobalt Strike Beacon远控木马，建立稳定的命令与控制（C2）通信通道，实现对受害主机的全程远程操控。由于所有恶意行为均在内存中完成，无落地痕迹，大幅提升了安全取证与溯源追责的难度。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从攻击基础设施特征分析，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">UNG0002组织呈现出基础设施高频轮换、本地化部署的典型特点。本次攻击持续沿用Bandizip作为合法工具滥用（LotL）的攻击载体，结合多渠道同类恶意样本关联分析，可溯源关联出20余个同源恶意文件。本次攻击所用指挥控制服务器部署于阿里云（AS37963），IP地址为60.205.**.**，关联域名lysan**.asia，该基础设施自2026年4月6日起持续处于活跃状态。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三、事件影响</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">安全研究人员指出，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">“Operation Dragon Whistle”是UNG0002组织首次将攻击边界明确拓展至国内普通高校师生群体</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次攻击核心特征可总结为：制度伪装权威性强、恶意执行链路隐蔽、防御规避技术成熟。该类攻击依托真实校园刚性制度构建高可信度诱饵，结合合法工具滥用、内存无文件攻击等前沿隐蔽技术，传统单一的特征码检测、邮件过滤机制无法实现有效防御。本次攻击活动也为国内高校网络安全防护敲响警钟，高校需常态化开展师生网络安全意识培训，重点强化校园行政通知、毕业资质审核、学业考核等高频场景的反诈防钓鱼教育，引导师生摒弃对官方制度、校园通知的固有信任心理，规避被定向钓鱼攻击裹挟的安全风险。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">参考链接：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://www.seqrite.com/blog/operation-dragon-whistle-ung002-targets-chinese-academia-via-weaponized-institutional-lure/" target="_blank">https://www.seqrite.com/blog/operation-dragon-whistle-ung002-targets-chinese-academia-via-weaponized-institutional-lure/</a></span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=10f4bf2e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492937%26idx%3D1%26sn%3D466fc6b4ed08ed5d1ecfc80ea3b215f7">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 22 May 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>疑似伊朗黑客组织Seedworm成功入侵韩国电子制造商，并展开全球攻击活动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492934&amp;idx=1&amp;sn=430fa6d1e9ca4fc1cb34e7041b457418</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-05-15 09:01</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一、背景概述</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">近期网络安全监测数据显示，伊朗关联</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT组织Seedworm（别名MuddyWater、Temp Zagros、Static Kitten），在2026年第一季度发起大规模跨国</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">网络攻击活动</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，成功渗透</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">入侵了</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">全球</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">9个国家、横跨四大洲的多家关键机构，其中就包括韩国一家大型电子制造企业。该行动具备持续时间长、隐蔽性强的特点，攻击者在韩国目标网络内潜伏近一周，重点窃取敏感商业数据与核心技术情报，充分暴露了国家背景APT组织对全球供应链安全的持续威胁，也凸显了当前跨国网络间谍活动的高发态势。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">公开情报显示，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Seedworm组织与伊朗情报与安全部（MOIS）存在明确关联，其目标选择具有极强的情报导向性，精准锁定高价值领域。本次行动覆盖范围广泛，涉及工业制造、电子研发、教育科研、公共服务、金融服务及专业服务等多个关键领域，受害者均具备明确的战略价值——要么掌握高科技制造领域的核心知识产权，要么持有对伊朗具有战略意义的政府敏感情报，要么可作为跳板提供下游核心客户的网络访问权限。结合当前地缘政治格局，尤其是伊朗核计划相关争议持续升温、地区冲突不断发酵的背景，此类密集的间谍活动，清晰反映出该组织急于获取关键信息、支撑其战略需求的迫切性。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二、攻击过程技术分析</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从网络攻防技术维度拆解，本次行动集中体现了</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Seedworm组织在战术层面的显著进化，其攻击手段更具隐蔽性和抗检测能力，核心依赖DLL侧加载技术实现入侵突破。攻击者巧妙利用合法签名的第三方可执行文件，作为恶意DLL的加载载体，成功绕过终端签名验证与路径检测机制，降低被发现的概率。本次行动中，攻击者重点使用两组侧加载组合：一是Fortemedia公司音频驱动工具fmapp.exe与恶意fmapp.dll的配对，二是SentinelOne安全产品组件sentinelmemoryscanner.exe与恶意sentinelagentcore.dll的组合。值得关注的是，滥用安全厂商自身的签名二进制文件，不仅能规避常规安全检测，还能干扰安全分析师的研判方向，增加溯源与处置难度。此外，两款恶意DLL均嵌入公开窃密工具ChromElevator，专门用于窃取Chromium内核浏览器中的密码、Cookie及支付卡等敏感信息，实现精准窃密。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次入侵行动的核心链条发生明显转变，打破了</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Seedworm组织以往单纯依赖PowerShell的操作习惯，以Node.js运行时（node.exe）为核心驱动整个攻击流程。攻击者通过Node.js脚本调用PowerShell执行各类恶意操作，实现攻击行为的分层隐藏与灵活调度。目前，该行动的初始访问向量尚未完全明确，但从韩国电子制造企业的受害案例来看，2月20日监测到最早的PowerShell侦察活动，且该活动由Node.js进程作为祖先进程发起，表明攻击者已成功将植入物潜伏至目标主机。侦察阶段，攻击者快速执行whoami、ipconfig、net group等一系列信息收集命令，全面摸清目标主机的系统配置、网络拓扑及域环境详情；随后通过WMI技术枚举终端防病毒产品配置，精准评估目标防御体系的薄弱环节，为后续攻击行动奠定基础。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在完成环境侦察与防御评估后，攻击者迅速推进后续攻击步骤，构建完整的攻击链路。首先通过</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">curl.exe工具下载额外恶意载荷，规避PowerShell日志记录，降低操作痕迹被发现的风险；随后部署前述DLL侧加载组合，同时通过修改注册表Run键值，实现恶意程序的开机自启动，建立稳定的持久化机制，确保长期潜伏。在权限提升与凭证窃取环节，攻击者采用多工具并行、多手段冗余的策略，全面窃取目标系统凭证：包括导出SAM、SYSTEM、SECURITY注册表配置单元，提取系统账户信息；运行恶意工具调用Windows凭证提示框，诱骗用户输入凭证；部署提权组件，利用GSS-API委托滥用技术提取Kerberos TGT票据，实现权限提升与横向移动准备。这种多维度、冗余式的窃密设计，体现了攻击者极强的反防御意识和成熟的战术思路。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">数据外传环节，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Seedworm组织延续并升级了“隐蔽融合”的战术思路，未构建专用恶意传输通道，而是将窃取的敏感文件通过公共文件传输服务sendit.sh进行上传。这种将恶意数据传输混入普通用户日常网络行为的方式，能够有效规避网络层的流量监测，大幅增加安全团队的检测难度。此外，攻击过程中还监测到定时信标通信、屏幕截图收集、SOCKS5反向代理等行为，整体攻击节奏呈现“植入物自动化执行+人工间歇干预”的混合模式，既提升了攻击效率，又减少了人工操作留下的痕迹，进一步增强了攻击的隐蔽性。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">综合来看，本次行动中</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Seedworm组织的战术成熟度实现显著提升，核心体现在三个方面：一是脚本运行时的创新使用，引入Node.js、Deno等工具，打破传统攻击模式；二是合法签名二进制文件的滥用，强化抗检测能力；三是公共云服务的恶意复用，实现隐蔽数据外传。这些变化表明，该组织正在持续强化操作卫生与反侦察能力，逐步向更高级、更隐蔽的APT攻击模式演进。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三、事件影响及总结</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">针对本次行动折射出的威胁，网络防御方需深刻认识到，传统签名检测、单一通道监控等被动防御手段，已难以有效应对此类高级</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT威胁。结合攻防对抗实际，防御方应从多维度构建立体防御体系：一是强化端点行为分析，重点监控异常进程关系（如Node.js驱动PowerShell的异常调用），及时发现隐蔽植入物；二是加强凭证使用审计，重点监测SAM注册表导出、Kerberos票据异常提取等高危行为；三是重点关注公共文件传输服务、云服务的流量异常，防范恶意数据外传；四是持续更新威胁情报，精准对接Seedworm组织的战术、技术和程序（TTPs），实现精准预警与快速处置。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">当前，网络攻防对抗日趋复杂，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT组织的跨国攻击已成为威胁全球网络安全的主要风险之一。此类事件不仅考验组织的技术防御能力，更对情报预警、应急响应速度提出了更高要求。尤其对于高科技制造企业、关键基础设施运营者而言，应将APT威胁纳入常态化风险评估框架，完善安全管理制度，强化技术防御体系，提升安全团队的应急处置能力，构建更具韧性的网络安全防护体系，有效抵御国家背景APT组织的跨国攻击威胁。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">参考链接：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://www.security.com/blog-post/iran-seedworm-electronics" target="_blank">https://www.security.com/blog-post/iran-seedworm-electronics</a></span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=14fac097&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492934%26idx%3D1%26sn%3D430fa6d1e9ca4fc1cb34e7041b457418">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 15 May 2026 09:01:00 +0800</pubDate>
    </item>
    <item>
      <title>警惕！AI黑客攻击将会大规模爆发，传统防御体系面临失效风险</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492932&amp;idx=1&amp;sn=6eb14e9dce43eaeb02876d52e2140e64</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-05-12 17:57</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5379061371841155" data-s="300,640" data-type="png" data-w="554" type="block" data-imgfileid="100009281" src="https://wechat2rss.xlab.app/img-proxy/?k=c283d4cd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FHBRznhxajkafCgJwhAq1EWpWiasMtXic93DrSvkDPJe7eJdB2JU45MpaCCuKyoqXGCwpqfPRkhJ32OevTmABFhUB8pDt94JzM4Kxj3iaqlKPMs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;" data-pm-slice="0 0 []"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">近年来，生成式人工智能、大模型、</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI智能体等技术快速普及，在推动产业数字化升级的同时，也被恶意组织用于网络攻击，大幅降低攻击门槛、提升攻击效率、扩大攻击范围。谷歌网络安全团队近期发布的分析报告明确警示：AI正在全面武装网络攻击，一场规模化、自动化、智能化的黑客攻击浪潮已近在眼前，全球政企机构、云平台、AI服务与关键信息基础设施将面临前所未有的安全冲击。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">全球首例</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">AI主导的0Day漏洞攻击已被确认</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">谷歌网络安全团队披露了一项令人警醒的调查结果</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">——全球首例借助人工智能开发、并计划进行大规模部署的0Day漏洞攻击事件已被正式确认。这一发现证实，AI已开始直接参与并主导从漏洞挖掘分析到恶意代码生成的关键步骤。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">此前，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">WormGPT等黑客服务平台已经降低了利用AI实施恶意活动的门槛；而此次曝光的真实案例则表明，AI正从辅助工具演变为具备自主攻击能力的&#34;数字黑客&#34;。研究人员在对恶意代码进行逆向分析时发现，黑客所用的Python攻击脚本中包含详尽的教学式文档字符串，甚至有AI模型凭空捏造的CVSS评分——这些特征几乎是大语言模型训练数据的专属标记。谷歌研究人员经溯源分析后排除了自家Gemini模型被利用的可能，但确认攻击代码的生成与大语言模型存在极高关联。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">黑客已形成成熟的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">AI漏洞挖掘战术</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在技术路径上，黑客组织已发展出一套相当成熟且隐蔽的战术体系。其中最危险的手段之一是</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">&#34;角色扮演越狱&#34;（Persona-driven Jailbreaking）——攻击者通过提示词工程诱导AI模型扮演高级网络安全专家，指令其对特定固件实施深度挖掘。GTIG监测到，一个黑客组织在对话中欺骗大语言模型，将其设定为嵌入式设备渗透测试审计师，从而诱导AI输出大量TP-Link路由器等设备的潜在攻击面信息，成功绕开了AI模型对直接制作病毒或攻击代码的常规限制。与此同时，另一个著名黑客组织则被观察到利用AI进行自动化筛选，通过发送数千条重复探查指令，快速过滤出具备实际渗透价值的漏洞。这些行为说明，AI漏洞研究绝非科幻设想，而是已在暗网情报站与国家背景黑客团队中成为常态。</span></span></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6889692585895117" data-s="300,640" data-type="png" data-w="553" type="block" data-imgfileid="100009283" src="https://wechat2rss.xlab.app/img-proxy/?k=1368d991&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FHBRznhxajkaJqa5p4VIibeiaiaOichSHMDLGZe7yWzwFmQ11tMmYvxTbuQF1NqCbXOsPVib5TYDwa2uwSia2O6tyojAea2PKhyxgewscic9gibiaJf54%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">AI驱动的攻击已形成标准化四步流程</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">当前，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI驱动的黑客攻击已形成完整且高效的标准化流程：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">第一步，全域自动化侦察</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI批量扫描公网资产、代码仓库、配置文件，快速定位暴露的API密钥、弱口令、未授权访问接口与已知漏洞，精准绘制目标网络拓扑与AI服务部署情况。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">第二步，多态恶意载荷生成</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">利用大模型自动生成多态恶意代码、定制化漏洞利用工具与高仿真钓鱼内容，绕过传统特征库、沙箱检测与终端防护软件，大幅提升攻击隐蔽性。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">第三步，精准突破</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">AI系统弱点</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">通过提示注入、记忆污染、工具调用劫持、容器逃逸、权限提升等手段，攻陷</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI智能体、推理节点与云原生环境，获取系统权限与敏感数据。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">第四步，横向渗透与持久化驻留</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">利用窃取的服务代理凭证、账号密钥访问云存储、大数据平台、内部业务系统，实现批量数据窃取、挖矿勒索、业务破坏等恶意目的，部分攻击可实现从接入到窃取核心资产的全流程无人干预自主执行。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研究人员已监测到，有攻击组织利用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI开发0Day漏洞并计划发起大规模利用行动，多国网络威胁主体正密集运用AI开展漏洞挖掘与攻击准备。AI正从辅助工具升级为攻击核心引擎，推动网络攻击向自主化、协同化、规模化方向加速演进。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三大颠覆性特征重塑攻防格局</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">此次</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI驱动的攻击浪潮呈现出三大颠覆性特征：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一是攻击门槛显著降低</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">即便缺乏深厚攻防技术的攻击者，也能借助</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI工具快速发起高精度、高强度攻击，网络威胁主体数量呈指数级增长。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二是攻防时间窗口彻底坍塌</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">漏洞从暴露到被批量利用的间隔大幅缩短，传统</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">&#34;发现—评估—补丁—防护&#34;的被动防御模式完全失效。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三是攻击面全面扩张</span></span></font></b><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">：</span></span></font></b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击目标不再局限于传统信息系统，而是转向</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI模型、API生态、智能代理、云服务账号等新型资产，安全风险快速向数字化业务全场景传导。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从已发生的案例来看，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI已被用于批量入侵防火墙设备、劫持海量AI智能体、自主挖掘操作系统内核漏洞并完成武器化开发，相关事件造成大规模数据泄露、业务中断与经济损失，充分证明AI黑客攻击已从技术趋势变为现实威胁。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">具备自主决策能力的恶意软件已经出现</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">更为棘手的是，人工智能正催生具有高度自主决策能力的恶意软件变体。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">GTIG发布的安卓木马&#34;PromptSpy&#34;便是典型代表——这款具备&#34;AI智能体&#34;属性的高阶恶意程序，能主动调用受感染手机的无障碍服务分析当前屏幕内容，私自捕获用户的生物识别手势，甚至能精准识别并屏蔽系统弹出的卸载按钮，使用户陷入无法移除的困境。与此同时，各类勒索病毒团伙也在利用AI赋能进行疯狂扩散，甚至在深度伪造等舆论操控中混淆视听。根据微软威胁情报部门披露的报告，AI已被系统化地运用在侦察、钓鱼、恶意软件开发及基础设施搭建等全部攻击链条上，各类大模型正成为助推勒索病毒与网络诈骗爆炸式增长的最强催化剂。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">传统防御已失效，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">AI原生安全体系势在必行</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">面对即将全面爆发的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI攻击浪潮，政企机构必须摒弃传统防御思路，快速构建AI原生安全防护体系。具体而言：全面梳理AI服务、云资源、API接口与智能代理资产，开展专项漏洞排查与密钥治理，严格落实最小权限原则；强化身份认证与访问控制，全面启用多因素认证，定期轮换凭证，封堵未授权访问入口；部署AI驱动的威胁检测与响应能力，实现对异常扫描、恶意代码、提示注入、横向渗透等行为的实时监测；建立漏洞应急响应与快速修复机制，缩短威胁处置周期，防范规模化攻击得逞。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">专家警告：这场战争已经打响</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">网络安全专家指出，一场由人工智能引发的数字攻防战争已在现实世界中悄然打响，并且注定持续升级。许多人误以为</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI驱动的黑客攻击仍处于萌芽阶段，但实际上，攻击方已实现工业化和智能化的升级，防御方必须同步进化。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">专家强调，这并非针对某一国家或企业的局部威胁，而是对全球数字体系与金融稳定的系统性挑战。由于</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI大幅放大了攻击强度，使得攻击演进速度远超传统防御的响应能力，极端网络安全事件极易迅速外溢，引发资本市场偿付危机乃至广泛的金融动荡。在此背景下，传统“亡羊补牢”式的被动防御已彻底失效。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">为打破当前的技术僵局，专家提出当务之急是全面引入对抗性威胁情报探查，利用</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI驱动的高阶检测模型来对抗恶意AI，并在软件交付生命周期中强制内嵌安全护栏。各行各业必须立即审视自身的安全防御基线，提升身份安全管控能力，同时对关键基础设施实施严密的可观测性与动态行为监控。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">AI赋能网络攻防的格局已不可逆转。全球组织应加快补齐AI生态安全短板，以主动防御、动态对抗、AI赋能安全的全新思路，筑牢数字时代的网络安全防线。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">参考链接：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access" target="_blank">https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access</a></span></span></font></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=28d5deac&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492932%26idx%3D1%26sn%3D6eb14e9dce43eaeb02876d52e2140e64">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 12 May 2026 17:57:00 +0800</pubDate>
    </item>
    <item>
      <title>APT32组织利用软件供应链攻击，投递新型木马ZiChatBot</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492928&amp;idx=1&amp;sn=3158abff335ff1188e9a6e3f51fbb71d</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-05-09 09:00</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4894433781190019" data-s="300,640" data-type="png" data-w="521" type="block" data-imgfileid="100009279" src="https://wechat2rss.xlab.app/img-proxy/?k=f4de8081&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FHBRznhxajkZkvN4ichBDV6S3icpxTnCGC0yq196j4ibycsicJuSSow3vvC7QuXPFhtufzvoTqBibwiay78uRprjE96nev84ibPEGojwq58M46AvWSg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一、事件背景概述</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">近期，网络安全研究人员监测发现，从</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2025年7月开始，Python官方软件包仓库PyPI平台陆续被上架了多款恶意wheel安装包。这类恶意程序包表面能够正常实现项目页面标注的对应功能，背地里却会暗中植入恶意文件，最终落地一款从未公开曝光的全新木马家族，研究人员将其命名为ZiChatBot。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">该木马具备跨平台攻击特性，可在</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Windows系统中释放DLL程序文件，在Linux系统中投放SO共享库文件。相较于传统木马，ZiChatBot不再依托专属C2服务器进行指令通信，而是直接利用开源聊天工具Zulip的REST</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">API</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">接口作为被控通信基础设施，隐蔽性大幅提升。攻击者还采用伪装依赖的方式规避检测，刻意搭建一款看似正常无害的软件包，把含毒恶意包设置为其依赖组件，进一步隐匿攻击链路。经研判，这是一次策划周密、流程完整的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">PyPI开源软件供应链攻击活动。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击者共计在</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">PyPI平台注册三个项目并上传恶意wheel包，均仿冒市面主流正规第三方库，以此诱导开发者误下载安装。三款恶意包分别为：伪装成UUID随机字符串生成工具的uuid32-utils、实现跨平台终端彩色文字输出的colorinal，以及提供终端ANSI色彩格式渲染的termncolor。三款恶意包集中在2025年7月16日至22日一周内批量上架。其中uuid32-utils与colorinal的植入链路、恶意载荷高度相近；termncolor自身代码无明显恶意行为，却通过引入colorinal作为依赖实现恶意加载，进一步拉长攻击隐匿链条。在被平台下架处置前，三款恶意包的累计下载量分别达到1479次、614次与387次。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二、事件分析过程</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">研究人员选取</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">colorinal恶意库作为典型样本，对本次攻击的感染机制开展了深度技术拆解。在Windows环境下，只要安装uuid32-utils或colorinal任一恶意包，内置恶意代码就会释放名为terminate.dll的加载器并写入本地磁盘。当项目引入该库时，DLL文件会自动加载运行，充当ZiChatBot木马的下发载体执行后续恶意行为；同时在系统注册表写入自启动配置，运行完成后还会自动清除自身痕迹。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Linux环境中，程序会释放terminate.so共享对象文件，将木马程序植入/tmp/obsHub/obs-check-update目录，并通过配置定时任务crontab实现持久化驻留。无论部署在哪种操作系统，ZiChatBot均可解析从命令控制端下发的Shellcode并执行系统指令</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">每完成一次命令执行，木马都会回传爱心表情符号，以此向控制端反馈任务执行状态。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次攻击最具代表性的技术特点，是恶意程序对</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Zulip协作工具的非常规滥用。Zulip是主流开源聊天协作平台，对外开放标准REST API接口。ZiChatBot摒弃了APT攻击惯用的自建域名、私有信道等传统C2架构，直接挪用Zulip公开API搭建命令控制通道。木马通过调用Zulip接口拉取攻击者下发的指令与Shellcode，执行后以特定表情回执完成交互确认。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击者</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">依托</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Zulip正规业务属性与企业广泛部署的现状，木马产生的网络流量和正常办公业务流量高度混淆，传统网络监测设备很难识别并拦截恶意通信。由此可见，攻击者深谙企业现有网络防御体系规则，具备极强的免杀对抗与隐蔽攻击技术功底。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">除流量高度隐蔽外，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">ZiChatBot还具备完整跨平台攻击能力。经核查，这批上传至PyPI的恶意包，编译适配Windows X86、X64架构以及Linux x86_64架构，可同时针对Windows、Linux两大主流操作系统发起入侵。跨平台的架构适配设计，也大幅拓宽了本次供应链攻击的受害覆盖面。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三、攻击活动归因分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在溯源归因层面，研究人员</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">通过深度分析发现</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">本次攻击所用的程序释放器，与</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT32（OceanLotus）组织过往使用的同类组件相似度达64%，据此研判这批PyPI恶意软件包和该组织过往披露的恶意程序存在关联。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT32组织也被</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">称为</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">海莲花、</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">OceanLotus</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">、</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">SeaLotus、APT-C-00</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">等名称</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">，普遍认为其关联越南相关</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">部门</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">。该组织的网络活动最早可追溯至</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2012年，自2015年被公开曝光后始终保持活跃，长期以政府机关、科研机构、海事航运、金融投资等关键领域为高价值目标，持续开展网络间谍渗透活动。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">这并非</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT32组织首次利用开发者工具链和开源公共平台实施供应链攻击。研究人员梳理发现，2024年末，该组织就曾伪造Visual Studio Code插件，伪装成Cobalt Strike相关扩展进行投毒，针对国内网络安全社群发起定向攻击。受害者编译项目时，恶意代码便会自动触发并下放木马程序，当时恶意程序选用Notion笔记服务作为命令控制通道，和本次借用Zulip接口搭建C2信道的技术思路如出一辙。这也能看出，APT32</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在保留传统鱼叉钓鱼邮件这类初始入侵手段的同时，正持续拓展供应链攻击等新型入侵路径。本次针对</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">PyPI软件包仓库的攻击，标志着该组织战术策略的进一步升级：将攻击链路前置至软件开发源头，通过污染开发者日常依赖的开源软件仓库，实现单点投毒、批量侵染下游使用者的效果，核心目的在于大幅拓宽攻击范围，同时提升整体渗透攻击的效率。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">四、事件影响与启示</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">此次安全事件对软件供应链安全形成了直接且严峻的现实威胁。</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">PyPI作为全球Python开发者最核心的第三方软件包仓库，每日承载海量开发者与企业用户的使用需求。攻击者仿冒主流常用类库名称，并借助软件包依赖嵌套机制隐藏恶意代码，导致安全防范意识薄弱的开发者在安装看似正规的程序包时，无意间成为整个攻击链路的突破口。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">一旦开发环境遭到入侵，</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">ZiChatBot便可通过Zulip</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">聊天工具</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">通信通道接收攻击者下发的任意指令，进而引发内网横向渗透、源码数据窃取、业务系统账号凭证泄露等一系列高危安全后果。加之该木马可适配</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Linux服务器环境，对企业后端业务系统及云基础设施构成的安全威胁进一步放大。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">从溯源研判与安全检测的视角来看，本次攻击折射出国家级</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT组织战术发展的新趋势：以往依赖自建命令控制服务器、定制化后门程序的传统攻击模式，正逐步转向依托合法第三方公共服务搭建隐蔽C2信道的新型打法。Zulip、Notion这类普及度极高的企业协作平台，现已成为攻击者青睐的命令控制载体，也让传统依靠IP黑名单、域名信誉库、固定流量特征的检测防护手段基本失效。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">对防守方来说，仅靠单一特征，比如识别</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">Zulip接口流量、排查PyPI包内可疑文件，已经很难精准判定APT攻击行为。这就要求企业安全团队构建复合型行为分析能力，把开发环境软件包审计、终端异常进程监控、与公共服务平台的异常通信行为研判等维度，统一纳入常态化威胁狩猎体系中。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">参考链接：</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://securelist.com/oceanlotus-suspected-pypi-zichatbot-campaign/119603/" target="_blank">https://securelist.com/oceanlotus-suspected-pypi-zichatbot-campaign/119603/</a></span></span></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=d58fc3d3&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492928%26idx%3D1%26sn%3D3158abff335ff1188e9a6e3f51fbb71d">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 09 May 2026 09:00:00 +0800</pubDate>
    </item>
    <item>
      <title>伊朗APT组织MuddyWater升级其攻击战术策略，利用第三方MaaS平台展开攻击活动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492925&amp;idx=1&amp;sn=5e0b1bbfde6029935517adbe30201918</link>
      <description></description>
      <content:encoded><![CDATA[<p>原创 <span>BaizeSec</span> <span>2026-04-30 14:32</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1a1429f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FNpPydsaAMINeYG0xg4btBInpvgswiaLDvMezqC0jzMYgNaiagu4ktmbPMeMNPegmKe7JaecHMuibo8tvBd5w2ZUOw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">一、事件背景概述</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">近日，网络安全研究人员首次通过基础设施与载荷双重证据，证实伊朗国家背景</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">APT组织MuddyWater（又称 Seedworm、Mango Sandstorm、TA450、Static Kitten），正作为客户角色，使用俄语系网络犯罪团伙组织TAG-150运营的CastleRAT恶意软件即服务（MaaS）平台，持续针对多个目标实施高强度网络间谍行动，且相关攻击活动在一些网络安全厂商曝光后仍保持活跃。该攻击活动中还部署了一款此前未被披露的、基于区块链进行指挥控制的新型木马ChainShell，标志着该组织与商业化地下犯罪工具的结合已经进入实战化阶段。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">事件背景源于</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">MuddyWater组织不断演进的战术需求。该组织自2017年以来长期活跃，直属于伊朗情报与安全部，惯用定制PowerShell后门和合法的远程管理工具。然而，本次攻击事件表明其正在转向采购成熟的商业木马MaaS平台，以快速获取高级入侵能力。研究人员调查的直接起因是他们发现了一台MuddyWater组织的C2服务器，上面不仅含有波斯语代码注释和精心整理的以色列IP地址段列表，还存在一个名为reset.ps1的PowerShell部署脚本，该脚本用于解密并释放ChainShell组件。同时，攻击者还将名为“Build 120”和“Build 13”的两个PE载荷通过隐写术隐藏在处理过的JPEG图片内。这两个载荷携带相同的MaaS模板标识，并且都是在美以2月28日对伊打击前编译完成的，这点呈现出明显的预先部署特征，属于提前预置的攻击能力。</span></span></font></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100009275" data-ratio="0.6292947558770343" data-s="300,640" type="block" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=cb93cef6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FHBRznhxajkanEXont9JCk1bU82mPMKGkSiadpRdODFaGK8QjmSzsc3XEA4JEuEOpPWpLjicIfMnlF0WYl9s0aibaloNoXZibjvZ4mXiagbUhiaA44%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-align: center;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">图 </span></span></font><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">1 </span></span><font face="Arial"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">MuddyWater</span></span></font><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织攻击示意图</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">二、攻击活动归因分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">在攻击活动归因和证据链分析方面，研究人员构建了一条</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">“证书-活动标识-木马任务”的闭环证据链。攻击者在投递环节中使用了两张由SSL.com签发、注册名为“Amy Cherne”和“Donald Gay”的代码签名证书。其中“Amy Cherne”证书不仅签发了已知被Google、微软等厂商明确归属MuddyWater</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">组织</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">StageComp木马，还签署了一个被赛门铁克命名为DinDoor的MSI安装包。对该MSI的行为分析显示，其会向多租户C2平台serialmonet.com发起携带JWT身份令牌的请求，内含活动名“Smokest”及用户ID。而这一完全相同的活动身份，被硬编码在CastleRAT Build 120和Build 666的持久化计划任务名称VirtualSmokestGuy中。另一条平行证据链来自那台暴露的伊朗服务器，其操作历史记录显示曾用命令行自测Build 13的C2端口8888，该服务器上留存的reset.ps1脚本哈希与公开恶意软件库中的样本完全一致，从而将伊朗操作者、TAG-150平台组件和CastleRAT C2直接绑定。此外，该C2域名serialmonet.com为一个多租户平台，LeakNet勒索软件等其他团伙也在使用相同的Deno代码库，但通过不同的JWT凭证区分用户，表明MuddyWater组织是平台客户而非开发者。代码中功能路径存在的俄语字符串与针对前苏联独联体国家的区域排除逻辑，也印证了其俄罗斯背景。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">三、攻击过程技术分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">技术分析显示，此次攻击带来了显著的能力跃升。其中最引人注目的是一款名为</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">ChainShell的Node.js木马，它抛弃了传统的HTTP直连，转而通过以太坊智能合约去中心化地解析C2服务器地址，通信全程采用AES-256-CBC加密。该木马本身是一个“thin shell”执行器，通过服务端推送JavaScript代码“new Function”执行命令，内置的俄罗斯开发者痕迹和独联体国家规避逻辑进一步指向TAG-150来源。与ChainShell配合的CastleRAT平台则提供了当前地下主流的HVNC功能，可在受害者正常操作时，通过隐藏桌面静默访问内部系统、云控制台和Web邮箱，复用受害者的会话Cookie以绕过MFA认证。平台还集成了针对Chrome v127以上版本应用绑定加密的Cookie窃取模块，这些都是MuddyWater原有自研工具完全不具备的能力。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">尽管多家厂商从</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">3月起陆续曝光相关基础设施和证书，攻击者的运营活动并未停止且保持了极限的响应速度。3月11日和13日，攻击者编译了新的NSIS安装器；3月16日，更新了JavaScript远控样本；甚至在3月20日，仍有新的恶意宏文档诱饵连接至MuddyWater组织的基础设施。攻击链在规避手段上也做到了多维度覆盖，包括滥用CMSTPLUA实现UAC绕过、利用合法应用进行DLL侧加载、通过WMI添加Windows Defender扫描排除项，以及沿用隐写术藏匿载荷。</span></span></font></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3562386980108499" data-s="300,640" data-type="png" data-w="553" type="block" data-imgfileid="100009276" src="https://wechat2rss.xlab.app/img-proxy/?k=3ead84f3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FHBRznhxajkYzlsPqupUwo6yFmgefS0BfX5RO04sbxibJ7Lklkocxjd4Ntz8R2xMWYzMhwvkdNGwfDF0j6oX20b6aDYAHnxcIy4XhskUy7Fbs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.6em;text-align: center;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">图 </span></span></font><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">2 </span></span><font face="黑体"><span leaf="" style="font-weight: bold;line-height: 1.6em;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">攻击活动时间节点</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;" data-pm-slice="0 0 []"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">四、事件影响分析</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">对于防守方而言，这一威胁融合带来了严峻的归因与检测挑战。当网络中出现携带俄语字符串、基于主流犯罪平台构建的</span></span></font><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;">CastleRAT或ChainShell报警时，初始分析极易将其归为一般的俄罗斯网络犯罪活动，而忽略其背后伊朗国家级间谍的真实意图。报告警示，严格将“网络犯罪”与“APT”分立处置的威胁情报工作流，很可能错漏此类混合型行动。防御侧需重点关注行为链条，包括从Outlook Web访问异常、CMSTP父进程调用，到与区块链节点非业务通信等异常的组合出现，主动梳理JWT凭证关联，并结合证书透明度日志监控，以期在攻击者实现横向移动前阻断入侵链条。此次事件不仅凸显了伊朗在网络行动中追求作战敏捷而非武器自研的战略转向，也为稍显特殊的地缘政治合作提供了可观测的网络侧印证。</span></span></font></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0px;"><b><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: bold;">五、参考链接</span></span></font></b></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 2em;"><font face="宋体"><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: justify;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;text-decoration: none;font-size: 15px;"><span textstyle="" style="font-weight: normal;"><a href="https://www.jumpsec.com/guides/chainshell-muddywater-russian-criminal-infrastructure/" target="_blank">https://www.jumpsec.com/guides/chainshell-muddywater-russian-criminal-infrastructure/</a></span></span></font></p><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-template="t" mpa-from-tpl="t"><div data-mpa-category="模板" style="display: flex;justify-content: center;align-items: center;padding-top: 20px;" data-mid="" mpa-from-tpl="t" data-mpa-template="t"><div style="display: flex;justify-content: center;align-items: center;" data-mid="" mpa-from-tpl="t"><div style="display: flex;justify-content: center;align-items: center;background: rgb(168, 229, 138);padding: 4px 9px 3px 10px;" data-mid="" mpa-from-tpl="t"><p style="font-size: 16px;font-family: PingFangSC-Medium, &#34;PingFang SC&#34;;color: rgb(255, 255, 255);line-height: 23px;letter-spacing: 1px;" data-mid=""><span leaf="">往期推荐</span></p></div></div></div></div></div><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492114&amp;idx=1&amp;sn=8d7c5643b4d7b9e6ba5fdb73db25f5ac&amp;chksm=e90dc838de7a412e358185c880ff13f5960c816f47faef975adecc92aa229dd947eaed7c1543&amp;scene=21#wechat_redirect" textvalue="LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）" data-itemshowtype="0" linktype="text" data-linktype="2">LockBit勒索组织发布声明并重建泄露网站——每周威胁情报动态第166期（2.23-2.29）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492108&amp;idx=1&amp;sn=9a94a877d19aae993613beabfed515b9&amp;chksm=e90dc826de7a4130e9c14fbecc4bb470c785600d65f4eca984822a3772b801007188d753444b&amp;scene=21#wechat_redirect" textvalue="GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）" data-itemshowtype="0" linktype="text" data-linktype="2">GoldFactory组织开发针对iOS系统的GoldPickaxe木马病毒——每周威胁情报动态第165期（2.9-2.22）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492097&amp;idx=1&amp;sn=53ec18ecbac467ab6dddeef971e8630f&amp;chksm=e90dc82bde7a413df05e08bc4d6136b60d4a339310cdb66a046cc0645bb90e447b8564e16180&amp;scene=21#wechat_redirect" textvalue="新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）" data-itemshowtype="0" linktype="text" data-linktype="2">新APT组织APT-LY-1009针对亚美尼亚政府投递VenomRAT——每周威胁情报动态第164期（02.02-02.07）</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="http://mp.weixin.qq.com/s?__biz=MzI0MTE4ODY3Nw==&amp;mid=2247492083&amp;idx=1&amp;sn=2c985de24dfa929181ba8e6ae63b02ab&amp;chksm=e90dcbd9de7a42cf2f738cbe44a3859ab3f78636b84ef2b930dfc29ecbfc05542ae161ab4e16&amp;scene=21#wechat_redirect" textvalue="APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）" data-itemshowtype="0" linktype="text" data-linktype="2">APT28组织对全球多个组织发起NTLMv2哈希中继攻击——每周威胁情报动态第163期（01.26-02.01）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=31fba9c8&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI0MTE4ODY3Nw%3D%3D%26mid%3D2247492925%26idx%3D1%26sn%3D5e0b1bbfde6029935517adbe30201918">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 30 Apr 2026 14:32:00 +0800</pubDate>
    </item>
  </channel>
</rss>